What Is a VPN Kill Switch and Why It Matters for Your Privacy
A 2026 test of 30 VPN apps found that only 16 fully blocked internet traffic the instant the connection dropped — the other 14 let real IP addresses slip through, some within seconds of the failure (TheBestVPN, 2026). That gap is the entire reason a kill switch exists. For the moment a VPN reconnects, or the minute it fails quietly in the background, a kill switch decides whether your identity stays hidden or leaks straight onto the network.
What a kill switch actually does
A kill switch is a feature built into the VPN app itself, not a separate tool. It watches the tunnel between your device and the VPN server, and if that tunnel goes down for any reason, it cuts your device’s internet access until the encrypted connection comes back.
Without a kill switch, the moment the VPN drops, your device quietly falls back to its normal, unencrypted connection — same as if the VPN had never been running. Any app or browser tab that’s mid-request at that moment sends its next packet from your real IP address, not the VPN’s.
What happens the instant your VPN drops
The failure window is usually short, but it doesn’t need to be long to matter — a single DNS lookup or one HTTPS request is enough to expose your IP to whoever is watching that connection.
A kill switch doesn’t prevent VPN drops — nothing can promise a connection never blips. What it prevents is that drop turning into a silent leak you never notice.
Why VPN connections drop in the first place
Drops are rarely dramatic. The most common triggers are mundane:
- Network handoff — switching from Wi-Fi to mobile data (or between Wi-Fi networks) briefly tears down the active tunnel.
- Server-side maintenance or restart — the VPN server your device is connected to goes down for seconds while traffic reroutes.
- OS battery optimization — the operating system suspends a background app, including the VPN client, to save power.
- Weak or congested signal — a spotty connection causes repeated handshake failures until the tunnel gives up.
Any one of these can happen while you’re mid-download, mid-call, or just idly connected with apps syncing in the background — exactly when you’re least likely to notice a leak happening.
Kill switch vs. DNS leak protection — not the same thing
These two terms get used interchangeably, but they guard against different failure modes:
| Kill switch | DNS leak protection | |
|---|---|---|
| Protects against | Your IP leaking when the VPN tunnel itself drops | DNS queries leaking outside the tunnel even while VPN is connected |
| Triggers on | Full connection loss | Misconfigured or ignored DNS routing |
| What leaks without it | Your real IP address | Which sites you’re visiting, via your ISP’s DNS resolver |
| Typically fixed by | Blocking all traffic until reconnect | Forcing DNS requests through the VPN’s own resolver |
A VPN app that only has one of the two is leaving a real gap — you want both.
The Android blind spot most people don’t know about
Even a working kill switch can’t stop what happens below the app layer. In 2022, a security audit by Mullvad found that Android sends connectivity-check traffic — DNS lookups and small HTTP requests — outside the VPN tunnel every time a device joins a Wi-Fi network, even with the OS-level “Block connections without VPN” setting turned on. Google’s engineering team classified the report as “Won’t Fix,” calling it expected behavior.
This is metadata, not your browsing activity — but it can reveal that a specific device is on a specific Wi-Fi network at a specific time, which is exactly the kind of correlation a privacy-focused VPN setup tries to avoid.
It’s one more reason the app-level kill switch matters: it’s the layer you actually control, even if the OS itself has its own quirks.
What to look for in a privacy-focused VPN app
- Automatic activation — a kill switch should be on by default, not something you have to remember to enable.
- Full-device coverage — it should block the entire device’s traffic, not just the VPN app itself.
- No manual configuration required — you shouldn’t need to import files, edit settings, or fight a menu to get baseline protection.
- A modern, DPI-resistant protocol underneath — the kill switch only matters if the underlying tunnel is worth protecting in the first place.
RunVPN is built around this baseline: after you sign in, the app configures itself automatically over VLESS-Reality and AmneziaWG, tuned for a fast, stable connection with no manual setup. There’s no config file to import and no menu to dig through — you sign in and connect. Read more about how the underlying approach to privacy works on the trust page.
FAQ
Does every VPN app have a kill switch? No. It’s a common feature among privacy-focused VPNs, but plenty of free or basic VPN apps skip it entirely, or implement it in a way that only partially blocks traffic.
Will a kill switch slow down my internet? No — it doesn’t add overhead while the VPN is connected. It only activates during the brief window when the tunnel is down, and its entire job is to block, not filter, traffic.
Can a kill switch fail? Yes, if it’s implemented poorly. Independent testing in 2025 found that many kill switches leak specifically during device reboot, before the VPN app has a chance to reconnect — which is why it matters which app you trust, not just whether the feature is listed.
Do I need to turn it on manually? That depends on the app. The safest default is one that’s active automatically the moment you connect, with nothing extra to configure.
A kill switch is a small, invisible feature until the one moment it matters. Download RunVPN and connect with a setup that’s automatic from the first sign-in.