Threat Level: green Handler on Duty: Guy Bruneau

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
Pragma
X-Powered-By
X-XSS-Protection
CF-RAY
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
P3P
Alt-Svc
X-Cache-Hits
X-UA-Compatible
X-Xss-Protection
X-Served-By
CF-Ray
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Request-Id
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
Access-Control-Allow-Credentials
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
X-Drupal-Cache
X-Generator
X-Cache-Status
X-Check
X-Cacheable
X-Envoy-Upstream-Service-Time
X-Request-ID
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-FRAME-OPTIONS
X-Iinfo
X-Dns-Prefetch-Control
X-Drupal-Dynamic-Cache
Feature-Policy
X-Content-Security-Policy
Content-Encoding
Access-Control-Expose-Headers
Upgrade
Status
X-CDN
X-AspNetMvc-Version
X-XSS-PROTECTION
Server-Timing
Access-Control-Max-Age
X-Amz-Request-Id
Request-Context
X-Amz-Id-2
X-Turbo-Charged-By
X-AH-Environment
X-Via
X-Robots-Tag
X-Backend
X-Cache-Group
Cf-Edge-Cache
Keep-Alive
Host-Header
X-Proxy-Cache
X-Hacker
X-Server
X-UA-Device
X-Rq
X-Server-Powered-By
X-Age
Allow
X-Vhost
X-Varnish-Cache
X-Ws-Request-Id
EagleId
X-Amz-Version-Id
X-Dispatcher
Grace
X-LiteSpeed-Cache
P3p
Cf-Apo-Via
Nel
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Page-Speed
Cf-Railgun
X-Device
EagleEye-TraceId
X-Aws-Lambda-Call-Status
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
Accept-CH
X-Pingback
X-Host
X-WebKit-CSP
X-Node
X-OneAgent-JS-Injection
X-Server-Id
Surrogate-Control
X-Backend-Server
X-CST
X-Readtime
X-Nginx-Cache-Status
X-Akam-SW-Version
X-Cache-Lookup
X-Content-Security-Policy-Report-Only
Permissions-Policy
Request-Id
X-Application-Context
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Nginx-Upstream-Cache-Status
X-Cloud-Trace-Context
X-Trace
X-Response-Time
X-Edge
X-HW
Accept-Ch-Lifetime
Accept-CH-Lifetime
X-Ua-Compatible
Content-Location
X-Mod-Pagespeed
X-Clacks-Overhead
X-Url
X-Ruxit-JS-Agent
X-Midtier
X-Oneagent-Js-Injection
X-ECACHE
X-ESI
X-Amz-Server-Side-Encryption
Rating
X-Mcache
X-Country
Xkey
X-Litespeed-Cache
X-Upstream
X-PC
X-TtlSet
X-Vname
X-Vcap-Request-Id
X-D2id
Cache-Tag
X-MS-InvokeApp
X-Rack-Cache
X-Exp-Id
X-GoogleNews-Bot
X-Kinja-Server
X-Kinja
X-Kinja-Revision
X-Element-Page-Cache
X-Exp-Variant
X-Use-Magma
Verso
X-Cdn-Fetch
X-Kinja-Build
Edge-Control
RTSS
X-Cache-TTL
Fastly-Restarts
X-Powered-By-Plesk
X-VARITI-CCR
Origin-Trial
X-Content-Type
X-Navigation-Version
X-Ac
Accept-Ch
X-Abt-Application-Version
X-Cached
X-Ruxit-Js-Agent
X-Goog-Hash
Service-Worker-Allowed
X-Country-Code
X-GitHub-Request-Id
X-Ttl
Pagespeed
X-Middleton-Display
Display
X-Sol
X-Amz-Rid
X-WebKit-CSP-Report-Only
X-Browser-Type
X-Dw-Request-Base-Id
X-Mg-S
X-SharePointHealthScore
SPRequestGuid
X-Server-Name
Cross-Origin-Opener-Policy
X-Varnish-TTL
X-B3-TraceId
Arr-Disable-Session-Affinity
X-Erf-Bev-Bev-Is-Generated
X-Instrumentation
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Erf-Bev-Bev
X-Powered-CMS
AR-SID
AR-PoweredBy
Response
X-Middleton-Response
AR-ATIME
AR-Request-ID
X-Amzn-Trace-Id
SPRequestDuration
SPIisLatency
X-Cache-Key
AR-CACHE
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Fastly-Request-ID
X-Webkit-CSP
X-Jurisdiction
X-HP-Webp
X-Version
X-HP-Trace-Id
X-Cnection
X-T
X-Accel-Expires
X-Times
Cache-Tags
Front-End-Https
Cache-Status
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
Edge-Cache-Tag
X-Client-IP
X-MSEdge-Ref
X-Pinterest-Rid
Pinterest-Version
Pinterest-Generated-By
X-Px
X-NF-Request-ID
X-Ser
X-Hits
Public-Key-Pins
Nginx-Cache
X-Fastcgi-Cache
X-Recruiting
X-NWS-LOG-UUID
Mrf-Cache-Status
X-Ua-Device
MRF-Tech
X-B3-TraceId-Primal
X-B3-Traceid
X-Frontend
X-Request-Received
X-LLID
X-Request-Processing-Time
Server-Node
Payment
X-Ua-Browser
X-Shield-Request-Id
X-FastCGI-Cache
Access-Control-Request-Method
X-Kinja-CCPA
X-DIS-Request-ID
X-Webkit-CSP-Report-Only
TP-Cache
X-Erf-Stays-Pdp-Viaduct-Migration-Web
X-RateLimit-Remaining
X-Ratelimit-Remaining
S
X-HS-Cache-Config
X-HS-Content-Id
X-Goog-Metageneration
X-HS-Combine-CSS
X-HS-Hub-Id
MicrosoftSharePointTeamServices
X-LB-Cache
TP-L2-Cache
X-Content-Digest
Content-MD5
X-PressLabs-Stats
X-Distributor
Realpath
X-Microsite
X-Request-Handler-Origin-Region
X-Ezoic-Cdn
X-Geo-Country
X-Hostname
Access-Control-Allow-Method
X-FB-Debug
X-RateLimit-Limit
Fastcgi-Cache
X-Page-Id
X-Server-ID
X-Forwarded-For
Accept-Charset
X-Cluster-Name
X-GUploader-UploadID
X-Rid
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Protected-By
X-Envoy-Decorator-Operation
X-Ratelimit-Limit
X-Seen-By
X-Correlation-Id
X-B3-Sampled
TCN
Cleartype
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
DC
X-Newrelic-App-Data
X-Goog-Generation
X-Origin-Server
X-Mobile
X-Debug-Info
Referer-Policy
X-XRDS-Location
X-Webkit-Csp
X-Varnish-Backend
X-Origin-Cache
Cross-Origin-Resource-Policy
X-Aspnet-Version
X-TTL
X-Logged-In
X-Git-Hash
X-Varnish-Grace
X-Contextid
X-Azure-Ref
X-Flags
X-Fb-Rlafr
X-Is-Crawler
X-Route-Name
X-Edge-Location-Klb
X-Grace
Alternate-Protocol
X-Providence-Cookie
X-Request-Guid
X-Amz-Replication-Status
X-Aspnet-Duration-Ms
X-Kinsta-Cache
X-Revision
X-Content-Options
Surrogate-Key
Count-Hit
X-App-Environment
X-TT
Healthy
X-Amz-Meta-S3cmd-Attrs
X-IPS-LoggedIn
X-Wix-Request-Id
X-Forwarded-Proto
X-Whom
X-App-Server
Charset
Frame-Options
WPO-Cache-Message
X-Akamai-Edgescape
WPO-Cache-Status
X-Hosted-By
MS-Author-Via
Viewport
Filterid
X-Daa-Tunnel
X-Magnolia-Registration
X-B
X-Id
X-Aspnetmvc-Version
X-Client-Ip
X-Backend-Name
Paypal-Debug-Id
Retry-After
X-Cache-Age
Section-Io-Cache
Amp-Access-Control-Allow-Source-Origin
X-F-Cache
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Trace-Id
X-Cache-Control
X-AppVersion
X-Az
SRV
X-Activity-Id
X-Www-Served-By
Server-Name
X-Proxy-Cache-Info
X-Type
X-Varnish-Server
X-Oracle-Dms-Ecid
X-Oracle-Dms-Rid
SD-X-WS
X-Cache-Rule
X-Original-Request-Id
X-App-Version
Refresh
VIX-Pulpo-Upstream-Status
X-Proxy
X-ARC
VIX-Pulpo-Node
X-Http-Reason
Host
X-Response-Served-From
X-Akamai-Request-ID2
X-Edge-Location
Version
Protected
X-Varnish-Age
X-UUID
X-Rule
Front
X-Time
X-Instance
X-Rocket-Nginx-Serving-Static
Akamai-GRN
X-Jobs
X-Unique-Id
X-L-Path
X-Region
X-Page-View
X-Cache-Grace
X-User-Agent
X-COUNTRY
From-Origin
X-Status
X-Environment-Context
X-Cacheable-TTL
Fastly-SWR
Fastly-SIE
Access-Control-Request-Headers
X-FW-Dynamic
X-FW-Static
X-FW-Type
X-Is-Bot
X-Rendered-As
X-FW-Server
X-FW-Serve
X-Adobe-Loc
X-Cache-Time
X-Framework
X-FW-Hash
X-Adobe-Content
X-FW-Version
X-EdgeConnect-Cache-Status
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-RemovedCookies
X-N
X-G
X-Tumblr-Pixel-1
X-ProcessESI
X-Tumblr-User
X-Load-Cache
X-Upgrade-Enabled
X-Source
X-Nf-Request-Id
X-Varnish-Ttl
X-RateLimit-Reset
Country
X-Language
ServerID
X-Datadog-Trace-Id
Content-Disposition
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
X-CDN-Forward
X-Drupal-Cache-Tags
X-Vcache
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-DataDome
X-HTML-Minification-Powered-By
Accept-Language
X-Datadog-Sampled
X-Tt-Trace-Host
X-Tt-Trace-Tag
Countrycode
X-Mg-Request-UUID
X-Amzn-Remapped-Content-Length
X-Debug-IsPreview
X-Debug-IsConnected
X-DynaTrace
X-ID
X-Generated-By
X-Xrds-Location
X-DynaTrace-JS-Agent
X-ECache
Xet-Cookie
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
X-B-Cache
X-Signature
Backend
CF-IPCountry
Liferay-Portal
Xserver
X-Nginx-Cache
X-B3-SpanId
X-Tt-Logid
X-Httpd
Webserver
X-Erf-Web-Scheduler
X-NYM-Debug-Backend
X-Device-Type
X-Mode
X-Content-Powered-By
X-Servername
X-Content-Age
Url
X-Zen-Fury
X-Drupal-Cache-Contexts
Load-Balancing
X-Git-Commit
Locale
Meta-Geo
X-JoinUs
Filters
X-GeoCountry
X-Varnish-Cache-Hits
X-SaId
X-SayCDN-TTL
X-GeoCode
X-Say-TTL
X-Rewrite-Enabled
Onion-Location
X-Container-Uri
X-Urbn-Context-Path
X-Say-Cacheable
X-Cache-Action
X-Proto
S-Rt
X-Cache-Operation
X-ServerID
X-UPSTREAM-Address
X-Urbn-Site-Id
Azure-InstanceId
X-Tb
X-Sucuri-ID
X-Varnish-Hostname
X-Sucuri-Cache
X-Director
Azure-RegionName
Uber-Trace-Id
X-Cluster-Node
X-Ratelimit-Reset
Fastcgi-Useragent
GEO-INFO
Azure-SiteName
X-Soup
Azure-SlotName
Azure-Version
X-Forwarded-Host
X-Ms-Version
X-Cache-Server
X-Served-From
X-Generation-Time
X-Labrador-Cache-Channel
X-Detected-As
X-VC-Cache
X-Adobe-Source
X-Ms-Request-Id
X-VCT
X-RM-Cache-TTL
X-Sql-Count
X-PHP-Host
X-Sql-Duration-Ms
Node
Property-Id
TWC-Connection-Speed
X-Extlb
Mn-Server-Ip
X-Storage
DB-Nickname
X-FB-TRIP-ID
TWC-Device-Class
TWC-Locale-Group
Webcakes-App-Version
Webcakes-Region
X-Debug
Webcakes-App-Name
Web-Mar-Node
TWC-GeoIP-LatLong
TWC-Privacy
X-Skip-Cache
TWC-GeoIP-Country
X-Routing-Service
X-LAGOON
X-Zipkin-Id
X-RCS-CacheZone
X-R9-Blue-Green-Version
X-Proxied
X-Origin-Hint
X-Logging-Id
X-Tumblr-Pixel-2
X-Tumblr-Pixel-3
Selected-Fe
X-Proxy-Build
X-Timing-Wait
X-LSADC-Cache
X-Uri
X-Tec-Api-Root
X-Tec-Api-Origin
X-Fetched-On
X-Format
X-Tec-Api-Version
X-Lambda-Id
CDN-RequestId
Fastly-Drupal-HTML
OT-Force-Account-Verify
X-Origin-Date
X-MP-GENERATED-AT
X-Template
Source
X-XRDS-LOCATION
X-MCACHE
X-Cache-Expired-At
X-Loop
X-Srv
X-Tncms
X-Pass-Why
X-Cache-Hit
X-Varnish-Hits
X-Endurance-Cache-Level
X-Via-JSL
Content-Secure-Policy
X-Cache-TTL-Remaining
X-NGENIX-Cache
X-UA-Device-Type
X-Redis-Cache
X-Ua
Upgrade-Insecure-Requests
X-Node-Name
X-Real-IP
X-Fastly-Request-Id
X-AIR-PT
X-Pubstack
Cross-Origin-Window-Policy
X-Origin-CC
X-Origin-TTL
X-CCDN-Origin-Time
X-CCDN-CacheTTL
X-Server-W
X-Hcs-Proxy-Type
Section-Origin-Responded
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
Section-Io-Id
X-GEO
NGB
Cache-Hits
X-PHP-Backend
X-S
X-Rn-Rsrv
MS-CV
Ms-Operation-Id
X-CSRF-Token
Cache-Name
X-RTag
X-IPLB-Request-ID
X-TimeS
X-Restarts
X-Reqid
X-Cache-Host
X-Cms-Context
X-Xfnlog-Site
Cache-Provider
X-Cache-Type
X-Optimistic-Header
X-Hl-Ver
X-IPLB-Instance
Apigw-Requestid
CDN-RequestPullSuccess
CDN-Uid
CDN-RequestPullCode
CDN-PullZone
X-Datadome
CDN-Cache
CDN-CachedAt
CDN-EdgeStorageId
X-Akamai-Transformed
CDN-RequestCountryCode
X-BYPASS-REASON
X-CACHE-AGE
X-No-Session
X-ProxyCache-Status
X-ProxyCache-Key
X-Parent-Response-Time
X-Application
Candidate-Md5Url
DCR-Processing-Time-Ms
X-Is-Gdpr
X-JWT-State
DCR-Decision-By
X-Nyt-Route
Redirect-Candidate
X-Orig-Expires
X-Worker
X-CF-Lambda-Fn
X-A-Wwc
X-Origin-Time
X-Conf
X-Cluster
X-Csrf-Jwt
X-Irp-Debug
X-Accel-Buffering
X-D
Xc-Version
X-Aed
X-Has-Esi
X-Forwarded-Path
X-Gdpr
X-Eu-Site
X-CF-Lambda-Version
X-FC-Vary-Parameters
X-Cache-NE
X-External-Request-Id
X-Fastly-Backend
BehaviorPad-Version
Canary
X-Epic-Correlation-Id
X-Bl-Debug
X-Developer
X-Destination
X-BCube-Filmed-By
X-Bc-Bl
X-Dispatcher-Number
X-Ec-Custom-Error
X-CacheTTL
X-Ec-GeoHdr
X-Ec-Fail
X-AWS-Id
X-B-Cookie
X-Via-Fastly
Vix-Hermes-Req-Id
Meta-Geo-Continent
N-Cache
True-Client-Country-4JS
X-Tenant
X-SRCache-Key
Fastly-SSL
X-Slack-Shared-Secret-Outcome
X-Slack-Backend
Magicmarker
X-Wix-Viewer-Type
W
Ngx.Var.Host
X-TIM-N
X-Vdms-Path
X-LJ-Flow-ID
X-Vdms-Version
Rendered-Blocks
X-Viewer-Country
Server-Host
Sslversion
Odigeo-Trace-Id
X-Vtex-Remote-Cache
T-Server
Surrogated-Key
X-Shop-Environment
MD5-Digest
X-Request-Host
X-A
X-Rojux
X-A-Dcw
Lang
Gh-Request-Id
X-A-Dam
HA-Ipaddr
X-A-Ccd
Ha-Gx-Prefs
L
X-S-Cookie
L5d-Success-Class
X-SD-PageType
X-Newrelic-Synthetics
X-CGP
X-VWS-Id
X-A-Dgt
X-ScT
Gannett-Cam-Experience-Id
X-Section
X-Handled-By
X-Access
X-Accel-Expires-Debug
X-Cdn-Origin
Release
TDXMobile
X-Cdn-Diag
Req-Svc-Chain
X-ApacheServer
VNS-Cache
X-Bip
X-Auto-Login
X-BBC-Edge-Cache-Status
Web-Mar-Region
We-Hiring
VNS-Age
X-Cache-Debug
X-Alternate-Cache-Key
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
Thinkindot-Control
X-App-Name
X-Cache-Info
X-GeoIP-Region-Code
X-Sn-Servicetimems
X-Shopify-Stage
X-ShopId
X-Wikidot-Static-Cache
X-Sorting-Hat-PodId
X-Storefront-Renderer-Rendered
X-Sorting-Hat-ShopId
X-ShardId
X-Server-IP
X-Qloud-Router
X-Pool
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-S-Maxage
X-Request-Time
X-Wikidot-Backend
X-SVT-ORM-RULES
X-Varnish-Remaining-TTL
X-Varnish-CookieINHashed-On
X-Varnish-CookieHashed-On
X-VServer
X-Varnishpool
X-VG-WebCache
X-VG-TLSProxy
X-Variation
X-Var-Ttl
X-SVT-ORM-VERSION
X-We-Are-Hiring
X-Test
X-Thanos
X-Up
X-Thinkindot-L3
X-Policy
X-Platform
X-Generated-On
X-Forwarded-Site
X-DPWN-IS-SECURE
X-Geo-Header
X-GeoIP-Country-Code
X-Hash
X-Vmg-Version
X-DefHash
X-DefElseHash
X-Core-Mission
X-CMSURLCustom
X-Core-Value
X-Date
X-Debug-Cache-Store
X-Debug-Cache-Fetch
X-Human
X-INCAP-ABP
X-App
X-Org
X-Origin-Response-Time
X-Owner
X-PERF
X-PAYTM-SRV-ID
X-Old-Content-Length
X-Node-Id
X-Loc
X-Level-Front-Cache
X-Mid
X-Mly-Id
X-Nitro-Cache
X-Mvc-Supplant-Cachable
X-Clientip
X-Cache-Bucket
Mail-Subject
Is-Eu
Host-ID
Memcached
Producers
X-Proxy-Cache-Status
X-TA-CDN-Provider
Fastly-GeoIP-CountryCode
Fastly-Backend-Name
Cmsid
AKAMAI
Adler-Geo
Cmstype
CPC-Age
Environment
CPC-Cache
Origin
Expect-Staple
Platform
User-Cache-Control
ServedBy
Server-Hostname
X-Origin
X-Cache-Id
CDCHOST
X-Hnp-Log
X-Gen-Mode
X-GeoIP
X-Gzip
Esi-Enabled
X-Akamai-Device-Characteristics
CloudFront-Viewer-Country
DSUID
Country-Code
X-Block-Status
X-Nginx-Cache-Key
Datacenter
Server-Ext
X-NodeID
X-From
Apple-News-Services-Host
X-Fmm-Version
NM-Fastcgi-Cache
Apple-News-Services-Handled
X-Device-Os
X-Dispatcher-Server
X-Presslabs-Stats
X-WA-Info
X-Clara-WADP
Machine
X-WADP-Cache
X-Cdn-Srv
Sever-Int
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
X-Scale
X-Esi-Check
X-Tx-Id
X-LB-NoCache
C-Via
X-Instance-Name
X-Cache-Enabled
Pics-Label
X-NCache
Ssr
Server-Info
X-Correlation-ID
Origin-CC
Wxu-Next-Region
Wxu-Next-Hostname
WP-Super-Cache
X-Web-Node
Wxu-Next-Commit
X-Op-Id-All
Origin-EX
X-Nananana
X-Mvc-Supplant-OutputCached
X-Cs
X-Refresh
X-Air-Hostname
X-Air-Trace-Id
X-Air-Source
X-Vcl-Version
X-TIME
Server-ID
Memory
Time
X-Azure-Ref-OriginShield
X-Amz-Meta-Cb-Modifiedtime
X-Cache-Status-Check
Hostname
X-HA-Backend
X-ZONE
X-API-Version
Cf-Device-Type
X-Microcachable
Origin-Agent-Cluster
X-Origin-Expires
X-Platform-Router
X-Platform-Processor
X-URL
X-Platform-Cluster
Cache-Host
GeoIP-Latitude
NGX
AMP-Access-Control-Allow-Source-Origin
X-VHOST
X-Dc
XM
X-CACHE-GROUP
X-Tb-Optimization-Total-Bytes-Saved
X-Locale
X-Site-Version
X-VarnishDD-TTL
PFcat
X-HN
X-Wp-Cf-Super-Cache-Active
X-Varnish-Beresp-Ttl
X-Varnish-Beresp-Grace
X-DC
X-Fpc
Resin-Trace
X-Ad-Defer-Variation
X-FL-EDGE
Edge-Copy-Time
X-FL-QIT-DEBUG
X-Webkit-Csp-Report-Only
X-Via-SSL
X-Vgn-Hpd-Reason
A
Cdn-Requestid
Srvid
X-Via-CDN
Locid
X-Internal-Host
X-Via-Edge
YJS-ID
X-Micro-Cache
Sid
X-WP-CF-Super-Cache-Active
X-Zone
X-Upstream-Ht
X-Upstream-Ct
X-Github-Request-Id
X-Cache-ASPX
X-Pod-Name
X-ATG-Version
X-Contensis-Viewer-Groups
X-TraceId
X-FireWall-Port
X-SIPLIST1
True-Client-Ip
IsBot
X-Moov-T
X-Moov-Xdn-Version
X-AB
Uri
User-Agent
X-Cached-By
X-DataCenter
X-Varnish-Authentication
Cache-Key
Location
X-LiteSpeed-Cache-Control
X-B3-Spanid
X-Info
GeoIP-Country-Code
X-B3-Parentspanid
X-Buckets
X-Geo-Region
X-Backend-Instance
State
X-NGINX-Cache
X-Accel-Version
X-FTR-Request-ID
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
X-Platform-Server
X-Planisys-CDN-TTL
X-Nitro-Rev
X-HS-Content-Campaign-Id
X-Nitro-Cache-From
X-LiteSpeed-Tag
X-Provided-By
X-MSEdge-Flight
X-MSEdge-Features
GeoIp-Country-Code
X-Datacenter
X-Release
X-Fastly-Cache
CF-Ctrl
X-VCache
SID
X-Cache-Remote
X-Is-Tablet
X-Rocket-Build-Number
X-RN-RSRV
X-Tcp-Rtt
X-CS
XServer
X-Is-Mobile
X-Is-Desktop
X-Browser-Name
Cdn
X-VC
X-Is-Supported-Browser
NtCoent-Length
X-Sigma-Backend
X-Sigma
X-CSRF-TOKEN
X-NewRelic-App-Data
Path
X-Vgn-Hpd-Cached
X-Vgn-Hpd-Variations-Key
True-Client-IP
X-Vgn-Hpd-Ssi
Cache
Lb
X-Geo
X-Api-Version
X-GeoIP-City
X-TRACE-ID
X-Hyper-Cache
X-Gamma-Serve
X-Generated-In
X-HS-Status
Epwk-X-Cache
X-Scheme
Fastly-Drupal-Html
X-FPC
X-HostName
Tcn
X-Service
Cache-Tv-Group
X-SRV
X-Webstats-RespID
X-GoCache-CacheStatus
Ohc-File-Size
Cf-Ipcountry
CountryCode
X-Rebelmouse-Cache-Control
Serverid
X-APP-VERSION
X-UA
X-Rebelmouse-Surrogate-Control
X-AK-Request-ID
X-Amz-Meta-Opti
Cdnsip
X-Air-Pt
X-Esi
Kp-EeAlive
X-Frame-Option
Cdncip
Srv
X-Guploader-Uploadid
X-Wp-Cf-Super-Cache
X-Pad
HostName
WebServer
X-Traceid
X-Cache-Ttl
X-Branch-Name
X-EC-Lua
X-Wp-Cf-Super-Cache-Cache-Control
X-Mobile-URL
X-Location
LB
X-Wp-Cf-Super-Cache-Cookies-Bypass
Env
X-Men
CacheControlHeader
X-Edge-Server
X-Vc
X-Cdn-Cache-Status
Cdn-Host
X-Developers
WZWS-RAY
X-Proxy-CacheRZ
Yak-Timeinfo
XkeyRZ
Cdn-Request-Time
X-Vercel-Cache
X-Cache-Tags
Proxy-Connection
X-Vercel-Id
On-Server
X-Region-Sid
X-Aicache-OS
Ohc-Cache-HIT
X-Origin-Cache-Key
CDN
X-TX-ID
X-CACHE-KEY
X-VCL-Version
X-Akamai-Pragma-Client-IP
X-CDN-Cache-Status
X-NMSegId
Tube-Return
X-FTR-Expires
X-Minions-Version
X-Cdn-Forward
V-Age
Tube-Get-Contents
X-Via-Popv
X-Via-Poph
Tube-Got-Results
M-TraceId
X-Via-Popn
Req-ID
X-Req
X-FTR-Cache-Status
X-Wa
Tube-Got-Eval
Mime-Version
X-FTR-Backend-Server
X-Servedbyhost
RNT-Machine
X-Country-Code-Real
Ngx
X-Edge-Pop
X-NWS-UUID-VERIFY
X-B3-Trace-ID
X-V-Cache
X-FTR-Backend
Click-Count-Error
Click-Count-Action-Start
X-Acquia-Purge-Cdn-Unconfigured
X-Nc
X-FTR-Balancer
Geoip-Latitude
X-Cache-FS-Status
X-LB-ID
RNT-Time
X-SB
X-Lb-Cache
X-Cdn-Request-ID
Content-Script-Type
X-Ha-Backend
Content-Style-Type
Server-Id
X-Ad-Load-Variation
X-WP-CF-Super-Cache-Cookies-Bypass
ENV
X-Fastly-Country-Code
WWW-Authenticate
CF-Cached-On
Cluster
X-TT-LOGID
PICS-Label
X-Lb-Nocache
X-MiniProfiler-Ids
X-User
X-IN-APIGATEWAY
X-Check-Cacheable
X-M-Reqid
X-Snapshot-Date
X-Edge-POP
X-M-Log
X-Acquia-Application-Trace
X-Request-Start
Pramga
X-Via-Ucdn
X-IN-APIGATEWAYSSL
X-Acquia-Application-UUID
X-Dw-Trace-Id
X-Acquia-Site
X-Scope-Id
X-Acquia-Purge-Tags
Yjs-Id
X-Varnish-Beresp-Status
X-Qnm-Cache
X-Request-URI
X-Shield-Cache-Expires
X-Cached-Since
CACHE-MISS-TO-ORIGIN
Inserted-Into-Cache-At
X-Fastly-Cache-Hits
X-Processor
X-Iauth-Set-Uid
X-APP
X-Fastly-Backend-Reqs
X-Ckpd-Fst-Backend
Vha6-Origin
X-Miniprofiler-Ids
X-TH-Server
X-RAMCache
Log-Origin
X-ElasticPress-Query
X-Litespeed-Cache-Control
Cneonction