Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-Cache-Status
Link
Accept-Ranges
CF-RAY
X-XSS-Protection
ETag
Expect-CT
Pragma
X-Powered-By
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
Alt-Svc
P3P
X-UA-Compatible
X-Served-By
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
X-Varnish
X-Xss-Protection
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
X-DNS-Prefetch-Control
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Cache-Status
X-Check
X-Generator
X-Cacheable
Timing-Allow-Origin
X-Content-Security-Policy
X-Iinfo
Feature-Policy
Status
X-Envoy-Upstream-Service-Time
Content-Encoding
Access-Control-Expose-Headers
P3p
X-Drupal-Dynamic-Cache
X-AspNetMvc-Version
X-CDN
Upgrade
X-Via
CF-Ray
X-Ws-Request-Id
Access-Control-Max-Age
X-Request-ID
Report-To
Server-Timing
EagleId
X-Cache-Group
X-Turbo-Charged-By
Keep-Alive
X-UA-Device
Request-Context
X-Age
X-Backend
X-Proxy-Cache
X-Server-Powered-By
X-AH-Environment
X-Robots-Tag
X-Hacker
X-Server
X-Amz-Request-Id
Host-Header
X-Amz-Id-2
Grace
X-Rq
X-LiteSpeed-Cache
X-Swift-SaveTime
X-Swift-CacheTime
NEL
X-Varnish-Cache
X-Nginx-Cache-Status
Ali-Swift-Global-Savetime
X-WebKit-CSP
X-Page-Speed
EagleEye-TraceId
X-Vhost
X-Ua-Compatible
X-Amz-Version-Id
X-OneAgent-JS-Injection
X-Pingback
X-Dispatcher
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
Accept-CH
X-Cache-Spec
X-Host
X-Server-Id
Cf-Railgun
X-Node
X-Backend-Server
X-Readtime
Surrogate-Control
X-Akam-SW-Version
X-Dns-Prefetch-Control
Request-Id
X-Response-Time
X-HW
X-Application-Context
Xkey
Content-Location
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Rating
Accept-CH-Lifetime
X-B3-TraceId
X-Cloud-Trace-Context
X-Country
X-Ruxit-JS-Agent
Accept-Ch-Lifetime
X-Cache-Lookup
X-Trace
X-Url
Allow
X-Content-Type
X-Ac
X-PC
X-Vname
X-TtlSet
X-Aws-Lambda-Call-Status
X-Varnish-TTL
X-Clacks-Overhead
Edge-Control
X-Server-Name
X-ESI
Fastly-Restarts
X-Mod-Pagespeed
Cache-Tag
X-Rack-Cache
Service-Worker-Allowed
X-FastCGI-Cache
X-VARITI-CCR
Verso
X-Element-Page-Cache
MS-Author-Via
X-Vcap-Request-Id
X-Upstream
X-Amz-Rid
X-MS-InvokeApp
Public-Key-Pins
X-GitHub-Request-Id
X-Dw-Request-Base-Id
X-Cached
X-Client-IP
X-Cache-TTL
X-Abt-Application-Version
X-D2id
X-Cnection
RTSS
X-Px
X-Exp-Id
X-Cdn-Fetch
X-Exp-Variant
X-Kinja-Revision
X-Use-Magma
X-GoogleNews-Bot
X-Kinja-Server
X-Kinja-Build
X-Kinja
X-Navigation-Version
Arr-Disable-Session-Affinity
Access-Control-Request-Method
X-Powered-By-Plesk
X-Country-Code
X-NF-Request-ID
X-Goog-Hash
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
X-Instrumentation
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-TTL
X-Middleton-Display
X-Sol
Pagespeed
Display
AR-ATIME
AR-SID
AR-CACHE
AR-Request-ID
AR-PoweredBy
X-Powered-CMS
X-Version
X-Origin-Cache
X-Middleton-Response
Response
X-LLID
X-CST
X-MSEdge-Ref
Nginx-Cache
TCN
X-Edge-Location-Klb
X-Kinsta-Cache
X-RateLimit-Remaining
X-Amz-Server-Side-Encryption
MRF-Tech
X-B3-TraceId-Primal
Mrf-Cache-Status
X-Edge
X-Protected-By
X-T
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-HP-Trace-Id
X-HP-Webp
X-Jurisdiction
X-Forwarded-For
X-Shield-Request-Id
X-Content-Security-Policy-Report-Only
X-Mg-S
X-Id
X-Aspnetmvc-Version
X-Language
Edge-Cache-Tag
S
Content-MD5
SPIisLatency
SPRequestDuration
X-Ruxit-Js-Agent
Front-End-Https
Fastcgi-Cache
X-Mid
Realpath
Server-Node
X-Request-Processing-Time
X-Request-Received
X-Frontend
X-Pinterest-Rid
Pinterest-Generated-By
Filters
Pinterest-Version
X-Recruiting
X-Cache-Key
Server-Name
X-Content
X-Ua-Browser
X-Ab
X-Ser
X-NWS-LOG-UUID
X-MCACHE
X-Correlation-Id
X-HS-Content-Id
X-HS-Cache-Config
X-HS-Hub-Id
X-Template
X-HS-Combine-CSS
X-Yandex-Sdch-Disable
X-DynaTrace
X-Ezoic-Cdn
SPRequestGuid
X-SharePointHealthScore
X-ECACHE
X-Hits
X-Parallel-Accel
X-Kong-Proxy-Latency
X-Ttl
X-Kong-Upstream-Latency
MicrosoftSharePointTeamServices
X-Tt-Trace-Tag
X-Tt-Trace-Host
Cache-Tags
X-Page-Id
Host
Cleartype
Charset
X-B3-Sampled
X-Daa-Tunnel
X-Git-Hash
X-Www-Served-By
X-Geo-Country
X-Debug-Info
Alternate-Protocol
X-Content-Options
X-DIS-Request-ID
Accept-Ch
X-Ratelimit-Limit
Fusion-Template-Id
Fusion-Source
Fusion-Content-Id
Fusion-Component-Id
Fusion-Content-Source
Fusion-Deployment-Id
X-Content-Digest
X-Hostname
X-Amzn-Trace-Id
Cross-Origin-Opener-Policy
Filterid
X-Amz-Replication-Status
X-Varnish-Age
X-DataDome
X-Grace
X-FB-Debug
X-F-Cache
ServerID
X-Activity-Id
X-Az
X-AppVersion
X-Upgrade-Enabled
X-VCache
X-Nginx-Upstream-Cache-Status
X-Accel-Expires
X-N
X-WebKit-CSP-Report-Only
X-Rid
X-Mobile-URL
X-Forwarded-Proto
X-Fastly-Request-Id
Access-Control-Allow-Method
X-Origin-Server
X-Aspnet-Duration-Ms
X-Flags
X-Providence-Cookie
X-Is-Crawler
X-Request-Guid
X-Route-Name
X-LB-Cache
X-Type
X-Server-ID
X-TT
X-Seen-By
X-Whom
X-GUploader-UploadID
X-App-Environment
X-Tb
Payment
X-Goog-Stored-Content-Length
X-Varnish-Grace
X-Goog-Stored-Content-Encoding
Viewport
X-Goog-Metageneration
X-Goog-Generation
X-Goog-Storage-Class
X-FW-Hash
X-FW-Serve
X-FW-Dynamic
X-Distributor
Node
X-User-Agent
X-FW-Server
Fastcgi-Useragent
X-FW-Type
X-FW-Static
DC
X-Ratelimit-Reset
Paypal-Debug-Id
X-Wix-Request-Id
X-Tec-Api-Version
X-Tec-Api-Root
Country
X-Tec-Api-Origin
TP-L2-Cache
TP-Cache
X-XRDS-LOCATION
X-Fastly-Request-ID
Accept-Charset
X-App-Server
X-Cache-Rule
X-Litespeed-Cache
X-Webkit-Csp
X-Cache-Control
X-Via-JSL
X-NGENIX-Cache
X-Fastcgi-Cache
X-Cluster-Name
X-Drupal-Cache-Tags
Version
X-Cache-Age
X-Microsite
X-Request-Handler-Origin-Region
X-Signature
X-Contextid
X-B-Cache
X-Buckets
Referer-Policy
X-Origin-Upstream-Status
Cache-Status
X-Oracle-Dms-Ecid
Amp-Access-Control-Allow-Source-Origin
X-Oracle-Dms-Rid
X-Node-Name
X-Logged-In
Refresh
X-Mobile
X-Browser-Type
VIX-Pulpo-Upstream-Status
X-Response-Served-From
X-Original-Request-Id
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
VIX-Pulpo-Node
SD-X-WS
X-IPLB-Instance
X-Rendered-As
X-Jobs
X-Real-IP
X-Vgn-Hpd-Reason
X-Is-Bot
X-Page-View
X-Cache-Expired-At
X-Load-Cache
X-Proxy-Cache-Status
X-RemovedCookies
X-Cacheable-TTL
X-Debug
X-Varnish-Backend
NGB
X-B
X-Revision
X-ProcessESI
Access-Control-Request-Headers
X-Device-Type
X-Rule
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Proxy
X-Cache-Action
X-Instance
X-UUID
X-Framework
X-G
X-Drupal-Cache-Contexts
Surrogate-Key
Akamai-GRN
X-Debug-IsPreview
X-Cache-Time
X-Debug-IsConnected
X-FW-Version
CF-IPCountry
SID
X-Accel-Buffering
X-Presslabs-Stats
GEO-INFO
X-Air-Hostname
X-Air-Source
X-Air-Trace-Id
X-Oneagent-Js-Injection
Count-Hit
X-Cache-NGX
Uber-Trace-Id
X-APP-VERSION
X-Cache-Operation
X-Azure-Ref
X-Source
DynaTrace
X-Ms-Request-Id
X-Nginx-Cache
X-XRDS-Location
X-Zen-Fury
X-Ms-Version
Protected
X-EdgeConnect-Cache-Status
Liferay-Portal
X-PressLabs-Stats
Frame-Options
Ms-Operation-Id
X-CDN-Forward
X-RTag
X-Trace-Id
MS-CV
WPO-Cache-Status
WPO-Cache-Message
X-Servername
X-Cache-Hit
X-Backend-Name
Ec-Rule-Version
X-Hyper-Cache
Healthy
X-RateLimit-Limit
Countrycode
X-Cache-TTL-Remaining
X-IPS-LoggedIn
Cross-Origin-Window-Policy
X-Environment-Context
X-Tumblr-Pixel
X-Mode
X-L-Path
Xserver
X-Tumblr-User
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-Adobe-Loc
X-Ratelimit-Remaining
Content-Disposition
X-Varnish-Server
X-Adobe-Content
Backend
X-Content-Age
X-Detected-As
Meta-Geo
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-JoinUs
X-Tid
X-UPSTREAM-Address
X-RN-RSRV
X-Rewrite-Enabled
X-SaId
LB
X-Generation-Time
X-Format
X-Redis-Cache
X-Uri
X-ShardId
X-Debug-Cache
X-Routing-Service
X-Hosted-By
X-Cache-Grace
Country-Code
Decoy-Debug-Key
Decoy-Debug-Status
Decoy-Debug-TTL
Apigw-Requestid
Url
X-Cache-Server
X-Alternate-Cache-Key
X-Proxied
X-ShopId
X-Extlb
X-Shopify-Stage
X-Sql-Duration-Ms
X-Sorting-Hat-ShopId
X-Sql-Count
X-Sorting-Hat-PodId
X-Zipkin-Id
Eomportal-Instance
CDN-PullZone
X-PCL
CDN-Uid
CDN-RequestId
CDN-RequestCountryCode
CDN-CachedAt
X-Access
X-PHP-Backend
X-Region
X-ApacheServer
X-Varnish-Beresp-Grace
CDN-Cache
Mn-Server-Ip
CDN-EdgeStorageId
Cache-Name
X-TIME
X-Via-Fastly
X-Microcachable
X-No-Session
X-OCL
X-FB-TRIP-ID
X-ServerID
X-Human
X-Section
X-UA-Device-Type
X-Forwarded-Host
Fastly-SSL
X-Origin-Date
X-PERF
X-Status
X-Site-Version
TWC-GeoIP-Country
TWC-GeoIP-LatLong
TWC-Device-Class
X-Say-Cacheable
X-Akamai-Edgescape
Property-Id
X-Generated-By
TWC-Connection-Speed
X-BYPASS-REASON
X-Pubstack
X-Content-Powered-By
X-ProxyCache-Status
X-Cluster-Node
X-SayCDN-TTL
X-NYM-Debug-Backend
X-Storage
X-NCache
X-Server-W
X-Web-Node
X-Cache-Type
X-Origin-Hint
Webcakes-Region
Webcakes-App-Version
Webcakes-App-Name
TWC-Privacy
X-Say-TTL
X-Proxy-Build
X-Cache-Host
X-Timing-Wait
X-ProxyCache-Key
TWC-Locale-Group
Selected-Fe
Cache-Tv-Group
X-Soup
Section-Io-Cache
X-R9-Blue-Green-Version
Retry-After
X-Varnishpool
X-Hl-Ver
X-Be
Azure-InstanceId
Azure-RegionName
X-LSADC-Cache
Content-Secure-Policy
Azure-SiteName
Azure-Version
Azure-SlotName
X-Nginx-Cache-Key
X-Webkit-CSP
X-Ua
X-NewRelic-App-Data
X-Cache-Remote
X-Unique-Id
DB-Nickname
X-Cached-By
X-Dc
OT-Force-Account-Verify
X-Bc-Bl
X-Platform-Server
X-Azure-Ref-OriginShield
X-Akamai-Transformed
Cache
Source
X-Xfnlog-Site
X-Auto-Login
X-TT-LOGID
X-Cache-Tags
X-GEO
Upgrade-Insecure-Requests
ServedBy
SRV
From-Origin
X-Cdn
X-LAGOON
X-Origin-CC
X-Varnish-Cache-Hits
X-Origin-TTL
Mime-Version
X-AOL-HN
X-Request-Time
Xet-Cookie
X-Varnish-Hits
X-Loop
X-TNCMS
Cache-Hits
X-Varnish-Hostname
X-NWS-UUID-VERIFY
HostName
X-HTML-Minification-Powered-By
X-EC-Lua
WP-Super-Cache
X-SRV
X-S-Maxage
X-Request-Host
Onion-Location
X-CSRF-Token
Webserver
X-ECache
X-Xrds-Location
X-FireWall-Port
X-Handled-By
Web-Mar-Node
X-Cache-Enabled
X-Tumblr-Pixel-2
X-Tumblr-Pixel-3
X-App-Version
X-B3-SpanId
N-Cache
X-Endurance-Cache-Level
X-Time
S-Rt
X-Proto
X-Http-Reason
Nel
X-Adobe-Source
X-Correlation-ID
X-Akamai-Request-ID2
X-Tenant
X-RCS-CacheZone
X-Reqid
X-Origin-Response-Time
X-A
Surrogated-Key
User-Cache-Control
Vix-Hermes-Req-Id
V-Age
Meta-Geo-Continent
Expiry
Fastcgi-X-Cache-Version
DCR-Processing-Time-Ms
DCR-Decision-By
A
BehaviorPad-Version
Xc-Version
Mobile-Detection-Method
Redirect-Candidate
Rendered-Blocks
X-Vtex-Remote-Cache
Pramga
Odigeo-Trace-Id
Sslversion
X-Block-Status
X-PAYTM-SRV-ID
X-Orig-Expires
X-PBS-Appsvrname
X-Planisys-CDN-Cache
X-Vdms-Path
X-ND-Cache
X-NAPM-TraceId
X-GG-Cache-Date
X-Hnp-Log
X-Vdms-Version
X-Ig-Push-State
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Shop-Environment
X-Session-Fingerprint
X-Slack-Backend
X-SRCache-Key
X-TIM-N
X-SD-PageType
X-ScT
X-Processor
X-Rojux
X-S
X-S-Cookie
X-Gen-Mode
X-Ftr-Request-Id
X-ARC
X-Application
X-B-Cookie
X-Backend-TTL
X-V-Cache
X-Aed
X-A-Wwc
X-A-Dam
X-Vtex-Processado-Em
X-A-Dcw
X-A-Dgt
X-Cache-NE
X-CF-Lambda-Fn
X-Epic-Correlation-Id
X-Developer
X-External-Request-Id
X-VG-WebCache
X-Forwarded-Path
X-Destination
X-D
X-CF-Lambda-Version
X-Ckpd-Fst-Backend
X-Cluster
X-Conf
X-A-Ccd
X-Connection-Hash
X-Amz-Meta-S3cmd-Attrs
X-VWS-Id
X-LJ-Flow-ID
X-AWS-Id
X-Edge-Location
Server-Info
X-Mg-Request-UUID
X-Time-Microsecs
X-MP-GENERATED-AT
X-Magnolia-Registration
X-LI-UUID
X-Location
X-Men
X-Mvc-Supplant-Cachable
X-Li-Pop
X-Li-Fabric
Origin-EX
Origin-CC
Origin
X-NodeID
X-Nyt-Route
X-Policy
Gh-Request-Id
X-Proxy-Upstream
Host-ID
X-Origin-Time
X-Cache-Bucket
X-Old-Content-Length
X-Origin
X-Cache-Date
X-Hash
X-Accel-Expires-Debug
X-Device-Os
X-Cache-Info
True-Client-Country-4JS
X-Date
Wxu-Next-Commit
X-Core-Mission
Wxu-Next-Region
Wxu-Next-Hostname
Traceparent
X-Fastly-Cache
X-Geo-Header
X-GeoIP-Country-Code
X-Aicache-OS
X-GeoIP-Region-Code
Fastcgi-Cache-TTL
X-Gdpr
X-Fetched-On
X-Forwarded-Site
Svr
X-Cdn-Srv
X-Origin-Expires
Apple-News-Services-Handled
X-Webstats-RespID
AKAMAI
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
CacheControlHeader
Arc-Country
X-VServer
X-Sucuri-Cache
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-Sucuri-ID
X-VG-TLSProxy
X-Viewer-Country
X-Locale
CDCHOST
Apple-News-Services-Request-Url
X-Server-IP
DSUID
X-Rocket-Nginx-Serving-Static
X-Request-URI
Cmstype
X-Scheme
Cmsid
Environment
CloudFront-Viewer-Country
X-Sn-Servicetimems
X-Restarts
X-Datadog-Trace-Id
X-Branch-Name
X-Developers
X-UnsetCookies
X-Envoy-Decorator-Operation
X-Varnish-Beresp-Status
X-VarnishDD-TTL
X-FC-Vary-Parameters
X-BBC-Edge-Cache-Status
X-Datadog-Sampling-Priority
X-JWT-State
X-Cdn-Origin
X-CGP
X-Is-Gdpr
X-Esi-Check
X-Core-Value
X-Cache-Id
X-Datadog-Parent-Id
X-Csrf-Jwt
X-Has-Esi
X-Cache-Debug
X-Fastly-Backend
X-GeoIP
X-Amzn-RequestId
X-Backend-State
X-Node-Id
X-Sigma
X-Skip-Cache
X-Sigma-Backend
X-Owner
X-Served-From
X-RateLimit-Remaining-Second
X-Region-Sid
X-RateLimit-Limit-Second
X-Rocket-Build-Number
X-PHP-Host
X-Level-Front-Cache
X-Labrador-Cache-Channel
X-Generated-On
X-Req
X-Gamma-Serve
X-TH-Server
X-TrackingId
X-Thinkindot-L3
X-GeoIP-City
X-Storefront-Renderer-Rendered
X-HS-Content-Campaign-Id
X-Irp-Debug
X-HN
X-Amz-Apigw-Id
X-Gzip
X-Eu-Site
X-Platform
State
Ssr
Server-Host
Req-Svc-Chain
TDXMobile
Thinkindot-CacheControl
Web-Mar-Region
We-Hiring
Thinkindot-Control
Thinkindot-CacheControl-Type
Release
PFcat
L
Ha-Gx-Prefs
Fastly-GeoIP-CountryCode
Fastly-Drupal-Html
L5d-Success-Class
Locid
Mail-Subject
Magicmarker
Machine
X-Varnish-Beresp-Ttl
HA-Ipaddr
X-ATG-Version
X-Via-NSCOPI
NM-Fastcgi-Cache
X-Zone
X-DefElseHash
X-Qloud-Router
Cf-Device-Type
Adler-Geo
X-DefHash
X-DPWN-IS-SECURE
X-Cache-Var
X-Response-By
X-Cache-Var-Map
X-Rebelmouse-Surrogate-Control
X-Tx-Id
X-Rebelmouse-Cache-Control
X-Amzn-Remapped-Content-Length
X-Loc
Platform
X-Varnish-CookieINHashed-On
Kp-EeAlive
X-Varnish-Remaining-TTL
Memcached
X-NU-AKA-ACS-Version
X-Worker
Fastly-SIE
X-Pod-Name
X-Variation
X-Varnish-CookieHashed-On
Fastly-SWR
Is-Eu
X-TraceId
X-Ua-Device
Accept-Language
X-CS
X-Mvc-Supplant-OutputCached
NGX
X-Cache-Backend
AMP-Access-Control-Allow-Source-Origin
X-RPM
X-RPS
X-DW
X-DSS
X-Action
X-DB
X-DI
Edge-Cache
X-RSL
X-Wix-Viewer-Type
X-VC-Cache
X-NC
X-Up
CDN
X-Request-Start
X-Srv
X-Bip
X-Trace-ID
X-Optimistic-Header
X-CacheTTL
X-Thanos
X-Minions-Version
X-Generated-In
Ms-Author-Via
X-LB-ID
Pics-Label
X-LB-NoCache
X-Tb-Optimization-Total-Bytes-Saved
X-Tt-Logid
X-Qnm-Cache
X-M-Log
X-M-Reqid
X-Urbn-Context-Path
Locale
X-Urbn-Site-Id
Memory
Env
X-API-Version
Time
X-Cache-Config
X-Edge-Pop
WebServer
X-Refresh
X-Varnish-Ttl
GeoIp-Country-Code
X-Via-Popn
X-Via-Poph
X-Via-Popv
X-TA-CDN-Provider
Datacenter
X-Ec-Fail
X-Ec-GeoHdr
X-HA-Backend
X-CACHE-KEY
X-User
X-DC
X-DynaTrace-JS-Agent
X-Parent-Response-Time
Candidate-Md5Url
NtCoent-Length
X-Servedbyhost
Server-ID
X-Esi
X-Vc
X-MSEdge-Flight
X-Dynatrace
X-MSEdge-Features
X-ZONE
X-CLOUD-TRACE-CONTEXT
X-Cs
X-AK-Request-ID
Cdncip
WWW-Authenticate
Cdnsip
On-Server
X-Datadome
X-TX-ID
X-Fmm-Version
X-Varnish-Beresp-TTL
X-WADP-Cache
X-VCL-Version
Cluster
X-Clara-WADP
My-App
Esi-Enabled
Geoip-Latitude
X-App
X-Cache-Ttl
X-Fpc
Tracecode
X-LI-Proto
X-Var-Ttl
X-Pass-Why
X-URL
X-Li-Proto
T-Server
X-CUA
X-From
X-Webkit-Csp-Report-Only
X-Unique-ID
Lfy
X-Cache-PHP
C-Via
X-Service
X-Traceid
DataCenter
X-Fragments
X-FPC
X-B3-Spanid
Lang
X-Newrelic-Synthetics
X-Webkit-CSP-Report-Only
X-NODE
Cf-Int-Pingora-Origin-Digest
Fastly-Drupal-HTML
X-Vcl-Version
X-VC
Test
Target-Params
Geo-Info
X-Mcache
X-Render-Time
Resin-Trace
Proxy-Connection
M-TraceId
X-WP-CF-Super-Cache-Cache-Control
X-CSRF-TOKEN
X-Cache-Status-Check
X-WP-CF-Super-Cache
X-Provided-By
X-RAMCache
Hostname
Server-Id
X-Ha-Backend
X-LiteSpeed-Cache-Control
X-Api-Version
MIME-Version
X-COUNTRY
Permissions-Policy
X-ID
Servername
WZWS-RAY
X-ServedByHost
X-Httpd
X-Proxy-Cache-Info
Hit
GeoIP-Country-Code
X-Clientip
X-NGINX-Cache
X-Geo
X-Dynatrace-Js-Agent
X-Via-PopN
X-Cdn-Forward
X-Via-PopH
X-Pad
Producers
X-SB
FSS-Cache
X-Via-PopV
X-Edge-POP
ENV
X-Edge-Cache
X-Fastly-Backend-Reqs
Cache-Host
HIT
X-Oss-Request-Id
X-Pool
X-Platform-Cluster
X-Platform-Processor
X-Platform-Router
UCS
X-LiteSpeed-Tag
X-Udemy-Cache-App-Namespace
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
X-Oss-Storage-Class
X-Oss-Server-Time
Section-Io-Id
X-Ec-Custom-Error
X-Scale
Section-Io-Origin-Status
X-Info
S-Cnection
Section-Origin-Responded
X-Ucs
Section-Io-Origin-Time-Seconds
X-ElasticPress-Query
X-AIR-PT
Server-Hostname
X-Lb-Nocache
ServerName
URI
X-Acquia-Application-Trace
Uri
X-Acquia-Purge-Tags
X-HS-Status
X-Acquia-Application-UUID
PICS-Label
X-Lb-Id
X-Cache-CFC
X-BBC-Origin-Response-Status
MD5-Digest
Server-Ext
X-Check-Cacheable
Sever-Int
X-GoCache-CacheStatus
X-Dispatcher-Number
X-Cache-Expires
X-UP
X-Acquia-Site
X-Srcache-Fetch-Status
X-Srcache-Store-Status
Ohc-File-Size
X-Micro-Cache
IsBot
X-Nc
X-SIPLIST1
X-Via-Ucdn
Tcn
Server-Ttl
User-Agent
X-Fastly-Cache-Hits
X-RateLimit-Reset
Cteonnt-Length
Fastly-Backend-Name
X-Release
Cneonction
X-Swift-Error
X-Cdn-Request-ID
X-Dw-Trace-Id
X-Cms-Context
Wpo-Cache-Message
X-Fetch-By
Ngx
X-Akamai-ERPolicy
Wpo-Cache-Status
X-Akamai-ERRuleID
X-Yottaa-OS
Cf-Ipcountry
X-Backend-Host
Vha6-Origin
X-Newrelic-App-Data
X-Vcache
CF-Cached-On
X-B3-ParentSpanId
X-Cache-Ngx
Sid
X-Air-Pt
X-ServerName
X-HostName
Load-Balancing
Shield-Pop
X-IN-APIGATEWAY
X-Sentry-ID
X-Akamai-Pragma-Client-IP
X-CacheKey
X-IN-APIGATEWAYSSL
X-B3-Parentspanid
X-Apw-Access-Action
X-Apw-Access-Object
X-Via-CDN
X-Apw-Hits
Inserted-Into-Cache-At
X-Litespeed-Cache-Control
X-UA
X-Logging-Id
X-Shopify-Generated-Cart-Token
X-BCube-Filmed-By
X-Varnish-Authentication
CountryCode
EpKe-Alive
X-Last-Modified
X-Cache-ASPX
X-Apw-Access-Token
X-Snapshot-Date
X-Akamai-Request-ID
Req-ID
X-APP
X-Http-Count
X-Http-Duration-Ms
X-Te-Duration-Ms
X-Te-Count
X-Contensis-Viewer-Groups