Threat Level: green Handler on Duty: Johannes Ullrich

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-Cache-Status
Link
Accept-Ranges
ETag
CF-RAY
X-XSS-Protection
Expect-CT
Pragma
X-Powered-By
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
Alt-Svc
X-Served-By
X-Xss-Protection
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
CF-Ray
X-Check
X-Cache-Status
X-Generator
X-Cacheable
Timing-Allow-Origin
X-Content-Security-Policy
X-Iinfo
Feature-Policy
Status
X-Envoy-Upstream-Service-Time
Content-Encoding
Access-Control-Expose-Headers
P3p
X-Drupal-Dynamic-Cache
X-CDN
X-AspNetMvc-Version
Upgrade
X-Via
X-Ws-Request-Id
Access-Control-Max-Age
X-Request-ID
Server-Timing
EagleId
X-Cache-Group
Keep-Alive
X-Turbo-Charged-By
Request-Context
X-Age
X-UA-Device
X-Server-Powered-By
X-Proxy-Cache
X-AH-Environment
X-Backend
X-Robots-Tag
X-Hacker
Report-To
X-Amz-Request-Id
Host-Header
X-Server
X-Amz-Id-2
Grace
X-LiteSpeed-Cache
X-Rq
X-Nginx-Cache-Status
X-Varnish-Cache
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-WebKit-CSP
X-Page-Speed
X-Vhost
X-Ua-Compatible
EagleEye-TraceId
X-Amz-Version-Id
X-Dns-Prefetch-Control
X-Pingback
X-OneAgent-JS-Injection
X-Dispatcher
X-Device
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Cache-Spec
NEL
X-Host
X-Server-Id
Cf-Railgun
X-Node
X-Backend-Server
Accept-CH
X-Readtime
Surrogate-Control
X-Akam-SW-Version
Request-Id
X-Response-Time
X-HW
Xkey
X-Application-Context
X-Ruxit-JS-Agent
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Content-Location
Rating
Accept-Ch-Lifetime
X-Country
X-B3-TraceId
X-Cloud-Trace-Context
Accept-CH-Lifetime
X-Cache-Lookup
X-Trace
X-Url
X-Ac
X-Content-Type
X-PC
X-Vname
X-TtlSet
Allow
X-Varnish-TTL
X-Clacks-Overhead
X-Mod-Pagespeed
Edge-Control
X-ESI
X-Server-Name
Fastly-Restarts
Cache-Tag
X-FastCGI-Cache
Service-Worker-Allowed
X-Rack-Cache
X-VARITI-CCR
X-Element-Page-Cache
Verso
X-Aws-Lambda-Call-Status
X-Upstream
MS-Author-Via
X-MS-InvokeApp
X-GitHub-Request-Id
X-Amz-Rid
X-Vcap-Request-Id
Public-Key-Pins
X-Dw-Request-Base-Id
X-Cached
X-Client-IP
X-D2id
X-Abt-Application-Version
X-Cnection
X-Cache-TTL
X-Px
Accept-Ch
Arr-Disable-Session-Affinity
RTSS
X-Country-Code
X-Navigation-Version
Access-Control-Request-Method
X-Origin-Cache
X-Goog-Hash
X-Powered-By-Plesk
X-NF-Request-ID
X-Kinja-Build
X-Server-Lifecycle-Phase
X-Kinja
X-Kraken-Loop-Name
X-Exp-Id
X-Use-Magma
X-Kinja-Server
X-Exp-Variant
X-Cdn-Fetch
X-GoogleNews-Bot
X-Instrumentation
X-Kinja-Revision
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
AR-ATIME
AR-Request-ID
X-Powered-CMS
AR-PoweredBy
AR-CACHE
AR-SID
X-Version
X-Sol
Pagespeed
X-Middleton-Display
Display
X-Middleton-Response
Response
X-Amz-Server-Side-Encryption
X-MSEdge-Ref
X-LLID
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Edge-Location-Klb
X-Kinsta-Cache
X-Edge
Nginx-Cache
X-RateLimit-Remaining
Mrf-Cache-Status
MRF-Tech
X-B3-TraceId-Primal
TCN
X-Protected-By
X-TTL
X-HP-Trace-Id
X-Shield-Request-Id
X-HP-Webp
X-Jurisdiction
X-T
X-Forwarded-For
X-Content-Security-Policy-Report-Only
S
X-Aspnetmvc-Version
X-Mg-S
X-Id
Content-MD5
Edge-Cache-Tag
Fastcgi-Cache
X-Mid
SPIisLatency
Realpath
SPRequestDuration
X-Language
Front-End-Https
X-Ttl
X-Recruiting
X-Request-Received
X-Request-Processing-Time
X-CST
Filters
Pinterest-Generated-By
Pinterest-Version
X-Pinterest-Rid
X-MCACHE
X-DynaTrace
Server-Node
X-Ua-Browser
X-Ab
X-Content
Server-Name
X-Frontend
X-Correlation-Id
X-HS-Hub-Id
X-HS-Content-Id
X-ECACHE
X-HS-Cache-Config
X-HS-Combine-CSS
X-NWS-LOG-UUID
X-Yandex-Sdch-Disable
X-SharePointHealthScore
SPRequestGuid
X-Ser
X-Ezoic-Cdn
X-Cache-Key
Fusion-Content-Source
X-Hits
Fusion-Template-Id
Fusion-Source
Fusion-Content-Id
X-Parallel-Accel
Fusion-Deployment-Id
Fusion-Component-Id
X-Template
Alternate-Protocol
X-Tt-Trace-Host
X-Tt-Trace-Tag
Cache-Tags
MicrosoftSharePointTeamServices
X-Content-Options
X-Page-Id
X-Ruxit-Js-Agent
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
Charset
X-Git-Hash
X-B3-Sampled
Cleartype
Host
X-Www-Served-By
X-DIS-Request-ID
X-Geo-Country
X-Debug-Info
X-Amzn-Trace-Id
X-Amz-Replication-Status
X-Content-Digest
X-Hostname
X-Daa-Tunnel
Filterid
X-Accel-Expires
X-Varnish-Age
X-Fastly-Request-Id
X-Az
X-AppVersion
X-Activity-Id
X-FB-Debug
X-Forwarded-Proto
Cross-Origin-Opener-Policy
X-Upgrade-Enabled
X-VCache
TP-L2-Cache
TP-Cache
X-Rid
X-Grace
X-Nginx-Upstream-Cache-Status
Access-Control-Allow-Method
X-Origin-Server
X-N
X-F-Cache
X-LB-Cache
ServerID
X-Mobile-URL
X-Aspnet-Duration-Ms
X-Providence-Cookie
X-Is-Crawler
X-Route-Name
X-Flags
X-Request-Guid
X-Whom
X-Server-ID
X-Ratelimit-Limit
X-GUploader-UploadID
X-TT
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-Goog-Metageneration
X-App-Environment
X-XRDS-LOCATION
Viewport
X-Tb
X-Varnish-Grace
X-Type
X-Seen-By
X-WebKit-CSP-Report-Only
X-FW-Serve
X-FW-Server
X-FW-Hash
Payment
Node
X-Distributor
X-FW-Static
X-FW-Dynamic
X-FW-Type
X-Oneagent-Js-Injection
X-App-Server
DC
X-User-Agent
Paypal-Debug-Id
X-Origin-Upstream-Status
X-NGENIX-Cache
Fastcgi-Useragent
Country
Accept-Charset
X-Cache-Control
X-Wix-Request-Id
X-Litespeed-Cache
X-Fastcgi-Cache
X-Cache-Rule
X-Logged-In
X-Fastly-Request-ID
Version
X-Webkit-CSP
X-DataDome
X-Cache-Age
X-Microsite
X-Request-Handler-Origin-Region
X-Via-JSL
X-Drupal-Cache-Tags
X-Oracle-Dms-Ecid
Referer-Policy
X-Oracle-Dms-Rid
X-Erf-Bev-Bev
X-Browser-Type
Amp-Access-Control-Allow-Source-Origin
X-Erf-Bev-Bev-Is-Generated
X-Load-Cache
Cache-Status
X-Varnish-Backend
X-B-Cache
X-Cluster-Name
X-Signature
Refresh
X-Contextid
SD-X-WS
Access-Control-Request-Headers
X-Buckets
X-Response-Served-From
X-Node-Name
X-Original-Request-Id
VIX-Pulpo-Upstream-Status
X-Mobile
VIX-Pulpo-Node
X-Rendered-As
X-Vgn-Hpd-Reason
X-Cacheable-TTL
X-Real-IP
X-Cache-Expired-At
X-Page-View
X-Is-Bot
X-Jobs
X-Proxy-Cache-Status
NGB
X-Debug
X-UUID
X-Revision
X-RemovedCookies
X-ProcessESI
X-Yottaa-Metrics
X-Cache-Action
X-Yottaa-Optimizations
X-B
X-Instance
X-IPLB-Instance
X-Device-Type
X-Proxy
X-Rule
Akamai-GRN
X-Tec-Api-Version
X-Tec-Api-Origin
X-Tec-Api-Root
X-Drupal-Cache-Contexts
X-G
X-Cache-Time
X-Framework
Surrogate-Key
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-Debug-IsConnected
X-TEC-API-ROOT
X-Debug-IsPreview
X-Air-Hostname
X-Air-Source
X-Air-Trace-Id
X-FW-Version
CF-IPCountry
SID
X-Ratelimit-Reset
DynaTrace
X-PressLabs-Stats
GEO-INFO
X-Azure-Ref
Liferay-Portal
X-Nginx-Cache
X-Cache-Operation
Count-Hit
X-Ms-Version
X-Ms-Request-Id
X-Accel-Buffering
X-Source
Healthy
Frame-Options
X-Presslabs-Stats
Uber-Trace-Id
X-RTag
Ms-Operation-Id
X-CDN-Forward
MS-CV
X-XRDS-Location
X-RateLimit-Limit
X-EdgeConnect-Cache-Status
X-APP-VERSION
X-Cache-NGX
Countrycode
X-Zen-Fury
X-L-Path
Xserver
X-Environment-Context
X-Tumblr-Pixel-0
X-Varnish-Server
X-Cache-Hit
X-Tumblr-User
X-Tumblr-Pixel-1
X-Tumblr-Pixel
X-Backend-Name
X-Mode
Ec-Rule-Version
Cross-Origin-Window-Policy
X-IPS-LoggedIn
X-Region
Protected
X-Forwarded-Host
X-Servername
Backend
X-Cache-TTL-Remaining
X-Content-Powered-By
X-Tid
X-Rewrite-Enabled
X-JoinUs
X-Detected-As
X-Cache-Type
X-RN-RSRV
Meta-Geo
X-UPSTREAM-Address
X-SaId
X-Sql-Count
X-Sql-Duration-Ms
X-Cache-Server
Section-Io-Cache
X-Proxied
X-Debug-Cache
X-Sorting-Hat-ShopId
X-Alternate-Cache-Key
X-Redis-Cache
X-Human
Decoy-Debug-Key
X-Generation-Time
X-ShardId
Country-Code
X-Routing-Service
X-Cache-Grace
X-Hosted-By
Decoy-Debug-Status
Eomportal-Instance
Apigw-Requestid
X-Shopify-Stage
X-Extlb
Decoy-Debug-TTL
X-Sorting-Hat-PodId
X-ShopId
X-Uri
X-Varnish-Beresp-Grace
X-Zipkin-Id
X-ServerID
X-Microcachable
X-BYPASS-REASON
X-UA-Device-Type
X-PHP-Backend
Fastly-SSL
X-ProxyCache-Key
X-NCache
X-ApacheServer
X-Via-Fastly
X-ProxyCache-Status
X-No-Session
Cache-Tv-Group
Cache-Name
X-PERF
Url
X-Content-Age
X-Format
X-Origin-Date
X-Status
X-Storage
X-FB-TRIP-ID
X-Soup
Mn-Server-Ip
X-Site-Version
Property-Id
TWC-Privacy
Selected-Fe
X-Adobe-Loc
TWC-Device-Class
X-Adobe-Content
X-Akamai-Edgescape
TWC-GeoIP-Country
Webcakes-App-Version
TWC-GeoIP-LatLong
X-Timing-Wait
Webcakes-Region
Webcakes-App-Name
X-Access
TWC-Locale-Group
X-Web-Node
X-Hyper-Cache
X-Say-TTL
TWC-Connection-Speed
X-SayCDN-TTL
X-Proxy-Build
X-Server-W
X-Section
X-Say-Cacheable
X-Cluster-Node
X-OCL
X-NYM-Debug-Backend
X-Cache-Host
X-Origin-Hint
X-PCL
LB
X-Hl-Ver
DB-Nickname
Azure-InstanceId
Azure-SlotName
Azure-SiteName
Azure-Version
X-Varnishpool
X-R9-Blue-Green-Version
X-Pubstack
Azure-RegionName
WPO-Cache-Message
WPO-Cache-Status
X-Be
X-NewRelic-App-Data
CDN-EdgeStorageId
Content-Secure-Policy
CDN-PullZone
CDN-RequestId
CDN-CachedAt
CDN-Cache
CDN-RequestCountryCode
CDN-Uid
OT-Force-Account-Verify
Content-Disposition
X-Generated-By
X-Azure-Ref-OriginShield
X-Webkit-Csp
X-LSADC-Cache
X-TIME
SRV
X-Ua
X-Cached-By
Source
Cache
X-Nginx-Cache-Key
X-SRV
X-Ratelimit-Remaining
X-Trace-Id
X-Bc-Bl
X-TT-LOGID
X-Unique-Id
X-App-Version
X-LAGOON
Cache-Hits
X-Auto-Login
X-Dc
Retry-After
X-Origin-TTL
X-GEO
X-Origin-CC
X-Varnish-Hits
X-Cache-Remote
Mime-Version
Xet-Cookie
X-Platform-Server
X-HTML-Minification-Powered-By
X-Varnish-Hostname
X-Akamai-Transformed
X-Cdn
X-Loop
X-TNCMS
Onion-Location
HostName
X-S-Maxage
X-Xfnlog-Site
X-Amz-Meta-S3cmd-Attrs
X-Cache-Tags
ServedBy
X-CSRF-Token
X-Varnish-Cache-Hits
Web-Mar-Node
Upgrade-Insecure-Requests
X-Time
X-Request-Time
X-Proto
Webserver
X-Cache-Var-Map
X-Cache-Var
X-Tumblr-Pixel-3
X-Tumblr-Pixel-2
X-AOL-HN
X-EC-Lua
X-Tenant
X-FireWall-Port
X-Xrds-Location
X-Endurance-Cache-Level
X-ECache
N-Cache
X-Time-Microsecs
From-Origin
X-Request-Host
X-AWS-Id
X-LJ-Flow-ID
X-Edge-Location
X-VWS-Id
WP-Super-Cache
X-GG-Cache-Date
X-Origin-Response-Time
CloudFront-Viewer-Country
X-B3-SpanId
X-Correlation-ID
Nel
X-Mg-Request-UUID
X-Cache-Enabled
X-Via-NSCOPI
DCR-Decision-By
X-Processor
Sslversion
X-Ftr-Request-Id
X-External-Request-Id
X-S
X-S-Cookie
X-ScT
X-SD-PageType
X-Rojux
DCR-Processing-Time-Ms
X-Forwarded-Path
User-Cache-Control
V-Age
Vix-Hermes-Req-Id
Surrogated-Key
X-Planisys-CDN-Cache
A
Mobile-Detection-Method
Odigeo-Trace-Id
Origin
Meta-Geo-Continent
X-Hnp-Log
X-ND-Cache
BehaviorPad-Version
X-NAPM-TraceId
X-Ig-Push-State
Fastcgi-X-Cache-Version
X-Orig-Expires
X-PBS-Appsvrname
Redirect-Candidate
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
DSUID
Expiry
X-Gen-Mode
X-PAYTM-SRV-ID
X-Shop-Environment
Pramga
Rendered-Blocks
X-Session-Fingerprint
X-Vdms-Version
X-Vdms-Path
X-Cache-NE
X-VG-WebCache
X-CF-Lambda-Fn
X-Cache-Date
X-Destination
X-B-Cookie
X-TIM-N
X-V-Cache
X-Developer
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
X-Conf
X-Cluster
X-Connection-Hash
X-Labrador-Cache-Channel
X-D
X-PHP-Host
X-Amzn-RequestId
X-CF-Lambda-Version
X-Ckpd-Fst-Backend
Xc-Version
X-Amz-Apigw-Id
X-ARC
X-Block-Status
X-SVT-ORM-RULES
X-A-Dcw
X-Slack-Backend
X-A-Ccd
X-Aicache-OS
X-Aed
X-SRCache-Key
X-A-Dgt
X-A-Wwc
X-SVT-ORM-VERSION
X-A-Dam
X-A
X-Application
X-M-Reqid
X-MP-GENERATED-AT
X-Handled-By
X-M-Log
X-Qnm-Cache
X-Core-Mission
Wxu-Next-Commit
X-Li-Fabric
X-Date
X-Li-Pop
X-Hash
L
Wxu-Next-Region
Fastcgi-Cache-TTL
Wxu-Next-Hostname
Host-ID
Gh-Request-Id
X-Accel-Expires-Debug
Svr
X-LI-UUID
X-Cache-Bucket
X-Device-Os
Release
Ssr
X-Forwarded-Site
X-Epic-Correlation-Id
Traceparent
True-Client-Country-4JS
Origin-EX
State
Origin-CC
X-Fastly-Cache
X-Cdn-Srv
X-Cache-Info
X-Fetched-On
X-Gdpr
X-Geo-Header
Arc-Country
X-Origin-Time
X-Owner
X-Policy
X-Proxy-Upstream
X-Origin-Expires
X-Old-Content-Length
AKAMAI
X-NodeID
X-Nyt-Route
X-Sucuri-ID
X-Sucuri-Cache
X-Served-From
X-Scheme
X-Request-URI
X-Rocket-Nginx-Serving-Static
Cmstype
X-Server-IP
X-RCS-CacheZone
X-Skip-Cache
Fastly-Drupal-Html
X-Varnish-Beresp-Status
X-NWS-UUID-VERIFY
X-Webstats-RespID
X-Men
X-VServer
X-Viewer-Country
X-Mvc-Supplant-Cachable
CDCHOST
Cmsid
X-Location
CacheControlHeader
Server-Info
X-Magnolia-Registration
Environment
X-Zone
X-Locale
X-Reqid
X-Core-Value
X-Datadog-Parent-Id
X-Backend-TTL
Web-Mar-Region
X-Datadog-Trace-Id
X-Csrf-Jwt
X-Sn-Servicetimems
X-Sigma-Backend
X-Sigma
X-Storefront-Renderer-Rendered
X-Eu-Site
X-Adobe-Source
X-Envoy-Decorator-Operation
X-BBC-Edge-Cache-Status
X-VG-TLSProxy
X-Backend-State
X-Developers
X-VarnishDD-TTL
X-Branch-Name
X-Cache-Id
X-Bip
X-UnsetCookies
X-TrackingId
X-Thanos
X-Cache-Debug
X-TH-Server
X-CGP
X-Thinkindot-L3
We-Hiring
X-Cdn-Origin
X-ATG-Version
X-Esi-Check
X-Req
X-Fastly-Backend
Fastly-GeoIP-CountryCode
Mail-Subject
Machine
X-Node-Id
X-Gzip
X-Generated-On
X-GeoIP
X-GeoIP-City
Locid
X-Irp-Debug
X-HS-Content-Campaign-Id
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
HA-Ipaddr
Apple-News-Services-Host
X-HN
X-Datadog-Sampling-Priority
L5d-Success-Class
Apple-News-Services-Handled
Ha-Gx-Prefs
PFcat
TDXMobile
X-Gamma-Serve
Thinkindot-CacheControl
X-Level-Front-Cache
Thinkindot-Control
Thinkindot-CacheControl-Type
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-Platform
X-Rocket-Build-Number
Req-Svc-Chain
Server-Host
X-Request-Start
X-Region-Sid
X-VC-Cache
X-Loc
X-Is-Gdpr
X-GeoIP-Country-Code
X-GeoIP-Region-Code
X-Origin
X-Worker
X-JWT-State
X-Has-Esi
X-Rebelmouse-Cache-Control
X-Qloud-Router
X-Rebelmouse-Surrogate-Control
X-FC-Vary-Parameters
X-Response-By
X-Pod-Name
X-NU-AKA-ACS-Version
X-Varnish-Remaining-TTL
X-DefHash
X-Varnish-CookieINHashed-On
X-Varnish-CookieHashed-On
X-Variation
X-DefElseHash
X-DPWN-IS-SECURE
Cf-Device-Type
Platform
Adler-Geo
Fastly-SWR
NM-Fastcgi-Cache
NGX
Fastly-SIE
Is-Eu
Memcached
X-Amzn-Remapped-Content-Length
X-Tx-Id
X-Varnish-Beresp-Ttl
AMP-Access-Control-Allow-Source-Origin
X-Ua-Device
X-Trace-ID
X-Cache-Config
X-CS
X-Mvc-Supplant-OutputCached
X-CLOUD-TRACE-CONTEXT
S-Rt
X-API-Version
X-LB-ID
X-Up
Magicmarker
X-CACHE-KEY
Datacenter
X-Datadome
X-Restarts
CDN
Kp-EeAlive
X-NC
Ms-Author-Via
X-Generated-In
Pics-Label
Env
Candidate-Md5Url
X-Akamai-Request-ID2
X-LB-NoCache
X-Http-Reason
Time
Memory
X-TraceId
X-Tb-Optimization-Total-Bytes-Saved
X-Optimistic-Header
X-Varnish-Ttl
X-Cache-Backend
X-RPS
X-RSL
Edge-Cache
X-Via-Popn
X-DC
X-Edge-Pop
WebServer
X-Via-Poph
X-RPM
X-Via-Popv
X-Wix-Viewer-Type
X-DI
X-DW
NtCoent-Length
X-DB
X-DSS
X-Action
X-Tt-Logid
X-DynaTrace-JS-Agent
X-Cache-Ttl
X-Refresh
X-Vc
On-Server
WWW-Authenticate
X-TA-CDN-Provider
X-CacheTTL
X-Minions-Version
X-Parent-Response-Time
Accept-Language
GeoIp-Country-Code
Esi-Enabled
X-Esi
X-Servedbyhost
X-HA-Backend
X-Srv
Server-ID
X-Varnish-Beresp-TTL
X-Unique-ID
X-Service
X-MSEdge-Flight
C-Via
X-MSEdge-Features
X-Cs
X-Cache-PHP
Locale
X-Urbn-Site-Id
X-Urbn-Context-Path
X-Newrelic-Synthetics
X-TX-ID
X-ZONE
X-Webkit-CSP-Report-Only
X-User
X-VCL-Version
X-Ec-Fail
X-Ec-GeoHdr
X-LI-Proto
X-Dynatrace
X-App
X-Traceid
X-Fpc
X-Cache-Status-Check
X-Render-Time
X-URL
X-Webkit-Csp-Report-Only
X-Li-Proto
Test
X-LiteSpeed-Cache-Control
Cdncip
X-B3-Spanid
X-FPC
X-AK-Request-ID
Cdnsip
X-Pass-Why
X-NODE
Proxy-Connection
Server-Id
X-Vcl-Version
Cluster
X-Fmm-Version
X-WADP-Cache
X-Clara-WADP
My-App
X-Mcache
Geoip-Latitude
Tracecode
M-TraceId
X-CUA
X-Var-Ttl
X-Info
X-Clientip
Resin-Trace
X-AIR-PT
X-LiteSpeed-Tag
X-Oss-Hash-Crc64ecma
Cache-Host
Fastly-Drupal-HTML
X-From
T-Server
X-Oss-Object-Type
UCS
X-Oss-Request-Id
Geo-Info
HIT
Lfy
X-Oss-Server-Time
Cf-Int-Pingora-Origin-Digest
X-Oss-Storage-Class
X-CSRF-TOKEN
GeoIP-Country-Code
X-Ha-Backend
Lang
S-Cnection
X-ID
X-Fragments
Hostname
X-ServedByHost
X-WP-CF-Super-Cache
Ohc-File-Size
Hit
X-Pad
Target-Params
Tcn
X-WP-CF-Super-Cache-Cache-Control
X-Geo
DataCenter
X-VC
X-Dynatrace-Js-Agent
X-Via-PopV
X-Via-PopN
Fastly-Backend-Name
X-RateLimit-Reset
MIME-Version
X-ElasticPress-Query
User-Agent
X-Cdn-Forward
X-Micro-Cache
X-RAMCache
X-Via-PopH
X-Edge-POP
X-HostName
X-Edge-Cache
Section-Io-Id
Section-Origin-Responded
X-Backend-Host
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
ENV
X-Check-Cacheable
Load-Balancing
X-BBC-Origin-Response-Status
X-NGINX-Cache
X-Api-Version
X-Release
Permissions-Policy
X-HS-Status
X-ServerName
X-APP
X-Lb-Nocache
Servername
X-Ucs
X-Fastly-Backend-Reqs
X-BCube-Filmed-By
X-Provided-By
X-GoCache-CacheStatus
Uri
X-UP
EpKe-Alive
URI
X-Httpd
X-Nc
Producers
ServerName
X-Proxy-Cache-Info
FSS-Cache
PICS-Label
X-TRACE-ID
Lb
X-Cache-CFC
X-Amz-Meta-Cb-Modifiedtime
Cdn
X-SB
X-Udemy-Cache-App-Namespace
X-Pool
Cneonction
CPC-Cache
WZWS-RAY
CPC-Age
Server-Ttl
X-Swift-Error
Cache-Key
VNS-Age
Path
VNS-Cache
X-Cdn-Request-ID
X-WA-Info
Cteonnt-Length
Ohc-Cache-HIT
X-Fastly-Cache-Hits
X-WA
X-Lb-Id
X-B3-ParentSpanId
X-Dw-Trace-Id
X-UA
X-Wikidot-Static-Cache
X-Vcache
X-Snapshot-Date
X-Acquia-Site
X-Wikidot-Backend
X-ES-SERVER
X-Contensis-Viewer-Groups
X-Apw-Access-Action
X-Apw-Access-Token
X-Apw-Hits
Shield-Pop
X-Apw-Access-Object
X-Cache-ASPX
X-Akamai-ERPolicy
X-Akamai-ERRuleID
X-Acquia-Purge-Tags
X-Acquia-Application-UUID
X-Platform-Cluster
X-Ec-Custom-Error
X-Platform-Processor
X-Platform-Router
Vha6-Origin
X-Akamai-Request-ID
CF-Cached-On
X-Acquia-Application-Trace
X-Newrelic-App-Data
Cf-Ipcountry
X-Yottaa-OS
X-Air-Pt
X-Cache-Ngx
Sid
X-Varnish-Authentication
X-Scale
X-Shopify-Generated-Cart-Token
GeoIP-Latitude
X-Http-Count
X-PJAX-URL
X-Cms-Context
Ngx
X-Sentry-ID
CountryCode
Req-ID
X-Akamai-Pragma-Client-IP
Pagetype
X-CacheKey
X-Last-Modified
X-Te-Duration-Ms
X-Te-Count
X-Http-Duration-Ms
X-Logging-Id