The host-side uptime watchdog and on-host cron jobs curl Caddy with a stock curl/8.5.0 UA from loopback and the host tailscale IP — ~300 GET /api/health 401 warn-events/day burying real perimeter signal (census: 339+20 of 5000 access.log lines). Dropping on UA alone would blind the store to external curl scanners, so generic tool UAs (curl/) are now dropped ONLY when the source remote_ip is one of this host's own addresses (DASHCADDY_SELF_IPS, default loopback; start.sh derives 127.0.0.1 + tailscale ip -4, empty-safe). remote_ip (TCP peer) is used, never the spoofable client_ip. DashCaddy-* probe UAs stay unconditionally dropped. 9 regression pins cover the full conjunction matrix incl. external-IP+curl KEPT and spoofed-XFF KEPT. 2858/2858 green (128 suites). Judge: glm-4.6@zai-coding-paas cold-read round 1 = A clean (0 blocking), both polish notes folded. URN urn:ump:s2sgitfepze65crtp57dpdw4gk4w7upsoi4tqcvfwahcsicyepba