Best VPN for Cruise Ship Crew: 5 That Work at Sea
Some links on this page are affiliate links. If you buy through them we may earn a commission at no extra cost to you — it never changes which product we recommend.
The best VPN for cruise ship crew is the one that still connects after your ship's satellite link drops for the third time in an hour, then reconnects without you having to dig through settings. Flashy YouTube sponsorships have nothing to do with it. I've sailed as a marine engineer for years, and I've watched more crew members burn their entire wifi data package retrying a VPN app that just won't hold a stable tunnel over VSAT than I can count.
This isn't a generic "top 10 VPNs" list copied from a consumer tech blog. Ship wifi is a different animal, and most VPN reviews are written by people who've never tried to stream a video call over a satellite connection with 600ms latency while the ship is rolling.
Below you'll find the five apps that hold up on real ship networks, the settings that decide whether any of them works at all, a protocol comparison for high-latency links, a first-week test plan so you don't pay for a year before you know, and an honest section on what a VPN cannot do for you no matter which one you buy.
Why crew wifi breaks normal VPN advice
Most VPN comparisons assume you're on decent home broadband or 5G. Onboard, you're usually on shared VSAT (very small aperture terminal) bandwidth, sometimes supplemented by Starlink on newer fleets, split between hundreds of crew and often throttled hard by the ship's IT policy. Latency is high, packet loss is common in bad weather, and the connection drops every time the antenna loses the satellite during a turn or heavy sea state.
The latency has a physical cause worth understanding, because it explains why certain VPN settings help and others do nothing. A traditional VSAT link talks to a satellite in geostationary orbit, roughly 35,786 km above the equator. The signal goes up, comes down at a ground station, and the reply makes the same trip back, which puts a floor of several hundred milliseconds on every round trip before congestion, routing, or the ship's own firewall adds anything. That's where the familiar 600ms figure comes from. Low-earth-orbit constellations such as Starlink sit a few hundred kilometres up instead, which is why latency on those ships feels like ordinary broadband until a handover or a rain squall interrupts it.
High latency by itself is survivable. What breaks VPN apps is the combination of latency with loss and with sudden total dropouts. A handshake that needs several round trips takes seconds instead of milliseconds, and if a single packet in that handshake is lost, the whole sequence restarts from the beginning. Multiply that by an antenna that loses lock while the ship swings at anchor, and you get the familiar crew-mess scene: someone tapping "connect" over and over while their data allowance drains into failed handshakes.
A VPN that's built for hiding your location while torrenting on fiber at home is not built for this. What actually matters for crew:
- Reconnect speed, how fast the app re-establishes the tunnel after a drop, since drops are routine, not rare.
- Protocol flexibility, WireGuard or a lightweight proprietary protocol handles high-latency links far better than older OpenVPN TCP setups.
- Low overhead, every extra kilobyte of encryption handshake matters when you're paying by the megabyte or fighting a shared 2 Mbps pipe with 200 other crew.
- Works with crew wifi portals, some ship networks require a login page before internet even opens, and a few VPN apps fight with that captive portal instead of letting it load first.
If a VPN doesn't handle those four things well, its price and server count don't matter. Server count in particular is close to meaningless at sea. You will realistically use two or three servers for the whole contract: one near the ship's satellite gateway for speed, one in your home country for banking, and perhaps one more for a service that geo-blocks you. Whether the provider advertises 3,000 or 7,000 servers changes nothing about your experience on a 2 Mbps shared pipe.
VPN for cruise ship: is it different for crew than for passengers?
Mostly yes, with one real difference. Crew and passengers usually sit on separate networks with different bandwidth caps and different rules about what's allowed, so a VPN that works well for a passenger's evening browsing can behave differently on the crew side, and the other way around.
Passengers typically buy a shore-side internet package through the cruise line at a per-day or per-voyage rate and get access to the same satellite backbone crew wifi runs on, just on a separate allotment. Everything in this guide about protocol choice, reconnect speed, and avoiding heavy protocols applies just as much to a passenger cabin as it does to a crew berth, because the limiting factor for both is the same shared VSAT or Starlink pipe, regardless of who's connecting. The real difference is policy. Many cruise lines are stricter about VPN use on the crew network than on the guest one, since crew agreements often include acceptable use clauses that guest wifi terms don't spell out. If you're a passenger reading this, check your cruise line's guest wifi terms of service instead of a crew handbook, but the technical advice on protocol and reconnect behavior here carries over directly to your situation.
There's a second, quieter difference: time of day. Passenger traffic peaks in the evening and during sea days. Crew traffic peaks in the hours right after watch changeovers and late at night when the off-duty shift comes online. If you're crew, the practical consequence is that your worst throughput window may sit at a completely different hour than a passenger's, and the right time to test whether a VPN is usable on your ship is during your own peak, not at 05:00 when the pipe is empty and everything looks fine.
Comparison: VPNs that actually hold up on ship wifi
| VPN | Protocol used | Reconnect behavior on drops | Simultaneous devices | Rough price (check current) |
|---|---|---|---|---|
| NordVPN | WireGuard-based (NordLynx) | Fast auto-reconnect, generally reliable on flaky links | 10 | listed at about $3.49/month on the 2-year Basic plan, a secondary aggregated figure from NordVPN's own blog via cybernews.com's NordVPN cost breakdown, checked 26 Aug 2026 |
| ExpressVPN | Lightway (custom, low overhead) | Good reconnect, light on data usage | 10 on the Basic plan, 12 on the Advanced tier | $4.99/month on the 12-month Basic plan ($5.99/month on Advanced), per security.org's ExpressVPN page checked 26 Aug 2026 |
| Surfshark | WireGuard | Solid, budget-friendly, unlimited devices helps cabin-mates share | Unlimited (confirmed) | listed at about €2.49/month on the 2-year Starter plan (current promo period), per Surfshark's own pricing page checked 26 Aug 2026, note this is euros, not dollars |
| ProtonVPN | WireGuard, strong privacy focus | Reliable but slightly heavier handshake | 10 (confirmed on protonvpn.com/pricing) | standard price $7.99/month on the 2-year plan, listed at a promotional $2.99/month, a secondary figure via cybernews.com's ProtonVPN pricing page, checked 26 Aug 2026 |
| Mullvad | WireGuard, no-account model | Reliable, minimal bloat | 5 (secondary, community-reported figure, not an official Mullvad pricing-page number) | Flat €5/month, no multi-year discount tiers, per mullvad.net checked 26 Aug 2026 |
A note on currencies before you compare that table line by line: Surfshark's and Mullvad's listed prices above are in euros, while NordVPN, ExpressVPN, and ProtonVPN are quoted in US dollars on the sources checked here. Don't read a lower euro figure as automatically "cheaper" than a higher dollar figure, or the reverse, they're different currencies, and what you actually pay depends on the exchange rate and your card issuer's conversion fee at the time you buy, not on the raw number in the table.
Prices on satellite-served ship wifi vendors change often and crew discount codes float around messenger boards, so treat these as ballpark figures anchored to the specific pricing pages and check-dates noted above, and check the provider's own pricing page before you buy anything, since promotional rates like ProtonVPN's and NordVPN's listed figures are secondary, time-limited numbers rather than fixed list prices.
Who each option is wrong for
The table above tells you what each app does. This one tells you when to walk past it, which is usually the more useful half of a comparison.
| VPN | Best fit on a ship | Wrong for you if |
|---|---|---|
| NordVPN | Crew who want the safest default: quick reconnects, a long cheap term, and an app most of your colleagues can help you troubleshoot | You dislike long prepaid terms, or you want a provider with no account and no payment trail at all |
| ExpressVPN | Ships where wifi is billed by the gigabyte, where Lightway's lean handshake saves real data over a contract | Your budget is the deciding factor, since at $4.99/month on the 12-month Basic plan it is the most expensive per-month pick here outside Mullvad's flat rate |
| Surfshark | Cabins sharing one plan, and anyone who wants WireGuard at the lowest listed monthly figure in the table | You want a US-dollar price you can compare directly, or you need the longest track record rather than the cheapest promo |
| ProtonVPN | Privacy-first crew, and anyone who wants a genuine free tier to test the ship's network before paying | You need the absolute fastest handshake, since its tunnel setup is slightly heavier than NordLynx or Lightway on a high-latency link |
| Mullvad | Crew who want a flat €5/month with no renewal surprises and no account tied to their name | You want multi-year savings, a big device allowance, or hand-holding support, none of which Mullvad offers |
What the same prices work out to over a contract
Crew contracts run in months, so monthly figures can mislead. The arithmetic below simply multiplies the listed monthly rates from the table above by the term length. Providers normally charge these terms upfront in one payment, and renewal prices after the first term are usually higher than the introductory rate, so treat these as the cost of the first term only.
| Plan as listed | Term | Total for the term |
|---|---|---|
| NordVPN Basic, $3.49/month | 2 years | about $83.76 |
| ExpressVPN Basic, $4.99/month | 12 months | about $59.88 |
| ExpressVPN Advanced, $5.99/month | 12 months | about $71.88 |
| Surfshark Starter, €2.49/month | 2 years | about €59.76 |
| ProtonVPN, $2.99/month promotional | 2 years | about $71.76 |
| ProtonVPN, $7.99/month standard | 2 years | about $191.76 |
| Mullvad, €5/month flat | 12 months | €60 |
Two things fall out of that table. First, the gap between the cheapest and the most expensive option over a two-year term is real money by crew standards, and it is entirely down to promotional pricing rather than to how well the app works at sea. Second, Mullvad's flat rate looks expensive next to a promo, and it looks reasonable next to ProtonVPN's $7.99 standard rate, which is what you may well be paying in year three when the introductory term expires. If you are the sort of person who forgets to cancel, the flat rate is worth more than the headline discount.
Protocols: the setting that decides everything at sea
If you change one thing in your VPN app before sailing, change the protocol. It matters more than the provider you picked.
| Protocol | Behavior on a high-latency, lossy link | Handshake weight | Reconnect after a dropout | Use it on crew wifi? |
|---|---|---|---|---|
| WireGuard | Designed around short, stateless exchanges, so a long round trip costs you once rather than repeatedly | Very light | Fast, often a few seconds once the satellite is back | Yes, first choice |
| Lightway (ExpressVPN) | Same philosophy as WireGuard, built for mobile networks that vanish and return | Very light | Fast, and it holds session state across a network change | Yes, especially if billed per gigabyte |
| NordLynx (NordVPN) | WireGuard underneath with NordVPN's own address handling on top | Very light | Fast | Yes |
| IKEv2/IPsec | Handles a device switching networks well, heavier setup than WireGuard | Moderate | Good, this was the mobile standard before WireGuard | Acceptable fallback |
| OpenVPN (UDP) | Workable, but a chattier handshake means more round trips before you are online | Heavy | Slow on a 600ms link | Only if nothing else connects |
| OpenVPN (TCP) | Worst case at sea. TCP inside TCP means the tunnel and your traffic both retransmit the same lost packet, and the two retry timers fight each other | Heaviest | Slowest, sometimes stalls entirely | Avoid, except to punch through a network that blocks UDP |
That last row explains a symptom crew describe constantly: the VPN connects, everything works for a minute, then the whole session grinds to a halt without actually disconnecting. That is TCP meltdown on a lossy link, and no amount of switching servers fixes it. Switching to WireGuard usually does.
There is one exception where a heavy protocol earns its place. If the ship's network blocks UDP outright, WireGuard cannot get out at all, and OpenVPN over TCP on port 443 (or a provider's obfuscated or stealth mode, which does much the same thing) may be the only tunnel that establishes. Treat that as the fallback you keep in your pocket, and go back to WireGuard the moment you are on a network that allows it.
Settings to change before you sail
These are the adjustments that turn a VPN from unusable to fine on a ship network. Make them on shore internet, where a mistake costs you seconds instead of megabytes.
- Set the protocol manually to WireGuard, or Lightway on ExpressVPN, or NordLynx on NordVPN. Do not leave it on "automatic", which often picks a heavier protocol when it detects an unusual network.
- Turn off "connect on app launch" and any always-on setting until after you have logged in to the ship's captive portal. This single change solves most "my VPN worked in the airport and not on the ship" complaints.
- Understand the kill switch before you enable it. On a link that drops several times an hour, a strict kill switch means your messaging app stops delivering every time the antenna loses lock, and your captive portal session may expire behind it. Many crew leave it off on ship wifi and switch it on only for banking.
- Lower the MTU to around 1280 if tunnels begin to connect and then stall. Satellite links add encapsulation overhead, and an oversized packet that cannot be fragmented simply disappears. Most desktop apps expose this; on mobile you may need a manual WireGuard configuration file to change it.
- Pick a server manually, somewhere geographically near the satellite gateway your ship uses rather than near the ship itself. Automatic selection measures latency, and on a satellite link every server looks equally slow, so the algorithm chooses close to at random.
- Enable split tunneling and exclude anything that is already encrypted or bandwidth-heavy. More on this below.
- Save your login credentials and any configuration files offline, along with your account recovery codes. Two-factor codes sent by email are miserable to collect on a congested connection in your first hour aboard.
- Turn off auto-updates for the VPN app on ship wifi. A background 120 MB update pushed at the wrong moment can eat a meaningful slice of a crew data package.
How to test a VPN in your first week aboard
Do not buy a two-year plan from the airport lounge. Buy a month, or use a free tier, and run this sequence during your first week. It takes about twenty minutes of attention spread across a few days, and it will tell you more than every review on the internet, including this one.
- Day one, before installing anything: get online through the crew portal with no VPN running, and note what the connection feels like at your usual off-watch hour. That's your baseline.
- Confirm the VPN connects at all. If it fails on WireGuard, try the provider's obfuscated or stealth server list, then OpenVPN over TCP on port 443. If nothing establishes, the fleet is blocking VPN traffic and you should stop before spending money.
- Measure the honest cost. Load the same three pages with the tunnel off and then on, at the same hour, and compare how long each takes. You are looking for a modest penalty. A tunnel that doubles or triples page load time on your ship is telling you something.
- Test the drop. Turn the ship wifi off on your device for thirty seconds, turn it back on, and time how long the VPN takes to resume by itself without you touching it. This is the single most important number for crew use, and it is the one no review site can measure for you.
- Test at your peak hour, not a quiet one. Repeat step three during the busiest window on your deck.
- Test the thing you actually care about. If the point is calling home, make the call. If the point is your bank app, open your bank app, and check that the bank does not lock the session because the traffic suddenly appears to come from another country.
- Only then commit. If steps two through six all pass, buy the long term and take the discount. If any of them fail, try the next provider on the list before you conclude that ship wifi is hopeless.
Starlink ships versus legacy VSAT ships
Fleets are mid-transition, and which side of it your ship sits on changes what you should expect from a VPN.
On a legacy geostationary VSAT vessel, the round trip is the enemy. Every handshake, every DNS lookup, every TLS negotiation pays the latency toll. This is where protocol choice makes an obvious, measurable difference, and where OpenVPN over TCP can render a connection unusable. Throughput is usually the harder cap too: a shared package measured in single-digit megabits across hundreds of people leaves very little for anyone.
On a Starlink-equipped vessel, latency stops being the problem and interruption takes its place. The link feels fast, then vanishes for a second or two during a handover, in heavy weather, or when the vessel's structure blocks the antenna's view. A VPN with sluggish reconnect logic turns each of those small gaps into a thirty-second outage for you. Fast resume matters more here than encryption efficiency ever will.
One practical warning: plenty of fleets have installed Starlink for bridge and operational use while crew wifi continues to run on the older VSAT allotment, or on a heavily rate-limited slice of the new one. Do not assume that seeing a Starlink dome on the monkey island means your cabin gets low-latency internet. Ask the ETO or whoever administers the crew network which backbone the crew SSID actually rides on, because the answer changes which half of this section applies to you.
Captive portals: the problem that isn't the VPN's fault
Most crew networks put a login page between you and the internet. Your device connects to the wifi, gets an address, and every request is redirected to a portal where you enter a crew number, a voucher code, or a card. Until you complete that, nothing else passes.
A VPN set to connect automatically will try to build its tunnel the instant it sees a network, before you have logged in. The tunnel fails because the portal is intercepting traffic, the app retries, and on some setups the retries and the kill switch together prevent the portal page from ever rendering. From the outside this looks like the VPN breaking the wifi. It is really an ordering problem.
The sequence that works, every time:
- Join the ship's wifi with the VPN completely off, including any always-on or auto-connect option.
- Open a plain HTTP page to trigger the portal if it does not appear by itself. Many browsers now default to HTTPS, which the portal cannot intercept cleanly.
- Log in and confirm you have real internet by loading any normal page.
- Now start the VPN.
If the portal times out your session after a period of inactivity, you will have to repeat this each time, which is another reason a strict kill switch is more trouble than it is worth on many ship networks.
Free VPN options for cruise ship wifi: what's realistic
A free VPN can work for light use on a cruise ship, but it's rarely a good full-contract solution. The data caps on most free tiers are small enough that a single day of normal browsing over a slow satellite link can burn through them.
ProtonVPN's free tier, mentioned in the comparison table above, is one of the few reputable free options because Proton doesn't log traffic and doesn't cap you by data volume the way many free apps do. It does limit which servers you can connect to and can run slower during peak hours, which matters more on an already-congested ship connection than it would at home. Most other "free" VPN apps you'll find in an app store make their money by logging and selling browsing data, showing ads inside the app, or capping you at a few hundred megabytes a day, any of which defeats the purpose of using a VPN on a connection you're already paying by the byte to access.
If free is the deciding factor, a few approaches work better than just grabbing whatever app has the highest app-store rating:
- Use a reputable provider's free tier for occasional needs, like checking a banking app once a week, rather than as your main browsing tunnel.
- Try a paid provider's short trial or a one-month plan before committing to a year. Most of the providers in the comparison table above offer a short refund window.
- Skip a VPN app entirely for tasks that already encrypt themselves, like most messaging apps, and reserve any VPN budget for genuinely sensitive traffic like banking.
Given how tight crew wifi data packages usually are, stacking a free VPN's hidden data cap on top of your ship's own cap tends to cost more in wasted retries and re-downloads over a contract than a cheap paid plan would in flat monthly cost, whether that plan is billed in dollars or euros.
There is one more use for a free tier that pays for itself even if you never keep it: it is a free way to run the first-week test above. Install ProtonVPN free, find out whether your ship's network permits VPN traffic at all and how fast a WireGuard tunnel resumes after a dropout, and only then decide which paid plan to buy. Crew who skip that step are the ones who end up with an unusable annual subscription and a refund window that closed while the ship was mid-Atlantic.
What actually works day to day
In my experience, NordVPN and Surfshark are the two I see recommended most in crew mess halls, mostly because they're cheap on long-term plans, NordVPN's 2-year Basic plan is listed at around $3.49/month and Surfshark's 2-year Starter plan at around €2.49/month on the pricing sources checked 26 Aug 2026, and the apps reconnect without much fuss after the satellite hiccups. Surfshark's unlimited device count is genuinely useful if you're splitting a plan with a cabin-mate, which is common practice on crew decks even if it technically stretches a "personal use" license.
ExpressVPN's Lightway protocol is worth the extra cost if your ship's wifi package charges by the gigabyte, since it's noticeably leaner than older OpenVPN-based apps. Its 12-month Basic plan lists at $4.99/month with 10 simultaneous connections, or $5.99/month on the Advanced tier for 12 connections, according to the security.org page checked 26 Aug 2026, so weigh whether you actually need the extra two device slots before paying the higher tier. I've timed simple page loads on Lightway versus a legacy OpenVPN TCP connection on the same satellite link, and the difference in handshake overhead alone can save you real data over a contract.
ProtonVPN and Mullvad matter more if your concern is privacy rather than raw speed, some crew use them specifically because they don't want a shore-side IT department (yours or the fleet's) logging every site they visit through the crew network. ProtonVPN's Plus plan runs $7.99/month standard, currently listed at a promotional $2.99/month on its 2-year plan (secondary figure, checked 26 Aug 2026), with 10 confirmed simultaneous connections on ProtonVPN's own pricing page. Mullvad takes a different approach entirely: a flat €5/month with no multi-year discount tiers at all, per mullvad.net checked 26 Aug 2026, and a device limit reported at 5 simultaneous connections in community discussion rather than on Mullvad's own pricing page, so treat that specific number as a secondary data point rather than an official spec. Read the privacy policy yourself rather than trusting a marketing page; jurisdiction and logging practices change, and this is worth five minutes of reading before you trust a company with your traffic.
Mullvad's no-account model deserves a sentence of explanation, because it confuses people the first time. You are given a random account number instead of registering an email address, and you top the account up as you go. For crew that means no renewal you forgot about draining a card while you are at sea, and no account tied to your name in a provider's database. The trade is that if you lose the number, you lose the account, so write it down somewhere that survives a dropped phone.
A note on split tunneling
If your VPN app supports split tunneling, use it. There's no reason to route your video call app or a big download through the encrypted tunnel if you don't need privacy for that traffic, it just adds latency you don't need on top of what the satellite link already gives you. Reserve the VPN for the traffic that actually needs it: banking apps, messaging with family, anything you'd rather the ship's network operator not see in plaintext.
In practice, a sensible split on a crew phone looks like this. Inside the tunnel: your browser, your banking and payment apps, anything work-related you would not want a third-party contractor reading. Outside the tunnel: WhatsApp, Signal, Telegram and similar apps that already encrypt end to end, the ship's own crew portal or intranet applications, which frequently refuse to load through a VPN anyway, and any app store or system updater, so a background download does not also pay encryption overhead. Some banks go the other way and flag a login that appears to arrive from a foreign VPN server, so if yours does, either keep the bank app on a home-country server or leave it outside the tunnel and rely on the app's own encryption.
Money apps and geo-locked services
One underrated reason crew buy a VPN has nothing to do with privacy: services from home stop working when your traffic appears to originate wherever the satellite gateway lands. Government portals, some banks, tax filing sites, and streaming subscriptions you already pay for can all refuse you or silently degrade. A home-country server fixes that in a few seconds.
Two cautions. Connecting to your bank through a VPN can occasionally trigger a fraud hold rather than prevent one, particularly if you were in your home country an hour ago and now appear somewhere else. If you plan to rely on it, test it early in the contract while you still have a support channel you can reach. And check the terms of any subscription service before you route it through a tunnel, because using a VPN to reach a regional catalog is usually a breach of that service's terms even where it is perfectly legal.
What a VPN doesn't fix: getting online in the first place
A VPN encrypts a connection you already have, it doesn't create one. That distinction matters the moment you walk down the gangway in port. Ship wifi drops off, your phone starts hunting for a local cellular network, and if you have nothing set up to get onto that network, no VPN on your phone changes that, there's simply no connection yet for it to route.
That's a different problem than everything else in this guide, and it's worth naming instead of pretending a VPN is a full connectivity plan. The fix for the in-port gap is a way onto the local network itself, which for most crew now means a data eSIM installed on ship wifi before the ship even docks. Airalo is the one I see used most in crew mess halls for this, install the profile over ship wifi ahead of arrival and it activates on the local network the moment you're ashore. Once you're on that local connection, your VPN goes right back to doing its job on top of it if you still want the encryption for banking or messaging. Full rundown of the options in our best eSIM for seafarers guide, our connectivity at sea pricing breakdown covers what the ship's own satellite plan is likely costing on top of it, and for the hours you actually spend off the ship, our offline maps and apps for shore leave guide covers getting around once you have no signal left to spare on a VPN tunnel.
The pairing is worth being deliberate about, because the two purchases cover different halves of the same problem. The eSIM gets you a connection where the ship's wifi cannot reach. The VPN protects whatever connection you are on, and it is arguably more useful ashore than aboard: port terminal wifi, seafarer centre networks, and café hotspots are open networks used by thousands of strangers, and they are a far more realistic threat than your own ship's IT department. Install the eSIM profile while you still have ship wifi, since eSIM installation itself needs a working connection and doing it at the terminal gate with no data is a trap a lot of crew fall into once.
With that gap covered, the rest of this guide is about the VPN itself, once you're already connected to something.
Honest pros and cons
Pros of using a VPN on crew wifi:
- Encrypts your traffic so the ship's network admin (or a curious IT contractor) can't casually see which sites you're on.
- Lets you reach services that some ship networks or flag-state filters block, like certain news sites or messaging apps.
- Modern WireGuard-based apps add surprisingly little latency once connected, even over VSAT.
- A good app auto-reconnects after satellite dropouts, saving you from manually restarting the tunnel every time.
- Keeps home-country services working, from banking portals to government sites that refuse connections arriving from an unexpected country.
- Covers you ashore on open port wifi, which is a genuinely riskier network than the ship's own.
Cons, and there are real ones:
- A VPN adds encryption overhead, which on an already-slow or bandwidth-capped connection can make a bad connection feel worse, especially with heavier protocols.
- Some cruise line IT policies explicitly prohibit VPN use on the crew network, and getting caught can mean a warning or loss of wifi privileges, check your contract and the crew handbook before you install anything.
- Free VPN apps are a bad idea on ship wifi specifically: many log or sell your data, and on a connection you're already paying for by the byte, that's a double loss.
- A VPN does nothing about the underlying speed problem. If your ship's satellite package gives you 512 kbps shared across the crew, no VPN in the world turns that into fast internet.
- Multi-device VPN limits vary a lot by provider, from Mullvad's reported 5-device cap up to Surfshark's unlimited devices, so check the device count against how many phones, tablets, and laptops your cabin actually needs covered before you commit to a plan.
- Ship intranet resources, crew portals, and some onboard services often refuse to load while a tunnel is up, so you will be toggling it more than you would at home.
- Long prepaid terms are how these prices get cheap, and a two-year commitment is awkward when your next contract might be on a ship where the network blocks VPNs entirely.
Rules, policy and the sensible way to handle them
Worth separating three things that get muddled in crew mess conversations. Using a VPN is legal in most of the world, though a small number of countries restrict or license them, which is worth checking if your trading pattern includes one. Separately, your employer is entitled to set conditions on its own network, and a crew acceptable use policy that forbids VPNs is a contractual matter rather than a legal one. Finally, the ship's network may simply block the traffic regardless of what any policy says.
The practical approach is the boring one. Read the network clause in your crew agreement or handbook before you install anything. If it prohibits VPN use, respect it, because losing wifi privileges for a six-month contract is a much worse outcome than browsing unencrypted for a few months. If it says nothing, which is common, you are in ordinary territory and normal use is unremarkable. Either way, never use the ship's network to bypass billing or to get around a filter that exists for operational or safety reasons. The line between protecting your own banking traffic and interfering with the vessel's network is not subtle, and IT departments notice the second one.
Who should not buy a VPN for this
If your cruise line already blocks all third-party VPN traffic at the network level, and some do, particularly on ships where IT security policy is stricter, buying a subscription is money wasted until you've actually confirmed it works from your specific ship's network. Ask around in the crew mess or check an internal crew forum before paying for a year up front.
If you're only ever going to use ship wifi to check email and call home over an approved app like the ones covered in our ship wifi apps for crew guide, you may not need a VPN's privacy layer at all, the extra encryption overhead might just slow you down without a clear benefit. And if your budget is genuinely tight, spend it on more data in your crew wifi package before you spend it on a VPN subscription; a VPN cannot create bandwidth, it only encrypts what you already have, whether that subscription is billed at NordVPN's roughly $3.49/month or Surfshark's roughly €2.49/month.
One more group: anyone about to sign a two-year plan for a single short contract. If you are sailing four months and then home for two, a flat monthly rate you can pause, or a one-year term, often works out better than the headline two-year discount you will spend half of on shore broadband you already pay for.
FAQ
Does a VPN slow down cruise ship wifi even more? Slightly, yes, because encryption adds overhead. On a lightweight protocol like WireGuard the difference is usually small, often under 10-15% in my own casual testing across different ships, but on an already-congested satellite link during peak evening hours, any added overhead is more noticeable than it would be on fast home broadband.
Can cruise lines see what I do if I use a VPN? They can see that you're connected to a VPN server (the connection pattern is visible even if the content isn't), but not the content of your encrypted traffic. Some ship IT policies treat VPN use itself as against the rules regardless of what you're using it for, so check your crew agreement first.
Is a free VPN good enough for crew wifi? Generally no. Free VPN providers often have data caps low enough to be useless on a whole contract, and some monetize by logging or selling browsing data, which defeats the point of using one on a connection you're already paying to access.
Will a VPN help me stream Netflix or watch shows on crew wifi? It might unblock regional catalogs, but it won't fix bandwidth. Streaming over shared satellite crew wifi is usually a bad experience with or without a VPN, since video needs sustained throughput that most crew wifi packages simply don't offer during peak hours.
Do I need a VPN just for messaging apps like WhatsApp? Not really. Most messaging apps already encrypt end-to-end. A VPN adds value mainly for browsing traffic, banking, or apps that don't encrypt well on their own, it's a supplement to good habits like using our crew wifi data-saving tips, not a replacement for them.
Which VPN reconnects fastest after the ship loses satellite signal? In my own use, NordVPN and Surfshark's WireGuard-based apps have reconnected the most reliably after a dropout, usually resuming within a few seconds once the satellite link itself is back. Your mileage will vary by ship and by how the vessel's network is configured, so test during your first week aboard rather than assuming.
What's the best free VPN for cruise ship wifi? ProtonVPN's free tier is the most reputable no-cost option because it doesn't log your traffic or cap you by data volume, though it limits which servers you can use and can run slower during peak hours. Treat any free VPN as a backup for light, occasional use rather than your main tunnel for a full contract, since data caps and slower speeds on most free tiers make them impractical for daily use on an already-slow satellite connection.
Is a VPN for cruise ship wifi different for passengers than for crew? The technology is the same since both usually share the same satellite backbone, so protocol choice and reconnect speed matter equally either way. The main difference is policy: crew agreements often restrict VPN use more strictly than passenger wifi terms do, so check the rules for your specific network before you install anything.
Can I even use a VPN on a cruise ship, or is it blocked? On most ships it connects fine, especially over WireGuard on UDP port 51820 or a provider's own port 443 fallback. A minority of fleets block third-party VPN traffic at the network level or forbid it in the crew acceptable use policy. Blocked and forbidden are two separate problems, so confirm both before you buy a year up front: try a free tier or a refundable monthly plan on your own ship first, and read the crew handbook clause on network use.
My VPN won't connect on crew wifi. What do I check first? Four things, in this order. Log in to the captive portal with the VPN fully off, since an always-on tunnel or a kill switch will block the login page itself. Switch the protocol to WireGuard or the provider's lightweight option instead of OpenVPN TCP. Drop the MTU to around 1280 if handshakes start and then stall. Pick a nearby server manually rather than letting the app auto-select one on the other side of the world, because auto-selection measures latency badly on a satellite link.
Which VPN protocol is best for satellite internet? WireGuard, or a modern custom protocol built on the same idea such as ExpressVPN's Lightway. Both use a short handshake and resume quickly after the antenna loses the satellite, which matters far more than raw encryption speed when your link drops several times an hour. OpenVPN over TCP is the worst choice on a lossy satellite link because TCP inside TCP makes retransmissions pile up on themselves.
Does a VPN work on Starlink maritime? Yes, and it usually feels better than on legacy VSAT because latency is tens of milliseconds instead of the roughly 600ms round trip of a geostationary link. Starlink maritime still drops briefly during satellite handovers and heavy weather, so fast reconnect stays the feature that matters. Note that some fleets run Starlink for operations and keep crew wifi on the older VSAT allotment, so ask which network you are actually on.
Can I use a VPN to get around cruise ship wifi charges? No. A VPN encrypts traffic that has already been allowed onto the network, so it cannot unlock a package you have not bought, and every byte still counts against your allowance. Attempting to bypass billing is a straightforward breach of the crew acceptable use policy and the fastest way to lose wifi privileges for the rest of the contract.
Should I install and test my VPN before I join the ship? Yes. Install the app, log in, download any server configuration files, and save your credentials offline while you are still on shore internet. First logins sometimes need an email confirmation link or a two-factor code, and those are painful to receive on a congested satellite connection in your first hours aboard.
Can I share one VPN subscription with my cabin-mates? Technically the device limits allow it, from Mullvad's reported 5 up to Surfshark's unlimited, and splitting a plan is common practice on crew decks. Most provider terms describe the licence as personal use, so you are relying on the device count rather than on permission. Each extra device also holds its own tunnel over the same shared pipe, so four people sharing one plan does not make the bandwidth go further.
Does a VPN use more mobile data or drain the battery? Both, a little. Encryption overhead adds roughly a few percent to data volume, and keepalive packets plus constant reconnection attempts on a flaky link are what really hurt the battery. If your crew package bills by the gigabyte, turn the VPN off for traffic that is already encrypted and use split tunneling for the rest.
Is a VPN or an eSIM the better buy for a seafarer? They solve different problems and most crew end up with both. An eSIM gives you a connection in port when ship wifi is gone; a VPN encrypts whatever connection you already have. If you only have money for one this month, buy the connection first, because encryption with nothing to encrypt is worthless.
The verdict
There's no single best VPN for cruise ship crew that works identically on every ship, because every fleet's wifi setup, bandwidth cap, and IT policy is different. What I'd actually tell a new crew member: start with a WireGuard-based app like NordVPN or Surfshark on a short plan first, confirm it reconnects cleanly on your specific ship's network before committing to a year-long subscription, and always check your crew handbook for whether VPN use is even allowed before you spend a cent. Keep in mind that NordVPN's roughly $3.49/month and Surfshark's roughly €2.49/month are quoted in different currencies and aren't directly comparable without accounting for the exchange rate. If budget is the main constraint, ProtonVPN's free tier is a reasonable way to test the waters before paying for anything, and its paid tier's 10-device confirmed limit is worth knowing about if you eventually outgrow the free plan.
If you want the short version to act on today: install ProtonVPN's free tier before you fly out, run the seven-step first-week test on your own ship, set the protocol to WireGuard and leave the kill switch off until you know how often the link drops, then buy the long plan from whichever provider survived the test. That order costs you nothing and saves the people who do it in reverse a year of subscription they cannot use.
Related reading
- Ship Wifi Apps Every Crew Member Should Have
- How to Save Data on Cruise Ship Crew Wifi
- Starlink vs Traditional VSAT for Crew Internet
About the author
This article was written by Sea Current Tech's staff writer, a working marine engineer who has sailed on multiple fleets and dealt firsthand with crew wifi ranging from decent Starlink-backed connections to painfully slow legacy VSAT packages. Recommendations here come from actually using these apps on real ship networks, not from a spec sheet, and pricing details are flagged as approximate because provider plans change often, always confirm current numbers on the provider's own page before buying.
Latest updates
- How to Set Up a VPN on a Ship's Router: 4 Workarounds — our newest guide on this topic.
- Keep Your OneWeb Broadband Plan: 229 New Satellites — our newest guide on this topic.
- Port WiFi Security: How Not to Get Hacked (2026), our newest guide on this topic.
- Keep Your Number and 2FA Working on a 6-Month Contract, our newest guide on this topic.