can wifi owner see my history can wifi owner see what sites i visit can wifi owner see what i search

Can the Wi-Fi owner see my history? What the router shows

Adrian Maverick · · 10 min read

You are on someone else's Wi-Fi: your parents' router, a roommate's plan, the landlord's building network, a friend's place, a cafe. You want to know whether the person who set up that router can pull up a list of what you looked at.

Short answer: yes, the Wi-Fi owner can see which websites and apps your device connects to, and when, if they look. They cannot see the pages you open, what you search, or anything you type on HTTPS sites. Incognito mode and deleting your history change nothing. A VPN hides the site names too.

Most home routers do not hand the owner a browsing history out of the box, though. What the owner sees depends on the router and on what they have switched on.

What the Wi-Fi owner can and cannot see

Nearly every major site and app now uses HTTPS, which encrypts the content of the connection. The name of the site still travels in the open, because the network needs it to deliver your traffic.

What you do on their Wi-Fi Can the owner see it?
That your device is connected, its name, when, and how much data it uses Yes, in the router's device list
Which sites you visit (the domain, such as reddit.com) Yes, if the router or a monitoring feature records it
Which apps you use Often, from the domains each app contacts
The exact page or video on an HTTPS site No
What you type into Google, YouTube, or any HTTPS search box No
Passwords, messages, card numbers on HTTPS sites No
Anything on a plain HTTP site (rare now) Yes, all of it
Your browser's saved history, in incognito or not No, that lives on your device
Sites you visit with a VPN on No, only that you use a VPN, when, and how much data

So the owner cannot learn what you read on a health site or which video you watched. They can learn that your phone reached that health site at 1am on Tuesday, which may be enough to cause the conversation you wanted to avoid.

Does the router keep a history of the sites I visit?

Less often than most articles claim. It depends on the model and on what the owner turned on. The router makers' own documentation tells you more than any guess.

That third group is what matters. If the person who runs the Wi-Fi uses a parental-control or security app tied to the router, they get a per-device list of sites in a phone app, with no technical skill needed. A technical owner can go further and send every device's lookups to a DNS service that logs them, or capture traffic on a computer. All of these still stop at the site name on HTTPS.

You usually cannot tell from your side which kind of router you are on. Treat the site names as visible and the pages as private.

How the site name gets out

Three parts of every connection give away the domain, and each has a different fix.

  1. The DNS lookup. Before loading a site, your device asks a DNS server to turn the name into an address. On most Wi-Fi the router tells your device which DNS server to use, and the question travels unencrypted. This is the easiest thing for an owner to log.
  2. The first message of the HTTPS connection. Your browser names the site it wants in a field called SNI, in plain text, so anyone on the path can read it. A fix exists: Encrypted Client Hello (ECH), published by the IETF in March 2026 as RFC 9849. Firefox and Chromium-based browsers such as Chrome and Edge support it. Safari is behind: Mozilla's ECH page lists WebKit and Safari as having "indicated support for ECH, but have not implemented it." ECH also works only on sites that have turned it on, and many have not.
  3. The destination IP address. Your traffic has to be sent somewhere. For a site on its own server, the address alone identifies it.

Our post on what your internet provider sees walks through the same three leaks from the ISP's side. The provider sits one step further out than the router and sees the same site names.

Can the Wi-Fi owner see my history on my phone?

Yes, a phone is treated like any other device on the network. The router does not care whether the traffic comes from Safari, Chrome, or an app.

Apps are a little more exposed than people expect. Each app talks to its own servers, so the domains give the app away even though the content stays encrypted. The owner can see that your phone used TikTok or a dating app at a given time. They cannot see your feed, your messages, or who you talked to.

The router's device list also shows the name your phone announces, which can be something like "Maya's iPhone." If you would rather not be that easy to pick out, change the device name in your phone's settings.

Switch to mobile data and none of this applies. Your traffic goes through your carrier and never touches the router.

Does incognito mode or deleting my history hide it?

No. Both act on your device only. Incognito stops your browser from saving history, and deleting history removes what was already saved. Neither changes what leaves your phone or laptop, so the DNS lookups and connections look exactly the same from the router.

Google says so on its own help page: organizations that manage your network "may be able to observe your activity in Incognito." Anything the router or a monitoring app recorded also stays there after you clear your browser. We cover what private browsing is good for in is incognito mode actually private.

Two checks you can run right now

1. See who answers your DNS lookups. On the Wi-Fi in question, open one.one.one.one/help in your browser. It is Cloudflare's test page, and the "AS Name" line shows whose DNS server is answering your lookups. If that is the internet provider behind the Wi-Fi, your device is using the DNS the router handed it, and the lookups are most likely unencrypted. Once you set up encrypted DNS with Cloudflare (step 2 below), the same page should say Yes next to "Using DNS over HTTPS (DoH)" or "Using DNS over TLS (DoT)."

2. Check that nobody set up your device to be read. HTTPS only protects you from the Wi-Fi owner if your device has not been told to trust a certificate of theirs. A router cannot install one by itself. Someone needs your device in hand, or needs you to tap through an install prompt.

  • On iPhone, open Settings > General > VPN & Device Management. If no profile is listed there, none is installed.
  • On Android, open Settings > Security & privacy > More security settings > Encryption & credentials > User credentials. The menu names vary a little by phone maker. It should be empty unless you added something yourself.

If you find a profile or certificate you do not recognize on a device that someone else set up, assume that device is monitored, whatever network it is on.

How to stop the Wi-Fi owner from seeing the sites you visit

Start with the cheapest step. Each one closes a different leak.

  1. Use mobile data for the things that matter. It takes the router out of the picture entirely and costs you only data.
  2. Turn on encrypted DNS and choose the provider yourself. In Chrome, go to Settings > Privacy and security > Security > Use secure DNS and pick a provider from the list. Chrome's default automatic mode can fall back to unencrypted lookups, and a provider you pick does not. On Android, Settings > Network & internet > Private DNS does the same for the whole phone. On iPhone, encrypted DNS comes from an app or a configuration profile. This hides your lookups from the router. It does not hide the SNI field or the IP address, and Chrome notes that secure DNS is unavailable when parental controls are on or the device is managed.
  3. Use a VPN when the site names need to stay private. A VPN puts all of your traffic, DNS included, inside one encrypted tunnel. The Wi-Fi owner sees a single connection to a VPN server, when it started, and how much data moved. For this job, look for two things. The VPN should answer DNS itself inside the tunnel, or you get a DNS leak that hands the site names back to the router. And it should have a kill switch that blocks traffic if the tunnel drops. Secria VPN has both, private DNS and a kill switch, and we keep no activity logs, meaning we do not record browsing, DNS queries or traffic contents. Every connection carries an ML-KEM-1024 post-quantum key. It is $7.99 a month, or included in Pro.

Two limits apply to every option here. The owner can still see that your device is online and how much data it uses, and they can see that you are using a VPN. And none of this hides you from the sites themselves or from accounts you are signed in to. If you share a Google or YouTube account with family, your activity shows up in that account on any network.

FAQ

Can the Wi-Fi owner see what I search on Google? No. Google runs on HTTPS, so the owner sees a connection to google.com and nothing about the words you typed. The sites you click through to afterward show up as their own domains.

Can the Wi-Fi owner see my history if I use a VPN? No. They see that your device is connected to a VPN server, at what times, and how much data moves. The site names stay inside the tunnel as long as the VPN does not leak DNS.

Can my parents see my search history on the Wi-Fi bill? No. An internet bill lists the plan and the charges, and sometimes total data used. It does not list websites or searches. Site names would come from a parental-control app, the router, or a shared account.

Can the Wi-Fi owner see my YouTube history? They can see that your device connected to YouTube, when, and roughly how much data it used. They cannot see which videos you watched or searched for. Your watch history is stored in your Google account.

Can a landlord or roommate see my history on shared Wi-Fi? Whoever has the router's admin login is in the same position as any other owner: site names at most, and only if the router or an app records them. Other people who simply share the password do not get that view.

Being on someone else's Wi-Fi shows them where you went, not what you did there. If where you went is the private part, use mobile data or a VPN such as Secria VPN.

Secria fact-checks every post against primary sources. Spotted something wrong or out of date? Email hq@secria.me and we will correct it.