Skip to content
Glossary

X-Forwarded-For

X-Forwarded-For is a de facto request header in which a proxy records the address of the client it received the request from.

X-Forwarded-For is a de facto request header in which a proxy records the address of the client it received the request from. It is not defined by any RFC. RFC 7239 standardised the same idea under the name Forwarded, and notes that the older header is nonetheless widely used.

#The two spellings

X-Forwarded-For: 203.0.113.7, 198.51.100.9
Forwarded: for=203.0.113.7;proto=https;by=198.51.100.9

Each intermediary appends the address it saw, so the list grows left to right and the leftmost entry is the furthest from your server. RFC 7239 also gives Forwarded a way to carry the protocol and the receiving interface, which the older header never had.

#Why the leftmost value is not the client

Any entry can be forged, because the client can simply send the header itself and a naive intermediary will append rather than replace. Only the entry added by an intermediary you operate is trustworthy. Counting from the right, discard as many entries as you have proxies you control, and treat everything beyond that as claimed rather than observed.

Using an unvalidated leftmost value for rate limiting, access control or logging is the standard way to build a limit that anybody can step around.

#What a proxy provider does with it

Some proxies add the header, some pass it through, some strip it. The categories sold as transparent, anonymous and elite describe this behaviour, but the labels are marketing terms with no specification behind them, so the only reliable answer is to test the endpoint you bought against a service that echoes the headers it received.

Test with the exact protocol you will use in production. A proxy can behave differently for plain HTTP and for CONNECT, because in a tunnel it has no request to edit.

#Commonly confused with

Via is standardised and records which intermediaries handled the message and on which protocol version. It is about the path. X-Forwarded-For is about the origin of the request. A proxy may send both, either, or neither.

Frequently asked questions

Is X-Forwarded-For a standard header?
No. It is a widely deployed convention with no defining RFC. RFC 7239 specifies Forwarded as the standardised replacement, carrying the same information plus the protocol and receiving interface, and acknowledges that the older header remains in common use. Many stacks emit both.
Can I trust the first address in the list?
Only if every intermediary between that entry and you is one you control. A client can send the header itself, and intermediaries that append rather than replace will preserve the forgery. Count entries from the right, keep only those your own proxies added, and treat the rest as unverified.
How do I find out whether my proxy adds it?
Send a request through the proxy to a service that echoes the headers it received, then repeat without the proxy as a control. Test both plain HTTP and a CONNECT tunnel, because a proxy that edits headers on one cannot edit anything inside the other.

Sources

  1. RFC 7239: the Forwarded HTTP extension, the standardised form of this header

Related terms