h3.alpagot.net · port 443 · UDP spoken here

HTTP/3, from the
very first packet.

A live HTTP/3 test page — and a tour of the lesser-known way to get there: not by upgrading, but by asking DNS before you ever connect.

YOUR CONNECTION, MEASURED AT THE EDGE

You arrived over HTTP/2 - the alt-svc offer is now planted. Reload, and your browser should switch to QUIC.

protocolHTTP/2
transportTCP
address familyIPv4
encryptionTLSv1.3
round-trip time~8 ms (TCP smoothed)
edge nodecache-cmh1290107-CMH

Synthesised into this HTML by VCL at the CMH POP — no JavaScript measured anything, the edge simply told you what it saw.

WHAT THIS IS

A protocol mirror

Every copy of this page is assembled at the moment you request it, and the edge writes the facts of your own connection into the HTML — protocol version, transport, address family, even the round-trip time it measured to you. Visit over HTTP/3 and the card above turns green.

It is the HTTPS sibling of http.alpagot.net, which lives at the opposite end of the security spectrum. Both share the same trick: an origin-less Fastly VCL service where every byte is a synthetic response.

THE USUAL PATH

alt-svc: upgrade after the fact

HTTP/3 runs over QUIC — encrypted, multiplexed, and on UDP rather than TCP. But a browser cannot simply guess that a server speaks it. The standard mechanism is an upgrade offer: your first connection rides HTTP/1.1 or HTTP/2 over TCP, and the response carries an alt-svc header advertising that h3 is available on UDP 443. The browser remembers, and switches to QUIC for subsequent connections.

On Fastly that offer is a service setting, or a single line of VCL — h3.alt_svc(); in vcl_recv — as covered in the HTTP/3 enablement guide. It works well, but notice the catch: the first connection never benefits. You pay the TCP toll once per host, per cache lifetime, per network change, just to learn that you did not need to.

Fastly also runs a public client tester at http3.is if you want a second opinion on your browser.

THE FAST PATH

DNS type 65: know before you connect

There is a better question than “upgrade me if you can” — and it is asked of DNS, not the server. Alongside A and AAAA lookups, modern clients also query the HTTPS record (type 65, defined in RFC 9460). The answer describes how to connect before any connection exists: which protocols the endpoint speaks, and even IP hints to skip follow-up lookups.

This hostname CNAMEs to a Fastly-managed DNS map, and the map answers the type-65 question itself:

# ask how to connect, before connecting $ dig -t HTTPS h3.alpagot.net +short alpagot.map.fastly.net. 1 . alpn="h3,h2" ipv4hint=151.101.… ipv6hint=2a04:4e42:…

That alpn="h3,h2" is the whole trick. A client that honours it can open a QUIC connection on first contact — no TCP bootstrap, no alt-svc memory, one round-trip handshake (zero on resumption). If the card at the top of this page was green on your very first visit, your resolver and browser did exactly this dance.

Two honest caveats. Client support is uneven — Apple platforms adopted HTTPS records earliest, other browsers vary in when and how they use them (some only via DNS-over-HTTPS). And the map-level record itself is behaviour I have observed on Fastly’s managed DNS maps rather than something in the public documentation yet, so treat the details as subject to change.

TRY IT

Watch both paths happen

Ask DNS the type-65 question yourself:

dig -t HTTPS h3.alpagot.net +short

Then force the protocol from the command line — curl --http3-only -sv https://h3.alpagot.net/ -o /dev/null proves the QUIC path end to end, while dropping the flag lets curl take the TCP road for comparison.

In a browser, the demo is simply this page: load it, note the card, reload. If your first visit landed on HTTP/2, the alt-svc offer has already been planted and the reload should come back green. Your devtools network panel will agree with the card — look for h3 in the protocol column.

UNDER THE HOOD

No origin here, either

Like its sibling, this site has no web server behind it. The whole thing is a Fastly VCL service: requests are routed to vcl_error, where the page — and robots.txt, llms.txt, security.txt, sitemap, icons via synthetic.base64 — is written straight into the response at the POP nearest you, then brotli-compressed on the way out.

The live card is the new trick. In vcl_recv, the service reads Fastly’s client-connection variables — fastly_info.is_h3, the quic.* family, req.is_ipv6 — captures them into request headers, and the synthetic interpolates them into the HTML. When you arrive over QUIC, the round-trip time shown above is quic.rtt.smoothed: the edge’s own live estimate of the distance between you and it, in milliseconds.

0origin servers
9live edge values in this HTML
1-RTTQUIC handshake (0 resumed)
everyFastly POP serves it
WHO BUILT THIS

Richard Alpagot

Senior Cloud Engineer at Fastly, collector of small sites that explain themselves. This one’s insecure sibling lives at http.alpagot.net.