AnonymFlow
securite-reseauINFO

Split Tunneling Explained: Route Some Apps Through the VPN, Others Direct (2026)

Split tunneling lets you send some apps or sites through the VPN while the rest use your normal connection. How it works, the three types, real use cases, and the leak risks to watch - explained without the marketing.

By Eric Gerard · Editor · AnonymFlow4 min readPhoto: Unsplash

Most people treat a VPN as all-or-nothing: either every app runs through the encrypted tunnel, or the VPN is off. Split tunneling is the middle path - it lets you send some traffic through the VPN while the rest uses your normal connection. Done well, it's genuinely useful; done carelessly, it quietly exposes traffic you assumed was protected. This guide explains how split tunneling works, the three types, when to use it, and the leak risks to watch.

What split tunneling is

A VPN normally captures all your device's traffic and routes it through an encrypted tunnel to a VPN server. Split tunneling changes that rule selectively: you decide which apps or destinations go through the tunnel and which bypass it to use your real, direct connection.

The benefit is flexibility. The catch, stated plainly: anything you route outside the tunnel is not protected - it travels over your normal connection with your real IP, visible to your ISP. Split tunneling is about applying that trade-off deliberately, not accidentally.

The three types

  • App-based (most common). You choose which applications use the VPN and which skip it - e.g. browser through the VPN, banking app direct. NordVPN and most providers offer this on Windows, macOS and Android.
  • URL/domain-based. Usually a browser extension: named sites go through (or around) the tunnel, the rest follow the default. Finer-grained for web use.
  • Inverse split tunneling. Everything goes through the VPN by default except the apps or sites you explicitly exclude. This is the safer default, because any new app is protected automatically - you only ever open specific, deliberate holes.

Note: iOS rarely supports split tunneling because Apple's VPN APIs restrict it; it's mainly a desktop and Android feature.

Real use cases

  • Keep local devices reachable. Route your traffic through the VPN but exclude your LAN so a printer, NAS or smart-home hub stays accessible.
  • Bank direct, stream abroad. Many banks block or challenge VPN IPs. Send your streaming app through a foreign server while your banking app uses your real connection.
  • Speed for heavy, non-sensitive traffic. Keep a large game download or backup off the tunnel so it doesn't pay the encryption/detour overhead.
Editorial pick
4.6 / 5

NordVPN - app-based split tunneling on desktop & Android

NordLynx (WireGuard) · App split tunneling · Internet Kill Switch · 30-day money-back guarantee

Deloitte audit 202430-day guarantee14M+ users
See the offer

An open laptop showing code on a desk
An open laptop showing code on a desk

The risk to watch: what leaks outside the tunnel

The whole danger of split tunneling is misjudging what to exclude. Exclude a browser "for speed," then use it for something sensitive, and you've sent that traffic in the clear with your real IP. Two safeguards:

  1. Prefer inverse split tunneling on untrusted networks - protect everything, exclude only specific apps you're sure don't need privacy.
  2. Pair it with a kill switch. A split-tunnel setup still benefits from a kill switch so that, if the VPN drops, the tunneled apps don't silently fall back to your real connection.

After configuring it, verify reality matches intent: run a DNS/IP leak test and confirm the apps you meant to protect show the VPN's IP - see how to check your VPN works and our complete VPN security audit.

The bottom line

Split tunneling turns the VPN from a blunt all-or-nothing switch into a precise tool: protect what matters, keep local devices and VPN-hostile services on your real connection, and spare bandwidth-heavy traffic the detour. Just respect the trade-off - excluded traffic is unprotected - favour inverse split tunneling on untrusted networks, and verify with a leak test that the apps you care about really are inside the tunnel.

Editorial guide based on how split tunneling works across major VPN clients (app-based, URL-based and inverse modes) and its documented platform limits (notably iOS). The commercial link carries the rel="sponsored nofollow" attribute; an affiliate commission may apply at no extra cost to you.

Tools and guides related to split tunneling and VPN security

Editorial pick
4.6 / 5

Secure your connection with NordVPN

Threat Protection blocks trackers & malware · kill switch · 30-day money-back

Deloitte audit 202430-day guarantee14M+ users
See the offer
Everything you need to know.

Frequently asked questions

What is split tunneling?

Split tunneling is a VPN feature that routes only part of your traffic through the encrypted tunnel while the rest uses your normal internet connection. For example, you can send your browser and a streaming app through the VPN to reach a foreign catalogue, while your banking app and local printer keep using your real connection. It lets you get VPN benefits where you want them without forcing every app through the tunnel - at the cost that whatever you route outside the tunnel is not protected.

What are the types of split tunneling?

Three common forms. App-based (the most common): you pick which applications use the VPN and which bypass it. URL/domain-based (often a browser extension): specific websites go through the tunnel or around it. Inverse split tunneling: everything goes through the VPN by default except the apps or sites you explicitly exclude - the safer default, because new apps are protected automatically. NordVPN and most major providers offer app-based split tunneling on desktop and Android; iOS rarely supports it due to Apple's VPN restrictions.

Why would I use split tunneling?

Common reasons: keep a local device reachable (a printer, a NAS, a smart-home hub) while the rest of your traffic is on the VPN; access a foreign streaming catalogue in one app while your bank - which may block or flag VPN IPs - uses your real connection; or improve speed for bandwidth-heavy apps that don't need privacy (a game download) by keeping them off the tunnel. It's about applying the VPN selectively rather than all-or-nothing.

Is split tunneling safe?

It's safe if you understand the trade-off: anything you route outside the tunnel travels over your normal connection, visible to your ISP and exposed on public Wi-Fi, with your real IP. The risk is misjudging what to exclude - excluding a browser you then use for something sensitive defeats the purpose. On untrusted networks, prefer inverse split tunneling (protect everything, exclude only specific safe apps) and combine it with a kill switch so a VPN drop never silently exposes the tunneled apps.

Does split tunneling slow down my VPN?

If anything it can speed things up for the apps you exclude, because they skip the encryption overhead and the detour through the VPN server and use your direct connection instead. The apps still inside the tunnel perform exactly as they would normally on the VPN. Split tunneling doesn't make the VPN itself faster - it just lets bandwidth-heavy, non-sensitive traffic avoid the tunnel entirely, which can ease congestion and improve overall responsiveness.