Threat Level: green Handler on Duty: Jan Kopriva

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
Link
CF-Cache-Status
Accept-Ranges
CF-RAY
ETag
X-XSS-Protection
Expect-CT
Pragma
X-Powered-By
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-UA-Compatible
X-Cache-Hits
Alt-Svc
P3P
X-Served-By
X-Xss-Protection
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Request-Id
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Cache-Status
X-Generator
X-Cacheable
Timing-Allow-Origin
X-FRAME-OPTIONS
P3p
X-Content-Security-Policy
X-Iinfo
X-Request-ID
Status
Feature-Policy
X-Envoy-Upstream-Service-Time
Content-Encoding
Access-Control-Expose-Headers
X-CDN
X-Drupal-Dynamic-Cache
X-AspNetMvc-Version
Upgrade
X-Via
CF-Ray
X-Ws-Request-Id
Access-Control-Max-Age
Server-Timing
EagleId
Keep-Alive
X-Cache-Group
X-Turbo-Charged-By
Request-Context
X-Age
X-Server-Powered-By
X-Proxy-Cache
X-AH-Environment
X-UA-Device
X-Backend
X-Hacker
X-Robots-Tag
Report-To
X-Amz-Request-Id
Host-Header
X-Server
X-Dns-Prefetch-Control
X-LiteSpeed-Cache
X-Amz-Id-2
Grace
X-Rq
X-Nginx-Cache-Status
X-Varnish-Cache
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-WebKit-CSP
X-Page-Speed
X-Vhost
X-OneAgent-JS-Injection
EagleEye-TraceId
X-Amz-Version-Id
X-Pingback
X-Device
X-Dispatcher
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Cache-Spec
NEL
X-Server-Id
X-Host
X-Backend-Server
X-Node
Cf-Railgun
X-Readtime
Accept-CH
X-Akam-SW-Version
Surrogate-Control
Request-Id
X-Response-Time
X-HW
Xkey
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Accept-Ch-Lifetime
X-Ruxit-JS-Agent
X-Application-Context
Content-Location
Rating
X-Ua-Compatible
X-Country
X-B3-TraceId
X-Cache-Lookup
X-Language
X-Cloud-Trace-Context
X-Ac
X-Url
X-Content-Type
X-Template
X-Trace
Allow
X-TtlSet
X-Varnish-TTL
X-PC
X-Vname
Accept-CH-Lifetime
X-Mod-Pagespeed
X-Clacks-Overhead
Edge-Control
X-FastCGI-Cache
Cache-Tag
X-ESI
Fastly-Restarts
X-Server-Name
X-Rack-Cache
Service-Worker-Allowed
X-VARITI-CCR
X-Element-Page-Cache
Verso
X-Buckets
X-MS-InvokeApp
X-GitHub-Request-Id
X-Upstream
Accept-Ch
X-Amz-Rid
MS-Author-Via
X-Vcap-Request-Id
X-Dw-Request-Base-Id
Public-Key-Pins
X-Cached
X-Client-IP
X-D2id
X-Abt-Application-Version
X-Origin-Cache
X-Cache-TTL
Arr-Disable-Session-Affinity
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
X-Cnection
X-Px
X-Country-Code
Access-Control-Request-Method
X-Aws-Lambda-Call-Status
X-Navigation-Version
X-NF-Request-ID
X-Powered-By-Plesk
X-Instrumentation
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Goog-Hash
X-Version
RTSS
X-Powered-CMS
X-Amz-Server-Side-Encryption
Pagespeed
X-Middleton-Display
X-Sol
Display
X-Kinja-Server
X-Kinja-Revision
X-Use-Magma
X-Kinja-Build
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Exp-Id
X-Cdn-Fetch
X-Kinja
X-Exp-Variant
X-GoogleNews-Bot
Response
X-Middleton-Response
X-MSEdge-Ref
X-LLID
X-Edge-Location-Klb
X-Kinsta-Cache
X-Edge
AR-ATIME
AR-Request-ID
AR-SID
AR-PoweredBy
AR-CACHE
Nginx-Cache
X-TTL
Mrf-Cache-Status
MRF-Tech
X-Shield-Request-Id
X-B3-TraceId-Primal
X-HP-Webp
X-HP-Trace-Id
X-Jurisdiction
X-Protected-By
S
X-T
X-RateLimit-Remaining
Content-MD5
X-Forwarded-For
X-Aspnetmvc-Version
X-Content-Security-Policy-Report-Only
X-Mg-S
X-Id
X-CST
TCN
Fastcgi-Cache
X-Mid
Realpath
X-MCACHE
Edge-Cache-Tag
SPIisLatency
SPRequestDuration
Front-End-Https
X-Parallel-Accel
X-Recruiting
X-Request-Processing-Time
X-Request-Received
Filters
Pinterest-Generated-By
Pinterest-Version
X-Pinterest-Rid
Fusion-Content-Id
Fusion-Component-Id
Fusion-Source
Fusion-Template-Id
Fusion-Deployment-Id
Fusion-Content-Source
Server-Node
X-Ua-Browser
X-Content
X-Ab
SPRequestGuid
X-SharePointHealthScore
X-Correlation-Id
X-Ezoic-Cdn
X-ECACHE
X-Ttl
Server-Name
X-DynaTrace
X-NWS-LOG-UUID
Alternate-Protocol
X-HS-Hub-Id
X-Frontend
X-HS-Cache-Config
X-HS-Combine-CSS
X-HS-Content-Id
X-Hits
X-Yandex-Sdch-Disable
X-Accel-Expires
X-Content-Options
X-Tt-Trace-Tag
X-Cache-Key
X-Tt-Trace-Host
MicrosoftSharePointTeamServices
X-Ruxit-Js-Agent
X-Page-Id
Host
Cache-Tags
X-Git-Hash
Cleartype
X-Ser
X-B3-Sampled
X-Kong-Proxy-Latency
X-Www-Served-By
X-Kong-Upstream-Latency
Charset
X-Fastly-Request-Id
X-Amz-Replication-Status
X-Content-Digest
X-Geo-Country
X-Daa-Tunnel
TP-L2-Cache
TP-Cache
Filterid
X-Forwarded-Proto
X-Amzn-Trace-Id
X-DIS-Request-ID
X-VCache
X-Varnish-Age
X-XRDS-LOCATION
X-Az
X-Activity-Id
X-AppVersion
X-Rid
X-Origin-Server
X-N
X-Debug-Info
X-Hostname
X-Upgrade-Enabled
X-Grace
Access-Control-Allow-Method
X-FB-Debug
X-LB-Cache
X-Nginx-Upstream-Cache-Status
X-Origin-Upstream-Status
ServerID
X-Microsite
X-Mobile-URL
X-Request-Handler-Origin-Region
X-WebKit-CSP-Report-Only
X-Providence-Cookie
X-Is-Crawler
X-Request-Guid
X-Flags
X-Route-Name
X-Aspnet-Duration-Ms
X-Whom
X-Server-ID
X-F-Cache
Cross-Origin-Opener-Policy
X-NGENIX-Cache
X-TT
X-Varnish-Grace
X-Tb
X-App-Environment
X-App-Server
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Metageneration
X-Goog-Generation
Viewport
X-GUploader-UploadID
X-Goog-Storage-Class
X-FW-Static
X-FW-Serve
X-FW-Type
X-FW-Hash
X-FW-Dynamic
X-Distributor
X-FW-Server
Payment
Node
Paypal-Debug-Id
DC
X-Seen-By
X-Cache-Control
X-Type
X-Logged-In
Fastcgi-Useragent
X-User-Agent
X-Litespeed-Cache
X-Ratelimit-Limit
Accept-Charset
X-PressLabs-Stats
Country
X-Cache-Age
X-Webkit-CSP
X-Wix-Request-Id
X-Cache-Rule
X-Varnish-Backend
Version
X-Node-Name
X-Erf-Bev-Bev-Is-Generated
X-Load-Cache
X-Erf-Bev-Bev
X-Browser-Type
Refresh
X-TEC-API-ROOT
X-TEC-API-VERSION
X-Via-JSL
X-TEC-API-ORIGIN
X-Drupal-Cache-Tags
Referer-Policy
X-IPLB-Instance
X-Response-Served-From
X-Cache-Action
X-Fastly-Request-ID
SD-X-WS
X-Original-Request-Id
Access-Control-Request-Headers
X-Page-View
X-Real-IP
X-Proxy-Cache-Status
X-Jobs
X-Rendered-As
X-Is-Bot
X-Cluster-Name
X-Vgn-Hpd-Reason
X-Cacheable-TTL
Cache-Status
X-DataDome
NGB
X-Debug
X-Fastcgi-Cache
X-Cache-Expired-At
X-ProcessESI
X-B
X-RemovedCookies
Amp-Access-Control-Allow-Source-Origin
X-Mobile
X-Device-Type
X-Proxy
X-Rule
X-UUID
X-B-Cache
X-Signature
X-Revision
X-Contextid
X-Instance
Surrogate-Key
X-Cache-Time
VIX-Pulpo-Upstream-Status
X-G
VIX-Pulpo-Node
DynaTrace
X-Drupal-Cache-Contexts
X-Framework
Akamai-GRN
X-Debug-IsConnected
X-Debug-IsPreview
X-Yottaa-Metrics
X-Yottaa-Optimizations
CF-IPCountry
X-FW-Version
Liferay-Portal
X-Air-Trace-Id
X-Air-Hostname
X-Air-Source
SID
Healthy
X-Oracle-Dms-Ecid
X-Azure-Ref
X-Oracle-Dms-Rid
X-Tec-Api-Version
X-Tec-Api-Root
X-Tec-Api-Origin
X-Source
X-Ms-Request-Id
X-Ms-Version
X-Oneagent-Js-Injection
X-CDN-Forward
Ms-Operation-Id
MS-CV
X-Nginx-Cache
X-RTag
Frame-Options
X-Cache-Hit
Count-Hit
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Tumblr-User
X-Tumblr-Pixel-1
Countrycode
X-XRDS-Location
X-Environment-Context
X-Varnish-Server
Xserver
X-L-Path
X-Cache-Operation
Uber-Trace-Id
X-Region
Section-Io-Cache
X-EdgeConnect-Cache-Status
X-Accel-Buffering
X-Servername
X-APP-VERSION
X-Ratelimit-Reset
X-Content-Powered-By
X-Forwarded-Host
X-Backend-Name
X-Mode
GEO-INFO
Cross-Origin-Window-Policy
Ec-Rule-Version
X-Zen-Fury
Backend
X-SaId
X-IPS-LoggedIn
Meta-Geo
X-RN-RSRV
X-UPSTREAM-Address
X-Detected-As
X-JoinUs
X-Alternate-Cache-Key
X-Shopify-Stage
X-Sorting-Hat-PodId
X-Tid
X-Debug-Cache
X-Adobe-Content
X-Varnish-Beresp-Grace
X-Uri
X-Cache-Server
X-Redis-Cache
X-Hosted-By
Eomportal-Instance
X-ShardId
X-Sorting-Hat-ShopId
X-Adobe-Loc
X-Human
X-Generation-Time
X-Sql-Count
X-ShopId
Country-Code
X-Cache-Grace
X-Sql-Duration-Ms
Apigw-Requestid
X-No-Session
Cache-Tv-Group
Mn-Server-Ip
Decoy-Debug-TTL
Decoy-Debug-Status
Decoy-Debug-Key
DB-Nickname
X-Origin-Date
X-UA-Device-Type
Cache-Name
X-Via-Fastly
X-Site-Version
X-PHP-Backend
X-Status
X-Cache-TTL-Remaining
X-RateLimit-Limit
X-FB-TRIP-ID
X-NCache
Url
X-ServerID
X-Rewrite-Enabled
Webcakes-App-Version
Webcakes-Region
X-BYPASS-REASON
X-Cache-Host
X-Proxy-Build
X-ProxyCache-Key
X-ProxyCache-Status
X-Akamai-Edgescape
X-Microcachable
Protected
X-Web-Node
Selected-Fe
TWC-Connection-Speed
X-Timing-Wait
TWC-Device-Class
TWC-GeoIP-LatLong
X-Storage
Fastly-SSL
TWC-GeoIP-Country
TWC-Locale-Group
X-Origin-Hint
Property-Id
TWC-Privacy
Webcakes-App-Name
X-Cache-NGX
X-PERF
X-R9-Blue-Green-Version
X-Say-Cacheable
X-PCL
X-NYM-Debug-Backend
X-Format
X-Hl-Ver
X-Cache-Type
X-OCL
X-Say-TTL
X-Server-W
X-Zipkin-Id
X-ApacheServer
X-SayCDN-TTL
X-Routing-Service
X-Varnishpool
X-Proxied
X-Extlb
X-Cluster-Node
X-Be
X-Access
X-Pubstack
Content-Secure-Policy
X-Soup
OT-Force-Account-Verify
X-LSADC-Cache
X-Azure-Ref-OriginShield
X-Section
Azure-InstanceId
Azure-RegionName
Azure-SiteName
Azure-SlotName
Azure-Version
X-Ua
X-Content-Age
Source
X-Webkit-Csp
X-Presslabs-Stats
X-Time
X-App-Version
CDN-CachedAt
CDN-Uid
X-Cached-By
Content-Disposition
SRV
CDN-EdgeStorageId
CDN-Cache
CDN-PullZone
CDN-RequestCountryCode
CDN-RequestId
X-NewRelic-App-Data
Cache
X-HTML-Minification-Powered-By
X-Generated-By
X-TT-LOGID
X-Hyper-Cache
X-SRV
X-Dc
X-Cache-Var
X-Cache-Var-Map
X-LAGOON
X-Amz-Meta-S3cmd-Attrs
X-TNCMS
X-Bc-Bl
X-Unique-Id
X-Nginx-Cache-Key
X-Varnish-Hostname
X-Loop
X-Varnish-Hits
Onion-Location
X-Auto-Login
X-S-Maxage
X-Trace-Id
Cache-Hits
Xet-Cookie
Retry-After
X-Origin-CC
LB
X-Origin-TTL
X-GEO
X-Tumblr-Pixel-3
X-Tumblr-Pixel-2
Web-Mar-Node
X-Cdn
X-Proto
Webserver
Mime-Version
X-Platform-Server
X-M-Reqid
X-Akamai-Transformed
X-Tenant
X-Qnm-Cache
HostName
X-Time-Microsecs
X-CSRF-Token
X-Endurance-Cache-Level
X-M-Log
X-Edge-Location
WPO-Cache-Message
WPO-Cache-Status
X-VWS-Id
X-GG-Cache-Date
X-LJ-Flow-ID
X-AWS-Id
CloudFront-Viewer-Country
X-B3-SpanId
X-Cache-Remote
X-Xfnlog-Site
N-Cache
X-Ratelimit-Remaining
X-CACHE-KEY
X-ECache
X-Mg-Request-UUID
X-Cache-Tags
X-TIME
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Labrador-Cache-Channel
X-PHP-Host
ServedBy
Upgrade-Insecure-Requests
X-Varnish-Cache-Hits
Nel
X-Request-Time
X-RCS-CacheZone
X-Correlation-ID
X-Via-NSCOPI
X-Handled-By
X-AOL-HN
X-Origin-Response-Time
X-Locale
X-SD-PageType
X-Destination
X-D
X-Developer
X-ScT
A
X-Vtex-Remote-Cache
X-A-Dcw
User-Cache-Control
X-S-Cookie
X-External-Request-Id
X-A-Dgt
X-A-Wwc
X-A-Ccd
X-Aed
Xc-Version
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-Cache-NE
X-Cache-Date
X-B-Cookie
X-Block-Status
X-Application
X-Ckpd-Fst-Backend
X-SVT-ORM-RULES
X-ARC
X-Shop-Environment
X-Session-Fingerprint
X-A
X-Slack-Backend
X-Connection-Hash
X-Cluster
X-SRCache-Key
X-Conf
X-SVT-ORM-VERSION
X-S
Meta-Geo-Continent
X-NAPM-TraceId
DSUID
X-ND-Cache
Mobile-Detection-Method
Odigeo-Trace-Id
X-Processor
X-Vtex-Processado-Em
X-Ig-Push-State
Origin
Fastcgi-X-Cache-Version
X-Planisys-CDN-TTL
X-Vdms-Version
X-PAYTM-SRV-ID
X-PBS-Appsvrname
X-Planisys-CDN-Cache
Expiry
X-Planisys-CDN-Rules
X-Orig-Expires
DCR-Decision-By
DCR-Processing-Time-Ms
X-Vdms-Path
X-Hnp-Log
X-Storefront-Renderer-Rendered
X-Gen-Mode
Surrogated-Key
X-A-Dam
X-Forwarded-Path
Rendered-Blocks
X-Rojux
X-Ftr-Request-Id
X-Request-Host
X-VG-WebCache
Redirect-Candidate
X-V-Cache
Pramga
BehaviorPad-Version
X-TIM-N
AMP-Access-Control-Allow-Source-Origin
X-VC-Cache
X-MP-GENERATED-AT
Traceparent
State
V-Age
Gh-Request-Id
Wxu-Next-Hostname
Wxu-Next-Region
Origin-CC
Host-ID
Release
Origin-EX
Wxu-Next-Commit
Fastcgi-Cache-TTL
X-Epic-Correlation-Id
X-Li-Pop
X-LI-UUID
X-Location
X-Li-Fabric
X-Sucuri-ID
X-Proxy-Upstream
X-Varnish-Beresp-Status
X-Men
X-Mvc-Supplant-Cachable
X-Origin-Time
X-Owner
X-Origin-Expires
X-Old-Content-Length
X-Policy
X-Nyt-Route
X-Hash
X-Geo-Header
X-Core-Mission
X-Date
X-Served-From
X-Server-IP
X-Sucuri-Cache
X-Skip-Cache
X-Device-Os
X-Webstats-RespID
X-Forwarded-Site
X-Gdpr
X-Fetched-On
X-VServer
X-Scheme
X-Fastly-Cache
X-Cache-Bucket
X-Accel-Expires-Debug
X-Reqid
X-ATG-Version
X-Adobe-Source
Arc-Country
Cmsid
CDCHOST
CacheControlHeader
Server-Info
Cmstype
AKAMAI
From-Origin
Environment
X-FireWall-Port
X-Datadog-Parent-Id
X-Cdn-Srv
X-Core-Value
True-Client-Country-4JS
X-Datadog-Trace-Id
Thinkindot-CacheControl-Type
X-Developers
Thinkindot-Control
X-Cdn-Origin
X-Datadog-Sampling-Priority
X-Cache-Id
X-Branch-Name
X-Bip
We-Hiring
X-Esi-Check
X-Cache-Config
Web-Mar-Region
X-Cache-Debug
Vix-Hermes-Req-Id
X-Cache-Info
X-Generated-On
X-Sn-Servicetimems
X-TH-Server
X-Rocket-Nginx-Serving-Static
X-Request-Start
X-Req
X-Thanos
X-Thinkindot-L3
Sslversion
X-Aicache-OS
X-VarnishDD-TTL
X-TrackingId
X-Region-Sid
X-Magnolia-Registration
X-GeoIP-City
X-Gzip
X-GeoIP
Thinkindot-CacheControl
X-Gamma-Serve
X-HN
X-HS-Content-Campaign-Id
X-NodeID
X-Node-Id
X-Level-Front-Cache
X-Irp-Debug
X-Fastly-Backend
X-Platform
Server-Host
Machine
L
PFcat
Locid
Svr
TDXMobile
Mail-Subject
X-CS
X-Xrds-Location
X-EC-Lua
X-Qloud-Router
X-Csrf-Jwt
X-Datadome
Is-Eu
X-Pod-Name
X-RateLimit-Limit-Second
X-CGP
X-Rocket-Build-Number
Ha-Gx-Prefs
X-Sigma
X-Response-By
HA-Ipaddr
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-RateLimit-Remaining-Second
X-NU-AKA-ACS-Version
NGX
NM-Fastcgi-Cache
X-FC-Vary-Parameters
Cf-Device-Type
Memcached
X-Is-Gdpr
X-JWT-State
X-Has-Esi
X-Zone
X-Eu-Site
Apple-News-Services-Request-Url
X-DefHash
X-DefElseHash
Candidate-Md5Url
L5d-Success-Class
X-Envoy-Decorator-Operation
X-DPWN-IS-SECURE
X-Origin
Platform
X-Variation
X-Varnish-CookieHashed-On
X-Worker
X-Viewer-Country
X-UnsetCookies
Fastly-Drupal-Html
Ssr
X-Varnish-Remaining-TTL
Adler-Geo
X-Amzn-Remapped-Content-Length
Apple-News-Services-Parsed-Url
X-Varnish-CookieINHashed-On
X-VG-TLSProxy
X-Backend-State
X-Sigma-Backend
X-BBC-Edge-Cache-Status
Apple-News-Services-Handled
WP-Super-Cache
Req-Svc-Chain
Fastly-SIE
Fastly-SWR
Datacenter
Apple-News-Services-Host
Fastly-GeoIP-CountryCode
X-Ua-Device
X-Mvc-Supplant-OutputCached
X-Loc
X-CLOUD-TRACE-CONTEXT
X-Request-URI
X-Tx-Id
X-Dynatrace
Pics-Label
X-NC
On-Server
WWW-Authenticate
X-Varnish-Beresp-Ttl
X-Up
X-LB-ID
X-API-Version
X-Cache-Enabled
CDN
X-Generated-In
X-Backend-TTL
X-Vc
X-Trace-ID
X-NWS-UUID-VERIFY
Ms-Author-Via
Esi-Enabled
Memory
Time
X-Refresh
X-DynaTrace-JS-Agent
NtCoent-Length
X-LB-NoCache
Magicmarker
X-Via-Popv
X-TraceId
X-Tb-Optimization-Total-Bytes-Saved
X-Service
C-Via
X-Via-Poph
X-Via-Popn
X-GeoIP-Country-Code
X-Edge-Pop
X-GeoIP-Region-Code
X-TA-CDN-Provider
GeoIp-Country-Code
X-Cache-PHP
X-Parent-Response-Time
X-Tt-Logid
X-CacheTTL
X-Restarts
X-DC
X-Optimistic-Header
WebServer
Env
S-Rt
X-Varnish-Beresp-TTL
X-Render-Time
X-Esi
Kp-EeAlive
X-Cache-Status-Check
X-Srv
X-DW
X-DI
X-TX-ID
X-Action
X-Servedbyhost
X-RPM
X-Wix-Viewer-Type
X-DSS
Edge-Cache
X-Cache-Backend
X-RPS
X-Unique-ID
X-RSL
X-DB
X-ZONE
X-Info
Server-ID
X-MSEdge-Flight
X-MSEdge-Features
Tcn
X-Cs
X-Minions-Version
X-AIR-PT
X-Http-Reason
X-Akamai-Request-ID2
X-Clientip
X-VCL-Version
X-Newrelic-Synthetics
X-HA-Backend
X-App
X-Cache-Ttl
Proxy-Connection
X-Li-Proto
X-URL
Geo-Info
Cache-Host
HIT
Test
X-Oss-Object-Type
X-Oss-Server-Time
X-Oss-Storage-Class
X-Oss-Hash-Crc64ecma
X-Webkit-Csp-Report-Only
X-FPC
UCS
X-Varnish-Ttl
X-Oss-Request-Id
X-LI-Proto
X-Fpc
X-Traceid
Accept-Language
S-Cnection
X-Vcl-Version
X-HostName
X-Webkit-CSP-Report-Only
X-NODE
X-LiteSpeed-Cache-Control
Server-Id
X-Ec-GeoHdr
X-User
X-Ec-Fail
X-Urbn-Site-Id
Locale
X-Urbn-Context-Path
X-B3-Spanid
Section-Io-Id
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
Lb
X-Pass-Why
Fastly-Backend-Name
User-Agent
X-Micro-Cache
Cf-Int-Pingora-Origin-Digest
X-LiteSpeed-Tag
X-Pad
Fastly-Drupal-HTML
X-Backend-Host
X-CSRF-TOKEN
Resin-Trace
Cdncip
Cdnsip
X-AK-Request-ID
M-TraceId
X-ServedByHost
X-ID
X-Ha-Backend
X-BBC-Origin-Response-Status
X-Release
X-BCube-Filmed-By
X-APP
Hostname
X-WADP-Cache
Cluster
GeoIP-Country-Code
Geoip-Latitude
My-App
ENV
X-Fmm-Version
Hit
Ohc-File-Size
X-Check-Cacheable
X-Clara-WADP
X-Geo
X-Dynatrace-Js-Agent
X-ES-SERVER
X-CUA
X-Var-Ttl
X-ElasticPress-Query
X-Via-PopV
X-Via-PopH
X-Edge-POP
X-Via-PopN
VNS-Age
VNS-Cache
Tracecode
EpKe-Alive
Path
Cache-Key
MIME-Version
X-Amz-Meta-Cb-Modifiedtime
CPC-Age
CPC-Cache
X-WA-Info
X-WA
Load-Balancing
Lfy
X-From
X-HS-Status
X-Api-Version
T-Server
X-Edge-Cache
X-NGINX-Cache
Srv
X-Akamai-Pragma-Client-IP
URI
X-PJAX-URL
X-Fragments
X-Wikidot-Backend
Lang
X-Cdn-Forward
X-ServerName
X-Cms-Context
X-Ucs
Pagetype
X-Wikidot-Static-Cache
Shield-Pop
X-Fastly-Backend-Reqs
X-Hcs-Proxy-Type
X-Fastly-Cache-Hits
X-WP-CF-Super-Cache
X-CCDN-Origin-Time
X-WP-CF-Super-Cache-Cache-Control
X-GoCache-CacheStatus
X-Mcache
X-RAMCache
X-CCDN-CacheTTL
MD5-Digest
X-Via-Ucdn
X-UP
Target-Params
Servername
X-TRACE-ID
X-Dw-Trace-Id
X-Lb-Id
WZWS-RAY
IsBot
X-Cdn-Request-ID
Cdn
Uri
X-VC
Server-Hostname
Sever-Int
Cneonction
X-Nc
DataCenter
X-VG-WebServer
X-SIPLIST1
Server-Ext
X-B3-ParentSpanId
Ohc-Cache-HIT
X-RateLimit-Reset
PICS-Label
X-Snapshot-Date
X-Acquia-Site
X-Newrelic-App-Data
X-Contensis-Viewer-Groups
W
X-Acquia-Purge-Tags
X-Swift-Error
X-Apw-Access-Object
X-Apw-Access-Action
X-Apw-Access-Token
X-Apw-Hits
X-Acquia-Application-Trace
X-Acquia-Application-UUID
X-Cache-ASPX
Cteonnt-Length
Cf-Ipcountry
X-Cache-Expires
CF-Cached-On
X-Yottaa-OS
Vha6-Origin
X-Air-Pt
Sid
X-Cache-Ngx
X-Miniprofiler-Ids
X-UA
X-Lb-Nocache
X-Te-Count
X-Te-Duration-Ms
X-Platform-Cluster
X-Akamai-ERPolicy
Permissions-Policy
X-Httpd
X-Proxy-Cache-Info
FSS-Cache
X-Last-Modified
X-Http-Duration-Ms
X-Akamai-ERRuleID
Server-Ttl
HitType
Dnion-Transfer-Encoding
X-B3-Parentspanid
X-Sentry-ID
X-Provided-By
Ngx
X-Akamai-Request-ID
CountryCode
X-Varnish-Authentication
X-CacheKey
X-Platform-Router
X-Platform-Processor
Req-ID
X-Logging-Id
X-Http-Count