Threat Level: green Handler on Duty: Rob VandenBrink

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
X-Powered-By
Pragma
X-XSS-Protection
CF-RAY
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
Alt-Svc
P3P
X-Cache-Hits
X-UA-Compatible
X-Xss-Protection
CF-Ray
X-Served-By
X-Download-Options
X-Timer
X-Request-Id
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
Access-Control-Allow-Credentials
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
X-Drupal-Cache
X-Generator
X-Cache-Status
X-Check
X-Cacheable
X-DNS-Prefetch-Control
X-Envoy-Upstream-Service-Time
X-FRAME-OPTIONS
X-Request-ID
Timing-Allow-Origin
X-Iinfo
X-Drupal-Dynamic-Cache
X-Dns-Prefetch-Control
Feature-Policy
X-Content-Security-Policy
Content-Encoding
Access-Control-Expose-Headers
Upgrade
X-XSS-PROTECTION
Server-Timing
Status
X-CDN
X-AspNetMvc-Version
Access-Control-Max-Age
X-Amz-Request-Id
Request-Context
X-Amz-Id-2
X-Via
X-Turbo-Charged-By
X-AH-Environment
X-Backend
X-Cache-Group
X-Robots-Tag
Cf-Edge-Cache
Host-Header
Keep-Alive
X-Hacker
X-Proxy-Cache
X-UA-Device
X-Server
X-Rq
X-Vhost
X-Server-Powered-By
Allow
X-Age
X-Varnish-Cache
X-Ws-Request-Id
X-Dispatcher
X-Amz-Version-Id
EagleId
P3p
Nel
Grace
Cf-Apo-Via
X-LiteSpeed-Cache
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Page-Speed
X-Device
Cf-Railgun
EagleEye-TraceId
X-Aws-Lambda-Call-Status
X-Swift-CacheTime
X-Swift-SaveTime
X-Pingback
X-OneAgent-JS-Injection
Ali-Swift-Global-Savetime
X-Host
X-Node
X-WebKit-CSP
Accept-CH
X-CST
X-Backend-Server
X-Server-Id
Surrogate-Control
X-Cache-Lookup
X-Nginx-Cache-Status
X-Readtime
Permissions-Policy
X-Akam-SW-Version
X-Nginx-Upstream-Cache-Status
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
Request-Id
X-Application-Context
X-Content-Security-Policy-Report-Only
Accept-CH-Lifetime
X-Cloud-Trace-Context
X-Ua-Compatible
X-Trace
X-Response-Time
X-HW
X-Edge
Content-Location
X-Clacks-Overhead
X-Mod-Pagespeed
Xkey
X-Ruxit-JS-Agent
X-Midtier
Rating
Accept-Ch-Lifetime
X-ESI
X-Litespeed-Cache
X-Url
X-Amz-Server-Side-Encryption
Accept-Ch
X-Mcache
X-ECACHE
X-Upstream
X-Country
X-Oneagent-Js-Injection
X-Vcap-Request-Id
Cache-Tag
X-D2id
X-MS-InvokeApp
X-Ruxit-Js-Agent
Verso
X-Kinja
X-Cdn-Fetch
X-Kinja-Build
X-Exp-Id
X-Exp-Variant
X-Element-Page-Cache
X-GoogleNews-Bot
X-Kinja-Server
X-Use-Magma
X-Kinja-Revision
X-Rack-Cache
X-Vname
X-PC
X-TtlSet
Edge-Control
X-Powered-By-Plesk
RTSS
Fastly-Restarts
X-Ac
X-WebKit-CSP-Report-Only
X-VARITI-CCR
Origin-Trial
X-Cache-TTL
X-Navigation-Version
X-Abt-Application-Version
X-Country-Code
Service-Worker-Allowed
X-Goog-Hash
X-Cached
X-Ttl
X-Middleton-Display
Display
Pagespeed
X-Sol
X-Amz-Rid
X-GitHub-Request-Id
X-Browser-Type
Cross-Origin-Opener-Policy
X-Dw-Request-Base-Id
X-Content-Type
X-SharePointHealthScore
SPRequestGuid
X-Varnish-TTL
X-Server-Name
X-Mg-S
X-Amzn-Trace-Id
X-Powered-CMS
X-Erf-Bev-Bev-Is-Generated
X-Kraken-Loop-Name
Response
X-Erf-Bev-Bev
X-Middleton-Response
Arr-Disable-Session-Affinity
X-Instrumentation
X-Server-Lifecycle-Phase
AR-ATIME
AR-PoweredBy
AR-Request-ID
AR-SID
SPRequestDuration
SPIisLatency
X-Cache-Key
X-Kinja-CCPA
X-NF-Request-ID
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-Webkit-CSP
X-Times
X-B3-TraceId
X-B3-Traceid
X-Version
X-NWS-LOG-UUID
AR-CACHE
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Jurisdiction
X-HP-Trace-Id
X-HP-Webp
X-Pinterest-Rid
Pinterest-Version
Pinterest-Generated-By
X-Accel-Expires
Cache-Tags
X-T
X-Fastly-Request-ID
X-Cnection
Cache-Status
Front-End-Https
Nginx-Cache
Edge-Cache-Tag
X-MSEdge-Ref
X-Client-IP
X-Aspnetmvc-Version
X-Hits
X-FastCGI-Cache
X-Ser
X-Px
Public-Key-Pins
Mrf-Cache-Status
X-B3-TraceId-Primal
MRF-Tech
X-Recruiting
Payment
X-LLID
X-RateLimit-Remaining
X-Request-Processing-Time
X-Frontend
X-Request-Received
Server-Node
X-Ua-Browser
X-Fastcgi-Cache
X-Erf-Stays-Pdp-Viaduct-Migration-Web
X-Shield-Request-Id
X-DIS-Request-ID
S
X-Server-ID
TP-Cache
X-RateLimit-Limit
X-GUploader-UploadID
X-Goog-Metageneration
Access-Control-Request-Method
MicrosoftSharePointTeamServices
X-HS-Content-Id
X-HS-Hub-Id
X-HS-Combine-CSS
X-HS-Cache-Config
X-Amzn-RequestId
X-Content-Digest
X-Amz-Apigw-Id
X-LB-Cache
Content-MD5
X-Request-Handler-Origin-Region
X-Protected-By
X-Microsite
X-Distributor
TP-L2-Cache
Realpath
X-Ratelimit-Remaining
X-Page-Id
X-FB-Debug
Access-Control-Allow-Method
Accept-Charset
Fastcgi-Cache
X-Ezoic-Cdn
X-Forwarded-For
X-Cluster-Name
X-PressLabs-Stats
X-Geo-Country
X-Rid
X-Hostname
X-B3-Sampled
X-Correlation-Id
X-Seen-By
X-Webkit-Csp
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Aspnet-Version
X-Ua-Device
X-Ratelimit-Limit
Cleartype
X-Envoy-Decorator-Operation
Referer-Policy
X-Mobile
X-Newrelic-App-Data
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Goog-Generation
Cross-Origin-Resource-Policy
TCN
DC
X-Daa-Tunnel
X-Content-Options
X-Debug-Info
Count-Hit
X-Varnish-Backend
X-Origin-Cache
X-Logged-In
X-Contextid
X-Varnish-Grace
X-Request-Guid
X-Grace
X-Providence-Cookie
X-Flags
X-IPS-LoggedIn
X-Git-Hash
X-Is-Crawler
X-Fb-Rlafr
X-Aspnet-Duration-Ms
Surrogate-Key
X-App-Server
X-Revision
X-Route-Name
X-Amz-Replication-Status
X-App-Environment
X-Hosted-By
X-Azure-Ref
X-Origin-Server
X-TTL
X-TT
Frame-Options
X-Amz-Meta-S3cmd-Attrs
X-XRDS-Location
X-Webkit-CSP-Report-Only
X-Forwarded-Proto
X-Client-Ip
X-Edge-Location-Klb
X-Kinsta-Cache
Alternate-Protocol
X-Wix-Request-Id
WPO-Cache-Message
Retry-After
WPO-Cache-Status
X-Whom
Healthy
X-F-Cache
X-RateLimit-Reset
Charset
X-Akamai-Edgescape
X-Magnolia-Registration
Viewport
MS-Author-Via
Section-Io-Cache
X-Backend-Name
Paypal-Debug-Id
X-B
X-Proxy-Cache-Info
SRV
X-COUNTRY
X-Az
X-AppVersion
Amp-Access-Control-Allow-Source-Origin
X-Activity-Id
X-ECache
X-Id
X-Language
ServerID
X-Rule
X-Response-Served-From
X-Instance
Host
X-Cache-Rule
Akamai-GRN
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
SD-X-WS
X-Http-Reason
X-ARC
X-Original-Request-Id
X-N
X-App-Version
Filterid
X-EdgeConnect-Cache-Status
X-Akamai-Request-ID2
X-Rocket-Nginx-Serving-Static
X-Cache-Grace
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Edge-Location
Protected
X-User-Agent
X-Status
X-Www-Served-By
Front
X-UUID
X-Varnish-Age
X-FW-Server
X-FW-Serve
X-FW-Type
X-Is-Bot
Fastly-SIE
X-FW-Static
X-Environment-Context
X-Varnish-Server
From-Origin
Fastly-SWR
X-Cacheable-TTL
X-Jobs
X-Load-Cache
X-FW-Dynamic
X-Framework
X-FW-Hash
X-FW-Version
X-Rendered-As
Server-Name
X-Unique-Id
X-Region
X-L-Path
X-Page-View
X-Cache-Time
Country
X-Cache-Control
X-Trace-Id
X-Adobe-Content
X-Cache-Age
X-Adobe-Loc
X-Type
Access-Control-Request-Headers
X-Tumblr-Pixel
X-Tumblr-Pixel-1
X-Tumblr-User
X-Tumblr-Pixel-0
X-RemovedCookies
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
X-G
X-ProcessESI
X-Datadog-Trace-Id
X-DataDome
X-Proxy
Refresh
X-Vcache
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Time
X-CDN-Forward
X-Datadog-Sampled
X-Mg-Request-UUID
X-Amzn-Remapped-Content-Length
X-Debug-IsConnected
X-Source
X-Debug-IsPreview
Content-Disposition
X-Drupal-Cache-Tags
Version
X-B-Cache
X-Signature
Accept-Language
X-Varnish-Ttl
X-Oracle-Dms-Ecid
Backend
X-WP-CF-Super-Cache-Cache-Control
Xet-Cookie
X-WP-CF-Super-Cache
X-Oracle-Dms-Rid
Countrycode
X-Generated-By
X-HTML-Minification-Powered-By
CF-IPCountry
X-Erf-Web-Scheduler
X-DynaTrace
Webserver
X-DynaTrace-JS-Agent
X-ID
X-XRDS-LOCATION
X-Nginx-Cache
X-Xrds-Location
X-Httpd
X-Servername
Url
X-Mode
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Upgrade-Enabled
GEO-INFO
X-Template
X-Device-Type
X-Storage
X-NYM-Debug-Backend
X-Content-Age
S-Rt
X-Director
X-Tb
Xserver
Onion-Location
X-UPSTREAM-Address
X-Content-Powered-By
X-Proto
Meta-Geo
X-SayCDN-TTL
X-GeoCode
Azure-Version
X-LAGOON
X-Cache-Action
Locale
Load-Balancing
Filters
X-ServerID
X-GeoCountry
X-JoinUs
X-SaId
X-Say-Cacheable
X-Urbn-Context-Path
X-Urbn-Site-Id
X-Rewrite-Enabled
X-Varnish-Cache-Hits
X-Say-TTL
Azure-InstanceId
Fastcgi-Useragent
Azure-RegionName
X-Cache-Operation
Azure-SlotName
Azure-SiteName
X-Nf-Request-Id
X-Cluster-Node
Uber-Trace-Id
X-Container-Uri
X-Git-Commit
X-Labrador-Cache-Channel
X-PHP-Host
X-VC-Cache
X-Varnish-Hostname
X-Forwarded-Host
X-Tt-Logid
X-Soup
X-RM-Cache-TTL
X-Served-From
X-Ms-Version
X-Ms-Request-Id
OT-Force-Account-Verify
Web-Mar-Node
X-Sql-Count
X-Sql-Duration-Ms
X-VCT
X-Cache-Server
X-Detected-As
X-Logging-Id
X-Generation-Time
X-Adobe-Source
X-RCS-CacheZone
X-Sucuri-Cache
X-R9-Blue-Green-Version
X-Sucuri-ID
X-LSADC-Cache
DB-Nickname
X-Skip-Cache
X-Debug
X-Extlb
Mn-Server-Ip
X-Routing-Service
X-FB-TRIP-ID
Property-Id
TWC-Locale-Group
TWC-GeoIP-Country
Webcakes-Region
TWC-Privacy
Webcakes-App-Version
X-Zen-Fury
TWC-Device-Class
X-Lambda-Id
Webcakes-App-Name
X-Origin-Hint
X-Zipkin-Id
TWC-Connection-Speed
X-Proxied
TWC-GeoIP-LatLong
X-URL
X-Tumblr-Pixel-3
Selected-Fe
X-Format
X-MCACHE
X-Proxy-Build
X-Uri
X-Drupal-Cache-Contexts
X-Timing-Wait
X-Tumblr-Pixel-2
CDN-RequestId
X-Fetched-On
Liferay-Portal
X-Tec-Api-Origin
X-Tec-Api-Root
Node
X-Tec-Api-Version
X-Tncms
X-Loop
Source
X-CCDN-CacheTTL
X-CCDN-Origin-Time
X-Srv
X-Hcs-Proxy-Type
X-Rn-Rsrv
X-B3-SpanId
X-Endurance-Cache-Level
X-Cache-Hit
X-Origin-Date
Cross-Origin-Window-Policy
X-Redis-Cache
X-MP-GENERATED-AT
X-Fastly-Request-Id
X-Ua
X-Varnish-Hits
Fastly-Drupal-HTML
X-TimeS
Section-Origin-Responded
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
X-Cache-Expired-At
Section-Io-Id
X-Pass-Why
Upgrade-Insecure-Requests
X-S
X-Ratelimit-Reset
Content-Secure-Policy
X-Real-IP
X-UA-Device-Type
X-Origin-TTL
X-Cache-TTL-Remaining
X-Origin-CC
X-Node-Name
X-Akamai-Transformed
X-Pubstack
X-CACHE-AGE
X-GEO
X-Server-W
CDN-CachedAt
CDN-RequestCountryCode
CDN-RequestPullCode
CDN-RequestPullSuccess
CDN-PullZone
CDN-Uid
CDN-EdgeStorageId
CDN-Cache
X-Via-JSL
X-Hl-Ver
Cache-Provider
X-Newrelic-Synthetics
X-RTag
Ms-Operation-Id
X-TIME
X-CSRF-Token
MS-CV
X-AIR-PT
X-NGENIX-Cache
NGB
X-Handled-By
X-Xfnlog-Site
X-Restarts
Apigw-Requestid
X-Cache-Type
X-Cms-Context
X-IPLB-Instance
X-IPLB-Request-ID
X-Reqid
X-Optimistic-Header
X-Parent-Response-Time
X-Cache-Host
ServedBy
X-Application
L
DCR-Decision-By
N-Cache
Cache-Name
CPC-Cache
X-Origin-Time
X-Accel-Expires-Debug
X-Aed
CPC-Age
X-Policy
X-App
DCR-Processing-Time-Ms
X-Rojux
X-Bl-Debug
X-S-Cookie
X-Cache-Bucket
X-SD-PageType
X-ScT
X-Request-Host
Meta-Geo-Continent
X-RateLimit-Limit-Second
X-JWT-State
X-RateLimit-Remaining-Second
X-Bc-Bl
X-BCube-Filmed-By
X-B-Cookie
X-A-Wwc
T-Server
Surrogated-Key
Odigeo-Trace-Id
True-Client-Country-4JS
X-Nyt-Route
X-Is-Gdpr
Sslversion
Server-Host
Canary
Redirect-Candidate
Rendered-Blocks
Candidate-Md5Url
BehaviorPad-Version
Ngx.Var.Host
Vix-Hermes-Req-Id
Xc-Version
X-A-Dam
X-A-Dcw
X-Worker
X-Mvc-Supplant-Cachable
X-A-Dgt
X-A-Ccd
X-A
VNS-Cache
VNS-Age
W
We-Hiring
Web-Mar-Region
X-Orig-Expires
X-Has-Esi
X-Vdms-Path
X-Developer
X-Dispatcher-Number
Gh-Request-Id
X-Ec-Fail
X-Ec-Custom-Error
X-Destination
X-SRCache-Key
X-Date
X-D
X-Debug-Cache-Fetch
X-Vdms-Version
Magicmarker
X-Ec-GeoHdr
X-Tenant
X-Var-Ttl
X-FC-Vary-Parameters
X-Gdpr
L5d-Success-Class
X-Forwarded-Path
Lang
X-Fastly-Backend
X-Epic-Correlation-Id
Ha-Gx-Prefs
HA-Ipaddr
X-Eu-Site
X-External-Request-Id
X-Csrf-Jwt
X-Debug-Cache-Store
X-We-Are-Hiring
Mail-Subject
X-Wikidot-Backend
X-CF-Lambda-Fn
X-CF-Lambda-Version
Gannett-Cam-Experience-Id
X-Vtex-Remote-Cache
X-Cdn-Diag
X-GeoIP-Region-Code
X-Cache-NE
X-Cache-Info
MD5-Digest
X-CacheTTL
X-Wikidot-Static-Cache
X-Shop-Environment
X-Presslabs-Stats
X-CGP
X-GeoIP-Country-Code
X-Slack-Backend
X-VG-WebCache
Fastly-SSL
X-Slack-Shared-Secret-Outcome
X-Conf
X-Viewer-Country
Fastly-GeoIP-CountryCode
Fastly-Backend-Name
X-BYPASS-REASON
WP-Super-Cache
X-ProxyCache-Status
X-No-Session
X-ProxyCache-Key
X-Tx-Id
Hostname
Producers
Origin
Machine
X-Irp-Debug
Platform
Memcached
X-Hash
X-CMSURLCustom
X-Core-Mission
X-Clientip
X-Clara-WADP
X-Gzip
X-Cdn-Origin
X-Core-Value
X-DefElseHash
X-Generated-On
X-Fmm-Version
X-Esi-Check
X-Geo-Header
X-DefHash
X-DPWN-IS-SECURE
X-Cache-Id
X-Cache-Debug
Thinkindot-Control
X-INCAP-ABP
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
Req-Svc-Chain
TDXMobile
X-Human
X-Accel-Buffering
X-BBC-Edge-Cache-Status
X-Bip
X-Auto-Login
X-App-Name
X-Alternate-Cache-Key
X-ApacheServer
Release
Expect-Staple
X-Thinkindot-L3
X-Varnish-CookieHashed-On
X-Platform
X-Thanos
X-Pool
X-Test
X-Refresh
X-Qloud-Router
X-PERF
X-Level-Front-Cache
Cache-Hits
X-Node-Id
Adler-Geo
X-Old-Content-Length
X-Variation
X-PAYTM-SRV-ID
X-Owner
X-Org
X-Varnish-CookieINHashed-On
X-Request-Time
X-Shopify-Stage
X-Vmg-Version
X-VServer
X-Sn-Servicetimems
X-Storefront-Renderer-Rendered
X-Sorting-Hat-ShopId
X-VG-TLSProxy
X-Sorting-Hat-PodId
X-WADP-Cache
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-Varnish-Remaining-TTL
X-S-Maxage
X-Wix-Viewer-Type
X-Varnishpool
X-ShopId
X-ShardId
X-Server-IP
AKAMAI
Origin-Agent-Cluster
Cmsid
X-Mid
Environment
X-Loc
Cf-Device-Type
Cmstype
Host-ID
X-Nitro-Cache
Is-Eu
X-Mly-Id
X-Datadome
Datacenter
User-Cache-Control
X-Cluster
X-AWS-Id
X-LJ-Flow-ID
X-Vcl-Version
X-VWS-Id
Apple-News-Services-Handled
X-Nginx-Cache-Key
X-Nananana
CDCHOST
X-Scale
CloudFront-Viewer-Country
NM-Fastcgi-Cache
X-Dispatcher-Server
X-Cdn-Srv
DSUID
X-Block-Status
X-WA-Info
X-Device-Os
X-Mvc-Supplant-OutputCached
X-Akamai-Device-Characteristics
X-GeoIP
X-PHP-Backend
Esi-Enabled
X-Gen-Mode
X-Forwarded-Site
Apple-News-Services-Host
X-From
X-NodeID
X-Origin
Apple-News-Services-Parsed-Url
X-Up
Server-Hostname
Apple-News-Services-Request-Url
Server-Ext
X-Origin-Response-Time
Country-Code
X-Hnp-Log
Sever-Int
X-Proxy-Cache-Status
X-B3-Spanid
X-LB-NoCache
X-Cache-Status-Check
X-Access
Server-Info
X-Op-Id-All
Wxu-Next-Region
Wxu-Next-Commit
Wxu-Next-Hostname
Origin-CC
X-Instance-Name
X-Section
X-Cache-Enabled
Origin-EX
Pics-Label
C-Via
X-NCache
Ssr
X-API-Version
X-TIM-N
X-Amz-Meta-Cb-Modifiedtime
Memory
Time
X-Via-Fastly
AMP-Access-Control-Allow-Source-Origin
X-Dc
Server-ID
NGX
X-Micro-Cache
X-CACHE-GROUP
X-Cs
X-Correlation-ID
X-Internal-Host
X-FTR-Request-ID
X-HA-Backend
X-Air-Hostname
X-Air-Source
X-Air-Trace-Id
X-Tb-Optimization-Total-Bytes-Saved
X-ZONE
X-AB
X-Wp-Cf-Super-Cache-Active
X-Platform-Processor
X-Platform-Cluster
X-Platform-Router
X-Azure-Ref-OriginShield
X-Varnish-Beresp-Grace
X-Vgn-Hpd-Reason
X-Geo-Region
X-Webkit-Csp-Report-Only
GeoIP-Latitude
X-Varnish-Beresp-Ttl
X-Buckets
X-Web-Node
Location
IsBot
X-Microcachable
X-Origin-Expires
Cache-Host
X-SIPLIST1
X-WP-CF-Super-Cache-Active
X-Accel-Version
X-TraceId
Cdn-Requestid
X-Zone
X-DC
X-B3-Parentspanid
Sid
X-Fpc
X-Github-Request-Id
XM
X-Backend-Instance
X-DataCenter
X-VarnishDD-TTL
Uri
X-Pod-Name
PFcat
X-HN
X-Tcp-Rtt
X-Is-Supported-Browser
X-Is-Tablet
X-Is-Mobile
X-Is-Desktop
X-Browser-Name
User-Agent
Resin-Trace
X-Cached-By
X-Ad-Defer-Variation
X-Info
YJS-ID
CF-Ctrl
X-TA-CDN-Provider
X-LiteSpeed-Cache-Control
X-Via-SSL
Edge-Copy-Time
X-Via-Edge
Locid
X-Via-CDN
X-Site-Version
X-FL-EDGE
X-Locale
A
X-FL-QIT-DEBUG
Srvid
GeoIp-Country-Code
X-NGINX-Cache
X-Nitro-Cache-From
XServer
True-Client-Ip
X-Nitro-Rev
X-Contensis-Viewer-Groups
GeoIP-Country-Code
X-Moov-T
X-Moov-Xdn-Version
Epwk-X-Cache
X-Hyper-Cache
X-FireWall-Port
X-Cache-ASPX
X-ATG-Version
X-VCache
Cdn
X-CS
X-Frame-Option
True-Client-IP
X-Varnish-Authentication
Cache-Key
X-NewRelic-App-Data
X-CSRF-TOKEN
X-Cache-Ttl
X-MSEdge-Features
X-Service
X-Webstats-RespID
X-MSEdge-Flight
SID
X-APP-VERSION
X-Upstream-Ht
X-Upstream-Ct
Fastly-Drupal-Html
X-Geo
X-FPC
X-TRACE-ID
NtCoent-Length
X-Datacenter
X-VC
Path
X-Platform-Server
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
State
X-Origin-Cache-Key
X-Planisys-CDN-Cache
X-HS-Content-Campaign-Id
X-HostName
Tcn
Lb
X-FTR-Balancer
X-FTR-Backend-Server
X-SRV
X-FTR-Cache-Status
X-FTR-Expires
X-Vgn-Hpd-Variations-Key
X-Vgn-Hpd-Ssi
X-Vgn-Hpd-Cached
X-Edge-Server
X-Country-Code-Real
X-Fastly-Cache
Cdn-Host
X-Vercel-Cache
Cdn-Request-Time
X-Release
X-FTR-Backend
X-Vercel-Id
X-LiteSpeed-Tag
Cf-Ipcountry
CountryCode
X-Api-Version
LB
X-Pad
X-Rocket-Build-Number
X-Generated-In
X-Sigma
Cdncip
Cdnsip
Req-ID
X-NMSegId
M-TraceId
X-Cache-Remote
X-AK-Request-ID
X-Amz-Meta-Opti
X-Sigma-Backend
WZWS-RAY
X-Air-Pt
X-Esi
X-Cdn-Request-ID
X-Wp-Cf-Super-Cache-Cache-Control
X-Wp-Cf-Super-Cache
X-WP-CF-Super-Cache-Cookies-Bypass
X-HS-Status
X-Branch-Name
X-Provided-By
Cluster
X-Ad-Load-Variation
WebServer
X-UA
Cache
X-Traceid
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
CDN
X-NWS-UUID-VERIFY
X-GoCache-CacheStatus
X-Scope-Id
X-M-Reqid
X-Scheme
X-M-Log
XkeyRZ
X-Request-Start
Pramga
Proxy-Connection
X-Gamma-Serve
X-Proxy-CacheRZ
Yak-Timeinfo
Content-Script-Type
Content-Style-Type
X-GeoIP-City
X-CACHE-KEY
X-RN-RSRV
Server-Id
X-Akamai-Pragma-Client-IP
X-Cdn-Forward
X-Cdn-Cache-Status
X-Ha-Backend
Srv
Geoip-Latitude
X-Shield-Cache-Expires
X-Qnm-Cache
X-Vc
X-Tim-N
X-Varnish-Beresp-Status
X-Lb-Cache
Ngx
Env
CF-Cached-On
X-Cache-Date
X-Request-URI
Edge-Cache
Ohc-File-Size
X-TT-LOGID
Serverid
X-Udemy-Cache-App-Namespace
X-User
X-CUA
X-VCL-Version
X-EC-Lua
X-Render-Time
X-TH-Server
X-Via-Ucdn
X-Edge-POP
X-Acquia-Application-Trace
Cache-Tv-Group
Kp-EeAlive
X-Acquia-Application-UUID
X-Acquia-Purge-Tags
X-Lb-Nocache
PICS-Label
Inserted-Into-Cache-At
X-Dw-Trace-Id
X-Acquia-Site
X-Varnish-Beresp-TTL
Yjs-Id
X-Via-PopN
Tube-Get-Contents
X-Via-PopV
Tube-Got-Results
Tube-Got-Eval
X-Wa
X-Req
MIME-Version
X-Fastly-Backend-Reqs
X-B3-Trace-ID
Tube-Return
X-Acquia-Purge-Cdn-Unconfigured
X-Lb-Id
X-Nc
X-UP
X-Servedbyhost
X-SB
X-Aicache-OS
X-Via-PopH
X-Iauth-Set-Uid
X-MiniProfiler-Ids
X-Location
Vha6-Origin
X-Mobile-URL
X-Snapshot-Date
X-Edge-Pop
CACHE-MISS-TO-ORIGIN
X-Fastly-Cache-Hits
X-Cached-Since
X-ElasticPress-Query
X-CF-Cache-Header-Cache-Control
X-CF-Cache-Header-Vary
Click-Count-Action-Start
Cneonction
X-Miniprofiler-Ids
X-Litespeed-Cache-Control
Log-Origin
X-RAMCache
Click-Count-Error