Setting up a VPN on Android is quick, but the defaults leave two holes: the system will put the app to sleep in the background to save battery, and when the tunnel drops it'll quietly send traffic out the normal way.
Closing both takes three settings: Always-on VPN, Block connections without VPN, and Unrestricted in the app's battery options. Here's the install, those settings, Private DNS, split tunneling, and a check that it all works.
[x] Always-on VPN [x] Block without VPN [x] Private DNS: Automatic [!] Battery: Unrestricted (Samsung, Xiaomi)
Option 1: install the VPN provider's app
- Install the app from Google Play or from the provider's own site. Not from APK mirrors. If the file did come from somewhere else, compare its checksum with the one on the provider's site before installing; how, in how to check a SHA-256 checksum.
- Sign in and tap connect. Android asks once for permission to set up a VPN connection; allow it.
- In the app's settings, turn on the kill switch and DNS leak protection if they're not on by default.
- Open What Is My IP: the address and country should be the server's.
the provider's app └─ one tap, updates handled a WireGuard config └─ works without their app, keys are yours, set up once
Option 2: set up WireGuard on Android
If the provider gives you a WireGuard file or QR code, install the official WireGuard app, tap +, scan the code or import the file, and flip the toggle. What each line of the config means, and when VLESS is the better protocol, is in WireGuard vs OpenVPN and what is VLESS.
[ ] Always-on VPN
[ ] Block connections without VPN
[ ] Battery: unrestricted
└─ first two under network,
third under the appAlways-on VPN and Block connections without VPN
Settings → Network & internet → VPN → gear icon next to your VPN app. Two toggles:
Always-on VPN. The system brings your tunnel back after a reboot, a network change, or any drop. Without it, once the tunnel falls over it just stays down and you won't notice.
Block connections without VPN. Until your tunnel is up, nothing on your phone gets online. This is a system-level kill switch (no tunnel, no internet), and it works even if your VPN app has crashed. The first toggle without the second doesn't protect you: between the drop and the reconnect, traffic goes out unprotected. Why that matters is in what is a VPN kill switch.
One side effect you'll hit: the login page on public Wi-Fi (the captive portal) can't load while everything is blocked. Turn the block off for a minute, sign in to the network, turn it back on.
Always-on VPN brings it back up
after a drop
Block without VPN holds traffic
while it is down
first alone → a leak every dropBattery: why the VPN dies on Samsung and Xiaomi
Samsung, Xiaomi, Huawei, OnePlus and Oppo kill background apps aggressively. You'll know it by the symptom: the VPN works fine while you're holding the phone, then you pick it up an hour later and it's off.
Settings → Apps → your VPN app → Battery → Unrestricted (or "Don't optimize"). On Xiaomi you also want Autostart on; on Huawei, set the app to manual management under app launch. Do that and your tunnel survives the screen going dark.
fine in hand, gone an hour later └─ the shell killed the process drops when the screen locks └─ same thing, sleep mode gone after a reboot └─ autostart disabled
Private DNS and VPN on Android
Android can encrypt DNS system-wide: Settings → Network & internet → Private DNS. But with a VPN running, a third-party Private DNS hostname will send your queries outside the tunnel. So while you're on the VPN, set Private DNS to Off or Automatic and let your VPN app deal with DNS (the internet's phone book). Check with the steps in is my DNS leaking.
Split tunneling on Android
Your VPN app usually lists your installed apps with checkboxes. Banking apps that flat-out refuse to work through a VPN can sit outside while your browser and messengers stay in. Anything you exclude goes out in the open, so keep that list short, and never put your browser on it. Details in what is split tunneling.
Private DNS: automatic └─ lookups go through the tunnel Private DNS: a named host └─ lookups go around it when unsure, leave it automatic
How to check the VPN works on Android
- What Is My IP: server address, not yours.
- WebRTC leak test in the browser: real address not shown.
- IPv6 leak test: no local IPv6.
- Switch from Wi-Fi to mobile data: the key icon in your status bar shouldn't vanish for more than a couple of seconds.
- Switch servers in the app while a page is loading: it should freeze until the tunnel is back. That's your proof the block actually works.
Every Android skin names these settings differently. Ask about yours.
Help me find the right VPN settings on my Android.
Phone: (make and model). Android version: (which).
Skin: (One UI / MIUI / HyperOS / EMUI / stock).
VPN app: (name).
I need three things: always-on VPN, blocking
connections without VPN, and removing battery
restrictions for this app.
Give me the exact menu path for my skin.
If my version has no such setting, say so plainly
rather than suggesting something similar.
VPN not working on Android: quick fixes
- Won't connect on one specific network (campus, office): that network is blocking UDP, so switch your protocol to VLESS or automatic. Causes and fixes in VPN not working on Wi-Fi.
- Connected but nothing loads: that's DNS or IPv6. Recheck steps 2 and 3 and your Private DNS setting.
- Drops after a few minutes: that's the battery section above, plus why does my VPN keep disconnecting.
404 VPN's Android app uses VLESS, keeps DNS inside the tunnel, supports a kill switch and per-app split tunneling, and works with Always-on VPN. For WireGuard, the dashboard gives a config file or QR code for Istanbul and Marseille that you import as in Option 2, and blocking traffic when that tunnel drops is then up to Always-on VPN and Block connections without VPN for the WireGuard app. Get started here.