Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
Link
CF-Cache-Status
Accept-Ranges
CF-RAY
ETag
Expect-CT
Pragma
X-Powered-By
X-XSS-Protection
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
Alt-Svc
P3P
X-Served-By
X-Xss-Protection
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Cache-Status
X-Generator
X-Cacheable
Timing-Allow-Origin
P3p
X-Content-Security-Policy
X-Iinfo
Feature-Policy
Status
X-Envoy-Upstream-Service-Time
Content-Encoding
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
X-CDN
X-AspNetMvc-Version
Upgrade
X-Via
CF-Ray
X-Ws-Request-Id
Access-Control-Max-Age
X-Request-ID
Server-Timing
EagleId
Keep-Alive
X-Cache-Group
X-Turbo-Charged-By
Request-Context
X-Age
X-Server-Powered-By
X-Proxy-Cache
X-UA-Device
X-AH-Environment
X-Backend
X-Hacker
X-Robots-Tag
Report-To
X-Amz-Request-Id
Host-Header
X-Server
X-Dns-Prefetch-Control
X-Amz-Id-2
Grace
X-LiteSpeed-Cache
X-Rq
X-Nginx-Cache-Status
X-Varnish-Cache
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-WebKit-CSP
X-Page-Speed
X-Vhost
X-Ua-Compatible
EagleEye-TraceId
X-Amz-Version-Id
X-OneAgent-JS-Injection
X-Pingback
X-Dispatcher
X-Device
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Cache-Spec
NEL
X-Host
X-Server-Id
Cf-Railgun
X-Backend-Server
X-Node
X-Readtime
Accept-CH
X-Akam-SW-Version
Surrogate-Control
Request-Id
X-Response-Time
X-HW
Xkey
Accept-Ch-Lifetime
X-Application-Context
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Content-Location
Rating
X-Ruxit-JS-Agent
X-Country
X-B3-TraceId
X-Cache-Lookup
X-Cloud-Trace-Context
X-Trace
X-Url
X-Ac
X-Content-Type
Accept-CH-Lifetime
X-TtlSet
X-PC
X-Vname
Allow
X-Clacks-Overhead
X-Mod-Pagespeed
Edge-Control
X-Varnish-TTL
X-ESI
X-Server-Name
Fastly-Restarts
Cache-Tag
X-FastCGI-Cache
X-VARITI-CCR
Service-Worker-Allowed
X-Rack-Cache
X-Element-Page-Cache
Verso
X-MS-InvokeApp
X-Upstream
X-GitHub-Request-Id
MS-Author-Via
Accept-Ch
X-Amz-Rid
Public-Key-Pins
X-Aws-Lambda-Call-Status
X-Vcap-Request-Id
X-Cached
X-Dw-Request-Base-Id
X-D2id
X-Client-IP
X-Abt-Application-Version
X-Cnection
X-Origin-Cache
X-Px
X-Cache-TTL
Arr-Disable-Session-Affinity
X-Country-Code
RTSS
X-Navigation-Version
X-Goog-Hash
Access-Control-Request-Method
X-Powered-By-Plesk
X-Kraken-Loop-Name
X-Instrumentation
X-Server-Lifecycle-Phase
X-NF-Request-ID
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
X-Exp-Variant
X-Exp-Id
X-GoogleNews-Bot
X-Kinja-Build
X-Use-Magma
X-Kinja-Server
X-Kinja-Revision
X-Kinja
X-Cdn-Fetch
X-Version
X-Language
X-Powered-CMS
AR-Request-ID
AR-SID
AR-PoweredBy
AR-CACHE
AR-ATIME
X-Sol
X-Middleton-Display
Pagespeed
Display
X-Amz-Server-Side-Encryption
X-Middleton-Response
Response
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-LLID
X-MSEdge-Ref
X-Kinsta-Cache
X-Edge
X-Edge-Location-Klb
X-RateLimit-Remaining
X-Template
Nginx-Cache
Mrf-Cache-Status
X-B3-TraceId-Primal
MRF-Tech
X-Protected-By
X-Shield-Request-Id
X-Jurisdiction
X-HP-Trace-Id
X-HP-Webp
X-TTL
TCN
X-Forwarded-For
X-T
S
X-Content-Security-Policy-Report-Only
X-Aspnetmvc-Version
X-Mg-S
X-Id
Content-MD5
Edge-Cache-Tag
X-Mid
Realpath
Fastcgi-Cache
SPIisLatency
SPRequestDuration
Front-End-Https
X-MCACHE
X-Ttl
X-CST
X-Recruiting
Pinterest-Generated-By
Pinterest-Version
Filters
X-Pinterest-Rid
X-DynaTrace
X-Request-Received
X-Request-Processing-Time
Server-Node
X-Content
X-Ua-Browser
X-Ab
X-Ruxit-Js-Agent
Server-Name
X-Frontend
X-Correlation-Id
X-ECACHE
X-SharePointHealthScore
SPRequestGuid
X-HS-Hub-Id
X-NWS-LOG-UUID
X-HS-Cache-Config
X-HS-Content-Id
Fusion-Template-Id
Fusion-Source
Fusion-Component-Id
Fusion-Deployment-Id
X-Parallel-Accel
Fusion-Content-Id
Fusion-Content-Source
X-HS-Combine-CSS
X-Yandex-Sdch-Disable
X-Ezoic-Cdn
X-Cache-Key
Alternate-Protocol
X-Hits
X-Ser
X-Buckets
X-Content-Options
X-Tt-Trace-Tag
X-Tt-Trace-Host
MicrosoftSharePointTeamServices
X-Page-Id
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
Cleartype
Charset
Cache-Tags
X-Git-Hash
X-B3-Sampled
Host
X-Www-Served-By
X-Geo-Country
X-Daa-Tunnel
X-DIS-Request-ID
X-Accel-Expires
X-Content-Digest
Filterid
X-Debug-Info
X-Amz-Replication-Status
X-Amzn-Trace-Id
X-Varnish-Age
X-Fastly-Request-Id
X-Hostname
X-AppVersion
X-Activity-Id
X-Az
X-Forwarded-Proto
X-FB-Debug
TP-Cache
X-VCache
TP-L2-Cache
X-Upgrade-Enabled
X-Rid
X-N
Access-Control-Allow-Method
Cross-Origin-Opener-Policy
X-Grace
X-Nginx-Upstream-Cache-Status
X-Origin-Server
X-LB-Cache
X-F-Cache
X-Mobile-URL
X-Aspnet-Duration-Ms
X-Flags
ServerID
X-Is-Crawler
X-Request-Guid
X-Providence-Cookie
X-Route-Name
X-XRDS-LOCATION
X-Whom
X-Server-ID
X-Goog-Metageneration
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-GUploader-UploadID
X-TT
X-Goog-Stored-Content-Length
X-App-Environment
Viewport
X-Tb
X-Varnish-Grace
Node
X-WebKit-CSP-Report-Only
X-Distributor
Payment
X-App-Server
X-Seen-By
X-FW-Hash
X-FW-Static
X-FW-Serve
X-FW-Type
X-FW-Dynamic
X-Origin-Upstream-Status
X-FW-Server
DC
X-Type
Paypal-Debug-Id
X-Ratelimit-Limit
X-NGENIX-Cache
X-Oneagent-Js-Injection
X-User-Agent
Fastcgi-Useragent
X-Cache-Control
Accept-Charset
X-Litespeed-Cache
Country
X-Wix-Request-Id
X-Logged-In
X-Cache-Rule
X-Microsite
X-Request-Handler-Origin-Region
X-Fastcgi-Cache
X-Webkit-CSP
X-Fastly-Request-ID
Version
X-DataDome
X-Cache-Age
X-Via-JSL
X-Oracle-Dms-Ecid
X-Oracle-Dms-Rid
X-Drupal-Cache-Tags
X-Browser-Type
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
Amp-Access-Control-Allow-Source-Origin
Referer-Policy
Refresh
X-Varnish-Backend
X-Node-Name
X-Load-Cache
X-B-Cache
X-Cluster-Name
Cache-Status
X-Contextid
X-Signature
X-Mobile
SD-X-WS
Access-Control-Request-Headers
X-Original-Request-Id
X-Response-Served-From
X-Rendered-As
X-Cacheable-TTL
X-Real-IP
X-Proxy-Cache-Status
X-Vgn-Hpd-Reason
X-Jobs
X-Cache-Expired-At
X-Cache-Action
X-Page-View
X-Is-Bot
X-UUID
VIX-Pulpo-Node
X-RemovedCookies
NGB
VIX-Pulpo-Upstream-Status
X-ProcessESI
X-B
X-Revision
X-Yottaa-Optimizations
X-Debug
X-IPLB-Instance
X-Yottaa-Metrics
X-Instance
X-Rule
X-Device-Type
X-Framework
X-Proxy
X-Drupal-Cache-Contexts
X-G
Surrogate-Key
X-Tec-Api-Origin
X-Tec-Api-Root
X-Tec-Api-Version
X-Debug-IsConnected
X-Cache-Time
X-Debug-IsPreview
X-Air-Hostname
X-Air-Source
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Air-Trace-Id
X-TEC-API-VERSION
Akamai-GRN
CF-IPCountry
X-FW-Version
DynaTrace
SID
X-PressLabs-Stats
Liferay-Portal
X-Azure-Ref
X-Nginx-Cache
Healthy
GEO-INFO
X-Ratelimit-Reset
X-CDN-Forward
Frame-Options
X-Ms-Version
X-Source
X-Ms-Request-Id
Count-Hit
X-Cache-Operation
X-Presslabs-Stats
X-RTag
MS-CV
Ms-Operation-Id
X-Accel-Buffering
X-XRDS-Location
Uber-Trace-Id
X-RateLimit-Limit
X-APP-VERSION
X-EdgeConnect-Cache-Status
X-L-Path
Countrycode
Xserver
X-Environment-Context
X-Cache-Hit
X-Zen-Fury
X-Tumblr-Pixel
X-Tumblr-Pixel-1
X-Tumblr-User
X-Tumblr-Pixel-0
X-Varnish-Server
X-Mode
Ec-Rule-Version
X-Region
X-Backend-Name
Cross-Origin-Window-Policy
X-Forwarded-Host
X-Cache-NGX
X-IPS-LoggedIn
Backend
X-Servername
X-Content-Powered-By
Meta-Geo
X-Cache-TTL-Remaining
X-Cache-Type
X-JoinUs
X-Detected-As
X-UPSTREAM-Address
X-SaId
X-Rewrite-Enabled
X-RN-RSRV
X-Human
X-Redis-Cache
Section-Io-Cache
Country-Code
X-Proxied
Decoy-Debug-Status
X-Zipkin-Id
X-Alternate-Cache-Key
X-Hosted-By
Apigw-Requestid
X-Tid
X-NewRelic-App-Data
X-Cache-Grace
X-Debug-Cache
Protected
X-Varnish-Beresp-Grace
X-Extlb
X-Generation-Time
Decoy-Debug-Key
X-Uri
X-Sql-Duration-Ms
X-ShopId
X-Sorting-Hat-PodId
Fastly-SSL
X-Shopify-Stage
X-Routing-Service
X-Sql-Count
X-ShardId
Decoy-Debug-TTL
Eomportal-Instance
X-Sorting-Hat-ShopId
Url
X-Cache-Server
X-Storage
X-Site-Version
X-BYPASS-REASON
X-ProxyCache-Status
X-Soup
X-Status
X-ProxyCache-Key
Cache-Name
X-Via-Fastly
X-Origin-Date
X-PHP-Backend
X-ServerID
X-PERF
X-FB-TRIP-ID
X-No-Session
X-NCache
X-UA-Device-Type
Mn-Server-Ip
X-ApacheServer
X-Microcachable
X-Adobe-Loc
DB-Nickname
X-Akamai-Edgescape
Selected-Fe
Cache-Tv-Group
X-Adobe-Content
X-Say-Cacheable
X-SayCDN-TTL
X-PCL
X-Format
X-Web-Node
X-Proxy-Build
X-Cache-Host
X-OCL
X-Say-TTL
X-Timing-Wait
X-Content-Age
SRV
X-NYM-Debug-Backend
X-Server-W
X-Pubstack
OT-Force-Account-Verify
X-Varnishpool
X-Section
Property-Id
X-Origin-Hint
TWC-GeoIP-Country
Webcakes-App-Version
Webcakes-Region
X-Cluster-Node
X-R9-Blue-Green-Version
Webcakes-App-Name
TWC-Privacy
TWC-Connection-Speed
TWC-Device-Class
TWC-GeoIP-LatLong
TWC-Locale-Group
X-Hl-Ver
X-Access
Azure-SlotName
Azure-SiteName
Azure-RegionName
Azure-InstanceId
Content-Secure-Policy
Azure-Version
X-Hyper-Cache
CDN-Cache
CDN-CachedAt
X-Webkit-Csp
X-LSADC-Cache
X-Be
CDN-EdgeStorageId
CDN-RequestId
CDN-PullZone
CDN-Uid
CDN-RequestCountryCode
LB
X-Generated-By
X-Azure-Ref-OriginShield
WPO-Cache-Status
WPO-Cache-Message
X-Ua
X-Cached-By
Content-Disposition
Source
Cache
X-Nginx-Cache-Key
X-SRV
X-TIME
X-App-Version
X-Unique-Id
X-TT-LOGID
X-LAGOON
X-Bc-Bl
X-Trace-Id
Cache-Hits
X-Dc
X-Origin-CC
X-Origin-TTL
X-HTML-Minification-Powered-By
X-Varnish-Hits
Xet-Cookie
Retry-After
X-Varnish-Hostname
X-Loop
Mime-Version
X-Auto-Login
X-TNCMS
X-GEO
X-S-Maxage
X-Cdn
X-Platform-Server
X-Amz-Meta-S3cmd-Attrs
X-Time
X-Akamai-Transformed
HostName
X-Ratelimit-Remaining
X-Xfnlog-Site
Onion-Location
X-CSRF-Token
X-Cache-Var-Map
X-Cache-Var
Web-Mar-Node
X-Cache-Remote
X-Proto
X-Cache-Tags
X-Tumblr-Pixel-3
Webserver
X-Edge-Location
Upgrade-Insecure-Requests
X-Tumblr-Pixel-2
X-Time-Microsecs
X-Tenant
X-Varnish-Cache-Hits
ServedBy
X-Endurance-Cache-Level
X-Request-Time
X-AWS-Id
X-VWS-Id
X-AOL-HN
N-Cache
X-EC-Lua
X-Xrds-Location
X-LJ-Flow-ID
X-ECache
X-GG-Cache-Date
CloudFront-Viewer-Country
WP-Super-Cache
X-Request-Host
X-Mg-Request-UUID
X-M-Log
X-B3-SpanId
Nel
X-M-Reqid
X-Qnm-Cache
X-Correlation-ID
From-Origin
X-PHP-Host
X-FireWall-Port
X-Labrador-Cache-Channel
X-Via-NSCOPI
X-Origin-Response-Time
X-VG-WebCache
X-SVT-ORM-RULES
X-ARC
X-Application
X-Session-Fingerprint
X-B-Cookie
Expiry
Meta-Geo-Continent
Mobile-Detection-Method
X-SVT-ORM-VERSION
X-Cache-NE
L
Odigeo-Trace-Id
Origin
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
X-Cache-Date
Fastcgi-X-Cache-Version
X-Block-Status
DSUID
BehaviorPad-Version
X-A-Dam
X-V-Cache
Sslversion
X-A-Dcw
Surrogated-Key
X-A-Ccd
V-Age
A
X-A
X-Slack-Backend
X-SRCache-Key
CDCHOST
Rendered-Blocks
DCR-Processing-Time-Ms
DCR-Decision-By
X-Aed
User-Cache-Control
X-Shop-Environment
X-Vdms-Version
X-Vdms-Path
Redirect-Candidate
Pramga
X-A-Dgt
X-A-Wwc
X-TIM-N
X-ScT
X-S
X-Conf
X-Connection-Hash
X-PAYTM-SRV-ID
X-Cluster
X-External-Request-Id
X-Planisys-CDN-Cache
X-Orig-Expires
X-Ftr-Request-Id
X-Developer
Xc-Version
X-Rojux
X-Destination
X-Hnp-Log
X-Ig-Push-State
X-D
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-SD-PageType
X-PBS-Appsvrname
X-NAPM-TraceId
X-Processor
X-ND-Cache
X-S-Cookie
X-CF-Lambda-Fn
X-Ckpd-Fst-Backend
X-Gen-Mode
X-Forwarded-Path
X-CF-Lambda-Version
X-Amz-Apigw-Id
X-Amzn-RequestId
X-RCS-CacheZone
Release
State
X-Sucuri-Cache
X-Storefront-Renderer-Rendered
Ssr
X-Owner
X-Sucuri-ID
X-LI-UUID
Origin-CC
X-Men
X-Mvc-Supplant-Cachable
X-NodeID
L5d-Success-Class
X-Li-Pop
Origin-EX
PFcat
X-HN
X-RateLimit-Remaining-Second
X-Origin-Expires
X-Li-Fabric
X-Hash
Wxu-Next-Hostname
X-Backend-State
X-Scheme
X-RateLimit-Limit-Second
Host-ID
X-Csrf-Jwt
X-Core-Mission
X-Server-IP
X-CGP
X-Cache-Info
X-Served-From
X-Proxy-Upstream
X-Policy
X-Cache-Bucket
X-Old-Content-Length
X-Accel-Expires-Debug
X-Date
X-Fetched-On
X-Fastly-Cache
X-Forwarded-Site
X-Rocket-Nginx-Serving-Static
Traceparent
True-Client-Country-4JS
X-Skip-Cache
Wxu-Next-Commit
X-Envoy-Decorator-Operation
X-Device-Os
X-Epic-Correlation-Id
X-Eu-Site
Wxu-Next-Region
Svr
X-UnsetCookies
Cmsid
X-Locale
Vix-Hermes-Req-Id
Cmstype
X-Varnish-Beresp-Status
X-VServer
X-Webstats-RespID
Arc-Country
X-Aicache-OS
HA-Ipaddr
X-Request-URI
Ha-Gx-Prefs
X-VarnishDD-TTL
X-Varnish-Ttl
X-Cache-Enabled
X-Zone
X-MP-GENERATED-AT
Fastly-Drupal-Html
X-Handled-By
Server-Info
Environment
X-NWS-UUID-VERIFY
X-Sigma
X-VG-TLSProxy
X-TH-Server
X-Viewer-Country
X-Adobe-Source
X-ATG-Version
X-Platform
X-Branch-Name
X-Cache-Debug
X-BBC-Edge-Cache-Status
X-Bip
X-Cdn-Origin
X-Cdn-Srv
X-Datadog-Sampling-Priority
X-Origin-Time
X-Irp-Debug
X-HS-Content-Campaign-Id
X-Region-Sid
X-Rocket-Build-Number
X-Level-Front-Cache
X-Request-Start
X-Nyt-Route
X-Node-Id
X-Req
X-Reqid
X-Location
X-Gzip
X-GeoIP-City
X-Datadog-Trace-Id
X-Esi-Check
X-Magnolia-Registration
X-Datadog-Parent-Id
X-Core-Value
X-Fastly-Backend
X-Gamma-Serve
X-GeoIP
X-Geo-Header
X-Generated-On
X-Gdpr
X-VC-Cache
X-Cache-Id
X-Sn-Servicetimems
X-TrackingId
Apple-News-Services-Handled
X-Thinkindot-L3
CacheControlHeader
X-Thanos
Fastcgi-Cache-TTL
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
Req-Svc-Chain
Server-Host
TDXMobile
Thinkindot-CacheControl
Thinkindot-Control
Thinkindot-CacheControl-Type
Fastly-GeoIP-CountryCode
AKAMAI
Mail-Subject
Machine
Web-Mar-Region
We-Hiring
X-Sigma-Backend
Locid
Gh-Request-Id
X-FC-Vary-Parameters
X-DefHash
Is-Eu
X-DefElseHash
X-Loc
X-DPWN-IS-SECURE
X-NU-AKA-ACS-Version
X-Origin
Platform
Fastly-SWR
NGX
NM-Fastcgi-Cache
X-Qloud-Router
X-Rebelmouse-Surrogate-Control
Fastly-SIE
X-Response-By
X-Rebelmouse-Cache-Control
Memcached
X-Developers
X-Tx-Id
X-Variation
X-Varnish-CookieHashed-On
X-Cache-Config
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
X-Worker
Adler-Geo
X-Trace-ID
X-Varnish-Beresp-Ttl
AMP-Access-Control-Allow-Source-Origin
X-Ua-Device
X-Has-Esi
X-GeoIP-Country-Code
Cf-Device-Type
X-CACHE-KEY
X-CLOUD-TRACE-CONTEXT
X-Backend-TTL
X-Mvc-Supplant-OutputCached
X-Amzn-Remapped-Content-Length
X-GeoIP-Region-Code
X-CS
X-Is-Gdpr
X-JWT-State
X-Pod-Name
Datacenter
X-LB-ID
X-Generated-In
Pics-Label
X-Up
X-API-Version
S-Rt
CDN
Magicmarker
X-NC
Candidate-Md5Url
Ms-Author-Via
X-Datadome
X-LB-NoCache
Kp-EeAlive
X-Tb-Optimization-Total-Bytes-Saved
X-DynaTrace-JS-Agent
X-Vc
X-Via-Popn
X-Restarts
X-DC
X-Via-Poph
X-Via-Popv
Memory
On-Server
Time
NtCoent-Length
WebServer
X-TraceId
Env
WWW-Authenticate
X-Cache-Ttl
X-Http-Reason
X-Tt-Logid
X-Akamai-Request-ID2
Edge-Cache
X-Cache-Backend
X-RSL
X-Wix-Viewer-Type
X-Optimistic-Header
X-DB
X-Action
X-Edge-Pop
Esi-Enabled
X-DI
X-TA-CDN-Provider
X-DSS
X-RPS
X-RPM
X-DW
GeoIp-Country-Code
X-CacheTTL
X-Refresh
X-Esi
C-Via
X-Minions-Version
X-Servedbyhost
X-Service
X-Parent-Response-Time
Accept-Language
X-Srv
X-HA-Backend
Server-ID
X-MSEdge-Features
X-MSEdge-Flight
X-Cache-PHP
X-Unique-ID
X-Varnish-Beresp-TTL
X-Newrelic-Synthetics
X-Cs
X-TX-ID
X-ZONE
X-VCL-Version
X-Cache-Status-Check
X-Urbn-Context-Path
Locale
X-Render-Time
X-Urbn-Site-Id
X-Dynatrace
X-Fpc
X-Webkit-CSP-Report-Only
X-User
X-Ec-GeoHdr
X-LI-Proto
X-App
X-Traceid
X-Ec-Fail
X-URL
Test
X-Webkit-Csp-Report-Only
X-Li-Proto
X-LiteSpeed-Cache-Control
Proxy-Connection
X-B3-Spanid
X-FPC
X-Info
X-Pass-Why
X-NODE
X-AIR-PT
X-AK-Request-ID
Geo-Info
Tcn
X-Clientip
X-Vcl-Version
Cdncip
Cdnsip
Server-Id
X-Oss-Storage-Class
Cluster
X-Oss-Server-Time
X-Oss-Request-Id
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
X-WADP-Cache
My-App
UCS
M-TraceId
X-Fmm-Version
X-Clara-WADP
HIT
Cache-Host
X-LiteSpeed-Tag
Fastly-Drupal-HTML
X-Var-Ttl
X-CUA
S-Cnection
Geoip-Latitude
X-HostName
Tracecode
Cf-Int-Pingora-Origin-Digest
Resin-Trace
X-CSRF-TOKEN
Lfy
GeoIP-Country-Code
X-From
T-Server
X-Ha-Backend
X-ID
Hostname
User-Agent
X-RAMCache
X-ServedByHost
X-Pad
X-Micro-Cache
Lang
X-Mcache
Hit
X-Fragments
Fastly-Backend-Name
Ohc-File-Size
X-Geo
X-Dynatrace-Js-Agent
MIME-Version
ENV
X-RateLimit-Reset
X-BBC-Origin-Response-Status
Target-Params
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
X-Release
X-Backend-Host
X-Via-PopN
X-Via-PopV
X-Via-PopH
X-Edge-POP
X-ElasticPress-Query
Section-Io-Id
Section-Io-Origin-Time-Seconds
DataCenter
X-BCube-Filmed-By
X-APP
Section-Io-Origin-Status
X-Cdn-Forward
X-NGINX-Cache
Section-Origin-Responded
X-Edge-Cache
X-Check-Cacheable
X-VC
Load-Balancing
X-Api-Version
Lb
EpKe-Alive
URI
X-Ucs
X-Fastly-Backend-Reqs
X-ServerName
Servername
X-HS-Status
X-Amz-Meta-Cb-Modifiedtime
X-Lb-Nocache
PICS-Label
Uri
X-UP
Path
VNS-Cache
X-Proxy-Cache-Info
Permissions-Policy
FSS-Cache
VNS-Age
X-Httpd
X-GoCache-CacheStatus
Cache-Key
X-WA-Info
X-WA
CPC-Cache
CPC-Age
X-TRACE-ID
X-Wikidot-Static-Cache
X-Lb-Id
X-Nc
X-ES-SERVER
Server-Ttl
ServerName
Ohc-Cache-HIT
Cneonction
WZWS-RAY
Cdn
X-Cdn-Request-ID
X-B3-ParentSpanId
X-Fastly-Cache-Hits
X-Wikidot-Backend
Producers
Cteonnt-Length
X-Provided-By
X-UA
X-Dw-Trace-Id
Shield-Pop
X-Apw-Access-Action
X-Cache-ASPX
X-Akamai-ERPolicy
X-PJAX-URL
X-Acquia-Application-UUID
X-SB
X-Snapshot-Date
X-Contensis-Viewer-Groups
X-Acquia-Purge-Tags
X-Acquia-Site
X-Acquia-Application-Trace
X-Apw-Access-Object
X-Akamai-ERRuleID
Cf-Ipcountry
X-Pool
Vha6-Origin
X-Vcache
X-Newrelic-App-Data
X-Cache-CFC
CF-Cached-On
X-Apw-Hits
X-Yottaa-OS
X-Apw-Access-Token
X-Swift-Error
Pagetype
X-Cms-Context
X-Cache-Ngx
Sid
X-Air-Pt
X-Udemy-Cache-App-Namespace
X-Platform-Router
X-Platform-Cluster
X-Platform-Processor
X-Akamai-Request-ID
X-Last-Modified
GeoIP-Latitude
X-Varnish-Authentication
MD5-Digest
X-Via-Ucdn
X-Logging-Id
X-CCDN-CacheTTL
X-CCDN-Origin-Time
X-Miniprofiler-Ids
X-Hcs-Proxy-Type
X-CacheKey
X-Akamai-Pragma-Client-IP
X-Http-Count
X-Http-Duration-Ms
X-Te-Count
Ngx
X-Sentry-ID
Req-ID
CountryCode
X-Te-Duration-Ms