Threat Level: green Handler on Duty: Johannes Ullrich

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-Cache-Status
Link
Accept-Ranges
CF-RAY
ETag
X-XSS-Protection
Expect-CT
Pragma
X-Powered-By
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
Alt-Svc
X-UA-Compatible
X-Served-By
X-Xss-Protection
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-AspNet-Version
X-Adblock-Key
X-Runtime
X-Permitted-Cross-Domain-Policies
X-DNS-Prefetch-Control
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Cache-Status
X-Check
X-Generator
X-Cacheable
Timing-Allow-Origin
Report-To
NEL
X-Content-Security-Policy
X-Iinfo
Feature-Policy
X-Envoy-Upstream-Service-Time
Status
Content-Encoding
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
X-AspNetMvc-Version
X-CDN
P3p
Upgrade
X-Via
CF-Ray
X-Ws-Request-Id
Access-Control-Max-Age
Server-Timing
EagleId
X-Turbo-Charged-By
X-Cache-Group
Keep-Alive
X-UA-Device
Request-Context
X-Backend
X-Age
X-Proxy-Cache
X-AH-Environment
X-Server-Powered-By
X-Robots-Tag
X-Hacker
X-Server
Host-Header
X-Amz-Request-Id
X-Request-ID
X-Amz-Id-2
Grace
X-Rq
X-LiteSpeed-Cache
X-Swift-SaveTime
X-Swift-CacheTime
X-Varnish-Cache
Ali-Swift-Global-Savetime
X-Nginx-Cache-Status
X-WebKit-CSP
X-Page-Speed
EagleEye-TraceId
X-Vhost
X-Amz-Version-Id
X-OneAgent-JS-Injection
X-Ua-Compatible
X-Pingback
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Dispatcher
X-Device
X-Cache-Spec
Accept-CH
X-Host
Cf-Railgun
X-Server-Id
X-Node
X-Backend-Server
X-Readtime
Surrogate-Control
X-Akam-SW-Version
X-Dns-Prefetch-Control
Request-Id
X-Response-Time
X-HW
X-Application-Context
Xkey
Content-Location
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Accept-CH-Lifetime
Rating
X-Ruxit-JS-Agent
X-Country
X-B3-TraceId
X-Cloud-Trace-Context
X-Cache-Lookup
Accept-Ch-Lifetime
Allow
X-Trace
X-Url
X-Aws-Lambda-Call-Status
X-Vname
X-TtlSet
X-PC
X-Content-Type
X-Ac
X-Clacks-Overhead
Edge-Control
Fastly-Restarts
X-Server-Name
X-ESI
X-Mod-Pagespeed
Cache-Tag
X-Varnish-TTL
X-Rack-Cache
X-VARITI-CCR
Service-Worker-Allowed
Verso
MS-Author-Via
X-Element-Page-Cache
X-Vcap-Request-Id
X-FastCGI-Cache
X-Amz-Rid
X-MS-InvokeApp
X-Upstream
Public-Key-Pins
X-GitHub-Request-Id
X-Dw-Request-Base-Id
X-Abt-Application-Version
RTSS
X-Client-IP
X-Cached
X-D2id
X-Cnection
X-Cache-TTL
X-Cdn-Fetch
X-Exp-Id
X-GoogleNews-Bot
X-Kinja-Revision
X-Exp-Variant
X-Kinja-Build
X-Kinja
X-Kinja-Server
X-Use-Magma
X-Px
X-Navigation-Version
X-CST
Arr-Disable-Session-Affinity
X-Powered-By-Plesk
Access-Control-Request-Method
X-Country-Code
X-NF-Request-ID
X-TTL
X-Goog-Hash
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-Server-Lifecycle-Phase
X-Instrumentation
X-Kraken-Loop-Name
Pagespeed
X-Middleton-Display
X-Sol
Display
AR-CACHE
AR-ATIME
AR-Request-ID
AR-PoweredBy
AR-SID
X-Version
X-Powered-CMS
Response
X-Middleton-Response
X-Origin-Cache
X-LLID
X-MSEdge-Ref
Nginx-Cache
TCN
X-Kinsta-Cache
X-Edge-Location-Klb
X-RateLimit-Remaining
X-Amz-Server-Side-Encryption
MRF-Tech
Mrf-Cache-Status
X-B3-TraceId-Primal
X-Edge
X-Protected-By
X-T
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Forwarded-For
X-HP-Webp
X-Jurisdiction
X-HP-Trace-Id
X-Content-Security-Policy-Report-Only
X-Shield-Request-Id
X-Id
X-Language
Edge-Cache-Tag
S
X-Mg-S
X-Aspnetmvc-Version
SPIisLatency
SPRequestDuration
Content-MD5
Front-End-Https
Fastcgi-Cache
X-Mid
Pinterest-Generated-By
X-Pinterest-Rid
Realpath
Pinterest-Version
X-Request-Processing-Time
X-Request-Received
X-NWS-LOG-UUID
Server-Node
X-Recruiting
X-Frontend
Filters
X-Correlation-Id
X-Ser
Server-Name
X-Content
X-Ab
X-Ua-Browser
Accept-Ch
X-Template
X-MCACHE
X-Cache-Key
X-Yandex-Sdch-Disable
X-HS-Content-Id
X-HS-Cache-Config
X-HS-Hub-Id
X-HS-Combine-CSS
X-DynaTrace
SPRequestGuid
X-Ruxit-Js-Agent
X-SharePointHealthScore
X-Ezoic-Cdn
X-Hits
X-Parallel-Accel
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
MicrosoftSharePointTeamServices
X-Daa-Tunnel
X-ECACHE
X-Tt-Trace-Tag
X-Tt-Trace-Host
Charset
X-Page-Id
X-Ttl
Cache-Tags
X-Debug-Info
Cleartype
Host
X-B3-Sampled
X-Server-ID
X-Geo-Country
X-Www-Served-By
X-Git-Hash
X-DIS-Request-ID
X-Content-Options
X-Content-Digest
X-DataDome
Cross-Origin-Opener-Policy
X-Amzn-Trace-Id
Alternate-Protocol
X-Ratelimit-Limit
X-Hostname
X-ASPNET-VERSION
X-Amz-Replication-Status
X-Grace
Fusion-Deployment-Id
Fusion-Content-Source
Fusion-Content-Id
Fusion-Template-Id
X-F-Cache
Fusion-Source
Fusion-Component-Id
Filterid
X-Accel-Expires
X-FB-Debug
ServerID
X-Upgrade-Enabled
X-Varnish-Age
X-AppVersion
X-Activity-Id
X-Az
X-N
X-VCache
X-Forwarded-Proto
X-Nginx-Upstream-Cache-Status
X-LB-Cache
X-Mobile-URL
X-Rid
X-Type
Access-Control-Allow-Method
X-Seen-By
X-Distributor
X-Tb
X-Whom
X-TT
X-Is-Crawler
X-Flags
X-FW-Hash
Viewport
X-FW-Dynamic
X-Request-Guid
X-Route-Name
X-Providence-Cookie
X-FW-Serve
X-App-Environment
X-WebKit-CSP-Report-Only
Payment
X-FW-Type
X-Aspnet-Duration-Ms
X-FW-Static
X-FW-Server
X-Origin-Server
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
X-Goog-Generation
X-Goog-Storage-Class
X-Fastly-Request-Id
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-User-Agent
X-Fastly-Request-ID
Node
X-Varnish-Grace
Fastcgi-Useragent
X-Ratelimit-Reset
X-Wix-Request-Id
X-XRDS-LOCATION
DC
Paypal-Debug-Id
Country
Accept-Charset
TP-Cache
TP-L2-Cache
X-Fastcgi-Cache
X-App-Server
X-Cache-Rule
X-Cluster-Name
X-Via-JSL
X-Cache-Control
X-Drupal-Cache-Tags
X-Litespeed-Cache
X-Tec-Api-Origin
X-Tec-Api-Version
X-Tec-Api-Root
X-Webkit-Csp
Version
X-Microsite
X-NGENIX-Cache
X-Signature
X-Request-Handler-Origin-Region
X-B-Cache
X-Cache-Age
X-Contextid
X-Buckets
Cache-Status
X-Node-Name
Referer-Policy
Refresh
X-Logged-In
X-Original-Request-Id
X-Response-Served-From
VIX-Pulpo-Upstream-Status
Amp-Access-Control-Allow-Source-Origin
X-Mobile
SD-X-WS
VIX-Pulpo-Node
X-Load-Cache
X-Jobs
X-Real-IP
X-Rendered-As
X-Vgn-Hpd-Reason
X-Is-Bot
X-Cache-Expired-At
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Varnish-Backend
X-IPLB-Instance
X-Browser-Type
X-Oracle-Dms-Ecid
X-Oracle-Dms-Rid
X-Origin-Upstream-Status
X-Yottaa-Metrics
Access-Control-Request-Headers
NGB
X-Debug
X-Cacheable-TTL
X-B
X-Yottaa-Optimizations
X-Revision
X-Proxy-Cache-Status
X-Rule
X-Cache-Action
Surrogate-Key
X-UUID
X-Device-Type
X-Proxy
X-Page-View
Akamai-GRN
X-Framework
X-G
X-FW-Version
X-Drupal-Cache-Contexts
X-Debug-IsPreview
X-Debug-IsConnected
X-Instance
X-Cache-Time
X-ProcessESI
X-RemovedCookies
X-Accel-Buffering
SID
CF-IPCountry
GEO-INFO
X-Cache-NGX
Count-Hit
X-RateLimit-Limit
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
Uber-Trace-Id
X-Presslabs-Stats
X-Nginx-Cache
X-Air-Hostname
X-Air-Source
X-Source
X-Ratelimit-Remaining
X-Cache-Operation
X-Air-Trace-Id
Protected
X-Azure-Ref
X-Oneagent-Js-Injection
X-APP-VERSION
X-Ms-Version
X-Ms-Request-Id
X-Zen-Fury
X-Trace-Id
X-PressLabs-Stats
X-EdgeConnect-Cache-Status
X-Servername
WPO-Cache-Message
WPO-Cache-Status
X-XRDS-Location
Frame-Options
DynaTrace
X-Cache-Hit
X-Hyper-Cache
X-RTag
X-Cache-TTL-Remaining
Healthy
Liferay-Portal
MS-CV
Ms-Operation-Id
Ec-Rule-Version
X-Backend-Name
X-IPS-LoggedIn
Content-Disposition
Countrycode
Cross-Origin-Window-Policy
X-Adobe-Loc
X-CDN-Forward
X-Adobe-Content
X-L-Path
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Tumblr-User
Backend
X-Tumblr-Pixel-1
Xserver
X-Cache-Grace
Url
X-Environment-Context
X-Varnish-Server
Retry-After
X-UPSTREAM-Address
X-Tid
X-RN-RSRV
Meta-Geo
X-Rewrite-Enabled
X-Detected-As
X-Debug-Cache
X-Content-Age
X-Shopify-Stage
X-Format
X-SaId
X-Uri
X-Generation-Time
Country-Code
Cache-Name
LB
X-Mode
Decoy-Debug-Key
X-Sorting-Hat-ShopId
X-ShardId
Eomportal-Instance
X-Cache-Server
X-Sorting-Hat-PodId
X-FB-TRIP-ID
X-Alternate-Cache-Key
X-ShopId
X-JoinUs
Decoy-Debug-TTL
Decoy-Debug-Status
X-Redis-Cache
Apigw-Requestid
X-Akamai-Edgescape
X-ApacheServer
X-UA-Device-Type
Mn-Server-Ip
X-Access
X-Human
CDN-RequestId
X-Region
X-NYM-Debug-Backend
CDN-RequestCountryCode
X-OCL
X-Via-Fastly
X-ServerID
X-Sql-Count
CDN-Uid
X-Site-Version
X-NCache
X-Say-Cacheable
X-Sql-Duration-Ms
X-No-Session
X-Microcachable
CDN-PullZone
X-Origin-Date
X-Forwarded-Host
CDN-EdgeStorageId
X-Hosted-By
X-PERF
X-PHP-Backend
X-PCL
CDN-Cache
CDN-CachedAt
X-Web-Node
X-Section
X-SayCDN-TTL
X-Generated-By
X-Say-TTL
TWC-Connection-Speed
Property-Id
Fastly-SSL
TWC-Device-Class
Selected-Fe
X-Status
X-ProxyCache-Status
X-Proxy-Build
X-ProxyCache-Key
X-Content-Powered-By
X-Origin-Hint
X-Server-W
X-Timing-Wait
X-Storage
X-Pubstack
X-Cluster-Node
X-Cache-Type
Webcakes-App-Name
TWC-Privacy
TWC-Locale-Group
Webcakes-App-Version
Webcakes-Region
X-Cache-Host
X-BYPASS-REASON
X-Be
TWC-GeoIP-LatLong
TWC-GeoIP-Country
Cache-Tv-Group
X-NewRelic-App-Data
X-Soup
X-Varnishpool
X-Varnish-Beresp-Grace
X-R9-Blue-Green-Version
X-Routing-Service
X-Zipkin-Id
X-Nginx-Cache-Key
X-Extlb
X-Hl-Ver
X-Proxied
Content-Secure-Policy
Azure-Version
Azure-RegionName
Azure-SlotName
Azure-InstanceId
Azure-SiteName
Section-Io-Cache
X-Unique-Id
X-TIME
X-Ua
X-Cache-Remote
X-LSADC-Cache
X-Webkit-CSP
X-Platform-Server
DB-Nickname
X-Cached-By
X-Azure-Ref-OriginShield
X-Bc-Bl
X-Dc
X-Cache-Tags
Cache
From-Origin
OT-Force-Account-Verify
X-TT-LOGID
X-Akamai-Transformed
X-Xfnlog-Site
ServedBy
X-GEO
Upgrade-Insecure-Requests
X-AOL-HN
Source
X-Auto-Login
X-Varnish-Cache-Hits
X-ECache
X-NWS-UUID-VERIFY
HostName
Xet-Cookie
X-LAGOON
X-Origin-TTL
Mime-Version
X-Origin-CC
X-Varnish-Ttl
X-Request-Time
X-CSRF-Token
X-Cdn
SRV
WP-Super-Cache
X-Request-Host
Cache-Hits
X-Akamai-Request-ID2
X-Varnish-Hits
X-TNCMS
S-Rt
X-Varnish-Hostname
X-Loop
X-Http-Reason
X-Cache-Enabled
X-S-Maxage
Webserver
Onion-Location
X-SRV
X-Time
X-FireWall-Port
X-Handled-By
X-HTML-Minification-Powered-By
X-Xrds-Location
X-App-Version
X-RCS-CacheZone
X-Endurance-Cache-Level
X-Tumblr-Pixel-2
X-Tumblr-Pixel-3
Web-Mar-Node
X-Adobe-Source
X-Reqid
Server-Info
N-Cache
X-Mg-Request-UUID
X-EC-Lua
X-Magnolia-Registration
X-B3-SpanId
X-Origin-Response-Time
X-GG-Cache-Date
X-NAPM-TraceId
X-Vtex-Remote-Cache
X-Hnp-Log
X-PBS-Appsvrname
X-PAYTM-SRV-ID
X-External-Request-Id
DCR-Processing-Time-Ms
X-Locale
BehaviorPad-Version
X-Gen-Mode
X-Developer
DCR-Decision-By
A
X-ARC
X-ND-Cache
Meta-Geo-Continent
Expiry
X-Epic-Correlation-Id
Nel
X-Forwarded-Path
X-Destination
X-Orig-Expires
Mobile-Detection-Method
X-VG-WebCache
X-Ig-Push-State
X-Vtex-Processado-Em
Fastcgi-X-Cache-Version
X-Ftr-Request-Id
Odigeo-Trace-Id
X-D
X-Connection-Hash
Sslversion
X-Session-Fingerprint
X-V-Cache
X-Shop-Environment
X-Aed
Pramga
X-Backend-TTL
X-Cache-NE
X-S-Cookie
X-ScT
X-Proto
X-SD-PageType
X-A-Wwc
User-Cache-Control
X-A-Dcw
X-Block-Status
X-A-Dam
X-A-Ccd
X-Tenant
X-A-Dgt
X-SRCache-Key
V-Age
X-Slack-Backend
Vix-Hermes-Req-Id
X-TIM-N
X-A
X-S
X-Processor
X-B-Cookie
X-Conf
X-Rojux
X-Correlation-ID
Rendered-Blocks
X-Ckpd-Fst-Backend
X-CF-Lambda-Version
Xc-Version
X-Vdms-Version
X-Planisys-CDN-Rules
X-Application
X-Planisys-CDN-Cache
Surrogated-Key
X-Planisys-CDN-TTL
X-Vdms-Path
X-CF-Lambda-Fn
X-GeoIP-Country-Code
DSUID
Cmstype
X-Forwarded-Site
X-Gdpr
Cmsid
X-Aicache-OS
CDCHOST
X-Geo-Header
CacheControlHeader
True-Client-Country-4JS
State
Origin-CC
Svr
X-Cdn-Srv
X-Cdn-Origin
Origin-EX
Arc-Country
Redirect-Candidate
X-Cluster
X-Webstats-RespID
X-Core-Mission
X-Cache-Info
X-Device-Os
Wxu-Next-Commit
X-Fastly-Cache
X-Fetched-On
Wxu-Next-Hostname
X-Cache-Bucket
X-Fastly-Backend
Host-ID
Traceparent
X-Cache-Date
Gh-Request-Id
Wxu-Next-Region
X-NodeID
X-Origin-Time
X-VG-TLSProxy
X-Sn-Servicetimems
X-Nyt-Route
X-Scheme
X-Origin-Expires
X-Server-IP
X-SVT-ORM-VERSION
X-Men
X-Mvc-Supplant-Cachable
Apple-News-Services-Request-Url
X-SVT-ORM-RULES
X-Edge-Location
X-Location
X-Viewer-Country
X-Proxy-Upstream
AKAMAI
X-GeoIP-Region-Code
Apple-News-Services-Handled
X-Request-URI
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
X-Time-Microsecs
X-Restarts
X-Rocket-Nginx-Serving-Static
X-Hash
X-Old-Content-Length
X-MP-GENERATED-AT
X-Origin
X-LJ-Flow-ID
Fastly-Drupal-Html
Accept-Language
Environment
X-Labrador-Cache-Channel
X-PHP-Host
X-Amz-Meta-S3cmd-Attrs
X-VWS-Id
X-AWS-Id
X-Response-By
X-Sigma
X-Rocket-Build-Number
X-Served-From
X-Cache-Id
X-Sucuri-Cache
X-Worker
X-Variation
X-UnsetCookies
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-VarnishDD-TTL
X-ATG-Version
X-Varnish-Remaining-TTL
X-TrackingId
X-BBC-Edge-Cache-Status
X-Storefront-Renderer-Rendered
X-Skip-Cache
X-Sigma-Backend
X-Branch-Name
X-Req
X-Thinkindot-L3
X-TH-Server
X-Sucuri-ID
X-Cache-Debug
X-Core-Value
X-Li-Pop
X-Li-Fabric
X-Level-Front-Cache
X-FC-Vary-Parameters
X-LI-UUID
X-Esi-Check
X-Eu-Site
X-Loc
X-JWT-State
X-Is-Gdpr
X-Generated-On
X-GeoIP
X-GeoIP-City
X-Gzip
X-Has-Esi
X-Gamma-Serve
X-HS-Content-Campaign-Id
X-HN
X-Envoy-Decorator-Operation
X-DPWN-IS-SECURE
X-Platform
X-Owner
X-Csrf-Jwt
X-Policy
X-Qloud-Router
X-Rebelmouse-Surrogate-Control
X-CGP
X-Rebelmouse-Cache-Control
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
X-Node-Id
X-Developers
X-VServer
X-DefHash
X-DefElseHash
X-Datadog-Trace-Id
X-Date
X-Region-Sid
Machine
Release
Platform
PFcat
Origin
Req-Svc-Chain
Fastly-SIE
Ssr
X-Via-NSCOPI
Server-Host
Mail-Subject
Fastcgi-Cache-TTL
HA-Ipaddr
Ha-Gx-Prefs
Fastly-SWR
Is-Eu
Fastly-GeoIP-CountryCode
Locid
L5d-Success-Class
L
TDXMobile
CloudFront-Viewer-Country
X-VC-Cache
X-Irp-Debug
We-Hiring
Web-Mar-Region
Adler-Geo
X-Accel-Expires-Debug
AMP-Access-Control-Allow-Source-Origin
Cf-Device-Type
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
Thinkindot-Control
X-Amz-Apigw-Id
X-Amzn-RequestId
Kp-EeAlive
X-Amzn-Remapped-Content-Length
X-DI
X-DSS
X-Pod-Name
X-Cache-Backend
X-DW
X-DB
NM-Fastcgi-Cache
X-RateLimit-Remaining-Second
X-RPM
Memcached
X-RPS
X-RateLimit-Limit-Second
X-RSL
X-Action
X-Wix-Viewer-Type
NGX
X-Tx-Id
X-Zone
X-Varnish-Beresp-Status
Edge-Cache
X-NU-AKA-ACS-Version
X-TraceId
X-Varnish-Beresp-Ttl
X-Ua-Device
X-Srv
CDN
X-CS
X-Up
X-LB-ID
X-Minions-Version
X-Urbn-Context-Path
Locale
X-NC
X-Urbn-Site-Id
X-CacheTTL
X-Mvc-Supplant-OutputCached
X-Backend-State
Magicmarker
X-Tb-Optimization-Total-Bytes-Saved
X-CACHE-KEY
X-Cache-Var
X-Cache-Var-Map
X-Optimistic-Header
X-Generated-In
Memory
Pics-Label
Env
X-Trace-ID
Ms-Author-Via
X-Request-Start
X-API-Version
Time
X-LB-NoCache
X-TA-CDN-Provider
X-Via-Poph
X-Via-Popn
X-Via-Popv
X-Thanos
X-Bip
X-Tt-Logid
X-Refresh
X-Edge-Pop
X-Qnm-Cache
X-HA-Backend
X-User
X-M-Reqid
X-M-Log
X-DC
WebServer
X-Ec-Fail
X-Ec-GeoHdr
X-Parent-Response-Time
X-Cache-Config
X-Servedbyhost
GeoIp-Country-Code
X-ZONE
X-Esi
X-AK-Request-ID
Candidate-Md5Url
X-MSEdge-Features
X-Cs
Cdnsip
Server-ID
X-MSEdge-Flight
Cdncip
NtCoent-Length
X-Dynatrace
X-Fmm-Version
Cluster
X-WADP-Cache
My-App
X-Clara-WADP
X-TX-ID
X-Varnish-Beresp-TTL
DataCenter
Datacenter
X-CLOUD-TRACE-CONTEXT
Tracecode
X-Pass-Why
X-DynaTrace-JS-Agent
X-CUA
X-Traceid
X-VC
X-Var-Ttl
X-Webkit-CSP-Report-Only
X-Fpc
X-VCL-Version
X-Vc
T-Server
On-Server
WWW-Authenticate
Geoip-Latitude
Lfy
X-App
Lang
X-Fragments
X-LI-Proto
X-Cache-Ttl
X-From
Esi-Enabled
X-B3-Spanid
Cf-Int-Pingora-Origin-Digest
X-URL
X-Li-Proto
X-Webkit-Csp-Report-Only
Target-Params
X-FPC
X-Provided-By
X-Datadome
X-WP-CF-Super-Cache-Cache-Control
X-Cache-PHP
Proxy-Connection
C-Via
X-Service
X-Vcl-Version
X-WP-CF-Super-Cache
X-NODE
Fastly-Drupal-HTML
X-RAMCache
X-Cache-Status-Check
X-Unique-ID
Geo-Info
X-Newrelic-Synthetics
X-Mcache
Permissions-Policy
M-TraceId
Test
Server-Id
X-Api-Version
X-Httpd
Resin-Trace
X-Proxy-Cache-Info
X-LiteSpeed-Cache-Control
X-Render-Time
WZWS-RAY
X-CSRF-TOKEN
Servername
X-ID
Producers
X-Ha-Backend
X-SB
GeoIP-Country-Code
MIME-Version
X-ServedByHost
FSS-Cache
X-Cdn-Forward
X-Udemy-Cache-App-Namespace
Hostname
Hit
X-Platform-Processor
X-Platform-Router
X-Platform-Cluster
X-Clientip
X-Pool
X-Dynatrace-Js-Agent
X-Geo
X-Via-PopV
X-Via-PopH
X-RateLimit-Reset
X-Via-PopN
X-Scale
X-Edge-POP
X-Ec-Custom-Error
X-Pad
ENV
MD5-Digest
X-Edge-Cache
X-Dispatcher-Number
X-NGINX-Cache
X-Fastly-Backend-Reqs
Section-Io-Id
Sever-Int
Server-Hostname
X-Oss-Object-Type
X-Akamai-Path-Stats
X-Oss-Storage-Class
X-Via-Ucdn
X-Oss-Server-Time
X-Oss-Request-Id
X-Oss-Hash-Crc64ecma
Section-Io-Origin-Status
X-LiteSpeed-Tag
Server-Ext
UCS
X-ElasticPress-Query
X-Cms-Context
HIT
Cache-Host
X-Ucs
X-Lb-Nocache
Section-Origin-Responded
PICS-Label
Section-Io-Origin-Time-Seconds
X-Newrelic-App-Data
X-UP
S-Cnection
X-HS-Status
X-Cache-CFC
X-BBC-Origin-Response-Status
Uri
Cneonction
Cf-Ipcountry
X-Nc
IsBot
X-Acquia-Site
ServerName
X-Check-Cacheable
URI
X-Acquia-Application-Trace
X-Acquia-Application-UUID
X-Acquia-Purge-Tags
X-GoCache-CacheStatus
X-SIPLIST1
X-Cache-Expires
X-AIR-PT
X-MG-S
X-Srcache-Fetch-Status
X-Srcache-Store-Status
X-Info
Server-Ttl
X-Yottaa-OS
X-Lb-Id
X-Cdn-Request-ID
X-Fastly-Cache-Hits
X-Swift-Error
X-Fetch-By
X-Wikidot-Backend
X-Wikidot-Static-Cache
Tcn
X-Dw-Trace-Id
Vha6-Origin
CF-Cached-On
X-Micro-Cache
X-Amz-Meta-Cb-Modifiedtime
X-WA-Info
X-Release
User-Agent
Ohc-File-Size
Fastly-Backend-Name
X-B3-ParentSpanId
X-Vcache
Cteonnt-Length
Ngx
X-Akamai-ERPolicy
X-Snapshot-Date
Wpo-Cache-Message
Wpo-Cache-Status
X-Akamai-ERRuleID
X-GeoCountry
X-Air-Pt
X-GeoCode
X-Cache-Ngx
Sid
X-HostName
VNS-Age
VNS-Cache
Inserted-Into-Cache-At
X-BCube-Filmed-By
X-Litespeed-Cache-Control
X-Sentry-ID
X-IN-APIGATEWAYSSL
CPC-Age
Client
Cache-Key
CPC-Cache
Path
GeoIP-Latitude
X-Apw-Hits
X-Akamai-Request-ID
X-Logging-Id
X-Te-Duration-Ms
X-CacheKey
X-UA
X-Last-Modified
X-Akamai-Pragma-Client-IP
CountryCode
X-Te-Count
X-Shopify-Generated-Cart-Token
X-B3-Parentspanid
X-Http-Count
X-Backend-Host
Req-ID
X-Apw-Access-Token
X-Http-Duration-Ms
X-Apw-Access-Action
X-Apw-Access-Object
X-IN-APIGATEWAY