How to choose a VPN in 2026: an honest checklist
The question of how to choose a VPN usually drowns in marketing: every service calls itself the fastest and most secure. In reality the decision comes down to a handful of clear criteria you can check with your own hands instead of taking anyone’s word. Below is a practical buyer’s checklist: what to look at, what trade-offs exist, and how to test a service yourself before you pay.
No-logs policy
The main reason people buy a VPN is so their traffic isn’t stored or handed to third parties. So the first item in any breakdown of how to choose a VPN is the logging policy.
Be honest with yourself about one thing: “no-logs” is mostly a promise. You can rarely prove a server writes nothing. But some indirect signs are worth a little more trust:
- A clear, plain-language policy stating exactly what isn’t kept (traffic, DNS queries, connection history).
- A jurisdiction without mandatory surveillance (more on that below).
- Independent audits — a plus when they exist, but their absence isn’t a dealbreaker for smaller services.
A concrete example of how to read a policy: look for the gap between “we keep no activity logs” and “we keep nothing at all.” Plenty of services don’t record your browsing history but do log connection timestamps, bandwidth used, and your device — that still counts as logging. If a policy vaguely says it “may collect data to improve the service,” assume logs exist.
GANVAS VPN keeps no traffic logs. That doesn’t make you invisible — the real limits of anonymity are covered honestly in can you be tracked with a VPN.
Modern protocols
The protocol is the “engine” of a VPN: it decides how your traffic is encrypted and carried. It drives speed and whether your connection survives filtering.
- WireGuard — fast and lightweight, a good default for ordinary networks.
- VLESS+Reality — for networks with active blocking: it disguises itself as an ordinary HTTPS visit to a popular site, so DPI doesn’t flag it as a VPN.
Avoid legacy protocols like PPTP entirely. For a full comparison, see VPN protocols compared. GANVAS supports WireGuard and VLESS (Reality and WS+TLS), so you get both speed and censorship resistance.
A real kill switch
A kill switch cuts your internet if the VPN connection suddenly drops, so your real IP and traffic don’t leak onto the open network during the seconds it takes the tunnel to recover.
It’s worth confirming it actually works rather than just sitting as a toggle in settings. The simplest test:
- Connect to the VPN and open the VPN check page — note the shown IP.
- Without disconnecting, break the connection (drop the server, pull Wi-Fi for a couple of seconds).
- Refresh the page. If your real IP appears, the kill switch didn’t fire.
GANVAS VPN includes a kill switch on desktop. It’s not a marketing checkbox: without one, any tunnel drop exposes you.
DNS and WebRTC leak protection
You can sit “behind a VPN” and still leak. The two most common leaks:
- DNS leak — domain lookups go outside the tunnel, so your provider sees which sites you open.
- WebRTC leak — the browser can reveal your real IP via WebRTC even with the VPN active.
This takes a minute to check: open the WebRTC leak test and inspect DNS with the DNS lookup tool. What a DNS leak is and why it matters is explained in what is a DNS leak. GANVAS has built-in DNS-leak protection, but WebRTC is closed off on the browser side — worth keeping in mind.
Speed
A VPN always slows your connection a little — that’s physics: traffic goes through an extra server and is encrypted. The question is how noticeable it is. Speed depends on the protocol (WireGuard is usually faster), distance to the server, and its load.
Don’t trust marketing numbers — measure yourself. Run the speed test without a VPN, then connected to the nearest server, and compare. A drop of tens of percent is normal; a drop by several times is a reason to switch server or protocol.
Censorship resistance and obfuscation
If you’re on a network with active DPI (state censorship, a corporate or campus filter), an ordinary VPN may simply fail to connect. Here obfuscation decides things — disguising traffic as something “ordinary.”
VLESS+Reality exists for exactly this: to the filtering system the connection looks like a regular HTTPS visit to a major site, not a VPN. GANVAS was built with censorship resistance in mind precisely thanks to Reality. If this scenario matters to you, test the service in the problem network, not at home — that’s the only way to know whether it gets through. More on filtering in bypassing blocks.
Price and “free” tiers
A free VPN also costs money — you just don’t pay directly. Often that means ads, selling anonymized data, or hard caps on traffic and speed. The old rule holds: if the product is free, you’re the product.
That doesn’t mean free is useless. A free tier is a handy way to test a service and cover basics. Just judge soberly what you give in return. Which free options are reasonable is covered in best free VPN.
GANVAS lets you use your own configs free — an honest way to try it without paying if you already have access to a server.
Jurisdiction
Jurisdiction is the country whose laws the service operates under. It determines whether authorities can lawfully demand data and whether the provider must cooperate. Countries in surveillance alliances (5/9/14 Eyes) are generally seen as less private.
Don’t make this your only criterion: jurisdiction matters, but the logging policy and technical implementation matter more. If data isn’t collected, there’s nothing to demand from the service.
Own configs, platforms and ease of use
A few things people often overlook:
- Your own configs. Being able to paste your own VLESS/WireGuard config gives you independence from the vendor’s servers. GANVAS supports this, and for free.
- Platform support. Pick a VPN for the devices you actually use. GANVAS is a desktop app for Windows and a CLI client for Linux; it has no iOS/Android/Mac apps, which is worth weighing honestly. If you specifically need a VPN for Windows, it fits.
- Ease of use and support. A good app picks the protocol for your network so you don’t touch configs. And responsive support matters when something won’t connect at an awkward moment.
How to evaluate a VPN in 10 minutes
Theory is one thing, but the real verdict comes from doing. Here’s a step-by-step ritual that takes about ten minutes and needs nothing but a browser. Run it right after installing — before you start relying on the service for anything that matters.
- Set a baseline. With the VPN off, open the my-ip page and write down your real IP, city, and provider. That’s the reference you’ll compare against.
- Connect and confirm the IP changed. Turn the VPN on, pick the nearest server, and reopen the VPN check. The IP, city, and provider should all switch to the server’s. If you still see your home provider, the tunnel never came up.
- Hunt for leaks. Run the WebRTC test and inspect DNS. Both should show the server’s IP, not yours. A WebRTC leak is especially sneaky: your IP changes on the check page, yet the browser still gives you away through a side channel.
- Measure the speed hit. Run the speed test once without the VPN and once with it, on the same server. That tells you the real price of privacy on your network, not in an ad.
- Test the kill switch. Without closing the app, break the tunnel (pull Wi-Fi for a couple of seconds or drop the server) and refresh the VPN check. If the internet goes dark or you still see the server IP, the kill switch works. If your real IP pops up, it doesn’t.
- Test censorship resistance where it counts. If your goal is to get past state or corporate filtering, test the service in that exact network, not at home — at home everything connects regardless.
If a service fails any step, that’s not a reason to panic — it’s a reason to dig in: switch protocol, switch server, or, as a last resort, switch service.
Common mistakes and red flags
A few things people get burned on most often when choosing:
- Trusting the words “fastest” or “most secure.” That’s marketing, not fact. Any such claim is settled by the ten-minute test above.
- Picking a shady free VPN for privacy. If a service charges you nothing, it earns its money another way — ads, selling anonymized data, analytics. For privacy that’s the worst trade: you hide your traffic from your ISP only to hand it to a stranger. Some have been caught injecting ads or quietly logging.
- Judging on price alone, or jurisdiction alone. A cheap service with no kill switch and active leaks isn’t more private than an expensive one. And a “good” jurisdiction won’t save you if the fine print quietly permits data collection.
- Testing censorship resistance at home. A service that connects beautifully on your couch can stall dead on a network with DPI. Test in real conditions.
- Ignoring WebRTC. Many assume that if the IP changed on the page, all is well. The browser is a separate leak vector, and it isn’t closed by the VPN app.
The biggest red flag is opacity. If you can’t tell who runs the service, where it’s registered, or how the free tier makes money, that’s an answer in itself.
Comparing services against these criteria is easy on the VPN comparison page. And you can refresh the basics — what a VPN is and why you’d want one — in what is a VPN.
FAQ
Should I get a free VPN? For testing and simple tasks, yes. But remember the limits, and that the monetization often runs on your data or ads. For privacy, a paid service with a clear logging policy is better.
How do I check that a VPN isn’t leaking? Connect and run the IP, DNS and WebRTC checks with the tools above. If your real IP or your provider’s DNS shows up, there’s a leak.
Which protocol should I choose? For an ordinary network, WireGuard for speed. For a network with blocking, VLESS+Reality, which disguises itself as ordinary HTTPS.
Does jurisdiction matter? It matters, but not on its own. If a service genuinely keeps no logs, there’s little to demand from it — the technical implementation counts for more than the country flag.