Neatbo.

IP in CIDR checker

Check a list of IP addresses against one IPv4 or IPv6 CIDR and export matching values.

Browser-local processingInputIP list + CIDROutputJSON / TXTUp to 10 MiB per file · File limit: 1
  1. 1Add input
  2. 2Adjust settings
  3. 3Get your result

Tool input and files are processed in this browser without being uploaded.

Your input

Inputs are kept temporarily in this tab when switching tools. Refreshing or closing clears them; large results may need to be regenerated.

⌘ / Ctrl + Enter to run

Check CIDR membership

Choose one IPv4 or IPv6 CIDR, then enter one address per line. Blank lines are ignored; up to 10,000 addresses. Host bits in the CIDR are normalized.

Enter a CIDR block, such as 192.168.1.0/24.

This checks mathematical containment only. It does not verify firewall rules, routing, address allocation or reachability.

Address input source
0 characters · 0 bytes
Preparing the tool…

Before you start

Paste one address per line or choose a UTF-8 text file, then compare each address with one CIDR. The result identifies inside, outside, malformed and wrong-version rows, retaining source line numbers. Host bits in the CIDR are normalized before comparison.

How to use this tool

  1. Enter the CIDR to check, such as 192.168.1.0/24 or 2001:db8::/32.
  2. Paste one IP address per line or choose a UTF-8 .txt file, then review the inside/outside preview.
  3. Select “Check CIDR membership”. Copy or download matching addresses, download outside addresses, or inspect the complete JSON report.

Supported inputs and limits

Up to 10,000 nonblank address lines and one IPv4 or IPv6 CIDR. Blank lines are ignored; mixed IP versions are reported as mismatches.

Files and text stay in your browser. Containment does not prove firewall behavior, route configuration, address ownership or reachability.

Worked example

Example input

192.168.1.20
192.168.2.1
bad
Example options
{"cidr":"192.168.1.0/24"}

Example output

{
  "networkCidr": "192.168.1.0/24",
  "networkStart": "192.168.1.0",
  "networkEnd": "192.168.1.255",
  "version": 4,
  "normalized": false,
  "total": 3,
  "inside": 1,
  "outside": 1,
  "invalid": 1,
  "rows": [
    {
      "line": 1,
      "address": "192.168.1.20",
      "version": 4,
      "status": "inside",
      "reason": null
    },
    {
      "line": 2,
      "address": "192.168.2.1",
      "version": 4,
      "status": "outside",
      "reason": null
    },
    {
      "line": 3,
      "address": "bad",
      "version": null,
      "status": "invalid",
      "reason": "format"
    }
  ]
}

When something does not work

If the CIDR is rejected, check the address family and prefix. If a row is invalid, use its source line number to correct the original list.

Frequently asked questions

Does 192.168.1.20/24 mean the same network as 192.168.1.0/24?

Yes. The tool clears host bits in the CIDR input and shows the normalized network before comparing addresses.

What happens if the list contains IPv6 but the CIDR is IPv4?

That line is labeled as an IP-version mismatch, not silently counted as outside the range. Invalid addresses keep their source line numbers.

Does an inside result mean a firewall allows this address?

No. This checks numeric containment only. It cannot inspect actual firewall rules, routing, allocation or connectivity.

Documentation & further reading

Related tools