Threat Level: green Handler on Duty: Johannes Ullrich

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-Cache-Status
Link
Accept-Ranges
CF-RAY
ETag
X-XSS-Protection
Expect-CT
Pragma
X-Powered-By
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
Alt-Svc
X-Served-By
X-Xss-Protection
X-Download-Options
X-Timer
X-Request-Id
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Cache-Status
X-Generator
X-Cacheable
Timing-Allow-Origin
X-Content-Security-Policy
X-Iinfo
Feature-Policy
Status
X-Envoy-Upstream-Service-Time
Content-Encoding
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
X-CDN
X-AspNetMvc-Version
P3p
X-Request-ID
Upgrade
X-Via
CF-Ray
X-Ws-Request-Id
Access-Control-Max-Age
Server-Timing
EagleId
X-Cache-Group
Keep-Alive
X-Turbo-Charged-By
Request-Context
X-Age
X-UA-Device
X-Server-Powered-By
X-Proxy-Cache
X-Backend
X-AH-Environment
X-Robots-Tag
X-Hacker
Report-To
X-Amz-Request-Id
Host-Header
X-Server
X-Amz-Id-2
Grace
X-LiteSpeed-Cache
X-Rq
X-Nginx-Cache-Status
X-Varnish-Cache
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-WebKit-CSP
X-Page-Speed
X-Vhost
EagleEye-TraceId
X-OneAgent-JS-Injection
X-Amz-Version-Id
X-Ua-Compatible
X-Pingback
X-Dns-Prefetch-Control
X-Dispatcher
X-Device
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
NEL
X-Cache-Spec
X-Host
X-Server-Id
Cf-Railgun
X-Node
X-Backend-Server
Accept-CH
X-Readtime
Surrogate-Control
X-Akam-SW-Version
Request-Id
X-Response-Time
X-HW
Xkey
X-Ruxit-JS-Agent
X-Application-Context
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
Content-Location
Rating
X-Country
X-B3-TraceId
Accept-Ch-Lifetime
Accept-CH-Lifetime
X-Cache-Lookup
X-Cloud-Trace-Context
X-Trace
X-Url
X-Ac
X-Content-Type
X-TtlSet
X-PC
X-Vname
Allow
X-Clacks-Overhead
X-Mod-Pagespeed
Edge-Control
X-Varnish-TTL
X-ESI
X-FastCGI-Cache
X-Server-Name
Fastly-Restarts
Cache-Tag
Service-Worker-Allowed
X-VARITI-CCR
X-Aws-Lambda-Call-Status
X-Rack-Cache
X-Element-Page-Cache
Verso
X-Upstream
MS-Author-Via
X-GitHub-Request-Id
X-MS-InvokeApp
X-Amz-Rid
X-Vcap-Request-Id
Public-Key-Pins
X-Dw-Request-Base-Id
X-Cached
X-Client-IP
X-D2id
X-Cache-TTL
X-Abt-Application-Version
X-Cnection
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-Px
X-Navigation-Version
RTSS
X-Country-Code
Arr-Disable-Session-Affinity
Access-Control-Request-Method
X-Powered-By-Plesk
X-NF-Request-ID
X-Exp-Id
X-Cdn-Fetch
X-Exp-Variant
X-Use-Magma
X-Kinja-Server
X-Kinja-Revision
X-Kinja-Build
X-Kinja
X-GoogleNews-Bot
X-Goog-Hash
Accept-Ch
X-Origin-Cache
X-Instrumentation
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Powered-CMS
AR-ATIME
AR-SID
AR-Request-ID
AR-PoweredBy
AR-CACHE
X-Version
Display
Pagespeed
X-Sol
X-Middleton-Display
Response
X-Middleton-Response
X-Amz-Server-Side-Encryption
X-LLID
X-MSEdge-Ref
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Kinsta-Cache
X-Edge-Location-Klb
X-Edge
Nginx-Cache
X-TTL
Mrf-Cache-Status
MRF-Tech
X-B3-TraceId-Primal
X-Protected-By
TCN
X-Jurisdiction
X-T
X-HP-Webp
X-HP-Trace-Id
X-Shield-Request-Id
X-Forwarded-For
X-Content-Security-Policy-Report-Only
X-Id
X-Mg-S
Content-MD5
S
X-RateLimit-Remaining
X-Aspnetmvc-Version
Edge-Cache-Tag
Fastcgi-Cache
X-Mid
SPRequestDuration
X-CST
Front-End-Https
SPIisLatency
X-Language
Realpath
X-Recruiting
X-Request-Received
X-Request-Processing-Time
Pinterest-Version
Pinterest-Generated-By
Filters
X-Ttl
X-Pinterest-Rid
Server-Node
X-MCACHE
X-Ab
X-Ua-Browser
Server-Name
X-Content
X-DynaTrace
X-Correlation-Id
X-Frontend
X-NWS-LOG-UUID
X-HS-Cache-Config
X-HS-Content-Id
X-HS-Hub-Id
X-Yandex-Sdch-Disable
X-HS-Combine-CSS
X-Ser
SPRequestGuid
X-SharePointHealthScore
X-Ezoic-Cdn
X-ECACHE
X-Hits
X-Template
X-Parallel-Accel
Alternate-Protocol
Fusion-Source
Fusion-Template-Id
Fusion-Component-Id
Fusion-Deployment-Id
Fusion-Content-Source
Fusion-Content-Id
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Kong-Upstream-Latency
Cache-Tags
X-Content-Options
X-Kong-Proxy-Latency
MicrosoftSharePointTeamServices
X-Page-Id
Host
X-B3-Sampled
Cleartype
Charset
X-Www-Served-By
X-Git-Hash
X-Fastly-Request-Id
X-Cache-Key
X-Ruxit-Js-Agent
X-Geo-Country
X-DIS-Request-ID
X-Daa-Tunnel
X-Debug-Info
X-Webkit-CSP
X-Amzn-Trace-Id
X-Content-Digest
X-Ratelimit-Limit
X-Amz-Replication-Status
Filterid
X-Varnish-Age
X-XRDS-LOCATION
X-Accel-Expires
X-Activity-Id
X-Hostname
X-Az
X-AppVersion
X-Forwarded-Proto
X-FB-Debug
X-VCache
X-Upgrade-Enabled
X-Grace
TP-Cache
TP-L2-Cache
Cross-Origin-Opener-Policy
X-Rid
X-WebKit-CSP-Report-Only
X-Origin-Server
Access-Control-Allow-Method
ServerID
X-Nginx-Upstream-Cache-Status
X-N
X-F-Cache
X-Mobile-URL
X-LB-Cache
X-Is-Crawler
X-Providence-Cookie
X-Flags
X-Aspnet-Duration-Ms
X-Request-Guid
X-Route-Name
X-Whom
X-TT
X-App-Environment
Viewport
X-Varnish-Grace
X-Goog-Storage-Class
X-GUploader-UploadID
X-Type
X-Goog-Stored-Content-Encoding
X-Seen-By
X-Goog-Generation
X-Tb
X-Goog-Metageneration
X-Goog-Stored-Content-Length
X-Distributor
X-FW-Server
X-FW-Static
X-FW-Serve
X-FW-Hash
Payment
X-FW-Dynamic
Node
X-FW-Type
Paypal-Debug-Id
X-Server-ID
DC
X-App-Server
X-User-Agent
Fastcgi-Useragent
X-NGENIX-Cache
Country
Accept-Charset
X-Origin-Upstream-Status
X-Cache-Control
X-Wix-Request-Id
X-DataDome
X-Cache-Rule
X-Litespeed-Cache
X-Logged-In
Version
X-Via-JSL
Referer-Policy
X-Drupal-Cache-Tags
X-Cache-Age
X-Ratelimit-Reset
X-Cluster-Name
X-Load-Cache
X-Signature
X-Varnish-Backend
X-Erf-Bev-Bev
Refresh
X-B-Cache
X-Erf-Bev-Bev-Is-Generated
X-Microsite
X-Request-Handler-Origin-Region
X-Browser-Type
X-Contextid
Cache-Status
X-Original-Request-Id
X-Node-Name
X-Buckets
VIX-Pulpo-Node
SD-X-WS
X-Response-Served-From
VIX-Pulpo-Upstream-Status
X-Tec-Api-Origin
X-Is-Bot
X-Cache-Expired-At
X-Tec-Api-Version
X-Tec-Api-Root
X-Page-View
X-Real-IP
X-Mobile
X-Rendered-As
X-Vgn-Hpd-Reason
X-Jobs
X-Debug
X-B
X-Cacheable-TTL
X-Proxy-Cache-Status
NGB
Access-Control-Request-Headers
X-Device-Type
X-Yottaa-Metrics
X-Instance
X-Revision
X-ProcessESI
X-RemovedCookies
X-IPLB-Instance
X-Proxy
X-Rule
X-Yottaa-Optimizations
X-UUID
X-Cache-Action
Surrogate-Key
Akamai-GRN
X-Drupal-Cache-Contexts
X-Fastly-Request-ID
X-Debug-IsPreview
X-Framework
X-Debug-IsConnected
X-Cache-Time
X-FW-Version
X-Fastcgi-Cache
X-G
Amp-Access-Control-Allow-Source-Origin
X-Air-Source
X-Air-Hostname
CF-IPCountry
X-Air-Trace-Id
SID
X-TEC-API-ROOT
X-TEC-API-VERSION
X-TEC-API-ORIGIN
DynaTrace
Liferay-Portal
X-Azure-Ref
X-Oracle-Dms-Rid
X-Oracle-Dms-Ecid
X-Presslabs-Stats
X-Nginx-Cache
GEO-INFO
X-PressLabs-Stats
X-Source
X-Accel-Buffering
X-Ms-Version
X-Ratelimit-Remaining
X-Ms-Request-Id
X-Oneagent-Js-Injection
Count-Hit
Frame-Options
Healthy
Uber-Trace-Id
X-Cache-Operation
Ms-Operation-Id
X-RTag
X-APP-VERSION
MS-CV
X-Cache-NGX
X-EdgeConnect-Cache-Status
X-XRDS-Location
X-Zen-Fury
X-CDN-Forward
Countrycode
Xserver
X-Environment-Context
X-Cache-Hit
X-L-Path
X-Tumblr-Pixel
X-Tumblr-Pixel-1
X-Varnish-Server
X-Tumblr-Pixel-0
X-Tumblr-User
X-Backend-Name
X-Mode
Cross-Origin-Window-Policy
Protected
Ec-Rule-Version
X-IPS-LoggedIn
X-Forwarded-Host
X-Region
X-Servername
X-Cache-TTL-Remaining
Backend
X-UPSTREAM-Address
X-JoinUs
X-Rewrite-Enabled
X-Detected-As
X-Content-Powered-By
Meta-Geo
X-Tid
X-RN-RSRV
X-SaId
Decoy-Debug-Key
Decoy-Debug-TTL
X-Extlb
X-Debug-Cache
Country-Code
X-Zipkin-Id
X-Alternate-Cache-Key
X-Adobe-Loc
Apigw-Requestid
X-Sql-Duration-Ms
X-Adobe-Content
Eomportal-Instance
X-Cache-Server
X-Routing-Service
X-Sorting-Hat-ShopId
X-Hosted-By
X-Sorting-Hat-PodId
X-Cache-Grace
X-Redis-Cache
X-Shopify-Stage
X-Proxied
X-ShopId
X-Generation-Time
X-Sql-Count
Decoy-Debug-Status
X-ShardId
X-Uri
X-Hyper-Cache
Cache-Name
X-ServerID
X-PHP-Backend
X-PERF
X-Site-Version
X-Status
X-Via-Fastly
X-Varnish-Beresp-Grace
X-Origin-Date
X-No-Session
X-ApacheServer
Mn-Server-Ip
X-FB-TRIP-ID
X-Format
X-NCache
X-Human
Fastly-SSL
Url
Section-Io-Cache
X-Content-Age
Webcakes-App-Name
TWC-Privacy
Webcakes-App-Version
X-Access
X-BYPASS-REASON
X-Akamai-Edgescape
Webcakes-Region
TWC-Locale-Group
Selected-Fe
Property-Id
TWC-Connection-Speed
TWC-Device-Class
TWC-GeoIP-LatLong
TWC-GeoIP-Country
X-Cache-Host
X-Cluster-Node
X-Section
X-Pubstack
X-ProxyCache-Status
X-Server-W
X-Storage
X-UA-Device-Type
X-Timing-Wait
X-ProxyCache-Key
X-Proxy-Build
X-NewRelic-App-Data
Cache-Tv-Group
X-Microcachable
X-NYM-Debug-Backend
X-PCL
X-Origin-Hint
X-Cache-Type
X-OCL
X-Say-TTL
X-Say-Cacheable
WPO-Cache-Status
X-SayCDN-TTL
WPO-Cache-Message
X-R9-Blue-Green-Version
LB
X-Hl-Ver
X-Varnishpool
X-Web-Node
CDN-Uid
Azure-InstanceId
Azure-SiteName
CDN-RequestId
Content-Disposition
Azure-SlotName
X-RateLimit-Limit
X-TIME
X-Be
Content-Secure-Policy
Azure-RegionName
CDN-CachedAt
CDN-Cache
Azure-Version
DB-Nickname
X-Soup
CDN-EdgeStorageId
CDN-PullZone
CDN-RequestCountryCode
X-Generated-By
X-Trace-Id
X-Azure-Ref-OriginShield
X-Ua
X-LSADC-Cache
OT-Force-Account-Verify
SRV
X-Webkit-Csp
X-Cached-By
X-Dc
X-Nginx-Cache-Key
Source
X-SRV
X-Bc-Bl
Cache
X-Unique-Id
Retry-After
X-LAGOON
X-TT-LOGID
X-Auto-Login
X-Origin-CC
X-Cache-Remote
X-Origin-TTL
X-Platform-Server
Xet-Cookie
X-Varnish-Hits
Mime-Version
Cache-Hits
X-App-Version
X-Varnish-Hostname
X-GEO
HostName
X-Akamai-Transformed
X-TNCMS
X-Loop
X-HTML-Minification-Powered-By
X-Xfnlog-Site
X-S-Maxage
X-ECache
Onion-Location
X-Amz-Meta-S3cmd-Attrs
ServedBy
X-CSRF-Token
X-Cache-Tags
X-Cdn
Upgrade-Insecure-Requests
X-Tumblr-Pixel-3
Web-Mar-Node
X-Varnish-Cache-Hits
X-Tumblr-Pixel-2
X-EC-Lua
X-Proto
Webserver
X-Request-Time
X-CLOUD-TRACE-CONTEXT
X-AOL-HN
From-Origin
N-Cache
X-Time
X-Tenant
X-CACHE-KEY
X-Request-Host
WP-Super-Cache
X-Endurance-Cache-Level
X-LJ-Flow-ID
X-VWS-Id
X-AWS-Id
X-Cache-Var
X-Cache-Var-Map
X-FireWall-Port
X-GG-Cache-Date
X-Time-Microsecs
X-Origin-Response-Time
X-Edge-Location
X-Cache-Enabled
AMP-Access-Control-Allow-Source-Origin
X-Mg-Request-UUID
X-Handled-By
X-Ig-Push-State
X-Aed
X-Hnp-Log
X-Via-NSCOPI
X-Gen-Mode
A
X-External-Request-Id
X-Conf
X-Connection-Hash
X-D
X-A-Dcw
X-Cluster
X-Ckpd-Fst-Backend
X-Cache-NE
X-CF-Lambda-Fn
X-A-Dgt
X-CF-Lambda-Version
X-Destination
X-Developer
X-Forwarded-Path
X-Application
X-A
X-Ftr-Request-Id
X-A-Ccd
X-ARC
X-A-Dam
X-A-Wwc
X-Block-Status
X-B-Cookie
X-Aicache-OS
Rendered-Blocks
X-Labrador-Cache-Channel
Odigeo-Trace-Id
X-Rojux
X-S
DCR-Processing-Time-Ms
X-S-Cookie
Pramga
X-Processor
X-V-Cache
X-Vdms-Path
X-Planisys-CDN-TTL
X-TIM-N
Redirect-Candidate
DCR-Decision-By
Mobile-Detection-Method
Meta-Geo-Continent
X-SD-PageType
X-Session-Fingerprint
X-Shop-Environment
CloudFront-Viewer-Country
X-Slack-Backend
X-SRCache-Key
X-NWS-UUID-VERIFY
X-B3-SpanId
X-Amzn-RequestId
X-Amz-Apigw-Id
X-ScT
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
Surrogated-Key
X-PHP-Host
X-Correlation-ID
X-Orig-Expires
Nel
X-ND-Cache
Xc-Version
User-Cache-Control
BehaviorPad-Version
X-NAPM-TraceId
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
Fastcgi-X-Cache-Version
X-VG-WebCache
X-Vdms-Version
Vix-Hermes-Req-Id
X-PAYTM-SRV-ID
X-PBS-Appsvrname
Sslversion
Expiry
V-Age
X-MP-GENERATED-AT
Wxu-Next-Hostname
True-Client-Country-4JS
Wxu-Next-Region
State
Origin
Wxu-Next-Commit
Svr
Fastcgi-Cache-TTL
Gh-Request-Id
Host-ID
X-Owner
X-Proxy-Upstream
X-RCS-CacheZone
X-Request-URI
X-Policy
X-Origin-Time
X-Old-Content-Length
X-Origin-Expires
X-Scheme
X-Server-IP
X-Viewer-Country
X-Webstats-RespID
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-Sucuri-Cache
X-Sucuri-ID
X-Nyt-Route
X-NodeID
X-Fastly-Cache
X-Forwarded-Site
X-Gdpr
X-Epic-Correlation-Id
X-Date
X-Cache-Date
X-Cdn-Srv
X-Geo-Header
X-Hash
X-Men
X-Mvc-Supplant-Cachable
X-Location
X-LI-UUID
X-Li-Fabric
X-Li-Pop
X-Cache-Bucket
X-Accel-Expires-Debug
AKAMAI
X-Reqid
X-Adobe-Source
Arc-Country
CacheControlHeader
Cmsid
CDCHOST
Cmstype
X-Magnolia-Registration
DSUID
Fastly-Drupal-Html
X-M-Log
Server-Info
X-Qnm-Cache
X-Varnish-Ttl
Environment
X-M-Reqid
X-Locale
Apple-News-Services-Handled
X-Cdn-Origin
Web-Mar-Region
X-Esi-Check
X-RateLimit-Remaining-Second
Ha-Gx-Prefs
HA-Ipaddr
X-RateLimit-Limit-Second
We-Hiring
X-Region-Sid
X-Request-Start
Machine
X-Generated-On
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
X-Req
Apple-News-Services-Host
X-Eu-Site
X-Fastly-Backend
X-Backend-State
X-Branch-Name
X-HN
X-Gzip
X-GeoIP-City
X-Bip
X-GeoIP
X-HS-Content-Campaign-Id
X-Irp-Debug
X-Cache-Id
X-Cache-Info
X-Platform
X-Cache-Debug
X-Level-Front-Cache
X-Gamma-Serve
X-Fetched-On
Traceparent
X-Envoy-Decorator-Operation
X-Datadog-Sampling-Priority
X-VarnishDD-TTL
X-Core-Value
PFcat
X-Datadog-Trace-Id
X-Varnish-Beresp-Status
X-Rocket-Nginx-Serving-Static
Origin-EX
Origin-CC
X-Backend-TTL
Locid
X-Datadog-Parent-Id
L5d-Success-Class
X-VG-TLSProxy
X-VServer
X-Core-Mission
L
X-Sn-Servicetimems
X-CGP
X-TH-Server
X-Skip-Cache
X-Device-Os
X-Served-From
Mail-Subject
Release
Ssr
Server-Host
X-TrackingId
X-Csrf-Jwt
X-Developers
X-Thanos
X-UnsetCookies
X-Zone
X-VC-Cache
X-DefElseHash
X-DPWN-IS-SECURE
X-DefHash
X-FC-Vary-Parameters
X-Rebelmouse-Cache-Control
X-Variation
X-Varnish-CookieHashed-On
X-Thinkindot-L3
X-Storefront-Renderer-Rendered
X-Sigma-Backend
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
X-Origin
X-GeoIP-Region-Code
X-GeoIP-Country-Code
X-Worker
X-Sigma
X-Rocket-Build-Number
X-Node-Id
Fastly-SIE
X-JWT-State
X-Is-Gdpr
X-NU-AKA-ACS-Version
Fastly-GeoIP-CountryCode
X-Rebelmouse-Surrogate-Control
Fastly-SWR
X-Qloud-Router
X-Pod-Name
X-Has-Esi
X-Response-By
NM-Fastcgi-Cache
Is-Eu
TDXMobile
Thinkindot-CacheControl
Req-Svc-Chain
X-BBC-Edge-Cache-Status
Platform
X-Amzn-Remapped-Content-Length
X-ATG-Version
Cf-Device-Type
Thinkindot-CacheControl-Type
Memcached
Adler-Geo
Thinkindot-Control
X-Xrds-Location
NGX
X-Loc
S-Rt
X-Mvc-Supplant-OutputCached
X-Ua-Device
X-API-Version
X-Up
X-CS
Magicmarker
X-Cache-Config
X-LB-ID
X-NC
X-TraceId
X-Tx-Id
X-Akamai-Request-ID2
CDN
X-Http-Reason
X-Varnish-Beresp-Ttl
X-Restarts
X-Generated-In
X-Datadome
Ms-Author-Via
Kp-EeAlive
Pics-Label
Time
Memory
X-Trace-ID
X-Tt-Logid
X-Tb-Optimization-Total-Bytes-Saved
NtCoent-Length
X-Optimistic-Header
Candidate-Md5Url
X-Via-Popn
X-DW
X-DSS
X-Edge-Pop
X-DI
X-RPM
X-RPS
X-Wix-Viewer-Type
X-Cache-Backend
Edge-Cache
X-RSL
Datacenter
X-DB
X-Via-Popv
X-Action
X-Via-Poph
Env
Accept-Language
WebServer
X-LB-NoCache
X-Refresh
GeoIp-Country-Code
X-DynaTrace-JS-Agent
X-Minions-Version
X-Vc
WWW-Authenticate
On-Server
X-Varnish-Beresp-TTL
X-HA-Backend
X-DC
Esi-Enabled
X-TA-CDN-Provider
X-CacheTTL
X-Parent-Response-Time
X-TX-ID
X-Cs
X-Esi
Locale
X-Dynatrace
X-Srv
X-Urbn-Context-Path
X-Urbn-Site-Id
X-Unique-ID
X-MSEdge-Flight
X-MSEdge-Features
X-Servedbyhost
C-Via
X-Service
X-ZONE
X-Newrelic-Synthetics
X-User
X-Cache-PHP
X-Ec-GeoHdr
Server-ID
X-Ec-Fail
X-Li-Proto
X-Cache-Ttl
X-Cache-Status-Check
X-VCL-Version
X-Render-Time
X-FPC
X-App
X-LiteSpeed-Cache-Control
X-B3-Spanid
X-URL
X-LI-Proto
Cdnsip
Cdncip
X-Webkit-Csp-Report-Only
Test
X-AK-Request-ID
X-Fpc
X-Vcl-Version
X-Pass-Why
X-Traceid
Cluster
Server-Id
X-WADP-Cache
My-App
Geoip-Latitude
X-Clara-WADP
X-Fmm-Version
Geo-Info
X-Webkit-CSP-Report-Only
Proxy-Connection
X-NODE
Resin-Trace
X-CUA
X-Var-Ttl
Tracecode
X-Mcache
Tcn
M-TraceId
T-Server
X-Info
Lfy
X-AIR-PT
X-Clientip
X-LiteSpeed-Tag
X-From
DataCenter
Fastly-Drupal-HTML
Lang
X-Oss-Server-Time
Cf-Int-Pingora-Origin-Digest
X-Oss-Request-Id
X-Fragments
X-Oss-Object-Type
Cache-Host
X-Oss-Storage-Class
X-ServedByHost
UCS
X-Oss-Hash-Crc64ecma
HIT
X-CSRF-TOKEN
X-Ha-Backend
S-Cnection
X-ID
X-VC
Target-Params
X-Geo
X-Cdn-Forward
Hostname
Ohc-File-Size
GeoIP-Country-Code
Hit
X-RAMCache
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
X-HostName
X-Pad
X-Dynatrace-Js-Agent
X-Via-PopN
MIME-Version
X-Via-PopV
User-Agent
X-Micro-Cache
X-Edge-POP
X-ElasticPress-Query
ENV
Fastly-Backend-Name
X-Check-Cacheable
X-Via-PopH
X-Release
X-Proxy-Cache-Info
X-Edge-Cache
X-Lb-Nocache
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
Section-Io-Id
Section-Origin-Responded
X-Httpd
Load-Balancing
X-Api-Version
X-NGINX-Cache
X-BBC-Origin-Response-Status
X-Provided-By
X-Backend-Host
Permissions-Policy
X-ServerName
X-Ucs
X-Fastly-Backend-Reqs
Producers
PICS-Label
X-APP
X-BCube-Filmed-By
Servername
WZWS-RAY
X-HS-Status
FSS-Cache
X-UP
X-GoCache-CacheStatus
Uri
X-Cache-CFC
ServerName
X-SB
EpKe-Alive
URI
Lb
X-TRACE-ID
X-Pool
X-Swift-Error
X-Platform-Router
X-Lb-Id
X-Udemy-Cache-App-Namespace
Server-Ttl
X-Platform-Processor
X-Platform-Cluster
Cteonnt-Length
Cneonction
X-B3-ParentSpanId
X-Nc
Cache-Key
Cdn
X-RateLimit-Reset
Ohc-Cache-HIT
CPC-Age
X-WA-Info
X-WA
X-Amz-Meta-Cb-Modifiedtime
Path
X-Cdn-Request-ID
VNS-Cache
X-Fastly-Cache-Hits
CPC-Cache
VNS-Age
X-Dw-Trace-Id
X-Scale
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-Apw-Access-Action
X-Shopify-Generated-Cart-Token
X-Newrelic-App-Data
X-Akamai-ERPolicy
Cf-Ipcountry
X-Ec-Custom-Error
X-Acquia-Site
X-Vcache
X-Akamai-ERRuleID
X-Akamai-Request-ID
X-Acquia-Purge-Tags
X-Contensis-Viewer-Groups
X-Cache-ASPX
X-Apw-Hits
X-Snapshot-Date
CF-Cached-On
X-ES-SERVER
X-Yottaa-OS
X-Apw-Access-Token
Shield-Pop
X-Acquia-Application-Trace
X-Apw-Access-Object
X-Acquia-Application-UUID
Vha6-Origin
Sid
X-Cache-Ngx
X-Air-Pt
X-CacheKey
X-UA
X-Cache-Expires
X-Logging-Id
X-PJAX-URL
X-Akamai-Pragma-Client-IP
Req-ID
X-Cms-Context
X-Varnish-Authentication
X-Te-Count
X-Http-Duration-Ms
X-Http-Count
X-Te-Duration-Ms
X-Last-Modified
X-Sentry-ID
Ngx
CountryCode
Pagetype