← All headersRequest header

What is a Forwarded header?

The standardised replacement for the various X-Forwarded-* headers, disclosing client info through a proxy in one field.

Forwarded is the RFC-standardised way for a proxy or load balancer in front of a website to pass along the original client's IP, protocol, and host in a single structured header, rather than the ad-hoc X-Forwarded-* headers it's meant to replace. Getting proxy header handling wrong is a common source of a website logging every visitor as coming from the load balancer's own IP, which quietly breaks rate limiting, geo-detection, and abuse monitoring all at once.

Common use case

A load balancer sets Forwarded with the original client IP, protocol, and host in one structured field, so the origin server can log and rate-limit by real visitor rather than the load balancer's own address.

Example

Forwarded: for=203.0.113.42;proto=https;host=example.com

History

Standardised in RFC 7239 (2014) specifically to unify the inconsistent set of X-Forwarded-* headers different vendors had each invented independently.

Did you know?

Despite being the official standard for over a decade, the informal X-Forwarded-For is still far more widely deployed in practice - a rare case where the unofficial convention outlasted its own formal replacement.