A protocol mirror
Every copy of this page is assembled at the moment you request it, and the edge writes the facts of your own connection into the HTML — protocol version, transport, address family, even the round-trip time it measured to you. Visit over HTTP/3 and the card above turns green.
It is the HTTPS sibling of http.alpagot.net, which lives at the opposite end of the security spectrum. Both share the same trick: an origin-less Fastly VCL service where every byte is a synthetic response.
alt-svc: upgrade after the fact
HTTP/3 runs over QUIC — encrypted, multiplexed, and on UDP rather than TCP. But a browser cannot simply guess that a server speaks it. The standard mechanism is an upgrade offer: your first connection rides HTTP/1.1 or HTTP/2 over TCP, and the response carries an alt-svc header advertising that h3 is available on UDP 443. The browser remembers, and switches to QUIC for subsequent connections.
On Fastly that offer is a service setting, or a single line of VCL — h3.alt_svc(); in vcl_recv — as covered in the HTTP/3 enablement guide. It works well, but notice the catch: the first connection never benefits. You pay the TCP toll once per host, per cache lifetime, per network change, just to learn that you did not need to.
Fastly also runs a public client tester at http3.is if you want a second opinion on your browser.
DNS type 65: know before you connect
There is a better question than “upgrade me if you can” — and it is asked of DNS, not the server. Alongside A and AAAA lookups, modern clients also query the HTTPS record (type 65, defined in RFC 9460). The answer describes how to connect before any connection exists: which protocols the endpoint speaks, and even IP hints to skip follow-up lookups.
This hostname CNAMEs to a Fastly-managed DNS map, and the map answers the type-65 question itself:
That alpn="h3,h2" is the whole trick. A client that honours it can open a QUIC connection on first contact — no TCP bootstrap, no alt-svc memory, one round-trip handshake (zero on resumption). If the card at the top of this page was green on your very first visit, your resolver and browser did exactly this dance.
Two honest caveats. Client support is uneven — Apple platforms adopted HTTPS records earliest, other browsers vary in when and how they use them (some only via DNS-over-HTTPS). And the map-level record itself is behaviour I have observed on Fastly’s managed DNS maps rather than something in the public documentation yet, so treat the details as subject to change.
Watch both paths happen
Ask DNS the type-65 question yourself:
dig -t HTTPS h3.alpagot.net +short
Then force the protocol from the command line — curl --http3-only -sv https://h3.alpagot.net/ -o /dev/null proves the QUIC path end to end, while dropping the flag lets curl take the TCP road for comparison.
In a browser, the demo is simply this page: load it, note the card, reload. If your first visit landed on HTTP/2, the alt-svc offer has already been planted and the reload should come back green. Your devtools network panel will agree with the card — look for h3 in the protocol column.
No origin here, either
Like its sibling, this site has no web server behind it. The whole thing is a Fastly VCL service: requests are routed to vcl_error, where the page — and robots.txt, llms.txt, security.txt, sitemap, icons via synthetic.base64 — is written straight into the response at the POP nearest you, then brotli-compressed on the way out.
The live card is the new trick. In vcl_recv, the service reads Fastly’s client-connection variables — fastly_info.is_h3, the quic.* family, req.is_ipv6 — captures them into request headers, and the synthetic interpolates them into the HTML. When you arrive over QUIC, the round-trip time shown above is quic.rtt.smoothed: the edge’s own live estimate of the distance between you and it, in milliseconds.
Richard Alpagot
Senior Cloud Engineer at Fastly, collector of small sites that explain themselves. This one’s insecure sibling lives at http.alpagot.net.
- websitewww.alpagot.net
- blogblog.alpagot.net
- linkedin/in/alpagot