How to get a static (public) IP address
Quick answer
Every connection has a public IP, but it's usually shared (CGNAT) or dynamic. To get a dedicated static one you have three real options: request a static IP from your ISP (often business-plan only), rent a cloud VPS and host or tunnel through it, or route a dedicated static IP to your own server over a WireGuard tunnel with a service like Get Real IP. Only the tunnel route works behind CGNAT with no ISP involvement.
"Public IP," "static IP," "real IP" — people mean slightly different things, but if you're trying to host something the goal is the same: a dedicated address on the internet that doesn't change and that inbound connections can actually reach. Here are the realistic ways to get one, with honest trade-offs.
First, the terms
- Public IP — any address visible on the open internet. Most homes have one, but it may be dynamic or shared via CGNAT.
- Dynamic IP — a public IP your ISP changes periodically. Fine for browsing, painful for hosting.
- Static IP — a public IP that never changes. This is what hosting, DNS, firewall rules, and email all depend on.
- Behind CGNAT — you don't get your own public IP at all; it's shared. Inbound connections can't reach you.
Option 1 — Request a static IP from your ISP
The most direct route: ask your ISP for a static IP add-on. When available it's a real dedicated address right on your line, working for every protocol.
Trade-offs: often restricted to business plans at $10–30/month; tied to your physical line (move house, lose the IP); residential IP ranges frequently have poor email-sender reputation; no failover; and many ISPs — especially mobile and newer fibre — simply don't offer it, or can't because you're behind CGNAT.
Option 2 — Rent a cloud VPS
A small cloud server (from any major provider) comes with a static IP. Two ways to use it:
- Host on the VPS directly. Simple if your workload can live in the cloud — but then it's not self-hosted at home, and you're paying for and maintaining a server.
- Tunnel back home. Keep your data and services on your home hardware and bridge the VPS's public IP to it with your own WireGuard relay or reverse proxy. This works, but now you're building and babysitting the tunnel, the firewall, and the routing yourself — see the VPS-tunnel tradeoffs.
Trade-offs: ongoing cost and maintenance, and the DIY tunnel path is genuinely fiddly to get right and keep running.
Option 3 — Route a dedicated static IP to your own server (Get Real IP)
This is the tunnel approach done for you. Your server, router, or laptop opens an outbound WireGuard tunnel, and Get Real IP routes a dedicated static public IPv4 to it. Inbound traffic for that IP comes down the tunnel to your machine.
- Works behind CGNAT — the tunnel is outbound, so no ISP static IP is needed.
- Truly static and portable — the IP stays yours across ISPs, moves, and failover.
- Any protocol — it's a real routed IP, not an HTTP proxy.
- Reverse DNS control — set your own PTR, which matters for email.
- Compatible with your own domain name (optional) — point an A record at the fixed IP.
- No server to maintain — no VPS, no reverse proxy to build.
- $8/month, self-serve, running in minutes, no contract.
Which one is right for you?
If your ISP offers a cheap static IP and you'll never move, take it. If you want your workload in the cloud anyway, a VPS is fine. If you want to keep hosting on your own hardware at home — and especially if you're behind CGNAT, on Starlink/LTE, or need clean reverse DNS for email — routing a dedicated IP over a tunnel is the fastest, lowest-maintenance path.
