Overview
ProtonVPN is the client from the same people as the encrypted mail service, and the design priorities show. There is no logging of connection contents or destinations, the applications are open to inspection, and the infrastructure is arranged so that the entry and exit points of a connection are separated where the secure core routing is used. It is one of the few clients in this category whose privacy claims are structurally supported rather than only stated.
The build posted here has the full server list and the higher tier features available: the complete country selection, the secure core multi hop routing, the onion routing exits, the split tunnelling and the port forwarding. The client itself is unmodified in how it handles the connection. There is no advertising, no telemetry and no upgrade prompt in the window.
Connecting and routing
The main window is a map and a server list. Connect to the fastest available, to a country, to a city or to a specific server, and the client shows load and latency per entry so a busy one can be avoided. Protocol selection covers the modern fast protocol and the older established one, with an automatic mode that tries them in order when a network is filtering.
Secure core routing sends the connection through a hardened intermediate location before it exits, so the server that sees your traffic never sees where it came from. It costs speed and is worth it for specific work rather than as a default. Onion exits route into the anonymity network directly from the client, which removes the need for a separate browser for occasional use.
The kill switch and split tunnelling
The kill switch blocks all traffic outside the tunnel, and the permanent variant keeps blocking even when the client is not running and across a reboot. That is the distinction that matters: an ordinary kill switch protects a dropped connection, a permanent one protects a machine that started up before you got to it. Turning it off is a deliberate action rather than an accident.
Split tunnelling works in both directions, either excluding named applications from the tunnel or including only those. Excluding is what you want for a banking application that dislikes foreign addresses. Including only is what you want when a single program should be tunnelled and nothing else. Rules can also be written by network address rather than by application.
Filtering, leaks and everyday use
The client has a filtering layer that blocks advertising, tracking domains and known malicious addresses at the resolver level for everything on the machine, not only the browser. It is effective and occasionally too aggressive, which is why it is switchable and has an exception list.
Leak protection covers the address resolution path, the newer browser connection protocol that can bypass a tunnel, and the address version that often goes unprotected. All three are handled by default rather than being options to find. There is a profile system for saving a combination of country, protocol and settings, and a connect on start-up option so a laptop is never briefly unprotected on a public network.
What you get
- Full country and server list with load and latency shown per entry
- Secure core multi hop routing through hardened intermediate locations
- Onion network exits directly from the client
- Permanent kill switch that holds across reboots and when the client is closed
- Split tunnelling by application or by network address, including or excluding
- Resolver level blocking of advertising, tracking and malicious domains
- Leak protection for address resolution, the newer browser protocol and both address versions
- Port forwarding for applications that need an incoming connection
- Saved profiles and connect on start-up for public network use
Inside the archive
- ProtonVPN 5 client, offline installer
- Full server configuration set
- Network driver components for the supported protocols
- Language packs for the interface list shown above
- Install notes covering the kill switch behaviour
System requirements
| Operating system | Windows 10 version 20H2 or Windows 11, 64-bit |
|---|---|
| Processor | Any dual core |
| Memory | 2 GB minimum |
| Graphics | Any |
| Storage | 300 MB free |
| Display | 1024 by 768 or higher |
Installing it
- Unpack and run the installer as administrator.
- Allow the network driver components when the system prompts for them, or no protocol will connect.
- Do not enable the permanent kill switch until you have confirmed a connection works, since it blocks everything otherwise.
- Set your preferred protocol rather than leaving it on automatic if your network is not filtering.
- No account sign-in is required and the full server list is available immediately.
Mirrors
| Route | Region | Note | State |
|---|---|---|---|
| Direct, primary | Europe | No wait, resumable | Online |
| Direct, secondary | North America | No wait, resumable | Online |
| Torrent magnet | Global | Small file, direct is faster | Online |
Release history
- Fixed the permanent kill switch releasing after a driver update
- Server list refreshed
- Split tunnelling now accepts address ranges as well as applications
- Faster reconnection after a network change between wireless and wired
- Resolver level filtering exception list added
- Leak protection extended to the newer browser connection protocol
- Profile system reworked
Questions about this release
Is anything logged?
Not connection contents or destinations. The client itself sends no telemetry in this build and there is no advertising or upgrade prompt.
Why did my internet stop working?
Almost certainly the permanent kill switch with no active connection. Open the client and connect, or turn the switch off deliberately from the settings.
Which protocol should I use?
The modern fast one unless your network blocks it, in which case the older established one over a common port usually gets through.
Does secure core slow things down?
Yes, noticeably, because the traffic takes a longer path through two locations. Use it when it matters rather than always.
Comments
Full country list, no upgrade banner anywhere. Split tunnelling by address range is new and useful.
Resolver blocking cleaned up the whole house network, not just my browser.
Comments are read before they appear. If a build stops working, say so here and it gets rebuilt rather than quietly left up.
Permanent kill switch survives a reboot properly now. That was the one thing I actually needed it for.