The specific risk in this unit is not that somebody attacks you. It is believing you are protected when you are not — a worse condition than having no protection at all, because it changes behaviour without changing the exposure.
This post lists the signals indicating the tunnel is not doing its job, and the checks that make them visible.
It expands on the recommendation a VPN for sensitive traffic.
The obvious signals
These are the ones the device shows, if you look.
The icon is not there. Almost every system shows an indicator when a VPN is on — in a phone’s status bar, in a computer’s menu bar. Its absence is the most direct signal.
The application says “disconnected”. Obvious, but worth opening: many stay in the background and do not warn you when they drop.
The connection has become fast again. A tunnel always adds a small delay. If browsing suddenly becomes quicker, the traffic may no longer be going through the server.
A service that did not work before now works. If the bank or a streaming service stop complaining, it is often because they are seeing you from your real location.
The content is local again. If you had chosen a server in another country and sites are showing you the local version again, the traffic is no longer leaving from there.
Home devices are visible again. Printer, shared archive, camera: if they were unreachable with the tunnel on and now appear, the tunnel is gone.
The signals after a change
These are the moments when VPNs drop most often, and when almost nobody checks.
| Situation | Why the tunnel drops |
|---|---|
| A change of network | The tunnel was tied to the previous connection |
| Waking from sleep | The system closed the background processes |
| Restarting the device | The application does not start automatically |
| A system update | The app’s permissions can be reset |
| Switching between Wi-Fi and data | The connection changes and the tunnel breaks |
| Coming out of flight mode | Every connection re-establishes from scratch |
The first and last rows describe the most common situation on the move: you leave the house, the phone switches to data, the tunnel drops, and the protection disappears with no notification at all.
It is exactly the case the block-if-it-drops setting resolves: if the tunnel falls, the traffic stops. Without that setting, it leaves in the clear.
The check that settles the doubt
There is a simple way of making sure the tunnel is working, and it needs no special tools.
Check the apparent location. Search “what is my IP address” or “check my IP” on a search engine: the result shows where you appear to be connecting from.
- If the VPN server’s city you chose appears → the tunnel is working.
- If your real city appears → the tunnel is not working.
It is a ten-second check, and it is worth doing at three moments: right after configuring the VPN, after a major update, and the first time you use it in a situation that counts.
An extra check for anybody wanting to be thorough: there are pages that also test whether site name resolution is leaving the tunnel. It is the most common gap, because it can fail even while the tunnel is working correctly for everything else.
What is NOT a signal
Useful to avoid needless alarm.
| What | Why it does not indicate a problem |
|---|---|
| The connection is slower | It is normal: the traffic takes a longer route |
| A site asks for an extra check | It sees you arriving from a shared address: that is the tunnel working |
| The bank asks for extra confirmation | It is detecting a sign-in from an unusual location: correct |
| The battery lasts less | The tunnel is an active process |
| Some content is unavailable | Geographic restrictions tied to the server’s location |
| The home printer is not visible | Local devices are outside the tunnel |
Rows two and three describe situations many people read as malfunctions and which are in fact proof that the tunnel is doing exactly what it exists for.
The most insidious signal: habit
There is a way of losing the protection that produces no technical clue at all, and it is the most frequent.
The “temporary” switch-off that becomes permanent. A service does not work, the VPN gets switched off for a minute, the problem is solved, and it never gets switched back on. From that moment the device is uncovered and nothing flags it.
Switching it off for speed. During a download, a video call, a heavy upload. The same mechanism.
The exclusion that widens. One service gets excluded from the tunnel to make it work, then another, then a third. At some point most of the traffic is outside.
The countermeasure is not technical: it is a periodic check. Once a week, look at whether the VPN is on and which services you have excluded. It takes thirty seconds and closes the one scenario no indicator detects.
The signals about the provider, not the tunnel
A different category: clues that the service chosen is not what it says it is. They are less frequent but more significant.
The application asks for disproportionate permissions. A VPN needs broad network permissions — that is its function. It does not need access to your contacts, precise location, camera or messages. If it asks, the request has no technical justification.
Adverts appear. A service inserting advertising is monetising in a way that contradicts its declared function.
The service is free and unlimited. It is not a clue, it is an economic certainty: that infrastructure is paid for by something, and what it has to sell is your traffic.
Information about the company cannot be found. Base, ownership, contacts: if a provider makes it hard to know who it is, that is information in itself.
The site promises total anonymity. No VPN can provide it, and a serious provider does not claim it. A technically impossible promise says something about the honesty of the communication.
The application installs alongside other things. Toolbars, extra programs, unrequested extensions: a practice incompatible with a security product.
None of these signals requires technical skill to notice. They can all be seen before subscribing, and that is the best moment to notice them.
What to do if you discover it was not protecting
It is not an emergency, and that is worth saying.
- Turn it back on and check the apparent location.
- Turn on the block if it drops, if it was off: it is what stops this repeating silently.
- Check the application’s automatic startup.
- Think back to what you did during the uncovered period. In most cases: ordinary browsing, so nothing significant — the traffic was encrypted by the sites anyway.
- If during that period you did the activities the VPN was really there for, consider that the destinations were visible to whoever ran the network. The content was not.
The last point is the correct measure of the thing: a dropped VPN does not expose your data. It exposes the list of sites you contacted — which is precisely what the VPN was meant to hide, and nothing else.
A three-point periodic check
Because this unit does not require continuous vigilance but a check now and then.
Once a month, or after a major update:
1. The apparent location. Ten seconds: look up your IP address and see which city appears. It is the check covering the most common case.
2. The configured exclusions. Open the application and look at the list of services you excluded from the tunnel. If it has grown without you remembering, the protection covers less than you think.
3. The key settings. Block if it drops on, name resolution protection on, automatic startup configured. Application updates sometimes reset these entries.
After changing device or restoring one: do it all again from scratch, because settings do not always transfer.
Three minutes a month. It is far less than the cost of discovering, weeks later, that the tunnel was not there — and more useful than any daily check nobody keeps up.
Why it is easy not to notice
A note explaining why this unit is necessary and not obvious.
Every other measure in this series is noticed when it is missing. If the password vault does not work, you cannot sign in. If the second factor is off, the service does not ask for it. If the screen does not lock, you see it.
A dropped VPN, by contrast, changes nothing perceptible: pages open, apps work, mail arrives. The only thing that changes is invisible by definition — who sees your destinations.
It is a general characteristic of measures protecting confidentiality rather than function: their absence produces no symptoms.
Two practical consequences follow:
An explicit check is needed, because it will not arrive on its own. It is why checking the apparent location is worth more than any indirect clue.
Automation is needed, because no manual check is reliable for long. The block if it drops is exactly that: it turns an invisible failure into a visible one, stopping the traffic instead of letting it pass in silence.
It is worth accepting its inconvenience precisely for that reason: a protection that breaks noisily is more reliable than one that breaks in silence.
How this connects to the Cyber Welfare Framework
| Pillar | What this content contributes |
|---|---|
| Awareness | Recognising that perceived protection changes behaviour |
| Skills | Checking the apparent location and name resolution leaks |
| Secure Behaviour | Periodically checking the status and the exclusions |
Reference level: FL3 — Autonomous.
Summary
- The risk here is believing you are protected, not being attacked.
- The tunnel drops mostly at network changes and after sleep, without warning.
- The decisive check takes ten seconds: which city you appear to connect from.
- The most insidious signal is not technical: the temporary switch-off that stays.
One thing to do today. If you use a VPN, search “what is my IP address” and look at which city appears. If it is yours, you have just found something useful.
Related content
- A VPN for sensitive traffic — the recommendation this expands on
- How to choose and use a VPN — the settings that avoid these situations
- How a VPN works — why the tunnel drops when the network changes
- Impact of unprotected traffic — what is really exposed when it drops
Related resources
Short reads from the Resources section, for anyone who wants to stop on a single aspect:
Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.



