Threat Level: green Handler on Duty: Guy Bruneau

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Accept-Ranges
Cf-Request-Id
CF-Cache-Status
Link
CF-RAY
ETag
Pragma
Expect-CT
X-XSS-Protection
X-Powered-By
Via
X-Cache
Age
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
Alt-Svc
P3P
X-Served-By
X-Xss-Protection
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
X-Runtime
X-AspNet-Version
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Cache-Status
X-Generator
X-Cacheable
X-Check
Timing-Allow-Origin
X-Request-ID
P3p
X-FRAME-OPTIONS
X-Iinfo
Feature-Policy
X-Content-Security-Policy
X-Envoy-Upstream-Service-Time
Content-Encoding
Status
X-Drupal-Dynamic-Cache
Access-Control-Expose-Headers
X-AspNetMvc-Version
X-CONTENT-TYPE-OPTIONS
X-CDN
Upgrade
X-Via
X-XSS-PROTECTION
CF-Ray
Access-Control-Max-Age
X-Ws-Request-Id
Server-Timing
X-Cache-Group
X-Turbo-Charged-By
X-Backend
Keep-Alive
Request-Context
EagleId
X-Age
X-Robots-Tag
X-Server
X-AH-Environment
X-Amz-Request-Id
Host-Header
X-Proxy-Cache
X-Akamai-Path-Stats
X-Amz-Id-2
X-UA-Device
X-Hacker
Grace
X-Rq
X-Dns-Prefetch-Control
X-Server-Powered-By
X-Swift-SaveTime
X-Swift-CacheTime
X-Varnish-Cache
Ali-Swift-Global-Savetime
X-Vhost
X-LiteSpeed-Cache
X-Amz-Version-Id
X-Dispatcher
X-Ua-Compatible
CONTENT-SECURITY-POLICY
EagleEye-TraceId
Allow
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-WebKit-CSP
X-Nginx-Cache-Status
X-OneAgent-JS-Injection
X-Device
X-Cache-Spec
Cf-Railgun
X-Page-Speed
X-Host
X-Node
X-Server-Id
X-CST
X-Pingback
X-Aws-Lambda-Call-Status
Surrogate-Control
Request-Id
X-Backend-Server
Accept-CH
X-Akam-SW-Version
X-Readtime
Cf-Edge-Cache
X-Cache-Lookup
X-Response-Time
X-HW
Xkey
X-Application-Context
Content-Location
X-ASPNET-VERSION
Accept-CH-Lifetime
Rating
X-Cloud-Trace-Context
X-Url
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Trace
Accept-Ch-Lifetime
Fastly-Restarts
X-Country
X-MS-InvokeApp
X-Mod-Pagespeed
X-Rack-Cache
X-Vname
X-TtlSet
X-PC
X-Clacks-Overhead
X-Ruxit-JS-Agent
X-Server-Name
RTSS
Edge-Control
X-Varnish-TTL
X-VARITI-CCR
X-ESI
X-B3-TraceId
X-Content-Type
Cache-Tag
X-Vcap-Request-Id
Accept-Ch
X-Amz-Server-Side-Encryption
X-Kinja-Build
X-Use-Magma
X-Kinja-Revision
X-Cdn-Fetch
X-Exp-Id
X-Exp-Variant
X-Kinja-Server
X-GoogleNews-Bot
X-Kinja
X-Amz-Rid
X-Dw-Request-Base-Id
Public-Key-Pins
X-Px
X-Cnection
X-Ac
X-RateLimit-Remaining
X-D2id
X-Element-Page-Cache
X-Navigation-Version
Verso
X-Edge
X-Abt-Application-Version
X-Client-IP
X-Sol
X-Middleton-Display
X-Powered-By-Plesk
Display
Pagespeed
X-Cache-TTL
X-Ser
X-FastCGI-Cache
X-Version
Service-Worker-Allowed
Arr-Disable-Session-Affinity
X-GitHub-Request-Id
X-Country-Code
X-Ruxit-Js-Agent
X-Middleton-Response
Response
X-NF-Request-ID
X-Correlation-Id
Access-Control-Request-Method
X-Goog-Hash
X-Ttl
X-Kinsta-Cache
SPRequestDuration
SPIisLatency
X-Edge-Location-Klb
AR-SID
AR-Request-ID
AR-ATIME
AR-PoweredBy
AR-CACHE
X-Cached
X-Upstream
X-Webkit-Csp
X-Ua-Device
X-RateLimit-Limit
X-TTL
X-Server-Lifecycle-Phase
X-LLID
X-NWS-LOG-UUID
X-Instrumentation
X-Kraken-Loop-Name
X-Content-Security-Policy-Report-Only
SPRequestGuid
X-Powered-CMS
X-SharePointHealthScore
Edge-Cache-Tag
Nginx-Cache
X-Forwarded-For
X-Cache-Key
X-Litespeed-Cache
TCN
Content-MD5
X-MSEdge-Ref
Mrf-Cache-Status
MRF-Tech
X-Shield-Request-Id
X-Daa-Tunnel
X-B3-TraceId-Primal
X-Id
X-T
MS-Author-Via
X-Recruiting
S
X-Content-Digest
X-Mg-S
X-TEC-API-VERSION
X-ECACHE
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Protected-By
X-HP-Trace-Id
X-Jurisdiction
MicrosoftSharePointTeamServices
X-HP-Webp
X-SRCache-Fetch-Status
X-DataDome
X-Ezoic-Cdn
X-Accel-Expires
X-SRCache-Store-Status
X-HS-Content-Id
X-HS-Cache-Config
X-HS-Combine-CSS
X-Frontend
X-HS-Hub-Id
X-Grace
X-Ab
X-Ua-Browser
X-Content
X-Request-Received
Front-End-Https
X-Request-Processing-Time
X-Yandex-Sdch-Disable
Server-Node
Filters
X-DynaTrace
X-Mid
TP-L2-Cache
X-Server-ID
Fastcgi-Cache
TP-Cache
X-Origin-Server
X-Geo-Country
X-Hits
X-Distributor
X-PressLabs-Stats
X-WebKit-CSP-Report-Only
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-Ratelimit-Reset
X-Microsite
X-Request-Handler-Origin-Region
X-Debug-Info
X-Amzn-Trace-Id
X-Tt-Trace-Host
Charset
Cleartype
X-Tt-Trace-Tag
X-Page-Id
Host
X-Git-Hash
X-LB-Cache
X-DIS-Request-ID
X-F-Cache
X-B3-Sampled
Cross-Origin-Opener-Policy
X-Pinterest-Rid
Pinterest-Version
Pinterest-Generated-By
X-Www-Served-By
X-Forwarded-Proto
X-Cache-Age
Access-Control-Allow-Method
ServerID
X-Seen-By
Cache-Status
X-Az
X-Activity-Id
X-MCACHE
X-AppVersion
Realpath
Cache-Tags
Accept-Charset
X-Cluster-Name
X-Varnish-Age
Filterid
X-Language
X-Rid
X-Aspnetmvc-Version
X-Kong-Upstream-Latency
X-Oracle-Dms-Ecid
X-Kong-Proxy-Latency
X-Oracle-Dms-Rid
Server-Name
X-Nginx-Upstream-Cache-Status
X-Type
X-Content-Options
X-App-Environment
Retry-After
X-Upgrade-Enabled
Viewport
X-Origin-Cache
X-XRDS-LOCATION
X-Varnish-Grace
X-Tb
Node
Country
X-User-Agent
X-Whom
X-Aspnet-Duration-Ms
X-Is-Crawler
X-Providence-Cookie
DC
X-Request-Guid
X-Route-Name
X-Drupal-Cache-Tags
X-Signature
X-Wix-Request-Id
Paypal-Debug-Id
X-B-Cache
X-Flags
X-FB-Debug
X-Mobile-URL
X-NWS-UUID-VERIFY
X-Varnish-Backend
X-TT
X-Fastly-Request-Id
X-GUploader-UploadID
X-Goog-Metageneration
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-VCache
X-Goog-Generation
Fastcgi-Useragent
Protected
X-N
X-B
X-Via-JSL
X-Debug
X-Amz-Replication-Status
X-Cache-NGX
Payment
X-Logged-In
X-Contextid
X-Fastly-Request-ID
WPO-Cache-Status
WPO-Cache-Message
X-Fastcgi-Cache
X-Load-Cache
Surrogate-Key
X-Mcache
X-Amz-Meta-S3cmd-Attrs
X-Template
X-Cache-Control
Count-Hit
X-FW-Hash
X-FW-Dynamic
Permissions-Policy
X-FW-Serve
X-FW-Server
X-FW-Type
X-FW-Static
X-Node-Name
X-Trace-Id
X-Erf-Bev-Bev-Is-Generated
X-Browser-Type
Healthy
X-Erf-Bev-Bev
Amp-Access-Control-Allow-Source-Origin
X-G
X-Original-Request-Id
X-Response-Served-From
SD-X-WS
X-Mobile
X-Proxy
X-Jobs
Refresh
Content-Disposition
X-Cache-Time
Akamai-GRN
X-Zen-Fury
X-Hostname
X-Akamai-Request-ID2
X-Revision
X-Cacheable-TTL
Uber-Trace-Id
X-Is-Bot
X-XRDS-Location
X-Real-IP
X-UUID
X-Rendered-As
X-Framework
X-Adobe-Loc
X-Cache-TTL-Remaining
X-Adobe-Content
Alternate-Protocol
X-Proxy-Cache-Status
X-Http-Reason
X-Page-View
Access-Control-Request-Headers
X-Drupal-Cache-Contexts
X-Device-Type
X-Debug-IsPreview
X-Debug-IsConnected
NGB
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Instance
Url
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Servername
X-IPLB-Instance
X-Cache-Grace
Version
X-COUNTRY
X-Source
X-Restarts
X-NGENIX-Cache
X-Varnish-Server
X-Mg-Request-UUID
X-ECache
X-L-Path
From-Origin
X-Cache-Rule
X-Environment-Context
X-B3-Traceid
Accept-Language
X-Cache-Hit
X-Vgn-Hpd-Reason
X-EdgeConnect-Cache-Status
X-Cache-Expired-At
X-Oneagent-Js-Injection
X-Parallel-Accel
Countrycode
X-RTag
MS-CV
Ms-Operation-Id
X-HTML-Minification-Powered-By
Referer-Policy
X-App-Server
Frame-Options
X-Datadome
X-NYM-Debug-Backend
Liferay-Portal
X-Tumblr-User
X-Tumblr-Pixel-1
X-FW-Version
X-Tumblr-Pixel-0
X-Tumblr-Pixel
Cross-Origin-Window-Policy
X-IPS-LoggedIn
Backend
X-RemovedCookies
Content-Secure-Policy
X-ProcessESI
X-APP-VERSION
Section-Io-Cache
X-Cache-Action
X-Midtier
WP-Super-Cache
X-Nginx-Cache
X-Redis-Cache
X-RN-RSRV
Cache-Tv-Group
X-UPSTREAM-Address
Meta-Geo
Upgrade-Insecure-Requests
X-Hosted-By
X-Cache-Server
CF-IPCountry
X-PCL
X-Detected-As
X-UA-Device-Type
X-Generation-Time
X-Ua
X-Content-Age
X-No-Session
X-Cache-Enabled
X-Web-Node
X-OCL
X-Region
X-FB-TRIP-ID
X-Cluster-Node
X-Access
Azure-Version
TWC-Locale-Group
Azure-SlotName
Locale
Azure-RegionName
Azure-SiteName
Property-Id
Fastly-SSL
TWC-Device-Class
TWC-GeoIP-Country
TWC-GeoIP-LatLong
TWC-Connection-Speed
S-Rt
Ec-Rule-Version
Azure-InstanceId
Apigw-Requestid
Webcakes-App-Version
X-ShardId
X-Alternate-Cache-Key
Webcakes-Region
X-AOL-HN
X-Akamai-Edgescape
X-ShopId
X-Shopify-Stage
X-Unique-Id
TWC-Privacy
Webcakes-App-Name
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Be
X-Sql-Count
X-Server-W
X-Site-Version
X-Section
X-SayCDN-TTL
X-Request-Time
X-Say-TTL
Mn-Server-Ip
X-Sql-Duration-Ms
X-Varnish-Cache-Hits
X-Via-Fastly
X-Uri
X-Urbn-Site-Id
X-Storage
X-Urbn-Context-Path
X-PHP-Backend
X-Say-Cacheable
X-Nginx-Cache-Key
X-Human
X-Origin-Date
X-Generated-By
X-Format
X-Origin-Hint
X-Mode
CDN-PullZone
CDN-RequestCountryCode
CDN-EdgeStorageId
X-Debug-Cache
CDN-Cache
X-Content-Powered-By
X-Status
X-Cache-Tags
X-NewRelic-App-Data
CDN-CachedAt
CDN-Uid
X-Xfnlog-Site
CDN-RequestId
X-BYPASS-REASON
X-Cache-Host
Eomportal-Instance
X-PERF
X-ApacheServer
X-Forwarded-Host
X-Adobe-Source
X-ProxyCache-Status
X-ProxyCache-Key
X-Platform-Server
X-Extlb
X-Varnishpool
X-Zipkin-Id
X-Handled-By
X-Hyper-Cache
X-Routing-Service
X-Backend-Name
X-Proxied
X-JoinUs
X-SaId
X-Cache-Type
X-Hl-Ver
X-ServerID
X-Tid
X-Locale
X-Labrador-Cache-Channel
X-PHP-Host
X-TT-LOGID
X-Dc
X-Proxy-Build
X-Ratelimit-Remaining
X-Timing-Wait
Selected-Fe
X-VWS-Id
X-AWS-Id
X-LJ-Flow-ID
ServedBy
X-Rule
X-Webkit-CSP
Webserver
X-VC-Cache
X-GG-Cache-Date
X-Cache-Operation
X-Edge-Location
X-Storefront-Renderer-Rendered
X-LSADC-Cache
X-Cms-Context
X-Accel-Buffering
SID
X-Proto
SRV
Web-Mar-Node
X-Rewrite-Enabled
X-CDN-Forward
X-Cached-By
Fastly-Drupal-Html
Mime-Version
X-Soup
X-Cache-Remote
Load-Balancing
Onion-Location
Xserver
X-GeoCountry
X-GeoCode
X-Varnish-Hostname
X-Pubstack
X-App-Version
X-GEO
Cache-Hits
X-Reqid
X-TA-CDN-Provider
Country-Code
X-Buckets
X-Cdn
X-Request-Host
X-Cluster
X-Origin-TTL
X-Origin-CC
X-Varnish-Hits
X-Microcachable
Decoy-Debug-Status
Decoy-Debug-TTL
Decoy-Debug-Key
Server-Info
X-SRV
X-Envoy-Decorator-Operation
X-Tumblr-Pixel-2
X-Tumblr-Pixel-3
LB
X-Ratelimit-Limit
X-MP-GENERATED-AT
X-Ms-Version
X-Magnolia-Registration
X-Ms-Request-Id
X-Air-Hostname
X-Air-Trace-Id
X-Air-Source
X-B3-SpanId
X-CSRF-Token
X-Amzn-RequestId
X-NCache
X-Amz-Apigw-Id
DB-Nickname
Cache
Xet-Cookie
X-Time
X-Endurance-Cache-Level
X-RCS-CacheZone
X-Tec-Api-Version
X-Tec-Api-Origin
X-Tec-Api-Root
X-Bc-Bl
DynaTrace
Odigeo-Trace-Id
Pramga
X-A-Ccd
DCR-Decision-By
T-Server
X-A
Surrogated-Key
Sslversion
Rendered-Blocks
X-A-Dam
A
Cdnsip
BehaviorPad-Version
Lang
Fastcgi-X-Cache-Version
Host-ID
Expiry
MD5-Digest
Mobile-Detection-Method
NM-Fastcgi-Cache
Meta-Geo-Continent
Cdncip
Cmsid
Cmstype
DCR-Processing-Time-Ms
X-D
X-Rojux
X-Processor
X-S
X-S-Cookie
X-SD-PageType
X-ScT
X-PBS-Appsvrname
X-PAYTM-SRV-ID
X-Ig-Push-State
X-HS-Content-Campaign-Id
X-NAPM-TraceId
X-Node-Id
X-Orig-Expires
X-Session-Fingerprint
X-Shop-Environment
X-Vdms-Version
X-Vdms-Path
X-VG-WebCache
X-Vtex-Processado-Em
Xc-Version
X-Vtex-Remote-Cache
X-User
X-TrackingId
X-SVT-ORM-RULES
X-SRCache-Key
X-SVT-ORM-VERSION
X-Tenant
X-TIM-N
X-Hash
X-Gzip
X-Cache-Id
X-Cache-Bucket
X-Cdn-Srv
X-CF-Lambda-Fn
X-Conf
X-CF-Lambda-Version
X-B-Cookie
X-ARC
X-A-Wwc
X-A-Dgt
X-Aed
X-AK-Request-ID
X-Application
X-Connection-Hash
X-Core-Mission
X-Fetched-On
X-External-Request-Id
X-Forwarded-Path
X-Ftr-Request-Id
X-Geo-Header
X-Esi-Check
X-Epic-Correlation-Id
X-Developer
X-Destination
X-Device-Os
X-Ec-Fail
X-Ec-GeoHdr
X-A-Dcw
X-Cache-NE
X-Varnish-Beresp-Grace
CDN
Cache-Name
X-Tx-Id
Source
X-R9-Blue-Green-Version
X-Rocket-Build-Number
X-Amzn-Remapped-Content-Length
X-TNCMS
X-Planisys-CDN-TTL
Wxu-Next-Region
Origin-CC
X-Planisys-CDN-Rules
X-Wix-Viewer-Type
X-Block-Status
X-Cache-Backend
Memcached
X-Planisys-CDN-Cache
X-Worker
X-Thinkindot-L3
Wxu-Next-Hostname
Wxu-Next-Commit
TDXMobile
Thinkindot-CacheControl
Platform
State
Release
Server-Host
Thinkindot-CacheControl-Type
Thinkindot-Control
User-Cache-Control
Web-Mar-Region
X-Azure-Ref
Traceparent
X-Webstats-RespID
Origin-EX
Producers
X-Origin-Response-Time
X-Gen-Mode
X-GeoIP
X-Mvc-Supplant-Cachable
X-Gdpr
X-From
X-Fastly-Cache
X-Fmm-Version
X-Has-Esi
X-Hnp-Log
X-Loop
X-Location
X-LAGOON
X-JWT-State
X-Irp-Debug
X-Is-Gdpr
X-NodeID
X-Nyt-Route
X-Origin
X-Ckpd-Fst-Backend
X-CacheTTL
X-Cache-Info
X-Origin-Time
X-Origin-Expires
X-Clara-WADP
X-Core-Value
X-DPWN-IS-SECURE
X-Ec-Custom-Error
X-Dispatcher-Number
X-Developers
X-DefElseHash
X-DefHash
X-Cache-Date
We-Hiring
X-Varnish-CookieHashed-On
Mail-Subject
AKAMAI
CloudFront-Viewer-Country
X-SB
Fastly-GeoIP-CountryCode
X-Variation
Environment
Adler-Geo
X-Varnish-CookieINHashed-On
X-Skip-Cache
X-Slack-Backend
X-IPLB-Request-ID
X-Sigma-Backend
X-VServer
X-Varnish-Remaining-TTL
X-Server-IP
X-Sigma
Is-Eu
X-Scheme
X-V-Cache
X-WADP-Cache
Machine
X-Varnish-Ttl
X-ZONE
X-Request-URI
X-Aicache-OS
X-Sn-Servicetimems
X-Datadog-Trace-Id
Origin
DSUID
X-Platform
Fastcgi-Cache-TTL
X-Pod-Name
X-Policy
N-Cache
X-Eu-Site
X-VarnishDD-TTL
NGX
X-Auto-Login
X-Datadog-Sampling-Priority
X-Served-From
Apple-News-Services-Handled
CDCHOST
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
X-CGP
Apple-News-Services-Request-Url
X-Cdn-Origin
X-Via-Ucdn
X-Csrf-Jwt
X-Level-Front-Cache
X-Datadog-Parent-Id
PFcat
X-BBC-Edge-Cache-Status
Cluster
X-Region-Sid
X-Branch-Name
X-Forwarded-Site
X-Rocket-Nginx-Serving-Static
X-Via-NSCOPI
X-RateLimit-Limit-Second
Server-Hostname
Sever-Int
X-Loc
X-Qloud-Router
IsBot
Ssr
Kp-EeAlive
Server-Ext
Req-Svc-Chain
X-Httpd
L
X-Minions-Version
X-Rebelmouse-Surrogate-Control
X-RateLimit-Remaining-Second
X-Rebelmouse-Cache-Control
Svr
X-HN
X-VG-TLSProxy
Vix-Hermes-Req-Id
V-Age
Fastly-SWR
Fastly-SIE
X-Pool
X-Gamma-Serve
X-Viewer-Country
X-Proxy-Cache-Info
X-Generated-On
X-SIPLIST1
L5d-Success-Class
X-Proxy-Upstream
HA-Ipaddr
Ha-Gx-Prefs
Gh-Request-Id
X-GeoIP-City
Redirect-Candidate
X-Optimistic-Header
HostName
Ohc-File-Size
X-Scale
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
X-Xrds-Location
X-CS
X-Newrelic-Synthetics
AMP-Access-Control-Allow-Source-Origin
Pics-Label
X-EC-Lua
X-Refresh
X-Tb-Optimization-Total-Bytes-Saved
X-NC
X-TraceId
X-Owner
Locid
Arc-Country
X-Men
Candidate-Md5Url
X-Wikidot-Backend
X-VC
Cache-Key
X-Wikidot-Static-Cache
X-Old-Content-Length
X-Srv
X-Parent-Response-Time
X-BCube-Filmed-By
X-Response-By
X-Ad-Defer-Variation
Datacenter
X-CACHE-KEY
CPC-Age
X-Tt-Logid
X-RPS
X-Cache-ASPX
X-RPM
X-Contensis-Viewer-Groups
X-DB
X-RSL
X-Mvc-Supplant-OutputCached
Servername
XM
X-SplitTest
X-DSS
X-DW
Env
GEO-INFO
X-Edge-Pop
X-Ah-Environment
CPC-Cache
X-LB-NoCache
VNS-Cache
VNS-Age
X-DI
Ms-Author-Via
X-Cache-Status-Check
X-TIME
X-Udemy-Cache-App-Namespace
X-WA-Info
X-Accel-Expires-Debug
X-Date
X-Generated-In
Memory
X-Varnish-Authentication
Fastly-Backend-Name
Time
X-Akamai-Transformed
X-Via-Poph
X-Micro-Cache
X-GeoIP-Region-Code
X-Amz-Meta-Cb-Modifiedtime
X-Via-Popn
X-Via-Popv
X-GeoIP-Country-Code
GeoIp-Country-Code
Lb
X-Servedbyhost
X-S-Maxage
X-AIR-PT
X-Cache-Debug
Path
Ohc-Cache-HIT
ITXSESSIONID
X-Presslabs-Stats
X-HA-Backend
Geoip-Latitude
X-API-Version
X-RateLimit-Reset
Fusion-Source
Fusion-Template-Id
Fusion-Deployment-Id
Fusion-Content-Id
Fusion-Content-Source
Geo-Info
Fusion-Component-Id
X-Vc
Client
True-Client-IP
Cache-Host
FSS-Cache
X-VCL-Version
CacheControlHeader
Ngx.Var.Host
X-Api-Version
True-Client-Country-4JS
Server-ID
X-Action
X-TH-Server
X-VHOST
Hostname
XkeyRZ
X-Cs
X-Proxy-CacheRZ
X-Varnish-Beresp-TTL
X-Backend-TTL
X-Trace-ID
X-Clientip
X-DC
X-FireWall-Port
X-Fpc
Edge-Cache
X-Zone
X-Req
X-TX-ID
X-Webkit-Csp-Report-Only
Powered-By
My-App
NtCoent-Length
X-NGINX-Cache
X-Provided-By
X-B3-Spanid
X-PX
X-Varnish-Beresp-Ttl
X-FPC
X-Pass-Why
X-Dmc
X-Origin-Upstream-Status
X-CSRF-TOKEN
X-Traceid
X-INCAP-ABP
X-MSEdge-Features
X-Up
X-Render-Time
X-MSEdge-Flight
Test
Cf-Int-Pingora-Origin-Digest
X-LB-ID
X-HS-Status
C-Via
X-Cdn-Request-ID
X-Correlation-ID
DataCenter
X-Vcl-Version
X-Webkit-CSP-Report-Only
Tube-Got-Results
Tube-Got-Eval
Tube-Get-Contents
Rip
Tube-Return
X-Gateway-Cache-Key
X-Service
X-Gateway-Skip-Cache
X-Gateway-Request-Id
X-Gateway-Cache-Status
Click-Count-Action-Start
Click-Count-Error
X-Beluga-Record
Server-Id
X-Beluga-Node
X-Beluga-Cache-Status
User-Agent
X-Beluga-Status
X-Beluga-Response-Time
X-Beluga-Trace
X-DynaTrace-JS-Agent
X-M-Reqid
Esi-Enabled
HIT
Proxy-Connection
X-Qnm-Cache
X-M-Log
X-Ha-Backend
X-Li-Fabric
X-UnsetCookies
Tcn
X-Li-Pop
OT-Force-Account-Verify
X-LI-UUID
X-Alfa-Service
X-ND-Cache
WZWS-RAY
Uri
X-Via-PopN
Srvid
On-Server
X-URL
X-Via-PopV
X-RAMCache
X-Via-PopH
Resin-Trace
X-Time-Microsecs
X-ServedByHost
X-Dynatrace
X-CLOUD-TRACE-CONTEXT
X-Geo
GeoIP-Latitude
X-CUA
Sid
GeoIP-Country-Code
X-Check-Cacheable
MIME-Version
X-Akamai-Pragma-Client-IP
X-Proxy-Cache-Hk
Tracecode
X-Hcs-Proxy-Type
Epwk-X-Cache
X-CCDN-CacheTTL
X-CCDN-Origin-Time
X-ATG-Version
X-LI-Proto
Cf-Device-Type
X-Fetch-By
X-APP
Srv
X-Platform-Router
Target-Params
X-Fragments
X-Platform-Processor
X-Platform-Cluster
X-TRACE-ID
X-Cdn-Forward
Fastly-Drupal-HTML
X-Backend-Host
X-Sucuri-ID
X-Sucuri-Cache
X-Var-Ttl
ENV
Lfy
X-Fastly-Backend-Reqs
X-Fastly-Backend
X-FC-Vary-Parameters
X-Azure-Ref-OriginShield
X-Edge-Origin-Shield-Bytes
X-ID
X-Esi
Cdn
Section-Origin-Responded
Section-Io-Id
Section-Io-Origin-Status
X-B3-Traceid-Primal
WebServer
XServer
X-Cache-Expires
X-Lb-Nocache
X-Edge-POP
X-App
Section-Io-Origin-Time-Seconds
ServerName
X-Varnish-Beresp-Status
X-Srcache-Store-Status
X-MG-S
X-HostName
X-Srcache-Fetch-Status
X-Edge-Origin-Shield-Region
X-LiteSpeed-Cache-Control
X-Yottaa-OS
X-Li-Proto
X-NU-AKA-ACS-Version
X-Backend-State
M-TraceId
X-Newrelic-App-Data
CF-Cached-On
PICS-Label
Inserted-Into-Cache-At
X-ElasticPress-Query
Magicmarker
Dt-Hot-News
Cf-Ipcountry
X-Nc
X-CF-Powered-By
D-Url-Rewrites
X-Iplb-Instance
X-Acquia-Application-UUID
X-Acquia-Purge-Tags
X-Serial
X-Acquia-Site
Wpo-Cache-Message
X-Acquia-Application-Trace
X-Vcache
X-Iplb-Request-Id
Server-Ttl
X-Dw-Trace-Id
Wpo-Cache-Status
Servedby
Warning
Ngx
X-Wp-Cf-Super-Cache
X-Vercel-Cache
X-Vercel-Id
X-Wp-Cf-Super-Cache-Cache-Control
X-Fastly-Cache-Hits
Fastcgi-Cache-Ttl
Cneonction
X-Th-Server
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
X-Cache-CFC
X-Release
X-BBC-Origin-Response-Status
X-Dist-Code
X-Request-Url
X-B3-Parentspanid
CountryCode
X-Storefront-Renderer-Verified
X-Request-URL
X-Snapshot-Date
X-Litespeed-Cache-Control
X-Back
Content-Script-Type
Content-Style-Type
X-Request-Start