Get One Month of Starlink FreeSPECIAL OFFER: GET A FREE MONTH OF STARLINK >
Connected network ports on a home router

Does Starlink Provide a Static IP? Public IP, CGNAT and Safe Alternatives

Tips & Tricks

Back to Tips & Tricks

Starlink can provide a public IPv4 address on eligible Priority service plans, but a normal residential connection usually uses carrier-grade network address translation (CGNAT). A public address is not the same thing as a permanently static address, and changing to a third-party router or bypass mode does not remove provider-side CGNAT.

This guide shows how to check what kind of address you have, what Starlink's current public-IP option does, and which safer alternatives work when you cannot receive unsolicited inbound connections.

Plan names, eligibility, pricing and account labels can vary by country and change over time. Treat the options shown in your Starlink account as the final authority.

The short answer

  • Default Starlink IPv4: usually CGNAT, which means your router does not receive a directly reachable public IPv4 address.
  • Public IPv4: available on eligible Local Priority and Global Priority service plans in supported markets.
  • Truly static IPv4: Starlink's current Help Center says a public address is not truly static. A reservation may keep the address across a normal reboot, but relocation or software updates can change it.
  • Best workaround for most homes: use a private mesh VPN for your own devices, or an authenticated outbound tunnel for a web application.
  • What bypass mode changes: it can remove an extra router layer inside your home. It cannot remove Starlink's upstream CGNAT.

Public IP versus static IP

These terms describe different properties.

A public IPv4 address is reachable from the wider internet, subject to your router firewall and any provider restrictions. It can make traditional inbound connections possible.

A static IPv4 address stays assigned to you reliably over time. That matters when a remote client, allow-list or DNS record must keep pointing to the same address.

Starlink's IP address guidance says the public IPv4 policy uses DHCP and that truly static IPs are not available. Starlink also describes a reservation system that can retain the public IPv4 address and IPv6 prefix when the system is switched off or rebooted, while warning that moving the service or applying software updates can change them.

Plan for a public but potentially changing address unless Starlink explicitly documents a different arrangement for your account.

Check whether you are behind CGNAT

You can check this without changing your plan.

  1. Connect a computer to the network you want to test.
  2. Open your router's administration page and find its WAN, Internet or external IPv4 address.
  3. In a separate browser tab, search for "what is my IP" and note the public IPv4 address shown by the result.
  4. Compare the two values.

You are probably behind provider-side CGNAT when the router's WAN address and the browser-reported public address are different and the WAN address is in the shared range 100.64.0.0 to 100.127.255.255. That range is the IPv4 block commonly used for carrier-grade NAT.

Private addresses are another sign that you are not directly receiving a public IPv4 address:

  • 10.0.0.0 through 10.255.255.255
  • 172.16.0.0 through 172.31.255.255
  • 192.168.0.0 through 192.168.255.255

Do not treat this comparison as a perfect diagnostic if you use a VPN, privacy relay, enterprise gateway or a browser that reports a different egress path. Disable those temporarily, or repeat the test from a simple device connected directly to the Starlink network.

Rule out ordinary double NAT

A second router can also make the comparison confusing.

If the Starlink router feeds a third-party router without bypass mode, the third-party router may receive a private address from the Starlink router. That is double NAT inside your home, not proof that Starlink has supplied a public address.

You can:

  • Test with the third-party router disconnected.
  • Use the Starlink router's own internet status where available.
  • Put the Starlink router into bypass mode only when your hardware and network plan support it.
  • Repeat the WAN-versus-public-address comparison after the change.

Bypass mode may remove the local NAT layer. It does not turn a CGNAT address into a public one.

For the hardware and recovery implications, see How to Use Your Own Router with Starlink Bypass Mode.

Check whether your plan can use a public IPv4

Starlink's current public-IP instructions describe the option for Local Priority and Global Priority service plans. The setting is account- and market-dependent, so do not assume that a plan name shown in another country has the same feature.

In the account area, the documented path is:

  1. Sign in at starlink.com/account.
  2. Open Account.
  3. Select Subscriptions.
  4. Select the service line you want to change.
  5. Select Edit beside IP Policy.
  6. Choose Public IP.
  7. Save the change.
  8. Reboot the Starlink system.

Business account screens may place the same setting under Dashboard and Service Line instead. Use the labels visible in your account, and open a support ticket when the option is missing or your market requires Starlink to make the change.

Before changing plans or IP policy, check:

  • Whether the public-IP option is available at your service address.
  • Whether there is a plan or data-cost increase.
  • Whether the address is public but dynamic rather than static.
  • Whether your router can handle the required firewall and forwarding rules.
  • Whether your application really needs arbitrary inbound connections.

A public IP is a routing feature, not a security feature.

Test the public-IP change safely

Do not start by forwarding every port.

After the account change and reboot:

  1. Check the router's new WAN IPv4 address.
  2. Compare it with the address reported by an external IP-check service.
  3. Confirm the router's firewall is still enabled.
  4. Test one low-risk service from a separate internet connection, such as a phone with Wi-Fi disabled.
  5. Remove the test rule when you are finished.

If the WAN and external IPv4 addresses still differ, or the WAN address remains in 100.64.0.0/10, the public policy may not be active, the reboot may not have completed, or another router may still be in the path. Check the account setting and contact Starlink Support before making more firewall changes.

If the addresses match but the service is unreachable, check the application itself:

  • Is the service running and listening on the expected local address?
  • Does the device firewall permit the connection?
  • Is the router forwarding the correct protocol and port?
  • Does the device have a stable DHCP reservation or local address?
  • Are you testing from genuinely outside the Starlink connection?
  • Does the application require a hostname that still points to an old address?

A port checker reports a closed port when no application is listening, even if the network path is correct.

If you cannot get a public IPv4

You still have practical options. Choose the smallest exposure that solves the actual problem.

Use a private mesh VPN

For reaching your own computer, NAS, printer, Home Assistant instance or remote desktop, a private mesh VPN is usually the cleanest option.

Install the VPN client on the device at home and on the phone or laptop you use remotely. Approve only the devices you recognise, enable multifactor authentication, and connect through the private VPN address. Because the connection starts outbound, this can work through CGNAT.

If a device cannot run the client, a supported always-on computer or router can sometimes act as a subnet router. Advertise only the local network ranges you need, and follow the VPN provider's current security guidance.

Use an authenticated outbound tunnel

For a browser-based dashboard or web application, an outbound tunnel can avoid inbound port forwarding. A connector inside your network makes outbound connections to the tunnel provider, while the public hostname is protected by authentication and access rules.

This is not a universal replacement for every protocol. Put an identity check in front of the application, keep the application patched and expose only the specific service that needs to be reachable.

Use a hosted relay or virtual server

Some applications need arbitrary inbound protocols or cannot run a VPN client. A small hosted server can provide the public endpoint and relay traffic back to your Starlink location through an outbound encrypted connection.

This adds cost and administration. Keep the relay updated, restrict its firewall and document how to revoke access if the home device is lost or compromised.

Consider IPv6 carefully

IPv6 can provide globally routable addresses without IPv4 port translation, but it is not an automatic promise that remote access will work. The Starlink plan, router, firewall policy and remote network all need working IPv6.

Do not disable the firewall just to make an IPv6 service reachable. For most households, a private mesh VPN is easier to understand and limit.

For a broader explanation of CGNAT and remote-access choices, see Starlink CGNAT and Port Forwarding: Remote Access Options.

Choose the right option

Use a public IPv4 when an application truly requires ordinary inbound protocols, the feature is available on your account and you are prepared to manage the firewall.

Use a private mesh VPN when access is for you, your family or a small team and the devices can run the client.

Use an authenticated outbound tunnel when you need to share a web application with named users.

Use a hosted relay when the application cannot run a VPN client or needs a public endpoint with arbitrary protocols.

Do not publish the service when it has weak authentication, old firmware, no reliable update path or sensitive administrative controls.

Security checklist

Before accepting inbound access:

  • Change default passwords and enable multifactor authentication where available.
  • Update the Starlink router, third-party router, server, NAS and application.
  • Allow only the exact ports and protocols you need.
  • Never expose router administration directly to the internet.
  • Prefer encrypted protocols and disable plain-text management interfaces.
  • Restrict access by identity, VPN membership or source address where possible.
  • Keep backups and a tested recovery path.
  • Review connection logs and remove unused rules.
  • Test from outside your Starlink connection.
  • Re-check the address after a relocation or major software update.

A public IP can make a service reachable. It cannot make an unsafe service safe.

Troubleshooting checklist

If remote access still fails:

  1. Confirm the Starlink account shows the intended IP policy.
  2. Reboot the Starlink system and allow it to finish starting.
  3. Compare the router WAN address with an external IPv4 check.
  4. Remove a second router temporarily or verify bypass mode.
  5. Confirm the application is listening on the expected device and port.
  6. Check the device firewall and router firewall separately.
  7. Test from mobile data with Wi-Fi disabled.
  8. Confirm DNS points to the current address if you use a hostname.
  9. Check whether the application or remote network supports IPv6.
  10. Ask Starlink Support to confirm the address policy attached to your service line.

Do not factory-reset the router as a first step. Preserve your working configuration until you know which layer is failing.

Bottom line

Starlink can provide a public IPv4 address on eligible Priority plans, but a public address is not the same as a guaranteed static address. Start by comparing your router's WAN address with an external IPv4 check. If your plan supports the public policy, enable it through the account area and test one service with the firewall intact. If it does not, use a private mesh VPN, authenticated tunnel or hosted relay instead of trying to force port forwarding through CGNAT.

Reviewed: 1 October 2026. References: Starlink IP address guidance, Starlink public-IP instructions and Starlink Support.

Get One Month of Starlink Free

Claim Your Free Month

Order through my referral link and activate your service. Your second month of Starlink service will be free.

Starlink Tips is independent and may receive a referral reward. Check the offer shown for your order.

Questions to help with your next step