A proxy server relays one application you pointed at it, so the destination sees the proxy's address. A VPN carries every packet the device sends through an encrypted tunnel to a network. One is scoped by configuration, the other by routing, and every other difference follows from that.
- A proxy covers one application
- A VPN covers the whole device
- HTTPS already encrypts the page, either way
- Only a VPN reaches a private network
- Only a proxy can read a request and refuse it
On this page
- The difference that actually matters
- What the destination actually learns
- The kinds of proxy, because they are not one thing
- Where each one leaks
- What a business should actually deploy
- What each one protects you from
- Free proxies and free VPNs
- The consumer question, answered honestly
- Choosing, in four lines
- Comparison
- FAQ
FundamentalsThe difference that actually matters
Both put a server between you and the destination, and both change where your data enters the internet. What separates them is how much of your traffic that machine sees, and how much of it can go around.
A proxy server is a relay you point an application at. The browser is told to send its requests to the proxy server, the server makes the request on its behalf, and the answer comes back over the same connection.
The destination logs the proxy's address. Nothing else on the machine is affected. Open a mail client, a game, a backup agent or a command line tool, and their traffic leaves the way it always did.
A VPN is a virtual network interface. The operating system routes data into it, so every application is carried whether it knows about the tunnel or not, and the far end of the tunnel is a network rather than a single server. That is why a VPN can put a laptop on an office network and a proxy cannot.
This is the whole distinction, and every practical difference below follows from it. One is scoped to an application by configuration. The other is scoped to a device by routing.
Encryption, stated more carefully
The line that a proxy does not encrypt is true of the proxy itself and misleading about the traffic.
Visiting an HTTPS site through a plain HTTP proxy still encrypts the page. The browser opens a tunnel through the proxy with a CONNECT request and negotiates TLS with the real destination inside it, so the proxy relays bytes it cannot read. What the proxy does see is the hostname you asked for, the timing, and the volume.
What is genuinely unencrypted is the leg between you and the proxy, for anything not already using TLS, and the fact that you are talking to the proxy at all. On a hostile network that matters: the coffee shop sees you connect to a proxy and sees every hostname you request of it.
A VPN encrypts that leg by construction. The network you are sitting on sees an encrypted connection to one VPN server and nothing about the data inside it. That is the real gain, and it is about the local network and the internet provider rather than about the destination.
What leaksWhat the destination actually learns
Both technologies are sold on hiding your IP address, so it is worth being exact about what a website learns either way.
Your address becomes the intermediary's. With a proxy server the site logs the proxy's address. With a VPN it logs the VPN server's. In both cases the site knows the connection came from a data center rather than a home connection, and large sites keep lists of which addresses belong to which providers. Hiding an address is not the same as looking like an ordinary user.
Headers can give you back. Some proxy servers add an X-Forwarded-For header carrying the original address, because that is what the header is for: it exists so that servers behind a load balancer can log real clients.
A proxy configured for transparency rather than privacy will happily announce you. VPNs do not have this problem, because they operate below the layer where headers exist.
The browser can give you back. Browsers leak the local network address through WebRTC unless that is disabled, and the collection of fonts, screen size and settings that make up a browser fingerprint identifies a returning visitor without any address at all. Neither a proxy server nor a VPN touches either of these.
Your accounts give you back immediately. Log into an account and the site knows exactly who you are, from any address, through any tunnel. This is the honest limit of both technologies: they change where your data enters the internet, not who you are once you introduce yourself.
What neither hides from the destination is the shape of the connection. Timing, volume and the pattern of requests all survive, and for a site that cares, they are informative.
Four proxiesThe kinds of proxy, because they are not one thing
Most confusion about proxies comes from one word covering four different jobs, and the four differ in who they protect and from whom.
A forward proxy is the one this article means by default. Clients are configured to use it, and it fetches the internet on their behalf. This is what a company uses to log and filter browsing.
A reverse proxy sits in front of servers rather than clients. It receives requests from the internet and passes them to whichever server should answer. Every load balancer and every content delivery network is one. It hides the servers, not the users.
A transparent proxy intercepts traffic without being configured on the client at all, usually by routing tricks on the network. Users do not know it is there, which is the point, and it is how guest networks and schools apply filtering.
A SOCKS proxy relays at a lower level than HTTP. Because it does not parse requests, it can carry protocols other than the web, which is why it turns up in tunneling over SSH. It also cannot filter what it does not understand.
Failure modesWhere each one leaks
Neither proxies nor VPNs fail in the way users expect, and both failures are quiet.
Proxies leak by omission. Only the traffic you configured goes through the proxy server. Applications that ignore system proxy settings, and there are many, go straight out. Anything using a protocol the proxy does not speak goes straight out.
This is why a proxy is a filtering tool and not a security boundary: the traffic that matters most is often the traffic that does not use the browser.
Proxies leak DNS. Unless the name lookup is also sent through the proxy server, your resolver still sees every domain you visit, which is enough to reconstruct the browsing you thought you had hidden.
VPNs leak through split tunneling. Most deployments send only some ranges into the tunnel and let the rest go direct, because sending everything through the office is slow and expensive. Every range outside the tunnel is traffic the local network still sees. Split tunneling is usually correct and always worth writing down.
VPNs leak when the connection drops. If the tunnel falls over and the operating system falls back to the normal route, traffic continues in the clear. A kill switch is the setting that prevents this, and it is off by default more often than not.
Both leak to the operator. Whoever runs the server sees what that server sees, and no amount of encryption elsewhere changes it. Choosing between them does not remove that; it only decides who is in the position of trust.
For a businessWhat a business should actually deploy
For a company the framing is rarely VPN vs proxy, because the two answer different questions and most businesses need both answers.
Outbound browsing is a filtering and visibility problem, and proxy servers are the tool. Modern deployments call it a secure web gateway: a forward proxy with category filtering, malware scanning and logging. It exists to enforce policy on where staff can go and to leave a record.
Reaching internal systems is an access problem, and this is where a VPN belongs. A tunnel puts a remote laptop on a network so it can reach the file server, the line of business application and the printer that only lives inside.
The replacement for the second one is worth naming, because it is where the market has gone. Zero trust network access grants a user one application rather than a whole network, checks the device on every request, and removes the flat network a stolen VPN credential otherwise hands over.
If you are choosing today rather than maintaining what exists, compare it with the VPN option rather than with the proxy.
Running both is normal and not redundant. The gateway watches what leaves. The tunnel decides what can be reached.
Threat by threatWhat each one protects you from
Security is the word both are sold on, so here is the same question asked once per threat. The useful column is often the third one.
| Threat | Proxy server | VPN |
|---|---|---|
| The cafe network reading your traffic | No, the connection to the proxy is not encrypted by itself | Yes, that is the main thing a VPN buys |
| The cafe network seeing which sites you visit | No, it sees every hostname you request | Yes, it sees one encrypted connection |
| Your internet provider logging your browsing | Partly, for the one application you routed | Yes, for everything the device sends |
| A website learning your location from your address | Yes, for that application | Yes, for the whole device |
| A website recognizing you across visits | No, fingerprinting and cookies survive both | No, the same |
| Your employer inspecting a managed device | No, inspection happens on the device | No, the same |
| Malware and phishing pages | Partly, a filtering gateway blocks known bad sites | No, encryption carries malware as happily as anything else |
| An attacker using a password that leaked | No | No, this is what multi factor authentication is for |
| Reaching a file server on the office network | No, it relays outward only | Yes, that is what the tunnel is for |
| Enforcing where staff may browse | Yes, it reads the request and can refuse it | No, not without a separate device in the path |
Two rows deserve the emphasis. Encryption protects data in transit and nothing else, so neither technology helps with malware or with a stolen credential, which between them account for most real incidents. And a privacy gain against your internet provider is a privacy transfer to the operator you chose instead, which is only an improvement if you trust them more.
The free tierFree proxies and free VPNs
Both markets have a free tier, and in both the economics are the same. Running servers that carry other people's data costs money every month, so a service with no revenue is either a loss leader for a paid product, a research project, or selling something. Usually the something is you.
The documented business models behind free services are worth naming, because they are not hypothetical. Some inject or replace advertising in the pages you load. Some sell the browsing data they collect, which is the entire point of the intermediary position.
Some resell your connection as an exit point for other people's traffic, which means requests you never made leave from your address. Some are simply run by whoever wants to read what passes through.
There is a narrower and honest use for a free proxy server: fetching something public where you do not care who sees the request. Checking how a page looks from another country, or scraping something already public. Neither the data nor the destination matters, so neither does the operator.
Where it stops being reasonable is anything with a login. Free proxies and free VPNs sit exactly where a password crosses, and the users most likely to reach for one are the users least likely to have anything else protecting the account.
The paid version of the same warning: paying does not make an operator trustworthy, it only removes the most obvious reason to be untrustworthy. What decides it is whether they publish what they log, and whether anyone independent has checked.
For a personThe consumer question, answered honestly
Most searches for this comparison come from people deciding whether to pay for a consumer VPN, so the honest version is worth stating.
Consumer VPNs move the point at which your data joins the internet from your internet provider to the VPN company, using servers they operate. That helps against your provider, against a hostile local network and against a website learning your home address.
It does nothing against a website you log into, because you told it who you are. It does nothing against malware. It does not make you anonymous, because your accounts identify you.
A browser proxy or extension does the same for that browser only, more cheaply and less thoroughly.
Against the two threats most people actually face, a password that leaked and a link they clicked, multi factor authentication does more than either.
The answerChoosing, in four lines
Pick a proxy server when the job is to control, filter or observe where an application goes. That is the protection a gateway provides, and proxies are the only one of the two that can read a request and refuse it.
Pick a VPN when the job is to reach systems that live on a private network, or to stop the network you are sitting on from seeing what you do. Those are the two things VPNs do that proxies cannot.
Deploy both if you run a company. They protect against different things and neither substitutes for the other.
Buy neither first. If the budget covers one thing this quarter, the protection with the best return is not on this page. It is multi factor authentication on email and remote access, because a leaked password is how most incidents start, and neither proxies nor VPNs touch it.
ComparisonA proxy server and a VPN, on the criteria that decide it
| Criterion | Proxy | VPN |
|---|---|---|
| What it covers | One application you configured | Every application on the device |
| Where it sits | Application layer, it understands requests | Network layer, it moves packets |
| The leg to the intermediary | Encrypted only if the traffic already was | Always encrypted |
| What the local network sees | Which hostnames you ask for | One encrypted flow to one endpoint |
| Reaching internal systems | No, it relays outward | Yes, it joins you to a network |
| Filtering and inspection by policy | Built for it, it reads the request | Possible, but it needs a separate device |
| Cost per user | Low, one server relays many | Higher, each client needs a tunnel |
| Speed penalty | Small, no per packet crypto | Real, everything is encrypted twice |
| Failure mode | Applications quietly bypass it | The whole device loses its route |
| Best fit | Controlling and filtering outbound browsing | Remote access to private systems |
FAQFrequently asked questions
What is the main difference between a VPN and a proxy?
Scope. A proxy relays the one application you pointed at it. A VPN carries every packet the device sends, through an encrypted tunnel to a network.
Does a proxy encrypt my traffic?
The proxy itself adds no encryption. Traffic that was already using HTTPS stays encrypted end to end, and traffic that was not stays readable on the way to the proxy.
Is a VPN always more secure than a proxy?
For hiding your traffic from the local network, yes. For controlling and inspecting where staff go, a proxy does a job a VPN was never built for.
Can I use both at the same time?
Yes, and companies routinely do, with the gateway filtering outbound browsing and the tunnel providing access to internal systems. Stacking a consumer VPN on top of a consumer proxy adds cost and latency and very little else.
Which one is faster?
A proxy, usually. It adds a hop but no per packet encryption. A VPN encrypts and decrypts everything, and on an already encrypted site that work happens twice.
What is a SOCKS5 proxy?
A proxy that relays at a lower level than HTTP, so it can carry protocols other than the web. It is more flexible and, because it does not read the requests, cannot filter them.
Does a VPN hide my browsing from my employer?
On a company managed device, assume not. The device can carry its own inspection, and the certificates that make that possible are installed as policy.
Do I still need a VPN if everything is HTTPS?
For privacy from the local network, less than you used to. The page contents were already protected. What a VPN still hides is which hostnames you visit and where you are.
What replaced the corporate VPN?
Zero trust network access, for new deployments. It grants one application rather than a whole network and checks the device on every request, which limits what a stolen credential reaches.
Is a reverse proxy the same thing?
No. A reverse proxy sits in front of servers and hides them from the internet. Everything else here is about proxies that sit in front of clients.
Which should a small office buy first?
Neither, usually. Multi factor authentication on email and remote access stops more real incidents than either of these, and costs less.
How does this relate to IPsec?
IPsec is one of the ways a VPN tunnel is built, the one most site to site links and most firewalls use.
Keep readingRelated concepts
Read next · Remote access What Is an IPsec VPN? IPsec is how most of the tunnels in this comparison are actually built. Open this next11 min- Identity and access · 16 min What Is MFA? The control this article recommends buying before either one.
- Addressing · 15 min What Is a Subnet? A VPN joins two address ranges. This is what those ranges are.
- Network security · 14 min What Is a Firewall? Filtering outbound browsing is a firewall question, and this is where that boundary sits.
- Identity and access · 13 min Zero Trust Explained Per application access is what replaces the VPN in the model that assumes breach.
- Protocols · 10 min TCP vs UDP Both tunnels here run on UDP, and this is the reason.
- Remote access · 14 min WireGuard Explained The protocol most new tunnels are built with, once you have decided you want one.
- Infrastructure · 11 min MPLS Explained The carrier grade version of a private path, and what it costs.
- Infrastructure · 10 min Proxy vs Reverse Proxy, and Which One Your Business Runs Into Forward and reverse proxies compared, and where a load balancer, WAF and CDN sit.