๐ŸŒ

IP Address (IPv4 & IPv6) Regular Expression Studio

Generate strict IPv4 and IPv6 validation regular expressions with our Network Address Regex Studio! Build precise octet boundary matchers (restricting values strictly to 0โ€“255 without allowing invalid numbers like 256), Classless Inter-Domain Routing (CIDR) subnet masks (`/24`, `/64`), and compressed IPv6 hextets.

โœจ NLP PROMPT ENGINEType your network validation parameters in plain English to formulate custom regex patterns instantly
๐Ÿ”ฎ
Or try prompts:

Select Preset Rules

โš™๏ธ IP Configurator

Core IP Protocols

Validation Boundaries & Extensions

Generated IP Regex Pattern
^(?:(?:25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\.){3}(?:25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)$
Export Code Snippet:

๐Ÿงช Live Interactive Validator

192.168.1.1
PASSED: IP satisfies formulated constraints.

๐Ÿ“Š Bulk Testing Lab

192.168.1.1 โœ“ PASS
8.8.8.8 โœ“ PASS
127.0.0.1:8080 โœ— FAIL
2001:0db8:85a3:0000:0000:8a2e:0370:7334 โœ— FAIL
invalid-ip โœ— FAIL

๐Ÿ“– Pattern Tokens Explanation

Here is a step-by-step breakdown of how regular expression engines evaluate your formulated IP validation rules:

Start Anchor (^)Asserts that the regex engine must start validation at the absolute beginning of the string value.
^
IPV4 Core SegmentValidates IPv4 segments conforming to numeric octets standard (0 to 255).
(?:(?:25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\.){3}(?:25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)
End Anchor ($)Asserts that the regex engine must conclude validation at the absolute end of the input string, disallowing trailing junk characters.
$

๐Ÿ“Š Reference Patterns

Addressing TypeMatch ExampleRegex Snippet
IPv4 (Strict / RFC)192.168.1.1^(?:(?:25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\.){3}(?:25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)$
IPv4 (Relaxed)999.999.999.999^(?:\d{1,3}\.){3}\d{1,3}$
IPv6 Complete Format2001:0db8:85a3:0000:0000:8a2e:0370:7334^([0-9a-fA-F]{1,4}:){7,7}[0-9a-fA-F]{1,4}$
IPv6 (Compressed Shortened)2001:db8::1^(([0-9a-fA-F]{1,4}:){1,7}:|::)$
IPv4 Subnet / CIDR Mask10.0.0.0/24^(?:(?:25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\.){3}(?:25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)(?:\/(?:3[0-2]|[12]?[0-9]))$
IPv4 with Socket Port127.0.0.1:8080^(?:(?:25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\.){3}(?:25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)(?::(?:[0-9]{1,4}|[1-5][0-9]{4}|6[0-4][0-9]{3}|65[0-4][0-9]{2}|655[0-2][0-9]|6553[0-5]))$
IPv6 Subnet / CIDR Mask2001:db8::/32^([0-9a-fA-F]{1,4}:){7,7}[0-9a-fA-F]{1,4}(?:\/(?:12[0-8]|1[0-1][0-9]|[1-9]?[0-9]))$
Localhost Loopback IPv4127.0.0.1^127\.(?:25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\.(?:25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\.(?:25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)$
Private Network Class A10.50.8.254^10\.(?:25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\.(?:25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\.(?:25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)$
Private Network Class B172.16.254.1^172\.(?:1[6-9]|2[0-9]|3[0-1])\.(?:25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\.(?:25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)$
Private Network Class C192.168.1.1^192\.168\.(?:25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\.(?:25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)$
Dual Stack Universal IP8.8.8.8^(?:(?:(?:25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\.){3}(?:25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)|([0-9a-fA-F]{1,4}:){7,7}[0-9a-fA-F]{1,4})$

๐Ÿงฌ Entropy Analysis

Character Pool SegmentDimension SizeEntropy Bits/Char
Digits (0-9)103.32 bits
Hex Characters (a-f)62.58 bits
Separator Dot (.)11.00 bits
Separator Colon (:)11.00 bits
CIDR Slash separator (/)11.00 bits
Hex Case Boundaries (A-F)62.58 bits
Loopback Signifier (127)31.58 bits
CIDR Subnet Digits103.32 bits
๐Ÿ”ฌ What is Entropy Analysis?

Entropy Analysis in regular expressions evaluates the information density and structural complexity of matched patterns based on Shannon's Entropy formula ($H = -\\sum P_i \\log_2 P_i$). Here is how it works:

  • Information Density: Measures the unpredictability and strictness of character classes. A pattern with higher entropy restricts inputs more precisely, leaving fewer opportunities for structural anomalies.
  • Character Pool Segmenting: Breaks down matched values into operational blocks (digits, spaces, hyphens, prefixes, parentheses) and calculates their corresponding bit pools.
  • ReDoS Vulnerability Protection: Helps developers analyze pattern backtracking depth. Low-entropy, overly loose patterns (like overlapping wildcards) can trigger catastrophic backtracking, causing servers to hang under ReDoS exploits. High-entropy, precise patterns mitigate this risk.

Overview & Capabilities

Generate strict IPv4 and IPv6 validation regular expressions with our Network Address Regex Studio! Build precise octet boundary matchers (restricting values strictly to 0โ€“255 without allowing invalid numbers like 256), Classless Inter-Domain Routing (CIDR) subnet masks (/24, /64), and compressed IPv6 hextets.

Tutorial

How to Use

01
Select your target protocol: IPv4 Dotted-Decimal, IPv6 Hexadecimal, or Dual Unified Matcher.
02
Optionally enable CIDR subnet mask prefixes (/0 to /32 or /128) or port numbers (:8080).
03
Inspect the strict octet-bounded regular expression generated in the console.
04
Test IP addresses in the network sandbox to verify valid IPs vs out-of-range octets.
05
Copy expression patterns for Nginx server rules, firewall configs, or backend validators.
Capabilities

Key Features

Strict 0-255 Octet Range Logic: Uses (?:25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?) to prevent illegal numbers > 255.
Compressed IPv6 Hextet Support: Accurately validates zero-compressed double-colon addresses (::1, 2001:db8::1).
CIDR Subnetwork Mask Support: Validates network prefix routing notation (192.168.1.0/24).
Port Suffix Matchers: Captures optional port extensions (127.0.0.1:3000).
Firewall Rule Export: Generates ready-to-use patterns for Apache .htaccess and Nginx server blocks.
Applications

Common Use Cases

Firewall Settings: Match and filter traffic sources based on specific subnet boundaries.
Access Controls: Authorize API callers matching designated IPv4 or IPv6 lists.
Log Parsers: Extract network host values from large system and access logs.
Subnet Configuration: Verify router CIDR ranges during setup and updates.
Security Auditing: Screen client addresses to protect endpoints against SSRF exploits.
Guidance

Tips & Best Practices

๐Ÿ’ก
๐ŸŒ For public APIs, dual-stack Universal IP patterns ensure complete compatibility across regions.
๐Ÿ’ก
๐Ÿ”’ Enabling "Strict Ranges" blocks leading zeroes, preventing octal parsing security exploits.
๐Ÿ’ก
๐Ÿš€ CIDR network subnet checks allow matching multiple machines (e.g. /24) inside local routers.
๐Ÿ’ก
๐Ÿ’ก Validating socket ports is essential for security proxies and gateways mapping backend services.
๐Ÿ’ก
๐Ÿงช Use the "Bulk Validator" to instantly verify routing tables or private network ranges.
Answers

Frequently Asked Questions

Q Why is `\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}` flawed for IPv4 validation?

Because `\d{1,3}` accepts any 3-digit number (including invalid values like 300 or 999). A strict IPv4 regex must test numerical ranges 0โ€“255 explicitly across all four octets.

Q What is the complete pattern for strict IPv4 validation?

`^(?:(?:25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\.){3}(?:25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)$`.

Q How are compressed IPv6 addresses validated in regular expressions?

IPv6 regexes use alternation branches matching 8 full 16-bit hextets (`[0-9a-fA-F]{1,4}`) or variations containing `::` indicating omitted consecutive zero fields.