How to check if you're behind CGNAT
Quick answer
Compare your router's WAN IP (in the router admin page) with your public IP as seen from the internet. If they don't match, you're behind CGNAT. A dead giveaway: a router WAN address in the 100.64.0.0–100.127.255.255 range, which is reserved specifically for carrier-grade NAT. If you're behind it, inbound connections can't reach you — bypass it with a static IP from your ISP or a dedicated-IP tunnel.
If hosting and port forwarding just won't work no matter what you try, the cause is usually carrier-grade NAT (CGNAT) — your ISP sharing one public IP across many customers so you never get your own. Here's how to confirm it in about two minutes.
The two-minute test
Compare two numbers:
- Your router's WAN IP. Log into your router's admin page and find the WAN / internet address it received from your ISP.
- Your public IP as seen from the internet. From any device on your network, check what the outside world sees — for example:
curl https://api.ipify.org
If the two addresses match, you have a real public IP on your line (it may still be dynamic, but it's yours). If they don't match, there's carrier equipment between you and the internet — you're behind CGNAT.
The dead giveaway: the 100.64.0.0/10 range
Look at your router's WAN IP. If it falls in 100.64.0.0 to 100.127.255.255, that's conclusive: that block (100.64.0.0/10) is reserved by RFC 6598 specifically for carrier-grade NAT. Seeing an address there means your ISP has placed you behind CGNAT and you do not have your own public IP.
Ordinary private ranges on your WAN (10.x.x.x, 192.168.x.x,172.16–31.x.x) can also indicate an extra layer of NAT, though those sometimes just mean a modem in bridge-vs-router mode. The 100.64/10 range specifically points at carrier NAT.
Another quick signal
Try forwarding a port and reaching it from outside your network (e.g. from mobile data, not your home Wi-Fi). If a correctly configured port forward is still unreachable from outside, and your WAN IP doesn't match your public IP, CGNAT is almost certainly the reason.
Which ISPs use CGNAT?
CGNAT is most common on mobile carriers, satellite internet, and newer fibre providers — but practices vary by plan, region, and even individual circuit, so treat this as "commonly, check yours" rather than a guarantee. The two-minute test above is always the real answer for your line.
Providers frequently reported to use CGNAT include:
- Satellite: Starlink (by default), most other LEO/satellite services.
- Mobile / 5G home internet: T-Mobile Home Internet, Verizon 5G Home, and most cellular carriers worldwide.
- India: Jio (incl. JioFiber on many plans), Airtel, BSNL, and ACT Fibernet commonly place residential customers behind CGNAT; static/public-IP options are usually a paid or business add-on where offered.
- Elsewhere: many regional fibre and WISP providers, and a growing number of residential ISPs conserving IPv4.
If your provider is on this list, don't assume — run the test. And if you are behind CGNAT, the fix is the same regardless of ISP: get a static IP from them if they offer one, or route a dedicated static IP to your server over a tunnel that works behind any CGNAT.
"But my ISP gives me IPv6 — am I set?"
Increasingly, ISPs that put you behind CGNAT on IPv4 do hand out real, publicly routable IPv6. That's genuinely useful — IPv6 traffic isn't NAT'd, so inbound connections can reach you over v6. But there's a catch that trips people up: the IPv6 prefix your ISP delegates is almost always dynamic. It's leased to your router (via DHCPv6-PD), and it typicallychanges when your router reboots, when the lease renews, or when the ISP renumbers — the same moving-target problem as a dynamic IPv4.
For casual use that's fine. But anything that depends on the address staying put breaks when it rotates: DNS records point at the old prefix, firewall allowlistsstop matching, TLS/HSTS and reverse DNS (PTR) assume a stable address, andemail — which leans heavily on a consistent IP with good reputation and matching PTR — is effectively impossible on a shifting residential prefix.
If you want the benefits of IPv6 without the churn — a static IPv6 range that never changes, with reverse DNS you control — you can get a dedicated static IPv6 range (and IPv4) routed to your network from Get Real IP. Your address stays fixed regardless of what your ISP does to your delegated prefix.
What to do if you're behind CGNAT
You have two paths:
- Ask your ISP to remove you from CGNAT or add a static IP. Some will (often on a business plan); many — especially mobile, Starlink, and newer fibre — won't or can't.
- Bypass it with a tunnel. Get Real IP routes a dedicated static public IP to your server over an outbound WireGuard tunnel. Because your server initiates the connection, it works behind the strictest CGNAT — no ISP change needed — and gives you a real, reachable IP for any protocol.
