Threat Level: green Handler on Duty: Rick Wanner

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
Link
CF-Cache-Status
Accept-Ranges
CF-RAY
ETag
Expect-CT
Pragma
X-Powered-By
X-XSS-Protection
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
Alt-Svc
P3P
X-Served-By
X-Xss-Protection
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Cache-Status
X-Generator
X-Cacheable
Timing-Allow-Origin
X-Request-ID
X-Content-Security-Policy
P3p
X-Iinfo
Status
Feature-Policy
X-Envoy-Upstream-Service-Time
Content-Encoding
Access-Control-Expose-Headers
X-CDN
X-Drupal-Dynamic-Cache
X-AspNetMvc-Version
Upgrade
X-Via
CF-Ray
Access-Control-Max-Age
X-Ws-Request-Id
Server-Timing
EagleId
Keep-Alive
X-Cache-Group
X-Turbo-Charged-By
Request-Context
X-Age
X-Proxy-Cache
X-Server-Powered-By
X-UA-Device
X-Backend
X-AH-Environment
X-Hacker
X-Robots-Tag
Report-To
X-Amz-Request-Id
X-LiteSpeed-Cache
Host-Header
X-Server
X-Amz-Id-2
X-Dns-Prefetch-Control
Grace
X-Rq
X-Nginx-Cache-Status
X-Varnish-Cache
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-WebKit-CSP
X-Page-Speed
X-Vhost
X-OneAgent-JS-Injection
EagleEye-TraceId
X-Amz-Version-Id
X-Ua-Compatible
X-Dispatcher
X-Device
X-Pingback
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Cache-Spec
NEL
X-Host
X-Server-Id
X-Backend-Server
X-Node
Cf-Railgun
X-Readtime
Accept-CH
X-Akam-SW-Version
Surrogate-Control
Request-Id
X-Response-Time
X-HW
X-Language
Xkey
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Ruxit-JS-Agent
Content-Location
X-Application-Context
X-Template
Accept-Ch-Lifetime
Rating
X-Country
X-B3-TraceId
X-Cloud-Trace-Context
X-Cache-Lookup
X-Ac
X-Url
Allow
X-Content-Type
X-Buckets
X-Trace
Accept-CH-Lifetime
X-Vname
X-TtlSet
X-PC
X-Mod-Pagespeed
X-Varnish-TTL
X-Clacks-Overhead
Edge-Control
X-FastCGI-Cache
X-ESI
Cache-Tag
Fastly-Restarts
X-Rack-Cache
Service-Worker-Allowed
X-VARITI-CCR
X-Server-Name
X-Element-Page-Cache
Verso
X-GitHub-Request-Id
X-MS-InvokeApp
X-Upstream
X-Amz-Rid
X-Vcap-Request-Id
Public-Key-Pins
X-Dw-Request-Base-Id
Accept-Ch
X-D2id
X-Client-IP
X-Cached
X-Abt-Application-Version
X-Origin-Cache
MS-Author-Via
X-Cache-TTL
Arr-Disable-Session-Affinity
X-Cnection
X-Country-Code
X-Px
X-Goog-Hash
X-Powered-By-Plesk
X-Navigation-Version
Access-Control-Request-Method
X-Server-Lifecycle-Phase
X-NF-Request-ID
X-Kraken-Loop-Name
X-Instrumentation
X-Version
X-Aws-Lambda-Call-Status
RTSS
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
X-Amz-Server-Side-Encryption
X-Powered-CMS
X-Middleton-Display
Display
Pagespeed
X-Sol
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Middleton-Response
Response
X-Kinja-Revision
X-Kinja-Server
X-Kinja-Build
X-Use-Magma
X-Cdn-Fetch
X-Exp-Id
X-Exp-Variant
X-Kinja
X-GoogleNews-Bot
X-MSEdge-Ref
X-LLID
X-Edge
X-Kinsta-Cache
X-Edge-Location-Klb
X-CST
Nginx-Cache
Mrf-Cache-Status
MRF-Tech
X-Shield-Request-Id
X-B3-TraceId-Primal
X-TTL
S
AR-ATIME
AR-SID
AR-PoweredBy
AR-CACHE
AR-Request-ID
Content-MD5
X-HP-Webp
X-Jurisdiction
X-HP-Trace-Id
X-T
X-Protected-By
X-RateLimit-Remaining
X-Forwarded-For
TCN
X-Content-Security-Policy-Report-Only
X-Id
X-Mg-S
X-Aspnetmvc-Version
X-Mid
X-MCACHE
Fastcgi-Cache
Realpath
Front-End-Https
X-Parallel-Accel
SPRequestDuration
SPIisLatency
Edge-Cache-Tag
X-Recruiting
X-Request-Received
X-Request-Processing-Time
Filters
X-Ttl
X-Pinterest-Rid
Pinterest-Generated-By
Pinterest-Version
Fusion-Deployment-Id
Fusion-Source
Fusion-Content-Id
Fusion-Content-Source
Server-Node
Fusion-Template-Id
Fusion-Component-Id
X-Content
X-DynaTrace
X-Ab
X-Ua-Browser
X-SharePointHealthScore
SPRequestGuid
X-Correlation-Id
X-Ezoic-Cdn
Server-Name
Alternate-Protocol
X-NWS-LOG-UUID
X-Accel-Expires
X-Frontend
X-HS-Combine-CSS
X-HS-Cache-Config
X-ECACHE
X-HS-Hub-Id
X-HS-Content-Id
X-Yandex-Sdch-Disable
X-Hits
X-Cache-Key
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Content-Options
Cache-Tags
X-Page-Id
MicrosoftSharePointTeamServices
X-Git-Hash
Charset
Cleartype
Host
X-B3-Sampled
X-Www-Served-By
X-Server-ID
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Geo-Country
X-Ruxit-Js-Agent
X-Content-Digest
TP-L2-Cache
X-Ser
TP-Cache
X-Amz-Replication-Status
X-Forwarded-Proto
Filterid
X-Fastly-Request-Id
X-VCache
X-Amzn-Trace-Id
X-Hostname
X-Varnish-Age
X-AppVersion
X-Az
X-Activity-Id
X-Daa-Tunnel
X-XRDS-LOCATION
X-Rid
X-Debug-Info
X-DIS-Request-ID
X-Upgrade-Enabled
X-Origin-Server
Access-Control-Allow-Method
X-Grace
X-Microsite
X-N
X-Request-Handler-Origin-Region
X-Origin-Upstream-Status
X-LB-Cache
X-FB-Debug
X-Nginx-Upstream-Cache-Status
ServerID
X-Mobile-URL
X-Whom
X-TT
X-Aspnet-Duration-Ms
X-Route-Name
X-Request-Guid
X-Is-Crawler
X-Providence-Cookie
X-Flags
X-GUploader-UploadID
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
X-NGENIX-Cache
X-Goog-Generation
X-F-Cache
X-App-Environment
X-App-Server
Cross-Origin-Opener-Policy
X-WebKit-CSP-Report-Only
X-Varnish-Grace
Viewport
X-PressLabs-Stats
Payment
X-Tb
DC
X-FW-Static
X-FW-Type
X-FW-Serve
X-FW-Dynamic
Node
Paypal-Debug-Id
X-Distributor
X-FW-Hash
X-FW-Server
X-Cache-Control
X-Logged-In
Fastcgi-Useragent
X-Seen-By
X-Type
X-User-Agent
X-Cache-Age
Country
Accept-Charset
X-Cache-Rule
X-Varnish-Backend
X-Erf-Bev-Bev-Is-Generated
X-Node-Name
X-Erf-Bev-Bev
X-Browser-Type
X-Webkit-CSP
X-DataDome
X-Load-Cache
Version
X-Fastly-Request-ID
X-Wix-Request-Id
X-Cache-Action
X-IPLB-Instance
X-Via-JSL
Refresh
X-Oracle-Dms-Rid
X-Oracle-Dms-Ecid
SD-X-WS
X-Response-Served-From
X-Original-Request-Id
Referer-Policy
Access-Control-Request-Headers
Cache-Status
Amp-Access-Control-Allow-Source-Origin
X-TEC-API-ORIGIN
X-Real-IP
X-Cacheable-TTL
X-Drupal-Cache-Tags
X-TEC-API-ROOT
X-TEC-API-VERSION
X-Ratelimit-Limit
X-Jobs
VIX-Pulpo-Upstream-Status
X-B
X-Page-View
X-Is-Bot
VIX-Pulpo-Node
NGB
X-UUID
X-Rendered-As
X-Proxy-Cache-Status
X-Contextid
X-Cluster-Name
X-Debug
X-ProcessESI
X-Vgn-Hpd-Reason
X-Revision
X-RemovedCookies
X-B-Cache
DynaTrace
X-Rule
X-Signature
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Device-Type
X-Cache-Expired-At
X-Proxy
X-Mobile
X-Drupal-Cache-Contexts
Liferay-Portal
X-Instance
Akamai-GRN
X-Cache-Time
X-G
Surrogate-Key
X-Framework
X-Tec-Api-Version
X-Tec-Api-Origin
X-Tec-Api-Root
X-Fastcgi-Cache
X-FW-Version
X-Debug-IsConnected
CF-IPCountry
X-Debug-IsPreview
Healthy
X-Azure-Ref
X-Source
SID
X-Air-Hostname
X-Air-Trace-Id
X-Air-Source
X-Ms-Request-Id
X-Ms-Version
Frame-Options
X-Nginx-Cache
X-Cache-Hit
X-RTag
Ms-Operation-Id
MS-CV
Section-Io-Cache
Countrycode
X-Tumblr-Pixel-0
X-CDN-Forward
X-Tumblr-User
X-Tumblr-Pixel-1
X-Tumblr-Pixel
X-Oneagent-Js-Injection
X-Environment-Context
X-Varnish-Server
Xserver
X-L-Path
Count-Hit
X-APP-VERSION
GEO-INFO
X-Cache-Operation
X-Region
X-XRDS-Location
X-Servername
X-Forwarded-Host
X-EdgeConnect-Cache-Status
X-RateLimit-Limit
X-Content-Powered-By
Uber-Trace-Id
X-Backend-Name
X-Mode
Cross-Origin-Window-Policy
X-IPS-LoggedIn
Backend
X-Accel-Buffering
X-Adobe-Content
Nel
X-Litespeed-Cache
X-Adobe-Loc
Ec-Rule-Version
X-Zen-Fury
X-SaId
X-UPSTREAM-Address
Meta-Geo
X-RN-RSRV
X-JoinUs
X-Alternate-Cache-Key
X-Redis-Cache
X-Detected-As
X-Debug-Cache
X-Cache-Type
X-ShopId
X-Generation-Time
X-Sorting-Hat-PodId
X-Cache-Grace
X-Varnish-Beresp-Grace
X-Sorting-Hat-ShopId
X-Cache-Server
X-Shopify-Stage
X-ShardId
Eomportal-Instance
X-Hosted-By
X-Microcachable
X-Human
X-Uri
X-Sql-Duration-Ms
Decoy-Debug-TTL
Url
X-FB-TRIP-ID
X-Site-Version
X-Cache-TTL-Remaining
X-ServerID
X-Storage
Cache-Tv-Group
X-BYPASS-REASON
X-Sql-Count
X-Via-Fastly
Cache-Name
Country-Code
Decoy-Debug-Key
X-Origin-Date
Decoy-Debug-Status
X-No-Session
X-NCache
X-ProxyCache-Status
X-Status
Apigw-Requestid
X-ProxyCache-Key
Webcakes-Region
TWC-GeoIP-LatLong
TWC-Device-Class
TWC-Connection-Speed
Selected-Fe
TWC-GeoIP-Country
TWC-Locale-Group
Webcakes-App-Name
TWC-Privacy
Webcakes-App-Version
X-OCL
X-PCL
X-Proxy-Build
X-Time
X-Cache-Host
X-PHP-Backend
Mn-Server-Ip
X-SayCDN-TTL
X-Timing-Wait
X-Origin-Hint
X-Say-TTL
X-UA-Device-Type
Fastly-SSL
X-Akamai-Edgescape
X-Format
X-Say-Cacheable
Protected
X-Web-Node
Property-Id
X-Pubstack
X-R9-Blue-Green-Version
X-NYM-Debug-Backend
Azure-Version
X-Proxied
X-PERF
X-Server-W
X-Routing-Service
X-ApacheServer
X-Extlb
X-Section
X-Zipkin-Id
DB-Nickname
X-Access
Azure-InstanceId
Azure-SlotName
Azure-RegionName
Azure-SiteName
Source
OT-Force-Account-Verify
X-Be
Content-Secure-Policy
X-Varnishpool
X-Cache-NGX
X-Tid
X-Hl-Ver
X-Cluster-Node
X-Rewrite-Enabled
X-Ua
X-Azure-Ref-OriginShield
X-Soup
X-SRV
X-LSADC-Cache
X-HTML-Minification-Powered-By
X-Content-Age
X-NewRelic-App-Data
X-Cache-Var-Map
X-Webkit-Csp
X-Amz-Meta-S3cmd-Attrs
X-Cached-By
X-App-Version
Content-Disposition
X-Cache-Var
SRV
X-Ratelimit-Reset
CDN-RequestId
CDN-EdgeStorageId
CDN-CachedAt
CDN-Cache
Cache
CDN-PullZone
CDN-RequestCountryCode
X-Generated-By
X-Unique-Id
CDN-Uid
X-LAGOON
X-TNCMS
X-TT-LOGID
X-Bc-Bl
X-Hyper-Cache
X-Loop
Webserver
X-Dc
Onion-Location
Retry-After
X-Varnish-Hits
X-Varnish-Hostname
X-Auto-Login
X-Origin-TTL
X-S-Maxage
X-Origin-CC
X-GEO
X-Tumblr-Pixel-3
X-Tumblr-Pixel-2
X-Presslabs-Stats
X-ECache
Cache-Hits
X-Nginx-Cache-Key
Web-Mar-Node
X-Proto
Xet-Cookie
X-Qnm-Cache
X-Endurance-Cache-Level
X-Time-Microsecs
X-M-Reqid
X-Tenant
X-M-Log
X-CSRF-Token
X-Akamai-Transformed
X-Edge-Location
X-Cdn
LB
X-VWS-Id
Mime-Version
X-Platform-Server
X-GG-Cache-Date
X-AWS-Id
X-Trace-Id
X-LJ-Flow-ID
HostName
CloudFront-Viewer-Country
X-Mg-Request-UUID
X-CACHE-KEY
X-Amzn-RequestId
X-Labrador-Cache-Channel
X-Amz-Apigw-Id
X-PHP-Host
X-Xfnlog-Site
N-Cache
X-Cache-Tags
X-B3-SpanId
X-Xrds-Location
X-Varnish-Cache-Hits
X-Handled-By
X-RCS-CacheZone
X-Locale
X-Storefront-Renderer-Rendered
Upgrade-Insecure-Requests
X-Request-Time
WPO-Cache-Status
X-Origin-Response-Time
WPO-Cache-Message
ServedBy
X-Adobe-Source
X-AOL-HN
X-Cache-Remote
X-CF-Lambda-Fn
X-ND-Cache
X-CF-Lambda-Version
X-Ig-Push-State
X-Ckpd-Fst-Backend
X-Developer
X-Request-Host
X-Ftr-Request-Id
X-Cache-Date
X-Cache-NE
Fastcgi-X-Cache-Version
X-Destination
X-Cluster
X-Connection-Hash
X-A-Dam
X-ScT
X-D
X-S-Cookie
Pramga
X-S
X-NAPM-TraceId
X-Conf
Meta-Geo-Continent
X-A-Ccd
X-A
X-Processor
Expiry
X-PBS-Appsvrname
BehaviorPad-Version
Surrogated-Key
A
X-A-Wwc
Odigeo-Trace-Id
X-ARC
X-Application
X-Forwarded-Path
X-Orig-Expires
X-PAYTM-SRV-ID
X-Aed
X-A-Dgt
State
Redirect-Candidate
X-External-Request-Id
DCR-Processing-Time-Ms
DSUID
DCR-Decision-By
Rendered-Blocks
X-Planisys-CDN-TTL
X-Planisys-CDN-Cache
X-B-Cookie
Mobile-Detection-Method
X-Planisys-CDN-Rules
Origin
X-A-Dcw
X-Rojux
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-Vtex-Remote-Cache
Xc-Version
X-SRCache-Key
Ms-Author-Via
X-Reqid
X-Vdms-Version
X-Vdms-Path
X-V-Cache
X-TIM-N
X-VG-WebCache
X-Slack-Backend
X-Vtex-Processado-Em
X-Via-NSCOPI
X-Session-Fingerprint
X-SD-PageType
X-Shop-Environment
X-ATG-Version
X-Correlation-ID
Environment
Datacenter
X-VC-Cache
X-MP-GENERATED-AT
Server-Info
X-LI-UUID
X-Fastly-Cache
X-Men
L
X-Li-Pop
X-Li-Fabric
X-Block-Status
X-Device-Os
X-Mvc-Supplant-Cachable
X-Hnp-Log
X-Nyt-Route
X-Old-Content-Length
X-Gen-Mode
Fastcgi-Cache-TTL
X-Cache-Bucket
Wxu-Next-Region
X-Gdpr
X-Scheme
User-Cache-Control
X-VServer
X-Epic-Correlation-Id
X-Varnish-Beresp-Status
X-Cache-Info
X-Fetched-On
Release
X-Hash
Wxu-Next-Commit
V-Age
Vix-Hermes-Req-Id
X-Forwarded-Site
X-VG-TLSProxy
Wxu-Next-Hostname
X-Geo-Header
X-Accel-Expires-Debug
Gh-Request-Id
AKAMAI
X-Date
X-Server-IP
X-Owner
X-Core-Mission
X-Rocket-Nginx-Serving-Static
From-Origin
X-Proxy-Upstream
X-Policy
X-Origin-Time
X-Skip-Cache
Cmsid
Cmstype
X-Origin-Expires
X-Served-From
CacheControlHeader
X-TIME
AMP-Access-Control-Allow-Source-Origin
X-Cache-Debug
X-Request-Start
X-Cache-Config
Web-Mar-Region
X-Sucuri-Cache
Arc-Country
We-Hiring
X-Req
True-Client-Country-4JS
X-GeoIP
Thinkindot-Control
X-Sucuri-ID
X-Generated-On
X-Region-Sid
X-Cache-Id
X-Datadog-Sampling-Priority
X-Datadog-Trace-Id
X-Rocket-Build-Number
X-Sigma-Backend
Traceparent
X-Bip
X-Sigma
X-Magnolia-Registration
X-BBC-Edge-Cache-Status
X-Branch-Name
X-Aicache-OS
Req-Svc-Chain
CDCHOST
X-Fastly-Backend
X-Core-Value
Origin-CC
Thinkindot-CacheControl-Type
Origin-EX
X-Sn-Servicetimems
X-Gzip
Locid
Apple-News-Services-Handled
Apple-News-Services-Host
Machine
Mail-Subject
X-Ratelimit-Remaining
X-Level-Front-Cache
Host-ID
Apple-News-Services-Parsed-Url
Fastly-GeoIP-CountryCode
Candidate-Md5Url
X-NodeID
X-TH-Server
X-Esi-Check
X-Location
Apple-News-Services-Request-Url
Thinkindot-CacheControl
X-TrackingId
Server-Host
X-EC-Lua
X-GeoIP-City
X-Developers
Svr
X-Datadog-Parent-Id
TDXMobile
X-Platform
X-Irp-Debug
X-Thanos
X-Thinkindot-L3
X-Cdn-Origin
X-Viewer-Country
X-HS-Content-Campaign-Id
X-DefHash
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-Webstats-RespID
X-DPWN-IS-SECURE
X-DefElseHash
X-Envoy-Decorator-Operation
X-JWT-State
X-Origin
X-Variation
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
X-UnsetCookies
X-Pod-Name
X-Request-URI
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-Qloud-Router
X-NU-AKA-ACS-Version
X-VarnishDD-TTL
Fastly-SIE
Fastly-SWR
NGX
X-FC-Vary-Parameters
X-Gamma-Serve
X-Worker
X-Loc
X-Is-Gdpr
X-HN
X-Has-Esi
X-Eu-Site
X-CGP
L5d-Success-Class
Is-Eu
X-Backend-State
NM-Fastcgi-Cache
X-Amzn-Remapped-Content-Length
PFcat
HA-Ipaddr
Ha-Gx-Prefs
X-Csrf-Jwt
Platform
Adler-Geo
Cf-Device-Type
X-Zone
X-FireWall-Port
X-CS
Fastly-Drupal-Html
X-Cdn-Srv
X-Node-Id
Sslversion
WWW-Authenticate
Memcached
X-Varnish-Beresp-Ttl
X-Tx-Id
X-Trace-ID
Esi-Enabled
X-LB-ID
X-Response-By
X-API-Version
Ssr
On-Server
X-NC
X-Mvc-Supplant-OutputCached
X-CLOUD-TRACE-CONTEXT
X-Up
CDN
X-Generated-In
Pics-Label
WP-Super-Cache
X-Service
X-Vc
X-Refresh
C-Via
X-Datadome
X-Ah-Environment
NtCoent-Length
X-Backend-TTL
X-LB-NoCache
X-Via-Popv
X-Tt-Logid
X-Via-Poph
X-Via-Popn
X-Cache-Enabled
Memory
Time
X-Cache-PHP
X-TA-CDN-Provider
X-DynaTrace-JS-Agent
X-DC
X-GeoIP-Region-Code
X-Tb-Optimization-Total-Bytes-Saved
X-GeoIP-Country-Code
X-Edge-Pop
Env
X-Varnish-Ttl
X-Dynatrace
X-NWS-UUID-VERIFY
X-Optimistic-Header
X-Cache-Status-Check
GeoIp-Country-Code
Magicmarker
X-TraceId
X-Parent-Response-Time
X-Render-Time
X-Info
X-Varnish-Beresp-TTL
X-Esi
X-Ua-Device
X-CacheTTL
X-Servedbyhost
X-Restarts
Kp-EeAlive
X-Unique-ID
S-Rt
X-TX-ID
X-AIR-PT
Server-ID
X-ZONE
X-Cs
X-Webkit-Csp-Report-Only
X-DSS
X-DW
X-Action
X-Clientip
Edge-Cache
X-RPM
X-DI
X-Cache-Backend
X-MSEdge-Features
X-MSEdge-Flight
X-DB
X-RSL
X-RPS
X-Wix-Viewer-Type
X-Srv
X-Oss-Hash-Crc64ecma
Cache-Host
X-Oss-Server-Time
X-Oss-Storage-Class
X-Oss-Object-Type
WebServer
X-VCL-Version
Proxy-Connection
X-Oss-Request-Id
HIT
UCS
X-Fpc
X-LI-Proto
S-Cnection
X-Minions-Version
X-Newrelic-Synthetics
X-Traceid
X-Cache-Ttl
X-Li-Proto
X-App
X-HA-Backend
Section-Origin-Responded
Section-Io-Origin-Status
Section-Io-Id
Section-Io-Origin-Time-Seconds
X-URL
Lb
X-FPC
Test
X-Akamai-Request-ID2
X-LiteSpeed-Cache-Control
X-Http-Reason
X-Micro-Cache
User-Agent
X-Vcl-Version
X-B3-Spanid
Fastly-Backend-Name
Server-Id
X-NODE
X-Webkit-CSP-Report-Only
Geo-Info
Tcn
Accept-Language
X-Backend-Host
X-Pass-Why
X-Release
X-User
X-Ec-Fail
X-BCube-Filmed-By
X-Ec-GeoHdr
X-Pad
X-ES-SERVER
X-APP
Fastly-Drupal-HTML
X-LiteSpeed-Tag
X-Check-Cacheable
Cf-Int-Pingora-Origin-Digest
Resin-Trace
Locale
X-Urbn-Site-Id
X-Urbn-Context-Path
X-HostName
X-CSRF-TOKEN
GeoIP-Country-Code
X-ServedByHost
X-ID
Cache-Key
VNS-Cache
X-Amz-Meta-Cb-Modifiedtime
VNS-Age
Path
CPC-Cache
EpKe-Alive
X-BBC-Origin-Response-Status
CPC-Age
Hostname
X-Dynatrace-Js-Agent
Cdncip
Cdnsip
X-Ha-Backend
Hit
Ohc-File-Size
M-TraceId
X-Edge-POP
Srv
X-WA-Info
X-Fmm-Version
X-WADP-Cache
X-AK-Request-ID
X-WA
X-Clara-WADP
X-Akamai-Pragma-Client-IP
X-Geo
X-Cdn-Forward
My-App
X-Wikidot-Static-Cache
X-PJAX-URL
X-Cms-Context
X-Via-PopV
X-ElasticPress-Query
X-Via-PopN
X-Via-PopH
Shield-Pop
Pagetype
X-Wikidot-Backend
ENV
MIME-Version
X-RateLimit-Reset
Cluster
X-CCDN-CacheTTL
X-Via-Ucdn
X-NGINX-Cache
X-HS-Status
X-CCDN-Origin-Time
X-Edge-Cache
Load-Balancing
Geoip-Latitude
MD5-Digest
X-Hcs-Proxy-Type
X-Var-Ttl
Lfy
X-Api-Version
X-From
X-CUA
Tracecode
X-Fastly-Cache-Hits
X-VG-WebServer
URI
X-Ucs
T-Server
X-ServerName
Sever-Int
X-Fragments
Server-Hostname
W
X-Mcache
X-RAMCache
X-UP
Lang
X-SIPLIST1
X-GoCache-CacheStatus
Servername
X-Fastly-Backend-Reqs
X-Cache-Expires
Server-Ext
IsBot
X-Dw-Trace-Id
X-TRACE-ID
X-VC
X-Provided-By
Cteonnt-Length
X-Lb-Id
Target-Params
Cdn
X-Cdn-Request-ID
X-WP-CF-Super-Cache
Ohc-Cache-HIT
X-WP-CF-Super-Cache-Cache-Control
X-B3-ParentSpanId
Cneonction
X-Nc
PICS-Label
WZWS-RAY
X-Contensis-Viewer-Groups
X-Swift-Error
X-Newrelic-App-Data
X-Cache-ASPX
X-Apw-Access-Token
X-Acquia-Application-UUID
X-Acquia-Purge-Tags
X-Acquia-Site
X-Acquia-Application-Trace
X-Apw-Access-Action
X-Via-CDN
X-Apw-Access-Object
X-Apw-Hits
X-Platform-Cluster
X-Snapshot-Date
Uri
CF-Cached-On
X-Yottaa-OS
Vha6-Origin
Cf-Ipcountry
X-Cc-Via
X-Platform-Router
X-Platform-Processor
X-Akamai-Request-ID
Dnion-Transfer-Encoding
HitType
X-Cache-Ngx
Sid
X-Air-Pt
Server-Ttl
X-Akamai-ERRuleID
X-Te-Duration-Ms
X-Te-Count
X-Akamai-ERPolicy
X-Http-Duration-Ms
GeoIP-Latitude
X-Last-Modified
X-Http-Count
FSS-Cache
X-Varnish-Authentication
X-Logging-Id
X-Lb-Nocache
X-Miniprofiler-Ids
X-B3-Parentspanid
X-HTML-Edge-Cache
X-CacheKey
X-Sentry-ID
CountryCode
Req-ID
X-UA
Ngx