Private & Public IP Classifier
Tell whether an address is routable, private, loopback or otherwise reserved.
Paste addresses on the left.
How it works
Triage starts with a question that sounds trivial: is this address ours, or somebody's on the internet? It is answered wrong often enough that the mistakes have names.
172.32.0.1 is public
The RFC 1918 middle block is 172.16.0.0/12, which ends at 172.31.255.255. It
looks like it should run to 172.32, and a hand-written check that assumes so will treat an internet
address as internal. This is the single most common error in a hand-rolled classifier.
There are more than three private ranges
100.64.0.0/10 is Shared Address Space from RFC 6598, used inside carrier-grade NAT. It is neither RFC
1918 private nor globally routable, and a check that only knows the three familiar blocks will call it public —
and then treat a carrier-internal address as an external one. 169.254.0.0/16 is link-local, which
usually means DHCP failed rather than anything routed. The documentation ranges from RFC 5737 —
192.0.2.0/24, 198.51.100.0/24, 203.0.113.0/24 — exist precisely so that
examples never name a real host, so one appearing in live telemetry is worth a second look.
Every answer cites its range and its RFC
Matching is longest-prefix, against the IANA special-purpose registries, so the most specific block wins rather than whichever was tested first. Each result names the block it matched, which is what makes the answer checkable instead of something you have to trust.
"Public" is a statement about allocation
It means the address falls outside every special-purpose range, so it is allocatable as global unicast. Whether it is assigned, routed, or has a host answering are three further questions — and none can be answered without a network lookup this page deliberately does not make.
Example
10.0.0.5 is Private-Use under RFC 1918, matched against 10.0.0.0/8.
100.64.1.1 is Shared Address Space under RFC 6598 — not private, not routable.
203.0.113.9 is documentation space under RFC 5737, which is why it appears throughout this site's own
examples.
Frequently asked questions
Is 172.32.0.1 a private address?
No. The private block is 172.16.0.0/12, which runs from 172.16.0.0 to 172.31.255.255 — so 172.32.0.1 is public. This is the most common mistake in a hand-written check, because the block looks like it should be 172.16 to 172.32 and the boundary is one short of that.
What is 100.64.0.0/10 doing in the results?
That is Shared Address Space from RFC 6598, used inside carrier-grade NAT. It is neither RFC 1918 private nor globally routable, so a check that only knows about the three private blocks will wrongly call it public — and then treat a carrier-internal address as an external one.
Does "public" mean the address is in use?
No. It means the address falls outside every special-purpose range, so it is allocatable as global unicast. Whether it is assigned to anyone, routed, or has a host answering on it are three further questions, and none of them can be answered without a network lookup this tool deliberately does not make.
Related tools
CIDR Calculator
Network, broadcast, mask and usable range for any block — and split it into subnets.
LocalIP Address Converter
Every representation of an address at once — dotted, binary, integer and hex.
LocalCIDR Overlap Checker
Find which blocks in a list overlap, contain or duplicate each other.
LocalIOC Extractor
Pull indicators of compromise out of any block of text, log or report.
LocalIP Subnet Calculator
Enter an IPv4 address with a prefix or subnet mask, see the whole subnet, and divide it.
LocalIPv6 Calculator
Expand, compress and inspect an IPv6 address or prefix.
LocalFrom the intelligence desk
- Vulnerability Mailgun for WordPress SSRF (CVE-2026-78003)
- Vulnerability Monsta FTP SSRF (CVE-2026-60105)
- Vulnerability 2 CVEs: Kan & Arcane (CVE-2026-32255)
- Vulnerability Kestra OSS Authentication Bypass (CVE-2026-49869)