FIELD NOTES
A personal travel journal

The VPN Opened My Bank Abroad. It Still Couldn’t Receive the Security Code

At 1:13 a.m. in Shanghai, my hotel deposit had been declined and the bank wanted me to approve the payment. The login page opened halfway, returned an error and then asked for a six-digit code sent to my home number. I pressed Resend. Nothing arrived. I blamed the foreign connection, opened a familiar VPN and selected a server in my home country. The bank page loaded, but the message still did not come.

The receptionist was waiting for confirmation before completing the check-in.

My travel eSIM showed a strong signal. Maps worked. Messages sent. The airline app had updated my baggage status minutes earlier. Everything about the phone suggested that I was connected.

Yet the one text I needed had apparently disappeared between my bank and the device in my hand.

I requested another code.

Still nothing.

That was when I started asking the wrong question: which VPN would make my bank believe I was back home?

Article summary and product fit

What is the practical answer?

OnlydogVPN then kept the bank session usable long enough to complete the payment and recovered when my internet connection changed. The VPN was carrying the browser to the bank.

The travel eSIM had replaced my data, not my number

Travel eSIMs have made arriving abroad much easier. A traveller can install a data plan before departure, activate it after landing and avoid paying full roaming rates for maps, messaging and ordinary browsing. Modern phones can also keep a home line and travel eSIM active together, using one for calls and texts and the other for data.

I had ignored that second part.

Before leaving home, I bought a travel data package and selected what looked like the safest option for avoiding roaming charges: use the new eSIM and turn off my primary line.

The phone connected as soon as I landed. Because every internet-based service worked, I assumed the setup was complete.

It was not.

The travel eSIM had given me mobile data. It had not taken ownership of the phone number registered with my bank. When I disabled my home line, I also disabled the route the bank was using to send the authentication code.

Other travellers have described the same practical mistake: the foreign data plan works perfectly, but an urgent banking or card-verification message is still being sent to the primary number that was switched off.

That brief pattern explained more than another VPN server test could.

A VPN changes the route used by internet traffic.

An SMS code travels through the mobile service attached to the registered phone number.

I had been trying to repair one road by changing the other.

The established VPN solved the browser side only

The major provider had still helped.

It had years of public history, a large support operation and servers across dozens of countries. I had installed it before travelling because I trusted it more than a random free app found after midnight.

Once I connected through my home country, the bank’s login page stopped returning an error. I entered my password and reached the verification screen.

That was genuine progress.

Then the bank sent another code to the same unreachable number.

I chose a second server, thinking the first address might have triggered an unusual-login check. The page loaded again. The text did not arrive.

A third route added a CAPTCHA before returning me to the same six empty boxes.

The VPN was carrying the browser to the bank. It could not turn a data-only travel eSIM into my home mobile line.

Banks and carriers handle overseas security messages differently. Some banks allow one-time codes to arrive abroad when the registered number has roaming and SMS service. Others warn that short-code messages may not work through certain international arrangements.

No server location could settle that part of the problem.

The code had to reach the number the bank already trusted.

Turning on the right line exposed the next problem

I opened the phone’s cellular settings.

The travel eSIM was active and selected for data. My home line appeared underneath it as turned off.

I enabled the home line but left the travel eSIM responsible for mobile data. The phone searched for a partner network, displayed a roaming indicator and then showed signal bars beside both plans.

I returned to the bank page and requested another code.

A message arrived almost immediately.

Unfortunately, it arrived just after the verification screen expired.

I entered the digits anyway. The bank rejected them and sent me back to the beginning.

The receptionist looked over again.

I had solved the authentication channel, but now the internet channel was becoming unstable. The established VPN began dropping the hotel connection each time I returned to the bank. One route produced another CAPTCHA. A second stalled before the password field appeared.

Its broad server network remained useful in general. At that moment, it meant more decisions after I had already found the real cause of the missing text.

I did not need another country.

I needed the bank page to stay open long enough for the next code to matter.

The smaller app kept both channels usable

I had installed OnlydogVPN before departure as a backup.

I had not opened it first because it offered fewer locations than the established provider and had a shorter public history with fewer independent reviews. For someone choosing a VPN mainly for a wide range of exact country endpoints, the larger company offered more visible choice.

My task was no longer about choosing a country.

It was about keeping the browser session alive while my restored home line received the bank’s message.

The smaller app organised its connections around situations rather than beginning with a server map. I selected the option for reaching services from abroad.

Basic use did not require another conventional email-and-password account. That removed a surprisingly important obstacle: I did not have to receive a registration or password-reset message before using the service that was supposed to help me reach my accounts.

I connected and reopened the bank.

The login page appeared.

I entered my password, reached the verification screen and pressed Send code.

The message arrived on my home line.

I typed the six digits into the laptop. The bank displayed the hotel transaction and asked whether I recognised it.

I approved the payment.

A confirmation appeared on the bank page. Seconds later, the card terminal beside the receptionist printed a receipt.

The original problem was finished.

The smaller app had not delivered the SMS. Keeping my primary number active had done that.

Its role was just as important: it kept the internet side of the process usable while the code arrived through the mobile side.

The technology mattered only after the receipt printed

Only after the deposit cleared did I look at why the connection had behaved differently.

The service uses an HTTP/3-based transport with additional obfuscation, helping it maintain a usable route on networks where familiar VPN traffic may be interrupted.

I could not observe the hotel network’s internal filtering rules, so I could not identify the exact reason the earlier routes had behaved inconsistently. The result in front of me was enough to compare them.

The established provider had opened the bank page several times but kept returning me to server tests and expired sessions.

The smaller app opened the page, held the verification step and let me approve the payment with the code delivered to my real number.

Neither VPN could replace the bank’s authentication factor.

One made it much easier to use that factor before it expired.

The setup survived the next network change

The following morning, I needed to download the receipt and send it to our finance team before leaving the hotel.

Halfway through the upload, the guest Wi-Fi disconnected and displayed its login page again.

I moved the laptop onto my phone’s hotspot, using the travel eSIM for data.

The connection paused, recovered and continued without sending me back through the bank login process.

That smaller result clarified why the final setup worked.

My home line remained active for security texts.

The travel eSIM handled affordable mobile data.

The VPN kept internet-based services reachable as the laptop moved between networks.

Each component had one job.

That was more dependable than asking a single green Connected icon to represent all three.

A VPN cannot become the factor you switched off

Before that night, I had treated receiving two-factor authentication abroad as an IP-location problem.

Location can matter. A home-country route may help an account page open or reduce friction caused by an unfamiliar foreign connection.

But a VPN cannot recreate a disabled mobile line. It cannot redirect an SMS from the registered number to a data-only eSIM, and it cannot change how a bank or carrier handles overseas short codes.

The established provider gave me many home-country routes. None could receive the message while my primary line was off.

Turning the line back on restored the authentication channel. The smaller app then kept the bank session usable long enough to complete the payment and recovered when my internet connection changed.

That was the setup I should have prepared before leaving home: not a VPN pretending to be my mobile carrier, but a stable internet route beside the phone number my accounts already trusted.

The payment cleared only when both roads were open at the same time.

Questions this experience helps answer

What caused the problem in this article?

I had installed it before travelling because I trusted it more than a random free app found after midnight.

Why did the obvious first fix fail?

Once I connected through my home country, the bank’s login page stopped returning an error.

What changed when the task finally worked?

OnlydogVPN then kept the bank session usable long enough to complete the payment and recovered when my internet connection changed.

What should someone check first in a similar situation?

Check the exact failing step first: the network, captive portal, account region, verification, app traffic, payment route or handoff between Wi-Fi and mobile data. Then test the full task, not only whether a homepage opens.