Breaking

VPN Kill Switches, Explained: the One Setting Most People Leave Off

What a VPN kill switch actually does, why a dropped VPN connection is a real privacy risk without one, and how to check whether yours is on.

Photograph: Wireless router, internal components (LevelOne WBR 6002).

Photo: Mk2010 · CC BY-SA 4.0 · source

Most VPN apps ship with a kill switch, and most users never turn it on — usually because they don’t understand what it protects against, or assume a VPN connection simply doesn’t drop. It does drop, more often than people expect, and the moment it does without a kill switch, every protection the VPN was providing disappears silently.

What actually happens when a VPN connection drops

A VPN works by routing all of a device’s internet traffic through an encrypted tunnel to the VPN provider’s server, which then forwards it to the destination site. If that tunnel breaks — a Wi-Fi network switch, a brief mobile signal drop, the VPN app crashing in the background — most operating systems don’t pause internet access while the VPN reconnects. They fall back to the regular, unencrypted connection automatically, because the device’s default behavior is to prioritize staying connected to the internet over staying connected to the VPN specifically.

That fallback is invisible unless something is actively checking for it. Norton’s explanation of kill switch mechanics describes exactly this gap: for the seconds or minutes it takes to notice and reconnect, real IP address, unencrypted traffic, and ISP-visible browsing activity are all exposed — the precise information a VPN exists to hide.

What a kill switch actually does

A kill switch is a monitoring process that watches the VPN connection continuously and, the instant it detects the tunnel has dropped, blocks all internet traffic at the device or app level until the VPN reconnects. Cybernews’ breakdown of kill switch implementations distinguishes two common approaches: a system-level kill switch blocks all network traffic from the device entirely, while an app-level kill switch (sometimes called split or selective) only blocks specific applications configured to require the VPN, letting other traffic continue normally.

The tradeoff between the two is straightforward: system-level is more protective (nothing leaks, full stop) but means losing all internet access, not just the sensitive traffic, during a reconnect. App-level is more convenient for daily use but requires manually specifying which apps matter, and anything not on that list isn’t protected during a drop.

Why this matters more than it sounds

For most everyday browsing, a brief unencrypted moment during a VPN reconnect is low-stakes. It’s not low-stakes for the reasons people actually use a VPN in situations with real exposure — logging into accounts on public Wi-Fi, torrenting in a jurisdiction where that carries legal risk, or simply not wanting an ISP or network operator to see browsing activity at all. Security.org’s kill switch guide frames the setting as effectively closing the single largest practical gap in VPN protection, since a VPN’s entire privacy value depends on the tunnel actually being up — a kill switch is what keeps that assumption true when the tunnel briefly isn’t.

How to check if yours is on

Kill switch settings are usually under a “Connection” or “Advanced” tab in the VPN app, not enabled by default in every provider’s app. The setting name varies: NordVPN calls it “Kill Switch,” some providers label it “Network Lock” or “Internet Kill Switch.” Worth checking specifically:

It’s a one-time, thirty-second setting change that closes a gap most VPN users don’t know exists until it’s explained — which is exactly why it’s worth checking today rather than assuming it’s handled.

A kill switch only matters if the rest of the provider’s privacy claims hold up — see what independent audits actually found on VPN ’no-logs’ claims and Proton VPN vs. CyberGhost, compared point by point.