Threat Level: green Handler on Duty: Guy Bruneau

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Link
Cf-Request-Id
CF-Cache-Status
Accept-Ranges
CF-RAY
ETag
X-XSS-Protection
Expect-CT
Pragma
X-Powered-By
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-UA-Compatible
X-Cache-Hits
Alt-Svc
P3P
X-Served-By
X-Xss-Protection
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Request-Id
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Cache-Status
X-Generator
X-Cacheable
Timing-Allow-Origin
X-Request-ID
X-Content-Security-Policy
P3p
X-Iinfo
Status
Feature-Policy
X-Envoy-Upstream-Service-Time
Content-Encoding
Access-Control-Expose-Headers
X-CDN
X-Drupal-Dynamic-Cache
Upgrade
X-AspNetMvc-Version
X-Via
CF-Ray
Access-Control-Max-Age
X-Ws-Request-Id
Server-Timing
EagleId
Keep-Alive
X-Cache-Group
X-Turbo-Charged-By
Request-Context
X-Age
X-Server-Powered-By
X-Proxy-Cache
X-AH-Environment
X-UA-Device
X-Backend
X-Hacker
X-Robots-Tag
Report-To
X-Amz-Request-Id
Host-Header
X-Server
X-LiteSpeed-Cache
X-Amz-Id-2
Grace
X-Rq
X-Nginx-Cache-Status
X-Varnish-Cache
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-WebKit-CSP
X-Dns-Prefetch-Control
X-Page-Speed
X-Vhost
X-OneAgent-JS-Injection
EagleEye-TraceId
X-Amz-Version-Id
X-Pingback
X-Device
X-Dispatcher
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Cache-Spec
NEL
X-Server-Id
X-Host
X-Backend-Server
Cf-Railgun
X-Node
Accept-CH
X-Readtime
X-Akam-SW-Version
Surrogate-Control
Request-Id
X-Response-Time
X-HW
X-Language
Xkey
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Application-Context
Content-Location
X-Template
X-Ruxit-JS-Agent
Rating
X-B3-TraceId
X-Ua-Compatible
Accept-Ch-Lifetime
X-Country
Accept-CH-Lifetime
X-Cloud-Trace-Context
X-Cache-Lookup
X-Ac
X-Url
X-Content-Type
Allow
X-Trace
X-Buckets
X-Vname
X-TtlSet
X-PC
X-Varnish-TTL
X-Mod-Pagespeed
X-Clacks-Overhead
Edge-Control
X-FastCGI-Cache
X-ESI
Cache-Tag
Fastly-Restarts
X-Server-Name
X-Rack-Cache
Service-Worker-Allowed
X-VARITI-CCR
X-Element-Page-Cache
Verso
X-MS-InvokeApp
X-GitHub-Request-Id
X-Upstream
X-Amz-Rid
MS-Author-Via
Public-Key-Pins
X-Vcap-Request-Id
X-Dw-Request-Base-Id
X-Cached
X-Client-IP
X-D2id
X-Abt-Application-Version
X-Origin-Cache
X-Cache-TTL
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
Arr-Disable-Session-Affinity
X-Aspnetmvc-Version
X-Cnection
X-Px
X-Country-Code
Access-Control-Request-Method
X-Goog-Hash
X-Powered-By-Plesk
X-Aws-Lambda-Call-Status
X-NF-Request-ID
X-Navigation-Version
X-Instrumentation
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Version
RTSS
Accept-Ch
X-Powered-CMS
X-Amz-Server-Side-Encryption
Display
X-Middleton-Display
X-Sol
Pagespeed
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Kinja-Revision
X-Use-Magma
X-Kinja-Server
X-Kinja-Build
X-Kinja
X-Exp-Id
X-Cdn-Fetch
X-GoogleNews-Bot
X-Exp-Variant
X-Middleton-Response
Response
X-MSEdge-Ref
X-LLID
X-Edge
X-Kinsta-Cache
X-Edge-Location-Klb
Nginx-Cache
AR-Request-ID
AR-CACHE
AR-ATIME
AR-PoweredBy
AR-SID
X-B3-TraceId-Primal
Mrf-Cache-Status
MRF-Tech
X-Shield-Request-Id
X-RateLimit-Remaining
X-TTL
S
X-HP-Webp
X-CST
X-Jurisdiction
X-HP-Trace-Id
Content-MD5
X-Protected-By
X-T
X-Forwarded-For
TCN
X-Content-Security-Policy-Report-Only
X-Mg-S
X-Id
Fastcgi-Cache
Realpath
X-Mid
X-MCACHE
Edge-Cache-Tag
SPRequestDuration
SPIisLatency
Front-End-Https
X-Parallel-Accel
X-Recruiting
X-Request-Processing-Time
X-Request-Received
Filters
Pinterest-Version
Fusion-Source
Server-Node
Fusion-Template-Id
Fusion-Content-Source
Fusion-Content-Id
Pinterest-Generated-By
X-Pinterest-Rid
Fusion-Component-Id
Fusion-Deployment-Id
X-Ttl
X-Ua-Browser
X-Ab
X-Content
X-DynaTrace
SPRequestGuid
X-SharePointHealthScore
X-Correlation-Id
X-Ezoic-Cdn
Server-Name
X-Ruxit-Js-Agent
Alternate-Protocol
X-NWS-LOG-UUID
X-HS-Cache-Config
X-HS-Content-Id
X-HS-Hub-Id
X-HS-Combine-CSS
X-Frontend
X-ECACHE
X-Hits
X-Accel-Expires
X-Yandex-Sdch-Disable
X-Cache-Key
X-Content-Options
X-Tt-Trace-Tag
X-Tt-Trace-Host
MicrosoftSharePointTeamServices
X-Page-Id
Cache-Tags
Host
X-Git-Hash
Charset
X-Fastly-Request-Id
X-Kong-Upstream-Latency
Cleartype
X-Kong-Proxy-Latency
X-Www-Served-By
X-B3-Sampled
X-Ser
X-Content-Digest
X-Amz-Replication-Status
Filterid
X-Geo-Country
TP-Cache
TP-L2-Cache
X-Forwarded-Proto
X-Amzn-Trace-Id
X-Daa-Tunnel
X-Varnish-Age
X-Hostname
X-VCache
X-AppVersion
X-Activity-Id
X-DIS-Request-ID
X-Az
X-Debug-Info
X-XRDS-LOCATION
X-Rid
X-Origin-Server
X-N
X-Upgrade-Enabled
Access-Control-Allow-Method
X-Grace
X-FB-Debug
X-Origin-Upstream-Status
X-LB-Cache
X-Nginx-Upstream-Cache-Status
X-WebKit-CSP-Report-Only
ServerID
X-Request-Handler-Origin-Region
X-Microsite
X-Mobile-URL
X-Aspnet-Duration-Ms
X-Request-Guid
X-Is-Crawler
X-Route-Name
X-Flags
X-Providence-Cookie
X-Whom
Cross-Origin-Opener-Policy
X-F-Cache
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-Goog-Metageneration
X-Goog-Generation
X-TT
X-GUploader-UploadID
X-NGENIX-Cache
X-App-Server
X-Varnish-Grace
X-App-Environment
X-Tb
Viewport
X-FW-Hash
X-FW-Server
Payment
X-FW-Dynamic
X-Distributor
X-FW-Serve
X-FW-Type
X-FW-Static
X-Server-ID
DC
Paypal-Debug-Id
Node
X-Cache-Control
X-Logged-In
X-Seen-By
X-Type
Fastcgi-Useragent
X-User-Agent
X-Ratelimit-Limit
X-Cache-Age
Country
Accept-Charset
X-PressLabs-Stats
X-Litespeed-Cache
X-Cache-Rule
X-DataDome
X-Wix-Request-Id
X-Varnish-Backend
X-Browser-Type
X-Webkit-CSP
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
Version
X-Load-Cache
X-Node-Name
X-Cache-Action
X-Tec-Api-Origin
X-Tec-Api-Root
Refresh
X-IPLB-Instance
X-Tec-Api-Version
X-Via-JSL
Referer-Policy
X-Drupal-Cache-Tags
Access-Control-Request-Headers
X-Original-Request-Id
X-Response-Served-From
SD-X-WS
Amp-Access-Control-Allow-Source-Origin
Cache-Status
X-Proxy-Cache-Status
X-Real-IP
X-Is-Bot
X-Cacheable-TTL
X-Page-View
X-Jobs
X-Vgn-Hpd-Reason
X-Rendered-As
NGB
X-Cluster-Name
X-Cache-Expired-At
X-B
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-RemovedCookies
X-Mobile
X-Signature
X-Revision
X-ProcessESI
X-UUID
X-Debug
X-B-Cache
X-Yottaa-Optimizations
X-Contextid
X-Proxy
X-Device-Type
X-Yottaa-Metrics
X-Rule
Surrogate-Key
X-Fastly-Request-ID
DynaTrace
Akamai-GRN
X-G
X-Instance
X-Drupal-Cache-Contexts
X-Cache-Time
X-Framework
X-Debug-IsPreview
X-Debug-IsConnected
Liferay-Portal
X-Fastcgi-Cache
X-FW-Version
CF-IPCountry
X-Azure-Ref
Healthy
X-Air-Trace-Id
X-Air-Hostname
SID
X-Air-Source
X-TEC-API-ROOT
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-Source
X-Ms-Request-Id
X-Oracle-Dms-Ecid
X-XRDS-Location
X-Oracle-Dms-Rid
X-Ms-Version
Frame-Options
MS-CV
Ms-Operation-Id
X-RTag
X-Cache-Hit
X-APP-VERSION
X-Oneagent-Js-Injection
X-CDN-Forward
X-Nginx-Cache
X-Environment-Context
X-L-Path
X-Tumblr-Pixel
X-Tumblr-Pixel-1
X-Tumblr-User
Countrycode
X-Tumblr-Pixel-0
Xserver
X-Varnish-Server
Count-Hit
Section-Io-Cache
GEO-INFO
X-Cache-Operation
Uber-Trace-Id
X-Region
X-EdgeConnect-Cache-Status
X-Servername
X-Content-Powered-By
X-Forwarded-Host
X-Accel-Buffering
X-Backend-Name
X-Ratelimit-Reset
Cross-Origin-Window-Policy
X-Mode
X-IPS-LoggedIn
X-Zen-Fury
Ec-Rule-Version
Backend
X-JoinUs
X-Adobe-Content
X-RN-RSRV
X-UPSTREAM-Address
X-SaId
X-Adobe-Loc
Meta-Geo
X-Detected-As
X-Cache-Grace
X-Alternate-Cache-Key
X-Generation-Time
X-Shopify-Stage
X-Varnish-Beresp-Grace
Eomportal-Instance
X-Redis-Cache
X-Sorting-Hat-ShopId
X-Cache-Server
X-Sql-Count
X-Uri
X-Hosted-By
X-ShopId
X-Debug-Cache
X-Human
X-ShardId
Country-Code
X-Sql-Duration-Ms
X-Cache-Type
X-Sorting-Hat-PodId
X-PHP-Backend
Apigw-Requestid
X-ServerID
Cache-Name
X-ProxyCache-Key
Mn-Server-Ip
X-Microcachable
X-NCache
X-BYPASS-REASON
X-Cache-TTL-Remaining
X-FB-TRIP-ID
X-No-Session
Url
X-Origin-Date
Decoy-Debug-Key
Decoy-Debug-Status
Decoy-Debug-TTL
Cache-Tv-Group
X-ProxyCache-Status
X-Site-Version
X-UA-Device-Type
X-Status
X-Via-Fastly
X-Tid
Selected-Fe
Protected
TWC-Connection-Speed
TWC-GeoIP-Country
TWC-GeoIP-LatLong
Property-Id
TWC-Device-Class
X-Proxy-Build
X-Origin-Hint
X-PCL
Fastly-SSL
TWC-Locale-Group
DB-Nickname
X-OCL
X-Web-Node
TWC-Privacy
X-Timing-Wait
X-Akamai-Edgescape
X-Presslabs-Stats
X-Say-Cacheable
X-Say-TTL
X-Cache-Host
X-Format
Webcakes-App-Name
X-Storage
Webcakes-App-Version
Webcakes-Region
X-Cache-NGX
X-SayCDN-TTL
X-Extlb
Azure-Version
X-Hl-Ver
OT-Force-Account-Verify
X-Varnishpool
X-NYM-Debug-Backend
X-Access
Azure-SlotName
X-ApacheServer
X-Zipkin-Id
X-Rewrite-Enabled
X-Proxied
X-Section
X-Routing-Service
Azure-SiteName
X-Pubstack
X-R9-Blue-Green-Version
X-PERF
X-Server-W
Azure-RegionName
Azure-InstanceId
X-Soup
Content-Secure-Policy
X-LSADC-Cache
X-Cluster-Node
X-Azure-Ref-OriginShield
X-Be
X-RateLimit-Limit
Source
X-Ua
X-NewRelic-App-Data
X-Content-Age
X-Webkit-Csp
Content-Disposition
X-HTML-Minification-Powered-By
CDN-PullZone
CDN-CachedAt
CDN-Uid
X-Cached-By
X-SRV
CDN-EdgeStorageId
X-Dc
CDN-RequestCountryCode
CDN-RequestId
CDN-Cache
X-Time
Cache
X-Amz-Meta-S3cmd-Attrs
X-Generated-By
X-LAGOON
X-Cache-Var-Map
SRV
X-Unique-Id
X-Hyper-Cache
X-Cache-Var
X-TNCMS
X-Loop
X-Varnish-Hits
X-Varnish-Hostname
X-Bc-Bl
X-App-Version
X-Trace-Id
X-Nginx-Cache-Key
Onion-Location
X-S-Maxage
X-Origin-CC
Retry-After
X-Auto-Login
X-Origin-TTL
X-GEO
X-TT-LOGID
Cache-Hits
X-Tumblr-Pixel-2
X-Tumblr-Pixel-3
Web-Mar-Node
Xet-Cookie
LB
X-Proto
X-ECache
Webserver
X-Qnm-Cache
X-M-Reqid
X-M-Log
X-Time-Microsecs
X-Tenant
Mime-Version
X-Endurance-Cache-Level
X-Cdn
X-Akamai-Transformed
X-Platform-Server
X-Edge-Location
X-VWS-Id
X-LJ-Flow-ID
X-GG-Cache-Date
X-AWS-Id
X-TIME
CloudFront-Viewer-Country
X-CSRF-Token
WPO-Cache-Message
X-Xfnlog-Site
WPO-Cache-Status
HostName
X-Mg-Request-UUID
X-CACHE-KEY
N-Cache
X-Cache-Tags
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Labrador-Cache-Channel
X-PHP-Host
X-Varnish-Cache-Hits
X-Cache-Remote
Upgrade-Insecure-Requests
X-B3-SpanId
X-RCS-CacheZone
ServedBy
X-Request-Time
X-Locale
X-Origin-Response-Time
X-Handled-By
X-AOL-HN
X-Storefront-Renderer-Rendered
X-Via-NSCOPI
X-A-Dam
A
X-A-Dcw
X-A-Wwc
X-B-Cookie
X-Block-Status
X-ARC
X-Application
X-Aed
X-A-Dgt
X-A-Ccd
Redirect-Candidate
Fastcgi-X-Cache-Version
X-Cache-Date
Pramga
Origin
Mobile-Detection-Method
Odigeo-Trace-Id
Expiry
Rendered-Blocks
X-A
DCR-Decision-By
BehaviorPad-Version
DCR-Processing-Time-Ms
User-Cache-Control
Surrogated-Key
DSUID
Meta-Geo-Continent
X-Hnp-Log
X-SD-PageType
X-Session-Fingerprint
X-Shop-Environment
X-Slack-Backend
X-ScT
X-S-Cookie
X-Request-Host
X-Rojux
X-S
X-SRCache-Key
X-SVT-ORM-RULES
X-VG-WebCache
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
Xc-Version
X-Vdms-Version
X-Vdms-Path
X-SVT-ORM-VERSION
X-TIM-N
X-V-Cache
X-Processor
X-Planisys-CDN-TTL
X-D
X-Destination
X-Developer
X-External-Request-Id
X-Connection-Hash
X-Cluster
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-Ckpd-Fst-Backend
X-Forwarded-Path
X-Ftr-Request-Id
X-PAYTM-SRV-ID
X-PBS-Appsvrname
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Orig-Expires
X-ND-Cache
X-Gen-Mode
X-Ig-Push-State
X-NAPM-TraceId
X-Cache-NE
X-Conf
X-Correlation-ID
Nel
X-VC-Cache
X-ATG-Version
X-MP-GENERATED-AT
Server-Info
X-Reqid
X-Adobe-Source
X-Origin-Time
Origin-EX
X-Old-Content-Length
State
X-Location
X-Men
X-Mvc-Supplant-Cachable
Release
X-Nyt-Route
X-Origin-Expires
Origin-CC
X-Rocket-Nginx-Serving-Static
Fastcgi-Cache-TTL
X-Scheme
X-Served-From
Gh-Request-Id
Host-ID
X-Policy
X-Proxy-Upstream
L
Traceparent
V-Age
X-Fastly-Cache
X-Cache-Bucket
X-Fetched-On
X-Forwarded-Site
X-Cache-Info
X-Epic-Correlation-Id
X-Core-Mission
X-Date
X-Device-Os
X-Gdpr
X-Geo-Header
Vix-Hermes-Req-Id
X-Server-IP
X-Li-Fabric
X-Li-Pop
Wxu-Next-Commit
Wxu-Next-Hostname
X-Accel-Expires-Debug
X-Hash
Wxu-Next-Region
X-LI-UUID
X-Owner
X-VServer
Cmsid
Cmstype
Arc-Country
X-Varnish-Beresp-Status
X-Sucuri-ID
X-Skip-Cache
AKAMAI
CDCHOST
CacheControlHeader
X-Sucuri-Cache
Environment
From-Origin
Datacenter
AMP-Access-Control-Allow-Source-Origin
X-HS-Content-Campaign-Id
Thinkindot-CacheControl
TDXMobile
X-HN
X-Magnolia-Registration
Thinkindot-CacheControl-Type
Svr
Thinkindot-Control
X-Sigma
X-TrackingId
X-Level-Front-Cache
We-Hiring
X-Irp-Debug
Web-Mar-Region
X-Gzip
X-GeoIP
X-Esi-Check
X-Cdn-Origin
X-Fastly-Backend
X-Cache-Id
X-Cache-Debug
X-Webstats-RespID
X-Developers
X-Core-Value
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
X-Datadog-Trace-Id
X-Cache-Config
X-Branch-Name
X-VG-TLSProxy
Apple-News-Services-Handled
X-GeoIP-City
X-Aicache-OS
X-Generated-On
X-Viewer-Country
X-Bip
X-BBC-Edge-Cache-Status
X-Gamma-Serve
X-Ratelimit-Remaining
X-VarnishDD-TTL
True-Client-Country-4JS
X-Request-Start
X-Platform
X-TH-Server
X-Thanos
X-Req
X-Region-Sid
Locid
Machine
Mail-Subject
Apple-News-Services-Host
X-Thinkindot-L3
PFcat
Apple-News-Services-Request-Url
Req-Svc-Chain
X-Rocket-Build-Number
Server-Host
X-NodeID
X-Sigma-Backend
X-Sn-Servicetimems
Fastly-GeoIP-CountryCode
Apple-News-Services-Parsed-Url
X-EC-Lua
X-FireWall-Port
Cf-Device-Type
X-Node-Id
X-Cdn-Srv
Is-Eu
X-Worker
X-FC-Vary-Parameters
X-Eu-Site
Fastly-SIE
Fastly-SWR
X-CGP
X-DefHash
X-DefElseHash
X-Request-URI
X-DPWN-IS-SECURE
HA-Ipaddr
Sslversion
Ha-Gx-Prefs
X-Envoy-Decorator-Operation
Fastly-Drupal-Html
Memcached
Platform
X-Is-Gdpr
X-Csrf-Jwt
X-Varnish-CookieHashed-On
X-Pod-Name
X-JWT-State
X-Variation
X-Loc
X-NU-AKA-ACS-Version
Adler-Geo
X-Origin
X-UnsetCookies
L5d-Success-Class
X-Varnish-CookieINHashed-On
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-Amzn-Remapped-Content-Length
X-Rebelmouse-Cache-Control
X-Backend-State
X-Rebelmouse-Surrogate-Control
NGX
NM-Fastcgi-Cache
X-Has-Esi
Candidate-Md5Url
X-Qloud-Router
X-Varnish-Remaining-TTL
X-Xrds-Location
X-Tx-Id
X-Response-By
Ssr
X-Mvc-Supplant-OutputCached
WP-Super-Cache
X-Ua-Device
X-Varnish-Beresp-Ttl
X-Up
On-Server
X-CS
X-NC
X-CLOUD-TRACE-CONTEXT
CDN
X-API-Version
WWW-Authenticate
X-Zone
X-Vc
Esi-Enabled
X-LB-ID
X-Generated-In
Pics-Label
X-Tt-Logid
NtCoent-Length
X-Trace-ID
Memory
Ms-Author-Via
X-Cache-Enabled
Time
X-Refresh
X-Backend-TTL
X-Datadome
X-NWS-UUID-VERIFY
X-Service
X-LB-NoCache
X-GeoIP-Region-Code
X-GeoIP-Country-Code
C-Via
X-TraceId
X-Edge-Pop
X-TA-CDN-Provider
X-DynaTrace-JS-Agent
X-Via-Poph
X-Via-Popv
X-Cache-PHP
GeoIp-Country-Code
Env
X-Tb-Optimization-Total-Bytes-Saved
X-Via-Popn
Magicmarker
X-Parent-Response-Time
X-Dynatrace
X-Varnish-Ttl
X-ZONE
X-Optimistic-Header
WebServer
X-Render-Time
X-Restarts
X-DC
X-Cache-Status-Check
Kp-EeAlive
X-CacheTTL
S-Rt
X-Varnish-Beresp-TTL
X-Servedbyhost
X-Cs
X-Esi
X-Srv
X-Info
X-RSL
X-RPS
Edge-Cache
X-Cache-Backend
X-Wix-Viewer-Type
X-MSEdge-Flight
X-RPM
X-DW
X-Action
Server-ID
X-DB
X-DI
X-DSS
X-Unique-ID
X-MSEdge-Features
X-TX-ID
Proxy-Connection
X-AIR-PT
X-VCL-Version
X-Clientip
X-Minions-Version
X-Http-Reason
X-Akamai-Request-ID2
X-Fpc
X-Oss-Object-Type
X-LI-Proto
X-Cache-Ttl
X-Oss-Request-Id
X-Oss-Hash-Crc64ecma
X-Oss-Storage-Class
Cache-Host
X-Newrelic-Synthetics
UCS
X-Li-Proto
HIT
X-App
X-Oss-Server-Time
X-URL
X-Webkit-Csp-Report-Only
Test
X-HA-Backend
X-FPC
Accept-Language
S-Cnection
Section-Io-Id
Section-Origin-Responded
X-Traceid
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
X-B3-Spanid
Lb
Server-Id
X-Vcl-Version
X-LiteSpeed-Cache-Control
X-NODE
X-Webkit-CSP-Report-Only
Tcn
Geo-Info
User-Agent
X-Ec-GeoHdr
X-Ec-Fail
X-User
Fastly-Backend-Name
X-Micro-Cache
X-Urbn-Site-Id
Locale
X-Urbn-Context-Path
X-CSRF-TOKEN
X-Backend-Host
X-Pad
X-Pass-Why
Fastly-Drupal-HTML
Resin-Trace
Hostname
X-Ha-Backend
X-APP
X-LiteSpeed-Tag
X-Release
Cf-Int-Pingora-Origin-Digest
X-HostName
X-BCube-Filmed-By
X-Check-Cacheable
X-BBC-Origin-Response-Status
X-ServedByHost
M-TraceId
X-AK-Request-ID
Cdnsip
Cdncip
X-ID
X-ES-SERVER
X-Dynatrace-Js-Agent
X-COUNTRY
My-App
Geoip-Latitude
X-WADP-Cache
X-Fmm-Version
X-Amz-Meta-Cb-Modifiedtime
Cluster
EpKe-Alive
GeoIP-Country-Code
Hit
Ohc-File-Size
Path
X-Via-PopH
X-Via-PopV
X-Via-PopN
X-Clara-WADP
X-NGINX-Cache
CPC-Age
CPC-Cache
X-WA-Info
X-WA
Cache-Key
VNS-Cache
Srv
VNS-Age
X-Geo
Tracecode
X-Edge-POP
ENV
X-Cdn-Forward
X-ElasticPress-Query
X-Var-Ttl
X-CUA
MIME-Version
X-Cms-Context
X-Edge-Cache
X-PJAX-URL
Shield-Pop
Pagetype
T-Server
X-Api-Version
X-From
Load-Balancing
X-Wikidot-Static-Cache
Lfy
X-HS-Status
X-Wikidot-Backend
X-Akamai-Pragma-Client-IP
X-CCDN-Origin-Time
X-Ucs
X-Hcs-Proxy-Type
MD5-Digest
Lang
X-Via-Ucdn
URI
X-RAMCache
X-ServerName
X-CCDN-CacheTTL
X-Fragments
Servername
X-WP-CF-Super-Cache-Cache-Control
Server-Ext
X-Lb-Id
X-UP
Target-Params
X-GoCache-CacheStatus
X-Fastly-Backend-Reqs
X-WP-CF-Super-Cache
IsBot
X-Mcache
X-SIPLIST1
X-Fastly-Cache-Hits
X-VG-WebServer
Server-Hostname
Sever-Int
X-TRACE-ID
X-Dw-Trace-Id
WZWS-RAY
Uri
PICS-Label
X-Cache-Expires
X-RateLimit-Reset
X-B3-ParentSpanId
W
Cneonction
Ohc-Cache-HIT
X-Cdn-Request-ID
Cdn
X-VC
X-Nc
X-Provided-By
Dnion-Transfer-Encoding
X-Acquia-Application-Trace
X-Swift-Error
X-Platform-Cluster
X-Platform-Router
X-Newrelic-App-Data
X-Yottaa-OS
X-Akamai-Request-ID
HitType
X-Platform-Processor
X-Apw-Access-Action
X-Apw-Access-Object
Cteonnt-Length
X-Snapshot-Date
X-Acquia-Purge-Tags
Vha6-Origin
X-Acquia-Site
Cf-Ipcountry
X-Contensis-Viewer-Groups
X-Acquia-Application-UUID
CF-Cached-On
X-Apw-Hits
X-Apw-Access-Token
X-Cache-ASPX
Sid
DataCenter
X-Cache-Ngx
X-Air-Pt
X-Http-Duration-Ms
Server-Ttl
X-Akamai-ERRuleID
X-Last-Modified
X-Akamai-ERPolicy
X-Http-Count
X-Te-Duration-Ms
X-Te-Count
Ngx
X-Lb-Nocache
X-UA
CountryCode
X-Varnish-Authentication
Req-ID
X-Miniprofiler-Ids
X-Sentry-ID
X-Via-CDN
X-Cc-Via
X-CacheKey
X-B3-Parentspanid
X-Logging-Id