JFK, LAX, ORD. We connected to the public Wi-Fi at all three.
Without a VPN, here is what we observed from our own device traffic:
- DNS queries (every domain we tried to visit, sent in plain text)
- HTTP traffic from apps that had not fully migrated to HTTPS
- Device identifiers broadcast during the connection handshake
- Email metadata from an app using an older IMAP configuration
None of this required specialized hacking tools. It required a laptop, Wireshark (a free network analysis tool), and access to the same public network as everyone else in the terminal.
Airport Wi-Fi is not monitored by a threat actor 24/7 waiting to steal your credit card. The realistic risk is more mundane. And in some ways more pervasive. Passive interception of traffic on open networks is trivially easy for anyone with basic network knowledge. That includes people sitting next to you in the terminal, not just sophisticated attackers.
A VPN costs $3–5/month. Here is what it actually protects, and what it does not.
What Is Airport Wi-Fi, Really?
Airport Wi-Fi networks are public, open networks. "Open" means no WPA2 or WPA3 encryption between your device and the router. Anyone connected to the same network can see the same broadcast traffic.
This is different from your home Wi-Fi, which uses a password and encrypts traffic between your device and the router (assuming WPA2 or WPA3). On airport Wi-Fi, that layer of encryption does not exist by default.
What happens on an unencrypted public network:
DNS queries are visible. When you type a URL, your device first asks a DNS server to look up the IP address for that domain. On an open network, these queries are sent in plain text by default. Anyone monitoring the network can see every domain name you attempt to visit: even if the connection to that site is encrypted via HTTPS.
ARP broadcasts are visible. Your device broadcasts information about itself during the connection process. This includes your MAC address and device type, which are not sensitive in isolation but contribute to a device fingerprint.
Unencrypted app traffic is readable. While major websites use HTTPS, many mobile apps, particularly older apps, background sync processes, and some email clients: still send unencrypted traffic. Any data in those connections is readable to anyone on the same network.
Evil twin attacks are possible. An attacker can set up a Wi-Fi access point with the same name as the airport network ("JFK_FREE_WIFI"). Your device may connect automatically if it previously connected to a network with that name. The attacker then sits between you and the real internet, a man-in-the-middle position.
What Did We Find on Real Airport Networks?
We ran passive traffic monitoring on our own devices at three major US airports in April and May 2026. We did not monitor or intercept any other users' traffic, only our own devices, to document what a passive observer could see.
What was visible without a VPN:
- Every DNS query in plain text: including news sites, email providers, and banking domains we queried to test
- App telemetry data from background processes on iOS and Windows devices
- IMAP email metadata from one device's email client (sender, recipient, subject line, not body) via an unencrypted IMAP connection
- Device broadcast packets including OS version and device type
What was visible with a VPN:
- Connection to one IP address (the VPN server)
- Encrypted, unreadable data
This is the core function of a VPN on a public network: it creates an encrypted tunnel between your device and the VPN server. Anyone intercepting your traffic on the airport network sees only that you are connected to an IP address, not what data is passing through.
Who Is Actually on Airport Wi-Fi With You?
The realistic threat model for airport Wi-Fi is not a professional hacker targeting you specifically. It is:
Other travelers with basic network tools: Wireshark is free, openly documented, and takes an afternoon to learn. People who travel frequently in technical roles often have it installed. Passive monitoring of shared network traffic is not illegal when you are only capturing your own traffic.
Automated network scanning tools: Scripts that scan open networks for exposed credentials, session tokens, or other harvestable data run automatically and do not require human attention.
Evil twin networks: Deliberately set up to intercept traffic from travelers who auto-connect to familiar network names. These are documented in security research and require minimal technical sophistication to deploy.
The airport network operator itself: The airport's Wi-Fi provider logs connection metadata. This is disclosed in the terms of service you click through (and nobody reads). It includes which sites you visit, how long you spend, and your device identifiers.
None of these require a sophisticated attacker. The unencrypted nature of open Wi-Fi is the vulnerability. A VPN addresses it.
What Does a VPN Actually Protect on Airport Wi-Fi?
A VPN encrypts all traffic between your device and the VPN server. On an airport network, this means:
Protected:
- DNS queries: instead of plain text domain lookups, everything goes through the VPN tunnel
- App traffic: all application data, encrypted
- Man-in-the-middle interception: an attacker on the same network sees only encrypted data going to your VPN server's IP
- Traffic analysis: nobody can tell which sites or services you are using
Not protected by a VPN:
- Threats that exist before you connect to the VPN (if your device is already compromised by malware, the VPN does not help)
- Attacks on the VPN server itself (though this is the VPN provider's responsibility, not the airport network's)
- HTTPS stripping on sites that do not enforce HSTS (rare but possible if you click through to an HTTP version of a site)
- Data you voluntarily share on websites (logging in sends your credentials through the encrypted VPN tunnel, but the destination site still receives them)
For a full breakdown of what VPNs protect and what they do not, see our complete VPN guide.
How Do You Choose a VPN for Travel?
Not all VPNs work well in travel scenarios. Airport networks sometimes use captive portals: the login page you see before getting internet access. Some VPNs have trouble connecting through captive portals without specific settings adjustments.
What to look for in a travel VPN:
Captive portal handling: The VPN should support connecting after you accept a captive portal login. NordVPN and ExpressVPN both handle this reliably. Some cheaper VPNs require manual configuration adjustments.
Mobile app reliability: Most airport VPN use is on phones. The iOS and Android apps should connect quickly, stay connected during brief interruptions (like switching between terminal Wi-Fi zones), and have a working kill switch.
WireGuard support: WireGuard connects faster than OpenVPN and IKEv2, which matters when you are trying to get online quickly before a gate change. Most current VPNs support WireGuard.
Kill switch: If your VPN connection drops while you are on airport Wi-Fi, your device will fall back to the unencrypted network without a kill switch. Make sure this is enabled.
We tested VPN behavior on public Wi-Fi networks including airports and hotels as part of our Best VPN for Public Wi-Fi 2026 review. Mullvad and NordVPN performed best in this specific scenario.
Is a /Month VPN Enough for Airport Wi-Fi?
A monthly VPN subscription from a tested, reliable provider costs between $3 and $5 per month when billed annually. Mullvad costs exactly $5/month flat, no annual commitment required. NordVPN costs approximately $3.50/month on a 2-year plan.
If you travel with any frequency: even two or three flights per year: the cost-to-protection ratio is straightforward. The alternative is not using one and accepting that your DNS queries, app metadata, and any unencrypted traffic are visible to anyone on the same network.
The $4/month figure in this article's title is not hypothetical. You can find tested VPNs that passed our five-point leak test at that price point. See the current rankings on our Best VPN 2026 page.
What Should You Do Before Your Next Flight?
Before you leave:
- Install a VPN on your phone and laptop. Test that it connects at home.
- Enable the kill switch in the VPN settings.
- Check that the VPN is set to WireGuard protocol (fastest connection speed).
At the airport:
- Connect to the airport Wi-Fi and go through the captive portal login.
- Open your VPN app and connect to the nearest server.
- Verify the VPN is active before opening email, banking apps, or any sensitive service.
The order matters. You need to connect to the Wi-Fi first (to get through the captive portal), then connect the VPN. If you connect the VPN before accepting the captive portal, some VPNs will block the portal from loading.
On your phone: Both iOS and Android have an option to disable Wi-Fi auto-connect to open networks. Enabling this prevents your phone from automatically connecting to a network named the same as one you previously used: which is how evil twin attacks work.
Which Airport Wi-Fi Risks Are Overstated?
Some airport Wi-Fi security advice is accurate. Some is overstated.
Overstated: "Your credit card will be stolen the moment you connect to airport Wi-Fi." Payment card data sent over HTTPS is encrypted. An attacker on the same network cannot read the card number. The HTTPS layer exists specifically to protect this data even on open networks. What is exposed is metadata, not your card number.
Accurate: DNS queries and unencrypted app traffic are visible. This is less dramatic than credit card theft but represents a real privacy exposure. Which sites you visit, which services you use, and your device identifiers are all readable.
Accurate: Evil twin attacks are real and documented, not theoretical. The defense is to verify the official Wi-Fi name before connecting and to use a VPN immediately after.
Overstated: "All public Wi-Fi should be avoided entirely." HTTPS encryption protects most web traffic. The practical risk on modern public Wi-Fi is meaningful but not catastrophic for most users. A VPN addresses the remaining exposure. Total avoidance of public Wi-Fi is impractical for frequent travelers.
Summary
Airport Wi-Fi is unencrypted by default. DNS queries, app metadata, and any unencrypted traffic are visible to anyone on the same network using basic tools.
A VPN creates an encrypted tunnel that makes all of that traffic unreadable. It costs $3–5/month from a tested provider.
The threat on airport Wi-Fi is not a sophisticated criminal operation targeting your credit card. It is the mundane reality of an unencrypted shared network: visible to other users, to the network operator, and to anyone running basic monitoring tools.
For travel specifically, choose a VPN that handles captive portals reliably, supports WireGuard, and has a working kill switch. Enable the kill switch before you leave home. Turn on the VPN before you open anything sensitive.
The full list of VPNs that passed our leak tests: including performance on public Wi-Fi scenarios: is at Best VPN 2026.
Morgan runs hands-on VPN and network security tests independently at Privaroo. No VPN company or airport paid for or influenced this article. Affiliate links are disclosed per our affiliate disclosure.
If you are traveling, a VPN also unlocks lower hotel prices by switching your apparent location. and the same goes for airline ticket pricing. plus subscription discounts on Spotify, Adobe, and YouTube Premium.



