Guides ·

Cloudflare WARP and AI sites: what Claude and ChatGPT see when WARP is on

WARP is the encrypted tunnel in Cloudflare’s 1.1.1.1 app. When it’s on, your device’s traffic enters Cloudflare’s network first, and websites see a Cloudflare IP instead of yours. That exit is shared by many users and stays near your real location, and because claude.ai and chatgpt.com sit behind Cloudflare, Cloudflare knows directly that the request came through WARP. If you use Claude or ChatGPT, turn WARP off, or make sure those two sites don’t go through it, so they see the exit you actually chose.

At a glance: what WARP changesWith WARP off, sites see the exit of the line you chose and the trace shows warp=off. With WARP on, traffic enters Cloudflare first, sites see a shared Cloudflare exit located near you, and the traces on claude.ai and chatgpt.com show warp=on. At a glance: what WARP changes WARP off warp=off Browser Your line Your exit Sites see the exit you chose WARP on (traffic mode) warp=on Browser WARP tunnel Shared exit A Cloudflare IP many people share, near you claude.ai and chatgpt.com can tell DNS-only mode (formerly 1.1.1.1) keeps your exit.
With WARP on, your exit becomes a shared Cloudflare IP in the same country; both AI sites sit behind Cloudflare, and their diagnostic page says warp=on.

What WARP does

According to Cloudflare’s WARP modes page, WARP encrypts your device’s traffic and sends it into Cloudflare’s global network. If the site you’re visiting is a Cloudflare customer, the content comes straight back from Cloudflare; if not, Cloudflare’s network fetches it. On iOS and Android the app installs as a VPN profile (see the iOS setup guide).

Your exit IP changes. Cloudflare’s WARP FAQ says 1.1.1.1 + WARP replaces your original IP with a Cloudflare IP that represents your approximate location, whether or not the site is on Cloudflare’s network.

A shared exit, in the same country

A 2022 Cloudflare blog post explains how exits are assigned: Cloudflare estimated how many users it has per city, divided them among a set of egress IPs, and submitted those IPs’ locations to geolocation database providers. So WARP users in the same city share a pool of exits, and anyone looking up the IP sees Cloudflare’s network in a location near you.

The modes page adds a caution: WARP doesn’t provide anonymity, isn’t designed to stop the servers you talk to from identifying you, and doesn’t let you appear to be in a different country. WARP won’t fix a region problem. Turn it on in Hong Kong and, by design, your exit still shows up near Hong Kong, which isn’t on ChatGPT’s or Claude’s list of supported regions. OpenAI’s supported countries page says access from outside the listed countries may get an account blocked or suspended.

How Claude and ChatGPT can tell

Cloudflare adds a /cdn-cgi/ path to every domain it proxies, and /cdn-cgi/trace is a troubleshooting page under it (Cloudflare docs). It lists fields about the current request, such as the IP and location (loc), plus a warp= line. Cloudflare’s Linux setup guide uses it to confirm the connection: fetch https://www.cloudflare.com/cdn-cgi/trace and check for warp=on.

We checked on 1 October 2026: claude.ai and chatgpt.com both answer with server: cloudflare, and both serve a /cdn-cgi/trace with a warp= line. The Cloudflare layer in front of these sites knows whether a request arrived through WARP, and the sites’ own pages can read that same page. gemini.google.com isn’t behind Cloudflare and has no such page, but Google still sees a Cloudflare IP as your exit.

Whether the platforms treat WARP traffic differently isn’t public. What is public: in Claude’s help center, the first troubleshooting step for login errors is to make sure you’re not using a VPN.

WARP modes

The WARP client has several modes, and the difference is which traffic enters the tunnel. Names follow Cloudflare’s current modes page, with the old names in brackets:

  • DNS only (formerly “1.1.1.1”): only DNS queries go to the 1.1.1.1 resolver, encrypted; the rest of your traffic isn’t tunneled. Sites see the same exit as before.
  • Traffic and DNS (formerly “1.1.1.1 with WARP”): all device traffic goes through WARP, with DNS inside the tunnel or encrypted. Your exit becomes a Cloudflare IP.
  • Traffic only: all traffic goes through WARP, while DNS stays with the operating system. Your exit changes too.
  • Local proxy (desktop only for now): WARP runs an HTTPS or SOCKS5 proxy on your machine, and only apps you point at it use WARP; everything else uses your regular connection.

The macOS and Windows guides boil this down to two modes: WARP (the default), which encrypts and sends all traffic, and 1.1.1.1, which only encrypts DNS to the 1.1.1.1 resolver.

WARP modes: does your exit change?DNS only encrypts DNS queries and keeps your exit. Traffic and DNS, and Traffic only, send all traffic through WARP, so sites see a Cloudflare exit. Local proxy, desktop only, sends only the apps configured to use it through WARP. WARP modes: does your exit change? DNS only Same exit Only DNS, encrypted, goes to 1.1.1.1 Formerly “1.1.1.1” Traffic and DNS New exit All traffic and DNS go through WARP Formerly “1.1.1.1 with WARP”; the default Traffic only New exit All traffic via WARP; the OS handles DNS Sites see a Cloudflare exit Local proxy Per app Only apps set to use the proxy go via WARP Desktop only for now; HTTPS or SOCKS5 Desktop guides list just two: WARP and 1.1.1.1.
Whether WARP affects AI sites comes down to one thing: does your browser’s page traffic go into the WARP tunnel?

What IP Judge shows

The home page and the Claude and ChatGPT pages read the /cdn-cgi/trace of claude.ai and chatgpt.com directly from your browser:

  • Under “Browser and connection checks”, the rows “IP used for Claude” and “IP used for ChatGPT” show the IP and location from each trace. With WARP on, that’s a Cloudflare exit; its IP type is looked up as usual, and the Cloudflare addresses we tested are classed as datacenter IPs.
  • If either trace has a warp value other than off, “How to fix” gets an amber item, “Cloudflare WARP is on”, naming the site.
  • Scores: in the Claude score, “Exit type” is capped at 6 of 30; in the Muse sign-up score, at 5 of 40. These are IP Judge’s own weights based on common risk signals, not published platform rules — see the Method page.
  • Gemini has no readable diagnostic page, so the check only tests whether it’s reachable and doesn’t judge WARP there.

What to do

  1. Turn WARP off while using Claude or ChatGPT, or switch the app to DNS only, then re-run the check on the home page. The “Cloudflare WARP is on” item should disappear and both rows should show your own exit again.
  2. To keep WARP off only on certain networks, the macOS and Windows apps have a preference to disable WARP on specific Wi-Fi or wired networks.
  3. If WARP runs alongside another proxy app, look at those two rows. A Cloudflare exit near you means the sites’ traffic went into WARP; the exit you chose means it didn’t.
  4. If you never installed WARP but still see the warning, the field’s meaning suggests (our inference) that the line you use hands your traffic to WARP somewhere along the way, so platforms see a shared Cloudflare exit too. Check with whoever runs that line.
  5. Cloudflare’s FAQ says WARP doesn’t proxy WebRTC: sites with microphone or camera access bypass WARP and can see your original IP. See WebRTC leaks.

For which exit each platform actually sees, read Which IP do ChatGPT and Claude actually see? For how datacenter and residential IPs differ, see Residential vs datacenter vs ISP IPs.

FAQ

I only use 1.1.1.1 for DNS. Will the check say WARP is on?

No. DNS-only mode doesn’t tunnel page traffic, so your exit stays the same and the trace shows warp=off. Where your DNS goes is a separate check; see DNS leaks.

Can WARP let me use Claude or ChatGPT from an unsupported region?

No. Cloudflare states that WARP doesn’t let you appear to be in a different country; the exit represents your approximate location.

Will WARP definitely trigger verification or a ban?

Nothing public says so. Two things are certain: the Cloudflare layer in front of these sites knows the request came through WARP, and the exit is a Cloudflare address shared by many people. IP Judge treats that as a signal worth fixing, not a verdict.

With WARP on, can WebRTC still expose my real IP?

It can. Per Cloudflare, WARP doesn’t proxy WebRTC. The check’s WebRTC row compares every IP it finds against your exits, so go by that row.

Which kind of IP do you have?

Check my IP for free