Most VPNs now bolt on a network-level ad and malware blocker, marketed under names like Threat Protection, CleanWeb or NetShield. They sound similar in a features list, but they don’t all do the same job, and one major provider in our table scores a flat zero on this specific measure. Here’s what each feature actually blocks, and what it doesn’t.

What a VPN’s built-in blocker actually does

These features work at the DNS level: when your device tries to resolve a domain known to serve ads, trackers or malware, the VPN’s DNS server refuses to resolve it, so the request never completes. That’s different from a browser extension, which inspects and blocks content after your browser has already loaded a page. A DNS-level blocker works across every app on your device, not just your browser, which is why VPNs market it as an upgrade over an ad blocker extension alone.

What it doesn’t do is replace antivirus software. A DNS blocklist stops a known-bad domain from loading; it does nothing once malware is already on your device, and it won’t stop you from manually downloading and opening an infected file. Think of it as a filter on where your traffic is allowed to go, not a scanner for what’s already on your machine.

Ad and malware blocking scores compared

VPNAd/malware blocking scoreFeature name
NordVPN5/5Threat Protection Pro
Surfshark5/5CleanWeb
ProtonVPN5/5NetShield
Private Internet Access5/5MACE
Mullvad5/5DNS content blockers
CyberGhost5/5Built-in ad and tracker blocker
Windscribe5/5R.O.B.E.R.T.
ExpressVPN0/5None built into the core VPN app

NordVPN: Threat Protection Pro

NordVPN’s version goes further than a basic blocklist. Threat Protection Pro scans downloaded files for malware in real time, blocks known malicious and phishing domains, and strips ad trackers, all before you connect to a single site. It runs whether or not the VPN tunnel itself is active, which is unusual: most competitors’ blockers only work while you’re connected. Combined with a 5/5 speed score, it’s the most complete package in this comparison.

Surfshark CleanWeb and Proton NetShield

Surfshark’s CleanWeb and Proton’s NetShield both work the same basic way: DNS-level blocking of ads, trackers and known malicious domains, bundled into every plan at no extra cost. Neither scans downloaded files the way NordVPN’s does, but both are reliable for the core job of stopping ad and tracker requests before they load. Proton’s NetShield adds a visible dashboard showing exactly how many trackers it blocked in a session, a small transparency touch that fits Proton’s broader privacy-first positioning.

PIA MACE and Windscribe R.O.B.E.R.T.

PIA’s MACE and Windscribe’s R.O.B.E.R.T. take a more customizable approach. Both let you toggle specific blocklist categories on or off, such as ads, trackers, malware domains or social media widgets, rather than applying one fixed list. R.O.B.E.R.T. in particular has a loyal following among Windscribe’s userbase for how granular the controls are, down to blocking specific ad networks by name.

Want to compare all VPNs side by side? Check our full VPN comparison table with scores across 18 criteria.

Mullvad and CyberGhost: built in, less marketed

Mullvad includes DNS-based content blockers directly in its app settings, covering ads, trackers and malware domains, without branding it as a headline feature the way competitors do. It’s just there, consistent with Mullvad’s minimalist approach to everything. CyberGhost bundles a comparable ad and tracker blocker across its plans, scoring 5/5 in our data alongside the rest of the field.

ExpressVPN: the outlier

ExpressVPN is the one major provider in this comparison that scores 0/5 on built-in ad and malware blocking. Its core VPN app doesn’t ship a network-level DNS blocklist the way NordVPN, Surfshark or Proton do. ExpressVPN has instead pushed newer features toward its Aware security-notification tools and its browser-based products, but as of our latest testing, there’s no equivalent to Threat Protection Pro or CleanWeb built into the main app. If a DNS-level ad and malware blocker is something you specifically want bundled with your VPN, this is worth weighing against ExpressVPN’s other strengths in speed and streaming.

How this compares to a browser ad blocker

If you already run uBlock Origin or a similar browser extension, a VPN’s built-in blocker can feel redundant, but the two work at different layers and actually complement each other. A browser extension inspects and blocks content after it loads inside that specific browser. A VPN’s DNS-level blocker stops the request before it ever leaves your device, and it covers every app on that device, not just the browser you happened to have open. Running both isn’t wasteful; it’s closer to defense in depth, since a domain that slips past one layer is often still caught by the other.

False positives and whitelisting

Aggressive blocklists occasionally break legitimate sites, particularly smaller ones that share infrastructure with ad networks or use tracking scripts for otherwise ordinary analytics. If a page suddenly stops loading correctly after you enable threat protection, that’s usually the first thing to check. Every provider covered here lets you whitelist specific domains, or in most apps, temporarily disable the blocker for a single browsing session without turning off the VPN itself. It’s worth knowing where that toggle lives before you need it, since digging through settings mid-browsing session is a common source of frustration.

Real numbers: what these blockers actually catch

Providers rarely publish granular data on how much their blockers actually stop, which makes the few that do worth paying attention to. NordVPN has started surfacing exactly this kind of detail to users directly in-app, showing what its Threat Protection and Scam Protection tools blocked in a given period rather than leaving the feature as an invisible background process; we cover the specifics in our look at NordVPN’s scam protection statistics. That kind of transparency is a useful signal on its own: a provider willing to show you the numbers is generally one that trusts the feature to hold up under scrutiny.

Do you still need separate antivirus software?

Yes. Every feature on this list operates at the network level, blocking known-bad domains before your device connects to them. None of them scan files already on your computer, detect ransomware behavior, or catch a malicious attachment you open manually. We cover the split in more detail in our guide to VPN vs antivirus, but the short version is that a VPN’s blocker and a real antivirus product solve different problems and neither substitutes for the other.

How to turn on threat protection

The setting is usually a single toggle, found in each app’s security or privacy settings, separate from the main connect button. Most providers let you enable it independently of the VPN connection itself, so it’s worth checking whether yours is switched on by default or something you have to activate manually after installing the app.

Our verdict

NordVPN's Threat Protection Pro is the most complete built-in option, adding real-time file scanning on top of standard ad and tracker blocking. Surfshark's CleanWeb and Proton's NetShield cover the essentials well at no extra cost. ExpressVPN is the clear gap in this comparison, scoring 0/5 with no equivalent feature in its core app. Whichever VPN you use, keep a real antivirus running alongside it; a DNS blocklist is a useful filter, not a replacement.

Keep reading: Best Audited No-Logs VPN in 2026 and Is a VPN Safe for Online Banking in 2026?.