Threat Level: green Handler on Duty: Jan Kopriva

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Link
Cf-Request-Id
CF-Cache-Status
Accept-Ranges
ETag
CF-RAY
X-XSS-Protection
Expect-CT
Pragma
X-Powered-By
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
Alt-Svc
P3P
X-Served-By
X-Xss-Protection
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Request-Id
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
CF-Ray
X-Check
X-Cache-Status
X-Generator
X-Cacheable
Timing-Allow-Origin
P3p
X-Content-Security-Policy
X-Iinfo
X-Request-ID
Status
Feature-Policy
X-Envoy-Upstream-Service-Time
Content-Encoding
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
X-CDN
X-AspNetMvc-Version
Upgrade
X-Via
X-Ws-Request-Id
Access-Control-Max-Age
Server-Timing
EagleId
Keep-Alive
X-Cache-Group
X-Turbo-Charged-By
Request-Context
X-Age
X-Server-Powered-By
X-Proxy-Cache
X-AH-Environment
X-UA-Device
X-Backend
X-Hacker
X-Robots-Tag
Report-To
X-Amz-Request-Id
Host-Header
X-Server
X-LiteSpeed-Cache
X-Amz-Id-2
Grace
X-Rq
X-Nginx-Cache-Status
X-Varnish-Cache
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-Dns-Prefetch-Control
X-WebKit-CSP
X-Page-Speed
X-Vhost
X-Ua-Compatible
EagleEye-TraceId
X-OneAgent-JS-Injection
X-Amz-Version-Id
X-Pingback
X-Dispatcher
X-Device
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Cache-Spec
NEL
X-Server-Id
X-Host
Cf-Railgun
X-Backend-Server
X-Node
X-Readtime
Accept-CH
X-Akam-SW-Version
Surrogate-Control
Request-Id
X-Response-Time
X-HW
Xkey
Accept-Ch-Lifetime
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Application-Context
Content-Location
Rating
X-Ruxit-JS-Agent
X-Country
X-B3-TraceId
X-Cache-Lookup
X-Cloud-Trace-Context
X-Url
X-Ac
X-Trace
X-Content-Type
X-Language
X-Vname
X-TtlSet
X-Varnish-TTL
X-PC
Allow
Accept-CH-Lifetime
X-Mod-Pagespeed
X-Clacks-Overhead
X-Template
Edge-Control
X-ESI
Cache-Tag
Fastly-Restarts
X-Server-Name
X-FastCGI-Cache
Service-Worker-Allowed
X-Rack-Cache
X-VARITI-CCR
X-Element-Page-Cache
Verso
X-MS-InvokeApp
X-GitHub-Request-Id
X-Upstream
X-Amz-Rid
MS-Author-Via
X-Vcap-Request-Id
Public-Key-Pins
X-Dw-Request-Base-Id
X-Cached
X-Client-IP
X-D2id
X-Abt-Application-Version
X-Origin-Cache
X-Buckets
X-Cache-TTL
X-Aws-Lambda-Call-Status
X-Px
Arr-Disable-Session-Affinity
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
X-Cnection
Accept-Ch
X-Powered-By-Plesk
Access-Control-Request-Method
X-Goog-Hash
X-Navigation-Version
X-Country-Code
X-NF-Request-ID
X-Instrumentation
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
RTSS
X-Version
X-Powered-CMS
X-Exp-Variant
X-GoogleNews-Bot
X-Kinja-Build
X-Use-Magma
X-Kinja-Server
X-Kinja-Revision
X-Exp-Id
X-Kinja
X-Cdn-Fetch
Pagespeed
Display
X-Middleton-Display
X-Sol
X-Amz-Server-Side-Encryption
X-SRCache-Fetch-Status
X-SRCache-Store-Status
Response
X-Middleton-Response
AR-Request-ID
AR-SID
AR-PoweredBy
X-MSEdge-Ref
AR-ATIME
AR-CACHE
X-LLID
X-Kinsta-Cache
X-Edge-Location-Klb
X-Edge
X-TTL
X-RateLimit-Remaining
Nginx-Cache
MRF-Tech
Mrf-Cache-Status
X-B3-TraceId-Primal
X-Shield-Request-Id
X-HP-Trace-Id
X-Protected-By
X-HP-Webp
X-Jurisdiction
X-T
S
TCN
X-Forwarded-For
Content-MD5
X-Content-Security-Policy-Report-Only
X-Aspnetmvc-Version
X-Mg-S
X-Id
Realpath
X-Mid
Fastcgi-Cache
X-MCACHE
Edge-Cache-Tag
X-CST
SPIisLatency
SPRequestDuration
Front-End-Https
X-Recruiting
X-Request-Processing-Time
X-Request-Received
Filters
Server-Node
X-Parallel-Accel
Pinterest-Generated-By
Pinterest-Version
X-Pinterest-Rid
X-Ab
X-Content
X-Ua-Browser
Fusion-Source
X-Ruxit-Js-Agent
Fusion-Deployment-Id
Fusion-Template-Id
Fusion-Component-Id
Fusion-Content-Source
Fusion-Content-Id
X-DynaTrace
SPRequestGuid
X-SharePointHealthScore
X-Correlation-Id
Server-Name
X-Ttl
X-NWS-LOG-UUID
X-ECACHE
X-Frontend
X-Ezoic-Cdn
X-HS-Content-Id
X-HS-Cache-Config
X-HS-Hub-Id
X-HS-Combine-CSS
Alternate-Protocol
X-Cache-Key
X-Yandex-Sdch-Disable
X-Hits
X-Content-Options
X-Ser
X-Tt-Trace-Tag
X-Tt-Trace-Host
MicrosoftSharePointTeamServices
Cache-Tags
X-Page-Id
X-Accel-Expires
X-B3-Sampled
Host
X-Git-Hash
Charset
X-Kong-Upstream-Latency
Cleartype
X-Kong-Proxy-Latency
X-Www-Served-By
X-Daa-Tunnel
X-Geo-Country
X-Content-Digest
X-Amz-Replication-Status
Filterid
X-Amzn-Trace-Id
X-DIS-Request-ID
TP-L2-Cache
TP-Cache
X-VCache
X-Forwarded-Proto
X-Varnish-Age
X-Az
X-Hostname
X-AppVersion
X-Activity-Id
X-XRDS-LOCATION
X-Debug-Info
X-Fastly-Request-Id
X-Upgrade-Enabled
X-Rid
X-N
X-Origin-Server
X-FB-Debug
Access-Control-Allow-Method
X-Grace
X-LB-Cache
X-Nginx-Upstream-Cache-Status
ServerID
X-WebKit-CSP-Report-Only
Cross-Origin-Opener-Policy
X-Mobile-URL
X-Origin-Upstream-Status
X-Providence-Cookie
X-Aspnet-Duration-Ms
X-Request-Guid
X-Route-Name
X-Flags
X-F-Cache
X-Is-Crawler
X-Server-ID
X-Whom
X-Goog-Stored-Content-Length
X-TT
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-GUploader-UploadID
X-Goog-Generation
X-Goog-Metageneration
X-App-Environment
X-Varnish-Grace
X-App-Server
X-Tb
X-NGENIX-Cache
Viewport
X-FW-Server
X-Request-Handler-Origin-Region
X-FW-Type
X-FW-Serve
X-FW-Static
X-Microsite
X-Distributor
Payment
X-FW-Dynamic
X-FW-Hash
DC
Node
Paypal-Debug-Id
X-Seen-By
X-Type
X-Cache-Control
Fastcgi-Useragent
X-User-Agent
X-Logged-In
X-Litespeed-Cache
Country
Accept-Charset
X-Fastcgi-Cache
X-Cache-Age
X-Cache-Rule
X-Wix-Request-Id
X-Fastly-Request-ID
X-Webkit-CSP
X-Ratelimit-Limit
Version
X-PressLabs-Stats
X-Varnish-Backend
X-Erf-Bev-Bev
X-Browser-Type
X-Erf-Bev-Bev-Is-Generated
X-Load-Cache
X-Node-Name
X-Drupal-Cache-Tags
X-Via-JSL
Referer-Policy
Refresh
X-Cache-Action
X-Original-Request-Id
X-IPLB-Instance
Access-Control-Request-Headers
X-Response-Served-From
SD-X-WS
Cache-Status
X-Cluster-Name
X-Contextid
X-Cacheable-TTL
X-Jobs
X-Is-Bot
X-DataDome
X-Proxy-Cache-Status
X-Rendered-As
X-B-Cache
X-Page-View
X-Signature
X-Vgn-Hpd-Reason
X-Real-IP
X-Mobile
Amp-Access-Control-Allow-Source-Origin
X-Cache-Expired-At
X-Revision
X-RemovedCookies
X-ProcessESI
VIX-Pulpo-Node
NGB
X-B
VIX-Pulpo-Upstream-Status
X-UUID
X-Debug
X-Rule
X-Device-Type
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Proxy
Surrogate-Key
Akamai-GRN
X-Cache-Time
X-Framework
X-G
X-Tec-Api-Root
X-Instance
X-Drupal-Cache-Contexts
X-Tec-Api-Version
X-Tec-Api-Origin
DynaTrace
X-Debug-IsConnected
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Debug-IsPreview
X-FW-Version
X-Air-Trace-Id
X-Air-Source
X-Air-Hostname
CF-IPCountry
Liferay-Portal
SID
X-Oracle-Dms-Ecid
X-Oracle-Dms-Rid
X-Azure-Ref
Healthy
X-Source
X-Ms-Version
X-Nginx-Cache
X-CDN-Forward
X-Ms-Request-Id
X-Oneagent-Js-Injection
Frame-Options
X-RTag
MS-CV
Ms-Operation-Id
Count-Hit
X-Ratelimit-Reset
X-XRDS-Location
X-Cache-Hit
X-Cache-Operation
X-L-Path
X-Environment-Context
X-Tumblr-Pixel
X-Tumblr-User
Countrycode
X-EdgeConnect-Cache-Status
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-RateLimit-Limit
Xserver
X-Varnish-Server
Uber-Trace-Id
X-Accel-Buffering
X-Region
X-Backend-Name
GEO-INFO
X-APP-VERSION
X-Servername
X-Mode
X-Forwarded-Host
X-Content-Powered-By
X-IPS-LoggedIn
Cross-Origin-Window-Policy
Section-Io-Cache
X-Zen-Fury
Ec-Rule-Version
Backend
X-UPSTREAM-Address
X-Cache-NGX
Meta-Geo
X-JoinUs
X-RN-RSRV
X-SaId
X-Detected-As
X-Presslabs-Stats
X-Generation-Time
X-Hosted-By
X-Proxied
X-Extlb
X-Human
X-Debug-Cache
Country-Code
X-Cache-Grace
Eomportal-Instance
X-Alternate-Cache-Key
X-Cache-Server
X-Redis-Cache
X-Routing-Service
X-Uri
X-Varnish-Beresp-Grace
X-Zipkin-Id
X-Cache-Type
X-Tid
X-Sql-Duration-Ms
X-Shopify-Stage
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Sql-Count
X-ShardId
X-ShopId
Decoy-Debug-Key
Decoy-Debug-Status
DB-Nickname
X-Cache-TTL-Remaining
X-Rewrite-Enabled
X-PHP-Backend
Decoy-Debug-TTL
Mn-Server-Ip
X-Origin-Date
X-NCache
Protected
Cache-Name
X-Status
Cache-Tv-Group
Url
Apigw-Requestid
X-ServerID
X-Adobe-Content
X-FB-TRIP-ID
X-ProxyCache-Status
X-Site-Version
X-UA-Device-Type
X-No-Session
X-BYPASS-REASON
X-Via-Fastly
X-Adobe-Loc
X-ProxyCache-Key
X-Microcachable
TWC-GeoIP-Country
X-Say-TTL
TWC-Device-Class
TWC-Connection-Speed
X-SayCDN-TTL
X-Web-Node
X-Cache-Host
X-Timing-Wait
X-Server-W
X-Akamai-Edgescape
TWC-Locale-Group
Selected-Fe
Property-Id
TWC-GeoIP-LatLong
X-PCL
X-Storage
X-Soup
Fastly-SSL
TWC-Privacy
X-Proxy-Build
X-Say-Cacheable
X-Origin-Hint
X-Format
Webcakes-Region
Webcakes-App-Name
X-OCL
Webcakes-App-Version
X-Section
X-Pubstack
X-NYM-Debug-Backend
Azure-InstanceId
Azure-SlotName
X-Varnishpool
X-R9-Blue-Green-Version
X-Access
OT-Force-Account-Verify
X-Hl-Ver
X-PERF
Azure-Version
X-ApacheServer
Azure-SiteName
Azure-RegionName
X-Be
Content-Secure-Policy
X-Cluster-Node
X-Content-Age
X-Azure-Ref-OriginShield
X-Ua
X-App-Version
X-Webkit-Csp
X-NewRelic-App-Data
Source
SRV
X-LSADC-Cache
CDN-Cache
CDN-CachedAt
X-Cached-By
CDN-EdgeStorageId
CDN-PullZone
CDN-RequestId
CDN-RequestCountryCode
CDN-Uid
Content-Disposition
X-Generated-By
X-Hyper-Cache
X-TT-LOGID
Cache
X-Dc
X-Time
X-Unique-Id
X-HTML-Minification-Powered-By
X-Nginx-Cache-Key
X-Trace-Id
LB
X-LAGOON
X-Amz-Meta-S3cmd-Attrs
X-Bc-Bl
X-Varnish-Hits
X-Varnish-Hostname
X-Cache-Var-Map
X-TNCMS
X-Cache-Var
X-SRV
X-Loop
X-Auto-Login
Onion-Location
X-S-Maxage
Cache-Hits
X-Origin-TTL
X-Origin-CC
Retry-After
WPO-Cache-Status
X-Cdn
Xet-Cookie
WPO-Cache-Message
X-Tumblr-Pixel-3
X-Tumblr-Pixel-2
Webserver
Web-Mar-Node
X-GEO
HostName
X-Proto
X-Akamai-Transformed
X-Platform-Server
X-TIME
X-CSRF-Token
X-Tenant
X-Time-Microsecs
Mime-Version
X-Endurance-Cache-Level
X-M-Log
X-Qnm-Cache
X-M-Reqid
X-VWS-Id
X-Edge-Location
X-Xfnlog-Site
X-LJ-Flow-ID
X-AWS-Id
X-GG-Cache-Date
X-Cache-Tags
X-B3-SpanId
X-Cache-Remote
X-Varnish-Cache-Hits
CloudFront-Viewer-Country
Upgrade-Insecure-Requests
N-Cache
X-ECache
X-Mg-Request-UUID
X-Request-Time
ServedBy
X-PHP-Host
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Labrador-Cache-Channel
X-AOL-HN
X-RCS-CacheZone
X-Correlation-ID
Nel
X-Request-Host
X-Via-NSCOPI
X-VG-WebCache
X-A-Dam
X-Handled-By
X-A-Dcw
BehaviorPad-Version
X-Vdms-Path
X-Gen-Mode
X-Vdms-Version
X-A
User-Cache-Control
X-TIM-N
X-SVT-ORM-VERSION
X-V-Cache
X-CF-Lambda-Version
X-A-Dgt
X-Hnp-Log
X-Ig-Push-State
X-A-Ccd
X-Ftr-Request-Id
X-ARC
X-Destination
X-Developer
X-B-Cookie
X-D
X-Conf
X-Connection-Hash
X-Cluster
X-Application
X-Ckpd-Fst-Backend
X-Forwarded-Path
X-A-Wwc
X-Block-Status
X-Orig-Expires
A
X-Aed
X-External-Request-Id
X-Vtex-Remote-Cache
X-Vtex-Processado-Em
X-SVT-ORM-RULES
X-Locale
X-Planisys-CDN-TTL
Fastcgi-X-Cache-Version
X-Processor
Expiry
Xc-Version
X-Rojux
Pramga
X-Cache-Date
X-Planisys-CDN-Rules
Mobile-Detection-Method
X-PAYTM-SRV-ID
Meta-Geo-Continent
Odigeo-Trace-Id
X-PBS-Appsvrname
Origin
X-Planisys-CDN-Cache
X-S
Redirect-Candidate
Rendered-Blocks
X-Shop-Environment
X-Session-Fingerprint
X-Cache-NE
X-Slack-Backend
X-CF-Lambda-Fn
X-ND-Cache
Surrogated-Key
X-SRCache-Key
X-S-Cookie
X-Origin-Response-Time
X-ScT
X-SD-PageType
DCR-Processing-Time-Ms
DSUID
X-NAPM-TraceId
DCR-Decision-By
X-FireWall-Port
X-MP-GENERATED-AT
X-Storefront-Renderer-Rendered
X-EC-Lua
AMP-Access-Control-Allow-Source-Origin
X-Webstats-RespID
Release
Origin-EX
Origin-CC
State
Traceparent
X-Aicache-OS
X-Accel-Expires-Debug
Host-ID
X-Nyt-Route
CDCHOST
X-Served-From
X-Li-Pop
X-Scheme
X-Server-IP
X-Skip-Cache
X-Sucuri-ID
X-Sucuri-Cache
X-Origin-Expires
X-LI-UUID
X-Rocket-Nginx-Serving-Static
X-Mvc-Supplant-Cachable
Sslversion
X-Owner
X-Location
X-Origin-Time
X-Proxy-Upstream
X-Policy
L
X-Li-Fabric
X-Old-Content-Length
Wxu-Next-Hostname
X-Device-Os
X-Epic-Correlation-Id
Wxu-Next-Commit
X-Date
X-Cache-Info
V-Age
X-Core-Mission
X-Fastly-Cache
X-Men
X-Gdpr
X-Geo-Header
X-Hash
X-Varnish-Beresp-Status
Wxu-Next-Region
X-Fetched-On
X-Forwarded-Site
X-VServer
X-Cache-Bucket
Vix-Hermes-Req-Id
AKAMAI
From-Origin
X-VC-Cache
Fastcgi-Cache-TTL
Arc-Country
Cmstype
Gh-Request-Id
CacheControlHeader
Cmsid
X-Adobe-Source
Environment
WP-Super-Cache
X-ATG-Version
X-Zone
X-Reqid
X-Ratelimit-Remaining
Server-Info
PFcat
X-NodeID
X-VG-TLSProxy
X-Core-Value
X-HN
X-Cache-Id
X-VarnishDD-TTL
X-Datadog-Sampling-Priority
We-Hiring
Web-Mar-Region
X-Datadog-Parent-Id
X-Developers
Locid
X-Cdn-Srv
X-BBC-Edge-Cache-Status
True-Client-Country-4JS
Svr
Ssr
X-Branch-Name
X-Bip
Apple-News-Services-Parsed-Url
X-Datadog-Trace-Id
X-Cache-Debug
Apple-News-Services-Request-Url
X-Cdn-Origin
Apple-News-Services-Handled
X-Cache-Config
Apple-News-Services-Host
X-Viewer-Country
Thinkindot-Control
X-HS-Content-Campaign-Id
X-Irp-Debug
X-Level-Front-Cache
X-Rocket-Build-Number
X-Gzip
X-GeoIP
X-GeoIP-City
Fastly-GeoIP-CountryCode
X-Request-Start
Machine
X-Platform
Mail-Subject
X-Node-Id
X-Req
X-Region-Sid
X-TrackingId
Req-Svc-Chain
Thinkindot-CacheControl
TDXMobile
X-Fastly-Backend
Thinkindot-CacheControl-Type
X-Thanos
X-Thinkindot-L3
X-Esi-Check
X-CACHE-KEY
X-TH-Server
X-Sigma
X-Generated-On
Server-Host
X-Gamma-Serve
X-Sigma-Backend
X-Sn-Servicetimems
X-CS
X-Xrds-Location
X-Magnolia-Registration
HA-Ipaddr
L5d-Success-Class
X-Is-Gdpr
X-Response-By
X-JWT-State
X-DPWN-IS-SECURE
NM-Fastcgi-Cache
Fastly-SIE
Cf-Device-Type
X-Request-URI
X-FC-Vary-Parameters
X-Envoy-Decorator-Operation
X-UnsetCookies
X-Eu-Site
X-RateLimit-Remaining-Second
X-Csrf-Jwt
X-CGP
Platform
X-Backend-State
X-Has-Esi
X-DefHash
X-DefElseHash
Memcached
X-NU-AKA-ACS-Version
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-Amzn-Remapped-Content-Length
X-Worker
Is-Eu
X-Origin
X-Qloud-Router
X-RateLimit-Limit-Second
Adler-Geo
NGX
Ha-Gx-Prefs
X-Loc
X-Variation
X-Varnish-CookieHashed-On
X-Pod-Name
X-Varnish-CookieINHashed-On
Fastly-SWR
X-Varnish-Remaining-TTL
X-Ua-Device
X-Varnish-Beresp-Ttl
X-NWS-UUID-VERIFY
X-Mvc-Supplant-OutputCached
X-Cache-Enabled
Fastly-Drupal-Html
X-CLOUD-TRACE-CONTEXT
Candidate-Md5Url
X-Datadome
Datacenter
X-Tx-Id
X-API-Version
X-NC
X-Up
X-LB-ID
Pics-Label
X-Backend-TTL
CDN
X-Vc
X-GeoIP-Region-Code
WWW-Authenticate
X-Trace-ID
Ms-Author-Via
On-Server
X-GeoIP-Country-Code
Time
X-LB-NoCache
Memory
Magicmarker
Esi-Enabled
NtCoent-Length
X-TraceId
X-DynaTrace-JS-Agent
X-Refresh
X-Generated-In
X-Edge-Pop
X-Via-Poph
X-Via-Popn
X-Via-Popv
X-Tb-Optimization-Total-Bytes-Saved
X-Dynatrace
X-Restarts
GeoIp-Country-Code
Kp-EeAlive
S-Rt
C-Via
X-Service
X-Optimistic-Header
X-TA-CDN-Provider
X-Srv
Env
X-CacheTTL
X-Cache-PHP
WebServer
X-DC
X-Parent-Response-Time
X-Tt-Logid
X-Esi
Edge-Cache
X-Cache-Backend
X-RSL
X-DW
X-Action
X-DB
X-DI
X-RPM
X-RPS
X-DSS
X-Wix-Viewer-Type
X-Cache-Status-Check
X-MSEdge-Flight
X-TX-ID
X-Render-Time
X-Varnish-Beresp-TTL
X-Servedbyhost
X-MSEdge-Features
X-Unique-ID
Server-ID
X-Http-Reason
X-Akamai-Request-ID2
X-Minions-Version
X-ZONE
X-HA-Backend
X-Cs
X-Newrelic-Synthetics
X-Info
X-App
X-Cache-Ttl
X-AIR-PT
X-VCL-Version
X-Li-Proto
Accept-Language
X-LiteSpeed-Cache-Control
Proxy-Connection
X-URL
Geo-Info
Test
X-Clientip
X-Webkit-Csp-Report-Only
X-LI-Proto
X-Fpc
X-Varnish-Ttl
X-FPC
X-Traceid
X-Oss-Object-Type
Locale
HIT
X-Urbn-Site-Id
X-Oss-Server-Time
X-Oss-Storage-Class
X-Urbn-Context-Path
Cache-Host
X-Ec-Fail
X-Vcl-Version
X-Oss-Hash-Crc64ecma
X-Oss-Request-Id
UCS
X-Ec-GeoHdr
X-User
X-Webkit-CSP-Report-Only
X-NODE
Server-Id
S-Cnection
Tcn
X-B3-Spanid
Fastly-Drupal-HTML
X-Pass-Why
Fastly-Backend-Name
Cf-Int-Pingora-Origin-Digest
X-HostName
X-LiteSpeed-Tag
Cdncip
X-Micro-Cache
M-TraceId
X-AK-Request-ID
Cdnsip
User-Agent
Section-Origin-Responded
Section-Io-Origin-Time-Seconds
X-CSRF-TOKEN
Lb
Section-Io-Id
Section-Io-Origin-Status
X-Pad
X-ServedByHost
X-WADP-Cache
Cluster
Geoip-Latitude
X-Fmm-Version
X-Backend-Host
My-App
X-Clara-WADP
X-ID
X-Ha-Backend
Resin-Trace
X-Geo
MIME-Version
Hostname
Tracecode
X-Release
Hit
X-BBC-Origin-Response-Status
X-BCube-Filmed-By
X-APP
X-Var-Ttl
Ohc-File-Size
X-CUA
GeoIP-Country-Code
ENV
X-Dynatrace-Js-Agent
X-ElasticPress-Query
X-Via-PopN
X-Edge-POP
X-Via-PopV
X-HS-Status
X-From
T-Server
X-Check-Cacheable
Lfy
X-Via-PopH
Load-Balancing
X-NGINX-Cache
Lang
CPC-Age
Cache-Key
VNS-Cache
X-Edge-Cache
X-Amz-Meta-Cb-Modifiedtime
X-WA-Info
X-WA
VNS-Age
X-Api-Version
Path
X-ES-SERVER
X-Fragments
EpKe-Alive
X-RAMCache
CPC-Cache
X-ServerName
X-WP-CF-Super-Cache
Servername
URI
X-Cdn-Forward
X-WP-CF-Super-Cache-Cache-Control
X-Fastly-Backend-Reqs
Target-Params
X-Ucs
DataCenter
X-Dw-Trace-Id
X-GoCache-CacheStatus
X-PJAX-URL
Pagetype
X-Wikidot-Static-Cache
X-Wikidot-Backend
Shield-Pop
X-Cms-Context
X-Mcache
X-UP
X-Fastly-Cache-Hits
X-TRACE-ID
Srv
X-CCDN-Origin-Time
X-CCDN-CacheTTL
X-Lb-Id
X-Via-Ucdn
X-Akamai-Pragma-Client-IP
Uri
X-VC
X-Hcs-Proxy-Type
WZWS-RAY
Cneonction
X-RateLimit-Reset
Cdn
X-Nc
X-B3-ParentSpanId
MD5-Digest
X-Cdn-Request-ID
Ohc-Cache-HIT
X-Httpd
X-Acquia-Site
X-Proxy-Cache-Info
Permissions-Policy
FSS-Cache
X-Acquia-Application-UUID
PICS-Label
X-Acquia-Purge-Tags
X-Swift-Error
Server-Ttl
X-Acquia-Application-Trace
Cf-Ipcountry
IsBot
X-Apw-Hits
X-Cache-ASPX
X-Contensis-Viewer-Groups
X-Snapshot-Date
X-Apw-Access-Object
X-Apw-Access-Action
Sever-Int
X-VG-WebServer
Server-Hostname
Server-Ext
X-Lb-Nocache
Cteonnt-Length
X-Apw-Access-Token
X-Newrelic-App-Data
Vha6-Origin
X-SIPLIST1
X-Yottaa-OS
CF-Cached-On
Sid
X-Cache-Ngx
X-Air-Pt
X-Last-Modified
X-Akamai-ERRuleID
Req-ID
X-Akamai-ERPolicy
W
X-Udemy-Cache-App-Namespace
Producers
X-Cache-Expires
ServerName
X-B3-Parentspanid
X-UA
X-CacheKey
CountryCode
Ngx
X-Logging-Id
X-Sentry-ID
X-Http-Count
X-Varnish-Authentication
X-Te-Duration-Ms
X-Te-Count
X-Http-Duration-Ms
X-Miniprofiler-Ids