Check an unknown network before you trust it, on Android
Arriving at a hotel, a client or a new office? The checks to run with NetBlade on Android before you trust the network, and the ones to leave alone.
When you join a network you do not manage, such as a hotel, an airport, a client’s office or a new workplace, you do not know who runs it or how. NetBlade has a set of checks that answer the practical question: is it safe to work here? This article gives you an order to run them in, what each result means, and which tools to leave alone on someone else’s network.
Before you start
- The phone connected to the network you want to check.
- The location permission for the Wi‑Fi parts. Android requires it to read Wi‑Fi details.
- “Hostile network check”, “My network”, the WiFi tab and “TLS certificate” are free. “LAN threat scan” is an advanced feature, unlocked for 24 hours with a video or permanently with “Remove ads”.
Warning: Only the checks below that stay passive are suitable for a network you do not run. Scanning other people’s devices on a client’s or a hotel’s network may break their rules. Ask first.
1. Look at what you are connected to
Tap the ⓘ “My network” icon in the top bar. You get your IP, subnet, gateway, DNS and interface; for Wi‑Fi the SSID, signal, channel and link speed; and for the internet your public IP, ISP and location.
Two things to note:
- The DNS servers. On a hotel network they are usually the gateway or the provider’s. Something unexpected is not proof of a problem, but it is worth keeping in mind for step 3.
- The public IP and ISP. They tell you whose connection you are actually using.
2. Check the Wi‑Fi security
Open the “WiFi” tab and tap “Scan”. Find the network you are on (marked as connected) and read its security:
- Open: no encryption on the air. Anyone nearby can see unencrypted traffic.
- WEP or legacy WPA: encryption that can be broken.
- WPA2 or WPA3: fine at the radio level.
Also look for the same network name listed twice with different security, for example one secured and one open. That is a classic sign of an “evil twin”, a fake access point imitating the real one.
3. Run the hostile network check
This is the core check, built for networks you do not manage.
- “Tools” → “Hostile network check” → “Run”.
- Read the three results:
- “Public exposure”: what the internet already knows about your public address, including ports reachable from outside.
- “DNS integrity”: whether the network’s resolver answers honestly for well-known names. A resolver that lies can send you to fake sites.
- “TLS interception”: whether someone decrypts your traffic on the way out.
It does not scan or attack anything. Any of the three may come back as “Could not be checked”, for example if the network blocks the test connections; that is not a pass.
Note: Your public IP is sent to Shodan InternetDB and ipinfo.io to learn what is visible from outside. Nothing else about the network leaves the phone.
Tip: Some companies decrypt traffic on purpose, with a security proxy whose certificate is installed on company devices. On a corporate network, “TLS interception” may be policy rather than an attack; ask IT. On a hotel or café network there is no good reason for it.
4. Look for spoofing on the local network
- “Tools” → “LAN threat scan” → “Analyze network”.
- Read the findings.
It looks for open, WEP, legacy WPA or WPS on the network you are on, possible evil twins, insecure networks nearby, and ARP anomalies: the same MAC on several addresses, or possible gateway spoofing, the typical sign of a man-in-the-middle attack.
Note: On Android 10 and later the ARP part depends on how much of the neighbour table the system lets apps see. A DHCP address reassigned to another device can also cause a false alarm, so repeat the check before drawing conclusions.
5. Check the certificate of a site you rely on
If step 3 raised doubts about TLS, confirm it on a service you use:
- “Tools” → “TLS certificate”.
- Type
host:port, for exampleexample.com:443, and start. - Look at the issuer. If a well-known site shows an issuer you do not recognise, or NetBlade warns that the certificate does not match the hostname, someone is in the middle.
What not to run on someone else’s network
- “Network grade” and “Router security” try common factory logins on the router’s admin page. Run them only on networks you manage.
- Port scans and LAN scans of other people’s devices. Stick to your own devices unless the owner has asked you to look.
Check that it worked
You should have, in a few minutes:
- The Wi‑Fi security of the network, with no duplicate name using weaker security.
- Three results from “Hostile network check”, ideally with no warnings.
- A “LAN threat scan” that reports “No threats detected.”
If all of that is clean, the network is behaving honestly as far as the phone can tell. Use a VPN anyway if your work requires it.
If something goes wrong
- “Could not be checked” everywhere. The network may have a captive portal you have not accepted yet. Open a browser, complete the sign-in page, then run the check again.
- The WiFi tab is empty. Grant location and, on Android 13 or later, “Nearby Wi‑Fi devices”.
- DNS integrity fails. Avoid signing in to anything on this network. If you must work, use a VPN or switch to mobile data.
- Gateway spoofing is reported twice in a row. Disconnect. On a network you do not run there is nothing you can fix; tell whoever runs it.
Next
- Analyze Wi‑Fi and choose a better channel
- Get started with NetBlade on Android
- NetBlade for Android guide: security tools
← All how-to guides Feature guide → The product: NetBlade Android →