Public Wi-Fi Signups

One sidedyou give, it gives none
A heavy outbound arrow and an empty return arrow between a person and a network
The network wants a real address in exchange for letting traffic through. Nothing of value comes back the other way.

You connect to the network, a page appears, and it wants an email address before it will let any traffic through. This is one of the clearest cases for a disposable address, because the exchange is entirely one sided.

What the network actually wants

Sometimes a legal requirement to identify users, which an unverified address satisfies only nominally.

More often, a marketing list. Airport lounges, cafes, hotels and shopping centres sell or use the addresses collected at the login page. Some send their own offers, others pass the list to whoever supplied the network hardware, and a few do both.

Occasionally nothing at all. The captive portal software asked for a field, so somebody enabled it, and the addresses go into a database nobody looks at.

In none of these cases does the network need to reach you again. You want twenty minutes of connectivity, not a relationship.

The practical problem

Here is the awkward part, and it catches people out: you often cannot receive mail until you are already online.

Networks vary. Some let you through immediately after you submit the form. Others send a code to the address you gave and expect you to enter it, which requires the connection you do not yet have.

If the network sends a code, check whether it lets any traffic through before verification. Many allow the login page's own domain and nothing else, in which case a disposable address will not help unless you have mobile data to read it on. With mobile data available, open this site there, get an address, submit it, read the code, and enter it in the browser on the other device.

Making it easy

Get the address before you need it. If you are travelling and know a captive portal is coming, open this page while you still have a connection and copy the address. It stays valid for hours.

Choose your own name. An address you can retype from memory is genuinely useful when the portal is on a laptop and the mail is on a phone.

Do not use a real address out of habit. Portal forms are among the most carelessly handled databases in existence, and the addresses collected there end up in unexpected places.

What a disposable address does not fix

It does nothing about the network itself. Public networks are shared, the operator can see traffic metadata, and other users may be doing things you would rather not be adjacent to.

Use encrypted connections, which almost everything is by default now. Avoid signing into anything sensitive on a network you do not control. If you do this often, use a VPN.

The address protects your inbox. It has no opinion about your traffic.

A note on hotel networks

Hotels are the worst offenders because they usually already have your real address from the booking, and the network form asks for it again anyway to feed a different system. Giving that second form a disposable address costs you nothing at all: the hotel can still reach you through the booking, and the marketing database gets an address that stops existing tomorrow.

Airports, cafes and trains, briefly

Airports usually ask once and let you through immediately, sometimes with a time limit and a second form when it expires. A disposable address covers both.

Cafes often use a shared code rather than a form, in which case nothing is collected at all. When there is a form, it is nearly always feeding a marketing list belonging to the chain.

Trains and planes frequently tie access to a booking reference rather than an address. If both are requested, the reference is the part that actually matters to them.

Conferences and events are the one case where a real address is sometimes worth it: the network login and the event communication may be the same system, and you may want the schedule changes.

The order that works every time

  1. Before you leave a connection you trust, open this page and copy an address.
  2. Connect to the network and open the login page.
  3. Paste the address, submit.
  4. If a code is required and the network blocks everything, read the code on your phone over mobile data, then enter it on the device you are connecting.
  5. Close the tab. The address disappears on its own within a day.

Step one is the one people skip and then regret, because getting an address requires the connection you are trying to obtain.

The login window is not your browser

When a device joins a network it quietly requests a known test address. If the answer is not the one it expects, the operating system concludes that something is intercepting traffic and opens a small built in window for the portal.

That window is a separate browsing context. It does not share cookies or storage with the browser you normally use, it usually cannot navigate to other sites, and your password manager is not there. The practical consequence for a temporary address is direct: a mailbox created inside that window is not the mailbox in your ordinary browser, and switching between the two loses track of which is which.

There is a simple way round it. Instead of using the window that popped up, close it and open any plain http address in your normal browser. The portal intercepts that request too and presents the same login page, only now it is running where your mailbox already exists and where pasting works properly. If the portal does send a code, it arrives in the same browser and there is no juggling at all.

Portals ask again more often than you expect

Access is normally granted to a device rather than to you, and for a fixed period: a session of a few hours in a cafe, a day in an airport, sometimes until the device disconnects. Come back tomorrow and the form is there again.

Two things make it worse than it sounds. Phones now present a different randomly generated hardware address to each network, and anything that resets that value, such as forgetting the network or a system update, makes you a stranger to the portal even in a place you visit daily. And your mailbox here is measured in twenty four hours from its last use, so the address you gave yesterday is usually gone by the time the second form appears.

For a network you use often that is an argument for signing in here. An account address survives seven days from each sign in, which comfortably covers a week of the same cafe, and you can give the portal the same address each time.

What to do on the network once you are on

The address protects your inbox and nothing else, so a short list is worth keeping in mind.

Nearly everything is encrypted by default now, which covers the largest risk. Avoid signing into anything financial on a network you do not control. Treat certificate warnings as a reason to stop rather than a dialog to dismiss, since that is exactly what interception looks like. If you use public networks regularly, a VPN removes the category of problem entirely.

None of this has anything to do with which address you gave the login form. They are separate problems that happen to occur at the same moment.

Read next

All guides