By Eric L.
09/08/2026 · 6 MIN READ

Split tunneling is a VPN setting that lets you choose which traffic goes through the encrypted tunnel and which goes directly to the internet.

A full tunnel sends everything through the VPN; a split tunnel sends, for example, your browser through the VPN and your banking app, printer and game straight out. It exists because "everything through the VPN" is the safest default but not always the most practical one.

TUNNEL MODESFIG. 01
everything in      full protection
some apps out      bank, printer
only chosen in     surgical
    └─ sensible default: everything in

Split tunneling vs full tunnel: how they differ

Full tunnel. The VPN app creates a virtual network interface and routes every packet from every app into it. Your ISP and local network see one encrypted connection. Websites see the VPN server's address. Nothing leaks unless something is misconfigured. This is what you want on public Wi-Fi and whenever privacy is the point.

Split tunnel. The app keeps the tunnel up but adds exceptions. Depending on the implementation, exceptions are by app (this program bypasses the VPN), by destination (this website or IP range bypasses the VPN), or inverted (only these apps use the VPN, everything else goes direct). The traffic that bypasses the tunnel behaves exactly as if the VPN were off: your real IP, your ISP's DNS, no encryption beyond what the app itself does.

● FULL TUNNEL: EVERY APP INSIDEBrowserBank appGameInternetVPN serverone encrypted connectionWebsites see the VPN server's address; the ISP and the local network see one encrypted connection.SPLIT TUNNEL: BANK APP AND GAME EXCLUDEDBrowserBank appGameInternetVPN serverencryptedreal IP, ISP DNS, no tunnelExcluded traffic behaves exactly as if the VPN were off.
An excluded app leaves the tunnel completely: to the network it looks exactly like no VPN at all.

In networking terms, the difference is in the routing table. Full tunnel sets the default route to the VPN interface. Split tunnel keeps the default route on your normal connection and adds specific routes, or uses per-app rules in the operating system, to steer selected traffic into the tunnel.

THE TWO MODESFIG. 02
include selected
  └─ only the list goes in
  └─ everything else goes direct
exclude selected
  └─ everything goes in
  └─ except the list

When split tunneling helps

  • Banking and payment apps that refuse to work through a VPN or lock your account when your country changes. Excluding them keeps the rest of your traffic protected.
  • Local devices: your printer, your NAS, casting to the TV, a console on the same Wi-Fi. A strict full tunnel can hide your own local network from you, and excluding local addresses fixes it.
  • Speed-sensitive apps: an online game or a large download that doesn't need privacy can skip the VPN's detour. The overhead is explained in does a VPN slow down your internet.
  • Work tools that must see your real location or corporate network, while the browser stays private.
  • Streaming on a TV app that behaves differently by region, while the phone's other apps stay on the VPN.
WHEN IT HELPSFIG. 03
a bank app that refuses tunnels
a work network needing direct access
a local printer or NAS
large downloads outside the tunnel
What ties these four together: none is a convenience call, each is a technical requirement the VPN can't override.

Is split tunneling safe? When it's a risk

Anything you exclude is fully exposed. Here are the three mistakes people actually make:

  1. Excluding the browser because a site didn't load, then forgetting. The browser is usually the one thing that should always be inside the tunnel.
  2. Excluding by destination on a shared network. On coffee shop Wi-Fi, the traffic you excluded is as visible to that network as if you had no VPN at all. Use split tunneling at home, not in public.
  3. DNS outside the tunnel. Some split configurations send DNS queries directly even for apps inside the tunnel, which exposes the list of sites you visit. After setting up a split tunnel, run the checks in is my DNS leaking.

A kill switch (no tunnel, no internet) only protects what's inside the tunnel. The apps you excluded keep right on working when the VPN drops, and that's by design, not a bug.

WHEN IT IS A RISKFIG. 04
browser on the exclude list  never
messenger excluded           bad
a long list                  you will
                             forget it
   └─ an excluded app goes out
      naked, with all that implies

How to set up split tunneling

Android. Split tunneling by app is native: the VPN app shows a list of installed apps with checkboxes. Android also offers "Always-on VPN" and "Block connections without VPN" in system settings; the second one applies to apps inside the tunnel only.

iPhone and iPad. iOS doesn't expose per-app split tunneling to ordinary VPN apps, except for managed devices. What VPN apps on iOS can do is exclude destinations, for example local network addresses, and use on-demand rules that switch the VPN on for certain Wi-Fi networks. If an iOS app claims per-app split tunneling, check what it actually excludes.

Windows and macOS. Most VPN apps list installed applications and let you check the ones to exclude or include. macOS additionally allows "exclude local network" so printers and AirPlay keep working.

WHAT EACH SYSTEM LETS A VPN APP SPLITANDROIDBy appnative listIPHONE, IPADBy appmanaged devicesBy destinationlocal addressesWINDOWSBy appexclude or includeMACOSBy appexclude or includeLocal networkexcludeAndroid's "Block connections without VPN" covers only the apps inside the tunnel.
What you can split depends on the system: on an iPhone it is mostly by destination, not by app.

Routers. On a router, split tunneling means policy routing: some of your devices go through the tunnel and others don't. It's the only way to run a VPN on a router without slowing down everything in the house, covered in VPN on router vs on each device.

THE INVERSE MODEFIG. 05
only the listed apps go through
everything else goes direct
   └─ useful for one work app
   └─ dangerous as a default: most
      of your traffic is then naked

Inverse split tunneling

Some apps let you flip the logic: only the selected apps use the VPN, everything else goes direct. This is convenient when you want just one program protected, say a torrent client or a browser profile for research, and don't want the rest of the system affected. The exposure is the mirror image: everything you didn't select is outside the tunnel, so treat the list as the thing you're protecting, not as exceptions.

BEFORE YOU BUILD THE LISTFIG. 06
[ ] mode: everything in the tunnel
[ ] no more than two exclusions
[ ] the browser is not one of them
[ ] review the list every few months
The opposite of the inverse mode above: default to everything in, and treat exceptions as the risk, not the rule.

An exclusion list is easier to get right once than to fix later.

Prompt for an AI
Help me build an exclusion list for my tunnel.

Device: (Android / iPhone / Windows / macOS).
Apps that do not work through the tunnel:
(list them).
Apps I use most: (list them).
Do I have a printer, NAS or cameras at home:
(yes / no).

Say what genuinely belongs outside the tunnel,
what must never be excluded, and why.
Keep the list short: the longer it gets, the less
the tunnel is worth.

A sensible default

Full tunnel everywhere, with two exclusions at most: local network access, plus one or two apps that genuinely break through a VPN. Look at that list again every few months. And on public Wi-Fi, turn the exclusions off entirely; that is where the tunnel matters most, and where excluded traffic is most visible.

404 VPN supports split tunneling by app on Android and macOS, excludes local network access on request, and keeps DNS inside the VLESS tunnel for the apps that use it, with a kill switch for the protected traffic on Android. Its WireGuard configs for Istanbul and Marseille, taken from the dashboard, send all traffic, IPv4 and IPv6, into the tunnel. Details are on the features page; get started here.