A double VPN routes your internet traffic through two VPN servers instead of one. The feature is also called multi-hop VPN. Your connection usually follows this path:

Device → entry VPN server → exit VPN server → website or online service

The extra server can make traffic harder to trace and reduce the risk linked to a compromised or monitored VPN server. It also usually slows the connection, so most people do not need it for everyday browsing.

Double VPN at a Glance

Feature Regular VPN Double VPN
VPN servers used 1 2
Public IP shown to websites VPN server IP Second, or exit, server IP
Privacy protection Standard More protection against some server-monitoring threats
Speed Usually faster Usually slower
Best for Everyday browsing, public Wi-Fi and streaming Higher-risk privacy situations
Common names VPN Double VPN, multi-hop or VPN chaining

How Does Double VPN Work?

A double VPN sends your traffic through two VPN servers in sequence.

  1. Your device connects to the first server, known as the entry server.
  2. The entry server forwards the connection to a second server, known as the exit server.
  3. The exit server connects to the website or online service.
  4. The website sees the exit server's IP address instead of your original IP address.

Many VPN providers operate both servers within their own network. Surfshark calls its version MultiHop, NordVPN offers Double VPN, and Proton VPN uses a related system called Secure Core.

The privacy benefit comes from separating the entry and exit points. An exit server may see the connection going to the website without directly receiving your original IP address from the internet connection. Proton VPN describes this setup as protection against certain timing and network-monitoring attacks, including cases where an exit server is compromised.

Is Double VPN Safer Than a Regular VPN?

Double VPN can be safer than a regular VPN in specific threat scenarios, but it is not automatically better for every user.

It may help if:

  • You are concerned about a VPN server being monitored or compromised.
  • You are a journalist, activist, researcher or whistleblower handling sensitive information.
  • You are in a country with extensive internet surveillance or censorship.
  • You want to separate the server that receives your connection from the server that connects to the destination website.

The protection depends on the provider's server design, logging practices, infrastructure security and jurisdiction. A double VPN does not remove the need to trust the VPN provider, especially when one company operates both servers.

It also does not make you completely anonymous. Websites can still identify you through account logins, cookies, browser fingerprinting and other tracking methods.

What Are the Disadvantages of Double VPN?

The main disadvantage is performance.

Your data passes through another server, which can increase latency and reduce download and upload speeds. The slowdown is usually more noticeable when the entry and exit servers are far apart. Proton VPN says its Secure Core feature can slow the connection considerably. NordVPN also says lower speeds are expected because traffic is routed and encrypted through a second server.

Other limitations include:

  • Fewer server combinations than a regular VPN connection.
  • More resource use on your device and the VPN network.
  • Possible problems with streaming, gaming and other latency-sensitive activities.
  • No guaranteed protection against malware, phishing, account compromise or tracking.
  • No automatic protection against VPN blocking. Double VPN does not necessarily hide the fact that you are using a VPN.

Double VPN is also different from an obfuscated VPN. Obfuscation tries to make VPN traffic look like ordinary internet traffic. Double VPN sends traffic through two VPN servers. One feature does not automatically provide the other.

Double VPN Versus Two Separate VPN Apps

A provider-supported double VPN is different from installing two independent VPN applications.

Setup How it works Practical result
Provider-supported double VPN One VPN app routes traffic through two of its servers A multi-hop connection managed by the provider
VPN over VPN Two VPN apps create nested tunnels May cause routing conflicts, crashes or leaks
VPN plus browser extension A device-wide VPN and a browser VPN run together Browser traffic may pass through another connection
Tor over VPN VPN traffic enters the Tor network More complex and usually much slower

Two separate VPN applications can create conflicting routing rules. They may also trigger a kill switch or interrupt the connection. Surfshark recommends using its built-in multi-hop feature instead of running two independent VPN services at the same time.

When Should You Use Double VPN?

Use double VPN when privacy against sophisticated monitoring matters more than speed. It may suit sensitive research, source protection, political activism or travel in a heavily monitored environment.

A multi-hop setup can be more useful when the first server is hardened or located in a jurisdiction with stronger privacy protections. Proton VPN's Secure Core, for example, sends traffic through company-controlled servers in Switzerland, Sweden or Iceland before connecting to the selected exit location.

When Should You Avoid Double VPN?

Use a regular VPN instead when you need:

  • The fastest possible connection.
  • Smooth streaming or online gaming.
  • Lower latency for video calls.
  • Reliable access to websites that block VPN traffic.
  • Everyday protection on public Wi-Fi.

For most people, a standard VPN with a kill switch, DNS leak protection, modern protocols and a trustworthy privacy policy offers a better balance of security and performance.

Is Double VPN Worth It?

Double VPN is worth using if you have an elevated privacy threat model. It is not worth using by default for ordinary browsing, streaming or gaming.

Choose a provider-supported multi-hop feature instead of combining two unrelated VPN apps. For everyday use, connect to a nearby standard VPN server. Turn on double VPN when the separation between the entry and exit servers is worth the slower connection.