Opera's Built-In "VPN": What It Actually Does and When It's Enough
Opera's built-in "VPN" is really an encrypted browser-only proxy. Here's how to enable it, verify it with a browser-vs-curl IP test, avoid the WebRTC leak, and know when you need a real VPN.
06 Sept 2025, 16:32 UTC

The hotel Wi-Fi problem
You're on hotel or café Wi-Fi, you don't trust the network, and you don't have a VPN subscription. Opera's answer is a toggle built into the browser labeled "VPN" — free, unlimited data, no account. It sounds too convenient, and in one important sense it is: despite the name, it is not a VPN in the way most people understand the term. Knowing what it actually is tells you exactly when it's enough and when it isn't.
The takeaway up front: Opera's feature is an encrypted HTTPS proxy that only covers traffic inside the Opera browser. That's genuinely useful for casual protection on untrusted networks, but it does nothing for your email client, your OS updates, or any other app — and it doesn't make you anonymous.
A proxy wearing a VPN's name
A traditional VPN client creates an encrypted tunnel at the operating-system level, so every application's traffic flows through it. Opera's feature works one layer up: the browser routes its own requests through Opera-operated proxy servers over an encrypted connection. The practical consequences:
- Scope: Only tabs in Opera are proxied. A
curlrequest from your terminal, your Slack client, and your system package manager all still use your real connection and real IP. - Encryption boundary: Traffic between Opera and the proxy is encrypted, which is what shields you from the Wi-Fi operator snooping. Beyond the proxy, normal HTTPS rules apply.
- Trust: You're shifting trust from the local network to Opera and its infrastructure. Opera can see the traffic it proxies, and its data-handling practices differ from audited no-log VPN providers. Read the current privacy policy before relying on it for anything sensitive.
None of this makes the feature bad. It makes it a specific tool with a specific blast radius.
Enabling it and checking that it works
On current Opera desktop builds (the exact path shifts between versions and platforms — Opera GX and mobile Opera differ), the flow is:
- Open Settings (Alt+P on Windows/Linux, ⌘+, on macOS) and go to Privacy & Security — on some versions it's under Advanced → Features.
- Toggle Enable VPN. No sign-in is required.
- A blue VPN badge appears to the left of the address bar. Click it to turn the proxy on or off per session and to pick a virtual location.
Location choice is coarse: broad regions like Americas, Europe, or Asia rather than specific countries or cities. That's fine for "not my real IP" and useless for "I need to appear to be in the Netherlands specifically."
Now verify instead of trusting the badge. With the VPN off, load any IP-check page (a "what is my IP" site) and note the address. Toggle the VPN on, reload, and confirm the IP and reported location changed. Then open a terminal — no special permissions needed — and run:
curl ifconfig.meIf the result is your real public IP while the browser shows a different one, you've confirmed the browser-only scope directly. That single comparison is the whole mental model in one experiment.
A worked example: region-dependent content
A realistic use case is checking how a site behaves for visitors from another region — say, a storefront that shows different pricing or a news site with regional editions. The procedure:
- Load the target site with the VPN off and note the content or currency shown.
- Enable the VPN, set the virtual location to a different region, and open the site in a fresh tab (or hard-reload with Ctrl+Shift+R to bypass cache).
- Compare. If the site keys off IP geolocation, you'll see the regional variant.
Two caveats. First, the broad region selector means you can't target a specific country, so this is a rough check, not precise QA. Second, some services detect and block known proxy exit IPs — Opera's included — so a "blocked" result may say more about the proxy than the region.
The leak that catches people: WebRTC
Even with the proxy on, WebRTC (the browser's real-time communication API used by voice/video chat) can expose your local or even public IP to sites that ask for it, depending on your configuration. If IP concealment is the point, test for it: search for a "WebRTC leak test" page and run it with the VPN on. If your real IP shows up, look in Opera's settings for the WebRTC handling option and set it to only use the proxy interface. This is the most commonly missed step and the easiest to check.
When to reach for a real VPN instead
Opera's feature is the right call when: you're on untrusted Wi-Fi and just want the browser session protected, you want a quick rough IP change, or you want zero cost and zero setup. It is the wrong call when:
- You need all device traffic tunneled — torrent clients, other browsers, background services.
- You need a specific exit country or city.
- Your threat model requires a provider with an audited no-logging policy rather than a browser vendor's privacy policy.
- You need anonymity. Sites can still fingerprint your browser, log you into accounts, and correlate sessions; Opera still sees proxied traffic.
Speeds, server counts, and data practices for this feature change over time and aren't worth quoting from memory — treat any specific numbers you read, including here, as things to verify against Opera's current documentation.
The actionable part
Spend five minutes now, before you need it: enable the VPN in settings, confirm the badge toggle works, run the browser-vs-curl IP comparison so the scope is concrete, and run a WebRTC leak test. After that, the decision rule is simple: browser-only, casual, free — Opera's proxy is fine. Whole device, specific location, or serious privacy — install a real VPN.
0 replies
A thoughtful contribution can make all the difference. Be the first to share one.