Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
X-Powered-By
Pragma
X-XSS-Protection
CF-RAY
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
Alt-Svc
P3P
X-Cache-Hits
X-Xss-Protection
X-UA-Compatible
X-Served-By
CF-Ray
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
Access-Control-Allow-Credentials
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
X-Drupal-Cache
X-Cache-Status
X-Generator
X-Check
X-Cacheable
X-FRAME-OPTIONS
X-Envoy-Upstream-Service-Time
Timing-Allow-Origin
X-Dns-Prefetch-Control
X-Iinfo
X-DNS-Prefetch-Control
Server-Timing
X-Drupal-Dynamic-Cache
Feature-Policy
X-Content-Security-Policy
Access-Control-Expose-Headers
X-XSS-PROTECTION
Content-Encoding
X-CDN
Status
Upgrade
X-AspNetMvc-Version
Access-Control-Max-Age
X-Request-ID
X-Via
X-Amz-Request-Id
X-Ua-Compatible
X-Amz-Id-2
Request-Context
X-Backend
X-Cache-Group
X-Turbo-Charged-By
X-Robots-Tag
Cf-Edge-Cache
Keep-Alive
Host-Header
X-AH-Environment
X-Vhost
X-Hacker
X-UA-Device
X-Proxy-Cache
X-Server
Allow
X-Rq
X-Server-Powered-By
X-Ws-Request-Id
X-Dispatcher
EagleId
X-Age
X-Varnish-Cache
X-Amz-Version-Id
P3p
Nel
X-LiteSpeed-Cache
Grace
Cf-Apo-Via
Cf-Railgun
X-OneAgent-JS-Injection
X-Page-Speed
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
EagleEye-TraceId
X-Device
X-Swift-CacheTime
X-Swift-SaveTime
X-Aws-Lambda-Call-Status
Ali-Swift-Global-Savetime
X-Pingback
X-Host
X-Cache-Lookup
X-CST
Accept-CH
X-Node
X-WebKit-CSP
X-Backend-Server
Surrogate-Control
Permissions-Policy
X-Server-Id
X-Nginx-Upstream-Cache-Status
X-Readtime
X-Akam-SW-Version
X-Nginx-Cache-Status
Accept-CH-Lifetime
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Application-Context
Request-Id
Xkey
X-Ruxit-JS-Agent
X-Cloud-Trace-Context
X-Content-Security-Policy-Report-Only
X-Response-Time
X-HW
X-Trace
X-Edge
Content-Location
X-Clacks-Overhead
X-Mod-Pagespeed
X-Url
Rating
X-Midtier
X-ESI
X-Amz-Server-Side-Encryption
X-ECACHE
Cache-Tag
X-Mcache
X-Rack-Cache
X-Powered-By-Plesk
X-Country
Accept-Ch
X-MS-InvokeApp
X-D2id
Service-Worker-Allowed
X-Exp-Id
X-Exp-Variant
X-Cdn-Fetch
X-Use-Magma
X-GoogleNews-Bot
X-Kinja-Server
X-Kinja-Revision
X-Kinja
X-Kinja-Build
Verso
X-Vcap-Request-Id
X-Element-Page-Cache
X-Upstream
Edge-Control
Accept-Ch-Lifetime
X-Country-Code
X-Ac
X-Kinja-CCPA
Origin-Trial
RTSS
X-PC
X-Vname
X-TtlSet
X-Goog-Hash
X-Navigation-Version
X-VARITI-CCR
X-Abt-Application-Version
X-Browser-Type
X-Cache-TTL
X-Oneagent-Js-Injection
Fastly-Restarts
X-NWS-LOG-UUID
X-Amz-Rid
X-Aspnetmvc-Version
X-Varnish-TTL
X-Litespeed-Cache
X-Webkit-CSP
X-GitHub-Request-Id
Cross-Origin-Opener-Policy
X-Cached
X-Server-Name
X-Amzn-Trace-Id
X-Dw-Request-Base-Id
X-Times
Display
Pagespeed
X-Sol
X-Middleton-Display
X-Server-ID
SPRequestGuid
X-SharePointHealthScore
X-Pinterest-Rid
X-Ruxit-Js-Agent
Pinterest-Version
Pinterest-Generated-By
X-Ttl
SPIisLatency
SPRequestDuration
X-Server-Lifecycle-Phase
X-Instrumentation
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Kraken-Loop-Name
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
X-WebKit-CSP-Report-Only
X-Cache-Key
X-Content-Type
AR-Request-ID
AR-PoweredBy
AR-ATIME
AR-SID
X-Powered-CMS
X-Client-IP
Arr-Disable-Session-Affinity
X-Version
X-B3-Traceid
X-Cnection
X-Mg-S
X-Middleton-Response
Response
X-FastCGI-Cache
X-Ser
Nginx-Cache
X-Jurisdiction
X-HP-Trace-Id
X-HP-Webp
X-Accel-Expires
Cache-Tags
X-T
AR-CACHE
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-B3-TraceId
X-Fastly-Request-ID
Cache-Status
X-NF-Request-ID
Edge-Cache-Tag
X-Hits
Public-Key-Pins
X-Px
X-MSEdge-Ref
X-Recruiting
S
Front-End-Https
X-RateLimit-Remaining
X-Daa-Tunnel
X-Shield-Request-Id
Payment
X-LLID
X-Frontend
Server-Node
X-Ua-Browser
X-Request-Received
X-Request-Processing-Time
Content-MD5
Mrf-Cache-Status
MRF-Tech
X-B3-TraceId-Primal
X-RateLimit-Limit
X-Goog-Metageneration
X-GUploader-UploadID
X-Content-Digest
X-Amz-Apigw-Id
X-Amzn-RequestId
Access-Control-Request-Method
MicrosoftSharePointTeamServices
X-DIS-Request-ID
X-Webkit-CSP-Report-Only
X-Forwarded-For
X-TTL
X-Protected-By
TP-Cache
Realpath
X-Microsite
X-Distributor
X-Request-Handler-Origin-Region
X-Ratelimit-Remaining
X-FB-Debug
X-PressLabs-Stats
Fastcgi-Cache
X-HS-Cache-Config
X-HS-Combine-CSS
X-HS-Content-Id
X-HS-Hub-Id
X-Page-Id
Access-Control-Allow-Method
Accept-Charset
X-Cluster-Name
X-Rid
X-LB-Cache
X-Id
X-Xrds-Location
Count-Hit
X-Fastcgi-Cache
X-Aspnet-Version
X-Ua-Device
X-B3-Sampled
X-Goog-Generation
X-Goog-Storage-Class
X-Edge-Location-Klb
X-Geo-Country
X-Goog-Stored-Content-Length
X-Kinsta-Cache
X-Goog-Stored-Content-Encoding
X-Hostname
Cross-Origin-Resource-Policy
TP-L2-Cache
X-Seen-By
X-App-Server
X-Ratelimit-Limit
X-Correlation-Id
X-TEC-API-VERSION
TCN
X-Logged-In
X-Varnish-Backend
X-TEC-API-ORIGIN
X-TEC-API-ROOT
Cleartype
X-Ezoic-Cdn
X-Git-Hash
X-Hosted-By
X-Mobile
X-Content-Options
Referer-Policy
Retry-After
X-Erf-Stays-Pdp-Viaduct-Migration-Web
DC
X-Contextid
X-Fb-Rlafr
X-Route-Name
X-F-Cache
X-Newrelic-App-Data
X-Aspnet-Duration-Ms
X-Origin-Cache
X-Flags
X-Is-Crawler
X-Request-Guid
X-Providence-Cookie
X-Forwarded-Proto
X-Grace
X-Revision
Surrogate-Key
X-TT
X-Amz-Replication-Status
X-App-Environment
X-Debug-Info
Frame-Options
X-IPS-LoggedIn
X-Varnish-Grace
X-Amz-Meta-S3cmd-Attrs
X-Azure-Ref
MS-Author-Via
X-Envoy-Decorator-Operation
X-Magnolia-Registration
Section-Io-Cache
X-Www-Served-By
X-RateLimit-Reset
X-App-Version
X-Wix-Request-Id
X-COUNTRY
X-Trace-Id
X-Proxy-Cache-Info
X-Webkit-Csp
X-Whom
X-Activity-Id
X-AppVersion
X-Az
X-Language
Healthy
Charset
Filterid
X-Akamai-Edgescape
WPO-Cache-Status
WPO-Cache-Message
Viewport
X-Origin-Server
X-Kong-Upstream-Latency
Server-Name
X-Kong-Proxy-Latency
Alternate-Protocol
X-Varnish-Server
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
Amp-Access-Control-Allow-Source-Origin
X-Datadog-Trace-Id
X-Backend-Name
Paypal-Debug-Id
X-Original-Request-Id
VIX-Pulpo-Upstream-Status
X-Response-Served-From
X-EdgeConnect-Cache-Status
X-Cache-Rule
X-B
X-Http-Reason
X-N
Host
VIX-Pulpo-Node
SRV
X-DataDome
X-UUID
X-Rule
X-Yottaa-Optimizations
X-Edge-Location
Front
X-User-Agent
X-Instance
X-Akamai-Request-ID2
X-Nf-Request-Id
X-Cacheable-TTL
X-Cache-Grace
X-Yottaa-Metrics
From-Origin
X-Mg-Request-UUID
X-ARC
X-Load-Cache
X-Unique-Id
X-L-Path
X-Vcache
X-Jobs
SD-X-WS
X-Signature
Protected
X-B-Cache
X-Region
Content-Disposition
X-Framework
X-Page-View
X-Environment-Context
Country
X-FW-Server
Akamai-GRN
X-ProcessESI
X-Adobe-Loc
X-Adobe-Content
X-FW-Type
X-FW-Version
X-FW-Static
X-RemovedCookies
X-Datadog-Sampled
X-FW-Dynamic
X-Varnish-Age
X-Is-Bot
Fastly-SWR
X-FW-Hash
X-Status
X-Rocket-Nginx-Serving-Static
X-FW-Serve
Fastly-SIE
X-Rendered-As
X-Tumblr-User
X-Proxy
X-G
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Type
X-Tumblr-Pixel-1
X-Cache-Time
X-Time
X-Debug-IsPreview
X-Amzn-Remapped-Content-Length
X-Debug-IsConnected
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
Access-Control-Request-Headers
ServerID
X-ECache
X-CDN-Forward
X-Tec-Api-Version
X-Client-Ip
X-Tec-Api-Root
X-Tec-Api-Origin
Backend
X-Erf-Web-Scheduler
X-Cache-Age
Refresh
X-Servername
X-Nginx-Cache
Xet-Cookie
X-Tt-Trace-Tag
X-DynaTrace
X-Tt-Trace-Host
X-Cache-Control
Url
Countrycode
X-Httpd
X-Template
Accept-Language
X-Drupal-Cache-Tags
CF-IPCountry
X-Device-Type
X-DynaTrace-JS-Agent
X-Mode
X-Content-Powered-By
X-NYM-Debug-Backend
X-Generated-By
X-FTR-Request-ID
Webserver
X-HTML-Minification-Powered-By
X-Cache-Hit
Xserver
X-URL
X-CCDN-CacheTTL
X-CCDN-Origin-Time
X-Storage
X-Hcs-Proxy-Type
GEO-INFO
X-Say-TTL
X-ServerID
X-Content-Age
X-SayCDN-TTL
X-Say-Cacheable
X-UPSTREAM-Address
X-XRDS-LOCATION
X-Urbn-Context-Path
X-Urbn-Site-Id
X-SaId
Cross-Origin-Window-Policy
Version
X-Tncms
Locale
X-GeoCode
X-Director
S-Rt
X-Soup
Meta-Geo
X-GeoCountry
X-Cache-Operation
X-Rn-Rsrv
Load-Balancing
Filters
X-Rewrite-Enabled
X-Loop
X-JoinUs
X-LAGOON
X-Served-From
X-Tt-Logid
X-Cache-Action
Onion-Location
X-Forwarded-Host
X-Git-Commit
OT-Force-Account-Verify
X-Cluster-Node
X-Varnish-Cache-Hits
X-Container-Uri
X-NGENIX-Cache
X-Source
X-MCACHE
X-Varnish-Hostname
X-VC-Cache
X-RM-Cache-TTL
Azure-SiteName
X-Adobe-Source
X-Ms-Request-Id
Azure-InstanceId
Azure-RegionName
Azure-SlotName
Azure-Version
X-Labrador-Cache-Channel
X-Detected-As
X-Ms-Version
X-VCT
X-R9-Blue-Green-Version
X-Sql-Count
X-Skip-Cache
X-Tb
X-PHP-Host
X-Sql-Duration-Ms
X-Lambda-Id
Web-Mar-Node
X-B3-SpanId
X-Extlb
X-Routing-Service
X-FB-TRIP-ID
DB-Nickname
X-RCS-CacheZone
X-Logging-Id
Node
X-Redis-Cache
X-Zipkin-Id
X-Proxied
Mn-Server-Ip
X-Cache-Server
Webcakes-App-Name
TWC-GeoIP-Country
TWC-Privacy
TWC-Locale-Group
TWC-Device-Class
TWC-GeoIP-LatLong
TWC-Connection-Speed
Fastcgi-Useragent
X-Origin-Hint
X-Generation-Time
X-Timing-Wait
X-Uri
X-Tumblr-Pixel-3
X-Tumblr-Pixel-2
Selected-Fe
X-Proxy-Build
Webcakes-Region
Webcakes-App-Version
X-Format
X-Debug
X-Fetched-On
Property-Id
X-Endurance-Cache-Level
X-Proto
Uber-Trace-Id
Source
X-Zen-Fury
X-LSADC-Cache
CDN-RequestId
X-Ua
X-S
X-Sucuri-Cache
X-XRDS-Location
X-Sucuri-ID
X-Ratelimit-Reset
Section-Io-Origin-Status
Section-Origin-Responded
Section-Io-Id
Section-Io-Origin-Time-Seconds
X-TimeS
NGB
X-Oracle-Dms-Rid
X-Oracle-Dms-Ecid
X-Origin-CC
X-Origin-TTL
X-Akamai-Transformed
Upgrade-Insecure-Requests
X-MP-GENERATED-AT
X-Origin-Date
X-Drupal-Cache-Contexts
X-Newrelic-Synthetics
X-Real-IP
X-Pass-Why
X-Handled-By
X-Varnish-Hits
Fastly-Drupal-HTML
X-Cache-Expired-At
X-TraceId
X-AB
X-Reqid
X-Srv
X-Xfnlog-Site
MS-CV
Ms-Operation-Id
Apigw-Requestid
X-Cms-Context
X-No-Session
X-Optimistic-Header
X-RTag
X-Restarts
ServedBy
X-CACHE-AGE
Liferay-Portal
X-GEO
X-Cache-Host
X-BYPASS-REASON
X-ProxyCache-Key
X-ProxyCache-Status
X-Hl-Ver
X-Varnish-Ttl
WP-Super-Cache
X-Tx-Id
X-Geo-Region
CDN-EdgeStorageId
CDN-CachedAt
CDN-RequestPullCode
CDN-Uid
CDN-RequestPullSuccess
CDN-RequestCountryCode
CDN-PullZone
X-VWS-Id
X-IPLB-Instance
X-Cluster
X-AWS-Id
X-Fastly-Request-Id
X-IPLB-Request-ID
X-Cache-Type
X-LJ-Flow-ID
CDN-Cache
X-UA-Device-Type
X-CSRF-Token
X-Upgrade-Enabled
X-Cache-TTL-Remaining
X-Node-Name
Cache-Provider
X-Proxy-Cache-Status
MD5-Digest
Magicmarker
N-Cache
Ngx.Var.Host
Lang
Meta-Geo-Continent
BehaviorPad-Version
Odigeo-Trace-Id
Canary
X-Owner
X-PAYTM-SRV-ID
X-Pool
X-Via-JSL
DCR-Decision-By
DCR-Processing-Time-Ms
HA-Ipaddr
L
Ha-Gx-Prefs
Gannett-Cam-Experience-Id
Fastly-SSL
L5d-Success-Class
Sslversion
X-CGP
X-Conf
X-Csrf-Jwt
X-D
X-CF-Lambda-Version
X-CF-Lambda-Fn
X-Bip
X-Bl-Debug
X-Cache-NE
X-CacheTTL
X-FC-Vary-Parameters
X-Debug-Cache-Fetch
X-Ec-GeoHdr
X-Epic-Correlation-Id
X-Eu-Site
X-External-Request-Id
X-Ec-Fail
X-Ec-Custom-Error
X-Debug-Cache-Store
X-Destination
X-Developer
X-Dispatcher-Number
X-BCube-Filmed-By
X-Bc-Bl
T-Server
True-Client-Country-4JS
Vix-Hermes-Req-Id
W
Surrogated-Key
X-Pubstack
Redirect-Candidate
Rendered-Blocks
Server-Host
X-Level-Front-Cache
Web-Mar-Region
X-A
X-App
X-Application
X-Generated-On
X-B-Cookie
X-Aed
X-A-Wwc
X-A-Ccd
X-A-Dam
X-A-Dcw
X-A-Dgt
Origin-Agent-Cluster
Candidate-Md5Url
X-Worker
X-S-Cookie
X-Slack-Shared-Secret-Outcome
X-Vdms-Version
X-Request-Host
X-Vtex-Remote-Cache
X-We-Are-Hiring
X-SRCache-Key
X-Vdms-Path
X-ScT
X-Micro-Cache
X-Slack-Backend
X-Rojux
X-Viewer-Country
X-Thanos
X-Parent-Response-Time
X-Cache-Status-Check
X-Fastly-Backend
Xc-Version
X-Qloud-Router
X-TIME
Cache-Name
X-Wikidot-Backend
VNS-Cache
We-Hiring
X-Alternate-Cache-Key
X-Sn-Servicetimems
X-VServer
X-Accel-Buffering
X-Sorting-Hat-PodId
X-Accel-Expires-Debug
X-Human
X-GeoIP-Region-Code
Thinkindot-CacheControl-Type
Release
Req-Svc-Chain
X-Loc
Datacenter
Producers
X-Mly-Id
Platform
X-Wix-Viewer-Type
X-Vgn-Hpd-Reason
X-Wikidot-Static-Cache
X-Irp-Debug
X-Server-W
Thinkindot-Control
X-GeoIP-Country-Code
TDXMobile
Thinkindot-CacheControl
VNS-Age
X-VG-WebCache
X-Varnish-CookieINHashed-On
X-DefElseHash
X-DefHash
X-SVT-ORM-RULES
X-Date
X-Varnishpool
X-Storefront-Renderer-Rendered
X-Varnish-Remaining-TTL
X-Correlation-ID
X-SVT-ORM-VERSION
X-Variation
X-Var-Ttl
X-Up
X-Tenant
X-Varnish-CookieHashed-On
X-Dispatcher-Server
X-DPWN-IS-SECURE
X-Core-Value
X-Core-Mission
X-Gdpr
X-BBC-Edge-Cache-Status
X-Mvc-Supplant-Cachable
X-Vmg-Version
X-Geo-Header
X-Sorting-Hat-ShopId
X-App-Name
X-VG-TLSProxy
X-Cache-Bucket
X-Cdn-Origin
X-Clientip
X-CMSURLCustom
X-Cdn-Diag
X-Forwarded-Path
X-Cache-Debug
X-Cache-Info
X-ApacheServer
X-Mid
Fastly-GeoIP-CountryCode
Fastly-Backend-Name
Expect-Staple
Environment
X-Origin-Time
Gh-Request-Id
X-Nitro-Cache
Host-ID
X-Platform
X-PERF
X-NodeID
X-Orig-Expires
Adler-Geo
AKAMAI
X-Thinkindot-L3
X-Nyt-Route
CloudFront-Viewer-Country
Cmsid
CPC-Cache
CPC-Age
X-Old-Content-Length
Cmstype
Is-Eu
X-SD-PageType
X-Policy
X-Server-IP
X-Shop-Environment
X-Refresh
Mail-Subject
X-ShardId
Origin
X-ShopId
Machine
X-Hash
X-Nananana
X-Shopify-Stage
X-Request-Time
X-Is-Supported-Browser
X-Is-Desktop
X-Accel-Version
X-AIR-PT
X-Is-Mobile
X-Is-Tablet
X-Browser-Name
X-Tcp-Rtt
Apple-News-Services-Host
X-Device-Os
X-S-Maxage
Apple-News-Services-Handled
X-Test
X-Org
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
X-Cache-Id
X-GeoIP
X-Forwarded-Site
X-RateLimit-Remaining-Second
X-Op-Id-All
X-Clara-WADP
X-From
X-Fmm-Version
X-RateLimit-Limit-Second
X-Origin
X-Origin-Response-Time
X-Esi-Check
X-Datadome
X-Ah-Environment
X-Node-Id
User-Cache-Control
X-WADP-Cache
X-Block-Status
X-INCAP-ABP
DSUID
NM-Fastcgi-Cache
X-Nginx-Cache-Key
Server-Ext
Esi-Enabled
Server-Hostname
Sever-Int
X-NCache
X-Hnp-Log
X-WA-Info
Cf-Device-Type
X-Auto-Login
X-Gzip
X-Gen-Mode
X-Mvc-Supplant-OutputCached
CDCHOST
Country-Code
X-Buckets
X-B3-Spanid
X-Cache-Enabled
Wxu-Next-Hostname
Wxu-Next-Region
X-Via-Fastly
C-Via
NGX
X-LB-NoCache
Pics-Label
X-Vcl-Version
X-Instance-Name
Wxu-Next-Commit
X-Cdn-Srv
X-Access
Ssr
X-Section
Server-Info
Content-Secure-Policy
AMP-Access-Control-Allow-Source-Origin
X-Amz-Meta-Cb-Modifiedtime
X-Varnish-Beresp-Ttl
X-Zone
X-Presslabs-Stats
X-Akamai-Device-Characteristics
Server-ID
X-CACHE-GROUP
X-Dc
X-Varnish-Beresp-Grace
X-API-Version
X-Origin-Cache-Key
YJS-ID
X-HA-Backend
IsBot
X-SIPLIST1
CF-Ctrl
X-B3-Parentspanid
X-WP-CF-Super-Cache-Active
X-JWT-State
Memcached
X-Frame-Option
X-Platform-Cluster
X-Platform-Processor
X-Platform-Router
X-Has-Esi
X-Cached-By
X-Is-Gdpr
Cdn-Requestid
Sid
Location
Cache-Hits
Hostname
Time
X-Internal-Host
Memory
X-Wp-Cf-Super-Cache-Active
X-FTR-Cache-Status
X-Country-Code-Real
X-FTR-Expires
X-FTR-Balancer
X-FTR-Backend
X-FTR-Backend-Server
X-TIM-N
X-Hyper-Cache
X-Fpc
X-Tb-Optimization-Total-Bytes-Saved
Origin-CC
X-Air-Trace-Id
Origin-EX
X-Scale
X-Air-Hostname
X-Air-Source
X-TA-CDN-Provider
X-Webstats-RespID
X-LiteSpeed-Cache-Control
X-Backend-Instance
X-Cs
X-DC
X-ID
X-Service
X-SRV
X-PHP-Backend
X-ZONE
X-VC
Resin-Trace
X-DataCenter
X-NewRelic-App-Data
Epwk-X-Cache
LB
X-Esi
True-Client-Ip
X-Site-Version
X-Webkit-Csp-Report-Only
Uri
X-Azure-Ref-OriginShield
X-NGINX-Cache
X-NODE
WZWS-RAY
X-Nitro-Cache-From
GeoIP-Latitude
X-Locale
GeoIp-Country-Code
X-Microcachable
Req-ID
X-NMSegId
X-Nitro-Rev
X-Edge-Server
Cdn-Request-Time
Cdn-Host
GeoIP-Country-Code
X-VCache
Cache-Host
X-Cache-Ttl
XServer
X-Ad-Load-Variation
X-Origin-Expires
X-CSRF-TOKEN
X-Request-URI
SID
X-Scope-Id
X-M-Log
X-M-Reqid
X-Datacenter
NtCoent-Length
M-TraceId
True-Client-IP
X-Info
X-Request-Start
Pramga
XM
Cdn
HostName
X-Geo
X-Qnm-Cache
Content-Script-Type
Content-Style-Type
X-Vercel-Cache
Cluster
X-Vercel-Id
X-Shield-Cache-Expires
WebServer
X-Pad
X-Varnish-Beresp-Status
X-HN
PFcat
X-VarnishDD-TTL
X-Github-Request-Id
X-Pod-Name
X-Cache-Date
X-FPC
Cache-Tv-Group
User-Agent
Fastly-Drupal-Html
X-Ad-Defer-Variation
X-Web-Node
X-WP-CF-Super-Cache-Cookies-Bypass
Tcn
X-HostName
A
X-TH-Server
Srvid
X-Via-CDN
X-MSEdge-Features
X-FL-QIT-DEBUG
X-FL-EDGE
Locid
X-MSEdge-Flight
X-Via-Edge
Edge-Copy-Time
X-Via-SSL
X-LiteSpeed-Tag
X-Cdn-Request-ID
X-Api-Version
Cf-Ipcountry
CountryCode
X-APP-VERSION
X-CS
X-Aicache-OS
X-Wa
X-NWS-UUID-VERIFY
X-AK-Request-ID
Cdnsip
Tube-Got-Eval
Edge-Cache
X-Cache-FS-Status
X-LB-ID
Click-Count-Error
X-Nc
X-Acquia-Purge-Cdn-Unconfigured
Cdncip
X-Via-Popv
Tube-Return
X-V-Cache
X-Servedbyhost
X-Via-Popn
X-Via-Poph
Click-Count-Action-Start
Tube-Got-Results
X-B3-Trace-ID
Tube-Get-Contents
X-Amz-Meta-Opti
MIME-Version
X-FireWall-Port
X-Req
X-SB
V-Age
X-Moov-T
On-Server
X-Contensis-Viewer-Groups
X-Cache-ASPX
X-ATG-Version
X-Branch-Name
X-Vary
X-Varnish-Authentication
Path
X-Men
X-Moov-Xdn-Version
X-VCL-Version
Priority
X-Wp-Cf-Super-Cache-Cookies-Bypass
Ngx-Var-Key
Cache-Key
X-Proxy-CacheRZ
XkeyRZ
Yak-Timeinfo
X-Akamai-Pragma-Client-IP
CDN
X-UA
X-CACHE-KEY
My-App
X-Render-Time
X-Tim-N
X-Fastly-Backend-Reqs
X-Cdn-Forward
X-Acquia-Site
X-Acquia-Purge-Tags
X-Acquia-Application-UUID
X-Acquia-Application-Trace
Wpo-Cache-Status
Geoip-Latitude
Srv
Wpo-Cache-Message
Proxy-Connection
X-Lb-Cache
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-User
X-Ha-Backend
X-Generated-In
X-Fastly-Country-Code
X-Air-Pt
X-Varnish-Director
Server-Id
Lb
X-Provided-By
X-TT-LOGID
X-TRACE-ID
Ohc-Cache-HIT
X-Wp-Cf-Super-Cache
Ohc-File-Size
X-Planisys-CDN-TTL
X-HS-Content-Campaign-Id
X-Platform-Server
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
X-CUA
X-Via-Ucdn
X-Wp-Cf-Super-Cache-Cache-Control
CF-Cached-On
X-Dw-Trace-Id
X-Lb-Nocache
PICS-Label
X-EC-Lua
X-Cdn-Cache-Status
Cache
State
X-Iplb-Request-Id
X-Iplb-Instance
Yjs-Id
X-Fastly-Cache-Hits
Fusion-Source
Warning
Fusion-Component-Id
X-Serial
X-GoCache-CacheStatus
X-GeoIP-City
Fusion-Content-Id
Type
Cross-Origin-Embedder-Policy-Report-Only
X-Check-Cacheable
Fusion-Template-Id
Fusion-Content-Source
X-Gamma-Serve
Fusion-Deployment-Id
X-Vgn-Hpd-Variations-Key
Ngx
X-Cache-Remote
X-Litespeed-Cache-Control
X-ElasticPress-Query
Log-Origin
Cneonction
X-RAMCache
X-Miniprofiler-Ids
X-HS-Status
X-Cached-Since
Vha6-Origin
X-Vgn-Hpd-Ssi
X-Vgn-Hpd-Cached
X-Snapshot-Date
X-Fastly-Cache
X-Udemy-Cache-App-Namespace
X-CF-Cache-Header-Cache-Control
X-CF-Cache-Header-Vary
X-Release
Inserted-Into-Cache-At