Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
X-Powered-By
Pragma
X-XSS-Protection
CF-RAY
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
Alt-Svc
P3P
X-Cache-Hits
X-Xss-Protection
X-UA-Compatible
X-Served-By
CF-Ray
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
Access-Control-Allow-Credentials
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
X-Drupal-Cache
X-Cache-Status
X-Generator
X-Check
X-Cacheable
X-FRAME-OPTIONS
X-Envoy-Upstream-Service-Time
Timing-Allow-Origin
X-Dns-Prefetch-Control
X-Iinfo
X-DNS-Prefetch-Control
Server-Timing
X-Drupal-Dynamic-Cache
Feature-Policy
X-Content-Security-Policy
Access-Control-Expose-Headers
X-XSS-PROTECTION
Content-Encoding
X-CDN
Status
Upgrade
X-AspNetMvc-Version
Access-Control-Max-Age
X-Request-ID
X-Amz-Request-Id
X-Via
X-Ua-Compatible
X-Amz-Id-2
Request-Context
X-Backend
X-Cache-Group
X-Turbo-Charged-By
X-Robots-Tag
Cf-Edge-Cache
Keep-Alive
Host-Header
X-AH-Environment
X-Vhost
X-Hacker
X-UA-Device
X-Proxy-Cache
X-Server
Allow
X-Rq
X-Server-Powered-By
X-Ws-Request-Id
X-Dispatcher
EagleId
X-Age
X-Varnish-Cache
X-Amz-Version-Id
P3p
Nel
X-LiteSpeed-Cache
Grace
Cf-Apo-Via
Cf-Railgun
X-OneAgent-JS-Injection
X-Page-Speed
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
EagleEye-TraceId
X-Device
X-Swift-SaveTime
X-Swift-CacheTime
X-Aws-Lambda-Call-Status
Ali-Swift-Global-Savetime
X-Pingback
X-Host
X-Cache-Lookup
X-CST
Accept-CH
X-Node
X-WebKit-CSP
X-Backend-Server
Surrogate-Control
Permissions-Policy
X-Server-Id
X-Nginx-Upstream-Cache-Status
X-Readtime
X-Akam-SW-Version
X-Nginx-Cache-Status
Accept-CH-Lifetime
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Request-Id
X-Application-Context
Xkey
X-Ruxit-JS-Agent
X-Cloud-Trace-Context
X-Content-Security-Policy-Report-Only
X-Response-Time
X-HW
X-Trace
X-Edge
Content-Location
X-Clacks-Overhead
X-Mod-Pagespeed
Rating
X-Url
X-Midtier
X-ESI
X-Amz-Server-Side-Encryption
X-ECACHE
Cache-Tag
X-Mcache
X-Rack-Cache
X-Powered-By-Plesk
X-Country
Accept-Ch
X-MS-InvokeApp
Service-Worker-Allowed
X-D2id
X-GoogleNews-Bot
X-Kinja-Revision
X-Use-Magma
X-Exp-Variant
X-Cdn-Fetch
X-Kinja
X-Kinja-Server
X-Exp-Id
X-Kinja-Build
Verso
X-Vcap-Request-Id
X-Element-Page-Cache
Edge-Control
X-Upstream
Accept-Ch-Lifetime
X-Country-Code
X-Ac
Origin-Trial
RTSS
X-Kinja-CCPA
X-PC
X-Vname
X-TtlSet
X-Goog-Hash
X-Navigation-Version
X-VARITI-CCR
X-Abt-Application-Version
X-Browser-Type
X-Cache-TTL
X-Oneagent-Js-Injection
Fastly-Restarts
X-NWS-LOG-UUID
X-Amz-Rid
X-Aspnetmvc-Version
X-Varnish-TTL
X-Litespeed-Cache
X-GitHub-Request-Id
X-Webkit-CSP
Cross-Origin-Opener-Policy
X-Cached
X-Server-Name
X-Amzn-Trace-Id
X-Dw-Request-Base-Id
X-Times
X-Sol
Display
X-Middleton-Display
Pagespeed
X-Server-ID
X-SharePointHealthScore
SPRequestGuid
Pinterest-Version
Pinterest-Generated-By
X-Ruxit-Js-Agent
X-Pinterest-Rid
X-Ttl
SPRequestDuration
SPIisLatency
X-Server-Lifecycle-Phase
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Instrumentation
X-Kraken-Loop-Name
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-WebKit-CSP-Report-Only
X-Cache-Key
X-Content-Type
AR-Request-ID
AR-ATIME
AR-SID
AR-PoweredBy
X-Powered-CMS
X-Client-IP
Arr-Disable-Session-Affinity
X-Version
X-B3-Traceid
X-Cnection
X-Mg-S
X-FastCGI-Cache
X-Middleton-Response
Response
X-Ser
Nginx-Cache
X-HP-Webp
X-Jurisdiction
X-HP-Trace-Id
X-Accel-Expires
Cache-Tags
X-T
X-SRCache-Store-Status
X-SRCache-Fetch-Status
AR-CACHE
X-Fastly-Request-ID
X-B3-TraceId
Cache-Status
X-NF-Request-ID
Edge-Cache-Tag
X-Hits
X-Px
X-MSEdge-Ref
Public-Key-Pins
X-Recruiting
Front-End-Https
X-RateLimit-Remaining
S
X-Daa-Tunnel
X-Shield-Request-Id
Payment
X-Frontend
Server-Node
X-LLID
X-Ua-Browser
X-Request-Received
X-Request-Processing-Time
Content-MD5
X-RateLimit-Limit
X-Goog-Metageneration
X-GUploader-UploadID
Mrf-Cache-Status
MRF-Tech
X-B3-TraceId-Primal
X-Content-Digest
Access-Control-Request-Method
X-Amz-Apigw-Id
X-Amzn-RequestId
MicrosoftSharePointTeamServices
X-DIS-Request-ID
X-Webkit-CSP-Report-Only
X-Forwarded-For
X-Protected-By
X-TTL
TP-Cache
Realpath
X-Microsite
X-Distributor
X-Request-Handler-Origin-Region
X-Ratelimit-Remaining
X-FB-Debug
X-PressLabs-Stats
Fastcgi-Cache
X-HS-Content-Id
X-HS-Cache-Config
X-HS-Hub-Id
X-HS-Combine-CSS
Access-Control-Allow-Method
X-Page-Id
Accept-Charset
X-Cluster-Name
X-Rid
X-LB-Cache
X-Id
X-Xrds-Location
X-Fastcgi-Cache
Count-Hit
X-Aspnet-Version
X-Ua-Device
X-B3-Sampled
X-Edge-Location-Klb
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Kinsta-Cache
X-Geo-Country
Cross-Origin-Resource-Policy
X-Hostname
TP-L2-Cache
X-App-Server
X-Seen-By
X-Correlation-Id
X-Ratelimit-Limit
TCN
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-Varnish-Backend
X-Logged-In
X-TEC-API-ROOT
X-Ezoic-Cdn
Cleartype
X-Hosted-By
X-Content-Options
X-Git-Hash
X-Mobile
Referer-Policy
Retry-After
X-Erf-Stays-Pdp-Viaduct-Migration-Web
DC
X-Contextid
X-Fb-Rlafr
X-Aspnet-Duration-Ms
X-Flags
X-F-Cache
X-Route-Name
X-Request-Guid
X-Providence-Cookie
X-Is-Crawler
X-Newrelic-App-Data
X-Origin-Cache
X-Revision
X-Grace
Surrogate-Key
X-Forwarded-Proto
X-TT
X-App-Environment
X-Amz-Replication-Status
X-Debug-Info
Frame-Options
X-IPS-LoggedIn
X-Amz-Meta-S3cmd-Attrs
X-Varnish-Grace
X-Azure-Ref
X-Envoy-Decorator-Operation
Section-Io-Cache
MS-Author-Via
X-Magnolia-Registration
X-Www-Served-By
X-RateLimit-Reset
X-App-Version
X-COUNTRY
X-Wix-Request-Id
X-Trace-Id
X-Proxy-Cache-Info
X-Whom
X-Webkit-Csp
X-Language
Healthy
Charset
Filterid
X-AppVersion
X-Activity-Id
X-Az
X-Akamai-Edgescape
WPO-Cache-Status
WPO-Cache-Message
Viewport
X-Kong-Proxy-Latency
X-Varnish-Server
Server-Name
X-Kong-Upstream-Latency
X-Backend-Name
Amp-Access-Control-Allow-Source-Origin
Alternate-Protocol
X-Origin-Server
X-Datadog-Sampling-Priority
X-Datadog-Trace-Id
X-Datadog-Parent-Id
Paypal-Debug-Id
X-Cache-Rule
X-Original-Request-Id
X-EdgeConnect-Cache-Status
VIX-Pulpo-Upstream-Status
Host
VIX-Pulpo-Node
X-Http-Reason
X-B
X-Response-Served-From
X-Nf-Request-Id
X-User-Agent
X-UUID
X-N
X-Yottaa-Metrics
X-Rule
X-DataDome
X-Cache-Grace
X-Akamai-Request-ID2
Front
X-Yottaa-Optimizations
SRV
X-Edge-Location
X-Instance
X-Cacheable-TTL
Protected
X-B-Cache
From-Origin
X-Unique-Id
X-Environment-Context
Content-Disposition
X-Load-Cache
X-Vcache
X-ARC
X-Signature
X-Jobs
SD-X-WS
X-Region
X-L-Path
X-Page-View
X-Framework
Country
X-RemovedCookies
X-Mg-Request-UUID
X-ProcessESI
X-Adobe-Content
X-Adobe-Loc
X-FW-Server
Fastly-SWR
X-FW-Static
X-Varnish-Age
X-FW-Hash
X-FW-Type
X-FW-Dynamic
X-FW-Version
X-Is-Bot
X-Status
X-Rocket-Nginx-Serving-Static
X-Rendered-As
X-FW-Serve
Akamai-GRN
Fastly-SIE
X-Datadog-Sampled
X-Tumblr-User
X-Proxy
X-G
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Type
X-Tumblr-Pixel-1
X-Cache-Time
X-Time
X-Debug-IsPreview
X-Amzn-Remapped-Content-Length
X-Debug-IsConnected
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
Access-Control-Request-Headers
ServerID
X-ECache
X-CDN-Forward
X-Tec-Api-Version
X-Client-Ip
X-Tec-Api-Root
X-Tec-Api-Origin
Backend
X-Erf-Web-Scheduler
X-Cache-Age
Refresh
X-Servername
X-Nginx-Cache
Xet-Cookie
X-Tt-Trace-Tag
X-DynaTrace
X-Tt-Trace-Host
X-Cache-Control
Url
Countrycode
X-Httpd
X-Template
Accept-Language
X-Drupal-Cache-Tags
CF-IPCountry
X-Device-Type
X-DynaTrace-JS-Agent
X-Mode
X-Content-Powered-By
X-NYM-Debug-Backend
X-Generated-By
X-FTR-Request-ID
Webserver
X-HTML-Minification-Powered-By
Xserver
X-Cache-Hit
X-Storage
X-URL
X-CCDN-CacheTTL
X-CCDN-Origin-Time
X-Hcs-Proxy-Type
GEO-INFO
X-Say-TTL
X-ServerID
X-Content-Age
X-SayCDN-TTL
X-Say-Cacheable
X-UPSTREAM-Address
X-XRDS-LOCATION
X-Urbn-Context-Path
X-Urbn-Site-Id
X-SaId
Cross-Origin-Window-Policy
Version
Locale
X-GeoCode
X-Tncms
X-Director
Meta-Geo
S-Rt
X-GeoCountry
X-Cache-Operation
Load-Balancing
Filters
X-Rn-Rsrv
X-Rewrite-Enabled
X-JoinUs
X-LAGOON
X-Loop
X-Soup
X-Served-From
X-Tt-Logid
X-Cache-Action
Onion-Location
X-Forwarded-Host
X-Git-Commit
OT-Force-Account-Verify
X-Cluster-Node
X-Varnish-Cache-Hits
X-Container-Uri
X-Source
X-MCACHE
X-NGENIX-Cache
X-RM-Cache-TTL
X-Adobe-Source
X-Detected-As
Azure-Version
Web-Mar-Node
Azure-SlotName
X-Ms-Request-Id
Azure-InstanceId
Azure-RegionName
X-Ms-Version
Azure-SiteName
X-VC-Cache
X-VCT
X-Tb
X-Labrador-Cache-Channel
X-Lambda-Id
X-R9-Blue-Green-Version
X-PHP-Host
X-Sql-Duration-Ms
X-Skip-Cache
X-Varnish-Hostname
X-Sql-Count
X-Proxied
X-Routing-Service
Node
X-Zipkin-Id
X-FB-TRIP-ID
DB-Nickname
Mn-Server-Ip
X-Extlb
X-Cache-Server
X-Logging-Id
X-B3-SpanId
X-RCS-CacheZone
X-Redis-Cache
X-Timing-Wait
TWC-Connection-Speed
TWC-Device-Class
TWC-GeoIP-Country
X-Tumblr-Pixel-2
Selected-Fe
Property-Id
X-Uri
X-Generation-Time
X-Format
TWC-GeoIP-LatLong
X-Tumblr-Pixel-3
X-Debug
Webcakes-Region
Webcakes-App-Version
TWC-Privacy
X-Fetched-On
Webcakes-App-Name
X-Origin-Hint
TWC-Locale-Group
Fastcgi-Useragent
X-Proxy-Build
X-Endurance-Cache-Level
X-Proto
Uber-Trace-Id
X-Zen-Fury
Source
X-LSADC-Cache
CDN-RequestId
X-Ua
X-Sucuri-ID
X-S
X-Sucuri-Cache
X-XRDS-Location
Section-Origin-Responded
X-Ratelimit-Reset
Section-Io-Origin-Time-Seconds
Section-Io-Id
Section-Io-Origin-Status
X-TimeS
NGB
X-Oracle-Dms-Ecid
X-Oracle-Dms-Rid
X-Origin-TTL
X-Origin-CC
Upgrade-Insecure-Requests
X-Akamai-Transformed
X-Origin-Date
X-Drupal-Cache-Contexts
X-MP-GENERATED-AT
X-Real-IP
X-Newrelic-Synthetics
X-Pass-Why
X-Varnish-Hits
X-Handled-By
X-TraceId
Fastly-Drupal-HTML
X-Cache-Expired-At
X-Srv
X-Xfnlog-Site
X-Reqid
X-AB
Apigw-Requestid
X-No-Session
X-Optimistic-Header
X-Cms-Context
X-Restarts
ServedBy
MS-CV
X-CACHE-AGE
X-RTag
Ms-Operation-Id
X-GEO
X-BYPASS-REASON
X-Cache-Host
Liferay-Portal
X-ProxyCache-Status
X-ProxyCache-Key
X-Varnish-Ttl
X-Tx-Id
WP-Super-Cache
X-Hl-Ver
X-Geo-Region
CDN-PullZone
CDN-Cache
CDN-RequestCountryCode
CDN-CachedAt
CDN-EdgeStorageId
X-AWS-Id
X-IPLB-Request-ID
X-LJ-Flow-ID
X-VWS-Id
X-IPLB-Instance
X-Cluster
CDN-Uid
X-Cache-Type
CDN-RequestPullCode
CDN-RequestPullSuccess
X-Fastly-Request-Id
X-UA-Device-Type
X-Cache-TTL-Remaining
X-CSRF-Token
X-Upgrade-Enabled
Cache-Provider
X-Proxy-Cache-Status
X-Node-Name
X-Parent-Response-Time
Origin-Agent-Cluster
X-A-Dam
BehaviorPad-Version
Candidate-Md5Url
X-A-Ccd
Web-Mar-Region
X-A
X-FC-Vary-Parameters
X-Cache-Status-Check
X-Fastly-Backend
X-Request-Host
X-A-Wwc
X-Rojux
X-A-Dgt
X-Pubstack
X-Aed
X-A-Dcw
X-Micro-Cache
X-S-Cookie
Redirect-Candidate
X-External-Request-Id
X-Eu-Site
True-Client-Country-4JS
X-Epic-Correlation-Id
Server-Host
X-PAYTM-SRV-ID
X-Level-Front-Cache
Sslversion
Surrogated-Key
T-Server
X-Ec-GeoHdr
Rendered-Blocks
Ha-Gx-Prefs
Gannett-Cam-Experience-Id
X-Dispatcher-Number
W
X-Thanos
Vix-Hermes-Req-Id
X-Via-JSL
X-Ec-Fail
X-Ec-Custom-Error
X-Developer
X-Destination
X-CacheTTL
DCR-Decision-By
X-We-Are-Hiring
DCR-Processing-Time-Ms
Lang
X-Cache-NE
X-ScT
X-Slack-Shared-Secret-Outcome
X-Worker
Magicmarker
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-Debug-Cache-Fetch
X-Viewer-Country
X-Csrf-Jwt
X-D
X-Debug-Cache-Store
X-Conf
X-CGP
L5d-Success-Class
X-Vtex-Remote-Cache
L
Xc-Version
X-Slack-Backend
X-B-Cookie
Meta-Geo-Continent
Fastly-SSL
X-Bc-Bl
X-Generated-On
Ngx.Var.Host
X-App
Odigeo-Trace-Id
X-Application
X-BCube-Filmed-By
N-Cache
X-Vdms-Path
X-Bl-Debug
MD5-Digest
X-SRCache-Key
X-Bip
X-Vdms-Version
HA-Ipaddr
Cache-Name
X-TIME
X-Mvc-Supplant-Cachable
X-Nananana
Host-ID
Mail-Subject
X-Nitro-Cache
Is-Eu
X-Mly-Id
Producers
Release
Req-Svc-Chain
Platform
X-Mid
X-Alternate-Cache-Key
X-Forwarded-Path
X-Cdn-Diag
X-Cdn-Origin
X-Cache-Info
X-Cache-Debug
X-BBC-Edge-Cache-Status
X-Cache-Bucket
X-Clientip
X-CMSURLCustom
X-DefHash
X-Dispatcher-Server
X-DPWN-IS-SECURE
X-DefElseHash
X-Date
X-Core-Mission
X-Core-Value
X-Gdpr
X-Geo-Header
X-Irp-Debug
VNS-Age
VNS-Cache
Thinkindot-Control
Thinkindot-CacheControl-Type
TDXMobile
Thinkindot-CacheControl
We-Hiring
X-Accel-Buffering
X-GeoIP-Country-Code
X-ApacheServer
X-App-Name
Gh-Request-Id
X-GeoIP-Region-Code
X-Accel-Expires-Debug
X-Human
X-Loc
X-Nyt-Route
X-Hash
X-Platform
X-Sn-Servicetimems
X-Wikidot-Backend
X-Policy
X-Server-W
X-PERF
X-Owner
X-Vmg-Version
X-VG-WebCache
X-Orig-Expires
X-Sorting-Hat-ShopId
X-Origin-Time
X-VServer
X-Wikidot-Static-Cache
X-Pool
X-Shop-Environment
X-ShopId
X-SD-PageType
X-ShardId
Origin
X-Server-IP
X-Shopify-Stage
X-Request-Time
X-Vgn-Hpd-Reason
X-Qloud-Router
X-Wix-Viewer-Type
Datacenter
X-Refresh
X-VG-TLSProxy
X-Sorting-Hat-PodId
Cmsid
X-Old-Content-Length
CloudFront-Viewer-Country
X-Correlation-ID
X-Up
X-Tenant
Cmstype
X-Varnish-CookieHashed-On
X-Var-Ttl
CPC-Cache
X-Variation
X-NodeID
CPC-Age
X-Thinkindot-L3
Canary
Expect-Staple
X-Storefront-Renderer-Rendered
Fastly-Backend-Name
Fastly-GeoIP-CountryCode
Adler-Geo
AKAMAI
X-SVT-ORM-RULES
Environment
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
X-SVT-ORM-VERSION
X-Varnishpool
X-Tcp-Rtt
X-Is-Mobile
X-Is-Tablet
X-Is-Desktop
X-Browser-Name
X-Is-Supported-Browser
X-Accel-Version
X-AIR-PT
NM-Fastcgi-Cache
X-Clara-WADP
X-Fmm-Version
X-WA-Info
X-Ah-Environment
X-Gen-Mode
X-WADP-Cache
X-Esi-Check
X-Forwarded-Site
X-Cache-Id
Esi-Enabled
X-Datadome
X-Block-Status
X-INCAP-ABP
X-Org
X-Test
X-Origin-Response-Time
X-GeoIP
X-Mvc-Supplant-OutputCached
User-Cache-Control
CDCHOST
X-Origin
Sever-Int
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
Server-Ext
Apple-News-Services-Request-Url
Server-Hostname
X-Op-Id-All
Apple-News-Services-Handled
X-From
X-Node-Id
X-NCache
X-Hnp-Log
X-Gzip
X-Auto-Login
DSUID
X-Device-Os
X-S-Maxage
X-RateLimit-Remaining-Second
Country-Code
X-RateLimit-Limit-Second
Machine
Cf-Device-Type
X-Buckets
X-B3-Spanid
NGX
X-Nginx-Cache-Key
Pics-Label
C-Via
X-LB-NoCache
Wxu-Next-Hostname
X-Cache-Enabled
Wxu-Next-Commit
X-Access
Server-Info
Ssr
Wxu-Next-Region
X-Instance-Name
X-Vcl-Version
X-Via-Fastly
X-Section
X-Cdn-Srv
Content-Secure-Policy
AMP-Access-Control-Allow-Source-Origin
X-Amz-Meta-Cb-Modifiedtime
X-Varnish-Beresp-Ttl
X-Zone
X-Presslabs-Stats
X-Akamai-Device-Characteristics
Server-ID
X-CACHE-GROUP
X-Dc
X-Varnish-Beresp-Grace
X-API-Version
X-Origin-Cache-Key
YJS-ID
X-HA-Backend
IsBot
X-SIPLIST1
CF-Ctrl
X-B3-Parentspanid
X-WP-CF-Super-Cache-Active
X-JWT-State
Memcached
X-Frame-Option
X-Platform-Cluster
X-Platform-Processor
X-Platform-Router
X-Has-Esi
X-Cached-By
X-Is-Gdpr
Cdn-Requestid
Sid
Location
Cache-Hits
Hostname
Time
X-Internal-Host
Memory
X-Wp-Cf-Super-Cache-Active
X-FTR-Cache-Status
X-Country-Code-Real
X-FTR-Expires
X-FTR-Balancer
X-FTR-Backend
X-FTR-Backend-Server
X-TIM-N
X-Hyper-Cache
X-Fpc
X-Tb-Optimization-Total-Bytes-Saved
Origin-CC
X-Air-Trace-Id
Origin-EX
X-Scale
X-Air-Hostname
X-Air-Source
X-TA-CDN-Provider
X-Webstats-RespID
X-LiteSpeed-Cache-Control
X-Backend-Instance
X-Cs
X-DC
X-ID
X-Service
X-SRV
X-PHP-Backend
X-ZONE
X-VC
Resin-Trace
X-DataCenter
X-NewRelic-App-Data
Epwk-X-Cache
LB
X-Esi
True-Client-Ip
X-Site-Version
X-Webkit-Csp-Report-Only
Uri
X-NGINX-Cache
X-Azure-Ref-OriginShield
WZWS-RAY
GeoIp-Country-Code
X-Locale
X-Nitro-Cache-From
X-NODE
GeoIP-Latitude
X-Nitro-Rev
X-NMSegId
X-Microcachable
Req-ID
X-Edge-Server
Cdn-Request-Time
Cdn-Host
GeoIP-Country-Code
X-VCache
X-Cache-Ttl
X-Ad-Load-Variation
XServer
Cache-Host
X-Origin-Expires
X-Request-URI
X-CSRF-TOKEN
XM
NtCoent-Length
X-Info
X-M-Reqid
X-Datacenter
SID
X-Request-Start
M-TraceId
True-Client-IP
X-Scope-Id
X-M-Log
Cdn
HostName
X-Geo
X-Qnm-Cache
Content-Style-Type
X-Vercel-Cache
Pramga
Cluster
Content-Script-Type
X-Vercel-Id
WebServer
X-Pad
X-Varnish-Beresp-Status
X-Shield-Cache-Expires
X-HN
PFcat
X-VarnishDD-TTL
X-Github-Request-Id
X-Pod-Name
X-Cache-Date
X-FPC
Cache-Tv-Group
User-Agent
Fastly-Drupal-Html
X-Ad-Defer-Variation
X-Web-Node
X-WP-CF-Super-Cache-Cookies-Bypass
Tcn
X-HostName
A
X-TH-Server
Srvid
X-Via-CDN
X-MSEdge-Features
X-FL-QIT-DEBUG
X-FL-EDGE
Locid
X-MSEdge-Flight
X-Via-Edge
Edge-Copy-Time
X-Via-SSL
X-LiteSpeed-Tag
X-Cdn-Request-ID
X-Api-Version
Cf-Ipcountry
CountryCode
X-APP-VERSION
X-CS
X-Aicache-OS
X-Wa
X-NWS-UUID-VERIFY
X-AK-Request-ID
Cdnsip
Tube-Got-Eval
Edge-Cache
X-Cache-FS-Status
X-LB-ID
Click-Count-Error
X-Nc
X-Acquia-Purge-Cdn-Unconfigured
Cdncip
X-Via-Popv
Tube-Return
X-V-Cache
X-Servedbyhost
X-Via-Popn
X-Via-Poph
Click-Count-Action-Start
Tube-Got-Results
X-B3-Trace-ID
Tube-Get-Contents
X-Amz-Meta-Opti
MIME-Version
X-FireWall-Port
X-Req
X-SB
V-Age
X-Moov-T
On-Server
X-Contensis-Viewer-Groups
X-Cache-ASPX
X-ATG-Version
X-Branch-Name
X-Vary
X-Varnish-Authentication
Path
X-Men
X-Moov-Xdn-Version
X-VCL-Version
Priority
X-Wp-Cf-Super-Cache-Cookies-Bypass
Ngx-Var-Key
Cache-Key
X-Proxy-CacheRZ
XkeyRZ
Yak-Timeinfo
X-Akamai-Pragma-Client-IP
CDN
X-UA
X-CACHE-KEY
My-App
X-Render-Time
X-Tim-N
X-Fastly-Backend-Reqs
X-Cdn-Forward
X-Acquia-Site
X-Acquia-Purge-Tags
X-Acquia-Application-UUID
X-Acquia-Application-Trace
Wpo-Cache-Status
Geoip-Latitude
Srv
Wpo-Cache-Message
Proxy-Connection
X-Lb-Cache
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-User
X-Ha-Backend
X-Generated-In
X-Fastly-Country-Code
X-Air-Pt
X-Varnish-Director
Server-Id
Lb
X-Provided-By
X-TT-LOGID
X-TRACE-ID
Ohc-Cache-HIT
X-Wp-Cf-Super-Cache
Ohc-File-Size
X-Planisys-CDN-TTL
X-HS-Content-Campaign-Id
X-Platform-Server
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
X-CUA
X-Via-Ucdn
X-Wp-Cf-Super-Cache-Cache-Control
CF-Cached-On
X-Dw-Trace-Id
X-Lb-Nocache
PICS-Label
X-EC-Lua
X-Cdn-Cache-Status
Cache
State
X-Iplb-Request-Id
X-Iplb-Instance
Yjs-Id
X-Fastly-Cache-Hits
Fusion-Source
Warning
Fusion-Component-Id
X-Serial
X-GoCache-CacheStatus
X-GeoIP-City
Fusion-Content-Id
Type
Cross-Origin-Embedder-Policy-Report-Only
X-Check-Cacheable
Fusion-Template-Id
Fusion-Content-Source
X-Gamma-Serve
Fusion-Deployment-Id
X-Vgn-Hpd-Variations-Key
Ngx
X-Cache-Remote
X-Litespeed-Cache-Control
X-ElasticPress-Query
Log-Origin
Cneonction
X-RAMCache
X-Miniprofiler-Ids
X-HS-Status
X-Cached-Since
Vha6-Origin
X-Vgn-Hpd-Ssi
X-Vgn-Hpd-Cached
X-Snapshot-Date
X-Fastly-Cache
X-Udemy-Cache-App-Namespace
X-CF-Cache-Header-Cache-Control
X-CF-Cache-Header-Vary
X-Release
Inserted-Into-Cache-At