Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-Cache-Status
Link
Accept-Ranges
CF-RAY
ETag
X-XSS-Protection
Expect-CT
Pragma
X-Powered-By
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
Alt-Svc
P3P
X-Served-By
X-Xss-Protection
X-Download-Options
X-Timer
X-Request-Id
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Cache-Status
X-Generator
X-Cacheable
Timing-Allow-Origin
X-Content-Security-Policy
P3p
X-Iinfo
Status
Feature-Policy
X-Envoy-Upstream-Service-Time
Content-Encoding
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
X-CDN
X-AspNetMvc-Version
X-Request-ID
Upgrade
X-Via
CF-Ray
X-Ws-Request-Id
Access-Control-Max-Age
Server-Timing
EagleId
Keep-Alive
X-Cache-Group
X-Turbo-Charged-By
Request-Context
X-Age
X-Server-Powered-By
X-Proxy-Cache
X-UA-Device
X-AH-Environment
X-Backend
X-Hacker
X-Robots-Tag
Report-To
X-Amz-Request-Id
Host-Header
X-Server
X-Amz-Id-2
X-LiteSpeed-Cache
Grace
X-Rq
X-Nginx-Cache-Status
X-Varnish-Cache
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-WebKit-CSP
X-Dns-Prefetch-Control
X-Page-Speed
X-Vhost
EagleEye-TraceId
X-OneAgent-JS-Injection
X-Amz-Version-Id
X-Ua-Compatible
X-Pingback
X-Dispatcher
X-Device
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Cache-Spec
NEL
X-Server-Id
X-Host
Cf-Railgun
X-Node
X-Backend-Server
Accept-CH
X-Readtime
X-Akam-SW-Version
Surrogate-Control
Request-Id
X-Response-Time
X-HW
Xkey
X-Ruxit-JS-Agent
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Application-Context
Content-Location
Rating
X-Country
X-B3-TraceId
Accept-Ch-Lifetime
Accept-CH-Lifetime
X-Cache-Lookup
X-Cloud-Trace-Context
X-Trace
X-Url
X-Ac
X-Content-Type
Allow
X-PC
X-TtlSet
X-Vname
X-Varnish-TTL
X-Clacks-Overhead
X-Mod-Pagespeed
Edge-Control
X-FastCGI-Cache
X-ESI
Fastly-Restarts
X-Server-Name
Cache-Tag
X-VARITI-CCR
X-Rack-Cache
Service-Worker-Allowed
X-Element-Page-Cache
Verso
X-Language
X-MS-InvokeApp
X-GitHub-Request-Id
X-Upstream
MS-Author-Via
X-Amz-Rid
X-Vcap-Request-Id
Public-Key-Pins
X-Aws-Lambda-Call-Status
X-Cached
X-Dw-Request-Base-Id
X-Client-IP
X-D2id
X-Abt-Application-Version
X-Cache-TTL
X-Template
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-Cnection
X-Origin-Cache
X-Px
Arr-Disable-Session-Affinity
X-Country-Code
RTSS
X-Navigation-Version
Access-Control-Request-Method
X-Powered-By-Plesk
X-Goog-Hash
X-NF-Request-ID
X-Instrumentation
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
Accept-Ch
X-GoogleNews-Bot
X-Cdn-Fetch
X-Exp-Id
X-Exp-Variant
X-Kinja-Build
X-Use-Magma
X-Version
X-Kinja-Server
X-Kinja-Revision
X-Kinja
X-Powered-CMS
X-Sol
X-Middleton-Display
Pagespeed
Display
AR-PoweredBy
AR-ATIME
AR-Request-ID
AR-SID
AR-CACHE
X-Amz-Server-Side-Encryption
Response
X-Middleton-Response
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-MSEdge-Ref
X-LLID
X-Kinsta-Cache
X-Edge
X-Edge-Location-Klb
Nginx-Cache
MRF-Tech
X-B3-TraceId-Primal
Mrf-Cache-Status
X-TTL
X-RateLimit-Remaining
X-Protected-By
X-Shield-Request-Id
X-Jurisdiction
X-HP-Webp
X-HP-Trace-Id
TCN
X-T
X-Buckets
X-Forwarded-For
S
X-Content-Security-Policy-Report-Only
X-Mg-S
Content-MD5
X-Id
X-Aspnetmvc-Version
X-Mid
Edge-Cache-Tag
Fastcgi-Cache
Realpath
X-CST
SPIisLatency
SPRequestDuration
X-MCACHE
Front-End-Https
X-Recruiting
X-Request-Received
X-Request-Processing-Time
Pinterest-Version
X-Pinterest-Rid
Filters
X-Ttl
Pinterest-Generated-By
Server-Node
X-Ua-Browser
X-Content
X-Ab
X-Correlation-Id
X-DynaTrace
Server-Name
X-NWS-LOG-UUID
X-Frontend
X-Parallel-Accel
X-SharePointHealthScore
SPRequestGuid
X-HS-Cache-Config
X-HS-Hub-Id
X-HS-Content-Id
Fusion-Content-Id
Fusion-Deployment-Id
Fusion-Content-Source
Fusion-Template-Id
Fusion-Source
Fusion-Component-Id
X-Ezoic-Cdn
X-HS-Combine-CSS
X-Yandex-Sdch-Disable
X-ECACHE
X-Hits
Alternate-Protocol
X-Ser
X-Cache-Key
X-Content-Options
X-Tt-Trace-Host
X-Tt-Trace-Tag
MicrosoftSharePointTeamServices
X-Page-Id
Cache-Tags
X-Kong-Upstream-Latency
X-Git-Hash
X-B3-Sampled
Host
X-Kong-Proxy-Latency
Charset
Cleartype
X-Fastly-Request-Id
X-Www-Served-By
X-Ruxit-Js-Agent
X-Accel-Expires
X-Daa-Tunnel
X-Geo-Country
X-DIS-Request-ID
X-Amz-Replication-Status
X-Content-Digest
X-Amzn-Trace-Id
Filterid
X-XRDS-LOCATION
X-Debug-Info
X-Varnish-Age
TP-L2-Cache
TP-Cache
X-Forwarded-Proto
X-Hostname
X-AppVersion
X-Az
X-Activity-Id
X-Upgrade-Enabled
X-FB-Debug
X-VCache
X-Rid
Access-Control-Allow-Method
X-Origin-Server
X-Grace
Cross-Origin-Opener-Policy
X-Ratelimit-Limit
X-LB-Cache
X-WebKit-CSP-Report-Only
X-Nginx-Upstream-Cache-Status
X-N
X-F-Cache
X-Mobile-URL
ServerID
X-Request-Guid
X-Providence-Cookie
X-Is-Crawler
X-Aspnet-Duration-Ms
X-Route-Name
X-Flags
X-Whom
X-TT
X-Goog-Generation
X-GUploader-UploadID
X-Goog-Storage-Class
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
Viewport
X-Varnish-Grace
X-Tb
X-App-Environment
Payment
X-Distributor
X-App-Server
X-FW-Static
Node
X-FW-Type
X-FW-Server
X-FW-Hash
X-FW-Dynamic
X-FW-Serve
X-Origin-Upstream-Status
X-Seen-By
DC
X-Server-ID
Paypal-Debug-Id
X-Type
X-User-Agent
Fastcgi-Useragent
X-Cache-Control
X-NGENIX-Cache
Country
Accept-Charset
X-Logged-In
X-Request-Handler-Origin-Region
X-Microsite
X-Cache-Rule
X-Wix-Request-Id
X-Litespeed-Cache
X-Cache-Age
Version
X-Via-JSL
X-Webkit-CSP
X-DataDome
X-Varnish-Backend
X-Drupal-Cache-Tags
X-Browser-Type
X-Erf-Bev-Bev
Referer-Policy
X-Erf-Bev-Bev-Is-Generated
X-Cluster-Name
X-Load-Cache
X-Node-Name
Refresh
X-B-Cache
X-Mobile
X-Contextid
X-Signature
X-Response-Served-From
X-Original-Request-Id
X-Tec-Api-Version
Access-Control-Request-Headers
X-Cache-Action
X-Tec-Api-Root
Amp-Access-Control-Allow-Source-Origin
Cache-Status
SD-X-WS
X-Tec-Api-Origin
X-Jobs
X-IPLB-Instance
X-Vgn-Hpd-Reason
X-Page-View
X-Cacheable-TTL
X-Real-IP
X-Rendered-As
X-Cache-Expired-At
X-Is-Bot
X-RemovedCookies
X-Revision
X-Proxy-Cache-Status
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-B
X-UUID
X-ProcessESI
X-Debug
X-Instance
X-Proxy
X-Rule
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Fastly-Request-ID
X-Cache-Time
Akamai-GRN
Surrogate-Key
X-Framework
X-Drupal-Cache-Contexts
NGB
X-G
X-Debug-IsPreview
X-Debug-IsConnected
X-Device-Type
CF-IPCountry
X-Fastcgi-Cache
X-FW-Version
X-Air-Trace-Id
X-Air-Source
X-Air-Hostname
DynaTrace
X-TEC-API-ORIGIN
X-Ratelimit-Reset
X-TEC-API-VERSION
X-TEC-API-ROOT
Liferay-Portal
SID
X-Azure-Ref
X-PressLabs-Stats
Healthy
X-Oracle-Dms-Ecid
X-Oracle-Dms-Rid
X-Presslabs-Stats
X-Nginx-Cache
X-Ms-Request-Id
Frame-Options
GEO-INFO
X-Ms-Version
X-Source
X-Oneagent-Js-Injection
MS-CV
X-CDN-Forward
Ms-Operation-Id
X-Cache-Operation
Count-Hit
X-RTag
X-APP-VERSION
Uber-Trace-Id
X-Accel-Buffering
X-Environment-Context
X-Tumblr-Pixel
X-Tumblr-User
X-Tumblr-Pixel-0
X-EdgeConnect-Cache-Status
Countrycode
Xserver
X-Tumblr-Pixel-1
X-Cache-Hit
X-L-Path
X-XRDS-Location
X-Varnish-Server
X-Zen-Fury
Ec-Rule-Version
X-Backend-Name
X-Mode
X-Region
X-Servername
X-Forwarded-Host
Cross-Origin-Window-Policy
Backend
X-Cache-NGX
X-IPS-LoggedIn
X-Content-Powered-By
Section-Io-Cache
X-Cache-Type
Meta-Geo
X-RN-RSRV
Protected
X-Cache-TTL-Remaining
X-Detected-As
X-SaId
X-JoinUs
X-UPSTREAM-Address
X-Zipkin-Id
X-Cache-Server
X-Sql-Count
X-Uri
X-Alternate-Cache-Key
X-Varnish-Beresp-Grace
X-Sorting-Hat-ShopId
X-ShardId
Decoy-Debug-Status
Decoy-Debug-Key
Country-Code
Apigw-Requestid
X-Cache-Grace
Decoy-Debug-TTL
X-Shopify-Stage
X-ShopId
Eomportal-Instance
X-Rewrite-Enabled
X-Sorting-Hat-PodId
X-Extlb
X-Redis-Cache
X-Human
X-Hosted-By
X-Generation-Time
X-Routing-Service
X-Proxied
X-Tid
X-Sql-Duration-Ms
X-PERF
X-ServerID
X-NCache
X-No-Session
X-Origin-Date
Url
X-Via-Fastly
X-PHP-Backend
X-UA-Device-Type
Mn-Server-Ip
X-ApacheServer
X-Microcachable
Cache-Name
Fastly-SSL
X-Status
Cache-Tv-Group
X-Soup
X-FB-TRIP-ID
X-Site-Version
X-Storage
X-SayCDN-TTL
Selected-Fe
TWC-Connection-Speed
Property-Id
X-Say-TTL
X-Timing-Wait
DB-Nickname
TWC-Device-Class
X-OCL
X-Origin-Hint
TWC-Privacy
X-BYPASS-REASON
X-ProxyCache-Status
X-Akamai-Edgescape
X-NYM-Debug-Backend
X-Format
X-Web-Node
X-Cache-Host
X-Say-Cacheable
X-ProxyCache-Key
X-Adobe-Content
TWC-GeoIP-LatLong
X-PCL
TWC-GeoIP-Country
TWC-Locale-Group
Webcakes-App-Name
Webcakes-Region
Webcakes-App-Version
X-Proxy-Build
X-Server-W
X-Adobe-Loc
X-NewRelic-App-Data
X-Varnishpool
OT-Force-Account-Verify
X-Access
X-R9-Blue-Green-Version
X-Pubstack
X-Debug-Cache
X-Hl-Ver
X-Content-Age
X-Section
X-Cluster-Node
Azure-RegionName
Azure-SiteName
Azure-Version
Azure-InstanceId
Azure-SlotName
Content-Secure-Policy
X-Be
X-RateLimit-Limit
X-LSADC-Cache
SRV
X-Ua
X-Hyper-Cache
CDN-EdgeStorageId
CDN-CachedAt
CDN-PullZone
CDN-RequestCountryCode
CDN-RequestId
CDN-Uid
CDN-Cache
X-Azure-Ref-OriginShield
X-Generated-By
Content-Disposition
Source
X-Webkit-Csp
X-Cached-By
X-TIME
LB
X-Unique-Id
X-Dc
X-Trace-Id
Cache
X-Nginx-Cache-Key
WPO-Cache-Status
WPO-Cache-Message
X-Bc-Bl
X-LAGOON
X-Ratelimit-Remaining
X-SRV
X-App-Version
X-HTML-Minification-Powered-By
Cache-Hits
Retry-After
X-Varnish-Hits
X-Auto-Login
X-Akamai-Transformed
X-TNCMS
Xet-Cookie
X-Loop
X-Amz-Meta-S3cmd-Attrs
X-GEO
X-Origin-CC
X-Origin-TTL
X-TT-LOGID
X-Varnish-Hostname
X-S-Maxage
Mime-Version
Onion-Location
X-ECache
X-Platform-Server
X-Cache-Var-Map
X-Cache-Var
X-Xfnlog-Site
X-CSRF-Token
Web-Mar-Node
X-Cdn
X-Tumblr-Pixel-3
X-Tumblr-Pixel-2
X-Proto
HostName
X-Time
X-Cache-Tags
X-Cache-Remote
Webserver
X-Tenant
X-Edge-Location
Upgrade-Insecure-Requests
X-Varnish-Cache-Hits
X-Time-Microsecs
ServedBy
X-VWS-Id
X-AWS-Id
X-LJ-Flow-ID
X-Request-Time
N-Cache
X-EC-Lua
X-AOL-HN
X-Endurance-Cache-Level
X-GG-Cache-Date
CloudFront-Viewer-Country
X-Mg-Request-UUID
X-M-Reqid
X-M-Log
X-Qnm-Cache
X-Request-Host
From-Origin
X-Amzn-RequestId
X-Labrador-Cache-Channel
X-Amz-Apigw-Id
X-PHP-Host
WP-Super-Cache
X-FireWall-Port
X-B3-SpanId
X-Via-NSCOPI
X-Ig-Push-State
A
X-Planisys-CDN-Cache
X-Hnp-Log
X-A-Dgt
X-PAYTM-SRV-ID
X-ND-Cache
X-A-Dcw
X-Orig-Expires
X-Origin-Response-Time
X-NAPM-TraceId
X-PBS-Appsvrname
Meta-Geo-Continent
Redirect-Candidate
Rendered-Blocks
X-Cache-NE
X-Cache-Date
Pramga
X-CF-Lambda-Fn
Origin
X-CF-Lambda-Version
X-A-Ccd
Sslversion
Surrogated-Key
X-ARC
X-Application
X-Aed
X-A
V-Age
X-Block-Status
X-B-Cookie
User-Cache-Control
X-Cluster
Odigeo-Trace-Id
DCR-Processing-Time-Ms
DSUID
Expiry
Fastcgi-X-Cache-Version
DCR-Decision-By
X-Forwarded-Path
X-Gen-Mode
CDCHOST
X-Ftr-Request-Id
X-External-Request-Id
X-Developer
X-Connection-Hash
X-Conf
X-Planisys-CDN-TTL
Mobile-Detection-Method
X-A-Dam
X-Destination
L
X-D
BehaviorPad-Version
X-Planisys-CDN-Rules
X-Vdms-Version
X-S
X-Rojux
X-CACHE-KEY
X-SVT-ORM-RULES
X-V-Cache
X-Slack-Backend
Nel
X-VG-WebCache
X-SD-PageType
X-ScT
X-Correlation-ID
X-S-Cookie
X-SRCache-Key
X-RCS-CacheZone
X-SVT-ORM-VERSION
Xc-Version
X-TIM-N
X-Vtex-Remote-Cache
X-Session-Fingerprint
X-Vtex-Processado-Em
X-Processor
X-A-Wwc
X-Shop-Environment
X-Vdms-Path
X-Handled-By
X-MP-GENERATED-AT
X-Locale
X-Cache-Bucket
X-VarnishDD-TTL
X-Fastly-Cache
X-Forwarded-Site
X-Epic-Correlation-Id
X-Skip-Cache
Server-Info
Cmstype
X-Fetched-On
Cmsid
Fastcgi-Cache-TTL
X-Sucuri-Cache
Origin-EX
Origin-CC
X-Core-Mission
X-Ckpd-Fst-Backend
PFcat
X-Cdn-Srv
Release
X-Cache-Info
X-Sucuri-ID
Ssr
Host-ID
Svr
Gh-Request-Id
X-Storefront-Renderer-Rendered
Traceparent
State
X-Varnish-Beresp-Status
X-Date
X-Device-Os
X-Geo-Header
X-NodeID
X-Nyt-Route
X-Rocket-Nginx-Serving-Static
X-Old-Content-Length
X-Aicache-OS
X-Mvc-Supplant-Cachable
X-Scheme
X-Location
X-Gdpr
X-Accel-Expires-Debug
X-Origin-Expires
X-VServer
X-Webstats-RespID
X-Policy
X-Owner
Wxu-Next-Region
Wxu-Next-Commit
Wxu-Next-Hostname
X-Origin-Time
X-LI-UUID
X-Men
X-Server-IP
Arc-Country
X-Hash
X-Served-From
X-Li-Pop
Vix-Hermes-Req-Id
CacheControlHeader
X-Li-Fabric
True-Client-Country-4JS
X-HN
AKAMAI
Fastly-Drupal-Html
X-NWS-UUID-VERIFY
AMP-Access-Control-Allow-Source-Origin
X-VC-Cache
Environment
X-TrackingId
L5d-Success-Class
X-Cdn-Origin
HA-Ipaddr
X-Viewer-Country
X-Cache-Id
X-Cache-Debug
X-VG-TLSProxy
X-ATG-Version
X-Branch-Name
X-Adobe-Source
X-Bip
X-Cache-Config
X-Sn-Servicetimems
X-Eu-Site
X-RateLimit-Limit-Second
X-Node-Id
X-Level-Front-Cache
X-Irp-Debug
X-Gzip
X-Envoy-Decorator-Operation
X-HS-Content-Campaign-Id
X-Rocket-Build-Number
X-Request-Start
X-UnsetCookies
X-Request-URI
Ha-Gx-Prefs
X-RateLimit-Remaining-Second
X-Proxy-Upstream
X-Reqid
X-Region-Sid
X-GeoIP-City
X-GeoIP
X-Core-Value
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
X-TH-Server
X-Csrf-Jwt
X-Thanos
X-Backend-State
X-CGP
X-Datadog-Trace-Id
X-Developers
X-Sigma
X-Gamma-Serve
X-Generated-On
X-Sigma-Backend
X-Platform
X-Esi-Check
X-Fastly-Backend
X-Thinkindot-L3
X-BBC-Edge-Cache-Status
Server-Host
Apple-News-Services-Handled
TDXMobile
Thinkindot-CacheControl
Thinkindot-Control
Thinkindot-CacheControl-Type
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
Machine
Mail-Subject
Locid
Fastly-GeoIP-CountryCode
Apple-News-Services-Request-Url
Req-Svc-Chain
X-Magnolia-Registration
X-Cache-Enabled
Web-Mar-Region
We-Hiring
X-Zone
X-FC-Vary-Parameters
X-Varnish-Remaining-TTL
Cf-Device-Type
Fastly-SIE
X-Varnish-CookieINHashed-On
X-DPWN-IS-SECURE
X-DefElseHash
X-Worker
X-DefHash
Is-Eu
X-Varnish-CookieHashed-On
Fastly-SWR
X-Variation
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-Qloud-Router
X-Pod-Name
X-Loc
Memcached
X-JWT-State
X-Response-By
X-Has-Esi
X-Req
Adler-Geo
X-Is-Gdpr
X-Origin
X-NU-AKA-ACS-Version
X-Amzn-Remapped-Content-Length
Platform
NM-Fastcgi-Cache
NGX
X-Xrds-Location
X-Tx-Id
X-Mvc-Supplant-OutputCached
X-Datadome
X-Backend-TTL
X-Ua-Device
X-NC
X-API-Version
X-GeoIP-Region-Code
X-CS
X-GeoIP-Country-Code
X-CLOUD-TRACE-CONTEXT
X-LB-ID
CDN
Datacenter
X-Varnish-Beresp-Ttl
Candidate-Md5Url
X-Up
Pics-Label
X-Generated-In
X-DynaTrace-JS-Agent
X-Vc
X-TraceId
S-Rt
X-Trace-ID
Magicmarker
Ms-Author-Via
X-Tt-Logid
X-Tb-Optimization-Total-Bytes-Saved
Env
X-LB-NoCache
WWW-Authenticate
Kp-EeAlive
NtCoent-Length
X-Restarts
On-Server
X-Edge-Pop
Esi-Enabled
X-Via-Popv
GeoIp-Country-Code
WebServer
X-Via-Popn
X-Via-Poph
Memory
Time
X-Varnish-Ttl
X-Akamai-Request-ID2
X-Http-Reason
X-RSL
X-DSS
X-RPS
X-RPM
X-DB
X-Varnish-Beresp-TTL
X-TA-CDN-Provider
X-Action
X-Optimistic-Header
X-Refresh
X-DI
X-DW
X-Cache-Backend
X-Wix-Viewer-Type
Edge-Cache
X-Srv
C-Via
X-DC
X-Service
X-CacheTTL
X-Dynatrace
X-Newrelic-Synthetics
X-Servedbyhost
X-Cs
X-Cache-PHP
X-Esi
X-Parent-Response-Time
X-Unique-ID
X-Minions-Version
X-ZONE
Accept-Language
X-TX-ID
X-MSEdge-Flight
X-MSEdge-Features
X-Cache-Status-Check
Server-ID
X-Render-Time
X-HA-Backend
X-Li-Proto
X-Urbn-Site-Id
X-Urbn-Context-Path
Locale
X-VCL-Version
X-Ec-Fail
X-Ec-GeoHdr
X-User
X-FPC
X-App
X-Cache-Ttl
X-URL
X-B3-Spanid
Proxy-Connection
X-Pass-Why
X-LI-Proto
X-Fpc
X-AIR-PT
Test
X-Webkit-Csp-Report-Only
X-Info
Server-Id
X-LiteSpeed-Cache-Control
X-Traceid
X-Clientip
X-Vcl-Version
X-NODE
X-Webkit-CSP-Report-Only
Geo-Info
X-Oss-Object-Type
Cdnsip
Tcn
Cache-Host
X-AK-Request-ID
Cdncip
X-Oss-Hash-Crc64ecma
X-Oss-Storage-Class
UCS
X-Oss-Server-Time
X-Oss-Request-Id
HIT
M-TraceId
X-Clara-WADP
S-Cnection
Geoip-Latitude
X-Fmm-Version
Cluster
My-App
X-WADP-Cache
Fastly-Drupal-HTML
Cf-Int-Pingora-Origin-Digest
X-LiteSpeed-Tag
Tracecode
X-Var-Ttl
Resin-Trace
X-Ha-Backend
X-HostName
X-CUA
X-CSRF-TOKEN
Hostname
Fastly-Backend-Name
X-ID
X-Micro-Cache
Lfy
T-Server
X-ServedByHost
User-Agent
X-From
Lang
X-Via-PopV
X-Via-PopH
X-Via-PopN
GeoIP-Country-Code
X-RAMCache
X-Pad
X-Fragments
Hit
Section-Io-Origin-Status
Section-Io-Id
X-Mcache
X-Release
Ohc-File-Size
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
X-Backend-Host
X-BBC-Origin-Response-Status
Lb
X-Geo
X-Dynatrace-Js-Agent
X-Cdn-Forward
DataCenter
X-WP-CF-Super-Cache
X-BCube-Filmed-By
X-Check-Cacheable
X-Edge-POP
X-WP-CF-Super-Cache-Cache-Control
MIME-Version
X-APP
Target-Params
X-ElasticPress-Query
ENV
X-Edge-Cache
X-Api-Version
X-NGINX-Cache
X-HS-Status
Load-Balancing
X-Amz-Meta-Cb-Modifiedtime
X-Fastly-Backend-Reqs
EpKe-Alive
Cache-Key
URI
X-ServerName
X-WA
Path
VNS-Age
Servername
X-Ucs
CPC-Cache
CPC-Age
X-UP
X-WA-Info
Uri
VNS-Cache
X-VC
X-ES-SERVER
X-Wikidot-Static-Cache
PICS-Label
X-Wikidot-Backend
Permissions-Policy
X-Fastly-Cache-Hits
FSS-Cache
X-GoCache-CacheStatus
X-Proxy-Cache-Info
X-Httpd
X-Lb-Nocache
X-TRACE-ID
X-Cms-Context
X-Cdn-Request-ID
X-Lb-Id
X-PJAX-URL
X-Nc
Cdn
Shield-Pop
ServerName
Cneonction
X-Akamai-ERRuleID
X-Akamai-ERPolicy
Cteonnt-Length
Ohc-Cache-HIT
Producers
Sid
X-B3-ParentSpanId
X-Provided-By
WZWS-RAY
X-RateLimit-Reset
Pagetype
X-Dw-Trace-Id
X-SB
X-Pool
X-Acquia-Application-UUID
X-Acquia-Site
Server-Ttl
X-Acquia-Purge-Tags
X-Acquia-Application-Trace
X-Cache-CFC
X-Akamai-Pragma-Client-IP
Vha6-Origin
X-Apw-Access-Object
X-Apw-Access-Token
X-Apw-Access-Action
CF-Cached-On
X-Snapshot-Date
X-Apw-Hits
X-Via-Ucdn
X-Contensis-Viewer-Groups
X-Cache-ASPX
X-Yottaa-OS
Srv
X-Vcache
X-Hcs-Proxy-Type
Cf-Ipcountry
X-Swift-Error
X-CCDN-Origin-Time
X-CCDN-CacheTTL
MD5-Digest
X-Newrelic-App-Data
X-Cache-Ngx
X-Air-Pt
X-Platform-Processor
X-Platform-Router
X-Platform-Cluster
X-VG-WebServer
X-Miniprofiler-Ids
X-Udemy-Cache-App-Namespace
X-Last-Modified
X-Te-Count
IsBot
CountryCode
Req-ID
X-B3-Parentspanid
Ngx
Server-Hostname
X-Sentry-ID
Server-Ext
X-UA
X-CacheKey
Sever-Int
X-Te-Duration-Ms
X-SIPLIST1
X-Http-Duration-Ms
X-Http-Count
X-Logging-Id
W
X-Varnish-Authentication