Split tunnelling is the VPN feature that splits your traffic into two: some of it travels through the encrypted tunnel to the VPN server, and the rest goes straight out through your internet service provider as it normally would. Setting it up takes about five minutes once you’ve decided which apps belong on each side.
You’ll need three things:
The steps below follow the typical desktop and Android app. Labels vary slightly between providers, but the sequence is the same.
Open your VPN app, go to Settings, and find the split tunnelling option (sometimes listed as “App split tunnelling” or “Bypasser”). If you can’t find it, confirm that your plan and device support it, as some apps hide it on platforms where it isn’t available.
Decide which way round the rule runs, because the two modes are the same mechanism with the default reversed. Most apps offer one or both:
Pick inverse split tunnelling unless you have a reason not to.
Add each app to whichever list your mode uses. The app shows your installed programs; tick the ones that should be in the tunnel (or the ones to exclude, if you chose inverse). Be deliberate here, because anything you route outside the tunnel is unprotected and uses your real IP address (the number that identifies your connection). Keep sensitive apps inside the tunnel.
Save your settings, then connect to a VPN server. The rule takes effect once you’re connected, and the app applies it whenever you launch any of the listed programs. If your provider offers URL- or domain-based split tunnelling via a browser extension, set that up separately in the extension, as it controls websites rather than whole apps.
Check both sides of the split, because a setup that protects only some apps is only doing half its job if the wrong app ends up on the wrong side. Open an app you routed through the VPN and visit an IP-checking site; it should show the VPN server’s location.
Now open an app you excluded and do the same; it should show your real location. To be thorough, run a DNS leak test while connected, as careless split tunnelling is a common cause of leaks. If each app appears where you intended it to, your split is working.
Yes, where your app allows both. A kill switch cuts your internet if the VPN drops, protecting the apps inside the tunnel during a brief outage. It generally applies to tunnelled traffic, not the apps you’ve deliberately routed outside, so the two features work together rather than against each other.
Apple restricts how third-party VPNs handle per-app routing on iOS, so most providers can’t offer app-based split tunnelling there. Some offer a limited alternative, but if per-app control is essential, you’ll find fuller support on Windows or Android.
Not in a way you’ll usually notice. If anything, excluding a large download or a video call from the VPN can recover speed for that task, since it skips the small overhead a VPN adds. The traffic you keep in the tunnel performs as it would on a normal VPN connection.
You can now keep the VPN on for the traffic that needs it without the side effects of tunnelling everything, and you’ve confirmed each app sits on the side you intended. The one thing to watch is your exclusions: anything you route outside the tunnel is unprotected, so review the list whenever you add a sensitive app. For the concept behind the feature, see what split tunnelling is, and if your VPN lacks reliable split tunnelling on your device, it’s one of the features we weigh in how to choose a VPN.
Check your email to confirm
We sent a confirmation link to . Confirm it to activate your Kyroo cashback — you can do this anytime.
Taking you to {partner} in ...