PublicIPChecker

Guide

What is CGNAT?

5 min read · Updated 2026-09-28

Carrier-grade NAT (CGNAT) puts hundreds of customers behind one public IPv4 address. Learn how to tell if you are behind CGNAT, what it breaks, and how to get around it.

CGNAT in one paragraph

Carrier-grade NAT is a second, network-level layer of address translation that your ISP runs. Your home router already does NAT — converting your devices' local addresses (192.168.x.x) onto one public address. CGNAT does the same thing again at the ISP's gateway, so your "public" address is actually a shared one used by hundreds or thousands of other customers. The reserved range for it is 100.64.0.0 – 100.127.255.255 (RFC 6598).

Why carriers did it

IPv4 simply ran out. Regional registries exhausted their free pools between 2011 and 2019, and mobile networks — with their billions of phones and IoT devices — were the first to feel the wall. Rather than give every customer a scarce unique IPv4 address, carriers now share one among many. The long-term fix is IPv6, which makes sharing unnecessary: see IPv6 in 2026 and IPv4 vs IPv6.

How to tell if you are behind CGNAT

  1. Open the IP checker and note your public address.
  2. Check your router's WAN status page and find its external address.
  3. If the router's address starts with 100.64 to 100.127, you are behind CGNAT — the router itself only has a shared carrier address.

Secondary signs: the checker's ISP field shows your carrier but the address behaves like a shared one (neighbors' activity affecting you), or a neighbour you know is on the same connection plan shows the same address.

What CGNAT breaks

  • Inbound connections and port forwarding — there is nowhere for an outside connection to land, so you cannot host a game server, camera or web app from home.
  • Shared reputation — a neighbour's spam or abuse can get the whole shared address flagged, producing unexpected CAPTCHAs or blacklisting. See IP reputation.
  • Remote access — tools that need a stable public endpoint simply do not work without a tunnel.

What it does not affect: normal browsing speed, streaming and almost everything day-to-day. CGNAT is a routing nuisance, not a speed one.

How to get a real public IP

  • Ask your ISP — many will allocate a unique IPv4 on request, sometimes free, sometimes a small monthly fee.
  • Switch on IPv6 — it gives every device its own globally unique address and bypasses the IPv4 pool entirely. Most modern routers have it enabled by default; the checker's IPv6 row confirms it is working.
  • Use a VPN when you need a different exit — it replaces your shared address with the provider's datacentre IP (which the checker will label as such).

Frequently asked questions

Is CGNAT a security risk?

The mechanism itself is not — it is the carrier's standard plumbing. The practical risk is shared reputation: a bad actor behind the same address can get it flagged, affecting everyone sharing it.

How many people share a CGNAT address?

It varies from tens to thousands depending on the carrier and area. Mobile networks, which use CGNAT most aggressively, tend toward the high end.

Does CGNAT slow down my internet?

Measurably, no. The extra translation happens on hardware built for it; any difference is in the noise compared to other network factors.


Keep reading

Check any other IP address

Investigating a suspicious login, a spam email header or a server log entry? Run any IPv4 or IPv6 address through the same geolocation and proxy checks.