Get Real IP

Frequently Asked Questions

Can't find your answer? Contact us.

Getting Started

What exactly is Get Real IP?↓
Get Real IP gives you a dedicated static public IPv4 address, routed to your home or office through an encrypted WireGuard tunnel. It's like having a business ISP static IP, but it works even if you're stuck behind CGNAT or a dynamic IP — and it costs a fraction of the price.
Do I need a static IP from my ISP?↓
No. That's the whole point. Get Real IP works regardless of what your ISP gives you — dynamic IP, shared IP, or CGNAT. The WireGuard tunnel connects outbound from your network to our servers, so your ISP's IP address doesn't matter.
What is CGNAT and why is it a problem?↓
Carrier-Grade NAT (CGNAT) is when your ISP shares one public IP address across many customers. You can connect outbound to the internet normally, but inbound connections to your home — like accessing your server, game server, or cameras — are blocked because nobody outside can reach you directly. Get Real IP solves this by giving you a real public IP that routes to your network.
Which endpoint should I choose?↓

Pick the endpoint with the lowest latency from your location. Our latency test page measures the round-trip time from your browser to every endpoint — run it and choose the one with the smallest number. Generally the geographically closest endpoint wins.

How long does setup take?↓
Under 10 minutes for most setups. Sign up, pay, download the WireGuard config, import it into your router or device, and connect. Your static IP is live the moment you subscribe — no waiting for ISP provisioning.
Is there a free trial?↓
Yes. Your first tunnel and IP are free for 7 days. A valid card is required at signup but you won't be charged until the trial ends. You can cancel anytime during the trial from your dashboard — no charge, no questions asked.
Can I add additional IPs or tunnels during the trial?↓
Yes — but doing so ends your free trial immediately and converts you to a paid subscription. When you add an IP ($4/mo each) or a tunnel ($8/mo each) during the trial, we bill you right away for your first full month plus the new resource, and your monthly billing date resets to that day. The dashboard asks you to confirm this before it happens. If you'd rather keep your trial running, wait until it ends before adding more.
What if I'm not ready to use my trial but I want to get announcements like new region endpoints?↓
Just create an account. Your free trial won't start until you create your first tunnel — signing up alone doesn't use it. You'll receive announcements about new features and endpoint launches automatically.

Technical

Can I use this to put my localhost app on the internet?↓

Yes — this is one of the simplest ways to make a local project accessible to anyone. If you're running something on 127.0.0.1:4321 (a dev server, an AI app, a side project), Get Real IP turns that into 134.49.x.x:4321 — a real public address anyone on the internet can reach.

No need to learn Nginx, Docker, cloud platforms, or DNS configuration. Just install WireGuard, paste the config we give you, and your local ports are reachable at your public IP. It takes about 5 minutes.

See the Put Your Localhost on the Internet guide for step-by-step instructions.

What devices and routers are supported?↓
Anything that supports WireGuard: Linux, Windows, macOS, iOS, Android, pfSense, OPNsense, GL.iNet, MikroTik, UniFi, Raspberry Pi, and more. WireGuard is widely supported and lightweight. See our setup guides for step-by-step instructions.
Can I run any service on any port?↓
Yes. All ports are open for inbound and outbound traffic, with one exception: outbound port 25 (SMTP) is blocked by default to prevent abuse by spammers. Inbound port 25 is open, so you can receive email without any special request. If you need to send email directly from your IP, like a mail server on port 25, contact us to request an outbound unblock.
Can I connect the tunnel over IPv6?↓

Yes. Our concentrators are dual-stack, so if your ISP gives you working IPv6 you can establish the WireGuard tunnel over your IPv6 connection. The endpoint hostname resolves on both IPv6 and IPv4, and WireGuard picks IPv6 automatically when it's available, falling back to IPv4 otherwise.

Connecting over IPv6 is slightly more efficient: your device gets a real end-to-end IPv6 path to the concentrator, avoiding the NAT that the IPv4 transport has to traverse — whether that's your own home NAT or your ISP's CGNAT. Either way your dedicated static IPv4 address works exactly the same; this only affects how the tunnel itself reaches us.

Can multiple computers share the same tunnel?↓

Yes. You can subscribe to multiple IPs on a single tunnel, then route each of those IPs to a different computer on your network. The tunnel runs on one device (often your router or a small always-on box), and traffic for each public IP is forwarded to whichever internal host you assign it to. See the Policy-Based Routing guide for step-by-step setup.

IPv6 makes this even easier. Your tunnel includes a dedicated IPv6 range of 264 addresses — enough for every device you'll ever own. You can configure your home network to hand out addresses from within this range and route them over the tunnel, so multiple computers get their own public IPv6 addresses at the same time without needing a separate subscription for each.

Is my traffic firewalled by Get Real IP?↓

No — and this is by design. We route your static IP directly to your device. We are not a middlebox and we do not filter or inspect your traffic. The entire point is that you get a real public IP with full control over what runs on it.

This means you are responsible for your own firewall. Any port that isn't protected by software on your device (or your router) is reachable from the internet. If you're running services you don't want exposed, make sure they're protected before connecting.

Most operating systems include a built-in firewall:

The exception is outbound port 25, which we block by default on our end to prevent abuse by spammers — see the question above.

Can I use it on my whole network, not just one device?↓
Yes. Run WireGuard on your router (pfSense, GL.iNet, etc.) and set up port forwarding to route inbound traffic to any device on your LAN. The static IP routes to the device running WireGuard — port forwarding gets it to the right machine behind it. See the pfSense or Linux guides for setup details.
Is my traffic inspected or logged?↓
No traffic inspection. Your data flows through an encrypted WireGuard tunnel — we don't see the content. We do collect minimal tunnel connection metadata (such as connection timestamps and aggregate bandwidth) for billing and abuse detection purposes — not the traffic you send through the tunnel. See our Privacy Policy for details.
Can I use the tunnel only for incoming traffic on my static IP?↓

Yes. By default the tunnel routes all your traffic (inbound and outbound) through your static IP, but if you'd rather keep your normal ISP for browsing and downloads and only use the tunnel for incoming connections, you can. For Linux and macOS we provide ready-made "incoming-only" config downloads — just pick that option when you download your config and it's set up for you, no manual routing required.

Under the hood this uses policy-based routing: packets arriving from the tunnel get marked, and a separate routing table sends replies back the same way, while your normal outbound traffic keeps using your default route. Our Linux and macOS configs handle this automatically. On other platforms or on a router, you set the same rules up yourself.

The reason this is needed: your OS won't automatically send replies back via the tunnel just because the inbound packet arrived that way — without the policy rules, replies leak out your ISP connection with the wrong source IP and the connection breaks. The incoming-only configs (or the guide below) take care of exactly that.

See the Policy-Based Routing guide for step-by-step instructions on Linux (fwmark + ip rule), BSD/pfSense/OPNsense (pf reply-to), and other routers. There's also an advanced section covering multiple IPs routed to different LAN hosts.

Can I move IPs between tunnels, or merge/split tunnels?↓

Same endpoint location: Yes. If both tunnels are on the same endpoint (e.g. both on turnpike), we can move IPs between them, merge two tunnels into one, or split a tunnel's IPs across new tunnels. Use the contact form to request this and we'll handle it for you.

Different endpoint locations: No. IPs are tied to the subnet of their endpoint location and can't be moved between locations. If you need an IP at a different endpoint, you'll need to create a new tunnel there.

Can I set up reverse DNS (PTR records)?↓
Yes. Every IP you provision can have a custom PTR record, set directly from the dashboard. This is important if you're running a mail server. Changes propagate within a few minutes. See the PTR Records guide for details.
Can I get a WHOIS reassignment record with my name and address?↓

Yes. By default, all our IP reassignment records in ARIN's WHOIS database are marked as a private customer — your name and address are not published. If you'd like your information to appear on the WHOIS record for your IPs, contact us and we'll update it.

This can be useful if you want GeoIP databases to associate your IP with a specific location, or if you're running a business and want your organization name visible on the IP registration. Most residential users prefer the default private record.

What's the difference between this and Cloudflare Tunnel / Ngrok?↓
Cloudflare Tunnel and Ngrok are HTTP proxies — they only work for web traffic and they sit in the middle of your connections. Get Real IP is a real routed IP address. Traffic arrives at your network unmodified — no proxy, no inspection, any protocol, any port. Your IP is also dedicated to you, not shared.
Can I get a custom WHOIS/RDAP record or GeoIP entry for my IP?↓
Yes. We can create a SWIP reassignment record so your name or organization shows up in WHOIS/RDAP lookups for your IP. We can also add a custom geolocation entry so your IP resolves to your city instead of our server location. Both are available at no extra charge for paying subscribers (not during free trial) — just contact us and let us know what you'd like.

IPv6

Do you support IPv6?↓
Yes. Every tunnel is dual-stack — you get IPv6 alongside your IPv4, both as real, publicly routable addresses. If your ISP gives you working IPv6, you can even connect the tunnel over your IPv6 connection, which avoids the extra layer of address translation (like carrier CGNAT) that IPv4 often goes through.
Do I get IPv6 addresses too?↓
Yes — every tunnel includes a dedicated IPv6 range in addition to your IPv4 address, at no additional charge. It's yours to use for your services exactly like your IPv4: any protocol, any port, routed straight to your network. It shows up in your downloadable config automatically.
Can I get more IPv6 space?↓
The IPv6 range included with each tunnel holds over 18 quintillion addresses (264) — enough for essentially any number of devices in a homelab or small business. If you need additional subnets to support multiple internal networks, contact us and we'll set you up.

Billing

What does it cost?↓
$8/month per tunnel, which includes one static IP. Additional IPs on the same tunnel are $4/month each. No contracts, no setup fees. See the pricing page for full details.
Can I pay in a currency other than USD?↓
Our payment processor offers checkout in a number of other currencies, as well as several USD stablecoins.
What if I want to pay with one-time payments like cryptocurrency or Cash App?↓
Your account needs a subscription-capable payment method (such as a card) on file to keep service running. That said, some one-time methods — like Cash App or certain USD stablecoins — are accepted by our payment processor and can be added to your account credit balance at any time, which is applied toward your service. And if you'd like to pay directly with another cryptocurrency, such as Bitcoin, Ethereum, or Litecoin, just reach out through our contact form and we can usually arrange a one-time payment link.
Can I cancel anytime?↓
Yes. You can mark any IP as "do not renew" from the dashboard and it stays active until the end of your current billing period — no immediate cutoff.
What happens if my payment fails?↓
We'll notify you by email with a link to update your payment method. If your payment isn't resolved by your renewal day, your tunnel is suspended. Update your payment method from the dashboard to restore service.
How do I delete my account?↓

First, cancel all your IPs and tunnels from the dashboard using "do not renew." Once your billing period ends and your resources are deactivated, contact us to request full account deletion.

We'll remove your account data from our systems. Payment records may be retained separately for tax and legal compliance.

General

How do I request an additional feature for the service?↓

Use the contact form and select "Feature Request" as the category. Describe what you're trying to do and why it would be useful. We read every submission and use them to prioritize the roadmap.

Some things we've heard interest in: expanded endpoint locations (West Coast, Europe, Asia), a reverse proxy option (like rathole or frp) instead of WireGuard, HTTP/SOCKS proxy access, IPv6 support, managed firewall rules, or API access for programmatic IP management. Even if it's on this list, let us know — the more people ask for something, the sooner it gets built.

Still have questions?

Contact Us