Threat Level: green Handler on Duty: Jan Kopriva

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
Link
CF-Cache-Status
Accept-Ranges
CF-RAY
ETag
X-XSS-Protection
Expect-CT
Pragma
X-Powered-By
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-UA-Compatible
X-Cache-Hits
Alt-Svc
P3P
X-Served-By
X-Xss-Protection
X-Download-Options
X-Timer
X-Request-Id
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Cache-Status
X-Generator
X-Cacheable
Timing-Allow-Origin
X-Content-Security-Policy
P3p
X-Iinfo
Status
Feature-Policy
X-Envoy-Upstream-Service-Time
Content-Encoding
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
X-CDN
X-Request-ID
Upgrade
X-AspNetMvc-Version
X-Via
CF-Ray
X-Ws-Request-Id
Access-Control-Max-Age
Server-Timing
EagleId
Keep-Alive
X-Cache-Group
X-Turbo-Charged-By
Request-Context
X-Age
X-Server-Powered-By
X-Proxy-Cache
X-AH-Environment
X-Backend
X-Hacker
X-Robots-Tag
X-UA-Device
Report-To
X-Amz-Request-Id
Host-Header
X-Server
X-Amz-Id-2
X-LiteSpeed-Cache
Grace
X-Dns-Prefetch-Control
X-Rq
X-Nginx-Cache-Status
X-Varnish-Cache
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-WebKit-CSP
X-Page-Speed
X-Vhost
X-OneAgent-JS-Injection
EagleEye-TraceId
X-Amz-Version-Id
X-Pingback
X-Device
X-Dispatcher
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Cache-Spec
NEL
X-Server-Id
X-Host
Cf-Railgun
X-Node
X-Backend-Server
Accept-CH
X-Readtime
X-Akam-SW-Version
Surrogate-Control
Request-Id
X-Response-Time
X-HW
Xkey
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Application-Context
Content-Location
X-Ruxit-JS-Agent
Rating
X-B3-TraceId
X-Ua-Compatible
Accept-Ch-Lifetime
X-Country
X-Cache-Lookup
X-Language
Accept-CH-Lifetime
X-Cloud-Trace-Context
X-Url
X-Trace
X-Template
X-Ac
X-Content-Type
Allow
X-Vname
X-TtlSet
X-PC
X-Varnish-TTL
X-Mod-Pagespeed
X-Clacks-Overhead
Edge-Control
X-FastCGI-Cache
X-ESI
Cache-Tag
Fastly-Restarts
X-Server-Name
X-Rack-Cache
Service-Worker-Allowed
X-VARITI-CCR
X-Element-Page-Cache
Verso
X-MS-InvokeApp
X-GitHub-Request-Id
X-Buckets
X-Upstream
MS-Author-Via
X-Amz-Rid
Public-Key-Pins
X-Vcap-Request-Id
X-Cached
X-Dw-Request-Base-Id
X-Client-IP
X-D2id
X-Abt-Application-Version
X-Aws-Lambda-Call-Status
X-Cache-TTL
X-Origin-Cache
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
X-Cnection
X-Aspnetmvc-Version
X-Px
Arr-Disable-Session-Affinity
X-Country-Code
X-Powered-By-Plesk
X-Goog-Hash
Access-Control-Request-Method
X-Navigation-Version
RTSS
X-NF-Request-ID
X-Kraken-Loop-Name
X-Instrumentation
X-Server-Lifecycle-Phase
Accept-Ch
X-Version
X-Powered-CMS
X-Kinja
X-GoogleNews-Bot
X-Exp-Variant
X-Kinja-Build
X-Kinja-Revision
X-Use-Magma
X-Kinja-Server
X-Exp-Id
X-Cdn-Fetch
X-Sol
Display
X-Middleton-Display
Pagespeed
X-Amz-Server-Side-Encryption
Response
X-Middleton-Response
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-MSEdge-Ref
AR-ATIME
AR-PoweredBy
AR-SID
AR-Request-ID
AR-CACHE
X-LLID
X-Edge-Location-Klb
X-Kinsta-Cache
X-Edge
Nginx-Cache
Mrf-Cache-Status
MRF-Tech
X-B3-TraceId-Primal
X-RateLimit-Remaining
X-Shield-Request-Id
X-Protected-By
X-Jurisdiction
X-HP-Trace-Id
X-HP-Webp
X-T
S
TCN
X-Forwarded-For
X-Content-Security-Policy-Report-Only
Content-MD5
X-Mg-S
X-TTL
X-Id
X-MCACHE
Realpath
Fastcgi-Cache
X-Mid
X-CST
Edge-Cache-Tag
X-Ttl
SPRequestDuration
SPIisLatency
Front-End-Https
X-Recruiting
X-Request-Received
X-Request-Processing-Time
Filters
Server-Node
X-Pinterest-Rid
Pinterest-Generated-By
Pinterest-Version
X-Parallel-Accel
X-Ab
X-Ua-Browser
X-Content
X-DynaTrace
X-Correlation-Id
Fusion-Template-Id
SPRequestGuid
Fusion-Source
Fusion-Component-Id
Server-Name
X-SharePointHealthScore
Fusion-Content-Id
Fusion-Deployment-Id
Fusion-Content-Source
X-NWS-LOG-UUID
X-Ruxit-Js-Agent
X-Frontend
X-Ezoic-Cdn
X-HS-Content-Id
X-HS-Hub-Id
X-HS-Cache-Config
X-HS-Combine-CSS
X-ECACHE
Alternate-Protocol
X-Yandex-Sdch-Disable
X-Hits
X-Ser
X-Cache-Key
X-Content-Options
X-Tt-Trace-Tag
X-Tt-Trace-Host
MicrosoftSharePointTeamServices
X-Page-Id
Cache-Tags
X-Git-Hash
X-Kong-Upstream-Latency
X-B3-Sampled
X-Kong-Proxy-Latency
Host
Cleartype
Charset
X-Accel-Expires
X-Fastly-Request-Id
X-Www-Served-By
X-Daa-Tunnel
X-ASPNET-VERSION
X-Content-Digest
X-Geo-Country
X-Amz-Replication-Status
X-Amzn-Trace-Id
X-DIS-Request-ID
Filterid
TP-L2-Cache
TP-Cache
X-Forwarded-Proto
X-VCache
X-Varnish-Age
X-Activity-Id
X-AppVersion
X-Az
X-Hostname
X-Debug-Info
X-Upgrade-Enabled
X-Rid
X-FB-Debug
X-N
X-XRDS-LOCATION
X-Origin-Server
Access-Control-Allow-Method
X-Grace
X-LB-Cache
X-WebKit-CSP-Report-Only
X-Nginx-Upstream-Cache-Status
ServerID
Cross-Origin-Opener-Policy
X-Mobile-URL
X-F-Cache
X-Providence-Cookie
X-Request-Guid
X-Is-Crawler
X-Flags
X-Route-Name
X-Aspnet-Duration-Ms
X-Ratelimit-Limit
X-Whom
X-Goog-Metageneration
X-Goog-Generation
X-Goog-Storage-Class
X-Origin-Upstream-Status
X-Goog-Stored-Content-Encoding
X-GUploader-UploadID
X-TT
X-Goog-Stored-Content-Length
X-Varnish-Grace
X-App-Environment
X-Tb
X-App-Server
Viewport
X-FW-Server
X-FW-Static
Payment
X-FW-Serve
X-Distributor
X-FW-Hash
X-FW-Dynamic
X-FW-Type
DC
X-NGENIX-Cache
X-Server-ID
Paypal-Debug-Id
Node
X-Seen-By
X-Type
X-Microsite
X-Request-Handler-Origin-Region
X-Cache-Control
Fastcgi-Useragent
X-User-Agent
X-Logged-In
Accept-Charset
Country
X-Cache-Rule
X-Wix-Request-Id
X-Litespeed-Cache
X-Cache-Age
X-DataDome
Version
X-Webkit-Csp
X-Webkit-CSP
X-Varnish-Backend
X-Browser-Type
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
Referer-Policy
X-Load-Cache
X-Drupal-Cache-Tags
X-Node-Name
X-Via-JSL
Refresh
X-Cache-Action
X-Cluster-Name
X-Tec-Api-Version
SD-X-WS
X-Tec-Api-Origin
Cache-Status
X-Tec-Api-Root
X-Original-Request-Id
X-Contextid
X-B-Cache
X-Mobile
X-IPLB-Instance
X-Response-Served-From
X-Signature
Amp-Access-Control-Allow-Source-Origin
Access-Control-Request-Headers
X-Cacheable-TTL
X-Vgn-Hpd-Reason
X-Real-IP
X-Jobs
X-Page-View
X-Is-Bot
X-Rendered-As
X-Proxy-Cache-Status
NGB
VIX-Pulpo-Upstream-Status
X-Debug
X-Cache-Expired-At
X-ProcessESI
X-B
VIX-Pulpo-Node
X-RemovedCookies
X-Revision
X-UUID
X-Yottaa-Optimizations
X-Device-Type
X-Proxy
X-Rule
X-Yottaa-Metrics
X-Fastly-Request-ID
X-Drupal-Cache-Contexts
Surrogate-Key
X-Cache-Time
Akamai-GRN
X-Framework
X-Instance
X-G
X-Debug-IsConnected
X-PressLabs-Stats
X-Debug-IsPreview
CF-IPCountry
X-FW-Version
X-Fastcgi-Cache
DynaTrace
X-Air-Hostname
X-Air-Source
X-Air-Trace-Id
Liferay-Portal
SID
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Azure-Ref
Healthy
X-Oracle-Dms-Ecid
X-Oracle-Dms-Rid
X-Source
X-Ms-Version
X-Ratelimit-Reset
X-Ms-Request-Id
Frame-Options
X-Ua-Device
X-RTag
MS-CV
Ms-Operation-Id
X-CDN-Forward
X-Oneagent-Js-Injection
Count-Hit
X-Nginx-Cache
GEO-INFO
X-Cache-Operation
X-APP-VERSION
X-Cache-Hit
X-Presslabs-Stats
X-Environment-Context
Uber-Trace-Id
X-L-Path
X-EdgeConnect-Cache-Status
Countrycode
X-Tumblr-Pixel
X-Tumblr-User
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
Xserver
X-Accel-Buffering
X-Varnish-Server
X-XRDS-Location
X-Region
X-Mode
X-Servername
X-Backend-Name
Section-Io-Cache
X-Zen-Fury
Ec-Rule-Version
X-Content-Powered-By
X-Forwarded-Host
X-IPS-LoggedIn
Cross-Origin-Window-Policy
Backend
X-Cache-NGX
X-SaId
X-JoinUs
X-UPSTREAM-Address
Meta-Geo
X-RN-RSRV
X-Detected-As
X-Routing-Service
X-Redis-Cache
X-Proxied
X-ShardId
X-Cache-Grace
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Shopify-Stage
X-Human
X-Hosted-By
Eomportal-Instance
Country-Code
Protected
X-Alternate-Cache-Key
X-Cache-Server
X-Generation-Time
X-Extlb
X-Debug-Cache
X-Sql-Count
X-ShopId
X-Varnish-Beresp-Grace
X-Cache-Type
X-Sql-Duration-Ms
X-Uri
X-Zipkin-Id
X-Tid
X-Cache-TTL-Remaining
X-BYPASS-REASON
Mn-Server-Ip
Decoy-Debug-TTL
X-Rewrite-Enabled
Url
Cache-Tv-Group
X-Status
X-FB-TRIP-ID
X-NCache
Cache-Name
X-No-Session
X-Via-Fastly
X-ProxyCache-Status
X-ServerID
X-UA-Device-Type
X-Site-Version
X-ProxyCache-Key
Apigw-Requestid
Decoy-Debug-Key
DB-Nickname
X-Origin-Date
X-PHP-Backend
Decoy-Debug-Status
X-Microcachable
X-Adobe-Loc
X-Adobe-Content
X-SayCDN-TTL
X-Say-Cacheable
X-Server-W
X-Soup
X-Origin-Hint
X-Storage
Fastly-SSL
X-OCL
X-Akamai-Edgescape
X-Cache-Host
Selected-Fe
X-PCL
X-Proxy-Build
X-Format
X-Timing-Wait
X-Say-TTL
TWC-GeoIP-Country
TWC-Connection-Speed
TWC-Device-Class
Webcakes-App-Name
TWC-Privacy
Webcakes-App-Version
Property-Id
Webcakes-Region
TWC-GeoIP-LatLong
TWC-Locale-Group
X-Web-Node
OT-Force-Account-Verify
X-NYM-Debug-Backend
X-Hl-Ver
X-Section
X-Pubstack
X-ApacheServer
X-Access
X-Varnishpool
Azure-SiteName
Azure-RegionName
Azure-InstanceId
Azure-SlotName
Azure-Version
X-R9-Blue-Green-Version
X-PERF
Content-Secure-Policy
X-Be
X-RateLimit-Limit
X-Cluster-Node
X-Content-Age
X-Ua
X-LSADC-Cache
X-Azure-Ref-OriginShield
CDN-PullZone
CDN-EdgeStorageId
CDN-CachedAt
CDN-RequestCountryCode
Source
CDN-Uid
SRV
X-NewRelic-App-Data
X-Hyper-Cache
CDN-Cache
CDN-RequestId
X-Cached-By
Content-Disposition
X-Generated-By
X-SRV
X-Dc
X-Unique-Id
Cache
X-Trace-Id
X-HTML-Minification-Powered-By
X-Nginx-Cache-Key
LB
X-TIME
X-Bc-Bl
X-LAGOON
X-App-Version
Xet-Cookie
X-Amz-Meta-S3cmd-Attrs
X-Varnish-Hits
X-Varnish-Hostname
X-Auto-Login
X-Loop
WPO-Cache-Message
X-TNCMS
WPO-Cache-Status
X-Origin-CC
Retry-After
X-Origin-TTL
X-S-Maxage
X-GEO
Onion-Location
X-TT-LOGID
X-Cache-Var-Map
X-Cache-Var
Cache-Hits
X-Akamai-Transformed
X-Time
Mime-Version
X-Tumblr-Pixel-3
X-ECache
X-Platform-Server
X-Tumblr-Pixel-2
Web-Mar-Node
X-Proto
X-Ratelimit-Remaining
X-Cdn
HostName
X-M-Reqid
X-M-Log
X-Time-Microsecs
X-Endurance-Cache-Level
X-Qnm-Cache
X-Tenant
X-Xfnlog-Site
X-VWS-Id
X-Cache-Remote
X-CSRF-Token
X-Cache-Tags
X-LJ-Flow-ID
X-AWS-Id
X-Edge-Location
Upgrade-Insecure-Requests
X-GG-Cache-Date
X-Varnish-Cache-Hits
ServedBy
N-Cache
X-Request-Time
CloudFront-Viewer-Country
Webserver
X-Mg-Request-UUID
X-AOL-HN
X-B3-SpanId
X-Amzn-RequestId
X-Labrador-Cache-Channel
X-Xrds-Location
X-PHP-Host
X-Amz-Apigw-Id
X-RCS-CacheZone
X-Request-Host
X-CACHE-KEY
X-Via-NSCOPI
X-EC-Lua
DCR-Processing-Time-Ms
Odigeo-Trace-Id
Origin
Mobile-Detection-Method
Meta-Geo-Continent
Fastcgi-X-Cache-Version
Pramga
Expiry
A
Redirect-Candidate
BehaviorPad-Version
DCR-Decision-By
DSUID
Xc-Version
X-V-Cache
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Cluster
X-Planisys-CDN-Cache
X-Conf
X-PBS-Appsvrname
X-Ckpd-Fst-Backend
X-Processor
X-S
X-S-Cookie
X-CF-Lambda-Fn
X-Rojux
X-CF-Lambda-Version
X-PAYTM-SRV-ID
X-Connection-Hash
X-Ig-Push-State
X-Hnp-Log
X-NAPM-TraceId
X-ND-Cache
X-Orig-Expires
X-Gen-Mode
X-Ftr-Request-Id
X-Destination
X-D
X-Developer
X-External-Request-Id
X-Forwarded-Path
X-Cache-NE
X-Cache-Date
X-Vdms-Version
X-VG-WebCache
X-Vdms-Path
X-Origin-Response-Time
X-TIM-N
X-A-Dgt
X-A-Dcw
X-A-Dam
X-Vtex-Remote-Cache
Surrogated-Key
X-Vtex-Processado-Em
X-A
X-A-Ccd
X-A-Wwc
X-Aed
X-Session-Fingerprint
X-B-Cookie
X-Block-Status
X-SD-PageType
X-ScT
X-ARC
X-Application
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-SRCache-Key
X-Slack-Backend
X-Shop-Environment
Rendered-Blocks
User-Cache-Control
X-Locale
X-Handled-By
Nel
X-Correlation-ID
X-MP-GENERATED-AT
From-Origin
X-FireWall-Port
X-Storefront-Renderer-Rendered
X-VServer
X-Fastly-Cache
X-Epic-Correlation-Id
X-Device-Os
X-Fetched-On
X-Date
Origin-CC
X-Aicache-OS
Fastcgi-Cache-TTL
X-Li-Fabric
X-Li-Pop
X-Hash
X-Geo-Header
Host-ID
Origin-EX
Gh-Request-Id
X-Forwarded-Site
CDCHOST
Wxu-Next-Region
Vix-Hermes-Req-Id
Sslversion
X-VC-Cache
V-Age
X-Accel-Expires-Debug
Wxu-Next-Commit
Wxu-Next-Hostname
X-Server-IP
Traceparent
X-LI-UUID
Release
X-Webstats-RespID
X-Cache-Info
L
X-Cache-Bucket
State
X-Core-Mission
X-Gdpr
X-Old-Content-Length
X-Origin-Expires
X-Nyt-Route
X-Policy
X-Owner
Arc-Country
WP-Super-Cache
X-Location
X-Varnish-Beresp-Status
X-Origin-Time
AKAMAI
X-Sucuri-ID
CacheControlHeader
Cmsid
X-Proxy-Upstream
Cmstype
X-Scheme
X-Served-From
X-Skip-Cache
X-Rocket-Nginx-Serving-Static
X-Mvc-Supplant-Cachable
X-Sucuri-Cache
X-Men
X-ATG-Version
X-Reqid
AMP-Access-Control-Allow-Source-Origin
Server-Info
Environment
X-Adobe-Source
X-GeoIP
X-Req
Ssr
X-Request-Start
X-Region-Sid
PFcat
X-VG-TLSProxy
X-Bip
Locid
X-Generated-On
X-Rocket-Build-Number
Svr
X-Sigma-Backend
X-Sigma
X-Irp-Debug
X-Level-Front-Cache
X-HS-Content-Campaign-Id
X-Gzip
True-Client-Country-4JS
X-GeoIP-City
X-Sn-Servicetimems
X-Branch-Name
X-Node-Id
Apple-News-Services-Handled
X-Datadog-Sampling-Priority
X-TH-Server
X-Datadog-Trace-Id
X-Thanos
X-NWS-UUID-VERIFY
X-Datadog-Parent-Id
X-TrackingId
X-Thinkindot-L3
X-Cdn-Origin
Apple-News-Services-Host
X-Platform
X-Cache-Config
X-Viewer-Country
X-Gamma-Serve
X-Cache-Id
X-Fastly-Backend
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
X-Esi-Check
X-Core-Value
X-BBC-Edge-Cache-Status
X-HN
TDXMobile
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
X-NodeID
Server-Host
Mail-Subject
Req-Svc-Chain
Machine
Thinkindot-Control
X-VarnishDD-TTL
Fastly-Drupal-Html
Web-Mar-Region
Fastly-GeoIP-CountryCode
X-Cache-Debug
We-Hiring
X-Cdn-Srv
X-Developers
X-Magnolia-Registration
X-Zone
X-Varnish-Remaining-TTL
X-NU-AKA-ACS-Version
X-Is-Gdpr
X-RateLimit-Limit-Second
X-Origin
X-DefHash
Adler-Geo
Memcached
NGX
X-DPWN-IS-SECURE
Fastly-SIE
X-Request-URI
X-DefElseHash
Cf-Device-Type
X-Loc
Is-Eu
X-UnsetCookies
X-FC-Vary-Parameters
X-Has-Esi
Fastly-SWR
X-RateLimit-Remaining-Second
X-CGP
Ha-Gx-Prefs
HA-Ipaddr
L5d-Success-Class
NM-Fastcgi-Cache
X-Qloud-Router
X-Pod-Name
X-Amzn-Remapped-Content-Length
X-Response-By
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-Worker
X-Backend-State
X-Csrf-Jwt
X-Envoy-Decorator-Operation
X-Variation
X-Varnish-CookieINHashed-On
X-JWT-State
X-Eu-Site
X-Varnish-CookieHashed-On
Platform
Datacenter
X-Cache-Enabled
X-Mvc-Supplant-OutputCached
X-Tx-Id
X-Varnish-Beresp-Ttl
X-Up
X-NC
Candidate-Md5Url
X-Backend-TTL
X-CS
X-CLOUD-TRACE-CONTEXT
X-API-Version
CDN
X-Vc
X-GeoIP-Region-Code
X-GeoIP-Country-Code
Pics-Label
X-LB-ID
X-TraceId
WebServer
On-Server
Memory
Ms-Author-Via
X-Trace-ID
WWW-Authenticate
X-Tb-Optimization-Total-Bytes-Saved
Magicmarker
X-Generated-In
Time
X-Datadome
X-Tt-Logid
X-LB-NoCache
Esi-Enabled
X-Edge-Pop
X-DynaTrace-JS-Agent
S-Rt
X-Via-Popn
NtCoent-Length
X-Restarts
Kp-EeAlive
GeoIp-Country-Code
X-Via-Poph
Env
X-Via-Popv
X-Refresh
X-TA-CDN-Provider
X-Optimistic-Header
X-Dynatrace
X-Varnish-Ttl
C-Via
X-Service
X-Parent-Response-Time
X-Wix-Viewer-Type
X-RPS
X-Cache-PHP
X-Cache-Backend
X-RSL
Edge-Cache
X-Action
X-CacheTTL
X-DC
X-DB
X-DI
X-DW
X-DSS
X-RPM
X-Akamai-Request-ID2
X-Http-Reason
X-Varnish-Beresp-TTL
X-Servedbyhost
X-Cs
X-Esi
X-Srv
X-Minions-Version
X-MSEdge-Flight
Server-ID
X-MSEdge-Features
X-Unique-ID
X-TX-ID
X-Cache-Status-Check
X-Render-Time
X-ZONE
X-Newrelic-Synthetics
Accept-Language
X-HA-Backend
X-VCL-Version
Proxy-Connection
X-Info
X-AIR-PT
X-Cache-Ttl
X-LI-Proto
X-Fpc
X-Li-Proto
X-App
X-Urbn-Context-Path
X-URL
Locale
X-Urbn-Site-Id
X-Clientip
X-Ec-GeoHdr
X-FPC
Test
X-Webkit-Csp-Report-Only
X-Ec-Fail
X-User
X-Traceid
X-LiteSpeed-Cache-Control
UCS
Server-Id
X-Oss-Hash-Crc64ecma
X-Oss-Storage-Class
Cache-Host
HIT
X-B3-Spanid
X-Oss-Server-Time
X-Oss-Object-Type
X-Oss-Request-Id
X-Vcl-Version
X-NODE
X-Webkit-CSP-Report-Only
S-Cnection
Tcn
Geo-Info
Cdncip
X-CSRF-TOKEN
X-AK-Request-ID
M-TraceId
X-Pass-Why
Cdnsip
X-Ha-Backend
User-Agent
My-App
X-HostName
Fastly-Drupal-HTML
Fastly-Backend-Name
X-LiteSpeed-Tag
Cf-Int-Pingora-Origin-Digest
Resin-Trace
X-Micro-Cache
Hostname
X-Fmm-Version
Cluster
Geoip-Latitude
X-WADP-Cache
X-Clara-WADP
Section-Io-Id
Section-Origin-Responded
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
Lb
X-Backend-Host
X-ServedByHost
X-Var-Ttl
X-ID
Tracecode
X-Pad
X-CUA
X-Dynatrace-Js-Agent
X-COUNTRY
T-Server
Hit
X-BBC-Origin-Response-Status
X-Via-PopH
X-APP
X-Via-PopN
X-Via-PopV
GeoIP-Country-Code
Lfy
Ohc-File-Size
X-From
X-Release
X-NGINX-Cache
X-BCube-Filmed-By
X-Geo
ENV
X-ElasticPress-Query
MIME-Version
X-Cdn-Forward
X-RAMCache
X-Fragments
X-Check-Cacheable
Lang
X-Edge-POP
X-Edge-Cache
CPC-Cache
Cache-Key
X-WP-CF-Super-Cache-Cache-Control
CPC-Age
Target-Params
X-WP-CF-Super-Cache
EpKe-Alive
X-Amz-Meta-Cb-Modifiedtime
X-ES-SERVER
VNS-Age
X-HS-Status
Load-Balancing
Path
X-WA-Info
VNS-Cache
X-WA
X-Api-Version
X-Fastly-Backend-Reqs
X-Ucs
URI
X-ServerName
Servername
DataCenter
X-Wikidot-Static-Cache
X-UP
X-Cms-Context
Pagetype
X-Mcache
X-PJAX-URL
X-Lb-Id
X-Wikidot-Backend
X-GoCache-CacheStatus
Shield-Pop
X-Fastly-Cache-Hits
Cteonnt-Length
X-Dw-Trace-Id
X-TRACE-ID
Srv
X-Akamai-Pragma-Client-IP
Uri
FSS-Cache
X-Nc
PICS-Label
Permissions-Policy
X-Lb-Nocache
X-CCDN-Origin-Time
Cneonction
WZWS-RAY
Server-Ttl
X-Hcs-Proxy-Type
X-Via-Ucdn
X-CCDN-CacheTTL
X-B3-ParentSpanId
X-Swift-Error
Ohc-Cache-HIT
MD5-Digest
X-Cdn-Request-ID
Cdn
X-VC
X-Httpd
X-RateLimit-Reset
X-Proxy-Cache-Info
X-VG-WebServer
Producers
X-Akamai-ERRuleID
Server-Ext
Cf-Ipcountry
X-Acquia-Application-Trace
X-Snapshot-Date
X-Contensis-Viewer-Groups
X-Akamai-ERPolicy
X-Udemy-Cache-App-Namespace
X-Acquia-Purge-Tags
X-Acquia-Site
X-Acquia-Application-UUID
X-Apw-Hits
IsBot
Vha6-Origin
Server-Hostname
Sever-Int
X-Yottaa-OS
X-Cache-ASPX
X-Newrelic-App-Data
X-Apw-Access-Action
CF-Cached-On
ServerName
X-Apw-Access-Token
X-Apw-Access-Object
X-SIPLIST1
X-Cache-Ngx
X-Provided-By
Sid
X-Air-Pt
X-Last-Modified
X-SB
X-Sentry-ID
Req-ID
CountryCode
X-Logging-Id
X-UA
X-Miniprofiler-Ids
X-CacheKey
X-B3-Parentspanid
W
X-Http-Duration-Ms
X-Te-Count
X-Http-Count
X-Varnish-Authentication
X-Cache-Expires
Ngx
X-Te-Duration-Ms