Skip to main content
FixMyTech

What a VPN Kill Switch Does and When to Turn It On

By

Published

7 min read

Share

Short answer

A kill switch blocks your device's internet access whenever the VPN tunnel drops, so traffic never falls back to your unprotected connection. Turn it on for long unattended transfers and anything where a brief exposure matters; leave it off for casual browsing, where it mostly produces mysterious dead connections after your laptop wakes from sleep.

On this page

A VPN tunnel is not a permanent thing. It drops when your laptop sleeps, when Wi-Fi hands off to mobile data, when the VPN server restarts, and when your connection stutters for longer than the protocol’s timeout. In each of those moments, your device still wants to send traffic.

Without a kill switch, the operating system does the sensible networking thing: it falls back to the normal route and sends the traffic unprotected. Your real IP address is visible to whatever you were connecting to, for however long it takes the VPN to reconnect.

A kill switch stops that by blocking everything instead.

How it actually works

The name suggests the app watches for a disconnect and reacts. Well-implemented kill switches do the opposite — they install a firewall rule that permits traffic only through the VPN’s virtual network adapter, and denies everything on your physical adapter.

That distinction matters:

  • A rule-based kill switch has no gap. There is no moment between the drop and the block, because the block was already in place.
  • A monitoring kill switch has a gap of however long detection takes, typically a second or two.

You cannot usually tell which one your client uses from the settings screen. A practical tell is what happens if you force-quit the VPN app: a firewall-rule implementation usually leaves you with no internet until you reopen the app, which is correct behaviour and also the single most common support complaint.

When it earns its place

Situation Kill switch? Why
Long unattended upload or download Yes Drops happen and you are not watching
Reaching a work network remotely Usually set by IT Prevents split-brain routing
Journalism, activism, sensitive research Yes, strict A brief exposure is the whole risk
Everyday browsing on a laptop No Interruptions outweigh the benefit
Phone on mobile data Rarely Network handoffs trigger it constantly

The pattern is simple enough: a kill switch is worth it when a few seconds of unprotected traffic would actually cost you something. For most people reading this on a home connection, it would not.

Where to find the setting

  • Windows and macOS apps: usually under Settings → Connection, labelled Kill Switch, Network Lock or Firewall. Some offer two modes.
  • Android (system level): Settings → Network & internet → VPN → the gear next to your VPN → Block connections without VPN. This is Android’s own implementation and works regardless of what the app offers.
  • iPhone and iPad: iOS has no user-facing kill switch. Some apps approximate it with an always-on profile, and managed devices can be configured with one through a mobile device management profile.

The iOS gap is worth stating plainly: if you need a guaranteed kill switch, an iPhone is not the device for it.

Strict mode versus the usable one

Clients that offer two levels are distinguishing between:

Allow local network access. The kill switch blocks the internet but permits traffic to addresses on your own subnet — printers, NAS boxes, Chromecast, router admin pages. Nearly everyone wants this on. Without it you will eventually spend twenty minutes wondering why your printer vanished.

Block everything. No local access. Correct if you do not trust the network you are on, which is arguably the point of being on a VPN there in the first place.

There is a genuine trade here and no single right answer. On your own home network, allow local access. On hotel Wi-Fi, do not.

When the kill switch is the problem

The classic symptom is internet that stays dead after you stop using the VPN. The firewall rule survives the app closing, and sometimes survives a reboot.

Work through this in order:

  1. Reopen the VPN client and connect, then disconnect from within the app. A clean disconnect removes the rule; a force-quit does not.
  2. Turn the kill switch off in the app’s settings, then quit.
  3. On Android, check Settings → Network & internet → VPN for a leftover “Block connections without VPN” toggle, which is independent of the app.
  4. On Windows, if the rule is genuinely stuck, uninstalling and reinstalling the client removes its firewall entries. A network reset also clears it, but wipes every saved Wi-Fi network as well.

A dead connection after a VPN session looks identical to several unrelated faults. If disabling the kill switch does not restore things, the broader diagnosis in Wi-Fi connected but no internet separates a leftover VPN route from a genuine network failure.

Testing that yours works

Most people enable it and assume. Checking takes a minute and is worth doing once, because a kill switch that does not engage is worse than none at all: you have the confidence without the protection.

  1. Connect the VPN and confirm an IP-checking site shows the server’s location.
  2. Start something continuous, such as a video, so traffic is actually flowing.
  3. Force-quit the VPN client rather than disconnecting cleanly. On Windows, end the process in Task Manager; on macOS, Force Quit.
  4. Reload the IP-checking site.

A working kill switch gives you a connection error. A failed one shows your real address, which means the firewall rule was never installed or was removed when the process died.

Afterwards, reopen the client and connect, then disconnect properly, to make sure you are not left with a stuck rule. If you are, the recovery steps below apply.

The gap nobody mentions

A kill switch protects traffic in flight. It does nothing about what already leaked.

If the tunnel dropped at 14:02 and the kill switch engaged at 14:02, the connections that were already open had a brief window where packets went out unprotected, before the operating system noticed the route change. On a firewall-rule implementation this window is essentially zero. On a monitoring implementation it is not.

More importantly, a kill switch does nothing about DNS. If your device is leaking DNS queries outside the tunnel while the tunnel is perfectly healthy, no kill switch will catch that, because nothing dropped. That is a separate check, covered in how to tell if your VPN is actually working.

Realistic expectations

On a stable home connection, a kill switch will engage perhaps once a week, usually when the laptop wakes from sleep before the Wi-Fi has reassociated. Most people experience that as “the internet was broken for ten seconds”.

If you are enabling it because you want to be thorough rather than because you have a specific reason, expect to turn it off again within a month. If you have a specific reason, use strict mode and allow local network access only on networks you own.

Frequently asked questions

Why does my internet stop working when the VPN is off?
A kill switch left enabled continues blocking traffic even after you quit the VPN app, because the blocking rule lives in the system firewall rather than the app. Reopen the VPN client and disable the kill switch properly, or reboot, rather than reinstalling your network drivers.
Is a kill switch the same as always-on VPN?
No. Always-on VPN reconnects the tunnel automatically when it drops; a kill switch blocks traffic while there is no tunnel. Many apps ship both, and on Android they are two separate toggles in the system settings.
Does a kill switch slow anything down?
No. It is a firewall rule that either permits or blocks packets, so it costs nothing measurable while the tunnel is up. The only cost is the interruption when the tunnel drops.
Will a kill switch break my local network?
It can. A strict kill switch blocks everything except the tunnel, which includes printers, network drives and casting to a TV on your own Wi-Fi. Most clients have a "allow local network access" option that fixes this.
Do I need a kill switch on my phone?
Only for the same reasons as on a laptop. Phones switch networks constantly, so a kill switch causes more interruptions there; Android's "Block connections without VPN" under the VPN settings is the system-level equivalent.

All VPN guides