← All posts Deutsch

Private Wi-Fi Addresses on a Mac: Check the Setting for One Network

A router, access-point log, or network inventory sometimes shows a Mac with a MAC address you don't recognize. You might think the computer's hardware has changed, someone else has joined the network, or a DHCP reservation has stopped working. Often, the explanation is simpler: the Mac is using a private Wi-Fi address for that network.

This guide is for a Mac and network you administer. It covers finding the setting, comparing it with the address your router sees, and deciding whether to make a small, reversible change. It doesn't tell you whether an unknown device is safe. It also isn't a reason to weaken your network's access controls.

The effect of a private address

A MAC address is a link-layer address used on a local network. When a device joins Wi-Fi and obtains an IP address, its MAC address is one of the details the access point and DHCP server can use. ARP then helps hosts associate an IPv4 address with a hardware address on that local segment. That's why a router table may show both an IP address and a MAC address. Neither field is a complete identity check. The ARP protocol is specified in RFC 826.

Apple's private Wi-Fi address feature lets a Mac use a different address on a Wi-Fi network instead of presenting its hardware address as usual. Apple documents this as a setting for each network. That matters when a laptop behaves normally at home but looks different on an office, guest, or test SSID. The feature is meant to reduce tracking across Wi-Fi networks; it isn't a sign of an error.

In practice, a router reservation, allow-list entry, or inventory note for an earlier address may no longer match the address the Mac currently uses on that SSID. The DHCP server may issue a different lease, or an access rule tied to the old address may no longer apply. DHCP's client and lease exchange is described in RFC 2131. A new lease doesn't prove there's a new computer.

The setting for the connected network

Start with the Mac that's actually connected to the network you're checking. Apple documents the current path in System Settings: open Wi-Fi, select the details button for the connected network, and check the Private Wi-Fi address option. This feature requires macOS Sequoia 15 or later and offers three modes: Off, Fixed, and Rotating. The network's security affects the default selection when joining a new network: Fixed for WPA2 or stronger security, and Rotating for weak or no security. Use Apple's Mac user guide rather than a screenshot from another version.

Before changing anything, write down the network name, the time, and the address the router currently reports. If you administer the router, compare its client or DHCP entry with the Mac's connected-network details. Check that the SSID and time window match. An old lease record, a guest network, or a wired adapter can give you an address that looks plausible but has nothing to do with the connection you're checking.

Don't publish the full address in a support forum or a public screenshot. A partial value and a timestamp are usually enough for a private troubleshooting record. If you need a network administrator's help, send the network name, time, and last few characters through their approved support channel.

The need for a change

Many home and guest networks need no change. You can leave the private address enabled, and the router can treat the Mac as the current client. You may only need to add a note to the inventory entry explaining that this is the same Mac using a network-specific Wi-Fi address.

Sometimes the address is a deliberate part of the local configuration. A DHCP reservation, captive-portal registration, device-specific access policy, or test network may be configured for the address the network sees. First, find out which address that configuration uses and whether the network actually depends on it. Don't change a reservation, firewall rule, and Mac setting all at once. You won't know which change affected the result.

If you decide the setting needs to change on a network you administer, record its previous state. Change only that network's setting, then reconnect once. Check the router's client table and the expected service. Keep the test narrow: does the Mac receive the intended lease or reach the intended internal service? Don't use a production NAS, backup job, security device, or another person's access as a convenient test target.

Apple also notes that private addresses can have different modes on current systems. A setting change is a compatibility decision for that network, not a general fix for Wi-Fi problems. If an enterprise or managed network requires a particular configuration, follow its documented policy or ask its administrator. Don't turn the feature off across unrelated networks. Apple's overview of private Wi-Fi addresses describes the feature and its network-specific behavior.

Device identity and address changes

An address mismatch tells you one thing. It doesn't settle the device's identity. Compare it with details you can responsibly check: the Mac's hostname, when it connected, the access point or SSID, and whether the Mac's user expected to be there. Routers can retain stale lease data, and a device may reconnect before another record expires. A familiar-looking hostname doesn't prove an unknown client is authorized, either.

If those checks still don't explain the device, keep your response proportionate. Confirm the SSID and check the router's current association, rather than relying only on an old lease list. Then use your usual access-control process. Don't repeatedly reconnect every client or restart the router just to tidy up the table. That can erase timing evidence and interrupt legitimate users.

DeviceShelf can provide another source of local observations for a network you administer. Compare its current device details with the router and Mac records, and keep the sources separate if they disagree. It can't tell you why a particular Wi-Fi address setting was chosen or certify that a device is authorized.

A short record for the next change

Often, a short note is more useful than a permanent configuration change. Record the date, SSID, router-visible address, whether the private-address setting was enabled, and the result of one limited reconnect. When a reservation next fails or an unfamiliar address appears, you'll have a record to compare with what you're seeing instead of guessing from a vendor lookup alone.

Private Wi-Fi addresses are a privacy feature that affects network management. Check the setting for the exact network and compare current records from the same time. Changing one thing at a time helps you get a useful answer without treating every new MAC address as a new device.

Network tips and product updates

The occasional guide, new features and release news, straight to your inbox. No spam, unsubscribe anytime.