Menu

We independently review everything we recommend. When you buy through our links, we may earn a commission. As an Amazon Associate we earn from qualifying purchases.

How To

How to Find Unknown Devices Connected to Your Wi-Fi

Owen Bradley Owen Bradley Aug 10, 2026 9 min read 1 views

Open your router’s device list and the odds are good you will find at least one entry you cannot identify. Something called ESP-4A2F91, or a bare MAC address with no name at all, or a generic label like android-device sitting quietly alongside your laptop and phone. Most of the time these turn out to be perfectly innocent: a smart plug, a thermostat, a games console using a randomised address. But you cannot be confident about that until you have checked. Learning to find unknown devices on your Wi-Fi, identify what they are, and remove anything that does not belong is a skill worth having, and none of it requires paid software.

Wi-Fi router in a home used to check the list of connected network devices

Signs Something May Be On Your Network

Unauthorised users rarely announce themselves, but a few symptoms are worth noticing. Internet speeds that sag at unpredictable times, unexplained data usage on a metered connection, and Wi-Fi that feels congested despite few devices being in use can all point to extra traffic. More serious signals include DNS settings you did not change, a router admin password that suddenly does not work, or devices connecting to networks you do not recognise.

Be careful about jumping to conclusions, though. Cloud backups, console game updates and streaming devices refreshing content all generate large bursts of traffic at odd hours. Investigate the device list before assuming an intrusion.

Step by Step: Auditing Your Connected Devices

  1. Log into your router. Find the gateway address by running ipconfig on Windows or checking Network details on macOS, then enter it in a browser and sign in.
  2. Open the client list. Look for Attached Devices, Connected Clients, Device List, DHCP Clients or Device Manager depending on the vendor.
  3. Record everything. Copy the whole list into a text file or spreadsheet, noting device name, IP address, MAC address and connection type for each entry.
  4. Take inventory of what you own. Walk through the house and count every connected item: phones, tablets, laptops, desktops, printers, TVs, streaming sticks, consoles, speakers, cameras, doorbells, thermostats, plugs, bulbs, watches, e-readers and anything else with a radio. Most households badly underestimate this number.
  5. Match the obvious entries. Devices reporting friendly names usually identify themselves clearly. Tick them off.
  6. Investigate the rest by MAC address. The first six characters of a MAC identify the manufacturer. Search that prefix in any online MAC vendor lookup and you will often get a definitive answer, such as a chipset maker used by a specific brand of smart plug.
  7. Use the switch-off test. For anything still unidentified, power down one suspect device at a time and refresh the client list. The entry that disappears is that device.
  8. Check each device’s own settings. Phones, laptops and consoles all display their Wi-Fi MAC address in network or about screens. Compare directly against your unknown entries.
  9. Look at connection details. Signal strength, band and connection time give useful hints. A device with a persistently weak signal that is always connected may be outside your walls.
  10. Decide on anything left over. If an entry survives all of the above, treat it as untrusted and move to the lockout steps below.

Free Tools That Make This Easier

The router list is authoritative but often poorly presented. Several free scanners give a clearer picture from a computer or phone on the same network.

  • Network scanner apps for phones sweep the local address range and report every responding device with its vendor, hostname and open ports. They frequently identify things the router shows as blank.
  • Desktop scanners offer more detail, including which services each device is running, which is useful for distinguishing a camera from a printer.
  • Your router’s own app. Many vendors provide a mobile app with friendlier device naming and push notifications when a new device joins, which is far more useful than periodic manual checks.
  • The ARP table. On any computer, running arp -a lists devices your machine has recently communicated with, a quick cross-check against the router list.

Notification-on-join is the feature worth prioritising. Catching an unfamiliar device the moment it connects beats discovering it during an audit months later, and it is a standard capability on the models in our best secure Wi-Fi routers roundup.

Network cables and equipment used to scan and secure a home Wi-Fi network

Why MAC Randomisation Confuses the Picture

Modern phones, tablets and laptops generate a random private MAC address for each network they join, and some rotate it periodically. This is a privacy feature that prevents tracking across public networks, but on your own network it produces exactly the symptom you are hunting: unfamiliar hardware addresses that resolve to no known vendor.

Before panicking about an unknown entry, check whether the household’s phones have private addresses enabled for the home network. On most devices you can turn this off per network, which is sensible at home since you already control the network. Doing so makes future audits dramatically easier and also lets DHCP reservations and parental controls work reliably.

Locking Out Anything That Does Not Belong

If you conclude a device is genuinely unauthorised, resist the temptation to simply block its MAC address. MAC filtering is trivially defeated because addresses can be spoofed, and it gives false confidence. The reliable fix is to change the credential the intruder is using.

  1. Change the Wi-Fi password to a long unique passphrase. This immediately disconnects everything, authorised or not.
  2. Change the router admin password too. If someone reached your network, assume they tried the admin page as well.
  3. Upgrade the encryption to WPA3, or WPA2 with AES as a minimum. Anything on WEP or TKIP should be changed without delay.
  4. Disable WPS. Push-button pairing is a common entry route and is rarely needed after initial setup.
  5. Turn off remote administration so the settings page cannot be reached from the internet.
  6. Update the firmware to close any known vulnerabilities in the router itself.
  7. Reconnect your own devices one at a time with the new password, keeping a list as you go.
  8. Re-audit after a day and confirm the unknown entry has not returned.

If it does return after a full password change, that points at a device inside your home rather than an outside intruder, most likely something you own that you have not correctly identified yet.

Preventing the Problem Long Term

A one-off audit is useful, but a few structural changes stop the question recurring.

Rename your devices

Most devices let you set a friendly hostname, and many routers let you assign a label to a client entry. Spend twenty minutes naming everything clearly and the next audit takes two minutes instead of an hour.

Use a guest network for visitors and smart gear

Visitors never need access to your main network, and neither do most smart bulbs and plugs. Putting them on an isolated guest network keeps your primary device list short and limits what a compromised gadget can reach.

Reserve addresses for permanent devices

Giving printers, servers and cameras fixed addresses through DHCP reservation makes the list stable and predictable, so anything on a dynamic address stands out.

Enable monitoring and controls

Routers with device-level visibility, scheduling and per-device blocking make ongoing supervision genuinely easy, which is the strength of the models in our best parental control routers guide. For deeper inspection and intrusion prevention, the units covered in our best firewall routers roundup add active threat blocking rather than just reporting.

Audit on a schedule

Once a quarter is plenty for most homes. Pair it with a firmware check and you cover both halves of router maintenance at the same time. Our broader guide to securing a home network from hackers sets out the full checklist, and stepping up to hardware from our best WPA3 routers list closes the encryption gap for good.

Common Mistakes to Avoid

The biggest is relying on MAC filtering as a security control. It is an administrative convenience, not a defence. The second is assuming every unrecognised name is hostile, when the overwhelming majority are your own smart devices reporting chipset identifiers instead of product names. The third is changing the Wi-Fi password while leaving the admin credentials at their defaults, which leaves the more valuable door open. And the fourth is doing one thorough audit, feeling reassured, and never looking again.

Troubleshooting

The router list shows devices that are switched off

Many routers display recent leases rather than live connections. Look for a filter showing only currently connected clients, or reboot the router to clear stale entries.

A scanner finds devices the router does not list

Usually devices connected through a mesh node or a secondary access point that reports separately. Check each node’s own client list.

The same unknown MAC keeps reappearing

Almost always a device with rotating private addresses. Disable that feature on household devices and watch whether it stops.

You cannot tell two identical devices apart

Power one down and refresh the list, then rename the one that remains before restoring power to the other.

Frequently Asked Questions

How many devices should a typical home have?

More than most people expect. Households commonly run between 20 and 40 connected devices once smart bulbs, plugs and sensors are counted.

Can someone use my Wi-Fi without appearing in the list?

Not while connected normally. Anyone using the network holds a lease and shows up, though a stale or filtered view can hide them.

Is blocking a device enough if I find an intruder?

No. Change the Wi-Fi and admin passwords, since blocking only stops that specific address and it can be changed in seconds.

Do smart devices really need their own network?

It is strongly advisable. Inexpensive connected gadgets receive limited security updates, and isolating them limits the damage if one is compromised.

Final Thoughts

Auditing your network is less about catching intruders, which is rare, and more about actually knowing what you own and how it is connected. Pull the client list, inventory your hardware, resolve the remainder through MAC vendor lookups and the switch-off test, and name everything as you go. If something genuinely does not belong, change both passwords rather than filtering an address. Then make it stick with a guest network for visitors and smart gear, fixed addresses for permanent devices, and a quarterly check alongside your firmware update. Do that and the unfamiliar entries that prompted this search will be a solved problem for the rest of 2026, not a recurring source of unease.

7