VPNLab buys accounts, tests 30 days, and publishes comparable measurements. Full protocol lives on Methodology; this guide expands the consumer-facing version.
We measure download/upload on nearby and distant servers using consistent baseline connections. WireGuard/NordLynx-class protocols usually win latency.
DNS, IPv6, and WebRTC leak checks matter; a “connected” UI means little if DNS leaves the tunnel.
We verify major platforms and read jurisdiction + audit claims critically. Marketing “no logs” language is not the same as audited no-logs.
We pay for the same plan a reader would, on the same tier, and we keep it for at least thirty days. Press accounts and vendor demos sit on different infrastructure and different support queues, and they never show you what happens when a renewal fails or a refund is requested. Buying is also the only way to test the cancellation path, which is where several well-reviewed providers get uncomfortable.
A single number is worthless without a baseline. We record the unprotected line first, then measure the same connection through a nearby server and a deliberately distant one, repeating across the day because congestion is time-of-day dependent. What we publish is the retained percentage of the baseline, not a headline megabit figure that only describes our office.
Modern WireGuard-derived stacks generally win on latency, which is what you feel. The reason is design: WireGuard's handshake and cipher set are fixed rather than negotiated, so there is far less work before the first packet moves.
We check DNS, IPv6 and WebRTC on every provider, on desktop and mobile, and we do it while forcing the tunnel to drop mid-session rather than on a clean disconnect. A provider that passes at rest and leaks during a reconnect has failed the case that matters, because that is the case you will not notice. We also verify that the advertised kill switch survives the client being terminated.
We verify major platforms from several regions and re-check later in the month, because unblocking is perishable: platforms score addresses by reputation and by the hosting networks they are announced from, so a server that worked in week one can be catalogued by week three. Any provider claiming permanent access to a given library is describing a wish. We report what worked, when, and how stable it stayed — never a guarantee.
We read the privacy policy rather than the landing page, and we separate three things that marketing blurs together: what is collected, what is retained, and what has been independently verified. We note the operating jurisdiction, who ultimately owns the company, and the date and scope of the most recent audit. "No logs" as a slogan and "no logs" as an audited finding are different claims, and only one of them is evidence.
Scores move when behaviour moves: a failed leak test, a jurisdiction change, an ownership change, a price rise that is not matched by capability, or a support experience that collapses at renewal. We re-test rather than re-word.
No. We buy every account at retail and the ranking is set before any affiliate relationship is considered. Where a link earns a commission it is disclosed, and it never changes an ordering.
Speed and leak checks are repeated when a provider ships a major client update, changes ownership or jurisdiction, or publishes a new audit. Streaming access is re-checked more often because it is the least stable thing we measure.
Because the baseline differs. We publish the percentage of our own unprotected line that a provider retains, which is comparable across providers, rather than a raw megabit number that mostly describes the tester's connection.