Case file 7239 / complete registry census

The forwarded fields unregisteredin IANA's snapshot updated 7 August 2026

In all 257 records of the IANA HTTP Field Name Registry snapshot updated 7 August 2026, not one of the three legacy fields named by RFC 7239, X-Forwarded-For, X-Forwarded-By, or X-Forwarded-Proto, is registered.

snapshot 2026-08-07 comparison case-insensitive verdict bounded registry absence
The certificatebounded null
The claim
No case-insensitive exact match for X-Forwarded-For, X-Forwarded-By, or X-Forwarded-Proto exists in the dated registry.
Domain swept
loading local snapshot. The real domain is every record element in the sole field-names registry.
Method
Parse every record, case-fold every Field Name, and compare it with the three RFC-named candidates. No sampling and no pagination.
Positive control
waiting for census
Planted witness
unplanted domain: waiting
Result
waiting for census
Bound
The frozen IANA snapshot updated 7 August 2026. This says nothing about later registrations, traffic, validity, or fields outside the three RFC-named candidates.

01 / touch the null

Ask the whole registry.

An exact query scans the same complete array used by the certificate. Letter case does not matter. Replace the legacy name with the standardized name to cross the boundary in one click.

exact-name terminalsnapshot loading

Loading the local registry snapshot.

Unregistered is the whole result. It does not mean invalid, forbidden, unused, unsafe, or unknown to software. RFC 9110 says fields ought to be registered, not that unregistered field names cannot travel.

02 / relax one constraint

The X is not a fence.

Maybe the null is automatic because names beginning X- never enter the registry. Move one step from the specific family prefix to the broad prefix. The complete sweep decides.

prefix boundaryexactly two positions
X-Forwarded-X-

Loading the local registry snapshot.

What two records prove

The X- prefix is not a categorical exclusion from this registry.

What they do not prove

They do not show that IANA would accept any particular new X- registration.

03 / four predicates, kept apart

A name can exist without registering.

The record and the standard are separate instruments. Registration and status below are recomputed from the shipped registry. The last two columns encode the bounded findings in RFC 7239.

Field nameIn registryRegistry statusMentioned by RFC 7239Standardized by RFC 7239
Loading registry.

RFC 7239 introduces the three legacy names as common non-standard examples. Its wording is not an exhaustive list of every deployed X-Forwarded name, so this page does not silently add X-Forwarded-Host to the three-item claim.

04 / substantive boundary

A registry change is also a syntax change.

For one X-Forwarded-For list, RFC 7239 describes a transition to Forwarded. This small syntax demonstrator adds for= and quotes an IPv6 node. It refuses when a simultaneous By field makes pairing underdetermined.

bounded output

This is not a general converter. It accepts one to six comma-separated IPv4 or IPv6 address tokens. It does not model trust, obfuscated identifiers, ports, repeated lines, or proxy ordering. IPv6 validation here is deliberately conservative.

05 / audit apparatus

The check.

Every green number below comes from parsing the local XML now. If loading, parsing, the snapshot date, byte length, or digest disagrees with the certified artifact, this panel turns the page's result into a refusal.

the check: running

...records parsed
...legacy matches
...control matches
...X- prefix records

SHA-256
computing

Status partition
computing

  • Snapshot identity pending.
  • The enumerated unit is every record directly under the sole registry with id field-names. The chosen column is value, the Field Name. IANA's older message-header registry explicitly directs HTTP registrations to this registry under RFC 9110.
  • The free choice is a case-insensitive exact-name comparison, required because RFC 9110 defines field names as case-insensitive.
  • The three-name candidate set is bounded to the examples named together in RFC 7239's introduction. It is not a census of deployed legacy names.
  • The planted row is visibly synthetic, exists only in browser memory, and is removed before the real-domain result is certified again.
  • Unknown past the bound: registry edits after 7 August 2026, private deployment, traffic frequency, and whether any field is valid for a particular application.

Sources / retrieved 11 August 2026

The record behind the record.

  1. IANA, HTTP Field Name Registry XML. The full shipped snapshot is parsed by this page. Registry data is released under CC0 1.0; see the local licence note.
  2. RFC 7239, Forwarded HTTP Extension, Petersson and Nilsson, June 2014. Source for the candidate names, the standardized control, and the transition boundary.
  3. RFC 9110, HTTP Semantics, Fielding, Nottingham, and Reschke, June 2022. Source for case-insensitive field names and the registry definition.
  4. RFC 6648, Deprecating the X- Prefix, Saint-Andre, Crocker, and Nottingham, June 2012. It discourages X- for newly defined parameters but does not decide whether existing X- names should remain or migrate.
  5. IANA and IETF Joint Statement on registry copyright, revised 10 November 2021. Source for the CC0 licence and its exclusion of linked RFCs.
  6. IANA, Message Headers registry. Its registry note says HTTP field registrations moved to the separate HTTP Field Name Registry under RFC 9110.

The source snapshot is frozen so that the claim remains checkable. A later registration would change the current registry, but would not alter what the dated snapshot contains.