"421 Misdirected Request" means a web server received a request for a website it does not believe it should answer on that connection. Visitors usually see it when a proxy or CDN in front of a site sends the wrong name to the server, and in July 2025 many servers started showing it after an Apache security update. This page explains what the error means, what you can check yourself, and, for readers who run their own server, how the Apache 2.4.64 case is fixed properly.
A 421 means the site name your browser or proxy asked for did not match the connection it used. On Domain India shared hosting, first check whether Cloudflare or another proxy sits in front of your site and whether it overrides the host name or SNI, then confirm your domain is added to your hosting account. If it still happens, open a ticket with the address and time. On your own server, the Apache 2.4.64 case is fixed by making the proxy send the correct SNI, not by holding Apache on an old version.
1. What 421 Misdirected Request means
HTTPS carries the site name twice: once in the TLS handshake (SNI, Server Name Indication) and once in the HTTP Host header. The server uses them to pick the right website and certificate. When they disagree, or when a connection set up for one site is reused for another, the server answers 421 Misdirected Request instead of guessing. The status is defined in the HTTP standard (RFC 9110), and it is a safety check, not a crash.
| Where you see it | Usual cause | Who fixes it |
|---|---|---|
| Only now and then, and it clears on reload | The browser reused one HTTP/2 connection for two sites; it normally retries by itself | Nobody; a reload is enough |
| Every request, through Cloudflare or another CDN | The CDN sends a Host header or SNI that differs from your domain | You, in the CDN's settings |
| Every request, straight to the server | The domain is not set up on the server the DNS points to, or a server-side proxy sends no SNI | Your host, or you on your own server |
| After an Apache update on your own server | Apache 2.4.64 and later check SNI against Host strictly | You, on your server's proxy |
2. If your site is on Domain India shared hosting
You cannot change the web server on shared hosting, but most causes are in settings you control. Work through these in order.
- Reload in a private window.If the 421 disappears, it was a reused connection in your browser, and nothing needs fixing.
- Check for a proxy or CDN.If your domain uses Cloudflare or a similar service, look for rules that override the Host header or the SNI (in Cloudflare, Origin Rules). Remove the override, or make it match your domain exactly.
- Check the SSL mode.With Cloudflare, use Full (strict) and make sure your hosting has a valid certificate for the domain; free AutoSSL or Let's Encrypt certificates are included with our hosting.
- Confirm the domain is on your account.A domain whose DNS points at our server must be added to your hosting account as the main domain, an addon or an alias. If you recently added it, wait for the certificate to be issued.
- Test the headers yourself.Run the command below and note the status line and the time.
curl -s -o /dev/null -D - 'https://yourdomain.com/?t=1' | head -5If the command returns 200 but your browser shows 421, the problem is in the browser or a proxy between you and us. If it returns 421 too, open a ticket.
We tested sites on our cPanel and DirectAdmin servers on 24 September 2026, and they answered normally, with no 421 responses. The July 2025 Apache issue is not affecting Domain India shared hosting. If you see a 421 on one of our servers, it is specific to your site's setup, and support will look at it with you.
When you open a ticket, include the full address, the time you saw the error, whether Cloudflare or another proxy is in front, and the output of the command above. That lets support read the server logs for exactly that request.
For Cloudflare settings in general, see Cloudflare setup for Indian websites. For certificates, see how to enable free SSL.
3. Own server: the Apache 2.4.64 case
This section is for readers who run their own VPS or server with Apache behind a reverse proxy, such as cPanel's EA-Nginx, HAProxy, Varnish with an HTTPS backend, or a CDN. On shared hosting none of this is in your hands.
What changed
Apache 2.4.64, released in July 2025, included a security fix that makes mod_ssl check that the SNI name of the TLS connection matches the Host of each request. A reverse proxy that connects to Apache over HTTPS without sending SNI, or with a different name, started receiving 421 for every site. cPanel servers with EA-Nginx and sites behind CDNs with host overrides were hit widely.
The proper fix: send the right SNI
Configure the proxy to pass the requested host name in the TLS handshake. For nginx proxying to an HTTPS backend:
proxy_ssl_server_name on;
proxy_ssl_name $host;
proxy_set_header Host $host;HAProxy has an equivalent sni option on the server line, and most CDNs have a setting for the origin SNI. Keep the Host header and the SNI identical. On a cPanel server, first bring EasyApache 4 and ea-nginx fully up to date and test again; a current system may need no manual change.
Why not downgrade and lock Apache
Older advice was to downgrade to 2.4.63 and version-lock the package. That removes the 421, but it also removes the security fixes, and every later Apache release (with further fixes) is blocked until someone remembers to unlock it. Treat a lock as a stopgap of days, not a fix. If you used one, list and remove it once the proxy sends SNI:
dnf versionlock list
sudo dnf versionlock delete ea-apache24
sudo dnf updateSee How to version-lock RPM packages for how locks work.
Test it
From the server, request each site through the proxy and directly with the correct SNI:
curl -sk -o /dev/null -w '%{http_code}\n' --resolve example.com:443:127.0.0.1 https://example.com/A 421 here, with a 200 from the public address, points at the proxy's SNI settings; the Apache error log shows an AH02032 line naming the host sent via SNI and the host sent via HTTP.
4. Where Domain India fits
On Domain India shared hosting the web server stack is managed for you, so updates like this one are handled on our side. If you need to run your own proxy and Apache configuration, a VPS gives you root access and is self-managed. The cards show live prices, excluding 18% GST.
- 25 GB NVMe SSD Storage
- 50 GB Monthly Bandwidth
- 1 Website
- 10 Email Accounts
- 1 vCPU
- 2 GB DDR4 RAM
- 64 GB NVMe SSD Storage
- 2 TB Monthly Bandwidth
Frequently asked questions
What does 421 Misdirected Request mean?
The server received a request for a site name that does not match the connection it arrived on, usually because the TLS SNI name and the HTTP Host header differ. The server refuses rather than serve the wrong site.
Why did 421 errors appear after Apache 2.4.64?
Apache 2.4.64, released in July 2025, added a security fix that checks the SNI name against the Host header. Reverse proxies that connected to Apache over HTTPS without sending SNI began receiving 421 for every request.
Is my Domain India shared hosting site affected by the Apache 2.4.64 issue?
No. We tested sites on our cPanel and DirectAdmin servers on 24 September 2026 and they answered normally. A 421 on shared hosting points to your site's own setup, such as a CDN rule or a domain not added to your account.
Can Cloudflare cause a 421 error?
Yes, when a rule overrides the Host header or the SNI sent to your server with a different name. Remove the override or make it match your domain, and use Full (strict) SSL with a valid certificate on the hosting.
Should I downgrade Apache to fix a 421 on my own server?
Only as a short stopgap. A downgrade and version lock removes security fixes. The proper fix is to make the reverse proxy send the correct SNI, for example proxy_ssl_server_name on in nginx, and to keep Apache up to date.
The 421 disappeared when I reloaded. Do I need to do anything?
No. Browsers sometimes reuse one HTTP/2 connection for two sites, receive a 421 and retry on a new connection. If it happens once and clears on reload, nothing needs fixing.
Ready to check your site? Run the test in section 2, or open a support ticket with the address, the time and the command output.
Send us the page address, the time of the error and whether a CDN is in front, and we will read the server logs for that request with you.
Open a support ticket