Threat Level: green Handler on Duty: Rob VandenBrink

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
X-Powered-By
Pragma
X-XSS-Protection
CF-RAY
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
Alt-Svc
P3P
X-Cache-Hits
X-UA-Compatible
X-Xss-Protection
X-Served-By
CF-Ray
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Request-Id
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
Access-Control-Allow-Credentials
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
X-Drupal-Cache
X-Generator
X-Cache-Status
X-Check
X-Cacheable
X-FRAME-OPTIONS
X-Envoy-Upstream-Service-Time
X-DNS-Prefetch-Control
X-Request-ID
Timing-Allow-Origin
X-Iinfo
X-Dns-Prefetch-Control
X-Drupal-Dynamic-Cache
Feature-Policy
X-Content-Security-Policy
X-XSS-PROTECTION
Content-Encoding
Access-Control-Expose-Headers
Upgrade
Status
X-CDN
Server-Timing
X-AspNetMvc-Version
Access-Control-Max-Age
X-Amz-Request-Id
Request-Context
X-Amz-Id-2
X-Via
X-Turbo-Charged-By
X-AH-Environment
X-Backend
X-Cache-Group
X-Robots-Tag
Cf-Edge-Cache
Keep-Alive
Host-Header
X-Hacker
X-Proxy-Cache
X-UA-Device
X-Server
X-Rq
X-Vhost
X-Server-Powered-By
Allow
X-Age
X-Varnish-Cache
X-Ws-Request-Id
X-Dispatcher
X-Amz-Version-Id
EagleId
P3p
Nel
Grace
X-LiteSpeed-Cache
Cf-Apo-Via
X-Styx-Req-Id
X-Page-Speed
X-Pantheon-Styx-Hostname
X-Device
Cf-Railgun
EagleEye-TraceId
X-Aws-Lambda-Call-Status
X-Swift-CacheTime
X-Swift-SaveTime
X-Pingback
Ali-Swift-Global-Savetime
X-Host
X-WebKit-CSP
X-Node
X-OneAgent-JS-Injection
Accept-CH
X-Server-Id
X-CST
X-Backend-Server
Surrogate-Control
X-Cache-Lookup
X-Nginx-Cache-Status
X-Readtime
Permissions-Policy
X-Akam-SW-Version
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Request-Id
X-Nginx-Upstream-Cache-Status
X-Application-Context
X-Content-Security-Policy-Report-Only
X-Cloud-Trace-Context
Accept-CH-Lifetime
X-Ua-Compatible
X-Trace
X-Response-Time
X-HW
X-Edge
Content-Location
X-Clacks-Overhead
X-Mod-Pagespeed
Accept-Ch-Lifetime
Xkey
X-Midtier
Rating
Accept-Ch
X-Amz-Server-Side-Encryption
X-Ruxit-JS-Agent
X-ECACHE
X-ESI
X-Mcache
X-Oneagent-Js-Injection
X-Url
X-Upstream
X-Ruxit-Js-Agent
X-Vcap-Request-Id
X-Litespeed-Cache
X-Country
X-D2id
Cache-Tag
X-PC
X-TtlSet
X-Vname
X-MS-InvokeApp
Verso
X-Kinja
X-Exp-Variant
X-Element-Page-Cache
X-Exp-Id
X-Cdn-Fetch
X-GoogleNews-Bot
X-Use-Magma
X-Kinja-Server
X-Kinja-Revision
X-Kinja-Build
X-Rack-Cache
Edge-Control
X-Powered-By-Plesk
X-WebKit-CSP-Report-Only
RTSS
X-Cache-TTL
Fastly-Restarts
X-Ac
X-VARITI-CCR
Origin-Trial
X-Navigation-Version
X-Abt-Application-Version
X-Country-Code
Service-Worker-Allowed
X-Goog-Hash
X-Cached
X-Ttl
Display
Pagespeed
X-Sol
X-Middleton-Display
X-GitHub-Request-Id
X-Browser-Type
X-Amz-Rid
X-Varnish-TTL
X-Content-Type
Cross-Origin-Opener-Policy
X-Dw-Request-Base-Id
SPRequestGuid
X-SharePointHealthScore
X-Mg-S
X-Server-Name
X-B3-TraceId
X-Amzn-Trace-Id
X-Middleton-Response
X-Powered-CMS
Response
X-Erf-Bev-Bev
Arr-Disable-Session-Affinity
X-Server-Lifecycle-Phase
X-Erf-Bev-Bev-Is-Generated
X-Instrumentation
X-Kraken-Loop-Name
AR-PoweredBy
AR-ATIME
AR-SID
AR-Request-ID
X-NF-Request-ID
SPIisLatency
SPRequestDuration
X-Cache-Key
X-Kinja-CCPA
X-Version
X-Times
AR-CACHE
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-HP-Trace-Id
X-HP-Webp
X-Jurisdiction
X-Accel-Expires
Pinterest-Generated-By
Pinterest-Version
X-Pinterest-Rid
X-T
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
Cache-Tags
Front-End-Https
Cache-Status
X-NWS-LOG-UUID
X-Cnection
X-Fastly-Request-ID
X-RateLimit-Remaining
X-Fastcgi-Cache
Nginx-Cache
X-MSEdge-Ref
Edge-Cache-Tag
X-Hits
X-B3-Traceid
X-Px
X-Webkit-CSP
X-Ser
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
X-RateLimit-Limit
Public-Key-Pins
X-Recruiting
Payment
X-LLID
X-Request-Processing-Time
X-Request-Received
X-Frontend
X-Ua-Browser
Server-Node
X-Client-IP
X-Erf-Stays-Pdp-Viaduct-Migration-Web
X-Shield-Request-Id
X-DIS-Request-ID
TP-Cache
X-FastCGI-Cache
S
X-Goog-Metageneration
X-GUploader-UploadID
Access-Control-Request-Method
X-HS-Content-Id
X-HS-Hub-Id
X-HS-Combine-CSS
X-HS-Cache-Config
MicrosoftSharePointTeamServices
X-Amz-Apigw-Id
X-Amzn-RequestId
X-LB-Cache
X-Protected-By
TP-L2-Cache
X-Content-Digest
X-Microsite
X-Request-Handler-Origin-Region
Content-MD5
X-Ezoic-Cdn
X-Distributor
X-FB-Debug
Realpath
X-Correlation-Id
Access-Control-Allow-Method
Accept-Charset
X-Page-Id
X-Cluster-Name
X-Geo-Country
Fastcgi-Cache
X-Rid
X-Hostname
X-Webkit-Csp
X-Forwarded-For
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-Aspnet-Version
X-Seen-By
X-B3-Sampled
X-Ua-Device
X-PressLabs-Stats
X-Server-ID
Cleartype
X-Envoy-Decorator-Operation
Referer-Policy
X-XRDS-Location
X-Client-Ip
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Mobile
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-Newrelic-App-Data
DC
TCN
Cross-Origin-Resource-Policy
X-Ratelimit-Remaining
X-Content-Options
X-Debug-Info
X-Origin-Cache
X-TTL
X-Varnish-Backend
Count-Hit
X-Varnish-Grace
X-Azure-Ref
X-Daa-Tunnel
X-Aspnetmvc-Version
X-Contextid
X-Providence-Cookie
X-Flags
X-Aspnet-Duration-Ms
X-Revision
X-Amz-Replication-Status
X-App-Environment
X-Route-Name
X-Is-Crawler
X-Request-Guid
X-Logged-In
X-IPS-LoggedIn
X-Git-Hash
X-Origin-Server
X-App-Server
X-Grace
X-Fb-Rlafr
X-Hosted-By
X-TT
Surrogate-Key
Frame-Options
X-Amz-Meta-S3cmd-Attrs
X-Ratelimit-Limit
X-Forwarded-Proto
X-Wix-Request-Id
X-Kinsta-Cache
X-RateLimit-Reset
Alternate-Protocol
X-Edge-Location-Klb
WPO-Cache-Status
WPO-Cache-Message
X-Whom
Healthy
Retry-After
Charset
X-Akamai-Edgescape
Viewport
X-F-Cache
MS-Author-Via
X-COUNTRY
X-Magnolia-Registration
Section-Io-Cache
X-Backend-Name
X-Webkit-CSP-Report-Only
X-B
Paypal-Debug-Id
SRV
X-Proxy-Cache-Info
X-Activity-Id
X-AppVersion
X-Az
X-App-Version
Amp-Access-Control-Allow-Source-Origin
ServerID
X-EdgeConnect-Cache-Status
X-N
X-Instance
X-ARC
VIX-Pulpo-Node
SD-X-WS
VIX-Pulpo-Upstream-Status
X-Http-Reason
Host
Filterid
X-Language
X-Cache-Rule
X-Response-Served-From
X-Original-Request-Id
Akamai-GRN
X-Edge-Location
X-Kong-Proxy-Latency
X-Status
X-Cache-Grace
X-Akamai-Request-ID2
X-Kong-Upstream-Latency
X-Id
X-Rule
Protected
X-UUID
X-Varnish-Age
X-Rocket-Nginx-Serving-Static
Front
From-Origin
Fastly-SWR
Fastly-SIE
X-FW-Static
X-Page-View
X-L-Path
X-Region
X-Rendered-As
X-User-Agent
X-Unique-Id
X-Jobs
X-Is-Bot
X-FW-Dynamic
X-Environment-Context
X-FW-Serve
X-FW-Server
X-FW-Version
X-FW-Type
X-Cacheable-TTL
X-FW-Hash
Server-Name
X-Cache-Control
X-Adobe-Content
X-Adobe-Loc
Access-Control-Request-Headers
Country
X-Oracle-Dms-Ecid
X-Framework
X-Varnish-Server
X-Type
X-Cache-Time
X-Www-Served-By
X-Oracle-Dms-Rid
X-Trace-Id
X-ProcessESI
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-Tumblr-Pixel
X-RemovedCookies
X-Proxy
X-G
X-Tumblr-User
X-Datadog-Sampling-Priority
X-Datadog-Trace-Id
X-Datadog-Parent-Id
X-Load-Cache
Refresh
X-DataDome
X-Vcache
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Cache-Age
X-ECache
X-Mg-Request-UUID
X-CDN-Forward
X-Time
X-Datadog-Sampled
X-Source
X-URL
X-Amzn-Remapped-Content-Length
X-Debug-IsConnected
X-Debug-IsPreview
X-Drupal-Cache-Tags
Version
X-Erf-Web-Scheduler
Accept-Language
Xet-Cookie
Content-Disposition
X-Signature
X-B-Cache
X-HTML-Minification-Powered-By
X-ID
Backend
X-Generated-By
X-WP-CF-Super-Cache-Cache-Control
CF-IPCountry
X-WP-CF-Super-Cache
X-DynaTrace-JS-Agent
Countrycode
X-DynaTrace
X-Upgrade-Enabled
X-Httpd
X-Servername
X-Nginx-Cache
X-Mode
Webserver
X-Varnish-Ttl
X-Tt-Trace-Host
Url
X-Tt-Trace-Tag
Xserver
X-Content-Age
GEO-INFO
X-Tb
X-LAGOON
X-NYM-Debug-Backend
X-GeoCountry
X-GeoCode
X-SaId
X-SayCDN-TTL
X-JoinUs
X-Git-Commit
X-Director
X-UPSTREAM-Address
Filters
X-XRDS-LOCATION
Fastcgi-Useragent
Azure-Version
X-Cache-Action
Load-Balancing
Locale
S-Rt
X-Template
Onion-Location
Meta-Geo
X-Rewrite-Enabled
X-Say-TTL
Azure-SlotName
X-Urbn-Context-Path
Azure-SiteName
X-Say-Cacheable
X-Urbn-Site-Id
X-Cache-Operation
X-Storage
X-Container-Uri
Azure-RegionName
Azure-InstanceId
X-Varnish-Cache-Hits
Uber-Trace-Id
X-Forwarded-Host
X-Device-Type
X-Cluster-Node
X-Labrador-Cache-Channel
X-Proto
X-B3-SpanId
X-Soup
X-RM-Cache-TTL
X-Tt-Logid
X-Xrds-Location
X-Varnish-Hostname
X-VC-Cache
X-ServerID
X-MCACHE
X-PHP-Host
CDN-RequestId
X-Cache-Server
X-Sucuri-Cache
X-Adobe-Source
X-Sucuri-ID
Web-Mar-Node
OT-Force-Account-Verify
X-Content-Powered-By
X-Detected-As
X-Sql-Duration-Ms
X-Served-From
X-Ms-Version
X-Ms-Request-Id
X-Logging-Id
X-Sql-Count
X-VCT
X-Generation-Time
TWC-GeoIP-LatLong
X-Zen-Fury
Webcakes-App-Name
TWC-GeoIP-Country
X-Zipkin-Id
X-LSADC-Cache
TWC-Device-Class
Mn-Server-Ip
Webcakes-Region
Node
TWC-Locale-Group
TWC-Privacy
TWC-Connection-Speed
Webcakes-App-Version
X-RCS-CacheZone
Property-Id
X-Routing-Service
X-FB-TRIP-ID
DB-Nickname
X-Skip-Cache
X-Origin-Hint
X-Lambda-Id
X-Debug
X-Extlb
X-Proxied
X-Drupal-Cache-Contexts
X-Format
X-Proxy-Build
X-Uri
X-Fetched-On
X-Tumblr-Pixel-3
X-Tumblr-Pixel-2
Selected-Fe
Liferay-Portal
X-R9-Blue-Green-Version
X-Timing-Wait
X-Loop
X-Tncms
Source
X-Rn-Rsrv
X-Endurance-Cache-Level
X-Fastly-Request-Id
X-Nf-Request-Id
X-Hcs-Proxy-Type
X-MP-GENERATED-AT
X-CCDN-CacheTTL
X-Cache-Hit
X-CCDN-Origin-Time
X-Redis-Cache
X-Tec-Api-Root
Cross-Origin-Window-Policy
X-Tec-Api-Origin
X-Origin-Date
X-Tec-Api-Version
Fastly-Drupal-HTML
X-Varnish-Hits
X-TimeS
X-Ua
X-CACHE-AGE
X-Srv
X-Pass-Why
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
Section-Io-Id
Section-Io-Origin-Status
X-Cache-Expired-At
X-Presslabs-Stats
Content-Secure-Policy
X-UA-Device-Type
X-Real-IP
Upgrade-Insecure-Requests
X-Cache-TTL-Remaining
X-S
X-Node-Name
X-Origin-CC
X-Akamai-Transformed
X-Origin-TTL
X-Newrelic-Synthetics
CDN-RequestPullCode
X-Server-W
X-TIME
CDN-RequestPullSuccess
CDN-RequestCountryCode
CDN-EdgeStorageId
CDN-CachedAt
X-Ratelimit-Reset
X-GEO
CDN-PullZone
CDN-Cache
CDN-Uid
X-Pubstack
X-Via-JSL
X-Hl-Ver
Cache-Provider
MS-CV
Ms-Operation-Id
X-AIR-PT
Cache-Hits
X-RTag
X-Cache-Host
X-Parent-Response-Time
X-Conf
X-Date
Candidate-Md5Url
X-Debug-Cache-Fetch
CPC-Age
X-D
DCR-Decision-By
X-CF-Lambda-Fn
Fastly-Backend-Name
X-CF-Lambda-Version
X-Cms-Context
X-Handled-By
DCR-Processing-Time-Ms
CPC-Cache
X-Gdpr
X-Dispatcher-Number
X-Developer
X-Destination
X-Ec-GeoHdr
BehaviorPad-Version
X-Ec-Fail
X-Ec-Custom-Error
Fastly-GeoIP-CountryCode
Apigw-Requestid
X-GeoIP-Country-Code
X-GeoIP-Region-Code
X-Debug-Cache-Store
X-Forwarded-Path
X-Fastly-Backend
X-Epic-Correlation-Id
X-External-Request-Id
X-Has-Esi
L
Server-Host
X-A-Dcw
X-A-Dam
X-A-Ccd
X-A-Dgt
X-A-Wwc
X-Accel-Expires-Debug
Redirect-Candidate
X-Accel-Buffering
Rendered-Blocks
X-A
Web-Mar-Region
T-Server
VNS-Age
Vix-Hermes-Req-Id
True-Client-Country-4JS
Surrogated-Key
VNS-Cache
We-Hiring
Sslversion
W
X-Aed
X-App
X-JWT-State
X-Bl-Debug
Lang
X-BCube-Filmed-By
X-Cache-Bucket
X-Cache-Info
Gannett-Cam-Experience-Id
X-Cdn-Diag
X-Cache-Type
X-Cache-NE
Magicmarker
Mail-Subject
Ngx.Var.Host
X-B-Cookie
Odigeo-Trace-Id
X-Application
NGB
N-Cache
MD5-Digest
X-Bc-Bl
Meta-Geo-Continent
Fastly-SSL
X-Is-Gdpr
X-RateLimit-Remaining-Second
X-Wix-Viewer-Type
Xc-Version
X-Optimistic-Header
X-Nyt-Route
X-Shop-Environment
X-SRCache-Key
X-Reqid
X-Orig-Expires
X-ScT
X-Slack-Backend
X-Wikidot-Static-Cache
X-Datadome
X-Wikidot-Backend
X-RateLimit-Limit-Second
X-Origin-Time
X-Slack-Shared-Secret-Outcome
X-Viewer-Country
X-Worker
X-Vtex-Remote-Cache
X-Var-Ttl
X-Tenant
X-Rojux
X-S-Cookie
X-Vdms-Version
X-Vdms-Path
Cache-Name
X-We-Are-Hiring
X-Restarts
X-Xfnlog-Site
X-Request-Host
X-Tx-Id
X-VG-WebCache
X-SD-PageType
WP-Super-Cache
X-CSRF-Token
X-ShardId
X-Bip
X-Cache-Id
X-Cache-Debug
X-Server-IP
X-Sn-Servicetimems
X-Up
X-Thinkindot-L3
X-Thanos
X-Test
X-Variation
X-Varnish-CookieHashed-On
X-WADP-Cache
X-Varnishpool
X-Varnish-Remaining-TTL
X-Varnish-CookieINHashed-On
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-App-Name
X-Auto-Login
X-BBC-Edge-Cache-Status
X-Shopify-Stage
X-Sorting-Hat-PodId
X-ApacheServer
X-Storefront-Renderer-Rendered
X-Sorting-Hat-ShopId
X-Alternate-Cache-Key
X-ShopId
X-Request-Time
X-NGENIX-Cache
X-Fmm-Version
X-Mvc-Supplant-OutputCached
X-Generated-On
X-Geo-Header
X-FC-Vary-Parameters
X-Nitro-Cache
X-Old-Content-Length
X-Esi-Check
X-Eu-Site
X-Node-Id
X-Mvc-Supplant-Cachable
X-Mly-Id
X-IPLB-Instance
X-IPLB-Request-ID
X-VG-TLSProxy
X-Loc
X-INCAP-ABP
X-Human
X-Gzip
X-Mid
X-Hash
X-Vmg-Version
Thinkindot-Control
X-Org
X-Refresh
X-CMSURLCustom
X-Qloud-Router
X-Core-Mission
X-Clientip
X-Clara-WADP
X-VServer
X-Cdn-Origin
X-Level-Front-Cache
X-CGP
X-Core-Value
X-Csrf-Jwt
X-DefHash
X-Owner
X-Origin-Response-Time
X-DPWN-IS-SECURE
X-DefElseHash
X-PAYTM-SRV-ID
Origin-Agent-Cluster
X-Pool
X-Policy
X-PERF
X-S-Maxage
X-CacheTTL
Platform
ServedBy
Is-Eu
Hostname
Producers
Memcached
Release
Cf-Device-Type
Canary
L5d-Success-Class
Machine
AKAMAI
Adler-Geo
Environment
Origin
Host-ID
Req-Svc-Chain
Thinkindot-CacheControl
TDXMobile
HA-Ipaddr
X-PHP-Backend
Thinkindot-CacheControl-Type
Gh-Request-Id
Cmsid
Ha-Gx-Prefs
Cmstype
Expect-Staple
Datacenter
User-Cache-Control
X-Device-Os
X-Dispatcher-Server
X-Cluster
CDCHOST
CloudFront-Viewer-Country
Country-Code
DSUID
X-Forwarded-Site
X-ProxyCache-Key
X-Platform
X-Origin
X-No-Session
X-Scale
X-VWS-Id
X-Vcl-Version
X-NodeID
X-WA-Info
X-Nginx-Cache-Key
X-Nananana
X-From
Apple-News-Services-Handled
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
X-Gen-Mode
X-GeoIP
X-LJ-Flow-ID
X-Irp-Debug
X-Hnp-Log
Apple-News-Services-Request-Url
X-ProxyCache-Status
X-Akamai-Device-Characteristics
NM-Fastcgi-Cache
Server-Ext
X-Block-Status
Sever-Int
X-AWS-Id
Server-Hostname
Esi-Enabled
X-BYPASS-REASON
X-Cdn-Srv
X-Access
X-Instance-Name
Origin-EX
Pics-Label
X-NCache
X-LB-NoCache
C-Via
X-Op-Id-All
Wxu-Next-Commit
X-Section
X-TIM-N
Ssr
Wxu-Next-Hostname
Wxu-Next-Region
Server-Info
Origin-CC
X-Cache-Enabled
X-Proxy-Cache-Status
X-API-Version
AMP-Access-Control-Allow-Source-Origin
Memory
Time
X-Amz-Meta-Cb-Modifiedtime
X-Via-Fastly
Server-ID
X-CACHE-GROUP
X-Tb-Optimization-Total-Bytes-Saved
X-HA-Backend
NGX
X-Micro-Cache
X-Cache-Status-Check
X-Wp-Cf-Super-Cache-Active
X-Internal-Host
X-Air-Source
X-Azure-Ref-OriginShield
X-Air-Trace-Id
X-Air-Hostname
X-Cs
X-Dc
X-Webkit-Csp-Report-Only
X-B3-Spanid
X-AB
X-Vgn-Hpd-Reason
X-Platform-Cluster
X-ZONE
X-Platform-Router
X-Platform-Processor
GeoIP-Latitude
X-DC
X-Web-Node
X-Origin-Expires
X-FTR-Request-ID
X-Varnish-Beresp-Ttl
Cache-Host
X-Varnish-Beresp-Grace
X-Microcachable
X-Buckets
X-Geo-Region
X-Zone
X-Correlation-ID
Location
XM
X-Fpc
X-Github-Request-Id
X-B3-Parentspanid
X-DataCenter
IsBot
X-SIPLIST1
X-Accel-Version
X-VarnishDD-TTL
PFcat
X-HN
X-Backend-Instance
X-Pod-Name
Cdn-Requestid
X-TraceId
X-WP-CF-Super-Cache-Active
X-Ad-Defer-Variation
User-Agent
Resin-Trace
X-Info
Uri
X-LiteSpeed-Cache-Control
X-TA-CDN-Provider
Sid
Edge-Copy-Time
X-Site-Version
X-Cached-By
Srvid
A
X-Via-SSL
X-Tcp-Rtt
X-Is-Tablet
X-Is-Supported-Browser
Locid
X-FL-EDGE
YJS-ID
X-FL-QIT-DEBUG
X-Is-Mobile
X-Locale
X-Via-Edge
X-Via-CDN
X-Is-Desktop
X-Browser-Name
CF-Ctrl
X-NGINX-Cache
GeoIp-Country-Code
X-Nitro-Rev
X-Nitro-Cache-From
X-Esi
True-Client-Ip
X-ATG-Version
X-CS
X-CSRF-TOKEN
X-FireWall-Port
X-Moov-T
X-Moov-Xdn-Version
X-Contensis-Viewer-Groups
X-Cache-ASPX
SID
X-VCache
True-Client-IP
GeoIP-Country-Code
XServer
Epwk-X-Cache
X-Hyper-Cache
X-Varnish-Authentication
Cdn
Cache-Key
X-NewRelic-App-Data
X-MSEdge-Flight
X-MSEdge-Features
X-Geo
X-Upstream-Ct
X-Upstream-Ht
X-Frame-Option
X-Service
X-TRACE-ID
X-SRV
X-Webstats-RespID
X-Platform-Server
State
Fastly-Drupal-Html
X-Planisys-CDN-Rules
X-Datacenter
Path
NtCoent-Length
X-HS-Content-Campaign-Id
X-Planisys-CDN-TTL
X-FPC
X-Planisys-CDN-Cache
Tcn
X-HostName
X-Fastly-Cache
X-Vgn-Hpd-Variations-Key
X-Vgn-Hpd-Ssi
X-Vgn-Hpd-Cached
X-VC
X-Release
X-LiteSpeed-Tag
Cf-Ipcountry
X-Api-Version
X-Origin-Cache-Key
X-APP-VERSION
WebServer
CountryCode
X-Generated-In
X-Rocket-Build-Number
X-Sigma
X-Sigma-Backend
LB
X-Vercel-Cache
X-Vercel-Id
X-Cache-Remote
X-Edge-Server
Lb
Cdncip
Cdnsip
X-AK-Request-ID
X-Air-Pt
Cdn-Host
X-Amz-Meta-Opti
Cdn-Request-Time
X-Pad
X-FTR-Backend-Server
X-FTR-Expires
X-FTR-Balancer
X-FTR-Backend
X-Country-Code-Real
X-FTR-Cache-Status
X-UA
Req-ID
Cache
X-Provided-By
X-NMSegId
X-Branch-Name
X-Cache-Ttl
M-TraceId
X-Wp-Cf-Super-Cache-Cache-Control
X-HS-Status
X-Wp-Cf-Super-Cache
WZWS-RAY
X-Traceid
X-Cdn-Request-ID
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
Cluster
X-Akamai-Pragma-Client-IP
X-Proxy-CacheRZ
Yak-Timeinfo
X-Gamma-Serve
XkeyRZ
X-Scheme
X-Ad-Load-Variation
Proxy-Connection
X-GeoIP-City
X-GoCache-CacheStatus
CDN
X-RN-RSRV
X-CACHE-KEY
X-WP-CF-Super-Cache-Cookies-Bypass
X-M-Log
X-M-Reqid
Geoip-Latitude
Content-Script-Type
X-Cdn-Cache-Status
Content-Style-Type
X-NWS-UUID-VERIFY
X-Vc
Pramga
Srv
X-Request-Start
X-Cdn-Forward
X-Scope-Id
X-Lb-Cache
X-Shield-Cache-Expires
Ohc-File-Size
Ngx
Env
CF-Cached-On
X-Tim-N
X-Ha-Backend
X-Qnm-Cache
Server-Id
X-TT-LOGID
Serverid
X-Lb-Nocache
X-VCL-Version
X-Request-URI
X-EC-Lua
X-Varnish-Beresp-Status
Edge-Cache
X-Cache-Date
X-Via-Ucdn
Kp-EeAlive
PICS-Label
X-Edge-POP
X-Acquia-Application-UUID
X-Acquia-Application-Trace
X-Dw-Trace-Id
X-Acquia-Purge-Tags
X-Acquia-Site
Yjs-Id
X-CF-Cache-Header-Cache-Control
X-Edge-Pop
X-Iauth-Set-Uid
X-CUA
X-TH-Server
X-Udemy-Cache-App-Namespace
X-User
X-Serial
X-Render-Time
X-Check-Cacheable
X-Location
X-CF-Cache-Header-Vary
Inserted-Into-Cache-At
X-ElasticPress-Query
Cneonction
X-Litespeed-Cache-Control
Log-Origin
X-RAMCache
X-Miniprofiler-Ids
X-Cached-Since
Vha6-Origin
X-Mobile-URL
CACHE-MISS-TO-ORIGIN
X-Fastly-Cache-Hits
X-Snapshot-Date
Cache-Tv-Group
X-MiniProfiler-Ids