Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-Cache-Status
Link
Accept-Ranges
CF-RAY
ETag
X-XSS-Protection
Expect-CT
Pragma
X-Powered-By
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
Alt-Svc
P3P
X-Served-By
X-Xss-Protection
X-Download-Options
X-Timer
X-Request-Id
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Cache-Status
X-Generator
X-Cacheable
Timing-Allow-Origin
X-Content-Security-Policy
P3p
X-Iinfo
Status
Feature-Policy
X-Envoy-Upstream-Service-Time
Content-Encoding
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
X-CDN
X-AspNetMvc-Version
X-Request-ID
Upgrade
X-Via
CF-Ray
X-Ws-Request-Id
Access-Control-Max-Age
Server-Timing
EagleId
Keep-Alive
X-Cache-Group
X-Turbo-Charged-By
Request-Context
X-Age
X-Server-Powered-By
X-Proxy-Cache
X-UA-Device
X-AH-Environment
X-Backend
X-Hacker
X-Robots-Tag
Report-To
X-Amz-Request-Id
Host-Header
X-Server
X-Amz-Id-2
X-LiteSpeed-Cache
Grace
X-Rq
X-Nginx-Cache-Status
X-Varnish-Cache
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-WebKit-CSP
X-Dns-Prefetch-Control
X-Page-Speed
X-Vhost
EagleEye-TraceId
X-OneAgent-JS-Injection
X-Amz-Version-Id
X-Ua-Compatible
X-Pingback
X-Dispatcher
X-Device
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Cache-Spec
NEL
X-Server-Id
X-Host
Cf-Railgun
X-Node
X-Backend-Server
Accept-CH
X-Readtime
Surrogate-Control
X-Akam-SW-Version
Request-Id
X-Response-Time
X-HW
Xkey
X-Ruxit-JS-Agent
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Application-Context
Content-Location
Rating
X-Country
X-B3-TraceId
Accept-Ch-Lifetime
Accept-CH-Lifetime
X-Cache-Lookup
X-Cloud-Trace-Context
X-Trace
X-Url
X-Ac
X-Content-Type
Allow
X-TtlSet
X-PC
X-Vname
X-Clacks-Overhead
X-Mod-Pagespeed
Edge-Control
X-Varnish-TTL
X-FastCGI-Cache
X-ESI
Fastly-Restarts
X-Server-Name
Cache-Tag
Service-Worker-Allowed
X-VARITI-CCR
X-Rack-Cache
X-Element-Page-Cache
Verso
X-Language
X-MS-InvokeApp
X-GitHub-Request-Id
X-Upstream
MS-Author-Via
X-Amz-Rid
Public-Key-Pins
X-Vcap-Request-Id
X-Aws-Lambda-Call-Status
X-Cached
X-Dw-Request-Base-Id
X-Client-IP
X-D2id
X-Abt-Application-Version
X-Cache-TTL
X-Template
X-ORACLE-DMS-ECID
X-Cnection
X-ORACLE-DMS-RID
X-Origin-Cache
X-Px
Arr-Disable-Session-Affinity
X-Country-Code
RTSS
X-Navigation-Version
Access-Control-Request-Method
X-Powered-By-Plesk
X-Goog-Hash
X-NF-Request-ID
X-Server-Lifecycle-Phase
X-Instrumentation
X-Kraken-Loop-Name
Accept-Ch
X-Cdn-Fetch
X-Use-Magma
X-Kinja-Server
X-Version
X-Kinja-Revision
X-Kinja-Build
X-GoogleNews-Bot
X-Kinja
X-Exp-Id
X-Exp-Variant
X-Powered-CMS
Pagespeed
X-Sol
Display
X-Middleton-Display
AR-SID
AR-Request-ID
AR-PoweredBy
AR-ATIME
AR-CACHE
X-Amz-Server-Side-Encryption
X-Middleton-Response
Response
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-MSEdge-Ref
X-LLID
X-Edge
X-Kinsta-Cache
X-Edge-Location-Klb
Nginx-Cache
Mrf-Cache-Status
X-TTL
X-B3-TraceId-Primal
MRF-Tech
X-Protected-By
X-Shield-Request-Id
X-HP-Trace-Id
X-Jurisdiction
X-HP-Webp
X-T
TCN
X-Buckets
S
X-Forwarded-For
X-Content-Security-Policy-Report-Only
Content-MD5
X-Mg-S
X-RateLimit-Remaining
X-Id
X-Aspnetmvc-Version
Edge-Cache-Tag
X-Mid
Fastcgi-Cache
Realpath
X-CST
SPRequestDuration
SPIisLatency
X-MCACHE
Front-End-Https
X-Recruiting
X-Request-Received
X-Request-Processing-Time
Pinterest-Generated-By
Pinterest-Version
X-Pinterest-Rid
Filters
X-Ttl
Server-Node
X-Content
X-Ua-Browser
X-Ab
X-Correlation-Id
X-DynaTrace
Server-Name
X-Frontend
X-NWS-LOG-UUID
X-Parallel-Accel
SPRequestGuid
X-SharePointHealthScore
X-HS-Cache-Config
X-HS-Content-Id
X-HS-Hub-Id
Fusion-Content-Source
Fusion-Deployment-Id
Fusion-Source
Fusion-Content-Id
Fusion-Template-Id
Fusion-Component-Id
X-Ezoic-Cdn
X-HS-Combine-CSS
X-Yandex-Sdch-Disable
X-ECACHE
Alternate-Protocol
X-Hits
X-Ser
X-Content-Options
X-Tt-Trace-Host
MicrosoftSharePointTeamServices
X-Tt-Trace-Tag
Cache-Tags
X-Page-Id
X-B3-Sampled
Host
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
Charset
Cleartype
X-Git-Hash
X-Fastly-Request-Id
X-Www-Served-By
X-Cache-Key
X-Ruxit-Js-Agent
X-Daa-Tunnel
X-Accel-Expires
X-Geo-Country
X-DIS-Request-ID
X-Content-Digest
X-Amzn-Trace-Id
X-Amz-Replication-Status
Filterid
X-XRDS-LOCATION
X-Debug-Info
X-Varnish-Age
TP-L2-Cache
TP-Cache
X-Hostname
X-Activity-Id
X-Az
X-Forwarded-Proto
X-AppVersion
X-VCache
X-Upgrade-Enabled
X-FB-Debug
X-Rid
X-Grace
X-Origin-Server
Access-Control-Allow-Method
X-N
Cross-Origin-Opener-Policy
X-Ratelimit-Limit
X-LB-Cache
X-WebKit-CSP-Report-Only
X-Nginx-Upstream-Cache-Status
X-F-Cache
ServerID
X-Mobile-URL
X-Route-Name
X-Request-Guid
X-Flags
X-Providence-Cookie
X-Aspnet-Duration-Ms
X-Is-Crawler
X-Whom
X-GUploader-UploadID
X-TT
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-Goog-Metageneration
X-Goog-Generation
X-Varnish-Grace
Viewport
X-App-Environment
X-Tb
X-FW-Server
X-FW-Static
X-FW-Type
X-FW-Serve
X-FW-Hash
X-App-Server
X-Distributor
X-FW-Dynamic
Payment
X-Origin-Upstream-Status
Node
X-Server-ID
X-Seen-By
DC
Paypal-Debug-Id
X-Type
X-NGENIX-Cache
X-User-Agent
Fastcgi-Useragent
X-Cache-Control
Country
Accept-Charset
X-Logged-In
X-Microsite
X-Request-Handler-Origin-Region
X-Wix-Request-Id
X-Cache-Rule
X-Litespeed-Cache
X-Cache-Age
Version
X-Via-JSL
X-Webkit-CSP
X-Varnish-Backend
Referer-Policy
X-DataDome
X-Drupal-Cache-Tags
X-Browser-Type
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Load-Cache
X-Node-Name
Refresh
X-Cluster-Name
X-Contextid
X-B-Cache
X-Mobile
X-Signature
Access-Control-Request-Headers
X-Original-Request-Id
X-Tec-Api-Origin
Cache-Status
SD-X-WS
X-Tec-Api-Root
X-Response-Served-From
X-Tec-Api-Version
X-Cache-Action
X-IPLB-Instance
X-Jobs
X-Rendered-As
X-Vgn-Hpd-Reason
X-Real-IP
X-Proxy-Cache-Status
X-Is-Bot
X-Page-View
X-Cacheable-TTL
X-Cache-Expired-At
X-RemovedCookies
VIX-Pulpo-Node
X-ProcessESI
X-Revision
X-UUID
VIX-Pulpo-Upstream-Status
X-B
X-Debug
NGB
X-Device-Type
X-Proxy
X-Instance
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Rule
X-Fastly-Request-ID
Surrogate-Key
X-G
Akamai-GRN
X-Framework
X-Cache-Time
X-Drupal-Cache-Contexts
X-Debug-IsConnected
X-Debug-IsPreview
X-FW-Version
X-Fastcgi-Cache
CF-IPCountry
Amp-Access-Control-Allow-Source-Origin
X-Air-Source
X-Air-Hostname
X-Air-Trace-Id
DynaTrace
SID
X-TEC-API-ROOT
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-Ratelimit-Reset
Liferay-Portal
X-Azure-Ref
X-PressLabs-Stats
Healthy
X-Oracle-Dms-Rid
X-Oracle-Dms-Ecid
X-Presslabs-Stats
X-Nginx-Cache
Frame-Options
X-Ms-Request-Id
X-Ms-Version
X-Source
GEO-INFO
Count-Hit
Ms-Operation-Id
MS-CV
X-RTag
X-Oneagent-Js-Injection
X-Cache-Operation
X-Accel-Buffering
X-APP-VERSION
Uber-Trace-Id
X-CDN-Forward
Xserver
X-Tumblr-User
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Environment-Context
X-Tumblr-Pixel-1
X-L-Path
X-EdgeConnect-Cache-Status
X-Cache-Hit
Countrycode
X-Varnish-Server
X-XRDS-Location
X-Zen-Fury
X-Backend-Name
X-Region
Ec-Rule-Version
X-Mode
X-Forwarded-Host
X-Servername
Cross-Origin-Window-Policy
Backend
X-Cache-NGX
X-IPS-LoggedIn
X-Content-Powered-By
Section-Io-Cache
X-Ratelimit-Remaining
X-Detected-As
X-Cache-Type
Meta-Geo
X-JoinUs
X-Cache-TTL-Remaining
Protected
X-SaId
X-RN-RSRV
X-UPSTREAM-Address
X-Debug-Cache
X-Proxied
X-Sorting-Hat-ShopId
X-Redis-Cache
Eomportal-Instance
X-Uri
X-Cache-Grace
Decoy-Debug-TTL
X-Extlb
X-Cache-Server
X-Shopify-Stage
X-Rewrite-Enabled
X-Hosted-By
X-Varnish-Beresp-Grace
X-Routing-Service
X-Sql-Count
X-Sorting-Hat-PodId
X-Zipkin-Id
X-Human
X-Generation-Time
X-Sql-Duration-Ms
X-ShardId
Decoy-Debug-Status
X-Alternate-Cache-Key
Decoy-Debug-Key
Apigw-Requestid
Country-Code
X-Tid
X-ShopId
Mn-Server-Ip
Url
X-ApacheServer
X-BYPASS-REASON
X-ProxyCache-Status
X-Site-Version
X-UA-Device-Type
X-ProxyCache-Key
X-FB-TRIP-ID
X-No-Session
X-Origin-Date
X-Soup
X-Via-Fastly
X-PERF
X-PHP-Backend
Fastly-SSL
X-Microcachable
Cache-Name
X-NCache
X-ServerID
X-Storage
Cache-Tv-Group
X-Status
TWC-Device-Class
Property-Id
TWC-GeoIP-Country
DB-Nickname
Selected-Fe
TWC-Connection-Speed
X-Say-Cacheable
X-Web-Node
X-NYM-Debug-Backend
X-Server-W
X-Format
X-Say-TTL
X-PCL
X-OCL
X-Timing-Wait
X-Origin-Hint
X-SayCDN-TTL
X-Proxy-Build
Webcakes-App-Name
TWC-Privacy
TWC-Locale-Group
Webcakes-App-Version
Webcakes-Region
X-Cache-Host
X-Akamai-Edgescape
X-Adobe-Loc
TWC-GeoIP-LatLong
X-Adobe-Content
X-NewRelic-App-Data
X-Access
X-Content-Age
X-Section
X-Varnishpool
Azure-Version
X-R9-Blue-Green-Version
X-Hl-Ver
OT-Force-Account-Verify
X-Pubstack
X-Cluster-Node
Azure-SiteName
Azure-SlotName
Azure-InstanceId
Azure-RegionName
X-RateLimit-Limit
X-Be
Content-Secure-Policy
X-LSADC-Cache
X-Ua
SRV
X-Hyper-Cache
CDN-RequestCountryCode
CDN-PullZone
CDN-RequestId
CDN-EdgeStorageId
CDN-CachedAt
CDN-Uid
CDN-Cache
X-Generated-By
X-Azure-Ref-OriginShield
X-TIME
Content-Disposition
X-Cached-By
X-Webkit-Csp
Source
X-Trace-Id
X-SRV
X-Unique-Id
LB
X-Dc
Cache
WPO-Cache-Status
WPO-Cache-Message
X-Nginx-Cache-Key
X-Bc-Bl
X-LAGOON
X-App-Version
X-HTML-Minification-Powered-By
X-Varnish-Hits
Cache-Hits
X-Auto-Login
Retry-After
Xet-Cookie
X-GEO
X-Varnish-Hostname
X-Loop
X-Akamai-Transformed
X-TNCMS
X-Origin-CC
X-Amz-Meta-S3cmd-Attrs
X-Origin-TTL
X-TT-LOGID
Mime-Version
X-S-Maxage
Onion-Location
HostName
X-Platform-Server
X-ECache
X-CSRF-Token
X-Cache-Var
X-Cache-Var-Map
X-Tumblr-Pixel-3
X-Xfnlog-Site
X-Cdn
X-Tumblr-Pixel-2
Web-Mar-Node
X-Proto
Webserver
X-CACHE-KEY
X-Time
X-Cache-Tags
X-Cache-Remote
X-Tenant
X-Time-Microsecs
Upgrade-Insecure-Requests
X-Endurance-Cache-Level
X-Edge-Location
X-Varnish-Cache-Hits
X-LJ-Flow-ID
X-AWS-Id
ServedBy
X-Request-Time
X-VWS-Id
X-AOL-HN
N-Cache
X-GG-Cache-Date
X-EC-Lua
CloudFront-Viewer-Country
X-M-Log
X-M-Reqid
AMP-Access-Control-Allow-Source-Origin
X-Qnm-Cache
X-Request-Host
X-Mg-Request-UUID
X-Amz-Apigw-Id
From-Origin
X-Labrador-Cache-Channel
X-PHP-Host
X-Amzn-RequestId
X-B3-SpanId
X-FireWall-Port
X-Via-NSCOPI
WP-Super-Cache
Sslversion
A
Surrogated-Key
Rendered-Blocks
X-TIM-N
X-A
X-SVT-ORM-VERSION
Pramga
X-V-Cache
V-Age
User-Cache-Control
X-Vdms-Version
L
Xc-Version
Fastcgi-X-Cache-Version
Origin
Odigeo-Trace-Id
Mobile-Detection-Method
X-Vtex-Remote-Cache
Expiry
DSUID
X-VG-WebCache
BehaviorPad-Version
Meta-Geo-Continent
CDCHOST
X-Vtex-Processado-Em
DCR-Processing-Time-Ms
DCR-Decision-By
X-Vdms-Path
X-Session-Fingerprint
X-S
X-Rojux
X-Processor
X-Ftr-Request-Id
X-Forwarded-Path
X-External-Request-Id
X-D
X-Destination
X-S-Cookie
X-Developer
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-ND-Cache
X-Orig-Expires
X-PAYTM-SRV-ID
X-Origin-Response-Time
X-NAPM-TraceId
X-PBS-Appsvrname
X-Gen-Mode
X-Hnp-Log
X-Planisys-CDN-Cache
X-Ig-Push-State
X-Connection-Hash
X-Conf
X-A-Wwc
X-Aed
X-Application
X-Shop-Environment
X-A-Dgt
X-A-Dcw
X-SVT-ORM-RULES
X-SRCache-Key
X-Slack-Backend
X-A-Dam
X-SD-PageType
X-ARC
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-Ckpd-Fst-Backend
X-Cluster
X-Cache-NE
X-ScT
X-B-Cookie
X-Block-Status
X-Cache-Date
X-A-Ccd
Redirect-Candidate
X-RCS-CacheZone
Nel
X-Correlation-ID
X-Locale
X-Handled-By
X-MP-GENERATED-AT
Origin-CC
X-Proxy-Upstream
X-VarnishDD-TTL
X-Cdn-Srv
Origin-EX
PFcat
X-Aicache-OS
X-NodeID
X-Mvc-Supplant-Cachable
X-Li-Fabric
X-Cache-Info
X-Li-Pop
Gh-Request-Id
Host-ID
X-Accel-Expires-Debug
X-Men
X-Cache-Bucket
X-Location
X-Nyt-Route
Vix-Hermes-Req-Id
X-Origin-Expires
Svr
State
X-Origin-Time
X-Varnish-Beresp-Status
X-VServer
True-Client-Country-4JS
Traceparent
Ssr
X-Owner
X-Zone
Fastcgi-Cache-TTL
Release
X-Webstats-RespID
X-Old-Content-Length
Wxu-Next-Commit
Wxu-Next-Hostname
Wxu-Next-Region
X-Policy
X-LI-UUID
AKAMAI
X-Rocket-Nginx-Serving-Static
X-Fastly-Cache
X-Scheme
X-Epic-Correlation-Id
X-Device-Os
X-Date
X-Hash
Arc-Country
X-Sucuri-ID
X-Fetched-On
X-Gdpr
X-Skip-Cache
X-Geo-Header
X-Storefront-Renderer-Rendered
X-Server-IP
X-Forwarded-Site
X-Served-From
X-Sucuri-Cache
CacheControlHeader
Server-Info
X-HN
X-Core-Mission
Cmsid
Cmstype
Fastly-Drupal-Html
Environment
X-Varnish-Ttl
X-NWS-UUID-VERIFY
X-VC-Cache
X-Cache-Id
X-Core-Value
Web-Mar-Region
X-GeoIP
X-Viewer-Country
X-HS-Content-Campaign-Id
X-Irp-Debug
X-Cdn-Origin
X-Gamma-Serve
X-GeoIP-City
X-VG-TLSProxy
We-Hiring
X-Fastly-Backend
X-Level-Front-Cache
X-Bip
X-Developers
X-Datadog-Sampling-Priority
X-Node-Id
X-Datadog-Trace-Id
X-ATG-Version
X-Sn-Servicetimems
X-Adobe-Source
X-Cache-Config
X-BBC-Edge-Cache-Status
X-Gzip
X-Esi-Check
X-Branch-Name
X-Datadog-Parent-Id
X-Cache-Debug
Thinkindot-CacheControl
X-Req
X-Csrf-Jwt
X-Reqid
X-Envoy-Decorator-Operation
X-Eu-Site
X-CGP
Fastly-GeoIP-CountryCode
Machine
Mail-Subject
Locid
X-Region-Sid
X-Backend-State
X-Request-Start
X-RateLimit-Limit-Second
X-Request-URI
X-Cache-Enabled
X-Sigma
X-Magnolia-Registration
X-Sigma-Backend
Apple-News-Services-Handled
Apple-News-Services-Host
X-Rocket-Build-Number
X-RateLimit-Remaining-Second
X-UnsetCookies
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
L5d-Success-Class
X-TH-Server
X-Thinkindot-L3
Server-Host
X-Platform
Ha-Gx-Prefs
X-TrackingId
TDXMobile
Thinkindot-Control
Thinkindot-CacheControl-Type
X-Generated-On
HA-Ipaddr
Req-Svc-Chain
X-Thanos
X-Rebelmouse-Cache-Control
X-DPWN-IS-SECURE
X-DefHash
X-DefElseHash
Memcached
X-Response-By
X-Has-Esi
X-Varnish-CookieINHashed-On
NGX
NM-Fastcgi-Cache
X-Qloud-Router
X-Origin
X-FC-Vary-Parameters
X-Variation
Adler-Geo
X-Pod-Name
Cf-Device-Type
X-Loc
Fastly-SWR
Fastly-SIE
X-Worker
X-Varnish-CookieHashed-On
X-Rebelmouse-Surrogate-Control
X-Amzn-Remapped-Content-Length
X-Varnish-Remaining-TTL
Is-Eu
Platform
X-NU-AKA-ACS-Version
X-Is-Gdpr
X-JWT-State
X-Xrds-Location
X-Mvc-Supplant-OutputCached
X-Backend-TTL
X-Datadome
X-Ua-Device
X-LB-ID
X-GeoIP-Region-Code
X-GeoIP-Country-Code
X-API-Version
X-CS
X-Up
X-CLOUD-TRACE-CONTEXT
X-NC
X-Tx-Id
X-Varnish-Beresp-Ttl
X-Generated-In
Datacenter
Candidate-Md5Url
CDN
X-TraceId
X-DynaTrace-JS-Agent
Ms-Author-Via
Pics-Label
X-Trace-ID
Magicmarker
S-Rt
X-Tb-Optimization-Total-Bytes-Saved
X-Tt-Logid
WWW-Authenticate
X-Vc
X-Via-Popv
Env
X-Restarts
NtCoent-Length
X-Edge-Pop
X-Via-Popn
Kp-EeAlive
On-Server
X-Via-Poph
X-Optimistic-Header
X-LB-NoCache
WebServer
Time
GeoIp-Country-Code
Memory
Esi-Enabled
X-Akamai-Request-ID2
X-Http-Reason
X-Refresh
X-Cache-Backend
X-Wix-Viewer-Type
X-Action
Edge-Cache
X-RSL
X-RPS
X-TA-CDN-Provider
X-RPM
X-Varnish-Beresp-TTL
X-DB
X-DSS
X-DI
X-DW
X-DC
X-CacheTTL
X-Service
X-Dynatrace
C-Via
X-TX-ID
X-Cs
X-Esi
X-Cache-PHP
X-Newrelic-Synthetics
X-Minions-Version
X-Parent-Response-Time
X-Srv
X-HA-Backend
X-Unique-ID
X-Servedbyhost
Accept-Language
X-MSEdge-Flight
X-MSEdge-Features
X-Cache-Status-Check
Server-ID
X-Render-Time
X-ZONE
X-Urbn-Site-Id
Locale
X-Li-Proto
X-Urbn-Context-Path
X-App
X-FPC
X-VCL-Version
X-Cache-Ttl
X-Ec-Fail
X-Ec-GeoHdr
X-User
X-B3-Spanid
X-URL
Proxy-Connection
X-Fpc
X-Info
Server-Id
X-Pass-Why
X-Webkit-Csp-Report-Only
X-LI-Proto
Test
X-AIR-PT
X-Vcl-Version
X-Traceid
X-LiteSpeed-Cache-Control
X-Clientip
X-Webkit-CSP-Report-Only
X-NODE
Cache-Host
X-Oss-Object-Type
X-Oss-Request-Id
Cdnsip
X-Oss-Server-Time
Cdncip
UCS
HIT
Tcn
X-Oss-Storage-Class
X-Oss-Hash-Crc64ecma
Geo-Info
X-AK-Request-ID
X-WADP-Cache
X-Clara-WADP
Cluster
My-App
M-TraceId
S-Cnection
X-Fmm-Version
Geoip-Latitude
X-ServedByHost
Fastly-Drupal-HTML
Tracecode
X-CUA
X-HostName
X-Var-Ttl
Resin-Trace
Cf-Int-Pingora-Origin-Digest
X-LiteSpeed-Tag
X-CSRF-TOKEN
X-Cdn-Forward
Lfy
X-ID
X-Micro-Cache
T-Server
X-Ha-Backend
Fastly-Backend-Name
User-Agent
X-From
Hostname
X-Pad
X-Mcache
Section-Origin-Responded
X-Fragments
Section-Io-Origin-Status
Section-Io-Id
X-RAMCache
X-Release
GeoIP-Country-Code
Ohc-File-Size
Hit
Section-Io-Origin-Time-Seconds
X-Backend-Host
Lang
DataCenter
X-Dynatrace-Js-Agent
Lb
X-Geo
X-Via-PopH
X-WP-CF-Super-Cache-Cache-Control
X-Edge-POP
X-Via-PopV
X-WP-CF-Super-Cache
Target-Params
X-Via-PopN
X-BBC-Origin-Response-Status
X-BCube-Filmed-By
MIME-Version
X-Check-Cacheable
X-APP
X-ElasticPress-Query
ENV
X-Api-Version
X-HS-Status
X-VC
Load-Balancing
X-Edge-Cache
X-NGINX-Cache
VNS-Age
X-Ucs
Servername
X-ServerName
X-WA
Uri
VNS-Cache
X-Amz-Meta-Cb-Modifiedtime
X-WA-Info
Path
X-Lb-Nocache
URI
CPC-Cache
CPC-Age
EpKe-Alive
PICS-Label
Cache-Key
X-Fastly-Backend-Reqs
X-ES-SERVER
X-Proxy-Cache-Info
X-Httpd
Permissions-Policy
X-GoCache-CacheStatus
FSS-Cache
X-UP
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-Fastly-Cache-Hits
X-TRACE-ID
X-Provided-By
Cteonnt-Length
Cneonction
X-Akamai-ERRuleID
Pagetype
X-Lb-Id
X-B3-ParentSpanId
Ohc-Cache-HIT
WZWS-RAY
ServerName
X-PJAX-URL
X-Cms-Context
Producers
X-RateLimit-Reset
X-Akamai-ERPolicy
X-Nc
Shield-Pop
X-Cdn-Request-ID
Cdn
X-Dw-Trace-Id
Cf-Ipcountry
X-Newrelic-App-Data
X-Acquia-Application-Trace
X-Vcache
Srv
X-Acquia-Application-UUID
X-Acquia-Purge-Tags
X-Acquia-Site
Server-Ttl
CF-Cached-On
X-Snapshot-Date
X-Pool
X-Via-Ucdn
X-Cache-CFC
X-Contensis-Viewer-Groups
X-Cache-ASPX
X-Apw-Access-Token
X-Apw-Access-Object
X-Apw-Access-Action
X-SB
X-Yottaa-OS
X-Hcs-Proxy-Type
X-Apw-Hits
MD5-Digest
X-Swift-Error
X-Akamai-Pragma-Client-IP
Vha6-Origin
X-CCDN-Origin-Time
X-CCDN-CacheTTL
Sid
X-Cache-Ngx
X-Air-Pt
X-Udemy-Cache-App-Namespace
X-Te-Duration-Ms
X-Last-Modified
Server-Ext
X-B3-Parentspanid
X-CacheKey
W
X-Logging-Id
X-SIPLIST1
X-Miniprofiler-Ids
X-Varnish-Authentication
X-VG-WebServer
X-UA
Req-ID
Ngx
X-Http-Count
X-Http-Duration-Ms
X-Sentry-ID
IsBot
Sever-Int
Server-Hostname
CountryCode
X-Te-Count