- Transport
- Provider implementation
- Protocol reference
- Tunnel protocol
- Address scope
- Current reference
How the connection works
The provider publishes Lightway documentation and describes its client integrations. The protocol core being available for review is different from every application component being open source. Read the implementation and audit scope separately.
Configuration checkpoints
- Identify the actual ExpressVPN client version and selected transport. A published protocol core is not a complete description of every app component.
- Check the current Lightway repository and the version covered by each audit. Reports for an earlier C implementation do not automatically establish the scope of a later Rust implementation.
- Use the platform instructions for protocol selection and network changes. Verify reconnection and traffic behavior on your own device before relying on a provider performance claim.
Verify the traffic path
- Check IPv4 and IPv6 routes separately. A route for one address family does not demonstrate coverage of the other.
- Check the resolver used by the operating system and by applications that select their own DNS service. A public DNS lookup on this site does not test your device for DNS leaks.
- Observe a controlled disconnect on your own device. Protocol support does not establish a client kill switch or application-specific routing policy.
Diagnose a connection problem
Separate endpoint reachability, authentication, route selection and DNS resolution. Record the client version and the exact error; change one setting at a time. A handshake with no working traffic often needs route or resolver investigation, while an authentication error needs credentials or certificate checks.
Scope and limitations
Provider performance claims require independent measurements in the relevant network. Protocol design alone does not establish a universal speed winner or uninterrupted roaming.
This page explains a mechanism and a verification approach. It contains no original speed, regional-access or leak measurements. Throughput depends on the implementation, device, path and server; a protocol name cannot identify a universal winner.