Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-Cache-Status
Link
Accept-Ranges
CF-RAY
ETag
X-XSS-Protection
Expect-CT
Pragma
X-Powered-By
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
Alt-Svc
X-UA-Compatible
X-Served-By
X-Xss-Protection
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-DNS-Prefetch-Control
X-Drupal-Cache
X-Cache-Status
X-Check
X-Generator
X-Cacheable
Timing-Allow-Origin
X-Content-Security-Policy
X-Iinfo
Feature-Policy
Status
X-Envoy-Upstream-Service-Time
Content-Encoding
Access-Control-Expose-Headers
P3p
X-Drupal-Dynamic-Cache
X-AspNetMvc-Version
X-CDN
Upgrade
X-Via
CF-Ray
X-Ws-Request-Id
Access-Control-Max-Age
X-Request-ID
Server-Timing
EagleId
X-Cache-Group
Report-To
X-Turbo-Charged-By
Keep-Alive
X-UA-Device
Request-Context
X-Age
X-Backend
X-Proxy-Cache
X-Server-Powered-By
X-AH-Environment
X-Robots-Tag
X-Hacker
X-Amz-Request-Id
X-Server
Host-Header
X-Amz-Id-2
Grace
X-Rq
X-LiteSpeed-Cache
X-Swift-CacheTime
X-Swift-SaveTime
X-Nginx-Cache-Status
X-Varnish-Cache
Ali-Swift-Global-Savetime
NEL
X-WebKit-CSP
X-Page-Speed
X-Vhost
EagleEye-TraceId
X-Ua-Compatible
X-Amz-Version-Id
X-OneAgent-JS-Injection
X-Pingback
X-Dispatcher
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
X-Cache-Spec
X-Host
Accept-CH
X-Dns-Prefetch-Control
Cf-Railgun
X-Server-Id
X-Backend-Server
X-Node
X-Readtime
Surrogate-Control
X-Akam-SW-Version
Request-Id
X-Response-Time
X-HW
Xkey
X-Application-Context
Content-Location
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Rating
Accept-Ch-Lifetime
X-Ruxit-JS-Agent
X-Country
X-B3-TraceId
X-Cloud-Trace-Context
X-Cache-Lookup
Accept-CH-Lifetime
X-Trace
X-Url
Allow
X-Ac
X-Content-Type
X-PC
X-Vname
X-TtlSet
X-Varnish-TTL
X-Aws-Lambda-Call-Status
X-Clacks-Overhead
Edge-Control
X-Server-Name
X-Mod-Pagespeed
X-ESI
Fastly-Restarts
Cache-Tag
Service-Worker-Allowed
X-VARITI-CCR
X-Rack-Cache
Verso
X-Element-Page-Cache
MS-Author-Via
X-Upstream
X-FastCGI-Cache
X-Vcap-Request-Id
X-MS-InvokeApp
X-Amz-Rid
X-GitHub-Request-Id
Public-Key-Pins
X-Dw-Request-Base-Id
X-Cached
X-Client-IP
X-Abt-Application-Version
X-D2id
X-Cnection
RTSS
X-Px
X-Cache-TTL
X-Kinja
X-GoogleNews-Bot
X-Use-Magma
X-Kinja-Revision
X-Exp-Variant
X-Cdn-Fetch
X-Exp-Id
X-Kinja-Server
X-Kinja-Build
X-Navigation-Version
Arr-Disable-Session-Affinity
Access-Control-Request-Method
X-Country-Code
X-Powered-By-Plesk
X-Goog-Hash
X-NF-Request-ID
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Instrumentation
X-TTL
X-Powered-CMS
AR-SID
AR-ATIME
AR-Request-ID
AR-CACHE
AR-PoweredBy
X-Middleton-Display
Display
X-Sol
Pagespeed
X-Version
X-Origin-Cache
X-Middleton-Response
Response
X-LLID
X-MSEdge-Ref
X-Amz-Server-Side-Encryption
Nginx-Cache
TCN
X-Edge-Location-Klb
X-Kinsta-Cache
X-RateLimit-Remaining
X-Edge
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
X-Protected-By
X-CST
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-T
X-HP-Webp
X-Jurisdiction
X-HP-Trace-Id
X-Forwarded-For
X-Content-Security-Policy-Report-Only
Accept-Ch
X-Shield-Request-Id
X-Aspnetmvc-Version
X-Id
X-Mg-S
S
Edge-Cache-Tag
X-Language
Content-MD5
SPIisLatency
SPRequestDuration
Front-End-Https
Fastcgi-Cache
X-Mid
Realpath
X-Request-Processing-Time
X-Request-Received
Server-Node
Pinterest-Version
X-Recruiting
X-Pinterest-Rid
Filters
Pinterest-Generated-By
X-DynaTrace
X-Frontend
Server-Name
X-Ab
X-Ua-Browser
X-Content
X-MCACHE
X-Cache-Key
X-Ser
X-Correlation-Id
X-HS-Cache-Config
X-Ruxit-Js-Agent
X-HS-Content-Id
X-NWS-LOG-UUID
X-HS-Hub-Id
X-Template
X-Yandex-Sdch-Disable
X-HS-Combine-CSS
X-Ezoic-Cdn
SPRequestGuid
X-ECACHE
X-SharePointHealthScore
X-Hits
X-Parallel-Accel
X-Ttl
MicrosoftSharePointTeamServices
X-Kong-Proxy-Latency
X-Server-ID
X-Tt-Trace-Tag
X-Kong-Upstream-Latency
X-Tt-Trace-Host
Cache-Tags
Charset
X-Page-Id
Host
X-B3-Sampled
Alternate-Protocol
Cleartype
X-Www-Served-By
X-Git-Hash
X-Geo-Country
X-Content-Options
Fusion-Content-Id
Fusion-Component-Id
Fusion-Content-Source
Fusion-Template-Id
Fusion-Source
Fusion-Deployment-Id
X-Debug-Info
X-Daa-Tunnel
X-DIS-Request-ID
X-Hostname
X-Amzn-Trace-Id
X-Content-Digest
X-Amz-Replication-Status
Cross-Origin-Opener-Policy
X-Varnish-Age
X-Ratelimit-Limit
Filterid
X-Az
X-FB-Debug
X-AppVersion
X-Activity-Id
X-Upgrade-Enabled
X-Grace
X-VCache
X-Accel-Expires
X-Nginx-Upstream-Cache-Status
X-F-Cache
X-N
X-Origin-Server
ServerID
X-Forwarded-Proto
X-Rid
X-Fastly-Request-ID
X-Mobile-URL
Access-Control-Allow-Method
X-Request-Guid
X-Aspnet-Duration-Ms
X-Flags
X-Providence-Cookie
X-Route-Name
X-Is-Crawler
X-Type
X-LB-Cache
X-Whom
X-DataDome
X-TT
X-Goog-Storage-Class
X-Goog-Metageneration
X-Goog-Generation
X-Seen-By
X-App-Environment
X-Goog-Stored-Content-Length
X-Varnish-Grace
X-GUploader-UploadID
X-Fastcgi-Cache
X-Goog-Stored-Content-Encoding
X-Tb
X-WebKit-CSP-Report-Only
Payment
X-FW-Hash
X-FW-Serve
X-FW-Server
Viewport
X-FW-Type
X-FW-Static
X-FW-Dynamic
TP-Cache
Node
X-Distributor
TP-L2-Cache
X-User-Agent
DC
Paypal-Debug-Id
X-App-Server
Country
X-Wix-Request-Id
X-XRDS-LOCATION
Accept-Charset
X-Fastly-Request-Id
Fastcgi-Useragent
X-Litespeed-Cache
X-Cache-Control
X-Cache-Rule
X-NGENIX-Cache
X-Webkit-Csp
Version
X-Origin-Upstream-Status
X-Via-JSL
X-Webkit-CSP
X-Ratelimit-Reset
X-Drupal-Cache-Tags
X-Cluster-Name
X-Microsite
X-Buckets
Referer-Policy
X-Request-Handler-Origin-Region
X-Contextid
X-Cache-Age
X-Oracle-Dms-Ecid
X-Oracle-Dms-Rid
X-Logged-In
X-Tec-Api-Root
X-Tec-Api-Origin
Amp-Access-Control-Allow-Source-Origin
X-Tec-Api-Version
X-Signature
X-B-Cache
Cache-Status
X-Node-Name
X-Browser-Type
Refresh
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Original-Request-Id
X-Mobile
VIX-Pulpo-Node
SD-X-WS
X-Response-Served-From
VIX-Pulpo-Upstream-Status
X-Varnish-Backend
X-Cache-Expired-At
X-Page-View
X-Real-IP
X-Rendered-As
X-Vgn-Hpd-Reason
X-Load-Cache
X-Is-Bot
X-Revision
X-IPLB-Instance
X-Debug
Access-Control-Request-Headers
NGB
X-B
X-Proxy-Cache-Status
X-Cacheable-TTL
X-Jobs
X-Rule
X-UUID
X-Proxy
X-Device-Type
X-Cache-Action
X-ProcessESI
X-RemovedCookies
X-Yottaa-Metrics
X-Yottaa-Optimizations
Akamai-GRN
Surrogate-Key
X-Instance
X-Debug-IsPreview
X-Framework
X-Debug-IsConnected
X-Drupal-Cache-Contexts
X-Cache-Time
X-G
X-FW-Version
CF-IPCountry
SID
X-Accel-Buffering
X-Air-Source
X-Air-Hostname
GEO-INFO
X-Air-Trace-Id
X-TEC-API-ROOT
X-Oneagent-Js-Injection
X-TEC-API-VERSION
X-TEC-API-ORIGIN
DynaTrace
X-Cache-NGX
X-PressLabs-Stats
Count-Hit
X-Nginx-Cache
Uber-Trace-Id
X-Azure-Ref
X-Presslabs-Stats
X-Cache-Operation
X-Ms-Request-Id
X-Ms-Version
X-Source
Liferay-Portal
X-RateLimit-Limit
X-XRDS-Location
X-Zen-Fury
X-EdgeConnect-Cache-Status
Frame-Options
X-APP-VERSION
X-CDN-Forward
Protected
Ms-Operation-Id
MS-CV
X-RTag
X-Cache-Hit
Healthy
X-Backend-Name
X-Mode
Cross-Origin-Window-Policy
X-IPS-LoggedIn
Xserver
X-Environment-Context
Ec-Rule-Version
Countrycode
X-L-Path
X-Hyper-Cache
WPO-Cache-Status
X-Servername
X-Varnish-Server
WPO-Cache-Message
X-Cache-TTL-Remaining
X-Tumblr-User
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Ratelimit-Remaining
X-Adobe-Loc
X-Adobe-Content
LB
Backend
X-Detected-As
X-Content-Age
Content-Disposition
X-Tid
X-Region
X-SaId
Meta-Geo
X-JoinUs
X-Rewrite-Enabled
X-UPSTREAM-Address
X-RN-RSRV
X-Uri
X-Sql-Duration-Ms
X-Hosted-By
Apigw-Requestid
Country-Code
X-Generation-Time
Decoy-Debug-Status
X-Extlb
X-Routing-Service
X-Cache-Grace
X-ShopId
X-Shopify-Stage
X-Proxied
Decoy-Debug-TTL
X-ShardId
X-Redis-Cache
X-Alternate-Cache-Key
X-Sql-Count
X-Cache-Server
X-Zipkin-Id
X-Format
X-Debug-Cache
Decoy-Debug-Key
X-Forwarded-Host
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
Eomportal-Instance
CDN-Cache
CDN-RequestId
X-ApacheServer
CDN-EdgeStorageId
CDN-CachedAt
CDN-PullZone
X-Access
Mn-Server-Ip
CDN-Uid
CDN-RequestCountryCode
Fastly-SSL
X-PCL
X-Varnish-Beresp-Grace
X-Human
X-Site-Version
X-ServerID
X-Via-Fastly
X-Origin-Date
X-FB-TRIP-ID
Url
Cache-Name
X-Section
X-Status
X-Microcachable
X-PERF
X-NCache
X-No-Session
X-OCL
X-PHP-Backend
Property-Id
X-Timing-Wait
X-Cluster-Node
X-Content-Powered-By
X-UA-Device-Type
X-Akamai-Edgescape
X-Web-Node
X-Generated-By
X-SayCDN-TTL
X-Say-TTL
X-NYM-Debug-Backend
Selected-Fe
X-Storage
Webcakes-App-Version
Webcakes-App-Name
X-Server-W
Webcakes-Region
X-ProxyCache-Status
X-Proxy-Build
X-ProxyCache-Key
X-Origin-Hint
X-Cache-Type
TWC-Device-Class
X-BYPASS-REASON
TWC-GeoIP-Country
TWC-GeoIP-LatLong
TWC-Privacy
TWC-Locale-Group
TWC-Connection-Speed
X-Say-Cacheable
Section-Io-Cache
Cache-Tv-Group
X-Trace-Id
X-Pubstack
X-Cache-Host
X-Soup
X-Hl-Ver
X-R9-Blue-Green-Version
X-Be
X-Varnishpool
Azure-SiteName
Azure-InstanceId
Azure-SlotName
Azure-Version
Azure-RegionName
X-LSADC-Cache
Retry-After
DB-Nickname
X-TIME
X-NewRelic-App-Data
X-Ua
X-Nginx-Cache-Key
Content-Secure-Policy
OT-Force-Account-Verify
X-Unique-Id
X-Azure-Ref-OriginShield
X-Cached-By
X-Cache-Remote
X-Bc-Bl
X-TT-LOGID
Source
X-Platform-Server
X-Auto-Login
X-Akamai-Transformed
Cache
X-Dc
X-GEO
X-Xfnlog-Site
SRV
X-LAGOON
X-Cdn
X-Cache-Tags
Upgrade-Insecure-Requests
ServedBy
HostName
Mime-Version
X-Origin-TTL
X-Origin-CC
X-Varnish-Cache-Hits
X-Varnish-Hits
Cache-Hits
From-Origin
X-Loop
X-TNCMS
X-App-Version
X-Varnish-Hostname
X-EC-Lua
X-Request-Time
X-HTML-Minification-Powered-By
X-CSRF-Token
Onion-Location
X-Time
X-AOL-HN
X-S-Maxage
Xet-Cookie
WP-Super-Cache
X-Request-Host
X-SRV
X-NWS-UUID-VERIFY
Webserver
X-ECache
X-Xrds-Location
N-Cache
X-Proto
X-Cache-Enabled
X-B3-SpanId
X-Tumblr-Pixel-3
X-Tumblr-Pixel-2
X-FireWall-Port
X-Endurance-Cache-Level
X-Handled-By
X-Amz-Meta-S3cmd-Attrs
Web-Mar-Node
X-Tenant
X-Correlation-ID
Nel
X-VWS-Id
X-LJ-Flow-ID
X-Origin-Response-Time
X-AWS-Id
Fastcgi-X-Cache-Version
DCR-Decision-By
X-Destination
Redirect-Candidate
X-Connection-Hash
Xc-Version
X-CF-Lambda-Version
Expiry
X-Ckpd-Fst-Backend
X-Conf
Mobile-Detection-Method
X-D
Odigeo-Trace-Id
DCR-Processing-Time-Ms
X-Cluster
X-CF-Lambda-Fn
Pramga
Meta-Geo-Continent
BehaviorPad-Version
X-RCS-CacheZone
X-A-Wwc
X-Aed
X-Application
X-ARC
X-A-Dgt
X-A-Dcw
X-Reqid
X-A
X-A-Ccd
X-A-Dam
X-B-Cookie
X-Backend-TTL
X-Adobe-Source
Sslversion
S-Rt
X-Cache-NE
Surrogated-Key
User-Cache-Control
A
X-Block-Status
Vix-Hermes-Req-Id
V-Age
Rendered-Blocks
X-Gen-Mode
X-Planisys-CDN-TTL
X-Processor
X-Rojux
X-S
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
X-NAPM-TraceId
X-ND-Cache
X-PAYTM-SRV-ID
X-PBS-Appsvrname
X-S-Cookie
X-ScT
X-TIM-N
X-V-Cache
X-Vdms-Path
X-Vdms-Version
X-VG-WebCache
X-SRCache-Key
X-SD-PageType
X-Session-Fingerprint
X-Shop-Environment
X-Slack-Backend
X-Ig-Push-State
X-Orig-Expires
X-Vtex-Processado-Em
X-GG-Cache-Date
X-Ftr-Request-Id
X-Hnp-Log
X-Forwarded-Path
X-External-Request-Id
X-Developer
X-Vtex-Remote-Cache
X-Time-Microsecs
X-Epic-Correlation-Id
X-Edge-Location
X-Mg-Request-UUID
X-MP-GENERATED-AT
X-Magnolia-Registration
X-Fastly-Cache
X-Gdpr
X-Scheme
X-SVT-ORM-VERSION
Gh-Request-Id
Wxu-Next-Hostname
X-VG-TLSProxy
X-SVT-ORM-RULES
Wxu-Next-Commit
X-Forwarded-Site
State
X-Geo-Header
X-Date
Origin
X-Server-IP
X-Sucuri-Cache
True-Client-Country-4JS
Svr
X-Sucuri-ID
X-Request-URI
X-Mvc-Supplant-Cachable
X-Men
X-Cdn-Srv
X-Viewer-Country
X-NodeID
X-Location
X-Cache-Bucket
X-Cache-Info
X-Li-Fabric
X-Li-Pop
X-LI-UUID
X-Cache-Date
X-Aicache-OS
X-Nyt-Route
X-GeoIP-Country-Code
X-GeoIP-Region-Code
X-Policy
X-Proxy-Upstream
X-Rocket-Nginx-Serving-Static
Fastcgi-Cache-TTL
X-Hash
X-Webstats-RespID
X-Old-Content-Length
X-Origin
X-Accel-Expires-Debug
X-Origin-Time
Wxu-Next-Region
Host-ID
X-Origin-Expires
Apple-News-Services-Parsed-Url
DSUID
Cmsid
AKAMAI
Apple-News-Services-Host
Apple-News-Services-Request-Url
X-Akamai-Request-ID2
Cmstype
CDCHOST
X-Http-Reason
CacheControlHeader
Arc-Country
Apple-News-Services-Handled
Environment
X-Cache-Var
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Cache-Var-Map
X-Labrador-Cache-Channel
CloudFront-Viewer-Country
X-PHP-Host
Server-Info
X-Via-NSCOPI
X-Fetched-On
X-GeoIP
X-Eu-Site
X-Esi-Check
X-Developers
L5d-Success-Class
X-Gamma-Serve
X-UnsetCookies
X-Gzip
X-Varnish-Beresp-Ttl
X-Generated-On
X-GeoIP-City
X-Device-Os
X-Datadog-Trace-Id
X-Cache-Id
X-Fastly-Backend
X-Cache-Debug
X-Varnish-Beresp-Status
X-Branch-Name
Fastly-Drupal-Html
X-CGP
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
X-Csrf-Jwt
X-Core-Value
X-TrackingId
X-HN
X-TH-Server
X-Served-From
X-Sn-Servicetimems
X-Rocket-Build-Number
X-Req
Fastly-GeoIP-CountryCode
X-Sigma
Ha-Gx-Prefs
X-Storefront-Renderer-Rendered
HA-Ipaddr
X-Skip-Cache
X-Sigma-Backend
X-Region-Sid
X-RateLimit-Remaining-Second
X-Core-Mission
L
X-Level-Front-Cache
X-Irp-Debug
X-HS-Content-Campaign-Id
X-Locale
X-Cdn-Origin
X-RateLimit-Limit-Second
X-Platform
X-VServer
X-Owner
X-BBC-Edge-Cache-Status
X-Envoy-Decorator-Operation
Magicmarker
Req-Svc-Chain
Machine
Locid
We-Hiring
Mail-Subject
Ssr
Origin-EX
Origin-CC
Server-Host
Release
X-VarnishDD-TTL
X-Backend-State
Traceparent
PFcat
Fastly-SWR
X-NU-AKA-ACS-Version
X-JWT-State
Memcached
X-FC-Vary-Parameters
X-Qloud-Router
X-Worker
Web-Mar-Region
X-Restarts
X-Varnish-CookieHashed-On
X-Node-Id
X-Thinkindot-L3
X-Varnish-Remaining-TTL
X-ATG-Version
Adler-Geo
X-Variation
X-Varnish-CookieINHashed-On
X-Loc
NM-Fastcgi-Cache
Thinkindot-CacheControl
X-Pod-Name
TDXMobile
NGX
X-DefElseHash
Is-Eu
Cf-Device-Type
Fastly-SIE
Thinkindot-Control
X-Has-Esi
X-DPWN-IS-SECURE
X-Is-Gdpr
X-Rebelmouse-Cache-Control
X-Tx-Id
X-DefHash
X-Amzn-Remapped-Content-Length
X-Response-By
Thinkindot-CacheControl-Type
X-Rebelmouse-Surrogate-Control
Platform
X-Ua-Device
X-Trace-ID
X-VC-Cache
X-NODE
Kp-EeAlive
X-Request-Start
AMP-Access-Control-Allow-Source-Origin
X-Zone
X-CS
Edge-Cache
X-Bip
X-RPM
X-DSS
X-Wix-Viewer-Type
X-Qnm-Cache
CDN
X-M-Reqid
X-Mvc-Supplant-OutputCached
X-Thanos
X-DW
X-Action
X-Up
X-DB
X-M-Log
X-RSL
X-RPS
X-DI
X-LB-ID
Accept-Language
X-Cache-Backend
Pics-Label
X-Srv
X-LB-NoCache
X-Generated-In
X-API-Version
X-TraceId
Ms-Author-Via
X-NC
X-Tb-Optimization-Total-Bytes-Saved
X-Minions-Version
X-CacheTTL
Memory
Env
Time
X-Cache-Config
X-Optimistic-Header
X-Edge-Pop
X-Via-Poph
WebServer
X-Via-Popn
X-DC
X-Varnish-Ttl
X-Refresh
X-Via-Popv
X-Urbn-Context-Path
Locale
X-Urbn-Site-Id
X-Tt-Logid
X-Cache-Ttl
X-HA-Backend
GeoIp-Country-Code
Candidate-Md5Url
NtCoent-Length
X-CACHE-KEY
Datacenter
X-Datadome
X-ZONE
X-Esi
X-TA-CDN-Provider
X-User
Server-ID
X-Ec-Fail
X-Ec-GeoHdr
X-Servedbyhost
X-DynaTrace-JS-Agent
X-Parent-Response-Time
X-Vc
WWW-Authenticate
On-Server
X-MSEdge-Features
X-MSEdge-Flight
X-Cs
X-CLOUD-TRACE-CONTEXT
Esi-Enabled
X-TX-ID
Cdncip
Cdnsip
X-AK-Request-ID
X-Webkit-CSP-Report-Only
X-Unique-ID
X-VCL-Version
X-Varnish-Beresp-TTL
X-Traceid
X-Cache-PHP
C-Via
X-Fpc
X-LI-Proto
X-App
X-Service
X-Fmm-Version
X-WADP-Cache
Cluster
X-Clara-WADP
My-App
X-URL
Geoip-Latitude
X-CUA
X-Dynatrace
X-Webkit-Csp-Report-Only
X-Var-Ttl
X-Li-Proto
Tracecode
X-Newrelic-Synthetics
X-Pass-Why
X-From
T-Server
Test
DataCenter
X-B3-Spanid
X-FPC
Lfy
Proxy-Connection
Cf-Int-Pingora-Origin-Digest
X-Render-Time
X-Cache-Status-Check
Lang
X-Fragments
Fastly-Drupal-HTML
X-VC
X-Vcl-Version
X-Mcache
Geo-Info
X-LiteSpeed-Cache-Control
M-TraceId
Target-Params
Resin-Trace
Server-Id
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
X-CSRF-TOKEN
X-Ha-Backend
X-Provided-By
X-RAMCache
GeoIP-Country-Code
X-ID
MIME-Version
Hostname
Permissions-Policy
X-Clientip
X-ServedByHost
X-Api-Version
Hit
X-Dynatrace-Js-Agent
X-Geo
Servername
HIT
X-Oss-Hash-Crc64ecma
X-Edge-POP
X-Httpd
Cache-Host
X-Via-PopH
UCS
Producers
X-Oss-Server-Time
X-Proxy-Cache-Info
X-Oss-Request-Id
X-RateLimit-Reset
X-Oss-Storage-Class
X-Cdn-Forward
X-Via-PopN
X-Oss-Object-Type
X-LiteSpeed-Tag
X-Via-PopV
X-Pad
WZWS-RAY
X-AIR-PT
X-Info
S-Cnection
X-Edge-Cache
X-Fastly-Backend-Reqs
X-SB
Section-Io-Id
Section-Io-Origin-Status
FSS-Cache
X-NGINX-Cache
Section-Origin-Responded
ENV
Section-Io-Origin-Time-Seconds
X-Pool
X-Ucs
X-Platform-Processor
X-Platform-Cluster
X-Check-Cacheable
X-ElasticPress-Query
X-Platform-Router
Ohc-File-Size
X-Udemy-Cache-App-Namespace
X-BBC-Origin-Response-Status
X-Scale
URI
X-Lb-Nocache
X-Acquia-Purge-Tags
ServerName
User-Agent
X-Nc
X-UP
Uri
X-Cache-CFC
Fastly-Backend-Name
X-Ec-Custom-Error
X-Acquia-Application-UUID
X-GoCache-CacheStatus
X-HS-Status
X-Acquia-Site
PICS-Label
X-Micro-Cache
X-Acquia-Application-Trace
X-Srcache-Store-Status
X-Srcache-Fetch-Status
X-SIPLIST1
X-Cdn-Request-ID
Sever-Int
X-Dispatcher-Number
Tcn
X-Backend-Host
X-Cache-Expires
Cteonnt-Length
X-ServerName
Server-Ext
X-Release
Load-Balancing
MD5-Digest
X-Fastly-Cache-Hits
X-Lb-Id
Server-Hostname
Cneonction
X-Swift-Error
IsBot
Server-Ttl
X-Dw-Trace-Id
X-Akamai-ERRuleID
X-Akamai-ERPolicy
X-Snapshot-Date
X-Via-Ucdn
Shield-Pop
Wpo-Cache-Status
Wpo-Cache-Message
EpKe-Alive
Vha6-Origin
CF-Cached-On
X-B3-ParentSpanId
X-Vcache
X-Newrelic-App-Data
X-Cache-ASPX
X-Yottaa-OS
X-BCube-Filmed-By
X-APP
Cf-Ipcountry
X-TRACE-ID
X-Contensis-Viewer-Groups
Cdn
X-Air-Pt
X-Cache-Ngx
X-HostName
Sid
X-B3-Parentspanid
X-Apw-Hits
Path
Ohc-Cache-HIT
X-Apw-Access-Token
X-IN-APIGATEWAY
GeoIP-Latitude
X-Cms-Context
X-Fetch-By
X-Varnish-Authentication
X-Litespeed-Cache-Control
X-IN-APIGATEWAYSSL
X-Apw-Access-Action
X-Apw-Access-Object
X-Shopify-Generated-Cart-Token
Ngx
X-Sentry-ID
X-Http-Count
X-Http-Duration-Ms
X-Te-Duration-Ms
X-Te-Count
CountryCode
Req-ID
X-CacheKey
X-Logging-Id
X-UA
X-Akamai-Request-ID
X-Akamai-Pragma-Client-IP
X-Last-Modified