Who Is Connected to My Wi-Fi: How to See and Kick Off Strangers
You know the feeling: it’s evening, the movie keeps buffering, pages take half a minute to load, and your video call dissolves into a mosaic. Your first thought is “the ISP is slacking off again.” But sometimes the cause is closer than you think — someone uninvited has joined your Wi-Fi and is happily torrenting or streaming on your dime. A neighbor you once gave the password to “just for a minute,” or, in the worst case, someone who simply guessed a weak one.
The good news: finding out who is connected to your Wi-Fi takes about five minutes, and kicking off strangers takes even less. In this article we’ll walk through how to see the list of connected devices, how to tell your own gadgets from someone else’s, how to reliably boot uninvited guests, and — honestly — why the trendy advice to “just turn on MAC address filtering” works far worse than it’s made out to be.
Signs that someone is freeloading on your Wi-Fi
Before diving into settings, it helps to know whether there’s a reason to worry. Indirect signs of an intruder:
- The internet is consistently slow even though your plan promises more — especially during hours when you yourself are barely downloading anything.
- The router stays hot and its lights keep blinking even when all your devices are off or asleep.
- The list of connected clients shows more devices than you can account for. This is the most reliable sign, and exactly the one we’ll learn to check.
- The password suddenly stops working or settings reset themselves — a worrying signal that someone has gotten into the router itself.
One honest caveat: slowdowns can have perfectly innocent causes — a congested ISP link, weak signal, outdated firmware, a neighbor on the same radio channel. So let’s not guess — let’s just look at the exact list of devices.
How to see the list of connected devices
There are two reliable ways to find out who’s on your Wi-Fi: the router’s admin panel (most accurate) and a network scanner app (fastest).
Method 1. The router admin panel
The router knows about everyone connected to it — that information lives in its web interface. To get there:
- Open a browser on a computer or phone connected to your network.
- Type in the router’s panel address. Most often it’s
192.168.1.1or192.168.0.1— the exact address is usually printed on a sticker on the bottom of the router, along with one liketplinkwifi.netorrouterlogin.netyou can also type into the address bar. - Log in. The admin username and password are, again, on the sticker or in the manual. If you’ve ever changed them (and you should), use yours.
- Find the device list. Different firmware names this section differently: “Connected Devices,” “Client List,” “DHCP Clients,” “Network Map,” “My Devices.” It’s often on the home page or in the Wi-Fi section.
In this list you’ll see every device: its name (if it “introduced itself”), IP, and MAC address. The MAC address is a unique hardware identifier of the network module — like a serial number — in the format A4:B1:C2:33:44:55. That’s what we’ll use to tell your own devices from strangers’.
Method 2. A network scanner app
If you’d rather not dig into the admin panel, there are apps that scan your network and show all connected devices in a friendly view. Popular options are Fing (for phones) or similar network scanners for computers. They show the device list, the manufacturer (the MAC address reveals whose chip it is — Apple, Samsung, Xiaomi, and so on), and sometimes the device type.
A scanner is handy for a quick check, but it only shows what it sees and gives you no way to control access. You can only kick someone off through the router, so either way we’ll come back to the admin panel.
How to identify your own devices
You opened the list and saw, say, 14 devices. Don’t panic: a modern home racks up that many easily. The phones and laptops of everyone in the household, a tablet, a smartwatch, the TV, a set-top box, a speaker, a robot vacuum, a couple of smart bulbs, a camera, a thermostat — there are your fifteen rows. The task is to go through the list and figure out what’s what.
By device name
Many devices honestly report their name. You’ll see readable entries like iPhone-Anna, DESKTOP-7K2L9, Galaxy-S23, LG-TV, HUAWEI-Watch — the simplest way to identify them. Phone and computer names were often set during first setup and are recognizable.
A handy trick: to avoid guessing, turn Wi-Fi off on your devices one by one and watch which row disappears. You turned Wi-Fi off on your phone and iPhone-Anna vanished — so that’s it. This way you can reliably match almost every row to a real gadget in about five minutes.
By MAC address
Some devices introduce themselves vaguely — android-a1b2c3, ESP_4F2A1B, unknown, or just a dash. Here the MAC address helps. Its first three pairs of characters (the OUI) encode the network chip’s manufacturer, and scanners usually label them right away: Espressif (almost certainly your smart plug or bulb), Tuya, Amazon, Sonoff. By matching the manufacturer to what you actually have at home, you’ll identify most “nameless” rows.
It’s worth building a “passport” of your network once: jot down the names and MAC addresses of all your devices in a note. On your next check you compare against it in a minute and instantly spot a stranger.
A nuance: random (private) MAC addresses
Modern phones (iPhones, recent Androids) can use a random MAC address for each network — a privacy feature that makes the device harder to track by Wi-Fi. Because of it, your own phone might “introduce itself” with an unfamiliar MAC, and you’ll mistake it for a stranger. If a row appears and disappears in sync with your phone (test it with the same Wi-Fi toggle), it’s yours. This nuance is also one reason MAC filtering works poorly — more below.
How to kick off strangers
Suppose you went through the list, identified all your devices, and there are one or two rows left you can’t explain. Don’t try to “block this specific device” — that’s a half-measure that’s easy to bypass. The right path is to close off the very ability to connect. Here are the actions in order, from most important to optional.
Step 1. Change your Wi-Fi password (the main action)
Changing the Wi-Fi password instantly disconnects everyone uninvited at once: all connected devices get kicked off, and only those who know the new password can get back in. The most reliable way to boot a stranger:
- In the router admin panel, find the “Wireless” / “Wi-Fi” section.
- Open the security settings and change the password (network key) to something new, long, and unique — at least 12–16 characters, ideally a passphrase of several unrelated words.
- Check the encryption type: it should be WPA2 or, better still, WPA3 (or mixed WPA2/WPA3 mode). If it’s set to outdated WPA or WEP, switch it — those protocols have been crackable for years.
- Save. The router restarts Wi-Fi, and you’ll reconnect your own devices with the new password.
Yes, you’ll reconnect all your home gadgets once — a small inconvenience, but the intruder is disconnected for good, not “until they change their MAC.”
Step 2. Set up a guest network
Often strangers appear not because of hacking, but because you once read the password out to a guest and it got saved in their phone (or passed further). To stop this, never give the main password to guests. Instead, turn on a guest network — a separate Wi-Fi with its own password, isolated from your devices.
Almost every modern router can do this out of the box: in the settings, find “Guest Network,” enable it, set a separate name and password. Now you give guests the guest password — which you won’t mind changing later — while your computers, NAS, and cameras stay on the main network, out of reach of guest devices.
Step 3. Disable WPS
WPS is a “quick connect” feature via a button press or an eight-digit PIN. It sounds convenient, but the PIN is vulnerable to brute-forcing: with a flawed implementation it can be guessed in hours, and then a stranger gets in bypassing your strong password. It’s safer to simply turn WPS off and connect devices by entering the password manually.
Step 4. Check whether anyone got into the router itself
If there were strangers on the network, make sure they didn’t gain access to the router’s control panel. Change the router admin password (not the same as the Wi-Fi password!) if it’s still the factory admin/admin or you’ve given it to someone. While you’re at it, disable remote administration (access to the panel from the internet) — the router should only be managed from your home network.
Should you use MAC address filtering
Here’s where it gets interesting, because this is the #1 tip in most “how to secure your Wi-Fi” articles, and it’s badly overrated.
MAC address filtering is a router feature that lets you build an “allowlist” of permitted MAC addresses: only devices on the list can connect, everyone else is blocked. On paper it sounds like perfect protection — add your devices and that’s it, strangers can’t get in.
In practice it’s weak protection that creates a false sense of security. Here’s why:
- A MAC address is easy to spoof. It’s not a secret key but an ordinary identifier that every device broadcasts over the air in the clear. An attacker with the right software listens to your network, sees the MAC of your allowed device, and with a couple of commands assigns their own adapter exactly the same one. The filter lets them through — they’re “one of yours.”
- The allowed addresses are visible to everyone. Since the MAC is transmitted unencrypted, your entire “allowlist” is essentially public to anyone who listens for a couple of minutes. You hide the lock and leave the key hanging next to it.
- It’s inconvenient for you. Every new phone, tablet, or guest device has to be added by MAC address manually. And because of random MAC addresses (see above), modern phones can change their address on their own, and your own device suddenly stops connecting. A constant headache in exchange for protection that’s bypassed in a minute.
The honest conclusion: MAC filtering is not a lock, it’s a “no entry” sign. It’ll deter a random person who wouldn’t have barged in anyway, but it won’t stop someone who genuinely wants to connect. Real Wi-Fi protection is WPA2/WPA3 encryption and a strong, unique password, not a list of MAC addresses. Keep such a list as a minor extra nuisance if you like — but never rely on it as your main defense.
How to protect yourself going forward
Kicking off strangers once treats the symptom. To keep the problem from coming back, close off the ability for outsiders to connect. The basic habits:
- A strong, unique Wi-Fi password — a long passphrase that can’t be brute-forced or guessed. This is the main lock.
- Modern encryption — WPA3, or at least WPA2. No WEP and no open WPA.
- A guest network for all temporary connections. Guests, repair techs, couriers — give them the guest password. The main password never leaves your family.
- WPS disabled, remote administration disabled, the router admin password changed from the factory default.
- Router firmware updated. Manufacturers patch exactly the holes attackers crawl through. Turn on auto-updates if available.
- Periodic device-list checks. Once a month, compare the router panel against your “network passport” — an anomaly will jump right out.
All of this is part of the bigger home-security picture. Network segmentation, isolating smart devices, encrypting DNS, and backups are covered in detail in a separate guide — How to Secure Your Home Network and Traffic. And if you’re setting up a router from scratch or want to reconfigure it properly, start with How to Set Up a Router.
Frequently asked questions
Can I find out exactly who connected — the person’s name? No. The router only sees devices (name, IP, MAC), not the owner’s identity. You can guess it’s, say, a Samsung phone, but not whose. If there’s a stranger’s device on the network, don’t try to figure out who it is — just change the password.
Can a stranger on my Wi-Fi see my data? If they’re on your main network, potentially yes: devices on the same network can see each other, and a malicious neighbor could try to reach shared folders or intercept unencrypted traffic. One more reason to kick strangers off and keep guests on a separate network.
I changed the password, but strangers showed up again. Why? Most likely the new password is weak or someone learned it. Set a genuinely long, unique passphrase, disable WPS, and make sure you didn’t read it out to outsiders. If it keeps happening even with a strong password, check whether someone got access to the router panel itself, and update the firmware.
Does hiding the network name (a hidden SSID) help? Barely. A hidden SSID doesn’t make the network invisible — it’s still broadcast over the air and easily found with tools. Meanwhile your devices start “searching” for that network everywhere, revealing its name. It’s just as much a myth as MAC filtering — rely on the password and encryption.
Will a VPN protect me from someone sitting on my Wi-Fi? A VPN won’t kick a stranger off — that takes the password and router settings. But a VPN encrypts your own traffic, so even if there’s an outsider on the network (or you’re on someone else’s untrusted one), they can’t peek at what you’re opening. Different layers of protection that complement each other.
The bottom line
Finding out who’s connected to your Wi-Fi is a five-minute job: open the router panel or run a network scanner, and match the device list to your gadgets by name and MAC address. One button kicks strangers off — changing the Wi-Fi password to something long and unique, with WPA2/WPA3 encryption. A guest network and a disabled WPS settle the matter for the future. As for MAC filtering as serious protection — don’t rely on it; a MAC is easy to spoof.
If you also want to protect the traffic itself — so that your ISP and random people on shared networks can’t see which sites you open — take a look at GANVAS VPN: an encrypted tunnel, DNS leak protection, and support for your own configs. You can start for free on the free VPN page. And to check your current IP and what it reveals, use the IP Lookup tool.