If a proxy also hides your IP address, how is a VPN any different?

Summary

A proxy relays traffic only for the browser or app you point at it, and relaying isn't the same as encrypting. A VPN puts all of a device's traffic into an encrypted tunnel, so apps are covered without being configured one by one. Some proxies also pass your original IP address to the website in a header, which means "my IP changed" can look the same in both cases while meaning something quite different.

Side by side

ProxyVPN
What goes through itTraffic from the browser or apps set to use itAll traffic from the device, unless you exclude some
EncryptionNot part of the job (SOCKS5 has none of its own)The tunnel is encrypted
Your original IPHidden from the site, unless the proxy adds it to a headerHidden from the site

Only what you point at it

MDN defines a proxy server as an intermediate program or computer between networks. A forward proxy handles requests going out to anywhere on the internet, and MDN notes that some are anonymous and let users hide their IP address while browsing.

Set a proxy in your browser and the browser's traffic goes through it. Every other app on the machine keeps using your normal connection. The Electronic Frontier Foundation describes a VPN, by contrast, as an encrypted tunnel carrying all your web traffic between your device and the VPN server.

Encryption comes from somewhere else

When you open an HTTPS site through a web proxy, the browser uses the CONNECT method to have the proxy open a tunnel, and the TLS connection to the site runs inside it. The website connection is encrypted; the proxy isn't adding anything. MDN also warns that not every proxy supports CONNECT, and some allow it only on port 443.

SOCKS5, defined in RFC 1928, can relay traffic for any application. The RFC calls it a "shim-layer" between the application and transport layers, and says its security depends heavily on the authentication and encapsulation methods a given implementation uses. Mullvad puts it plainly for its own SOCKS5 proxy: the protocol has no encryption, and traffic is encrypted only because the connection runs inside Mullvad's VPN tunnel. Disconnect the VPN and you can't reach the proxy at all.

Some proxies tell the site who you are

A website sees a proxied request as coming from the proxy's address. Because servers often want the real client IP anyway, proxies commonly add it to a request header. MDN calls X-Forwarded-For a de facto standard for identifying the originating IP of a client connecting through a proxy, and says the header "exposes privacy-sensitive information by design." If hiding your address is the goal, whether a particular proxy adds that header decides the outcome.

Splitting the relay in two

Apple's iCloud Private Relay sends Safari browsing through two relays. Apple runs the first one, which sees your IP address but not where you're going, because your DNS records are encrypted. A third-party provider runs the second, which assigns a temporary IP address and connects you to the site. Apple's point is that no single party, Apple included, sees both who you are and what you visit. A VPN provider, on the other hand, sees both. Private Relay covers only Safari and isn't available in every country or region.

Sources

Related on this site


Written by Kaz (pen name). Published September 28, 2026. The facts above come from the vendor and standards pages listed under Sources. We have not used these products. Corrections: contact form.