Guide
Check your IP address from the command line
One-line commands for your public IPv4 and IPv6, local address and DNS resolver on Linux, macOS and Windows — plus IP-change monitoring.
On this page
The browser check on our home page is the fastest way to see what the internet thinks your address is. But when you are on a server, over SSH, inside a container or writing a script, the terminal is faster — and it tells you which protocol the address came from, which the browser usually hides. Here are the commands worth memorising.
Get your public IP
# Public IPv4 (forces the IPv4 stack)
curl -4 https://api.ipify.org
# Plain text, no formatting at all
curl https://ifconfig.me
curl https://ifconfig.co
curl https://icanhazip.com
# Public IPv6 (fails if the host has no v6 route)
curl -6 https://api64.ipify.org
# Full lookup: ISP, ASN, city, time zone, proxy flags
curl -s https://ipwho.is/ | python3 -m json.tool
# Check somebody else's address
curl -s https://api.ipquery.io/8.8.8.8 | python3 -m json.tool
All of those endpoints are the same keyless, CORS-clean services our checker uses, so the result matches what the page shows — and the flags let you pin the protocol, which is how you catch an IPv6 leak: if curl -4 returns your VPN's address but curl -6 returns your home carrier's, IPv6 is bypassing the tunnel.
What the commands actually return
| Command | Returns | Use when |
|---|---|---|
curl https://api.ipify.org | Address only, plain text | Scripts, quick checks |
curl https://ifconfig.me/ua | Your user agent, from that server's view | Debugging headers and proxies |
curl -s https://ipwho.is/ | JSON: ISP, ASN, city, country, timezone | Full picture, no browser |
dig +short myip.opendns.com @resolver1.opendns.com | Address via DNS, port 53 | When HTTP(S) egress is blocked |
dig -4 TXT +short o-o.myaddr.l.google.com @ns1.google.com | Address, optionally mirrored on the IPv6 path | Comparing v4 and v6 paths |
The DNS-based methods matter in locked-down networks where only DNS is allowed out — a common pattern in captive portals and corporate filters.
Local addresses and interfaces
# Linux (iproute2 — the modern default)
ip -4 addr show scope global
ip -6 addr show scope global
ip route get 1.1.1.1 # which source address will be used
# macOS
ipconfig getifaddr en0
ifconfig | grep "inet " | grep -v 127.0.0.1
# Windows (PowerShell)
Get-NetIPAddress -AddressFamily IPv4 | Select-Object IPAddress, InterfaceAlias
ipconfig /all | findstr /i "IPv4 Default"
Remember the split these commands expose: everything starting with 10., 172.16–31. or 192.168. is a private address inside your network (see public vs private IP), and 127.0.0.1 is loopback. If you are looking for the router, read the default gateway — the router IP guide has the per-platform detail.
Resolver and DNS checks
# Which resolver is actually answering?
resolvectl status # Linux (systemd)
scutil --dns | head -20 # macOS
ipconfig /all | findstr /i "DNS Servers" # Windows
# Query a specific resolver
dig @1.1.1.1 example.com +short
nslookup example.com 9.9.9.9
If the resolver listed belongs to your ISP while a VPN is connected, you have the classic setup for a DNS leak. Compare both before and after connecting the tunnel — see is my VPN working.
Monitor your IP in a script
#!/bin/sh
# Log a line whenever the public IP changes — handy on dynamic connections
IP=$(curl -4 -s https://api.ipify.org)
echo "$(date -Iseconds) $IP" >> ~/ip-history.log
tail -n 1 ~/ip-history.log
Run that from cron every fifteen minutes and you have a record of every lease change, useful for explaining a dropped port forward or a session that a streaming service killed. On a server, do the same over SSH and combine it with -6 to watch both protocols. A dynamic DNS client automates the useful part: it re-points a hostname at whatever address you have — see why your IP changes and static vs dynamic addresses.
Bottom line: curl -4 https://api.ipify.org covers 90% of terminal checks; ipwho.is gives the full lookup; dig variants work when HTTP is blocked. Pin the protocol with -4 and -6 and you will find leaks a browser hides.
Frequently asked questions
What is the curl command to check my IP address?
curl -4 https://api.ipify.org prints your public IPv4 in plain text; swap to -6 and api64.ipify.org for IPv6. Add -s in scripts to suppress progress output.
How do I check my IP address on Linux?
Public: curl -4 https://api.ipify.org. Local: ip -4 addr show scope global. Router: ip route. Resolver: resolvectl status.
Does curl show IPv4 or IPv6?
It uses whichever the resolver returns and the host can route, preferring IPv6 on many systems. Force a family with -4 or -6 to know exactly which one you tested.
Keep reading
- How to check your IP address on a phone
- Is an IP address personal data?
- How to fix an IP address conflict
- MAC address vs IP address
- How to find your IP address on a computer
- How to find your router's IP address
- How to trace an IP address
- What can someone do with my IP address?
- What is a local IP address?
- How to change your IP address
- How to hide your IP address
- What is an IP address?
- Browse all IP guides
- Check my public IP address
Check any other IP address
Investigating a suspicious login, a spam email header or a server log entry? Run any IPv4 or IPv6 address through the same geolocation and proxy checks.