Threat Level: green Handler on Duty: Jan Kopriva

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
Link
CF-Cache-Status
Accept-Ranges
CF-RAY
ETag
Expect-CT
Pragma
X-Powered-By
X-XSS-Protection
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-UA-Compatible
X-Cache-Hits
Alt-Svc
P3P
X-Served-By
X-Xss-Protection
X-Download-Options
X-Timer
X-Request-Id
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Cache-Status
X-Generator
X-Cacheable
Timing-Allow-Origin
X-Content-Security-Policy
P3p
X-Iinfo
Status
Feature-Policy
X-Envoy-Upstream-Service-Time
Content-Encoding
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
X-CDN
X-AspNetMvc-Version
X-Request-ID
Upgrade
X-Via
CF-Ray
X-Ws-Request-Id
Access-Control-Max-Age
Server-Timing
EagleId
X-Cache-Group
Keep-Alive
X-Turbo-Charged-By
Request-Context
X-Age
X-Server-Powered-By
X-Proxy-Cache
X-AH-Environment
X-UA-Device
X-Backend
X-Hacker
X-Robots-Tag
Report-To
X-Amz-Request-Id
X-Server
Host-Header
X-Amz-Id-2
X-LiteSpeed-Cache
Grace
X-Rq
X-Nginx-Cache-Status
X-Varnish-Cache
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-WebKit-CSP
X-Dns-Prefetch-Control
X-Page-Speed
X-Vhost
EagleEye-TraceId
X-OneAgent-JS-Injection
X-Amz-Version-Id
X-Pingback
X-Device
X-Dispatcher
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Cache-Spec
NEL
X-Server-Id
X-Host
Cf-Railgun
X-Node
X-Backend-Server
Accept-CH
X-Readtime
Surrogate-Control
X-Akam-SW-Version
Request-Id
X-Response-Time
X-HW
Xkey
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Ruxit-JS-Agent
X-Application-Context
Content-Location
Rating
X-Country
X-Ua-Compatible
X-B3-TraceId
Accept-Ch-Lifetime
X-Cache-Lookup
Accept-CH-Lifetime
X-Language
X-Cloud-Trace-Context
X-Trace
X-Ac
X-Template
X-Content-Type
X-Url
Allow
X-PC
X-TtlSet
X-Vname
X-Varnish-TTL
X-Mod-Pagespeed
X-Clacks-Overhead
Edge-Control
X-FastCGI-Cache
Cache-Tag
Fastly-Restarts
X-Server-Name
X-ESI
Service-Worker-Allowed
X-Rack-Cache
X-VARITI-CCR
X-Element-Page-Cache
Verso
X-MS-InvokeApp
X-GitHub-Request-Id
X-Upstream
MS-Author-Via
X-Buckets
X-Amz-Rid
X-Vcap-Request-Id
Public-Key-Pins
X-Dw-Request-Base-Id
X-Cached
X-Client-IP
X-D2id
X-Abt-Application-Version
X-Aws-Lambda-Call-Status
X-Cache-TTL
X-Origin-Cache
X-Cnection
X-Px
Arr-Disable-Session-Affinity
X-Country-Code
X-Navigation-Version
X-Goog-Hash
X-Powered-By-Plesk
RTSS
Access-Control-Request-Method
X-NF-Request-ID
X-Server-Lifecycle-Phase
X-Instrumentation
X-Kraken-Loop-Name
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
Accept-Ch
X-Version
X-Powered-CMS
X-Cdn-Fetch
X-Exp-Id
X-Use-Magma
X-Kinja-Server
X-Kinja-Revision
X-Kinja-Build
X-Kinja
X-GoogleNews-Bot
X-Exp-Variant
X-Middleton-Display
X-Sol
Display
Pagespeed
X-Amz-Server-Side-Encryption
X-SRCache-Fetch-Status
Response
X-Middleton-Response
X-SRCache-Store-Status
AR-CACHE
AR-SID
AR-Request-ID
AR-PoweredBy
AR-ATIME
X-MSEdge-Ref
X-LLID
X-Edge-Location-Klb
X-Kinsta-Cache
X-Edge
Nginx-Cache
MRF-Tech
Mrf-Cache-Status
X-B3-TraceId-Primal
X-RateLimit-Remaining
X-Shield-Request-Id
X-Protected-By
X-Jurisdiction
X-HP-Trace-Id
X-HP-Webp
X-T
TCN
S
X-Forwarded-For
Content-MD5
X-Content-Security-Policy-Report-Only
X-Mg-S
X-TTL
X-Id
X-Aspnetmvc-Version
Realpath
X-CST
X-MCACHE
Edge-Cache-Tag
Fastcgi-Cache
X-Mid
X-Ttl
SPRequestDuration
SPIisLatency
Front-End-Https
X-Recruiting
X-Request-Received
X-Request-Processing-Time
Filters
Server-Node
Pinterest-Generated-By
Pinterest-Version
X-Pinterest-Rid
X-Parallel-Accel
X-Ab
X-Content
X-Ua-Browser
X-Correlation-Id
X-DynaTrace
Server-Name
Fusion-Template-Id
Fusion-Source
Fusion-Component-Id
Fusion-Content-Id
Fusion-Deployment-Id
Fusion-Content-Source
SPRequestGuid
X-SharePointHealthScore
X-NWS-LOG-UUID
X-Frontend
X-Ezoic-Cdn
X-HS-Cache-Config
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Combine-CSS
Alternate-Protocol
X-ECACHE
X-Yandex-Sdch-Disable
X-Hits
X-Content-Options
X-Cache-Key
X-Ser
X-Tt-Trace-Tag
X-Tt-Trace-Host
Cache-Tags
X-Kong-Proxy-Latency
X-Git-Hash
MicrosoftSharePointTeamServices
X-Kong-Upstream-Latency
X-B3-Sampled
Cleartype
X-Accel-Expires
X-Page-Id
Host
Charset
X-Www-Served-By
X-Ruxit-Js-Agent
X-Daa-Tunnel
X-Content-Digest
X-Geo-Country
X-Amz-Replication-Status
X-DIS-Request-ID
X-Amzn-Trace-Id
Filterid
X-Fastly-Request-Id
TP-L2-Cache
TP-Cache
X-Varnish-Age
X-VCache
X-Hostname
X-Debug-Info
X-Forwarded-Proto
X-AppVersion
X-Az
X-Activity-Id
X-Upgrade-Enabled
X-Rid
X-N
X-FB-Debug
X-XRDS-LOCATION
X-Origin-Server
Access-Control-Allow-Method
X-Grace
X-LB-Cache
Cross-Origin-Opener-Policy
ServerID
X-Nginx-Upstream-Cache-Status
X-WebKit-CSP-Report-Only
X-Mobile-URL
X-F-Cache
X-Route-Name
X-Providence-Cookie
X-Aspnet-Duration-Ms
X-Flags
X-Request-Guid
X-Is-Crawler
X-Whom
X-Goog-Metageneration
X-Goog-Stored-Content-Length
X-Origin-Upstream-Status
X-GUploader-UploadID
X-Goog-Storage-Class
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-TT
X-App-Environment
X-Tb
X-Varnish-Grace
X-App-Server
Viewport
X-FW-Static
X-FW-Type
X-FW-Server
X-FW-Serve
X-FW-Dynamic
X-FW-Hash
X-Distributor
Paypal-Debug-Id
Node
Payment
DC
X-Server-ID
X-Seen-By
X-NGENIX-Cache
X-Type
X-Cache-Control
Fastcgi-Useragent
X-Request-Handler-Origin-Region
X-Microsite
X-User-Agent
X-Ratelimit-Limit
Accept-Charset
Country
X-Logged-In
X-Cache-Rule
X-Cache-Age
X-Litespeed-Cache
X-Wix-Request-Id
X-DataDome
Version
X-Webkit-CSP
X-Fastly-Request-ID
X-Varnish-Backend
X-Browser-Type
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Via-JSL
Referer-Policy
X-Node-Name
X-Drupal-Cache-Tags
Refresh
X-Load-Cache
X-Cache-Action
X-Mobile
Access-Control-Request-Headers
X-B-Cache
X-Response-Served-From
X-Contextid
Amp-Access-Control-Allow-Source-Origin
X-Signature
SD-X-WS
X-Cluster-Name
X-Original-Request-Id
Cache-Status
X-IPLB-Instance
X-TEC-API-ORIGIN
X-Jobs
X-TEC-API-VERSION
X-Vgn-Hpd-Reason
X-Rendered-As
X-Oracle-Dms-Rid
X-Cacheable-TTL
X-Page-View
X-TEC-API-ROOT
X-Proxy-Cache-Status
X-Oracle-Dms-Ecid
X-Is-Bot
VIX-Pulpo-Upstream-Status
X-B
X-UUID
X-Debug
X-Revision
VIX-Pulpo-Node
NGB
X-Real-IP
X-RemovedCookies
X-Cache-Expired-At
X-ProcessESI
X-Proxy
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-G
X-Drupal-Cache-Contexts
X-Cache-Time
X-Rule
Akamai-GRN
X-Instance
X-PressLabs-Stats
Surrogate-Key
X-Debug-IsPreview
X-Debug-IsConnected
X-Device-Type
X-Framework
X-Fastcgi-Cache
X-FW-Version
CF-IPCountry
DynaTrace
X-Air-Source
X-Air-Hostname
X-Air-Trace-Id
SID
X-Tec-Api-Origin
X-Tec-Api-Version
Liferay-Portal
X-Tec-Api-Root
X-Azure-Ref
Healthy
X-XRDS-Location
X-Source
X-Ms-Version
X-Nginx-Cache
X-Ratelimit-Reset
X-Ms-Request-Id
Frame-Options
X-CDN-Forward
Count-Hit
MS-CV
Ms-Operation-Id
X-RTag
X-Oneagent-Js-Injection
X-Cache-Operation
GEO-INFO
X-APP-VERSION
X-Cache-Hit
X-Presslabs-Stats
Uber-Trace-Id
X-Environment-Context
X-EdgeConnect-Cache-Status
X-Tumblr-User
X-Tumblr-Pixel-1
X-L-Path
X-Tumblr-Pixel-0
X-Tumblr-Pixel
Xserver
X-Accel-Buffering
X-Varnish-Server
X-RateLimit-Limit
Countrycode
X-Region
X-Servername
X-Mode
Section-Io-Cache
Ec-Rule-Version
X-Forwarded-Host
X-Zen-Fury
Cross-Origin-Window-Policy
Backend
X-IPS-LoggedIn
X-Content-Powered-By
X-Backend-Name
X-Cache-NGX
Meta-Geo
X-UPSTREAM-Address
X-RN-RSRV
X-SaId
X-Detected-As
X-JoinUs
X-Sql-Count
X-Sql-Duration-Ms
X-Tid
X-ShardId
Eomportal-Instance
X-Proxied
X-Sorting-Hat-ShopId
X-Cache-Grace
X-Varnish-Beresp-Grace
X-Routing-Service
X-Sorting-Hat-PodId
X-Redis-Cache
X-Cache-Type
X-ShopId
X-Shopify-Stage
X-Extlb
X-Generation-Time
X-Debug-Cache
X-Uri
X-Cache-Server
X-Hosted-By
X-Zipkin-Id
Protected
X-Human
X-Alternate-Cache-Key
Country-Code
X-Site-Version
X-Cache-TTL-Remaining
Cache-Tv-Group
X-Microcachable
Cache-Name
Apigw-Requestid
Decoy-Debug-Status
X-UA-Device-Type
X-Via-Fastly
Decoy-Debug-TTL
X-FB-TRIP-ID
X-Origin-Date
X-Adobe-Loc
X-Adobe-Content
X-No-Session
X-Rewrite-Enabled
X-Status
Url
Decoy-Debug-Key
X-NCache
DB-Nickname
Mn-Server-Ip
X-PHP-Backend
X-OCL
X-PCL
X-Say-Cacheable
X-Akamai-Edgescape
X-Server-W
X-Timing-Wait
X-Cache-Host
X-BYPASS-REASON
X-SayCDN-TTL
X-Say-TTL
X-ProxyCache-Key
X-ProxyCache-Status
Selected-Fe
X-Web-Node
X-Proxy-Build
X-Storage
X-Format
TWC-Privacy
TWC-Locale-Group
X-Soup
Webcakes-App-Name
Webcakes-Region
Webcakes-App-Version
TWC-GeoIP-Country
TWC-GeoIP-LatLong
TWC-Connection-Speed
Property-Id
TWC-Device-Class
Fastly-SSL
X-Origin-Hint
X-Varnishpool
X-PERF
X-Access
X-NYM-Debug-Backend
OT-Force-Account-Verify
X-Pubstack
Azure-SlotName
Azure-InstanceId
X-R9-Blue-Green-Version
X-Section
X-ApacheServer
Azure-RegionName
Azure-Version
Azure-SiteName
X-Cluster-Node
Content-Secure-Policy
X-Be
X-ServerID
X-Content-Age
X-LSADC-Cache
X-Ua
X-Azure-Ref-OriginShield
X-NewRelic-App-Data
X-Hl-Ver
CDN-RequestId
CDN-Uid
CDN-RequestCountryCode
X-Hyper-Cache
CDN-EdgeStorageId
Source
CDN-Cache
CDN-PullZone
CDN-CachedAt
SRV
X-Webkit-Csp
X-Generated-By
Content-Disposition
X-Cached-By
X-Unique-Id
X-SRV
Cache
X-TT-LOGID
LB
X-HTML-Minification-Powered-By
X-Nginx-Cache-Key
Xet-Cookie
X-TIME
X-Bc-Bl
X-Dc
X-App-Version
X-LAGOON
X-Auto-Login
X-Varnish-Hits
WPO-Cache-Message
X-Origin-TTL
WPO-Cache-Status
Retry-After
X-Varnish-Hostname
X-Origin-CC
X-Trace-Id
X-TNCMS
X-Loop
X-GEO
X-Amz-Meta-S3cmd-Attrs
Onion-Location
X-S-Maxage
X-Cache-Var
Cache-Hits
X-Cache-Var-Map
X-Time
Mime-Version
X-Akamai-Transformed
Web-Mar-Node
X-Platform-Server
X-ECache
X-Tumblr-Pixel-3
X-Tumblr-Pixel-2
X-Ratelimit-Remaining
X-Cdn
HostName
X-Xfnlog-Site
X-Tenant
X-Time-Microsecs
X-Endurance-Cache-Level
X-M-Log
X-M-Reqid
X-Proto
X-Qnm-Cache
Webserver
X-Cache-Remote
X-Edge-Location
X-CSRF-Token
X-VWS-Id
X-AWS-Id
X-LJ-Flow-ID
Upgrade-Insecure-Requests
X-GG-Cache-Date
X-Cache-Tags
X-Varnish-Cache-Hits
ServedBy
CloudFront-Viewer-Country
N-Cache
X-Request-Time
X-B3-SpanId
X-Mg-Request-UUID
X-AOL-HN
X-PHP-Host
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Labrador-Cache-Channel
X-CACHE-KEY
X-Via-NSCOPI
X-RCS-CacheZone
X-Request-Host
X-EC-Lua
X-Aed
X-A-Dam
X-A-Wwc
X-A-Dcw
X-A-Dgt
X-Session-Fingerprint
X-SRCache-Key
X-Forwarded-Path
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-TIM-N
X-Application
X-Slack-Backend
X-Shop-Environment
X-S-Cookie
X-S
X-ScT
X-SD-PageType
X-A-Ccd
Nel
X-Rojux
X-PAYTM-SRV-ID
Mobile-Detection-Method
Odigeo-Trace-Id
Meta-Geo-Continent
User-Cache-Control
X-ND-Cache
X-NAPM-TraceId
Origin
Pramga
X-Ig-Push-State
X-Hnp-Log
Surrogated-Key
Rendered-Blocks
Redirect-Candidate
X-Gen-Mode
Fastcgi-X-Cache-Version
BehaviorPad-Version
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
A
X-A
X-Planisys-CDN-TTL
X-PBS-Appsvrname
X-Origin-Response-Time
X-Orig-Expires
Expiry
DSUID
DCR-Processing-Time-Ms
DCR-Decision-By
X-Processor
X-Ftr-Request-Id
X-Conf
Xc-Version
X-Cache-Date
X-Block-Status
X-Connection-Hash
X-VG-WebCache
X-Vtex-Processado-Em
X-Cluster
X-Ckpd-Fst-Backend
X-Destination
X-ARC
X-Developer
X-Cache-NE
X-CF-Lambda-Version
X-CF-Lambda-Fn
X-Vdms-Version
X-Vtex-Remote-Cache
X-Vdms-Path
X-Handled-By
X-External-Request-Id
X-Locale
X-Correlation-ID
X-V-Cache
X-D
X-B-Cookie
From-Origin
X-FireWall-Port
X-Storefront-Renderer-Rendered
Fastcgi-Cache-TTL
State
Cmsid
X-Owner
CacheControlHeader
Wxu-Next-Region
X-Hash
X-Origin-Time
Cmstype
X-Date
X-Origin-Expires
X-Nyt-Route
X-Geo-Header
X-Zone
X-Core-Mission
X-Men
X-Location
X-VC-Cache
Traceparent
X-LI-UUID
Wxu-Next-Hostname
X-Gdpr
Origin-CC
X-Old-Content-Length
X-Li-Fabric
Vix-Hermes-Req-Id
Host-ID
X-Li-Pop
Origin-EX
V-Age
X-Rocket-Nginx-Serving-Static
X-VServer
X-Webstats-RespID
X-Cache-Bucket
X-Epic-Correlation-Id
X-Sucuri-ID
X-Scheme
Wxu-Next-Commit
X-Forwarded-Site
X-Skip-Cache
X-Sucuri-Cache
X-Server-IP
X-Served-From
X-Aicache-OS
X-Varnish-Beresp-Status
X-Accel-Expires-Debug
X-Proxy-Upstream
AKAMAI
X-Cache-Info
X-Device-Os
X-Fastly-Cache
Arc-Country
WP-Super-Cache
Sslversion
CDCHOST
X-Fetched-On
L
X-Adobe-Source
X-MP-GENERATED-AT
X-ATG-Version
X-Reqid
Server-Info
AMP-Access-Control-Allow-Source-Origin
Environment
Thinkindot-CacheControl-Type
X-Datadog-Sampling-Priority
Thinkindot-CacheControl
Thinkindot-Control
TDXMobile
X-Datadog-Parent-Id
X-Fastly-Backend
X-Generated-On
X-Cache-Id
We-Hiring
Web-Mar-Region
X-Cdn-Origin
X-Gamma-Serve
X-Branch-Name
X-Bip
X-Core-Value
X-GeoIP
X-Gzip
X-Esi-Check
X-BBC-Edge-Cache-Status
X-Policy
X-VG-TLSProxy
X-TrackingId
X-Viewer-Country
Apple-News-Services-Handled
Apple-News-Services-Host
X-Thanos
X-TH-Server
Fastly-Drupal-Html
X-Sigma
X-Sigma-Backend
X-Sn-Servicetimems
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
X-Developers
X-Cdn-Srv
X-HN
X-NodeID
X-VarnishDD-TTL
X-Cache-Debug
True-Client-Country-4JS
Locid
PFcat
Ssr
Svr
X-Rocket-Build-Number
X-Thinkindot-L3
X-Node-Id
Release
Req-Svc-Chain
Fastly-GeoIP-CountryCode
Gh-Request-Id
X-Mvc-Supplant-Cachable
X-Level-Front-Cache
Mail-Subject
Machine
Server-Host
X-HS-Content-Campaign-Id
X-Req
X-Region-Sid
X-Datadog-Trace-Id
X-NWS-UUID-VERIFY
X-Request-URI
X-DefElseHash
X-Is-Gdpr
X-UnsetCookies
X-DefHash
X-RateLimit-Remaining-Second
X-Envoy-Decorator-Operation
X-RateLimit-Limit-Second
X-Pod-Name
X-Backend-State
X-Irp-Debug
X-DPWN-IS-SECURE
X-Platform
X-Variation
X-Has-Esi
X-Qloud-Router
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-Request-Start
X-Loc
X-NU-AKA-ACS-Version
X-Worker
X-Varnish-Remaining-TTL
X-Origin
X-JWT-State
X-GeoIP-City
Is-Eu
Fastly-SWR
Memcached
NGX
Platform
NM-Fastcgi-Cache
X-Cache-Config
Fastly-SIE
X-Amzn-Remapped-Content-Length
Adler-Geo
Cf-Device-Type
X-Xrds-Location
X-Magnolia-Registration
Datacenter
X-Cache-Enabled
X-CS
L5d-Success-Class
X-Csrf-Jwt
X-Eu-Site
HA-Ipaddr
Ha-Gx-Prefs
X-Tx-Id
X-Response-By
X-FC-Vary-Parameters
X-CGP
X-Ua-Device
X-Varnish-Beresp-Ttl
X-API-Version
X-Up
Candidate-Md5Url
X-Trace-ID
X-CLOUD-TRACE-CONTEXT
X-NC
X-Mvc-Supplant-OutputCached
X-Backend-TTL
CDN
X-Vc
Pics-Label
X-GeoIP-Region-Code
X-GeoIP-Country-Code
X-LB-ID
X-Esi
WWW-Authenticate
X-Tb-Optimization-Total-Bytes-Saved
Ms-Author-Via
Magicmarker
Time
Memory
On-Server
X-Datadome
Esi-Enabled
X-Generated-In
X-Via-Poph
X-LB-NoCache
X-Via-Popv
X-Via-Popn
X-DynaTrace-JS-Agent
S-Rt
X-TraceId
Env
X-URL
X-Refresh
X-Restarts
GeoIp-Country-Code
X-TA-CDN-Provider
WebServer
X-DC
X-Edge-Pop
Kp-EeAlive
NtCoent-Length
X-Optimistic-Header
X-Tt-Logid
X-Varnish-Ttl
X-Dynatrace
X-Service
X-Parent-Response-Time
C-Via
X-DI
X-DB
X-Wix-Viewer-Type
X-RSL
X-DSS
X-RPS
X-CacheTTL
X-RPM
Edge-Cache
X-Cache-Backend
X-Action
X-Cache-PHP
X-DW
X-Akamai-Request-ID2
X-Varnish-Beresp-TTL
X-Http-Reason
X-Servedbyhost
X-Srv
X-Unique-ID
X-Cache-Status-Check
X-MSEdge-Flight
X-Render-Time
X-Minions-Version
X-TX-ID
X-MSEdge-Features
Server-ID
X-Cs
X-HA-Backend
X-Newrelic-Synthetics
X-ZONE
Accept-Language
X-VCL-Version
Proxy-Connection
X-Info
X-App
X-AIR-PT
X-Li-Proto
X-Fpc
X-Cache-Ttl
X-Traceid
X-LI-Proto
Locale
X-Urbn-Context-Path
X-Urbn-Site-Id
X-Webkit-Csp-Report-Only
Test
X-User
X-Ec-Fail
X-Clientip
X-FPC
X-Ec-GeoHdr
X-LiteSpeed-Cache-Control
Server-Id
X-Oss-Server-Time
X-Oss-Request-Id
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
HIT
X-Oss-Storage-Class
X-B3-Spanid
Cache-Host
X-Vcl-Version
UCS
X-Webkit-CSP-Report-Only
X-NODE
Tcn
Geo-Info
S-Cnection
Cdncip
X-Pass-Why
X-CSRF-TOKEN
Cdnsip
M-TraceId
X-AK-Request-ID
Cf-Int-Pingora-Origin-Digest
X-WADP-Cache
X-HostName
Cluster
User-Agent
Hostname
X-LiteSpeed-Tag
Resin-Trace
My-App
X-Micro-Cache
Fastly-Drupal-HTML
Fastly-Backend-Name
X-Fmm-Version
X-Clara-WADP
Section-Origin-Responded
Section-Io-Origin-Time-Seconds
Section-Io-Id
Lb
Section-Io-Origin-Status
X-CUA
X-Pad
X-Backend-Host
X-Var-Ttl
Tracecode
X-ServedByHost
Geoip-Latitude
X-Ha-Backend
X-ID
X-Dynatrace-Js-Agent
Hit
X-APP
Ohc-File-Size
X-BCube-Filmed-By
X-BBC-Origin-Response-Status
T-Server
Lfy
X-Release
X-From
GeoIP-Country-Code
X-Geo
X-RAMCache
X-Fragments
MIME-Version
Lang
X-Via-PopN
X-Via-PopV
X-Edge-POP
X-Via-PopH
X-Cdn-Forward
ENV
X-ElasticPress-Query
X-Check-Cacheable
X-WA
X-HS-Status
X-WA-Info
X-Api-Version
CPC-Age
Load-Balancing
VNS-Cache
VNS-Age
Target-Params
X-WP-CF-Super-Cache-Cache-Control
Cache-Key
Path
X-Amz-Meta-Cb-Modifiedtime
X-Edge-Cache
X-WP-CF-Super-Cache
CPC-Cache
X-ES-SERVER
X-NGINX-Cache
EpKe-Alive
X-Ucs
X-ServerName
URI
X-Fastly-Backend-Reqs
Servername
DataCenter
Uri
X-UP
X-GoCache-CacheStatus
X-Cms-Context
X-Fastly-Cache-Hits
X-Wikidot-Backend
X-PJAX-URL
Pagetype
Shield-Pop
X-Wikidot-Static-Cache
X-Mcache
Cteonnt-Length
X-Dw-Trace-Id
X-TRACE-ID
Srv
X-RateLimit-Reset
X-Lb-Id
X-Swift-Error
X-Via-Ucdn
PICS-Label
X-CCDN-Origin-Time
WZWS-RAY
X-Proxy-Cache-Info
X-Akamai-Pragma-Client-IP
X-Hcs-Proxy-Type
X-Nc
X-CCDN-CacheTTL
Cneonction
MD5-Digest
FSS-Cache
Cdn
X-VC
Permissions-Policy
Ohc-Cache-HIT
X-B3-ParentSpanId
X-Cdn-Request-ID
X-Httpd
X-Lb-Nocache
Server-Ext
ServerName
IsBot
X-Apw-Access-Token
X-Apw-Access-Object
X-Acquia-Application-Trace
X-Akamai-ERRuleID
X-Akamai-ERPolicy
Server-Ttl
Server-Hostname
X-Acquia-Site
X-Apw-Access-Action
X-Acquia-Application-UUID
X-Acquia-Purge-Tags
X-Apw-Hits
CF-Cached-On
X-Udemy-Cache-App-Namespace
X-Yottaa-OS
X-VG-WebServer
Cf-Ipcountry
X-Snapshot-Date
X-Newrelic-App-Data
X-Cache-ASPX
X-Contensis-Viewer-Groups
X-SIPLIST1
Sever-Int
Vha6-Origin
Producers
Sid
X-Cache-Ngx
X-Air-Pt
X-Provided-By
X-Last-Modified
GeoIP-Latitude
X-SB
W
X-Logging-Id
X-CacheKey
X-Varnish-Authentication
X-Miniprofiler-Ids
X-Cache-Expires
X-B3-Parentspanid
X-UA
Req-ID
X-Http-Duration-Ms
X-Te-Count
X-Http-Count
Ngx
CountryCode
X-Sentry-ID
X-Te-Duration-Ms