CGNAT (carrier-grade network address translation) is a technique internet providers and mobile operators use to share one public IPv4 address among many customers at the same time.
It exists because IPv4 addresses ran out. Instead of giving each subscriber a public address, the carrier translates many private connections onto a pool of shared public ones. Mobile networks use it widely, and so do some home broadband providers. Inside the carrier, customers get addresses from 100.64.0.0/10, a range set aside for exactly this.
Why does CGNAT matter for fraud prevention?
Because one IP address no longer means one customer.
- Blocking an address can block many innocent people who share it with one abuser.
- Per-IP rate limits misfire on busy shared addresses.
- Two accounts from one address are not necessarily the same person.
How should you handle shared addresses?
Decide on evidence against the address rather than on a raw score, prefer a step-up check (a one-time code, email confirmation) over a block for mobile addresses, and check the person as well as the network: the email, the phone number and the browser.
How Hextner uses it
VerifIP's verdict stays allow for classification alone (VPN, proxy, Tor, hosting); it needs accusing evidence before it says challenge. connection_type marks mobile networks as Mobile. If your logs show a client address in 100.64.0.0/10, you are reading an internal address instead of the public one: VerifIP answers it as a bogon (score 100, block), so fix how your server reads proxy headers. The India guide works through shared mobile addresses in detail.
Related reading
Browse every definition in the glossary.