Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-Cache-Status
Link
Accept-Ranges
CF-RAY
ETag
X-XSS-Protection
Expect-CT
Pragma
X-Powered-By
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
Alt-Svc
X-UA-Compatible
P3P
X-Served-By
X-Xss-Protection
X-Download-Options
X-Timer
X-Request-Id
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Cache-Status
X-Generator
X-Cacheable
Timing-Allow-Origin
X-Content-Security-Policy
P3p
X-Iinfo
Status
Feature-Policy
X-Envoy-Upstream-Service-Time
Content-Encoding
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
X-CDN
X-AspNetMvc-Version
X-Request-ID
Upgrade
X-Via
CF-Ray
X-Ws-Request-Id
Access-Control-Max-Age
Server-Timing
EagleId
X-Cache-Group
Keep-Alive
X-Turbo-Charged-By
Request-Context
X-Age
X-Server-Powered-By
X-Proxy-Cache
X-AH-Environment
X-Backend
X-Ua-Compatible
X-UA-Device
X-Hacker
X-Robots-Tag
Report-To
X-Amz-Request-Id
Host-Header
X-Server
X-Amz-Id-2
X-LiteSpeed-Cache
Grace
X-Rq
X-Nginx-Cache-Status
X-Varnish-Cache
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-WebKit-CSP
X-Dns-Prefetch-Control
X-Page-Speed
X-Vhost
EagleEye-TraceId
X-OneAgent-JS-Injection
X-Amz-Version-Id
X-Pingback
X-Dispatcher
X-Device
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Cache-Spec
NEL
X-Server-Id
X-Host
Cf-Railgun
X-Node
X-Backend-Server
Accept-CH
X-Readtime
X-Akam-SW-Version
Surrogate-Control
Request-Id
X-Response-Time
X-HW
Xkey
X-Ruxit-JS-Agent
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Application-Context
Content-Location
Rating
X-Country
X-B3-TraceId
Accept-Ch-Lifetime
Accept-CH-Lifetime
X-Cache-Lookup
X-Cloud-Trace-Context
X-Trace
X-Url
X-Ac
X-Content-Type
Allow
X-TtlSet
X-PC
X-Vname
X-Varnish-TTL
X-Clacks-Overhead
X-Mod-Pagespeed
Edge-Control
X-FastCGI-Cache
X-ESI
X-Server-Name
Fastly-Restarts
Cache-Tag
Service-Worker-Allowed
X-VARITI-CCR
X-Rack-Cache
X-Element-Page-Cache
Verso
X-Language
X-GitHub-Request-Id
X-Upstream
X-MS-InvokeApp
MS-Author-Via
X-Amz-Rid
X-Vcap-Request-Id
Public-Key-Pins
X-Cached
X-Dw-Request-Base-Id
X-Aws-Lambda-Call-Status
X-Client-IP
X-D2id
X-Abt-Application-Version
X-Template
X-Cache-TTL
X-ORACLE-DMS-ECID
X-Cnection
X-ORACLE-DMS-RID
X-Origin-Cache
X-Px
Arr-Disable-Session-Affinity
X-Country-Code
X-Navigation-Version
RTSS
X-Goog-Hash
Access-Control-Request-Method
X-Powered-By-Plesk
X-Kraken-Loop-Name
X-Instrumentation
X-Server-Lifecycle-Phase
X-NF-Request-ID
Accept-Ch
X-GoogleNews-Bot
X-Exp-Variant
X-Exp-Id
X-Kinja
X-Kinja-Build
X-Use-Magma
X-Kinja-Server
X-Cdn-Fetch
X-Kinja-Revision
X-Powered-CMS
X-Version
Pagespeed
Display
X-Middleton-Display
X-Sol
AR-Request-ID
AR-SID
AR-CACHE
AR-ATIME
AR-PoweredBy
X-Amz-Server-Side-Encryption
X-Middleton-Response
Response
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-MSEdge-Ref
X-LLID
X-Edge-Location-Klb
X-Edge
X-Kinsta-Cache
Nginx-Cache
X-TTL
X-RateLimit-Remaining
X-B3-TraceId-Primal
Mrf-Cache-Status
MRF-Tech
X-Shield-Request-Id
X-Protected-By
X-HP-Trace-Id
X-Jurisdiction
X-HP-Webp
TCN
X-T
X-Buckets
X-Forwarded-For
S
X-Content-Security-Policy-Report-Only
X-Mg-S
Content-MD5
X-Id
X-Aspnetmvc-Version
X-Mid
Realpath
Edge-Cache-Tag
Fastcgi-Cache
X-CST
SPIisLatency
X-MCACHE
SPRequestDuration
Front-End-Https
X-Recruiting
Pinterest-Version
X-Pinterest-Rid
Filters
Pinterest-Generated-By
X-Request-Processing-Time
X-Request-Received
X-Ttl
Server-Node
X-Ab
X-Content
X-Ua-Browser
X-DynaTrace
Server-Name
X-Frontend
X-Parallel-Accel
X-NWS-LOG-UUID
SPRequestGuid
X-SharePointHealthScore
Fusion-Content-Id
Fusion-Deployment-Id
Fusion-Content-Source
X-Ezoic-Cdn
Fusion-Template-Id
Fusion-Source
Fusion-Component-Id
X-Correlation-Id
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Cache-Config
X-HS-Combine-CSS
X-Yandex-Sdch-Disable
X-ECACHE
Alternate-Protocol
X-Hits
X-Ser
X-Cache-Key
X-Content-Options
X-Tt-Trace-Tag
X-Tt-Trace-Host
MicrosoftSharePointTeamServices
Cache-Tags
Host
Charset
Cleartype
X-Git-Hash
X-Page-Id
X-B3-Sampled
X-Fastly-Request-Id
X-Kong-Upstream-Latency
X-Www-Served-By
X-Kong-Proxy-Latency
X-Ruxit-Js-Agent
X-Accel-Expires
X-Daa-Tunnel
X-Geo-Country
X-Content-Digest
X-DIS-Request-ID
X-Amzn-Trace-Id
X-Amz-Replication-Status
X-XRDS-LOCATION
Filterid
X-Varnish-Age
X-Debug-Info
X-Hostname
TP-L2-Cache
TP-Cache
X-AppVersion
X-Az
X-Activity-Id
X-FB-Debug
X-VCache
X-Forwarded-Proto
X-Rid
X-Upgrade-Enabled
X-Grace
X-Origin-Server
Access-Control-Allow-Method
X-N
Cross-Origin-Opener-Policy
X-Ratelimit-Limit
X-WebKit-CSP-Report-Only
X-Nginx-Upstream-Cache-Status
X-LB-Cache
X-F-Cache
ServerID
X-Mobile-URL
X-Flags
X-Providence-Cookie
X-Whom
X-Aspnet-Duration-Ms
X-Route-Name
X-Request-Guid
X-Is-Crawler
X-Goog-Stored-Content-Encoding
X-GUploader-UploadID
X-Goog-Generation
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-Goog-Metageneration
X-TT
X-Varnish-Grace
Viewport
X-App-Environment
X-Tb
Node
X-App-Server
X-Origin-Upstream-Status
X-Server-ID
X-Seen-By
X-FW-Serve
X-FW-Hash
X-FW-Server
X-FW-Static
X-FW-Type
X-Distributor
X-FW-Dynamic
DC
Payment
Paypal-Debug-Id
X-Type
X-NGENIX-Cache
X-User-Agent
Fastcgi-Useragent
X-Cache-Control
Country
Accept-Charset
X-Logged-In
X-Request-Handler-Origin-Region
X-Microsite
X-Cache-Rule
X-Wix-Request-Id
X-Cache-Age
X-Litespeed-Cache
Version
X-Webkit-CSP
X-Via-JSL
X-Varnish-Backend
X-Erf-Bev-Bev
X-DataDome
X-Browser-Type
X-Erf-Bev-Bev-Is-Generated
Referer-Policy
X-Drupal-Cache-Tags
X-Node-Name
Refresh
X-Cluster-Name
X-Load-Cache
X-Mobile
X-Response-Served-From
X-Cache-Action
Cache-Status
X-Original-Request-Id
X-Tec-Api-Root
X-Contextid
X-Signature
X-Tec-Api-Version
X-B-Cache
SD-X-WS
X-Tec-Api-Origin
Access-Control-Request-Headers
X-Jobs
X-Real-IP
X-Cacheable-TTL
X-Is-Bot
VIX-Pulpo-Node
NGB
Amp-Access-Control-Allow-Source-Origin
X-IPLB-Instance
X-Debug
X-B
X-Cache-Expired-At
X-ProcessESI
VIX-Pulpo-Upstream-Status
X-Page-View
X-Rendered-As
X-RemovedCookies
X-Revision
X-Proxy-Cache-Status
X-UUID
X-Vgn-Hpd-Reason
X-Yottaa-Metrics
X-Instance
X-Proxy
X-Device-Type
X-Yottaa-Optimizations
X-Rule
Akamai-GRN
X-Cache-Time
X-Framework
X-G
Surrogate-Key
X-Fastly-Request-ID
X-Drupal-Cache-Contexts
CF-IPCountry
X-FW-Version
X-Debug-IsPreview
X-Debug-IsConnected
X-Fastcgi-Cache
X-Air-Source
X-Air-Hostname
X-Air-Trace-Id
DynaTrace
SID
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Ratelimit-Reset
X-PressLabs-Stats
X-Azure-Ref
X-Oracle-Dms-Rid
Healthy
Liferay-Portal
X-Oracle-Dms-Ecid
X-Presslabs-Stats
X-Nginx-Cache
GEO-INFO
X-Source
Frame-Options
X-Ms-Request-Id
Count-Hit
X-Ms-Version
X-Oneagent-Js-Injection
X-Cache-Operation
Ms-Operation-Id
X-RTag
MS-CV
Uber-Trace-Id
X-Accel-Buffering
X-Ua-Device
X-CDN-Forward
X-APP-VERSION
Xserver
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Tumblr-User
Countrycode
X-Tumblr-Pixel-1
X-EdgeConnect-Cache-Status
X-Varnish-Server
X-Cache-Hit
X-L-Path
X-XRDS-Location
X-Environment-Context
X-Zen-Fury
X-Region
X-Mode
Ec-Rule-Version
X-Backend-Name
X-Servername
X-Forwarded-Host
Backend
Cross-Origin-Window-Policy
X-IPS-LoggedIn
X-Cache-NGX
X-Content-Powered-By
Section-Io-Cache
X-UPSTREAM-Address
X-JoinUs
X-SaId
X-RN-RSRV
Protected
Meta-Geo
X-Cache-Type
X-Cache-Server
X-Varnish-Beresp-Grace
X-Redis-Cache
X-Generation-Time
Apigw-Requestid
X-Zipkin-Id
X-Rewrite-Enabled
Eomportal-Instance
X-Human
X-Hosted-By
X-Routing-Service
Decoy-Debug-Status
X-Cache-TTL-Remaining
Decoy-Debug-TTL
X-Cache-Grace
X-Debug-Cache
X-Extlb
Decoy-Debug-Key
X-Proxied
X-Detected-As
Fastly-SSL
Url
X-Via-Fastly
X-ServerID
X-FB-TRIP-ID
X-BYPASS-REASON
X-ApacheServer
Cache-Tv-Group
X-Alternate-Cache-Key
X-ShardId
X-NCache
X-Sorting-Hat-ShopId
X-Status
X-ShopId
X-ProxyCache-Key
X-Soup
X-PHP-Backend
X-Origin-Date
X-Shopify-Stage
X-Sql-Count
X-No-Session
X-PERF
X-Site-Version
X-Sorting-Hat-PodId
Country-Code
X-ProxyCache-Status
Cache-Name
X-Sql-Duration-Ms
X-Uri
Selected-Fe
Webcakes-App-Version
Property-Id
Webcakes-App-Name
TWC-GeoIP-LatLong
TWC-Device-Class
TWC-GeoIP-Country
Webcakes-Region
Mn-Server-Ip
TWC-Privacy
DB-Nickname
TWC-Connection-Speed
TWC-Locale-Group
X-PCL
X-Timing-Wait
X-Storage
X-Say-TTL
X-UA-Device-Type
X-Web-Node
X-NYM-Debug-Backend
X-Format
X-NewRelic-App-Data
X-Say-Cacheable
X-SayCDN-TTL
X-Microcachable
X-Akamai-Edgescape
X-Origin-Hint
X-OCL
X-Proxy-Build
X-Cache-Host
X-Access
X-Cluster-Node
X-Hl-Ver
X-Section
X-Varnishpool
X-Tid
OT-Force-Account-Verify
X-Pubstack
X-Adobe-Content
X-Server-W
X-Adobe-Loc
Azure-RegionName
X-Content-Age
Azure-SiteName
Azure-InstanceId
Azure-Version
Azure-SlotName
Content-Secure-Policy
X-RateLimit-Limit
X-R9-Blue-Green-Version
X-Be
X-Ua
SRV
X-LSADC-Cache
X-Hyper-Cache
X-Azure-Ref-OriginShield
X-Generated-By
CDN-PullZone
CDN-RequestId
CDN-Uid
CDN-EdgeStorageId
CDN-RequestCountryCode
CDN-Cache
CDN-CachedAt
X-Webkit-Csp
Content-Disposition
Source
X-Cached-By
X-TIME
X-Trace-Id
LB
X-Dc
WPO-Cache-Status
Cache
WPO-Cache-Message
X-Unique-Id
X-Nginx-Cache-Key
X-App-Version
X-Bc-Bl
X-SRV
X-LAGOON
X-Ratelimit-Remaining
X-Varnish-Hits
Retry-After
Cache-Hits
X-Auto-Login
X-TT-LOGID
X-HTML-Minification-Powered-By
Xet-Cookie
X-Origin-TTL
X-Varnish-Hostname
X-Amz-Meta-S3cmd-Attrs
X-Origin-CC
X-Loop
X-GEO
X-TNCMS
X-Akamai-Transformed
X-S-Maxage
Mime-Version
Onion-Location
HostName
X-ECache
X-Platform-Server
X-Tumblr-Pixel-2
X-Xfnlog-Site
X-Tumblr-Pixel-3
X-CSRF-Token
X-Cache-Var
X-Cdn
X-Cache-Var-Map
Web-Mar-Node
X-Proto
Webserver
X-Correlation-ID
X-Cache-Tags
X-Time
X-Time-Microsecs
X-Tenant
X-Edge-Location
X-Varnish-Cache-Hits
X-Cache-Remote
X-Endurance-Cache-Level
Upgrade-Insecure-Requests
X-AWS-Id
X-LJ-Flow-ID
ServedBy
X-VWS-Id
X-Request-Time
X-AOL-HN
X-EC-Lua
N-Cache
X-GG-Cache-Date
CloudFront-Viewer-Country
X-M-Log
X-Qnm-Cache
X-M-Reqid
X-Mg-Request-UUID
X-Request-Host
X-Labrador-Cache-Channel
X-Amzn-RequestId
X-Amz-Apigw-Id
X-PHP-Host
From-Origin
X-Via-NSCOPI
X-B3-SpanId
WP-Super-Cache
X-FireWall-Port
X-NAPM-TraceId
X-A
X-Planisys-CDN-Rules
X-A-Dcw
X-A-Dgt
X-Planisys-CDN-Cache
X-PBS-Appsvrname
X-PAYTM-SRV-ID
X-Origin-Response-Time
X-Orig-Expires
V-Age
X-ND-Cache
X-A-Dam
X-A-Ccd
Expiry
X-Cluster
X-Ckpd-Fst-Backend
X-CF-Lambda-Version
Mobile-Detection-Method
Meta-Geo-Continent
X-D
X-Connection-Hash
X-Conf
Odigeo-Trace-Id
X-CF-Lambda-Fn
Rendered-Blocks
Sslversion
X-Cache-Date
Redirect-Candidate
Pramga
Origin
X-Cache-NE
X-Planisys-CDN-TTL
L
DCR-Decision-By
DCR-Processing-Time-Ms
X-Aed
X-Forwarded-Path
X-Ftr-Request-Id
A
X-A-Wwc
BehaviorPad-Version
DSUID
X-External-Request-Id
X-ARC
X-Developer
X-Destination
Surrogated-Key
X-Application
X-B-Cookie
Fastcgi-X-Cache-Version
X-Ig-Push-State
X-Processor
X-SVT-ORM-VERSION
X-ScT
X-S-Cookie
X-S
X-Rojux
X-TIM-N
Xc-Version
X-SVT-ORM-RULES
X-SRCache-Key
X-Slack-Backend
X-Shop-Environment
X-CACHE-KEY
X-Session-Fingerprint
X-V-Cache
X-SD-PageType
X-Vdms-Version
X-Vtex-Remote-Cache
X-Vtex-Processado-Em
X-Vdms-Path
X-VG-WebCache
Nel
X-MP-GENERATED-AT
X-Locale
X-Handled-By
Svr
X-Sucuri-ID
Ssr
X-Sucuri-Cache
Release
X-Fetched-On
CDCHOST
CacheControlHeader
X-Skip-Cache
X-Forwarded-Site
Cmstype
Cmsid
PFcat
X-Cache-Info
X-Cdn-Srv
X-Gdpr
X-Varnish-Beresp-Status
X-Cache-Bucket
X-Webstats-RespID
X-Core-Mission
X-Block-Status
X-RCS-CacheZone
X-Epic-Correlation-Id
X-VarnishDD-TTL
X-Device-Os
Gh-Request-Id
X-Date
Host-ID
Fastcgi-Cache-TTL
X-Aicache-OS
X-Li-Pop
X-Served-From
X-Gen-Mode
X-Origin-Expires
X-Server-IP
Vix-Hermes-Req-Id
X-Li-Fabric
X-Rocket-Nginx-Serving-Static
X-LI-UUID
X-Scheme
X-Nyt-Route
X-Mvc-Supplant-Cachable
X-Old-Content-Length
X-Location
X-Men
User-Cache-Control
X-Origin-Time
X-Accel-Expires-Debug
X-Proxy-Upstream
Wxu-Next-Hostname
X-Geo-Header
Wxu-Next-Commit
X-VServer
X-Policy
X-Hash
AKAMAI
X-Hnp-Log
X-Owner
Server-Info
True-Client-Country-4JS
X-HN
Wxu-Next-Region
X-NodeID
Fastly-Drupal-Html
X-NWS-UUID-VERIFY
AMP-Access-Control-Allow-Source-Origin
X-VC-Cache
L5d-Success-Class
HA-Ipaddr
X-Eu-Site
X-Csrf-Jwt
X-Backend-State
X-CGP
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Cache-Config
X-Bip
X-ATG-Version
Ha-Gx-Prefs
X-UnsetCookies
X-Request-URI
X-Fastly-Backend
X-Sigma
X-HS-Content-Campaign-Id
X-Gzip
X-GeoIP-City
X-Sigma-Backend
X-GeoIP
X-Irp-Debug
X-Level-Front-Cache
X-Req
X-Region-Sid
X-Reqid
X-Request-Start
X-Node-Id
X-Rocket-Build-Number
X-Generated-On
X-Gamma-Serve
X-Thanos
X-Datadog-Parent-Id
X-Thinkindot-L3
X-TrackingId
X-Cache-Id
X-Cdn-Origin
X-Datadog-Sampling-Priority
X-Datadog-Trace-Id
X-Sn-Servicetimems
X-Fastly-Cache
X-Storefront-Renderer-Rendered
X-Platform
X-Developers
X-Esi-Check
X-Viewer-Country
X-Branch-Name
Mail-Subject
Machine
Origin-CC
Apple-News-Services-Parsed-Url
State
Server-Host
Locid
X-Magnolia-Registration
Arc-Country
Apple-News-Services-Request-Url
Apple-News-Services-Host
Apple-News-Services-Handled
Fastly-GeoIP-CountryCode
X-Cache-Enabled
TDXMobile
Origin-EX
Thinkindot-Control
Traceparent
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
Web-Mar-Region
We-Hiring
X-Zone
Environment
X-Envoy-Decorator-Operation
X-Core-Value
Memcached
X-Pod-Name
NM-Fastcgi-Cache
X-Amzn-Remapped-Content-Length
X-NU-AKA-ACS-Version
X-DefElseHash
X-Is-Gdpr
Cf-Device-Type
Adler-Geo
X-Has-Esi
X-JWT-State
X-FC-Vary-Parameters
X-Adobe-Source
X-DefHash
X-DPWN-IS-SECURE
X-Loc
Is-Eu
X-Origin
X-Variation
X-TH-Server
Platform
X-Cache-Debug
Req-Svc-Chain
X-BBC-Edge-Cache-Status
X-Response-By
X-Varnish-CookieHashed-On
X-Qloud-Router
X-VG-TLSProxy
X-Worker
X-Varnish-Remaining-TTL
X-Varnish-CookieINHashed-On
X-Xrds-Location
X-Mvc-Supplant-OutputCached
X-Backend-TTL
Fastly-SIE
Fastly-SWR
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-Datadome
NGX
X-NC
X-GeoIP-Region-Code
X-API-Version
X-CS
X-GeoIP-Country-Code
X-LB-ID
X-CLOUD-TRACE-CONTEXT
X-Tx-Id
CDN
Candidate-Md5Url
Datacenter
X-Up
X-Generated-In
X-Varnish-Beresp-Ttl
X-DynaTrace-JS-Agent
X-TraceId
Magicmarker
Pics-Label
S-Rt
Ms-Author-Via
X-Trace-ID
X-Tt-Logid
X-Tb-Optimization-Total-Bytes-Saved
WWW-Authenticate
X-Via-Poph
NtCoent-Length
Env
X-Edge-Pop
X-Vc
Kp-EeAlive
X-Via-Popn
X-Restarts
On-Server
X-Via-Popv
GeoIp-Country-Code
Memory
X-Optimistic-Header
Esi-Enabled
X-LB-NoCache
X-Varnish-Ttl
Time
WebServer
X-Akamai-Request-ID2
X-Http-Reason
X-Wix-Viewer-Type
X-Varnish-Beresp-TTL
X-Refresh
X-RPM
X-DI
X-DB
X-Action
X-DSS
X-DW
Edge-Cache
X-RSL
X-RPS
X-Cache-Backend
X-TA-CDN-Provider
X-DC
X-CacheTTL
X-Dynatrace
C-Via
X-Service
X-Srv
X-TX-ID
X-Cache-PHP
X-Cs
X-Parent-Response-Time
X-Esi
X-Newrelic-Synthetics
X-Unique-ID
X-Servedbyhost
X-MSEdge-Flight
X-Minions-Version
X-MSEdge-Features
Accept-Language
X-ZONE
Server-ID
X-Cache-Status-Check
X-HA-Backend
X-Render-Time
X-Urbn-Site-Id
X-Li-Proto
Locale
X-Urbn-Context-Path
X-FPC
X-App
X-Cache-Ttl
X-VCL-Version
X-Ec-GeoHdr
X-Ec-Fail
X-User
X-B3-Spanid
Proxy-Connection
X-URL
X-AIR-PT
X-Vcl-Version
Server-Id
X-LI-Proto
X-Info
X-Webkit-Csp-Report-Only
X-Fpc
Test
X-LiteSpeed-Cache-Control
X-Pass-Why
X-Traceid
X-Clientip
X-NODE
X-Webkit-CSP-Report-Only
Cache-Host
Cdncip
Geo-Info
HIT
X-AK-Request-ID
Cdnsip
X-Oss-Request-Id
X-Oss-Storage-Class
X-Oss-Server-Time
Tcn
X-Oss-Hash-Crc64ecma
UCS
X-Oss-Object-Type
Cluster
My-App
S-Cnection
Geoip-Latitude
M-TraceId
Fastly-Drupal-HTML
X-WADP-Cache
X-Clara-WADP
X-ServedByHost
Resin-Trace
X-Fmm-Version
X-CUA
X-HostName
X-Var-Ttl
Tracecode
Cf-Int-Pingora-Origin-Digest
X-LiteSpeed-Tag
X-CSRF-TOKEN
Fastly-Backend-Name
X-Micro-Cache
T-Server
User-Agent
X-ID
X-Ha-Backend
Hostname
Section-Io-Id
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
Lang
X-Fragments
X-RAMCache
X-Mcache
Section-Origin-Responded
Ohc-File-Size
X-From
GeoIP-Country-Code
Hit
Lfy
X-Pad
X-Backend-Host
X-Release
X-Cdn-Forward
Lb
X-Geo
DataCenter
X-Dynatrace-Js-Agent
X-WP-CF-Super-Cache-Cache-Control
X-BCube-Filmed-By
X-Via-PopN
X-Via-PopH
X-Via-PopV
MIME-Version
X-Check-Cacheable
X-BBC-Origin-Response-Status
X-Edge-POP
X-ElasticPress-Query
Target-Params
ENV
X-APP
X-WP-CF-Super-Cache
X-Edge-Cache
X-NGINX-Cache
Load-Balancing
X-HS-Status
X-Api-Version
X-VC
X-ServerName
X-Ucs
X-WA
X-WA-Info
EpKe-Alive
X-Amz-Meta-Cb-Modifiedtime
VNS-Cache
Path
CPC-Age
Uri
CPC-Cache
Cache-Key
URI
Servername
X-Fastly-Backend-Reqs
VNS-Age
X-ES-SERVER
X-Httpd
X-Proxy-Cache-Info
PICS-Label
X-GoCache-CacheStatus
Permissions-Policy
FSS-Cache
X-Fastly-Cache-Hits
X-UP
X-Lb-Nocache
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-TRACE-ID
Cteonnt-Length
X-PJAX-URL
X-Cms-Context
Cneonction
X-Akamai-ERPolicy
Cdn
X-Akamai-ERRuleID
Pagetype
ServerName
X-Lb-Id
WZWS-RAY
Shield-Pop
Producers
X-Provided-By
X-B3-ParentSpanId
X-Cdn-Request-ID
X-Nc
Ohc-Cache-HIT
X-RateLimit-Reset
X-Dw-Trace-Id
X-Contensis-Viewer-Groups
X-Hcs-Proxy-Type
X-SB
Server-Ttl
X-Cache-ASPX
MD5-Digest
X-Snapshot-Date
X-Acquia-Purge-Tags
X-Acquia-Site
X-Pool
X-Acquia-Application-Trace
X-Acquia-Application-UUID
X-Apw-Access-Object
X-Via-Ucdn
CF-Cached-On
X-Apw-Access-Action
X-Vcache
Cf-Ipcountry
X-Cache-CFC
X-Yottaa-OS
X-Akamai-Pragma-Client-IP
Vha6-Origin
Srv
X-CCDN-Origin-Time
X-Apw-Hits
X-Apw-Access-Token
X-Newrelic-App-Data
X-CCDN-CacheTTL
X-Swift-Error
X-Cache-Ngx
Sid
X-Air-Pt
X-Te-Duration-Ms
X-Last-Modified
X-Udemy-Cache-App-Namespace
Server-Ext
X-VG-WebServer
X-UA
Req-ID
X-CacheKey
X-Logging-Id
W
X-Varnish-Authentication
X-Miniprofiler-Ids
Sever-Int
X-B3-Parentspanid
IsBot
X-Http-Count
X-Http-Duration-Ms
Ngx
X-Sentry-ID
Server-Hostname
CountryCode
X-SIPLIST1
X-Te-Count