hmm interesting. I think the rack protection middleware came after the
suggestion to configure nginx (which looks like you follow).
It might be worth googling that Ruby Rack Middleware to see how it detects spoofing, and work backwards to see why it thinks it’s being spoofed