How to Check Your Public IP with curl

Learn how to retrieve your public IP with curl, handle lookup errors, and understand what the result tells you about your network connection.

Contents

A PC monitor displaying a public IP lookup floats above Earth, connected to a global internet network.

You need to allow your office IP through a firewall. Or check whether a request goes through your VPN. You run ip addr, get 192.168.1.42, and that's not the address the remote firewall sees.

Short version. Behind a router using NAT, your computer's address is usually different from the one an internet service sees. Ask a public IP endpoint to report the address used by your request. Vishow Tools' endpoint, https://vishowtools.com/ip, returns it as plain text.

Why your local address may not be your public address

On many IPv4 networks, your router or provider uses NAT, which replaces your private source address with a public one as traffic leaves the network. Traffic sent through a VPN may appear under the VPN server's address instead.

It's like posting a letter from a hotel. You know your room number; the recipient sees the hotel's street address. Asking the recipient tells you which address they saw.

That's what a public IP endpoint does: it reports the address it sees for your request.

There are exceptions. A server can have a public IPv4 address assigned directly to its interface, and computers often have globally routable IPv6 addresses. ip addr can show those addresses too. It shows addresses assigned to your interfaces, not necessarily the address a particular remote service sees.

Get just the address

The examples below use Vishow Tools' plain-text /ip endpoint. Adding /ip to an arbitrary website will not make it report your address.

curl https://vishowtools.com/ip

With a plain-text endpoint, the response contains the address rather than JSON or HTML. That matters when you're piping it somewhere.

The browser version is at What's My IP if you want it with context rather than in a script.

Put it in a variable

if public_ip="$(curl --fail --silent --show-error --max-time 10 https://vishowtools.com/ip)"; then
  printf '%s\n' "$public_ip"
else
  printf 'Public IP lookup failed.\n' >&2
fi

The options keep the output useful:

  • --fail makes HTTP errors such as 404 or 502 fail the request and suppresses their response body.
  • --silent hides the progress meter.
  • --show-error keeps error messages visible.
  • --max-time 10 limits the request to ten seconds.

The if checks whether curl succeeded before printing the result. Without --fail, an HTTP 502 response could leave an error page in the variable.

A successful request does not guarantee a valid IP address. Before using the value to update firewall rules automatically, validate it as IPv4 or IPv6 and handle lookup failures explicitly.

Why the address keeps changing

Residential connections often use dynamic addresses. Yours may change after a reconnection or when your provider assigns a different address. A reboot does not always change it.

Mobile networks often share public IPv4 addresses among customers. Your address can change when the data session reconnects or the network changes its routing; moving between towers does not necessarily change it.

VPNs usually show an exit server's address for traffic routed through them. If the lookup returns that address, it supports the conclusion that this request used the VPN exit. It does not prove that every application or destination uses the tunnel. Split tunnelling can send different traffic along different routes.

An HTTP or SOCKS proxy used by curl can also affect the result. For a firewall allowlist, check from the same machine and network path as the connection you intend to permit.

Practical consequence: an allowlist based on a dynamic address can stop working when that address changes. For long-term access, use a stable exit address or maintain the rule as the address changes.

You got an IPv6 address and expected IPv4

When both your connection and an IP lookup service support IPv6, a lookup may use it. An address containing colons is IPv6.

For a direct connection, request IPv4 explicitly:

curl -4 https://vishowtools.com/ip

An IPv6 lookup requires IPv6 connectivity on your side and a reachable IPv6 endpoint with an IPv6 DNS record. The -6 option selects IPv6; it does not convert an IPv4 address into IPv6. Use it only with an endpoint that meets those requirements. No IPv6 endpoint is provided in this guide.

Check which family the protected service uses before adding a firewall rule. Your IPv4 and IPv6 connections can take different routes and appear under different source addresses.

Private vs public addresses

The comparison below covers IPv4. IPv6 has its own address ranges and scopes.

Private IPv4 Public IPv4
Examples 192.168.1.42, 10.0.0.5 The public IPv4 address reported by an IP lookup
Who assigns it Usually your router or network administrator Usually an ISP, hosting provider, or network administrator
Routable over the public internet No Yes, but firewalls may block incoming connections
Shown by ip addr Yes, if assigned to a local interface Yes, if assigned directly to a local interface
Use in firewall rules For private networks, including routed VPN networks For connections arriving over the public internet

The private IPv4 ranges are 10.0.0.0/8, 172.16.0.0/12, and 192.168.0.0/16. In everyday notation, that means addresses beginning with 10., 172.16. through 172.31., or 192.168.. They are intended for private networks and should not be routed over the public internet.

An address outside these ranges is not automatically public. Loopback, link-local, and provider-shared address ranges are also reserved for special uses.

What to remember

  • ip addr shows interface addresses, which may be private or public.
  • An IP lookup reports the address seen for that request, not every connection from your machine.
  • Check curl's result and validate the address before using it in automation.
  • Use -4 or -6 when the address family matters and the endpoint supports it.
  • Keep address-based access rules up to date when your public address changes.
  • Seeing a VPN exit address does not prove that all traffic uses the VPN.

Check it in the browser at What's My IP.