October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PCOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
Host header

What Is a Host Header? HTTP/1.1, HTTP/2, Routing, and Security

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A Host header is an HTTP request field that carries the hostname and, when applicable, port from the target URI. It lets one server distinguish which named website or service a request is intended for. In HTTP/1.1, every request must include exactly one valid Host field; in HTTP/2 and HTTP/3, the :authority pseudo-header can carry that authority instead.

What the Host header contains

RFC 9110 defines Host as the host and port information from the target URI. The value identifies the destination name at the application layer; it is not a DNS lookup and does not authenticate the server. The standard definition is in RFC 9110 §7.2.

For a request to http://www.example.org/where?q=now, an HTTP/1.1 client sends:

GET /where?q=now HTTP/1.1
Host: www.example.org
  • GET /where?q=now supplies the method, path, and query.
  • Host: www.example.org identifies the requested host.
  • If the URI specifies a non-default port, the authority can include that port, such as www.example.org:8080.

One server address can serve many named sites. The host value acts like the named destination that allows the server or proxy to select the appropriate virtual host and application.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why servers use it for routing

Web servers commonly configure several domains on one IP address. The server examines the request’s authority and chooses the matching virtual-host configuration, certificate context, application, or content directory. The Host field therefore helps route a request after the connection reaches the server.

For HTTPS, the secured connection and certificate validation establish the authenticated server identity. A Host value should not be treated as a security credential or proof that the client reached the intended site.

HTTP/1.1 requirements

Under RFC 9112 §3.2, a client must send a Host field in every HTTP/1.1 request. If the target URI has an authority component, Host must match it, excluding any userinfo. A server must respond with 400 Bad Request when Host is missing, repeated, or invalid.

This means a compliant HTTP/1.1 request cannot simply omit Host, even when the server has only one website.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Host versus :authority in HTTP/2

HTTP/2 uses pseudo-headers rather than an HTTP/1.1 request line. Its :authority pseudo-header carries the authority portion of the target URI. As described in RFC 9113 §8.3.1, when :authority is present, the recipient must not use Host to determine the target URI.

Aspect HTTP/1.1 HTTP/2
Authority field Host field is required :authority carries authority when present
Target selection Host corresponds to target-URI authority Recipient uses :authority, not Host, when it is present
Translation to HTTP/1.1 Not applicable An intermediary derives Host from :authority unless it changes the request target
Primary standard RFC 9112 §3.2 RFC 9113 §8.3.1

HTTP/3 also uses the authority concept through :authority; RFC 9110 discusses Host being supplanted by that pseudo-header for HTTP/2 and HTTP/3. The exact framing details are defined by the HTTP/3 specification.

Rank #3
Sale
HTTP: The Definitive Guide
  • Used Book in Good Condition

Why an unvalidated Host value is dangerous

Clients can send arbitrary request fields, and systems often copy Host into routing decisions, redirects, emails, or generated links. RFC 9110 warns that request data can become injection input when passed unsafely to commands, interpreters, or database queries; see §17.4.

OWASP’s Host Header Injection guidance describes possible consequences when validation is insufficient:

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Dispatching a request to an unintended virtual host.
  • Redirecting users to an attacker-controlled domain.
  • Web-cache poisoning.
  • Manipulating password-reset links or other generated URLs.
  • Reaching virtual hosts that were not meant to be public.

These are potential outcomes, not proof that every application is vulnerable. In authorized testing, a tester may supply another domain in Host and observe routing and generated responses. Where a proxy rewrites or filters Host, X-Forwarded-Host may also affect the application’s view of the original host and must be handled according to the deployment’s trusted-proxy design.

Rank #4
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How applications should handle Host

Allow only hosts you serve

Configure an explicit allowlist of expected hostnames, including the ports and environments your application genuinely supports. Reject unexpected values rather than accepting any syntactically valid domain.

Do not build security-sensitive URLs blindly

Password-reset links, canonical redirects, invitation URLs, and similar values should use a configured public origin or a validated host mapping. Do not concatenate an unchecked Host value into these outputs.

Keep proxy handling explicit

If a reverse proxy terminates TLS or forwards requests, define which proxy is trusted and how it communicates the original authority. Treat forwarded host fields as untrusted unless the request came through that trusted boundary.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Validate before using the value elsewhere

Even after routing validation, treat the value as untrusted input before inserting it into HTML, logs, database queries, shell commands, or other interpreters. Apply context-appropriate output encoding and parameterization.

Common points of confusion

Is Host the same as an IP address?

No. Host normally contains a DNS name, though an IP-literal authority is possible. DNS and connection setup determine where traffic goes; Host tells the HTTP service which authority the request names.

Does Host prove the request is legitimate?

No. A client can send a different Host value. It identifies the requested authority for protocol processing, not the client’s identity or the authenticity of the server.

Can HTTP/1.1 send two Host fields?

No. RFC 9112 requires a 400 response for repeated Host field lines. Applications should reject ambiguity instead of choosing one value.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What happens when Host and :authority disagree?

In HTTP/2, :authority is the authority source when present. A translating intermediary must derive the HTTP/1.1 Host value from it unless the request target changes; deployments should reject inconsistent or malformed input rather than allowing different layers to route differently.

Quick Recap

SaleBestseller No. 3
HTTP: The Definitive Guide
HTTP: The Definitive Guide
Used Book in Good Condition
$26.04
SaleBestseller No. 4
HTTP Pocket Reference: Hypertext Transfer Protocol
HTTP Pocket Reference: Hypertext Transfer Protocol
Used Book in Good Condition
$6.94
Bestseller No. 5

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Read next

Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.