What split tunneling actually does
A standard VPN connection routes every packet leaving your device through the encrypted tunnel to the VPN server. Split tunneling changes the routing rules so that only some traffic goes through the tunnel, while the rest goes out over your normal internet connection, unencrypted by the VPN and using your real IP address. Technically, this is implemented at the routing table level: the VPN app adds routes for specific apps, IP ranges, or domains that point through the virtual network interface it creates, while everything else keeps using the device’s default route.
The two common implementations
- App-based split tunneling — you choose specific applications (a banking app, a work VPN client, a torrent client) to either include in or exclude from the VPN tunnel. Most consumer VPN apps on Windows and Android support this; iOS’s more restrictive network extension model has historically made this harder to implement fully.
- Destination-based (IP/domain) split tunneling — more common in business VPN and router-level setups, where traffic to specific IP ranges or domains (e.g. an internal corporate network) is routed through the tunnel and everything else isn’t.
Why people actually use it
The most common real-world reasons aren’t exotic. Remote workers use it to reach an internal corporate network over the VPN while their personal browsing and video calls use the faster direct connection. Some people exclude bandwidth-heavy local services (smart TV apps, local network printers, file-sharing on a home LAN) from the tunnel because routing local-network traffic through a remote VPN server doesn’t make sense and can break local device discovery. Others use it because a specific site or service behaves oddly or blocks connections when it detects a VPN IP, and excluding just that one app or site is simpler than turning the whole VPN off.
The tradeoff people often miss
Split tunneling is a deliberate reduction in protection for whatever traffic you exclude, not a clever way to get full protection more efficiently. Any app or site you route outside the tunnel sees your real IP address and is visible to your ISP or local network exactly as it would be without a VPN at all. That’s a reasonable, intentional tradeoff for low-sensitivity traffic, but it’s worth being deliberate about what you exclude — excluding a browser ‘to make streaming faster’ also means that browser’s DNS queries and connection metadata are no longer going through the VPN for anything you do in it, not just the one site you had in mind.
It’s also worth knowing that split tunneling is a feature the VPN client controls, not something a website can detect and opt itself into or out of. Sites that try to detect and block VPN traffic are working from your VPN server’s IP address showing up in known VPN IP ranges, which split tunneling for that specific app would sidestep by not sending it through the VPN at all.
Split tunneling outside consumer apps
The same concept shows up at other layers. Business VPNs commonly use destination-based split tunneling by default so that only traffic destined for the corporate network goes through the company’s VPN gateway, while employees’ general internet use (and the bandwidth it consumes) doesn’t route through corporate infrastructure at all — this is standard in remote-access VPN deployments and is what most enterprise VPN clients are configured to do out of the box, not an optional extra. Router-level VPN setups can also implement a version of this by policy-based routing, sending traffic from specific devices on the network through the VPN while other devices on the same network use the regular connection — useful in a household where only some devices need the VPN’s IP.
FAQ
Does split tunneling weaken my VPN’s kill switch?
It can complicate it. A kill switch is usually designed to block all non-VPN traffic if the tunnel drops; with split tunneling active, excluded apps are expected to use the direct connection, so most implementations only apply the kill switch to tunnel-routed traffic. Check your specific app’s documentation if this matters to you.
Is split tunneling available on iOS?
Support varies and has historically lagged Android/Windows/macOS due to how Apple’s NEVPNManager and network extension APIs work, though some providers now offer limited per-app exclusion on iOS. Check the specific app’s current feature list rather than assuming.
Does split tunneling reduce my VPN’s server load?
Marginally, from the provider’s side, since less of your traffic passes through their servers. That’s not the primary reason most people use it, but it is a real secondary effect.
Compare VPN providers side by side