Threat Level: green Handler on Duty: Jan Kopriva

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Link
Cf-Request-Id
CF-Cache-Status
Accept-Ranges
CF-RAY
ETag
X-XSS-Protection
Expect-CT
Pragma
X-Powered-By
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-UA-Compatible
X-Cache-Hits
Alt-Svc
P3P
X-Served-By
X-Xss-Protection
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Request-Id
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Cache-Status
X-Generator
X-Cacheable
Timing-Allow-Origin
X-Content-Security-Policy
P3p
X-Iinfo
Status
Feature-Policy
X-Request-ID
X-Envoy-Upstream-Service-Time
Content-Encoding
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
X-CDN
X-AspNetMvc-Version
Upgrade
X-Via
CF-Ray
X-Ws-Request-Id
Access-Control-Max-Age
Server-Timing
EagleId
Keep-Alive
X-Cache-Group
X-Turbo-Charged-By
Request-Context
X-Age
X-Server-Powered-By
X-Proxy-Cache
X-AH-Environment
X-UA-Device
X-Backend
X-Hacker
X-Robots-Tag
Report-To
X-Amz-Request-Id
Host-Header
X-Server
X-LiteSpeed-Cache
X-Amz-Id-2
Grace
X-Rq
X-Nginx-Cache-Status
X-Varnish-Cache
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-WebKit-CSP
X-Dns-Prefetch-Control
X-Page-Speed
X-Vhost
X-OneAgent-JS-Injection
EagleEye-TraceId
X-Amz-Version-Id
X-Pingback
X-Device
X-Dispatcher
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Cache-Spec
NEL
X-Server-Id
X-Host
Cf-Railgun
X-Backend-Server
X-Node
Accept-CH
X-Readtime
X-Akam-SW-Version
Surrogate-Control
Request-Id
X-Response-Time
X-HW
Xkey
X-Ruxit-JS-Agent
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Application-Context
Content-Location
Rating
X-Country
X-B3-TraceId
X-Ua-Compatible
Accept-Ch-Lifetime
Accept-CH-Lifetime
X-Cache-Lookup
X-Cloud-Trace-Context
X-Language
X-Url
X-Ac
X-Trace
X-Content-Type
X-Template
Allow
X-PC
X-Vname
X-TtlSet
X-Varnish-TTL
X-Mod-Pagespeed
X-Clacks-Overhead
Edge-Control
X-FastCGI-Cache
X-ESI
Cache-Tag
Fastly-Restarts
X-Server-Name
X-Rack-Cache
X-VARITI-CCR
Service-Worker-Allowed
X-Element-Page-Cache
Verso
X-MS-InvokeApp
X-GitHub-Request-Id
X-Buckets
X-Upstream
MS-Author-Via
X-Amz-Rid
X-Vcap-Request-Id
Public-Key-Pins
X-Dw-Request-Base-Id
X-Cached
X-Client-IP
X-D2id
X-Abt-Application-Version
X-Origin-Cache
X-Cache-TTL
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
Arr-Disable-Session-Affinity
X-Px
X-Cnection
X-Aws-Lambda-Call-Status
X-Goog-Hash
X-Country-Code
X-Powered-By-Plesk
Access-Control-Request-Method
X-NF-Request-ID
X-Navigation-Version
X-Kraken-Loop-Name
X-Instrumentation
X-Server-Lifecycle-Phase
RTSS
X-Version
Accept-Ch
X-Powered-CMS
X-Amz-Server-Side-Encryption
X-Sol
X-Middleton-Display
Pagespeed
Display
X-Kinja-Build
X-Kinja-Revision
X-Use-Magma
X-Kinja
X-Kinja-Server
X-GoogleNews-Bot
X-Exp-Id
X-Cdn-Fetch
X-Exp-Variant
X-SRCache-Fetch-Status
X-SRCache-Store-Status
Response
X-Middleton-Response
X-MSEdge-Ref
X-LLID
X-Kinsta-Cache
X-Edge-Location-Klb
AR-CACHE
AR-Request-ID
AR-SID
AR-PoweredBy
X-Edge
AR-ATIME
Nginx-Cache
MRF-Tech
Mrf-Cache-Status
X-B3-TraceId-Primal
X-Shield-Request-Id
X-RateLimit-Remaining
X-HP-Webp
X-Jurisdiction
S
X-HP-Trace-Id
X-Protected-By
X-T
X-Forwarded-For
Content-MD5
TCN
X-Content-Security-Policy-Report-Only
X-Mg-S
X-Id
X-TTL
X-CST
X-Aspnetmvc-Version
Realpath
Fastcgi-Cache
X-Mid
X-MCACHE
Edge-Cache-Tag
X-Ttl
SPRequestDuration
SPIisLatency
Front-End-Https
X-Recruiting
X-Parallel-Accel
X-Request-Received
X-Request-Processing-Time
Filters
Fusion-Content-Id
Fusion-Deployment-Id
Server-Node
Fusion-Component-Id
X-Pinterest-Rid
Pinterest-Version
Pinterest-Generated-By
Fusion-Source
Fusion-Template-Id
Fusion-Content-Source
X-Ua-Browser
X-Ab
X-Content
X-DynaTrace
SPRequestGuid
X-Correlation-Id
X-SharePointHealthScore
Server-Name
X-Ezoic-Cdn
X-NWS-LOG-UUID
X-Frontend
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Cache-Config
X-HS-Combine-CSS
Alternate-Protocol
X-Yandex-Sdch-Disable
X-Hits
X-Content-Options
X-Accel-Expires
X-ECACHE
X-Cache-Key
X-Tt-Trace-Host
X-Tt-Trace-Tag
MicrosoftSharePointTeamServices
Cache-Tags
X-Ser
X-Page-Id
Host
X-Git-Hash
X-Kong-Proxy-Latency
Cleartype
X-Fastly-Request-Id
X-Kong-Upstream-Latency
Charset
X-B3-Sampled
X-Www-Served-By
X-Ruxit-Js-Agent
X-Daa-Tunnel
X-Geo-Country
X-XRDS-LOCATION
X-Amz-Replication-Status
X-Content-Digest
Filterid
TP-Cache
TP-L2-Cache
X-Forwarded-Proto
X-Amzn-Trace-Id
X-DIS-Request-ID
X-Varnish-Age
X-Hostname
X-VCache
X-AppVersion
X-Activity-Id
X-Az
X-Debug-Info
X-Rid
X-Upgrade-Enabled
X-Grace
X-N
X-Origin-Server
X-FB-Debug
Access-Control-Allow-Method
X-LB-Cache
X-Origin-Upstream-Status
X-WebKit-CSP-Report-Only
X-Nginx-Upstream-Cache-Status
ServerID
X-Mobile-URL
Cross-Origin-Opener-Policy
X-Request-Guid
X-Providence-Cookie
X-Flags
X-F-Cache
X-Aspnet-Duration-Ms
X-Route-Name
X-Is-Crawler
X-Whom
X-Goog-Generation
X-TT
X-GUploader-UploadID
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
X-Goog-Storage-Class
X-Tb
X-Varnish-Grace
X-App-Environment
X-Microsite
X-Request-Handler-Origin-Region
X-App-Server
Viewport
X-FW-Server
X-FW-Static
X-FW-Serve
X-FW-Dynamic
Payment
X-Distributor
X-FW-Hash
X-FW-Type
X-Server-ID
DC
Node
Paypal-Debug-Id
X-NGENIX-Cache
X-Ratelimit-Limit
X-Seen-By
X-Type
X-Cache-Control
Fastcgi-Useragent
X-Logged-In
X-User-Agent
Country
Accept-Charset
X-Cache-Age
X-Litespeed-Cache
X-Cache-Rule
X-Wix-Request-Id
X-DataDome
X-Varnish-Backend
X-Webkit-CSP
Version
X-Erf-Bev-Bev-Is-Generated
X-Node-Name
X-Browser-Type
X-Erf-Bev-Bev
X-Load-Cache
X-PressLabs-Stats
X-Drupal-Cache-Tags
X-Cache-Action
Referer-Policy
X-Via-JSL
Refresh
X-Tec-Api-Version
X-Tec-Api-Origin
X-Tec-Api-Root
X-IPLB-Instance
Access-Control-Request-Headers
Amp-Access-Control-Allow-Source-Origin
SD-X-WS
X-Original-Request-Id
X-Cluster-Name
X-Response-Served-From
Cache-Status
X-Jobs
X-Is-Bot
X-Page-View
X-Rendered-As
X-Real-IP
X-Vgn-Hpd-Reason
X-Signature
X-B-Cache
X-Contextid
X-Cacheable-TTL
X-Mobile
X-UUID
X-Revision
X-Cache-Expired-At
X-RemovedCookies
X-B
X-Proxy-Cache-Status
VIX-Pulpo-Node
X-ProcessESI
VIX-Pulpo-Upstream-Status
X-Rule
X-Debug
X-Proxy
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-G
Akamai-GRN
NGB
X-Framework
X-Cache-Time
Surrogate-Key
X-Drupal-Cache-Contexts
X-Fastly-Request-ID
X-Instance
X-Debug-IsPreview
X-Device-Type
DynaTrace
X-Debug-IsConnected
CF-IPCountry
X-FW-Version
X-Fastcgi-Cache
X-Air-Hostname
Liferay-Portal
X-Air-Source
X-Air-Trace-Id
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
Healthy
X-Azure-Ref
SID
X-Source
X-Oracle-Dms-Rid
X-Oracle-Dms-Ecid
X-Ms-Request-Id
X-Ms-Version
X-Nginx-Cache
Frame-Options
MS-CV
Ms-Operation-Id
X-RTag
X-APP-VERSION
X-CDN-Forward
X-Cache-Hit
X-Oneagent-Js-Injection
Count-Hit
X-L-Path
X-Tumblr-Pixel-0
X-Environment-Context
X-Tumblr-Pixel
X-Tumblr-Pixel-1
X-Tumblr-User
GEO-INFO
X-Cache-Operation
Countrycode
X-Varnish-Server
X-Ratelimit-Reset
Xserver
X-EdgeConnect-Cache-Status
Uber-Trace-Id
X-XRDS-Location
X-Accel-Buffering
X-Region
Section-Io-Cache
X-Servername
X-Content-Powered-By
X-Forwarded-Host
X-Backend-Name
X-Mode
X-Presslabs-Stats
Cross-Origin-Window-Policy
X-IPS-LoggedIn
Ec-Rule-Version
X-Zen-Fury
Backend
X-RN-RSRV
X-SaId
X-JoinUs
X-UPSTREAM-Address
X-Detected-As
Meta-Geo
X-Sorting-Hat-ShopId
Eomportal-Instance
X-Sorting-Hat-PodId
X-Cache-NGX
X-Varnish-Beresp-Grace
X-Sql-Count
X-Uri
Country-Code
X-ShardId
X-Shopify-Stage
X-Cache-Grace
X-Human
X-Tid
X-ShopId
X-Sql-Duration-Ms
X-Hosted-By
X-Redis-Cache
X-Cache-Server
X-Cache-Type
X-Generation-Time
X-Adobe-Loc
X-Adobe-Content
X-Alternate-Cache-Key
X-Cache-TTL-Remaining
X-UA-Device-Type
Decoy-Debug-TTL
Apigw-Requestid
Mn-Server-Ip
X-PHP-Backend
Url
Cache-Name
X-ServerID
X-Origin-Date
DB-Nickname
X-No-Session
X-Microcachable
X-NCache
X-FB-TRIP-ID
X-Status
Cache-Tv-Group
X-Site-Version
Decoy-Debug-Status
Decoy-Debug-Key
Protected
Property-Id
Fastly-SSL
Selected-Fe
X-Cache-Host
X-Storage
X-Rewrite-Enabled
X-SayCDN-TTL
X-Format
X-Web-Node
X-Via-Fastly
X-Proxy-Build
X-Origin-Hint
X-ProxyCache-Key
X-Timing-Wait
X-Say-TTL
X-Say-Cacheable
TWC-Locale-Group
TWC-GeoIP-LatLong
TWC-GeoIP-Country
TWC-Device-Class
TWC-Privacy
Webcakes-App-Name
X-ProxyCache-Status
X-BYPASS-REASON
X-Akamai-Edgescape
Webcakes-Region
TWC-Connection-Speed
Webcakes-App-Version
X-PCL
X-PERF
X-Pubstack
X-NYM-Debug-Backend
X-Hl-Ver
X-Access
X-ApacheServer
X-Debug-Cache
X-R9-Blue-Green-Version
X-Section
X-Server-W
X-Zipkin-Id
X-Soup
X-Routing-Service
X-Proxied
X-Varnishpool
X-Extlb
OT-Force-Account-Verify
X-OCL
Azure-SiteName
Azure-RegionName
Azure-InstanceId
Azure-Version
Azure-SlotName
X-Cluster-Node
X-Be
X-RateLimit-Limit
Content-Secure-Policy
X-Azure-Ref-OriginShield
X-Content-Age
X-Ua
X-LSADC-Cache
X-NewRelic-App-Data
Source
CDN-Cache
CDN-CachedAt
CDN-EdgeStorageId
X-Webkit-Csp
CDN-Uid
CDN-RequestCountryCode
CDN-RequestId
CDN-PullZone
SRV
Content-Disposition
X-Hyper-Cache
X-Generated-By
Cache
X-Dc
X-Cached-By
X-HTML-Minification-Powered-By
X-ECache
X-Unique-Id
X-LAGOON
X-Amz-Meta-S3cmd-Attrs
X-SRV
X-App-Version
X-Bc-Bl
X-Nginx-Cache-Key
X-Cache-Var-Map
X-Cache-Var
X-Loop
X-Trace-Id
X-Varnish-Hits
X-TNCMS
X-Varnish-Hostname
X-Time
Xet-Cookie
LB
X-Auto-Login
Onion-Location
X-S-Maxage
X-GEO
Retry-After
X-TT-LOGID
X-Origin-TTL
Cache-Hits
X-Origin-CC
X-Tumblr-Pixel-2
X-Tumblr-Pixel-3
X-TIME
Web-Mar-Node
X-Proto
WPO-Cache-Message
Mime-Version
X-Cdn
X-CSRF-Token
WPO-Cache-Status
X-Platform-Server
X-M-Reqid
X-Time-Microsecs
X-Qnm-Cache
X-M-Log
X-Akamai-Transformed
X-Tenant
Webserver
X-Edge-Location
HostName
X-VWS-Id
X-Endurance-Cache-Level
X-Cache-Remote
X-LJ-Flow-ID
X-AWS-Id
X-GG-Cache-Date
X-Xfnlog-Site
CloudFront-Viewer-Country
X-Cache-Tags
N-Cache
X-Mg-Request-UUID
X-Varnish-Cache-Hits
Upgrade-Insecure-Requests
X-Amzn-RequestId
X-CACHE-KEY
X-Amz-Apigw-Id
X-PHP-Host
X-Labrador-Cache-Channel
X-Request-Time
ServedBy
X-AOL-HN
X-Ratelimit-Remaining
X-Via-NSCOPI
X-RCS-CacheZone
X-Handled-By
X-Origin-Response-Time
X-B3-SpanId
X-Locale
Fastcgi-X-Cache-Version
Odigeo-Trace-Id
X-Vtex-Processado-Em
Origin
Mobile-Detection-Method
X-S-Cookie
A
X-Slack-Backend
X-Shop-Environment
X-VG-WebCache
X-SRCache-Key
X-SVT-ORM-RULES
X-V-Cache
X-TIM-N
X-SVT-ORM-VERSION
BehaviorPad-Version
DCR-Decision-By
X-ScT
DSUID
Expiry
DCR-Processing-Time-Ms
Xc-Version
X-Session-Fingerprint
X-SD-PageType
X-Vtex-Remote-Cache
X-A-Ccd
X-Conf
X-Connection-Hash
X-PAYTM-SRV-ID
X-Orig-Expires
X-PBS-Appsvrname
X-Cluster
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-ND-Cache
X-D
X-Hnp-Log
X-Gen-Mode
X-Ftr-Request-Id
X-Forwarded-Path
X-External-Request-Id
X-Ig-Push-State
X-Destination
X-Developer
X-NAPM-TraceId
X-Cache-NE
X-Planisys-CDN-TTL
X-Vdms-Path
X-Rojux
X-Request-Host
X-Vdms-Version
X-A
User-Cache-Control
Pramga
Redirect-Candidate
Rendered-Blocks
Surrogated-Key
X-A-Dam
X-A-Dcw
X-ARC
X-B-Cookie
X-Block-Status
X-Cache-Date
X-Application
X-Processor
X-A-Dgt
X-A-Wwc
X-Aed
X-S
Meta-Geo-Continent
Nel
X-Correlation-ID
X-Storefront-Renderer-Rendered
X-VC-Cache
X-MP-GENERATED-AT
X-Reqid
X-Ckpd-Fst-Backend
X-Rocket-Nginx-Serving-Static
X-Adobe-Source
X-Sucuri-Cache
Origin-CC
Release
X-Sucuri-ID
Origin-EX
X-Scheme
L
X-Served-From
X-Server-IP
Gh-Request-Id
X-Skip-Cache
Host-ID
Server-Info
X-Li-Fabric
X-Core-Mission
Fastcgi-Cache-TTL
State
X-Cache-Bucket
X-Origin-Expires
X-Origin-Time
Wxu-Next-Region
X-Location
X-Accel-Expires-Debug
X-Mvc-Supplant-Cachable
X-Men
X-Nyt-Route
X-Old-Content-Length
Wxu-Next-Hostname
Wxu-Next-Commit
Traceparent
X-LI-UUID
X-Date
X-Cache-Info
X-Policy
V-Age
X-Owner
X-ATG-Version
Vix-Hermes-Req-Id
X-Li-Pop
X-Hash
X-Geo-Header
Arc-Country
CacheControlHeader
CDCHOST
X-Forwarded-Site
X-Varnish-Beresp-Status
X-Webstats-RespID
X-Epic-Correlation-Id
X-Fetched-On
AKAMAI
From-Origin
X-Gdpr
X-Device-Os
X-Fastly-Cache
Cmstype
X-VServer
Cmsid
X-FireWall-Port
Environment
AMP-Access-Control-Allow-Source-Origin
X-Cache-Config
X-Viewer-Country
Server-Host
X-Magnolia-Registration
X-Generated-On
X-Level-Front-Cache
X-Platform
X-TH-Server
X-Branch-Name
Req-Svc-Chain
X-Region-Sid
X-Fastly-Backend
Web-Mar-Region
X-Cache-Id
Thinkindot-Control
Thinkindot-CacheControl-Type
True-Client-Country-4JS
X-Cache-Debug
X-Aicache-OS
Thinkindot-CacheControl
TDXMobile
We-Hiring
X-Esi-Check
X-Proxy-Upstream
X-VarnishDD-TTL
Svr
X-VG-TLSProxy
X-Rocket-Build-Number
X-Node-Id
X-Sigma
X-Datadog-Parent-Id
X-NodeID
X-Core-Value
X-TrackingId
X-Gzip
Fastly-GeoIP-CountryCode
X-Sigma-Backend
X-Thinkindot-L3
X-Thanos
X-BBC-Edge-Cache-Status
X-Sn-Servicetimems
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
X-GeoIP
X-Developers
X-Gamma-Serve
Apple-News-Services-Handled
Apple-News-Services-Host
X-Bip
X-GeoIP-City
PFcat
X-Cdn-Origin
X-Cdn-Srv
X-Irp-Debug
Apple-News-Services-Parsed-Url
Mail-Subject
Machine
Locid
Sslversion
X-HN
X-HS-Content-Campaign-Id
Apple-News-Services-Request-Url
X-Request-Start
Fastly-Drupal-Html
X-Zone
WP-Super-Cache
X-JWT-State
X-Csrf-Jwt
X-Backend-State
X-DefHash
X-Has-Esi
X-DefElseHash
X-DPWN-IS-SECURE
X-CGP
X-Loc
X-Eu-Site
X-Envoy-Decorator-Operation
X-Is-Gdpr
X-FC-Vary-Parameters
X-RateLimit-Remaining-Second
HA-Ipaddr
Ha-Gx-Prefs
Fastly-SWR
L5d-Success-Class
Memcached
X-Response-By
NM-Fastcgi-Cache
NGX
Fastly-SIE
Cf-Device-Type
X-Varnish-Remaining-TTL
X-Worker
Ssr
X-Varnish-CookieINHashed-On
X-Varnish-CookieHashed-On
X-UnsetCookies
Adler-Geo
X-Variation
X-Request-URI
Is-Eu
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-Pod-Name
X-RateLimit-Limit-Second
X-Qloud-Router
Platform
X-Origin
X-Req
X-Amzn-Remapped-Content-Length
X-NU-AKA-ACS-Version
X-EC-Lua
X-Xrds-Location
Datacenter
X-Tx-Id
Candidate-Md5Url
X-Mvc-Supplant-OutputCached
X-NWS-UUID-VERIFY
X-Ua-Device
X-NC
X-API-Version
X-Cache-Enabled
X-CS
X-CLOUD-TRACE-CONTEXT
CDN
X-Vc
X-Backend-TTL
On-Server
Pics-Label
X-LB-ID
X-Varnish-Beresp-Ttl
WWW-Authenticate
X-Up
X-DynaTrace-JS-Agent
X-Trace-ID
Esi-Enabled
Memory
X-Tt-Logid
Time
X-Refresh
X-GeoIP-Region-Code
X-GeoIP-Country-Code
NtCoent-Length
Ms-Author-Via
X-Datadome
X-TraceId
X-LB-NoCache
Magicmarker
X-Tb-Optimization-Total-Bytes-Saved
X-Edge-Pop
X-Generated-In
Env
X-Service
GeoIp-Country-Code
C-Via
X-Via-Popn
X-Via-Poph
X-Via-Popv
WebServer
X-Varnish-Ttl
X-Dynatrace
X-TA-CDN-Provider
X-Parent-Response-Time
X-CacheTTL
S-Rt
Kp-EeAlive
X-Varnish-Beresp-TTL
X-Restarts
X-Cache-PHP
X-Srv
X-DC
X-Optimistic-Header
X-RSL
Edge-Cache
X-RPS
X-DW
X-Render-Time
X-RPM
X-MSEdge-Features
X-Action
X-Servedbyhost
X-MSEdge-Flight
X-DSS
X-Cache-Backend
X-Cache-Status-Check
X-Wix-Viewer-Type
X-Esi
X-DI
X-DB
X-Cs
X-TX-ID
X-ZONE
X-Unique-ID
X-Akamai-Request-ID2
X-Http-Reason
Server-ID
X-Info
X-AIR-PT
X-Li-Proto
X-Minions-Version
X-VCL-Version
X-Clientip
X-Newrelic-Synthetics
Proxy-Connection
X-HA-Backend
X-Cache-Ttl
X-FPC
Accept-Language
X-App
X-LiteSpeed-Cache-Control
X-URL
X-B3-Spanid
HIT
X-Oss-Hash-Crc64ecma
Cache-Host
X-Fpc
X-Webkit-Csp-Report-Only
UCS
Test
Server-Id
X-Oss-Server-Time
X-Oss-Storage-Class
X-Oss-Request-Id
X-Oss-Object-Type
X-LI-Proto
X-Traceid
X-Urbn-Context-Path
X-Urbn-Site-Id
X-Vcl-Version
X-User
Locale
X-Ec-Fail
S-Cnection
X-Ec-GeoHdr
X-Webkit-CSP-Report-Only
X-NODE
Geo-Info
Tcn
Section-Origin-Responded
Section-Io-Id
Section-Io-Origin-Time-Seconds
Lb
Section-Io-Origin-Status
Fastly-Backend-Name
User-Agent
X-Pass-Why
X-Micro-Cache
Cdncip
X-HostName
M-TraceId
X-Pad
X-Backend-Host
Cdnsip
Cf-Int-Pingora-Origin-Digest
Fastly-Drupal-HTML
X-Ha-Backend
X-AK-Request-ID
X-LiteSpeed-Tag
X-CSRF-TOKEN
Hostname
Geoip-Latitude
X-ServedByHost
X-APP
Cluster
X-Release
Resin-Trace
My-App
X-ID
X-BCube-Filmed-By
X-Fmm-Version
X-Clara-WADP
X-WADP-Cache
X-BBC-Origin-Response-Status
X-Via-PopV
X-CUA
X-Check-Cacheable
Tracecode
Hit
Ohc-File-Size
GeoIP-Country-Code
X-Var-Ttl
X-Via-PopH
X-Via-PopN
X-Geo
X-Dynatrace-Js-Agent
X-ES-SERVER
X-ElasticPress-Query
Lfy
X-From
T-Server
X-Edge-POP
X-Amz-Meta-Cb-Modifiedtime
VNS-Age
EpKe-Alive
X-Cdn-Forward
Cache-Key
VNS-Cache
X-WA
MIME-Version
CPC-Age
CPC-Cache
X-WA-Info
Path
ENV
X-RAMCache
Load-Balancing
Lang
X-HS-Status
X-Edge-Cache
X-Fragments
X-Api-Version
X-NGINX-Cache
Srv
X-Akamai-Pragma-Client-IP
X-Wikidot-Static-Cache
Pagetype
X-ServerName
Servername
Shield-Pop
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
Target-Params
X-Cms-Context
URI
X-Ucs
X-Wikidot-Backend
X-PJAX-URL
X-Fastly-Backend-Reqs
X-UP
DataCenter
Uri
X-GoCache-CacheStatus
X-Mcache
X-Via-Ucdn
X-CCDN-Origin-Time
X-Hcs-Proxy-Type
X-Fastly-Cache-Hits
X-CCDN-CacheTTL
MD5-Digest
X-TRACE-ID
X-Dw-Trace-Id
Cdn
WZWS-RAY
X-Cdn-Request-ID
X-RateLimit-Reset
Sid
X-Lb-Id
X-VC
X-Nc
Sever-Int
Server-Hostname
Cneonction
Ohc-Cache-HIT
X-VG-WebServer
X-SIPLIST1
Server-Ext
X-B3-ParentSpanId
PICS-Label
IsBot
Cf-Ipcountry
X-Httpd
X-Proxy-Cache-Info
X-Cache-ASPX
X-Contensis-Viewer-Groups
X-Snapshot-Date
CF-Cached-On
X-Newrelic-App-Data
X-Apw-Hits
X-Acquia-Purge-Tags
X-Acquia-Site
X-Apw-Access-Action
X-Acquia-Application-UUID
X-Acquia-Application-Trace
X-Apw-Access-Token
X-Apw-Access-Object
Permissions-Policy
Cteonnt-Length
W
X-Cache-Expires
X-Yottaa-OS
X-Swift-Error
FSS-Cache
Vha6-Origin
X-Lb-Nocache
X-Cache-Ngx
X-Air-Pt
X-Last-Modified
X-Akamai-ERRuleID
X-Akamai-ERPolicy
X-Te-Count
X-Http-Duration-Ms
X-Miniprofiler-Ids
Server-Ttl
X-Te-Duration-Ms
ServerName
Ngx
Dnion-Transfer-Encoding
CountryCode
X-Logging-Id
Req-ID
X-CacheKey
HitType
X-UA
X-Akamai-Request-ID
X-Platform-Cluster
X-Sentry-ID
X-B3-Parentspanid
X-Varnish-Authentication
X-Provided-By
X-Platform-Processor
X-Platform-Router
X-Http-Count