🔒 Private IP Checker

Enter an IPv4 address to check whether it falls within a private (RFC 1918), loopback, link-local, CGNAT or other reserved range.

Why the ranges stop where they do

Each reserved block is a prefix, and the prefix decides how many bits of the second octet are pinned. That is the whole reason 172.16 to 172.31 is private but 172.32 is not:

172.16.0.0/12   mask 255.240.0.0
  second octet  16 = 0001 0000
  /12 fixes the top four bits -> 0001xxxx -> 16 through 31

100.64.0.0/10   mask 255.192.0.0
  second octet  64 = 0100 0000
  /10 fixes the top two bits  -> 01xxxxxx -> 64 through 127

The three RFC 1918 blocks hold 16,777,216 + 1,048,576 + 65,536 addresses, which is 17,891,328 in total - about 0.4% of the IPv4 space, and the reason large networks reach for 10.0.0.0/8 rather than stacking 192.168 subnets.

What each match means

The checker tests these ranges only. Class E space (240.0.0.0/4), the 0.0.0.0/8 block and 255.255.255.255 are reported as public even though no ISP will route them.

Frequently asked questions

Is 172.20.1.5 a private IP address?

Yes. 172.16.0.0/12 runs from 172.16.0.0 to 172.31.255.255, and 20 sits inside that, so the address is private.

Why is 172.32.0.1 public when 172.31.0.1 is private?

Because the private block is a /12, not the whole 172 range. The mask 255.240.0.0 pins the second octet's top four bits to 0001, and 32 is 00100000 - the first value that no longer matches.

What is 100.64.0.0/10 used for?

Carrier-grade NAT, defined in RFC 6598. If your router's WAN address is in it, your ISP is sharing one public address between subscribers, which is why inbound port forwarding will not work.