Definitions covering IP, DNS, routing, VPNs, privacy, phone lookups, and diagnostics.
Search a term, filter by category, then follow its linked tool or deeper guide. Each definition is short enough to scan and detailed enough to keep you moving.

Use this glossary while reading our guides and tool explainers. Search terms, scan by category, and jump directly to any entry with#term anchors when you want a stable reference.
Definitions covering IP, DNS, routing, VPNs, privacy, phone lookups, and diagnostics.
Filter terms by IP addressing, DNS, VPN access, infrastructure, security, hardware, and more.
Most entries connect directly to deeper explainers, live lookups, or related glossary terms.
A security method that requires two forms of verification (typically password + phone code) before granting access to an account.
A DNS record that maps a hostname to an IPv4 address.
A DNS record that maps a hostname to an IPv6 address.
The device providing the Wi-Fi radio for a network. A home router packages one together with a switch and a router in a single box.
A symmetric cipher with a 256-bit key used by VPNs, disk encryption, and TLS. It has no practical brute-force attack, so implementation is what matters.
A routing method where multiple servers share the same IP and the network routes users to the nearest one.
Address Resolution Protocol maps an IP address to a device's MAC address on a local network.
A number that identifies a network/operator on the internet (an autonomous system). ASNs help route traffic across networks (BGP).
The maximum data transfer rate of a network connection, measured in bits per second (bps). Higher bandwidth means more data can flow at once.
The routing protocol used between networks on the internet to exchange routes and reachability information.
Announcing IP ranges you do not own so traffic to them diverts through your network. It can be an attack or a mistyped configuration.
A bit is one binary digit and a byte is eight. Speeds are quoted in megabits and file sizes in megabytes, so a 100 Mbps line downloads about 12.5 MB per second.
A network of compromised devices under remote control, usually rented out to send spam or run DDoS attacks.
The last address in an IPv4 subnet, used to send one packet to every host on that segment. IPv6 dropped broadcast in favour of multicast.
Identifying a visitor from the combination of screen size, fonts, timezone, and hardware their browser exposes. It needs no cookies and survives hiding your IP.
A record listing which certificate authorities may issue certificates for a domain. It limits the damage if another authority is tricked into issuing one.
The name and number information shown for an incoming call. Caller ID can be helpful, but it can also be spoofed by scam callers and robocall systems.
Faking the number shown on an incoming call, often to imitate a local area code or a real institution. It is why caller ID alone should never be trusted.
A network of edge servers caching a site close to its visitors. It cuts latency and hides the origin server behind provider IP ranges.
A large-scale NAT system used by ISPs that shares public IPv4 addresses across many customers using the 100.64.0.0/10 range (RFC 6598). It can block inbound connections and port forwarding.
A notation for IP ranges like 203.0.113.0/24. It indicates how many bits are fixed in a network prefix, defining the size of a subnet.
A DNS record that maps one hostname to another hostname (an alias).
A web control panel for managing hosting accounts: domains, email, databases, and files. Its licence cost is part of why some hosts are cheaper than others.
Sites reachable only through anonymity networks such as Tor. It hosts criminal marketplaces alongside legitimate tools for journalists and whistleblowers.
A facility that houses servers, storage, networking equipment, and power/cooling systems used to run websites, cloud platforms, and internet services.
An IP belonging to a hosting or cloud provider rather than a consumer ISP. Streaming services and anti-fraud systems flag these because most VPN exits use them.
An attack that overwhelms a target network or service with traffic from many sources. Gamers and streamers sometimes use VPNs and router hardening to reduce DDoS exposure risks.
A VPN address assigned to you alone rather than shared with other subscribers. It cuts CAPTCHAs and blocklisting but shrinks the crowd you hide in.
A complete physical machine rented to one customer. It removes shared-resource contention entirely and is priced accordingly.
The local router address your device uses to reach other networks (including the internet). It is commonly something like 192.168.1.1 or 10.0.0.1 on home networks.
Dynamic Host Configuration Protocol automatically assigns IP addresses to devices on a network.
A signature added to outgoing mail and verified against a public key published in DNS. It proves the message was not altered and came from the claimed domain.
A DNS policy telling receiving servers what to do when SPF and DKIM fail, and where to send reports. It is what turns those two checks into real enforcement.
The system that maps domain names (example.com) to IP addresses so browsers can connect to websites.
Stored copies of recent DNS answers held by your browser, operating system, and resolver. Caching makes lookups fast but delays your view of a record that just changed.
An attack that redirects lookups to a resolver the attacker controls, sending you to a fake site while the address bar still looks correct.
A privacy issue where DNS queries bypass the VPN tunnel and go to ISP/public resolvers, revealing provider or location patterns even when your visible IP changes.
The delay between changing a DNS record and every resolver seeing the new value. It is governed by the old record TTL, not by any global sync process.
The server that performs lookups on your behalf, querying root, TLD, and authoritative servers until it has an answer. Usually your ISP unless you change it.
A DNS-based list used by email/security systems to flag IPs associated with spam or abuse. DNSBL checks help determine whether an IP may be blocked or filtered by receiving systems.
DNS Security Extensions add cryptographic signatures to DNS records to prevent tampering and spoofing.
A protocol that encrypts DNS queries inside HTTPS traffic, preventing ISPs and networks from seeing which domains you resolve. Supported by most modern browsers.
The readable name people type, such as example.com, which DNS translates into an IP address. Domains are rented through a registrar rather than owned outright.
A protocol that encrypts DNS queries using TLS on port 853. Similar goal to DoH but operates as a dedicated encrypted DNS channel rather than piggybacking on HTTPS.
A network setup where traffic is translated by two routers/NAT devices (for example an ISP modem/router plus your own router). It can complicate gaming, port forwarding, and inbound connections.
Publishing private details about someone in order to invite harassment. An IP address alone rarely gets there, but combined with other leaks it narrows the search.
A public IP address that can change over time, typically assigned by your ISP via DHCP.
The process of converting readable data into unreadable ciphertext using a key, so only authorized parties can decode it. Essential for VPNs, HTTPS, and secure messaging.
Encryption where only the sender and recipient hold the keys, so the service carrying the message cannot read it.
A wired networking standard (IEEE 802.3) using cables and switches for fast, reliable local network connections. Common speeds range from 100 Mbps to 10 Gbps.
A connection carrying data as light through glass strands instead of electricity through copper. It delivers higher speeds over longer distances with less interference.
A security system that monitors and filters network traffic based on defined rules, blocking unauthorized connections while allowing legitimate ones.
Low-level software running on hardware devices such as routers. Keeping firmware updated helps fix bugs, improve stability, and patch security issues.
Groups of countries with intelligence-sharing agreements. Privacy VPNs often advertise being based outside them, though logging practice matters more than jurisdiction.
A complete domain name that spells out every level up to the root, such as server1.eu.example.com. It resolves the same way regardless of a client search domain.
A restriction that changes or blocks content based on your IP geolocation, DNS resolver location, account region, or payment country.
The name given to one machine or service, such as mail.example.com. Resolving a hostname to an IP is the first step in almost every connection.
HyperText Transfer Protocol is the foundation of web communication. HTTPS adds TLS encryption for secure connections (the lock icon in browsers).
An Apple feature sending Safari traffic through two relays so neither sees both who you are and where you went. It is not a full VPN and covers only some traffic.
The control protocol behind ping and traceroute. Many hosts deliberately ignore ICMP, so no reply does not always mean the host is down.
A VPN protocol pair that reconnects quickly when a device changes network, which makes it a common default on phones.
The global network of networks that connects devices, ISPs, data centers, mobile carriers, and cloud services using shared protocols and routing systems.
A numeric identifier for a device on a network. Public IPs are visible on the internet; private IPs are used inside local networks.
An estimate of where an IP address is located based on allocation data, routing patterns, and geolocation databases. It is not GPS and is usually city/region level at best.
A score mail servers and security services attach to an IP based on its past behaviour. A poor reputation gets your mail rejected or your traffic challenged.
The most common IP format using four numbers like 8.8.8.8. IPv4 space is limited, which is why IPv6 exists.
The shortage of available IPv4 addresses, which led to widespread use of NAT, CGNAT, and IPv6 adoption.
A newer IP format using hexadecimal groups like 2001:4860:4860::8888. It provides a much larger address space.
A failure where IPv6 traffic bypasses a tunnel carrying only IPv4, exposing your real address to any site that supports IPv6.
A company that provides your internet connection (home/mobile). Your public IP address is typically assigned by your ISP.
A shared facility where many networks connect to peer with each other. Large exchanges such as AMS-IX and DE-CIX carry a large share of regional traffic.
Variation in latency between packets. A steady 60 ms is fine for a call; 20 ms that spikes to 200 ms is not, which is why jitter matters more than average ping.
A network that connects devices within a limited area such as a home, office, or school using Ethernet cables or Wi-Fi.
The time it takes for data to travel from source to destination, usually measured in milliseconds (ms). Lower latency means faster response times.
The in-house ExpressVPN protocol, built for fast connection setup and quick recovery when a network drops.
An address a device assigns itself when no DHCP server answers, such as 169.254.x.x in IPv4. It only works on the local segment and usually signals a DHCP failure.
127.0.0.1 in IPv4 and ::1 in IPv6. Traffic sent to a loopback address never leaves the device, so it is used to test whether the local network stack works.
A unique hardware identifier (48-bit) assigned to every network interface. MAC addresses operate at the link layer and are used for local network communication.
Any software written to damage or exploit a device, covering viruses, trojans, spyware, and ransomware.
A network that spans a city or large campus, bridging the gap between LANs and WANs. Often uses fiber optic backbone.
An attacker sitting between you and the site you think you are reaching, able to read or alter traffic. HTTPS and a VPN are the standard defences.
Hosting where the provider handles updates, backups, caching, and security instead of leaving them to you. Common for WordPress.
Several access points sharing one network name and handing devices between them. It fixes coverage in large homes better than a single stronger router.
A device that converts signals from your ISP (cable, fiber, DSL) into data your router and devices can use. The modem connects your home to the internet.
Multiprotocol Label Switching is a routing technique that directs data using short path labels rather than long network addresses, improving speed and traffic management.
The largest packet a link will carry, usually 1500 bytes on Ethernet. VPN overhead lowers the usable value, and a mismatch causes connections that stall rather than fail.
Routing traffic through two VPN servers so neither one sees both your real IP and your destination. It costs speed and is rarely needed for everyday privacy.
A delivery method where one packet reaches a group of interested receivers instead of every host. Used for streaming video, service discovery, and routing protocols.
A DNS record that specifies the mail server responsible for receiving email for a domain.
A technique that lets many private devices share one public IP address via a router. It's why devices inside your home network aren't directly reachable from the internet.
The shape of how devices connect: star, bus, ring, mesh, or a hybrid. Topology decides what stops working when a single link goes down.
The hardware connecting a device to a network and carrying its MAC address. Most machines have one wired and one wireless.
A provider commitment not to record which sites you visit or which IP you connected from. Its value rests on independent audits, not on the claim itself.
The NordVPN implementation of WireGuard, adding a double NAT layer so the server does not need to store a static IP against your key.
A DNS record that delegates a domain to specific authoritative name servers.
Disguising VPN traffic so it looks like ordinary HTTPS. Used on networks and in countries where VPN protocols are detected and blocked.
One of the four numbers in an IPv4 address, each holding 8 bits and a value from 0 to 255. 192.168.1.1 has four octets.
Connecting to a VPN first and then entering the Tor network. Your ISP sees only the VPN, and the Tor entry node sees the VPN server rather than your real IP.
A long-established open-source VPN protocol known for flexibility and broad compatibility across desktop, mobile, and router setups.
A seven-layer reference model describing network functions from physical cabling up to applications. Engineers mostly use it as shared vocabulary for locating a fault.
The first three bytes of a MAC address, assigned to a manufacturer. It is what lets a MAC lookup name the vendor of an unknown device.
A small unit of data transmitted over a network. Internet traffic is broken into packets that travel independently and are reassembled at the destination.
A networking problem where some packets never reach their destination. Packet loss can cause buffering, lag, poor call quality, and unstable VPN or gaming sessions.
An arrangement where two networks exchange traffic directly instead of paying a transit provider. Good peering is why some routes beat what distance alone predicts.
A key exchange design where every session uses a fresh key. Recording traffic today does not let an attacker decrypt it later even if the long-term key leaks.
A social engineering attack where fake emails, messages, or websites impersonate trusted entities to trick users into revealing passwords, payment details, or personal information.
A network utility that sends ICMP echo requests to test whether a host is reachable and measures round-trip latency in milliseconds.
A physical facility where a provider terminates connections in a given city. More PoPs near you generally means lower latency.
A number from 0 to 65535 identifying one service on a host. Web traffic uses 80 and 443, so an address plus a port defines a single endpoint.
A router feature that directs inbound traffic on a public IP/port to a specific device on a private network.
An internal network address (RFC1918) that is not routable on the public internet, such as 10.x.x.x or 192.168.x.x.
A standardized set of rules that devices follow to exchange data. TCP, IP, HTTP, TLS, DNS, and VPN protocols all define how internet traffic behaves.
A server that forwards your traffic. Proxies can change apparent IPs but often don't encrypt traffic like a VPN.
A DNS record used for reverse lookups: it maps an IP address back to a hostname. PTR records are commonly used by email servers and for diagnostics.
An IP address that is routable on the public internet. It's what websites see when you connect from home or mobile networks.
Router settings that prioritise some traffic over the rest. Useful when one large upload would otherwise ruin calls and gaming on the same line.
A VPN server running entirely from volatile memory with no writable disk. Every reboot wipes the machine, so there is nothing persistent to seize.
Malware that encrypts your files and demands payment for the key. Offline backups are the only dependable defence once it has run.
Capping how many requests one client may make in a time window. It is the first defence against scraping, credential stuffing, and abusive bots.
A modern, structured protocol used to retrieve registration and allocation data for domains and IP resources. RDAP is the successor to legacy WHOIS for many registries and internet registries.
An IP assigned by a consumer ISP to a home connection. Sites treat these as ordinary users, which is why residential proxies are harder to detect than datacenter ones.
A lookup that asks "what hostname is configured for this IP?". It typically uses a PTR record under in-addr.arpa (IPv4) or ip6.arpa (IPv6).
One of five bodies (ARIN, RIPE NCC, APNIC, LACNIC, AFRINIC) allocating IP blocks and ASNs in their region. Their databases are what WHOIS and RDAP query.
A file at the root of a site asking crawlers which paths to skip. Well-behaved bots honour it, but it is a request rather than an enforcement mechanism.
One of the thirteen logical server addresses at the top of DNS. They do not know your domain, only which servers are authoritative for .com, .org, and every other TLD.
A device that forwards data packets between networks, directing traffic from your local network to the internet and back based on IP addresses.
Software-Defined Wide Area Network uses software to intelligently manage multiple WAN connections, improving performance and reducing costs for businesses.
A system that stores data, runs applications, or answers requests from other devices called clients. Websites, APIs, and email all depend on servers.
An attack that moves your number to an attacker SIM so they receive your SMS codes. It is the main reason SMS is the weakest form of two-factor authentication.
A DNS-based service that reroutes specific requests so streaming and geo-restricted apps see a different region without encrypting your full device traffic.
The Start of Authority record naming the primary nameserver for a zone and holding its serial number and refresh timers. Every DNS zone has exactly one.
A versatile proxy protocol that routes any type of traffic (not just HTTP) through a proxy server. SOCKS5 supports authentication but does not encrypt traffic by default.
A TXT record listing which servers may send mail for a domain. Receiving servers check it to reject forged senders.
A VPN feature that routes only selected apps or traffic through the VPN while other traffic uses the normal internet connection. Misconfigured split tunneling can cause leaks or inconsistent results.
A record pointing a named service and protocol at a host and port. SIP, XMPP, and Microsoft directory services rely on it.
Service Set Identifier is the name of a Wi-Fi network that appears when you scan for available connections.
A file proving a domain identity and enabling HTTPS. Free automated certificates have made paid ones unnecessary for most sites.
A public IP address that stays the same over time. Often required for hosting services or consistent remote access.
Session Traversal Utilities for NAT is a protocol used by WebRTC and other apps to discover network path information. STUN behavior is one reason WebRTC leak tests matter for VPN users.
A logical subdivision of an IP network. Subnetting splits a larger network into smaller segments for better organization, security, and routing efficiency.
A value such as 255.255.255.0 that splits an IP address into a network part and a host part. It tells a device which addresses it can reach directly.
A network device that connects devices within a LAN and forwards data based on MAC addresses. Switches are more efficient than hubs because they send data only to the intended recipient.
A reliable, connection-oriented protocol that ensures data arrives completely and in order. Used for web browsing, email, and file transfers.
The actual amount of data successfully transferred over a network in a given time period. Unlike bandwidth, throughput accounts for overhead and packet loss.
A backbone network that reaches the entire internet through peering alone and buys transit from nobody. Only a handful exist worldwide.
A regional time setting (for example, Europe/Chisinau or America/New_York). IP tools estimate timezone from IP geolocation data, so it may differ from your device clock settings.
A cryptographic protocol that provides encrypted communication over networks. TLS is the security layer behind HTTPS, email encryption, and VPN protocols.
A privacy network that routes traffic through three encrypted relays so no single node sees both sender and destination. Significantly slower than VPNs.
A network diagnostic tool that shows the path packets take from your device to a destination, listing each hop and its latency.
A tiny invisible image loaded from an advertiser server. Requesting it hands over your IP, user agent, and the page you are reading.
How long a server takes to send the first byte of a response. It separates hosting speed from front-end speed when a page feels slow.
A DNS cache duration (in seconds) that tells resolvers how long to keep a record before refreshing it.
A DNS record that stores text values, often used for domain verification and email security records such as SPF, DKIM, and DMARC.
A faster but less reliable protocol that sends data without guaranteeing delivery or order. Used for streaming, gaming, and VoIP.
A protocol letting applications open router ports automatically. Convenient for consoles and games, and a common security recommendation to switch off.
The share of time a service is reachable, normally quoted as 99.9 percent or better. 99.9 percent still allows roughly 43 minutes of downtime a month.
A string a browser or bot sends to identify itself. It is trivially faked, so it labels polite crawlers but never proves who a visitor is.
A calling technology that routes phone conversations over internet connections instead of traditional phone lines. VoIP numbers are common in business systems and scam campaigns.
A Virtual Private Network encrypts your traffic and routes it through a VPN server, helping reduce tracking and protect data on untrusted networks.
Enterprise hardware or software that terminates many simultaneous VPN tunnels at one point, typically so remote staff can reach an internal company network. It is a corporate remote-access device, not something a consumer VPN subscription involves.
A VPN safety feature that blocks internet traffic if the VPN tunnel drops unexpectedly, helping prevent accidental IP exposure.
A router setting that lets older VPN protocols such as PPTP, L2TP, and IPsec cross the router's NAT to reach a VPN server elsewhere. It does not run a VPN on the router and does not protect your traffic by itself. Modern protocols like WireGuard and OpenVPN run over UDP and rarely need it, which is why the toggle is increasingly vestigial on new hardware.
The company that operates the VPN servers you connect through and that can technically observe your traffic at the exit point. Choosing one is a decision about who you move that visibility to, which is why jurisdiction, logging policy, and independent audits matter more than server counts.
A router that runs the VPN client itself, so every device on the network is tunnelled without installing an app on each one. Useful for smart TVs and consoles that cannot run VPN software, at the cost of slower throughput because the router CPU handles encryption.
A guaranteed slice of a physical server with its own operating system and usually its own IP. More control than shared hosting, less cost than a whole machine.
A network that connects LANs across large geographic distances: cities, countries, or continents. The internet is the largest WAN.
A published statement that a provider has received no secret legal demands. Its removal is meant to signal that one has arrived.
An automated client fetching pages to build a search index or a training set. Search engines and AI companies publish the IP ranges their crawlers use.
A service that runs your site on a server connected to the internet and answers requests for your domain.
Web Real-Time Communication is a browser technology for real-time audio/video/data connections. Depending on browser behavior and settings, WebRTC can expose IP-related information through STUN requests.
A protocol/service used to retrieve registration information for domains and allocation/ownership info for IP address ranges. It's not the same as IP geolocation.
A family of wireless networking protocols (IEEE 802.11) that let devices connect to a local network without cables. Wi-Fi is not the same as the internet.
A Wi-Fi generation aimed at crowded networks. It raises throughput when many devices are active rather than lifting the peak speed of a single one.
A modern VPN protocol designed to be lean, fast, and easier to audit than older VPN stacks. Many current VPNs use WireGuard for better speed and lower overhead.
Wi-Fi Protected Access is a series of security protocols that encrypt wireless network traffic. WPA3 is the latest and most secure standard.
A router feature designed to simplify Wi-Fi device setup (often using a button or PIN). Many users disable WPS for security and control reasons.
A vulnerability already being exploited before the vendor has a patch. Until an update ships, only reduced exposure helps.
Social Engineering
Manipulating a person into granting access rather than defeating the technology. It remains the most reliable way into most organisations.
Learn more