On this page
Definition
A kill switch is a VPN client feature that monitors the VPN connection and, if it disconnects unexpectedly, immediately cuts off the device's internet access until the VPN reconnects, preventing traffic from leaking outside the encrypted tunnel.
Simple explanation
VPN connections occasionally drop — a Wi-Fi hiccup, a server switch, a network change. Without a kill switch, your device typically just falls back to your normal, unencrypted internet connection automatically, often without any visible warning.
A kill switch prevents that silent fallback. If the VPN drops, it blocks all internet traffic outright until the encrypted connection is restored, so nothing you send or receive is ever exposed on the open network in the gap.
Why it matters
The moments right after an unexpected VPN drop are exactly when exposure is most likely, and least likely to be noticed — you keep browsing, assuming you're still protected, while your traffic is actually going out in the clear.
For anyone using a VPN specifically to avoid exposing sensitive activity, such as journalists, activists or people on untrusted networks, this brief unprotected window can matter far more than the average moment of everyday browsing.
How it works
- 1MonitoringThe VPN client continuously checks that the encrypted tunnel is active.
- 2Drop detectedIf the tunnel disconnects unexpectedly, the client detects the change immediately.
- 3Traffic blockedAll internet traffic is blocked at the firewall or network-adapter level.
- 4Reconnection attemptThe VPN client attempts to re-establish the encrypted connection.
- 5Traffic restoredOnce reconnected, internet access resumes automatically.
Real examples
Products named for illustration only. Inclusion is not an endorsement.
- ProtonVPN kill switchOffers both standard and 'always-on' kill switch modes.
- Mullvad kill switchEnabled by default, blocking traffic outside the VPN tunnel.
- NordVPN kill switchAvailable at both the app level and full system level.
- macOS/Windows firewall rulesSome advanced users configure manual firewall-based kill switches without relying on the VPN app's built-in one.
Advantages
- Prevents silent, unnoticed exposure of traffic during VPN drops.
- Requires no ongoing manual attention once enabled.
- Particularly valuable on unstable networks where disconnects are more frequent.
- Available as a standard feature in most reputable VPN clients.
Limitations
- Blocking all traffic during a drop means losing internet access entirely until reconnection, which can disrupt active downloads or calls.
- Some implementations only block traffic at the app level rather than system-wide, leaving other apps exposed.
- Not enabled by default on every VPN client, requiring manual activation.
- Poorly implemented kill switches can occasionally fail to trigger during certain types of network changes.
Common misunderstandings
- ClaimA kill switch prevents VPN disconnections from happening.RealityIt does not stop disconnections — it prevents unprotected traffic from flowing during and after one.
- ClaimAll VPNs have an equally reliable kill switch.RealityImplementation quality varies significantly, and some only cover specific apps rather than the whole device.
Frequently asked questions
Should I always leave my kill switch enabled?
Yes, if privacy is your priority — the brief loss of connectivity during a drop is a reasonable trade-off against silent exposure.
Does a kill switch protect against DNS leaks too?
Not necessarily — a kill switch blocks traffic during a full disconnect, while DNS leak protection is a separate, specific safeguard.
Will a kill switch slow down my normal browsing?
No — it has no effect on speed while the VPN connection is active and stable.
Is a kill switch available on mobile VPN apps?
Increasingly yes, though feature depth and reliability can vary more on mobile than on desktop clients.
What happens to an active download if the kill switch triggers?
It will typically pause or fail, since all internet traffic is blocked until the VPN reconnects.
The Tool Money Lab perspective
We treat a reliable, system-wide kill switch as a baseline requirement for any VPN we'd recommend for privacy-sensitive use, not an advanced extra.
When testing, we specifically force VPN disconnections to see whether traffic actually stops — a feature listed on a spec sheet isn't the same as one we've verified works in practice.
Conclusion
A kill switch blocks all internet traffic the moment a VPN connection drops, closing the silent gap where unprotected data could otherwise leak out unnoticed.
It's a small feature with an outsized impact on real-world privacy, and worth confirming is both present and system-wide before relying on any VPN for sensitive activity.