VPN Split Tunneling Explained: What It Is and When to Use It
VPN
Split tunneling lets you run two internet connections at once. Some of your traffic goes through the encrypted VPN tunnel, and the rest travels directly over your normal connection, at the same time, based on rules you set.
That’s a real departure from how a VPN normally works. By default, a VPN routes everything through the tunnel. Split tunneling deliberately punches specific holes in that, on purpose, for specific traffic.
How it works technically
You configure which apps, websites, or IP ranges bypass the VPN entirely, and everything else keeps going through the encrypted tunnel as usual. The routing decision happens on your own device, before traffic ever leaves it, so the split is enforced locally rather than negotiated with the VPN server.
The practical effect: you stay connected to the VPN for the traffic you’ve chosen to protect, while other traffic, streaming, gaming, a local printer, whatever you’ve excluded, goes out over your regular ISP connection unencrypted and untouched by the VPN.
Common use cases
Split tunneling exists because full-tunnel VPN use has real, ordinary costs, and there are specific situations where routing everything through the tunnel actively gets in the way:
Streaming services that block or restrict access when they detect a VPN, where excluding just that app lets it work normally while everything else stays protected. Gaming, where routing game traffic through a distant VPN server adds latency that shows up directly as lag, much of which is distance you cannot avoid. Remote work, where you need the VPN for company systems but don’t want ordinary browsing routed through corporate infrastructure. Local device access, printers, smart home gear, a NAS on your home network, that a full-tunnel VPN would otherwise cut you off from. And large downloads you don’t need encrypted, where excluding them preserves bandwidth for the traffic that actually matters.
The security tradeoff
The tradeoff is built into the name. Split tunneling is never as protected as a full-tunnel VPN, because by definition some of your traffic isn’t going through the tunnel at all.
The traffic you exclude gets none of the VPN’s protection: no IP masking, no encryption, visible to your ISP and anything else positioned to observe your regular connection. Misconfiguration is a real risk too, it’s easy to exclude more than you meant to, or to assume something is protected because the VPN is “on” when the app or site you’re using is actually routed outside the tunnel. And split tunneling doesn’t change what a VPN was never going to do anyway: it won’t stop phishing, and it won’t block malware, regardless of which pathway your traffic takes.
None of this makes split tunneling a bad feature. It makes it a deliberate tradeoff, more convenience and performance in exchange for narrower protection, and worth using with a clear idea of exactly what you’re excluding and why.
When it makes sense, and when it doesn’t
Split tunneling is a good fit when you know precisely what you want outside the tunnel, a specific app, a specific site, your local network, and you’re comfortable with that traffic being exposed the same way it would be without a VPN at all.
It’s a poor fit if your reason for using a VPN in the first place is broad privacy or security on an untrusted network, public Wi-Fi being the obvious case, where the traffic you’d be tempted to exclude for convenience is often exactly the traffic you most wanted covered. On a network you don’t trust, full tunneling is the safer default, and split tunneling is worth reserving for networks and situations where the risk is genuinely lower.
Checking what’s actually going through the tunnel
Because split tunneling’s whole point is that some traffic bypasses the VPN on purpose, it’s worth confirming your setup matches what you intended rather than assuming it does. Check your visible IP on My IP Address with the VPN connected, then run the Network Leak Check and WebRTC Leak Test to see what’s actually leaving your tunnel and what isn’t. If traffic you meant to protect is showing your real IP or ISP, your split tunneling rules need a second look.
A VPN kill switch is worth understanding alongside split tunneling too, since the two interact: a kill switch protects the traffic inside your tunnel if the VPN drops, but it generally has no effect on traffic you’ve already routed outside the tunnel on purpose. For a provider whose apps support proper split tunneling controls, see our NordVPN review.