Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

An IP address is a numerical identifier assigned to a network interface so networks can route data to it. It is not a permanent identity for a person or even necessarily for a whole device: addresses can change, be shared, or belong to different interfaces on the same computer.

On a typical home network, each device has a private address for local communication, while the router uses a public address to communicate with the internet. DHCP usually assigns local network settings, DNS finds addresses for domain names, and NAT commonly lets several devices share one public IPv4 address.

What an IP address does

When an app sends data across a network, the Internet Protocol (IP) uses source and destination addresses to help deliver packets to the right network endpoint. A postal address is a useful but imperfect analogy: IP addresses help locate destinations, but routing is hierarchical, addresses can change, and one public address can represent many devices.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

An address belongs to a network interface in a particular network context, not necessarily to a physical device as a whole. A laptop can have separate addresses for Wi-Fi, Ethernet, a VPN adapter, virtual machines, and IPv6. Seeing more than one address for one computer is normal.

An IP address alone does not reliably identify a person. It may represent a household router, a company gateway, a mobile carrier’s shared connection, a VPN server, a proxy, or a cloud service. It can sometimes suggest an approximate network location, but location databases vary in accuracy.

IPv4 and IPv6: two address formats

Version Address size Typical notation Example
IPv4 32 bits Four decimal numbers from 0 to 255, separated by dots 203.0.113.42
IPv6 128 bits Hexadecimal groups separated by colons 2001:db8:85a3::8a2e:370:7334

IPv4 has 232, or 4,294,967,296, possible bit patterns; many are reserved or unavailable for ordinary hosts. IPv6 has 2128 possible bit patterns. IPv6 addresses are written as eight groups of hexadecimal digits. Leading zeros in a group can be omitted, and one consecutive run of all-zero groups can be shortened to :: once in an address. The formats and CIDR examples are documented by AWS; IPv6 addressing architecture is specified in RFC 4291.

IPv6 was designed with a much larger address space, but it has not replaced IPv4 everywhere. Networks may be IPv4-only, IPv6-only, or dual-stack, meaning they support both. Some environments use translation mechanisms such as NAT64 to connect IPv6-only clients to IPv4 services. The details differ by network and provider; AWS’s comparison describes these modes and distinctions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Public, private, and special-purpose addresses

Private IPv4 addresses

Private IPv4 ranges are intended for use inside local or organizational networks. They can be reused on many disconnected networks and are not routed directly across the public internet.

Private range CIDR Typical context
10.0.0.0–10.255.255.255 10.0.0.0/8 Large private networks
172.16.0.0–172.31.255.255 172.16.0.0/12 Private networks
192.168.0.0–192.168.255.255 192.168.0.0/16 Home and small-office networks

These are the RFC 1918 ranges listed by IANA and RFC 1918. Private does not mean secret: other devices and administrators on the relevant network can see these addresses. A private device can still reach the internet through a router or gateway.

Do not treat every address beginning with 172 as private. Only 172.16.0.0 through 172.31.255.255 are in the private range. For example, Cloudflare documents 172.64.0.0/13 as public egress space in its IP address documentation.

Public addresses and reachability

A public address comes from globally managed address space and can be routed across the internet. That does not mean a device using it is automatically reachable: routing, firewalls, NAT, security rules, and whether an application is listening all matter. A router’s public IPv4 address does not make every device behind it accept incoming connections.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

IPv6 devices can have globally unique addresses without traditional IPv4-style NAT. They still need suitable routing and firewall rules. Public addressing and security are separate questions: a public address does not itself say whether traffic is allowed.

Special-purpose addresses

Address or range Meaning
127.0.0.1 (within 127.0.0.0/8) IPv4 loopback: refers to the local machine
::1 IPv6 loopback: refers to the local machine
169.254.0.0/16 IPv4 link-local range, often seen when automatic address configuration is used
fe80::/10 IPv6 link-local range
192.0.2.0/24, 198.51.100.0/24, 203.0.113.0/24 IPv4 documentation examples
2001:db8::/32 IPv6 documentation examples

The example ranges are reserved for documentation, not to identify a live public service. IANA maintains the IPv4 and IPv6 special-purpose registries.

How DHCP, DNS, routers, NAT, and firewalls fit together

Component What it does
DHCP Supplies a device with network settings, often including an address lease
DNS Resolves names such as example.com to one or more IP addresses
Router Moves traffic between networks
NAT Translates addresses, and often ports, between networks
Firewall Allows or blocks traffic according to policy
ISP Connects a home or organization to the wider internet

DHCP assigns network settings

Dynamic Host Configuration Protocol (DHCP) lets a client obtain network configuration from a server. It commonly supplies an address, subnet information, a default gateway, DNS resolver addresses, and a lease duration. The usual exchange is often called DORA: the client discovers a server, receives an offer, requests the offered settings, and gets an acknowledgment. DHCP’s purpose and parameters are defined in RFC 2131.

A DHCP lease can last a long time. Dynamic means the address is assigned automatically and may change, not that it must change frequently.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

DNS looks up names

DNS helps applications find the IP address or addresses associated with a human-readable name. A domain can resolve to several IPv4 or IPv6 addresses, and results may vary by location, network, time, or service health. A content-delivery network or reverse proxy may return its own address rather than the origin server’s. For instance, Cloudflare explains that proxied DNS records return Cloudflare IPs instead of the origin’s address.

Changing DNS servers normally changes which resolver answers name lookups; it does not change the IP address assigned to your device.

NAT lets devices share an IPv4 address

In a common home setup, a router translates traffic from several private addresses to one public IPv4 address. It tracks connections, including port information, so replies can be sent back to the device that started each connection.

Laptop       192.168.1.20
Phone        192.168.1.21
Game console 192.168.1.22
                    │
                    ▼
               Home router
        Public IPv4: 198.51.100.14
                    │
                    ▼
                Internet

The addresses in this diagram use documentation space where appropriate. NAT helps conserve IPv4 addresses, but it can complicate inbound connections, port forwarding, and some peer-to-peer applications. Multiple layers of NAT can create additional difficulties for hosting, voice, or gaming. NAT is not a substitute for a firewall: security depends on filtering rules and configuration. AWS describes the common mapping of multiple private IPv4 addresses to one public IPv4 address.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Carrier-grade NAT can affect inbound connections

Some ISPs place customers behind carrier-grade NAT, so the router’s WAN address is not the same as the public address seen by an external site. In that case, setting up port forwarding on the home router alone may not make a service reachable from the internet; an upstream translation layer is also involved.

Static and dynamic IP addresses

Type How it is assigned What to expect
Dynamic Automatically, commonly through DHCP or an ISP allocation May change after reconnecting, lease renewal, router restart, or a provider-side change; it may also remain stable for a long time
Static Configured to remain stable, through a reservation, manual setting, or provider allocation Useful when a known address is needed; not inherently faster or more secure

A DHCP reservation tells a router to give a particular device the same local address. It is often simpler and safer to manage than manually assigning an address that might collide with the DHCP pool. A static public address is a different thing: it is a stable internet-facing address, often arranged with an ISP or cloud provider. Dynamic DNS can provide a stable hostname that updates when a changing public address changes.

When a stable address helps

  • You host a service on your network or maintain a server.
  • You need predictable access to a printer, NAS, camera, or other local device.
  • You create firewall or port-forwarding rules that refer to a specific endpoint.
  • A business needs fixed endpoints for allowlists or documented network operations.

When it is usually unnecessary

  • Your devices only browse, stream, or use ordinary outbound services.
  • A hostname or local device-discovery feature already solves the access problem.
  • A router reservation can provide the local stability you need.
  • A cloud load balancer or DNS name is more appropriate than pinning a service to one address.

What CIDR and subnet masks mean

A subnet is a logical section of a larger network. Devices on the same subnet can communicate locally; traffic destined for a different subnet normally goes through a router. Networks that will be connected through a VPN or cloud link should use non-overlapping address ranges.

CIDR notation puts a slash and prefix length after an address. In 192.168.1.0/24, the first 24 bits identify the network prefix, leaving 8 bits for addresses in the block. For IPv4, a block contains 2(32 − prefix length) total addresses.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Prefix Total IPv4 addresses in block
/24 256
/25 128
/26 64
/27 32
/28 16

A larger prefix number means a smaller address block. In ordinary IPv4 subnet arithmetic, the first address is typically the network address and the last the broadcast address, so the familiar usable-host estimate is total addresses minus two. That rule has exceptions, and cloud platforms can reserve addresses differently. For example, AWS reserves five IPv4 addresses in each VPC subnet and documents its own subnet-size constraints; see AWS subnet sizing. AWS also advises using non-overlapping CIDR blocks for connected networks in its networking essentials.

Find your local IP address

The local address shown by your operating system is usually not the public address a website sees. A device can also have multiple local addresses, so check which network interface is active.

Windows

  1. Open Command Prompt or PowerShell.
  2. Run ipconfig.
  3. Under the active adapter, check IPv4 Address, Subnet Mask, and Default Gateway. IPv6 entries may appear too. Microsoft documents the command in its ipconfig reference.

macOS

  1. Open Terminal.
  2. For Wi-Fi IPv4 on many Macs, run ipconfig getifaddr en0. Interface names can vary.
  3. To inspect interfaces and IPv4/IPv6 addresses more generally, run ifconfig.

Linux

  1. Open a terminal.
  2. Run ip address or ip addr.
  3. Look for inet entries for IPv4 and inet6 entries for IPv6. See the Linux ip reference.

Find the public IP an outside service sees

A public-IP lookup site, your router’s status page, or an ISP account page may show an address associated with your connection. The result depends on the path your traffic takes. A VPN can make a lookup show the VPN server’s egress address; a corporate proxy can show the organization’s address; a mobile provider may use carrier-grade NAT. IPv4 and IPv6 lookups may also return different addresses.

If the router’s WAN address differs from the one an external lookup shows, the ISP or another upstream network may be performing translation. A lookup reports the address visible at that point in the connection; it does not reveal every address assigned to your devices.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Diagnose common IP address problems

An address starts with 169.254

An IPv4 address in 169.254.0.0/16 is link-local. It may mean the device did not obtain a DHCP lease, but it does not prove the router itself is broken. Wi-Fi authentication, a VLAN, adapter, driver, or DHCP server problem can also be involved.

  1. Check that Wi-Fi or Ethernet is connected and the access point or router is powered.
  2. Disconnect and reconnect, then restart the network adapter.
  3. Renew the DHCP lease using the operating system’s network controls or command tools.
  4. Check whether other devices on the same network receive normal addresses.
  5. If the issue persists, inspect the router’s DHCP pool and logs, and consider a router restart only when it will not disrupt important work.

Two devices appear to have the same address

An IP conflict occurs when two interfaces use the same address on one network. Connectivity may become intermittent, one device may work while another fails, or the operating system may warn about a duplicate address. Common causes include a manually assigned address inside the DHCP pool, duplicated virtual-machine settings, repeated static assignments, or an unintended second DHCP server.

  • Use router DHCP reservations for devices that need stable local addresses.
  • Keep manually assigned addresses outside the DHCP pool and document them.
  • Check for unauthorized DHCP servers, then renew leases or reconfigure the conflicting device.

You have an IP address but no internet

An assigned address only shows that one part of network configuration succeeded. Check the default gateway, DNS settings, router connectivity, and whether other devices can reach the internet. If numeric destinations work but names do not, DNS may be the failing part; changing the IP address is not automatically the fix.

Port forwarding does not work

Check that the service is running, the device has a stable local address, the router forwards the correct port, and the host firewall permits the traffic. If the ISP uses carrier-grade NAT, the router may not have a directly reachable public IPv4 address, so local port forwarding alone may be insufficient.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Connected networks overlap

Two separate networks can both use a range such as 192.168.1.0/24 and work on their own. If connected by a site-to-site VPN, remote-access VPN, or cloud link, overlapping ranges make it ambiguous where traffic should go. Renumbering one network or using a carefully designed translation approach may be needed.

IP addresses, privacy, and security

Websites and services may log the public address from which a connection arrives. That address can be associated with an ISP, organization, VPN, proxy, or shared carrier network; it does not by itself prove which person or device performed an action. Approximate geographic databases can be useful clues but are not reliable proof of a precise location.

A VPN generally changes the egress address a website sees to the VPN server’s address. It does not make a user anonymous: the VPN provider handles the connection, and accounts, cookies, browser fingerprints, device identifiers, DNS behavior, and application telemetry can still link activity. A VPN is not mandatory for ordinary browsing and is not the same as a static IP, a remote-access VPN, or a website reverse proxy.

For security, focus on the controls that actually govern access: firewalls, strong authentication, software updates, encryption, least-privilege access, and secure router configuration. NAT alone is not a security plan, and IPv6 is not inherently more secure or less secure than IPv4; implementation and policy matter.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Do you need a paid IP tool or service?

Most home users do not need to buy anything to find an address, set a local DHCP reservation, or understand their network. Paid services make sense when they solve a real operational problem.

Option Who may benefit When it is a poor fit
Router DHCP reservation Home users who need a device to keep the same local address Not a way to obtain a stable public IP from an ISP
Static public IP from an ISP or cloud provider Services needing a stable internet-facing endpoint or allowlist address Unnecessary for ordinary browsing; other cloud costs may apply
Amazon VPC IP Address Manager (IPAM) Cloud teams managing address space across AWS accounts or Regions Not useful for finding a laptop address or managing a small home LAN
Cloudflare proxying Website operators using Cloudflare’s proxy and related services Not a way to change a home ISP address or a personal VPN
Consumer VPN Users with a specific privacy, network-access, or location-related use case Not complete anonymity and not a replacement for firewall or account security

AWS IPAM offers Free and Advanced tiers for different capabilities. AWS lists Advanced Tier at $0.00027 per active IP address per hour; this is the listed rate, not a total bill, and other VPC charges such as public IPv4 and NAT Gateway charges are separate. Check the current IPAM tier details and AWS VPC pricing before planning costs.

AWS also charges for public IPv4 addresses associated with VPC resources, as covered on its VPC pricing page. Cloudflare says certain static-IP or custom-IP options are available to Business and Enterprise customers, with details handled through an account team; it does not publish a price on the cited IP address page.

Quick glossary

  • Address: A numerical identifier used by IP networking to route packets.
  • Default gateway: The router or next hop a device uses to reach other networks.
  • DHCP lease: A time-bounded assignment of an address and other network settings.
  • Interface: A network connection point, such as Wi-Fi, Ethernet, or a VPN adapter.
  • Loopback: An address that refers back to the local machine, such as 127.0.0.1 or ::1.
  • NAT: Translation of network addresses, commonly used so private IPv4 devices share a public IPv4 address.
  • Prefix length: The number after the slash in CIDR notation that indicates the network prefix size.
  • Subnet: A logical division of an IP network.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.