Home / Blog / What Your ISP Can Actually See — an Honest, Technical Answer
Korp Labs · Field Notes

What Your ISP Can Actually See — an Honest, Technical Answer

 ·  5 min read  ·  By Korp VPN

Ask what an internet provider can see and you will get two bad answers. One says they read everything you do. The other says HTTPS means they see nothing.

Both are wrong, and the accurate answer is more useful than either.

Start with what encryption already covers

Almost all web traffic is now encrypted with TLS — the padlock in the address bar. Where it is in use, your provider cannot see:

This is real protection and it covers the majority of what people worry about. Your provider is not reading your emails as you write them.

Now what remains visible

Encryption protects the contents of the envelope. It does not hide the envelope.

Which sites you connect to. This is the big one, and it leaks through two separate channels.

The first is DNS. Before your device can connect to a site, it converts the name into an address, and by default that lookup goes to your provider's DNS server in plain text. They receive a direct, timestamped request: this customer wants the address for this hostname. That is a browsing history, delivered voluntarily, in a convenient list.

The second is the connection itself. Even with encrypted DNS, your traffic goes to an IP address your provider can see. For sites on dedicated infrastructure, the address identifies the site. Historically the server name was also sent in the clear during the TLS handshake; encrypted variants exist but are not universally deployed, so this often remains visible.

When and how much. Every connection is timestamped and measured. Your provider knows when your devices are active, when you sleep, when the house is empty, when you started streaming and for how long.

Traffic shape, which implies content type. Video streaming, voice calls, large downloads and ordinary browsing all have distinct patterns. Nobody needs to decrypt a video call to know it was a video call.

Everything your devices do without you. Background sync, app updates, telemetry, smart-home devices phoning home. This is a continuous, passive inventory of the software and hardware in your home.

Anything not encrypted. Increasingly rare on the web, but older devices, some apps and various embedded systems still transmit in the clear.

Why this is not a trivial residue

It is tempting to conclude that hostnames and timings are harmless metadata. They are not.

A list of which sites you visited and when is, for most practical purposes, the interesting part. It reveals which bank you use, which health conditions you research, which political sites you read, which dating services you have accounts with, and who you might be talking to. Content is often predictable once the destination is known.

What happens to that record varies by jurisdiction. Some countries mandate retention for a fixed period. In some, providers may sell aggregated browsing data commercially. In most, it is obtainable by legal process. The consistent fact is that the record exists and you are not the one holding it.

What a VPN changes, precisely

A VPN encrypts everything leaving your device and sends it through one tunnel to a server you have chosen. From your provider's position, that changes the picture:

The honest framing is that a VPN does not delete the observation point. It relocates it. Your provider stops being able to build the list; the VPN operator now occupies that position instead.

Which makes the operator's policy the entire question, and the reason to be specific rather than trusting a logo:

What a VPN does not do

Worth stating plainly, because the industry is bad at this:

The practical summary

Use encrypted DNS and keep everything on HTTPS — that is free and closes the largest leak on any network.

Use a VPN when the observer you want to remove is the network operator: your ISP, a public Wi-Fi provider, a hotel, a landlord's shared connection, or a national filtering system. That is the specific problem it solves, and it solves it well.

Do not use it expecting anonymity, and do choose the operator as carefully as you would choose an ISP — because for the duration of the connection, that is exactly what they are.

vpn guideprivacydnsencryption

Read this on a network nobody is watching

Korp VPN encrypts every packet leaving your device with AES-256 and a stealth protocol that looks like ordinary HTTPS traffic. Unlimited bandwidth, 20+ countries, a strict no-logs policy, and a 5-day free trial — from $1.60 per month.

← Previous
The Bangladesh Bank Heist: How a Spelling Mistake Stopped a $951 Million Theft
Next →
Why Free VPNs Are Dangerous — What the Research Actually Found

More from Korp Labs

What "No-Logs VPN" Really Means and How to Check the Claim

Almost every VPN says it keeps no logs. The phrase can mean very different things. Here is what a meaningful no-logs policy covers, and the questions that expose a weak one.

VPN vs Proxy vs Tor: What Each One Actually Protects

They all change your IP address, but they protect very different things. A plain-language comparison of VPNs, proxies and Tor, and how to pick the right one for what you are doing.

How to Test Your VPN for Leaks: DNS, IPv6 and WebRTC

A VPN can be connected and still leak your real IP address or DNS lookups. Here is how to run the three tests that matter in under five minutes, and how to fix what you find.