Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-Cache-Status
Link
Accept-Ranges
ETag
CF-RAY
X-XSS-Protection
Expect-CT
Pragma
X-Powered-By
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
Alt-Svc
X-Served-By
X-Xss-Protection
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Request-Id
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
CF-Ray
X-Cache-Status
X-Check
X-Generator
X-Cacheable
Timing-Allow-Origin
X-Content-Security-Policy
X-Iinfo
Feature-Policy
X-Request-ID
Status
X-Envoy-Upstream-Service-Time
Content-Encoding
Access-Control-Expose-Headers
P3p
X-Drupal-Dynamic-Cache
X-CDN
X-AspNetMvc-Version
Upgrade
X-Via
X-Ws-Request-Id
Access-Control-Max-Age
Server-Timing
EagleId
X-Cache-Group
X-Turbo-Charged-By
Keep-Alive
Request-Context
X-UA-Device
Report-To
X-Age
X-Backend
X-Proxy-Cache
X-Server-Powered-By
X-AH-Environment
X-Robots-Tag
X-Hacker
X-Amz-Request-Id
X-Server
Host-Header
X-Amz-Id-2
Grace
X-LiteSpeed-Cache
X-Rq
X-Swift-CacheTime
X-Swift-SaveTime
X-Nginx-Cache-Status
X-Varnish-Cache
Ali-Swift-Global-Savetime
X-WebKit-CSP
X-Page-Speed
NEL
X-Vhost
EagleEye-TraceId
X-Ua-Compatible
X-Amz-Version-Id
X-OneAgent-JS-Injection
X-Dns-Prefetch-Control
X-Pingback
X-Dispatcher
X-Device
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Cache-Spec
X-Host
Cf-Railgun
X-Server-Id
Accept-CH
X-Node
X-Backend-Server
X-Readtime
Surrogate-Control
X-Akam-SW-Version
Request-Id
X-Response-Time
X-HW
Xkey
X-Application-Context
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Content-Location
Rating
Accept-Ch-Lifetime
X-Ruxit-JS-Agent
X-Country
X-B3-TraceId
X-Cloud-Trace-Context
X-Cache-Lookup
Accept-CH-Lifetime
X-Trace
X-Url
X-Ac
X-Content-Type
X-Vname
X-PC
X-TtlSet
Allow
X-Varnish-TTL
X-Clacks-Overhead
Edge-Control
X-Mod-Pagespeed
X-Server-Name
X-ESI
Fastly-Restarts
X-Aws-Lambda-Call-Status
Cache-Tag
X-VARITI-CCR
Service-Worker-Allowed
X-Rack-Cache
Verso
X-Element-Page-Cache
X-Upstream
MS-Author-Via
X-Vcap-Request-Id
X-FastCGI-Cache
X-MS-InvokeApp
X-Amz-Rid
X-GitHub-Request-Id
Public-Key-Pins
X-Dw-Request-Base-Id
X-Cached
X-Client-IP
X-D2id
X-Abt-Application-Version
X-Cache-TTL
X-Cnection
X-Px
RTSS
X-Navigation-Version
X-GoogleNews-Bot
X-Cdn-Fetch
X-Kinja
X-Exp-Id
X-Kinja-Revision
Arr-Disable-Session-Affinity
X-Use-Magma
X-Kinja-Server
X-Kinja-Build
X-Exp-Variant
X-Country-Code
Access-Control-Request-Method
X-Powered-By-Plesk
X-NF-Request-ID
X-Goog-Hash
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-Instrumentation
X-Powered-CMS
AR-CACHE
AR-PoweredBy
AR-ATIME
AR-SID
AR-Request-ID
X-Origin-Cache
Display
X-Sol
X-Middleton-Display
Pagespeed
X-Version
Response
X-Middleton-Response
Accept-Ch
X-TTL
X-LLID
X-Amz-Server-Side-Encryption
X-MSEdge-Ref
X-Kinsta-Cache
X-Edge-Location-Klb
TCN
Nginx-Cache
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Edge
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
X-RateLimit-Remaining
X-Protected-By
X-T
X-HP-Trace-Id
X-Jurisdiction
X-HP-Webp
X-Forwarded-For
X-Content-Security-Policy-Report-Only
X-Shield-Request-Id
X-Id
X-Aspnetmvc-Version
S
Content-MD5
Edge-Cache-Tag
X-CST
X-Mg-S
X-Language
SPIisLatency
SPRequestDuration
Fastcgi-Cache
X-Mid
Front-End-Https
Realpath
X-DynaTrace
X-Request-Received
X-Request-Processing-Time
Server-Node
X-Recruiting
Filters
X-Pinterest-Rid
Pinterest-Version
Pinterest-Generated-By
X-Frontend
Server-Name
X-Content
X-Ab
X-Ua-Browser
X-MCACHE
X-Ruxit-Js-Agent
X-Correlation-Id
X-Cache-Key
X-Ttl
X-Ser
X-HS-Hub-Id
X-HS-Cache-Config
X-HS-Content-Id
X-HS-Combine-CSS
X-Yandex-Sdch-Disable
X-NWS-LOG-UUID
X-Ezoic-Cdn
X-ECACHE
X-Template
SPRequestGuid
X-SharePointHealthScore
X-Hits
X-Parallel-Accel
X-Server-ID
MicrosoftSharePointTeamServices
X-Tt-Trace-Host
X-Tt-Trace-Tag
Alternate-Protocol
Cache-Tags
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
Charset
X-Page-Id
Host
X-B3-Sampled
Cleartype
X-Www-Served-By
X-Git-Hash
Fusion-Deployment-Id
Fusion-Source
Fusion-Template-Id
Fusion-Component-Id
Fusion-Content-Source
Fusion-Content-Id
X-Content-Options
X-Geo-Country
X-Hostname
X-Debug-Info
X-DIS-Request-ID
X-Daa-Tunnel
X-Amzn-Trace-Id
X-Amz-Replication-Status
X-Content-Digest
X-Varnish-Age
X-Ratelimit-Limit
Cross-Origin-Opener-Policy
X-Activity-Id
X-Az
Filterid
X-AppVersion
X-FB-Debug
X-Upgrade-Enabled
X-VCache
X-Grace
X-Accel-Expires
X-N
ServerID
X-Nginx-Upstream-Cache-Status
X-Forwarded-Proto
X-F-Cache
X-Origin-Server
X-Rid
Access-Control-Allow-Method
X-Mobile-URL
X-Fastly-Request-Id
X-Providence-Cookie
X-Aspnet-Duration-Ms
X-Is-Crawler
X-Route-Name
X-Request-Guid
X-Flags
X-LB-Cache
X-Type
X-Fastcgi-Cache
TP-L2-Cache
TP-Cache
X-Whom
X-TT
X-App-Environment
X-Varnish-Grace
Viewport
X-Seen-By
Payment
X-Tb
X-DataDome
X-Goog-Metageneration
X-WebKit-CSP-Report-Only
X-Goog-Storage-Class
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-GUploader-UploadID
X-Goog-Stored-Content-Length
Node
X-FW-Dynamic
X-FW-Hash
X-FW-Static
X-FW-Type
X-Distributor
X-FW-Serve
X-FW-Server
X-User-Agent
Paypal-Debug-Id
DC
X-XRDS-LOCATION
X-App-Server
X-Fastly-Request-ID
Country
Fastcgi-Useragent
Accept-Charset
X-Wix-Request-Id
X-NGENIX-Cache
X-Litespeed-Cache
X-Cache-Control
X-Cache-Rule
X-Webkit-CSP
X-Origin-Upstream-Status
Version
X-Webkit-Csp
X-Via-JSL
Referer-Policy
X-Drupal-Cache-Tags
X-Microsite
X-Logged-In
X-Request-Handler-Origin-Region
X-Oracle-Dms-Rid
X-Cluster-Name
X-Oracle-Dms-Ecid
X-Cache-Age
Amp-Access-Control-Allow-Source-Origin
X-Contextid
X-Buckets
X-Signature
X-Tec-Api-Root
X-Tec-Api-Version
X-Ratelimit-Reset
X-Tec-Api-Origin
X-B-Cache
X-Erf-Bev-Bev
Cache-Status
X-Browser-Type
X-Erf-Bev-Bev-Is-Generated
Refresh
VIX-Pulpo-Upstream-Status
SD-X-WS
VIX-Pulpo-Node
X-Varnish-Backend
X-Mobile
X-Node-Name
X-Original-Request-Id
X-Response-Served-From
X-Load-Cache
X-Real-IP
X-Vgn-Hpd-Reason
X-Cache-Expired-At
X-Page-View
X-Is-Bot
X-Jobs
X-Rendered-As
Access-Control-Request-Headers
X-Debug
X-IPLB-Instance
X-Revision
X-Cacheable-TTL
X-B
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Cache-Action
X-Proxy-Cache-Status
X-Device-Type
X-RemovedCookies
X-Rule
X-Proxy
X-Instance
X-ProcessESI
X-UUID
Surrogate-Key
Akamai-GRN
X-Drupal-Cache-Contexts
NGB
X-Framework
X-Debug-IsConnected
X-Debug-IsPreview
X-Cache-Time
X-G
X-FW-Version
CF-IPCountry
X-Air-Hostname
X-Air-Source
X-Air-Trace-Id
SID
GEO-INFO
X-Accel-Buffering
DynaTrace
X-TEC-API-ROOT
X-PressLabs-Stats
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-Azure-Ref
X-Oneagent-Js-Injection
X-Nginx-Cache
Liferay-Portal
X-Cache-NGX
Count-Hit
X-Source
X-Ms-Version
Uber-Trace-Id
X-Ms-Request-Id
X-Presslabs-Stats
X-Cache-Operation
X-XRDS-Location
Frame-Options
Ms-Operation-Id
X-Zen-Fury
X-CDN-Forward
X-RTag
MS-CV
X-EdgeConnect-Cache-Status
X-APP-VERSION
Healthy
X-RateLimit-Limit
Protected
X-Backend-Name
X-L-Path
X-Mode
X-Environment-Context
X-Cache-Hit
Countrycode
Xserver
Cross-Origin-Window-Policy
Ec-Rule-Version
X-Tumblr-User
X-Tumblr-Pixel-1
X-IPS-LoggedIn
X-Varnish-Server
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Ratelimit-Remaining
X-Cache-TTL-Remaining
LB
X-Hyper-Cache
Backend
Meta-Geo
X-JoinUs
X-SaId
X-Content-Age
X-Adobe-Loc
X-Rewrite-Enabled
X-Region
X-UPSTREAM-Address
X-Servername
X-RN-RSRV
X-Tid
X-Detected-As
X-Adobe-Content
X-Forwarded-Host
X-Shopify-Stage
X-Redis-Cache
X-Format
Decoy-Debug-Key
Country-Code
Decoy-Debug-Status
Decoy-Debug-TTL
Eomportal-Instance
Apigw-Requestid
X-Alternate-Cache-Key
X-Extlb
X-Generation-Time
X-Debug-Cache
X-Cache-Grace
X-Cache-Server
X-Hosted-By
X-Sorting-Hat-PodId
X-Sql-Duration-Ms
X-ShopId
WPO-Cache-Status
X-Proxied
X-Zipkin-Id
X-ShardId
X-Uri
X-Sql-Count
WPO-Cache-Message
X-Routing-Service
Section-Io-Cache
X-Sorting-Hat-ShopId
Cache-Name
X-Access
X-Section
Content-Disposition
X-FB-TRIP-ID
X-Content-Powered-By
X-ApacheServer
Url
X-PCL
X-ServerID
X-Via-Fastly
X-Varnish-Beresp-Grace
X-No-Session
X-Site-Version
X-PHP-Backend
X-NCache
X-Microcachable
Fastly-SSL
X-PERF
X-Human
Mn-Server-Ip
X-Origin-Date
X-OCL
Webcakes-App-Version
Webcakes-Region
CDN-Uid
Webcakes-App-Name
TWC-GeoIP-LatLong
TWC-Connection-Speed
Selected-Fe
CDN-Cache
TWC-Device-Class
TWC-GeoIP-Country
X-Say-TTL
Property-Id
TWC-Locale-Group
X-Cluster-Node
X-Say-Cacheable
X-Pubstack
X-Server-W
CDN-RequestId
X-ProxyCache-Status
X-Storage
X-ProxyCache-Key
X-Origin-Hint
X-NYM-Debug-Backend
X-Status
X-SayCDN-TTL
X-Timing-Wait
X-BYPASS-REASON
CDN-EdgeStorageId
X-Akamai-Edgescape
CDN-CachedAt
CDN-PullZone
X-Cache-Host
CDN-RequestCountryCode
X-UA-Device-Type
X-Cache-Type
X-Proxy-Build
TWC-Privacy
Cache-Tv-Group
X-Hl-Ver
X-Soup
X-Trace-Id
X-NewRelic-App-Data
X-Be
X-Web-Node
X-Varnishpool
X-R9-Blue-Green-Version
X-Generated-By
Azure-RegionName
Azure-SiteName
Content-Secure-Policy
Azure-SlotName
Azure-InstanceId
Azure-Version
X-LSADC-Cache
X-Azure-Ref-OriginShield
DB-Nickname
X-Ua
X-TIME
Retry-After
X-Nginx-Cache-Key
OT-Force-Account-Verify
X-Cached-By
X-TT-LOGID
Source
X-Bc-Bl
Cache
X-Unique-Id
SRV
X-Cache-Remote
X-Dc
X-Auto-Login
X-Akamai-Transformed
X-Platform-Server
X-LAGOON
X-GEO
X-Xfnlog-Site
X-Cdn
Cache-Hits
X-Cache-Tags
Upgrade-Insecure-Requests
X-EC-Lua
ServedBy
X-Varnish-Hits
X-Origin-TTL
X-Origin-CC
HostName
X-App-Version
X-Varnish-Hostname
X-HTML-Minification-Powered-By
X-SRV
Mime-Version
X-TNCMS
X-Loop
Onion-Location
X-S-Maxage
X-Varnish-Cache-Hits
X-CSRF-Token
From-Origin
X-Request-Time
X-Time
X-AOL-HN
Xet-Cookie
X-Tumblr-Pixel-2
X-Tumblr-Pixel-3
Webserver
X-Amz-Meta-S3cmd-Attrs
Web-Mar-Node
X-Request-Host
WP-Super-Cache
X-ECache
X-Proto
X-Xrds-Location
N-Cache
X-NWS-UUID-VERIFY
X-B3-SpanId
X-Cache-Enabled
X-FireWall-Port
X-Tenant
X-Endurance-Cache-Level
Nel
X-Handled-By
X-VWS-Id
X-Correlation-ID
X-AWS-Id
X-LJ-Flow-ID
X-GG-Cache-Date
X-Time-Microsecs
X-Origin-Response-Time
X-Processor
X-Planisys-CDN-TTL
X-Ftr-Request-Id
X-Hnp-Log
X-SRCache-Key
BehaviorPad-Version
X-ScT
X-Ckpd-Fst-Backend
DCR-Decision-By
X-PBS-Appsvrname
Expiry
X-S-Cookie
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Gen-Mode
DCR-Processing-Time-Ms
X-Slack-Backend
X-SD-PageType
X-External-Request-Id
X-D
X-Connection-Hash
X-Destination
X-Session-Fingerprint
X-Developer
X-Shop-Environment
X-Rojux
Fastcgi-X-Cache-Version
X-Forwarded-Path
A
X-Cluster
X-Cache-Var-Map
X-Conf
X-Cache-Var
X-Epic-Correlation-Id
X-TIM-N
X-Aicache-OS
User-Cache-Control
X-Aed
X-A-Wwc
X-Vdms-Version
Surrogated-Key
X-NAPM-TraceId
Sslversion
X-Vdms-Path
X-A-Dgt
Xc-Version
X-Vtex-Processado-Em
V-Age
Vix-Hermes-Req-Id
X-A-Ccd
X-Vtex-Remote-Cache
X-A-Dam
X-A-Dcw
X-VG-WebCache
X-S
X-ND-Cache
X-Application
X-Ig-Push-State
Mobile-Detection-Method
Odigeo-Trace-Id
X-Cache-NE
Meta-Geo-Continent
X-CF-Lambda-Fn
X-PAYTM-SRV-ID
X-CF-Lambda-Version
X-Edge-Location
X-Orig-Expires
X-Block-Status
Redirect-Candidate
X-ARC
Rendered-Blocks
X-A
Pramga
X-Backend-TTL
X-V-Cache
X-B-Cookie
X-Reqid
X-RCS-CacheZone
X-Magnolia-Registration
X-Adobe-Source
X-MP-GENERATED-AT
X-Mg-Request-UUID
X-Fastly-Cache
X-SVT-ORM-VERSION
Fastcgi-Cache-TTL
X-LI-UUID
X-VG-TLSProxy
X-Cdn-Srv
X-SVT-ORM-RULES
DSUID
X-Forwarded-Site
CDCHOST
X-Policy
Cmsid
Cmstype
X-Sucuri-ID
X-Sucuri-Cache
Wxu-Next-Commit
Gh-Request-Id
X-Location
X-Old-Content-Length
X-Amzn-RequestId
X-Origin
Origin
X-Nyt-Route
X-NodeID
X-Amz-Apigw-Id
State
X-Origin-Expires
Host-ID
X-Origin-Time
True-Client-Country-4JS
X-Men
X-Mvc-Supplant-Cachable
Svr
X-Scheme
CacheControlHeader
X-Li-Pop
X-Li-Fabric
X-Request-URI
X-Gdpr
X-Rocket-Nginx-Serving-Static
X-GeoIP-Country-Code
X-Webstats-RespID
X-Cache-Info
X-Server-IP
X-Cache-Date
Wxu-Next-Hostname
X-Geo-Header
CloudFront-Viewer-Country
X-Cache-Bucket
Arc-Country
AKAMAI
X-PHP-Host
X-Hash
Wxu-Next-Region
X-GeoIP-Region-Code
Apple-News-Services-Request-Url
Apple-News-Services-Host
Apple-News-Services-Handled
Apple-News-Services-Parsed-Url
X-Labrador-Cache-Channel
X-Via-NSCOPI
S-Rt
Environment
Server-Host
X-Csrf-Jwt
Req-Svc-Chain
X-Datadog-Parent-Id
X-BBC-Edge-Cache-Status
X-VarnishDD-TTL
X-Core-Value
X-Branch-Name
X-Core-Mission
X-Cache-Debug
X-Cdn-Origin
X-Viewer-Country
X-Irp-Debug
X-VServer
Release
Web-Mar-Region
X-Locale
X-Cache-Id
X-HS-Content-Campaign-Id
X-Level-Front-Cache
X-CGP
Traceparent
X-Accel-Expires-Debug
Ssr
X-Device-Os
X-Storefront-Renderer-Rendered
X-Fetched-On
X-Proxy-Upstream
X-Sn-Servicetimems
X-Gamma-Serve
X-Platform
X-Fastly-Backend
X-Varnish-Beresp-Status
Fastly-GeoIP-CountryCode
X-Esi-Check
X-Eu-Site
X-Generated-On
X-Gzip
X-Sigma
Fastly-Drupal-Html
X-Rocket-Build-Number
X-Served-From
X-Sigma-Backend
X-Skip-Cache
X-GeoIP
Server-Info
X-Region-Sid
X-GeoIP-City
X-HN
X-Envoy-Decorator-Operation
X-Varnish-Beresp-Ttl
X-Owner
X-Date
X-Developers
X-TrackingId
PFcat
Origin-CC
Origin-EX
X-UnsetCookies
X-Backend-State
Machine
L
X-Datadog-Sampling-Priority
Ha-Gx-Prefs
X-Datadog-Trace-Id
Locid
L5d-Success-Class
HA-Ipaddr
X-JWT-State
X-Is-Gdpr
X-Http-Reason
X-FC-Vary-Parameters
X-DPWN-IS-SECURE
X-Akamai-Request-ID2
X-Has-Esi
X-DefHash
X-DefElseHash
TDXMobile
Is-Eu
Mail-Subject
Fastly-SWR
Fastly-SIE
X-Thinkindot-L3
Memcached
NM-Fastcgi-Cache
X-Node-Id
X-Varnish-CookieINHashed-On
X-Varnish-CookieHashed-On
Platform
X-NU-AKA-ACS-Version
X-TH-Server
X-Pod-Name
X-Tx-Id
X-Rebelmouse-Surrogate-Control
X-Req
X-Request-Start
X-Response-By
X-Rebelmouse-Cache-Control
X-RateLimit-Remaining-Second
Cf-Device-Type
X-Qloud-Router
Adler-Geo
X-RateLimit-Limit-Second
X-Varnish-Remaining-TTL
X-Variation
Thinkindot-Control
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
Magicmarker
We-Hiring
X-ATG-Version
X-Amzn-Remapped-Content-Length
X-Loc
X-Worker
X-Ua-Device
X-M-Log
X-M-Reqid
X-Qnm-Cache
X-VC-Cache
X-Thanos
AMP-Access-Control-Allow-Source-Origin
X-CS
NGX
X-Bip
X-Restarts
X-Zone
X-LB-ID
Kp-EeAlive
X-API-Version
X-Mvc-Supplant-OutputCached
X-Up
X-DW
X-Wix-Viewer-Type
CDN
X-Cache-Backend
X-RSL
X-RPM
X-DB
X-RPS
X-Action
Edge-Cache
X-DSS
X-DI
X-LB-NoCache
X-NC
X-Cache-Config
X-Trace-ID
Pics-Label
Ms-Author-Via
X-Generated-In
X-TraceId
Time
Memory
Accept-Language
Env
X-Srv
X-Tb-Optimization-Total-Bytes-Saved
X-Via-Poph
X-Optimistic-Header
X-CacheTTL
X-Minions-Version
X-Via-Popv
X-Via-Popn
WebServer
X-DC
X-Varnish-Ttl
X-Refresh
X-Edge-Pop
X-Tt-Logid
X-HA-Backend
NtCoent-Length
Datacenter
Candidate-Md5Url
X-Urbn-Context-Path
GeoIp-Country-Code
X-CACHE-KEY
X-Urbn-Site-Id
Locale
X-DynaTrace-JS-Agent
X-ZONE
X-Servedbyhost
WWW-Authenticate
On-Server
Server-ID
X-Vc
X-Esi
X-Datadome
Esi-Enabled
X-Ec-GeoHdr
X-Unique-ID
X-Ec-Fail
X-User
X-MSEdge-Flight
X-MSEdge-Features
X-Parent-Response-Time
X-CLOUD-TRACE-CONTEXT
X-Cs
X-TX-ID
X-TA-CDN-Provider
X-Varnish-Beresp-TTL
X-Cache-PHP
X-Service
X-Webkit-CSP-Report-Only
C-Via
X-VCL-Version
X-Newrelic-Synthetics
X-Cache-Ttl
X-Traceid
X-App
X-LI-Proto
Cdncip
X-AK-Request-ID
X-Fpc
Cdnsip
X-URL
Test
X-WADP-Cache
X-LiteSpeed-Cache-Control
X-Clara-WADP
My-App
X-Webkit-Csp-Report-Only
X-Fmm-Version
X-Li-Proto
Proxy-Connection
Tracecode
X-Cache-Status-Check
X-CUA
X-Var-Ttl
X-FPC
Geoip-Latitude
X-B3-Spanid
Cf-Int-Pingora-Origin-Digest
Cluster
X-Render-Time
X-Pass-Why
X-NODE
DataCenter
T-Server
X-From
X-Vcl-Version
Lfy
X-Mcache
Fastly-Drupal-HTML
X-Fragments
Lang
M-TraceId
Geo-Info
Resin-Trace
X-VC
X-Dynatrace
Server-Id
Target-Params
X-CSRF-TOKEN
X-Clientip
X-WP-CF-Super-Cache
X-Ha-Backend
X-ID
X-LiteSpeed-Tag
X-WP-CF-Super-Cache-Cache-Control
GeoIP-Country-Code
MIME-Version
Hostname
X-RAMCache
X-Oss-Object-Type
HIT
X-Oss-Hash-Crc64ecma
UCS
X-Oss-Server-Time
X-Oss-Storage-Class
Cache-Host
X-Oss-Request-Id
Hit
X-Info
X-ServedByHost
X-AIR-PT
X-Provided-By
X-Geo
X-Dynatrace-Js-Agent
S-Cnection
X-Pad
X-Cdn-Forward
Permissions-Policy
X-Via-PopN
X-Via-PopH
Section-Io-Id
X-RateLimit-Reset
Section-Origin-Responded
X-Via-PopV
X-Httpd
Section-Io-Origin-Status
X-Proxy-Cache-Info
Section-Io-Origin-Time-Seconds
X-Edge-POP
X-NGINX-Cache
X-Edge-Cache
Servername
X-Check-Cacheable
WZWS-RAY
Producers
ENV
Ohc-File-Size
X-Api-Version
X-ServerName
X-Cache-CFC
X-ElasticPress-Query
X-Ucs
X-Fastly-Backend-Reqs
FSS-Cache
X-SB
X-Micro-Cache
X-BBC-Origin-Response-Status
User-Agent
X-HS-Status
Fastly-Backend-Name
Load-Balancing
X-Udemy-Cache-App-Namespace
X-Backend-Host
X-Platform-Cluster
X-Platform-Processor
X-Pool
X-Platform-Router
X-Acquia-Application-UUID
PICS-Label
X-UP
Uri
ServerName
X-Lb-Nocache
X-Acquia-Purge-Tags
X-Acquia-Site
X-Acquia-Application-Trace
X-GoCache-CacheStatus
URI
X-Nc
X-Release
X-TRACE-ID
X-MG-S
Cteonnt-Length
X-Swift-Error
Tcn
X-Ec-Custom-Error
Cneonction
Cdn
X-Scale
X-Lb-Id
EpKe-Alive
X-Fastly-Cache-Hits
Server-Ttl
X-BCube-Filmed-By
X-APP
X-Cdn-Request-ID
X-Dw-Trace-Id
IsBot
X-Snapshot-Date
Shield-Pop
Cf-Ipcountry
X-Cache-ASPX
X-Akamai-ERRuleID
X-Contensis-Viewer-Groups
X-Akamai-ERPolicy
Path
X-Yottaa-OS
Ohc-Cache-HIT
Wpo-Cache-Message
X-B3-Parentspanid
CF-Cached-On
X-Cache-Expires
X-B3-ParentSpanId
Wpo-Cache-Status
X-Dispatcher-Number
Sever-Int
MD5-Digest
X-SIPLIST1
X-Newrelic-App-Data
Vha6-Origin
X-Vcache
Server-Hostname
Server-Ext
X-HostName
Sid
X-Air-Pt
X-Cache-Ngx
X-Shopify-Generated-Cart-Token
GeoIP-Latitude
X-WA-Info
X-Akamai-Request-ID
X-IN-APIGATEWAYSSL
X-IN-APIGATEWAY
X-WA
X-Http-Duration-Ms
VNS-Cache
X-Amz-Meta-Cb-Modifiedtime
X-Sentry-ID
Ngx
VNS-Age
X-CacheKey
Req-ID
CountryCode
X-Akamai-Pragma-Client-IP
X-UA
X-Logging-Id
CPC-Cache
X-Http-Count
X-Te-Count
X-Te-Duration-Ms
X-Varnish-Authentication
Cache-Key
CPC-Age
X-Apw-Hits
X-Apw-Access-Token
X-Apw-Access-Object
X-Apw-Access-Action
X-Last-Modified