How to get the maximum protection from your VPN

A finger pressing a padlock icon
(Image credit: Shutterstock)

Some people use VPNs for only a few very specific tasks - unblocking Netflix, anonymous torrenting and enhanced gaming, for example - but what if privacy is absolutely your top priority?

Are you one of those VPN users that wants to protect just about all of your traffic, all of the time, and with all your privacy settings turned up to the max?

Most VPN apps have all kinds of features you can use to ramp up protection, but they're not always obvious and many are turned off by default. In this article we'll look at how you can best configure your setup for the maximum possible privacy.

Automatically connect

VPN apps typically don't connect until you ask, but if you're slow off the mark, that could leave a lot of system and app traffic unprotected.

If you'd like to avoid this entirely, then set the app to launch when your system starts. NordVPN's Windows app has a 'Launch at Windows startup' setting, for instance, and most services have something similar.

Next, look for an option to automatically connect when the app starts. ExpressVPN's desktop app has a 'Connect to the last used location when ExpressVPN is launched' setting which gets the job done, and ProtonVPN has an equivalent 'Auto Connect' option on its Connection menu.

If having the VPN on all the time is a step too far, look for any other auto-connect options your app might have. Many providers have a setting to automatically connect whenever you access a new Wi-Fi network, for instance. Turn this on and the app will protect you right away, whenever you access a hotspot. So there's no need for you to connect manually and no chance that you'll forget and leave your traffic exposed.

The ProtonVPN Windows app displaying its Permanent Kill Switch dialog

(Image credit: ProtonVPN)

Block unprotected internet access

Automatic connections are a good start, but what if the VPN drops? Chances are your device will immediately switch to its regular unencrypted connection.

Turn on the kill switch and the app blocks your internet access if the VPN drops, reducing the chance that any data will be exposed.

But there could be a catch. By default, most kill switches only kick in if the VPN drops during a session. They won't protect you when your device boots, say, or if you accidentally hit the Disconnect button or close the app.

If that's a problem, and you don't want any traffic allowed unless the VPN is active, then look for an additional setting which turns the kill switch on all the time. ProtonVPN's sensibly-named 'Permanent Kill Switch' does exactly that, only allowing access to the internet when you're connected to the VPN.

Losing your internet is annoying, of course, and this could be a hassle if your VPN drops regularly - if that keeps happening, it might be a sign that you really need to be using another provider. But in the meantime, if your app has an 'auto-redial if the connection drops' option, make sure it's enabled to speed up reconnections.

It's a good idea to have the app raise an alert when it connects or the connection drops, too, so you're always aware of what's going on. If your app doesn't keep you informed, look for an option to 'Show notifications' or similar and check it's turned on.

Tighten up your VPN settings

VPNs often include all kinds of privacy-oriented settings and options, especially with their desktop apps. The defaults don't always offer the best protection, though, so it's a good idea to review them occasionally, make sure they're delivering what you need.

Does your app have specific options for DNS leak or IPv6 protection, for instance? Check they're enabled.

Some VPNs have a Custom DNS Feature which enables using your preferred DNS server when connected to the VPN. That can be a plus in some situations, such as using a server which blocks malicious websites (OpenDNS is a good example.) But it also means that server gets to see every domain you visit. Turn Custom DNS off unless you're confident that you trust the server, and you really need whatever extra features it offers.

Many apps include a crash reporting or similar feature which sends data back to the provider. Every VPN who does this says it's all anonymous and includes nothing that could identify you, and probably they're right. But even if the odds are it's entirely safe, there's no benefit for you in taking the gamble. Just turn it off.

NordVPN, Surfshark and others have two-factor authentication (2FA) systems, where you're asked to verify your identity via a mobile (or some other route) whenever you access your account. It takes a few extra seconds, but goes a very long way to prevent your account from being hijacked.

If you don't have 2FA, at least make sure you're using a secure and unique password for your VPN, and change it every few months, to reduce your exposure if the account is hacked.

Take a look at your app's preferred VPN protocol, too. Are you using the most secure option? As a general rule, modern is generally better (say yes to WireGuard, but ignore PPTP if you care about security), but if you're unsure, then you can use our guide to the best VPN protocol to work out which is best for you.

ExpressVPN's Split Tunneling settings

(Image credit: ExpressVPN)

VPN troubleshooting

Having your VPN active all the time increases privacy, but might introduce new problems, for example if the VPN conflicts with other apps. Fortunately, you can often address these with some quick settings tweaks.

Suppose a streaming app no longer works, for instance, because it detects the VPN and locks you out of the service. You might think that as you need to use that app, you'll have to give up on the idea of leaving the VPN connected.

But wait: maybe there's another way. If your VPN supports split tunneling, turn this on and you can set particular apps to bypass the VPN and use your regular internet connection instead. This isn't ideal, because you're removing the VPN's protection for those apps. But if they're not handling sensitive information, you may feel it's a step worth taking.

Connection times can be another annoying issue. If the VPN drops, it might take a few seconds before the app notices, redials, and maybe takes another 20 seconds before it connects and your internet is available again.

If that's a problem for you, take a look at the protocol you're using. OpenVPN is secure, but we've seen it take 10-20 seconds (sometimes even more) to connect with some providers. If your app has WireGuard or an equivalent modern protocol (NordLynx, Lightway), switching can reduce connection times to a couple of seconds, maybe less, making a huge difference to your experience of the service.

Mike Williams
Lead security reviewer

Mike is a lead security reviewer at Future, where he stress-tests VPNs, antivirus and more to find out which services are sure to keep you safe, and which are best avoided. Mike began his career as a lead software developer in the engineering world, where his creations were used by big-name companies from Rolls Royce to British Nuclear Fuels and British Aerospace. The early PC viruses caught Mike's attention, and he developed an interest in analyzing malware, and learning the low-level technical details of how Windows and network security work under the hood.

Read more
An illustration of a mobile phone running a VPN
How does a VPN work?
Someone using a VPN on a PC.
How to buy a VPN – a jargon-free guide
best Secure VPN
Secure VPN providers 2025: safe options for the best security and encryption
An illustration of a laptop screen running a VPN service, accompanied by images of a padlock, globe, and a man using a tablet.
What are the benefits of using a VPN in 2025?
Laptop in home office with stylised letters VPN on the screen
The best Windows VPN for PC in 2025
Abstract illustration of a young woman looking at a smartphone, as large eyes peek through from her hair
Want to hit restart on your online presence? Here's 5 tools you need to stay truly private online
Latest in VPN
ExpressVPN mobile app and Aircove
ExpressVPN ‘reduces workforce’ for the second time in two years
Teenager playing on a gaming PC with two monitors
Is using a VPN while gaming cheating? 5 myths you shouldn't believe about gaming with a VPN
Neon blue email symbols on a black background
Why am I suddenly getting so many spam emails?
A computer file surrounded by red laser beams
Cover your tracks: the risk of sending unencrypted files
Using an Amazon Fire Stick on a Smart TV
How to use a VPN with Fire Stick
Close up of PS5 DualSense controller leaning on a PS5
5 reasons your PS5 needs a VPN
Latest in How Tos
Smartphone with new logo X twitter app background. Application twitter old blue bird change X black and white new.
How to delete all your tweets on X
ChatGPT Voice mode
How to add ChatGPT or Gemini voice mode to your iPhone Action button (while you wait for Siri's big upgrade)
McLaren’s Lando Norris leads Red Bull’s Max Verstappen driving round a bend at the 2025 Australian Grand Prix
How to watch Chinese Grand Prix 2025: TV & live streams, schedule, start time, what channel is it on?
Marlow Murder Club S2
How to watch Marlow Murder Club season 2 online — stream now
TOLUCA, MEXICO - NOVEMBER 19: Raul Jimenez of Mexico reacts during the CONCACAF Nations League match between Mexico and Honduras at Nemesio Diez Stadium on November 19, 2024 in Toluca, Mexico. (Photo by Jonathan Mondragon/Jam Media/Getty Images)
Canada vs Mexico live stream: how to watch CONCACAF Nations League semi-final 2025 online for free today
Beibhinn Parsons #11 of Ireland races away with a rugby ball during the Ireland V Wales, Women's Six Nations Rugby match in 2024
Women’s Six Nations 2025: How to watch rugby live streams online from anywhere