FIELD NOTES
A personal record of travel, networks and small failures
TRAVEL NOTE

Why Your VPN Makes One Trip Look Like Three Different Logins

The security email arrived while I was trying to send a contract before boarding.

New sign-in detected near Washington, Virginia.

I was sitting at an airport gate in New Jersey.

The device listed in the alert was mine. The browser was mine. The time matched. The location did not.

I had spent several weeks moving between World Cup host cities and had grown used to inaccurate map pins. This was different. The alert came from my work account, and I could not dismiss an unfamiliar login simply because airports made the internet behave strangely.

I opened the security page, signed out the other sessions, and changed my password.

Then I reconnected the VPN and tried again.

A second alert appeared:

New sign-in near Chicago, Illinois.

This time the account demanded another security code. The code was being sent to the SIM I had temporarily disabled to avoid roaming charges.

The contract was still sitting in my drafts.

By then, the problem was no longer whether the VPN protected airport Wi-Fi. It was why protecting the connection made my own account behave as though someone else kept trying to enter it.

The short answer

Other travelers describe the same small panic: a VPN changes the visible state or city, and a routine login alert suddenly looks like evidence that somebody else has the password. ( Reddit )

The alert was reacting to my route, not my seat

This became an especially common travel problem during the 2026 World Cup. The tournament brought millions of visitors across the United States, Canada, and Mexico, while stadium Wi-Fi, hotels, airports, trains, and travel eSIMs turned an ordinary day into a chain of unrelated networks. (Fifa)

VPN use rose with the tournament as travelers protected public connections and reached services from home. (Techradar) The result was a confusing mismatch: the same person, carrying the same phone, could appear online through several distant cities within an hour.

Account-security systems do not know where someone is physically sitting. They judge the sign-in from the online signals they receive.

One of those signals is the public IP address. Without a VPN, it usually belongs to the hotel, mobile carrier, airport, or other network carrying the connection. With a VPN, the account sees the address of the VPN exit instead.

If the app selects an exit near Chicago, the login appears to come from Chicago. If it reconnects through Virginia five minutes later, the next login appears to have crossed several states.

Google and Microsoft both explain that sign-ins from unfamiliar locations or devices can trigger security warnings. Microsoft also notes that mobile networks may route traffic through distant places, causing an account to display a city far from the user’s physical position. (Google)

A VPN adds another moving location to that picture.

The warning itself is still useful. A real attacker may also arrive from an unfamiliar address. The sensible check is to compare the device, browser, time, and recent activity rather than treating the map pin as proof.

In my case, everything except the location matched. The alerts were reacting to my changing VPN exits, not an unknown device.

That removed the fear of an account takeover. It did not remove the repeated verification screens standing between me and the contract.

A large server network kept giving me a new identity

I had chosen an established VPN provider because I was traveling.

It had years of public history, a large support operation, and servers in almost every country I might need. Its automatic mode also seemed convenient. I did not want to study a server map whenever I entered a hotel or airport.

That convenience became the source of the interruption.

On the hotel Wi-Fi that morning, the app had selected one US exit. When I left for the airport and switched to cellular data, it reconnected through another. At the terminal, airport Wi-Fi produced a third.

From my perspective, I had traveled about 15 miles.

From the account’s perspective, the same device had signed in from several distant regions.

The provider encrypted the connection each time, but every reconnection presented my accounts with a different public identity. Each new address forced the security system to decide whether I was still me.

I tried choosing a server manually. That held for a while, but the airport Wi-Fi weakened near the gate and the phone returned to mobile data. The tunnel stalled, reconnected, and the work account asked me to verify myself again.

Other travelers describe the same small panic: a VPN changes the visible state or city, and a routine login alert suddenly looks like evidence that somebody else has the password. (Reddit)

That was the mistake I had made. I had been comparing VPNs by how many locations they offered when my account needed the opposite—one network identity that stayed steady long enough to finish the job.


I stopped choosing cities and chose the situation

I closed the security page and opened OnlydogVPN.

Instead of beginning with a country list, the smaller app organised its options around situations. I selected the setting intended for a weak or changing travel connection and connected on the airport Wi-Fi.

I reopened the work account.

The security page showed the VPN location. I approved it once, returned to the draft, and attached the signed contract.

Then boarding began.

I closed the laptop, walked toward the gate, and continued from my phone. As the terminal Wi-Fi weakened, the phone moved onto mobile data.

The email session paused briefly.

It did not sign me out.

No new-location warning appeared. The attachment finished uploading, and the contract left my outbox before my boarding group was called.

When I checked the account activity, the visible VPN exit had remained the same through the handoff.

That was the result I had needed all morning. The network underneath the phone changed, but the identity presented to the account did not.

The service uses an HTTP/3-based transport designed to handle changing network paths more gracefully. In practical terms, it helped the existing protected session continue when the phone moved from Wi-Fi to cellular data instead of rebuilding the connection through a different exit. (IETF)

The technology mattered because the effect was visible. My phone had left the airport network, yet the work account still saw one continuous session.

For login security, that continuity was more useful than an automatic server picker searching for another city.

The account finally had a quiet ten minutes

After the contract was sent, I reopened the sent folder to make sure the attachment had arrived correctly.

No verification banner appeared. No password-reset email followed. The security page showed the expected device, browser, and VPN location.

For the first time that morning, I could stop managing the VPN and finish the work.

While I checked the document, I noticed the app’s blocked-request counter increasing. The mail page was contacting services beyond the functions I was actively using, and the smaller app was filtering some of those background requests.

I could see the counter change, but I could not inspect the service’s internal filtering rules or determine the purpose of every request it blocked.

That was a secondary benefit rather than the reason the app had solved the problem. The important result had already happened: the connection survived the network change without turning one verified session into another suspicious login.

The service has fewer server locations, a shorter public history, and fewer independent ratings than the established provider. Travelers who need to appear in a precise country or city may still prefer the broader network.

But an exact city was not what my work account had been asking for.

Its security system wanted continuity: a familiar device, a plausible session, and a network identity that did not jump across the map whenever the phone found a stronger signal.

The established provider gave me more exits and made the same morning resemble a series of unrelated logins. The smaller app kept one protected route steady long enough for one verified session to remain one verified session.

The alerts stopped when my VPN stopped turning every travel-network change into a new place.

Questions this experience may leave you with

What was actually causing the problem?

Other travelers describe the same small panic: a VPN changes the visible state or city, and a routine login alert suddenly looks like evidence that somebody else has the password. ( Reddit ) (Reddit)

Why did the obvious fixes fail?

I tried choosing a server manually. That held for a while, but the airport Wi-Fi weakened near the gate and the phone returned to mobile data. The tunnel stalled, reconnected, and the work account asked me to verify myself again.

What should you check first?

The warning itself is still useful. A real attacker may also arrive from an unfamiliar address. The sensible check is to compare the device, browser, time, and recent activity rather than treating the map pin as proof.

What finally changed the result?

That was a secondary benefit rather than the reason the app had solved the problem. The important result had already happened: the connection survived the network change without turning one verified session into another suspicious login.

What is worth remembering?

The established provider gave me more exits and made the same morning resemble a series of unrelated logins. The smaller app kept one protected route steady long enough for one verified session to remain one verified session.