Mac Internet Stops After a VPN Disconnect? Check the System Proxy
If web pages stop loading after you disconnect a VPN on your Mac, check for stale HTTP, HTTPS, SOCKS, or PAC proxy settings and test the route.
Web pages stop loading after you disconnect a VPN on your Mac. Wi-Fi stays connected, the signal looks normal, and other devices still work. Safari or Chrome spins because the VPN may have left an HTTP, HTTPS, SOCKS, or PAC proxy enabled after its route disappeared.
Check that proxy state before restarting the router or changing DNS. The steps below show where macOS stores the settings, how to inspect them, and how WiFi Lens separates a Mac-side routing problem from LAN or internet trouble.
Different symptoms need a broader sequence. Mac Connected to Wi-Fi but No Internet? Check DNS and Proxy Settings covers DHCP, DNS, captive portals, and router problems.
Why a VPN disconnect can leave browsing broken
The Wi-Fi icon in the menu bar reports one thing: your Mac has established a wireless link with an access point. Everything a web page needs happens above that link.
For a page to load, your Mac needs a valid IP address, the router needs to reach the internet, DNS needs to translate the domain, and — less visibly — your system proxy and VPN settings need to route traffic correctly. Any of these can fail while the Wi-Fi icon still looks healthy.
The confusing part is that failures are often selective. Messaging apps establish a connection when they start and keep it open, so they keep working while DNS or proxy problems block every new browser request. Other devices on the same network are unaffected because their settings differ. The result: Wi-Fi looks fine, the network looks fine, and only your Mac’s browsing is broken.
Think in three stages: This Mac, LAN, Internet
Instead of changing settings at random, sort every possible cause into three stages:
| Stage | What it covers | Typical sign |
|---|---|---|
| This Mac | Network path, DNS, system proxy, VPN and virtual-interface routing | Only this Mac fails; messaging works but browsers don’t; trouble started after using or quitting a VPN |
| LAN | Reaching your router (gateway) | Wi-Fi shows connected but the Mac cannot reach its own router — often a DHCP or router problem |
| Internet | Connectivity beyond the router, ISP, captive portals | Every device on the network fails, or a public network is waiting for sign-in |
Most “connected but won’t load” cases that affect a single Mac land in the This Mac stage — and inside that stage, proxy and VPN routing are the easiest things to miss.
How stale VPN and proxy routing breaks browsing
VPN apps create virtual network interfaces (often named utun...) and can configure the system proxy while they run. When the VPN app quits abnormally, or you leave a network while it was active, the proxy settings can stay behind. Traffic then tries to route through a server or tunnel that no longer exists, and browsing dies even though Wi-Fi is perfectly healthy.
Apple’s proxy settings guide lists the proxy mechanisms available in macOS. Any of them can be left in a stale state:
- Auto Proxy Discovery — macOS asks the network for a proxy configuration automatically
- Automatic Proxy Configuration (PAC) — a URL points to a script that decides when to use a proxy
- Web Proxy (HTTP), Secure Web Proxy (HTTPS), and SOCKS Proxy — explicit proxy servers for different traffic types
Proxy and VPN are not the same thing, but they overlap often: a VPN may set a system proxy, and a proxy app may create a virtual interface. That is why a check needs to look at both the proxy configuration and the interfaces traffic is routed through.
How to check proxy and firewall settings on macOS
Start with the system proxy: open System Settings > Network > Wi-Fi > Details > Proxies and review which proxy types are enabled. For a compact terminal view of the same configuration, run scutil --proxy.
The built-in macOS Application Firewall primarily controls incoming connections. It is usually not the first suspect when ordinary web browsing suddenly fails after a VPN disconnect. A third-party firewall, network filter, VPN helper, or security product is more likely to affect outbound browser traffic.
On a managed Mac, do not disable security software or remove a required proxy on your own. Check with your IT team before changing an organization-managed network policy.
A three-stage check that runs on your Mac
WiFi Lens’s Network Self-Check was reworked in version 1.5.1 to follow exactly this three-stage structure: This Mac, LAN, and Internet, with results grouped into a workbench so you can see at a glance which layer is failing.
What the check covers:
- This Mac — whether the macOS network path is active, whether DNS can resolve a test domain, and the system proxy configuration (HTTP, HTTPS, SOCKS, PAC, and auto discovery)
- This Mac — whether a configured proxy routes through a virtual network interface such as a VPN or TUN device. This is the check that catches the stale-VPN scenario above
- LAN — whether your Mac can reach its gateway
- Internet — whether the Mac can reach the internet, using Apple’s authoritative captive-portal probe plus a stable HTTPS page
- Additional checks — IPv6 access, and evidence-based next steps when something is abnormal
Each check ends with one of three verdicts — Normal, Abnormal, or Indeterminate — and when a check fails, the app suggests a concrete next step. For example, “A configured proxy route could not be reached” points you to start the proxy app or disable the stale system proxy. “The network may require sign-in” tells you a captive portal is intercepting web access, so you look for a sign-in page instead of DNS settings.
Everything runs locally. WiFi Lens does not upload your diagnostic results, does not read or save proxy credentials, and does not send HTTP test requests through your proxies. The only network traffic is the connection and DNS checks the tool needs to test connectivity by design.
What to do when the proxy or VPN layer is the problem
If the check (or your own investigation) points at proxy or VPN routing:
- Quit the VPN app completely — not just toggle it off in its menu. Check Activity Monitor or the app’s quit command if it keeps a helper running.
- Write down your current proxy settings — System Settings > Network > Wi-Fi > Details > Proxies. Note what is checked before changing anything, so you can restore it.
- Temporarily uncheck proxies you did not set for this network — if browsing returns, a stale proxy was the cause.
- Check for leftovers in the terminal —
scutil --proxyprints the active proxy configuration in a compact summary. If it shows a proxy you did not configure, that is likely your culprit. - On a managed Mac, check with IT first — corporate or school devices may require proxies. Do not remove them permanently.
After each change, re-run the network check. The app’s guidance includes a “run again” step so you can confirm whether the fix worked before moving on to the next suspect.
What else a VPN can leave behind
The system proxy is the best-known leftover, but it is not the only one. A VPN that quit badly — or that you left while it was active — can leave three other things behind, and each one breaks browsing in a slightly different way.
DNS servers that outlived the tunnel
Many VPNs push their own DNS resolvers so that lookups go through the tunnel. If those servers are written into the network configuration and the tunnel then disappears, your Mac keeps sending DNS queries to an address it can no longer reach. The Wi-Fi link is fine, the IP address is fine, and every domain still fails to resolve.
Where to look: System Settings > Network > Wi-Fi > Details > DNS. Compare the listed servers against what you expect from that network. A resolver on a private range that you do not recognise is a strong sign it came from a VPN.
What good looks like: on a home network, DNS is usually either empty — meaning the router supplies it — or a public resolver you chose yourself. If you are unsure, note the current list before changing it, so you can put it back.
Virtual interfaces that did not go away
VPN apps create virtual interfaces, usually named utun, and route traffic through them. When the app exits without tearing them down, routes can still point at an interface with nothing behind it.
Where to look: ifconfig -a | grep utun lists the virtual interfaces that currently exist. scutil --nc list lists the VPN network services macOS knows about and their status. A service still listed as connected — or interfaces that persist when no VPN app is running — explains routing that goes nowhere.
A VPN network service still configured
A VPN can also stay registered as a network service in System Settings > Network, even after the app itself is gone. Traffic may still be routed through it depending on how it was configured.
Where to look: System Settings > Network lists every service, not just the active one. If a VPN entry remains that you no longer use, remove it there.
Also worth checking: System Settings > General > Login Items may still list a VPN helper set to launch at login, which will recreate the tunnel the next time you restart.
Order matters here: fix the proxy first, then DNS, then the interfaces and services. Changing all of them at once means you will not know which one was actually responsible.
When the Mac is not the cause
The three-stage view also tells you when to stop blaming the Mac:
- Every device on the network fails — the problem is the router or ISP, not your settings
- Only one room is bad — this is usually coverage or congestion, not proxy routing. See Wi-Fi Slow in One Room? Don’t Replace Your Router Yet
- Only one app or service fails — the problem is usually that app, its servers, or its account state
- Public Wi-Fi shows a connection but no internet — check for a captive portal sign-in page before touching DNS or proxies
Frequently asked questions
Why does my Mac have no internet after I disconnect from a VPN? Disconnecting usually removes the tunnel but not the settings the VPN left behind. The system proxy, DNS servers, virtual interfaces, or a still-registered VPN network service can each keep routing traffic somewhere that no longer exists. Because the Wi-Fi link itself is unaffected, the Mac still reports a normal connection.
How do I check the proxy settings on a Mac?
Open System Settings > Network > Wi-Fi > Details > Proxies to see every proxy type — Auto Proxy Discovery, Automatic Proxy Configuration (PAC), Web Proxy (HTTP), Secure Web Proxy (HTTPS), and SOCKS Proxy. For a compact view of the same configuration in the terminal, run scutil --proxy.
Is the macOS firewall blocking my internet? Usually not. The built-in Application Firewall controls incoming connections, so it rarely explains browsing that suddenly stops working. A third-party firewall, network filter, or security product is a more likely cause because those can inspect outbound traffic. On a managed Mac, check with IT before disabling anything.
Do I need to uninstall the VPN to fix this? No. Start by quitting the app completely rather than toggling it off, then clear the stale proxy and DNS settings. Only look at removing a leftover network service or login item if the problem keeps coming back after you restart.
How do I tell whether the problem is my Mac or the network? Ask whether other devices on the same network are affected. If they are, the router or ISP is the source. If only this Mac fails, the fault is in the Mac’s own network path — which is where the proxy, DNS, and interface checks above apply.
Where to go from here
If browsing stopped after a VPN disconnect, inspect the system proxy before changing the router or DNS. A three-stage check then confirms whether the fault stays on the Mac or extends to the LAN or internet path.
If your pages load but crawl in specific rooms, the room-by-room guide separates coverage problems from congestion before you spend money on equipment. For the full manual walkthrough of the “connected but no internet” scenario, see Mac Connected to Wi-Fi but No Internet? Check DNS and Proxy Settings.
To inspect the proxy, VPN route, gateway, and internet path on your Mac, see the WiFi Lens Network Self-Check feature overview or get WiFi Lens Pro. An open-source edition is also available on GitHub. If you need a different kind of network evidence, the Network Analyzer for Mac guide explains when to use Wi-Fi analysis, packet capture, port scanning, or a traffic monitor.
- Download WiFi Lens from the Mac App Store
- View the open-source code on GitHub
- Encountered a network problem or have feedback? Open an issue