What Is a VPN Kill Switch? What Actually Happens When Your Connection Drops

A VPN can fail silently. A kill switch is the feature that decides what your device does in that exact moment — and not all kill switches handle it the same way.

Quick answer

A VPN kill switch is a feature that blocks your device's internet traffic automatically if the VPN connection drops unexpectedly, so your traffic never quietly falls back to your normal, unencrypted connection and exposes your real IP address without warning. It works by monitoring the VPN tunnel and either shutting off network access entirely or killing specific apps the instant the tunnel is no longer active, then restoring normal connectivity once the VPN reconnects. Kill switches differ in scope (system-wide versus per-app) and in how instantly they react, which matters most on unstable networks like public Wi-Fi or mobile data where brief VPN drops are common. It is a genuinely important setting to have switched on if the reason you use a VPN is to consistently hide your IP address or keep traffic off an untrusted network, and it is worth testing rather than assuming it works.

What is a VPN kill switch, in plain terms?

A VPN kill switch is a safety feature, built into most VPN apps, that cuts off your device's internet access the moment the VPN connection drops — rather than letting your device quietly keep browsing over your normal, unprotected connection as if nothing happened. The name is dramatic but the mechanism is straightforward: the VPN app continuously monitors whether the encrypted tunnel to the VPN server is up, and if that tunnel disappears for any reason it did not expect, it blocks outgoing (and usually incoming) network traffic until the tunnel is re-established.

The problem it solves is a genuinely common one. VPN connections do not fail loudly. A laptop moving out of Wi-Fi range, a phone switching from Wi-Fi to mobile data, a VPN server briefly restarting, an ISP hiccup — any of these can end a VPN tunnel mid-session, and by default, most operating systems handle that the same way they handle any other network interruption: they fall back to whatever connection is available and keep going. Your browser does not pop up a warning that says "this next request is going out unprotected." It just sends it. If you are relying on the VPN specifically to hide your IP address, keep traffic off an untrusted network, or route around a restriction, that silent fallback is exactly the failure mode you do not want, and a kill switch exists specifically to prevent it.

It helps to think of a kill switch less as a VPN feature and more as a specific answer to a specific question: what should happen to my traffic in the gap between "the VPN just dropped" and "the VPN is back up"? Without a kill switch, the answer is "it goes out unprotected." With one, the answer is "it goes nowhere until the VPN is back."

Why does a VPN connection drop in the first place?

A kill switch only matters because VPN tunnels are not permanently unbreakable pipes — they depend on an active, continuous network path between your device and the VPN server, and several ordinary things can interrupt that path:

  • Network changes. Moving from Wi-Fi to mobile data, switching Wi-Fi networks, or a laptop waking from sleep on a different network than it fell asleep on can all briefly break the tunnel while the device re-establishes a connection.
  • Unstable or weak signal. Public Wi-Fi in particular is prone to brief drops and interference, and a VPN tunnel riding on top of a shaky connection inherits that instability.
  • Server-side issues. The specific VPN server you are connected to can restart for maintenance, hit a load threshold, or otherwise become unreachable, forcing your app to reconnect — sometimes to the same server, sometimes to a different one.
  • The VPN app itself crashing or being closed. If the app process dies or is force-closed, the tunnel it was maintaining goes with it, but the device's underlying internet connection is usually still perfectly functional — so traffic can keep flowing with nothing encrypting or rerouting it.
  • Protocol renegotiation taking longer than expected. Some reconnections are near-instant; others require a fuller handshake between your device and the server, which takes longer and widens the window where traffic could otherwise leak out unprotected.

None of these are exotic edge cases. They are the ordinary texture of using a mobile device or a laptop that changes networks throughout the day, which is exactly why a kill switch is treated as a core feature rather than a niche one in most VPN apps today.

What specifically happens on your device the moment a VPN connection drops?

It is worth walking through the sequence concretely, because the phrase "the VPN drops" covers a very short window in which several things happen in a specific order.

Without a kill switch

The VPN tunnel disappears. Your device's operating system notices, essentially instantly, that the virtual network adapter the VPN was using is no longer a usable route, and its routing table falls back to the next available path — typically your normal Wi-Fi or mobile connection, the same one that was there before the VPN connected. Any app with an open connection or a pending request — a page still loading, a background sync, a chat app checking for messages — simply continues over that normal connection. Your device's real IP address is now visible to whatever you are connected to, your traffic is no longer routed through the VPN server, and in most cases there is no visible alert telling you this happened. Some VPN apps show a small icon change or a notification, but plenty of people do not notice these in the moment, especially if they are not actively looking at their phone or laptop when it happens. The VPN app itself is usually still trying to reconnect in the background during this whole window; the gap is simply however long that reconnection takes.

With a kill switch enabled

The kill switch's monitoring detects the tunnel going down — either by watching for the virtual network adapter disappearing, by noticing the encrypted connection to the VPN server stop responding, or through a firewall-based method described further down — and immediately applies a block on outgoing network traffic before the operating system's routing table has a chance to quietly reroute everything to your normal connection. Depending on the implementation, this either blocks all traffic system-wide or kills the specific apps you have designated as requiring VPN protection. Any request already in flight is cut off; any new request simply fails to connect rather than silently going out unprotected. This state persists until the VPN tunnel is fully re-established, at which point the block is lifted and normal traffic flow through the VPN resumes automatically.

The practical difference is not subtle: one path leaves you briefly exposed without your knowledge, and the other trades a few seconds of no internet access for the guarantee that nothing left your device unprotected during the gap.

How does a kill switch technically block traffic?

Different VPN apps implement the actual blocking mechanism differently, and the approach affects both how reliable the kill switch is and how disruptive it feels day to day.

Firewall-rule-based kill switches

This is the most common and generally the most robust approach. The VPN app installs firewall rules, at the operating-system level, that only permit outbound traffic through the VPN's virtual network adapter. Because these rules live in the operating system's own firewall rather than in the VPN app's own process, they keep working even if the VPN app's user interface freezes or the tunnel drops in a way the app has not yet detected — the firewall rule itself is what is actually preventing traffic from going out over any other interface. This is why firewall-based kill switches are usually considered the more dependable of the two common approaches: the protection is enforced at a lower, more fundamental level than the app's own logic.

Application-monitoring kill switches

A simpler and older approach has the VPN app itself watch its own connection status and, on detecting a drop, either close specific designated apps or attempt to block their network access directly. This can work fine in the ordinary case, but it depends on the VPN app's own process staying alive and responsive to actually notice the drop and act on it — if the app crashes outright rather than just losing its tunnel, an application-monitoring kill switch built into that same app may not get the chance to act at all, since the mechanism enforcing the block disappeared along with the app.

Why the distinction matters in practice

You will not usually see marketing copy specify which of these two approaches a given VPN uses, and the labeling in-app is rarely this precise. What is worth taking away is simply that "kill switch" is not one single, standardized mechanism — it is a category of feature that different providers implement with different levels of robustness, which is one more reason to actually test the feature (covered later in this guide) rather than assume that toggling it on is the end of the story.

System-wide vs. app-level kill switch: what is the difference?

Most VPN apps that offer a kill switch let you choose, or default to, one of two scopes for what gets blocked when the tunnel drops.

System-wide (or "network-level") kill switch

This blocks all internet traffic from the device — every app, every background process, system updates, everything — the instant the VPN drops, and keeps it blocked until the tunnel is back. It is the more thorough option: nothing on the device can accidentally leak traffic because nothing on the device has any network access at all during the gap. The trade-off is that it is also the more disruptive option in daily use — if you are in a video call or streaming something when the VPN briefly drops, a system-wide kill switch will interrupt that activity completely rather than letting it continue unprotected, which is the point, but it is worth knowing to expect.

App-level (or "per-app") kill switch

This lets you specify which particular apps should be blocked if the VPN drops, while other apps continue operating normally over whatever connection is available. This is useful when you only care about VPN protection for specific activities — a torrent client, a work app handling sensitive data — and do not want, say, a music app or a weather widget losing connectivity every time the VPN blips. The trade-off is the inverse of the system-wide option: any app you did not explicitly designate is not protected by the kill switch at all, so it is only as good as the list of apps you remembered to add to it.

Which one should you use?

If the entire reason you run a VPN is to keep your device's traffic consistently protected — for privacy on untrusted networks, or because you specifically do not want your real IP address exposed under any circumstance — a system-wide kill switch is the more reliable choice, precisely because it does not depend on you remembering to list every app that matters. An app-level kill switch makes more sense if you have a narrower goal, are on a network where unrelated interruptions would be genuinely costly (a work call you cannot afford to drop), and are comfortable maintaining the list of apps that need to be covered.

Does a kill switch protect you if the VPN app crashes, or only if the tunnel drops?

This is one of the more important practical distinctions, and it depends entirely on which implementation approach (described above) a given kill switch uses. A firewall-rule-based kill switch, because its block is enforced by the operating system's firewall rather than by the VPN app's own running process, generally continues to hold even if the VPN app itself crashes or is force-quit — the firewall rule stays in place regardless of whether the app that set it is still running, until something explicitly removes it. An application-monitoring kill switch, by contrast, is only as good as the app process that is supposed to notice the crash and react to it — if that same process is what just crashed, there may be nothing left to enforce the block.

This is a genuinely useful question to have an answer to for any VPN you rely on, and it is part of why the testing steps later in this guide are worth doing at least once rather than trusting the feature blindly: a kill switch that reliably handles an ordinary Wi-Fi drop but fails to hold when the app itself misbehaves is giving you a meaningfully narrower guarantee than its name suggests.

Does a VPN kill switch slow down my connection or cause other side effects?

A properly functioning kill switch has no effect on your connection speed or behavior while the VPN tunnel is healthy — it is a monitoring and contingency mechanism, not something that intercepts or processes your ordinary traffic. You should not notice it at all during normal use; its entire job happens only in the moment the tunnel actually drops.

There are, however, a few real side effects worth knowing about:

  • Loss of connectivity during drops, by design. The whole point of the feature is to block traffic during a drop, so if your network is genuinely unstable — a spotty hotel Wi-Fi, for instance — a system-wide kill switch will mean your device effectively has no internet access at all during each of those blips, rather than a degraded connection. This is more noticeable, not less, precisely because the kill switch is working correctly.
  • Occasional over-triggering. A kill switch with an aggressive or poorly tuned detection mechanism can sometimes trigger on very brief network hiccups that would have resolved on their own in under a second, producing more interruptions than strictly necessary. This varies by app and is one of the things worth noticing during ordinary use.
  • Interference with local-network devices. A system-wide kill switch, because it blocks all traffic not going through the VPN, can also block access to devices on your local network — a printer, a smart-home hub, a network drive — if it is active and your VPN is not currently connected. Many apps offer a setting to allow local network traffic through even while the kill switch is engaged; whether that setting exists and what it is called varies by app.

None of these are reasons to avoid using a kill switch — they are the expected, sometimes inconvenient, cost of the protection it provides. Understanding them mainly helps you distinguish "the kill switch is working as intended" from "something is actually broken" when you notice a connectivity interruption.

How do you check whether your VPN's kill switch is actually working?

A kill switch is a feature you mostly hope never to notice, which unfortunately also means it is easy to leave untested and simply assume works. A few concrete ways to check:

Confirm it is actually turned on

This sounds obvious, but on a meaningful number of VPN apps the kill switch is an opt-in setting rather than something enabled by default, and it is worth checking the app's settings menu directly rather than assuming. Look specifically for whether it is set to system-wide or app-level scope, since the two behave very differently, as covered above.

Force a disconnect and watch what happens

With the VPN connected and the kill switch enabled, the most direct test is to force the tunnel to drop in a way that mimics a real-world failure and observe what your device does. Turning off Wi-Fi and immediately turning it back on, or switching from Wi-Fi to mobile data and back, are both reasonable ways to simulate the kind of network change that ordinarily triggers a drop. Some VPN apps also include a manual "test kill switch" option in their settings, which is the more controlled way to check without depending on real network conditions to cooperate.

Check what a website sees during the test

Before intentionally dropping the connection, load a site that shows your current public IP address and note the VPN server's IP. Then trigger the disconnect described above and, in the same moment, try to load a different page or refresh that IP-checking site. If the kill switch is working, that request should simply fail to load rather than succeeding and showing your real IP address — a successful page load with your real IP visible during that window means traffic was not actually being blocked.

Repeat it more than once

Because a kill switch's job is specifically to handle an unpredictable, momentary failure, testing it once and confirming it worked is a reasonable baseline, but testing it a couple of times, including on different networks (home Wi-Fi versus mobile data, for instance), gives a more honest picture than a single successful test, given that the underlying implementation can behave slightly differently depending on which specific thing triggers the drop.

Do all VPNs have a kill switch, and is it on by default?

A kill switch is a common feature among established VPN providers today — it shows up in the apps offered by NordVPN, Proton VPN, PureVPN, and FastestVPN, among others, and is generally treated as a standard, expected part of a VPN app's feature set rather than a premium add-on. That said, "the feature exists" and "the feature is switched on by default" are two different things, and whether it is enabled out of the box, what it is called in the settings menu, and whether it defaults to system-wide or app-level scope all vary between apps and even between platforms within the same provider — a desktop app and a mobile app from the same VPN do not always handle this identically. Checking the specific settings menu of whichever app you are using, rather than assuming based on what another platform's version does, is the only reliable way to know where you stand. Our individual provider reviews — for NordVPN, Proton VPN, PureVPN, and FastestVPN — cover what each app's everyday settings actually look like.

Who actually needs a kill switch, and when does it matter most?

In principle, a kill switch is a reasonable default for anyone using a VPN, since the downside — a brief connectivity interruption during an already-occurring drop — is small compared to the upside of not silently exposing your real IP address. But it matters more in some situations than others:

  • Using public or untrusted Wi-Fi. These networks are both more prone to unpredictable drops and exactly the setting where you most want your device's traffic to never fall back to an unencrypted connection that anyone else on the same network could potentially observe.
  • Torrenting or P2P activity. Because this kind of traffic is often the exact reason someone is using a VPN in the first place, a brief unprotected gap during a drop is the scenario a kill switch most directly guards against here — see our guide to VPNs and torrenting for more on this.
  • Journalists, activists, and others with a genuine safety stake in not exposing their real IP address. For anyone whose VPN use is tied to a real personal-safety consideration rather than general convenience, a kill switch moves from "nice to have" to something worth actively confirming is on and tested, not just assumed. Our guides for journalists and activists go into this in more depth.
  • Frequent network switching. Commuting, working from multiple locations, or otherwise moving between Wi-Fi and mobile data throughout the day all increase how often a VPN tunnel actually drops, which correspondingly increases how often a kill switch actually does something rather than sitting dormant.

Conversely, if your use of a VPN is occasional and low-stakes — say, briefly connecting to check a streaming catalog in another region — the consequences of an unprotected gap during a rare drop are correspondingly lower, though there is generally little reason to turn the feature off even then, given that its cost during normal operation is effectively zero.

What is the difference between a kill switch and split tunneling?

These two features get confused because they are both about controlling exactly which traffic goes through the VPN, but they solve different problems and are not substitutes for each other. Split tunneling is a feature you configure in advance to deliberately route some traffic through the VPN and let other traffic (a local printer, a banking app you trust on your home network) bypass it entirely, even while the VPN is connected and working normally. A kill switch, by contrast, only does anything at the moment the VPN unexpectedly stops working, and its purpose is to prevent traffic from going out unprotected during that failure — it has nothing to do with deliberately routing specific traffic around the VPN while it is healthy. You can use either feature independently, or both together (for example, split tunneling to exclude a specific app from the VPN entirely, alongside a kill switch protecting everything else in case of a drop), and having one configured says nothing about whether the other is also enabled.

Is a kill switch the same as auto-reconnect?

These two features are related but answer different questions, and a lot of the confusion around kill switches actually comes from conflating them. Auto-reconnect is what a VPN app does after a drop: it detects that the tunnel is down and automatically attempts to re-establish it without you having to manually hit "connect" again. A kill switch is about what happens during the gap between the drop and that reconnection — specifically, whether your traffic is blocked or allowed to flow unprotected while the app is in the process of reconnecting.

A VPN app can have either feature without the other. Auto-reconnect without a kill switch means the app will eventually get you back on the VPN, but anything your device sent in the meantime went out over your normal connection. A kill switch without auto-reconnect means your traffic stays safely blocked during a drop, but you may need to manually restart the connection once you notice it happened, rather than the app doing it for you. Most modern VPN apps ship with both, working together: the kill switch keeps you protected during the gap, and auto-reconnect closes that gap as quickly as possible so the kill switch's block is lifted sooner rather than later. Neither one is a substitute for the other, and it is worth checking a VPN app's settings for both rather than assuming that having one implies the other is also present.

Does a kill switch work the same way on mobile as it does on a laptop or desktop?

Not always, and the differences are largely driven by what each mobile operating system's own networking rules actually allow a third-party app to do, rather than by choices individual VPN providers make.

Android

Android exposes a system setting, generally called something like "Always-on VPN" combined with "Block connections without VPN," built into the operating system itself rather than requiring the VPN app to build the mechanism from scratch. When enabled for a specific VPN app, this operating-system-level setting blocks all network traffic unless it is going through that app's VPN tunnel, which functions as a kill switch even if a particular VPN app's own interface does not separately label a feature "kill switch." Many Android VPN apps also layer their own app-level kill switch setting on top of this.

iOS

iOS is more restrictive about what any app, including a VPN app, is permitted to do at the network level, which has historically made a true, instantaneous kill switch harder to implement on iPhone and iPad than on desktop platforms. Apple provides VPN apps with a mechanism called "Connect On Demand" and related on-demand VPN rules, which VPN apps use to approximate kill switch behavior by automatically blocking or re-establishing the VPN connection based on network changes — but the underlying implementation is different from the firewall-rule approach common on Windows and Mac, and the practical result can be a very brief window of exposure during a transition that a desktop firewall-based kill switch would close more completely. This is a platform constraint rather than something any individual VPN provider chooses; it is still worth knowing about if you rely primarily on a phone.

What this means in practice

If consistent kill switch protection matters to you and you use a VPN across multiple device types, it is worth checking the setting on each platform separately rather than assuming your desktop configuration carries over to your phone, or that an iOS app behaves identically to its Android counterpart. The feature name, its default state, and how completely it closes the gap during a drop can all differ by platform even within the same VPN provider's own app lineup.

Common misconceptions about VPN kill switches

A few misunderstandings come up often enough to be worth addressing directly.

"A kill switch means my VPN never disconnects"

A kill switch does not prevent the VPN from disconnecting — nothing can guarantee that, given how many ordinary things (described earlier) can interrupt a tunnel. What it changes is what happens to your traffic once a disconnection has already occurred. The VPN dropping and the kill switch engaging are two separate events, one causing the other, not the same thing.

"If I see the VPN app's icon still showing 'connected,' the kill switch isn't needed"

A VPN app's displayed status can occasionally lag behind the actual state of the tunnel, particularly during a fast reconnection cycle, which is part of why the kill switch is designed to react to the tunnel's actual technical state rather than to what the app's interface happens to be showing at that instant. Relying on the visible connection indicator alone, instead of the kill switch, reintroduces exactly the silent-gap problem the feature exists to close.

"A kill switch protects me from the VPN provider itself"

A kill switch has nothing to do with what the VPN provider can see or retain about your traffic while the tunnel is active and healthy — that is a separate question governed by the provider's logging policy and jurisdiction, covered in our guide to VPNs and privacy. A kill switch only concerns the moment the tunnel is down; it says nothing about the provider's practices while it is up.

"Once I turn it on, there's nothing left to check"

As covered in the testing section above, a kill switch that is toggled on in settings is not the same guarantee as a kill switch confirmed to work by an actual test. The setting existing and the setting functioning correctly on your specific device and network are related but distinct facts, and only the second one is the thing that actually protects you.

Practical takeaway

A VPN kill switch answers a specific, concrete question: what happens to your device's traffic in the gap between a VPN tunnel dropping and reconnecting? Without one, the honest default answer on most systems is that traffic quietly falls back to your normal, unprotected connection, often without any obvious warning. With one enabled and working correctly, that traffic is blocked instead, until the tunnel is back. The feature is common across established VPN providers, but it is not always on by default, its scope (system-wide versus app-level) changes how thoroughly it protects you, and how robustly it is implemented (firewall-based versus application-monitoring) affects whether it holds up even if the VPN app itself misbehaves. If you are using a VPN for a reason where a brief unprotected gap would actually matter — public Wi-Fi, torrenting, or any use case with real safety stakes — check that the kill switch is enabled, understand which scope it is set to, and actually test it at least once rather than trusting the toggle alone.

Frequently asked questions

What happens if I don't have a kill switch enabled and my VPN drops?

Your device typically falls back to sending traffic over its normal, unprotected connection almost immediately, without any obvious warning in most cases. That means your real IP address becomes visible to whatever you're connected to, and any traffic sent during the gap isn't routed through the VPN server at all, for as long as it takes the VPN app to reconnect.

Is a VPN kill switch the same as a firewall?

Not the same thing, though some kill switches use the operating system's firewall as their enforcement mechanism. A firewall is a general tool for controlling network traffic based on rules you or an app define; a kill switch is a specific, narrower behavior — blocking traffic only when the VPN tunnel drops — that some VPN apps happen to implement by installing temporary firewall rules.

Should I use a system-wide or app-level kill switch?

A system-wide kill switch is generally the more reliable choice if consistent protection is the goal, since it doesn't depend on you remembering to list every app that matters. An app-level kill switch makes more sense if you only need protection for specific activities and don't want unrelated apps losing connectivity every time the VPN briefly drops.

Will a kill switch slow down my internet connection?

No — a properly functioning kill switch has no effect on speed or behavior while the VPN tunnel is healthy. It only does anything in the moment the tunnel actually drops, at which point it blocks traffic rather than slowing it down.

How do I test if my VPN's kill switch actually works?

With the VPN connected, load a page showing your public IP address, then force a disconnect — for example by toggling Wi-Fi off and on, or switching to mobile data — and immediately try to load a page again. If the kill switch is working, that request should fail to load rather than succeed and reveal your real IP address. Some VPN apps also include a built-in kill switch test in their settings.

Does every VPN app have a kill switch turned on by default?

No — while a kill switch is a common feature among established VPN providers, whether it's enabled by default, what it's called, and whether it defaults to system-wide or app-level scope all vary by provider and even by platform. It's worth checking the settings menu of the specific app you're using rather than assuming.