// http header · request header

X-Forwarded-For

Original client IP address behind proxies and load balancers

What the X-Forwarded-For header does

X-Forwarded-For (XFF) records the IP address of the client that originally made a request when it passes through proxies, CDNs or load balancers. Each proxy appends the address it received the request from, so the value is a comma-separated list: the claimed client first, then every proxy on the way. It is a de facto standard; the standardised equivalent is Forwarded (RFC 7239).

Example

X-Forwarded-For: 203.0.113.7, 198.51.100.23

X-Forwarded-For in practice

What the server receives after two proxies

X-Forwarded-For: 203.0.113.7, 198.51.100.23

nginx: append the client address

proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;

Express: trust one proxy hop

app.set("trust proxy", 1);
// req.ip now comes from X-Forwarded-For

The standardised form

Forwarded: for=203.0.113.7;proto=https;by=198.51.100.23

Common X-Forwarded-For questions and problems

How do I get the real client IP behind a proxy or load balancer?

Read it from X-Forwarded-For, but only trust the entries added by proxies you control. Your own proxy appends the address it saw, so count from the right: with one trusted proxy, the last entry is the client as your proxy saw it. Frameworks have a setting for this, for example Express's trust proxy or nginx's set_real_ip_from.

Can X-Forwarded-For be spoofed?

Yes. Any client can send its own X-Forwarded-For header, and the first entries may be fake. Do not base rate limiting, allow-lists or fraud checks on the leftmost value unless your edge proxy discards or overwrites untrusted incoming values.

X-Forwarded-For vs X-Real-IP vs Forwarded?

X-Forwarded-For is a list that grows with each hop. X-Real-IP is a single address set by one proxy such as nginx. Forwarded is the RFC 7239 standard that carries the same information as for=, proto= and by= parameters, but it is less widely used.

Why do I see ports or IPv6 addresses in the list?

Some proxies include a port (203.0.113.7:4711) and IPv6 addresses may appear in brackets or as ::ffff: mapped IPv4. Parse and normalise before comparing.

Is the value personal data?

IP addresses count as personal data under rules such as the GDPR. Log and retain them only as needed, and document it in your privacy policy.

X-Forwarded-For vs related headers

  • Host: Host is the domain the client asked for. X-Forwarded-For carries the client's address.
  • Forwarded: The standardised replacement for the X-Forwarded-* family, using for=, proto= and by= parameters.
  • Origin: Origin identifies the web origin that started a cross-origin request. It says nothing about the client's IP address.

Where it's used

X-Forwarded-For is a request header. Request headers are sent by the client to describe the request and what the client can accept.

Other request headers