How to Block ISP Tracking: What Your Provider Sees and How to Stop It

Written by

Zahra Habib

Last Updated on

Reading time:

How to Block ISP Tracking

By clicking a retailer link you consent to third party cookies that track your onward journey. If you make a purchase, TechVise will receive an affiliate commission which supports our mission to inform on the best products and services on offer.

If the walls have ears, your digital privacy is leaking too. We will discuss how to block ISP tracking everything including your browsing activity.

Most people worry about Google, Facebook or their favourite app tracking them. Fewer think about the company that connects them to the internet in the first place. That’s the gap worth closing, because your internet service provider sees more of your online life than almost anyone else, and unlike a search engine or social platform, you can’t just log out of it.

This guide covers what ISP tracking actually looks like, what an ISP employee can genuinely see on their end, the online privacy myths worth retiring, and the tools, VPNs included, that actually stop it.

Do ISPs Track Your Browsing Data?

Yes. 

Every ISP can see which sites and services you connect to, when, and for how long, even if it can’t read the content of encrypted pages. Whether a given provider uses that visibility to build targeted advertising profiles or sell it on depends on the company and, in some regions, on local law. It’s also worth keeping this in proportion. 

A network administrator’s job is not to sit and watch individual customers browse; most ISPs only pull up a specific person’s traffic when there’s a subpoena, an abuse complaint, or a security flag on the account. Tracking capability existing, and documented cases of it being used for advertising, is not the same as claiming every provider is actively monitoring everyone’s specific browsing history all the time. 

Either way, the underlying visibility isn’t optional or something you can switch off from your end without changing how you connect to the internet.

What an ISP Actually Sees

It helps to know exactly what shows up on an ISP’s side of the connection, rather than treating it as a black box. On a typical account, an ISP can see:

  • Your IP address and the IP address of whatever you’re connecting to
  • Source and destination port numbers
  • The general type of traffic, for example whether it’s HTTP/HTTPS, email, or a file transfer
  • DNS queries, which reveal the domain names you’re looking up, usually in plain text unless you’ve encryption is on.

For older, unencrypted protocols, an ISP can also see the actual content passing through, including passwords, which is one of the strongest practical arguments for making sure everything you use runs on HTTPS. Most of the modern web does by default now, but it’s still worth checking, particularly on smart home devices and older apps that haven’t been updated in years.

Your ISP has a Unique View of your Internet Activity

Every website you visit, every app you open, every video you stream passes through your ISP’s infrastructure before it reaches you. Google can only see what you do on Google. Your ISP sees the destination, timing and volume of every connection you make, across every service, all day, every day, on every device on your home network, smart TVs included. 

Smart TVs now account for a large and growing share of household viewing time, and manufacturers and ISPs alike can use that viewing data to build advertising profiles the same way they do with regular browsing, something most people never think to protect the way they protect a phone or laptop.

Here’s the technical detail that catches most people out. HTTPS encrypts the content of a page, so your ISP cannot read your emails or see your banking details. It does not hide the domains you visit, how long you stay, or how much data you use. Your device also makes DNS requests to translate website names into IP addresses, and by default those requests go straight to your ISP, giving it a running log of every site you visit, encrypted or not.

Some ISPs go further with deep packet inspection, a technique that examines the structure of your internet traffic in more detail than basic connection logs allow. It can’t read encrypted content, but it can identify patterns, the kind of traffic that looks like video streaming versus gaming versus file sharing, and that’s also how some providers justify bandwidth throttling, deliberately slowing certain types of traffic during busy periods. 

If your streaming has ever mysteriously buffered worse in the evening while everything else runs fine, throttling by traffic type is a plausible reason why. This is also where a VPN can occasionally feel like it speeds things up rather than just protecting you: if a provider is throttling specific traffic types based on what deep packet inspection identifies, encrypting that traffic through a VPN can mask what type it is and, in that specific case, restore your normal speed. It won’t make your connection faster than what you’re paying for, but it can remove a throttling penalty that was quietly there.

What ISPs have Actually Done With your Data

This isn’t hypothetical. 

A major US carrier was fined for using tracking cookies that survived even when users cleared their browser data. Another tried charging customers extra simply to opt out of having their data sold to advertisers. 

A 2021 FTC study found that several large US ISPs combine data across their own services, home broadband, mobile, connected devices, to build detailed advertising profiles on customers, often without a clear way to opt out.

There’s a newer wrinkle too. Some ISP-supplied routers now include Wi-Fi sensing features that can detect movement inside your home using signal disruption, essentially treating your Wi-Fi router as a crude motion sensor. Because the ISP controls the router’s firmware, it controls which features get switched on, often without much fanfare.

Privacy Myths Worth Retiring

Incognito mode does not stop ISP tracking. Private browsing modes in Google Chrome and other browsers stop your device from saving local history and prevent some websites from identifying you through stored cookies. They do nothing at the network level. Your ISP still sees your real IP address and every domain you connect to, incognito or not.

Your IP address isn’t something that gets “leaked”, it’s public by design. Every device on your home network shares a real IP address that your ISP assigns and can trace directly back to your account, and any site or service you connect to can see it too, much like a phone number. The privacy question isn’t whether your IP address is visible, it always is to whoever you’re talking to, it’s whether it can be tied back to your identity and browsing habits over time. That’s part of how advertisers piece together habits across sites without needing cookies at all.

A VPN connection doesn’t make you invisible, it moves who you’re trusting. This is worth being blunt about, because a lot of VPN marketing dodges it. Your ISP is always the first hop in your connection; nothing removes that. What a VPN changes is what that first hop can see, encrypted traffic to a VPN server instead of your actual destinations, but the VPN provider itself now occupies the position your ISP used to. 

A genuine no-logs policy, ideally independently audited, is what determines whether that trade-off is worth it. Claims of total anonymous browsing from any provider should be treated with scepticism; fingerprinting, account logins, and cross-site tracking can still identify you even behind a VPN.

How to Block ISP Tracking

Encrypted DNS

Since DNS queries are one of the clearest ISP tracking tools, encrypting them is one of the simplest fixes and it’s often skipped. Switching your DNS provider to a public option like Cloudflare (1.1.1.1), Google DNS (8.8.8.8), or OpenDNS, combined with DNS over HTTPS or DNS over TLS so the queries themselves are encrypted in transit, stops your ISP from logging which domains you look up. 

It’s not a complete solution on its own, since your ISP can still see the destination IP addresses your device ultimately connects to, but it closes one of the most detailed logging channels available to them.

A VPN Service

A virtual private network encrypts your traffic and routes it through the VPN server instead of going straight through your ISP. Your ISP still sees that you’re connected to a VPN and roughly how much data passes through, but not which sites you visit or what you do on them. 

This is the layer most people miss: browser-level tools like ad blocker and private browsing modes never touch the network layer, so they can’t stop your ISP. A VPN is one of the few tools that does.

Look for a verified no-logs policy backed by an independent audit, DNS leak protection so your DNS requests don’t accidentally slip outside the encrypted tunnel back to your ISP, a kill switch that cuts your internet connection entirely if the VPN drops rather than silently falling back to your unprotected connection, and protection against WebRTC leaks, a lesser-known flaw where your real IP address can be exposed through your browser even while a VPN looks fully connected. 

Skip free VPN services for anything privacy-sensitive; a free VPN still has to fund itself somehow, and that’s frequently through the very data collection you’re trying to avoid.

Proton VPN is a strong pick on this front. It publishes an audited no-logs policy, is based in Switzerland outside the Five Eyes intelligence-sharing alliance, and includes DNS leak protection and a kill switch as standard. Its NetShield feature also blocks ads and trackers at the DNS level, covering ground a VPN alone doesn’t touch. 

Surfshark is worth considering too, particularly if you want unlimited simultaneous device connections without paying more for it, alongside solid encryption and leak protection. 

Mullvad deserves a mention for a different reason: it doesn’t require an email address to sign up at all, generating an account number instead, which is about as close to anonymous VPN signup as the market currently offers.

We’d stop short of recommending ExpressVPN or NordVPN as strongly as some comparison sites do. Both are competent, well-established VPN providers, but neither offers a meaningfully better privacy proposition than Proton, Surfshark or Mullvad for this specific use case, and both cost more for it.

Tor, as an Alternative

The Tor browser, also known as the onion router, routes your traffic through multiple volunteer-run relays instead of a single VPN server, which makes it harder for any single party, including your ISP, to trace your activity back to you. 

It’s slower than a VPN and can draw unwanted attention from some ISPs and networks simply because Tor traffic is recognisable as Tor traffic. 

For everyday browsing, a VPN is the more practical choice. Tor has its place for higher-risk situations, journalism and activism among them, where its anonymity properties outweigh the speed cost.

Ad and Tracker Blockers

A VPN blocks your ISP. It doesn’t block trackers running inside the pages you visit once your traffic reaches its destination. 

A browser extension like Privacy Badger, or a bundled ad blocker like Proton’s NetShield, closes that separate gap by blocking known trackers and malicious scripts before they load.

Public WiFi Changes the Picture

On public Wi Fi, the network operator, not just your home ISP, can see your unencrypted traffic, and other users on the same network can potentially intercept data if the connection isn’t secured properly. A VPN matters even more here, since you’re extending the same tracking risk to a network you have no relationship with and no way to audit.

How to actually set this up

  1. Switch to an encrypted public DNS provider (Cloudflare, Google DNS, or OpenDNS) with DNS over HTTPS or DNS over TLS enabled.
  2. Choose a VPN provider with an audited no-logs policy, DNS leak protection, WebRTC leak protection, and a kill switch. Proton VPN, Surfshark and Mullvad all meet that bar.
  3. Install the VPN app on every device you want protected, not just your laptop, and consider setting it up at the router level to cover smart TVs and other connected devices at once.
  4. Enable the kill switch in settings so a dropped connection doesn’t silently expose your real IP address.
  5. Add a tracker blocker for the layer a VPN doesn’t cover.
  6. Avoid free VPN apps for anything you’d consider private.

If you cannot access the Proton VPN site directly, try a VPN or check your network settings, since availability can vary by country. The same applies if you cannot access Proton Mail directly.

The bottom line

Your ISP’s position in your internet connection gives it visibility no single app or website has on its own, from the domains you visit to your DNS queries and, on older unencrypted protocols, even page content. Encrypted DNS closes one part of that gap. A VPN with a genuinely audited no-logs policy, DNS and WebRTC leak protection, and a kill switch closes most of the rest. Neither is a silver bullet on its own, and any provider promising total anonymous browsing is overselling what the technology can do. What you can reasonably expect is a setup where your ISP sees that you’re online, and very little else.

Frequently Asked Questions

My ISP is the first hop on my connection no matter what I do. How does anything actually hide me from them?

It doesn’t remove that first hop, nothing can. What tools like a VPN or Tor change is what that first hop can see. Instead of watching your traffic go directly to every site you visit, your ISP sees encrypted traffic going to one destination, your VPN server or a Tor relay, and nothing more specific than that. You’re not becoming invisible, you’re changing which party downstream has the fuller picture, and choosing one with a genuinely audited no-logs policy is what makes that trade worthwhile.

Does a VPN stop targeted advertising completely?

No. A VPN stops your ISP from seeing your browsing, but sites and advertisers can still track you through cookies, account logins, and browser fingerprinting once your traffic reaches them. A tracker blocker handles that separate layer.

Is my ISP actually selling my specific browsing history?

Some ISPs have been documented building advertising profiles from customer data, and regulators have taken action over it. That’s different from every provider actively selling individually identifiable browsing history for every customer. Treat the risk as real and worth protecting against, without assuming the worst-case version is universal.

Zahra Habib

A published author and content strategist, Zahra’s passion for technology and creativity fuels everything she does, one word at a time.