How a kill switch works
VPN connections drop more often than people notice: when you move from Wi-Fi to mobile data, when a laptop wakes from sleep, when a hotel network redirects you to its login page, or when a server restarts. Your apps don’t wait. They send and receive over whatever connection exists. A kill switch makes sure that connection is the tunnel or nothing.
| App-level kill switch | System-level kill switch | |
|---|---|---|
| What it does | Closes selected apps when the VPN drops | Blocks all traffic that isn’t going through the tunnel |
| How | Watches the connection and reacts | Firewall or operating system rules that are in place before anything drops |
| Gaps | Other apps and background services can still leak | Only traffic the operating system itself exempts |
Operating systems now offer the building blocks. Android has “Always-on VPN” with a “Block connections without VPN” switch, available since Android 7.0.1 On Apple platforms, a VPN app can route all traffic through the tunnel except a few system services Apple designates.2
Why it matters
A drop that lasts two seconds is enough for an app to reveal your real IP address to a site, or for a messaging app to reconnect in the clear on public Wi-Fi. You won’t see it happen. The kill switch is what makes a VPN’s protection continuous rather than “most of the time.”
How to test your kill switch
- Connect to your VPN and open a site that shows your IP address. Note the VPN’s address.
- Force a drop: turn Wi-Fi off and on, switch networks, or block the VPN server in your router for a moment.
- Reload the page while the VPN reconnects. With a working kill switch, the page fails to load. If it shows your real IP address, traffic is leaking.
Where you’ll see it
Most VPN apps offer a kill switch, sometimes under names like “network lock” or “always-on.” Check whether it is on by default and whether it works at the system level on each of your devices.
The kill switch in Secria VPN
Secria VPN has an OS-level kill switch on iOS, Android, Windows, macOS and Linux. It blocks all traffic the moment the tunnel drops, and nothing leaks while the connection comes back. Every connection that does go through is protected with WireGuard plus ML-KEM-1024. See Secria VPN or the post-quantum VPN page.
Related terms
Sources
- Android Developers, VPN: always-on VPN.
- Apple Developer, NEVPNProtocol includeAllNetworks.
Checked September 2026. Secria facts are from our Mail and VPN pages and the whitepaper.