What Your Internet Service Provider Can Actually See
Photo: DockedReads.com | Information Made Easy editorial
Key Takeaways
- ISPs can see which websites you connect to, even if they cannot read the content of encrypted pages.
- DNS queries — the requests that translate domain names into IP addresses — are visible to your ISP by default.
- HTTPS encryption hides the specific content of a page, but not the fact that you visited a site.
- A VPN shifts visibility away from your ISP, though it does not make you anonymous on the internet.
- ISPs in the US can share or sell certain non-sensitive browsing data under current federal rules.
The Basic Picture: Your ISP as a Network Gatekeeper
Every time you load a webpage, stream a video, or send a message, that data travels from your device through your ISP's infrastructure and out to the broader internet. Your ISP assigns you an IP address, routes your traffic, and — by the nature of how the internet works — handles every packet of data that enters or leaves your home network.
This structural position gives ISPs passive visibility into your network activity. They are not necessarily reading everything, but the information passes through equipment they operate. Think of it like a postal service: they know the return address, the destination, and how often you send mail, even if they do not open each envelope.
It is worth understanding that this visibility is not inherently sinister — ISPs need this access to manage their networks, diagnose outages, and enforce terms of service. The question worth asking is: what exactly can they see, and what stays private?
ISP Visibility Varies by Connection Type
What ISPs Can See: DNS Requests and Connection Metadata
The clearest window your ISP has into your activity is through DNS queries. When you type a web address into your browser, your device asks a DNS server to translate that human-readable name (like example.com) into a numeric IP address. By default, that request goes through servers operated by your ISP — and it is visible to them in plain text, even when the site itself uses HTTPS.
Beyond DNS, ISPs routinely log:
- IP addresses — both your assigned address and the destination servers you contact.
- Timestamps — when connections were made and for how long.
- Data volume — how much data was transferred to and from each destination.
- Protocol type — whether you were browsing the web, streaming video, or using peer-to-peer file sharing.
This category of data is often called metadata, and it can reveal a great deal about your habits even without exposing the actual content. To understand the broader landscape of how data about you is collected online, the plain-language guide to personal data on the internet offers a useful reference.
~90%
Share of web traffic using HTTPS
Google's Transparency Report has consistently tracked HTTPS usage above 90% across Chrome browser page loads in recent years.
2017
Year US ISP privacy rules were rolled back
A Congressional resolution in 2017 nullified FCC rules that would have required ISPs to obtain opt-in consent before sharing browsing data with advertisers.
Every packet
Traffic routed through your ISP
All data leaving or entering a home network passes through the ISP's infrastructure by design, giving them structural access to connection-level metadata.
What HTTPS Protects — and What It Doesn't
When a website uses HTTPS (signaled by the padlock icon in your browser's address bar), the content of your communication with that site is encrypted. Your ISP can see that you connected to a particular domain, but they cannot read the text of articles you viewed, the passwords you typed, or the details of a form you submitted.
However, HTTPS does not hide:
- The domain name itself (e.g., your ISP knows you visited a medical information site, even if not which specific page).
- The frequency and timing of your connections to that domain.
- The approximate size of the data exchanged, which can sometimes allow educated guesses about content type.
This is why the distinction between privacy and security matters. HTTPS provides strong security — protecting your data from tampering or interception by third parties — but it offers limited privacy from the ISP itself. Many people conflate the two, and it is a common source of confusion. The article on online privacy myths explores several related misconceptions in more depth.
Use Encrypted DNS to Reduce Metadata Exposure
Legal Context and What ISPs Can Do With Your Data
In the United States, ISPs are classified under federal communications law in a way that currently gives them some latitude to collect and share non-sensitive browsing data. A 2017 Congressional resolution overturned FCC rules that would have required ISPs to obtain opt-in consent before sharing certain data with advertisers. Since then, ISP data practices are primarily governed by the providers' own privacy policies and a patchwork of state laws — with California's consumer privacy law being one of the more comprehensive examples.
In practice, this means your ISP may, depending on their policies, share or use anonymized browsing data for targeted advertising purposes. Sensitive categories — such as financial account information or health data — generally receive stronger protection.
If you want to reduce what your ISP can observe, two practical steps are commonly discussed: using a reputable encrypted DNS service (which moves DNS queries away from your ISP's servers) and using a VPN. For a clear comparison of what these tools actually accomplish, see VPN vs. private browsing.
“Metadata absolutely tells you everything about somebody's life. If you have enough metadata, you don't really need content.”
— Stewart Baker, Former General Counsel, National Security Agency
Frequently Asked Questions
The content on this site is for informational purposes only and is not a substitute for professional advice. Always consult a qualified professional for guidance specific to your situation.
