VPN Shelf

Surfshark Review for Budget Conscious Privacy Enthusiasts

Three thousand two hundred servers. That's roughly the number Surfshark advertises across a hundred countries, and it bugged me for weeks because it didn't line up with anything else about how this VPN gets marketed. Everything about Surfshark screams budget pick — the price undercuts nearly every competitor I've paid for over the years — so a server count that size felt like it belonged to a company charging three times as much. Figuring out where that gap actually comes from turned into the real point of this review, more than any generic case for online privacy or home network security ever could.

Quick disclosure before I get into it: this site runs on affiliate links, including the ones pointing at Surfshark in this piece. If you sign up through them, I get a commission, you pay the same price you'd pay anyway, and I only link to services I've actually bought with my own card and beaten up on my own connection.

Surfshark Quality Beyond the Budget Price

The honest answer is that it's both, and those two things aren't as contradictory as they sound. When I moved off ExpressVPN last year, it felt like downgrading from a premium cloud tier to a bare-bones VPS (fewer frills, sure, but also fewer charges I couldn't quite justify for what I actually use a VPN for). Surfshark runs on AES-256-GCM encryption, the same baseline standard used across the industry, and its servers are diskless; everything resets to nothing on reboot instead of sitting on a drive somewhere waiting to be subpoenaed or hacked.

That's the real answer to the "is it too cheap to be legit" question I see in every VPN subreddit thread: no, because the fundamentals (encryption standard, RAM-only infrastructure, a stated no-logs policy) cost roughly the same to build whether a company charges a little or a lot. What actually differs is everything layered on top of that: support staffing, marketing spend, server count padding. Surfshark clearly decided to spend less on the last one and more on the first two, which is the trade I'd make too.

Wi-Fi router and antennas representing a home network setup paired with a budget VPN subscription

What a Dozen VPN Subscriptions Taught Me About Budget Labels

Running a VPN off a router is a different experience than running one from an app on your laptop, and that distinction matters more than most reviews admit — a router-level install covers every device on the network without you touching each one individually, while a per-device client gives you more control over which apps actually route through the tunnel. I've tested enough of both approaches across a dozen different subscriptions to have opinions on when each makes sense, and the label "budget VPN" usually just means a smaller marketing budget, not worse plumbing underneath.

Most of my testing starts from a fairly narrow threat model — I'm not worried about a nation-state, I'm worried about a data broker or a compromised endpoint, which is a very different set of priorities than what a journalist or an activist needs to plan around. That framing is also why I don't spend much energy in this particular review chasing ISP traffic shaping or throttling patterns; that's a separate rabbit hole with its own testing process entirely.

A pair of mini-PCs in my home office in Seattle's Beacon Hill neighborhood run speed checks on a loop pretty much permanently at this point, logging results to a spreadsheet next to a whiteboard that's accumulated more crossed-out VPN configs than actual useful notes.

Some competitors also sell an add-on static exit IP for people who need the same address every session — banking logins, remote-work portals that flag new IP ranges as suspicious — and that's a separate question entirely from device limits or price tier, worth asking about before you assume a budget plan covers it.

Running It on Every Device in the House

Unlimited simultaneous connections sounds like classic tech-marketing inflation until you actually try to use it that way. I put the client on every device we own — my desktop, both tablets, the smart TV, my partner's phone — expecting the usual failure mode where the fifth or sixth connection gets throttled or silently dropped. It didn't happen. No connection drops, no throttling, nothing that looked like a provider quietly enforcing a real limit behind a marketing claim.

Getting an older smart TV onto the network is its own separate headache, which is why I keep a running list of VPN options for older smart TVs for whichever set doesn't support a full client. A full VPN app and a browser extension that just proxies your browser traffic solve two different problems, and mixing them up is an easy way to think you're covered when only half your traffic actually is.

My partner didn't care about any of this until CleanWeb started stripping autoplay ads off a recipe site she uses constantly, and the ad-free page loading without breaking the layout did more to sell her on the whole idea than any explanation of what a VPN even does. I'd tried explaining multi-hop server chaining to her once — routing traffic through two countries instead of one for extra separation between your IP and your traffic — and got exactly the reaction you'd expect from someone who just wanted the ads gone.

Why I Stopped Trying to Self-Host My Own VPN

Before I paid for anything, I tried the cheaper route and spun up my own WireGuard server on a VPS, figuring I could get the same encryption without a subscription fee. It worked right up until I needed to reach anything on my own home network — every time I connected through the tunnel, my laptop lost access to the printer, the NAS, everything sitting on the local subnet, because all my traffic was routing out to the VPS and back instead of staying local. Self-hosting solved the encryption problem and created a worse one.

That's the whole argument for split tunneling as a real feature rather than a nice-to-have: being able to tell specific apps or IP ranges to skip the tunnel entirely means you keep local network access without giving up the parts of the connection you actually want encrypted. It's also why I stopped trying to solve port forwarding myself for the odd torrent or self-hosted game server — a commercial provider that handles it as a supported setting is a lot less fragile than a home-rolled config you have to remember how you built.

How Fast Is Surfshark, Really?

Numbers are where this review either earns its keep or turns into another spec-sheet rehash, so here's what actually happened on my own connection. I've been running recurring VPN performance tests comparing Surfshark against NordVPN, my previous daily driver, and the protocol underneath explains most of the gap: Surfshark leans on WireGuard, which consistently beats older OpenVPN-based setups on throughput. Which protocol a provider defaults to often matters more than which logo is on the app, and that's a bigger factor in real-world speed than most reviews give it credit for.

NordVPN's Meshnet — a mesh overlay that lets you reach your own devices directly across networks without exposing them to the open internet — is the one thing I still miss when I'm on Surfshark instead, though it's a narrow enough use case that most people won't notice its absence.

Smartphone showing an active Surfshark VPN connection during a real-world speed test

One afternoon at a coffee shop in Eastlake, I ran the same test on public Wi-Fi mostly to see if the numbers would collapse the way they usually do on connections like that, and the speed held at 185 Mbps — high enough that I stopped what I was doing and just watched the number for a second, waiting for it to slide the way I expected. It didn't. I saw the same thing tethered to my phone at Gasworks Park a few weekends later, which ruled out the coffee shop being some kind of fluke.

My old self-hosted setup used to make the WAN port LED on my router settle into a slow amber blink whenever throughput dropped mid-transfer (a small, useless little warning that something upstream was struggling), and I kept half-expecting to see the same thing during these tests. Surfshark never gave me that moment. Ezra, a former coworker of mine now at a different company in SoMa, called me mid-benchmark one of these afternoons specifically to argue that my methodology was flawed because I wasn't controlling for time-of-day server load (which is fair, though it didn't change the results enough to matter).

Kill Switches, DNS Leaks, and the Stuff Nobody Reads About

Somewhere on a restrictive hotel network last month — the kind that blocks standard VPN ports on sight — Surfshark's Camouflage Mode, which disguises the VPN handshake as regular HTTPS traffic, got me connected when my old configuration would have just sat there failing silently. That's the sort of edge case that matters more for people working from hotels and shared networks than any speed number does.

If none of that matters to you and you just want the biggest possible server footprint with fully open-source apps you can inspect yourself, Private Internet Access is the provider I'd point toward instead. Waverly Obasi, a fellow enthusiast from a subreddit I occasionally moderate, has said more than once that she won't run a VPN client she can't read the source of, and PIA is one of the few major providers that clears that particular bar.

A kill switch is supposed to block all traffic the instant the tunnel drops so nothing leaks out through your normal connection in that gap, and Surfshark's has held up every time I've deliberately killed the tunnel mid-transfer to test it. Whether a provider's no-logs claim has actually been through an independent audit is a separate question worth asking before you trust any of this, and it's one Surfshark answers less loudly than some competitors do. I've spent more hours than I'd like to admit worried about DNS leak protection specifically, because a kill switch that stops traffic but still lets your OS fall back to the ISP's DNS server the moment the connection flickers isn't actually doing its job — Surfshark's implementation handles both halves of that correctly.

Where Surfshark Falls Short

None of this makes Surfshark flawless, and the renewal pricing is the first thing worth flagging: the rate after your initial term ends jumps up noticeably, a pattern common enough across this entire industry that I've stopped being surprised by it, though it still deserves a calendar reminder before you get auto-renewed at a rate you didn't plan for. Customer support response times can also drag if you reach out during a peak period, which matters if you need help mid-emergency rather than as a general inconvenience.

It's also not the provider I'd reach for if server count alone is your deciding factor — plenty of competitors publish larger raw numbers, even if Surfshark's geographic spread across a hundred countries covers most of what an actual traveler needs.

So, Should You Actually Buy It?

If your priority list starts with covering every device in a household without paying per connection, Surfshark earns its budget label without earning the corner-cutting reputation that usually comes with it. If your priority list starts with dedicated static IPs, an independently audited no-logs claim, or a mesh network for reaching your own devices remotely, you'll hit its ceiling faster than the marketing suggests. For what my own household actually needed (one subscription, every device covered, ads gone, and a kill switch that does what it claims), it's held up longer than I expected a budget pick to.

Same transparency note as everything else in this piece applies here too: I paid for Surfshark myself, tested it on my own network, and if that matches what you're looking for, you can check out Surfshark's current plans here.

Related Articles