# CDN (Content Delivery Network)

> A CDN is a network of edge servers that cache and serve responses near users. See how cache hits show up in headers and what CDNs do not cache by default.

Source: https://howhttpworks.com/glossary/cdn
Last reviewed: 2026-10-04

> **TL;DR:** A CDN is a fleet of reverse proxies spread across regions that cache your responses and serve them from the nearest edge, so most requests never reach your origin server.

A content delivery network (CDN) is a geographically distributed set of caching reverse proxies. Browsers connect to a nearby edge server; on a cache hit the edge answers directly, and on a miss it fetches from your origin, stores the response according to its caching headers, and returns it.

## What a hit looks like

```http
HTTP/1.1 200 OK
Content-Type: text/css
Cache-Control: public, max-age=31536000, immutable
Age: 4312
CF-Cache-Status: HIT
```

`Age` is the number of seconds the response has sat in a shared cache, as defined by RFC 9111. The status header is vendor-specific: Cloudflare uses `CF-Cache-Status`, CloudFront uses `X-Cache: Hit from cloudfront` plus `X-Amz-Cf-Id`, and other vendors use their own `X-Cache` variants. No `Age` on a response you expected to be cached usually means a miss or a bypass.

## Non-obvious facts

- **A CDN follows your caching headers, then its own rules.** `Cache-Control: s-maxage` applies to shared caches such as CDNs only, so you can give the edge an hour while browsers revalidate every time. `private` and `no-store` keep a response off the edge.
- **HTML is often not cached by default.** Cloudflare, for example, caches by file extension and does not cache HTML unless a cache rule says so. If pages are slow, check this before blaming the network.
- **`Vary` fragments the cache.** `Vary: Accept-Encoding` is fine; `Vary: User-Agent` or `Vary: Cookie` can drop the hit ratio to near zero because every distinct value gets its own entry.
- **A CDN adds another place to debug.** A 502 or 504 may come from the edge, not your server. Compare headers such as `Server`, `Via` and `CF-Ray` with a request made directly to the origin.
- **Purging is not instant everywhere.** Invalidations take time to propagate across the network, so versioned asset URLs are more reliable than purging.

## Go deeper

- [Cache-Control header](https://howhttpworks.com/headers/cache-control)
- [Age header](https://howhttpworks.com/headers/age)
- [X-Cache header](https://howhttpworks.com/headers/x-cache)
- [Vary header](https://howhttpworks.com/headers/vary)
- [Reverse proxy](https://howhttpworks.com/glossary/reverse-proxy)
