Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-Cache-Status
Link
Accept-Ranges
CF-RAY
ETag
X-XSS-Protection
Expect-CT
Pragma
X-Powered-By
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
Alt-Svc
X-Served-By
X-Xss-Protection
X-Download-Options
X-Timer
X-Request-Id
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Cache-Status
X-Check
X-Generator
X-Cacheable
Timing-Allow-Origin
X-Content-Security-Policy
X-Iinfo
Feature-Policy
Status
X-Envoy-Upstream-Service-Time
Content-Encoding
Access-Control-Expose-Headers
P3p
X-Drupal-Dynamic-Cache
X-CDN
X-Request-ID
X-AspNetMvc-Version
Upgrade
X-Via
CF-Ray
X-Ws-Request-Id
Access-Control-Max-Age
Server-Timing
EagleId
X-Cache-Group
X-Turbo-Charged-By
Keep-Alive
Request-Context
Report-To
X-UA-Device
X-Age
X-Backend
X-Server-Powered-By
X-Proxy-Cache
X-AH-Environment
X-Robots-Tag
X-Hacker
X-Amz-Request-Id
X-Server
Host-Header
X-Amz-Id-2
Grace
X-LiteSpeed-Cache
X-Rq
X-Swift-CacheTime
X-Nginx-Cache-Status
X-Swift-SaveTime
X-Varnish-Cache
Ali-Swift-Global-Savetime
X-WebKit-CSP
X-Page-Speed
NEL
X-Vhost
EagleEye-TraceId
X-Ua-Compatible
X-Amz-Version-Id
X-Dns-Prefetch-Control
X-Pingback
X-OneAgent-JS-Injection
X-Dispatcher
X-Device
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Cache-Spec
X-Host
Accept-CH
X-Server-Id
Cf-Railgun
X-Node
X-Backend-Server
X-Readtime
Surrogate-Control
X-Akam-SW-Version
Request-Id
X-Response-Time
X-HW
Xkey
X-Application-Context
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Content-Location
Rating
Accept-CH-Lifetime
X-Country
X-Cloud-Trace-Context
X-Ruxit-JS-Agent
X-B3-TraceId
Accept-Ch-Lifetime
X-Cache-Lookup
X-Trace
X-Url
X-Ac
X-Content-Type
X-TtlSet
X-PC
X-Vname
Allow
X-Clacks-Overhead
Edge-Control
X-Mod-Pagespeed
X-Varnish-TTL
X-Server-Name
X-ESI
Fastly-Restarts
X-Aws-Lambda-Call-Status
Cache-Tag
Service-Worker-Allowed
X-FastCGI-Cache
X-VARITI-CCR
X-Rack-Cache
Verso
X-Element-Page-Cache
X-Upstream
MS-Author-Via
X-Vcap-Request-Id
X-MS-InvokeApp
X-Amz-Rid
X-GitHub-Request-Id
Public-Key-Pins
X-Dw-Request-Base-Id
X-Cached
X-Client-IP
X-Abt-Application-Version
X-D2id
X-Cnection
X-Px
RTSS
X-Cache-TTL
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-Navigation-Version
X-Exp-Variant
X-Exp-Id
X-GoogleNews-Bot
X-Cdn-Fetch
Arr-Disable-Session-Affinity
X-Kinja-Revision
X-Country-Code
X-Kinja
X-Use-Magma
X-Kinja-Server
X-Kinja-Build
Access-Control-Request-Method
X-Powered-By-Plesk
X-Goog-Hash
X-NF-Request-ID
X-Instrumentation
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Powered-CMS
AR-ATIME
AR-CACHE
AR-Request-ID
AR-PoweredBy
AR-SID
X-Origin-Cache
Display
X-Middleton-Display
X-Sol
Pagespeed
X-Version
X-Middleton-Response
Response
X-TTL
X-LLID
X-Amz-Server-Side-Encryption
X-MSEdge-Ref
X-Edge-Location-Klb
X-Kinsta-Cache
Nginx-Cache
TCN
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Edge
X-RateLimit-Remaining
MRF-Tech
X-B3-TraceId-Primal
Mrf-Cache-Status
X-Protected-By
X-T
X-Jurisdiction
X-HP-Trace-Id
X-HP-Webp
X-Forwarded-For
X-Shield-Request-Id
X-Content-Security-Policy-Report-Only
X-Id
X-Aspnetmvc-Version
X-Mg-S
Accept-Ch
S
Content-MD5
Edge-Cache-Tag
X-Ruxit-Js-Agent
X-CST
X-Language
SPRequestDuration
SPIisLatency
Fastcgi-Cache
Front-End-Https
X-Mid
Realpath
X-Request-Received
X-Recruiting
Server-Node
X-Request-Processing-Time
Pinterest-Version
X-DynaTrace
X-Pinterest-Rid
Filters
Pinterest-Generated-By
X-Frontend
Server-Name
X-Ua-Browser
X-MCACHE
X-Ab
X-Content
X-Ser
X-Cache-Key
X-Ttl
X-HS-Content-Id
X-HS-Hub-Id
X-HS-Cache-Config
X-NWS-LOG-UUID
X-Yandex-Sdch-Disable
X-HS-Combine-CSS
X-Template
X-Ezoic-Cdn
X-ECACHE
X-Correlation-Id
X-SharePointHealthScore
SPRequestGuid
X-Hits
X-Parallel-Accel
X-Tt-Trace-Tag
X-Tt-Trace-Host
MicrosoftSharePointTeamServices
X-Kong-Upstream-Latency
Cache-Tags
Alternate-Protocol
X-Kong-Proxy-Latency
Charset
X-Page-Id
Fusion-Content-Id
Fusion-Component-Id
Cleartype
Host
Fusion-Deployment-Id
Fusion-Template-Id
Fusion-Source
X-B3-Sampled
Fusion-Content-Source
X-Git-Hash
X-Www-Served-By
X-Content-Options
X-Geo-Country
X-Debug-Info
X-Hostname
X-DIS-Request-ID
X-Daa-Tunnel
X-Amzn-Trace-Id
X-Content-Digest
X-Amz-Replication-Status
X-Varnish-Age
Filterid
Cross-Origin-Opener-Policy
X-Ratelimit-Limit
X-Activity-Id
X-AppVersion
X-Az
X-FB-Debug
X-Upgrade-Enabled
X-Accel-Expires
X-VCache
X-Grace
X-N
X-F-Cache
ServerID
X-Nginx-Upstream-Cache-Status
X-Forwarded-Proto
X-Origin-Server
X-Rid
Access-Control-Allow-Method
X-Fastly-Request-Id
X-Mobile-URL
X-Route-Name
X-Providence-Cookie
X-Flags
X-Request-Guid
X-Aspnet-Duration-Ms
X-Is-Crawler
X-Type
TP-L2-Cache
TP-Cache
X-LB-Cache
X-Server-ID
X-TT
X-Whom
Viewport
X-App-Environment
X-Varnish-Grace
X-Seen-By
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
X-Goog-Generation
X-Tb
Payment
X-WebKit-CSP-Report-Only
X-FW-Server
X-FW-Static
X-FW-Type
X-FW-Hash
X-FW-Serve
X-Distributor
X-FW-Dynamic
Node
DC
X-User-Agent
Paypal-Debug-Id
X-XRDS-LOCATION
X-App-Server
X-Oneagent-Js-Injection
X-Fastly-Request-ID
X-Wix-Request-Id
Fastcgi-Useragent
Country
Accept-Charset
X-DataDome
X-Litespeed-Cache
X-Cache-Control
X-NGENIX-Cache
X-Cache-Rule
X-Fastcgi-Cache
X-Tec-Api-Version
X-Tec-Api-Origin
X-Tec-Api-Root
X-Ratelimit-Reset
X-Origin-Upstream-Status
X-Webkit-CSP
Version
X-Webkit-Csp
X-Via-JSL
X-Drupal-Cache-Tags
Referer-Policy
X-Microsite
X-Request-Handler-Origin-Region
X-Logged-In
X-Cluster-Name
X-Cache-Age
X-Buckets
X-Contextid
X-Signature
X-B-Cache
Cache-Status
X-Erf-Bev-Bev-Is-Generated
Refresh
X-Erf-Bev-Bev
X-Browser-Type
X-Original-Request-Id
X-Response-Served-From
X-Node-Name
VIX-Pulpo-Node
X-Load-Cache
X-Varnish-Backend
SD-X-WS
VIX-Pulpo-Upstream-Status
X-Mobile
X-Rendered-As
X-Page-View
X-Real-IP
X-Cache-Expired-At
X-Is-Bot
X-Vgn-Hpd-Reason
Amp-Access-Control-Allow-Source-Origin
NGB
X-Debug
X-Jobs
X-Cacheable-TTL
X-B
Access-Control-Request-Headers
X-Proxy-Cache-Status
X-Revision
X-IPLB-Instance
X-Device-Type
X-Cache-Action
X-Instance
X-Rule
X-UUID
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Proxy
X-RemovedCookies
X-ProcessESI
X-Drupal-Cache-Contexts
Surrogate-Key
Akamai-GRN
X-Debug-IsPreview
X-Cache-Time
X-Debug-IsConnected
X-Framework
X-FW-Version
X-G
X-Air-Source
X-Air-Hostname
SID
X-Air-Trace-Id
X-XRDS-Location
X-Oracle-Dms-Ecid
X-Oracle-Dms-Rid
CF-IPCountry
X-Accel-Buffering
DynaTrace
X-PressLabs-Stats
X-Azure-Ref
X-Nginx-Cache
X-Cache-NGX
GEO-INFO
Liferay-Portal
Count-Hit
X-Source
X-Ms-Request-Id
Uber-Trace-Id
X-Presslabs-Stats
X-Ms-Version
X-Cache-Operation
Frame-Options
X-APP-VERSION
X-Zen-Fury
X-EdgeConnect-Cache-Status
Ms-Operation-Id
MS-CV
X-RTag
X-CDN-Forward
X-TEC-API-VERSION
Healthy
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-RateLimit-Limit
Protected
X-Cache-Hit
Xserver
X-Mode
Countrycode
X-L-Path
X-Backend-Name
X-Environment-Context
X-IPS-LoggedIn
X-Tumblr-User
X-Varnish-Server
X-Tumblr-Pixel
X-Tumblr-Pixel-1
Cross-Origin-Window-Policy
X-Tumblr-Pixel-0
Ec-Rule-Version
X-Cache-TTL-Remaining
X-Ratelimit-Remaining
LB
Backend
X-Hyper-Cache
X-SaId
X-Tid
X-UPSTREAM-Address
X-Rewrite-Enabled
X-Region
X-Servername
Meta-Geo
X-JoinUs
X-RN-RSRV
X-Detected-As
X-Adobe-Loc
X-Adobe-Content
X-Content-Age
X-Forwarded-Host
Decoy-Debug-TTL
X-Alternate-Cache-Key
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
Eomportal-Instance
X-Uri
X-Zipkin-Id
Country-Code
Decoy-Debug-Key
X-Redis-Cache
X-Proxied
X-ShopId
X-Extlb
Apigw-Requestid
X-Cache-Grace
X-ShardId
X-Sql-Duration-Ms
X-Debug-Cache
X-Cache-Server
X-Routing-Service
X-Format
X-Shopify-Stage
X-Hosted-By
Section-Io-Cache
WPO-Cache-Status
WPO-Cache-Message
X-Generation-Time
X-Sql-Count
Decoy-Debug-Status
X-Status
Content-Disposition
Cache-Name
X-Human
X-No-Session
X-PERF
X-FB-TRIP-ID
X-PHP-Backend
X-Section
X-Via-Fastly
X-Microcachable
X-NCache
X-Site-Version
X-PCL
X-OCL
Mn-Server-Ip
Fastly-SSL
X-Access
X-ApacheServer
X-ServerID
X-Origin-Date
X-Varnish-Beresp-Grace
Url
X-Content-Powered-By
TWC-Privacy
TWC-Locale-Group
X-UA-Device-Type
Webcakes-App-Version
X-Akamai-Edgescape
Webcakes-Region
Webcakes-App-Name
TWC-GeoIP-Country
CDN-Cache
CDN-CachedAt
CDN-EdgeStorageId
Property-Id
Selected-Fe
TWC-Device-Class
TWC-Connection-Speed
X-Timing-Wait
X-BYPASS-REASON
X-ProxyCache-Key
X-ProxyCache-Status
X-Pubstack
X-Proxy-Build
X-Origin-Hint
X-Trace-Id
X-NYM-Debug-Backend
X-Say-Cacheable
X-Say-TTL
X-Cache-Host
CDN-PullZone
X-Cache-Type
X-Server-W
X-Cluster-Node
X-SayCDN-TTL
X-Storage
TWC-GeoIP-LatLong
CDN-RequestId
CDN-RequestCountryCode
Cache-Tv-Group
CDN-Uid
X-Web-Node
X-Soup
X-R9-Blue-Green-Version
X-NewRelic-App-Data
X-Hl-Ver
X-Be
X-Generated-By
X-Varnishpool
Azure-Version
Azure-SlotName
Azure-SiteName
Azure-InstanceId
Content-Secure-Policy
Azure-RegionName
X-Azure-Ref-OriginShield
X-Ua
X-LSADC-Cache
DB-Nickname
X-TIME
OT-Force-Account-Verify
X-Nginx-Cache-Key
Retry-After
X-Cached-By
X-Dc
Source
X-TT-LOGID
X-Bc-Bl
X-Unique-Id
Cache
X-Cache-Remote
SRV
X-Akamai-Transformed
X-Platform-Server
X-Auto-Login
X-LAGOON
X-Xfnlog-Site
X-Cdn
HostName
Upgrade-Insecure-Requests
X-Origin-CC
X-Origin-TTL
X-GEO
X-Correlation-ID
Cache-Hits
ServedBy
X-Cache-Tags
X-Varnish-Hits
X-EC-Lua
X-Loop
X-SRV
X-TNCMS
X-App-Version
X-HTML-Minification-Powered-By
X-Varnish-Hostname
X-S-Maxage
X-CSRF-Token
Xet-Cookie
Onion-Location
X-Varnish-Cache-Hits
X-Request-Time
X-Time
From-Origin
X-AOL-HN
Mime-Version
Web-Mar-Node
WP-Super-Cache
X-Tumblr-Pixel-3
Webserver
X-Tumblr-Pixel-2
X-Request-Host
X-Amz-Meta-S3cmd-Attrs
X-ECache
N-Cache
X-Proto
X-NWS-UUID-VERIFY
X-Cache-Enabled
X-FireWall-Port
X-Endurance-Cache-Level
X-Tenant
X-VWS-Id
X-LJ-Flow-ID
X-AWS-Id
X-Handled-By
Nel
X-Origin-Response-Time
X-GG-Cache-Date
X-Time-Microsecs
Redirect-Candidate
V-Age
User-Cache-Control
Rendered-Blocks
Pramga
X-Forwarded-Path
Surrogated-Key
X-Vdms-Path
BehaviorPad-Version
Sslversion
X-External-Request-Id
X-B3-SpanId
X-VG-WebCache
X-Vdms-Version
X-Developer
X-Planisys-CDN-Cache
Expiry
X-Hnp-Log
Fastcgi-X-Cache-Version
Xc-Version
X-Orig-Expires
X-Ig-Push-State
X-ND-Cache
A
DCR-Decision-By
DCR-Processing-Time-Ms
X-NAPM-TraceId
Meta-Geo-Continent
Mobile-Detection-Method
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Gen-Mode
X-Ftr-Request-Id
Vix-Hermes-Req-Id
Odigeo-Trace-Id
X-Vtex-Remote-Cache
X-PAYTM-SRV-ID
X-Vtex-Processado-Em
X-PBS-Appsvrname
X-Processor
X-Epic-Correlation-Id
X-B-Cookie
X-Cache-Var-Map
X-Destination
X-Backend-TTL
X-Cache-Var
X-D
X-Application
X-ScT
X-ARC
X-SD-PageType
X-Edge-Location
X-Connection-Hash
X-Ckpd-Fst-Backend
X-Cluster
X-Conf
X-Cache-NE
X-Shop-Environment
X-Session-Fingerprint
X-CF-Lambda-Fn
X-Block-Status
X-Slack-Backend
X-SRCache-Key
X-S-Cookie
X-A-Dgt
X-A-Wwc
X-CF-Lambda-Version
X-A-Dam
X-A-Ccd
X-A
X-V-Cache
X-TIM-N
X-A-Dcw
X-S
X-Aed
X-Aicache-OS
X-Rojux
X-Varnish-Ttl
X-Mg-Request-UUID
X-Magnolia-Registration
X-Adobe-Source
X-RCS-CacheZone
X-Reqid
X-MP-GENERATED-AT
Cmstype
CacheControlHeader
X-LI-UUID
X-Li-Fabric
X-Li-Pop
Cmsid
CDCHOST
X-Cdn-Srv
X-Cache-Info
DSUID
X-Geo-Header
State
X-Fastly-Cache
X-Accel-Expires-Debug
X-Forwarded-Site
Svr
Wxu-Next-Region
Wxu-Next-Commit
Wxu-Next-Hostname
True-Client-Country-4JS
Origin
X-Gdpr
X-Hash
Fastcgi-Cache-TTL
X-Cache-Bucket
Gh-Request-Id
X-GeoIP-Region-Code
X-Date
X-GeoIP-Country-Code
Host-ID
X-Cache-Date
Apple-News-Services-Host
X-Rocket-Nginx-Serving-Static
X-Request-URI
CloudFront-Viewer-Country
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Scheme
X-Nyt-Route
X-VG-TLSProxy
X-Proxy-Upstream
X-Origin-Expires
X-Origin-Time
X-Origin
X-Old-Content-Length
X-Viewer-Country
X-Policy
X-NodeID
X-Server-IP
AKAMAI
X-PHP-Host
AMP-Access-Control-Allow-Source-Origin
Apple-News-Services-Handled
Apple-News-Services-Parsed-Url
Arc-Country
Apple-News-Services-Request-Url
X-Webstats-RespID
X-Location
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-Mvc-Supplant-Cachable
X-Men
X-Sucuri-Cache
X-Sucuri-ID
X-Labrador-Cache-Channel
S-Rt
X-Via-NSCOPI
Environment
X-Sigma-Backend
X-Varnish-Beresp-Status
Machine
We-Hiring
Web-Mar-Region
X-Req
X-Sigma
X-Skip-Cache
X-Cache-Debug
X-Device-Os
X-Irp-Debug
X-Envoy-Decorator-Operation
Traceparent
X-Cache-Id
X-VarnishDD-TTL
X-Developers
X-Branch-Name
Server-Info
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
X-Datadog-Trace-Id
X-BBC-Edge-Cache-Status
X-Served-From
X-Csrf-Jwt
X-HS-Content-Campaign-Id
X-Core-Value
X-Core-Mission
X-Varnish-Beresp-Ttl
X-UnsetCookies
X-TH-Server
X-Rocket-Build-Number
X-TrackingId
X-HN
Fastly-GeoIP-CountryCode
X-Backend-State
X-Region-Sid
Origin-CC
X-Platform
Fastly-Drupal-Html
Origin-EX
X-Gamma-Serve
HA-Ipaddr
X-Sn-Servicetimems
PFcat
X-VServer
L
X-GeoIP
X-GeoIP-City
Mail-Subject
Locid
L5d-Success-Class
X-Generated-On
X-Owner
X-Esi-Check
Ha-Gx-Prefs
X-Locale
Server-Host
X-CGP
X-RateLimit-Limit-Second
Ssr
X-Eu-Site
X-RateLimit-Remaining-Second
X-Gzip
X-Fastly-Backend
X-Storefront-Renderer-Rendered
Release
X-Cdn-Origin
Req-Svc-Chain
X-Fetched-On
X-Level-Front-Cache
X-Xrds-Location
X-Is-Gdpr
X-Node-Id
X-JWT-State
X-Varnish-CookieHashed-On
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-DPWN-IS-SECURE
X-Loc
X-FC-Vary-Parameters
X-Pod-Name
X-Worker
X-Qloud-Router
X-Has-Esi
X-Varnish-Remaining-TTL
X-Response-By
Magicmarker
X-Thinkindot-L3
X-Request-Start
X-Variation
X-Varnish-CookieINHashed-On
X-DefHash
X-DefElseHash
X-NU-AKA-ACS-Version
X-Amzn-Remapped-Content-Length
TDXMobile
X-Akamai-Request-ID2
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
Thinkindot-Control
X-Http-Reason
Fastly-SIE
Memcached
NM-Fastcgi-Cache
Is-Eu
Platform
Fastly-SWR
Cf-Device-Type
Adler-Geo
X-ATG-Version
X-M-Reqid
X-Qnm-Cache
X-M-Log
X-Ua-Device
X-VC-Cache
X-Restarts
NGX
X-Bip
X-Thanos
X-CS
X-Tx-Id
X-Zone
X-Mvc-Supplant-OutputCached
X-LB-ID
X-API-Version
Kp-EeAlive
X-Up
X-NC
X-Trace-ID
X-Wix-Viewer-Type
Ms-Author-Via
X-Generated-In
X-LB-NoCache
X-DSS
Edge-Cache
X-DW
X-RSL
X-RPS
X-RPM
X-Cache-Config
X-DI
X-Action
Pics-Label
X-DB
CDN
X-Cache-Backend
X-TraceId
Accept-Language
Time
Memory
X-Srv
X-Tb-Optimization-Total-Bytes-Saved
WebServer
X-Via-Poph
X-Optimistic-Header
Env
X-Refresh
X-Datadome
X-Via-Popn
X-CacheTTL
X-Minions-Version
X-Edge-Pop
X-Via-Popv
X-Tt-Logid
X-Cache-Ttl
NtCoent-Length
X-HA-Backend
Candidate-Md5Url
Datacenter
X-Urbn-Context-Path
X-CACHE-KEY
X-Urbn-Site-Id
Locale
X-DC
GeoIp-Country-Code
X-ZONE
X-DynaTrace-JS-Agent
WWW-Authenticate
X-Esi
Server-ID
On-Server
X-Servedbyhost
X-Vc
X-Unique-ID
X-User
X-MSEdge-Flight
X-Ec-Fail
X-Ec-GeoHdr
X-MSEdge-Features
Esi-Enabled
X-TX-ID
X-CLOUD-TRACE-CONTEXT
X-Parent-Response-Time
X-Cs
X-TA-CDN-Provider
X-Webkit-CSP-Report-Only
C-Via
X-Service
X-Cache-PHP
X-Varnish-Beresp-TTL
X-Newrelic-Synthetics
Cdnsip
X-LI-Proto
X-App
X-VCL-Version
X-B3-Spanid
X-Fpc
Cdncip
X-AK-Request-ID
X-Traceid
X-URL
X-Dynatrace
X-Webkit-Csp-Report-Only
X-Clara-WADP
Cluster
X-Li-Proto
My-App
X-Fmm-Version
X-WADP-Cache
Test
Proxy-Connection
Geo-Info
Tracecode
X-Vcl-Version
Cf-Int-Pingora-Origin-Digest
X-Render-Time
X-Cache-Status-Check
X-FPC
X-CUA
Geoip-Latitude
X-Var-Ttl
X-Pass-Why
X-NODE
X-LiteSpeed-Cache-Control
DataCenter
X-From
T-Server
Lfy
Fastly-Drupal-HTML
X-Mcache
Resin-Trace
X-Fragments
Lang
M-TraceId
X-VC
Target-Params
Server-Id
MIME-Version
X-CSRF-TOKEN
X-B3-Traceid
X-Geo
X-Ha-Backend
X-WP-CF-Super-Cache
X-ID
X-WP-CF-Super-Cache-Cache-Control
GeoIP-Country-Code
X-Clientip
Hostname
X-Oss-Server-Time
X-Oss-Object-Type
X-Oss-Request-Id
Hit
X-AIR-PT
X-ServedByHost
X-Oss-Storage-Class
HIT
Cache-Host
X-Info
X-Oss-Hash-Crc64ecma
X-LiteSpeed-Tag
X-RAMCache
UCS
X-Provided-By
X-Dynatrace-Js-Agent
X-Via-PopN
X-Proxy-Cache-Info
X-Pad
X-Httpd
Permissions-Policy
X-Edge-POP
Section-Origin-Responded
X-Cdn-Forward
ENV
X-Via-PopV
X-Via-PopH
S-Cnection
Section-Io-Id
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
WZWS-RAY
X-Edge-Cache
Producers
Servername
X-NGINX-Cache
Ohc-File-Size
X-Check-Cacheable
X-Api-Version
FSS-Cache
X-BBC-Origin-Response-Status
X-Fastly-Backend-Reqs
X-Ucs
X-Micro-Cache
X-HS-Status
X-SB
User-Agent
Fastly-Backend-Name
X-ElasticPress-Query
X-ServerName
X-Udemy-Cache-App-Namespace
Load-Balancing
X-Platform-Router
ServerName
X-Backend-Host
X-Nc
X-GoCache-CacheStatus
Cf-Ipcountry
PICS-Label
X-Release
X-Acquia-Application-Trace
URI
X-UP
Uri
X-Acquia-Application-UUID
X-Lb-Nocache
X-Pool
X-Platform-Processor
X-Platform-Cluster
X-Cache-CFC
X-Acquia-Purge-Tags
X-Acquia-Site
X-TRACE-ID
X-RateLimit-Reset
X-BCube-Filmed-By
Cneonction
X-Scale
EpKe-Alive
X-Swift-Error
X-Ec-Custom-Error
Server-Ttl
X-APP
X-Lb-Id
Cdn
X-Cdn-Request-ID
Tcn
X-Fastly-Cache-Hits
Cteonnt-Length
X-Dw-Trace-Id
CF-Cached-On
Sever-Int
Server-Hostname
X-B3-ParentSpanId
X-Contensis-Viewer-Groups
X-Dispatcher-Number
X-Vcache
Shield-Pop
X-Cache-Expires
X-B3-Parentspanid
Vha6-Origin
X-Cache-ASPX
Path
X-Yottaa-OS
MD5-Digest
X-Akamai-ERPolicy
X-Newrelic-App-Data
IsBot
Wpo-Cache-Status
Wpo-Cache-Message
X-Akamai-ERRuleID
Ohc-Cache-HIT
X-SIPLIST1
Server-Ext
X-Snapshot-Date
X-Air-Pt
Sid
X-HostName
X-Cache-Ngx
GeoIP-Latitude
X-Litespeed-Cache-Control
X-IN-APIGATEWAYSSL
X-IN-APIGATEWAY
X-Akamai-Request-ID
X-Via-Ucdn
X-Shopify-Generated-Cart-Token
CPC-Age
X-UA
X-CacheKey
X-WA-Info
X-Akamai-Pragma-Client-IP
X-WA
X-Varnish-Authentication
X-Apw-Access-Action
X-Apw-Hits
X-Apw-Access-Token
X-Logging-Id
X-Apw-Access-Object
Req-ID
CountryCode
X-Te-Count
X-Http-Duration-Ms
X-Te-Duration-Ms
VNS-Cache
X-Amz-Meta-Cb-Modifiedtime
X-Http-Count
VNS-Age
X-Sentry-ID
Ngx
Cache-Key
CPC-Cache
X-Last-Modified