What is a subnet mask actually for?
It tells a device which part of an IP address identifies the network and which part identifies the host — and therefore whether a destination is local or has to go via the router.
The decision it enables. Every time a device sends a packet it must answer one question: is this destination on my own network? If yes, send it directly to that device. If no, hand it to the default gateway — the router — and let it deal with it.
The subnet mask is how that question gets answered. The device applies the mask to both its own address and the destination address; if the resulting network portions match, the destination is local.
Reading a mask. An IPv4 address is 32 bits. A mask of 255.255.255.0 means the first 24 bits identify the network and the last 8 identify the host. In CIDR notation that is written /24, which is simply the number of network bits.
What that gives you. A /24 has 256 addresses, of which 254 are usable — one is reserved as the network address and one as the broadcast address. A /25 splits that in half with 126 usable hosts each; a /16 gives over 65,000.
Why it matters practically:
Two devices with mismatched masks cannot communicate reliably, even on the same physical network, because they disagree about what is local. This causes the classic fault where a device can reach some machines and not others.
A device outside the subnet range is unreachable without routing, which is why a static IP set carelessly stops working.
Subnetting separates traffic. Splitting a network reduces broadcast traffic and allows different rules — the basis of separating guest Wi-Fi, IoT devices and cameras from the main network.
The private ranges reserved for internal use: 10.0.0.0/8, 172.16.0.0/12 and 192.168.0.0/16. Home routers almost always use something in 192.168.
IPv6 changes the arithmetic but not the concept — a /64 is the standard subnet size, and address scarcity disappears entirely.