DNS leak
When name lookups travel to your ISP’s resolver instead of through the tunnel, exposing every domain you visit.
Glossary
A control that blocks all internet traffic if the VPN tunnel drops, rather than letting it fall back to your normal connection.
Tunnels drop — on network changes, on suspend and resume, on server restarts. Without a kill switch those seconds go out over your ordinary connection with your real address attached, and you will not notice.
The distinction that matters is between an application-level switch and a firewall-level one. An app-level switch relies on the app still running to notice the failure. A firewall-level switch installs rules that block traffic even if the app crashes, which is the failure mode you actually need covered. Test it by killing the VPN process, not by clicking disconnect.
When name lookups travel to your ISP’s resolver instead of through the tunnel, exposing every domain you visit.
When a tunnel carries only IPv4 while your connection also has IPv6, so IPv6-capable sites see your real address.
An operating-system-level setting that prevents any traffic leaving the device unless the tunnel is up.
Terms are defined here because they appear in our scoring rubric or in provider reviews, not to fill a glossary.