Threat Level: green Handler on Duty: Daniel Wesemann

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-Cache-Status
Accept-Ranges
Link
CF-RAY
ETag
Pragma
Expect-CT
X-Powered-By
X-XSS-Protection
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Report-To
NEL
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
Alt-Svc
X-UA-Compatible
P3P
X-Xss-Protection
X-Served-By
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Varnish
X-Request-Id
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
X-Runtime
X-AspNet-Version
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Cache-Status
X-Generator
X-Check
X-Cacheable
Timing-Allow-Origin
X-Request-ID
X-FRAME-OPTIONS
Feature-Policy
X-Iinfo
X-Content-Security-Policy
X-Envoy-Upstream-Service-Time
Content-Encoding
P3p
Status
X-CONTENT-TYPE-OPTIONS
X-CDN
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
X-AspNetMvc-Version
Upgrade
X-Via
X-XSS-PROTECTION
CF-Ray
X-Ws-Request-Id
Access-Control-Max-Age
Server-Timing
X-Cache-Group
X-Turbo-Charged-By
X-Backend
EagleId
Keep-Alive
Request-Context
X-Age
X-Robots-Tag
X-Server
X-AH-Environment
X-UA-Device
Host-Header
X-Proxy-Cache
X-Amz-Request-Id
X-Amz-Id-2
X-Hacker
X-Dns-Prefetch-Control
Grace
X-Rq
X-Swift-CacheTime
X-Swift-SaveTime
X-Server-Powered-By
X-Varnish-Cache
Ali-Swift-Global-Savetime
X-Vhost
X-Amz-Version-Id
X-Ua-Compatible
CONTENT-SECURITY-POLICY
X-LiteSpeed-Cache
X-Dispatcher
EagleEye-TraceId
X-WebKit-CSP
X-Nginx-Cache-Status
X-Akamai-Path-Stats
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-OneAgent-JS-Injection
X-Cache-Spec
Cf-Railgun
X-Device
X-Page-Speed
Allow
X-Host
X-Node
X-Pingback
X-Aws-Lambda-Call-Status
X-Server-Id
Surrogate-Control
X-CST
X-Backend-Server
Request-Id
Accept-CH
X-Akam-SW-Version
X-Readtime
X-HW
X-Cache-Lookup
X-Response-Time
X-Application-Context
Xkey
Content-Location
X-ASPNET-VERSION
X-Cloud-Trace-Context
Accept-CH-Lifetime
Rating
X-Trace
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
Cf-Edge-Cache
X-Url
Accept-Ch-Lifetime
X-Country
Fastly-Restarts
X-Ruxit-JS-Agent
X-Mod-Pagespeed
X-PC
X-Vname
X-TtlSet
X-MS-InvokeApp
X-Rack-Cache
X-Varnish-TTL
X-Server-Name
X-Clacks-Overhead
Edge-Control
RTSS
X-ESI
X-Content-Type
X-B3-TraceId
X-VARITI-CCR
Accept-Ch
Cache-Tag
X-Vcap-Request-Id
X-Amz-Rid
X-Px
X-Kinja-Revision
X-Kinja-Build
X-Kinja
X-GoogleNews-Bot
X-Kinja-Server
X-Use-Magma
X-Cdn-Fetch
X-Exp-Id
X-Exp-Variant
X-Ac
Public-Key-Pins
X-Dw-Request-Base-Id
X-Cnection
X-Amz-Server-Side-Encryption
X-Element-Page-Cache
X-D2id
Verso
X-Navigation-Version
X-Cache-TTL
X-Abt-Application-Version
X-RateLimit-Remaining
X-Client-IP
X-Powered-By-Plesk
Service-Worker-Allowed
Display
X-Middleton-Display
Pagespeed
X-Sol
X-Ser
X-Version
X-GitHub-Request-Id
X-Country-Code
Arr-Disable-Session-Affinity
X-Edge
X-TTL
Response
X-Middleton-Response
Access-Control-Request-Method
X-FastCGI-Cache
X-NF-Request-ID
X-Goog-Hash
X-Ruxit-Js-Agent
X-Correlation-Id
X-Upstream
AR-PoweredBy
AR-Request-ID
AR-ATIME
AR-SID
AR-CACHE
X-Webkit-Csp
X-Kinsta-Cache
X-Edge-Location-Klb
SPRequestDuration
SPIisLatency
X-Cached
X-LLID
X-Cache-Key
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-NWS-LOG-UUID
X-Instrumentation
Nginx-Cache
X-Litespeed-Cache
X-Powered-CMS
Edge-Cache-Tag
MS-Author-Via
TCN
X-RateLimit-Limit
X-Ttl
SPRequestGuid
X-SharePointHealthScore
MRF-Tech
Mrf-Cache-Status
X-Forwarded-For
X-MSEdge-Ref
Content-MD5
X-Id
X-Shield-Request-Id
X-Content-Security-Policy-Report-Only
X-B3-TraceId-Primal
X-T
X-Daa-Tunnel
X-Recruiting
X-Mg-S
S
X-Ua-Device
X-Content-Digest
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Protected-By
X-HP-Trace-Id
X-Jurisdiction
X-HP-Webp
X-DataDome
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Frontend
X-Ezoic-Cdn
X-HS-Cache-Config
X-HS-Hub-Id
X-HS-Content-Id
X-Yandex-Sdch-Disable
MicrosoftSharePointTeamServices
X-Ua-Browser
X-HS-Combine-CSS
X-Content
X-Ab
Server-Node
Front-End-Https
Filters
X-Accel-Expires
X-Request-Processing-Time
X-Request-Received
X-Grace
X-Server-ID
X-ECACHE
Fastcgi-Cache
X-Mid
X-Geo-Country
X-ORACLE-DMS-ECID
X-Hits
X-ORACLE-DMS-RID
X-Pinterest-Rid
Pinterest-Generated-By
Pinterest-Version
X-Origin-Server
X-PressLabs-Stats
X-Distributor
X-Debug-Info
TP-Cache
TP-L2-Cache
X-Ratelimit-Reset
X-Amzn-Trace-Id
X-Tt-Trace-Host
X-Tt-Trace-Tag
Charset
X-Page-Id
Cleartype
Host
X-F-Cache
X-B3-Sampled
X-DIS-Request-ID
Cross-Origin-Opener-Policy
X-Www-Served-By
X-Git-Hash
X-DynaTrace
Cache-Tags
X-Forwarded-Proto
X-LB-Cache
X-Cache-Age
ServerID
Access-Control-Allow-Method
X-Seen-By
X-Oracle-Dms-Ecid
X-Kong-Proxy-Latency
X-Language
X-Request-Handler-Origin-Region
X-Microsite
X-Kong-Upstream-Latency
X-Aspnetmvc-Version
X-Cluster-Name
X-MCACHE
Server-Name
X-AppVersion
X-Az
X-Activity-Id
X-Oracle-Dms-Rid
X-Varnish-Age
Accept-Charset
Realpath
Cache-Status
Filterid
X-Rid
X-Type
X-Fastcgi-Cache
X-Content-Options
X-Mobile-URL
X-App-Environment
X-Origin-Cache
X-WebKit-CSP-Report-Only
X-Via-JSL
X-Upgrade-Enabled
X-Varnish-Grace
X-FB-Debug
Node
X-User-Agent
X-Fastly-Request-ID
X-Tb
Viewport
X-Wix-Request-Id
Country
X-Signature
X-Route-Name
X-Providence-Cookie
X-Is-Crawler
X-Request-Guid
X-Whom
X-Drupal-Cache-Tags
X-B-Cache
X-Aspnet-Duration-Ms
X-Flags
Protected
X-TT
X-Goog-Storage-Class
X-Nginx-Upstream-Cache-Status
DC
Paypal-Debug-Id
X-Goog-Generation
X-Goog-Metageneration
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-VCache
X-GUploader-UploadID
X-NWS-UUID-VERIFY
Fastcgi-Useragent
X-Varnish-Backend
Retry-After
X-XRDS-LOCATION
X-Cache-NGX
X-Contextid
Payment
X-Amz-Replication-Status
X-B
X-Debug
X-N
X-Template
X-Logged-In
X-XRDS-Location
WPO-Cache-Status
WPO-Cache-Message
X-FW-Hash
X-FW-Static
X-FW-Type
X-FW-Dynamic
X-FW-Server
X-FW-Serve
X-Fastly-Request-Id
X-Load-Cache
Surrogate-Key
Amp-Access-Control-Allow-Source-Origin
X-Cache-Control
X-Hostname
X-Parallel-Accel
Count-Hit
X-Browser-Type
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Node-Name
X-Response-Served-From
X-Original-Request-Id
SD-X-WS
Healthy
Akamai-GRN
X-Jobs
X-Is-Bot
X-Zen-Fury
X-Cache-Time
X-Akamai-Request-ID2
X-UUID
VIX-Pulpo-Node
Uber-Trace-Id
X-Revision
VIX-Pulpo-Upstream-Status
X-Rendered-As
X-G
X-Amz-Meta-S3cmd-Attrs
X-Http-Reason
X-Cache-TTL-Remaining
Refresh
X-Page-View
X-Real-IP
X-Proxy
NGB
X-Debug-IsPreview
X-Yottaa-Optimizations
X-Device-Type
Content-Disposition
X-Cacheable-TTL
X-Debug-IsConnected
Alternate-Protocol
X-Proxy-Cache-Status
X-Drupal-Cache-Contexts
X-Yottaa-Metrics
X-Instance
X-Mobile
X-Framework
X-Adobe-Loc
Access-Control-Request-Headers
X-Cache-Rule
X-Adobe-Content
X-IPLB-Instance
X-Vgn-Hpd-Reason
X-Trace-Id
X-Source
Url
From-Origin
X-Servername
X-B3-Traceid
Version
X-Cache-Grace
X-Cache-Expired-At
X-Oneagent-Js-Injection
X-Mcache
Accept-Language
Permissions-Policy
X-Varnish-Server
X-Cache-Hit
X-Environment-Context
Referer-Policy
X-L-Path
X-Ratelimit-Remaining
X-Mg-Request-UUID
X-App-Server
X-EdgeConnect-Cache-Status
Countrycode
X-FW-Version
X-RTag
MS-CV
X-Restarts
Ms-Operation-Id
X-Cache-Action
X-NGENIX-Cache
Cross-Origin-Window-Policy
X-IPS-LoggedIn
X-ECache
X-Tumblr-Pixel
X-COUNTRY
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
Backend
X-Tumblr-User
X-NYM-Debug-Backend
Liferay-Portal
X-ProcessESI
X-RemovedCookies
X-Nginx-Cache
CF-IPCountry
X-HTML-Minification-Powered-By
Frame-Options
Content-Secure-Policy
X-Hyper-Cache
X-RN-RSRV
X-PCL
X-OCL
Meta-Geo
WP-Super-Cache
Upgrade-Insecure-Requests
X-Rule
X-UPSTREAM-Address
Ec-Rule-Version
X-Access
X-Ua
X-Redis-Cache
X-Cluster-Node
Cache-Tv-Group
Apigw-Requestid
X-Section
Section-Io-Cache
X-Cache-Enabled
X-Format
X-Generation-Time
X-FB-TRIP-ID
X-Detected-As
X-Content-Age
X-Cache-Server
X-UA-Device-Type
X-Urbn-Context-Path
S-Rt
X-Storage
X-Sql-Count
X-Sql-Duration-Ms
X-Urbn-Site-Id
X-Varnish-Cache-Hits
Mn-Server-Ip
Property-Id
X-Web-Node
X-Akamai-Edgescape
X-Hosted-By
Locale
X-No-Session
Azure-RegionName
Azure-InstanceId
Azure-SiteName
Azure-SlotName
X-Request-Time
Azure-Version
X-PHP-Backend
X-Say-Cacheable
X-Origin-Date
Fastly-SSL
X-Server-W
X-SayCDN-TTL
X-Say-TTL
TWC-Connection-Speed
X-Uri
Webcakes-Region
Webcakes-App-Version
X-Region
X-AOL-HN
TWC-Device-Class
X-Unique-Id
X-Origin-Hint
X-TT-LOGID
Webcakes-App-Name
TWC-Locale-Group
TWC-GeoIP-Country
X-Be
X-Mode
TWC-Privacy
TWC-GeoIP-LatLong
X-Cache-Type
X-Cache-Tags
X-Debug-Cache
X-Cache-Host
X-BYPASS-REASON
X-Platform-Server
CDN-EdgeStorageId
CDN-RequestId
CDN-Uid
X-ProxyCache-Key
CDN-RequestCountryCode
CDN-PullZone
CDN-Cache
CDN-CachedAt
Eomportal-Instance
X-ProxyCache-Status
X-Xfnlog-Site
X-Webkit-CSP
X-Forwarded-Host
X-ApacheServer
Webserver
X-Human
X-Nginx-Cache-Key
X-PERF
X-Site-Version
X-Content-Powered-By
X-Generated-By
X-Status
X-Hl-Ver
X-Alternate-Cache-Key
X-Proxied
X-Backend-Name
X-Extlb
X-JoinUs
X-ServerID
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Tid
X-Zipkin-Id
X-Varnishpool
X-ShopId
X-Shopify-Stage
X-Routing-Service
X-SaId
X-ShardId
X-Via-Fastly
X-Cache-Operation
X-Adobe-Source
X-Accel-Buffering
X-Handled-By
X-Proxy-Build
X-NewRelic-App-Data
ServedBy
Selected-Fe
X-Timing-Wait
X-Ratelimit-Limit
X-Cache-Remote
X-GG-Cache-Date
X-PHP-Host
X-Datadome
X-Labrador-Cache-Channel
X-Rewrite-Enabled
X-Locale
Xserver
X-APP-VERSION
X-VWS-Id
X-LJ-Flow-ID
X-LSADC-Cache
X-AWS-Id
SID
X-VC-Cache
SRV
X-Pubstack
X-Cached-By
X-App-Version
X-Buckets
X-CDN-Forward
X-Soup
X-Dc
Fastly-Drupal-Html
LB
Mime-Version
Country-Code
X-Proto
Web-Mar-Node
X-Edge-Location
Decoy-Debug-Status
X-Storefront-Renderer-Rendered
X-Request-Host
Decoy-Debug-TTL
Decoy-Debug-Key
X-GEO
X-Reqid
X-Microcachable
Onion-Location
X-Cms-Context
X-Varnish-Hostname
X-Origin-CC
Server-Info
X-Origin-TTL
X-Ms-Request-Id
X-TA-CDN-Provider
X-Ms-Version
Xet-Cookie
Cache-Hits
X-MP-GENERATED-AT
X-B3-SpanId
X-GeoCode
X-Cluster
X-CSRF-Token
Load-Balancing
X-GeoCountry
X-Varnish-Hits
X-SRV
DynaTrace
X-Tumblr-Pixel-2
X-Tumblr-Pixel-3
X-Bc-Bl
X-NCache
X-Air-Hostname
X-Air-Trace-Id
X-Air-Source
X-Amz-Apigw-Id
X-Amzn-RequestId
Cache-Name
X-Varnish-Beresp-Grace
X-R9-Blue-Green-Version
X-Midtier
X-Endurance-Cache-Level
X-Envoy-Decorator-Operation
X-Origin-Response-Time
X-Tx-Id
X-Azure-Ref
X-RCS-CacheZone
Expiry
Meta-Geo-Continent
X-SRCache-Key
Lang
X-Vdms-Path
Host-ID
X-User
Fastcgi-X-Cache-Version
DCR-Decision-By
X-TrackingId
Cdncip
BehaviorPad-Version
A
Cdnsip
Cmstype
X-Tenant
X-TIM-N
DB-Nickname
DCR-Processing-Time-Ms
Surrogated-Key
X-D
X-Connection-Hash
X-Destination
X-Developer
X-Ec-Fail
X-Conf
X-CF-Lambda-Version
X-Cache-Id
X-Cache-NE
X-Cdn-Srv
X-CF-Lambda-Fn
X-Ec-GeoHdr
X-Epic-Correlation-Id
X-HS-Content-Campaign-Id
X-Hash
X-Ig-Push-State
X-LAGOON
X-Processor
X-Gzip
X-Ftr-Request-Id
X-Esi-Check
X-External-Request-Id
X-Forwarded-Path
X-From
X-Cache-Bucket
X-Rojux
Sslversion
X-SD-PageType
X-PAYTM-SRV-ID
T-Server
X-ScT
Rendered-Blocks
Pramga
NM-Fastcgi-Cache
X-Shop-Environment
Odigeo-Trace-Id
X-Session-Fingerprint
X-S-Cookie
X-A
X-AK-Request-ID
X-Aed
X-Application
X-ARC
X-B-Cookie
X-S
X-A-Wwc
X-A-Ccd
X-A-Dam
X-A-Dcw
X-A-Dgt
Mobile-Detection-Method
Cmsid
X-NAPM-TraceId
X-Vtex-Remote-Cache
X-NodeID
X-PBS-Appsvrname
X-Men
X-Vtex-Processado-Em
X-Magnolia-Registration
Xc-Version
X-VG-WebCache
X-Vdms-Version
X-Orig-Expires
X-Webstats-RespID
X-Via-NSCOPI
X-DPWN-IS-SECURE
Fastly-GeoIP-CountryCode
X-Old-Content-Length
We-Hiring
X-Sigma-Backend
X-Cache-Backend
X-Fastly-Cache
Is-Eu
User-Cache-Control
X-Slack-Backend
Apple-News-Services-Handled
Apple-News-Services-Host
X-Device-Os
V-Age
X-Wix-Viewer-Type
Vix-Hermes-Req-Id
X-SB
X-Nyt-Route
Wxu-Next-Region
X-Node-Id
X-Core-Mission
X-Core-Value
X-Server-IP
Server-Host
X-Developers
State
X-Ckpd-Fst-Backend
X-Clara-WADP
Producers
Platform
Wxu-Next-Commit
X-Sigma
X-WADP-Cache
Memcached
X-DefHash
X-DefElseHash
Wxu-Next-Hostname
X-Cache-Info
X-Request-URI
Mail-Subject
X-Fetched-On
X-Planisys-CDN-Cache
X-Origin-Time
X-Mvc-Supplant-Cachable
X-V-Cache
X-Hnp-Log
X-TNCMS
X-Planisys-CDN-Rules
Environment
X-Amzn-Remapped-Content-Length
X-Viewer-Country
X-Irp-Debug
X-Variation
X-JWT-State
Apple-News-Services-Parsed-Url
X-Location
X-Loop
X-VG-TLSProxy
X-Is-Gdpr
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
Apple-News-Services-Request-Url
X-Has-Esi
X-Worker
X-SVT-ORM-VERSION
X-Planisys-CDN-TTL
X-Rocket-Build-Number
X-Block-Status
X-SVT-ORM-RULES
Web-Mar-Region
X-Fmm-Version
X-Gen-Mode
X-Gdpr
Adler-Geo
X-Origin-Expires
X-GeoIP
X-Geo-Header
X-Origin
CDN
Source
X-Pod-Name
X-Ec-Custom-Error
X-Auto-Login
X-Branch-Name
X-Cdn-Origin
X-Response-By
X-Rocket-Nginx-Serving-Static
X-BBC-Edge-Cache-Status
X-Cache-Date
X-RPM
X-RPS
X-Rebelmouse-Surrogate-Control
X-Proxy-Upstream
HostName
X-Qloud-Router
X-Forwarded-Site
X-RateLimit-Limit-Second
Locid
X-Gamma-Serve
X-Httpd
X-HN
X-Proxy-Cache-Info
X-GeoIP-City
X-RateLimit-Remaining-Second
X-Rebelmouse-Cache-Control
X-Datadog-Trace-Id
X-DB
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
X-Csrf-Jwt
X-DI
X-DSS
X-Eu-Site
X-Platform
X-RSL
X-DW
X-CGP
Traceparent
L
Machine
Kp-EeAlive
HA-Ipaddr
Gh-Request-Id
Ha-Gx-Prefs
N-Cache
Origin
Redirect-Candidate
Release
PFcat
Origin-EX
Origin-CC
X-Sn-Servicetimems
Fastly-SWR
X-Policy
X-Thinkindot-L3
X-VarnishDD-TTL
X-Minions-Version
X-Loc
X-VServer
AKAMAI
Fastcgi-Cache-TTL
Fastly-SIE
Cluster
CDCHOST
Cache
Req-Svc-Chain
L5d-Success-Class
Svr
TDXMobile
Thinkindot-CacheControl-Type
X-Aicache-OS
X-Scheme
Thinkindot-Control
Thinkindot-CacheControl
X-Time
X-CS
X-Tec-Api-Origin
X-Tec-Api-Root
X-Tec-Api-Version
X-Optimistic-Header
Arc-Country
X-Pool
X-Level-Front-Cache
X-Accel-Expires-Debug
X-EC-Lua
X-Generated-On
MD5-Digest
CloudFront-Viewer-Country
DSUID
Ssr
NGX
X-Date
X-Region-Sid
X-Skip-Cache
X-TIME
X-Served-From
X-TraceId
X-Parent-Response-Time
X-WP-CF-Super-Cache
X-VC
X-ZONE
X-Dispatcher-Number
Pics-Label
X-GeoIP-Country-Code
X-GeoIP-Region-Code
GEO-INFO
X-NC
X-Udemy-Cache-App-Namespace
X-CacheTTL
X-Akamai-Transformed
X-WP-CF-Super-Cache-Cache-Control
X-Srv
X-SIPLIST1
X-Owner
Server-Hostname
IsBot
X-API-Version
Env
Sever-Int
Servername
X-LB-NoCache
X-Via-Ucdn
X-Scale
X-Ah-Environment
Server-Ext
X-Tb-Optimization-Total-Bytes-Saved
Ms-Author-Via
X-Generated-In
Memory
Time
X-Refresh
X-Cache-Debug
AMP-Access-Control-Allow-Source-Origin
X-Mvc-Supplant-OutputCached
Fusion-Content-Source
X-Newrelic-Synthetics
Fusion-Content-Id
Fusion-Component-Id
Fusion-Source
Fusion-Deployment-Id
Fusion-Template-Id
X-Wikidot-Backend
X-Edge-Pop
Geo-Info
X-Wikidot-Static-Cache
CacheControlHeader
X-Tt-Logid
X-Varnish-Ttl
X-Xrds-Location
Candidate-Md5Url
X-Ad-Defer-Variation
X-TH-Server
X-BCube-Filmed-By
Cache-Key
X-Amz-Meta-Cb-Modifiedtime
X-Servedbyhost
X-Via-Popv
X-Via-Popn
X-Via-Poph
X-Action
Ohc-File-Size
X-IPLB-Request-ID
True-Client-Country-4JS
Datacenter
X-Trace-ID
GeoIp-Country-Code
X-S-Maxage
X-Cache-ASPX
X-HA-Backend
VNS-Cache
X-SplitTest
XM
VNS-Age
CPC-Cache
X-Contensis-Viewer-Groups
CPC-Age
X-Backend-TTL
X-RateLimit-Reset
X-Presslabs-Stats
X-WA-Info
Client
X-Varnish-Authentication
Fastly-Backend-Name
ITXSESSIONID
FSS-Cache
X-VCL-Version
X-DC
X-Micro-Cache
X-Varnish-Beresp-TTL
Server-ID
Edge-Cache
X-Provided-By
Geoip-Latitude
X-Vc
X-Req
Path
X-Dynatrace
X-VHOST
X-Webkit-Csp-Report-Only
X-AIR-PT
My-App
X-CACHE-KEY
X-Zone
Cache-Host
X-Cache-Status-Check
Hostname
X-Cs
X-Pass-Why
Ohc-Cache-HIT
X-Origin-Upstream-Status
X-Up
X-Fpc
Ngx.Var.Host
DataCenter
X-FireWall-Port
True-Client-IP
Lb
NtCoent-Length
X-LB-ID
X-TX-ID
X-Proxy-CacheRZ
XkeyRZ
X-Traceid
X-Clientip
X-Varnish-Beresp-Ttl
X-Li-Fabric
OT-Force-Account-Verify
X-Li-Pop
Test
X-FPC
Powered-By
X-LI-UUID
Cf-Int-Pingora-Origin-Digest
X-NGINX-Cache
X-B3-Spanid
X-UnsetCookies
X-Cdn-Request-ID
X-ND-Cache
X-Api-Version
X-CSRF-TOKEN
X-Correlation-ID
X-Beluga-Cache-Status
X-Beluga-Trace
X-Beluga-Node
X-Beluga-Status
X-Beluga-Record
X-Beluga-Response-Time
X-CUA
X-Webkit-CSP-Report-Only
User-Agent
X-Time-Microsecs
X-MSEdge-Features
Proxy-Connection
X-Dmc
X-RAMCache
X-MSEdge-Flight
X-Fragments
WZWS-RAY
Resin-Trace
Server-Id
Target-Params
Tracecode
Cf-Device-Type
X-Vcl-Version
X-CLOUD-TRACE-CONTEXT
X-Azure-Ref-OriginShield
X-Platform-Cluster
X-Via-PopV
GeoIP-Country-Code
X-Render-Time
X-HS-Status
X-Var-Ttl
X-FC-Vary-Parameters
X-Via-PopN
Lfy
Uri
X-ATG-Version
X-Fastly-Backend
X-Sucuri-Cache
X-Via-PopH
X-Ha-Backend
X-Sucuri-ID
X-URL
GeoIP-Latitude
X-Platform-Processor
X-B3-Traceid-Primal
X-Platform-Router
X-Geo
X-INCAP-ABP
Sid
C-Via
Srvid
Rip
X-ServedByHost
MIME-Version
X-PX
X-Li-Proto
X-Alfa-Service
X-Gateway-Skip-Cache
Tube-Get-Contents
X-Varnish-Beresp-Status
Tube-Got-Eval
X-Proxy-Cache-Hk
Epwk-X-Cache
X-DynaTrace-JS-Agent
X-Qnm-Cache
X-M-Log
X-M-Reqid
Tube-Return
X-Gateway-Cache-Key
X-CCDN-CacheTTL
X-LI-Proto
X-CCDN-Origin-Time
X-Hcs-Proxy-Type
X-Service
Tube-Got-Results
Click-Count-Action-Start
X-Gateway-Request-Id
Click-Count-Error
X-Fetch-By
X-Gateway-Cache-Status
X-NU-AKA-ACS-Version
X-Akamai-Pragma-Client-IP
Fastly-Drupal-HTML
X-TRACE-ID
X-Check-Cacheable
X-Backend-State
Magicmarker
X-Fastly-Backend-Reqs
Esi-Enabled
X-Edge-POP
X-Backend-Host
ENV
X-Esi
Cdn
X-Cdn-Forward
X-Cache-Expires
On-Server
HIT
XServer
X-App
X-Request-Start
X-Cache-CFC
X-Srcache-Fetch-Status
X-MG-S
X-Srcache-Store-Status
X-LiteSpeed-Cache-Control
Srv
Tcn
PICS-Label
Section-Io-Origin-Status
X-Yottaa-OS
Server-Ttl
X-Bip
X-Thanos
CF-Cached-On
X-ElasticPress-Query
X-Lb-Nocache
ServerName
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
X-Newrelic-App-Data
Section-Io-Id
X-APP
D-Url-Rewrites
X-Acquia-Application-Trace
X-Iplb-Request-Id
Inserted-Into-Cache-At
Cf-Ipcountry
X-Nc
X-Iplb-Instance
X-BBC-Origin-Response-Status
X-Acquia-Application-UUID
X-Acquia-Purge-Tags
X-Acquia-Site
Wpo-Cache-Status
X-Vcache
Wpo-Cache-Message
X-Serial
Servedby
X-HostName
Warning
X-Akamai-Request-ID
X-Cache-Config
X-LiteSpeed-Tag
True-Client-Ip
Hit
X-Wp-Cf-Super-Cache-Cache-Control
X-Fastly-Cache-Hits
Fastcgi-Cache-Ttl
X-Akamai-ERPolicy
X-Shopify-Generated-Cart-Token
X-Akamai-ERRuleID
M-TraceId
X-Wp-Cf-Super-Cache
X-B3-Parentspanid
X-Back
X-Request-Url
X-Th-Server
Content-Style-Type
Content-Script-Type
X-Release
X-Dw-Trace-Id
X-Dist-Code
X-Storefront-Renderer-Verified
X-CF-Powered-By
X-Request-URL
X-IN-APIGATEWAY
CountryCode
X-IN-APIGATEWAYSSL
X-Litespeed-Cache-Control
X-Snapshot-Date
Ngx
Cneonction
X-Swift-Error