# Invalid HTTP\_HOST Header

**URL:** <https://forum.djangoproject.com/t/invalid-http-host-header/1011>\
**Category:** Using Django\
**Created:** [January 30, 2020, 9:34am UTC](https://forum.djangoproject.com/t/invalid-http-host-header/1011 "2020-01-30T09:34:47Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![rofr](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.djangoproject.com/rofr/32/671_2.png) [@rofr](https://forum.djangoproject.com/u/rofr)\
**Post date:** [January 30, 2020, 9:34am UTC](https://forum.djangoproject.com/t/invalid-http-host-header/1011/1 "2020-01-30T09:34:47Z")

</div>

Hi,  
I have installed and configured weblate which is based on django. It’s configured for https only and using a letsencrypt certificate. Random attacks on the site using the IP adress as the host header are generating emails. I don’t want these emails so would like to configure so this particular exception is ignored.

The full message can be found here: [https://gist.github.com/rofr/8838ce11126f987bc2de4cbcc501c4ba](https://gist.github.com/rofr/8838ce11126f987bc2de4cbcc501c4ba)

I set the log level to CRITIICAL for the mail\_admins logger, (see line 334) but that didn’t seem to help. Maybe I could get apache2 to deny the request based on the header so the request never reaches django, checking that out now… But if that doesn’t work how would I filter these warnings in the django config?

Regards,  
Robert Friberg

---

<div class="post-metadata">

**Author:** ![takkaria](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.djangoproject.com/takkaria/32/288_2.png) [@takkaria](https://forum.djangoproject.com/u/takkaria)\
**Post date:** [January 31, 2020, 6:40pm UTC](https://forum.djangoproject.com/t/invalid-http-host-header/1011/2 "2020-01-31T18:40:30Z")

</div>

The [Django logging documentation](https://docs.djangoproject.com/en/3.0/topics/logging/#django-security) suggests the following in your LOGGING config:

```auto
'loggers': {
    'django.security.DisallowedHost': {
        'handlers': ['null'],
        'propagate': False,
    },
},

```

---

<div class="post-metadata">

**Author:** ![rofr](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.djangoproject.com/rofr/32/671_2.png) [@rofr](https://forum.djangoproject.com/u/rofr)\
**Post date:** [February 11, 2020, 1:38pm UTC](https://forum.djangoproject.com/t/invalid-http-host-header/1011/3 "2020-02-11T13:38:06Z")

</div>

Thanks, I tried that but then django failed to start. Why pass the string ‘null’? That seems very odd. But it is official documentation so what do I know. Trying with an empty handlers array now and at least I can start the app.

---

<div class="post-metadata">

**Author:** ![rofr](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.djangoproject.com/rofr/32/671_2.png) [@rofr](https://forum.djangoproject.com/u/rofr)\
**Post date:** [February 11, 2020, 1:41pm UTC](https://forum.djangoproject.com/t/invalid-http-host-header/1011/4 "2020-02-11T13:41:39Z")

</div>

Ah, stupid of me. Just read the doc section again and there is a handler named ‘null’ defined a few lines above…

```
'handlers': {
    'null': {
        'class': 'logging.NullHandler',
    },
},
'loggers': {
    'django.security.DisallowedHost': {
        'handlers': ['null'],
        'propagate': False,
    },
},
```
