Log into your router's admin page — the address is your default gateway, typically something like 192.168.1.1 or 192.168.0.1, but verify yours first rather than guessing. Once inside, look for a section labelled Connected Devices, DHCP Client List, or Attached Devices. That table shows every device your router has handed an IP address to, along with its MAC address and hostname. If you spot something you cannot account for, the most common explanation is MAC address randomisation on your own phone — not an intruder.

Step 1: Find Your Router's Admin Address

Do not assume the router address. Look it up directly on the device in front of you right now.

Windows

Open Command Prompt and run:

ipconfig /all

Scroll to the Wi-Fi adapter section and read the Default Gateway line. Type that address into your browser's address bar — not the search bar.

macOS

networksetup -getinfo Wi-Fi

The output includes a Router: line with the address. Alternatively:

netstat -nr | grep default

The IP on the row labelled default is your gateway.

Linux

ip route show default

The address following via is your gateway. To check which DNS resolver your machine is using at the same time:

resolvectl status

iOS

Settings → Wi-Fi → tap the connected network name → scroll down to the Router field.

Android

Settings → Wi-Fi → tap the network name → look for Advanced or Network Details → find the Gateway field. The exact path varies by manufacturer and Android version — if you cannot find it, install a basic network info app that exposes the gateway IP.

Tip: If the gateway address shown starts with 100.64, your ISP is using carrier-grade NAT (CGNAT). Your home router still has a private address in the 192.168.x.x or 10.x.x.x range — that is what you log into. The 100.64 address sits between your router and the ISP and is not something you administer.

Step 2: Log In to the Router Admin Panel

Type the gateway IP address into your browser's address bar — not the search bar. Press Enter. The router login page should appear. The default username and password are printed on a sticker on the bottom or back of the router. If those credentials have been changed and you no longer know them, a factory reset restores the defaults: hold the recessed reset button for roughly 10–15 seconds until the lights change, then power-cycle the unit. Check your router's documentation for the exact procedure, as it varies by model.

Common admin addresses by router brand — always verify against the label on your specific unit, since firmware revisions and regional variants can differ:

  • TP-Link: 192.168.0.1 or tplinkwifi.net
  • ASUS: 192.168.1.1 or asusrouter.com
  • Netgear: 192.168.1.1 or routerlogin.net
  • Linksys: 192.168.1.1 or linksyssmartwifi.com
  • Netgear Orbi: 192.168.1.1 or orbilogin.com
  • Xiaomi (MiWiFi): 192.168.31.1 or miwifi.com
  • Any other brand: Use the exact gateway address from Step 1

On routers running open-source firmware: OpenWrt defaults to 192.168.1.1 with the LuCI web interface. DD-WRT also typically uses 192.168.1.1, but a previous admin may have changed the subnet. Both platforms can also be managed over SSH if the web interface has been disabled.

Step 3: Find and Read the Connected Devices List

Every router firmware has a list of current DHCP leases somewhere in the interface. The menu label varies — look for any of these:

  • Connected Devices
  • DHCP Client List
  • Client List
  • Attached Devices
  • Network Map
  • Device Manager
  • LAN → DHCP Clients (common on ASUS routers)

On OpenWrt: go to Status → Overview and scroll to Active DHCP Leases, or navigate to Network → DHCP and DNS → Active Leases.

On DD-WRT: go to Status → LAN and scroll down to the DHCP Clients table.

The table will typically include these columns:

  • IP Address — the address DHCP assigned to this device
  • MAC Address — the hardware identifier of the network adapter
  • Hostname — the name the device advertised when requesting a lease
  • Lease Expiry — when the IP assignment expires (usually 24 hours or 7 days)
  • Connection Type — wired vs. wireless, shown on some firmware only

How to Identify Each Device in the List

By hostname

Many devices broadcast recognisable hostnames when they connect. An iPhone might appear as Johns-iPhone, a Windows PC as DESKTOP-7KF2AB, a Chromecast as Chromecast-Living-Room. Blank hostnames or random-looking strings are common on IoT devices — many smart bulbs, plugs, and cameras simply do not advertise a readable name. A blank hostname is not by itself suspicious.

By MAC address prefix (OUI lookup)

The first three octets of a MAC address — called the OUI, or Organisationally Unique Identifier — identify the manufacturer. For example, a MAC starting with B8:27:EB or DC:A6:32 is a Raspberry Pi Foundation device. Use the DNS Lookup tool or any public OUI registry to paste in the first six hex characters of a MAC address and get back the manufacturer name. This quickly distinguishes an Amazon Echo from a Samsung phone from a Hikvision camera.

The MAC randomisation problem

Modern phones use private or randomised MAC addresses by default on Wi-Fi. This privacy feature was introduced in iOS 14, Android 10, and Windows 10 version 1903, and it is enabled by default on all three. The MAC your phone presents to the router is not its real hardware MAC — it changes periodically and looks like a random device to anything reading the DHCP list. The result: your own phone can appear in the list as an unknown device, especially if it disconnected and reconnected with a new random MAC while the previous lease has not yet expired, creating two entries for the same phone.

Before treating any unknown entry as evidence of an intruder, disable MAC randomisation on every device you own, have them reconnect, and reload the router's device list. The majority of unexplained entries resolve at this step.

How to disable MAC randomisation:

  • iPhone / iPad: Settings → Wi-Fi → tap the network name → set Private Wi-Fi Address to off
  • Android: Settings → Wi-Fi → tap the network name → Privacy (or Advanced on older versions) → set to Use device MAC. Path varies by manufacturer — some put it under Network Details or Connection Details
  • Windows 11: Settings → Network and Internet → Wi-Fi → Manage known networks → select the network → set Random hardware addresses to off
Tip: If a device appears in the router's connected list but cannot reach the internet or resolve hostnames, the problem is often a bad DNS server address being handed out by DHCP rather than an access issue. Use our DNS Propagation Checker to confirm external DNS is working, then check what DNS server address your router is advertising in its DHCP settings.

CLI Verification: Go Beyond the Router's DHCP List

The router admin panel only shows devices that obtained an address via DHCP. Devices with manually configured static IP addresses will not appear there, even though they are fully active on your network. The following CLI tools find everything.

ARP table — all platforms

The ARP cache on your machine records every device it has recently exchanged packets with at layer 2:

arp -a

Entries listed as dynamic are real devices. The scope is limited to devices your machine has recently communicated with — combine it with a ping sweep below to populate it fully.

Ping sweep then ARP (Linux / macOS)

ping -b -c 3 192.168.1.255 arp -a

The broadcast ping wakes up all responsive devices on the subnet. Replace 192.168.1.255 with the broadcast address for your subnet — if your subnet is 192.168.0.0/24, use 192.168.0.255. Then dump the ARP cache to see who replied.

nmap host discovery

nmap is a standard network auditing tool included in most Linux distributions and available for macOS via Homebrew and for Windows via the official installer. A basic discovery scan across the entire subnet:

sudo nmap -sn 192.168.1.0/24

The -sn flag runs host discovery without a port scan, so it completes in seconds. Running as root or Administrator enables ARP-based discovery and includes MAC addresses with manufacturer names in the output. Replace 192.168.1.0/24 with your own subnet. This will find both DHCP-leased and statically addressed devices.

Linux: ip neigh

ip neigh show

The state column indicates freshness: REACHABLE means the entry was confirmed active recently; STALE means it has not been confirmed but is still cached; FAILED means the host did not respond to an ARP probe.

Windows PowerShell

Get-NetNeighbor -AddressFamily IPv4 | Where-Object State -ne Unreachable

Query the router's local DNS

If your router runs a local DNS resolver — which most do — you can resolve device hostnames directly:

nslookup johns-iphone.local 192.168.1.1 dig @192.168.1.1 johns-iphone.local

Replace the hostname with one from the DHCP list and the IP with your router's address. This works reliably on ASUS, OpenWrt, and pfSense setups. It is hit-or-miss on ISP-supplied routers.

What to Do When You Find an Unknown Device

  1. Run the MAC randomisation check first. Disable private MAC on every device you own, reconnect them, reload the device list. This resolves most unknown-device cases.
  2. Account for all smart home devices. Smart plugs, bulbs, cameras, doorbells, thermostats, voice assistants, and streaming sticks all appear in the list. Walk through your home and count them. Most households have significantly more connected devices than they realise.
  3. Check whether a neighbour joined accidentally. In apartments or townhouses, a neighbour may have connected to your network — particularly if the Wi-Fi password is still the ISP default, which is a short numeric string in many cases.
  4. Change the Wi-Fi password immediately if you still cannot account for a device after the above steps. Do this before any further investigation so the unknown device loses access now.
  5. Upgrade encryption if needed. WPA2-AES is the minimum acceptable standard in 2026. WEP and WPA-TKIP are both cryptographically broken and should not be used on any network.
  6. Block the MAC address via the router's access control or MAC filter list if the device reappears after a password change. This is not a hard security boundary — MAC addresses can be spoofed — but it stops unsophisticated access.
  7. Enable a guest network for IoT devices. Isolate smart home devices on a separate SSID so that a compromised camera or bulb cannot reach your laptop, NAS, or other sensitive devices.

Common Misdiagnoses

"There are more devices than I own"

Almost always MAC randomisation. The same phone can appear two or three times if it reconnected with a different random MAC while the old lease has not yet expired. Both entries point to the same device. Disable MAC randomisation on your own phones, reconnect them, and the duplicates will collapse.

"A device disappeared from the list"

DHCP leases expire. Once a device is powered off or enters deep sleep, it stops renewing its lease. When the lease lifetime runs out — typically 24 hours or 7 days depending on the router's configuration — the entry is removed. This is expected behaviour. If you want devices to always show up, assign them static DHCP reservations (sometimes called IP binding or address reservation) in the router settings.

"I see a 169.254.x.x address"

An address in the 169.254.0.0/16 range is an APIPA (Automatic Private IP Addressing) self-assigned address. The device sent DHCP requests and got no response, so it assigned itself a link-local address as a fallback. This means the device cannot reach the router's DHCP server — it is a connectivity problem on that device, not a sign of an intruder. Troubleshoot its Wi-Fi connection separately.

"The device list is empty but I can see devices are connected"

Many router firmwares separate wireless and wired clients into different sections. Check both the wireless client tab and the wired or LAN section. Also note that devices configured with a static IP address bypass DHCP entirely and will never appear in the DHCP lease table — only in the ARP table and in nmap scans.

Prevention: Keeping Unauthorised Devices Off Your Network

  • Use WPA3 where supported, or WPA2-AES at minimum. WEP and WPA-TKIP are broken and trivially crackable.
  • Set a strong, unique passphrase. Aim for 16 or more random characters. A dictionary word or the ISP's four-digit default gives almost no protection.
  • Change the router admin password from the factory default. Default credentials are compiled in public databases and are the first thing an attacker tries.
  • Disable WPS PIN mode. The eight-digit WPS PIN is vulnerable to brute-force attacks. The push-button method is comparatively safe but worth disabling if you never use it.
  • Keep firmware updated. Enable automatic firmware updates in the router admin panel. Regular updates patch known security vulnerabilities.
  • Use a separate SSID for IoT devices. Many routers support a guest network or VLAN. Placing cameras, smart bulbs, and thermostats on a separate network prevents a compromised device from reaching your computers or storage.

2026: IPv6, Privacy Extensions, and Encrypted DNS

IPv6 changes device enumeration in two ways. First, devices on a dual-stack network may have multiple addresses simultaneously: a link-local address starting fe80::, a global unicast address from your ISP, and possibly a ULA address starting fd. Most router admin pages only display IPv4 DHCP leases. To enumerate IPv6 neighbours from the command line:

ip -6 neigh show netsh interface ipv6 show neighbors ndp -an

The first command is Linux, the second Windows, the third macOS.

Second, IPv6 privacy extensions — described in RFC 4941 — rotate a device's global IPv6 address on a schedule similar to MAC randomisation but at the IP layer. A single device may appear in logs with several different IPv6 source addresses over the course of a week. This is normal privacy behaviour, not evasion.

DNS over HTTPS (DoH) and DNS over TLS (DoT) do not affect which devices show up in the DHCP list, but they do affect your router's visibility into DNS queries. If a device bypasses the router's DNS server by using an encrypted public resolver, the router's DNS log will not record those lookups. This breaks DNS-based parental controls and monitoring solutions that rely on seeing all queries. OpenWrt and ASUS Merlin firmware both support firewall rules that intercept port 53 and 853 traffic and redirect it through the router's own resolver, restoring that visibility even when clients request encrypted DNS.