A VPN kill switch is a feature built into many VPN apps that automatically cuts your internet connection the moment your VPN tunnel drops. Without it, your device quietly reverts to your regular connection, exposing your real IP address and traffic to anyone watching. It sounds dramatic, but VPN connections do drop. Wi-Fi hiccups, server timeouts, and app crashes are all ordinary events that can expose you without warning.
If you're already using a VPN for privacy, understanding the kill switch is the difference between genuine protection and a false sense of security.
Why VPN connections drop in the first place
A VPN routes your traffic through an encrypted tunnel to a remote server. That tunnel is only as stable as your underlying internet connection. When your Wi-Fi drops for two seconds while you're switching between rooms, your device doesn't just pause. It falls back to your regular connection while the VPN app tries to reconnect. That brief window can last five to thirty seconds, and your real IP address is fully visible during that time.
Common causes include network congestion, ISP throttling, switching between Wi-Fi and mobile data, server-side restarts, and power-saving features on laptops and phones that interrupt background processes. None of these are rare.
What the kill switch actually does
A kill switch monitors the VPN tunnel in real time. The moment it detects the connection has dropped, it tells your operating system to block all outbound network traffic. Your browser stalls, your apps stop sending data, and nothing leaves your device unprotected. When the VPN reconnects successfully, the kill switch lifts the block and traffic flows again through the encrypted tunnel.
Some VPN apps implement this at the application level, meaning the app itself manages the block. Others operate at the system or driver level, writing firewall rules directly into the OS. System-level kill switches are generally more reliable because they remain active even if the VPN app itself crashes.
There are two main types you'll encounter:
- Application-level kill switches block only specific apps (your browser, for example) when the VPN drops. The rest of your system still has a connection.
- System-level kill switches block all traffic at the network adapter level, which provides complete coverage but can cause confusion if you're not expecting the cutout.
Who actually needs a kill switch?
Not everyone who uses a VPN needs a kill switch turned on at all times. If you're using one to access a streaming library overseas, a brief reconnect is irritating but not a real privacy risk.
The kill switch matters most in three situations. First, journalists and activists who need to keep sources and communications confidential. Second, people using public Wi-Fi at airports, cafes, and hotels, where traffic interception is genuinely easier. Third, anyone downloading or sharing files where their IP address appearing in logs could have legal or personal consequences.
For everyday Australians concerned about what a VPN actually protects them from, the kill switch is the feature that turns "mostly private" into "private even when things go wrong."
How to check if your VPN has a kill switch
Most premium VPN providers include a kill switch, though they don't always use that name. NordVPN calls it a kill switch. ExpressVPN labels it "Network Lock." ProtonVPN refers to it as a "permanent kill switch" with an option to keep it active even when the VPN is off. Whatever the name, look for it in the app's settings under "General," "Privacy," or "Advanced."
Free VPN apps rarely include a reliable kill switch. That's one of the structural reasons free VPNs offer weaker privacy guarantees overall.
To test whether your kill switch actually works, connect to a VPN server, then manually disconnect the VPN from within the app's settings (not by disabling it from the kill switch setting). If your internet cuts out immediately, the kill switch is working. If pages keep loading, it isn't.
Kill switches and split tunnelling don't mix well
Split tunnelling lets you route some apps through the VPN while others use your regular connection directly. It's a useful feature for speed, but it creates a conflict with a system-level kill switch. If the VPN drops and the kill switch fires, it blocks all traffic, including the apps you'd excluded from the tunnel. That breaks the point of split tunnelling.
Application-level kill switches handle this better, since they only block the apps you've told them to protect. If you use both features together, check your VPN provider's documentation carefully to understand which apps are covered.
The relationship between kill switches and other privacy tools
A kill switch addresses one specific failure mode: the gap between a VPN dropping and reconnecting. It doesn't protect against a VPN provider that logs your activity, nor against pixel trackers embedded in emails and web pages that follow you regardless of your IP address.
Privacy online is built in layers. The kill switch is one layer. DNS leak protection is another. A no-logs policy from your provider is another. Together they add up to something meaningful. On its own, no single feature closes every gap.
For Australians using a VPN on public networks or for sensitive work, enabling the kill switch is the single easiest step to take right now. It's already built into the app. It just needs to be switched on.

