Threat Level: green Handler on Duty: Guy Bruneau

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Link
Cf-Request-Id
CF-Cache-Status
Accept-Ranges
CF-RAY
ETag
X-XSS-Protection
Expect-CT
Pragma
X-Powered-By
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-UA-Compatible
X-Cache-Hits
Alt-Svc
P3P
X-Served-By
X-Xss-Protection
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Varnish
X-Request-Id
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Cache-Status
X-Generator
X-Cacheable
Timing-Allow-Origin
X-Request-ID
P3p
X-Content-Security-Policy
X-Iinfo
Status
Feature-Policy
X-Envoy-Upstream-Service-Time
Content-Encoding
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
X-CDN
X-AspNetMvc-Version
Upgrade
X-Via
CF-Ray
Access-Control-Max-Age
X-Ws-Request-Id
Server-Timing
EagleId
Keep-Alive
X-Cache-Group
X-Turbo-Charged-By
Request-Context
X-Age
X-Server-Powered-By
X-Proxy-Cache
X-UA-Device
X-AH-Environment
X-Backend
X-Hacker
X-Robots-Tag
Report-To
X-Amz-Request-Id
Host-Header
X-Server
X-LiteSpeed-Cache
X-Amz-Id-2
Grace
X-Rq
X-Nginx-Cache-Status
X-Varnish-Cache
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-Dns-Prefetch-Control
X-WebKit-CSP
X-Page-Speed
X-Vhost
EagleEye-TraceId
X-Amz-Version-Id
X-OneAgent-JS-Injection
X-Pingback
X-Dispatcher
X-Device
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Cache-Spec
NEL
X-Server-Id
X-Host
X-Backend-Server
X-Node
Cf-Railgun
X-Readtime
Accept-CH
X-Akam-SW-Version
Surrogate-Control
Request-Id
X-Response-Time
X-HW
X-Language
Xkey
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Template
X-Application-Context
Content-Location
Rating
X-Ruxit-JS-Agent
X-Ua-Compatible
Accept-Ch-Lifetime
X-Country
X-B3-TraceId
X-Cloud-Trace-Context
X-Cache-Lookup
Accept-CH-Lifetime
X-Buckets
X-Ac
X-Url
X-Content-Type
Allow
X-Trace
X-Vname
X-TtlSet
X-PC
X-Mod-Pagespeed
X-Clacks-Overhead
Edge-Control
X-Varnish-TTL
X-ESI
Cache-Tag
X-FastCGI-Cache
Fastly-Restarts
X-Server-Name
X-Rack-Cache
Service-Worker-Allowed
X-VARITI-CCR
X-Element-Page-Cache
Verso
X-MS-InvokeApp
X-GitHub-Request-Id
X-Upstream
X-Amz-Rid
X-Vcap-Request-Id
Public-Key-Pins
MS-Author-Via
X-Dw-Request-Base-Id
X-Cached
X-Client-IP
X-D2id
X-Abt-Application-Version
X-Origin-Cache
Arr-Disable-Session-Affinity
X-Country-Code
X-ORACLE-DMS-ECID
X-Cnection
Accept-Ch
X-ORACLE-DMS-RID
X-Powered-By-Plesk
X-Px
X-Aws-Lambda-Call-Status
X-Goog-Hash
Access-Control-Request-Method
X-NF-Request-ID
X-Navigation-Version
X-Cache-TTL
X-Version
X-Instrumentation
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
RTSS
X-Amz-Server-Side-Encryption
X-Powered-CMS
X-Sol
X-Middleton-Display
Display
Pagespeed
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Middleton-Response
Response
X-Use-Magma
X-Kinja-Revision
X-Kinja-Server
X-Cdn-Fetch
X-Exp-Id
X-GoogleNews-Bot
X-Kinja
X-Kinja-Build
X-Exp-Variant
X-MSEdge-Ref
X-LLID
X-Edge
X-Kinsta-Cache
X-Edge-Location-Klb
X-TTL
Nginx-Cache
AR-ATIME
AR-PoweredBy
AR-CACHE
AR-Request-ID
AR-SID
X-B3-TraceId-Primal
Mrf-Cache-Status
MRF-Tech
X-Shield-Request-Id
S
Content-MD5
X-Jurisdiction
X-CST
X-HP-Trace-Id
X-T
X-HP-Webp
X-RateLimit-Remaining
X-Protected-By
X-Forwarded-For
TCN
X-Content-Security-Policy-Report-Only
X-Aspnetmvc-Version
X-Id
X-Mg-S
Fastcgi-Cache
X-Mid
X-MCACHE
Realpath
Edge-Cache-Tag
SPIisLatency
SPRequestDuration
Front-End-Https
X-Parallel-Accel
X-Recruiting
X-Request-Received
X-Request-Processing-Time
Filters
Pinterest-Generated-By
Fusion-Deployment-Id
Fusion-Source
Fusion-Template-Id
Server-Node
Fusion-Content-Id
Fusion-Content-Source
X-Pinterest-Rid
Fusion-Component-Id
Pinterest-Version
X-DynaTrace
X-Ab
X-Content
X-Ua-Browser
X-SharePointHealthScore
SPRequestGuid
X-Ruxit-Js-Agent
X-Ezoic-Cdn
X-Correlation-Id
X-Ttl
Server-Name
X-ECACHE
Alternate-Protocol
X-NWS-LOG-UUID
X-HS-Content-Id
X-Frontend
X-HS-Cache-Config
X-HS-Hub-Id
X-HS-Combine-CSS
X-Accel-Expires
X-Hits
X-Yandex-Sdch-Disable
X-Content-Options
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Cache-Key
Cache-Tags
MicrosoftSharePointTeamServices
X-Page-Id
Host
X-Git-Hash
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
Charset
Cleartype
X-Www-Served-By
X-B3-Sampled
X-Ser
X-Geo-Country
X-Content-Digest
X-Amz-Replication-Status
TP-L2-Cache
TP-Cache
X-Forwarded-Proto
Filterid
X-Amzn-Trace-Id
X-Varnish-Age
X-XRDS-LOCATION
X-Daa-Tunnel
X-Hostname
X-AppVersion
X-VCache
X-Activity-Id
X-Az
X-DIS-Request-ID
X-Debug-Info
X-Rid
X-Fastly-Request-Id
X-Upgrade-Enabled
X-Origin-Server
Access-Control-Allow-Method
X-Grace
X-Origin-Upstream-Status
X-Microsite
X-N
X-Request-Handler-Origin-Region
X-FB-Debug
X-LB-Cache
X-Nginx-Upstream-Cache-Status
ServerID
X-Mobile-URL
X-WebKit-CSP-Report-Only
X-Server-ID
X-Request-Guid
X-Is-Crawler
X-Aspnet-Duration-Ms
X-F-Cache
X-Whom
X-Providence-Cookie
X-Flags
X-TT
X-Route-Name
X-Goog-Storage-Class
X-Goog-Generation
Cross-Origin-Opener-Policy
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-GUploader-UploadID
X-NGENIX-Cache
X-Goog-Stored-Content-Length
X-App-Environment
X-App-Server
X-Varnish-Grace
X-Tb
X-Distributor
Payment
Viewport
X-FW-Static
X-FW-Hash
X-FW-Serve
X-FW-Server
X-FW-Dynamic
X-FW-Type
Paypal-Debug-Id
Node
DC
X-PressLabs-Stats
X-Cache-Control
X-Oneagent-Js-Injection
X-Logged-In
X-Seen-By
X-Type
Fastcgi-Useragent
X-User-Agent
X-Cache-Age
Accept-Charset
X-Fastcgi-Cache
Country
X-Webkit-CSP
X-Fastly-Request-ID
X-Cache-Rule
X-Varnish-Backend
X-Erf-Bev-Bev-Is-Generated
X-Wix-Request-Id
Version
X-Load-Cache
X-Browser-Type
X-Erf-Bev-Bev
X-Node-Name
X-Cache-Action
X-IPLB-Instance
Refresh
X-Via-JSL
Referer-Policy
X-Original-Request-Id
Access-Control-Request-Headers
SD-X-WS
X-Drupal-Cache-Tags
Cache-Status
X-Response-Served-From
X-Vgn-Hpd-Reason
X-Is-Bot
X-Cacheable-TTL
X-Rendered-As
X-UUID
X-Jobs
X-Real-IP
X-Proxy-Cache-Status
X-DataDome
NGB
X-Tec-Api-Version
X-Signature
VIX-Pulpo-Upstream-Status
X-B-Cache
X-Debug
X-ProcessESI
X-RemovedCookies
X-Revision
X-Page-View
X-Tec-Api-Root
X-Cache-Expired-At
X-Cluster-Name
X-Contextid
X-B
VIX-Pulpo-Node
X-Ratelimit-Limit
X-Tec-Api-Origin
X-Drupal-Cache-Contexts
X-Mobile
X-Proxy
X-Rule
X-Yottaa-Optimizations
X-Yottaa-Metrics
DynaTrace
Liferay-Portal
X-Device-Type
X-Debug-IsPreview
X-Debug-IsConnected
X-Cache-Time
Surrogate-Key
Akamai-GRN
X-Framework
X-G
X-TEC-API-VERSION
X-TEC-API-ROOT
X-Instance
X-TEC-API-ORIGIN
X-FW-Version
Amp-Access-Control-Allow-Source-Origin
Healthy
X-Azure-Ref
SID
X-Air-Hostname
X-Air-Trace-Id
X-Air-Source
X-Source
X-Oracle-Dms-Ecid
X-Oracle-Dms-Rid
CF-IPCountry
X-Ms-Version
X-Ms-Request-Id
Frame-Options
Ms-Operation-Id
X-Cache-Hit
X-RTag
X-Nginx-Cache
MS-CV
X-CDN-Forward
Section-Io-Cache
X-Tumblr-User
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Environment-Context
X-Tumblr-Pixel-1
X-L-Path
Countrycode
Xserver
X-XRDS-Location
X-Varnish-Server
Count-Hit
X-RateLimit-Limit
X-Cache-Operation
X-Region
X-APP-VERSION
X-EdgeConnect-Cache-Status
Uber-Trace-Id
X-Servername
X-Content-Powered-By
X-Forwarded-Host
X-Backend-Name
X-Litespeed-Cache
X-Mode
X-Accel-Buffering
X-IPS-LoggedIn
Cross-Origin-Window-Policy
GEO-INFO
Backend
X-Adobe-Loc
X-Adobe-Content
Ec-Rule-Version
X-UPSTREAM-Address
X-SaId
X-ShardId
X-JoinUs
Meta-Geo
X-Detected-As
X-Zen-Fury
X-Ratelimit-Reset
X-RN-RSRV
X-Alternate-Cache-Key
X-ShopId
X-Sorting-Hat-PodId
X-Shopify-Stage
X-Sorting-Hat-ShopId
X-Human
Country-Code
Eomportal-Instance
X-Microcachable
X-Redis-Cache
X-Varnish-Beresp-Grace
X-Debug-Cache
X-Uri
X-Cache-Server
X-Cache-TTL-Remaining
X-Cache-Grace
X-Generation-Time
X-Cache-Type
X-ServerID
Mn-Server-Ip
X-Origin-Date
X-Tid
X-Hosted-By
X-UA-Device-Type
Url
Decoy-Debug-TTL
Cache-Tv-Group
Cache-Name
Apigw-Requestid
X-No-Session
Decoy-Debug-Key
X-Sql-Count
X-FB-TRIP-ID
Decoy-Debug-Status
X-Via-Fastly
X-Sql-Duration-Ms
X-ProxyCache-Key
X-Cache-Host
X-BYPASS-REASON
X-PHP-Backend
X-NCache
X-Site-Version
X-Status
X-Storage
X-ProxyCache-Status
X-OCL
X-SayCDN-TTL
DB-Nickname
X-Web-Node
X-R9-Blue-Green-Version
X-Format
X-Say-Cacheable
X-Say-TTL
Property-Id
TWC-Privacy
TWC-Locale-Group
X-Origin-Hint
X-Proxy-Build
Webcakes-Region
X-Akamai-Edgescape
TWC-GeoIP-LatLong
TWC-GeoIP-Country
X-Timing-Wait
Protected
Selected-Fe
X-PCL
TWC-Device-Class
TWC-Connection-Speed
Webcakes-App-Version
Webcakes-App-Name
X-Time
X-Hl-Ver
X-Azure-Ref-OriginShield
X-Extlb
X-ApacheServer
OT-Force-Account-Verify
X-Cache-NGX
X-Access
X-NYM-Debug-Backend
X-PERF
X-Server-W
X-Varnishpool
X-Rewrite-Enabled
X-Section
X-Routing-Service
X-Proxied
X-Pubstack
Fastly-SSL
X-Zipkin-Id
Azure-InstanceId
Azure-SiteName
Azure-RegionName
Azure-Version
Azure-SlotName
X-Soup
Source
Content-Secure-Policy
X-Be
X-LSADC-Cache
X-Cluster-Node
X-App-Version
X-Ua
X-Webkit-Csp
X-NewRelic-App-Data
X-HTML-Minification-Powered-By
X-Content-Age
CDN-PullZone
Content-Disposition
CDN-EdgeStorageId
CDN-Cache
CDN-CachedAt
CDN-RequestCountryCode
CDN-Uid
CDN-RequestId
X-Cached-By
X-Cache-Var-Map
X-Cache-Var
X-TT-LOGID
X-Amz-Meta-S3cmd-Attrs
X-Dc
X-SRV
X-Generated-By
X-LAGOON
SRV
Cache
X-Bc-Bl
X-Varnish-Hostname
X-Varnish-Hits
Webserver
X-Hyper-Cache
X-Unique-Id
X-S-Maxage
X-Presslabs-Stats
Onion-Location
X-Auto-Login
X-TNCMS
X-Nginx-Cache-Key
X-Loop
Retry-After
X-Origin-TTL
X-Tumblr-Pixel-2
X-Trace-Id
X-Tumblr-Pixel-3
X-Origin-CC
Cache-Hits
Web-Mar-Node
Xet-Cookie
X-Cdn
LB
X-M-Log
X-Tenant
X-Qnm-Cache
X-Time-Microsecs
X-Proto
X-M-Reqid
X-Akamai-Transformed
X-GEO
X-Endurance-Cache-Level
X-CSRF-Token
X-Edge-Location
X-Platform-Server
X-CACHE-KEY
X-AWS-Id
X-GG-Cache-Date
HostName
X-VWS-Id
X-LJ-Flow-ID
CloudFront-Viewer-Country
X-B3-SpanId
Mime-Version
X-Mg-Request-UUID
X-ECache
AMP-Access-Control-Allow-Source-Origin
X-Xfnlog-Site
X-Amzn-RequestId
N-Cache
X-PHP-Host
X-Amz-Apigw-Id
X-Labrador-Cache-Channel
X-Cache-Tags
WPO-Cache-Status
X-Cache-Remote
Upgrade-Insecure-Requests
WPO-Cache-Message
X-Storefront-Renderer-Rendered
X-RCS-CacheZone
X-Varnish-Cache-Hits
X-Correlation-ID
X-Locale
Nel
X-Origin-Response-Time
X-Request-Time
ServedBy
X-Handled-By
X-Adobe-Source
X-AOL-HN
BehaviorPad-Version
X-Fastly-Cache
Mobile-Detection-Method
X-Ig-Push-State
DCR-Decision-By
DCR-Processing-Time-Ms
Meta-Geo-Continent
X-Conf
X-Cluster
X-Planisys-CDN-Cache
X-PBS-Appsvrname
X-Ckpd-Fst-Backend
X-PAYTM-SRV-ID
X-External-Request-Id
X-Connection-Hash
X-CF-Lambda-Version
X-Via-NSCOPI
X-Forwarded-Path
Fastcgi-X-Cache-Version
X-Orig-Expires
X-Cache-NE
X-Cache-Date
Expiry
X-ND-Cache
X-Gen-Mode
X-D
X-Hnp-Log
X-Developer
X-CF-Lambda-Fn
X-Ftr-Request-Id
DSUID
A
X-Destination
X-NAPM-TraceId
Pramga
X-Shop-Environment
X-Aed
X-A-Wwc
X-A-Dgt
X-Planisys-CDN-Rules
X-Vtex-Processado-Em
X-S-Cookie
X-ScT
Rendered-Blocks
X-Session-Fingerprint
X-Slack-Backend
X-A-Dcw
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
Surrogated-Key
X-A
State
X-A-Ccd
X-V-Cache
X-TIM-N
X-A-Dam
X-SRCache-Key
X-Vtex-Remote-Cache
X-SD-PageType
X-VG-WebCache
Origin
X-B-Cookie
X-ARC
Xc-Version
X-Processor
Odigeo-Trace-Id
X-Planisys-CDN-TTL
User-Cache-Control
X-Block-Status
X-VC-Cache
X-Application
X-Request-Host
X-S
X-Rojux
X-Vdms-Path
Redirect-Candidate
X-Vdms-Version
X-Reqid
X-ATG-Version
Environment
X-MP-GENERATED-AT
X-TIME
Server-Info
X-Device-Os
Vix-Hermes-Req-Id
Wxu-Next-Commit
Wxu-Next-Hostname
X-Date
Cmstype
Traceparent
Wxu-Next-Region
Cmsid
V-Age
Host-ID
X-Cache-Debug
X-Cache-Info
X-BBC-Edge-Cache-Status
Origin-EX
X-Cache-Bucket
Origin-CC
X-Epic-Correlation-Id
Release
X-Core-Mission
X-Core-Value
Gh-Request-Id
X-Accel-Expires-Debug
L
Req-Svc-Chain
Fastcgi-Cache-TTL
X-Owner
CDCHOST
X-Origin-Time
X-VG-TLSProxy
X-Policy
X-Old-Content-Length
X-Nyt-Route
X-Location
X-Men
X-Mvc-Supplant-Cachable
X-Varnish-Ttl
X-Proxy-Upstream
X-Skip-Cache
X-TH-Server
X-Varnish-Beresp-Status
X-Server-IP
X-Served-From
X-Ratelimit-Remaining
X-Rocket-Nginx-Serving-Static
X-Scheme
X-Hash
X-Origin-Expires
X-Geo-Header
X-Gdpr
CacheControlHeader
AKAMAI
Arc-Country
X-Fetched-On
X-Forwarded-Site
From-Origin
X-VServer
X-Sigma-Backend
X-Sigma
X-Developers
X-Rocket-Build-Number
X-Fastly-Backend
X-Aicache-OS
X-Viewer-Country
Web-Mar-Region
X-Esi-Check
We-Hiring
X-VarnishDD-TTL
X-Webstats-RespID
X-TrackingId
X-Thinkindot-L3
X-Sn-Servicetimems
X-Request-Start
X-Sucuri-Cache
X-Sucuri-ID
X-Thanos
X-Envoy-Decorator-Operation
X-Region-Sid
X-GeoIP-City
X-Gzip
X-Cdn-Origin
X-Datadog-Parent-Id
X-NodeID
X-LI-UUID
X-Li-Pop
X-HS-Content-Campaign-Id
X-Irp-Debug
X-Level-Front-Cache
X-Li-Fabric
X-Cache-Id
X-Datadog-Sampling-Priority
X-Gamma-Serve
X-Bip
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-HN
X-Platform
X-Branch-Name
X-GeoIP
X-Cache-Config
X-Generated-On
X-Datadog-Trace-Id
X-Req
Mail-Subject
Server-Host
Apple-News-Services-Host
Fastly-GeoIP-CountryCode
X-Magnolia-Registration
NGX
Locid
X-EC-Lua
PFcat
Datacenter
Machine
Candidate-Md5Url
Svr
Fastly-SWR
Apple-News-Services-Parsed-Url
True-Client-Country-4JS
Apple-News-Services-Handled
TDXMobile
Apple-News-Services-Request-Url
Thinkindot-Control
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
Fastly-SIE
X-FireWall-Port
X-Xrds-Location
X-CS
X-Eu-Site
X-DefElseHash
Ha-Gx-Prefs
HA-Ipaddr
X-Csrf-Jwt
X-DefHash
X-DPWN-IS-SECURE
Cf-Device-Type
X-Variation
X-Zone
X-Origin
Sslversion
X-Pod-Name
X-Qloud-Router
X-Request-URI
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-NU-AKA-ACS-Version
X-Loc
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
X-Has-Esi
X-Is-Gdpr
X-UnsetCookies
X-JWT-State
Adler-Geo
X-FC-Vary-Parameters
X-Node-Id
L5d-Success-Class
Memcached
Platform
X-Backend-State
Is-Eu
X-Worker
NM-Fastcgi-Cache
X-Cdn-Srv
X-Amzn-Remapped-Content-Length
X-CGP
Fastly-Drupal-Html
X-Varnish-Beresp-Ttl
Ssr
WWW-Authenticate
On-Server
X-Datadome
X-Up
X-CLOUD-TRACE-CONTEXT
X-Mvc-Supplant-OutputCached
X-Response-By
X-Tx-Id
X-LB-ID
Esi-Enabled
X-API-Version
Pics-Label
WP-Super-Cache
CDN
X-Trace-ID
X-Vc
Ms-Author-Via
X-NC
X-Generated-In
X-Backend-TTL
NtCoent-Length
Time
Memory
X-Service
X-LB-NoCache
C-Via
X-Cache-Enabled
X-Refresh
X-DynaTrace-JS-Agent
X-TA-CDN-Provider
X-GeoIP-Country-Code
X-GeoIP-Region-Code
X-Cache-PHP
X-Via-Poph
X-Via-Popv
X-Edge-Pop
X-Via-Popn
X-Dynatrace
X-NWS-UUID-VERIFY
X-Cache-Ttl
X-Tb-Optimization-Total-Bytes-Saved
Magicmarker
X-Tt-Logid
X-TraceId
Env
X-DC
X-Optimistic-Header
GeoIp-Country-Code
X-Cache-Status-Check
X-Render-Time
X-Parent-Response-Time
X-CacheTTL
X-Restarts
X-Srv
Kp-EeAlive
X-Servedbyhost
X-Esi
X-Info
X-TX-ID
Server-ID
X-ZONE
S-Rt
X-Varnish-Beresp-TTL
X-Unique-ID
X-DB
X-DW
X-Action
X-RPM
X-DSS
X-Wix-Viewer-Type
X-RPS
X-RSL
X-MSEdge-Flight
Edge-Cache
X-Cache-Backend
X-AIR-PT
X-MSEdge-Features
X-DI
WebServer
Proxy-Connection
X-Cs
X-Clientip
X-HA-Backend
UCS
X-Traceid
X-Minions-Version
X-Oss-Storage-Class
Cache-Host
X-Newrelic-Synthetics
X-Fpc
X-App
X-Oss-Hash-Crc64ecma
HIT
X-Oss-Server-Time
X-Oss-Request-Id
X-Oss-Object-Type
X-VCL-Version
Geo-Info
X-URL
X-Webkit-Csp-Report-Only
X-Li-Proto
S-Cnection
Test
X-LI-Proto
Section-Origin-Responded
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
X-Akamai-Request-ID2
X-Http-Reason
Section-Io-Id
X-Vcl-Version
X-FPC
Lb
X-Webkit-CSP-Report-Only
X-NODE
X-LiteSpeed-Cache-Control
Server-Id
X-Micro-Cache
Fastly-Backend-Name
Accept-Language
User-Agent
Tcn
X-B3-Spanid
X-Pad
X-Ec-GeoHdr
X-Backend-Host
X-Pass-Why
X-Ec-Fail
X-User
X-BCube-Filmed-By
X-Urbn-Site-Id
X-HostName
Cf-Int-Pingora-Origin-Digest
Resin-Trace
X-Check-Cacheable
Fastly-Drupal-HTML
X-Release
X-APP
X-Urbn-Context-Path
X-LiteSpeed-Tag
Locale
X-CSRF-TOKEN
X-ES-SERVER
X-Geo
X-ID
X-BBC-Origin-Response-Status
Hostname
MIME-Version
X-WADP-Cache
GeoIP-Country-Code
X-AK-Request-ID
Cdncip
X-Ha-Backend
ENV
Cdnsip
M-TraceId
X-Clara-WADP
Hit
X-Fmm-Version
X-Amz-Meta-Cb-Modifiedtime
X-ServedByHost
CPC-Cache
EpKe-Alive
Path
VNS-Age
CPC-Age
Cache-Key
Srv
X-WA-Info
X-WA
Ohc-File-Size
VNS-Cache
X-Dynatrace-Js-Agent
X-Via-PopV
X-ElasticPress-Query
X-Cdn-Forward
Cluster
My-App
X-Via-PopH
X-Via-PopN
X-Edge-POP
Geoip-Latitude
X-Api-Version
Lfy
Tracecode
X-HS-Status
X-NGINX-Cache
X-CUA
X-Edge-Cache
Load-Balancing
X-Wikidot-Static-Cache
Pagetype
X-Wikidot-Backend
Shield-Pop
X-Var-Ttl
X-From
X-Cms-Context
X-PJAX-URL
X-Akamai-Pragma-Client-IP
X-CCDN-Origin-Time
X-ServerName
T-Server
MD5-Digest
X-Via-Ucdn
URI
X-CCDN-CacheTTL
X-Ucs
X-Hcs-Proxy-Type
X-SIPLIST1
X-Fragments
X-Fastly-Backend-Reqs
X-GoCache-CacheStatus
Servername
X-Mcache
X-VG-WebServer
IsBot
Sever-Int
X-UP
Cf-Ipcountry
Server-Hostname
Server-Ext
Lang
X-Nc
X-Fastly-Cache-Hits
X-RAMCache
X-TRACE-ID
X-Dw-Trace-Id
X-VC
Target-Params
X-Lb-Id
WZWS-RAY
X-WP-CF-Super-Cache
Cdn
X-WP-CF-Super-Cache-Cache-Control
X-Cdn-Request-ID
Cneonction
X-RateLimit-Reset
X-B3-ParentSpanId
Ohc-Cache-HIT
W
X-Cache-Expires
X-Apw-Hits
X-Akamai-Request-ID
CF-Cached-On
X-Snapshot-Date
X-Contensis-Viewer-Groups
X-Cache-ASPX
X-Apw-Access-Token
X-Apw-Access-Action
Uri
X-Platform-Cluster
X-Platform-Processor
X-Acquia-Site
X-Acquia-Purge-Tags
X-Newrelic-App-Data
X-Acquia-Application-Trace
X-Acquia-Application-UUID
X-Apw-Access-Object
X-Provided-By
Dnion-Transfer-Encoding
X-Yottaa-OS
HitType
PICS-Label
Vha6-Origin
Cteonnt-Length
X-Platform-Router
X-Swift-Error
X-Air-Pt
DataCenter
X-Cache-Ngx
Sid
X-Sentry-ID
X-UA
X-Miniprofiler-Ids
X-Te-Duration-Ms
X-Varnish-Authentication
Server-Ttl
X-Last-Modified
X-Akamai-ERRuleID
X-Akamai-ERPolicy
X-Te-Count
X-Http-Duration-Ms
X-Cc-Via
X-Lb-Nocache
CountryCode
X-Logging-Id
X-B3-Parentspanid
X-CacheKey
X-Http-Count
Req-ID
Ngx
X-Via-CDN