You set up a reverse proxy. You added HTTPS. You feel safe. But your home IP address might be sitting in plain sight — printed on the front door of every service you host.

Here are four ways it leaks, and how to stop each one.

Mistake 1: Pointing DNS straight at your house

You bought a domain. You made an A record like home.example.com pointing to 73.42.x.x. That IP is your house. Anyone can run dig home.example.com and read it in one second.

Fix: Put a service in front. Cloudflare Tunnel or a cheap $5 VPS as a relay means your DNS points at their IP, not yours. Your home address never touches public DNS.

Mistake 2: Certificate transparency logs snitching

Every HTTPS certificate you request gets logged publicly and forever. Search crt.sh for your domain and you'll see every subdomain you ever secured — plex., photos., router. — a full map of your setup for any stranger.

Fix: Use a wildcard certificate (*.example.com) instead of one per subdomain. The log shows the wildcard, not your list of apps. Let's Encrypt supports this with DNS validation.

Mistake 3: App headers spilling your internals

Many apps send their real internal address in error pages, email links, or redirect headers. A misconfigured Nextcloud will happily email a password reset link containing 192.168.1.50 — or worse, your public IP.

Fix: Set the app's "trusted domain" or "external URL" to your public hostname, and tell your proxy to forward the right X-Forwarded-Host header. Then send yourself a test email and read the links carefully.

Mistake 4: WebRTC and media servers bypassing the proxy

This one bites Plex, Jellyfin, and video-call apps. They love direct peer-to-peer connections for speed — which means they hand out your real IP to connect faster, skipping your proxy entirely.

Fix: In Plex, disable "Remote Access" and reach it only through your tunnel or VPN. In Jellyfin, turn off the published server URL discovery. Speed drops slightly. Your address stays hidden.

The 60-second self-audit

Run these three checks tonight:

  1. dig +short yourdomain.com — is that your home IP? Bad.
  2. Visit crt.sh/?q=yourdomain.com — is your whole app list exposed? Fix with a wildcard.
  3. Trigger a password reset email from one app and inspect the link. Internal IP? Fix the external URL setting.

Most people stop at "the padlock is green" and assume nobody can find them. But an IP leak means someone can hammer your router directly, ignore your proxy's rate limits, and map your network before you notice.

Do this now: Run dig +short on every domain you host. If any answer is your home IP, put a tunnel or VPS relay in front before you do anything else this weekend.