When you set up a VPN on Windows for the first time, what usually trips people up isn't the technology — it's not knowing where to click next. This Windows VPN guide follows the real order of operations: get the client, import your subscription link, pick a route, confirm the connection is live, and enable auto-start. Every step spells out what to click and what you should see, so you can follow along and get connected.
- 120+Countries and regions
- 240+Global routes
- UnlimitedDevices online at once
- 7 daysMoney-back guarantee
The walkthrough below uses the VPNDQ Windows client. Other platforms label their menus a little differently, but the order of steps is the same — just follow the same logic.
Before You Start: Account and System Prep
The whole process needs just two things: a working account and a Windows PC with a normal internet connection. No email address is required to sign up — a username and password are enough. Payment supports Alipay, WeChat Pay, and USDT. There are two billing options, a monthly plan and a data pack, so pick whichever fits your usage: monthly plans start at ¥9.9 with 60GB of data, and data packs start at ¥158 and never expire.
- Account: a username and password — no email address needed. Set a unique password here rather than reusing one from another site.
- Client: download it only from the official download page; the Windows build runs on Windows10 and Windows 11 desktops.
- Network: installing and signing in the first time needs a working internet connection on your machine. If your company or campus network uses its own proxy settings, first confirm in your browser that ordinary web pages load.
- Subscription link: copy it after signing in to the user panel — you'll need it in step three, so make sure you can log in to the panel first.
Step 1: Get and Install the Windows Client
Open the site's download page, pick Windows from the platform list, and download the installer. Once it's done, double-click the file and follow the wizard — no command line needed at any point.
- Go to the download page, choose the Windows build, and wait for the installer to finish downloading.
- Double-click the installer, choose an install folder, and click Next until it finishes. If Windows shows the blue SmartScreen warning, click More info → Run anyway.
- Launch the client once installation finishes. Its icon appears in the system tray (under the small arrow next to the clock in the bottom-right corner) — double-click it any time to bring up the main window.
- On first launch the client will say you have no subscription yet and the server list will be empty — that's expected. Just import your subscription in the next step.
Get the installer only from the official download page
Installers repackaged by third-party sites may have altered settings or bundled extra components, which makes problems hard to trace.
Step 2: Import the Subscription Link
The subscription link is an address the panel generates for your account; it contains the server list, protocol settings, and ports. Once imported, the client pulls in every server automatically. When servers change, just refresh the subscription — no manual edits to any settings.
- Sign in to the user panel, find your subscription info, and copy the address that starts with https — be careful not to miss any characters at the end.
- Open the client, switch to the Subscription or Servers tab, and click Add Subscription.
- Paste the link into the field, leave the subscription name as it is, and save.
- Click Update Subscription and wait a few seconds — the server list appears, grouped by region.
- Check that the number of servers and the regions match what the panel shows. If the list is empty, the link was probably copied incompletely — copy it again and retry.
| Comparison | Import a subscription link | Add servers manually |
|---|---|---|
| What you enter | A single link | Server address, port, protocol settings, password or UUID |
| Server updates | Refreshes automatically when the subscription is pulled again | You edit them by hand every time you switch servers |
| Room for error | Low — the panel supplies the settings | Easy to mistype a port or key, and hard to diagnose when it won't connect |
| Best for | Everyday use, syncing across devices | Temporarily testing a single server |
Your subscription link is as sensitive as account credentials
Don't forward it to anyone or post it on public pages or in code repositories. If you suspect it has leaked, change your account password first, then go back to the panel, copy the subscription address again, and import it into the client.
Step 3: Choose a Route and Routing Rules
Within one region, the server list often holds several routes, and the names may carry labels like Direct, Relay, or IEPL. They all reach the same internet; the difference is how your traffic travels once it leaves your machine, and how steady it stays during peak hours.
| Route type | Traffic path | Traits | Best for |
|---|---|---|---|
| Direct | Your machine connects straight to an overseas server | Simplest to set up; speed follows the ups and downs of the international gateway | Quick lookups, browsing pages |
| Relay | Connects to a relay entry point first, then heads overseas | Uses optimized routing; steadier than Direct at peak hours | Everyday video, long sessions online |
| IEPL dedicated line | Runs over an international Ethernet private line | Skips the public international gateway, so latency and packet loss stay steadier | Video meetings, online classes, cross-border work |
The priciest route isn't automatically the best one — match it to the job. For occasional lookups, Direct is plenty. If you stream video every day, pick Relay. For anything sensitive to stability and latency, switch to an IEPL dedicated line. When a region has several routes, connect to each once, see which loads faster, and set that one as your default.
Routing rules: which traffic uses the route and which doesn't
Clients usually offer three routing modes: Rule, Global, and Direct. Rule mode consults a built-in ruleset — sites and apps in mainland China connect directly, while overseas domains go through the route. Global mode sends all traffic through the route, which helps with obscure sites the ruleset doesn't cover. Direct mode is effectively the proxy switched off, handy for comparing before and after you connect. For everyday use, stay in Rule mode:
- Banking and video apps in mainland China use your local connection, so nothing takes a detour and pages load faster.
- Overseas sites and tools go through the route, keeping your exit IP in one consistent region.
- For the occasional app that needs separate handling, use per-app proxy settings: set a mainland China client to Direct and let everything else go through the route.
Let the client choose the protocol
The subscription already carries the protocol settings, and the client picks the right one per server after import — no manual choosing. The common ones are Shadowsocks, VMess, Trojan, VLESS, Hysteria2, and TUIC: Shadowsocks is lightweight with little overhead; VMess and VLESS expose finer settings and, with TLS, look much like ordinary HTTPS traffic; Trojan runs straight over standard TLS ports; Hysteria2 and TUIC are built on QUIC and deliver better throughput on lossy networks, though they may not suit networks that throttle UDP hard. All of this comes from the subscription — in the client you only pick a region and a route.
Step 4: Confirm the Connection Is Really Working
The client showing Connected only means the local proxy process started — it doesn't prove all your traffic is using the route. A one-minute, three-part check beats disconnecting and reconnecting over and over.
Signs the connection is working
- ✅ Open the site's My IP page: the exit IP matches the region of the route you picked.
- ✅ Refresh twice: the exit IP stays in the same region instead of snapping back to your local ISP.
- ✅ DNS lookups resolve on the route's side, not through your local broadband provider.
- ✅ The live traffic figures in the client keep moving and change clearly as you load pages.
Signs your traffic isn't using the route
- ❌ The exit IP is still your local ISP's address, meaning traffic never entered the route.
- ❌ Only your browser can reach overseas sites while desktop apps (cloud drives, games, dev tools) still use the local network — most likely system-proxy mode isn't capturing all traffic. Switch to virtual network adapter mode and try again.
- ❌ After disconnecting, lookups still resolve to the route's side — usually the local DNS cache just hasn't been flushed.
- ❌ It says Connected but no site opens: switch to another route first, then check whether your security software is blocking the virtual network adapter.
For anything DNS-related, flush the local cache first and test again:
ipconfig /flushdns
ipconfig /displaydns
When you want finer control, use per-app proxy settings to split programs into two groups: those that must use the route (browsers, overseas tools) and those that must connect directly (mainland China banking clients, LAN device admin pages). Per-app rules work by process, use less data than Global mode, and make it easier to tell which group of programs is causing trouble.
Step 5: Set Up Auto-Start and Daily Upkeep
On a computer you use every day, the easiest setup is to let the client start with the system: it connects to your default route on boot, with no clicking each time. Menu names vary slightly between versions — just look for the keywords.
- Open the client settings and find the General or System section.
- Turn on Launch at startup.
- Turn on Auto-connect on launch and choose a default server or policy group.
- If the client offers Auto-reconnect, turn that on too: it recovers after you switch from Wi-Fi to Ethernet or wake the machine from sleep.
- Reboot once to verify: the tray icon appears after you log in and turns to Connected within seconds.
If it doesn't start on boot, open Windows Settings → Apps → Startup and make sure the client is enabled. Some security suites also block startup items, so you may need to allow it manually.
Three small upkeep habits
- Subscription updates: turn on automatic subscription updates in settings so the client pulls the latest servers on a schedule. Update manually before switching regions so you don't land on an entry point that has already gone offline.
- Data and plans: monthly plans reset their data each month, data packs never expire, and your remaining data is right on the panel home page. For everyday browsing and some video, the ¥9.9 60GB monthly plan is usually enough; if you download a lot or watch 4K, a data pack is the simpler choice.
- Multiple devices and refunds: one account can be online on unlimited devices at once, with clients for Windows, macOS, iOS, Android, and Linux. Moving to a new computer? Install the client and import the subscription link once more. If it isn't right for you, there's a 7-day money-back guarantee.
Common Troubleshooting
The client still says Not connected and the server list is empty?
Go back to the Subscription tab and click Update Subscription once to see whether servers appear. If it's still empty, copy the subscription link again and watch for missing characters. If the link is fine but the update fails, try a different network — some company or campus networks block subscription requests.
Connected, but some sites won't load?
Switch the routing mode to Global temporarily. If the site opens in Global, your rules were sending that domain direct — switch back to Rule mode and change it to use the route in per-app or custom rules. If it won't open in Global either, try another route and flush the DNS cache again.
Auto-start is on, but it doesn't connect after a reboot?
Open Windows Settings → Apps → Startup and confirm the client is enabled, then check your security software's startup manager and allow it. Reboot once to verify — the normal result is the tray icon appearing and switching to Connected within seconds.
New computer — do I need to buy another plan?
No. Install the client on the new machine, sign in to the panel, copy the subscription link, and import it once. One account can be online on unlimited devices, so you don't need to sign out on the old computer.
Summary
The whole process comes down to five steps: get the client, import the subscription link, pick a route, check the exit IP and DNS, and turn on auto-start. Once you've done those five the first time, day-to-day use barely requires opening the client — it starts with the system and connects to your default route on its own.
If you get stuck on a step, go back to that section and check your actions, then search the exact error in the Support Center. To compare plans, the pricing page lists the data allowance and price for every tier, and the Quick Start page shows where to get the client on each platform.