Threat Level: green Handler on Duty: Johannes Ullrich

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-Cache-Status
Link
Accept-Ranges
CF-RAY
ETag
X-XSS-Protection
Expect-CT
Pragma
X-Powered-By
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
Alt-Svc
P3P
X-Served-By
X-Xss-Protection
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Cache-Status
X-Generator
X-Cacheable
Timing-Allow-Origin
P3p
X-Content-Security-Policy
X-Iinfo
Feature-Policy
Status
X-Envoy-Upstream-Service-Time
Content-Encoding
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
X-CDN
X-AspNetMvc-Version
Upgrade
X-Via
CF-Ray
X-Ws-Request-Id
Access-Control-Max-Age
X-Request-ID
Server-Timing
EagleId
X-Cache-Group
Keep-Alive
X-Turbo-Charged-By
Request-Context
X-Age
X-UA-Device
X-Server-Powered-By
X-Proxy-Cache
X-Backend
X-AH-Environment
X-Robots-Tag
X-Hacker
Report-To
X-Amz-Request-Id
Host-Header
X-Server
X-Amz-Id-2
Grace
X-LiteSpeed-Cache
X-Rq
X-Nginx-Cache-Status
X-Varnish-Cache
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-Dns-Prefetch-Control
X-WebKit-CSP
X-Page-Speed
X-Vhost
X-Ua-Compatible
EagleEye-TraceId
X-Amz-Version-Id
X-Pingback
X-OneAgent-JS-Injection
X-Dispatcher
X-Device
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
NEL
X-Cache-Spec
X-Host
X-Server-Id
Cf-Railgun
X-Node
X-Backend-Server
Accept-CH
X-Readtime
Surrogate-Control
X-Akam-SW-Version
Request-Id
X-Response-Time
X-HW
Xkey
X-Application-Context
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Content-Location
Rating
X-Ruxit-JS-Agent
Accept-Ch-Lifetime
X-Country
X-B3-TraceId
X-Cloud-Trace-Context
Accept-CH-Lifetime
X-Cache-Lookup
X-Trace
X-Url
X-Ac
X-Content-Type
X-TtlSet
X-Vname
X-PC
Allow
X-Clacks-Overhead
X-Mod-Pagespeed
Edge-Control
X-Varnish-TTL
X-ESI
X-Server-Name
Fastly-Restarts
Cache-Tag
X-FastCGI-Cache
X-VARITI-CCR
Service-Worker-Allowed
X-Rack-Cache
X-Element-Page-Cache
Verso
X-Aws-Lambda-Call-Status
X-Upstream
X-MS-InvokeApp
MS-Author-Via
X-GitHub-Request-Id
X-Amz-Rid
Public-Key-Pins
X-Vcap-Request-Id
X-Dw-Request-Base-Id
X-Cached
X-D2id
X-Client-IP
X-Abt-Application-Version
X-Cnection
X-Px
X-Cache-TTL
X-Country-Code
Accept-Ch
Arr-Disable-Session-Affinity
RTSS
X-Navigation-Version
X-Origin-Cache
X-Goog-Hash
Access-Control-Request-Method
X-Powered-By-Plesk
X-NF-Request-ID
X-Kinja-Build
X-Server-Lifecycle-Phase
X-Exp-Variant
X-Exp-Id
X-GoogleNews-Bot
X-Instrumentation
X-Use-Magma
X-Kinja-Server
X-Kinja-Revision
X-Cdn-Fetch
X-Kraken-Loop-Name
X-Kinja
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
AR-SID
AR-ATIME
AR-PoweredBy
AR-Request-ID
AR-CACHE
X-Powered-CMS
X-Version
Display
X-Middleton-Display
Pagespeed
X-Sol
Response
X-Amz-Server-Side-Encryption
X-Middleton-Response
X-LLID
X-MSEdge-Ref
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Kinsta-Cache
X-Edge-Location-Klb
X-Edge
X-RateLimit-Remaining
Nginx-Cache
MRF-Tech
X-B3-TraceId-Primal
Mrf-Cache-Status
TCN
X-Protected-By
X-TTL
X-Jurisdiction
X-Shield-Request-Id
X-HP-Webp
X-HP-Trace-Id
X-T
X-Forwarded-For
X-Content-Security-Policy-Report-Only
S
X-Aspnetmvc-Version
X-Mg-S
Content-MD5
X-Id
Edge-Cache-Tag
X-Mid
Fastcgi-Cache
Realpath
SPIisLatency
SPRequestDuration
Front-End-Https
X-Language
X-Ttl
X-Recruiting
X-Pinterest-Rid
Filters
Pinterest-Version
Pinterest-Generated-By
X-MCACHE
X-CST
X-DynaTrace
Server-Node
X-Request-Received
X-Request-Processing-Time
X-Ruxit-Js-Agent
X-Content
X-Ab
X-Ua-Browser
Server-Name
X-Frontend
X-Correlation-Id
X-HS-Hub-Id
X-HS-Cache-Config
X-ECACHE
X-HS-Content-Id
X-HS-Combine-CSS
SPRequestGuid
X-SharePointHealthScore
X-NWS-LOG-UUID
X-Yandex-Sdch-Disable
X-Ser
X-Ezoic-Cdn
X-Cache-Key
Fusion-Content-Id
Fusion-Component-Id
Fusion-Template-Id
X-Parallel-Accel
Fusion-Source
Fusion-Deployment-Id
Fusion-Content-Source
X-Hits
X-Template
Alternate-Protocol
X-Tt-Trace-Host
X-Tt-Trace-Tag
MicrosoftSharePointTeamServices
Cache-Tags
X-Kong-Upstream-Latency
X-Content-Options
X-Kong-Proxy-Latency
Charset
X-Page-Id
X-Git-Hash
Cleartype
Host
X-B3-Sampled
X-Www-Served-By
X-Geo-Country
X-DIS-Request-ID
X-Debug-Info
X-Hostname
X-Amz-Replication-Status
X-Content-Digest
X-Amzn-Trace-Id
X-Daa-Tunnel
Filterid
X-Accel-Expires
X-Fastly-Request-Id
X-Varnish-Age
X-AppVersion
X-Activity-Id
X-Az
X-FB-Debug
X-Upgrade-Enabled
X-VCache
Cross-Origin-Opener-Policy
X-Forwarded-Proto
TP-Cache
X-Rid
TP-L2-Cache
Access-Control-Allow-Method
X-Grace
X-Nginx-Upstream-Cache-Status
X-N
X-Origin-Server
X-F-Cache
X-LB-Cache
X-Mobile-URL
X-Request-Guid
X-Providence-Cookie
X-Is-Crawler
X-Route-Name
ServerID
X-Flags
X-Aspnet-Duration-Ms
X-Server-ID
X-Whom
X-Ratelimit-Limit
X-GUploader-UploadID
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-TT
X-Goog-Generation
X-Goog-Metageneration
X-XRDS-LOCATION
Viewport
X-Tb
X-App-Environment
X-Varnish-Grace
X-WebKit-CSP-Report-Only
X-Seen-By
X-Distributor
Payment
Node
X-Type
X-FW-Serve
X-FW-Server
X-FW-Static
X-FW-Type
X-FW-Hash
X-Oneagent-Js-Injection
X-FW-Dynamic
X-App-Server
DC
Paypal-Debug-Id
X-User-Agent
X-NGENIX-Cache
Fastcgi-Useragent
X-Origin-Upstream-Status
X-Cache-Control
X-Wix-Request-Id
Country
Accept-Charset
X-Litespeed-Cache
X-Cache-Rule
X-Fastcgi-Cache
X-Logged-In
Version
X-Webkit-CSP
X-DataDome
X-Fastly-Request-ID
X-Request-Handler-Origin-Region
X-Via-JSL
X-Cache-Age
X-Microsite
X-Drupal-Cache-Tags
Referer-Policy
X-Oracle-Dms-Ecid
X-Oracle-Dms-Rid
X-Browser-Type
X-Erf-Bev-Bev-Is-Generated
Amp-Access-Control-Allow-Source-Origin
X-Erf-Bev-Bev
X-Signature
X-Load-Cache
X-Cluster-Name
Refresh
X-B-Cache
X-Contextid
Cache-Status
X-Varnish-Backend
SD-X-WS
VIX-Pulpo-Upstream-Status
X-Original-Request-Id
VIX-Pulpo-Node
X-Mobile
X-Buckets
X-Response-Served-From
Access-Control-Request-Headers
X-Node-Name
X-Is-Bot
X-Proxy-Cache-Status
X-Real-IP
X-Page-View
X-Cache-Expired-At
X-Vgn-Hpd-Reason
X-Rendered-As
X-Cacheable-TTL
X-Jobs
X-B
X-Yottaa-Optimizations
X-RemovedCookies
X-UUID
X-Yottaa-Metrics
X-ProcessESI
X-Revision
X-Cache-Action
NGB
X-Rule
X-Debug
X-Device-Type
X-Instance
X-Drupal-Cache-Contexts
Surrogate-Key
X-Framework
X-G
X-IPLB-Instance
X-Proxy
X-Tec-Api-Root
X-Tec-Api-Origin
X-Tec-Api-Version
X-Debug-IsConnected
X-Debug-IsPreview
X-Cache-Time
Akamai-GRN
X-TEC-API-VERSION
X-Air-Trace-Id
X-Air-Source
X-Air-Hostname
X-TEC-API-ROOT
X-TEC-API-ORIGIN
CF-IPCountry
X-FW-Version
X-Ratelimit-Reset
SID
DynaTrace
X-PressLabs-Stats
GEO-INFO
X-Azure-Ref
Liferay-Portal
X-Nginx-Cache
X-Ms-Request-Id
X-Ms-Version
Count-Hit
X-Accel-Buffering
X-Cache-Operation
Frame-Options
X-Source
X-Presslabs-Stats
Healthy
Uber-Trace-Id
Ms-Operation-Id
X-CDN-Forward
X-RTag
MS-CV
X-XRDS-Location
X-RateLimit-Limit
X-EdgeConnect-Cache-Status
X-APP-VERSION
X-Cache-NGX
Xserver
X-Environment-Context
X-Zen-Fury
Countrycode
X-L-Path
X-Tumblr-Pixel-1
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Tumblr-User
X-Cache-Hit
X-Varnish-Server
X-Mode
X-Backend-Name
Ec-Rule-Version
Cross-Origin-Window-Policy
X-IPS-LoggedIn
X-Region
X-Forwarded-Host
X-Servername
X-Cache-TTL-Remaining
Backend
X-Content-Powered-By
Protected
X-RN-RSRV
X-Rewrite-Enabled
X-Detected-As
Meta-Geo
X-Tid
X-SaId
X-Cache-Type
X-UPSTREAM-Address
X-JoinUs
X-Varnish-Beresp-Grace
Decoy-Debug-TTL
X-Proxied
X-Zipkin-Id
X-Human
X-Hosted-By
X-ShopId
Section-Io-Cache
X-Extlb
Country-Code
Eomportal-Instance
X-Debug-Cache
X-Uri
X-Redis-Cache
X-Sql-Count
X-Sql-Duration-Ms
X-Alternate-Cache-Key
X-Sorting-Hat-ShopId
X-Shopify-Stage
X-Sorting-Hat-PodId
Decoy-Debug-Status
Decoy-Debug-Key
X-Cache-Grace
X-ShardId
X-Routing-Service
Apigw-Requestid
X-PHP-Backend
X-ServerID
X-FB-TRIP-ID
X-PERF
X-Content-Age
X-BYPASS-REASON
X-Cache-Server
X-ApacheServer
Fastly-SSL
X-Storage
X-UA-Device-Type
Cache-Name
X-Status
X-Origin-Date
Mn-Server-Ip
X-ProxyCache-Key
X-Soup
Cache-Tv-Group
X-NCache
X-Via-Fastly
X-ProxyCache-Status
X-No-Session
Url
X-Microcachable
X-Site-Version
X-Adobe-Loc
X-Adobe-Content
X-Hyper-Cache
Selected-Fe
X-Timing-Wait
X-Web-Node
X-PCL
X-SayCDN-TTL
X-OCL
X-Pubstack
X-Akamai-Edgescape
X-Say-TTL
X-Cache-Host
X-Format
X-Proxy-Build
X-Say-Cacheable
Property-Id
X-Section
X-Origin-Hint
X-R9-Blue-Green-Version
TWC-Connection-Speed
X-NYM-Debug-Backend
TWC-Locale-Group
Webcakes-Region
X-Hl-Ver
X-Generation-Time
X-Access
X-Cluster-Node
Webcakes-App-Version
X-Varnishpool
TWC-GeoIP-Country
TWC-GeoIP-LatLong
X-Server-W
TWC-Privacy
TWC-Device-Class
Webcakes-App-Name
LB
DB-Nickname
Content-Secure-Policy
Azure-SiteName
CDN-Uid
Azure-RegionName
CDN-RequestCountryCode
WPO-Cache-Message
WPO-Cache-Status
X-NewRelic-App-Data
Azure-SlotName
Azure-InstanceId
CDN-CachedAt
CDN-EdgeStorageId
CDN-PullZone
Azure-Version
OT-Force-Account-Verify
CDN-Cache
CDN-RequestId
X-LSADC-Cache
X-Azure-Ref-OriginShield
X-Webkit-Csp
X-Be
X-Generated-By
X-TIME
Content-Disposition
SRV
X-Ua
X-Cached-By
X-Nginx-Cache-Key
Source
Cache
X-SRV
X-Trace-Id
X-Ratelimit-Remaining
X-TT-LOGID
X-Bc-Bl
X-Unique-Id
X-LAGOON
X-App-Version
X-Dc
Cache-Hits
Retry-After
X-Origin-CC
X-Origin-TTL
X-GEO
Mime-Version
Xet-Cookie
X-Varnish-Hits
X-Platform-Server
X-Auto-Login
X-Cache-Remote
X-Cdn
X-HTML-Minification-Powered-By
X-Akamai-Transformed
X-Varnish-Hostname
X-TNCMS
X-Loop
HostName
X-Xfnlog-Site
X-S-Maxage
X-Amz-Meta-S3cmd-Attrs
Onion-Location
X-CSRF-Token
ServedBy
X-Cache-Tags
Upgrade-Insecure-Requests
Web-Mar-Node
X-Time
X-Proto
X-Varnish-Cache-Hits
Webserver
X-Request-Time
X-Cache-Var-Map
X-EC-Lua
X-Cache-Var
X-Tumblr-Pixel-3
X-AOL-HN
X-Tumblr-Pixel-2
X-Xrds-Location
X-Tenant
X-Endurance-Cache-Level
X-ECache
N-Cache
X-Time-Microsecs
X-AWS-Id
X-LJ-Flow-ID
X-Edge-Location
From-Origin
X-VWS-Id
WP-Super-Cache
X-Request-Host
X-GG-Cache-Date
X-FireWall-Port
CloudFront-Viewer-Country
X-B3-SpanId
Nel
X-Correlation-ID
X-Origin-Response-Time
X-Mg-Request-UUID
X-Via-NSCOPI
X-Cache-Enabled
A
Expiry
X-D
User-Cache-Control
X-Forwarded-Path
BehaviorPad-Version
Fastcgi-X-Cache-Version
Surrogated-Key
Meta-Geo-Continent
X-External-Request-Id
X-Developer
Vix-Hermes-Req-Id
V-Age
X-Destination
X-CF-Lambda-Fn
X-Application
Pramga
DCR-Decision-By
DCR-Processing-Time-Ms
X-A-Dam
X-A-Dcw
X-Aicache-OS
Redirect-Candidate
X-Aed
X-A-Wwc
X-A-Dgt
Sslversion
Rendered-Blocks
DSUID
Origin
X-CF-Lambda-Version
X-Cache-NE
X-Ckpd-Fst-Backend
X-Cluster
X-Connection-Hash
X-Conf
Mobile-Detection-Method
X-Cache-Date
X-ARC
Odigeo-Trace-Id
X-B-Cookie
X-Block-Status
X-A-Ccd
X-A
X-ND-Cache
X-ScT
X-S
X-Labrador-Cache-Channel
X-SD-PageType
X-Session-Fingerprint
X-Rojux
X-PHP-Host
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Processor
X-Shop-Environment
X-Slack-Backend
X-VG-WebCache
X-Vdms-Version
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
Xc-Version
X-Vdms-Path
X-V-Cache
X-SRCache-Key
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-TIM-N
X-PBS-Appsvrname
X-S-Cookie
X-PAYTM-SRV-ID
X-Ig-Push-State
X-NAPM-TraceId
X-Orig-Expires
X-Gen-Mode
X-Hnp-Log
X-Ftr-Request-Id
X-Qnm-Cache
X-M-Log
X-M-Reqid
Ssr
State
Svr
True-Client-Country-4JS
X-Sucuri-Cache
X-Sucuri-ID
Traceparent
Release
X-Li-Fabric
Origin-EX
X-VServer
X-Viewer-Country
X-Fetched-On
X-Webstats-RespID
L
X-Geo-Header
X-Fastly-Cache
X-Varnish-Beresp-Status
X-Device-Os
Origin-CC
X-Hash
X-Epic-Correlation-Id
Wxu-Next-Region
X-Request-URI
X-RCS-CacheZone
X-Rocket-Nginx-Serving-Static
X-NodeID
Host-ID
X-Proxy-Upstream
X-Old-Content-Length
X-Owner
X-Origin-Expires
X-Cache-Info
X-Policy
X-Forwarded-Site
X-Scheme
X-LI-UUID
X-Men
X-Skip-Cache
Wxu-Next-Hostname
Wxu-Next-Commit
X-Server-IP
X-Served-From
X-Accel-Expires-Debug
X-Core-Mission
X-Mvc-Supplant-Cachable
X-Date
X-Li-Pop
X-Cache-Bucket
X-Amzn-RequestId
X-Amz-Apigw-Id
X-NWS-UUID-VERIFY
CDCHOST
Cmsid
Cmstype
Arc-Country
X-Varnish-Ttl
Fastly-Drupal-Html
X-Zone
Environment
X-Magnolia-Registration
X-Handled-By
X-MP-GENERATED-AT
Server-Info
X-Reqid
X-Locale
X-RateLimit-Limit-Second
X-ATG-Version
We-Hiring
Web-Mar-Region
X-HS-Content-Campaign-Id
X-Level-Front-Cache
X-Node-Id
X-Nyt-Route
X-Origin-Time
AKAMAI
X-HN
X-Adobe-Source
X-Irp-Debug
X-Platform
X-Location
Apple-News-Services-Handled
X-Backend-State
X-Cdn-Srv
X-Cdn-Origin
X-Esi-Check
X-Eu-Site
X-Envoy-Decorator-Operation
X-CGP
X-Datadog-Sampling-Priority
X-Csrf-Jwt
X-Core-Value
X-Datadog-Trace-Id
X-Fastly-Backend
X-Cache-Id
X-GeoIP
X-BBC-Edge-Cache-Status
X-Datadog-Parent-Id
X-GeoIP-City
X-Generated-On
X-Bip
X-Cache-Debug
X-Gamma-Serve
X-Gdpr
X-Branch-Name
X-Gzip
X-RateLimit-Remaining-Second
X-Thanos
X-TrackingId
X-UnsetCookies
X-VarnishDD-TTL
PFcat
X-TH-Server
X-Sigma-Backend
X-Sn-Servicetimems
X-Storefront-Renderer-Rendered
Fastcgi-Cache-TTL
X-VG-TLSProxy
HA-Ipaddr
Ha-Gx-Prefs
Gh-Request-Id
Fastly-GeoIP-CountryCode
L5d-Success-Class
Mail-Subject
Machine
Locid
Req-Svc-Chain
X-Thinkindot-L3
X-Request-Start
X-Sigma
Thinkindot-CacheControl-Type
X-Req
X-Region-Sid
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
Thinkindot-CacheControl
Thinkindot-Control
CacheControlHeader
TDXMobile
Server-Host
X-Rocket-Build-Number
X-VC-Cache
X-Developers
X-Tx-Id
X-Rebelmouse-Surrogate-Control
X-DefHash
X-DefElseHash
X-Origin
X-DPWN-IS-SECURE
X-GeoIP-Country-Code
X-GeoIP-Region-Code
X-Qloud-Router
X-FC-Vary-Parameters
X-Varnish-Remaining-TTL
X-Varnish-CookieINHashed-On
X-Varnish-CookieHashed-On
X-NU-AKA-ACS-Version
Fastly-SIE
X-Variation
X-Loc
X-Response-By
X-Worker
X-Backend-TTL
X-Rebelmouse-Cache-Control
Memcached
NGX
NM-Fastcgi-Cache
Adler-Geo
Is-Eu
Platform
Fastly-SWR
AMP-Access-Control-Allow-Source-Origin
X-Trace-ID
X-Ua-Device
X-Varnish-Beresp-Ttl
X-Mvc-Supplant-OutputCached
X-JWT-State
X-Pod-Name
X-Cache-Config
X-CLOUD-TRACE-CONTEXT
Cf-Device-Type
X-Is-Gdpr
X-Has-Esi
X-Amzn-Remapped-Content-Length
X-CS
S-Rt
Magicmarker
X-CACHE-KEY
X-LB-ID
X-Up
X-Datadome
Datacenter
X-NC
CDN
Ms-Author-Via
X-Generated-In
Kp-EeAlive
X-API-Version
Pics-Label
Candidate-Md5Url
X-Restarts
Env
X-LB-NoCache
X-Akamai-Request-ID2
Memory
Time
X-Http-Reason
X-Tb-Optimization-Total-Bytes-Saved
X-TraceId
X-RSL
X-RPS
X-RPM
X-DSS
X-DI
X-Optimistic-Header
X-DW
X-Cache-Backend
NtCoent-Length
WebServer
X-DC
X-Via-Poph
X-Via-Popn
X-DB
X-Via-Popv
Edge-Cache
X-Wix-Viewer-Type
X-Action
X-Tt-Logid
X-Cache-Ttl
X-DynaTrace-JS-Agent
X-Vc
On-Server
X-Edge-Pop
WWW-Authenticate
X-Refresh
Accept-Language
X-TA-CDN-Provider
X-CacheTTL
X-Parent-Response-Time
X-Minions-Version
Esi-Enabled
GeoIp-Country-Code
X-Servedbyhost
X-HA-Backend
X-Esi
X-Srv
X-Varnish-Beresp-TTL
X-Unique-ID
X-Service
Server-ID
C-Via
X-MSEdge-Flight
X-MSEdge-Features
X-Cs
X-Cache-PHP
X-Urbn-Context-Path
X-Urbn-Site-Id
Locale
X-Newrelic-Synthetics
X-ZONE
X-TX-ID
X-VCL-Version
X-Ec-Fail
X-Ec-GeoHdr
X-User
X-Webkit-CSP-Report-Only
X-Fpc
X-App
X-Cache-Status-Check
X-Dynatrace
X-Render-Time
X-Traceid
X-LI-Proto
X-URL
Test
X-Webkit-Csp-Report-Only
X-Li-Proto
X-LiteSpeed-Cache-Control
Cdncip
Cdnsip
X-AK-Request-ID
X-FPC
X-B3-Spanid
Proxy-Connection
X-NODE
X-Pass-Why
Cluster
My-App
X-Fmm-Version
X-Vcl-Version
X-WADP-Cache
X-Clara-WADP
Server-Id
X-Mcache
M-TraceId
Resin-Trace
Geoip-Latitude
X-CUA
Tracecode
X-Info
X-Clientip
X-Var-Ttl
X-AIR-PT
Fastly-Drupal-HTML
T-Server
X-Oss-Storage-Class
X-Oss-Hash-Crc64ecma
X-From
X-Oss-Object-Type
X-Oss-Request-Id
X-Oss-Server-Time
HIT
Lfy
UCS
Geo-Info
Cf-Int-Pingora-Origin-Digest
X-LiteSpeed-Tag
Cache-Host
X-CSRF-TOKEN
X-Ha-Backend
GeoIP-Country-Code
S-Cnection
Lang
X-Fragments
X-ID
Hostname
X-Pad
X-WP-CF-Super-Cache-Cache-Control
X-ServedByHost
X-WP-CF-Super-Cache
Target-Params
Ohc-File-Size
Tcn
Hit
X-VC
X-Geo
X-Dynatrace-Js-Agent
DataCenter
X-Micro-Cache
X-RateLimit-Reset
User-Agent
X-Via-PopH
X-Via-PopN
X-Via-PopV
X-ElasticPress-Query
MIME-Version
X-Edge-POP
X-Cdn-Forward
X-RAMCache
Fastly-Backend-Name
X-HostName
X-Edge-Cache
Section-Io-Origin-Time-Seconds
X-Check-Cacheable
X-BBC-Origin-Response-Status
X-Release
X-Api-Version
X-NGINX-Cache
X-Backend-Host
ENV
Section-Io-Id
Section-Origin-Responded
Section-Io-Origin-Status
Load-Balancing
X-Ucs
X-Fastly-Backend-Reqs
X-BCube-Filmed-By
X-Proxy-Cache-Info
X-Httpd
Permissions-Policy
X-Lb-Nocache
Servername
X-ServerName
X-HS-Status
X-APP
URI
FSS-Cache
X-UP
Uri
PICS-Label
ServerName
Producers
X-Provided-By
X-GoCache-CacheStatus
EpKe-Alive
X-TRACE-ID
Lb
CPC-Cache
X-Lb-Id
Path
VNS-Cache
Cache-Key
X-Swift-Error
Cneonction
Cdn
X-Nc
CPC-Age
X-B3-ParentSpanId
Cteonnt-Length
X-WA-Info
X-Udemy-Cache-App-Namespace
Ohc-Cache-HIT
X-Pool
X-Cache-CFC
WZWS-RAY
X-Cdn-Request-ID
X-Fastly-Cache-Hits
VNS-Age
X-Amz-Meta-Cb-Modifiedtime
X-WA
Server-Ttl
X-SB
X-Dw-Trace-Id
X-UA
CF-Cached-On
X-Vcache
X-Wikidot-Backend
X-Akamai-ERRuleID
X-Akamai-ERPolicy
X-Yottaa-OS
X-Snapshot-Date
X-Wikidot-Static-Cache
X-Apw-Access-Action
X-Platform-Cluster
X-Platform-Processor
X-Platform-Router
X-Ec-Custom-Error
X-Akamai-Request-ID
X-Apw-Access-Object
X-Apw-Access-Token
X-Contensis-Viewer-Groups
Vha6-Origin
X-Acquia-Purge-Tags
X-Apw-Hits
X-Acquia-Application-UUID
X-Newrelic-App-Data
X-Acquia-Site
Shield-Pop
X-ES-SERVER
X-Cache-ASPX
Cf-Ipcountry
X-Acquia-Application-Trace
Sid
X-Cache-Ngx
X-Air-Pt
X-PJAX-URL
Pagetype
Ngx
X-Shopify-Generated-Cart-Token
X-Scale
GeoIP-Latitude
X-Sentry-ID
CountryCode
X-Te-Duration-Ms
X-Te-Count
X-Http-Duration-Ms
X-Http-Count
X-Logging-Id
X-Akamai-Pragma-Client-IP
X-Varnish-Authentication
X-Cms-Context
Req-ID
X-Last-Modified
X-CacheKey