# DisallowedHost: Invalid HTTP_HOST header How to fix it.

URL: https://antideploy.com/blog/django-disallowedhost-invalid-http-host-header

Django only answers requests for addresses listed in ALLOWED_HOSTS. Add your Antideploy address, and your own domain if you attach one.

**What you see**

```
DisallowedHost at /
Invalid HTTP_HOST header: 'my-app.antideploy.app'. You may need to add
'my-app.antideploy.app' to ALLOWED_HOSTS.
```

## At a glance

- **What it means**: Your address is not allowed
- **The fix**: Add it to ALLOWED_HOSTS
- **Also**: CSRF_TRUSTED_ORIGINS for forms
- **Own domain**: Add it too

Published 7 October 2026. Facts checked 7 October 2026. 1 min read.

## What it means

Django checks the address of every request against a list called `ALLOWED_HOSTS`. When `DEBUG` is off, as it should be online, a request for an address that is not in the list is refused. Your Antideploy address is new, so it is not in your list yet.

## How to fix it

### 1. Add your address to ALLOWED_HOSTS

Use the exact address, or the pattern `.antideploy.app`, which matches every address under it.

**settings.py**

```
ALLOWED_HOSTS = [".antideploy.app"]
CSRF_TRUSTED_ORIGINS = ["https://*.antideploy.app"]
```

### 2. Add CSRF_TRUSTED_ORIGINS for forms

Without it, form submissions over HTTPS can be refused with a CSRF error.

### 3. Add your own domain if you attach one

Add `www.verdant.in`, or your own name, to both settings.

## Django host questions, answered.

Anything else? Write to us and a person answers.

[support@antideploy.com](mailto:support@antideploy.com)

### Is it safe to allow .antideploy.app?

It allows your Django app to answer requests for any address under it. An address under `.antideploy.app` that points to your app is yours. Use your exact address if you prefer to be strict.

### Why did it work locally?

Locally Django allows `localhost` in debug mode.

### Does this error cost anything?

No. It is a response from your app, and a deploy is not involved.

## More guides, and the platform.

Each platform page covers one part of Antideploy: what it does, where it stops and the questions people ask. [See the whole platform](https://antideploy.com/platform), or [all the guides](https://antideploy.com/blog).

- [How to deploy a Django app](https://antideploy.com/blog/how-to-deploy-a-django-app): gunicorn, automatic migrations, ALLOWED_HOSTS, static files and the database setting.
- [How to connect your own domain](https://antideploy.com/blog/how-to-connect-your-own-domain): One CNAME record, HTTPS included. Available from the Go plan. Root domains versus www.
- [Your app built successfully but never started listening on its port](https://antideploy.com/blog/your-app-built-successfully-but-never-started-listening-on-its-port): The app built but never answered on its port. Read PORT, listen on 0.0.0.0 and check the logs.

- [Deployments](https://antideploy.com/platform/deployments)
- [Environment variables](https://antideploy.com/platform/environment-variables)
- [Custom domains](https://antideploy.com/platform/custom-domains)

Facts on this page were checked against the live platform on 7 October 2026.

## Deploy something. Start with one sentence.

Paste one sentence into your coding agent, click Approve once, and get a live link. No card, no trial clock.

To set this up, give your coding agent this sentence:

```text
Set this project up to deploy on Antideploy. Fetch https://antideploy.com/agent.md and follow it.
```
