VPN guides throw around a lot of terms that nobody ever really stops to explain, on this site included. This page is that stop. Every term here is written for someone who has never touched a VPN before, not for someone who already knows the difference between a protocol and a proxy. If you hit a word anywhere on this site that isn't making sense, this is the page to come back to.
The absolute basics
VPN (Virtual Private Network)
Software that does two things: it hides your real IP address by routing your internet traffic through one of its own servers, and it encrypts that traffic so nobody in between can see what you're doing online. "Virtual" because there's no physical wire, it's all done in software over the ordinary internet. "Private" because your traffic is scrambled so nobody else on the path can read it. Our full what is a VPN guide goes into this in more depth.
IP address
A number your internet provider assigns to your connection. Every device that goes online gets one, and websites use it to work out roughly where you are, sometimes down to city level. Think of it like a return address on an envelope. A VPN gives you a different one, borrowed from wherever its server is, which is why it's the standard fix for a service that's only available in a certain country.
VPN server
A computer, run by your VPN provider, that your traffic passes through on its way to the internet. When you "connect to a UK server," you're picking which of the VPN company's computers your traffic routes through, and that server's location is what websites see as your location.
ISP (internet service provider)
The company that actually gets you online at home, such as BT, Sky, Virgin Media, or Vodafone. Without a VPN, your ISP can see every website you visit, even if they can't read the content of encrypted pages. A VPN hides that from them by routing your traffic through its own servers instead.
How your VPN connects
Protocol
The method your VPN uses to package and send your data. Different protocols are faster or slower, and easier or harder for networks to detect and block, but you don't need to understand how any of them work to use one. Just think of them as different routes to the same destination. Our protocol switching guide covers when and how to change yours.
WireGuard
The newest and generally fastest protocol, and the one most VPN apps use by default now. It's also lighter on battery life if you're on mobile.
OpenVPN
An older, well-established protocol. Slower than WireGuard but very reliable, and its TCP version (see below) is often the best option on networks that block other types of VPN traffic.
IKEv2
A protocol that's particularly good at handling network changes without dropping the connection, which is why it's often recommended on mobile, where you're regularly switching between wi-fi and mobile data.
Lightway / NordLynx
Not separate protocols in their own right, these are just ExpressVPN's and NordVPN's own branded versions of WireGuard. If you see either name in your app's settings, it's doing the same job WireGuard does elsewhere.
TCP vs UDP
Two different ways your VPN can send data. TCP double-checks every bit of data arrived correctly, which makes it more reliable but slightly slower. UDP doesn't bother double-checking, which makes it faster but very slightly less reliable, and it's what most VPNs use by default for that reason. On a restricted network, TCP is often the one that gets through when UDP is blocked.
Port (and port 443)
A number that helps route a specific type of internet traffic to the right place, a bit like a numbered gate at an airport. Port 443 is the one all normal HTTPS websites use, so almost every network leaves it open, even ones that block VPNs. That's why "OpenVPN over port 443" is such a common suggestion on locked-down networks: it makes your VPN traffic look like ordinary web browsing.
Obfuscation / obfuscated servers
A mode some VPNs offer that disguises your VPN traffic so it doesn't look like VPN traffic at all, even to networks specifically trying to detect and block it. Worth trying on school, work, or hotel networks that block standard VPN connections.
Smart DNS
A lighter alternative to a full VPN that only reroutes the part of your connection that reveals your location, without encrypting everything else. It's faster than a full VPN and works on devices that can't run a VPN app, like most smart TVs, but it doesn't give you the privacy or security benefits of full encryption.
Router-level VPN
Installing your VPN on your home router instead of (or as well as) on individual devices. Every device connected to that router, including smart TVs and consoles that can't run their own VPN app, gets covered automatically.
Privacy and security
Encryption
Scrambling data so only someone with the right key can read it. Once you're connected to a VPN, everything leaving your device is scrambled before it goes anywhere, so anyone intercepting it, whether that's someone on the same public wi-fi or your ISP, sees only meaningless data.
HTTPS
The padlock-icon version of a website address, the "S" stands for "secure." It means the connection between your device and that specific website is already encrypted, separately from anything a VPN does. It's why online banking is reasonably safe even without a VPN, though a VPN still adds protection on networks you don't trust, like hotel wi-fi.
No-logs policy
A VPN provider's claim that it doesn't record what you do while connected. The claim alone is just marketing copy; what actually matters is whether it's been checked by an independent security firm and the results published, which is what "audited no-logs policy" means.
Kill switch
A safety net that cuts your internet completely if your VPN connection drops, rather than quietly letting your real IP address show through while it reconnects. Most VPN apps have this as a toggle in settings. Our kill switch guide covers it in full.
DNS leak
DNS is the system that translates a website name you type into the actual address your device needs to find it, a bit like a phone book. A DNS leak happens when those lookup requests slip outside your VPN's protection and go straight to your ISP instead, which can reveal your real location even while your IP address looks fine. See our DNS leak guide for the fix.
IPv6
A newer version of the IP address system (the older, more common version is IPv4). Some VPNs only fully protect IPv4 traffic, which means a device that also has an IPv6 address can occasionally leak your real location through it even when your VPN looks connected. "IPv6 leak protection," a setting in most VPN apps, closes this gap.
Split tunnelling
A setting that lets you choose which apps go through the VPN and which connect directly. Handy if you want your browser protected but a specific game or app running at full speed without the VPN's added delay.
Dedicated IP / residential IP
A dedicated IP is an address used only by you, rather than shared with thousands of other VPN users, which makes it far less likely to already be flagged by a streaming service. A residential IP goes further, routing through what looks like an ordinary home broadband connection rather than a data centre, which is even harder for detection systems to spot.
Threat Protection / Threat Manager
Add-on features some VPN apps include (NordVPN calls its version Threat Protection, ExpressVPN calls its Threat Manager) that block ads, trackers, and known malicious sites at the network level. Useful, but not a substitute for proper antivirus software.
Five Eyes / Nine Eyes / Fourteen Eyes
Informal names for groups of countries that share intelligence with each other, based on old surveillance-sharing agreements. Five Eyes is the US, UK, Canada, Australia, and New Zealand; Nine and Fourteen Eyes add further European countries to that list. Some VPN providers deliberately base themselves outside these alliances and market that as a privacy advantage, on the theory that a government request for user data is less likely to succeed, or less likely to happen at all, if the provider isn't under one of those countries' legal systems.
It's a genuine consideration for people with serious privacy needs, but for the average reader using a VPN to unblock a streaming service, it matters a lot less than whether the provider actually keeps a no-logs policy in the first place, since a "clean" jurisdiction can't protect you if the VPN is logging your activity anyway.
Double VPN / multi-hop
A mode that routes your traffic through two VPN servers instead of one, encrypting it twice along the way. It adds a genuine extra layer of privacy since no single server ever sees both your real IP address and your destination at the same time, but it also roughly doubles the distance your traffic has to travel, which means a real, noticeable speed hit. Worth knowing about, but it's a niche option built for people with specific privacy needs rather than something you'd want switched on for everyday streaming.
VPN app vs browser extension
A full VPN app protects everything on your device, every app and every browser. A browser extension only protects traffic inside that one browser, so a streaming app, a game, or a second browser would all still show your real location. Extensions are fine for quick browser-only tasks, but a full app is what you want for anything else.
Getting blocked, and getting around it
Geo-blocking / geo-restriction
When a service only works in certain countries and checks your IP address to enforce it. BBC iPlayer being UK-only is a geo-block. A VPN gets around this by giving you an IP address from a country where the service is allowed.
CAPTCHA
The "click all the traffic lights" or "I'm not a robot" puzzle websites use to check you're a real person rather than automated software. Some sites show one when they see an unusual IP address, including VPN IPs, as a fraud check rather than an actual block. Completing it usually clears you straight through.
MFA / 2FA (multi-factor authentication / two-factor authentication)
An extra login step beyond your password, usually a code sent to your phone or an app, used to confirm it's really you signing in. Services sometimes trigger this more often when you connect from a VPN, since a new IP address looks similar to a stolen-password sign-in attempt.
Conditional access
A workplace or school security setting that only allows sign-ins from approved networks, devices, or countries. If your personal VPN is being blocked from a work account, this is very often what's happening, and no amount of VPN troubleshooting on your end will get around a policy your employer's IT team has deliberately set up.
Deep packet inspection (DPI)
A technique some networks, particularly at universities and workplaces, use to examine the structure of your traffic and identify VPN connections by their pattern, even when they're using an unusual port. Obfuscated or "stealth" protocols are specifically designed to get past this.
P2P / torrenting
P2P (peer-to-peer) means downloading a file in pieces directly from other users' devices, rather than from one central server. Torrenting is the most common form of this. Some VPN servers are optimised for it, and streaming services tend to flag P2P-labelled server IPs more readily, since that traffic pattern is easy to spot.
WebRTC
A feature built into Chrome, Firefox, and Edge that powers real-time browser features like video calls. It can also leak your real IP address to a website even while your VPN is connected and everything otherwise looks fine, because it works slightly outside the normal traffic path a VPN protects. Switching to a streaming service's dedicated app instead of using it in a browser usually sidesteps this entirely.
Proxy
A lighter-weight tool that changes the IP address a single app or browser shows to websites, but typically doesn't encrypt your traffic the way a VPN does. Faster, but offers much less privacy, and generally only worth using for a single narrow task.
Tor
Short for The Onion Router. Routes your traffic through several volunteer-run servers with layers of encryption, making it the strongest option for anonymity, but considerably slower than a VPN, which makes it impractical for streaming.


