You join the Wi-Fi in a café and want to check your email. Two different protections can help. HTTPS protects information between your browser and the website. A VPN creates a protected path from your device to a VPN server.
What HTTPS does
HTTPS is a protected connection to a website. You can usually recognize it by an address that starts with https:// and by the absence of browser warnings.
When HTTPS works correctly, the Wi-Fi owner cannot read your password or email message. The website still receives anything you send to it. Check the address carefully because a scam website can use HTTPS too.
What a VPN adds
A VPN encrypts your internet traffic until it reaches the VPN server. The café or hotel can usually see that you connected to a VPN, but it cannot see the normal route of traffic inside that connection.
Your traffic then travels from the VPN server to the website. HTTPS is still necessary. A VPN cannot fix a fake website address or cancel a browser security warning.
When you should stop
Do not enter a password if your browser says the connection is unsafe or the website address looks strange. Do not click through a warning just to sign in quickly.
Open the website from a saved bookmark or type the familiar address yourself. If the problem appears only on that Wi-Fi network, use mobile data for the moment and check the page again.
A 30-second check
- Open the website address you know.
- Make sure the browser shows no security warning.
- If you use a VPN, check that it is connected.
- Do not send a password through a page with a warning.
- Turn on two-step sign-in where it is available.
The main idea is simple: HTTPS protects your conversation with the website, while a VPN adds a protected section through the unfamiliar network. Use both when appropriate and always check who will receive your information.