Your ISP Cannot See Where You Went. It Can See That You Used Tor.
Written with AI assistance and reviewed by the NorwegianSpark SA editorial team.
Affiliate disclosure: This article contains affiliate links. If you click a link and buy a subscription, we may earn a commission at no cost to you. Our editorial recommendations are never influenced by commissions — read the full disclosure.
People install Tor expecting invisibility and get something more specific and more useful: strong protection of where you go, and almost none of the fact that you went. That is not a flaw or a compromise — it is documented behaviour that the Tor Project states plainly, and the gap between it and what users assume is where most bad decisions about anonymity are made. This part of the series covers exactly what an observer on your network can and cannot determine, in the project's own words, and what actually changes it.
What the Tor Project Says, In Its Own Words
The clearest statement of this comes from the Tor Project's own support documentation, and it is worth quoting rather than paraphrasing: 'Tor tries to prevent attackers from learning what destination websites you connect to. However, by default, it does not prevent somebody watching your Internet traffic from learning that you're using Tor.' Read that twice, because it is the whole article in one sentence. Your internet provider, or anyone else positioned to watch your connection, generally cannot tell which sites you visited. They can very often tell that your traffic entered the Tor network, because the entry points are publicly listed by design and the traffic has recognisable characteristics. Two further statements from the same source set the boundaries: 'Tor does not protect all of your computer's Internet traffic when you run it. Tor only protects applications that are properly configured to send their Internet traffic through Tor.' And, bluntly: 'Generally it is impossible to have perfect anonymity, even with Tor.'
Why That Distinction Matters More Than It Sounds
In most of the world, an internet provider knowing that you used Tor is of no consequence — it is lawful software and the observation goes nowhere. The distinction becomes significant in two situations. The first is a country that treats the use of anonymity tools as suspicious or unlawful, where the observable fact of connecting is itself the risk, entirely separately from anything you did. The second is any situation where the pattern matters rather than the content: a journalist whose provider records that they began using Tor on a particular date, a researcher whose employer monitors the corporate network. In both, the protection you needed was of your participation, and that is the one thing Tor does not offer by default. Recognising which of the two things you actually need to hide is the decision that should drive your setup, and it is why VPN vs proxy vs Tor is a real question rather than a matter of picking the strongest-sounding option.
What a VPN Changes, and What It Does Not
Routing Tor through a VPN moves the observation rather than removing it. Your internet provider then sees an encrypted connection to a VPN server and not a connection to a Tor entry point; the VPN operator, however, sees that you connected to Tor. You have not eliminated the observer — you have chosen a different one, and the entire value of the change rests on whether that operator keeps records, and what it would do if asked for them. That is a judgement about a company and its jurisdiction, not about cryptography, which is why independently audited no-logs claims matter far more here than any feature list. It is also worth being clear about what the combination does not do: it does not make you anonymous to a site you log into, it does not protect traffic from applications not configured to use Tor, and it does not repair a mistake you make at the destination.
The Leaks That Are Not About the Network at All
The Tor Project's warning that it 'only protects applications that are properly configured' is the practical trap. Tor Browser routes its own traffic; another browser open at the same time does not. A document downloaded through Tor and then opened in an ordinary application can fetch remote content directly, outside Tor, announcing your real address at the moment you open it. A messaging client, an update checker or a cloud-sync agent running in the background continues talking to the internet normally throughout. None of these are failures of Tor and none are exotic — they are the ordinary behaviour of a computer that is doing other things. This is why the safety advice in how to access the dark web safely is mostly about what else is running and what you do with what you download, rather than about the browser itself.
A Realistic Mental Model
The accurate way to hold this is that Tor gives you very strong unlinkability between you and your destination, and says almost nothing about whether your participation is observable. If your concern is that a website should not learn who you are, or that your provider should not build a profile of what you read, Tor addresses it directly and well. If your concern is that nobody should be able to tell you used it, Tor alone does not address that, and you need either a bridge with a pluggable transport — the subject of what bridges actually do — or a preceding hop you trust more than your provider. Being precise about which of those you need is not pedantry. It is the difference between a setup that matches your situation and one that merely feels secure, and the Tor Project's own documentation is unusually honest that the second is not good enough.
Frequently Asked Questions
Can my ISP see that I am using Tor?
Usually yes. The Tor Project states that 'by default, it does not prevent somebody watching your Internet traffic from learning that you're using Tor.' Its main entry points are publicly listed by design, which makes the connection recognisable.
Can my ISP see which sites I visit on Tor?
Generally no. The Tor Project describes the network as preventing attackers 'from learning what destination websites you connect to.' Your destination is the thing Tor protects well; your participation is not.
Does a VPN hide that I am using Tor?
It moves the observation rather than removing it. Your ISP sees a connection to the VPN instead of to Tor, while the VPN operator sees the Tor connection. The value depends entirely on whether that operator keeps logs and what jurisdiction it answers to.
Does Tor protect everything on my computer?
No. In the Tor Project's words, 'Tor only protects applications that are properly configured to send their Internet traffic through Tor.' Other browsers, background apps and files opened outside Tor Browser can connect directly and expose your real address.
Is Tor completely anonymous?
No, and the Tor Project says so: 'Generally it is impossible to have perfect anonymity, even with Tor.' It is a strong tool against specific threats, not a guarantee against all of them.
VPNTex is published by NorwegianSpark SA (Org no: 834 984 172). We may earn commissions on qualifying purchases via affiliate links. This does not affect our editorial independence. Full disclosure · Privacy policy