
How this article was prepared
VPNScout reviews official documentation and public security guidance, then checks material claims during editorial updates. We do not describe a product as hands-on tested unless the article includes the test conditions and results.
If your VPN works in a browser but not in other apps, first determine whether you are using a full-device VPN app or only a browser extension. A browser extension normally protects only browser traffic. With a full VPN app, the most common causes are split tunneling excluding or incorrectly including an app, a kill switch blocking excluded traffic, DNS or firewall conflicts, an app-specific cache or permission problem, or a service that rejects the selected VPN server.
Do not disable security features permanently or enter credentials into unofficial tools while troubleshooting. Change one setting at a time, test again, and restore your preferred protection when you identify the cause.
A working browser does not prove that every application follows the same route. Browsers and installed apps can use different network paths, DNS resolvers, proxy settings, permissions, address families, and security controls.
| What you observe | Most likely place to check |
|---|---|
| Only the browser extension works | Install or connect the full-device VPN app |
| Browser shows the VPN IP but another app shows the ISP IP | Split tunneling or browser-only protection |
| Excluded apps have no internet | Kill switch and split-tunneling interaction |
| One app fails while every other app works | App cache, permissions, account, or service policy |
| Several apps fail but websites work | Firewall, DNS, protocol, or per-app VPN rules |
| Apps work when the VPN is disconnected | VPN server, DNS, filtering, or service compatibility |
| Apps fail with and without the VPN | Underlying app, account, device, or network problem |
If websites also stop loading, use our VPN connected but no internet guide. If the VPN says connected but your public address remains unchanged, follow our IP address troubleshooting guide.
A VPN browser extension generally routes traffic generated inside that browser. It does not automatically protect desktop programs, games, email clients, streaming apps, app stores, or every process on the device.
This can produce an apparently confusing result:
Install the provider's official Windows, macOS, Android, or iOS application when you need device-wide VPN routing. Disconnect the browser extension while testing the full app so two separate VPN locations or filtering systems do not complicate the result.
If you intentionally want browser-only protection, the other apps are not broken merely because they do not use the extension. Test them on the ordinary network and understand that their traffic is outside that browser tunnel.
Split tunneling lets selected applications bypass the VPN or, depending on the provider, allows only selected apps to enter it. A reversed rule, old application path, or incomplete allowlist can send the browser through the VPN while leaving another app outside it.
On Android, per-app VPN rules can allow or disallow specific apps. Google's Android Enterprise documentation explains that an app excluded from the VPN normally uses the system network, but it can lose internet access when Block connections without VPN is also enabled.
Some desktop applications launch helper processes from a different file path. Adding only the visible launcher may not cover the background service that actually connects. Use the provider's current documentation and avoid manually excluding unknown system processes.
A kill switch is designed to prevent traffic from leaving the device without VPN protection. Depending on the platform and provider, that can conflict with split tunneling: an app is told to bypass the VPN, while the kill switch blocks non-VPN traffic.
Temporarily test with split tunneling disabled. If every app works through the full VPN, the interaction is confirmed. Then decide which behavior matters more:
Do not leave the kill switch off without considering the privacy tradeoff. It exists to block unprotected traffic during connection failures.
Mobile and desktop apps can keep an existing session, DNS answer, socket, or authentication token after the network route changes. The browser may create a fresh connection while an app continues retrying an obsolete one.
Clearing application data can remove downloads, preferences, or login sessions. Confirm what will be erased before proceeding.
A browser can use DNS over HTTPS while installed applications use the operating system or VPN resolver. That means websites may resolve normally while an app fails to locate its servers. The reverse can also happen when a custom browser resolver conflicts with VPN filtering.
Return DNS to a simple baseline:
If this fixes the issue, restore one DNS feature at a time. Do not copy random DNS addresses from a forum. Use the VPN provider, operating-system vendor, or a reputable resolver's official settings.
A DNS result alone does not show whether the app's full traffic entered the VPN. DNS and public-IP tests measure different parts of the connection.
Firewalls, antivirus web shields, parental controls, corporate filters, and ad blockers can treat browser traffic differently from installed programs. Some ad blockers also create a local VPN, which can compete with a commercial VPN on mobile devices.
Check whether the VPN and affected app are allowed through the operating-system firewall. Temporarily pause one third-party network filter at a time only for diagnosis, then restore it.
Do not permanently disable antivirus or firewall protection. Update both products, add only documented exclusions, and contact their support teams if they cannot coexist. Never remove an employer-managed security profile without authorization.
Some banking, streaming, gaming, shopping, and workplace services restrict VPN or proxy traffic, challenge unfamiliar locations, or block an address associated with abuse. A browser page may load while the installed app applies stricter checks.
A VPN does not grant rights to content, override an employer's policy, or guarantee that a third-party service will accept every server. Avoid repeated location changes during account verification because they can trigger additional fraud checks.
A VPN can connect while a particular protocol, packet size, or route behaves poorly for real-time apps, games, calls, or large transfers. Browsing may still appear normal because it uses short, retry-friendly connections.
Start with the VPN's Automatic option. Then test its maintained protocols one at a time, reconnecting between tests. Also try a different server before concluding that an entire protocol is unsuitable.
Avoid obsolete protocols and unverified configuration files. If the problem occurs only on hotel Wi-Fi, complete the captive portal first and follow our hotel Wi-Fi VPN guide.
The browser and app may prefer different address families or network interfaces. Local apps for printers, casting, file sharing, or smart-home devices may also need access to the local network, which some VPN settings intentionally restrict.
Allowing LAN traffic is useful at home but increases exposure to devices on the same local network. Keep it off on hotel, airport, and café networks unless you have a specific trusted-device need.
The timing can be coincidental. An app service may be unavailable, the account session may have expired, or an old version may no longer communicate with its servers.
Test the app with the VPN disconnected. Check the developer's official status page, update the app from its verified store, restart the device, and confirm that device date and time are automatic. If only that application fails on every network, contact its developer rather than repeatedly changing VPN settings.
Use this order to avoid changing several variables at once:
Microsoft notes that a Windows network reset removes network adapters and their settings, then reinstalls them after restart. It can require you to reinstall VPN clients or virtual networking software, so it should not be the first step.
Open Settings > Network & internet > VPN and review the active VPN, Always-on VPN, and Block connections without VPN settings. In the VPN app, check split tunneling for the affected application. Remember that an ad blocker or firewall implemented through Android's VPN interface can conflict with another VPN.
Force-stop the affected app, connect the VPN, and reopen it. Clear cache before clearing data. Work-profile apps may follow an administrator's per-app VPN policy that you cannot change yourself.
Review Settings > General > VPN & Device Management for VPNs or managed profiles you recognize. Check whether the affected app has required cellular, local-network, or background-data permissions. Restart the app after connecting the VPN.
Do not delete a work or school profile without authorization. If one consumer app fails while Safari works, update or reinstall that app only after checking its service status and account.
Review the VPN's split-tunneling list, Windows proxy settings, firewall permissions, and other virtual adapters. Some apps use a launcher plus a separate executable, so confirm that the correct program is covered by the VPN rule. Try the full VPN client rather than relying on a browser extension.
Use Settings > Network & internet > Advanced network settings > Network reset only after server, protocol, DNS, firewall, and reinstall checks. Save Wi-Fi credentials and VPN settings first.
Open System Settings > Network > VPN & Filters and check for multiple VPNs, content filters, or security extensions. Confirm local-network permission for apps that communicate with nearby devices. Restart the affected app after changing the VPN route.
Check whether the streaming app was excluded through split tunneling. Force-stop it, clear cache, connect the VPN first, and reopen it. Confirm that the app, device region, account, and subscription satisfy the service's rules. A browser working on another device does not prove the television app has the same routing or access rights.
Use this sequence with NordVPN:
NordVPN documents that excluded applications can sometimes conflict with its DNS routing, and its current support guidance recommends testing other servers, default DNS, Threat Protection settings, and connection protocols when apps fail. Feature names and availability can vary by platform and app version.
After each change, check:
Do not rely on a location label alone. Apps can use GPS, account settings, cookies, and billing region in addition to an IP address.
Contact the VPN provider when several unrelated apps fail only while the VPN is active, especially after testing default split tunneling, DNS, multiple servers, and multiple supported protocols.
Contact the app developer when one app fails with and without the VPN, displays an account-specific error, or has a documented outage.
Include the device model, operating-system version, VPN version, affected app version, server location, protocol, exact error, and the smallest set of steps that reproduces it. Send diagnostic logs only through official support channels and remove personal information from screenshots.
You may be using a Chrome VPN extension, or Chrome may be routed differently through split tunneling, DNS over HTTPS, or proxy settings. Use the provider's full VPN app for device-wide routing and review exclusions.
Normally no. It generally affects supported browser traffic only. Use the official desktop or mobile VPN application when you want other apps routed through the VPN.
Yes. An incorrect per-app rule can route the app outside the VPN or omit it from an allowlist. A kill switch may then block that excluded traffic.
The VPN's kill switch or Android's Block connections without VPN setting may prohibit traffic that bypasses the tunnel. Check the provider's documented interaction between those features.
The app may be outside the VPN, or it may use GPS, local-network information, account region, cookies, or saved settings. A VPN changes network routing; it does not rewrite every location signal.
Use that only as a brief diagnostic test. If it confirms a conflict, choose a supported configuration that preserves the protection you need rather than leaving the feature disabled without understanding the risk.
It can when the browser and apps resolve domains differently or a custom resolver conflicts with VPN routing. Return to the VPN's default DNS temporarily and restore changes one at a time.
Real-time applications can use different protocols, ports, packet sizes, or regional checks than browsers. Try another server and supported VPN protocol, then check firewall and app-specific rules.
Yes. A service can restrict known VPN addresses or require a consistent account region. Follow its terms and contact the service if you believe access was blocked incorrectly.
When a VPN works in a browser but not apps, confirm the scope of protection first. A browser extension is not a full-device VPN. With the full app, reset split tunneling to its default, review the kill switch, restart the affected app, then test another server, default DNS, another maintained protocol, and security-software conflicts.
Treat a single failing app differently from a device-wide failure. One app usually points to its route, cache, permissions, account, or service policy; several failing apps point more strongly to VPN routing or filtering. Make reversible changes, preserve security settings where possible, and use official support when the same result remains reproducible.