Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-Cache-Status
Link
Accept-Ranges
CF-RAY
ETag
Expect-CT
Pragma
X-Powered-By
X-XSS-Protection
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
P3P
Alt-Svc
X-Served-By
X-Xss-Protection
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Cache-Status
X-Generator
X-Cacheable
Timing-Allow-Origin
X-Content-Security-Policy
X-Iinfo
Feature-Policy
Status
X-Envoy-Upstream-Service-Time
Content-Encoding
Access-Control-Expose-Headers
P3p
X-Drupal-Dynamic-Cache
X-CDN
X-AspNetMvc-Version
Upgrade
X-Via
CF-Ray
X-Ws-Request-Id
Access-Control-Max-Age
X-Request-ID
Server-Timing
EagleId
X-Cache-Group
Keep-Alive
X-Turbo-Charged-By
Request-Context
X-Age
X-Server-Powered-By
X-Proxy-Cache
X-UA-Device
X-AH-Environment
X-Backend
X-Hacker
X-Robots-Tag
Report-To
X-Amz-Request-Id
Host-Header
X-Server
X-Amz-Id-2
Grace
X-LiteSpeed-Cache
X-Rq
X-Nginx-Cache-Status
X-Varnish-Cache
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-Dns-Prefetch-Control
X-WebKit-CSP
X-Page-Speed
X-Vhost
X-Ua-Compatible
EagleEye-TraceId
X-OneAgent-JS-Injection
X-Amz-Version-Id
X-Pingback
X-Dispatcher
X-Device
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Cache-Spec
NEL
X-Host
X-Server-Id
Cf-Railgun
X-Node
X-Backend-Server
Accept-CH
X-Readtime
X-Akam-SW-Version
Surrogate-Control
Request-Id
X-Response-Time
X-HW
Xkey
Accept-Ch-Lifetime
X-Ruxit-JS-Agent
X-Application-Context
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
Content-Location
Rating
X-Country
X-B3-TraceId
X-Cache-Lookup
X-Cloud-Trace-Context
X-Trace
X-Url
X-Ac
X-Content-Type
Accept-CH-Lifetime
X-Vname
X-PC
X-TtlSet
Allow
X-Varnish-TTL
X-Clacks-Overhead
X-Mod-Pagespeed
Edge-Control
X-ESI
X-FastCGI-Cache
X-Server-Name
Fastly-Restarts
Cache-Tag
Service-Worker-Allowed
X-VARITI-CCR
X-Rack-Cache
X-Element-Page-Cache
Verso
X-MS-InvokeApp
X-GitHub-Request-Id
X-Upstream
MS-Author-Via
X-Amz-Rid
X-Aws-Lambda-Call-Status
X-Vcap-Request-Id
Public-Key-Pins
X-Cached
X-Dw-Request-Base-Id
X-Client-IP
X-D2id
X-Abt-Application-Version
X-Cache-TTL
X-Cnection
X-Origin-Cache
X-Px
Arr-Disable-Session-Affinity
X-Country-Code
Accept-Ch
X-Navigation-Version
Access-Control-Request-Method
RTSS
X-Powered-By-Plesk
X-Goog-Hash
X-NF-Request-ID
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-Instrumentation
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-GoogleNews-Bot
X-Exp-Id
X-Kinja
X-Kinja-Build
X-Kinja-Server
X-Cdn-Fetch
X-Kinja-Revision
X-Use-Magma
X-Exp-Variant
X-Powered-CMS
X-Version
X-Language
AR-CACHE
AR-PoweredBy
AR-Request-ID
AR-ATIME
AR-SID
Display
Pagespeed
X-Sol
X-Middleton-Display
X-Amz-Server-Side-Encryption
X-Middleton-Response
Response
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-MSEdge-Ref
X-LLID
X-Edge
X-Edge-Location-Klb
X-Kinsta-Cache
X-TTL
Nginx-Cache
X-Template
MRF-Tech
X-B3-TraceId-Primal
Mrf-Cache-Status
X-Protected-By
X-Shield-Request-Id
X-Jurisdiction
X-HP-Webp
X-HP-Trace-Id
TCN
X-T
X-RateLimit-Remaining
X-Forwarded-For
S
X-Content-Security-Policy-Report-Only
X-Aspnetmvc-Version
X-Mg-S
X-Id
Content-MD5
Edge-Cache-Tag
X-Mid
Realpath
Fastcgi-Cache
SPRequestDuration
SPIisLatency
Front-End-Https
X-MCACHE
X-CST
X-Recruiting
X-Request-Received
X-Request-Processing-Time
Pinterest-Version
Pinterest-Generated-By
Filters
X-Pinterest-Rid
Server-Node
X-DynaTrace
X-Ua-Browser
X-Content
X-Ab
Server-Name
X-Frontend
X-Correlation-Id
X-Ttl
X-ECACHE
X-NWS-LOG-UUID
X-HS-Cache-Config
X-SharePointHealthScore
X-HS-Content-Id
X-HS-Hub-Id
SPRequestGuid
Fusion-Template-Id
Fusion-Source
Fusion-Content-Source
Fusion-Deployment-Id
X-HS-Combine-CSS
X-Parallel-Accel
Fusion-Component-Id
Fusion-Content-Id
X-Ezoic-Cdn
X-Yandex-Sdch-Disable
X-Cache-Key
X-Hits
Alternate-Protocol
X-Ser
X-Server-ID
X-Buckets
X-Content-Options
X-Tt-Trace-Host
X-Tt-Trace-Tag
MicrosoftSharePointTeamServices
X-Ruxit-Js-Agent
X-Page-Id
Cache-Tags
Charset
Cleartype
X-Kong-Upstream-Latency
Host
X-B3-Sampled
X-Kong-Proxy-Latency
X-Git-Hash
X-Www-Served-By
X-Geo-Country
X-Daa-Tunnel
X-DIS-Request-ID
X-Accel-Expires
X-Amzn-Trace-Id
X-Content-Digest
X-Amz-Replication-Status
X-Debug-Info
Filterid
X-Varnish-Age
X-Fastly-Request-Id
X-Az
X-Hostname
X-Activity-Id
X-AppVersion
X-Forwarded-Proto
X-FB-Debug
TP-L2-Cache
TP-Cache
X-Upgrade-Enabled
X-VCache
X-N
X-Rid
Access-Control-Allow-Method
X-Grace
Cross-Origin-Opener-Policy
X-Origin-Server
X-Nginx-Upstream-Cache-Status
X-Ratelimit-Limit
X-LB-Cache
X-F-Cache
ServerID
X-Mobile-URL
X-Flags
X-Is-Crawler
X-Providence-Cookie
X-Route-Name
X-Request-Guid
X-Aspnet-Duration-Ms
X-Whom
X-XRDS-LOCATION
X-TT
X-GUploader-UploadID
X-Goog-Generation
X-Goog-Stored-Content-Length
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Varnish-Grace
X-App-Environment
Viewport
X-Tb
Node
X-Seen-By
X-FW-Static
X-FW-Type
X-Type
X-FW-Server
X-FW-Serve
X-App-Server
X-Distributor
X-FW-Hash
Payment
X-FW-Dynamic
X-WebKit-CSP-Report-Only
DC
X-Origin-Upstream-Status
Paypal-Debug-Id
X-User-Agent
X-NGENIX-Cache
Fastcgi-Useragent
X-Cache-Control
Country
Accept-Charset
X-Litespeed-Cache
X-Wix-Request-Id
X-Cache-Rule
X-Logged-In
X-Microsite
X-Request-Handler-Origin-Region
X-Fastly-Request-ID
X-Webkit-CSP
Version
X-Cache-Age
X-DataDome
X-Via-JSL
X-Oracle-Dms-Ecid
X-Oracle-Dms-Rid
X-Erf-Bev-Bev-Is-Generated
X-Browser-Type
Amp-Access-Control-Allow-Source-Origin
Referer-Policy
X-Erf-Bev-Bev
X-Drupal-Cache-Tags
X-Varnish-Backend
Refresh
X-Cluster-Name
X-Node-Name
X-Signature
X-B-Cache
Cache-Status
X-Load-Cache
X-Contextid
X-Response-Served-From
X-Original-Request-Id
X-Mobile
SD-X-WS
Access-Control-Request-Headers
X-Proxy-Cache-Status
X-Vgn-Hpd-Reason
X-Real-IP
X-Rendered-As
X-Cacheable-TTL
X-Cache-Expired-At
X-Page-View
X-Is-Bot
X-Cache-Action
X-Jobs
X-Debug
X-B
X-Instance
X-ProcessESI
X-IPLB-Instance
X-RemovedCookies
X-Revision
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
NGB
X-UUID
X-Fastcgi-Cache
X-Yottaa-Optimizations
X-Proxy
X-Device-Type
X-Rule
X-Yottaa-Metrics
X-G
X-Framework
X-Cache-Time
Akamai-GRN
X-Tec-Api-Version
X-Tec-Api-Root
X-Tec-Api-Origin
X-Drupal-Cache-Contexts
Surrogate-Key
X-Debug-IsConnected
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
X-Debug-IsPreview
X-FW-Version
X-Air-Trace-Id
X-Air-Hostname
CF-IPCountry
X-Air-Source
X-Ratelimit-Reset
SID
DynaTrace
X-PressLabs-Stats
Liferay-Portal
X-Azure-Ref
Healthy
X-CDN-Forward
GEO-INFO
X-Nginx-Cache
X-Oneagent-Js-Injection
Frame-Options
Count-Hit
X-Source
X-Ms-Request-Id
X-Ms-Version
X-Presslabs-Stats
X-Cache-Operation
Ms-Operation-Id
X-Accel-Buffering
X-RTag
MS-CV
Uber-Trace-Id
X-XRDS-Location
X-EdgeConnect-Cache-Status
X-APP-VERSION
X-Tumblr-User
Xserver
X-L-Path
X-Tumblr-Pixel
X-Tumblr-Pixel-1
X-Environment-Context
X-Tumblr-Pixel-0
Countrycode
X-Zen-Fury
X-Cache-Hit
X-Varnish-Server
X-Mode
Ec-Rule-Version
X-Backend-Name
Nel
X-Forwarded-Host
Cross-Origin-Window-Policy
X-Region
X-Cache-NGX
X-IPS-LoggedIn
Backend
X-Servername
X-Content-Powered-By
X-RN-RSRV
X-JoinUs
X-Detected-As
Meta-Geo
X-Rewrite-Enabled
X-UPSTREAM-Address
Protected
X-Cache-TTL-Remaining
X-Cache-Type
X-SaId
Country-Code
X-Shopify-Stage
X-ShopId
X-Cache-Server
X-Sql-Count
X-Redis-Cache
X-Alternate-Cache-Key
Fastly-SSL
X-Routing-Service
X-Zipkin-Id
X-Extlb
X-Generation-Time
X-Hosted-By
X-Human
Section-Io-Cache
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Proxied
X-ShardId
Decoy-Debug-Key
X-NewRelic-App-Data
X-Sql-Duration-Ms
X-Cache-Grace
X-Tid
Eomportal-Instance
Apigw-Requestid
X-Varnish-Beresp-Grace
Decoy-Debug-Status
X-Uri
Decoy-Debug-TTL
X-Debug-Cache
Url
X-BYPASS-REASON
X-ApacheServer
Mn-Server-Ip
Cache-Name
Cache-Tv-Group
X-NYM-Debug-Backend
X-Status
X-Soup
X-FB-TRIP-ID
X-ProxyCache-Key
X-PHP-Backend
X-Storage
X-UA-Device-Type
X-RateLimit-Limit
X-ServerID
X-Site-Version
X-Via-Fastly
X-PERF
X-ProxyCache-Status
X-Origin-Date
X-NCache
X-No-Session
X-Format
X-Microcachable
Selected-Fe
TWC-Connection-Speed
X-Say-TTL
X-Timing-Wait
Property-Id
X-SayCDN-TTL
X-Cluster-Node
TWC-Device-Class
X-Web-Node
X-Section
X-Server-W
TWC-GeoIP-LatLong
X-Access
Webcakes-Region
X-Origin-Hint
X-Proxy-Build
X-Akamai-Edgescape
X-Adobe-Loc
Webcakes-App-Version
Webcakes-App-Name
TWC-Locale-Group
X-PCL
X-Cache-Host
TWC-Privacy
X-OCL
X-Say-Cacheable
TWC-GeoIP-Country
X-Adobe-Content
X-Content-Age
DB-Nickname
SRV
Azure-InstanceId
X-Varnishpool
X-Ratelimit-Remaining
X-Hl-Ver
X-R9-Blue-Green-Version
Azure-RegionName
Azure-SlotName
X-Pubstack
OT-Force-Account-Verify
Azure-Version
Azure-SiteName
X-Be
Content-Secure-Policy
X-Hyper-Cache
CDN-RequestCountryCode
CDN-Uid
X-LSADC-Cache
CDN-RequestId
X-Ua
X-Webkit-Csp
CDN-Cache
CDN-CachedAt
CDN-PullZone
CDN-EdgeStorageId
X-Generated-By
LB
X-Azure-Ref-OriginShield
Content-Disposition
WPO-Cache-Message
WPO-Cache-Status
X-Cached-By
Source
Cache
X-SRV
X-Unique-Id
X-TIME
X-Nginx-Cache-Key
X-App-Version
X-LAGOON
X-TT-LOGID
X-Bc-Bl
X-Trace-Id
X-Auto-Login
Cache-Hits
X-Dc
Xet-Cookie
X-Origin-TTL
X-Origin-CC
X-HTML-Minification-Powered-By
X-Varnish-Hits
X-TNCMS
Retry-After
X-GEO
X-Loop
X-Varnish-Hostname
Mime-Version
X-Time
X-Amz-Meta-S3cmd-Attrs
X-Akamai-Transformed
Onion-Location
X-S-Maxage
X-Cdn
X-Platform-Server
HostName
X-Xfnlog-Site
X-Cache-Var-Map
X-Cache-Var
X-Tumblr-Pixel-3
X-Tumblr-Pixel-2
X-CSRF-Token
X-Cache-Remote
Web-Mar-Node
X-Proto
X-Cache-Tags
Webserver
X-Varnish-Cache-Hits
Upgrade-Insecure-Requests
X-Edge-Location
X-Tenant
X-Endurance-Cache-Level
X-Request-Time
ServedBy
X-Time-Microsecs
X-AOL-HN
X-VWS-Id
X-Xrds-Location
X-EC-Lua
X-ECache
X-LJ-Flow-ID
N-Cache
X-AWS-Id
X-GG-Cache-Date
X-Request-Host
CloudFront-Viewer-Country
WP-Super-Cache
X-FireWall-Port
X-Correlation-ID
From-Origin
X-M-Reqid
X-Mg-Request-UUID
X-B3-SpanId
X-Qnm-Cache
X-M-Log
X-Via-NSCOPI
X-Amzn-RequestId
X-Amz-Apigw-Id
X-PHP-Host
X-Labrador-Cache-Channel
X-Origin-Response-Time
X-NAPM-TraceId
CDCHOST
X-Gen-Mode
Expiry
X-A
X-D
X-Aed
X-Forwarded-Path
X-Ftr-Request-Id
X-ND-Cache
X-Application
BehaviorPad-Version
X-A-Wwc
X-A-Dgt
DCR-Decision-By
X-ARC
DCR-Processing-Time-Ms
X-Block-Status
DSUID
X-B-Cookie
X-Developer
X-Destination
X-A-Dam
X-External-Request-Id
X-A-Dcw
X-Hnp-Log
X-Ig-Push-State
X-A-Ccd
X-ScT
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-TIM-N
Redirect-Candidate
X-V-Cache
A
Rendered-Blocks
Sslversion
X-Slack-Backend
X-SRCache-Key
L
Pramga
X-Vdms-Path
Xc-Version
Mobile-Detection-Method
X-CF-Lambda-Fn
Origin
Meta-Geo-Continent
X-Vtex-Remote-Cache
X-Vdms-Version
X-VG-WebCache
X-CF-Lambda-Version
X-Vtex-Processado-Em
X-Shop-Environment
X-Session-Fingerprint
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
X-Planisys-CDN-TTL
V-Age
X-Processor
X-PBS-Appsvrname
X-PAYTM-SRV-ID
X-Orig-Expires
X-Cache-Date
Odigeo-Trace-Id
X-Connection-Hash
User-Cache-Control
X-Conf
X-S
X-S-Cookie
Surrogated-Key
Fastcgi-X-Cache-Version
X-Ckpd-Fst-Backend
X-Cluster
X-Cache-NE
X-Rojux
X-SD-PageType
X-RCS-CacheZone
X-Handled-By
X-MP-GENERATED-AT
Svr
Ssr
State
Release
PFcat
Origin-CC
Origin-EX
Traceparent
True-Client-Country-4JS
X-Accel-Expires-Debug
X-Backend-State
Wxu-Next-Region
Wxu-Next-Hostname
Wxu-Next-Commit
X-Cache-Bucket
X-Origin-Time
X-Rocket-Nginx-Serving-Static
X-Scheme
X-Served-From
X-Server-IP
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-Origin-Expires
X-Owner
X-Policy
X-Proxy-Upstream
X-Skip-Cache
X-Storefront-Renderer-Rendered
X-Webstats-RespID
Vix-Hermes-Req-Id
X-Aicache-OS
X-Request-URI
X-VServer
X-VarnishDD-TTL
X-Sucuri-Cache
X-Sucuri-ID
X-UnsetCookies
X-Varnish-Beresp-Status
X-Old-Content-Length
X-Nyt-Route
X-Epic-Correlation-Id
X-Eu-Site
X-Fastly-Cache
X-Fetched-On
X-Envoy-Decorator-Operation
X-Device-Os
X-CGP
X-Core-Mission
X-Csrf-Jwt
X-Date
X-Forwarded-Site
X-Gdpr
X-Location
X-Men
X-Mvc-Supplant-Cachable
X-NodeID
X-LI-UUID
X-Li-Pop
X-Geo-Header
X-Hash
X-HN
X-Li-Fabric
X-Cdn-Srv
X-Cache-Info
Gh-Request-Id
X-Locale
Ha-Gx-Prefs
HA-Ipaddr
Host-ID
Fastcgi-Cache-TTL
Cmsid
X-Cache-Enabled
AKAMAI
Arc-Country
CacheControlHeader
L5d-Success-Class
Cmstype
Environment
X-Zone
Fastly-Drupal-Html
X-NWS-UUID-VERIFY
Server-Info
X-Esi-Check
X-Reqid
X-Fastly-Backend
X-BBC-Edge-Cache-Status
X-GeoIP-City
X-Gzip
X-ATG-Version
X-HS-Content-Campaign-Id
X-Level-Front-Cache
X-Adobe-Source
X-Viewer-Country
X-Irp-Debug
Locid
X-Bip
X-GeoIP
X-Generated-On
Apple-News-Services-Parsed-Url
Req-Svc-Chain
X-Gamma-Serve
Apple-News-Services-Host
X-Cdn-Origin
Apple-News-Services-Request-Url
X-Cache-Id
X-VG-TLSProxy
X-Branch-Name
X-Cache-Config
X-Request-Start
X-Cache-Debug
X-VC-Cache
X-Req
X-Sigma
Server-Host
X-Sigma-Backend
X-Sn-Servicetimems
X-Core-Value
X-Rocket-Build-Number
Thinkindot-Control
Thinkindot-CacheControl-Type
X-Platform
Machine
Mail-Subject
X-Datadog-Parent-Id
Thinkindot-CacheControl
TDXMobile
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
X-Thinkindot-L3
X-Region-Sid
X-TrackingId
X-Magnolia-Registration
X-Developers
Apple-News-Services-Handled
X-Thanos
We-Hiring
X-Node-Id
Web-Mar-Region
X-TH-Server
Fastly-GeoIP-CountryCode
X-Response-By
X-Worker
X-DefHash
X-DPWN-IS-SECURE
X-Tx-Id
X-Origin
X-NU-AKA-ACS-Version
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-Pod-Name
X-Qloud-Router
X-Loc
X-Variation
X-Varnish-Remaining-TTL
X-Has-Esi
X-Varnish-CookieINHashed-On
X-Is-Gdpr
X-Varnish-CookieHashed-On
X-JWT-State
X-FC-Vary-Parameters
X-DefElseHash
Memcached
Adler-Geo
Platform
Is-Eu
NGX
X-Amzn-Remapped-Content-Length
Fastly-SIE
Cf-Device-Type
Fastly-SWR
X-Backend-TTL
NM-Fastcgi-Cache
AMP-Access-Control-Allow-Source-Origin
X-Trace-ID
X-Ua-Device
X-Varnish-Beresp-Ttl
X-CLOUD-TRACE-CONTEXT
X-CACHE-KEY
X-GeoIP-Region-Code
X-GeoIP-Country-Code
X-Mvc-Supplant-OutputCached
X-CS
Datacenter
X-API-Version
X-NC
X-Generated-In
X-LB-ID
Pics-Label
X-Up
Candidate-Md5Url
CDN
Ms-Author-Via
Magicmarker
S-Rt
X-Datadome
X-Restarts
X-LB-NoCache
Kp-EeAlive
X-DynaTrace-JS-Agent
X-Tb-Optimization-Total-Bytes-Saved
WWW-Authenticate
X-Via-Popv
X-Varnish-Ttl
Memory
On-Server
X-TraceId
Time
X-DC
Env
WebServer
X-Vc
X-Via-Poph
X-Via-Popn
NtCoent-Length
X-Akamai-Request-ID2
X-Tt-Logid
X-Http-Reason
X-RPS
X-TA-CDN-Provider
X-Cache-Backend
X-Wix-Viewer-Type
Edge-Cache
X-RSL
X-DB
Esi-Enabled
X-Edge-Pop
X-Action
X-DSS
X-DI
X-DW
X-RPM
X-Optimistic-Header
GeoIp-Country-Code
X-CacheTTL
X-Refresh
X-Servedbyhost
X-Esi
C-Via
X-Service
X-Minions-Version
X-Parent-Response-Time
Accept-Language
X-Srv
X-Cache-PHP
X-MSEdge-Flight
Server-ID
X-HA-Backend
X-Unique-ID
X-Varnish-Beresp-TTL
X-MSEdge-Features
X-Newrelic-Synthetics
X-Cs
X-Webkit-Csp-Report-Only
X-ZONE
X-TX-ID
X-Urbn-Context-Path
X-Urbn-Site-Id
X-VCL-Version
X-Render-Time
X-Cache-Status-Check
Locale
X-Dynatrace
X-Fpc
X-App
X-Ec-Fail
X-Ec-GeoHdr
X-User
X-Traceid
X-LI-Proto
X-Cache-Ttl
X-URL
X-Li-Proto
Test
X-Pass-Why
X-LiteSpeed-Cache-Control
Proxy-Connection
X-B3-Spanid
X-FPC
X-Webkit-CSP-Report-Only
X-Info
X-AIR-PT
X-NODE
X-Vcl-Version
X-Clientip
Cdnsip
Tcn
X-AK-Request-ID
Server-Id
Cdncip
Geo-Info
X-Clara-WADP
X-Oss-Request-Id
X-Oss-Server-Time
Cache-Host
X-Fmm-Version
M-TraceId
X-Oss-Storage-Class
My-App
X-WADP-Cache
X-Oss-Object-Type
HIT
UCS
Cluster
X-Oss-Hash-Crc64ecma
Geoip-Latitude
Fastly-Drupal-HTML
S-Cnection
Resin-Trace
Tracecode
Cf-Int-Pingora-Origin-Digest
X-LiteSpeed-Tag
X-HostName
X-Var-Ttl
X-CUA
X-CSRF-TOKEN
GeoIP-Country-Code
X-ID
X-From
Lfy
T-Server
X-Ha-Backend
Hostname
X-Dynatrace-Js-Agent
X-Pad
X-Micro-Cache
X-Edge-POP
Lang
X-RAMCache
Ohc-File-Size
X-ServedByHost
X-Mcache
Hit
X-Fragments
User-Agent
Fastly-Backend-Name
X-Geo
X-BBC-Origin-Response-Status
Target-Params
X-Via-PopV
X-Via-PopN
MIME-Version
ENV
X-Via-PopH
X-ElasticPress-Query
X-WP-CF-Super-Cache-Cache-Control
X-Release
X-Backend-Host
X-WP-CF-Super-Cache
X-APP
X-Cdn-Forward
Load-Balancing
DataCenter
X-BCube-Filmed-By
X-VC
X-Api-Version
X-Edge-Cache
Section-Io-Id
X-Check-Cacheable
Section-Origin-Responded
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
X-NGINX-Cache
Lb
X-ServerName
X-Ucs
X-HS-Status
URI
Servername
X-Fastly-Backend-Reqs
EpKe-Alive
X-GoCache-CacheStatus
VNS-Age
X-UP
Path
Uri
Permissions-Policy
FSS-Cache
X-WA-Info
X-WA
X-Proxy-Cache-Info
X-Httpd
PICS-Label
X-Lb-Nocache
Cache-Key
CPC-Age
X-Amz-Meta-Cb-Modifiedtime
VNS-Cache
CPC-Cache
X-TRACE-ID
X-Nc
X-Wikidot-Backend
X-Lb-Id
Cdn
Producers
ServerName
X-ES-SERVER
X-RateLimit-Reset
X-Wikidot-Static-Cache
Ohc-Cache-HIT
Cneonction
X-Cdn-Request-ID
Cteonnt-Length
X-Provided-By
Server-Ttl
WZWS-RAY
X-B3-ParentSpanId
X-Fastly-Cache-Hits
X-Dw-Trace-Id
X-Pool
X-Acquia-Application-UUID
X-Acquia-Application-Trace
X-Cache-CFC
X-Acquia-Purge-Tags
X-SB
X-Akamai-ERRuleID
X-Akamai-ERPolicy
X-Acquia-Site
X-Yottaa-OS
Shield-Pop
X-Cache-ASPX
X-Contensis-Viewer-Groups
X-Vcache
X-Newrelic-App-Data
X-Apw-Hits
X-Cms-Context
X-Apw-Access-Action
X-Apw-Access-Object
X-Apw-Access-Token
Cf-Ipcountry
X-Snapshot-Date
CF-Cached-On
Pagetype
Vha6-Origin
X-PJAX-URL
X-Swift-Error
X-Cache-Ngx
Sid
X-Air-Pt
X-Platform-Processor
X-Platform-Router
X-Platform-Cluster
X-Via-Ucdn
X-Udemy-Cache-App-Namespace
GeoIP-Latitude
X-Akamai-Request-ID
X-Hcs-Proxy-Type
X-Miniprofiler-Ids
X-CCDN-CacheTTL
X-UA
MD5-Digest
X-CacheKey
X-Akamai-Pragma-Client-IP
Req-ID
Ngx
CountryCode
X-Logging-Id
X-Varnish-Authentication
X-Sentry-ID
X-CCDN-Origin-Time
X-Te-Duration-Ms
X-Te-Count
X-Http-Count
X-Http-Duration-Ms
X-Last-Modified