Threat Level: green Handler on Duty: Jim Clausing

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
Pragma
X-Powered-By
X-XSS-Protection
CF-RAY
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
P3P
X-Cache-Hits
X-UA-Compatible
Alt-Svc
X-Xss-Protection
X-Served-By
CF-Ray
X-Download-Options
X-Timer
X-Request-Id
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
Access-Control-Allow-Credentials
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
X-Drupal-Cache
X-Generator
X-Cache-Status
X-Check
X-Cacheable
X-Envoy-Upstream-Service-Time
X-DNS-Prefetch-Control
X-Request-ID
Timing-Allow-Origin
X-Iinfo
X-FRAME-OPTIONS
X-Dns-Prefetch-Control
X-Drupal-Dynamic-Cache
Feature-Policy
X-Content-Security-Policy
Content-Encoding
Access-Control-Expose-Headers
Upgrade
Status
X-CDN
X-AspNetMvc-Version
Server-Timing
X-XSS-PROTECTION
Access-Control-Max-Age
X-Amz-Request-Id
Request-Context
X-Amz-Id-2
X-Turbo-Charged-By
X-AH-Environment
X-Via
X-Robots-Tag
X-Backend
X-Cache-Group
Cf-Edge-Cache
Keep-Alive
Host-Header
X-Proxy-Cache
X-Hacker
X-Server
X-Rq
X-Server-Powered-By
X-Age
Allow
X-Vhost
X-UA-Device
X-Varnish-Cache
X-Ws-Request-Id
EagleId
X-Dispatcher
X-Amz-Version-Id
Grace
X-LiteSpeed-Cache
Cf-Apo-Via
P3p
Nel
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Page-Speed
X-Device
Cf-Railgun
EagleEye-TraceId
X-Swift-SaveTime
X-Swift-CacheTime
X-Aws-Lambda-Call-Status
Ali-Swift-Global-Savetime
X-Pingback
X-Node
X-Host
Accept-CH
X-WebKit-CSP
X-Server-Id
Surrogate-Control
X-OneAgent-JS-Injection
X-Backend-Server
X-CST
X-Readtime
X-Nginx-Cache-Status
X-Akam-SW-Version
X-Cache-Lookup
X-Content-Security-Policy-Report-Only
Permissions-Policy
Request-Id
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Application-Context
X-Nginx-Upstream-Cache-Status
X-Cloud-Trace-Context
X-Trace
X-Response-Time
X-Edge
Accept-Ch-Lifetime
X-HW
Accept-CH-Lifetime
X-Ua-Compatible
Content-Location
X-Mod-Pagespeed
X-Clacks-Overhead
X-Url
X-Oneagent-Js-Injection
X-Midtier
X-Litespeed-Cache
X-Ruxit-JS-Agent
X-ECACHE
X-ESI
Rating
X-Amz-Server-Side-Encryption
X-Country
X-Mcache
Xkey
X-Upstream
X-Vname
X-PC
X-TtlSet
X-Vcap-Request-Id
Cache-Tag
X-Rack-Cache
X-D2id
X-MS-InvokeApp
Verso
X-Use-Magma
X-Kinja-Build
X-Kinja-Revision
X-GoogleNews-Bot
X-Kinja-Server
X-Element-Page-Cache
X-Exp-Variant
X-Kinja
X-Exp-Id
X-Cdn-Fetch
Accept-Ch
Fastly-Restarts
X-Cache-TTL
Edge-Control
RTSS
X-Powered-By-Plesk
X-Ruxit-Js-Agent
X-VARITI-CCR
Origin-Trial
X-Content-Type
X-Ac
X-Navigation-Version
X-Abt-Application-Version
X-Cached
X-Goog-Hash
Service-Worker-Allowed
X-Ua-Device
X-Country-Code
X-GitHub-Request-Id
X-Amz-Rid
X-Middleton-Display
X-Sol
Pagespeed
Display
X-WebKit-CSP-Report-Only
X-B3-TraceId
X-Ttl
X-Mg-S
X-Browser-Type
X-Dw-Request-Base-Id
X-SharePointHealthScore
SPRequestGuid
X-Server-Name
Cross-Origin-Opener-Policy
Arr-Disable-Session-Affinity
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Instrumentation
X-Varnish-TTL
X-Powered-CMS
AR-ATIME
AR-SID
Response
AR-PoweredBy
AR-Request-ID
X-Middleton-Response
X-Amzn-Trace-Id
SPRequestDuration
SPIisLatency
X-Cache-Key
AR-CACHE
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Fastly-Request-ID
X-Version
X-Cnection
X-Jurisdiction
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-HP-Webp
X-HP-Trace-Id
X-Webkit-CSP
X-Accel-Expires
X-T
Cache-Tags
Front-End-Https
Cache-Status
X-Client-IP
Edge-Cache-Tag
X-MSEdge-Ref
X-NF-Request-ID
X-Ser
X-Px
Pinterest-Generated-By
X-Times
X-Pinterest-Rid
Pinterest-Version
X-Fastcgi-Cache
X-Hits
Public-Key-Pins
Nginx-Cache
X-Recruiting
X-B3-TraceId-Primal
X-RateLimit-Remaining
Mrf-Cache-Status
MRF-Tech
X-NWS-LOG-UUID
X-Frontend
X-Request-Received
X-LLID
X-Shield-Request-Id
X-Request-Processing-Time
Server-Node
X-Ua-Browser
Payment
Access-Control-Request-Method
X-DIS-Request-ID
TP-Cache
X-FastCGI-Cache
X-RateLimit-Limit
X-Kinja-CCPA
X-Webkit-CSP-Report-Only
X-Goog-Metageneration
X-HS-Cache-Config
X-HS-Hub-Id
X-Erf-Stays-Pdp-Viaduct-Migration-Web
S
X-HS-Content-Id
X-HS-Combine-CSS
MicrosoftSharePointTeamServices
TP-L2-Cache
X-B3-Traceid
X-Webkit-Csp
X-LB-Cache
X-Content-Digest
Content-MD5
X-PressLabs-Stats
X-Distributor
Realpath
X-Geo-Country
X-Microsite
X-Request-Handler-Origin-Region
X-Ezoic-Cdn
X-GUploader-UploadID
Access-Control-Allow-Method
X-Forwarded-For
X-FB-Debug
X-Page-Id
Accept-Charset
Fastcgi-Cache
X-Cluster-Name
X-Protected-By
X-Hostname
X-Envoy-Decorator-Operation
X-Seen-By
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Ratelimit-Remaining
X-Correlation-Id
X-Rid
X-B3-Sampled
Cleartype
X-TTL
TCN
DC
X-Goog-Generation
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Newrelic-App-Data
X-Origin-Server
X-Debug-Info
X-Mobile
Referer-Policy
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
X-Ratelimit-Limit
X-Varnish-Backend
X-Git-Hash
X-Logged-In
Cross-Origin-Resource-Policy
X-Origin-Cache
X-Kinsta-Cache
X-Edge-Location-Klb
X-XRDS-Location
X-Azure-Ref
Alternate-Protocol
X-Contextid
X-Varnish-Grace
X-Grace
X-Is-Crawler
X-Providence-Cookie
X-Revision
X-Flags
X-Fb-Rlafr
Surrogate-Key
X-Amz-Replication-Status
X-App-Environment
X-Aspnet-Duration-Ms
X-Route-Name
X-Request-Guid
X-Aspnet-Version
X-Content-Options
X-TT
Count-Hit
Healthy
X-Amz-Meta-S3cmd-Attrs
X-Server-ID
X-Wix-Request-Id
X-IPS-LoggedIn
X-Forwarded-Proto
X-Whom
X-App-Server
MS-Author-Via
Charset
Frame-Options
WPO-Cache-Status
X-Hosted-By
WPO-Cache-Message
X-Akamai-Edgescape
Viewport
Filterid
X-Id
X-Daa-Tunnel
X-Magnolia-Registration
X-B
Paypal-Debug-Id
X-Cache-Age
X-Backend-Name
Section-Io-Cache
Retry-After
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-F-Cache
X-Trace-Id
X-Az
X-AppVersion
X-Client-Ip
X-Www-Served-By
X-Activity-Id
X-Cache-Control
Server-Name
X-Proxy-Cache-Info
X-Type
X-Varnish-Ttl
X-Varnish-Server
Refresh
X-Time
SRV
X-Proxy
X-App-Version
Version
VIX-Pulpo-Upstream-Status
X-Cache-Rule
VIX-Pulpo-Node
SD-X-WS
Akamai-GRN
X-ARC
X-Http-Reason
X-Response-Served-From
X-Original-Request-Id
X-Instance
X-Rule
Host
X-EdgeConnect-Cache-Status
X-Akamai-Request-ID2
Protected
X-Cache-Grace
Front
X-Rocket-Nginx-Serving-Static
X-Edge-Location
X-Status
X-UUID
X-Varnish-Age
X-User-Agent
X-FW-Serve
X-FW-Hash
X-FW-Server
X-FW-Static
X-FW-Version
X-FW-Dynamic
X-Environment-Context
Fastly-SWR
X-Cacheable-TTL
Fastly-SIE
From-Origin
X-Framework
X-FW-Type
Amp-Access-Control-Allow-Source-Origin
X-Region
X-Rendered-As
X-Unique-Id
X-Page-View
X-Is-Bot
X-L-Path
X-Jobs
X-Adobe-Loc
X-Adobe-Content
X-N
X-Oracle-Dms-Ecid
X-Cache-Time
Access-Control-Request-Headers
X-Tumblr-Pixel-1
X-Oracle-Dms-Rid
X-Tumblr-User
X-G
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-RemovedCookies
X-ProcessESI
X-RateLimit-Reset
X-Upgrade-Enabled
X-Load-Cache
X-COUNTRY
ServerID
X-Source
Content-Disposition
Country
X-Language
X-CDN-Forward
X-Drupal-Cache-Tags
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
X-Datadog-Trace-Id
X-Nf-Request-Id
X-HTML-Minification-Powered-By
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Vcache
Accept-Language
Countrycode
X-Datadog-Sampled
X-DynaTrace
X-Amzn-Remapped-Content-Length
X-Debug-IsConnected
X-Mg-Request-UUID
X-Debug-IsPreview
X-B3-SpanId
X-DynaTrace-JS-Agent
X-Generated-By
Liferay-Portal
X-ID
X-Xrds-Location
Backend
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
X-B-Cache
CF-IPCountry
X-Signature
Xet-Cookie
Xserver
X-DataDome
Webserver
X-Nginx-Cache
X-ECache
X-Tt-Logid
X-Device-Type
X-Httpd
X-Mode
X-NYM-Debug-Backend
X-Drupal-Cache-Contexts
X-Content-Powered-By
X-Tec-Api-Root
X-Servername
X-Tec-Api-Version
X-Tec-Api-Origin
X-Zen-Fury
Url
X-Content-Age
X-MCACHE
X-Erf-Web-Scheduler
GEO-INFO
X-Director
X-ServerID
X-Proto
X-Tb
X-Rewrite-Enabled
X-Container-Uri
S-Rt
X-Cache-Action
X-Cache-Operation
X-Sucuri-ID
Load-Balancing
X-Varnish-Cache-Hits
X-SayCDN-TTL
X-Say-Cacheable
Locale
Onion-Location
X-Urbn-Site-Id
Filters
Fastcgi-Useragent
X-Say-TTL
X-JoinUs
X-Git-Commit
X-GeoCountry
X-LAGOON
X-GeoCode
Azure-SlotName
Azure-Version
X-UPSTREAM-Address
Azure-InstanceId
Azure-SiteName
X-SaId
Azure-RegionName
Meta-Geo
X-Sucuri-Cache
X-Urbn-Context-Path
X-Labrador-Cache-Channel
X-Varnish-Hostname
X-XRDS-LOCATION
X-Cluster-Node
Uber-Trace-Id
X-PHP-Host
X-VC-Cache
X-Forwarded-Host
X-RM-Cache-TTL
X-Soup
Web-Mar-Node
X-VCT
X-Ms-Version
X-Served-From
X-Storage
X-Sql-Duration-Ms
X-Sql-Count
X-Detected-As
X-Ms-Request-Id
X-Logging-Id
X-Adobe-Source
X-Cache-Server
X-Generation-Time
Mn-Server-Ip
Node
X-Zipkin-Id
DB-Nickname
X-Origin-Hint
X-Skip-Cache
X-FB-TRIP-ID
X-Routing-Service
X-Proxied
TWC-Privacy
X-Extlb
X-Debug
Webcakes-Region
Webcakes-App-Name
TWC-Locale-Group
X-R9-Blue-Green-Version
TWC-Connection-Speed
Webcakes-App-Version
X-RCS-CacheZone
TWC-Device-Class
TWC-GeoIP-Country
Property-Id
TWC-GeoIP-LatLong
X-Timing-Wait
X-Tumblr-Pixel-2
X-Proxy-Build
Selected-Fe
X-LSADC-Cache
X-Format
X-Tumblr-Pixel-3
X-Fetched-On
X-Ratelimit-Reset
X-Uri
X-Lambda-Id
X-MP-GENERATED-AT
Source
X-Origin-Date
OT-Force-Account-Verify
Fastly-Drupal-HTML
X-Template
CDN-RequestId
X-Cache-Expired-At
X-Tncms
X-Cache-Hit
X-Loop
X-NGENIX-Cache
X-Via-JSL
X-Varnish-Hits
X-Pass-Why
Content-Secure-Policy
X-Endurance-Cache-Level
X-Cache-TTL-Remaining
X-UA-Device-Type
X-Ua
X-Srv
X-Node-Name
X-Redis-Cache
X-AIR-PT
Upgrade-Insecure-Requests
X-TimeS
X-Pubstack
Cross-Origin-Window-Policy
X-Real-IP
X-Origin-TTL
Section-Origin-Responded
X-Origin-CC
X-Server-W
Section-Io-Id
Section-Io-Origin-Status
X-Datadome
Section-Io-Origin-Time-Seconds
X-CCDN-Origin-Time
X-Hcs-Proxy-Type
X-Fastly-Request-Id
X-CCDN-CacheTTL
NGB
Cache-Hits
X-PHP-Backend
X-Cache-Host
X-S
X-RTag
X-CSRF-Token
Cache-Name
Ms-Operation-Id
MS-CV
Cache-Provider
CDN-RequestCountryCode
CDN-PullZone
CDN-EdgeStorageId
CDN-RequestPullCode
X-Restarts
CDN-Uid
CDN-RequestPullSuccess
X-Optimistic-Header
X-Xfnlog-Site
CDN-CachedAt
X-IPLB-Instance
X-Reqid
Apigw-Requestid
X-IPLB-Request-ID
CDN-Cache
X-Cms-Context
X-Hl-Ver
X-Rn-Rsrv
X-Cache-Type
X-ProxyCache-Key
X-ProxyCache-Status
X-BYPASS-REASON
X-GEO
X-Akamai-Transformed
X-No-Session
X-Aspnetmvc-Version
X-Via-Fastly
X-Newrelic-Synthetics
X-VWS-Id
X-LJ-Flow-ID
X-Cluster
X-AWS-Id
X-Worker
X-S-Cookie
T-Server
X-ScT
X-Shop-Environment
X-SD-PageType
X-Developer
Surrogated-Key
Server-Host
X-Csrf-Jwt
X-Destination
Sslversion
True-Client-Country-4JS
X-Request-Host
X-Rojux
X-Slack-Shared-Secret-Outcome
Vix-Hermes-Req-Id
X-Cache-NE
X-SRCache-Key
X-GeoIP-Region-Code
VNS-Age
X-GeoIP-Country-Code
X-Nyt-Route
X-Vdms-Path
X-Orig-Expires
BehaviorPad-Version
X-Access
X-Wikidot-Static-Cache
X-Wikidot-Backend
X-Conf
X-Slack-Backend
X-RateLimit-Remaining-Second
Gannett-Cam-Experience-Id
X-Debug-Cache-Fetch
X-Date
Fastly-SSL
Fastly-GeoIP-CountryCode
Meta-Geo-Continent
Fastly-Backend-Name
Gh-Request-Id
Ha-Gx-Prefs
L
L5d-Success-Class
Magicmarker
Mail-Subject
HA-Ipaddr
MD5-Digest
X-Debug-Cache-Store
N-Cache
Candidate-Md5Url
X-Origin-Time
X-Policy
Canary
Redirect-Candidate
Xc-Version
X-RateLimit-Limit-Second
X-Irp-Debug
Odigeo-Trace-Id
DCR-Processing-Time-Ms
X-D
DCR-Decision-By
Ngx.Var.Host
CPC-Age
CPC-Cache
Rendered-Blocks
X-We-Are-Hiring
X-Aed
Lang
X-TIM-N
X-JWT-State
X-Var-Ttl
X-TA-CDN-Provider
X-CF-Lambda-Fn
X-Eu-Site
X-Is-Gdpr
X-Accel-Buffering
X-A-Wwc
X-Epic-Correlation-Id
X-Viewer-Country
VNS-Cache
X-Accel-Expires-Debug
X-CF-Lambda-Version
X-External-Request-Id
X-Mvc-Supplant-Cachable
X-B-Cookie
X-BCube-Filmed-By
X-Vdms-Version
X-Bc-Bl
X-FC-Vary-Parameters
X-VG-WebCache
X-Forwarded-Path
X-Bl-Debug
X-Fastly-Backend
X-CGP
X-Section
X-Application
X-CACHE-AGE
X-Ec-GeoHdr
X-Cache-Bucket
X-CacheTTL
X-Cdn-Diag
X-A-Ccd
X-Tenant
X-Cache-Info
X-Vtex-Remote-Cache
X-Ec-Custom-Error
X-A-Dam
X-A-Dgt
X-Gdpr
Web-Mar-Region
X-A
X-Has-Esi
W
X-Ec-Fail
X-Dispatcher-Number
X-A-Dcw
X-Wix-Viewer-Type
We-Hiring
X-Proxy-Cache-Status
X-Old-Content-Length
X-CMSURLCustom
X-Auto-Login
X-PAYTM-SRV-ID
X-Loc
X-Cache-Id
Machine
X-Node-Id
X-Bip
Memcached
X-BBC-Edge-Cache-Status
X-Owner
Req-Svc-Chain
Thinkindot-CacheControl-Type
X-Cache-Debug
Thinkindot-Control
Thinkindot-CacheControl
X-Origin-Response-Time
TDXMobile
X-Clara-WADP
X-Core-Mission
X-Core-Value
Release
X-Cdn-Origin
Origin
X-Alternate-Cache-Key
X-Org
X-ApacheServer
X-Level-Front-Cache
Platform
X-Mid
X-Mly-Id
Producers
X-App-Name
X-Shopify-Stage
X-Server-IP
X-S-Maxage
X-ShardId
X-ShopId
X-Clientip
X-Variation
X-Request-Time
X-Varnish-CookieHashed-On
AKAMAI
X-Fmm-Version
X-Varnishpool
X-Varnish-Remaining-TTL
Adler-Geo
X-Varnish-CookieINHashed-On
X-Sn-Servicetimems
X-Sorting-Hat-PodId
X-Thinkindot-L3
X-SVT-ORM-VERSION
X-Human
X-Thanos
X-Test
X-DPWN-IS-SECURE
X-SVT-ORM-RULES
X-Parent-Response-Time
X-INCAP-ABP
X-Sorting-Hat-ShopId
X-Up
X-Storefront-Renderer-Rendered
X-Esi-Check
X-Forwarded-Site
X-VG-TLSProxy
X-Generated-On
X-DefElseHash
Datacenter
Cmstype
X-Handled-By
Environment
X-Geo-Header
Is-Eu
X-PERF
Host-ID
X-Platform
Expect-Staple
X-WADP-Cache
Cmsid
X-Pool
X-Qloud-Router
X-Gzip
X-VServer
X-Hash
X-Vmg-Version
X-DefHash
AMP-Access-Control-Allow-Source-Origin
User-Cache-Control
X-Nitro-Cache
X-Nginx-Cache-Key
X-Mvc-Supplant-OutputCached
X-From
X-Gen-Mode
X-Vcl-Version
X-GeoIP
X-Block-Status
X-App
X-WA-Info
X-Hnp-Log
X-Cdn-Srv
X-Nananana
X-Akamai-Device-Characteristics
X-Dispatcher-Server
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
Apple-News-Services-Handled
ServedBy
Sever-Int
Server-Hostname
Apple-News-Services-Request-Url
CDCHOST
DSUID
Esi-Enabled
NM-Fastcgi-Cache
Country-Code
CloudFront-Viewer-Country
X-Origin
Server-Ext
X-Device-Os
X-NodeID
X-Scale
X-Web-Node
X-Correlation-ID
WP-Super-Cache
X-Cs
Pics-Label
X-Air-Source
X-Air-Trace-Id
X-Air-Hostname
X-Instance-Name
Wxu-Next-Hostname
Wxu-Next-Region
Wxu-Next-Commit
Origin-CC
Origin-EX
X-LB-NoCache
C-Via
X-Refresh
Ssr
X-Presslabs-Stats
Server-Info
X-Cache-Enabled
X-NCache
X-Op-Id-All
X-Tx-Id
Memory
X-Azure-Ref-OriginShield
Time
Server-ID
X-Amz-Meta-Cb-Modifiedtime
X-TIME
X-HA-Backend
Cache-Host
X-Platform-Cluster
X-Platform-Processor
X-Platform-Router
X-Cache-Status-Check
X-Dc
NGX
X-Microcachable
Hostname
X-Origin-Expires
X-API-Version
X-Tb-Optimization-Total-Bytes-Saved
Origin-Agent-Cluster
X-Site-Version
XM
Cf-Device-Type
X-Locale
X-URL
GeoIP-Latitude
X-VHOST
X-VarnishDD-TTL
PFcat
X-HN
X-CACHE-GROUP
X-ZONE
Cdn-Requestid
X-Varnish-Beresp-Ttl
Resin-Trace
X-Varnish-Beresp-Grace
X-Ad-Defer-Variation
X-Wp-Cf-Super-Cache-Active
X-Zone
Srvid
X-Fpc
X-Via-SSL
Locid
X-Internal-Host
X-Via-Edge
X-FL-EDGE
X-DC
A
X-Via-CDN
Edge-Copy-Time
X-FL-QIT-DEBUG
X-Vgn-Hpd-Reason
YJS-ID
X-Micro-Cache
X-Webkit-Csp-Report-Only
X-WP-CF-Super-Cache-Active
Sid
X-Upstream-Ht
X-Upstream-Ct
X-ATG-Version
X-FireWall-Port
X-Contensis-Viewer-Groups
X-TraceId
X-Cache-ASPX
X-Moov-Xdn-Version
X-Moov-T
X-Pod-Name
X-Cached-By
X-Varnish-Authentication
Cache-Key
True-Client-Ip
X-Github-Request-Id
X-DataCenter
X-AB
IsBot
User-Agent
X-SIPLIST1
Uri
X-Buckets
Location
X-LiteSpeed-Cache-Control
GeoIP-Country-Code
X-Info
X-B3-Parentspanid
X-B3-Spanid
X-Geo-Region
X-Planisys-CDN-TTL
State
X-Planisys-CDN-Rules
X-HS-Content-Campaign-Id
X-Planisys-CDN-Cache
X-Platform-Server
X-VCache
X-Provided-By
X-Backend-Instance
GeoIp-Country-Code
X-Accel-Version
X-Release
X-NGINX-Cache
X-Nitro-Cache-From
X-Nitro-Rev
X-Datacenter
X-FTR-Request-ID
X-Fastly-Cache
X-VC
X-RN-RSRV
X-LiteSpeed-Tag
X-Geo
X-MSEdge-Flight
X-Cache-Remote
X-MSEdge-Features
Lb
X-Sigma-Backend
X-Sigma
Cdn
X-Rocket-Build-Number
CF-Ctrl
SID
X-Is-Tablet
X-Tcp-Rtt
XServer
X-Is-Supported-Browser
NtCoent-Length
X-Browser-Name
X-Is-Desktop
X-CS
X-Is-Mobile
X-Api-Version
Cache
Path
X-HostName
Tcn
X-NewRelic-App-Data
X-CSRF-TOKEN
True-Client-IP
X-Vgn-Hpd-Variations-Key
X-Generated-In
X-GeoIP-City
X-Gamma-Serve
X-Vgn-Hpd-Ssi
X-Vgn-Hpd-Cached
Fastly-Drupal-Html
X-SRV
X-Hyper-Cache
X-TRACE-ID
X-FPC
Epwk-X-Cache
X-Scheme
X-HS-Status
Cache-Tv-Group
X-Rebelmouse-Surrogate-Control
Srv
X-Frame-Option
X-Rebelmouse-Cache-Control
Ohc-File-Size
X-Service
Kp-EeAlive
X-Webstats-RespID
X-GoCache-CacheStatus
Serverid
Cf-Ipcountry
CountryCode
X-APP-VERSION
HostName
X-UA
X-Mobile-URL
X-Amz-Meta-Opti
X-Air-Pt
X-AK-Request-ID
Cdncip
Cdnsip
X-Esi
X-Location
X-Guploader-Uploadid
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-Wp-Cf-Super-Cache
WebServer
X-Region-Sid
Proxy-Connection
X-EC-Lua
X-Branch-Name
X-Traceid
X-Men
X-Developers
X-Cache-Tags
CacheControlHeader
X-Wp-Cf-Super-Cache-Cache-Control
X-Cache-Ttl
X-Aicache-OS
X-TX-ID
On-Server
X-Proxy-CacheRZ
Tube-Got-Results
XkeyRZ
X-Vc
X-Cdn-Cache-Status
X-Edge-Server
Env
Cdn-Request-Time
X-CDN-Cache-Status
Cdn-Host
X-Acquia-Purge-Cdn-Unconfigured
X-Pad
Click-Count-Error
Click-Count-Action-Start
Tube-Got-Eval
Yak-Timeinfo
Tube-Return
Geoip-Latitude
X-LB-ID
Mime-Version
WZWS-RAY
X-Vercel-Cache
X-Vercel-Id
X-Wa
X-B3-Trace-ID
X-Minions-Version
Ohc-Cache-HIT
V-Age
X-Cache-FS-Status
X-Akamai-Pragma-Client-IP
X-Via-Popv
X-Nc
Tube-Get-Contents
X-V-Cache
X-Servedbyhost
X-Via-Popn
X-Via-Poph
RNT-Time
X-SB
X-Req
RNT-Machine
X-VCL-Version
CDN
X-CACHE-KEY
X-Origin-Cache-Key
X-FTR-Balancer
X-Cdn-Request-ID
X-Edge-Pop
ENV
X-NMSegId
X-FTR-Expires
X-FTR-Backend
X-NWS-UUID-VERIFY
Req-ID
X-Country-Code-Real
M-TraceId
Ngx
X-FTR-Backend-Server
X-FTR-Cache-Status
X-Cdn-Forward
WWW-Authenticate
LB
X-Lb-Cache
X-User
Content-Style-Type
X-Ha-Backend
Cluster
Server-Id
CF-Cached-On
X-Ad-Load-Variation
Content-Script-Type
X-Fastly-Country-Code
X-WP-CF-Super-Cache-Cookies-Bypass
X-RID
X-TT-LOGID
X-Scope-Id
X-Acquia-Site
X-Snapshot-Date
X-Check-Cacheable
X-M-Log
PICS-Label
X-Lb-Nocache
X-M-Reqid
X-Dw-Trace-Id
X-IN-APIGATEWAYSSL
Pramga
X-IN-APIGATEWAY
X-APP
X-Processor
X-TH-Server
X-Acquia-Purge-Tags
X-Request-Start
X-Acquia-Application-Trace
X-Acquia-Application-UUID
X-Edge-POP
X-Via-Ucdn
X-MiniProfiler-Ids
X-Ckpd-Fst-Backend
Yjs-Id
X-Shield-Cache-Expires
X-Qnm-Cache
X-ElasticPress-Query
CACHE-MISS-TO-ORIGIN
Inserted-Into-Cache-At
X-Fastly-Cache-Hits
X-CUA
X-Iauth-Set-Uid
X-Fastly-Backend-Reqs
X-Render-Time
X-Udemy-Cache-App-Namespace
Vha6-Origin
X-RAMCache
X-Miniprofiler-Ids
HIT
Log-Origin
X-Cached-Since
X-Litespeed-Cache-Control
Cneonction