VPNSecure
About VPNSecure
VPNSecure is a VPN client for the person who wants to choose the cipher. Most consumer clients pick a protocol and an encryption level for you and hide the choice. This one puts OpenVPN in front of you with a dropdown for the cipher and a Stealth mode that disguises the tunnel as random traffic.
A kill switch is labelled in plain words, and a settings panel accepts your own OpenVPN directives and routing rules. It is a small service with a modest server count, and its client reflects that. Fewer places to connect to, more control over how.
The comparison is with the settings-heavy clients rather than the one-button ones. TorGuard covers similar ground with more protocols and more servers. VPNSecure covers it with OpenVPN alone and a couple of features the others lack, a domain-based routing rule and a proxy that reaches the same servers without a tunnel. Whether that is enough depends on what you connect for, and the sections below try to be specific about it.
OpenVPN and three ciphers
The VPNSecure client runs OpenVPN and nothing else. No WireGuard, no IKEv2, which puts it behind on speed against services that adopted the newer protocol and ahead on transparency, since every line of what it runs has been examined in public.
The cipher dropdown offers the standard 256-bit AES, the faster 128-bit variant, and a legacy 56-bit option that belongs in a museum and should never be picked.
The choice is offered so that a stream or a download can run with lighter encryption when the content does not matter. It is one of the few clients that puts that decision in your hands.
Stealth mode and obscure ports
Stealth VPN wraps the tunnel so that its packets look random rather than like a VPN, which gets through networks that inspect traffic and block what they recognise. It is a checkbox. Obscure ports move the connection to ports that filters tend to leave open.
Together they cover the hotel network that blocks everything and the country that inspects everything, with some speed lost along the way.
Kill switch, leak fixes and IPv6
The kill switch is called Disable Internet on Disconnection, which is exactly what it does. When the tunnel drops, nothing reaches the network until it returns or you untick the box. It is off by default and lives in the advanced settings, so the first task after installing VPNSecure is to find it. A DNS leak fix forces name lookups through the tunnel. A UDP leak fix closes a gap in how the tunnel handles connectionless traffic, and Disable IPv6 shuts the other route by which a real address escapes. None are on until you switch them.
There is no WebRTC blocking in the client, so a browser can still give away the real address through a video-call handshake unless the browser is configured itself. With the settings on, the tunnel holds and the address stays hidden, and the settings are the point. Turn them on.
Routing, custom options and the proxy
The VPNSecure Routing panel is the closest thing to split tunnelling, and it works backwards from most. Instead of choosing programs to exempt from the tunnel, you list domains that should go through it, and everything else uses the ordinary connection.
For a torrent tracker, a work site or a streaming service that must appear from abroad while banking stays local, it is the right shape. For sending one program outside the tunnel, it is the wrong one, and there is no per-application option.
Custom OpenVPN options and custom routes can be typed into the settings, which is a feature for people who know the directives and a wall of text for those who do not. Separate from the tunnel, an HTTP proxy reaches all of the provider’s servers, with a browser extension that switches between them, and SSH-based SOCKS proxies are available for programs that take a proxy setting.
A proxy hides the address without encrypting the traffic, and the client is honest about that distinction.
Smart DNS and the extras
VPNSecure Smart DNS is for devices that cannot run a VPN. Change the DNS servers on a games console, a television or a streaming box to the provider’s, and sites that check location see a different country, with no tunnel and no speed loss. It is included with the account and configured on the device rather than in this client. A meta search engine that queries the major search sites without passing your address or history to them is included as well, and a browser extension controls the proxy.
The server list is short beside the big services, a few dozen locations, and streaming through the tunnel is unreliable against the major video platforms, which is what the Smart DNS is for. The client itself has a few rough edges. Minimising sends it to the tray without warning, and there is no quick connect button, so a server is chosen from the list every time.
Conclusion
VPNSecure is for the person who wants a plain OpenVPN client with the important switches exposed and a Stealth mode for hostile networks. The routing rule that sends a few sites abroad while the rest of the machine stays home is a bonus. People who already know OpenVPN’s directives will feel at home, and people who connect from networks that fight VPNs will find the obfuscation earns its place.
Anyone who wants WireGuard speed, a large server map or a working streaming connection through the tunnel should look at the bigger services. This client asks you to turn on your own protection, and rewards you for reading the settings.
Pros & Cons
- Selectable cipher strength for trading security against speed
- Stealth mode and obscure ports for networks that block or inspect VPNs
- Kill switch plus DNS, UDP and IPv6 leak fixes
- Domain-based routing sends chosen sites through the tunnel and nothing else
- Custom OpenVPN directives and routes for people who know them
- Smart DNS and proxies for devices and programs that cannot tunnel
- OpenVPN only, with no WireGuard
- Kill switch and leak fixes are off until enabled
- No per-application split tunnelling
- Small server list and weak streaming through the tunnel
- Legacy cipher still offered
Frequently asked questions
In the advanced settings, labelled Disable Internet on Disconnection. It is off by default. Enable it along with the DNS leak fix and Disable IPv6 before relying on the tunnel.
Partly. The Routing panel sends the domains you list through the tunnel and leaves everything else on the normal connection. There is no way to route a specific program outside the tunnel.
Leave it on 256-bit AES. The 128-bit option is a little faster for streaming where privacy matters less. The 56-bit legacy option should not be used for anything.
The tunnel's shared addresses are recognised and blocked by most platforms. Use the Smart DNS on the device instead, which is what the provider offers for that purpose.