Hosting Through the Years / 2020 to today: Edge, automation and email grows up

2020 to today: Edge, automation and email grows up

HISTORY

4 min read · 782 words

HTTP/3, built on QUIC, was standardised in 2022 and is now supported by the major browsers and many CDNs. Serverless and edge platforms run small pieces of code close to the visitor. Managed WordPress hosting, with built-in caching and automatic updates, is the default for many small businesses.

Meanwhile, email authentication stopped being optional. Large mailbox providers started requiring SPF, DKIM and DMARC from bulk senders in 2024. And certificate lifetimes have been getting shorter, with the industry moving toward renewals measured in weeks, not years, which makes automation less a convenience and more a necessity.

What links these is a shift of work from people to systems. The tasks that used to be an annual chore, a renewal or a manual configuration, are now expected to run on their own and to be checked by software on the other side. That is good news if your host has done the wiring and a nasty surprise if it has not.

HTTP/3 and QUIC

HTTP/2 multiplexed many requests over one TCP connection, which was a gain, with one weakness: TCP delivers bytes in order, so a single lost packet stalls every stream on that connection until it is resent. On a good wired link you rarely notice. On a phone moving between mobile networks and wifi you do.

QUIC, standardised in 2021, moves transport to UDP and builds reliability, encryption and multiplexing into the protocol itself. Streams are independent, so loss on one does not block the others, and the handshake combines transport and TLS 1.3 setup, saving round trips on new connections. HTTP/3 is HTTP carried over QUIC, published in 2022. It always uses encryption, and it runs on UDP port 443.

HTTP/2HTTP/3HTTP/2TLSTCP (ordered stream)IPHTTP/3QUICTLS 1.3 built in,independent streamsUDP / IP
QUIC folds encryption and reliable streams into one layer on top of UDP, which is why a lost packet no longer stalls everything.

A browser does not know in advance that a site speaks HTTP/3. It connects over TCP first, and the server advertises HTTP/3 with an Alt-Svc header; later visits can use QUIC. You can see the header with curl -sI https://example.com/ | grep -i alt-svc, and if your firewall drops UDP 443 the browser falls back to HTTP/2 without complaint.

Edge, serverless and managed hosting

Serverless platforms let you upload a function and have the provider run it on demand, billing by use, with no server to patch. Edge platforms go a step further and run that code at the CDN's locations around the world, so that redirects, authentication checks or content tweaks happen near the visitor. They suit small, fast, stateless jobs. They suit big databases badly, since the data still lives somewhere in particular.

Managed WordPress hosting grew alongside. The pattern is a plan tuned for one application: page and object caching preconfigured, automatic core and plugin updates, daily backups, and staff who know the usual failures. The trade is less freedom, such as restricted plugins or no shell access on some plans, in exchange for less to maintain. On a plain shared or VPS plan you carry more of that work yourself, which is fine if you enjoy it.

Email grows up

For years, SPF, DKIM and DMARC were recommended and widely skipped. In February 2024 Google and Yahoo began requiring bulk senders to authenticate their mail, with SPF and DKIM in place, a DMARC record published, easy unsubscribe, and low spam complaint rates. Other providers moved in similar directions. The practical meaning is that an unauthenticated newsletter is now likely to land in spam, or be refused.

example.com.         TXT  "v=spf1 include:_spf.mail.example.net -all"
sel1._domainkey      TXT  "v=DKIM1; k=rsa; p=MIIBIjANBg..."
_dmarc.example.com.  TXT  "v=DMARC1; p=none; rua=mailto:[email protected]"

Start DMARC at p=none to collect reports, fix the legitimate senders that fail, then tighten to quarantine and reject. The SPF builder and DMARC builder write the records for you.

Shorter certificate lifetimes

Certificate validity has been shrinking for years. Browsers stopped trusting certificates valid for more than 398 days from September 2020, and the industry has agreed a schedule that steps the maximum down to 200 days, then 100, then 47 by 2029. Let's Encrypt, with its ninety days, was ahead of the curve.

Maximum certificate lifetime, in days202039820262002027100202947
Each step cuts the window in which a stolen or mistaken certificate stays valid, and removes the option of renewing by hand.

Nobody renews 47-day certificates by hand eight times a year. If your certificate is issued by ACME, check that renewal runs on its own and that you are told if it fails. The SSL expiry tool and openssl s_client -connect example.com:443 -servername example.com | openssl x509 -noout -dates will show the dates.

If a task has a calendar reminder, ask whether it could have a cron job instead. The cron helper writes the schedule.
Previous2018: Privacy law reshapes the registryNext2020: A sudden shift online

More from Hosting Through the Years

History

1993 to 1996: The first hosts

The NCSA's Mosaic browser appeared in 1993 and made the web visible to people who were not computer...

History

2016: When DNS fell over

In October 2016, a huge botnet built from poorly secured cameras and routers directed a flood of traffic at...

History

2018: Privacy law reshapes the registry

When the European GDPR came into force in May 2018, the public WHOIS system, which listed names, addresses...