Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
X-Powered-By
Pragma
X-XSS-Protection
CF-RAY
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
Alt-Svc
P3P
X-Cache-Hits
X-UA-Compatible
X-Xss-Protection
X-Served-By
CF-Ray
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
Access-Control-Allow-Credentials
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
X-Drupal-Cache
X-Cache-Status
X-Generator
X-Check
X-Cacheable
X-FRAME-OPTIONS
X-Envoy-Upstream-Service-Time
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Iinfo
X-Dns-Prefetch-Control
X-Drupal-Dynamic-Cache
Feature-Policy
X-Content-Security-Policy
Server-Timing
X-XSS-PROTECTION
Access-Control-Expose-Headers
Content-Encoding
X-CDN
Status
Upgrade
X-Request-ID
X-AspNetMvc-Version
Access-Control-Max-Age
X-Amz-Request-Id
X-Amz-Id-2
X-Via
Request-Context
X-Turbo-Charged-By
X-Backend
X-Cache-Group
X-AH-Environment
X-Robots-Tag
Cf-Edge-Cache
Keep-Alive
Host-Header
X-Hacker
X-Proxy-Cache
X-UA-Device
X-Vhost
X-Server
X-Rq
X-Server-Powered-By
Allow
X-Ws-Request-Id
X-Age
X-Varnish-Cache
X-Dispatcher
EagleId
X-Amz-Version-Id
X-LiteSpeed-Cache
P3p
Nel
Grace
Cf-Apo-Via
Cf-Railgun
X-Page-Speed
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Device
EagleEye-TraceId
X-Aws-Lambda-Call-Status
X-Swift-CacheTime
X-Swift-SaveTime
X-OneAgent-JS-Injection
Ali-Swift-Global-Savetime
X-Pingback
X-Host
X-WebKit-CSP
X-Node
X-CST
X-Cache-Lookup
X-Server-Id
Accept-CH
X-Backend-Server
Surrogate-Control
X-Readtime
Permissions-Policy
X-Nginx-Cache-Status
X-Nginx-Upstream-Cache-Status
X-EdgeConnect-Origin-MEX-Latency
X-Akam-SW-Version
X-EdgeConnect-MidMile-RTT
Request-Id
X-Application-Context
Accept-CH-Lifetime
X-Content-Security-Policy-Report-Only
X-Cloud-Trace-Context
X-Ua-Compatible
X-Response-Time
X-HW
X-Trace
X-Ruxit-JS-Agent
Xkey
X-Edge
Content-Location
X-Clacks-Overhead
X-Mod-Pagespeed
Rating
X-ESI
Accept-Ch
X-Midtier
X-Url
X-Amz-Server-Side-Encryption
Accept-Ch-Lifetime
X-Mcache
Cache-Tag
X-ECACHE
X-MS-InvokeApp
X-Country
X-Upstream
X-D2id
X-Vcap-Request-Id
X-Powered-By-Plesk
X-Rack-Cache
X-Exp-Variant
X-Exp-Id
X-GoogleNews-Bot
X-Cdn-Fetch
X-Use-Magma
X-Kinja-Revision
X-Kinja-Build
X-Kinja
X-Kinja-Server
Verso
X-Oneagent-Js-Injection
X-Element-Page-Cache
Edge-Control
X-WebKit-CSP-Report-Only
X-Vname
X-TtlSet
X-PC
RTSS
Service-Worker-Allowed
X-Country-Code
X-Ac
Origin-Trial
X-Navigation-Version
X-VARITI-CCR
X-GitHub-Request-Id
X-Goog-Hash
Fastly-Restarts
X-Abt-Application-Version
X-Cache-TTL
X-Browser-Type
X-Aspnetmvc-Version
X-Cached
X-Amz-Rid
X-Webkit-CSP
X-Kinja-CCPA
X-Varnish-TTL
X-Ruxit-Js-Agent
Cross-Origin-Opener-Policy
Pagespeed
X-Middleton-Display
Display
X-Sol
X-NWS-LOG-UUID
X-Server-Name
X-Dw-Request-Base-Id
X-Amzn-Trace-Id
SPRequestGuid
X-SharePointHealthScore
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
X-Ttl
SPIisLatency
X-Powered-CMS
SPRequestDuration
X-Kraken-Loop-Name
X-Instrumentation
X-Erf-Bev-Bev-Is-Generated
X-Times
X-Server-Lifecycle-Phase
X-Erf-Bev-Bev
X-Content-Type
AR-PoweredBy
AR-ATIME
AR-Request-ID
AR-SID
X-Mg-S
X-FastCGI-Cache
X-Litespeed-Cache
Pinterest-Version
X-Pinterest-Rid
Pinterest-Generated-By
X-Fastly-Request-ID
X-Middleton-Response
Response
Arr-Disable-Session-Affinity
X-Client-IP
X-Cache-Key
X-B3-Traceid
X-Version
X-Jurisdiction
X-HP-Webp
X-HP-Trace-Id
X-Cnection
Nginx-Cache
X-Ser
AR-CACHE
X-T
X-Accel-Expires
Cache-Tags
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-B3-TraceId
X-RateLimit-Remaining
Cache-Status
Edge-Cache-Tag
Front-End-Https
X-MSEdge-Ref
X-NF-Request-ID
X-Hits
X-Px
Public-Key-Pins
X-Recruiting
Payment
X-Request-Received
X-LLID
X-Request-Processing-Time
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
X-Frontend
S
Server-Node
X-Ua-Browser
X-Shield-Request-Id
X-RateLimit-Limit
X-PressLabs-Stats
X-Goog-Metageneration
X-GUploader-UploadID
X-DIS-Request-ID
Content-MD5
X-Daa-Tunnel
MicrosoftSharePointTeamServices
X-Amz-Apigw-Id
X-Amzn-RequestId
TP-Cache
X-Content-Digest
Access-Control-Request-Method
X-TTL
X-Protected-By
Realpath
X-Request-Handler-Origin-Region
X-Microsite
X-Distributor
Access-Control-Allow-Method
X-HS-Cache-Config
X-HS-Combine-CSS
Fastcgi-Cache
X-FB-Debug
X-HS-Hub-Id
X-HS-Content-Id
X-Page-Id
X-LB-Cache
X-Rid
Accept-Charset
X-Forwarded-For
X-Cluster-Name
X-Erf-Stays-Pdp-Viaduct-Migration-Web
X-Geo-Country
X-Server-ID
X-Aspnet-Version
TP-L2-Cache
X-Ua-Device
X-Hostname
X-Ezoic-Cdn
X-Goog-Generation
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-B3-Sampled
X-Goog-Stored-Content-Length
X-Seen-By
Count-Hit
Cross-Origin-Resource-Policy
X-Ratelimit-Remaining
X-Ratelimit-Limit
Cleartype
X-Correlation-Id
TCN
X-Newrelic-App-Data
X-Webkit-CSP-Report-Only
X-App-Server
X-Fastcgi-Cache
X-Mobile
Referer-Policy
DC
X-Logged-In
X-Content-Options
X-Kinsta-Cache
X-Edge-Location-Klb
X-Varnish-Backend
X-Hosted-By
X-Origin-Cache
X-Git-Hash
X-Contextid
X-Id
X-Fb-Rlafr
X-Is-Crawler
X-Providence-Cookie
X-Route-Name
X-Request-Guid
X-Flags
X-Aspnet-Duration-Ms
X-Amz-Replication-Status
X-Debug-Info
X-Grace
X-Revision
X-IPS-LoggedIn
Frame-Options
X-TT
X-App-Environment
X-Varnish-Grace
Surrogate-Key
X-Amz-Meta-S3cmd-Attrs
Retry-After
X-Envoy-Decorator-Operation
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-TEC-API-ROOT
X-Forwarded-Proto
X-F-Cache
X-Azure-Ref
X-RateLimit-Reset
X-Xrds-Location
Section-Io-Cache
X-Magnolia-Registration
X-Wix-Request-Id
X-Whom
Alternate-Protocol
X-COUNTRY
Healthy
Charset
X-Origin-Server
MS-Author-Via
X-Akamai-Edgescape
WPO-Cache-Status
WPO-Cache-Message
X-Proxy-Cache-Info
Viewport
X-Backend-Name
X-ECache
X-Language
Paypal-Debug-Id
X-Www-Served-By
X-App-Version
X-B
X-Az
X-AppVersion
X-Activity-Id
Filterid
X-Datadog-Parent-Id
VIX-Pulpo-Node
X-Original-Request-Id
X-Response-Served-From
SD-X-WS
X-Varnish-Server
X-Datadog-Trace-Id
X-Cache-Rule
X-Datadog-Sampling-Priority
VIX-Pulpo-Upstream-Status
X-DataDome
X-Rule
X-User-Agent
Server-Name
Host
Country
Front
X-Cache-Grace
X-UUID
X-Http-Reason
X-Nf-Request-Id
X-Cacheable-TTL
X-Edge-Location
X-N
X-Instance
X-ARC
X-Akamai-Request-ID2
ServerID
Akamai-GRN
From-Origin
SRV
Protected
X-Jobs
X-EdgeConnect-Cache-Status
X-Varnish-Age
X-Page-View
X-Unique-Id
X-Adobe-Loc
X-Status
X-Framework
X-Rendered-As
X-Adobe-Content
X-Tumblr-Pixel-1
X-Rocket-Nginx-Serving-Static
X-Tumblr-Pixel
Fastly-SIE
Fastly-SWR
X-Load-Cache
X-Tumblr-User
X-Environment-Context
X-Is-Bot
X-L-Path
X-Region
X-Tumblr-Pixel-0
X-G
X-FW-Type
X-RemovedCookies
X-FW-Dynamic
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-FW-Static
Amp-Access-Control-Allow-Source-Origin
X-Yottaa-Optimizations
X-Cache-Time
X-FW-Hash
X-FW-Serve
X-FW-Server
X-Yottaa-Metrics
X-ProcessESI
X-FW-Version
X-Time
Access-Control-Request-Headers
X-Type
X-Trace-Id
X-Vcache
X-Datadog-Sampled
X-Mg-Request-UUID
X-Proxy
X-Signature
X-B-Cache
X-Amzn-Remapped-Content-Length
X-Debug-IsConnected
X-Debug-IsPreview
Content-Disposition
X-Cache-Control
X-Tec-Api-Version
X-Tec-Api-Origin
X-Tec-Api-Root
X-Cache-Age
X-Client-Ip
Backend
X-CDN-Forward
X-Erf-Web-Scheduler
Refresh
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
X-XRDS-LOCATION
X-DynaTrace
Countrycode
Xet-Cookie
X-Drupal-Cache-Tags
Accept-Language
X-XRDS-Location
X-Httpd
X-Source
X-DynaTrace-JS-Agent
X-Servername
X-Generated-By
Webserver
Url
X-HTML-Minification-Powered-By
X-Tt-Trace-Tag
X-Template
X-Tt-Trace-Host
CF-IPCountry
X-Nginx-Cache
X-Device-Type
X-Storage
X-Content-Powered-By
X-NYM-Debug-Backend
X-Mode
X-Content-Age
Version
X-Rn-Rsrv
X-GeoCode
OT-Force-Account-Verify
X-SaId
X-GeoCountry
X-Director
X-Cache-Action
GEO-INFO
Meta-Geo
Filters
X-JoinUs
S-Rt
Onion-Location
Load-Balancing
X-Cache-Operation
X-UPSTREAM-Address
X-Generation-Time
X-Say-TTL
X-ServerID
X-LAGOON
X-URL
X-Say-Cacheable
X-Rewrite-Enabled
X-SayCDN-TTL
X-Git-Commit
X-MCACHE
X-Container-Uri
X-Soup
X-Urbn-Context-Path
Locale
X-Varnish-Cache-Hits
Xserver
X-Urbn-Site-Id
X-Varnish-Hostname
X-Cluster-Node
X-Hcs-Proxy-Type
X-Tb
X-RM-Cache-TTL
X-Detected-As
Azure-InstanceId
Azure-SiteName
Azure-SlotName
Azure-Version
Azure-RegionName
X-CCDN-Origin-Time
X-Tncms
X-Loop
X-Adobe-Source
X-Sql-Count
X-VCT
X-Served-From
X-Cache-Server
X-Ms-Request-Id
X-CCDN-CacheTTL
X-VC-Cache
X-Ms-Version
X-Sql-Duration-Ms
X-Forwarded-Host
X-Labrador-Cache-Channel
X-PHP-Host
X-Proto
X-Skip-Cache
X-Cache-Hit
X-Tt-Logid
Web-Mar-Node
Node
DB-Nickname
X-Lambda-Id
X-Tumblr-Pixel-3
X-R9-Blue-Green-Version
X-FB-TRIP-ID
X-Logging-Id
X-Tumblr-Pixel-2
X-Ua
X-Fetched-On
Fastcgi-Useragent
X-Format
X-Proxy-Build
Cross-Origin-Window-Policy
Selected-Fe
Uber-Trace-Id
X-Timing-Wait
X-RCS-CacheZone
TWC-GeoIP-Country
TWC-Device-Class
TWC-GeoIP-LatLong
TWC-Connection-Speed
X-Uri
X-Debug
Webcakes-App-Version
Webcakes-App-Name
X-Origin-Hint
TWC-Privacy
TWC-Locale-Group
Webcakes-Region
Property-Id
X-Webkit-Csp
X-Routing-Service
X-Zipkin-Id
Mn-Server-Ip
X-Endurance-Cache-Level
X-Extlb
X-Proxied
X-Redis-Cache
Source
X-LSADC-Cache
X-Zen-Fury
X-Sucuri-ID
X-Sucuri-Cache
X-B3-SpanId
CDN-RequestId
X-Drupal-Cache-Contexts
X-Srv
Section-Origin-Responded
Section-Io-Origin-Time-Seconds
X-Upgrade-Enabled
Section-Io-Id
Section-Io-Origin-Status
X-TimeS
X-Varnish-Ttl
X-S
X-Origin-Date
X-MP-GENERATED-AT
X-Newrelic-Synthetics
X-NGENIX-Cache
X-Varnish-Hits
X-Pass-Why
X-Origin-TTL
X-Cache-Expired-At
X-Origin-CC
Liferay-Portal
Upgrade-Insecure-Requests
X-Real-IP
X-Akamai-Transformed
X-CACHE-AGE
X-FTR-Request-ID
X-Ratelimit-Reset
Fastly-Drupal-HTML
NGB
X-Handled-By
X-GEO
X-Oracle-Dms-Ecid
X-Oracle-Dms-Rid
X-Hl-Ver
X-Node-Name
X-ID
X-Cache-Type
CDN-EdgeStorageId
X-UA-Device-Type
X-Optimistic-Header
Apigw-Requestid
CDN-RequestCountryCode
CDN-PullZone
CDN-RequestPullCode
CDN-RequestPullSuccess
CDN-Uid
X-Via-JSL
X-Cms-Context
CDN-CachedAt
X-Pubstack
X-Reqid
CDN-Cache
X-Cache-TTL-Remaining
ServedBy
X-ProxyCache-Key
X-BYPASS-REASON
X-Cache-Host
X-Restarts
X-CSRF-Token
X-ProxyCache-Status
Ms-Operation-Id
MS-CV
WP-Super-Cache
X-Parent-Response-Time
X-RTag
X-Xfnlog-Site
X-No-Session
X-Tx-Id
Sslversion
Surrogated-Key
Server-Host
T-Server
True-Client-Country-4JS
Meta-Geo-Continent
DCR-Processing-Time-Ms
Gannett-Cam-Experience-Id
DCR-Decision-By
Candidate-Md5Url
BehaviorPad-Version
Canary
Lang
Magicmarker
Origin-Agent-Cluster
Redirect-Candidate
Odigeo-Trace-Id
Ngx.Var.Host
MD5-Digest
N-Cache
Rendered-Blocks
X-B-Cookie
X-Origin-Time
X-Orig-Expires
X-Request-Host
X-Rojux
X-S-Cookie
X-Nyt-Route
X-Gdpr
X-External-Request-Id
X-Epic-Correlation-Id
X-Fastly-Backend
X-FC-Vary-Parameters
X-Forwarded-Path
X-ScT
X-SD-PageType
X-Vtex-Remote-Cache
X-Viewer-Country
X-We-Are-Hiring
X-Worker
Xc-Version
X-Vdms-Version
X-Vdms-Path
X-Slack-Backend
X-Shop-Environment
X-Slack-Shared-Secret-Outcome
X-SRCache-Key
X-Tenant
X-Ec-GeoHdr
X-Ec-Fail
X-App
X-Aed
X-App-Name
X-Application
X-BCube-Filmed-By
X-A-Wwc
X-A-Dgt
X-A
Web-Mar-Region
X-A-Ccd
X-A-Dam
X-A-Dcw
X-Bl-Debug
X-Cache-NE
X-Destination
X-Debug-Cache-Store
X-Developer
X-Dispatcher-Number
X-Ec-Custom-Error
X-Debug-Cache-Fetch
X-D
X-CacheTTL
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-Conf
Vix-Hermes-Req-Id
X-Bc-Bl
Content-Secure-Policy
X-IPLB-Request-ID
X-IPLB-Instance
X-Server-W
X-TIME
X-DPWN-IS-SECURE
X-CGP
Platform
X-SVT-ORM-VERSION
Producers
X-AB
X-Policy
X-Pool
X-BBC-Edge-Cache-Status
X-Qloud-Router
X-Bip
X-SVT-ORM-RULES
Release
X-Org
Req-Svc-Chain
Origin
X-Thanos
X-Cache-Debug
X-Up
X-Nitro-Cache
L5d-Success-Class
Is-Eu
HA-Ipaddr
X-Nananana
X-Node-Id
Mail-Subject
X-Storefront-Renderer-Rendered
X-Test
X-Thinkindot-L3
X-Cache-Bucket
X-NodeID
X-Eu-Site
X-Old-Content-Length
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Refresh
X-Core-Value
X-Csrf-Jwt
X-Owner
X-Server-IP
X-Date
X-Core-Mission
X-PAYTM-SRV-ID
X-Alternate-Cache-Key
X-CMSURLCustom
X-Clientip
X-Request-Time
X-S-Maxage
X-Accel-Buffering
X-Accel-Expires-Debug
We-Hiring
W
TDXMobile
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
X-Sn-Servicetimems
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
Ha-Gx-Prefs
Thinkindot-Control
X-DefElseHash
VNS-Age
VNS-Cache
AMP-Access-Control-Allow-Source-Origin
X-ShardId
X-Shopify-Stage
X-ShopId
X-DefHash
L
X-Varnish-Remaining-TTL
X-Varnishpool
X-VServer
X-Geo-Header
X-Loc
X-Micro-Cache
X-GeoIP-Country-Code
X-Level-Front-Cache
Cf-Device-Type
X-Varnish-CookieINHashed-On
X-Mly-Id
X-Generated-On
Adler-Geo
X-Cdn-Diag
X-VG-TLSProxy
X-VG-WebCache
AKAMAI
X-Correlation-ID
X-Vmg-Version
X-Cache-Info
Gh-Request-Id
X-Platform
Cmsid
Host-ID
X-Irp-Debug
Expect-Staple
X-Cdn-Origin
Environment
Fastly-Backend-Name
Fastly-GeoIP-CountryCode
X-Var-Ttl
X-Variation
X-Human
Fastly-SSL
X-Varnish-CookieHashed-On
X-Wix-Viewer-Type
CPC-Cache
CPC-Age
X-GeoIP-Region-Code
Cmstype
X-Mid
X-Wikidot-Backend
X-Mvc-Supplant-Cachable
Datacenter
X-Hash
X-Wikidot-Static-Cache
X-VWS-Id
X-Cache-Status-Check
X-Cluster
X-Proxy-Cache-Status
X-AWS-Id
X-LJ-Flow-ID
X-Akamai-Device-Characteristics
X-ApacheServer
X-Gzip
X-PERF
Cache-Name
X-GeoIP
X-Datadome
X-Fmm-Version
NM-Fastcgi-Cache
Country-Code
X-Dispatcher-Server
DSUID
X-Esi-Check
X-Clara-WADP
X-Mvc-Supplant-OutputCached
Machine
Esi-Enabled
CloudFront-Viewer-Country
X-Device-Os
X-From
X-INCAP-ABP
X-WA-Info
X-Origin-Response-Time
X-Origin
X-Vcl-Version
X-Cache-Id
Cache-Provider
X-Forwarded-Site
X-WADP-Cache
X-Geo-Region
X-Dc
X-B3-Spanid
User-Cache-Control
X-Cache-Enabled
CDCHOST
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
X-Hnp-Log
X-Gen-Mode
Apple-News-Services-Handled
Apple-News-Services-Host
X-Nginx-Cache-Key
X-Block-Status
Ssr
X-Auto-Login
X-AIR-PT
Sever-Int
Server-Info
NGX
Server-Ext
Server-Hostname
X-Cdn-Srv
X-API-Version
X-TraceId
X-Vgn-Hpd-Reason
X-LB-NoCache
Wxu-Next-Commit
Wxu-Next-Hostname
X-NCache
X-Instance-Name
X-Op-Id-All
Pics-Label
C-Via
Wxu-Next-Region
X-CACHE-GROUP
X-Has-Esi
X-JWT-State
X-Is-Gdpr
X-Amz-Meta-Cb-Modifiedtime
X-Access
X-Accel-Version
Memcached
X-Section
Memory
Hostname
Time
X-Via-Fastly
Server-ID
X-Buckets
X-ZONE
X-Varnish-Beresp-Grace
X-Is-Supported-Browser
X-Is-Tablet
X-HA-Backend
Sid
Cache-Hits
X-Tcp-Rtt
X-Browser-Name
X-Is-Mobile
X-Scale
Origin-CC
Origin-EX
X-Is-Desktop
X-TIM-N
X-Wp-Cf-Super-Cache-Active
X-Platform-Router
X-Platform-Processor
X-Platform-Cluster
X-SIPLIST1
Cdn-Requestid
X-PHP-Backend
IsBot
X-Varnish-Beresp-Ttl
X-Fastly-Request-Id
YJS-ID
X-Tb-Optimization-Total-Bytes-Saved
X-Air-Hostname
X-Air-Source
X-B3-Parentspanid
X-Air-Trace-Id
CF-Ctrl
X-WP-CF-Super-Cache-Active
X-Cached-By
X-Backend-Instance
X-Internal-Host
Location
X-Zone
Resin-Trace
X-Azure-Ref-OriginShield
X-Fpc
X-NGINX-Cache
X-Cs
X-TA-CDN-Provider
X-Frame-Option
GeoIP-Latitude
X-Hyper-Cache
Epwk-X-Cache
X-Presslabs-Stats
X-Origin-Expires
Cache-Host
X-DC
X-Microcachable
X-LiteSpeed-Cache-Control
X-Origin-Cache-Key
X-Webstats-RespID
Uri
X-Site-Version
X-DataCenter
X-Service
X-Info
XM
X-Nitro-Cache-From
X-Nitro-Rev
GeoIp-Country-Code
XServer
X-VC
X-Web-Node
True-Client-Ip
X-Pod-Name
PFcat
X-HN
X-Locale
X-VarnishDD-TTL
X-FTR-Backend-Server
X-FTR-Balancer
X-FTR-Expires
X-Country-Code-Real
X-FTR-Backend
X-VCache
X-FTR-Cache-Status
X-Ad-Defer-Variation
X-Cache-Ttl
X-CS
User-Agent
True-Client-IP
GeoIP-Country-Code
X-NewRelic-App-Data
X-CSRF-TOKEN
LB
X-Via-SSL
X-FL-EDGE
X-Via-Edge
NtCoent-Length
A
X-Via-CDN
X-Edge-Server
X-FL-QIT-DEBUG
X-Datacenter
Locid
Cdn-Host
Cdn
Cdn-Request-Time
Srvid
Edge-Copy-Time
X-Geo
Fastly-Drupal-Html
Req-ID
X-Vercel-Id
M-TraceId
X-Vercel-Cache
WZWS-RAY
X-FPC
X-TRACE-ID
X-NMSegId
X-SRV
Cf-Ipcountry
X-APP-VERSION
X-Pad
X-Moov-T
X-CACHE-KEY
X-Cache-ASPX
X-MSEdge-Flight
X-Varnish-Authentication
X-ATG-Version
X-Ad-Load-Variation
X-FireWall-Port
X-MSEdge-Features
X-Contensis-Viewer-Groups
X-Moov-Xdn-Version
X-HostName
Tcn
WebServer
X-LiteSpeed-Tag
Content-Script-Type
Content-Style-Type
Cluster
SID
X-Request-Start
Pramga
X-M-Reqid
X-M-Log
X-Scope-Id
Cache-Key
CountryCode
X-Cdn-Request-ID
X-Api-Version
Path
X-Amz-Meta-Opti
X-Varnish-Beresp-Status
X-NWS-UUID-VERIFY
Cdnsip
X-AK-Request-ID
X-Qnm-Cache
Cdncip
X-Shield-Cache-Expires
X-Esi
X-Air-Pt
X-Request-URI
X-Branch-Name
HostName
Edge-Cache
X-Cache-Date
Srv
X-Wp-Cf-Super-Cache-Cache-Control
X-Cdn-Forward
X-Wp-Cf-Super-Cache
CDN
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-TH-Server
X-Proxy-CacheRZ
X-Platform-Server
Yak-Timeinfo
X-Planisys-CDN-TTL
State
X-Planisys-CDN-Cache
XkeyRZ
X-HS-Content-Campaign-Id
X-WP-CF-Super-Cache-Cookies-Bypass
X-Planisys-CDN-Rules
Lb
X-Rebelmouse-Surrogate-Control
X-Upstream-Ht
X-Rebelmouse-Cache-Control
Cache-Tv-Group
X-Upstream-Ct
X-Vgn-Hpd-Ssi
X-Vgn-Hpd-Cached
Server-Id
X-Tim-N
X-Akamai-Pragma-Client-IP
X-Req
Geoip-Latitude
X-Acquia-Purge-Cdn-Unconfigured
X-Aicache-OS
X-B3-Trace-ID
X-Release
Tube-Return
X-Fastly-Cache
Tube-Got-Eval
Tube-Got-Results
X-Render-Time
Tube-Get-Contents
X-V-Cache
Proxy-Connection
X-Vgn-Hpd-Variations-Key
X-LB-ID
X-Cache-FS-Status
Click-Count-Error
Click-Count-Action-Start
Ohc-File-Size
X-Lb-Cache
X-SB
Ohc-Cache-HIT
X-Wa
On-Server
X-Men
X-Vary
X-Via-Popv
X-Via-Popn
V-Age
X-Nc
X-Servedbyhost
X-Via-Poph
X-User
X-Dw-Trace-Id
X-Traceid
X-VCL-Version
X-Generated-In
X-Sigma-Backend
X-Sigma
X-HS-Status
X-Cache-Remote
X-Rocket-Build-Number
X-Ha-Backend
CF-Cached-On
X-Lb-Nocache
X-TT-LOGID
Cache
X-Fastly-Backend-Reqs
Wpo-Cache-Message
X-Acquia-Purge-Tags
X-Acquia-Site
Ngx-Var-Key
MIME-Version
PICS-Label
Wpo-Cache-Status
X-Acquia-Application-UUID
X-CUA
X-EC-Lua
X-Via-Ucdn
X-Acquia-Application-Trace
X-Varnish-Beresp-TTL
X-UA
X-Iplb-Request-Id
X-Iplb-Instance
Yjs-Id
Ngx
X-Gamma-Serve
X-RAMCache
X-Miniprofiler-Ids
Warning
X-WA
My-App
Mime-Version
X-GoCache-CacheStatus
X-Scheme
X-GeoIP-City
X-CF-Cache-Header-Vary
CACHE-MISS-TO-ORIGIN
Cneonction
Inserted-Into-Cache-At
X-Fastly-Cache-Hits
X-Snapshot-Date
X-Udemy-Cache-App-Namespace
Log-Origin
X-CF-Cache-Header-Cache-Control
Vha6-Origin
X-ElasticPress-Query
X-Cached-Since
X-Litespeed-Cache-Control