Threat Level: green Handler on Duty: Russ McRee

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Accept-Ranges
Cf-Request-Id
CF-Cache-Status
Link
CF-RAY
ETag
Pragma
Expect-CT
X-XSS-Protection
X-Powered-By
Via
X-Cache
Age
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
Alt-Svc
X-UA-Compatible
P3P
X-Served-By
X-Xss-Protection
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
X-Runtime
X-AspNet-Version
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Cache-Status
X-Generator
P3p
X-Cacheable
X-Check
Timing-Allow-Origin
X-Request-ID
X-FRAME-OPTIONS
X-Iinfo
Feature-Policy
X-Content-Security-Policy
X-Envoy-Upstream-Service-Time
Content-Encoding
Status
X-CONTENT-TYPE-OPTIONS
X-CDN
X-Drupal-Dynamic-Cache
Access-Control-Expose-Headers
X-AspNetMvc-Version
Upgrade
X-Via
X-XSS-PROTECTION
CF-Ray
Access-Control-Max-Age
X-Ws-Request-Id
Server-Timing
X-Cache-Group
X-Turbo-Charged-By
X-Backend
Keep-Alive
Request-Context
EagleId
X-Age
X-Robots-Tag
X-Server
X-AH-Environment
X-UA-Device
Host-Header
X-Proxy-Cache
X-Amz-Request-Id
X-Amz-Id-2
X-Hacker
X-Dns-Prefetch-Control
X-Rq
Grace
X-Swift-SaveTime
X-Swift-CacheTime
X-Server-Powered-By
X-Varnish-Cache
X-Akamai-Path-Stats
Ali-Swift-Global-Savetime
X-Vhost
X-Amz-Version-Id
X-Ua-Compatible
CONTENT-SECURITY-POLICY
X-Dispatcher
X-LiteSpeed-Cache
EagleEye-TraceId
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-WebKit-CSP
X-Nginx-Cache-Status
Allow
X-Cache-Spec
X-Device
X-OneAgent-JS-Injection
Cf-Railgun
X-Page-Speed
X-Host
X-Node
X-Pingback
X-CST
X-Server-Id
X-Aws-Lambda-Call-Status
Surrogate-Control
Request-Id
Accept-CH
X-Backend-Server
X-Akam-SW-Version
X-Readtime
X-Cache-Lookup
X-HW
X-Response-Time
Cf-Edge-Cache
X-Application-Context
Xkey
Content-Location
X-ASPNET-VERSION
Accept-CH-Lifetime
Rating
X-Cloud-Trace-Context
X-Trace
X-Url
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Country
Fastly-Restarts
Accept-Ch-Lifetime
X-Mod-Pagespeed
X-MS-InvokeApp
X-Rack-Cache
X-TtlSet
X-Vname
X-PC
X-Server-Name
X-Ruxit-JS-Agent
X-Clacks-Overhead
RTSS
Edge-Control
X-Varnish-TTL
X-ESI
X-VARITI-CCR
X-Content-Type
X-B3-TraceId
Cache-Tag
X-Vcap-Request-Id
X-Cdn-Fetch
X-Exp-Id
X-Kinja
X-Amz-Rid
X-Kinja-Build
X-Exp-Variant
X-Use-Magma
X-Kinja-Server
X-GoogleNews-Bot
X-Kinja-Revision
X-Amz-Server-Side-Encryption
Public-Key-Pins
X-Dw-Request-Base-Id
X-Cnection
X-Ac
X-Px
X-RateLimit-Remaining
Accept-Ch
X-Element-Page-Cache
X-D2id
Verso
X-Navigation-Version
X-Abt-Application-Version
X-Client-IP
X-Powered-By-Plesk
X-Cache-TTL
X-Sol
Pagespeed
Display
X-Middleton-Display
X-Ser
X-Ruxit-Js-Agent
Service-Worker-Allowed
X-Edge
X-Litespeed-Cache
X-FastCGI-Cache
X-Version
Arr-Disable-Session-Affinity
X-GitHub-Request-Id
X-Country-Code
Response
X-Middleton-Response
X-NF-Request-ID
Access-Control-Request-Method
X-Ttl
X-Goog-Hash
X-Correlation-Id
X-Webkit-Csp
X-Kinsta-Cache
AR-ATIME
AR-CACHE
AR-PoweredBy
AR-SID
AR-Request-ID
SPIisLatency
X-Edge-Location-Klb
SPRequestDuration
X-Upstream
X-NWS-LOG-UUID
X-RateLimit-Limit
X-LLID
X-Cached
X-Cache-Key
X-Powered-CMS
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-Instrumentation
Edge-Cache-Tag
Nginx-Cache
X-SharePointHealthScore
X-TTL
SPRequestGuid
TCN
X-Forwarded-For
MRF-Tech
Mrf-Cache-Status
X-MSEdge-Ref
Content-MD5
X-Id
X-Shield-Request-Id
MS-Author-Via
X-Daa-Tunnel
X-Content-Security-Policy-Report-Only
X-T
X-B3-TraceId-Primal
X-Recruiting
S
X-Content-Digest
X-Mg-S
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
X-Ua-Device
X-Protected-By
X-DataDome
X-HP-Trace-Id
X-Jurisdiction
X-HP-Webp
X-SRCache-Store-Status
X-Frontend
X-Ezoic-Cdn
X-SRCache-Fetch-Status
MicrosoftSharePointTeamServices
X-HS-Hub-Id
X-Accel-Expires
X-HS-Content-Id
X-HS-Combine-CSS
X-HS-Cache-Config
Server-Node
X-Ua-Browser
X-Content
X-Ab
X-Grace
X-Request-Received
Front-End-Https
X-Request-Processing-Time
X-Yandex-Sdch-Disable
Filters
X-Server-ID
X-ECACHE
Fastcgi-Cache
X-Mid
X-Hits
X-Origin-Server
TP-L2-Cache
TP-Cache
X-DynaTrace
X-Distributor
X-Geo-Country
X-PressLabs-Stats
X-ORACLE-DMS-ECID
X-Debug-Info
X-ORACLE-DMS-RID
X-Ratelimit-Reset
X-Amzn-Trace-Id
X-Tt-Trace-Tag
Charset
X-Pinterest-Rid
Pinterest-Generated-By
X-Tt-Trace-Host
Pinterest-Version
Cleartype
Host
X-F-Cache
X-DIS-Request-ID
X-Git-Hash
X-Request-Handler-Origin-Region
Cross-Origin-Opener-Policy
X-Microsite
X-B3-Sampled
X-Page-Id
X-Www-Served-By
X-LB-Cache
Access-Control-Allow-Method
X-Forwarded-Proto
X-Cache-Age
ServerID
X-Seen-By
Cache-Tags
X-Activity-Id
X-Az
X-AppVersion
X-MCACHE
X-Aspnetmvc-Version
Cache-Status
X-Cluster-Name
Accept-Charset
X-Oracle-Dms-Ecid
X-Varnish-Age
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
Realpath
X-Oracle-Dms-Rid
X-Language
X-WebKit-CSP-Report-Only
Filterid
Server-Name
X-Content-Options
X-Rid
X-Type
X-App-Environment
X-Nginx-Upstream-Cache-Status
X-Upgrade-Enabled
X-Fastly-Request-ID
X-Varnish-Grace
Viewport
Country
X-Mobile-URL
Node
X-Tb
X-Oneagent-Js-Injection
X-NWS-UUID-VERIFY
X-Origin-Cache
X-Is-Crawler
X-Providence-Cookie
X-Flags
Paypal-Debug-Id
X-Drupal-Cache-Tags
X-Signature
X-Aspnet-Duration-Ms
Retry-After
X-Whom
X-Request-Guid
X-Route-Name
X-B-Cache
X-User-Agent
DC
X-Wix-Request-Id
X-TT
Protected
X-FB-Debug
X-Varnish-Backend
X-GUploader-UploadID
X-VCache
X-Goog-Metageneration
X-Goog-Storage-Class
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Via-JSL
Fastcgi-Useragent
X-XRDS-LOCATION
X-Cache-NGX
X-B
X-Fastcgi-Cache
X-Amz-Replication-Status
X-Debug
Payment
X-Contextid
X-N
X-XRDS-Location
X-Logged-In
X-Load-Cache
WPO-Cache-Status
WPO-Cache-Message
X-Template
Surrogate-Key
X-FW-Static
X-FW-Hash
X-FW-Dynamic
X-FW-Serve
Amp-Access-Control-Allow-Source-Origin
X-Fastly-Request-Id
X-FW-Server
X-FW-Type
X-Cache-Control
X-Amz-Meta-S3cmd-Attrs
Count-Hit
X-Hostname
X-Node-Name
X-Erf-Bev-Bev
X-Browser-Type
X-Erf-Bev-Bev-Is-Generated
Healthy
X-Response-Served-From
X-Original-Request-Id
SD-X-WS
X-Mcache
Akamai-GRN
Content-Disposition
Refresh
X-Proxy
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Akamai-Request-ID2
X-Is-Bot
X-Rendered-As
X-UUID
X-Cache-Time
X-Revision
Uber-Trace-Id
X-Zen-Fury
X-G
X-Jobs
X-Adobe-Loc
X-Adobe-Content
X-Http-Reason
X-Page-View
X-Mobile
X-Cache-TTL-Remaining
X-Cacheable-TTL
X-Real-IP
Alternate-Protocol
X-Debug-IsConnected
X-Yottaa-Optimizations
X-Framework
X-Instance
X-Trace-Id
Permissions-Policy
X-Proxy-Cache-Status
X-Drupal-Cache-Contexts
X-Yottaa-Metrics
NGB
X-Debug-IsPreview
X-Device-Type
Access-Control-Request-Headers
X-IPLB-Instance
Url
X-Source
X-Servername
X-ECache
X-Cache-Grace
From-Origin
X-Parallel-Accel
X-B3-Traceid
X-Cache-Rule
Version
X-Vgn-Hpd-Reason
X-Varnish-Server
Accept-Language
X-Mg-Request-UUID
X-Cache-Hit
X-L-Path
X-Environment-Context
X-Restarts
X-Cache-Expired-At
X-NGENIX-Cache
X-EdgeConnect-Cache-Status
Referer-Policy
X-RTag
MS-CV
Ms-Operation-Id
X-App-Server
Countrycode
Cross-Origin-Window-Policy
X-FW-Version
X-HTML-Minification-Powered-By
X-APP-VERSION
Liferay-Portal
X-Tumblr-Pixel
X-Tumblr-User
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-IPS-LoggedIn
Frame-Options
X-NYM-Debug-Backend
X-COUNTRY
Backend
X-Cache-Action
X-Nginx-Cache
X-RemovedCookies
Content-Secure-Policy
X-Datadome
X-ProcessESI
WP-Super-Cache
CF-IPCountry
X-OCL
X-PCL
Section-Io-Cache
X-Redis-Cache
Meta-Geo
X-UPSTREAM-Address
X-Cache-Server
Upgrade-Insecure-Requests
X-RN-RSRV
Apigw-Requestid
X-Detected-As
X-Generation-Time
X-Cluster-Node
X-Content-Age
X-Access
X-Format
Fastly-SSL
Ec-Rule-Version
X-Cache-Enabled
X-FB-TRIP-ID
Cache-Tv-Group
X-Hyper-Cache
X-Section
X-No-Session
X-Ua
X-Via-Fastly
X-Uri
X-Ratelimit-Remaining
TWC-GeoIP-LatLong
S-Rt
X-Urbn-Site-Id
X-Urbn-Context-Path
X-Sql-Duration-Ms
X-Request-Time
Property-Id
TWC-Connection-Speed
TWC-Device-Class
Azure-InstanceId
Azure-Version
X-Varnish-Cache-Hits
X-UA-Device-Type
Webserver
X-Storage
X-AOL-HN
X-Web-Node
X-SayCDN-TTL
Azure-RegionName
TWC-Locale-Group
Azure-SiteName
Locale
Azure-SlotName
Mn-Server-Ip
TWC-GeoIP-Country
X-Hosted-By
TWC-Privacy
X-Be
X-Say-TTL
X-Server-W
X-Region
X-Origin-Date
X-Human
X-PHP-Backend
X-Origin-Hint
X-Say-Cacheable
X-PERF
X-ApacheServer
X-Site-Version
X-Sql-Count
Webcakes-Region
Webcakes-App-Version
X-Akamai-Edgescape
X-Mode
X-Generated-By
Webcakes-App-Name
X-BYPASS-REASON
CDN-RequestId
X-Forwarded-Host
CDN-Uid
Eomportal-Instance
X-ProxyCache-Key
X-Unique-Id
X-Nginx-Cache-Key
X-Adobe-Source
X-Status
X-Cache-Host
X-Xfnlog-Site
X-Debug-Cache
X-Platform-Server
X-ProxyCache-Status
X-Cache-Tags
CDN-PullZone
CDN-RequestCountryCode
CDN-EdgeStorageId
CDN-Cache
X-Webkit-CSP
CDN-CachedAt
X-Routing-Service
X-SaId
X-ServerID
X-Proxied
X-JoinUs
X-Handled-By
X-ShardId
X-Extlb
X-Shopify-Stage
X-Zipkin-Id
X-Cache-Type
X-Content-Powered-By
X-Varnishpool
X-Tid
X-Alternate-Cache-Key
X-ShopId
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Backend-Name
X-Hl-Ver
X-Proxy-Build
X-Locale
ServedBy
X-PHP-Host
X-Rule
X-GG-Cache-Date
X-Timing-Wait
X-TT-LOGID
X-Labrador-Cache-Channel
X-NewRelic-App-Data
Selected-Fe
X-AWS-Id
X-VWS-Id
X-LJ-Flow-ID
X-Accel-Buffering
X-VC-Cache
X-Cache-Operation
X-Cache-Remote
X-Midtier
X-Rewrite-Enabled
X-LSADC-Cache
X-CDN-Forward
Xserver
X-Edge-Location
X-Cached-By
SID
X-Proto
X-Pubstack
X-Dc
X-Cms-Context
SRV
X-Soup
Web-Mar-Node
X-TA-CDN-Provider
X-Storefront-Renderer-Rendered
Mime-Version
Fastly-Drupal-Html
X-Reqid
X-GEO
Onion-Location
X-Buckets
Country-Code
X-GeoCode
Decoy-Debug-TTL
X-Varnish-Hostname
Decoy-Debug-Status
Decoy-Debug-Key
X-GeoCountry
X-Request-Host
LB
Load-Balancing
X-Microcachable
Cache-Hits
X-Origin-CC
X-Ratelimit-Limit
X-Origin-TTL
Server-Info
X-Cluster
X-App-Version
Xet-Cookie
X-Ms-Version
X-MP-GENERATED-AT
X-Tumblr-Pixel-2
X-Tumblr-Pixel-3
X-Ms-Request-Id
X-Varnish-Hits
X-Envoy-Decorator-Operation
X-SRV
X-NCache
X-Air-Hostname
DynaTrace
X-Amz-Apigw-Id
X-CSRF-Token
X-Air-Source
X-Amzn-RequestId
X-B3-SpanId
X-Air-Trace-Id
X-Magnolia-Registration
X-Bc-Bl
X-Endurance-Cache-Level
X-RCS-CacheZone
X-Tx-Id
Pramga
DCR-Decision-By
Fastcgi-X-Cache-Version
DCR-Processing-Time-Ms
DB-Nickname
Expiry
Meta-Geo-Continent
Lang
Host-ID
Cmstype
Cmsid
Odigeo-Trace-Id
BehaviorPad-Version
X-Varnish-Beresp-Grace
NM-Fastcgi-Cache
Cdncip
Mobile-Detection-Method
Cdnsip
A
X-Hash
X-Origin-Response-Time
X-Orig-Expires
X-NodeID
X-PAYTM-SRV-ID
X-PBS-Appsvrname
X-Rojux
X-Processor
X-NAPM-TraceId
X-LAGOON
X-Time
X-Ftr-Request-Id
X-Geo-Header
X-Gzip
X-Ig-Push-State
X-HS-Content-Campaign-Id
X-S
X-S-Cookie
X-VG-WebCache
X-Vdms-Version
X-Vdms-Path
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
Xc-Version
X-Webstats-RespID
X-User
X-TIM-N
X-SD-PageType
X-ScT
X-Session-Fingerprint
X-Shop-Environment
X-Tenant
X-SRCache-Key
X-From
X-Forwarded-Path
X-Aed
X-A-Wwc
X-A-Dgt
Cache-Name
X-AK-Request-ID
X-ARC
X-Application
X-A-Dcw
X-A-Dam
Surrogated-Key
Sslversion
T-Server
X-R9-Blue-Green-Version
X-A-Ccd
X-A
X-B-Cookie
X-Cache-Bucket
X-Ec-Fail
X-Developer
X-Destination
X-Ec-GeoHdr
X-Epic-Correlation-Id
X-External-Request-Id
X-Esi-Check
X-D
X-Connection-Hash
X-Cache-NE
X-Cache-Id
X-Cdn-Srv
X-CF-Lambda-Fn
X-Conf
X-CF-Lambda-Version
Rendered-Blocks
X-ZONE
X-Azure-Ref
X-Varnish-Ttl
X-Gdpr
X-Gen-Mode
X-GeoIP
X-Fmm-Version
X-Fastly-Cache
X-Developers
X-DPWN-IS-SECURE
X-Has-Esi
X-Hnp-Log
X-Mvc-Supplant-Cachable
X-Nyt-Route
X-Origin
X-Loop
X-JWT-State
X-Irp-Debug
X-Is-Gdpr
X-DefHash
X-DefElseHash
Web-Mar-Region
Wxu-Next-Commit
Wxu-Next-Hostname
We-Hiring
Vix-Hermes-Req-Id
User-Cache-Control
V-Age
Wxu-Next-Region
State
X-Clara-WADP
X-Core-Value
X-Origin-Expires
X-Ckpd-Fst-Backend
X-Cache-Backend
X-Amzn-Remapped-Content-Length
X-Block-Status
Svr
X-Planisys-CDN-Cache
MD5-Digest
X-Cache-Info
X-Core-Mission
Fastly-GeoIP-CountryCode
X-Worker
X-Viewer-Country
X-WADP-Cache
X-Wix-Viewer-Type
X-Device-Os
X-Ec-Custom-Error
X-Sigma-Backend
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-Sigma
X-Rocket-Build-Number
X-Fetched-On
X-Node-Id
X-VG-TLSProxy
X-Varnish-Remaining-TTL
X-RateLimit-Remaining-Second
X-Request-URI
X-SB
X-RateLimit-Limit-Second
X-Planisys-CDN-TTL
Server-Host
X-Planisys-CDN-Rules
X-Scheme
X-Server-IP
X-Variation
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-V-Cache
X-TrackingId
X-Slack-Backend
X-TNCMS
X-Origin-Time
X-Location
Cache
CDN
Source
Environment
Memcached
Adler-Geo
AKAMAI
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
Apple-News-Services-Handled
Platform
Mail-Subject
Machine
Producers
Is-Eu
X-Rebelmouse-Cache-Control
X-Region-Sid
HA-Ipaddr
X-Generated-On
Cluster
X-Response-By
L5d-Success-Class
X-Forwarded-Site
X-Gamma-Serve
Ha-Gx-Prefs
X-Qloud-Router
X-Men
X-Minions-Version
X-Level-Front-Cache
Fastly-SIE
Fastly-SWR
CDCHOST
X-HN
X-Proxy-Cache-Info
X-Proxy-Upstream
X-Pod-Name
X-GeoIP-City
Fastcgi-Cache-TTL
X-Httpd
X-VarnishDD-TTL
X-CacheTTL
X-Dispatcher-Number
X-Cache-Date
X-BBC-Edge-Cache-Status
Thinkindot-Control
Traceparent
X-Loc
X-Pool
X-Thinkindot-L3
X-VServer
X-Skip-Cache
X-Served-From
X-Rocket-Nginx-Serving-Static
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
Kp-EeAlive
L
CloudFront-Viewer-Country
X-Via-NSCOPI
Arc-Country
X-Eu-Site
Origin
Origin-CC
Ssr
TDXMobile
Req-Svc-Chain
Release
Origin-EX
X-Sn-Servicetimems
X-Rebelmouse-Surrogate-Control
Redirect-Candidate
X-Csrf-Jwt
X-Cdn-Origin
X-Aicache-OS
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
X-CGP
X-Datadog-Parent-Id
X-Auto-Login
N-Cache
Locid
X-Branch-Name
PFcat
X-Tec-Api-Version
X-Tec-Api-Root
X-Tec-Api-Origin
Server-Ext
Server-Hostname
Sever-Int
Gh-Request-Id
X-Optimistic-Header
X-Via-Ucdn
X-Parent-Response-Time
X-Old-Content-Length
NGX
DSUID
X-Policy
X-Scale
IsBot
X-SIPLIST1
X-Platform
HostName
X-Refresh
Pics-Label
X-WP-CF-Super-Cache-Cache-Control
X-IPLB-Request-ID
X-RSL
X-RPM
X-Owner
X-RPS
X-WP-CF-Super-Cache
X-NC
X-DI
X-DB
X-CS
X-EC-Lua
X-Srv
X-DSS
X-DW
X-TraceId
Ohc-File-Size
Env
X-Date
X-Newrelic-Synthetics
X-Tt-Logid
Memory
X-Accel-Expires-Debug
X-Tb-Optimization-Total-Bytes-Saved
X-Ah-Environment
X-LB-NoCache
Time
Servername
X-TIME
X-VC
Ms-Author-Via
X-Mvc-Supplant-OutputCached
AMP-Access-Control-Allow-Source-Origin
X-BCube-Filmed-By
X-Ad-Defer-Variation
X-Wikidot-Backend
X-Amz-Meta-Cb-Modifiedtime
Candidate-Md5Url
Datacenter
X-Generated-In
Cache-Key
X-Wikidot-Static-Cache
X-GeoIP-Country-Code
X-GeoIP-Region-Code
X-Akamai-Transformed
X-Udemy-Cache-App-Namespace
VNS-Age
GEO-INFO
VNS-Cache
X-Cache-Debug
X-Edge-Pop
CPC-Cache
CPC-Age
X-SplitTest
XM
X-Cache-ASPX
X-Contensis-Viewer-Groups
Geo-Info
X-Xrds-Location
X-Via-Popn
X-Varnish-Authentication
X-Via-Poph
ITXSESSIONID
GeoIp-Country-Code
Fastly-Backend-Name
X-API-Version
X-Via-Popv
X-WA-Info
X-Servedbyhost
Fusion-Template-Id
Fusion-Deployment-Id
Fusion-Component-Id
X-Cache-Status-Check
Fusion-Source
Fusion-Content-Source
Fusion-Content-Id
X-HA-Backend
X-Presslabs-Stats
Path
X-Micro-Cache
X-S-Maxage
CacheControlHeader
X-Vc
X-RateLimit-Reset
X-Trace-ID
X-CACHE-KEY
X-AIR-PT
X-DC
Client
X-VCL-Version
X-TH-Server
X-Action
True-Client-Country-4JS
X-Backend-TTL
Cache-Host
Lb
Geoip-Latitude
Ohc-Cache-HIT
Server-ID
X-Cs
X-VHOST
Hostname
FSS-Cache
True-Client-IP
Ngx.Var.Host
Edge-Cache
X-Varnish-Beresp-TTL
X-Req
X-Api-Version
X-Proxy-CacheRZ
XkeyRZ
My-App
X-Clientip
X-Fpc
X-Provided-By
X-Webkit-Csp-Report-Only
X-FireWall-Port
Powered-By
X-Pass-Why
NtCoent-Length
X-TX-ID
X-Origin-Upstream-Status
X-Zone
X-B3-Spanid
X-PX
X-Up
X-Traceid
X-Varnish-Beresp-Ttl
X-CSRF-TOKEN
X-FPC
X-LB-ID
Test
X-NGINX-Cache
DataCenter
Cf-Int-Pingora-Origin-Digest
X-MSEdge-Features
X-Cdn-Request-ID
X-Dynatrace
X-Dmc
X-MSEdge-Flight
X-Correlation-ID
X-Webkit-CSP-Report-Only
X-INCAP-ABP
X-HS-Status
X-Beluga-Trace
X-Li-Fabric
X-Li-Pop
X-LI-UUID
X-Beluga-Status
X-Beluga-Record
X-Beluga-Node
X-Beluga-Cache-Status
User-Agent
X-Beluga-Response-Time
X-UnsetCookies
X-Render-Time
OT-Force-Account-Verify
Proxy-Connection
Server-Id
C-Via
Rip
X-ND-Cache
X-Vcl-Version
WZWS-RAY
X-CLOUD-TRACE-CONTEXT
X-Check-Cacheable
X-Time-Microsecs
X-Via-PopN
X-Service
X-Gateway-Skip-Cache
X-Alfa-Service
Tube-Get-Contents
GeoIP-Latitude
X-Gateway-Cache-Status
X-Gateway-Cache-Key
Tube-Got-Results
Click-Count-Error
Click-Count-Action-Start
X-Via-PopV
X-URL
Tube-Return
X-Via-PopH
X-Ha-Backend
Srvid
X-B3-Traceid-Primal
X-Gateway-Request-Id
X-CUA
X-RAMCache
Tube-Got-Eval
X-Geo
Cf-Device-Type
GeoIP-Country-Code
Tracecode
X-ServedByHost
Uri
Esi-Enabled
X-Fragments
X-Platform-Cluster
Sid
X-Platform-Processor
X-Platform-Router
Target-Params
X-Akamai-Pragma-Client-IP
MIME-Version
X-Proxy-Cache-Hk
X-CCDN-CacheTTL
X-CCDN-Origin-Time
X-Hcs-Proxy-Type
Epwk-X-Cache
X-M-Log
X-Qnm-Cache
On-Server
X-M-Reqid
HIT
X-Azure-Ref-OriginShield
X-Sucuri-ID
X-Var-Ttl
X-ATG-Version
X-Sucuri-Cache
X-FC-Vary-Parameters
Srv
Lfy
X-Fastly-Backend
X-DynaTrace-JS-Agent
Resin-Trace
X-Fastly-Backend-Reqs
X-LI-Proto
X-Fetch-By
X-LiteSpeed-Cache-Control
Fastly-Drupal-HTML
X-TRACE-ID
ENV
X-Backend-Host
X-Cdn-Forward
X-Esi
Cdn
XServer
Section-Io-Id
Section-Io-Origin-Status
X-NU-AKA-ACS-Version
X-App
X-Backend-State
Magicmarker
X-Li-Proto
X-Cache-Expires
X-Edge-POP
Section-Io-Origin-Time-Seconds
X-Varnish-Beresp-Status
X-APP
Section-Origin-Responded
X-Srcache-Store-Status
X-MG-S
X-Srcache-Fetch-Status
ServerName
PICS-Label
X-ElasticPress-Query
X-Newrelic-App-Data
Tcn
X-Lb-Nocache
CountryCode
Inserted-Into-Cache-At
CF-Cached-On
X-Yottaa-OS
X-Iplb-Request-Id
Wpo-Cache-Message
X-Acquia-Application-Trace
X-Acquia-Site
X-Vcache
D-Url-Rewrites
Wpo-Cache-Status
X-Iplb-Instance
X-Acquia-Application-UUID
Server-Ttl
X-Cache-CFC
X-Nc
Cf-Ipcountry
X-Serial
X-Request-Start
X-Acquia-Purge-Tags
X-HostName
Servedby
Warning
X-Fastly-Cache-Hits
Fastcgi-Cache-Ttl
Hit
X-Vercel-Cache
X-Wp-Cf-Super-Cache
X-Vercel-Id
X-Wp-Cf-Super-Cache-Cache-Control
X-Th-Server
X-Release
X-Thanos
X-Swift-Error
X-Request-Url
X-BBC-Origin-Response-Status
X-B3-Parentspanid
X-Litespeed-Cache-Control
X-IN-APIGATEWAYSSL
X-Dist-Code
X-IN-APIGATEWAY
X-Shopify-Generated-Cart-Token
X-LiteSpeed-Tag
X-Back
X-Snapshot-Date
X-Storefront-Renderer-Verified
X-CF-Powered-By
Content-Style-Type
Content-Script-Type
Cneonction
Ngx
X-Bip
X-Dw-Trace-Id
X-Request-URL