Hardware FixRecommendedDevice not working? Your driver may be the problemCheck updates for common hardware issues.Fix DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run Scan×
Skip to content
Cloudflare

How to Find a Website’s Origin IP Behind Cloudflare (Safely and Legally)

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Short answer: you usually cannot discover a Cloudflare-proxied website’s origin IP by looking up its main hostname. An active, proxied DNS record returns a Cloudflare anycast address instead of the backend address. Finding a likely origin requires an authorized review of every public DNS name—especially DNS-only services such as mail, FTP, SSH, APIs and staging—plus cautious comparison with historical DNS data. Any old or matching address is only a lead until you verify that it is still assigned to the site.

Start with authorization and a precise scope

Only investigate domains, subdomains and infrastructure that you own or have explicit permission to assess. DNS enumeration is generally low impact, but connecting to a suspected address can trigger intrusion detection, rate limits or contractual violations. Define the exact domain, permitted hostnames, time window and testing methods before you begin. Do not attempt to defeat authentication, bot checks, CAPTCHAs, firewalls or access controls.

Keep a record of the resolver used, query time, answer, TTL, record type and whether the response appears to be Cloudflare or a direct hosting provider. DNS answers can differ by resolver, location and time, so a single lookup is not proof of ownership or current use.

Understand what Cloudflare changes

Cloudflare separates the public DNS answer from the server that actually serves the application. When a zone is active and a DNS record is set to proxied, Cloudflare responds with an anycast IP rather than the origin IP defined in the DNS table. Traffic then passes through Cloudflare before reaching the origin.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A record set to DNS only is different: DNS returns the address stored in the zone. Non-HTTP services generally cannot use Cloudflare’s standard HTTP proxy, so mail, FTP, SSH, RDP, game servers and similar names are often left DNS-only. If one of those records points to the same machine as the web application, it can expose the backend address even though the web hostname is proxied.

During initial activation, records intended to be proxied can also return the origin temporarily while the zone is still pending. Treat the activation state as part of the investigation timeline.

Map the complete DNS surface

Looking only at the apex (for example, example.com) misses the names that most often disclose infrastructure. Build a hostname inventory from the organization’s documentation, certificates and public references, then test each name that is in scope.

  • example.com and www.example.com
  • Application and API names such as app, api, graphql and webhook
  • Mail names and MX targets
  • ftp, sftp, ssh, remote and administrative portals
  • Development, staging, preview, origin and legacy names
  • Any service-specific hostname published in documentation or client software

Do not assume a familiar prefix exists, and do not perform unbounded brute-force scans against systems you do not control. The objective is an authorized inventory, not a high-volume probe.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Query A, AAAA and CNAME records

Use a current dig installation (part of the DNS utilities package on most Linux and macOS systems). Replace example.com with your authorized target.

dig A example.com +noall +answer
dig AAAA example.com +noall +answer
dig CNAME example.com +noall +answer
dig A www.example.com +noall +answer
dig AAAA www.example.com +noall +answer
dig CNAME www.example.com +noall +answer

The answer section shows the record, TTL and returned value. A Cloudflare anycast address indicates that the queried record is probably proxied; it does not identify the origin. A provider address, cloud load balancer, or another hostname may be a direct endpoint, but it still requires confirmation.

Repeat the three queries for every hostname in your inventory. Capture both IPv4 (A) and IPv6 (AAAA) results: an origin can be hidden on IPv4 while an overlooked IPv6 record remains directly reachable, or the reverse. Follow a CNAME to its final A and AAAA answers and note each hop.

Record the evidence

Field Why it matters
Hostname and record type Shows which service, not just which domain, is exposed.
Answer and TTL Allows later comparison and indicates how quickly a change may propagate.
CNAME chain Identifies the service or provider ultimately answering the query.
Resolver and timestamp DNS answers vary by resolver, location and time.
Proxy status, if known Separates a Cloudflare edge address from a DNS-only answer.

Follow MX records to the mail servers

Cloudflare specifically warns that a mail server sharing the web server’s IP exposes that address because MX records are not hidden behind the HTTP proxy. Query MX first, then resolve every target returned.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
dig MX example.com +noall +answer
dig A mail.example.com +noall +answer
dig AAAA mail.example.com +noall +answer

For multiple MX targets, repeat the A and AAAA lookups for each fully qualified name. An MX target can itself be a CNAME or point to a managed mail provider, so distinguish an external mail service from an address belonging to the web environment. Never infer that a mail address is the origin merely because it is public; confirm whether the same infrastructure is actually serving the authorized web application.

Check DNS-only service names and forgotten systems

Review each DNS-only name for services that cannot use the normal Cloudflare HTTP proxy. FTP, SSH, RDP, game servers, API endpoints, webhooks and staging systems are common examples. A direct address that responds to a service does not automatically prove it hosts the website, but it is a candidate worth correlating with your asset inventory.

Use the organization’s own DNS zone, deployment records and cloud inventory whenever possible. Public certificate names, documentation and code references can reveal forgotten hostnames; treat them as leads and stay within scope. Avoid port scans or application fuzzing unless your authorization explicitly allows those actions.

Use historical DNS data carefully

Passive-DNS and other historical sources can show addresses that a hostname used in the past. Compare those records with current A, AAAA, CNAME and MX answers, deployment history and provider ownership. An old address is not proof of the current origin: organizations rotate addresses, use multiple load balancers, migrate providers and leave historical records indexed after decommissioning.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Cloudflare recommends rotating origin addresses after exposure or onboarding. Therefore, a historical match should be treated as a discovery lead, not as a target to contact. Do not attempt to log in, bypass a WAF or send traffic simply because an old record resembles the present configuration.

Validate a candidate conservatively

Validation should answer one question: does an address that you are authorized to test currently serve this site? Preserve the intended hostname so TLS Server Name Indication and virtual-host routing remain correct.

  1. Confirm ownership first. Match the candidate to an authorized cloud account, hosting record, firewall rule or provider contract.
  2. Check the certificate. Connect with the real hostname and inspect whether the presented certificate is appropriate for that name. A certificate mismatch is evidence against the candidate, not permission to bypass TLS.
  3. Send the minimum request. For an approved test, use a single HEAD request with a short timeout and normal user agent. Stop on errors or rate limiting.
  4. Compare application behavior. Look for the expected status, redirects and headers without probing hidden paths or authentication boundaries.
curl --resolve example.com:443:203.0.113.10 https://example.com/ -I --connect-timeout 10 --max-time 20

The --resolve option keeps the URL hostname while directing the connection to the candidate address. Replace the example address only with an address you are permitted to test. A successful response still does not establish that the address is the sole origin; it may be a load balancer, shared host or one member of a larger pool.

Why common approaches fail

Looking up only the apex

The apex and www may both return Cloudflare, while mail, staging or API names remain DNS-only. Inventory the whole surface instead of stopping at the first lookup.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Calling a Cloudflare address the origin

A proxied record deliberately returns a Cloudflare anycast address. That answer identifies the reverse-proxy edge, not the backend server.

Trusting every historical hit

Historical data records past states. Address rotation, migrations and multiple endpoints make an old match inconclusive without present-day ownership and behavior checks.

Rank #4
Sale
Forvencer Password Book with Individual Alphabetical Tabs, 4" x 5.5" Small
  • Individual A-Z Tabs for Quick Access: No need for annoying searches! With individual alphabetical tabs, this password keeper makes it easier to find your passwords in no time. It also features an extra tab for your most used websites. All the tabs are laminated to resist tears.
  • Handy Size & Premium Quality: Measuring 4.2" x 5.4", this password notebook fits easily into purses or pockets, which is handy for accessibility. With sturdy spiral binding, this logbook can lay flat for ease of use. 120 GSM thick paper to reduce ink leakage.
  • Never Forget Another Password: Bored of hunting for passwords or constantly resetting them? Then this password book is absolutely a lifesaver! Provides a dedicated place to store all of your important website addresses, emails, usernames, and passwords. Saves you from password forgetting or hackers stealing.
  • Simple Layout & Ample Space: This password tracker is well laid out and easy to use. 120 pages totally offer ample space to store up to 380 website entries. It also provides extra pages to record additional information, such as email settings, card information, and more.
  • Discreet Design for Secure Password Organization: With no title on the front to keep your passwords safe, it also has space to write password hints instead of the password itself! Finished with an elastic band for safe closure.

Ignoring IPv6

An unreviewed AAAA record can expose a different path than IPv4. Query both families for every relevant hostname.

Forgetting pending activation

While a zone is not yet active, a record intended to be proxied may temporarily return the origin. Include activation status and timestamps in your assessment.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Remediation for website owners

Finding Defensive action
HTTP or HTTPS record is DNS-only Proxy it through Cloudflare when the application and architecture support HTTP proxying.
Mail shares the web server’s address Separate mail from the web origin where possible; update MX and dependent systems together.
Non-HTTP service exposes the origin Place the service on separate infrastructure or a separately protected network; do not force unsupported traffic through the HTTP proxy.
Origin address appeared publicly Rotate the address, update every dependent record and deployment, and invalidate old access paths.
Direct access remains possible Where your design permits, restrict the origin firewall to Cloudflare IP ranges and keep administrative services off the web origin.
Unexpected records or warnings Review the Cloudflare dashboard, remove stale names and verify proxy status after DNS propagation.

After changes, repeat the authorized A, AAAA, CNAME and MX review from more than one resolver. Confirm that applications, webhooks, mail and operational tooling still use the intended endpoints.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Or skip the browser setup

If your goal is to capture how a site looks while documenting an authorized DNS or migration review, ScreenshotNeo can return a screenshot or PDF through one request. It is a screenshot API and MCP server for developers; it does not replace DNS analysis or reveal an origin by itself. Before capture it accepts cookie and consent banners like a visitor and removes more than 60 known consent platforms, newsletter popups and chat widgets. Bot checks, blank pages, timeouts, failed loads and cache hits are not billed, and the response identifies the page verdict and billing status in X-Page-Verdict and X-Billed headers. Its MCP server lets Claude, Cursor and other MCP clients call take_screenshot, get_page_info and capture_pdf.

See the ScreenshotNeo documentation for all options, including full-page lazy-image loading, CSS-selector captures, device presets, dark mode, custom CSS and JavaScript, waits, request blocking, headers and cookies, geolocation, PDF controls, caching, signed links, asynchronous webhooks, bulk capture and usage reporting.

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' }); const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);

Every plan includes the features above. The Free plan provides 1,000 screenshots per month with no card; paid plans start at $5 for 3,000 screenshots, with yearly billing giving two months free. Create a free ScreenshotNeo account to try it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

FAQ

Can a shared hosting address be the origin?

Yes. Shared hosting and load-balancing platforms can serve many sites from one address, so an IP match alone cannot establish that it belongs exclusively to your target. Ownership records and hostname-preserving validation are essential.

Best Value
Sale
Address Book with Alphabetical Tabs, Large Print for Seniors 5.7"x7.7"
  • 【Keep Your Contacts Organized】 This 7.7" x 5.7" address book keeps all your information in one place, helping you keep track of important dates, numbers, addresses and passwords.
  • 【Colorful Alphabetical Tabs】 Address book features individual tabs with colorful design that help you easily organize and quickly locate the phone numbers and addresses of your contacts.
  • 【Plenty of Writing Space】 Our phone number book has 384 entries to record contacts necessary information, 64 entries to store Internet passwords. And includes birthday pages, anniversary pages, notes pages, emergency contact pages, etc.
  • 【Premium Quality and Convenient Design】 The leather hardcover book makes telephone address book elegant and practical. Sturdy double-wire binding allows the address book to lay flat 360 °. And comes with thick no-bleed 100gsm paper, elastic band, inner pocket.
  • 【 Perfect Gift for Everyone】 Address and password book is a thoughtful and stylishl gift, keep work and life organized. The contact book with large fonts is geared for seniors.

Should I change DNS TTLs before rotating an exposed address?

Coordinate TTL changes with your DNS and deployment process. The correct value depends on your provider, failover design and maintenance window; changing it without updating dependent systems can create outages.

What should an incident report contain?

Include the hostname, record type, resolver, timestamp, TTL, observed answer, proxy state, evidence of ownership, validation commands used and remediation owner. Redact credentials, private keys and unrelated customer data.

Does moving mail to another provider solve every exposure?

No. It removes the specific MX-to-web relationship, but DNS-only APIs, staging systems, administrative names and IPv6 records can still disclose infrastructure. Recheck the entire authorized inventory after the move.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Frequently Asked Questions

Can a shared hosting address be the origin?

Yes. Shared hosting and load-balancing platforms can serve many sites from one address, so an IP match alone cannot establish that it belongs exclusively to your target. Ownership records and hostname-preserving validation are essential.

Should I change DNS TTLs before rotating an exposed address?

Coordinate TTL changes with your DNS and deployment process. The correct value depends on your provider, failover design and maintenance window; changing it without updating dependent systems can create outages.

What should an incident report contain?

Include the hostname, record type, resolver, timestamp, TTL, observed answer, proxy state, evidence of ownership, validation commands used and remediation owner. Redact credentials, private keys and unrelated customer data.

Does moving mail to another provider solve every exposure?

No. It removes the specific MX-to-web relationship, but DNS-only APIs, staging systems, administrative names and IPv6 records can still disclose infrastructure. Recheck the entire authorized inventory after the move.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Read next

Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.