Reverse Proxy Analyzer
Analyze X-Forwarded-For and other headers.
Last reviewed by the Radiatus Cloud team
Need this monitored 24/7?
Radiatus delivers managed cloud & network operations.
Make sense of the headers a proxy adds
When traffic passes through a reverse proxy or load balancer, the original client details are rewritten into headers like X-Forwarded-For, X-Forwarded-Proto and X-Real-IP. Read them wrong and your logs show the proxy’s address instead of the client’s, your rate limiting keys on the wrong thing, and your access controls trust the wrong source. This tool analyses those headers and explains what each is telling you.
X-Forwarded-For is a chain, not an address
The most misunderstood header is X-Forwarded-For, which is a comma-separated list that each proxy appends to, not a single client IP. The real client is usually the leftmost entry, but only if you trust every hop that added to it, because any client can send a fake X-Forwarded-For to begin with. Knowing which entry to trust, and only trusting headers from proxies you control, is the difference between correct client identification and a spoofable one.
Getting the client IP right matters for security
Rate limits, geoblocking, audit logs and abuse controls all depend on identifying the real client, and all of them fail quietly when the proxy headers are read naively. Analysing the header chain shows you where the trustworthy client address actually is. The analysis runs in your browser, so pasted headers stay on your machine.
Related tools
- Port Scanner — Check which common ports respond on a host and understand what each exposed service means. Scan only systems you are authorised to test.
- DNS Misconfiguration — Analyze DNS records (TXT, SPF) for security gaps.
- TLS Compat Tester — Check client-server compatibility for TLS versions.
- Firewall Rule Risk — Evaluate firewall rules for over-permissive exposure.
Frequently Asked Questions
What is X-Forwarded-For?
A header that proxies use to record the original client address. It is a comma-separated chain that each proxy appends to, not a single address.
Which entry is the real client IP?
Usually the leftmost, but only if you trust every proxy that added to the chain. Because a client can send a fake X-Forwarded-For, you should only trust the portion added by proxies you control.
Why does reading these headers wrong matter?
Because logs, rate limiting, geoblocking and access controls all key on the client IP. Trusting a spoofable header lets an attacker forge their apparent source.
What other headers does a proxy add?
Commonly X-Forwarded-Proto for the original scheme and X-Real-IP for the client address, among others, depending on the proxy configuration.
Is my header data uploaded?
No. The analysis runs entirely in your browser.
Privacy & Security
Processed locally.
About This Tool
This tool runs entirely in your browser. No data is sent to any server, ensuring complete privacy. Simply use the interface above to get started — no registration or login required.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
Port Scanner
NetworkCheck which common ports respond on a host and understand what each exposed service means. Scan only systems you are authorised to test.
DNS Misconfiguration
NetworkAnalyze DNS records (TXT, SPF) for security gaps.
TLS Compat Tester
NetworkCheck client-server compatibility for TLS versions.