// TOOLS · IP CALC

Subnet Calculator

IPv4 or IPv6, CIDR or dotted mask. Network, broadcast, host range, wildcard and the reverse-DNS zone, computed as you type and never sent anywhere.

ADDRESS / PREFIX
IPV4 NETWORK
CIDR
192.168.1.0/24
NETWORK
192.168.1.0
BROADCAST
192.168.1.255
FIRST HOST
192.168.1.1
LAST HOST
192.168.1.254
USABLE HOSTS
254
TOTAL ADDRESSES
256
MASKS
SUBNET MASK
255.255.255.0
WILDCARD
0.0.0.255
PREFIX
/24
MASK (BINARY)
11111111.11111111.11111111.00000000
ADDRESS (BINARY)
11000000.10101000.00000001.00100101
ADDRESS
INPUT
192.168.1.37
CLASS
C
SCOPE
Private (RFC 1918)
REVERSE DNS
37.1.168.192.in-addr.arpa
IP RANGE → CIDR BLOCKS
192.168.1.10/31
192.168.1.12/30
192.168.1.16/28
192.168.1.32/27
192.168.1.64/27
192.168.1.96/30
192.168.1.100/32
91 addresses in 7 blocks. Firewalls and route tables take blocks, not ranges; this is the smallest set that covers exactly the range.
ON YOUR PHONE · IP CALC

The same calculator lives in the app, next to the LAN scan that tells you which of those addresses actually have something on them. Get RECON for iPhone — one-time purchase, no account, nothing leaves the device.

How to read a CIDR prefix

The number after the slash is how many leading bits of the address are fixed. A /24 fixes the first 24 bits, so 192.168.1.0/24 covers 192.168.1.0 through 192.168.1.255: 256 addresses, of which 254 are usable once the network address and the broadcast address are set aside. Each step down in the prefix doubles the block, so a /23 is 512 addresses and a /16 is 65,536.

Subnet mask and wildcard mask

The subnet mask writes the same prefix as four octets: /24 is 255.255.255.0, /20 is 255.255.240.0. The wildcard mask is its inverse, 0.0.0.255 for a /24, and is what Cisco access lists and OSPF network statements expect. Both are derived from the prefix, which is why the calculator accepts any of the three forms.

Why /31 and /32 have no broadcast

A /32 is one address, a single host or a loopback. A /31 is two addresses used for a point-to-point link between routers, where RFC 3021 does away with the network and broadcast addresses because nothing else can be on the link. Every other prefix loses two addresses to those roles.

Private, public and the addresses in between

The scope line says whether an address is globally routable or belongs to one of the reserved ranges: RFC 1918 private space (10/8, 172.16/12, 192.168/16), the 100.64/10 carrier-grade NAT range that many ISPs now hand out instead of a public address, link-local 169.254/16 that a device assigns itself when DHCP fails, and the documentation and benchmarking blocks that should never appear on a real network. If your router's WAN address starts with 100.64 through 100.127, you are behind carrier-grade NAT and inbound port forwarding will not work.

IPv6 prefixes

IPv6 uses the same idea with 128-bit addresses. A /64 is the standard size for one LAN and holds 2^64 addresses, which is why the calculator reports counts as powers of two rather than as numbers nobody can read. An ISP typically delegates a /56 or /48 to a home or office, giving 256 or 65,536 individual /64 subnets. The tool also shows the fully expanded form, the RFC 5952 compressed form, and the ip6.arpa reverse zone, which is the nibble-reversed address that PTR records live under.

Range to CIDR

Firewalls, route tables and cloud security groups take CIDR blocks, not "from this address to that one". Given any start and end address the tool returns the smallest set of aligned blocks that covers exactly that range and nothing outside it. A range that starts or ends off a block boundary will need several blocks; that is normal.

// OTHER TOOLS
MAC Vendor Lookup
OUI · MA-L · MA-M · MA-S
Certificate & CSR Decoder
X.509 · PKCS#10 · PEM · DER
DNS Leak Test
VPN · RESOLVER · PRIVACY
DNS Benchmark
CLOUDFLARE · GOOGLE · QUAD9 · 8 RESOLVERS
Port Lookup
TCP · UDP · WHAT IS PORT…
HAR Analyzer
HTTP ARCHIVE
What Is My IP
PUBLIC IP · FINGERPRINT