Skip to content
IP-013 IP Addresses & Networks

What is the difference between a static and dynamic IP address?


title: "What is the difference between a static and dynamic IP address?" card_id: "IP-013" status: "complete" source_document: "https://docs.google.com/document/d/1oSUmRvn7oMUO7cta-iDaqmPccin1gXgd7ow3-TP0Cpw/edit?usp=drivesdk"


What is the difference between a static and dynamic IP address?

A public IP address may be static or dynamic.

A static IP address is intended to remain allocated to the same customer, connection or service for an extended period.

Static addresses are often used by businesses, organisations, servers and other services that need a predictable internet address.

But static doesn’t mean permanent.

The provider can still change the address.

The customer can change provider.

The service can end.

And the address may eventually be allocated somewhere else.

A dynamic IP address is allocated from a pool of addresses controlled by the provider.

The address used by a customer may change when the connection is re-established, when an allocation expires or when the provider changes its network arrangements.

That doesn’t mean dynamic addresses change constantly.

Some remain with the same connection for days, weeks or even months.

Others may change much more frequently.

You can’t normally tell whether an address is static or dynamic just by looking at it.

A basic infrastructure lookup may show which provider controls the address range.

It won’t normally show which customer was using the address or whether that particular allocation was static or dynamic.

That information usually has to come from the provider or whichever organisation allocated the address.

The distinction matters because dynamic IP allocation is time-dependent.

The relevant question isn’t:

“Who uses this IP address?”

It’s:

“Which connection or customer was using this IP address at the recorded time?”

The answer today may be different from the answer at the time of the event.

The same public IP address could be allocated to one subscriber on Monday and another subscriber later.

Equally, one subscriber may appear behind several different public IP addresses over time.

Finding the same dynamic IP address in two records doesn’t therefore prove that the same subscriber—or the same person—was involved in both events.

You need the relevant allocation records for each event.

A static IP address may provide a more consistent link to a customer, organisation or service.

But it still doesn’t identify the person responsible for the activity.

A business may have hundreds of users behind one static public address.

A static address might identify a server, firewall, VPN gateway or other infrastructure rather than an individual device.

And even a residential static address identifies a connection or service before it identifies whoever was using it.

So, static or dynamic changes the allocation question.

It doesn’t remove the need for attribution.

For a dynamic IP address, the essential lookup information is the exact address together with the precise date, time and time zone of the event.

You can’t simply ask who uses the address now.

You need to ask which customer connection was allocated—or was using—that address at the recorded time.

There is one further complication.

A provider may share the same public IP address between several customers simultaneously using Carrier-Grade NAT.

In that situation, the provider may also need a source port or other session information to identify the relevant customer connection.

We explain Carrier-Grade NAT and source ports separately.

For now, remember:

Dynamic addresses make accurate timing essential.

Static addresses may provide continuity.

Neither one identifies the person responsible without further evidence.


Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.