Updated: 28 September 2026 · Applies to: Self-managed dedicated servers on Linux
A server with several IP addresses uses its main address for outgoing connections unless you tell it otherwise. Sometimes you want a service to leave from a specific address: a partner that only allows one IP, an API with per-IP limits, a mail server whose reputation belongs to one address, or customers who each need their own address. This guide shows the ways to choose the source address, from a single command to a permanent setup.
Before you start
The extra address must be configured and tested (How to test that every additional IP address works on your server?), step 4 in particular: curl --interface must print the extra address.
Per command
curl --interface 203.0.113.11 https://example.com wget --bind-address=203.0.113.11 https://example.com/file ssh -b 203.0.113.11 user@remote-server rsync -e "ssh -b 203.0.113.11" file user@remote-server:/path/
In a web server or proxy
Nginx, when it fetches content from another server or acts as a proxy:
location /api/ {
proxy_bind 203.0.113.11;
proxy_pass https://backend.example.com;
}
In a mail server
Postfix sends from the address you set in smtp_bind_address. Details and the matching host name: How to make Postfix send from a specific IP address with a matching HELO name?.
In your own program
Most languages let you bind a socket to a local address before you connect. In Python:
import socket
s = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
s.bind(("203.0.113.11", 0)) # port 0 = any free port
s.connect(("example.com", 80))
All traffic of one Linux user or service
When you cannot change the program, you can rewrite the source address of everything that a system user sends. Create a dedicated user for the service, then:
sudo iptables -t nat -A POSTROUTING -m owner --uid-owner svcuser -j SNAT --to-source 203.0.113.11
The rule is not permanent by itself. Save it with your firewall tool (iptables-persistent on Ubuntu) once it works. On systems that use nftables directly, an equivalent rule matches meta skuid in a postrouting chain and uses snat to.
Change the default source address for the whole server
To make the server use another address for all outgoing traffic, set it as the source of the default route. With netplan (see How to add additional IPv4 addresses on Ubuntu with netplan?):
routes:
- to: default
via: 203.0.113.9
from: 203.0.113.11
Run sudo netplan try to test. Do this only if you are sure; the main address is normally the right default, and some services you connect to expect it.
Windows
Windows chooses the source address by itself. Add extra addresses with -SkipAsSource $true (How to add additional IPv4 addresses on Windows Server?) to keep the main address as default, and set the source address inside the application where it allows it (for example the bind address of a server program).
Check that it works
Connect to a service that shows your address (curl https://ifconfig.me is an example) or read the log of the remote server. Also check that the reverse DNS name of the address fits the service that uses it (How to set reverse DNS (PTR) for many IP addresses and check forward-confirmed rDNS?).
Frequently asked questions
Why not switch addresses automatically all the time?
Remote services build up a history for each address. A service that keeps a fixed address gets a stable reputation; constantly changing the source address makes it look less trustworthy. Ucartz's Acceptable Use Policy allows you to assign addresses to services and to automate that assignment, and does not allow using address changes to evade blocks. Choose one address per service and keep it; see How to automate multi-IP mail management safely: assignments, warm-up schedules and automatic pausing for automation that does this safely.
Does the extra address need its own network card?
No. All addresses can sit on the same card.
Need a dedicated server, more IP addresses, or a hand with the setup?
- Unmanaged dedicated servers: full root access and IPv4 subnets from /29 up to /24, ordered with the server or added later.
- Managed dedicated servers: our team looks after the operating system, updates, security and monitoring.
- Dedicated server locations: choose the country and data centre when you order.
Prefer a hand with the setup? Our engineers can do it for you: Hire an Expert, or use our on-demand server management.
