Why your Wi-Fi is slow: a diagnostic order of operations

Your Wi-Fi is slow because the bottleneck is almost certainly inside your house, not at your ISP, and a wired speed test taken before you change any setting is the only way to prove it. In a University of Chicago study, households on access links above 800 Mbps saw their own Wi-Fi act as the bottleneck 100% of the time. Work the steps below cheapest first, one change at a time.

The order to work in

StepCostTimeHelps most when
1. Wired baseline testfree10 minalways, first
2. Band and SSID settingsfree15 min6 GHz never appears
3. Channel and widthfree20 mindense building
4. Placement and backhaulfree, or a cable run30 minone bad room
5. Firmwarefree20 minyour model has an advisory
6. New hardwarehundreds of dollarsan eveningsteps 1 to 5 failed

The bottleneck moved indoors

That study took 13,581 joint measurements in 52 households between September 2021 and June 2023. A Raspberry Pi at the router measured the access link while a browser test against the same Pi measured Wi-Fi, so both numbers came from one house at one moment. 89% of households hit at least one Wi-Fi bottleneck.

The distribution is bimodal: most vantage points sit below 10% or above 80% prevalence. One session tells you which house you live in.

The gap costs money. In the 200 to 400 Mbps tier, mean actual throughput was 155.69 Mbps against 265.60 Mbps of access throughput. The shortfall grew to about 240 Mbps in the 400 to 800 tier, and roughly 602 Mbps above 800. The authors are blunt: above 200 Mbps, improve your Wi-Fi before upgrading your plan. Earlier 802.11b-era work put that crossover near 30 Mbps, which is why "buy more bandwidth" used to be right and now is not.

Throughput lost to Wi-Fi, by access link tier A bar comparison of how much of a home broadband link never reaches the device, by access link tier. In the 200 to 400 Mbps tier the access link measured 265.60 Mbps while Wi-Fi delivered 155.69 Mbps. The gap grows to about 240 Mbps in the 400 to 800 tier and roughly 602 Mbps above 800, so the faster the plan, the larger the share of it the Wi-Fi swallows. Bar length is the shortfall, on one shared scale. Bar length is the throughput lost to Wi-Fi. One shared scale, in Mbps. 200 to 400 Mbps tier 265.60 Mbps access, 155.69 over Wi-Fi 400 to 800 Mbps tier about 240 Mbps short above 800 Mbps tier roughly 602 Mbps short 89% of households hit at least one Wi-Fi bottleneck. Above 800 Mbps the figure was 100%, but that tier rests on 13 vantage points and the data stops in 2023.
The loss grows faster than the plan does, so each tier you buy into hands a larger share of the link to your own Wi-Fi.

Read the 100% with care: it rests on the 13 vantage points in the top tier, the data stops in 2023, and the researchers could not see the client devices or radio conditions involved.

Step 1: the wired baseline

Plug a computer into a LAN port, turn off any VPN, and run a speed test. The port is often the ceiling: 1 GbE caps TCP throughput near 940 Mbps whatever the plan behind it, so a multi-gigabit plan needs 2.5GbE at both ends before the number means anything.

Distrust two instruments. A speed test built into the router measures traffic that never crosses the forwarding path the router optimises for, so you may be reading its CPU. And no internet speed test isolates Wi-Fi: it reports the slowest hop on the path, including the test device's own adapter. Use iperf3 between a wired and a wireless machine on your LAN.

Check for double NAT while you are wired. Apple's rule is one NAT device and one DHCP server per network; with NAT on both the ISP gateway and your router, devices can lose access to network resources, and a second DHCP server can hand out clashing addresses. Set the DHCP lease to 8 hours at home, 1 hour for guests.

If the wired test is also slow, stop. Your problem is not Wi-Fi.

Step 2: band and SSID settings

Now test beside the router, then in the problem room. The difference is your Wi-Fi problem.

Apple refreshed its recommended router settings on July 14, 2026. The key line is the network name: one unique, case-sensitive name for all bands. Split them and devices "might not connect reliably to your network, to all routers on your network, or to all available bands." Apple devices flag a 6E network without a shared name as having limited compatibility. Guides that told you to create "MyNetwork-5G" now work against you.

Use WPA3 Personal, or WPA2/WPA3 Transitional for older devices, and avoid WPA/WPA2 mixed modes, WPA Personal, every WEP variant and anything with TKIP in the name. This trap is silent: WPA3 or Enhanced Open is mandatory on 6 GHz with no WPA2 fallback, so plain WPA2 "for compatibility" switches the 6 GHz radio off. If your 6E or Wi-Fi 7 router has never shown a 6 GHz connection, look here first.

Set radio mode to All. Apple recommends every mode rather than a subset, and says this "also helps reduce interference from nearby legacy networks and devices," reversing the old advice to disable 802.11b/g.

Do not fear 6 GHz for range. The path loss gap against 5 GHz is 1 to 2 dB; Juniper Mist attributes the 3 to 10 dB it measures on clients to the -1 dBm/MHz US cap, a regulatory limit rather than physics. Aim for -70 dBm for data, -67 dBm for voice.

Step 3: channel and channel width

Set channel selection to Auto, 20 MHz on 2.4 GHz, Auto or all widths on 5 and 6 GHz. Wider is not free speed. A 160 MHz channel spreads the same power across eight times the bandwidth, raising the noise floor about 9 dB. It is also blocked outright if any one of its 20 MHz sub-channels is busy; Wi-Fi 7's preamble puncturing works around that only at 80 MHz and wider. Juniper Mist ships 80 MHz in 6 GHz; copy that default. In 5 GHz, 160 MHz almost always means sitting on DFS spectrum. The 320 MHz channels in Wi-Fi 7 marketing are 6 GHz only, and US standard power allows exactly one.

How one busy sub-channel blocks a wide Wi-Fi channel Three channel widths drawn to scale on the same frequency axis, each built from 20 MHz sub-channels: 20 MHz is one block, 80 MHz is four and 160 MHz is eight. A shaded column marks one busy 20 MHz sub-channel near the top of the range. The 20 and 80 MHz channels sit below it and keep working, while the 160 MHz channel spans it and is blocked outright. One channel, drawn to scale as 20 MHz sub-channels. busy sub-channel 20 MHz use on 2.4 GHz 80 MHz Mist default 160 MHz Blocked outright: a 160 MHz channel cannot be used while any one 20 MHz sub-channel is busy. It also spreads the same power over eight times the bandwidth: noise floor up about 9 dB. Juniper Mist ships 80 MHz in 6 GHz. In 5 GHz, 160 MHz almost always sits on DFS spectrum. Wi-Fi 7 preamble puncturing works around a busy sub-channel only at 80 MHz and wider.
Narrowing the channel is not a downgrade when the spectrum is dirty: the wider setting has more ways to be stopped, which is how 160 MHz ends up measuring slower than 80 MHz in the same room.

DFS explains a specific symptom: 5 GHz drops for a minute, then returns on a worse channel. Before using a DFS channel an access point runs a Channel Availability Check of 60 seconds, extended to 600 seconds on the weather radar channels 120, 124 and 128. On detecting radar it leaves within about 10 seconds and stays off for 30 minutes. Near an airport the cycle repeats, which is why "use the empty DFS channels" backfires.

Seeing congestion got harder in 2026. On Windows, netsh wlan show interfaces reports band, channel, rates and signal strength. On macOS, hold Option, click the Wi-Fi menu icon and choose Open Wireless Diagnostics. Android throttles a foreground app to four scans per two minutes, adjustable on Android 10 and later under Developer options, Networking, Wi-Fi scan throttling. iOS is close to a dead end: App Store apps get no raw scan results, and AirPort Utility "will no longer be available for new downloads" per Apple's iOS 27 beta 2 notes of June 22, 2026. Existing owners can re-download it; everyone else should scan from an Android phone or a laptop.

Step 4: placement and backhaul

Central, high, off the floor, out of the corner, and not shut inside a cabinet. Netgear and eero name the same things to avoid: large metal objects, microwave ovens, cordless phones and baby monitors.

The under-reported cause is USB 3.0. Intel's white paper 327216-001 from April 2012, also hosted by USB-IF, describes "a broadband noise that cannot be filtered out, since it falls" inside 2.4 to 2.5 GHz. In Intel's chamber a USB 3.0 hard drive raised the 2.4 GHz noise floor by nearly 20 dB, a notebook's own connector by about 25 dB. An unshielded dock or external SSD beside a laptop or router is a real cause of 2.4 GHz collapse, and the easiest test here: unplug and re-measure.

Run Ethernet backhaul wherever you can. It beats wireless on throughput, latency and consistency, because a wireless backhaul carries every frame twice through shared spectrum. Published figures for the penalty disagree, so trust the direction, not the numbers.

Step 5: firmware

Enable automatic firmware updates, back up your settings first, and expect to rejoin on some clients.

Firmware sits at step 5 because its justification is security, not speed. The KV Botnet associated with Volt Typhoon ran largely on end-of-life Cisco and Netgear routers, and FBI and CISA disclosures in early 2024 traced the compromises back to at least 2021. CVE-2023-39780, a command injection in ASUS router firmware, entered CISA's Known Exploited Vulnerabilities catalog on June 2, 2025, and reporting that year counted 9,000-plus backdoored units. The fix was a firmware update plus a factory reset, because updating alone left the backdoor in place.

Two settings older articles tell you to enable, Apple tells you to disable. Hiding the network name "doesn't conceal the network from detection or secure it against unauthorized access," and can expose information identifying you. MAC filtering does nothing against interception, addresses are trivially spoofed, and some Apple devices use a different MAC per network by default, which breaks the allow-list anyway.

Step 6: hardware, last

Check what your clients can do before spending. Apple's N1 chip, in the iPhone 17, 17 Pro, 17 Pro Max and iPhone Air from September 2025, supports Wi-Fi 7 but is 2x2 MIMO and caps out at 160 MHz, not the 320 MHz the standard allows. A 320 MHz router does nothing for any of them.

Waiting for the next standard is also wrong. Wi-Fi 7 is settled: IEEE 802.11be was approved in September 2024 and published in July 2025, and Wi-Fi CERTIFIED 7 launched on January 8, 2024. Wi-Fi 8, IEEE 802.11bn, targets reliability rather than peak speed, with certification expected around CES in January 2028. TP-Link announced the Archer 8 on May 28, 2026 for an October launch, "built around the emerging IEEE 802.11bn specification," on sale well over a year before any certification exists to test it against.

Buy Wi-Fi 7 when you are replacing a router anyway, and buy it for Multi-Link Operation and clean 6 GHz spectrum rather than for 320 MHz. One caveat on brand: the US Commerce Department has proposed barring TP-Link sales on national security grounds, reported in October 2025 and backed by the Justice, Defense and Homeland Security departments. TP-Link disputes the findings, and it remains a proposal rather than a ban.

The 6 GHz rules are still moving: an FCC order adopted January 29, 2026 created a geofenced variable power class allowed outdoors, unlike low power indoor gear.

Whichever step you are on, write the numbers down: band, channel, width, and the iperf3 result from the same spot in the same room. Without a before number, the next change is a guess.

Sources