What an IP address is
An IP address is where a device sits on a network, the place packets have to reach, and every packet leaving your device carries a destination address and a return address on it. The address says where to deliver; it does not say who is sitting behind the device.
- Lesson 3 of 12
- Beginner
- Free, no signup
From your device to the destination, four links
-
1
Your device
the phone or laptop that builds the packet
-
2
The private address
taken from the router, meaningful only inside the house
-
3
The public address
one for the whole house, and what websites see
-
4
The destination address
where the packet must arrive, and the answer that returns the same way
These four links are an order for understanding, not a formal network layering. On corporate networks and at some operators more links sit between two and three.
Last checked: Facts and tool names in this lesson are re-checked against their sources on this date.
What does an IP address actually do?
An IP address is where a device sits on a network. It does nothing else: routers look at it to decide which neighbour to hand a packet to, and that is all. The document that defined this address, RFC 791, is dated September 1981, and the reference text is still the version running on most networks today.
Every packet carries two addresses, source and destination, and the source address is what brings the answer back. Without it a server knows what to send but not where. That is very nearly the only reason websites see your address: not curiosity, not tracking, simply that the answer has to return somewhere.
One point that confuses a lot of people: the address belongs to the place on the network, not to the device. A laptop that moves from home to a cafe gets a different address, the way your postal address changes when you move house. A serial number and a MAC address stay on the hardware; an IP address does not.
And keep this separate from whatever turns a site name into an address. That is a different machine's job, and the next lesson in this path is entirely about it.

Why does your device have two addresses?
Because the address you hold inside the house is not the address the world sees. The phone, the laptop and the television each take a private address from the router, and all of them go out under one public address. If the address on your phone differs from the one a website shows you, nothing is broken; that is the design.
The private ranges are agreed and specific. RFC 1918 sets aside three ranges for internal networks: 10.0.0.0/8, 172.16.0.0/12 and 192.168.0.0/16. If your device address starts with 192.168, that address is not routed on the internet at all and means something only inside your own network. Our own server sits behind a gateway in the 172.16 range too, which is to say that even a public server is a member of a local network first.
Translating between the two is exactly what the router does: a packet on its way out takes the public address, and the router remembers which internal device the answer belonged to. Everyone has seen the practical consequence. When several people share a house and a site says "unusual traffic from this address", the site is not seeing you; it is seeing the house.
There is a layer above that which gets mentioned less: some operators do the same thing for hundreds of subscribers at once. Then a public address does not belong to a house, it belongs to a neighbourhood. How many subscribers of an Iranian operator are in that position is something we cannot measure from here, and we will not invent a number for it.
How do IPv4 and IPv6 differ, and which do you need?
One ran out of room and the other was built for exactly that. An IPv4 address is thirty two bits, which is about four billion three hundred million possible addresses, and that number, which looked infinite in 1981, ran out on 3 February 2011: on that day the NRO announced that IANA's last free blocks had been split between the five regional registries and there was nothing left to hand out.
An IPv6 address is a hundred and twenty eight bits, and according to the same announcement it has been available since 1999. So the successor was ready years before the room ran out, and the move still went slowly, because no single network can decide it alone; the operator, the middle path, the server and the device all have to carry it together.
For an ordinary user the answer is simple: you have both or you have only the fourth version, and the operating system picks. There is nothing to do. But if you run a server, that choice sends you a bill exactly once, and further down, in the experience block, we have printed that exact bill.
And a warning for that same group: having a version six address is not enough, everything attached to it has to be ready too. A missing record, a missing reverse record, or a firewall carrying only version four rules are three known routes to a half invisible failure.
Two versions of the address, side by side
IPv4
- Thirty two bits, about four billion three hundred million addresses
- Four numbers with dots, like the documentation example 203.0.113.7
- Its global pool ran out on 3 February 2011
- Nearly every network understands it
IPv6
- A hundred and twenty eight bits, a space that does not run out
- Hexadecimal groups with colons, like 2001:db8::7
- By the same announcement, available since 1999
- Not every operator and not every path carries it yet
There is no winner here. A home user chooses neither and the operating system does the choosing; the choice only means something to someone running a server.
What does an IP address give away, and what does it not?
The country almost always, the city sometimes, the person never. We are quoting the vendor of this data rather than guessing: on its own accuracy page MaxMind estimates country level identification at about 99.8 percent, and for addresses inside the United States about 80 percent at state level and about 66 percent at city level, and that within a fifty kilometre radius of the city.
And one sentence on that same page is worth more than all three numbers: this data is never precise enough to identify a household, an individual or a street address. The page adds that if someone is on a VPN, or the address belongs to a hosting server, what gets located is that server rather than the person.
For Iran we hold no published figure and will not invent one. What can be said is this: the larger the share of mobile networks and shared addresses, the lower city level accuracy goes, and the scene where an address leads to somebody's front door is the thing this data does not do.
What genuinely comes out of an address is something else: which organisation the block is registered to. The regional registries publish that openly, and the fast path block on this page shows how to read it in two minutes.
What actually comes out of an address
Usually comes out right
- The country, estimated at about 99.8 percent by the data vendor itself.
- The organisation the address block is assigned to, from the public registry.
- Whether the address is private or public, from the number alone.
Does not come out
- A household, a street or a number. The vendor's own page says this data is never that precise.
- The identity of the person sitting behind the address.
- The city with confidence; the published city figure is about 66 percent, and within a fifty kilometre radius at that.
The numbers here come from MaxMind's own accuracy page, and the city figure is only for addresses inside the United States. For Iran we have no published figure.
The server that sees your address does not always see your address
Wherever there is an intermediary on the path, the source address that reaches the server belongs to the intermediary rather than to the visitor. This site sits behind a content delivery network too, and without one specific piece of configuration every visitor would look like one person to us. That specific piece is this: nginx knows twenty published ranges of that network as a trusted intermediary and takes the real address from the CF-Connecting-IP header.
Behind that, our own code follows the same order. The address detection function reads CF-Connecting-IP first, then X-Forwarded-For, and only last REMOTE_ADDR, and it validates each one before use so that a forged header cannot take the place of an address. The daily caps on our free tools are counted against that address, and if the chain were wrong, the first person to reach a cap would fill it for everybody.
The general lesson is that any number a dashboard shows you labelled "visitor IP" has no settled meaning until you know whether the site sits behind an intermediary. That single ambiguity ruins geographic analysis and address based blocking more often than people expect.
Want to get hands on? See which address a name reaches: the free DNS check tool queries the A and AAAA records live from our server, and the free whois tool shows the registration side. One caution that confuses many people: if the domain sits behind a content delivery network, the address you see belongs to that network and not to the server the site runs on.
The fast path, with AI
Reading the public record of an address used to be something only network people could do, because the output is a long text full of jargon. Now it takes two minutes, provided you fetch the data yourself and let the model only read it.
- Fetch the data from the official registry, not from the model: curl -s https://rdap.org/ip/203.0.113.7, putting your own address in place of the example. The answer is a JSON file.
- Paste that JSON untouched. A fast cheap class of model is enough here; this is extraction, not judgement. Our current pick is written up in the AI reference.
- Ask for four things and no more: the organisation name, the regional registry, the range this address falls inside, and the date the record last changed.
- If a decision depends on the answer, look at the file yourself as well. An address record rarely lies, but a model summarising it can add something the file does not contain.
Copy-ready recipe
The text below is raw RDAP output for one IP address, untouched.
{paste the JSON output here}
Pull only these four things out of this text, and write unknown for anything the text does not contain:
1. The organisation this block is assigned to.
2. The regional registry holding the record.
3. The address range and its prefix, exactly as the text gives it.
4. The date the record last changed.
Then write one sentence: what this record says about the city or the identity of the user. If it says nothing, write exactly that.
Rule: add nothing from your own knowledge. Make no geographic guess. If the text carries two contradictory values, write both.
Before you trust the output: This tells you whose name the address block is in, not who was using it at a given moment. The organisation record is months old, blocks change hands, and if the address belongs to a cloud network or a mobile operator there can be thousands of subscribers behind it. For any decision that concerns a person, this output alone is not enough.
AI in this kind of work
On this topic a language model does one job genuinely well: it translates technical text. An RDAP record, a firewall error message, or the sentence a service shows when it blocks you are all text, and the model is good at reading them. The job not to ask of it is looking something up: the model does not query the address, it answers from memory, and ownership of address blocks genuinely changes. Our position is simple: for "who owns this address" go to the official registry, for "what does this text mean" go to the model.
Tools that actually help
- Claude Works well for reading raw RDAP JSON and pulling out only the four requested fields, because the file is long and the model does not get bored. Iran is not on Anthropic's supported countries list, so there is no official signup or payment.
- Gemini Good for translating network jargon into Persian and explaining an error message. Google's own page says the Gemini app works in more than 230 countries and territories, and Iran is not on that list.
- ChatGPT Used for the same text reading job. We have not verified its access status from Iran: OpenAI's supported countries page returns 403 to our server, and we do not write a claim with nothing behind it.
Where it backfires
The risk here has its own shape and few people think about it: a server log is full of visitors' IP addresses, and under most privacy laws an IP address counts as personal data. When you paste a chunk of log into a chat "to check an error", you have handed your own users' data to another company, and Google's own help page for Gemini says plainly not to enter confidential information. The fix is simple: replace the addresses with an example address before pasting; the official documentation examples such as 203.0.113.7 exist for exactly this. The second risk is a confident answer with no lookup behind it: in the same tone the model will say which company and which city an address belongs to, when it has only guessed from a pattern. Anthropic itself calls this confident invention hallucination in its documentation and writes about reducing it. For what paying for each of these tools looks like from Iran, see the buying guide.
Sources: Anthropic: reduce hallucinations Anthropic: supported countries Google: Gemini Apps privacy and data Google: where Gemini Apps are available
Where this advice stops
This lesson explains the address and finds nobody. If what you want is to get from an address to a person, the honest answer is that this data was not built for that, and the vendor's own page says so. The accuracy numbers belong to one vendor and most of them to addresses inside the United States; for Iran we have no published figure and will not invent one. And everything said here about intermediaries comes from this server's configuration: your site may sit behind a different intermediary or none at all, and then the chain of headers is different.
From our own work
The most expensive lesson we ever took about addressing was about email, not the website. On 18 July 2026 the signup verification codes for our SEO tools sometimes arrived and sometimes did not, and the program code was fine. The cause was that Postfix, configured with inet_protocols = all, picked version four or version six at random for each delivery, and this server's version six address had no reverse record at all; Gmail rejected every version six attempt with a 550-5.7.25 error that said exactly that the reverse record was missing. So roughly half the mail vanished silently. The fix was two lines, inet_protocols = ipv4 and smtp_address_preference = ipv4, plus one detail that takes a while to find: that setting applies on a full restart and a reload is not enough. What we carry from that day: an address is not only a number for arriving at, it has a name attached to it backwards, and some services take that name seriously.
Real follow-up questions
Is a static IP better than a dynamic one?
For a home user it usually makes no difference and the extra fee is not worth it. Static matters when something from outside has to connect to you, such as a server you host or a camera you watch remotely. If you only consume the internet, a changing address even gives you a small extra layer of privacy.
Why does a site say my IP is blocked?
Because the rule is written against an address, and an address is usually not yours alone. With address translation in the router and shared operator addresses, your neighbour can be the reason for the block. If you use a VPN or an intermediary server it is likelier still, because those addresses have more than one person behind them.
Does changing my site's IP affect SEO?
A change of address on its own is not something to worry about; sites move every day. What has an effect is the state after the move: slowness, temporary errors, or an address that reaches no server. If you are moving, lower the record lifetimes in advance and check the pages yourself afterwards, which is exactly what the next lesson walks through.