How to Secure Your Home Wi-Fi Network and Keep Hackers Out

Your home Wi-Fi network is the digital front door to almost everything you do online. Computers, smartphones, security cameras, smart TVs, gaming consoles, voice assistants, and IoT devices may all connect through the same router. If that router or wireless network is poorly secured, an attacker who gains access could potentially misuse your internet connection, target connected devices, or change network settings.

Fortunately, a few carefully chosen settings can significantly strengthen a home network.

1. Use WPA3 encryption

The first setting to check is Wi-Fi security mode. For modern devices, use WPA3-Personal whenever your router supports it. The FTC recommends WPA3 Personal or WPA2 Personal, with WPA3 being the newer option. Avoid legacy WEP and WPA, which no longer provide adequate protection. Consumer Advice

If some older devices cannot connect using WPA3, a WPA2/WPA3 transitional mode may be necessary. If your router supports only WEP or the original WPA even after a firmware update, consider replacing it.

2. Create a strong Wi-Fi password

Your Wi-Fi password should be long, unique, and difficult to guess. Avoid names, addresses, telephone numbers, birthdays, or simple passwords such as HomeWiFi123.

A long random password or passphrase is considerably stronger. For example, use several unrelated words combined with numbers or symbols. The FTC recommends aiming for at least 15 characters when creating passwords. Consumer Advice

Just as importantly, never reuse your Wi-Fi password for email, banking, social media, or other accounts.

3. Secure the router administrator account

Your Wi-Fi password and router administrator password should be different. The administrator account controls critical settings including DNS, firewall rules, wireless security, port forwarding, and firmware.

Change the router’s factory-default administrator credentials immediately. If the router supports multi-factor authentication for its management account, enable it. Disable administration from the internet—often called Remote Administration, Remote Management, or WAN Management—unless you genuinely need it. The FTC specifically recommends disabling remote management. Consumer Advice

4. Disable unnecessary network features

Convenient router features can sometimes increase the attack surface. Unless specifically required, consider disabling:

  • WPS (Wi-Fi Protected Setup): Connect devices by entering the Wi-Fi password instead.
  • UPnP: Disable it if your applications and devices do not require automatic port configuration.
  • Remote administration: Manage the router only from your local network.
  • DMZ host: Do not expose a computer or other device directly to the internet unless you understand and require the configuration.
  • Unnecessary port forwarding: Remove rules you no longer use.

The FTC recommends turning off WPS, remote management, and UPnP when they are unnecessary. Consumer Advice

5. Keep your router updated

Routers are computers running specialized operating systems, and vulnerabilities can be discovered in their firmware.

Enable automatic firmware/security updates if your router provides the option. Otherwise, periodically check the manufacturer’s support site. Software updates frequently contain security patches that address newly discovered vulnerabilities. Consumer Advice

If your router has reached end-of-support and no longer receives security updates, replacing it should be seriously considered.

6. Turn on the router firewall

Most modern routers contain a built-in firewall that separates your home network from unsolicited connections originating on the internet. Verify that it is enabled. The FTC specifically recommends checking that your router firewall is turned on. Consumer Advice

For most households, avoid manually exposing devices to the internet unless there is a clear reason.

7. Separate IoT and guest devices

Smart cameras, doorbells, televisions, speakers, appliances, and other IoT devices should ideally be separated from computers and devices containing sensitive information.

If your router supports Guest Wi-Fi, VLANs, or IoT network isolation, consider placing IoT devices on a separate network. Guests should similarly use a guest network rather than receiving the password for your primary Wi-Fi.

The FTC recommends separate networks as a way of limiting access between devices—for example, separating security cameras from computers and printers. Consumer Advice

8. Secure your DNS

Wi-Fi security should work alongside secure DNS. Configure a trusted DNS resolver such as Quad9, Cloudflare, Google Public DNS, or NextDNS. Where supported, enable DNS over HTTPS (DoH) or DNS over TLS (DoT) and DNSSEC validation.

A security-filtering DNS service can provide another defensive layer by preventing devices from resolving known malicious or phishing domains.

A recommended secure configuration

For a typical modern home, a strong baseline would be WPA3-Personal, a long unique Wi-Fi passphrase, a completely different router-administration password, automatic firmware updates, the router firewall enabled, WPS and remote administration disabled, and separate guest/IoT networks. Add encrypted and security-filtering DNS for another layer of protection.

No home network can be made completely immune to attack. The objective is defense in depth: an attacker should have to overcome several independent security controls rather than exploiting one weak password or poorly configured setting.

Conclusion

Securing your Wi-Fi network does not require becoming a network engineer. A handful of router settings can dramatically reduce unnecessary exposure. Start with strong WPA3 encryption and unique passwords, secure the router’s administrator interface, install firmware updates, disable services you do not need, isolate less-trusted IoT devices, and periodically review the devices connected to your network.

Your router protects the boundary between your digital home and the internet. Secure the router, strengthen the Wi-Fi, and every connected device benefits.

For additional guidance, see the FTC’s guide to securing home Wi-Fi and CISA’s wireless security guidance.

Why Your Home Router’s DNS Settings Matter

A simple configuration change can improve security, privacy, and resilience across your entire home network.

Your router is the gateway between your home and the internet, but one of its most important settings is often overlooked: the Domain Name System (DNS) resolver. DNS translates familiar names such as example.com into IP addresses that computers can use. Most home routers automatically use DNS servers supplied by the Internet service provider (ISP). That works, but it is not always the strongest choice for security or privacy.

Why DNS security matters:

Nearly every website, app, smart television, game console, phone, and IoT device in a home performs DNS lookups. Traditional DNS can travel across the network without encryption, making queries potentially visible to parties on the network path. A trustworthy resolver can also provide DNSSEC validation, which helps detect forged or tampered DNS responses. Security-focused resolvers go further by blocking domains associated with malware, phishing, botnets, and other threats before a device connects to them.

Configuring DNS at the router is particularly useful because the setting can automatically apply to devices that obtain their network configuration from the router. Instead of changing DNS individually on every laptop, phone, smart speaker, or appliance, you establish a stronger default for the entire household.

The most secure settings for a home router:

Recommended DNS providers:

ProviderUseful home-security optionAddresses / features
Quad9Malware blocking + DNSSEC9.9.9.9 / 149.112.112.112; DoH and DoT available
Cloudflare1.1.1.1 for Families — malware blocking1.1.1.2 / 1.0.0.2; DoH and DoT available
Google Public DNSGeneral-purpose validated/encrypted DNS8.8.8.8 / 8.8.4.4; DoH and DoT available
NextDNSCustomizable filtering and privacy controlsPersonalized configuration; encrypted DNS supported

Provider links:

Quad9

Cloudflare 1.1.1.1

Google Public DNS

NextDNS

A practical security-first choice

For a household primarily concerned with cybersecurity, a strong starting point is Quad9’s malware-blocking resolver (9.9.9.9 and 149.112.112.112), combined with DoH or DoT when the router supports encrypted DNS. Cloudflare’s malware-blocking addresses (1.1.1.2 and 1.0.0.2) are another straightforward option. Families wanting more granular policies, analytics, or configurable blocklists may prefer NextDNS.

DNS filtering is not a replacement for router firmware updates, strong Wi-Fi encryption, unique passwords, endpoint protection, or safe browsing habits. It is, however, an unusually effective security layer because one router-level change can improve the DNS posture of many devices at once. After changing the settings, restart or renew network connections and use the DNS provider’s test page to verify that the intended resolver and encrypted-DNS features are actually being used.

Sources and further reading

Cloudflare: Set up 1.1.1.1 on a router

Cloudflare: DNS encryption

Quad9: Service addresses and features

Google Public DNS: FAQ

NextDNS: Privacy policy

DNS may operate quietly in the background, but it plays a critical role in the security, privacy, and reliability of a home network. By configuring a trusted DNS provider at the router level, you can extend an additional layer of protection to virtually every connected device in your home—from laptops and smartphones to smart TVs, gaming consoles, cameras, and IoT devices.

For stronger protection, consider a DNS service that supports DNSSEC validation, DNS over HTTPS (DoH), or DNS over TLS (DoT) and, where appropriate, malicious-domain filtering. Providers such as Quad9, Cloudflare, Google Public DNS, and NextDNS offer different combinations of security, privacy, performance, and filtering capabilities, allowing you to choose the service that best matches your household’s requirements.

Secure DNS should be viewed as one component of a broader defense-in-depth strategy. Keeping your router firmware updated, using WPA2 or WPA3 encryption, maintaining strong and unique passwords, securing IoT devices, and regularly reviewing connected devices remain equally important.

A small change to your router’s DNS configuration can strengthen the security posture of your entire home network. Your router is the front door to your digital home—secure the DNS behind it.