~/network ☀ LIGHT apps ← about me

🌐 Language

███╗ ██╗ ███████╗ ████████╗ ██╗ ██╗ ██████╗ ██████╗ ██╗ ██╗ ████╗ ██║ ██╔════╝ ╚══██╔══╝ ██║ ██║ ██╔═══██╗ ██╔══██╗ ██║ ██╔╝ ██╔██╗ ██║ █████╗ ██║ ██║ █╗ ██║ ██║ ██║ ██████╔╝ █████╔╝ ██║╚██╗██║ ██╔══╝ ██║ ██║███╗██║ ██║ ██║ ██╔══██╗ ██╔═██╗ ██║ ╚████║ ███████╗ ██║ ╚███╔███╔╝ ╚██████╔╝ ██║ ██║ ██║ ██╗ ╚═╝ ╚═══╝ ╚══════╝ ╚═╝ ╚══╝╚══╝ ╚═════╝ ╚═╝ ╚═╝ ╚═╝ ╚═╝

What Is My IP Address?_

Your public IPv4 and IPv6, who owns them, and what leaks

By Jasper Bernaers · Updated 18 September 2026 · free, no signup, nothing stored
Public IPv4 address
detecting…
Seen by every server you visit · —
Country
—
City / region
—
ISP / organisation
—
ASN
—
Time zone
—
Coordinates
—
Postal code
—
Network
—
Reverse DNS (PTR)
—
Geolocation source
—
Where the geolocation provider places this address on a latitude/longitude grid. It is the registered position of the range, not your device — city accuracy is a guess and can be far off.
IPv6 address
detecting…
—
Leak & consistency checks
…
running checks…
Connection security
Answering Cloudflare edge
—
HTTP version
—
TLS version
—
Key exchange
—
Server name (SNI)
—
Cloudflare WARP
—
Network type
—
Read from Cloudflare's trace endpoint — the only way a browser can see how its own TLS connection was negotiated. A post-quantum key exchange (ML-KEM) protects today's traffic against decryption later; Encrypted Client Hello hides which site you asked for from anyone watching the wire.
Who owns this address
Registered netblock
—
Network name
—
Abuse contact
—
Straight from the regional internet registry over RDAP. The abuse address is where reports about this range are meant to go.

Internet speed test — with the packet loss most tests hide

Download, upload, latency and jitter measured against Cloudflare's nearest edge, plus the retransmissions that edge counted on its side of the same TCP connection.

📡
Ping / latency
—
ms
〜
Jitter
—
ms
⬇
Download
—
Mbps
⬆
Upload
—
Mbps
⚠
Retransmitted
—
%
⇄
TCP min RTT
—
ms
— download— upload
Press run to start. The test moves about 100 MB of data.
What the browser itself reports
Effective type
—
Downlink estimate
RTT estimate
—
Data saver
—
These come from the Network Information API, which only Chromium browsers implement, and they are coarse estimates from recent traffic — the measured numbers above are the real ones.

DNS lookup, DNSSEC and resolver comparison

Every record type over DNS-over-HTTPS, with the DNSSEC verdict and, on request, the same question asked of Google and Cloudflare side by side.

Enter a domain name — or an IP address for a reverse lookup
Try one

SPF, DKIM and DMARC checker

Everything a receiving mail server looks at before it decides whether your message is really from you — including the SPF lookup count that silently breaks most records.

Enter the domain you send mail from
Try one

WHOIS / RDAP lookup & blacklist check

Registry data for any IP address, domain or AS number, straight from RDAP — plus eight public blacklists for an address.

Enter an IP address, a domain or an AS number
Try one

Browser, device & fingerprint

What every website can read about this device without asking — and how identifying the combination is.

Browser & system
Browser
—
Engine
—
Operating system
—
Device
—
Language
—
Time zone
—
Platform
—
Storage quota
—
Screen & hardware
Screen
—
Window
—
Pixel ratio
—
Colour depth
—
CPU
—
Memory
—
Browser fingerprint
…
GPU
—
Fonts
—
Canvas hash
—
Audio hash
—
Privacy signals
Web capabilities
Raw user agent
—

Subnet, CIDR, IPv6 and MAC tools

The everyday calculations, done in the page: subnetting and splitting, address-in-block checks, range to CIDR, address conversion, MAC decoding and a port reference.

Subnet / CIDR calculator
Is this address inside that block?
Address range → CIDR blocks
IPv4 ↔ IPv6 & number formats
MAC address decoder
Port reference
What the server sees of your request
…

Encode, decode & hash

Base64, percent-encoding, SHA hashes and a JWT decoder. All of it happens in the page — nothing you paste is sent anywhere.

Base64
Input
Output
URL encoding
Input
Output
SHA hashes
Text
Type something above to hash it
JWT decoder
Token
Paste a token to decode it
FAQ — IP addresses, leaks, DNS, e-mail authentication and speed

Frequently asked questions — network tools

Your IP address
What is my IP address, and what can someone do with it?

Your public IP address is the address the rest of the internet answers back to — it identifies your connection, not you personally. From it, a website can look up which company owns the range and roughly where that range is used, which is how “IP geolocation” works. What it does not give anyone is your name, your street address or what you do online; that comes from accounts, cookies and fingerprinting. This page shows the address exactly as a server sees it, together with the network that owns it.

Why is my public IP different from the 192.168.x.x address on my computer?

Your router performs NAT: every device at home keeps a private address (192.168.x.x, 10.x.x.x or 172.16–172.31.x.x) and they all share one public address on the outside. Private ranges are defined in RFC 1918 and are not routed on the internet, so two different homes can use 192.168.1.10 at the same time without any conflict.

How accurate is the location shown for an IP address?

Country is usually right. City is a guess based on where the owner of the range registered it or where its customers tend to be, so it can be tens or hundreds of kilometres off, and on mobile networks it often points at the operator's core site rather than at you. Nothing about IP geolocation is precise enough to find a house; GPS-level accuracy only comes from a browser location prompt that you accept.

Why do I have no IPv6 address?

Because your ISP has not enabled it on your line, or your router has it switched off. IPv4-only works fine today, but IPv6 avoids carrier-grade NAT, which is what puts you behind a shared address. The IPv6 check here loads a resource that exists only over IPv6: if it fails, your connection has no working IPv6 path at this moment.

What is CGNAT, and why does it matter?

Carrier-grade NAT means your ISP puts hundreds of subscribers behind one public IPv4 address, from the 100.64.0.0/10 range. It saves addresses, and it breaks incoming connections: port forwarding, self-hosting and some game consoles stop working, and a ban aimed at one subscriber can catch the rest. If your router shows a 100.64–100.127 address on its WAN side, you are behind CGNAT.

VPN, privacy and leaks
What is a WebRTC leak, and does this page test for it?

WebRTC is the browser API behind video calls. To connect two people it asks a STUN server “which address do I appear as?”, and historically that answer bypassed VPN tunnels and exposed the real address. This page runs that exact query and compares the answer with the address your ordinary web requests come from. If they differ while you are on a VPN, that is the leak, and it is reported in plain words.

My local IP shows as a name ending in .local — is something broken?

No, that is the browser protecting you. Chrome, Edge, Firefox and Safari replace the LAN address in WebRTC candidates with a random mDNS hostname, so a web page can no longer read your internal network layout. Seeing it means the protection is working.

Can this page tell whether I am using a VPN?

It can tell you what a website would conclude, which is not the same as certainty. Three signals are shown: whether the owner of your IP range is a hosting or VPN company rather than a consumer ISP, whether your browser's time zone and locale match the country of your IP, and whether Cloudflare sees the connection as WARP traffic. Any of those makes a site treat you as “probably a VPN”, which is why some sites block you.

Does a VPN hide my IP completely?

It replaces the address that websites see with the VPN's exit address. It does not hide you from the VPN provider, it does not stop cookies or browser fingerprinting from recognising you, and it leaks if IPv6 or WebRTC travels outside the tunnel — both of which are checked here. Tor gives stronger separation at a large cost in speed, and neither makes you anonymous while you stay signed in to accounts.

What is a browser fingerprint, and why does it matter more than my IP?

Your screen size, GPU model, font list, time zone and dozens of other details combine into a value that is often unique, needs no cookie and follows you across sites even when your IP changes. This page computes one from your browser so you can see how distinctive the combination is. Lowering it means being ordinary: a default window size, no exotic fonts, and a browser that resists these APIs.

Does this site store or log my IP address?

No. The page is static HTML with no backend of its own. To answer “what is my IP” at all, your browser must ask a server that can see it — here that is ipwho.is or ipapi.co for geolocation and Cloudflare's trace endpoint for connection details; DNS queries go to Google and Cloudflare DNS-over-HTTPS, and registry lookups go to RDAP servers. Those providers see the request, as they would for any tool. Nothing is sent to jasperbernaers.com, and nothing you type is stored.

Speed, latency and packet loss
How does the speed test work, and why is it slower than what I pay for?

Four parallel download streams and three upload streams run against Cloudflare's edge for a few seconds each, after a warm-up so TCP slow start does not drag the figure down. A browser competes with everything else on your line, Wi-Fi loses throughput to distance and interference, and an advertised “up to” rate is measured to the ISP's own equipment, not across the internet. Wired, with nothing else running, is the closest you get to the number on the contract.

What is jitter, and why does it ruin calls more than low speed does?

Jitter is how much the round-trip delay varies from packet to packet. Voice and video need a steady stream: when delay jumps around, the receiver either waits (adding lag) or drops what arrives late, which is what you hear as robotic or choppy audio. Under 10 ms is comfortable, over 30 ms is audible — even on a connection that measures hundreds of megabits.

How can a browser measure packet loss?

It cannot, directly — JavaScript has no access to the TCP stack. What this page does instead is read the Server-Timing header Cloudflare attaches to its speed endpoints, which reports the TCP statistics from the server's side of the same connection: round-trip time, minimum round-trip time and how many packets it had to resend. Retransmissions are the honest browser-side proxy for loss, and they are shown as measured, not estimated.

Which server am I being tested against?

The nearest Cloudflare edge, shown by its three-letter code (AMS is Amsterdam, BRU Brussels, IAD Ashburn). You are measuring the path to that edge, not to any particular website, which is the same thing every browser-based speed test measures.

DNS
What do the different DNS record types mean?

A and AAAA point a name at an IPv4 or IPv6 address. CNAME makes one name an alias of another. MX says which servers accept mail. NS lists the authoritative nameservers, SOA carries the zone's serial number and timers. TXT holds free-form text, which is where SPF, DMARC and verification strings live. CAA names the certificate authorities allowed to issue for the domain, and DS/DNSKEY carry DNSSEC signatures.

What is DNSSEC, and what does the validated badge mean?

DNSSEC signs DNS answers so a resolver can prove they were not tampered with on the way. When the resolver validates a signature chain it sets the AD (Authenticated Data) flag, which is what this page reports. “Not signed” is not an error — most domains still are not — but a SERVFAIL on a signed domain means the signatures are broken, and validating resolvers will refuse to resolve it at all.

Why compare Google and Cloudflare resolvers?

Because a difference tells you something no single lookup can. Right after a change, one resolver may still serve the old answer from cache while the other has the new one — that is propagation, and it explains why a site works for you and not for a colleague. A persistent difference usually means split-horizon DNS, a geo-routed answer, or a zone that is inconsistent between nameservers.

What is reverse DNS (PTR), and why is mine wrong?

A PTR record maps an address back to a name, and it lives with whoever owns the address range — your ISP or hosting provider, not you. That is why a home connection usually shows something like dsl-12-34.example-isp.net. For a mail server the PTR must match the name it announces, or receivers will treat it as suspicious.

E-mail authentication
What do SPF, DKIM and DMARC actually do?

SPF publishes which servers may send mail for your domain. DKIM signs each message with a key published in DNS, so the content can be proven unmodified. DMARC ties them together: it tells receivers what to do when both fail, and where to send reports. You need all three — SPF alone breaks on forwarding, DKIM alone gives no instruction, and DMARC without either has nothing to check.

What is the SPF 10-lookup limit, and why does this page count it?

Every include:, a, mx, ptr, exists and redirect in your SPF record forces the receiver to make another DNS query, and RFC 7208 caps the total at ten. Past that the receiver returns permerror and your SPF simply fails, usually without anyone noticing until mail starts bouncing. Adding a third-party sender is the normal way to cross the line, so the count here follows every include recursively.

My DMARC says p=none — is that good enough?

It means “watch only”. Mail that fails authentication is still delivered, so nothing stops someone spoofing your domain; you only get reports. It is the right first step while you find every legitimate sender, but the destination is p=reject. Moving through p=quarantine first is the usual, safe route.

Why does the DKIM check say it found nothing?

DNS gives no way to list selectors, so any tool has to guess names. This page probes about twenty common ones (google, selector1 and selector2 for Microsoft 365, k1 for Mailchimp and so on). A custom selector will not be found, which is why a blank result is reported as “not found” and never as “you have no DKIM”.

WHOIS, RDAP and blacklists
What is RDAP, and why not WHOIS?

RDAP is the structured, JSON replacement for WHOIS that registries are required to run. It answers over HTTPS with proper fields instead of free text, which is what lets a browser page like this one query it directly. Classic WHOIS runs on TCP port 43, which no browser can open — any “whois” web tool is really a server doing it for you.

Why is the registrant hidden on most domains?

GDPR. Since 2018 registries and registrars redact personal contact details from public records, so you see the registrar, the dates and the status codes, and usually an anonymised e-mail. Law enforcement and rights-holders can request the rest through the registrar.

What does the blacklist check actually check?

It asks seven public DNSBL zones — Spamhaus ZEN, SpamCop, Barracuda, UCEPROTECT, PSBL, DroneBL and s5h — using the same reversed-address DNS query a mail server makes. Each zone is also asked about 127.0.0.2, the address every list publishes as its own self-test: if that control answer does not come back, the list is refusing queries that arrive through a public resolver, and the row says “no verdict” rather than a false “clean”. Spamhaus blocks public resolvers this way, so use its own lookup page for a definitive answer.

My IP is listed. How do I get it removed?

Find out why first: a listing usually means a device on the network was sending spam, or your ISP's whole range is listed as consumer space (Spamhaus PBL does this deliberately, to stop home machines sending mail directly). Each list has its own removal page, and delisting without fixing the cause gets you relisted. For a home line, the answer is to send through your provider's mail server rather than to delist.

Subnetting and the toolkit
How many hosts are in a /24, and why two fewer than you expect?

A /24 has 256 addresses and 254 usable ones: the first is the network address and the last is the broadcast address, and neither can be assigned to a device. A /25 gives 126 usable, a /26 gives 62, and so on — each extra bit halves the block. The exceptions are /31, used for point-to-point links where both addresses are usable, and /32, a single host.

What can a browser-based network tool not do?

It cannot ping, traceroute or scan ports: those need raw sockets and ICMP, which no browser exposes, and any web page offering them is running a server on your behalf. It cannot see the MAC address of a remote device, or your router's internal configuration. It cannot run a true DNS leak test either — that needs a wildcard DNS zone to watch which resolver asks for a unique name. Everything on this page is something a browser really can do, which is why the list stops where it does.

Is this free, and do I need an account?

Free, no account, no API key, no ads and no affiliate links to VPN providers. It is one of the free tools at jasperbernaers.com, all of which run in your browser.

Free network tools that run in your browser

Everything on this page happens in the tab you are reading it in. There is no backend, no account and no advertising: your address is resolved through public APIs, DNS questions go straight to Google and Cloudflare over DNS-over-HTTPS, and registry data comes from RDAP. Nothing you type is stored, and nothing is sent to this site's own server, because it does not have one.

What you can check here

How to use it

  1. Open the page — your address, location and the leak checks run straight away.
  2. Read the checks list: green is fine, amber is worth knowing, red means something disagrees.
  3. Run the speed test if the line feels slow, and look at jitter and retransmits, not only the megabits.
  4. Use the DNS, e-mail and WHOIS tabs for a domain you own — each result explains what it means, not just what it says.

How it compares

FeatureThis toolwhatismyipaddress.comwhatismyip.combrowserleaks.comipleak.net
Runs without ads or VPN affiliate offers✓ yes✗ VPN affiliate offers~ ad-supported✓ no ads~ ad-supported
Account needed✓ never✓ no✓ no✓ no✓ no
IPv4 + IPv6 shown together✓ both✓ both✓ both✓ both✓ both
WebRTC leak test✓ with IP comparison~ separate page~ separate page✓ yes✓ yes
Speed test✓ with server-measured retransmits✓ yes✓ yes✗ no✗ no
DNS records + DNSSEC + two-resolver comparison✓ yes~ lookup only~ lookup only✗ no✗ no
SPF / DKIM / DMARC audit with the 10-lookup count✓ yes✗ no~ SPF checker✗ no✗ no
RDAP (WHOIS) for IP, domain and ASN✓ all three~ IP + domain✓ IP, domain, ASN✗ no✗ no
Blacklist (DNSBL) check✓ 7 lists + control query✓ yes✓ yes✗ no✗ no
Browser fingerprint report✓ hash + signals✗ no~ partial✓ its speciality✓ yes
Subnet / CIDR toolkit✓ split, contains, range→CIDR✗ no✓ subnet + CIDR✗ no✗ no
TLS version, post-quantum key exchange and ECH✓ yes✗ no✗ no~ TLS fingerprint✗ no

Checked on 18 September 2026 against the public pages of whatismyipaddress.com, whatismyip.com, browserleaks.com and ipleak.net. They are good tools and several do things this one does not; the table is what each offers for free without an account, not a verdict on quality.

What a browser cannot do

Honesty is more useful than a longer feature list. A web page has no raw sockets, so it cannot send an ICMP ping, run a traceroute, or scan ports — tools that claim to do so run a server that does it for you, and the result describes that server's path, not yours. It cannot read the MAC address of anything but its own guesses, cannot see inside your router, and cannot run a real DNS leak test, which needs a wildcard DNS zone watching which resolver asks for a one-off name. What is here is what a browser can genuinely measure.

Common questions in one line

Why is my IP different at home and on mobile? They are different networks with different ranges. Why did my IP change? Most consumer lines get a dynamic address that changes when the router reconnects. Is my IP unique to me? On IPv4 it is usually shared with everyone in the house, and under CGNAT with hundreds of other customers. Can I hide it? A VPN or Tor replaces it, but cookies and fingerprinting still recognise you — the fingerprint section shows how easily.

Related free tools