Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-Cache-Status
Link
Accept-Ranges
CF-RAY
ETag
Expect-CT
Pragma
X-Powered-By
X-XSS-Protection
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
Alt-Svc
X-UA-Compatible
P3P
X-Served-By
X-Xss-Protection
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Cache-Status
X-Generator
X-Cacheable
Timing-Allow-Origin
X-Content-Security-Policy
P3p
X-Iinfo
Feature-Policy
Status
X-Envoy-Upstream-Service-Time
Content-Encoding
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
X-CDN
X-AspNetMvc-Version
Upgrade
X-Via
CF-Ray
X-Ws-Request-Id
Access-Control-Max-Age
X-Request-ID
Server-Timing
EagleId
X-Cache-Group
Keep-Alive
X-Turbo-Charged-By
Request-Context
X-Age
X-Server-Powered-By
X-UA-Device
X-Proxy-Cache
X-Ua-Compatible
X-AH-Environment
X-Backend
X-Robots-Tag
X-Hacker
Report-To
X-Amz-Request-Id
Host-Header
X-Server
X-Amz-Id-2
Grace
X-LiteSpeed-Cache
X-Rq
X-Nginx-Cache-Status
X-Varnish-Cache
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-Dns-Prefetch-Control
X-WebKit-CSP
X-Page-Speed
X-Vhost
EagleEye-TraceId
X-Amz-Version-Id
X-OneAgent-JS-Injection
X-Pingback
X-Dispatcher
X-Device
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
NEL
X-Cache-Spec
X-Host
X-Server-Id
Cf-Railgun
X-Node
X-Backend-Server
Accept-CH
X-Readtime
Surrogate-Control
X-Akam-SW-Version
Request-Id
X-Response-Time
X-HW
Xkey
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Application-Context
Content-Location
X-Ruxit-JS-Agent
Rating
Accept-Ch-Lifetime
X-Country
Accept-CH-Lifetime
X-B3-TraceId
X-Cache-Lookup
X-Cloud-Trace-Context
X-Trace
X-Url
X-Ac
X-Content-Type
Allow
X-PC
X-TtlSet
X-Vname
X-Varnish-TTL
X-Clacks-Overhead
X-Mod-Pagespeed
Edge-Control
X-FastCGI-Cache
X-ESI
X-Server-Name
Fastly-Restarts
Cache-Tag
Service-Worker-Allowed
X-VARITI-CCR
X-Rack-Cache
Verso
X-Element-Page-Cache
X-Aws-Lambda-Call-Status
X-Upstream
X-MS-InvokeApp
X-GitHub-Request-Id
MS-Author-Via
X-Amz-Rid
X-Vcap-Request-Id
Public-Key-Pins
X-Dw-Request-Base-Id
X-Cached
X-Client-IP
X-D2id
X-Abt-Application-Version
X-Cache-TTL
X-Cnection
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
X-Px
Arr-Disable-Session-Affinity
X-Origin-Cache
X-Country-Code
RTSS
X-Navigation-Version
Access-Control-Request-Method
X-Goog-Hash
X-Powered-By-Plesk
X-NF-Request-ID
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Instrumentation
X-GoogleNews-Bot
X-Exp-Id
X-Kinja
X-Cdn-Fetch
X-Exp-Variant
X-Kinja-Server
X-Use-Magma
X-Kinja-Revision
X-Kinja-Build
Accept-Ch
X-Powered-CMS
X-Version
AR-Request-ID
AR-SID
AR-CACHE
AR-PoweredBy
AR-ATIME
X-Language
Pagespeed
X-Middleton-Display
Display
X-Sol
Response
X-Amz-Server-Side-Encryption
X-Middleton-Response
X-MSEdge-Ref
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-LLID
X-Edge-Location-Klb
X-Kinsta-Cache
X-Edge
Nginx-Cache
X-TTL
X-B3-TraceId-Primal
X-Template
MRF-Tech
Mrf-Cache-Status
X-RateLimit-Remaining
X-Protected-By
X-Shield-Request-Id
X-Jurisdiction
X-HP-Trace-Id
X-HP-Webp
TCN
X-T
X-Forwarded-For
X-Content-Security-Policy-Report-Only
S
X-Mg-S
X-Id
Content-MD5
X-Aspnetmvc-Version
Edge-Cache-Tag
X-Mid
Fastcgi-Cache
X-CST
Realpath
SPRequestDuration
SPIisLatency
Front-End-Https
X-Recruiting
X-Request-Processing-Time
X-MCACHE
X-Request-Received
X-Ttl
X-Pinterest-Rid
Pinterest-Generated-By
Filters
Pinterest-Version
Server-Node
X-Content
X-Ab
X-Ua-Browser
X-Correlation-Id
Server-Name
X-DynaTrace
X-Frontend
X-Ruxit-Js-Agent
X-NWS-LOG-UUID
X-HS-Cache-Config
X-HS-Content-Id
X-HS-Hub-Id
X-SharePointHealthScore
SPRequestGuid
X-HS-Combine-CSS
X-Yandex-Sdch-Disable
X-Parallel-Accel
X-Ezoic-Cdn
X-ECACHE
Fusion-Component-Id
Fusion-Deployment-Id
Fusion-Source
Fusion-Template-Id
Fusion-Content-Id
Fusion-Content-Source
X-Ser
X-Hits
Alternate-Protocol
X-Cache-Key
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Content-Options
X-Buckets
MicrosoftSharePointTeamServices
X-Page-Id
Cache-Tags
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
Cleartype
X-B3-Sampled
Host
X-Git-Hash
Charset
X-Fastly-Request-Id
X-Www-Served-By
X-Server-ID
X-Geo-Country
X-DIS-Request-ID
X-Daa-Tunnel
X-Accel-Expires
X-Amzn-Trace-Id
X-Debug-Info
X-Content-Digest
X-Amz-Replication-Status
Filterid
X-Varnish-Age
X-Activity-Id
X-Az
X-AppVersion
X-FB-Debug
X-Ratelimit-Limit
X-Hostname
X-Forwarded-Proto
TP-L2-Cache
TP-Cache
X-Upgrade-Enabled
X-VCache
X-Rid
Cross-Origin-Opener-Policy
X-N
X-Grace
Access-Control-Allow-Method
X-Origin-Server
X-Nginx-Upstream-Cache-Status
X-XRDS-LOCATION
X-WebKit-CSP-Report-Only
X-LB-Cache
X-F-Cache
X-Mobile-URL
ServerID
X-Route-Name
X-Flags
X-Is-Crawler
X-Providence-Cookie
X-Request-Guid
X-Aspnet-Duration-Ms
X-Whom
X-GUploader-UploadID
X-TT
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-Goog-Generation
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-Tb
X-App-Environment
Viewport
X-Varnish-Grace
X-FW-Type
X-FW-Dynamic
Payment
X-FW-Hash
X-FW-Serve
X-Distributor
X-FW-Static
X-FW-Server
X-Seen-By
Node
X-Type
X-App-Server
Paypal-Debug-Id
DC
X-User-Agent
X-Origin-Upstream-Status
X-NGENIX-Cache
Fastcgi-Useragent
X-Oneagent-Js-Injection
X-Cache-Control
Country
Accept-Charset
X-Wix-Request-Id
X-Cache-Rule
X-Logged-In
X-Litespeed-Cache
X-Cache-Age
Version
X-Microsite
X-Request-Handler-Origin-Region
X-Webkit-Csp
X-Via-JSL
X-Webkit-CSP
Referer-Policy
X-Drupal-Cache-Tags
X-DataDome
X-Browser-Type
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Varnish-Backend
X-Cluster-Name
Refresh
X-B-Cache
X-Signature
X-Contextid
Cache-Status
X-Node-Name
X-Load-Cache
X-Tec-Api-Root
X-Original-Request-Id
X-Tec-Api-Version
X-Mobile
Access-Control-Request-Headers
SD-X-WS
X-Response-Served-From
X-Tec-Api-Origin
Amp-Access-Control-Allow-Source-Origin
X-Real-IP
X-Rendered-As
X-Jobs
X-Cache-Expired-At
X-Cacheable-TTL
X-Is-Bot
X-Vgn-Hpd-Reason
X-Page-View
X-Proxy-Cache-Status
X-Cache-Action
X-Revision
X-B
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
NGB
X-IPLB-Instance
X-Debug
X-RemovedCookies
X-ProcessESI
X-UUID
X-Ratelimit-Reset
X-Instance
X-Rule
X-Yottaa-Optimizations
X-Device-Type
X-Proxy
X-Yottaa-Metrics
X-G
X-Framework
Surrogate-Key
X-Fastly-Request-ID
X-Drupal-Cache-Contexts
X-Cache-Time
Akamai-GRN
X-Debug-IsPreview
X-Debug-IsConnected
X-Fastcgi-Cache
X-FW-Version
CF-IPCountry
X-Air-Trace-Id
X-Air-Source
X-Air-Hostname
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-TEC-API-VERSION
DynaTrace
SID
Liferay-Portal
X-XRDS-Location
X-Azure-Ref
X-PressLabs-Stats
X-Oracle-Dms-Rid
X-Oracle-Dms-Ecid
X-Presslabs-Stats
GEO-INFO
Healthy
Count-Hit
Frame-Options
X-Cache-Operation
X-Ms-Request-Id
X-Source
X-Ms-Version
X-Nginx-Cache
X-Accel-Buffering
X-RTag
X-CDN-Forward
Uber-Trace-Id
MS-CV
Ms-Operation-Id
X-APP-VERSION
X-EdgeConnect-Cache-Status
X-L-Path
X-Tumblr-Pixel-1
X-Tumblr-User
Xserver
Countrycode
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Environment-Context
X-Zen-Fury
X-Varnish-Server
X-Cache-Hit
X-Cache-NGX
X-Backend-Name
X-Mode
Ec-Rule-Version
X-Region
Cross-Origin-Window-Policy
X-Servername
X-Forwarded-Host
X-IPS-LoggedIn
Protected
X-Content-Powered-By
Backend
X-Cache-TTL-Remaining
X-SaId
Meta-Geo
X-RN-RSRV
X-UPSTREAM-Address
X-JoinUs
X-Rewrite-Enabled
X-Detected-As
X-Cache-Type
X-Zipkin-Id
X-Alternate-Cache-Key
X-Tid
X-Sql-Duration-Ms
X-Shopify-Stage
X-Uri
X-Extlb
Section-Io-Cache
X-Sorting-Hat-PodId
X-Varnish-Beresp-Grace
X-ShopId
X-Cache-Server
X-Human
X-ShardId
X-Redis-Cache
X-Sql-Count
Decoy-Debug-Key
X-Generation-Time
Decoy-Debug-Status
Apigw-Requestid
Decoy-Debug-TTL
X-Cache-Grace
Country-Code
X-Routing-Service
X-Sorting-Hat-ShopId
Eomportal-Instance
X-Debug-Cache
X-Proxied
X-Hosted-By
Cache-Name
Mn-Server-Ip
Url
X-UA-Device-Type
X-ApacheServer
X-Storage
X-BYPASS-REASON
Fastly-SSL
X-Via-Fastly
X-Soup
X-No-Session
X-ProxyCache-Key
X-Origin-Date
X-PERF
X-PHP-Backend
X-Format
Cache-Tv-Group
X-Microcachable
X-Site-Version
X-NCache
X-Status
X-ServerID
X-FB-TRIP-ID
X-ProxyCache-Status
Property-Id
X-Origin-Hint
TWC-Connection-Speed
TWC-Device-Class
Selected-Fe
X-Say-TTL
X-OCL
X-NYM-Debug-Backend
X-PCL
X-Say-Cacheable
X-SayCDN-TTL
X-Section
X-Server-W
X-Adobe-Content
X-Access
X-Adobe-Loc
X-Akamai-Edgescape
X-Web-Node
X-Cache-Host
X-Timing-Wait
X-Proxy-Build
TWC-Locale-Group
TWC-GeoIP-LatLong
TWC-Privacy
X-Cluster-Node
Webcakes-App-Version
Webcakes-App-Name
TWC-GeoIP-Country
Webcakes-Region
X-Content-Age
X-Hyper-Cache
X-Hl-Ver
X-R9-Blue-Green-Version
X-Varnishpool
OT-Force-Account-Verify
X-Pubstack
Azure-RegionName
Azure-Version
DB-Nickname
Azure-SiteName
Azure-SlotName
Azure-InstanceId
X-TIME
X-Be
X-RateLimit-Limit
Content-Secure-Policy
CDN-RequestId
CDN-Uid
SRV
X-LSADC-Cache
CDN-Cache
CDN-RequestCountryCode
CDN-CachedAt
X-Ua
CDN-EdgeStorageId
CDN-PullZone
X-NewRelic-App-Data
X-Azure-Ref-OriginShield
X-Trace-Id
X-Generated-By
X-Ratelimit-Remaining
LB
Content-Disposition
WPO-Cache-Message
WPO-Cache-Status
Source
X-Cached-By
X-SRV
X-Dc
Cache
X-Nginx-Cache-Key
X-Unique-Id
X-Bc-Bl
X-LAGOON
X-App-Version
Cache-Hits
Xet-Cookie
X-Auto-Login
X-TT-LOGID
Retry-After
Mime-Version
X-HTML-Minification-Powered-By
X-Origin-TTL
X-Origin-CC
X-Varnish-Hits
X-GEO
X-Varnish-Hostname
X-Platform-Server
X-TNCMS
X-Loop
X-S-Maxage
X-Amz-Meta-S3cmd-Attrs
X-Akamai-Transformed
X-ECache
Onion-Location
X-Xfnlog-Site
X-Cache-Remote
X-Cdn
Web-Mar-Node
HostName
X-Tumblr-Pixel-2
X-Tumblr-Pixel-3
X-Cache-Tags
X-Varnish-Cache-Hits
Webserver
Upgrade-Insecure-Requests
X-Proto
X-CSRF-Token
X-Cache-Var
X-Cache-Var-Map
X-Request-Time
ServedBy
X-Time-Microsecs
X-AOL-HN
X-Endurance-Cache-Level
X-Tenant
X-Edge-Location
X-EC-Lua
X-Time
X-AWS-Id
N-Cache
X-VWS-Id
X-LJ-Flow-ID
From-Origin
X-Request-Host
WP-Super-Cache
X-GG-Cache-Date
X-FireWall-Port
CloudFront-Viewer-Country
X-Mg-Request-UUID
X-Via-NSCOPI
X-Origin-Response-Time
X-PHP-Host
X-Labrador-Cache-Channel
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Ftr-Request-Id
X-A-Dam
X-ScT
X-S
X-S-Cookie
X-A-Dcw
BehaviorPad-Version
X-A-Dgt
X-Rojux
X-ND-Cache
X-Cache-Date
X-SD-PageType
X-ARC
Expiry
X-Application
X-Processor
X-Planisys-CDN-TTL
X-PAYTM-SRV-ID
Fastcgi-X-Cache-Version
X-PBS-Appsvrname
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Orig-Expires
X-Gen-Mode
X-Aed
X-A-Wwc
X-Block-Status
X-B-Cookie
DCR-Decision-By
A
DSUID
X-Cache-NE
X-Forwarded-Path
DCR-Processing-Time-Ms
X-NAPM-TraceId
X-Ckpd-Fst-Backend
Redirect-Candidate
Pramga
X-D
Rendered-Blocks
X-Hnp-Log
X-M-Log
X-M-Reqid
X-Connection-Hash
X-TIM-N
X-Ig-Push-State
Meta-Geo-Continent
X-V-Cache
X-Vdms-Path
X-Vdms-Version
Xc-Version
X-Destination
Surrogated-Key
X-Developer
User-Cache-Control
X-Vtex-Remote-Cache
X-Vtex-Processado-Em
V-Age
X-VG-WebCache
Sslversion
X-B3-SpanId
X-Conf
X-Qnm-Cache
X-Slack-Backend
X-A
X-SRCache-Key
X-External-Request-Id
Origin
X-A-Ccd
X-CF-Lambda-Version
Nel
Mobile-Detection-Method
X-Session-Fingerprint
X-CF-Lambda-Fn
X-Shop-Environment
X-SVT-ORM-RULES
Odigeo-Trace-Id
X-Correlation-ID
X-Cluster
X-SVT-ORM-VERSION
X-Cache-Enabled
X-RCS-CacheZone
X-Handled-By
X-NWS-UUID-VERIFY
X-MP-GENERATED-AT
Gh-Request-Id
Host-ID
X-Mvc-Supplant-Cachable
State
X-Li-Pop
Origin-EX
Svr
X-Li-Fabric
True-Client-Country-4JS
CDCHOST
Cmsid
X-Hash
Cmstype
Ssr
Wxu-Next-Commit
L
Wxu-Next-Region
CacheControlHeader
Origin-CC
X-Accel-Expires-Debug
Release
X-Gdpr
X-Men
X-LI-UUID
X-Location
X-Geo-Header
Fastcgi-Cache-TTL
Wxu-Next-Hostname
X-Scheme
X-VServer
X-Date
X-Cdn-Srv
X-Rocket-Nginx-Serving-Static
X-Fastly-Cache
X-Fetched-On
Fastly-Drupal-Html
X-Webstats-RespID
X-Cache-Info
X-Zone
Traceparent
X-CACHE-KEY
X-Core-Mission
X-Varnish-Beresp-Status
X-Locale
X-Sucuri-ID
X-Sucuri-Cache
X-Served-From
X-Server-IP
X-Skip-Cache
X-Aicache-OS
Vix-Hermes-Req-Id
AKAMAI
X-Device-Os
X-Proxy-Upstream
X-Forwarded-Site
Arc-Country
X-NodeID
Server-Info
X-Nyt-Route
X-Cache-Bucket
X-Old-Content-Length
X-Origin-Expires
X-Epic-Correlation-Id
X-Origin-Time
X-Owner
X-Policy
X-Reqid
X-Magnolia-Registration
AMP-Access-Control-Allow-Source-Origin
Environment
X-Datadog-Parent-Id
We-Hiring
X-Esi-Check
X-GeoIP
X-GeoIP-City
X-Developers
X-Datadog-Trace-Id
X-Gzip
X-Datadog-Sampling-Priority
X-Envoy-Decorator-Operation
X-ATG-Version
X-Cache-Debug
X-Cache-Id
X-Branch-Name
X-Bip
X-BBC-Edge-Cache-Status
X-Gamma-Serve
X-Generated-On
X-Cdn-Origin
X-Eu-Site
X-Core-Value
X-Csrf-Jwt
X-Fastly-Backend
X-CGP
X-Adobe-Source
X-Backend-State
Web-Mar-Region
X-Platform
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
Apple-News-Services-Handled
X-Thinkindot-L3
Thinkindot-Control
Apple-News-Services-Request-Url
X-TrackingId
X-VC-Cache
Fastly-GeoIP-CountryCode
X-UnsetCookies
X-Node-Id
X-Thanos
X-TH-Server
X-Sigma-Backend
X-Request-Start
X-Sigma
X-Rocket-Build-Number
X-Req
X-Region-Sid
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Storefront-Renderer-Rendered
X-Sn-Servicetimems
X-VarnishDD-TTL
Ha-Gx-Prefs
HA-Ipaddr
Server-Host
X-HN
X-Request-URI
X-Viewer-Country
X-HS-Content-Campaign-Id
PFcat
X-Irp-Debug
X-Level-Front-Cache
Mail-Subject
Thinkindot-CacheControl
X-VG-TLSProxy
Thinkindot-CacheControl-Type
Req-Svc-Chain
TDXMobile
Machine
Locid
L5d-Success-Class
X-DPWN-IS-SECURE
X-Worker
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
X-Varnish-CookieHashed-On
X-Variation
X-DefHash
X-DefElseHash
X-Backend-TTL
X-Origin
Is-Eu
Memcached
X-Amzn-Remapped-Content-Length
Fastly-SWR
Fastly-SIE
NGX
NM-Fastcgi-Cache
X-Has-Esi
Platform
X-Is-Gdpr
X-JWT-State
X-Response-By
X-Loc
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-FC-Vary-Parameters
X-Pod-Name
X-Qloud-Router
Cf-Device-Type
Adler-Geo
X-NU-AKA-ACS-Version
X-Xrds-Location
X-Datadome
X-GeoIP-Region-Code
X-GeoIP-Country-Code
X-Mvc-Supplant-OutputCached
X-Cache-Config
X-Tx-Id
X-Ua-Device
X-CLOUD-TRACE-CONTEXT
X-CS
X-NC
X-API-Version
S-Rt
X-Varnish-Beresp-Ttl
X-Generated-In
X-TraceId
CDN
Pics-Label
X-LB-ID
Magicmarker
X-TA-CDN-Provider
X-Up
Candidate-Md5Url
Datacenter
X-Restarts
X-Tt-Logid
Ms-Author-Via
Kp-EeAlive
X-Trace-ID
X-Vc
X-Tb-Optimization-Total-Bytes-Saved
X-LB-NoCache
Env
Memory
X-Http-Reason
X-Akamai-Request-ID2
Time
X-Edge-Pop
NtCoent-Length
X-DynaTrace-JS-Agent
X-Via-Popv
X-RPM
X-Via-Poph
X-RPS
X-Via-Popn
Edge-Cache
X-Wix-Viewer-Type
X-Refresh
WWW-Authenticate
X-Varnish-Ttl
X-DSS
X-Cache-Backend
X-RSL
X-DW
X-DI
X-Optimistic-Header
X-Action
GeoIp-Country-Code
WebServer
X-DB
On-Server
X-Parent-Response-Time
Esi-Enabled
X-Varnish-Beresp-TTL
X-Minions-Version
X-CacheTTL
Accept-Language
X-DC
X-Service
C-Via
X-Servedbyhost
X-Cs
X-Esi
X-Dynatrace
X-Srv
X-Unique-ID
X-HA-Backend
X-Cache-PHP
X-TX-ID
X-MSEdge-Flight
X-MSEdge-Features
X-Newrelic-Synthetics
Server-ID
Locale
X-Urbn-Context-Path
X-Urbn-Site-Id
X-ZONE
X-User
X-Ec-GeoHdr
X-Ec-Fail
X-VCL-Version
X-Cache-Status-Check
X-Render-Time
X-Li-Proto
X-App
X-Cache-Ttl
X-LI-Proto
X-FPC
X-URL
X-B3-Spanid
X-Webkit-Csp-Report-Only
Server-Id
Test
X-Fpc
Proxy-Connection
X-LiteSpeed-Cache-Control
X-Traceid
X-Vcl-Version
Cdnsip
X-AK-Request-ID
Cdncip
X-Info
X-Webkit-CSP-Report-Only
X-AIR-PT
X-NODE
X-Pass-Why
Geo-Info
My-App
Geoip-Latitude
X-Fmm-Version
Tcn
X-Clientip
X-Clara-WADP
Cluster
X-WADP-Cache
X-Mcache
HIT
X-CUA
X-Var-Ttl
Tracecode
Cache-Host
Resin-Trace
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
X-CSRF-TOKEN
M-TraceId
UCS
X-Oss-Request-Id
X-Oss-Server-Time
X-Oss-Storage-Class
T-Server
Hostname
X-LiteSpeed-Tag
X-HostName
X-Ha-Backend
Fastly-Drupal-HTML
Lfy
S-Cnection
X-From
Cf-Int-Pingora-Origin-Digest
X-ServedByHost
X-Fragments
DataCenter
X-ID
Lang
X-B3-Traceid
Hit
X-Via-PopV
X-WP-CF-Super-Cache-Cache-Control
X-Via-PopN
X-Via-PopH
X-WP-CF-Super-Cache
Target-Params
GeoIP-Country-Code
X-Pad
X-COUNTRY
X-NGINX-Cache
User-Agent
Ohc-File-Size
Fastly-Backend-Name
X-Micro-Cache
X-Dynatrace-Js-Agent
X-Geo
X-Check-Cacheable
ENV
X-Edge-POP
X-BBC-Origin-Response-Status
X-RAMCache
X-ElasticPress-Query
X-Cdn-Forward
MIME-Version
X-Backend-Host
X-Release
X-BCube-Filmed-By
Load-Balancing
X-VC
X-Api-Version
X-APP
X-Edge-Cache
Section-Origin-Responded
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
Section-Io-Id
Lb
X-Lb-Nocache
X-HS-Status
X-Ucs
X-Fastly-Backend-Reqs
X-UP
X-Httpd
X-Proxy-Cache-Info
Permissions-Policy
EpKe-Alive
Servername
X-ServerName
URI
CPC-Cache
Producers
VNS-Age
X-WA
CPC-Age
X-GoCache-CacheStatus
Cache-Key
Path
VNS-Cache
X-WA-Info
Uri
FSS-Cache
Server-Ttl
X-Amz-Meta-Cb-Modifiedtime
PICS-Label
ServerName
X-Lb-Id
X-TRACE-ID
Sid
X-Provided-By
X-Pool
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-ES-SERVER
Cneonction
X-B3-ParentSpanId
WZWS-RAY
X-Udemy-Cache-App-Namespace
X-Nc
X-Cache-CFC
X-RateLimit-Reset
Cdn
X-Fastly-Cache-Hits
Vha6-Origin
X-Cdn-Request-ID
Cteonnt-Length
Ohc-Cache-HIT
X-SB
X-Dw-Trace-Id
X-Acquia-Purge-Tags
X-Acquia-Site
X-Acquia-Application-UUID
X-Platform-Router
X-Akamai-ERRuleID
X-Acquia-Application-Trace
X-Akamai-ERPolicy
X-Contensis-Viewer-Groups
X-Snapshot-Date
Shield-Pop
X-Newrelic-App-Data
X-Apw-Hits
X-Cache-ASPX
X-Apw-Access-Token
CF-Cached-On
X-PJAX-URL
Cf-Ipcountry
X-Swift-Error
X-Vcache
X-Apw-Access-Action
X-Cms-Context
X-Akamai-Request-ID
X-Platform-Processor
X-Apw-Access-Object
X-Platform-Cluster
X-Yottaa-OS
X-Ec-Custom-Error
Pagetype
X-Cache-Ngx
X-Air-Pt
X-CCDN-CacheTTL
X-Shopify-Generated-Cart-Token
X-Scale
Ngx
X-Via-Ucdn
Req-ID
CountryCode
X-CCDN-Origin-Time
X-Akamai-Pragma-Client-IP
X-Logging-Id
X-CacheKey
X-UA
X-Hcs-Proxy-Type
X-Sentry-ID
X-Te-Count
X-Te-Duration-Ms
MD5-Digest
X-Http-Duration-Ms
X-Http-Count
X-Varnish-Authentication
X-Miniprofiler-Ids
X-Last-Modified