Response header
< Alt-Svc: h3=":443"; ma=86400Alt-Svc Header: How Browsers Discover HTTP/3
Alt-Svc advertises an alternative protocol for an origin. How h3=":443"; ma=86400 moves browsers to HTTP/3, what clear does, and how HTTPS DNS records differ.
- Direction
- Response
- Category
- Connection management
- Spec
- RFC 7838 §3
On this page
TL;DR:
Alt-Svcis how a server says “I am also reachable over this other protocol or port.” In practice it is the header that moves browsers from HTTP/2 over TCP to HTTP/3 over QUIC, typicallyAlt-Svc: h3=":443"; ma=86400. The first visit still uses TCP unless you also publish an HTTPS DNS record.
What a response looks like
HTTP/2 200
content-type: text/html
alt-svc: h3=":443"; ma=86400
Each entry is protocol-id="authority" plus parameters (RFC 7838 section 3). The protocol id is an ALPN token: h3 for HTTP/3 (RFC 9114), h2 for HTTP/2. The authority is a quoted host:port; leaving the host empty (":443") means the same host as the origin. The port is mandatory, and for QUIC it is a UDP port.
Several alternatives can be listed, most preferred first:
Alt-Svc: h3=":443"; ma=86400, h2=":443"; ma=86400
Parameters
mais the freshness in seconds. The default is 86400 (24 hours). A client subtracts the responseAgefrom it.persist=1asks the client to keep the entry across network changes such as moving from Wi-Fi to cellular. Without it, a client is allowed to drop alternatives when its network configuration changes.clearis a standalone value, not a parameter.Alt-Svc: clearwipes all cached alternatives for the origin.
How the switch to HTTP/3 happens
- The browser connects with TCP and TLS (HTTP/1.1 or HTTP/2) because it cannot know the server speaks QUIC.
- The response includes
Alt-Svc: h3=":443". - For later requests to that origin, the browser attempts QUIC against the advertised endpoint.
- If UDP 443 is blocked (common on corporate networks and some firewalls) or the QUIC handshake fails, the browser keeps using TCP.
This is why “is HTTP/3 working?” checks that look only at the first load are misleading. Reload, or look at the protocol column in DevTools on the second navigation.
Alt-Svc versus the HTTPS DNS record
Alt-Svc is learned after a connection exists. RFC 9460 defines the HTTPS DNS record, which carries the same kind of information (an alpn list such as h3,h2) at resolution time, so a capable client can open QUIC on the very first request.
example.com. 300 IN HTTPS 1 . alpn="h3,h2"
The two are complementary. RFC 9460 section 9.3 covers their interaction: when both are present the client has to satisfy the constraints of both, not treat them independently. Keep them consistent. Advertising h3 in DNS while the server stops answering QUIC gives clients a failed attempt and a fallback on every visit.
Enabling it
nginx (HTTP/3 support arrived in 1.25.0 and needs a build with QUIC; http2 on is the 1.25.1+ syntax):
server {
listen 443 ssl;
listen 443 quic reuseport;
http2 on;
http3 on;
add_header Alt-Svc 'h3=":443"; ma=86400' always;
}
Open UDP 443 in the firewall and security group too. The header alone does nothing if the port is closed. If a CDN terminates TLS for you and has HTTP/3 enabled, check the response for an alt-svc header before adding your own.
Rolling it back
Removing the header does not disable HTTP/3 for clients that already cached the entry; they keep trying until ma expires. To retire QUIC cleanly, send Alt-Svc: clear for at least as long as your previous ma, then stop serving QUIC. A short ma during a rollout (for example 3600) keeps this cheap.
Alt-Used
When a client sends a request over an alternative service it can include Alt-Used: example.com:443 (RFC 7838 section 5) so the server can detect loops and balance load. Do not treat it as authentication.
Verify
curl -sI https://example.com | grep -i alt-svc
curl -sI --http3 https://example.com | head -1
The second command needs a curl built with HTTP/3 support. If it fails while Alt-Svc is present, suspect UDP 443 filtering before suspecting the server config.
Related
Frequently asked questions
What does Alt-Svc: h3=":443"; ma=86400 mean?
It tells the client that the same origin is also reachable over HTTP/3 (ALPN token h3) on UDP port 443 of the same host, and that this claim stays fresh for 86400 seconds (24 hours). Browsers that understand it will try QUIC for later requests to that origin and fall back to TCP if it fails.
Why does my site load over HTTP/2 on the first visit and HTTP/3 afterwards?
A browser has no way to know a server speaks QUIC until it is told. The first connection uses TCP with TLS, the response carries Alt-Svc, and later connections use HTTP/3. An HTTPS DNS record containing alpn=h3 removes that first-visit penalty because the client learns about h3 during name resolution.
What does Alt-Svc: clear do?
It invalidates every alternative service the client has cached for that origin. Send it when you turn HTTP/3 off, so clients stop attempting QUIC against a server that no longer answers on UDP.
What is the default lifetime of an Alt-Svc entry?
RFC 7838 sets 24 hours (86400 seconds) when ma is omitted. The ma parameter overrides it in seconds, and the entry is reduced by the Age of the response that carried it.
Is Alt-Svc a security risk?
The client must verify that the alternative endpoint is authoritative for the origin, in practice by validating a TLS certificate for the origin hostname, so Alt-Svc cannot point a browser at an impostor. The concerns RFC 7838 documents are host hijacking attempts, protocol downgrade, and client tracking through unique alternative identifiers.
Sources
Related
Connection Header
Learn how the Connection header controls whether HTTP connections stay open (keep-alive) or close after each request. Optimize with persistent connections.
Via Header
Learn how the Via header tracks the path of HTTP requests through proxies and gateways. Debug routing issues and understand your network infrastructure.
HTTPS Explained: How TLS Secures HTTP
HTTPS is HTTP over TLS. What the TLS handshake does, how certificates prove identity, what HTTPS hides and what it does not, and how to migrate a site safely.
Accept-Ranges Header
Learn how the Accept-Ranges header tells clients whether your server supports partial content requests (byte ranges) for efficient downloads and streaming.