Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Accept-Ranges
X-XSS-Protection
Expect-CT
Pragma
X-Powered-By
X-Cache
CF-RAY
Via
Age
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
CF-Ray
X-Xss-Protection
X-Download-Options
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Request-Id
X-Adblock-Key
Access-Control-Allow-Credentials
X-FRAME-OPTIONS
X-Permitted-Cross-Domain-Policies
X-AspNet-Version
Alt-Svc
X-Request-ID
X-Runtime
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Generator
X-Cache-Status
X-Cacheable
Timing-Allow-Origin
X-Envoy-Upstream-Service-Time
X-Iinfo
X-Content-Security-Policy
X-Drupal-Dynamic-Cache
Feature-Policy
Content-Encoding
Access-Control-Expose-Headers
Upgrade
Status
X-CDN
X-AspNetMvc-Version
Access-Control-Max-Age
X-Via
X-UA-Device
Server-Timing
Request-Context
X-Robots-Tag
X-Turbo-Charged-By
X-Amz-Request-Id
X-Cache-Group
X-Amz-Id-2
EagleId
X-Backend
X-AH-Environment
P3p
X-Proxy-Cache
X-Dns-Prefetch-Control
Keep-Alive
X-Server
X-Ws-Request-Id
X-Age
Cf-Edge-Cache
Host-Header
X-Hacker
X-Vhost
X-Server-Powered-By
X-Rq
X-Varnish-Cache
X-Dispatcher
X-Amz-Version-Id
Grace
Allow
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-OneAgent-JS-Injection
X-LiteSpeed-Cache
X-WebKit-CSP
X-Ua-Compatible
X-Page-Speed
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
Cf-Apo-Via
Cf-Railgun
Accept-CH
X-Aws-Lambda-Call-Status
X-Node
X-Pingback
X-Host
X-Ruxit-JS-Agent
EagleEye-TraceId
X-Server-Id
X-Nginx-Cache-Status
Surrogate-Control
X-Akam-SW-Version
X-Readtime
Request-Id
X-Backend-Server
X-Cache-Spec
X-Content-Security-Policy-Report-Only
X-Cache-Lookup
X-HW
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Accept-Ch-Lifetime
X-Cloud-Trace-Context
X-Application-Context
X-Trace
X-Response-Time
Permissions-Policy
X-Nginx-Upstream-Cache-Status
Fastly-Restarts
X-Edge
X-Mod-Pagespeed
X-WebKit-CSP-Report-Only
Accept-CH-Lifetime
X-Country
X-Litespeed-Cache
Content-Location
X-Mcache
X-Content-Type
X-MS-InvokeApp
X-Url
X-Clacks-Overhead
X-Vname
X-PC
X-TtlSet
X-CST
X-Amz-Server-Side-Encryption
X-Midtier
Rating
RTSS
Cache-Tag
X-ESI
X-Vcap-Request-Id
X-D2id
X-Element-Page-Cache
X-Rack-Cache
X-Kinja-Build
Origin-Trial
X-Kinja-Server
X-Kinja
X-Cdn-Fetch
X-Exp-Variant
X-GoogleNews-Bot
X-Use-Magma
X-Exp-Id
X-Kinja-Revision
Verso
X-VARITI-CCR
X-Server-Name
X-Ac
X-Powered-By-Plesk
Service-Worker-Allowed
X-Ttl
X-Cnection
X-ECACHE
X-Amz-Rid
SPRequestGuid
X-SharePointHealthScore
X-Navigation-Version
X-GitHub-Request-Id
X-Client-IP
Xkey
X-Abt-Application-Version
Edge-Control
SPRequestDuration
SPIisLatency
X-Upstream
X-Cache-TTL
Arr-Disable-Session-Affinity
X-B3-TraceId
X-Cached
X-Mg-S
X-Dw-Request-Base-Id
X-Erf-Bev-Bev
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Instrumentation
X-NWS-LOG-UUID
X-Browser-Type
X-Erf-Bev-Bev-Is-Generated
X-Px
X-FastCGI-Cache
X-Sol
Display
X-Middleton-Display
Pagespeed
X-Varnish-TTL
X-Cache-Key
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-NF-Request-ID
Access-Control-Request-Method
X-Forwarded-For
Edge-Cache-Tag
X-Country-Code
X-Correlation-Id
X-Goog-Hash
X-Powered-CMS
TCN
Content-MD5
Front-End-Https
X-Ser
AR-CACHE
AR-Request-ID
AR-PoweredBy
AR-ATIME
AR-SID
Public-Key-Pins
X-RateLimit-Remaining
X-Id
X-Version
X-HP-Webp
X-Jurisdiction
Accept-Ch
X-HP-Trace-Id
X-MSEdge-Ref
X-Content-Digest
X-Recruiting
X-Amzn-Trace-Id
X-T
X-Ratelimit-Limit
Response
X-Middleton-Response
X-Accel-Expires
TP-L2-Cache
TP-Cache
MicrosoftSharePointTeamServices
X-Shield-Request-Id
X-XRDS-Location
S
Nginx-Cache
Cache-Status
X-Webkit-Csp
X-Daa-Tunnel
X-Request-Processing-Time
X-Request-Received
Server-Node
X-HS-Combine-CSS
X-HS-Cache-Config
X-HS-Hub-Id
X-HS-Content-Id
Mrf-Cache-Status
X-B3-TraceId-Primal
MRF-Tech
Cache-Tags
Cross-Origin-Opener-Policy
X-Fastcgi-Cache
X-Distributor
X-Hits
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-TEC-API-ROOT
X-LB-Cache
X-Edge-Location-Klb
X-Kinsta-Cache
X-Origin-Server
X-Ratelimit-Remaining
X-Ua-Browser
X-Ezoic-Cdn
X-Fastly-Request-ID
Alternate-Protocol
Fastcgi-Cache
X-PressLabs-Stats
Filterid
X-Grace
X-Ratelimit-Reset
X-Hostname
X-Frontend
X-LLID
Server-Name
X-Geo-Country
X-ORACLE-DMS-ECID
X-Request-Handler-Origin-Region
X-Microsite
X-ORACLE-DMS-RID
X-Rid
X-DIS-Request-ID
X-FB-Debug
Healthy
X-Logged-In
X-Varnish-Backend
X-Git-Hash
X-NGENIX-Cache
X-Debug-Info
Payment
Cleartype
X-Www-Served-By
Realpath
X-Load-Cache
X-Cluster-Name
X-Page-Id
X-Protected-By
DC
X-Forwarded-Proto
X-ASPNET-VERSION
MS-Author-Via
X-ECache
X-DataDome
Content-Disposition
Access-Control-Allow-Method
X-Origin-Cache
Charset
X-B3-Sampled
X-Goog-Metageneration
X-GUploader-UploadID
X-Upgrade-Enabled
X-Kong-Upstream-Latency
X-Server-ID
X-Kong-Proxy-Latency
X-Az
X-AppVersion
X-Activity-Id
X-Proxy
X-Seen-By
X-F-Cache
Count-Hit
X-Cache-Age
X-B3-Traceid
X-Amz-Meta-S3cmd-Attrs
X-Amz-Replication-Status
X-Fb-Rlafr
Cross-Origin-Resource-Policy
X-Azure-Ref
Paypal-Debug-Id
X-TTL
X-Whom
X-Times
X-Type
X-Revision
X-B
X-Akamai-Edgescape
Surrogate-Key
X-Contextid
X-Providence-Cookie
X-Request-Guid
X-Route-Name
X-App-Environment
X-Aspnet-Duration-Ms
X-Is-Crawler
X-Aspnetmvc-Version
Accept-Charset
Viewport
Retry-After
X-Flags
X-Wix-Request-Id
X-Varnish-Server
X-TT
X-Hosted-By
X-B-Cache
X-Signature
X-Language
X-DynaTrace
Amp-Access-Control-Allow-Source-Origin
X-Cache-Control
X-Source
X-Oracle-Dms-Rid
X-Oracle-Dms-Ecid
X-Envoy-Decorator-Operation
X-Varnish-Ttl
X-App-Server
X-Magnolia-Registration
X-Mobile
X-Varnish-Grace
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Goog-Storage-Class
X-VCache
Host
WPO-Cache-Message
WPO-Cache-Status
Version
X-Fastly-Request-Id
Referer-Policy
X-Cache-Rule
X-N
Refresh
X-HTML-Minification-Powered-By
X-Tumblr-User
X-Varnish-Age
X-Tumblr-Pixel-0
X-Tumblr-Pixel
Access-Control-Request-Headers
X-Cache-Time
X-Original-Request-Id
X-Tumblr-Pixel-1
X-Response-Served-From
X-Amz-Apigw-Id
X-Cache-Status-Check
X-EdgeConnect-Cache-Status
X-Rule
X-Amzn-RequestId
X-Cacheable-TTL
X-Framework
X-Content-Powered-By
X-Cache-Grace
X-Jobs
X-RTag
Ms-Operation-Id
MS-CV
X-User-Agent
X-UUID
Protected
SD-X-WS
CDN-RequestId
X-G
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
Section-Io-Cache
X-Backend-Name
GEO-INFO
X-FW-Dynamic
X-FW-Type
X-FW-Static
X-FW-Serve
X-FW-Version
X-RemovedCookies
X-L-Path
X-ProcessESI
From-Origin
X-FW-Server
X-Device-Type
X-Environment-Context
X-FW-Hash
X-Instance
X-Tt-Trace-Tag
X-Page-View
Akamai-GRN
X-Trace-Id
NGB
X-Status
X-Tt-Trace-Host
X-Rendered-As
X-Adobe-Loc
X-Akamai-Request-ID2
X-Drupal-Cache-Tags
X-Drupal-Cache-Contexts
X-Region
X-Adobe-Content
X-Is-Bot
X-Http-Reason
X-NYM-Debug-Backend
X-Cache-Expired-At
X-Nginx-Cache
X-XRDS-LOCATION
X-RateLimit-Limit
Front
Url
X-Servername
X-Unique-Id
SRV
Accept-Language
X-Template
X-Pinterest-Rid
Pinterest-Version
Pinterest-Generated-By
Liferay-Portal
X-CDN-Forward
X-Content-Options
X-Debug-IsPreview
X-Debug-IsConnected
Fastly-SWR
Backend
Fastly-SIE
X-Air-Hostname
X-Air-Source
X-Cache-Hit
X-Air-Trace-Id
X-Time
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Newrelic-App-Data
X-Zen-Fury
Country
X-DynaTrace-JS-Agent
X-Mode
X-COUNTRY
Content-Secure-Policy
X-Rocket-Nginx-Serving-Static
X-Cache-Operation
X-Uri
Node
S-Rt
X-Proxy-Cache-Info
Filters
Meta-Geo
X-IPS-LoggedIn
X-Generation-Time
X-Rewrite-Enabled
Webserver
X-RN-RSRV
Onion-Location
X-UPSTREAM-Address
X-Content-Age
X-Amzn-Remapped-Content-Length
Uber-Trace-Id
X-Cache-Server
X-Tumblr-Pixel-2
X-Web-Node
Selected-Fe
X-Tb
X-Tumblr-Pixel-3
X-Proxy-Build
X-PHP-Backend
X-Edge-Location
Azure-SiteName
X-Timing-Wait
CF-IPCountry
Azure-RegionName
X-Locale
Azure-Version
Azure-SlotName
Cache-Hits
Azure-InstanceId
X-Cache-Action
X-Cms-Context
X-Sucuri-Cache
X-ARC
X-BYPASS-REASON
X-Access
X-Cluster-Node
X-Say-Cacheable
X-Soup
X-Skip-Cache
X-Site-Version
X-Format
Cache-Name
X-Sucuri-ID
X-PHP-Host
X-Proto
X-Origin-Date
X-ProxyCache-Status
X-Section
X-Server-W
X-SayCDN-TTL
X-Labrador-Cache-Channel
X-ProxyCache-Key
X-Via-Fastly
X-Real-IP
X-Varnish-Beresp-Grace
X-Ms-Request-Id
X-Say-TTL
X-Ms-Version
Property-Id
TWC-Connection-Speed
Cross-Origin-Window-Policy
ServerID
DB-Nickname
TWC-Device-Class
ServedBy
X-R9-Blue-Green-Version
X-Zipkin-Id
X-Reqid
X-Routing-Service
X-Proxy-Cache-Status
X-VC-Cache
X-UA-Device-Type
X-Proxied
X-Sql-Duration-Ms
X-Sql-Count
X-Origin-Hint
X-Handled-By
Webcakes-App-Version
TWC-Privacy
TWC-Locale-Group
TWC-GeoIP-LatLong
Webcakes-Region
X-Cache-Host
X-Forwarded-Host
X-Extlb
X-Debug
TWC-GeoIP-Country
Webcakes-App-Name
Countrycode
WP-Super-Cache
Web-Mar-Node
X-LJ-Flow-ID
Cache-Tv-Group
X-IPLB-Instance
X-AWS-Id
X-Optimistic-Header
X-Adobe-Source
X-VWS-Id
Apigw-Requestid
X-Ruxit-Js-Agent
X-LAGOON
X-IPLB-Request-ID
X-FB-TRIP-ID
X-JoinUs
X-SaId
X-Detected-As
X-Cluster
X-Ua
X-Urbn-Context-Path
X-Urbn-Site-Id
X-App-Version
Locale
X-Cache-TTL-Remaining
Mn-Server-Ip
X-No-Session
X-Node-Name
X-GeoCountry
X-LSADC-Cache
X-GeoCode
Fastcgi-Useragent
X-Tt-Logid
X-WP-CF-Super-Cache-Cache-Control
X-Xfnlog-Site
X-WP-CF-Super-Cache
X-Director
Mime-Version
X-Oneagent-Js-Injection
Upgrade-Insecure-Requests
Source
X-Varnish-Hits
X-GEO
Frame-Options
X-Buckets
CDN-EdgeStorageId
CDN-CachedAt
CDN-Uid
CDN-RequestCountryCode
X-Hl-Ver
X-Generated-By
CDN-Cache
CDN-PullZone
Fastly-Drupal-HTML
X-Tec-Api-Origin
X-TIME
X-Tec-Api-Version
X-Tec-Api-Root
X-Mg-Request-UUID
X-Request-Time
X-Varnish-Cache-Hits
X-FireWall-Port
X-Webkit-CSP-Report-Only
X-Api-Version
X-Redis-Cache
Load-Balancing
Xet-Cookie
X-TA-CDN-Provider
X-Origin-CC
X-ServerID
X-RM-Cache-TTL
X-Varnish-Hostname
X-Origin-TTL
X-URL
X-Loop
X-Datadog-Sampling-Priority
X-Datadog-Trace-Id
CF-Cached-On
X-Datadog-Sampled
X-SRV
X-Datadog-Parent-Id
X-Cache-Debug
X-Tx-Id
X-Akamai-Transformed
X-Storefront-Renderer-Rendered
X-Sorting-Hat-PodId
X-Alternate-Cache-Key
X-ShardId
X-ShopId
X-Shopify-Stage
X-Sorting-Hat-ShopId
X-Pubstack
X-Served-From
X-Newrelic-Synthetics
X-Endurance-Cache-Level
X-Pass-Why
X-Storage
X-Request-Host
X-CSRF-Token
Server-Info
X-Service
X-Restarts
X-Location
Xserver
X-TNCMS
Meta-Geo-Continent
X-Ec-Fail
X-Conf
T-Server
X-CMSURLCustom
X-Cache-NE
X-Cdn-Origin
X-Ec-GeoHdr
X-Core-Mission
X-CUA
X-Destination
Lang
X-Developer
X-External-Request-Id
X-Epic-Correlation-Id
DCR-Processing-Time-Ms
MD5-Digest
X-D
Memcached
X-Cache-Info
Cache-Host
X-A-Wwc
X-A-Dgt
BehaviorPad-Version
Edge-Cache
X-Akamai-Device-Characteristics
X-Aed
Sslversion
DSUID
X-A-Dcw
X-A-Ccd
X-A
WWW-Authenticate
Surrogated-Key
Candidate-Md5Url
X-A-Dam
Thinkindot-CacheControl-Type
X-Gdpr
X-Application
X-B-Cookie
Redirect-Candidate
Gannett-Cam-Experience-Id
DCR-Decision-By
Thinkindot-Control
Origin
Host-ID
NM-Fastcgi-Cache
Odigeo-Trace-Id
X-Cache-Date
TDXMobile
X-BCube-Filmed-By
X-Bc-Bl
A
Server-Host
X-Bip
Thinkindot-CacheControl
Release
Rendered-Blocks
Ngx.Var.Host
X-Mobile-URL
X-Origin
X-SVT-ORM-RULES
X-SRCache-Key
X-Sn-Servicetimems
X-Origin-Time
X-SVT-ORM-VERSION
X-Nyt-Route
X-Mid
X-TIM-N
X-Thanos
X-Test
X-Platform-Cluster
X-Platform-Processor
X-S-Cookie
X-Sigma-Backend
X-S-Maxage
X-Sigma
X-ScT
X-S
X-Rojux
X-Platform-Router
X-Processor
X-Correlation-ID
X-Rocket-Build-Number
X-Men
X-Thinkindot-L3
X-Hash
X-Vdms-Version
X-Httpd
X-Provided-By
X-We-Are-Hiring
X-Generated-On
Xc-Version
X-INCAP-ABP
X-Vdms-Path
X-Level-Front-Cache
X-Loc
X-WP-CF-Super-Cache-Active
HostName
X-Slack-Backend
X-VServer
We-Hiring
X-Server-IP
X-Worker
X-Variation
Mail-Subject
X-Response-By
X-Varnish-Beresp-Status
Vix-Hermes-Req-Id
Tube-Return
X-Slack-Shared-Secret-Outcome
X-Varnish-CookieHashed-On
Platform
X-Varnish-CookieINHashed-On
X-Varnishpool
Tube-Get-Contents
Tube-Got-Eval
X-Varnish-Remaining-TTL
Tube-Got-Results
Req-Svc-Chain
X-Var-Ttl
X-Vmg-Version
X-Region-Sid
X-Dispatcher-Server
X-Ec-Custom-Error
X-Human
X-Is-Gdpr
X-Dispatcher-Number
X-DefElseHash
X-DefHash
X-JWT-State
X-HS-Content-Campaign-Id
X-Esi-Check
X-Fastly-Backend
X-Fastly-Cache
X-Fetched-On
X-Geo-Header
X-GeoIP
X-Has-Esi
X-Gzip
X-GeoIP-City
X-Date
Magicmarker
X-BBC-Edge-Cache-Status
X-Pool
X-Platform
X-Gamma-Serve
X-Auto-Login
X-Scale
X-Accel-Expires-Debug
X-Req
X-Cache-Bucket
X-Origin-Response-Time
X-NodeID
X-Node-Id
X-Mvc-Supplant-Cachable
X-CacheTTL
X-Org
X-Cache-Id
X-Origin-Expires
X-SD-PageType
X-Ad-Defer-Variation
Cache-Key
Section-Origin-Responded
Country-Code
Section-Io-Origin-Status
Section-Io-Id
Fastly-GeoIP-CountryCode
Fastly-Backend-Name
Cmstype
Cmsid
AKAMAI
C-Via
CacheControlHeader
Click-Count-Action-Start
Click-Count-Error
Adler-Geo
CloudFront-Viewer-Country
X-Varnish-Beresp-Ttl
Section-Io-Origin-Time-Seconds
Is-Eu
Gh-Request-Id
Environment
X-Parent-Response-Time
X-Planisys-CDN-TTL
X-Cache-Tags
X-Azure-Ref-OriginShield
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
X-V-Cache
X-Owner
X-Cache-FS-Status
X-Air-Pt
Apple-News-Services-Request-Url
X-Release
X-Accel-Buffering
X-Request-Start
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
X-Cdn-Srv
Apple-News-Services-Handled
X-App
X-Qloud-Router
X-Clara-WADP
X-WA-Info
X-Mly-Id
X-GeoIP-Country-Code
X-Nginx-Cache-Key
X-GeoIP-Region-Code
Expect-Staple
X-WADP-Cache
X-Irp-Debug
X-Instance-Name
X-VG-TLSProxy
Machine
X-Device-Os
X-Core-Value
X-Wix-Viewer-Type
X-DPWN-IS-SECURE
X-FC-Vary-Parameters
X-Frame-Option
X-Forwarded-Site
X-Fmm-Version
X-Ckpd-Fst-Backend
X-Developers
Web-Mar-Region
Origin-CC
Origin-EX
Producers
Ssr
On-Server
Datacenter
Canary
State
Kp-EeAlive
X-Via-CDN
Srvid
X-Gen-Mode
Cache-Provider
Server-Ext
Locid
Fastly-SSL
X-FL-EDGE
Sever-Int
X-FL-QIT-DEBUG
PFcat
X-VarnishDD-TTL
NGX
X-Platform-Server
L
X-Op-Id-All
X-Old-Content-Length
X-HN
X-Hnp-Log
X-Minions-Version
X-NCache
X-SB
Server-Hostname
Wxu-Next-Hostname
X-Aicache-OS
Wxu-Next-Region
User-Cache-Control
Wxu-Next-Commit
X-Block-Status
X-Via-SSL
X-CACHE-AGE
X-Via-Edge
X-VC
X-Zone
Edge-Copy-Time
X-LB-NoCache
X-Mvc-Supplant-OutputCached
X-Eu-Site
X-Vcl-Version
Ha-Gx-Prefs
X-From
X-Microcachable
X-B3-Spanid
X-Nananana
X-Cache-Remote
HA-Ipaddr
L5d-Success-Class
X-CGP
X-Csrf-Jwt
CDCHOST
X-Cache-Enabled
X-Cache-Backend
X-DC
X-Up
X-Tb-Optimization-Total-Bytes-Saved
Env
X-Debug-Cache-Store
X-Generated-In
X-ND-Cache
Decoy-Debug-Key
GeoIP-Latitude
X-Presslabs-Stats
Pics-Label
X-Debug-Cache-Fetch
Decoy-Debug-Status
Cluster
X-RCS-CacheZone
Decoy-Debug-TTL
X-Refresh
X-Lambda-Id
X-Dc
X-Trace-ID
X-Cached-By
X-Tid
X-NWS-UUID-VERIFY
X-Via-Popv
X-VCT
X-Via-Popn
X-Via-Poph
NtCoent-Length
Cache
X-Cs
SID
Sid
X-Render-Time
Memory
VNS-Cache
CPC-Cache
CPC-Age
Time
VNS-Age
X-Vtex-Remote-Cache
X-HS-Status
X-Webkit-CSP
X-B3-SpanId
X-Upstream-Ht
X-HA-Backend
X-Edge-Pop
X-CCDN-CacheTTL
X-Hcs-Proxy-Type
X-CCDN-Origin-Time
X-DataCenter
X-LB-ID
X-Upstream-Ct
X-Servedbyhost
X-Srv
X-Vgn-Hpd-Cached
X-Wa
X-Nc
X-Esi
X-Vgn-Hpd-Variations-Key
X-TH-Server
X-Cache-Type
Svr
X-AIR-PT
X-Vgn-Hpd-Ssi
Fastly-Drupal-Html
Cdn
AMP-Access-Control-Allow-Source-Origin
Server-ID
X-Client-Ip
X-NewRelic-App-Data
X-CLOUD-TRACE-CONTEXT
X-ATG-Version
X-ZONE
GeoIp-Country-Code
X-Contensis-Viewer-Groups
X-Via-JSL
X-Varnish-Authentication
X-Cache-ASPX
Srv
X-Fpc
Uri
X-Proxy-CacheRZ
X-Vc
XkeyRZ
X-Check-Cacheable
X-RateLimit-Limit-Second
X-CF-Lambda-Fn
X-RateLimit-Remaining-Second
X-CF-Lambda-Version
X-PAYTM-SRV-ID
Esi-Enabled
True-Client-IP
X-MP-GENERATED-AT
X-Amz-Meta-Cb-Modifiedtime
XServer
X-AK-Request-ID
Cdnsip
X-Gateway-Skip-Cache
M-TraceId
X-Nf-Request-Id
X-Gateway-Cache-Status
X-Gateway-Request-Id
Cdncip
X-Varnish-Beresp-TTL
X-Gateway-Cache-Key
X-NGINX-Cache
X-EC-Lua
X-CS
X-Udemy-Cache-App-Namespace
Hostname
Resin-Trace
X-Via-NSCOPI
N-Cache
X-Wikidot-Static-Cache
True-Client-Ip
X-API-Version
X-Wikidot-Backend
YJS-ID
X-CSRF-TOKEN
X-Tenant
RNT-Time
RNT-Machine
X-Shop-Environment
X-CDN-Cache-Status
X-FPC
Lb
X-Bl-Debug
X-MSEdge-Flight
X-Forwarded-Path
OT-Force-Account-Verify
X-MSEdge-Features
X-Orig-Expires
X-Datadome
Eomportal-Instance
X-Fastly-Country-Code
X-TX-ID
Request-ID
X-Policy
X-APP-VERSION
GeoIP-Country-Code
X-B3-Trace-ID
X-App-Name
CDN
X-RateLimit-Reset
Path
Ngx-Var-Key
X-CACHE-KEY
X-Service-Response-Time
X-Cache-Ttl
Server-Id
Sm-Log-Id
X-Micro-Cache
X-VCL-Version
IsBot
X-Accel-Version
LB
X-WA
X-Vcache
X-SIPLIST1
X-Logging-Id
X-Cache-NGX
X-MCACHE
X-NC
X-Lb-Id
X-Request-URI
X-Edge-POP
X-Ha-Backend
Hit
X-Git-Commit
X-Container-Uri
HIT
X-Cdn-Diag
Pramga
X-Info
X-Datacenter
X-Cdn-Cache-Status
X-ServedByHost
Cross-Origin-Opener-Policy-Report-Only
Location
X-Github-Request-Id
X-SERVER-NAME
X-Akamai-Pragma-Client-IP
X-Geo
X-Snapshot-Date
X-Srcache-Store-Status
X-Srcache-Fetch-Status
X-Pod-Name
Ohc-File-Size
X-VG-WebCache
X-Tncms
Timeexpire
FSS-Cache
X-Cdn-Forward
X-ID
X-Via-PopH
X-Via-PopV
Geoip-Latitude
Yjs-Id
X-Acquia-Purge-Cdn-Unconfigured
Epwk-X-Cache
X-Via-PopN
V-Age
True-Client-Country-4JS
ENV
X-Ctl-Mach
Req-ID
XM
X-Wp-Cf-Super-Cache
X-Iauth-Set-Uid
X-Wp-Cf-Super-Cache-Cache-Control
X-Amz-Meta-Opti
X-Hyper-Cache
CDN-RequestPullCode
CDN-RequestPullSuccess
X-Clientip
X-Oss-Request-Id
X-Oss-Storage-Class
X-Fastly-Backend-Reqs
X-Serial
X-Oss-Server-Time
X-Oss-Object-Type
X-TT-LOGID
X-LiteSpeed-Cache-Control
X-Oss-Hash-Crc64ecma
X-Cdn-Request-ID
X-Lb-Nocache
Servername
X-Cache-Expires
Proxy-Connection
X-Dw-Trace-Id
X-Rebelmouse-Surrogate-Control
Warning
X-Rebelmouse-Cache-Control
X-M-Reqid
X-M-Log
X-RAMCache
X-Acquia-Purge-Tags
X-Akamai-ERRuleID
X-Acquia-Application-UUID
X-B3-Parentspanid
X-UP
X-Akamai-ERPolicy
X-Acquia-Site
Content-Style-Type
Ec-Rule-Version
X-Acquia-Application-Trace
WZWS-RAY
Cneonction
Content-Script-Type
X-Swift-Error
X-Qnm-Cache
X-Lsadc-Cache
X-MiniProfiler-Ids
X-F-Status
CountryCode
X-UA
My-App
X-Cached-Since
W
Ngx
X-LiteSpeed-Tag
Ohc-Cache-HIT
X-WP-CF-Super-Cache-Cookies-Bypass
PICS-Label
X-Mg-Cache
X-Moov-Xdn-Version
X-Moov-T
X-Fastly-Cache-Hits
X-Th-Server
X-Scheme
X-Webstats-RespID
X-Cache-Ngx
X-IPS-Cached-Response
X-Litespeed-Cache-Control
X-B3-ParentSpanId
MIME-Version