IP Address Converter

Convert an IPv4 address between dotted decimal, binary, hexadecimal and 32-bit integer notation, and see how each octet maps to bits.

Runs entirely in your browser. Your input is never sent to our servers.

Dotted decimal
192.168.1.10
32-bit integer
3232235786
Hexadecimal
0xC0A8010A
Binary
11000000.10101000.00000001.00001010
Octal per octet
300.250.1.12
Reverse DNS name
10.1.168.192.in-addr.arpa
Scope
Private — reserved by RFC 1918
Private address
This address is reserved by RFC 1918 and is not routable across the public internet. Seeing one in a log that should contain client addresses usually means a proxy header was trusted, or was not read at all.

What is IP Address Converter?

An IP address converter renders the same IPv4 address in each of its equivalent notations — dotted decimal, 32-bit integer, hexadecimal, binary and octal — and identifies which reserved range, if any, the address belongs to.

What this IP Address Converter does

An IPv4 address is a single 32-bit number. 192.168.1.10 is a convenience for humans; 3232235786 and 0xC0A8010A are the same value written differently. Databases store addresses as integers, packet captures and firmware show them in hex, and access control logic is easier to reason about in binary.

Paste any of those forms and this converter produces the rest, along with the reverse DNS name and the scope the address falls in — private, loopback, link-local, carrier-grade NAT, multicast or globally routable.

How to use it

  1. Paste an address in any notation. The tool detects which one you used.
  2. Dotted decimal needs four octets of 0–255; hexadecimal should carry the 0x prefix.
  3. Read across for the other representations, the in-addr.arpa name and the scope.

Understanding your results

32-bit integer — the form most databases use, because comparing and range-checking integers is far cheaper than parsing strings. Converting back is often the only way to read such a column.

Reverse DNS name — the octets reversed under in-addr.arpa. This is the name a PTR lookup queries, and mail servers check it when deciding whether to trust a sending host.

Scope — which reserved block the address sits in, and the RFC that reserves it. Addresses in these ranges are not routable across the public internet.

Why this matters

Reserved ranges appearing where public addresses should be is a diagnostic signal. A web log full of 10.x or 172.16–31.x client addresses usually means the application is reading the socket address rather than the forwarded header, so every request appears to come from the load balancer.

The reverse mistake matters more. Trusting a client-supplied forwarded header without checking which hop added it lets a visitor choose the address your rate limiter and audit log will record — which defeats both.

Carrier-grade NAT space (100.64.0.0/10) is worth recognising in particular: many mobile users share those addresses, so blocking one can block a large number of unrelated people.

Common mistakes

Assuming 127.0.0.1 is the only loopback. The whole 127.0.0.0/8 is reserved, so 127.0.0.2 is equally local.

Reading a leading-zero octet as decimal. Some libraries parse 0177.0.0.1 as octal, which has been used to slip past naive address filters.

Treating any 172.x as private. Only 172.16.0.0/12 is — that is 172.16 through 172.31, not the whole 172 block.

Limitations

IPv4 only. IPv6 addresses are 128 bits with their own text representation and compression rules.

Scope is determined from the address alone. It cannot tell you whether an address is reachable, allocated, or filtered on your network.

Frequently asked questions

Why would an address be stored as an integer?

Because integer comparison is fast and range queries become simple arithmetic. Checking whether an address falls inside a block is one BETWEEN clause rather than string parsing on every row.

What is in-addr.arpa?

The domain used for IPv4 reverse lookups. The octets are reversed and appended to in-addr.arpa, so 192.168.1.10 becomes 10.1.168.192.in-addr.arpa. A PTR record there maps the address back to a name.

Is 100.64.0.0/10 private?

It is reserved, but not private in the RFC 1918 sense. It is shared address space for carrier-grade NAT, so many unrelated subscribers can appear behind one address in that range.

Why does 0177.0.0.1 sometimes resolve to localhost?

Some parsers interpret a leading zero as octal, making 0177 equal to 127. Inconsistent handling between a filter and the library that finally opens the connection has been used to bypass address restrictions.

References

Last reviewed