VPN Guide
What Is VPN Split Tunneling?
Split tunneling is a VPN feature that lets you choose which apps or websites use the encrypted VPN tunnel and which connect directly through your regular internet connection. It's the best of both worlds: you can protect sensitive activities while keeping strong practical performance for everything else. Here's how it works and when you should use it.
Editorial shortlist
Need a VPN recommendation now?
Skip the theory — compare our top-rated VPNs for US users, with pricing, privacy notes, and setup guides.
See all VPN reviewsCompare providersHow Split Tunneling Works
By default, a VPN routes all your internet traffic through the encrypted tunnel — this is called full-tunnel mode. Split tunneling gives you granular control by letting you create two paths: one through the VPN and one through your regular ISP connection.
For example, you might route your web browser and email through the VPN for privacy while letting your gaming traffic go directly for the lowest possible latency. Or you might VPN-protect your P2P client while allowing smart home devices to connect directly to local services.
Under the hood, split tunneling works by modifying your device's routing table. When you designate an app for VPN routing, the VPN software creates firewall rules that direct that app's packets into the encrypted tunnel while allowing other apps to use the default gateway.
Types of Split Tunneling
App-based split tunneling lets you choose which applications use the VPN. You select specific apps to include or exclude from the VPN tunnel. This is the most common type and is offered by NordVPN, Surfshark, and ExpressVPN on supported platforms.
URL-based split tunneling works at the website level. You can specify which domains go through the VPN, typically through a browser extension. ExpressVPN's browser extensions support this approach.
Inverse split tunneling flips the default: all traffic goes through the VPN except the apps you specifically exclude. This is the most secure approach because new apps are automatically protected — you have to deliberately opt them out of VPN protection.
Per-device split tunneling is available on some routers with VPN support. You can configure certain devices (like a gaming console) to go directly while others (like laptops) use the VPN.
When to Use Split Tunneling
Split tunneling is ideal when you need privacy for some activities but not others. Common use cases include:
- Remote work — VPN for company resources, direct connection for personal browsing
- Gaming — Direct connection for lowest ping while protecting browser traffic
- Banking — Some banks flag VPN connections as suspicious, so exclude your banking app
- Local network devices — Access printers, smart home devices, and NAS drives while VPN-connected
- Bandwidth management — Keep high-bandwidth activities off the VPN to reduce server load
- Speed optimization — Route only privacy-sensitive traffic through the VPN
Split tunneling is also useful if you have a limited VPN data plan or are on a metered connection where bandwidth is expensive.
Security Considerations
Split tunneling introduces a tradeoff: convenience vs. comprehensive protection. Traffic that goes directly is visible to your ISP and unprotected on public Wi-Fi. If you're on an untrusted network (airport, hotel, coffee shop), use full-tunnel mode instead.
Also be aware that DNS leaks can occur with split tunneling if not properly configured. Your device might send DNS queries through the direct connection even for VPN-routed traffic, potentially revealing the websites you're visiting. Use a VPN that handles DNS queries within the tunnel regardless of split tunneling settings.
Finally, consider the risk of app identification errors. If you accidentally exclude a sensitive app from the VPN tunnel, that traffic travels unprotected. Inverse split tunneling (exclude specific apps, protect everything else) is safer than inclusive split tunneling (only protect specific apps).
Platform Support for Split Tunneling
Split tunneling support varies significantly by platform:
Windows — Full app-based split tunneling supported by most major VPNs. This is the most mature implementation.
Android — Android's VPN API supports per-app routing, making split tunneling reliable and widely available.
macOS — Limited support due to Apple's networking APIs. ExpressVPN offers split tunneling on macOS; most others don't.
iOS — Apple does not allow third-party VPN apps to implement split tunneling due to platform restrictions. Some VPNs offer URL-based splitting through Safari extensions as a workaround.
Linux — Split tunneling is available through manual iptables/routing table configuration or through GUI apps from NordVPN and Private Internet Access.
How to Check Split Tunneling
When checking split tunneling, verify three things:
- Routing accuracy — Confirm that included apps use the VPN tunnel and excluded apps use the direct connection
- DNS leak prevention — Run a DNS leak check for VPN-routed traffic
- Kill switch interaction — Check how the kill switch behaves when the tunnel drops
These checks are most practical on Windows and Android, where split tunneling support is broader.
Frequently Asked Questions
Continue comparing
Full reviews
Reviewed Sep 2026 · Public-source research · First-party tests appear on review pages when dated results are published · Verify details on provider sites. Editorial policy & scoring