How to choose a VPN: a practical checklist
Most VPN marketing optimizes for fear and big round numbers — thousands of servers, military-grade encryption, lightning speed. Very little of that helps you make a good decision. This guide focuses on the criteria that genuinely separate a trustworthy VPN from a risky one.
1. Logging policy — and proof
Every VPN claims to be 'no-logs.' The claim is meaningless on its own. What matters is whether it has been verified by an independent audit, and ideally whether the provider has been tested in the real world by a legal request or seizure.
Look for providers that publish their audit reports in full — including the problems found — rather than summarizing a clean result. Open-source apps are a strong bonus, because they let researchers verify behavior directly instead of trusting a marketing page.
2. Jurisdiction
Where a VPN is legally based determines what governments can compel it to do. Providers outside the major intelligence-sharing alliances (the Five/Nine/Fourteen Eyes) generally face less pressure to log or share data. Switzerland and Sweden are common examples of privacy-friendly homes.
This matters more for some users than others. A journalist or activist should weigh jurisdiction heavily; someone who just wants to use coffee-shop Wi-Fi safely can treat it as a smaller factor.
3. Protocols and leak protection
Modern VPNs should support WireGuard — it is fast, lean, and easier to audit than older protocols. OpenVPN remains a solid, compatible fallback. For restrictive networks, a stealth or obfuscation mode helps the VPN get through.
Just as important is leak protection: a kill switch that cuts your traffic if the VPN drops, plus protection against DNS, IPv6, and WebRTC leaks. A VPN that leaks your real IP defeats its own purpose, so this is non-negotiable. (We have a separate guide on testing for leaks yourself.)
What doesn't matter as much
Server count is mostly a vanity metric. Beyond a reasonable spread of countries, ten thousand servers do not help you more than a few hundred well-placed ones. 'Military-grade encryption' is marketing — virtually every serious VPN uses AES-256 or ChaCha20, which is the same encryption everyone means by that phrase.
Be skeptical of headline speed claims and lifetime deals. Speeds depend heavily on your own connection and distance to the server, and a VPN selling a one-time lifetime subscription has little incentive to maintain the service long-term.