Skip to content
VPNmine
SECURITY

Do you need a VPN at home?

At home nobody is intercepting your traffic. The question is whether you want your internet provider to hold a complete list of the sites you visit, which it can build from DNS and hostname data without decrypting anything. That varies by country and by preference.

4 min read

Illustration of a house and a shield with a check mark, joined by a dashed tunnel line on a dark grid.

On a home network the classic arguments for a VPN mostly do not apply. Your network is not shared with strangers, your traffic is encrypted by default, and nobody is sitting between you and your router.

What remains is one thing, and whether it matters is a genuine judgement rather than a technical question.

What your ISP can see without a VPN

Every domain you resolve, unless your DNS is encrypted.

Every hostname you connect to, from the Server Name Indication field in each TLS handshake, which is sent in the clear unless Encrypted Client Hello is in use.

When, and how much data moved.

That is a complete, timestamped list of the sites you visit, obtainable without decrypting anything. It is small, cheap to store, and describes a great deal about a household.

What it cannot see

Contents. Everything above is metadata, and the pages themselves are encrypted.

Whether that matters depends on where you are

Jurisdictions with retention mandates. Where providers are legally required to retain connection records for a period, the list exists whether the provider wants it or not, and it is available to whoever the law says.

Jurisdictions where ISPs may monetise browsing data. Some permit it, sometimes with an opt-out most customers never see.

Jurisdictions with neither. The list may still be generated for operational reasons and kept for an unstated period.

Knowing which of these applies where you live is more informative than any general argument about whether a home VPN is worthwhile.

The cheaper alternative that covers most of it

Encrypted DNS closes the largest half of the leak and costs nothing. DNS over HTTPS or DNS over TLS, configured in the browser, the operating system or the router, stops your provider seeing your lookups.

It does not close the hostname leak in TLS handshakes, which remains until Encrypted Client Hello is widely deployed. So it is most of the benefit for none of the throughput cost, which makes it the right first step for anyone unsure whether a home tunnel is worth it.

What a home VPN costs

Ten to thirty percent of throughput on a nearby server, some latency, and occasional friction with services that block datacentre addresses — banking apps, streaming, and anything with strict geolocation.

That friction is the real reason most people who try a permanent home tunnel end up turning it off. It is not the speed; it is having to disable it to log into something.

Reasonable positions

Always on. If the destination list is something you would rather your provider not compile, and you accept the friction. Split tunnelling for the handful of services that object.

On for specific things. A tunnel for the traffic you care about and direct for everything else.

Off at home, on when out. The most common arrangement, and defensible: the threat model genuinely differs between a home network and a café.

Encrypted DNS only. Most of the privacy benefit, none of the cost.

What it will not do at home

It will not stop tracking, which is done with cookies, accounts and browser fingerprinting rather than with your address. It will not protect a device from malware. And it will not make you anonymous to anything you sign into.

If those are the goals, a tunnel is the wrong tool and the right tools are a content blocker, keeping software updated, and separating accounts.

Whatever you choose, verify it does what you think with the DNS leak test — an encrypted DNS setting that is not actually in effect is a common and invisible outcome. And read what your provider retains in its own privacy policy, because a home tunnel moves the list from one company to another rather than deleting it.

The household argument

One consideration that does not apply to a phone: a home connection is shared, and the destination list your provider builds is the household's rather than yours. It mixes everyone in the house together, which makes it less precise about any individual and more revealing about the family.

Whether that cuts for or against a tunnel depends on how you feel about it. Some people find the aggregation reassuring; others find a single list covering children, partners and guests worse rather than better.

Torrenting, briefly

The most common concrete reason people run a home VPN is peer-to-peer file sharing, where your address is visible to every other peer in the swarm and is routinely collected by monitoring firms acting for rights holders.

That is a real and specific exposure that a tunnel removes, and it is worth saying plainly that removing it does not change the legality of what is being shared. It changes who can see the address doing it.

What to do if you are undecided

Turn on encrypted DNS today, which takes two minutes and costs nothing. Live with it for a month. If the remaining hostname exposure still bothers you, add a tunnel then, with split tunnelling for the services that object.

That sequence gets most of the benefit immediately and defers the friction until you have decided it is worth accepting.

Sources

  1. RFC 8484 — DNS Queries over HTTPS
  2. Investigatory Powers Act 2016
  3. RFC 6797 — HTTP Strict Transport Security

Try it on the network this was written from

VPNmine is a free no-logs VPN running its own WireGuard servers, with native apps for Windows, macOS, Android, iOS, Android TV and Apple TV. No ads, no card.

Get VPNmine