We review products independently, but we may earn commissions if you make a purchase using affiliate links on our website. Also note that we are not antivirus software; we only provide information about some products.

Intego VPN review · checked August 7, 2026

Intego VPN Review: Privacy, Speed and Connection Fixes

The integrated ONE VPN is simple, current and useful for ordinary Mac travel—but its privacy claim deserves more evidence than a badge. The separate Privacy Protection app has a deeper toolbox and a different protocol/account model. We keep them apart, show what is actually documented, and fix each failure from a clean disconnected baseline.

ONE Complete onlyLightway ≠ OpenVPN/WireGuardNo invented speed resultNo public Intego audit found

Quick verdict: Intego ONE VPN is a convenient fit for a Complete subscriber who wants a Mac-focused tunnel, nearby/city locations, Automatic or Lightway UDP/TCP and a kill switch inside the same suite. It isn't our high-assurance privacy pick: Intego says it keeps zero/no activity logs, but its general policy permits broad service telemetry and we found no current public VPN-specific logging table or independent audit for this app. The separate Privacy Protection client adds OpenVPN/WireGuard, split tunneling, MACE, multi-hop and port forwarding—but those features and credentials can't be assumed inside ONE.

Intego VPN verdict: convenient in ONE, incomplete for high-assurance privacy

ReaderFitWhyWhat to verify
ONE Complete Mac userGood convenience fitIntegrated locations, Lightway and kill switchRenewal cost and privacy evidence
Public-Wi-Fi travelerUseful connection protectionWhole-device tunnel and auto/fast protocol choicesKill Switch behavior before travel
Privacy-critical userCompare firstNo public Intego-specific audit foundLogging/retention, infrastructure and audit scope
Advanced separate-client userPotentially usefulPrivacy Protection has deeper routing controlsSeparate billing, credentials and platform support
Streaming-only buyerDon't buy on promise aloneVPN IP blocks change continuouslyTest during refund window; respect terms/law

The convenience case is straightforward. ONE Complete places VPN beside Antivirus, Firewall and SmartClean, and the current ONE VPN guide documents locations, latency, Lightway choices and Kill Switch. A person already paying for Complete can protect an airport or hotel connection without installing another dashboard.

The trust case is weaker. The product page makes a clear no-activity-logging promise, but a VPN asks the provider—not only the ISP—to become the connection trust point. We want a VPN-specific policy, retention table, operating entity and repeatable independent audit. Those weren't present in the current official materials we found.

We didn't run a current paid Intego tunnel on this local build Mac, so this review doesn't claim a measured speed loss, leak-test pass, server count or streaming win. That omission is intentional. A useful review separates documented capability, policy evidence and real measurements instead of manufacturing a benchmark.

There are two Intego VPN branches—and their menus aren't interchangeable

Selected ONE VPN and separate Privacy Protection features divided into distinct protocol and troubleshooting branches
Editorial feature-ownership map, not a literal Intego screen and not a complete feature checklist. Shared functions such as locations and a kill switch exist in both branches; the diagram highlights the controls readers most often mix up.

ONE VPN is the integrated module in ONE Complete. Current documentation lists Automatic, Lightway UDP and Lightway TCP. The separate Intego Privacy Protection application predates ONE and supports macOS/Windows, its own username/password and a much larger settings surface built around OpenVPN/WireGuard, MACE, split tunnel, multi-hop, custom DNS, MTU and port forwarding.

An old article can be freshly updated and still describe the separate client. Product name, executable and protocol list are the reliable branch markers. If your screen says Lightway, follow ONE. If it offers OpenVPN/WireGuard, MACE or Multi-Hop, follow Privacy Protection. Don't “fix” a missing ONE option by installing a legacy network filter without understanding the subscription and conflict.

EvidenceONE VPNPrivacy Protection
Where it livesIntegrated ONE VPN dashboardSeparate menu-bar/application client
Current protocolsAutomatic, Lightway UDP, Lightway TCPOpenVPN and WireGuard; UDP/TCP options
CredentialsONE account + Complete entitlementDedicated VPN username/password
Advanced features documentedLocations, latency, Kill SwitchMACE, split tunnel, multi-hop, port forwarding, custom DNS
Billing riskComplete tier renewalSeparate add-on renewal may persist

ONE Complete includes the VPN; Essential and Advanced don't

Intego’s current ladder puts Antivirus and Firewall in Essential, adds SmartClean in Advanced, and adds VPN in Complete. The word “ONE” in the installer doesn't grant every module. If VPN is absent or locked, check the signed-in subscription before reinstalling network extensions.

Our Intego pricing and renewal guide records the full current tier/term/Mac-count table. Complete carries the highest published renewal, so compare its incremental cost with a specialist VPN you'd otherwise buy. Don't treat a first-term discount as the ongoing VPN price.

Migration adds another trap. Intego says an older separately purchased Privacy Protection subscription can continue after X9 is upgraded to ONE. ONE Complete and Privacy Protection may therefore overlap while billing separately. Inventory both account views, renewal dates and devices before deciding which client remains.

ONE seats are Mac seats. Don't assume a three-Mac Complete plan grants three Windows/iPhone/Android installations because the separate Privacy Protection product historically supported other platforms. The ONE versus X9 guide owns the wider migration map.

“Zero logs” is an Intego claim; we didn't find an Intego-specific public audit

The current Intego VPN product page says “Zero logs policy” and “No activity logging,” then narrows the promise by saying it never records browsing history. That's a meaningful public commitment. It isn't the same evidence as an independent examination of servers, authentication systems, support tools and retention controls.

Intego’s general Privacy Policy, effective November 17, 2025, says the Services may automatically collect IP address, access dates/times, hardware/software and device information, unique identifiers, crash data, pages engaged with, product usage/diagnostics and approximate location derived from IP. The policy covers Intego Services generally; it doesn't state that browsing destinations inside the VPN tunnel are recorded. Calling that list proof of traffic logging would be inaccurate.

The real gap is specificity. We didn't find a current VPN-only table explaining connection metadata fields, retention windows, diagnostic opt-ins, server/operator entities, legal-request handling or deletion. Nor did we find a named audit report whose scope explicitly covers ONE VPN or Privacy Protection. An audit for another Kape-owned brand can't be inherited by association.

Kape’s own investor site lists Intego among its brands. Ownership is relevant to the trust model, but it isn't a verdict by itself. A privacy-critical buyer should ask Intego who operates the VPN infrastructure, which jurisdiction/contracts govern it, what session data exists, how long it remains, whether diagnostic logs are optional, and where the most recent independent assurance report can be read.

StatementEvidence foundEditorial status
No browsing-history/activity loggingCurrent official product claimVendor-asserted
General service telemetryCurrent Privacy Policy categoriesDisclosed, not equivalent to tunnel history
VPN metadata retention tableNot found in current official materials reviewedAsk before high-assurance use
Independent Intego no-logs auditNo named current report foundNot independently verified
OwnershipKape investor materials list IntegoRelevant context, not proof of behavior

A VPN moves trust and hides the route; it doesn't make you anonymous

The tunnel encrypts traffic between the Mac and VPN server, and destinations normally see the server IP instead of the home/hotel IP. That helps against local-network snooping and limits what the ISP can see about ordinary destination traffic. The ISP can still see that the device talks to a VPN endpoint plus timing and volume, while the VPN provider becomes the next trust point.

Cookies, signed-in accounts, browser fingerprinting, ad identifiers and information typed into a website can still identify you. A VPN doesn't remove malware, stop phishing, make a reused password safe or undo tracking performed inside a logged-in Google/Meta/bank session. Intego’s own newer location copy sensibly says a VPN improves connection privacy but doesn't make a user anonymous.

Keep the division of labor clear: VirusBarrier/ONE Antivirus handles malicious files, NetBarrier/ONE Firewall handles connection policy, a password manager/passkeys protect accounts, and the VPN protects the route to its server. Complete bundles several controls; it doesn't make them substitutes.

ONE protocol choice: Automatic first, Lightway UDP for speed, TCP for difficult networks

The current ONE protocol article, illustrated with ONE 1.3.2, requires disconnecting before the change. Automatic selects a suitable protocol for the current network. Intego describes Lightway UDP as the speed-and-security option and Lightway TCP as more reliable on some networks but slower; both are described as having post-quantum protection.

Start with Automatic. If a call, stream or download is slow but stable, compare UDP on the same nearby server. If the tunnel can't establish, repeatedly drops or a restrictive network interferes with UDP, compare TCP. Change one variable, reconnect and repeat the same action—switching server and protocol together destroys the comparison.

Don't look for WireGuard in current ONE instructions. It belongs to separate Privacy Protection documentation, where OpenVPN, WireGuard, UDP/TCP, remote/local port and MTU controls exist. That client can solve a different class of restriction, but its complexity and network extensions aren't evidence that ONE is missing or broken.

Kill Switch is valuable—and the first suspect when disconnect leaves no Internet

The current ONE Kill Switch guide says it stops all Internet traffic when the VPN unexpectedly disconnects and takes effect immediately without restart. Test this intentionally before travel: connect, enable Kill Switch, interrupt the tunnel, confirm ordinary traffic stops, reconnect and confirm traffic resumes.

If the app says disconnected and the Mac remains offline, check the switch before rewriting DNS. The block may be the feature working as designed. If the switch is off or reconnection doesn't restore traffic, Intego says DNS may not have reset; reconnect Wi-Fi/Ethernet, then restart if necessary.

Encrypted DNS is part of current marketing, while the separate client exposes VPN DNS, existing device DNS or custom DNS. Avoid casual custom-DNS changes during a connection incident. Record the working value first and use one resolver path at a time; a DNS failure can make hostnames appear offline while the underlying tunnel still carries packets.

Choose a location for latency and policy—not a giant server-count badge

ONE shows recent, recommended and favorite locations, country entries, city-specific choices where available and latency. Use Recommended or a physically close low-latency location for everyday work. A farther country increases distance and may change content, tax, banking or fraud checks even when raw throughput remains acceptable.

We don't publish the old “25,196 servers/77 countries” number as current ONE coverage. It appears on a separate legacy/origin Privacy Protection page, while the current primary VPN page says only global servers. Count physical/virtual locations in the actual subscribed client on the check date if that number matters.

A server that works today can be congested or blocked tomorrow. Record location and latency, try several appropriate entries, and keep a nearby favorite. Don't interpret a CAPTCHA, bank challenge or streaming block as proof that encryption failed; shared VPN addresses are intentionally visible to destinations.

Intego VPN speed: measure the delta; don't borrow somebody else’s percentage

A defensible speed test starts with at least three disconnected runs and three connected runs using the same Mac, Ethernet/Wi-Fi, test service, server, protocol and short time window. Report median latency, download and upload plus the absolute baseline. A 20% loss from 1 Gbps and from 20 Mbps create very different experiences.

Intego’s June 2026 ONE slow-speed guide identifies base connection, Ethernet/Wi-Fi, ISP path, server distance and device capacity, then recommends update, nearby location and protocol cycling. That sequence is sound. It doesn't establish a universal 3% or “no slowdown” result.

RunServer/protocolRecordInterpretation
Baseline ×3VPN disconnectedLatency, download, upload, packet lossInternet ceiling before VPN
Recommended ×3Same nearby server, AutomaticSame metrics and taskEveryday default delta
UDP ×3Same server, Lightway UDPMedian and stabilitySpeed-oriented comparison
TCP ×3Same server, Lightway TCPMedian and reconnect behaviorRestrictive/unstable network comparison

Repeat at a second time if congestion is suspected. A single browser speed test can't measure reconnect reliability, long video calls, battery cost or overnight stability. Keep those as separate observations instead of compressing everything into one score.

Streaming and site access can work, but no location is a permanent guarantee

Streaming platforms and banks can block shared VPN addresses, compare account region with IP location, read cookies or demand extra verification. Intego’s separate-client support guide recommends appropriate/streaming locations, another protocol and a fresh browser/app cache; it also says multi-hop/obfuscation may reduce speed. These are troubleshooting options, not a contractual unblocking guarantee.

Test the service you actually pay for during the refund window. Use an allowed region, respect local law and the service terms, and don't buy on an old screenshot. If access fails, rotate several correct locations, change one protocol, reopen the app/private browser and stop if the service forbids the route.

CAPTCHA frequency and email/bank blocks are common side effects of shared egress reputation. Split tunneling in separate Privacy Protection can route a chosen app outside the VPN, but that app then loses tunnel protection. ONE doesn't currently document that same control, so don't promise it as the fix in the integrated module.

Feature review: ONE favors simplicity; Privacy Protection favors control

ONE documents the essentials most people will touch: fast connect/disconnect, selected location/IP, locations and latency, Automatic/Lightway protocols and Kill Switch. The separate Privacy Protection guide exposes a broader technical surface.

FeatureONE VPN current docsPrivacy Protection docsRisk/benefit
Kill switchYesYesPrevents fallback leakage; can explain no-Internet state
Split tunnelNot found in current ONE guideApps/IP exclusionsRestores compatibility but bypasses encryption
MACENot found in current ONE guideDNS domain blockingBlocks some ads/malware domains; can block a whole site
Multi-hop/obfuscationNot found in current ONE guideDocumentedMore routing privacy/compatibility; usually slower
Port forwardingNot found in current ONE guideSupported locations onlySpecialized inbound reachability; exposure risk
Allow LAN/custom DNSNot documented in current ONE guideDocumentedUseful for local devices/control; configuration risk

“Not found” is deliberate wording. It means the reviewed current ONE guide doesn't establish the feature, not that future versions can never add it. Check the installed build and current release notes before relying on either conclusion.

Invalid login usually means the wrong account model, not a broken tunnel

ONE uses the Intego account and needs the Complete entitlement. Verify the signed-in email, plan, renewal/expiry and device, then synchronize the account. Don't paste an X9 serial number or legacy VPN username into a ONE account field.

The separate Privacy Protection client can use a dedicated VPN username and password retrievable from the Intego account. Its current invalid-login article says bad credentials trigger that specific error. Reset the VPN credential, then update it on each client; don't confuse it with the website account password.

If a migration created both products, identify which subscription owns the client before resetting anything. The Intego account and devices guide covers ONE accounts, X9 serials, legacy seats and transfer evidence in detail.

Intego VPN can't connect or keeps disconnecting: test server, protocol, network and filters

Prove the base Internet first, update the correct client and try a geographically close second server. Disconnect, then cycle only that branch’s protocol: Automatic/Lightway UDP/Lightway TCP in ONE; OpenVPN/WireGuard and its connection controls in Privacy Protection. Test a second network as evidence—if home Wi-Fi fails and phone hotspot works, the local router/ISP path matters.

Temporarily isolate a conflicting third-party network/security filter only long enough to reproduce once, then restore it. Create a narrow documented exception for the exact client/service rather than lowering the whole security level. Our NetBarrier blocked-app guide explains application/direction/port scope.

ONE’s connected-but-no-browsing page mentions UDP ports 1194–1204 while the current ONE protocol page lists Lightway choices. We treat that as version/context ambiguity, not a universal firewall recipe. Don't open that range inbound or system-wide; ask Intego which executable, direction and current protocol requires it on your exact build.

Connected but can't browse: separate server, packet size, browser, proxy and firewall

Disconnect and open a normal site. If that also fails, the base connection owns the incident. If it works, reconnect to a nearby different server, change the correct protocol and try a second browser. A browser-only failure points toward cache, extension, proxy or site handling rather than a dead tunnel.

Separate Privacy Protection exposes MTU/Small Packets and alternate OpenVPN/WireGuard settings; ONE’s current simple guide doesn't document the same menu. Small packets can help a path that drops larger VPN packets, but don't invent the control in ONE. Record the client before applying it.

Intego support suggests turning proxies off. On a personal unmanaged network, a short comparison can isolate a stale proxy. On work, school or managed Macs, the proxy may be mandatory: compare with the administrator-approved baseline and restore it after the test. Likewise, a third-party firewall exception must be narrow and outbound unless the vendor proves otherwise.

Disconnected but no Internet: check Kill Switch, then recover the network/DNS state

If Kill Switch is enabled, reconnecting the VPN should restore the protected route; disabling the switch temporarily can prove that it owns the block. Don't leave it off automatically—decide whether fallback traffic is acceptable for the use case and retest the expected failure behavior.

Intego’s July 22 post-disconnect article says DNS may fail to reset. Its safe sequence is to toggle Wi-Fi off/on or unplug/replug Ethernet, then restart the Mac if the connection remains down. That's preferable to copying destructive network commands from an old forum.

If the restart recovers access repeatedly, capture the app/macOS versions, transport, server, protocol, Kill Switch state and errors before reinstalling. A repeatable cleanup failure after disconnect is a support-quality bug report, not a reason to keep resetting DNS by hand.

Split tunneling, MACE, LAN, Private Relay and network filters belong to the separate client

Privacy Protection can exclude selected apps/IPs from the tunnel. That can restore banking, printer or low-latency traffic, but excluded data uses the ordinary connection and public IP. Its current split-tunneling article requires additional network/proxy approval on Sequoia; Mojave/Catalina support is restricted on newer client builds.

MACE blocks known advertising/malware domains at DNS level and can block an entire site when an embedded advertising domain is part of the user flow. Disable it for one controlled test rather than abandoning the VPN. Allow LAN can restore local-device access; verify the network is trusted first.

iCloud Private Relay can conflict with Privacy Protection. Intego recommends disabling Private Relay during a conflict because it protects Safari’s route rather than all device traffic. Record the before/after state, and don't describe Private Relay as a full VPN replacement.

Port forwarding and multi-hop are advanced. Forward only the assigned port for an application that genuinely needs inbound reachability; don't use it as a generic speed boost. Multi-hop/obfuscation can help a restrictive route but adds latency and another moving part.

One-hour Intego VPN diagnostic workflow

  1. Identify the VPN branch. Confirm whether you use the VPN inside Intego ONE Complete or the separate Intego Privacy Protection application; record the app version and don't apply the other branch's protocols or credentials.
  2. Establish a disconnected baseline. Disconnect the VPN, verify ordinary browsing, record Wi-Fi or Ethernet, run repeatable latency/download/upload tests and note whether the fault exists before the tunnel starts.
  3. Check entitlement and account. For ONE, verify that the signed-in subscription is Complete and synchronize the account; for separate Privacy Protection, retrieve the dedicated VPN username and reset that credential if login is invalid.
  4. Update before changing network policy. Install the current ONE or Privacy Protection version from the authenticated Intego route, then restart only when the installer or network-extension change requires it.
  5. Choose a nearby low-latency location. Start with Recommended or a geographically close server, record the location and latency, reconnect and repeat the same action before rotating through more locations.
  6. Change only a protocol at a time. Disconnect first; in ONE test Automatic, Lightway UDP and Lightway TCP, while separate Privacy Protection uses its own OpenVPN or WireGuard controls; never combine those menus.
  7. Interpret no-Internet states. If connected but browsing fails, test another browser/server/protocol and inspect firewall or approved proxy context; if disconnected and offline, check Kill Switch, reconnect the network, then restart if DNS didn't recover.
  8. Test optional filters deliberately. On separate Privacy Protection, isolate MACE, custom DNS, split tunnel, multi-hop, Allow LAN and port forwarding one at a time; preserve managed proxy and network-filter requirements.
  9. Retest performance fairly. Use the same server, protocol, test endpoint and time window for multiple baseline and VPN runs; report median latency/download/upload and don't claim a universal speed percentage from one result.
  10. Reset or reinstall last. Preserve settings and logs, use the branch-specific reset or official uninstall route only after simpler evidence-led tests, then submit a sanitized support packet if the failure returns.

Each step preserves a comparison. The baseline answers whether the tunnel owns the failure; the branch decides which credentials and protocols exist; repeated measurements prevent one congested server from becoming a product-wide verdict. Reset/reinstall comes last because it erases the state needed to explain the bug.

Reset, reinstall and support: preserve settings and sanitize logs first

ONE and separate Privacy Protection have different reset/uninstall routes. Follow the current official path for the installed executable and use the authenticated account download. Preserve favorites, protocol, Kill Switch, DNS, split-tunnel exclusions, MACE/multi-hop/port settings and screenshots before removal.

Separate Privacy Protection can generate debug logs for troubleshooting. The guide describes them as connectivity/functionality rather than traffic logs, but inspect filenames/paths and remove unrelated sensitive context before sharing. Never paste passwords, VPN credentials, serials, cookies or private browsing content into a ticket.

A useful support packet includes product branch/version, macOS version, subscription state, Wi-Fi/Ethernet, ISP/network type, server and shown latency, protocol, Kill Switch, exact error/time, disconnected baseline, connected result, whether another network works, optional-feature state and the smallest reproduction. If the problem repeats after clean install, send that evidence instead of performing another unrecorded reset.

Intego VPN review and troubleshooting FAQ

Is Intego VPN included with Intego ONE?

The integrated VPN is included with Intego ONE Complete. Essential and Advanced don't include it. A separately purchased Intego Privacy Protection subscription is a different product and can continue billing independently, so audit both the ONE plan and any legacy VPN renewal.

Is Intego VPN the same as Intego Privacy Protection?

No. ONE VPN is integrated into the current ONE Complete app and its current documentation lists Automatic, Lightway UDP and Lightway TCP. Privacy Protection is a separate macOS/Windows VPN client with separate credentials and documentation for OpenVPN/WireGuard, split tunneling, MACE, multi-hop and port forwarding. Don't merge their menus or feature lists.

Does Intego VPN keep logs?

Intego markets a zero-logs/no-activity-logging policy and says it doesn't record browsing history. Its general Privacy Policy also says the Services may collect IP address, access times, device identifiers, crash and product-usage data. That doesn't prove VPN traffic logging, but we found no VPN-specific retention table or current public independent audit for this app, so the no-logs claim remains vendor-asserted rather than independently verified.

Has Intego VPN passed an independent no-logs audit?

We didn't find a current named public audit or downloadable assurance report specifically covering Intego ONE VPN or Intego Privacy Protection infrastructure and no-logs controls. Audits of other Kape-owned VPN brands don't automatically apply to Intego. Privacy-critical buyers should ask Intego for the exact audit scope and report.

Which Intego ONE VPN protocol should I use?

Start with Automatic. Lightway UDP is the vendor's speed-oriented option; Lightway TCP is usually the better test on a network where UDP is blocked or unstable, though it can be slower. Disconnect before changing the protocol, then compare the same server and task. Separate Privacy Protection uses a different OpenVPN/WireGuard workflow.

Why is Intego VPN connected but the Internet doesn't work?

First disconnect the VPN and prove the base connection. If browsing returns, update the correct client, try a nearby server, change only the matching protocol, test another browser and inspect third-party firewall or approved proxy rules. Don't open a UDP range or disable managed proxy settings globally from a generic instruction.

Why do I have no Internet after disconnecting Intego VPN?

Check whether Kill Switch is still enforcing its intended all-traffic block. Intego also says DNS may not reset after disconnect: reconnect Wi-Fi or Ethernet, then restart the Mac if necessary. If the problem remains, preserve the macOS version, connection type, errors and whether Internet worked before the VPN, then contact support.

How can I make Intego VPN faster?

Measure the disconnected baseline, update the client, use Ethernet where practical, choose a nearby low-latency location and compare protocols one at a time. For ONE, test Automatic, Lightway UDP and Lightway TCP. Report medians from repeated tests; distance, ISP path, Wi-Fi quality, server load and device capacity mean no single speed-loss percentage applies to everyone.

Does Intego VPN work with streaming services?

It may, but access isn't guaranteed. Streaming providers can block shared VPN addresses and change detection without notice. Try the correct region, several appropriate locations, another protocol and a fresh browser/app session, while respecting the service's terms and local law. We don't claim current unblocking without controlled tests.

What should I do when Intego VPN says invalid login?

First identify the branch. ONE uses the signed-in ONE account and requires the Complete entitlement; synchronize the account if the module is missing. The separate Privacy Protection client can use a dedicated VPN username and password retrievable from the Intego account. Reset that VPN credential rather than repeatedly entering an X9 serial number or ONE password.

Bottom line: ONE VPN is easy to use; privacy proof remains the missing feature

ONE Complete makes a practical Mac travel VPN: location choice, Lightway and Kill Switch are clear, and the same suite owns antivirus/firewall. Separate Privacy Protection offers much more control, but it's a different client, credential set and potentially separate renewal.

Use the tunnel for connection privacy, not anonymity. Measure speed from your own baseline, treat streaming as changeable, and fix connection failures inside the correct branch. For high-assurance privacy, wait for or request a VPN-specific retention disclosure and independently verifiable audit; a zero-logs badge should start the evidence review, not end it.