Public IP vs Private IP: What's the difference?

When you connect to the internet, your device uses two IP addresses: a public IP address and a private IP address. Understanding public IP vs private IP addresses is important for network security, remote access, and online privacy.

In this guide, I’ll explain how to find your public and private IP addresses. You’ll also learn how NAT and shared IP systems like Carrier-Grade NAT (CGNAT) affect remote access, and how tools like VPNs, proxy servers, Dynamic DNS (DDNS), and firewalls help protect your privacy and security online.

Public IP vs private IP differences

Public IP addresses and private IP addresses play different roles in how devices communicate across local networks and the internet.

Your public IP address is assigned by your Internet Service Provider (ISP) and acts as the internet-facing address that websites and online services use to communicate with your network. You can liken this to the postal address on an envelope that ensures it reaches your home.

Unlike public IP addresses, which must be globally unique, private IP addresses are local and can be reused across millions of different networks worldwide. This is why routers on completely different networks can both use addresses like 192.168.1.1 without interfering with each other.

Private IP addresses cannot be routed directly across the public internet. To solve this, routers use Network Address Translation (NAT) to map private IP addresses to a public IP address before traffic is sent over the internet.

Public IP vs Private IP comparison table

FeaturePublic IP AddressPrivate IP Address
Visible on the internetYesNo
Assigned byISPRouter
Used forInternet communicationLocal network communication
Globally uniqueYesNo
Routable onlineYesNo
Common examplesISP WAN IP192.168.x.x

What is a public IP address?

A public IP address is the external address that allows websites, streaming platforms, game servers, torrent clients, VoIP messengers, and other internet-connected services to send data back to your network.

Your public IP address is assigned by your Internet Service Provider (ISP) from a pool of globally unique addresses. Most ISPs assign these addresses dynamically, which means your public IP address will change over time. Public IP addresses are sometimes called external IP addresses because they are visible outside of your local network.

Every public IP address must be globally unique because it is used to distinguish your network from every other internet-connected network worldwide. This ensures that internet traffic reaches the correct destination.

Because every public IPv4 address must remain unique, the number of available addresses is limited. That is why technologies like NAT and IPv6 have become essential for scaling modern internet communications.

Why public IP addresses matter for privacy

Your public IP address is specific and public, which means that, in addition to allowing you to watch movies, join video calls, or play games online, it also serves as a key identifier that can be used to track you online.

Anyone can check their public IP address using our IP-checking tool. This tool displays the public IP address that websites and online services can see when you browse the internet.

The downside of a public IP address is that it can be used to identify and target your network. Hackers often scan public IP addresses for open ports and other vulnerabilities that can be exploited to gain access to the network and connected devices.

This is why many privacy-conscious users now rely on VPN services. A VPN hides your real public IP address from websites and other internet users, which helps improve privacy and reduce exposure when browsing online or engaging in P2P activities.

Can a public IP address reveal your location?

A public IP address can usually reveal your approximate location, including your city, region, and Internet Service Provider (ISP). Websites, streaming services, advertisers, apps, and online platforms can use this information to track your activity, enforce geo-restrictions, or profile your browsing habits.

This is one reason many people now use a VPN. A VPN replaces your real public IP address with the IP address of the VPN server, which helps prevent tracking and profiling online. It also makes it safer to use Peer-to-Peer (P2P) services by hiding your real IP address from other users.

What is a private IP address?

A private IP address (sometimes called a local IP or internal IP address) is used for communication inside a Local Area Network (LAN). These addresses are assigned by the router and are visible only to devices on the same local network. This allows each device on your home or business network to be uniquely identified, so data reaches the correct device.

Your router automatically assigns private IP addresses to connected devices using the Dynamic Host Configuration Protocol (DHCP). As a result, laptops, phones, smart TVs, printers, CCTV systems, Industrial IoT (IIoT) devices, gaming consoles, and other hardware can communicate on the local network.

Private IP addresses use reserved ranges such as 192.168.x.x, 10.x.x.x, and 172.16.x.x. These ranges are defined by RFC 1918 and reserved specifically for private networking. Because these addresses are used only locally, the same ranges can be reused across networks worldwide without conflict.

For devices to communicate across a local network, IP addresses must also be linked to physical hardware addresses known as MAC addresses. This is why the Address Resolution Protocol (ARP) is used to map private IP addresses to MAC addresses on the local network.

The benefit of private IP addressing and NAT is that devices can access the internet without every device needing its own public IP address. This improves security by reducing direct exposure of individual devices to the internet, while also conserving the limited number of available IPv4 addresses.

What is my IP address? How to find your public IP

Your public IP address is assigned to your network by your Internet Service Provider (ISP). It allows websites, streaming services, online games, apps, and other internet-connected services to send data back to your network.

If you want to know your public IP address, you can easily check it with an online IP-checking tool. Simply visit an IP lookup website or search “What is my IP address?” in Google. The tool displays your public IP address, DNS servers, and other important information, such as WebRTC leaks. It also reveals general information such as your approximate location and ISP.

Unless you pay extra for a static IP, your public IP address will change over time. This is because ISPs assign IP addresses dynamically from a pool. For this reason, you may want to check your IP address from time to time. This is particularly useful if you need remote access to services or devices on your LAN.

If you need a static IP address for remote access to services hosted on your LAN, you can often get one cheaper through a consumer VPN. This includes services such as NAS drives, game servers, and email servers.

How to find your private IP address on Windows or Mac

Most users only need to know their public IP address. However, if you want to identify the private IP address assigned to a specific device on your local network, you can use the steps below:

Find your private IP address on Windows

  1. Press the Windows key and search for Command Prompt.
  2. Open Command Prompt.
  3. Type ipconfig and press Enter.
  4. Look for the line labeled IPv4 Address under your active network adapter.
  5. The number shown (for example, 192.168.1.25) is your private IP address.

Find your private IP address on macOS

  1. Click the Apple menu and open System Settings.
  2. Select Network.
  3. Choose your active WiFi or Ethernet connection.
  4. Click Details or Advanced depending on your macOS version.
  5. Your private IP address will appear under the TCP/IP or network information section.

Private IP addresses usually begin with:

  • 192.168.x.x
  • 10.x.x.x
  • 172.16.x.x to 172.31.x.x

How to hide your IP address

A public IP address allows data to be sent back to your network from the internet. However, it also affects your privacy by linking your online activity to your connection. Websites, apps, advertisers, and online services can use your IP address to track activity, build browsing profiles, and estimate your approximate location.

Every public IP address is assigned to a specific ISP customer account at a given time. This means ISP records can link internet activity associated with an IP address back to the account holder. This is one reason many privacy-conscious users choose to hide their real IP address with a VPN.

VPN servers act as a proxy between you and the websites you visit. Your real IP address is still used to route traffic between your network and the VPN server. However, websites and online services only see the VPN server IP address instead of your home IP. This helps prevent tracking, profiling, and direct exposure of your home network online.

Concealing your real IP address also improves privacy when using torrents, VoIP apps, and other peer-to-peer technologies that connect users directly online.

Masking public IP address with a VPN

Using a VPN to hide your IP address online is easy. However, there are dozens of competing VPNs, and they are not all created equal. Users who want high levels of privacy should ensure they use a reliable, independently audited VPN with robust tunneling protocols, DNS leak protection, and a strict no-logging policy.

The benefit of a VPN is that it also prevents local networks and ISPs from monitoring your activity. This makes a VPN a useful way to bypass network restrictions, such as at work or school, without revealing what you are doing online. It also allows you to use public wifi more safely and privately.

What’s more, in some countries, ISPs are legally required to store browsing data and communications metadata. This makes using a VPN essential for users who want to browse privately without their ISP monitoring and logging their activity.

Steps to hide your IP address with a VPN

VPNs improve privacy at home, protect you on public wifi, help bypass censorship, and allow access to region-locked services while traveling. Here is how to set one up:

  1. Choose a reliable VPN to hide your IP address. NordVPN is our top recommendation because it offers fast speeds, strong encryption, DNS leak protection, and an audited no-logs policy. Surfshark is an excellent budget alternative if you want reliability, streaming access, and trusted privacy features. TotalVPN is a good option if you want a VPN bundled with antivirus protection.
  2. Sign up for your preferred VPN. Using our links gives you access to discounts and a money-back guarantee. This lets you test the VPN risk-free and check that it hides your real IP address properly.
  3. Install the VPN app. All recommended VPNs support major platforms, including Windows, macOS, Android, and iOS. This makes it easy to protect your laptop, phone, tablet, or desktop computer.
  4. Connect to a VPN server. Choose a server in the country or region you want to appear to be in. Once connected, websites and online services will see the VPN server’s IP address instead of your real public IP address.
  5. Check your IP address. Open an IP checking tool to confirm that your real IP address is hidden. You should see the VPN server IP address, not the IP address assigned by your ISP.
  6. Browse privately. With the VPN connected, your ISP, local wifi network, and the websites you visit will no longer be able to see your real public IP address. This improves privacy, helps prevent tracking, and protects your data on public wifi.

If your real IP address still appears, clear your cookies and cache, reconnect to a different VPN server, and check that DNS leak protection is enabled.

Static IP vs dynamic IP

Public IP addresses can either be static or dynamic. A static IP address remains permanently assigned to your network, while a dynamic IP address changes periodically over time.

Most home internet connections use dynamic IP addresses because they are easier for ISPs to manage and make more efficient use of the limited IPv4 address pool. Dynamic IPs are usually assigned automatically from a shared pool of addresses whenever a router reconnects to the ISP network.

Common uses for static IP addresses

Static IP addresses are typically used when a device or service needs to be reached consistently from outside the network. This includes hosting websites, game servers, email servers, NAS drives, CCTV systems, smart home hubs, and remote desktop services.

Businesses often rely on static IP addresses for remote access systems, VPN gateways, VoIP infrastructure, and cloud-connected services. They are also commonly used to secure access to internal company resources.

Some online gaming setups and self-hosted applications also work more reliably with a static IP address. This is because the address does not change unexpectedly, allowing third parties to connect when needed.

Do I need a static IP address?

Static IP addresses are useful for hosting and remote access, but most home users don’t actually need one. Dynamic IP addresses are cheaper, easier for ISPs to manage, and improve user privacy by limiting how long a single IP address remains associated with one customer account. This is why ISPs generally offer dynamic IPs.

Users who need a stable static IP for long-term remote access may prefer to get one more cheaply from a VPN provider instead of paying their ISP. This provides a consistent static IP address for sharing access to network resources without exposing the network’s real public IP address.

In some cases, this also makes it easier to improve security if the IP address becomes targeted or exposed. Instead of relying on the ISP to change the network’s public IP address, users can simply disconnect or replace the VPN server IP being used for remote access.

Are there any other ways to hide my public IP?

Besides using a VPN, it is also possible to use proxy servers to hide your IP address. However, proxies do not always encrypt your traffic, which means your ISP and local networks may still be able to monitor your activity. For this reason, VPNs provide much stronger privacy and security protections.

Another option for hiding your IP address is Tor. The Tor Browser routes your traffic through multiple volunteer-operated servers to provide increased privacy and anonymity when used correctly. However, Tor is generally much slower than a reliable VPN. This makes VPNs much more practical for data-intensive tasks such as streaming, gaming, video calls, or everyday browsing.

What is NAT (Network Address Translation)?

When a device communicates with the internet, the router replaces the device’s private IP address with the network’s public IP address before forwarding the traffic online. This is made possible by Network Address Translation (NAT), which allows the router to send data from multiple devices through a single public IP address. NAT acts as a bridge that allows private IP addresses on your home network to communicate with the public internet.

To make this possible, the router keeps a temporary record in a NAT translation table. This record tracks which device initiated each internet connection. When data returns from the internet, the router uses this table to route traffic back to the correct device.

Without the NAT translation table, websites and online services would not be able to send returning traffic back to the correct device on your local network.

NAT was originally introduced to help solve the scarcity of IPv4 addresses. There are only 4.29 billion IPv4 addresses in total, which is not enough for every internet-connected device to have its own public IP address. NAT allows many devices to access the internet without requiring each one to have its own public IP address.

Even with NAT helping extend the lifespan of IPv4, pressure on the limited address pool continued to grow. This is why IPv6 was introduced. IPv6 uses 128-bit addresses, which increases the number of public IP addresses from 4.29 billion to an effectively unlimited pool (340 undecillion addresses).

NAT as a natural firewall

NAT improves security by reducing the attack surface of devices on your local network. Because private IP addresses are not directly exposed to the public internet, unsolicited inbound traffic is usually blocked unless specific rules, such as port forwarding, are configured manually.

This makes NAT function like a natural firewall. By hiding local devices behind a shared public IP address, NAT helps protect home networks from constant scanning attempts, automated bots, and other malicious traffic commonly found on the public internet.

What is CGNAT (Carrier-Grade NAT)?

Carrier-Grade NAT (CGNAT) is a system that allows ISPs to assign a single IPv4 address to multiple subscribers. Because CGNAT allows customers to share the same public IP address, it helps reduce pressure caused by IPv4 exhaustion.

It also allows ISPs to scale their networks more efficiently, helping reduce infrastructure and IPv4 allocation costs while generating greater profits from a limited pool of increasingly valuable IPv4 addresses.

Under CGNAT, your ISP assigns your router a private WAN IP address instead of a public one. The ISP then performs an extra layer of NAT before your traffic reaches the public internet. This setup is commonly referred to as “double NAT”.

For most home users, CGNAT poses no problems because browsing, streaming, and video calls continue to work as usual. However, CGNAT can create issues for users who need hosting capabilities or direct inbound access to devices on their home network.

Because the ISP controls the outer NAT layer, traditional port forwarding can stop working correctly. This can affect:

  • hosting game servers
  • CCTV remote access
  • NAS drives
  • smart home systems
  • remote desktop connections
  • peer-to-peer gaming

Double NAT can also cause strict NAT problems in online games, as frequently reported by gamers on Reddit. This may make it harder to join multiplayer matches, use voice chat, or host online game lobbies.

Users who need reliable remote access often avoid CGNAT by requesting a static public IP address from their ISP. However, ISPs usually charge extra for static IP addresses.

Another option is to use a VPN that supports dedicated IP addresses and port forwarding, which can often provide a cheaper alternative. This allows inbound traffic to be routed back through the VPN tunnel. As a result, remote access connections can continue to work reliably despite the ISP’s CGNAT layer.

Public IP vs Private IP FAQs

What is the difference between IPv4 and IPv6?

IPv4 and IPv6 are two versions of the Internet Protocol used to identify devices and route traffic online.

IPv4 uses 32-bit addresses and supports roughly 4.29 billion unique IP addresses. The IPv4 address pool is limited, which is why technologies such as NAT and CGNAT are used to conserve IPv4 addresses.

IPv6 uses 128-bit addresses. This increases the number of available IP addresses to support the rapidly growing number of internet-connected devices worldwide. It also allows more devices to connect directly to the internet when needed.

What is the 100.64.0.0/10 range?

The 100.64.0.0/10 range is a reserved IP range used specifically for Carrier-Grade NAT (CGNAT). If your router’s WAN IP address falls inside this range, it usually means your ISP is using CGNAT and your connection is operating behind ISP-managed double NAT.

What is RFC 1918?

RFC 1918 is the technical standard that defines the private IPv4 address ranges used inside local networks. This includes:

  • 192.168.x.x
  • 10.x.x.x
  • 172.16.x.x to 172.31.x.x

These address ranges are reserved for private networking and are not routable across the public internet.

What is APIPA?

Automatic Private IP Addressing (APIPA) is a fallback system used when a device cannot obtain an IP address from a DHCP server. In these situations, the device automatically assigns itself an address in the 169.254.x.x range so that limited local network communication is still possible.

APIPA is most commonly encountered when troubleshooting local network or DHCP problems.

What is IP Passthrough?

IP Passthrough is a router feature that allows a public IP address to be passed directly to another router, firewall, or server on the local network. This is commonly used in business networks, advanced home labs, and mobile internet setups where users want external hardware to manage routing or firewall rules directly.

What is a Reverse Tunnel?

A reverse tunnel is a remote access technique that allows inbound connections to reach a device located behind a firewall or CGNAT connection. Instead of relying on direct inbound traffic, the device first creates an outbound connection to an external server, which then routes traffic back to the device securely.

Reverse tunnels are often used when traditional port forwarding is unavailable or blocked by CGNAT.