Threat Level: green Handler on Duty: Daniel Wesemann

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
Accept-Ranges
CF-Cache-Status
Link
ETag
CF-RAY
Pragma
Expect-CT
X-Powered-By
X-XSS-Protection
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Report-To
NEL
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
Alt-Svc
X-UA-Compatible
P3P
X-Served-By
X-Xss-Protection
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Varnish
X-Request-Id
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
X-Runtime
X-AspNet-Version
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
CF-Ray
X-Cache-Status
X-Generator
X-Check
X-Cacheable
Timing-Allow-Origin
X-Request-ID
X-FRAME-OPTIONS
Feature-Policy
X-Iinfo
X-Content-Security-Policy
X-Envoy-Upstream-Service-Time
Content-Encoding
P3p
Status
X-CONTENT-TYPE-OPTIONS
X-CDN
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
X-AspNetMvc-Version
Upgrade
X-Via
X-XSS-PROTECTION
X-Ws-Request-Id
Access-Control-Max-Age
Server-Timing
X-Cache-Group
X-Turbo-Charged-By
X-Backend
EagleId
Keep-Alive
Request-Context
X-Age
X-Robots-Tag
X-Server
X-AH-Environment
X-UA-Device
X-Proxy-Cache
Host-Header
X-Amz-Request-Id
X-Amz-Id-2
X-Hacker
X-Dns-Prefetch-Control
Grace
X-Rq
X-Swift-SaveTime
X-Swift-CacheTime
X-Server-Powered-By
Ali-Swift-Global-Savetime
X-Varnish-Cache
X-Vhost
X-Ua-Compatible
CONTENT-SECURITY-POLICY
X-Amz-Version-Id
X-LiteSpeed-Cache
X-Dispatcher
EagleEye-TraceId
X-Nginx-Cache-Status
X-Akamai-Path-Stats
X-WebKit-CSP
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Cache-Spec
X-OneAgent-JS-Injection
X-Device
Cf-Railgun
X-Page-Speed
Allow
X-Host
X-Node
X-Pingback
X-Aws-Lambda-Call-Status
X-CST
Surrogate-Control
X-Backend-Server
Accept-CH
X-Server-Id
Request-Id
X-Akam-SW-Version
X-Readtime
X-HW
X-Cache-Lookup
X-Response-Time
X-Application-Context
Xkey
Content-Location
X-ASPNET-VERSION
Accept-CH-Lifetime
Rating
X-Cloud-Trace-Context
X-Trace
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Cf-Edge-Cache
X-Url
X-Country
Fastly-Restarts
Accept-Ch-Lifetime
X-Mod-Pagespeed
X-Vname
X-PC
X-TtlSet
X-MS-InvokeApp
X-Rack-Cache
X-Server-Name
X-Ruxit-JS-Agent
X-Clacks-Overhead
Edge-Control
RTSS
X-Content-Type
X-Varnish-TTL
X-ESI
X-VARITI-CCR
X-B3-TraceId
Cache-Tag
X-Vcap-Request-Id
X-Px
X-Exp-Variant
X-Kinja-Server
X-Use-Magma
X-Kinja-Revision
X-Kinja-Build
X-GoogleNews-Bot
X-Kinja
X-Exp-Id
X-Cdn-Fetch
X-Amz-Rid
X-Ac
Public-Key-Pins
X-Cnection
X-Dw-Request-Base-Id
X-Element-Page-Cache
X-RateLimit-Remaining
Accept-Ch
X-Amz-Server-Side-Encryption
Verso
X-D2id
X-Abt-Application-Version
X-Navigation-Version
X-Powered-By-Plesk
X-Cache-TTL
Service-Worker-Allowed
X-Client-IP
X-Ruxit-Js-Agent
X-Ser
X-Middleton-Display
Display
Pagespeed
X-Sol
X-Country-Code
X-GitHub-Request-Id
X-Version
Arr-Disable-Session-Affinity
X-Edge
X-FastCGI-Cache
Access-Control-Request-Method
X-Middleton-Response
Response
X-NF-Request-ID
X-Goog-Hash
X-Correlation-Id
AR-CACHE
AR-PoweredBy
AR-ATIME
AR-SID
AR-Request-ID
X-Upstream
X-Kinsta-Cache
X-Webkit-Csp
X-TTL
X-Edge-Location-Klb
X-Ttl
SPIisLatency
SPRequestDuration
X-RateLimit-Limit
X-Cached
X-LLID
X-NWS-LOG-UUID
X-Cache-Key
X-Instrumentation
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-Litespeed-Cache
Nginx-Cache
X-Powered-CMS
Edge-Cache-Tag
TCN
MS-Author-Via
MRF-Tech
Mrf-Cache-Status
X-Forwarded-For
X-SharePointHealthScore
SPRequestGuid
X-MSEdge-Ref
Content-MD5
X-Id
X-Shield-Request-Id
X-Content-Security-Policy-Report-Only
X-B3-TraceId-Primal
X-Daa-Tunnel
X-Server-ID
X-T
X-Recruiting
S
X-Mg-S
X-Ua-Device
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Content-Digest
X-Protected-By
X-HP-Trace-Id
X-HP-Webp
X-Jurisdiction
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-DataDome
X-Frontend
X-Ezoic-Cdn
X-Yandex-Sdch-Disable
X-Content
Front-End-Https
X-HS-Content-Id
X-Ua-Browser
X-HS-Cache-Config
Server-Node
X-HS-Hub-Id
MicrosoftSharePointTeamServices
X-Ab
X-HS-Combine-CSS
X-Accel-Expires
X-Request-Processing-Time
X-Request-Received
X-Grace
X-ECACHE
Filters
X-Mid
Fastcgi-Cache
X-Geo-Country
X-ORACLE-DMS-ECID
X-Hits
X-ORACLE-DMS-RID
X-Pinterest-Rid
Pinterest-Generated-By
X-Origin-Server
Pinterest-Version
X-Debug-Info
X-Distributor
TP-Cache
TP-L2-Cache
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Amzn-Trace-Id
X-PressLabs-Stats
Charset
Cleartype
X-Ratelimit-Reset
X-Page-Id
Host
X-F-Cache
X-Git-Hash
X-DIS-Request-ID
X-B3-Sampled
Cross-Origin-Opener-Policy
X-Www-Served-By
X-DynaTrace
X-Forwarded-Proto
X-LB-Cache
X-Cache-Age
Cache-Tags
Access-Control-Allow-Method
ServerID
X-Seen-By
X-Kong-Proxy-Latency
X-Oracle-Dms-Ecid
X-Aspnetmvc-Version
X-Language
X-Kong-Upstream-Latency
X-Request-Handler-Origin-Region
X-Microsite
Server-Name
X-Oracle-Dms-Rid
X-Cluster-Name
Accept-Charset
Realpath
X-Varnish-Age
X-Activity-Id
X-AppVersion
X-Az
Filterid
X-Rid
Cache-Status
X-Type
X-Content-Options
X-Mobile-URL
X-App-Environment
X-Via-JSL
X-WebKit-CSP-Report-Only
X-Upgrade-Enabled
X-Origin-Cache
X-Fastcgi-Cache
X-Varnish-Grace
Viewport
X-Fastly-Request-ID
X-User-Agent
Node
X-FB-Debug
Country
X-Wix-Request-Id
X-MCACHE
X-Tb
X-B-Cache
Protected
X-Drupal-Cache-Tags
X-Flags
X-Providence-Cookie
X-Request-Guid
X-Signature
X-Route-Name
X-Whom
X-Is-Crawler
X-Aspnet-Duration-Ms
X-TT
DC
X-NWS-UUID-VERIFY
Paypal-Debug-Id
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-GUploader-UploadID
X-Goog-Metageneration
X-Goog-Generation
X-VCache
Fastcgi-Useragent
X-Nginx-Upstream-Cache-Status
Retry-After
X-Varnish-Backend
X-Oneagent-Js-Injection
X-XRDS-LOCATION
X-Cache-NGX
X-B
Payment
X-Contextid
X-Amz-Replication-Status
X-XRDS-Location
X-Debug
X-Template
X-N
X-Logged-In
X-FW-Server
X-FW-Serve
X-FW-Dynamic
X-FW-Hash
WPO-Cache-Message
WPO-Cache-Status
X-FW-Type
X-FW-Static
Amp-Access-Control-Allow-Source-Origin
X-Load-Cache
X-Fastly-Request-Id
Surrogate-Key
X-Hostname
X-Node-Name
X-Cache-Control
X-Parallel-Accel
Count-Hit
X-Erf-Bev-Bev-Is-Generated
X-Mcache
X-Erf-Bev-Bev
X-Browser-Type
X-Response-Served-From
SD-X-WS
X-Original-Request-Id
Refresh
Healthy
X-Akamai-Request-ID2
X-Proxy
X-Is-Bot
X-Real-IP
X-Rendered-As
X-Zen-Fury
X-Revision
X-G
X-Jobs
VIX-Pulpo-Node
Uber-Trace-Id
X-Cache-Time
VIX-Pulpo-Upstream-Status
X-Framework
X-Cache-TTL-Remaining
X-Mobile
X-UUID
X-Page-View
X-Http-Reason
Akamai-GRN
X-Cacheable-TTL
X-Yottaa-Metrics
X-Amz-Meta-S3cmd-Attrs
X-Device-Type
X-Yottaa-Optimizations
X-Drupal-Cache-Contexts
X-Debug-IsConnected
X-Proxy-Cache-Status
NGB
X-Debug-IsPreview
Alternate-Protocol
X-Adobe-Loc
X-Adobe-Content
X-Instance
Content-Disposition
Access-Control-Request-Headers
X-Cache-Rule
X-Trace-Id
From-Origin
X-Vgn-Hpd-Reason
X-Source
X-IPLB-Instance
Url
X-Servername
X-B3-Traceid
Version
X-Cache-Grace
X-Cache-Expired-At
Accept-Language
X-Cache-Hit
Permissions-Policy
X-Varnish-Server
X-Environment-Context
Referer-Policy
X-L-Path
X-Mg-Request-UUID
X-FW-Version
Countrycode
X-App-Server
X-EdgeConnect-Cache-Status
X-NGENIX-Cache
X-Cache-Action
Cross-Origin-Window-Policy
X-Restarts
X-ECache
X-RTag
MS-CV
Ms-Operation-Id
X-IPS-LoggedIn
X-COUNTRY
Backend
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Tumblr-User
X-Tumblr-Pixel-1
Liferay-Portal
X-ProcessESI
X-RemovedCookies
X-NYM-Debug-Backend
X-Nginx-Cache
X-Hyper-Cache
Content-Secure-Policy
X-HTML-Minification-Powered-By
Frame-Options
CF-IPCountry
X-Ratelimit-Remaining
Upgrade-Insecure-Requests
X-Rule
X-RN-RSRV
X-Redis-Cache
Ec-Rule-Version
WP-Super-Cache
Meta-Geo
X-UPSTREAM-Address
X-Detected-As
X-Cache-Enabled
X-Cache-Server
X-Content-Age
X-OCL
Apigw-Requestid
X-FB-TRIP-ID
X-PCL
Section-Io-Cache
X-Cluster-Node
X-No-Session
Azure-RegionName
Azure-SiteName
X-UA-Device-Type
X-Storage
X-Site-Version
Azure-Version
X-Mode
X-Akamai-Edgescape
X-AOL-HN
Cache-Tv-Group
X-Sql-Duration-Ms
Locale
Azure-InstanceId
X-Uri
Webcakes-App-Name
X-Origin-Hint
TWC-Device-Class
TWC-GeoIP-Country
X-Sql-Count
X-PERF
TWC-Connection-Speed
X-Generated-By
X-Hosted-By
X-Region
TWC-GeoIP-LatLong
TWC-Locale-Group
X-PHP-Backend
Webcakes-Region
X-TT-LOGID
Webcakes-App-Version
X-Access
X-Origin-Date
TWC-Privacy
X-Format
X-ApacheServer
X-Section
X-Human
X-Web-Node
X-SayCDN-TTL
X-Say-TTL
X-Via-Fastly
X-Unique-Id
X-Server-W
X-Urbn-Context-Path
X-Urbn-Site-Id
X-Say-Cacheable
Mn-Server-Ip
X-Request-Time
Azure-SlotName
Property-Id
CDN-CachedAt
X-Cache-Type
X-Status
CDN-EdgeStorageId
X-Varnish-Cache-Hits
X-Platform-Server
S-Rt
X-Forwarded-Host
CDN-PullZone
X-Content-Powered-By
CDN-Cache
X-Cache-Tags
CDN-RequestId
X-Be
X-ProxyCache-Key
X-Nginx-Cache-Key
X-ProxyCache-Status
X-BYPASS-REASON
Webserver
CDN-RequestCountryCode
X-Debug-Cache
X-Xfnlog-Site
Fastly-SSL
CDN-Uid
X-Cache-Host
X-Webkit-CSP
X-SaId
X-Routing-Service
X-ServerID
X-ShardId
X-Shopify-Stage
Eomportal-Instance
X-Proxied
X-Extlb
X-Alternate-Cache-Key
X-Generation-Time
X-Hl-Ver
X-JoinUs
X-Sorting-Hat-PodId
X-ShopId
X-Ua
X-Zipkin-Id
X-Varnishpool
X-Tid
X-Sorting-Hat-ShopId
X-Accel-Buffering
X-Cache-Operation
X-Adobe-Source
X-Backend-Name
X-Proxy-Build
X-Timing-Wait
ServedBy
X-NewRelic-App-Data
Selected-Fe
X-Cache-Remote
X-Handled-By
X-Locale
X-PHP-Host
X-Labrador-Cache-Channel
X-GG-Cache-Date
X-Datadome
X-Rewrite-Enabled
Xserver
X-APP-VERSION
X-VWS-Id
SID
X-LSADC-Cache
X-AWS-Id
X-LJ-Flow-ID
X-App-Version
X-VC-Cache
X-Soup
X-Pubstack
SRV
X-Buckets
X-Cached-By
LB
X-CDN-Forward
X-Dc
Mime-Version
Fastly-Drupal-Html
Web-Mar-Node
Country-Code
X-Edge-Location
Decoy-Debug-TTL
X-Storefront-Renderer-Rendered
Decoy-Debug-Status
X-Reqid
Decoy-Debug-Key
X-Proto
X-Request-Host
X-GEO
X-Microcachable
X-Ratelimit-Limit
X-Cms-Context
X-Varnish-Hostname
Server-Info
X-Origin-CC
X-Origin-TTL
X-Ms-Request-Id
Onion-Location
X-Ms-Version
X-TA-CDN-Provider
Cache-Hits
Xet-Cookie
X-NCache
X-GeoCountry
X-CSRF-Token
X-Cluster
X-B3-SpanId
X-GeoCode
Load-Balancing
X-SRV
DynaTrace
X-Tumblr-Pixel-2
X-MP-GENERATED-AT
X-Bc-Bl
X-Tumblr-Pixel-3
X-Varnish-Hits
X-Air-Hostname
X-Air-Source
X-Air-Trace-Id
X-Midtier
Cache-Name
X-R9-Blue-Green-Version
X-Varnish-Beresp-Grace
X-Tx-Id
X-Endurance-Cache-Level
X-Envoy-Decorator-Operation
X-Origin-Response-Time
X-RCS-CacheZone
X-Connection-Hash
X-From
X-Forwarded-Path
X-Conf
X-Amzn-RequestId
X-Ec-Fail
X-Amz-Apigw-Id
X-Destination
X-Esi-Check
X-Ec-GeoHdr
X-Developer
X-External-Request-Id
X-D
X-Epic-Correlation-Id
BehaviorPad-Version
Fastcgi-X-Cache-Version
X-A
T-Server
X-A-Ccd
Expiry
X-A-Dgt
X-A-Dcw
X-A-Dam
Surrogated-Key
Host-ID
Odigeo-Trace-Id
NM-Fastcgi-Cache
Mobile-Detection-Method
Pramga
Lang
Sslversion
Rendered-Blocks
X-A-Wwc
DCR-Processing-Time-Ms
X-Ftr-Request-Id
X-B-Cookie
X-ARC
X-Cache-Bucket
X-Cache-Id
X-CF-Lambda-Fn
X-Cache-NE
A
Cdncip
Cdnsip
Cmstype
DB-Nickname
DCR-Decision-By
Cmsid
X-Aed
X-Application
X-AK-Request-ID
X-CF-Lambda-Version
X-VG-WebCache
X-SRCache-Key
X-Orig-Expires
X-PAYTM-SRV-ID
X-PBS-Appsvrname
X-Vtex-Processado-Em
X-NodeID
X-Men
X-Webstats-RespID
Meta-Geo-Continent
X-Shop-Environment
Xc-Version
X-ScT
X-Rojux
X-S
X-S-Cookie
X-SD-PageType
X-Processor
X-Vdms-Path
X-Session-Fingerprint
X-Vdms-Version
X-Magnolia-Registration
X-NAPM-TraceId
X-Ig-Push-State
X-Gzip
X-TrackingId
X-Tenant
X-TIM-N
X-User
X-Vtex-Remote-Cache
X-Hash
X-LAGOON
X-Via-NSCOPI
X-Azure-Ref
X-Varnish-Ttl
X-Server-IP
Producers
X-Variation
X-WADP-Cache
X-Block-Status
X-Varnish-CookieINHashed-On
X-Scheme
Apple-News-Services-Handled
Platform
X-V-Cache
X-Slack-Backend
X-SB
X-Wix-Viewer-Type
Web-Mar-Region
User-Cache-Control
Vix-Hermes-Req-Id
We-Hiring
X-SVT-ORM-VERSION
Svr
X-Sigma-Backend
X-Sigma
V-Age
X-TNCMS
X-SVT-ORM-RULES
X-Varnish-Remaining-TTL
State
X-Cdn-Srv
Apple-News-Services-Parsed-Url
X-Fmm-Version
X-HS-Content-Campaign-Id
Apple-News-Services-Request-Url
X-Irp-Debug
X-Fetched-On
X-Mvc-Supplant-Cachable
X-Loop
X-Fastly-Cache
X-Hnp-Log
X-VG-TLSProxy
X-Gen-Mode
X-Varnish-CookieHashed-On
X-Gdpr
X-Viewer-Country
X-Geo-Header
Wxu-Next-Region
Wxu-Next-Hostname
X-GeoIP
X-DPWN-IS-SECURE
X-Node-Id
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-Ckpd-Fst-Backend
Wxu-Next-Commit
X-Request-URI
X-Cache-Info
X-Rocket-Build-Number
Apple-News-Services-Host
X-Clara-WADP
X-Planisys-CDN-Cache
X-DefElseHash
X-DefHash
X-Device-Os
X-Nyt-Route
X-Old-Content-Length
X-Origin-Time
X-Origin-Expires
X-Origin
X-Cache-Backend
X-Core-Mission
Memcached
Adler-Geo
Fastly-GeoIP-CountryCode
Is-Eu
Machine
Environment
Mail-Subject
Source
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-Core-Value
X-Region-Sid
X-CGP
CDCHOST
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
X-RateLimit-Remaining-Second
X-Csrf-Jwt
X-Response-By
X-Cdn-Origin
AKAMAI
Arc-Country
X-Branch-Name
Cache
X-Cache-Date
X-BBC-Edge-Cache-Status
X-RPS
X-RSL
X-Datadog-Trace-Id
X-Rocket-Nginx-Serving-Static
X-RateLimit-Limit-Second
X-GeoIP-City
X-Minions-Version
X-Gamma-Serve
X-Forwarded-Site
X-Pod-Name
X-Has-Esi
X-HN
X-Is-Gdpr
X-JWT-State
X-Loc
X-Location
X-Httpd
X-Eu-Site
X-Ec-Custom-Error
X-Proxy-Cache-Info
X-DI
X-Proxy-Upstream
X-Qloud-Router
X-Served-From
X-DSS
X-DW
X-Developers
X-Platform
X-Policy
X-Pool
X-DB
X-RPM
Traceparent
X-Time
Ha-Gx-Prefs
X-VarnishDD-TTL
PFcat
Origin-EX
X-Sn-Servicetimems
Locid
HA-Ipaddr
Kp-EeAlive
Release
Redirect-Candidate
L5d-Success-Class
L
Req-Svc-Chain
HostName
X-Amzn-Remapped-Content-Length
Server-Host
Fastly-SWR
X-Worker
CloudFront-Viewer-Country
N-Cache
X-Aicache-OS
Fastly-SIE
Cluster
X-VServer
Origin
X-Skip-Cache
Origin-CC
X-Tec-Api-Root
X-CS
CDN
X-Tec-Api-Version
X-Tec-Api-Origin
X-Optimistic-Header
NGX
MD5-Digest
Ssr
X-Generated-On
X-Auto-Login
Gh-Request-Id
X-TIME
X-Accel-Expires-Debug
X-Thinkindot-L3
X-Level-Front-Cache
Fastcgi-Cache-TTL
Thinkindot-CacheControl-Type
Thinkindot-Control
X-EC-Lua
DSUID
X-Date
TDXMobile
Thinkindot-CacheControl
X-TraceId
X-Parent-Response-Time
X-Udemy-Cache-App-Namespace
X-GeoIP-Country-Code
X-ZONE
X-GeoIP-Region-Code
Pics-Label
X-Srv
X-Akamai-Transformed
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
X-CacheTTL
X-Dispatcher-Number
X-VC
X-Owner
GEO-INFO
X-SIPLIST1
X-Ah-Environment
X-LB-NoCache
X-API-Version
X-Via-Ucdn
IsBot
X-Scale
Env
Server-Ext
Server-Hostname
Sever-Int
X-NC
Servername
X-Tb-Optimization-Total-Bytes-Saved
Ms-Author-Via
Time
X-Refresh
X-RateLimit-Reset
X-Cache-Debug
X-Mvc-Supplant-OutputCached
AMP-Access-Control-Allow-Source-Origin
Memory
X-Generated-In
X-Newrelic-Synthetics
Fusion-Component-Id
Fusion-Content-Source
Fusion-Content-Id
Fusion-Deployment-Id
Fusion-Source
Fusion-Template-Id
X-Presslabs-Stats
Geo-Info
CacheControlHeader
X-Wikidot-Static-Cache
X-Edge-Pop
X-Wikidot-Backend
X-Xrds-Location
X-Tt-Logid
Candidate-Md5Url
X-Ad-Defer-Variation
X-BCube-Filmed-By
X-Via-Poph
X-Via-Popv
X-Via-Popn
Datacenter
X-Action
Ohc-File-Size
X-TH-Server
Cache-Key
True-Client-Country-4JS
X-Servedbyhost
X-IPLB-Request-ID
X-Contensis-Viewer-Groups
CPC-Age
GeoIp-Country-Code
X-Amz-Meta-Cb-Modifiedtime
CPC-Cache
X-Trace-ID
X-Cache-ASPX
X-S-Maxage
X-Backend-TTL
X-HA-Backend
VNS-Age
X-SplitTest
VNS-Cache
XM
FSS-Cache
X-Varnish-Authentication
X-VCL-Version
X-DC
ITXSESSIONID
Client
X-WA-Info
Path
X-Vc
Server-ID
X-Provided-By
Geoip-Latitude
X-Micro-Cache
Edge-Cache
X-Dynatrace
X-Varnish-Beresp-TTL
X-Req
Fastly-Backend-Name
X-VHOST
X-Cache-Status-Check
X-AIR-PT
X-CACHE-KEY
My-App
X-Zone
X-Cs
Cache-Host
Hostname
X-Pass-Why
X-Origin-Upstream-Status
Ohc-Cache-HIT
X-Up
Ngx.Var.Host
X-Fpc
DataCenter
True-Client-IP
X-Webkit-Csp-Report-Only
X-LB-ID
NtCoent-Length
Lb
X-TX-ID
X-FireWall-Port
X-Webkit-CSP-Report-Only
XkeyRZ
X-Proxy-CacheRZ
X-Clientip
X-Traceid
X-LI-UUID
X-FPC
Test
X-Li-Pop
OT-Force-Account-Verify
X-Li-Fabric
Powered-By
X-Varnish-Beresp-Ttl
X-B3-Spanid
X-NGINX-Cache
Cf-Int-Pingora-Origin-Digest
X-Cdn-Request-ID
X-CSRF-TOKEN
X-ND-Cache
X-Api-Version
X-UnsetCookies
X-Correlation-ID
X-Beluga-Trace
X-Time-Microsecs
X-Beluga-Record
User-Agent
X-Beluga-Status
X-Beluga-Response-Time
X-Beluga-Node
X-CUA
X-Beluga-Cache-Status
Resin-Trace
WZWS-RAY
Server-Id
X-Dmc
X-RAMCache
Tracecode
X-Vcl-Version
Cf-Device-Type
Proxy-Connection
X-Fragments
X-MSEdge-Flight
Target-Params
X-MSEdge-Features
X-CLOUD-TRACE-CONTEXT
X-Azure-Ref-OriginShield
X-Platform-Cluster
X-Sucuri-ID
X-Sucuri-Cache
X-HS-Status
X-Var-Ttl
X-Render-Time
Uri
X-Fastly-Backend
X-FC-Vary-Parameters
Lfy
X-URL
X-B3-Traceid-Primal
GeoIP-Latitude
X-Via-PopN
X-Via-PopV
X-Platform-Router
X-Platform-Processor
X-ATG-Version
X-Via-PopH
X-Ha-Backend
GeoIP-Country-Code
X-Geo
Sid
Srvid
Rip
C-Via
X-INCAP-ABP
X-ServedByHost
X-PX
MIME-Version
X-Fetch-By
Tube-Return
X-Service
X-Gateway-Request-Id
X-Gateway-Cache-Key
X-Gateway-Skip-Cache
X-LI-Proto
X-Gateway-Cache-Status
Epwk-X-Cache
X-Proxy-Cache-Hk
X-NU-AKA-ACS-Version
X-Li-Proto
X-Varnish-Beresp-Status
X-Alfa-Service
X-M-Reqid
X-Qnm-Cache
X-Hcs-Proxy-Type
X-CCDN-Origin-Time
Click-Count-Error
Tube-Get-Contents
Tube-Got-Eval
Click-Count-Action-Start
X-DynaTrace-JS-Agent
X-CCDN-CacheTTL
X-M-Log
Tube-Got-Results
X-TRACE-ID
X-Check-Cacheable
Fastly-Drupal-HTML
X-Akamai-Pragma-Client-IP
Cdn
X-Client-Ip
X-Fastly-Backend-Reqs
Esi-Enabled
X-Backend-State
Magicmarker
X-Backend-Host
ENV
X-Esi
X-Cdn-Forward
X-Cache-Ttl
XServer
X-Edge-POP
X-Request-Start
On-Server
HIT
X-App
X-Cache-Expires
X-Cache-CFC
Srv
X-MG-S
X-Srcache-Fetch-Status
X-LiteSpeed-Cache-Control
X-Srcache-Store-Status
Tcn
Section-Io-Origin-Time-Seconds
X-Newrelic-App-Data
CF-Cached-On
X-Thanos
Section-Origin-Responded
X-ElasticPress-Query
PICS-Label
ServerName
X-Bip
X-Yottaa-OS
Section-Io-Origin-Status
X-Lb-Nocache
Section-Io-Id
Server-Ttl
X-Acquia-Purge-Tags
X-Iplb-Instance
X-BBC-Origin-Response-Status
X-Acquia-Site
D-Url-Rewrites
X-Iplb-Request-Id
X-Serial
X-Acquia-Application-Trace
Inserted-Into-Cache-At
X-Acquia-Application-UUID
Cf-Ipcountry
Wpo-Cache-Status
Wpo-Cache-Message
X-Vcache
X-APP
X-Nc
X-HostName
Warning
Servedby
X-UA
X-Akamai-ERPolicy
X-Akamai-ERRuleID
X-Fastly-Cache-Hits
X-Snapshot-Date
X-Akamai-Request-ID
Ngx
Hit
X-Litespeed-Cache-Control
Cneonction
X-Wp-Cf-Super-Cache
M-TraceId
Fastcgi-Cache-Ttl
True-Client-Ip
X-Wp-Cf-Super-Cache-Cache-Control
X-Request-URL
X-Back
X-Swift-Error
X-Th-Server
Content-Style-Type
Content-Script-Type
CountryCode
X-Release
X-Dw-Trace-Id
X-Dist-Code
X-Storefront-Renderer-Verified
X-Shopify-Generated-Cart-Token
X-Cache-Config
X-IN-APIGATEWAYSSL
X-IN-APIGATEWAY
X-B3-Parentspanid
X-CF-Powered-By
X-LiteSpeed-Tag
X-Request-Url