Threat Level: green Handler on Duty: Russ McRee

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
X-Powered-By
Pragma
X-XSS-Protection
X-Cache
CF-RAY
Via
Age
Content-Security-Policy
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
Alt-Svc
P3P
X-Cache-Hits
X-UA-Compatible
X-Xss-Protection
CF-Ray
X-Served-By
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
Access-Control-Allow-Credentials
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
X-Drupal-Cache
X-Generator
X-Cache-Status
X-Check
X-Cacheable
X-DNS-Prefetch-Control
X-FRAME-OPTIONS
X-Envoy-Upstream-Service-Time
Timing-Allow-Origin
X-Iinfo
X-Drupal-Dynamic-Cache
Feature-Policy
X-Content-Security-Policy
X-Dns-Prefetch-Control
Content-Encoding
X-XSS-PROTECTION
Access-Control-Expose-Headers
Server-Timing
Upgrade
X-CDN
Status
X-Request-ID
X-AspNetMvc-Version
Access-Control-Max-Age
X-Amz-Request-Id
Request-Context
X-Amz-Id-2
X-Via
X-Turbo-Charged-By
X-AH-Environment
X-Backend
X-Cache-Group
X-Robots-Tag
Cf-Edge-Cache
Host-Header
Keep-Alive
X-Hacker
X-Proxy-Cache
X-UA-Device
X-Server
X-Rq
X-Vhost
X-Server-Powered-By
Allow
X-Age
X-Varnish-Cache
X-Ws-Request-Id
X-Dispatcher
X-Amz-Version-Id
EagleId
P3p
Nel
Grace
Cf-Apo-Via
X-LiteSpeed-Cache
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Page-Speed
Cf-Railgun
X-Device
EagleEye-TraceId
X-Aws-Lambda-Call-Status
X-Swift-SaveTime
X-OneAgent-JS-Injection
X-Swift-CacheTime
X-Pingback
Ali-Swift-Global-Savetime
X-Node
Accept-CH
X-Host
X-WebKit-CSP
X-CST
X-Backend-Server
Surrogate-Control
X-Server-Id
X-Cache-Lookup
X-Nginx-Cache-Status
X-Readtime
Accept-CH-Lifetime
Permissions-Policy
X-Akam-SW-Version
X-Nginx-Upstream-Cache-Status
Request-Id
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Application-Context
X-Content-Security-Policy-Report-Only
X-Cloud-Trace-Context
X-Ua-Compatible
X-Trace
X-Response-Time
X-HW
X-Edge
Content-Location
X-Clacks-Overhead
X-Mod-Pagespeed
Xkey
X-Litespeed-Cache
X-Midtier
Rating
X-ESI
X-Ruxit-JS-Agent
X-Url
X-Amz-Server-Side-Encryption
X-ECACHE
X-Mcache
X-Upstream
X-Ruxit-Js-Agent
Accept-Ch
X-Vcap-Request-Id
Cache-Tag
X-D2id
X-MS-InvokeApp
X-Element-Page-Cache
X-Exp-Id
X-Cdn-Fetch
X-Kinja-Revision
Verso
X-Exp-Variant
X-Use-Magma
X-GoogleNews-Bot
X-Kinja-Build
X-Kinja-Server
X-Kinja
X-Rack-Cache
X-Powered-By-Plesk
X-Vname
X-TtlSet
X-PC
Accept-Ch-Lifetime
Edge-Control
X-WebKit-CSP-Report-Only
RTSS
X-Country
Fastly-Restarts
X-Cache-TTL
X-Oneagent-Js-Injection
X-Ac
X-VARITI-CCR
Origin-Trial
X-Navigation-Version
X-Country-Code
X-Abt-Application-Version
Service-Worker-Allowed
X-Goog-Hash
X-Cached
X-Ttl
X-Varnish-TTL
Display
X-Middleton-Display
Pagespeed
X-Sol
X-Amz-Rid
X-Browser-Type
X-GitHub-Request-Id
Cross-Origin-Opener-Policy
X-Dw-Request-Base-Id
SPRequestGuid
X-SharePointHealthScore
X-Server-Name
X-Content-Type
X-Mg-S
X-B3-TraceId
X-Amzn-Trace-Id
X-Powered-CMS
Response
X-Middleton-Response
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Server-Lifecycle-Phase
X-Instrumentation
X-Kraken-Loop-Name
Arr-Disable-Session-Affinity
AR-PoweredBy
AR-SID
AR-Request-ID
AR-ATIME
X-Kinja-CCPA
X-NF-Request-ID
SPIisLatency
SPRequestDuration
X-Cache-Key
X-Webkit-CSP
X-Times
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-Version
X-NWS-LOG-UUID
Pinterest-Version
AR-CACHE
X-Pinterest-Rid
Pinterest-Generated-By
X-Jurisdiction
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-HP-Webp
X-HP-Trace-Id
X-Accel-Expires
X-T
Cache-Tags
X-Cnection
Cache-Status
X-Aspnetmvc-Version
X-Fastly-Request-ID
Front-End-Https
X-RateLimit-Remaining
X-FastCGI-Cache
Nginx-Cache
X-MSEdge-Ref
Edge-Cache-Tag
X-Hits
X-B3-Traceid
X-Px
X-Client-IP
X-Ser
X-RateLimit-Limit
Mrf-Cache-Status
MRF-Tech
X-B3-TraceId-Primal
Public-Key-Pins
Payment
X-Recruiting
X-LLID
X-Request-Processing-Time
X-Request-Received
X-Frontend
Server-Node
X-Ua-Browser
X-Server-ID
X-Erf-Stays-Pdp-Viaduct-Migration-Web
X-Shield-Request-Id
X-DIS-Request-ID
S
TP-Cache
X-Fastcgi-Cache
X-GUploader-UploadID
X-Goog-Metageneration
Access-Control-Request-Method
MicrosoftSharePointTeamServices
X-HS-Cache-Config
X-HS-Content-Id
X-HS-Hub-Id
X-HS-Combine-CSS
X-Amz-Apigw-Id
X-Amzn-RequestId
Content-MD5
X-Content-Digest
X-Distributor
X-Microsite
X-Request-Handler-Origin-Region
X-Protected-By
X-LB-Cache
Access-Control-Allow-Method
X-Page-Id
TP-L2-Cache
Realpath
X-FB-Debug
Fastcgi-Cache
Accept-Charset
X-Ezoic-Cdn
X-Cluster-Name
X-Geo-Country
X-Forwarded-For
X-Rid
X-PressLabs-Stats
X-Hostname
X-Webkit-Csp
X-B3-Sampled
X-Aspnet-Version
X-Ua-Device
X-Correlation-Id
X-Seen-By
Cleartype
Referer-Policy
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-Goog-Storage-Class
X-Mobile
Cross-Origin-Resource-Policy
X-Envoy-Decorator-Operation
DC
X-Daa-Tunnel
TCN
X-Ratelimit-Remaining
X-Content-Options
Count-Hit
X-Debug-Info
X-Newrelic-App-Data
X-TTL
X-Varnish-Backend
X-COUNTRY
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-Logged-In
X-Origin-Cache
X-App-Server
X-Contextid
X-XRDS-Location
X-Varnish-Grace
X-Route-Name
X-Aspnet-Duration-Ms
X-Revision
X-Amz-Replication-Status
X-Is-Crawler
Surrogate-Key
X-Hosted-By
X-Fb-Rlafr
X-App-Environment
X-Request-Guid
X-Grace
X-Git-Hash
X-IPS-LoggedIn
X-Flags
X-Providence-Cookie
X-Azure-Ref
X-TT
Frame-Options
X-Client-Ip
X-Amz-Meta-S3cmd-Attrs
X-Ratelimit-Limit
X-Origin-Server
X-Edge-Location-Klb
X-Kinsta-Cache
X-Forwarded-Proto
X-RateLimit-Reset
Retry-After
Alternate-Protocol
X-Wix-Request-Id
WPO-Cache-Status
WPO-Cache-Message
X-Whom
X-F-Cache
Healthy
Charset
X-Akamai-Edgescape
X-Magnolia-Registration
Section-Io-Cache
Viewport
X-Backend-Name
MS-Author-Via
Paypal-Debug-Id
X-Proxy-Cache-Info
X-App-Version
X-B
X-Id
ServerID
SRV
X-Webkit-CSP-Report-Only
X-AppVersion
X-Az
X-Activity-Id
Amp-Access-Control-Allow-Source-Origin
X-Language
VIX-Pulpo-Node
SD-X-WS
VIX-Pulpo-Upstream-Status
X-Cache-Rule
X-ARC
Akamai-GRN
X-Original-Request-Id
X-N
Host
X-Instance
X-Response-Served-From
X-Rule
X-Http-Reason
X-Cache-Grace
Protected
X-UUID
X-Varnish-Age
X-Rocket-Nginx-Serving-Static
X-Status
X-Akamai-Request-ID2
X-User-Agent
Filterid
X-Edge-Location
Front
X-Www-Served-By
X-DataDome
X-Varnish-Server
Fastly-SIE
X-Unique-Id
From-Origin
Fastly-SWR
X-Environment-Context
X-Jobs
X-Is-Bot
X-L-Path
X-Page-View
X-Rendered-As
X-Region
X-FW-Version
X-FW-Type
X-FW-Dynamic
X-Framework
X-FW-Hash
X-FW-Serve
X-FW-Static
X-FW-Server
X-Cacheable-TTL
X-Load-Cache
Country
X-Kong-Proxy-Latency
Access-Control-Request-Headers
X-Type
X-Kong-Upstream-Latency
X-Adobe-Loc
X-EdgeConnect-Cache-Status
X-Cache-Time
X-Datadog-Trace-Id
X-Adobe-Content
Server-Name
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
X-Tumblr-Pixel-1
X-G
X-Tumblr-User
X-RemovedCookies
X-ProcessESI
X-Tumblr-Pixel-0
X-Trace-Id
X-Tumblr-Pixel
X-Cache-Control
X-Proxy
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Vcache
Refresh
X-Datadog-Sampled
X-Mg-Request-UUID
X-ECache
X-CDN-Forward
X-Amzn-Remapped-Content-Length
X-Time
X-Debug-IsPreview
X-Debug-IsConnected
X-Cache-Age
X-Source
X-Oracle-Dms-Ecid
X-Drupal-Cache-Tags
X-B-Cache
X-Signature
Content-Disposition
X-Oracle-Dms-Rid
X-Erf-Web-Scheduler
Xet-Cookie
Backend
X-WP-CF-Super-Cache-Cache-Control
Accept-Language
X-WP-CF-Super-Cache
X-Generated-By
Countrycode
Version
X-HTML-Minification-Powered-By
X-DynaTrace
Webserver
X-Xrds-Location
CF-IPCountry
X-DynaTrace-JS-Agent
X-Servername
X-Tec-Api-Root
X-Tec-Api-Origin
X-Httpd
X-Tec-Api-Version
Url
X-Mode
X-Tt-Trace-Tag
X-Tt-Trace-Host
Xserver
X-Template
GEO-INFO
X-Upgrade-Enabled
X-ID
X-Content-Age
X-NYM-Debug-Backend
X-Nginx-Cache
X-Storage
X-Device-Type
X-GeoCountry
X-Tb
X-Cache-Operation
X-GeoCode
X-Cache-Action
X-Director
Onion-Location
X-XRDS-LOCATION
X-Urbn-Context-Path
Azure-SlotName
X-Urbn-Site-Id
X-Varnish-Cache-Hits
Azure-RegionName
Azure-SiteName
X-UPSTREAM-Address
X-ServerID
Load-Balancing
Fastcgi-Useragent
Locale
Filters
Azure-Version
Meta-Geo
X-SayCDN-TTL
X-URL
X-Say-TTL
X-Rewrite-Enabled
X-Proto
S-Rt
X-JoinUs
X-LAGOON
Azure-InstanceId
X-Content-Powered-By
X-Say-Cacheable
X-SaId
X-Labrador-Cache-Channel
X-Soup
X-Container-Uri
X-Forwarded-Host
X-Cluster-Node
X-MCACHE
X-PHP-Host
X-VC-Cache
OT-Force-Account-Verify
X-Varnish-Hostname
Uber-Trace-Id
X-RM-Cache-TTL
X-Git-Commit
Web-Mar-Node
X-Adobe-Source
X-Generation-Time
X-Ms-Request-Id
X-VCT
X-LSADC-Cache
X-Served-From
X-Sql-Duration-Ms
X-Sql-Count
X-Logging-Id
X-Ms-Version
X-Cache-Server
X-Detected-As
X-Debug
X-Zen-Fury
X-Routing-Service
X-Zipkin-Id
X-Skip-Cache
Node
Webcakes-App-Name
Webcakes-App-Version
X-Sucuri-Cache
X-Sucuri-ID
Mn-Server-Ip
X-RCS-CacheZone
X-R9-Blue-Green-Version
TWC-GeoIP-LatLong
TWC-GeoIP-Country
X-Lambda-Id
TWC-Locale-Group
X-FB-TRIP-ID
X-Extlb
TWC-Device-Class
X-Proxied
Property-Id
X-Origin-Hint
Webcakes-Region
TWC-Privacy
TWC-Connection-Speed
DB-Nickname
X-Tt-Logid
X-Tumblr-Pixel-2
X-Tumblr-Pixel-3
X-Timing-Wait
X-Format
X-Proxy-Build
Selected-Fe
X-Fetched-On
X-Uri
X-Loop
X-Tncms
X-Drupal-Cache-Contexts
CDN-RequestId
X-B3-SpanId
X-Rn-Rsrv
Liferay-Portal
X-Cache-Hit
Source
X-Endurance-Cache-Level
X-Nf-Request-Id
X-Fastly-Request-Id
X-CCDN-CacheTTL
X-Hcs-Proxy-Type
X-CCDN-Origin-Time
X-Ua
X-Varnish-Ttl
X-Redis-Cache
X-MP-GENERATED-AT
X-Origin-Date
Cross-Origin-Window-Policy
X-Srv
Fastly-Drupal-HTML
X-TimeS
X-Varnish-Hits
X-CACHE-AGE
Section-Io-Id
Section-Origin-Responded
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
X-Pass-Why
X-Cache-Expired-At
X-S
Upgrade-Insecure-Requests
Content-Secure-Policy
X-Real-IP
X-UA-Device-Type
X-Cache-TTL-Remaining
X-Origin-CC
X-Origin-TTL
X-Akamai-Transformed
X-Newrelic-Synthetics
X-Ratelimit-Reset
X-Pubstack
CDN-RequestPullCode
CDN-Uid
CDN-RequestPullSuccess
X-TIME
CDN-Cache
CDN-CachedAt
CDN-EdgeStorageId
CDN-RequestCountryCode
CDN-PullZone
X-Node-Name
X-GEO
X-Hl-Ver
X-Server-W
X-Via-JSL
X-NGENIX-Cache
NGB
X-Presslabs-Stats
Cache-Provider
MS-CV
Ms-Operation-Id
X-RTag
X-Handled-By
X-Cache-Type
X-Restarts
X-Cms-Context
X-Reqid
WP-Super-Cache
Apigw-Requestid
X-Optimistic-Header
X-IPLB-Request-ID
X-Xfnlog-Site
X-IPLB-Instance
X-A-Dam
X-App
X-A-Dgt
BehaviorPad-Version
X-A-Wwc
X-Accel-Expires-Debug
X-A-Dcw
X-Aed
X-Application
X-BCube-Filmed-By
X-Cache-NE
X-Cache-Info
X-VG-WebCache
X-CacheTTL
X-Cdn-Diag
X-Slack-Shared-Secret-Outcome
X-Cache-Host
X-Vdms-Version
X-Bc-Bl
X-Var-Ttl
X-A-Ccd
X-Bl-Debug
X-Cache-Bucket
X-Vdms-Path
X-B-Cookie
We-Hiring
Server-Host
L
L5d-Success-Class
Lang
X-SRCache-Key
Sslversion
Gh-Request-Id
Ha-Gx-Prefs
HA-Ipaddr
X-Origin-Time
Magicmarker
Redirect-Candidate
Ngx.Var.Host
Odigeo-Trace-Id
N-Cache
Meta-Geo-Continent
Mail-Subject
MD5-Digest
Rendered-Blocks
X-Tenant
Gannett-Cam-Experience-Id
VNS-Cache
VNS-Age
Vix-Hermes-Req-Id
True-Client-Country-4JS
W
X-Viewer-Country
Canary
Candidate-Md5Url
Web-Mar-Region
CPC-Age
CPC-Cache
Fastly-Backend-Name
Fastly-GeoIP-CountryCode
Fastly-SSL
Surrogated-Key
T-Server
DCR-Decision-By
DCR-Processing-Time-Ms
X-RateLimit-Limit-Second
X-A
ServedBy
X-Ec-Custom-Error
X-Parent-Response-Time
X-Dispatcher-Number
X-Ec-Fail
X-Ec-GeoHdr
X-ScT
X-Wikidot-Static-Cache
X-Is-Gdpr
X-JWT-State
X-Debug-Cache-Store
X-Debug-Cache-Fetch
X-We-Are-Hiring
X-Request-Host
X-Developer
X-Destination
X-SD-PageType
X-Epic-Correlation-Id
X-GeoIP-Country-Code
X-GeoIP-Region-Code
X-RateLimit-Remaining-Second
X-Orig-Expires
X-Forwarded-Path
X-Gdpr
X-Shop-Environment
X-FC-Vary-Parameters
X-Fastly-Backend
Xc-Version
X-Worker
X-Has-Esi
X-AIR-PT
X-External-Request-Id
X-Eu-Site
X-Date
X-Wikidot-Backend
X-Conf
X-D
Origin-Agent-Cluster
X-Mvc-Supplant-Cachable
X-CF-Lambda-Version
X-CF-Lambda-Fn
X-CGP
X-Policy
X-Nyt-Route
X-Rojux
X-Csrf-Jwt
X-Vtex-Remote-Cache
X-Slack-Backend
X-S-Cookie
Hostname
X-CSRF-Token
X-BYPASS-REASON
Cache-Name
X-Vcl-Version
X-ProxyCache-Status
X-ProxyCache-Key
X-No-Session
X-Tx-Id
Platform
Producers
X-Generated-On
X-Gzip
X-Sorting-Hat-ShopId
X-Core-Mission
X-Cache-Debug
X-CMSURLCustom
X-Cache-Id
X-ShardId
Req-Svc-Chain
X-Esi-Check
Release
X-Server-IP
X-Org
X-Geo-Header
X-Sn-Servicetimems
X-Fmm-Version
X-Clientip
X-Clara-WADP
X-ShopId
X-Shopify-Stage
Thinkindot-Control
X-Accel-Buffering
X-Mid
X-DefHash
X-Cdn-Origin
X-Level-Front-Cache
X-Loc
X-Mly-Id
X-Alternate-Cache-Key
X-S-Maxage
X-Auto-Login
X-App-Name
X-DefElseHash
X-ApacheServer
X-Nitro-Cache
X-Irp-Debug
Thinkindot-CacheControl-Type
X-Sorting-Hat-PodId
X-Core-Value
Thinkindot-CacheControl
TDXMobile
X-Bip
X-NodeID
X-BBC-Edge-Cache-Status
X-Node-Id
X-DPWN-IS-SECURE
X-INCAP-ABP
X-Human
X-Hash
X-Thanos
X-Varnish-CookieINHashed-On
X-Varnish-CookieHashed-On
Cmstype
Cmsid
X-Varnish-Remaining-TTL
Datacenter
X-Varnishpool
Environment
AKAMAI
X-Variation
Cf-Device-Type
X-Up
X-Owner
Adler-Geo
X-Refresh
X-Platform
X-Thinkindot-L3
X-Old-Content-Length
X-WADP-Cache
X-Wix-Viewer-Type
Expect-Staple
X-Test
X-PAYTM-SRV-ID
X-SVT-ORM-VERSION
X-VG-TLSProxy
Machine
X-PERF
X-Request-Time
X-Storefront-Renderer-Rendered
X-SVT-ORM-RULES
Origin
Memcached
Host-ID
X-VServer
X-Qloud-Router
X-Vmg-Version
X-Pool
Is-Eu
X-AWS-Id
X-VWS-Id
Cache-Hits
X-LJ-Flow-ID
User-Cache-Control
X-Cluster
X-Nananana
X-Cdn-Srv
X-Akamai-Device-Characteristics
X-Mvc-Supplant-OutputCached
X-WA-Info
X-Nginx-Cache-Key
X-Block-Status
X-Origin
X-Gen-Mode
X-Origin-Response-Time
Esi-Enabled
DSUID
Apple-News-Services-Handled
Sever-Int
X-GeoIP
X-Hnp-Log
NM-Fastcgi-Cache
Server-Ext
Server-Hostname
Country-Code
X-From
Apple-News-Services-Request-Url
X-Dispatcher-Server
X-Forwarded-Site
Apple-News-Services-Parsed-Url
X-Datadome
Apple-News-Services-Host
CloudFront-Viewer-Country
CDCHOST
X-Device-Os
X-Proxy-Cache-Status
X-PHP-Backend
X-LB-NoCache
X-Instance-Name
X-Scale
X-Section
X-Op-Id-All
X-NCache
X-Cache-Status-Check
Time
Wxu-Next-Hostname
Wxu-Next-Region
C-Via
Ssr
Server-Info
Origin-CC
Origin-EX
Pics-Label
Memory
X-Access
Wxu-Next-Commit
X-Cache-Enabled
AMP-Access-Control-Allow-Source-Origin
X-API-Version
X-TIM-N
X-Amz-Meta-Cb-Modifiedtime
NGX
Server-ID
X-Micro-Cache
X-CACHE-GROUP
X-Via-Fastly
X-Correlation-ID
X-B3-Spanid
X-HA-Backend
X-Dc
X-FTR-Request-ID
X-Wp-Cf-Super-Cache-Active
X-AB
X-ZONE
X-Internal-Host
X-Vgn-Hpd-Reason
X-Air-Trace-Id
X-Air-Source
X-Tb-Optimization-Total-Bytes-Saved
X-Air-Hostname
X-Varnish-Beresp-Ttl
X-Varnish-Beresp-Grace
X-Platform-Router
X-Webkit-Csp-Report-Only
X-Platform-Processor
X-Platform-Cluster
X-Cs
X-Azure-Ref-OriginShield
X-Geo-Region
X-Buckets
Location
GeoIP-Latitude
IsBot
X-SIPLIST1
X-Accel-Version
Cdn-Requestid
X-DC
X-DataCenter
X-B3-Parentspanid
X-Backend-Instance
Cache-Host
X-Microcachable
X-Origin-Expires
X-Github-Request-Id
X-Fpc
X-Web-Node
X-TraceId
X-WP-CF-Super-Cache-Active
XM
X-Zone
X-Is-Mobile
X-NGINX-Cache
X-Is-Supported-Browser
X-Is-Desktop
X-Is-Tablet
X-Tcp-Rtt
X-Browser-Name
PFcat
X-VarnishDD-TTL
CF-Ctrl
X-Pod-Name
YJS-ID
Resin-Trace
X-HN
X-Info
Uri
X-LiteSpeed-Cache-Control
Sid
X-TA-CDN-Provider
User-Agent
X-Ad-Defer-Variation
X-Cached-By
Edge-Copy-Time
X-Locale
X-Via-Edge
X-NewRelic-App-Data
X-Nitro-Cache-From
GeoIp-Country-Code
X-Nitro-Rev
X-Via-CDN
X-Via-SSL
X-FL-QIT-DEBUG
A
X-Site-Version
X-FL-EDGE
Srvid
Locid
X-HOST
Epwk-X-Cache
X-Hyper-Cache
True-Client-Ip
X-CSRF-TOKEN
X-CS
X-VCache
True-Client-IP
X-ATG-Version
X-Cache-ASPX
X-Contensis-Viewer-Groups
X-FireWall-Port
SID
XServer
X-Frame-Option
Cdn
X-Moov-T
GeoIP-Country-Code
X-Moov-Xdn-Version
X-Webstats-RespID
X-MSEdge-Features
X-MSEdge-Flight
X-Service
Cache-Key
X-Varnish-Authentication
X-Geo
X-SRV
X-TRACE-ID
X-VC
X-Origin-Cache-Key
NtCoent-Length
X-Upstream-Ct
Path
X-Datacenter
X-FPC
X-Upstream-Ht
Fastly-Drupal-Html
Tcn
X-HostName
LB
X-FTR-Cache-Status
X-FTR-Backend-Server
X-FTR-Balancer
X-Vercel-Cache
X-Country-Code-Real
X-FTR-Expires
X-Planisys-CDN-TTL
X-FTR-Backend
X-Platform-Server
X-Vercel-Id
X-Planisys-CDN-Cache
State
X-LiteSpeed-Tag
X-Planisys-CDN-Rules
X-HS-Content-Campaign-Id
X-Edge-Server
Cdn-Request-Time
Cdn-Host
X-Api-Version
CountryCode
X-APP-VERSION
Cf-Ipcountry
WZWS-RAY
X-Esi
X-Amz-Meta-Opti
X-AK-Request-ID
M-TraceId
Req-ID
X-Air-Pt
X-NMSegId
Cdncip
Cdnsip
X-Pad
X-Fastly-Cache
X-Vgn-Hpd-Variations-Key
X-Vgn-Hpd-Ssi
X-Vgn-Hpd-Cached
X-Release
X-Cdn-Request-ID
WebServer
X-Wp-Cf-Super-Cache-Cache-Control
X-Traceid
X-WP-CF-Super-Cache-Cookies-Bypass
X-Cache-Remote
Cluster
X-Ad-Load-Variation
X-Rocket-Build-Number
X-Generated-In
X-Wp-Cf-Super-Cache
X-Sigma-Backend
X-Branch-Name
X-Sigma
X-Cache-Ttl
Lb
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-M-Reqid
X-M-Log
XkeyRZ
X-Scope-Id
Pramga
Yak-Timeinfo
X-Request-Start
X-HS-Status
X-Proxy-CacheRZ
Cache
Proxy-Connection
X-UA
X-CACHE-KEY
CDN
X-Provided-By
X-Shield-Cache-Expires
X-Tim-N
X-Akamai-Pragma-Client-IP
Geoip-Latitude
X-Scheme
X-GoCache-CacheStatus
X-GeoIP-City
X-Varnish-Beresp-Status
X-Gamma-Serve
X-Cdn-Forward
X-NWS-UUID-VERIFY
Content-Script-Type
X-Qnm-Cache
Content-Style-Type
Srv
X-Lb-Cache
Edge-Cache
X-Cache-Date
X-Cdn-Cache-Status
X-Ha-Backend
Server-Id
X-Request-URI
X-Vc
CF-Cached-On
Ohc-File-Size
X-RN-RSRV
X-TT-LOGID
Env
Ngx
X-Lb-Nocache
X-Acquia-Application-Trace
X-Acquia-Application-UUID
X-Edge-POP
X-CUA
X-Via-Ucdn
X-EC-Lua
X-Acquia-Purge-Tags
PICS-Label
Inserted-Into-Cache-At
X-Acquia-Site
X-Dw-Trace-Id
X-TH-Server
Yjs-Id
Tube-Return
MIME-Version
Tube-Get-Contents
Tube-Got-Eval
Tube-Got-Results
X-Acquia-Purge-Cdn-Unconfigured
X-Lb-Id
X-Via-Poph
X-Servedbyhost
X-Via-Popn
X-Via-Popv
X-Wa
X-SB
X-Req
X-B3-Trace-ID
X-Fastly-Backend-Reqs
Click-Count-Error
X-Nc
X-Aicache-OS
Cneonction
Log-Origin
X-Snapshot-Date
X-Fastly-Cache-Hits
X-Litespeed-Cache-Control
X-ElasticPress-Query
Kp-EeAlive
Vha6-Origin
X-Cached-Since
X-RAMCache
X-VCL-Version
X-Udemy-Cache-App-Namespace
X-User
Cache-Tv-Group
X-Render-Time
X-CF-Cache-Header-Vary
X-Miniprofiler-Ids
CACHE-MISS-TO-ORIGIN
X-CF-Cache-Header-Cache-Control
Click-Count-Action-Start