What is an X-Forwarded-Host header?
Identifies the original Host header requested by the client before it reached a proxy.
X-Forwarded-Host preserves the original hostname a visitor requested before a proxy or CDN in front of a website potentially rewrote the Host header on its way to the origin. It matters most for websites hosted behind a CDN that serve multiple domains from shared infrastructure, where losing track of the original host can cause a server to generate links or redirects pointing at the wrong domain entirely.
Common use case
An origin server behind a CDN reads X-Forwarded-Host instead of Host to generate absolute URLs (e.g. in emails or redirects) that point at the domain the visitor actually requested.
Example
X-Forwarded-Host: www.kawze.comHistory
An informal convention, part of the same family of X-Forwarded-* headers as X-Forwarded-For, never formally standardised outside of the newer Forwarded header.
Did you know?
A server that trusts this header blindly without validating it against a known list of allowed hosts opens itself up to "Host header injection" style attacks, since a malicious client can set it to anything.