Your Router Sees Every Site On The Network
The device you never think about
Most people worry about being tracked by websites, apps, or their internet provider. Fewer people think about the box sitting under their TV stand or in the office server closet. But your router sits between every device on your network and the internet, which means it is in a structural position to see, at minimum, which sites every one of those devices is talking to. Not the box’s fault, exactly. That is just where it sits in the path.
This matters more than it used to, because routers now log more, retain it longer, and in some cases sync it to a manufacturer’s cloud dashboard by default. Understanding what a router actually sees, and what it does not, is the difference between a reasonable threat model and either paranoia or false comfort.
Why DNS is the part that leaks
Every time a device visits a website, it first has to translate a name like example.com into an IP address. That lookup is DNS, the domain name system. For a long time, DNS queries traveled in plain text. Your router, sitting on the path between your laptop and your ISP’s DNS resolver, could see every query going out and every answer coming back, in the clear, whether or not it was configured to log anything.
This is why “router DNS logging” is worth understanding as its own thing, separate from general traffic monitoring. A router doesn’t need to inspect the contents of your traffic to build a fairly complete picture of your browsing. The list of domain names alone (your bank, a specific subreddit, a telehealth provider, a job search site) is often enough to infer what someone is doing, even without seeing a single page they loaded.
Many consumer routers, especially ones provided by an ISP, keep a query log for troubleshooting or parental control features. Some expose that log in the admin panel. Some upload it to a manufacturer app so you can see “connected devices and activity” from your phone. That second category is worth pausing on, because it means the log isn’t just sitting on a device in your house. It is leaving the house.
HTTPS narrows the leak, it doesn’t close it
A common misconception is that once a site uses HTTPS, the router (or anyone else on the local network path) is blind. HTTPS does encrypt the contents of the page, form fields, and cookies, which is a real and important improvement. But two things still typically leak even over HTTPS:
The DNS lookup itself, if it’s not also encrypted, tells anyone watching the local network which domain you’re about to talk to.
The TLS handshake that sets up the encrypted connection has traditionally included the domain name in plain text, in a field called SNI (Server Name Indication), so the receiving server knows which certificate to present. A device on the network path, including a router, can read that field without decrypting anything.
So a router can often tell that a device on the network visited example.com, without being able to read what that device did once it got there. That’s a meaningful boundary, and it’s worth being precise about it rather than rounding it up to “they can see everything” or down to “HTTPS means I’m invisible.” Neither is accurate.
Who is actually positioned to see this
This is the part that gets skipped in most privacy explainers, and it’s the part that matters most for deciding whether this is a real concern for your situation.
Anyone with admin access to the router. In a household, that might be one parent, a partner, or whoever set the network up. In a shared apartment, it could be a roommate. In a rental, it is sometimes the landlord, if they manage the router rather than the tenant.
The router or gateway’s manufacturer, if the device phones home with usage data or logs, which some ISP-supplied gateways and some consumer mesh systems do as part of their app-based management features.
An employer, on a work network or a company-managed router, where monitoring network traffic is often an explicit part of the IT policy you agreed to.
Anyone who compromises the router itself. Home routers are frequently under-patched, and a router with default credentials or unpatched firmware is a real target, not a theoretical one.
Notice that your ISP is not on this list in the same way, because your ISP sees your traffic upstream of your router regardless of what your router logs. The router is a second, distinct point of visibility, closer to home, often with weaker security practices than your ISP’s infrastructure, and often controlled by someone you know personally rather than a company you have a contract with.
What this looks like day to day
Concretely, router DNS logging means that if someone with access to your router’s admin panel or app wants to check, they can often see a list of domains each device on the network has queried recently, sometimes timestamped, sometimes tied to a device name or MAC address. On networks with basic parental control or “family” features enabled, this is frequently a built-in, user-facing feature rather than something hidden.
It doesn’t usually mean a full record of every page, every search term, or every message. DNS logging shows domains, not URLs or content. Someone reviewing the log would see that a device visited reddit.com, not which subreddit or which post.
Encrypted DNS moves the visibility, it doesn’t remove it from existence
DNS-over-HTTPS (DoH) and DNS-over-TLS (DoT) encrypt the query itself, so a router sitting on the local network path can no longer read the plain-text domain name in the DNS request. This is a real, useful change, and it’s part of why some browsers and operating systems now default to it.
But it’s worth being precise about what actually happens: the visibility doesn’t disappear, it relocates. Instead of your router (or your ISP) seeing the query, whichever DNS resolver you’ve pointed your device at now sees it. If that’s your ISP’s own encrypted resolver, you’ve closed the local leak but the ISP still sees the query. If it’s a third-party resolver, that resolver now has the same list your router used to have, plus your IP address. Encrypted SNI and newer protocols like ECH extend this same idea to the TLS handshake, hiding the domain name from network observers, again by shifting who sees it rather than making it unseen.
None of this is a downside exactly. It’s just a reason to treat “encrypted DNS” as a change in who holds the information, not a step toward nobody holding it.
A VPN changes the picture, but it’s the same kind of change
A VPN routes your traffic, including your DNS queries, through the VPN provider’s network before it reaches the open internet. Done properly, this does stop your local router from seeing your DNS queries or destination domains, because from the router’s point of view, all it sees is an encrypted tunnel to one IP address.
But this is a relocation of trust, not an elimination of the underlying fact that something, somewhere, still resolves your DNS queries and knows the domains you’re visiting. That something is now the VPN provider instead of your router or your ISP. Whether that’s a better place for that visibility to live depends entirely on the provider’s own logging practices, jurisdiction, and security, none of which a router or a VPN badge on an app can tell you on its own. No single tool, including a VPN, makes a person’s browsing private in some absolute sense. It changes which party is positioned to see what, and that’s worth evaluating on its own terms rather than treating as a solved problem.
What’s actually worth doing
If router-level visibility is part of your threat model, the practical, non-absolute steps are the ones that address the actual mechanism described above: change the router’s default admin credentials, keep its firmware updated, check whether its manufacturer app uploads usage logs by default and whether that can be turned off, and understand who else has admin access to it. If you’re on a network you don’t control, like a workplace, an ISP-managed gateway, or a household where you’re not the admin, it helps to just know that DNS-level visibility from that box is a realistic part of the picture, not a remote hypothetical.
None of this is about disappearing. It’s about knowing which parts of your daily browsing are visible from where, so the decisions you make about it are based on how the network actually works rather than on a vague sense of being watched or an equally vague sense of being safe.
If you want more explainers like this, written the same way, check out the rest of The Privacy Wire.