Hostinger CDN: Visitor IP addresses in logs and analytics

Find the real visitor IP address behind Hostinger CDN in server logs, plugins, and analytics.

Updated 2 weeks ago

Requests reach your hosting server from the Content Delivery Network (CDN) servers with Hostinger CDN enabled, so raw server logs and some plugins show CDN addresses instead of visitor addresses. The real visitor IP address is passed to your website in the X-Forwarded-For and X-Real-IP request headers. Tools that read these headers show the correct visitor addresses; tools that only read the connecting address show the CDN.

Where the visitor IP address travels

Every request forwarded by Hostinger CDN to your website carries three headers.

Header

Value

X-Forwarded-For

The addresses the request passed through. Hostinger CDN appends the address that connected to it as the last entry; earlier entries come from the visitor’s own client or from a proxy in front of the CDN and cannot be trusted on their own.

X-Real-IP

The address that connected to Hostinger CDN — the visitor, or another proxy service if one sits in front of the CDN.

X-Forwarded-Proto

https or http, the protocol the visitor used.

The connecting address that appears in raw access logs is the CDN server that fetched the page.

Websites and plugins on Hostinger web hosting

Applications on Hostinger web hosting generally receive the visitor’s address as the client address (REMOTE_ADDR in PHP), because the hosting server trusts the Hostinger CDN servers and applies the forwarded address before your code runs. WordPress core, WooCommerce, and most plugins therefore keep working without changes.

Plugins that read a specific header can still show CDN addresses. Check their proxy or “how to get visitor IPs” setting and select the X-Real-IP option, or the X-Forwarded-For option where the plugin uses the last entry — the plugin’s own documentation names the exact setting. Custom code should read HTTP_X_REAL_IP, or the last entry of HTTP_X_FORWARDED_FOR — both hold the address that connected to Hostinger CDN. The first entry of X-Forwarded-For is the visitor only when no other proxy sits in front of the CDN and the client sent no such header itself; any client can send one, so never trust it on its own.

NOTES

  • Client-side analytics, such as Google Analytics, run in the visitor’s browser and are not affected by the CDN — they always see the real visitor.
  • Do not rely on the CF-Connecting-IP header. Hostinger CDN removes it from incoming requests because any client could send it.

Another proxy in front of Hostinger CDN

X-Real-IP and the last entry of X-Forwarded-For contain the Cloudflare address when Cloudflare or a similar service proxies the website before Hostinger CDN. The visitor’s address is the earlier X-Forwarded-For entry that Cloudflare added, which is trustworthy only when the request really came from a Cloudflare address. Per-visitor limits on the hosting server also see the whole audience arriving from a few proxy addresses (see Hostinger CDN: 429 Too Many Requests errors). Keep one service active, as described in Hostinger CDN vs Cloudflare.

Blocked countries still appear in analytics

Traffic from a blocked country still appears in the CDN Analytics tab because the CDN counts the request before answering it with a 403 response — the request never reaches your website. Requests from a blocked country in your server’s own logs have three possible causes: the block was added after those requests, the visitor’s address is geolocated to another country by the IP database, or the request bypassed the CDN by connecting directly to your hosting server’s address. Country rules apply only to traffic that flows through Hostinger CDN.

When to contact Hostinger support about visitor IP addresses

Contact Hostinger support if your application still records CDN addresses after selecting the X-Forwarded-For option, and include the domain name, the plugin or application name, and an example log line with its timestamp. Include the x-hcdn-request-id value of a matching response when available.

With logs and plugins reading X-Forwarded-For, your website keeps accurate visitor addresses while Hostinger CDN handles the traffic.