HTTP 421 Misdirected Request
The request reached a server that isn’t configured for that host name — usually HTTP/2 connection reuse across domains sharing a certificate, or a wrong SNI.
Meaning
With HTTP/2, browsers reuse one connection for several hosts covered by the same certificate (e.g. a wildcard). If those hosts are served by different backends or virtual hosts, the server replies 421 so the browser opens a new connection.
Apache also returns 421 when SNI and the Host header don’t match, and reverse proxies return it when proxying to an HTTPS backend without passing the right SNI.
Common causes
- HTTP/2 connection coalescing across hosts on a shared/wildcard certificate
- SNI and Host header mismatch (Apache SSLStrictSNIVHostCheck)
- Proxy forwarding to an HTTPS upstream without proxy_ssl_server_name
⚡ Quick fix
- Give each host its own certificate, or serve them from the same vhost/IP
- Nginx proxying HTTPS: enable proxy_ssl_server_name on
- Check vhost ServerName/ServerAlias for the host
Detailed fix by platform
Nginx
- nginx
location / { proxy_pass https://backend.example.com; proxy_ssl_server_name on; proxy_set_header Host backend.example.com; }
Apache
- apache
# per vhost: ServerName and matching certificate; or relax strict SNI SSLStrictSNIVHostCheck off
How to diagnose
- Hosts — Which hostnames share the certificate/IP?
- SNI — openssl s_client -servername host -connect ip:443
- Proxy — Does it send SNI upstream?
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
Most viewed in HTTP
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Report a correction or suggest an improvement
Last updated 7 Oct 2026