Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-Cache-Status
Link
Accept-Ranges
CF-RAY
ETag
X-XSS-Protection
Expect-CT
Pragma
X-Powered-By
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
Alt-Svc
P3P
X-Served-By
X-Xss-Protection
X-Download-Options
X-Timer
X-Request-Id
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Cache-Status
X-Check
X-Generator
X-Cacheable
Timing-Allow-Origin
P3p
X-Content-Security-Policy
X-Iinfo
Feature-Policy
Status
X-Envoy-Upstream-Service-Time
Content-Encoding
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
X-Request-ID
X-CDN
X-AspNetMvc-Version
Upgrade
X-Via
CF-Ray
X-Ws-Request-Id
Access-Control-Max-Age
Server-Timing
EagleId
X-Cache-Group
X-Turbo-Charged-By
Keep-Alive
Request-Context
X-UA-Device
Report-To
X-Age
X-Backend
X-Server-Powered-By
X-Proxy-Cache
X-AH-Environment
X-Robots-Tag
X-Hacker
X-Amz-Request-Id
X-Server
Host-Header
X-Amz-Id-2
Grace
X-LiteSpeed-Cache
X-Rq
X-Nginx-Cache-Status
X-Varnish-Cache
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-WebKit-CSP
X-Page-Speed
X-Vhost
NEL
EagleEye-TraceId
X-Ua-Compatible
X-Dns-Prefetch-Control
X-Amz-Version-Id
X-Pingback
X-OneAgent-JS-Injection
X-Dispatcher
X-Device
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Cache-Spec
X-Host
X-Server-Id
Cf-Railgun
Accept-CH
X-Node
X-Backend-Server
X-Readtime
Surrogate-Control
X-Akam-SW-Version
Request-Id
X-Response-Time
X-HW
Xkey
X-Application-Context
X-EdgeConnect-Origin-MEX-Latency
Content-Location
X-EdgeConnect-MidMile-RTT
Rating
Accept-Ch-Lifetime
X-Country
X-Cloud-Trace-Context
X-Ruxit-JS-Agent
X-B3-TraceId
Accept-CH-Lifetime
X-Cache-Lookup
X-Trace
X-Ac
X-Url
X-Content-Type
Allow
X-PC
X-TtlSet
X-Vname
X-Varnish-TTL
X-Clacks-Overhead
Edge-Control
X-Mod-Pagespeed
X-Server-Name
X-ESI
X-Aws-Lambda-Call-Status
Fastly-Restarts
Cache-Tag
Service-Worker-Allowed
X-VARITI-CCR
X-Rack-Cache
X-FastCGI-Cache
Verso
X-Element-Page-Cache
X-Upstream
MS-Author-Via
X-Vcap-Request-Id
X-MS-InvokeApp
X-Amz-Rid
X-GitHub-Request-Id
Public-Key-Pins
X-Dw-Request-Base-Id
X-Cached
X-Abt-Application-Version
X-Client-IP
X-D2id
X-Cache-TTL
X-Cnection
X-Px
RTSS
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
X-Navigation-Version
X-Cdn-Fetch
X-Kinja
X-GoogleNews-Bot
X-Kinja-Build
X-Kinja-Revision
X-Exp-Id
X-Exp-Variant
X-Use-Magma
X-Kinja-Server
Arr-Disable-Session-Affinity
Access-Control-Request-Method
X-Country-Code
X-NF-Request-ID
X-Powered-By-Plesk
X-Goog-Hash
X-Kraken-Loop-Name
X-Instrumentation
X-Server-Lifecycle-Phase
X-Powered-CMS
AR-ATIME
AR-SID
AR-PoweredBy
AR-Request-ID
AR-CACHE
X-Origin-Cache
X-Middleton-Display
Pagespeed
Display
X-Sol
X-Version
Response
X-Middleton-Response
Accept-Ch
X-TTL
X-LLID
X-Amz-Server-Side-Encryption
X-MSEdge-Ref
Nginx-Cache
X-Edge-Location-Klb
TCN
X-Kinsta-Cache
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Edge
Mrf-Cache-Status
X-B3-TraceId-Primal
MRF-Tech
X-Protected-By
X-RateLimit-Remaining
X-T
X-Jurisdiction
X-HP-Webp
X-HP-Trace-Id
X-Content-Security-Policy-Report-Only
X-Forwarded-For
X-Shield-Request-Id
X-Aspnetmvc-Version
X-Id
S
X-Mg-S
Content-MD5
Edge-Cache-Tag
X-CST
X-Ruxit-Js-Agent
X-Language
SPRequestDuration
SPIisLatency
X-Mid
Front-End-Https
Fastcgi-Cache
Realpath
X-Request-Received
X-Recruiting
Server-Node
X-Request-Processing-Time
X-DynaTrace
Filters
Pinterest-Version
Pinterest-Generated-By
X-Pinterest-Rid
X-Frontend
Server-Name
X-Ua-Browser
X-Content
X-Ab
X-MCACHE
X-Cache-Key
X-Ttl
X-Ser
X-HS-Cache-Config
X-HS-Hub-Id
X-HS-Content-Id
X-Yandex-Sdch-Disable
X-NWS-LOG-UUID
X-HS-Combine-CSS
X-Correlation-Id
X-Template
X-ECACHE
X-Ezoic-Cdn
X-SharePointHealthScore
SPRequestGuid
X-Hits
X-Parallel-Accel
MicrosoftSharePointTeamServices
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
Cache-Tags
Charset
Cleartype
X-B3-Sampled
Alternate-Protocol
Host
Fusion-Content-Source
Fusion-Content-Id
Fusion-Deployment-Id
Fusion-Template-Id
X-Page-Id
X-Www-Served-By
Fusion-Component-Id
Fusion-Source
X-Content-Options
X-Git-Hash
X-Geo-Country
X-Hostname
X-Debug-Info
X-DIS-Request-ID
X-Daa-Tunnel
X-Amzn-Trace-Id
X-Content-Digest
X-Amz-Replication-Status
X-Varnish-Age
X-Ratelimit-Limit
Cross-Origin-Opener-Policy
X-Activity-Id
X-AppVersion
Filterid
X-Az
X-FB-Debug
X-Accel-Expires
X-Upgrade-Enabled
X-Grace
X-VCache
X-Nginx-Upstream-Cache-Status
X-Forwarded-Proto
X-F-Cache
ServerID
X-N
X-Origin-Server
X-Rid
Access-Control-Allow-Method
X-Fastly-Request-Id
X-Mobile-URL
X-LB-Cache
X-Type
X-Server-ID
X-Flags
X-Is-Crawler
X-Route-Name
X-Request-Guid
X-Providence-Cookie
X-Aspnet-Duration-Ms
TP-Cache
TP-L2-Cache
X-TT
X-Whom
X-Varnish-Grace
Viewport
Payment
X-WebKit-CSP-Report-Only
Node
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-Tb
X-Goog-Metageneration
X-Goog-Generation
X-FW-Hash
X-FW-Dynamic
X-FW-Serve
X-FW-Static
X-FW-Type
X-Seen-By
X-FW-Server
X-App-Environment
Paypal-Debug-Id
X-User-Agent
X-Distributor
DC
X-XRDS-LOCATION
X-App-Server
Country
X-Fastly-Request-ID
X-Oneagent-Js-Injection
Accept-Charset
Fastcgi-Useragent
X-DataDome
X-Wix-Request-Id
X-Litespeed-Cache
X-NGENIX-Cache
X-Fastcgi-Cache
X-Cache-Control
X-Cache-Rule
X-Tec-Api-Root
X-Tec-Api-Origin
X-Tec-Api-Version
X-Webkit-CSP
X-Origin-Upstream-Status
Version
X-Webkit-Csp
X-Drupal-Cache-Tags
X-Logged-In
X-Via-JSL
X-Microsite
X-Request-Handler-Origin-Region
X-Ratelimit-Reset
Referer-Policy
X-Cluster-Name
X-Cache-Age
X-Contextid
X-Buckets
X-B-Cache
X-Signature
X-Browser-Type
X-Erf-Bev-Bev-Is-Generated
Refresh
X-Erf-Bev-Bev
Cache-Status
SD-X-WS
VIX-Pulpo-Node
X-Mobile
X-Varnish-Backend
X-Node-Name
VIX-Pulpo-Upstream-Status
X-Load-Cache
X-Original-Request-Id
X-Response-Served-From
X-Cache-Expired-At
X-Real-IP
X-Vgn-Hpd-Reason
X-Page-View
Amp-Access-Control-Allow-Source-Origin
X-Jobs
X-B
X-Cacheable-TTL
X-Debug
Access-Control-Request-Headers
X-IPLB-Instance
X-RemovedCookies
X-Yottaa-Metrics
X-Revision
X-Proxy
X-Yottaa-Optimizations
X-Device-Type
X-ProcessESI
X-Proxy-Cache-Status
X-Instance
X-Drupal-Cache-Contexts
NGB
X-Cache-Action
X-UUID
X-Rule
Surrogate-Key
Akamai-GRN
X-Is-Bot
X-Debug-IsPreview
X-Debug-IsConnected
X-Cache-Time
X-Rendered-As
X-G
X-Framework
X-FW-Version
X-Air-Source
X-Air-Hostname
SID
X-Oracle-Dms-Rid
X-Air-Trace-Id
X-Oracle-Dms-Ecid
CF-IPCountry
GEO-INFO
DynaTrace
X-Azure-Ref
X-PressLabs-Stats
X-Accel-Buffering
X-Nginx-Cache
Count-Hit
X-Cache-NGX
X-Source
Liferay-Portal
X-Ms-Version
Uber-Trace-Id
X-Presslabs-Stats
X-Ms-Request-Id
X-Cache-Operation
X-XRDS-Location
Frame-Options
Ms-Operation-Id
X-CDN-Forward
X-Zen-Fury
MS-CV
X-RTag
X-APP-VERSION
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-TEC-API-ROOT
X-EdgeConnect-Cache-Status
Healthy
Protected
X-Mode
Xserver
X-L-Path
Countrycode
X-Backend-Name
X-Cache-Hit
X-Environment-Context
X-IPS-LoggedIn
Ec-Rule-Version
X-Varnish-Server
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
Cross-Origin-Window-Policy
X-Tumblr-User
LB
X-Ratelimit-Remaining
X-Cache-TTL-Remaining
X-Hyper-Cache
X-RateLimit-Limit
X-RN-RSRV
X-Rewrite-Enabled
X-Region
X-SaId
X-Adobe-Content
Meta-Geo
X-UPSTREAM-Address
Backend
X-Tid
X-Adobe-Loc
X-Servername
X-Forwarded-Host
X-JoinUs
Eomportal-Instance
X-Content-Age
Section-Io-Cache
X-Format
X-Proxied
X-Extlb
WPO-Cache-Message
X-Generation-Time
X-Sorting-Hat-PodId
X-ShopId
X-Shopify-Stage
X-ShardId
Apigw-Requestid
X-Routing-Service
WPO-Cache-Status
X-Sorting-Hat-ShopId
X-Cache-Grace
X-Zipkin-Id
X-Alternate-Cache-Key
X-Debug-Cache
X-Cache-Server
Country-Code
Decoy-Debug-Status
Cache-Name
Decoy-Debug-Key
Content-Disposition
X-FB-TRIP-ID
X-Origin-Date
X-OCL
X-No-Session
X-Sql-Duration-Ms
X-Uri
X-Varnish-Beresp-Grace
X-PERF
X-PHP-Backend
X-Via-Fastly
X-NCache
X-Sql-Count
X-ApacheServer
X-Access
Mn-Server-Ip
Fastly-SSL
X-PCL
X-Hosted-By
X-Microcachable
X-ServerID
X-Section
Decoy-Debug-TTL
Url
X-Content-Powered-By
Selected-Fe
Property-Id
X-Origin-Hint
TWC-Connection-Speed
TWC-Device-Class
X-UA-Device-Type
TWC-GeoIP-Country
X-Proxy-Build
X-Timing-Wait
X-ProxyCache-Status
X-Server-W
X-Pubstack
X-Site-Version
X-ProxyCache-Key
X-Storage
Cache-Tv-Group
X-Status
TWC-GeoIP-LatLong
TWC-Locale-Group
X-Cache-Host
X-BYPASS-REASON
X-Cache-Type
X-Cluster-Node
X-Detected-As
X-Akamai-Edgescape
X-Human
Webcakes-App-Name
TWC-Privacy
Webcakes-Region
Webcakes-App-Version
X-NYM-Debug-Backend
X-Say-Cacheable
X-R9-Blue-Green-Version
X-Be
X-Trace-Id
X-NewRelic-App-Data
X-Hl-Ver
X-Redis-Cache
CDN-EdgeStorageId
CDN-CachedAt
CDN-PullZone
CDN-RequestCountryCode
CDN-Uid
CDN-RequestId
CDN-Cache
X-Varnishpool
X-Soup
X-Say-TTL
X-SayCDN-TTL
Content-Secure-Policy
X-Generated-By
X-Web-Node
DB-Nickname
Azure-SlotName
X-Azure-Ref-OriginShield
Azure-Version
X-LSADC-Cache
Azure-RegionName
Azure-InstanceId
X-Ua
Azure-SiteName
X-TIME
OT-Force-Account-Verify
X-Nginx-Cache-Key
Retry-After
X-Cached-By
Source
X-Dc
X-TT-LOGID
X-Bc-Bl
X-Unique-Id
Cache
X-Cache-Remote
SRV
X-Akamai-Transformed
X-Auto-Login
X-Platform-Server
X-Xfnlog-Site
X-Cdn
X-LAGOON
X-EC-Lua
Cache-Hits
X-Origin-CC
X-Origin-TTL
X-Varnish-Hits
X-GEO
HostName
Upgrade-Insecure-Requests
X-Cache-Tags
ServedBy
X-Loop
X-SRV
X-Correlation-ID
X-TNCMS
X-Varnish-Hostname
X-HTML-Minification-Powered-By
X-CSRF-Token
X-Varnish-Cache-Hits
X-S-Maxage
X-App-Version
Onion-Location
From-Origin
X-Request-Time
Mime-Version
Xet-Cookie
X-AOL-HN
X-Time
X-Tumblr-Pixel-2
X-Tumblr-Pixel-3
N-Cache
X-Request-Host
Webserver
X-ECache
X-Proto
X-Xrds-Location
X-Amz-Meta-S3cmd-Attrs
X-NWS-UUID-VERIFY
Web-Mar-Node
WP-Super-Cache
X-Tenant
X-Endurance-Cache-Level
X-FireWall-Port
X-LJ-Flow-ID
Nel
X-VWS-Id
X-Cache-Enabled
X-AWS-Id
X-Handled-By
X-Time-Microsecs
X-GG-Cache-Date
X-TIM-N
BehaviorPad-Version
Xc-Version
X-SRCache-Key
X-Shop-Environment
DCR-Decision-By
X-External-Request-Id
Expiry
X-Session-Fingerprint
DCR-Processing-Time-Ms
X-V-Cache
X-D
X-CF-Lambda-Version
X-VG-WebCache
X-Vtex-Processado-Em
X-Developer
X-Cluster
X-Destination
X-Epic-Correlation-Id
X-Vtex-Remote-Cache
X-Vdms-Version
X-Vdms-Path
X-Ckpd-Fst-Backend
A
X-Connection-Hash
X-Conf
X-SD-PageType
X-Orig-Expires
Vix-Hermes-Req-Id
X-A
X-PAYTM-SRV-ID
X-PBS-Appsvrname
V-Age
X-Ftr-Request-Id
X-ARC
X-Application
X-A-Ccd
X-NAPM-TraceId
X-Ig-Push-State
X-A-Dgt
X-ND-Cache
X-A-Dam
X-Aicache-OS
X-A-Wwc
X-B-Cookie
Surrogated-Key
X-CF-Lambda-Fn
X-Cache-NE
X-Backend-TTL
X-Forwarded-Path
Mobile-Detection-Method
Meta-Geo-Continent
X-A-Dcw
X-ScT
Odigeo-Trace-Id
X-S-Cookie
Rendered-Blocks
Sslversion
X-Processor
X-Rojux
Redirect-Candidate
X-S
Pramga
Fastcgi-X-Cache-Version
X-Aed
X-Edge-Location
X-Cache-Var
X-B3-SpanId
X-Cache-Var-Map
X-Magnolia-Registration
X-RCS-CacheZone
X-Origin-Response-Time
X-Mg-Request-UUID
X-Adobe-Source
X-Reqid
X-MP-GENERATED-AT
X-Origin-Time
X-Origin-Expires
X-Request-URI
X-Hnp-Log
CacheControlHeader
CDCHOST
X-Geo-Header
Gh-Request-Id
X-Amz-Apigw-Id
Apple-News-Services-Request-Url
Host-ID
Apple-News-Services-Parsed-Url
Arc-Country
X-Origin
True-Client-Country-4JS
X-Location
Wxu-Next-Region
Cmsid
X-Nyt-Route
X-Gdpr
X-Gen-Mode
X-Planisys-CDN-Cache
User-Cache-Control
Fastcgi-Cache-TTL
X-Planisys-CDN-Rules
X-Policy
DSUID
Wxu-Next-Hostname
Cmstype
Wxu-Next-Commit
X-NodeID
X-Amzn-RequestId
Apple-News-Services-Host
X-Planisys-CDN-TTL
CloudFront-Viewer-Country
X-Sucuri-ID
X-Sucuri-Cache
Origin
X-Hash
X-VG-TLSProxy
Apple-News-Services-Handled
X-Block-Status
State
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-Cdn-Srv
X-Slack-Backend
X-Scheme
X-Cache-Date
X-Rocket-Nginx-Serving-Static
AKAMAI
Svr
X-Cache-Bucket
X-Li-Pop
X-LI-UUID
X-Server-IP
X-Li-Fabric
S-Rt
X-Via-NSCOPI
AMP-Access-Control-Allow-Source-Origin
Environment
X-GeoIP
X-HN
X-Forwarded-Site
X-Gamma-Serve
Req-Svc-Chain
X-Generated-On
Server-Host
X-GeoIP-Region-Code
X-GeoIP-City
Ssr
X-GeoIP-Country-Code
X-Developers
X-Backend-State
X-Core-Mission
X-Core-Value
X-Csrf-Jwt
X-BBC-Edge-Cache-Status
X-CGP
X-Cache-Debug
X-Cdn-Origin
X-Branch-Name
X-Labrador-Cache-Channel
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
X-Eu-Site
X-Fastly-Backend
X-Fastly-Cache
X-Fetched-On
X-Envoy-Decorator-Operation
X-Device-Os
X-Datadog-Trace-Id
X-Date
X-Accel-Expires-Debug
X-PHP-Host
Traceparent
Locid
X-Proxy-Upstream
X-Varnish-Beresp-Status
X-UnsetCookies
X-Platform
X-Varnish-Beresp-Ttl
HA-Ipaddr
Server-Info
X-Owner
Release
X-TrackingId
X-Served-From
X-Sigma-Backend
X-Sigma
X-Rocket-Build-Number
X-Skip-Cache
X-Region-Sid
X-Storefront-Renderer-Rendered
X-Sn-Servicetimems
X-Old-Content-Length
Ha-Gx-Prefs
X-Level-Front-Cache
Origin-EX
L
PFcat
X-VarnishDD-TTL
X-Webstats-RespID
X-VServer
X-Viewer-Country
Fastly-Drupal-Html
Origin-CC
L5d-Success-Class
X-Cache-Info
X-Mvc-Supplant-Cachable
X-Men
X-Locale
X-Worker
Magicmarker
X-Varnish-Remaining-TTL
X-Varnish-CookieINHashed-On
X-TH-Server
X-Varnish-CookieHashed-On
X-Variation
X-Thinkindot-L3
X-RateLimit-Remaining-Second
X-JWT-State
X-NU-AKA-ACS-Version
X-FC-Vary-Parameters
X-Pod-Name
X-Is-Gdpr
X-Gzip
X-HS-Content-Campaign-Id
X-Irp-Debug
X-Has-Esi
X-Qloud-Router
X-Esi-Check
X-Request-Start
X-Response-By
X-DefHash
X-Req
X-DPWN-IS-SECURE
X-RateLimit-Limit-Second
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-DefElseHash
X-Loc
TDXMobile
Platform
NM-Fastcgi-Cache
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
Web-Mar-Region
We-Hiring
Thinkindot-Control
Memcached
Mail-Subject
Cf-Device-Type
Adler-Geo
X-Cache-Id
Fastly-SIE
Fastly-SWR
Machine
Is-Eu
X-Amzn-Remapped-Content-Length
Fastly-GeoIP-CountryCode
X-Ua-Device
X-VC-Cache
X-Akamai-Request-ID2
X-M-Reqid
X-M-Log
X-Qnm-Cache
X-Http-Reason
X-Restarts
NGX
X-ATG-Version
X-CS
X-Bip
X-Node-Id
X-Thanos
X-Tx-Id
X-Zone
Kp-EeAlive
X-Mvc-Supplant-OutputCached
X-Up
X-API-Version
X-LB-ID
X-LB-NoCache
X-Cache-Backend
Ms-Author-Via
CDN
X-Generated-In
Edge-Cache
X-Trace-ID
X-NC
X-Cache-Config
X-Action
Pics-Label
X-TraceId
X-RPM
Memory
X-RPS
X-DB
Time
X-Wix-Viewer-Type
X-DI
X-RSL
X-DSS
X-DW
X-Srv
Accept-Language
X-Refresh
WebServer
X-Via-Poph
X-Via-Popn
X-Minions-Version
X-Via-Popv
Env
X-Edge-Pop
X-CacheTTL
X-Varnish-Ttl
X-Optimistic-Header
X-Tt-Logid
X-Tb-Optimization-Total-Bytes-Saved
X-URL
X-Datadome
X-HA-Backend
NtCoent-Length
Candidate-Md5Url
Datacenter
X-DC
X-CACHE-KEY
GeoIp-Country-Code
X-Urbn-Site-Id
Locale
X-Urbn-Context-Path
X-ZONE
X-DynaTrace-JS-Agent
WWW-Authenticate
On-Server
X-Servedbyhost
Server-ID
X-Vc
X-Esi
X-Ec-GeoHdr
Esi-Enabled
X-User
X-Unique-ID
X-Ec-Fail
X-MSEdge-Flight
X-MSEdge-Features
X-CLOUD-TRACE-CONTEXT
X-Cs
X-TX-ID
X-Parent-Response-Time
X-TA-CDN-Provider
X-Webkit-CSP-Report-Only
X-Varnish-Beresp-TTL
X-Service
X-Cache-PHP
C-Via
X-Newrelic-Synthetics
X-VCL-Version
X-Traceid
X-Cache-Ttl
X-Fpc
X-App
Cdncip
Cdnsip
X-LI-Proto
X-AK-Request-ID
X-B3-Spanid
X-Li-Proto
X-Webkit-Csp-Report-Only
Test
My-App
Proxy-Connection
X-Dynatrace
X-Var-Ttl
Cf-Int-Pingora-Origin-Digest
X-CUA
X-Clara-WADP
X-Cache-Status-Check
X-Render-Time
X-Fmm-Version
X-WADP-Cache
Cluster
Geoip-Latitude
X-FPC
Tracecode
X-Pass-Why
X-LiteSpeed-Cache-Control
X-NODE
DataCenter
X-Vcl-Version
Lfy
T-Server
X-From
X-Mcache
Fastly-Drupal-HTML
Geo-Info
Lang
X-Fragments
Resin-Trace
M-TraceId
X-VC
Target-Params
Server-Id
MIME-Version
X-CSRF-TOKEN
GeoIP-Country-Code
X-ID
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
X-Clientip
X-Ha-Backend
X-Geo
Hostname
X-B3-Traceid
X-Oss-Storage-Class
X-Oss-Server-Time
X-Info
X-AIR-PT
UCS
X-ServedByHost
Cache-Host
X-Oss-Object-Type
X-RAMCache
X-Oss-Request-Id
X-LiteSpeed-Tag
HIT
Hit
X-Oss-Hash-Crc64ecma
X-Dynatrace-Js-Agent
X-Provided-By
X-Via-PopH
X-Proxy-Cache-Info
Permissions-Policy
X-Edge-POP
X-Pad
X-Via-PopN
X-Httpd
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
X-Via-PopV
Section-Io-Id
Section-Origin-Responded
S-Cnection
X-Cdn-Forward
X-Edge-Cache
Servername
Producers
X-NGINX-Cache
Ohc-File-Size
ENV
X-Check-Cacheable
X-Api-Version
X-ServerName
FSS-Cache
Fastly-Backend-Name
X-Fastly-Backend-Reqs
X-Micro-Cache
X-HS-Status
WZWS-RAY
X-BBC-Origin-Response-Status
X-ElasticPress-Query
X-Ucs
X-SB
User-Agent
X-Udemy-Cache-App-Namespace
Load-Balancing
X-Backend-Host
X-Nc
X-Platform-Router
X-Platform-Processor
X-Release
X-Platform-Cluster
X-GoCache-CacheStatus
X-Pool
PICS-Label
X-Acquia-Purge-Tags
X-Cache-CFC
Uri
X-Acquia-Site
X-Acquia-Application-UUID
ServerName
X-Lb-Nocache
URI
X-UP
X-Acquia-Application-Trace
Cf-Ipcountry
X-TRACE-ID
X-Scale
X-BCube-Filmed-By
Tcn
X-Swift-Error
X-APP
X-Lb-Id
X-Fastly-Cache-Hits
Cdn
X-Cdn-Request-ID
EpKe-Alive
Server-Ttl
Cteonnt-Length
X-Ec-Custom-Error
X-RateLimit-Reset
Cneonction
X-Dw-Trace-Id
Wpo-Cache-Message
Wpo-Cache-Status
Ohc-Cache-HIT
X-Vcache
X-Akamai-ERRuleID
X-Cache-ASPX
Shield-Pop
X-Akamai-ERPolicy
Path
IsBot
X-B3-Parentspanid
X-Cache-Expires
X-SIPLIST1
Sever-Int
Server-Hostname
MD5-Digest
Server-Ext
X-Contensis-Viewer-Groups
X-Newrelic-App-Data
X-Snapshot-Date
X-Yottaa-OS
Vha6-Origin
CF-Cached-On
X-B3-ParentSpanId
X-Cache-Ngx
X-Air-Pt
X-HostName
Sid
VNS-Cache
VNS-Age
X-Amz-Meta-Cb-Modifiedtime
X-Shopify-Generated-Cart-Token
X-UA
X-CacheKey
X-Akamai-Pragma-Client-IP
Ngx
GeoIP-Latitude
X-Litespeed-Cache-Control
X-IN-APIGATEWAYSSL
X-IN-APIGATEWAY
CountryCode
X-Dispatcher-Number
Req-ID
CPC-Age
X-WA-Info
X-WA
X-Apw-Access-Action
X-Varnish-Authentication
X-Http-Count
X-Te-Count
X-Te-Duration-Ms
X-Apw-Access-Object
X-Last-Modified
X-Http-Duration-Ms
CPC-Cache
X-Akamai-Request-ID
Cache-Key
X-Apw-Hits
X-Sentry-ID
X-Apw-Access-Token
X-Logging-Id