How to Check Connected Sites in MetaMask: A Clear 2026 Guide

Written by: Abigail Ivy
Published on:

What connected sites in MetaMask actually mean

If you use MetaMask with decentralized apps, each connection gives a website permission to see your wallet address and request actions.

Knowing how to check connected sites in MetaMask helps you spot old permissions, reduce risk, and keep control of your crypto activity.

A connected site is not the same as a token approval, but both matter for wallet security.

A site connection lets a dApp recognize your account, while smart contract approvals can allow spending of assets under specific conditions.

How to check connected sites in MetaMask

You can review connected sites directly from the MetaMask extension or mobile app.

The exact labels may vary slightly by version, but the path is similar across desktop and mobile.

In the MetaMask browser extension

  1. Open MetaMask and unlock your wallet.
  2. Click the account icon or the menu button.
  3. Go to Connected sites or Settings and then Connected sites.
  4. Review the list of websites and dApps connected to the currently selected account.

If you manage multiple accounts, check each one individually.

A site can be connected to one account and not another, so the list may change when you switch accounts.

In the MetaMask mobile app

  1. Open the MetaMask app and unlock it.
  2. Tap the menu or account profile icon.
  3. Open Connected sites or find it under Settings.
  4. Review the connected dApps for the current wallet account.

On mobile, the layout can differ between iOS and Android, but the same account-level connection concept applies.

What you will see in the connected sites list

The connected sites page usually shows the domain name of each dApp, sometimes with a favicon or app name.

In some versions of MetaMask, you may also see which account is connected and whether the connection is active.

  • Site name or domain: Helps you identify the app or website.
  • Connected account: Shows which wallet address is linked.
  • Connection status: Indicates whether MetaMask still recognizes the site.

Check carefully for lookalike domains and stale entries.

A site you used months ago may still appear even if you no longer visit it.

How to disconnect a site in MetaMask

If a website no longer needs access, remove it from your connected sites list.

This is a good habit after using a dApp once, especially if you no longer trust the project or do not plan to return.

  1. Open the Connected sites screen.
  2. Select the website you want to remove.
  3. Choose Disconnect or Remove connection.
  4. Confirm the action if prompted.

Disconnecting a site stops it from automatically recognizing your wallet in future sessions.

It does not remove any blockchain transactions you already signed, and it does not revoke token approvals by itself.

Connected sites vs token approvals: what is the difference?

Many wallet users confuse site connections with token allowances.

They are related, but they serve different purposes and should be reviewed separately.

  • Connected sites: Let a dApp identify your wallet address and interact with MetaMask.
  • Token approvals: Let a smart contract spend certain tokens from your wallet under defined conditions.

For stronger security, check both.

A removed site connection may still have a token approval on-chain, and an approved contract may still exist even after you disconnect the website.

How to review token approvals after checking connected sites

After you learn how to check connected sites in MetaMask, the next step is reviewing spending permissions.

This matters because malicious or abandoned contracts can continue to hold allowances until you revoke them.

Common tools for reviewing approvals include blockchain explorers and wallet security services such as Etherscan token approval pages, Revoke.cash, and similar network-specific tools.

These services show which contracts can spend your tokens and let you revoke access when needed.

Before revoking, confirm you are using the official tool or the correct blockchain network.

Always verify the contract address and the token involved.

Security signs that a connected site should be removed

Not every connected site is dangerous, but certain warning signs justify immediate action.

Treat unfamiliar, broken, or suspicious domains as potential threats until verified.

  • You do not remember connecting the site.
  • The site domain looks misspelled or unusual.
  • The project is inactive, abandoned, or has poor reputation.
  • The dApp asks for excessive permissions or repeatedly triggers wallet prompts.
  • You used a public computer or shared device to connect.

If you suspect a compromise, disconnect the site, revoke any token approvals, and consider moving assets to a fresh wallet.

Best practices for managing MetaMask connections

Good wallet hygiene reduces risk without making everyday DeFi use difficult.

These habits are especially useful if you connect to NFT marketplaces, decentralized exchanges, lending platforms, or staking dashboards.

  • Use separate wallets: Keep a main wallet for storage and another for dApps.
  • Review connections regularly: Check connected sites after each major session.
  • Disconnect when finished: Remove access to dApps you no longer use.
  • Limit approvals: Approve only what is necessary and revoke old allowances.
  • Verify domains: Bookmark official URLs and avoid search-engine ads.
  • Use a hardware wallet: Add an extra layer of protection for high-value accounts.

These steps are especially important during periods of phishing activity, fake airdrops, and cloned websites that imitate popular web3 platforms.

Why some sites reappear after you disconnect them

Sometimes a site seems to return after you disconnect it.

This usually happens because the dApp asks you to reconnect when you visit it again, or because a browser session or extension cache still shows recent activity.

To confirm the disconnect worked, reopen the connected sites page after leaving the site and reloading MetaMask.

If the dApp is still able to prompt for connection, verify whether you visited the correct domain and whether a different account is in use.

When to create a new wallet instead of just disconnecting

Disconnecting is enough for routine cleanup, but some situations call for a fresh wallet.

If you signed a malicious transaction, entered your seed phrase on a fake site, or unknowingly granted broad approvals to risky contracts, a new wallet may be the safest option.

Move funds only after you confirm the old wallet is no longer exposed.

For large balances, many users keep a cold storage wallet separate from an active web3 wallet to reduce operational risk.

Checklist for checking connected sites in MetaMask

Use this quick process whenever you want to audit your wallet connections:

  1. Open MetaMask and unlock the correct account.
  2. Navigate to Connected sites.
  3. Review each listed domain carefully.
  4. Disconnect any site you no longer trust or need.
  5. Check token approvals on-chain if you used the dApp for swaps, staking, minting, or lending.
  6. Repeat the review for each wallet account you control.

By making this a routine, you can use MetaMask with more confidence and less exposure to unwanted access.