Threat Level: green Handler on Duty: Rick Wanner

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
Link
CF-Cache-Status
Accept-Ranges
CF-RAY
ETag
Expect-CT
Pragma
X-Powered-By
X-XSS-Protection
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-UA-Compatible
X-Cache-Hits
Alt-Svc
P3P
X-Served-By
X-Xss-Protection
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Cache-Status
X-Generator
X-Request-ID
X-Cacheable
Timing-Allow-Origin
X-Content-Security-Policy
P3p
X-Iinfo
Status
Feature-Policy
X-Envoy-Upstream-Service-Time
Content-Encoding
Access-Control-Expose-Headers
X-CDN
X-Drupal-Dynamic-Cache
X-AspNetMvc-Version
Upgrade
X-Via
CF-Ray
Access-Control-Max-Age
X-Ws-Request-Id
Server-Timing
EagleId
Keep-Alive
X-Cache-Group
X-Turbo-Charged-By
Request-Context
X-Age
X-Proxy-Cache
X-Server-Powered-By
X-AH-Environment
X-UA-Device
X-Backend
X-Hacker
X-Robots-Tag
Report-To
X-Amz-Request-Id
Host-Header
X-LiteSpeed-Cache
X-Server
X-Amz-Id-2
Grace
X-Dns-Prefetch-Control
X-Rq
X-Nginx-Cache-Status
X-Varnish-Cache
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-WebKit-CSP
X-Page-Speed
X-Vhost
EagleEye-TraceId
X-Amz-Version-Id
X-OneAgent-JS-Injection
X-Device
X-Pingback
X-Dispatcher
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Cache-Spec
NEL
X-Server-Id
X-Host
X-Backend-Server
X-Node
Cf-Railgun
Accept-CH
X-Readtime
X-Akam-SW-Version
Surrogate-Control
Request-Id
X-Response-Time
X-HW
X-Language
Xkey
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Application-Context
Content-Location
X-Template
X-Ruxit-JS-Agent
Rating
X-Ua-Compatible
X-B3-TraceId
Accept-Ch-Lifetime
X-Country
Accept-CH-Lifetime
X-Cloud-Trace-Context
X-Cache-Lookup
X-Ac
X-Url
Allow
X-Content-Type
X-Buckets
X-Trace
X-TtlSet
X-PC
X-Vname
X-Mod-Pagespeed
X-Varnish-TTL
X-Clacks-Overhead
Edge-Control
X-FastCGI-Cache
X-ESI
Cache-Tag
Fastly-Restarts
X-Rack-Cache
Service-Worker-Allowed
X-Server-Name
X-VARITI-CCR
X-Element-Page-Cache
Verso
X-GitHub-Request-Id
X-MS-InvokeApp
X-Amz-Rid
X-Upstream
MS-Author-Via
X-Vcap-Request-Id
Public-Key-Pins
X-Dw-Request-Base-Id
X-D2id
X-Client-IP
X-Cached
X-Abt-Application-Version
X-Origin-Cache
X-Cache-TTL
Arr-Disable-Session-Affinity
X-Cnection
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-Country-Code
X-Px
X-Powered-By-Plesk
X-Goog-Hash
X-Navigation-Version
Access-Control-Request-Method
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Instrumentation
X-Aws-Lambda-Call-Status
X-NF-Request-ID
X-Version
Accept-Ch
RTSS
X-Amz-Server-Side-Encryption
X-Powered-CMS
Pagespeed
Display
X-Middleton-Display
X-Sol
X-SRCache-Store-Status
X-SRCache-Fetch-Status
Response
X-Middleton-Response
X-Kinja-Server
X-Kinja-Revision
X-Use-Magma
X-Exp-Id
X-Cdn-Fetch
X-Exp-Variant
X-Kinja-Build
X-GoogleNews-Bot
X-Kinja
X-MSEdge-Ref
X-LLID
X-Edge
X-Kinsta-Cache
X-Edge-Location-Klb
X-CST
Nginx-Cache
X-Shield-Request-Id
Mrf-Cache-Status
X-TTL
MRF-Tech
X-B3-TraceId-Primal
AR-ATIME
S
AR-CACHE
AR-Request-ID
AR-PoweredBy
AR-SID
X-Jurisdiction
Content-MD5
X-HP-Trace-Id
X-HP-Webp
X-T
X-RateLimit-Remaining
X-Protected-By
X-Forwarded-For
X-Content-Security-Policy-Report-Only
TCN
X-Mg-S
X-Id
X-Mid
X-MCACHE
Fastcgi-Cache
X-Aspnetmvc-Version
Realpath
Front-End-Https
X-Parallel-Accel
SPIisLatency
Edge-Cache-Tag
SPRequestDuration
X-Recruiting
X-Request-Received
X-Request-Processing-Time
Filters
X-Ttl
Pinterest-Version
Pinterest-Generated-By
X-Pinterest-Rid
Fusion-Content-Id
Fusion-Content-Source
Fusion-Deployment-Id
Fusion-Source
Fusion-Template-Id
Fusion-Component-Id
Server-Node
X-Content
X-Ab
X-Ua-Browser
X-DynaTrace
X-SharePointHealthScore
SPRequestGuid
X-Correlation-Id
X-Ezoic-Cdn
X-Ruxit-Js-Agent
Alternate-Protocol
Server-Name
X-NWS-LOG-UUID
X-Accel-Expires
X-Frontend
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Cache-Config
X-HS-Combine-CSS
X-ECACHE
X-Yandex-Sdch-Disable
X-Hits
X-Cache-Key
X-Content-Options
X-Tt-Trace-Host
X-Tt-Trace-Tag
Cache-Tags
X-Git-Hash
X-Page-Id
MicrosoftSharePointTeamServices
Host
X-Fastly-Request-Id
Cleartype
Charset
X-Www-Served-By
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-B3-Sampled
X-Geo-Country
X-Content-Digest
TP-Cache
X-Amz-Replication-Status
TP-L2-Cache
Filterid
X-Ser
X-Forwarded-Proto
X-Hostname
X-VCache
X-Varnish-Age
X-Amzn-Trace-Id
X-AppVersion
X-Az
X-Activity-Id
X-Daa-Tunnel
X-XRDS-LOCATION
X-DIS-Request-ID
X-Debug-Info
X-Rid
X-Upgrade-Enabled
X-Origin-Server
X-Grace
Access-Control-Allow-Method
X-N
X-Microsite
X-Request-Handler-Origin-Region
X-LB-Cache
X-Origin-Upstream-Status
X-FB-Debug
X-WebKit-CSP-Report-Only
X-Nginx-Upstream-Cache-Status
ServerID
X-Mobile-URL
X-Providence-Cookie
X-Is-Crawler
X-Whom
X-Request-Guid
X-Route-Name
X-Aspnet-Duration-Ms
X-TT
X-Flags
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-Goog-Stored-Content-Encoding
X-NGENIX-Cache
X-Goog-Generation
X-Goog-Storage-Class
X-F-Cache
X-Goog-Metageneration
X-Varnish-Grace
Cross-Origin-Opener-Policy
X-App-Environment
X-App-Server
Viewport
Payment
X-Tb
X-Distributor
Paypal-Debug-Id
X-FW-Type
Node
DC
X-FW-Server
X-FW-Static
X-FW-Serve
X-Server-ID
X-FW-Hash
X-FW-Dynamic
X-Logged-In
X-Cache-Control
X-Seen-By
Fastcgi-Useragent
X-PressLabs-Stats
X-Type
X-Oneagent-Js-Injection
X-User-Agent
X-Cache-Age
Country
Accept-Charset
X-Ratelimit-Limit
X-Varnish-Backend
X-Cache-Rule
X-Webkit-CSP
Version
X-Webkit-Csp
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Browser-Type
X-Wix-Request-Id
X-DataDome
X-Load-Cache
X-Node-Name
X-Tec-Api-Root
X-Tec-Api-Version
X-Cache-Action
X-Tec-Api-Origin
X-IPLB-Instance
Refresh
X-Via-JSL
Referer-Policy
SD-X-WS
Access-Control-Request-Headers
X-Original-Request-Id
X-Response-Served-From
Cache-Status
X-Drupal-Cache-Tags
Amp-Access-Control-Allow-Source-Origin
X-Cacheable-TTL
X-Real-IP
X-Jobs
X-ProcessESI
X-Is-Bot
X-Revision
X-Page-View
X-Proxy-Cache-Status
X-B
X-Vgn-Hpd-Reason
X-Cluster-Name
X-Contextid
X-UUID
VIX-Pulpo-Upstream-Status
NGB
X-RemovedCookies
X-Rendered-As
VIX-Pulpo-Node
X-Yottaa-Metrics
DynaTrace
X-Signature
X-Device-Type
X-Drupal-Cache-Contexts
X-Debug
X-Yottaa-Optimizations
X-B-Cache
X-Proxy
X-Rule
X-Cache-Expired-At
Liferay-Portal
X-Instance
X-Framework
X-Mobile
Akamai-GRN
X-Cache-Time
X-Fastly-Request-ID
Surrogate-Key
X-G
X-Debug-IsConnected
X-Debug-IsPreview
X-Azure-Ref
X-Fastcgi-Cache
X-FW-Version
CF-IPCountry
Healthy
X-Source
X-Air-Trace-Id
X-TEC-API-ORIGIN
X-Air-Hostname
X-Air-Source
X-TEC-API-VERSION
X-TEC-API-ROOT
X-Ms-Version
X-Ms-Request-Id
SID
Frame-Options
X-Oracle-Dms-Ecid
X-Oracle-Dms-Rid
X-XRDS-Location
Ms-Operation-Id
X-RTag
MS-CV
X-Cache-Hit
X-APP-VERSION
Section-Io-Cache
Countrycode
X-Tumblr-User
X-Tumblr-Pixel-0
X-Nginx-Cache
X-Tumblr-Pixel
X-CDN-Forward
X-Tumblr-Pixel-1
Xserver
X-L-Path
X-Environment-Context
X-Varnish-Server
Count-Hit
GEO-INFO
X-Cache-Operation
X-Region
X-Servername
X-Content-Powered-By
Uber-Trace-Id
X-EdgeConnect-Cache-Status
X-Forwarded-Host
X-Backend-Name
Cross-Origin-Window-Policy
X-IPS-LoggedIn
X-Mode
Backend
X-Accel-Buffering
X-Adobe-Loc
X-Adobe-Content
X-Litespeed-Cache
Ec-Rule-Version
X-Zen-Fury
X-JoinUs
Meta-Geo
X-UPSTREAM-Address
X-RN-RSRV
X-SaId
X-Human
X-Microcachable
X-Redis-Cache
X-Cache-Type
Eomportal-Instance
X-Detected-As
X-Cache-Server
X-Hosted-By
X-Generation-Time
X-Varnish-Beresp-Grace
X-FB-TRIP-ID
X-Debug-Cache
X-ShopId
X-BYPASS-REASON
X-ProxyCache-Key
X-Alternate-Cache-Key
X-Sorting-Hat-PodId
X-Shopify-Stage
X-ProxyCache-Status
X-Sorting-Hat-ShopId
Url
Cache-Tv-Group
Apigw-Requestid
Cache-Name
Decoy-Debug-Key
Decoy-Debug-Status
X-ShardId
X-Cache-Grace
Decoy-Debug-TTL
X-Sql-Count
X-PHP-Backend
X-Origin-Date
X-Storage
X-Sql-Duration-Ms
X-No-Session
X-Via-Fastly
X-Uri
X-ServerID
X-Status
Country-Code
X-Cache-TTL-Remaining
X-NCache
TWC-Connection-Speed
TWC-Device-Class
TWC-GeoIP-Country
Selected-Fe
TWC-Locale-Group
TWC-GeoIP-LatLong
X-Origin-Hint
X-UA-Device-Type
X-Site-Version
X-OCL
X-Ratelimit-Reset
Fastly-SSL
X-PCL
Property-Id
Protected
TWC-Privacy
X-Say-TTL
Mn-Server-Ip
X-Proxy-Build
X-Timing-Wait
X-Format
X-Say-Cacheable
X-Web-Node
X-Akamai-Edgescape
X-SayCDN-TTL
Webcakes-App-Version
Webcakes-App-Name
Webcakes-Region
X-Cache-Host
X-Section
X-Hl-Ver
X-Pubstack
Azure-Version
X-PERF
X-Varnishpool
OT-Force-Account-Verify
Azure-SlotName
X-R9-Blue-Green-Version
X-Server-W
X-ApacheServer
X-NYM-Debug-Backend
DB-Nickname
X-Access
X-Azure-Ref-OriginShield
Azure-SiteName
Azure-InstanceId
Azure-RegionName
X-Routing-Service
X-Cache-NGX
X-LSADC-Cache
Source
X-Tid
X-Extlb
X-RateLimit-Limit
X-Be
X-Cluster-Node
X-Rewrite-Enabled
Content-Secure-Policy
X-Zipkin-Id
X-Proxied
X-SRV
X-Soup
X-Ua
X-NewRelic-App-Data
X-Time
X-HTML-Minification-Powered-By
X-Content-Age
X-Amz-Meta-S3cmd-Attrs
X-Cache-Var-Map
X-Cached-By
X-Cache-Var
SRV
X-Presslabs-Stats
Content-Disposition
X-Dc
CDN-EdgeStorageId
CDN-Cache
X-Generated-By
X-Unique-Id
CDN-Uid
X-LAGOON
CDN-PullZone
CDN-RequestCountryCode
CDN-CachedAt
Cache
CDN-RequestId
X-Loop
X-TNCMS
X-Varnish-Hits
X-Varnish-Hostname
X-Hyper-Cache
X-Bc-Bl
X-S-Maxage
X-App-Version
Onion-Location
Retry-After
X-Auto-Login
X-Origin-TTL
X-Origin-CC
X-GEO
X-TT-LOGID
X-Trace-Id
Webserver
X-Tumblr-Pixel-3
X-Tumblr-Pixel-2
Web-Mar-Node
Cache-Hits
X-Proto
X-Nginx-Cache-Key
X-ECache
Xet-Cookie
X-Endurance-Cache-Level
X-Tenant
X-Time-Microsecs
X-Cdn
X-Akamai-Transformed
X-Edge-Location
X-Qnm-Cache
X-VWS-Id
X-LJ-Flow-ID
X-GG-Cache-Date
X-M-Log
Mime-Version
X-AWS-Id
X-Platform-Server
X-M-Reqid
LB
CloudFront-Viewer-Country
X-Mg-Request-UUID
X-CSRF-Token
X-Labrador-Cache-Channel
X-CACHE-KEY
X-PHP-Host
X-Amzn-RequestId
X-Amz-Apigw-Id
HostName
X-Xfnlog-Site
X-Cache-Tags
N-Cache
X-Handled-By
X-B3-SpanId
X-RCS-CacheZone
X-Varnish-Cache-Hits
Upgrade-Insecure-Requests
WPO-Cache-Status
X-Origin-Response-Time
X-Request-Time
X-TIME
ServedBy
X-Adobe-Source
WPO-Cache-Message
X-AOL-HN
X-VC-Cache
X-Storefront-Renderer-Rendered
X-Locale
X-Cache-Remote
X-A-Ccd
State
Surrogated-Key
X-A
Expiry
Pramga
Fastcgi-X-Cache-Version
A
BehaviorPad-Version
DCR-Decision-By
X-A-Dam
Meta-Geo-Continent
Mobile-Detection-Method
DSUID
Redirect-Candidate
DCR-Processing-Time-Ms
Origin
Odigeo-Trace-Id
Rendered-Blocks
X-Forwarded-Path
X-ScT
X-S-Cookie
X-SD-PageType
X-Session-Fingerprint
X-Shop-Environment
X-S
X-Rojux
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Processor
X-Request-Host
X-Slack-Backend
X-SRCache-Key
X-VG-WebCache
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
Xc-Version
X-Vdms-Version
X-Vdms-Path
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-TIM-N
X-V-Cache
X-Planisys-CDN-Cache
X-PBS-Appsvrname
X-Cache-NE
X-CF-Lambda-Fn
X-Ckpd-Fst-Backend
X-Cluster
X-B-Cookie
X-ARC
X-A-Dgt
X-A-Wwc
X-Aed
X-Application
X-Conf
X-Connection-Hash
X-NAPM-TraceId
X-ND-Cache
X-Orig-Expires
X-PAYTM-SRV-ID
X-Ig-Push-State
X-Ftr-Request-Id
X-D
X-Destination
X-Developer
X-External-Request-Id
X-A-Dcw
X-CF-Lambda-Version
X-ATG-Version
Nel
X-Reqid
X-Correlation-ID
X-Via-NSCOPI
Server-Info
Environment
X-MP-GENERATED-AT
X-Sucuri-ID
Gh-Request-Id
X-Epic-Correlation-Id
X-Fetched-On
X-Device-Os
X-Gdpr
X-Hash
X-Block-Status
Cmstype
Datacenter
V-Age
X-Forwarded-Site
Host-ID
Fastcgi-Cache-TTL
X-Sucuri-Cache
X-Accel-Expires-Debug
X-Skip-Cache
Release
Wxu-Next-Region
Wxu-Next-Hostname
Vix-Hermes-Req-Id
Wxu-Next-Commit
X-Cache-Bucket
X-Cache-Date
X-Core-Mission
Cmsid
X-Date
X-Fastly-Cache
X-Gen-Mode
X-Cache-Info
X-Hnp-Log
L
X-Geo-Header
X-Location
X-Men
X-Origin-Expires
AKAMAI
X-VG-TLSProxy
X-Served-From
X-Mvc-Supplant-Cachable
From-Origin
X-Old-Content-Length
X-Nyt-Route
X-Varnish-Beresp-Status
X-Scheme
X-Li-Pop
X-LI-UUID
X-Server-IP
User-Cache-Control
X-Owner
CacheControlHeader
X-Proxy-Upstream
X-Rocket-Nginx-Serving-Static
X-Policy
X-Li-Fabric
X-VServer
X-Origin-Time
AMP-Access-Control-Allow-Source-Origin
X-Cache-Config
Traceparent
X-Branch-Name
X-Bip
X-Ratelimit-Remaining
X-Platform
Origin-CC
Web-Mar-Region
We-Hiring
X-Sigma
Origin-EX
Req-Svc-Chain
X-Cache-Id
X-Req
X-TH-Server
X-Datadog-Sampling-Priority
X-GeoIP
X-Level-Front-Cache
X-Generated-On
X-Gamma-Serve
X-GeoIP-City
X-Irp-Debug
X-HS-Content-Campaign-Id
X-BBC-Edge-Cache-Status
X-Gzip
X-Cache-Debug
X-Fastly-Backend
X-HN
X-Datadog-Parent-Id
X-Rocket-Build-Number
X-Datadog-Trace-Id
X-Core-Value
X-Esi-Check
X-NodeID
X-Developers
X-Request-Start
X-Aicache-OS
X-Magnolia-Registration
X-TrackingId
Server-Host
Candidate-Md5Url
X-Thinkindot-L3
X-Thanos
CDCHOST
PFcat
X-VarnishDD-TTL
Mail-Subject
Machine
Locid
Fastly-GeoIP-CountryCode
X-Viewer-Country
Apple-News-Services-Request-Url
Arc-Country
TDXMobile
Apple-News-Services-Handled
Thinkindot-Control
Thinkindot-CacheControl
True-Client-Country-4JS
X-Sigma-Backend
Svr
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
Thinkindot-CacheControl-Type
HA-Ipaddr
X-DPWN-IS-SECURE
X-Varnish-Remaining-TTL
Ha-Gx-Prefs
Is-Eu
X-DefElseHash
X-Worker
Memcached
Adler-Geo
X-Loc
X-DefHash
L5d-Success-Class
X-FC-Vary-Parameters
X-Has-Esi
X-Csrf-Jwt
NGX
Cf-Device-Type
X-Is-Gdpr
X-NU-AKA-ACS-Version
Fastly-SWR
X-JWT-State
X-Eu-Site
X-Varnish-CookieHashed-On
X-Origin
X-Variation
X-Varnish-CookieINHashed-On
X-Request-URI
Platform
X-Region-Sid
X-EC-Lua
X-Rebelmouse-Surrogate-Control
X-Sn-Servicetimems
X-RateLimit-Remaining-Second
X-Backend-State
X-Amzn-Remapped-Content-Length
X-Qloud-Router
X-RateLimit-Limit-Second
X-Rebelmouse-Cache-Control
X-Pod-Name
NM-Fastcgi-Cache
X-Envoy-Decorator-Operation
Fastly-SIE
X-Webstats-RespID
X-CGP
X-Cdn-Origin
X-FireWall-Port
X-Xrds-Location
Fastly-Drupal-Html
X-UnsetCookies
WWW-Authenticate
Sslversion
X-Node-Id
X-Cdn-Srv
X-Tx-Id
X-Zone
CDN
X-Varnish-Beresp-Ttl
On-Server
X-NC
Ssr
X-API-Version
X-Response-By
Esi-Enabled
X-Mvc-Supplant-OutputCached
X-CLOUD-TRACE-CONTEXT
X-CS
Pics-Label
X-Vc
X-Up
X-LB-ID
X-Generated-In
WP-Super-Cache
X-Tt-Logid
X-Refresh
Memory
X-Trace-ID
Time
X-Service
Ms-Author-Via
C-Via
X-Datadome
NtCoent-Length
X-LB-NoCache
X-Edge-Pop
X-Cache-PHP
X-Backend-TTL
X-Cache-Enabled
X-TraceId
X-DynaTrace-JS-Agent
X-TA-CDN-Provider
X-Via-Popv
X-Tb-Optimization-Total-Bytes-Saved
X-GeoIP-Country-Code
X-Via-Poph
GeoIp-Country-Code
X-Via-Popn
X-GeoIP-Region-Code
Env
X-NWS-UUID-VERIFY
X-Varnish-Ttl
X-Dynatrace
X-Cache-Status-Check
Magicmarker
X-Parent-Response-Time
X-DC
X-Optimistic-Header
X-Render-Time
X-Info
X-Varnish-Beresp-TTL
X-ZONE
X-Esi
X-CacheTTL
X-Restarts
X-Servedbyhost
Kp-EeAlive
X-Ua-Device
X-Cs
WebServer
X-Unique-ID
X-TX-ID
S-Rt
Server-ID
X-AIR-PT
X-DW
X-DSS
X-DB
X-Action
X-Clientip
X-Srv
X-DI
X-RPM
X-MSEdge-Features
X-MSEdge-Flight
X-Wix-Viewer-Type
X-RPS
X-Cache-Backend
X-RSL
Edge-Cache
Cache-Host
X-VCL-Version
HIT
UCS
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
X-Oss-Server-Time
X-Oss-Storage-Class
X-Oss-Request-Id
X-Minions-Version
X-Newrelic-Synthetics
X-Li-Proto
X-Cache-Ttl
X-App
Proxy-Connection
X-LI-Proto
S-Cnection
Lb
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
Section-Io-Id
X-LiteSpeed-Cache-Control
X-URL
Section-Origin-Responded
X-FPC
X-HA-Backend
X-Webkit-Csp-Report-Only
Test
X-Fpc
X-Akamai-Request-ID2
X-Traceid
X-Http-Reason
X-Micro-Cache
Server-Id
User-Agent
X-Vcl-Version
Fastly-Backend-Name
X-B3-Spanid
X-NODE
X-Webkit-CSP-Report-Only
Tcn
X-Backend-Host
Geo-Info
Accept-Language
X-Pad
X-CSRF-TOKEN
X-Ec-GeoHdr
X-User
X-Pass-Why
X-Release
X-BCube-Filmed-By
X-Ec-Fail
X-ES-SERVER
X-Check-Cacheable
X-LiteSpeed-Tag
Cf-Int-Pingora-Origin-Digest
X-Urbn-Context-Path
X-HostName
X-Urbn-Site-Id
Locale
Fastly-Drupal-HTML
X-APP
Resin-Trace
Hostname
X-BBC-Origin-Response-Status
CPC-Cache
X-Ha-Backend
EpKe-Alive
X-ID
Path
VNS-Age
VNS-Cache
CPC-Age
Cache-Key
X-Amz-Meta-Cb-Modifiedtime
X-ServedByHost
X-COUNTRY
X-Dynatrace-Js-Agent
X-AK-Request-ID
M-TraceId
Cdnsip
Ohc-File-Size
X-NGINX-Cache
X-Clara-WADP
X-Via-PopN
Hit
GeoIP-Country-Code
X-Via-PopH
X-WADP-Cache
X-Via-PopV
Cdncip
X-Fmm-Version
X-Akamai-Pragma-Client-IP
X-WA
Srv
X-WA-Info
X-Geo
ENV
My-App
X-Edge-POP
X-PJAX-URL
Pagetype
X-ElasticPress-Query
X-Cdn-Forward
X-Cms-Context
Geoip-Latitude
Cluster
Shield-Pop
X-Wikidot-Static-Cache
MIME-Version
X-Wikidot-Backend
MD5-Digest
Load-Balancing
X-From
X-CCDN-CacheTTL
X-CCDN-Origin-Time
X-Edge-Cache
X-CUA
Tracecode
X-HS-Status
X-Var-Ttl
X-Hcs-Proxy-Type
X-Via-Ucdn
X-Api-Version
Lfy
X-Ucs
X-Fastly-Cache-Hits
T-Server
X-ServerName
X-VG-WebServer
URI
Server-Hostname
Server-Ext
X-Fastly-Backend-Reqs
X-RAMCache
X-UP
WZWS-RAY
IsBot
X-GoCache-CacheStatus
W
Lang
Servername
X-Lb-Id
X-Cache-Expires
X-SIPLIST1
X-Fragments
Sever-Int
X-Mcache
X-Dw-Trace-Id
Sid
X-TRACE-ID
Target-Params
X-VC
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
X-Provided-By
X-B3-ParentSpanId
X-Nc
X-RateLimit-Reset
Cteonnt-Length
Ohc-Cache-HIT
Cdn
PICS-Label
Cneonction
X-Cdn-Request-ID
X-Platform-Router
X-Newrelic-App-Data
Cf-Ipcountry
X-Platform-Processor
X-Swift-Error
X-Platform-Cluster
Dnion-Transfer-Encoding
X-Akamai-Request-ID
X-Via-CDN
CF-Cached-On
HitType
X-Apw-Access-Object
Server-Ttl
X-Yottaa-OS
X-Acquia-Purge-Tags
X-Acquia-Site
X-Last-Modified
Vha6-Origin
X-Acquia-Application-UUID
X-Snapshot-Date
X-Cc-Via
X-Apw-Access-Action
X-Apw-Access-Token
X-Apw-Hits
X-Contensis-Viewer-Groups
X-Cache-ASPX
X-Acquia-Application-Trace
X-Cache-Ngx
X-Air-Pt
X-Akamai-ERPolicy
X-Akamai-ERRuleID
Uri
X-Te-Duration-Ms
X-Te-Count
X-Http-Count
X-Http-Duration-Ms
X-Sentry-ID
X-Logging-Id
X-Varnish-Authentication
Req-ID
X-CacheKey
X-UA
CountryCode
X-Lb-Nocache
X-HTML-Edge-Cache
Ngx
X-B3-Parentspanid
X-Miniprofiler-Ids
FSS-Cache