For most of the internet's history, every device was identified by an IPv4 address like 203.0.113.45. Those addresses ran out years ago, and their successor, IPv6, has been steadily rolling out alongside them. Many of your customers' phones and home connections already use IPv6 every day without them noticing. Comparing IPv4 vs IPv6 is less about choosing one and more about making sure your websites, email and firewalls handle both correctly.
Why IPv6 exists
An IPv4 address is 32 bits long, which allows about 4.3 billion addresses. That sounded enormous in the 1980s; it is not enough for a world of phones, laptops, servers and connected devices. The central pool managed by IANA was exhausted in 2011, and the regional registries that hand addresses to internet providers have since run out of fresh IPv4 blocks or impose strict limits. Today, IPv4 addresses are mostly obtained through transfers between organizations, and some cloud providers now charge separately for public IPv4 addresses.
The industry stretched IPv4 with NAT (Network Address Translation), letting many devices share one public address, but that adds complexity. IPv6, specified today in RFC 8200, solves the shortage properly.
How the addresses look
IPv6 addresses are 128 bits, written as eight groups of four hexadecimal digits separated by colons:
2001:0db8:0000:0000:0000:ff00:0042:8329
Two shortening rules make them more manageable:
- Leading zeros in each group can be dropped:
0db8becomesdb8. - One run of consecutive all-zero groups can be replaced by
::, once per address.
So the address above becomes 2001:db8::ff00:42:8329. (The 2001:db8::/32 range is reserved for documentation, so it is safe to use in examples.) In URLs, IPv6 addresses go in square brackets: https://[2001:db8::1]:8443/.
IPv4 vs IPv6: the practical differences
| IPv4 | IPv6 | |
|---|---|---|
| Address length | 32 bits | 128 bits |
| Example | 192.0.2.10 | 2001:db8::10 |
| DNS record | A | AAAA |
| Typical LAN size | /24 (254 hosts) | /64 (vastly more than needed) |
| NAT | Almost universal | Generally not needed |
| Address configuration | DHCP or manual | SLAAC, DHCPv6 or manual |
| Reverse DNS zone | in-addr.arpa | ip6.arpa |
| Loopback | 127.0.0.1 | ::1 |
Devices can configure their own IPv6 addresses automatically using SLAAC (Stateless Address Autoconfiguration), based on information the router announces. Each device commonly has several IPv6 addresses at once, including temporary "privacy" addresses that change over time.
Dual stack: running both
IPv4 and IPv6 are not directly compatible; a device with only IPv4 cannot talk to one with only IPv6 without a translation service. The standard approach is dual stack: servers and networks run both protocols side by side. Modern operating systems prefer IPv6 when both are available, and fall back to IPv4 quickly if IPv6 fails (a technique called "Happy Eyeballs").
For a website, dual stack means the domain has both an A record (IPv4) and an AAAA record (IPv6) pointing to servers that answer on both.
What businesses should check
1. Is your website reachable over IPv6?
Look up your domain's records with a DNS lookup. If there is no AAAA record, visitors on IPv6-only networks reach you through their provider's translation gateways, which usually works but adds a dependency. Many hosting providers, CDNs and cloud load balancers can add IPv6 with little effort.
2. Is an old AAAA record pointing somewhere wrong?
The opposite problem is common and more harmful. After a server migration, someone updates the A record but forgets the AAAA record. Visitors on IPv6 then reach the old server and see outdated content or certificate errors, while IPv4 visitors see everything working. Always update or remove both record types during moves.
3. Are your firewall rules applied to both?
IPv6 rules are often separate from IPv4 rules. A server can have a carefully locked-down IPv4 firewall and a wide-open IPv6 one. Check that database, SSH and admin ports are restricted on both protocols. On Linux, ip6tables or the IPv6 side of nftables rules must be configured separately in many setups. You can test whether specific ports respond with a port checker.
4. Do not block all ICMPv6
In IPv4, some admins block ICMP (the protocol behind ping) entirely. In IPv6 this breaks things, because ICMPv6 carries essential functions such as neighbour discovery and "packet too big" messages. Allow the necessary ICMPv6 types rather than dropping everything.
5. Do logs, allow-lists and applications handle IPv6?
Database columns sized for IPv4 strings, regular expressions that only match dotted decimal addresses, and allow-lists containing only IPv4 ranges are common sources of subtle bugs.
6. Does your mail setup cover IPv6?
If your mail server sends over IPv6, receiving providers check its IPv6 address just as they do IPv4. Make sure the address is included in your SPF record (using an ip6: mechanism if you list addresses directly) and has matching reverse DNS. Otherwise mail sent over IPv6 may be rejected or marked as spam even though IPv4 delivery works fine.
Testing IPv6 from the command line
dig AAAA example.com +short
ping -6 example.com
curl -6 -I https://example.com
On Windows, use nslookup -type=AAAA example.com and ping -6 example.com. If curl -6 fails from a machine that has working IPv6, your site's IPv6 path needs attention.
Key takeaways
- IPv4 is exhausted; IPv6 provides a practically unlimited address space and is already in widespread use.
- Most networks run dual stack, with A and AAAA records side by side.
- Keep A and AAAA records in sync during migrations to avoid split behaviour.
- Apply firewall rules to IPv6 as carefully as IPv4, and allow essential ICMPv6.