Threat Level: green Handler on Duty: Russ McRee

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
X-Powered-By
Pragma
X-XSS-Protection
X-Cache
CF-RAY
Via
Age
Content-Security-Policy
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
Alt-Svc
P3P
X-Cache-Hits
X-UA-Compatible
X-Xss-Protection
CF-Ray
X-Served-By
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
Access-Control-Allow-Credentials
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
X-Drupal-Cache
X-Generator
X-Cache-Status
X-Check
X-Cacheable
X-DNS-Prefetch-Control
X-FRAME-OPTIONS
X-Envoy-Upstream-Service-Time
Timing-Allow-Origin
X-Iinfo
X-Drupal-Dynamic-Cache
Feature-Policy
X-Content-Security-Policy
X-Dns-Prefetch-Control
Content-Encoding
X-XSS-PROTECTION
Access-Control-Expose-Headers
Server-Timing
Upgrade
X-CDN
Status
X-Request-ID
X-AspNetMvc-Version
Access-Control-Max-Age
X-Amz-Request-Id
Request-Context
X-Amz-Id-2
X-Via
X-Turbo-Charged-By
X-AH-Environment
X-Backend
X-Cache-Group
X-Robots-Tag
Cf-Edge-Cache
Keep-Alive
Host-Header
X-Hacker
X-Proxy-Cache
X-UA-Device
X-Server
X-Rq
X-Vhost
X-Server-Powered-By
Allow
X-Age
X-Varnish-Cache
X-Ws-Request-Id
X-Dispatcher
X-Amz-Version-Id
EagleId
P3p
Nel
Grace
Cf-Apo-Via
X-LiteSpeed-Cache
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Page-Speed
Cf-Railgun
X-Device
EagleEye-TraceId
X-Aws-Lambda-Call-Status
X-Swift-SaveTime
X-Swift-CacheTime
X-OneAgent-JS-Injection
X-Pingback
Ali-Swift-Global-Savetime
X-Node
Accept-CH
X-Host
X-WebKit-CSP
X-CST
X-Backend-Server
Surrogate-Control
X-Server-Id
X-Cache-Lookup
X-Nginx-Cache-Status
X-Readtime
Accept-CH-Lifetime
Permissions-Policy
X-Akam-SW-Version
X-Nginx-Upstream-Cache-Status
Request-Id
X-EdgeConnect-Origin-MEX-Latency
X-Application-Context
X-EdgeConnect-MidMile-RTT
X-Content-Security-Policy-Report-Only
X-Cloud-Trace-Context
X-Ua-Compatible
X-Trace
X-Response-Time
X-HW
X-Edge
Content-Location
X-Clacks-Overhead
X-Mod-Pagespeed
Xkey
X-Litespeed-Cache
X-Midtier
Rating
X-ESI
X-Ruxit-JS-Agent
X-Url
X-Amz-Server-Side-Encryption
X-ECACHE
X-Mcache
X-Upstream
X-Ruxit-Js-Agent
X-Vcap-Request-Id
Accept-Ch
Cache-Tag
X-D2id
X-MS-InvokeApp
Verso
X-Use-Magma
X-Cdn-Fetch
X-Kinja-Build
X-GoogleNews-Bot
X-Kinja
X-Kinja-Revision
X-Element-Page-Cache
X-Kinja-Server
X-Exp-Id
X-Exp-Variant
X-Rack-Cache
X-TtlSet
X-Vname
X-PC
X-Powered-By-Plesk
Edge-Control
Accept-Ch-Lifetime
X-WebKit-CSP-Report-Only
RTSS
X-Country
Fastly-Restarts
X-Cache-TTL
X-Oneagent-Js-Injection
X-Ac
X-VARITI-CCR
Origin-Trial
X-Navigation-Version
X-Abt-Application-Version
X-Country-Code
Service-Worker-Allowed
X-Goog-Hash
X-Cached
X-Ttl
X-Varnish-TTL
X-Sol
Pagespeed
X-Middleton-Display
Display
X-Browser-Type
X-Amz-Rid
X-GitHub-Request-Id
Cross-Origin-Opener-Policy
X-Dw-Request-Base-Id
SPRequestGuid
X-SharePointHealthScore
X-Server-Name
X-Content-Type
X-Mg-S
X-Amzn-Trace-Id
X-B3-TraceId
X-Powered-CMS
X-Erf-Bev-Bev
Arr-Disable-Session-Affinity
Response
X-Middleton-Response
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-Instrumentation
X-Erf-Bev-Bev-Is-Generated
AR-PoweredBy
AR-SID
AR-ATIME
AR-Request-ID
X-NF-Request-ID
X-Kinja-CCPA
SPIisLatency
SPRequestDuration
X-Cache-Key
X-Webkit-CSP
X-Times
X-NWS-LOG-UUID
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
X-Version
X-Pinterest-Rid
Pinterest-Version
Pinterest-Generated-By
AR-CACHE
X-SRCache-Store-Status
X-HP-Webp
X-SRCache-Fetch-Status
X-Jurisdiction
X-HP-Trace-Id
X-Accel-Expires
Cache-Tags
X-T
X-Cnection
Cache-Status
X-RateLimit-Remaining
X-Fastly-Request-ID
Front-End-Https
X-Aspnetmvc-Version
X-FastCGI-Cache
Nginx-Cache
Edge-Cache-Tag
X-MSEdge-Ref
X-Hits
X-B3-Traceid
X-Ser
X-Px
X-Client-IP
MRF-Tech
Public-Key-Pins
Mrf-Cache-Status
X-RateLimit-Limit
X-B3-TraceId-Primal
X-Recruiting
Payment
X-LLID
X-Frontend
X-Request-Received
X-Request-Processing-Time
Server-Node
X-Ua-Browser
X-Server-ID
X-Erf-Stays-Pdp-Viaduct-Migration-Web
X-Shield-Request-Id
X-DIS-Request-ID
S
TP-Cache
X-Fastcgi-Cache
X-Goog-Metageneration
X-GUploader-UploadID
Access-Control-Request-Method
MicrosoftSharePointTeamServices
X-HS-Content-Id
X-Amz-Apigw-Id
X-HS-Hub-Id
X-Amzn-RequestId
X-HS-Cache-Config
X-HS-Combine-CSS
Content-MD5
X-Content-Digest
X-Request-Handler-Origin-Region
X-Distributor
X-LB-Cache
X-Protected-By
X-Microsite
TP-L2-Cache
Realpath
X-FB-Debug
X-Page-Id
Access-Control-Allow-Method
Fastcgi-Cache
Accept-Charset
X-Cluster-Name
X-Ezoic-Cdn
X-Geo-Country
X-Forwarded-For
X-Rid
X-PressLabs-Stats
X-Hostname
X-Webkit-Csp
X-Aspnet-Version
X-B3-Sampled
X-Ua-Device
X-Correlation-Id
X-Seen-By
Cleartype
Referer-Policy
X-Daa-Tunnel
X-Goog-Generation
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Mobile
X-Envoy-Decorator-Operation
Cross-Origin-Resource-Policy
TCN
DC
X-Ratelimit-Remaining
X-Content-Options
Count-Hit
X-Varnish-Backend
X-TTL
X-COUNTRY
X-Debug-Info
X-Newrelic-App-Data
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-TEC-API-ROOT
X-Logged-In
X-Origin-Cache
X-Varnish-Grace
X-XRDS-Location
X-Contextid
X-App-Server
X-Request-Guid
Surrogate-Key
X-Revision
X-Route-Name
X-Hosted-By
X-Amz-Replication-Status
X-Providence-Cookie
X-Git-Hash
X-Fb-Rlafr
X-Grace
X-App-Environment
X-Is-Crawler
X-IPS-LoggedIn
X-Flags
X-Aspnet-Duration-Ms
X-Azure-Ref
Frame-Options
X-TT
X-Client-Ip
X-Amz-Meta-S3cmd-Attrs
X-Ratelimit-Limit
X-Origin-Server
X-Edge-Location-Klb
X-Forwarded-Proto
X-Kinsta-Cache
X-RateLimit-Reset
X-Wix-Request-Id
Retry-After
Alternate-Protocol
X-Whom
WPO-Cache-Status
WPO-Cache-Message
X-F-Cache
Healthy
Charset
X-Akamai-Edgescape
X-Magnolia-Registration
Section-Io-Cache
X-Backend-Name
Viewport
MS-Author-Via
Paypal-Debug-Id
X-Proxy-Cache-Info
X-App-Version
X-Id
X-B
ServerID
X-Webkit-CSP-Report-Only
SRV
X-AppVersion
X-Activity-Id
X-Az
Amp-Access-Control-Allow-Source-Origin
X-Language
X-ARC
X-Http-Reason
X-Response-Served-From
Host
X-Rule
X-N
X-Cache-Rule
X-Original-Request-Id
SD-X-WS
VIX-Pulpo-Upstream-Status
X-Instance
Akamai-GRN
VIX-Pulpo-Node
Front
Protected
X-Cache-Grace
X-UUID
X-Status
X-Rocket-Nginx-Serving-Static
X-Akamai-Request-ID2
X-Varnish-Age
X-User-Agent
X-DataDome
X-Www-Served-By
X-Edge-Location
Filterid
X-Varnish-Server
X-Page-View
X-Region
Country
X-L-Path
X-Unique-Id
X-Load-Cache
X-Rendered-As
Fastly-SWR
X-FW-Dynamic
X-FW-Hash
X-Framework
X-Environment-Context
X-Cacheable-TTL
X-FW-Serve
X-FW-Server
From-Origin
X-Is-Bot
X-FW-Version
X-FW-Type
X-FW-Static
X-Jobs
Fastly-SIE
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Adobe-Content
X-Datadog-Trace-Id
X-Cache-Time
X-Adobe-Loc
X-Datadog-Sampling-Priority
X-EdgeConnect-Cache-Status
X-Type
X-Datadog-Parent-Id
Access-Control-Request-Headers
Server-Name
X-G
X-Cache-Control
X-ProcessESI
X-Tumblr-Pixel-1
X-Trace-Id
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-RemovedCookies
X-Tumblr-User
X-Proxy
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Vcache
Refresh
X-ECache
X-Mg-Request-UUID
X-Datadog-Sampled
X-Amzn-Remapped-Content-Length
X-CDN-Forward
X-Time
X-Debug-IsPreview
X-Debug-IsConnected
X-Cache-Age
X-Oracle-Dms-Ecid
X-Source
X-B-Cache
X-Signature
X-Oracle-Dms-Rid
Content-Disposition
X-Drupal-Cache-Tags
X-Erf-Web-Scheduler
X-WP-CF-Super-Cache-Cache-Control
Accept-Language
Backend
X-WP-CF-Super-Cache
Xet-Cookie
Version
X-Generated-By
Countrycode
X-HTML-Minification-Powered-By
X-DynaTrace
Webserver
X-Xrds-Location
CF-IPCountry
X-DynaTrace-JS-Agent
X-Servername
X-Tec-Api-Version
X-Tec-Api-Root
X-Tec-Api-Origin
X-Httpd
Url
X-Mode
X-Tt-Trace-Tag
X-Tt-Trace-Host
Xserver
X-Upgrade-Enabled
GEO-INFO
X-ID
X-Template
X-Content-Age
X-Device-Type
X-NYM-Debug-Backend
X-Nginx-Cache
X-Storage
X-GeoCode
X-Cache-Operation
X-Director
X-GeoCountry
X-Tb
X-ServerID
S-Rt
Azure-Version
Onion-Location
Azure-SlotName
X-Varnish-Cache-Hits
X-UPSTREAM-Address
X-LAGOON
Meta-Geo
Locale
X-Urbn-Context-Path
Filters
X-XRDS-LOCATION
X-Proto
Fastcgi-Useragent
X-Urbn-Site-Id
X-URL
Azure-SiteName
X-Rewrite-Enabled
X-SayCDN-TTL
X-Say-TTL
X-Say-Cacheable
X-Cache-Action
X-Content-Powered-By
X-SaId
Load-Balancing
Azure-InstanceId
Azure-RegionName
X-JoinUs
X-Cluster-Node
X-Container-Uri
X-Soup
X-PHP-Host
X-RM-Cache-TTL
X-Varnish-Hostname
X-VC-Cache
X-MCACHE
Uber-Trace-Id
X-Git-Commit
X-Labrador-Cache-Channel
OT-Force-Account-Verify
X-Forwarded-Host
Web-Mar-Node
X-Adobe-Source
X-Sql-Duration-Ms
X-Tt-Logid
X-LSADC-Cache
X-VCT
X-Sql-Count
X-Cache-Server
X-Generation-Time
X-Served-From
X-Logging-Id
X-Ms-Request-Id
X-Detected-As
X-Ms-Version
X-Proxied
X-RCS-CacheZone
X-Zen-Fury
X-Zipkin-Id
X-Origin-Hint
X-R9-Blue-Green-Version
X-Lambda-Id
Mn-Server-Ip
Node
X-Sucuri-ID
TWC-Device-Class
X-Extlb
X-FB-TRIP-ID
Webcakes-App-Name
Webcakes-App-Version
X-Debug
Webcakes-Region
X-Skip-Cache
TWC-Privacy
TWC-Connection-Speed
X-Routing-Service
X-Sucuri-Cache
TWC-GeoIP-LatLong
TWC-Locale-Group
Property-Id
TWC-GeoIP-Country
DB-Nickname
X-Format
X-Fetched-On
Selected-Fe
X-Uri
X-Tumblr-Pixel-2
X-Timing-Wait
X-Proxy-Build
X-Tumblr-Pixel-3
X-Tncms
X-Loop
X-Drupal-Cache-Contexts
CDN-RequestId
X-B3-SpanId
X-Rn-Rsrv
Liferay-Portal
X-Hcs-Proxy-Type
X-CCDN-Origin-Time
X-Endurance-Cache-Level
X-CCDN-CacheTTL
Source
X-Cache-Hit
X-Nf-Request-Id
X-Fastly-Request-Id
X-Varnish-Ttl
X-Ua
X-Redis-Cache
Cross-Origin-Window-Policy
X-MP-GENERATED-AT
X-Origin-Date
Fastly-Drupal-HTML
X-Srv
X-TimeS
X-CACHE-AGE
X-Varnish-Hits
Section-Io-Origin-Status
Section-Io-Id
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
X-Pass-Why
X-Cache-Expired-At
Upgrade-Insecure-Requests
X-S
X-Real-IP
Content-Secure-Policy
X-Origin-CC
X-UA-Device-Type
X-Cache-TTL-Remaining
X-Origin-TTL
X-Akamai-Transformed
X-Newrelic-Synthetics
X-Node-Name
X-Pubstack
X-Ratelimit-Reset
X-TIME
CDN-RequestPullSuccess
CDN-EdgeStorageId
CDN-PullZone
CDN-RequestCountryCode
CDN-Cache
CDN-RequestPullCode
CDN-Uid
CDN-CachedAt
X-GEO
X-Server-W
X-Hl-Ver
X-Via-JSL
X-Handled-By
X-Presslabs-Stats
X-RTag
Ms-Operation-Id
X-NGENIX-Cache
MS-CV
NGB
Cache-Provider
WP-Super-Cache
Apigw-Requestid
X-Restarts
X-Reqid
X-Cache-Type
X-Cms-Context
X-Optimistic-Header
X-Xfnlog-Site
X-IPLB-Instance
X-IPLB-Request-ID
X-JWT-State
True-Client-Country-4JS
Lang
X-RateLimit-Limit-Second
X-Policy
Mail-Subject
ServedBy
DCR-Processing-Time-Ms
X-Debug-Cache-Fetch
X-RateLimit-Remaining-Second
Magicmarker
X-Debug-Cache-Store
L
Ha-Gx-Prefs
X-Request-Host
VNS-Age
X-Rojux
HA-Ipaddr
X-S-Cookie
Vix-Hermes-Req-Id
DCR-Decision-By
Fastly-GeoIP-CountryCode
Fastly-Backend-Name
Fastly-SSL
Gannett-Cam-Experience-Id
Gh-Request-Id
L5d-Success-Class
T-Server
X-CGP
X-D
X-Nyt-Route
X-Csrf-Jwt
Odigeo-Trace-Id
X-CF-Lambda-Version
BehaviorPad-Version
Origin-Agent-Cluster
Rendered-Blocks
VNS-Cache
Redirect-Candidate
X-Conf
Server-Host
X-GeoIP-Country-Code
Sslversion
Canary
N-Cache
X-Cache-Info
Meta-Geo-Continent
CPC-Age
MD5-Digest
CPC-Cache
X-Origin-Time
X-Is-Gdpr
Ngx.Var.Host
Candidate-Md5Url
X-CF-Lambda-Fn
X-Orig-Expires
X-Mvc-Supplant-Cachable
Surrogated-Key
X-Date
X-Cdn-Diag
X-Bl-Debug
X-We-Are-Hiring
X-Aed
X-Vtex-Remote-Cache
X-Epic-Correlation-Id
X-BCube-Filmed-By
X-CacheTTL
X-FC-Vary-Parameters
X-Gdpr
X-A-Wwc
X-Accel-Expires-Debug
X-Tenant
X-Cache-Bucket
X-Viewer-Country
X-App
X-B-Cookie
X-Vdms-Path
X-Eu-Site
X-Fastly-Backend
X-External-Request-Id
X-Application
X-Vdms-Version
X-VG-WebCache
X-Bc-Bl
X-Destination
X-AIR-PT
X-Var-Ttl
X-SRCache-Key
X-A-Dgt
X-Shop-Environment
X-Forwarded-Path
X-Cache-Host
Xc-Version
X-GeoIP-Region-Code
X-Worker
Web-Mar-Region
X-Dispatcher-Number
X-SD-PageType
X-ScT
X-Developer
W
We-Hiring
X-Has-Esi
X-A
X-Parent-Response-Time
X-Ec-Fail
X-Ec-GeoHdr
X-Slack-Shared-Secret-Outcome
X-A-Dam
X-A-Ccd
X-Wikidot-Static-Cache
X-Slack-Backend
X-Ec-Custom-Error
X-Cache-NE
X-A-Dcw
X-Wikidot-Backend
Cache-Name
X-CSRF-Token
X-ProxyCache-Status
X-Vcl-Version
X-Tx-Id
X-No-Session
Hostname
X-BYPASS-REASON
X-ProxyCache-Key
X-INCAP-ABP
X-Cache-Debug
X-Accel-Buffering
X-Clara-WADP
Machine
TDXMobile
Thinkindot-CacheControl
X-Cdn-Origin
X-Cache-Id
X-Human
X-Core-Value
Thinkindot-Control
Thinkindot-CacheControl-Type
Is-Eu
X-Hash
X-Alternate-Cache-Key
Producers
X-Irp-Debug
X-App-Name
Platform
Origin
X-Auto-Login
X-Clientip
X-BBC-Edge-Cache-Status
Release
X-CMSURLCustom
Req-Svc-Chain
Memcached
X-Core-Mission
X-ApacheServer
X-Bip
X-Gzip
X-Owner
X-ShopId
X-DPWN-IS-SECURE
X-ShardId
X-Shopify-Stage
X-Sn-Servicetimems
X-Storefront-Renderer-Rendered
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Server-IP
X-S-Maxage
X-DefElseHash
X-Platform
X-PERF
Host-ID
X-Qloud-Router
X-Request-Time
X-Refresh
X-DefHash
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-Generated-On
X-VG-TLSProxy
X-Varnishpool
X-Vmg-Version
X-VServer
X-Fmm-Version
X-Wix-Viewer-Type
X-WADP-Cache
X-Varnish-Remaining-TTL
X-Varnish-CookieINHashed-On
X-Geo-Header
X-Thanos
X-Test
X-Thinkindot-L3
X-Esi-Check
X-Varnish-CookieHashed-On
X-Variation
X-Up
X-PAYTM-SRV-ID
X-Pool
AKAMAI
X-Mly-Id
Datacenter
Adler-Geo
X-Mid
X-Nitro-Cache
Environment
Expect-Staple
Cmstype
X-Level-Front-Cache
X-Org
Cf-Device-Type
X-Old-Content-Length
X-Loc
X-Node-Id
X-NodeID
Cmsid
User-Cache-Control
X-VWS-Id
X-LJ-Flow-ID
X-AWS-Id
X-Cluster
Cache-Hits
X-Gen-Mode
X-From
Country-Code
CloudFront-Viewer-Country
DSUID
CDCHOST
X-WA-Info
X-Block-Status
Esi-Enabled
Apple-News-Services-Parsed-Url
X-Hnp-Log
Server-Ext
X-Device-Os
X-Dispatcher-Server
Server-Hostname
X-Cdn-Srv
X-Origin-Response-Time
X-GeoIP
Sever-Int
X-Forwarded-Site
X-Nginx-Cache-Key
X-Mvc-Supplant-OutputCached
X-Datadome
X-Akamai-Device-Characteristics
X-Nananana
Apple-News-Services-Request-Url
Apple-News-Services-Handled
Apple-News-Services-Host
X-Origin
NM-Fastcgi-Cache
X-Proxy-Cache-Status
X-PHP-Backend
Memory
Origin-CC
Origin-EX
X-Section
X-LB-NoCache
X-NCache
X-Cache-Status-Check
X-Op-Id-All
C-Via
X-Scale
Pics-Label
Wxu-Next-Hostname
Wxu-Next-Region
X-Access
Wxu-Next-Commit
Time
Server-Info
X-Cache-Enabled
X-Instance-Name
Ssr
X-API-Version
AMP-Access-Control-Allow-Source-Origin
X-Via-Fastly
X-TIM-N
X-CACHE-GROUP
X-Amz-Meta-Cb-Modifiedtime
X-Micro-Cache
NGX
Server-ID
X-B3-Spanid
X-Correlation-ID
X-Dc
X-FTR-Request-ID
X-HA-Backend
X-Wp-Cf-Super-Cache-Active
X-ZONE
X-AB
X-Internal-Host
X-Vgn-Hpd-Reason
X-Air-Trace-Id
X-Air-Source
X-Air-Hostname
X-Tb-Optimization-Total-Bytes-Saved
X-Platform-Router
X-Platform-Cluster
X-Platform-Processor
X-Azure-Ref-OriginShield
X-Cs
X-Webkit-Csp-Report-Only
X-Geo-Region
X-Varnish-Beresp-Ttl
X-Varnish-Beresp-Grace
Location
X-Buckets
GeoIP-Latitude
IsBot
X-SIPLIST1
X-Accel-Version
Cdn-Requestid
X-Web-Node
X-DC
X-Fpc
X-Microcachable
X-Github-Request-Id
Cache-Host
X-B3-Parentspanid
X-Backend-Instance
X-DataCenter
X-Origin-Expires
X-TraceId
X-WP-CF-Super-Cache-Active
X-Zone
XM
X-NGINX-Cache
X-Is-Mobile
X-Is-Supported-Browser
X-Is-Desktop
X-Browser-Name
X-Tcp-Rtt
X-Is-Tablet
X-Pod-Name
PFcat
Uri
X-Info
Resin-Trace
X-VarnishDD-TTL
X-HN
YJS-ID
CF-Ctrl
X-TA-CDN-Provider
X-LiteSpeed-Cache-Control
Sid
X-Ad-Defer-Variation
X-Cached-By
User-Agent
X-HOST
X-Via-Edge
X-Nitro-Rev
GeoIp-Country-Code
X-Nitro-Cache-From
X-Via-CDN
X-NewRelic-App-Data
X-Site-Version
X-Via-SSL
Locid
Edge-Copy-Time
Srvid
X-FL-EDGE
X-FL-QIT-DEBUG
A
X-Locale
Epwk-X-Cache
X-CS
X-CSRF-TOKEN
True-Client-Ip
X-Hyper-Cache
X-VCache
SID
X-Frame-Option
X-FireWall-Port
X-Moov-Xdn-Version
True-Client-IP
X-Contensis-Viewer-Groups
X-Moov-T
X-Cache-ASPX
X-ATG-Version
Cdn
GeoIP-Country-Code
XServer
X-MSEdge-Flight
Cache-Key
X-MSEdge-Features
X-Webstats-RespID
X-Varnish-Authentication
X-Service
X-Geo
X-SRV
X-TRACE-ID
X-VC
X-Origin-Cache-Key
X-Upstream-Ht
NtCoent-Length
Path
Fastly-Drupal-Html
X-Upstream-Ct
X-Datacenter
X-FPC
X-HostName
Tcn
LB
X-Edge-Server
X-FTR-Backend-Server
X-FTR-Balancer
X-FTR-Cache-Status
X-HS-Content-Campaign-Id
X-FTR-Backend
X-Platform-Server
X-Planisys-CDN-Rules
State
X-Planisys-CDN-TTL
X-Country-Code-Real
X-FTR-Expires
X-Planisys-CDN-Cache
X-Vercel-Cache
X-Vercel-Id
X-LiteSpeed-Tag
Cdn-Request-Time
Cdn-Host
X-Api-Version
Cf-Ipcountry
CountryCode
X-APP-VERSION
Req-ID
X-Pad
WZWS-RAY
X-Fastly-Cache
X-AK-Request-ID
Cdnsip
Cdncip
X-Amz-Meta-Opti
M-TraceId
X-Vgn-Hpd-Cached
X-Vgn-Hpd-Variations-Key
X-Vgn-Hpd-Ssi
X-Esi
X-Release
X-NMSegId
X-Air-Pt
X-Cdn-Request-ID
X-Cache-Ttl
X-Branch-Name
X-WP-CF-Super-Cache-Cookies-Bypass
X-Generated-In
X-Sigma
X-Sigma-Backend
X-Traceid
WebServer
X-Rocket-Build-Number
Lb
Cluster
X-Wp-Cf-Super-Cache-Cache-Control
X-Wp-Cf-Super-Cache
X-Ad-Load-Variation
X-Cache-Remote
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
Yak-Timeinfo
Content-Script-Type
Content-Style-Type
X-NWS-UUID-VERIFY
X-M-Log
X-M-Reqid
X-Proxy-CacheRZ
X-Request-Start
Pramga
Proxy-Connection
X-HS-Status
Cache
X-Scope-Id
XkeyRZ
X-UA
X-CACHE-KEY
X-Provided-By
CDN
Geoip-Latitude
X-Varnish-Beresp-Status
X-Akamai-Pragma-Client-IP
X-Qnm-Cache
X-Shield-Cache-Expires
X-Tim-N
X-GeoIP-City
X-GoCache-CacheStatus
X-Cdn-Forward
Srv
X-Scheme
X-Gamma-Serve
X-Lb-Cache
X-RN-RSRV
X-Vc
Ohc-File-Size
CF-Cached-On
X-Ha-Backend
X-Request-URI
X-Cache-Date
Edge-Cache
Server-Id
X-Cdn-Cache-Status
X-TT-LOGID
X-Acquia-Purge-Tags
X-Via-Ucdn
X-EC-Lua
Env
X-Acquia-Site
X-CUA
X-User
X-TH-Server
X-Render-Time
Ngx
X-Acquia-Application-UUID
X-Lb-Nocache
X-Acquia-Application-Trace
X-Dw-Trace-Id
X-Edge-POP
Inserted-Into-Cache-At
PICS-Label
Yjs-Id
X-Acquia-Purge-Cdn-Unconfigured
X-Wa
X-Via-Poph
X-SB
X-Servedbyhost
V-Age
Tube-Got-Eval
Tube-Got-Results
Tube-Return
X-Aicache-OS
X-B3-Trace-ID
X-Fastly-Backend-Reqs
X-Lb-Id
X-Nc
X-Via-Popn
X-Via-Popv
X-Req
X-Cache-FS-Status
X-V-Cache
Tube-Get-Contents
X-CF-Cache-Header-Vary
Log-Origin
Kp-EeAlive
X-VCL-Version
X-Litespeed-Cache-Control
Cneonction
CACHE-MISS-TO-ORIGIN
X-Miniprofiler-Ids
X-Fastly-Cache-Hits
X-Snapshot-Date
Vha6-Origin
Cache-Tv-Group
Click-Count-Action-Start
Click-Count-Error
X-Udemy-Cache-App-Namespace
X-RAMCache
X-Cached-Since
X-ElasticPress-Query
X-CF-Cache-Header-Cache-Control
MIME-Version