A VPN, in simple terms, creates an encrypted tunnel between your device and the websites you visit. When you access an international site, your request first goes to a server operated by the VPN provider, which then forwards it to the destination. The destination site sees the server's IP address, not your real one. You don't have to physically leave the country, yet your traffic travels an international route. That's how cross-border access works. If you're new to this, understanding a few key concepts will help you avoid most common mistakes.

Start with three concepts: VPN, subscription link, and protocols

A subscription link is how your client gets its server configuration. It's usually a long URL starting with https://, containing server addresses, ports, protocol, and authentication info. You paste it into your client, and the client automatically pulls the latest server list and configures itself. For beginners, understanding how sensitive a subscription link is matters more than knowing protocol details. It's like a keychain for your account: anyone who has it can use your servers.

Protocols are the rules for encrypting and transmitting data. Common ones include Shadowsocks, VMess, Trojan, VLESS, and Hysteria2, which differ mainly in encryption, handshake, and resistance to interference. You don't need to memorize these details. The provider configures the protocol in the subscription link, and your client detects it automatically. The only thing you need to do is keep your client up to date.

Our server coverage and refund policy can help you decide:

120+
Countries/Regions
220+
Server Nodes
30 days
Money-back guarantee
Unlimited
Simultaneous devices

Protecting your account and subscription link: your first line of defense

Your subscription link is the first gate to your account security. Many people screenshot the link and send it in chat apps or save it in notes. That's actually the riskiest thing you can do. Screenshots end up in photo backup services, and chat history can be read by third parties. Safer habits:

  1. Copy the subscription link instead of taking a screenshot
  2. Store the link in a password manager, not in plain-text notes
  3. Never show your client interface on social media if it displays a subscription link
  4. If you suspect the link has leaked, reset it immediately in the provider's dashboard

For your account password, use a random password of at least 12 characters, and never reuse a password from another site. If your provider supports two-factor authentication, enable it right away. Two-factor authentication prevents the scenario where a leaked password still leads to a compromised account — even if someone has your password, they can't log in without the second factor.

One thing people often overlook is multiple-device sign-in. Modern VPN services usually allow unlimited simultaneous connections, and we do too. That means you need to secure every device. Set a lock screen PIN or biometric authentication on your phone, computer, and tablet so that if a device is lost, someone can't just open the already-logged-in client.

The information in a subscription link is equivalent to account access. Never provide your subscription link to anyone who asks for it, no matter if they claim to be "helping you configure it," "providing customer support," or "testing servers." Official support will never ask for your full subscription link in a chat.

Public Wi-Fi risks and how to deal with them

Public Wi-Fi is one of the most common scenarios for using a VPN. Free networks at cafés, airports, and hotels are convenient, but they come with three types of risk.

The first is man-in-the-middle attacks. An attacker can create a fake Wi-Fi network with the same name as a real hotspot and trick you into connecting. All the data you send passes through the attacker's device, including login passwords and payment info.

The second is ARP spoofing. An attacker on the same local network can impersonate the gateway and intercept packets between you and the internet. Even if you're visiting an HTTPS site, the attacker can see which domains you're visiting, though not the content.

The third is rogue hotspots. Some free Wi-Fi networks inject ads, collect browsing history, or even hijack DNS requests to redirect you to phishing sites.

A VPN can mitigate some of these risks. When the VPN is connected, your traffic is encrypted and routed through the VPN server. Even if a man-in-the-middle intercepts the packets, all they see is ciphertext. But a VPN doesn't replace HTTPS. If you're visiting an HTTP site, the VPN only hides the traffic between you and the server; the plaintext between the server and the website can still be read. So on public Wi-Fi, you should do all of the following:

  • Connect the VPN first, then open your browser
  • Only visit HTTPS sites — look for the padlock in the address bar
  • Don't make large transfers or enter payment passwords on public Wi-Fi
  • Turn off "auto-join known Wi-Fi" on your devices to avoid accidentally connecting to a hotspot with the same name

What information you should not provide when signing up

Many VPN services only need an email address to sign up. But some platforms ask for more information, and you need to learn to tell the difference between "necessary" and "unnecessary."

When signing up, only provide what the provider explicitly requires. Our signup process doesn't require an email address — you can create an account and start using the service without giving us your email. That's a real privacy advantage: you don't have to expose your personal inbox to the provider, which removes a layer of spam and account-linking risk.

If a VPN service asks for your real name, ID number, or home address, be cautious. This kind of information has nothing to do with providing VPN access, and providers that collect it usually have other motives. When paying, use a payment method the platform officially supports, and avoid sending your card number directly to customer service or typing it into a chat.

A common mistake is writing your real name or employer in the notes field of your client. Notes are stored locally, but if your client has sync features or you share a screenshot, that information can be exposed.

A five-minute security check checklist

Here's a quick checklist you can run through before your first use. Each item addresses a real risk. Spend five minutes checking these off, and you'll avoid most beginner pitfalls.

  • ✅ Copy your subscription link — don't screenshot it, don't forward it to anyone
  • ✅ Use a password of at least 12 characters, different from any other site
  • ✅ Enable two-factor authentication as soon as your provider supports it
  • ✅ Set a lock screen PIN or biometric authentication on your phone and computer
  • ✅ On public Wi-Fi, connect the VPN first, then browse
  • ✅ Only visit HTTPS sites, don't click unknown links
  • ✅ Only provide required info when signing up, leave everything else blank
  • ✅ Regularly check your device list and sign out any unfamiliar devices

Conclusion: security habits matter more than tools

The truth is, most beginners don't fail because they don't know — they fail because they haven't built habits. Running through the checklist above takes five minutes and avoids most common pitfalls. The table below summarizes four of the most frequent security mistakes so you can check yourself.

Common practice Potential risk Correct approach
Screenshotting and forwarding your subscription link Link leaks, traffic stolen Copy it into a password manager
Reusing the same password as another site Credential stuffing attacks Use a unique random password for each site
Logging into online banking directly on public Wi-Fi Intercepted by a man-in-the-middle Connect the VPN first, confirm HTTPS
Writing your real name in the client notes Exposed via screenshot or sync Use a nickname or leave it blank

Conclusion: For beginners, using a VPN isn't about picking the most complex protocol or the most servers. It's about managing your subscription link, isolating your accounts, and building the habit of "connect the VPN first, then browse." We offer 120+ countries / 220+ routes, plans starting at ¥9.9/month, and a 30-day money-back guarantee — a solid starting point for your first try.