Guide

Unknown devices on a Wi-Fi network

An unidentified device on a network is normal and is almost always mundane. Most everyday equipment publishes no useful name, advertises no services, and answers on no recognisable ports — so a scan sees an address that responds and nothing more. "Unknown" is a statement about the information available to the scanner, not about the device.

If you have just scanned a home or rental network and found six things you cannot account for, that is the ordinary result. This guide explains why, what the small amount of information you do get actually means, and how to narrow an unknown down without leaping to a conclusion.

Why networks are full of unidentifiable devices

Count what is on a typical household network: a router, a range extender or mesh node or two, a television, a streaming stick, a games console, a printer, a couple of smart bulbs or plugs, a speaker, a thermostat, a robot vacuum, a doorbell, phones and laptops belonging to people who live there, and a smart watch. Fifteen to twenty-five addresses is unremarkable.

Now consider what each of those tells a scanner about itself. Some publish a friendly name over Bonjour and are instantly recognisable. Many publish nothing at all — they connect, get an address, talk outward to their manufacturer's servers, and never announce themselves locally. A smart plug has no reason to advertise a service to other devices in the house, so it does not.

There are further reasons an address looks anonymous:

On iOS specifically

iOS does not give apps access to the ARP table, which is where hardware addresses live. That means no app on your iPhone can look up a device's manufacturer from its hardware address the way a desktop scanner can. Anything an iOS app tells you about a device's maker has been inferred from a published hostname or service, if there is one. This is a real limit, and it is why iOS scans show more unknowns than desktop ones do.

What a device name actually tells you

Names are self-declared. A device chooses what to call itself, and there is nothing verifying it. A name is a hint of varying quality:

Reading a hostname
What you seeWhat it is worth
A clear consumer name, e.g. a TV or printer model Usually accurate. Manufacturers have no motive to mislabel a television. Reasonably trustworthy, and easy to confirm by looking at the device in the room.
A camera-suggestive name such as IPC- or NVR- or something containing "cam" Genuinely worth investigating, especially alongside an open video port. Still not a conclusion — it could be a declared doorbell or an exterior camera.
A generic string, a serial number, or a manufacturer prefix with digits Very little. Extremely common on smart-home equipment of every kind.
No name at all Nothing. This is the single most common result and carries no information in either direction.

The asymmetry matters: a suspicious name is meaningful because harmless devices rarely adopt one, but a harmless name proves nothing, and no name proves nothing at all.

What an open port actually tells you

An open port means a device is running a service that accepts connections on that port number. Port numbers are conventions, not guarantees — anything can listen on any port.

The reasoning that holds up is combination. One open web port on an unnamed device is noise. An RTSP port plus a Bonjour _rtsp._tcp advertisement plus a camera-suggestive name, on a device that was not there yesterday, is a coherent picture worth acting on — by going and looking at the room, not by concluding anything from the screen.

How to reason about an unknown without panicking

  1. Account for what you own first. Work through your own devices and the property's obvious equipment and tick them off. Most unknowns resolve here.
  2. Check the count against the room. How many connected things can you actually see? Televisions, speakers, bulbs, thermostats, a doorbell, a printer. If the numbers roughly match, the unknowns are probably those objects failing to introduce themselves.
  3. Scan again later. A second scan a few hours apart separates permanently present devices from sleeping ones and passing phones. A device present in both scans, at the same address, is a fixture.
  4. Look at the indicators together, not one at a time. A device with several camera-related signals is a different proposition from a device with one.
  5. Turn things off, one at a time — but only equipment you control or are permitted to switch off, such as unplugging your own laptop or asking a host about a device. Rescan and see what disappeared. This is the most reliable way to attribute an address to a physical object.
  6. Take the shortlist into the room. If something still looks camera-shaped after all that, the next step is a visual inspection of the rooms where such a device would have a sightline. See the hotel guide or the rental guide.

Two things not to do. Do not try to log in to, probe aggressively, or interfere with a device you do not own — that is unlawful in most jurisdictions regardless of what you suspect. And do not scan a network you were not given access to.

Hotel networks are a special case

On most hotel Wi-Fi you will see almost nothing at all, because hotels run client isolation to stop guests reaching each other's laptops. That is good security and bad visibility: an empty scan in a hotel is the expected result and tells you nothing about whether devices exist. Do not read it as reassurance. In hotels, the visual inspection carries the weight.

Rentals are the opposite. You are usually on the household's ordinary network with no isolation, so a scan is genuinely informative — and correspondingly full of ordinary unknowns.

What Findy can help with

The network scanner requires the subscription, $39.99 per year in the US.

What Findy cannot determine

The complete limitations.

Related guides

Last reviewed 2026-07-23 · Written and reviewed by the Findy developer.