Knowledgebase

Cloudflare and Your Origin IP Print

  • dedicatedips, dedicated, cloudflare, dns, domain, subdomain, restore, security, plugins, woocommerce
  • 0

When Cloudflare proxies your site, the address visitors see is not yours.

HOW IT WORKS

Your domain's A record at Cloudflare points at your server, but the record is proxied, so DNS returns Cloudflare's addresses to visitors. Traffic reaches Cloudflare first and is forwarded to your server.

WHAT THIS MEANS

A DNS lookup of your domain returns Cloudflare's addresses, not your server's. This is expected and not a fault. Your visitor logs show Cloudflare addresses unless you install the Cloudflare plugin to restore real visitor IPs. Your origin address is concealed, which is a real security benefit.

WHAT TO BE CAREFUL ABOUT

Do not publish your origin address. If an attacker learns it, they can connect directly and bypass Cloudflare entirely.

Sources that leak it include mail headers from mail sent by the server, unproxied subdomain records, and historic DNS records archived by lookup services.

Keep mail records DNS-only, which is required for delivery anyway, and be aware this exposes the mail server address.

IF YOU HOLD A DEDICATED IP AND USE CLOUDFLARE

The dedicated address is your origin. Point the Cloudflare A record at it.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot