Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
X-Powered-By
Pragma
X-XSS-Protection
X-Cache
CF-RAY
Via
Age
Content-Security-Policy
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
Alt-Svc
X-Xss-Protection
P3P
X-Cache-Hits
X-UA-Compatible
CF-Ray
X-Served-By
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
Access-Control-Allow-Credentials
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
X-Drupal-Cache
X-Cache-Status
X-Generator
X-Check
X-Cacheable
X-FRAME-OPTIONS
X-Envoy-Upstream-Service-Time
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Iinfo
X-Dns-Prefetch-Control
X-Drupal-Dynamic-Cache
Feature-Policy
X-Content-Security-Policy
X-XSS-PROTECTION
Content-Encoding
Access-Control-Expose-Headers
Server-Timing
Upgrade
Status
X-CDN
X-Request-ID
X-AspNetMvc-Version
Access-Control-Max-Age
X-Amz-Request-Id
X-Amz-Id-2
Request-Context
X-Via
X-Turbo-Charged-By
X-AH-Environment
X-Cache-Group
X-Backend
X-Robots-Tag
Cf-Edge-Cache
Keep-Alive
Host-Header
X-Hacker
X-Proxy-Cache
X-Server
X-Vhost
X-Rq
X-UA-Device
X-Server-Powered-By
Allow
X-Age
X-Ws-Request-Id
X-Varnish-Cache
X-Dispatcher
X-Amz-Version-Id
EagleId
P3p
Nel
Grace
Cf-Apo-Via
X-LiteSpeed-Cache
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
Cf-Railgun
X-Page-Speed
X-Device
EagleEye-TraceId
X-OneAgent-JS-Injection
X-Aws-Lambda-Call-Status
X-Swift-SaveTime
X-Swift-CacheTime
X-Pingback
Ali-Swift-Global-Savetime
X-Host
X-Node
Accept-CH
X-Backend-Server
X-CST
X-WebKit-CSP
X-Cache-Lookup
Surrogate-Control
X-Server-Id
X-Nginx-Cache-Status
X-Readtime
Permissions-Policy
Accept-CH-Lifetime
X-Akam-SW-Version
X-Nginx-Upstream-Cache-Status
Request-Id
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Application-Context
X-Content-Security-Policy-Report-Only
X-Cloud-Trace-Context
X-Ua-Compatible
X-Trace
X-HW
X-Response-Time
X-Edge
Content-Location
Xkey
X-Clacks-Overhead
X-Mod-Pagespeed
X-Ruxit-JS-Agent
X-Litespeed-Cache
Rating
X-Midtier
X-ESI
X-Url
X-Amz-Server-Side-Encryption
X-ECACHE
X-Mcache
Accept-Ch
X-Upstream
Cache-Tag
X-Vcap-Request-Id
X-MS-InvokeApp
X-D2id
X-Rack-Cache
Verso
X-Powered-By-Plesk
X-Element-Page-Cache
X-Kinja
X-Kinja-Build
X-Cdn-Fetch
X-Exp-Id
X-Kinja-Server
X-Exp-Variant
X-GoogleNews-Bot
X-Kinja-Revision
Edge-Control
X-Use-Magma
Accept-Ch-Lifetime
X-WebKit-CSP-Report-Only
X-Ruxit-Js-Agent
X-Country
RTSS
X-TtlSet
X-PC
X-Vname
Fastly-Restarts
X-Cache-TTL
X-Ac
Origin-Trial
X-VARITI-CCR
X-Country-Code
Service-Worker-Allowed
X-Navigation-Version
X-Abt-Application-Version
X-Goog-Hash
X-Varnish-TTL
X-GitHub-Request-Id
X-Aspnetmvc-Version
X-Cached
X-Oneagent-Js-Injection
X-Browser-Type
X-Amz-Rid
X-Webkit-CSP
Display
Pagespeed
X-Middleton-Display
X-Sol
Cross-Origin-Opener-Policy
X-Ttl
X-SharePointHealthScore
SPRequestGuid
X-Server-Name
X-Dw-Request-Base-Id
X-Amzn-Trace-Id
X-Mg-S
X-Kinja-CCPA
X-Powered-CMS
X-B3-TraceId
X-Content-Type
Arr-Disable-Session-Affinity
X-Erf-Bev-Bev
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Instrumentation
X-Erf-Bev-Bev-Is-Generated
AR-SID
AR-PoweredBy
AR-ATIME
AR-Request-ID
SPRequestDuration
X-Middleton-Response
SPIisLatency
Response
X-Cache-Key
X-NWS-LOG-UUID
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
X-NF-Request-ID
X-Times
X-Version
X-FastCGI-Cache
X-Pinterest-Rid
Pinterest-Version
Pinterest-Generated-By
X-HP-Webp
X-Jurisdiction
X-HP-Trace-Id
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Fastly-Request-ID
AR-CACHE
X-Accel-Expires
X-Cnection
X-T
Cache-Tags
X-Client-IP
Nginx-Cache
Cache-Status
Front-End-Https
X-Ua-Device
Edge-Cache-Tag
X-RateLimit-Remaining
X-MSEdge-Ref
X-Ser
X-Hits
X-B3-Traceid
X-Px
Public-Key-Pins
Payment
X-RateLimit-Limit
X-B3-TraceId-Primal
X-Recruiting
MRF-Tech
Mrf-Cache-Status
X-LLID
X-Request-Received
X-Request-Processing-Time
Server-Node
X-Ua-Browser
X-Frontend
X-Server-ID
X-Shield-Request-Id
X-DIS-Request-ID
S
X-GUploader-UploadID
X-Goog-Metageneration
TP-Cache
Content-MD5
MicrosoftSharePointTeamServices
Access-Control-Request-Method
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Erf-Stays-Pdp-Viaduct-Migration-Web
X-Content-Digest
X-HS-Combine-CSS
X-HS-Cache-Config
X-HS-Content-Id
X-HS-Hub-Id
X-Microsite
X-PressLabs-Stats
X-Request-Handler-Origin-Region
X-Protected-By
X-Distributor
X-LB-Cache
X-Page-Id
Fastcgi-Cache
Access-Control-Allow-Method
Realpath
Accept-Charset
TP-L2-Cache
X-Rid
X-FB-Debug
X-Forwarded-For
X-Cluster-Name
X-Fastcgi-Cache
X-Geo-Country
X-Ezoic-Cdn
X-Webkit-Csp
X-Hostname
X-Aspnet-Version
X-TTL
X-Daa-Tunnel
X-B3-Sampled
X-Seen-By
X-Goog-Storage-Class
X-Goog-Generation
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
Cleartype
Cross-Origin-Resource-Policy
TCN
X-Correlation-Id
X-Ratelimit-Remaining
X-Mobile
Referer-Policy
Count-Hit
DC
X-Envoy-Decorator-Operation
X-Content-Options
X-Newrelic-App-Data
X-Varnish-Backend
X-Logged-In
X-Debug-Info
X-App-Server
X-Origin-Cache
X-Contextid
X-Hosted-By
X-Providence-Cookie
X-Request-Guid
X-Route-Name
X-Varnish-Grace
X-Amz-Replication-Status
X-App-Environment
X-COUNTRY
X-Git-Hash
X-Grace
X-Aspnet-Duration-Ms
X-Flags
X-Is-Crawler
X-Kinsta-Cache
Surrogate-Key
X-Edge-Location-Klb
X-Revision
Frame-Options
X-IPS-LoggedIn
X-Fb-Rlafr
X-Ratelimit-Limit
X-TT
X-Azure-Ref
X-Amz-Meta-S3cmd-Attrs
X-Forwarded-Proto
X-TEC-API-ORIGIN
X-RateLimit-Reset
X-TEC-API-ROOT
Retry-After
X-TEC-API-VERSION
X-Origin-Server
X-F-Cache
X-Wix-Request-Id
WPO-Cache-Message
WPO-Cache-Status
Alternate-Protocol
X-Magnolia-Registration
Healthy
X-Whom
X-XRDS-Location
Section-Io-Cache
Charset
X-Id
X-Client-Ip
MS-Author-Via
X-Akamai-Edgescape
Viewport
X-Backend-Name
X-Proxy-Cache-Info
Paypal-Debug-Id
X-App-Version
X-B
SRV
X-AppVersion
X-Az
X-Activity-Id
X-Webkit-CSP-Report-Only
ServerID
Amp-Access-Control-Allow-Source-Origin
X-Language
X-Www-Served-By
SD-X-WS
X-N
X-DataDome
Akamai-GRN
X-Instance
X-Response-Served-From
X-Original-Request-Id
X-Rule
X-Http-Reason
Filterid
X-UUID
X-Cache-Rule
X-ARC
X-Akamai-Request-ID2
X-Cache-Grace
X-Edge-Location
X-Framework
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
Fastly-SIE
Country
Fastly-SWR
Front
Protected
X-FW-Hash
X-FW-Serve
X-Status
X-Rocket-Nginx-Serving-Static
X-Unique-Id
X-User-Agent
X-Varnish-Age
X-Rendered-As
X-Page-View
X-FW-Static
X-FW-Server
X-FW-Type
X-FW-Version
X-Is-Bot
Host
X-FW-Dynamic
X-EdgeConnect-Cache-Status
Server-Name
X-Varnish-Server
X-Adobe-Content
X-Cacheable-TTL
X-Adobe-Loc
X-Load-Cache
From-Origin
X-Tumblr-Pixel
X-Region
X-Tumblr-Pixel-1
X-Tumblr-User
X-Tumblr-Pixel-0
Access-Control-Request-Headers
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-G
X-ProcessESI
X-RemovedCookies
X-Trace-Id
X-Jobs
X-Environment-Context
X-Type
X-Cache-Time
X-L-Path
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
X-Datadog-Trace-Id
X-Xrds-Location
X-Cache-Control
X-Proxy
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Vcache
X-Mg-Request-UUID
X-Amzn-Remapped-Content-Length
X-ECache
X-Datadog-Sampled
Refresh
X-CDN-Forward
X-Signature
X-Time
X-Debug-IsConnected
X-Debug-IsPreview
X-B-Cache
Content-Disposition
X-Tec-Api-Version
X-Cache-Age
X-Tec-Api-Root
X-Tec-Api-Origin
X-Erf-Web-Scheduler
X-WP-CF-Super-Cache-Cache-Control
X-Drupal-Cache-Tags
X-WP-CF-Super-Cache
Backend
Accept-Language
Countrycode
X-Source
X-DynaTrace
Webserver
Xet-Cookie
X-Generated-By
X-HTML-Minification-Powered-By
CF-IPCountry
X-Httpd
X-DynaTrace-JS-Agent
X-Servername
X-Tt-Trace-Tag
Url
Version
X-Tt-Trace-Host
X-Mode
X-Nf-Request-Id
X-Device-Type
X-Nginx-Cache
X-Storage
X-NYM-Debug-Backend
Xserver
GEO-INFO
X-Template
X-Content-Powered-By
X-Oracle-Dms-Ecid
X-Say-Cacheable
X-XRDS-LOCATION
X-Proto
Filters
X-Oracle-Dms-Rid
X-Upgrade-Enabled
X-GeoCode
OT-Force-Account-Verify
X-JoinUs
Azure-SlotName
X-Content-Age
X-Director
X-SaId
X-Say-TTL
X-Cache-Operation
X-GeoCountry
X-SayCDN-TTL
X-URL
Load-Balancing
Azure-SiteName
Azure-InstanceId
Azure-Version
X-Rewrite-Enabled
X-UPSTREAM-Address
Azure-RegionName
Meta-Geo
X-Tb
X-LAGOON
X-Labrador-Cache-Channel
X-Container-Uri
X-Cluster-Node
X-Generation-Time
X-Urbn-Context-Path
X-PHP-Host
Onion-Location
X-RM-Cache-TTL
Locale
X-MCACHE
X-Cache-Action
X-Varnish-Cache-Hits
X-VC-Cache
X-Soup
Uber-Trace-Id
X-Git-Commit
X-Urbn-Site-Id
X-Adobe-Source
Web-Mar-Node
X-Tt-Logid
X-VCT
X-Cache-Server
X-Forwarded-Host
X-Sql-Duration-Ms
X-Served-From
X-Ms-Version
X-LSADC-Cache
X-Sql-Count
X-Detected-As
X-Varnish-Hostname
X-Ms-Request-Id
Mn-Server-Ip
Node
X-Zen-Fury
X-Tumblr-Pixel-2
X-Logging-Id
DB-Nickname
Property-Id
X-Origin-Hint
X-ServerID
X-RCS-CacheZone
X-FB-TRIP-ID
TWC-Privacy
Webcakes-App-Name
Webcakes-App-Version
X-Debug
Webcakes-Region
X-Format
TWC-Locale-Group
TWC-Device-Class
TWC-Connection-Speed
X-Tumblr-Pixel-3
X-Rn-Rsrv
TWC-GeoIP-LatLong
X-R9-Blue-Green-Version
S-Rt
TWC-GeoIP-Country
X-Proxy-Build
X-Proxied
X-Fetched-On
X-Extlb
X-Routing-Service
X-Skip-Cache
X-Lambda-Id
X-Zipkin-Id
Fastcgi-Useragent
X-Sucuri-Cache
Selected-Fe
X-Timing-Wait
X-Loop
X-Tncms
X-Uri
X-CCDN-CacheTTL
X-Sucuri-ID
X-CCDN-Origin-Time
X-Hcs-Proxy-Type
X-ID
X-Ua
X-Cache-Hit
X-Drupal-Cache-Contexts
X-Endurance-Cache-Level
Source
X-B3-SpanId
Cross-Origin-Window-Policy
CDN-RequestId
X-Redis-Cache
Liferay-Portal
X-Origin-Date
X-Srv
X-TimeS
Section-Origin-Responded
X-MP-GENERATED-AT
Section-Io-Origin-Time-Seconds
Section-Io-Id
Section-Io-Origin-Status
Fastly-Drupal-HTML
X-Varnish-Hits
X-Pass-Why
X-S
X-Cache-Expired-At
X-CACHE-AGE
X-Akamai-Transformed
Upgrade-Insecure-Requests
X-Origin-CC
X-Origin-TTL
X-Real-IP
X-UA-Device-Type
X-Ratelimit-Reset
X-Fastly-Request-Id
X-Cache-TTL-Remaining
X-Newrelic-Synthetics
Content-Secure-Policy
X-Node-Name
X-NGENIX-Cache
X-TIME
X-Pubstack
X-Handled-By
X-Varnish-Ttl
X-Hl-Ver
NGB
X-GEO
X-Via-JSL
CDN-PullZone
CDN-EdgeStorageId
CDN-CachedAt
CDN-Cache
X-Server-W
CDN-RequestPullCode
CDN-Uid
CDN-RequestCountryCode
CDN-RequestPullSuccess
X-RTag
X-Cms-Context
Ms-Operation-Id
X-Reqid
X-Restarts
X-Xfnlog-Site
MS-CV
X-Optimistic-Header
X-Parent-Response-Time
X-Cache-Type
X-IPLB-Request-ID
X-IPLB-Instance
WP-Super-Cache
X-Vcl-Version
ServedBy
Apigw-Requestid
Candidate-Md5Url
BehaviorPad-Version
Canary
Rendered-Blocks
X-Tx-Id
X-ProxyCache-Key
X-No-Session
X-ProxyCache-Status
Redirect-Candidate
Sslversion
Surrogated-Key
T-Server
DCR-Decision-By
L
True-Client-Country-4JS
N-Cache
HA-Ipaddr
L5d-Success-Class
Lang
Mail-Subject
Magicmarker
MD5-Digest
Meta-Geo-Continent
Ha-Gx-Prefs
Gh-Request-Id
Fastly-GeoIP-CountryCode
Fastly-Backend-Name
DCR-Processing-Time-Ms
CPC-Cache
Origin-Agent-Cluster
Odigeo-Trace-Id
Gannett-Cam-Experience-Id
Fastly-SSL
Ngx.Var.Host
CPC-Age
X-Application
X-Gdpr
X-Wikidot-Backend
X-We-Are-Hiring
X-Nyt-Route
X-Origin-Time
X-Orig-Expires
X-Forwarded-Path
X-FC-Vary-Parameters
X-Ec-Fail
X-Ec-Custom-Error
X-Ec-GeoHdr
X-Epic-Correlation-Id
X-External-Request-Id
X-Eu-Site
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Var-Ttl
X-Tenant
X-Vdms-Path
X-Vdms-Version
X-Vtex-Remote-Cache
X-Viewer-Country
X-SRCache-Key
X-Shop-Environment
X-Rojux
X-Request-Host
X-S-Cookie
X-ScT
X-SD-PageType
X-Developer
X-Destination
X-A-Dcw
X-A-Dam
X-A-Dgt
X-A-Wwc
X-Worker
X-Aed
Xc-Version
X-A-Ccd
W
VNS-Cache
We-Hiring
Web-Mar-Region
X-A
X-B-Cookie
X-Bc-Bl
X-Conf
X-CGP
X-Csrf-Jwt
X-D
X-Debug-Cache-Store
X-Debug-Cache-Fetch
X-CF-Lambda-Version
X-CF-Lambda-Fn
X-Bl-Debug
X-BCube-Filmed-By
X-Wikidot-Static-Cache
X-Cache-NE
X-Cdn-Diag
VNS-Age
X-App
X-BYPASS-REASON
Cache-Provider
X-CSRF-Token
X-Geo-Header
X-Generated-On
Platform
X-GeoIP-Country-Code
X-GeoIP-Region-Code
Producers
Req-Svc-Chain
X-Fastly-Backend
X-Esi-Check
X-AIR-PT
Server-Host
X-Gzip
Release
Origin
Machine
X-Loc
X-Mly-Id
X-Mvc-Supplant-Cachable
Is-Eu
X-Level-Front-Cache
Memcached
X-Human
X-INCAP-ABP
X-Irp-Debug
X-Cluster
X-DPWN-IS-SECURE
X-DefHash
X-Cache-Debug
X-Cache-Bucket
X-Cache-Host
X-Cache-Id
X-Cache-Info
X-Bip
X-BBC-Edge-Cache-Status
X-App-Name
X-ApacheServer
X-Accel-Expires-Debug
X-Accel-Buffering
X-Auto-Login
X-CacheTTL
Vix-Hermes-Req-Id
X-Core-Value
TDXMobile
X-Date
X-DefElseHash
Host-ID
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
X-Correlation-ID
X-Clientip
X-CMSURLCustom
Thinkindot-Control
X-Dispatcher-Number
X-Mid
X-Varnishpool
X-Varnish-Remaining-TTL
X-Slack-Backend
Adler-Geo
X-VG-TLSProxy
Datacenter
X-Request-Time
X-Variation
X-VWS-Id
X-Slack-Shared-Secret-Outcome
Cf-Device-Type
X-Varnish-CookieHashed-On
X-Test
X-Thanos
X-Thinkindot-L3
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-Node-Id
AKAMAI
X-Varnish-CookieINHashed-On
X-Refresh
X-S-Maxage
X-PAYTM-SRV-ID
X-PERF
X-Qloud-Router
X-Old-Content-Length
X-Org
Cache-Name
X-Wix-Viewer-Type
Expect-Staple
X-LJ-Flow-ID
X-Pool
X-VServer
X-Vmg-Version
X-VG-WebCache
X-Policy
X-AWS-Id
X-NodeID
User-Cache-Control
X-Core-Mission
X-Nananana
X-WA-Info
X-Cdn-Origin
X-Datadome
X-Cdn-Srv
X-Block-Status
X-WADP-Cache
X-Clara-WADP
X-Sn-Servicetimems
X-Hnp-Log
X-Platform
X-Hash
X-Has-Esi
X-GeoIP
X-JWT-State
X-Owner
X-Nginx-Cache-Key
X-Nitro-Cache
X-Mvc-Supplant-OutputCached
X-Origin-Response-Time
X-Alternate-Cache-Key
X-Server-IP
X-ShardId
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Storefront-Renderer-Rendered
X-Device-Os
X-FTR-Request-ID
X-Fmm-Version
X-Forwarded-Site
X-ShopId
X-Gen-Mode
X-From
X-Shopify-Stage
X-Up
X-Is-Gdpr
CloudFront-Viewer-Country
CDCHOST
Sever-Int
X-Proxy-Cache-Status
Cmsid
Cmstype
Apple-News-Services-Handled
Apple-News-Services-Host
DSUID
Apple-News-Services-Parsed-Url
Esi-Enabled
Environment
Apple-News-Services-Request-Url
Hostname
Server-Hostname
Server-Ext
Ssr
Country-Code
X-Akamai-Device-Characteristics
Time
NM-Fastcgi-Cache
Cache-Hits
C-Via
Pics-Label
Wxu-Next-Hostname
X-NCache
X-Cache-Status-Check
Wxu-Next-Commit
X-Micro-Cache
X-Access
X-Origin
X-Amz-Meta-Cb-Modifiedtime
X-Op-Id-All
X-LB-NoCache
X-Presslabs-Stats
Memory
Wxu-Next-Region
X-Section
X-Cache-Enabled
X-Dispatcher-Server
NGX
X-Instance-Name
X-API-Version
AMP-Access-Control-Allow-Source-Origin
Server-Info
X-Dc
Origin-CC
X-CACHE-GROUP
X-Scale
X-PHP-Backend
Origin-EX
X-Via-Fastly
X-AB
X-B3-Spanid
X-TIM-N
Server-ID
X-Vgn-Hpd-Reason
X-Tb-Optimization-Total-Bytes-Saved
X-Wp-Cf-Super-Cache-Active
X-HA-Backend
X-Geo-Region
Location
X-Buckets
X-Air-Source
X-Air-Hostname
X-Varnish-Beresp-Ttl
X-Webkit-Csp-Report-Only
X-Platform-Router
X-Platform-Processor
X-Air-Trace-Id
X-Internal-Host
X-Accel-Version
X-ZONE
X-Varnish-Beresp-Grace
Cdn-Requestid
X-Platform-Cluster
X-TraceId
X-Cs
X-Azure-Ref-OriginShield
X-SIPLIST1
IsBot
X-Zone
X-B3-Parentspanid
X-WP-CF-Super-Cache-Active
GeoIP-Latitude
X-Backend-Instance
X-Is-Desktop
X-Tcp-Rtt
X-Is-Mobile
X-Is-Tablet
X-Browser-Name
X-Is-Supported-Browser
Cache-Host
Sid
X-Fpc
X-Origin-Expires
X-DataCenter
Resin-Trace
YJS-ID
X-Microcachable
CF-Ctrl
X-Web-Node
X-DC
Uri
X-NGINX-Cache
XM
X-Info
X-TA-CDN-Provider
X-LiteSpeed-Cache-Control
X-Pod-Name
PFcat
X-NewRelic-App-Data
X-HN
X-VarnishDD-TTL
X-Cached-By
User-Agent
Epwk-X-Cache
X-Nitro-Cache-From
X-Nitro-Rev
X-Ad-Defer-Variation
GeoIp-Country-Code
X-Frame-Option
X-Via-Edge
Edge-Copy-Time
X-Via-SSL
X-Via-CDN
A
X-Hyper-Cache
X-Site-Version
X-Locale
True-Client-Ip
Srvid
X-FL-QIT-DEBUG
X-FL-EDGE
Locid
X-VCache
X-CS
X-Webstats-RespID
X-Github-Request-Id
XServer
GeoIP-Country-Code
True-Client-IP
X-CSRF-TOKEN
X-ATG-Version
X-Service
Cdn
SID
X-FireWall-Port
X-Varnish-Authentication
X-Moov-T
X-Contensis-Viewer-Groups
X-Cache-ASPX
X-Moov-Xdn-Version
X-Geo
X-VC
X-TRACE-ID
X-MSEdge-Features
X-Origin-Cache-Key
Cache-Key
X-MSEdge-Flight
X-Datacenter
X-Country-Code-Real
LB
X-SRV
X-FTR-Cache-Status
X-FTR-Balancer
X-FTR-Expires
X-FTR-Backend
X-FTR-Backend-Server
X-Edge-Server
X-Vercel-Id
Cdn-Host
X-FPC
X-Vercel-Cache
Cdn-Request-Time
X-Pad
Fastly-Drupal-Html
Path
X-HostName
Tcn
M-TraceId
X-LiteSpeed-Tag
Req-ID
NtCoent-Length
WZWS-RAY
X-Api-Version
X-Upstream-Ct
X-Cdn-Request-ID
Cf-Ipcountry
X-Upstream-Ht
X-APP-VERSION
CountryCode
X-Planisys-CDN-Cache
X-Esi
X-Air-Pt
X-Ad-Load-Variation
Cluster
X-NMSegId
X-WP-CF-Super-Cache-Cookies-Bypass
X-HS-Content-Campaign-Id
Cdncip
State
X-Planisys-CDN-TTL
X-Amz-Meta-Opti
X-AK-Request-ID
X-Planisys-CDN-Rules
X-Platform-Server
Cdnsip
X-M-Log
X-M-Reqid
WebServer
X-Cache-Ttl
Content-Script-Type
X-NWS-UUID-VERIFY
X-Branch-Name
Content-Style-Type
X-Release
X-Vgn-Hpd-Variations-Key
X-Wp-Cf-Super-Cache-Cache-Control
Pramga
X-Vgn-Hpd-Ssi
X-Scope-Id
X-Wp-Cf-Super-Cache
X-Vgn-Hpd-Cached
X-Fastly-Cache
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-Shield-Cache-Expires
X-Sigma-Backend
Lb
XkeyRZ
X-Traceid
X-Varnish-Beresp-Status
X-Proxy-CacheRZ
X-Sigma
Yak-Timeinfo
Proxy-Connection
X-Generated-In
X-Request-Start
X-Qnm-Cache
X-Cache-Remote
X-Rocket-Build-Number
CDN
X-Rebelmouse-Cache-Control
X-CACHE-KEY
X-Rebelmouse-Surrogate-Control
Cache
X-Cdn-Forward
X-HS-Status
X-Akamai-Pragma-Client-IP
Geoip-Latitude
X-Cache-Date
X-Tim-N
Edge-Cache
X-Request-URI
Srv
X-Lb-Cache
X-Gamma-Serve
X-Scheme
X-GoCache-CacheStatus
CF-Cached-On
X-TH-Server
X-UA
Ohc-File-Size
X-GeoIP-City
Server-Id
X-Ha-Backend
X-Render-Time
X-User
X-Provided-By
X-TT-LOGID
V-Age
X-Req
X-Nc
X-B3-Trace-ID
X-SB
X-Servedbyhost
X-Wa
X-V-Cache
X-Aicache-OS
X-Acquia-Purge-Cdn-Unconfigured
Click-Count-Error
Click-Count-Action-Start
Cache-Tv-Group
Tube-Get-Contents
Tube-Got-Eval
Tube-Return
Tube-Got-Results
X-CUA
X-Via-Ucdn
X-Acquia-Application-Trace
X-Acquia-Purge-Tags
X-Vc
X-Cdn-Cache-Status
X-Dw-Trace-Id
X-EC-Lua
X-Acquia-Site
X-Acquia-Application-UUID
X-Lb-Nocache
PICS-Label
HostName
X-RN-RSRV
Yjs-Id
X-Lb-Id
X-Sucuri-Id
X-Fastly-Backend-Reqs
X-LB-ID
X-Via-Poph
X-Cache-FS-Status
MIME-Version
X-Via-Popv
X-Via-Popn
X-Edge-POP
On-Server
X-Snapshot-Date
X-CF-Cache-Header-Vary
X-Udemy-Cache-App-Namespace
Log-Origin
X-CF-Cache-Header-Cache-Control
X-RAMCache
Cneonction
X-Miniprofiler-Ids
Ngx
X-Litespeed-Cache-Control
Inserted-Into-Cache-At
Env
X-Fastly-Cache-Hits
Vha6-Origin
X-ElasticPress-Query
X-Cached-Since
CACHE-MISS-TO-ORIGIN