Skip to content

freeswan.ca is independent. Some links earn us a commission; your price stays the same. How we review

freeswan.ca

VPN vs proxy: what is the difference, and which one do you need?

A VPN encrypts all the traffic from your device and sends it through the provider's server. A proxy forwards only the apps or requests you point at it, and an ordinary HTTP or SOCKS proxy does not encrypt anything by itself.

Updated

Fibre optic cables connected to a network switch in a rack

The short answer

Both a VPN and a proxy put a server between you and the websites you use, so the site sees the server's IP address instead of yours. The difference is in what gets protected. A VPN works at the level of your whole device: it encrypts all traffic between you and the VPN server, whatever the app. A proxy works per app or per request: only the traffic you send to it goes through it, and a standard HTTP or SOCKS proxy does not encrypt that traffic on its own.

If you want protection on café or hotel Wi-Fi, use a VPN. A proxy fits narrower jobs, such as routing a single browser or tool through another address on a network you already trust.

Side by side: VPN, proxy, Tor and Smart DNS

VPNHTTP proxySOCKS5 proxyTorSmart DNS
What it routesAll device traffic (unless you use split tunnelling)Web requests from apps set to use itTCP and UDP connections from apps set to use itTraffic from Tor Browser or apps set to use TorOnly DNS lookups
Encrypts traffic to the serverYesNot by itselfNot by itselfYes, in layers across several relaysNo
Hides your IP from websitesYesYes, for proxied requestsYes, for proxied connectionsYesNo
Who can see your destinationsThe VPN providerThe proxy operatorThe proxy operatorNo single relay sees both you and the siteYour network and internet provider still can
Useful on public Wi-FiYesLittleLittleYes, for browsingNo
SpeedDepends on server and protocolDepends on the proxyDepends on the proxyUsually slower, because traffic hops through several relaysUnchanged

The table describes how each tool is designed. It is not the result of our own tests.

What a proxy is

The HTTP standard defines a proxy in one sentence. RFC 9110 says that a "proxy" is "a message-forwarding agent that is chosen by the client, usually via local configuration rules". In plain words, you tell an app (often a browser) to send its requests to another computer, which makes them on your behalf and passes the answers back.

Two kinds of proxy come up most often:

HTTP and HTTPS proxies

These handle web traffic. You set them in a browser or in your system's network settings. When you visit an HTTPS site through one, the content stays encrypted between your browser and the site, because HTTPS does that work. The proxy still learns which site you are connecting to. When you visit a plain HTTP site, the proxy can read and change everything.

SOCKS proxies

SOCKS works one level lower. It forwards connections rather than web requests, so it can carry traffic from apps that are not browsers. Version 5 was published as RFC 1928 in March 1996, and the RFC states that it "extends the SOCKS Version 4 model to include UDP". The protocol includes ways to authenticate to the proxy, but a typical SOCKS proxy does not encrypt the traffic it carries. If the app's own connection is encrypted, it stays encrypted. If it is not, anyone on the path to the proxy can read it.

Where proxies make sense

  • A company network that requires all web traffic to pass through a filtering proxy.
  • A developer or researcher who needs one tool to appear from another IP address.
  • A single browser profile you want routed differently from the rest of the computer.

In each case the network you start from is already trusted, or the encryption comes from somewhere else, such as HTTPS.

What a VPN does differently

A VPN creates an encrypted tunnel at the network level. The Canadian Centre for Cyber Security describes it as a tunnel that "encrypts the data being transmitted between 2 parties over an untrusted network, such as the Internet." Because the tunnel sits under all your apps, you do not have to configure each one. Email, messaging, updates running in the background and your browser all go through it.

That is why the VPN is the tool official Canadian guidance mentions for public networks. The Cyber Centre lists a "third-party privacy" VPN type used to secure a connection from an airport or hotel hotspot, and the Privacy Commissioner's 2017 blog post notes that security experts often suggest a VPN on an insecure network such as a café or public library. Our guide What is a VPN? explains what the tunnel hides and what it leaves visible.

A VPN does not remove the trust problem. It moves it. The same OPC post warns that the provider is in a "privileged position to monitor, log, or tamper with any or all communications that are sent through the VPN." A proxy operator is in exactly the same position, often with less encryption on the way there.

Where Tor fits

Tor is a different design. The Tor Project describes it as software that bounces your communications around a network of relays run by volunteers. According to its support site, Tor "prevents somebody watching your Internet connection from learning what sites you visit, and it prevents the sites you visit from learning your physical location." Most people use it through Tor Browser, a version of Firefox.

The project's history page traces the idea of onion routing to research at the U.S. Naval Research Lab in the mid-1990s, with the aim to "route traffic through multiple servers and encrypt it each step of the way." Because each relay knows only the step before and after it, no single relay sees both who you are and where you are going. With a VPN or a proxy, one company sees both.

The cost is speed and convenience. Pages can load more slowly because each request crosses several relays, and Tor Browser protects the browser, not every app on your device. The OPC post points to Tor as an example of a system "deliberately designed with anonymity" in mind, which is a goal VPNs were not built for.

A word on Smart DNS

Smart DNS services change only the server that answers your device's DNS lookups (the step that turns a name like example.ca into an address). Your traffic itself is not rerouted or encrypted, so your IP address stays visible to websites and your activity stays visible to the local network and your internet provider. Smart DNS gives no protection on public Wi-Fi and should not be confused with a VPN.

Which one should you use?

  • Café, airport, hotel or library Wi-Fi: a VPN, with its kill switch on. Our public Wi-Fi safety checklist covers the other habits that matter.
  • You want your internet provider not to see the sites you visit: a VPN, from a provider whose privacy policy and audits you have read.
  • One app needs a different IP address on a network you trust: a proxy can be enough.
  • You need strong anonymity when browsing: Tor Browser, accepting slower pages.
  • You are on a tight budget: look at free VPN plans from known providers before a random free proxy. See free VPNs for Canada for what the free tiers include and leave out.

Whichever you choose, it does not change what the law allows. Our page Is a VPN legal in Canada? sets out what official sources say about VPN use here.

How to tell what you are actually using

Product names can blur the line. Some browser extensions sold as a "VPN" only proxy the browser's own traffic, and the rest of your device goes out unprotected. Check the description: if it works only inside the browser and installs no system-level connection, treat it as a proxy. On a phone, a real VPN connection usually shows a VPN or key icon in the status bar, and your system settings list it under VPN. If you are not sure, ask the provider's support what traffic the product covers before you rely on it on public Wi-Fi.

The protocol matters too. Our overview of VPN protocols compares IPsec/IKEv2, WireGuard and OpenVPN, three protocols you will meet in VPN apps.

Common questions

Is a proxy safer than a VPN?

Usually not. A plain HTTP or SOCKS proxy adds no encryption of its own, so on public Wi-Fi it protects less than a VPN. Both send your traffic through a server run by someone else, so in each case you have to trust that operator.

Is a free web proxy a good idea?

Be careful. Whoever runs the proxy sees every request you send through it, and a free service still has to pay for its servers somehow. Avoid signing in to important accounts through a proxy you know nothing about.

Can I use a VPN and Tor together?

It is possible, but it adds complexity, and the VPN provider then becomes one more party in the chain that you have to trust. For most people on public Wi-Fi, a VPN alone or Tor Browser alone is the simpler choice.

Does a proxy hide my IP address?

From the website, yes, for the traffic that goes through the proxy: the site sees the proxy's address. Apps that are not configured to use the proxy still connect directly and show your real address.

Sources