Does a VPN Protect You on Public Wi-Fi? What It Does and Doesn't Stop

Does a VPN Protect You on Public Wi-Fi? What It Does and Doesn't Stop

Public Wi-Fi in cafés, airports and hotels is convenient, but it puts your device on the same network as strangers you can't see. So does a VPN protect you there? Yes, in the way that matters most on a shared network: it encrypts your traffic so other people on the hotspot can't read it. It won't stop phishing, malware already on your device, or a weak password, though.

Below, we walk through the real risks of public Wi-Fi, the protection a VPN adds, the threats it can't touch, and the habits that close the gaps.

Does a VPN protect you on public Wi-Fi? The short answer

Yes, a VPN protects the data you send and receive over public Wi-Fi. It wraps every connection from your device in an encrypted tunnel to the VPN server, so anyone sniffing the hotspot or snooping on the router sees scrambled data instead of your logins, messages and browsing.

That protection covers the network, not you. A VPN can't judge whether a site is fake, whether a file is infected, or whether the password you just typed is the one you use everywhere else, so treat it as an extra layer that works alongside good habits, not a replacement for them.

What are the risks of public Wi-Fi?

Public Wi-Fi is less dangerous than it used to be, but it isn't risk-free. The FTC's guidance on public Wi-Fi, last updated in February 2023, says a public network is usually safe today because most websites encrypt their traffic, while warning that encryption won't protect you from scammers who run the site itself. The risks that remain fall into four groups.

A laptop on a café table showing a Wi-Fi network list with two nearly identical open hotspots named "Free Cafe WiFi" and "Free_Cafe_WiFi".

Unencrypted networks and packet sniffing

Packet sniffing means capturing the data that travels over a network, and on an open hotspot anyone with a laptop and free software can do it. A network password doesn't fully fix this, because on WPA2-Personal everyone shares a key derived from the same password, so a person who read it off the café chalkboard can join and intercept other users' traffic with common tools.

Man-in-the-middle attacks

A man-in-the-middle (or adversary-in-the-middle) attack is when someone quietly places themselves between your device and the internet, so your traffic passes through them first. From there, an attacker on the same network can read unencrypted data or redirect you to look-alike pages.

Evil twin and fake hotspots

An evil twin hotspot is a fake Wi-Fi access point made to look like the real one. It can copy the exact network name, and a phone set to auto-join known names can connect to it without any prompt.

This isn't theoretical. An Australian man charged in 2024 ran fake free Wi-Fi networks at Perth, Melbourne and Adelaide airports and on domestic flights, where fraudulent login pages collected email and social media passwords, and in November 2025 he was sentenced to 7 years and 4 months in prison.

Malware distribution

A compromised network can push malicious downloads, fake update prompts or infected pages. The network is only the delivery route, and once malware lands on your device the problem follows you home.

How a VPN protects you on public Wi-Fi

A VPN protects you in three concrete ways, all about the path between your device and the wider internet. Our guide to how a VPN works with Wi-Fi covers the tunnel mechanics in more depth.

It encrypts your traffic

Encryption turns your data into scrambled text that only the VPN server can unlock, so anyone intercepting it on the hotspot gets unreadable noise. People often miss the scope: the VPN encrypts traffic from every app on the device, not just the browser, which matters for mail, messaging and background sync services that never show you a padlock.

It hides your IP address

Sites and services you connect to see the VPN server's IP address instead of the one the hotspot assigned you. That stops other people on the network from tying activity to your device and keeps the sites you visit from learning which café you're sitting in.

It keeps your browsing private from the Wi-Fi operator

Without a VPN, the hotspot operator can log which sites you visit, even on HTTPS, largely through DNS lookups. DNS is the internet's phone book, turning a name like example.com into an address, and those lookups often travel in plain text. With the VPN on, lookups and traffic both go through the tunnel, which gives you real privacy from whoever runs the router.

Which public Wi-Fi threats a VPN stops, and which it doesn't

Here's how common public Wi-Fi threats line up against what a VPN actually does about them.

Which public Wi-Fi threats a VPN stops, and which it doesn't
Public Wi-Fi threat Does a VPN help? Why
Packet sniffing Yes Others on the hotspot capture only encrypted data
Man-in-the-middle Yes The tunnel blocks reading or altering traffic, TunnelVision aside
Evil twin hotspot Partly Traffic is safe once the VPN is up, but not a password typed into a fake sign-in page first
DNS snooping Yes Lookups go through the tunnel, if DNS leak protection works
Phishing No A VPN can't tell a fake site or link from a real one
Malware No Malware reads data before it's encrypted
Weak passwords No A stolen password works the same through a VPN
Shoulder surfing No A VPN can't stop someone watching your screen

What a VPN can't protect you from on public Wi-Fi

A VPN can't protect you from anything that happens on your device or in your own choices. The tunnel secures only the connection, and these four threats sit on either side of it.

  • Phishing websites and links
  • Malware already on your device
  • Weak or reused passwords
  • Shoulder surfing and device theft

Phishing websites

Phishing is a scam that uses a fake site, email or link to trick you into handing over details. The VPN can't tell whether a website, email or link is fake, so a phishing page loads through the tunnel as smoothly as the real one would.

Watch out

A VPN won't stop a fake Wi-Fi sign-in page. Evil twin attacks usually harvest passwords through a login page shown before any VPN can connect, so never enter an email or social media password just to get online.

Malware already on your device

Malware or a keylogger already on the device keeps collecting and sending data with the VPN on, because it sits before the encryption. That's a job for security software, and we compare suites that bundle both in our look at the best antivirus with a VPN.

Weak or reused passwords

If your password turned up in an old breach, it works just as well for an attacker on any network. Sites also still recognize you through cookies, browser fingerprints and logged-in accounts even when the VPN changes your IP address.

Shoulder surfing and device theft

The oldest public Wi-Fi threats are physical, and someone reading your screen on a busy train or walking off with an unlocked laptop needs no network skills at all.

Do you still need a VPN if websites use HTTPS?

Yes, though you need it less than you did ten years ago. HTTPS is the encrypted version of the web protocol, shown by the padlock in your address bar. Google's HTTPS Transparency Report tracks how the share of Chrome page loads over HTTPS climbed from about 30-45% in 2015 to the 95-99% range around 2020, where it leveled off, and Chrome 147 began warning Enhanced Safe Browsing users about insecure sites by default.

HTTPS still leaves gaps a VPN fills. It protects page content but not always the names of the sites you visit, it doesn't cover apps that skip encryption, and it doesn't hide your IP address.

When a VPN is enough, and when it isn't

A VPN is enough for most everyday public Wi-Fi use, such as reading the news, checking email, streaming, or working in a web app you trust. There, the main threat is someone watching the network, and that's exactly what the tunnel handles.

It isn't enough when the hotspot controls your device's network settings. A hostile network that runs DHCP, the service that hands out those settings, can quietly route traffic around the tunnel while the VPN app still shows connected. This trick, called TunnelVision and tracked as CVE-2024-3661, was disclosed in May 2024 and abuses DHCP option 121, which Android doesn't implement, so Android phones were immune. A kill switch gives only partial protection, because each VPN app enforces its firewall rules differently and vendors have patched unevenly since then. And no VPN is enough against a phishing link, an infected download, or a reused password.

How to use a VPN on public Wi-Fi safely

Using a VPN on public Wi-Fi safely depends on the order you connect in. Most hotel and airport networks use a captive portal, the sign-in or terms page you have to clear before the network lets you online.

  1. Join the Wi-Fi network after checking the exact name with staff.
  2. Clear the captive portal, entering only the room number or code the venue gave you.
  3. Connect the VPN before you open any other page or app.
  4. Confirm the app shows it's connected.

We stick to that order because there's a short unprotected window between clearing the portal and reconnecting the VPN, and reconnecting before your mail and apps start syncing keeps that window as small as possible. Expect some slowdown too: a VPN always adds a little on top of the hotspot's own limits, and even a good provider can only keep it small, never zero.

A smartphone showing a hotel Wi-Fi sign-in page with a room number field, beside the same phone showing a VPN app with a connected status.

Other ways to stay safe on public Wi-Fi

A VPN handles the connection, and these habits cover the rest without taking much time.

  • Stick to HTTPS sites, and save banking for a network you trust.
  • Enable two-factor authentication on email, banking and social media accounts.
  • Turn off file sharing and Wi-Fi auto-connect on laptops and mobile devices.
  • Use strong, unique passwords stored in a password manager.
  • Keep your OS, browser, apps and security software updated.
  • Log out of accounts when you're done, then forget the network.
A Windows laptop network settings screen with the profile set to Public and the file and printer sharing toggle switched off.

What to look for in a VPN for public Wi-Fi

A few features make the difference between a VPN you can trust on a hotspot and one you have to babysit.

  • Auto-connect on untrusted networks, so the VPN starts before anything else does.
  • A kill switch that blocks traffic if the tunnel drops, as we explain in what a VPN kill switch does.
  • A modern protocol such as WireGuard for speed and battery life.
  • An independently audited no-logs policy, so the provider isn't the new weak point.
  • DNS leak protection, so your lookups stay inside the tunnel.
  • TCP 443 or an obfuscation mode for hotspots that block VPN ports.
Tip

Turn on auto-connect for untrusted networks and leave it on, because it protects you on the day you forget to open the app.

That last feature earns its place. We've seen a WireGuard connection that works fine at home and on mobile data fail outright on a hotel network that only let web and mail traffic through, and switching the app to TCP on port 443 or its obfuscated mode usually restores the tunnel at some cost in speed. When you're ready to compare providers against this checklist, start with the VPNs we tested for public Wi-Fi.

A VPN app's protocol settings screen on a laptop with WireGuard deselected and a TCP 443 obfuscated option selected, plus an auto-connect on untrusted Wi-Fi toggle switched on.

FAQ

Should I use a VPN on hotel or airport Wi-Fi?
Yes, those are the networks where it helps most. They're busy, shared by strangers, and exactly where fake hotspots turn up, so confirm the network name with staff before you join.
Do I need a VPN on password-protected public Wi-Fi?
Yes, in most cases. Everyone with the shared password is on the network with you, and while Wi-Fi Enhanced Open (announced in 2018) and WPA3 encrypt each device separately, neither proves the network is genuine, so they don't stop an evil twin.
Can the Wi-Fi owner see what sites I visit with a VPN?
No, not while the VPN is working. The router still logs your device, when and how long you were connected, one VPN server address, and how much encrypted data you moved, and if the VPN is off or leaking DNS, the site names show up again.
Can hackers see my data if I use a VPN on public Wi-Fi?
No, not your traffic, but your device still sits on the same local network as everyone else. Open file sharing and unpatched software are exposed at the device level, which is why switching off sharing and staying updated still matter.
Should I connect to Wi-Fi or the VPN first?
Wi-Fi first. If the login page won't load while the VPN is already connected, turn the VPN off, sign in, and turn it back on, and if the page never appears at all, loading a plain-HTTP address such as neverssl.com usually forces the redirect.
Is a free VPN safe on public Wi-Fi?
Yes, from a reputable provider, but expect data caps that run out mid-trip, fewer servers, and at worst logging or ads that pay for the service. Our roundup of the best free VPNs separates the trustworthy plans from the risky ones.
Can public Wi-Fi block a VPN?
Yes, and restrictive hotel and airport networks often block ports such as WireGuard's UDP 51820 and OpenVPN's UDP 1194. They can't block TCP port 443 without breaking ordinary browsing, and on guest networks that filter plain DNS, pages may only load once DNS-over-HTTPS is enabled in the VPN app.

The bottom line

A VPN does protect you on public Wi-Fi wherever the network itself is the threat. It can't spot a phishing page, clean up malware or rescue a reused password, so pair it with two-factor authentication, updates and a healthy suspicion of free sign-in pages.