Skip to content

10.0.0.0/8: the largest private IPv4 range

Runs in your browser — nothing you paste leaves this page. How we prove that

Subnet Calculator playground

Examples

IPv4 or IPv6, with or without a prefix — 10.0.0.0/8, 2001:db8::/48, or a dotted netmask like 192.168.1.0 255.255.255.0. A bare address means one host (/32 or /128).

Results update as you type — press Enter to run now.

fig. 10 — subnet-calculator · networking /8 — 16777214 usable hosts
Result
IPv410.0.0.0/8
Usable hosts16 777 214
Usable range10.0.0.1 – 10.255.255.254
Total addresses16 777 216

Addressing

Network address
10.0.0.0
Broadcast address
10.255.255.255
Usable host range
10.0.0.1 – 10.255.255.254

Masks

Netmask
255.0.0.0
Wildcard maskInverse of the netmask — the match form Cisco ACLs and OSPF expect.
0.255.255.255
Netmask (binary)The mask bit by bit — the 1s are the network part.
11111111.00000000.00000000.00000000

Details

Address type
Private (RFC 1918)
Network (integer)The network address as a single 32-bit number, as scripts and databases store it.
167 772 160

10.0.0.0/8 is the largest of the three RFC 1918 private ranges: 16,777,216 addresses from 10.0.0.0 to 10.255.255.255, mask 255.0.0.0. Enterprises and cloud platforms build their internal address plans inside it.

The block

RFC 1918 sets aside 10.0.0.0/8, 172.16.0.0/12 and 192.168.0.0/16 for private networks; routers on the public internet do not carry them, so reaching the internet requires NAT. The calculator classifies this block as "Private (RFC 1918)".

With mask 255.0.0.0 and wildcard 0.255.255.255, only the first octet is fixed. That leaves 2^24 = 16,777,216 addresses, 16,777,214 if you treated it as one flat network, which nobody does.

Carving it up

The size invites a hierarchy: a /16 per region or environment, a /20 or /24 per subnet. 10.0.0.0/8 contains 256 /16s, so a plan like 10.region.tier.x stays readable for years.

Popular defaults live here too, which is a reason to avoid them in your own plan. Kubernetes clusters built with kubeadm use 10.96.0.0/12 for Services by default, Flannel's default pod network is 10.244.0.0/16, and many tutorials and VPC wizards suggest 10.0.0.0/16.

Overlap is the real risk

Everyone picks 10.0.0.0/16 first. When two companies merge, two VPCs need peering, or a remote worker's VPN lands on a corporate subnet that matches their ISP's equipment, overlapping 10.x ranges force NAT or renumbering. Choose a less obvious /16, such as 10.142.0.0/16, and record every allocation.

Do not confuse it with 100.64.0.0/10, the RFC 6598 carrier-grade NAT range that some ISPs and overlay VPNs use; it is not RFC 1918 space and should not be in your private address plan.

Checking an allocation

Before taking a new /16 or /20 from the block, check it against every VPC, on-premises network, VPN pool and Kubernetes cluster you run, plus the networks of partners you peer with. Overlap checks are cheap in a spreadsheet and expensive after a peering request has been approved.

Paste candidate ranges into the calculator to confirm boundaries: a typo such as 10.20.8.0/20 instead of 10.20.16.0/20 shifts a whole subnet onto its neighbour, and the calculator shows it as a host inside 10.20.0.0/20.

FAQ

Questions, answered.

Tap a question to expand the answer.

16,777,216, from 10.0.0.0 to 10.255.255.255.

No. It is RFC 1918 private space; traffic to the internet must be translated with NAT.

More free, private DevOps tools.

The Subnet Calculator is one tool in OpsCanopy — a growing canopy of browser-based validators, converters and testers that never touch a server.

New to Networking?  Read the Networking guide →

42 free tools, every one offline-capable — opscanopy.com works with no signup and nothing uploaded.

More networking: the IP Address Converter, the CIDR / Subnet Checker and the Subnet Splitter, or browse the full tools directory.

Provided as-is for convenience; always confirm critical network changes against your own authority. OpsCanopy is free and open.