Matomo: Remove original IP before the tracker
Matomo's normal IP anonymization masks the address after the tracking request reaches Matomo. For stricter data economy, Matomo documents a tracker proxy that can remove the original visitor IP before Matomo.
Difference to normal IP masking
With normal anonymization, the full IP first reaches the Matomo server and is then masked in the main memory. With the appropriate tracker proxy configuration, Matomo does not receive the original visitor IP for standard tracking requests.
Consciously accept consequences
Without the original IP, location determination, IP-based exclusions and some spam/bot checks work worse or not at all. Cookieless recognition and key figures such as unique visitors can also become less accurate.
Continue to check web servers separately
The tracker proxy does not automatically solve the logging of the upstream web server or proxy level. Continue to ensure that the original visitor IP is not stored unnecessarily and permanently.
Basics of visitor recognition
For classification purposes, Cookieless is not automatically tracking-free and Use unique visitors without recognition . What is important is not just the presence of cookies, but also whether requests are merged via sessions, hashes, local storage or other features.
Requirements
Access to reverse proxy and Matomo tracker configuration as well as a test option for incoming headers.
Dismantling
If Matomo functions technically require the original IP, only restore the transfer in a targeted manner and check IP masking, retention and web server logs again.
Related guides
Sources and verification
This guide is based on multiple current sources. Vendor documentation is not treated as proof that every concrete installation automatically follows the same privacy characteristics.
Important: IP processing is not IP storage
An IP address has to be processed to establish and deliver a network connection. Hosting providers, firewalls or DDoS protection may also process or retain it for a limited time for security purposes. No Logging distinguishes this security layer from unnecessary persistent visitor logging by the website, application and ordinary access logs.