Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
X-Powered-By
Pragma
X-XSS-Protection
X-Cache
CF-RAY
Via
Age
Content-Security-Policy
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
Alt-Svc
X-Xss-Protection
P3P
X-Cache-Hits
X-UA-Compatible
CF-Ray
X-Served-By
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Request-Id
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
Access-Control-Allow-Credentials
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
X-Drupal-Cache
X-Cache-Status
X-Generator
X-Check
X-Cacheable
X-FRAME-OPTIONS
X-Envoy-Upstream-Service-Time
X-Request-ID
Timing-Allow-Origin
X-DNS-Prefetch-Control
X-Iinfo
X-Dns-Prefetch-Control
X-Drupal-Dynamic-Cache
Server-Timing
Feature-Policy
X-Content-Security-Policy
Access-Control-Expose-Headers
X-XSS-PROTECTION
Content-Encoding
X-CDN
Status
Upgrade
X-AspNetMvc-Version
Access-Control-Max-Age
X-Amz-Request-Id
X-Via
X-Amz-Id-2
Request-Context
X-Backend
X-Turbo-Charged-By
X-Cache-Group
X-Robots-Tag
X-AH-Environment
Cf-Edge-Cache
Keep-Alive
Host-Header
X-Hacker
X-Proxy-Cache
X-UA-Device
X-Vhost
X-Server
X-Rq
X-Server-Powered-By
Allow
X-Ws-Request-Id
X-Age
X-Dispatcher
EagleId
X-Varnish-Cache
X-Amz-Version-Id
P3p
X-LiteSpeed-Cache
Nel
Grace
Cf-Apo-Via
Cf-Railgun
X-Page-Speed
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
X-OneAgent-JS-Injection
EagleEye-TraceId
X-Swift-CacheTime
X-Swift-SaveTime
X-Aws-Lambda-Call-Status
Ali-Swift-Global-Savetime
X-Pingback
X-Host
X-Node
X-WebKit-CSP
X-Cache-Lookup
X-CST
X-Backend-Server
Accept-CH
X-Server-Id
Surrogate-Control
Permissions-Policy
X-Readtime
X-Nginx-Cache-Status
X-Nginx-Upstream-Cache-Status
X-Akam-SW-Version
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Application-Context
Request-Id
Accept-CH-Lifetime
X-Content-Security-Policy-Report-Only
X-Cloud-Trace-Context
X-Ruxit-JS-Agent
X-Ua-Compatible
X-Response-Time
X-HW
Xkey
X-Trace
X-Edge
Content-Location
X-Clacks-Overhead
X-Mod-Pagespeed
Rating
X-Url
Accept-Ch
X-ESI
X-Midtier
X-Amz-Server-Side-Encryption
Accept-Ch-Lifetime
X-Mcache
Cache-Tag
X-Country
X-ECACHE
X-Rack-Cache
X-MS-InvokeApp
X-D2id
X-Powered-By-Plesk
X-Vcap-Request-Id
X-Upstream
X-Kinja-Server
X-Kinja-Revision
X-Exp-Id
X-Kinja
X-Cdn-Fetch
X-Kinja-Build
X-Use-Magma
X-GoogleNews-Bot
X-Exp-Variant
X-Element-Page-Cache
Verso
Edge-Control
Service-Worker-Allowed
RTSS
X-TtlSet
X-Vname
X-PC
X-Country-Code
X-Ac
Origin-Trial
X-Goog-Hash
X-VARITI-CCR
X-Navigation-Version
X-Abt-Application-Version
X-WebKit-CSP-Report-Only
Fastly-Restarts
X-Oneagent-Js-Injection
X-GitHub-Request-Id
X-Kinja-CCPA
X-Browser-Type
X-Cache-TTL
X-Amz-Rid
X-Aspnetmvc-Version
X-Cached
X-Webkit-CSP
X-Varnish-TTL
Cross-Origin-Opener-Policy
X-NWS-LOG-UUID
X-Server-Name
X-Sol
Display
X-Middleton-Display
Pagespeed
X-Amzn-Trace-Id
X-Dw-Request-Base-Id
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
SPRequestGuid
X-SharePointHealthScore
X-Ruxit-Js-Agent
X-Times
X-Ttl
X-B3-Traceid
X-Content-Type
X-Erf-Bev-Bev-Is-Generated
X-Server-Lifecycle-Phase
X-Erf-Bev-Bev
X-Instrumentation
X-Kraken-Loop-Name
SPRequestDuration
SPIisLatency
AR-PoweredBy
Pinterest-Generated-By
X-Pinterest-Rid
X-Powered-CMS
Pinterest-Version
AR-ATIME
X-Cache-Key
AR-Request-ID
AR-SID
X-FastCGI-Cache
X-Litespeed-Cache
X-Client-IP
X-Mg-S
Arr-Disable-Session-Affinity
Response
X-Middleton-Response
X-Version
X-Fastly-Request-ID
X-Cnection
X-Ser
X-HP-Webp
X-HP-Trace-Id
X-Jurisdiction
Nginx-Cache
Cache-Tags
AR-CACHE
X-Accel-Expires
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-T
Cache-Status
Edge-Cache-Tag
X-NF-Request-ID
X-Hits
X-MSEdge-Ref
Front-End-Https
X-Px
Public-Key-Pins
X-RateLimit-Remaining
X-B3-TraceId
X-Recruiting
Payment
S
X-Frontend
X-Shield-Request-Id
X-Server-ID
X-Ua-Browser
Server-Node
X-LLID
X-Request-Received
X-Request-Processing-Time
X-B3-TraceId-Primal
Mrf-Cache-Status
MRF-Tech
X-Daa-Tunnel
X-RateLimit-Limit
X-GUploader-UploadID
X-Goog-Metageneration
Content-MD5
X-DIS-Request-ID
Access-Control-Request-Method
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Content-Digest
MicrosoftSharePointTeamServices
X-PressLabs-Stats
TP-Cache
X-TTL
Realpath
X-Forwarded-For
X-Protected-By
X-Microsite
X-Request-Handler-Origin-Region
Fastcgi-Cache
X-HS-Content-Id
X-HS-Combine-CSS
X-HS-Cache-Config
X-HS-Hub-Id
X-Distributor
X-Ratelimit-Remaining
X-FB-Debug
Access-Control-Allow-Method
X-Page-Id
X-Rid
X-Cluster-Name
X-LB-Cache
Accept-Charset
X-Webkit-CSP-Report-Only
X-Geo-Country
X-Aspnet-Version
X-Ua-Device
X-Hostname
TP-L2-Cache
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-B3-Sampled
X-Goog-Generation
X-Goog-Storage-Class
Count-Hit
X-Erf-Stays-Pdp-Viaduct-Migration-Web
X-Seen-By
X-Ezoic-Cdn
Cross-Origin-Resource-Policy
X-Kinsta-Cache
X-Correlation-Id
Cleartype
X-Ratelimit-Limit
X-Edge-Location-Klb
TCN
X-App-Server
X-Newrelic-App-Data
X-Fastcgi-Cache
X-Id
X-Varnish-Backend
Referer-Policy
X-Logged-In
X-Content-Options
X-Mobile
DC
X-Hosted-By
X-Git-Hash
X-Origin-Cache
X-Xrds-Location
X-Flags
X-Is-Crawler
X-Contextid
X-Amz-Replication-Status
X-Route-Name
X-Fb-Rlafr
X-Aspnet-Duration-Ms
X-Request-Guid
X-Providence-Cookie
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Revision
X-TEC-API-VERSION
Surrogate-Key
X-Debug-Info
Retry-After
Frame-Options
X-Grace
X-App-Environment
X-Varnish-Grace
X-IPS-LoggedIn
X-Amz-Meta-S3cmd-Attrs
X-Forwarded-Proto
X-TT
X-F-Cache
X-Envoy-Decorator-Operation
X-Azure-Ref
X-RateLimit-Reset
Section-Io-Cache
X-Wix-Request-Id
X-Magnolia-Registration
MS-Author-Via
X-Whom
Healthy
X-COUNTRY
X-Proxy-Cache-Info
X-Webkit-Csp
Charset
Viewport
X-Akamai-Edgescape
X-ECache
X-Origin-Server
Alternate-Protocol
X-Backend-Name
X-Language
X-Www-Served-By
WPO-Cache-Status
WPO-Cache-Message
X-AppVersion
X-Az
X-Activity-Id
X-App-Version
Filterid
X-Varnish-Server
Paypal-Debug-Id
X-Datadog-Sampling-Priority
Server-Name
X-Datadog-Parent-Id
X-Datadog-Trace-Id
Amp-Access-Control-Allow-Source-Origin
SRV
X-EdgeConnect-Cache-Status
X-Trace-Id
Host
X-DataDome
X-Cache-Rule
SD-X-WS
X-Response-Served-From
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-B
X-Http-Reason
X-Original-Request-Id
Akamai-GRN
X-Cache-Grace
X-Akamai-Request-ID2
Front
X-Kong-Upstream-Latency
X-User-Agent
X-Rule
X-Kong-Proxy-Latency
X-Instance
X-Nf-Request-Id
X-Edge-Location
X-Tumblr-Pixel-1
X-Tumblr-User
X-Page-View
X-Region
X-Cacheable-TTL
X-Rocket-Nginx-Serving-Static
From-Origin
X-N
X-Tumblr-Pixel
X-Status
X-L-Path
X-Jobs
X-Environment-Context
X-ARC
X-UUID
X-Varnish-Age
Country
X-Unique-Id
X-Tumblr-Pixel-0
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-ProcessESI
X-RemovedCookies
Protected
X-FW-Server
X-FW-Static
X-FW-Serve
X-FW-Hash
X-Framework
X-FW-Dynamic
X-Load-Cache
X-FW-Type
X-FW-Version
X-Vcache
X-Is-Bot
X-Rendered-As
X-Cache-Time
Fastly-SIE
X-Type
Fastly-SWR
ServerID
X-Proxy
X-Mg-Request-UUID
X-Datadog-Sampled
Content-Disposition
X-Adobe-Content
X-Adobe-Loc
Access-Control-Request-Headers
X-G
X-Amzn-Remapped-Content-Length
X-Debug-IsPreview
X-B-Cache
X-Debug-IsConnected
X-Signature
X-Time
X-Tec-Api-Origin
X-Tec-Api-Version
X-Tec-Api-Root
X-Client-Ip
X-CDN-Forward
X-Cache-Control
X-WP-CF-Super-Cache
Backend
X-WP-CF-Super-Cache-Cache-Control
X-Erf-Web-Scheduler
X-Cache-Age
Refresh
X-DynaTrace
X-XRDS-LOCATION
Countrycode
X-Drupal-Cache-Tags
Accept-Language
X-Servername
Xet-Cookie
Url
X-Httpd
X-Nginx-Cache
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-DynaTrace-JS-Agent
X-Generated-By
CF-IPCountry
X-Template
X-HTML-Minification-Powered-By
Webserver
X-Device-Type
X-Source
X-Mode
X-Content-Powered-By
X-NYM-Debug-Backend
GEO-INFO
X-Storage
OT-Force-Account-Verify
X-Urbn-Context-Path
X-JoinUs
X-Content-Age
Load-Balancing
Locale
Meta-Geo
S-Rt
Filters
X-Cache-Action
X-GeoCode
X-Urbn-Site-Id
X-Director
X-Cache-Operation
X-GeoCountry
X-UPSTREAM-Address
X-Say-Cacheable
X-Say-TTL
X-SayCDN-TTL
Version
X-Rn-Rsrv
X-LAGOON
X-Rewrite-Enabled
X-ServerID
X-SaId
X-URL
X-Cache-Hit
X-Cluster-Node
X-Container-Uri
X-Soup
X-Varnish-Cache-Hits
X-Loop
X-Tncms
X-Cache-Server
X-Forwarded-Host
X-Tumblr-Pixel-2
X-MCACHE
Onion-Location
X-Varnish-Hostname
X-Git-Commit
X-Tumblr-Pixel-3
Xserver
X-Lambda-Id
X-Detected-As
Azure-Version
Azure-RegionName
Azure-SlotName
Azure-SiteName
X-Hcs-Proxy-Type
Azure-InstanceId
Cross-Origin-Window-Policy
X-Sql-Count
Web-Mar-Node
X-XRDS-Location
X-Tb
X-RM-Cache-TTL
X-Sql-Duration-Ms
X-Tt-Logid
X-VCT
X-Served-From
X-CCDN-CacheTTL
X-CCDN-Origin-Time
X-Proxied
X-Extlb
X-Ms-Request-Id
DB-Nickname
X-Skip-Cache
Mn-Server-Ip
X-Proto
X-Labrador-Cache-Channel
X-Adobe-Source
X-PHP-Host
X-FB-TRIP-ID
X-VC-Cache
X-Logging-Id
X-Zipkin-Id
X-RCS-CacheZone
X-Routing-Service
X-Generation-Time
X-Ms-Version
TWC-Device-Class
TWC-GeoIP-Country
TWC-GeoIP-LatLong
TWC-Locale-Group
X-Origin-Hint
X-Proxy-Build
Webcakes-Region
X-Format
X-Fetched-On
X-Debug
X-R9-Blue-Green-Version
Webcakes-App-Name
X-Uri
TWC-Connection-Speed
X-Timing-Wait
TWC-Privacy
Webcakes-App-Version
Property-Id
Selected-Fe
Fastcgi-Useragent
Uber-Trace-Id
X-Endurance-Cache-Level
Node
X-Zen-Fury
X-LSADC-Cache
X-Redis-Cache
Source
X-Ua
X-Sucuri-Cache
X-NGENIX-Cache
X-Sucuri-ID
CDN-RequestId
X-Srv
Section-Origin-Responded
Section-Io-Id
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
X-TimeS
X-Drupal-Cache-Contexts
X-Varnish-Ttl
X-B3-SpanId
X-FTR-Request-ID
X-Origin-CC
X-Origin-TTL
X-MP-GENERATED-AT
X-Origin-Date
X-Varnish-Hits
X-S
X-Pass-Why
X-Cache-Expired-At
X-Real-IP
X-Upgrade-Enabled
NGB
Upgrade-Insecure-Requests
Liferay-Portal
X-CACHE-AGE
X-Newrelic-Synthetics
X-Ratelimit-Reset
X-Handled-By
Fastly-Drupal-HTML
X-Akamai-Transformed
X-Optimistic-Header
X-GEO
Apigw-Requestid
X-Reqid
X-Xfnlog-Site
X-Cms-Context
X-Restarts
X-Oracle-Dms-Ecid
X-TIME
ServedBy
X-Hl-Ver
X-UA-Device-Type
X-Oracle-Dms-Rid
Ms-Operation-Id
MS-CV
X-No-Session
X-BYPASS-REASON
X-Node-Name
X-Tx-Id
X-ProxyCache-Status
X-RTag
X-Cache-Host
X-ProxyCache-Key
X-Cache-Type
X-Parent-Response-Time
X-Cache-TTL-Remaining
X-CSRF-Token
WP-Super-Cache
X-Via-JSL
X-Pubstack
X-IPLB-Request-ID
X-LJ-Flow-ID
X-IPLB-Instance
X-Cluster
X-B3-Spanid
CDN-EdgeStorageId
CDN-CachedAt
CDN-Cache
X-VWS-Id
CDN-PullZone
CDN-RequestCountryCode
X-AWS-Id
CDN-RequestPullSuccess
CDN-Uid
CDN-RequestPullCode
N-Cache
Odigeo-Trace-Id
Ngx.Var.Host
Host-ID
Origin-Agent-Cluster
DCR-Processing-Time-Ms
Fastly-SSL
DCR-Decision-By
Candidate-Md5Url
BehaviorPad-Version
Canary
Gannett-Cam-Experience-Id
Ha-Gx-Prefs
Magicmarker
MD5-Digest
Lang
L5d-Success-Class
HA-Ipaddr
L
Meta-Geo-Continent
X-App-Name
X-Epic-Correlation-Id
X-Ec-GeoHdr
X-Eu-Site
X-External-Request-Id
X-FC-Vary-Parameters
X-Fastly-Backend
X-Ec-Fail
X-Ec-Custom-Error
X-Debug-Cache-Store
X-Debug-Cache-Fetch
X-Destination
X-Developer
X-Dispatcher-Number
X-Request-Host
X-Rojux
X-Viewer-Country
X-Vdms-Version
X-Vtex-Remote-Cache
X-We-Are-Hiring
Xc-Version
X-Worker
X-Vdms-Path
X-SRCache-Key
X-ScT
X-S-Cookie
X-SD-PageType
X-Slack-Backend
X-Slack-Shared-Secret-Outcome
X-D
X-Csrf-Jwt
Web-Mar-Region
W
X-A
X-A-Ccd
X-A-Dcw
X-A-Dam
Vix-Hermes-Req-Id
True-Client-Country-4JS
Server-Host
Rendered-Blocks
Sslversion
Surrogated-Key
T-Server
X-A-Dgt
X-A-Wwc
X-CF-Lambda-Fn
X-CacheTTL
X-CF-Lambda-Version
X-CGP
X-Conf
X-Cache-NE
X-Bl-Debug
X-App
X-Aed
X-Application
X-B-Cookie
X-BCube-Filmed-By
Redirect-Candidate
X-Bc-Bl
X-Server-W
X-AB
X-Proxy-Cache-Status
Cache-Provider
Expect-Staple
X-Node-Id
X-Var-Ttl
Fastly-GeoIP-CountryCode
AKAMAI
X-GeoIP-Country-Code
TDXMobile
Fastly-Backend-Name
X-Org
X-VG-WebCache
X-Correlation-ID
X-GeoIP-Region-Code
X-Mvc-Supplant-Cachable
CPC-Age
Gh-Request-Id
Datacenter
CPC-Cache
X-Micro-Cache
X-Generated-On
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-Accel-Buffering
X-Forwarded-Path
X-Request-Time
X-Varnishpool
X-Policy
Origin
X-Shop-Environment
X-Wix-Viewer-Type
Mail-Subject
Release
X-Refresh
X-S-Maxage
X-Gdpr
VNS-Cache
X-Accel-Expires-Debug
X-Nyt-Route
We-Hiring
VNS-Age
X-Bip
X-Cache-Status-Check
X-Human
X-Owner
X-SVT-ORM-VERSION
X-Origin-Time
X-Mid
X-Sn-Servicetimems
X-CMSURLCustom
X-Date
X-RateLimit-Remaining-Second
X-Core-Mission
X-SVT-ORM-RULES
X-Level-Front-Cache
X-Loc
X-Pool
X-Platform
X-Qloud-Router
Thinkindot-CacheControl
X-RateLimit-Limit-Second
X-Irp-Debug
X-Tenant
X-Clientip
X-Cache-Bucket
X-Geo-Header
Thinkindot-Control
X-PAYTM-SRV-ID
X-Server-IP
X-Orig-Expires
X-Hash
Cache-Name
X-VServer
X-Cache-Info
X-Vmg-Version
X-Cdn-Diag
X-Test
X-Cdn-Origin
Thinkindot-CacheControl-Type
X-Thanos
X-Thinkindot-L3
User-Cache-Control
Content-Secure-Policy
X-Geo-Region
X-DPWN-IS-SECURE
X-AIR-PT
X-VG-TLSProxy
X-Nitro-Cache
X-Sorting-Hat-PodId
X-Auto-Login
X-Block-Status
X-Up
X-Datadome
X-BBC-Edge-Cache-Status
X-DefElseHash
X-Cache-Debug
X-Core-Value
X-Cdn-Srv
X-Storefront-Renderer-Rendered
X-DefHash
X-Nginx-Cache-Key
X-Akamai-Device-Characteristics
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
X-ID
X-Alternate-Cache-Key
X-Device-Os
X-TraceId
X-Variation
X-Varnish-CookieHashed-On
X-Sorting-Hat-ShopId
X-ShopId
Country-Code
DSUID
Cmstype
Cmsid
Cf-Device-Type
X-ApacheServer
Environment
X-Gen-Mode
Is-Eu
X-GeoIP
X-Old-Content-Length
X-Mvc-Supplant-OutputCached
CDCHOST
X-Dispatcher-Server
X-PERF
X-Hnp-Log
X-Origin-Response-Time
X-INCAP-ABP
X-Instance-Name
X-Origin
Adler-Geo
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
Apple-News-Services-Handled
X-Mly-Id
CloudFront-Viewer-Country
X-Forwarded-Site
Platform
X-Shopify-Stage
X-NodeID
Req-Svc-Chain
Sever-Int
Server-Hostname
Server-Ext
X-Nananana
Producers
Machine
X-ShardId
NM-Fastcgi-Cache
X-Vcl-Version
X-NCache
X-Op-Id-All
Server-Info
X-From
Ssr
X-Vgn-Hpd-Reason
X-Esi-Check
X-Section
X-Clara-WADP
X-Via-Fastly
X-Access
X-WA-Info
Wxu-Next-Commit
X-WADP-Cache
Wxu-Next-Hostname
Wxu-Next-Region
X-Fastly-Request-Id
X-Dc
X-Gzip
X-Fmm-Version
Esi-Enabled
X-Cache-Id
C-Via
X-Accel-Version
AMP-Access-Control-Allow-Source-Origin
X-LB-NoCache
X-CACHE-GROUP
NGX
X-Amz-Meta-Cb-Modifiedtime
Pics-Label
X-Cache-Enabled
X-API-Version
Hostname
X-Buckets
X-Is-Tablet
X-Tcp-Rtt
X-Is-Desktop
X-Is-Supported-Browser
X-Is-Mobile
Server-ID
Memcached
IsBot
X-SIPLIST1
X-JWT-State
X-Is-Gdpr
X-Varnish-Beresp-Grace
X-Browser-Name
X-Has-Esi
Memory
Sid
Time
X-HA-Backend
X-Varnish-Beresp-Ttl
YJS-ID
X-B3-Parentspanid
X-Wp-Cf-Super-Cache-Active
CF-Ctrl
X-Scale
X-ZONE
X-Platform-Cluster
Cdn-Requestid
Cache-Hits
X-Platform-Router
Origin-EX
Origin-CC
X-Platform-Processor
X-Presslabs-Stats
Location
X-Cached-By
X-Tb-Optimization-Total-Bytes-Saved
X-TIM-N
X-PHP-Backend
X-Air-Source
X-Air-Trace-Id
X-Zone
X-Air-Hostname
X-WP-CF-Super-Cache-Active
X-Backend-Instance
X-Internal-Host
X-TA-CDN-Provider
X-Frame-Option
X-Origin-Cache-Key
X-Cache-Ttl
Resin-Trace
X-Fpc
X-Hyper-Cache
X-Cs
X-Azure-Ref-OriginShield
X-LiteSpeed-Cache-Control
X-Webstats-RespID
X-DC
Epwk-X-Cache
X-Service
GeoIP-Latitude
X-DataCenter
Uri
X-VC
X-Nitro-Rev
XServer
GeoIp-Country-Code
X-NGINX-Cache
X-Site-Version
X-Origin-Expires
Cache-Host
X-Nitro-Cache-From
X-Microcachable
X-FTR-Cache-Status
X-FTR-Expires
X-FTR-Balancer
X-FTR-Backend
X-FTR-Backend-Server
X-Country-Code-Real
XM
X-Locale
X-Info
True-Client-Ip
X-VCache
True-Client-IP
PFcat
X-HN
NtCoent-Length
LB
X-Pod-Name
GeoIP-Country-Code
X-VarnishDD-TTL
Cdn
X-Web-Node
X-CSRF-TOKEN
X-NewRelic-App-Data
Cdn-Request-Time
X-Edge-Server
Cdn-Host
User-Agent
X-Ad-Defer-Variation
M-TraceId
WZWS-RAY
X-Datacenter
X-NMSegId
X-Geo
X-CS
Fastly-Drupal-Html
Req-ID
Locid
X-FPC
X-Via-SSL
X-Vercel-Id
X-Via-Edge
Edge-Copy-Time
A
X-SRV
X-Vercel-Cache
Srvid
X-Via-CDN
X-APP-VERSION
WebServer
X-FL-QIT-DEBUG
X-FL-EDGE
X-MSEdge-Flight
X-Pad
X-MSEdge-Features
X-LiteSpeed-Tag
X-Scope-Id
X-M-Log
X-M-Reqid
Cluster
X-Ad-Load-Variation
Pramga
X-Request-Start
SID
X-Request-URI
Tcn
X-HostName
X-Cache-ASPX
X-Qnm-Cache
X-Moov-T
X-Moov-Xdn-Version
X-Shield-Cache-Expires
X-Varnish-Beresp-Status
X-FireWall-Port
X-Contensis-Viewer-Groups
X-NWS-UUID-VERIFY
X-ATG-Version
X-Varnish-Authentication
X-TRACE-ID
X-Cdn-Request-ID
X-Api-Version
Cf-Ipcountry
CountryCode
X-AK-Request-ID
Edge-Cache
Cdnsip
X-Cache-Date
Content-Script-Type
X-Amz-Meta-Opti
Content-Style-Type
Cache-Key
Cdncip
X-Esi
Path
Cache-Tv-Group
X-WP-CF-Super-Cache-Cookies-Bypass
X-TH-Server
X-Branch-Name
HostName
CDN
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-Air-Pt
X-Cache-FS-Status
X-B3-Trace-ID
X-Github-Request-Id
XkeyRZ
X-Aicache-OS
Tube-Got-Results
Tube-Got-Eval
Click-Count-Error
Tube-Return
Click-Count-Action-Start
X-Proxy-CacheRZ
X-Acquia-Purge-Cdn-Unconfigured
Yak-Timeinfo
X-Render-Time
X-SB
X-Req
Tube-Get-Contents
X-Servedbyhost
X-V-Cache
X-Nc
X-Wa
Lb
X-CACHE-KEY
X-VCL-Version
X-Tim-N
X-Wp-Cf-Super-Cache-Cache-Control
X-Via-Popv
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-Via-Popn
MIME-Version
X-Wp-Cf-Super-Cache
Srv
X-Cdn-Forward
X-HS-Content-Campaign-Id
Geoip-Latitude
X-Planisys-CDN-Cache
On-Server
X-LB-ID
X-Ha-Backend
State
Wpo-Cache-Message
X-Via-Poph
Wpo-Cache-Status
X-Platform-Server
Proxy-Connection
Server-Id
V-Age
X-Akamai-Pragma-Client-IP
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-Lb-Cache
X-Vgn-Hpd-Variations-Key
X-Release
CF-Cached-On
X-UA
X-Vgn-Hpd-Ssi
X-Fastly-Cache
X-Generated-In
X-Dw-Trace-Id
X-Vary
X-Men
Ngx-Var-Key
X-Upstream-Ct
X-Vgn-Hpd-Cached
X-Upstream-Ht
X-Fastly-Backend-Reqs
X-User
X-TT-LOGID
X-CUA
X-Lb-Nocache
X-EC-Lua
X-Acquia-Site
X-Traceid
X-Acquia-Application-UUID
X-Acquia-Application-Trace
My-App
X-Via-Ucdn
PICS-Label
X-Acquia-Purge-Tags
X-Sigma
X-Rocket-Build-Number
X-Cache-Remote
Ohc-Cache-HIT
X-HS-Status
X-Sigma-Backend
Ohc-File-Size
X-Varnish-Beresp-TTL
Yjs-Id
X-Iplb-Instance
X-Iplb-Request-Id
X-Via-PopN
X-Via-PopV
Warning
X-Lb-Id
X-Varnish-Director
X-Via-PopH
X-Miniprofiler-Ids
Cache
Vha6-Origin
X-Cached-Since
X-Snapshot-Date
X-Fastly-Cache-Hits
CACHE-MISS-TO-ORIGIN
Inserted-Into-Cache-At
X-ElasticPress-Query
X-Litespeed-Cache-Control
X-CF-Cache-Header-Cache-Control
X-CF-Cache-Header-Vary
Cneonction
X-RAMCache
Ngx
Log-Origin
X-Udemy-Cache-App-Namespace