---
title: "Varnish headers"
date: "2024-02-14T06:18:38+00:00"
summary: "Explore Varnish headers on Cloud Platform to optimize caching and boost website performance. Learn to analyze and leverage key headers."
image:
type: "page"
url: "/acquia-cloud-platform/varnish-headers"
id: "28e7d24e-9b52-4d7c-b1c0-e4a6edeb7fb7"
---

Cloud Platform uses Varnish® caching to increase an application’s perceived performance for visitors. For more information about Varnish, see [Using Varnish](/acquia-cloud-platform/performance/varnish). Using developer tools integrated with your browser, you can examine the Varnish caching headers sent with each page and item request to see how Varnish caching is working with your application.

To examine what Varnish is doing (or not doing) on one of the pages in your application, examine the values of the Varnish cache headers for the page.

Important

Varnish HTTP response headers are appended by Cloud Platform and cannot be removed. However, it might be possible to remove these headers by using a Web Application Firewall like [Acquia Edge](/service-offerings/edge-product-guide "Edge Product Guide").

To view these headers, use one of the [development tools](https://webmasters.stackexchange.com/questions/8525/how-do-i-open-the-javascript-console-in-different-browsers) available for your web browser to view a served web page’s Varnish headers. Your installed browser may already include a set of development tools that you can use. You can also run the following command from a command prompt:

    curl -sSLIXGET urlname

The following are some of the headers you should see:

Header

Description

`Age`

The amount of time the served item was in the cache, in seconds. If the age is zero, the item was not served from the Varnish cache.

`Cache-Control`

The directives that must be applied by all caching mechanisms, from Varnish to the browser cache.

If the field has the value `no-cache, must-revalidate, post-check=0` or `pre-check=0`, this item instructs any upstream proxy layers (such as Acquia load balancers or a CDN) to not cache. This header generally is used when Drupal page caching is disabled. Acquia recommends you verify this value is present on all of your website’s pages. If it is, enable caching, and consider using [Acquia Purge](/acquia-cloud-platform/help/94206-installing-acquia-purge-drupal-7x "Installing Acquia Purge for Drupal 7.x") for cache invalidation.

Note

If the `Cache-Control` header contains both `s-maxage` and `max-age` values, Varnish uses `s-maxage` to determine the cache lifetime for that request.

`Server`

The web infrastructure application (currently `nginx`) that acts as a load balancer to serve the content.

`Vary`

The inbound HTTP request headers that need to be taken into account when caching a single URL. The most common example is `Accept-Encoding` – a header that browsers usually send to websites to indicate whether they want the returned page compressed using `gzip` or the `deflate` compression algorithm. This can prevent serving gzip-compressed pages from cache to older browsers that do not support it.

`Via`

The web infrastructure application (currently `Varnish`) over which the request was sent.

`X-Acquia-Stripped-Query`

The query strings that have been stripped from the URL, if any. For more information, see [Stripping query strings in Varnish](/acquia-cloud-platform/performance/varnish/querystrings).

`X-AH-App-Trace`

A response header added when a request is forwarded to PHP-FPM. If PHP-FPM was not needed to serve this request, this header is not added.

`X-AH-Environment`

The Acquia environment that provides the page response. Usually `prod`, but could also include values such as `dev` or `stage`.

`X-Cache`

Either `HIT` or `MISS` depending on whether or not the item was served from the Varnish cache.

`X-Cache-Hits`

The number of times this object has been served from cache. Higher numbers indicate that this URL has received more visitors.

`X-Drupal-Cache`

Similar to `X-Cache`, this header indicates the outcome of Drupal’s page cache with `HIT` or `MISS` values. A `MISS` value is not unusual here. For more information about Drupal cache `MISS`, see [Varnish cache HITS and Drupal cache MISS](/acquia-cloud-platform/help/92591-varnish-cache-hits-and-drupal-cache-miss "Varnish cache HITS and Drupal cache MISS").

`X-Forwarded-For`

The originating IP address for a request.

`X-Generator`

The software used to create the page. On Cloud Platform, this says `Drupal` along with the version number of Drupal core.

`X-Geo-Country`

The two-letter ISO-3166–1 alpha-2 country code. Available only for Cloud Platform Enterprise and Site Factory subscriptions with dedicated load balancers. For more information, see [Using GeoIP information](/acquia-cloud-platform/develop-apps/drupal-apps/geoip).

`X-Request-ID`

The request ID for a given request. For more information, see [Using HTTP request IDs](/acquia-cloud-platform/develop-apps/drupal-apps/requestid).

`X-Static-Assets`

Certain non-HTML static assets have cookie headers removed, and receive the HTTP request header `X-Static-Asset: True`. For more information, see [Stripping cookies from static files](/acquia-cloud-platform/performance/varnish/files#cookies-stripped-static-files).

`X-UA-FCF`

Either `allow` or `deny` depending on whether or not the user has followed a link from Google, Facebook, or LinkedIn. To use the value of this header to construct a paywall or registration wall, see [First Click Free support in Varnish](/acquia-cloud-platform/performance/varnish/firstclickfree).

Other headers
-------------

### X-Acquia-No-301-404-Caching-Enforcement

By default, the Acquia Platform Varnish configuration caches all HTTP 301 (redirect) and HTTP 404 (not found) responses for a minimum of 15 minutes. If the application sends a max-age value greater than 15 minutes, Varnish uses the application value. If the application max-age is less than 15 minutes, Varnish overrides it to 15 minutes (900 seconds).

To override this behavior and give the application full control over caching for 301 and 404 responses, set the following response header in your application:

    X-Acquia-No-301-404-Caching-Enforcement: 1

When this header is present, Varnish does not modify any of the response headers for 301 and 404 responses. The application’s max-age value is used without modification.

Note

Setting this header does not disable caching of 301 and 404 responses. The responses are still cached by Varnish, but the application controls the cache lifetime instead of Varnish enforcing the 15-minute minimum.

For example, if a site's Drupal cache maximum age (_system.performance > cache > page > max\_age_) is set to 60 seconds:

*   With X-Acquia-No-301-404-Caching-Enforcement: 1 set - a 404 response returns Cache-Control: max-age=60, public (the site's 60-second cache duration is used).
*   Without the header - the same 404 response returns Cache-Control: max-age=900, public (Varnish overrides to the 15-minute minimum).

### How to set this header

Set this header in PHP code. For example, add the following line to your settings.php file:

    header
    (
    'X-Acquia-No-301-404-Caching-Enforcement: 1'
    )
    ;

Important

On Cloud Classic, mod\_headers directives in .htaccess files are not applied to PHP/Drupal requests — they only apply to static files. Because this header must be present on responses generated by PHP/Drupal, do not use .htaccess to set this header on Cloud Classic. Use PHP code instead.

On Cloud Next, mod\_headers directives in .htaccess are applied to PHP/Drupal requests, so you can use either PHP code or .htaccess. For consistency across environments, using PHP code is recommended. For more information, see [Known issues in Cloud Next](/acquia-cloud-platform/known-issues-cloud-next "Known issues in Cloud Next").

### Verifying the header

To confirm the header is working, use curl to request a non-existent path and check the response headers:

    curl
    -sILXGET http://your-site.prod.acquia-sites.com/invalid-path

If the header is set correctly, you should see X-Acquia-No-301-404-Caching-Enforcement: 1 in the response headers, and the Cache-Control max-age should reflect your site's configured cache duration rather than 900 seconds.