Origin shield

Updated 1 Oct 2026

The origin shield puts one of our locations between your origin and the rest of the network. With a Home PoP chosen, only that location fetches from your origin; every other location fetches through it, and a file fetched once is served to all of them from its cache, so your origin sees one location instead of all of them and its traffic falls to roughly one fetch per file. The same applies to the pieces of a large file and to the background refresh of a file that has expired.

Choosing a Home PoP#

Home PoP, in the Origin Shield box on the zone page, offers Auto Detect, Off and every location by name. Pick the location nearest your origin, since every fetch passes through it, or choose Auto Detect and it is measured and chosen for you. From the API the setting is HOME_POP: a location id from Locations, auto, or an empty string for off; HOME_POP_LOCATION reports the location in use.

Auto Detect#

Every location measures its round trip to your origin every five minutes, and the location with the shortest becomes the Home PoP. The note under the box names the location in use. Another location takes over only when it is clearly nearer, at least 20% and 5 milliseconds shorter, so two locations at a similar distance never trade the zone back and forth; a location that can no longer reach your origin, or that is out of service, hands the zone to the next nearest. Switched on from a location you had picked, that location stays until the measurements say otherwise; switched on from Off, every location fetches from your origin directly until the first measurements arrive, within about ten minutes. The measurement is a connection that opens and closes, three times from each location, and nothing is requested.

When the Home PoP cannot answer#

If the Home PoP is offline, or a fetch through it fails or comes back with a 5xx or a 403, the location that wanted the file fetches it from your origin directly and carries on; your origin just sees more than one location until it is back. Any other answer through the Home PoP is your origin's answer, relayed: a 404 through the shield is your 404.

What goes through it#

Every GET and HEAD: fetches to fill the cache, the pieces of large files, the refresh of expired files, and a request passed straight through because of a cookie or an Authorization header. Only a POST, PUT, PATCH, DELETE or OPTIONS goes to your origin directly.

What the statistics show#

The zone's statistics gain an Origin Shield chart of the bytes the Home PoP sent to the other locations, with the number of requests it answered for them above it. That traffic is between our own locations and is neither counted as viewer traffic nor billed. Origin bandwidth is counted where your origin was actually fetched, which with a shield is the Home PoP.

When it helps#

When your origin is far from most of your viewers, when its bandwidth is metered, or when it is a server rather than a store and would rather be asked once. It adds a hop to the first fetch of each file in every location other than the Home PoP, so for a bucket that already sits close to your viewers it can cost a few milliseconds on a cold file and save nothing. It is set per zone.

Ask a human

To
Subject
Docs: Origin shield

Read and answered by the people who build CacheGenie, seven days a week.

Write to us