Can My ISP See My Browsing History in Australia?
- Written by: Times Media

Search this question and you get two answers that contradict each other. Forum threads say HTTPS encrypts everything, so your provider sees nothing. Security vendors say your provider sees every site you visit. Both descriptions were accurate at some point, and neither describes the connection you are using right now.
Australia adds a second layer: a data retention scheme that requires telecommunications and internet providers to store a defined set of customer records for at least two years. What that scheme covers is narrower than most people assume.
This article separates three questions — what your provider can see, what the scheme requires it to keep, and why those two things are not the same.
The Short Answer
Your internet provider can see which sites you connect to. It cannot read what is on those pages.
That split comes from how encryption works. HTTPS protects the contents of a page: the text you read, the details you type into a form, the individual pages you open within a site. It leaves the destination visible. Your provider sees that a connection went to a particular domain, when it started, how long it ran and how much data moved.
Australia's data retention scheme does not close that gap, and it does not widen it. The scheme lists the categories of records providers must keep. Web browsing history is not one of them.
What Your Internet Provider Can See
Four layers sit between you and a website, and they expose different amounts of information.
The Domain You Look Up. Before your device opens a connection, it asks a resolver where that site lives. This lookup is plain text by default, and by default it goes to your provider's resolver. Your provider sees the domain name you asked for, even when the connection that follows is encrypted.
The Name in the Handshake. Encrypted connections open with a handshake, and that handshake carries the server name in plain text on most connections today. The effect is a sealed envelope with the recipient written on the outside.
Addresses, Timing and Data Volumes. Destination IP addresses, connection times, session length and the amount of data moved are visible to whoever carries the traffic. Encryption does not conceal them.
What Your Provider Cannot Read. Page contents, form entries, message text and the individual pages you open inside a site sit behind HTTPS.
|
What Your Provider Can See |
What Your Provider Cannot Read |
|
The domain names your device looks up |
The contents of the pages you open |
|
The server name in the connection handshake |
Text you type into forms |
|
Destination IP addresses |
Messages sent through encrypted apps |
|
Connection times and session length |
The individual pages you open within a site |
|
Upload and download data volumes |
Search terms you enter on an encrypted site |
The domain layer is the part an encrypted tunnel changes. Testing that on your own connection costs nothing — a free VPN tier is enough to watch what drops out of your provider's view once traffic runs through one.
Your Phone Sits in the Same Position
Mobile data does not change the picture. Your mobile carrier occupies the position a home internet provider holds: it routes your traffic, it resolves your domain lookups, and it carries the same retention obligations.
Two details differ on a phone. Apps open connections in the background, which produces a steadier stream of domain lookups than a browser session does. And phones move between networks — home Wi-Fi, mobile data, a café — so the record of your connections is split across several operators rather than held by one.
The remedy is the one that works on a desktop. A free VPN for iPhone puts an encrypted tunnel between the handset and the carrier, and the domain-level view moves with it.
Why You Find Two Opposite Answers Online
The forum answer — HTTPS encrypts everything, so your provider sees nothing — describes the content layer correctly and skips the two layers above it. Domain lookups and handshake server names sit outside the encrypted payload.
The vendor answer — your provider sees everything you do — described the web before HTTPS became the default. On today's web it overstates what is visible by a wide margin.
Each answer stopped at a different point in time. Much of the Australian material on this question dates from 2015, written before encrypted DNS existed and before HTTPS covered the majority of traffic.
What Changes the Picture
Encrypted DNS. Encrypted DNS, using DoH or DoT, conceals your domain lookups from your provider. The lookup does not disappear. It moves to whichever resolver your device points at, and that operator sees it instead.
A VPN. A VPN routes your traffic through an encrypted tunnel to a server run by the VPN provider. Your internet provider then sees one encrypted connection to one address, plus timing and data volumes. Domain lookups, server names and destination addresses move inside the tunnel.
This is a transfer, not a deletion. The visibility that sat with your internet provider now sits with your VPN provider, which makes the identity of that provider the question worth asking.
What Does Not Change Anything. Incognito mode governs what your browser stores on your device. It has no effect at the network layer. Clearing your browser history works the same way: the record on your machine goes, and the record held by whoever carries your traffic was separate to begin with.
Three Things Worth Checking in Any VPN Provider
If the visibility moves to a VPN provider, three questions decide whether that is an improvement.
Has the no-logs claim been examined by an outside party? Every provider publishes one. An independent audit is what separates a policy from a statement.
Do the servers run in memory? RAM-only servers hold nothing after a restart, so there is no disk image to hand over or recover.
What does signing up require? An email address and a payment record are themselves a log, held by the same company that carries your traffic.
As a worked example: X-VPN's no-logs policy was independently audited in 2026 under the ISAE 3000 (Revised) assurance standard, its servers run in RAM rather than writing to disk, and DNS, IP and WebRTC leak protection are included on the free tier as well as the paid one. Its free tier runs with no sign-up and no data cap. Those three questions apply to whichever provider you look at.
Common Questions
Can my internet provider see my browsing history on my phone?
Your mobile carrier sits in the position a home provider holds and carries the same retention obligations. On mobile data, the carrier resolves your domain lookups and sees which addresses you connect to.
Does incognito mode stop my provider seeing what I browse?
No. Incognito mode governs what your browser stores on the device. Your provider's view of the connection is unchanged.
Does the retention scheme record which websites I visit?
No. Section 187A(4) of the Telecommunications (Interception and Access) Act 1979 leaves out the contents of a communication and the internet addresses a communication was sent to. Providers keep subscriber details, connection times and service types, not a list of the pages you opened.
Can my provider still see what I browse if I use a VPN?
It sees an encrypted connection to a VPN server, plus when it ran and how much data moved. The domain-level detail moves to the VPN provider.
The Answer Sits Between the Two You Find Most Often
Your provider sees where your connections go, not what you do once you arrive. Australia's retention scheme requires less of it than the name suggests. The useful question is not whether anyone can see your traffic — it is who, and whether you have reason to trust them.












