Threat Level: green Handler on Duty: Guy Bruneau

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Link
Cf-Request-Id
CF-Cache-Status
Accept-Ranges
CF-RAY
ETag
X-XSS-Protection
Expect-CT
Pragma
X-Powered-By
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-UA-Compatible
X-Cache-Hits
Alt-Svc
P3P
X-Served-By
X-Xss-Protection
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Varnish
X-Request-Id
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Cache-Status
X-Generator
X-Cacheable
Timing-Allow-Origin
X-Request-ID
P3p
X-Content-Security-Policy
X-Iinfo
Status
Feature-Policy
X-Envoy-Upstream-Service-Time
Content-Encoding
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
X-CDN
X-AspNetMvc-Version
Upgrade
X-Via
CF-Ray
Access-Control-Max-Age
X-Ws-Request-Id
Server-Timing
EagleId
Keep-Alive
X-Cache-Group
X-Turbo-Charged-By
Request-Context
X-Age
X-Server-Powered-By
X-Proxy-Cache
X-UA-Device
X-AH-Environment
X-Backend
X-Hacker
X-Robots-Tag
Report-To
X-Amz-Request-Id
Host-Header
X-Server
X-LiteSpeed-Cache
X-Amz-Id-2
Grace
X-Rq
X-Nginx-Cache-Status
X-Varnish-Cache
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-Dns-Prefetch-Control
X-WebKit-CSP
X-Page-Speed
X-Vhost
X-OneAgent-JS-Injection
EagleEye-TraceId
X-Amz-Version-Id
X-Pingback
X-Dispatcher
X-Device
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Cache-Spec
NEL
X-Server-Id
X-Host
X-Backend-Server
X-Node
Cf-Railgun
X-Readtime
Accept-CH
X-Akam-SW-Version
Surrogate-Control
Request-Id
X-Response-Time
X-HW
X-Language
Xkey
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Template
X-Ruxit-JS-Agent
X-Application-Context
Content-Location
Rating
X-Ua-Compatible
Accept-Ch-Lifetime
X-Country
X-B3-TraceId
X-Cloud-Trace-Context
X-Cache-Lookup
X-Buckets
X-Ac
Accept-CH-Lifetime
X-Url
X-Content-Type
X-Trace
Allow
X-Vname
X-TtlSet
X-PC
X-Mod-Pagespeed
X-Varnish-TTL
X-Clacks-Overhead
Edge-Control
X-FastCGI-Cache
X-ESI
Cache-Tag
Fastly-Restarts
X-Rack-Cache
X-Server-Name
Service-Worker-Allowed
X-VARITI-CCR
X-Element-Page-Cache
Verso
X-MS-InvokeApp
X-GitHub-Request-Id
X-Upstream
X-Amz-Rid
Accept-Ch
X-Vcap-Request-Id
X-Dw-Request-Base-Id
Public-Key-Pins
X-Cached
X-Client-IP
X-Abt-Application-Version
X-Origin-Cache
X-D2id
MS-Author-Via
X-Cache-TTL
Arr-Disable-Session-Affinity
X-Cnection
X-Country-Code
X-Powered-By-Plesk
X-Goog-Hash
Access-Control-Request-Method
X-Aws-Lambda-Call-Status
X-Px
X-NF-Request-ID
X-Version
X-Server-Lifecycle-Phase
X-Instrumentation
X-Kraken-Loop-Name
RTSS
X-Navigation-Version
X-Amz-Server-Side-Encryption
X-Powered-CMS
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
Display
Pagespeed
X-Middleton-Display
X-Sol
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Kinja-Server
X-Use-Magma
Response
X-Middleton-Response
X-Kinja-Revision
X-Cdn-Fetch
X-Exp-Variant
X-Exp-Id
X-Kinja-Build
X-Kinja
X-GoogleNews-Bot
X-MSEdge-Ref
X-LLID
X-Edge
X-Edge-Location-Klb
X-Kinsta-Cache
X-TTL
Nginx-Cache
AR-Request-ID
AR-CACHE
AR-PoweredBy
AR-ATIME
AR-SID
X-B3-TraceId-Primal
Mrf-Cache-Status
MRF-Tech
X-Shield-Request-Id
S
Content-MD5
X-CST
X-HP-Trace-Id
X-HP-Webp
X-T
X-Jurisdiction
X-Protected-By
X-RateLimit-Remaining
X-Forwarded-For
TCN
X-Content-Security-Policy-Report-Only
X-Aspnetmvc-Version
X-Mg-S
X-Id
Fastcgi-Cache
X-Mid
X-MCACHE
Realpath
SPIisLatency
Front-End-Https
SPRequestDuration
Edge-Cache-Tag
X-Parallel-Accel
X-Recruiting
X-Request-Processing-Time
X-Request-Received
Filters
X-Correlation-Id
Fusion-Source
Fusion-Template-Id
Fusion-Deployment-Id
Fusion-Content-Id
Pinterest-Version
Fusion-Component-Id
Pinterest-Generated-By
Fusion-Content-Source
Server-Node
X-Pinterest-Rid
X-Content
X-Ua-Browser
X-Ab
X-DynaTrace
SPRequestGuid
X-SharePointHealthScore
X-Ezoic-Cdn
X-Ttl
X-ECACHE
Server-Name
Alternate-Protocol
X-NWS-LOG-UUID
X-Frontend
X-HS-Combine-CSS
X-HS-Content-Id
X-HS-Cache-Config
X-HS-Hub-Id
X-Accel-Expires
X-Hits
X-Yandex-Sdch-Disable
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Content-Options
X-Cache-Key
MicrosoftSharePointTeamServices
X-Ruxit-Js-Agent
X-Page-Id
Cache-Tags
Host
X-Git-Hash
X-Kong-Proxy-Latency
Charset
Cleartype
X-Kong-Upstream-Latency
X-Www-Served-By
X-B3-Sampled
X-Geo-Country
X-Ser
X-Amz-Replication-Status
X-Content-Digest
TP-L2-Cache
TP-Cache
Filterid
X-Forwarded-Proto
X-Varnish-Age
X-VCache
X-Amzn-Trace-Id
X-Hostname
X-AppVersion
X-Az
X-Activity-Id
X-DIS-Request-ID
X-Daa-Tunnel
X-Debug-Info
X-Fastly-Request-Id
X-Rid
X-Upgrade-Enabled
X-Origin-Server
Access-Control-Allow-Method
X-Grace
X-Origin-Upstream-Status
X-Request-Handler-Origin-Region
X-N
X-Microsite
X-XRDS-LOCATION
X-LB-Cache
X-FB-Debug
X-Nginx-Upstream-Cache-Status
ServerID
X-Mobile-URL
X-Route-Name
X-Is-Crawler
X-Request-Guid
X-Flags
X-Providence-Cookie
X-Aspnet-Duration-Ms
X-Whom
X-F-Cache
X-TT
X-Server-ID
X-Goog-Stored-Content-Length
Cross-Origin-Opener-Policy
X-Goog-Generation
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-GUploader-UploadID
X-NGENIX-Cache
X-App-Server
X-Varnish-Grace
X-Tb
X-App-Environment
Payment
X-Distributor
Viewport
X-FW-Type
X-WebKit-CSP-Report-Only
X-FW-Server
X-FW-Serve
X-FW-Dynamic
X-FW-Static
X-FW-Hash
DC
Paypal-Debug-Id
Node
X-Cache-Control
X-PressLabs-Stats
X-Logged-In
X-Seen-By
X-Type
Fastcgi-Useragent
X-Litespeed-Cache
X-User-Agent
X-Cache-Age
Accept-Charset
Country
X-Fastly-Request-ID
X-Webkit-CSP
X-Cache-Rule
X-Browser-Type
X-Varnish-Backend
X-Erf-Bev-Bev-Is-Generated
X-Load-Cache
X-Erf-Bev-Bev
X-Wix-Request-Id
Version
X-Node-Name
X-Oracle-Dms-Ecid
X-Oracle-Dms-Rid
X-DataDome
X-TEC-API-ROOT
X-Cache-Action
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-IPLB-Instance
Refresh
X-Via-JSL
Referer-Policy
X-Response-Served-From
Access-Control-Request-Headers
X-Original-Request-Id
X-Vgn-Hpd-Reason
X-Drupal-Cache-Tags
SD-X-WS
Cache-Status
X-Rendered-As
X-Is-Bot
X-Jobs
X-Proxy-Cache-Status
X-Cacheable-TTL
X-Page-View
X-Real-IP
Amp-Access-Control-Allow-Source-Origin
DynaTrace
X-Debug
X-Contextid
X-Cluster-Name
X-Cache-Expired-At
X-Ratelimit-Limit
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-B
X-ProcessESI
X-Fastcgi-Cache
X-Signature
X-B-Cache
X-Revision
X-UUID
NGB
X-RemovedCookies
Liferay-Portal
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Device-Type
X-Drupal-Cache-Contexts
X-Mobile
X-Rule
X-Proxy
Akamai-GRN
X-Cache-Time
Surrogate-Key
X-Framework
X-Debug-IsConnected
X-G
X-Debug-IsPreview
X-Instance
CF-IPCountry
X-FW-Version
X-Azure-Ref
Healthy
X-Air-Source
X-Air-Hostname
X-Air-Trace-Id
SID
X-Source
X-Tec-Api-Origin
X-Tec-Api-Version
X-Tec-Api-Root
X-Ms-Request-Id
X-Ms-Version
Frame-Options
X-Nginx-Cache
X-Oneagent-Js-Injection
X-Cache-Hit
Ms-Operation-Id
MS-CV
X-RTag
X-CDN-Forward
Section-Io-Cache
X-L-Path
X-Environment-Context
X-Tumblr-Pixel
X-Tumblr-User
Countrycode
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
Xserver
X-XRDS-Location
X-Varnish-Server
X-RateLimit-Limit
Count-Hit
X-Cache-Operation
X-Region
GEO-INFO
X-Servername
X-APP-VERSION
Uber-Trace-Id
X-EdgeConnect-Cache-Status
X-Forwarded-Host
X-Content-Powered-By
Nel
X-Backend-Name
X-Accel-Buffering
X-Mode
Cross-Origin-Window-Policy
X-IPS-LoggedIn
Backend
X-Adobe-Content
X-Zen-Fury
X-Adobe-Loc
Ec-Rule-Version
X-ShopId
X-ShardId
X-Shopify-Stage
X-RN-RSRV
X-SaId
X-UPSTREAM-Address
X-Alternate-Cache-Key
Meta-Geo
X-Detected-As
X-JoinUs
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Sql-Duration-Ms
X-Microcachable
X-Cache-TTL-Remaining
X-Sql-Count
X-Redis-Cache
X-Cache-Grace
X-Uri
X-Cache-Server
X-Cache-Type
X-Generation-Time
X-Varnish-Beresp-Grace
Eomportal-Instance
X-Hosted-By
X-Human
Country-Code
X-Debug-Cache
X-ServerID
Mn-Server-Ip
X-ProxyCache-Status
X-ProxyCache-Key
X-PHP-Backend
Decoy-Debug-Status
Url
Cache-Tv-Group
X-Origin-Date
Decoy-Debug-Key
Cache-Name
Decoy-Debug-TTL
Apigw-Requestid
X-No-Session
X-Storage
X-Via-Fastly
X-BYPASS-REASON
X-FB-TRIP-ID
X-Tid
X-UA-Device-Type
X-Site-Version
X-NCache
X-Status
X-Cache-Host
X-Proxy-Build
X-R9-Blue-Green-Version
X-Time
Webcakes-App-Name
X-PCL
X-Origin-Hint
Property-Id
Protected
Selected-Fe
TWC-Device-Class
X-Format
TWC-GeoIP-Country
Fastly-SSL
X-OCL
X-Timing-Wait
TWC-GeoIP-LatLong
TWC-Privacy
DB-Nickname
X-SayCDN-TTL
X-Akamai-Edgescape
X-Say-Cacheable
X-Say-TTL
TWC-Locale-Group
TWC-Connection-Speed
X-Web-Node
Webcakes-Region
Webcakes-App-Version
X-NYM-Debug-Backend
X-Access
X-Varnishpool
X-Extlb
X-Azure-Ref-OriginShield
X-Server-W
OT-Force-Account-Verify
X-Section
X-Hl-Ver
Azure-Version
X-PERF
X-Cache-NGX
X-Routing-Service
X-ApacheServer
X-Rewrite-Enabled
X-Pubstack
X-Zipkin-Id
X-Proxied
Azure-InstanceId
Azure-SlotName
Azure-RegionName
Azure-SiteName
Content-Secure-Policy
Source
X-LSADC-Cache
X-Soup
X-Cluster-Node
X-Be
X-Ua
X-App-Version
X-Webkit-Csp
X-SRV
X-Content-Age
X-HTML-Minification-Powered-By
X-Ratelimit-Reset
X-Cached-By
X-Cache-Var-Map
X-Cache-Var
CDN-EdgeStorageId
CDN-Cache
CDN-CachedAt
Content-Disposition
CDN-PullZone
CDN-RequestId
X-NewRelic-App-Data
CDN-RequestCountryCode
CDN-Uid
X-Amz-Meta-S3cmd-Attrs
X-TT-LOGID
X-Generated-By
SRV
X-LAGOON
Cache
X-Bc-Bl
X-Hyper-Cache
X-Varnish-Hostname
X-Varnish-Hits
Webserver
X-Unique-Id
X-TNCMS
X-Loop
X-S-Maxage
X-Presslabs-Stats
Onion-Location
X-Dc
X-Auto-Login
X-Nginx-Cache-Key
Xet-Cookie
X-Tumblr-Pixel-2
X-Tumblr-Pixel-3
Cache-Hits
X-GEO
Web-Mar-Node
Retry-After
X-Origin-TTL
X-Origin-CC
X-Proto
X-Cdn
LB
X-M-Reqid
X-M-Log
X-Akamai-Transformed
X-Qnm-Cache
X-Tenant
X-Time-Microsecs
Mime-Version
X-CSRF-Token
X-Edge-Location
X-Platform-Server
HostName
X-VWS-Id
X-CACHE-KEY
X-Trace-Id
X-AWS-Id
X-LJ-Flow-ID
X-GG-Cache-Date
X-Endurance-Cache-Level
CloudFront-Viewer-Country
X-B3-SpanId
X-ECache
X-Amzn-RequestId
X-Xrds-Location
X-PHP-Host
X-Xfnlog-Site
X-Labrador-Cache-Channel
X-Amz-Apigw-Id
N-Cache
X-Cache-Tags
WPO-Cache-Status
WPO-Cache-Message
X-Mg-Request-UUID
X-Storefront-Renderer-Rendered
X-Varnish-Cache-Hits
Upgrade-Insecure-Requests
X-Cache-Remote
X-RCS-CacheZone
ServedBy
X-Origin-Response-Time
Ms-Author-Via
X-Handled-By
X-Locale
X-Request-Time
X-AOL-HN
X-Adobe-Source
DSUID
DCR-Processing-Time-Ms
Surrogated-Key
DCR-Decision-By
Expiry
Fastcgi-X-Cache-Version
X-D
X-Request-Host
X-Planisys-CDN-TTL
X-Destination
Xc-Version
X-Developer
X-Via-NSCOPI
X-Processor
BehaviorPad-Version
X-ND-Cache
A
X-Ftr-Request-Id
X-NAPM-TraceId
User-Cache-Control
X-Ig-Push-State
X-Gen-Mode
X-Forwarded-Path
X-Orig-Expires
X-PBS-Appsvrname
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-PAYTM-SRV-ID
X-External-Request-Id
X-Connection-Hash
X-Fastly-Cache
X-Hnp-Log
X-CF-Lambda-Version
Pramga
X-TIM-N
Redirect-Candidate
X-V-Cache
X-Application
X-ARC
Origin
X-B-Cookie
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
Rendered-Blocks
X-Aed
X-A-Dcw
X-A-Dam
X-Vtex-Processado-Em
X-A-Ccd
X-VG-WebCache
X-A-Dgt
X-A-Wwc
X-Vdms-Path
X-Vdms-Version
X-Conf
X-SRCache-Key
X-ScT
X-SD-PageType
X-Cluster
X-CF-Lambda-Fn
X-A
X-Ckpd-Fst-Backend
X-S
X-VC-Cache
X-S-Cookie
Odigeo-Trace-Id
X-Cache-NE
State
Mobile-Detection-Method
X-Block-Status
X-Slack-Backend
Meta-Geo-Continent
X-Vtex-Remote-Cache
X-Cache-Date
X-Session-Fingerprint
X-Shop-Environment
X-Rojux
Datacenter
Environment
X-MP-GENERATED-AT
X-Reqid
X-TIME
X-ATG-Version
Server-Info
AMP-Access-Control-Allow-Source-Origin
X-Varnish-Beresp-Status
Req-Svc-Chain
X-Core-Mission
X-Hash
Gh-Request-Id
Fastcgi-Cache-TTL
X-Ratelimit-Remaining
X-VServer
X-Proxy-Upstream
X-Date
Release
X-VG-TLSProxy
X-Accel-Expires-Debug
X-Scheme
X-Sucuri-ID
X-Cache-Bucket
X-Skip-Cache
X-BBC-Edge-Cache-Status
X-Sucuri-Cache
Origin-EX
X-TH-Server
X-Server-IP
Host-ID
Origin-CC
L
X-Served-From
X-Cache-Debug
X-Cache-Info
X-Rocket-Nginx-Serving-Static
X-Policy
X-Men
X-Location
X-LI-UUID
X-Mvc-Supplant-Cachable
Wxu-Next-Hostname
X-Nyt-Route
AKAMAI
X-Li-Pop
X-Gdpr
Traceparent
V-Age
Vix-Hermes-Req-Id
Wxu-Next-Commit
X-Li-Fabric
X-Geo-Header
X-Forwarded-Site
Wxu-Next-Region
X-Owner
Cmsid
X-Old-Content-Length
CacheControlHeader
CDCHOST
X-Epic-Correlation-Id
Cmstype
X-Fetched-On
X-Device-Os
Arc-Country
X-Origin-Expires
X-Origin-Time
From-Origin
Web-Mar-Region
We-Hiring
X-Thinkindot-L3
X-TrackingId
X-Webstats-RespID
X-VarnishDD-TTL
X-Aicache-OS
X-Thanos
X-Viewer-Country
X-Request-Start
X-Fastly-Backend
X-Gamma-Serve
X-Esi-Check
X-Envoy-Decorator-Operation
X-Developers
X-Platform
X-NodeID
X-Irp-Debug
X-HN
X-Gzip
X-GeoIP-City
X-HS-Content-Campaign-Id
X-GeoIP
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-Cache-Config
X-Cache-Id
X-Sigma
X-Sigma-Backend
X-Sn-Servicetimems
X-Branch-Name
X-Cdn-Origin
X-Rocket-Build-Number
X-Datadog-Trace-Id
X-Region-Sid
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
X-Req
X-Bip
X-Core-Value
NGX
Apple-News-Services-Parsed-Url
Fastly-GeoIP-CountryCode
Fastly-SIE
PFcat
Locid
Candidate-Md5Url
X-EC-Lua
Mail-Subject
Machine
TDXMobile
Svr
Apple-News-Services-Request-Url
Apple-News-Services-Handled
True-Client-Country-4JS
Apple-News-Services-Host
Thinkindot-Control
Fastly-SWR
Thinkindot-CacheControl
X-Magnolia-Registration
Thinkindot-CacheControl-Type
X-CS
X-FireWall-Port
X-FC-Vary-Parameters
X-Eu-Site
X-DefElseHash
X-Csrf-Jwt
X-Node-Id
Ha-Gx-Prefs
X-Cdn-Srv
X-DefHash
X-DPWN-IS-SECURE
X-Worker
X-RateLimit-Remaining-Second
X-Varnish-Remaining-TTL
X-Origin
X-NU-AKA-ACS-Version
X-Tx-Id
X-Loc
X-Request-URI
X-Pod-Name
X-RateLimit-Limit-Second
X-Qloud-Router
X-Zone
X-UnsetCookies
X-Variation
HA-Ipaddr
X-Has-Esi
X-Generated-On
X-Varnish-CookieINHashed-On
X-Varnish-CookieHashed-On
X-Level-Front-Cache
X-JWT-State
X-Is-Gdpr
Adler-Geo
Cf-Device-Type
Server-Host
L5d-Success-Class
Memcached
NM-Fastcgi-Cache
X-Amzn-Remapped-Content-Length
X-Backend-State
Is-Eu
Platform
Sslversion
X-CGP
X-Varnish-Beresp-Ttl
X-Correlation-ID
X-Trace-ID
Fastly-Drupal-Html
Ssr
X-Up
X-Mvc-Supplant-OutputCached
On-Server
WWW-Authenticate
X-Response-By
X-CLOUD-TRACE-CONTEXT
X-NC
X-LB-ID
WP-Super-Cache
Pics-Label
Esi-Enabled
X-API-Version
CDN
X-Generated-In
X-Vc
X-Datadome
X-Service
X-Cache-Enabled
X-Refresh
NtCoent-Length
Time
X-LB-NoCache
X-Backend-TTL
C-Via
Memory
X-TA-CDN-Provider
X-GeoIP-Country-Code
X-DC
X-GeoIP-Region-Code
X-Via-Popv
X-Cache-PHP
X-Via-Poph
X-Via-Popn
X-DynaTrace-JS-Agent
X-Varnish-Ttl
X-Dynatrace
Env
Magicmarker
X-Tb-Optimization-Total-Bytes-Saved
X-Edge-Pop
X-NWS-UUID-VERIFY
X-Tt-Logid
GeoIp-Country-Code
X-Cache-Status-Check
X-Optimistic-Header
X-Render-Time
X-TraceId
X-Parent-Response-Time
X-CacheTTL
X-Esi
Kp-EeAlive
X-Restarts
X-Servedbyhost
X-Info
Server-ID
X-ZONE
X-Varnish-Beresp-TTL
X-Unique-ID
X-Webkit-Csp-Report-Only
S-Rt
X-DB
Edge-Cache
X-DSS
X-RPM
X-RPS
X-AIR-PT
X-DW
X-RSL
X-DI
X-Wix-Viewer-Type
X-MSEdge-Flight
X-Action
X-Cache-Backend
X-MSEdge-Features
X-Srv
X-TX-ID
X-Cs
X-VCL-Version
Proxy-Connection
X-Clientip
WebServer
X-Newrelic-Synthetics
X-Fpc
X-App
X-LI-Proto
X-HA-Backend
X-Oss-Hash-Crc64ecma
Cache-Host
X-Oss-Storage-Class
X-Traceid
X-Oss-Request-Id
X-Cache-Ttl
HIT
X-Minions-Version
X-Oss-Server-Time
UCS
X-Oss-Object-Type
X-URL
X-Li-Proto
S-Cnection
Test
X-Akamai-Request-ID2
Section-Io-Id
Section-Io-Origin-Status
Section-Origin-Responded
Section-Io-Origin-Time-Seconds
X-Http-Reason
X-FPC
Lb
X-LiteSpeed-Cache-Control
X-NODE
X-Webkit-CSP-Report-Only
User-Agent
Server-Id
Geo-Info
Fastly-Backend-Name
Tcn
X-Micro-Cache
X-Vcl-Version
Accept-Language
X-B3-Spanid
X-Backend-Host
X-User
X-Pad
X-Pass-Why
X-Ec-Fail
X-Ec-GeoHdr
X-Check-Cacheable
X-LiteSpeed-Tag
X-HostName
X-Urbn-Site-Id
Fastly-Drupal-HTML
Locale
X-BCube-Filmed-By
Resin-Trace
X-Release
X-APP
X-Urbn-Context-Path
Cf-Int-Pingora-Origin-Digest
X-CSRF-TOKEN
X-ES-SERVER
GeoIP-Country-Code
X-BBC-Origin-Response-Status
X-ID
X-Dynatrace-Js-Agent
Hostname
M-TraceId
X-Amz-Meta-Cb-Modifiedtime
X-Edge-POP
X-AK-Request-ID
X-Ha-Backend
Cdncip
Path
X-WADP-Cache
EpKe-Alive
X-Fmm-Version
X-Clara-WADP
Ohc-File-Size
CPC-Age
CPC-Cache
Cache-Key
VNS-Age
Hit
X-WA
X-ServedByHost
Cdnsip
Srv
VNS-Cache
X-WA-Info
X-Geo
X-RateLimit-Reset
X-Cdn-Forward
X-ElasticPress-Query
My-App
X-Via-PopH
ENV
MIME-Version
Cluster
X-Via-PopV
X-Via-PopN
X-From
X-Wikidot-Static-Cache
X-CUA
Shield-Pop
X-Var-Ttl
Tracecode
X-Wikidot-Backend
X-Api-Version
Load-Balancing
X-Edge-Cache
X-HS-Status
Geoip-Latitude
Lfy
X-Cms-Context
Pagetype
X-NGINX-Cache
X-PJAX-URL
X-Akamai-Pragma-Client-IP
X-Ucs
X-CCDN-CacheTTL
X-CCDN-Origin-Time
X-Via-Ucdn
X-ServerName
URI
X-Hcs-Proxy-Type
X-Fastly-Cache-Hits
T-Server
MD5-Digest
X-VG-WebServer
IsBot
X-GoCache-CacheStatus
Servername
Lang
X-Fastly-Backend-Reqs
X-Mcache
X-RAMCache
X-SIPLIST1
X-Fragments
Sever-Int
Server-Ext
X-UP
Server-Hostname
X-Dw-Trace-Id
X-TRACE-ID
W
Cdn
X-VC
Cneonction
X-Cdn-Request-ID
X-Lb-Id
X-WP-CF-Super-Cache
WZWS-RAY
Target-Params
X-B3-ParentSpanId
X-WP-CF-Super-Cache-Cache-Control
X-Cache-Expires
Ohc-Cache-HIT
X-Nc
HitType
PICS-Label
X-Swift-Error
X-Akamai-Request-ID
Dnion-Transfer-Encoding
X-Provided-By
X-Apw-Access-Token
X-Apw-Access-Object
X-Apw-Access-Action
X-Yottaa-OS
X-Apw-Hits
X-Cache-ASPX
Cteonnt-Length
X-Snapshot-Date
X-Contensis-Viewer-Groups
Uri
X-Newrelic-App-Data
X-Acquia-Application-UUID
X-Platform-Router
X-Platform-Processor
X-Platform-Cluster
Vha6-Origin
CF-Cached-On
Cf-Ipcountry
X-Acquia-Site
X-Acquia-Purge-Tags
X-Acquia-Application-Trace
X-Air-Pt
X-Cache-Ngx
Sid
X-Miniprofiler-Ids
X-Logging-Id
X-Te-Duration-Ms
X-Lb-Nocache
X-B3-Parentspanid
X-Akamai-ERPolicy
GeoIP-Latitude
X-Last-Modified
X-Akamai-ERRuleID
X-Te-Count
Server-Ttl
X-Http-Count
CountryCode
X-Varnish-Authentication
X-Cc-Via
X-Sentry-ID
Req-ID
X-UA
Ngx
X-Via-CDN
X-CacheKey
X-Http-Duration-Ms