Split tunneling VPN: choosing what goes through the tunnel

Split tunnelling lets you decide, application by application, which traffic goes through the encrypted tunnel and which takes the ordinary route. It exists because a VPN is all-or-nothing by default, and all-or-nothing breaks things: banking apps that refuse a foreign address, a work system that only accepts connections from your real network, a printer on the local network that vanishes the moment the tunnel comes up.

The two directions, and which one you want

Inclusive split tunnelling routes only the applications you name through the VPN and leaves everything else alone. Exclusive routes everything through the VPN except the applications you name. They sound symmetrical and they are not: exclusive is the safer default, because anything you forget to configure stays protected, while inclusive leaves anything you forget exposed. Providers ship one or both and rarely label them with these words, so the setting screen is the place to look.

The problems it actually solves

Three come up constantly. A bank or a payment app that blocks logins from an address in another country, which is fixed by excluding that one app. A work VPN or a corporate tool that conflicts with a consumer VPN running at the same time. And local devices, meaning printers, network storage, a games console or a smart speaker, that stop being reachable when everything is routed through a distant server. Each is a one-application exclusion rather than a reason to switch the VPN off entirely, which is what most people do instead.

Where it is not available

Split tunnelling is a per-platform feature, not a per-provider one. It is common on Windows and Android, less common on macOS, and largely absent on iOS, where the operating system does not give VPN apps the control it would need. If it matters on a specific device, the provider's own app page for that platform is the only reliable source, and it is linked from every provider profile on this site.

What it does not do

Split tunnelling is a routing decision, not a security feature. Traffic outside the tunnel is exactly as exposed as it would be with no VPN at all, which is the point of it, and it is worth being deliberate about which applications you have put in that category. Combining it with a kill switch is also fiddlier than it looks: an application-level kill switch and an exclusive split tunnel can be configured to contradict each other.

Questions people ask about split tunneling vpn

Does split tunneling slow the VPN down?

Not meaningfully. It reduces the traffic going through the tunnel, if anything, and the routing decision itself is negligible either way.

Can I split tunnel by website rather than by app?

Some providers offer this in a browser extension rather than the main app, which is a different thing: the extension only controls that browser's traffic.

Is split tunneling worth paying more for?

No provider in this index charges extra for it. It is a standard-plan feature wherever the platform supports it at all.

Sources

Related answers

Which VPN do I need?Compare VPN prices