What is a captive portal, and why does hotel Wi-Fi work that way?
A network that lets you associate and get an address, but intercepts your traffic until you complete some action — accepting terms, entering a room number, watching an advert. The awkwardness everyone experiences comes from the fact that it works by deliberately breaking the thing your device expects.
How it works:
You associate with the access point and receive an IP address by DHCP as normal.
The gateway allows only DNS and traffic to the portal, blocking everything else.
When you request any website, the gateway returns its own page instead, or redirects you to it.
Once you authenticate, your MAC address is added to an allow list and traffic passes normally — usually with a session timeout, which is why you must sign in again the next day.
Why devices behave oddly:
HTTPS cannot be intercepted. Redirecting an encrypted request produces a certificate error, not a login page, because that interception is exactly what TLS exists to prevent. Devices therefore probe with a plain HTTP request to a known URL and watch for an unexpected response — that is what triggers the "sign in to network" prompt.
DNS over HTTPS and encrypted DNS interfere with the detection, which is why turning them on can leave you unable to reach the portal at all.
Private or randomised MAC addresses can break the allow list between sessions, so your device appears as a new client.
Apps fail silently. Anything that is not a browser gets no login page — only a timeout — which is why email and messaging appear broken before you have signed in.
The security position. A captive portal authenticates you to the network; it does not encrypt anything. Open networks with portals are unencrypted over the air unless they use one of the newer opportunistic encryption modes. Treat them as untrusted: rely on HTTPS, use a VPN for anything sensitive, and turn off automatic reconnection to familiar open names.