421 🌐 HTTP

HTTP 421 Misdirected Request

The request reached a server that isn’t configured for that host name — usually HTTP/2 connection reuse across domains sharing a certificate, or a wrong SNI.

Seen on: REST API

Meaning

With HTTP/2, browsers reuse one connection for several hosts covered by the same certificate (e.g. a wildcard). If those hosts are served by different backends or virtual hosts, the server replies 421 so the browser opens a new connection.

Apache also returns 421 when SNI and the Host header don’t match, and reverse proxies return it when proxying to an HTTPS backend without passing the right SNI.

Common causes

  • HTTP/2 connection coalescing across hosts on a shared/wildcard certificate
  • SNI and Host header mismatch (Apache SSLStrictSNIVHostCheck)
  • Proxy forwarding to an HTTPS upstream without proxy_ssl_server_name

⚡ Quick fix

  1. Give each host its own certificate, or serve them from the same vhost/IP
  2. Nginx proxying HTTPS: enable proxy_ssl_server_name on
  3. Check vhost ServerName/ServerAlias for the host

Detailed fix by platform

Nginx

  1. nginx
    location / {
        proxy_pass https://backend.example.com;
        proxy_ssl_server_name on;
        proxy_set_header Host backend.example.com;
    }

Apache

  1. apache
    # per vhost: ServerName and matching certificate; or relax strict SNI
    SSLStrictSNIVHostCheck off

How to diagnose

  1. Hosts — Which hostnames share the certificate/IP?
  2. SNI — openssl s_client -servername host -connect ip:443
  3. Proxy — Does it send SNI upstream?

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.