You've probably realized by now that clicking the little fedora icon in your browser is mostly privacy theatre. It hides your late-night snack searches from your spouse, but it leaves you wide open to everyone else.
Most guides on this topic will tell you that true anonymity is impossible, right before trying to sell you the same generic list of tools. This is not that guide.
We’re treating anonymity as a spectrum: a series of layers you stack based on who you’re actually trying to hide from. Whether you want to stop creepy ads or block state-level surveillance, we’ll show you how to build a stack that fits your specific threat model and, more importantly, how to prove it is actually working.
So what does anonymous browsing actually mean, and how is it different from the incognito tab you have been using?
What Anonymous Browsing Actually Means
Anonymous browsing means using the internet so your activity cannot be tied back to your real identity. It hides your IP address, blocks trackers, and reduces your browser fingerprint. Anonymous browsing is not the same as incognito mode, which only hides your history from the device you’re using.
In technical terms, the goal of anonymous browsing is unlinkability. When you browse the web normally, you leave a massive digital footprint that your ISP, advertisers, and data brokers use to build a profile of your life. Unlinkability ensures that while an observer might see that someone is visiting a website or downloading a file, they have no way to link that action to your name, home address, or specific device.
But anonymity isn’t the same as privacy, and vice versa. Privacy is about controlling who sees what you’re doing (like an encrypted message that only the recipient can read). Anonymity is about hiding who you are while you do it. You can have privacy without anonymity, and you can be anonymous without having privacy.
Most people talk about anonymity like it’s a binary: you’re either a ghost or you’re totally exposed. In reality, anonymous browsing is not a switch you flip. It’s a spectrum, and where you land depends on what you stack and who’s trying to find you. Someone trying to avoid targeted shoe ads requires a much shorter stack than a whistleblower trying to avoid a local government.
The most common confusion in this category, however, is the gap between actual anonymous browsing and the "private" or "incognito" mode built into your browser. The difference between the two is significantly bigger than most people realize.
Anonymous Browsing vs Incognito vs Private Mode
You’ve probably been using incognito mode for years and, at some point, realized it’s a bit of a scam. Maybe you searched for a very specific, very embarrassing thing in a private tab, only to have a targeted ad for it pop up on your Facebook feed five minutes later. It feels like your computer is gaslighting you, but it’s actually the system working exactly as designed.

Incognito mode (or Private Browsing) is essentially just Forgetful Mode for your own laptop. It tells your browser: "Hey, when I close this window, delete the history and the cookies so my roommate doesn't see what I was doing." That’s it. It’s a local cleanup crew, but it doesn’t protect you from being tracked online by your ISP, advertisers, and other third parties desperate to know what you search for and click.
| Feature | Regular Browsing | Private/Incognito | Anonymous Browsing |
|---|---|---|---|
| Hides history from your device | No | Yes | Yes |
| Hides activity from your ISP | No | No | Yes |
| Hides IP address from sites | No | No | Yes |
| Blocks 3rd-party cookies | No | Mostly | Yes |
| Blocks fingerprinting | No | No | Yes |
| Blocks account tracking | No | No | Yes |
| Encrypts network traffic | No | No | Yes |
The big mix-up here is that people think incognito mode and anonymous browsing are on the same team. They aren't. Incognito is a local storage feature. Anonymous browsing is a network and identity feature. They’re playing two different sports.
This is also why the VPN + Incognito strategy is a bit of a myth. People think layering them creates some kind of super ghost mode, but in reality, the VPN is doing 99% of the heavy lifting there. Adding an incognito tab to a VPN is like wearing a fake moustache while you're already inside a tank: it doesn't hurt, but the tank is the part actually stopping the bullets.
Incognito is fine if you’re shopping for a surprise gift or your “weird YouTube searches ruining my algorithm" worry spiral. But it’s not a privacy tool.
If incognito isn't actually hiding you, what is, and from whom? To figure that out, we have to look at the sneaky ways websites actually pin a name to your face.
How Websites Actually Identify You
You leave four kinds of traces when you browse. To actually go anonymous, you have to look at the entire threat surface. Think of it like a crime scene: even if you wear a mask, you might still leave a footprint, a fingerprint, or a strand of hair, and that’s definitely going to get you in trouble.

Your IP Address
Your IP address is your digital home address. It’s the most basic way sites identify you, revealing your rough physical location and which ISP you’re paying for. While it’s the easiest thing to hide, it’s also a bit messy: mobile IPs change constantly, and carrier-grade NAT means you might share an IP with hundreds of other people. Still, if you don't mask this, you're essentially shouting your location to every server you touch.
Cookies
Cookies are the classic trackers. First-party cookies remember your login or what’s in your shopping cart, which is helpful. Third-party cookies, however, are the stalker variety. They follow you across different websites to build a cohesive map of your interests.
Clearing your cookies is a decent start, but it’s a temporary fix at best. As soon as you visit another site, the collection starts all over again.
Browser Fingerprinting
This is where the heavy lifting happens. Even if you hide your IP and block cookies, your browser is incredibly talkative, and it eagerly shares your screen resolution, installed fonts, timezone, language, and technical specs like canvas rendering and WebGL hashes.
When combined, these details create a browser fingerprint that’s super unique to you. You can see your own fingerprint using a browser fingerprinting test, but we’ll come back to that.
Account-Based Tracking
If you’re logged into Gmail, Facebook, or a Google account on Chrome, none of the other layers matter. The moment you sign in, you have linked your current browsing session directly to your real-world identity.
This is the hardest leak to plug because, let’s face it, we all want to check our email or see Aunt Becky’s latest cringey Facebook update. For true anonymity, you’d have to avoid logging in to all of your accounts. Which is kinda impossible in the world we live in.
Behavioral Biometrics
The newest frontier in tracking isn't about what you use, but how you use it. Behavioral biometrics track your unique typing rhythm, how fast you move your mouse, and your specific scroll velocity.
While often used for fraud detection to make sure you aren't a bot, these patterns can also build a behavioral profile that identifies you even if you’ve swapped your hardware and hidden your IP.
The Anonymity Stack by Threat Level
Anonymity is not a one-size-fits-all checklist. Trying to stop a shoe brand from following you around the web is not the same as being a whistleblower in a high-risk region trying to avoid getting identified. One requires a very basic anonymity stack, while the other needs something way more complex.
The Casual (Stop Advertisers, Stop Casual Tracking)
If you’re just an average internet user who’s fed up with having your every click tracked, this one is for you. You just need the right tools to hide from data brokers and the creepy accuracy of modern advertising.
Basically, all you need is a VPN running on all your devices at all times, a privacy-focused browser like Brave or Firefox (sorry, Chrome has to go!) with the Resist Fingerprinting feature enabled, a tracker and ad blocker like uBlock Origin or the Windscribe extension, and, ideally, ditch Google and switch to DuckDuckGo, Brave Search, or Startpage as your default search engine.
That’s it. This setup effectively kills IP-based tracking and the majority of third-party cookies. It stops your ISP from logging your DNS queries (the list of sites you visit) and breaks the casual fingerprinting used by most ad networks.
However, this still won’t help you if you stay logged into your Google or Facebook accounts while browsing. It also won't stop advanced fingerprinting from the most determined trackers, and it offers no protection against state-level surveillance.
The Concerned Citizen (Stop Most Adversaries, Including Your ISP)
If you’re a privacy-aware professional or someone who follows the security space, and you understand that your data is a liability, you want a stack that provides a high degree of unlinkability against almost anyone short of a government agency.
You’ll need everything that the casual user does, but with more resilience. This means adding active anti-fingerprinting at the browser layer, specifically an extension that randomizes your canvas, fonts, and user agent, and using an OS-level Firewall that blocks all non-VPN traffic.
You should also route encrypted DNS (DoH or DoT) through your VPN, use a privacy-first email provider like Proton Mail with email aliases, and move all credentials into a password manager. Also, switch your sensitive chats to Signal. This stops your ISP, most fingerprinting, and the account-correlation tricks used by data brokers. It creates a fail-safe environment where your identity doesn't leak even if the VPN connection blips.
Still, all this doesn’t stop adversaries with access to your VPN provider's infrastructure or state-level actors with cross-network correlation capabilities.
The High-Risk User (Journalist, Activist, Whistleblower, Researcher)
If you’re a journalist, activist, whistleblower, researcher, or anyone else whose anonymity is operationally critical, your adversary isn’t just an online advertiser. It’s a motivated entity with significant resources. At this level, a single mistake, like logging into a personal account once, can have real-world consequences.
You need a more complex setup, like everything the privacy-concerned user has, plus a shift in hardware. Use the Tor Browser for all sensitive sessions, specifically in a VPN-then-Tor configuration. Use a dedicated device or a virtual machine that never touches your real identity. For the highest risk, use a live OS like Tails that leaves no trace on the hardware. Payments should be made via Monero rather than Bitcoin.
And most importantly, you must maintain strict identity hygiene: no reused usernames, no real-name logins, and monitoring your writing style to avoid stylometric fingerprinting. This is the ceiling for technical anonymity, stopping commercial tracking and most technical means of state-level surveillance.
However, even this stack cannot save you from human error. Logging into a personal Gmail account from a Tails session deanonymizes you instantly. It also cannot protect against targeted physical surveillance or global passive observation of the internet's backbone.
Your Anonymity Stack in One Glance
To make this easier for you, here’s a table that illustrates which tools you need for each level of anonymity. You can think of this as your shopping list for a less surveilled life.
| Component | Tier 1: Casual | Tier 2: Concerned | Tier 3: High-Risk |
|---|---|---|---|
| Network Layer | Always On VPN | VPN + OS Firewall | VPN + Tor Browser |
| Browser | Brave / Firefox | Brave + Anti-Fingerprint | Tails / Whonix |
| Search Engine | DuckDuckGo / Startpage | Brave Search / Startpage | .onion Search |
| DNS | Standard VPN DNS | Encrypted DNS (DoH) | Tor Multi-hop |
| Regular | Proton + Aliases | Fully Anonymous Aliases | |
| Identity | Log out of Google/FB | Password Manager | No Real-Name Accounts |
| Payments | Credit Card / PayPal | Masked Cards | Monero (XMR) |
The Trust Shift Problem (Why "No-Logs" Isn't Magic)
A VPN doesn’t eliminate trust. It relocates it. Instead of trusting your ISP not to log and sell your browsing history, you’re trusting your VPN provider not to log it. But in reality, for most VPN providers, the no-logs policy is just a pinky promise on a marketing page. To actually browse anonymously, you need to verify that promise.

If you’re going to hand over your traffic to a third party, you need to vet them like a pro. Here’s how to separate the marketing fluff from actual security:
- Independent audits: A real no-logs claim is backed by a reputable third-party firm (like Cure53, KPMG, or Deloitte) that has poked around the server infrastructure in the last 24 months. If a company says they were audited by an internal team, that’s just them grading their own homework.
- RAM-only servers: Look for diskless infrastructure. RAM-only servers run entirely on volatile memory, meaning that the moment a server is rebooted or unplugged, every bit of data on it vanishes. There’s no hard drive to seize or forget to wipe.
- Jurisdiction: Where the company is incorporated matters. You want to know if they are subject to mandatory data retention laws or if they live in a jurisdiction that is part of the Five/Nine/Fourteen Eyes intelligence-sharing alliances.
- Transparency reports & warrant canaries: A provider should regularly publish a transparency report showing exactly what data requests they’ve received from law enforcement. A warrant canary is a passive notice that they haven’t been served a secret subpoena; if the canary disappears, you have your answer.
- Ownership transparency: You’d be surprised how many VPN brands are owned by the same few parent companies. If you can’t find a clear About page with real names and owners, keep walking.
The Browser Layer (Where Most People Miss the Point)
You can have a VPN running, your cookies cleared, and your IP masked, yet still be uniquely identifiable on the open web in under 30 seconds. The reason is fingerprinting, and a VPN does nothing to stop it. While a VPN hides your location, your browser is busy telling every website you visit exactly how unique your computer is.
To stop this, you have to tackle the problem at the browser level. There are three main ways to do it.
Use a Browser Built for It
The Tor Browser remains the gold standard for defeating fingerprinting because it uses a herd model: it forces every user to look identical. By locking the window size, using a generic set of fonts, and disabling scripts by default, it ensures you blend into the crowd. The tradeoff, as any Tor user knows, is speed and the "Are you a robot?" CAPTCHAs that haunt your dreams.
Brave gets close out of the box with its Shields feature, which aggressively blocks trackers. Firefox is also a strong contender if you enable the Resist Fingerprinting (RFP) mode. You can do this by typing about:config into your address bar and setting privacy.resistFingerprinting to true. It’s a bit of a manual pro move, but it significantly reduces your browser's unique signature.
Add an Anti-Fingerprinting Layer
If switching browsers feels like too much work, you can add an anti-fingerprinting layer to the one you already use. This is where the Windscribe extension comes in. Instead of just blocking trackers, it actively randomizes the surfaces that fingerprinting tools use to identify you.
Specifically, it spoofs your canvas hash, WebGL renderer, font enumeration, locale, and timezone. It also swaps your user agent, screen resolution, and audio fingerprint, while blocking WebRTC IP exposure to ensure your real IP doesn't leak through the browser.
The thing is, you can’t actually hide your fingerprint; it’s always there. So our browser extension’s goal isn’t to hide your fingerprint, but to make it fingerprint inconsistent. By rotating these values every session, you ensure that even if a tracker sees you twice, it has no way to link the two visits together.
Combine Both
The serious-but-not-paranoid approach is to combine both. Use a privacy-hardened browser like Brave or Firefox with RFP and layer an anti-fingerprinting extension on top (like ours). This provides a "belt and suspenders" defense that makes you an incredibly difficult target for data brokers.
Diminishing returns kick in pretty quickly after this. Once you’ve randomized your browser’s identity and hardened the application itself, you’ve reached the practical ceiling for most people.
Kill Switch vs Firewall (Why the Difference Matters)
Almost every guide to anonymous browsing tells you to make sure your VPN has a kill switch. Here’s what they don't always tell you: a kill switch is a reactive bandage, not a proactive shield. While the term sounds industrial and final, the actual mechanics often leave a gap wide enough for your real identity to slip through.
The problem lies in how a kill switch operates. It’s essentially a monitor that waits for a VPN drop to happen. Once it detects that the connection is gone, it rushes to kill specified processes like your browser or torrent client. The issue is the detection-to-action gap. In the milliseconds between the VPN failing and the kill switch reacting, packets can leak.
Besides, your operating system is constantly making background connections that might not even be on the kill switch’s hit list. Whether it’s an OS update or an IPv6 request routing around the tunnel, a leak is often just a blink away.
A proper firewall handles the problem at the operating system network layer, rather than the process layer. Instead of waiting for something to go wrong, it establishes a permanent rule: block all outbound traffic, period. It then adds a single exception: traffic going through the encrypted VPN tunnel is allowed.
If the VPN connection drops, the "allow" rule disappears, but the "block everything" rule remains. There’s no detection gap because there is no detection at all… the system fails closed by design. Nothing gets out to the open web because the OS has been told there is no other path to the internet.
This is why we built Windscribe's Firewall as a core feature of our desktop apps. It offers four modes depending on how much control you want:
- Automatic: This turns on when you connect and off when you disconnect. It’s smart and lazy, perfect for most people who don’t want to switch it on and off every time.
- Manual: You control it with a physical switch. It’s for those who want more manual control.
- Always On: This stays active even if you close the Windscribe app entirely. No sneaky traffic gets outside the tunnel, period.
- Always On+: This takes "no means no" to another level. With this enabled, absolutely nothing comes or goes unless you are actively connected to a VPN location.
At this point, you have the network layer (VPN), the application layer (browser and extensions), the resilience layer (Firewall), and identity hygiene. For most internet users, that’s the ceiling. For some, there’s one more layer: Tor.
Should You Add Tor? (And the Order Matters)
Tor is the most powerful anonymity tool available to civilians. It’s also the slowest, the most operationally demanding, and overkill in every way for most of you reading this. While it’s the gold standard for untraceable browsing, it comes with a massive side of friction.
If you just want to stop Instagram from knowing you’re looking at luxury watches, Tor is like using a sledgehammer to kill a fly. But if your life or livelihood depends on being a ghost, you need to know how it works and how to pair it with a VPN correctly.
What Tor Actually Does
Tor (The Onion Router) uses a technique called onion routing to bounce your traffic through three encrypted hops: the entry node, the middle node, and the exit node. The entry node sees your real IP address but has no idea what you’re looking at, the middle node sees neither your IP nor your destination, and the exit node sees where you’re going, but has no clue who you are.
This results in extremely strong anonymity, but there’s a major catch: this only applies to traffic inside the Tor Browser. Other apps on your computer, like Spotify, Zoom, or your email client, will still leak your real identity normally through your standard internet connection.
VPN over Tor
You connect to your VPN first, then open the Tor Browser. This is the order we generally recommend, and you can find the specific setup steps for how to use Windscribe with Tor in our knowledge base.
Since you’re connecting to the VPN first, your ISP only sees that you’re using a VPN; they have no idea you’re accessing the Tor network. This is crucial in jurisdictions where simply using Tor can flag you for manual surveillance. Plus, the Tor entry node only sees the VPN’s IP address, not your home IP. This adds a buffer of trust between you and the volunteer-run Tor network.
Tor over VPN
The other way around: your traffic goes through Tor first and then exits through a VPN tunnel. This is a very specific configuration used mainly to access websites or services that flat-out block Tor exit nodes (which many do).
The tradeoff is a total reversal of exposure. You’re now showing your VPN provider the traffic that just came out of the Tor network. While the VPN provider won't know who you are (since your IP is masked by Tor), they can see exactly what you’re doing once the traffic is decrypted at the exit. Unless you have a very specific technical reason to do this, you don't need it.
When You Actually Need Tor
For 99% of people, Tor is more headache than help. You only really need to add this layer to your stack if you fall into one of three categories:
- You are a high-risk user, like a journalist, whistleblower, or activist whose physical safety depends on anonymity.
- You’re accessing sites that only exist on the Tor network.
- You’re in a highly restrictive jurisdiction where your ISP is actively scrutinizing or blocking standard VPN traffic.
That’s it. In any other case, the VPN + Browser Extension + Firewall stack provides plenty of anonymity without the soul-crushing speeds of the Tor network.
Verify Your Setup (Test It Yourself Right Now)
Your anonymity stack is only as good as its weakest leak. Instead of taking a set-it-and-forget-it approach and hoping it all works well, verify that each layer is actually doing its job. Run these four tests to see if your digital mask is actually strapped on straight.
Test 1: Your IP Address
This is the most basic check. Visit our free What Is My IP tool to see what the internet thinks your location is. If the VPN is working, you should see the IP address and city of the VPN server you selected. If you see your actual city or the name of your local ISP, your network layer is exposed.
Test 2: DNS Leak Test
Even if your IP is hidden, your browser might be whispering your activity to your ISP via DNS queries. Every time you type a URL, your computer asks a server where to go. A DNS leak means these requests are bypassing your VPN.
Use our free DNS Leak Test to run a standard test. You want to see only the IP addresses of your VPN provider’s servers. If you see even one entry belonging to Google, Comcast, or your local provider, you have a leak. Your ISP can still see exactly which domains you’re visiting.
Test 3: WebRTC Leak Test
WebRTC is a browser feature used for voice and video chat, but it has a nasty habit of decloaking VPN users by requesting your real IP directly from the hardware.
Use this free WebRTC Leak Test to see if your browser is running its mouth. A clean result will only show your VPN’s public IP. If the Private IP or Public IP fields show your actual, non-VPN address, your browser is leaking. The Windscribe extension blocks this by default, but other browsers may require a manual fix.
Test 4: Browser Fingerprint Test
Even with a masked IP, your browser configuration can identify you. Visit EFF’s Cover Your Tracks to see how unique your setup looks to trackers. If you have an anti-fingerprinting tool active, run the test once, then refresh or restart your browser and run it again.
Don't panic if it says you’re unique. On the open web, you almost always will be. The goal is to see your bits of identifying information change between sessions. If the fingerprint is inconsistent, it cannot be used to track you over time.

What Anonymous Browsing Can't Do
Even if you’ve built a perfect technical fortress, your behavior over time leaves a distinct silhouette. This is called long-term pattern correlation, and it’s the glass ceiling of anonymity.
Your daily browsing habits, the combo of sites you visit, and even the way you move your mouse create a profile. If someone collects enough data over a few months, they can often link those patterns back to the real you. While whistleblowers and activists try to fight this with exhausting levels of discipline, for the rest of us, it’s just the price of admission for using the internet.
Then there’s the heavy stuff: state-level adversaries. We’re talking national intelligence agencies with the power to watch the entire backbone of the internet. Even Tor admits it has limits here: it can’t protect you if an adversary is powerful enough to watch both where your data enters the network and where it leaves at the exact same time.
If your threat model involves a literal government coming after you specifically, you do need some seriously complex setups to hide… and even that isn’t bulletproof.
Finally, the most common way people get caught isn't a high-tech hack. It’s a "oops, I did it again" moment. You can have the most hardened, encrypted, multi-hop setup on the planet, but it’s all for nothing if you log into your personal Spotify or reuse a username you’ve had since middle school. The second you mention a personal detail in a thread or use your anonymous tab to check your real-name Gmail, your tech stack becomes a paperweight.
At the end of the day, your own discipline matters way more than the software you’re running.
Anonymous Browsing Frequently Asked Questions
Does a VPN make you anonymous?
No. A VPN is a vital tool for hiding your IP address from websites and your traffic from your ISP, but it is not a "make me invisible" button. It does nothing to stop browser fingerprinting, account-based tracking (like being logged into Google), or cookie profiling. Think of a VPN as a single layer of a bulletproof vest: it protects your vitals, but you still need the rest of the stack to be fully covered.
Is incognito mode the same as anonymous browsing?
Not even close. Incognito mode is essentially “forgetful mode” for your own computer. It clears your local history, cookies, and form data after you close the window, so your roommate doesn't see what you were looking at. However, your ISP, the websites you visit, and advertisers can still see you just fine. It is a local storage feature, not a network privacy tool.
Can my ISP see my activity if I use anonymous browsing tools?
If you use a VPN with encrypted DNS, your ISP only sees that you are connected to that VPN. They cannot see your traffic content or the specific websites you visit. Without a VPN, your ISP sees every domain you visit, even with HTTPS, because of leaks at the DNS or SNI level. If you add Tor to the mix, your ISP will know you are using Tor, but nothing about what you are doing inside it.
Is Tor truly anonymous?
Tor is the heavy hitter of anonymity, but it has limits. It can be vulnerable to traffic correlation if a powerful adversary (like a nation-state) is watching both ends of the connection. You also have to be careful with unencrypted traffic at the exit node and, most importantly, you have to avoid operational mistakes like logging into your personal Facebook account. For almost everyone not hiding from a government, Tor is more than enough.
How can I browse anonymously on Chrome?
Chrome is built by an advertising company, so it isn't anonymous by default. To make it work, you need a stack: run a VPN, install a tracker and ad blocker, add an anti-fingerprinting extension, and use a private search engine. Most importantly, log out of your Google account. If you want a higher baseline of anonymity without the DIY hassle, switching to Brave, Firefox (with Resist Fingerprinting enabled), or Tor Browser is a smarter move.
Does anonymous browsing slow down the internet?
It depends on the layer. A VPN adds a bit of latency, though with modern protocols like WireGuard, the hit is usually only 5% to 15%. Tor is significantly slower because your data is bouncing through three different relays around the world. On the flip side, tracker and ad blockers often make the web feel much faster because your browser isn't wasting time loading 40 different pieces of spyware just to show you a news article.