Skip to content

Error 1000

Error 1000: DNS points to prohibited IP

This error indicates that a Cloudflare DNS record points to a prohibited IP, blocking access to the requested domain.

Common causes

Cloudflare halted the request for one of the following reasons:

  • An A record within your Cloudflare DNS app points to a Cloudflare IP address, or a Load Balancer Origin points to a proxied record.
  • Your Cloudflare DNS A or CNAME record references another reverse proxy (such as an nginx web server that uses the proxy_pass function) that then proxies the request to Cloudflare a second time.
  • The request X-Forwarded-For header is longer than 100 characters.
  • The request includes two X-Forwarded-For headers.
  • The request includes a CF-Connecting-IP header.
  • A Server Name Indication (SNI) issue or mismatch at the origin.
  • Your DNS record points to a SaaS provider that uses Cloudflare for SaaS with BYOIP (Bring Your Own IP). Because the provider's IP addresses are advertised through Cloudflare's network, requests resolve to Cloudflare infrastructure. If the provider has not configured a custom hostname for your domain, this error is returned.

Resolution

  • If an A record within your Cloudflare DNS app points to a Cloudflare IP address, update the IP address to your origin web server IP address. Reach out to your hosting provider if you need help obtaining the origin IP address.
  • There is a reverse-proxy at your origin that sends the request back through the Cloudflare proxy. Instead of using a reverse-proxy, contact your hosting provider or site administrator to configure an HTTP redirect at your origin.
  • If your domain points to a SaaS provider that uses Cloudflare, contact the SaaS provider to verify that a custom hostname is properly configured for your domain. The error originates from the provider's Cloudflare account, not yours.