Glossary

What is a VPN kill switch?

A VPN kill switch blocks your device’s internet traffic whenever the VPN connection drops, so nothing is sent outside the encrypted tunnel. Without one, apps quietly fall back to your regular connection, exposing your real IP address and unencrypted traffic to your network and internet provider until the VPN reconnects.

Also called: kill switch, network lock, block connections without VPN

Updated September 2026. Sources are numbered and listed at the end.

How a kill switch works

VPN connections drop more often than people notice: when you move from Wi-Fi to mobile data, when a laptop wakes from sleep, when a hotel network redirects you to its login page, or when a server restarts. Your apps don’t wait. They send and receive over whatever connection exists. A kill switch makes sure that connection is the tunnel or nothing.

App-level kill switchSystem-level kill switch
What it doesCloses selected apps when the VPN dropsBlocks all traffic that isn’t going through the tunnel
HowWatches the connection and reactsFirewall or operating system rules that are in place before anything drops
GapsOther apps and background services can still leakOnly traffic the operating system itself exempts

Operating systems now offer the building blocks. Android has “Always-on VPN” with a “Block connections without VPN” switch, available since Android 7.0.1 On Apple platforms, a VPN app can route all traffic through the tunnel except a few system services Apple designates.2

Why it matters

A drop that lasts two seconds is enough for an app to reveal your real IP address to a site, or for a messaging app to reconnect in the clear on public Wi-Fi. You won’t see it happen. The kill switch is what makes a VPN’s protection continuous rather than “most of the time.”

How to test your kill switch

  1. Connect to your VPN and open a site that shows your IP address. Note the VPN’s address.
  2. Force a drop: turn Wi-Fi off and on, switch networks, or block the VPN server in your router for a moment.
  3. Reload the page while the VPN reconnects. With a working kill switch, the page fails to load. If it shows your real IP address, traffic is leaking.

Where you’ll see it

Most VPN apps offer a kill switch, sometimes under names like “network lock” or “always-on.” Check whether it is on by default and whether it works at the system level on each of your devices.

The kill switch in Secria VPN

Secria VPN has an OS-level kill switch on iOS, Android, Windows, macOS and Linux. It blocks all traffic the moment the tunnel drops, and nothing leaks while the connection comes back. Every connection that does go through is protected with WireGuard plus ML-KEM-1024. See Secria VPN or the post-quantum VPN page.

Sources

  1. Android Developers, VPN: always-on VPN.
  2. Apple Developer, NEVPNProtocol includeAllNetworks.

Checked September 2026. Secria facts are from our Mail and VPN pages and the whitepaper.

Questions about VPN kill switches

Should I turn on the VPN kill switch?+

Yes, if you use a VPN for privacy. Without it, any drop in the connection sends your traffic over your regular network until the VPN comes back.

Does a kill switch slow down my internet?+

No. It only acts when the tunnel is down. While the VPN is connected, traffic flows normally.

Why do I have no internet with the kill switch on?+

The VPN tunnel is down, so the kill switch is blocking traffic as designed. Reconnect or pick another server. On hotel or airport Wi-Fi, you may need to open the network’s login page first.

What is the difference between a kill switch and always-on VPN?+

Always-on VPN starts the VPN automatically and keeps it running. A kill switch blocks traffic whenever that VPN isn’t connected. On Android, the two work together.

A VPN built for the quantum era. Post-quantum on every connection, nothing to switch on.