A reverse proxy is a server that stands in front of one or more web servers, accepts requests addressed to them and passes those requests on, returning the answers as if it had produced them itself. The arrangement exists because putting a single, controllable layer between the public internet and the machines that run a website makes it possible to cache pages, absorb attacks, spread load, terminate encryption and inspect every request before anything reaches the origin.
The Internet Engineering Task Force (IETF) gives the formal version in RFC 9110, published in June 2022. It calls the device a "gateway (a.k.a. reverse proxy)" and defines it as "an intermediary that acts as an origin server for the outbound connection" but "translates received requests and forwards them inbound to another server or servers". To the outside world, the proxy is the website.
How a reverse proxy works
The mechanics start with the Domain Name System (DNS). The domain's DNS records point to the proxy's IP address rather than the origin server, so a browser opens its connection, and usually its encrypted TLS session, with the proxy.
The proxy then decides what to do with the request. If it holds a valid stored copy, it answers immediately, which is called a cache hit. If not, it opens a separate connection to the origin, fetches the response and relays it, possibly keeping a copy for the next visitor. It can also rewrite headers, reject attack traffic, challenge suspected bots or route a path such as /metrics to a different back-end service.
The origin now sees the proxy's IP address rather than the visitor's, so proxies add headers preserving the original details. The non-standard X-Forwarded-For header became the common way to do this. RFC 7239, published in June 2014 by Andreas Petersson and Martin Nilsson of Opera Software, introduced a standard Forwarded header, noting that "the use of a reverse proxy also hides information". In marketing infrastructure the same problem surfaces with geography: Google's tag gateway requires headers such as X-Forwarded-Country, because the proxy otherwise hides the visitor's location from Google.
Common software includes nginx, HAProxy, Varnish and Envoy, but the dominant commercial operators are content delivery networks. According to W3Techs, as of October 8, 2026, 31.2% of all websites used a reverse proxy service it monitors. Cloudflare alone sat in front of 26.7% of sites, a share of 85.4% among proxy users, with Amazon CloudFront at 1.7%, Fastly at 0.9% and Akamai at 0.6%. Those figures count websites, not traffic.
Origin and evolution
In April 1995 Mike Schwartz announced on an IETF working group mailing list that the Harvest object cache, built at the University of Colorado Boulder, was available as an "httpd accelerator", a cache placed in front of a web server rather than in front of users. Duane Wessels forked the non-commercial Harvest code and released it as Squid 1.0.0 in July 1996, and its accelerator mode became one of the first widely deployed reverse proxies.
The commercial version arrived quickly. Tom Leighton and Danny Lewin incorporated Akamai on August 20, 1998, and Akamai delivered its first live traffic in February 1999, a pixel on the Disney site. A content delivery network (CDN) is, in effect, a reverse proxy replicated across hundreds of locations.
Igor Sysoev began writing nginx in 2002 to handle tens of thousands of simultaneous connections for the Russian portal Rambler, and released it publicly on October 4, 2004. F5 bought Nginx, Inc. on March 11, 2019, for $670 million.
Cloudflare launched at TechCrunch Disrupt on September 27, 2010, selling a reverse proxy with security and performance features to sites of any size. Cloudflare announced Workers on September 29, 2017, letting customers run code inside the proxy.
Marketing technology adopted the pattern next. Google made server-side tagging available to all Tag Manager accounts on August 13, 2020, according to a post by Ben Fisher, a product manager on the product. Apple responded within months. A WebKit post by John Wilander dated November 12, 2020 said Safari 14 "detects third-party CNAME cloaking requests and caps the expiry of any cookies set in the HTTP response to 7 days". Google then announced a first-party mode beta for its tags on October 9, 2024, with Cloudflare as the automated integration, and renamed it Google tag gateway for advertisers at general availability on May 8, 2025.
Why it matters for marketers
For advertisers, the reverse proxy is now the plumbing behind first-party measurement. In a server-side Google Tag Manager setup, a tagging server on a subdomain such as sgtm.example.com receives browser events and forwards them to GA4, Google Ads and Meta's Conversions API. Google tag gateway goes a step further by placing the proxy on the advertiser's own domain at the CDN edge. Google cited an 11% increase in observed signals at launch; Adswerve reported 9% to 18% more measured conversions among its clients. Both figures come from interested parties, and Google's measure tag script loads rather than revenue.
Meta's Conversions API Gateway follows the same logic. According to Meta's developer documentation, advertisers provision middleware in their own AWS or Google Cloud account, point a DNS endpoint at it, and configure the Meta Pixel to send each event both to Meta and to the gateway, which converts browser events into server events with a shared event_id for deduplication. Meta later added a free one-click server connection in April 2026 that needs no advertiser infrastructure.
Cookie lifetimes add to the attraction. Cookies set by a server response on the first-party domain are not subject to Safari's seven-day cap on JavaScript-written cookies.
The second major use is bot control. Every request passes through the proxy, so CDNs became the natural place to block AI crawlers. Cloudflare said on July 1, 2025 that it would ask every new domain whether to allow AI crawlers, blocking them by default, and launched Pay Per Crawl in private beta the same day using the HTTP 402 Payment Required status. Its dashboards put crawl-to-referral ratios between 118 and nearly 50,000 in 2025 data. Verification standards such as Web Bot Auth, in which bots sign requests cryptographically, are usually checked at the proxy.
Limitations and disputes
The most contested marketing use is ad blocker circumvention. Routing tracking through a site's own domain defeats filter rules written against third-party hostnames, which is partly the point. Simo Ahava of Simmer called using first-party setups to get around ad blockers "ethically questionable" in July 2024. Francois de Broissia, in a later discussion, used the same words and added "ultimately futile". The futility argument has evidence behind it. AdGuard's first-party tracking list holds more than 3,400 rules, including 83 for gtm. and 42 for sgtm. subdomains, and Mariusz Brucki of TAGGRS estimated the resulting data gap at 5% to 40% depending on audience.
Browsers have escalated too. According to analytics consultancy Louder, Safari 16.4 extended the seven-day cap to server-set cookies when the setting server's IP address does not match the first half of the website's own address. A review of WebKit code for Safari 27 found blocking by destination IP address, which first-party proxying does not evade.
Routing does not alter law. The Verwaltungsgericht Hannover ruled on March 19, 2025 that Google Tag Manager may not run before explicit consent, regardless of which domain serves it.
Concentration is the structural criticism. When one company fronts over a quarter of websites, its failures spread widely. On November 18, 2025, a database permissions change doubled the size of a Cloudflare Bot Management file and crashed its proxy software, disrupting core traffic for more than three hours. Fastly's June 8, 2021 outage left 85% of its network returning errors. Legal exposure follows: Italy's AGCOM fined Cloudflare EUR 14,247,698.56 in January 2026 after a Rome court found its reverse proxy masked the hosting providers of pirate sites.
Not the same as
A forward proxy works for the client, not the server. RFC 9110 describes it as a "message-forwarding agent that is chosen by the client", such as a corporate web filter or a VPN-style service. A reverse proxy is chosen by the site owner and is invisible to visitors.
A load balancer distributes requests among several back-end servers. Many reverse proxies balance load, but a network-layer load balancer can route packets without reading HTTP at all.
A CDN is a specialised reverse proxy spread across many points of presence, with caching as its primary job. A single nginx instance in front of an application is not a CDN.
Server-side tagging is a measurement architecture, not a network device. It typically relies on a reverse proxy or a subdomain to receive browser events, but the defining feature is that tags execute on a server the advertiser controls. Tag gateway, by contrast, changes only the route; the tags still run in the browser.
Recent developments
The AI crawler question has dominated 2026. Cloudflare said on July 1, 2026 that from September 15, 2026 it would block Training and Agent crawlers by default on ad-carrying pages for newly onboarded domains, and announced a shift from charging per crawl to paying publishers per answer. HasData then found that 118 sites lost Cloudflare's managed AI rules from their robots.txt files after the September 15 migration, while 16 of 21 affected sites still blocked or challenged GPTBot at the proxy.
On the tagging side, the gateway model has broadened. Akamai joined as a partner on January 29, 2026, Fastly launched its integration on April 8, 2026, and Google documented randomised paths that hide container IDs on May 11, 2026, before confirming general availability on Google Cloud on June 1, 2026.
Timeline
- April 1995 - Harvest object cache offered as an "httpd accelerator", an early reverse proxy.
- July 1996 - Squid 1.0.0 released by Duane Wessels.
- August 20, 1998 - Akamai incorporated; first live traffic follows in February 1999.
- October 4, 2004 - nginx publicly released by Igor Sysoev.
- September 27, 2010 - Cloudflare launches at TechCrunch Disrupt.
- June 2014 - RFC 7239 standardises the Forwarded header.
- September 29, 2017 - Cloudflare announces Workers for running code at the edge.
- March 11, 2019 - F5 acquires Nginx, Inc. for $670 million.
- August 13, 2020 - Google opens server-side tagging to all Tag Manager accounts.
- November 12, 2020 - Safari 14 caps cookies set through CNAME-cloaked responses at seven days.
- June 8, 2021 - Fastly outage leaves 85% of its network returning errors.
- June 2022 - RFC 9110 defines the gateway, or reverse proxy, in HTTP semantics.
- 2023 - Safari 16.4 extends cookie caps to servers on mismatched IP addresses.
- October 9, 2024 - Google announces first-party mode beta with Cloudflare.
- May 8, 2025 - First-party mode becomes Google tag gateway for advertisers.
- July 1, 2025 - Cloudflare blocks AI crawlers by default for new domains and launches Pay Per Crawl.
- November 18, 2025 - Cloudflare proxy outage after a Bot Management file error.
- January 8, 2026 - AGCOM fines Cloudflare EUR 14.2 million.
- January 29, 2026 - Akamai joins Google tag gateway.
- April 8, 2026 - Fastly launches its tag gateway integration.
- May 11, 2026 - Google documents randomised paths hiding container IDs.
- September 15, 2026 - Cloudflare default blocking of Training and Agent crawlers on ad-carrying pages for new domains takes effect.
Related PPC Land coverage
- Explaining CDN - How content delivery networks work as specialised reverse proxies, with their history and major outages.
- Explaining Google tag gateway - The edge proxy that serves Google tags from an advertiser's own domain, with its dates and uplift claims.
- Ad blockers are now targeting server-side GTM subdomains by name - Filter lists adding named sgtm. and gtm. subdomains, and the debate it prompted.
- isblocked.fyi: the tool that shows if adblockers are silently killing your data - A checker for first-party tracking domains across 22 filter lists.
- Safari 27 blocks LinkedIn and Bing ad trackers by IP address - A WebKit code review showing network-layer blocking that first-party proxies do not avoid.
- Explaining server-side - What changes when tags and auctions move to servers, including cookie lifetime effects.
- Google Tag Manager debuts First-party Mode Beta with Cloudflare Integration - The October 2024 beta that preceded tag gateway.
- Google tag gateway now lets advertisers hide GTM container IDs - The May 2026 option to randomise serving paths.
- Google tag gateway for advertisers hits general availability on Google Cloud - The Google Cloud load balancer route reaching general availability.
- Meta's free one-click Conversions API is now live - no developer needed - Meta's April 2026 server connection that runs without advertiser infrastructure.
- Explaining Conversions API - How server-to-server conversion APIs work across Meta, LinkedIn, TikTok and others.
- Cloudflare stops charging AI per crawl and starts paying per answer - Cloudflare's July 2026 shift and the history of Pay Per Crawl.
- Cloudflare exposes AI crawlers hitting sites 50000 times per visitor - Crawl-to-referral ratios reported through Cloudflare's dashboards.
- Cloudflare drops AI opt-outs from 118 sites' robots.txt, HasData finds - What happened to managed robots.txt rules after the September 2026 migration.
- Explaining Web Bot Auth - The signed-request protocol that proxies and CDNs use to verify bots.
- Cloudflare faces EUR 14.2 million fine from Italian regulator over piracy enforcement - AGCOM's sanction and the court finding on Cloudflare's reverse proxy.
Summary
Who. Website operators deploy reverse proxies, usually through CDNs such as Cloudflare, Akamai, Fastly and Amazon CloudFront, or software such as nginx, HAProxy and Squid. Advertisers and their agencies use them for tagging, Google and Meta supply gateway products, and browser makers, filter list maintainers and regulators set the limits.
What. A reverse proxy is a server that receives requests on behalf of one or more origin servers, forwards them and returns the responses as if it were the origin. It caches, filters, balances and rewrites traffic from a single point of control.
When. The concept appeared with the Harvest cache's accelerator mode in 1995 and Squid in 1996, scaled commercially with Akamai from 1998 and Cloudflare from 2010, and entered marketing measurement with server-side tagging in 2020 and Google tag gateway in 2024 and 2025.
Where. It sits between the public internet and a site's servers, at the domain's DNS-advertised address, often at a CDN's edge locations around the world.
Why. It gives site owners one place to speed up delivery, absorb attacks and decide which visitors, bots and data flows reach their infrastructure. For marketers, it routes measurement through first-party domains and controls AI crawler access, which is also why browsers, ad blockers and critics contest its use.
Discussion