VPN for public Wi-Fi
Updated 21 September 2026 · How we research
Public Wi-Fi is the clearest case for a VPN. It is also the case most often explained badly — the modern threat is not someone reading your bank password, because HTTPS already prevents that.
The realistic threat model
The value is mostly in hiding metadata and neutralising a hostile local network.
| Risk | Still a problem in 2026? | What a VPN does |
|---|---|---|
| Reading your HTTPS traffic | No — TLS prevents this | Nothing extra, though it adds a second layer |
| Seeing which sites you visit | Yes, via DNS and TLS SNI | Hides both inside the tunnel |
| Rogue access point impersonating the venue | Yes | Traffic stays encrypted to your chosen server regardless |
| Captive portal interception | Yes | Connect the VPN after the portal, then keep it up |
| Attacks on unencrypted local services | Yes | Tunnelling removes them from the local network's reach |
A workable routine
- Turn off automatic connection to open networks; that is how you end up on a rogue access point.
- Join the network and complete the captive portal first — portals normally cannot work through a tunnel.
- Connect the VPN immediately afterwards, before doing anything else.
- Confirm the kill switch is on, so a drop does not silently expose you — see kill switch.
- Disable file and printer sharing on untrusted networks.
- Prefer WireGuard; fall back to OpenVPN TCP on 443 if the network filters UDP.
Split tunneling is a liability here
Any application you excluded from the tunnel at home is fully exposed on public Wi-Fi. Either review the exclusion list before you travel or disable split tunneling entirely — see split tunneling.
Providers compared
Commercial terms as published on VPN Sherlock.
| # | VPN | Best for | Key features | Protocols | Devices | Price | Learn more |
|---|---|---|---|---|---|---|---|
| 1 | Best overall | Six published protocols — the widest range among the five compared here | 6 (incl. Shadow, ZoogTLS) | Unlimited | $2.49/month | Get dealRead review | |
| 2 | Clearest obfuscation | The only provider here that publishes how its obfuscation protocol is built | 3 (incl. Stealth) | 10 | $4.99/month | Get dealRead review | |
| 3 | Most devices covered | Native Apple TV and Fire Stick apps, which removes the usual reason to configure a router | 3 (WireGuard, OpenVPN, IKEv2) | 10 | $3.24/month | Get dealRead review | |
| 4 | Most obfuscation options | Two proprietary transports, one of them available at router level. No IKEv2 | 4 (incl. OpenWeb, StealthVPN) | 5 | $5.00/month | Get dealRead review | |
| 5 | Most flexible | Manual config generation for all three protocols, plus a free tier you can evaluate first | 3 (OpenVPN, IKEv2, WireGuard) | Unlimited | $3.00/month | Get dealRead review |
ZoogVPN's OpenVPN TCP option gives a fallback when a venue's network filters UDP, which is common on hotel and airport Wi-Fi.
$2.49/month+ 3 months free
2-year plans
Unlimited devices30-day guarantee
Affiliate link — we may earn a commission at no extra cost to you. See our affiliate disclosure. Pricing shown as published on VPN Sherlock; confirm current terms at checkout.
Frequently asked questions
Do I still need a VPN if sites use HTTPS?
HTTPS protects the contents of a page. It does not hide which sites you visit, which DNS and TLS SNI still reveal to the local network. A VPN hides that metadata.
Should I connect the VPN before or after the captive portal?
After. Captive portals usually cannot complete through a tunnel. Sign in first, then connect the VPN before doing anything else.