How to Prevent Direct Access to Your Website Origin Server

This article explains how to reduce the risk of Cloudflare bypass by preventing visitors from reaching the origin server directly.

Overview

A website is not fully protected by Cloudflare if the origin IP address can be used directly. Origin protection means the server accepts web traffic only through Cloudflare or through a private tunnel.

  1. Confirm that the website DNS records are proxied in Cloudflare.
  2. Remove unnecessary A, AAAA, or CNAME records that reveal the origin IP.
  3. Check old subdomains such as dev, staging, cp, panel, webmail, or direct that may point to the same server.
  4. On VPS or dedicated servers, allow ports 80 and 443 only from Cloudflare IP ranges.
  5. On managed hosting, check with Libyan Spider support before applying restrictions.
  6. Consider Authenticated Origin Pulls for stronger origin validation.
  7. Use Cloudflare Tunnel when the origin should not accept public inbound web traffic.

Common Mistakes to Avoid

  • Blocking all traffic before confirming Cloudflare IP ranges.
  • Forgetting IPv6 rules if the server has IPv6 enabled.
  • Leaving an unprotected subdomain pointing to the same web root.
  • Assuming WAF rules alone block direct IP access, direct traffic does not pass through Cloudflare.
Share this:
FacebookXWhatsAppTelegramLinkedInGmailCopy Link
Updated on June 24, 2026
Was this article helpful?

Related Articles

Need Support?
Can't find the answer you're looking for?
Contact Support