← All guides

Caddy: Reconstruct original IP behind reverse proxy only if necessary

Requirements

Access to Caddyfile or server configuration and clarity as to whether the original IP is actually needed at the origin.

Caddy by default does not trust proxy headers to the client IP. If trusted_proxies is activated, Caddy can evaluate X-Forwarded-For or other client IP headers and also use the reconstructed address in logs. For a data-saving Origin, only activate this reconstruction if a specific function requires it.

Check after the change

Check browser memory and network requests and also view web server, proxy, application and provider logs separately. A single product setting does not automatically cover the entire processing chain.

Check origin and proxy together

With Reverse Proxy: Check forwarding of the visitor IP at the origin check whether the reconstructed client IP is actually needed and processed further.

Reset

If the reduced configuration affects a required function, restore only the relevant setting and then recheck data flow, storage, retention and third-party connections.

Related guides

Sources and verification

This guide is based on multiple current sources. Vendor documentation is not treated as proof that every concrete installation automatically follows the same privacy characteristics.

Important: IP processing is not IP storage

An IP address has to be processed to establish and deliver a network connection. Hosting providers, firewalls or DDoS protection may also process or retain it for a limited time for security purposes. No Logging distinguishes this security layer from unnecessary persistent visitor logging by the website, application and ordinary access logs.

↑