Browser folks/HTTP client folks I have a quandary: if a request is made to example.ORG, with a Host:example.COM header, should cookies for example.ORG or example.COM be sent? Or neither/both? /cc

@dshafik Where are they about to end up? Probably

@dshafik The Host: header is used by the HTTP server to determine what gets served. If you GET / by asking “” but say “Host:” then the origin is

The UA is expected to use the vhost (Host header), not the DNS name used. The domainspec on the cookie itself must then be unspecified or exactly “”. See for more.

