Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-Cache-Status
Link
Accept-Ranges
CF-RAY
ETag
X-XSS-Protection
Expect-CT
Pragma
X-Powered-By
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
Alt-Svc
X-UA-Compatible
P3P
X-Served-By
X-Xss-Protection
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Cache-Status
X-Generator
X-Cacheable
Timing-Allow-Origin
X-Content-Security-Policy
P3p
X-Iinfo
Feature-Policy
Status
X-Envoy-Upstream-Service-Time
Content-Encoding
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
X-CDN
X-AspNetMvc-Version
Upgrade
X-Via
CF-Ray
X-Ws-Request-Id
Access-Control-Max-Age
X-Request-ID
Server-Timing
EagleId
Keep-Alive
X-Cache-Group
X-Turbo-Charged-By
Request-Context
X-Age
X-UA-Device
X-Server-Powered-By
X-Proxy-Cache
X-AH-Environment
X-Ua-Compatible
X-Backend
X-Robots-Tag
X-Hacker
Report-To
X-Amz-Request-Id
Host-Header
X-Server
X-Amz-Id-2
Grace
X-LiteSpeed-Cache
X-Rq
X-Nginx-Cache-Status
X-Varnish-Cache
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-Dns-Prefetch-Control
X-WebKit-CSP
X-Page-Speed
X-Vhost
EagleEye-TraceId
X-Amz-Version-Id
X-OneAgent-JS-Injection
X-Pingback
X-Dispatcher
X-Device
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
NEL
X-Cache-Spec
X-Host
X-Server-Id
Cf-Railgun
X-Node
X-Backend-Server
Accept-CH
X-Readtime
Surrogate-Control
X-Akam-SW-Version
Request-Id
X-Response-Time
X-HW
Xkey
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Application-Context
Content-Location
X-Ruxit-JS-Agent
Rating
X-Country
Accept-Ch-Lifetime
Accept-CH-Lifetime
X-B3-TraceId
X-Cache-Lookup
X-Cloud-Trace-Context
X-Trace
X-Url
X-Ac
X-Content-Type
Allow
X-Vname
X-TtlSet
X-PC
X-Varnish-TTL
X-Clacks-Overhead
X-Mod-Pagespeed
Edge-Control
X-FastCGI-Cache
X-ESI
X-Server-Name
Fastly-Restarts
Cache-Tag
Service-Worker-Allowed
X-Rack-Cache
X-VARITI-CCR
X-Element-Page-Cache
Verso
X-Aws-Lambda-Call-Status
X-MS-InvokeApp
X-Upstream
MS-Author-Via
X-GitHub-Request-Id
X-Amz-Rid
X-Vcap-Request-Id
Public-Key-Pins
X-Dw-Request-Base-Id
X-Cached
X-Client-IP
X-D2id
X-Abt-Application-Version
X-Cache-TTL
X-Cnection
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
X-Px
X-Origin-Cache
X-Country-Code
Arr-Disable-Session-Affinity
RTSS
Access-Control-Request-Method
X-Navigation-Version
X-Goog-Hash
X-Powered-By-Plesk
X-NF-Request-ID
X-Instrumentation
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-GoogleNews-Bot
X-Exp-Variant
X-Exp-Id
X-Kinja
X-Kinja-Build
X-Use-Magma
X-Kinja-Revision
X-Cdn-Fetch
X-Kinja-Server
Accept-Ch
X-Powered-CMS
X-Version
AR-PoweredBy
AR-SID
AR-Request-ID
AR-CACHE
AR-ATIME
X-Language
X-Middleton-Display
Display
X-Sol
Pagespeed
X-Amz-Server-Side-Encryption
Response
X-Middleton-Response
X-MSEdge-Ref
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-LLID
X-Kinsta-Cache
X-Edge-Location-Klb
X-Edge
Nginx-Cache
X-TTL
X-Template
Mrf-Cache-Status
MRF-Tech
X-B3-TraceId-Primal
X-RateLimit-Remaining
X-Protected-By
X-Shield-Request-Id
X-HP-Webp
X-HP-Trace-Id
X-Jurisdiction
TCN
X-T
X-Forwarded-For
X-Content-Security-Policy-Report-Only
S
X-Id
X-Mg-S
Content-MD5
X-Aspnetmvc-Version
Edge-Cache-Tag
X-Mid
Fastcgi-Cache
Realpath
X-CST
SPRequestDuration
SPIisLatency
Front-End-Https
X-Recruiting
X-Request-Received
X-Request-Processing-Time
X-Ttl
X-MCACHE
X-Pinterest-Rid
Filters
Pinterest-Version
Pinterest-Generated-By
Server-Node
X-Ua-Browser
X-Content
X-Ab
X-DynaTrace
X-Correlation-Id
Server-Name
X-Frontend
X-Ruxit-Js-Agent
X-NWS-LOG-UUID
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Cache-Config
X-SharePointHealthScore
SPRequestGuid
X-HS-Combine-CSS
X-Yandex-Sdch-Disable
X-Ezoic-Cdn
X-Parallel-Accel
X-ECACHE
Fusion-Content-Source
Fusion-Content-Id
X-Ser
Fusion-Component-Id
Fusion-Deployment-Id
Fusion-Template-Id
Fusion-Source
X-Hits
Alternate-Protocol
X-Cache-Key
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Content-Options
MicrosoftSharePointTeamServices
X-Buckets
X-Page-Id
Cache-Tags
Cleartype
Charset
X-Git-Hash
X-B3-Sampled
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Fastly-Request-Id
Host
X-Www-Served-By
X-Server-ID
X-Geo-Country
X-DIS-Request-ID
X-Daa-Tunnel
X-Debug-Info
X-Amzn-Trace-Id
X-Content-Digest
X-Accel-Expires
X-Amz-Replication-Status
Filterid
X-Varnish-Age
X-Activity-Id
X-AppVersion
X-FB-Debug
X-Ratelimit-Limit
X-Az
X-Forwarded-Proto
X-Hostname
X-VCache
X-Upgrade-Enabled
TP-L2-Cache
TP-Cache
X-Rid
Cross-Origin-Opener-Policy
X-N
X-Grace
X-Origin-Server
Access-Control-Allow-Method
X-WebKit-CSP-Report-Only
X-XRDS-LOCATION
X-Nginx-Upstream-Cache-Status
X-LB-Cache
X-F-Cache
X-Mobile-URL
ServerID
X-Route-Name
X-Request-Guid
X-Is-Crawler
X-Providence-Cookie
X-Flags
X-Aspnet-Duration-Ms
X-Whom
X-Goog-Storage-Class
X-GUploader-UploadID
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Metageneration
Viewport
X-Tb
X-App-Environment
X-TT
X-Varnish-Grace
X-Seen-By
X-FW-Type
X-FW-Serve
Node
X-FW-Static
Payment
X-FW-Server
X-FW-Hash
X-FW-Dynamic
X-Type
DC
X-Distributor
Paypal-Debug-Id
X-App-Server
X-User-Agent
X-Origin-Upstream-Status
Fastcgi-Useragent
X-NGENIX-Cache
X-Oneagent-Js-Injection
Country
X-Cache-Control
Accept-Charset
X-Wix-Request-Id
X-Cache-Rule
X-Logged-In
X-Litespeed-Cache
X-Request-Handler-Origin-Region
X-Microsite
Version
X-Cache-Age
X-Via-JSL
X-Webkit-Csp
X-Webkit-CSP
Referer-Policy
X-Drupal-Cache-Tags
X-DataDome
X-Browser-Type
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Varnish-Backend
X-Cluster-Name
X-Signature
Refresh
X-B-Cache
X-Contextid
X-Load-Cache
X-Node-Name
Cache-Status
X-Response-Served-From
X-Tec-Api-Version
X-Tec-Api-Root
X-Mobile
Amp-Access-Control-Allow-Source-Origin
X-Original-Request-Id
SD-X-WS
X-Tec-Api-Origin
X-Real-IP
X-Is-Bot
X-Cache-Expired-At
X-Page-View
X-Proxy-Cache-Status
X-Rendered-As
Access-Control-Request-Headers
NGB
X-RemovedCookies
X-IPLB-Instance
X-Cacheable-TTL
X-ProcessESI
X-Debug
X-Jobs
X-Vgn-Hpd-Reason
X-UUID
X-Cache-Action
X-Proxy
X-Device-Type
X-B
X-Revision
X-Rule
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Ratelimit-Reset
X-Instance
VIX-Pulpo-Upstream-Status
X-Fastly-Request-ID
X-Cache-Time
X-G
Akamai-GRN
X-Framework
VIX-Pulpo-Node
X-Drupal-Cache-Contexts
Surrogate-Key
X-Debug-IsConnected
X-Debug-IsPreview
X-FW-Version
CF-IPCountry
X-Fastcgi-Cache
X-Air-Source
X-Air-Trace-Id
X-Air-Hostname
X-TEC-API-ROOT
X-TEC-API-VERSION
X-TEC-API-ORIGIN
DynaTrace
SID
Liferay-Portal
X-Azure-Ref
X-Oracle-Dms-Ecid
X-XRDS-Location
X-Oracle-Dms-Rid
X-PressLabs-Stats
X-Presslabs-Stats
GEO-INFO
Healthy
Frame-Options
X-Ms-Version
X-Ms-Request-Id
X-Cache-Operation
Count-Hit
X-Accel-Buffering
X-Source
X-Nginx-Cache
Ms-Operation-Id
X-RTag
X-CDN-Forward
MS-CV
Uber-Trace-Id
X-APP-VERSION
X-EdgeConnect-Cache-Status
X-Tumblr-Pixel
Xserver
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-Tumblr-User
Countrycode
X-L-Path
X-Environment-Context
X-Cache-Hit
X-Cache-NGX
X-Zen-Fury
X-Varnish-Server
X-Backend-Name
X-Mode
X-Region
Cross-Origin-Window-Policy
Ec-Rule-Version
X-Servername
X-Forwarded-Host
X-IPS-LoggedIn
Backend
Protected
X-Content-Powered-By
X-Cache-TTL-Remaining
X-Cache-Type
Meta-Geo
X-Rewrite-Enabled
X-JoinUs
X-SaId
X-Detected-As
X-RN-RSRV
X-UPSTREAM-Address
X-ShardId
X-Cache-Grace
X-ShopId
X-Generation-Time
X-Varnish-Beresp-Grace
X-Cache-Server
X-Sql-Count
X-Sorting-Hat-PodId
X-Debug-Cache
X-Hosted-By
Eomportal-Instance
X-Zipkin-Id
X-Redis-Cache
Decoy-Debug-Status
Section-Io-Cache
X-Extlb
Decoy-Debug-Key
Country-Code
X-Human
X-Sorting-Hat-ShopId
X-Shopify-Stage
X-Proxied
X-Sql-Duration-Ms
Decoy-Debug-TTL
X-Alternate-Cache-Key
X-Routing-Service
Url
X-ApacheServer
X-NCache
Mn-Server-Ip
X-Via-Fastly
X-FB-TRIP-ID
X-BYPASS-REASON
X-Soup
X-Microcachable
X-ProxyCache-Status
X-Storage
X-UA-Device-Type
X-Uri
X-Tid
Cache-Tv-Group
Cache-Name
X-Status
X-PERF
X-Site-Version
Apigw-Requestid
Fastly-SSL
X-ProxyCache-Key
X-PHP-Backend
X-Format
X-No-Session
X-Origin-Date
TWC-GeoIP-LatLong
Property-Id
TWC-GeoIP-Country
TWC-Connection-Speed
TWC-Device-Class
Selected-Fe
TWC-Locale-Group
X-Proxy-Build
X-OCL
X-Web-Node
X-Server-W
X-Cluster-Node
X-Origin-Hint
X-NYM-Debug-Backend
X-ServerID
X-Timing-Wait
X-PCL
X-Section
X-Akamai-Edgescape
X-Say-Cacheable
Webcakes-App-Version
Webcakes-App-Name
X-Say-TTL
X-Access
X-Adobe-Loc
X-Adobe-Content
X-SayCDN-TTL
TWC-Privacy
Webcakes-Region
X-Content-Age
X-Cache-Host
X-Hl-Ver
X-Varnishpool
X-Hyper-Cache
X-R9-Blue-Green-Version
OT-Force-Account-Verify
X-Pubstack
Azure-RegionName
Azure-SiteName
DB-Nickname
Azure-Version
Azure-InstanceId
Azure-SlotName
X-TIME
X-Be
X-RateLimit-Limit
Content-Secure-Policy
CDN-EdgeStorageId
SRV
CDN-RequestId
X-LSADC-Cache
X-Ua
CDN-CachedAt
CDN-PullZone
CDN-RequestCountryCode
CDN-Cache
CDN-Uid
X-Trace-Id
X-Generated-By
X-Azure-Ref-OriginShield
Content-Disposition
LB
X-Ratelimit-Remaining
X-NewRelic-App-Data
WPO-Cache-Message
WPO-Cache-Status
X-Cached-By
Source
X-Dc
Cache
X-SRV
X-Nginx-Cache-Key
X-Unique-Id
X-Bc-Bl
X-LAGOON
X-App-Version
Retry-After
Xet-Cookie
X-TT-LOGID
X-Auto-Login
Cache-Hits
X-Origin-CC
X-HTML-Minification-Powered-By
X-GEO
X-Varnish-Hits
Mime-Version
X-Origin-TTL
X-Varnish-Hostname
X-Loop
X-TNCMS
X-Platform-Server
X-S-Maxage
X-Akamai-Transformed
Onion-Location
X-ECache
X-Amz-Meta-S3cmd-Attrs
X-Cache-Remote
X-Xfnlog-Site
X-Cdn
HostName
X-Tumblr-Pixel-3
X-Tumblr-Pixel-2
X-Cache-Tags
Web-Mar-Node
Webserver
Upgrade-Insecure-Requests
X-Varnish-Cache-Hits
X-Proto
ServedBy
X-Request-Time
X-Cache-Var-Map
X-CSRF-Token
X-Cache-Var
X-Endurance-Cache-Level
X-Tenant
X-AOL-HN
X-Time-Microsecs
X-VWS-Id
N-Cache
X-AWS-Id
X-Edge-Location
X-EC-Lua
X-LJ-Flow-ID
X-Time
X-Request-Host
X-GG-Cache-Date
WP-Super-Cache
From-Origin
X-FireWall-Port
CloudFront-Viewer-Country
X-Via-NSCOPI
X-Mg-Request-UUID
X-Origin-Response-Time
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Labrador-Cache-Channel
X-PHP-Host
X-ScT
X-Rojux
DCR-Decision-By
X-S-Cookie
X-Connection-Hash
X-S
X-NAPM-TraceId
Redirect-Candidate
X-Hnp-Log
Sslversion
Rendered-Blocks
X-ND-Cache
BehaviorPad-Version
X-CF-Lambda-Fn
X-VG-WebCache
X-D
X-Processor
X-Ckpd-Fst-Backend
Fastcgi-X-Cache-Version
X-Conf
X-PAYTM-SRV-ID
X-External-Request-Id
X-PBS-Appsvrname
Meta-Geo-Continent
Mobile-Detection-Method
X-Ig-Push-State
Expiry
Pramga
DSUID
Origin
X-CF-Lambda-Version
X-Orig-Expires
A
Odigeo-Trace-Id
DCR-Processing-Time-Ms
X-Shop-Environment
X-ARC
X-Application
X-B-Cookie
Xc-Version
X-Qnm-Cache
X-SD-PageType
X-TIM-N
X-Correlation-ID
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-A-Wwc
X-Aed
X-Ftr-Request-Id
X-Block-Status
X-Cache-NE
X-B3-SpanId
X-Vdms-Path
X-Vdms-Version
X-Forwarded-Path
X-Vtex-Processado-Em
X-Cache-Date
X-Destination
X-Vtex-Remote-Cache
X-M-Reqid
X-M-Log
X-Developer
X-A-Dgt
X-Gen-Mode
X-A
Surrogated-Key
X-Session-Fingerprint
Nel
User-Cache-Control
X-Slack-Backend
X-A-Ccd
X-SRCache-Key
X-A-Dam
X-A-Dcw
X-Handled-By
X-RCS-CacheZone
X-MP-GENERATED-AT
X-Cache-Enabled
X-NWS-UUID-VERIFY
X-Hash
Traceparent
Fastcgi-Cache-TTL
True-Client-Country-4JS
Cmsid
X-Core-Mission
X-Location
Svr
X-Forwarded-Site
State
X-Cache-Info
X-Cache-Bucket
Ssr
X-Men
X-Mvc-Supplant-Cachable
Cmstype
Wxu-Next-Hostname
X-Li-Fabric
L
Host-ID
X-Geo-Header
X-Cdn-Srv
Origin-EX
X-Fastly-Cache
X-Accel-Expires-Debug
X-Li-Pop
Gh-Request-Id
X-Cluster
Origin-CC
Wxu-Next-Commit
X-Gdpr
Release
Wxu-Next-Region
X-LI-UUID
V-Age
X-Planisys-CDN-Rules
X-Rocket-Nginx-Serving-Static
Server-Info
X-Zone
X-Served-From
X-Date
X-Epic-Correlation-Id
X-Policy
X-Proxy-Upstream
Fastly-Drupal-Html
X-Fetched-On
X-Server-IP
X-Skip-Cache
X-Varnish-Beresp-Status
X-Locale
X-VServer
X-Device-Os
X-V-Cache
X-Webstats-RespID
X-Aicache-OS
X-Sucuri-Cache
X-Sucuri-ID
X-CACHE-KEY
X-Planisys-CDN-TTL
X-Scheme
X-Nyt-Route
X-Old-Content-Length
X-Planisys-CDN-Cache
AKAMAI
X-Origin-Expires
CacheControlHeader
X-NodeID
Arc-Country
CDCHOST
X-Origin-Time
Environment
X-Reqid
AMP-Access-Control-Allow-Source-Origin
X-Magnolia-Registration
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
X-Storefront-Renderer-Rendered
X-TH-Server
Apple-News-Services-Host
X-GeoIP-City
X-Gzip
Apple-News-Services-Handled
We-Hiring
Web-Mar-Region
X-Thanos
X-Request-URI
X-GeoIP
X-Sn-Servicetimems
X-UnsetCookies
X-Core-Value
X-Branch-Name
X-Bip
X-Developers
X-Cache-Debug
X-VG-TLSProxy
X-VarnishDD-TTL
X-Cache-Id
X-Gamma-Serve
X-BBC-Edge-Cache-Status
X-Generated-On
X-TrackingId
X-Thinkindot-L3
X-Sigma-Backend
X-ATG-Version
X-Backend-State
Vix-Hermes-Req-Id
X-Adobe-Source
X-Sigma
X-Datadog-Sampling-Priority
X-Level-Front-Cache
X-CGP
X-RateLimit-Remaining-Second
X-Datadog-Trace-Id
X-Region-Sid
PFcat
X-Irp-Debug
X-Req
X-RateLimit-Limit-Second
X-Datadog-Parent-Id
X-Esi-Check
X-Fastly-Backend
X-Platform
L5d-Success-Class
Locid
Ha-Gx-Prefs
Mail-Subject
Machine
X-Cdn-Origin
X-Request-Start
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
TDXMobile
X-Eu-Site
Thinkindot-Control
X-VC-Cache
HA-Ipaddr
X-HN
X-Viewer-Country
X-Csrf-Jwt
X-Node-Id
X-Rocket-Build-Number
Fastly-GeoIP-CountryCode
Req-Svc-Chain
X-Envoy-Decorator-Operation
X-Owner
X-HS-Content-Campaign-Id
Server-Host
X-DefHash
X-FC-Vary-Parameters
X-DefElseHash
X-DPWN-IS-SECURE
X-Pod-Name
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-Qloud-Router
X-Origin
X-Amzn-Remapped-Content-Length
X-Response-By
X-Variation
X-Worker
X-Backend-TTL
X-Varnish-Remaining-TTL
X-Varnish-CookieINHashed-On
X-Varnish-CookieHashed-On
X-NU-AKA-ACS-Version
Adler-Geo
Cf-Device-Type
Platform
NGX
NM-Fastcgi-Cache
X-JWT-State
Memcached
Is-Eu
X-Has-Esi
X-Loc
Fastly-SIE
Fastly-SWR
X-Is-Gdpr
X-Datadome
X-Xrds-Location
X-GeoIP-Region-Code
X-Mvc-Supplant-OutputCached
X-GeoIP-Country-Code
X-Cache-Config
X-Tx-Id
X-Ua-Device
X-CLOUD-TRACE-CONTEXT
X-CS
X-NC
X-API-Version
S-Rt
X-TA-CDN-Provider
X-Generated-In
X-TraceId
X-Varnish-Beresp-Ttl
Magicmarker
X-Up
X-LB-ID
Pics-Label
X-Restarts
CDN
Candidate-Md5Url
Datacenter
Kp-EeAlive
X-Tt-Logid
X-Trace-ID
Ms-Author-Via
X-Tb-Optimization-Total-Bytes-Saved
X-Vc
Memory
X-Akamai-Request-ID2
Env
NtCoent-Length
X-Http-Reason
X-LB-NoCache
Time
X-Edge-Pop
X-DynaTrace-JS-Agent
X-RPM
X-DW
X-RPS
X-DB
X-Wix-Viewer-Type
X-DSS
X-Cache-Backend
X-Action
WWW-Authenticate
X-DI
X-Varnish-Ttl
X-Via-Poph
X-RSL
X-Via-Popn
WebServer
Edge-Cache
X-Optimistic-Header
X-Refresh
X-Via-Popv
GeoIp-Country-Code
On-Server
X-Parent-Response-Time
Esi-Enabled
X-Varnish-Beresp-TTL
X-CacheTTL
X-DC
Accept-Language
X-Minions-Version
X-Cs
X-Esi
C-Via
X-Service
X-Dynatrace
X-Servedbyhost
X-Srv
X-Unique-ID
X-MSEdge-Flight
X-Cache-PHP
X-MSEdge-Features
X-HA-Backend
X-TX-ID
X-Newrelic-Synthetics
Locale
X-Urbn-Site-Id
Server-ID
X-Urbn-Context-Path
X-ZONE
X-Cache-Status-Check
X-VCL-Version
X-Ec-GeoHdr
X-User
X-Render-Time
X-Ec-Fail
X-FPC
X-App
X-Li-Proto
X-LI-Proto
X-Cache-Ttl
X-URL
X-B3-Spanid
X-Webkit-Csp-Report-Only
X-Fpc
Test
Server-Id
Proxy-Connection
X-Traceid
X-LiteSpeed-Cache-Control
X-Vcl-Version
Cdncip
Cdnsip
X-AK-Request-ID
X-Info
X-Webkit-CSP-Report-Only
X-Pass-Why
X-AIR-PT
X-NODE
My-App
X-Fmm-Version
Geoip-Latitude
Cluster
Geo-Info
X-Clara-WADP
X-WADP-Cache
Tcn
X-Clientip
X-Mcache
UCS
X-Oss-Storage-Class
X-CSRF-TOKEN
X-CUA
X-Var-Ttl
Resin-Trace
Tracecode
HIT
Cache-Host
X-Oss-Hash-Crc64ecma
X-Oss-Server-Time
X-Oss-Object-Type
M-TraceId
X-Oss-Request-Id
T-Server
Lfy
X-Ha-Backend
X-From
Fastly-Drupal-HTML
X-LiteSpeed-Tag
X-HostName
S-Cnection
Cf-Int-Pingora-Origin-Digest
Hostname
X-ID
Lang
X-ServedByHost
DataCenter
X-Fragments
Target-Params
X-B3-Traceid
Fastly-Backend-Name
Ohc-File-Size
X-Via-PopN
X-Via-PopH
X-Via-PopV
Hit
X-WP-CF-Super-Cache
User-Agent
X-Micro-Cache
GeoIP-Country-Code
X-WP-CF-Super-Cache-Cache-Control
X-Pad
X-Geo
X-Dynatrace-Js-Agent
X-NGINX-Cache
X-RAMCache
X-Backend-Host
ENV
X-Edge-POP
X-Release
X-ElasticPress-Query
MIME-Version
X-BBC-Origin-Response-Status
X-Cdn-Forward
X-Check-Cacheable
X-VC
X-Api-Version
Section-Io-Id
Load-Balancing
Section-Origin-Responded
X-Edge-Cache
X-APP
X-BCube-Filmed-By
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
Lb
X-Proxy-Cache-Info
URI
Servername
X-ServerName
X-Fastly-Backend-Reqs
EpKe-Alive
X-Lb-Nocache
X-UP
X-HS-Status
X-Httpd
X-Ucs
X-Provided-By
Cache-Key
X-WA-Info
X-WA
CPC-Age
X-GoCache-CacheStatus
Path
VNS-Cache
X-Lb-Id
CPC-Cache
FSS-Cache
PICS-Label
Server-Ttl
Permissions-Policy
ServerName
VNS-Age
Uri
Producers
X-Amz-Meta-Cb-Modifiedtime
X-TRACE-ID
Sid
X-SB
X-Pool
X-Udemy-Cache-App-Namespace
X-Cache-CFC
WZWS-RAY
X-RateLimit-Reset
Cneonction
X-ES-SERVER
X-B3-ParentSpanId
X-Nc
Cdn
Ohc-Cache-HIT
X-Cdn-Request-ID
X-Wikidot-Static-Cache
Cteonnt-Length
X-Wikidot-Backend
X-Fastly-Cache-Hits
Vha6-Origin
X-Dw-Trace-Id
X-Akamai-ERPolicy
X-Acquia-Site
X-Apw-Hits
X-Cache-ASPX
X-Akamai-ERRuleID
Shield-Pop
X-Vcache
X-Newrelic-App-Data
X-Ec-Custom-Error
X-Platform-Cluster
X-Platform-Processor
X-Platform-Router
X-Akamai-Request-ID
Cf-Ipcountry
X-Apw-Access-Object
X-Apw-Access-Action
X-Acquia-Application-UUID
X-Apw-Access-Token
X-Acquia-Purge-Tags
X-Yottaa-OS
X-Cms-Context
CF-Cached-On
X-Swift-Error
Pagetype
X-Snapshot-Date
X-PJAX-URL
X-Contensis-Viewer-Groups
X-Acquia-Application-Trace
X-Cache-Ngx
X-Air-Pt
X-Via-Ucdn
X-UA
X-CacheKey
X-Shopify-Generated-Cart-Token
Req-ID
X-CCDN-CacheTTL
X-Akamai-Pragma-Client-IP
X-Hcs-Proxy-Type
X-Scale
X-Logging-Id
X-Te-Duration-Ms
X-CCDN-Origin-Time
X-Te-Count
X-Http-Duration-Ms
X-Http-Count
X-Varnish-Authentication
MD5-Digest
CountryCode
Ngx
X-Last-Modified
X-Miniprofiler-Ids
X-Sentry-ID