Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-Cache-Status
Link
Accept-Ranges
CF-RAY
ETag
X-XSS-Protection
Expect-CT
Pragma
X-Powered-By
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
Alt-Svc
X-Served-By
X-Xss-Protection
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Cache-Status
X-Generator
X-Cacheable
Timing-Allow-Origin
X-Content-Security-Policy
X-Iinfo
Feature-Policy
Status
X-Envoy-Upstream-Service-Time
Content-Encoding
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
X-CDN
X-AspNetMvc-Version
P3p
Upgrade
X-Via
CF-Ray
X-Ws-Request-Id
Access-Control-Max-Age
X-Request-ID
Server-Timing
EagleId
X-Cache-Group
Keep-Alive
X-Turbo-Charged-By
Request-Context
X-Age
X-Server-Powered-By
X-UA-Device
X-Proxy-Cache
X-AH-Environment
X-Backend
X-Robots-Tag
X-Hacker
Report-To
X-Amz-Request-Id
Host-Header
X-Server
X-Amz-Id-2
Grace
X-LiteSpeed-Cache
X-Rq
X-Nginx-Cache-Status
X-Varnish-Cache
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-WebKit-CSP
X-Dns-Prefetch-Control
X-Page-Speed
X-Vhost
EagleEye-TraceId
X-OneAgent-JS-Injection
X-Amz-Version-Id
X-Ua-Compatible
X-Pingback
X-Dispatcher
X-Device
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
NEL
X-Cache-Spec
X-Host
X-Server-Id
Cf-Railgun
X-Node
X-Backend-Server
Accept-CH
X-Readtime
Surrogate-Control
X-Akam-SW-Version
Request-Id
X-Response-Time
X-HW
Xkey
X-Ruxit-JS-Agent
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Application-Context
Content-Location
Rating
X-Country
X-B3-TraceId
Accept-Ch-Lifetime
Accept-CH-Lifetime
X-Cache-Lookup
X-Cloud-Trace-Context
X-Trace
X-Url
X-Ac
X-Content-Type
Allow
X-TtlSet
X-Vname
X-PC
X-Varnish-TTL
X-Clacks-Overhead
X-Mod-Pagespeed
Edge-Control
X-FastCGI-Cache
X-ESI
X-Server-Name
Fastly-Restarts
Cache-Tag
Service-Worker-Allowed
X-VARITI-CCR
X-Rack-Cache
Verso
X-Element-Page-Cache
X-Aws-Lambda-Call-Status
X-MS-InvokeApp
X-Upstream
MS-Author-Via
X-GitHub-Request-Id
X-Amz-Rid
X-Vcap-Request-Id
Public-Key-Pins
X-Dw-Request-Base-Id
X-Cached
X-Client-IP
X-D2id
X-Abt-Application-Version
X-Cache-TTL
X-Cnection
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
X-Px
X-Origin-Cache
Arr-Disable-Session-Affinity
X-Country-Code
RTSS
X-Navigation-Version
Access-Control-Request-Method
X-Powered-By-Plesk
X-Goog-Hash
X-NF-Request-ID
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-Instrumentation
X-Exp-Variant
X-Exp-Id
X-Cdn-Fetch
X-Use-Magma
X-GoogleNews-Bot
X-Kinja-Server
X-Kinja-Revision
X-Kinja-Build
X-Kinja
Accept-Ch
X-Powered-CMS
X-Version
AR-SID
AR-PoweredBy
AR-ATIME
AR-CACHE
AR-Request-ID
X-Language
X-Sol
X-Middleton-Display
Display
Pagespeed
X-Middleton-Response
Response
X-Amz-Server-Side-Encryption
X-MSEdge-Ref
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-LLID
X-Edge-Location-Klb
X-Kinsta-Cache
X-Edge
Nginx-Cache
X-TTL
Mrf-Cache-Status
X-B3-TraceId-Primal
MRF-Tech
X-Template
X-Protected-By
X-RateLimit-Remaining
X-Shield-Request-Id
X-Jurisdiction
X-HP-Trace-Id
X-HP-Webp
TCN
X-T
X-Forwarded-For
X-Content-Security-Policy-Report-Only
S
X-Id
X-Mg-S
Content-MD5
X-Aspnetmvc-Version
Edge-Cache-Tag
Fastcgi-Cache
X-Mid
Realpath
X-CST
SPRequestDuration
SPIisLatency
Front-End-Https
X-Recruiting
X-MCACHE
X-Request-Processing-Time
X-Request-Received
X-Ttl
Filters
X-Pinterest-Rid
Pinterest-Version
Pinterest-Generated-By
Server-Node
X-Ua-Browser
X-Content
X-Ab
Server-Name
X-DynaTrace
X-Frontend
X-NWS-LOG-UUID
X-HS-Cache-Config
X-HS-Content-Id
X-HS-Hub-Id
SPRequestGuid
X-SharePointHealthScore
X-HS-Combine-CSS
X-Correlation-Id
X-Yandex-Sdch-Disable
X-Ezoic-Cdn
X-Parallel-Accel
X-ECACHE
Fusion-Deployment-Id
Fusion-Source
X-Ser
Fusion-Content-Id
Fusion-Template-Id
Fusion-Content-Source
Fusion-Component-Id
X-Hits
Alternate-Protocol
X-Cache-Key
X-Tt-Trace-Tag
X-Tt-Trace-Host
MicrosoftSharePointTeamServices
X-Buckets
X-Content-Options
Cache-Tags
X-Page-Id
X-B3-Sampled
Host
Charset
X-Kong-Upstream-Latency
X-Git-Hash
X-Kong-Proxy-Latency
Cleartype
X-Fastly-Request-Id
X-Www-Served-By
X-Ruxit-Js-Agent
X-Geo-Country
X-DIS-Request-ID
X-Daa-Tunnel
X-Content-Digest
X-Accel-Expires
X-Amzn-Trace-Id
X-Debug-Info
X-Amz-Replication-Status
Filterid
X-XRDS-LOCATION
X-Varnish-Age
X-Az
X-AppVersion
X-Ratelimit-Limit
X-Activity-Id
X-FB-Debug
X-Hostname
X-Forwarded-Proto
X-Upgrade-Enabled
X-VCache
TP-Cache
TP-L2-Cache
X-Rid
X-N
X-Grace
Cross-Origin-Opener-Policy
Access-Control-Allow-Method
X-Origin-Server
X-WebKit-CSP-Report-Only
X-Nginx-Upstream-Cache-Status
X-LB-Cache
X-F-Cache
X-Mobile-URL
ServerID
X-Flags
X-Providence-Cookie
X-Aspnet-Duration-Ms
X-Is-Crawler
X-Request-Guid
X-Route-Name
X-Whom
X-Goog-Generation
X-TT
X-Goog-Storage-Class
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-App-Environment
X-Varnish-Grace
X-Tb
Viewport
X-Distributor
Node
X-Seen-By
Payment
X-FW-Static
X-FW-Server
X-FW-Dynamic
X-FW-Serve
X-Type
X-FW-Type
X-FW-Hash
X-Server-ID
DC
Paypal-Debug-Id
X-App-Server
X-User-Agent
X-Origin-Upstream-Status
X-NGENIX-Cache
Fastcgi-Useragent
X-Cache-Control
Country
Accept-Charset
X-Wix-Request-Id
X-Cache-Rule
X-Logged-In
X-Litespeed-Cache
Version
X-Cache-Age
X-Microsite
X-Request-Handler-Origin-Region
X-Via-JSL
X-Webkit-CSP
X-Drupal-Cache-Tags
Referer-Policy
X-DataDome
X-Browser-Type
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Cluster-Name
X-Varnish-Backend
X-B-Cache
X-Signature
Refresh
X-Contextid
X-Node-Name
Cache-Status
X-Load-Cache
Access-Control-Request-Headers
X-Mobile
SD-X-WS
X-Tec-Api-Origin
X-Response-Served-From
X-Tec-Api-Version
Amp-Access-Control-Allow-Source-Origin
X-Tec-Api-Root
X-Original-Request-Id
X-Cache-Action
X-Is-Bot
X-Real-IP
X-Rendered-As
X-Vgn-Hpd-Reason
X-Page-View
X-Proxy-Cache-Status
X-Cache-Expired-At
X-Jobs
X-Cacheable-TTL
X-ProcessESI
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-UUID
X-Revision
X-RemovedCookies
X-B
X-Debug
NGB
X-IPLB-Instance
X-Instance
X-Proxy
X-Ratelimit-Reset
X-Device-Type
X-Rule
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Fastly-Request-ID
Akamai-GRN
X-Cache-Time
X-Drupal-Cache-Contexts
Surrogate-Key
X-G
X-Framework
X-Debug-IsPreview
X-Debug-IsConnected
CF-IPCountry
X-Fastcgi-Cache
X-FW-Version
X-Air-Trace-Id
X-Air-Source
X-Air-Hostname
SID
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
DynaTrace
Liferay-Portal
X-Oracle-Dms-Rid
X-Azure-Ref
X-Oracle-Dms-Ecid
X-PressLabs-Stats
X-Nginx-Cache
X-Presslabs-Stats
GEO-INFO
Healthy
X-Ms-Version
Count-Hit
X-Cache-Operation
X-Ms-Request-Id
Frame-Options
X-Source
X-Accel-Buffering
X-Oneagent-Js-Injection
X-RTag
Uber-Trace-Id
X-CDN-Forward
Ms-Operation-Id
MS-CV
X-EdgeConnect-Cache-Status
X-APP-VERSION
X-Environment-Context
X-L-Path
Countrycode
X-Tumblr-Pixel-1
X-XRDS-Location
Xserver
X-Tumblr-Pixel-0
X-Tumblr-User
X-Tumblr-Pixel
X-Cache-Hit
X-Varnish-Server
X-Zen-Fury
X-Cache-NGX
X-Backend-Name
X-Mode
X-Region
Cross-Origin-Window-Policy
Ec-Rule-Version
X-IPS-LoggedIn
X-Forwarded-Host
X-Servername
Protected
Backend
X-Content-Powered-By
X-Cache-TTL-Remaining
X-RN-RSRV
X-Rewrite-Enabled
X-UPSTREAM-Address
X-Cache-Type
Meta-Geo
X-Detected-As
X-SaId
X-JoinUs
X-Sorting-Hat-ShopId
X-Routing-Service
X-Sql-Count
X-Cache-Server
X-Tid
X-Sql-Duration-Ms
X-Sorting-Hat-PodId
X-Debug-Cache
Section-Io-Cache
X-Extlb
Country-Code
X-ShopId
Decoy-Debug-Status
X-Cache-Grace
X-ShardId
X-Alternate-Cache-Key
X-Generation-Time
Apigw-Requestid
X-Varnish-Beresp-Grace
X-Uri
Eomportal-Instance
Decoy-Debug-TTL
X-Hosted-By
X-Proxied
X-Human
Decoy-Debug-Key
X-Zipkin-Id
X-Redis-Cache
X-Shopify-Stage
X-ApacheServer
Fastly-SSL
X-BYPASS-REASON
Mn-Server-Ip
Cache-Tv-Group
Url
Cache-Name
X-UA-Device-Type
X-ProxyCache-Key
X-ServerID
X-NCache
X-Origin-Date
X-PHP-Backend
X-Soup
X-FB-TRIP-ID
X-PERF
X-ProxyCache-Status
X-No-Session
X-Storage
X-Via-Fastly
X-Site-Version
X-Format
X-Status
X-Microcachable
Selected-Fe
X-Say-TTL
TWC-Connection-Speed
TWC-GeoIP-Country
TWC-Device-Class
Property-Id
X-Proxy-Build
X-Say-Cacheable
X-SayCDN-TTL
X-Section
X-PCL
Webcakes-App-Name
X-Akamai-Edgescape
X-Adobe-Loc
X-NYM-Debug-Backend
X-Web-Node
X-Timing-Wait
X-Cluster-Node
X-Cache-Host
X-OCL
X-Access
TWC-Locale-Group
X-Server-W
TWC-Privacy
X-Origin-Hint
Webcakes-Region
Webcakes-App-Version
TWC-GeoIP-LatLong
X-Adobe-Content
X-Content-Age
Azure-InstanceId
OT-Force-Account-Verify
X-Hl-Ver
X-Hyper-Cache
X-R9-Blue-Green-Version
DB-Nickname
Azure-Version
X-Pubstack
Azure-RegionName
Azure-SlotName
X-Varnishpool
Azure-SiteName
Content-Secure-Policy
X-Be
X-RateLimit-Limit
X-TIME
CDN-Cache
CDN-EdgeStorageId
X-LSADC-Cache
X-Ua
SRV
CDN-PullZone
CDN-CachedAt
CDN-RequestCountryCode
CDN-Uid
CDN-RequestId
X-Ratelimit-Remaining
X-Generated-By
LB
X-NewRelic-App-Data
X-Trace-Id
X-Azure-Ref-OriginShield
WPO-Cache-Message
WPO-Cache-Status
Content-Disposition
X-Webkit-Csp
X-Cached-By
X-Dc
Source
Cache
X-Nginx-Cache-Key
X-Unique-Id
X-Bc-Bl
X-LAGOON
X-SRV
X-App-Version
Cache-Hits
X-Auto-Login
Retry-After
Xet-Cookie
X-TT-LOGID
X-GEO
X-Origin-TTL
X-Origin-CC
X-HTML-Minification-Powered-By
Mime-Version
X-Varnish-Hits
X-Loop
X-Varnish-Hostname
X-TNCMS
X-Platform-Server
X-Amz-Meta-S3cmd-Attrs
HostName
X-S-Maxage
Onion-Location
X-ECache
X-Akamai-Transformed
X-Cache-Remote
X-Xfnlog-Site
X-CSRF-Token
X-Cdn
X-Correlation-ID
X-Tumblr-Pixel-2
Web-Mar-Node
X-Tumblr-Pixel-3
X-Cache-Tags
X-CLOUD-TRACE-CONTEXT
X-Proto
Webserver
X-Varnish-Cache-Hits
Upgrade-Insecure-Requests
X-Cache-Var-Map
X-Cache-Var
X-Request-Time
ServedBy
X-Endurance-Cache-Level
X-AOL-HN
X-Time-Microsecs
X-Tenant
N-Cache
X-Edge-Location
X-Time
X-VWS-Id
X-EC-Lua
X-LJ-Flow-ID
X-AWS-Id
From-Origin
WP-Super-Cache
X-Request-Host
X-GG-Cache-Date
X-FireWall-Port
CloudFront-Viewer-Country
X-Origin-Response-Time
X-Via-NSCOPI
X-Mg-Request-UUID
X-Amz-Apigw-Id
X-PHP-Host
X-Amzn-RequestId
X-Labrador-Cache-Channel
X-SVT-ORM-RULES
V-Age
X-A
Sslversion
Surrogated-Key
User-Cache-Control
X-Vdms-Path
Expiry
Fastcgi-X-Cache-Version
X-VG-WebCache
DSUID
DCR-Processing-Time-Ms
BehaviorPad-Version
A
DCR-Decision-By
Meta-Geo-Continent
Mobile-Detection-Method
X-TIM-N
X-SVT-ORM-VERSION
Redirect-Candidate
X-V-Cache
X-Vdms-Version
Odigeo-Trace-Id
Origin
Pramga
Rendered-Blocks
X-B-Cookie
X-Ig-Push-State
X-NAPM-TraceId
X-Session-Fingerprint
X-SD-PageType
X-Shop-Environment
X-Vtex-Remote-Cache
X-Ftr-Request-Id
X-Slack-Backend
X-Gen-Mode
X-Hnp-Log
X-ND-Cache
X-Orig-Expires
X-ScT
X-S-Cookie
X-Processor
X-Rojux
Xc-Version
X-Planisys-CDN-TTL
X-PAYTM-SRV-ID
X-PBS-Appsvrname
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Forwarded-Path
X-External-Request-Id
X-SRCache-Key
X-ARC
X-S
X-Block-Status
X-Application
X-Aed
X-A-Dam
X-A-Dcw
X-A-Dgt
X-A-Wwc
X-Cache-NE
X-CF-Lambda-Fn
X-D
X-Vtex-Processado-Em
X-Destination
X-Developer
X-Connection-Hash
X-Conf
X-CF-Lambda-Version
X-Ckpd-Fst-Backend
X-Cluster
X-A-Ccd
X-Cache-Date
X-M-Log
X-M-Reqid
X-B3-SpanId
Nel
X-Qnm-Cache
X-Cache-Enabled
X-Handled-By
X-NWS-UUID-VERIFY
X-RCS-CacheZone
X-MP-GENERATED-AT
X-Epic-Correlation-Id
Origin-CC
X-Fastly-Cache
X-Device-Os
Origin-EX
X-Forwarded-Site
X-Hash
Fastcgi-Cache-TTL
X-Li-Fabric
Gh-Request-Id
Host-ID
Vix-Hermes-Req-Id
X-Gdpr
L
X-Fetched-On
Release
X-Server-IP
X-Zone
X-Cache-Bucket
True-Client-Country-4JS
X-Served-From
Wxu-Next-Commit
X-Accel-Expires-Debug
Wxu-Next-Region
Wxu-Next-Hostname
Traceparent
X-Cache-Info
X-Scheme
X-Core-Mission
X-Li-Pop
X-Aicache-OS
Ssr
State
X-Cdn-Srv
Svr
X-CACHE-KEY
X-Date
X-Geo-Header
X-Origin-Time
X-Owner
X-Policy
X-Varnish-Beresp-Status
CacheControlHeader
X-Rocket-Nginx-Serving-Static
X-Mvc-Supplant-Cachable
AKAMAI
Fastly-Drupal-Html
X-Old-Content-Length
X-Origin-Expires
X-Nyt-Route
X-NodeID
Arc-Country
X-Proxy-Upstream
Server-Info
CDCHOST
X-Men
X-Webstats-RespID
X-Skip-Cache
X-Location
X-LI-UUID
Cmstype
X-Sucuri-ID
X-Locale
Cmsid
X-Sucuri-Cache
X-VServer
X-Magnolia-Registration
AMP-Access-Control-Allow-Source-Origin
Environment
X-Cache-Id
X-Rocket-Build-Number
X-Cdn-Origin
X-Platform
X-RateLimit-Remaining-Second
X-Request-Start
X-VarnishDD-TTL
X-Adobe-Source
X-Req
X-VC-Cache
X-Region-Sid
X-Reqid
X-RateLimit-Limit-Second
X-Branch-Name
X-Bip
X-BBC-Edge-Cache-Status
X-Backend-State
X-Cache-Debug
X-Datadog-Sampling-Priority
X-GeoIP
X-Generated-On
X-Gamma-Serve
X-Node-Id
X-GeoIP-City
X-Gzip
X-Level-Front-Cache
X-Irp-Debug
X-HS-Content-Campaign-Id
X-HN
X-Fastly-Backend
X-Eu-Site
X-Core-Value
X-Request-URI
X-Viewer-Country
X-CGP
X-Csrf-Jwt
X-Datadog-Parent-Id
X-Esi-Check
X-Envoy-Decorator-Operation
X-Developers
X-Datadog-Trace-Id
X-VG-TLSProxy
X-ATG-Version
Machine
Mail-Subject
Locid
L5d-Success-Class
TDXMobile
X-Sigma-Backend
X-Sigma
X-Thanos
X-Storefront-Renderer-Rendered
Thinkindot-CacheControl
X-TH-Server
Apple-News-Services-Handled
Thinkindot-Control
Thinkindot-CacheControl-Type
HA-Ipaddr
X-UnsetCookies
Req-Svc-Chain
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
X-Sn-Servicetimems
PFcat
Apple-News-Services-Request-Url
We-Hiring
Fastly-GeoIP-CountryCode
X-TrackingId
Ha-Gx-Prefs
Web-Mar-Region
X-Thinkindot-L3
Server-Host
X-DefElseHash
NM-Fastcgi-Cache
X-DefHash
X-DPWN-IS-SECURE
X-FC-Vary-Parameters
Cf-Device-Type
Fastly-SIE
X-Is-Gdpr
X-JWT-State
X-Loc
X-Qloud-Router
X-Has-Esi
Fastly-SWR
X-Response-By
X-Rebelmouse-Cache-Control
Memcached
X-Worker
Is-Eu
NGX
Platform
X-Varnish-Remaining-TTL
X-Varnish-CookieINHashed-On
X-Backend-TTL
X-Varnish-CookieHashed-On
X-Variation
X-Amzn-Remapped-Content-Length
Adler-Geo
X-Pod-Name
X-Origin
X-NU-AKA-ACS-Version
X-Rebelmouse-Surrogate-Control
X-Xrds-Location
X-Datadome
X-Cache-Config
X-GeoIP-Country-Code
X-GeoIP-Region-Code
X-Tx-Id
X-Mvc-Supplant-OutputCached
X-Ua-Device
X-CS
X-API-Version
X-LB-ID
X-NC
S-Rt
X-TA-CDN-Provider
CDN
X-Up
X-Generated-In
X-Varnish-Beresp-Ttl
Magicmarker
Pics-Label
X-TraceId
Datacenter
Kp-EeAlive
X-Trace-ID
X-Restarts
X-Tt-Logid
Ms-Author-Via
Candidate-Md5Url
X-Tb-Optimization-Total-Bytes-Saved
X-Vc
Env
X-Edge-Pop
X-Akamai-Request-ID2
NtCoent-Length
Time
Memory
X-LB-NoCache
X-Http-Reason
X-DynaTrace-JS-Agent
X-Action
X-Via-Popv
X-Optimistic-Header
X-DI
X-DSS
X-Via-Popn
X-Via-Poph
WWW-Authenticate
X-Varnish-Ttl
X-Refresh
WebServer
X-DW
X-DB
X-RSL
GeoIp-Country-Code
X-Cache-Backend
X-Wix-Viewer-Type
X-RPS
Edge-Cache
On-Server
X-RPM
X-Varnish-Beresp-TTL
X-Parent-Response-Time
Esi-Enabled
X-Srv
X-Minions-Version
X-DC
X-CacheTTL
Accept-Language
X-Cs
X-Service
X-Dynatrace
X-Servedbyhost
X-Esi
C-Via
X-Unique-ID
X-Cache-PHP
X-HA-Backend
X-TX-ID
X-MSEdge-Flight
X-MSEdge-Features
X-Newrelic-Synthetics
X-Urbn-Context-Path
Server-ID
Locale
X-Urbn-Site-Id
X-ZONE
X-Cache-Status-Check
X-Ec-Fail
X-User
X-Ec-GeoHdr
X-Li-Proto
X-Render-Time
X-VCL-Version
X-App
X-Cache-Ttl
X-FPC
X-B3-Spanid
X-URL
Server-Id
X-Vcl-Version
X-LI-Proto
X-Fpc
Test
X-Webkit-Csp-Report-Only
X-Traceid
Proxy-Connection
X-LiteSpeed-Cache-Control
Cdnsip
Cdncip
X-AK-Request-ID
X-Pass-Why
X-Info
X-Webkit-CSP-Report-Only
X-NODE
X-AIR-PT
Geoip-Latitude
My-App
X-Clara-WADP
X-Fmm-Version
X-WADP-Cache
Cluster
Geo-Info
Tcn
X-Clientip
X-Mcache
X-Oss-Request-Id
X-Oss-Object-Type
X-CUA
M-TraceId
HIT
Cache-Host
X-Oss-Server-Time
Tracecode
X-Oss-Hash-Crc64ecma
UCS
X-Var-Ttl
Resin-Trace
X-Oss-Storage-Class
Fastly-Drupal-HTML
X-LiteSpeed-Tag
X-HostName
Lfy
X-From
T-Server
X-Ha-Backend
Cf-Int-Pingora-Origin-Digest
S-Cnection
X-CSRF-TOKEN
Lang
X-Fragments
X-ServedByHost
DataCenter
X-ID
Hostname
User-Agent
GeoIP-Country-Code
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
Target-Params
X-Via-PopV
X-Via-PopH
X-Via-PopN
Ohc-File-Size
Fastly-Backend-Name
Hit
X-Micro-Cache
X-Pad
X-Geo
X-Dynatrace-Js-Agent
X-Backend-Host
X-RAMCache
MIME-Version
X-BBC-Origin-Response-Status
X-Edge-POP
X-Cdn-Forward
X-Release
ENV
X-ElasticPress-Query
X-VC
Load-Balancing
X-NGINX-Cache
Section-Origin-Responded
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
X-Check-Cacheable
X-BCube-Filmed-By
X-Api-Version
X-Edge-Cache
X-APP
Section-Io-Id
Lb
X-Proxy-Cache-Info
X-HS-Status
X-UP
Permissions-Policy
X-Lb-Nocache
X-Httpd
EpKe-Alive
Servername
URI
X-ServerName
X-Ucs
X-Fastly-Backend-Reqs
X-Provided-By
CPC-Cache
X-GoCache-CacheStatus
Producers
FSS-Cache
X-WA-Info
X-WA
Uri
Server-Ttl
ServerName
PICS-Label
CPC-Age
Cache-Key
Path
VNS-Age
X-Amz-Meta-Cb-Modifiedtime
VNS-Cache
X-TRACE-ID
X-Wikidot-Backend
X-Wikidot-Static-Cache
WZWS-RAY
X-ES-SERVER
Cdn
X-Nc
Cneonction
X-B3-ParentSpanId
Cteonnt-Length
Ohc-Cache-HIT
X-RateLimit-Reset
X-Pool
X-Lb-Id
Vha6-Origin
X-Fastly-Cache-Hits
X-Cache-CFC
X-SB
X-Cdn-Request-ID
X-Udemy-Cache-App-Namespace
X-Dw-Trace-Id
X-Apw-Hits
X-Platform-Router
X-Platform-Processor
X-Acquia-Application-Trace
X-Acquia-Application-UUID
X-Acquia-Site
X-Acquia-Purge-Tags
X-Akamai-ERRuleID
X-Contensis-Viewer-Groups
X-Cache-ASPX
Shield-Pop
X-Akamai-Request-ID
X-Snapshot-Date
X-Akamai-ERPolicy
X-Platform-Cluster
X-Ec-Custom-Error
Cf-Ipcountry
X-Newrelic-App-Data
X-PJAX-URL
Pagetype
X-Apw-Access-Action
X-Swift-Error
X-Vcache
X-Yottaa-OS
X-Cms-Context
X-Apw-Access-Object
X-Apw-Access-Token
CF-Cached-On
X-Cache-Ngx
Sid
X-Air-Pt
X-CacheKey
CountryCode
X-CCDN-Origin-Time
X-Shopify-Generated-Cart-Token
X-CCDN-CacheTTL
X-Akamai-Pragma-Client-IP
Req-ID
X-UA
MD5-Digest
X-Last-Modified
X-Te-Count
X-Http-Duration-Ms
X-Http-Count
X-Via-Ucdn
X-Te-Duration-Ms
X-Miniprofiler-Ids
X-Hcs-Proxy-Type
X-Varnish-Authentication
X-Sentry-ID
Ngx
X-Logging-Id