What is a Cache-Control header?
Directives that caches (browsers, proxies, CDNs) must follow for both requests and responses, such as how long a response may be reused.
Cache-Control is the single most consequential header for how a website actually performs in the real world - get it wrong and visitors either see stale content long after you've published a fix, or your origin gets hammered by requests that should have been served from a cache. Because a caching misconfiguration often looks fine in a quick manual check and only shows up under real traffic, it's exactly the kind of slow-burn problem an uptime monitor tracking response times and status codes over weeks, not seconds, is built to catch.
Common use case
Setting max-age on static assets (images, CSS, JS bundles) so browsers and CDNs reuse them for days without re-fetching, while marking API responses no-store so sensitive data is never cached.
Example
Cache-Control: max-age=31536000, public, immutableHistory
Introduced in HTTP/1.1 (RFC 2068, 1997) to replace the more limited Pragma and Expires model from HTTP/1.0, and refined further in RFC 7234 (2014) and RFC 9111 (2022).
Did you know?
The immutable directive, added later via a separate spec, tells the browser not to even revalidate the file on a hard refresh - a small addition that measurably speeds up repeat page loads for fingerprinted asset URLs.