Threat Level: green Handler on Duty: Guy Bruneau

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
Pragma
X-Powered-By
X-XSS-Protection
CF-RAY
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
P3P
Alt-Svc
X-Cache-Hits
X-UA-Compatible
X-Xss-Protection
X-Served-By
CF-Ray
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Request-Id
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
Access-Control-Allow-Credentials
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
X-Drupal-Cache
X-Generator
X-Cache-Status
X-Check
X-Cacheable
X-Envoy-Upstream-Service-Time
X-Request-ID
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-FRAME-OPTIONS
X-Iinfo
X-Dns-Prefetch-Control
X-Drupal-Dynamic-Cache
Feature-Policy
X-Content-Security-Policy
Content-Encoding
Access-Control-Expose-Headers
Upgrade
Status
X-CDN
X-XSS-PROTECTION
X-AspNetMvc-Version
Server-Timing
Access-Control-Max-Age
X-Amz-Request-Id
Request-Context
X-Amz-Id-2
X-Turbo-Charged-By
X-AH-Environment
X-Via
X-Robots-Tag
X-Backend
X-Cache-Group
Cf-Edge-Cache
Keep-Alive
Host-Header
X-Proxy-Cache
X-Hacker
X-Server
X-UA-Device
X-Rq
X-Server-Powered-By
X-Age
Allow
X-Vhost
X-Varnish-Cache
X-Ws-Request-Id
EagleId
X-Dispatcher
X-Amz-Version-Id
Grace
X-LiteSpeed-Cache
P3p
Cf-Apo-Via
Nel
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Page-Speed
X-Device
Cf-Railgun
EagleEye-TraceId
X-Aws-Lambda-Call-Status
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
Accept-CH
X-Pingback
X-Node
X-WebKit-CSP
X-Host
X-OneAgent-JS-Injection
X-Server-Id
Surrogate-Control
X-Backend-Server
X-CST
X-Readtime
X-Nginx-Cache-Status
X-Akam-SW-Version
X-Cache-Lookup
Permissions-Policy
X-Content-Security-Policy-Report-Only
Request-Id
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Application-Context
X-Nginx-Upstream-Cache-Status
X-Cloud-Trace-Context
X-Trace
X-Response-Time
X-Edge
X-HW
Accept-Ch-Lifetime
Accept-CH-Lifetime
X-Ua-Compatible
Content-Location
X-Mod-Pagespeed
X-Clacks-Overhead
X-Url
X-Ruxit-JS-Agent
X-Midtier
X-Oneagent-Js-Injection
X-ECACHE
Rating
X-ESI
X-Amz-Server-Side-Encryption
X-Mcache
X-Country
Xkey
X-Litespeed-Cache
X-Upstream
X-Vname
X-TtlSet
X-PC
X-Vcap-Request-Id
Cache-Tag
X-D2id
X-MS-InvokeApp
X-Rack-Cache
X-Exp-Id
X-Element-Page-Cache
X-Cdn-Fetch
Verso
X-Exp-Variant
X-Kinja-Server
X-Use-Magma
X-GoogleNews-Bot
X-Kinja-Revision
X-Kinja-Build
X-Kinja
Edge-Control
X-Cache-TTL
Fastly-Restarts
RTSS
X-Powered-By-Plesk
X-VARITI-CCR
Origin-Trial
X-Ac
X-Content-Type
X-Navigation-Version
Accept-Ch
X-Abt-Application-Version
X-Cached
X-Ruxit-Js-Agent
X-Goog-Hash
Service-Worker-Allowed
X-Country-Code
X-GitHub-Request-Id
X-Ttl
X-Middleton-Display
X-Sol
Pagespeed
X-Amz-Rid
Display
X-WebKit-CSP-Report-Only
X-Mg-S
X-Browser-Type
X-Dw-Request-Base-Id
X-SharePointHealthScore
SPRequestGuid
X-Server-Name
Cross-Origin-Opener-Policy
X-Varnish-TTL
X-B3-TraceId
Arr-Disable-Session-Affinity
X-Kraken-Loop-Name
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Server-Lifecycle-Phase
X-Instrumentation
X-Powered-CMS
Response
AR-SID
AR-ATIME
X-Middleton-Response
AR-PoweredBy
AR-Request-ID
X-Amzn-Trace-Id
SPRequestDuration
SPIisLatency
X-Cache-Key
AR-CACHE
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Fastly-Request-ID
X-Webkit-CSP
X-Version
X-HP-Webp
X-HP-Trace-Id
X-Jurisdiction
X-Cnection
X-Times
X-Accel-Expires
X-ORACLE-DMS-RID
X-T
X-ORACLE-DMS-ECID
Cache-Tags
Cache-Status
Front-End-Https
X-Client-IP
Edge-Cache-Tag
X-MSEdge-Ref
Pinterest-Version
Pinterest-Generated-By
X-Pinterest-Rid
X-Px
X-NF-Request-ID
X-Ser
X-Hits
Nginx-Cache
Public-Key-Pins
X-Fastcgi-Cache
X-Recruiting
X-NWS-LOG-UUID
MRF-Tech
X-Ua-Device
X-B3-TraceId-Primal
Mrf-Cache-Status
X-B3-Traceid
X-LLID
X-Frontend
X-Request-Processing-Time
X-Request-Received
Server-Node
X-Shield-Request-Id
X-Ua-Browser
Payment
X-FastCGI-Cache
Access-Control-Request-Method
X-Kinja-CCPA
X-DIS-Request-ID
TP-Cache
X-Erf-Stays-Pdp-Viaduct-Migration-Web
X-Webkit-CSP-Report-Only
X-RateLimit-Remaining
X-Goog-Metageneration
X-Ratelimit-Remaining
MicrosoftSharePointTeamServices
S
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Cache-Config
X-HS-Combine-CSS
TP-L2-Cache
X-LB-Cache
X-Content-Digest
X-Distributor
Content-MD5
X-PressLabs-Stats
Realpath
X-Microsite
X-Request-Handler-Origin-Region
X-Server-ID
X-Geo-Country
X-Ezoic-Cdn
X-Hostname
Access-Control-Allow-Method
X-Page-Id
X-FB-Debug
X-Forwarded-For
X-RateLimit-Limit
X-GUploader-UploadID
Fastcgi-Cache
Accept-Charset
X-Cluster-Name
X-Protected-By
X-Rid
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Envoy-Decorator-Operation
X-Seen-By
X-Ratelimit-Limit
Cleartype
X-B3-Sampled
X-Correlation-Id
TCN
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
DC
X-Goog-Storage-Class
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Newrelic-App-Data
Referer-Policy
X-Origin-Server
X-Debug-Info
X-Mobile
X-XRDS-Location
X-Webkit-Csp
X-Origin-Cache
X-Varnish-Backend
Cross-Origin-Resource-Policy
X-TTL
X-Logged-In
X-Aspnet-Version
X-Git-Hash
X-Azure-Ref
X-Varnish-Grace
X-Contextid
X-Edge-Location-Klb
X-Kinsta-Cache
X-Request-Guid
X-Providence-Cookie
X-Revision
Alternate-Protocol
X-Route-Name
Surrogate-Key
X-Amz-Replication-Status
X-Flags
X-Aspnet-Duration-Ms
X-App-Environment
X-Is-Crawler
X-Fb-Rlafr
X-Grace
X-Content-Options
X-TT
Count-Hit
X-IPS-LoggedIn
X-Amz-Meta-S3cmd-Attrs
Healthy
X-Wix-Request-Id
X-Forwarded-Proto
X-Whom
Frame-Options
X-App-Server
X-Hosted-By
Charset
WPO-Cache-Message
WPO-Cache-Status
X-Akamai-Edgescape
MS-Author-Via
Viewport
X-Aspnetmvc-Version
Filterid
X-Daa-Tunnel
X-Magnolia-Registration
X-Id
X-B
Paypal-Debug-Id
X-Backend-Name
X-Client-Ip
Retry-After
Section-Io-Cache
X-Cache-Age
X-F-Cache
Amp-Access-Control-Allow-Source-Origin
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Trace-Id
X-Activity-Id
SRV
X-Cache-Control
X-Az
X-AppVersion
X-Proxy-Cache-Info
X-Www-Served-By
Server-Name
X-Type
X-Varnish-Server
Refresh
X-Oracle-Dms-Ecid
X-App-Version
X-Http-Reason
X-Response-Served-From
X-Proxy
X-Instance
X-Original-Request-Id
VIX-Pulpo-Upstream-Status
Host
X-Oracle-Dms-Rid
X-Cache-Rule
X-ARC
Akamai-GRN
SD-X-WS
VIX-Pulpo-Node
X-Time
X-Rule
X-Akamai-Request-ID2
X-Edge-Location
X-Rocket-Nginx-Serving-Static
Front
Version
X-User-Agent
X-Status
Protected
X-Varnish-Age
X-UUID
X-Cache-Grace
From-Origin
Fastly-SIE
X-Jobs
X-Page-View
X-Region
X-EdgeConnect-Cache-Status
Fastly-SWR
X-Unique-Id
X-Rendered-As
X-Is-Bot
X-L-Path
X-FW-Hash
X-FW-Serve
X-FW-Dynamic
X-COUNTRY
X-Cacheable-TTL
X-Environment-Context
X-FW-Server
X-Framework
X-FW-Version
X-FW-Type
X-FW-Static
X-Cache-Time
Access-Control-Request-Headers
X-Adobe-Content
X-Adobe-Loc
X-N
X-Tumblr-User
X-G
X-Tumblr-Pixel-1
X-ProcessESI
X-RemovedCookies
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Load-Cache
ServerID
X-Source
X-Upgrade-Enabled
X-Nf-Request-Id
X-Varnish-Ttl
X-Language
X-RateLimit-Reset
Country
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
X-Datadog-Trace-Id
Content-Disposition
X-Drupal-Cache-Tags
X-Vcache
X-CDN-Forward
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-DataDome
X-HTML-Minification-Powered-By
X-Datadog-Sampled
Accept-Language
X-Tt-Trace-Tag
X-Amzn-Remapped-Content-Length
X-Tt-Trace-Host
Countrycode
X-Mg-Request-UUID
X-Debug-IsConnected
X-DynaTrace
X-Debug-IsPreview
X-Xrds-Location
X-ID
X-Generated-By
X-DynaTrace-JS-Agent
Backend
X-ECache
Xet-Cookie
CF-IPCountry
X-B-Cache
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
Liferay-Portal
X-Signature
Webserver
X-Nginx-Cache
Xserver
X-B3-SpanId
X-Tt-Logid
X-Httpd
X-Mode
X-NYM-Debug-Backend
X-Device-Type
X-Erf-Web-Scheduler
X-Drupal-Cache-Contexts
X-Servername
X-Content-Powered-By
X-Zen-Fury
X-Content-Age
Url
X-SaId
X-UPSTREAM-Address
X-Git-Commit
X-Say-Cacheable
X-Cache-Action
Azure-RegionName
X-SayCDN-TTL
X-Sucuri-Cache
X-Say-TTL
Meta-Geo
X-LAGOON
X-Sucuri-ID
X-Container-Uri
S-Rt
X-JoinUs
Locale
Load-Balancing
X-Tb
X-ServerID
Azure-SlotName
X-Urbn-Context-Path
Onion-Location
GEO-INFO
X-Director
X-Varnish-Cache-Hits
Azure-InstanceId
Azure-SiteName
Azure-Version
X-Rewrite-Enabled
Filters
X-Cache-Operation
Fastcgi-Useragent
X-GeoCountry
X-GeoCode
X-Proto
X-Urbn-Site-Id
X-Forwarded-Host
X-Varnish-Hostname
X-Cluster-Node
Uber-Trace-Id
X-PHP-Host
X-VC-Cache
X-Ratelimit-Reset
X-Soup
X-Labrador-Cache-Channel
X-RM-Cache-TTL
X-VCT
X-Storage
X-Ms-Request-Id
X-Logging-Id
X-Generation-Time
X-Adobe-Source
X-Sql-Duration-Ms
X-Served-From
X-Sql-Count
X-Ms-Version
X-Cache-Server
X-Detected-As
Web-Mar-Node
TWC-Privacy
TWC-Locale-Group
Webcakes-App-Name
Webcakes-App-Version
Webcakes-Region
TWC-GeoIP-LatLong
TWC-GeoIP-Country
Node
Property-Id
TWC-Connection-Speed
TWC-Device-Class
X-Debug
X-Extlb
X-Tec-Api-Root
X-Tec-Api-Origin
X-Skip-Cache
X-Zipkin-Id
X-Tec-Api-Version
X-Routing-Service
X-FB-TRIP-ID
X-Origin-Hint
X-Proxied
X-R9-Blue-Green-Version
Mn-Server-Ip
X-RCS-CacheZone
DB-Nickname
X-Tumblr-Pixel-3
X-Fetched-On
X-Format
Selected-Fe
X-Uri
X-Timing-Wait
X-Tumblr-Pixel-2
X-Proxy-Build
X-LSADC-Cache
X-Lambda-Id
CDN-RequestId
OT-Force-Account-Verify
Fastly-Drupal-HTML
X-Template
X-MP-GENERATED-AT
X-Origin-Date
Source
X-XRDS-LOCATION
X-MCACHE
X-Cache-Expired-At
X-Tncms
X-Cache-Hit
X-Loop
X-Srv
X-Pass-Why
X-Varnish-Hits
X-Via-JSL
X-Endurance-Cache-Level
Content-Secure-Policy
X-NGENIX-Cache
X-Cache-TTL-Remaining
X-Redis-Cache
X-Ua
X-UA-Device-Type
Upgrade-Insecure-Requests
X-Node-Name
X-Fastly-Request-Id
X-Real-IP
Cross-Origin-Window-Policy
X-Pubstack
X-AIR-PT
X-Origin-CC
X-Origin-TTL
X-Hcs-Proxy-Type
X-CCDN-Origin-Time
Section-Io-Origin-Time-Seconds
X-CCDN-CacheTTL
Section-Io-Id
Section-Io-Origin-Status
X-Server-W
Section-Origin-Responded
NGB
X-GEO
X-PHP-Backend
X-S
Cache-Hits
Cache-Provider
X-Rn-Rsrv
X-Cache-Host
CDN-Cache
CDN-RequestCountryCode
CDN-EdgeStorageId
CDN-RequestPullCode
CDN-CachedAt
CDN-PullZone
X-RTag
CDN-RequestPullSuccess
Ms-Operation-Id
Cache-Name
MS-CV
X-CSRF-Token
CDN-Uid
X-Restarts
X-IPLB-Instance
X-Cms-Context
X-TimeS
X-Cache-Type
Apigw-Requestid
X-Xfnlog-Site
X-IPLB-Request-ID
X-Reqid
X-Hl-Ver
X-Optimistic-Header
X-Akamai-Transformed
X-Datadome
X-BYPASS-REASON
X-No-Session
X-ProxyCache-Status
X-ProxyCache-Key
X-CACHE-AGE
X-Parent-Response-Time
X-Newrelic-Synthetics
Canary
Gh-Request-Id
X-A-Dam
Ha-Gx-Prefs
Fastly-SSL
Gannett-Cam-Experience-Id
X-A-Dcw
X-A-Dgt
HA-Ipaddr
DCR-Decision-By
CPC-Cache
CPC-Age
DCR-Processing-Time-Ms
Candidate-Md5Url
Fastly-GeoIP-CountryCode
Fastly-Backend-Name
X-A-Wwc
X-Accel-Buffering
Magicmarker
Ngx.Var.Host
T-Server
N-Cache
True-Client-Country-4JS
Surrogated-Key
Odigeo-Trace-Id
Sslversion
Server-Host
Rendered-Blocks
Redirect-Candidate
Meta-Geo-Continent
Vix-Hermes-Req-Id
We-Hiring
Web-Mar-Region
X-A
L5d-Success-Class
Lang
W
VNS-Age
MD5-Digest
Mail-Subject
VNS-Cache
L
X-Date
X-Is-Gdpr
X-Viewer-Country
X-Vtex-Remote-Cache
X-JWT-State
X-Mvc-Supplant-Cachable
X-Orig-Expires
X-Nyt-Route
X-Irp-Debug
X-Has-Esi
X-FC-Vary-Parameters
X-Fastly-Backend
X-External-Request-Id
X-Forwarded-Path
X-Gdpr
X-GeoIP-Region-Code
X-GeoIP-Country-Code
X-Origin-Time
X-Policy
X-Tenant
X-Var-Ttl
X-Vdms-Path
X-SD-PageType
X-SRCache-Key
X-Slack-Backend
X-Shop-Environment
X-Vdms-Version
X-VG-WebCache
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-Request-Host
X-Rojux
X-ScT
X-S-Cookie
X-Eu-Site
X-Epic-Correlation-Id
X-CF-Lambda-Fn
X-Cdn-Diag
X-CacheTTL
X-CF-Lambda-Version
X-CGP
X-Csrf-Jwt
X-Conf
X-Cache-NE
X-Cache-Info
X-B-Cookie
X-Application
X-Aed
X-Bc-Bl
X-BCube-Filmed-By
X-Cache-Bucket
X-Bl-Debug
X-D
Xc-Version
X-Dispatcher-Number
X-Wikidot-Backend
BehaviorPad-Version
X-Ec-Custom-Error
X-Ec-Fail
X-We-Are-Hiring
X-Ec-GeoHdr
X-Developer
X-Destination
X-Slack-Shared-Secret-Outcome
X-Worker
X-Wix-Viewer-Type
X-Debug-Cache-Fetch
X-Wikidot-Static-Cache
X-Debug-Cache-Store
X-Accel-Expires-Debug
X-A-Ccd
X-LJ-Flow-ID
X-VWS-Id
X-Cluster
X-Via-Fastly
X-AWS-Id
X-Section
X-Handled-By
X-Access
X-Mid
X-Level-Front-Cache
AKAMAI
X-Loc
TDXMobile
X-Human
Thinkindot-Control
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
X-INCAP-ABP
X-Nitro-Cache
Origin
X-Org
X-Origin-Response-Time
X-Owner
X-PAYTM-SRV-ID
X-Old-Content-Length
Producers
Req-Svc-Chain
X-Hash
Release
X-Node-Id
X-Mly-Id
X-Generated-On
X-Cdn-Origin
X-ApacheServer
X-Alternate-Cache-Key
X-Clara-WADP
X-Clientip
X-Cache-Id
X-App-Name
X-BBC-Edge-Cache-Status
X-Bip
X-Cache-Debug
X-Auto-Login
X-CMSURLCustom
X-TA-CDN-Provider
X-Fmm-Version
X-Esi-Check
X-Forwarded-Site
X-PERF
X-Geo-Header
X-DPWN-IS-SECURE
X-Proxy-Cache-Status
X-Core-Mission
X-Core-Value
X-DefElseHash
X-DefHash
X-Gzip
Platform
X-Storefront-Renderer-Rendered
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-Test
X-Sorting-Hat-ShopId
X-Varnishpool
X-Varnish-CookieHashed-On
X-Sn-Servicetimems
X-Sorting-Hat-PodId
X-VG-TLSProxy
X-Thanos
X-Thinkindot-L3
X-Up
Cmstype
X-Variation
Datacenter
X-TIM-N
Cmsid
Expect-Staple
X-Varnish-Remaining-TTL
X-Varnish-CookieINHashed-On
Environment
Is-Eu
Host-ID
X-Pool
Adler-Geo
Machine
X-Shopify-Stage
X-S-Maxage
Memcached
X-Request-Time
X-Qloud-Router
X-ShardId
X-Server-IP
X-Platform
X-VServer
X-Vmg-Version
X-WADP-Cache
X-ShopId
X-App
User-Cache-Control
ServedBy
Country-Code
X-Presslabs-Stats
Apple-News-Services-Handled
Apple-News-Services-Request-Url
X-WA-Info
X-Akamai-Device-Characteristics
X-Cdn-Srv
CDCHOST
Apple-News-Services-Parsed-Url
CloudFront-Viewer-Country
X-Block-Status
Apple-News-Services-Host
X-GeoIP
Server-Ext
X-Mvc-Supplant-OutputCached
Server-Hostname
X-Nananana
X-Nginx-Cache-Key
X-Origin
X-NodeID
X-Scale
X-Device-Os
Sever-Int
DSUID
X-From
Esi-Enabled
X-Gen-Mode
NM-Fastcgi-Cache
X-Dispatcher-Server
X-Hnp-Log
X-Correlation-ID
X-Tx-Id
X-Vcl-Version
X-Refresh
X-Op-Id-All
X-NCache
X-Cs
X-Instance-Name
X-Cache-Enabled
X-LB-NoCache
Ssr
Wxu-Next-Commit
Wxu-Next-Hostname
Wxu-Next-Region
C-Via
Origin-CC
Server-Info
Pics-Label
Origin-EX
X-Web-Node
WP-Super-Cache
X-Air-Hostname
X-Air-Source
X-TIME
X-Air-Trace-Id
Time
Server-ID
X-Amz-Meta-Cb-Modifiedtime
X-Azure-Ref-OriginShield
Memory
X-Cache-Status-Check
Hostname
X-HA-Backend
X-ZONE
X-API-Version
Cache-Host
NGX
Cf-Device-Type
X-Platform-Cluster
X-Platform-Processor
X-Platform-Router
Origin-Agent-Cluster
X-Origin-Expires
X-Microcachable
GeoIP-Latitude
X-URL
X-Dc
X-Tb-Optimization-Total-Bytes-Saved
AMP-Access-Control-Allow-Source-Origin
X-VHOST
X-CACHE-GROUP
XM
X-Locale
X-Site-Version
X-VarnishDD-TTL
PFcat
X-HN
X-Varnish-Beresp-Ttl
X-Varnish-Beresp-Grace
X-Wp-Cf-Super-Cache-Active
X-Ad-Defer-Variation
X-DC
X-Fpc
Resin-Trace
Cdn-Requestid
X-FL-QIT-DEBUG
X-FL-EDGE
Srvid
X-Vgn-Hpd-Reason
Locid
A
X-Micro-Cache
Edge-Copy-Time
X-Via-SSL
X-Via-CDN
X-Webkit-Csp-Report-Only
X-Via-Edge
X-Internal-Host
YJS-ID
X-Zone
Sid
X-WP-CF-Super-Cache-Active
X-ATG-Version
X-Contensis-Viewer-Groups
X-Github-Request-Id
X-Upstream-Ct
X-Upstream-Ht
X-Pod-Name
X-Cache-ASPX
X-TraceId
X-FireWall-Port
X-B3-Spanid
X-DataCenter
X-SIPLIST1
X-Varnish-Authentication
IsBot
Cache-Key
X-Moov-T
X-Moov-Xdn-Version
X-AB
True-Client-Ip
User-Agent
Uri
X-Cached-By
Location
X-LiteSpeed-Cache-Control
X-Buckets
GeoIP-Country-Code
X-Info
X-B3-Parentspanid
X-Geo-Region
X-Backend-Instance
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-HS-Content-Campaign-Id
X-Planisys-CDN-Cache
X-Platform-Server
State
X-FTR-Request-ID
X-NGINX-Cache
X-Nitro-Cache-From
X-Accel-Version
X-Nitro-Rev
X-LiteSpeed-Tag
X-Provided-By
CF-Ctrl
GeoIp-Country-Code
X-Fastly-Cache
X-MSEdge-Flight
X-Datacenter
X-Release
X-MSEdge-Features
X-VCache
SID
XServer
X-CS
X-Is-Mobile
X-VC
X-Rocket-Build-Number
X-Is-Supported-Browser
Cdn
X-Sigma-Backend
X-RN-RSRV
X-Tcp-Rtt
X-Sigma
X-Cache-Remote
X-Is-Tablet
X-Browser-Name
X-Is-Desktop
NtCoent-Length
X-CSRF-TOKEN
X-NewRelic-App-Data
X-Vgn-Hpd-Ssi
True-Client-IP
X-Vgn-Hpd-Cached
Cache
Path
X-Vgn-Hpd-Variations-Key
X-Api-Version
X-Geo
Lb
X-Generated-In
X-GeoIP-City
X-Scheme
X-HS-Status
Epwk-X-Cache
X-TRACE-ID
X-Hyper-Cache
X-Gamma-Serve
X-FPC
Fastly-Drupal-Html
X-HostName
Tcn
Cache-Tv-Group
X-Frame-Option
Ohc-File-Size
X-Webstats-RespID
X-SRV
X-GoCache-CacheStatus
X-Service
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
Serverid
CountryCode
X-APP-VERSION
X-UA
Cf-Ipcountry
Kp-EeAlive
X-Esi
Cdnsip
X-Amz-Meta-Opti
X-Air-Pt
X-AK-Request-ID
Cdncip
Srv
X-Guploader-Uploadid
X-Mobile-URL
X-Branch-Name
X-EC-Lua
X-Cache-Ttl
HostName
X-Wp-Cf-Super-Cache
WebServer
X-Wp-Cf-Super-Cache-Cache-Control
X-Traceid
X-Location
X-Pad
LB
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-Edge-Server
X-Vc
Env
X-Cdn-Cache-Status
On-Server
X-Men
Cdn-Request-Time
X-Proxy-CacheRZ
X-Developers
X-Aicache-OS
Yak-Timeinfo
X-Cache-Tags
X-Region-Sid
Ohc-Cache-HIT
WZWS-RAY
Proxy-Connection
Cdn-Host
CacheControlHeader
X-Vercel-Id
X-Vercel-Cache
XkeyRZ
X-Origin-Cache-Key
X-VCL-Version
X-TX-ID
CDN
X-CACHE-KEY
X-Akamai-Pragma-Client-IP
M-TraceId
Geoip-Latitude
X-Req
RNT-Machine
X-Nc
RNT-Time
X-Minions-Version
Mime-Version
Req-ID
X-FTR-Expires
X-Servedbyhost
X-SB
X-LB-ID
Tube-Get-Contents
X-CDN-Cache-Status
X-Cache-FS-Status
X-B3-Trace-ID
X-Acquia-Purge-Cdn-Unconfigured
V-Age
Tube-Got-Eval
Tube-Got-Results
Tube-Return
X-FTR-Cache-Status
X-NMSegId
X-Cdn-Forward
X-Wa
X-Via-Popv
X-FTR-Backend-Server
X-FTR-Backend
Ngx
X-Country-Code-Real
X-NWS-UUID-VERIFY
X-Via-Popn
X-Edge-Pop
X-Via-Poph
X-V-Cache
X-FTR-Balancer
Click-Count-Action-Start
Click-Count-Error
X-Lb-Cache
X-Cdn-Request-ID
X-WP-CF-Super-Cache-Cookies-Bypass
X-Ha-Backend
Server-Id
CF-Cached-On
X-Ad-Load-Variation
ENV
X-Fastly-Country-Code
WWW-Authenticate
Cluster
Content-Script-Type
Content-Style-Type
X-TT-LOGID
X-Edge-POP
X-Acquia-Application-Trace
X-Dw-Trace-Id
Pramga
X-Request-Start
X-Snapshot-Date
X-MiniProfiler-Ids
X-User
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
X-Check-Cacheable
X-Lb-Nocache
X-Scope-Id
X-M-Log
X-Via-Ucdn
X-M-Reqid
X-Acquia-Site
X-Acquia-Purge-Tags
X-Acquia-Application-UUID
PICS-Label
Yjs-Id
X-Varnish-Beresp-Status
X-Processor
X-Shield-Cache-Expires
X-Request-URI
X-TH-Server
X-APP
X-Ckpd-Fst-Backend
X-Qnm-Cache
X-Tim-N
X-Iauth-Set-Uid
X-Cached-Since
Vha6-Origin
X-ElasticPress-Query
X-Litespeed-Cache-Control
Log-Origin
X-RAMCache
X-Fastly-Cache-Hits
Cneonction
X-Miniprofiler-Ids
CACHE-MISS-TO-ORIGIN
Inserted-Into-Cache-At
X-Fastly-Backend-Reqs