Get Real IP

Expose your home server to the internet

Quick answer

If you have a real public IP, forward the port on your router and point DNS at it (with dynamic DNS if it changes). If you're behind CGNAT or want a stable, all-protocol setup, use a tunnel: Cloudflare Tunnel for websites, Tailscale for private device access, or Get Real IP to route a dedicated static public IP to your server for any protocol — web, game servers, email, SSH, and more.

You've got something running at home — a website, Nextcloud, Jellyfin, a game server, Home Assistant — and you want to reach it from outside. There are five common ways to do it. Which one fits depends on whether you have a real public IP and what you're exposing.

1. Port forwarding (if you have a real public IP)

The classic method: log into your router, forward the external port to your server's LAN IP and port, and point your domain at your public IP. Works for any protocol.

Only works if you actually have a public IP on your router. If you're behind CGNAT, there's nothing to forward and this silently fails — the number-one reason "port forwarding doesn't work."

2. Dynamic DNS (for a changing public IP)

If you have a real but dynamic public IP, a dynamic DNS client updates a hostname whenever your IP changes so your domain keeps pointing at you. Pair it with port forwarding.

Trade-off: it only papers over a changing IP for DNS. IP-based firewall allowlists, TLS pinned to an address, and email reverse DNS all still break when the IP moves. And it does nothing for CGNAT.

3. Cloudflare Tunnel (websites only)

Runs an outbound tunnel from your server to Cloudflare and exposes a local web service publicly, free, bypassing CGNAT.

Trade-off: HTTP/HTTPS only — no game servers, email, SSH on custom ports, VoIP, or raw TCP/UDP — and Cloudflare terminates TLS at its edge, so it can see your traffic in plaintext.

4. Mesh VPN like Tailscale (private access)

If only you and your own devices need access, a mesh VPN is ideal — reach your server from anywhere without opening any ports, and it bypasses CGNAT.

Trade-off: it's private. People who aren't on your VPN — friends on your game server, a webhook from a third-party service, the general public — can't reach you.

5. A dedicated static IP over a tunnel (Get Real IP)

Your server opens an outbound WireGuard tunnel and gets a dedicated static public IPv4 routed to it. Inbound traffic for that IP flows down the tunnel. It combines the strengths of the others without their main limits:

How to choose

Not behind CGNAT and exposing a website? Port forwarding + dynamic DNS is free and fine. Just a website and don't mind the edge seeing traffic? Cloudflare Tunnel. Only your own devices? Tailscale. Need a real public IP the whole internet can reach on any protocol — game servers, email, SSH, or you're stuck behind CGNAT? A dedicated static IP over a tunnel is the general-purpose answer.

Frequently asked questions

How do I expose my home server to the internet?

If you have a real public IP, forward the port on your router and point DNS at your IP (use dynamic DNS if the IP changes). If you are behind CGNAT or want a stable address, use a tunnel: Cloudflare Tunnel for websites, or Get Real IP to route a dedicated static public IP to your server for any protocol.

Why does port forwarding not work for me?

The most common reason is CGNAT — your ISP shares one public IP across many customers, so you have no public IP to forward. If your router WAN address is in the 100.64.0.0/10 range, you are behind CGNAT and port forwarding will silently do nothing. A tunnel to a dedicated IP fixes this.

Is it safe to expose a home server?

It can be, with basic hygiene: expose only the specific ports you need, keep services patched, use strong authentication, and terminate TLS on your own server. A dedicated IP with end-to-end encryption (no third-party middlebox seeing your traffic) plus a tight firewall is a reasonable setup.

Do I need a static IP to expose a home server?

You need a reachable public IP. It can be dynamic if you use dynamic DNS, but a static IP is far less fragile — DNS, firewall allowlists, TLS, and email all depend on the address staying the same. A dedicated static IP removes the moving-target problem entirely.

Want a dedicated static IP in minutes?

Get Real IP delivers a dedicated static public IPv4 to your server, router, or laptop over an encrypted WireGuard tunnel — any protocol, any port, works behind CGNAT. $8/mo, no contract.

Start your free trial

7 days free · Cancel anytime

Related guides

Updated September 4, 2026