Threat Level: green Handler on Duty: Johannes Ullrich

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-Cache-Status
Link
Accept-Ranges
CF-RAY
ETag
X-XSS-Protection
Expect-CT
Pragma
X-Powered-By
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
P3P
Alt-Svc
X-Served-By
X-Xss-Protection
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Cache-Status
X-Generator
X-Cacheable
Timing-Allow-Origin
X-Content-Security-Policy
X-Iinfo
Feature-Policy
Status
X-Envoy-Upstream-Service-Time
Content-Encoding
Access-Control-Expose-Headers
P3p
X-Drupal-Dynamic-Cache
X-CDN
X-AspNetMvc-Version
Upgrade
X-Via
CF-Ray
X-Ws-Request-Id
Access-Control-Max-Age
X-Request-ID
Server-Timing
EagleId
X-Cache-Group
Keep-Alive
X-Turbo-Charged-By
Request-Context
X-Age
X-UA-Device
X-Server-Powered-By
X-Proxy-Cache
X-AH-Environment
X-Backend
X-Robots-Tag
X-Hacker
Report-To
X-Amz-Request-Id
X-Server
Host-Header
X-Amz-Id-2
Grace
X-LiteSpeed-Cache
X-Rq
X-Nginx-Cache-Status
X-Varnish-Cache
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-WebKit-CSP
X-Page-Speed
X-Vhost
X-Ua-Compatible
EagleEye-TraceId
X-OneAgent-JS-Injection
X-Amz-Version-Id
X-Dns-Prefetch-Control
X-Pingback
X-Dispatcher
X-Device
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
NEL
X-Cache-Spec
X-Host
X-Server-Id
Cf-Railgun
Accept-CH
X-Node
X-Backend-Server
X-Readtime
Surrogate-Control
X-Akam-SW-Version
Request-Id
X-Response-Time
X-HW
Xkey
X-Application-Context
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Ruxit-JS-Agent
Content-Location
Rating
X-Country
Accept-CH-Lifetime
X-B3-TraceId
X-Cloud-Trace-Context
Accept-Ch-Lifetime
X-Cache-Lookup
X-Trace
X-Ac
X-Url
X-Content-Type
X-TtlSet
X-Vname
X-PC
Allow
X-Varnish-TTL
X-Clacks-Overhead
X-Mod-Pagespeed
Edge-Control
X-FastCGI-Cache
X-Server-Name
Fastly-Restarts
Cache-Tag
X-ESI
Service-Worker-Allowed
X-Rack-Cache
X-VARITI-CCR
Verso
X-Element-Page-Cache
X-Aws-Lambda-Call-Status
X-Upstream
MS-Author-Via
X-GitHub-Request-Id
X-MS-InvokeApp
X-Amz-Rid
X-Vcap-Request-Id
Public-Key-Pins
X-Cached
X-Dw-Request-Base-Id
X-Client-IP
X-D2id
X-Abt-Application-Version
X-Cache-TTL
X-Cnection
X-Px
Arr-Disable-Session-Affinity
X-Country-Code
RTSS
X-Navigation-Version
X-Origin-Cache
X-Goog-Hash
Access-Control-Request-Method
X-Powered-By-Plesk
X-NF-Request-ID
X-Kinja-Server
X-Kinja-Build
X-Kinja
X-Kraken-Loop-Name
X-Exp-Id
X-Exp-Variant
X-GoogleNews-Bot
X-Cdn-Fetch
X-Instrumentation
X-Server-Lifecycle-Phase
X-Kinja-Revision
X-Use-Magma
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
AR-PoweredBy
AR-Request-ID
AR-SID
AR-CACHE
X-Powered-CMS
AR-ATIME
X-Version
X-Middleton-Display
Pagespeed
X-Sol
Display
X-Middleton-Response
Response
X-Amz-Server-Side-Encryption
X-MSEdge-Ref
X-LLID
Accept-Ch
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Edge-Location-Klb
X-Kinsta-Cache
X-Edge
Nginx-Cache
X-RateLimit-Remaining
MRF-Tech
X-B3-TraceId-Primal
TCN
Mrf-Cache-Status
X-Protected-By
X-TTL
X-HP-Webp
X-Jurisdiction
X-HP-Trace-Id
X-Shield-Request-Id
X-T
X-Forwarded-For
X-Content-Security-Policy-Report-Only
X-Aspnetmvc-Version
S
X-Mg-S
X-Id
Content-MD5
Edge-Cache-Tag
X-Mid
Fastcgi-Cache
Realpath
X-Language
SPIisLatency
SPRequestDuration
Front-End-Https
X-Ttl
X-Recruiting
X-Request-Processing-Time
X-Request-Received
Filters
X-MCACHE
X-CST
X-Pinterest-Rid
Pinterest-Generated-By
Pinterest-Version
X-DynaTrace
Server-Node
X-Ab
X-Content
X-Ua-Browser
X-Frontend
Server-Name
X-Correlation-Id
X-HS-Hub-Id
X-ECACHE
X-HS-Content-Id
X-HS-Cache-Config
X-NWS-LOG-UUID
X-HS-Combine-CSS
X-Yandex-Sdch-Disable
X-SharePointHealthScore
SPRequestGuid
X-Ezoic-Cdn
X-Ser
X-Cache-Key
Fusion-Content-Id
Fusion-Component-Id
X-Hits
Fusion-Source
Fusion-Template-Id
Fusion-Deployment-Id
Fusion-Content-Source
X-Parallel-Accel
X-Template
Alternate-Protocol
X-Tt-Trace-Host
X-Tt-Trace-Tag
Cache-Tags
X-Content-Options
MicrosoftSharePointTeamServices
X-Ruxit-Js-Agent
Charset
X-Kong-Upstream-Latency
X-B3-Sampled
X-Kong-Proxy-Latency
Cleartype
X-Git-Hash
X-Page-Id
Host
X-Www-Served-By
X-DIS-Request-ID
X-Geo-Country
X-Debug-Info
X-Amzn-Trace-Id
X-Amz-Replication-Status
X-Hostname
X-Content-Digest
X-Daa-Tunnel
Filterid
X-Accel-Expires
X-Varnish-Age
X-Fastly-Request-Id
X-AppVersion
X-FB-Debug
X-Activity-Id
X-Az
X-VCache
Cross-Origin-Opener-Policy
X-Upgrade-Enabled
TP-L2-Cache
TP-Cache
X-Forwarded-Proto
X-Rid
X-N
X-Nginx-Upstream-Cache-Status
X-Grace
X-Origin-Server
Access-Control-Allow-Method
X-F-Cache
X-Mobile-URL
X-WebKit-CSP-Report-Only
ServerID
X-LB-Cache
X-Providence-Cookie
X-Flags
X-Aspnet-Duration-Ms
X-Is-Crawler
X-Request-Guid
X-Route-Name
X-Server-ID
X-Whom
X-Ratelimit-Limit
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Generation
X-TT
X-GUploader-UploadID
X-Goog-Metageneration
X-Goog-Storage-Class
X-XRDS-LOCATION
X-Varnish-Grace
X-Tb
Viewport
X-App-Environment
X-Seen-By
X-Type
X-FW-Server
X-FW-Type
X-Distributor
Node
X-FW-Hash
X-FW-Dynamic
X-FW-Static
X-FW-Serve
Paypal-Debug-Id
Payment
DC
X-App-Server
X-User-Agent
X-Origin-Upstream-Status
Fastcgi-Useragent
Country
X-NGENIX-Cache
Accept-Charset
X-Cache-Control
X-Wix-Request-Id
X-Litespeed-Cache
X-Cache-Rule
X-Webkit-CSP
X-Fastly-Request-ID
X-Logged-In
Version
X-DataDome
X-Cache-Age
X-Request-Handler-Origin-Region
X-Via-JSL
X-Microsite
Referer-Policy
X-Drupal-Cache-Tags
Amp-Access-Control-Allow-Source-Origin
X-Browser-Type
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Oracle-Dms-Ecid
X-Oracle-Dms-Rid
X-Varnish-Backend
X-Signature
X-Contextid
X-Cluster-Name
X-Load-Cache
X-B-Cache
Refresh
Cache-Status
X-Response-Served-From
X-Buckets
VIX-Pulpo-Upstream-Status
Access-Control-Request-Headers
SD-X-WS
VIX-Pulpo-Node
X-Mobile
X-Original-Request-Id
X-Node-Name
X-Vgn-Hpd-Reason
X-Proxy-Cache-Status
X-Page-View
X-Ratelimit-Reset
X-Is-Bot
X-Jobs
X-Cacheable-TTL
X-Rendered-As
X-Cache-Expired-At
X-Yottaa-Metrics
X-Fastcgi-Cache
X-Cache-Action
X-B
X-Yottaa-Optimizations
X-Revision
X-RemovedCookies
X-Real-IP
X-Debug
X-UUID
NGB
X-ProcessESI
X-IPLB-Instance
X-Proxy
X-Instance
Akamai-GRN
X-Drupal-Cache-Contexts
X-Tec-Api-Origin
X-G
X-Tec-Api-Root
X-Tec-Api-Version
X-Cache-Time
X-Rule
Surrogate-Key
X-Device-Type
X-Framework
X-TEC-API-ORIGIN
X-Debug-IsConnected
X-Debug-IsPreview
X-TEC-API-ROOT
X-TEC-API-VERSION
X-Air-Trace-Id
X-Air-Source
X-FW-Version
CF-IPCountry
X-Air-Hostname
SID
X-XRDS-Location
DynaTrace
X-Presslabs-Stats
GEO-INFO
X-Azure-Ref
Liferay-Portal
X-Oneagent-Js-Injection
X-Nginx-Cache
Count-Hit
X-APP-VERSION
X-Ms-Version
X-Ms-Request-Id
X-Accel-Buffering
X-Cache-Operation
X-PressLabs-Stats
Healthy
X-Source
Frame-Options
Uber-Trace-Id
X-CDN-Forward
MS-CV
X-EdgeConnect-Cache-Status
Ms-Operation-Id
X-RTag
X-RateLimit-Limit
X-Cache-NGX
X-Tumblr-Pixel-0
X-L-Path
Xserver
X-Tumblr-User
X-Environment-Context
X-Zen-Fury
X-Tumblr-Pixel-1
X-Tumblr-Pixel
X-Cache-Hit
X-Varnish-Server
X-Mode
Countrycode
Cross-Origin-Window-Policy
Ec-Rule-Version
X-IPS-LoggedIn
X-Region
X-Forwarded-Host
Protected
X-Servername
X-Backend-Name
Backend
X-Cache-TTL-Remaining
X-Rewrite-Enabled
X-JoinUs
X-RN-RSRV
X-UPSTREAM-Address
X-Detected-As
X-Cache-Type
X-Tid
Meta-Geo
X-Content-Powered-By
X-SaId
X-Debug-Cache
Apigw-Requestid
X-Cache-Server
X-Sql-Count
X-Alternate-Cache-Key
X-Extlb
X-Hosted-By
Section-Io-Cache
X-Generation-Time
X-Human
X-Routing-Service
Decoy-Debug-Key
X-Varnish-Beresp-Grace
X-Sorting-Hat-ShopId
X-Proxied
X-Uri
X-Redis-Cache
Eomportal-Instance
Decoy-Debug-TTL
Country-Code
X-Sorting-Hat-PodId
Decoy-Debug-Status
X-Zipkin-Id
X-ShardId
X-Sql-Duration-Ms
X-ShopId
X-Cache-Grace
X-Shopify-Stage
X-Content-Age
Cache-Tv-Group
Url
X-Origin-Date
Cache-Name
X-Soup
X-PHP-Backend
X-PERF
X-No-Session
X-ApacheServer
X-Storage
X-NCache
X-UA-Device-Type
X-Microcachable
X-Via-Fastly
X-TIME
X-Site-Version
X-Format
Mn-Server-Ip
X-Status
X-FB-TRIP-ID
Fastly-SSL
Property-Id
Selected-Fe
TWC-Privacy
TWC-Locale-Group
TWC-GeoIP-LatLong
TWC-Connection-Speed
TWC-Device-Class
TWC-GeoIP-Country
X-SayCDN-TTL
X-ProxyCache-Status
X-Timing-Wait
X-Pubstack
X-Web-Node
X-ProxyCache-Key
X-NYM-Debug-Backend
X-Proxy-Build
X-PCL
X-Origin-Hint
X-OCL
X-Server-W
X-Section
X-Adobe-Loc
X-Adobe-Content
X-Access
Webcakes-Region
X-Akamai-Edgescape
X-BYPASS-REASON
X-Say-TTL
X-Say-Cacheable
X-Cluster-Node
X-Cache-Host
Webcakes-App-Version
Webcakes-App-Name
X-Hyper-Cache
Azure-SiteName
OT-Force-Account-Verify
Azure-InstanceId
X-R9-Blue-Green-Version
DB-Nickname
Azure-SlotName
Azure-RegionName
X-Varnishpool
Azure-Version
LB
CDN-RequestId
CDN-RequestCountryCode
Content-Secure-Policy
CDN-PullZone
CDN-Uid
CDN-EdgeStorageId
WPO-Cache-Message
CDN-Cache
CDN-CachedAt
X-NewRelic-App-Data
WPO-Cache-Status
X-ServerID
X-Be
X-LSADC-Cache
X-Ua
Content-Disposition
X-Webkit-Csp
X-Generated-By
X-Azure-Ref-OriginShield
X-Hl-Ver
SRV
X-Cached-By
Source
Cache
X-Nginx-Cache-Key
X-SRV
X-Trace-Id
X-Ratelimit-Remaining
X-Bc-Bl
X-Unique-Id
X-LAGOON
Retry-After
X-Auto-Login
Cache-Hits
X-Dc
X-Origin-CC
X-GEO
Xet-Cookie
X-Origin-TTL
Mime-Version
X-Cache-Remote
X-Platform-Server
X-TT-LOGID
X-Varnish-Hits
X-HTML-Minification-Powered-By
X-TNCMS
X-Varnish-Hostname
X-Loop
X-Cdn
X-Akamai-Transformed
X-App-Version
X-Xfnlog-Site
Onion-Location
X-S-Maxage
ServedBy
Upgrade-Insecure-Requests
Web-Mar-Node
X-Tumblr-Pixel-2
X-Tumblr-Pixel-3
X-Varnish-Cache-Hits
X-Cache-Tags
X-Amz-Meta-S3cmd-Attrs
HostName
X-Request-Time
X-CSRF-Token
Webserver
X-Cache-Var-Map
X-AOL-HN
X-Cache-Var
X-Tenant
X-EC-Lua
X-FireWall-Port
X-Proto
X-Time-Microsecs
X-Endurance-Cache-Level
N-Cache
X-ECache
WP-Super-Cache
From-Origin
X-Request-Host
X-AWS-Id
X-VWS-Id
X-Edge-Location
X-LJ-Flow-ID
X-Time
X-GG-Cache-Date
X-Origin-Response-Time
Nel
X-Correlation-ID
CloudFront-Viewer-Country
X-B3-SpanId
X-Cache-Enabled
X-Mg-Request-UUID
X-Via-NSCOPI
Pramga
Mobile-Detection-Method
X-Shop-Environment
Odigeo-Trace-Id
X-Session-Fingerprint
Origin
X-ScT
X-Rojux
Sslversion
Surrogated-Key
Rendered-Blocks
Redirect-Candidate
Meta-Geo-Continent
X-S-Cookie
X-S
X-SD-PageType
X-SVT-ORM-RULES
X-Vdms-Path
X-V-Cache
A
X-Vdms-Version
X-VG-WebCache
Xc-Version
X-Vtex-Remote-Cache
X-Vtex-Processado-Em
X-TIM-N
BehaviorPad-Version
X-SVT-ORM-VERSION
Fastcgi-X-Cache-Version
X-SRCache-Key
Expiry
DSUID
DCR-Decision-By
DCR-Processing-Time-Ms
X-Slack-Backend
X-Processor
X-Cache-Date
X-Ftr-Request-Id
X-Cache-NE
X-Gen-Mode
X-B-Cookie
X-Aicache-OS
X-Application
X-ARC
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-Connection-Hash
X-D
X-Developer
X-Conf
X-Cluster
X-Forwarded-Path
X-External-Request-Id
X-Ckpd-Fst-Backend
X-Hnp-Log
X-Aed
X-A
X-Planisys-CDN-Cache
X-PBS-Appsvrname
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
V-Age
X-Destination
Vix-Hermes-Req-Id
X-A-Ccd
X-A-Dam
X-ND-Cache
X-NAPM-TraceId
X-Ig-Push-State
X-Orig-Expires
X-A-Wwc
X-A-Dcw
X-A-Dgt
X-PAYTM-SRV-ID
User-Cache-Control
X-Block-Status
X-PHP-Host
X-Labrador-Cache-Channel
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Qnm-Cache
X-Handled-By
X-M-Log
X-M-Reqid
X-Date
X-Core-Mission
X-Cdn-Srv
X-Cache-Info
X-Fetched-On
X-Forwarded-Site
X-Device-Os
X-Fastly-Cache
X-Epic-Correlation-Id
X-NWS-UUID-VERIFY
X-Accel-Expires-Debug
Ssr
State
Release
Origin-EX
L
Origin-CC
Svr
Traceparent
Wxu-Next-Region
X-Gdpr
Wxu-Next-Hostname
Wxu-Next-Commit
True-Client-Country-4JS
X-Cache-Bucket
X-Li-Pop
X-Served-From
X-Server-IP
X-Scheme
X-Rocket-Nginx-Serving-Static
X-Request-URI
X-Skip-Cache
X-Sucuri-Cache
X-VServer
X-Webstats-RespID
X-Viewer-Country
X-Varnish-Beresp-Status
X-Sucuri-ID
X-RCS-CacheZone
X-Proxy-Upstream
X-LI-UUID
X-Location
Host-ID
X-Li-Fabric
X-Hash
X-Men
X-NodeID
X-Owner
X-Origin-Time
X-Origin-Expires
X-Old-Content-Length
X-Geo-Header
X-Nyt-Route
Fastcgi-Cache-TTL
Cmsid
AKAMAI
CDCHOST
Arc-Country
CacheControlHeader
Fastly-Drupal-Html
Cmstype
Environment
X-Reqid
X-Zone
Server-Info
X-Locale
X-MP-GENERATED-AT
X-Backend-State
X-BBC-Edge-Cache-Status
X-Fastly-Backend
X-Generated-On
X-Gzip
X-ATG-Version
X-GeoIP
X-Gamma-Serve
X-Envoy-Decorator-Operation
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
X-Core-Value
X-Cdn-Origin
X-Datadog-Trace-Id
X-Cache-Debug
X-Bip
X-Cache-Id
X-Branch-Name
X-Developers
X-Esi-Check
Apple-News-Services-Parsed-Url
X-TH-Server
X-Thanos
X-Storefront-Renderer-Rendered
X-Sn-Servicetimems
X-Sigma-Backend
X-Thinkindot-L3
X-TrackingId
X-Magnolia-Registration
X-Backend-TTL
X-VG-TLSProxy
X-VarnishDD-TTL
X-UnsetCookies
X-Sigma
X-Rocket-Build-Number
Apple-News-Services-Host
Apple-News-Services-Handled
X-Adobe-Source
Apple-News-Services-Request-Url
X-Level-Front-Cache
X-Mvc-Supplant-Cachable
X-Node-Id
X-Region-Sid
X-Req
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-Policy
X-HS-Content-Campaign-Id
X-HN
Mail-Subject
Req-Svc-Chain
Web-Mar-Region
Locid
Server-Host
We-Hiring
Thinkindot-CacheControl
Gh-Request-Id
PFcat
Machine
Thinkindot-Control
TDXMobile
Fastly-GeoIP-CountryCode
Thinkindot-CacheControl-Type
X-VC-Cache
X-Xrds-Location
Fastly-SWR
X-NU-AKA-ACS-Version
X-Pod-Name
X-Platform
Platform
Adler-Geo
X-Csrf-Jwt
X-DPWN-IS-SECURE
X-Eu-Site
X-Tx-Id
Fastly-SIE
X-Has-Esi
X-GeoIP-City
X-Irp-Debug
Cf-Device-Type
X-DefHash
X-Loc
X-JWT-State
X-Is-Gdpr
X-DefElseHash
X-Qloud-Router
X-GeoIP-Region-Code
L5d-Success-Class
Ha-Gx-Prefs
Memcached
X-GeoIP-Country-Code
X-Varnish-Remaining-TTL
X-Varnish-CookieHashed-On
X-Variation
X-CGP
X-Origin
NGX
X-Request-Start
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
HA-Ipaddr
X-Amzn-Remapped-Content-Length
X-Worker
NM-Fastcgi-Cache
Is-Eu
X-Varnish-CookieINHashed-On
AMP-Access-Control-Allow-Source-Origin
X-Varnish-Beresp-Ttl
X-Ua-Device
X-Trace-ID
X-CS
X-Cache-Config
X-FC-Vary-Parameters
X-CLOUD-TRACE-CONTEXT
X-Response-By
S-Rt
Magicmarker
X-CACHE-KEY
X-NC
X-Mvc-Supplant-OutputCached
X-Up
X-API-Version
Datacenter
X-Esi
X-Datadome
X-Tt-Logid
X-LB-ID
Pics-Label
Ms-Author-Via
CDN
X-Restarts
Kp-EeAlive
Candidate-Md5Url
X-Akamai-Request-ID2
X-Generated-In
Memory
X-Http-Reason
Env
X-LB-NoCache
Time
X-Vc
X-Tb-Optimization-Total-Bytes-Saved
X-TraceId
X-Via-Popn
WebServer
X-Cache-Backend
X-Via-Poph
X-Optimistic-Header
X-DC
X-Wix-Viewer-Type
Edge-Cache
NtCoent-Length
X-Via-Popv
X-Varnish-Ttl
X-DI
X-DB
X-RSL
X-DSS
X-DW
X-RPS
X-URL
X-RPM
X-Action
X-DynaTrace-JS-Agent
X-Refresh
X-Edge-Pop
On-Server
GeoIp-Country-Code
WWW-Authenticate
X-TA-CDN-Provider
X-CacheTTL
X-Parent-Response-Time
X-Minions-Version
Accept-Language
Esi-Enabled
X-Servedbyhost
X-HA-Backend
X-Srv
X-Unique-ID
X-Service
Server-ID
X-Varnish-Beresp-TTL
X-MSEdge-Flight
C-Via
X-MSEdge-Features
X-Cs
X-Urbn-Context-Path
X-Urbn-Site-Id
X-Cache-PHP
Locale
X-Newrelic-Synthetics
X-ZONE
X-TX-ID
X-Ec-Fail
X-User
X-VCL-Version
X-Ec-GeoHdr
X-LI-Proto
X-Cache-Ttl
X-Render-Time
X-Dynatrace
X-Traceid
X-Cache-Status-Check
X-Fpc
X-App
X-Webkit-Csp-Report-Only
X-Li-Proto
Test
Cdncip
Cdnsip
X-FPC
X-B3-Spanid
X-AK-Request-ID
X-NODE
X-LiteSpeed-Cache-Control
Proxy-Connection
X-Webkit-CSP-Report-Only
X-WADP-Cache
My-App
Server-Id
X-Fmm-Version
Cluster
X-Vcl-Version
X-Clara-WADP
X-Mcache
X-Pass-Why
X-AIR-PT
Tracecode
Resin-Trace
X-CUA
M-TraceId
X-Var-Ttl
Geoip-Latitude
X-Clientip
X-CSRF-TOKEN
X-Info
X-Oss-Server-Time
X-Oss-Storage-Class
X-Oss-Object-Type
Fastly-Drupal-HTML
X-From
Lfy
X-Oss-Request-Id
T-Server
Geo-Info
X-Oss-Hash-Crc64ecma
Cf-Int-Pingora-Origin-Digest
Hostname
HIT
Cache-Host
UCS
X-Fragments
X-LiteSpeed-Tag
Lang
S-Cnection
X-Ha-Backend
X-ID
X-Pad
Tcn
Target-Params
Hit
Ohc-File-Size
X-WP-CF-Super-Cache-Cache-Control
X-ServedByHost
GeoIP-Country-Code
X-WP-CF-Super-Cache
X-Geo
DataCenter
X-Dynatrace-Js-Agent
Fastly-Backend-Name
X-Via-PopV
X-Micro-Cache
X-Edge-POP
X-Cdn-Forward
X-RAMCache
X-ElasticPress-Query
User-Agent
X-Via-PopN
MIME-Version
X-Via-PopH
X-HostName
X-Edge-Cache
X-Release
Section-Io-Id
Load-Balancing
Section-Io-Origin-Status
X-Check-Cacheable
X-VC
X-NGINX-Cache
X-Api-Version
Section-Io-Origin-Time-Seconds
ENV
X-BBC-Origin-Response-Status
Section-Origin-Responded
X-Backend-Host
X-Ucs
X-Lb-Nocache
Servername
X-Httpd
Permissions-Policy
X-Proxy-Cache-Info
X-Fastly-Backend-Reqs
X-BCube-Filmed-By
X-APP
X-HS-Status
X-ServerName
X-Provided-By
EpKe-Alive
X-UP
PICS-Label
ServerName
Producers
URI
FSS-Cache
X-GoCache-CacheStatus
Uri
Lb
X-TRACE-ID
CPC-Age
Cache-Key
WZWS-RAY
X-Udemy-Cache-App-Namespace
Server-Ttl
X-Cache-CFC
X-Pool
X-SB
Path
Cdn
X-Amz-Meta-Cb-Modifiedtime
VNS-Cache
VNS-Age
X-RateLimit-Reset
X-B3-ParentSpanId
CPC-Cache
Vha6-Origin
X-Fastly-Cache-Hits
X-WA
X-Nc
X-Cdn-Request-ID
Cneonction
Cteonnt-Length
Ohc-Cache-HIT
X-WA-Info
X-Lb-Id
X-Dw-Trace-Id
X-Wikidot-Static-Cache
X-Apw-Access-Token
X-Apw-Access-Object
X-Akamai-ERPolicy
X-Apw-Hits
X-Apw-Access-Action
X-Akamai-ERRuleID
Shield-Pop
X-Ec-Custom-Error
X-Platform-Cluster
X-Platform-Processor
X-Platform-Router
X-Akamai-Request-ID
X-Snapshot-Date
X-Acquia-Site
X-Cache-ASPX
X-Contensis-Viewer-Groups
X-Yottaa-OS
X-Wikidot-Backend
X-Newrelic-App-Data
X-Vcache
X-Acquia-Purge-Tags
CF-Cached-On
X-Swift-Error
Cf-Ipcountry
X-ES-SERVER
X-Acquia-Application-UUID
X-Acquia-Application-Trace
X-Air-Pt
Sid
X-Cache-Ngx
X-Cms-Context
X-Shopify-Generated-Cart-Token
X-Scale
X-PJAX-URL
Req-ID
X-Varnish-Authentication
CountryCode
GeoIP-Latitude
X-UA
X-Te-Duration-Ms
X-Te-Count
X-Http-Duration-Ms
X-Http-Count
Pagetype
X-Logging-Id
X-Sentry-ID
Ngx
X-Last-Modified
X-CacheKey
X-Akamai-Pragma-Client-IP