How to choose a VPN for public Wi-Fi without assuming it makes you anonymous everywhere
A VPN is genuinely useful on airport, hotel and cafe Wi-Fi, but it does not make you anonymous. We explain what the public-Wi-Fi risk really is, the features that actually matter when choosing a VPN for it, and the expectations to keep realistic.

Table of contents
Public Wi-Fi is the classic reason to own a VPN: airports, hotels, cafes, trains and conference halls where you have no idea who runs the network or who else is on it. A VPN genuinely helps here. But a lot of buying advice oversells it, leaving people to believe that installing any VPN makes them anonymous everywhere. It does not. The trick is to choose a VPN that solves the specific public-Wi-Fi problem well, while keeping realistic expectations about what it changes.
This guide covers what actually matters when choosing a VPN for public networks — and, just as importantly, what a VPN on public Wi-Fi does not do.
What the public Wi-Fi problem really is
On an open or shared network, your traffic passes through equipment you do not control. The realistic risks are things like a malicious hotspot impersonating the venue's network, and someone on the same network trying to observe or interfere with unencrypted traffic. A VPN addresses this directly: it wraps everything your device sends in an encrypted tunnel, so the network operator and other users see only scrambled traffic to a VPN server, not the sites and services you are actually using.
That is a real and worthwhile protection. Modern websites already encrypt a lot with HTTPS, but a VPN adds a consistent layer that covers all your apps, hides which sites you connect to from the local network, and protects the moments when something is not using HTTPS properly.
What it does not make you
Here is the part the marketing tends to skip. A VPN on public Wi-Fi:
- Does not make you anonymous. It hides your traffic from the local network and swaps your IP address, but you are still logged into your accounts, still carrying cookies, and still identifiable to the services you use. Anonymity and encryption are different things — our list of what a VPN cannot protect you from spells out the gap.
- Does not stop you handing over your data. If you type your password into a phishing page, the VPN faithfully encrypts and delivers it to the attacker. It protects the pipe, not your judgement.
- Does not block malware or trackers by default. Some VPNs bundle basic blocking, but the core VPN function is routing and encryption, not security software.
- Does not hide your activity from the sites you log into. They see you as you, from a VPN IP.
Being clear-eyed about this is the point: choose a VPN to close the "untrusted network" risk, not to become invisible. For the fuller picture of what the tunnel does and does not conceal, see what a VPN actually hides.
What to look for when choosing one
With realistic expectations set, these are the features that genuinely matter for public-Wi-Fi use — and they are a slightly different shortlist than you would build for, say, streaming.
- A reliable kill switch. On untrusted networks the moment of highest risk is a tunnel drop. A kill switch that cuts traffic until the VPN reconnects is close to non-negotiable here.
- Auto-connect on untrusted networks. The best protection is the one you do not have to remember. Look for a VPN that can connect automatically whenever you join an unknown or open network, so you are never briefly exposed while fumbling to turn it on.
- Leak protection. DNS and IPv6 leaks can expose which sites you visit even while "connected." A VPN with built-in leak protection matters more on public networks than almost anywhere else.
- Strong, modern protocols. A VPN offering a current protocol such as WireGuard or a well-implemented alternative gives you solid encryption without draining battery or crawling. If you want the details, compare WireGuard, OpenVPN and IKEv2.
- A trustworthy privacy stance. Because your traffic now flows through the VPN provider instead of the cafe, you are shifting trust to them. Prefer providers with a clear, ideally independently examined no-logs position rather than a free app funded by selling data.
- Good mobile apps and quick reconnection. Public Wi-Fi use is mostly phones and laptops on the move, switching between networks. Fast, stable reconnection and a mobile kill switch matter more than a huge server count.
- Cross-device coverage. You will want it on the phone, the laptop and maybe a tablet, so simultaneous connections and easy multi-device setup are worth checking.
A useful rule: features that reduce your exposure during the unpredictable moments — auto-connect, kill switch, leak protection — outrank raw speed or server totals for this particular job. Our general framework on how to choose a VPN without falling for marketing claims applies the same skeptical lens across use cases.
Habits that matter as much as the app
The right VPN reduces risk, but a few habits do the rest:
- Turn the VPN on before you join and start browsing, not after.
- Verify the network name with staff rather than trusting a plausible-looking SSID.
- Keep sensitive logins for networks you trust when you can, even with a VPN running.
- Do not treat the VPN as permission to ignore browser warnings or reuse passwords.
If you travel a lot, the same reasoning extends to hotels, foreign networks and roaming — our guide on VPNs for travel covers those wider scenarios.
The practical takeaway
For public Wi-Fi, choose a VPN for its kill switch, auto-connect, leak protection and honest privacy stance — the things that protect you in the unpredictable moment a network turns hostile. Then hold the right expectation: it encrypts your connection and hides it from the local network, but it does not make you anonymous, does not fix bad security habits, and does not hide you from the services you log into. A VPN that quietly does its narrow job well, paired with sensible habits, is exactly what public Wi-Fi calls for.


