Skip to content
VPNmine
LEAKS AND TESTING

What your IP address actually reveals

Your address tells every server you reach which network you are on, roughly where that network is, and whether two visits came from the same connection. It does not carry your identity, though your provider can link it to your account and is obliged to in some jurisdictions.

4 min read

Illustration of a run of binary digits and a map pin, joined by a dashed tunnel line on a dark grid.

Your address is in the header of every packet you send. It has to be, because it is how responses find their way back. That makes it the one identifier you cannot withhold from a server you connect to — there is no permission prompt and no browser setting, because it is not in the page.

What it discloses is worth being precise about, because both the alarmist and dismissive versions are wrong.

What it does reveal

Your network operator. The address belongs to a registered block, and the registry says who runs it. That names your ISP, your mobile carrier, your employer, or the hosting company behind a VPN.

A rough location. Country is usually right. City is often wrong. The lookup is against a commercial database recording where a block was allocated, not where you are sitting.

Connection type. Residential, mobile, business and datacentre ranges are distinguishable, which is how services identify VPN and proxy traffic.

Session linkage. Two visits from the same address are probably the same connection. Combined with anything else — a browser fingerprint, a login — that becomes a durable identifier.

Coarse timing. When your connection was active, from the perspective of each server you reached.

You can see all of this for your own connection on what is my IP.

What it does not reveal

Your name or address. The registry lists the ISP, not the customer.

Your exact location. Geolocation is not GPS and does not claim to be.

Your identity to a website. A site learns who you are when you sign in, not from the packet header.

What you did elsewhere. Each server sees only its own traffic.

Your provider can connect the address to your account, because it assigned it. In most jurisdictions that link is available to law enforcement through a legal process, and in several it must be retained for a period specified by law.

The Court of Justice of the European Union held in Breyer that a dynamic address is personal data for an operator with a legal route to identifying the subscriber. That is the reason address handling falls under GDPR at all, and it is a good summary of the address's real status: not identifying by itself, and one step from identifying.

Dynamic, static and carrier-grade NAT

Dynamic addresses change periodically, often at a router reboot or on the ISP's schedule. They still identify a connection for as long as they last, which is frequently weeks.

Static addresses do not change, which makes them a stable identifier.

Carrier-grade NAT puts many subscribers behind one public address, standard on mobile and increasingly on fixed lines. That makes the address much less identifying on its own — hundreds of people share it — and it means the provider needs port and timestamp records to link a session back to a subscriber, which is exactly what retention rules require them to keep.

IPv6 is more identifying, not less

An IPv6 address is not shared behind carrier NAT. Each connection, often each device, gets its own. That makes an IPv6 address a considerably better identifier than an IPv4 one behind CGN.

Privacy extensions randomise the host portion of the address periodically, which helps. The network prefix does not change, and it identifies the connection.

What a VPN changes

Websites see the server's address instead of yours: your network operator, your rough location and your session linkage all become the server's rather than your own. Since a VPN exit is shared, session linkage weakens considerably.

Your provider still knows which address it assigned you, and now also sees a tunnel to a VPN server. The exposure moves rather than vanishing, which is why what the provider records matters — VPNmine's privacy policy states what is kept, and the source address of a session is the field to look for in anyone's.

Keeping it in proportion

An address is one identifier among many, and not the strongest. Cookies, accounts and browser fingerprinting identify people more reliably and survive an address change without effort. Hiding your address is worth doing and it is the beginning of a privacy practice rather than the whole of one.

Sources

  1. RFC 791 — Internet Protocol
  2. EU Court of Justice — Breyer v Germany (C-582/14)
  3. RFC 6598 — Shared Address Space for CGN

Try it on the network this was written from

VPNmine is a free no-logs VPN running its own WireGuard servers, with native apps for Windows, macOS, Android, iOS, Android TV and Apple TV. No ads, no card.

Get VPNmine