Surfshark is recognized among the top VPN services globally, providing an efficient means to secure your online privacy and enhance your web freedom. The service is known for its ability to spoof locations, block activity trackers, and circumvent VPN detection systems. With its commendable speeds and support for unlimited simultaneous connections, Surfshark is an excellent choice for both families and travelers.
Features
- Rating: 4.5/5
- Price: $2.49 – $12.95 per month
- Refund Period: 30 days
- Headquarters: The Netherlands
- Devices per License: Unlimited
- Servers: 3,200
- Server Locations: 133 locations in 95 countries, including the USA, UK, Canada, Australia, India (virtual), and Singapore
- Streaming Sites Unblocked: Netflix, Disney+, Amazon Prime
- Supports Torrenting: Yes
- No Logs Policy: Yes
- 24/7 Customer Support: Yes
- Website: Surfshark
Established in 2018, Surfshark initially operated out of the British Virgin Islands—a VPN-friendly jurisdiction. The company launched with a mobile app for iOS devices, followed by a smart DNS system, Trust DNS, for Android users. Although Trust DNS did not offer security features, it provided efficient management of internet connections without significant slowdowns.
In its early days, Surfshark prioritized demonstrating its commitment to privacy by engaging Cure53, a cybersecurity firm from Germany, to conduct a comprehensive audit. This audit validated Surfshark’s no-logs policy and confirmed the absence of activity record retention.
Currently, Surfshark offers applications for all major operating systems, along with browser extensions for Chrome, Firefox, and Edge. Additionally, Surfshark VPN can be configured on smart TVs, gaming consoles such as Xbox, TV boxes, streaming systems including Fire TV and Apple TV, and routers.
Although Surfshark’s headquarters was initially in the British Virgin Islands, the company, founded by a Lithuanian team, now operates from the Netherlands. In 2021, Surfshark merged with NordVPN, a leading VPN provider also headquartered in Lithuania. Despite the merger, the two brands continue to operate separately while collaborating on technological advancements.
Privacy and Security
Surfshark provides a robust VPN service, though it may not match the leading VPNs such as ExpressVPN, NordVPN, and CyberGhost in terms of features. This section explores Surfshark’s security measures and identifies areas for potential improvement.
Headquarters Location
In October 2021, Surfshark relocated its headquarters from the British Virgin Islands to the Netherlands. While this move may have been driven by business considerations, it has potential security implications. The European Union’s ongoing efforts to impose stricter controls on internet access could lead to mandatory data retention requirements for ISPs, potentially extending to VPNs in the future. This development could necessitate another relocation for Surfshark to maintain its no-logs policy.
How Surfshark VPN Works
A Virtual Private Network (VPN) was initially designed for business use, allowing remote workers to connect to office networks securely. VPNs protect data privacy by encrypting it during transmission. However, since data travels in packets with visible headers, complete encryption is challenging. To address this, VPNs employ encapsulation, where the entire packet is encrypted and placed within an outer packet addressed to the VPN server.
Surfshark’s VPN service involves both a client application (Surfshark app) and a server. Users select a destination server from the app, and all internet traffic is routed through this server. ISPs only log data related to the VPN server address, rather than individual packet destinations. Upon reaching the VPN server, the outer packet is removed, and the inner packet is decrypted, maintaining encryption for the data payload. This encapsulation process, known as tunneling, ensures secure and private internet connections.
The IP packet header includes the source IP address of the packet, which the VPN server replaces with its own address. This substitution is a key benefit of using a VPN service.
Internet IP addresses must be globally unique and are allocated by a central authority that distributes address ranges to institutions in various countries for sale. This system allows IP addresses to be traced to specific countries. Many websites use IP address locations to regulate access to their content.
As a result, you may encounter access restrictions when visiting a website due to your geographical location. Selecting a VPN server in the appropriate country can bypass these restrictions and grant you access.
Surfshark VPN Protocols
Network and internet technologies are governed by protocols—sets of rules that ensure compatibility between different systems. Surfshark offers several VPN protocols:
- WireGuard: Available for Windows, macOS, iOS, Android, and Amazon Fire OS, WireGuard is Surfshark’s preferred protocol due to its robust security and lightweight design.
- IKEv2: Supported on macOS, iOS, and Android, IKEv2 is known for its speed and efficiency, particularly in mobile environments.
- OpenVPN: Compatible with Windows, Linux, macOS, Android, Amazon Fire OS, and routers, OpenVPN is widely used but is gradually being replaced by WireGuard. Its longstanding use and extensive testing contribute to its security reputation.
When using OpenVPN, users must choose between TCP and UDP:
- TCP (Transmission Control Protocol): TCP adds session controls, such as packet loss detection and retransmission, and ensures packet sequencing. While this enhances reliability, it can slow down connections.
- UDP (User Datagram Protocol): UDP does not include session controls, which is advantageous for streaming and VoIP applications that manage these functions independently. UDP offers better performance for these use cases.
Surfshark Encryption
Surfshark employs a two-phase encryption approach: AES-256 and RSA-2048.
- AES-256 (Advanced Encryption Standard): This symmetric cipher, used by the CIA and the US military, employs a single key for both encryption and decryption. The 256-bit key length provides strong security, making it resistant to brute-force attacks.
- RSA-2048: This public key encryption system safeguards the transmission of the AES key. It uses different keys for encryption and decryption, enhancing security. While RSA-2048 is considered less secure than longer keys (such as 4096 bits used by other VPNs like ExpressVPN and NordVPN), it remains a robust standard. RSA is also utilized for authentication, ensuring that only the legitimate owner of a public key can decrypt information encrypted with it. When the Surfshark VPN client connects to the server, it uses the server’s key from its SSL certificate to encrypt a challenge, which the server must respond to correctly to verify its identity and prevent man-in-the-middle attacks.
Surfshark DNS Leak Protection
The Domain Name System (DNS) serves as a bridge between Internet Protocol (IP) addresses and web addresses (URLs). While web addresses are user-friendly, routers operate solely with IP addresses. Consequently, before a browser can retrieve a webpage, it must first resolve the IP address of the relevant web server through the DNS network.
Your Internet Service Provider (ISP) has the potential to monitor your web activity and restrict your online freedom through DNS. By default, your browser uses the DNS servers provided by your ISP. Without the correct IP address, your browser cannot load the desired webpage. ISPs can exploit this by returning incorrect IP addresses to block specific websites, a practice that is unfortunately common.
Surfshark counters these ISP tactics by offering its own DNS system. When the VPN is active, all DNS queries are directed to Surfshark’s DNS resolver, ensuring that your browsing remains secure and private.
A DNS leak occurs when a VPN connection fails to contain all traffic within its encrypted tunnel. If a VPN service lacks its own DNS servers, it must route DNS queries externally, which can lead to unencrypted traffic being exposed to the ISP. This exposure allows the ISP to log user activity, as IP addresses accessed by the user are visible in plaintext.
This vulnerability underscores why relying on inexpensive or free VPN services can be problematic, as they often lack the resources to manage their own DNS resolvers.
Surfshark IP Leak Protection
An IP leak arises when a VPN fails to protect all traffic, inadvertently exposing your IP address. Keeping the VPN active at all times helps prevent IP leaks. However, brief interruptions in internet service can terminate the VPN session, causing temporary exposure during reconnection.
To address this risk, Surfshark includes a kill switch feature. When enabled, the kill switch disables your network connection if the VPN disconnects, preventing unprotected internet activity until the VPN is reactivated. This feature effectively mitigates the risk of IP leaks.
Additionally, Surfshark offers a Bypasser tool that allows you to deliberately route specific web traffic outside the VPN tunnel through split tunneling. This intentional traffic routing is not classified as an IP leak.
Website Blocking and Cross-Border Access
The Surfshark VPN app provides a range of server locations globally, crucial for bypassing geographic access restrictions imposed by various websites and internet systems. These restrictions are particularly stringent for streaming services, which work diligently to prevent users from circumventing their location detection mechanisms using VPNs. Similarly, access controls are frequently applied by employment sites, news outlets, and gaming platforms.
For instance, Hulu restricts account access to users within a specific country, while services like Netflix, Disney+, and Amazon Prime Video offer different content libraries based on the user’s location. Surfshark stands out with its ability to overcome these geographical barriers.
A notable example is YouTube TV, which employs advanced measures to prevent cross-border access, including connection request verification and GPS-based location checks. Surfshark successfully navigates these controls by aligning the device’s GPS location with the selected VPN server location.
Gaining cross-border access to sites, particularly streaming services, is a significant challenge, as these systems are adept at detecting and blocking VPN traffic. Achieving access to US Netflix is considered a benchmark in the VPN industry, and Surfshark excels in this area.
Test Results for Streaming Services with Surfshark
- Netflix: Access confirmed for Hong Kong, the UK, the USA, and France.
- Disney+: Access confirmed for the UK, the USA, and France.
- ITV Hub: Access confirmed from the USA.
- Channel 4: Access confirmed from the USA.
- ABC: Access confirmed from the UK.
- NBC: Access confirmed from the UK.
Surfshark also provides cross-border access to HBO Max, ESPN+, and Amazon Prime Video. However, it has been unable to bypass the BBC iPlayer’s VPN detection and cannot access Hulu.
Pricing
Surfshark provides a single plan with three subscription options. Pricing is more favorable with longer subscription periods, although payment is required in full upfront.
The Surfshark website displays the following prices:
- 1-Month Plan: $12.95 per month
- 12-Month Plan: $59.76 (equivalent to $4.98 per month)
- 24-Month Plan: $59.76 for the first two years (equivalent to $2.49 per month)
Upon examining the pricing structure, several observations can be made:
- The cost for a two-year subscription is equivalent to that of a one-year subscription.
- The monthly rate for the 12-month plan is incorrectly stated; the correct calculation is $59.76 divided by 12, which equals $4.98.
- The 24-month plan is indicated as being valid for the first two years.
The following clarifications address these anomalies:
- The 12-month plan is billed at $47.88 for the first year and $59.76 for each subsequent year.
- The 24-month plan covers two years initially. Upon renewal, it transitions to an annual payment cycle at $59.76 per year.
Thus, both the one-year and two-year plans increase in price after the initial subscription period.
Additional security services can be added through Surfshark One for an extra $1.49 per month. This package includes Antivirus, Alert, and Search features.
All plans are set to auto-renew at the end of each payment period unless payment card details are removed from your Surfshark account settings.
Prices on the Surfshark website vary based on your location, with local sales tax (VAT) added to the quoted prices.
Surfshark offers a 30-day money-back guarantee on all plans, including the one-month plan. This guarantee applies only to the first subscription. Refunds are not available after the plan renews. If you cancel and then initiate a new subscription, you are only eligible for a refund on the initial subscription if six months have passed since the previous refund. Multiple refund claims are not permitted if an account is reopened.
Payments for Surfshark subscriptions can be made using credit cards (Mastercard, Visa, American Express, Discover), PayPal, Google Pay, Amazon Pay, or cryptocurrency (Bitcoin, Ethereum, Ripple).
An email address is required during the order process. However, unlike many VPN providers, Surfshark does not require email verification to activate the account. After payment, you will be prompted to create a password for your account. Notably, Surfshark’s password creation system checks known data breach records to ensure the chosen password has not been compromised.
Speed Tests
Performance tests for Surfshark were conducted in the UK using a wireless mobile internet system provided by the 3 network, a subsidiary of CK Hutchison Holdings. The VPN protocol was set to WireGuard, and tests were performed using the Ookla Speedtest tool.
Initial tests without the VPN yielded:
- Download Speed: 10.34 Mbps
- Upload Speed: 3.22 Mbps
Enabling the VPN, with the server located in the same city, resulted in:
- Download Speed: 11.89 Mbps
- Upload Speed: 1.50 Mbps
The increase in download speed and reduction in upload speed can be attributed to the variability inherent in wireless internet services.
Testing long-distance connections revealed no significant speed degradation. For example, a test to Sydney, Australia, yielded:
- Download Speed: 10.46 Mbps
- Upload Speed: 3.96 Mbps
These speeds were comparable to those achieved with local connections, and the upload speed was even higher.
Using the Surfshark server in Manchester improved download speeds:
- Download Speed: 13.47 Mbps
- Upload Speed: 4.05 Mbps
This improvement was consistent across multiple test runs, exceeding typical variability caused by wireless instability. The benefits of using Surfshark increased with distance.
International connections also showed speed improvements. For instance:
- Connecting to Sydney through a VPN server in New York: Download Speed: 13.53 Mbps, Upload Speed: 3.15 Mbps
- Connecting to Sydney through a Surfshark server in Hong Kong: Download Speed: 12.26 Mbps, Upload Speed: 3.43 Mbps
These results demonstrate that Surfshark enhances speeds on long-distance connections, which is advantageous for accessing cross-border streaming services and for international online gaming.
Installation Instructions
To install the Surfshark VPN application on Android devices, please visit the Google Play Store. For Mac, iPad, and iPhone users, the app can be downloaded from the Apple App Store. Both app versions offer a 7-day free trial, available exclusively with the one-year subscription plan.