Answers to the questions we expect most — and a human at the end of the page.
That's usually VPNKill doing its job: when it's armed and your VPN is not connected, all non-VPN traffic is blocked. Either connect your VPN, or click the VPNKill menu bar icon and choose Disarm (or Pause for a temporary window).
VPNKill needs two one-time macOS approvals during onboarding: allowing the system extension in System Settings → General → Login Items & Extensions, and allowing the content filter when macOS asks. The in-app onboarding shows exactly where to click.
Yes — VPNKill is VPN-agnostic. WireGuard, OpenVPN, IKEv2, and corporate clients all work: it allows traffic on VPN tunnel interfaces and blocks everything that would leave through a physical interface. There is nothing to configure.
Use the built-in uninstaller: open VPNKill's Settings → Uninstall VPNKill… and authenticate when macOS asks. It removes the filter extension, the filter configuration, and the login item in one step. For a fully scripted removal you can also run:
/Applications/VPNKill.app/Contents/MacOS/VPNKill --uninstall
We don't recommend just dragging the app to the Trash: macOS is supposed to remove the filter extension with it, but sometimes silently doesn't. If that already happened, see the next answer.
The kill switch keeps enforcing even when the app isn't running — that's what makes it trustworthy — so a Trash-deleted copy can leave the filter active. To get back online right away: System Settings → Network → Filters → turn VPNKill off. (Toggling VPNKill off under System Settings → General → Login Items & Extensions → Network Extensions works too.)
To remove the leftover extension completely, reinstall VPNKill and use Settings → Uninstall VPNKill… as above.
Bugs, questions, ideas: support@vpnkill.com