Connected without internet describes two different network facts. Your phone has successfully joined a local Wi-Fi network, but a later test cannot reach the wider internet. The Wi-Fi symbol confirms the first link; it does not guarantee that the router, modem, service provider, name servers, and destination beyond it are all working.

What normally happens in five steps

1. The phone discovers a Wi-Fi network

The access point advertises a network name and radio capabilities. Your phone selects it, negotiates a compatible radio connection, and, on a protected network, proves that it has the right credential.

2. The phone receives local network settings

Joining the radio link is not enough. The device normally needs an IP address, a local network prefix, a default router, and one or more Domain Name System servers. These are commonly supplied automatically by DHCP or the IPv6 configuration process.

3. Local packets reach the router

The phone can now exchange traffic with devices on the same local link. That is the condition the Wi-Fi icon most directly represents. A printer or local control page may still be reachable even if nothing beyond the home works.

4. The router sends traffic toward the provider

The router needs its own working connection through a modem, fiber terminal, cellular link, or another upstream network. It must have valid addressing and a route toward off-link destinations. A failure here leaves the local Wi-Fi network intact but cuts off internet access.

5. The phone validates broader connectivity

Operating systems make a small connectivity check and may also look for a captive portal. If the expected response does not arrive, the phone can label the network as having no internet even though association with the access point succeeded.

Where the chain commonly breaks

  • Provider or modem problem: the router is broadcasting normally, but its upstream connection is down.
  • Router state: the router has lost a lease, route, or stable link and needs time or a documented restart.
  • Local configuration: the phone has an invalid address, stale settings, manual proxy, custom DNS service, or privacy tool that prevents the validation request.
  • Captive portal: a hotel, airport, school, or guest network requires a sign-in or acceptance page before allowing general traffic.
  • DNS failure: packets may reach the internet, but human-readable names are not being translated into IP addresses.
  • Signal quality: the device can remain associated while interference or weak signal makes useful packet exchange unreliable.

First find the scope of the failure

Check another trusted device on the same Wi-Fi network. If every device fails, the fault is probably at the router, modem, or provider rather than in one phone. If only the phone fails, temporarily forget and rejoin the network after confirming the correct password. Also check whether a VPN, manual proxy, custom DNS setting, or randomized-address restriction is relevant to that network.

Next try a different known-good network. If the phone works there, its radio and general network stack are probably functional. If it fails everywhere, consult the current device support guidance before resetting network settings, because a reset can remove saved Wi-Fi networks and other connection preferences.

A safe troubleshooting sequence

  1. Confirm whether the problem affects one device or all devices.
  2. Move within reasonable range of the access point and wait briefly for the link to settle.
  3. Open a normal browser window to see whether a legitimate sign-in portal appears.
  4. Check the provider’s official status channel using cellular data or another connection.
  5. Restart network equipment only with its documented procedure, allowing each device to finish booting.
  6. On a single affected phone, forget and rejoin the network, then review VPN, proxy, DNS, and date settings.
  7. Escalate to the network administrator or provider if the upstream link remains unavailable.

Treat unexpected sign-in pages carefully

A captive portal explains many public-network cases, but a page asking for credentials is not automatically legitimate. Confirm the venue’s network name through posted or staff-provided information. Do not install an unknown certificate, profile, app, or remote-management tool merely to obtain access. Avoid sensitive transactions on an untrusted network.

Why DNS can make the internet look completely broken

People normally request a name such as a website address, not a numeric IP address. If the configured DNS resolver does not answer, apps may report that the internet is unavailable even while some underlying routes still work. That does not mean changing DNS is always the answer: the router, provider, captive portal, or security filter may be the real cause.

Why the status can appear imperfect

Connectivity detection is a test, not an all-seeing measurement. A firewall can block the test destination while allowing other services, or a portal can intercept it. Conversely, the test may succeed briefly while a particular website or app remains unavailable. The label is a useful clue about layers, not a diagnosis of the exact failed component.

The useful mental model

Think of Wi-Fi as the hallway from your phone to the building’s front door. The hallway can be open while the street beyond the door is closed. Connected describes the hallway; without internet describes the missing route beyond it.