
Airplane Wi-Fi is not a cafe with worse coffee. It is a captive portal bolted to a satellite or air-to-ground link, sold by an airline you do not run, often with a thin pipe and a UDP allergy. You either finish their page, then start a tunnel, or you sit there with a kill switch fighting a splash you never saw. Ranked listicles will tell you a VPN makes the cabin safe. It does not. It changes what that inflight AP, and whoever operates it, can read about your next hop.
This is not the VPN on Cafe Wi-Fi: A Habit, Not a Superpower. Shops, menus, skip-on-purpose. Different chair. This is not the VPN Travel Checklist: Before You Go. Download the apps on hotel Wi-Fi before you fly. This page assumes you already have the apps. This is not Linux esim_travel: Not a VPN Setting. Cellular in another country is a different radio. At 35,000 feet you are on the airline's SSID or you are offline. This is not the How to Use a VPN on Public WiFi Safely. That piece is sniffing and evil twins as a checklist. Here the plot is altitude: splash, paid versus messaging, UDP, deadlock, two gadgets in a row.
A VPN still wraps the path from your device to a server you picked. Wikipedia's VPN page is the noun. RFC 8446 is TLS 1.3 on the website. It is not a tunnel. The cabin can still see an IP you hop to if you skip the VPN. It can often see a server name if SNI is in the clear. Encrypted Client Hello exists in the industry and is uneven. Do not pretend the lock hid the graph. HTTPS already encrypted the page on most sites you actually use. The remainder is the hop. That remainder is why people open a VPN over inflight Wi-Fi. It is not a streaming unlock. I will not sell you a catalog I did not promise.
KloxVPN is WireGuard, OpenVPN, OpenConnect, and Shadowsocks, five devices, yearly from $2.83 a month, 7-day money-back on first purchase. Phone plus laptop is two seats. Pricing is the live number. Download is the apps. Smart Connect, if the app shows the row, means connect on untrusted Wi-Fi. Inflight SSIDs are untrusted. The row can race the airline splash. If the row is missing, you have a Connect button. Use the button after the page. I will not invent an On Demand toggle. I will not invent a city count as a reason the cabin is special. I will not invent airline legal advice. If the inflight portal or the airline's site forbids a VPN, that is their page. Read it. I will not pretend I wrote their contract.
I have a bias. Finish the airline page first. WireGuard next. OpenVPN when UDP dies. Pause the kill switch until you have a route. Skip messaging-only SSIDs if they cannot carry a tunnel. Two seats in a row, not five. Seven days if you bought only for this flight. Do not leave fail-closed fighting a portal at cruising altitude and then blame the product.
Related reading: What is a VPN? and WireGuard vs OpenVPN.
Looking for a reliable VPN?
KloxVPN — from $2.83/month. Apps for every device.
Not a cafe, not a packing list
A cafe has a rude AP and a splash. An airplane has that plus a pipe that was never meant to look like home fiber. Latency is worse. Loss is worse. Some inflight stacks block UDP because their CGNAT or their satellite modem had a bad decade. Cafe advice still helps: get a real route, then tunnel. Cabin advice adds: the route is expensive, the portal is picky, and the radio will drop when the aircraft hands off.
The packing list is a before-you-fly article. Install Klox on the phone and the laptop while you still have a normal network. Log into the account. Test WireGuard once. Do not discover in row 14C that you never downloaded the Android build. This page will not walk your toiletries. It will not walk eSIM activation. If your plan is to ignore the airline Wi-Fi and use a phone eSIM in the air, check whether that eSIM even has altitude coverage. Many do not. I will not pretend they do.
Seatback screens are not your laptop. The seatback is the airline's computer. You do not install Klox on it. You do not get a tunnel on a screen you do not control. If you plug a cable into the seat USB, that is power, maybe. It is not a VPN seat. The habit lives on the phone in your hand and the laptop on the tray. Those are two of five. The tablet in the overhead is a third if you turn it on and connect.
Surfshark's inflight VPN article is a competitor specimen. Farms will also rank best VPN for airplanes until the affiliate cookie expires. I am not competing on city counts. I am competing on whether you get a handshake after the splash without deadlocking the kill switch. That is a smaller claim. It is also the one that matches the product.
- 1Join the SSID. Do not start the VPN yet.
- 2Open a browser and finish the captive portal.
- 3Open Klox. Connect WireGuard.
- 4If the handshake dies, switch to OpenVPN. Then work.
Do this in order
| Situation | Have a real route yet? | Start the tunnel? | Kill switch |
|---|---|---|---|
| Airline splash / accept / pay | Not until the page finishes | After the page, then yes | Off or paused until a boring site loads |
| Paid inflight Wi-Fi, already authenticated | Usually yes | Yes, WireGuard first | On if you accept hard cuts on drop |
| Free messaging SSID only | Maybe for a few apps | Often no; the pipe cannot carry a VPN | Irrelevant if you never get a handshake |
| Seatback screen | The airline's computer | You cannot install Klox there | Not your client |
| Phone plus laptop both on the SSID | Each device separately | Each device is a habit | Per device, two of five seats |
The cabin is a rude portal and a thin pipe. Connect after the airline page.
— KloxVPN consumer notes
Cloudflare Learning: What is a VPN?
Do not rehearse this at 35,000 feet
Install and sign in on the ground. The packing list exists for that. This article starts when the SSID appears. If you skipped the ground work, you will spend the first hour of Wi-Fi on an app store that may also be blocked. That is not a VPN failure. That is a packing failure.
Seatback is not a Klox device
You cannot put WireGuard on the airline's IFE. Watch the movie. Use your own gadgets for mail. If the seatback browser is the only network they sold you, you do not have a tunnel product in that hour. Say it and sit still.
Airline splash first
Captive portals want a clear hop. The inflight AP intercepts HTTP, shows accept, pay, voucher, sometimes a loyalty number. Your phone's OS tries to detect that garden. A VPN that starts the instant the radio associates can steal the first hop the portal wanted. Then you have no internet, no splash, and a long flight.
If Smart Connect or a kill switch already fired, disconnect. Pause the switch if traffic is still blocked. Complete the airline page. Confirm a boring site loads. Then connect Klox. WireGuard first. You will be naked on that LAN for a minute. That is the cost of the splash. I will not claim zero exposure. I will claim this is normal, and that leaving the tunnel up during the splash is why people think the app is broken at cruising altitude.
If the portal never appears, you probably already have fail-closed eating the detection traffic. Turn Klox off. Open a plain HTTP site if the OS is shy. Some phones need that. Then the tunnel. Cafe Wi-Fi has the same deadlock. The cabin version is worse because you cannot walk to another AP. There is one radio in the ceiling. Treat it as the only door.
Read the text on the airline page. If they say VPN is not allowed on this service, that is their rule for their network. I am not your lawyer. I am not the airline. I will not invent a policy that says you must tunnel. I will not invent a policy that says you must not. If you choose to connect after you were told not to, you chose it. If you skip the VPN because their page said so, you also chose it. The habit in this article is technical: splash, then handshake. The permission is theirs.
When the portal needs a clear hop
Symptom: Wi-Fi says connected, nothing loads, no login page. Tunnel and fail-closed are the usual culprits. Turn them down, finish the garden, bring them back. Do not reboot the phone as the first move. You will lose the captive dance and start over.
Smart Connect races the splash
If the row exists, it will treat inflight Wi-Fi as untrusted and try to connect. That is correct after you have a route. It is wrong during the garden. Pause it for the page. Restore it if you still want auto on the next network. If the row is missing, you already live on the button. Use the button late, not early.
Paid portal vs messaging SSID
Airlines split the product. Full internet after a card or a pass. A cheaper or free SSID that claims messaging only: iMessage, WhatsApp, maybe a few domains. That second network is not a VPN platform. A tunnel wants a path to a VPN server, not a whitelist of chat hosts. If you connect Klox on a messaging SSID, the handshake often dies. Then you blame WireGuard. The SSID never offered you a general route.
Paid inflight Wi-Fi is still a thin pipe. It can carry a tunnel. It may still hate UDP. It may still captive-portal you again after a handoff. Pay, finish the page, test a boring site, then tunnel. Do not pay, then immediately fail-closed, then open a ticket from the seat. You have not proven the pipe yet.
I will not quote a price for inflight Wi-Fi. I will not name an airline's SKU. Those change. The split does not: garden, then maybe a real route, then maybe a VPN. Messaging-only is a maybe that is usually no. If chat apps work and nothing else does, stay off Klox or buy the full pass if you wanted a tunnel. That is a purchase decision, not a protocol decision.
Cookies on the airline portal are their website. Our cookie page is Klox's site, not the inflight vendor. Do not mix those. Rejecting analytics on klox.app does nothing to the splash in the seat. Completing their portal may set a device cookie so you stay authenticated. If you clear cookies mid-flight you may buy the pass twice. That is their funnel. It is not a leak test.
Messaging-only usually cannot hold a tunnel
Handshake timeout, or connect then instant drop. Switch SSID or buy the full pass before you protocol-hop. OpenVPN will not invent a route the airline did not sell. UDP is not the first suspect on a whitelist network.
Paid still means splash, then test, then tunnel
A receipt is not a route. Load a site. Then WireGuard. If you skip the test, you will not know whether the VPN failed or the pass never activated. Two minutes of clear after pay is the garden, not a lifestyle.
Kill switch at altitude
A kill switch is fail-closed: if the tunnel dies, nothing else leaves. On a laptop at home that is often what you want. Over inflight Wi-Fi it collides with the splash page and with a radio that drops every time the aircraft changes beams. Deadlock looks like this. Auto-connect starts WireGuard. Handshake fails because the portal has not blessed you. Kill switch blocks the HTTP the portal needs. You toggle random settings. You tell the person in 14B the VPN is malware. The product did what you asked. You asked for a brick until the tunnel exists. The tunnel cannot exist until the brick is lifted.
Pause the switch for the garden. Restore it after the tunnel is up if you still want fail-closed on a radio that will drop. Restoring it means you will get cut every handoff. That can be the right call if you care about a leak window. It can be the wrong call if you are trying to keep a work chat alive across the Atlantic. Adult trade. Pretending fail-closed and captive portals are friends is how support tickets get written from 35,000 feet.
Cafe radios are rude. Cabin radios are ruder. They roam, they rate-limit, they reboot the whole aircraft's NAT. Fail-closed will cut you more often than at a shop. That is not a defect in WireGuard. It is a small flying ISP with two hundred phones.
If you cannot live with a pause, skip kill switch on flight days and accept a leak window on drop. Use the Connect button. Smart Connect can wait until you land. I would rather you have a splash and a tunnel than a perfect fail-closed story and no email.
Fail-closed versus the login page
If nothing loads and the OS never shows the portal, assume the switch. Disconnect Klox. Allow traffic. Load a plain HTTP site if the OS is shy. Then the tunnel. Then the switch, if you still want it. The sequence is ugly. It works. Rebooting the laptop is slower.
Handoffs will look like drops
The tunnel dies, the switch cuts you, you think the pass expired. Wait. Reconnect WireGuard. If the airline wants the splash again, pause, garden, restore. Do not buy a second pass as the first debug step.
UDP dies, OpenVPN next
Klox ships WireGuard, OpenVPN, OpenConnect, and Shadowsocks. WireGuard is the default I want on a normal network: fast handshake, light on a phone battery, enough encryption for a LAN you do not run. Inflight Wi-Fi is not a normal network. UDP gets dropped. Handshake hangs. Or it connects and dies. Then OpenVPN, often TCP, is the spare tire. You will feel it. The pipe was already thin. TCP over a high-latency link is not pretty. You will also get a route, which is the actual job.
Do not protocol-hop as a personality. One change, test a site, stop. If both fail, it is the portal, the kill switch, the messaging SSID, or a network that does not want a VPN. Read their page. Cellular is not a cabin strategy unless you have a very specific air-to-ground product, which most people do not. I will not invent one.
DNS through the tunnel still matters on whichever protocol actually connected. IPv6 leak protection still matters if the inflight stack hands you a v6 address and your tunnel is v4-only without a block. WebRTC in the browser can still embarrass you to a page you opened. Those are Features-page sentences. They are not a reason to skip WireGuard on the first try. They are a reason to connect, then optionally leak-test if you are bored in the last hour, then close the laptop and sleep.
I will not publish a speed SLA for inflight plus OpenVPN. I will not publish a city count you should pick. Pick a server that connects. If the app has a default, use it. Fidgeting through a list on a 600ms satellite path is how you spend the whole flight in the server picker. The packing-list article can nag you to test protocols on hotel Wi-Fi. This article says: WireGuard, then OpenVPN, then stop.
Cabin APs that hate UDP
Handshake hangs, or connects and dies, and you already finished the splash. Switch to OpenVPN. If the client labels TCP, try that. Do not sit there fixing Wi-Fi for forty minutes. The ceiling AP does not care. The person waiting for the aisle cares.
Do not collect protocols as a hobby
WireGuard until it is rude. OpenVPN when it is. Back to WireGuard on the next normal network, which is probably after you land. Collecting protocols in row 14 is fidgeting. Fidgeting burns the pass.
Two seats in a row
A tray table is usually two gadgets. Phone already on airplane mode with Wi-Fi, or still on a dead cellular radio. Laptop joining the inflight SSID. That is two simultaneous seats if both tunnels are up. Klox is five. You can install in more places. Only five can be connected at once.
The tablet you left at home on auto-connect still counts if it is holding a session. Ghost phones count. A router at home holding a tunnel counts as one seat and then covers a house, which is a different article. For the cabin: disconnect what is not in the bag, or live with an error when the sixth handshake tries. I travel with phone plus laptop. That is the kit. I do not need a family seating chart to know two is two. If a partner's phone also joins, you are at three. Still fine. Count before you pay for two passes and then hit a cap.
Seatback is zero Klox seats. Good. USB power is zero seats. Also good. A work laptop plus a personal laptop plus a phone is three. The home tablet on Smart Connect is the one that ruins the math. Smart Connect, if the row exists, is untrusted Wi-Fi. Home Wi-Fi you marked trusted should not hold a tunnel. If you never marked home trusted, the tablet on the couch is still in the five. Open the app at home before you fly, or live with the error in the air.
Remove retired devices in the portal. Sleep is not disconnect. A laptop lid can keep a peer. This is not the stolen-phone remote-logout essay. You still own these gadgets. You just forgot which ones are connected. Look at the list. Do not assume the aircraft is why you hit the cap.
Do not leave the home tablet holding a seat
Auto-connect on a tablet at home is how you discover the cap in row 14. Disconnect it before you leave, or take it off untrusted-only so home Wi-Fi does not keep a tunnel you forgot. The family guide is the household chart. This is travel kit versus furniture.
Phone and laptop are two habits
Each device finishes the splash on its own, or shares a portal cookie if the airline wired that, which many do not. Assume two gardens. Then two tunnels. Then two of five. If the phone stays offline, only the laptop needs the cabin habit.
What the cabin still sees
The farm copy still talks as if 2012 HTTP is the default web. It is not. Your bank, your mail web UI, your work chat: TLS. RFC 8446 is how a lot of that encryption works. Contents of the page are not a gift to the person in 14B running Wireshark for fun, if they even could on a client-isolated inflight LAN. Isolation varies. Do not bet your password on it.
What the inflight operator still gets, without a VPN, is the fact of a hop. Destination IP. Often the name in SNI. DNS if your queries are not inside some other encryption. That is a map of who you talked to, not the password you typed into the form. People mash those together because both sound like they can see me. Split them.
A VPN hides that map from the cabin by making the interesting hop a VPN server. The inflight AP sees encrypted traffic to that server. Your ISP at home sees a similar blob if you tunnel at home. Different chair, same idea. Cloudflare's explainer is the generic picture if you want it in someone else's words. Klox routes DNS through the tunnel. Features also lists IPv6 leak protection and WebRTC leak blocking. Those matter after you are connected. They are not a reason to skip the splash sequence. They are why a connected session is more than HTTPS was on anyway.
The cabin still sees that you used their SSID, roughly how much you transferred, and that you spoke to a VPN. Encryption is not authentication of the airline. A VPN cannot make their AP honest. It cannot unlock a streaming catalog I did not promise. Inflight plus a VPN is not a Netflix product. If a farm said otherwise, they were selling a cookie. Klox is a tunnel, five devices, two protocols. Use it as that. It cannot hide that you are on that aircraft. Logs, cameras, the boarding pass: those are not VPN problems.
HTTPS already locked the page
The remainder is the hop. Without a tunnel: IPs, often names, DNS. With a tunnel: a VPN endpoint. They do not get your Gmail body from that. They also do not lose the fact that you bought a pass. The pass is their business.
Read the airline page for their rules
I will not tell you it is legal or illegal to run a VPN on a given carrier. I will tell you to read the portal and the airline's Wi-Fi page. If they forbid it, that is their network. If they allow it and UDP dies, that is OpenVPN. Those are different sentences. Do not mash them into legal advice from a blog.
Seven days if the trip was the product
If you bought Klox only for one long-haul and the inflight Wi-Fi was the whole point, the consumer window is seven days on first purchase. Live page: /refund. Renewals are not that window. Processing is typically several business days to the original method. Store purchases follow the store.
I would rather you keep the year if you will sit in cafes and airports after you land. Yearly from $2.83 a month is not a seatback movie. If you will not, refund inside the clock instead of leaving a subscription you resent. Resentment is how chargebacks happen. Chargebacks are a different mess.
Do not buy a month of a farm brand because a best VPN for airplanes list told you to, then also buy Klox, then refund neither. Pick one tunnel. Five devices is enough for a trip kit. WireGuard, OpenVPN, OpenConnect, and Shadowsocks are enough protocols. You do not need a city count to send mail over a satellite. You do not need a dedicated-IP consumer SKU. We do not sell that as a Klox consumer line item. Do not invent IAP SKUs as a reason the handshake failed. The handshake failed because of the portal, UDP, or the messaging SSID.
If the apps will not handshake even after the splash, try OpenVPN. If they still will not, that is what the seven days are for. Document the airline and the SSID in the ticket if you write in. Do not invent a story about SOC 2. Nobody in the cabin asked. Do not invent an SLA percentage for inflight. We do not publish one. The packing list can still save the next trip. This trip was a thin pipe. Treat it that way.
First purchase, not a free week forever
The window is so you can try the apps, including on rude Wi-Fi. It is not a coupon for every flight. If you already used a first purchase, you already used the window.
If you only needed the cabin
Refund inside seven days if that was the whole product for you. Keep it if airports and cafes are a habit you will repeat after you land. Habits are why a year exists. Capes are why farms exist. This page was the cabin habit: splash, paid versus messaging, deadlock, UDP, two seats, remainder, seven days.
Key Takeaways
Airplane Wi-Fi needs a habit, not a cape. Finish the airline page. Then tunnel. WireGuard first. OpenVPN when UDP dies. HTTPS already locked the page. The cabin still sees the hop unless that hop is a VPN. Messaging-only SSIDs usually cannot hold a tunnel. Seatback is not a device. Pause fail-closed through the garden.
Phone plus laptop is two of five. Smart Connect, if the row exists, is untrusted Wi-Fi and will race the splash. Seven days if you bought only for the flight. Yearly from $2.83 a month. No city count. No streaming fairy tale. No airline legal advice from this URL. Read their page.
If you wanted a cafe, that habit is next door. If you wanted a packing list or an eSIM essay, those are different URLs. If you wanted a tunnel you will actually use in row 14, download the apps on the ground, practice the splash sequence once on hotel Wi-Fi, and do not discover OpenVPN for the first time at cruising altitude.
Related Resources
Install on the ground. Connect after the splash.
KloxVPN is WireGuard, OpenVPN, OpenConnect, and Shadowsocks, five devices, yearly from $2.83 a month, 7-day first-purchase money-back. Smart Connect, if your app shows it, is connect on untrusted Wi-Fi. Use it after the airline page, not as a cape.
Download KloxVPNFrequently Asked Questions
KloxVPN Team
Experts in VPN infrastructure, network security, and online privacy. The KloxVPN team has been building and operating VPN services since 2019, providing consumer and white-label VPN solutions to thousands of users worldwide.