What a VPN kill switch does, and how to set one up
A kill switch blocks a device's internet access when its VPN connection drops, keeping the IP address and DNS queries private. Engadget explains how app-level and system-level switches differ, and how to configure and test one.
The tool addresses a gap that exists in ordinary VPN use. A VPN hides a user's IP address by building an encrypted connection between the device and a VPN server before the user reaches a website, linking device, server and destination through encrypted tunnels. That arrangement makes it harder for outsiders to spy on internet traffic or run man-in-the-middle attacks, and it also obscures browsing activity from advertisers, websites and the internet service provider. The protection holds only while the tunnel is up. If the connection drops and the device falls back to its regular network, the user's real IP address can be visible again, and even a brief exposure can be compromising. Watching for that moment manually is impractical, which is why Engadget describes a kill switch as a way to turn a VPN into a set-and-forget service.
While enabled, the kill switch monitors the quality of the connection to the VPN server. When it detects an irregularity, it blocks the device's internet connection, which stops the IP address or DNS queries from leaking. Many kill switches also act when a user switches servers, adding protection against DNS leakages during automatic reconnection. Once the tunnel between device and server is back online, the VPN restores the device's internet access.
Modern kill switches operate at either the application or the system level. An app-specific switch blocks connections only for selected apps that might leak sensitive data to outside observers, which lets a user keep browser traffic protected while updates and video-calling apps continue to run. A system-level switch, also called a network kill switch, cuts off all internet traffic on the device. It is the more effective of the two but can produce frequent disconnections when the underlying connection is spotty.
Finding the setting is usually a matter of opening the VPN app's menu. It may appear as a network lock, auto-disconnection protection, leak protection, or simply as an option to block connections when disconnected. If it is not on the top-level menu, Engadget advises checking tabs labeled Security, Privacy, Network protection or Advanced. Users configuring an app-specific switch may want it active for email, web browsers and messaging apps; exceptions make sense for apps where a dropped connection causes trouble, such as video conferencing or gaming tools.
A feature commonly paired with a kill switch is auto-connect, which engages automatically whenever the device joins a public network. It can also be set so the VPN connects whenever the device is switched on, removing the need to remember it each time.
Engadget suggests two basic checks. In a disconnect test, the user manually severs the VPN connection and tries to browse; if the device loses its internet connection, the kill switch is working. If browsing continues, the switch may only guard against accidental disconnections. A second test uses sites such as ipleak.net or whatismyipaddress.com, where the user deliberately interrupts the VPN connection and watches whether the real IP address appears. If it does not, the kill switch is doing its job.
Editor's Summary
A VPN kill switch blocks a device's internet traffic when the VPN tunnel drops, keeping the user's IP address and DNS queries hidden until the connection is restored. Engadget's explainer notes that switches can be limited to specific apps or applied system-wide, and that free or budget VPNs may omit the feature. It recommends confirming the setting is enabled and testing it by manually disconnecting the VPN and checking for IP leaks.