HostingRanker: VPN kill-switch test worksheet Guide: https://www.hostingranker.com/what-is-a-vpn-kill-switch/ Prepared: September 9, 2026 Use harmless activity on a device and network you control. Save work and keep recovery instructions offline. Do not run a test that can remove your only remote access to the device. SETUP Date and time zone: Device and OS version: VPN app and version: Protocol and server: Kill-switch mode and documented trigger: Apps intended to use the VPN: Split-tunnel / LAN exceptions: DNS configuration: IPv4 available? IPv6 available? Baseline public IP (keep private): VPN public IP (keep private): Recovery steps: COPY THIS BLOCK FOR EACH SCENARIO Event tested: Expected behavior (write before testing): Underlying internet available during the event? How established? Requests attempted and observation method: Start / interruption / recovery timestamps: Observed route or failure for fresh requests: Address families and applications actually checked: DNS observations: Recovery result: Result: observed as expected / unexpected / inconclusive / not tested Limitations and follow-up: SCENARIOS TO CONSIDER [ ] Manual Disconnect: interpret against the chosen mode. [ ] Unexpected tunnel loss with underlying internet available: only use a supported procedure or an isolated environment you can restore. [ ] Server switch. [ ] Sleep / wake. [ ] Network transition. [ ] App exit (different from closing its window). [ ] Device restart / first connection. [ ] Split-tunnel apps and LAN exceptions. INTERPRETATION - Nothing loading while Wi-Fi is off is not proof of a working kill switch. - The final VPN IP does not rule out direct traffic during the transition. - Cached pages and buffered media do not demonstrate a live connection. - A failed DNS lookup alone does not establish all traffic was blocked. - A successful manual-disconnect check does not cover unexpected crashes. - An unavailable IPv6 connection is not a passing IPv6 leak test. - A browser check does not establish the route of every background app. - Record one specific observation, not a claim that a provider never leaks. - Restore intended settings and verify normal tasks after testing.