Threat Level: green Handler on Duty: Jan Kopriva

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Link
Cf-Request-Id
CF-Cache-Status
Accept-Ranges
CF-RAY
ETag
X-XSS-Protection
Expect-CT
Pragma
X-Powered-By
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
Alt-Svc
P3P
X-Served-By
X-Xss-Protection
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Request-Id
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Cache-Status
X-Generator
X-Cacheable
Timing-Allow-Origin
P3p
X-Content-Security-Policy
X-Iinfo
X-Request-ID
Status
Feature-Policy
X-Envoy-Upstream-Service-Time
Content-Encoding
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
X-CDN
X-AspNetMvc-Version
Upgrade
X-Via
CF-Ray
X-Ws-Request-Id
Access-Control-Max-Age
Server-Timing
EagleId
Keep-Alive
X-Cache-Group
X-Turbo-Charged-By
Request-Context
X-Age
X-Server-Powered-By
X-Proxy-Cache
X-AH-Environment
X-UA-Device
X-Backend
X-Hacker
X-Robots-Tag
Report-To
X-Amz-Request-Id
Host-Header
X-Server
X-LiteSpeed-Cache
X-Amz-Id-2
Grace
X-Rq
X-Nginx-Cache-Status
X-Varnish-Cache
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-Dns-Prefetch-Control
X-WebKit-CSP
X-Page-Speed
X-Vhost
EagleEye-TraceId
X-OneAgent-JS-Injection
X-Amz-Version-Id
X-Ua-Compatible
X-Pingback
X-Dispatcher
X-Device
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Cache-Spec
NEL
X-Server-Id
X-Host
Cf-Railgun
X-Backend-Server
X-Node
X-Readtime
Accept-CH
X-Akam-SW-Version
Surrogate-Control
Request-Id
X-Response-Time
X-HW
Xkey
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Accept-Ch-Lifetime
X-Application-Context
Content-Location
Rating
X-Ruxit-JS-Agent
X-Country
X-B3-TraceId
X-Cache-Lookup
X-Cloud-Trace-Context
X-Url
X-Ac
X-Trace
X-Content-Type
X-Language
X-Vname
X-PC
X-TtlSet
X-Varnish-TTL
Allow
Accept-CH-Lifetime
X-Mod-Pagespeed
X-Clacks-Overhead
X-Template
Edge-Control
X-FastCGI-Cache
X-ESI
Cache-Tag
Fastly-Restarts
X-Server-Name
Service-Worker-Allowed
X-Rack-Cache
X-VARITI-CCR
X-Element-Page-Cache
Verso
X-GitHub-Request-Id
X-MS-InvokeApp
X-Upstream
MS-Author-Via
X-Amz-Rid
Accept-Ch
X-Vcap-Request-Id
Public-Key-Pins
X-Dw-Request-Base-Id
X-Cached
X-Client-IP
X-D2id
X-Abt-Application-Version
X-Origin-Cache
X-Buckets
X-Cache-TTL
X-Px
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-Aws-Lambda-Call-Status
Arr-Disable-Session-Affinity
X-Cnection
Access-Control-Request-Method
X-Powered-By-Plesk
X-Goog-Hash
X-Navigation-Version
X-Country-Code
X-NF-Request-ID
RTSS
X-Version
X-Instrumentation
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Powered-CMS
Pagespeed
Display
X-Sol
X-Middleton-Display
X-Kinja-Build
X-Kinja
X-Kinja-Revision
X-Use-Magma
X-Kinja-Server
X-GoogleNews-Bot
X-Cdn-Fetch
X-Amz-Server-Side-Encryption
X-Exp-Variant
X-Exp-Id
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Middleton-Response
Response
AR-CACHE
AR-PoweredBy
AR-SID
AR-ATIME
AR-Request-ID
X-MSEdge-Ref
X-LLID
X-Kinsta-Cache
X-Edge-Location-Klb
X-Edge
X-TTL
Nginx-Cache
Mrf-Cache-Status
X-B3-TraceId-Primal
MRF-Tech
X-Jurisdiction
X-HP-Webp
X-HP-Trace-Id
X-Shield-Request-Id
X-T
X-Protected-By
S
X-RateLimit-Remaining
Content-MD5
X-Forwarded-For
X-Content-Security-Policy-Report-Only
X-Aspnetmvc-Version
X-Mg-S
X-Id
TCN
Realpath
Fastcgi-Cache
X-Mid
X-MCACHE
Edge-Cache-Tag
X-CST
Front-End-Https
SPIisLatency
SPRequestDuration
X-Recruiting
X-Request-Processing-Time
X-Request-Received
Filters
Server-Node
Pinterest-Version
Pinterest-Generated-By
X-Pinterest-Rid
X-Parallel-Accel
X-Ua-Browser
X-Ab
X-Content
Fusion-Source
Fusion-Deployment-Id
Fusion-Content-Source
Fusion-Content-Id
X-Ruxit-Js-Agent
Fusion-Template-Id
Fusion-Component-Id
X-Correlation-Id
Server-Name
X-SharePointHealthScore
SPRequestGuid
X-NWS-LOG-UUID
X-Ttl
X-Ezoic-Cdn
X-Frontend
X-DynaTrace
X-ECACHE
X-HS-Hub-Id
X-HS-Cache-Config
X-HS-Combine-CSS
X-HS-Content-Id
Alternate-Protocol
X-Cache-Key
X-Yandex-Sdch-Disable
X-Hits
X-Content-Options
X-Ser
Cache-Tags
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Page-Id
MicrosoftSharePointTeamServices
Host
X-Accel-Expires
X-B3-Sampled
X-Git-Hash
Cleartype
Charset
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Www-Served-By
X-Fastly-Request-Id
X-Daa-Tunnel
X-Content-Digest
X-Amz-Replication-Status
Filterid
X-Geo-Country
X-Amzn-Trace-Id
TP-L2-Cache
TP-Cache
X-DIS-Request-ID
X-Forwarded-Proto
X-VCache
X-Varnish-Age
X-XRDS-LOCATION
X-Activity-Id
X-Az
X-AppVersion
X-Debug-Info
X-Hostname
X-Upgrade-Enabled
X-N
X-Rid
X-Origin-Server
X-FB-Debug
X-Grace
Access-Control-Allow-Method
X-LB-Cache
X-Nginx-Upstream-Cache-Status
X-WebKit-CSP-Report-Only
ServerID
X-Origin-Upstream-Status
X-Mobile-URL
X-Is-Crawler
X-Providence-Cookie
X-Request-Guid
X-Route-Name
X-F-Cache
Cross-Origin-Opener-Policy
X-Aspnet-Duration-Ms
X-Flags
X-Server-ID
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-TT
X-Whom
X-Goog-Storage-Class
X-GUploader-UploadID
X-Goog-Metageneration
X-Goog-Generation
X-App-Environment
X-Varnish-Grace
X-NGENIX-Cache
Viewport
X-App-Server
X-Tb
Payment
X-FW-Server
X-FW-Hash
X-Distributor
X-FW-Serve
X-FW-Dynamic
X-FW-Type
X-Request-Handler-Origin-Region
X-FW-Static
X-Microsite
Paypal-Debug-Id
Node
DC
X-Seen-By
X-Type
X-Cache-Control
X-Ratelimit-Limit
Fastcgi-Useragent
X-User-Agent
X-Logged-In
Accept-Charset
X-Litespeed-Cache
Country
X-Cache-Age
X-Wix-Request-Id
X-Webkit-CSP
X-Cache-Rule
Version
X-PressLabs-Stats
X-Varnish-Backend
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Browser-Type
X-Load-Cache
X-Node-Name
Refresh
X-Drupal-Cache-Tags
X-Via-JSL
Referer-Policy
X-Cache-Action
X-Fastly-Request-ID
X-IPLB-Instance
SD-X-WS
X-Original-Request-Id
X-Response-Served-From
X-DataDome
X-Rendered-As
X-Signature
X-Mobile
X-Contextid
X-Page-View
X-Vgn-Hpd-Reason
X-B-Cache
X-Real-IP
X-Is-Bot
Cache-Status
VIX-Pulpo-Node
X-UUID
X-B
X-Fastcgi-Cache
Access-Control-Request-Headers
X-Cacheable-TTL
NGB
VIX-Pulpo-Upstream-Status
X-Cache-Expired-At
Amp-Access-Control-Allow-Source-Origin
X-Cluster-Name
X-Proxy-Cache-Status
X-Revision
X-Jobs
X-Rule
X-Proxy
X-ProcessESI
X-Device-Type
X-Yottaa-Optimizations
X-RemovedCookies
X-Yottaa-Metrics
X-Debug
X-Tec-Api-Origin
X-Tec-Api-Root
X-Tec-Api-Version
Surrogate-Key
X-Drupal-Cache-Contexts
X-Instance
Akamai-GRN
DynaTrace
X-Debug-IsConnected
X-Debug-IsPreview
X-Framework
X-TEC-API-ORIGIN
X-Cache-Time
X-TEC-API-ROOT
X-TEC-API-VERSION
X-G
X-FW-Version
X-Air-Hostname
X-Air-Source
X-Air-Trace-Id
CF-IPCountry
Liferay-Portal
X-Oracle-Dms-Rid
X-Oracle-Dms-Ecid
SID
X-Azure-Ref
Healthy
X-Source
X-CDN-Forward
X-Nginx-Cache
X-Ms-Request-Id
X-Ms-Version
X-Oneagent-Js-Injection
Frame-Options
X-RTag
Ms-Operation-Id
MS-CV
X-Ratelimit-Reset
X-Cache-Hit
X-XRDS-Location
X-L-Path
X-Cache-Operation
X-Environment-Context
Count-Hit
Countrycode
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Varnish-Server
Xserver
X-EdgeConnect-Cache-Status
X-Tumblr-Pixel-1
X-Tumblr-User
Uber-Trace-Id
X-Accel-Buffering
X-Mode
X-Backend-Name
GEO-INFO
X-Servername
X-Region
X-APP-VERSION
X-Forwarded-Host
X-Zen-Fury
Ec-Rule-Version
Nel
Section-Io-Cache
Cross-Origin-Window-Policy
X-Content-Powered-By
X-IPS-LoggedIn
Backend
X-Presslabs-Stats
Meta-Geo
X-Cache-NGX
X-SaId
X-JoinUs
X-RN-RSRV
X-Detected-As
X-UPSTREAM-Address
X-Tid
X-Zipkin-Id
X-Cache-Type
Eomportal-Instance
X-Sql-Duration-Ms
X-Alternate-Cache-Key
X-Redis-Cache
X-Routing-Service
X-Extlb
X-Proxied
X-Hosted-By
X-Cache-Grace
X-Generation-Time
X-ShardId
X-ShopId
X-Sorting-Hat-ShopId
X-Sql-Count
Country-Code
X-Sorting-Hat-PodId
X-Shopify-Stage
X-Cache-Server
X-Uri
X-Debug-Cache
X-Varnish-Beresp-Grace
X-Site-Version
X-ServerID
X-ProxyCache-Status
Cache-Name
Apigw-Requestid
Decoy-Debug-Status
Decoy-Debug-Key
DB-Nickname
X-ProxyCache-Key
X-PHP-Backend
X-RateLimit-Limit
X-BYPASS-REASON
Url
Protected
X-FB-TRIP-ID
X-Human
X-Origin-Date
X-No-Session
X-Microcachable
Decoy-Debug-TTL
X-Via-Fastly
X-NCache
X-Cache-TTL-Remaining
X-Adobe-Loc
Mn-Server-Ip
X-Adobe-Content
X-Status
X-Rewrite-Enabled
Webcakes-Region
Cache-Tv-Group
Selected-Fe
X-OCL
X-Format
X-Cache-Host
Webcakes-App-Version
X-Akamai-Edgescape
X-Origin-Hint
Fastly-SSL
TWC-Privacy
TWC-GeoIP-LatLong
X-UA-Device-Type
TWC-GeoIP-Country
TWC-Device-Class
Property-Id
TWC-Connection-Speed
X-Timing-Wait
TWC-Locale-Group
X-Say-Cacheable
Webcakes-App-Name
X-Say-TTL
X-SayCDN-TTL
X-Server-W
X-PCL
X-Proxy-Build
OT-Force-Account-Verify
X-Access
X-Varnishpool
X-NYM-Debug-Backend
X-Section
X-Hl-Ver
X-Pubstack
X-R9-Blue-Green-Version
X-Web-Node
Azure-RegionName
Azure-InstanceId
X-Storage
Azure-SlotName
Azure-SiteName
X-ApacheServer
Azure-Version
X-Soup
X-PERF
X-Be
Content-Secure-Policy
X-Cluster-Node
X-Content-Age
X-Azure-Ref-OriginShield
X-Ua
X-App-Version
X-Webkit-Csp
SRV
CDN-RequestId
CDN-Uid
CDN-RequestCountryCode
CDN-CachedAt
X-Cached-By
CDN-EdgeStorageId
CDN-PullZone
CDN-Cache
Content-Disposition
X-NewRelic-App-Data
Source
X-Hyper-Cache
X-LSADC-Cache
X-Generated-By
X-TT-LOGID
X-Unique-Id
X-Dc
X-Time
Cache
X-HTML-Minification-Powered-By
X-SRV
LB
X-Trace-Id
X-LAGOON
X-Amz-Meta-S3cmd-Attrs
X-Nginx-Cache-Key
X-Bc-Bl
X-Varnish-Hostname
X-TNCMS
X-Cache-Var-Map
X-Loop
X-Cache-Var
X-Varnish-Hits
X-Auto-Login
Onion-Location
X-S-Maxage
X-Origin-TTL
X-Origin-CC
Retry-After
Xet-Cookie
X-Cdn
WPO-Cache-Status
WPO-Cache-Message
Cache-Hits
Web-Mar-Node
X-Ratelimit-Remaining
X-Tumblr-Pixel-2
X-Tumblr-Pixel-3
X-Akamai-Transformed
X-GEO
X-Proto
HostName
X-Platform-Server
X-CSRF-Token
X-TIME
X-Tenant
Mime-Version
X-Endurance-Cache-Level
X-M-Reqid
X-Qnm-Cache
X-M-Log
X-LJ-Flow-ID
Webserver
X-Xfnlog-Site
X-VWS-Id
X-AWS-Id
X-B3-SpanId
X-GG-Cache-Date
X-Time-Microsecs
X-Cache-Tags
X-Cache-Remote
X-Varnish-Cache-Hits
N-Cache
Upgrade-Insecure-Requests
X-Edge-Location
ServedBy
X-ECache
X-Request-Time
CloudFront-Viewer-Country
X-Labrador-Cache-Channel
X-PHP-Host
X-Amzn-RequestId
X-Amz-Apigw-Id
X-AOL-HN
X-RCS-CacheZone
X-Correlation-ID
X-Mg-Request-UUID
X-Request-Host
X-Hnp-Log
X-CF-Lambda-Version
X-Cluster
X-External-Request-Id
X-Forwarded-Path
X-Developer
X-Conf
X-D
X-Destination
X-Ckpd-Fst-Backend
X-Ftr-Request-Id
DCR-Decision-By
Fastcgi-X-Cache-Version
DCR-Processing-Time-Ms
X-Cache-NE
X-Gen-Mode
X-CF-Lambda-Fn
Meta-Geo-Continent
X-ND-Cache
X-SRCache-Key
A
X-Locale
X-Planisys-CDN-TTL
X-Slack-Backend
User-Cache-Control
Surrogated-Key
X-Planisys-CDN-Cache
BehaviorPad-Version
X-Connection-Hash
X-Planisys-CDN-Rules
X-A-Dcw
X-Handled-By
X-A
X-S-Cookie
X-ScT
X-SD-PageType
X-Session-Fingerprint
X-S
X-Rojux
X-Processor
X-A-Dam
X-A-Ccd
X-Shop-Environment
X-PBS-Appsvrname
X-PAYTM-SRV-ID
X-VG-WebCache
X-Vtex-Processado-Em
X-Vdms-Version
X-Block-Status
X-B-Cookie
X-Vtex-Remote-Cache
Redirect-Candidate
Mobile-Detection-Method
Odigeo-Trace-Id
Pramga
Xc-Version
X-Vdms-Path
X-ARC
X-A-Wwc
X-Orig-Expires
Rendered-Blocks
X-A-Dgt
X-Aed
Expiry
X-V-Cache
X-Application
X-NAPM-TraceId
X-TIM-N
X-Ig-Push-State
X-Storefront-Renderer-Rendered
X-Via-NSCOPI
X-EC-Lua
X-MP-GENERATED-AT
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
State
X-Sucuri-ID
Vix-Hermes-Req-Id
X-Rocket-Nginx-Serving-Static
X-Scheme
X-Server-IP
X-Sucuri-Cache
X-Webstats-RespID
CDCHOST
Wxu-Next-Commit
Wxu-Next-Hostname
Wxu-Next-Region
Fastcgi-Cache-TTL
Gh-Request-Id
Host-ID
Origin
L
Sslversion
V-Age
X-Proxy-Upstream
X-Owner
X-Cache-Info
X-Cache-Date
X-Li-Fabric
X-Cache-Bucket
X-Hash
X-Geo-Header
X-Epic-Correlation-Id
X-Fastly-Cache
X-Forwarded-Site
X-Gdpr
X-Li-Pop
X-LI-UUID
X-Origin-Expires
X-Origin-Response-Time
X-Origin-Time
X-Date
X-Old-Content-Length
X-Nyt-Route
X-Location
X-Men
X-Mvc-Supplant-Cachable
X-Aicache-OS
X-Policy
X-Accel-Expires-Debug
Arc-Country
Cmsid
Cmstype
AMP-Access-Control-Allow-Source-Origin
X-VC-Cache
CacheControlHeader
DSUID
AKAMAI
X-FireWall-Port
X-Adobe-Source
Server-Info
X-Zone
X-Reqid
Environment
WP-Super-Cache
From-Origin
X-Req
X-TH-Server
X-Region-Sid
X-Platform
X-Request-Start
X-Thanos
We-Hiring
X-Rocket-Build-Number
X-Sigma
X-Sigma-Backend
Web-Mar-Region
X-Served-From
X-Sn-Servicetimems
X-Cache-Config
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
X-Generated-On
X-Core-Value
X-Datadog-Trace-Id
X-Gamma-Serve
X-Device-Os
X-Esi-Check
X-Fastly-Backend
X-Fetched-On
X-Core-Mission
X-Gzip
Traceparent
X-Branch-Name
X-Bip
X-CACHE-KEY
X-Cache-Id
X-Level-Front-Cache
X-HS-Content-Campaign-Id
X-Irp-Debug
X-Cdn-Origin
X-BBC-Edge-Cache-Status
X-Skip-Cache
Origin-EX
Origin-CC
X-Cache-Debug
Svr
PFcat
Apple-News-Services-Request-Url
Release
X-Cdn-Srv
X-Developers
Machine
Fastly-GeoIP-CountryCode
Mail-Subject
X-VarnishDD-TTL
X-HN
X-NodeID
Req-Svc-Chain
True-Client-Country-4JS
X-VServer
Server-Host
X-Varnish-Beresp-Status
X-Viewer-Country
X-VG-TLSProxy
Apple-News-Services-Handled
X-TrackingId
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
X-Magnolia-Registration
X-ATG-Version
X-Xrds-Location
X-CS
X-Variation
L5d-Success-Class
X-GeoIP
X-Has-Esi
X-GeoIP-City
HA-Ipaddr
X-Backend-State
X-Eu-Site
X-RateLimit-Remaining-Second
X-UnsetCookies
X-Request-URI
X-FC-Vary-Parameters
X-RateLimit-Limit-Second
X-Csrf-Jwt
X-Envoy-Decorator-Operation
X-CGP
X-DPWN-IS-SECURE
X-Worker
X-Origin
X-Thinkindot-L3
Ssr
X-Rebelmouse-Cache-Control
X-Response-By
Locid
X-Rebelmouse-Surrogate-Control
X-NU-AKA-ACS-Version
X-Node-Id
X-JWT-State
X-Is-Gdpr
X-Varnish-CookieHashed-On
X-Pod-Name
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
X-Loc
Ha-Gx-Prefs
X-Qloud-Router
TDXMobile
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
Fastly-Drupal-Html
Fastly-SWR
NM-Fastcgi-Cache
Platform
Thinkindot-Control
Memcached
Fastly-SIE
X-Amzn-Remapped-Content-Length
Is-Eu
Adler-Geo
X-DefElseHash
X-DefHash
Cf-Device-Type
X-Ua-Device
X-NWS-UUID-VERIFY
Candidate-Md5Url
Datacenter
X-Cache-Enabled
NGX
X-Mvc-Supplant-OutputCached
X-Datadome
X-CLOUD-TRACE-CONTEXT
X-Tx-Id
Pics-Label
X-Dynatrace
X-Up
X-API-Version
X-NC
X-Varnish-Beresp-Ttl
X-LB-ID
X-Backend-TTL
CDN
X-GeoIP-Region-Code
On-Server
X-Trace-ID
X-GeoIP-Country-Code
WWW-Authenticate
X-Vc
Ms-Author-Via
Time
Magicmarker
Esi-Enabled
X-LB-NoCache
Memory
X-DynaTrace-JS-Agent
X-TraceId
X-Via-Popv
X-Via-Poph
X-Refresh
X-Edge-Pop
X-Tb-Optimization-Total-Bytes-Saved
X-Via-Popn
X-Generated-In
NtCoent-Length
WebServer
Kp-EeAlive
C-Via
X-Restarts
X-TA-CDN-Provider
X-Optimistic-Header
S-Rt
X-Service
GeoIp-Country-Code
X-CacheTTL
X-Cache-PHP
X-DC
Env
X-Parent-Response-Time
X-Tt-Logid
X-Varnish-Beresp-TTL
X-Cache-Backend
X-Wix-Viewer-Type
X-RSL
X-DI
X-Action
X-DB
X-DSS
X-Esi
X-RPS
X-RPM
X-DW
Edge-Cache
X-Srv
X-Cache-Status-Check
X-TX-ID
X-Render-Time
X-Unique-ID
X-Servedbyhost
Server-ID
X-MSEdge-Features
X-MSEdge-Flight
X-Akamai-Request-ID2
X-Http-Reason
X-Minions-Version
X-ZONE
X-Newrelic-Synthetics
X-Cs
X-HA-Backend
X-Info
X-VCL-Version
X-AIR-PT
X-App
X-Cache-Ttl
Tcn
X-Li-Proto
Accept-Language
Proxy-Connection
X-LiteSpeed-Cache-Control
X-URL
Geo-Info
X-Varnish-Ttl
X-LI-Proto
X-Fpc
X-FPC
X-Webkit-Csp-Report-Only
X-Clientip
Test
X-Traceid
Cache-Host
X-Ec-GeoHdr
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
X-Urbn-Site-Id
X-Oss-Request-Id
X-Oss-Storage-Class
X-User
Locale
X-Vcl-Version
X-Urbn-Context-Path
HIT
UCS
X-Ec-Fail
X-Oss-Server-Time
X-NODE
X-Webkit-CSP-Report-Only
Server-Id
S-Cnection
X-B3-Spanid
X-Pass-Why
X-LiteSpeed-Tag
X-Micro-Cache
Fastly-Backend-Name
User-Agent
X-HostName
X-AK-Request-ID
Cdnsip
M-TraceId
Cdncip
Fastly-Drupal-HTML
Cf-Int-Pingora-Origin-Digest
Section-Io-Id
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
X-CSRF-TOKEN
Lb
Section-Origin-Responded
Geoip-Latitude
X-Ha-Backend
Cluster
X-Geo
X-ServedByHost
X-WADP-Cache
My-App
X-Fmm-Version
Resin-Trace
X-Pad
X-ID
X-Backend-Host
X-Clara-WADP
MIME-Version
Hostname
X-BBC-Origin-Response-Status
X-Var-Ttl
X-CUA
X-Release
X-APP
Ohc-File-Size
Hit
GeoIP-Country-Code
X-BCube-Filmed-By
Tracecode
ENV
X-Dynatrace-Js-Agent
T-Server
X-Via-PopV
X-ElasticPress-Query
X-From
X-Via-PopN
Lfy
X-Via-PopH
X-Check-Cacheable
X-Edge-POP
X-WA-Info
X-ES-SERVER
X-Api-Version
Load-Balancing
X-WA
X-RAMCache
X-Fragments
X-NGINX-Cache
VNS-Age
CPC-Cache
CPC-Age
Cache-Key
Path
X-HS-Status
X-Edge-Cache
EpKe-Alive
X-Amz-Meta-Cb-Modifiedtime
Lang
VNS-Cache
X-Ucs
Target-Params
URI
X-Cdn-Forward
Servername
X-Fastly-Backend-Reqs
X-ServerName
DataCenter
X-Wikidot-Static-Cache
X-Wikidot-Backend
X-Mcache
X-WP-CF-Super-Cache-Cache-Control
X-Fastly-Cache-Hits
Pagetype
X-WP-CF-Super-Cache
Shield-Pop
X-Cms-Context
X-GoCache-CacheStatus
X-UP
X-PJAX-URL
X-TRACE-ID
X-Dw-Trace-Id
Srv
X-VC
X-Lb-Id
X-Cdn-Request-ID
X-CCDN-Origin-Time
X-B3-ParentSpanId
X-Via-Ucdn
Cdn
X-CCDN-CacheTTL
Uri
MD5-Digest
Ohc-Cache-HIT
Cneonction
X-Nc
X-Hcs-Proxy-Type
X-RateLimit-Reset
WZWS-RAY
X-Akamai-Pragma-Client-IP
Permissions-Policy
X-Httpd
PICS-Label
X-Acquia-Site
FSS-Cache
X-Acquia-Application-UUID
X-Swift-Error
X-Acquia-Application-Trace
X-Proxy-Cache-Info
Server-Ttl
X-Acquia-Purge-Tags
X-Newrelic-App-Data
X-Apw-Hits
X-Cache-ASPX
Cf-Ipcountry
X-Snapshot-Date
X-Apw-Access-Token
X-Apw-Access-Object
X-SIPLIST1
X-VG-WebServer
X-Lb-Nocache
X-Apw-Access-Action
Cteonnt-Length
X-Contensis-Viewer-Groups
IsBot
Vha6-Origin
Server-Ext
CF-Cached-On
X-Yottaa-OS
Sever-Int
Server-Hostname
X-Air-Pt
Sid
X-Cache-Ngx
X-Cache-Expires
Producers
X-Akamai-ERRuleID
X-Last-Modified
ServerName
X-Akamai-ERPolicy
X-B3-Parentspanid
X-Logging-Id
Ngx
X-Sentry-ID
X-CacheKey
Req-ID
X-UA
X-Varnish-Authentication
X-Miniprofiler-Ids
X-Http-Duration-Ms
X-Te-Count
X-Http-Count
W
CountryCode
X-Te-Duration-Ms