Network

Cloudflare Resolver

The Cloudflare Resolver checks whether a domain's origin IP is exposed behind Cloudflare, using passive Certificate Transparency and DNS techniques. Access is gated behind a DNS TXT ownership challenge, so it only works on domains you can prove you control.

Last updated · Free, no signup

Loading interactive Cloudflare Resolver…

What does a Cloudflare origin-exposure check do?

A Cloudflare origin-exposure check looks for public DNS and Certificate Transparency clues that may reveal an origin address behind the proxy. Finding such an address can identify a configuration gap that allows traffic to bypass Cloudflare protections and reach the server directly.

Access requires a DNS TXT ownership challenge valid for 24 hours. The check passively cross-references crt.sh and resolves eight common non-proxied subdomains without port-scanning or connecting to the target. A clean result cannot prove that the origin is hidden through every historical record, third party, or undiscovered hostname.