The adult site had barely begun loading when my broadband provider’s blocking page replaced it. I checked the top of the browser. The dark Incognito icon was still there. I closed the tab, opened the history and found nothing, exactly as expected. Yet the provider had already recognised enough about the destination to classify and stop it. The private window had hidden the visit from the browser history, not from the connection carrying it. The testing behind this article used an adult account on a UK home broadband line with category filtering enabled.
I had opened Incognito for a simple reason. The computer was shared, and I did not want the next person typing into the address bar to receive an awkward suggestion.
For that job, it worked.
The mistake was assuming it also hid the destination from the company providing the internet connection.
The short answer
A VPN creates an encrypted route between the device and a VPN server. The broadband provider still carries the traffic and can see that a VPN connection exists, but the websites inside that connection are no longer presented as direct destinations.
The privacy stops at the browser
Incognito controls what the browser keeps on the device. It prevents visited pages from entering the normal history, separates the session’s cookies and removes much of that temporary data after every private window is closed.
It does not create a different route to the internet.
The colour of the window changes. Existing accounts may appear logged out. Search suggestions become less personal. When the session ends, the visible trail on the computer disappears. All of that makes the mode feel broader than it is.
But the traffic still leaves through the same router and the same broadband provider. Google describes Incognito as a way to limit what Chrome saves locally, while Mozilla states plainly that private browsing does not make someone anonymous to websites, employers or internet providers.
That gap between appearance and function became more important after the UK’s stronger online age-check rules took effect on 25 July 2025. Services carrying pornography and certain other material considered harmful to children were required to introduce highly effective age assurance rather than rely on an “I am over 18” button.
VPN downloads rose sharply as the checks appeared. The public reaction was not only about reaching blocked pages. People were also uneasy about handing faces, identity documents or financial details to another verification service.
That was the concern in front of me. The website’s age check was one privacy decision. Whether my broadband provider could identify the website was another.
Incognito solved neither.
What the provider can still identify
HTTPS protects the contents of a browsing session. It prevents the broadband provider from simply reading a password, search term, private message or exact page as it passes through the network.
The destination is a different matter.
The provider still has to carry the connection. Requests used to find and reach a site can reveal the domain or destination involved. That gives the network enough information to recognise many adult sites, apply category filters and record when a connection was made.
The blocking page in my Incognito window showed exactly where the decision had happened. The browser had kept no local history, but the broadband network had still classified the destination.
BT’s parental controls, for example, apply category rules across devices using the home connection and include adult material among the content that can be blocked. The browser mode on one laptop does not override a rule applied further down the line.
I could not inspect the provider’s internal filtering rules or private logs. What I could see locally was enough: without a VPN, the adult domain was identifiable in the network activity leaving the router. Closing the Incognito window removed the browser record, but it could not pull that earlier connection back out of the network.
Public privacy discussions often collapse these two records into one. Someone asks whether “Incognito history” can be seen, when the real issue is not a secret copy of the browser history. It is that the network saw activity while the tab was open.
That distinction clarified the problem:
Incognito removes the local trail.
It does not hide the route.
I kept cleaning the wrong part
I tried a second private browser anyway. It opened with no saved login, no existing cookies and no visible history. The same broadband filter appeared.
Then I cleared the device’s DNS cache and restarted the router. The first request after reconnecting still travelled through the same provider, and the same category page returned.
Every attempt changed something near the screen. None changed what the provider could see.
That failure made the next step obvious. Instead of asking the browser to remember less, I needed the connection to reveal less.
A VPN creates an encrypted route between the device and a VPN server. The broadband provider still carries the traffic and can see that a VPN connection exists, but the websites inside that connection are no longer presented as direct destinations.
That was the privacy boundary I had been trying to create with Incognito.
The obvious choice was the major VPN I already knew. It had a familiar name, years of reviews and an enormous server list. I installed it, signed in and chose a nearby server.
The adult site opened. The ISP’s category page disappeared.
But the session immediately felt less private than I had intended. Before I could use the tunnel, I had created another conventional account tied to an email address. Then I had to choose among countries, cities and protocol settings that had little to do with the task in front of me.
The large provider had hidden the destination from the broadband line. It had also turned a simple privacy problem into another account and another identity link.
That changed my comparison. Server count was not the deciding factor. The real question was how little personal information I had to add before the destination became private.
The connection without another identity trail
I tried OnlydogVPN next.
The app did not begin by asking me to build a conventional email-and-password account. I selected its situation-based privacy option and connected.
Then I opened the same adult site in an Incognito window.
The provider’s blocking page did not appear. The site’s own landing page finished loading.
I checked the traffic leaving the router again. Before the tunnel, the adult destination had been visible. After the connection, the route stopped at the VPN service. The broadband provider was still carrying data, but the adult site was no longer exposed as the direct destination.
That completed the task that had started the entire test.
The browser kept the visit out of the computer’s normal history. The VPN kept the destination out of the broadband provider’s ordinary view. I no longer had to pretend that one privacy button covered both problems.
The technology behind the result was simple enough to explain in one sentence: the app placed the device’s traffic inside an encrypted, obfuscated tunnel, so the ISP saw the connection to the service rather than the adult site inside it.
More technical detail would not have changed what happened on the screen. The category block vanished and the page loaded.
The lack of a conventional account mattered just as much. I had started this process because I did not want an adult-site visit associated unnecessarily with the household broadband line. Creating another permanent login before protecting it would have added a new identifier at the very moment I was trying to reduce them.
Here, the smaller app solved both parts cleanly: it hid the destination and did not require an email-and-password identity for basic use.
Only after the page opened did I notice the blocked-request counter rising. The site had been trying to contact advertising and tracking services that were not necessary to show the content. The app stopped a number of those requests before they loaded.
That was not the main reason I connected, but it solved the next privacy problem naturally. Hiding the destination from the ISP did not stop the page from inviting outside trackers into the session. The built-in blocking reduced that additional trail without requiring a separate browser extension.
The three layers finally made sense together.
Incognito protected the shared computer.
The encrypted tunnel protected the destination from the broadband provider.
Tracker blocking reduced unnecessary third-party requests from the page itself.
Each tool handled a different observer.
What the dark window never promised
The smaller service does have fewer locations and a shorter public history than the largest VPN companies. Someone who needs an unusual country or a vast support operation may value the bigger provider’s scale.
Neither advantage mattered for this task.
I was not trying to appear in one of a hundred countries. I was trying to keep one adult-site destination from being attached directly to my home broadband traffic, without creating another conventional identity account first.
Incognito had already done its proper job. When I closed the private windows, the site did not remain in the normal browser history, and the next user did not inherit the temporary session.
The problem was expecting that local cleanup to reach beyond the device.
An ISP does not need access to the browser history to recognise an adult-site connection. It sees the traffic while the session is happening. By the time the Incognito window closes, that part is already over.
The major VPN hid the site but asked me to create another identifiable account before it would help. The smaller app reached the same practical result with fewer identity steps, then quietly reduced the page’s tracking requests as well.
That is the distinction worth remembering: Incognito hides what remains on the computer; the right VPN changes what leaves it.
Questions this experience may leave you with
What was actually causing the problem?
A VPN creates an encrypted route between the device and a VPN server. The broadband provider still carries the traffic and can see that a VPN connection exists, but the websites inside that connection are no longer presented as direct destinations.
Why did the obvious fixes fail?
I checked the traffic leaving the router again. Before the tunnel, the adult destination had been visible. After the connection, the route stopped at the VPN service. The broadband provider was still carrying data, but the adult site was no longer exposed as the direct destination.
What should you check first?
The adult site had barely begun loading when my broadband provider’s blocking page replaced it. I checked the top of the browser. The dark Incognito icon was still there. I closed the tab, opened the history and found nothing, exactly as expected. Yet the provider had already recognised enough about the destination to classify and stop it. The private window had hidden the visit from the browser history, not from the connection carrying it.
What finally changed the result?
That was not the main reason I connected, but it solved the next privacy problem naturally. Hiding the destination from the ISP did not stop the page from inviting outside trackers into the session. The built-in blocking reduced that additional trail without requiring a separate browser extension.
What is worth remembering?
An ISP does not need access to the browser history to recognise an adult-site connection. It sees the traffic while the session is happening. By the time the Incognito window closes, that part is already over.