Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-Cache-Status
Link
Accept-Ranges
CF-RAY
ETag
X-XSS-Protection
Expect-CT
Pragma
X-Powered-By
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
Alt-Svc
X-Served-By
X-Xss-Protection
X-Download-Options
X-Timer
X-Request-Id
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Cache-Status
X-Check
X-Generator
X-Cacheable
Timing-Allow-Origin
X-Content-Security-Policy
X-Iinfo
Feature-Policy
Status
X-Envoy-Upstream-Service-Time
Content-Encoding
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
X-AspNetMvc-Version
X-CDN
P3p
X-Request-ID
Upgrade
X-Via
CF-Ray
X-Ws-Request-Id
Access-Control-Max-Age
Server-Timing
EagleId
X-Cache-Group
X-Turbo-Charged-By
Report-To
Keep-Alive
Request-Context
X-UA-Device
X-Age
X-Backend
X-Proxy-Cache
X-Server-Powered-By
X-AH-Environment
X-Robots-Tag
X-Hacker
X-Amz-Request-Id
Host-Header
X-Server
X-Amz-Id-2
Grace
X-LiteSpeed-Cache
X-Rq
X-Swift-CacheTime
X-Swift-SaveTime
X-Varnish-Cache
X-Nginx-Cache-Status
Ali-Swift-Global-Savetime
NEL
X-WebKit-CSP
X-Page-Speed
X-Vhost
EagleEye-TraceId
X-OneAgent-JS-Injection
X-Amz-Version-Id
X-Ua-Compatible
X-Pingback
X-Dns-Prefetch-Control
X-Dispatcher
X-Device
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Cache-Spec
X-Host
Accept-CH
X-Server-Id
Cf-Railgun
X-Node
X-Backend-Server
X-Readtime
Surrogate-Control
X-Akam-SW-Version
Request-Id
X-Response-Time
X-HW
Xkey
X-Application-Context
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Content-Location
Rating
X-Country
X-B3-TraceId
X-Cloud-Trace-Context
Accept-Ch-Lifetime
X-Ruxit-JS-Agent
Accept-CH-Lifetime
X-Cache-Lookup
X-Trace
X-Url
Allow
X-Ac
X-Content-Type
X-Vname
X-TtlSet
X-PC
X-Clacks-Overhead
Edge-Control
X-Aws-Lambda-Call-Status
X-Varnish-TTL
X-Mod-Pagespeed
X-Server-Name
X-ESI
Fastly-Restarts
Cache-Tag
Service-Worker-Allowed
X-VARITI-CCR
X-Rack-Cache
Verso
X-Element-Page-Cache
MS-Author-Via
X-Upstream
X-FastCGI-Cache
X-Vcap-Request-Id
X-MS-InvokeApp
X-Amz-Rid
X-GitHub-Request-Id
Public-Key-Pins
X-Dw-Request-Base-Id
X-Cached
X-Client-IP
X-Abt-Application-Version
X-D2id
X-Cache-TTL
X-Cnection
X-Px
RTSS
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-Navigation-Version
X-Exp-Id
X-Cdn-Fetch
X-Exp-Variant
X-Kinja-Build
X-Use-Magma
X-Kinja-Server
X-Kinja-Revision
X-GoogleNews-Bot
X-Kinja
X-Country-Code
Arr-Disable-Session-Affinity
Access-Control-Request-Method
X-Powered-By-Plesk
X-NF-Request-ID
X-Goog-Hash
X-Instrumentation
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Powered-CMS
AR-ATIME
AR-PoweredBy
AR-Request-ID
AR-SID
AR-CACHE
Display
X-Sol
X-Middleton-Display
Pagespeed
X-Version
X-Origin-Cache
Response
X-Middleton-Response
X-LLID
X-Amz-Server-Side-Encryption
X-MSEdge-Ref
Nginx-Cache
X-Kinsta-Cache
X-Edge-Location-Klb
TCN
X-TTL
X-Edge
Mrf-Cache-Status
MRF-Tech
X-B3-TraceId-Primal
X-Protected-By
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-RateLimit-Remaining
X-T
X-CST
X-HP-Webp
X-Jurisdiction
X-HP-Trace-Id
X-Forwarded-For
X-Shield-Request-Id
X-Content-Security-Policy-Report-Only
X-Id
X-Mg-S
Content-MD5
S
Edge-Cache-Tag
X-Aspnetmvc-Version
Accept-Ch
SPRequestDuration
SPIisLatency
X-Language
X-Ruxit-Js-Agent
Fastcgi-Cache
Front-End-Https
X-Mid
Realpath
X-Request-Received
Server-Node
X-Request-Processing-Time
X-Recruiting
X-Ttl
X-Pinterest-Rid
X-DynaTrace
Pinterest-Version
Filters
Pinterest-Generated-By
X-Frontend
X-Ua-Browser
X-Ab
Server-Name
X-Content
X-MCACHE
X-Correlation-Id
X-NWS-LOG-UUID
X-Ser
X-HS-Content-Id
X-HS-Hub-Id
X-HS-Cache-Config
X-HS-Combine-CSS
X-Yandex-Sdch-Disable
X-Ezoic-Cdn
X-Cache-Key
X-SharePointHealthScore
X-Template
SPRequestGuid
X-Hits
X-Parallel-Accel
X-ECACHE
X-Tt-Trace-Host
MicrosoftSharePointTeamServices
X-Tt-Trace-Tag
X-Kong-Proxy-Latency
Cache-Tags
X-Kong-Upstream-Latency
Charset
X-Page-Id
Host
Alternate-Protocol
X-B3-Sampled
Cleartype
X-Git-Hash
X-Www-Served-By
X-Geo-Country
X-Content-Options
Fusion-Source
Fusion-Template-Id
Fusion-Deployment-Id
Fusion-Content-Source
Fusion-Component-Id
Fusion-Content-Id
X-Daa-Tunnel
X-Debug-Info
X-Webkit-Csp
X-DIS-Request-ID
X-Hostname
X-Amzn-Trace-Id
X-Content-Digest
X-Ratelimit-Limit
X-Amz-Replication-Status
X-Varnish-Age
Filterid
Cross-Origin-Opener-Policy
X-AppVersion
X-Activity-Id
X-XRDS-LOCATION
X-Az
X-FB-Debug
X-Upgrade-Enabled
X-Grace
X-Accel-Expires
X-VCache
X-Fastly-Request-Id
X-WebKit-CSP-Report-Only
X-N
X-F-Cache
ServerID
X-Forwarded-Proto
X-Nginx-Upstream-Cache-Status
X-Rid
X-Origin-Server
Access-Control-Allow-Method
X-Mobile-URL
X-Flags
X-Route-Name
X-Aspnet-Duration-Ms
X-Providence-Cookie
X-Is-Crawler
X-Request-Guid
X-LB-Cache
X-Type
X-TT
TP-Cache
X-Whom
TP-L2-Cache
X-Seen-By
X-Goog-Stored-Content-Encoding
Viewport
X-Varnish-Grace
X-App-Environment
X-Goog-Generation
X-Goog-Metageneration
X-GUploader-UploadID
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
Payment
X-Tb
X-FW-Static
X-Distributor
Node
X-FW-Dynamic
X-FW-Hash
X-FW-Serve
X-FW-Server
X-FW-Type
Paypal-Debug-Id
X-Server-ID
DC
X-User-Agent
X-Fastcgi-Cache
X-DataDome
X-App-Server
Accept-Charset
Country
Fastcgi-Useragent
X-Wix-Request-Id
X-Tec-Api-Version
X-Tec-Api-Root
X-Tec-Api-Origin
X-Fastly-Request-ID
X-Cache-Control
X-Ratelimit-Reset
X-Cache-Rule
X-NGENIX-Cache
X-Litespeed-Cache
X-Via-JSL
Version
X-Origin-Upstream-Status
Referer-Policy
X-Drupal-Cache-Tags
X-Microsite
X-Request-Handler-Origin-Region
X-Cluster-Name
X-Logged-In
X-Contextid
X-Cache-Age
X-Signature
X-B-Cache
X-Buckets
Cache-Status
X-Node-Name
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
Refresh
X-Browser-Type
X-Response-Served-From
X-Load-Cache
SD-X-WS
VIX-Pulpo-Node
X-Original-Request-Id
X-Mobile
X-Varnish-Backend
VIX-Pulpo-Upstream-Status
X-Cache-Expired-At
X-Vgn-Hpd-Reason
X-IPLB-Instance
X-Is-Bot
X-Rendered-As
X-Page-View
X-Real-IP
X-Jobs
X-B
X-Revision
X-Debug
NGB
Access-Control-Request-Headers
X-Cacheable-TTL
X-Proxy-Cache-Status
X-UUID
X-RemovedCookies
X-Cache-Action
X-Device-Type
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Rule
X-Instance
X-Proxy
X-ProcessESI
Akamai-GRN
X-Drupal-Cache-Contexts
Surrogate-Key
X-Debug-IsConnected
X-Framework
X-Debug-IsPreview
X-Cache-Time
X-G
Amp-Access-Control-Allow-Source-Origin
X-FW-Version
CF-IPCountry
SID
X-Air-Source
X-Air-Trace-Id
X-Air-Hostname
X-Accel-Buffering
X-Oracle-Dms-Ecid
DynaTrace
X-Oracle-Dms-Rid
X-Presslabs-Stats
X-Nginx-Cache
GEO-INFO
Count-Hit
X-Cache-NGX
X-Azure-Ref
X-PressLabs-Stats
Liferay-Portal
X-Source
Uber-Trace-Id
X-Ms-Version
X-Cache-Operation
X-Oneagent-Js-Injection
X-Ms-Request-Id
X-Ratelimit-Remaining
X-APP-VERSION
Frame-Options
X-Zen-Fury
Ms-Operation-Id
X-RTag
X-EdgeConnect-Cache-Status
MS-CV
Healthy
Protected
X-XRDS-Location
X-Cache-Hit
X-CDN-Forward
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Environment-Context
X-L-Path
X-Backend-Name
X-Mode
Xserver
Countrycode
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-RateLimit-Limit
Cross-Origin-Window-Policy
X-IPS-LoggedIn
Ec-Rule-Version
X-Varnish-Server
X-Tumblr-User
X-Cache-TTL-Remaining
X-Hyper-Cache
LB
Backend
X-Adobe-Content
X-Adobe-Loc
X-UPSTREAM-Address
X-Detected-As
Meta-Geo
X-JoinUs
X-Servername
X-Rewrite-Enabled
WPO-Cache-Status
X-Tid
X-Region
X-Content-Age
X-SaId
X-RN-RSRV
X-Forwarded-Host
WPO-Cache-Message
X-Hosted-By
X-Generation-Time
X-Format
X-Debug-Cache
X-Sorting-Hat-ShopId
X-Sql-Count
X-Sorting-Hat-PodId
Content-Disposition
X-Proxied
X-Sql-Duration-Ms
Apigw-Requestid
Country-Code
Decoy-Debug-Key
Decoy-Debug-Status
Decoy-Debug-TTL
X-Zipkin-Id
X-Alternate-Cache-Key
X-Cache-Server
X-ShopId
X-Redis-Cache
X-ShardId
X-Shopify-Stage
Eomportal-Instance
X-Uri
X-Extlb
X-Trace-Id
X-Routing-Service
X-Cache-Grace
X-Human
Cache-Name
Mn-Server-Ip
X-Access
X-ApacheServer
X-FB-TRIP-ID
Url
Section-Io-Cache
Fastly-SSL
X-Content-Powered-By
X-PHP-Backend
X-ServerID
X-Varnish-Beresp-Grace
X-Microcachable
X-Via-Fastly
X-PERF
X-Section
X-NCache
X-No-Session
X-OCL
X-Site-Version
X-Status
X-Origin-Date
X-PCL
TWC-GeoIP-LatLong
X-SayCDN-TTL
Webcakes-App-Name
X-Storage
TWC-GeoIP-Country
CDN-Uid
TWC-Locale-Group
CDN-RequestCountryCode
X-Server-W
CDN-RequestId
Webcakes-App-Version
Property-Id
TWC-Connection-Speed
Selected-Fe
TWC-Device-Class
X-Timing-Wait
X-Pubstack
X-Cluster-Node
X-Say-Cacheable
X-ProxyCache-Status
X-ProxyCache-Key
X-NYM-Debug-Backend
X-Origin-Hint
X-Proxy-Build
X-Cache-Type
X-Cache-Host
CDN-EdgeStorageId
CDN-PullZone
X-Say-TTL
CDN-CachedAt
X-Akamai-Edgescape
X-BYPASS-REASON
CDN-Cache
X-UA-Device-Type
Webcakes-Region
TWC-Privacy
Cache-Tv-Group
X-Soup
X-Generated-By
X-Be
X-Web-Node
X-R9-Blue-Green-Version
X-Hl-Ver
X-Varnishpool
Azure-SlotName
Azure-SiteName
Azure-RegionName
Azure-InstanceId
Azure-Version
X-TIME
Content-Secure-Policy
X-Ua
X-LSADC-Cache
Retry-After
X-NewRelic-App-Data
DB-Nickname
X-Nginx-Cache-Key
X-Webkit-CSP
X-Cached-By
OT-Force-Account-Verify
X-Dc
X-Azure-Ref-OriginShield
Source
X-Unique-Id
X-Bc-Bl
X-Cache-Remote
X-Akamai-Transformed
Cache
SRV
X-TT-LOGID
X-Platform-Server
X-Auto-Login
X-Xfnlog-Site
X-LAGOON
X-EC-Lua
ServedBy
HostName
X-SRV
X-GEO
X-Cache-Tags
Upgrade-Insecure-Requests
Cache-Hits
X-ECache
X-Origin-TTL
X-Origin-CC
X-Varnish-Hits
From-Origin
X-Loop
X-Varnish-Cache-Hits
X-HTML-Minification-Powered-By
X-Cdn
X-Varnish-Hostname
X-CSRF-Token
X-TNCMS
Onion-Location
X-S-Maxage
Mime-Version
Xet-Cookie
X-Request-Time
X-App-Version
X-AOL-HN
X-Request-Host
X-NWS-UUID-VERIFY
Webserver
WP-Super-Cache
X-Tumblr-Pixel-2
X-Time
Web-Mar-Node
X-Amz-Meta-S3cmd-Attrs
X-Tumblr-Pixel-3
N-Cache
X-Proto
X-Cache-Enabled
X-Tenant
X-Handled-By
X-FireWall-Port
X-Endurance-Cache-Level
X-VWS-Id
AMP-Access-Control-Allow-Source-Origin
X-AWS-Id
X-LJ-Flow-ID
X-GG-Cache-Date
X-Origin-Response-Time
X-Time-Microsecs
X-B3-SpanId
Fastcgi-X-Cache-Version
X-ScT
X-S-Cookie
X-S
BehaviorPad-Version
X-A-Wwc
X-Cluster
Nel
X-B-Cookie
A
X-Aed
X-SRCache-Key
X-Ckpd-Fst-Backend
X-Planisys-CDN-Cache
Expiry
X-Block-Status
X-Cache-NE
X-Slack-Backend
X-Adobe-Source
X-Planisys-CDN-TTL
X-Aicache-OS
DCR-Decision-By
DCR-Processing-Time-Ms
X-Session-Fingerprint
X-Shop-Environment
X-Application
X-Rojux
X-SD-PageType
X-CF-Lambda-Fn
X-Processor
X-ARC
X-Conf
X-RCS-CacheZone
X-Planisys-CDN-Rules
X-Reqid
X-Backend-TTL
X-CF-Lambda-Version
X-Destination
Vix-Hermes-Req-Id
X-PBS-Appsvrname
X-Forwarded-Path
X-Orig-Expires
V-Age
Odigeo-Trace-Id
Xc-Version
Mobile-Detection-Method
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
X-Epic-Correlation-Id
X-Ftr-Request-Id
X-Edge-Location
X-NAPM-TraceId
Sslversion
X-Hnp-Log
Surrogated-Key
X-ND-Cache
Rendered-Blocks
User-Cache-Control
X-Gen-Mode
Pramga
Redirect-Candidate
Meta-Geo-Continent
X-External-Request-Id
X-A-Dam
X-A-Ccd
X-Developer
X-V-Cache
X-PAYTM-SRV-ID
X-D
X-Correlation-ID
X-A-Dcw
X-A
X-A-Dgt
X-Vdms-Version
X-TIM-N
X-Vdms-Path
X-VG-WebCache
X-Connection-Hash
X-Ig-Push-State
X-Mg-Request-UUID
X-MP-GENERATED-AT
X-Magnolia-Registration
Apple-News-Services-Request-Url
Arc-Country
Svr
X-Accel-Expires-Debug
CDCHOST
Gh-Request-Id
X-Proxy-Upstream
X-NodeID
True-Client-Country-4JS
X-Li-Pop
CacheControlHeader
X-Mvc-Supplant-Cachable
X-Nyt-Route
Host-ID
X-Origin-Expires
X-LI-UUID
X-Origin
Wxu-Next-Region
X-Origin-Time
Wxu-Next-Hostname
DSUID
Origin
X-Location
X-Old-Content-Length
Cmstype
X-Men
Wxu-Next-Commit
Fastcgi-Cache-TTL
Apple-News-Services-Parsed-Url
X-Policy
Cmsid
X-Sucuri-ID
X-Amzn-RequestId
X-Geo-Header
X-Cache-Var
X-Amz-Apigw-Id
X-SVT-ORM-VERSION
X-Labrador-Cache-Channel
State
X-SVT-ORM-RULES
X-Cache-Var-Map
Apple-News-Services-Host
X-PHP-Host
X-Fastly-Cache
X-Webstats-RespID
X-Forwarded-Site
X-Viewer-Country
X-Date
X-Gdpr
X-VG-TLSProxy
X-Cdn-Srv
X-Sucuri-Cache
AKAMAI
X-Cache-Bucket
X-Rocket-Nginx-Serving-Static
X-GeoIP-Region-Code
X-Request-URI
CloudFront-Viewer-Country
X-Li-Fabric
X-Hash
X-Scheme
Apple-News-Services-Handled
X-Cache-Info
S-Rt
X-GeoIP-Country-Code
X-Server-IP
X-Cache-Date
Environment
Server-Info
X-Varnish-Ttl
X-Fastly-Backend
X-Fetched-On
X-Generated-On
Traceparent
X-GeoIP
X-GeoIP-City
X-Gamma-Serve
X-Gzip
X-HS-Content-Campaign-Id
X-Datadog-Trace-Id
X-Cdn-Origin
X-CGP
X-Irp-Debug
X-Core-Mission
X-Cache-Id
X-Cache-Debug
X-Backend-State
X-BBC-Edge-Cache-Status
X-Level-Front-Cache
X-Branch-Name
X-Core-Value
X-Csrf-Jwt
We-Hiring
X-Envoy-Decorator-Operation
X-Locale
X-Esi-Check
Web-Mar-Region
X-Device-Os
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
X-Developers
X-Eu-Site
X-Region-Sid
X-Req
X-HN
X-Rocket-Build-Number
X-Served-From
X-Sigma
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
HA-Ipaddr
Ha-Gx-Prefs
Fastly-GeoIP-CountryCode
X-Platform
X-Sigma-Backend
Ssr
X-VarnishDD-TTL
X-VServer
X-Akamai-Request-ID2
X-Http-Reason
X-Varnish-Beresp-Status
X-UnsetCookies
X-Sn-Servicetimems
X-Storefront-Renderer-Rendered
X-TH-Server
X-TrackingId
L
X-Skip-Cache
PFcat
Origin-EX
Release
Server-Host
Req-Svc-Chain
X-Owner
Origin-CC
Mail-Subject
L5d-Success-Class
Machine
Locid
X-Via-NSCOPI
X-Is-Gdpr
X-NU-AKA-ACS-Version
X-Varnish-Remaining-TTL
X-DPWN-IS-SECURE
X-JWT-State
Thinkindot-CacheControl
X-Node-Id
X-DefHash
Thinkindot-Control
X-DefElseHash
Thinkindot-CacheControl-Type
X-Varnish-CookieHashed-On
X-Varnish-Beresp-Ttl
X-Varnish-CookieINHashed-On
X-Thinkindot-L3
Is-Eu
Fastly-SWR
Fastly-Drupal-Html
X-ATG-Version
Memcached
Adler-Geo
X-Rebelmouse-Cache-Control
X-Loc
X-Qloud-Router
X-Amzn-Remapped-Content-Length
X-Has-Esi
Cf-Device-Type
X-Rebelmouse-Surrogate-Control
NM-Fastcgi-Cache
X-Worker
Fastly-SIE
X-Pod-Name
X-Variation
X-Response-By
TDXMobile
X-FC-Vary-Parameters
Magicmarker
Platform
X-VC-Cache
X-Xrds-Location
X-Request-Start
NGX
X-Restarts
X-M-Reqid
X-TraceId
X-Qnm-Cache
X-M-Log
X-Ua-Device
X-API-Version
X-CS
X-NC
X-Bip
Kp-EeAlive
X-Thanos
X-LB-ID
X-Up
X-Tx-Id
X-Zone
X-DW
X-RPM
X-RPS
Edge-Cache
X-Wix-Viewer-Type
X-Cache-Backend
X-DSS
X-RSL
X-Mvc-Supplant-OutputCached
X-DB
X-Action
X-DI
CDN
X-Generated-In
X-CACHE-KEY
Accept-Language
X-LB-NoCache
X-Cache-Config
Time
Ms-Author-Via
X-Trace-ID
Memory
Pics-Label
X-Tb-Optimization-Total-Bytes-Saved
X-Tt-Logid
X-Refresh
X-Via-Poph
X-Via-Popv
X-Edge-Pop
X-Minions-Version
Env
X-CacheTTL
X-Via-Popn
X-Optimistic-Header
X-Srv
X-Datadome
GeoIp-Country-Code
X-HA-Backend
WebServer
Locale
X-Urbn-Context-Path
X-Urbn-Site-Id
X-ZONE
Candidate-Md5Url
NtCoent-Length
Datacenter
X-DC
X-DynaTrace-JS-Agent
X-TX-ID
X-Vc
X-TA-CDN-Provider
WWW-Authenticate
On-Server
X-Esi
Server-ID
X-Cs
X-Ec-Fail
X-User
X-Ec-GeoHdr
X-Parent-Response-Time
X-MSEdge-Features
X-Servedbyhost
X-MSEdge-Flight
Esi-Enabled
X-Unique-ID
X-CLOUD-TRACE-CONTEXT
X-Varnish-Beresp-TTL
Cdnsip
X-Li-Proto
C-Via
X-Service
X-AK-Request-ID
X-Cache-PHP
Cdncip
X-Newrelic-Synthetics
X-Fmm-Version
X-VCL-Version
Geoip-Latitude
My-App
X-FPC
Cluster
X-Cache-Ttl
X-Clara-WADP
X-WADP-Cache
X-App
X-URL
Proxy-Connection
X-B3-Spanid
X-Fpc
X-Webkit-Csp-Report-Only
X-LI-Proto
X-CUA
X-Vcl-Version
X-Var-Ttl
Tracecode
Test
X-Dynatrace
Geo-Info
X-Traceid
X-Pass-Why
DataCenter
Cf-Int-Pingora-Origin-Digest
Fastly-Drupal-HTML
X-Cache-Status-Check
T-Server
X-From
X-Render-Time
Lfy
X-Webkit-CSP-Report-Only
X-LiteSpeed-Cache-Control
X-NODE
Lang
X-VC
X-Fragments
X-Mcache
Server-Id
M-TraceId
Target-Params
Resin-Trace
MIME-Version
X-ServedByHost
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
X-CSRF-TOKEN
X-Ha-Backend
X-RAMCache
X-Clientip
X-Provided-By
X-Geo
X-ID
Hostname
X-Cdn-Forward
Permissions-Policy
X-Info
GeoIP-Country-Code
Hit
X-AIR-PT
X-Proxy-Cache-Info
X-Oss-Server-Time
X-Oss-Request-Id
X-LiteSpeed-Tag
X-Oss-Storage-Class
HIT
Cache-Host
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
UCS
X-Httpd
X-Dynatrace-Js-Agent
Producers
X-Check-Cacheable
X-Edge-POP
Section-Origin-Responded
WZWS-RAY
S-Cnection
Servername
X-Pad
X-Via-PopN
ENV
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
X-Via-PopH
X-Via-PopV
Section-Io-Id
X-Api-Version
X-Fastly-Backend-Reqs
FSS-Cache
X-SB
X-Edge-Cache
X-NGINX-Cache
Ohc-File-Size
X-Udemy-Cache-App-Namespace
X-Platform-Router
Fastly-Backend-Name
PICS-Label
X-Micro-Cache
X-Platform-Processor
X-Pool
X-ElasticPress-Query
User-Agent
X-BBC-Origin-Response-Status
X-Platform-Cluster
X-ServerName
X-Ucs
X-Lb-Nocache
X-HS-Status
Load-Balancing
X-GoCache-CacheStatus
X-Release
X-Acquia-Purge-Tags
X-Acquia-Application-UUID
X-Acquia-Site
X-Backend-Host
Uri
URI
X-Cache-CFC
X-Scale
X-UP
ServerName
X-Ec-Custom-Error
X-Acquia-Application-Trace
X-Srcache-Fetch-Status
X-Srcache-Store-Status
X-TRACE-ID
Server-Hostname
X-Dispatcher-Number
Server-Ttl
X-SIPLIST1
Server-Ext
X-Cache-Expires
MD5-Digest
IsBot
Sever-Int
X-Swift-Error
Cneonction
EpKe-Alive
X-RateLimit-Reset
X-Cdn-Request-ID
Cteonnt-Length
Cdn
X-Lb-Id
X-Nc
X-BCube-Filmed-By
X-Fastly-Cache-Hits
X-APP
Tcn
X-Dw-Trace-Id
Path
X-Snapshot-Date
X-Via-Ucdn
X-Akamai-ERRuleID
X-Contensis-Viewer-Groups
Ohc-Cache-HIT
Shield-Pop
X-Cache-ASPX
Cf-Ipcountry
X-Akamai-ERPolicy
CF-Cached-On
X-Newrelic-App-Data
X-B3-ParentSpanId
X-Vcache
Vha6-Origin
Wpo-Cache-Status
Wpo-Cache-Message
X-Yottaa-OS
X-Air-Pt
Sid
X-Cache-Ngx
X-HostName
CPC-Cache
Ngx
X-Shopify-Generated-Cart-Token
X-Akamai-Pragma-Client-IP
VNS-Age
X-IN-APIGATEWAYSSL
Req-ID
X-Litespeed-Cache-Control
CountryCode
X-IN-APIGATEWAY
X-Sentry-ID
VNS-Cache
X-B3-Parentspanid
X-Amz-Meta-Cb-Modifiedtime
CPC-Age
X-UA
X-Apw-Access-Object
X-Apw-Access-Action
X-Varnish-Authentication
X-Te-Duration-Ms
X-Te-Count
X-Http-Count
X-Http-Duration-Ms
X-Apw-Hits
X-Last-Modified
X-Apw-Access-Token
X-Akamai-Request-ID
X-CacheKey
X-WA
X-Logging-Id
X-WA-Info
Cache-Key