What is double VPN? Two servers, twice the encryption
A double VPN routes your internet traffic through two VPN servers instead of one, encrypting it at each hop. The first server sees your real IP address but not your destination; the second sees your destination but not your real IP. You gain resistance to tracing and pay for it in speed.
Multi-hop, double-hop, VPN chaining, cascading — the name changes with the provider, but the routing trick is the same: your traffic passes through two VPN servers in sequence instead of one. Double VPN is a feature inside some VPN apps, not a separate product you buy, and only a handful of providers offer one. The four covered below all appear in our full VPN rankings.
How a double VPN works
A standard VPN encrypts your traffic and sends it through one server, which swaps your IP address for its own before passing the request to the website. A double VPN inserts a second server into that path and applies encryption at each stage.
The second hop changes who can see what. The first server receives your connection, so it knows your real IP address — but the traffic it forwards is still encrypted for the second server, so it cannot read where you are going. The second server removes the final encryption layer and contacts the website, so it knows your destination — but the connection it sees arrives from the first server, not from you. No single machine in the chain holds both halves of the picture.
That split is the entire point; the names, the marketing, and the speed penalty all follow from it. If the basics are still fuzzy, start with what a VPN is and how it works — everything here builds on it.
| Single VPN | Double VPN | |
|---|---|---|
| VPN servers in the path | 1 | 2 |
| Encryption layers | 1 | 2 |
| Sees your real IP address | The one server | Only the first server |
| Sees your destination | The one server | Only the second server |
| Speed cost | Smaller | Larger — CNET reports up to 50% |
| Best for | Everyday privacy | High-stakes privacy |
What it protects against — and what it doesn’t
The extra hop targets one specific threat: an observer who can watch, compromise, or compel a single VPN server. With one hop, that server briefly holds both your identity and your destination. With two, neither server has the full pair, so tracing traffic back to you requires correlating both ends of the chain.
Three honest limits sit next to that gain.
Both hops usually belong to one company. NordVPN’s Double VPN and Surfshark’s MultiHop run both servers on the provider’s own network. That defends against an attacker who seizes one server; it does nothing against the provider itself. If your worry is what the company logs or hands over, hop count is irrelevant — jurisdiction and independent audits are what protect you, and no-log VPN audits explained covers how to read those.
There is no absolute anonymity. Gizmodo’s guide to the feature concedes the point plainly. Sign in to your email and you have identified yourself to that site, no matter how many servers sit in between. Browser fingerprinting and malware on your device operate outside the tunnel entirely. A double VPN hides your route, not you.
It inherits the app’s weaknesses. A dropped tunnel or a DNS request that slips outside the app fails the same way with two hops as with one. The feature doubles the route, not the software’s discipline — the client app still decides what actually stays inside the tunnel.
How much speed does it cost?
More than a single hop, always. Your traffic travels farther, and every packet is encrypted and decrypted twice. CNET reports that adding the second hop can slow a connection by as much as 50%. Our sources offer no other measured figure, so treat the exact penalty as something to check yourself inside your provider’s refund window.
A single well-chosen server costs far less — does a VPN slow down your internet breaks down where that loss comes from. The practical rule: keep double VPN off for gaming, video calls, and anything live, and switch it on only for the sessions that need it.
Which VPNs offer a double VPN?
| Provider | Feature name | What the sources say |
|---|---|---|
| NordVPN | Double VPN | Routes traffic through two servers and encrypts it twice; listed under Specialty Servers in the app, per TechRadar |
| Surfshark | MultiHop | Routes traffic through two VPN servers and encrypts data twice, per its feature page |
| Proton VPN | Not named in our sources | CNET lists Proton VPN among the providers with double-VPN capability |
| CyberGhost | Not named in our sources | Its privacy hub explains the concept — two servers, a second encryption round, two IP changes — rather than documenting an in-app switch |
NordVPN files Double VPN under Specialty Servers and calls it an advanced security feature. Surfshark brands the same idea MultiHop. Proton VPN appears in CNET’s coverage as offering the capability, though that coverage never names its implementation. CyberGhost publishes an explainer on building a double VPN rather than a feature page for one.
What none of these sources state: which subscription tiers include the feature, how many server pairs each app offers, or which platforms carry it. Those gaps are real. Open the app during the money-back window and confirm the feature exists where you need it before the refund period closes.
Can you chain two separate VPN providers instead?
Yes, and it changes the trust math. A built-in double VPN keeps both hops inside one company’s network, so you are still trusting a single operator with the whole chain. Run two unrelated VPN services at once — the first tunnel carrying the second — and no single company can see both your real IP address and your destination. CyberGhost’s privacy hub explainer covers building this kind of setup by hand.
The costs stack up fast: two subscriptions, two apps that were never designed to cooperate, more to misconfigure, and a second speed penalty on top of the one a single provider’s double VPN already charges. For almost everyone who genuinely needs two hops, the built-in feature is the workable version; the do-it-yourself chain is for people who have decided they cannot put both hops in one company’s hands.
Should you turn it on?
Use a double VPN when:
- Your work makes you a target. CNET and Norton both point to journalists, activists, and whistleblowers — people for whom one compromised server would be a disaster, not an inconvenience.
- You face heavy surveillance or censorship and want no single server holding your identity and destination together.
- You can live with the slowdown as a standing cost of the sessions that need it.
Skip it when:
- Latency shows. Gaming, calls, and live video get worse with every hop.
- Speed is the product. For streaming or large downloads, the second hop buys protection you are not using.
- Your real concern is the provider. Two hops run by a company you distrust are no safer than one — the most private VPNs ranks providers on jurisdiction, logging policy, and audit history instead of feature count.
Frequently asked questions
Frequently asked questions
Is double VPN the same as multi-hop VPN?
Yes. Double VPN, double-hop, multi-hop, VPN chaining, and cascading all describe the same setup: traffic routed through two VPN servers in sequence. Providers pick their own branding — NordVPN calls it Double VPN, Surfshark calls it MultiHop.
Does a double VPN encrypt your data twice?
Yes. Encryption is applied at each hop, so your traffic crosses the first stretch of the chain wrapped in two layers. The first server strips one layer, the second strips the other before passing the request to its destination.
Is a double VPN more secure than a regular VPN?
Against tracing, yes: no single server sees both your real IP address and your destination. It is an advanced feature rather than a default necessity, and it adds nothing against account logins, browser fingerprinting, or malware on your device.
Does a double VPN slow down your internet?
Yes. Traffic travels farther and is encrypted twice, so latency rises and throughput falls compared with a single VPN connection. CNET reports the second hop can cut speeds by as much as 50%.
When should you use a double VPN?
When the stakes are personal. CNET and Norton point to journalists, activists, whistleblowers, and people under heavy surveillance or censorship. For everyday browsing, a single well-run server is enough.
Can a double VPN hide your IP address better?
It makes tracing harder. Each server sees only the hop beside it: the first knows your real IP address but not your destination, and the second knows your destination but only sees traffic arriving from the first server.
Is a double VPN worth it?
For most people, no — the speed cost outweighs the privacy gain for everyday browsing. If your priority is resisting traffic tracing rather than speed, it is one of the few features that genuinely adds a layer.
Sources
- Palo Alto Networks — What is a double VPN? — accessed
- Nym blog — Double VPN — accessed
- Cybernews — What is double VPN — accessed
- NordVPN — Double VPN feature page — accessed
- TechRadar — NordVPN Double VPN — accessed
- Surfshark — MultiHop feature page — accessed
- CyberGhost Privacy Hub — What is double VPN — accessed
- CNET — Understanding the power and pitfalls of double VPNs — accessed
- Norton blog — Double VPN — accessed
- SafetyDetectives — What is a double VPN? — accessed
- Gizmodo — What is double VPN — accessed