iOS Per-App VPN and background email notifications on personal devicesSolved

Participant
Discussion
11 hours ago Aug 31, 2026

We’re looking at using Hexnode for personal iPhones where only work apps should use the company VPN. The goal is to let apps like a managed browser, email app, and an internal app reach company servers without routing personal app traffic through VPN. The main doubt is around background behavior. Can Per-App VPN stay active in the background so the email app keeps checking for new mail and shows notifications automatically? Or does the user need to open the app for the VPN tunnel to start?

Replies (1)

Marked SolutionPending Review
Hexnode Expert
4 hours ago Aug 31, 2026
Marked SolutionPending Review

Per-App VPN on iOS is designed for this type of separation between work and personal traffic.

With Hexnode, the VPN tunnel can be assigned only to selected managed apps. When those managed apps generate network traffic, iOS can bring up the VPN tunnel for that app. Personal apps are not routed through the VPN.

Key points to keep in mind:

1. The target apps must be managed by Hexnode.

2. The VPN client must also be managed on the device.

3. The Per-App VPN configuration is created from Policies > iOS > Network > Per-App VPN.

4. You can configure the tunneling layer, such as App-proxy or Packet-tunnel, depending on the VPN provider and use case.

5. On-demand domain rules can trigger the VPN when specific domains are accessed from supported Apple apps such as Safari, Mail, Contacts, or Calendar.

However, iOS does not allow managed apps to keep a VPN tunnel continuously active in the background just for polling data. The tunnel is generally established when the assigned app or configured domain generates traffic. Because of iOS background execution restrictions, email sync and notification behavior can be limited. In many cases, new messages are fetched when the email app is opened and the VPN tunnel becomes active.

Regards,

Mary Romero

Save