Threat Level: green Handler on Duty: Rick Wanner

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
Link
CF-Cache-Status
Accept-Ranges
CF-RAY
ETag
X-XSS-Protection
Expect-CT
Pragma
X-Powered-By
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-UA-Compatible
X-Cache-Hits
Alt-Svc
P3P
X-Served-By
X-Xss-Protection
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Cache-Status
X-Generator
X-Cacheable
Timing-Allow-Origin
X-Request-ID
X-Content-Security-Policy
P3p
X-Iinfo
Status
Feature-Policy
X-Envoy-Upstream-Service-Time
Content-Encoding
Access-Control-Expose-Headers
X-CDN
X-Drupal-Dynamic-Cache
Upgrade
X-AspNetMvc-Version
X-Via
CF-Ray
Access-Control-Max-Age
X-Ws-Request-Id
Server-Timing
EagleId
Keep-Alive
X-Cache-Group
X-Turbo-Charged-By
Request-Context
X-Age
X-Proxy-Cache
X-Server-Powered-By
X-AH-Environment
X-UA-Device
X-Backend
X-Hacker
X-Robots-Tag
Report-To
X-Amz-Request-Id
Host-Header
X-LiteSpeed-Cache
X-Server
X-Amz-Id-2
Grace
X-Rq
X-Nginx-Cache-Status
X-Varnish-Cache
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-WebKit-CSP
X-Dns-Prefetch-Control
X-Page-Speed
X-Vhost
X-OneAgent-JS-Injection
EagleEye-TraceId
X-Amz-Version-Id
X-Pingback
X-Device
X-Dispatcher
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Cache-Spec
NEL
X-Server-Id
X-Host
X-Backend-Server
X-Node
Cf-Railgun
Accept-CH
X-Readtime
X-Akam-SW-Version
Surrogate-Control
Request-Id
X-Response-Time
X-HW
X-Language
Xkey
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Application-Context
Content-Location
X-Template
X-Ruxit-JS-Agent
Rating
X-B3-TraceId
X-Ua-Compatible
Accept-Ch-Lifetime
X-Country
Accept-CH-Lifetime
X-Cloud-Trace-Context
X-Cache-Lookup
X-Ac
X-Url
Allow
X-Content-Type
X-Buckets
X-Trace
X-PC
X-Vname
X-TtlSet
X-Mod-Pagespeed
X-Varnish-TTL
X-Clacks-Overhead
Edge-Control
X-FastCGI-Cache
X-ESI
Cache-Tag
Fastly-Restarts
X-Rack-Cache
Service-Worker-Allowed
X-VARITI-CCR
X-Server-Name
X-Element-Page-Cache
Verso
X-GitHub-Request-Id
X-MS-InvokeApp
X-Upstream
X-Amz-Rid
X-Vcap-Request-Id
MS-Author-Via
Public-Key-Pins
X-Dw-Request-Base-Id
X-D2id
X-Client-IP
X-Cached
X-Abt-Application-Version
X-Origin-Cache
X-Cache-TTL
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-Aspnetmvc-Version
Arr-Disable-Session-Affinity
X-Country-Code
X-Cnection
X-Px
X-Powered-By-Plesk
X-Goog-Hash
X-Navigation-Version
Access-Control-Request-Method
X-Server-Lifecycle-Phase
X-Aws-Lambda-Call-Status
X-Kraken-Loop-Name
X-Instrumentation
X-NF-Request-ID
X-Version
Accept-Ch
RTSS
X-Amz-Server-Side-Encryption
X-Powered-CMS
X-Middleton-Display
Pagespeed
X-Sol
Display
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Middleton-Response
Response
X-Kinja-Server
X-Kinja-Revision
X-Use-Magma
X-Kinja-Build
X-Exp-Id
X-Exp-Variant
X-GoogleNews-Bot
X-Kinja
X-Cdn-Fetch
X-MSEdge-Ref
X-LLID
X-Edge
X-Kinsta-Cache
X-Edge-Location-Klb
X-CST
Nginx-Cache
X-Shield-Request-Id
X-TTL
X-B3-TraceId-Primal
Mrf-Cache-Status
MRF-Tech
AR-PoweredBy
AR-ATIME
AR-CACHE
S
AR-Request-ID
AR-SID
X-HP-Trace-Id
Content-MD5
X-HP-Webp
X-Jurisdiction
X-T
X-RateLimit-Remaining
X-Protected-By
X-Forwarded-For
TCN
X-Content-Security-Policy-Report-Only
X-Id
X-Mg-S
X-Mid
X-MCACHE
Fastcgi-Cache
Realpath
Front-End-Https
X-Parallel-Accel
SPIisLatency
SPRequestDuration
Edge-Cache-Tag
X-Recruiting
X-Request-Received
X-Request-Processing-Time
Filters
X-Ttl
X-Pinterest-Rid
Pinterest-Version
Pinterest-Generated-By
Fusion-Content-Source
Fusion-Content-Id
Fusion-Source
Fusion-Component-Id
Fusion-Deployment-Id
Fusion-Template-Id
Server-Node
X-Content
X-DynaTrace
X-Ua-Browser
X-Ab
SPRequestGuid
X-SharePointHealthScore
X-Correlation-Id
X-Ezoic-Cdn
X-Ruxit-Js-Agent
Server-Name
Alternate-Protocol
X-Accel-Expires
X-NWS-LOG-UUID
X-ECACHE
X-Frontend
X-HS-Cache-Config
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Combine-CSS
X-Yandex-Sdch-Disable
X-Hits
X-Cache-Key
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Content-Options
Cache-Tags
Host
X-Git-Hash
X-Page-Id
MicrosoftSharePointTeamServices
Charset
X-Fastly-Request-Id
Cleartype
X-Www-Served-By
X-B3-Sampled
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Geo-Country
X-Content-Digest
X-Amz-Replication-Status
X-Ser
TP-L2-Cache
TP-Cache
X-Forwarded-Proto
Filterid
X-Hostname
X-Varnish-Age
X-VCache
X-Amzn-Trace-Id
X-AppVersion
X-Az
X-Activity-Id
X-Daa-Tunnel
X-XRDS-LOCATION
X-DIS-Request-ID
X-Debug-Info
X-Rid
X-Origin-Server
X-Upgrade-Enabled
Access-Control-Allow-Method
X-Grace
X-N
X-Microsite
X-Request-Handler-Origin-Region
X-Origin-Upstream-Status
X-LB-Cache
X-FB-Debug
X-WebKit-CSP-Report-Only
ServerID
X-Nginx-Upstream-Cache-Status
X-Mobile-URL
X-Request-Guid
X-Flags
X-Route-Name
X-Aspnet-Duration-Ms
X-Whom
X-Is-Crawler
X-TT
X-Providence-Cookie
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
X-Goog-Generation
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-NGENIX-Cache
X-GUploader-UploadID
X-F-Cache
X-App-Environment
X-App-Server
X-Varnish-Grace
Cross-Origin-Opener-Policy
Viewport
X-Tb
X-Distributor
Payment
DC
X-FW-Dynamic
Paypal-Debug-Id
Node
X-Server-ID
X-FW-Hash
X-FW-Serve
X-FW-Static
X-FW-Server
X-FW-Type
X-Cache-Control
X-Logged-In
X-Seen-By
Fastcgi-Useragent
X-PressLabs-Stats
X-Type
X-User-Agent
X-Cache-Age
Country
Accept-Charset
X-Ratelimit-Limit
X-Cache-Rule
X-Varnish-Backend
X-DataDome
X-Browser-Type
X-Node-Name
X-Erf-Bev-Bev-Is-Generated
X-Webkit-CSP
X-Erf-Bev-Bev
Version
X-Load-Cache
X-Wix-Request-Id
X-Tec-Api-Origin
X-Tec-Api-Root
X-Tec-Api-Version
X-Cache-Action
Refresh
X-IPLB-Instance
X-Via-JSL
SD-X-WS
Referer-Policy
X-Response-Served-From
Access-Control-Request-Headers
X-Original-Request-Id
Cache-Status
Amp-Access-Control-Allow-Source-Origin
X-Drupal-Cache-Tags
X-Cacheable-TTL
X-Real-IP
X-Jobs
X-Contextid
X-Page-View
X-Is-Bot
X-Proxy-Cache-Status
X-Rendered-As
X-Vgn-Hpd-Reason
X-UUID
X-Revision
X-RemovedCookies
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-B
X-Cluster-Name
X-ProcessESI
NGB
X-Debug
X-Device-Type
X-Cache-Expired-At
X-Signature
X-Drupal-Cache-Contexts
X-Yottaa-Optimizations
X-Rule
X-Yottaa-Metrics
X-Proxy
DynaTrace
X-B-Cache
Liferay-Portal
X-Framework
X-Fastly-Request-ID
X-Cache-Time
Surrogate-Key
Akamai-GRN
X-Mobile
X-G
X-Instance
X-Debug-IsConnected
X-Debug-IsPreview
X-Fastcgi-Cache
X-FW-Version
X-Azure-Ref
Healthy
CF-IPCountry
X-Source
SID
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-Air-Trace-Id
X-Air-Source
X-Air-Hostname
X-TEC-API-ROOT
X-Ms-Version
X-Ms-Request-Id
X-Oracle-Dms-Ecid
X-XRDS-Location
X-Oracle-Dms-Rid
Frame-Options
X-RTag
X-Cache-Hit
MS-CV
Ms-Operation-Id
X-APP-VERSION
Section-Io-Cache
Countrycode
X-Tumblr-User
X-CDN-Forward
X-Oneagent-Js-Injection
X-Tumblr-Pixel-1
X-Tumblr-Pixel
X-Nginx-Cache
X-Tumblr-Pixel-0
Xserver
X-Varnish-Server
X-Environment-Context
X-L-Path
Count-Hit
X-Region
X-Cache-Operation
GEO-INFO
X-Servername
X-Content-Powered-By
X-EdgeConnect-Cache-Status
Uber-Trace-Id
X-Forwarded-Host
X-Backend-Name
X-Mode
X-Accel-Buffering
Backend
X-IPS-LoggedIn
Cross-Origin-Window-Policy
X-Adobe-Content
X-Litespeed-Cache
X-Adobe-Loc
X-Zen-Fury
Ec-Rule-Version
Meta-Geo
X-JoinUs
X-UPSTREAM-Address
X-SaId
X-RN-RSRV
Eomportal-Instance
X-Shopify-Stage
X-Microcachable
X-ShopId
X-ShardId
X-Detected-As
X-Cache-Server
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Alternate-Cache-Key
X-Cache-Grace
X-Cache-Type
X-Redis-Cache
X-Debug-Cache
X-Varnish-Beresp-Grace
X-Hosted-By
X-Generation-Time
X-Human
X-Via-Fastly
Cache-Name
X-ServerID
X-ProxyCache-Key
Url
X-Uri
X-Storage
Country-Code
X-Site-Version
X-FB-TRIP-ID
X-NCache
X-Cache-TTL-Remaining
Apigw-Requestid
Decoy-Debug-Status
Decoy-Debug-Key
X-Status
X-Origin-Date
X-Sql-Duration-Ms
X-Sql-Count
X-ProxyCache-Status
Decoy-Debug-TTL
Cache-Tv-Group
X-No-Session
X-PHP-Backend
X-BYPASS-REASON
X-Say-Cacheable
X-Say-TTL
TWC-GeoIP-LatLong
Mn-Server-Ip
Fastly-SSL
TWC-GeoIP-Country
X-SayCDN-TTL
Protected
TWC-Locale-Group
Property-Id
Selected-Fe
X-UA-Device-Type
X-Web-Node
TWC-Connection-Speed
TWC-Device-Class
X-Proxy-Build
X-PCL
Webcakes-Region
X-Format
X-Akamai-Edgescape
X-Ratelimit-Reset
X-Timing-Wait
Webcakes-App-Version
X-OCL
Webcakes-App-Name
X-Origin-Hint
TWC-Privacy
X-Cache-Host
Azure-InstanceId
Azure-RegionName
Azure-SlotName
Azure-SiteName
DB-Nickname
OT-Force-Account-Verify
X-Pubstack
X-NYM-Debug-Backend
Azure-Version
X-ApacheServer
X-R9-Blue-Green-Version
X-Access
X-Hl-Ver
X-PERF
X-Routing-Service
X-Zipkin-Id
X-Extlb
X-Proxied
X-Varnishpool
X-Section
X-Azure-Ref-OriginShield
X-Server-W
X-Cluster-Node
Source
X-LSADC-Cache
X-Be
X-Rewrite-Enabled
X-Cache-NGX
Content-Secure-Policy
X-Tid
X-RateLimit-Limit
X-Ua
X-Soup
X-SRV
X-Content-Age
X-Time
X-HTML-Minification-Powered-By
X-NewRelic-App-Data
X-Cache-Var
X-Cache-Var-Map
Content-Disposition
X-Amz-Meta-S3cmd-Attrs
X-Webkit-Csp
X-Cached-By
X-Presslabs-Stats
SRV
X-Dc
X-Unique-Id
Cache
CDN-EdgeStorageId
CDN-RequestId
CDN-Cache
CDN-Uid
CDN-RequestCountryCode
X-LAGOON
CDN-CachedAt
X-Generated-By
CDN-PullZone
X-Loop
X-Varnish-Hits
X-Varnish-Hostname
X-Bc-Bl
X-Hyper-Cache
X-TNCMS
Retry-After
X-App-Version
Onion-Location
X-S-Maxage
X-Auto-Login
X-Origin-CC
X-Origin-TTL
X-TT-LOGID
X-GEO
Webserver
X-Trace-Id
X-Tumblr-Pixel-3
X-Tumblr-Pixel-2
X-ECache
Cache-Hits
Web-Mar-Node
X-Nginx-Cache-Key
X-Proto
Xet-Cookie
X-Qnm-Cache
X-M-Reqid
X-Endurance-Cache-Level
X-Tenant
X-Time-Microsecs
X-M-Log
X-Akamai-Transformed
X-Cdn
X-Edge-Location
LB
X-GG-Cache-Date
Mime-Version
X-LJ-Flow-ID
X-VWS-Id
X-AWS-Id
X-Platform-Server
CloudFront-Viewer-Country
X-Mg-Request-UUID
X-CSRF-Token
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Labrador-Cache-Channel
X-PHP-Host
X-CACHE-KEY
X-Xfnlog-Site
N-Cache
HostName
X-Cache-Tags
X-B3-SpanId
X-Varnish-Cache-Hits
X-Handled-By
Upgrade-Insecure-Requests
X-RCS-CacheZone
X-Storefront-Renderer-Rendered
X-Locale
X-Request-Time
X-Origin-Response-Time
ServedBy
X-Adobe-Source
WPO-Cache-Status
WPO-Cache-Message
X-TIME
X-VC-Cache
X-AOL-HN
X-Cache-Remote
X-Connection-Hash
X-Rojux
X-S
X-D
X-Planisys-CDN-TTL
X-Destination
X-Processor
X-S-Cookie
X-Request-Host
X-SD-PageType
X-Session-Fingerprint
X-Shop-Environment
X-CF-Lambda-Fn
X-Ckpd-Fst-Backend
X-Cluster
X-ScT
Meta-Geo-Continent
X-Planisys-CDN-Rules
X-Conf
X-PAYTM-SRV-ID
X-Ig-Push-State
X-Reqid
X-External-Request-Id
DCR-Decision-By
X-Forwarded-Path
Nel
BehaviorPad-Version
X-Ftr-Request-Id
A
DCR-Processing-Time-Ms
DSUID
X-Developer
Mobile-Detection-Method
X-PBS-Appsvrname
Fastcgi-X-Cache-Version
X-Orig-Expires
X-NAPM-TraceId
X-ND-Cache
Expiry
X-Planisys-CDN-Cache
X-CF-Lambda-Version
Xc-Version
State
Surrogated-Key
X-Slack-Backend
X-Vtex-Processado-Em
Rendered-Blocks
X-VG-WebCache
X-B-Cookie
X-ARC
X-Application
X-ATG-Version
X-A-Ccd
X-A
X-A-Dam
X-A-Dcw
X-Aed
X-A-Wwc
X-A-Dgt
X-Vdms-Version
X-Vtex-Remote-Cache
X-Cache-Date
X-TIM-N
Pramga
X-V-Cache
X-SVT-ORM-RULES
X-Cache-NE
Odigeo-Trace-Id
X-SRCache-Key
Origin
Redirect-Candidate
X-SVT-ORM-VERSION
X-Vdms-Path
Datacenter
X-Correlation-ID
Environment
X-Via-NSCOPI
Server-Info
X-MP-GENERATED-AT
V-Age
X-Forwarded-Site
Vix-Hermes-Req-Id
Gh-Request-Id
CacheControlHeader
Wxu-Next-Hostname
X-Gdpr
Wxu-Next-Region
Cmsid
Host-ID
X-Fetched-On
X-Device-Os
X-Epic-Correlation-Id
X-Cache-Bucket
Fastcgi-Cache-TTL
X-Core-Mission
X-Cache-Info
X-Accel-Expires-Debug
Release
X-Date
X-Geo-Header
L
Cmstype
X-Li-Pop
X-Scheme
X-Server-IP
X-Skip-Cache
X-Sucuri-Cache
X-Rocket-Nginx-Serving-Static
X-Proxy-Upstream
X-Origin-Time
X-Owner
X-Policy
X-Sucuri-ID
X-Varnish-Beresp-Status
X-Fastly-Cache
X-Gen-Mode
X-Hnp-Log
From-Origin
X-Block-Status
X-VG-TLSProxy
X-VServer
User-Cache-Control
X-Origin-Expires
X-Served-From
X-LI-UUID
X-Men
Wxu-Next-Commit
X-Li-Fabric
X-Old-Content-Length
X-Hash
X-Location
AKAMAI
X-Mvc-Supplant-Cachable
X-Nyt-Route
AMP-Access-Control-Allow-Source-Origin
X-Generated-On
Arc-Country
CDCHOST
X-TH-Server
X-HN
X-Bip
X-Viewer-Country
Origin-CC
X-HS-Content-Campaign-Id
X-Branch-Name
X-Aicache-OS
X-BBC-Edge-Cache-Status
X-Gzip
X-Cache-Debug
X-Core-Value
Traceparent
X-VarnishDD-TTL
X-Gamma-Serve
X-GeoIP-City
Req-Svc-Chain
Origin-EX
X-Cache-Id
X-Datadog-Parent-Id
X-Region-Sid
X-Req
X-Request-Start
X-Datadog-Sampling-Priority
X-Datadog-Trace-Id
X-Developers
X-NodeID
X-Platform
X-Esi-Check
X-Rocket-Build-Number
X-GeoIP
X-Thanos
X-Thinkindot-L3
X-Cache-Config
X-TrackingId
X-Sn-Servicetimems
X-Cdn-Origin
X-Sigma
X-Sigma-Backend
X-Fastly-Backend
X-Irp-Debug
X-Level-Front-Cache
X-Magnolia-Registration
Mail-Subject
Svr
TDXMobile
Machine
Apple-News-Services-Request-Url
X-Ratelimit-Remaining
Apple-News-Services-Handled
PFcat
Apple-News-Services-Host
Server-Host
Apple-News-Services-Parsed-Url
Locid
Candidate-Md5Url
Thinkindot-CacheControl
Fastly-GeoIP-CountryCode
We-Hiring
Web-Mar-Region
True-Client-Country-4JS
Thinkindot-CacheControl-Type
Thinkindot-Control
X-Loc
X-Has-Esi
X-Is-Gdpr
Adler-Geo
X-JWT-State
X-DPWN-IS-SECURE
X-Worker
Cf-Device-Type
X-FC-Vary-Parameters
X-Eu-Site
X-DefHash
X-Qloud-Router
X-Varnish-CookieINHashed-On
X-Varnish-CookieHashed-On
X-Variation
X-Varnish-Remaining-TTL
NGX
X-EC-Lua
Fastly-SIE
Fastly-SWR
X-UnsetCookies
X-Envoy-Decorator-Operation
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-Origin
X-Pod-Name
X-DefElseHash
X-Request-URI
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-NU-AKA-ACS-Version
X-Webstats-RespID
X-Csrf-Jwt
Is-Eu
L5d-Success-Class
NM-Fastcgi-Cache
Memcached
X-CGP
X-Amzn-Remapped-Content-Length
HA-Ipaddr
X-Backend-State
Ha-Gx-Prefs
Platform
X-FireWall-Port
X-Xrds-Location
Fastly-Drupal-Html
X-Tx-Id
Sslversion
X-Node-Id
WWW-Authenticate
X-Cdn-Srv
X-Varnish-Beresp-Ttl
CDN
X-Zone
X-NC
X-Response-By
X-CLOUD-TRACE-CONTEXT
X-Up
X-Mvc-Supplant-OutputCached
X-CS
Ssr
Esi-Enabled
On-Server
X-API-Version
X-Vc
WP-Super-Cache
X-Generated-In
X-LB-ID
Pics-Label
X-Tt-Logid
X-Trace-ID
Ms-Author-Via
Memory
Time
X-Service
X-Refresh
C-Via
X-Datadome
X-Backend-TTL
X-Cache-PHP
X-Edge-Pop
NtCoent-Length
X-LB-NoCache
X-Cache-Enabled
X-TA-CDN-Provider
X-TraceId
X-DynaTrace-JS-Agent
X-Via-Popv
X-Via-Popn
X-Tb-Optimization-Total-Bytes-Saved
X-GeoIP-Region-Code
GeoIp-Country-Code
X-GeoIP-Country-Code
X-Via-Poph
Env
X-Varnish-Ttl
X-Dynatrace
X-NWS-UUID-VERIFY
Magicmarker
X-Cache-Status-Check
X-Parent-Response-Time
X-Optimistic-Header
X-DC
X-Render-Time
X-Varnish-Beresp-TTL
X-Info
X-ZONE
X-Cs
X-Restarts
X-Ua-Device
X-Esi
X-CacheTTL
X-Servedbyhost
Kp-EeAlive
X-TX-ID
X-AIR-PT
WebServer
X-Unique-ID
Server-ID
S-Rt
X-Wix-Viewer-Type
X-RPM
X-RSL
Edge-Cache
X-DW
X-Srv
X-Clientip
X-MSEdge-Flight
X-DI
X-Action
X-RPS
X-MSEdge-Features
X-DB
X-Cache-Backend
X-DSS
UCS
X-Oss-Server-Time
Cache-Host
X-Oss-Storage-Class
X-VCL-Version
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
HIT
X-Oss-Request-Id
X-Li-Proto
X-App
X-Newrelic-Synthetics
Proxy-Connection
X-Cache-Ttl
X-Fpc
S-Cnection
X-Minions-Version
X-LI-Proto
Lb
Section-Io-Origin-Time-Seconds
X-URL
Section-Io-Id
Section-Io-Origin-Status
X-LiteSpeed-Cache-Control
Section-Origin-Responded
X-HA-Backend
Test
X-FPC
X-Webkit-Csp-Report-Only
X-Akamai-Request-ID2
X-Traceid
X-Http-Reason
X-Micro-Cache
Fastly-Backend-Name
Server-Id
X-B3-Spanid
User-Agent
X-Vcl-Version
X-Webkit-CSP-Report-Only
X-NODE
Tcn
Geo-Info
X-Backend-Host
Accept-Language
X-Pass-Why
X-Pad
X-Ec-GeoHdr
X-Ec-Fail
X-Release
X-BCube-Filmed-By
X-CSRF-TOKEN
X-User
X-ES-SERVER
X-HostName
X-Urbn-Context-Path
X-Urbn-Site-Id
X-APP
X-LiteSpeed-Tag
Fastly-Drupal-HTML
Cf-Int-Pingora-Origin-Digest
Hostname
Locale
Resin-Trace
X-Check-Cacheable
X-ID
X-BBC-Origin-Response-Status
Cache-Key
X-ServedByHost
VNS-Age
VNS-Cache
X-Ha-Backend
Path
X-Amz-Meta-Cb-Modifiedtime
EpKe-Alive
CPC-Age
CPC-Cache
X-Dynatrace-Js-Agent
X-COUNTRY
X-WA-Info
GeoIP-Country-Code
X-WADP-Cache
Hit
X-WA
Cdncip
Srv
X-NGINX-Cache
M-TraceId
X-Akamai-Pragma-Client-IP
Cdnsip
X-AK-Request-ID
X-Via-PopV
Ohc-File-Size
X-Via-PopH
X-Clara-WADP
X-Fmm-Version
X-Via-PopN
X-Geo
X-Wikidot-Static-Cache
X-Cms-Context
Shield-Pop
Pagetype
X-Wikidot-Backend
X-Cdn-Forward
X-ElasticPress-Query
Cluster
ENV
MIME-Version
Geoip-Latitude
My-App
X-PJAX-URL
X-Edge-POP
X-Var-Ttl
X-From
X-Via-Ucdn
X-Api-Version
X-Edge-Cache
X-HS-Status
Tracecode
Lfy
Load-Balancing
X-Hcs-Proxy-Type
MD5-Digest
X-CUA
X-CCDN-Origin-Time
X-CCDN-CacheTTL
T-Server
X-Ucs
X-VG-WebServer
URI
X-Fastly-Cache-Hits
X-ServerName
X-Cache-Expires
Sever-Int
Servername
Lang
X-SIPLIST1
X-UP
X-Fastly-Backend-Reqs
W
X-RAMCache
WZWS-RAY
IsBot
X-Mcache
X-Lb-Id
Server-Ext
X-Fragments
Server-Hostname
X-GoCache-CacheStatus
X-TRACE-ID
X-Dw-Trace-Id
Cdn
X-VC
Cneonction
X-Provided-By
X-RateLimit-Reset
PICS-Label
Ohc-Cache-HIT
Cteonnt-Length
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
X-Nc
X-B3-ParentSpanId
Target-Params
X-Cdn-Request-ID
Server-Ttl
X-Last-Modified
X-Acquia-Application-UUID
X-Cc-Via
X-Swift-Error
X-Acquia-Application-Trace
X-Acquia-Purge-Tags
X-Acquia-Site
Cf-Ipcountry
X-Platform-Processor
X-Platform-Router
X-Platform-Cluster
X-Newrelic-App-Data
X-Contensis-Viewer-Groups
X-Via-CDN
X-Yottaa-OS
X-Apw-Hits
X-Apw-Access-Token
X-Apw-Access-Object
X-Apw-Access-Action
CF-Cached-On
X-Cache-ASPX
X-Snapshot-Date
HitType
Dnion-Transfer-Encoding
X-Akamai-Request-ID
Vha6-Origin
X-Cache-Ngx
X-Air-Pt
Sid
X-Akamai-ERPolicy
X-Http-Count
X-Varnish-Authentication
X-Te-Count
Uri
X-Akamai-ERRuleID
X-Te-Duration-Ms
X-Http-Duration-Ms
X-CacheKey
X-Sentry-ID
X-HTML-Edge-Cache
Req-ID
CountryCode
Ngx
FSS-Cache
X-Lb-Nocache
X-Miniprofiler-Ids
X-B3-Parentspanid
X-UA
X-Logging-Id