Surok

Can my ISP see which sites I visit: without a VPN, with a VPN, with DoH

What exactly your internet provider knows about the sites you visit in 2026: DNS, SNI, addresses. What a VPN hides, what encrypted DNS hides, and where traces remain regardless.

·3 min read·11 viewsBasicsPrivacy

Short answer: yes, your ISP can see which sites you visit, even over HTTPS. Not the page contents, but the site names, almost always. Here is where that comes from, and what a VPN closes.

What is visible without a VPN

DNS queries. Before opening a site, your phone asks a DNS server for its address. By default that server belongs to the ISP, and it records every query: time, your address, the site name. This is the most detailed source.

SNI in HTTPS. Even with encrypted DNS, when a secure connection is set up the browser sends the site name in plain text so the server can pick the right certificate. Equipment at the ISP's border reads this field; that is exactly how blocking works.

IP addresses. The server's address is always visible. For big sites the address identifies the site; for small ones behind a CDN it only says "Cloudflare".

Volume and timing. How much traffic, when, how regularly. This alone tells whether you watch video or sit in a messenger, without knowing any addresses.

What encrypted DNS closes

DNS over HTTPS or DNS over TLS hides the first item: the ISP doesn't see the DNS queries. But SNI and addresses remain, so it still learns the site name at connection time. In Russia popular encrypted DNS services also get blocked periodically, and the phone silently falls back to the ISP's resolver. Useful, not a solution.

What a VPN closes

With a VPN the ISP sees one connection to one address and a stream of encrypted data inside. DNS queries, SNI, site addresses, per-site volume: all of it moves inside the tunnel. What remains: the VPN server's address, total volume and timing. That is why a VPN, not DNS, answers the question in the title.

One condition: the tunnel must be disguised, otherwise the ISP doesn't see "which sites" but "this person uses a VPN", and that ends with a block. With Surok the connection looks like ordinary HTTPS to a domestic server, and the ISP loses interest there.

Where traces remain anyway

  • On the sites themselves. Google, social networks, marketplaces know who you are by your account, not your address. A VPN doesn't make you anonymous to a service you signed into.
  • At the VPN service. It sees what the ISP used to see. So "what logs does the VPN keep" is the main question. Surok doesn't record where you go: we store your email or Telegram, plan dates and technical device data. Traffic destinations are not written down.
  • In the browser. History, cookies, autofill. Nothing to do with the ISP, everything to do with "who knows where I've been".
  • Leaks. If the VPN app dropped and the phone kept working, traffic went direct. See our kill switch article.

How to check yourself

Open our "My IP" page without a VPN and with it. Without it you'll see your ISP and city, with it the exit country. The page also shows which DNS server answers your queries: if with the VPN on it is still your ISP's DNS, site names leak around the tunnel and that needs fixing.

In short

The ISP sees site names via DNS and SNI, and addresses always. Encrypted DNS closes only DNS. A VPN closes everything except the fact of connecting to a VPN server, and only if the tunnel is disguised. Traces remain at sites you signed into and at the VPN service itself, so the logging policy matters more than the country list.

Try Surok
3 days free, no card needed. Apps for everything.

More to read