Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
X-XSS-Protection
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Accept-Ranges
Expect-CT
CF-RAY
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
X-Served-By
P3P
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Xss-Protection
X-FRAME-OPTIONS
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
Content-Security-Policy-Report-Only
P3p
X-Runtime
X-AspNet-Version
X-DNS-Prefetch-Control
Accept-CH
X-Cache-Status
X-Drupal-Cache
Accept-CH-Lifetime
X-Ua-Compatible
CF-Ray
X-Check
X-Generator
X-Cacheable
Server-Timing
X-Envoy-Upstream-Service-Time
Timing-Allow-Origin
X-Iinfo
X-Drupal-Dynamic-Cache
Access-Control-Expose-Headers
X-Request-ID
Feature-Policy
Content-Encoding
X-Content-Security-Policy
X-CDN
Status
Upgrade
X-AspNetMvc-Version
Access-Control-Max-Age
X-Via
X-Amz-Request-Id
X-Amz-Id-2
Host-Header
X-Backend
Allow
Cf-Edge-Cache
X-Cache-Group
X-Robots-Tag
Request-Context
X-Server
Keep-Alive
X-Hacker
X-UA-Device
X-AH-Environment
X-Turbo-Charged-By
X-Ws-Request-Id
X-Vhost
X-Proxy-Cache
X-Rq
X-Age
Xkey
EagleId
X-Dispatcher
X-Server-Powered-By
X-Amz-Version-Id
X-Varnish-Cache
Grace
Cf-Apo-Via
X-LiteSpeed-Cache
X-Pingback
X-Page-Speed
Cf-Railgun
EagleEye-TraceId
X-Device
X-Swift-CacheTime
X-Swift-SaveTime
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Dns-Prefetch-Control
X-Aws-Lambda-Call-Status
Ali-Swift-Global-Savetime
X-CST
X-WebKit-CSP
X-OneAgent-JS-Injection
X-Backend-Server
Permissions-Policy
Accept-Ch-Lifetime
X-Server-Id
X-Readtime
X-Host
X-Response-Time
Surrogate-Control
Request-Id
X-Akam-SW-Version
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Nginx-Upstream-Cache-Status
X-HW
X-Cloud-Trace-Context
X-Nginx-Cache-Status
X-Node
X-Application-Context
X-Country-Code
X-Ruxit-JS-Agent
X-Trace
Content-Location
X-Cache-Lookup
X-Url
Service-Worker-Allowed
X-Oneagent-Js-Injection
X-Content-Type
X-Country
X-Clacks-Overhead
X-ECACHE
X-Litespeed-Cache
X-Edge
X-Mod-Pagespeed
Accept-Ch
X-Amz-Server-Side-Encryption
X-Rack-Cache
X-Origin-Cache-Key
X-Midtier
Cache-Tag
X-FTR-Request-ID
Cross-Origin-Opener-Policy
X-MS-InvokeApp
X-Mcache
X-Upstream
X-PC
X-Powered-By-Plesk
X-Vname
X-ESI
X-TtlSet
Nginx-Cache
Rating
Edge-Control
X-D2id
X-Element-Page-Cache
X-Browser-Type
X-Kinja-Server
X-Cdn-Fetch
X-Kinja-Revision
X-Kinja
X-Exp-Variant
X-Exp-Id
X-GoogleNews-Bot
X-Kinja-Build
Verso
X-Times
X-Ac
X-Server-Name
X-Cnection
SPRequestDuration
SPIisLatency
X-Ruxit-Js-Agent
X-Vcap-Request-Id
AR-Request-ID
AR-PoweredBy
AR-ATIME
AR-SID
X-Navigation-Version
X-Abt-Application-Version
X-SharePointHealthScore
X-Dw-Request-Base-Id
X-RateLimit-Remaining
SPRequestGuid
X-B3-TraceId
X-VARITI-CCR
X-NF-Request-ID
X-Ser
Pinterest-Version
Pinterest-Generated-By
X-Pinterest-Rid
X-GitHub-Request-Id
Origin-Trial
AR-CACHE
S
X-Cache-Key
X-Cache-TTL
X-Mg-S
RTSS
Edge-Cache-Tag
X-Middleton-Display
Pagespeed
Display
X-Sol
X-Goog-Hash
X-Amz-Rid
X-Content-Security-Policy-Report-Only
Fastly-Restarts
X-Amzn-Trace-Id
X-Powered-CMS
X-Client-IP
X-Ttl
X-Varnish-TTL
X-NWS-LOG-UUID
X-Server-ID
X-Instrumentation
X-Erf-Bev-Bev
X-Version
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Erf-Bev-Bev-Is-Generated
Access-Control-Request-Method
X-Kinsta-Cache
X-Edge-Location-Klb
X-ARC
Cache-Status
X-Recruiting
X-Webkit-Csp
X-Content-Digest
Arr-Disable-Session-Affinity
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-T
X-MSEdge-Ref
X-Forwarded-For
X-Ua-Device
Content-MD5
X-TraceId
X-Middleton-Response
Response
MicrosoftSharePointTeamServices
X-Accel-Expires
TP-Cache
X-Hits
X-Shield-Request-Id
X-Cached
X-Erf-Stays-Pdp-Viaduct-Migration-Web-V2
X-RateLimit-Limit
Public-Key-Pins
X-Fastcgi-Cache
X-Country-Code-Real
X-Frontend
X-FTR-Backend
X-FTR-Cache-Status
X-FTR-Balancer
X-FTR-Backend-Server
Server-Node
X-FTR-Expires
X-Id
X-Request-Received
X-Request-Processing-Time
Payment
X-HS-Combine-CSS
X-Ua-Browser
X-HS-Content-Id
X-HS-Hub-Id
X-HS-Cache-Config
X-WebKit-CSP-Report-Only
MS-Author-Via
X-DIS-Request-ID
X-Kinja-CCPA
X-ORACLE-DMS-RID
Front-End-Https
X-GUploader-UploadID
X-LLID
X-Forwarded-Proto
Cross-Origin-Resource-Policy
X-Jurisdiction
X-HP-Trace-Id
X-HP-Webp
Cache-Tags
TP-L2-Cache
X-LB-Cache
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Protected-By
Realpath
X-FastCGI-Cache
X-Origin-Server
X-Distributor
X-PressLabs-Stats
Count-Hit
X-Daa-Tunnel
X-TTL
X-Microsite
X-Request-Handler-Origin-Region
X-ORACLE-DMS-ECID
X-Page-Id
X-Cluster-Name
X-F-Cache
Accept-Charset
X-Varnish-Backend
X-Az
X-B3-TraceId-Primal
MRF-Tech
X-Activity-Id
Mrf-Cache-Status
X-AppVersion
X-Www-Served-By
X-NGENIX-Cache
X-Rid
X-App-Server
X-FB-Debug
Referer-Policy
X-Hostname
X-Geo-Country
X-Kong-Proxy-Latency
X-Goog-Metageneration
X-Debug-Info
X-Kong-Upstream-Latency
X-Varnish-Server
Host
Fastcgi-Cache
X-Envoy-Decorator-Operation
Access-Control-Allow-Method
X-Correlation-Id
X-Git-Hash
X-RateLimit-Reset
Retry-After
X-XRDS-LOCATION
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
Server-Name
X-Px
DC
X-Content-Options
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Load-Cache
X-B3-Sampled
X-Providence-Cookie
X-Is-Crawler
X-Request-Guid
X-Fastly-Request-ID
X-Aspnet-Duration-Ms
X-Route-Name
X-Flags
X-Contextid
X-Revision
X-Mobile
X-Language
X-Grace
Cleartype
X-Type
X-App-Environment
X-Trace-Id
TCN
X-Signature
X-Origin-Cache
X-B-Cache
Paypal-Debug-Id
X-Fb-Rlafr
Charset
X-ASPNET-VERSION
X-B
X-TT
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
X-Datadog-Trace-Id
X-CSRF-Token
X-Cache-Control
X-Amz-Meta-S3cmd-Attrs
Section-Io-Cache
Frame-Options
X-Logged-In
X-Goog-Storage-Class
X-Ratelimit-Limit
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Seen-By
X-Amz-Replication-Status
X-Upgrade-Enabled
Filterid
X-Newrelic-App-Data
X-Whom
X-Ezoic-Cdn
X-Magnolia-Registration
Healthy
X-Oracle-Dms-Ecid
X-Wix-Request-Id
X-EdgeConnect-Cache-Status
X-App-Version
X-Azure-Ref
X-Node-Name
Content-Disposition
Backend
X-Proxy
X-N
X-Fastly-Request-Id
X-Oracle-Dms-Rid
Akamai-GRN
X-Varnish-Ttl
X-Template
Upgrade-Insecure-Requests
X-Proxy-Cache-Info
NGB
Refresh
X-Response-Served-From
X-Air-Pt
X-Original-Request-Id
X-Is-Bot
X-B3-SpanId
X-Servername
X-Rendered-As
Url
X-ProcessESI
X-RTag
X-Tumblr-Pixel
VIX-Pulpo-Node
SD-X-WS
VIX-Pulpo-Upstream-Status
Ms-Operation-Id
X-Unique-Id
X-RemovedCookies
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
MS-CV
Liferay-Portal
X-Tumblr-User
X-B3-Traceid
X-Page-View
X-Datadog-Sampled
X-L-Path
X-Environment-Context
X-Amzn-Remapped-Content-Length
X-Instance
X-Region
X-Yottaa-Metrics
X-Cacheable-TTL
X-User-Agent
Viewport
X-Yottaa-Optimizations
X-Varnish-Grace
X-Jobs
X-UUID
X-Debug
X-Debug-IsConnected
Fastly-SIE
X-FW-Dynamic
X-Cache-Grace
Fastly-SWR
X-FW-Hash
X-G
X-FW-Version
X-FW-Static
X-FW-Type
X-Adobe-Content
X-FW-Server
X-Debug-IsPreview
X-IPS-LoggedIn
X-FW-Serve
X-Adobe-Loc
X-Ratelimit-Remaining
X-Use-Magma
X-Device-Type
Country
From-Origin
X-NYM-Debug-Backend
X-Cache-Hit
X-Status
X-Rule
Surrogate-Key
X-Hosted-By
X-Air-Trace-Id
X-Air-Hostname
X-Air-Source
X-Hl-Ver
X-Backend-Name
X-Webkit-CSP
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
ServerID
Protected
X-Http-Reason
X-Content-Powered-By
X-Cache-Age
X-Akamai-Request-ID2
X-XRDS-Location
X-Time
X-Cache-Status-Check
X-VC-Cache
Version
X-NODE
X-Origin-TTL
Alternate-Protocol
X-Origin-CC
Amp-Access-Control-Allow-Source-Origin
X-CCDN-Origin-Time
X-CCDN-CacheTTL
X-Hcs-Proxy-Type
X-Tec-Api-Origin
X-Tec-Api-Root
X-Tec-Api-Version
X-HTML-Minification-Powered-By
WPO-Cache-Status
WPO-Cache-Message
X-Akamai-Edgescape
Countrycode
X-INCAP-ABP
X-Framework
X-Rocket-Nginx-Serving-Static
X-CDN-Forward
X-Nginx-Cache
Front
CF-IPCountry
X-Edge-Location
SRV
X-Source
X-Cache-Rule
GEO-INFO
X-Via-JSL
Access-Control-Request-Headers
X-Storage
X-Httpd
X-Accel-Version
X-Mode
X-Endurance-Cache-Level
X-WP-CF-Super-Cache-Active
X-Use-Mantle
X-Cache-Operation
Filters
Webserver
OT-Force-Account-Verify
X-Rewrite-Enabled
X-Upstream-Ct
Accept-Language
X-VC
X-Xfnlog-Site
X-Upstream-Ht
X-UPSTREAM-Address
X-Rn-Rsrv
Meta-Geo
CDN-RequestId
X-Lambda-Id
X-Loop
X-Proxy-Build
X-Director
X-Detected-As
Selected-Fe
X-Cache-Debug
X-SaId
X-Served-From
X-Tumblr-Pixel-3
X-Varnish-Age
X-Real-IP
X-Tumblr-Pixel-2
X-Tncms
X-Soup
X-Timing-Wait
Xet-Cookie
X-JoinUs
X-Cache-Time
X-Say-TTL
X-SayCDN-TTL
X-Say-Cacheable
ServedBy
X-Redis-Cache
AMP-Access-Control-Allow-Source-Origin
X-ProxyCache-Key
X-Skip-Cache
X-Sql-Count
X-Varnish-Cache-Hits
X-Handled-By
X-BYPASS-REASON
X-Varnish-Beresp-Grace
Apigw-Requestid
X-Sql-Duration-Ms
X-Cms-Context
X-ProxyCache-Status
Web-Mar-Node
Webcakes-App-Version
Webcakes-Region
TWC-Privacy
Webcakes-App-Name
TWC-Connection-Speed
DB-Nickname
Azure-Version
Azure-SlotName
Property-Id
X-Adobe-Source
TWC-GeoIP-LatLong
TWC-GeoIP-Country
TWC-Device-Class
TWC-Locale-Group
X-Labrador-Cache-Channel
X-Server-W
X-S
X-RM-Cache-TTL
X-COUNTRY
X-Uri
X-Worker
Xserver
X-Restarts
X-PHP-Host
X-GeoCode
X-Format
X-GeoCountry
Azure-SiteName
X-Origin-Hint
X-Logging-Id
X-Cache-Host
X-No-Session
Azure-RegionName
Azure-InstanceId
X-Extlb
X-DynaTrace
X-Fetched-On
X-Generation-Time
X-Routing-Service
X-Cache-Server
X-AB
X-AWS-Id
X-Browser-Name
X-Geo-Region
X-Container-Uri
X-RCS-CacheZone
X-Is-Tablet
X-Proxied
X-Origin
X-LJ-Flow-ID
X-Is-Supported-Browser
X-Is-Mobile
X-Git-Commit
X-IPLB-Instance
X-IPLB-Request-ID
X-Is-Desktop
X-Tcp-Rtt
X-ServerID
X-VWS-Id
Mn-Server-Ip
X-Vercel-Id
X-VCT
X-Zipkin-Id
X-Vercel-Cache
X-Cluster
Node
X-Frame-Option
X-Reqid
X-Forwarded-Host
X-Provided-By
X-Tb
X-Ms-Request-Id
Cache-Tv-Group
X-Ms-Version
X-R9-Blue-Green-Version
X-FB-TRIP-ID
Section-Io-Id
X-Vcache
Content-Secure-Policy
X-Locale
X-Site-Version
Priority
X-Platform-Processor
X-Platform-Router
X-Platform-Cluster
X-MP-GENERATED-AT
Source
Fastcgi-Useragent
X-Webstats-RespID
X-Web-Node
X-Vcl-Version
Onion-Location
WZWS-RAY
WP-Super-Cache
S-Rt
X-Drupal-Cache-Contexts
X-Drupal-Cache-Tags
X-Storefront-Renderer-Rendered
X-Urbn-Context-Path
X-Urbn-Site-Id
X-Alternate-Cache-Key
X-Shopify-Stage
Cross-Origin-Embedder-Policy
CDN-Cache
CDN-RequestCountryCode
CDN-PullZone
CDN-RequestPullCode
CDN-Uid
X-Content-Age
Locale
CDN-EdgeStorageId
CDN-RequestPullSuccess
X-Ua
CDN-CachedAt
X-Origin-Date
X-Generated-By
X-ShardId
X-ShopId
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Varnish-Beresp-Ttl
X-Cluster-Node
X-SRV
X-Cache-Action
X-Pass-Why
X-Sucuri-Cache
X-Proxy-Cache-Status
X-Cdn-Origin
Sid
X-Buckets
X-Mg-Request-UUID
X-Sucuri-ID
X-Newrelic-Synthetics
Cross-Origin-Window-Policy
X-Cache-Expired-At
X-Correlation-ID
X-Xrds-Location
X-VCache
X-TT-LOGID
Fastly-Drupal-HTML
X-Datadome
X-CMSURLCustom
Cache
X-Scope-Id
TDXMobile
Thinkindot-CacheControl
Thinkindot-Control
Thinkindot-CacheControl-Type
X-Request-URI
X-Thinkindot-L3
X-Shield-Cache-Expires
Cross-Origin-Embedder-Policy-Report-Only
HostName
X-DataDome
X-LSADC-Cache
X-Aspnetmvc-Version
X-A-Dgt
V-Age
X-D
X-B-Cookie
X-Application
X-A-Dam
X-Cache-NE
X-Bc-Bl
X-Destination
X-Conf
X-A
X-BCube-Filmed-By
X-Aed
X-Bl-Debug
X-Cache-Bucket
X-A-Dcw
X-A-Ccd
X-SRCache-Key
Origin-Agent-Cluster
Lang
X-Vdms-Version
X-S-Cookie
X-Developer
X-ScT
Candidate-Md5Url
Ngx.Var.Host
DCR-Decision-By
Origin
X-Rojux
X-A-Wwc
Surrogated-Key
X-Men
T-Server
Type
Sslversion
X-PAYTM-SRV-ID
Redirect-Candidate
Rendered-Blocks
X-Vdms-Path
Gannett-Cam-Experience-Id
X-Scheme
CDCHOST
X-TIM-N
X-External-Request-Id
X-Ec-GeoHdr
X-Up
DCR-Processing-Time-Ms
X-Ec-Custom-Error
X-Ec-Fail
MD5-Digest
X-Epic-Correlation-Id
X-Viewer-Country
Meta-Geo-Continent
X-Vtex-Remote-Cache
Environment
Ngx-Var-Key
Edge-Copy-Time
X-Via-CDN
X-GEO
X-Optimistic-Header
X-Via-SSL
X-Via-Edge
X-Service
X-TimeS
Fastly-SSL
Magicmarker
Ssr
L
Server-Ext
Vix-Hermes-Req-Id
Pramga
Fastly-GeoIP-CountryCode
Req-Svc-Chain
Server-Host
Server-Hostname
Host-ID
Sever-Int
X-Fastly-Cache
X-SD-PageType
X-SB
X-Section
X-Sigma
X-Sigma-Backend
X-Rocket-Build-Number
X-Request-Time
X-Pool
X-Proxied-Request
X-Pubstack
X-Req
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-VG-WebCache
X-VServer
X-We-Are-Hiring
X-Server-IP
X-VG-TLSProxy
X-Varnish-Hostname
X-Thanos
X-V-Cache
X-Varnish-Beresp-Status
X-Varnish-Director
X-Platform
X-Origin-Time
X-Core-Value
X-Core-Mission
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-Dispatcher-Server
X-Cache-Info
X-Bip
X-Acquia-Purge-Cdn-Unconfigured
X-Aicache-OS
X-B3-Trace-ID
X-BBC-Edge-Cache-Status
X-Fastly-Backend
X-Gdpr
X-Level-Front-Cache
X-Mly-Id
X-Nyt-Route
X-Op-Id-All
X-Instance-Name
X-Human
X-Generated-On
X-GeoIP-Country-Code
X-GeoIP-Region-Code
X-Hash
X-Access
Release
Apple-News-Services-Request-Url
Apple-News-Services-Host
X-Tt-Logid
Apple-News-Services-Handled
Country-Code
Apple-News-Services-Parsed-Url
User-Cache-Control
X-Parent-Response-Time
X-Gzip
X-GoCache-CacheStatus
X-HA-Backend
X-FC-Vary-Parameters
X-Fmm-Version
X-GeoIP-City
X-Geo-Header
X-DPWN-IS-SECURE
X-Gen-Mode
X-From
X-GeoIP
X-Clientip
X-Ad-Load-Variation
X-ApacheServer
Wxu-Next-Region
Wxu-Next-Hostname
Web-Mar-Region
Wxu-Next-Commit
X-Auto-Login
Atl-Traceid
X-CacheTTL
X-Hnp-Log
X-Cache-TTL-Remaining
X-Cache-Id
X-Block-Status
X-Cache-Date
X-Device-Os
X-Irp-Debug
X-Via-Poph
X-Via-Popn
X-Via-Popv
X-Var-Ttl
X-UA-Device-Type
X-Slack-Backend
X-Slack-Shared-Secret-Outcome
X-WA-Info
X-Zen-Fury
X-TH-Server
X-Varnishpool
X-Request-Start
X-Node-Id
Req-ID
X-Forwarded-Site
X-Request-Host
X-RateLimit-Remaining-Second
X-Mvc-Supplant-OutputCached
X-NCache
X-Mvc-Supplant-Cachable
X-Micro-Cache
We-Hiring
X-Loc
X-Nginx-Cache-Key
X-NMSegId
X-Policy
X-RateLimit-Limit-Second
X-PERF
X-Origin-Response-Time
X-Old-Content-Length
X-Org
X-HS-Content-Campaign-Id
X-Esi-Check
Producers
C-Via
Platform
Cache-Provider
Proxy-Firewall
Adler-Geo
Tube-Got-Eval
Tube-Get-Contents
True-Client-Country-4JS
On-Server
Canary
Gh-Request-Id
Esi-Enabled
DSUID
Is-Eu
Click-Count-Error
Mail-Subject
Machine
Click-Count-Action-Start
Tube-Got-Results
NM-Fastcgi-Cache
Uber-Trace-Id
Tube-Return
X-WP-CF-Super-Cache-Cookies-Bypass
X-DC
X-TA-CDN-Provider
Cdn-Host
Pics-Label
X-Accel-Expires-Debug
X-Date
X-CF-Lambda-Version
X-ZONE
AKAMAI
X-Edge-Server
Cdn-Request-Time
X-Owner
X-Wikidot-Backend
LB
X-Wikidot-Static-Cache
Expect-Staple
W
X-Test
IsBot
Cf-Device-Type
X-Proto
X-SIPLIST1
X-Sn-Servicetimems
X-CF-Lambda-Fn
N-Cache
X-App-Name
X-Cdn-Srv
X-Dc
X-Qloud-Router
X-Eu-Site
Xc-Version
Fastly-Backend-Name
X-Cache-Type
HA-Ipaddr
X-Orig-Expires
Ha-Gx-Prefs
X-Forwarded-Path
NGX
X-Amz-Meta-Cb-Modifiedtime
X-Ah-Environment
X-Shop-Environment
L5d-Success-Class
X-Csrf-Jwt
X-CGP
Cluster
X-Tenant
X-Connection-Hash
Datacenter
Expiry
Content-Script-Type
X-Cache-Aspx
X-LB-NoCache
X-Varnish-Authentication
X-Contensis-Viewer-Groups
A
X-Moov-T
X-Moov-Xdn-Version
Content-Style-Type
X-Branch-Name
X-Gamma-Serve
RNT-Machine
Cmsid
X-LB-ID
Server-ID
Cmstype
Cdn-Requestid
Locid
Cache-Key
X-NGINX-Cache
RNT-Time
SID
Cdn
X-Ratelimit-Reset
X-Refresh
X-Varnish-Hits
CPC-Cache
X-Vmg-Version
Cdnsip
Cdncip
X-ND-Cache
X-Tx-Id
X-AK-Request-ID
X-Region-Sid
CPC-Age
X-Nf-Request-Id
X-Cdn-Diag
Yak-Timeinfo
X-DynaTrace-JS-Agent
X-VHOST
X-Api-Version
X-LAGOON
X-Amz-Storage-Class
RATING
X-MCACHE
PFcat
NtCoent-Length
X-Client-Ip
X-CDN-Cache-Status
GeoIp-Country-Code
X-Servedbyhost
X-Wa
X-Nc
X-HN
X-VarnishDD-TTL
X-Srv
X-Tb-Optimization-Total-Bytes-Saved
X-Fpc
X-Backend-Instance
X-TX-ID
X-Nananana
CloudFront-Viewer-Country
CacheControlHeader
X-Azure-Ref-OriginShield
XM
X-Hit
X-TIME
X-Akamai-Transformed
Resin-Trace
X-B3-Parentspanid
X-Via-Fastly
X-Cache-Backend
X-API-Version
X-Variation
X-CACHE-AGE
Uri
X-LiteSpeed-Tag
X-Origin-Expires
User-Agent
X-Lagoon
VNS-Cache
X-Proxy-CacheRZ
X-Fastly-Country-Code
X-LiteSpeed-Cache-Control
X-CSRF-TOKEN
X-URL
VNS-Age
X-Zone
XkeyRZ
Cache-Name
True-Client-Ip
X-Datacenter
X-Info
X-Amz-Meta-Opti
Cross-Origin-Opener-Policy-Report-Only
MIME-Version
X-Geo
Tcn
Lb
X-Vc
DataCenter
X-HostName
Mime-Version
Hostname
X-Dispatcher-Number
X-DataCenter
X-NewRelic-App-Data
True-Client-IP
X-Dynatrace-Js-Agent
X-UA
X-AIR-PT
X-Cached-By
GeoIP-Latitude
X-Ig-Origin-Region
X-Location
Fastly-Drupal-Html
Cache-Hits
X-B3-Spanid
Fusion-Source
Fusion-Template-Id
X-NWS-UUID-VERIFY
Fusion-Deployment-Id
X-Mid
Fusion-Content-Source
Fusion-Content-Id
Fusion-Component-Id
X-Presslabs-Stats
Cf-Ipcountry
Powered-By
X-Webkit-Csp-Report-Only
X-Cdn-Forward
X-Cloudmap
X-CUA
X-Jungle-Id
X-IAuth-Set-Uid
Origin-CC
Origin-EX
BehaviorPad-Version
Srv
X-Traceid
X-User
X-Segment-20210421
X-Varnish-Beresp-TTL
CountryCode
X-CS
X-ECache
X-FPC
X-Dispatch
X-Esi
X-Cache-Enabled
Debug
Ohc-File-Size
GeoIP-Country-Code
CDN
X-NC
X-ServedByHost
Cl-Cache
X-WA
Server-Info
Location
X-Oracle-DMS-ECID
X-Cs
My-App
X-Render-Time
X-Wp-Cf-Super-Cache
X-Cdn-Cache-Status
X-Wp-Cf-Super-Cache-Cache-Control
Wpo-Cache-Message
Ohc-Cache-HIT
Wpo-Cache-Status
X-VTEX-Cache-Time
X-Snapshot-Date
X-Wormhole-Sdk
X-Lb-Id
X-VTEX-Cache-Server
X-Litespeed-Tag
Server-Id
X-Internal-Host
CF-Ctrl
YJS-ID
X-Powered-By-VTEX-Cache
Load-Balancing
Rtss
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
Edge-Cache
X-MSEdge-Flight
X-MSEdge-Features
X-Nitro-Cache
X-App
X-Fastly-Backend-Reqs
X-Lb-Nocache
X-Auth-Group-Type
X-ID
Ms-Author-Via
X-VCL-Version
X-Litespeed-Cache-Control
Xkey-La3
X-Akamai-Pragma-Client-IP
X-Proxy-Cache-La3
Xkeylog
X-Cdn-Request-ID
X-Cache-FS-Status
CF-Cached-On
X-MiniProfiler-Ids
X-Nitro-Cache-From
X-Nitro-Rev
X-Dw-Trace-Id
X-RID
Memory
OriginIP
Memcached
X-IN-APIGATEWAYSSL
X-Acquia-Purge-Tags
X-APP-VERSION
X-Ig-Push-State
X-NodeID
X-Acquia-Site
X-Acquia-Application-UUID
Time
X-Acquia-Application-Trace
X-Th-Server
X-IN-APIGATEWAY
Geoip-Latitude
Srvid
X-FL-EDGE
Ngx
FSS-Cache
X-FL-QIT-DEBUG
X-Shopid
X-Sorting-Hat-Podid
X-Shardid
X-Cache-Version
X-Sorting-Hat-Shopid
Akamai-Cache-Status
X-Via-PopH
X-Ha-Backend
X-Via-PopN
X-Via-PopV
X-Te-Duration-Ms
X-Fastly-Cache-Hits
X-DefElseHash
X-Mg-Cache
X-DefHash
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-Pad
X-Varnish-CookieINHashed-On
Sm-Log-Id
X-Lsadc-Cache
X-Http-Duration-Ms
X-Vary
X-Varnish-Remaining-TTL
X-Http-Count
X-Check-Cacheable
X-Serial
X-Varnish-CookieHashed-On
X-RequestId
Yjs-Id
X-Udemy-Cache-App-Namespace
X-Te-Count
X-Service-Response-Time
X-Web-Server
X-Sucuri-Id