Subnet Calculator
IPv4 or IPv6, CIDR or dotted mask. Network, broadcast, host range, wildcard and the reverse-DNS zone, computed as you type and never sent anywhere.
The same calculator lives in the app, next to the LAN scan that tells you which of those addresses actually have something on them. Get RECON for iPhone — one-time purchase, no account, nothing leaves the device.
How to read a CIDR prefix
The number after the slash is how many leading bits of the address are fixed. A /24 fixes the first 24 bits, so 192.168.1.0/24 covers 192.168.1.0 through 192.168.1.255: 256 addresses, of which 254 are usable once the network address and the broadcast address are set aside. Each step down in the prefix doubles the block, so a /23 is 512 addresses and a /16 is 65,536.
Subnet mask and wildcard mask
The subnet mask writes the same prefix as four octets: /24 is 255.255.255.0, /20 is 255.255.240.0. The wildcard mask is its inverse, 0.0.0.255 for a /24, and is what Cisco access lists and OSPF network statements expect. Both are derived from the prefix, which is why the calculator accepts any of the three forms.
Why /31 and /32 have no broadcast
A /32 is one address, a single host or a loopback. A /31 is two addresses used for a point-to-point link between routers, where RFC 3021 does away with the network and broadcast addresses because nothing else can be on the link. Every other prefix loses two addresses to those roles.
Private, public and the addresses in between
The scope line says whether an address is globally routable or belongs to one of the reserved ranges: RFC 1918 private space (10/8, 172.16/12, 192.168/16), the 100.64/10 carrier-grade NAT range that many ISPs now hand out instead of a public address, link-local 169.254/16 that a device assigns itself when DHCP fails, and the documentation and benchmarking blocks that should never appear on a real network. If your router's WAN address starts with 100.64 through 100.127, you are behind carrier-grade NAT and inbound port forwarding will not work.
IPv6 prefixes
IPv6 uses the same idea with 128-bit addresses. A /64 is the standard size for one LAN and holds 2^64 addresses, which is why the calculator reports counts as powers of two rather than as numbers nobody can read. An ISP typically delegates a /56 or /48 to a home or office, giving 256 or 65,536 individual /64 subnets. The tool also shows the fully expanded form, the RFC 5952 compressed form, and the ip6.arpa reverse zone, which is the nibble-reversed address that PTR records live under.
Range to CIDR
Firewalls, route tables and cloud security groups take CIDR blocks, not "from this address to that one". Given any start and end address the tool returns the smallest set of aligned blocks that covers exactly that range and nothing outside it. A range that starts or ends off a block boundary will need several blocks; that is normal.