Your IP address:
Provider:
...

IPv6 privacy addresses: why they change

A temporary IPv6 address is an additional device address used for outgoing connections. It changes over time so that one fixed device identifier is harder to correlate across visits. The mechanism does not make a person anonymous or necessarily change the address prefix assigned to their network.

How does a temporary address appear?

A router advertises a network prefix and the device forms an address within it. RFC 8981 describes temporary interface identifiers and address lifetimes. One interface can simultaneously hold a stable address, a temporary address, a link-local fe80::/10 address and other addresses. This is expected behaviour, not evidence of an intrusion or a broken connection.

When an application starts an outgoing connection, the operating system selects a suitable source address according to its policy. A browser may use a temporary address while a service hosted on the same device uses a stable address. Rotation of an interface identifier is separate from a provider changing the delegated network prefix. Compare both parts before diagnosing the change.

What privacy benefit does rotation offer?

Replacing the identifier shortens the period in which one IPv6 address can trivially link a device’s activity. A site may still correlate visits through cookies, logins, browser characteristics or the network prefix. The provider can generally still observe its subscriber connection. Temporary addresses do not replace browser privacy controls, transport encryption or sensible access rules.

Do not infer a specific person from an address change alone. Several people may share a device, and one person may use several devices. Corporate networks can also impose different address policies from a home network. Decide whether temporary addressing suits a particular deployment by considering service reliability and logging requirements, rather than treating it as a promise of complete anonymity.

How do you troubleshoot a changing address?

Inspect the interface addresses and their lifetimes in the operating system. Compare the IPv6 address reported by the IP information tool with any published AAAA record. If an inbound service or DNS record targets a temporary address, it may fail after that address expires. Use an appropriate stable address for the server and keep inbound firewall rules narrow.

If the network prefix changes as well, coordinate DNS updates with the router and provider settings. Test IPv4 and IPv6 independently because the client may use a different address family for each request. Record the time, complete address and exact error while keeping account credentials out of public troubleshooting logs. A successful outgoing test alone does not prove that inbound access works.