What happens when you turn it offImmediately, and what stays behind
Your real address is used again from the next request onwards. What you were already signed in to stays signed in — which is the part that surprises people.
Turning a VPN off is instant and mostly unremarkable: the tunnel closes, and the next connection your device makes uses your own address again.
What is worth understanding is the boundary — what changes at that moment and what does not — because the things that do not change are where people get caught out.
- From the next request, sites see your real address again
- Sessions you are already signed in to continue as normal
- Streaming may reassess your region mid-playback, or not until the next title
- Downloads in progress usually continue; the address they came from changed
- A kill switch is for the disconnection you did not choose
What changes immediately
Every new connection uses your own address. Sites you open from that point see your real country, your internet provider sees your destinations again, and anything geo-restricted reverts to your actual location.
The word doing the work is new. Connections already established do not retroactively change, which is why a large download frequently carries on without interruption after the tunnel closes.
What does not change, and catches people
Sessions stay signed in. A cookie set while you were connected through another country does not expire when you disconnect. You remain signed in, from a different country than the one you signed in from.
Cached region data stays cached. A service that stored your apparent region may keep serving that region until the cache expires, which produces the confusing state where things still work for a while after you disconnect.
Account records do not change. Anything tied to the account — the country it was created in, the payment method — was never affected by the tunnel and is not affected by closing it.
What you already did is already logged. Sites recorded the address they saw at the time. Disconnecting is not a retraction.
The disconnection you did not choose
Deliberately turning it off is not the interesting case. The one that matters is the tunnel dropping on its own — a network change as you walk between floors, a server restarting, a phone switching from Wi-Fi to mobile data.
When that happens, most software reconnects transparently and everything in between went over your real address without any indication. You were not told, because nothing failed from the device's point of view.
This is the specific problem a kill switch solves: it blocks all traffic the instant the tunnel drops, converting a silent gap into an obvious outage. Of the seven providers we track, five publish a feature list and three name a kill switch — NordVPN, Surfshark and Private Internet Access, the last calling it an Advanced Kill Switch. If you use public networks regularly, this is the feature to check for.
Split tunnelling, which is the middle option
The choice is not only on or off. Split tunnelling lets you route some applications through the tunnel and leave the rest on your own connection — the streaming app through a Japanese server, the maps and delivery apps direct.
Of the seven providers we track, five publish a feature list, and three of those name split tunnelling: NordVPN, Private Internet Access, and Surfshark — the last under the name Bypasser. It is the feature that removes most of the reasons people toggle a VPN on and off all day, and it is rarely the thing comparison articles lead with.
The caveat is that it works per application, not per website, on most clients. Routing a browser through the tunnel routes every tab through it.
When turning it off is the right move
Leaving it on permanently is not the goal, and several things work better without it.
- Local services. Maps, delivery, transport and local payment apps behave oddly when your address says another continent.
- Banking from home. Some banks challenge a login from an unfamiliar address, and your own is the familiar one.
- Captive portals. Hotel and airport sign-in pages cannot intercept an established tunnel. Join the network, complete the portal, then connect.
- Speed-sensitive tasks on a trusted network. We measured 10% to 60% of a line disappearing into the tunnel — at home, that is a cost with no benefit attached.
How much speed actually survives the tunnel
Every VPN site says a tunnel costs you speed. Almost none of them say how much. We measured it by hand rather than repeating a claim: 14 cities, 46 paired runs, comparing NordVPN and Surfshark against the same raw line in the same session. In the 11 cities where we also measured the bare line, the share that survived the tunnel ranged from 40% to 90%.
| City | Raw line | NordVPN | Surfshark | Paired runs |
|---|---|---|---|---|
| Tokyo | 780 Mbps | 444.9 Mbps (57%) | 399.9 Mbps (51%) | 9 |
| London | 790 Mbps | 712.6 Mbps (90%) | 713.5 Mbps (90%) | 9 |
| New York | 760 Mbps | 598.9 Mbps (79%) | 556.6 Mbps (73%) | 7 |
| Los Angeles | 530 Mbps | 358.8 Mbps (68%) | 305.8 Mbps (58%) | 5 |
Measured by VPN LIFE. Raw-line figures are rounded to the nearest 10 Mbps. Percentages are the share of the raw line that survived.
- 14 cities, 46 paired runs, measured by hand
- 11 of those cities also have the bare line measured
- 40% to 90% of the raw line survived
- We only name a winner in 4 cities — the rest have too few runs
The spread between cities is larger than the spread between providers. In London roughly nine tenths of the line survived on both services; in Tokyo it was closer to half. That is worth knowing before you blame the provider: "this VPN is slow" is usually "this route is slow".
We only call a winner in a city when we have five or more paired runs there and the gap is at least 10%. That threshold is met in 4 of the 14 cities — Tokyo and Los Angeles, where NordVPN averaged ahead, and London and New York, where the two were level. In the remaining ten cities we publish the numbers and say the sample is too small, rather than ranking on one run.
How much of the line survived the tunnel
How long you have to change your mind
![]()
![]()
![]()
![]()
![]()
![]()
![]()
The apps behind our measurements

The providers we track
We rank on what we can check. Each of the five below publishes a location in this use; the tables are our own counts and the providers' own published terms, not a summary of their marketing.
ExpressVPN: the widest spread of cities
ExpressVPN publishes more multi-city countries than anyone else in our set — 11 countries where you can pick between two or more locations, including 56 in the United States, 7 in the United Kingdom, 6 in Australia and 4 in Japan. If your problem is a blocked address rather than a missing country, that spread is the thing that gets you out of it. It is the most expensive option here, and it is the one we would pick for streaming.
| ExpressVPN | |
|---|---|
| Locations in this country | 4 cities |
| Countries covered | 112 of the 155 we count |
| Money-back window | 30 days |
ExpressVPN in use

NordVPN: the largest country list, and the one we measured
NordVPN covers more countries than anything else we track. It is also one of the two services we measured ourselves, so the retention figures above are its actual numbers rather than a claim. It operates from Panama, has been audited by Deloitte, allows 10 simultaneous connections, and lists obfuscated servers and a kill switch among its features — the two things that matter where VPN traffic is filtered.
| NordVPN | |
|---|---|
| Locations in this country | 2 cities |
| Countries covered | 149 of the 155 we count |
| Money-back window | 30 days |
| Operates under the law of | Panama |
| No-logs claim examined by | Deloitte |
| Features the provider names | Threat Protection, Double VPN, obfuscated servers, Meshnet, dedicated IP, kill switch and split tunnelling |
NordVPN in use

Surfshark: unlimited devices, and level with NordVPN in half our tests
Surfshark is the other service in our own measurements. In London and New York it was level with NordVPN; in Tokyo and Los Angeles it trailed by 11% and 17%. It places no limit on simultaneous connections, which makes it the sensible choice for a household rather than a person. Audited by Deloitte, operating from the Netherlands, with Camouflage Mode for networks that filter VPN traffic.
| Surfshark | |
|---|---|
| Locations in this country | 1 city |
| Countries covered | 100 of the 155 we count |
| Money-back window | 30 days |
| Operates under the law of | the Netherlands |
| No-logs claim examined by | Deloitte |
| Features the provider names | CleanWeb, Dynamic MultiHop, rotating IP, Camouflage Mode, kill switch and split tunnelling (Bypasser) |
Surfshark in use

CyberGhost: the longest money-back window, with a catch
CyberGhost's 45-day money-back guarantee is the longest here, and it is the reason it appears on most lists. Read the condition: 45 days applies to the six-month and two-year plans, and the monthly plan gets 14 days. It publishes 10 multi-city countries, with 11 locations in the United States, but only a single city in Japan — so it is a weaker choice if Japanese services are your target.
| CyberGhost | |
|---|---|
| Locations in this country | 1 city |
| Countries covered | 100 of the 155 we count |
| Money-back window | 45 days (six-month and two-year plans; 14 days on monthly) |
CyberGhost in use

Private Internet Access: unlimited connections, US jurisdiction
PIA places no limit on devices and publishes an Advanced Kill Switch, obfuscation, multi-hop and port forwarding. Its no-logs claim has been audited by Deloitte Audit Romania. The trade-off is jurisdiction: it operates from the United States, which some readers will rule out on principle. We list it because the rest of the record is strong and because it is one of only four providers with two or more cities in Japan.
| Private Internet Access | |
|---|---|
| Locations in this country | 2 cities |
| Countries covered | 92 of the 155 we count |
| Money-back window | 30 days |
| Operates under the law of | the United States |
| No-logs claim examined by | Deloitte (Deloitte Audit Romania) |
| Features the provider names | unlimited connections, PIA MACE ad and tracker blocking, Advanced Kill Switch, split tunnelling, multi-hop, obfuscation and port forwarding |
Private Internet Access in use

Frequently asked questions
Will a streaming service notice mid-episode?
Sometimes. Some check only when playback starts, so the current title finishes and the next one fails. Others check periodically and stop mid-stream. The behaviour differs by service and changes over time.
Do I need to sign out of things before disconnecting?
Only if you care that the session continues from your real address. The session itself is unaffected — that is the point of the answer above.
Will it slow my connection down?
Yes, and we have measured how much: across 14 cities and 46 paired runs, between 40% and 90% of the raw line survived the tunnel. The variation between cities is wider than the variation between providers — London kept about 90% on both services we tested, Tokyo about half. If a VPN feels slow, the route is a more likely explanation than the provider.
What is a VPN, in one paragraph?
A VPN is an encrypted connection between your device and a server run by the provider. Everything you send goes through that tunnel, so the network you are sitting on sees only an encrypted link to one address, and the sites you open see the server's address rather than yours. That is the entire mechanism; the differences between providers are about where the servers are, how fast the route is, and what the provider keeps.
Conclusion
Disconnecting changes the next request and nothing behind it. The case worth preparing for is the disconnection you did not choose, and that is what a kill switch is for.
Which providers publish one is in the tables above, read from their own sites.
Every figure on this page comes from our own daily collection or our own measurements. The files are published as open data under CC BY 4.0, and the method — including what the numbers do not prove — is on how we test.