Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-Cache-Status
Link
Accept-Ranges
CF-RAY
ETag
X-XSS-Protection
Expect-CT
Pragma
X-Powered-By
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
Alt-Svc
X-Served-By
X-Xss-Protection
X-Download-Options
X-Timer
X-Request-Id
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Cache-Status
X-Check
X-Generator
X-Cacheable
Timing-Allow-Origin
X-Content-Security-Policy
X-Iinfo
Feature-Policy
Status
X-Envoy-Upstream-Service-Time
Content-Encoding
Access-Control-Expose-Headers
P3p
X-Drupal-Dynamic-Cache
X-Request-ID
X-CDN
X-AspNetMvc-Version
Upgrade
X-Via
CF-Ray
X-Ws-Request-Id
Access-Control-Max-Age
Server-Timing
EagleId
X-Cache-Group
X-Turbo-Charged-By
Keep-Alive
Request-Context
Report-To
X-UA-Device
X-Age
X-Backend
X-Server-Powered-By
X-Proxy-Cache
X-AH-Environment
X-Robots-Tag
X-Hacker
X-Amz-Request-Id
X-Server
Host-Header
X-Amz-Id-2
Grace
X-LiteSpeed-Cache
X-Rq
X-Nginx-Cache-Status
X-Swift-CacheTime
X-Swift-SaveTime
X-Varnish-Cache
Ali-Swift-Global-Savetime
X-WebKit-CSP
X-Page-Speed
NEL
X-Vhost
EagleEye-TraceId
X-Ua-Compatible
X-Amz-Version-Id
X-Dns-Prefetch-Control
X-Pingback
X-OneAgent-JS-Injection
X-Dispatcher
X-Device
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Cache-Spec
X-Host
Accept-CH
X-Server-Id
Cf-Railgun
X-Node
X-Backend-Server
X-Readtime
Surrogate-Control
X-Akam-SW-Version
Request-Id
X-Response-Time
X-HW
Xkey
X-Application-Context
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Content-Location
Rating
X-Country
Accept-CH-Lifetime
X-Cloud-Trace-Context
X-Ruxit-JS-Agent
X-B3-TraceId
Accept-Ch-Lifetime
X-Cache-Lookup
X-Trace
X-Url
X-Ac
X-Content-Type
X-Vname
X-TtlSet
X-PC
Allow
X-Clacks-Overhead
X-Mod-Pagespeed
Edge-Control
X-Varnish-TTL
X-Server-Name
X-ESI
Fastly-Restarts
X-Aws-Lambda-Call-Status
Cache-Tag
X-FastCGI-Cache
Service-Worker-Allowed
X-VARITI-CCR
X-Rack-Cache
Verso
X-Element-Page-Cache
X-Upstream
MS-Author-Via
X-Vcap-Request-Id
X-MS-InvokeApp
X-GitHub-Request-Id
X-Amz-Rid
Public-Key-Pins
X-Dw-Request-Base-Id
X-Cached
X-Client-IP
X-D2id
X-Abt-Application-Version
X-Cnection
X-Px
RTSS
X-Cache-TTL
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-Navigation-Version
X-Country-Code
Arr-Disable-Session-Affinity
X-Kinja-Build
X-Kinja
X-GoogleNews-Bot
Access-Control-Request-Method
X-Exp-Id
X-Kinja-Server
X-Kinja-Revision
X-Exp-Variant
X-Cdn-Fetch
X-Use-Magma
X-Powered-By-Plesk
X-Goog-Hash
X-NF-Request-ID
X-Instrumentation
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Powered-CMS
AR-ATIME
AR-SID
AR-PoweredBy
AR-Request-ID
AR-CACHE
X-Origin-Cache
X-Middleton-Display
Display
X-Sol
Pagespeed
X-Version
X-Middleton-Response
Response
X-TTL
X-LLID
X-Amz-Server-Side-Encryption
X-MSEdge-Ref
X-Kinsta-Cache
X-Edge-Location-Klb
Nginx-Cache
TCN
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Edge
Mrf-Cache-Status
X-B3-TraceId-Primal
MRF-Tech
X-RateLimit-Remaining
X-Protected-By
X-T
X-HP-Webp
X-Jurisdiction
X-HP-Trace-Id
X-Forwarded-For
X-Shield-Request-Id
X-Content-Security-Policy-Report-Only
X-Aspnetmvc-Version
X-Id
X-Mg-S
Accept-Ch
S
Content-MD5
Edge-Cache-Tag
X-Ruxit-Js-Agent
X-CST
X-Language
SPIisLatency
SPRequestDuration
Fastcgi-Cache
Front-End-Https
X-Mid
Realpath
X-Request-Received
X-Recruiting
X-Request-Processing-Time
Server-Node
X-DynaTrace
Filters
Pinterest-Generated-By
Pinterest-Version
X-Pinterest-Rid
X-Frontend
Server-Name
X-Content
X-Ua-Browser
X-Ab
X-MCACHE
X-Ser
X-Cache-Key
X-Ttl
X-HS-Cache-Config
X-HS-Hub-Id
X-HS-Content-Id
X-NWS-LOG-UUID
X-HS-Combine-CSS
X-Yandex-Sdch-Disable
X-Template
X-Correlation-Id
X-ECACHE
X-Ezoic-Cdn
X-SharePointHealthScore
SPRequestGuid
X-Hits
X-Parallel-Accel
X-Tt-Trace-Tag
X-Tt-Trace-Host
MicrosoftSharePointTeamServices
Alternate-Protocol
Cache-Tags
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
Charset
X-Page-Id
Fusion-Content-Source
Fusion-Component-Id
Fusion-Deployment-Id
Host
X-B3-Sampled
Fusion-Template-Id
Fusion-Source
Fusion-Content-Id
Cleartype
X-Www-Served-By
X-Content-Options
X-Git-Hash
X-Geo-Country
X-Debug-Info
X-Hostname
X-DIS-Request-ID
X-Daa-Tunnel
X-Amzn-Trace-Id
X-Content-Digest
X-Amz-Replication-Status
Filterid
X-Varnish-Age
X-Ratelimit-Limit
Cross-Origin-Opener-Policy
X-Az
X-AppVersion
X-Activity-Id
X-Upgrade-Enabled
X-FB-Debug
X-Grace
X-VCache
X-Accel-Expires
X-Nginx-Upstream-Cache-Status
X-N
X-Forwarded-Proto
ServerID
X-F-Cache
X-Origin-Server
X-Rid
Access-Control-Allow-Method
X-Mobile-URL
X-Fastly-Request-Id
TP-Cache
TP-L2-Cache
X-Type
X-LB-Cache
X-Server-ID
X-Providence-Cookie
X-Request-Guid
X-Route-Name
X-Whom
X-Is-Crawler
X-Flags
X-Aspnet-Duration-Ms
X-TT
X-App-Environment
X-Goog-Metageneration
X-GUploader-UploadID
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Seen-By
X-Goog-Generation
X-WebKit-CSP-Report-Only
Viewport
Payment
X-Tb
X-FW-Static
Node
X-FW-Serve
X-FW-Dynamic
X-Varnish-Grace
X-FW-Server
X-FW-Hash
X-Distributor
X-FW-Type
Paypal-Debug-Id
DC
X-User-Agent
X-XRDS-LOCATION
X-Oneagent-Js-Injection
X-App-Server
X-Fastly-Request-ID
X-Wix-Request-Id
Country
Fastcgi-Useragent
X-DataDome
Accept-Charset
X-Cache-Control
X-NGENIX-Cache
X-Litespeed-Cache
X-Cache-Rule
X-Fastcgi-Cache
X-Tec-Api-Version
X-Tec-Api-Root
X-Tec-Api-Origin
X-Ratelimit-Reset
X-Origin-Upstream-Status
X-Webkit-CSP
X-Webkit-Csp
Version
X-Via-JSL
X-Drupal-Cache-Tags
Referer-Policy
X-Microsite
X-Request-Handler-Origin-Region
X-Logged-In
X-Cluster-Name
X-Buckets
X-Cache-Age
X-Contextid
X-B-Cache
X-Signature
Cache-Status
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
Refresh
X-Browser-Type
X-Node-Name
SD-X-WS
X-Load-Cache
VIX-Pulpo-Upstream-Status
X-Varnish-Backend
VIX-Pulpo-Node
X-Original-Request-Id
X-Mobile
X-Response-Served-From
X-Vgn-Hpd-Reason
X-Is-Bot
X-Rendered-As
X-Cache-Expired-At
X-Real-IP
X-Debug
NGB
X-Revision
Access-Control-Request-Headers
X-B
X-IPLB-Instance
Amp-Access-Control-Allow-Source-Origin
X-Proxy-Cache-Status
X-Page-View
X-Jobs
X-UUID
X-Proxy
X-Yottaa-Metrics
X-Instance
X-Cache-Action
X-Rule
X-ProcessESI
X-Cacheable-TTL
X-Yottaa-Optimizations
X-Device-Type
X-RemovedCookies
Surrogate-Key
X-Drupal-Cache-Contexts
Akamai-GRN
X-Debug-IsPreview
X-Framework
X-Debug-IsConnected
X-Cache-Time
X-G
X-FW-Version
X-Air-Source
X-Air-Trace-Id
X-Air-Hostname
SID
X-Oracle-Dms-Ecid
X-Oracle-Dms-Rid
X-XRDS-Location
CF-IPCountry
X-Accel-Buffering
DynaTrace
X-PressLabs-Stats
X-Azure-Ref
X-Nginx-Cache
X-Source
Count-Hit
Liferay-Portal
X-Cache-NGX
GEO-INFO
X-Ms-Request-Id
X-Presslabs-Stats
X-Ms-Version
Uber-Trace-Id
X-Cache-Operation
Frame-Options
X-RTag
Ms-Operation-Id
X-Zen-Fury
X-CDN-Forward
MS-CV
X-EdgeConnect-Cache-Status
X-APP-VERSION
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
Healthy
X-RateLimit-Limit
X-Cache-Hit
X-Environment-Context
Xserver
X-Backend-Name
X-L-Path
Countrycode
X-Mode
Protected
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Tumblr-User
X-IPS-LoggedIn
X-Varnish-Server
Ec-Rule-Version
X-Tumblr-Pixel-1
Cross-Origin-Window-Policy
X-Cache-TTL-Remaining
LB
X-Ratelimit-Remaining
Backend
X-Hyper-Cache
X-Tid
X-JoinUs
X-SaId
X-Servername
X-Adobe-Loc
X-Adobe-Content
X-Region
X-Detected-As
Meta-Geo
X-Content-Age
X-Rewrite-Enabled
X-UPSTREAM-Address
X-Forwarded-Host
X-RN-RSRV
X-Alternate-Cache-Key
X-Generation-Time
Decoy-Debug-Status
X-Routing-Service
Eomportal-Instance
X-Zipkin-Id
WPO-Cache-Status
X-Format
X-Sorting-Hat-ShopId
Decoy-Debug-Key
X-Sorting-Hat-PodId
X-Shopify-Stage
Section-Io-Cache
X-Proxied
X-Cache-Server
X-Debug-Cache
X-ShardId
X-ShopId
X-Uri
X-Sql-Duration-Ms
Apigw-Requestid
X-Hosted-By
WPO-Cache-Message
X-Extlb
X-Redis-Cache
Decoy-Debug-TTL
X-Sql-Count
Country-Code
X-Human
Content-Disposition
Cache-Name
X-FB-TRIP-ID
X-Section
X-NCache
X-Via-Fastly
X-Status
X-Origin-Date
X-Cache-Grace
X-No-Session
X-Varnish-Beresp-Grace
X-Site-Version
X-PHP-Backend
X-ApacheServer
X-Access
Mn-Server-Ip
X-PCL
X-ServerID
X-OCL
X-PERF
X-Microcachable
Fastly-SSL
Url
X-Content-Powered-By
TWC-Privacy
TWC-Locale-Group
X-UA-Device-Type
Webcakes-App-Version
X-Akamai-Edgescape
Webcakes-Region
Webcakes-App-Name
TWC-GeoIP-Country
CDN-Cache
CDN-CachedAt
CDN-EdgeStorageId
Property-Id
Selected-Fe
TWC-Device-Class
TWC-Connection-Speed
X-Timing-Wait
X-BYPASS-REASON
X-ProxyCache-Key
X-ProxyCache-Status
X-Pubstack
X-Proxy-Build
X-Origin-Hint
X-Trace-Id
X-NYM-Debug-Backend
X-Say-Cacheable
X-Say-TTL
X-Cache-Host
CDN-PullZone
X-Cache-Type
X-Server-W
X-Cluster-Node
X-SayCDN-TTL
X-Storage
TWC-GeoIP-LatLong
CDN-RequestId
CDN-RequestCountryCode
Cache-Tv-Group
CDN-Uid
X-Web-Node
X-Soup
X-R9-Blue-Green-Version
X-NewRelic-App-Data
X-Hl-Ver
X-Be
X-Generated-By
X-Varnishpool
Azure-Version
Azure-SlotName
Azure-SiteName
Azure-InstanceId
Content-Secure-Policy
Azure-RegionName
X-Azure-Ref-OriginShield
X-Ua
X-LSADC-Cache
DB-Nickname
X-TIME
OT-Force-Account-Verify
X-Nginx-Cache-Key
Retry-After
X-Cached-By
X-Dc
Source
X-TT-LOGID
X-Bc-Bl
X-Unique-Id
Cache
X-Cache-Remote
SRV
X-Akamai-Transformed
X-Platform-Server
X-Auto-Login
X-LAGOON
X-Xfnlog-Site
X-Cdn
HostName
Upgrade-Insecure-Requests
X-Origin-CC
X-Origin-TTL
X-GEO
Cache-Hits
X-Varnish-Hits
X-Correlation-ID
ServedBy
X-EC-Lua
X-SRV
X-Cache-Tags
X-Loop
X-Varnish-Hostname
X-TNCMS
X-App-Version
X-S-Maxage
X-CSRF-Token
Xet-Cookie
X-Varnish-Cache-Hits
Onion-Location
X-Request-Time
X-HTML-Minification-Powered-By
From-Origin
X-Time
X-AOL-HN
Mime-Version
X-Request-Host
Web-Mar-Node
WP-Super-Cache
X-Tumblr-Pixel-2
X-Amz-Meta-S3cmd-Attrs
Webserver
X-Tumblr-Pixel-3
X-ECache
X-Proto
N-Cache
X-NWS-UUID-VERIFY
X-Tenant
X-FireWall-Port
X-Cache-Enabled
X-Endurance-Cache-Level
X-VWS-Id
X-Handled-By
Nel
X-AWS-Id
X-LJ-Flow-ID
X-GG-Cache-Date
X-Time-Microsecs
X-Origin-Response-Time
Rendered-Blocks
X-Vdms-Version
X-VG-WebCache
Pramga
X-B3-SpanId
X-ND-Cache
DCR-Processing-Time-Ms
Redirect-Candidate
X-Forwarded-Path
X-Epic-Correlation-Id
X-Developer
A
DCR-Decision-By
BehaviorPad-Version
X-NAPM-TraceId
Sslversion
X-Vdms-Path
X-External-Request-Id
X-CF-Lambda-Version
Fastcgi-X-Cache-Version
X-Vtex-Processado-Em
X-PBS-Appsvrname
Expiry
X-PAYTM-SRV-ID
Mobile-Detection-Method
X-Orig-Expires
Meta-Geo-Continent
X-Vtex-Remote-Cache
X-Planisys-CDN-Cache
User-Cache-Control
X-Ftr-Request-Id
X-Processor
X-Ig-Push-State
X-Gen-Mode
Odigeo-Trace-Id
X-Hnp-Log
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
Xc-Version
Surrogated-Key
X-D
X-Cache-Var
V-Age
X-B-Cookie
X-Edge-Location
X-ARC
X-SD-PageType
X-S-Cookie
X-Aicache-OS
X-Application
X-ScT
X-Backend-TTL
X-Connection-Hash
X-Ckpd-Fst-Backend
X-Slack-Backend
X-SRCache-Key
X-CF-Lambda-Fn
X-Cache-NE
X-Cluster
X-Session-Fingerprint
X-Shop-Environment
X-Conf
X-Block-Status
X-Aed
X-Cache-Var-Map
X-A-Dam
X-A-Dcw
X-A-Dgt
X-A-Ccd
Vix-Hermes-Req-Id
X-Destination
X-V-Cache
X-TIM-N
X-A
X-A-Wwc
X-Rojux
X-S
X-RCS-CacheZone
X-Adobe-Source
X-Magnolia-Registration
X-Reqid
X-MP-GENERATED-AT
X-Mg-Request-UUID
X-Li-Fabric
X-Cdn-Srv
Svr
Wxu-Next-Commit
X-LI-UUID
True-Client-Country-4JS
CDCHOST
Cmsid
DSUID
Cmstype
CacheControlHeader
X-Li-Pop
Fastcgi-Cache-TTL
X-GeoIP-Country-Code
Host-ID
X-GeoIP-Region-Code
X-Geo-Header
X-Forwarded-Site
Origin
X-Date
X-Accel-Expires-Debug
Gh-Request-Id
X-Hash
X-Cache-Bucket
State
X-Cache-Date
Wxu-Next-Hostname
X-Gdpr
X-Fastly-Cache
Wxu-Next-Region
X-Cache-Info
Apple-News-Services-Handled
X-Policy
X-SVT-ORM-RULES
X-Old-Content-Length
X-Scheme
Arc-Country
X-Nyt-Route
X-Sucuri-ID
X-Viewer-Country
X-Origin
X-VG-TLSProxy
X-Request-URI
X-Server-IP
X-Origin-Time
X-SVT-ORM-VERSION
X-Origin-Expires
X-Webstats-RespID
X-Proxy-Upstream
X-Sucuri-Cache
AKAMAI
X-Rocket-Nginx-Serving-Static
X-Location
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
CloudFront-Viewer-Country
Apple-News-Services-Request-Url
X-Men
X-Amz-Apigw-Id
X-Mvc-Supplant-Cachable
X-Labrador-Cache-Channel
X-Amzn-RequestId
X-NodeID
AMP-Access-Control-Allow-Source-Origin
X-PHP-Host
Environment
X-Via-NSCOPI
S-Rt
X-Varnish-Ttl
X-Varnish-Beresp-Ttl
X-Varnish-Beresp-Status
X-Device-Os
X-Envoy-Decorator-Operation
X-VarnishDD-TTL
X-Esi-Check
Traceparent
X-Developers
Web-Mar-Region
We-Hiring
X-Req
X-Rocket-Build-Number
X-UnsetCookies
X-Csrf-Jwt
X-Cache-Debug
X-Skip-Cache
X-Branch-Name
X-Sigma-Backend
X-Cache-Id
X-CGP
X-Sn-Servicetimems
X-Storefront-Renderer-Rendered
X-Cdn-Origin
X-Sigma
X-Core-Mission
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
X-Datadog-Trace-Id
X-Served-From
X-TH-Server
X-BBC-Edge-Cache-Status
X-Core-Value
X-Eu-Site
X-TrackingId
Server-Host
X-Region-Sid
X-VServer
X-Generated-On
X-Owner
Fastly-Drupal-Html
X-Platform
X-Gamma-Serve
Origin-EX
Origin-CC
X-GeoIP
X-GeoIP-City
HA-Ipaddr
Ha-Gx-Prefs
X-Gzip
L
L5d-Success-Class
Mail-Subject
Machine
Locid
PFcat
Fastly-GeoIP-CountryCode
X-Fastly-Backend
X-Irp-Debug
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Level-Front-Cache
Ssr
X-Locale
X-HS-Content-Campaign-Id
Server-Info
X-HN
X-Fetched-On
Release
Req-Svc-Chain
X-Xrds-Location
Magicmarker
X-Loc
X-Worker
X-NU-AKA-ACS-Version
X-Has-Esi
X-Is-Gdpr
X-Node-Id
X-JWT-State
X-Thinkindot-L3
X-Varnish-CookieINHashed-On
X-Varnish-CookieHashed-On
X-Varnish-Remaining-TTL
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-DPWN-IS-SECURE
X-FC-Vary-Parameters
X-Variation
X-Qloud-Router
X-Response-By
X-Request-Start
X-DefElseHash
X-DefHash
X-Pod-Name
X-Amzn-Remapped-Content-Length
Thinkindot-CacheControl
Platform
Thinkindot-CacheControl-Type
Thinkindot-Control
Cf-Device-Type
NM-Fastcgi-Cache
Memcached
Fastly-SIE
X-Akamai-Request-ID2
Fastly-SWR
X-Http-Reason
Is-Eu
Adler-Geo
TDXMobile
X-ATG-Version
X-Backend-State
X-M-Reqid
X-M-Log
X-Ua-Device
X-Qnm-Cache
X-VC-Cache
X-Bip
X-CS
X-Restarts
X-Thanos
NGX
X-Tx-Id
X-Zone
X-API-Version
X-Mvc-Supplant-OutputCached
Kp-EeAlive
X-Up
X-LB-ID
X-Action
X-DB
X-Wix-Viewer-Type
X-DW
X-RPM
X-Trace-ID
X-Cache-Config
X-Cache-Backend
CDN
X-LB-NoCache
X-RSL
X-RPS
X-Generated-In
X-DI
X-NC
Pics-Label
X-DSS
Ms-Author-Via
X-TraceId
Accept-Language
Edge-Cache
Time
Memory
X-Srv
X-Tb-Optimization-Total-Bytes-Saved
Env
X-Via-Popn
X-CacheTTL
X-Via-Poph
X-Refresh
X-Via-Popv
WebServer
X-Edge-Pop
X-Datadome
X-Optimistic-Header
X-Minions-Version
X-Tt-Logid
Datacenter
Candidate-Md5Url
X-HA-Backend
NtCoent-Length
X-Cache-Ttl
X-CACHE-KEY
X-Urbn-Context-Path
X-Urbn-Site-Id
GeoIp-Country-Code
Locale
X-DC
X-ZONE
X-DynaTrace-JS-Agent
X-Esi
X-Vc
On-Server
X-Servedbyhost
Server-ID
WWW-Authenticate
X-Ec-GeoHdr
X-TX-ID
X-MSEdge-Features
X-Ec-Fail
X-MSEdge-Flight
Esi-Enabled
X-Unique-ID
X-User
X-CLOUD-TRACE-CONTEXT
X-Cs
X-Parent-Response-Time
X-TA-CDN-Provider
X-Service
X-Varnish-Beresp-TTL
C-Via
X-Cache-PHP
X-Webkit-CSP-Report-Only
X-Newrelic-Synthetics
X-B3-Spanid
X-LI-Proto
X-App
X-Fpc
X-VCL-Version
X-AK-Request-ID
Cdnsip
X-Traceid
Cdncip
X-URL
X-Dynatrace
X-Li-Proto
Test
X-Clara-WADP
X-Fmm-Version
X-Webkit-Csp-Report-Only
X-WADP-Cache
My-App
Cluster
Proxy-Connection
X-Cache-Status-Check
X-Render-Time
Geo-Info
X-FPC
Geoip-Latitude
Cf-Int-Pingora-Origin-Digest
X-CUA
X-Vcl-Version
Tracecode
X-NODE
X-LiteSpeed-Cache-Control
X-Pass-Why
DataCenter
X-Var-Ttl
Lfy
T-Server
X-From
X-Mcache
Fastly-Drupal-HTML
Lang
X-Fragments
M-TraceId
Resin-Trace
X-VC
Server-Id
Target-Params
MIME-Version
X-CSRF-TOKEN
X-B3-Traceid
X-Ha-Backend
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
X-ID
X-Geo
GeoIP-Country-Code
X-Clientip
Hostname
X-RAMCache
HIT
UCS
Hit
Cache-Host
X-Oss-Request-Id
X-AIR-PT
X-Oss-Server-Time
X-Info
X-ServedByHost
X-Oss-Storage-Class
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
X-LiteSpeed-Tag
X-Provided-By
X-Dynatrace-Js-Agent
X-Via-PopN
X-Via-PopV
Permissions-Policy
X-Proxy-Cache-Info
X-Pad
X-Httpd
X-Edge-POP
X-Cdn-Forward
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
Section-Origin-Responded
ENV
Section-Io-Id
X-Via-PopH
S-Cnection
Producers
Servername
X-Edge-Cache
X-NGINX-Cache
X-Api-Version
X-Check-Cacheable
Ohc-File-Size
X-Fastly-Backend-Reqs
X-Ucs
X-Micro-Cache
X-HS-Status
X-SB
WZWS-RAY
User-Agent
Fastly-Backend-Name
X-ElasticPress-Query
X-ServerName
X-BBC-Origin-Response-Status
FSS-Cache
X-Udemy-Cache-App-Namespace
Load-Balancing
X-GoCache-CacheStatus
X-Release
X-Backend-Host
URI
PICS-Label
X-Lb-Nocache
Cf-Ipcountry
ServerName
X-UP
X-Platform-Cluster
X-Platform-Processor
X-Pool
X-Cache-CFC
Uri
X-Acquia-Purge-Tags
X-Acquia-Site
X-Nc
X-Acquia-Application-Trace
X-Acquia-Application-UUID
X-Platform-Router
X-TRACE-ID
Cneonction
X-Scale
X-BCube-Filmed-By
X-Swift-Error
X-RateLimit-Reset
EpKe-Alive
Cteonnt-Length
X-Cdn-Request-ID
Server-Ttl
X-Fastly-Cache-Hits
Cdn
X-APP
X-Lb-Id
Tcn
X-Dw-Trace-Id
X-B3-Parentspanid
X-Cache-Expires
Sever-Int
X-Contensis-Viewer-Groups
CF-Cached-On
X-Ec-Custom-Error
X-Vcache
X-Cache-ASPX
X-Newrelic-App-Data
X-Dispatcher-Number
Shield-Pop
X-Yottaa-OS
Server-Hostname
Wpo-Cache-Message
X-B3-ParentSpanId
MD5-Digest
X-Akamai-ERRuleID
X-SIPLIST1
X-Akamai-ERPolicy
Wpo-Cache-Status
Server-Ext
X-Snapshot-Date
Path
Ohc-Cache-HIT
Vha6-Origin
IsBot
X-Air-Pt
Sid
X-HostName
X-Cache-Ngx
X-Litespeed-Cache-Control
X-Via-Ucdn
GeoIP-Latitude
X-IN-APIGATEWAYSSL
X-Akamai-Request-ID
X-IN-APIGATEWAY
X-Shopify-Generated-Cart-Token
CPC-Cache
X-WA-Info
X-CacheKey
X-UA
X-WA
X-Akamai-Pragma-Client-IP
X-Varnish-Authentication
X-Apw-Access-Action
X-Apw-Hits
X-Apw-Access-Token
X-Apw-Access-Object
X-Logging-Id
Req-ID
CountryCode
X-Http-Duration-Ms
X-Http-Count
X-Te-Count
X-Te-Duration-Ms
X-Amz-Meta-Cb-Modifiedtime
VNS-Cache
VNS-Age
X-Sentry-ID
Cache-Key
Ngx
CPC-Age
X-Last-Modified