VPNBeginnerSecurity Guide: Protecting Subscription Links on Public Wi-Fi

Learn how to protect your password and subscription link, stay safe on public Wi-Fi, and avoid sharing personal information unnecessarily. A practical VPN security checklist for beginners.

Know the difference between accounts and subscription links

This VPN security guide for beginners starts with an easy-to-miss point: a subscription link is not just a webpage bookmark. VPN clients typically use it to retrieve server configurations, and it may contain a token that identifies your subscription. Anyone with the link may be able to import the configuration into their own client, even without your account password. Treat both your password and subscription link as sensitive credentials, but remember that the steps to take if either is exposed are different.

Your password is used to access your account. Keep it unique and don't reuse it on other sites. Your subscription link configures your client, so don't post it on public forums, include it in screenshots, share it in public support tickets, or paste it into untrusted online conversion tools. Even if only part of the link appears in a screenshot, check that the full address isn't visible in a QR code, browser address bar, client logs, or link preview. When sending it to another device you own, use a secure method you control. After importing it, clear temporary chat messages or clipboard history.

ItemTypical purposeHow to store it and what to do if exposed
Account passwordSign in and manage your accountStore it in a password manager. If you suspect it was exposed, change it through the official site and review account activity.
Subscription link or QR codeLet the client retrieve server configurationsImport it only into a trusted client. If you suspect it was exposed, check whether you can reset the link or token; contact support if needed.
Payment and identity detailsComplete a specific account actionSubmit them only after confirming the domain and why the information is needed. Don't respond to pressure from pop-ups or unfamiliar messages.

On public Wi-Fi, connect before you browse

Public Wi-Fi names are easy to imitate. If you see a hotspot with a name similar to the venue's, don't assume it's legitimate—ask staff to confirm the network name. Turn off auto-join when you don't need it to prevent your device from reconnecting to a similarly named network after you leave. If the network requires you to accept its terms on a captive portal, complete that network's access steps first. Then start your VPN client, make sure it shows that you're connected, and only then visit sites that require a sign-in.

That sequence doesn't mean the captive portal is trustworthy. If it asks for account credentials or payment details unrelated to getting online, stop and check with the venue. Once the VPN is connected, traffic between your device and the VPN server receives tunnel protection. Whether the destination site is genuine still depends on the browser's HTTPS connection, certificate checks, and your own verification of the domain. Never dismiss a browser certificate warning just to continue.

Shared networks may also expose services on your device's local network. If your system offers a “Public network” setting, choose it and turn off file sharing you don't currently need. Check that your client is still connected before handling sensitive information, especially after waking your device from sleep or switching networks. If the VPN drops unexpectedly and your client offers a kill switch, consider whether to enable it for your needs. Don't assume traffic is still tunneled just because the connection worked earlier.

  • ✅ Check the hotspot name and what the captive portal is asking you to do. Don't enter account details on an unfamiliar page.
  • ✅ Connect to the VPN after getting online, and check the connection status before visiting websites.
  • ✅ Take browser certificate warnings seriously; don't “fix” a page by ignoring them.
  • ✅ Recheck the VPN after switching networks or waking your device, and turn off local network sharing you don't need.
Keep in mind: A VPN on public Wi-Fi protects a stretch of network traffic; it doesn't verify the identity of the hotspot or the website. Check where you're connected before deciding what to share.

Check the client and permissions before importing a subscription

Downloading a client and importing a subscription are two separate steps. First, verify the app's source through the service documentation or the client's trusted release channel. Then check that the client supports the protocols used by the subscription. Shadowsocks, VMess, Trojan, VLESS, Hysteria2, and TUIC are different connection protocols or methods. A client that claims to “support subscriptions” may not correctly handle every configuration they contain. After importing, check that the expected servers appear and verify by connecting; don't rely only on a success message.

Some clients request permission to install a system network extension or VPN configuration so they can route selected traffic. That's different from a webpage asking to access your contacts or files. Read permission prompts during installation and pause if a request doesn't make sense for network access. Desktop and mobile operating systems have different settings and background-running restrictions, so don't follow screenshots from another platform step by step. For platform-specific import instructions, start with the Guides and compare them with the prompts on your own device.

Don't disable certificate verification just to get a server to “connect.” TLS configurations must verify the server's identity. A verification failure may point to a configuration issue, incorrect system time, or a network problem; investigate before proceeding. Protocol names don't replace checking the client's source: even a configuration using a familiar protocol could have been altered to route your connection to an unexpected server.

Split tunneling and DNS: check where your traffic goes

“Client connected” doesn't mean all traffic on your device takes the same route. Global mode typically sends more traffic through the tunnel, while split tunneling uses rules to decide which requests go through the proxy and which connect directly. Rules may apply by domain, address, or app. If you want to access a particular site through the VPN, check that your current mode and rules cover it. On the other hand, local devices and company systems may need a direct connection. Switching to global mode without checking may not suit your needs.

DNS translates domain names into IP addresses. Depending on your settings, your web traffic may use the expected route while DNS queries still go through the local network. This is commonly called a DNS leak. You can use a trusted DNS test before and after connecting to see how queries are routed, but don't rely only on a site's “secure” label. Compare the DNS servers shown with your client's DNS options, system settings, and split-tunneling rules. Your browser's encrypted DNS settings may also affect the results.

Server types don't replace these checks either. With a direct connection, your device connects to the server entry point; a relay adds a forwarding hop. IEPL describes a specific type of network transport—it doesn't mean your browser can skip website certificate checks or that your split-tunneling rules are automatically correct. Choose a server based on your needs, then check the client's actual routing and DNS behavior. Don't treat a “dedicated line” as a switch that handles every privacy setting.

  1. Connect to the server you want to use, then note the mode shown in the client and which rules are active.
  2. Visit the site you need and check that the domain, certificate status, and sign-in page look right.
  3. Check the DNS route. If the results don't match your expectations, review the DNS and split-tunneling settings in your client and system.
  4. Repeat the key checks after switching networks, since changes in your network environment can affect connections and DNS resolution.

What information not to share casually

A VPN can't tell you whether a form belongs to the real website. If you receive a message saying your “subscription is about to expire” or a “server needs verification,” don't follow its link and submit your password, subscription link, or payment details. Open a saved official site yourself and check your domain and account status. If the page asks for information unrelated to what you're doing, stop and verify first. Don't include your subscription link in a troubleshooting screenshot, and never upload your full configuration file to get an “acceleration test report.”

When signing in over public Wi-Fi, pay close attention to redirects. A pop-up that looks like a sign-in page could be the hotspot portal, an ad, or a third-party page. The domain in the address bar matters more than the site's logo. If you entered your password on a suspicious page, change it through an official site you've verified. If your subscription link was exposed, check whether your account lets you reset it. If there's no such option, contact support and explain what type of credential was exposed—there's no need to send the full link again.

Good privacy habits also mean sharing less when you can. If the service clearly says an email address isn't required, don't add one just because a third-party guide suggests it. For any site, first ask whether the information is necessary for the action you're taking. If you're unsure about a page, leave and return through a trusted link.

What to do if something goes wrong

If you notice something unusual, first work out whether it's a connection problem or a possible credential leak. If you simply can't connect, check your network access, client version, subscription status, and server configuration. Don't send anyone your password for help. If your subscription link has been posted publicly, save any relevant evidence, then try updating the link in your account or contact support. If you reused the same password on other sites, change it on each of those accounts too, so a problem with one account doesn't spread.

If you entered payment or identity details on a suspicious page, contact the relevant organization through its official channels as soon as possible. Keep the page address, time, and related notifications for reference. Clearing browser history can't undo information you've submitted, and uninstalling the client won't invalidate an exposed subscription token. Address the specific information that was exposed instead of repeatedly switching servers.

A checklist for beginners: Protect your password and subscription link, verify hotspots and websites, check where your client came from, and review split tunneling and DNS. A VPN is a connection tool; safe use also depends on these everyday decisions.
Try it free