Skip to main content
Back to blog

VPN Kill Switch: What It Is and Why It Matters

VPN

VPN Kill Switch: What It Is and Why It Matters article illustration

A VPN kill switch is a safety net for the moment your VPN connection fails. It watches your VPN link, and the instant it drops, it blocks your device (or a chosen set of apps) from reaching the internet at all, rather than letting your traffic quietly fall back to your normal, unprotected connection.

That gap, the few seconds between a VPN dropping and you noticing, is exactly when a kill switch earns its place.

Why VPN connections drop in the first place

A VPN connection isn’t a permanent piece of infrastructure. It’s a live tunnel that has to survive whatever your network throws at it, and several ordinary things can break it:

Weak or unstable Wi-Fi signals, network congestion or ISP throttling, security software (firewalls, antivirus) interfering with the tunnel, the VPN protocol itself switching or failing to reconnect cleanly, and server-side issues like an overloaded or unstable VPN server.

None of these are exotic failure modes. They happen on ordinary home and public Wi-Fi connections regularly. The problem isn’t that a VPN drops sometimes, it’s what happens on your device in the moment it does.

What a kill switch actually does

Without a kill switch, a dropped VPN connection is invisible by default. Your device notices the tunnel is gone and quietly routes traffic through your normal ISP connection instead, the same connection the VPN was supposed to be hiding you from in the first place. Any page loading, download in progress, or app syncing in the background during that gap goes out with your real IP address exposed.

A kill switch closes that gap by cutting your internet access the moment it detects the VPN is down, and keeping it cut until the VPN reconnects. No traffic gets a chance to leak out unprotected, because nothing gets out at all.

System-level vs. app-level kill switches

Not all kill switches work the same way, and the difference matters for how you use one.

A system-level (or network-level) kill switch blocks all internet traffic on your device the moment the VPN drops. Nothing gets through, not your browser, not background apps, nothing, until the VPN is back up. This gives you the strongest guarantee, at the cost of a hard stop to everything you’re doing.

An app-level kill switch lets you choose specific apps to protect, torrent clients and browsers are common choices, while everything else keeps working normally if the VPN drops. This is more forgiving day to day, but anything you didn’t select is exposed the moment the tunnel fails, which defeats the point if you picked the wrong app list.

If you’re using a VPN for something where any exposure at all is a real problem, system-level is the safer default. If you mainly want a specific app protected and would rather not lose your whole connection over it, app-level is the more livable choice.

How to check yours is actually working

A kill switch you’ve never tested is a kill switch you’re just assuming works. The direct way to check: connect your VPN, confirm your visible IP has changed on My IP Address, then force the VPN connection to drop, either by disabling your network adapter briefly, or by quitting the VPN app’s background process outright, and watch what happens. With the kill switch working, your internet access should cut off immediately rather than silently falling back to your real connection.

If your internet keeps working normally the moment the VPN drops, the kill switch isn’t doing its job, and it’s worth checking the setting is actually enabled rather than just present in the app’s feature list.

What a kill switch doesn’t do

A kill switch only reacts to a VPN connection that’s already dropped. It doesn’t stop you connecting through a bad or compromised server in the first place, it doesn’t substitute for leak protection (a VPN can stay technically connected while DNS or WebRTC traffic still leaks outside the tunnel), and it can’t help if the VPN app itself hangs without ever registering that the connection is down.

That’s why it’s worth pairing a working kill switch with a proper leak check rather than treating either one alone as complete coverage. Run the Network Leak Check and the WebRTC Leak Test after connecting, and use Is My VPN Working? for a full before-and-after comparison of your visible IP.

A kill switch is a small feature with an outsized job: making sure the one moment your VPN fails is also the one moment nothing gets through unprotected. Worth checking it’s actually on, and worth testing it once so you know it works before you need it to. For a provider that implements one properly, see our NordVPN review.