A kill switch blocks all internet traffic if your VPN connection drops unexpectedly, so your phone never falls back to your unprotected real IP address without you knowing. On desktop, most VPN apps enable this by default. On mobile, it’s frequently buried in a settings menu or, in some apps, not turned on out of the box at all. Here’s exactly where to find it.
Why mobile kill switches matter more than people think
Phones move between networks constantly: Wi-Fi to cellular data, one Wi-Fi network to another, dead zones in elevators and parking garages. Every one of those transitions is a moment where a VPN connection can briefly drop. Without a kill switch, your phone reverts to your normal connection during that gap, exposing your real IP address for however long it takes the VPN to reconnect, sometimes just seconds, sometimes longer on an unstable network.
For anyone using a VPN for a reason that actually matters, avoiding surveillance in a restrictive country, keeping torrenting traffic private, or simply not wanting gaps in protection, that brief exposure window is exactly the failure the kill switch exists to prevent.
Setting up a kill switch on iPhone
Apple’s iOS has a system-level feature for this, separate from whatever toggle your VPN app itself provides, and turning on both is the more reliable approach.
iOS system setting: Go to Settings > VPN and Device Management > VPN, tap the info icon next to your VPN configuration, and enable “Connect On Demand” if your provider’s app supports this integration. Not every VPN app plugs into this iOS feature, so check your specific provider’s support documentation.
In-app setting (NordVPN, ExpressVPN, Surfshark, ProtonVPN): Open the app, go to Settings, and look for “Kill Switch” or “Network Lock” (naming varies by provider). Toggle it on. NordVPN and ExpressVPN both enable a straightforward on/off toggle here; ProtonVPN calls the same feature “Always-on VPN” in its iOS settings.
Setting up a kill switch on Android
Android has a built-in, OS-level kill switch that works with any VPN app, which makes this more consistent across providers than iOS.
Android system setting: Go to Settings > Network & Internet > VPN, tap the gear icon next to your active VPN app, and enable “Block connections without VPN.” This is Android’s native kill switch and it works regardless of which VPN app you’re using, since it operates at the operating system level rather than depending on the app’s own implementation.
In-app setting: Most major VPN apps (NordVPN, Surfshark, ProtonVPN, Mullvad) also include their own kill switch toggle in the app’s settings menu, usually under a “Connection” or “Advanced” section. Turning on both the Android system setting and the app’s own toggle isn’t redundant, it covers you if one implementation has a gap the other doesn’t.
How to test that it’s actually working
Turning on a kill switch setting and confirming it works are two different things. To test it: connect your VPN, open a page that shows your IP address, then manually turn on airplane mode for a few seconds and turn it back off before the VPN has time to gracefully reconnect. If the kill switch works, you should see no internet connectivity at all during that gap rather than a brief flash of your real IP. Refresh the IP-checking page immediately after reconnecting to confirm it reads the VPN’s IP, not your real one, at any point. For a full walkthrough of this kind of testing on both desktop and mobile, see our guide on how to test your VPN’s kill switch.
Provider-specific notes worth knowing
Mullvad includes a kill switch enabled by default on both iOS and Android, one of the few providers that ships this on rather than requiring users to find and enable it, consistent with Mullvad’s broader privacy-by-default philosophy. Surfshark labels its mobile kill switch clearly in the main connection screen rather than burying it in an advanced settings submenu, which makes it easier to verify at a glance that it’s active. ProtonVPN ties its kill switch setting to its “Always-on VPN” feature on both platforms, so enabling one enables the other, which is worth knowing if you only toggle one and expect both behaviors. NordVPN offers the same on/off simplicity with a clearly labeled toggle under its Connection settings on both platforms.
Common mistakes that leave you unprotected anyway
Enabling the kill switch inside the VPN app but not the Android system-level “Block connections without VPN” setting leaves a gap if the app itself crashes rather than just losing its connection, since an app-level kill switch can’t do much if the app process isn’t running at all. On iOS, relying solely on Connect On Demand without also checking the app’s own kill switch toggle can leave a brief exposure window during the handoff between the two systems. The safest approach on both platforms is enabling every available layer, app-level and OS-level, rather than assuming one covers what the other doesn’t.
What a kill switch does not protect against
A kill switch handles the specific case of your VPN connection dropping unexpectedly. It does not protect you from DNS leaks (your device querying DNS servers outside the VPN tunnel), browser fingerprinting, or any privacy risk that isn’t about the tunnel itself failing. Check separately for IP and DNS leaks if you want fuller confidence in your setup, since a working kill switch and a leak-free connection are two different things worth verifying independently.
Battery and performance impact of leaving it on permanently
A kill switch itself has negligible battery or performance impact, since it’s essentially a passive rule that only activates during a connection drop, not a feature that runs continuously in the background doing active work. There’s no meaningful trade-off to weigh here: leaving it enabled at all times is the right default, and there’s no legitimate reason to disable it “to save battery,” a justification that doesn’t hold up given how the feature actually works at the OS and app level.
If your VPN app doesn’t have a kill switch at all
Rely on the operating system’s built-in option instead. Android’s “Block connections without VPN” setting works with any VPN app regardless of whether that app has its own kill switch feature. iOS is more limited here since its Connect On Demand feature depends on provider support, so if your iPhone VPN app has no kill switch and doesn’t support Connect On Demand, that’s a real gap worth switching providers over if kill switch reliability matters for your use case.
Want to compare all VPNs side by side? Check our full VPN comparison table with scores across 18 criteria.
A quick pre-flight checklist before you trust it
Before relying on your mobile kill switch for anything sensitive, confirm all of the following: the Android system-level “Block connections without VPN” toggle is on, or iOS Connect On Demand is enabled and supported by your provider; your VPN app’s own kill switch toggle is also on; and you’ve actually run the airplane-mode test described above rather than just assuming the settings work as labeled. Settings menus get renamed between app updates, and a toggle that used to work can occasionally reset after a major app update, so a periodic recheck, not just a one-time setup, is the more reliable habit.
Want to compare all VPNs side by side? Check our full VPN comparison table with scores across 18 criteria.
Enable the kill switch at both the operating system level and inside your VPN app on iPhone and Android: Android's "Block connections without VPN" setting and iOS's Connect On Demand feature, alongside your provider's own toggle. Test it with the airplane-mode method before trusting it, since a setting that's turned on isn't the same as a setting you've confirmed actually works.
Keep reading: VPN Kill Switch Explained: How It Actually Works and How to Set Up a VPN on Android in 2026.