By Eric L.
09/08/2026 · 7 MIN READ

Setting up a VPN on Android is quick, but the defaults leave two holes: the system will put the app to sleep in the background to save battery, and when the tunnel drops it'll quietly send traffic out the normal way.

Closing both takes three settings: Always-on VPN, Block connections without VPN, and Unrestricted in the app's battery options. Here's the install, those settings, Private DNS, split tunneling, and a check that it all works.

FOUR THINGS, ONE LEAK EACHFIG. 01
[x] Always-on VPN
[x] Block without VPN
[x] Private DNS: Automatic

[!] Battery: Unrestricted (Samsung, Xiaomi)
The first three sit in Android's network settings. The battery override lives under a different menu entirely, which is why it gets skipped most often.

Option 1: install the VPN provider's app

  1. Install the app from Google Play or from the provider's own site. Not from APK mirrors. If the file did come from somewhere else, compare its checksum with the one on the provider's site before installing; how, in how to check a SHA-256 checksum.
  2. Sign in and tap connect. Android asks once for permission to set up a VPN connection; allow it.
  3. In the app's settings, turn on the kill switch and DNS leak protection if they're not on by default.
  4. Open What Is My IP: the address and country should be the server's.
TWO ROUTES, ONE RESULTFIG. 02
the provider's app
  └─ one tap, updates handled
a WireGuard config
  └─ works without their app,
     keys are yours, set up once

Option 2: set up WireGuard on Android

If the provider gives you a WireGuard file or QR code, install the official WireGuard app, tap +, scan the code or import the file, and flip the toggle. What each line of the config means, and when VLESS is the better protocol, is in WireGuard vs OpenVPN and what is VLESS.

THREE SETTINGS, NOT ONEFIG. 03
[ ] Always-on VPN
[ ] Block connections without VPN
[ ] Battery: unrestricted
    └─ first two under network,
       third under the app

Always-on VPN and Block connections without VPN

Settings → Network & internet → VPN → gear icon next to your VPN app. Two toggles:

Always-on VPN. The system brings your tunnel back after a reboot, a network change, or any drop. Without it, once the tunnel falls over it just stays down and you won't notice.

Block connections without VPN. Until your tunnel is up, nothing on your phone gets online. This is a system-level kill switch (no tunnel, no internet), and it works even if your VPN app has crashed. The first toggle without the second doesn't protect you: between the drop and the reconnect, traffic goes out unprotected. Why that matters is in what is a VPN kill switch.

One side effect you'll hit: the login page on public Wi-Fi (the captive portal) can't load while everything is blocked. Turn the block off for a minute, sign in to the network, turn it back on.

WHAT EACH SWITCH DOESFIG. 04
Always-on VPN      brings it back up
                   after a drop
Block without VPN  holds traffic
                   while it is down
first alone     →  a leak every drop

Battery: why the VPN dies on Samsung and Xiaomi

Samsung, Xiaomi, Huawei, OnePlus and Oppo kill background apps aggressively. You'll know it by the symptom: the VPN works fine while you're holding the phone, then you pick it up an hour later and it's off.

Settings → Apps → your VPN app → Battery → Unrestricted (or "Don't optimize"). On Xiaomi you also want Autostart on; on Huawei, set the app to manual management under app launch. Do that and your tunnel survives the screen going dark.

SYMPTOM AND CAUSEFIG. 05
fine in hand, gone an hour later
  └─ the shell killed the process
drops when the screen locks
  └─ same thing, sleep mode
gone after a reboot
  └─ autostart disabled

Private DNS and VPN on Android

Android can encrypt DNS system-wide: Settings → Network & internet → Private DNS. But with a VPN running, a third-party Private DNS hostname will send your queries outside the tunnel. So while you're on the VPN, set Private DNS to Off or Automatic and let your VPN app deal with DNS (the internet's phone book). Check with the steps in is my DNS leaking.

Split tunneling on Android

Your VPN app usually lists your installed apps with checkboxes. Banking apps that flat-out refuse to work through a VPN can sit outside while your browser and messengers stay in. Anything you exclude goes out in the open, so keep that list short, and never put your browser on it. Details in what is split tunneling.

PRIVATE DNS AND THE TUNNELFIG. 06
Private DNS: automatic
  └─ lookups go through the tunnel
Private DNS: a named host
  └─ lookups go around it
when unsure, leave it automatic

How to check the VPN works on Android

  1. What Is My IP: server address, not yours.
  2. WebRTC leak test in the browser: real address not shown.
  3. IPv6 leak test: no local IPv6.
  4. Switch from Wi-Fi to mobile data: the key icon in your status bar shouldn't vanish for more than a couple of seconds.
  5. Switch servers in the app while a page is loading: it should freeze until the tunnel is back. That's your proof the block actually works.
● FIVE CHECKS, AND WHAT A PASS LOOKS LIKE1What Is My IPthe server'saddress, notyours2WebRTC testreal addressnot shown3IPv6 testno local IPv64Wi-Fi to mobilethe key icon isback in a coupleof seconds5Switch serversthe page freezesuntil the tunnelis backThe last one is your proof that the block actually works.
What each check should show when everything is set up right.

Every Android skin names these settings differently. Ask about yours.

Prompt for an AI
Help me find the right VPN settings on my Android.

Phone: (make and model). Android version: (which).
Skin: (One UI / MIUI / HyperOS / EMUI / stock).
VPN app: (name).

I need three things: always-on VPN, blocking
connections without VPN, and removing battery
restrictions for this app.
Give me the exact menu path for my skin.
If my version has no such setting, say so plainly
rather than suggesting something similar.

VPN not working on Android: quick fixes

  • Won't connect on one specific network (campus, office): that network is blocking UDP, so switch your protocol to VLESS or automatic. Causes and fixes in VPN not working on Wi-Fi.
  • Connected but nothing loads: that's DNS or IPv6. Recheck steps 2 and 3 and your Private DNS setting.
  • Drops after a few minutes: that's the battery section above, plus why does my VPN keep disconnecting.
SYMPTOMCAUSEFIXWon't connect on one networkcampus, officeUDP is blockedby that networkSwitch to VLESSor automaticConnected, nothing loadsDNS or IPv6Recheck steps 2 and 3and Private DNSDrops after a few minutesBattery settingsthe app gets killedBattery: UnrestrictedAutostart on Xiaomi
Three common symptoms, each traced to its cause and the setting that ends it.

404 VPN's Android app uses VLESS, keeps DNS inside the tunnel, supports a kill switch and per-app split tunneling, and works with Always-on VPN. For WireGuard, the dashboard gives a config file or QR code for Istanbul and Marseille that you import as in Option 2, and blocking traffic when that tunnel drops is then up to Always-on VPN and Block connections without VPN for the WireGuard app. Get started here.