Split tunneling lets you decide which traffic goes through your VPN's encrypted tunnel and which traffic goes straight to the internet the normal way. Instead of an all-or-nothing VPN connection, you choose specific apps, sites, or types of traffic to exclude — or, less commonly, to specifically include. It exists because a full-tunnel VPN sometimes breaks things that need your real IP address or your real local network to work properly, and split tunneling is the fix for that specific friction.
What changed in 2026
- More VPN apps expose split tunneling as a simple, per-app toggle, instead of the more technical configuration it used to require, making it accessible to non-technical users.
- Mobile split tunneling improved, with better per-app control on phones, where the feature used to lag behind desktop VPN clients.
- Guidance shifted toward narrower, more deliberate use, as more people ran into the risk of accidentally excluding traffic they meant to protect.
How it works
A normal VPN connection wraps every bit of traffic leaving your device in its encrypted tunnel, routing all of it through the VPN server. With split tunneling turned on, you specify exceptions — a particular app, a particular site, or a category of traffic — and that excepted traffic bypasses the tunnel entirely, going out through your regular internet connection instead, visible with your real IP address and without the VPN's encryption.
Common reasons people use it
| Reason |
What split tunneling solves |
| Local network devices (printers, smart TVs) |
Lets your device still reach devices on your home network while the VPN is on |
| Banking or government apps that block VPN IPs |
Lets those specific apps use your real IP instead of getting blocked |
| Saving bandwidth on the VPN connection |
Routes non-sensitive traffic like large downloads outside the tunnel |
| Using region-specific local services |
Keeps traffic that needs your real location outside the tunnel |
| Reducing speed loss for latency-sensitive apps |
Excludes apps like some games from the added latency of the tunnel |
Where it quietly works against you
The tradeoff is exactly what the feature is built to do: excluded traffic gets none of the VPN's protection. It is not encrypted by the VPN, and your real IP address is visible to whatever that traffic reaches. That is a reasonable trade for a printer or a banking app. It is a bad trade for anything you actually wanted the VPN's protection on in the first place. The risk is not the feature itself, it is scope — being vague about what you exclude rather than deliberate about it.
How to use it safely
- Exclude specific apps, not broad categories, whenever the option exists. Precision keeps the excluded surface small and intentional.
- Double-check what is excluded periodically. Settings and app lists can drift, especially after app updates change how they are identified.
- Never exclude anything privacy- or security-sensitive — banking is a reasonable exception only if the VPN itself is actually breaking the app; otherwise leave it inside the tunnel.
- If you are unsure what a rule excludes, turn split tunneling off. A full tunnel is the safer default when precision is not clear.
FAQ
Is split tunneling safe to use?
It is safe for its intended purpose — excluding specific traffic that does not need VPN protection. It becomes a risk when used broadly or carelessly for traffic that does need protection.
Does split tunneling slow down my VPN?
No, generally the opposite — excluded traffic bypasses the tunnel entirely, so it can reduce the load on your VPN connection and improve speed for the traffic still inside it.
Can I use split tunneling on my phone?
On many VPN apps, yes, with per-app controls that have improved significantly, though support still varies by provider and operating system.
Should I leave split tunneling on all the time?
Only if you have deliberately chosen what it excludes and are comfortable with that traffic being unprotected. Otherwise, a full tunnel is the simpler, safer default.
Where to go next