The first evaluation criterion is control granularity, because split tunneling implementations vary widely. The best offer three capabilities: exclude specific apps, include only specific apps in an only-VPN mode, and route by IP subnet or domain patterns.
Per-app rules are the most useful for day-to-day work. You keep your browser and password manager inside the tunnel while letting a local banking app or printer helper stay out. This approach prevents conflicts without exposing sensitive traffic.
IP-based rules are better for fixed resources like a NAS, smart TV, or office subnet. The sharp edge: on iOS in particular, some vendors implement split tunneling in a more limited, website-based way, which is helpful but not as precise as true per-app routing.
Platform reality demands OS-specific evaluation. If you're shopping for a VPN with split tunneling feature, you need to treat supported as OS-specific, not brand-specific. In 2026, Windows and Android are still the most flexible for app-level split tunneling.
macOS can be excellent with the right client, but some providers have reduced or delayed macOS split tunneling because Apple's networking framework has tightened what VPN apps can do system-wide. iOS is usually the most restrictive, although there's a notable exception covered in the rankings.