Split tunneling is a VPN setting that lets you choose which traffic goes through the encrypted tunnel and which goes directly to the internet.
A full tunnel sends everything through the VPN; a split tunnel sends, for example, your browser through the VPN and your banking app, printer and game straight out. It exists because "everything through the VPN" is the safest default but not always the most practical one.
everything in full protection
some apps out bank, printer
only chosen in surgical
└─ sensible default: everything inSplit tunneling vs full tunnel: how they differ
Full tunnel. The VPN app creates a virtual network interface and routes every packet from every app into it. Your ISP and local network see one encrypted connection. Websites see the VPN server's address. Nothing leaks unless something is misconfigured. This is what you want on public Wi-Fi and whenever privacy is the point.
Split tunnel. The app keeps the tunnel up but adds exceptions. Depending on the implementation, exceptions are by app (this program bypasses the VPN), by destination (this website or IP range bypasses the VPN), or inverted (only these apps use the VPN, everything else goes direct). The traffic that bypasses the tunnel behaves exactly as if the VPN were off: your real IP, your ISP's DNS, no encryption beyond what the app itself does.
In networking terms, the difference is in the routing table. Full tunnel sets the default route to the VPN interface. Split tunnel keeps the default route on your normal connection and adds specific routes, or uses per-app rules in the operating system, to steer selected traffic into the tunnel.
include selected └─ only the list goes in └─ everything else goes direct exclude selected └─ everything goes in └─ except the list
When split tunneling helps
- Banking and payment apps that refuse to work through a VPN or lock your account when your country changes. Excluding them keeps the rest of your traffic protected.
- Local devices: your printer, your NAS, casting to the TV, a console on the same Wi-Fi. A strict full tunnel can hide your own local network from you, and excluding local addresses fixes it.
- Speed-sensitive apps: an online game or a large download that doesn't need privacy can skip the VPN's detour. The overhead is explained in does a VPN slow down your internet.
- Work tools that must see your real location or corporate network, while the browser stays private.
- Streaming on a TV app that behaves differently by region, while the phone's other apps stay on the VPN.
a bank app that refuses tunnels a work network needing direct access a local printer or NAS large downloads outside the tunnel
Is split tunneling safe? When it's a risk
Anything you exclude is fully exposed. Here are the three mistakes people actually make:
- Excluding the browser because a site didn't load, then forgetting. The browser is usually the one thing that should always be inside the tunnel.
- Excluding by destination on a shared network. On coffee shop Wi-Fi, the traffic you excluded is as visible to that network as if you had no VPN at all. Use split tunneling at home, not in public.
- DNS outside the tunnel. Some split configurations send DNS queries directly even for apps inside the tunnel, which exposes the list of sites you visit. After setting up a split tunnel, run the checks in is my DNS leaking.
A kill switch (no tunnel, no internet) only protects what's inside the tunnel. The apps you excluded keep right on working when the VPN drops, and that's by design, not a bug.
browser on the exclude list never
messenger excluded bad
a long list you will
forget it
└─ an excluded app goes out
naked, with all that impliesHow to set up split tunneling
Android. Split tunneling by app is native: the VPN app shows a list of installed apps with checkboxes. Android also offers "Always-on VPN" and "Block connections without VPN" in system settings; the second one applies to apps inside the tunnel only.
iPhone and iPad. iOS doesn't expose per-app split tunneling to ordinary VPN apps, except for managed devices. What VPN apps on iOS can do is exclude destinations, for example local network addresses, and use on-demand rules that switch the VPN on for certain Wi-Fi networks. If an iOS app claims per-app split tunneling, check what it actually excludes.
Windows and macOS. Most VPN apps list installed applications and let you check the ones to exclude or include. macOS additionally allows "exclude local network" so printers and AirPlay keep working.
Routers. On a router, split tunneling means policy routing: some of your devices go through the tunnel and others don't. It's the only way to run a VPN on a router without slowing down everything in the house, covered in VPN on router vs on each device.
only the listed apps go through everything else goes direct └─ useful for one work app └─ dangerous as a default: most of your traffic is then naked
Inverse split tunneling
Some apps let you flip the logic: only the selected apps use the VPN, everything else goes direct. This is convenient when you want just one program protected, say a torrent client or a browser profile for research, and don't want the rest of the system affected. The exposure is the mirror image: everything you didn't select is outside the tunnel, so treat the list as the thing you're protecting, not as exceptions.
[ ] mode: everything in the tunnel [ ] no more than two exclusions [ ] the browser is not one of them [ ] review the list every few months
An exclusion list is easier to get right once than to fix later.
Help me build an exclusion list for my tunnel.
Device: (Android / iPhone / Windows / macOS).
Apps that do not work through the tunnel:
(list them).
Apps I use most: (list them).
Do I have a printer, NAS or cameras at home:
(yes / no).
Say what genuinely belongs outside the tunnel,
what must never be excluded, and why.
Keep the list short: the longer it gets, the less
the tunnel is worth.
A sensible default
Full tunnel everywhere, with two exclusions at most: local network access, plus one or two apps that genuinely break through a VPN. Look at that list again every few months. And on public Wi-Fi, turn the exclusions off entirely; that is where the tunnel matters most, and where excluded traffic is most visible.
404 VPN supports split tunneling by app on Android and macOS, excludes local network access on request, and keeps DNS inside the VLESS tunnel for the apps that use it, with a kill switch for the protected traffic on Android. Its WireGuard configs for Istanbul and Marseille, taken from the dashboard, send all traffic, IPv4 and IPv6, into the tunnel. Details are on the features page; get started here.