Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Link
Cf-Request-Id
CF-Cache-Status
Accept-Ranges
CF-RAY
ETag
X-XSS-Protection
Expect-CT
Pragma
X-Powered-By
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-UA-Compatible
X-Cache-Hits
Alt-Svc
P3P
X-Served-By
X-Xss-Protection
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Adblock-Key
X-Runtime
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Cache-Status
X-Generator
X-Cacheable
Timing-Allow-Origin
X-Request-ID
P3p
X-Content-Security-Policy
X-Iinfo
Status
Feature-Policy
Content-Encoding
X-Envoy-Upstream-Service-Time
Access-Control-Expose-Headers
X-CDN
X-Drupal-Dynamic-Cache
X-AspNetMvc-Version
Upgrade
X-Via
CF-Ray
Access-Control-Max-Age
X-Ws-Request-Id
Server-Timing
EagleId
Keep-Alive
X-Cache-Group
X-Turbo-Charged-By
Request-Context
X-Age
X-Proxy-Cache
X-Server-Powered-By
X-AH-Environment
X-Hacker
X-Backend
X-UA-Device
X-Robots-Tag
Report-To
X-Amz-Request-Id
X-LiteSpeed-Cache
Host-Header
X-Server
X-Amz-Id-2
Grace
X-Rq
X-Varnish-Cache
X-Nginx-Cache-Status
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-Dns-Prefetch-Control
X-WebKit-CSP
X-Page-Speed
X-Vhost
X-OneAgent-JS-Injection
X-Amz-Version-Id
EagleEye-TraceId
X-Dispatcher
X-Device
X-Pingback
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Cache-Spec
NEL
X-Server-Id
X-Host
X-Backend-Server
X-Node
Cf-Railgun
X-Readtime
Accept-CH
X-Akam-SW-Version
Surrogate-Control
Request-Id
X-Response-Time
X-Language
X-HW
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Xkey
X-Template
Content-Location
X-Ruxit-JS-Agent
X-Application-Context
Rating
X-Ua-Compatible
Accept-Ch-Lifetime
X-Country
X-B3-TraceId
X-Cloud-Trace-Context
X-Buckets
X-Cache-Lookup
Allow
X-Ac
Accept-CH-Lifetime
X-Url
X-Content-Type
X-Trace
X-TtlSet
X-PC
X-Vname
X-Mod-Pagespeed
X-Varnish-TTL
X-Clacks-Overhead
Edge-Control
X-FastCGI-Cache
X-ESI
Cache-Tag
Fastly-Restarts
X-Rack-Cache
Service-Worker-Allowed
X-VARITI-CCR
X-Element-Page-Cache
Verso
X-Server-Name
X-GitHub-Request-Id
X-MS-InvokeApp
X-Amz-Rid
X-Upstream
X-Vcap-Request-Id
X-Dw-Request-Base-Id
X-D2id
Public-Key-Pins
MS-Author-Via
X-Client-IP
X-Origin-Cache
X-Abt-Application-Version
X-Cached
X-Cache-TTL
Arr-Disable-Session-Affinity
Accept-Ch
X-Country-Code
X-Powered-By-Plesk
X-Goog-Hash
X-Navigation-Version
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-Px
X-Version
X-Cnection
X-NF-Request-ID
X-Server-Lifecycle-Phase
Access-Control-Request-Method
X-Amz-Server-Side-Encryption
X-Kraken-Loop-Name
X-Instrumentation
X-Aws-Lambda-Call-Status
X-Powered-CMS
X-SRCache-Fetch-Status
X-Sol
X-SRCache-Store-Status
Display
Pagespeed
X-Middleton-Display
RTSS
X-Middleton-Response
Response
X-MSEdge-Ref
X-CST
X-LLID
X-GoogleNews-Bot
X-Exp-Variant
X-Edge
X-Cdn-Fetch
X-Exp-Id
X-Kinja-Server
X-Kinja
X-Use-Magma
X-Kinja-Revision
X-Kinja-Build
X-Edge-Location-Klb
X-Kinsta-Cache
Nginx-Cache
X-Shield-Request-Id
X-B3-TraceId-Primal
Mrf-Cache-Status
MRF-Tech
S
Content-MD5
X-HP-Webp
X-HP-Trace-Id
X-Jurisdiction
X-T
X-TTL
AR-PoweredBy
AR-SID
AR-Request-ID
AR-CACHE
AR-ATIME
X-Forwarded-For
X-Protected-By
X-Content-Security-Policy-Report-Only
TCN
X-Aspnetmvc-Version
X-Mg-S
X-Id
X-Mid
X-MCACHE
Fastcgi-Cache
X-RateLimit-Remaining
X-Parallel-Accel
Front-End-Https
Realpath
SPRequestDuration
SPIisLatency
X-Ttl
X-Recruiting
Edge-Cache-Tag
X-Request-Received
X-Request-Processing-Time
Filters
X-Pinterest-Rid
Pinterest-Generated-By
Pinterest-Version
Fusion-Source
Fusion-Deployment-Id
Server-Node
Fusion-Template-Id
Fusion-Component-Id
Fusion-Content-Id
Fusion-Content-Source
SPRequestGuid
X-SharePointHealthScore
X-Ua-Browser
X-Content
X-Ab
X-Ezoic-Cdn
X-DynaTrace
X-Correlation-Id
Alternate-Protocol
X-Accel-Expires
Server-Name
X-NWS-LOG-UUID
X-ECACHE
X-HS-Combine-CSS
X-HS-Cache-Config
X-Frontend
X-HS-Hub-Id
X-HS-Content-Id
X-Hits
X-Cache-Key
X-Yandex-Sdch-Disable
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Content-Options
X-Ruxit-Js-Agent
Cache-Tags
X-Page-Id
Host
X-Git-Hash
Cleartype
Charset
MicrosoftSharePointTeamServices
X-B3-Sampled
X-Www-Served-By
X-Geo-Country
TP-L2-Cache
TP-Cache
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Fastly-Request-Id
X-Amz-Replication-Status
X-Content-Digest
X-XRDS-LOCATION
Filterid
X-Forwarded-Proto
X-Microsite
X-Request-Handler-Origin-Region
X-Varnish-Age
X-VCache
X-Ser
X-Hostname
X-Amzn-Trace-Id
X-Activity-Id
X-AppVersion
X-Az
X-Rid
X-Upgrade-Enabled
X-Daa-Tunnel
Access-Control-Allow-Method
X-DIS-Request-ID
X-Origin-Server
X-Debug-Info
X-Grace
X-LB-Cache
X-N
X-FB-Debug
X-Origin-Upstream-Status
ServerID
X-WebKit-CSP-Report-Only
X-PressLabs-Stats
X-Mobile-URL
X-Nginx-Upstream-Cache-Status
X-Is-Crawler
X-Flags
X-Providence-Cookie
X-Aspnet-Duration-Ms
X-Route-Name
X-Request-Guid
X-Whom
X-Server-ID
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-Goog-Generation
X-TT
X-NGENIX-Cache
X-Goog-Metageneration
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-App-Environment
X-App-Server
X-Varnish-Grace
Viewport
X-Logged-In
X-F-Cache
X-Distributor
X-Cache-Control
Payment
DC
X-FW-Dynamic
Paypal-Debug-Id
X-FW-Hash
X-FW-Type
X-FW-Static
X-FW-Server
X-FW-Serve
Cross-Origin-Opener-Policy
Node
X-Tb
Fastcgi-Useragent
X-Cache-Age
X-Seen-By
X-Type
X-User-Agent
Country
X-Webkit-CSP
Accept-Charset
X-Varnish-Backend
X-Cache-Rule
X-Node-Name
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Load-Cache
X-Browser-Type
X-DataDome
X-Cache-Action
Version
X-IPLB-Instance
Refresh
X-Wix-Request-Id
X-Via-JSL
Liferay-Portal
X-Original-Request-Id
X-Tec-Api-Version
X-Tec-Api-Origin
X-Tec-Api-Root
X-Response-Served-From
Cache-Status
Access-Control-Request-Headers
X-Fastly-Request-ID
SD-X-WS
X-Jobs
X-Cacheable-TTL
X-Real-IP
X-UUID
VIX-Pulpo-Upstream-Status
NGB
X-Page-View
X-B
X-Vgn-Hpd-Reason
X-Fastcgi-Cache
X-Rendered-As
X-Is-Bot
X-Cluster-Name
X-Debug
X-ProcessESI
X-RemovedCookies
X-Proxy-Cache-Status
X-Revision
VIX-Pulpo-Node
X-Contextid
X-Proxy
X-Yottaa-Optimizations
X-Rule
Referer-Policy
X-Ratelimit-Limit
X-Drupal-Cache-Tags
Healthy
DynaTrace
X-Device-Type
X-Azure-Ref
X-Yottaa-Metrics
Amp-Access-Control-Allow-Source-Origin
X-Cache-Expired-At
X-Cache-Time
Akamai-GRN
X-Drupal-Cache-Contexts
X-Framework
X-G
X-Mobile
X-Instance
X-Debug-IsConnected
Surrogate-Key
X-Debug-IsPreview
X-B-Cache
X-TEC-API-VERSION
X-Signature
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Source
CF-IPCountry
X-FW-Version
X-Oracle-Dms-Ecid
SID
X-Oracle-Dms-Rid
X-Air-Trace-Id
X-Air-Source
X-Ms-Request-Id
X-Ms-Version
X-Air-Hostname
Frame-Options
X-Cache-Hit
Ms-Operation-Id
X-RTag
Section-Io-Cache
MS-CV
X-Nginx-Cache
X-Oneagent-Js-Injection
X-APP-VERSION
Countrycode
X-Tumblr-Pixel
X-Tumblr-User
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-L-Path
X-Varnish-Server
X-Environment-Context
Xserver
X-CDN-Forward
X-XRDS-Location
X-Region
X-Servername
X-EdgeConnect-Cache-Status
X-Content-Powered-By
X-Forwarded-Host
Count-Hit
X-Cache-Operation
GEO-INFO
X-Litespeed-Cache
X-Backend-Name
Uber-Trace-Id
Backend
Cross-Origin-Window-Policy
X-IPS-LoggedIn
X-Adobe-Content
X-Adobe-Loc
X-Mode
X-Accel-Buffering
X-SaId
X-UPSTREAM-Address
X-RN-RSRV
X-JoinUs
Meta-Geo
X-Alternate-Cache-Key
X-Human
X-Varnish-Beresp-Grace
X-Shopify-Stage
X-Cache-Server
X-Zen-Fury
Ec-Rule-Version
X-Redis-Cache
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-ShopId
Eomportal-Instance
X-Time
X-Detected-As
X-Debug-Cache
X-Cache-Type
X-ShardId
X-Generation-Time
X-Hosted-By
X-Cache-Grace
Decoy-Debug-Status
Country-Code
Cache-Tv-Group
Cache-Name
Decoy-Debug-TTL
Decoy-Debug-Key
Url
X-NCache
X-ProxyCache-Status
Apigw-Requestid
X-ProxyCache-Key
X-Site-Version
X-RateLimit-Limit
X-Microcachable
X-ServerID
X-BYPASS-REASON
X-No-Session
X-Uri
X-Via-Fastly
X-Storage
X-Status
X-Cache-TTL-Remaining
X-Sql-Duration-Ms
X-FB-TRIP-ID
X-Azure-Ref-OriginShield
X-PHP-Backend
X-Sql-Count
X-Origin-Date
X-SayCDN-TTL
Mn-Server-Ip
X-Say-TTL
Fastly-SSL
X-Web-Node
X-UA-Device-Type
X-Timing-Wait
Property-Id
TWC-Device-Class
X-Proxy-Build
Webcakes-Region
Webcakes-App-Version
X-Origin-Hint
X-Format
X-Cache-Host
X-Cache-Var
X-Cache-Var-Map
Webcakes-App-Name
TWC-Privacy
TWC-Connection-Speed
Source
Selected-Fe
TWC-GeoIP-Country
TWC-GeoIP-LatLong
TWC-Locale-Group
X-Say-Cacheable
Protected
X-Akamai-Edgescape
X-Pubstack
X-Proxied
X-R9-Blue-Green-Version
X-Routing-Service
X-Access
X-PERF
X-NYM-Debug-Backend
X-ApacheServer
X-Extlb
OT-Force-Account-Verify
X-Hl-Ver
X-Server-W
X-Section
Azure-InstanceId
X-Zipkin-Id
X-OCL
X-PCL
Azure-RegionName
X-Varnishpool
Azure-SiteName
Azure-Version
Azure-SlotName
X-HTML-Minification-Powered-By
X-Be
X-LSADC-Cache
X-Cluster-Node
Content-Secure-Policy
X-Rewrite-Enabled
SRV
X-Ua
X-Amz-Meta-S3cmd-Attrs
X-Tid
X-Webkit-Csp
X-SRV
X-Soup
DB-Nickname
X-Cache-NGX
X-NewRelic-App-Data
X-Content-Age
Content-Disposition
X-LAGOON
X-Cached-By
X-Dc
Webserver
X-Varnish-Hostname
X-TNCMS
X-Varnish-Hits
X-App-Version
X-Loop
Retry-After
X-S-Maxage
Onion-Location
X-Generated-By
CDN-Uid
CDN-PullZone
X-Unique-Id
CDN-EdgeStorageId
CDN-CachedAt
CDN-RequestCountryCode
CDN-Cache
Cache
CDN-RequestId
X-Bc-Bl
X-TT-LOGID
X-ECache
X-Ratelimit-Reset
X-Origin-CC
X-Origin-TTL
X-Tumblr-Pixel-3
X-Tumblr-Pixel-2
X-Auto-Login
Web-Mar-Node
X-Proto
X-Hyper-Cache
X-GEO
Cache-Hits
X-Qnm-Cache
X-M-Log
X-Tenant
X-Time-Microsecs
X-Cdn
X-M-Reqid
X-Nginx-Cache-Key
X-Endurance-Cache-Level
X-Edge-Location
X-GG-Cache-Date
X-VWS-Id
X-LJ-Flow-ID
X-AWS-Id
CloudFront-Viewer-Country
X-Presslabs-Stats
X-Trace-Id
X-CSRF-Token
X-Mg-Request-UUID
Xet-Cookie
X-Akamai-Transformed
X-CACHE-KEY
X-PHP-Host
Mime-Version
X-Labrador-Cache-Channel
X-Amzn-RequestId
X-Amz-Apigw-Id
HostName
LB
N-Cache
X-Platform-Server
X-Storefront-Renderer-Rendered
X-Handled-By
X-Locale
X-RCS-CacheZone
X-Xfnlog-Site
X-B3-SpanId
X-Cache-Tags
X-VC-Cache
X-Origin-Response-Time
X-Adobe-Source
Nel
X-Varnish-Cache-Hits
X-Correlation-ID
X-Reqid
Upgrade-Insecure-Requests
X-A-Wwc
Xc-Version
X-Forwarded-Path
X-Ftr-Request-Id
X-A-Ccd
Pramga
X-A
Redirect-Candidate
Rendered-Blocks
Surrogated-Key
Origin
X-Vtex-Remote-Cache
X-A-Dgt
Mobile-Detection-Method
X-A-Dcw
X-A-Dam
Odigeo-Trace-Id
Meta-Geo-Continent
X-Destination
X-CF-Lambda-Version
X-CF-Lambda-Fn
X-Ckpd-Fst-Backend
X-Cache-Date
X-Cluster
BehaviorPad-Version
Candidate-Md5Url
X-Cache-NE
DCR-Processing-Time-Ms
DSUID
DCR-Decision-By
Expiry
Fastcgi-X-Cache-Version
X-Conf
X-Connection-Hash
X-Application
X-ARC
X-Developer
X-VG-WebCache
X-Aed
X-External-Request-Id
X-B-Cookie
X-Vtex-Processado-Em
X-D
X-V-Cache
A
X-Request-Time
ServedBy
X-Vdms-Version
X-TIM-N
X-Vdms-Path
X-ScT
X-Ig-Push-State
X-Planisys-CDN-Rules
X-Slack-Backend
X-Processor
Server-Info
From-Origin
X-S
X-S-Cookie
X-ATG-Version
X-Request-Host
X-NAPM-TraceId
X-Planisys-CDN-Cache
X-SVT-ORM-RULES
X-Shop-Environment
X-Planisys-CDN-TTL
X-Session-Fingerprint
X-Rojux
X-SRCache-Key
X-SD-PageType
X-PAYTM-SRV-ID
X-PBS-Appsvrname
X-Orig-Expires
X-SVT-ORM-VERSION
AMP-Access-Control-Allow-Source-Origin
X-AOL-HN
X-Cache-Remote
X-MP-GENERATED-AT
X-Via-NSCOPI
X-Sucuri-ID
X-Policy
X-EC-Lua
Cmsid
X-VServer
Datacenter
Fastcgi-Cache-TTL
X-Cache-Info
X-Proxy-Upstream
Cmstype
X-Varnish-Beresp-Status
Release
X-Served-From
Wxu-Next-Commit
Wxu-Next-Hostname
X-Server-IP
X-ND-Cache
User-Cache-Control
V-Age
Vix-Hermes-Req-Id
Wxu-Next-Region
State
Host-ID
Gh-Request-Id
X-Block-Status
X-Cache-Bucket
L
X-Rocket-Nginx-Serving-Static
X-Skip-Cache
X-Scheme
X-Accel-Expires-Debug
X-Sucuri-Cache
CacheControlHeader
X-Fetched-On
X-Location
X-LI-UUID
X-Mvc-Supplant-Cachable
X-Epic-Correlation-Id
X-Nyt-Route
X-Device-Os
X-Li-Pop
X-Forwarded-Site
X-Hnp-Log
X-Hash
X-Geo-Header
X-Gen-Mode
X-Li-Fabric
X-Gdpr
X-Old-Content-Length
X-Fastly-Cache
X-Owner
X-Core-Mission
X-Ratelimit-Remaining
X-Origin-Time
AKAMAI
X-Date
X-Origin-Expires
Environment
WWW-Authenticate
X-Irp-Debug
X-GeoIP
X-Generated-On
X-Sigma-Backend
X-Gamma-Serve
X-HS-Content-Campaign-Id
X-Core-Value
X-Sigma
X-VarnishDD-TTL
True-Client-Country-4JS
X-Gzip
X-Platform
Thinkindot-Control
Thinkindot-CacheControl-Type
X-HN
X-GeoIP-City
Web-Mar-Region
We-Hiring
X-Men
X-TrackingId
X-Level-Front-Cache
Thinkindot-CacheControl
X-BBC-Edge-Cache-Status
X-Req
X-Datadog-Parent-Id
X-Fastly-Backend
X-Sn-Servicetimems
X-Bip
X-Esi-Check
X-Cache-Config
X-NodeID
X-Branch-Name
X-Datadog-Sampling-Priority
X-TH-Server
X-Viewer-Country
X-Developers
X-Cache-Debug
X-Cdn-Origin
X-Region-Sid
X-Thanos
X-Datadog-Trace-Id
X-Request-Start
X-Aicache-OS
X-Cache-Id
X-Rocket-Build-Number
X-Thinkindot-L3
Fastly-GeoIP-CountryCode
PFcat
Mail-Subject
WPO-Cache-Message
Apple-News-Services-Handled
X-Zone
X-Magnolia-Registration
WPO-Cache-Status
TDXMobile
Machine
Locid
Apple-News-Services-Host
Req-Svc-Chain
X-VG-TLSProxy
Apple-News-Services-Parsed-Url
CDCHOST
Arc-Country
Server-Host
Svr
Apple-News-Services-Request-Url
X-Xrds-Location
Cf-Device-Type
Esi-Enabled
X-Envoy-Decorator-Operation
X-DefHash
X-Csrf-Jwt
Adler-Geo
X-DefElseHash
X-CGP
X-DPWN-IS-SECURE
X-Is-Gdpr
X-Qloud-Router
X-TIME
X-Varnish-CookieHashed-On
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Request-URI
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-Pod-Name
X-Varnish-CookieINHashed-On
Fastly-SIE
X-Has-Esi
X-Variation
X-JWT-State
X-Loc
X-Varnish-Remaining-TTL
X-Origin
X-FC-Vary-Parameters
X-Eu-Site
X-Worker
X-NU-AKA-ACS-Version
NGX
L5d-Success-Class
X-Amzn-Remapped-Content-Length
X-Backend-State
Is-Eu
Fastly-SWR
NM-Fastcgi-Cache
X-UnsetCookies
Platform
Origin-CC
Origin-EX
On-Server
Traceparent
HA-Ipaddr
Memcached
Ha-Gx-Prefs
X-CS
X-Webstats-RespID
X-FireWall-Port
Fastly-Drupal-Html
X-Tx-Id
CDN
X-Cdn-Srv
X-Mvc-Supplant-OutputCached
Sslversion
X-Service
X-LB-ID
X-NC
C-Via
X-Up
X-Varnish-Beresp-Ttl
X-API-Version
X-Node-Id
X-CLOUD-TRACE-CONTEXT
Ssr
Pics-Label
X-Generated-In
X-Cache-PHP
X-Response-By
Ms-Author-Via
X-Trace-ID
X-Vc
X-Tt-Logid
X-Datadome
Memory
X-Refresh
WP-Super-Cache
Time
X-Edge-Pop
X-TA-CDN-Provider
X-DynaTrace-JS-Agent
X-Via-Popn
X-Via-Poph
X-Via-Popv
NtCoent-Length
X-Cache-Status-Check
X-Dynatrace
X-Varnish-Ttl
GeoIp-Country-Code
X-Backend-TTL
X-Cache-Enabled
X-Tb-Optimization-Total-Bytes-Saved
X-LB-NoCache
X-Render-Time
X-TraceId
X-Parent-Response-Time
X-Info
X-GeoIP-Region-Code
X-DC
X-Optimistic-Header
Env
X-GeoIP-Country-Code
X-Varnish-Beresp-TTL
X-Esi
Magicmarker
X-AIR-PT
X-Ua-Device
X-Clientip
X-Restarts
X-Unique-ID
X-Servedbyhost
X-TX-ID
X-Cs
X-NWS-UUID-VERIFY
X-Oss-Storage-Class
X-Oss-Server-Time
Cache-Host
X-Oss-Request-Id
Server-ID
X-Oss-Object-Type
X-CacheTTL
Kp-EeAlive
HIT
X-Oss-Hash-Crc64ecma
UCS
Section-Io-Origin-Status
Section-Origin-Responded
Section-Io-Id
Section-Io-Origin-Time-Seconds
X-Srv
X-ZONE
S-Cnection
X-Newrelic-Synthetics
X-App
Lb
X-DSS
X-DI
X-Wix-Viewer-Type
Proxy-Connection
S-Rt
X-VCL-Version
Edge-Cache
X-Cache-Backend
X-MSEdge-Features
X-MSEdge-Flight
X-RSL
X-Li-Proto
X-Action
X-DB
X-RPM
X-Cache-Ttl
X-RPS
X-DW
X-URL
WebServer
X-Fpc
X-HA-Backend
X-LI-Proto
Test
Fastly-Backend-Name
User-Agent
X-Micro-Cache
X-FPC
X-Webkit-Csp-Report-Only
X-LiteSpeed-Cache-Control
X-Traceid
X-B3-Spanid
X-Backend-Host
X-Vcl-Version
X-Minions-Version
Server-Id
X-Webkit-CSP-Report-Only
X-NODE
X-BCube-Filmed-By
Geo-Info
X-Pad
Tcn
X-Release
X-ES-SERVER
Resin-Trace
X-Pass-Why
Fastly-Drupal-HTML
X-LiteSpeed-Tag
X-APP
X-Amz-Meta-Cb-Modifiedtime
CPC-Cache
X-HostName
Cache-Key
CPC-Age
X-BBC-Origin-Response-Status
EpKe-Alive
Cf-Int-Pingora-Origin-Digest
VNS-Cache
Path
VNS-Age
X-Http-Reason
X-Akamai-Request-ID2
X-CSRF-TOKEN
X-Akamai-Pragma-Client-IP
X-ID
X-ServedByHost
X-WA-Info
X-Ec-GeoHdr
X-Ec-Fail
X-User
Hostname
Accept-Language
X-Cms-Context
X-Check-Cacheable
Srv
X-WA
Pagetype
X-PJAX-URL
X-Wikidot-Static-Cache
Hit
Ohc-File-Size
X-Wikidot-Backend
GeoIP-Country-Code
X-Dynatrace-Js-Agent
X-Geo
Locale
ENV
X-ElasticPress-Query
X-Urbn-Site-Id
MIME-Version
MD5-Digest
X-Urbn-Context-Path
X-Cdn-Forward
X-Via-PopH
X-Ha-Backend
X-Edge-POP
Shield-Pop
X-Via-Ucdn
X-Via-PopV
X-Via-PopN
X-HS-Status
X-VG-WebServer
M-TraceId
Cdnsip
X-WADP-Cache
Cdncip
X-Api-Version
X-Edge-Cache
X-AK-Request-ID
Load-Balancing
X-Hcs-Proxy-Type
X-Fmm-Version
X-CCDN-Origin-Time
X-CCDN-CacheTTL
URI
X-NGINX-Cache
X-Clara-WADP
X-Kraken-Routeconfig-Destination
Cluster
X-ServerName
X-Ucs
Geoip-Latitude
Server-Hostname
Server-Ext
W
X-Cache-Expires
X-SIPLIST1
X-Fastly-Backend-Reqs
IsBot
Sever-Int
My-App
X-CUA
Lfy
X-From
X-Provided-By
X-GoCache-CacheStatus
X-Var-Ttl
X-Mcache
Tracecode
X-UP
Vha6-Origin
X-Dw-Trace-Id
X-TRACE-ID
X-RateLimit-Reset
X-Acquia-Site
X-Lb-Id
X-Fastly-Cache-Hits
X-Acquia-Application-UUID
X-Acquia-Purge-Tags
Cteonnt-Length
X-Acquia-Application-Trace
PICS-Label
Ohc-Cache-HIT
X-B3-ParentSpanId
X-Platform-Processor
X-Cdn-Request-ID
Cdn
X-VC
HitType
X-Nc
X-Platform-Cluster
X-Via-CDN
Cneonction
X-Platform-Router
T-Server
Lang
Servername
X-Fragments
X-Apw-Access-Action
WZWS-RAY
X-Apw-Access-Object
X-Cc-Via
X-Swift-Error
X-Akamai-Request-ID
X-Snapshot-Date
X-Contensis-Viewer-Groups
FSS-Cache
X-Cache-ASPX
Dnion-Transfer-Encoding
X-Yottaa-OS
X-Apw-Access-Token
CF-Cached-On
Cf-Ipcountry
X-RAMCache
X-Apw-Hits
X-Newrelic-App-Data
X-Air-Pt
X-Cache-Ngx
Sid
X-Request-UUID
X-Http-Count
X-IN-APIGATEWAYSSL
X-Wa
X-Edge-IP
X-IN-APIGATEWAY
X-Http-Duration-Ms
X-Te-Count
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
Uri
Target-Params
X-Te-Duration-Ms
X-77-NZT
PB-RID
X-Varnish-Authentication
X-Lb-Nocache
X-Logging-Id
X-CacheKey
Req-ID
X-UA
X-Miniprofiler-Ids
X-Sentry-ID
PB-PID
CountryCode
X-B3-Parentspanid
Ngx
Arc-Version
X-HTML-Edge-Cache