Threat Level: green Handler on Duty: Jan Kopriva

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-Cache-Status
Link
Accept-Ranges
CF-RAY
ETag
X-XSS-Protection
Expect-CT
Pragma
X-Powered-By
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-UA-Compatible
X-Cache-Hits
Alt-Svc
P3P
X-Served-By
X-Xss-Protection
X-Download-Options
X-Timer
X-Request-Id
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Cache-Status
X-Generator
X-Cacheable
Timing-Allow-Origin
P3p
X-Content-Security-Policy
X-Iinfo
Status
Feature-Policy
X-Envoy-Upstream-Service-Time
Content-Encoding
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
X-CDN
X-AspNetMvc-Version
X-Request-ID
Upgrade
X-Via
CF-Ray
X-Ws-Request-Id
Access-Control-Max-Age
Server-Timing
EagleId
X-Cache-Group
Keep-Alive
X-Turbo-Charged-By
Request-Context
X-Age
X-Server-Powered-By
X-Proxy-Cache
X-AH-Environment
X-UA-Device
X-Backend
X-Hacker
X-Robots-Tag
Report-To
X-Amz-Request-Id
Host-Header
X-Server
X-Amz-Id-2
X-LiteSpeed-Cache
Grace
X-Rq
X-Nginx-Cache-Status
X-Varnish-Cache
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-WebKit-CSP
X-Dns-Prefetch-Control
X-Page-Speed
X-Vhost
EagleEye-TraceId
X-OneAgent-JS-Injection
X-Amz-Version-Id
X-Pingback
X-Device
X-Dispatcher
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Cache-Spec
NEL
X-Server-Id
X-Host
Cf-Railgun
X-Node
X-Backend-Server
X-Readtime
Accept-CH
Surrogate-Control
X-Akam-SW-Version
Request-Id
X-Response-Time
X-HW
Xkey
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Ruxit-JS-Agent
X-Application-Context
Content-Location
Accept-Ch-Lifetime
Rating
X-Country
X-Ua-Compatible
X-B3-TraceId
X-Cache-Lookup
X-Cloud-Trace-Context
X-Language
X-Url
X-Trace
Accept-CH-Lifetime
X-Ac
X-Content-Type
X-Template
Allow
X-PC
X-TtlSet
X-Vname
X-Varnish-TTL
X-Mod-Pagespeed
X-Clacks-Overhead
Edge-Control
Cache-Tag
X-FastCGI-Cache
X-Server-Name
Fastly-Restarts
X-ESI
Service-Worker-Allowed
X-Rack-Cache
X-VARITI-CCR
X-Element-Page-Cache
Verso
X-MS-InvokeApp
X-GitHub-Request-Id
X-Upstream
MS-Author-Via
X-Amz-Rid
Public-Key-Pins
X-Vcap-Request-Id
X-Buckets
X-Dw-Request-Base-Id
X-Cached
Accept-Ch
X-Client-IP
X-Abt-Application-Version
X-D2id
X-Aws-Lambda-Call-Status
X-Cache-TTL
X-Origin-Cache
X-Cnection
Arr-Disable-Session-Affinity
X-Px
X-Country-Code
X-Goog-Hash
RTSS
X-Powered-By-Plesk
Access-Control-Request-Method
X-Navigation-Version
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-NF-Request-ID
X-Instrumentation
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-Version
X-Powered-CMS
X-Exp-Id
X-Cdn-Fetch
X-Use-Magma
X-Kinja-Server
X-Kinja-Revision
X-Kinja-Build
X-Kinja
X-GoogleNews-Bot
X-Exp-Variant
X-Middleton-Display
X-Sol
Display
Pagespeed
X-Amz-Server-Side-Encryption
X-SRCache-Fetch-Status
X-SRCache-Store-Status
Response
X-Middleton-Response
X-MSEdge-Ref
AR-ATIME
AR-CACHE
AR-PoweredBy
AR-Request-ID
AR-SID
X-LLID
X-Edge-Location-Klb
X-Kinsta-Cache
X-Edge
Nginx-Cache
X-B3-TraceId-Primal
Mrf-Cache-Status
MRF-Tech
X-RateLimit-Remaining
X-TTL
X-Protected-By
X-HP-Webp
X-Jurisdiction
X-Shield-Request-Id
X-HP-Trace-Id
X-T
TCN
S
Content-MD5
X-Content-Security-Policy-Report-Only
X-Mg-S
X-Id
X-Forwarded-For
X-Aspnetmvc-Version
Realpath
X-CST
X-MCACHE
X-Mid
Fastcgi-Cache
Edge-Cache-Tag
SPIisLatency
SPRequestDuration
Front-End-Https
X-Recruiting
X-Request-Processing-Time
X-Request-Received
Filters
Server-Node
Pinterest-Generated-By
X-Ttl
Pinterest-Version
X-Pinterest-Rid
X-Parallel-Accel
X-Ab
X-Content
X-Ua-Browser
X-Correlation-Id
X-DynaTrace
Server-Name
Fusion-Template-Id
Fusion-Source
Fusion-Component-Id
X-SharePointHealthScore
Fusion-Deployment-Id
SPRequestGuid
Fusion-Content-Source
Fusion-Content-Id
X-NWS-LOG-UUID
X-Frontend
X-Ezoic-Cdn
X-HS-Cache-Config
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Combine-CSS
Alternate-Protocol
X-ECACHE
X-Yandex-Sdch-Disable
X-Hits
X-Content-Options
X-Cache-Key
X-Tt-Trace-Tag
X-Ser
X-Tt-Trace-Host
Cache-Tags
X-B3-Sampled
X-Git-Hash
MicrosoftSharePointTeamServices
Cleartype
X-Kong-Proxy-Latency
X-Page-Id
X-Kong-Upstream-Latency
X-Www-Served-By
Charset
Host
X-Accel-Expires
X-Ruxit-Js-Agent
X-Daa-Tunnel
X-Amz-Replication-Status
X-Geo-Country
X-Content-Digest
X-Amzn-Trace-Id
X-Fastly-Request-Id
X-DIS-Request-ID
Filterid
TP-Cache
TP-L2-Cache
X-Varnish-Age
X-VCache
X-Forwarded-Proto
X-Hostname
X-Debug-Info
X-Az
X-AppVersion
X-Activity-Id
X-Upgrade-Enabled
X-Rid
X-N
X-Origin-Server
X-FB-Debug
X-XRDS-LOCATION
Access-Control-Allow-Method
X-Grace
ServerID
Cross-Origin-Opener-Policy
X-LB-Cache
X-Nginx-Upstream-Cache-Status
X-F-Cache
X-Mobile-URL
X-Providence-Cookie
X-Is-Crawler
X-Aspnet-Duration-Ms
X-Flags
X-Route-Name
X-Request-Guid
X-Goog-Metageneration
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-GUploader-UploadID
X-Origin-Upstream-Status
X-Whom
X-TT
X-WebKit-CSP-Report-Only
X-Tb
X-App-Server
Viewport
X-Varnish-Grace
X-Distributor
X-App-Environment
X-FW-Dynamic
X-FW-Serve
X-FW-Hash
X-FW-Type
X-FW-Server
X-FW-Static
DC
Paypal-Debug-Id
X-Server-ID
Payment
X-Seen-By
Node
X-NGENIX-Cache
X-Type
Fastcgi-Useragent
X-Request-Handler-Origin-Region
X-Microsite
X-Cache-Control
X-Ratelimit-Limit
Country
X-User-Agent
Accept-Charset
X-Logged-In
X-Cache-Rule
X-Litespeed-Cache
X-Cache-Age
X-Wix-Request-Id
X-Fastcgi-Cache
X-DataDome
Version
X-Webkit-CSP
X-Fastly-Request-ID
X-Varnish-Backend
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Browser-Type
X-Node-Name
X-Drupal-Cache-Tags
Refresh
X-Via-JSL
X-Load-Cache
Referer-Policy
X-PressLabs-Stats
X-Cache-Action
X-Mobile
X-Signature
SD-X-WS
X-Original-Request-Id
Cache-Status
X-Response-Served-From
X-B-Cache
Amp-Access-Control-Allow-Source-Origin
Access-Control-Request-Headers
X-Cluster-Name
X-Vgn-Hpd-Reason
X-Rendered-As
X-Contextid
X-IPLB-Instance
X-Page-View
X-TEC-API-VERSION
X-Cacheable-TTL
X-Is-Bot
X-TEC-API-ORIGIN
X-Proxy-Cache-Status
X-TEC-API-ROOT
X-ProcessESI
VIX-Pulpo-Node
X-Real-IP
X-Oracle-Dms-Ecid
X-B
X-Debug
X-Oracle-Dms-Rid
X-UUID
VIX-Pulpo-Upstream-Status
NGB
X-RemovedCookies
X-Jobs
X-Yottaa-Optimizations
X-Cache-Expired-At
X-Revision
X-Yottaa-Metrics
X-Proxy
X-Instance
X-Drupal-Cache-Contexts
X-G
X-Rule
Akamai-GRN
X-Cache-Time
X-Framework
X-Device-Type
X-Debug-IsPreview
X-Debug-IsConnected
Surrogate-Key
CF-IPCountry
X-FW-Version
DynaTrace
X-Air-Source
SID
X-Air-Hostname
X-Air-Trace-Id
X-Tec-Api-Version
X-Tec-Api-Origin
Liferay-Portal
X-Tec-Api-Root
X-Azure-Ref
Healthy
X-Source
X-Ratelimit-Reset
X-XRDS-Location
X-Nginx-Cache
X-Ms-Request-Id
X-Ms-Version
Frame-Options
Count-Hit
X-RTag
Ms-Operation-Id
X-CDN-Forward
MS-CV
X-Oneagent-Js-Injection
X-Cache-Operation
X-APP-VERSION
GEO-INFO
X-Cache-Hit
X-Tumblr-Pixel-0
X-EdgeConnect-Cache-Status
X-L-Path
X-Tumblr-User
X-Tumblr-Pixel-1
X-Tumblr-Pixel
X-Environment-Context
Uber-Trace-Id
X-Varnish-Server
X-Accel-Buffering
Xserver
X-RateLimit-Limit
Countrycode
X-Region
X-Servername
X-Mode
X-Forwarded-Host
X-Presslabs-Stats
Section-Io-Cache
X-IPS-LoggedIn
Backend
X-Zen-Fury
Cross-Origin-Window-Policy
X-Content-Powered-By
Ec-Rule-Version
X-Backend-Name
X-Cache-NGX
X-UPSTREAM-Address
X-JoinUs
X-RN-RSRV
X-Detected-As
Meta-Geo
X-SaId
X-Varnish-Beresp-Grace
X-Hosted-By
X-Alternate-Cache-Key
X-Cache-Grace
Country-Code
X-Generation-Time
Protected
X-Debug-Cache
X-Cache-Type
X-Extlb
X-Zipkin-Id
Eomportal-Instance
X-Uri
X-Human
X-Sorting-Hat-ShopId
X-Sql-Count
X-Routing-Service
X-Redis-Cache
X-Tid
X-Sorting-Hat-PodId
X-Sql-Duration-Ms
X-Proxied
X-Shopify-Stage
X-ShardId
X-ShopId
X-Cache-Server
X-Adobe-Loc
X-Rewrite-Enabled
Decoy-Debug-Key
X-Via-Fastly
X-Microcachable
Apigw-Requestid
X-Cache-TTL-Remaining
X-Status
X-Adobe-Content
Decoy-Debug-Status
Decoy-Debug-TTL
X-NCache
X-Site-Version
Cache-Tv-Group
Cache-Name
X-SayCDN-TTL
X-Say-Cacheable
X-Say-TTL
X-Web-Node
Mn-Server-Ip
X-BYPASS-REASON
X-UA-Device-Type
X-PHP-Backend
X-Soup
X-PCL
X-Origin-Date
X-No-Session
X-OCL
X-Format
X-Storage
X-Cache-Host
Url
X-ProxyCache-Status
X-ProxyCache-Key
Fastly-SSL
Azure-InstanceId
Azure-RegionName
Azure-SiteName
X-Akamai-Edgescape
X-R9-Blue-Green-Version
X-Pubstack
X-Proxy-Build
X-Timing-Wait
X-Varnishpool
Selected-Fe
Azure-Version
X-Server-W
OT-Force-Account-Verify
Azure-SlotName
Property-Id
Webcakes-Region
X-Access
X-PERF
TWC-Device-Class
TWC-GeoIP-LatLong
TWC-GeoIP-Country
X-Section
TWC-Connection-Speed
X-ApacheServer
Webcakes-App-Version
X-Origin-Hint
Webcakes-App-Name
TWC-Locale-Group
TWC-Privacy
X-NYM-Debug-Backend
X-Content-Age
X-FB-TRIP-ID
X-ServerID
Content-Secure-Policy
DB-Nickname
X-Ua
X-Be
X-LSADC-Cache
X-Cluster-Node
X-NewRelic-App-Data
X-Hl-Ver
X-Azure-Ref-OriginShield
CDN-EdgeStorageId
SRV
CDN-RequestId
CDN-Uid
CDN-RequestCountryCode
CDN-PullZone
Source
CDN-CachedAt
CDN-Cache
X-Hyper-Cache
X-Generated-By
Content-Disposition
X-Webkit-Csp
X-Cached-By
X-Unique-Id
X-SRV
Cache
X-Nginx-Cache-Key
X-HTML-Minification-Powered-By
X-TT-LOGID
LB
X-LAGOON
X-TIME
Xet-Cookie
X-Dc
X-App-Version
X-Bc-Bl
X-TNCMS
X-Loop
X-Varnish-Hits
Retry-After
X-Origin-CC
X-Auto-Login
X-Trace-Id
X-Origin-TTL
WPO-Cache-Status
Onion-Location
X-Amz-Meta-S3cmd-Attrs
WPO-Cache-Message
X-GEO
X-S-Maxage
X-Cache-Var
Cache-Hits
X-Varnish-Hostname
X-Cache-Var-Map
X-Akamai-Transformed
X-Time
Mime-Version
Web-Mar-Node
X-Tumblr-Pixel-3
X-Tumblr-Pixel-2
X-Platform-Server
X-ECache
X-Ratelimit-Remaining
X-Cdn
HostName
X-CSRF-Token
X-Tenant
X-Xfnlog-Site
X-Time-Microsecs
X-Endurance-Cache-Level
X-M-Log
X-M-Reqid
X-Proto
X-Qnm-Cache
Webserver
X-Cache-Remote
X-Edge-Location
X-GG-Cache-Date
X-Cache-Tags
X-AWS-Id
CloudFront-Viewer-Country
ServedBy
X-VWS-Id
X-Varnish-Cache-Hits
N-Cache
X-LJ-Flow-ID
Upgrade-Insecure-Requests
X-Request-Time
X-B3-SpanId
X-Mg-Request-UUID
X-PHP-Host
X-AOL-HN
X-Amz-Apigw-Id
X-Labrador-Cache-Channel
X-Amzn-RequestId
X-Request-Host
X-CACHE-KEY
X-RCS-CacheZone
X-Via-NSCOPI
X-EC-Lua
X-ScT
X-S
X-External-Request-Id
X-Rojux
X-S-Cookie
X-Developer
X-D
X-SRCache-Key
X-Correlation-ID
X-Connection-Hash
X-SVT-ORM-RULES
Fastcgi-X-Cache-Version
X-Slack-Backend
X-Destination
X-Session-Fingerprint
X-Shop-Environment
X-SD-PageType
DSUID
X-ND-Cache
X-Ftr-Request-Id
X-Forwarded-Path
X-Orig-Expires
X-NAPM-TraceId
X-Gen-Mode
X-Ig-Push-State
X-Hnp-Log
BehaviorPad-Version
DCR-Decision-By
X-Origin-Response-Time
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Processor
X-Planisys-CDN-Cache
X-PBS-Appsvrname
DCR-Processing-Time-Ms
Nel
X-PAYTM-SRV-ID
Expiry
X-SVT-ORM-VERSION
X-Block-Status
X-B-Cookie
X-ARC
X-Application
Rendered-Blocks
X-Conf
X-Cache-NE
Pramga
Redirect-Candidate
X-Aed
Surrogated-Key
X-A
X-Handled-By
User-Cache-Control
X-Locale
X-A-Ccd
X-A-Dam
X-A-Wwc
X-A-Dgt
X-A-Dcw
Xc-Version
X-Cache-Date
X-CF-Lambda-Version
X-Vdms-Path
X-Vdms-Version
Odigeo-Trace-Id
X-TIM-N
Mobile-Detection-Method
X-Cluster
A
Meta-Geo-Continent
X-VG-WebCache
X-CF-Lambda-Fn
X-Vtex-Processado-Em
Origin
X-Vtex-Remote-Cache
X-Storefront-Renderer-Rendered
From-Origin
X-FireWall-Port
X-Cache-Info
X-Fastly-Cache
Traceparent
Fastcgi-Cache-TTL
X-Geo-Header
X-Epic-Correlation-Id
X-Core-Mission
AKAMAI
Arc-Country
Vix-Hermes-Req-Id
Cmstype
State
Origin-EX
Host-ID
X-Aicache-OS
Origin-CC
X-Forwarded-Site
X-Accel-Expires-Debug
Cmsid
X-Cache-Bucket
X-Date
X-Ckpd-Fst-Backend
X-Gdpr
X-Origin-Time
X-Varnish-Beresp-Status
X-V-Cache
X-Rocket-Nginx-Serving-Static
L
X-Proxy-Upstream
CDCHOST
X-Zone
V-Age
X-Scheme
X-Sucuri-ID
Sslversion
X-Sucuri-Cache
X-Skip-Cache
X-Served-From
X-Server-IP
X-Origin-Expires
X-Owner
X-Webstats-RespID
X-LI-UUID
X-Li-Pop
X-Li-Fabric
WP-Super-Cache
X-Men
X-Location
X-Old-Content-Length
X-VC-Cache
X-Nyt-Route
X-VServer
AMP-Access-Control-Allow-Source-Origin
X-Adobe-Source
Environment
X-MP-GENERATED-AT
X-ATG-Version
Apple-News-Services-Parsed-Url
X-Bip
Locid
Apple-News-Services-Request-Url
PFcat
Wxu-Next-Hostname
X-Developers
X-Cdn-Srv
X-HN
X-NodeID
X-VarnishDD-TTL
X-Cache-Debug
Wxu-Next-Region
Svr
True-Client-Country-4JS
Wxu-Next-Commit
X-Cache-Id
X-BBC-Edge-Cache-Status
X-Thanos
X-Fetched-On
Web-Mar-Region
X-Policy
X-Region-Sid
X-Fastly-Backend
X-Node-Id
X-Mvc-Supplant-Cachable
X-Level-Front-Cache
X-Hash
X-Generated-On
X-Gamma-Serve
X-Req
X-Esi-Check
X-VG-TLSProxy
X-TrackingId
X-Cdn-Origin
X-Viewer-Country
Apple-News-Services-Handled
X-Thinkindot-L3
X-HS-Content-Campaign-Id
X-Device-Os
X-Sn-Servicetimems
X-Core-Value
X-TH-Server
Apple-News-Services-Host
X-Gzip
Thinkindot-CacheControl
Req-Svc-Chain
TDXMobile
Gh-Request-Id
Release
Server-Host
Thinkindot-Control
Thinkindot-CacheControl-Type
Fastly-GeoIP-CountryCode
Machine
CacheControlHeader
Fastly-Drupal-Html
Server-Info
X-Reqid
X-Is-Gdpr
X-Irp-Debug
Adler-Geo
X-Worker
X-NU-AKA-ACS-Version
X-Origin
X-Has-Esi
X-Loc
NGX
X-JWT-State
X-Datadog-Sampling-Priority
X-GeoIP
X-GeoIP-City
X-DPWN-IS-SECURE
Fastly-SWR
Fastly-SIE
X-DefHash
X-DefElseHash
X-Datadog-Parent-Id
X-Request-URI
X-Datadog-Trace-Id
Is-Eu
Mail-Subject
Platform
X-Amzn-Remapped-Content-Length
X-Pod-Name
X-Sigma-Backend
X-Sigma
X-UnsetCookies
X-Variation
X-Varnish-CookieHashed-On
We-Hiring
Ssr
X-Varnish-Remaining-TTL
X-Varnish-CookieINHashed-On
X-Rocket-Build-Number
X-Backend-State
X-Envoy-Decorator-Operation
X-Cache-Config
Cf-Device-Type
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Request-Start
X-Branch-Name
X-Rebelmouse-Surrogate-Control
X-Qloud-Router
X-Rebelmouse-Cache-Control
X-Platform
X-Xrds-Location
X-CS
X-NWS-UUID-VERIFY
X-Magnolia-Registration
X-Csrf-Jwt
X-Eu-Site
NM-Fastcgi-Cache
X-Cache-Enabled
X-CGP
X-Response-By
Ha-Gx-Prefs
HA-Ipaddr
L5d-Success-Class
Memcached
X-Tx-Id
X-FC-Vary-Parameters
Datacenter
X-Varnish-Beresp-Ttl
X-Ua-Device
X-Up
X-Backend-TTL
X-Mvc-Supplant-OutputCached
X-NC
X-CLOUD-TRACE-CONTEXT
X-Trace-ID
X-API-Version
Candidate-Md5Url
CDN
X-GeoIP-Region-Code
X-GeoIP-Country-Code
Pics-Label
X-LB-ID
X-Esi
Ms-Author-Via
X-Tb-Optimization-Total-Bytes-Saved
On-Server
X-Vc
WWW-Authenticate
X-Datadome
Esi-Enabled
X-Via-Popn
X-Via-Popv
X-LB-NoCache
Memory
Time
Magicmarker
X-Generated-In
X-Via-Poph
X-TraceId
S-Rt
X-DynaTrace-JS-Agent
Env
WebServer
X-TA-CDN-Provider
X-DC
X-Refresh
NtCoent-Length
X-Edge-Pop
X-Restarts
X-Optimistic-Header
X-Varnish-Ttl
X-Tt-Logid
X-Dynatrace
C-Via
GeoIp-Country-Code
X-Parent-Response-Time
X-Service
Kp-EeAlive
X-RSL
X-Cache-Backend
X-Action
X-Wix-Viewer-Type
X-RPS
X-DW
X-DSS
X-CacheTTL
X-DI
X-DB
X-Cache-PHP
X-RPM
X-Varnish-Beresp-TTL
X-Http-Reason
Edge-Cache
X-Akamai-Request-ID2
X-Servedbyhost
X-Srv
X-Unique-ID
X-Minions-Version
X-MSEdge-Flight
X-TX-ID
X-MSEdge-Features
Server-ID
X-Render-Time
X-Cache-Status-Check
X-Cs
X-Newrelic-Synthetics
X-HA-Backend
Accept-Language
X-ZONE
X-Webkit-Csp-Report-Only
X-VCL-Version
X-Info
X-App
X-Li-Proto
X-LI-Proto
X-AIR-PT
X-Traceid
X-Fpc
X-Cache-Ttl
X-URL
X-Urbn-Site-Id
X-Urbn-Context-Path
Proxy-Connection
Locale
X-Ec-GeoHdr
Test
X-FPC
X-Clientip
X-User
X-Ec-Fail
X-LiteSpeed-Cache-Control
X-Oss-Storage-Class
HIT
X-Oss-Request-Id
Cache-Host
X-Oss-Server-Time
Server-Id
X-B3-Spanid
X-Oss-Object-Type
UCS
X-Oss-Hash-Crc64ecma
X-Vcl-Version
X-NODE
X-Webkit-CSP-Report-Only
Tcn
S-Cnection
Geo-Info
X-AK-Request-ID
M-TraceId
Cdncip
X-Pass-Why
Cdnsip
X-WADP-Cache
X-Fmm-Version
X-HostName
X-Clara-WADP
X-LiteSpeed-Tag
Cf-Int-Pingora-Origin-Digest
Fastly-Backend-Name
Resin-Trace
User-Agent
X-Micro-Cache
Cluster
Fastly-Drupal-HTML
My-App
X-CSRF-TOKEN
Section-Io-Origin-Status
Section-Origin-Responded
Lb
Section-Io-Origin-Time-Seconds
Section-Io-Id
X-Pad
X-Ha-Backend
X-CUA
Geoip-Latitude
X-ServedByHost
Tracecode
X-ID
X-Backend-Host
X-Var-Ttl
X-Dynatrace-Js-Agent
Hostname
Hit
X-From
X-APP
Ohc-File-Size
GeoIP-Country-Code
X-BBC-Origin-Response-Status
X-BCube-Filmed-By
T-Server
X-Release
X-Geo
X-Fragments
X-Via-PopV
Lfy
X-Edge-POP
Lang
X-Cdn-Forward
X-Via-PopN
X-Via-PopH
MIME-Version
ENV
X-ElasticPress-Query
X-Check-Cacheable
X-RAMCache
EpKe-Alive
X-WP-CF-Super-Cache
X-Edge-Cache
Path
X-HS-Status
X-ES-SERVER
X-WA-Info
Load-Balancing
X-WA
VNS-Age
CPC-Cache
X-NGINX-Cache
X-Amz-Meta-Cb-Modifiedtime
X-Api-Version
VNS-Cache
CPC-Age
Target-Params
Cache-Key
X-WP-CF-Super-Cache-Cache-Control
X-Ucs
Servername
X-Fastly-Backend-Reqs
URI
X-ServerName
DataCenter
Uri
X-Mcache
X-UP
X-PJAX-URL
X-Fastly-Cache-Hits
X-Wikidot-Static-Cache
Shield-Pop
Cteonnt-Length
X-GoCache-CacheStatus
X-Cms-Context
X-VC
Pagetype
X-Wikidot-Backend
Srv
X-TRACE-ID
X-Dw-Trace-Id
X-Lb-Id
X-Swift-Error
X-Cdn-Request-ID
Permissions-Policy
Ohc-Cache-HIT
PICS-Label
X-Akamai-Pragma-Client-IP
X-Hcs-Proxy-Type
X-Lb-Nocache
X-B3-ParentSpanId
X-Via-Ucdn
X-FORWARDED-FOR
Cdn
X-RateLimit-Reset
WZWS-RAY
FSS-Cache
X-CCDN-CacheTTL
X-Httpd
X-Proxy-Cache-Info
X-Nc
X-CCDN-Origin-Time
MD5-Digest
Cneonction
X-Akamai-ERPolicy
Producers
Server-Ttl
X-Udemy-Cache-App-Namespace
ServerName
X-Acquia-Site
X-Acquia-Application-UUID
X-Acquia-Application-Trace
X-Acquia-Purge-Tags
X-Akamai-ERRuleID
X-VG-WebServer
X-Apw-Hits
X-Cache-ASPX
Cf-Ipcountry
X-Snapshot-Date
X-Apw-Access-Token
X-Apw-Access-Object
X-Newrelic-App-Data
X-SIPLIST1
X-Apw-Access-Action
IsBot
X-Contensis-Viewer-Groups
Vha6-Origin
X-Yottaa-OS
CF-Cached-On
Sever-Int
Server-Hostname
Server-Ext
X-Cache-Ngx
X-Air-Pt
Sid
X-Provided-By
X-SB
GeoIP-Latitude
X-Cache-Expires
X-Last-Modified
X-Http-Duration-Ms
X-CacheKey
X-Logging-Id
X-UA
Req-ID
CountryCode
Ngx
X-Varnish-Authentication
X-Http-Count
X-Miniprofiler-Ids
X-B3-Parentspanid
X-Te-Duration-Ms
X-Te-Count
X-Sentry-ID
W