This is the address servers see when you connect — the one to whitelist in a server firewall before you lock SSH or WHM down to known IPs.
Table of Contents
Whitelisting your IP on a server
On a CSF server: csf -a YOUR.IP.HERE “office”. For cPHulk in WHM, add it under Security Center » cPHulk » Whitelist. In Imunify360: imunify360-agent whitelist ip add YOUR.IP.HERE –comment office.
If your ISP gives you a dynamic address it will change; whitelist a VPN or office static IP instead, or use two-factor authentication rather than IP restrictions.
VPN and proxy check: device time zone vs IP location
The result compares two clocks. Your device time zone comes from your computer or phone settings, and a VPN or proxy does not change it. The IP location time zone comes from where your public IP address is registered. When they differ by an hour or more, you are most likely connected through a VPN, proxy, Tor or a corporate network, or you are travelling. Tor Browser and Firefox with fingerprinting protection report UTC on purpose, so for them the check is inconclusive.
The location is city-level and approximate, and mobile or satellite networks can place you in a city far away. It is looked up on srvScripts’ own server from a monthly copy of the DB-IP Lite database, so your address is not sent to any other service. For servers, cron jobs follow the server’s own clock: check it with timedatectl or convert between zones with the time zone converter.
What is my IP at a glance



How to use this tool
- Open the page. The check runs by itself; there is nothing to type.
- Copy the value in the IP address row. That is the public address servers see for this browser, and the one to add to a firewall allow list.
- Press Refresh after you connect or disconnect a VPN, switch from Wi-Fi to mobile data or restart your router, to see the new address.
- To find the address of another device or network, open this page on that device. The tool can only see the connection it receives.
How to read the results
| Row | What it means |
|---|---|
| IP address | The public address your connection arrived from. Behind a home or office router every device shares this address. |
| Version | IPv4 or IPv6, depending on which one your browser used to reach srvScripts. A dual-stack connection has one of each, and other sites may see the other one. |
| Reverse DNS | The PTR hostname your ISP set for the address, often something like a generic name containing the IP, or none. It often reveals the ISP and whether the line is fixed or dynamic. |
| Network | The network name and country from the regional internet registry’s record for the address block. |
| Approximate location | City, region and country from the DB-IP Lite database. City-level at best. |
| Time zone of this IP’s location | The zone for that location with its UTC offset. “, estimated” means the country has several time zones and the one nearest to the IP’s approximate coordinates was picked. |
| Your device time zone | The zone your browser reports from your operating system settings. |
| VPN / proxy check | Green when both zones have the same UTC offset. Amber with the gap in hours when they differ. Information only (“Inconclusive”) when the browser reports UTC. |
| Browser | The User-Agent string your browser sent: browser, version and operating system as the browser describes itself. |
Common problems and how to fix them
You allow-listed your IP but the server still blocks you
The most common cause is IPv6. Your connection to the server may use the IPv6 address while you added the IPv4 one shown on another site, or the reverse. Check both addresses from your own computer (curl is built into Windows 10 and later, Linux and macOS):
curl -4 https://ifconfig.co
curl -6 https://ifconfig.co
Allow both if you have both. In CSF, IPv6 rules only work when IPV6 = "1" is set in /etc/csf/csf.conf.
Your IP changed and you are locked out of SSH or WHM
Dynamic addresses change after a router restart or at the ISP’s schedule. Connect from another network, a phone hotspot or the provider’s web console, then remove the block and add the new address:
csf -g 203.0.113.10 # find which rule matches
csf -dr 203.0.113.10 # remove from csf.deny
csf -tr 203.0.113.10 # remove a temporary ban
whmapi1 flush_cphulk_login_history_for_ips ip=203.0.113.10
For Imunify360 see allow-listing IPs from the Imunify360 CLI. Long term, allow a VPN or office address with a fixed IP rather than a home line.
The IP in your router differs from the one shown here
If the WAN address in the router is in 100.64.0.0/10 (100.64.0.0 to 100.127.255.255) or in a private range such as 10.0.0.0/8, your ISP uses carrier-grade NAT. You share the public address with other customers, so port forwarding to a home server cannot work. Ask the ISP for a public IPv4 address, use IPv6, or publish the service through an outbound tunnel such as Cloudflare Tunnel.
Your server logs show a different IP than this page
If the site sits behind Cloudflare or another proxy, the web server logs the proxy’s address unless it is configured to restore the visitor IP from the forwarded header. Firewalls and login-protection tools then block or allow the wrong address. See Cloudflare in front of cPanel and real visitor IPs.
The location shows the wrong city or country
IP location comes from how the address block is registered and routed, not from your device. Mobile, satellite and some fibre providers route customers through gateways in another city or country, and a block that moved to a new region can still show the old place for a while. This affects geo-blocking and country-based firewall rules; prefer allow-listing exact addresses.
The VPN check is amber but you are not using a VPN
Check the time zone setting of your computer or phone first; a wrong manual setting produces the same result. Corporate networks that send traffic out through a head office in another zone, privacy relays and travelling all trigger it too. It is a hint, not proof.
Public and private IP addresses
Your computer usually has a private address such as 192.168.1.23 that the router gave it. The router translates every outgoing connection to its single public address (NAT), and that public address is what this page shows. Private addresses are reused in millions of networks and never appear on the internet. To see your private address and gateway:
# Windows
ipconfig
# Linux
ip -4 addr show
ip route
# macOS (Wi-Fi)
ipconfig getifaddr en0
To learn more about an address, look it up with the WHOIS lookup, which shows the network holder and abuse contact, or check whether it is listed with the IP blacklist check.
Official documentation: Windows Server documentation, AlmaLinux wiki, Linux man pages.
Related guides: Set up Windows LAPS on Windows Server 2025 and Windows 11 · Configure fine-grained password policies (PSOs) in Active Directory · Mitigating Copy Fail, Dirty Frag and the DirectAdmin 1.711 TLS privilege escalation.
Frequently asked questions
Why is my IP different on another website?
You may have both IPv4 and IPv6; sites reached over IPv6 show a different address. VPNs and corporate proxies also change the address sites see.
Is my IP address private information?
It reveals your ISP and approximate region, not your identity. Nothing you see here is stored.
How do I find my server’s public IP?
From the server run curl -4 ifconfig.co or dig +short myip.opendns.com @resolver1.opendns.com.
Why does Reverse DNS say none?
Your ISP has not set a PTR record for the address. That is common for home and mobile connections and does not affect browsing.
Does pressing Refresh change my IP address?
No. Your ISP assigns the address; Refresh only shows it again. Reconnecting a router or switching networks can give you a new one.
What is the difference between my public and private IP?
The private IP, such as 192.168.1.23, identifies your device inside your own network. The public IP shown here is the address your router uses on the internet and is shared by all devices behind it.
How can I tell if my ISP uses CGNAT?
Compare the WAN address in your router with the address shown here. If they differ and the router shows an address starting with 100.64 to 100.127, you are behind carrier-grade NAT.
Can I whitelist a range instead of one address?
You can, but an ISP range covers many other customers. Allowing a fixed VPN or office IP, or using two-factor authentication, is safer than opening a whole range.