The VPN Settings I Actually Bother Changing From Default

Sep 03, 2026By Jay Kells
Jay Kells

Most people install a VPN, tap connect, and never open the settings menu again. For a long time that was me too, until a dropped connection on a train left my laptop briefly exposed on the open network without me noticing for a good ten minutes. Nothing came of it that time, but it was enough to make me actually go through every setting my VPN app offers rather than trusting whatever ships as default. Here's what I actually changed, and why each one mattered enough to bother with.

Why I Stopped Trusting Default Settings Out of the Box


VPN apps are built to get you connected in one tap, which means the defaults are tuned for ease of use rather than maximum protection. That's a reasonable trade-off for the company to make, since most users would abandon an app that demanded a settings review before it worked at all. But it means the responsible thing is to assume the out-of-the-box configuration is the minimum viable setup, not the best one, and to go through the menu once properly rather than assuming someone already optimised it on your behalf. It took me about twenty minutes the first time, working through every tab in the settings menu and reading what each toggle actually did rather than guessing from the label alone. Most of them turned out not to matter much either way, but the handful that did were worth that twenty minutes many times over.


The Kill Switch Setting I Turn On Before Anything Else


A kill switch cuts your internet entirely the moment your VPN connection drops, rather than quietly falling back to your normal, unprotected connection while you carry on browsing none the wiser. On the app I use it isn't switched on by default, it's a toggle buried under an "advanced" section, which is exactly backwards given how much it matters. That train journey I mentioned is precisely the scenario a kill switch exists for: a connection that drops without warning while you're on a network you don't control. It's the first thing I check on any new install now, before I even log in properly.


Split Tunneling: The One Feature I Actually Use Daily


Split tunneling lets you choose which apps route through the VPN and which use your normal connection directly, and it's the setting I actually interact with most often day to day. I route my browser and email client through the VPN always, but I let my banking app and a couple of UK-only streaming services bypass it, since routing through a VPN server abroad breaks them or triggers extra security checks. Without split tunneling I'd be constantly switching the whole VPN on and off depending on what I'm doing, which is exactly the kind of friction that makes people give up on using one consistently at all.


Why I Switched My Protocol From OpenVPN to WireGuard


Most VPN apps let you choose which underlying protocol handles the actual encrypted tunnel, and the default is often an older one for compatibility reasons rather than performance. I switched mine from OpenVPN to WireGuard once I understood the difference: WireGuard uses a smaller, more modern codebase that's easier to audit for vulnerabilities, and it's noticeably faster on both mobile data and Wi-Fi. It's not a setting most people know exists, let alone that it's worth changing, but it took me under a minute to switch once I found it in the menu. The difference showed up almost immediately on video calls, which used to occasionally stutter over the VPN and now don't, and that alone would have been worth the change even without the security argument for a newer protocol.


The Auto-Connect Rule I Set for Untrusted Networks


I've written before about the public Wi-Fi habit that took me too long to break, and the setting that actually fixed the underlying problem was auto-connect rules based on network trust. My VPN app lets me mark home and work Wi-Fi as trusted, and automatically fires up the VPN the instant I join anything else, including mobile hotspots I don't recognise. That removes the human error entirely: I no longer have to remember to switch it on in a coffee shop or hotel lobby, because the decision is already made before I've even opened a browser tab.


The One Setting I Deliberately Leave Turned Off


Not every extra toggle is worth switching on. My app offers a setting that automatically connects to the "fastest available" server rather than a specific location I choose, and I leave that off deliberately, because I'd rather pick a server myself based on what I'm actually trying to do, whether that's reaching a specific country's content or just staying on a server I've already confirmed performs well for me. I've also left the ad and tracker blocking feature switched off, not because it doesn't work, but because I already handle that through my browser and didn't want two separate systems quietly fighting over the same job and occasionally breaking a site in the process. More settings enabled isn't automatically better protection, and it's worth working out which ones genuinely change your risk and which just add complexity for no real benefit. I use NordVPN for the settings described here, which is part of why I run a VPN on every device I own rather than just my main laptop. If you want a second opinion on VPN security more broadly, NCSC has clear, current guidance on this, and my free Safety Toolkit walks through the basics I'd want anyone starting from zero to get right first.