# Troubleshooting a 429 (rate limit)

**URL:** https://meta.discourse.org/t/troubleshooting-a-429-rate-limit/81060
**Category:** Self-hosting
**Created:** [February 20, 2018, 6:20pm UTC](https://meta.discourse.org/t/troubleshooting-a-429-rate-limit/81060 "2018-02-20T18:20:41Z")
**Posts on this page:** 1
**Showing post:** 8

<div class="post-metadata">

### Author: ![mpalmer](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/mpalmer/32/45740_2.png) [@mpalmer](https://meta.discourse.org/u/mpalmer)
#### Post date: [February 21, 2018, 1:54am UTC](https://meta.discourse.org/t/troubleshooting-a-429-rate-limit/81060/8 "2018-02-21T01:54:46Z")

</div>

If nginx isn’t stripping untrusted XFF, and Discourse is seeing a request from 127.0.0.1 and saying “I trust that IP to give me legit XFF headers”, doesn’t that imply that source IP can be spoofed?

---

_[View the full topic](https://meta.discourse.org/t/troubleshooting-a-429-rate-limit/81060)._
