- 1 dedicated IP address
- 10 devices
- 5 open ports
- 100 GBbandwidth
- 20 Mbpsspeed
Enter the WAN address from your router and we compare it with the IPv4 the internet sees. If they match, you have a public IP. If the WAN is in 100.64.0.0/10, your ISP shares one address among many customers.
Updated
Looking up your public IPv4…
This check runs over IPv4; we cannot see your IPv6 address here. IP to ISP by DB-IP.
Carrier-grade NAT (CGNAT) means your ISP shares one public IPv4 address among many customers. Your router gets a private address on its WAN side, and the ISP translates it to a shared public address further up the line. Outgoing traffic works normally. Incoming connections stop at the ISP, so port forwarding on your router does nothing.
The CGNAT IP range is 100.64.0.0/10 (100.64.0.0 to 100.127.255.255), reserved by RFC 6598 for exactly this. A router WAN address in that range is a definitive sign of CGNAT. A WAN address in 192.0.0.0/29 means DS-Lite or 464XLAT: you have no public IPv4 at all, and IPv4 runs through the carrier's NAT.
A WAN address in private space (10.x, 172.16 to 172.31, or 192.168.x) means there is NAT upstream of your router. That is either an ISP modem or gateway in front of it (double NAT, usually fixable with bridge mode) or CGNAT that uses private addresses. The address alone cannot tell you which. Check whether another box sits between your router and the line.
CGNAT is commonly used on T-Mobile Home Internet, Verizon 5G Home, AT&T Internet Air, Starlink residential plans, most mobile and 4G or 5G connections, and often on satellite services like HughesNet and Viasat. DS-Lite is normal on some European cable and fiber, such as Deutsche Glasfaser and Vodafone Kabel. Digi, Jio and many UK altnets also commonly use CGNAT by default.
If the check says you are not behind CGNAT, you do not need us. Your WAN address is public, so a port forward on your router should work. If it does not, the cause is the forward rule, a firewall, or an ISP port block. The port checker and its troubleshooting steps cover those.
If you are behind CGNAT, first ask your ISP. Some sell a public or static IP add-on or a business plan; some UK altnets, such as Hyperoptic and Community Fibre, offer a public IP for a few pounds a month. Starlink Priority plans reportedly get a public IPv4, but not a static one.
Overlay networks such as Tailscale or ZeroTier reach your own devices through CGNAT but give nothing a public address. Cloudflare Tunnel covers HTTP only. IPv6 can work under CGNAT if your ISP allows inbound IPv6, but some, including T-Mobile, filter it.
GetAStatic gives you a dedicated public IPv4 over WireGuard. Your server or router dials out to our node in Kansas City, Missouri or San Jose, California, so CGNAT cannot block it. You open the ports you need in the dashboard, and people connect to your IP as if it were on your line. It works for any TCP or UDP service: game servers, Plex, Home Assistant, cameras and SSH.
The tool above does steps 2 and 3 for you. You only need the WAN address from step 1.
Traceroute is weak evidence. ISPs often number their internal links with private addresses, so a private hop does not prove CGNAT. A 100.x address on your PC from Tailscale is also not CGNAT; check the router, not the PC.
Plus for light use, Pro for most people, Ultra for full gigabit.
5× speed · 10× bandwidth · 2 IPs — only $2/mo more
Compare the WAN IPv4 address on your router's status page with the public IP a website shows you. If they match, you are not behind CGNAT. If the WAN address is in 100.64.0.0/10, you are. A private WAN address means NAT upstream: double NAT (an ISP modem in front of your router, usually fixed with bridge mode) or CGNAT, which no setting in your home can fix.
100.64.0.0/10, which runs from 100.64.0.0 to 100.127.255.255. RFC 6598 reserves it for carrier-grade NAT, so a router WAN address in it means CGNAT. ISPs that use DS-Lite give the router an address in 192.0.0.0/29 instead.
Not necessarily. Tailscale gives each device an address in 100.64.0.0/10, so a 100.x address on your PC may come from Tailscale, not your ISP. Only the WAN address on your router's status page tells you whether you are behind CGNAT.
Not on their standard residential plans, which normally use CGNAT. A forward on your router never sees outside traffic. You need a public IP from the ISP where they sell one, or a tunnel that gives you a public IPv4, such as a WireGuard static IP. Starlink does give public IPv6, but it only helps when the people connecting also have IPv6.
Ask your ISP for a public or static IP add-on. Overlay networks such as Tailscale or ZeroTier reach your own devices through CGNAT but give nothing a public address. Cloudflare Tunnel covers HTTP only. For any public TCP or UDP service, use a public IPv4 delivered over a tunnel, such as GetAStatic.
We use your IP address only to show it to you and to look up its network in a public IP-to-ISP database. The router WAN address you type never leaves your browser, so we never see or store it. We only count which kind of result came up, for example 'no CGNAT', like any page view. Normal web-server logs apply.
Have more questions? See the full FAQ →