SecuFocus
VPNGetting started & analysis

Mullvad: what your VPN hides, and from whom

IP addresses, internet providers, signed-in accounts and dropped connections: choose a VPN around its actual role.

Before you get started

What to expect

Mullvad routes supported traffic through a tunnel to its servers, so websites see its exit address. This shifts part of your trust to the VPN provider. It does not remove signed-in accounts or other ways of recognising you.

What do you want to use Mullvad for?

Mullvad may suit you if you want to hide your home IP address from sites or limit what the network you are using can observe. Reaching a server at home is a separate need, requiring a tunnel to your own network.

Mullvad is a commercial VPN: its application creates a tunnel to the provider’s infrastructure. That is worth evaluating for the first two needs. The third requires a connection into your own network, which an exit VPN subscription does not organise by itself.

For example, you can check whether the IP address visible to a site changes when you connect. That tells you about the route taken by the traffic you checked; it does not establish that all your activity is anonymous.

Who can still see what?

The tunnel protects the path to the VPN server. Beyond that, application protections such as HTTPS still matter. The VPN provider becomes a trusted intermediary; do not mentally remove it from the diagram.

This table describes ordinary use with traffic actually handled by the VPN. Excluded applications, particular protocols and operating-system differences can affect the outcome.

Scroll the table sideways to read every column.

ObserverWhat the tunnel changesWhat remains
Local network and internet providerTunnelled traffic goes to the VPNThe connection’s existence, volume and timing
WebsiteIt receives the VPN exit IP addressYour signed-in account and submitted data
VPN providerIt is on the traffic’s pathThe need to examine and trust its policy
Person looking at the screenThe network route changesVisible pages and notifications

An account without an email address

Mullvad uses an account number without requiring an email address to register. The provider states that it does not retain VPN activity logs. Its policy separately discusses data involved in payments and support exchanges.

These are documented provider commitments, not an audit performed by SecuFocus. Keep the account number somewhere reliable and consider what your payment method discloses for your particular needs. Minimal registration does not automatically make every other interaction anonymous.

Check a disconnection and a wake from sleep

Do not stop the evaluation after opening a page and pressing Connect. The revealing moments often involve a network change, waking a laptop or a dropped tunnel. Observe these with ordinary activities, never with a sensitive action supposedly serving as a test.

  1. Install the official application for your system and read its documented platform limitations.
  2. Choose a server, check connection status and observe the exit address through the provider’s checking tool.
  3. Try what matters to you: video calls, browsing, printer access and everyday services. Record incompatibilities instead of claiming a universal speed result.
  4. Examine a Wi-Fi interruption, return from sleep and intentional VPN disconnection. They are not all governed by the same setting.
  5. Decide which exceptions are necessary and keep a list. An application excluded from the tunnel takes a different path.

Kill switch and Lockdown differ when you disconnect

The application documentation describes the kill switch as protecting against events such as an unexpected tunnel interruption. Lockdown also covers intentional disconnection and quitting the application. Applications excluded through split tunnelling are an exception to consider.

Choose the behaviour deliberately. If your priority is to avoid continuing an ordinary session outside the tunnel, learn to recognise and resolve a blocked connection. Otherwise you may disable the feature in a hurry just when it is doing its job.

DAITA and multihop: purpose and trade-offs

DAITA aims to make encrypted traffic patterns harder to analyse, including through packet transformations and additional traffic. This addresses a more specific threat than merely changing an IP address.

For advanced use, weigh the benefit against the data consumption, battery use or latency you can accept. A limited mobile connection and a permanently powered desktop have different constraints. Options vary between applications and evolve; read their description on your actual device.

Protection you still need outside the VPN

If you reuse one password everywhere, have no recovery path for email or use a computer that no longer receives updates, a tunnel does not fix those problems. Start with your accounts and device.

A social network you are signed in to still knows your account when your IP address changes. Keep that limit in mind when evaluating Mullvad: the tunnel changes the network route, while your accounts and the data sent to sites still need separate attention.

From the provider

Mullvad

Downloads, compatibility and current terms.

Official website

Check and explore

Sources for this article

Numbers connect each reference to the passages that use it. Dates show when the documentation was consulted.

This article draws on the sources above. The exercises are for you to try on your devices; SecuFocus does not present them as tests carried out by its editorial team. Interfaces and features can change. Method and corrections.

Cite this article

Keep this reference with the article when you save or share it.