Every other feature of a VPN describes what happens when it works. The kill switch is the only one that describes what happens when it does not.
That makes it the most honest item in the product, and the least tested.
What it does
When the tunnel drops, your applications do not stop. They fall back to the ordinary connection and carry on, quietly, with your real address attached. Most of them will not tell you.
The kill switch blocks traffic while the tunnel is not up. That is the entire feature, and its value is proportional to how often your tunnel drops, which is more often than the interface suggests: a laptop lid closing, a train tunnel, a wifi handover, a server restarting.

The cover is still closed, which is the point of the photograph. A stop button nobody has ever pressed and a stop button that does not work look exactly the same from the outside, and the difference only appears on the day it is needed.
App-level and system-level are not the same product
They are sold under the same name.
App-level closes the applications you nominated. Usually a browser, sometimes a torrent client. Everything you did not list keeps talking, and most people do not list everything, because most people do not know everything their machine talks to.
System-level blocks all traffic at the operating system firewall until the tunnel returns. It is the one people believe they have.
Checking which one you actually have takes thirty seconds in the settings, and it changes what the feature means for you.
The gap at reconnection
The switch blocks while the tunnel is down and unblocks when it comes back. The interesting part is what counts as coming back.
A careful implementation holds the block until the tunnel is verified, not merely started. A less careful one releases it earlier, leaving a short window where traffic flows before protection is genuinely restored.
You cannot read this off a feature list, and providers do not usually document it. Which is why the test below is worth more than the comparison table.
How to test yours, in two minutes
Do not click disconnect. That is the path the software handles gracefully, and testing it proves nothing.
- Connect the VPN.
- Start something producing continuous traffic that you can watch.
- Kill the tunnel abruptly: end the VPN process, or drop the network interface for a moment.
- Watch whether the traffic stops immediately.
You are testing the failure the software did not plan for, which is the only failure that matters. A switch that survives a polite disconnect and not an abrupt one is worse than no switch, because it is trusted.

Every breaker on this board is labelled and nobody knows which one cuts what until somebody flips it. Documentation is a claim. Flipping it is a measurement, and the two are only occasionally the same.
What it costs, and why that cost is the feature
It will block something you wanted, at a bad moment. A video call that dies because the tunnel hiccuped. A file upload that stops halfway.
That is the switch working correctly. The alternative was the upload continuing without protection, which is exactly what you enabled it to prevent.
If you find yourself turning it off to get things done, you have learned something true about your own priorities: you prefer availability to privacy in that situation. That is worth knowing about yourself before an incident rather than after, and it may mean your threat model is smaller than your settings suggest.
What it does not do
It does not hide anything while the tunnel is up. Your login, your cookies, your browser fingerprint are all untouched by it.
It does not fix a leak that happens through the tunnel, such as DNS queries escaping around it or WebRTC handing your address to a page directly. Those are different failures with different fixes, and a working kill switch will sit there quietly while they happen, because from its point of view nothing is wrong.
Frequently asked questions
- What does a VPN kill switch actually do?
- It blocks your device's traffic when the tunnel is not up. Without one, a dropped connection means your applications quietly carry on over the ordinary connection, exposing your real address to whatever they were talking to. The switch is the answer to a question the rest of the product does not ask: what should happen when this stops working.
- What is the difference between an app-level and a system-level kill switch?
- An app-level switch closes specific applications you nominated, usually a browser or a torrent client. A system-level switch blocks all network traffic at the operating system's firewall until the tunnel returns. They are marketed under the same name and they are not the same product: the first leaves everything you did not list running freely, and most people do not list everything.
- Does a kill switch protect me at reconnection?
- That is the gap worth knowing about. The switch blocks traffic while the tunnel is down, then unblocks once it is up again. The risk sits in the moments around that transition, and its size depends entirely on the implementation. A well built switch keeps the block in place until the tunnel is verified rather than merely started. This is not something you can read off a feature list, which is why testing yours matters more than choosing on the basis of the checkbox.
- How do I test a VPN kill switch?
- Connect the VPN, start something that produces continuous traffic, then cut the tunnel abruptly rather than clicking disconnect: kill the VPN process, or pull the network for a moment. Watch whether the traffic stops. Disconnecting politely through the interface is not the test, because that is the path the software handles gracefully. You are checking the failure it did not plan for.
- Should the kill switch always be on?
- On the device where it matters, yes, and expect it to cost you something. It will occasionally block a connection you wanted, usually at the worst moment, and that is the feature working. If you find yourself turning it off to get something done, you have learned that your real preference is availability over privacy, which is worth knowing about yourself before an incident rather than after.
Store your files privately → pCloud
Swiss privacy · 10 GB free · optional zero-knowledge Crypto



