Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
X-Powered-By
Pragma
X-XSS-Protection
X-Cache
CF-RAY
Via
Age
Content-Security-Policy
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
Alt-Svc
X-Xss-Protection
X-Cache-Hits
P3P
X-UA-Compatible
CF-Ray
X-Served-By
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
Access-Control-Allow-Credentials
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
X-Drupal-Cache
X-Generator
X-Cache-Status
X-Check
X-Cacheable
X-DNS-Prefetch-Control
X-FRAME-OPTIONS
X-Envoy-Upstream-Service-Time
Timing-Allow-Origin
X-Iinfo
X-Drupal-Dynamic-Cache
Feature-Policy
X-Content-Security-Policy
X-Dns-Prefetch-Control
X-XSS-PROTECTION
Content-Encoding
Access-Control-Expose-Headers
Server-Timing
Upgrade
X-CDN
Status
X-Request-ID
X-AspNetMvc-Version
Access-Control-Max-Age
X-Amz-Request-Id
Request-Context
X-Amz-Id-2
P3p
X-Via
X-Turbo-Charged-By
X-AH-Environment
X-Backend
X-Cache-Group
X-Robots-Tag
Cf-Edge-Cache
Keep-Alive
Host-Header
X-Hacker
X-Proxy-Cache
X-UA-Device
X-Server
X-Vhost
X-Rq
X-Server-Powered-By
Allow
X-Age
X-Ws-Request-Id
X-Varnish-Cache
X-Dispatcher
X-Amz-Version-Id
EagleId
Nel
Grace
X-Ua-Compatible
X-LiteSpeed-Cache
Cf-Apo-Via
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
Cf-Railgun
X-Page-Speed
X-Device
EagleEye-TraceId
X-OneAgent-JS-Injection
X-Aws-Lambda-Call-Status
X-Swift-CacheTime
X-Swift-SaveTime
X-Pingback
Ali-Swift-Global-Savetime
X-Host
X-Node
Accept-CH
X-Backend-Server
X-CST
X-WebKit-CSP
X-Server-Id
Surrogate-Control
X-Cache-Lookup
X-Nginx-Cache-Status
X-Readtime
Permissions-Policy
Accept-CH-Lifetime
X-Akam-SW-Version
X-Nginx-Upstream-Cache-Status
Request-Id
X-EdgeConnect-Origin-MEX-Latency
X-Application-Context
X-EdgeConnect-MidMile-RTT
X-Content-Security-Policy-Report-Only
X-Cloud-Trace-Context
X-Trace
X-Response-Time
X-HW
X-Edge
Content-Location
X-Clacks-Overhead
Xkey
X-Mod-Pagespeed
Rating
X-Midtier
X-ESI
X-Ruxit-JS-Agent
X-Url
X-Amz-Server-Side-Encryption
X-ECACHE
X-Ruxit-Js-Agent
X-Mcache
X-Litespeed-Cache
Accept-Ch
X-Upstream
Cache-Tag
X-Vcap-Request-Id
X-Country
X-D2id
X-Rack-Cache
X-MS-InvokeApp
X-Element-Page-Cache
X-Use-Magma
X-Kinja-Server
X-Cdn-Fetch
X-Exp-Id
X-Kinja-Build
X-Kinja-Revision
X-Exp-Variant
X-Kinja
X-GoogleNews-Bot
X-Powered-By-Plesk
Verso
Edge-Control
Accept-Ch-Lifetime
X-PC
X-WebKit-CSP-Report-Only
X-TtlSet
X-Vname
RTSS
X-Cache-TTL
Fastly-Restarts
X-Ac
Origin-Trial
X-VARITI-CCR
X-Navigation-Version
Service-Worker-Allowed
X-Country-Code
X-Abt-Application-Version
X-Goog-Hash
X-Varnish-TTL
X-Cached
X-Aspnetmvc-Version
X-GitHub-Request-Id
X-Oneagent-Js-Injection
X-Browser-Type
X-Webkit-CSP
Display
Pagespeed
X-Sol
X-Middleton-Display
X-Amz-Rid
Cross-Origin-Opener-Policy
X-Ttl
X-Dw-Request-Base-Id
SPRequestGuid
X-Server-Name
X-SharePointHealthScore
X-Amzn-Trace-Id
X-Mg-S
X-Kinja-CCPA
X-ORACLE-DMS-RID
X-Powered-CMS
X-ORACLE-DMS-ECID
X-Content-Type
X-Instrumentation
X-Erf-Bev-Bev-Is-Generated
X-Kraken-Loop-Name
X-Erf-Bev-Bev
X-Server-Lifecycle-Phase
AR-SID
AR-ATIME
AR-PoweredBy
AR-Request-ID
Arr-Disable-Session-Affinity
Response
X-Middleton-Response
SPIisLatency
SPRequestDuration
X-Cache-Key
X-NWS-LOG-UUID
X-B3-TraceId
X-Times
X-NF-Request-ID
Pinterest-Version
X-Pinterest-Rid
Pinterest-Generated-By
X-Version
X-Jurisdiction
X-HP-Trace-Id
X-SRCache-Store-Status
X-HP-Webp
AR-CACHE
X-SRCache-Fetch-Status
X-Fastly-Request-ID
Cache-Tags
X-Accel-Expires
X-T
X-Cnection
X-B3-Traceid
Nginx-Cache
X-RateLimit-Remaining
X-FastCGI-Cache
Front-End-Https
Cache-Status
Edge-Cache-Tag
X-Ser
X-MSEdge-Ref
X-Hits
X-Client-IP
X-Px
Public-Key-Pins
X-RateLimit-Limit
X-Recruiting
X-B3-TraceId-Primal
Mrf-Cache-Status
MRF-Tech
Payment
X-LLID
X-Request-Processing-Time
X-Request-Received
X-Frontend
Server-Node
X-Ua-Browser
X-Server-ID
X-Shield-Request-Id
S
X-DIS-Request-ID
X-Fastcgi-Cache
X-GUploader-UploadID
X-Goog-Metageneration
TP-Cache
X-Erf-Stays-Pdp-Viaduct-Migration-Web
X-Amzn-RequestId
MicrosoftSharePointTeamServices
X-Amz-Apigw-Id
Access-Control-Request-Method
Content-MD5
X-Content-Digest
X-HS-Cache-Config
X-HS-Content-Id
X-HS-Combine-CSS
X-HS-Hub-Id
X-PressLabs-Stats
X-Microsite
X-Request-Handler-Origin-Region
X-Distributor
X-LB-Cache
X-Page-Id
Fastcgi-Cache
X-Protected-By
Realpath
X-FB-Debug
Access-Control-Allow-Method
Accept-Charset
X-Rid
X-Cluster-Name
X-Geo-Country
TP-L2-Cache
X-Ezoic-Cdn
X-Webkit-Csp
X-Hostname
X-Aspnet-Version
X-Ua-Device
X-B3-Sampled
X-TTL
X-Forwarded-For
X-Daa-Tunnel
X-Seen-By
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
Cleartype
Cross-Origin-Resource-Policy
Referer-Policy
X-Correlation-Id
X-Ratelimit-Remaining
TCN
DC
X-Mobile
Count-Hit
X-Content-Options
X-Envoy-Decorator-Operation
X-Varnish-Backend
X-Newrelic-App-Data
X-Debug-Info
X-Origin-Cache
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-Hosted-By
X-TEC-API-ROOT
X-Logged-In
X-Varnish-Grace
X-App-Server
X-Fb-Rlafr
X-App-Environment
X-Flags
Surrogate-Key
X-Aspnet-Duration-Ms
X-Contextid
X-Request-Guid
X-Providence-Cookie
X-Route-Name
X-IPS-LoggedIn
X-Is-Crawler
X-Git-Hash
X-Grace
X-Revision
X-Kinsta-Cache
X-Amz-Replication-Status
X-Edge-Location-Klb
X-Client-Ip
X-Azure-Ref
Frame-Options
X-Amz-Meta-S3cmd-Attrs
X-TT
X-Ratelimit-Limit
X-Origin-Server
X-Forwarded-Proto
X-RateLimit-Reset
Retry-After
X-F-Cache
X-Wix-Request-Id
X-XRDS-Location
Alternate-Protocol
X-Whom
WPO-Cache-Status
WPO-Cache-Message
Healthy
X-Magnolia-Registration
Charset
Section-Io-Cache
X-Id
X-Akamai-Edgescape
X-Backend-Name
X-COUNTRY
Viewport
MS-Author-Via
X-App-Version
X-Proxy-Cache-Info
X-B
Paypal-Debug-Id
SRV
X-Activity-Id
Amp-Access-Control-Allow-Source-Origin
X-AppVersion
X-Az
X-Webkit-CSP-Report-Only
ServerID
X-N
X-Language
X-ARC
X-Instance
X-Original-Request-Id
VIX-Pulpo-Upstream-Status
X-Response-Served-From
Akamai-GRN
X-DataDome
Host
X-Cache-Rule
SD-X-WS
VIX-Pulpo-Node
X-Www-Served-By
Front
X-Edge-Location
Protected
X-Cache-Grace
X-Akamai-Request-ID2
X-Http-Reason
X-Varnish-Server
X-Rocket-Nginx-Serving-Static
X-User-Agent
Filterid
X-Varnish-Age
Country
X-Status
X-Rule
X-Cacheable-TTL
X-Environment-Context
Fastly-SWR
Fastly-SIE
X-FW-Dynamic
From-Origin
X-EdgeConnect-Cache-Status
X-FW-Type
X-Region
X-Page-View
X-Rendered-As
X-Unique-Id
X-UUID
X-L-Path
X-Jobs
X-FW-Server
X-FW-Serve
X-FW-Static
X-FW-Version
X-Is-Bot
X-FW-Hash
X-Framework
X-Kong-Proxy-Latency
X-Tumblr-Pixel
X-Kong-Upstream-Latency
X-Cache-Time
X-Adobe-Content
X-Adobe-Loc
X-Datadog-Trace-Id
X-Load-Cache
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-Tumblr-User
X-Type
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
Server-Name
Access-Control-Request-Headers
X-RemovedCookies
X-G
X-ProcessESI
X-Trace-Id
X-Proxy
X-Vcache
X-Xrds-Location
X-Cache-Control
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Mg-Request-UUID
X-ECache
X-Datadog-Sampled
X-Amzn-Remapped-Content-Length
X-Debug-IsPreview
X-Debug-IsConnected
X-CDN-Forward
X-Signature
Refresh
Content-Disposition
X-B-Cache
X-Time
X-Cache-Age
X-Source
Backend
X-Drupal-Cache-Tags
X-Erf-Web-Scheduler
Accept-Language
X-DynaTrace
Xet-Cookie
Webserver
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
X-Generated-By
CF-IPCountry
X-HTML-Minification-Powered-By
Version
X-DynaTrace-JS-Agent
Countrycode
X-Servername
X-Nginx-Cache
X-Tec-Api-Version
X-Tec-Api-Origin
X-Httpd
X-Tec-Api-Root
Url
X-Mode
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Nf-Request-Id
Xserver
X-NYM-Debug-Backend
X-Storage
X-Content-Powered-By
GEO-INFO
X-Content-Age
X-Device-Type
X-Template
X-URL
X-Director
X-Say-TTL
X-Varnish-Cache-Hits
Azure-Version
Load-Balancing
X-Cache-Operation
Locale
S-Rt
Onion-Location
Meta-Geo
X-Cache-Action
Azure-SlotName
Azure-SiteName
Azure-RegionName
Azure-InstanceId
OT-Force-Account-Verify
X-Rewrite-Enabled
X-Upgrade-Enabled
X-Say-Cacheable
X-XRDS-LOCATION
X-GeoCountry
X-SaId
X-UPSTREAM-Address
X-ServerID
X-SayCDN-TTL
X-GeoCode
X-Urbn-Context-Path
Filters
X-JoinUs
X-Proto
X-LAGOON
X-Urbn-Site-Id
X-Container-Uri
X-MCACHE
X-Labrador-Cache-Channel
X-Cluster-Node
Uber-Trace-Id
X-Generation-Time
X-Varnish-Hostname
X-RM-Cache-TTL
X-PHP-Host
X-Soup
X-VC-Cache
X-Forwarded-Host
X-Tb
X-Git-Commit
Web-Mar-Node
X-Sql-Duration-Ms
X-Sql-Count
X-LSADC-Cache
X-Adobe-Source
X-Tt-Logid
X-Ms-Version
X-Ms-Request-Id
X-Cache-Server
X-Detected-As
X-Origin-Hint
X-R9-Blue-Green-Version
X-Routing-Service
Node
X-Extlb
X-Format
X-Lambda-Id
X-Zipkin-Id
X-VCT
Mn-Server-Ip
Property-Id
X-Proxied
X-FB-TRIP-ID
X-Skip-Cache
TWC-Privacy
X-Served-From
X-Tumblr-Pixel-2
X-Tumblr-Pixel-3
Webcakes-App-Version
Webcakes-App-Name
TWC-Locale-Group
X-RCS-CacheZone
TWC-Device-Class
TWC-Connection-Speed
X-Rn-Rsrv
X-Debug
TWC-GeoIP-LatLong
Webcakes-Region
TWC-GeoIP-Country
DB-Nickname
X-Uri
X-Zen-Fury
X-Fetched-On
X-Logging-Id
X-Sucuri-Cache
X-Tncms
X-Loop
Fastcgi-Useragent
X-B3-SpanId
X-Cache-Hit
X-Sucuri-ID
X-Hcs-Proxy-Type
X-Endurance-Cache-Level
X-CCDN-Origin-Time
X-ID
X-Ua
X-Drupal-Cache-Contexts
X-CCDN-CacheTTL
X-Timing-Wait
Selected-Fe
X-Proxy-Build
Cross-Origin-Window-Policy
X-Oracle-Dms-Ecid
Source
X-Redis-Cache
X-Oracle-Dms-Rid
CDN-RequestId
X-Origin-Date
X-Srv
Liferay-Portal
X-MP-GENERATED-AT
X-TimeS
Fastly-Drupal-HTML
X-CACHE-AGE
Section-Origin-Responded
Section-Io-Id
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
X-Varnish-Hits
X-Pass-Why
X-Cache-Expired-At
X-Akamai-Transformed
X-S
Upgrade-Insecure-Requests
X-Origin-CC
X-Newrelic-Synthetics
X-Origin-TTL
X-Real-IP
X-Ratelimit-Reset
X-Cache-TTL-Remaining
X-UA-Device-Type
X-Fastly-Request-Id
X-Node-Name
Content-Secure-Policy
X-TIME
X-GEO
X-Handled-By
X-Pubstack
NGB
X-Varnish-Ttl
X-NGENIX-Cache
CDN-EdgeStorageId
CDN-CachedAt
CDN-Cache
CDN-PullZone
CDN-RequestCountryCode
CDN-Uid
CDN-RequestPullSuccess
X-Server-W
CDN-RequestPullCode
X-Via-JSL
MS-CV
Ms-Operation-Id
X-Parent-Response-Time
X-IPLB-Request-ID
X-IPLB-Instance
Apigw-Requestid
X-Cache-Type
X-Reqid
X-Cms-Context
X-Restarts
X-Xfnlog-Site
X-Hl-Ver
X-RTag
X-Vcl-Version
WP-Super-Cache
ServedBy
X-Epic-Correlation-Id
Candidate-Md5Url
X-Worker
X-Ec-Custom-Error
X-Dispatcher-Number
X-Developer
Canary
X-Eu-Site
X-Ec-Fail
X-Ec-GeoHdr
X-External-Request-Id
X-Aed
X-A-Wwc
X-Wikidot-Static-Cache
X-Accel-Expires-Debug
X-Gdpr
X-A-Dgt
X-Fastly-Backend
X-FC-Vary-Parameters
X-Forwarded-Path
Xc-Version
X-Bl-Debug
X-D
X-CacheTTL
X-ProxyCache-Key
X-No-Session
X-Cdn-Diag
X-B-Cookie
X-ProxyCache-Status
X-Tx-Id
X-BCube-Filmed-By
X-Cache-Host
X-Bc-Bl
X-Cache-NE
X-BYPASS-REASON
X-CF-Lambda-Fn
X-Date
X-A-Dam
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-App
X-Csrf-Jwt
X-Application
X-CF-Lambda-Version
X-CGP
BehaviorPad-Version
X-Conf
X-Destination
X-A-Dcw
Surrogated-Key
T-Server
Meta-Geo-Continent
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
N-Cache
MD5-Digest
Mail-Subject
L5d-Success-Class
X-Wikidot-Backend
Lang
Magicmarker
X-Tenant
X-SRCache-Key
Sslversion
X-Slack-Backend
X-Slack-Shared-Secret-Outcome
X-ScT
X-SD-PageType
X-Shop-Environment
Redirect-Candidate
Origin-Agent-Cluster
X-S-Cookie
Server-Host
Ngx.Var.Host
Odigeo-Trace-Id
X-Rojux
Rendered-Blocks
HA-Ipaddr
L
W
We-Hiring
Ha-Gx-Prefs
Fastly-GeoIP-CountryCode
X-Vdms-Path
X-Vdms-Version
Web-Mar-Region
X-A
X-A-Ccd
X-We-Are-Hiring
X-Vtex-Remote-Cache
DCR-Decision-By
X-Viewer-Country
DCR-Processing-Time-Ms
Fastly-SSL
Fastly-Backend-Name
X-Nyt-Route
X-Origin-Time
Gh-Request-Id
X-Orig-Expires
True-Client-Country-4JS
Vix-Hermes-Req-Id
Gannett-Cam-Experience-Id
X-Optimistic-Header
Cache-Provider
X-CSRF-Token
X-Accel-Buffering
X-BBC-Edge-Cache-Status
Thinkindot-CacheControl-Type
Producers
Thinkindot-Control
Req-Svc-Chain
VNS-Cache
VNS-Age
X-Auto-Login
X-ApacheServer
TDXMobile
X-Alternate-Cache-Key
Thinkindot-CacheControl
X-DefElseHash
X-Var-Ttl
X-Variation
X-PERF
X-Up
X-Test
X-Thinkindot-L3
X-PAYTM-SRV-ID
X-Varnish-CookieHashed-On
X-Varnish-Remaining-TTL
X-NodeID
X-Varnish-CookieINHashed-On
X-Old-Content-Length
X-Owner
X-Org
X-Platform
X-Policy
X-Sorting-Hat-PodId
X-Request-Time
X-Sn-Servicetimems
X-S-Maxage
X-Shopify-Stage
X-ShardId
X-Request-Host
X-Refresh
X-SVT-ORM-VERSION
X-Pool
X-Qloud-Router
X-SVT-ORM-RULES
X-Sorting-Hat-ShopId
X-Storefront-Renderer-Rendered
X-Nitro-Cache
X-Mvc-Supplant-Cachable
X-DPWN-IS-SECURE
X-DefHash
X-Esi-Check
X-Generated-On
X-GeoIP-Country-Code
X-Geo-Header
X-ShopId
X-Core-Value
X-Cache-Id
X-Cache-Debug
X-Cache-Info
X-Cdn-Origin
X-Core-Mission
X-CMSURLCustom
X-Wix-Viewer-Type
X-GeoIP-Region-Code
X-Irp-Debug
X-VG-WebCache
X-Level-Front-Cache
X-Loc
X-VG-TLSProxy
X-Mly-Id
X-Vmg-Version
X-VServer
X-Hash
X-Gzip
X-Human
X-INCAP-ABP
Platform
X-Cache-Bucket
X-App-Name
Cf-Device-Type
AKAMAI
Expect-Staple
Is-Eu
Adler-Geo
Memcached
Machine
Environment
X-AIR-PT
Cmsid
X-Correlation-ID
Cmstype
CPC-Age
Datacenter
CPC-Cache
X-VWS-Id
Host-ID
X-AWS-Id
X-Cluster
X-LJ-Flow-ID
Origin
Hostname
User-Cache-Control
X-Origin-Response-Time
X-Clientip
X-Hnp-Log
X-GeoIP
X-Has-Esi
X-Dispatcher-Server
X-Is-Gdpr
X-Akamai-Device-Characteristics
X-Datadome
X-Device-Os
X-Gen-Mode
CDCHOST
Apple-News-Services-Parsed-Url
X-Cdn-Srv
X-From
X-Server-IP
X-Proxy-Cache-Status
X-Fmm-Version
X-Block-Status
X-Bip
X-FTR-Request-ID
X-Clara-WADP
X-WADP-Cache
Apple-News-Services-Host
Apple-News-Services-Handled
Apple-News-Services-Request-Url
CloudFront-Viewer-Country
X-Thanos
X-Nananana
X-Mid
X-Mvc-Supplant-OutputCached
NM-Fastcgi-Cache
Cache-Name
Sever-Int
X-Varnishpool
X-JWT-State
Server-Hostname
Esi-Enabled
Server-Ext
Country-Code
X-Nginx-Cache-Key
X-Node-Id
Release
X-Cache-Status-Check
Server-Info
Pics-Label
X-NCache
X-Op-Id-All
X-Presslabs-Stats
X-Section
X-WA-Info
X-Origin
Memory
Wxu-Next-Region
Wxu-Next-Hostname
C-Via
DSUID
X-Instance-Name
X-Access
X-Amz-Meta-Cb-Modifiedtime
Wxu-Next-Commit
X-LB-NoCache
X-Cache-Enabled
Ssr
X-Micro-Cache
X-Forwarded-Site
Time
NGX
Cache-Hits
X-API-Version
AMP-Access-Control-Allow-Source-Origin
Origin-CC
X-Scale
Server-ID
X-PHP-Backend
X-Dc
Origin-EX
X-Via-Fastly
X-CACHE-GROUP
X-AB
X-B3-Spanid
X-TIM-N
X-HA-Backend
X-Vgn-Hpd-Reason
X-Tb-Optimization-Total-Bytes-Saved
X-Wp-Cf-Super-Cache-Active
X-Geo-Region
X-Varnish-Beresp-Ttl
X-Varnish-Beresp-Grace
Location
X-Platform-Processor
X-Air-Source
X-Internal-Host
X-Platform-Router
X-Air-Hostname
X-Platform-Cluster
X-Webkit-Csp-Report-Only
X-ZONE
X-Air-Trace-Id
Cdn-Requestid
X-Accel-Version
X-Cs
X-Buckets
X-SIPLIST1
IsBot
X-Azure-Ref-OriginShield
X-TraceId
GeoIP-Latitude
X-Backend-Instance
X-B3-Parentspanid
X-Fpc
X-Is-Mobile
X-Is-Supported-Browser
X-Is-Tablet
X-WP-CF-Super-Cache-Active
X-Tcp-Rtt
X-Is-Desktop
X-Browser-Name
X-Zone
CF-Ctrl
X-DataCenter
X-Microcachable
YJS-ID
X-Origin-Expires
Cache-Host
Sid
Resin-Trace
X-DC
X-Web-Node
XM
Uri
X-Cached-By
X-Info
X-TA-CDN-Provider
PFcat
X-Pod-Name
X-NewRelic-App-Data
X-HN
X-VarnishDD-TTL
X-LiteSpeed-Cache-Control
GeoIp-Country-Code
User-Agent
X-Nitro-Cache-From
X-Hyper-Cache
X-Nitro-Rev
X-Ad-Defer-Variation
X-NGINX-Cache
X-Frame-Option
X-Via-Edge
X-Site-Version
X-Via-CDN
X-Via-SSL
X-FL-EDGE
Locid
Srvid
X-FL-QIT-DEBUG
Epwk-X-Cache
True-Client-Ip
X-Locale
Edge-Copy-Time
X-CSRF-TOKEN
A
X-VCache
X-CS
Cdn
True-Client-IP
GeoIP-Country-Code
XServer
X-Service
X-Github-Request-Id
SID
X-Varnish-Authentication
X-Cache-ASPX
X-ATG-Version
X-Moov-Xdn-Version
X-Contensis-Viewer-Groups
X-Moov-T
X-FireWall-Port
X-VC
X-Webstats-RespID
X-Origin-Cache-Key
X-Geo
X-Datacenter
X-MSEdge-Flight
LB
X-MSEdge-Features
X-SRV
Cache-Key
X-TRACE-ID
X-FTR-Expires
X-FTR-Backend
X-Country-Code-Real
X-FTR-Backend-Server
X-FTR-Balancer
X-FTR-Cache-Status
Path
X-Pad
CountryCode
Fastly-Drupal-Html
X-Edge-Server
X-FPC
X-Vercel-Cache
X-Vercel-Id
Cdn-Request-Time
Cdn-Host
X-HostName
Tcn
X-LiteSpeed-Tag
X-NMSegId
NtCoent-Length
M-TraceId
WZWS-RAY
Cf-Ipcountry
X-Upstream-Ct
X-Api-Version
X-APP-VERSION
X-Upstream-Ht
X-HS-Content-Campaign-Id
X-Esi
X-Planisys-CDN-Cache
X-Platform-Server
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
Cdnsip
Cluster
X-Ad-Load-Variation
Req-ID
State
X-Amz-Meta-Opti
Cdncip
X-AK-Request-ID
X-Air-Pt
X-Cdn-Request-ID
X-WP-CF-Super-Cache-Cookies-Bypass
X-Vgn-Hpd-Ssi
X-Branch-Name
WebServer
X-Fastly-Cache
Content-Script-Type
Content-Style-Type
X-Vgn-Hpd-Cached
X-Vgn-Hpd-Variations-Key
X-Wp-Cf-Super-Cache
X-Scope-Id
X-Cache-Ttl
X-Release
X-Wp-Cf-Super-Cache-Cache-Control
Pramga
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-Rocket-Build-Number
X-NWS-UUID-VERIFY
X-Sigma-Backend
X-Shield-Cache-Expires
X-Varnish-Beresp-Status
Lb
X-Traceid
X-Proxy-CacheRZ
XkeyRZ
X-M-Reqid
X-M-Log
X-Cache-Remote
Proxy-Connection
X-Request-Start
Yak-Timeinfo
X-Generated-In
X-Sigma
CDN
X-Rebelmouse-Cache-Control
X-CACHE-KEY
X-Rebelmouse-Surrogate-Control
X-Cache-Date
X-HS-Status
Geoip-Latitude
Ohc-File-Size
Cache
X-Akamai-Pragma-Client-IP
X-Cdn-Forward
X-Request-URI
X-Tim-N
X-Qnm-Cache
Edge-Cache
Srv
X-Lb-Cache
X-FORWARDED-FOR
X-Render-Time
X-TH-Server
X-Dw-Trace-Id
X-User
CF-Cached-On
X-GoCache-CacheStatus
X-UA
X-Ha-Backend
X-Provided-By
X-GeoIP-City
X-Scheme
X-Gamma-Serve
Server-Id
X-TT-LOGID
X-CUA
X-Wa
X-Via-Popv
Click-Count-Action-Start
X-Aicache-OS
X-Acquia-Purge-Cdn-Unconfigured
V-Age
X-Req
X-Via-Poph
X-Cache-FS-Status
X-B3-Trace-ID
X-V-Cache
Tube-Return
Tube-Got-Results
Click-Count-Error
X-Nc
Cache-Tv-Group
X-SB
X-Via-Popn
Tube-Got-Eval
Tube-Get-Contents
X-Servedbyhost
X-Acquia-Site
X-Acquia-Purge-Tags
X-Lb-Nocache
X-Acquia-Application-UUID
X-Acquia-Application-Trace
X-EC-Lua
X-Via-Ucdn
X-Vc
PICS-Label
X-Cdn-Cache-Status
X-RN-RSRV
HostName
Yjs-Id
X-Sucuri-Id
Inserted-Into-Cache-At
X-Snapshot-Date
X-Edge-POP
X-Fastly-Cache-Hits
CACHE-MISS-TO-ORIGIN
Vha6-Origin
MIME-Version
Ohc-Cache-HIT
On-Server
X-Men
Ngx
Env
X-Miniprofiler-Ids
X-CF-Cache-Header-Vary
X-CF-Cache-Header-Cache-Control
Cneonction
X-Udemy-Cache-App-Namespace
X-RAMCache
X-Fastly-Backend-Reqs
X-LB-ID
X-ElasticPress-Query
X-Litespeed-Cache-Control
Log-Origin
X-Cached-Since