Threat Level: green Handler on Duty: Johannes Ullrich

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-Cache-Status
Link
Accept-Ranges
CF-RAY
ETag
X-XSS-Protection
Expect-CT
Pragma
X-Powered-By
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
Alt-Svc
X-Served-By
X-Xss-Protection
X-Download-Options
X-Timer
X-Request-Id
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Cache-Status
X-Generator
X-Cacheable
Timing-Allow-Origin
X-Content-Security-Policy
X-Iinfo
Feature-Policy
Status
X-Envoy-Upstream-Service-Time
Content-Encoding
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
X-CDN
X-AspNetMvc-Version
P3p
X-Request-ID
Upgrade
X-Via
CF-Ray
X-Ws-Request-Id
Access-Control-Max-Age
Server-Timing
EagleId
X-Cache-Group
X-Turbo-Charged-By
Keep-Alive
Request-Context
X-UA-Device
Report-To
X-Age
X-Server-Powered-By
X-Backend
X-Proxy-Cache
X-AH-Environment
X-Robots-Tag
X-Hacker
X-Amz-Request-Id
Host-Header
X-Server
X-Amz-Id-2
Grace
X-LiteSpeed-Cache
X-Rq
X-Nginx-Cache-Status
X-Varnish-Cache
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-WebKit-CSP
X-Page-Speed
X-Vhost
EagleEye-TraceId
NEL
X-OneAgent-JS-Injection
X-Amz-Version-Id
X-Ua-Compatible
X-Pingback
X-Dns-Prefetch-Control
X-Dispatcher
X-Device
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Cache-Spec
X-Host
X-Server-Id
Accept-CH
Cf-Railgun
X-Node
X-Backend-Server
X-Readtime
Surrogate-Control
X-Akam-SW-Version
Request-Id
X-Response-Time
X-HW
Xkey
X-Application-Context
Content-Location
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Ruxit-JS-Agent
Rating
X-Country
X-B3-TraceId
Accept-Ch-Lifetime
Accept-CH-Lifetime
X-Cloud-Trace-Context
X-Cache-Lookup
X-Trace
X-Url
X-Ac
X-Content-Type
X-TtlSet
Allow
X-PC
X-Vname
X-Varnish-TTL
X-Clacks-Overhead
X-Mod-Pagespeed
Edge-Control
X-ESI
X-Server-Name
Fastly-Restarts
X-Aws-Lambda-Call-Status
Cache-Tag
X-FastCGI-Cache
Service-Worker-Allowed
X-VARITI-CCR
X-Rack-Cache
Verso
X-Element-Page-Cache
X-Upstream
MS-Author-Via
X-Vcap-Request-Id
X-MS-InvokeApp
X-GitHub-Request-Id
X-Amz-Rid
Public-Key-Pins
X-Dw-Request-Base-Id
X-Cached
X-Client-IP
X-D2id
X-Cache-TTL
X-Abt-Application-Version
X-Cnection
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-Px
RTSS
X-Navigation-Version
Arr-Disable-Session-Affinity
X-Country-Code
Access-Control-Request-Method
X-Kinja-Server
X-Kinja-Revision
X-Exp-Id
X-GoogleNews-Bot
X-Kinja
X-Cdn-Fetch
X-Exp-Variant
X-Use-Magma
X-Kinja-Build
X-Powered-By-Plesk
X-NF-Request-ID
X-Goog-Hash
X-Server-Lifecycle-Phase
X-Instrumentation
X-Kraken-Loop-Name
X-Origin-Cache
AR-Request-ID
X-Powered-CMS
AR-CACHE
AR-PoweredBy
AR-ATIME
AR-SID
Pagespeed
X-Sol
X-Version
X-Middleton-Display
Display
Response
X-Middleton-Response
X-TTL
X-Amz-Server-Side-Encryption
X-LLID
X-MSEdge-Ref
X-Kinsta-Cache
X-Edge-Location-Klb
X-SRCache-Store-Status
X-SRCache-Fetch-Status
Nginx-Cache
Accept-Ch
X-Edge
MRF-Tech
Mrf-Cache-Status
X-B3-TraceId-Primal
TCN
X-Protected-By
X-T
X-HP-Webp
X-HP-Trace-Id
X-Jurisdiction
X-Shield-Request-Id
X-RateLimit-Remaining
X-Forwarded-For
X-Content-Security-Policy-Report-Only
X-Mg-S
X-Id
S
Content-MD5
X-Aspnetmvc-Version
Edge-Cache-Tag
X-CST
SPIisLatency
Fastcgi-Cache
X-Language
SPRequestDuration
X-Mid
Front-End-Https
Realpath
X-Recruiting
X-Request-Processing-Time
X-Request-Received
Pinterest-Version
Filters
X-Pinterest-Rid
Pinterest-Generated-By
Server-Node
X-MCACHE
X-Frontend
Server-Name
X-Ua-Browser
X-Content
X-Ab
X-Correlation-Id
X-DynaTrace
X-Ser
X-HS-Content-Id
X-HS-Hub-Id
X-HS-Cache-Config
X-NWS-LOG-UUID
X-Ruxit-Js-Agent
X-Yandex-Sdch-Disable
X-HS-Combine-CSS
X-Ezoic-Cdn
X-Ttl
X-SharePointHealthScore
SPRequestGuid
X-Template
X-Hits
X-ECACHE
X-Parallel-Accel
X-Cache-Key
Alternate-Protocol
X-Tt-Trace-Tag
X-Tt-Trace-Host
MicrosoftSharePointTeamServices
Cache-Tags
X-Kong-Proxy-Latency
Fusion-Content-Source
Fusion-Deployment-Id
Fusion-Template-Id
X-Kong-Upstream-Latency
Fusion-Component-Id
Fusion-Source
Fusion-Content-Id
X-Page-Id
Cleartype
Host
Charset
X-B3-Sampled
X-Www-Served-By
X-Git-Hash
X-Content-Options
X-Geo-Country
X-Debug-Info
X-DIS-Request-ID
X-Daa-Tunnel
X-Amzn-Trace-Id
X-Ratelimit-Limit
X-Fastly-Request-Id
X-Content-Digest
X-Hostname
X-Amz-Replication-Status
Filterid
X-Varnish-Age
X-XRDS-LOCATION
X-AppVersion
X-Activity-Id
X-Az
Cross-Origin-Opener-Policy
X-FB-Debug
X-VCache
X-Upgrade-Enabled
X-Accel-Expires
X-Grace
X-Forwarded-Proto
X-N
X-WebKit-CSP-Report-Only
X-F-Cache
ServerID
X-Rid
X-Origin-Server
X-Nginx-Upstream-Cache-Status
Access-Control-Allow-Method
TP-L2-Cache
TP-Cache
X-Mobile-URL
X-Providence-Cookie
X-Flags
X-Request-Guid
X-Route-Name
X-Is-Crawler
X-Aspnet-Duration-Ms
X-LB-Cache
X-TT
X-Whom
X-App-Environment
Viewport
X-Type
X-Varnish-Grace
X-Seen-By
X-Goog-Generation
X-Goog-Metageneration
X-Tb
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-FW-Static
X-FW-Serve
X-Distributor
X-FW-Dynamic
X-FW-Hash
X-FW-Type
X-FW-Server
Payment
X-Server-ID
DC
Node
Paypal-Debug-Id
X-User-Agent
X-App-Server
Fastcgi-Useragent
Country
Accept-Charset
X-Wix-Request-Id
X-Cache-Control
X-NGENIX-Cache
X-DataDome
X-Cache-Rule
X-Origin-Upstream-Status
X-Litespeed-Cache
X-Fastcgi-Cache
Version
X-Ratelimit-Reset
X-Logged-In
X-Microsite
X-Via-JSL
X-Request-Handler-Origin-Region
X-Drupal-Cache-Tags
Referer-Policy
X-Fastly-Request-ID
X-Tec-Api-Root
X-Tec-Api-Origin
X-Tec-Api-Version
X-Cluster-Name
X-Webkit-Csp
X-Cache-Age
X-B-Cache
X-Webkit-CSP
X-Signature
X-Contextid
Refresh
X-Browser-Type
X-Erf-Bev-Bev-Is-Generated
X-Buckets
X-Erf-Bev-Bev
Cache-Status
X-Load-Cache
X-Varnish-Backend
SD-X-WS
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Node-Name
X-Original-Request-Id
X-Response-Served-From
X-Cache-Expired-At
X-Is-Bot
X-Real-IP
X-Vgn-Hpd-Reason
X-Page-View
X-Rendered-As
X-Mobile
Access-Control-Request-Headers
NGB
X-B
X-Debug
X-Proxy-Cache-Status
X-Jobs
X-Cacheable-TTL
X-Yottaa-Optimizations
X-Revision
X-Yottaa-Metrics
X-IPLB-Instance
X-Proxy
X-RemovedCookies
X-ProcessESI
X-Rule
X-Instance
X-UUID
X-Device-Type
X-Drupal-Cache-Contexts
Surrogate-Key
X-Cache-Action
Akamai-GRN
X-Debug-IsPreview
X-Cache-Time
X-Framework
X-Debug-IsConnected
X-FW-Version
X-G
Amp-Access-Control-Allow-Source-Origin
CF-IPCountry
SID
X-Air-Hostname
X-Air-Trace-Id
X-PressLabs-Stats
X-Air-Source
DynaTrace
X-Oracle-Dms-Rid
X-Oracle-Dms-Ecid
X-Azure-Ref
X-Accel-Buffering
X-Nginx-Cache
GEO-INFO
Liferay-Portal
X-Source
X-Ms-Request-Id
X-Ms-Version
X-Ratelimit-Remaining
Count-Hit
Uber-Trace-Id
X-TEC-API-VERSION
X-Oneagent-Js-Injection
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Cache-Operation
Frame-Options
X-Cache-NGX
Ms-Operation-Id
MS-CV
X-RTag
X-Presslabs-Stats
X-EdgeConnect-Cache-Status
Healthy
X-Zen-Fury
X-XRDS-Location
X-CDN-Forward
X-Cache-Hit
Protected
Countrycode
Xserver
X-APP-VERSION
X-Tumblr-Pixel-1
X-Varnish-Server
X-L-Path
X-Mode
X-Backend-Name
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Tumblr-User
X-Environment-Context
Cross-Origin-Window-Policy
Ec-Rule-Version
X-IPS-LoggedIn
X-Cache-TTL-Remaining
X-Region
X-Servername
X-Tid
Meta-Geo
X-Rewrite-Enabled
X-RN-RSRV
X-JoinUs
X-Hyper-Cache
X-RateLimit-Limit
X-SaId
Backend
X-Adobe-Content
X-Adobe-Loc
X-Forwarded-Host
X-Detected-As
X-UPSTREAM-Address
X-Cache-Server
Section-Io-Cache
X-Debug-Cache
Decoy-Debug-Key
X-Generation-Time
X-Content-Age
LB
Country-Code
X-Extlb
Decoy-Debug-Status
X-Hosted-By
X-Content-Powered-By
X-Sql-Count
X-Sorting-Hat-ShopId
X-Alternate-Cache-Key
X-Sql-Duration-Ms
X-Sorting-Hat-PodId
X-Redis-Cache
X-Cache-Grace
X-Shopify-Stage
X-Routing-Service
X-Proxied
X-ShopId
X-ShardId
X-Zipkin-Id
Apigw-Requestid
Decoy-Debug-TTL
X-Uri
Eomportal-Instance
Fastly-SSL
X-ApacheServer
Mn-Server-Ip
Url
X-No-Session
X-Format
X-PHP-Backend
X-Status
Cache-Name
X-Via-Fastly
X-Site-Version
X-Varnish-Beresp-Grace
X-PERF
X-ServerID
X-FB-TRIP-ID
X-Human
X-NCache
X-Origin-Date
TWC-Connection-Speed
Property-Id
Selected-Fe
X-Pubstack
X-UA-Device-Type
X-Timing-Wait
X-Microcachable
X-PCL
Cache-Tv-Group
X-Server-W
X-OCL
TWC-Device-Class
X-Access
TWC-Privacy
X-Proxy-Build
X-ProxyCache-Key
X-Akamai-Edgescape
X-BYPASS-REASON
X-Origin-Hint
X-Cache-Type
X-Cache-Host
Webcakes-Region
Webcakes-App-Version
TWC-GeoIP-LatLong
X-ProxyCache-Status
TWC-Locale-Group
X-Cluster-Node
X-Section
X-Storage
TWC-GeoIP-Country
Webcakes-App-Name
Content-Disposition
X-NewRelic-App-Data
X-Web-Node
X-Varnishpool
X-R9-Blue-Green-Version
X-Hl-Ver
X-NYM-Debug-Backend
X-Trace-Id
X-Say-TTL
X-Say-Cacheable
CDN-PullZone
CDN-RequestCountryCode
CDN-RequestId
CDN-Uid
X-SayCDN-TTL
CDN-EdgeStorageId
CDN-CachedAt
CDN-Cache
X-Generated-By
Content-Secure-Policy
X-Be
X-TIME
X-Azure-Ref-OriginShield
X-Soup
Azure-InstanceId
Azure-RegionName
Azure-SiteName
Azure-SlotName
Azure-Version
DB-Nickname
X-Ua
X-LSADC-Cache
WPO-Cache-Message
WPO-Cache-Status
OT-Force-Account-Verify
Retry-After
X-Dc
X-Nginx-Cache-Key
X-Cached-By
X-TT-LOGID
Source
SRV
X-Bc-Bl
X-Unique-Id
Cache
X-SRV
X-Platform-Server
X-LAGOON
X-App-Version
X-Auto-Login
X-Cache-Remote
X-Xfnlog-Site
X-Varnish-Hits
X-Akamai-Transformed
Cache-Hits
X-GEO
HostName
X-Origin-TTL
X-HTML-Minification-Powered-By
X-TNCMS
X-Cache-Tags
X-Varnish-Hostname
X-Origin-CC
ServedBy
X-Loop
X-S-Maxage
X-ECache
Mime-Version
X-CSRF-Token
Onion-Location
X-Cdn
X-Varnish-Cache-Hits
Upgrade-Insecure-Requests
X-Amz-Meta-S3cmd-Attrs
Xet-Cookie
From-Origin
X-Request-Time
Web-Mar-Node
X-Tumblr-Pixel-2
Webserver
X-AOL-HN
X-Tumblr-Pixel-3
X-EC-Lua
X-Time
X-Request-Host
X-Proto
WP-Super-Cache
X-B3-SpanId
N-Cache
X-Tenant
X-Endurance-Cache-Level
X-NWS-UUID-VERIFY
X-VWS-Id
X-Cache-Enabled
X-LJ-Flow-ID
X-FireWall-Port
X-AWS-Id
X-GG-Cache-Date
X-Time-Microsecs
X-Handled-By
AMP-Access-Control-Allow-Source-Origin
X-Cache-Var
X-Origin-Response-Time
X-Cache-Var-Map
X-ND-Cache
User-Cache-Control
V-Age
Vix-Hermes-Req-Id
X-PAYTM-SRV-ID
X-Orig-Expires
X-Ig-Push-State
X-NAPM-TraceId
X-A
X-Hnp-Log
X-Destination
Odigeo-Trace-Id
X-Block-Status
X-B-Cookie
X-Cache-NE
Mobile-Detection-Method
X-CF-Lambda-Version
X-CF-Lambda-Fn
Meta-Geo-Continent
X-ARC
Pramga
Sslversion
X-A-Wwc
Surrogated-Key
X-Aed
X-Aicache-OS
Redirect-Candidate
X-Application
Rendered-Blocks
X-Ckpd-Fst-Backend
X-Cluster
X-External-Request-Id
DCR-Decision-By
DCR-Processing-Time-Ms
X-Forwarded-Path
X-Ftr-Request-Id
X-Gen-Mode
A
BehaviorPad-Version
X-Developer
Expiry
X-A-Dam
X-Conf
X-A-Dcw
X-Connection-Hash
X-D
Fastcgi-X-Cache-Version
X-A-Dgt
X-Planisys-CDN-Cache
X-A-Ccd
X-PBS-Appsvrname
X-Vtex-Remote-Cache
X-Rojux
X-S
X-S-Cookie
X-Correlation-ID
X-Vtex-Processado-Em
X-VG-WebCache
X-V-Cache
X-Via-NSCOPI
X-Vdms-Path
X-Vdms-Version
X-Mg-Request-UUID
X-TIM-N
X-SRCache-Key
X-SD-PageType
X-Slack-Backend
X-Shop-Environment
X-Planisys-CDN-Rules
X-Session-Fingerprint
X-ScT
X-Processor
Nel
Xc-Version
X-Planisys-CDN-TTL
X-Magnolia-Registration
X-PHP-Host
X-Reqid
X-Adobe-Source
X-Labrador-Cache-Channel
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Edge-Location
CloudFront-Viewer-Country
X-MP-GENERATED-AT
Wxu-Next-Region
Svr
Fastcgi-Cache-TTL
True-Client-Country-4JS
Wxu-Next-Commit
Cmsid
X-Fastly-Cache
X-Backend-TTL
X-Date
DSUID
Wxu-Next-Hostname
X-Sucuri-Cache
X-SVT-ORM-VERSION
X-Epic-Correlation-Id
X-Cache-Bucket
Origin
CacheControlHeader
X-Cdn-Srv
X-SVT-ORM-RULES
X-Viewer-Country
Host-ID
X-Cache-Date
X-Sucuri-ID
State
X-Accel-Expires-Debug
X-Webstats-RespID
Gh-Request-Id
Cmstype
X-Proxy-Upstream
X-Mvc-Supplant-Cachable
X-Li-Fabric
X-Nyt-Route
X-Policy
X-Old-Content-Length
X-Hash
X-Scheme
X-LI-UUID
X-Li-Pop
X-Forwarded-Site
X-Location
X-RCS-CacheZone
X-Men
X-Geo-Header
X-NodeID
AKAMAI
X-Origin-Time
Arc-Country
X-Gdpr
X-Server-IP
X-Origin-Expires
Environment
X-Req
Apple-News-Services-Request-Url
X-Locale
X-Varnish-Beresp-Status
X-Branch-Name
Apple-News-Services-Parsed-Url
Web-Mar-Region
X-Region-Sid
X-VServer
X-Rocket-Nginx-Serving-Static
Apple-News-Services-Host
Apple-News-Services-Handled
X-RateLimit-Limit-Second
X-VG-TLSProxy
X-Platform
X-RateLimit-Remaining-Second
We-Hiring
X-Cache-Info
X-Origin
X-Generated-On
X-Sn-Servicetimems
X-GeoIP-Country-Code
X-Storefront-Renderer-Rendered
X-Datadog-Trace-Id
X-GeoIP
X-Developers
X-Skip-Cache
X-Fastly-Backend
X-Fetched-On
X-Gamma-Serve
X-Served-From
X-Device-Os
X-Esi-Check
X-Datadog-Sampling-Priority
X-GeoIP-City
X-TH-Server
X-Irp-Debug
X-Level-Front-Cache
X-TrackingId
X-UnsetCookies
X-Cache-Id
X-HS-Content-Campaign-Id
X-Request-Start
X-Gzip
X-Datadog-Parent-Id
X-Core-Value
X-Core-Mission
X-Request-URI
X-GeoIP-Region-Code
X-Cache-Debug
X-Cdn-Origin
Mail-Subject
Release
CDCHOST
Fastly-Drupal-Html
Ssr
Server-Info
Traceparent
Origin-EX
Locid
Origin-CC
Machine
Server-Host
X-CACHE-KEY
S-Rt
X-Rebelmouse-Cache-Control
Ha-Gx-Prefs
HA-Ipaddr
X-Csrf-Jwt
X-FC-Vary-Parameters
Cf-Device-Type
X-Eu-Site
X-Envoy-Decorator-Operation
X-DefElseHash
Fastly-SIE
X-DefHash
X-Sigma-Backend
Fastly-SWR
X-DPWN-IS-SECURE
X-VarnishDD-TTL
X-Thinkindot-L3
X-NU-AKA-ACS-Version
X-Response-By
X-Node-Id
X-JWT-State
X-VC-Cache
X-Owner
X-Rebelmouse-Surrogate-Control
X-Qloud-Router
X-Pod-Name
X-Is-Gdpr
X-Qnm-Cache
Adler-Geo
X-Variation
X-Varnish-CookieHashed-On
Is-Eu
X-M-Log
X-HN
X-Has-Esi
X-M-Reqid
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
Platform
X-Worker
X-ATG-Version
X-Rocket-Build-Number
X-Sigma
X-Backend-State
L
TDXMobile
X-BBC-Edge-Cache-Status
Req-Svc-Chain
Fastly-GeoIP-CountryCode
Thinkindot-Control
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
PFcat
X-Amzn-Remapped-Content-Length
NM-Fastcgi-Cache
Memcached
L5d-Success-Class
X-CGP
X-CS
X-Xrds-Location
NGX
X-Akamai-Request-ID2
Magicmarker
X-Http-Reason
X-Mvc-Supplant-OutputCached
X-Zone
X-Thanos
X-Loc
X-Bip
X-Varnish-Beresp-Ttl
X-Ua-Device
X-NC
X-LB-ID
X-TraceId
X-Restarts
X-API-Version
X-CLOUD-TRACE-CONTEXT
X-Up
X-Tx-Id
X-Cache-Config
CDN
X-Generated-In
Kp-EeAlive
X-Datadome
Ms-Author-Via
X-RSL
Pics-Label
Time
X-Cache-Backend
X-DW
Edge-Cache
X-RPM
X-Wix-Viewer-Type
X-Action
X-RPS
X-DB
X-Trace-ID
X-DI
X-DSS
Memory
X-Tb-Optimization-Total-Bytes-Saved
X-Via-Popn
X-Optimistic-Header
X-Edge-Pop
X-Refresh
Env
X-Via-Popv
X-Via-Poph
X-LB-NoCache
Accept-Language
X-Varnish-Ttl
X-CacheTTL
Candidate-Md5Url
X-Minions-Version
WebServer
GeoIp-Country-Code
NtCoent-Length
Datacenter
X-Tt-Logid
X-HA-Backend
X-DynaTrace-JS-Agent
X-Srv
X-Vc
X-DC
WWW-Authenticate
X-Urbn-Context-Path
X-Urbn-Site-Id
Locale
On-Server
X-TX-ID
X-ZONE
X-Varnish-Beresp-TTL
X-Esi
X-MSEdge-Flight
Esi-Enabled
X-MSEdge-Features
X-Parent-Response-Time
X-Dynatrace
Server-ID
X-Ec-Fail
X-Ec-GeoHdr
X-User
X-Servedbyhost
X-Unique-ID
X-Cs
X-Service
C-Via
X-Newrelic-Synthetics
X-TA-CDN-Provider
X-Li-Proto
X-Cache-PHP
X-App
X-AK-Request-ID
Cdnsip
Cdncip
X-FPC
X-VCL-Version
X-Cache-Ttl
X-URL
X-Fmm-Version
X-Webkit-Csp-Report-Only
X-Vcl-Version
X-WADP-Cache
Cluster
Test
My-App
Geoip-Latitude
X-Cache-Status-Check
X-Fpc
X-Clara-WADP
X-LI-Proto
X-Render-Time
X-Traceid
X-LiteSpeed-Cache-Control
X-B3-Spanid
X-CUA
X-Var-Ttl
Tracecode
Geo-Info
X-Pass-Why
Proxy-Connection
X-NODE
X-Webkit-CSP-Report-Only
Server-Id
Lfy
X-From
T-Server
Cf-Int-Pingora-Origin-Digest
DataCenter
Fastly-Drupal-HTML
X-Mcache
Resin-Trace
X-Fragments
M-TraceId
Lang
X-VC
X-Clientip
Target-Params
X-ServedByHost
X-LiteSpeed-Tag
X-CSRF-TOKEN
X-AIR-PT
X-Info
X-Ha-Backend
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
X-Geo
X-Oss-Request-Id
X-Oss-Server-Time
X-Oss-Storage-Class
X-Oss-Hash-Crc64ecma
UCS
HIT
Cache-Host
X-ID
X-Oss-Object-Type
MIME-Version
X-Cdn-Forward
Hostname
X-RAMCache
X-Pad
S-Cnection
GeoIP-Country-Code
Hit
X-Dynatrace-Js-Agent
X-Provided-By
Section-Io-Id
Ohc-File-Size
Tcn
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
ENV
Section-Origin-Responded
X-Via-PopV
X-Via-PopN
X-Via-PopH
X-Proxy-Cache-Info
X-Edge-POP
X-Httpd
Permissions-Policy
X-Api-Version
X-NGINX-Cache
Producers
WZWS-RAY
User-Agent
Fastly-Backend-Name
X-ElasticPress-Query
X-Check-Cacheable
Load-Balancing
X-HS-Status
X-Edge-Cache
X-Micro-Cache
Servername
X-Ucs
X-Cache-CFC
X-Lb-Nocache
X-ServerName
ServerName
X-Release
X-SB
X-Backend-Host
X-Fastly-Backend-Reqs
X-BBC-Origin-Response-Status
X-HostName
X-UP
X-GoCache-CacheStatus
Wpo-Cache-Message
X-Acquia-Application-UUID
X-Platform-Cluster
FSS-Cache
X-Acquia-Application-Trace
X-APP
PICS-Label
X-BCube-Filmed-By
X-Acquia-Site
Uri
X-Platform-Processor
X-Platform-Router
X-Pool
Wpo-Cache-Status
URI
X-Acquia-Purge-Tags
X-Udemy-Cache-App-Namespace
X-TRACE-ID
X-Swift-Error
X-Cdn-Request-ID
Server-Ttl
X-Fastly-Cache-Hits
X-Nc
Ohc-Cache-HIT
Cneonction
EpKe-Alive
Cdn
X-RateLimit-Reset
X-Lb-Id
Cteonnt-Length
X-Ec-Custom-Error
X-Scale
X-Dw-Trace-Id
X-Apw-Access-Action
X-Akamai-ERPolicy
X-Akamai-ERRuleID
X-Amz-Meta-Cb-Modifiedtime
X-Apw-Access-Object
VNS-Age
Vha6-Origin
VNS-Cache
X-Snapshot-Date
X-IN-APIGATEWAY
X-Yottaa-OS
X-Apw-Access-Token
X-Dispatcher-Number
X-Contensis-Viewer-Groups
X-Cache-ASPX
X-SIPLIST1
X-WA-Info
X-WA
Cf-Ipcountry
Shield-Pop
X-Litespeed-Cache-Control
X-B3-ParentSpanId
X-Cache-Expires
CPC-Cache
CPC-Age
Server-Ext
MD5-Digest
X-Apw-Hits
IsBot
Cache-Key
Server-Hostname
X-Vcache
X-B3-Parentspanid
Path
CF-Cached-On
X-Newrelic-App-Data
Sever-Int
X-IN-APIGATEWAYSSL
X-Air-Pt
Sid
X-Cache-Ngx
Lb
X-Shopify-Generated-Cart-Token
CountryCode
X-CacheKey
X-UA
X-Akamai-Pragma-Client-IP
X-Logging-Id
X-Varnish-Authentication
X-Wikidot-Static-Cache
X-Wikidot-Backend
Req-ID
X-ES-SERVER
X-Te-Count
X-Te-Duration-Ms
X-Last-Modified
X-Http-Duration-Ms
X-Http-Count
X-Sentry-ID
Ngx
X-Akamai-Request-ID