When a proxy forwards a request, the server behind it sees the proxy's address, not the client's. X-Forwarded-For was invented to carry the original address along. Each proxy appends the address it received the request from:
X-Forwarded-For: 198.51.100.23, 203.0.113.10
The first entry is the client as the first proxy saw it; later entries are proxies along the way. The standardised equivalent is the Forwarded header from RFC 7239, as in Forwarded: for=198.51.100.23, but X-Forwarded-For remains far more common.
Why it matters for proxy buyers
A forward proxy that adds X-Forwarded-For hands your real IP to every site you visit; that is what makes a transparent proxy transparent. Commercial proxies normally do not add it. Check with a plain HTTP request:
curl -s -x http://USERNAME:PASSWORD@HOST:PORT http://httpbin.org/headers
If your own IP appears in X-Forwarded-For or Forwarded, the proxy leaks it. Test over http://, because a proxy cannot add headers to HTTPS requests inside a tunnel.
Why sites treat it carefully
Anyone can send the header, with any value. A site that trusted it blindly could be fooled by a client claiming another IP, so well-built sites only trust entries added by their own reverse proxies and load balancers. That is also why setting the header yourself does not change the IP a site acts on; it only adds a claim that does not match the connection.
Common confusion
X-Forwarded-For lists addresses; the Via header names the proxies. A proxy can add either, both or neither, and each tells the site something different.