Subnet calculator

IP + prefix/mask → network, broadcast, usable range and subnet splitting, with an IPv6 inspector; local math.

The same arithmetic shows up in every network config session: which subnet is this IP in, what prefix is 255.255.255.192, where do usable hosts start and end, how many subnets does one more mask bit buy. Mental math slips, and one wrong number costs an evening of debugging. Subnet math is one sentence: IP AND mask = network, inverted mask = host bits.

This tool accepts either a prefix (/26) or a dotted mask and lays out the full result from mask to binary in the order you copy it into a config; masks are validated for contiguity — illegal ones like 255.0.255.0 error out instead of producing wrong answers. Splitting mode lists the child subnets for a new prefix. /31 and /32 follow RFC 3021 and host-route semantics rather than the usual minus-two rule.

Mask, wildcard and CIDR are one thing in three notations

255.255.255.192, 0.0.0.63 and /26 describe the same boundary: 26 network bits, 6 host bits. Router configs favor wildcards (ACL rules), Linux and docs favor prefixes, and manual conversion goes wrong on exactly those mental shortcuts. The tool's value is showing all three notations aligned at once.

Why IPv6 is inspection-only

IPv6 has no mask culture: practice fixes the prefix at /64 and VLSM-style splitting essentially vanished, so there is little to compute and a lot to inspect. This tool shows the fully expanded form (8 groups of 4 hex digits), the RFC 5952 canonical compression (longest zero run becomes ::), and classifies common types: loopback, link-local, unique-local, multicast and IPv4-mapped.

Frequently asked questions

Why does a /26 only have 62 usable hosts?
Of the 64 addresses, all-zero host bits is the network itself and all-ones is broadcast — neither can be assigned, leaving 62. The exceptions: /31 point-to-point links (RFC 3021) can use both addresses, and /32 is a single-host route with no network/broadcast concept.
Why was my mask rejected as invalid?
Subnet masks must have contiguous 1s from the top: 255.0.255.0 and 255.255.0.255 cannot define a "network bits first" boundary and no mainstream device accepts them. The tool errors out. If what you actually want is a non-contiguous match (as in ACLs), that is wildcard-mask territory — it will be correctly rejected in the mask field.
Is the computation local?
Yes — pure unsigned integer bit math in the browser, no network requests.

Related tools