Skip to content
Skip to main content
IP Addresses & Networks Technical Explainer

What does a VPN do to the IP address a service sees?

A virtual private network (VPN) places a VPN server between the user’s device and the online service. For traffic sent through it, the service normally records the VPN server’s public IP address rather than the user’s home, workplace or mobile address.

The short version

A VPN changes the address visible to the destination. The recorded IP may identify the VPN service or its hosting provider, while other records may still lead back to the account, device or user.

Follow one event through the VPN

Dave edits a project note in the fictional Northstar Files service while connected to a VPN. His laptop first connects to the VPN service. The VPN then makes a separate onward connection to Northstar Files.

Earlier connectionDave's device → VPN serviceThe VPN can observe a connection arriving from Dave's network.
IntermediaryVPN serverThe server receives the tunnelled traffic and makes the onward connection.
Destination viewVPN exit → Northstar FilesThe service normally records the VPN exit IP for Dave's event.

The encrypted VPN tunnel protects traffic between Dave's device and the VPN service. The public address used for the onward connection is often called the exit IP address. That is normally the address recorded at the destination's observation point.

The two sides can create different records:

Record holder What its record may connect
Northstar Files Account, session or document event to the VPN exit IP and time
VPN service An incoming customer connection or account to an outgoing VPN session, if that detail was recorded and retained
Dave's network or device The earlier connection to the VPN service and related local activity, where suitable records exist

Joining those records may reconnect the two sides. The existence, precision and availability of each record must be established; the diagram does not imply that every VPN keeps connection logs.

What changes for the investigation

The exit address may:

  • be shared by many VPN customers;
  • appear to be in a different country from the user;
  • belong publicly to a data centre rather than the named VPN service; and
  • change between sessions or VPN locations.

An IP geolocation result may therefore describe the VPN server, not the user’s physical location. Repeated activity from one exit address may also involve several unrelated customers.

What evidence may still exist

The destination service may hold useful account, session, device, cookie, payment and activity records. The VPN provider may hold account details and, depending on how it operates, records connecting an incoming customer address with an outgoing session.

A useful destination record might preserve:

event_id=DOC-20481
time=2026-09-06T19:14:22.418Z
source_ip=203.0.113.44
source_port=53128
account=nsf-4471
action=document_updated

The event links an account action to the VPN exit connection seen by Northstar Files. It does not identify the earlier connection or the person operating the account.

Not all device traffic necessarily uses the VPN. Split-tunnelling, application settings or a dropped VPN connection can leave other traffic using the ordinary internet connection.

What to do next

If the visible address appears to be a VPN:

  1. preserve the complete event, including the exact time, time zone, IP address, ports and session identifiers;
  2. identify the likely VPN service and the legal entity operating it;
  3. establish what account or connection records may exist; and
  4. continue with the platform’s other account and device evidence.

The practical question is not simply “Who owns this IP?” It is:

Which records can connect this destination event to the VPN session, earlier connection, account, device or user?

Explore related guidance
Reference: IP-059IP Addresses & Networks