The specific problem a kill switch solves
A VPN connection can drop without warning: the server restarts, your Wi-Fi briefly disconnects and reconnects, your device switches networks, or the app crashes. The moment the tunnel drops, most operating systems don’t just stop sending traffic — they fall back to the normal network interface and keep browsing, syncing, and downloading exactly as before, just without the VPN’s encryption or IP masking. If you didn’t notice the drop, anything sent in that window goes out over your real IP address. A kill switch exists specifically to prevent that silent fallback.
How it actually works
A kill switch monitors the state of the VPN tunnel and, when it detects the tunnel is down, blocks network traffic until the tunnel is re-established. The mechanism differs by implementation:
- System-level (firewall-based) kill switches add rules directly to the operating system’s firewall (Windows Filtering Platform on Windows, pf on macOS, iptables/nftables on Linux) that only permit traffic through the VPN’s virtual network interface. If the VPN interface goes down, the firewall rule blocks everything else by default, regardless of which app is trying to send it. This is the more robust approach because it doesn’t depend on the VPN app staying alive to enforce it.
- App-level kill switches monitor the VPN app’s own connection state and close network sockets for specific monitored apps when the tunnel drops. This is more flexible — you can choose which apps get shut off — but if the VPN app itself crashes rather than just losing connection, an app-level kill switch that lives inside that same crashed process may not trigger at all.
What a kill switch does not do
It doesn’t prevent a DNS leak that happens while the tunnel is technically still up but misconfigured (that’s a separate, related issue — see our DNS leak explainer). It doesn’t protect you if you manually disconnect the VPN yourself; most kill switches are designed to distinguish an intentional disconnect from an unexpected drop, though poorly implemented ones sometimes fail to make that distinction and block your internet entirely until you notice. And it doesn’t do anything about the VPN provider itself, which sits outside the tunnel by definition and can see your traffic on their end regardless of the kill switch — that’s what no-logs policies and independent audits speak to instead.
How to actually check yours works
- Connect your VPN and confirm your IP address has changed using any IP-check site.
- With the kill switch enabled in your VPN app’s settings, force-close the VPN app’s process (not just disconnect from within the app — kill the process itself) or disable your Wi-Fi adapter briefly while connected.
- Try to load a webpage during that window. If the kill switch is working, it should fail to load rather than succeed over your unprotected connection.
- Re-enable networking and confirm the app either automatically reconnects the VPN or clearly prompts you that you’re unprotected.
Mobile platforms behave differently
Kill switch implementation quality varies more on mobile than desktop, largely because of how each OS restricts background network control. Android’s VPNService API allows apps to implement a genuine always-on, system-level block (Android even has a built-in ‘Block connections without VPN’ toggle in system settings, independent of any third-party app). iOS is more restrictive: apps use the NetworkExtension framework, and a fully reliable kill switch there generally depends on the provider implementing an on-demand rule that tears down networking if the VPN tunnel fails, rather than a simple in-app toggle. If a kill switch matters to you on a phone, it’s worth checking the provider’s own documentation for how they implement it on that specific platform rather than assuming parity with their desktop app.
FAQ
Should I always leave the kill switch on?
For most people, yes — the downside is occasional brief internet interruption during a VPN reconnect, which is a small cost against silently leaking traffic on your real IP.
Does every VPN app have a kill switch?
No. It’s common among paid providers but not universal, and free or lightweight VPN apps sometimes omit it entirely. Check the specific app’s feature list rather than assuming.
Is a kill switch the same as split tunneling?
No, and they can interact in ways worth understanding. Split tunneling deliberately routes some traffic outside the VPN; a kill switch is about what happens to tunnel-routed traffic when the tunnel unexpectedly fails. See our split tunneling explainer for the distinction.
Compare VPN providers side by side