Using banking apps from abroad: what to prepare
Most problems come from identity verification rather than from the connection.

Quick answer
- Secure a way to receive verification codes: most travel eSIMs are data-only and cannot receive SMS.
- Do transactions on your own mobile data rather than on public Wi-Fi.
When a banking app fails abroad, people assume it is the connection. Usually it is identity verification tied to your home number, or the bank reacting to access from an unfamiliar country.

Before you travel
- Check how the app sends codes: if by SMS, keep the home SIM available to receive them
- If in-app or authenticator verification is offered, set it up in advance
- Tell the bank your travel dates if it offers that facility
- Save the bank's international contact details offline
While you are there
- Transact on your own mobile data rather than public Wi-Fi
- If a VPN causes the app to refuse, exclude that app from the VPN
- Keep at least one backup verification method available
When the code does not arrive
| Common cause | What to try |
|---|---|
| The home line is fully disabled | Keep the line enabled but turn off its data and roaming |
| The home operator is not delivering SMS abroad | Contact that operator directly: it concerns your own number |
| App-based verification not yet enrolled on this device | Complete enrolment before departure |
Why the trouble shows up on arrival, not at home
At home everything lines up so quietly that you never count the moving parts. Your usual number sits in the phone, the signal comes from an operator your bank has seen a thousand times, the location it observes is the city you always log in from, and the handset you tap to approve is the one already enrolled. Step off the plane and several of those change at once. The IP address belongs to another country, the network the phone attaches to is unfamiliar, and if you disabled the home line to avoid roaming charges, the SMS channel disappeared along with it. Bank security is built to get suspicious when a cluster of signals moves together. Nothing is broken; the system is doing precisely what it was designed to do.
Framing it that way changes the whole preparation. Instead of asking whether the data is fast enough, the useful question is how the bank will confirm you are you on a day when you are half a world away from the number on file. That answer has to be arranged while you are still at home, because nearly every method that genuinely proves identity has to be enrolled from a device that has already been trusted. Leave it until you are stuck in a hotel lobby and you meet the loop with no exit: you need to verify yourself in order to switch on a way of verifying yourself.

The three layers a bank checks, and which ones travel breaks
Break it down and a bank is really checking three separate layers. The first is something you know: a password or a PIN. The second is something you have: an enrolled handset, a SIM tied to a registered number, or a key held inside an authenticator app. The third is context: which country the request came from, which network carried it, what time it arrived, and how it compares with your usual pattern. Travel barely touches the first layer. It touches the second only if you remove a SIM or change phones. It changes the third every single time, automatically. Once you see that split, it is obvious where preparation time should go.
| Layer | What travel does to it | What to arrange in advance |
|---|---|---|
| Something you know, such as a password | Almost unaffected, unless you normally use a fingerprint and have forgotten the password | Log in once with the actual password before you leave |
| Something you have, such as a handset or SIM | Affected when the home SIM comes out, the phone changes, or the device is reset | Enrol an in-app or authenticator method while still at home |
| Context, such as country and network | Changes the moment the phone attaches to a foreign network | Tell the bank your dates if it provides a way to do so |
The layers work together: a well-prepared second layer is what rescues you when the third makes you look suspicious.
A one-week-out audit of your own accounts
This takes under half an hour and returns more than any other preparation you can do. The trick is to behave as if you were already abroad without waiting to be. Open every banking app you expect to use on the trip and work out, app by app, which verification methods each one offers. Write the answers into a note you can read offline rather than trusting memory, because the moment you need this information is usually the moment nothing else will open.
- 1Sign out, then sign back in with the real passwordPlenty of people have used a fingerprint or face for so long that the password has faded. Banks often demand the full password when they see a login from a new country. If you cannot recall it at home, resetting is far easier than doing the same thing from abroad.
- 2Walk through each app's security menuLook for in-app approval or authenticator support. The menu names differ by bank: some call it in-app approval, others trusted devices. If it exists, switch it on and test it once now rather than trusting that it will work later.
- 3Confirm your email opens on the same phoneMany banks fall back to email, which becomes useless the instant that email account itself demands an SMS to open. Check that you can reach your inbox without depending on a message to the home number.
- 4Save the bank's contact routes offlineCopy whatever routes the bank publishes for customers overseas into an offline note, and onto one piece of paper kept away from the phone. If the handset is lost or dead, that paper is all that is left.
- 5Push one small transfer throughA genuine low-value transaction reveals every verification step the bank will ask for, and some of those never appear when you merely check a balance. Once is enough, but do it before the flight rather than after.
Leave the home line on, or switch it off? The most commonly botched decision
Most people treat this as binary: everything on, or everything off. That is where it goes wrong, because a single line has several independent switches. Voice and messaging are separate from data, and data roaming is a further switch on top. Turn the whole line off to control costs and you shut down the SMS channel too, even though in many cases receiving a message costs the recipient nothing. Whether that holds for your number depends entirely on your home operator, so ask them before you go. There is no universal answer that applies to every line.
| Home-line setting | Effect on receiving codes | Use it when |
|---|---|---|
| Line enabled, its data and data roaming off | Messages can still arrive, subject to what your home operator allows | The sensible default for anyone still relying on SMS |
| Line fully disabled | No messages arrive at all | Fine once every account has moved to in-app verification |
| Line and data roaming both on | Messages arrive, but data charges become possible | Best avoided when you already bought an eSIM for data |
Authenticator apps and keys that live on the device
The verification methods that survive travel best are the ones that never depend on the home number's network. An authenticator app generating six digits from the device clock works with no signal at all, and in-app approval inside the banking app needs only an internet connection, which your eSIM already provides. Both are bound to the handset rather than the SIM, so they survive switching the home line off. The flip side is that if the handset is lost or dies, the keys go with it. That is exactly what recovery codes are for.
Recovery codes are the string of characters a service hands you when you first switch on two-step verification. Most people click past them without saving anything, even though they are the only way out when both the handset and the SIM are unavailable. A reasonable place to keep them is printed on paper, stored away from the phone: in a different bag, or with the person travelling with you. What not to do is screenshot them into your photo library, which syncs to the cloud and is far easier to browse than most people assume.

Email is the backup route nobody tests
Plenty of banks fall back to email when an SMS does not arrive, which sounds like a solid safety net until you remember that the email account has its own two-step verification, quite possibly tied to the same home number. If so, your safety net hangs from the same rope it is meant to catch. Testing costs a few minutes: sign out of email on one device and sign back in. If it asks for an SMS code, that is something to fix before you fly, not after.
When the bank asks something you cannot answer from abroad
Sometimes verification does not end at a code and turns into questions that need information kept at home: a recent transaction amount, the date the account was opened, card details you did not bring. The way to handle that is to prepare a small set of answers in advance, somewhere you can read offline. It does not need to be detailed enough to be dangerous, just enough to clear a question gate: the last four digits of the account, the branch where it was opened, the month and year. Information at that level will not let anyone move money, but it does get you past the questions.
A VPN helps in a few cases and hurts in many others
A common instinct: if the bank objects to a foreign login, use a VPN so it looks domestic. In practice that usually makes things worse, because fraud systems see more than location. They can also tell the connection is coming from a data centre rather than a mobile operator, which is a stranger signal than travelling ever was. Some apps refuse to run the moment they detect a VPN, and some accounts get locked down harder afterwards.
Where a VPN genuinely earns its place is on Wi-Fi you do not control, such as a lobby or a café network. If you already carry your own data, doing the transaction on your own mobile data is enough and far simpler. If you need the VPN running for other reasons, exclude the banking apps from it; most VPN apps offer that under one name or another.
Paying at the counter while the app is still refusing
Standing at a till, the real problem is not that the app will not open; it is that you cannot pay, which is a different thing. A card that taps normally does not require you to log into anything. So when the app misbehaves, separate the two in your head and deal with the urgent one, the payment in front of you. Recovering the app can wait until you are back at the accommodation, rather than being attempted while a queue builds behind you.
Carrying at least two ways to pay turns this into a minor event: cards from two different institutions kept in different pockets, plus enough local cash for a day. How much depends on the country and the way you travel, and we will not put a number on it because the range is enormous. The principle is enough to cover the trip back to where you are staying, a meal, and one unexpected expense.

Changing phones, or losing one, mid-trip
This is where preparation proves itself. If every verification method lives on one handset and that handset disappears, you lose the bank, the email, and the authenticator in one stroke. Two things can be arranged beforehand: recovery codes kept away from the device, and a second enrolled handset where the bank permits one. The data eSIM is a separate problem, because many plans install only once, so moving to a new phone is not a matter of pulling out a SIM and pushing it into another slot.
The checklist to run before you leave the house
- Signed into every banking app at least once using the real password
- Enabled in-app or authenticator verification wherever the bank offers it
- Recovery codes stored on paper, kept separately from the phone
- Verified that email opens without an SMS to the home number
- Home line set to enabled with data and data roaming off, and screenshotted
- Bank contact routes for overseas customers saved offline
- At least two ways to pay, carried in different places
- eSIM installed and proven to connect before departure
The order to work through when the app refuses at the destination
When something actually goes wrong, the biggest waste of time is random tapping. The order below runs from the easiest and most common check to the harder ones. Do one at a time and wait for the result before moving on, because changing several things at once leaves you with no idea which one fixed it.
- Confirm data actually works by opening any page that is not the banking app
- Turn off any VPN completely and try the app again
- Fully close the app and reopen it rather than just switching away
- Check the device clock is set automatically, since authenticator codes depend on time
- Alternate between Wi-Fi and your own mobile data, testing each separately
- If it is a code problem, compare the home line's switches against your screenshot
- If it still fails, use the contact route you saved rather than a number found in search results
The line between what we can help with and what only your bank can do
We look after the connection: whether the plan installs, whether the phone attaches to a network it should, whether data flows as expected. What we have no access to at all is your bank account, your verification status, or the reasoning behind a decision their systems made about a particular transaction. Knowing where that line sits saves your own time, because you send each question to the side that can actually answer it the first time rather than waiting on the side that never held the information.
Časté dotazy
Can a travel eSIM receive SMS codes?+
Usually not, since travel plans are typically data-only. Keep the home SIM enabled for SMS with its data switched off.
The bank blocked access from abroad. What now?+
Contact the bank through the details you saved and be ready to verify your identity. Using a VPN to appear at home is not something we advise.
If I keep the home SIM off for the whole trip, can I still bank?+
Yes, provided every account you plan to use has moved to in-app or authenticator verification. If any of them still sends codes only by SMS, disabling the line completely locks you out of that one. The safer arrangement is to leave the line enabled with its data and data roaming switched off, and take your data from the eSIM instead.
The bank locked my account after a foreign login. What comes first?+
Use the contact route you saved before travelling rather than a number or link from search results, which is a place fraudsters wait. Have the identity details you prepared to hand, and resist logging in repeatedly while you wait, since that only makes the pattern look more irregular.
The app says it detects a VPN even though I turned it off. Why?+
Usually either the VPN is set to reconnect automatically, or an ad blocker or content filter is running through a VPN profile on the device without you having switched it on. Look in the phone's network or VPN settings and disable any profile still active. Menu names vary by manufacturer and OS version.
Should I always tell the bank before I travel?+
If the bank provides a way to register travel dates, doing so can reduce the chance of a transaction being held. Many banks have dropped the practice and rely on behavioural analysis instead, so it should not be your only preparation. Setting up verification that does not depend on SMS remains the more dependable step.
Can an eSIM bought here receive the bank's verification messages?+
Most travel plans are data-only, so there is no number to receive SMS on, and even where a plan does include one, your bank still sends codes to the number registered with it. The workable plan is therefore to keep the home line available for messages, or to move to in-app verification. What each plan includes is stated on that plan's own page.
Instagram and TikTok have no web share button, so we open your phone's share sheet or copy the link instead.