Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
X-Powered-By
Pragma
CF-RAY
X-Cache
Via
X-XSS-Protection
Age
Content-Security-Policy
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Xss-Protection
X-Amz-Cf-Pop
X-Amz-Cf-Id
Alt-Svc
P3P
X-Cache-Hits
X-UA-Compatible
X-Served-By
CF-Ray
X-Download-Options
X-Timer
X-Request-Id
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
Access-Control-Allow-Credentials
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
X-Drupal-Cache
X-Cache-Status
X-Generator
X-Check
X-Cacheable
X-Envoy-Upstream-Service-Time
X-FRAME-OPTIONS
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Iinfo
X-Dns-Prefetch-Control
X-Request-ID
X-Drupal-Dynamic-Cache
Feature-Policy
Server-Timing
X-Content-Security-Policy
Access-Control-Expose-Headers
Content-Encoding
X-XSS-PROTECTION
Status
X-CDN
Upgrade
X-AspNetMvc-Version
Access-Control-Max-Age
X-Amz-Request-Id
X-Via
X-Amz-Id-2
Request-Context
X-Turbo-Charged-By
X-Backend
X-Cache-Group
X-AH-Environment
X-Robots-Tag
Cf-Edge-Cache
Keep-Alive
Host-Header
X-Hacker
X-Proxy-Cache
X-UA-Device
X-Vhost
X-Server
X-Rq
Allow
X-Server-Powered-By
X-Ws-Request-Id
X-Age
X-Dispatcher
X-Varnish-Cache
EagleId
X-Amz-Version-Id
X-LiteSpeed-Cache
P3p
Nel
Grace
X-Ua-Compatible
Cf-Apo-Via
X-Page-Speed
X-Styx-Req-Id
Cf-Railgun
X-Pantheon-Styx-Hostname
X-Device
EagleEye-TraceId
X-Swift-CacheTime
X-Swift-SaveTime
X-Aws-Lambda-Call-Status
Ali-Swift-Global-Savetime
X-OneAgent-JS-Injection
X-Pingback
X-Host
X-Node
Accept-CH
X-Cache-Lookup
X-CST
X-WebKit-CSP
X-Backend-Server
X-Server-Id
Surrogate-Control
X-Readtime
Permissions-Policy
X-Nginx-Cache-Status
X-Nginx-Upstream-Cache-Status
X-Akam-SW-Version
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Application-Context
Request-Id
X-Content-Security-Policy-Report-Only
X-Cloud-Trace-Context
Accept-CH-Lifetime
X-Response-Time
X-HW
X-Trace
Xkey
X-Ruxit-JS-Agent
X-Edge
Content-Location
X-Clacks-Overhead
X-Mod-Pagespeed
Rating
X-Url
Accept-Ch-Lifetime
X-ESI
X-Midtier
X-Amz-Server-Side-Encryption
X-Oneagent-Js-Injection
X-ECACHE
X-Mcache
X-Country
Cache-Tag
X-Rack-Cache
X-MS-InvokeApp
X-D2id
X-Powered-By-Plesk
X-Upstream
X-Vcap-Request-Id
Verso
X-Kinja-Revision
X-Use-Magma
X-Kinja-Server
X-Kinja-Build
X-Kinja
X-Exp-Variant
X-GoogleNews-Bot
X-Cdn-Fetch
X-Exp-Id
X-Element-Page-Cache
Accept-Ch
Edge-Control
Service-Worker-Allowed
X-PC
X-TtlSet
X-Vname
RTSS
X-Ac
X-Country-Code
X-Webkit-CSP
Origin-Trial
X-Goog-Hash
X-Navigation-Version
X-VARITI-CCR
Fastly-Restarts
X-Abt-Application-Version
X-Ruxit-Js-Agent
X-Cache-TTL
X-WebKit-CSP-Report-Only
X-GitHub-Request-Id
X-Browser-Type
X-Amz-Rid
X-Cached
X-Kinja-CCPA
X-Varnish-TTL
X-Aspnetmvc-Version
Cross-Origin-Opener-Policy
X-Middleton-Display
X-Sol
Display
Pagespeed
X-Server-Name
X-NWS-LOG-UUID
X-Dw-Request-Base-Id
X-Amzn-Trace-Id
X-SharePointHealthScore
SPRequestGuid
X-Ttl
X-Content-Type
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
X-Times
SPIisLatency
X-Server-Lifecycle-Phase
SPRequestDuration
X-Erf-Bev-Bev
X-Instrumentation
X-Kraken-Loop-Name
X-Erf-Bev-Bev-Is-Generated
X-Powered-CMS
AR-ATIME
AR-PoweredBy
AR-SID
AR-Request-ID
X-Cache-Key
X-Mg-S
Pinterest-Version
Pinterest-Generated-By
X-Pinterest-Rid
X-B3-Traceid
Arr-Disable-Session-Affinity
X-Middleton-Response
Response
X-Litespeed-Cache
X-Client-IP
X-Fastly-Request-ID
X-Version
X-Cnection
X-HP-Webp
X-Jurisdiction
X-HP-Trace-Id
X-Ser
X-FastCGI-Cache
Nginx-Cache
AR-CACHE
Cache-Tags
X-Accel-Expires
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-T
Cache-Status
Edge-Cache-Tag
X-B3-TraceId
X-Hits
X-RateLimit-Remaining
Front-End-Https
X-MSEdge-Ref
X-Px
Public-Key-Pins
X-NF-Request-ID
X-Recruiting
Payment
S
X-LLID
X-Frontend
X-Ua-Browser
MRF-Tech
X-B3-TraceId-Primal
Server-Node
Mrf-Cache-Status
X-RateLimit-Limit
X-Shield-Request-Id
X-Request-Processing-Time
X-Request-Received
X-Server-ID
X-GUploader-UploadID
Content-MD5
X-Goog-Metageneration
X-Daa-Tunnel
X-DIS-Request-ID
Access-Control-Request-Method
X-PressLabs-Stats
MicrosoftSharePointTeamServices
X-Amz-Apigw-Id
X-Content-Digest
X-Amzn-RequestId
TP-Cache
Realpath
X-Webkit-CSP-Report-Only
X-Protected-By
X-HS-Hub-Id
X-Distributor
X-HS-Content-Id
X-HS-Combine-CSS
X-Request-Handler-Origin-Region
X-Microsite
X-HS-Cache-Config
X-Forwarded-For
Fastcgi-Cache
Access-Control-Allow-Method
X-FB-Debug
X-Fastcgi-Cache
X-TTL
X-LB-Cache
X-Page-Id
X-Cluster-Name
X-Rid
Accept-Charset
X-Ratelimit-Remaining
X-Hostname
X-Geo-Country
TP-L2-Cache
X-Erf-Stays-Pdp-Viaduct-Migration-Web
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-Goog-Stored-Content-Length
X-B3-Sampled
X-Goog-Storage-Class
X-Aspnet-Version
Count-Hit
X-Ua-Device
X-Seen-By
X-Ezoic-Cdn
Cross-Origin-Resource-Policy
Cleartype
X-Newrelic-App-Data
X-Kinsta-Cache
TCN
X-Edge-Location-Klb
X-App-Server
Referer-Policy
X-Mobile
X-Logged-In
X-Varnish-Backend
X-Correlation-Id
DC
X-Ratelimit-Limit
X-Content-Options
X-Id
X-Hosted-By
X-Origin-Cache
X-Git-Hash
X-Amz-Replication-Status
X-Fb-Rlafr
X-Debug-Info
X-Contextid
X-Grace
X-Revision
Surrogate-Key
X-Providence-Cookie
X-Is-Crawler
Retry-After
X-Flags
X-Request-Guid
X-TT
X-Route-Name
X-Aspnet-Duration-Ms
X-App-Environment
X-Forwarded-Proto
Frame-Options
X-IPS-LoggedIn
X-Amz-Meta-S3cmd-Attrs
X-Envoy-Decorator-Operation
X-Xrds-Location
X-Varnish-Grace
X-F-Cache
X-Azure-Ref
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
Section-Io-Cache
X-RateLimit-Reset
X-Magnolia-Registration
X-Wix-Request-Id
X-Whom
MS-Author-Via
Healthy
Alternate-Protocol
X-Origin-Server
X-Proxy-Cache-Info
Charset
X-Akamai-Edgescape
Viewport
X-App-Version
X-Www-Served-By
X-Nf-Request-Id
X-COUNTRY
X-Backend-Name
X-Language
X-Webkit-Csp
X-AppVersion
X-Az
X-Activity-Id
X-Varnish-Server
Paypal-Debug-Id
Filterid
X-B
SRV
WPO-Cache-Status
WPO-Cache-Message
X-Datadog-Sampling-Priority
X-Http-Reason
X-Cache-Rule
Server-Name
VIX-Pulpo-Node
X-Response-Served-From
X-Datadog-Trace-Id
Host
X-Original-Request-Id
X-Datadog-Parent-Id
VIX-Pulpo-Upstream-Status
X-Akamai-Request-ID2
X-Edge-Location
X-User-Agent
X-Rule
X-UUID
Akamai-GRN
X-Kong-Proxy-Latency
X-Jobs
X-Environment-Context
X-L-Path
X-Kong-Upstream-Latency
X-Varnish-Age
X-ARC
Front
X-Time
X-Instance
Protected
X-Status
X-Region
Amp-Access-Control-Allow-Source-Origin
From-Origin
Country
X-Unique-Id
X-Cache-Grace
SD-X-WS
X-Load-Cache
X-N
X-Cacheable-TTL
X-FW-Dynamic
X-FW-Serve
X-Rendered-As
X-FW-Server
X-FW-Static
X-EdgeConnect-Cache-Status
X-FW-Type
Fastly-SWR
X-FW-Hash
X-Rocket-Nginx-Serving-Static
X-Framework
X-FW-Version
X-Page-View
X-Is-Bot
Fastly-SIE
X-Adobe-Content
X-Adobe-Loc
X-G
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Client-Ip
X-Tumblr-User
X-ProcessESI
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-RemovedCookies
X-DataDome
X-Type
X-Trace-Id
ServerID
X-Cache-Time
Content-Disposition
X-Tec-Api-Root
X-Tec-Api-Version
X-Proxy
X-Tec-Api-Origin
X-Mg-Request-UUID
Access-Control-Request-Headers
X-Datadog-Sampled
X-B-Cache
X-Signature
X-Debug-IsConnected
X-Debug-IsPreview
X-Amzn-Remapped-Content-Length
X-Vcache
X-CDN-Forward
X-Cache-Control
X-Cache-Age
X-ECache
Backend
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
Refresh
Countrycode
X-Nginx-Cache
X-Drupal-Cache-Tags
X-DynaTrace
Accept-Language
X-Httpd
Xet-Cookie
X-Servername
X-Erf-Web-Scheduler
X-Tt-Trace-Tag
CF-IPCountry
X-Tt-Trace-Host
Url
X-DynaTrace-JS-Agent
X-Generated-By
X-Source
X-HTML-Minification-Powered-By
X-Template
X-XRDS-Location
X-XRDS-LOCATION
X-Device-Type
Webserver
X-Mode
X-Content-Powered-By
Xserver
X-NYM-Debug-Backend
Version
X-Storage
GEO-INFO
X-LAGOON
X-UPSTREAM-Address
X-Urbn-Context-Path
X-JoinUs
X-Urbn-Site-Id
OT-Force-Account-Verify
S-Rt
Filters
X-Say-Cacheable
X-Say-TTL
X-ServerID
X-SaId
X-Rn-Rsrv
X-Content-Age
X-Rewrite-Enabled
X-GeoCountry
X-Cache-Action
X-SayCDN-TTL
Meta-Geo
X-GeoCode
Locale
Load-Balancing
X-Director
X-Cache-Operation
X-Forwarded-Host
X-Git-Commit
X-Varnish-Cache-Hits
X-Cluster-Node
X-Soup
X-Varnish-Hostname
X-Tt-Logid
X-Container-Uri
Onion-Location
X-Cache-Hit
X-Detected-As
X-RM-Cache-TTL
X-VC-Cache
X-Served-From
X-Labrador-Cache-Channel
X-VCT
X-Sql-Count
X-Cache-Server
X-Tb
X-Sql-Duration-Ms
Azure-Version
Azure-SlotName
X-Ms-Version
X-Ms-Request-Id
X-Lambda-Id
X-PHP-Host
Web-Mar-Node
Azure-SiteName
Azure-RegionName
Azure-InstanceId
Node
X-Adobe-Source
Cross-Origin-Window-Policy
DB-Nickname
Mn-Server-Ip
X-RCS-CacheZone
X-Routing-Service
X-Proxied
X-Proto
X-Skip-Cache
X-Tncms
X-Zipkin-Id
X-URL
X-Loop
X-Logging-Id
X-R9-Blue-Green-Version
X-Extlb
X-CCDN-Origin-Time
X-Hcs-Proxy-Type
X-FB-TRIP-ID
X-CCDN-CacheTTL
X-Generation-Time
X-Tumblr-Pixel-3
X-Tumblr-Pixel-2
TWC-Device-Class
TWC-GeoIP-Country
TWC-Connection-Speed
TWC-GeoIP-LatLong
X-Timing-Wait
TWC-Locale-Group
X-Format
Webcakes-App-Name
X-Origin-Hint
X-Fetched-On
X-Proxy-Build
Webcakes-Region
X-Uri
X-Debug
TWC-Privacy
Webcakes-App-Version
X-MCACHE
Property-Id
Fastcgi-Useragent
Selected-Fe
Uber-Trace-Id
X-Endurance-Cache-Level
X-LSADC-Cache
X-Zen-Fury
X-Ua
X-Redis-Cache
Source
X-Sucuri-Cache
X-Sucuri-ID
X-NGENIX-Cache
X-Srv
Section-Io-Origin-Status
CDN-RequestId
X-Drupal-Cache-Contexts
Section-Origin-Responded
Section-Io-Origin-Time-Seconds
Section-Io-Id
X-B3-SpanId
X-Oracle-Dms-Ecid
X-S
X-Oracle-Dms-Rid
X-Pass-Why
X-Origin-Date
X-MP-GENERATED-AT
X-Upgrade-Enabled
X-Ratelimit-Reset
Fastly-Drupal-HTML
X-Varnish-Ttl
X-Cache-Expired-At
X-TimeS
X-Origin-TTL
X-Varnish-Hits
X-Origin-CC
Liferay-Portal
Upgrade-Insecure-Requests
X-FTR-Request-ID
X-Real-IP
NGB
X-Newrelic-Synthetics
X-Akamai-Transformed
X-Handled-By
X-CACHE-AGE
X-Optimistic-Header
X-Xfnlog-Site
X-Cache-TTL-Remaining
Apigw-Requestid
X-UA-Device-Type
X-Reqid
ServedBy
X-Hl-Ver
X-Cache-Type
X-Node-Name
X-Cms-Context
X-Restarts
X-Via-JSL
X-Correlation-ID
CDN-PullZone
CDN-RequestCountryCode
CDN-CachedAt
CDN-EdgeStorageId
CDN-Cache
MS-CV
X-No-Session
X-ProxyCache-Key
X-ProxyCache-Status
X-Cache-Host
X-BYPASS-REASON
X-RTag
CDN-Uid
X-CSRF-Token
Ms-Operation-Id
CDN-RequestPullSuccess
CDN-RequestPullCode
X-Pubstack
X-GEO
X-ID
X-Parent-Response-Time
X-VWS-Id
WP-Super-Cache
X-Server-W
X-AWS-Id
X-Cluster
X-IPLB-Instance
X-LJ-Flow-ID
X-IPLB-Request-ID
X-Cache-NE
X-CacheTTL
True-Client-Country-4JS
BehaviorPad-Version
X-Slack-Shared-Secret-Outcome
Lang
X-FC-Vary-Parameters
X-BCube-Filmed-By
Candidate-Md5Url
Xc-Version
X-Worker
Canary
X-Bc-Bl
X-Bl-Debug
X-Tx-Id
T-Server
X-Epic-Correlation-Id
X-CF-Lambda-Version
X-Destination
X-Developer
X-CGP
Meta-Geo-Continent
L5d-Success-Class
Surrogated-Key
X-Debug-Cache-Store
X-Dispatcher-Number
X-CF-Lambda-Fn
N-Cache
X-Eu-Site
X-External-Request-Id
X-Slack-Backend
L
X-Ec-Custom-Error
X-Ec-Fail
X-Ec-GeoHdr
X-Fastly-Backend
Redirect-Candidate
X-A-Ccd
X-Vtex-Remote-Cache
X-Conf
Rendered-Blocks
X-A-Dam
X-A-Dcw
X-SRCache-Key
X-A-Wwc
X-A-Dgt
X-We-Are-Hiring
X-A
X-Vdms-Version
X-S-Cookie
Gannett-Cam-Experience-Id
X-ScT
W
Odigeo-Trace-Id
X-Rojux
Web-Mar-Region
X-Viewer-Country
X-Csrf-Jwt
X-Request-Host
Origin-Agent-Cluster
DCR-Processing-Time-Ms
Sslversion
Magicmarker
HA-Ipaddr
Vix-Hermes-Req-Id
X-App-Name
X-Debug-Cache-Fetch
X-B-Cookie
X-Application
DCR-Decision-By
Ha-Gx-Prefs
Server-Host
X-Aed
MD5-Digest
X-Vdms-Path
Ngx.Var.Host
X-D
X-Datadome
X-Proxy-Cache-Status
X-AB
X-Clientip
X-CMSURLCustom
Thinkindot-Control
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
TDXMobile
X-Bip
X-Accel-Expires-Debug
X-Alternate-Cache-Key
X-Accel-Buffering
VNS-Age
Req-Svc-Chain
We-Hiring
X-App
Release
X-Cache-Info
X-Cdn-Diag
Producers
X-Cache-Debug
VNS-Cache
X-Cache-Bucket
X-Cdn-Origin
X-Mly-Id
X-Sorting-Hat-PodId
X-Sn-Servicetimems
X-Shopify-Stage
X-Sorting-Hat-ShopId
X-Storefront-Renderer-Rendered
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-ShopId
X-Shop-Environment
X-Request-Time
X-Refresh
X-RateLimit-Remaining-Second
X-S-Maxage
X-SD-PageType
X-ShardId
X-Server-IP
X-Tenant
X-Test
X-Vmg-Version
X-VG-WebCache
X-VG-TLSProxy
X-Wikidot-Backend
X-Wikidot-Static-Cache
Host-ID
X-Wix-Viewer-Type
X-Varnishpool
X-Varnish-Remaining-TTL
X-Up
X-Thinkindot-L3
X-Thanos
X-Var-Ttl
X-Variation
X-Varnish-CookieINHashed-On
X-Varnish-CookieHashed-On
X-RateLimit-Limit-Second
X-Qloud-Router
X-Hash
X-GeoIP-Region-Code
X-GeoIP-Country-Code
X-Human
X-Irp-Debug
X-Loc
X-Level-Front-Cache
X-Geo-Header
X-Generated-On
X-DefElseHash
X-Date
X-Core-Value
X-DefHash
X-DPWN-IS-SECURE
X-Gdpr
X-Forwarded-Path
X-Mid
Platform
X-Owner
X-Origin-Time
X-Orig-Expires
X-PAYTM-SRV-ID
X-Platform
X-Pool
X-Policy
X-Org
X-Old-Content-Length
X-Nananana
X-Mvc-Supplant-Cachable
X-Nitro-Cache
X-Node-Id
X-Nyt-Route
X-NodeID
X-Core-Mission
X-BBC-Edge-Cache-Status
Datacenter
CPC-Cache
Adler-Geo
Cache-Provider
Fastly-Backend-Name
X-Cache-Status-Check
Environment
Is-Eu
Mail-Subject
Content-Secure-Policy
CPC-Age
Gh-Request-Id
Origin
Fastly-GeoIP-CountryCode
Cmstype
Cmsid
X-B3-Spanid
Fastly-SSL
Cf-Device-Type
X-Micro-Cache
AKAMAI
Expect-Staple
User-Cache-Control
AMP-Access-Control-Allow-Source-Origin
X-TIME
Apple-News-Services-Host
X-Auto-Login
X-Geo-Region
CDCHOST
X-Block-Status
X-Origin
Apple-News-Services-Handled
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
X-Origin-Response-Time
X-VServer
X-Gen-Mode
X-WA-Info
X-GeoIP
X-Gzip
X-INCAP-ABP
X-PERF
X-Hnp-Log
X-From
X-Forwarded-Site
Cache-Name
CloudFront-Viewer-Country
X-Clara-WADP
X-Device-Os
X-Dispatcher-Server
X-WADP-Cache
X-Fmm-Version
X-Esi-Check
X-Cdn-Srv
X-Cache-Id
NM-Fastcgi-Cache
Esi-Enabled
X-ApacheServer
Machine
DSUID
X-Nginx-Cache-Key
X-Akamai-Device-Characteristics
Country-Code
X-Mvc-Supplant-OutputCached
X-Vcl-Version
X-AIR-PT
X-Access
X-Section
Pics-Label
Server-Info
Sever-Int
X-TraceId
Ssr
X-Instance-Name
NGX
Server-Hostname
X-Op-Id-All
X-LB-NoCache
C-Via
Server-Ext
Wxu-Next-Region
X-Cache-Enabled
Wxu-Next-Commit
Wxu-Next-Hostname
X-NCache
X-Dc
X-Fastly-Request-Id
Server-ID
X-Amz-Meta-Cb-Modifiedtime
X-Via-Fastly
X-API-Version
X-Accel-Version
Memcached
X-JWT-State
X-Is-Gdpr
X-Has-Esi
X-HA-Backend
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Ttl
X-CACHE-GROUP
X-Vgn-Hpd-Reason
X-Is-Mobile
X-Is-Tablet
X-Is-Desktop
X-Browser-Name
X-Is-Supported-Browser
X-Tcp-Rtt
X-Buckets
X-SIPLIST1
Hostname
Cdn-Requestid
IsBot
Memory
Time
X-Platform-Router
Origin-EX
Sid
Origin-CC
X-Scale
X-Platform-Processor
Cache-Hits
X-Platform-Cluster
CF-Ctrl
X-TIM-N
YJS-ID
X-Air-Trace-Id
X-Air-Hostname
X-PHP-Backend
Location
X-Air-Source
X-ZONE
X-B3-Parentspanid
X-Wp-Cf-Super-Cache-Active
X-Tb-Optimization-Total-Bytes-Saved
X-Zone
X-Presslabs-Stats
X-Cached-By
X-Fpc
X-Internal-Host
X-Backend-Instance
X-WP-CF-Super-Cache-Active
X-Frame-Option
X-Origin-Cache-Key
X-Hyper-Cache
X-Azure-Ref-OriginShield
Resin-Trace
X-DC
X-Cs
X-TA-CDN-Provider
Uri
GeoIP-Latitude
X-VC
X-Site-Version
X-Service
True-Client-Ip
X-Webstats-RespID
Cache-Host
X-DataCenter
Epwk-X-Cache
X-Microcachable
X-Origin-Expires
X-LiteSpeed-Cache-Control
X-VCache
X-Nitro-Rev
X-Nitro-Cache-From
GeoIP-Country-Code
X-NGINX-Cache
XM
X-Info
X-Locale
X-Web-Node
X-FTR-Cache-Status
X-FTR-Expires
X-FTR-Balancer
X-FTR-Backend
X-FTR-Backend-Server
X-Country-Code-Real
Cdn
PFcat
GeoIp-Country-Code
X-Pod-Name
X-VarnishDD-TTL
X-HN
LB
Cdn-Request-Time
X-Edge-Server
Cdn-Host
NtCoent-Length
X-CS
XServer
X-Datacenter
X-Cache-Ttl
User-Agent
X-Geo
X-Ad-Defer-Variation
X-NewRelic-App-Data
X-CSRF-TOKEN
X-FL-EDGE
Req-ID
Srvid
Locid
WZWS-RAY
Edge-Copy-Time
X-NMSegId
A
M-TraceId
X-Via-Edge
X-Via-SSL
X-Via-CDN
True-Client-IP
X-FL-QIT-DEBUG
WebServer
X-Vercel-Cache
X-SRV
X-Vercel-Id
X-TRACE-ID
X-Ad-Load-Variation
SID
X-Moov-T
X-Varnish-Authentication
X-MSEdge-Flight
X-Moov-Xdn-Version
X-Cache-ASPX
X-FireWall-Port
X-Pad
X-FPC
X-M-Reqid
X-Scope-Id
X-Request-Start
Cluster
X-Contensis-Viewer-Groups
Fastly-Drupal-Html
X-ATG-Version
X-M-Log
X-MSEdge-Features
Pramga
Tcn
X-HostName
X-Request-URI
X-LiteSpeed-Tag
X-Shield-Cache-Expires
X-Varnish-Beresp-Status
Cache-Key
X-NWS-UUID-VERIFY
X-Qnm-Cache
HostName
X-Cdn-Request-ID
CountryCode
X-APP-VERSION
Cf-Ipcountry
X-Api-Version
Cdnsip
Edge-Cache
X-Cache-Date
X-Amz-Meta-Opti
Path
Content-Script-Type
Cdncip
Content-Style-Type
X-AK-Request-ID
X-Air-Pt
X-Esi
Cache-Tv-Group
Wpo-Cache-Message
X-TH-Server
X-Branch-Name
Wpo-Cache-Status
X-Wp-Cf-Super-Cache-Cookies-Bypass
Click-Count-Action-Start
XkeyRZ
Click-Count-Error
Tube-Get-Contents
X-Render-Time
X-Github-Request-Id
Tube-Got-Eval
X-Planisys-CDN-TTL
X-Planisys-CDN-Cache
X-Platform-Server
State
X-Planisys-CDN-Rules
Tube-Return
X-V-Cache
X-Servedbyhost
X-SB
X-Via-Poph
X-Via-Popn
X-Wa
X-Via-Popv
X-Req
X-Nc
X-Acquia-Purge-Cdn-Unconfigured
X-HS-Content-Campaign-Id
X-Aicache-OS
X-B3-Trace-ID
X-LB-ID
X-Cache-FS-Status
Tube-Got-Results
X-Proxy-CacheRZ
Yak-Timeinfo
X-WP-CF-Super-Cache-Cookies-Bypass
X-Upstream-Ct
X-VCL-Version
X-Upstream-Ht
CDN
X-Rebelmouse-Surrogate-Control
X-CACHE-KEY
Lb
X-Rebelmouse-Cache-Control
X-Vgn-Hpd-Variations-Key
X-Vary
Proxy-Connection
X-Cdn-Forward
Geoip-Latitude
X-Men
X-Wp-Cf-Super-Cache
V-Age
X-Vgn-Hpd-Cached
X-Vgn-Hpd-Ssi
X-Fastly-Cache
X-Release
X-Tim-N
Srv
On-Server
X-Akamai-Pragma-Client-IP
X-Wp-Cf-Super-Cache-Cache-Control
X-Lb-Cache
X-Sigma
CF-Cached-On
X-Rocket-Build-Number
X-Sigma-Backend
MIME-Version
X-User
X-UA
Server-Id
X-Cache-Remote
X-HS-Status
X-Ha-Backend
Ohc-File-Size
X-Traceid
Ngx-Var-Key
X-Dw-Trace-Id
X-Generated-In
X-TT-LOGID
X-Fastly-Backend-Reqs
X-CUA
Cache
Ohc-Cache-HIT
X-Acquia-Purge-Tags
X-Acquia-Application-UUID
X-Acquia-Application-Trace
X-Via-Ucdn
PICS-Label
X-Acquia-Site
X-EC-Lua
X-Lb-Nocache
My-App
X-Iplb-Request-Id
Yjs-Id
X-Iplb-Instance
X-TX-ID
CACHE-MISS-TO-ORIGIN
Mime-Version
Warning
X-Scheme
Cneonction
X-Cached-Since
Vha6-Origin
X-ElasticPress-Query
X-Miniprofiler-Ids
Log-Origin
X-RAMCache
X-Litespeed-Cache-Control
X-GoCache-CacheStatus
Ngx
X-Snapshot-Date
X-Fastly-Cache-Hits
Inserted-Into-Cache-At
X-GeoIP-City
X-Udemy-Cache-App-Namespace
X-CF-Cache-Header-Cache-Control
X-CF-Cache-Header-Vary
X-Gamma-Serve