Threat Level: green Handler on Duty: Guy Bruneau

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Link
Cf-Request-Id
CF-Cache-Status
Accept-Ranges
CF-RAY
ETag
X-XSS-Protection
Expect-CT
Pragma
X-Powered-By
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-UA-Compatible
X-Cache-Hits
Alt-Svc
P3P
X-Served-By
X-Xss-Protection
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Cache-Status
X-Generator
X-Cacheable
Timing-Allow-Origin
X-Request-ID
P3p
X-Content-Security-Policy
X-Iinfo
Status
Feature-Policy
X-Envoy-Upstream-Service-Time
Content-Encoding
Access-Control-Expose-Headers
X-CDN
X-Drupal-Dynamic-Cache
X-AspNetMvc-Version
Upgrade
X-Via
CF-Ray
Access-Control-Max-Age
X-Ws-Request-Id
Server-Timing
EagleId
Keep-Alive
X-Cache-Group
X-Turbo-Charged-By
Request-Context
X-Age
X-Server-Powered-By
X-Proxy-Cache
X-UA-Device
X-AH-Environment
X-Backend
X-Hacker
X-Robots-Tag
Report-To
X-Amz-Request-Id
Host-Header
X-Server
X-LiteSpeed-Cache
X-Amz-Id-2
Grace
X-Rq
X-Nginx-Cache-Status
X-Varnish-Cache
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-Dns-Prefetch-Control
X-WebKit-CSP
X-Page-Speed
X-Vhost
EagleEye-TraceId
X-Amz-Version-Id
X-OneAgent-JS-Injection
X-Pingback
X-Device
X-Dispatcher
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Cache-Spec
NEL
X-Server-Id
X-Host
X-Backend-Server
X-Node
Cf-Railgun
X-Readtime
Accept-CH
X-Akam-SW-Version
Surrogate-Control
Request-Id
X-Response-Time
X-HW
X-Language
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Xkey
Accept-Ch-Lifetime
X-Application-Context
X-Template
Content-Location
Rating
X-Ruxit-JS-Agent
X-Ua-Compatible
X-Country
X-B3-TraceId
X-Cloud-Trace-Context
X-Cache-Lookup
X-Buckets
X-Ac
X-Url
X-Content-Type
Allow
X-Trace
X-TtlSet
X-Vname
X-PC
Accept-CH-Lifetime
X-Mod-Pagespeed
X-Varnish-TTL
X-Clacks-Overhead
Edge-Control
Cache-Tag
X-ESI
X-FastCGI-Cache
Fastly-Restarts
X-Server-Name
Service-Worker-Allowed
X-Rack-Cache
X-VARITI-CCR
X-Element-Page-Cache
Verso
X-MS-InvokeApp
X-GitHub-Request-Id
X-Upstream
X-Amz-Rid
MS-Author-Via
Public-Key-Pins
X-Vcap-Request-Id
X-Dw-Request-Base-Id
X-Cached
X-D2id
X-Client-IP
X-Origin-Cache
X-Abt-Application-Version
X-Cache-TTL
Arr-Disable-Session-Affinity
X-ORACLE-DMS-ECID
X-Cnection
X-ORACLE-DMS-RID
Accept-Ch
X-Country-Code
X-Powered-By-Plesk
X-Aws-Lambda-Call-Status
X-Goog-Hash
Access-Control-Request-Method
X-Px
X-NF-Request-ID
X-Navigation-Version
X-Instrumentation
X-Version
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
RTSS
X-Amz-Server-Side-Encryption
X-Powered-CMS
Display
X-Middleton-Display
Pagespeed
X-Sol
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Middleton-Response
Response
X-Cdn-Fetch
X-GoogleNews-Bot
X-Exp-Variant
X-Exp-Id
X-Kinja
X-Kinja-Revision
X-Use-Magma
X-Kinja-Build
X-Kinja-Server
X-MSEdge-Ref
X-LLID
X-Edge
X-Edge-Location-Klb
X-Kinsta-Cache
X-TTL
Nginx-Cache
AR-CACHE
AR-PoweredBy
AR-SID
AR-ATIME
AR-Request-ID
MRF-Tech
X-B3-TraceId-Primal
Mrf-Cache-Status
X-Shield-Request-Id
S
X-HP-Trace-Id
X-HP-Webp
X-Jurisdiction
X-T
Content-MD5
X-CST
X-RateLimit-Remaining
X-Protected-By
X-Forwarded-For
TCN
X-Content-Security-Policy-Report-Only
X-Aspnetmvc-Version
X-Id
X-Mg-S
Fastcgi-Cache
X-Mid
X-MCACHE
Realpath
Edge-Cache-Tag
SPIisLatency
SPRequestDuration
Front-End-Https
X-Parallel-Accel
X-Recruiting
X-Request-Processing-Time
X-Request-Received
Filters
Server-Node
Pinterest-Version
X-Pinterest-Rid
X-Correlation-Id
Pinterest-Generated-By
Fusion-Content-Source
Fusion-Source
Fusion-Component-Id
Fusion-Template-Id
Fusion-Content-Id
Fusion-Deployment-Id
X-Ua-Browser
X-DynaTrace
X-Content
X-Ab
X-SharePointHealthScore
SPRequestGuid
X-Ruxit-Js-Agent
X-Ezoic-Cdn
X-Ttl
X-ECACHE
Server-Name
Alternate-Protocol
X-NWS-LOG-UUID
X-HS-Cache-Config
X-Frontend
X-HS-Combine-CSS
X-HS-Hub-Id
X-HS-Content-Id
X-Accel-Expires
X-Hits
X-Yandex-Sdch-Disable
X-Tt-Trace-Tag
X-Content-Options
X-Tt-Trace-Host
X-Cache-Key
MicrosoftSharePointTeamServices
Cache-Tags
X-Page-Id
Host
X-Git-Hash
Cleartype
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
Charset
X-B3-Sampled
X-Www-Served-By
X-Ser
X-Geo-Country
TP-L2-Cache
TP-Cache
X-Amz-Replication-Status
Filterid
X-Forwarded-Proto
X-Content-Digest
X-XRDS-LOCATION
X-Varnish-Age
X-Amzn-Trace-Id
X-Activity-Id
X-Az
X-Daa-Tunnel
X-Hostname
X-VCache
X-AppVersion
X-DIS-Request-ID
X-Rid
X-Fastly-Request-Id
X-Debug-Info
X-Upgrade-Enabled
X-Origin-Server
Access-Control-Allow-Method
X-Grace
X-N
X-Request-Handler-Origin-Region
X-Microsite
X-LB-Cache
X-FB-Debug
X-Origin-Upstream-Status
X-Nginx-Upstream-Cache-Status
ServerID
X-Mobile-URL
X-WebKit-CSP-Report-Only
X-Route-Name
X-Request-Guid
X-Is-Crawler
X-Flags
X-TT
X-Providence-Cookie
X-Whom
X-Aspnet-Duration-Ms
X-Server-ID
X-NGENIX-Cache
Cross-Origin-Opener-Policy
X-GUploader-UploadID
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Metageneration
X-F-Cache
X-Goog-Storage-Class
X-Tb
X-App-Server
X-App-Environment
X-Varnish-Grace
Viewport
Payment
X-Distributor
Paypal-Debug-Id
DC
X-FW-Dynamic
X-FW-Serve
X-FW-Hash
Node
X-FW-Type
X-FW-Static
X-FW-Server
X-PressLabs-Stats
X-Cache-Control
X-Logged-In
X-Oneagent-Js-Injection
X-Type
X-Seen-By
X-User-Agent
X-Cache-Age
Fastcgi-Useragent
X-Fastcgi-Cache
Accept-Charset
Country
X-Webkit-CSP
X-Fastly-Request-ID
X-Cache-Rule
X-Varnish-Backend
Version
X-Load-Cache
X-Browser-Type
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Node-Name
X-Wix-Request-Id
X-Cache-Action
Refresh
Referer-Policy
X-IPLB-Instance
X-Via-JSL
X-Response-Served-From
X-Vgn-Hpd-Reason
SD-X-WS
X-Original-Request-Id
Cache-Status
Access-Control-Request-Headers
X-Rendered-As
X-Cacheable-TTL
X-Real-IP
X-Is-Bot
X-Jobs
X-Proxy-Cache-Status
X-UUID
X-DataDome
X-Drupal-Cache-Tags
X-Page-View
X-Debug
X-Contextid
X-B
X-Cache-Expired-At
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-ProcessESI
X-Tec-Api-Version
X-Tec-Api-Origin
NGB
X-Tec-Api-Root
X-RemovedCookies
X-Ratelimit-Limit
X-Revision
X-Cluster-Name
X-B-Cache
X-Signature
X-Rule
Liferay-Portal
X-Device-Type
DynaTrace
X-Mobile
X-Proxy
X-Framework
X-G
X-Yottaa-Metrics
X-Yottaa-Optimizations
Akamai-GRN
X-Drupal-Cache-Contexts
X-Debug-IsPreview
X-Debug-IsConnected
Surrogate-Key
X-Cache-Time
X-Instance
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Azure-Ref
Amp-Access-Control-Allow-Source-Origin
Healthy
X-FW-Version
X-Air-Source
X-Air-Hostname
SID
X-Air-Trace-Id
X-Oracle-Dms-Ecid
X-Oracle-Dms-Rid
X-Source
CF-IPCountry
X-Ms-Request-Id
X-Ms-Version
Frame-Options
MS-CV
X-RTag
X-Cache-Hit
X-Nginx-Cache
Ms-Operation-Id
X-CDN-Forward
Section-Io-Cache
X-Environment-Context
X-Tumblr-Pixel
X-Tumblr-User
X-Tumblr-Pixel-0
X-L-Path
X-Tumblr-Pixel-1
Countrycode
X-XRDS-Location
Xserver
X-Varnish-Server
X-RateLimit-Limit
Count-Hit
X-Cache-Operation
X-Region
Uber-Trace-Id
X-EdgeConnect-Cache-Status
X-APP-VERSION
X-Forwarded-Host
X-Content-Powered-By
X-Backend-Name
X-Litespeed-Cache
X-Servername
X-Mode
Cross-Origin-Window-Policy
X-IPS-LoggedIn
GEO-INFO
X-Accel-Buffering
Backend
X-Adobe-Loc
Ec-Rule-Version
X-Adobe-Content
X-UPSTREAM-Address
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-ShardId
X-SaId
X-Shopify-Stage
X-JoinUs
X-Ratelimit-Reset
X-Alternate-Cache-Key
X-RN-RSRV
X-Detected-As
X-Zen-Fury
X-ShopId
Meta-Geo
Eomportal-Instance
X-Varnish-Beresp-Grace
X-Cache-Grace
X-Uri
X-Human
X-Cache-Type
X-Cache-TTL-Remaining
X-Cache-Server
X-Debug-Cache
X-Generation-Time
X-Redis-Cache
Country-Code
X-Microcachable
X-Via-Fastly
X-Tid
Decoy-Debug-Key
X-ProxyCache-Status
Cache-Name
Apigw-Requestid
Cache-Tv-Group
X-UA-Device-Type
Decoy-Debug-TTL
Decoy-Debug-Status
Mn-Server-Ip
X-Storage
X-No-Session
X-Site-Version
X-Sql-Count
X-NCache
X-Hosted-By
X-Cache-Host
X-ProxyCache-Key
X-Origin-Date
X-Sql-Duration-Ms
X-ServerID
X-BYPASS-REASON
X-PHP-Backend
X-Status
X-Proxy-Build
X-R9-Blue-Green-Version
TWC-Privacy
TWC-Locale-Group
Url
X-Akamai-Edgescape
TWC-GeoIP-LatLong
Webcakes-App-Version
X-FB-TRIP-ID
X-Format
X-OCL
TWC-GeoIP-Country
X-Timing-Wait
Property-Id
Protected
Selected-Fe
Webcakes-Region
X-PCL
TWC-Device-Class
DB-Nickname
X-Origin-Hint
TWC-Connection-Speed
Webcakes-App-Name
X-Time
OT-Force-Account-Verify
X-ApacheServer
X-Access
X-PERF
X-Hl-Ver
X-Azure-Ref-OriginShield
Fastly-SSL
X-Web-Node
X-Say-TTL
X-Extlb
X-Varnishpool
Azure-Version
Azure-SlotName
X-Rewrite-Enabled
X-Section
X-Routing-Service
X-SayCDN-TTL
X-Say-Cacheable
X-Server-W
X-Pubstack
Azure-RegionName
Azure-InstanceId
X-Zipkin-Id
X-Proxied
Azure-SiteName
X-Soup
X-LSADC-Cache
X-NYM-Debug-Backend
Content-Secure-Policy
X-Cluster-Node
Source
X-App-Version
X-Be
X-Ua
X-Webkit-Csp
X-Cache-NGX
X-Content-Age
X-HTML-Minification-Powered-By
X-NewRelic-App-Data
X-Cache-Var
CDN-CachedAt
CDN-Uid
CDN-Cache
CDN-EdgeStorageId
CDN-RequestCountryCode
CDN-RequestId
Content-Disposition
CDN-PullZone
X-Cache-Var-Map
X-Cached-By
X-TT-LOGID
X-Amz-Meta-S3cmd-Attrs
X-Dc
X-LAGOON
SRV
X-SRV
X-Bc-Bl
X-Generated-By
X-Unique-Id
Webserver
X-Varnish-Hits
X-Hyper-Cache
X-Varnish-Hostname
X-S-Maxage
Cache
Onion-Location
X-Presslabs-Stats
X-Nginx-Cache-Key
X-TNCMS
X-Loop
X-Auto-Login
Retry-After
Cache-Hits
Web-Mar-Node
X-Tumblr-Pixel-2
X-Origin-CC
X-Trace-Id
X-Tumblr-Pixel-3
Xet-Cookie
X-Origin-TTL
X-Cdn
LB
X-M-Reqid
X-M-Log
X-Endurance-Cache-Level
X-Tenant
X-Proto
X-Qnm-Cache
X-Akamai-Transformed
X-Time-Microsecs
X-GEO
X-Edge-Location
X-CSRF-Token
X-CACHE-KEY
X-GG-Cache-Date
HostName
X-VWS-Id
X-AWS-Id
X-LJ-Flow-ID
CloudFront-Viewer-Country
X-ECache
X-B3-SpanId
Mime-Version
X-Mg-Request-UUID
X-Platform-Server
X-Amz-Apigw-Id
X-Xfnlog-Site
X-Amzn-RequestId
AMP-Access-Control-Allow-Source-Origin
N-Cache
X-PHP-Host
X-Labrador-Cache-Channel
Upgrade-Insecure-Requests
X-Varnish-Cache-Hits
WPO-Cache-Message
WPO-Cache-Status
X-Cache-Tags
X-Storefront-Renderer-Rendered
X-Cache-Remote
X-RCS-CacheZone
Nel
ServedBy
X-Origin-Response-Time
X-Handled-By
X-Request-Time
X-Locale
X-Adobe-Source
X-AOL-HN
X-ND-Cache
X-V-Cache
X-NAPM-TraceId
X-Fastly-Cache
X-Cache-NE
X-External-Request-Id
X-Destination
X-D
X-TIM-N
A
X-Orig-Expires
X-Via-NSCOPI
X-Cache-Date
X-Gen-Mode
X-Vdms-Path
X-A
X-A-Ccd
X-Forwarded-Path
State
X-Ckpd-Fst-Backend
Xc-Version
Fastcgi-X-Cache-Version
X-Cluster
X-Ig-Push-State
User-Cache-Control
X-Hnp-Log
X-Conf
X-Vtex-Remote-Cache
X-Vtex-Processado-Em
X-VG-WebCache
Surrogated-Key
X-Vdms-Version
BehaviorPad-Version
X-Developer
Expiry
X-CF-Lambda-Version
X-CF-Lambda-Fn
X-A-Dam
Meta-Geo-Continent
X-A-Wwc
Odigeo-Trace-Id
X-Application
X-Connection-Hash
X-ARC
X-Shop-Environment
X-Session-Fingerprint
X-A-Dgt
X-Request-Host
X-SD-PageType
X-Aed
X-Rojux
X-S
X-Ftr-Request-Id
X-ScT
Origin
DCR-Processing-Time-Ms
X-Processor
X-B-Cookie
X-PBS-Appsvrname
Rendered-Blocks
X-SRCache-Key
DCR-Decision-By
X-PAYTM-SRV-ID
X-Block-Status
X-S-Cookie
X-SVT-ORM-RULES
X-Slack-Backend
Redirect-Candidate
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
DSUID
X-Planisys-CDN-Cache
X-A-Dcw
Pramga
X-SVT-ORM-VERSION
Mobile-Detection-Method
Environment
X-Reqid
X-ATG-Version
X-TIME
Server-Info
X-MP-GENERATED-AT
Release
X-Date
Wxu-Next-Region
Req-Svc-Chain
Wxu-Next-Commit
V-Age
CDCHOST
Vix-Hermes-Req-Id
Cmsid
Cmstype
Wxu-Next-Hostname
X-Accel-Expires-Debug
Host-ID
X-Cache-Info
X-Core-Value
Fastcgi-Cache-TTL
Gh-Request-Id
L
X-Cache-Debug
Origin-EX
CacheControlHeader
Origin-CC
X-BBC-Edge-Cache-Status
X-Cache-Bucket
X-Core-Mission
X-VC-Cache
X-Origin-Time
X-Owner
Traceparent
X-Policy
X-Device-Os
X-Old-Content-Length
X-Men
X-Mvc-Supplant-Cachable
X-Nyt-Route
X-Proxy-Upstream
X-Rocket-Nginx-Serving-Static
X-TH-Server
X-Varnish-Beresp-Status
X-VG-TLSProxy
X-Skip-Cache
X-Server-IP
X-Ratelimit-Remaining
X-Scheme
X-Served-From
X-Location
X-Origin-Expires
X-Hash
Arc-Country
X-Gdpr
X-Epic-Correlation-Id
X-Forwarded-Site
X-Geo-Header
AKAMAI
X-Fetched-On
From-Origin
X-Sucuri-ID
X-Sucuri-Cache
X-Sigma-Backend
X-Datadog-Trace-Id
X-Esi-Check
X-Sigma
X-Sn-Servicetimems
X-Thinkindot-L3
X-Viewer-Country
X-VServer
X-Webstats-RespID
True-Client-Country-4JS
X-Developers
We-Hiring
X-TrackingId
X-Envoy-Decorator-Operation
X-VarnishDD-TTL
Web-Mar-Region
X-Thanos
X-Request-Start
X-Gzip
X-HN
X-Cache-Id
X-NodeID
X-GeoIP-City
X-Cdn-Origin
X-LI-UUID
X-Irp-Debug
X-Level-Front-Cache
X-Li-Fabric
X-Li-Pop
X-GeoIP
X-Cache-Config
X-Gamma-Serve
X-Region-Sid
X-Req
X-HS-Content-Campaign-Id
X-Datadog-Sampling-Priority
X-Platform
X-Branch-Name
X-Generated-On
X-Bip
X-Datadog-Parent-Id
X-Rocket-Build-Number
X-Aicache-OS
PFcat
Server-Host
Apple-News-Services-Handled
Datacenter
X-Magnolia-Registration
Locid
NGX
Apple-News-Services-Request-Url
Mail-Subject
Machine
Apple-News-Services-Host
Fastly-GeoIP-CountryCode
Thinkindot-CacheControl
Svr
TDXMobile
Thinkindot-CacheControl-Type
Apple-News-Services-Parsed-Url
Candidate-Md5Url
X-EC-Lua
Thinkindot-Control
X-FireWall-Port
X-Xrds-Location
X-CS
X-Origin
L5d-Success-Class
X-Eu-Site
X-Zone
HA-Ipaddr
Memcached
X-Csrf-Jwt
X-Fastly-Backend
Fastly-SIE
Fastly-SWR
Cf-Device-Type
Ha-Gx-Prefs
X-CGP
X-Loc
X-Pod-Name
X-UnsetCookies
X-Rebelmouse-Surrogate-Control
X-Amzn-Remapped-Content-Length
X-Request-URI
Sslversion
X-Node-Id
X-Cdn-Srv
X-Backend-State
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
NM-Fastcgi-Cache
X-Rebelmouse-Cache-Control
X-Varnish-Beresp-Ttl
X-Correlation-ID
X-Variation
Adler-Geo
X-Up
X-Has-Esi
X-DPWN-IS-SECURE
X-Varnish-CookieHashed-On
WWW-Authenticate
X-Varnish-Remaining-TTL
X-DefHash
X-DefElseHash
X-FC-Vary-Parameters
X-Varnish-CookieINHashed-On
X-Worker
X-Datadome
X-CLOUD-TRACE-CONTEXT
X-Mvc-Supplant-OutputCached
X-NU-AKA-ACS-Version
Is-Eu
On-Server
Ssr
Platform
X-Is-Gdpr
X-JWT-State
X-Qloud-Router
X-Tx-Id
X-Response-By
WP-Super-Cache
Pics-Label
Fastly-Drupal-Html
CDN
X-LB-ID
Esi-Enabled
X-API-Version
X-Generated-In
X-Trace-ID
X-Vc
X-NC
Ms-Author-Via
X-Backend-TTL
X-LB-NoCache
X-Service
Memory
NtCoent-Length
X-Refresh
Time
X-Cache-Enabled
C-Via
X-TA-CDN-Provider
X-DynaTrace-JS-Agent
X-GeoIP-Region-Code
X-Cache-PHP
X-GeoIP-Country-Code
X-Via-Popn
X-Via-Poph
X-Edge-Pop
X-Via-Popv
X-NWS-UUID-VERIFY
X-Varnish-Ttl
X-Dynatrace
X-TraceId
X-Tb-Optimization-Total-Bytes-Saved
Magicmarker
X-Tt-Logid
Env
X-Render-Time
X-Cache-Status-Check
X-Optimistic-Header
X-DC
GeoIp-Country-Code
X-Parent-Response-Time
X-Srv
X-Esi
X-CacheTTL
X-Restarts
Kp-EeAlive
X-Info
X-Unique-ID
X-TX-ID
Server-ID
X-ZONE
X-Varnish-Beresp-TTL
X-Servedbyhost
S-Rt
X-DI
X-Cache-Backend
X-MSEdge-Flight
X-Action
X-RSL
X-RPM
X-RPS
X-AIR-PT
X-MSEdge-Features
Edge-Cache
X-DSS
X-DW
X-DB
Proxy-Connection
X-Clientip
X-Cs
X-Wix-Viewer-Type
WebServer
X-Cache-Ttl
X-HA-Backend
HIT
X-VCL-Version
X-App
Cache-Host
X-Oss-Object-Type
X-Minions-Version
X-Newrelic-Synthetics
UCS
X-Oss-Storage-Class
X-Oss-Request-Id
X-Oss-Server-Time
X-Oss-Hash-Crc64ecma
Geo-Info
X-URL
S-Cnection
X-Webkit-Csp-Report-Only
X-Li-Proto
X-Fpc
Test
X-LI-Proto
Section-Io-Id
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
X-Traceid
Section-Origin-Responded
X-Akamai-Request-ID2
X-Vcl-Version
X-FPC
Lb
X-Http-Reason
X-LiteSpeed-Cache-Control
X-NODE
X-Webkit-CSP-Report-Only
Tcn
Server-Id
Fastly-Backend-Name
Accept-Language
X-Micro-Cache
User-Agent
X-B3-Spanid
X-Ec-GeoHdr
X-Backend-Host
X-Pass-Why
Fastly-Drupal-HTML
X-User
X-Pad
X-Ec-Fail
X-BCube-Filmed-By
X-Check-Cacheable
X-Urbn-Site-Id
Locale
X-Urbn-Context-Path
X-HostName
X-APP
Resin-Trace
X-Release
Cf-Int-Pingora-Origin-Digest
X-LiteSpeed-Tag
X-CSRF-TOKEN
X-Geo
X-ES-SERVER
X-BBC-Origin-Response-Status
X-ID
Hostname
MIME-Version
X-Ha-Backend
ENV
GeoIP-Country-Code
M-TraceId
Hit
X-WADP-Cache
X-Fmm-Version
X-Clara-WADP
X-ServedByHost
VNS-Cache
VNS-Age
Path
Cache-Key
CPC-Age
X-Amz-Meta-Cb-Modifiedtime
EpKe-Alive
CPC-Cache
Srv
Ohc-File-Size
X-WA
X-WA-Info
X-Dynatrace-Js-Agent
X-ElasticPress-Query
Cdnsip
My-App
X-AK-Request-ID
Cluster
Cdncip
X-Edge-POP
X-Via-PopV
X-Cdn-Forward
X-Via-PopH
X-Via-PopN
X-Api-Version
Load-Balancing
X-Edge-Cache
X-Wikidot-Backend
Shield-Pop
X-Wikidot-Static-Cache
X-NGINX-Cache
X-PJAX-URL
X-Cms-Context
Geoip-Latitude
Lfy
X-HS-Status
X-From
X-Var-Ttl
Tracecode
X-CUA
Pagetype
X-Akamai-Pragma-Client-IP
X-Hcs-Proxy-Type
URI
X-CCDN-Origin-Time
X-Via-Ucdn
T-Server
X-ServerName
MD5-Digest
X-CCDN-CacheTTL
X-Ucs
Server-Hostname
X-GoCache-CacheStatus
Sever-Int
IsBot
Server-Ext
X-Fastly-Cache-Hits
X-Mcache
X-Fastly-Backend-Reqs
X-RAMCache
X-VG-WebServer
X-SIPLIST1
Lang
X-Fragments
Cf-Ipcountry
Servername
X-UP
X-Dw-Trace-Id
X-TRACE-ID
X-VC
X-WP-CF-Super-Cache-Cache-Control
Target-Params
X-WP-CF-Super-Cache
WZWS-RAY
W
X-Lb-Id
X-Cache-Expires
X-RateLimit-Reset
Ohc-Cache-HIT
X-Nc
Cneonction
X-B3-ParentSpanId
Cdn
X-Cdn-Request-ID
X-Platform-Processor
X-Platform-Cluster
X-Contensis-Viewer-Groups
X-Platform-Router
X-Cache-ASPX
CF-Cached-On
X-Apw-Access-Token
X-Acquia-Application-UUID
X-Acquia-Purge-Tags
X-Acquia-Site
X-Acquia-Application-Trace
X-Provided-By
X-Swift-Error
X-Apw-Access-Object
X-Apw-Access-Action
X-Apw-Hits
X-Snapshot-Date
HitType
Dnion-Transfer-Encoding
PICS-Label
X-Akamai-Request-ID
Vha6-Origin
X-Yottaa-OS
X-Newrelic-App-Data
Uri
Cteonnt-Length
X-Cache-Ngx
DataCenter
Sid
X-Air-Pt
X-Te-Count
X-Last-Modified
X-Akamai-ERRuleID
X-Te-Duration-Ms
X-B3-Parentspanid
X-Http-Duration-Ms
X-Via-CDN
Server-Ttl
X-Akamai-ERPolicy
X-Sentry-ID
X-Cc-Via
X-CacheKey
Req-ID
X-UA
X-Logging-Id
CountryCode
X-Miniprofiler-Ids
X-Lb-Nocache
Ngx
X-Varnish-Authentication
X-Http-Count