# PHP REMOTE\_ADDR security

**URL:** <https://forum.kirupa.com/t/php-remote-addr-security/219754>\
**Category:** programming\
**Created:** [March 19, 2007, 11:34pm UTC](https://forum.kirupa.com/t/php-remote-addr-security/219754 "2007-03-19T23:34:03Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![espmartin](https://yyz1.discourse-cdn.com/flex011/user_avatar/forum.kirupa.com/espmartin/32/3458_2.png) [@espmartin](https://forum.kirupa.com/u/espmartin)\
**Post date:** [March 19, 2007, 11:34pm UTC](https://forum.kirupa.com/t/php-remote-addr-security/219754/1 "2007-03-19T23:34:03Z")

</div>

Hello All,  
My 1st post here! I have a contact form that submits all the info just great.  
However, I get the occasional poster that just spams the form with tons of  
links. I do have this disclaimer on the page itself:

> The comments posted on the form are NOT in anyway posted  
> online on this, or any other website. I’ve been getting allot of spammers  
> filling out this form, and including hundreds of lines of code, all for backlinks  
> to their spammy sites. You will in no way inherent ANY IBL, or PageRank!  
> That doesn’t stop them. I want to exclude/deny their IP addys from the site  
> but the means of capturing the users IP:

```php
$ipi = getenv("REMOTE_ADDR");

```

is not full-proof. I get users submitting with IPs such as: 127.0.0.1 - obviously spoofed/hacked.

So, what can I do to prevent the spoofing of IPs submitted vis that  
REMOTE\_ADDR function?
