Skip to content
LunoVPN
Explainer

What is split tunneling?

Normally a VPN takes everything. Split tunneling lets you decide app by app: this one goes through the encrypted tunnel, that one goes straight out to the internet. It solves real problems — and it opens a hole you should understand before you use it.

See how ours works
3 modes When to use it When not to
The mechanism

How it actually works

When a VPN connects, it normally installs a default route that captures all outbound traffic on the device and sends it into the tunnel. Every app, every background service, every update check — everything goes the same way.

Split tunneling changes the routing table so that only some traffic matches the tunnel route. The client tags traffic by application, by destination address, or by domain, and everything unmatched leaves through your ordinary internet connection with your real IP address attached.

The result is two simultaneous paths out of one device. That is the entire feature, and also the entire risk: two paths means two identities, and anything on the direct path sees exactly what it would have seen with no VPN at all.

Modes

Three ways to split it

Per-app (inclusive)

You name the apps that should use the VPN; everything else goes direct. The safer default when you only need a couple of things protected, because anything you forget to add stays outside rather than accidentally leaking in.

Inverse (exclusive)

Everything uses the VPN except the apps you exclude. The right choice for privacy, because the default is protection and only named exceptions escape. This is what you want for banking apps that refuse foreign IP addresses.

Per-domain or per-IP

Route by destination rather than application. Useful when one browser needs some sites tunnelled and others direct, or to keep a printer, NAS or local device reachable while everything else is tunnelled.

Use cases

What people actually use it for

SituationRoute through VPNRoute direct
Banking app blocks foreign IPsEverything elseBanking app
Printer or NAS on your LANEverything elseLocal devices
Work VPN plus personal privacyPersonal browserCorporate client
Low-latency gamingBrowser, downloadsGame client
Streaming another countryStreaming appEverything else
Slow connection, big downloadSensitive appsBulk download

The trade-off nobody spells out: anything on the direct path carries your real IP address and your provider sees every domain it contacts. Worse, a browser that is excluded still carries the cookies and login sessions of your tunnelled identity, which lets a site link the two. If your reason for using a VPN is that someone specific should not be able to see what you do, do not use split tunnelling for that traffic — use the full tunnel.

Platform support

Where you can actually get it

Android has the cleanest support, because the operating system exposes per-app VPN routing directly. Most clients offer both inclusive and exclusive modes, and it works reliably.

Windows and Linux can do it well, since the client has enough access to the routing table and to per-process network attribution to make app-level decisions stick.

macOS is more limited, and the mechanism has changed across recent releases as Apple moved network extensions around. Many clients offer destination-based splitting rather than true per-app routing.

iOS effectively does not support it. Apple’s network extension framework does not expose per-app routing to third-party VPNs, so anything advertised as split tunnelling on iOS is usually domain-based filtering inside the tunnel rather than genuine split routing.

Routers can split by device rather than by app — this laptop through the VPN, that TV direct — which is often the more useful granularity for a household.

FAQ

Common questions

Is split tunneling safe?
It is safe in the sense that it does not weaken the encryption of what stays inside the tunnel. It is unsafe in the sense that everything you route around the tunnel is completely unprotected — real IP address, visible destinations, your provider logging all of it. The feature is not risky; forgetting what you excluded is.
Does split tunneling make my VPN faster?
It makes the excluded traffic faster, because that traffic stops being encrypted and stops taking a detour through a distant server. It does nothing for the traffic still inside the tunnel. If everything feels slow, a closer server usually helps more.
Why does my banking app stop working on a VPN?
Because banks flag logins from an IP address in a country you do not normally use, and treat it as possible fraud. Excluding the banking app from the tunnel is the standard fix — it is the single most common reason people turn split tunneling on.
Can I use split tunneling on iPhone?
Not properly. Apple does not expose per-app VPN routing to third-party apps on iOS, so genuine split tunnelling is not possible. Features marketed under that name on iOS are generally domain-based rules applied inside the tunnel, not traffic that actually leaves outside it.
Does split tunneling leak DNS?
It can, and this is the subtle failure. If DNS resolution is not split the same way as the traffic, lookups for excluded apps may still go through the tunnel or, worse, lookups for tunnelled apps may go to your provider. Test with our DNS leak test after configuring any split rules.

Split it deliberately

LunoVPN supports per-app, inverse and per-domain routing, and shows you exactly which apps are outside the tunnel at any moment.