What is split tunneling?
Normally a VPN takes everything. Split tunneling lets you decide app by app: this one goes through the encrypted tunnel, that one goes straight out to the internet. It solves real problems — and it opens a hole you should understand before you use it.
See how ours worksHow it actually works
When a VPN connects, it normally installs a default route that captures all outbound traffic on the device and sends it into the tunnel. Every app, every background service, every update check — everything goes the same way.
Split tunneling changes the routing table so that only some traffic matches the tunnel route. The client tags traffic by application, by destination address, or by domain, and everything unmatched leaves through your ordinary internet connection with your real IP address attached.
The result is two simultaneous paths out of one device. That is the entire feature, and also the entire risk: two paths means two identities, and anything on the direct path sees exactly what it would have seen with no VPN at all.
Three ways to split it
Per-app (inclusive)
You name the apps that should use the VPN; everything else goes direct. The safer default when you only need a couple of things protected, because anything you forget to add stays outside rather than accidentally leaking in.
Inverse (exclusive)
Everything uses the VPN except the apps you exclude. The right choice for privacy, because the default is protection and only named exceptions escape. This is what you want for banking apps that refuse foreign IP addresses.
Per-domain or per-IP
Route by destination rather than application. Useful when one browser needs some sites tunnelled and others direct, or to keep a printer, NAS or local device reachable while everything else is tunnelled.
What people actually use it for
| Situation | Route through VPN | Route direct |
|---|---|---|
| Banking app blocks foreign IPs | Everything else | Banking app |
| Printer or NAS on your LAN | Everything else | Local devices |
| Work VPN plus personal privacy | Personal browser | Corporate client |
| Low-latency gaming | Browser, downloads | Game client |
| Streaming another country | Streaming app | Everything else |
| Slow connection, big download | Sensitive apps | Bulk download |
The trade-off nobody spells out: anything on the direct path carries your real IP address and your provider sees every domain it contacts. Worse, a browser that is excluded still carries the cookies and login sessions of your tunnelled identity, which lets a site link the two. If your reason for using a VPN is that someone specific should not be able to see what you do, do not use split tunnelling for that traffic — use the full tunnel.
Where you can actually get it
Android has the cleanest support, because the operating system exposes per-app VPN routing directly. Most clients offer both inclusive and exclusive modes, and it works reliably.
Windows and Linux can do it well, since the client has enough access to the routing table and to per-process network attribution to make app-level decisions stick.
macOS is more limited, and the mechanism has changed across recent releases as Apple moved network extensions around. Many clients offer destination-based splitting rather than true per-app routing.
iOS effectively does not support it. Apple’s network extension framework does not expose per-app routing to third-party VPNs, so anything advertised as split tunnelling on iOS is usually domain-based filtering inside the tunnel rather than genuine split routing.
Routers can split by device rather than by app — this laptop through the VPN, that TV direct — which is often the more useful granularity for a household.
Common questions
Is split tunneling safe?
Does split tunneling make my VPN faster?
Why does my banking app stop working on a VPN?
Can I use split tunneling on iPhone?
Does split tunneling leak DNS?
Related reading
Split it deliberately
LunoVPN supports per-app, inverse and per-domain routing, and shows you exactly which apps are outside the tunnel at any moment.