A VPN kill switch prevents ordinary network traffic from continuing when the encrypted tunnel is unavailable. Without it, a brief Wi-Fi change or VPN crash may return applications to the direct connection.
Implementation matters
A system-level switch can apply firewall rules across applications. An app-specific switch may close selected programs. Marketing labels do not reveal which design is used.
Test predictable failures
- Record the direct public IP.
- Connect the VPN and confirm the changed route.
- Interrupt the VPN process or network.
- Verify that browsing and DNS stop rather than falling back.
- Repeat after sleep, Wi-Fi switching and updates.
Know the limitation
A kill switch protects route continuity, not malware, cookies or account identity. Misconfiguration can also block local printers or captive portals.
Enable it when an unintended direct connection creates a meaningful risk, then test the exact device and applications rather than assuming the setting name proves coverage.
Restart behavior is easy to miss
Some clients enforce the kill switch only after the application starts. Reboot while Wi-Fi is connected and check whether traffic leaves before the VPN service loads. Also test an application already holding an open connection.
Recovery from a lockout
Document how to disable the rule locally when the VPN endpoint is unavailable. A safety control that permanently blocks updates or support access can create its own operational risk.
Test the failure modes that users actually encounter
Begin a harmless download, interrupt the VPN process, change from Wi-Fi to mobile data, wake the device from sleep and reboot. Observe whether traffic stops, reconnects through the tunnel or leaves directly. Test both IPv4 and IPv6 where available.
System-wide and application rules differ
An application-level kill switch may protect selected programs while background services continue. A firewall-based rule can be broader but may block captive portals, local printers or updates. Document exceptions and verify that DNS follows the same policy.
A kill switch reduces accidental exposure during tunnel failure; it does not repair a malicious VPN provider, compromised endpoint or unsafe destination. Choose the trust model first, then test continuity controls.
Sources and further reading
Use the right privacy tool for the task
A browser proxy changes the network path for one session. Review the Privacy Policy and use a trusted direct connection for sensitive accounts.