VPN for public Wi-Fi

Updated 21 September 2026 · How we research

Public Wi-Fi is the clearest case for a VPN. It is also the case most often explained badly — the modern threat is not someone reading your bank password, because HTTPS already prevents that.

The realistic threat model

The value is mostly in hiding metadata and neutralising a hostile local network.

RiskStill a problem in 2026?What a VPN does
Reading your HTTPS trafficNo — TLS prevents thisNothing extra, though it adds a second layer
Seeing which sites you visitYes, via DNS and TLS SNIHides both inside the tunnel
Rogue access point impersonating the venueYesTraffic stays encrypted to your chosen server regardless
Captive portal interceptionYesConnect the VPN after the portal, then keep it up
Attacks on unencrypted local servicesYesTunnelling removes them from the local network's reach

A workable routine

  1. Turn off automatic connection to open networks; that is how you end up on a rogue access point.
  2. Join the network and complete the captive portal first — portals normally cannot work through a tunnel.
  3. Connect the VPN immediately afterwards, before doing anything else.
  4. Confirm the kill switch is on, so a drop does not silently expose you — see kill switch.
  5. Disable file and printer sharing on untrusted networks.
  6. Prefer WireGuard; fall back to OpenVPN TCP on 443 if the network filters UDP.

Split tunneling is a liability here

Any application you excluded from the tunnel at home is fully exposed on public Wi-Fi. Either review the exclusion list before you travel or disable split tunneling entirely — see split tunneling.

Providers compared

Commercial terms as published on VPN Sherlock.

#VPNBest forKey featuresProtocolsDevicesPriceLearn more
1ZoogVPN logoBest overallSix published protocols — the widest range among the five compared here6 (incl. Shadow, ZoogTLS)Unlimited$2.49/monthGet dealRead review
2Proton VPNClearest obfuscationThe only provider here that publishes how its obfuscation protocol is built3 (incl. Stealth)10$4.99/monthGet dealRead review
3PureVPNMost devices coveredNative Apple TV and Fire Stick apps, which removes the usual reason to configure a router3 (WireGuard, OpenVPN, IKEv2)10$3.24/monthGet dealRead review
4Astrill VPN logoMost obfuscation optionsTwo proprietary transports, one of them available at router level. No IKEv24 (incl. OpenWeb, StealthVPN)5$5.00/monthGet dealRead review
5WindscribeMost flexibleManual config generation for all three protocols, plus a free tier you can evaluate first3 (OpenVPN, IKEv2, WireGuard)Unlimited$3.00/monthGet dealRead review
ZoogVPN logoSave 82%

ZoogVPN's OpenVPN TCP option gives a fallback when a venue's network filters UDP, which is common on hotel and airport Wi-Fi.

$2.49/month+ 3 months free

2-year plans

Unlimited devices30-day guarantee

Affiliate link — we may earn a commission at no extra cost to you. See our affiliate disclosure. Pricing shown as published on VPN Sherlock; confirm current terms at checkout.

Frequently asked questions

Do I still need a VPN if sites use HTTPS?
HTTPS protects the contents of a page. It does not hide which sites you visit, which DNS and TLS SNI still reveal to the local network. A VPN hides that metadata.
Should I connect the VPN before or after the captive portal?
After. Captive portals usually cannot complete through a tunnel. Sign in first, then connect the VPN before doing anything else.