Threat Level: green Handler on Duty: Russ McRee

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Accept-Ranges
X-XSS-Protection
Expect-CT
Pragma
X-Powered-By
CF-RAY
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-Xss-Protection
X-Download-Options
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
CF-Ray
X-Adblock-Key
X-Request-ID
Access-Control-Allow-Credentials
X-FRAME-OPTIONS
X-Permitted-Cross-Domain-Policies
X-Request-Id
X-AspNet-Version
Alt-Svc
X-Runtime
Content-Security-Policy-Report-Only
X-DNS-Prefetch-Control
X-Drupal-Cache
X-Check
X-Cache-Status
X-Generator
X-Cacheable
Timing-Allow-Origin
X-Iinfo
X-Envoy-Upstream-Service-Time
X-Content-Security-Policy
X-Drupal-Dynamic-Cache
Feature-Policy
Content-Encoding
Upgrade
Access-Control-Expose-Headers
Status
X-CDN
X-AspNetMvc-Version
P3p
Access-Control-Max-Age
X-Via
Server-Timing
X-UA-Device
X-Robots-Tag
Request-Context
X-Turbo-Charged-By
EagleId
X-Cache-Group
X-Amz-Request-Id
X-Amz-Id-2
X-Backend
X-AH-Environment
Keep-Alive
X-Proxy-Cache
X-Server
X-Ws-Request-Id
X-Ua-Compatible
X-Age
Host-Header
X-Hacker
Cf-Edge-Cache
X-Vhost
X-Server-Powered-By
X-Rq
X-Varnish-Cache
Allow
X-Dispatcher
X-Amz-Version-Id
Grace
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-LiteSpeed-Cache
X-OneAgent-JS-Injection
Accept-CH
X-WebKit-CSP
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Page-Speed
X-Device
Cf-Apo-Via
Cf-Railgun
X-Aws-Lambda-Call-Status
X-Server-Id
X-Node
X-Host
X-Pingback
X-Cache-Spec
X-Dns-Prefetch-Control
X-Nginx-Cache-Status
X-Akam-SW-Version
Surrogate-Control
EagleEye-TraceId
X-Backend-Server
Request-Id
X-Readtime
X-Cache-Lookup
X-Ruxit-JS-Agent
X-HW
Accept-CH-Lifetime
X-Cloud-Trace-Context
X-Content-Security-Policy-Report-Only
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Trace
X-Application-Context
X-Response-Time
Permissions-Policy
Fastly-Restarts
X-Nginx-Upstream-Cache-Status
X-Mod-Pagespeed
X-Edge
X-CST
X-WebKit-CSP-Report-Only
Content-Location
X-Content-Type
X-Url
X-Mcache
Accept-Ch-Lifetime
X-MS-InvokeApp
X-Clacks-Overhead
X-Country
Rating
X-ECACHE
X-Midtier
X-Amz-Server-Side-Encryption
X-Vname
X-TtlSet
X-PC
X-Litespeed-Cache
RTSS
X-VARITI-CCR
Cache-Tag
X-Vcap-Request-Id
X-D2id
X-ESI
X-Element-Page-Cache
Origin-Trial
Verso
X-Server-Name
X-Ac
X-Cdn-Fetch
X-Exp-Id
X-Kinja-Revision
X-Kinja-Server
X-Use-Magma
X-Kinja
X-Kinja-Build
X-Exp-Variant
X-GoogleNews-Bot
X-Ttl
X-Varnish-TTL
X-B3-TraceId
X-Rack-Cache
X-Cnection
X-Powered-By-Plesk
Service-Worker-Allowed
X-GitHub-Request-Id
X-Cache-TTL
X-Navigation-Version
Xkey
X-SharePointHealthScore
SPRequestGuid
X-Client-IP
X-Amz-Rid
X-Abt-Application-Version
X-NWS-LOG-UUID
Edge-Control
X-Cached
Arr-Disable-Session-Affinity
SPIisLatency
SPRequestDuration
X-Px
X-Upstream
X-Erf-Bev-Bev-Is-Generated
X-Server-Lifecycle-Phase
X-Mg-S
X-Browser-Type
X-Instrumentation
X-Erf-Bev-Bev
X-Kraken-Loop-Name
X-Dw-Request-Base-Id
X-Correlation-Id
X-Cache-Key
Display
X-Middleton-Display
Pagespeed
X-Sol
Content-MD5
X-Fastcgi-Cache
X-SRCache-Store-Status
X-SRCache-Fetch-Status
Access-Control-Request-Method
Edge-Cache-Tag
X-NF-Request-ID
X-Goog-Hash
X-Country-Code
Front-End-Https
X-Forwarded-For
X-Daa-Tunnel
X-Version
X-XRDS-Location
X-Id
Public-Key-Pins
X-Powered-CMS
AR-PoweredBy
AR-ATIME
TCN
AR-Request-ID
AR-SID
AR-CACHE
X-Jurisdiction
X-HP-Trace-Id
X-HP-Webp
X-T
X-Recruiting
X-Content-Digest
X-MSEdge-Ref
X-Accel-Expires
X-RateLimit-Remaining
Response
X-Middleton-Response
X-Shield-Request-Id
X-Ser
TP-L2-Cache
TP-Cache
X-Amzn-Trace-Id
Mrf-Cache-Status
X-B3-TraceId-Primal
MRF-Tech
Nginx-Cache
S
X-Ratelimit-Limit
X-Request-Processing-Time
X-Request-Received
X-HS-Combine-CSS
Server-Node
X-HS-Cache-Config
X-HS-Content-Id
X-HS-Hub-Id
MicrosoftSharePointTeamServices
X-Distributor
Cache-Status
X-Fastly-Request-ID
X-Hits
Cache-Tags
X-Kinsta-Cache
X-Edge-Location-Klb
X-Grace
Fastcgi-Cache
Server-Name
X-Ratelimit-Remaining
X-Ruxit-Js-Agent
Alternate-Protocol
X-Ezoic-Cdn
X-DIS-Request-ID
X-LB-Cache
X-Origin-Server
X-Ua-Browser
X-Protected-By
X-DataDome
X-FastCGI-Cache
X-Ratelimit-Reset
X-Geo-Country
X-Request-Handler-Origin-Region
X-Microsite
X-Frontend
Cross-Origin-Opener-Policy
X-Rid
Filterid
Healthy
X-Varnish-Backend
X-Www-Served-By
X-Logged-In
Cleartype
X-Debug-Info
X-FB-Debug
X-Git-Hash
Payment
X-NGENIX-Cache
X-Forwarded-Proto
X-Page-Id
X-Load-Cache
X-Webkit-Csp
X-LLID
X-ASPNET-VERSION
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
Charset
X-Hostname
X-Cluster-Name
X-B3-Sampled
X-Origin-Cache
Content-Disposition
DC
MS-Author-Via
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Goog-Metageneration
X-GUploader-UploadID
X-VCache
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
Access-Control-Allow-Method
X-PressLabs-Stats
X-Upgrade-Enabled
X-Proxy
Retry-After
Realpath
X-F-Cache
Cross-Origin-Resource-Policy
X-Activity-Id
X-AppVersion
X-Az
X-Amz-Replication-Status
Accept-Charset
X-TTL
Paypal-Debug-Id
X-Type
X-Revision
X-Contextid
X-Amz-Meta-S3cmd-Attrs
Viewport
X-Signature
X-Azure-Ref
X-B-Cache
X-Fb-Rlafr
X-Whom
X-Seen-By
X-TT
X-Varnish-Server
X-Hosted-By
Surrogate-Key
X-Aspnetmvc-Version
X-B
X-DynaTrace
X-App-Environment
Count-Hit
X-Request-Guid
X-Route-Name
X-Flags
X-Aspnet-Duration-Ms
X-Wix-Request-Id
X-Providence-Cookie
X-Is-Crawler
X-Language
X-Akamai-Edgescape
X-Oracle-Dms-Ecid
X-Oracle-Dms-Rid
X-Source
Amp-Access-Control-Allow-Source-Origin
Referer-Policy
X-Template
X-App-Server
X-Mobile
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-B3-Traceid
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-Cache-Control
X-COUNTRY
Host
X-RateLimit-Limit
X-Oneagent-Js-Injection
X-Magnolia-Registration
Version
X-EdgeConnect-Cache-Status
X-HTML-Minification-Powered-By
X-Cache-Rule
X-Varnish-Grace
X-N
X-Tumblr-User
X-Response-Served-From
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
Accept-Ch
X-Tumblr-Pixel
X-Original-Request-Id
X-UUID
Ms-Operation-Id
X-Varnish-Age
MS-CV
X-RTag
X-Cache-Time
X-Trace-Id
X-Rule
X-Framework
X-Cache-Status-Check
X-Envoy-Decorator-Operation
Access-Control-Request-Headers
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Content-Powered-By
X-Cache-Expired-At
Akamai-GRN
X-Backend-Name
Section-Io-Cache
Refresh
X-FW-Static
X-FW-Server
X-FW-Serve
X-FW-Type
X-FW-Version
X-User-Agent
X-RemovedCookies
X-ProcessESI
X-FW-Hash
X-Jobs
X-Device-Type
X-FW-Dynamic
X-Adobe-Content
X-Status
X-Cacheable-TTL
Url
Protected
NGB
X-L-Path
SD-X-WS
X-Adobe-Loc
X-G
X-Cache-Grace
GEO-INFO
X-Environment-Context
X-Http-Reason
X-Cache-Age
X-Servername
X-Instance
SRV
X-Page-View
X-Akamai-Request-ID2
X-NYM-Debug-Backend
X-Is-Bot
X-Rendered-As
X-Drupal-Cache-Contexts
X-Debug-IsPreview
X-Debug-IsConnected
X-CDN-Forward
From-Origin
X-Drupal-Cache-Tags
X-Region
WPO-Cache-Status
WPO-Cache-Message
CDN-RequestId
X-Cache-Hit
X-Yottaa-Metrics
X-Yottaa-Optimizations
Front
Accept-Language
X-Newrelic-App-Data
X-Nginx-Cache
X-Amzn-RequestId
Country
X-Tec-Api-Version
X-Tec-Api-Root
X-Amz-Apigw-Id
X-Tec-Api-Origin
X-Tb
X-Tt-Logid
X-Fastly-Request-Id
X-Node-Name
Pinterest-Generated-By
Pinterest-Version
X-Pinterest-Rid
X-Buckets
Backend
X-Content-Options
X-Unique-Id
Fastly-SWR
Fastly-SIE
Fastly-Drupal-HTML
X-Real-IP
X-Zen-Fury
X-Mode
X-VC-Cache
Uber-Trace-Id
X-DynaTrace-JS-Agent
X-XRDS-LOCATION
X-Cache-Operation
Content-Secure-Policy
X-Times
X-Air-Trace-Id
X-Air-Hostname
X-Air-Source
X-Tumblr-Pixel-2
X-Amzn-Remapped-Content-Length
X-Ms-Request-Id
X-Proxy-Cache-Info
X-UPSTREAM-Address
Webserver
X-Rewrite-Enabled
X-RN-RSRV
X-Generation-Time
Filters
Meta-Geo
X-Ms-Version
X-Cache-Server
Azure-SiteName
Azure-Version
Azure-SlotName
X-Reqid
Azure-InstanceId
X-IPS-LoggedIn
Azure-RegionName
X-Format
X-Access
Cache-Hits
X-Section
X-TIME
X-Rocket-Nginx-Serving-Static
Onion-Location
X-Time
CF-IPCountry
TWC-GeoIP-Country
TWC-GeoIP-LatLong
Property-Id
TWC-Connection-Speed
TWC-Locale-Group
TWC-Device-Class
X-Ua
X-IPLB-Instance
X-ProxyCache-Key
X-Proxy-Cache-Status
X-IPLB-Request-ID
X-LJ-Flow-ID
X-ProxyCache-Status
X-R9-Blue-Green-Version
X-Cluster
X-Cache-TTL-Remaining
X-Cache-Host
X-Cluster-Node
X-Debug
X-Server-W
Apigw-Requestid
Webcakes-App-Version
X-Locale
Webcakes-App-Name
X-PHP-Backend
TWC-Privacy
X-Web-Node
X-VWS-Id
X-UA-Device-Type
X-BYPASS-REASON
X-AWS-Id
X-Via-Fastly
X-Origin-Hint
Webcakes-Region
Node
X-Content-Age
X-SayCDN-TTL
DB-Nickname
X-Forwarded-Host
X-Skip-Cache
X-Say-TTL
X-Say-Cacheable
X-Proto
X-Adobe-Source
X-PHP-Host
X-Soup
X-Labrador-Cache-Channel
X-Sql-Count
X-Varnish-Beresp-Grace
Web-Mar-Node
X-Cms-Context
X-Cache-Action
ServedBy
S-Rt
X-No-Session
X-Sql-Duration-Ms
X-Sucuri-Cache
X-Sucuri-ID
ServerID
Cache-Name
X-LSADC-Cache
X-FB-TRIP-ID
X-Edge-Location
X-Extlb
Selected-Fe
X-Handled-By
X-JoinUs
X-Routing-Service
Cross-Origin-Window-Policy
X-Site-Version
X-Timing-Wait
X-Xfnlog-Site
Liferay-Portal
X-SaId
Mn-Server-Ip
X-Zipkin-Id
X-Proxied
X-Proxy-Build
X-Urbn-Site-Id
X-GeoCode
X-LAGOON
X-Urbn-Context-Path
X-GeoCountry
CDN-RequestCountryCode
Locale
WP-Super-Cache
CDN-PullZone
CDN-Uid
CDN-Cache
CDN-CachedAt
CDN-EdgeStorageId
X-Hl-Ver
Mime-Version
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
X-Detected-As
X-ECache
X-Webkit-CSP
X-Optimistic-Header
X-SRV
Source
X-Tumblr-Pixel-3
X-Origin-Date
X-CACHE-AGE
Fastcgi-Useragent
X-Request-Time
CF-Cached-On
X-Uri
X-Presslabs-Stats
Upgrade-Insecure-Requests
X-Generated-By
X-Mg-Request-UUID
X-Redis-Cache
X-Cache-Debug
X-Varnish-Hits
Xserver
X-Akamai-Transformed
Countrycode
X-Director
X-TNCMS
X-Loop
Xet-Cookie
X-GEO
X-ARC
X-App-Version
X-Pass-Why
X-NWS-UUID-VERIFY
X-Varnish-Beresp-Ttl
Frame-Options
X-URL
X-FireWall-Port
X-Newrelic-Synthetics
X-Tx-Id
Cache-Tv-Group
X-Origin-TTL
X-Origin-CC
X-Varnish-Cache-Hits
X-Storage
X-TA-CDN-Provider
X-Tid
X-Varnish-Ttl
X-ShardId
X-Storefront-Renderer-Rendered
X-Varnish-Hostname
X-Sorting-Hat-ShopId
X-Alternate-Cache-Key
X-ShopId
X-Shopify-Stage
X-Sorting-Hat-PodId
X-Service
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
X-Datadog-Sampled
X-Datadog-Trace-Id
X-RM-Cache-TTL
X-ServerID
X-Endurance-Cache-Level
Environment
X-DC
Memcached
Odigeo-Trace-Id
MD5-Digest
Ngx.Var.Host
Origin
Meta-Geo-Continent
DCR-Processing-Time-Ms
X-Origin-Time
X-S
X-S-Cookie
X-Rojux
X-Rocket-Build-Number
A
BehaviorPad-Version
Cache-Host
Candidate-Md5Url
DCR-Decision-By
Host-ID
X-S-Maxage
X-Platform-Cluster
X-Platform-Processor
Gannett-Cam-Experience-Id
Edge-Cache
X-Platform-Router
Lang
X-A-Wwc
X-Destination
X-Developer
X-Ec-Fail
X-Ec-GeoHdr
X-D
X-Core-Value
X-Cache-Info
X-Cache-NE
X-CMSURLCustom
X-Conf
X-Epic-Correlation-Id
X-External-Request-Id
X-Httpd
X-INCAP-ABP
X-Loc
X-Level-Front-Cache
X-Generated-On
X-Gdpr
X-Mobile-URL
X-Frame-Option
X-Mid
X-Location
X-BCube-Filmed-By
X-Bc-Bl
TDXMobile
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
Thinkindot-Control
T-Server
Surrogated-Key
Release
Rendered-Blocks
Req-Svc-Chain
Sslversion
X-Nyt-Route
WWW-Authenticate
X-Aed
X-Application
X-B-Cookie
X-BBC-Edge-Cache-Status
X-A-Dgt
X-A-Dcw
X-A
X-A-Ccd
X-A-Dam
Redirect-Candidate
X-Processor
X-Sigma
X-Vdms-Path
X-VG-TLSProxy
X-We-Are-Hiring
X-Sigma-Backend
X-TIM-N
X-SRCache-Key
X-Test
X-Thinkindot-L3
Xc-Version
X-Vdms-Version
X-ScT
X-Served-From
Server-Info
X-GeoIP
X-Varnish-Beresp-Status
X-GeoIP-City
State
X-Varnish-CookieHashed-On
X-Org
Tube-Get-Contents
X-SB
X-Old-Content-Length
Ssr
X-Varnish-CookieINHashed-On
X-Origin-Response-Time
Magicmarker
X-B3-Spanid
Kp-EeAlive
X-SVT-ORM-VERSION
Mail-Subject
X-Thanos
Tube-Got-Eval
X-Hash
X-HS-Content-Campaign-Id
NM-Fastcgi-Cache
Server-Host
Tube-Return
X-Cdn-Srv
X-Cdn-Origin
X-Fetched-On
X-Cache-Bucket
X-Clara-WADP
X-Core-Mission
X-Developers
X-DefHash
X-DefElseHash
X-CUA
X-Bip
X-WADP-Cache
X-Geo-Header
We-Hiring
Vix-Hermes-Req-Id
X-NodeID
X-SVT-ORM-RULES
X-Fmm-Version
X-WA-Info
X-Auto-Login
X-Vmg-Version
X-Akamai-Device-Characteristics
Tube-Got-Results
X-Varnish-Remaining-TTL
CloudFront-Viewer-Country
Click-Count-Error
X-Platform-Server
X-Pool
Cluster
Country-Code
Decoy-Debug-TTL
Decoy-Debug-Status
Decoy-Debug-Key
X-Restarts
CacheControlHeader
Apple-News-Services-Handled
AKAMAI
X-Req
X-Pubstack
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
Cache-Key
C-Via
Apple-News-Services-Request-Url
DSUID
Click-Count-Action-Start
X-Sn-Servicetimems
Gh-Request-Id
X-Request-Host
Fastly-GeoIP-CountryCode
Fastly-Backend-Name
X-AIR-PT
Section-Io-Id
Section-Io-Origin-Status
Section-Origin-Responded
X-Parent-Response-Time
Section-Io-Origin-Time-Seconds
X-Mvc-Supplant-Cachable
X-Scale
X-Azure-Ref-OriginShield
X-Irp-Debug
L
X-FC-Vary-Parameters
X-VServer
X-Esi-Check
X-Accel-Expires-Debug
X-Ad-Defer-Variation
X-Fastly-Backend
X-Nginx-Cache-Key
SID
X-Request-Start
X-Human
X-Block-Status
X-Ckpd-Fst-Backend
NGX
Adler-Geo
X-CacheTTL
X-LB-NoCache
X-Region-Sid
X-Date
X-JWT-State
X-WP-CF-Super-Cache-Active
X-Worker
X-Device-Os
X-Cache-Tags
X-Platform
X-Cache-Backend
Cache-Provider
X-Is-Gdpr
X-NCache
X-DPWN-IS-SECURE
X-Dispatcher-Server
Is-Eu
X-Cache-Id
X-Ec-Custom-Error
Wxu-Next-Hostname
X-Gamma-Serve
X-Origin
X-Men
X-Cache-Date
X-Gzip
Machine
X-Minions-Version
X-Has-Esi
Origin-EX
X-Gen-Mode
Producers
Platform
Pics-Label
On-Server
X-Up
X-Owner
X-Var-Ttl
X-V-Cache
X-Variation
Datacenter
Web-Mar-Region
Canary
X-Node-Id
X-VarnishDD-TTL
Wxu-Next-Commit
X-Varnishpool
Wxu-Next-Region
Origin-CC
PFcat
User-Cache-Control
Cmsid
X-SD-PageType
Cmstype
X-Op-Id-All
X-HN
X-Hnp-Log
X-Qloud-Router
CDCHOST
X-Refresh
X-Forwarded-Site
X-GeoIP-Country-Code
X-Eu-Site
X-Dispatcher-Number
X-GeoIP-Region-Code
X-Server-IP
HA-Ipaddr
Sever-Int
X-Cache-FS-Status
X-Server-ID
X-App
X-Accel-Buffering
Svr
X-Slack-Backend
X-Slack-Shared-Secret-Outcome
X-Wix-Viewer-Type
X-Nananana
Ha-Gx-Prefs
X-Csrf-Jwt
Server-Ext
Server-Hostname
X-CGP
L5d-Success-Class
X-Webkit-CSP-Report-Only
X-CSRF-Token
X-Mly-Id
X-Microcachable
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
Fastly-SSL
X-Mvc-Supplant-OutputCached
X-Cache-Remote
Load-Balancing
X-Servedbyhost
X-Tb-Optimization-Total-Bytes-Saved
X-Via-Popn
X-Via-Poph
X-Via-Popv
HostName
X-HA-Backend
GeoIP-Latitude
Env
X-Zone
X-RCS-CacheZone
X-Cached-By
X-Fastly-Cache
X-Aicache-OS
X-Api-Version
X-VC
X-Trace-ID
Cdn
X-ND-Cache
X-Instance-Name
X-Origin-Expires
Server-ID
X-Response-By
Memory
Time
X-HS-Status
X-Nc
X-Release
X-AK-Request-ID
Cache
Cdncip
Cdnsip
X-NGINX-Cache
X-DataCenter
Locid
X-Wa
Expect-Staple
X-Generated-In
Srvid
X-From
X-Gateway-Cache-Status
X-Gateway-Skip-Cache
X-Gateway-Request-Id
X-Gateway-Cache-Key
X-Fpc
X-FL-EDGE
X-FL-QIT-DEBUG
X-Vc
X-API-Version
X-Via-CDN
X-Esi
X-Cache-Enabled
X-Edge-Pop
X-LB-ID
X-ZONE
AMP-Access-Control-Allow-Source-Origin
X-NewRelic-App-Data
X-Via-NSCOPI
X-Provided-By
NtCoent-Length
X-Correlation-ID
X-Hcs-Proxy-Type
X-Via-Edge
X-Via-SSL
Edge-Copy-Time
X-Client-Ip
X-CCDN-Origin-Time
X-Check-Cacheable
X-CCDN-CacheTTL
Hostname
X-CS
X-Vgn-Hpd-Cached
X-Vgn-Hpd-Variations-Key
X-Vgn-Hpd-Ssi
Eomportal-Instance
GeoIp-Country-Code
X-Srv
X-Vcl-Version
X-Dc
X-APP-VERSION
X-Micro-Cache
Ngx-Var-Key
X-Air-Pt
X-Debug-Cache-Store
X-Lambda-Id
X-CSRF-TOKEN
X-Debug-Cache-Fetch
XkeyRZ
X-Proxy-CacheRZ
Sid
X-Amz-Meta-Cb-Modifiedtime
X-Via-JSL
X-MCACHE
True-Client-IP
OT-Force-Account-Verify
X-B3-SpanId
X-Nf-Request-Id
VNS-Cache
Srv
CPC-Age
VNS-Age
CPC-Cache
X-Render-Time
IsBot
X-Vtex-Remote-Cache
X-Request-URI
X-SIPLIST1
X-Cache-NGX
X-VCL-Version
X-Cs
X-Info
True-Client-Ip
X-EC-Lua
Path
X-Fastly-Country-Code
X-VCT
X-TH-Server
Uri
Location
X-ATG-Version
Request-ID
X-Datadome
X-MSEdge-Features
X-MSEdge-Flight
Resin-Trace
Esi-Enabled
X-TX-ID
X-Upstream-Ct
X-Upstream-Ht
X-Oss-Hash-Crc64ecma
CDN
X-Oss-Object-Type
X-Oss-Request-Id
X-Oss-Server-Time
Fastly-Drupal-Html
X-Oss-Storage-Class
X-CLOUD-TRACE-CONTEXT
GeoIP-Country-Code
M-TraceId
X-Cache-Type
X-Contensis-Viewer-Groups
X-Cache-ASPX
X-Cache-Expires
X-Varnish-Authentication
YJS-ID
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-CF-Lambda-Fn
X-Accel-Version
Servername
X-Cdn-Request-ID
X-PAYTM-SRV-ID
X-CF-Lambda-Version
Cross-Origin-Opener-Policy-Report-Only
X-Edge-POP
X-Udemy-Cache-App-Namespace
X-Lb-Id
X-Pod-Name
X-Datacenter
X-FPC
X-Akamai-Pragma-Client-IP
X-Varnish-Beresp-TTL
Traceparent
Sm-Log-Id
X-Service-Response-Time
X-RateLimit-Reset
X-Moov-T
X-Moov-Xdn-Version
CountryCode
X-Scheme
LB
X-CDN-Cache-Status
X-Wikidot-Backend
X-Wikidot-Static-Cache
RNT-Time
RNT-Machine
HIT
N-Cache
Timeexpire
XServer
X-Geo
X-SERVER-NAME
X-PERF
X-Viewer-Country
X-Tenant
X-Shop-Environment
X-Orig-Expires
X-ApacheServer
X-WA
X-Forwarded-Path
X-Cdn-Cache-Status
X-Bl-Debug
X-MP-GENERATED-AT
ENV
X-Srcache-Store-Status
X-B3-Trace-ID
Proxy-Connection
X-CACHE-KEY
X-Srcache-Fetch-Status
Ohc-File-Size
X-NC
Server-Id
FSS-Cache
X-NAPM-TraceId
X-LiteSpeed-Cache-Control
Powered-By
X-App-Name
X-Policy
X-TraceId
X-ServedByHost
X-Ha-Backend
Epwk-X-Cache
Yjs-Id
X-Snapshot-Date
WZWS-RAY
X-Via-PopN
X-Amz-Meta-Opti
X-Hyper-Cache
X-Cdn-Forward
X-Rebelmouse-Cache-Control
X-Dw-Trace-Id
X-Via-PopH
X-Via-PopV
Geoip-Latitude
X-Rebelmouse-Surrogate-Control
X-TimeS
Rip
X-M-Log
X-M-Reqid
Content-Style-Type
Ngx
Content-Script-Type
Inserted-Into-Cache-At
X-Qnm-Cache
X-Lb-Nocache
V-Age
X-RAMCache
X-Acquia-Site
X-Clientip
Ec-Rule-Version
X-Fastly-Backend-Reqs
Cdn-Requestid
X-Serial
X-Swift-Error
X-B3-Parentspanid
True-Client-Country-4JS
X-Acquia-Purge-Tags
X-Vgn-Hpd-Reason
User-Agent
X-Acquia-Application-Trace
Tracecode
X-Acquia-Application-UUID
X-Lsadc-Cache
X-TT-LOGID
X-Wp-Cf-Super-Cache
X-Wp-Cf-Super-Cache-Cache-Control
X-F-Status
Lb
X-Fastly-Cache-Hits
Hit
X-Webstats-RespID
X-LiteSpeed-Tag
X-B3-ParentSpanId
X-IPS-Cached-Response
Warning
X-MiniProfiler-Ids
XM
X-UP
X-Cache-Ngx
X-VG-WebCache
Cneonction
X-Mid-Debug-Cache-Key
X-Mid-Debug-Cache-Disk
X-Th-Server
X-Request-URL
MIME-Version
My-App
X-Stale