We Put Colitu's VPN Verification to the Test. Here's What Changed.
Good engineering gets stronger when people challenge it.
On October 10, 2026, a DEV Community member, @launchgatecheck, suggested an interesting test for Colitu's VPN connection verification system.
The question was simple but important:
What happens if a VPN handshake succeeds, but the tunnel itself cannot carry traffic? Could the application mistakenly report a working connection?
Rather than speculate, we reproduced the scenario, examined the results, made improvements, and published our findings through Colitu Lab.
The test
We built a controlled environment where a VPN server accepts the handshake but silently drops traffic inside the tunnel, while verification endpoints remain accessible through the normal internet connection.
We also examined automatic fallback between servers, DNS routing, and network changes.
The testing identified three areas requiring improvements.
What we improved
1. Tunnel-bound verification
We identified a case where certain follow-up verification requests could be affected by split-tunneling rules, potentially reporting a successful connection through the wrong route.
We corrected this behavior. Connection checks now use a dedicated, tunnel-bound verification path that cannot be redirected by ordinary routing rules.
2. Network transition recovery
We improved how the Windows application responds when the same Wi-Fi adapter connects to a different network.
Colitu now detects address and gateway changes, invalidates previous verification, and begins reconnecting within seconds.
3. DNS consistency
Our tests also revealed an opportunity to improve DNS handling on one Windows transport path.
We standardized tunnel adapter handling so DNS resolution follows the VPN tunnel across the tested Windows transports.
Released and documented
These improvements are available in Colitu Windows 2.8.4 and Linux 1.4.3, including fixes introduced in earlier releases.
Our published research includes the test methodology, results, technical changes, and testing limitations. Windows was tested on real devices; Linux verification used automated tests and the same fixture logic. Mobile platforms were outside the scope of this investigation.
Thanks to the community
Special thanks to @launchgatecheck for proposing the test scenarios that prompted this investigation.
This is exactly why we believe open technical discussion matters.
At Colitu, constructive criticism is an opportunity to validate assumptions, improve our engineering, and make our results publicly available.
Read the full technical research:
Colitu Lab — Does the connection check really go through the tunnel?
Colitu — Connection Liberty Tunnel
Built for networks that fight back.
Top comments (1)
Some comments may only be visible to logged-in visitors. Sign in to view all comments. Some comments have been hidden by the post's author - find out more