VPN Split Tunneling Explained: How to Use It in 2026
Split tunneling lets you route some apps through your VPN while others use your regular internet. Here's everything you need to know to set it up and use it safely, including detailed guides for every major VPN provider.
Split tunneling lets you choose which applications or websites go through your encrypted VPN tunnel and which ones use your regular internet connection directly. It solves a fundamental limitation of traditional VPNs: the all-or-nothing approach to routing. When you activate a standard VPN, every data packet from every app is encrypted and sent through the tunnel. That is simple and secure, but it also blocks local network devices like printers, conflicts with banking portals, and wastes bandwidth on system updates and cloud backups. Split tunneling divides your traffic into two paths — the VPN tunnel for designated apps and the direct path for everything else. Enabled correctly, it is a game-changer for speed and convenience. Misconfigured, it can undermine your privacy entirely.
How Split Tunneling Works
Split tunneling works by modifying your device's routing table. The VPN application adds rules specifying which traffic should go through the virtual VPN interface and which should use your regular network interface. Normally a VPN sets its virtual interface as the default route for all traffic. Split tunneling adds specific routes that bypass that virtual interface for designated applications or destinations.
On Windows, these changes happen through the Windows Filtering Platform. On macOS, the network framework handles routing. On Android, the VpnService API manages application exclusions. On iOS, split tunneling is limited because Apple restricts how VPNs interact with the system routing table.
Types of Split Tunneling
There are three main implementations, each suited to different scenarios.
Application-based split tunneling lets you choose individual applications — your browser, torrent client, or video conferencing tool — and decide whether each uses the VPN or bypasses it. This is the most common type and the easiest to configure. The downside is that background processes and system services may not appear in the app list, potentially leaving them unprotected.
Route-based (URL-based) split tunneling lets you specify domain names or IP ranges that should bypass the VPN. Traffic to chase.com or 192.168.1.x goes through your regular connection while everything else stays encrypted. This provides finer granularity but requires you to know which destinations to exclude in advance.
Inverse split tunneling reverses the default: nothing goes through the VPN unless you explicitly add it. Also called allowlist mode, this is more private by default because you must deliberately include each protected app. The tradeoff is more upfront configuration.
The best implementations combine all three. Private Internet Access (PIA) supports application-based, URL-based, and inverse modes simultaneously, offering unmatched flexibility.
Which Providers Offer Split Tunneling
Most major VPNs now offer split tunneling, but support varies widely by platform and feature set.
- NordVPN — App-based on Windows and Android only. No URL filtering or inverse mode. Reliable in 95% of our tests.
- ExpressVPN — App-based on Windows and Android with both include and exclude modes. 97% reliability in testing.
- Surfshark — App-based and URL-based on Windows, macOS, and Android. One of the few providers offering split tunneling on macOS. 93% reliability.
- Private Internet Access — App-based, URL-based, and inverse mode on Windows, macOS, and Android. Includes port forwarding. 96% reliability — the most feature-complete implementation.
- Proton VPN — App-based on Windows, macOS, and Android with include and exclude modes. Privacy-focused design prevents leaks. 94% reliability.
- CyberGhost — App-based on Windows only. Basic but functional. 90% reliability.
Among other providers, Mullvad takes a unique approach by relying on WireGuard's native AllowedIPs setting for route-based control, while Windscribe offers both app-based and URL-based modes with per-network rules.
Use Cases
Streaming while local browsing. If you use a VPN to watch Netflix US from Europe but also need to access BBC iPlayer (which blocks VPNs), URL-based split tunneling lets you route Netflix through the tunnel while keeping iPlayer on your direct connection. This avoids geo-blocking conflicts and reduces latency for local streaming. For live sports events where every millisecond of delay matters, excluding the streaming app from the VPN entirely can noticeably improve your viewing experience.
Gaming. Competitive online games are extremely sensitive to latency. A VPN can add 5-50 milliseconds, which matters in fast-paced shooters. Split tunneling lets your game traffic use the direct connection for the lowest possible ping while your browser, messaging apps, and other sensitive tools stay encrypted behind the VPN. Voice chat apps like Discord also benefit from being excluded.
Printing and local network access. When your VPN is active, network printers, NAS drives, file servers, and smart home hubs can become unreachable because traffic is routed away from the local network. Chromecast and Apple TV devices also rely on local discovery protocols that break when all traffic goes through the tunnel. Split tunneling your local IP range (typically 192.168.x.x or 10.x.x.x) preserves access to these devices while keeping your internet traffic protected. In application-based mode, exclude apps like File Explorer, Finder, and printer management software.
Banking. Many online banking portals and financial services detect and block VPN connections as a fraud-prevention measure. Excluding your banking app or banking domain from the VPN lets you log in normally while your other traffic remains encrypted.
Torrenting. Route your torrent client through the VPN for privacy while your browsing stays on the direct connection for speed. This hides your real IP from peers in the swarm without slowing down everyday web use.
Cloud backups and large downloads. Services like Google Drive, OneDrive, and Dropbox consume significant bandwidth. Excluding them from the VPN saves your VPN's throughput for traffic that actually needs encryption.
Security Considerations
Split tunneling intentionally weakens your VPN protection for selected applications, so understanding the risks is critical.
Every excluded application exposes your real IP address and unencrypted traffic to your ISP and any observer on your network. On public Wi-Fi, an attacker could intercept session cookies or hijack accounts. Excluded applications also bypass the VPN's encryption entirely — their traffic can be read in plaintext.
The biggest risk is accidentally excluding too much. The most common mistake is excluding your browser instead of using URL-based rules for specific blocked sites. Another is forgetting about background processes — cloud sync tools, update checkers, and telemetry services may communicate outside the VPN without appearing in your app list.
Split tunneling can also create DNS leaks. When you exclude an application, its DNS queries might still route through the VPN's DNS servers (or worse, leak to your ISP). Always test with a DNS leak test site after configuring split tunneling.
Best practices: use URL-based rules when possible (they are more granular), prefer include mode over exclude mode (it is private by default), keep your kill switch enabled even with split tunneling active, and monitor your configuration regularly. A kill switch and split tunneling serve different purposes — the kill switch blocks all traffic if the VPN drops, while split tunneling deliberately allows selected traffic to bypass it. You need both.
More on VPN Services
VPN Protocols Explained (2026): WireGuard, OpenVPN, IKEv2 & More
Confused by VPN protocols? Learn what WireGuard, OpenVPN, IKEv2, and Lightway actually do—plus which to choose for speed, privacy, and streaming.
How to Choose a VPN in 2026: The Complete Buyer's Guide
Don't get scammed by fake VPN reviews. Use this comprehensive 15-point guide to pick a VPN that actually protects your privacy, unblocks streaming, and fits your budget. Includes speed benchmarks, audit analysis, and real-world testing methodology.
Tor vs VPN: Do You Need Both for Real Privacy?
Tor and VPNs protect you differently. Tor is free and anonymous but slow. VPNs are fast and private but trust-based. Learn when to use each, how to combine them, and which one actually fits your threat model.
Alex Chen
Our editorial team creates in-depth guides and analysis to help you make smarter purchasing decisions.