Back to Blog•
September 29, 2026
•
8 min

What Is VPN Split Tunneling? How It Works and When to Use It

Split tunneling sends some traffic through the VPN and the rest direct. How it works, the types, when to use it and the risks.

A VPN normally sends all of your internet traffic through its encrypted tunnel. That's the point: everything is protected. But sometimes you want an exception. Your banking app refuses to work over a VPN. Your printer disappears from the network. A streaming app shows the wrong country. A work tool only works from your home IP address.

Split tunneling is the feature that handles those exceptions. It lets you decide which traffic goes through the VPN and which goes straight to the internet. Here's how it works, the different types, when it's worth using, and the risks to understand before you turn it on.

TL;DR
  • Split tunneling sends some traffic through the VPN and the rest through your normal connection.
  • You can split by app, by website or IP, or flip the logic with inverse mode: only chosen apps use the VPN.
  • Useful for banking apps, printers, smart TVs, gaming and saving bandwidth.
  • The trade-off: excluded traffic isn't protected. Your ISP or Wi-Fi owner sees it, and sites see your real IP.
  • Android and Windows apps usually support it. iPhone apps generally don't.

How VPN split tunneling works

Without split tunneling, a VPN creates one route for everything. Every app and every request goes into the encrypted tunnel, out through the VPN server, and on to the internet. Websites see the VPN server's IP address, and your internet provider sees only encrypted traffic going to one server.

With split tunneling, the VPN app installs two routes:

  1. The tunnel route, for traffic you want protected. It's encrypted and exits from the VPN server.
  2. The direct route, for traffic you exclude. It goes out through your normal internet connection, from your real IP address, exactly as if the VPN were off.

Your device decides which route each connection takes based on the rules you set: by app, by website or IP address, or by type of traffic.

Types and modes of split tunneling

ModeWhat goes through the VPNExampleBest for
Exclude (standard)Everything except the apps or sites you pickBanking app goes direct, the rest stays in the VPNMost people. Safer default, forgotten apps stay protected
Include (inverse)Only the apps or sites you pickOnly the torrent client uses the VPNProtecting one app while everything else stays fast
By URL or IPChosen domains or address rangesyourbank.com goes directSites that block VPNs. Harder to maintain, IPs change

App-based split tunneling is the most common in consumer VPN apps. You pick apps from a list. On Android, this works through the system's VPN framework, which lets VPN apps include or exclude specific apps.

URL or IP-based split tunneling routes traffic by destination. It's more precise but harder to maintain, because large services use many IP addresses that change over time.

Inverse split tunneling flips the default. In inverse (or "include") mode, only the apps you pick use the VPN and everything else goes direct. In standard "exclude" mode, everything uses the VPN except what you pick. Exclude mode is safer for everyday use: if you forget about an app, it stays protected. Inverse mode fits a narrow job, such as protecting one app.

When split tunneling is useful

  • Banking and payment apps. Some banks flag or block VPN IP addresses. Excluding the banking app lets it connect from your real address while the rest of your traffic stays protected.
  • Local devices. Printers, network drives, smart TVs, Chromecast and AirPlay often become unreachable when all traffic goes through a VPN, because your device stops seeing the local network. Excluding local traffic fixes it.
  • Streaming and local content. Watch a local service from your real location while other apps stay in the VPN, or the other way around.
  • Gaming. Route the game directly for the lowest latency, while your browser and chat stay protected.
  • Work tools. Companies often split traffic so video calls and cloud apps go direct, while internal systems go through the corporate VPN. Microsoft publishes guidance for sending Microsoft 365 traffic outside the corporate tunnel for this reason.
  • Getting around a local block. In Spain, for example, some legitimate sites go offline during LaLiga matches because of IP blocking. Sending only the affected traffic through a VPN keeps everything else on your normal connection. See our guide to LaLiga blocks in Spain.
  • Saving bandwidth. Large downloads or updates from trusted sources don't need to go through the VPN.

The risks and trade-offs

Split tunneling is a convenience feature, and every exception is a gap in your protection. Know what you're giving up:

  • Excluded traffic isn't encrypted by the VPN. Your internet provider, the Wi-Fi owner, or anyone on a public network sees it the same way they would without a VPN. HTTPS still protects page content, but not which services you connect to.
  • Excluded apps reveal your real IP address and location.
  • DNS can leak. If the VPN isn't careful about DNS, lookups for excluded or even included traffic can go to your normal DNS server. Run a DNS leak test after setting up split tunneling.
  • Browsers are tricky. If a browser is excluded, every site in it goes direct, including ones you'd want protected.
  • On public Wi-Fi, keep exclusions to a minimum. Café, hotel and airport networks are where the tunnel matters most.
  • Work devices. Corporate split tunneling is set by your IT team for a reason. Don't change it on a managed device.
Exclude it, or keep it in the tunnel?
Banking app that blocks VPNsExclude
Printer, Chromecast, NASExclude local network
Game that needs low pingExclude
Browser on public Wi-FiKeep in the tunnel
Messaging and email appsKeep in the tunnel

A good rule: use exclude mode, exclude only what breaks, and review the list now and then.

Which devices support split tunneling?

PlatformSupportNote
WindowsWidely supportedApp-based and IP-based
AndroidWidely supportedBuilt into the system VPN framework
macOSVaries by appDepends on the VPN app and macOS version
iPhone and iPadGenerally noTrue per-app VPN mainly on organization-managed devices
RouterDevice-levelRoute chosen devices through the VPN for the whole home

How to set up split tunneling

The exact steps depend on the VPN app, but the flow is almost always the same:

  1. Open the VPN app's Settings.
  2. Find Split tunneling (sometimes under Advanced or Connection).
  3. Choose the mode: exclude apps (everything uses the VPN except selected apps) or include apps, also called inverse (only selected apps use the VPN).
  4. Add the apps, sites or IP addresses.
  5. Reconnect the VPN.
  6. Test: check your IP address in an included app and an excluded app. They should differ. Then run a DNS leak test.

Split tunneling vs. a kill switch

These two features pull in opposite directions, so it's worth understanding how they interact.

  • A kill switch blocks traffic if the VPN connection drops, so nothing leaks outside the tunnel.
  • Split tunneling deliberately lets some traffic go outside the tunnel.

How they interact depends on the VPN app. A system-level kill switch blocks all traffic on the device when the tunnel drops, which can cut excluded apps off too. Other apps let excluded apps keep using your normal connection. Check how your VPN handles it, and remember that excluded apps are never protected by the tunnel.

Split tunneling in Atomic VPN

Split tunneling is coming to Atomic VPN. Until it ships, Atomic VPN protects all of your traffic on the device, which is the safest default. When split tunneling arrives, it will be included on every plan.

What you get today:

  • WireGuard by default, about 890 Mbps on a 1 Gbps line with 0.2-second reconnects, plus OpenVPN over TCP 443 for restrictive networks. See WireGuard vs OpenVPN.
  • DNS inside the tunnel, with IPv6 blocked outside it by default.
  • Router setup that covers every device on your home network without using a device slot.
  • No activity logs, RAM-only servers and an independently audited no-log policy.
  • $2 a month on the yearly plan, 5 devices, 88+ countries.

Apps for Windows and macOS are available now. iOS and Android apps are on the way.

Protect everything by default

Atomic VPN sends all your traffic through the tunnel today. WireGuard speed, 88+ countries, 5 devices, from $2 a month on the yearly plan.

FAQ

What is split tunneling in a VPN?

It's a feature that sends some of your traffic through the encrypted VPN tunnel and lets the rest use your normal internet connection. You choose which apps, sites or addresses go where.

Is split tunneling safe?

It's safe for the traffic that stays in the tunnel. Traffic you exclude isn't protected by the VPN, so exclude only what you need to, and avoid exclusions on public Wi-Fi.

Should I turn split tunneling on or off?

Leave it off unless something breaks with the VPN, such as a banking app, a printer or a local device. Then exclude just that app or device.

What is inverse split tunneling?

It's the reverse of standard split tunneling: only the apps or addresses you choose go through the VPN, and everything else connects directly. It suits protecting one app. For everyday use, exclude mode is safer, because anything you forget stays protected.

Does split tunneling make my VPN faster?

It can. Traffic you exclude skips the VPN server, which frees up bandwidth and lowers latency for those apps. Traffic in the tunnel runs at the same speed as before.

Can I use split tunneling on iPhone?

Usually not in consumer VPN apps. iOS offers per-app VPN mainly on devices managed by an organization. Android, Windows and many macOS VPN apps support it.

Does split tunneling cause DNS leaks?

It can, if the VPN handles DNS poorly. Run a DNS leak test after setting it up to make sure lookups for tunneled traffic go through the VPN.

What's the difference between split tunneling and a kill switch?

A kill switch blocks traffic when the VPN drops. Split tunneling lets chosen traffic bypass the VPN on purpose. Excluded apps are never protected by the tunnel, and how they behave when it drops depends on the VPN app.

‍

Questions and answers

Apps for everything you own

Windows icon
Windows
Download
Google Play icon
Android
Download
App Store icon
iOS
Coming soon
Android TV icon
Android TV
Coming soon
Chrome icon
Chrome
Coming soon
Firefox icon
Firefox
Coming soon
Linux icon
Linux
Coming soon

Stay private on any Wi‑Fi

One account, five devices, 88+ countries. From $2 a month on the yearly plan, cancel in one click.