Get a Static Public IP Behind CGNAT
Your ISP shares one public address between many customers, so nothing on the internet can connect in to your server. GetPublicIP routes a static public IPv4 and IPv6 address to that server. No router changes, no ISP upgrade, every port you map open to the world.
Why port forwarding can't work behind CGNAT
With carrier-grade NAT, the address on your router's WAN port isn't a public address. It sits in 100.64.0.0/10, the range RFC 6598 reserves for ISPs, and your ISP translates it a second time onto a public IPv4 address shared with other customers.
A port-forwarding rule on your router only works for traffic that reaches your router. With CGNAT, inbound connections stop at your ISP's NAT, which has no idea which customer they're for. No setting on your own equipment can change that.
For the full explanation, including how to confirm it and which ISPs use CGNAT, read how to self-host behind CGNAT.
How a static public IP gets around CGNAT
The trick is direction. Your ISP's NAT blocks connections coming in, but lets your server connect out. Your server opens an encrypted WireGuard tunnel out to one of our locations, and your public address is routed down that tunnel. Visitors connect to the address; the traffic arrives at your server as if the address were plugged straight into it.
- Choose a location. Pick the closest of 32 locations across 6 continents to the people who will connect.
- Connect your server. Import the WireGuard config on Linux, use the Windows client, or run the Docker image next to your containers.
- Open the ports you need. Map single ports or ranges in the dashboard, with optional source-IP rules. The address goes live within minutes.
We never inspect or modify your packets and never terminate your TLS, so your certificates, protocols and logs all see real client traffic.
What you can host behind CGNAT
Anything that needs a reachable address, over TCP or UDP, on IPv4 and IPv6. Some common examples, with their default ports:
| What | Default ports |
|---|---|
| Minecraft (Java / Bedrock) | 25565/tcp · 19132/udp |
| Valheim and other UDP game servers | 2456-2458/udp |
| Plex / Jellyfin | 32400/tcp · 8096/tcp |
| Home Assistant | 8123/tcp |
| Mail server, with reverse DNS | 25/tcp · 587/tcp |
| Websites and reverse proxies | 80/tcp · 443/tcp |
| SSH | 22/tcp |
CGNAT workarounds compared
A dedicated public IP isn't the only way around CGNAT. Here's how the common options differ in what they can actually do.
| Option | Protocols | Who can connect | Catch |
|---|---|---|---|
| Static IP from your ISP | All | Anyone | Only if your ISP offers one; many residential plans don't, and it stays with that connection. No fail over and often low reputation |
| Cloudflare Tunnel | HTTP and HTTPS | Anyone | Free for websites. Cloudflare terminates your TLS which means the traffic goes to clear text on their infrastructure. Game, mail or raw TCP/UDP traffic is out of scope. |
| Tailscale or another mesh VPN | All | Your own devices | Excellent for private access; not a way to serve the public. |
| GetPublicIP | All: TCP, UDP, ICMP | Anyone | $8.99/month per IP. Nothing to maintain; the address is yours. |
More detail in GetPublicIP vs Cloudflare Tunnel vs Tailscale.
One price, everything included
$8.99 USD per IP, per month
- Static public IPv4 and IPv6
- All ports and protocols, with port ranges
- Reverse DNS for mail servers
- 32 locations across 6 continents
- 99.9% availability, backed by our service level agreement
- No contract, cancel anytime
Questions about CGNAT and a static IP
Does it work on Starlink and T-Mobile Home Internet?
Yes. We've tested GetPublicIP on both. They put customers behind CGNAT by default, and because the tunnel is an outbound WireGuard connection from your server, your ISP's NAT never has to accept an inbound connection. Other fixed-wireless, 5G home internet and mobile hotspot connections work the same way, as long as they allow outbound UDP.
Do I need to change anything on my router?
No. There is no port forwarding, DMZ or UPnP to set up. The tunnel runs from your server, so your router and your ISP only ever see an ordinary outbound connection.
Is the IP address really static?
Yes. Your address stays the same for as long as you keep it, even if you switch ISPs, move house or move the server to another machine. That means DNS records pointing at it keep working.
Can I run a mail server behind CGNAT?
Yes. You can set a reverse DNS record for your address in the dashboard, which most receiving mail servers check. Personal mail servers are supported; bulk and mass mailing are not allowed under our acceptable use policy.
Do I get IPv6 as well?
Yes. Every IP includes both a public IPv4 and a public IPv6 address, routed through the same tunnel.
Will it slow my connection down?
Traffic to your public address makes one extra hop through the location you choose, so latency depends mostly on that choice. Pick the location closest to the people who will connect to your server.
Can I cancel anytime?
Yes. GetPublicIP is billed monthly at $8.99 USD per IP, with no contract or minimum term.