Fizzi Media
Back to all articles
What Works in Online Advertising Right Now

Why Reverse Proxies Degrade Meta Conversions API Match Quality

Published October 6, 2026 · Last reviewed October 6, 2026

Abstract technical architecture diagram illustrating server proxy nodes routing traffic to an API gateway

Deploying server-side tracking infrastructure is supposed to stabilize conversion tracking against browser restrictions, but misconfigured network architecture often does the exact opposite. When a company routes website traffic through a content delivery network or reverse proxy before hitting the tracking endpoint, default proxy behavior frequently strips or replaces client-level metadata. The tracking container receives the request, builds the event payload, and sends it to Meta, but the payload contains the proxy IP address instead of the customer IP address. For teams spending significant budget on Meta ads, this silent data distortion degrades Event Match Quality scores, weakens ad optimization, and inflates acquisition costs without triggering a single error notification.

The short answer

Meta Conversions API Gateway drops Event Match Quality when reverse proxies such as Cloudflare or AWS CloudFront overwrite the visitor client IP address with the proxy's own egress IP or strip incoming IP headers. When Meta receives the proxy IP instead of the visitor IP, it cannot correlate server-side events with user accounts, degrading match rates for top-of-funnel events. Resolving this requires configuring the proxy to pass original visitor IP addresses through headers like CF-Connecting-IP or X-Forwarded-For to the Gateway container.

How reverse proxies corrupt client IP parameters

When a visitor lands on a website, their browser initiates a network request carrying their public IP address and browser user-agent string. When an edge reverse proxy sits between the visitor and the application or tracking endpoint, the proxy terminates the client TCP connection and opens a separate connection to the origin server. Under default configurations on networks like Cloudflare or AWS CloudFront, the proxy replaces the source IP of the incoming packet with its own IP address.

Meta uses the Conversions API customer information parameters to pair incoming server events with user accounts. The client_ip_address parameter is one of the primary network identifiers used for matching, especially on anonymous page views and content views before a lead enters an email address or phone number. If the proxy forwards its own IP address, Meta receives thousands of events originating from a handful of data center IP addresses. Meta rejects or down-weights these data center IPs because they do not match residential or mobile network users.

According to the Meta Business Help Center documentation on Conversions API, server-side events require authentic customer data parameters to establish attribution. When every event payload carries an edge server IP instead of a real visitor IP, the Event Match Quality (EMQ) score on top-of-funnel events drops significantly, often falling below 4.0 out of 10.0.

The mechanics of header forwarding

To ensure the tracking container receives the actual visitor IP, the edge network must extract the source IP from the incoming request and inject it into a dedicated HTTP header before passing the request downstream. Standard industry implementations rely on headers documented by MDN Web Docs on X-Forwarded-For and provider-specific headers.

Proxy Platform Default Injected Client IP Header Gateway Configuration Requirement
Cloudflare CF-Connecting-IP Forward CF-Connecting-IP or rewrite to X-Forwarded-For
AWS CloudFront CloudFront-Viewer-Address or X-Forwarded-For Attach Managed Origin Request Policy (AllViewerExceptHostHeader)
NGINX Origin X-Real-IP or X-Forwarded-For Configure real_ip_module to trust upstream proxy CIDRs
Fastly Fastly-Client-IP Pass header to origin and map to X-Forwarded-For

When deploying Conversions API Gateway (CAPIG) on an AWS EC2 instance or Google Cloud instance behind a custom domain proxy, the host container environment must be configured to read the specified header rather than the direct connection remote address. If the container networking stack inspects REMOTE_ADDR instead of the forwarded header, the proxy IP will still be transmitted to Meta.

For teams comparing the relative weight of identifiers, our guide on Meta Conversions API EMQ cookie IDs versus hashed data breaks down how IP addresses combine with _fbp and _fbc parameters during the identity resolution process.

Step-by-step remediation for Cloudflare and CloudFront

Fixing IP stripping requires explicit rules at the proxy layer and verification inside the tracking environment. Below are the operational configurations for two common reverse proxy setups.

Cloudflare configuration

Cloudflare automatically includes the CF-Connecting-IP header on requests routed through its network as detailed in the Cloudflare HTTP request headers documentation. However, if the CAPIG endpoint expects standard HTTP headers or sits behind an intermediate load balancer, that header must be mapped cleanly.

  1. In Cloudflare, navigate to Rules > Transform Rules > Modify Request Header.
  2. Create a rule matching the path hostname of the CAPIG instance (for example, capig.yourdomain.com).
  3. Set the action to dynamic rewrite: Set header X-Forwarded-For to expression http.request.headers["cf-connecting-ip"][0].
  4. Ensure SSL/TLS encryption mode is set to Full (Strict) to prevent protocol downgrade between Cloudflare and the Gateway origin.

AWS CloudFront configuration

When routing traffic through AWS CloudFront to an Application Load Balancer (ALB) hosting CAPIG, follow the guidelines in the AWS CloudFront viewer headers guide.

  1. Open the CloudFront console and select the distribution handling the tracking domain.
  2. Navigate to Behaviors and edit the cache behavior covering the Gateway path.
  3. Under Origin Request Policy, select the AWS managed policy Managed-AllViewerExceptHostHeader or create a custom policy that explicitly forwards CloudFront-Viewer-Address and X-Forwarded-For.
  4. Save changes and invalidate the cache behavior to ensure all incoming POST and GET requests pass client headers unmodified.
# Example NGINX origin snippet for servers upstream of Cloudflare
# Place inside the server or http block handling the CAPIG container

set_real_ip_from 173.245.48.0/20;
set_real_ip_from 103.21.244.0/22;
set_real_ip_from 103.22.200.0/22;
set_real_ip_from 103.31.4.0/22;
set_real_ip_from 141.101.64.0/18;
set_real_ip_from 108.162.192.0/18;
set_real_ip_from 190.93.240.0/20;
set_real_ip_from 188.114.96.0/20;
set_real_ip_from 197.234.240.0/22;
set_real_ip_from 198.41.128.0/17;
set_real_ip_from 162.158.0.0/15;
set_real_ip_from 104.16.0.0/13;
set_real_ip_from 104.24.0.0/14;
set_real_ip_from 172.64.0.0/13;
set_real_ip_from 131.0.72.0/22;

real_ip_header CF-Connecting-IP;
real_ip_recursive on;

Where this fix breaks and who should avoid manual proxying

This remediation applies specifically to engineering teams and technical marketers managing self-hosted CAPIG or server-side Google Tag Manager instances behind custom CDNs. If a company uses a direct SaaS integration via Shopify, native CRM webhooks, or fully managed partner integrations that do not route traffic through a custom DNS proxy, manual header rewriting is unnecessary.

Header rewriting will fail if the origin web server does not trust the proxy IP addresses. If real_ip_recursive or trusted proxy ranges are not configured in NGINX or Apache, the server will either select the nearest proxy hop instead of the client IP or reject the header entirely. Additionally, if an upstream web application firewall (WAF) sanitizes incoming headers, it may drop custom headers before the Gateway container processes the event.

What this means if you're running spend

When client IP forwarding breaks, the ad account suffers in ways that standard dashboard metrics do not immediately explain. Meta ad delivery algorithms rely on fast, high-confidence feedback loops. When top-of-funnel events like PageView, ViewContent, and AddToCart lose IP attribution, Meta cannot accurately match those browsing actions back to platform profiles. Consequently, delivery models lose signal on which user profiles exhibit high purchase intent.

Operationally, this creates three downstream consequences:

  1. Retargeting and custom audience degradation: Custom audiences built from web traffic shrink because Meta fails to match up to 30 percent of non-logged-in visitors.
  2. Algorithmic misallocation: Advantage+ campaigns drift toward lower-intent audiences because conversion probability models lack the network-layer data required for accurate scoring.
  3. Discrepancies between CRM data and Meta Ads Manager: Conversion events recorded in your sales pipeline fail to reconcile with reported ad conversions, causing leadership to misjudge campaign profitability.

Fixing header forwarding restores the data integrity needed for our team to scale accounts through our main service and eliminates attribution lag across your growth stack.

FAQ

How can an operator verify if the Meta Conversions API Gateway is receiving the real client IP?

Check the Event Match Quality score in Meta Events Manager for top-of-funnel events such as PageView. Additionally, inspect the payload logs inside the Conversions API Gateway dashboard to verify that the client_ip_address field contains distinct residential and commercial IP ranges rather than repeated data center IP addresses.

Does passing the client IP address violate GDPR or CCPA privacy regulations?

Passing client IP addresses to Meta via Conversions API requires proper disclosure in your privacy policy and adherence to local consent frameworks. When users decline tracking via cookie consent banners, your tracking infrastructure must prevent the transmission of network parameters in compliance with platform policies.

Why does Event Match Quality drop even when email addresses are sent?

Email matching operates on hashed customer data, which provides high match confidence for post-opt-in events like purchases. However, top-of-funnel events lack email parameters, making network parameters like client IP and browser user agent the primary signals Meta uses to match anonymous visitors.

What happens if multiple reverse proxies sit in front of the tracking server?

If traffic routes through multiple proxies (such as Cloudflare to an AWS ALB to an EC2 instance), each hop appends an IP address to the X-Forwarded-For chain. Origin web servers must be configured to parse the entire chain and select the first non-trusted public IP address.

How much of this applies to your operation?

The performance impact of reverse proxy IP stripping depends on your specific infrastructure stack, event volume, and proxy architecture. If your team manages mid-market to enterprise media spend and notices falling Event Match Quality scores despite server-side tracking, we can audit your event pipelines and optimize your data architecture. You can apply to work with Fizzi Media to review your attribution setup and ad operations.

Last reviewed October 6, 2026. Sources linked inline.

Speak directly with Jason, our Managing Director. No sales reps.

More from the blog