A VPN changes your IP address. It does not change what your browser tells every website about your device, your installed fonts, your screen size, or the quirks of how your graphics card renders a canvas element. That combination is called browser fingerprinting, and it can identify and track you across sites even when your IP address is masked by a VPN. This is one of the most persistent misunderstandings about what a VPN actually does.

What browser fingerprinting actually collects

Fingerprinting scripts run in the background of a webpage and quietly collect dozens of data points: your browser and operating system version, installed fonts, screen resolution and color depth, timezone, language settings, list of browser plugins, and how your specific hardware renders a hidden canvas or WebGL element. Combined, these details are often unique enough to identify one device among millions, without ever touching a cookie or an IP address.

Panopticlick, the original fingerprinting research project from the Electronic Frontier Foundation, found that the vast majority of browser configurations tested were unique or nearly unique based on this kind of data alone. A VPN does nothing to change any of it, because none of it depends on your network connection.

Why a VPN can’t fix this

A VPN operates at the network layer: it encrypts your traffic and routes it through a different exit IP address. Fingerprinting operates at the browser and application layer, reading information your browser voluntarily exposes to any website that asks. These are different problems that require different tools.

This is also why switching VPN servers doesn’t reset a fingerprint. Your IP address changes, but your fonts, screen resolution, and canvas rendering signature stay exactly the same, so a sufficiently sophisticated tracker can still connect your activity on the old server to your activity on the new one.

What a VPN does protect against

To be clear about what you are getting: a VPN hides your IP address and real location from the sites you visit, encrypts your traffic from your ISP and anyone on the same network, and prevents IP-based tracking and geographic profiling. That’s real, useful protection, and it’s the correct tool for hiding your location, defeating IP-based geo-blocks, or securing traffic on public Wi-Fi.

It’s a different job from stopping fingerprinting, which is why treating “I have a VPN on” as equivalent to “I am anonymous” is the mistake to avoid.

What actually reduces fingerprinting

Use a browser built to resist it. Firefox in strict mode and the Tor Browser both include specific countermeasures: standardizing canvas output, blocking known fingerprinting scripts, and normalizing screen and font reporting across all users of that browser so individual devices blend together.

Disable or limit JavaScript on sites you don’t trust. Most fingerprinting techniques, including canvas and WebGL fingerprinting, rely on JavaScript to run. Extensions like NoScript give you granular control, though they will break some sites.

Use privacy-focused browser extensions built for this specifically. Tools designed to resist fingerprinting will spoof or randomize the data points scripts try to read, rather than simply blocking ads and trackers by domain.

Keep your setup as generic as possible. An unusual combination of browser, extensions, screen resolution, and fonts makes you easier to fingerprint precisely because it’s rare. A common browser and default settings blend in with millions of other users.

Combine a VPN with these measures rather than relying on either alone. A VPN plus a fingerprint-resistant browser covers both the network layer and the browser layer, which is what actually approaches real anonymity.

A concrete example of how fingerprinting defeats a VPN alone

Imagine you connect to a VPN server in one country to research something you’d rather keep separate from your usual browsing identity, then disconnect and reconnect through a server in a different country for something else entirely. Your IP address changed twice. But if you used the same browser, with the same installed fonts, the same screen resolution, and the same canvas rendering signature both times, a tracking script embedded on both sites can still recognize that the same device visited both, purely from the fingerprint, with no need for your IP address at all. This is precisely the scenario people assume a VPN protects against, and precisely the scenario it doesn’t, because fingerprinting operates independently of which network you’re connected through.

This is also why “clearing cookies” doesn’t help against fingerprinting the way people expect. Cookies are a storage mechanism the site controls and you can delete. A fingerprint is derived fresh, in real time, from your device’s actual characteristics every time you load a page, so there’s nothing stored locally to clear.

Does Tor solve this?

The Tor Browser is specifically engineered to make every user’s fingerprint look identical, standardizing window size, timezone reporting, and canvas output across the entire user base. Combined with Tor’s onion routing for IP anonymity, this is a stronger anti-fingerprinting setup than a VPN alone, though it comes with a significant speed trade-off. Some privacy-focused users route VPN traffic through Tor, or vice versa, for layered protection; see our guide on VPN vs. Tor for the trade-offs of each approach and when combining them makes sense.

Mobile fingerprinting: a slightly different picture

Fingerprinting on mobile devices works a bit differently than on desktop browsers, since mobile hardware and software configurations are more standardized across users of the same phone model and OS version, which naturally reduces how unique any single fingerprint is. That said, mobile apps (as opposed to mobile browsers) often have deeper access to device identifiers, advertising IDs, sensor data, and installed app lists, which can create an equally strong or stronger tracking signal than a desktop browser fingerprint, just through a different set of data points. A VPN on mobile has the same fundamental limitation as on desktop: it hides your IP and encrypts traffic, but doesn’t touch what an app itself can read directly from the device.

Resetting your phone’s advertising identifier periodically, and reviewing app permissions to limit what each app can access, does more to reduce mobile tracking specifically than any VPN setting will, since the tracking mechanism at play is different from network-based tracking.

Why this matters more for some users than others

If your VPN use case is unblocking a streaming library or securing a connection on public Wi-Fi, fingerprinting resistance is largely irrelevant to your actual goal, and a standard VPN setup does everything you need. If your use case involves needing genuine separation between different online identities or activities, journalism, activism, sensitive research, or any situation where being linked across sessions carries real risk, understanding this gap matters a lot more, and the additional steps outlined above stop being optional extras and start being part of a baseline setup.

Which VPNs are more transparent about this limitation

Providers that are open about fingerprinting risk rather than overselling VPN protection are generally the more trustworthy ones on privacy claims overall. Mullvad and ProtonVPN both publish educational content acknowledging that a VPN doesn’t stop fingerprinting, and Mullvad in particular has built its own privacy-focused browser (Mullvad Browser, built on Tor Browser’s anti-fingerprinting base) specifically to address the gap a VPN leaves open.

Want to compare all VPNs side by side? Check our full VPN comparison table with scores across 18 criteria.

Our verdict

A VPN protects your IP address and encrypts your traffic. It does not stop browser fingerprinting, which relies on device and browser characteristics that have nothing to do with your network connection. If fingerprinting resistance matters to you, pair your VPN with a fingerprint-resistant browser like Firefox in strict mode or Tor Browser, rather than assuming the VPN alone covers it.

A well-audited VPN like NordVPN is still the right foundation for the network layer of this problem, even though it won’t touch fingerprinting on its own.

Keep reading: VPN vs. Tor in 2026: Which One Do You Actually Need? and How to Check if Your VPN Is Leaking Your IP Address.