Threat Level: green Handler on Duty: Russ McRee

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
X-Powered-By
Pragma
X-XSS-Protection
X-Cache
CF-RAY
Via
Age
Content-Security-Policy
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
Alt-Svc
X-Xss-Protection
P3P
X-Cache-Hits
X-UA-Compatible
CF-Ray
X-Served-By
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
Access-Control-Allow-Credentials
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
X-Drupal-Cache
X-Generator
X-Cache-Status
X-Check
X-Cacheable
X-FRAME-OPTIONS
X-Envoy-Upstream-Service-Time
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Iinfo
X-Dns-Prefetch-Control
X-Drupal-Dynamic-Cache
Feature-Policy
X-Content-Security-Policy
Content-Encoding
X-XSS-PROTECTION
Access-Control-Expose-Headers
Server-Timing
Upgrade
X-CDN
Status
X-Request-ID
X-AspNetMvc-Version
Access-Control-Max-Age
X-Amz-Request-Id
Request-Context
X-Amz-Id-2
X-Via
X-Turbo-Charged-By
X-AH-Environment
X-Backend
X-Cache-Group
X-Robots-Tag
Cf-Edge-Cache
Keep-Alive
Host-Header
X-Hacker
X-Proxy-Cache
X-UA-Device
X-Server
X-Rq
X-Vhost
X-Server-Powered-By
Allow
X-Age
X-Varnish-Cache
X-Ws-Request-Id
X-Dispatcher
X-Amz-Version-Id
EagleId
P3p
Nel
Grace
Cf-Apo-Via
X-LiteSpeed-Cache
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Page-Speed
Cf-Railgun
X-Device
EagleEye-TraceId
X-Aws-Lambda-Call-Status
X-OneAgent-JS-Injection
X-Swift-CacheTime
X-Swift-SaveTime
X-Pingback
Ali-Swift-Global-Savetime
X-Host
X-Node
Accept-CH
X-WebKit-CSP
X-CST
X-Backend-Server
Surrogate-Control
X-Server-Id
X-Cache-Lookup
X-Nginx-Cache-Status
X-Readtime
Accept-CH-Lifetime
Permissions-Policy
X-Akam-SW-Version
X-Nginx-Upstream-Cache-Status
Request-Id
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Application-Context
X-Content-Security-Policy-Report-Only
X-Cloud-Trace-Context
X-Ua-Compatible
X-Trace
X-Response-Time
X-HW
X-Edge
Content-Location
X-Clacks-Overhead
X-Mod-Pagespeed
Xkey
X-Litespeed-Cache
X-Midtier
Rating
X-ESI
X-Ruxit-JS-Agent
X-Url
X-Amz-Server-Side-Encryption
X-ECACHE
X-Mcache
X-Upstream
X-Ruxit-Js-Agent
X-Vcap-Request-Id
Accept-Ch
Cache-Tag
X-D2id
X-MS-InvokeApp
X-Exp-Variant
X-Element-Page-Cache
X-Cdn-Fetch
X-Exp-Id
X-GoogleNews-Bot
X-Use-Magma
X-Kinja-Server
Verso
X-Kinja-Revision
X-Kinja
X-Kinja-Build
X-Rack-Cache
X-TtlSet
X-PC
X-Vname
X-Powered-By-Plesk
Accept-Ch-Lifetime
Edge-Control
X-WebKit-CSP-Report-Only
RTSS
X-Country
Fastly-Restarts
X-Cache-TTL
X-Oneagent-Js-Injection
X-Ac
X-VARITI-CCR
Origin-Trial
X-Navigation-Version
X-Abt-Application-Version
X-Country-Code
Service-Worker-Allowed
X-Goog-Hash
X-Cached
X-Ttl
X-Varnish-TTL
X-Sol
Display
X-Middleton-Display
Pagespeed
X-Browser-Type
X-Amz-Rid
X-GitHub-Request-Id
Cross-Origin-Opener-Policy
X-Dw-Request-Base-Id
X-SharePointHealthScore
SPRequestGuid
X-Server-Name
X-Content-Type
X-Mg-S
X-Amzn-Trace-Id
X-B3-TraceId
X-Powered-CMS
X-Kraken-Loop-Name
Arr-Disable-Session-Affinity
X-Middleton-Response
X-Erf-Bev-Bev-Is-Generated
Response
X-Server-Lifecycle-Phase
X-Instrumentation
X-Erf-Bev-Bev
AR-PoweredBy
AR-ATIME
AR-SID
AR-Request-ID
X-Kinja-CCPA
X-NF-Request-ID
SPIisLatency
SPRequestDuration
X-Cache-Key
X-Webkit-CSP
X-Times
X-ORACLE-DMS-RID
X-NWS-LOG-UUID
X-ORACLE-DMS-ECID
X-Version
AR-CACHE
X-Pinterest-Rid
Pinterest-Version
Pinterest-Generated-By
X-HP-Trace-Id
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Jurisdiction
X-HP-Webp
X-Accel-Expires
Cache-Tags
X-T
X-Cnection
Cache-Status
X-Aspnetmvc-Version
Front-End-Https
X-Fastly-Request-ID
X-RateLimit-Remaining
Nginx-Cache
X-FastCGI-Cache
X-MSEdge-Ref
Edge-Cache-Tag
X-Hits
X-B3-Traceid
X-Ser
X-Client-IP
X-Px
X-B3-TraceId-Primal
Public-Key-Pins
MRF-Tech
Mrf-Cache-Status
X-RateLimit-Limit
Payment
X-Recruiting
X-LLID
X-Request-Received
X-Frontend
X-Request-Processing-Time
Server-Node
X-Ua-Browser
X-Server-ID
X-Shield-Request-Id
X-Erf-Stays-Pdp-Viaduct-Migration-Web
X-DIS-Request-ID
S
TP-Cache
X-Fastcgi-Cache
X-Goog-Metageneration
X-GUploader-UploadID
MicrosoftSharePointTeamServices
Access-Control-Request-Method
X-Amz-Apigw-Id
X-Amzn-RequestId
X-HS-Hub-Id
X-HS-Combine-CSS
X-HS-Cache-Config
X-HS-Content-Id
Content-MD5
X-Content-Digest
X-LB-Cache
X-Microsite
X-Request-Handler-Origin-Region
X-Distributor
X-Protected-By
Access-Control-Allow-Method
Realpath
X-Page-Id
X-FB-Debug
TP-L2-Cache
Fastcgi-Cache
Accept-Charset
X-Ezoic-Cdn
X-Cluster-Name
X-Geo-Country
X-Rid
X-Forwarded-For
X-PressLabs-Stats
X-Hostname
X-Webkit-Csp
X-B3-Sampled
X-Aspnet-Version
X-Ua-Device
X-Correlation-Id
X-Seen-By
Cleartype
X-Daa-Tunnel
Referer-Policy
X-Goog-Generation
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
Cross-Origin-Resource-Policy
X-Mobile
X-Envoy-Decorator-Operation
TCN
DC
X-Ratelimit-Remaining
X-Content-Options
Count-Hit
X-Debug-Info
X-Varnish-Backend
X-TTL
X-Newrelic-App-Data
X-COUNTRY
X-TEC-API-ROOT
X-Origin-Cache
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-Logged-In
X-Contextid
X-App-Server
X-Varnish-Grace
X-XRDS-Location
X-Hosted-By
Surrogate-Key
X-Amz-Replication-Status
X-Grace
X-Git-Hash
X-Flags
X-Fb-Rlafr
X-IPS-LoggedIn
X-Is-Crawler
X-Route-Name
X-Revision
X-Request-Guid
X-Aspnet-Duration-Ms
X-Providence-Cookie
X-App-Environment
X-Azure-Ref
Frame-Options
X-Client-Ip
X-TT
X-Amz-Meta-S3cmd-Attrs
X-Origin-Server
X-Ratelimit-Limit
X-Edge-Location-Klb
X-Forwarded-Proto
X-Kinsta-Cache
X-RateLimit-Reset
Retry-After
X-Wix-Request-Id
Alternate-Protocol
X-Whom
WPO-Cache-Message
WPO-Cache-Status
Healthy
X-F-Cache
Charset
X-Magnolia-Registration
X-Akamai-Edgescape
X-Backend-Name
Viewport
Section-Io-Cache
MS-Author-Via
Paypal-Debug-Id
X-Proxy-Cache-Info
X-App-Version
X-B
X-Id
X-Webkit-CSP-Report-Only
SRV
ServerID
X-AppVersion
X-Activity-Id
X-Az
Amp-Access-Control-Allow-Source-Origin
X-Language
X-ARC
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
SD-X-WS
Akamai-GRN
Host
X-Cache-Rule
X-N
X-Http-Reason
X-Instance
X-Response-Served-From
X-Rule
X-Original-Request-Id
X-User-Agent
X-UUID
X-Varnish-Age
Front
X-Status
X-Rocket-Nginx-Serving-Static
X-Cache-Grace
X-Akamai-Request-ID2
Protected
X-Edge-Location
X-DataDome
Filterid
X-Www-Served-By
X-Is-Bot
X-FW-Version
X-Varnish-Server
X-Jobs
X-L-Path
X-Page-View
X-FW-Type
X-Load-Cache
X-Rendered-As
X-FW-Server
X-FW-Dynamic
X-Framework
X-Environment-Context
X-Cacheable-TTL
X-FW-Hash
X-FW-Serve
X-Unique-Id
Fastly-SIE
Fastly-SWR
From-Origin
X-FW-Static
X-Region
Country
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Adobe-Loc
X-Datadog-Trace-Id
X-Adobe-Content
X-Datadog-Sampling-Priority
X-EdgeConnect-Cache-Status
Server-Name
X-Type
X-Cache-Time
X-Datadog-Parent-Id
Access-Control-Request-Headers
X-Tumblr-User
X-Trace-Id
X-Tumblr-Pixel-0
X-ProcessESI
X-Cache-Control
X-Tumblr-Pixel-1
X-Tumblr-Pixel
X-RemovedCookies
X-G
X-Proxy
X-Yottaa-Metrics
X-Vcache
X-Yottaa-Optimizations
Refresh
X-ECache
X-Mg-Request-UUID
X-Datadog-Sampled
X-CDN-Forward
X-Amzn-Remapped-Content-Length
X-Time
X-Debug-IsConnected
X-Cache-Age
X-Debug-IsPreview
X-Oracle-Dms-Ecid
X-Source
X-Signature
X-Oracle-Dms-Rid
Content-Disposition
X-Drupal-Cache-Tags
X-B-Cache
X-Erf-Web-Scheduler
Backend
Accept-Language
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
Xet-Cookie
Version
X-Generated-By
Countrycode
X-DynaTrace
Webserver
X-HTML-Minification-Powered-By
X-Xrds-Location
CF-IPCountry
X-DynaTrace-JS-Agent
X-Httpd
X-Servername
X-Tec-Api-Root
X-Tec-Api-Version
X-Tec-Api-Origin
X-Mode
Url
X-Tt-Trace-Host
X-Tt-Trace-Tag
Xserver
X-Template
GEO-INFO
X-ID
X-Upgrade-Enabled
X-Device-Type
X-Storage
X-Nginx-Cache
X-NYM-Debug-Backend
X-Content-Age
X-JoinUs
X-Director
X-Urbn-Context-Path
X-Tb
X-UPSTREAM-Address
X-GeoCode
X-URL
X-Cache-Operation
X-GeoCountry
Locale
X-Cache-Action
S-Rt
Onion-Location
Meta-Geo
X-Say-TTL
Azure-Version
Azure-SlotName
Fastcgi-Useragent
Filters
X-LAGOON
X-ServerID
Load-Balancing
X-SayCDN-TTL
X-SaId
Azure-SiteName
X-Say-Cacheable
X-Rewrite-Enabled
X-Varnish-Cache-Hits
X-Urbn-Site-Id
X-Content-Powered-By
X-Proto
Azure-RegionName
X-XRDS-LOCATION
Azure-InstanceId
X-Container-Uri
Uber-Trace-Id
X-Cluster-Node
OT-Force-Account-Verify
X-PHP-Host
X-Git-Commit
X-VC-Cache
X-Varnish-Hostname
X-Soup
X-Forwarded-Host
X-MCACHE
X-Labrador-Cache-Channel
X-RM-Cache-TTL
X-VCT
Web-Mar-Node
X-Generation-Time
X-Served-From
X-LSADC-Cache
X-Ms-Request-Id
X-Tt-Logid
X-Cache-Server
X-Logging-Id
X-Sql-Duration-Ms
X-Ms-Version
X-Adobe-Source
X-Detected-As
X-Sql-Count
X-Origin-Hint
X-Proxied
Node
X-Lambda-Id
X-Skip-Cache
Mn-Server-Ip
X-RCS-CacheZone
Property-Id
TWC-Privacy
Webcakes-Region
Webcakes-App-Version
X-Zen-Fury
X-Debug
X-Sucuri-ID
X-FB-TRIP-ID
X-Zipkin-Id
Webcakes-App-Name
X-Sucuri-Cache
X-Routing-Service
TWC-GeoIP-Country
TWC-GeoIP-LatLong
X-R9-Blue-Green-Version
X-Extlb
TWC-Locale-Group
TWC-Connection-Speed
TWC-Device-Class
DB-Nickname
X-Tumblr-Pixel-3
X-Uri
Selected-Fe
X-Proxy-Build
X-Tumblr-Pixel-2
X-Fetched-On
X-Format
X-Timing-Wait
X-Loop
X-B3-SpanId
X-Tncms
CDN-RequestId
X-Drupal-Cache-Contexts
X-Rn-Rsrv
Liferay-Portal
X-CCDN-CacheTTL
X-CCDN-Origin-Time
X-Hcs-Proxy-Type
Source
X-Cache-Hit
X-Endurance-Cache-Level
X-Nf-Request-Id
X-Fastly-Request-Id
X-Varnish-Ttl
X-Redis-Cache
X-Ua
Cross-Origin-Window-Policy
X-Origin-Date
X-MP-GENERATED-AT
X-Srv
Fastly-Drupal-HTML
X-TimeS
X-CACHE-AGE
X-Varnish-Hits
Section-Origin-Responded
Section-Io-Id
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
X-Pass-Why
X-Cache-Expired-At
Upgrade-Insecure-Requests
X-S
X-Real-IP
Content-Secure-Policy
X-Cache-TTL-Remaining
X-UA-Device-Type
X-Origin-CC
X-Origin-TTL
X-Akamai-Transformed
X-Newrelic-Synthetics
X-Node-Name
X-Ratelimit-Reset
X-Pubstack
X-TIME
CDN-Uid
CDN-RequestPullSuccess
CDN-CachedAt
CDN-Cache
X-GEO
CDN-EdgeStorageId
CDN-RequestPullCode
CDN-PullZone
CDN-RequestCountryCode
X-Via-JSL
X-Hl-Ver
X-Server-W
X-RTag
Cache-Provider
X-Handled-By
X-NGENIX-Cache
X-Presslabs-Stats
Ms-Operation-Id
MS-CV
NGB
X-Xfnlog-Site
X-Restarts
X-Reqid
X-IPLB-Instance
X-Cms-Context
X-Cache-Type
Apigw-Requestid
WP-Super-Cache
X-IPLB-Request-ID
X-Optimistic-Header
BehaviorPad-Version
Canary
X-CGP
X-CF-Lambda-Version
X-CF-Lambda-Fn
X-Fastly-Backend
X-Cdn-Diag
X-CacheTTL
X-FC-Vary-Parameters
X-Conf
X-External-Request-Id
Candidate-Md5Url
X-Epic-Correlation-Id
X-Destination
X-Developer
X-Date
X-Debug-Cache-Store
X-Cache-NE
X-Dispatcher-Number
X-Ec-Custom-Error
X-Eu-Site
X-D
X-Debug-Cache-Fetch
X-Ec-GeoHdr
X-Ec-Fail
X-Csrf-Jwt
X-BCube-Filmed-By
X-A-Dcw
Odigeo-Trace-Id
Origin-Agent-Cluster
X-A-Dam
X-A-Ccd
X-A-Dgt
X-A-Wwc
X-Accel-Expires-Debug
Meta-Geo-Continent
N-Cache
Ngx.Var.Host
X-A
Web-Mar-Region
Server-Host
Vix-Hermes-Req-Id
True-Client-Country-4JS
Sslversion
T-Server
VNS-Age
Rendered-Blocks
We-Hiring
W
Redirect-Candidate
VNS-Cache
X-Aed
MD5-Digest
X-Forwarded-Path
X-Bl-Debug
X-Bc-Bl
Fastly-Backend-Name
Fastly-GeoIP-CountryCode
X-Cache-Bucket
DCR-Processing-Time-Ms
X-Cache-Host
CPC-Age
CPC-Cache
DCR-Decision-By
Fastly-SSL
Gannett-Cam-Experience-Id
L5d-Success-Class
L
Lang
Magicmarker
Mail-Subject
X-App
X-Application
X-B-Cookie
Gh-Request-Id
Ha-Gx-Prefs
HA-Ipaddr
X-Cache-Info
ServedBy
X-RateLimit-Limit-Second
X-Parent-Response-Time
X-Vdms-Version
X-Nyt-Route
X-Mvc-Supplant-Cachable
Surrogated-Key
X-Vdms-Path
X-Wikidot-Backend
X-Worker
X-Viewer-Country
X-SRCache-Key
Xc-Version
X-Slack-Backend
X-Policy
X-VG-WebCache
X-Slack-Shared-Secret-Outcome
X-Shop-Environment
X-Orig-Expires
X-Wikidot-Static-Cache
X-Origin-Time
X-We-Are-Hiring
X-Tenant
X-GeoIP-Region-Code
X-Has-Esi
X-Request-Host
X-ScT
X-Vtex-Remote-Cache
X-GeoIP-Country-Code
X-Gdpr
X-Rojux
X-S-Cookie
X-SD-PageType
X-Var-Ttl
X-Is-Gdpr
X-JWT-State
X-RateLimit-Remaining-Second
X-AIR-PT
X-ProxyCache-Status
Cache-Name
X-ProxyCache-Key
X-Vcl-Version
Hostname
X-BYPASS-REASON
X-CSRF-Token
X-Tx-Id
X-No-Session
X-S-Maxage
X-App-Name
X-Server-IP
X-ShardId
X-ApacheServer
X-Alternate-Cache-Key
X-Storefront-Renderer-Rendered
Thinkindot-Control
X-Up
X-Varnish-Remaining-TTL
X-Varnishpool
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
X-Varnish-CookieHashed-On
X-Variation
TDXMobile
X-Thinkindot-L3
X-Thanos
X-Sorting-Hat-PodId
X-Accel-Buffering
X-Sn-Servicetimems
X-Shopify-Stage
X-Sorting-Hat-ShopId
X-VG-TLSProxy
X-Test
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-ShopId
X-Qloud-Router
X-DefElseHash
X-Mid
X-Loc
X-Level-Front-Cache
X-Mly-Id
X-Nitro-Cache
X-Old-Content-Length
X-NodeID
X-Node-Id
X-DefHash
X-Irp-Debug
X-Esi-Check
X-Geo-Header
X-Generated-On
X-Varnish-CookieINHashed-On
X-Gzip
X-Hash
X-INCAP-ABP
X-Human
X-DPWN-IS-SECURE
X-Org
X-Core-Value
X-Bip
X-Cache-Debug
X-Fmm-Version
X-Pool
X-Refresh
X-BBC-Edge-Cache-Status
X-VServer
X-Request-Time
X-WADP-Cache
X-Cache-Id
X-Wix-Viewer-Type
X-Clara-WADP
X-Clientip
X-CMSURLCustom
X-Core-Mission
X-Owner
X-PAYTM-SRV-ID
X-Platform
X-Cdn-Origin
X-PERF
X-Vmg-Version
X-Auto-Login
AKAMAI
Adler-Geo
Platform
Release
Is-Eu
Cmsid
Memcached
Cf-Device-Type
Machine
Origin
Req-Svc-Chain
Producers
Cmstype
Host-ID
Datacenter
Environment
Expect-Staple
Cache-Hits
X-Cluster
User-Cache-Control
X-AWS-Id
X-LJ-Flow-ID
X-VWS-Id
CDCHOST
DSUID
CloudFront-Viewer-Country
Country-Code
Apple-News-Services-Host
X-WA-Info
X-Dispatcher-Server
X-GeoIP
X-Gen-Mode
X-Forwarded-Site
X-From
X-Device-Os
X-Hnp-Log
X-Nananana
X-Nginx-Cache-Key
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
Apple-News-Services-Handled
X-Mvc-Supplant-OutputCached
X-Cdn-Srv
X-Block-Status
Sever-Int
Server-Hostname
Server-Ext
NM-Fastcgi-Cache
X-Origin-Response-Time
X-Akamai-Device-Characteristics
Esi-Enabled
X-Datadome
X-Origin
X-PHP-Backend
X-Proxy-Cache-Status
X-Instance-Name
Wxu-Next-Commit
X-LB-NoCache
Wxu-Next-Hostname
Ssr
X-Scale
Time
Server-Info
Wxu-Next-Region
X-Section
X-Cache-Status-Check
Pics-Label
Origin-EX
X-NCache
Memory
X-Access
X-Cache-Enabled
C-Via
Origin-CC
X-Op-Id-All
AMP-Access-Control-Allow-Source-Origin
X-API-Version
Server-ID
X-Via-Fastly
X-Micro-Cache
X-TIM-N
X-Amz-Meta-Cb-Modifiedtime
NGX
X-CACHE-GROUP
X-Correlation-ID
X-B3-Spanid
X-FTR-Request-ID
X-Dc
X-HA-Backend
X-AB
X-ZONE
X-Wp-Cf-Super-Cache-Active
X-Vgn-Hpd-Reason
X-Internal-Host
X-Air-Trace-Id
X-Tb-Optimization-Total-Bytes-Saved
X-Air-Hostname
X-Air-Source
X-Platform-Cluster
X-Platform-Processor
X-Webkit-Csp-Report-Only
X-Platform-Router
X-Cs
X-Azure-Ref-OriginShield
X-Varnish-Beresp-Ttl
X-Varnish-Beresp-Grace
X-Geo-Region
X-Buckets
Location
GeoIP-Latitude
X-SIPLIST1
IsBot
Cdn-Requestid
X-Accel-Version
X-DataCenter
X-Microcachable
X-Github-Request-Id
X-Backend-Instance
X-Fpc
X-Origin-Expires
X-B3-Parentspanid
X-DC
X-Web-Node
Cache-Host
X-WP-CF-Super-Cache-Active
X-TraceId
X-Zone
XM
X-Browser-Name
X-NGINX-Cache
X-Tcp-Rtt
X-Is-Desktop
X-Is-Tablet
X-Is-Supported-Browser
X-Is-Mobile
X-Info
PFcat
YJS-ID
X-HN
X-VarnishDD-TTL
Uri
Resin-Trace
X-Pod-Name
CF-Ctrl
Sid
X-TA-CDN-Provider
X-LiteSpeed-Cache-Control
X-Ad-Defer-Variation
User-Agent
X-Cached-By
Srvid
X-NewRelic-App-Data
Locid
X-Site-Version
GeoIp-Country-Code
X-Nitro-Rev
X-Nitro-Cache-From
X-Via-Edge
X-Via-SSL
X-FL-QIT-DEBUG
X-FL-EDGE
X-Via-CDN
X-Locale
A
Edge-Copy-Time
Epwk-X-Cache
X-CS
X-CSRF-TOKEN
X-Hyper-Cache
True-Client-Ip
X-VCache
SID
True-Client-IP
X-ATG-Version
X-Cache-ASPX
X-Frame-Option
XServer
X-Contensis-Viewer-Groups
Cdn
X-Moov-T
X-Moov-Xdn-Version
X-FireWall-Port
GeoIP-Country-Code
X-Varnish-Authentication
X-MSEdge-Flight
X-MSEdge-Features
X-Service
Cache-Key
X-Webstats-RespID
X-Geo
X-TRACE-ID
X-SRV
X-VC
Path
X-FPC
X-Datacenter
X-Origin-Cache-Key
Fastly-Drupal-Html
X-Upstream-Ct
X-Upstream-Ht
NtCoent-Length
X-HostName
Tcn
LB
X-FTR-Expires
X-Country-Code-Real
X-Vercel-Cache
Cdn-Request-Time
X-LiteSpeed-Tag
Cdn-Host
X-FTR-Balancer
X-FTR-Cache-Status
State
X-FTR-Backend-Server
X-Vercel-Id
X-Planisys-CDN-Cache
X-FTR-Backend
X-Planisys-CDN-Rules
X-HS-Content-Campaign-Id
X-Planisys-CDN-TTL
X-Platform-Server
X-Edge-Server
X-APP-VERSION
Cf-Ipcountry
X-Api-Version
CountryCode
X-NMSegId
Req-ID
M-TraceId
WZWS-RAY
Cdnsip
X-AK-Request-ID
Cdncip
X-Esi
X-Release
X-Fastly-Cache
X-Air-Pt
X-Vgn-Hpd-Ssi
X-Vgn-Hpd-Variations-Key
X-Pad
X-Vgn-Hpd-Cached
X-Amz-Meta-Opti
X-Cdn-Request-ID
X-Ad-Load-Variation
X-Branch-Name
Cluster
X-Rocket-Build-Number
X-Sigma
X-Generated-In
X-Traceid
X-Cache-Remote
Lb
X-WP-CF-Super-Cache-Cookies-Bypass
X-Cache-Ttl
X-Wp-Cf-Super-Cache
X-Sigma-Backend
X-Wp-Cf-Super-Cache-Cache-Control
WebServer
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-Wp-Cf-Super-Cache-Cookies-Bypass
Pramga
X-M-Reqid
X-HS-Status
X-NWS-UUID-VERIFY
Cache
X-Request-Start
Proxy-Connection
X-M-Log
Yak-Timeinfo
X-Proxy-CacheRZ
XkeyRZ
Content-Script-Type
X-Scope-Id
Content-Style-Type
X-CACHE-KEY
X-Provided-By
CDN
X-UA
X-Qnm-Cache
X-Akamai-Pragma-Client-IP
X-GoCache-CacheStatus
X-GeoIP-City
X-Scheme
Geoip-Latitude
X-Gamma-Serve
X-Shield-Cache-Expires
X-Cdn-Forward
X-Tim-N
X-Varnish-Beresp-Status
Srv
X-Lb-Cache
Server-Id
X-Cdn-Cache-Status
Edge-Cache
CF-Cached-On
X-Cache-Date
X-RN-RSRV
X-Ha-Backend
Ohc-File-Size
X-Request-URI
X-Vc
X-TT-LOGID
X-Udemy-Cache-App-Namespace
X-User
X-CUA
X-EC-Lua
Env
Ngx
X-Render-Time
X-TH-Server
X-Lb-Nocache
X-Acquia-Application-Trace
X-Acquia-Application-UUID
X-Dw-Trace-Id
X-Via-Ucdn
Inserted-Into-Cache-At
X-Edge-POP
X-Acquia-Site
X-Acquia-Purge-Tags
PICS-Label
Yjs-Id
X-Acquia-Purge-Cdn-Unconfigured
X-Aicache-OS
Tube-Get-Contents
Tube-Got-Results
Tube-Return
X-B3-Trace-ID
Tube-Got-Eval
X-SB
X-Via-Poph
X-Via-Popn
X-Via-Popv
X-Wa
X-Servedbyhost
MIME-Version
X-Lb-Id
X-Nc
X-Req
X-Fastly-Backend-Reqs
CACHE-MISS-TO-ORIGIN
Log-Origin
X-Litespeed-Cache-Control
X-ElasticPress-Query
Kp-EeAlive
X-RAMCache
Cneonction
X-Miniprofiler-Ids
X-Cached-Since
Vha6-Origin
X-VCL-Version
Cache-Tv-Group
Click-Count-Action-Start
X-Fastly-Cache-Hits
X-CF-Cache-Header-Vary
X-Snapshot-Date
X-CF-Cache-Header-Cache-Control
Click-Count-Error