What is an X-Forwarded-For header?
Identifies the originating IP address of a client connecting through a proxy or load balancer.
X-Forwarded-For is the de facto standard way a proxy or load balancer preserves the real visitor's IP address as a request passes through to a website's origin server, since without it every request would otherwise appear to come from the load balancer itself. Getting this wrong quietly breaks IP-based rate limiting, geo-blocking, and abuse detection all at once - problems that tend to surface as confusing support tickets long before anyone traces them back to a missing header.
Common use case
A rate limiter reads the first IP in X-Forwarded-For instead of the raw TCP connection IP, so it correctly identifies and throttles an individual abusive visitor rather than the load balancer sitting in front of everyone.
Example
X-Forwarded-For: 203.0.113.42, 198.51.100.17History
An informal convention dating back to the mid-1990s, originally popularised by the Squid proxy, never formally standardised - RFC 7239's Forwarded header was created specifically to be its official replacement.
Did you know?
Despite never being an official standard, it's arguably the most universally implemented header in this entire reference - virtually every proxy, CDN, and load balancer in existence sets it.