iOS / Guides

How to Use a VPN on iPhone: A Complete iOS Guide for Beginners

Follow this step-by-step guide to install a compatible app, import your subscription, approve the VPN configuration, and verify your connection on iPhone or iPad.

To use a VPN on iPhone, first check which app works with your subscription. Install it from a trusted source, import your subscription, allow iOS to add the VPN configuration, then check your connection’s exit details. Don’t rely on the app’s “Connected” status alone: confirm separately that the configuration was added, the route is available, and traffic is taking the path you expect. The steps are similar on iPad, though button locations may differ with the screen layout.

Before you start, understand the difference between an app and a subscription

A VPN app is installed on your device and handles configuration, connections, and routing rules. A subscription provides the server configurations. You usually import a subscription link into the app; opening it in Safari won’t connect your device. VPNQL users can check how to get started at the client download page, then follow the setup instructions there. If you use another service, follow its instructions for supported apps and import methods.

The VPN page in iOS Settings lets you view and manage configurations you’ve added, but you can’t paste any subscription link there as a native system configuration. Configuration formats vary by connection type. Shadowsocks, VMess, Trojan, VLESS, Hysteria2, and TUIC are different protocols or connection methods; check the app’s documentation to see what it supports and which settings it requires. Don’t assume one format will work in another app just because the protocol names look similar.

What you needPurposeCheck before you begin
VPN appImport configuration and connectCheck the source, device compatibility, and supported import methods
Subscription link or configuration fileProvides available routes and connection settingsMake sure it comes from your service’s official portal; don’t share it publicly
Working internet connectionInstall the app, update your subscription, and test the connectionFirst, make sure you can browse the web without the VPN
Service documentationExplains routes, split tunneling, and how to update configurationsChoose a configuration based on the app you’re actually using

Import your setup on iPhone or iPad

The steps below are general; menu labels may include “Subscription,” “Configuration,” “Import from URL,” or “Add Configuration.” If the service provides a file or QR code instead, use the corresponding import option. Don’t switch to an unsupported app just to find a button with a particular name.

  1. Get a compatible app. Open the app page from the channel specified in the service documentation. Check the app name and developer before installing. If there are multiple versions, choose the one for iOS or iPadOS.
  2. Get your subscription. Find the subscription link, configuration file, or QR code in the service portal. If you copy a link, make sure it’s complete and doesn’t include extra spaces. If you need to sign in to access it, use a trusted device.
  3. Import it in the app. Open the app’s subscription or configuration menu and choose the import method that matches what you have. Paste the link and follow the prompts to save and update it. For a file, use the system file picker to open it in the app.
  4. Choose a route and mode. Wait for the imported routes to appear, then choose one based on your destination and needs. When troubleshooting for the first time, stick with the service’s recommended default mode. Once connected, you can adjust the routing rules if needed.
  5. Connect and allow the VPN configuration. The first time you connect, iOS may ask whether you want to allow the app to add a VPN configuration. Make sure the request is from the app you just installed, then follow the system prompts to approve it. If iOS asks you to unlock your device to confirm, follow the onscreen instructions.

System approval lets the app create a VPN configuration on your device; it doesn’t mean you’re connected to a route. Return to the app and check its status. If it’s still connecting, check your current network and selected route rather than importing the same subscription repeatedly. You can view the VPN status in Settings, but return to the app to choose routes, update subscriptions, and manage routing rules.

How to verify your connection

Check your connection in stages. First, confirm that the app says it’s connected and that the sites you need load. Then compare your public IP and exit location before and after connecting. Note your location and exit IP before connecting, then check again on our IP check page. The exit location should match the route and routing mode you selected, but location databases can be out of date, so a city name alone doesn’t indicate route quality.

  • ✅ The app shows that you’re connected, and the site you’re testing loads normally. This confirms that the basic connection works.
  • ✅ The exit check matches the expected location for your selected route. If you use split tunneling, test only traffic that should use that route.
  • ✅ After switching networks or reopening the app, check your actual exit again instead of relying on an old status message.
  • ❌ If the app says you’re connected but your exit hasn’t changed as expected, don’t reinstall it right away. Check the routing rules and make sure the test site is included in the VPN route.

Check your exit IP and DNS separately. The public IP shown by a website is only one part of the picture. To understand how DNS requests are handled, check the app’s DNS settings and use reliable test results. A DNS test listing servers outside your selected region doesn’t, on its own, prove there’s a leak: DNS resolvers may use infrastructure in other locations, and system or browser behavior can affect the results. If certain domains consistently take the wrong route, check the app’s DNS and routing settings before trying another protocol.

How to tell: “Connected” is the app’s status; loading a webpage checks basic access; matching the exit to your routing rules checks the traffic path. Verify all three separately to pinpoint whether the issue is with importing, connecting, or routing.

Choosing a route and split tunneling

After importing, route names often include a location or type. A direct route connects to a remote server over your current network. A relay route passes through an intermediate server before reaching its exit. IEPL usually refers to a route that uses dedicated connectivity as part of the provider’s network design. These terms describe connection and transmission methods; none guarantees faster speeds at all times. Your experience also depends on your local network, the destination site, congestion, and app settings.

For your first connection, choose a location that suits your needs, keep the default routing rules, and verify your exit as described above. To send different sites over different routes, check the routing modes available in your app. Global mode typically sends more traffic through the selected route; rule-based mode chooses a path based on domains, IP addresses, or other conditions. Which apps and domains match depends on the app and its rule set, so don’t assume that a mode’s name tells you exactly where all traffic goes.

For example, if you’re connected but a site still uses your regular network, check whether the routing rules exclude it. If a local service stops working as expected, check whether it was mistakenly routed through the VPN. Change one setting at a time and test again to make it easier to find the cause. To compare locations and route types, review the details on our network routes page. Don’t rely on speed tests from someone using a different network.

Troubleshooting common issues

No authorization prompt appears

Make sure you’ve started a connection from inside the app, rather than just saving the subscription. If the app has already added a VPN configuration in Settings, iOS may not show the first-time authorization prompt again. Don’t keep deleting the configuration just to make the prompt appear. Check the app’s error message and the VPN status in Settings instead.

Stuck connecting, or no access after switching networks

Disconnect first and check whether your current Wi-Fi or cellular connection can load webpages on its own. If a public network requires you to complete a sign-in page in your browser, connect to the network before starting the VPN. Then update your subscription, try another route suited to your needs, and reconnect. If several routes fail, note the error shown in the app and check the service’s help documentation. Switching between Wi-Fi and cellular may interrupt the connection, so check that the app reconnects afterward.

Connection seems to drop when the screen locks or you switch apps

iOS manages background activity, so reconnection behavior depends on the app, network changes, and system state. When you return to the app, check its status and your exit instead of relying on whether the VPN icon stays visible in the status bar. If the app offers on-demand connection or automatic reconnection, read the option’s description before enabling it. Also check whether system settings are restricting the network access the app needs.

Connected, but a specific site won’t load

Try other websites to determine whether the connection is down entirely or the problem is limited to one site. Then check whether that site is using the expected route. If needed, temporarily test another mode supported by the app, then restore your usual settings. If the issue only occurs in one browser, check whether extensions, cached data, or features such as iCloud Private Relay are affecting the test. These features aren’t the same as a VPN configuration, so avoid changing several things at once and guessing at the cause.

Troubleshoot in this order: Check that your regular network works, then confirm the subscription updated, the app connected, and the exit is correct. Finally, check the site’s routing and DNS. Keeping track of each result is more useful than repeatedly reinstalling the app.

Everyday best practices

Subscription configurations may change when the service updates its servers. If the route list looks outdated or you can’t connect, update the subscription in the app before importing it again. When you switch devices, get the latest setup instructions from the service portal rather than relying on screenshots from an old device. For VPNQL installation steps, see our quick start guide and follow the instructions shown in your app.

On iPad, the process is the same: install a compatible app, import your subscription, approve the system configuration, choose a route, and verify your exit. With multiple windows, it can seem as though switching apps changes your route, but the connection is still managed by the app and the system VPN configuration. Whatever device you use, check that your network and exit meet your expectations before accessing services containing personal information. Follow the rules in your location and the terms of the services you use.

If you’re still comparing plans, review the data allowances and terms on our pricing page before setting things up. After setup, keep this checklist in mind: your regular network works, the subscription is up to date, the VPN is connected, and the exit is verified. The next time something goes wrong, you can start by checking what changed.

Start Free