Origin server exposed

Origin server exposed: what it means, why it may matter, and how to remediate with external verification using ExposureGrid.

The problem

Origin server exposed: Origin/CDN/WAF topology mistakes can let traffic bypass intended protections or reveal infrastructure.

Why it matters

Direct-origin access can weaken DDoS/WAF value and leak operational context - severity depends on hardening at origin.

How to check

Map DNS to edges vs origin, verify firewall allowlists, test direct-origin reachability hypothesis carefully.

How to fix

Firewall origin to edge IP ranges, avoid leaking origin via DNS/certs, validate coverage on apex/www/subs.

  1. Identify owners for the affected component (app, edge, DNS, or mail).
  2. Make a minimal change and validate in staging or a canary route.
  3. Deploy with monitoring and rollback readiness.
  4. Re-run ExposureGrid to confirm the external signal improved.

Run a scan to verify this fix on your domain

Use the same public scanner as the homepage — results honor your plan tier.

Scan your domain

What ExposureGrid checks

ExposureGrid compares edge vs origin signals where configured for your plan.

FAQ

Why does "Origin server exposed" appear in ExposureGrid?
Scanners observe externally visible signals. A finding means our rules matched - validate severity and applicability in your environment.
Could this be a false positive?
Yes, depending on context and coverage limits. Especially for heuristic, partial, or pattern-based checks, corroborate with manual review.
What should I do after changing configuration?
Re-run a scan to confirm the external signal changed, then enable monitoring where your plan supports it.

ExposureGrid continuously monitors these issues and alerts you before they become exploitable.

Run a private scan

Compare plans