Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
X-Powered-By
Pragma
CF-RAY
X-XSS-Protection
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
Alt-Svc
X-Xss-Protection
P3P
X-Cache-Hits
X-UA-Compatible
X-Served-By
CF-Ray
X-Download-Options
X-Timer
X-Request-Id
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
Access-Control-Allow-Credentials
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
X-Drupal-Cache
X-Cache-Status
X-Generator
X-Check
X-Cacheable
X-Envoy-Upstream-Service-Time
X-FRAME-OPTIONS
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Iinfo
X-Dns-Prefetch-Control
X-Request-ID
X-Drupal-Dynamic-Cache
Feature-Policy
Server-Timing
X-Content-Security-Policy
Access-Control-Expose-Headers
Content-Encoding
X-CDN
X-XSS-PROTECTION
Status
Upgrade
X-AspNetMvc-Version
Access-Control-Max-Age
X-Amz-Request-Id
X-Via
X-Amz-Id-2
Request-Context
X-Turbo-Charged-By
X-Backend
X-Cache-Group
X-AH-Environment
X-Robots-Tag
Cf-Edge-Cache
Keep-Alive
Host-Header
X-Hacker
X-UA-Device
X-Proxy-Cache
X-Vhost
X-Server
X-Rq
X-Server-Powered-By
Allow
X-Ws-Request-Id
X-Age
X-Dispatcher
X-Varnish-Cache
EagleId
X-Amz-Version-Id
X-LiteSpeed-Cache
P3p
Nel
Grace
Cf-Apo-Via
Cf-Railgun
X-Page-Speed
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Device
EagleEye-TraceId
X-Swift-SaveTime
X-Swift-CacheTime
X-Aws-Lambda-Call-Status
Ali-Swift-Global-Savetime
X-OneAgent-JS-Injection
X-Pingback
X-Host
X-Node
Accept-CH
X-Cache-Lookup
X-CST
X-WebKit-CSP
X-Backend-Server
X-Server-Id
Surrogate-Control
X-Readtime
Permissions-Policy
X-Nginx-Cache-Status
X-Nginx-Upstream-Cache-Status
X-Akam-SW-Version
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
Request-Id
X-Application-Context
Accept-CH-Lifetime
X-Content-Security-Policy-Report-Only
X-Cloud-Trace-Context
X-Response-Time
X-HW
X-Ua-Compatible
X-Trace
Xkey
X-Ruxit-JS-Agent
X-Edge
Content-Location
X-Clacks-Overhead
X-Mod-Pagespeed
X-Url
Rating
X-ESI
X-Midtier
X-Oneagent-Js-Injection
X-Amz-Server-Side-Encryption
X-ECACHE
X-Mcache
Accept-Ch-Lifetime
Cache-Tag
X-Country
X-MS-InvokeApp
X-Rack-Cache
X-Upstream
X-D2id
X-Powered-By-Plesk
X-Vcap-Request-Id
X-Exp-Id
X-Cdn-Fetch
Verso
X-Exp-Variant
X-Kinja
X-Kinja-Server
X-Kinja-Revision
X-Kinja-Build
X-GoogleNews-Bot
X-Use-Magma
X-Element-Page-Cache
Accept-Ch
Edge-Control
Service-Worker-Allowed
X-TtlSet
X-PC
X-Vname
RTSS
X-Ac
X-Country-Code
X-Webkit-CSP
Origin-Trial
X-Goog-Hash
X-VARITI-CCR
X-Navigation-Version
X-Abt-Application-Version
Fastly-Restarts
X-Cache-TTL
X-Ruxit-Js-Agent
X-WebKit-CSP-Report-Only
X-GitHub-Request-Id
X-Browser-Type
X-Cached
X-Amz-Rid
X-Kinja-CCPA
X-Varnish-TTL
X-Aspnetmvc-Version
Cross-Origin-Opener-Policy
Pagespeed
X-Sol
Display
X-Middleton-Display
X-Server-Name
X-NWS-LOG-UUID
X-Dw-Request-Base-Id
X-Amzn-Trace-Id
X-SharePointHealthScore
SPRequestGuid
X-Ttl
X-Content-Type
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-Times
SPIisLatency
SPRequestDuration
X-Kraken-Loop-Name
X-Instrumentation
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Server-Lifecycle-Phase
X-Powered-CMS
AR-ATIME
AR-PoweredBy
AR-Request-ID
X-Cache-Key
AR-SID
Pinterest-Version
X-Pinterest-Rid
X-Mg-S
Pinterest-Generated-By
X-B3-Traceid
Arr-Disable-Session-Affinity
X-Middleton-Response
Response
X-Litespeed-Cache
X-Client-IP
X-Fastly-Request-ID
X-Version
X-Cnection
X-HP-Webp
X-HP-Trace-Id
X-Jurisdiction
X-Ser
AR-CACHE
X-FastCGI-Cache
Nginx-Cache
Cache-Tags
X-Accel-Expires
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-T
Cache-Status
Edge-Cache-Tag
X-B3-TraceId
X-Hits
X-MSEdge-Ref
Front-End-Https
X-RateLimit-Remaining
X-Px
Public-Key-Pins
X-NF-Request-ID
X-Recruiting
Payment
S
X-LLID
X-Frontend
X-Ua-Browser
X-Shield-Request-Id
X-B3-TraceId-Primal
Server-Node
Mrf-Cache-Status
MRF-Tech
X-RateLimit-Limit
X-Request-Received
X-Request-Processing-Time
X-Server-ID
X-GUploader-UploadID
Content-MD5
X-Goog-Metageneration
X-Daa-Tunnel
X-DIS-Request-ID
MicrosoftSharePointTeamServices
Access-Control-Request-Method
X-PressLabs-Stats
X-Content-Digest
X-Amz-Apigw-Id
X-Amzn-RequestId
TP-Cache
X-Webkit-CSP-Report-Only
Realpath
X-Protected-By
X-Request-Handler-Origin-Region
X-Microsite
X-Forwarded-For
X-HS-Combine-CSS
X-HS-Cache-Config
X-HS-Content-Id
X-HS-Hub-Id
X-Distributor
Fastcgi-Cache
X-FB-Debug
X-TTL
X-Fastcgi-Cache
Access-Control-Allow-Method
X-Page-Id
X-LB-Cache
Accept-Charset
X-Cluster-Name
X-Rid
X-Ratelimit-Remaining
TP-L2-Cache
X-Geo-Country
X-Hostname
X-Erf-Stays-Pdp-Viaduct-Migration-Web
X-Goog-Generation
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-B3-Sampled
X-Goog-Stored-Content-Length
X-Aspnet-Version
Count-Hit
X-Ua-Device
X-Seen-By
X-Ezoic-Cdn
Cross-Origin-Resource-Policy
Cleartype
X-Newrelic-App-Data
TCN
X-Kinsta-Cache
X-Edge-Location-Klb
X-App-Server
Referer-Policy
X-Varnish-Backend
X-Logged-In
X-Mobile
X-Correlation-Id
X-Ratelimit-Limit
X-Content-Options
DC
X-Id
X-Hosted-By
X-Git-Hash
X-Origin-Cache
X-Contextid
X-Aspnet-Duration-Ms
X-Request-Guid
X-Flags
X-Providence-Cookie
X-Is-Crawler
X-Fb-Rlafr
X-Route-Name
X-Amz-Replication-Status
X-Debug-Info
X-Revision
Surrogate-Key
X-Grace
X-TT
Retry-After
X-App-Environment
X-IPS-LoggedIn
X-Varnish-Grace
X-Amz-Meta-S3cmd-Attrs
X-Forwarded-Proto
Frame-Options
X-Xrds-Location
X-Envoy-Decorator-Operation
X-F-Cache
X-Azure-Ref
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-TEC-API-VERSION
Section-Io-Cache
X-RateLimit-Reset
X-Magnolia-Registration
X-Wix-Request-Id
X-Whom
MS-Author-Via
Healthy
Alternate-Protocol
Charset
X-Proxy-Cache-Info
X-Origin-Server
X-Akamai-Edgescape
Viewport
X-App-Version
X-Nf-Request-Id
X-Www-Served-By
X-Backend-Name
X-COUNTRY
X-Webkit-Csp
X-Language
X-Activity-Id
X-Az
X-AppVersion
Filterid
Paypal-Debug-Id
X-Varnish-Server
X-B
SRV
WPO-Cache-Status
WPO-Cache-Message
X-Http-Reason
X-Original-Request-Id
VIX-Pulpo-Node
X-Datadog-Trace-Id
X-Cache-Rule
X-Datadog-Sampling-Priority
X-Response-Served-From
VIX-Pulpo-Upstream-Status
X-Datadog-Parent-Id
SD-X-WS
Host
Server-Name
X-Instance
Akamai-GRN
X-User-Agent
X-UUID
X-Edge-Location
X-Cache-Grace
Front
X-Akamai-Request-ID2
X-Kong-Proxy-Latency
X-Rule
X-Kong-Upstream-Latency
X-Region
X-Cacheable-TTL
Protected
X-Environment-Context
X-Page-View
Amp-Access-Control-Allow-Source-Origin
X-Jobs
X-Varnish-Age
X-Unique-Id
X-Status
X-ARC
Country
X-Time
From-Origin
X-L-Path
X-FW-Type
Fastly-SIE
X-Is-Bot
Fastly-SWR
X-Adobe-Loc
X-Adobe-Content
X-Rendered-As
X-FW-Version
X-FW-Static
X-FW-Hash
X-FW-Dynamic
X-Rocket-Nginx-Serving-Static
X-FW-Serve
X-FW-Server
X-Framework
X-N
X-EdgeConnect-Cache-Status
X-Load-Cache
ServerID
X-Type
X-Trace-Id
X-Cache-Time
X-G
X-Client-Ip
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-RemovedCookies
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-ProcessESI
X-Tumblr-User
X-DataDome
X-Tumblr-Pixel-1
Content-Disposition
X-Tec-Api-Root
X-Tec-Api-Origin
X-Proxy
X-Tec-Api-Version
X-Mg-Request-UUID
Access-Control-Request-Headers
X-Datadog-Sampled
X-B-Cache
X-Signature
X-Vcache
X-Amzn-Remapped-Content-Length
X-Debug-IsConnected
X-Debug-IsPreview
X-CDN-Forward
X-Cache-Control
X-Cache-Age
X-ECache
Backend
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
Refresh
Countrycode
X-DynaTrace
X-Drupal-Cache-Tags
X-Nginx-Cache
X-Servername
Accept-Language
Xet-Cookie
X-Httpd
X-Erf-Web-Scheduler
X-Tt-Trace-Host
CF-IPCountry
Url
X-Tt-Trace-Tag
X-Generated-By
X-XRDS-LOCATION
X-DynaTrace-JS-Agent
X-Source
X-HTML-Minification-Powered-By
X-XRDS-Location
X-Template
X-Device-Type
X-Mode
Webserver
Xserver
X-NYM-Debug-Backend
X-Content-Powered-By
X-Storage
Version
GEO-INFO
X-Content-Age
X-Urbn-Context-Path
X-Urbn-Site-Id
X-GeoCountry
X-SayCDN-TTL
Meta-Geo
X-JoinUs
Locale
OT-Force-Account-Verify
X-Say-Cacheable
X-UPSTREAM-Address
X-Say-TTL
X-LAGOON
X-SaId
X-Rewrite-Enabled
Filters
X-Rn-Rsrv
X-Cache-Operation
X-ServerID
Load-Balancing
X-GeoCode
S-Rt
X-Cache-Action
X-Director
X-Cluster-Node
X-Git-Commit
X-Container-Uri
Onion-Location
X-Varnish-Hostname
X-Tt-Logid
X-Varnish-Cache-Hits
X-Soup
X-Forwarded-Host
X-Detected-As
X-Tncms
X-Cache-Hit
Azure-SiteName
Azure-SlotName
Azure-Version
Azure-RegionName
Azure-InstanceId
X-Adobe-Source
Web-Mar-Node
X-Sql-Count
X-Ms-Version
X-Ms-Request-Id
X-Lambda-Id
X-PHP-Host
X-Served-From
X-Loop
X-RM-Cache-TTL
X-Labrador-Cache-Channel
X-Sql-Duration-Ms
X-VC-Cache
X-Tb
X-Cache-Server
X-VCT
Node
X-URL
Mn-Server-Ip
X-Skip-Cache
X-Logging-Id
DB-Nickname
X-RCS-CacheZone
X-Zipkin-Id
X-Proto
X-Extlb
X-Routing-Service
X-CCDN-CacheTTL
X-FB-TRIP-ID
X-CCDN-Origin-Time
X-R9-Blue-Green-Version
X-Hcs-Proxy-Type
X-Generation-Time
X-Proxied
Cross-Origin-Window-Policy
TWC-Connection-Speed
TWC-GeoIP-LatLong
TWC-Device-Class
TWC-GeoIP-Country
X-Tumblr-Pixel-2
X-Fetched-On
TWC-Privacy
X-Proxy-Build
Webcakes-App-Name
X-Format
X-Uri
X-Debug
X-Tumblr-Pixel-3
X-Timing-Wait
Webcakes-Region
X-Origin-Hint
TWC-Locale-Group
Webcakes-App-Version
X-MCACHE
Property-Id
Fastcgi-Useragent
Selected-Fe
Uber-Trace-Id
X-Endurance-Cache-Level
X-LSADC-Cache
X-Zen-Fury
X-Ua
X-Redis-Cache
Source
X-Sucuri-Cache
X-Sucuri-ID
X-NGENIX-Cache
X-Srv
Section-Io-Origin-Status
CDN-RequestId
X-Drupal-Cache-Contexts
Section-Origin-Responded
Section-Io-Origin-Time-Seconds
Section-Io-Id
X-B3-SpanId
X-Oracle-Dms-Ecid
X-S
X-Oracle-Dms-Rid
X-Varnish-Ttl
X-Origin-Date
X-Pass-Why
X-Upgrade-Enabled
X-Ratelimit-Reset
X-MP-GENERATED-AT
X-TimeS
Fastly-Drupal-HTML
X-FTR-Request-ID
X-Cache-Expired-At
X-Origin-TTL
X-Origin-CC
X-Varnish-Hits
Upgrade-Insecure-Requests
Liferay-Portal
X-Real-IP
NGB
X-Newrelic-Synthetics
X-Handled-By
X-Akamai-Transformed
X-CACHE-AGE
X-UA-Device-Type
X-Cms-Context
X-Xfnlog-Site
X-Optimistic-Header
X-Cache-TTL-Remaining
Apigw-Requestid
X-Reqid
ServedBy
X-Hl-Ver
X-Cache-Type
X-Restarts
X-Via-JSL
X-Node-Name
X-Correlation-ID
CDN-PullZone
CDN-RequestCountryCode
CDN-EdgeStorageId
CDN-Cache
CDN-CachedAt
MS-CV
X-No-Session
X-ProxyCache-Key
X-ProxyCache-Status
X-Cache-Host
X-BYPASS-REASON
X-RTag
CDN-Uid
X-CSRF-Token
Ms-Operation-Id
CDN-RequestPullCode
CDN-RequestPullSuccess
X-GEO
X-Pubstack
X-ID
X-VWS-Id
X-AWS-Id
WP-Super-Cache
X-Cluster
X-Server-W
X-Parent-Response-Time
X-LJ-Flow-ID
X-IPLB-Request-ID
X-IPLB-Instance
X-Cache-NE
BehaviorPad-Version
Magicmarker
L
True-Client-Country-4JS
Redirect-Candidate
X-CacheTTL
W
Candidate-Md5Url
X-Bc-Bl
Xc-Version
Canary
X-BCube-Filmed-By
X-Debug-Cache-Store
X-Bl-Debug
X-FC-Vary-Parameters
X-Tx-Id
L5d-Success-Class
N-Cache
X-CF-Lambda-Version
X-Destination
X-Developer
X-CGP
Meta-Geo-Continent
Vix-Hermes-Req-Id
Lang
X-SRCache-Key
X-Dispatcher-Number
X-CF-Lambda-Fn
X-Eu-Site
T-Server
X-External-Request-Id
X-B-Cookie
X-Epic-Correlation-Id
X-Ec-Custom-Error
X-Ec-Fail
X-Ec-GeoHdr
X-Fastly-Backend
X-Slack-Shared-Secret-Outcome
X-Vtex-Remote-Cache
X-Conf
Origin-Agent-Cluster
Fastly-SSL
X-A
X-A-Ccd
X-A-Dgt
X-A-Dcw
X-We-Are-Hiring
X-A-Dam
Odigeo-Trace-Id
X-Request-Host
Sslversion
Web-Mar-Region
X-ScT
X-SD-PageType
X-S-Cookie
X-Viewer-Country
Server-Host
Ha-Gx-Prefs
Gannett-Cam-Experience-Id
X-Rojux
X-Worker
X-A-Wwc
Ngx.Var.Host
MD5-Digest
X-Application
X-Debug-Cache-Fetch
Rendered-Blocks
X-App-Name
X-App
X-Slack-Backend
Surrogated-Key
HA-Ipaddr
X-D
DCR-Decision-By
DCR-Processing-Time-Ms
X-Csrf-Jwt
X-Vdms-Path
X-Aed
X-Vdms-Version
X-Datadome
X-Proxy-Cache-Status
X-AB
X-CMSURLCustom
X-Clientip
Thinkindot-Control
TDXMobile
Thinkindot-CacheControl
X-Bip
VNS-Cache
Thinkindot-CacheControl-Type
X-Accel-Expires-Debug
X-Accel-Buffering
We-Hiring
Req-Svc-Chain
X-Alternate-Cache-Key
Release
X-Cdn-Diag
VNS-Age
X-Cache-Info
X-Cache-Debug
X-Cache-Bucket
X-Cdn-Origin
X-Mly-Id
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Sn-Servicetimems
X-Storefront-Renderer-Rendered
X-SVT-ORM-RULES
X-Tenant
X-SVT-ORM-VERSION
X-Shopify-Stage
X-ShopId
X-Request-Time
X-Refresh
X-RateLimit-Remaining-Second
X-S-Maxage
X-Server-IP
X-Shop-Environment
X-ShardId
X-Test
X-Thanos
X-VServer
X-Vmg-Version
X-VG-WebCache
X-Wikidot-Backend
X-Wikidot-Static-Cache
Host-ID
X-Wix-Viewer-Type
X-VG-TLSProxy
X-Varnishpool
X-Var-Ttl
X-Up
X-Thinkindot-L3
X-Variation
X-Varnish-CookieHashed-On
X-Varnish-Remaining-TTL
X-Varnish-CookieINHashed-On
X-RateLimit-Limit-Second
X-Qloud-Router
X-Hash
X-GeoIP-Region-Code
X-GeoIP-Country-Code
X-Human
X-Irp-Debug
X-Loc
X-Level-Front-Cache
X-Geo-Header
X-Generated-On
X-DefElseHash
X-Date
X-Core-Value
X-DefHash
X-DPWN-IS-SECURE
X-Gdpr
X-Forwarded-Path
X-Mid
Producers
X-Owner
X-Origin-Time
X-Orig-Expires
X-PAYTM-SRV-ID
X-Platform
X-Pool
X-Policy
X-Org
X-Old-Content-Length
X-Nananana
X-Mvc-Supplant-Cachable
X-Nitro-Cache
X-Node-Id
X-Nyt-Route
X-NodeID
X-Core-Mission
X-BBC-Edge-Cache-Status
Cf-Device-Type
Fastly-GeoIP-CountryCode
X-B3-Spanid
Fastly-Backend-Name
Cache-Provider
Gh-Request-Id
CPC-Age
Mail-Subject
Is-Eu
X-Micro-Cache
Expect-Staple
Environment
Datacenter
Content-Secure-Policy
Cmstype
CPC-Cache
Cmsid
X-Cache-Status-Check
AKAMAI
Adler-Geo
Origin
Platform
User-Cache-Control
AMP-Access-Control-Allow-Source-Origin
X-TIME
X-Cdn-Srv
X-ApacheServer
X-Auto-Login
Apple-News-Services-Handled
X-INCAP-ABP
X-Clara-WADP
Country-Code
X-Esi-Check
X-Fmm-Version
Apple-News-Services-Host
X-Dispatcher-Server
X-Hnp-Log
X-Gzip
X-Block-Status
X-GeoIP
X-Gen-Mode
X-Cache-Id
Apple-News-Services-Request-Url
X-From
CloudFront-Viewer-Country
CDCHOST
X-Forwarded-Site
Apple-News-Services-Parsed-Url
X-Geo-Region
NM-Fastcgi-Cache
X-PERF
X-Origin-Response-Time
X-Origin
X-WA-Info
Sever-Int
Cache-Name
Server-Ext
Server-Hostname
X-WADP-Cache
X-Nginx-Cache-Key
Machine
X-Mvc-Supplant-OutputCached
X-Akamai-Device-Characteristics
DSUID
X-Device-Os
Esi-Enabled
X-TraceId
X-Vcl-Version
Pics-Label
Server-Info
X-Instance-Name
X-Access
Ssr
X-AIR-PT
Wxu-Next-Hostname
Wxu-Next-Commit
X-NCache
X-LB-NoCache
X-Cache-Enabled
Wxu-Next-Region
NGX
C-Via
X-Section
X-Op-Id-All
X-Dc
Server-ID
X-Amz-Meta-Cb-Modifiedtime
X-Vgn-Hpd-Reason
X-Via-Fastly
X-Fastly-Request-Id
X-Accel-Version
X-API-Version
X-Is-Gdpr
X-CACHE-GROUP
X-JWT-State
X-Varnish-Beresp-Ttl
X-Varnish-Beresp-Grace
X-HA-Backend
X-Has-Esi
Memcached
X-Tcp-Rtt
X-Is-Mobile
X-Is-Desktop
X-Browser-Name
X-Buckets
X-Is-Tablet
X-Is-Supported-Browser
Time
Hostname
X-SIPLIST1
Memory
Cdn-Requestid
IsBot
X-Platform-Cluster
X-Platform-Processor
X-Platform-Router
X-Scale
Cache-Hits
Origin-EX
Origin-CC
Sid
X-Air-Source
X-ZONE
X-Air-Hostname
X-Tb-Optimization-Total-Bytes-Saved
X-PHP-Backend
X-B3-Parentspanid
X-Zone
X-Air-Trace-Id
CF-Ctrl
Location
YJS-ID
X-TIM-N
X-Wp-Cf-Super-Cache-Active
X-Presslabs-Stats
X-Fpc
X-WP-CF-Super-Cache-Active
X-Cached-By
X-Internal-Host
X-Backend-Instance
X-Frame-Option
X-Origin-Cache-Key
X-Azure-Ref-OriginShield
Resin-Trace
X-Hyper-Cache
X-Cs
X-DC
X-TA-CDN-Provider
Uri
GeoIP-Latitude
X-VC
X-Webstats-RespID
X-VCache
Epwk-X-Cache
X-Origin-Expires
True-Client-Ip
X-Site-Version
X-Microcachable
X-DataCenter
Cache-Host
X-Service
X-LiteSpeed-Cache-Control
X-Nitro-Rev
X-FTR-Cache-Status
X-Nitro-Cache-From
X-FTR-Backend-Server
X-Country-Code-Real
X-FTR-Backend
XM
X-FTR-Expires
X-FTR-Balancer
X-Info
X-NGINX-Cache
X-Locale
GeoIP-Country-Code
X-Web-Node
X-Pod-Name
X-VarnishDD-TTL
PFcat
Cdn
GeoIp-Country-Code
X-HN
LB
Cdn-Request-Time
X-Edge-Server
X-Cache-Ttl
Cdn-Host
X-Datacenter
User-Agent
XServer
X-Geo
NtCoent-Length
X-CS
X-Ad-Defer-Variation
X-CSRF-TOKEN
X-NewRelic-App-Data
WZWS-RAY
X-NMSegId
Req-ID
True-Client-IP
A
X-Via-CDN
X-FL-EDGE
X-Via-SSL
X-Via-Edge
Srvid
X-FL-QIT-DEBUG
Edge-Copy-Time
Locid
M-TraceId
WebServer
X-Ad-Load-Variation
X-SRV
X-Vercel-Id
X-Vercel-Cache
X-TRACE-ID
SID
X-M-Log
X-Cache-ASPX
X-Request-Start
X-M-Reqid
Fastly-Drupal-Html
X-FPC
X-Contensis-Viewer-Groups
X-Scope-Id
X-MSEdge-Flight
Pramga
X-Moov-T
X-MSEdge-Features
X-ATG-Version
Cluster
X-FireWall-Port
X-Moov-Xdn-Version
X-Varnish-Authentication
X-Pad
X-HostName
Tcn
X-Request-URI
Cache-Key
X-NWS-UUID-VERIFY
X-LiteSpeed-Tag
X-Varnish-Beresp-Status
X-Qnm-Cache
X-Shield-Cache-Expires
HostName
X-Api-Version
CountryCode
Cf-Ipcountry
X-APP-VERSION
X-Cdn-Request-ID
X-Esi
X-Air-Pt
X-Amz-Meta-Opti
Path
Cdnsip
X-AK-Request-ID
Cdncip
Edge-Cache
Content-Script-Type
X-Cache-Date
Content-Style-Type
Cache-Tv-Group
X-Branch-Name
X-TH-Server
Wpo-Cache-Status
Wpo-Cache-Message
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Wa
Click-Count-Action-Start
X-Via-Popv
X-Render-Time
Click-Count-Error
Tube-Get-Contents
X-Proxy-CacheRZ
Yak-Timeinfo
XkeyRZ
X-Req
X-Via-Poph
X-Github-Request-Id
X-LB-ID
X-Via-Popn
X-Nc
X-Servedbyhost
X-B3-Trace-ID
X-Cache-FS-Status
Tube-Got-Eval
X-V-Cache
X-Aicache-OS
X-SB
X-Acquia-Purge-Cdn-Unconfigured
X-WP-CF-Super-Cache-Cookies-Bypass
Tube-Return
Tube-Got-Results
State
X-Planisys-CDN-TTL
X-HS-Content-Campaign-Id
X-Platform-Server
Lb
X-VCL-Version
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
CDN
X-Upstream-Ht
X-Upstream-Ct
X-CACHE-KEY
X-Wp-Cf-Super-Cache-Cache-Control
X-Men
X-Vary
Geoip-Latitude
X-Wp-Cf-Super-Cache
X-Tim-N
X-Fastly-Cache
X-Release
Proxy-Connection
V-Age
X-Vgn-Hpd-Ssi
X-Vgn-Hpd-Variations-Key
Srv
On-Server
X-Vgn-Hpd-Cached
X-Akamai-Pragma-Client-IP
X-Cdn-Forward
X-Lb-Cache
MIME-Version
Ngx-Var-Key
X-User
X-Rocket-Build-Number
X-UA
X-Generated-In
X-HS-Status
Ohc-File-Size
X-Dw-Trace-Id
CF-Cached-On
X-Sigma
X-Sigma-Backend
X-Traceid
X-Ha-Backend
X-Cache-Remote
Server-Id
X-TT-LOGID
X-EC-Lua
X-Acquia-Site
X-Lb-Nocache
PICS-Label
Ohc-Cache-HIT
My-App
X-Fastly-Backend-Reqs
X-Acquia-Application-Trace
X-Via-Ucdn
X-Acquia-Application-UUID
Cache
X-CUA
X-Acquia-Purge-Tags
X-Iplb-Request-Id
X-TX-ID
X-Iplb-Instance
Yjs-Id
Mime-Version
X-GoCache-CacheStatus
Warning
X-GeoIP-City
X-Gamma-Serve
X-Fastly-Cache-Hits
X-CF-Cache-Header-Vary
Ngx
X-Litespeed-Cache-Control
X-CF-Cache-Header-Cache-Control
Log-Origin
X-Miniprofiler-Ids
X-RAMCache
X-Udemy-Cache-App-Namespace
X-ElasticPress-Query
Inserted-Into-Cache-At
CACHE-MISS-TO-ORIGIN
Cneonction
X-Snapshot-Date
X-Cached-Since
Vha6-Origin
X-Scheme