Cloudflare Health Checks: IPs & Locations
Verified Cloudflare Health Checks IP Addresses. Copy-Paste Firewall-Setups.
Every official Cloudflare Health Checks monitoring IP—verified in real-time against the canonical source, featuring ready-to-use firewall templates. Stop false downtime alerts caused by blocked checking nodes on your infrastructure.
Made and Hosted in the
European Union
GDPR-Compliant Hosting
in Germany
GEO-Redundant Replica
across the EU
Three-Step Activation & Frictionless Firewall Alignment
Bring your perimeter security rules up to date in three simple steps. Our production-ready configuration templates for common server architectures eliminate fragmented routing filters and costly check flapping.
15 IPv4 and 7 IPv6 ranges — one click below copies everything as a plain list or as ready-to-paste UFW, nginx, or Apache config.
Add every address to your allow list — UFW, nginx, Apache, or a Cloudflare/WAF skip rule. Partial lists cause flapping checks and false alerts.
Cloudflare Health Checks updates its list occasionally. This page was verified on 2026-06-12 against the official source — re-check after unexplained alerts or automate the sync.
Official Cloudflare Health Checks Monitoring IPs
Cloudflare publishes its ranges at cloudflare.com/ips (machine-readable at /ips-v4 and /ips-v6).
Cloudflare Health Checks (and load-balancer health monitoring) probe your origin from Cloudflare's edge network. The egress addresses are Cloudflare's published IP ranges — the same canonical lists you should already allow on your origin if it sits behind Cloudflare.
If your origin firewall only allows part of these ranges, health checks flap depending on which edge location probes. Whitelist the complete lists below.
This list contains 15 IPv4 and 7 IPv6 ranges, verified against the official source on 2026-06-12.
IPv4 addresses 15
- 173.245.48.0/20
- 103.21.244.0/22
- 103.22.200.0/22
- 103.31.4.0/22
- 141.101.64.0/18
- 108.162.192.0/18
- 190.93.240.0/20
- 188.114.96.0/20
- 197.234.240.0/22
- 198.41.128.0/17
- 162.158.0.0/15
- 104.16.0.0/13
- 104.24.0.0/14
- 172.64.0.0/13
- 131.0.72.0/22
IPv6 addresses 7
- 2400:cb00::/32
- 2606:4700::/32
- 2803:f800::/32
- 2405:b500::/32
- 2405:8100::/32
- 2a06:98c0::/29
- 2c0f:f248::/32
Last verified: 2026-06-12
Official source: https://www.cloudflare.com/ips/
Whitelisting Cloudflare Health Checks-Monitoring IPs
Pick a format — the block below contains the complete config for every address in the list above. The plain list is also available as a .txt download.
ufw allow from 173.245.48.0/20 ufw allow from 103.21.244.0/22 ufw allow from 103.22.200.0/22 ufw allow from 103.31.4.0/22 ufw allow from 141.101.64.0/18 ufw allow from 108.162.192.0/18 ufw allow from 190.93.240.0/20 ufw allow from 188.114.96.0/20 ufw allow from 197.234.240.0/22 ufw allow from 198.41.128.0/17 ufw allow from 162.158.0.0/15 ufw allow from 104.16.0.0/13 ufw allow from 104.24.0.0/14 ufw allow from 172.64.0.0/13 ufw allow from 131.0.72.0/22 ufw allow from 2400:cb00::/32 ufw allow from 2606:4700::/32 ufw allow from 2803:f800::/32 ufw allow from 2405:b500::/32 ufw allow from 2405:8100::/32 ufw allow from 2a06:98c0::/29 ufw allow from 2c0f:f248::/32
Cloudflare / WAF: create an IP Access Rule (or custom WAF skip rule) with action Allow for the addresses above, so bot fight mode and managed challenges never block probe traffic.
Whitelisting only exempts these addresses from blocking and rate-limiting rules — it grants no access beyond what your site already serves publicly.
Frequently Asked Questions
No — Cloudflare publishes one canonical set of ranges for its edge network, and health checks originate from it. Origins behind Cloudflare should allow the full set anyway, which covers health checks automatically.
Rarely, and cloudflare.com/ips is the canonical source. The plain-text endpoints /ips-v4 and /ips-v6 are made for firewall automation.
Yes — the published set includes IPv6 ranges. Whitelist both lists if your origin is dual-stacked.
Both — wherever requests can be blocked. If your site sits behind a CDN or WAF (Cloudflare, AWS WAF, Akamai…), add an allow/skip rule there so probes are never challenged; if your origin firewall also filters traffic, whitelist them there too. A single missed layer is enough to cause false alerts.
Most providers expose a machine-readable source (linked above). Fetch it on a schedule — a small cron job that pulls the list and updates your firewall ruleset — instead of hardcoding addresses by hand. This page is re-verified against the official source regularly, but automation on your side is the most reliable option.
No. Allow-listing only exempts known monitoring addresses from blocking and rate-limiting rules — it grants no access beyond what your site already serves publicly, and authentication, authorization, and TLS are unchanged. You are simply telling your firewall "these are not attackers".
A blocklist keeps known-bad addresses out; an allow/whitelist makes sure known-good addresses — here, the monitoring probes — never end up caught in a block or rate-limit rule. The two coexist: you keep blocking attackers while explicitly exempting the probes.
The IP addresses on this page belong to Cloudflare Health Checks and are published by Cloudflare Health Checks for whitelisting purposes. List verified on 2026-06-12 against the official source. Always cross-check with the official documentation before locking down production firewalls. All product names and trademarks are the property of their respective owners; Uptimeify is not affiliated with Cloudflare Health Checks. Uptimeify's own worker IPs are published at /ips.txt; a feature comparison is on our comparison page.
Monitoring Without IP Guesswork.
Protect your clients' digital assets and lock down your webserver routing. Leverage our verified network catalogs for clean whitelist setups, or migrate directly to the rock-solid, EU-only architecture of Uptimeify.