Threat Level: green Handler on Duty: Jan Kopriva

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
X-XSS-Protection
Accept-Ranges
Expect-CT
Pragma
X-Powered-By
CF-RAY
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
CF-Ray
X-Download-Options
X-Xss-Protection
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Request-Id
X-Adblock-Key
Access-Control-Allow-Credentials
X-FRAME-OPTIONS
X-Permitted-Cross-Domain-Policies
X-AspNet-Version
Alt-Svc
X-Request-ID
X-Runtime
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Generator
X-Cache-Status
X-Check
X-Cacheable
Timing-Allow-Origin
X-Envoy-Upstream-Service-Time
X-Iinfo
X-Content-Security-Policy
X-Drupal-Dynamic-Cache
Feature-Policy
Content-Encoding
Access-Control-Expose-Headers
Upgrade
Status
X-CDN
X-AspNetMvc-Version
P3p
Access-Control-Max-Age
X-Dns-Prefetch-Control
X-Via
Server-Timing
Request-Context
X-Robots-Tag
X-Turbo-Charged-By
X-UA-Device
X-Amz-Request-Id
X-Cache-Group
X-Amz-Id-2
EagleId
X-Backend
X-AH-Environment
X-Proxy-Cache
Keep-Alive
X-Server
X-Ua-Compatible
X-Ws-Request-Id
X-Age
Cf-Edge-Cache
Host-Header
X-Hacker
X-Vhost
X-Server-Powered-By
X-Rq
X-Varnish-Cache
X-Dispatcher
X-Amz-Version-Id
Grace
Allow
X-OneAgent-JS-Injection
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-LiteSpeed-Cache
X-Page-Speed
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
Cf-Apo-Via
X-Device
X-WebKit-CSP
Cf-Railgun
Accept-CH
X-Aws-Lambda-Call-Status
X-Node
X-Pingback
X-Host
EagleEye-TraceId
X-Ruxit-JS-Agent
X-Server-Id
Surrogate-Control
X-Nginx-Cache-Status
X-Akam-SW-Version
X-Readtime
Request-Id
X-Backend-Server
Accept-Ch-Lifetime
X-Content-Security-Policy-Report-Only
X-HW
X-Cache-Lookup
X-Cloud-Trace-Context
X-Cache-Spec
X-Trace
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Response-Time
X-Application-Context
Permissions-Policy
X-Nginx-Upstream-Cache-Status
Fastly-Restarts
X-Edge
X-Mod-Pagespeed
X-WebKit-CSP-Report-Only
X-Litespeed-Cache
X-Country
Content-Location
X-Mcache
X-MS-InvokeApp
X-Content-Type
X-Url
X-Clacks-Overhead
X-TtlSet
X-PC
X-Vname
X-Midtier
X-Amz-Server-Side-Encryption
X-CST
Rating
Accept-CH-Lifetime
RTSS
Cache-Tag
X-ESI
X-Vcap-Request-Id
X-D2id
X-Rack-Cache
X-Element-Page-Cache
X-Exp-Variant
X-Kinja
X-Use-Magma
X-Kinja-Server
X-Kinja-Build
X-Kinja-Revision
X-Exp-Id
X-GoogleNews-Bot
X-Cdn-Fetch
Verso
Origin-Trial
X-VARITI-CCR
X-Server-Name
X-GitHub-Request-Id
X-ECACHE
X-Ac
Service-Worker-Allowed
X-Powered-By-Plesk
X-Amz-Rid
X-Cnection
X-SharePointHealthScore
SPRequestGuid
X-Navigation-Version
X-Client-IP
Xkey
Edge-Control
SPRequestDuration
SPIisLatency
X-Abt-Application-Version
X-Upstream
X-Cache-TTL
Accept-Ch
X-Ttl
Arr-Disable-Session-Affinity
X-Cached
X-Dw-Request-Base-Id
X-Mg-S
X-Varnish-TTL
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Browser-Type
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Instrumentation
X-B3-TraceId
X-NWS-LOG-UUID
X-Webkit-Csp
X-Px
Pagespeed
Display
X-Middleton-Display
X-Sol
X-NF-Request-ID
X-FastCGI-Cache
X-SRCache-Store-Status
X-SRCache-Fetch-Status
Access-Control-Request-Method
X-Correlation-Id
Edge-Cache-Tag
X-Forwarded-For
X-Cache-Key
X-Country-Code
X-Goog-Hash
X-Ser
X-Powered-CMS
X-Id
AR-PoweredBy
AR-ATIME
AR-CACHE
AR-Request-ID
AR-SID
Content-MD5
Front-End-Https
Public-Key-Pins
X-RateLimit-Remaining
TCN
X-Amzn-Trace-Id
X-Version
X-Jurisdiction
X-HP-Webp
X-HP-Trace-Id
X-Recruiting
X-Content-Digest
X-T
X-MSEdge-Ref
X-Middleton-Response
Response
X-Accel-Expires
X-Ratelimit-Limit
TP-L2-Cache
TP-Cache
X-Shield-Request-Id
MicrosoftSharePointTeamServices
S
Cache-Status
Nginx-Cache
X-Fastcgi-Cache
X-Request-Processing-Time
X-Request-Received
Cross-Origin-Opener-Policy
X-HS-Hub-Id
X-HS-Cache-Config
X-HS-Content-Id
X-HS-Combine-CSS
Server-Node
Cache-Tags
X-XRDS-Location
X-Fastly-Request-ID
MRF-Tech
X-Daa-Tunnel
X-B3-TraceId-Primal
Mrf-Cache-Status
X-Distributor
X-ORACLE-DMS-ECID
X-Hits
X-ORACLE-DMS-RID
X-PressLabs-Stats
X-LB-Cache
X-Kinsta-Cache
X-Edge-Location-Klb
X-Origin-Server
X-Ua-Browser
X-Ezoic-Cdn
X-TEC-API-ROOT
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-Ratelimit-Reset
Filterid
Fastcgi-Cache
Alternate-Protocol
X-Ratelimit-Remaining
X-Frontend
X-LLID
X-Microsite
X-Request-Handler-Origin-Region
X-Grace
X-Hostname
X-Rid
Healthy
Realpath
X-DIS-Request-ID
X-Logged-In
X-Varnish-Backend
X-Git-Hash
X-FB-Debug
Server-Name
X-Geo-Country
X-NGENIX-Cache
X-Www-Served-By
Cleartype
X-Cluster-Name
X-Page-Id
Payment
X-Debug-Info
DC
X-Load-Cache
X-TTL
X-Protected-By
MS-Author-Via
X-Forwarded-Proto
X-Origin-Cache
Access-Control-Allow-Method
X-ECache
Content-Disposition
X-ASPNET-VERSION
X-B3-Traceid
X-Upgrade-Enabled
Charset
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Goog-Metageneration
X-B3-Sampled
X-GUploader-UploadID
X-Activity-Id
X-AppVersion
X-Az
X-Proxy
X-DataDome
X-Seen-By
Count-Hit
X-Server-ID
X-Cache-Age
X-Amz-Meta-S3cmd-Attrs
X-F-Cache
X-Times
X-Whom
X-Azure-Ref
X-Amz-Replication-Status
X-Fb-Rlafr
Paypal-Debug-Id
Cross-Origin-Resource-Policy
X-Revision
X-B
Surrogate-Key
X-Type
Accept-Charset
X-Contextid
X-Akamai-Edgescape
X-App-Environment
Viewport
X-Varnish-Server
X-Providence-Cookie
X-Is-Crawler
X-Flags
X-Request-Guid
X-Route-Name
X-Aspnet-Duration-Ms
Retry-After
X-TT
X-Wix-Request-Id
X-Hosted-By
X-Aspnetmvc-Version
X-Language
X-Envoy-Decorator-Operation
X-DynaTrace
X-B-Cache
X-Signature
X-Cache-Control
X-Mobile
X-App-Server
X-Magnolia-Registration
X-Source
X-Varnish-Grace
X-Goog-Storage-Class
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
Version
Host
WPO-Cache-Message
WPO-Cache-Status
X-VCache
Amp-Access-Control-Allow-Source-Origin
Refresh
X-Amz-Apigw-Id
X-Amzn-RequestId
X-N
X-Cache-Rule
X-RateLimit-Limit
Referer-Policy
X-HTML-Minification-Powered-By
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-Varnish-Age
X-Tumblr-User
Access-Control-Request-Headers
X-Cache-Time
X-Original-Request-Id
X-Response-Served-From
X-Tumblr-Pixel
X-XRDS-LOCATION
X-Rule
X-Cacheable-TTL
SD-X-WS
X-RTag
X-Content-Powered-By
X-Framework
X-G
X-Jobs
X-Trace-Id
X-EdgeConnect-Cache-Status
Protected
X-User-Agent
X-UUID
MS-CV
Ms-Operation-Id
X-L-Path
X-ProcessESI
X-Environment-Context
X-RemovedCookies
X-Oracle-Dms-Rid
X-Cache-Grace
X-Backend-Name
X-Oracle-Dms-Ecid
X-Region
NGB
Akamai-GRN
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Device-Type
GEO-INFO
Section-Io-Cache
X-Tt-Trace-Tag
X-FW-Static
X-FW-Type
X-FW-Server
X-FW-Serve
X-FW-Hash
From-Origin
X-FW-Version
X-Status
X-Tt-Trace-Host
X-FW-Dynamic
X-Rendered-As
X-Varnish-Ttl
Front
X-Http-Reason
X-Page-View
X-Cache-Status-Check
X-Akamai-Request-ID2
X-Is-Bot
X-Cache-Expired-At
X-Instance
X-NYM-Debug-Backend
X-Adobe-Loc
X-Drupal-Cache-Contexts
X-Adobe-Content
X-Drupal-Cache-Tags
X-Nginx-Cache
CDN-RequestId
Pinterest-Version
X-Pinterest-Rid
Pinterest-Generated-By
X-Unique-Id
Url
X-Servername
X-Fastly-Request-Id
Liferay-Portal
Accept-Language
X-Content-Options
X-Template
X-Time
Fastly-SIE
Fastly-SWR
X-CDN-Forward
X-Debug-IsPreview
X-Air-Source
X-Air-Trace-Id
Backend
X-Zen-Fury
X-Air-Hostname
X-Debug-IsConnected
X-Cache-Hit
SRV
X-DynaTrace-JS-Agent
X-Yottaa-Optimizations
X-Newrelic-App-Data
X-Yottaa-Metrics
Country
X-Mode
X-Rocket-Nginx-Serving-Static
Content-Secure-Policy
X-Uri
Node
X-Edge-Location
X-ARC
X-Cache-Operation
X-Tumblr-Pixel-3
X-Rewrite-Enabled
X-COUNTRY
X-Tumblr-Pixel-2
X-Amzn-Remapped-Content-Length
X-IPS-LoggedIn
Webserver
X-App-Version
Onion-Location
S-Rt
Filters
X-UPSTREAM-Address
Meta-Geo
X-Generation-Time
X-Cache-Server
X-RN-RSRV
X-Locale
Uber-Trace-Id
CF-IPCountry
X-Content-Age
Selected-Fe
X-Timing-Wait
Countrycode
WP-Super-Cache
Azure-SiteName
X-Proxy-Build
Azure-RegionName
Azure-SlotName
X-PHP-Backend
Azure-Version
Cache-Hits
X-Proxy-Cache-Info
Azure-InstanceId
X-Via-Fastly
X-ProxyCache-Status
X-BYPASS-REASON
Cache-Name
X-Web-Node
X-Ua
X-Cms-Context
X-ProxyCache-Key
X-Reqid
X-Tb
X-Sucuri-Cache
X-Server-W
X-Cache-Action
X-Soup
X-Ms-Request-Id
X-Ms-Version
X-Site-Version
X-Sucuri-ID
X-Skip-Cache
X-Say-Cacheable
ServerID
Cache-Tv-Group
X-Say-TTL
X-Section
X-SayCDN-TTL
Webcakes-App-Version
X-Format
X-LJ-Flow-ID
X-Origin-Date
X-Extlb
X-VWS-Id
X-Routing-Service
X-Cache-Host
X-PHP-Host
X-Origin-Hint
X-Cluster-Node
X-Proxy-Cache-Status
TWC-GeoIP-Country
X-Proto
X-Proxied
X-Zipkin-Id
TWC-GeoIP-LatLong
X-Access
X-IPLB-Request-ID
Property-Id
TWC-Device-Class
Webcakes-Region
X-IPLB-Instance
TWC-Privacy
Webcakes-App-Name
X-Labrador-Cache-Channel
TWC-Connection-Speed
X-UA-Device-Type
TWC-Locale-Group
X-AWS-Id
X-R9-Blue-Green-Version
DB-Nickname
Cross-Origin-Window-Policy
X-No-Session
X-JoinUs
X-LAGOON
X-SaId
X-Optimistic-Header
X-Sql-Duration-Ms
Apigw-Requestid
X-Sql-Count
X-Forwarded-Host
Web-Mar-Node
X-VC-Cache
X-Debug
X-Cluster
X-Varnish-Beresp-Grace
Mn-Server-Ip
X-Cache-TTL-Remaining
X-FB-TRIP-ID
X-Handled-By
X-Adobe-Source
X-Urbn-Site-Id
X-Urbn-Context-Path
Locale
X-Detected-As
X-Real-IP
X-LSADC-Cache
ServedBy
X-Director
X-Ruxit-Js-Agent
X-Node-Name
X-Xfnlog-Site
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
X-Tec-Api-Origin
X-Tec-Api-Version
Frame-Options
Fastcgi-Useragent
X-Tec-Api-Root
X-GeoCode
X-GeoCountry
Upgrade-Insecure-Requests
Mime-Version
X-Varnish-Hits
X-Tt-Logid
Source
X-Oneagent-Js-Injection
CDN-Uid
CDN-EdgeStorageId
CDN-PullZone
CDN-RequestCountryCode
CDN-CachedAt
Load-Balancing
X-Api-Version
X-Generated-By
CDN-Cache
X-Hl-Ver
X-Varnish-Cache-Hits
X-GEO
X-Buckets
Fastly-Drupal-HTML
Xet-Cookie
X-Request-Time
X-TIME
X-Varnish-Hostname
X-FireWall-Port
X-ServerID
X-Datadog-Parent-Id
X-RM-Cache-TTL
X-Datadog-Sampling-Priority
X-Mg-Request-UUID
X-Datadog-Sampled
X-Datadog-Trace-Id
X-Redis-Cache
X-Origin-CC
X-SRV
X-Origin-TTL
CF-Cached-On
X-TA-CDN-Provider
X-Cache-Debug
X-URL
X-Loop
X-Storage
X-Akamai-Transformed
X-Served-From
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Storefront-Renderer-Rendered
X-Shopify-Stage
X-Pubstack
X-ShardId
X-ShopId
X-Alternate-Cache-Key
X-Provided-By
X-Tx-Id
X-Endurance-Cache-Level
X-Restarts
X-Pass-Why
X-Request-Host
X-Newrelic-Synthetics
X-Location
Xserver
X-Level-Front-Cache
Surrogated-Key
Sslversion
X-CMSURLCustom
X-Origin
NM-Fastcgi-Cache
X-Mobile-URL
X-Mid
X-Aed
X-Cache-Date
MD5-Digest
Memcached
X-Men
X-Generated-On
DCR-Processing-Time-Ms
Origin
X-Developer
DCR-Decision-By
X-Ec-Fail
Candidate-Md5Url
X-Ec-GeoHdr
X-Destination
DSUID
X-CUA
Host-ID
Gannett-Cam-Experience-Id
X-D
Edge-Cache
Odigeo-Trace-Id
X-Epic-Correlation-Id
Cache-Host
Redirect-Candidate
X-Conf
X-Gdpr
Release
Rendered-Blocks
X-Hash
Server-Host
X-Cache-Info
X-Cache-NE
A
BehaviorPad-Version
X-External-Request-Id
X-Fetched-On
Lang
X-Core-Mission
X-INCAP-ABP
X-Nyt-Route
Thinkindot-Control
X-TIM-N
X-Bc-Bl
X-Vdms-Path
X-Vdms-Version
X-Thinkindot-L3
X-Thanos
X-SRCache-Key
X-Sigma-Backend
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-Test
X-B-Cookie
X-We-Are-Hiring
X-A-Wwc
X-A-Dgt
X-Application
Meta-Geo-Continent
X-CSRF-Token
X-A-Dcw
X-A-Dam
Ngx.Var.Host
Xc-Version
WWW-Authenticate
X-A
X-A-Ccd
X-Sigma
X-BCube-Filmed-By
X-Rojux
X-S
X-S-Cookie
T-Server
X-Rocket-Build-Number
X-Processor
TDXMobile
X-Response-By
X-S-Maxage
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
X-ScT
X-Origin-Time
X-Bip
X-Service
Server-Info
Click-Count-Error
Click-Count-Action-Start
CloudFront-Viewer-Country
X-Date
Cmsid
X-Ec-Custom-Error
X-Platform-Cluster
X-Platform-Processor
Cache-Key
C-Via
CacheControlHeader
X-Platform-Router
Fastly-Backend-Name
Cmstype
Country-Code
Gh-Request-Id
X-Cdn-Origin
X-Accel-Expires-Debug
Fastly-GeoIP-CountryCode
X-CacheTTL
X-Org
X-Auto-Login
X-Dispatcher-Number
X-Dispatcher-Server
X-Akamai-Device-Characteristics
X-Cache-Bucket
X-Platform
X-Scale
X-Fastly-Backend
Req-Svc-Chain
X-Gzip
X-HS-Content-Campaign-Id
X-Req
X-Mvc-Supplant-Cachable
X-Var-Ttl
X-Geo-Header
X-Httpd
X-Human
X-Loc
X-Server-IP
Magicmarker
X-Slack-Backend
X-Sn-Servicetimems
X-Slack-Shared-Secret-Outcome
X-Origin-Response-Time
X-Node-Id
X-SD-PageType
X-Fastly-Cache
X-BBC-Edge-Cache-Status
X-Pool
Mail-Subject
X-Esi-Check
We-Hiring
Tube-Return
Tube-Got-Results
X-Cache-Id
X-Gamma-Serve
Tube-Get-Contents
Tube-Got-Eval
X-Region-Sid
X-Varnishpool
AKAMAI
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
Section-Io-Id
HostName
Section-Origin-Responded
X-Vcl-Version
X-WP-CF-Super-Cache-Active
Environment
X-Via-CDN
X-Cache-FS-Status
X-Azure-Ref-OriginShield
X-Irp-Debug
X-VServer
X-WA-Info
X-WADP-Cache
X-Worker
X-Vmg-Version
X-Varnish-Remaining-TTL
X-V-Cache
X-Variation
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
Locid
On-Server
X-FL-EDGE
X-FL-QIT-DEBUG
X-Instance-Name
X-Nginx-Cache-Key
X-Developers
X-Cdn-Srv
Origin-CC
Origin-EX
Srvid
X-SB
X-Planisys-CDN-TTL
X-Forwarded-Site
X-Frame-Option
X-GeoIP
X-GeoIP-City
X-FC-Vary-Parameters
X-Device-Os
X-Clara-WADP
X-Core-Value
X-DefElseHash
X-DefHash
X-GeoIP-Country-Code
X-GeoIP-Region-Code
X-Origin-Expires
X-Owner
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-NodeID
X-Mly-Id
X-Has-Esi
X-Is-Gdpr
X-JWT-State
X-Ckpd-Fst-Backend
X-Fmm-Version
Ssr
State
Adler-Geo
Machine
Platform
Canary
X-TNCMS
Is-Eu
Kp-EeAlive
Web-Mar-Region
Expect-Staple
Vix-Hermes-Req-Id
X-Ad-Defer-Variation
Datacenter
X-Air-Pt
X-Via-SSL
X-Via-Edge
Edge-Copy-Time
X-Varnish-Beresp-Ttl
X-Op-Id-All
X-Minions-Version
X-NCache
PFcat
X-HN
X-VarnishDD-TTL
X-Block-Status
X-Old-Content-Length
X-Qloud-Router
X-Release
L
X-From
X-VG-TLSProxy
Cache-Provider
X-DPWN-IS-SECURE
Server-Hostname
Sever-Int
Server-Ext
X-Gen-Mode
X-Cache-Tags
User-Cache-Control
Wxu-Next-Commit
Wxu-Next-Region
X-App
X-Accel-Buffering
Wxu-Next-Hostname
X-Hnp-Log
Producers
Apple-News-Services-Handled
Apple-News-Services-Host
NGX
Apple-News-Services-Parsed-Url
X-VC
Apple-News-Services-Request-Url
X-Wix-Viewer-Type
X-Aicache-OS
X-RCS-CacheZone
X-Microcachable
X-CGP
X-Platform-Server
X-Eu-Site
X-Nananana
X-Csrf-Jwt
X-Varnish-Beresp-Status
HA-Ipaddr
Ha-Gx-Prefs
X-Ua-Device
CDCHOST
L5d-Success-Class
X-Mvc-Supplant-OutputCached
X-Cache-Remote
X-Request-Start
X-Parent-Response-Time
X-CACHE-AGE
X-B3-Spanid
X-Webkit-CSP-Report-Only
X-Zone
X-Dc
X-Debug-Cache-Store
X-Lambda-Id
Fastly-SSL
X-Cache-Enabled
X-LB-NoCache
X-Debug-Cache-Fetch
X-VCT
AMP-Access-Control-Allow-Source-Origin
Sid
Pics-Label
X-Tb-Optimization-Total-Bytes-Saved
X-Up
X-Correlation-ID
X-Cs
VNS-Cache
X-Generated-In
CPC-Cache
VNS-Age
X-Render-Time
X-Vtex-Remote-Cache
X-Via-Popn
X-Via-Poph
X-Upstream-Ct
X-Via-Popv
CPC-Age
Env
X-Refresh
X-Cache-Backend
X-Cached-By
X-Upstream-Ht
X-DC
X-B3-SpanId
NtCoent-Length
X-Trace-ID
Time
Decoy-Debug-TTL
X-Hcs-Proxy-Type
Memory
Decoy-Debug-Key
Cluster
X-CCDN-CacheTTL
X-CCDN-Origin-Time
X-ND-Cache
GeoIP-Latitude
Decoy-Debug-Status
Cache
X-Cache-Type
X-TH-Server
X-AIR-PT
X-HA-Backend
Fastly-Drupal-Html
X-NWS-UUID-VERIFY
X-Webkit-CSP
X-Tid
Srv
X-HS-Status
X-Servedbyhost
X-Edge-Pop
SID
X-NewRelic-App-Data
X-LB-ID
X-ATG-Version
X-Via-JSL
X-Presslabs-Stats
X-Wa
X-Srv
X-Esi
X-DataCenter
X-Nc
Cdn
X-ZONE
GeoIp-Country-Code
Server-ID
Svr
Uri
X-Varnish-Authentication
X-Client-Ip
X-Contensis-Viewer-Groups
X-Cache-ASPX
X-Check-Cacheable
X-MP-GENERATED-AT
X-CF-Lambda-Fn
X-Vgn-Hpd-Variations-Key
X-Vgn-Hpd-Cached
X-Vgn-Hpd-Ssi
X-CF-Lambda-Version
X-PAYTM-SRV-ID
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
Esi-Enabled
X-Amz-Meta-Cb-Modifiedtime
True-Client-IP
X-Vc
X-Proxy-CacheRZ
XkeyRZ
YJS-ID
X-Datadome
X-Fpc
Lb
XServer
Hostname
X-Wikidot-Backend
X-CDN-Cache-Status
X-Udemy-Cache-App-Namespace
N-Cache
X-Wikidot-Static-Cache
X-Varnish-Beresp-TTL
X-CACHE-KEY
M-TraceId
X-Tenant
X-Nf-Request-Id
X-CSRF-TOKEN
RNT-Machine
X-Shop-Environment
X-Bl-Debug
X-Forwarded-Path
Resin-Trace
X-Orig-Expires
RNT-Time
X-TX-ID
X-CS
X-NGINX-Cache
X-Gateway-Cache-Key
X-Gateway-Request-Id
X-Gateway-Skip-Cache
True-Client-Ip
X-FPC
X-MSEdge-Features
X-AK-Request-ID
OT-Force-Account-Verify
Cdnsip
Cdncip
X-MSEdge-Flight
X-Gateway-Cache-Status
X-EC-Lua
X-Fastly-Country-Code
X-API-Version
X-B3-Trace-ID
X-Via-NSCOPI
X-Policy
X-App-Name
X-Logging-Id
Sm-Log-Id
X-Service-Response-Time
Server-Id
Eomportal-Instance
CDN
Hit
GeoIP-Country-Code
X-Container-Uri
Path
X-Git-Commit
X-Cache-Ttl
X-Cdn-Diag
X-Lb-Id
X-WA
X-Accel-Version
X-Micro-Cache
X-CLOUD-TRACE-CONTEXT
X-APP-VERSION
X-Vcache
X-Datacenter
Ngx-Var-Key
X-NC
X-VCL-Version
X-MCACHE
IsBot
X-Ha-Backend
X-Cache-NGX
X-SIPLIST1
X-Request-URI
X-Geo
X-ServedByHost
LB
X-Edge-POP
HIT
X-RateLimit-Reset
X-Akamai-Pragma-Client-IP
X-Cdn-Forward
X-Cdn-Cache-Status
Pramga
X-Info
V-Age
X-Acquia-Purge-Cdn-Unconfigured
X-SERVER-NAME
XM
RATING
X-Tncms
X-VG-WebCache
X-Xrds-Location
X-Clientip
ENV
X-Snapshot-Date
Cross-Origin-Opener-Policy-Report-Only
Location
CDN-RequestPullCode
X-Srcache-Fetch-Status
CDN-RequestPullSuccess
X-Srcache-Store-Status
X-Rebelmouse-Surrogate-Control
Geoip-Latitude
X-Via-PopN
FSS-Cache
X-Via-PopH
X-Via-PopV
Timeexpire
X-Rebelmouse-Cache-Control
Tcn
X-TT-LOGID
Ohc-File-Size
Req-ID
X-Lb-Nocache
Epwk-X-Cache
X-Pod-Name
True-Client-Country-4JS
Yjs-Id
X-Ctl-Mach
X-TimeS
X-Wp-Cf-Super-Cache
X-HostName
X-LiteSpeed-Cache-Control
X-Iauth-Set-Uid
X-Wp-Cf-Super-Cache-Cache-Control
X-Hyper-Cache
X-Serial
X-Dw-Trace-Id
X-Amz-Meta-Opti
X-UP
W
X-M-Log
X-M-Reqid
Warning
X-LiteSpeed-Tag
X-Cdn-Request-ID
X-PERF
Proxy-Connection
X-User
X-Vgn-Hpd-Reason
X-Oss-Hash-Crc64ecma
X-Oss-Storage-Class
WZWS-RAY
X-Oss-Server-Time
X-Oss-Request-Id
Cneonction
X-Oss-Object-Type
X-Litespeed-Cache-Control
X-RAMCache
X-Viewer-Country
Servername
Cdn-Requestid
X-Cache-Expires
Content-Script-Type
X-Fastly-Backend-Reqs
Content-Style-Type
X-Acquia-Application-Trace
X-Qnm-Cache
Ec-Rule-Version
X-ApacheServer
X-Acquia-Application-UUID
X-Acquia-Site
X-Acquia-Purge-Tags
X-MiniProfiler-Ids
CountryCode
X-Lsadc-Cache
PICS-Label
X-Akamai-ERPolicy
X-Akamai-ERRuleID
X-WP-CF-Super-Cache-Cookies-Bypass
Inserted-Into-Cache-At
Ngx
My-App
MIME-Version
X-Swift-Error
X-IPS-Cached-Response
X-B3-Parentspanid
X-B3-ParentSpanId
X-Mg-Cache
X-Webstats-RespID
X-Fastly-Cache-Hits
X-Th-Server
Ohc-Cache-HIT