{"id":1699,"date":"2020-06-08T01:11:37","date_gmt":"2020-06-07T17:11:37","guid":{"rendered":"https:\/\/www.wesbytes.com\/guide\/?post_type=kb&#038;p=1699"},"modified":"2026-03-26T12:25:32","modified_gmt":"2026-03-26T04:25:32","slug":"warning-about-exposing-your-origin-ip-address","status":"publish","type":"kb","link":"https:\/\/www.servergigabit.com\/guide\/kb\/warning-about-exposing-your-origin-ip-address","title":{"rendered":"Warning about exposing your origin IP address"},"content":{"rendered":"<h2><strong>Warning about exposing your origin IP address<\/strong><\/h2>\n<p><img fetchpriority=\"high\" decoding=\"async\" class=\"aligncenter\" src=\"https:\/\/preview.redd.it\/previewing-this-file-can-potentially-expose-your-ip-address-v0-td8irzw1cxad1.jpeg?width=1080&amp;crop=smart&amp;auto=webp&amp;s=5c385647774f71d72312c356a93ca6b74731d8b6\" alt=\"Warning about exposing your origin IP address\" width=\"1080\" height=\"494\" \/><\/p>\n<h5><span style=\"font-size: 1.7em; font-weight: bold;\">Overview<\/span><\/h5>\n<div class=\"mkb-anchor mkb-clearfix mkb-back-to-top-inline\">\n<p><em>When you have grey-clouded DNS records, <a href=\"https:\/\/www.cloudflare.com\/\" rel=\"nofollow noopener\" target=\"_blank\">Cloudflare<\/a> may warn you that your DNS records might reveal your origin server\u2019s IP address. This is most common with A, AAAA, CNAME, and MX DNS records.<\/em><\/p>\n<\/div>\n<p>When your DNS records are orange-clouded, Cloudflare speeds up and protects your site.<\/p>\n<p>A\u00a0<em>dig<\/em>\u00a0query against your orange-cloud root domain returns a Cloudflare IP address. This way, your origin server\u2019s IP address remains concealed from the public. Remember that orange cloud benefits only apply to HTTP traffic.<\/p>\n<p>Under certain circumstances, the\u00a0<strong>DNS Records<\/strong>\u00a0panel in the Cloudflare dashboard\u00a0<strong>DNS<\/strong>\u00a0app displays a warning whenever you have grey-clouded DNS records that may expose your origin server\u2019s IP address. This warning does not block, or in any way affect, traffic destine to your site.<\/p>\n<p>When your server\u2019s IP address is expose, your server is more vulnerable to direct attacks.<\/p>\n<p>Below are two cases where you might see an IP exposure warning from Cloudflare.<\/p>\n<p>&nbsp;<\/p>\n<hr \/>\n<div class=\"mkb-anchor mkb-clearfix mkb-back-to-top-inline\">\n<h2 class=\"mkb-anchor__title\">Case 1 \u2013 DNS records that should be orange-clouded<\/h2>\n<\/div>\n<p>If you see the following warning:<\/p>\n<p><em>This record is exposing your origin server\u2019s IP address. To hide your origin IP address, and increase your server security, click on the grey cloud to change it to orange.<\/em><\/p>\n<p>Cloudflare recommends orange-clouding the record so that any dig query against that record returns a Cloudflare IP address and your origin server IP address remains concealed from the public.<\/p>\n<p>To take advantage of Cloudflare\u2019s performance and security benefits, we recommend you orange-cloud DNS records that handle HTTP traffic, including A, AAAA, and CNAME. Do not orange-cloud MX records.<\/p>\n<p>&nbsp;<\/p>\n<hr \/>\n<div class=\"mkb-anchor mkb-clearfix mkb-back-to-top-inline\">\n<h2 class=\"mkb-anchor__title\">Case 2 \u2013 DNS records that need to be grey-clouded<\/h2>\n<\/div>\n<p>When you have a grey-clouded\u00a0<em>A<\/em>,\u00a0<em>AAAA<\/em>,\u00a0<em>CNAME<\/em>, or\u00a0<em>MX<\/em>\u00a0record pointing to the same origin server hosting your site, Cloudflare displays one of the following warnings:<\/p>\n<p><em>An A, AAA, CNAME, or MX record is pointed to your origin server exposing your origin IP.<\/em><\/p>\n<p><em>This record is exposing your origin server\u2019s IP address, potentially exposing it to denial of service.<\/em><\/p>\n<p>Wildcard \u201c<strong>*<\/strong>\u201d DNS records can only be proxied to Cloudflare for domains on the Enterprise plan. For all other plans, a wildcard DNS record reveals the origin IP.<\/p>\n<p>A\u00a0<em>dig<\/em>\u00a0query against these records reveals your origin server\u2019s IP address. This information makes it easier for potential attackers to target your origin server directly.<\/p>\n<p>However, there are times when some of your DNS records need to remain grey-clouded. For example:<\/p>\n<ul>\n<li>MX records must be orange-cloud because email isn\u2019t route via HTTP; otherwise, email routing won\u2019t work<\/li>\n<li>When you have to host multiple services (for example, a website and email) on the same physical server<\/li>\n<\/ul>\n<p>To mitigate this risk, we recommend that you:<\/p>\n<ul>\n<li>Host your email service in a server (in-house or external) that is different from your site\u2019s origin server<\/li>\n<li>Analyze the impact of<a href=\"https:\/\/www.servergigabit.com\/\"> hosting<\/a> multiple services on the same origin server in cases when having grey-clouded DNS records can\u2019t be avoide<\/li>\n<li>Orange-cloud all records that share the same origin IP address as your root domain and can be safely proxied through Cloudflare<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Warning about exposing your origin IP address Overview When you have grey-clouded DNS records, Cloudflare may warn you that your DNS records might reveal your origin server\u2019s IP address. This is most common with A, AAAA, CNAME, and MX DNS records. When your DNS records are orange-clouded, Cloudflare speeds up and protects your site. A\u00a0dig\u00a0query against your orange-cloud root domain&hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"kbtopic":[43],"kbtag":[1386,1387],"class_list":["post-1699","kb","type-kb","status-publish","hentry","kbtopic-cloudflare","kbtag-ip-address-exposed","kbtag-warning"],"_links":{"self":[{"href":"https:\/\/www.servergigabit.com\/guide\/wp-json\/wp\/v2\/kb\/1699","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.servergigabit.com\/guide\/wp-json\/wp\/v2\/kb"}],"about":[{"href":"https:\/\/www.servergigabit.com\/guide\/wp-json\/wp\/v2\/types\/kb"}],"author":[{"embeddable":true,"href":"https:\/\/www.servergigabit.com\/guide\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.servergigabit.com\/guide\/wp-json\/wp\/v2\/comments?post=1699"}],"version-history":[{"count":4,"href":"https:\/\/www.servergigabit.com\/guide\/wp-json\/wp\/v2\/kb\/1699\/revisions"}],"predecessor-version":[{"id":5989,"href":"https:\/\/www.servergigabit.com\/guide\/wp-json\/wp\/v2\/kb\/1699\/revisions\/5989"}],"wp:attachment":[{"href":"https:\/\/www.servergigabit.com\/guide\/wp-json\/wp\/v2\/media?parent=1699"}],"wp:term":[{"taxonomy":"kbtopic","embeddable":true,"href":"https:\/\/www.servergigabit.com\/guide\/wp-json\/wp\/v2\/kbtopic?post=1699"},{"taxonomy":"kbtag","embeddable":true,"href":"https:\/\/www.servergigabit.com\/guide\/wp-json\/wp\/v2\/kbtag?post=1699"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}