How HTTP Works

Response header

< Alt-Svc: h3=":443"; ma=86400

Alt-Svc Header: How Browsers Discover HTTP/3

Alt-Svc advertises an alternative protocol for an origin. How h3=":443"; ma=86400 moves browsers to HTTP/3, what clear does, and how HTTPS DNS records differ.

Reviewed 3 min readadvanced4 sourcesTry itMarkdown
Direction
Response
Category
Connection management
Spec
RFC 7838 §3
On this page

TL;DR: Alt-Svc is how a server says “I am also reachable over this other protocol or port.” In practice it is the header that moves browsers from HTTP/2 over TCP to HTTP/3 over QUIC, typically Alt-Svc: h3=":443"; ma=86400. The first visit still uses TCP unless you also publish an HTTPS DNS record.

What a response looks like

HTTP/2 200
content-type: text/html
alt-svc: h3=":443"; ma=86400

Each entry is protocol-id="authority" plus parameters (RFC 7838 section 3). The protocol id is an ALPN token: h3 for HTTP/3 (RFC 9114), h2 for HTTP/2. The authority is a quoted host:port; leaving the host empty (":443") means the same host as the origin. The port is mandatory, and for QUIC it is a UDP port.

Several alternatives can be listed, most preferred first:

Alt-Svc: h3=":443"; ma=86400, h2=":443"; ma=86400

Parameters

  • ma is the freshness in seconds. The default is 86400 (24 hours). A client subtracts the response Age from it.
  • persist=1 asks the client to keep the entry across network changes such as moving from Wi-Fi to cellular. Without it, a client is allowed to drop alternatives when its network configuration changes.
  • clear is a standalone value, not a parameter. Alt-Svc: clear wipes all cached alternatives for the origin.

How the switch to HTTP/3 happens

  1. The browser connects with TCP and TLS (HTTP/1.1 or HTTP/2) because it cannot know the server speaks QUIC.
  2. The response includes Alt-Svc: h3=":443".
  3. For later requests to that origin, the browser attempts QUIC against the advertised endpoint.
  4. If UDP 443 is blocked (common on corporate networks and some firewalls) or the QUIC handshake fails, the browser keeps using TCP.

This is why “is HTTP/3 working?” checks that look only at the first load are misleading. Reload, or look at the protocol column in DevTools on the second navigation.

Alt-Svc versus the HTTPS DNS record

Alt-Svc is learned after a connection exists. RFC 9460 defines the HTTPS DNS record, which carries the same kind of information (an alpn list such as h3,h2) at resolution time, so a capable client can open QUIC on the very first request.

example.com. 300 IN HTTPS 1 . alpn="h3,h2"

The two are complementary. RFC 9460 section 9.3 covers their interaction: when both are present the client has to satisfy the constraints of both, not treat them independently. Keep them consistent. Advertising h3 in DNS while the server stops answering QUIC gives clients a failed attempt and a fallback on every visit.

Enabling it

nginx (HTTP/3 support arrived in 1.25.0 and needs a build with QUIC; http2 on is the 1.25.1+ syntax):

server {
    listen 443 ssl;
    listen 443 quic reuseport;
    http2 on;
    http3 on;

    add_header Alt-Svc 'h3=":443"; ma=86400' always;
}

Open UDP 443 in the firewall and security group too. The header alone does nothing if the port is closed. If a CDN terminates TLS for you and has HTTP/3 enabled, check the response for an alt-svc header before adding your own.

Rolling it back

Removing the header does not disable HTTP/3 for clients that already cached the entry; they keep trying until ma expires. To retire QUIC cleanly, send Alt-Svc: clear for at least as long as your previous ma, then stop serving QUIC. A short ma during a rollout (for example 3600) keeps this cheap.

Alt-Used

When a client sends a request over an alternative service it can include Alt-Used: example.com:443 (RFC 7838 section 5) so the server can detect loops and balance load. Do not treat it as authentication.

Verify

curl -sI https://example.com | grep -i alt-svc
curl -sI --http3 https://example.com | head -1

The second command needs a curl built with HTTP/3 support. If it fails while Alt-Svc is present, suspect UDP 443 filtering before suspecting the server config.

Frequently asked questions

What does Alt-Svc: h3=":443"; ma=86400 mean?

It tells the client that the same origin is also reachable over HTTP/3 (ALPN token h3) on UDP port 443 of the same host, and that this claim stays fresh for 86400 seconds (24 hours). Browsers that understand it will try QUIC for later requests to that origin and fall back to TCP if it fails.

Why does my site load over HTTP/2 on the first visit and HTTP/3 afterwards?

A browser has no way to know a server speaks QUIC until it is told. The first connection uses TCP with TLS, the response carries Alt-Svc, and later connections use HTTP/3. An HTTPS DNS record containing alpn=h3 removes that first-visit penalty because the client learns about h3 during name resolution.

What does Alt-Svc: clear do?

It invalidates every alternative service the client has cached for that origin. Send it when you turn HTTP/3 off, so clients stop attempting QUIC against a server that no longer answers on UDP.

What is the default lifetime of an Alt-Svc entry?

RFC 7838 sets 24 hours (86400 seconds) when ma is omitted. The ma parameter overrides it in seconds, and the entry is reduced by the Age of the response that carried it.

Is Alt-Svc a security risk?

The client must verify that the alternative endpoint is authoritative for the origin, in practice by validating a TLS certificate for the origin hostname, so Alt-Svc cannot point a browser at an impostor. The concerns RFC 7838 documents are host hijacking attempts, protocol downgrade, and client tracking through unique alternative identifiers.

Sources

  1. MDN Web Docs: Alt-Svcdeveloper.mozilla.org
  2. RFC 7838: HTTP Alternative Servicesrfc-editor.org
  3. RFC 9114: HTTP/3rfc-editor.org
  4. RFC 9460: SVCB and HTTPS Resource Recordsrfc-editor.org

Keep going

Browse /search