Skip to content
RU
← All articles

What Is 0.0.0.0? Listen Address, Default Route and Hosts File

A terminal listing listening network sockets and their addresses

0.0.0.0 is a reserved IPv4 address that means "no particular address", so its meaning depends on where you see it: on a server it means "listen on every interface", in a routing table it means "any destination", and on a client it means "no address assigned yet". You cannot send traffic to it like a normal host.

What does 0.0.0.0 mean?

The whole 0.0.0.0/8 block is reserved for "this host on this network". The host requirements in RFC 1122 only allow 0.0.0.0 as a source address, while a machine is booting and does not yet know its own IP. The special-purpose registry in RFC 6890 confirms it is not a valid destination, and routers will not forward packets addressed to it.

In day-to-day work you will meet it in five different roles:

  • A server bind address (0.0.0.0:80) — accept connections on every IPv4 address the machine has.
  • The default route (0.0.0.0/0) — "anything not matched by a more specific route".
  • A placeholder for a missing address — a DHCP client that has not been served, a router with no upstream link.
  • A blackhole entry in the hosts file — a cheap way to block a domain.
  • "Anywhere" in firewall rules and cloud security groups.

In binary it is 32 zero bits, which is why a netmask of 0.0.0.0 matches every address. If prefixes and masks feel fuzzy, the subnet mask guide walks through /8 to /32.

0.0.0.0 as a listen address

When a program opens a listening socket it chooses the local address to accept connections on:

  • 127.0.0.1 — only connections from the same machine;
  • a specific address such as 10.0.0.5 — only through that interface;
  • 0.0.0.0 — through any IPv4 interface: loopback, LAN, public IP, VPN tunnel, Docker bridge.

This explains the most common dev-environment puzzle: the app works at http://localhost:3000 on your laptop but not from your phone on the same Wi-Fi. The server is bound to 127.0.0.1. Vite's dev server binds to localhost unless you pass --host; Flask needs --host=0.0.0.0.

The reverse mistake is the dangerous one: an internal service bound to 0.0.0.0 on a machine with a public IP. That is why databases ship with conservative defaults — PostgreSQL uses listen_addresses = 'localhost', most MySQL/MariaDB packages set bind-address = 127.0.0.1, and Redis uses bind 127.0.0.1 -::1 with protected-mode yes. If you widen them, a firewall has to do the job instead. The open ports security guide covers what an exposed port really costs you.

Config examples

# nginx: no address means all IPv4 interfaces
listen 80;
listen 0.0.0.0:80;        # same thing, explicit
listen 127.0.0.1:8080;    # local only, e.g. an internal backend

# Python's built-in server, local only
python3 -m http.server 8000 --bind 127.0.0.1

# Docker: -p without an address publishes on every host interface
docker run -p 8080:80 nginx
docker run -p 127.0.0.1:8080:80 nginx   # reachable from the host only

Docker deserves a warning of its own. Published ports are wired up with iptables rules that Docker manages itself, so the traffic does not pass through your ufw or firewalld rules where you would expect — the Docker firewall documentation says so explicitly. If only a reverse proxy on the same host needs the container, publish it on 127.0.0.1. For the full picture of listen and server blocks, see the nginx configuration guide.

The IPv6 equivalent

In IPv6 the unspecified address is :: (RFC 4291). On Linux a socket bound to [::]:80 also accepts IPv4 connections unless net.ipv6.bindv6only=1 is set or nginx is told ipv6only=on. A service you carefully restricted on IPv4 can still be wide open on IPv6, so check both stacks.

How to check what a service is listening on

Linux — ss from iproute2 (sudo to see other users' processes):

sudo ss -tlnp
State   Recv-Q  Send-Q  Local Address:Port  Peer Address:Port  Process
LISTEN  0       511     0.0.0.0:80          0.0.0.0:*          users:(("nginx",pid=812,fd=6))
LISTEN  0       244     127.0.0.1:5432      0.0.0.0:*          users:(("postgres",pid=640,fd=5))
LISTEN  0       511     [::]:80             [::]:*             users:(("nginx",pid=812,fd=7))

nginx is reachable from the network; PostgreSQL is local only. *:80 means the same as "all addresses", and a peer column of 0.0.0.0:* simply means "no remote end yet". On older systems, sudo netstat -tlnp does the same job.

Windows — from cmd:

netstat -ano | findstr LISTENING
  TCP    0.0.0.0:135      0.0.0.0:0     LISTENING     1044
  TCP    0.0.0.0:445      0.0.0.0:0     LISTENING     4
  TCP    127.0.0.1:9229   0.0.0.0:0     LISTENING     15320

The last column is the PID; tasklist /FI "PID eq 15320" gives the process name. In PowerShell:

Get-NetTCPConnection -State Listen | Select-Object LocalAddress, LocalPort, OwningProcess | Sort-Object LocalPort

macOS — sudo lsof -nP -iTCP -sTCP:LISTEN; an asterisk in *:8080 means all interfaces.

A local listing only tells you a service is willing to accept outside connections; the firewall and NAT decide whether any arrive. Test from the outside with the enterno.io port scanner, and see how to check open ports for per-OS methods.

0.0.0.0/0: the default route

A routing entry with destination 0.0.0.0 and mask 0.0.0.0 (prefix /0) matches every destination. Because the longest matching prefix wins, it is used only when nothing more specific applies — usually pointing at your ISP's gateway or your home router.

# Linux: "default" is 0.0.0.0/0
ip route show default
default via 192.168.1.1 dev eth0 proto dhcp metric 100

# Windows
route print -4
Network Destination        Netmask          Gateway       Interface  Metric
          0.0.0.0          0.0.0.0      192.168.1.1    192.168.1.10     25

In the legacy route -n output on Linux, 0.0.0.0 can also appear in the Gateway column, where it means "no gateway, directly connected"; Windows labels the same thing "On-link".

In firewall rules and cloud security groups, 0.0.0.0/0 means "from anywhere on the internet". "TCP 22 from 0.0.0.0/0" exposes SSH to the whole world; administrative ports should list specific source ranges. The IP calculator helps you work out what a prefix actually covers.

0.0.0.0 on DHCP clients and routers

A machine joining a network does not know its address, so its first DHCPDISCOVER goes from 0.0.0.0 to the broadcast address 255.255.255.255, exactly as described in RFC 2131. That is the one legitimate use of 0.0.0.0 on the wire; the DHCP explainer covers the rest of the exchange.

When the process stalls, 0.0.0.0 turns into a symptom:

  • Router status page shows WAN IP 0.0.0.0 — the router has no address from the ISP: a cable problem, the wrong connection type (PPPoE vs. DHCP/IPoE), MAC binding on the provider side, or an outage.
  • A client shows a gateway or mask of 0.0.0.0 — no DHCP reply arrived. Windows then typically falls back to a self-assigned 169.254.x.x address (APIPA), another sign DHCP failed.

Fixes: ipconfig /release then ipconfig /renew on Windows; sudo dhclient -r && sudo dhclient or restarting the connection with nmcli on Linux; then check cabling and the router's WAN settings.

0.0.0.0 in the hosts file

Ad and tracker blocklists usually look like this:

0.0.0.0 ads.example.com
0.0.0.0 tracker.example.net

The file lives at C:\Windows\System32\drivers\etc\hosts on Windows and /etc/hosts on Linux and macOS. Flush the resolver cache afterwards: ipconfig /flushdns on Windows, sudo resolvectl flush-caches on Linux with systemd-resolved, sudo dscacheutil -flushcache; sudo killall -HUP mDNSResponder on macOS.

Why 0.0.0.0 rather than 127.0.0.1? With 127.0.0.1 the browser connects to your own machine, and if a web server is running there, it answers. With 0.0.0.0 the result depends on the OS: Windows refuses the connection immediately, while Linux and macOS quietly connect to the local host just as they would for 127.0.0.1. On a developer workstation running a local server on port 80, the two entries may behave identically.

0.0.0.0 vs 127.0.0.1

Aspect0.0.0.0127.0.0.1
Official meaning"This host", unspecified addressLoopback — the machine itself
As a bind addressAll IPv4 interfaces, reachable from the networkLocal connections only
As a destinationNot valid; Linux and macOS map it to the local host, Windows refusesAlways the local machine
In a routing table0.0.0.0/0 is the default route127.0.0.0/8 goes to the lo interface
In the hosts fileBlock a domainBlock it or point it at a local server
IPv6 counterpart::::1

The "0.0.0.0 Day" browser flaw

In 2024, researchers at Oligo Security described an issue they named 0.0.0.0 Day. Browsers stopped public websites from reaching localhost and 127.0.0.1, but not 0.0.0.0 — and because Linux and macOS route a connection to 0.0.0.0 to the local machine, a web page could send requests to services running on the visitor's computer: dev servers, local dashboards, developer-tool APIs. Windows was not affected, since it never completes such a connection.

Browser vendors have since moved to block websites from reaching 0.0.0.0; in Chrome this falls under Private Network Access. The lesson for developers holds regardless of browser version: do not bind local tools to 0.0.0.0 unless you need to, prefer 127.0.0.1, and do not leave local APIs unauthenticated on the assumption that nobody outside can see them.

How to check your setup

  1. List everything bound to 0.0.0.0: sudo ss -tlnp on Linux, netstat -ano | findstr LISTENING on Windows.
  2. For each one, decide whether it should be reachable from the network. If not, rebind it to 127.0.0.1 in its config.
  3. Scan the server from outside with the port scanner to catch anything the firewall lets through.
  4. Review firewall rules and security groups with a 0.0.0.0/0 source, starting with SSH, RDP and database ports.

FAQ

Is 0.0.0.0 my IP address?

No. If your computer or router reports 0.0.0.0 as its address, it has not been assigned one — DHCP or the ISP did not respond. Your real local address shows up in ipconfig on Windows or ip -4 addr on Linux.

Can I open http://0.0.0.0:8000 in a browser?

On Linux and macOS it usually reaches your local server, like localhost. On Windows the connection fails and Chrome shows an error such as ERR_ADDRESS_INVALID. Use http://127.0.0.1:8000 or http://localhost:8000 instead.

Is it unsafe for a server to listen on 0.0.0.0?

For a web server on ports 80 and 443 it is expected. For a database, Redis, an admin panel or a debug port it is a risk unless a firewall blocks outside access. Bind those to 127.0.0.1 or a private address.

What does a 0.0.0.0 netmask mean?

A mask of all zeros fixes no network bits, so every address matches. In CIDR notation it is /0, and together with network 0.0.0.0 it forms the default route.

How is 0.0.0.0 different from 255.255.255.255?

0.0.0.0 means "no specific address" or "this host"; 255.255.255.255 is the limited broadcast to every node on the local network. DHCP uses them as a pair: the request goes from the first to the second.

Check your website right now

Check if your site is reachable →
More articles: Networking
Networking
Cloudflare Blocked in Russia? Why Sites Fail and How to Fix It
20.07.2026 · 2 945 views
Networking
Your Site Is Blocked in Russia: Owner's Guide
13.07.2026 · 1 143 views
Networking
ERR_CONNECTION_TIMED_OUT: Fix It in Chrome, Windows and Android
23.06.2026 · 1 041 views
Networking
IP Geolocation Accuracy: How It Works and Where It Fails
11.03.2026 · 1 019 views