Is a VPN safe? On its own, neither safe nor unsafe. It is an encrypted tunnel to someone else's server, and everything hinges on whose server, what gets written down there, and what you do while the tunnel is up. A good VPN hides your list of sites from the café Wi-Fi and from your ISP. A bad one does the opposite: it collects that list itself, sells it, and throws in ads. And then there are the cases where the VPN is honest and useless, because the hole is somewhere else.

Here are five situations where a VPN makes you less safe, not more. If none applies, your tunnel is doing its job. If one does, it is an evening's fix.

1. The free app from the store

Servers and bandwidth cost money. An app that does not charge you is charging someone else, and the product it sells is usually you: ad SDKs inside the app ship your device ID and habits to ad networks, and some services rent out your connection so that strangers exit to the internet from your address. You hid from your ISP to expose yourself to a company with no name and no address. How to tell an honest free tier from that is in Free VPN: what it actually costs.

2. The tunnel is up and DNS is leaking around it

The most common failure, and an invisible one. The connection is established, your IP has changed, and your device is still asking the ISP's DNS server "where is this site". The list of sites goes to the ISP exactly as before, except now you are confident you are protected. Two minutes to check: What Is My IP should show the server's country, and the WebRTC and IPv6 leak tests should not show your real address. The fixes, platform by platform, are in Is my DNS leaking.

3. The kill switch is off

Tunnels drop. Not because the service is bad, but because your phone hopped from Wi-Fi to cellular or the elevator ate the signal. For those seconds your device goes online directly, and whatever was open goes out unencrypted, with your address attached. A kill switch simply cuts the internet for that moment. Without it your protection works "almost always", and "almost" is not a word that belongs in privacy. Details in What is a VPN kill switch.

4. You believe the "no logs" banner

The VPN server stands exactly where your ISP used to stand: it can see domains, timing and volume. Whether it records any of that is policy, not technology. "No logs" on a landing page means nothing; a policy that lists what is stored and what is not means something, because you can check it. A service that "stores nothing at all" is either not running a business or not telling you everything: at minimum it stores your email and subscription status. What a real policy reads like is in What does no-logs VPN mean.

5. You expect things a VPN does not do

It does not make you anonymous: you signed into your email and your social accounts, and the site knows who you are through any tunnel. It does not hide your browser fingerprint: screen, fonts and time zone go to the site straight from the browser. It is not an antivirus: a malicious download comes through the tunnel just fine. It does not stop phishing: a fake bank page loads inside the tunnel like the real one. If those were the reasons you installed it, your security did not go up; your confidence did, and that is the worst combination.

The one that is actually dangerous: certificate installs

The most harmful "VPN" looks innocent. The app asks you to install a profile or a certificate "for the secure connection to work". A root certificate lets whoever issued it decrypt your HTTPS traffic wholesale: banking, email, passwords. A real tunnel never needs it; it needs permission to add a VPN configuration, nothing more. If an app insists on a certificate, delete it, then check Settings, General, VPN & Device Management on iPhone, or the credential storage on Android, for anything you do not recognize. This is the one scenario where a VPN is not "slightly worse" but the exact opposite of its purpose.

When a VPN really is safer than none

Public Wi-Fi, where the network owner and everyone on it can see domains and DNS; a tunnel closes that. A home ISP that monetizes browsing data. Travel, where you join dozens of strange networks. Working with company services from a café. In all of these the tunnel does what it should, provided the first four points are in order. The public-Wi-Fi case in detail: Is public Wi-Fi safe.

The ten-minute check

  1. Open the privacy policy and find the list of what is stored. No list, only a slogan: minus one.
  2. Connect and check the IP, WebRTC and IPv6 pages above.
  3. Turn the kill switch on and switch from Wi-Fi to cellular: the internet should drop for a few seconds, not fall back to the open network.
  4. Look at the app's permissions: a VPN does not need contacts, SMS or the microphone.
  5. Check that there is a paid plan and that the free plan has stated limits. Neither: you are the payment.

Red flags in one minute

No paid plan at all. A certificate install. No company name or country. "No logs" with no list behind it. Permissions for contacts, SMS or microphone. Hundreds of identical five-star reviews with no text. Any one of these is not a verdict; two together are a reason to look elsewhere rather than to argue for this one.

Bottom line

Whether a VPN is safe is decided by three things, none of them the word "VPN": whose server, what it writes down, and whether the leaks on your side are closed. All three are checkable, and checking takes less time than reading this.

404 VPN lists in its privacy policy what is kept and what is not: no browsing history, DNS queries, traffic content or source IP after connection; email, subscription status and aggregated volume statistics are kept. VLESS and WireGuard, DNS inside the tunnel, a kill switch, and a free plan with stated limits: 5 GB a day, one device, five locations. Verify all of it yourself, starting on the home page.