What a VPN actually protects when you connect at a hotel, an airport or a cafe, and the three things it does nothing about.
For most people, NordVPN is the strongest choice for public wifi. It has passed six independent no-logs assessments since 2018, covers ten devices on one subscription, and its threat-blocking tool is the only one from a VPN company to hold an anti-phishing certification from the testing lab AV-Comparatives. There is a catch worth knowing before you buy, and it is in the plans table further down.
Affiliate link. Pricing moves constantly, so we point to the live offer rather than quote a figure that goes stale.
Most articles on this subject are still describing the internet of 2013. Being precise about what changed is the difference between useful advice and scare copy.
Ten years ago, someone sitting three tables away with the right software could read a good portion of what you sent over a cafe network. That threat has largely closed. Nearly every site now uses HTTPS, which encrypts the contents of the connection between your browser and the site. Your bank login, your email, the message you just typed: a stranger on the network cannot read any of it.
Three problems survived, and those are the ones worth designing around.
Anyone with about eighty dollars of hardware can broadcast a Wi-Fi network and give it whatever name they like. Sitting in an airport lounge, your phone shows a list of names and one of them says Free Airport WiFi. Join the wrong one and the attacker becomes the road your traffic travels on. They still cannot read your HTTPS traffic, but they decide which address your device reaches when it asks for a website, and they can serve you a login page that looks exactly like the one you were expecting.
HTTPS hides the contents of a page, not the address of it. The hotel, the shopping center or the airline lounge can build a list of every domain your device contacted while you were connected. That is not a hacker, it is ordinary infrastructure, and it is usually logged somewhere. Whether it bothers you is a personal call, but it is worth knowing the choice exists.
When something is wrong with a connection, the browser says so. It puts up a full-page warning about a certificate. The trouble is that these warnings also appear for harmless reasons, so people learn to click through them, and by the time it matters the habit is already set.
Worth being clear about: the biggest financial losses in this age group do not come from Wi-Fi at all. They come from investment schemes, from someone phoning and claiming to be from the bank, and from romance approaches built over months. No VPN touches any of that. If you only have the energy to fix one thing this week, turn on two-factor authentication for your bank and your email instead.
Five checks, none of which need any technical knowledge. Together they take about thirty seconds.
Yes, for the part of the problem you cannot control. A VPN wraps everything leaving your device in its own layer of encryption and sends it to the provider's server before it goes anywhere else. The cafe network, the hotel portal and anyone running a fake access point all see the same thing: one encrypted stream heading to one address, with no way to read it or redirect it.
What it will not do is protect you from yourself. Type your card number into a page you reached from an email and the VPN carries that data faithfully to the scammer, encrypted the whole way. That is the honest limit of the tool, and it is why the two lists below matter as much as the recommendation.
Every VPN says it keeps no records. The question is whether anyone outside the company has ever checked. NordVPN has now been through six independent no-logs assurance engagements, in 2018, 2020, 2022, 2023, 2024 and 2025. The most recent was carried out by Deloitte Lithuania under the ISAE 3000 standard, with auditors working through the infrastructure between November 10 and December 12, 2025, covering the standard servers along with the Double VPN, Onion Over VPN and obfuscated ones. They inspected configuration files and live system logs rather than reading a policy document.
The company is registered in Panama, which has no data retention requirement, and it runs its servers from RAM instead of hard drives, so a seized machine holds nothing once it loses power.
The independent Austrian lab AV-Comparatives runs an anti-phishing comparison against live phishing addresses. In the January 2026 round, using 250 of them, NordVPN's Threat Protection Pro blocked 92% with no false alarms, placing fourth overall behind three antivirus products. Across the whole of 2025, tested quarterly against a thousand addresses, it averaged 90% and came third. It is the only tool from a VPN provider holding the lab's anti-phishing certification, which requires blocking at least 85% without ever wrongly flagging a legitimate banking site.
Here is the part most reviews leave out. Threat Protection Pro is not in the entry-level plan, and it runs on Windows and macOS only. If the feature that blocks fake sites is your reason for buying, the Basic plan is not the one you want, and it will not help you on an iPad.
| Feature | Basic | Plus | Complete | Prime |
|---|---|---|---|---|
| VPN, 10 devices, 9,200+ servers in 224+ locations | Yes | Yes | Yes | Yes |
| Threat Protection (basic ad and site blocking) | Yes | Yes | Yes | Yes |
| Threat Protection Pro, the certified one | No | Yes | Yes | Yes |
| Password manager and breach scanner | No | Yes | Yes | Yes |
| 1 TB encrypted cloud storage | No | No | Yes | Yes |
| Personal data removal service | No | No | No | Yes |
Every plan carries the same thirty-day money-back guarantee. Prices move constantly and differ by country, so we link to the live offer instead of printing a number that will be wrong by next month.
There is no free trial unless you download through the Google Play Store on an Android phone, and in that case Google handles the billing rather than NordVPN. The refund is not automatic either. Canceling your subscription stops the renewal but does not return your money, and you have to contact support and ask for it within the thirty days. If you bought through Apple's App Store, that request goes to Apple.
On price alone it sits at the higher end of the market and cheaper providers exist. What the difference buys you is the audit record, which no budget provider can match.
Already decided? The two-year plan is where the price drops the most, and the thirty days give you room to change your mind.
See the current NordVPN offerFor the full assessment, including streaming, speed and how the apps behave on an older laptop, read our detailed NordVPN review.
We do not buy every subscription and we do not run our own speed tests. A number generated on one home connection, in one city, on one afternoon would tell you very little about what happens on yours.
What we do instead is compile the evidence that already exists and can be checked: published independent audits and the standards they were conducted under, results from testing laboratories such as AV-Comparatives, each provider's own technical documentation and refund terms, the jurisdiction the company operates from, and the problems users report repeatedly across support forums. When a claim comes from the company, we say so. When it comes from an outside body, we name that body and the date.
We earn a commission if you buy through our links. We are not paid for placement or for a higher position, and you will find the shortcomings of every product we cover written down alongside the strengths. More about who writes this site.
Public wifi is safer than it was a decade ago, because almost every website now uses HTTPS encryption. The risks that remain are a fake network set up to imitate the venue's, and the fact that whoever runs the network can see which sites you connect to. A VPN addresses both of those.
Hotel Wi-Fi carries the same risks as any shared network, with one addition: hotel networks often use a login portal, and portals are the easiest thing for an attacker to imitate. Ask reception for the exact network name rather than picking the one that looks right, and never enter a card number into a portal page.
Airport Wi-Fi is usually run by the airport or a contracted provider, and the connection itself is normally fine. The recurring problem is that airports are crowded with people scanning for a network, which makes them a favorite spot for fake access points with names like Free Airport WiFi. Confirm the official name on airport signage before joining.
An unsecured network is one that does not ask for a password to join, so the link between your device and the router is not encrypted. It does not mean the network is malicious, and a password-protected network is not automatically trustworthy, since everyone in the cafe has the same password.
A VPN encrypts everything leaving your device and sends it through the provider's server, so the network operator and anyone running a fake access point sees only encrypted traffic to a single address. It does not protect you from entering your details into a convincing fake website, because that traffic leaves your device willingly.
NordVPN has passed six independent no-logs assurance engagements since 2018, the most recent carried out by Deloitte Lithuania at the end of 2025 under the ISAE 3000 standard. Auditors inspected the server infrastructure directly rather than reviewing documentation. It is based in Panama, which has no data retention requirement.
Every plan carries a 30-day money-back guarantee, but canceling the subscription does not by itself trigger the refund. You have to contact support and request it within the 30 days. Purchases made through the Apple App Store are handled by Apple rather than NordVPN.
A VPN covers the network layer, which is the part you cannot control in a cafe or hotel. It does nothing about a phishing email, a scam phone call, or an account you log into yourself. Treat it as one layer alongside a password manager, two-factor authentication and keeping your devices updated.
Three guides written without jargon, in the order most people need them.
NordVPN — our pick for public Wi-Fi, with a 30-day money-back guarantee
Check current offer