A content delivery network (CDN) is a network of servers spread across many cities. It keeps copies of your site’s files, such as images, stylesheets, scripts and sometimes whole pages, and serves each visitor from the location nearest to them.
A CDN makes a site faster for distant visitors and takes load off your own server. Your server stays the origin, the source of truth; the CDN’s edge servers hold cached copies.
CDN in one sentence
A content delivery network is a network of servers spread around the world that keeps copies of your site’s files close to visitors, so each visitor is served from nearby instead of from your one server.
Why distance matters
Data travels fast, but not instantly. A request from Sydney to a server in London and back takes around 250 milliseconds before any work is done, and a page needs many requests. Serving from an edge server in Sydney cuts that to a few milliseconds.
How it works
- You point your domain (or a subdomain) at the CDN, usually by changing DNS.
- A visitor’s request goes to the nearest edge server.
- If the edge has a fresh copy, it answers straight away (a cache hit).
- If not (a cache miss), it fetches the file from your origin, keeps a copy, and answers.
How long copies are kept is set by cache headers your server sends, or by rules in the CDN.
What else CDNs usually do
- Absorb traffic floods and many denial-of-service attacks.
- Handle HTTPS at the edge.
- Compress files and convert images to modern formats.
- Keep serving cached pages for a while if your origin goes down.
Two ways to set one up
| Setup | How | Caches | Example |
|---|---|---|---|
| Full-site proxy | Change your domain’s nameservers or DNS to the CDN | Static files, and pages if you allow it | Cloudflare, and most CDNs’ “full site” modes |
| Static files only | Serve images, CSS and scripts from a CDN hostname such as cdn.example.com | Static files only | A CDN “pull zone” pointed at your origin |
A full-site proxy is easier and brings security features, but every request goes through the CDN. A static-only CDN leaves your main domain untouched and is simpler to remove.
Cache headers decide what is kept
The CDN follows the Cache-Control header your server sends with each file. For files whose names change when their content does (such as style.css?v=123 or app.4f9a2c.js), a long time is safe:
location ~* \.(css|js|woff2|webp|jpg|png|svg)$ {
add_header Cache-Control "public, max-age=31536000, immutable";
}
For HTML pages, which change, either do not cache at the CDN or cache briefly and purge when you publish. Check what a CDN did with a request by looking at its response headers:
curl -sI https://example.com/style.css | grep -iE "cache|age|cf-"
Cloudflare reports cf-cache-status: HIT or MISS; other CDNs use x-cache or similar.
Things to know
- Changes take a moment. After updating a file, purge it from the CDN cache, or use versioned file names.
- Logged-in pages should not be cached. Shops, dashboards and account pages must pass straight through to the origin.
- Your server sees the CDN’s address. Configure it to read the real visitor IP from a header such as
X-Forwarded-For, or logs and rate limits will treat everyone as one visitor.
When a CDN is worth it
- Visitors are spread across countries or continents.
- Pages are heavy with images or video.
- The site gets traffic spikes, from news coverage or campaigns.
- You want protection from floods and bots without running it yourself.
For a local business whose visitors are all in one city, with a server in the same country, a CDN adds less. Good caching on the server matters more.
Errors that come from the CDN
When the CDN cannot reach your origin, visitors see the CDN’s error page, not yours. A Cloudflare-branded 502 or 504 means the CDN is fine and your server is not; see 502 Bad Gateway and 504 Gateway Timeout. An HTTPS setting mismatch between the CDN and your server causes redirect loops.
Related
Something out of date? Software changes. If a step no longer works, tell us and we will check it and update the page.

