Driver FixRecommendedSound, Wi-Fi or graphics acting up? Check drivers firstFind missing or outdated drivers fast.Check DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run Scan×
Skip to content
World desk4 min

How to Fix the “Specify a Vary: Accept-Encoding Header” Warning

The warning points to how caches distinguish compressed and uncompressed responses. Check the public response and its serving layer before changing NGINX, Apache, or CDN settings.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The warning means an audit did not find Vary: Accept-Encoding on a response where content may be selected according to a visitor’s compression support. First inspect the response as visitors receive it; then adjust the layer that serves or transforms it. NGINX’s gzip_vary on; or Apache’s compression modules may already handle the header, while a CDN or managed host may control the public response.

What the warning means

Accept-Encoding is a request header: a client uses it to indicate which content encodings it accepts. A server can use that information to choose a compressed or uncompressed representation. Vary is a response header that tells caches which request headers influenced that choice. With Vary: Accept-Encoding, a cache distinguishes responses according to the request’s Accept-Encoding value rather than reusing one representation indiscriminately. See RFC 9110, HTTP Semantics.

RFC 9110 says an origin server “SHOULD generate a Vary header field on a cacheable response when it wishes that response to be selectively reused for subsequent requests.” The warning is a prompt to check the actual response and its serving path. It does not prove that compression is enabled, that every response needs a manually added header, or that the origin server is responsible for the missing field.

Find which layer serves the response

Check the exact URL flagged by the audit, using the same hostname and public path visitors use. The response may be generated or changed by the application, web server, reverse proxy, CDN, or managed host. If the audit is checking a third-party resource, only the party controlling that resource’s host can change its headers; see Kinsta’s explanation of third-party requests.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Origin or application: Check whether it generates compressed and uncompressed responses and whether it already sets Vary.
  • Apache or NGINX: Check compression settings and existing response-header rules.
  • Proxy, CDN, or managed host: Inspect the response after it passes through that service and review its compression and cache configuration.

Do not add a second or overriding header until you know what the current response contains. An existing Vary value may identify other fields that also affect representation selection.

Fix it on NGINX

Google Cloud external Application Load Balancer setup

For the NGINX configuration described in Google Cloud’s Cloud CDN troubleshooting guide, add these directives in the http section of nginx.conf:

gzip_proxied any;
gzip_vary on;

gzip_proxied any; enables compression for requests forwarded by a proxy in this documented setup, and gzip_vary on; adds Vary: Accept-Encoding. The field allows Cloud CDN to keep compressed and uncompressed variants separate; multiple cache fills for the same resource can therefore be expected.

This is guidance for the described Google Cloud proxy arrangement, not a universal NGINX recipe. Confirm that your proxy topology and existing gzip configuration match before applying it. After changing the configuration, restart NGINX using the service-management method for your host so it loads the change. Google identifies /etc/nginx/nginx.conf as a common file location, but installations can differ.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Fix it on Apache

Check the compression modules first

Apache’s mod_deflate and mod_brotli documentation says these modules send Vary: Accept-Encoding for compressed responses so proxies can serve a cached compressed representation only to clients that sent a suitable Accept-Encoding request. If either module handles the flagged response, inspect its public headers before adding a manual rule. Documentation: mod_deflate and mod_brotli.

If a manual header rule is needed

Apache’s mod_headers can modify response fields in server, virtual-host, directory, and .htaccess contexts. Its Header directive supports operations such as append, merge, and set. Apache generally recommends those operations over add, which can create multiple fields with the same name.

Choose the directive and its placement only after checking the response and the site’s configuration. In particular, avoid using set in a way that discards existing Vary dimensions. If compression selection also depends on another request field—for example, a User-Agent-based exclusion—that field may also need to appear in Vary. When the response depends on information outside request headers, Apache’s compression documentation discusses Vary: *; this prevents compliant caches from reusing the response and is a special case, not a general fix.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

When a CDN or managed host is involved

If a CDN or hosting platform produces the public response, an origin-only change may not alter what the audit sees. Check the final response through that provider and review its compression and cache settings. Google’s Cloud CDN guidance demonstrates why the origin and CDN need to handle compressed and uncompressed variants consistently. If you cannot edit server configuration, look for the provider’s controls or ask its support team to confirm which layer sets the public response headers.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Verify the change

  1. Request the exact flagged URL through the same hostname and CDN or proxy path used by visitors.
  2. Inspect the response headers. For a response whose representation is selected based on Accept-Encoding and is cacheable, confirm that Vary includes Accept-Encoding; also check whether the Content-Encoding is appropriate to the request.
  3. Compare requests with different Accept-Encoding values. Confirm that the response and any cached variants are handled according to those preferences.
  4. Recheck the audit target. If the header was already present, investigate another flagged URL, a different response layer, or a third-party resource rather than adding a duplicate rule.

These checks follow the selection and cache-reuse semantics in RFC 9110; Google’s Cloud CDN guide describes separate variants for compressed and uncompressed content.

Apply Vary only to fields that affect the response

Vary helps caches retain negotiated representations side by side, but each additional field can increase the number of cache variants. Apache’s caching guide cautions that high-cardinality fields can produce many duplicate cache entries. Include the request fields that actually influence representation selection, preserve existing dimensions, and avoid adding a blanket list.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.