# Mailgun leaking server's real IP behind Cloudflare

**URL:** https://meta.discourse.org/t/mailgun-leaking-servers-real-ip-behind-cloudflare/59128
**Category:** Support
**Created:** [March 15, 2017, 3:01am UTC](https://meta.discourse.org/t/mailgun-leaking-servers-real-ip-behind-cloudflare/59128 "2017-03-15T03:01:37Z")
**Posts on this page:** 1
**Showing post:** 16

<div class="post-metadata">

### Author: ![DNSTARS](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/dnstars/32/100957_2.png) [@DNSTARS](https://meta.discourse.org/u/DNSTARS)
#### Post date: [May 16, 2019, 12:30pm UTC](https://meta.discourse.org/t/mailgun-leaking-servers-real-ip-behind-cloudflare/59128/16 "2019-05-16T12:30:43Z")

</div>

I don’t know how feasible it is but if during installation there was a means to specificy those kinds of requests to a different gateway or something that would be cool. Also, before discourse error handles this it can be used by bad actors to grab someone’s IP address in a PM, a setting to not list the link until it had been processed could prevent that maybe?

Last I looked the latter problem was “turn off embed content globally or live with it”.

> [@What are some of the hardest moments you had as a moderator?](https://meta.discourse.org/t/what-are-some-of-the-hardest-moments-you-had-as-a-moderator/117677/3):
>
> More on topic — I’ve been lightly doxxed (had my home address posted) in the past when someone didn’t like what I was saying online. Nothing came of it, but it’s not pleasant

It wouldn’t stop someone clicking on a random link though that wasn’t embedded so I dunno.

---

_[View the full topic](https://meta.discourse.org/t/mailgun-leaking-servers-real-ip-behind-cloudflare/59128)._
