You connect to café Wi-Fi and a page appears on its own: enter your email, tick the consent box, click "Connect". That page is called a captive portal, sometimes also called a splash page or Wi-Fi landing page. The technology has been in wide use since the early 2000s, but how it works is rarely explained in full.

Understanding the mechanism is useful in both directions. For users, it explains what data changes hands. For business owners, it shows why a guest network can be a marketing asset rather than just a cost.

A short definition

A captive portal is a web page forced onto a device that has just joined a network, before that device is granted full internet access. Until the user completes the required step, filling a form, accepting terms, watching an ad, or entering a code, the network holds back outbound traffic.

The word "captive" refers to the device being held inside the local network. It already has an IP address, but no way out.

How a captive portal works technically

The process runs through five stages that happen within seconds.

The device receives an IP address

Once the Wi-Fi association succeeds, the network's DHCP server hands out an IP address, gateway, and DNS addresses. Up to this point everything is normal.

The gateway marks the device as unauthenticated

The network controller records the device's MAC address on a "not yet cleared" list. Firewall rules block all traffic except DNS and requests to the portal server.

The operating system runs a connectivity check

Android, iOS, Windows, and macOS each call a special address to confirm the internet is really available. If the answer differs from what's expected, the system concludes there's a portal and shows a "Sign in to network" notification.

The user is redirected to the portal page

The redirect happens via an HTTP 302 response, DNS interception, or the more modern RFC 8910 standard, which delivers the portal URL directly through a DHCP option.

After authentication, the firewall rules open

The controller moves the device's MAC to the allowed list, usually with a session time limit. When the session expires, the device returns to the first stage.

Common authentication methods

MethodData requestedSuits
Click-to-continueNone, just accepting termsPublic spaces, transport
Email formName and email addressCafés, restaurants, retail
Phone OTPVerified mobile numberHotels, clinics, offices
Social media loginBasic profile from the platformEntertainment venues, coworking
Voucher/codeA code from the receipt or front deskHotels, premium cafés
Sponsored adWatching a short promoAd-supported free networks

Choosing a method is more than a technical decision. The more data you request, the greater the compliance obligation attached, and the more users abandon the connection. From what we've observed across venues, forms asking for more than three fields significantly reduce completion rates.

Why businesses install captive portals

For a venue owner, a portal provides four things an ordinary open network does not.

  • Access control. Sessions can be time-limited, bandwidth shared evenly, and abusive devices blocked without disturbing other guests.
  • Network separation. Guests sit on a VLAN separate from the point of sale, CCTV, and office computers, the most important safeguard, and the most often ignored.
  • Brand identity. The portal page is a visual touchpoint seen by nearly every visitor, free and repeated.
  • Legitimate visitor data. With proper consent, the venue learns its busy hours, repeat-visit rate, and dwell time.

Compliance note: collecting data through a portal is subject to Law No. 27 of 2022 on Personal Data Protection. Consent must be specific, withdrawable, and never a hidden condition. Provide a privacy policy link that genuinely opens from the portal page.

The security side to watch

Because a captive portal appears automatically and looks "official", it is an effective target for imitation. Signs of a portal that isn't legitimate:

  • Asking for another account's password, email, social media, or banking.
  • Asking you to install a certificate, configuration profile, or app.
  • Asking for card numbers for a service advertised as free.
  • Having no working privacy policy link.
  • A network name that doesn't match the one posted at the venue.

Keep in mind, too, that the portal page itself is often served over HTTP rather than HTTPS, because of the technical limits of redirection. Never type confidential information into a page that isn't showing a secure connection.

Fixing a portal that won't appear

The most common complaint is a portal that fails to load, leaving the connection feeling "connected but no internet". Some causes and their fixes:

CauseFix
Private DNS active (e.g. 1.1.1.1, 8.8.8.8)Turn it off temporarily in network settings
VPN on from the startTurn off the VPN, complete the portal, then turn it back on
Browser forcing HTTPSOpen a plain HTTP address such as http://neverssl.com
Old portal cache storedUse private browsing or clear the cache
Random MAC enabled on iOS/AndroidTurn off "Private Wi-Fi Address" for that network

The order to work through these, along with why a device can fail to notice a portal exists at all, is covered in more detail in the guide to a Wi-Fi login page that won't appear.

Designing a portal experience that isn't annoying

From the venue's side, a bad portal carries a hidden cost: staff repeatedly asked to help guests who can't connect. A few design decisions that meaningfully reduce that load:

  • Long enough sessions. A 30-minute session forces guests to log in repeatedly. For a café, two to four hours is usually more appropriate.
  • Remember devices. Keep device status for a few days so regulars don't fill in a form on every visit.
  • A lightweight page. Portals containing large videos often fail to load precisely because bandwidth hasn't been fully opened yet.
  • Instructions for when the portal doesn't appear. One sentence on a table card can prevent dozens of questions to staff.

The technical standards underneath

For years, portal redirection relied on methods that were never entirely clean: injecting responses into HTTP requests or manipulating DNS answers. These methods fail more and more often as browsers force HTTPS and encrypted DNS becomes common.

A newer standard, RFC 8910, introduces a cleaner mechanism: the DHCP server includes the portal URL directly in the network configuration options. Operating systems that support it can open the right page without any traffic manipulation. Its companion standard, RFC 8908, defines an API that lets a device query session status, remaining time, for example, without opening a web page.

For a venue owner the implication is practical: network equipment supporting these standards produces far fewer "the portal won't appear" complaints. It's worth asking about when choosing hardware or a portal service provider.

Alternatives to a captive portal

ApproachAdvantagesDrawbacks
Open network, no portalSimplest for guestsNo control, no data, risk of abuse
Shared WPA2 passwordEasy to set upThe password spreads, hard to revoke per user
Captive portalControl, brand identity, consented dataNeeds equipment and management
Passpoint / Hotspot 2.0Automatic, encrypted connectionDevice and carrier support still limited

For most small businesses in Indonesia, the captive portal remains the most sensible middle ground between convenience for guests and control for the owner.

Conclusion

A captive portal is a thin layer standing between your device and the internet. For users, it deserves reasonable caution: fill in only what's needed, install nothing, and check the network name. For business owners, it's the most affordable way to turn a guest network from a cost centre into a customer relationship channel.

Read on with the public Wi-Fi safety guide for the user side, or the Wi-Fi marketing guide for small businesses if you run a venue.

Frequently asked questions

Why doesn't the Wi-Fi login page appear on my phone?

Usually because automatic detection failed. Try opening a browser and visiting a plain HTTP address such as http://neverssl.com, or temporarily turn off private DNS and any VPN so the portal redirect can work.

Can a captive portal read my WhatsApp messages?

No. Modern messaging apps use end-to-end encryption, so the network operator only sees that you're connected to that service's servers, not the contents of your conversations.

What data does a captive portal typically collect?

Generally the device's MAC address, the time and duration of the connection, and whatever you enter in the form yourself, name, email, or phone number. All of it must be explained in the operator's privacy policy.

Are captive portals mandatory for public Wi-Fi providers in Indonesia?

There's no specific technical requirement, but operators who collect personal data are subject to Law No. 27 of 2022 on Personal Data Protection, which requires a lawful basis for processing and clear notice to users.