Threat Level: green Handler on Duty: Jan Kopriva

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
X-XSS-Protection
Accept-Ranges
Expect-CT
Pragma
X-Powered-By
CF-RAY
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
CF-Ray
X-Download-Options
X-Xss-Protection
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Request-Id
X-Adblock-Key
Access-Control-Allow-Credentials
X-FRAME-OPTIONS
X-Permitted-Cross-Domain-Policies
X-AspNet-Version
Alt-Svc
X-Request-ID
X-Runtime
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Generator
X-Cache-Status
X-Check
X-Cacheable
Timing-Allow-Origin
X-Envoy-Upstream-Service-Time
X-Iinfo
X-Content-Security-Policy
X-Drupal-Dynamic-Cache
Feature-Policy
Content-Encoding
Access-Control-Expose-Headers
Upgrade
Status
X-CDN
X-AspNetMvc-Version
Access-Control-Max-Age
X-Via
Server-Timing
Request-Context
X-Robots-Tag
X-Turbo-Charged-By
X-UA-Device
X-Amz-Request-Id
X-Cache-Group
X-Dns-Prefetch-Control
X-Amz-Id-2
EagleId
X-Backend
X-AH-Environment
X-Proxy-Cache
P3p
Keep-Alive
X-Server
X-Ws-Request-Id
X-Age
Cf-Edge-Cache
Host-Header
X-Hacker
X-Vhost
X-Server-Powered-By
X-Rq
X-Varnish-Cache
X-Dispatcher
X-Amz-Version-Id
Grace
Allow
X-OneAgent-JS-Injection
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-LiteSpeed-Cache
X-Page-Speed
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Ua-Compatible
Cf-Apo-Via
X-Device
X-WebKit-CSP
Cf-Railgun
Accept-CH
X-Aws-Lambda-Call-Status
X-Node
X-Pingback
X-Host
X-Ruxit-JS-Agent
EagleEye-TraceId
X-Server-Id
Surrogate-Control
X-Nginx-Cache-Status
X-Akam-SW-Version
Request-Id
X-Readtime
X-Backend-Server
Accept-Ch-Lifetime
X-Content-Security-Policy-Report-Only
X-HW
X-Cache-Lookup
X-Cloud-Trace-Context
X-Cache-Spec
X-Trace
X-Response-Time
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Application-Context
Permissions-Policy
X-Nginx-Upstream-Cache-Status
Fastly-Restarts
X-Edge
X-Mod-Pagespeed
X-WebKit-CSP-Report-Only
X-Litespeed-Cache
X-Country
X-Mcache
Content-Location
X-MS-InvokeApp
X-Content-Type
X-Url
X-Clacks-Overhead
X-TtlSet
X-PC
X-Vname
X-Midtier
X-Amz-Server-Side-Encryption
X-CST
Rating
Accept-CH-Lifetime
RTSS
Cache-Tag
X-ESI
X-Vcap-Request-Id
X-D2id
X-Rack-Cache
X-Element-Page-Cache
X-Exp-Variant
X-Kinja
X-Use-Magma
X-Kinja-Server
X-Kinja-Build
X-Kinja-Revision
X-Exp-Id
X-GoogleNews-Bot
Origin-Trial
Verso
X-Cdn-Fetch
X-VARITI-CCR
X-Server-Name
X-ECACHE
X-GitHub-Request-Id
Service-Worker-Allowed
X-Ac
X-Powered-By-Plesk
X-Amz-Rid
X-Cnection
SPRequestGuid
X-SharePointHealthScore
X-Navigation-Version
X-Client-IP
Xkey
Edge-Control
X-Abt-Application-Version
SPIisLatency
SPRequestDuration
X-Upstream
X-Cache-TTL
X-Ttl
Accept-Ch
Arr-Disable-Session-Affinity
X-Cached
X-Mg-S
X-Dw-Request-Base-Id
X-Varnish-TTL
X-Browser-Type
X-Instrumentation
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-B3-TraceId
X-NWS-LOG-UUID
X-Webkit-Csp
X-Px
Display
Pagespeed
X-Sol
X-Middleton-Display
X-NF-Request-ID
X-FastCGI-Cache
X-SRCache-Fetch-Status
X-SRCache-Store-Status
Access-Control-Request-Method
Edge-Cache-Tag
X-Correlation-Id
X-Forwarded-For
X-Cache-Key
X-Country-Code
X-Goog-Hash
X-Ser
X-Powered-CMS
X-Id
AR-PoweredBy
AR-Request-ID
AR-SID
AR-ATIME
AR-CACHE
Content-MD5
Front-End-Https
Public-Key-Pins
TCN
X-RateLimit-Remaining
X-Amzn-Trace-Id
X-Jurisdiction
X-Version
X-HP-Trace-Id
X-HP-Webp
X-T
X-Recruiting
X-Content-Digest
X-MSEdge-Ref
X-Middleton-Response
Response
X-Accel-Expires
TP-Cache
TP-L2-Cache
X-Ratelimit-Limit
X-Shield-Request-Id
MicrosoftSharePointTeamServices
S
Cache-Status
Nginx-Cache
X-Fastcgi-Cache
X-Request-Received
X-Request-Processing-Time
X-HS-Content-Id
Cross-Origin-Opener-Policy
X-HS-Cache-Config
X-HS-Combine-CSS
X-HS-Hub-Id
Server-Node
Cache-Tags
X-XRDS-Location
X-Fastly-Request-ID
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
X-Daa-Tunnel
X-Distributor
X-ORACLE-DMS-ECID
X-Hits
X-ORACLE-DMS-RID
X-PressLabs-Stats
X-LB-Cache
X-Kinsta-Cache
X-Edge-Location-Klb
X-Origin-Server
X-Ua-Browser
X-Ezoic-Cdn
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Ratelimit-Reset
Filterid
Fastcgi-Cache
Alternate-Protocol
X-Ratelimit-Remaining
X-Frontend
X-LLID
X-Grace
X-Request-Handler-Origin-Region
X-Microsite
X-Rid
X-Hostname
Healthy
X-DIS-Request-ID
X-Logged-In
X-Git-Hash
Server-Name
X-Varnish-Backend
X-FB-Debug
Cleartype
X-Geo-Country
Realpath
X-Www-Served-By
X-NGENIX-Cache
X-Cluster-Name
X-Debug-Info
X-Page-Id
Payment
DC
MS-Author-Via
X-Protected-By
X-Load-Cache
X-TTL
X-Forwarded-Proto
X-Origin-Cache
Access-Control-Allow-Method
X-ECache
Content-Disposition
X-ASPNET-VERSION
X-Upgrade-Enabled
X-B3-Traceid
Charset
X-GUploader-UploadID
X-Kong-Upstream-Latency
X-Goog-Metageneration
X-Kong-Proxy-Latency
X-B3-Sampled
X-Az
X-Activity-Id
X-AppVersion
X-Proxy
X-DataDome
X-Seen-By
X-Cache-Age
Count-Hit
X-Amz-Meta-S3cmd-Attrs
Paypal-Debug-Id
X-F-Cache
X-Times
X-Fb-Rlafr
X-Azure-Ref
X-Amz-Replication-Status
X-Whom
X-Revision
X-B
Accept-Charset
Cross-Origin-Resource-Policy
X-Contextid
Surrogate-Key
X-Type
X-Server-ID
X-App-Environment
X-Akamai-Edgescape
Viewport
X-Varnish-Server
X-Providence-Cookie
X-Request-Guid
X-Flags
X-Route-Name
X-Is-Crawler
X-Aspnet-Duration-Ms
X-TT
Retry-After
X-Wix-Request-Id
X-Aspnetmvc-Version
X-Hosted-By
X-Envoy-Decorator-Operation
X-Language
X-DynaTrace
X-Cache-Control
X-B-Cache
X-Signature
X-App-Server
X-Magnolia-Registration
X-Mobile
X-Source
X-Varnish-Grace
X-Goog-Storage-Class
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
Version
WPO-Cache-Message
WPO-Cache-Status
Host
X-VCache
Amp-Access-Control-Allow-Source-Origin
Refresh
X-Amz-Apigw-Id
X-Amzn-RequestId
Referer-Policy
X-Cache-Rule
X-N
X-HTML-Minification-Powered-By
X-Tumblr-Pixel-1
X-Tumblr-User
X-Tumblr-Pixel-0
X-Varnish-Age
Access-Control-Request-Headers
X-Original-Request-Id
X-Response-Served-From
X-Tumblr-Pixel
X-RateLimit-Limit
X-XRDS-LOCATION
X-Rule
X-Cache-Time
X-Jobs
SD-X-WS
X-Content-Powered-By
X-Cacheable-TTL
X-Framework
X-RTag
X-EdgeConnect-Cache-Status
X-User-Agent
Protected
X-G
X-UUID
Ms-Operation-Id
MS-CV
X-Trace-Id
X-RemovedCookies
X-ProcessESI
X-L-Path
X-Backend-Name
X-Environment-Context
X-Cache-Grace
X-Oracle-Dms-Ecid
X-Oracle-Dms-Rid
VIX-Pulpo-Node
X-Region
X-Device-Type
VIX-Pulpo-Upstream-Status
Section-Io-Cache
NGB
GEO-INFO
Akamai-GRN
X-FW-Static
X-FW-Type
X-FW-Server
X-FW-Serve
X-FW-Dynamic
X-FW-Version
From-Origin
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Status
X-FW-Hash
X-Varnish-Ttl
X-Page-View
Front
X-Rendered-As
X-Cache-Status-Check
X-Is-Bot
X-NYM-Debug-Backend
X-Cache-Expired-At
X-Adobe-Content
X-Instance
X-Drupal-Cache-Contexts
X-Adobe-Loc
X-Http-Reason
X-Akamai-Request-ID2
X-Drupal-Cache-Tags
X-Nginx-Cache
CDN-RequestId
X-Unique-Id
Url
X-Pinterest-Rid
Pinterest-Version
X-Servername
Pinterest-Generated-By
Liferay-Portal
X-Fastly-Request-Id
Accept-Language
X-Content-Options
X-Time
X-Template
Fastly-SIE
Fastly-SWR
Backend
X-CDN-Forward
X-Zen-Fury
X-Cache-Hit
X-Debug-IsConnected
X-Air-Source
X-Air-Trace-Id
X-Debug-IsPreview
SRV
X-Air-Hostname
X-Yottaa-Optimizations
X-Newrelic-App-Data
X-Yottaa-Metrics
X-DynaTrace-JS-Agent
Country
X-Mode
X-Rocket-Nginx-Serving-Static
Content-Secure-Policy
X-Uri
X-Edge-Location
X-ARC
X-Cache-Operation
S-Rt
X-Amzn-Remapped-Content-Length
X-Cache-Server
X-RN-RSRV
Onion-Location
Meta-Geo
X-UPSTREAM-Address
X-Tumblr-Pixel-3
X-Tumblr-Pixel-2
Webserver
X-Generation-Time
Filters
X-COUNTRY
X-Rewrite-Enabled
Azure-RegionName
Azure-InstanceId
X-Content-Age
Azure-SlotName
Azure-Version
WP-Super-Cache
X-IPS-LoggedIn
X-Proxy-Build
X-Timing-Wait
Countrycode
Cache-Hits
X-Proxy-Cache-Info
Azure-SiteName
X-Locale
Uber-Trace-Id
X-App-Version
X-PHP-Backend
Selected-Fe
CF-IPCountry
X-Cache-Action
X-Cms-Context
X-Ua
X-Via-Fastly
X-ProxyCache-Status
X-Tb
X-ProxyCache-Key
X-Server-W
X-Ms-Request-Id
X-Ms-Version
X-Web-Node
X-Site-Version
X-Skip-Cache
X-BYPASS-REASON
Cache-Name
X-Soup
X-Sucuri-ID
X-Sucuri-Cache
X-Reqid
Node
X-SayCDN-TTL
TWC-Device-Class
ServerID
X-AWS-Id
TWC-Locale-Group
X-Proxied
X-Origin-Hint
X-Cache-Host
TWC-GeoIP-LatLong
X-Section
X-Extlb
X-Say-Cacheable
X-VWS-Id
Webcakes-App-Name
X-Format
X-Say-TTL
X-IPLB-Instance
X-Access
Cache-Tv-Group
X-LJ-Flow-ID
X-Proxy-Cache-Status
Webcakes-App-Version
X-Routing-Service
Property-Id
X-Origin-Date
X-Proto
TWC-Privacy
X-Cluster-Node
TWC-GeoIP-Country
Webcakes-Region
X-Zipkin-Id
X-IPLB-Request-ID
X-UA-Device-Type
TWC-Connection-Speed
X-SaId
X-Forwarded-Host
X-R9-Blue-Green-Version
Cross-Origin-Window-Policy
X-JoinUs
X-Labrador-Cache-Channel
X-Optimistic-Header
X-LAGOON
X-PHP-Host
X-No-Session
DB-Nickname
X-VC-Cache
Web-Mar-Node
Apigw-Requestid
X-Cluster
X-Debug
X-Sql-Count
X-Sql-Duration-Ms
X-Handled-By
Mn-Server-Ip
X-FB-TRIP-ID
X-Adobe-Source
X-Cache-TTL-Remaining
X-Varnish-Beresp-Grace
X-Detected-As
X-Real-IP
X-Urbn-Context-Path
ServedBy
X-Director
X-Urbn-Site-Id
X-LSADC-Cache
Locale
X-Node-Name
X-Xfnlog-Site
X-Ruxit-Js-Agent
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
Fastcgi-Useragent
Frame-Options
X-Tec-Api-Origin
X-Tec-Api-Root
X-Tec-Api-Version
X-GeoCountry
X-GeoCode
Upgrade-Insecure-Requests
Mime-Version
X-Varnish-Hits
Source
X-Tt-Logid
X-Oneagent-Js-Injection
CDN-CachedAt
CDN-EdgeStorageId
CDN-PullZone
CDN-RequestCountryCode
X-Hl-Ver
CDN-Uid
Load-Balancing
X-Generated-By
CDN-Cache
X-Api-Version
X-Varnish-Cache-Hits
X-GEO
Fastly-Drupal-HTML
Xet-Cookie
X-Buckets
X-TIME
X-Varnish-Hostname
X-Request-Time
X-FireWall-Port
X-ServerID
X-Mg-Request-UUID
X-RM-Cache-TTL
X-Origin-TTL
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
X-SRV
X-Redis-Cache
X-Datadog-Trace-Id
X-Datadog-Sampled
X-Origin-CC
X-TA-CDN-Provider
CF-Cached-On
X-Cache-Debug
X-URL
X-Loop
X-Served-From
X-Storage
X-Akamai-Transformed
X-Storefront-Renderer-Rendered
X-Sorting-Hat-ShopId
X-ShopId
X-ShardId
X-Alternate-Cache-Key
X-Shopify-Stage
X-Sorting-Hat-PodId
X-Pubstack
X-Endurance-Cache-Level
X-Restarts
X-Provided-By
X-Tx-Id
X-Pass-Why
X-Request-Host
X-Newrelic-Synthetics
Xserver
X-Location
X-A-Wwc
Redirect-Candidate
X-Cache-Info
X-Cache-Date
Origin
X-Gdpr
Ngx.Var.Host
Odigeo-Trace-Id
X-Hash
X-Generated-On
X-INCAP-ABP
X-Aed
WWW-Authenticate
X-Mid
X-Mobile-URL
X-Nyt-Route
X-A
X-A-Dam
X-CSRF-Token
X-A-Dcw
Release
Rendered-Blocks
X-Level-Front-Cache
X-A-Dgt
X-Cache-NE
X-D
X-CUA
Edge-Cache
DSUID
Memcached
MD5-Digest
Gannett-Cam-Experience-Id
X-CMSURLCustom
Lang
X-Conf
Host-ID
X-Core-Mission
X-Destination
DCR-Processing-Time-Ms
A
X-Ec-GeoHdr
X-Epic-Correlation-Id
X-Fetched-On
X-Bip
BehaviorPad-Version
Cache-Host
X-Developer
DCR-Decision-By
Meta-Geo-Continent
Candidate-Md5Url
X-Ec-Fail
X-External-Request-Id
X-A-Ccd
X-We-Are-Hiring
X-S-Maxage
T-Server
Thinkindot-CacheControl
X-SRCache-Key
X-Sigma-Backend
X-Rojux
X-BCube-Filmed-By
X-Bc-Bl
X-Sigma
X-Processor
X-Vdms-Version
X-Response-By
X-ScT
X-Rocket-Build-Number
Surrogated-Key
X-Origin-Time
Sslversion
X-B-Cookie
X-SVT-ORM-RULES
X-TIM-N
TDXMobile
X-S-Cookie
X-Application
Thinkindot-Control
X-Vdms-Path
Xc-Version
X-Test
X-SVT-ORM-VERSION
X-Thanos
X-S
Thinkindot-CacheControl-Type
X-Thinkindot-L3
Server-Info
X-Service
AKAMAI
X-Server-IP
X-SD-PageType
X-Fastly-Backend
X-Dispatcher-Number
Cmstype
Cmsid
Fastly-GeoIP-CountryCode
Country-Code
Tube-Get-Contents
X-Var-Ttl
X-Date
X-Cdn-Origin
CloudFront-Viewer-Country
Click-Count-Error
X-Slack-Shared-Secret-Outcome
CacheControlHeader
Cache-Key
X-Sn-Servicetimems
X-Ec-Custom-Error
Click-Count-Action-Start
X-CacheTTL
X-Slack-Backend
X-Req
Tube-Return
X-Auto-Login
X-Origin-Response-Time
X-Varnishpool
X-Men
Gh-Request-Id
X-Loc
Req-Svc-Chain
We-Hiring
Magicmarker
Server-Host
X-Org
Mail-Subject
C-Via
X-Mvc-Supplant-Cachable
X-Node-Id
X-Accel-Expires-Debug
X-BBC-Edge-Cache-Status
X-Geo-Header
Tube-Got-Eval
X-Region-Sid
Fastly-Backend-Name
X-Gamma-Serve
X-Origin
NM-Fastcgi-Cache
X-Pool
X-Cache-Bucket
X-Platform-Cluster
X-Human
Tube-Got-Results
X-Httpd
X-HS-Content-Campaign-Id
X-Platform-Router
X-Platform-Processor
X-Fastly-Cache
HostName
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
Section-Io-Id
Section-Origin-Responded
X-Vcl-Version
X-WP-CF-Super-Cache-Active
X-Ad-Defer-Variation
X-Cache-Id
X-Azure-Ref-OriginShield
X-Akamai-Device-Characteristics
X-Is-Gdpr
X-Vmg-Version
X-Varnish-Remaining-TTL
X-VServer
X-WA-Info
X-WADP-Cache
X-Varnish-CookieINHashed-On
X-Varnish-CookieHashed-On
X-Platform
X-SB
X-V-Cache
X-Variation
X-Worker
Locid
X-FL-QIT-DEBUG
X-FL-EDGE
X-Instance-Name
X-Nginx-Cache-Key
X-Scale
X-Developers
X-Cdn-Srv
On-Server
Origin-CC
Origin-EX
Srvid
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-FC-Vary-Parameters
X-Esi-Check
X-Forwarded-Site
X-Frame-Option
X-GeoIP
X-Dispatcher-Server
X-Device-Os
X-Clara-WADP
X-Core-Value
X-DefElseHash
X-DefHash
X-GeoIP-City
X-GeoIP-Country-Code
X-NodeID
X-Origin-Expires
X-Owner
X-Planisys-CDN-Cache
X-Mly-Id
X-JWT-State
X-GeoIP-Region-Code
X-Gzip
X-Has-Esi
X-Irp-Debug
X-Ckpd-Fst-Backend
X-Fmm-Version
X-TNCMS
Platform
State
Ssr
Is-Eu
Datacenter
Kp-EeAlive
Expect-Staple
Adler-Geo
Web-Mar-Region
Canary
Vix-Hermes-Req-Id
Machine
Environment
X-Varnish-Beresp-Ttl
X-Via-CDN
Apple-News-Services-Host
Apple-News-Services-Handled
X-Release
X-Qloud-Router
X-Old-Content-Length
X-From
Apple-News-Services-Parsed-Url
X-Air-Pt
X-Wix-Viewer-Type
X-VG-TLSProxy
X-VC
Server-Hostname
X-Op-Id-All
X-NCache
X-Minions-Version
Cache-Provider
L
X-VarnishDD-TTL
X-HN
PFcat
X-Hnp-Log
X-Gen-Mode
User-Cache-Control
Sever-Int
Server-Ext
Wxu-Next-Commit
Wxu-Next-Hostname
X-Block-Status
Wxu-Next-Region
X-Accel-Buffering
Apple-News-Services-Request-Url
Producers
X-DPWN-IS-SECURE
NGX
X-Cache-Tags
X-Cache-FS-Status
X-App
X-Aicache-OS
Edge-Copy-Time
X-Via-SSL
X-Via-Edge
X-Nananana
HA-Ipaddr
Ha-Gx-Prefs
X-Mvc-Supplant-OutputCached
L5d-Success-Class
X-Platform-Server
X-Cache-Remote
X-RCS-CacheZone
X-Csrf-Jwt
X-Request-Start
X-Eu-Site
X-Microcachable
X-Varnish-Beresp-Status
CDCHOST
X-CGP
X-Ua-Device
X-Parent-Response-Time
X-Webkit-CSP-Report-Only
X-CACHE-AGE
X-Zone
X-B3-Spanid
X-Dc
X-Lambda-Id
X-Debug-Cache-Store
X-Debug-Cache-Fetch
Fastly-SSL
X-LB-NoCache
X-Cache-Enabled
X-VCT
AMP-Access-Control-Allow-Source-Origin
X-Up
X-Tb-Optimization-Total-Bytes-Saved
Sid
Pics-Label
X-Correlation-ID
X-Cs
X-Generated-In
X-Refresh
X-Cache-Backend
X-Via-Popv
X-Via-Popn
VNS-Cache
X-Via-Poph
CPC-Age
Env
X-Upstream-Ht
X-Upstream-Ct
CPC-Cache
VNS-Age
X-Render-Time
X-Cached-By
X-Vtex-Remote-Cache
X-DC
NtCoent-Length
X-Trace-ID
X-B3-SpanId
X-CCDN-CacheTTL
Decoy-Debug-Status
X-CCDN-Origin-Time
Decoy-Debug-Key
X-Hcs-Proxy-Type
GeoIP-Latitude
Time
Memory
Cluster
Cache
Decoy-Debug-TTL
X-ND-Cache
X-Cache-Type
X-AIR-PT
X-HA-Backend
Fastly-Drupal-Html
X-Tid
X-Webkit-CSP
X-NWS-UUID-VERIFY
X-TH-Server
X-Edge-Pop
X-LB-ID
X-HS-Status
X-ATG-Version
SID
Srv
X-Servedbyhost
X-NewRelic-App-Data
X-Srv
X-Nc
X-Wa
X-Via-JSL
X-Presslabs-Stats
X-DataCenter
X-Esi
X-ZONE
GeoIp-Country-Code
X-Client-Ip
Svr
X-Cache-ASPX
X-Varnish-Authentication
X-Contensis-Viewer-Groups
Server-ID
Uri
X-Check-Cacheable
X-MP-GENERATED-AT
Cdn
X-PAYTM-SRV-ID
X-Vgn-Hpd-Variations-Key
X-RateLimit-Limit-Second
X-Vgn-Hpd-Ssi
X-CF-Lambda-Version
X-Vgn-Hpd-Cached
X-RateLimit-Remaining-Second
Esi-Enabled
X-CF-Lambda-Fn
X-Amz-Meta-Cb-Modifiedtime
True-Client-IP
X-Vc
X-Proxy-CacheRZ
YJS-ID
XkeyRZ
X-Datadome
Hostname
Lb
X-Fpc
X-Wikidot-Backend
X-CDN-Cache-Status
X-Wikidot-Static-Cache
XServer
N-Cache
X-Varnish-Beresp-TTL
X-Udemy-Cache-App-Namespace
X-Nf-Request-Id
X-Bl-Debug
Resin-Trace
X-CACHE-KEY
X-Tenant
M-TraceId
RNT-Machine
RNT-Time
X-Orig-Expires
X-Shop-Environment
X-Forwarded-Path
X-CS
X-NGINX-Cache
X-TX-ID
X-CSRF-TOKEN
OT-Force-Account-Verify
X-Gateway-Request-Id
X-Gateway-Skip-Cache
X-MSEdge-Features
X-FPC
X-Gateway-Cache-Key
X-Gateway-Cache-Status
X-AK-Request-ID
Cdncip
X-MSEdge-Flight
True-Client-Ip
Cdnsip
X-Fastly-Country-Code
X-EC-Lua
X-Via-NSCOPI
X-Policy
X-App-Name
X-API-Version
X-B3-Trace-ID
X-Logging-Id
X-Service-Response-Time
Server-Id
Eomportal-Instance
Sm-Log-Id
CDN
Hit
Path
GeoIP-Country-Code
X-Cache-Ttl
X-Container-Uri
X-Git-Commit
X-Cdn-Diag
X-Lb-Id
X-Datacenter
Ngx-Var-Key
X-APP-VERSION
X-CLOUD-TRACE-CONTEXT
X-WA
X-Micro-Cache
X-Vcache
X-Accel-Version
X-Cache-NGX
X-NC
X-Ha-Backend
X-SIPLIST1
IsBot
X-VCL-Version
X-MCACHE
LB
X-ServedByHost
X-Edge-POP
X-Geo
X-Request-URI
X-RateLimit-Reset
HIT
X-Akamai-Pragma-Client-IP
X-Cdn-Forward
RATING
X-Cdn-Cache-Status
XM
X-SERVER-NAME
X-Info
V-Age
X-Tncms
X-Acquia-Purge-Cdn-Unconfigured
X-VG-WebCache
Pramga
X-Via-PopH
CDN-RequestPullCode
X-Via-PopN
X-Via-PopV
X-Srcache-Fetch-Status
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-Snapshot-Date
Cross-Origin-Opener-Policy-Report-Only
X-Srcache-Store-Status
Timeexpire
X-Clientip
Geoip-Latitude
FSS-Cache
Location
CDN-RequestPullSuccess
ENV
X-Xrds-Location
Tcn
X-TT-LOGID
X-Ctl-Mach
Epwk-X-Cache
Req-ID
Ohc-File-Size
X-Lb-Nocache
Yjs-Id
X-Pod-Name
True-Client-Country-4JS
X-TimeS
X-HostName
X-Wp-Cf-Super-Cache
X-Wp-Cf-Super-Cache-Cache-Control
X-LiteSpeed-Cache-Control
X-Iauth-Set-Uid
X-UP
X-Serial
X-Amz-Meta-Opti
X-Hyper-Cache
X-Dw-Trace-Id
W
X-LiteSpeed-Tag
X-M-Log
Warning
X-M-Reqid
X-Litespeed-Cache-Control
Proxy-Connection
X-Viewer-Country
X-Vgn-Hpd-Reason
X-RAMCache
X-ApacheServer
X-Cdn-Request-ID
X-PERF
X-User
X-Fastly-Backend-Reqs
X-Oss-Request-Id
X-Oss-Object-Type
Content-Script-Type
Content-Style-Type
X-Oss-Server-Time
Ec-Rule-Version
Cdn-Requestid
X-Cache-Expires
Cneonction
WZWS-RAY
X-Oss-Storage-Class
X-Acquia-Purge-Tags
X-Acquia-Application-UUID
X-Acquia-Application-Trace
X-Oss-Hash-Crc64ecma
X-Qnm-Cache
X-Acquia-Site
Servername
CountryCode
X-MiniProfiler-Ids
X-Lsadc-Cache
X-Akamai-ERRuleID
X-Akamai-ERPolicy
X-WP-CF-Super-Cache-Cookies-Bypass
X-B3-ParentSpanId
Inserted-Into-Cache-At
X-IPS-Cached-Response
X-Swift-Error
X-Th-Server
X-Fastly-Cache-Hits
X-Mg-Cache
X-Webstats-RespID
Ngx
Ohc-Cache-HIT
PICS-Label
My-App
X-B3-Parentspanid
MIME-Version