Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
X-Powered-By
Pragma
X-XSS-Protection
X-Cache
CF-RAY
Via
Age
Content-Security-Policy
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
Alt-Svc
X-Xss-Protection
X-Cache-Hits
P3P
X-UA-Compatible
CF-Ray
X-Served-By
X-Download-Options
X-Timer
X-Request-Id
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
Access-Control-Allow-Credentials
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
X-Drupal-Cache
X-Generator
X-Cache-Status
X-Check
X-Cacheable
X-DNS-Prefetch-Control
X-FRAME-OPTIONS
X-Envoy-Upstream-Service-Time
Timing-Allow-Origin
X-Iinfo
X-Request-ID
X-Drupal-Dynamic-Cache
Feature-Policy
X-Content-Security-Policy
X-Dns-Prefetch-Control
Content-Encoding
X-XSS-PROTECTION
Access-Control-Expose-Headers
Server-Timing
Upgrade
X-CDN
Status
X-AspNetMvc-Version
P3p
Access-Control-Max-Age
X-Amz-Request-Id
Request-Context
X-Amz-Id-2
X-Via
X-Turbo-Charged-By
X-AH-Environment
X-Backend
X-Cache-Group
X-Robots-Tag
Cf-Edge-Cache
Keep-Alive
Host-Header
X-Hacker
X-Proxy-Cache
X-Server
X-Vhost
X-Rq
X-Server-Powered-By
X-UA-Device
Allow
X-Age
X-Ws-Request-Id
X-Varnish-Cache
X-Dispatcher
X-Amz-Version-Id
EagleId
Nel
X-Ua-Compatible
Grace
X-LiteSpeed-Cache
Cf-Apo-Via
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
Cf-Railgun
X-Page-Speed
X-Device
EagleEye-TraceId
X-OneAgent-JS-Injection
X-Aws-Lambda-Call-Status
X-Swift-SaveTime
X-Swift-CacheTime
X-Pingback
Ali-Swift-Global-Savetime
X-Node
X-Host
Accept-CH
X-CST
X-Backend-Server
X-WebKit-CSP
X-Cache-Lookup
X-Server-Id
Surrogate-Control
X-Nginx-Cache-Status
X-Readtime
Permissions-Policy
Accept-CH-Lifetime
X-Akam-SW-Version
X-Nginx-Upstream-Cache-Status
Request-Id
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Application-Context
X-Content-Security-Policy-Report-Only
X-Cloud-Trace-Context
X-Trace
X-Response-Time
X-HW
X-Edge
Content-Location
X-Clacks-Overhead
Xkey
X-Mod-Pagespeed
X-Ruxit-JS-Agent
Rating
X-Midtier
X-ESI
X-Url
X-Amz-Server-Side-Encryption
X-ECACHE
X-Mcache
X-Litespeed-Cache
Accept-Ch
X-Upstream
Cache-Tag
X-Vcap-Request-Id
X-MS-InvokeApp
X-D2id
X-Rack-Cache
Verso
X-GoogleNews-Bot
X-Kinja
X-Exp-Id
X-Cdn-Fetch
X-Element-Page-Cache
X-Exp-Variant
X-Use-Magma
X-Kinja-Build
X-Kinja-Server
X-Kinja-Revision
X-Powered-By-Plesk
Edge-Control
Accept-Ch-Lifetime
X-WebKit-CSP-Report-Only
X-Vname
X-TtlSet
X-PC
X-Ruxit-Js-Agent
RTSS
X-Country
X-Cache-TTL
Fastly-Restarts
X-Ac
Origin-Trial
X-VARITI-CCR
Service-Worker-Allowed
X-Navigation-Version
X-Country-Code
X-Abt-Application-Version
X-Goog-Hash
X-Varnish-TTL
X-GitHub-Request-Id
X-Aspnetmvc-Version
X-Cached
X-Oneagent-Js-Injection
X-Browser-Type
X-Amz-Rid
X-Webkit-CSP
Pagespeed
X-Middleton-Display
Display
X-Sol
Cross-Origin-Opener-Policy
X-Ttl
X-Dw-Request-Base-Id
X-SharePointHealthScore
SPRequestGuid
X-Server-Name
X-Amzn-Trace-Id
X-Mg-S
X-Kinja-CCPA
X-B3-TraceId
X-Powered-CMS
X-Content-Type
X-Kraken-Loop-Name
X-Instrumentation
Arr-Disable-Session-Affinity
X-Erf-Bev-Bev
X-Server-Lifecycle-Phase
X-Erf-Bev-Bev-Is-Generated
X-Middleton-Response
SPRequestDuration
AR-PoweredBy
AR-Request-ID
AR-SID
AR-ATIME
Response
SPIisLatency
X-NWS-LOG-UUID
X-Cache-Key
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
X-Times
X-NF-Request-ID
X-Pinterest-Rid
Pinterest-Version
Pinterest-Generated-By
X-FastCGI-Cache
X-Version
X-HP-Webp
X-Jurisdiction
X-HP-Trace-Id
X-Fastly-Request-ID
AR-CACHE
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Cnection
X-Accel-Expires
X-T
Cache-Tags
X-Ua-Device
X-Client-IP
Nginx-Cache
X-RateLimit-Remaining
Cache-Status
Front-End-Https
Edge-Cache-Tag
X-Ser
X-MSEdge-Ref
X-Hits
X-B3-Traceid
X-Px
Public-Key-Pins
X-RateLimit-Limit
X-Recruiting
Payment
Mrf-Cache-Status
X-B3-TraceId-Primal
MRF-Tech
X-LLID
X-Request-Received
X-Frontend
X-Request-Processing-Time
Server-Node
X-Ua-Browser
X-Server-ID
X-Shield-Request-Id
S
X-DIS-Request-ID
X-GUploader-UploadID
X-Goog-Metageneration
TP-Cache
Content-MD5
MicrosoftSharePointTeamServices
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Erf-Stays-Pdp-Viaduct-Migration-Web
Access-Control-Request-Method
X-Content-Digest
X-HS-Cache-Config
X-HS-Hub-Id
X-HS-Combine-CSS
X-HS-Content-Id
X-PressLabs-Stats
X-Request-Handler-Origin-Region
X-Microsite
X-Distributor
X-Protected-By
Realpath
X-LB-Cache
Fastcgi-Cache
X-Page-Id
Access-Control-Allow-Method
X-FB-Debug
Accept-Charset
X-Rid
X-Cluster-Name
TP-L2-Cache
X-Fastcgi-Cache
X-Forwarded-For
X-Geo-Country
X-Ezoic-Cdn
X-Webkit-Csp
X-Hostname
X-Aspnet-Version
X-Daa-Tunnel
X-B3-Sampled
X-TTL
X-Seen-By
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Goog-Stored-Content-Encoding
Cleartype
Referer-Policy
Cross-Origin-Resource-Policy
X-Correlation-Id
TCN
X-Ratelimit-Remaining
X-Mobile
DC
Count-Hit
X-Content-Options
X-Envoy-Decorator-Operation
X-Varnish-Backend
X-Logged-In
X-Newrelic-App-Data
X-App-Server
X-COUNTRY
X-Debug-Info
X-Hosted-By
X-Origin-Cache
X-Contextid
X-Varnish-Grace
X-App-Environment
X-Fb-Rlafr
Surrogate-Key
X-Route-Name
X-Flags
X-Amz-Replication-Status
X-Aspnet-Duration-Ms
X-Providence-Cookie
X-Request-Guid
X-IPS-LoggedIn
X-Is-Crawler
X-Grace
X-Git-Hash
X-Edge-Location-Klb
X-Revision
X-Kinsta-Cache
X-Azure-Ref
Frame-Options
X-TT
X-Amz-Meta-S3cmd-Attrs
X-Ratelimit-Limit
X-Forwarded-Proto
X-TEC-API-VERSION
X-Origin-Server
X-RateLimit-Reset
X-TEC-API-ROOT
X-TEC-API-ORIGIN
Retry-After
X-F-Cache
X-Wix-Request-Id
X-XRDS-Location
WPO-Cache-Message
WPO-Cache-Status
Alternate-Protocol
X-Whom
X-Id
Healthy
X-Magnolia-Registration
Section-Io-Cache
Charset
X-Client-Ip
X-Akamai-Edgescape
Viewport
X-Backend-Name
MS-Author-Via
X-Proxy-Cache-Info
X-App-Version
Paypal-Debug-Id
X-B
SRV
X-AppVersion
X-Activity-Id
X-Az
Amp-Access-Control-Allow-Source-Origin
X-Webkit-CSP-Report-Only
ServerID
X-Language
X-Www-Served-By
X-N
Akamai-GRN
SD-X-WS
X-Cache-Rule
Host
X-ARC
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-DataDome
X-Instance
X-Response-Served-From
X-Http-Reason
X-Original-Request-Id
X-Varnish-Age
X-UUID
X-User-Agent
X-Varnish-Server
Front
Protected
Filterid
X-Rocket-Nginx-Serving-Static
Country
X-Rule
X-Akamai-Request-ID2
X-Cache-Grace
X-Edge-Location
X-Status
X-Datadog-Trace-Id
From-Origin
X-Cacheable-TTL
X-Datadog-Sampling-Priority
X-L-Path
X-Datadog-Parent-Id
X-Environment-Context
X-Page-View
X-Framework
X-Rendered-As
Fastly-SWR
X-Region
X-Jobs
X-FW-Static
X-FW-Type
X-FW-Version
X-FW-Serve
X-FW-Hash
Fastly-SIE
X-FW-Dynamic
X-EdgeConnect-Cache-Status
X-FW-Server
X-Unique-Id
X-Is-Bot
Access-Control-Request-Headers
X-Cache-Time
X-Tumblr-Pixel-1
X-Adobe-Loc
X-Adobe-Content
X-Kong-Upstream-Latency
X-Tumblr-User
X-Tumblr-Pixel-0
Server-Name
X-Kong-Proxy-Latency
X-Type
X-Tumblr-Pixel
X-Load-Cache
X-G
X-Trace-Id
X-RemovedCookies
X-ProcessESI
X-Proxy
X-Xrds-Location
X-Yottaa-Optimizations
X-Vcache
X-Cache-Control
X-Yottaa-Metrics
X-Datadog-Sampled
X-Mg-Request-UUID
X-ECache
X-Amzn-Remapped-Content-Length
Refresh
X-Debug-IsConnected
X-Debug-IsPreview
X-CDN-Forward
X-B-Cache
X-Tec-Api-Root
X-Tec-Api-Origin
Content-Disposition
X-Time
X-Signature
X-Tec-Api-Version
X-Cache-Age
X-Drupal-Cache-Tags
X-Source
X-WP-CF-Super-Cache-Cache-Control
Backend
X-WP-CF-Super-Cache
X-Erf-Web-Scheduler
Accept-Language
Xet-Cookie
Countrycode
Webserver
X-DynaTrace
X-Generated-By
CF-IPCountry
X-HTML-Minification-Powered-By
Version
X-DynaTrace-JS-Agent
X-Httpd
X-Servername
Url
X-Mode
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Oracle-Dms-Ecid
X-Nf-Request-Id
Xserver
X-Storage
X-Oracle-Dms-Rid
GEO-INFO
X-Template
X-Nginx-Cache
X-Device-Type
X-NYM-Debug-Backend
X-Content-Age
X-Content-Powered-By
X-ServerID
X-Urbn-Context-Path
Locale
Azure-InstanceId
X-Director
X-Cache-Action
X-Cache-Operation
Azure-RegionName
Azure-SiteName
X-GeoCode
Azure-SlotName
OT-Force-Account-Verify
X-UPSTREAM-Address
X-GeoCountry
X-Tb
X-Say-Cacheable
X-Say-TTL
X-Upgrade-Enabled
Filters
S-Rt
X-SaId
Meta-Geo
X-Proto
X-Rewrite-Enabled
Onion-Location
X-Urbn-Site-Id
X-SayCDN-TTL
X-Varnish-Cache-Hits
X-XRDS-LOCATION
Load-Balancing
X-JoinUs
X-LAGOON
X-URL
Azure-Version
X-Container-Uri
X-Cluster-Node
Uber-Trace-Id
X-Soup
X-Labrador-Cache-Channel
X-PHP-Host
X-Git-Commit
X-Generation-Time
X-Varnish-Hostname
X-RM-Cache-TTL
X-MCACHE
X-Forwarded-Host
X-VC-Cache
X-Ms-Request-Id
Web-Mar-Node
X-Tt-Logid
X-Served-From
X-LSADC-Cache
X-Ms-Version
X-Adobe-Source
X-Sql-Count
X-Sql-Duration-Ms
X-Cache-Server
X-Detected-As
X-VCT
TWC-GeoIP-Country
X-Rn-Rsrv
Node
TWC-Connection-Speed
Mn-Server-Ip
Property-Id
TWC-Device-Class
X-Skip-Cache
X-Routing-Service
X-Lambda-Id
X-Zipkin-Id
X-Zen-Fury
X-RCS-CacheZone
X-R9-Blue-Green-Version
X-Logging-Id
X-Origin-Hint
X-Proxied
X-Format
X-FB-TRIP-ID
Webcakes-App-Version
Webcakes-App-Name
TWC-Privacy
Webcakes-Region
X-Debug
X-Tumblr-Pixel-3
X-Extlb
X-Tumblr-Pixel-2
TWC-Locale-Group
TWC-GeoIP-LatLong
DB-Nickname
X-Uri
X-Loop
X-Timing-Wait
X-Fetched-On
X-Proxy-Build
X-Tncms
X-Sucuri-Cache
Fastcgi-Useragent
Selected-Fe
X-CCDN-Origin-Time
X-Hcs-Proxy-Type
X-B3-SpanId
X-CCDN-CacheTTL
X-Cache-Hit
X-Sucuri-ID
X-ID
Source
X-Drupal-Cache-Contexts
X-Endurance-Cache-Level
X-Ua
Cross-Origin-Window-Policy
X-Redis-Cache
CDN-RequestId
Liferay-Portal
X-Srv
X-Origin-Date
X-MP-GENERATED-AT
X-TimeS
Section-Io-Origin-Time-Seconds
X-CACHE-AGE
Section-Origin-Responded
Section-Io-Origin-Status
Section-Io-Id
Fastly-Drupal-HTML
X-Varnish-Hits
X-Pass-Why
X-S
X-Cache-Expired-At
X-Akamai-Transformed
Upgrade-Insecure-Requests
X-Real-IP
X-Origin-TTL
X-Newrelic-Synthetics
X-Origin-CC
X-Fastly-Request-Id
X-UA-Device-Type
X-Ratelimit-Reset
X-Cache-TTL-Remaining
X-NGENIX-Cache
Content-Secure-Policy
X-Node-Name
X-Pubstack
X-TIME
X-Handled-By
X-GEO
X-Hl-Ver
X-Via-JSL
NGB
X-Varnish-Ttl
CDN-Uid
CDN-PullZone
CDN-CachedAt
CDN-Cache
CDN-EdgeStorageId
CDN-RequestCountryCode
CDN-RequestPullCode
CDN-RequestPullSuccess
X-Server-W
X-Xfnlog-Site
X-IPLB-Instance
X-Cms-Context
X-Cache-Type
X-Parent-Response-Time
Apigw-Requestid
X-IPLB-Request-ID
MS-CV
X-Reqid
X-RTag
X-Optimistic-Header
Ms-Operation-Id
X-Restarts
X-Vcl-Version
WP-Super-Cache
ServedBy
X-Accel-Expires-Debug
BehaviorPad-Version
X-Csrf-Jwt
X-D
X-Dispatcher-Number
X-A-Dgt
X-A-Dcw
Candidate-Md5Url
Canary
X-Date
X-A-Wwc
X-Conf
X-Destination
X-Tx-Id
X-Var-Ttl
X-App
X-Aed
X-CGP
X-Debug-Cache-Store
X-ProxyCache-Status
X-Developer
X-Vdms-Path
X-ProxyCache-Key
X-BYPASS-REASON
X-No-Session
X-Debug-Cache-Fetch
X-CF-Lambda-Version
N-Cache
Meta-Geo-Continent
X-CacheTTL
True-Client-Country-4JS
Ngx.Var.Host
X-SRCache-Key
MD5-Digest
X-Vdms-Version
Vix-Hermes-Req-Id
Mail-Subject
X-B-Cookie
X-Bc-Bl
T-Server
Redirect-Candidate
X-Tenant
Rendered-Blocks
Sslversion
Server-Host
X-BCube-Filmed-By
X-Cache-Host
Odigeo-Trace-Id
Surrogated-Key
Origin-Agent-Cluster
X-Cache-NE
Magicmarker
X-Cdn-Diag
Fastly-Backend-Name
X-A-Ccd
Fastly-GeoIP-CountryCode
X-A
X-Application
X-CF-Lambda-Fn
X-Bl-Debug
CPC-Cache
X-A-Dam
DCR-Decision-By
DCR-Processing-Time-Ms
Web-Mar-Region
We-Hiring
L5d-Success-Class
W
VNS-Cache
VNS-Age
Lang
L
HA-Ipaddr
Fastly-SSL
Gannett-Cam-Experience-Id
Gh-Request-Id
Ha-Gx-Prefs
CPC-Age
X-Ec-Fail
X-We-Are-Hiring
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-Worker
X-Gdpr
X-Slack-Backend
X-Slack-Shared-Secret-Outcome
X-Forwarded-Path
X-Viewer-Country
X-Vtex-Remote-Cache
X-Shop-Environment
X-SD-PageType
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Rojux
X-Request-Host
X-S-Cookie
X-ScT
X-Nyt-Route
X-Orig-Expires
X-Origin-Time
X-FC-Vary-Parameters
Xc-Version
X-Eu-Site
X-Ec-Custom-Error
X-Ec-GeoHdr
X-External-Request-Id
X-Epic-Correlation-Id
X-Fastly-Backend
Cache-Provider
X-CSRF-Token
X-Node-Id
Release
Producers
X-NodeID
X-Nitro-Cache
X-Cache-Debug
X-SVT-ORM-RULES
X-AIR-PT
X-Cache-Bucket
X-Varnish-Remaining-TTL
Platform
Req-Svc-Chain
X-Test
X-Server-IP
X-Storefront-Renderer-Rendered
X-ShardId
Memcached
X-Mid
X-Mly-Id
X-Varnish-CookieINHashed-On
X-Thanos
X-Cache-Info
X-Loc
X-Bip
X-Mvc-Supplant-Cachable
Origin
X-Cache-Id
TDXMobile
X-App-Name
X-Pool
X-Policy
X-VG-WebCache
X-Platform
X-Qloud-Router
X-VG-TLSProxy
Cache-Name
X-ApacheServer
X-DPWN-IS-SECURE
X-Accel-Buffering
X-Refresh
X-S-Maxage
X-Alternate-Cache-Key
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
X-Sn-Servicetimems
X-SVT-ORM-VERSION
X-Org
Thinkindot-Control
X-Varnishpool
X-PAYTM-SRV-ID
X-PERF
X-Auto-Login
X-Owner
X-BBC-Edge-Cache-Status
X-Old-Content-Length
X-Level-Front-Cache
X-CMSURLCustom
X-Clientip
X-AWS-Id
X-Sorting-Hat-ShopId
X-Up
Cf-Device-Type
Cmsid
Datacenter
X-ShopId
X-GeoIP-Region-Code
X-GeoIP-Country-Code
Cmstype
X-Core-Mission
X-Geo-Header
X-VServer
X-VWS-Id
X-Vmg-Version
X-DefElseHash
X-LJ-Flow-ID
X-Cluster
X-Esi-Check
X-Core-Value
X-Generated-On
AKAMAI
Adler-Geo
X-Gzip
X-Shopify-Stage
X-Human
X-INCAP-ABP
Host-ID
X-Sorting-Hat-PodId
X-DefHash
X-Variation
X-Varnish-CookieHashed-On
Is-Eu
X-Cdn-Origin
X-Hash
X-Wix-Viewer-Type
Machine
X-Irp-Debug
X-Thinkindot-L3
X-Request-Time
X-Correlation-ID
Expect-Staple
Environment
User-Cache-Control
Hostname
X-Is-Gdpr
X-From
X-Fmm-Version
X-Device-Os
X-Forwarded-Site
X-Cdn-Srv
X-Origin
X-Clara-WADP
X-JWT-State
X-Has-Esi
X-Block-Status
X-Origin-Response-Time
X-Nginx-Cache-Key
X-Hnp-Log
X-Dispatcher-Server
X-Mvc-Supplant-OutputCached
X-GeoIP
X-Gen-Mode
Esi-Enabled
Country-Code
CloudFront-Viewer-Country
CDCHOST
DSUID
X-Nananana
Server-Ext
NM-Fastcgi-Cache
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
X-WADP-Cache
X-WA-Info
X-Akamai-Device-Characteristics
X-Proxy-Cache-Status
Apple-News-Services-Handled
Apple-News-Services-Host
X-Datadome
Server-Hostname
X-FTR-Request-ID
Sever-Int
X-Cache-Status-Check
Wxu-Next-Hostname
Wxu-Next-Commit
X-Op-Id-All
X-Instance-Name
X-LB-NoCache
X-Presslabs-Stats
X-Amz-Meta-Cb-Modifiedtime
X-Micro-Cache
Cache-Hits
X-Access
Time
Wxu-Next-Region
C-Via
Ssr
Memory
Server-Info
Pics-Label
X-Cache-Enabled
X-Section
NGX
X-NCache
AMP-Access-Control-Allow-Source-Origin
X-API-Version
Origin-EX
X-PHP-Backend
X-Dc
X-AB
X-Via-Fastly
Origin-CC
X-CACHE-GROUP
Server-ID
X-Scale
X-B3-Spanid
X-Vgn-Hpd-Reason
X-TIM-N
X-HA-Backend
X-Geo-Region
X-Tb-Optimization-Total-Bytes-Saved
X-Wp-Cf-Super-Cache-Active
Location
X-Buckets
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Ttl
X-Accel-Version
X-Platform-Processor
X-Air-Source
X-Air-Trace-Id
X-Internal-Host
Cdn-Requestid
X-Webkit-Csp-Report-Only
X-ZONE
X-Platform-Router
X-Platform-Cluster
X-Air-Hostname
X-Cs
X-TraceId
X-Azure-Ref-OriginShield
X-SIPLIST1
IsBot
X-Zone
X-Is-Supported-Browser
X-Is-Tablet
X-Tcp-Rtt
X-B3-Parentspanid
X-Backend-Instance
GeoIP-Latitude
X-Is-Mobile
X-Browser-Name
X-WP-CF-Super-Cache-Active
X-Is-Desktop
X-Fpc
Cache-Host
CF-Ctrl
Resin-Trace
X-Origin-Expires
YJS-ID
X-Microcachable
Sid
X-DataCenter
X-DC
X-NGINX-Cache
X-Web-Node
XM
X-Cached-By
Uri
X-Info
X-TA-CDN-Provider
X-NewRelic-App-Data
X-LiteSpeed-Cache-Control
X-HN
X-Pod-Name
X-VarnishDD-TTL
PFcat
X-HOST
X-Nitro-Cache-From
X-Nitro-Rev
User-Agent
Epwk-X-Cache
X-Ad-Defer-Variation
X-Hyper-Cache
GeoIp-Country-Code
X-Frame-Option
X-Via-Edge
X-Via-CDN
X-Site-Version
True-Client-Ip
Edge-Copy-Time
X-FL-EDGE
X-FL-QIT-DEBUG
X-Via-SSL
X-CSRF-TOKEN
A
Srvid
X-Locale
Locid
X-VCache
X-Webstats-RespID
True-Client-IP
XServer
X-Service
X-Github-Request-Id
GeoIP-Country-Code
Cdn
X-CS
SID
X-Varnish-Authentication
X-ATG-Version
X-Cache-ASPX
X-Moov-Xdn-Version
X-Moov-T
X-FireWall-Port
X-VC
X-Contensis-Viewer-Groups
X-Origin-Cache-Key
X-Geo
X-Datacenter
X-SRV
LB
Cache-Key
X-TRACE-ID
X-MSEdge-Features
X-MSEdge-Flight
X-FTR-Backend-Server
X-FTR-Backend
X-Country-Code-Real
X-FTR-Expires
X-FTR-Balancer
X-FTR-Cache-Status
X-Pad
X-Vercel-Cache
Path
Fastly-Drupal-Html
Cdn-Request-Time
X-Edge-Server
Cdn-Host
NtCoent-Length
X-Vercel-Id
X-FPC
X-HostName
Tcn
X-LiteSpeed-Tag
X-NMSegId
Req-ID
M-TraceId
WZWS-RAY
X-Api-Version
X-Upstream-Ht
X-Cdn-Request-ID
CountryCode
Cf-Ipcountry
X-APP-VERSION
X-Upstream-Ct
X-Amz-Meta-Opti
X-Ad-Load-Variation
Cluster
Cdnsip
X-Air-Pt
Cdncip
X-Esi
X-AK-Request-ID
X-Planisys-CDN-TTL
X-Platform-Server
X-Planisys-CDN-Rules
X-HS-Content-Campaign-Id
State
X-WP-CF-Super-Cache-Cookies-Bypass
X-Planisys-CDN-Cache
Content-Script-Type
X-Scope-Id
X-NWS-UUID-VERIFY
X-Vgn-Hpd-Variations-Key
X-M-Reqid
X-M-Log
X-Wp-Cf-Super-Cache-Cache-Control
X-Wp-Cf-Super-Cache
X-Fastly-Cache
Content-Style-Type
WebServer
Pramga
X-Cache-Ttl
X-Request-Start
X-Vgn-Hpd-Cached
X-Branch-Name
X-Release
X-Vgn-Hpd-Ssi
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-Rocket-Build-Number
X-Varnish-Beresp-Status
X-Proxy-CacheRZ
X-Shield-Cache-Expires
X-Qnm-Cache
X-Cache-Remote
X-Sigma
X-Sigma-Backend
XkeyRZ
Yak-Timeinfo
X-Generated-In
Lb
X-Traceid
Proxy-Connection
X-Rebelmouse-Cache-Control
CDN
X-Rebelmouse-Surrogate-Control
X-CACHE-KEY
Cache
X-Cdn-Forward
Geoip-Latitude
Edge-Cache
X-HS-Status
X-Akamai-Pragma-Client-IP
X-Tim-N
X-Cache-Date
Ohc-File-Size
X-Request-URI
Srv
X-Lb-Cache
X-Provided-By
X-Dw-Trace-Id
CF-Cached-On
X-GeoIP-City
X-Scheme
Server-Id
X-GoCache-CacheStatus
X-Gamma-Serve
X-Render-Time
X-User
X-Ha-Backend
X-TH-Server
X-UA
X-TT-LOGID
X-CUA
Click-Count-Error
Click-Count-Action-Start
Cache-Tv-Group
Tube-Get-Contents
V-Age
X-V-Cache
X-Servedbyhost
X-SB
X-Via-Poph
X-Via-Popn
X-Wa
X-Via-Popv
X-Req
X-Nc
Tube-Return
Tube-Got-Results
X-Acquia-Purge-Cdn-Unconfigured
X-Aicache-OS
X-Cache-FS-Status
X-B3-Trace-ID
Tube-Got-Eval
X-EC-Lua
X-Acquia-Site
X-Lb-Nocache
X-Cdn-Cache-Status
X-Acquia-Purge-Tags
X-Acquia-Application-UUID
X-Via-Ucdn
X-Acquia-Application-Trace
X-Vc
PICS-Label
Yjs-Id
X-RN-RSRV
HostName
Inserted-Into-Cache-At
X-Fastly-Cache-Hits
Ngx
Env
Log-Origin
X-Snapshot-Date
Ohc-Cache-HIT
X-Men
X-Sucuri-Id
X-Lb-Id
On-Server
X-CF-Cache-Header-Cache-Control
MIME-Version
X-Edge-POP
X-ElasticPress-Query
X-RAMCache
X-Miniprofiler-Ids
Cneonction
X-Udemy-Cache-App-Namespace
Vha6-Origin
CACHE-MISS-TO-ORIGIN
X-Cached-Since
X-LB-ID
X-Fastly-Backend-Reqs
X-Litespeed-Cache-Control
X-CF-Cache-Header-Vary