Short answer
A subnet mask is a 32-bit number used alongside an IP address to identify which portion of the address refers to the network and which portion refers to the individual device (host). The mask separates an IP address into two parts, allowing routers to direct traffic efficiently within and between networks.
At a glance
- Key stage
- GCSE
- Subject
- Computing
- Type
- Guide
- For
- Students
- Read time
- 4 min
- Last updated
- 8 October 2026
Where this fits
- Key Stage 3Years 7–9
- GCSEYears 10–11This article
Why are subnet masks necessary?
An IPv4 address such as 192.168.1.42 contains 32 bits but gives no indication on its own of where the network ends and the host begins. Is this a device with host number 42 on network 192.168.1? Or host 1.42 on network 192.168? The subnet mask answers this question definitively.
Without subnetting, every organisation would need an individual IP address registered globally for each device. Subnetting allows a company to take one block of addresses and divide it internally — for example, separating HR, Engineering, and Finance onto different sub-networks, while still appearing as a single network to the outside world.
How does a subnet mask work in binary?
A subnet mask contains a run of 1-bits followed by a run of 0-bits (no mixing). The 1-bits mark the network portion; the 0-bits mark the host portion.
Worked example — IP address 192.168.1.42 with mask 255.255.255.0:
| Decimal | Binary | |
|---|---|---|
| IP address | 192.168.1.42 | 11000000.10101000.00000001.00101010 |
| Subnet mask | 255.255.255.0 | 11111111.11111111.11111111.00000000 |
| Network address | 192.168.1.0 | 11000000.10101000.00000001.00000000 |
| Broadcast address | 192.168.1.255 | 11000000.10101000.00000001.11111111 |
The AND operation (1 AND 1 = 1, anything AND 0 = 0) applied between the IP address and the mask extracts the network address. The host portion is found in the bits where the mask has 0s — here, the last 8 bits give host numbers 0–255.
Host addresses 0 and 255 are reserved: 0 identifies the network itself and 255 is the broadcast address. This leaves 254 usable host addresses for devices (1–254).
What is CIDR notation?
CIDR (Classless Inter-Domain Routing) notation writes the subnet mask as a slash followed by the number of 1-bits in the mask. It is more compact than writing the full dotted-decimal mask.
| CIDR | Mask | Usable hosts | Typical use |
|---|---|---|---|
| /8 | 255.0.0.0 | 16,777,214 | Large ISP blocks |
| /16 | 255.255.0.0 | 65,534 | Medium enterprises |
| /24 | 255.255.255.0 | 254 | Small office/home network |
| /25 | 255.255.255.128 | 126 | Smaller sub-division |
| /30 | 255.255.255.252 | 2 | Point-to-point links |
So 192.168.1.42/24 carries the same information as 192.168.1.42 with mask 255.255.255.0.
How do routers use subnet masks?
When a router receives a packet, it performs a bitwise AND between the destination IP address and its own subnet mask to find the network address. It then consults its routing table to decide where to forward the packet.
Example:
A packet arrives for 192.168.1.42. The router has an interface on 192.168.1.0/24.
- AND
192.168.1.42with255.255.255.0→ network192.168.1.0. - The routing table has an entry for
192.168.1.0/24→ forward to that interface.
If the destination were 10.0.0.5, the AND result would be 10.0.0.0, which is a different network, and the router would forward to the default gateway instead.
What is the difference between a public and a private subnet?
Certain IP address ranges are reserved for private networks and are never routed across the public Internet:
| Range | CIDR | Common use |
|---|---|---|
| 10.0.0.0 – 10.255.255.255 | 10.0.0.0/8 | Large organisations |
| 172.16.0.0 – 172.31.255.255 | 172.16.0.0/12 | Medium organisations |
| 192.168.0.0 – 192.168.255.255 | 192.168.0.0/16 | Home and small office |
Devices on private subnets access the Internet through NAT (Network Address Translation), which maps many private addresses to a single public IP address. This is why your home router shows one public IP to the world while every device at home has a private 192.168.x.x address.
Frequently asked questions
What is the subnet mask for a typical home network?
Most home routers use the address range 192.168.1.0/24 (or 192.168.0.0/24), with subnet mask 255.255.255.0. This provides 254 usable host addresses — more than enough for a home with a handful of devices, and with private addressing so no address registration is needed.
Do I need to convert subnet masks to binary in my GCSE exam?
Some GCSE questions require you to apply a subnet mask in binary to find the network address, as shown in the worked example above. You should be comfortable performing a bitwise AND between two binary numbers and understand what the network and broadcast addresses mean. Full subnetting calculations involving multiple subnets are less common at GCSE level but may appear at the higher end of mark schemes.
Why do subnet masks always start with 1-bits and end with 0-bits?
A valid subnet mask must have a contiguous block of 1s followed by a contiguous block of 0s. Mixing (e.g. 11001111) would create an ambiguous boundary between network and host portions that routers could not interpret consistently. The CIDR prefix length (e.g. /24) simply counts the leading 1-bits, which is only meaningful because the mask is always contiguous.
What happens if two devices on the same network have conflicting subnet masks?
If device A thinks the network is /24 and device B thinks it is /16, they will disagree about which addresses are "local" and which require a router. Device A would try to send traffic to 192.168.2.5 via the router; device B would treat it as a local address and attempt a direct delivery. This results in unreachable hosts, dropped packets, and difficult-to-diagnose connectivity faults.
Want to practise applying subnet masks in binary with step-by-step checking? Professor Turing at aitutors.me will work through every worked example with you.
Key terms
- network
- host
- AND
- NAT (Network Address Translation)