Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
X-Powered-By
Pragma
CF-RAY
X-Cache
Via
X-XSS-Protection
Age
Content-Security-Policy
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Xss-Protection
X-Amz-Cf-Pop
X-Amz-Cf-Id
Alt-Svc
P3P
X-Cache-Hits
X-UA-Compatible
X-Served-By
CF-Ray
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Request-Id
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
Access-Control-Allow-Credentials
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
X-Drupal-Cache
X-Cache-Status
X-Generator
X-Check
X-Cacheable
X-Envoy-Upstream-Service-Time
X-FRAME-OPTIONS
X-Request-ID
Timing-Allow-Origin
X-Iinfo
X-Dns-Prefetch-Control
X-DNS-Prefetch-Control
X-Drupal-Dynamic-Cache
Feature-Policy
Server-Timing
X-Content-Security-Policy
Access-Control-Expose-Headers
Content-Encoding
X-CDN
X-XSS-PROTECTION
Status
Upgrade
X-AspNetMvc-Version
Access-Control-Max-Age
X-Amz-Request-Id
X-Via
X-Amz-Id-2
Request-Context
X-Turbo-Charged-By
X-Backend
X-Cache-Group
X-AH-Environment
X-Robots-Tag
Cf-Edge-Cache
Keep-Alive
Host-Header
X-Hacker
X-UA-Device
X-Proxy-Cache
X-Vhost
X-Server
X-Rq
X-Server-Powered-By
Allow
X-Ws-Request-Id
X-Age
X-Dispatcher
X-Varnish-Cache
EagleId
X-Amz-Version-Id
X-LiteSpeed-Cache
P3p
Nel
Grace
Cf-Apo-Via
Cf-Railgun
X-Page-Speed
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
EagleEye-TraceId
X-Swift-CacheTime
X-Swift-SaveTime
X-Aws-Lambda-Call-Status
Ali-Swift-Global-Savetime
X-OneAgent-JS-Injection
X-Pingback
X-Host
X-Node
Accept-CH
X-WebKit-CSP
X-Cache-Lookup
X-CST
X-Backend-Server
X-Server-Id
Surrogate-Control
X-Readtime
Permissions-Policy
X-Nginx-Cache-Status
X-Nginx-Upstream-Cache-Status
X-Akam-SW-Version
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
Request-Id
X-Application-Context
Accept-CH-Lifetime
X-Content-Security-Policy-Report-Only
X-Cloud-Trace-Context
X-Response-Time
X-HW
X-Ua-Compatible
X-Trace
Xkey
X-Ruxit-JS-Agent
X-Edge
Content-Location
X-Clacks-Overhead
X-Mod-Pagespeed
X-Url
Rating
X-ESI
X-Midtier
X-Oneagent-Js-Injection
X-Amz-Server-Side-Encryption
X-ECACHE
X-Mcache
Accept-Ch-Lifetime
Cache-Tag
X-Country
X-MS-InvokeApp
X-Rack-Cache
X-Upstream
X-D2id
X-Powered-By-Plesk
X-Vcap-Request-Id
X-Exp-Id
X-Cdn-Fetch
Verso
X-Exp-Variant
X-Kinja
X-Kinja-Server
X-Kinja-Revision
X-Kinja-Build
X-GoogleNews-Bot
X-Use-Magma
X-Element-Page-Cache
Accept-Ch
Edge-Control
Service-Worker-Allowed
X-TtlSet
X-Vname
X-PC
RTSS
X-Country-Code
X-Ac
Origin-Trial
X-WebKit-CSP-Report-Only
X-Goog-Hash
X-VARITI-CCR
X-Navigation-Version
X-Abt-Application-Version
Fastly-Restarts
X-Cache-TTL
X-Ruxit-Js-Agent
X-GitHub-Request-Id
X-Browser-Type
X-Cached
X-Amz-Rid
X-Kinja-CCPA
X-Varnish-TTL
X-Aspnetmvc-Version
Cross-Origin-Opener-Policy
X-Webkit-CSP
X-Sol
Pagespeed
Display
X-Middleton-Display
X-Server-Name
X-NWS-LOG-UUID
X-Dw-Request-Base-Id
X-Amzn-Trace-Id
X-SharePointHealthScore
SPRequestGuid
X-Ttl
X-Content-Type
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-Times
SPIisLatency
SPRequestDuration
X-Kraken-Loop-Name
X-Instrumentation
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Server-Lifecycle-Phase
X-Powered-CMS
AR-ATIME
AR-PoweredBy
AR-Request-ID
X-Cache-Key
AR-SID
Pinterest-Version
X-Pinterest-Rid
X-Mg-S
Pinterest-Generated-By
X-B3-Traceid
Arr-Disable-Session-Affinity
X-Middleton-Response
Response
X-Litespeed-Cache
X-Client-IP
X-Fastly-Request-ID
X-Version
X-Cnection
X-HP-Webp
X-HP-Trace-Id
X-Jurisdiction
X-Ser
AR-CACHE
X-FastCGI-Cache
Nginx-Cache
Cache-Tags
X-Accel-Expires
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-T
Cache-Status
Edge-Cache-Tag
X-B3-TraceId
X-Hits
X-MSEdge-Ref
Front-End-Https
X-RateLimit-Remaining
X-Px
Public-Key-Pins
X-NF-Request-ID
X-Recruiting
Payment
S
X-LLID
X-Frontend
X-Ua-Browser
X-Shield-Request-Id
X-B3-TraceId-Primal
Server-Node
Mrf-Cache-Status
MRF-Tech
X-RateLimit-Limit
X-Request-Received
X-Request-Processing-Time
X-Server-ID
X-GUploader-UploadID
Content-MD5
X-Goog-Metageneration
X-Daa-Tunnel
X-DIS-Request-ID
MicrosoftSharePointTeamServices
Access-Control-Request-Method
X-PressLabs-Stats
X-Content-Digest
X-Amz-Apigw-Id
X-Amzn-RequestId
TP-Cache
Realpath
X-Protected-By
X-HS-Combine-CSS
X-Request-Handler-Origin-Region
X-Forwarded-For
X-HS-Content-Id
X-Microsite
X-HS-Cache-Config
X-Distributor
X-HS-Hub-Id
Fastcgi-Cache
X-TTL
X-Fastcgi-Cache
Access-Control-Allow-Method
X-FB-Debug
X-Page-Id
X-LB-Cache
X-Cluster-Name
Accept-Charset
X-Rid
X-Ratelimit-Remaining
TP-L2-Cache
X-Geo-Country
X-Hostname
X-Erf-Stays-Pdp-Viaduct-Migration-Web
X-Goog-Stored-Content-Length
X-B3-Sampled
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Webkit-CSP-Report-Only
X-Goog-Generation
Count-Hit
X-Aspnet-Version
X-Seen-By
X-Ua-Device
X-Ezoic-Cdn
Cross-Origin-Resource-Policy
Cleartype
X-Kinsta-Cache
TCN
X-Newrelic-App-Data
X-Edge-Location-Klb
X-App-Server
Referer-Policy
X-Varnish-Backend
X-Mobile
X-Logged-In
X-Correlation-Id
X-Ratelimit-Limit
X-Content-Options
DC
X-Id
X-Hosted-By
X-Git-Hash
X-Origin-Cache
X-Contextid
X-Aspnet-Duration-Ms
X-Request-Guid
X-Flags
X-Providence-Cookie
X-Is-Crawler
X-Fb-Rlafr
X-Route-Name
X-Amz-Replication-Status
X-Debug-Info
X-Revision
Surrogate-Key
X-Grace
X-TT
Retry-After
X-App-Environment
X-IPS-LoggedIn
X-Varnish-Grace
X-Amz-Meta-S3cmd-Attrs
X-Forwarded-Proto
Frame-Options
X-Xrds-Location
X-Envoy-Decorator-Operation
X-F-Cache
X-Azure-Ref
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-TEC-API-VERSION
Section-Io-Cache
X-RateLimit-Reset
X-Magnolia-Registration
X-Wix-Request-Id
X-Whom
MS-Author-Via
Healthy
Alternate-Protocol
Charset
X-Proxy-Cache-Info
X-Origin-Server
X-Akamai-Edgescape
Viewport
X-App-Version
X-Nf-Request-Id
X-Www-Served-By
X-Backend-Name
X-COUNTRY
WPO-Cache-Message
X-Webkit-Csp
X-Language
WPO-Cache-Status
X-Activity-Id
X-Az
X-AppVersion
X-B
Paypal-Debug-Id
X-Varnish-Server
Filterid
SRV
X-Original-Request-Id
X-Http-Reason
X-Datadog-Trace-Id
VIX-Pulpo-Node
X-Cache-Rule
X-Datadog-Sampling-Priority
X-Response-Served-From
VIX-Pulpo-Upstream-Status
X-Datadog-Parent-Id
SD-X-WS
Host
Server-Name
X-Instance
Akamai-GRN
X-User-Agent
X-UUID
X-Edge-Location
X-Cache-Grace
Front
X-Akamai-Request-ID2
X-Kong-Proxy-Latency
X-Rule
X-Kong-Upstream-Latency
X-Region
X-Cacheable-TTL
Protected
X-Environment-Context
X-Page-View
Amp-Access-Control-Allow-Source-Origin
X-Jobs
X-Varnish-Age
X-Unique-Id
X-Status
X-ARC
Country
X-Time
From-Origin
X-L-Path
X-FW-Type
Fastly-SIE
X-Is-Bot
Fastly-SWR
X-Adobe-Loc
X-Adobe-Content
X-Rendered-As
X-FW-Version
X-FW-Static
X-FW-Hash
X-FW-Dynamic
X-Rocket-Nginx-Serving-Static
X-FW-Serve
X-FW-Server
X-Framework
X-N
X-EdgeConnect-Cache-Status
X-Load-Cache
ServerID
X-Type
X-Trace-Id
X-Cache-Time
X-G
X-Client-Ip
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-RemovedCookies
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-ProcessESI
X-Tumblr-User
X-DataDome
X-Tumblr-Pixel-1
Content-Disposition
X-Tec-Api-Root
X-Tec-Api-Origin
X-Proxy
X-Tec-Api-Version
X-Mg-Request-UUID
Access-Control-Request-Headers
X-Datadog-Sampled
X-B-Cache
X-Signature
X-Vcache
X-Amzn-Remapped-Content-Length
X-Debug-IsConnected
X-Debug-IsPreview
X-CDN-Forward
X-Cache-Control
X-Cache-Age
X-ECache
Backend
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
Refresh
Countrycode
X-DynaTrace
X-Drupal-Cache-Tags
X-Nginx-Cache
X-Servername
Accept-Language
Xet-Cookie
X-Httpd
X-Erf-Web-Scheduler
X-Tt-Trace-Host
CF-IPCountry
Url
X-Tt-Trace-Tag
X-Generated-By
X-XRDS-LOCATION
X-DynaTrace-JS-Agent
X-Source
X-HTML-Minification-Powered-By
X-XRDS-Location
X-Template
X-Device-Type
X-Mode
Webserver
Xserver
X-NYM-Debug-Backend
X-Content-Powered-By
X-Storage
Version
GEO-INFO
X-Content-Age
X-Urbn-Context-Path
X-Urbn-Site-Id
X-GeoCountry
X-SayCDN-TTL
Meta-Geo
X-JoinUs
Locale
OT-Force-Account-Verify
X-Say-Cacheable
X-UPSTREAM-Address
X-Say-TTL
X-LAGOON
X-SaId
X-Rewrite-Enabled
Filters
X-Rn-Rsrv
X-Cache-Operation
X-ServerID
Load-Balancing
X-GeoCode
S-Rt
X-Cache-Action
X-Director
X-Cluster-Node
X-Git-Commit
X-Container-Uri
Onion-Location
X-Varnish-Hostname
X-Tt-Logid
X-Varnish-Cache-Hits
X-Soup
X-Forwarded-Host
X-Detected-As
X-Tncms
X-Cache-Hit
Azure-SiteName
Azure-SlotName
Azure-Version
Azure-RegionName
Azure-InstanceId
X-Adobe-Source
Web-Mar-Node
X-Sql-Count
X-Ms-Version
X-Ms-Request-Id
X-Lambda-Id
X-PHP-Host
X-Served-From
X-Loop
X-RM-Cache-TTL
X-Labrador-Cache-Channel
X-Sql-Duration-Ms
X-VC-Cache
X-Tb
X-Cache-Server
X-VCT
Node
X-URL
Mn-Server-Ip
X-Skip-Cache
X-Logging-Id
DB-Nickname
X-RCS-CacheZone
X-Zipkin-Id
X-Proto
X-Extlb
X-Routing-Service
X-CCDN-CacheTTL
X-FB-TRIP-ID
X-CCDN-Origin-Time
X-R9-Blue-Green-Version
X-Hcs-Proxy-Type
X-Generation-Time
X-Proxied
Cross-Origin-Window-Policy
TWC-Connection-Speed
TWC-GeoIP-LatLong
TWC-Device-Class
TWC-GeoIP-Country
X-Tumblr-Pixel-2
X-Fetched-On
TWC-Privacy
X-Proxy-Build
Webcakes-App-Name
X-Format
X-Uri
X-Debug
X-Tumblr-Pixel-3
X-Timing-Wait
Webcakes-Region
X-Origin-Hint
TWC-Locale-Group
Webcakes-App-Version
X-MCACHE
Fastcgi-Useragent
Property-Id
Selected-Fe
Uber-Trace-Id
X-Endurance-Cache-Level
X-LSADC-Cache
X-Zen-Fury
X-Redis-Cache
X-Ua
Source
X-Sucuri-ID
X-Sucuri-Cache
X-Srv
X-NGENIX-Cache
X-Drupal-Cache-Contexts
Section-Io-Id
Section-Origin-Responded
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
CDN-RequestId
X-B3-SpanId
X-Oracle-Dms-Rid
X-S
X-Varnish-Ttl
X-Oracle-Dms-Ecid
X-MP-GENERATED-AT
X-Ratelimit-Reset
X-Origin-Date
X-Pass-Why
X-Upgrade-Enabled
X-Varnish-Hits
Fastly-Drupal-HTML
X-FTR-Request-ID
X-TimeS
X-Origin-TTL
X-Cache-Expired-At
X-Origin-CC
Liferay-Portal
Upgrade-Insecure-Requests
NGB
X-Real-IP
X-Newrelic-Synthetics
X-Akamai-Transformed
X-Handled-By
X-CACHE-AGE
X-Cache-TTL-Remaining
X-UA-Device-Type
X-Xfnlog-Site
X-Cms-Context
X-Reqid
X-Optimistic-Header
Apigw-Requestid
ServedBy
X-Hl-Ver
X-Correlation-ID
X-Node-Name
X-Cache-Type
X-Restarts
X-Via-JSL
X-No-Session
CDN-Cache
X-ProxyCache-Key
X-ProxyCache-Status
X-Cache-Host
CDN-CachedAt
CDN-RequestCountryCode
X-BYPASS-REASON
X-RTag
Ms-Operation-Id
CDN-Uid
CDN-RequestPullSuccess
MS-CV
CDN-RequestPullCode
CDN-EdgeStorageId
CDN-PullZone
X-Pubstack
X-CSRF-Token
X-GEO
X-ID
X-LJ-Flow-ID
X-VWS-Id
WP-Super-Cache
X-Parent-Response-Time
X-Server-W
X-AWS-Id
X-Cluster
X-IPLB-Request-ID
X-IPLB-Instance
X-Cache-NE
X-CacheTTL
X-Tx-Id
Lang
N-Cache
Odigeo-Trace-Id
BehaviorPad-Version
HA-Ipaddr
X-BCube-Filmed-By
X-Bc-Bl
X-Vdms-Path
Candidate-Md5Url
Canary
Redirect-Candidate
X-Bl-Debug
X-FC-Vary-Parameters
X-Debug-Cache-Store
X-Eu-Site
Vix-Hermes-Req-Id
X-CF-Lambda-Version
X-Destination
X-Developer
X-CGP
True-Client-Country-4JS
Ngx.Var.Host
T-Server
Magicmarker
X-Dispatcher-Number
X-CF-Lambda-Fn
X-B-Cookie
X-SRCache-Key
X-External-Request-Id
MD5-Digest
X-Epic-Correlation-Id
X-Ec-Custom-Error
X-Ec-Fail
X-Ec-GeoHdr
X-Fastly-Backend
X-Worker
Sslversion
X-We-Are-Hiring
Gannett-Cam-Experience-Id
X-Vtex-Remote-Cache
X-Conf
Fastly-SSL
Xc-Version
X-A-Dcw
X-A-Dam
X-A-Ccd
Server-Host
X-Request-Host
Web-Mar-Region
X-ScT
X-SD-PageType
Ha-Gx-Prefs
Origin-Agent-Cluster
X-S-Cookie
X-Viewer-Country
X-A
X-Rojux
X-A-Wwc
X-A-Dgt
L
Rendered-Blocks
X-Slack-Backend
X-Vdms-Version
X-App
X-App-Name
L5d-Success-Class
X-Debug-Cache-Fetch
X-Application
Meta-Geo-Continent
X-Slack-Shared-Secret-Outcome
DCR-Decision-By
DCR-Processing-Time-Ms
X-Csrf-Jwt
X-D
X-Aed
W
Surrogated-Key
Cache-Provider
X-AB
X-Proxy-Cache-Status
X-Datadome
Thinkindot-CacheControl
X-CMSURLCustom
X-Clientip
TDXMobile
Thinkindot-CacheControl-Type
X-Bip
VNS-Cache
X-Alternate-Cache-Key
X-Accel-Expires-Debug
X-Accel-Buffering
We-Hiring
Req-Svc-Chain
Release
X-Cache-Bucket
X-Cdn-Origin
VNS-Age
X-Cdn-Diag
X-Cache-Info
X-Cache-Debug
Thinkindot-Control
X-Mly-Id
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Sn-Servicetimems
X-Storefront-Renderer-Rendered
X-SVT-ORM-RULES
X-Tenant
X-SVT-ORM-VERSION
X-Shopify-Stage
X-ShopId
X-Request-Time
X-Refresh
X-RateLimit-Remaining-Second
X-S-Maxage
X-Server-IP
X-Shop-Environment
X-ShardId
X-Test
X-Thanos
X-VServer
X-Vmg-Version
X-VG-WebCache
X-Wikidot-Backend
X-Wikidot-Static-Cache
Host-ID
X-Wix-Viewer-Type
X-VG-TLSProxy
X-Varnishpool
X-Var-Ttl
X-Up
X-Thinkindot-L3
X-Variation
X-Varnish-CookieHashed-On
X-Varnish-Remaining-TTL
X-Varnish-CookieINHashed-On
X-RateLimit-Limit-Second
X-Qloud-Router
X-Hash
X-GeoIP-Region-Code
X-GeoIP-Country-Code
X-Human
X-Irp-Debug
X-Loc
X-Level-Front-Cache
X-Geo-Header
X-Generated-On
X-DefElseHash
X-Date
X-Core-Value
X-DefHash
X-DPWN-IS-SECURE
X-Gdpr
X-Forwarded-Path
X-Mid
Producers
X-Owner
X-Origin-Time
X-Orig-Expires
X-PAYTM-SRV-ID
X-Platform
X-Pool
X-Policy
X-Org
X-Old-Content-Length
X-Nananana
X-Mvc-Supplant-Cachable
X-Nitro-Cache
X-Node-Id
X-Nyt-Route
X-NodeID
X-Core-Mission
X-BBC-Edge-Cache-Status
AKAMAI
Fastly-GeoIP-CountryCode
Fastly-Backend-Name
Gh-Request-Id
Adler-Geo
Platform
Is-Eu
Expect-Staple
Environment
CPC-Age
Cmsid
Cmstype
Cf-Device-Type
CPC-Cache
Content-Secure-Policy
Datacenter
Mail-Subject
X-B3-Spanid
Origin
X-Cache-Status-Check
X-Micro-Cache
AMP-Access-Control-Allow-Source-Origin
X-TIME
User-Cache-Control
X-Block-Status
X-WADP-Cache
X-Nginx-Cache-Key
Apple-News-Services-Request-Url
X-GeoIP
X-Cache-Id
X-Hnp-Log
X-Mvc-Supplant-OutputCached
X-INCAP-ABP
X-Geo-Region
CloudFront-Viewer-Country
CDCHOST
X-Origin
X-Gzip
X-WA-Info
X-Clara-WADP
X-Forwarded-Site
X-Auto-Login
X-Device-Os
X-Fmm-Version
X-Dispatcher-Server
X-From
X-PERF
X-Esi-Check
X-Gen-Mode
Apple-News-Services-Parsed-Url
Apple-News-Services-Handled
X-Cdn-Srv
X-Origin-Response-Time
Apple-News-Services-Host
DSUID
Sever-Int
Esi-Enabled
Server-Hostname
Server-Ext
Cache-Name
NM-Fastcgi-Cache
X-Akamai-Device-Characteristics
Country-Code
X-ApacheServer
Machine
X-Vcl-Version
X-TraceId
X-AIR-PT
X-Section
Wxu-Next-Commit
Ssr
Server-Info
NGX
X-Op-Id-All
X-Instance-Name
X-Cache-Enabled
X-Access
Wxu-Next-Hostname
X-LB-NoCache
C-Via
Pics-Label
X-NCache
Wxu-Next-Region
X-Dc
X-Vgn-Hpd-Reason
X-Via-Fastly
X-Amz-Meta-Cb-Modifiedtime
Server-ID
X-Fastly-Request-Id
X-Accel-Version
X-API-Version
X-CACHE-GROUP
X-Has-Esi
X-JWT-State
X-HA-Backend
X-Is-Gdpr
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Ttl
Memcached
X-Is-Desktop
X-Browser-Name
X-Is-Mobile
X-Buckets
X-Tcp-Rtt
X-Is-Supported-Browser
X-Is-Tablet
Cdn-Requestid
Time
IsBot
Hostname
Memory
X-SIPLIST1
X-Platform-Router
X-Scale
Origin-CC
Sid
Origin-EX
X-Platform-Processor
Cache-Hits
X-Platform-Cluster
Location
X-Air-Hostname
X-Air-Source
X-Air-Trace-Id
X-TIM-N
X-ZONE
X-Zone
YJS-ID
X-B3-Parentspanid
X-PHP-Backend
X-Tb-Optimization-Total-Bytes-Saved
CF-Ctrl
X-Wp-Cf-Super-Cache-Active
X-Presslabs-Stats
X-Cached-By
X-Fpc
X-WP-CF-Super-Cache-Active
X-Backend-Instance
X-Internal-Host
X-Frame-Option
X-Origin-Cache-Key
X-Azure-Ref-OriginShield
X-Hyper-Cache
Resin-Trace
X-DC
X-Cs
Uri
GeoIP-Latitude
X-TA-CDN-Provider
X-VC
X-Origin-Expires
Epwk-X-Cache
X-Service
True-Client-Ip
Cache-Host
X-VCache
X-Microcachable
X-Site-Version
X-DataCenter
X-Webstats-RespID
X-LiteSpeed-Cache-Control
X-NGINX-Cache
X-Nitro-Cache-From
X-Country-Code-Real
X-FTR-Expires
X-Nitro-Rev
XM
X-FTR-Cache-Status
X-FTR-Balancer
X-FTR-Backend
X-FTR-Backend-Server
GeoIp-Country-Code
X-Locale
X-Info
X-Web-Node
X-VarnishDD-TTL
PFcat
X-HN
LB
GeoIP-Country-Code
Cdn
X-Pod-Name
X-Geo
X-Ad-Defer-Variation
X-Datacenter
XServer
NtCoent-Length
X-CS
X-Cache-Ttl
User-Agent
Cdn-Host
Cdn-Request-Time
X-Edge-Server
X-NewRelic-App-Data
X-CSRF-TOKEN
A
X-Via-CDN
X-Via-SSL
X-Via-Edge
X-NMSegId
WZWS-RAY
Srvid
M-TraceId
True-Client-IP
X-FL-EDGE
X-FL-QIT-DEBUG
Locid
Edge-Copy-Time
Req-ID
WebServer
X-SRV
X-TRACE-ID
X-Ad-Load-Variation
X-Vercel-Id
X-Vercel-Cache
SID
X-M-Reqid
X-MSEdge-Features
X-Contensis-Viewer-Groups
X-Scope-Id
X-MSEdge-Flight
Pramga
X-ATG-Version
Cluster
X-FPC
X-M-Log
X-Cache-ASPX
X-Pad
X-Request-Start
X-Varnish-Authentication
X-Moov-Xdn-Version
Fastly-Drupal-Html
X-Moov-T
X-FireWall-Port
X-HostName
X-Request-URI
Tcn
X-LiteSpeed-Tag
X-Varnish-Beresp-Status
Cache-Key
X-Qnm-Cache
X-Shield-Cache-Expires
X-NWS-UUID-VERIFY
Cf-Ipcountry
CountryCode
X-Cdn-Request-ID
HostName
X-APP-VERSION
X-Api-Version
X-Esi
Edge-Cache
X-Cache-Date
Content-Script-Type
X-AK-Request-ID
Content-Style-Type
Cdnsip
Cdncip
Path
X-Amz-Meta-Opti
X-Air-Pt
Cache-Tv-Group
X-TH-Server
X-Branch-Name
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-LB-ID
X-Cache-FS-Status
X-Planisys-CDN-Rules
X-Platform-Server
X-Acquia-Purge-Cdn-Unconfigured
X-Planisys-CDN-TTL
X-SB
Tube-Get-Contents
X-Wa
Yak-Timeinfo
X-Render-Time
X-Via-Popv
X-Aicache-OS
Click-Count-Error
Click-Count-Action-Start
X-WP-CF-Super-Cache-Cookies-Bypass
X-Req
XkeyRZ
X-Github-Request-Id
X-Nc
X-B3-Trace-ID
X-Planisys-CDN-Cache
X-Via-Popn
X-Proxy-CacheRZ
X-Via-Poph
Tube-Got-Results
Tube-Got-Eval
State
Tube-Return
X-Servedbyhost
X-HS-Content-Campaign-Id
X-V-Cache
X-VCL-Version
X-Upstream-Ct
X-CACHE-KEY
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
Lb
CDN
X-Upstream-Ht
Geoip-Latitude
X-Akamai-Pragma-Client-IP
X-Vgn-Hpd-Ssi
X-Cdn-Forward
X-Vgn-Hpd-Cached
X-Vgn-Hpd-Variations-Key
Srv
X-Wp-Cf-Super-Cache-Cache-Control
X-Fastly-Cache
X-Release
X-Wp-Cf-Super-Cache
X-Tim-N
On-Server
X-Men
Proxy-Connection
Wpo-Cache-Status
V-Age
Wpo-Cache-Message
X-Vary
X-Lb-Cache
X-User
MIME-Version
Ngx-Var-Key
X-Rocket-Build-Number
X-UA
X-Generated-In
X-HS-Status
Ohc-File-Size
X-Dw-Trace-Id
CF-Cached-On
X-Sigma
X-Sigma-Backend
X-Traceid
X-Ha-Backend
X-Cache-Remote
Server-Id
X-TT-LOGID
X-EC-Lua
X-Acquia-Site
X-Lb-Nocache
PICS-Label
Ohc-Cache-HIT
My-App
X-Fastly-Backend-Reqs
X-Acquia-Application-Trace
X-Via-Ucdn
X-Acquia-Application-UUID
Cache
X-CUA
X-Acquia-Purge-Tags
X-Iplb-Request-Id
X-TX-ID
X-Iplb-Instance
Yjs-Id
Mime-Version
X-GoCache-CacheStatus
Warning
X-GeoIP-City
X-Gamma-Serve
X-Fastly-Cache-Hits
X-CF-Cache-Header-Vary
Ngx
X-Litespeed-Cache-Control
X-CF-Cache-Header-Cache-Control
Log-Origin
X-Miniprofiler-Ids
X-RAMCache
X-Udemy-Cache-App-Namespace
X-ElasticPress-Query
Inserted-Into-Cache-At
CACHE-MISS-TO-ORIGIN
Cneonction
X-Snapshot-Date
X-Cached-Since
Vha6-Origin
X-Scheme