It usually starts with a line in the router’s client list that nobody recognizes: 192.168.1.87, hostname blank, manufacturer “Unknown”. Nine times out of ten it turns out to be a smart plug, a printer that woke up, or a phone using a randomized Wi-Fi address. The tenth time it is a neighbor who still has your old Wi-Fi password. Either way, you want an answer you can trust, and you want it without guessing.
This walkthrough is for a network you own or have been asked to look after: your home, your small office, a client site where you have written permission. We treat it like surveying a plot of land: first collect the landmarks you already know, then chase down whatever is left on the map.
Before you scan: Everything below involves looking at devices on a network. Do it on networks you own or administer. Scanning someone else’s network without permission can breach acceptable-use terms and, in many places, the law.
Step 1: Start with what the router already knows
Your router hands out addresses through DHCP, so it keeps the most complete list of who has joined recently.
- Open a browser and go to your router’s address. Common defaults are
192.168.1.1,192.168.0.1and10.0.0.1; the label on the underside of the router usually says which. - Sign in with the admin credentials (not the Wi-Fi password, unless they happen to match).
- Look for a page named Attached Devices, DHCP Clients, Client List or LAN Status. Mesh systems such as Eero, Deco or Nest Wifi show the same list inside their phone app instead.
- Write down, or screenshot, the IP address, MAC address and hostname of the device you don’t recognize. The MAC address is the most useful of the three.
Many routers also show when each device connected and whether it is on 2.4 GHz, 5 GHz or wired. That alone can narrow things down: a wired unknown is physically plugged into something in your building.
Step 2: Confirm the address from a computer
If you’re not near the router admin page, any computer on the same network can list its recent neighbors from the ARP cache. Ping the suspect address first so the cache is fresh, then read it.
On Windows:
ping 192.168.1.87
arp -a
On macOS or Linux, arp -a works the same way; on Linux, ip neigh gives a tidier view. Each line pairs an IP with a MAC address. If the mystery IP shows up with a MAC, the device is alive and on your local segment right now.
Windows can sometimes resolve a name too:
ping -a 192.168.1.87
nbtstat -A 192.168.1.87
nbtstat only answers for devices that speak NetBIOS, which mostly means Windows PCs and some NAS boxes, but when it works it hands you the computer name and workgroup.
Step 3: Read the MAC address like a label
The first three bytes of a MAC address (the OUI) are assigned to a manufacturer. 3C:22:FB or F0:18:98 point to Apple, B8:27:EB and DC:A6:32 to Raspberry Pi, 18:B4:30 to Nest, and so on. Paste the first half into any OUI lookup site, or let a scanner do it for you.
One catch trips up nearly everyone: randomized MAC addresses. iOS, Android and Windows 10/11 can use a “private” address per network. You can spot one by the second character of the first byte: if it is 2, 6, A or E (for example DA:4F:... or A6:...), the address is locally administered and no vendor lookup will match it. That’s almost always a phone, tablet or laptop, not an intruder. Check the Wi-Fi settings on your family’s phones; each one shows the private address it uses for your network.
Step 4: Scan the whole segment with Fing
When there are several unknowns, a scanner saves time. Fing is the gentlest option for non-specialists: the mobile app scans the network your phone is on and classifies devices by type, brand and model using its own recognition database, which regularly turns “Unknown” into “Amazon Echo Dot” or “HP LaserJet”.
- Get the Fing app from the App Store or Google Play, or the desktop app from the vendor’s site (see /where-to-get for how to verify what you install).
- Connect your phone to the network you want to map, then tap Scan for devices.
- Tap the mystery entry. Fing shows the vendor, any open services it noticed, and when it was first seen.
- Rename the device once identified, so the next scan shows “Kitchen speaker” instead of an address.
If you prefer a Windows desktop tool, Advanced IP Scanner and Angry IP Scanner both list IP, hostname, MAC and vendor for a whole range in under a minute on a typical /24. Our IP scanners category compares the options side by side, and Advanced IP Scanner vs Angry IP Scanner covers the most common choice.
For people comfortable in a terminal, a ping sweep with Nmap does the same job:
nmap -sn 192.168.1.0/24
Run it with administrator rights on the local subnet and Nmap also prints MAC vendors.
Step 5: The unplug test
If a device still won’t identify itself, use the oldest trick in the field guide: remove candidates one at a time.
- Note the time and keep the router client list (or Fing) open.
- Switch off or unplug one suspect: a TV, a smart plug, the printer.
- Refresh the list after a minute. When the mystery entry drops off, you’ve found it.
For wired unknowns, look at the port lights on your switch while you unplug cables.
Step 6: If it really isn’t yours
Suppose the device survives every test and nobody in the house or office owns it. Don’t try to probe it further. Instead:
- Change the Wi-Fi password (and use WPA2-AES or WPA3, not WEP or open networks).
- Turn off WPS on the router; it is a common weak spot.
- Use the router’s Block or Pause option on that MAC as a short-term measure. Remember that a determined visitor can change MAC, so the password change is the real fix.
- Update the router’s firmware and change the admin password if it’s still the default.
Common mistakes
- Assuming “Unknown vendor” means an intruder. Randomized MACs from your own phones are the usual cause.
- Scanning from a guest network. Guest Wi-Fi is often isolated, so you’ll see only yourself. Connect to the main network first.
- Trusting hostnames blindly. A hostname is whatever the device announces; the MAC plus the unplug test is stronger evidence.
- Blocking before identifying. Blocking an unfamiliar MAC can knock the thermostat or the alarm panel offline. Identify first, then decide.
Once every device has a name, keep the list. Our guide to building a device inventory spreadsheet turns a one-off hunt into a map you can check against next month, and Discovery & Inventory tools covers options if you want that done automatically.