Everything You Need to Know About Double VPN in 2020

By Jayden Andrews. March 31, 2020

When it comes to online security, the concept of less is more does not apply. In fact, more is better. This is particularly true for VPNs. We know that VPNs work by encrypting the user’s data as it goes through a secure digital tunnel before going out to the World Wide Web. An effective VPN service should have more advanced encryption technology, more flexible settings, and more security features. This is the concept behind Double VPN.

If you’re familiar with the concept of VPNs, you’ve probably heard of the Double VPN technology. This is not actually a new concept because it has been in use for quite some time. When the VPN service uses double VPN, it simply means that the encrypted data goes through two VPN servers instead of just one. This provides additional protection for the user because it will be harder for the session to be traced back to him or her.

This guide will discuss what double VPN is all about, how it works, when to use and not to use it, its advantages and disadvantages, and which VPN services offer this feature. By the end of this article, you’ll have a thorough understanding of the double VPN technology that would help you make an informed decision.

Top VPNs
Price from:
Price from:
Price from:

What Is a Double VPN and How Does It Work?

Double VPN, also known as double-hop, multi-hop, nested, cascading, or chained VPN, is a type of VPN connection where the internet traffic goes through two VPN servers instead of one. The original double VPN requires just two virtual networks joined together. Today’s double VPN came from that idea. But before we go into the specifics of a double VPN, it is necessary to understand the basic technology behind VPNs or Virtual Private Networks.

A regular VPN encrypts information sent to and received from the public internet to prevent third parties from deciphering the transmitted data. That data is then passed through a secure VPN server in the user’s preferred location. The VPN server masks the user’s real IP address and replaces it with that of a temporary address assigned by the server.

The outgoing data on a regular VPN usually goes through this process:

  • The user’s data is encrypted on the device, such as smartphones, laptops, computers, tablets, and others.
  • The encrypted data is forwarded to the VPN server.
  • The encrypted data is decrypted by the VPN server.
  • The decrypted data is then sent to the destination app, website, or online service.

The incoming data follows a reversed version of this process wherein the data is encrypted on the VPN server and is then decrypted on the user’s device. A double VPN works the same way, except that it adds another secure digital tunnel and another VPN server to the equation. Hence, the name Double VPN.

Using NordVPN, you can filter Double VPN servers:

Try NordVPN risk-free

If your VPN provider normally uses AES 256-bit encryption, switching to a double VPN does not equate to a 512-bit encryption. The level of encryption is not affected, but using a double VPN means that your internet traffic is rerouted, and hopefully encrypted, twice.

There are various types of double VPNs, but the basic idea behind it lies in the use of two encrypted tunnels together. Here is what happens when you use a double VPN:

  • The user’s data is encrypted on the device, such as smartphones, laptops, computers, tablets, and others.
  • The encrypted data is encrypted again on the user’s device.
  • The double-encrypted data is forwarded to the first VPN server.
  • The second layer of the encrypted data is removed by the first VPN server.
  • The original encrypted data is forwarded to the second VPN server where the first layer of encryption is removed and the information is fully decrypted.
  • The decrypted data is then sent to the destination app, website, or online service.

Take note, however, that not all double VPNs offer double encryption, which means that the data is encrypted just once, where it is fully removed after arriving at the first server. From the first server to the second server, the user’s data is completely naked and unprotected. The ideal situation is that the user’s data should be encrypted according to the number of servers it should go through to ensure that it is protected all throughout the process.

Ideally, all your internet traffic should be encrypted and rerouted through these two secure tunnels, consecutively. This is called VPN server cascading, the central idea behind double VPNs. With a double VPN, your actual IP address gets masked twice rather than just once.

Double VPN and Multihop VPN

A multihop VPN is a different version of VPN server cascading which has also become synonymous with double VPN. With a multihop VPN, the user is not restricted to only two simultaneous VPN connections. The user can actually enjoy multiple simultaneous VPN connections.

Based on its name, a multi-hop VPN gets your internet traffic “hopping” through several VPN servers before sending it to the public internet. Instead of just two VPN servers, your traffic can go through three or four servers, where each additional server provides a new layer of encryption and a new IP address.

SurfShark Multihop Servers:

Try Surfshark risk-free

Multihop VPNs can be categorized into two types: the cascade and the nested chain categories.

A cascade type of multihop VPN requires one main VPN service and two or more VPN servers. With every hop, your IP address is masked and a new IP address is assigned to you. Your data is also decrypted, and then re-encrypted as it goes through the whole process.

Another type of multihop VPN is called the nested chain configuration. This type uses two or more different VPN services with different locations. A nested chain multihop VPN provides protection against a VPN provider or server that might be compromised.

Nested chain setups are not offered by individual VPN providers, since it takes more than one VPN service to carry out this process. It needs to be set up by an expert who knows how to run one VPN on top of another.

VPN on a VPN

As mentioned above, a nested chain multihop VPN uses a VPN over another VPN. Actually, you can either use different VPNs for your router and your device, or install one on your device and then run the second VPN on a virtual machine installed on that same device.

Whatever setup you choose, it is recommended that you use two different VPN services for maximum security.

If you want to set up your own VPN on a VPN configuration and create your own version of a double VPN, follow our guide below:


Install a virtual machine on your computer

Download a virtualization tool, such as Hyper-V or Virtual Box, then use it to install another operating system on the virtual machine. You don’t need to install the same operating system for this setup to work.


Install your VPN app on both machines.

Make sure that your VPN provider supports multiple installations because this would count as two devices.


Set up your own double VPN.

Open the VPN installed on your computer and connect to a server in one location. Turn on your virtual machine. If you check your virtual machine’s IP address, you should see that it matches the location of the first server. Next, launch the VPN installed on your virtual machine and select a server from a different country.

You should now have a double VPN. Any traffic that goes out from your virtual machine will go through the first VPN server and then the second VPN server.

Onion Over VPN vs. Double VPN

If you don’t have a VPN but you want to protect your privacy so nobody knows what sites you visit and what IP address you’re using, onion routing is a good option. Onion routing is a technology that ensures protected and anonymous communication over a network.

When you use the onion network, your internet traffic is encrypted multiple times at the beginning of the communication, before being sent through multiple servers called onion routers. Every onion router gets an encryption key that can be used to peel off a layer of encryption from the data before forwarding it to the next router.

When the information gets to its destination server on the public internet, the request is then processed. Messages can also be sent back using the same nodes in the opposite direction. Each onion router encrypts the message until it reaches your computer as a multi-encrypted response. Only your computer has all the keys, so it is the only device that can decrypt the message. All the onion routers in between have no information regarding the message’s content, origin, and destination.

Onion over VPN is a special privacy feature offered by NordVPN. This option sends the user’s traffic through one of NordVPN’s servers and goes though the onion network before exiting to the public internet. You just need to connect to the Onion over VPN server and NordVPN takes care of all the routing needed.

When you connect to a VPN server before connecting to the Onion router, which is popularly known as the Tor network, you get to enjoy all the advantages of the Tor network plus the benefits of using a VPN, particularly the ability to hide your real IP address. This is important because of the completely decentralized nature of the network where anybody can become a node.

This is crucial because monitoring agencies and your internet service provider can easily track if you try to access the Tor network. If you use a VPN while using Tor, you won’t be flagged by the entities monitoring you because they will only see your encrypted traffic going to the VPN server.

It might seem like Onion over VPN works the same as a double VPN, but there are minor differences between these two technologies.

Double VPN encrypts your traffic using the first VPN server before being routed to the second VPN server, where it is decrypted and then re-encrypted before it exits the tunnel.

With Onion over VPN, on the other hand, the VPN encrypts the internet traffic first. Then it goes through multiple layers of encryption before being sent through the onion network. This means that the data you send and receive is protected by several layers of encryption throughout the process.

Advantages of Using a Double VPN

Whether you don’t want anyone snooping in on what you do online or you simply want to protect your data, using a double VPN can give you the protection that you need. Here are some of the benefits of using a double VPN:

  • It protects your anonymity. This is one of the main advantages of double VPN. Government agencies, ISPs, and other entities monitoring your network traffic will only see your connection to the first VPN server. Anything else after that gets masked by the VPN server. They also won’t know the IP address of your destination. Consequently, the next VPN server won’t have any idea about your real IP address since it will be masked by the first VPN server. In case the second VPN server becomes compromised, your traffic won’t be traced back to you.
  • It is useful in evading government censorship. Double VPN bounces off your traffic between different servers located in different countries or regions, making it easier to avoid monitoring by government agencies and any censorship attempts. Double VPN does a great job of confusing whoever is spying on your network. For example, if you’re in a country where censorship is strictly implemented and you want to access restricted websites, you can connect to the US using the first server, then jump to a second server in the UK. Anyone monitoring you from the original country will see you accessing US sites, while those in the UK will see that the traffic is coming from the US.
  • It helps circumvent censorship. If the website or service you are trying to access only allows connections from a domestic IP address, you can connect to a VPN server located in that country to access it, then choose another server from a different country for your exit.
  • It protects you against sophisticated attacks. One specific attack that Double VPN thwarts is the traffic correlation attacks wherein the attacker analyzes the metadata of your incoming and outgoing traffic to reveal your real IP address. Because of the multiple jumps from server to server, your data is protected by layers of encryption to help protect your online identity and anonymity. Every hop means a new IP address, which makes your traffic difficult to track. Another attack that double VPN protects users against is the de-anonymization attack which aims to decipher the users’ identities.


Disadvantages of Using a Double VPN

Using Double VPN is not all about benefits. All these extra layers of protection come at a price. Here are some of the pitfalls of using a Double VPN:

  • Because double VPN connections go through several VPN servers and need to be re-encrypted each time they pass through, they are a bit slower compared to the normal VPN. The more server the data has to go through, the slower the process will be.
  • Double VPN can also be more resource-intensive for your device because of the double encryption and decryption process. Low-powered smartphones or laptops might suffer greater drops in speed or other performance issues as a result.
  • And if you’re using a VPN that offers Double VPN features, you won’t have much freedom in choosing the server you want to connect to. VPNs, like NordVPN, do not allow users to link together the servers or locations that they want. They will have to choose from a preset of servers that are already connected, which can be a hassle for some.

Who Needs a Double VPN?

It is a fact that a double VPN offers additional protection for your identity, personal data, and privacy. But should everyone use it? Though some people find the extra protection quite helpful, there are others who think that it’s a bit overkill.

For the regular internet user, a standard VPN service should be enough for everyday browsing. As long as the VPN has a strong encryption and has a solid line of privacy tools, you should be well-protected.

Here are some of the people who would benefit the most by using a Double VPN:


People who live in a highly-restricted country.

If you live in China or other countries that implement strict internet censorship, tracking, and surveillance, you will need an extra strong VPN to overcome the restrictions. With the double encryption offered by a Double VPN, you make it twice as hard for these entities to track your activities.


People who are in a sensitive profession.

If you’re an activist that promotes freedom of speech or a journalist who wants to protect your sources, a Double VPN will be quite handy in shaking off those who want to know about your real location or other information about your activities. All your communications (emails, messages, video chats) will be encrypted, so you can go about your work without worries.


People who perform competitor’s research.

If you’re in the marketing department and you want to learn what your competitors are doing, using a Double VPN allows you to conduct your research without alerting your subject. Your identity will be completely hidden and even if they notice anything, they won’t be able to trace it back to you.

Double VPN may be useful, but it is more useful in the hands of the right people. If you’re not involved in any sensitive work or you don’t live in a high-restricted country, a regular VPN should do.

VPNs That Offer Double VPN

Not all VPNs offer Double VPN. In fact, only a handful of them offers this feature. So if you’re after the extra protection this technology brings, you need to choose a VPN service that has a built-in Double VPN option.

Here are some of the top VPNs that provide Double VPN features right now:


NordVPN is one of the top-rated VPNs today because of its great balance between speed and security. Plus, it has one of the biggest networks of servers compared to other VPNs in the market today. NordVPN implements a strict no-logs policy and is based in Panama, so it is not required to surrender their user logs.

NordVPN is also one of the few VPN providers that offer a Double VPN feature. This feature is available in their mMacOS, Windows, and Android apps.

If you need an even higher level of online privacy, you can also avail of the Onion Over VPN feature. With the Onion Over VPN option, users can safely access and use the Tor network. This is quite handy if you live or work somewhere with extreme government censorship and surveillance.

Here are the other security features of NordVPN include:

  • Military-grade AES encryption
  • CyberSec feature that blocks malware and malicious ads
  • Automatic kill switch
  • SmartPlay mode for one-click access to video streaming

If you’re not satisfied with any of these services, you can take advantage of NordVPN’s 30-day money-back guarantee.


Surfshark might be relatively new in the VPN industry, but it has already proven itself to be one of the best services so far. Aside from achieving the perfect balance between speed and security features, Surfshark is also known for its ability to support smooth streaming, safe browsing, and easy torrenting. Surfshark currently has 500 servers in 50 countries, but the network is fast expanding so we can expect more servers in the near future.

Surfshark also offers its own version of double VPN, called MultiHop. MultiHop can be accessed from the interface with just a few clicks and it works well on Surfshark’s macOS, Windows, iOS, and Android apps. Most double VPNs greatly affect the speed of your connection, but MultiHop works the other way. It can actually improve your speed.


There is no question that Double VPNs provide several additional layers of protection for your identity, your data, and your privacy. However, it is not for everyone. Double VPNs are suitable for those who need extra protection because of the sensitive nature of their work or because of the country they live in. For users who just want to unblock Netflix or those who want to access a restricted website, a single server VPN from a reliable provider should be enough for your online security needs.

Do you like this post? 1 Star2 Stars3 Stars4 Stars5 Stars