Skip to content
Fixedmark
Docs

Verify your egress IP

Before you allowlist anything, confirm which IP your traffic leaves from. Call the Fixedmark IP endpoint through your proxy and compare the result with the IP pair in your dashboard.

Docs preview: Fixedmark is not live yet. Endpoints are issued at launch, and these pages describe planned launch behavior. Anything marked planned may change. Join early access to get yours first.

Check with curl

https://fixedmark.com/api/ip returns the IP address that connected to it. Called through the proxy, that is your Fixedmark egress IP. Called directly, it is your app's own egress IP.

# Plain text: prints the IP the destination sees.
curl --proxy "$FIXEDMARK_PROXY_URL" https://fixedmark.com/api/ip

# JSON: {"ip":"203.0.113.10","version":4}
curl --proxy "$FIXEDMARK_PROXY_URL" -H "Accept: application/json" https://fixedmark.com/api/ip

Run the same command without --proxy to see the difference. You can also open the What's my IP tool in a browser.

Response format

Responses from the IP endpoint
RequestStatusBody
Default200The IP as plain text, then a newline
`Accept: application/json`200{"ip":"203.0.113.10","version":4}
IP could not be read503unknown, or {"ip":null,"version":null} as JSON

Responses send cache-control: no-store, so a shared cache never returns someone else's IP. CORS is open, so browser code can call it too.

See both IPs in the pair

One request shows one IP. Send several new connections to see both addresses. If the count shows only one IP after many requests, that is fine too. Allowlist both anyway, because failover can move traffic to the other address at any time.

# Each new connection can leave from either IP in the pair.
for i in $(seq 1 20); do
  curl -s --proxy "$FIXEDMARK_PROXY_URL" https://fixedmark.com/api/ip
done | sort | uniq -c

Check from code

Run the check with the same client setup your app uses. That proves the proxy settings in your code, not only in your shell.

import { fetch, ProxyAgent } from "undici";

const dispatcher = new ProxyAgent(process.env.FIXEDMARK_PROXY_URL);
const res = await fetch("https://fixedmark.com/api/ip", {
  dispatcher,
  headers: { accept: "application/json" },
});
console.log(await res.json()); // { ip: "...", version: 4 }

Check from the database

For database traffic, ask the server which address it sees. Run these over a connection made through SOCKS5 or bm tunnel. Managed databases behind their own proxies may show an internal address instead.

-- Postgres: the client address the server sees
SELECT inet_client_addr();

-- MySQL: host and port of the current connection
SELECT host FROM information_schema.processlist
WHERE id = CONNECTION_ID();

If the IP is wrong

  • You see your platform's IP. The request did not use the proxy. Check that the variable is set in this environment, and that NO_PROXY does not match the destination.
  • The request fails with 407. The credentials are wrong or not URL-encoded. See troubleshooting.
  • You see an IP that is not in your pair. Check the region in the proxy host name. Each region has its own pair.

Platform guides

Frequently asked questions

How do I check the IP a destination sees through a proxy?

Send a request through the proxy to an IP echo endpoint such as https://fixedmark.com/api/ip. It returns the address the request came from, which should be one of your Fixedmark IPs.

Why do I see two different IPs?

That is expected. Your plan includes an IP pair, and each new connection can leave from either one. Both should appear in your allowlists.

Does the IP endpoint log my requests?

The endpoint reads the request's source IP and returns it with caching disabled. See the privacy policy for what the Fixedmark website records.

Make it fixed.

Fixedmark is in early access. Join the list to get dedicated static IPs when your region opens.