{"id":2603,"date":"2019-10-22T17:00:03","date_gmt":"2019-10-22T09:00:03","guid":{"rendered":"https:\/\/www.mondoze.com\/guide\/?post_type=kb&#038;p=2603"},"modified":"2022-10-05T08:02:50","modified_gmt":"2022-10-05T00:02:50","slug":"warning-about-exposing-your-origin-ip-address-via-dns-records","status":"publish","type":"kb","link":"https:\/\/www.mondoze.com\/guide\/kb\/warning-about-exposing-your-origin-ip-address-via-dns-records","title":{"rendered":"Warning about exposing your origin IP address"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"2603\" class=\"elementor elementor-2603\" data-elementor-settings=\"[]\">\n\t\t\t\t\t\t<div class=\"elementor-inner\">\n\t\t\t\t\t\t\t<div class=\"elementor-section-wrap\">\n\t\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-1f7976a0 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"1f7976a0\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t\t\t<div class=\"elementor-row\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-6f5d30ee\" data-id=\"6f5d30ee\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-column-wrap elementor-element-populated\">\n\t\t\t\t\t\t\t<div class=\"elementor-widget-wrap\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-bbe09cb elementor-widget elementor-widget-heading\" data-id=\"bbe09cb\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Warning about Exposing your Origin IP Address<\/h2>\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-4b0a9cee elementor-widget elementor-widget-text-editor\" data-id=\"4b0a9cee\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t<div class=\"elementor-text-editor elementor-clearfix\">\n\t\t\t\t<p><em>When you have grey-clouded DNS records, Cloudflare may warn you that your DNS records might reveal your origin server\u2019s IP address. This is most common with A, AAAA, CNAME, and MX DNS records.<\/em><\/p><hr \/><h3><strong>Overview<\/strong><\/h3><p>When your DNS records are orange-clouded, Cloudflare speeds up and protects your site.<\/p><p>A\u00a0<em>dig<\/em> query against your orange-cloud root domain returns a Cloudflare IP address. This way, your origin server\u2019s IP address remains concealed from the public. Remember that orange cloud benefits only apply to HTTP traffic.<\/p><p>Under certain circumstances, the\u00a0<strong>DNS Records<\/strong>\u00a0panel in the Cloudflare dashboard\u00a0<strong>DNS<\/strong> app displays a warning whenever you have grey-clouded DNS records that may expose your origin server\u2019s IP address. This warning does not block, or in any way affect, traffic destine to your site.<\/p><p>When your server\u2019s IP address is expose, your server is more vulnerable to direct attacks.<\/p><p>Below are two cases where you might see an IP exposure warning from Cloudflare.<\/p><hr \/><h3><strong>Case 1 &#8211; DNS records that should be orange-clouded<\/strong><\/h3><p>If you see the following warning:<\/p><p><em>This record is exposing your origin server\u2019s IP address. To hide your origin IP address, and increase your server security, click on the grey cloud to change it to orange.<\/em><\/p><p>Cloudflare recommends orange-clouding the record so that any dig query against that record returns a Cloudflare IP address and your origin server IP address remains concealed from the public.<\/p><p>To take advantage of Cloudflare\u2019s performance and security benefits, we recommend you orange-cloud DNS records that handle HTTP traffic, including A, AAAA, and CNAME. Do not orange-cloud MX records.<\/p><hr \/><h3><strong>Case 2 &#8211; DNS records that need to be grey-clouded<\/strong><\/h3><p>When you have a grey-clouded\u00a0<em>A<\/em>,\u00a0<em>AAAA<\/em>,\u00a0<em>CNAME<\/em>, or\u00a0<em>MX<\/em>\u00a0record pointing to the same origin server hosting your site, Cloudflare displays one of the following warnings:<\/p><p><em>An A, AAA, CNAME, or MX record is pointed to your origin server exposing your origin IP.<\/em><\/p><p><em>This record is exposing your origin server\u2019s IP address, potentially exposing it to denial of service.<\/em><\/p><p>Wildcard &#8220;<strong>*<\/strong>&#8221; DNS records can only be proxied to Cloudflare for domains on the Enterprise plan. For all other plans, a wildcard DNS record reveals the origin IP.<\/p><p>A\u00a0<em>dig<\/em>\u00a0query against these records reveals your origin server\u2019s IP address. This information makes it easier for potential attackers to target your origin server directly.<\/p><p>However, there are times when some of your DNS records need to remain grey-clouded. For example:<\/p><ul><li>MX records must be orange-cloud because email isn\u2019t route via HTTP; otherwise, email routing won\u2019t work<\/li><li>When you have to host multiple services (for example, a website and email) on the same physical server<\/li><\/ul><p>To mitigate this risk, we recommend that you:<\/p><ul><li>Host your email service in a server (in-house or external) that is different from your site\u2019s origin server<\/li><li>Analyze the impact of hosting multiple services on the same origin server in cases when having grey-clouded DNS records can\u2019t be avoide<\/li><li>Orange-cloud all records that share the same origin IP address as your root domain and can be safely proxied through Cloudflare<\/li><\/ul>\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Warning about Exposing your Origin IP Address When you have grey-clouded DNS records, Cloudflare may warn you that your DNS records might reveal your origin server\u2019s IP address. This is most common with A, AAAA, CNAME, and MX DNS records. Overview When your DNS records are orange-clouded, Cloudflare speeds up and protects your site. A\u00a0dig &hellip;<\/p>\n<p class=\"read-more\"> <a class=\"\" href=\"https:\/\/www.mondoze.com\/guide\/kb\/warning-about-exposing-your-origin-ip-address-via-dns-records\"> <span class=\"screen-reader-text\">Warning about exposing your origin IP address<\/span> Read More \u00bb<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-gradient":""}}},"kbtopic":[53],"kbtag":[110],"mkb_version":[],"_links":{"self":[{"href":"https:\/\/www.mondoze.com\/guide\/wp-json\/wp\/v2\/kb\/2603"}],"collection":[{"href":"https:\/\/www.mondoze.com\/guide\/wp-json\/wp\/v2\/kb"}],"about":[{"href":"https:\/\/www.mondoze.com\/guide\/wp-json\/wp\/v2\/types\/kb"}],"author":[{"embeddable":true,"href":"https:\/\/www.mondoze.com\/guide\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.mondoze.com\/guide\/wp-json\/wp\/v2\/comments?post=2603"}],"version-history":[{"count":6,"href":"https:\/\/www.mondoze.com\/guide\/wp-json\/wp\/v2\/kb\/2603\/revisions"}],"predecessor-version":[{"id":18701,"href":"https:\/\/www.mondoze.com\/guide\/wp-json\/wp\/v2\/kb\/2603\/revisions\/18701"}],"wp:attachment":[{"href":"https:\/\/www.mondoze.com\/guide\/wp-json\/wp\/v2\/media?parent=2603"}],"wp:term":[{"taxonomy":"kbtopic","embeddable":true,"href":"https:\/\/www.mondoze.com\/guide\/wp-json\/wp\/v2\/kbtopic?post=2603"},{"taxonomy":"kbtag","embeddable":true,"href":"https:\/\/www.mondoze.com\/guide\/wp-json\/wp\/v2\/kbtag?post=2603"},{"taxonomy":"mkb_version","embeddable":true,"href":"https:\/\/www.mondoze.com\/guide\/wp-json\/wp\/v2\/mkb_version?post=2603"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}