πŸ”’

IP Address Anonymizer

Mask host bits while reviewing what remains in your log

IP Address Anonymization
πŸ”’ 100% client-side β€” your data never leaves this page
Maintained by Evanβ€’Updated: September 30, 2026
Logs or text

Host-bit masking is partial redaction, not guaranteed anonymization. It preserves prefixes, ports and other text; unsupported or malformed tokens remain unchanged. Zones, encoded addresses and other identifiers need manual review. /32 and /128 retain all address bits. Limit: 1 MiB.

Result

Run the tool or try an example to see results.

About this tool

Paste up to 1 MiB of text to zero the host bits of recognized IPv4 and IPv6 addresses. Retain 0–32 bits for IPv4 and 0–128 for IPv6; the defaults are /24 and /64. The same address maps to the same network under the same settings, which preserves broad grouping but may merge different hosts. Bracketed IPv6 and supported numeric ports keep their surrounding notation. The report distinguishes recognized occurrences from addresses whose bits actually changed, and counts address-like tokens left unchanged. Full-width settings /32 and /128 keep every address bit, though textual spelling can still normalize. This is partial redaction, not guaranteed anonymization: network prefixes, usernames, tokens, hostnames, encoded addresses and unsupported zone forms can remain identifying. Conservative token boundaries also leave some unfamiliar log forms untouched. Inspect the entire output before sharing. Processing and copying happen in this page; there is no file-upload or download feature, and the original log is not stored.

Failure Clinic (Common Pitfalls)

Zero changed addresses does not mean there was nothing sensitive

Cause: Addresses may already lie on a network boundary, all bits may be retained, or the source format may be unsupported. Usernames and secrets are not IP tokens.

Fix: Read the settings and diagnostic counts together, then inspect the complete output. Choose a separate redaction method for identifiers that this tool does not process.

Scenario Recipes

01

Prepare a diagnostic excerpt for manual review

Goal: Reduce exposed host bits while retaining enough context to inspect the output.

  1. Paste the excerpt and choose retained IPv4 and IPv6 prefix lengths.
  2. Run the masker and compare recognized, numerically changed and skipped-token counts.
  3. Read the whole result for unsupported addresses and other identifiers before copying. Reduce retained bits if the network itself is sensitive.

Result: A partially redacted excerpt that still requires a sharing review.

Production Snippets

Default prefixes and a deliberately unchanged zone

text

client=203.0.113.42:443 β†’ client=203.0.113.0:443
backend=[2001:db8:abcd::42]:80 β†’ backend=[2001:db8:abcd::]:80
zone=[fe80::42%eth0] β†’ unchanged; review manually
user=alice β†’ unchanged; not an IP address

Frequently Asked Questions

What do /0, /32 and /128 do?

A zero retained prefix replaces all address bits with zero. IPv4 /32 and IPv6 /128 retain every bit, so they do not hide the address. Intermediate prefixes preserve that many high bits and zero the remaining host bits.

Can the result identify the original host?

Potentially. A retained network, timestamp, username or other context can still identify someone; different masked rows can also correlate. Do not treat prefix masking as a guarantee of irreversible anonymity.

Which values stay unchanged?

Unsupported zone-bearing addresses, malformed candidates, encoded values and non-IP identifiers remain in the output. The skipped-token count is a diagnostic hint, not a count of every possible sensitive identifier.

Why is the recognized count larger than the changed count?

An address already on the selected network boundary has zero host bits, so it is recognized without any bit change. Full-width prefixes behave similarly. Text normalization can change spelling even when the numeric bits do not change.

Keep browsing