Threat Level: green Handler on Duty: Daniel Wesemann

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
Pragma
X-Powered-By
X-XSS-Protection
CF-RAY
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
P3P
X-Cache-Hits
X-UA-Compatible
Alt-Svc
X-Xss-Protection
X-Served-By
CF-Ray
X-Download-Options
X-Timer
X-Request-Id
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
Access-Control-Allow-Credentials
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
X-Drupal-Cache
X-Generator
X-Cache-Status
X-Check
X-Cacheable
X-Envoy-Upstream-Service-Time
X-DNS-Prefetch-Control
X-Request-ID
Timing-Allow-Origin
X-FRAME-OPTIONS
X-Iinfo
X-Dns-Prefetch-Control
X-Drupal-Dynamic-Cache
Feature-Policy
X-Content-Security-Policy
Content-Encoding
Access-Control-Expose-Headers
Upgrade
Status
X-CDN
X-AspNetMvc-Version
Server-Timing
X-XSS-PROTECTION
Access-Control-Max-Age
X-Amz-Request-Id
Request-Context
X-Amz-Id-2
X-Turbo-Charged-By
X-AH-Environment
X-Via
X-Robots-Tag
X-Backend
X-Cache-Group
Cf-Edge-Cache
Host-Header
Keep-Alive
X-Proxy-Cache
X-Hacker
X-Server
X-Rq
X-UA-Device
X-Age
X-Server-Powered-By
Allow
X-Vhost
X-Varnish-Cache
X-Ws-Request-Id
EagleId
X-Dispatcher
X-Amz-Version-Id
Grace
Cf-Apo-Via
P3p
X-LiteSpeed-Cache
Nel
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Page-Speed
X-Device
Cf-Railgun
EagleEye-TraceId
X-Swift-CacheTime
X-Swift-SaveTime
X-Aws-Lambda-Call-Status
Ali-Swift-Global-Savetime
Accept-CH
X-WebKit-CSP
X-Pingback
X-Node
X-Host
X-Server-Id
Surrogate-Control
X-OneAgent-JS-Injection
X-Backend-Server
X-CST
X-Readtime
X-Nginx-Cache-Status
X-Akam-SW-Version
X-Content-Security-Policy-Report-Only
Permissions-Policy
Request-Id
X-Cache-Lookup
X-Application-Context
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Nginx-Upstream-Cache-Status
X-Cloud-Trace-Context
X-Trace
X-Response-Time
X-Edge
Accept-Ch-Lifetime
X-HW
Accept-CH-Lifetime
X-Litespeed-Cache
X-Ua-Compatible
X-Mod-Pagespeed
Content-Location
X-Url
X-Clacks-Overhead
X-Oneagent-Js-Injection
X-Midtier
X-ECACHE
X-Ruxit-JS-Agent
X-ESI
X-Mcache
Rating
X-Amz-Server-Side-Encryption
X-Country
X-Upstream
X-Vname
X-PC
X-TtlSet
Xkey
X-Vcap-Request-Id
Cache-Tag
X-Rack-Cache
X-D2id
X-MS-InvokeApp
Fastly-Restarts
X-Element-Page-Cache
Verso
X-Cache-TTL
X-Cdn-Fetch
X-Kinja-Build
X-Kinja-Revision
X-Kinja-Server
X-Use-Magma
X-GoogleNews-Bot
X-Kinja
X-Exp-Id
X-Exp-Variant
Edge-Control
RTSS
X-Content-Type
X-Powered-By-Plesk
X-Ruxit-Js-Agent
X-VARITI-CCR
Origin-Trial
X-Ac
X-Navigation-Version
X-Cached
X-Abt-Application-Version
X-WebKit-CSP-Report-Only
Accept-Ch
X-Goog-Hash
Service-Worker-Allowed
X-Ttl
X-GitHub-Request-Id
X-Country-Code
X-Amz-Rid
Pagespeed
Display
X-Sol
X-Middleton-Display
X-Mg-S
X-Dw-Request-Base-Id
X-Browser-Type
SPRequestGuid
X-SharePointHealthScore
X-Server-Name
X-B3-TraceId
Arr-Disable-Session-Affinity
Cross-Origin-Opener-Policy
X-Varnish-TTL
X-Server-Lifecycle-Phase
X-Powered-CMS
X-Kraken-Loop-Name
X-Instrumentation
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
Response
AR-SID
AR-ATIME
X-Middleton-Response
AR-PoweredBy
AR-Request-ID
X-Amzn-Trace-Id
SPIisLatency
SPRequestDuration
X-Cache-Key
X-Ua-Device
AR-CACHE
X-Fastly-Request-ID
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Cnection
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-Jurisdiction
X-HP-Trace-Id
X-HP-Webp
X-Version
X-Accel-Expires
X-Fastcgi-Cache
X-NF-Request-ID
X-T
Front-End-Https
Cache-Tags
Cache-Status
X-Times
Edge-Cache-Tag
X-Ser
X-Px
X-MSEdge-Ref
Pinterest-Version
Pinterest-Generated-By
X-Pinterest-Rid
Public-Key-Pins
X-Client-IP
X-Hits
Nginx-Cache
X-Recruiting
X-B3-TraceId-Primal
Mrf-Cache-Status
X-RateLimit-Remaining
MRF-Tech
X-Shield-Request-Id
X-Request-Received
X-Request-Processing-Time
X-Frontend
Access-Control-Request-Method
Server-Node
X-LLID
X-Ua-Browser
X-NWS-LOG-UUID
X-B3-Traceid
Payment
X-Webkit-CSP
TP-Cache
X-DIS-Request-ID
X-RateLimit-Limit
MicrosoftSharePointTeamServices
X-HS-Combine-CSS
X-HS-Cache-Config
X-HS-Content-Id
X-HS-Hub-Id
S
TP-L2-Cache
X-Content-Digest
X-LB-Cache
X-Goog-Metageneration
X-Webkit-Csp
Content-MD5
X-Distributor
X-Erf-Stays-Pdp-Viaduct-Migration-Web
Realpath
X-Hostname
X-Kinja-CCPA
X-Microsite
X-Request-Handler-Origin-Region
X-Geo-Country
X-Forwarded-For
X-Ezoic-Cdn
X-Page-Id
X-FastCGI-Cache
Access-Control-Allow-Method
X-FB-Debug
Fastcgi-Cache
Accept-Charset
X-Cluster-Name
X-Envoy-Decorator-Operation
X-PressLabs-Stats
X-Webkit-CSP-Report-Only
X-Rid
X-Correlation-Id
X-GUploader-UploadID
X-Protected-By
TCN
X-Amzn-RequestId
X-Seen-By
X-Amz-Apigw-Id
X-Ratelimit-Remaining
Cleartype
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
X-B3-Sampled
DC
X-Origin-Server
X-Origin-Cache
X-XRDS-Location
X-Debug-Info
X-Newrelic-App-Data
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Mobile
Referer-Policy
X-Ratelimit-Limit
X-Git-Hash
X-Varnish-Backend
X-Logged-In
X-Kinsta-Cache
X-Edge-Location-Klb
Cross-Origin-Resource-Policy
X-Azure-Ref
Alternate-Protocol
X-Varnish-Grace
X-TTL
X-Revision
X-App-Environment
Healthy
Surrogate-Key
X-Contextid
X-Fb-Rlafr
X-Aspnet-Version
X-Is-Crawler
X-Grace
X-Providence-Cookie
X-Request-Guid
X-Route-Name
X-Aspnet-Duration-Ms
X-Flags
X-Amz-Replication-Status
X-Amz-Meta-S3cmd-Attrs
X-TT
X-Content-Options
Count-Hit
X-Server-ID
X-Wix-Request-Id
X-Forwarded-Proto
X-Whom
X-IPS-LoggedIn
Filterid
Charset
MS-Author-Via
Viewport
Frame-Options
X-Akamai-Edgescape
X-Client-Ip
WPO-Cache-Message
X-Id
WPO-Cache-Status
X-App-Server
X-Hosted-By
X-B
Paypal-Debug-Id
X-Magnolia-Registration
X-Backend-Name
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Az
X-Activity-Id
X-Trace-Id
X-Cache-Control
X-Daa-Tunnel
X-AppVersion
X-Www-Served-By
X-Cache-Age
Retry-After
Section-Io-Cache
Server-Name
X-F-Cache
Refresh
Amp-Access-Control-Allow-Source-Origin
X-Type
X-Proxy-Cache-Info
X-Varnish-Ttl
X-Upgrade-Enabled
X-Varnish-Server
Version
X-Proxy
VIX-Pulpo-Node
X-Original-Request-Id
VIX-Pulpo-Upstream-Status
SD-X-WS
X-Cache-Rule
X-App-Version
Host
X-Rule
X-ARC
Akamai-GRN
X-Response-Served-From
X-Instance
X-Varnish-Age
Protected
Front
X-Rocket-Nginx-Serving-Static
X-Akamai-Request-ID2
X-Edge-Location
X-Http-Reason
X-UUID
X-Status
X-User-Agent
X-Is-Bot
X-EdgeConnect-Cache-Status
X-Unique-Id
X-Cache-Grace
X-Rendered-As
X-Environment-Context
X-Cacheable-TTL
X-Jobs
X-L-Path
SRV
X-Region
X-Framework
X-Source
Access-Control-Request-Headers
X-N
X-Page-View
X-FW-Serve
Fastly-SIE
X-FW-Type
X-FW-Hash
X-Oracle-Dms-Ecid
X-FW-Version
Fastly-SWR
X-Cache-Time
From-Origin
X-FW-Dynamic
X-FW-Server
X-FW-Static
X-Tumblr-Pixel-1
X-Time
X-RemovedCookies
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Adobe-Content
X-Adobe-Loc
X-Oracle-Dms-Rid
X-G
X-ProcessESI
X-Tumblr-User
X-Load-Cache
X-COUNTRY
ServerID
Content-Disposition
X-Drupal-Cache-Tags
X-CDN-Forward
Country
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
X-RateLimit-Reset
X-Language
X-HTML-Minification-Powered-By
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Vcache
Accept-Language
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Datadog-Sampled
X-DynaTrace
X-DataDome
Liferay-Portal
X-Amzn-Remapped-Content-Length
Countrycode
X-Debug-IsConnected
X-Mg-Request-UUID
X-Debug-IsPreview
X-DynaTrace-JS-Agent
X-Generated-By
X-B3-SpanId
X-ID
X-Nf-Request-Id
Backend
Xet-Cookie
X-WP-CF-Super-Cache-Cache-Control
CF-IPCountry
X-WP-CF-Super-Cache
X-ECache
X-Drupal-Cache-Contexts
X-Tt-Logid
Webserver
Xserver
X-Mode
X-NYM-Debug-Backend
X-B-Cache
X-Signature
X-Nginx-Cache
X-Content-Powered-By
X-Device-Type
X-Zen-Fury
X-Httpd
GEO-INFO
X-Erf-Web-Scheduler
X-Ratelimit-Reset
X-Servername
X-Content-Age
Url
X-Container-Uri
Locale
Azure-Version
X-UPSTREAM-Address
Onion-Location
X-SaId
X-ServerID
X-Sucuri-Cache
Filters
X-Director
X-Sucuri-ID
S-Rt
Load-Balancing
Azure-SiteName
X-Urbn-Context-Path
X-Rewrite-Enabled
X-LAGOON
Azure-InstanceId
X-JoinUs
X-Varnish-Cache-Hits
Azure-SlotName
Azure-RegionName
X-Urbn-Site-Id
X-Cache-Action
X-Cache-Operation
Meta-Geo
X-Git-Commit
X-Soup
X-Proto
X-SayCDN-TTL
X-Tb
X-Say-Cacheable
X-Say-TTL
X-Varnish-Hostname
Uber-Trace-Id
X-Cluster-Node
X-Storage
X-Labrador-Cache-Channel
X-Logging-Id
Web-Mar-Node
X-VCT
X-Ms-Request-Id
X-PHP-Host
X-Ms-Version
X-RM-Cache-TTL
X-Served-From
X-Generation-Time
X-XRDS-LOCATION
X-Forwarded-Host
X-Xrds-Location
X-Detected-As
X-VC-Cache
X-Origin-Hint
X-Proxied
X-RCS-CacheZone
Mn-Server-Ip
Webcakes-Region
X-Zipkin-Id
X-Cache-Server
Webcakes-App-Version
X-Extlb
DB-Nickname
Webcakes-App-Name
TWC-Privacy
TWC-Device-Class
X-GeoCountry
Property-Id
TWC-Connection-Speed
X-Skip-Cache
X-GeoCode
X-Sql-Count
X-Sql-Duration-Ms
TWC-GeoIP-LatLong
TWC-GeoIP-Country
X-Adobe-Source
TWC-Locale-Group
Fastcgi-Useragent
Node
X-Routing-Service
X-FB-TRIP-ID
X-Tumblr-Pixel-3
X-R9-Blue-Green-Version
X-Proxy-Build
X-Timing-Wait
X-Fetched-On
X-Format
X-Tumblr-Pixel-2
X-Uri
X-LSADC-Cache
X-Debug
Selected-Fe
CDN-RequestId
X-Tec-Api-Origin
X-Tec-Api-Root
Fastly-Drupal-HTML
X-Tec-Api-Version
X-Lambda-Id
X-MP-GENERATED-AT
X-Cache-Expired-At
X-Origin-Date
X-Via-JSL
OT-Force-Account-Verify
Source
X-Cache-Hit
X-NGENIX-Cache
X-Template
X-MCACHE
X-Varnish-Hits
X-Node-Name
Content-Secure-Policy
X-AIR-PT
X-UA-Device-Type
X-Cache-TTL-Remaining
X-Tncms
X-Loop
X-Pass-Why
X-Endurance-Cache-Level
X-Ua
X-Pubstack
Upgrade-Insecure-Requests
X-Srv
Cross-Origin-Window-Policy
X-Redis-Cache
X-Server-W
NGB
X-PHP-Backend
X-Real-IP
X-Origin-CC
X-Origin-TTL
X-Fastly-Request-Id
X-CCDN-Origin-Time
X-Hcs-Proxy-Type
Cache-Hits
X-CCDN-CacheTTL
X-RTag
Section-Io-Origin-Status
MS-CV
Section-Io-Id
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
Ms-Operation-Id
X-Cache-Host
Cache-Name
Cache-Provider
X-Restarts
X-Reqid
X-Cms-Context
X-Xfnlog-Site
X-S
X-Optimistic-Header
X-GEO
X-IPLB-Instance
X-IPLB-Request-ID
Apigw-Requestid
X-Cache-Type
X-CACHE-AGE
CDN-Cache
CDN-CachedAt
CDN-PullZone
CDN-Uid
CDN-RequestPullCode
CDN-RequestCountryCode
CDN-RequestPullSuccess
CDN-EdgeStorageId
X-No-Session
X-ProxyCache-Status
X-ProxyCache-Key
X-BYPASS-REASON
X-Datadome
X-CSRF-Token
X-Via-Fastly
X-AWS-Id
X-Presslabs-Stats
X-Cluster
X-LJ-Flow-ID
X-VWS-Id
X-Hl-Ver
X-Aspnetmvc-Version
X-Access
X-Rn-Rsrv
X-Section
X-CGP
X-Cache-NE
X-Cache-Info
X-Cdn-Diag
X-CF-Lambda-Fn
BehaviorPad-Version
X-Conf
X-CF-Lambda-Version
X-CacheTTL
X-Developer
X-Ec-GeoHdr
X-Ec-Fail
Rendered-Blocks
X-Epic-Correlation-Id
X-Eu-Site
X-Fastly-Backend
X-External-Request-Id
X-Ec-Custom-Error
X-Dispatcher-Number
X-Date
X-D
X-Debug-Cache-Fetch
X-Debug-Cache-Store
Sslversion
X-Destination
X-Csrf-Jwt
X-BCube-Filmed-By
X-A-Dcw
X-A-Dam
X-A-Ccd
Odigeo-Trace-Id
Lang
L5d-Success-Class
X-Accel-Expires-Debug
X-A-Wwc
X-A-Dgt
L
VNS-Age
Magicmarker
Web-Mar-Region
Meta-Geo-Continent
We-Hiring
N-Cache
X-A
MD5-Digest
VNS-Cache
Ngx.Var.Host
Mail-Subject
HA-Ipaddr
Ha-Gx-Prefs
X-Bc-Bl
CPC-Age
CPC-Cache
X-B-Cookie
W
X-Bl-Debug
Redirect-Candidate
Canary
Candidate-Md5Url
X-Cache-Bucket
DCR-Decision-By
DCR-Processing-Time-Ms
Fastly-GeoIP-CountryCode
Vix-Hermes-Req-Id
Gannett-Cam-Experience-Id
Gh-Request-Id
Fastly-Backend-Name
T-Server
X-Application
X-Aed
X-FC-Vary-Parameters
Surrogated-Key
X-Irp-Debug
X-RateLimit-Limit-Second
X-Proxy-Cache-Status
X-RateLimit-Remaining-Second
X-Request-Host
X-Newrelic-Synthetics
X-Policy
X-Vdms-Version
X-We-Are-Hiring
X-Vtex-Remote-Cache
X-Akamai-Transformed
X-VG-WebCache
X-Vdms-Path
X-Rojux
X-Tenant
X-Slack-Backend
X-Slack-Shared-Secret-Outcome
X-SRCache-Key
X-Shop-Environment
X-SD-PageType
X-S-Cookie
X-Var-Ttl
X-ScT
X-TIM-N
X-Origin-Time
X-Viewer-Country
X-GeoIP-Region-Code
X-Gdpr
Server-Host
X-Wikidot-Backend
X-Mvc-Supplant-Cachable
X-Nyt-Route
X-Orig-Expires
X-GeoIP-Country-Code
X-Wikidot-Static-Cache
X-Forwarded-Path
Xc-Version
X-Test
X-JWT-State
X-Thanos
X-Thinkindot-L3
X-SVT-ORM-RULES
X-Sorting-Hat-ShopId
X-Storefront-Renderer-Rendered
X-Worker
X-SVT-ORM-VERSION
X-Wix-Viewer-Type
X-Varnishpool
Fastly-SSL
True-Client-Country-4JS
X-VG-TLSProxy
X-Sorting-Hat-PodId
X-WADP-Cache
X-Accel-Buffering
Thinkindot-Control
X-Has-Esi
X-Up
TDXMobile
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
X-Is-Gdpr
X-BBC-Edge-Cache-Status
X-Old-Content-Length
X-Node-Id
X-Mly-Id
X-Org
X-Origin-Response-Time
X-Core-Mission
X-Core-Value
X-Owner
X-Level-Front-Cache
X-INCAP-ABP
X-Geo-Header
X-Generated-On
X-Forwarded-Site
X-Gzip
X-Handled-By
X-Esi-Check
X-Human
X-Hash
X-PAYTM-SRV-ID
X-CMSURLCustom
X-ShardId
X-Fmm-Version
X-Server-IP
X-ShopId
X-Shopify-Stage
X-ApacheServer
X-App-Name
X-Auto-Login
X-Bip
X-S-Maxage
X-Platform
X-Clara-WADP
X-PERF
X-Pool
X-Request-Time
X-Cache-Debug
X-Cache-Id
X-Alternate-Cache-Key
X-Clientip
Cmstype
X-TimeS
Cmsid
Machine
Origin
Memcached
Host-ID
Req-Svc-Chain
Datacenter
Environment
AKAMAI
X-Vcl-Version
X-TIME
User-Cache-Control
WP-Super-Cache
X-Web-Node
CDCHOST
Platform
X-Block-Status
Is-Eu
X-Cdn-Srv
Apple-News-Services-Request-Url
CloudFront-Viewer-Country
DSUID
X-DefHash
X-DefElseHash
Country-Code
Apple-News-Services-Parsed-Url
X-Cdn-Origin
Adler-Geo
X-Parent-Response-Time
X-NodeID
X-Gen-Mode
X-Nginx-Cache-Key
X-Hnp-Log
X-Mid
X-Mvc-Supplant-OutputCached
X-Nananana
X-Origin
X-From
X-DPWN-IS-SECURE
Apple-News-Services-Handled
Apple-News-Services-Host
X-WA-Info
X-Device-Os
X-TA-CDN-Provider
X-Scale
X-Dispatcher-Server
Expect-Staple
Producers
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
X-Varnish-CookieHashed-On
X-Variation
NM-Fastcgi-Cache
ServedBy
X-VServer
Release
Sever-Int
Server-Hostname
Server-Ext
X-Sn-Servicetimems
X-Vmg-Version
X-Loc
X-Qloud-Router
Esi-Enabled
X-Air-Trace-Id
X-Air-Source
X-Air-Hostname
X-Azure-Ref-OriginShield
X-Instance-Name
Ssr
X-Akamai-Device-Characteristics
X-LB-NoCache
Pics-Label
X-NCache
Origin-CC
Origin-EX
X-GeoIP
X-App
X-Nitro-Cache
X-Cs
Wxu-Next-Hostname
Wxu-Next-Region
C-Via
X-Op-Id-All
Wxu-Next-Commit
X-Cache-Enabled
Server-Info
Server-ID
X-Amz-Meta-Cb-Modifiedtime
X-Refresh
Memory
Time
X-Tx-Id
AMP-Access-Control-Allow-Source-Origin
X-Platform-Processor
X-Platform-Cluster
X-Platform-Router
X-Cache-Status-Check
X-HA-Backend
X-Microcachable
Cache-Host
X-Locale
X-Site-Version
XM
NGX
X-Correlation-ID
X-Origin-Expires
PFcat
Hostname
X-HN
X-VarnishDD-TTL
GeoIP-Latitude
X-VHOST
X-Dc
X-Tb-Optimization-Total-Bytes-Saved
X-API-Version
Origin-Agent-Cluster
Resin-Trace
X-CACHE-GROUP
Cf-Device-Type
X-ZONE
X-DC
X-Varnish-Beresp-Ttl
Srvid
X-Via-CDN
X-Via-Edge
X-Via-SSL
X-Varnish-Beresp-Grace
A
X-FL-EDGE
Edge-Copy-Time
Locid
X-Ad-Defer-Variation
X-FL-QIT-DEBUG
X-Wp-Cf-Super-Cache-Active
X-Zone
X-Fpc
X-Vgn-Hpd-Reason
YJS-ID
X-Upstream-Ht
X-Upstream-Ct
Cdn-Requestid
X-FireWall-Port
X-Webkit-Csp-Report-Only
X-Internal-Host
X-ATG-Version
Sid
Cache-Key
X-Micro-Cache
X-Cache-ASPX
X-Contensis-Viewer-Groups
X-WP-CF-Super-Cache-Active
X-Github-Request-Id
Uri
X-Varnish-Authentication
X-DataCenter
X-Moov-Xdn-Version
X-Moov-T
X-Pod-Name
X-Cached-By
X-TraceId
User-Agent
True-Client-Ip
X-LiteSpeed-Cache-Control
X-Provided-By
X-SIPLIST1
State
X-Planisys-CDN-TTL
X-Planisys-CDN-Cache
X-Info
X-HS-Content-Campaign-Id
IsBot
X-Planisys-CDN-Rules
Location
X-B3-Spanid
X-AB
X-URL
X-Fastly-Cache
X-B3-Parentspanid
X-Platform-Server
GeoIP-Country-Code
X-RN-RSRV
X-Buckets
X-Sigma
X-NGINX-Cache
X-Release
X-Cache-Remote
X-VC
X-VCache
X-Sigma-Backend
X-Geo-Region
X-Backend-Instance
X-Nitro-Rev
GeoIp-Country-Code
X-Nitro-Cache-From
X-Rocket-Build-Number
X-LiteSpeed-Tag
SID
X-Api-Version
X-CS
X-Datacenter
X-MSEdge-Features
X-CSRF-TOKEN
X-MSEdge-Flight
X-Accel-Version
Cdn
Cache
XServer
X-Gamma-Serve
X-Geo
NtCoent-Length
X-Generated-In
True-Client-IP
X-FTR-Request-ID
CF-Ctrl
Srv
X-NewRelic-App-Data
X-Vgn-Hpd-Variations-Key
Path
X-GeoIP-City
X-Vgn-Hpd-Ssi
Lb
X-Vgn-Hpd-Cached
Cache-Tv-Group
X-Is-Mobile
X-Tcp-Rtt
X-Is-Tablet
X-Is-Desktop
X-Browser-Name
X-Is-Supported-Browser
X-SRV
X-Scheme
X-Rebelmouse-Surrogate-Control
X-TRACE-ID
X-Rebelmouse-Cache-Control
X-HS-Status
CountryCode
X-Hyper-Cache
Kp-EeAlive
HostName
X-FPC
Epwk-X-Cache
Fastly-Drupal-Html
X-Frame-Option
X-HostName
Tcn
X-Mobile-URL
X-GoCache-CacheStatus
Ohc-File-Size
X-Service
X-Amz-Meta-Opti
X-Location
X-APP-VERSION
Serverid
X-TX-ID
X-UA
Cf-Ipcountry
X-Men
X-AK-Request-ID
On-Server
Cdncip
Cdnsip
X-Webstats-RespID
X-Aicache-OS
X-Developers
X-Region-Sid
X-Air-Pt
CacheControlHeader
X-Esi
X-Guploader-Uploadid
X-Via-Popv
X-Via-Popn
X-Via-Poph
X-Cache-Ttl
Click-Count-Error
Tube-Got-Results
Tube-Got-Eval
X-Traceid
X-Branch-Name
X-V-Cache
X-Wp-Cf-Super-Cache
RNT-Machine
X-B3-Trace-ID
RNT-Time
X-Wp-Cf-Super-Cache-Cache-Control
X-SB
X-EC-Lua
WebServer
X-Req
Tube-Return
Tube-Get-Contents
Mime-Version
X-LB-ID
X-Cache-FS-Status
Click-Count-Action-Start
X-Cache-Tags
X-Acquia-Purge-Cdn-Unconfigured
Proxy-Connection
X-Minions-Version
V-Age
X-CDN-Cache-Status
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-Nc
X-Proxy-CacheRZ
XkeyRZ
X-Wa
X-Vc
X-Pad
X-Cdn-Cache-Status
Env
Yak-Timeinfo
X-Servedbyhost
ENV
WWW-Authenticate
Ohc-Cache-HIT
WZWS-RAY
X-CACHE-KEY
X-VCL-Version
CDN
Cdn-Host
Cdn-Request-Time
X-Vercel-Cache
LB
X-Fastly-Country-Code
X-Edge-Server
Geoip-Latitude
X-Vercel-Id
Ngx
X-User
X-NWS-UUID-VERIFY
X-Cdn-Forward
X-Edge-Pop
X-Akamai-Pragma-Client-IP
CF-Cached-On
X-Check-Cacheable
X-Lb-Cache
Req-ID
X-FTR-Backend-Server
X-Processor
Content-Style-Type
Content-Script-Type
X-FTR-Backend
X-FTR-Balancer
X-TH-Server
X-Ckpd-Fst-Backend
Server-Id
X-WP-CF-Super-Cache-Cookies-Bypass
M-TraceId
X-Origin-Cache-Key
X-NMSegId
X-Country-Code-Real
X-FTR-Cache-Status
X-FTR-Expires
X-Ha-Backend
X-TT-LOGID
PICS-Label
Cluster
X-Snapshot-Date
X-MiniProfiler-Ids
X-Ad-Load-Variation
X-Lb-Nocache
HIT
X-APP
X-Litespeed-Cache-Control
X-Cdn-Request-ID
X-Acquia-Purge-Tags
X-Acquia-Site
X-Render-Time
X-CUA
X-IN-APIGATEWAYSSL
X-IN-APIGATEWAY
X-Via-Ucdn
X-Edge-POP
X-Acquia-Application-Trace
X-Acquia-Application-UUID
X-Dw-Trace-Id
Yjs-Id
Edge-Cache
Cneonction
X-Request-Start
X-Miniprofiler-Ids
Log-Origin
X-Fastly-Backend-Reqs
X-Response-By
CACHE-MISS-TO-ORIGIN
Sm-Log-Id
X-Iauth-Set-Uid
X-Service-Response-Time
X-Serial
Inserted-Into-Cache-At
X-Fastly-Cache-Hits
X-M-Log
X-M-Reqid
X-RAMCache
X-Udemy-Cache-App-Namespace
X-ElasticPress-Query
Vha6-Origin
X-Cached-Since
X-Cache-Date