Start with a question the original version of this page never asked: who, specifically, are you trying to keep this from?
Every useful answer about VPNs depends on it, and the four plausible answers point in completely different directions. A tool that solves the first problem entirely does nothing whatsoever about the second.
What a VPN actually does
It encrypts your traffic between your device and a server run by the VPN company, then sends it onward from there. Your network — home broadband, mobile carrier, office, hotel — sees an encrypted stream to one address and nothing about its contents. The sites you reach see the VPN server's address rather than yours.
That is the whole mechanism. Note what it is: not the removal of an observer, but the substitution of one. Your internet provider can no longer see which sites you visit, because the VPN company can. Whether that is an improvement depends entirely on which of the two you would rather trust, and that is a judgement about a company, not about a technology.
The four observers
Your network operator. This is the case a VPN genuinely solves. Without one, your provider can see the domain of every site you connect to — encryption protects the contents of a page, not the name of the server you asked for — and in some jurisdictions retains that record. With one, they see an encrypted connection to a VPN endpoint and the volume and timing of traffic through it. This is also the case for a shared office or campus network, where the operator is doing filtering rather than logging.
Other people who use your device or your home. A VPN does nothing here, and this is the observer most people actually have in mind. Browser history, autofill, DNS caches, a signed-in account syncing across devices, an app in the tray, a notification on a shared screen — none of that is network traffic, so none of it is touched. Private browsing windows and account hygiene address this; a subscription does not.
The site you are visiting. Partially. It sees a different IP address, which changes its guess at your location. It still sees your browser fingerprint, its own cookies, and — decisively — whoever you are logged in as. A VPN plus a logged-in account identifies you completely, and paying for anything with a card ends the discussion.
Anyone with legal process. Least of all here. A provider can only hand over what it holds, which is why logging policy matters, but "no logs" is a marketing claim about internal practice, not a property anyone can inspect from outside. A handful of providers have had the claim tested — by an independent audit, or by a court order producing nothing — and those are the ones where the claim means something. For the rest it is a sentence on a pricing page.
What changed in 2025
The reason people reach for a VPN has shifted, and it is no longer mainly about country-level blocking.
In the UK, age-assurance duties under the Online Safety Act took effect on 25 July 2025: services hosting pornographic material must run "highly effective" age checks, in practice photo ID or a facial age estimate, and the requirement has extended well beyond adult sites. VPN downloads in the UK rose sharply in the weeks afterwards. Using one is not an offence there.
In the United States, the Supreme Court upheld Texas's age-verification statute in Free Speech Coalition v. Paxton on 27 June 2025, by six votes to three, applying a lower standard of review than earlier internet-speech cases had. More than twenty states have comparable laws, and several large platforms responded by withdrawing from those states rather than implementing checks.
The practical consequence for the question in this article's title: a VPN changes where you appear to be, which is enough where a site geoblocks a jurisdiction or serves a check based on apparent location. It does nothing at all against a check you are actually put through — no VPN uploads a document on your behalf. And it does not change the legal position of anyone but you, which is why the sites themselves are choosing between compliance and withdrawal rather than routing around it.
Evaluating a provider without believing the pitch
Since no ranking is offered here, criteria are more useful than names.
Whether the no-logs claim has been tested. An independent audit, or a documented case where a provider was compelled to produce records and had none. Both are public. Absence of either means the claim rests on the provider's word.
Ownership and jurisdiction. Who owns the company, and which country's compulsory-disclosure regime it sits under. Consolidation in this sector means several familiar brand names share a parent, which is worth knowing if you are choosing between them for diversity.
Leak handling, not feature lists. A kill switch that blocks traffic when the tunnel drops, DNS queries going through the tunnel rather than to your ISP's resolver, and IPv6 and WebRTC handled rather than ignored. These are the failure modes that actually expose people, and they are testable in ten minutes with any leak-check page.
How you pay. A subscription tied to your name and card is a record connecting you to the account, held by the provider, regardless of what they log about traffic.
Whether it is free, and how it is funded. Running servers and bandwidth costs money. A free consumer VPN recovers that somewhere, and the available options are advertising, data, or someone else's traffic passing through your connection. Free browser-extension proxies are the worst version of this.
That last point is where the original's advice was most wrong. It presented a proxy as a cheaper VPN. A proxy typically covers one application rather than the device, and a plain HTTP proxy provides no encryption at all — an unencrypted proxy substitutes an observer without removing one, which is the wrong half of the trade.
The directory's VPN listings carry the current provider entries; if the concern is what tracks you on the sites themselves rather than in transit, the ad blocker guide covers that layer, which is a different problem with a different tool.
Why this is marked partial
The original ranked five named services. Those rankings are from 2017, every claim in them was reproduced from vendor marketing, and none of it could be verified now — logging policies, ownership, audit status, server counts and prices have all had nine years to move, and in this sector several of them have.
Naming a fresh five without testing them would be the same article with newer logos. The criteria above are what a ranking would have to be built on anyway, and unlike a ranking they do not expire.