What is my IP address?
serverYour address is given by the r-no.fr server, which sees it with every request: that part cannot be checked from your browser. Why, and what it does.
This is the address the internet sees when you connect: your router's, your operator's, or your VPN's, not the one of your computer on your local network.
Transparency
This tool has to ask the server: your browser does not know the address under which the internet sees it.
- Why this tool is tagged [server]
- The answer comes from a rule of the server, shown in full below: it sends back the address the request came from. Nothing you type is sent, and the server learns nothing it does not already receive with every page. But nothing lets you check from here that this rule is what actually answers: for that part, you have to trust r-no.fr.
- The request
- The page asks
/ip/my-ip/address, on this same site. The server answers with the address the request came from, as plain text, and nothing else. This page's Content Security Policy allows only one other destination, as on every page of the site:https://stats.r-no.fr, the audience measurement (connect-src 'self' https://stats.r-no.fr, see below). No form submission. - Audience measurement
- Like every page of the site, this one counts its visit with Umami, installed on R-no’s own server (
stats.r-no.fr). It receives the address of the page, without parameters or anchor, the site you came from (its domain only), your browser, system, language and screen size, and the country, region and city deduced from your IP address, which is not kept. It never receives what you type, nor the result of the tool. No cookie, nothing stored in your browser; if your browser asks not to be tracked (Do Not Track), nothing is measured. The data is erased after 25 months.- /commun/mesure.js: the filter applied before each sending, written for R-no Toolbox. 1.4 kB
SHA-256225eec74fd12623d82fc05ee7d222be629ce454d081c129e8d1e249ed37ee716 - https://stats.r-no.fr/m.js: Umami’s tracker, open source (MIT), served by the measurement server. Its fingerprint is not shown here: it changes with each version of Umami, and you cannot check from your browser that it is the published code. For that part, you have to trust R-no.
- /commun/mesure.js: the filter applied before each sending, written for R-no Toolbox. 1.4 kB
- Only from this site
- The server answers only requests that your browser marks as coming from a page of r-no.fr itself (the
Sec-Fetch-Site: same-originheader, which a page cannot choose). Other websites,curland scripts are refused, so that the address is not reused by outside tools. It is a brake, not a lock: a script can add that header itself. - What the server keeps
- Every website receives your IP address with each request: that is how the answer finds its way back. Like every request to this site, this one is recorded in the server's access logs: your IP address, the date and time, the address requested and your browser's name. These logs are used to run and secure the server, and are never shared. For now they have no automatic retention limit; a log rotation is being set up. The answer itself is marked as not cacheable.
- Where the address comes from
- The reverse proxy in front of the site records the address of the connection it receives, and passes it on in a header that it rewrites itself: a visitor cannot make the page display another address by sending that header. Every deployment checks this too.
- Code that runs here
-
In your browser, checkable
- app.js: asks for the address and displays it. Written for R-no Toolbox, not minified, no third-party library. 3.4 kB
SHA-2568cc549768e63569ff7192a4578241d4aa6df1ac54cad1832638bd1b8ca15c10e - textes.js: the French messages of the tool, shown by its script (the rest of the French page is written into its HTML when the site is built). It only defines texts, with no logic. 6.2 kB
SHA-25669c366f21ef4b77e7a7668dfd7cd89434b0095004f359bced0443a52cb937989 - /commun/langue.js: the language helper, the same on every page of the site. It reads the language of the page and gives the tool its messages in that language. It stores nothing. 1.6 kB
SHA-25680f76f69773ef628d36d09bf8387cfedebda4529210d7120649b6f5603310631
On the server, to be trusted
/ip/my-ip/addressis not a program, but a rule of the nginx web server, in the site's configuration. Here it is, without its comments:map $http_x_real_ip $ip_visiteur { "~^[0-9A-Fa-f:.]{2,45}$" $http_x_real_ip; default $remote_addr; } location = /ip/my-ip/address { default_type text/plain; add_header Cache-Control "no-store" always; add_header X-Content-Type-Options "nosniff" always; if ($appel_du_site = 0) { return 403 "Only r-no.fr pages can ask for this address: …"; } return 200 "$ip_visiteur\n"; }X-Real-Ipis written by the reverse proxy in front of the site (see below);$appel_du_siteis 1 when the browser says the request comes from a page of r-no.fr. - app.js: asks for the address and displays it. Written for R-no Toolbox, not minified, no third-party library. 3.4 kB
- What is stored
- No cookie, nothing in the address. Your language is given by the address itself (
/en/or/fr/): nothing is stored to remember it. - Check it yourself
- Download the script and compare its fingerprint with the one above:
curl -s https://r-no.fr/ip/my-ip/app.js | shasum -a 256 - Limits
- This site is reachable over IPv4 only for now: you will see your IPv4 address, even if your connection also has IPv6. A browser too old to send the
Sec-Fetch-Siteheader (Safari before 16.4, for example) is refused like an outside tool. No location or operator is shown: that would need a database. For the reverse DNS name and the registry record of your address, see ip/reverse and ip/whois.