To hide your IP address from a website, your traffic has to reach the website through something else. The website then sees that address instead of yours. A proxy, a VPN, Tor, iCloud Private Relay or another network all work this way. None of them hides your address from everyone. The service in the middle sees it, your network provider still knows it, and your browser can give it away on the side.
This guide shows how to use each method, who still sees what, and four leaks we measured on 11 October 2026.
Which method hides your IP from whom?
| Method | What websites see | Who still sees your real address | What your network provider sees |
|---|---|---|---|
| Proxy | The proxy's address | The proxy operator | Your connection to the proxy, and with a plain HTTP proxy the names of the sites |
| VPN | The VPN server's address | The VPN provider | Encrypted traffic to the VPN server |
| Tor | The address of a Tor exit relay | The first Tor relay | That you use Tor |
| iCloud Private Relay | A temporary address | Your network provider and Apple's first relay | Traffic to Apple's relay, not the sites |
| Another network | That network's address | The mobile carrier or the Wi-Fi operator | It is now your network provider |
The deeper trade-offs between the first three are in proxy vs VPN vs Tor. Here we stay with the practical side.
1. Use a proxy
A proxy forwards your requests, so the website sees the proxy's address. On Windows 11, Microsoft puts the switch here: "In the Settings app on your Windows device select Network & internet > Proxy." Under Manual proxy setup, choose Use a proxy server and enter its address and port. A tool like curl takes the proxy directly, with -x.
The proxy is the one place that sees everything. The Tor Project puts it bluntly: "The provider knows both who you are and what you browse on the Internet."
There is a second catch with plain HTTP proxies. For an HTTPS site, your browser first asks the proxy to open a tunnel, with a CONNECT request. RFC 9110 defines it as a request to "establish a tunnel to the destination origin server". That request travels before any encryption starts. We sent requests through five working free proxies from our own list, and all five received the site's name in clear text:

So anyone between you and such a proxy, including your network provider, can read which sites you open. They cannot read the pages themselves. The website saw the proxy's address three times and a different exit twice, and never ours.
2. Use a VPN
A VPN works below the browser. It encrypts whole IP packets and sends them to its server. WireGuard, one of the common VPN protocols, describes the step as "Encrypt entire IP packet" with the key of the other side. Your network provider sees encrypted traffic going to one server. The websites see that server's address.
The VPN provider takes the place the proxy had: it sees your address and where your traffic goes. A VPN does not hide your address from your network provider either, because the provider gave it to you.
3. Use Tor
Tor sends your traffic through three relays. The first one sees your address but not where you go. In the Tor Project's words, a bad first relay "merely sees 'This IP address is using Tor'". The website sees the address of the last relay, the exit.
That makes Tor stronger than one proxy, because no single relay knows both ends. Your network provider can still tell that you use Tor. The Tor Project offers bridges to people who are "worried somebody will recognize that they are contacting a public Tor relay IP address".
4. Turn on iCloud Private Relay on an iPhone or Mac
Apple's Private Relay covers browsing in Safari. On an iPhone, Apple's steps are: "go to Settings > [your name] > iCloud. Tap Private Relay, then turn on Private Relay."
It uses two relays. Apple describes who sees what: "Your IP address is visible to your network provider and to the first relay, which is operated by Apple." The second relay, run by another company, "generates a temporary IP address" and connects you to the site.
Private Relay comes with an iCloud+ subscription and is not available in every country. Apple lists what it protects: "web browsing in Safari, DNS resolution queries, and insecure http app traffic". Other browsers and encrypted app traffic go out as before.
5. Switch to another network
The quickest change is a different connection. On mobile data, websites see your carrier's address instead of your home address. A carrier can put many customers behind one address. RFC 6598 even reserves a block of addresses "to accommodate the needs of Carrier-Grade NAT (CGN) devices", the systems that do this. A café's Wi-Fi works the same way: websites see the café's address.
This hides your home address from websites, not your identity from the network. The carrier or the Wi-Fi operator knows which device used the connection.
What still gives your real IP away?
Four things can undo the methods above. We tested each of them.
WebRTC. Browsers use WebRTC for calls and video, and it asks a STUN server for your public address. RFC 8828 warns that "WebRTC's STUN checks will bypass the proxy and reveal the public IP address of the client". With an HTTP proxy set in Chrome, the website saw the proxy, while WebRTC still found our real address. Chrome's WebRTC policy, set to disable_non_proxied_udp, stopped it. How to set it, and which way failed in our tests, is in BrowserScan explained.
DNS lookups. Before a connection, the name of the site has to be turned into an address. With a SOCKS5 proxy, curl's --socks5 will "resolve the hostname locally", on your machine. Its --socks5-hostname lets "the proxy resolve the hostname". Our test showed exactly that: "locally resolved" in the first case, "remotely resolved" in the second. A local lookup tells your own DNS resolver which site you open.
Forwarding headers. A proxy may add your address to the request it forwards. RFC 7239 defines a header whose "for" parameter is used "to disclose information about the client that initiated the request". Through 1 of 12 working free HTTP proxies, our own address reached the website this way.
Private browsing. Incognito mode is not one of the methods. Google's help page is clear: "While Incognito can help keep your browsing private on your device, it doesn't make you invisible."
How do you check that it worked?
Test before you trust a setup. Open our proxy IP checker with the method switched off, then on. It shows the address and the network that websites see. Then run the WebRTC leak test. It shows whether your browser still sends your real address. The proxy leak test shows what a proxy passes on.
If you need a proxy exit in a chosen country, our residential proxies let you pick it.
What this page could not check
- We measured free proxies from our own list only: 12 HTTP proxies for headers, 5 for the CONNECT test and one SOCKS5 proxy for DNS. Paid proxies were not part of the test.
- We did not measure a VPN, Tor or iCloud Private Relay. Those sections rest on their makers' own documentation.
- The WebRTC tests ran in headless Chrome on a Linux server, in two builds.
- The DNS test shows who looks up the name, not what a resolver keeps.
- Each test ran once, on one morning, and free proxies change within hours. We will run them again by 11 January 2027.
Sources
- RFC 9110, HTTP Semantics, the CONNECT method, IETF, June 2022: rfc-editor.org.
- RFC 7239, Forwarded HTTP Extension, IETF, June 2014: rfc-editor.org.
- RFC 8828, WebRTC IP Address Handling Requirements, IETF, January 2021: rfc-editor.org.
- RFC 6598, Shared Address Space for Carrier-Grade NAT, IETF, April 2012: rfc-editor.org.
- curl, man page, --socks5 and --socks5-hostname, read 11 October 2026: curl.se.
- The Tor Project, How is Tor different from other proxies, read 11 October 2026: support.torproject.org.
- Apple, About iCloud Private Relay, read 11 October 2026: support.apple.com.
- Apple, Set up iCloud Private Relay on all your devices, read 11 October 2026: support.apple.com.
- Apple Developer, Prepare your network or web server for iCloud Private Relay, read 11 October 2026: developer.apple.com.
- The Tor Project, Types of relays on the Tor network, read 11 October 2026: community.torproject.org.
- Microsoft, Use a proxy server in Windows, read 11 October 2026: support.microsoft.com.
- WireGuard, overview, read 11 October 2026: wireguard.com.
- Google Chrome Help, Browse in Incognito mode, read 11 October 2026: support.google.com.
- Our own tests on our server, 11 October 2026: forwarding headers and SOCKS5 name lookups at 01:35 UTC, WebRTC in Chrome 143 at 01:38 UTC and in our BrowserScan and CreepJS runs, the CONNECT test at 07:11 UTC.



