1. Prevent DNS Leaks

Ensure all DNS queries are routed exclusively through the encrypted tunnel using DNS over HTTPS (DoH) or DNS over TLS (DoT). XNEOVPN configurations automatically enforce private upstream DNS resolvers.

2. Use Strict Zero-Log Architecture

Never use providers that log IP addresses, connection timestamps, or bandwidth statistics. XNEOVPN servers run on non-persistent RAM disks where no activity logs are written to physical storage.

3. Enable Kill Switch and Auto-Connect

If the Wi-Fi or cellular connection drops unexpectedly, the client must immediately block unprotected outgoing traffic until the secure tunnel is re-established.