In this article
The next step depends on the question. “Is my printer connected to this access point?” calls for different evidence from “Does this Mac currently have an address mapping for the printer?” Comparing those answers is useful; expecting their lists to match exactly is not.
Check the router’s list and its meaning
Use your router or access point’s documented app or management interface. If you need the router address, Apple’s TCP/IP settings guide points to System Settings → Network → your connection → Details → TCP/IP. Read the setting; you do not need to change it.
Look at what the router actually calls the list. A wireless association list concerns clients joined to an access point. A DHCP lease list concerns assigned addresses. A vendor’s “devices” page may combine current and remembered observations.
Those are different records. A retained lease can outlast a device’s current activity, and a manually configured address need not appear among DHCP assignments. Mesh nodes, guest networks and separate access points may have separate views. Consult the model’s documentation before interpreting an absent entry.
What the Mac’s cache is for
ARP resolves a network address to a link-layer address for local delivery. The protocol is described in RFC 826. The Mac’s arp command displays the mappings currently available in its translation table.
A cache is populated as networking needs arise; it is not a registration ledger for everyone nearby. It can learn mappings from received ARP traffic as well as resolution initiated by the Mac. Entries can change or expire. Therefore, “the Mac has not recently needed a mapping” is a possible explanation for absence, not proof that the device is disconnected.
For a destination reached through a router, local delivery uses the next hop. The remote internet server is not an Ethernet neighbor on your Wi-Fi. Ubiquiti’s ARP explanation illustrates why each local link has its own address-resolution step.
If you are investigating an app’s internet destinations, use the separate process-and-connection workflow. A local neighbor table does not replace an app’s socket listing.
Read IPv4 and IPv6 separately
For a numeric, read-only IPv4 listing, open Terminal and run:
/usr/sbin/arp -an
Here, -a lists current entries and -n keeps addresses numeric. Read the interface alongside the address. A Mac can have multiple network interfaces; do not assume every row belongs to the Wi-Fi connection you meant to inspect.
IPv6 uses Neighbor Discovery, defined in RFC 4861, rather than the IPv4 ARP mechanism. On macOS, inspect its current neighbor table separately:
/usr/sbin/ndp -an
The installed man arp and man ndp pages describe these options and the displayed states. The NDP manual distinguishes reachable, stale, incomplete and other states. A stale entry is not an authoritative declaration that a physical device has left the network.
Neither command above scans an entire subnet or changes the cache. Do not add deletion or modification flags merely to make the list look cleaner. Also avoid adding the two row totals together: address entries are not a count of unique physical devices.
A dated observation: seven rows did not mean seven devices
On September 25, 2026 at 08:10 UTC, we ran /usr/sbin/arp -an on macOS 15.7.5. We classified the output before saving it, removing addresses and hardware identifiers from the retained record.
| Classification in this snapshot | Rows |
|---|---|
| Resolved entries other than IPv4 multicast or broadcast-MAC rows | 6 |
| IPv4 multicast entry | 1 |
| Incomplete entries | 0 |
| Entries with the all-ones broadcast MAC address | 0 |
| Total output rows | 7 |
A multicast address represents a group destination, not an extra phone or printer. This one observation is enough to show why counting every output line as a device gives an unsound result.
It does not establish that six physical devices were present, identify their owners or measure how many devices were missing. We did not compare against a verified inventory, ping a subnet or alter the cache. Treat the table as an example of classifying evidence, not a benchmark for network discovery.
Investigate one missing device
Keep the check specific. Choose a known device you own or administer and record what you expect to see.
- Confirm its connection. Check the device’s own network settings and the appropriate router or access point view. A similar network name alone does not establish that both devices share the same local segment.
- Check the address family. An IPv6 neighbor belongs in the IPv6 investigation; an empty IPv4 result cannot settle that question.
- Compare the interface and time. Note which Mac connection you inspected and when. A remembered router entry and a current Mac cache are not simultaneous observations.
- Check separation. Guest-network isolation, VLANs or another routed segment can prevent direct neighbor visibility. A VPN can also change which path you are examining.
- Record the remaining uncertainty. “Not present in this cache at this time” is a useful result. “Not on the network” needs additional evidence.
If you use a local discovery application, check its macOS privacy access where relevant. Declared capabilities and granted permissions are different facts; a capability list alone does not show that discovery succeeded.
There is no need to start by probing every address in a guessed 192.168.1.0/24 range. Your network may use another address range or subnet size, and a broader scan still cannot promise to see a sleeping or isolated device.
Understand the limits of a local-device view
VaultDog’s Network Watch includes observations of visible local devices. Its current discovery action is scoped to the current private IPv4 /24; it does not enumerate every subnet or provide a complete list of devices across guest networks, VLANs and IPv6.
The getting started guide explains where this view fits alongside app connection inspection. Use it to organize what was visible and when, then cross-check a missing device against the relevant network equipment. A recognizable name or a recent observation helps investigation; neither guarantees identity, safety or complete coverage.


