When a proxy forwards a request, the server behind it sees the proxy's address, not the client's. X-Forwarded-For was invented to carry the original address along. Each proxy appends the address it received the request from:

X-Forwarded-For: 198.51.100.23, 203.0.113.10

The first entry is the client as the first proxy saw it; later entries are proxies along the way. The standardised equivalent is the Forwarded header from RFC 7239, as in Forwarded: for=198.51.100.23, but X-Forwarded-For remains far more common.

Why it matters for proxy buyers

A forward proxy that adds X-Forwarded-For hands your real IP to every site you visit; that is what makes a transparent proxy transparent. Commercial proxies normally do not add it. Check with a plain HTTP request:

curl -s -x http://USERNAME:PASSWORD@HOST:PORT http://httpbin.org/headers

If your own IP appears in X-Forwarded-For or Forwarded, the proxy leaks it. Test over http://, because a proxy cannot add headers to HTTPS requests inside a tunnel.

Why sites treat it carefully

Anyone can send the header, with any value. A site that trusted it blindly could be fooled by a client claiming another IP, so well-built sites only trust entries added by their own reverse proxies and load balancers. That is also why setting the header yourself does not change the IP a site acts on; it only adds a claim that does not match the connection.

Common confusion

X-Forwarded-For lists addresses; the Via header names the proxies. A proxy can add either, both or neither, and each tells the site something different.