The short answer
Quick answer: Every device on the internet needs an IP address. IPv4 addresses are 32 bits long, which allows about 4.3 billion of them, and far fewer are usable once reserved ranges are removed. That seemed endless in 1981. With billions of phones, laptops and servers, it wasn't. The regional registries ran out of fresh addresses in the 2010s. NAT (Network Address Translation) kept things going by letting a whole network of devices share one public address. IPv6, with 128-bit addresses, is the permanent fix, and its adoption is finally passing the halfway mark.
Why IPv4 ran out
An IPv4 address like 203.0.113.10 is four numbers from 0 to 255, which is 32 bits. That gives 2³² = 4,294,967,296 possible addresses. Big chunks are reserved for private networks, multicast, testing and future use, and early allocations were generous: some organisations received blocks of 16 million addresses each.
Addresses flow down a hierarchy. IANA hands large blocks to five Regional Internet Registries (RIRs), which allocate them to ISPs and companies in their region. Exhaustion happened in stages as each pool emptied:
| Date | Event |
|---|---|
| April 2026 | Google reports that half its users now reach it over IPv6 |
| November 2019 | RIPE NCC (Europe, Middle East) runs out of IPv4 addresses and moves to a waiting list |
| September 2015 | ARIN (North America) exhausts its free pool |
| September 2012 | RIPE NCC reaches its last /8 block and starts rationing |
| April 2011 | APNIC (Asia-Pacific) reaches its final /8 block |
| February 2011 | IANA hands out its last five /8 blocks, one to each RIR |
| December 1998 | IPv6 is first specified |
| February 1996 | Private address ranges are reserved in RFC 1918 |
| 1994 | NAT is proposed as a short-term fix |
| 1981 | IPv4 is specified in RFC 791 |
Today, IPv4 addresses are bought and sold on a secondary market, and cloud providers charge for public IPv4 addresses. The internet didn't stop growing, though. That's thanks almost entirely to NAT.
How NAT works

The trick behind NAT is private addresses. RFC 1918 set aside three ranges that are never routed on the public internet, so every home and office can reuse them:
10.0.0.0to10.255.255.255172.16.0.0to172.31.255.255192.168.0.0to192.168.255.255
Your router has one public address from your ISP and hands out private ones to your devices. When a device talks to the internet, the router rewrites each packet on the way through. This is usually NAPT (Network Address and Port Translation), which also changes port numbers so many connections can share one address:
- Your laptop sends a packet from
192.168.1.10:51000to a web server. - The router rewrites the source to its public address and a free port, say
203.0.113.7:40001, and records the pair in its translation table. - The server replies to
203.0.113.7:40001. It has no idea your laptop exists. - The router looks up port 40001 in its table, rewrites the destination back to
192.168.1.10:51000, and forwards the reply to your laptop.
Ports are 16-bit numbers, so one public IP can carry tens of thousands of simultaneous connections. TCP and UDP both carry port numbers, which is what makes this possible; see TCP vs UDP for how ports fit in.
NAT works invisibly for most traffic, including every step of loading a web page. Entries expire after a period of inactivity, which is one reason long-lived connections like WebSockets send regular heartbeats.
Carrier-grade NAT: NAT on top of NAT
As addresses ran out, ISPs, especially mobile networks, stopped giving every customer a public IPv4 address at all. Instead they run carrier-grade NAT (CGNAT): your home router gets an address from a shared range reserved for this purpose (100.64.0.0/10, defined in RFC 6598), and the ISP translates again at its edge. Hundreds or thousands of customers can share one public IPv4 address.
You can spot it yourself: if your router's "WAN" address differs from what a "what is my IP" site reports, you're behind CGNAT.
The downsides of NAT
NAT saved IPv4, but it broke one of the internet's original ideas: that any device can reach any other directly.
- Incoming connections fail by default. The router only knows where to send replies to connections started from inside. To host a game server or camera at home, you need manual port forwarding, which is impossible behind CGNAT.
- Peer-to-peer gets complicated. Video calls and file sharing use tricks like STUN, TURN and ICE (all part of WebRTC) to punch through NAT, and fall back to relaying traffic through a server when that fails.
- Shared reputation. Under CGNAT, many strangers share your public IP. If one of them spams or attacks a site, everyone behind that address can get rate-limited or blocked.
- State and logging costs. The NAT device must track every connection, and ISPs must log port mappings to identify users for abuse or legal requests.
- Server-side headaches. Load balancers and CDNs that rate-limit by IP address risk treating a whole office or mobile network as one client.
IPv6: the permanent fix
IPv6, specified today in RFC 8200, uses 128-bit addresses like 2001:db8::10. That's 2¹²⁸, roughly 3.4 × 10³⁸ addresses, enough to give every device its own globally unique address with plenty to spare.
| IPv4 | IPv6 | |
|---|---|---|
| Address size | 32 bits | 128 bits |
| Number of addresses | About 4.3 billion | About 3.4 × 10³⁸ |
| Example | 203.0.113.10 | 2001:db8::10 |
| NAT needed? | Almost always | No; every device can have a public address |
| Address setup | Usually DHCP | Automatic (SLAAC) or DHCPv6 |
| DNS record | A | AAAA |
Without NAT, security comes from a firewall that blocks unsolicited incoming traffic, which is what home routers do for IPv6 by default.
So why hasn't IPv6 simply replaced IPv4? IPv4 and IPv6 aren't directly compatible, so networks run both side by side (dual stack), and NAT made the pain of IPv4 scarcity tolerable enough that many organisations delayed. Adoption has climbed steadily anyway: in April 2026, Google reported that half of its users now reach it over IPv6. When both are available, your device's DNS lookup asks for both A and AAAA records and usually prefers IPv6.
Frequently asked questions
Has the world actually run out of IPv4 addresses?
The free pools at IANA and the regional registries are essentially empty. Addresses still change hands through transfers and a paid market, and recovered addresses go to waiting lists, but there's no longer an easy supply of new ones.
Is NAT a security feature?
Not by design, though it has a side effect: devices behind NAT can't be reached by unsolicited connections. A proper firewall provides that protection deliberately, and IPv6 networks rely on firewalls instead of NAT.
What is the difference between a public and a private IP address?
A public IP address is unique on the internet and reachable from anywhere. A private address, such as 192.168.1.10, is only meaningful inside a local network and is reused by millions of networks.
How do I know if I'm behind CGNAT?
Compare the WAN address shown in your router's settings with the address a "what is my IP" website reports. If they differ, or the router's address starts with 100.64 to 100.127, there's another layer of NAT at your ISP.
Does IPv6 get rid of NAT?
Mostly, yes. With enough addresses for every device, NAT isn't needed for address sharing. Some networks still use translation to connect IPv6-only devices to IPv4-only services (NAT64).
Conclusion
IPv4's 4.3 billion addresses were never going to cover a world of phones, laptops and cloud servers. NAT bought decades of extra time by hiding whole networks behind one public address, at the cost of direct connectivity and a lot of engineering workarounds. IPv6 removes the scarcity for good, and after a long, slow start, it now carries a large share of real traffic.
Related articles
- What happens when you type a URL and press Enter
- How DNS turns "google.com" into an IP address
- TCP vs UDP: why the internet needs both
- How HTTPS keeps your data safe (TLS handshake explained)
- Why HTTP/2 and HTTP/3 exist
- How CDNs make websites load faster worldwide
- What is a load balancer?
- How WebSockets enable real-time apps
- How email travels from your outbox to someone's inbox
