Does a VPN Make You Anonymous?
A VPN changes your IP address. It does not change who you log in as, how you write, or whose card paid for it. The three layers that still identify you.
Published September 15, 2026· By Juan Martinez

Turn on a VPN and something visibly changes. A site that knew your city a second ago now thinks you’re in Frankfurt. Your internet provider, which could see every domain you opened, sees one encrypted connection and nothing else. That is real, it is worth having, and it is the thing you paid for.
It is also the reason the question in the title gets answered wrongly so often. The change is dramatic enough that it feels total — and the marketing around VPNs has spent a decade encouraging you to read it that way. So: does a VPN make you anonymous? No. Not because it’s weak, and not because you picked the wrong provider. A VPN works on the network layer: the route your traffic takes and who can read it along the way. Almost everything that actually identifies a person online works somewhere else entirely, on information you hand over yourself.
Three layers, in particular, keep identifying you after the VPN is on. None of them involves your IP address at all.
Layer One: You Introduce Yourself
The moment you sign in to anything, the anonymity question is over for that site. Your account is the identifier. It doesn’t matter which country the connection appears to come from — you are the person who owns that inbox, that order history, that follower list. A VPN never claimed otherwise, but this is where most people’s actual browsing lives: logged in, all day, on a handful of large services.
The subtler half is what happens when you aren’t logged in. Cookies do the recognizing. The EFF’s Surveillance Self-Defense glossary puts the reach plainly — cookies “enable tracking and profiling so sites can recognize you and learn more about where you go, which devices you use, and what you are interested in,” and it specifies that this holds “even if you don’t have an account with that site, or aren’t logged in.”[2] A cookie sits in your browser and travels with it. Changing the IP address the traffic arrives from does not disturb it.
And cookies are now the old mechanism. As browsers have restricted third-party cookies, the advertising industry has moved to what researchers call extended identifiers — persistent identifiers, typically a hashed email address, used to link one person across different sites and different devices. A 41-month study published in September 2026 measured how far this has gone, examining over 145 million ad-bidding requests from 616,539 websites. Extended identifiers had reached nearly 84% of the studied sites by May 2025. Of the 18 providers that account for essentially all of the identifiers observed, 12 build identifiers persistent enough to recognize the same person “across visits, websites, devices, and months,” and 16 transmit them on EU websites without user consent.[1]
Read that mechanism closely, because it explains the whole article. The key is a hashed email address. You supplied it — at a newsletter signup, a checkout, an account creation — and it follows you between devices precisely because it was never tied to a network address in the first place. A VPN changes the network address. There is no point at which the two interact. This isn’t a gap in VPN coverage; it’s a different system.
What does push back on this layer is the browser. Firefox’s Total Cookie Protection, on by default worldwide since 2022, “creates a separate ‘cookie jar’ for each website you visit,” confining cookies to the site that set them so they can’t be used to follow you from site to site — and Mozilla is explicit that this applies to all cookies, not only ones on a blocklist.[3] That’s the right shape of defense for this layer. Note where it lives: in the browser, not in the tunnel.
Your browser also broadcasts a fingerprint — screen size, fonts, graphics hardware — that identifies your device without any cookie at all. It’s a large enough subject that it has its own article here; the short version is that a VPN doesn’t touch it either.
Layer Two: A Pseudonym Is Not Anonymity
This is the layer people miss, because a handle genuinely feels like a disguise. You post under a nickname, there’s no real name on the profile, and the VPN has made the IP address useless. What links that account to you is the writing itself.
The landmark result here is 14 years old, and it’s worth saying that out loud rather than presenting it as news. In 2012, a group of researchers led by Arvind Narayanan tested whether an anonymous author could be picked out of a very large crowd by writing style alone. Matching a sample of three blog posts against a pool of 100,000 authors, their classifiers identified the correct author in over 20% of cases, and placed the right author in the top 20 guesses about 35% of the time. When the system was allowed to decline to guess on cases it was unsure about, precision on its top guess rose from 20% to over 80%. The paper’s own conclusion: “an anonymous blogger or whistleblower may be unmasked unless they take steps to obfuscate their writing style.”[4]
A 20% hit rate out of 100,000 is not a machine that unmasks everyone. It is, however, a demonstration that the thing is possible at internet scale — done in 2012, with 2012 tools.
The tools changed. In February 2026, researchers including Nicholas Carlini and Florian Tramèr published work on large-scale deanonymization using language models, and the shift is in kind rather than degree. Their agent re-identified Hacker News users “at high precision, given pseudonymous online profiles and conversations alone, matching what would take hours for a dedicated human investigator.” One of their test sets links Hacker News accounts to LinkedIn profiles; another splits a single Reddit user’s history in two by date and matches the halves back together as if they were two strangers. Against classical methods, the improvement is not incremental: up to 68% recall at 90% precision, compared to near 0% for the best non-LLM approach. The authors state the consequence directly — “the practical obscurity protecting pseudonymous users online no longer holds.”[5]
That last phrase is the useful one. Pseudonymity never rested on being impossible to unmask; it rested on nobody bothering, because it took an investigator hours per target. That was a real protection, and it was a protection made of cost. Automation removes it.
Nothing in this layer has anything to do with the tunnel. The VPN delivered your words faithfully. The words were the identifier.
Layer Three: You Bought the VPN
The third layer is the one specific to this purchase, and it’s the one competitors writing this topic tend to skip: to use most VPNs, you hand the provider your email address and a payment card in your name. You have bought a tool for not being identified, and identified yourself to buy it.
For most threat models this is fine, and it’s important not to overstate it. If your concern is your ISP profiling your browsing or a café network logging which sites you open, your provider knowing your billing details changes nothing about that. It matters in one specific case: when the provider itself — or anyone who can compel, breach, or subpoena it — is part of what you’re worried about. Then the account is a name attached to a subscription, and the strength of the protection depends on what the company has to hand over rather than on the encryption.
This is measurable rather than theoretical, and it’s where this site’s own reviews are the source. Of the 14 VPNs reviewed here, exactly four let you create an account without an email address: Mullvad, IVPN, OVPN, and Windscribe. The other ten require one.
- Mullvad issues a 16-digit account number generated in the client. There is no email field, no username, no password — the number is the account. It accepts cash sent by mail, and Monero or Bitcoin at a 10% discount over card payment.
- IVPN works the same way: no email at signup, a random account code instead, with cash and Monero accepted.
- OVPN asks for a username and a password, with email optional, and takes cash and Bitcoin alongside cards.
- Windscribe also needs only a username and password. Adding an email is optional and raises the free tier’s data cap, which is a reason to give one rather than a requirement.
Those four make an end-to-end anonymous relationship genuinely possible: no identifying detail at signup, no identifying instrument at payment. Most services reviewed here cannot, and the reason is usually the account rather than the checkout — plenty of providers accept cryptocurrency while still requiring an email address to create the account at all, which reduces what the payment processor learns without changing what the provider knows. Proton VPN is a clear example: it accepts both cash and Bitcoin, but a recovery email is mandatory at signup and doubles as the username, so the account cannot exist without one.
It’s also worth knowing that this can move backwards. TunnelBear accepted Bitcoin until August 2025 and now takes credit cards only — a payment-anonymity option that existed, and then didn’t.
So What Is a VPN Actually For?
Stripping away what it doesn’t do leaves something specific and genuinely valuable. A VPN hides your traffic from the network you’re on — the ISP, the hotel, the employer’s router — and hides your IP address from the sites you visit. That defeats profiling by your internet provider, reduces what a hostile local network can learn, and removes your location and provider from what sites see by default. Those are the jobs it does properly, and no amount of careful browsing substitutes for it.
What it cannot do is make you a different person to services you identify yourself to. The honest framing isn’t “VPNs don’t work.” It’s that identity online is assembled from several independent channels, and a VPN covers exactly one of them well.
If your goal is genuinely to separate your identity from an activity — not privacy from your ISP, but real unlinkability — the tool class is different, and its own developers are candid about the ceiling. The Tor Project says plainly that “generally it is impossible to have perfect anonymity, even with Tor,” and notes that signing in to a site means “they still don’t know your location but they know who you are.”[6] Our guide to VPNs, proxies and Tor covers when each one is the right answer.
Summary
A VPN changes the route your traffic takes and who can read it. It does not change who you log in as, what your browser stores, how you write, or whose card paid for the subscription.
Three things keep identifying you with the VPN on, and none of them touches your IP address. You identify yourself by logging in — and even logged out, cookies and hashed-email identifiers now reaching most of the ad-funded web recognize you across sites and devices. A pseudonym is not a disguise: writing style was enough to unmask authors out of 100,000 candidates in 2012, and language models have since removed the effort that made that attack rare. And buying most VPNs requires handing over an email address and a card in your name.
The practical version: use a VPN for what it’s built for, let the browser handle cookies and fingerprinting, keep separate identities genuinely separate in how you use them rather than trusting an IP change to do it, and if the provider is part of your threat model, pick one of the four reviewed here that never needs your name. For providers chosen specifically on audited no-logs records, see our best VPNs for privacy.