Threat Level: green Handler on Duty: Jan Kopriva

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Link
Cf-Request-Id
CF-Cache-Status
Accept-Ranges
ETag
CF-RAY
Expect-CT
Pragma
X-Powered-By
X-XSS-Protection
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-UA-Compatible
X-Cache-Hits
Alt-Svc
P3P
X-Served-By
X-Xss-Protection
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Request-Id
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
CF-Ray
X-Check
X-Cache-Status
X-Generator
X-Cacheable
Timing-Allow-Origin
X-Content-Security-Policy
P3p
X-Iinfo
Status
Feature-Policy
X-Request-ID
X-Envoy-Upstream-Service-Time
Content-Encoding
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
X-AspNetMvc-Version
X-CDN
Upgrade
X-Via
X-Ws-Request-Id
Access-Control-Max-Age
Server-Timing
EagleId
Keep-Alive
X-Cache-Group
X-Turbo-Charged-By
Request-Context
X-Age
X-Server-Powered-By
X-Proxy-Cache
X-AH-Environment
X-UA-Device
X-Backend
X-Hacker
X-Robots-Tag
Report-To
X-Amz-Request-Id
Host-Header
X-Server
X-LiteSpeed-Cache
X-Amz-Id-2
Grace
X-Dns-Prefetch-Control
X-Rq
X-Nginx-Cache-Status
X-Varnish-Cache
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-WebKit-CSP
X-Page-Speed
X-Vhost
EagleEye-TraceId
X-Amz-Version-Id
X-OneAgent-JS-Injection
X-Pingback
X-Device
X-Dispatcher
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Cache-Spec
NEL
X-Server-Id
X-Host
Cf-Railgun
X-Backend-Server
X-Node
Accept-CH
X-Readtime
X-Akam-SW-Version
Surrogate-Control
Request-Id
X-Response-Time
X-HW
Xkey
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Application-Context
Content-Location
X-Ruxit-JS-Agent
Rating
X-B3-TraceId
X-Ua-Compatible
Accept-Ch-Lifetime
X-Country
Accept-CH-Lifetime
X-Cache-Lookup
X-Cloud-Trace-Context
X-Language
X-Url
X-Ac
X-Trace
X-Content-Type
Allow
X-Template
X-TtlSet
X-PC
X-Vname
X-Varnish-TTL
X-Mod-Pagespeed
X-Clacks-Overhead
Edge-Control
X-FastCGI-Cache
X-ESI
Cache-Tag
Fastly-Restarts
X-Server-Name
X-Rack-Cache
Service-Worker-Allowed
X-VARITI-CCR
X-Element-Page-Cache
Verso
X-MS-InvokeApp
X-GitHub-Request-Id
X-Buckets
X-Upstream
X-Amz-Rid
MS-Author-Via
Public-Key-Pins
X-Vcap-Request-Id
X-Dw-Request-Base-Id
X-Cached
X-Client-IP
X-Abt-Application-Version
X-D2id
X-Origin-Cache
X-Cache-TTL
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
Arr-Disable-Session-Affinity
X-Px
X-Cnection
X-Aws-Lambda-Call-Status
X-Goog-Hash
Access-Control-Request-Method
X-Country-Code
X-Powered-By-Plesk
X-Navigation-Version
X-NF-Request-ID
X-Server-Lifecycle-Phase
RTSS
X-Kraken-Loop-Name
X-Instrumentation
X-Version
Accept-Ch
X-Powered-CMS
X-Amz-Server-Side-Encryption
Display
X-Middleton-Display
Pagespeed
X-Sol
X-Kinja-Build
X-Kinja-Revision
X-Use-Magma
X-Kinja
X-Kinja-Server
X-GoogleNews-Bot
X-Cdn-Fetch
X-Exp-Id
X-Exp-Variant
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Middleton-Response
Response
X-MSEdge-Ref
X-LLID
X-Edge-Location-Klb
X-Kinsta-Cache
AR-Request-ID
AR-PoweredBy
AR-CACHE
AR-ATIME
AR-SID
X-Edge
Nginx-Cache
MRF-Tech
Mrf-Cache-Status
X-B3-TraceId-Primal
X-Shield-Request-Id
X-RateLimit-Remaining
X-TTL
X-Jurisdiction
X-HP-Trace-Id
X-Protected-By
X-HP-Webp
S
X-T
X-Forwarded-For
Content-MD5
TCN
X-Content-Security-Policy-Report-Only
X-Mg-S
X-Id
X-CST
Realpath
X-Aspnetmvc-Version
X-Mid
Fastcgi-Cache
X-MCACHE
Edge-Cache-Tag
SPRequestDuration
SPIisLatency
Front-End-Https
X-Recruiting
X-Parallel-Accel
X-Request-Processing-Time
X-Request-Received
Filters
Fusion-Template-Id
Fusion-Content-Source
Fusion-Deployment-Id
Fusion-Source
Fusion-Content-Id
Fusion-Component-Id
Pinterest-Generated-By
Server-Node
Pinterest-Version
X-Pinterest-Rid
X-Ua-Browser
X-Content
X-Ab
X-Ttl
X-DynaTrace
X-Correlation-Id
X-SharePointHealthScore
SPRequestGuid
Server-Name
X-Ruxit-Js-Agent
X-Ezoic-Cdn
X-NWS-LOG-UUID
X-Frontend
X-HS-Content-Id
X-HS-Combine-CSS
X-HS-Cache-Config
X-HS-Hub-Id
Alternate-Protocol
X-ECACHE
X-Yandex-Sdch-Disable
X-Hits
X-Cache-Key
X-Content-Options
X-Accel-Expires
X-Tt-Trace-Tag
X-Tt-Trace-Host
MicrosoftSharePointTeamServices
X-Ser
X-Page-Id
Cache-Tags
Host
X-Git-Hash
X-Kong-Upstream-Latency
Charset
X-Kong-Proxy-Latency
X-Fastly-Request-Id
Cleartype
X-Www-Served-By
X-B3-Sampled
X-Geo-Country
X-Daa-Tunnel
X-Content-Digest
X-Amz-Replication-Status
Filterid
TP-Cache
TP-L2-Cache
X-Amzn-Trace-Id
X-Forwarded-Proto
X-DIS-Request-ID
X-Varnish-Age
X-VCache
X-Hostname
X-AppVersion
X-Az
X-Activity-Id
X-Debug-Info
X-Rid
X-XRDS-LOCATION
X-N
X-Grace
X-Upgrade-Enabled
X-Origin-Server
Access-Control-Allow-Method
X-FB-Debug
X-LB-Cache
X-Origin-Upstream-Status
X-WebKit-CSP-Report-Only
ServerID
X-Nginx-Upstream-Cache-Status
Cross-Origin-Opener-Policy
X-Mobile-URL
X-Route-Name
X-Is-Crawler
X-Providence-Cookie
X-F-Cache
X-Request-Guid
X-Aspnet-Duration-Ms
X-Flags
X-Whom
X-TT
X-GUploader-UploadID
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-Goog-Metageneration
X-Goog-Generation
X-Tb
X-Varnish-Grace
X-App-Environment
X-Request-Handler-Origin-Region
Viewport
X-App-Server
X-Microsite
X-NGENIX-Cache
X-Distributor
X-FW-Serve
X-FW-Hash
Payment
X-FW-Type
X-FW-Static
X-FW-Dynamic
X-FW-Server
DC
Paypal-Debug-Id
X-Server-ID
Node
X-Ratelimit-Limit
X-Seen-By
X-Type
X-Cache-Control
Fastcgi-Useragent
X-Logged-In
X-Oneagent-Js-Injection
X-User-Agent
Country
Accept-Charset
X-Cache-Age
X-Litespeed-Cache
X-Cache-Rule
X-Wix-Request-Id
X-DataDome
X-Varnish-Backend
X-Webkit-CSP
Version
X-Load-Cache
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Browser-Type
X-PressLabs-Stats
X-Node-Name
X-Cache-Action
Refresh
Referer-Policy
X-Drupal-Cache-Tags
X-Via-JSL
X-IPLB-Instance
X-Tec-Api-Version
X-Tec-Api-Root
X-Tec-Api-Origin
Cache-Status
Access-Control-Request-Headers
X-Original-Request-Id
SD-X-WS
X-Cluster-Name
Amp-Access-Control-Allow-Source-Origin
X-Response-Served-From
X-Page-View
X-Vgn-Hpd-Reason
X-Is-Bot
X-Proxy-Cache-Status
X-Real-IP
X-Jobs
X-Mobile
X-Rendered-As
X-Cacheable-TTL
X-B-Cache
X-Contextid
X-Signature
X-RemovedCookies
X-ProcessESI
X-Revision
X-UUID
NGB
VIX-Pulpo-Upstream-Status
X-B
X-Debug
VIX-Pulpo-Node
X-Cache-Expired-At
X-Device-Type
X-Proxy
X-Yottaa-Metrics
X-Rule
X-Yottaa-Optimizations
X-G
X-Framework
X-Fastly-Request-ID
X-Cache-Time
Akamai-GRN
X-Drupal-Cache-Contexts
Surrogate-Key
X-Instance
X-Debug-IsConnected
DynaTrace
X-Debug-IsPreview
X-FW-Version
X-Fastcgi-Cache
CF-IPCountry
Liferay-Portal
X-Air-Trace-Id
X-Air-Hostname
X-Air-Source
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-TEC-API-VERSION
Healthy
X-Azure-Ref
SID
X-Source
X-Oracle-Dms-Rid
X-Oracle-Dms-Ecid
X-XRDS-Location
X-Ms-Request-Id
X-Ms-Version
Frame-Options
MS-CV
X-RTag
Ms-Operation-Id
X-APP-VERSION
X-Cache-Hit
X-Nginx-Cache
X-CDN-Forward
Count-Hit
GEO-INFO
X-Tumblr-Pixel-0
X-L-Path
X-Environment-Context
X-Cache-Operation
X-Tumblr-Pixel
X-Tumblr-Pixel-1
Countrycode
X-Tumblr-User
X-Varnish-Server
Xserver
X-Ratelimit-Reset
Uber-Trace-Id
X-EdgeConnect-Cache-Status
X-Region
X-Accel-Buffering
X-Servername
Section-Io-Cache
X-Content-Powered-By
X-Backend-Name
X-Mode
X-Presslabs-Stats
X-Forwarded-Host
X-Zen-Fury
Cross-Origin-Window-Policy
Ec-Rule-Version
X-IPS-LoggedIn
Backend
X-UPSTREAM-Address
Meta-Geo
X-RN-RSRV
X-SaId
X-JoinUs
X-Detected-As
X-Cache-NGX
Country-Code
X-Cache-Server
X-Tid
X-Debug-Cache
X-Sql-Duration-Ms
X-Human
X-Generation-Time
X-Redis-Cache
X-Cache-Type
X-Sql-Count
X-Adobe-Loc
X-Uri
X-Adobe-Content
X-Origin-Date
Decoy-Debug-Key
X-Sorting-Hat-ShopId
X-ProxyCache-Status
X-Alternate-Cache-Key
Decoy-Debug-TTL
X-Via-Fastly
X-Varnish-Beresp-Grace
Mn-Server-Ip
X-UA-Device-Type
Eomportal-Instance
Decoy-Debug-Status
X-Sorting-Hat-PodId
Url
DB-Nickname
Cache-Tv-Group
X-ShardId
X-ServerID
X-FB-TRIP-ID
Cache-Name
X-BYPASS-REASON
X-PHP-Backend
Apigw-Requestid
X-ProxyCache-Key
X-ShopId
X-NCache
X-Cache-Grace
X-No-Session
X-Microcachable
X-Hosted-By
X-Shopify-Stage
X-Origin-Hint
Property-Id
Fastly-SSL
X-Web-Node
X-Proxy-Build
X-Say-Cacheable
X-Rewrite-Enabled
Webcakes-Region
X-Site-Version
X-SayCDN-TTL
X-Say-TTL
X-OCL
X-Format
X-Akamai-Edgescape
X-Cache-Host
X-PCL
X-Cache-TTL-Remaining
Webcakes-App-Version
X-Status
TWC-GeoIP-Country
TWC-Device-Class
TWC-Connection-Speed
Selected-Fe
TWC-GeoIP-LatLong
X-Timing-Wait
TWC-Privacy
TWC-Locale-Group
X-Storage
Protected
Webcakes-App-Name
X-Proxied
X-Varnishpool
OT-Force-Account-Verify
X-Routing-Service
X-Zipkin-Id
X-Server-W
X-Hl-Ver
X-Section
X-NYM-Debug-Backend
X-ApacheServer
X-Access
X-PERF
X-R9-Blue-Green-Version
X-Pubstack
X-Soup
X-Extlb
Azure-SlotName
Azure-SiteName
Azure-RegionName
Azure-Version
Azure-InstanceId
Content-Secure-Policy
X-Be
X-Cluster-Node
X-RateLimit-Limit
X-Azure-Ref-OriginShield
X-Ua
Source
X-NewRelic-App-Data
X-LSADC-Cache
X-Content-Age
CDN-EdgeStorageId
CDN-RequestCountryCode
CDN-Uid
CDN-CachedAt
CDN-RequestId
X-Webkit-Csp
CDN-PullZone
CDN-Cache
X-Generated-By
Cache
SRV
X-SRV
X-Hyper-Cache
X-Cached-By
Content-Disposition
X-Dc
X-HTML-Minification-Powered-By
X-Unique-Id
X-LAGOON
X-Trace-Id
X-Amz-Meta-S3cmd-Attrs
X-App-Version
X-Nginx-Cache-Key
X-Bc-Bl
X-Cache-Var-Map
X-Cache-Var
X-Varnish-Hostname
X-Varnish-Hits
X-Loop
X-TNCMS
X-Time
X-Auto-Login
X-S-Maxage
Xet-Cookie
LB
Onion-Location
X-GEO
Retry-After
X-TT-LOGID
X-Origin-CC
Cache-Hits
X-Origin-TTL
X-Tumblr-Pixel-3
Web-Mar-Node
X-Tumblr-Pixel-2
X-TIME
X-ECache
Mime-Version
X-Proto
X-Cdn
X-Platform-Server
WPO-Cache-Status
WPO-Cache-Message
X-M-Log
X-Qnm-Cache
X-M-Reqid
X-Time-Microsecs
X-Tenant
X-Endurance-Cache-Level
X-Akamai-Transformed
X-Edge-Location
Webserver
X-AWS-Id
X-GG-Cache-Date
HostName
X-LJ-Flow-ID
X-Cache-Remote
X-Xfnlog-Site
X-CSRF-Token
X-VWS-Id
X-Cache-Tags
CloudFront-Viewer-Country
X-Mg-Request-UUID
X-Varnish-Cache-Hits
Upgrade-Insecure-Requests
N-Cache
X-CACHE-KEY
X-Amz-Apigw-Id
X-Labrador-Cache-Channel
X-Request-Time
X-Amzn-RequestId
ServedBy
X-PHP-Host
X-Ratelimit-Remaining
X-AOL-HN
X-B3-SpanId
X-RCS-CacheZone
X-Via-NSCOPI
X-Origin-Response-Time
X-Handled-By
X-B-Cookie
X-VG-WebCache
Meta-Geo-Continent
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
Odigeo-Trace-Id
Mobile-Detection-Method
X-CF-Lambda-Version
X-PBS-Appsvrname
Expiry
X-Hnp-Log
X-NAPM-TraceId
X-ND-Cache
Fastcgi-X-Cache-Version
DSUID
X-Ig-Push-State
BehaviorPad-Version
DCR-Decision-By
A
DCR-Processing-Time-Ms
X-Gen-Mode
X-Orig-Expires
X-Block-Status
X-CF-Lambda-Fn
X-Forwarded-Path
X-Cache-NE
Xc-Version
X-Planisys-CDN-TTL
X-Ftr-Request-Id
X-PAYTM-SRV-ID
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Processor
X-Vdms-Path
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-Session-Fingerprint
X-Conf
X-A
X-Destination
X-Developer
X-ScT
X-SD-PageType
X-Correlation-ID
X-Shop-Environment
X-External-Request-Id
X-Connection-Hash
X-D
X-Aed
X-SRCache-Key
X-A-Wwc
X-V-Cache
Surrogated-Key
X-A-Dcw
X-A-Dgt
User-Cache-Control
X-S-Cookie
X-A-Ccd
X-S
Pramga
X-Vdms-Version
X-Request-Host
Nel
X-Application
X-TIM-N
X-ARC
X-Ckpd-Fst-Backend
X-Rojux
Origin
Redirect-Candidate
Rendered-Blocks
X-Cluster
X-A-Dam
X-VC-Cache
X-MP-GENERATED-AT
X-Locale
X-Accel-Expires-Debug
Fastcgi-Cache-TTL
Wxu-Next-Commit
CacheControlHeader
Cmsid
X-Core-Mission
Cmstype
CDCHOST
Wxu-Next-Region
X-Li-Pop
X-Li-Fabric
Wxu-Next-Hostname
X-LI-UUID
X-Fetched-On
X-Forwarded-Site
State
X-Cache-Bucket
X-Device-Os
Release
Origin-CC
Origin-EX
X-Fastly-Cache
X-Epic-Correlation-Id
X-Cache-Date
X-Cache-Info
Host-ID
Vix-Hermes-Req-Id
X-Geo-Header
Gh-Request-Id
X-Gdpr
L
X-Date
Traceparent
V-Age
X-Hash
X-Policy
X-Adobe-Source
X-Storefront-Renderer-Rendered
X-Proxy-Upstream
X-ATG-Version
X-Webstats-RespID
X-Mvc-Supplant-Cachable
X-Slack-Backend
X-Skip-Cache
X-Scheme
X-Old-Content-Length
X-Nyt-Route
X-Server-IP
X-Origin-Expires
X-Served-From
X-Varnish-Beresp-Status
X-Rocket-Nginx-Serving-Static
X-Owner
X-Reqid
Server-Info
Arc-Country
X-Sucuri-ID
AKAMAI
X-VServer
X-Location
From-Origin
X-Origin-Time
X-Sucuri-Cache
X-Men
X-FireWall-Port
Environment
AMP-Access-Control-Allow-Source-Origin
X-Rocket-Build-Number
Svr
Req-Svc-Chain
TDXMobile
X-Developers
Server-Host
X-VarnishDD-TTL
True-Client-Country-4JS
X-Magnolia-Registration
X-Core-Value
Web-Mar-Region
X-TH-Server
X-Thanos
X-TrackingId
X-Thinkindot-L3
We-Hiring
X-Datadog-Parent-Id
X-Sigma
Thinkindot-Control
Thinkindot-CacheControl-Type
X-Sigma-Backend
X-VG-TLSProxy
X-Datadog-Sampling-Priority
X-Datadog-Trace-Id
Thinkindot-CacheControl
X-BBC-Edge-Cache-Status
X-Cache-Debug
Fastly-GeoIP-CountryCode
X-NodeID
X-Gzip
X-GeoIP-City
X-Viewer-Country
X-Generated-On
X-GeoIP
X-Node-Id
X-HN
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
X-Level-Front-Cache
Apple-News-Services-Handled
X-HS-Content-Campaign-Id
X-Irp-Debug
X-Cache-Id
X-Cache-Config
Sslversion
X-Fastly-Backend
X-Cdn-Srv
X-Req
X-Esi-Check
X-Request-Start
PFcat
Locid
X-Bip
X-Aicache-OS
X-Platform
Mail-Subject
Machine
X-Branch-Name
X-Zone
WP-Super-Cache
X-Worker
X-Varnish-CookieHashed-On
X-Cdn-Origin
X-CGP
Ssr
X-Varnish-Remaining-TTL
X-Varnish-CookieINHashed-On
X-DPWN-IS-SECURE
X-Qloud-Router
X-Pod-Name
X-RateLimit-Limit-Second
X-FC-Vary-Parameters
X-RateLimit-Remaining-Second
X-Gamma-Serve
X-Origin
X-JWT-State
X-Is-Gdpr
X-NU-AKA-ACS-Version
X-Has-Esi
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-DefElseHash
X-DefHash
X-Sn-Servicetimems
X-Csrf-Jwt
X-UnsetCookies
X-Loc
X-Response-By
X-Region-Sid
X-Eu-Site
X-Envoy-Decorator-Operation
X-Request-URI
X-Variation
X-Amzn-Remapped-Content-Length
Fastly-SIE
Fastly-SWR
Fastly-Drupal-Html
Datacenter
Platform
Adler-Geo
Cf-Device-Type
Ha-Gx-Prefs
HA-Ipaddr
NGX
NM-Fastcgi-Cache
Memcached
L5d-Success-Class
X-Backend-State
Is-Eu
X-Xrds-Location
X-EC-Lua
Candidate-Md5Url
X-Mvc-Supplant-OutputCached
X-Tx-Id
X-NWS-UUID-VERIFY
X-Ua-Device
X-CS
X-CLOUD-TRACE-CONTEXT
X-Varnish-Beresp-Ttl
X-Cache-Enabled
X-NC
X-API-Version
CDN
On-Server
X-Vc
X-Up
X-LB-ID
WWW-Authenticate
X-Backend-TTL
Pics-Label
X-DynaTrace-JS-Agent
X-Trace-ID
Esi-Enabled
X-Tt-Logid
Memory
X-Refresh
Ms-Author-Via
Time
NtCoent-Length
X-GeoIP-Region-Code
X-GeoIP-Country-Code
X-Datadome
X-TraceId
X-LB-NoCache
X-Tb-Optimization-Total-Bytes-Saved
Magicmarker
X-Edge-Pop
X-Generated-In
C-Via
X-Service
WebServer
X-Via-Poph
Env
GeoIp-Country-Code
X-Via-Popv
X-Via-Popn
X-Dynatrace
X-Varnish-Ttl
X-TA-CDN-Provider
X-Parent-Response-Time
Kp-EeAlive
X-Restarts
X-CacheTTL
X-Optimistic-Header
X-Cache-PHP
S-Rt
X-DC
X-Varnish-Beresp-TTL
X-DW
Edge-Cache
X-RPM
X-RSL
X-DI
X-MSEdge-Flight
X-DSS
X-Wix-Viewer-Type
X-Cache-Status-Check
X-MSEdge-Features
X-DB
X-Render-Time
X-Servedbyhost
X-Cache-Backend
X-RPS
X-Esi
X-Cs
X-Srv
X-ZONE
X-Unique-ID
X-Action
X-TX-ID
X-Akamai-Request-ID2
X-Http-Reason
Server-ID
X-Minions-Version
X-Info
X-VCL-Version
X-AIR-PT
X-LI-Proto
X-Cache-Ttl
X-Newrelic-Synthetics
X-Clientip
X-HA-Backend
X-Li-Proto
X-App
Accept-Language
Proxy-Connection
X-URL
X-LiteSpeed-Cache-Control
X-Oss-Hash-Crc64ecma
HIT
X-FPC
Cache-Host
UCS
X-Webkit-Csp-Report-Only
X-Oss-Object-Type
X-Fpc
Test
X-Oss-Request-Id
X-Oss-Storage-Class
X-Oss-Server-Time
X-Traceid
X-Vcl-Version
X-B3-Spanid
X-Ec-Fail
Locale
X-User
X-Urbn-Site-Id
S-Cnection
Server-Id
X-Ec-GeoHdr
X-Urbn-Context-Path
X-NODE
X-Webkit-CSP-Report-Only
Tcn
Geo-Info
Section-Io-Origin-Status
Lb
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
Section-Io-Id
X-CSRF-TOKEN
Fastly-Backend-Name
User-Agent
X-Pass-Why
X-Micro-Cache
X-Backend-Host
X-HostName
Cdncip
Cdnsip
X-AK-Request-ID
X-LiteSpeed-Tag
Cf-Int-Pingora-Origin-Digest
Fastly-Drupal-HTML
M-TraceId
Hostname
X-Ha-Backend
X-Pad
X-APP
X-WADP-Cache
X-Release
X-Fmm-Version
Cluster
Resin-Trace
My-App
Geoip-Latitude
X-ID
X-ServedByHost
X-Clara-WADP
X-BCube-Filmed-By
X-BBC-Origin-Response-Status
X-Via-PopV
Hit
X-NGINX-Cache
Tracecode
X-CUA
X-Var-Ttl
X-Via-PopN
Ohc-File-Size
X-Check-Cacheable
X-Via-PopH
X-COUNTRY
GeoIP-Country-Code
X-ES-SERVER
X-Dynatrace-Js-Agent
X-Geo
X-ElasticPress-Query
X-From
X-Amz-Meta-Cb-Modifiedtime
T-Server
CPC-Cache
Cache-Key
CPC-Age
X-Cdn-Forward
X-Edge-POP
MIME-Version
EpKe-Alive
X-WA
VNS-Age
ENV
Lfy
Path
X-WA-Info
VNS-Cache
Load-Balancing
Lang
X-Fragments
X-RAMCache
X-Api-Version
X-Edge-Cache
X-HS-Status
Srv
X-Akamai-Pragma-Client-IP
X-Fastly-Backend-Reqs
URI
X-PJAX-URL
X-Ucs
Shield-Pop
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-ServerName
Pagetype
X-Cms-Context
Target-Params
Servername
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
X-Mcache
Uri
X-CCDN-CacheTTL
X-CCDN-Origin-Time
X-Via-Ucdn
MD5-Digest
X-Hcs-Proxy-Type
X-GoCache-CacheStatus
X-UP
X-Lb-Id
X-Fastly-Cache-Hits
X-Dw-Trace-Id
Sid
X-TRACE-ID
IsBot
DataCenter
X-RateLimit-Reset
X-Nc
X-B3-ParentSpanId
Server-Hostname
WZWS-RAY
Cneonction
Ohc-Cache-HIT
Sever-Int
X-VG-WebServer
PICS-Label
Server-Ext
X-Cdn-Request-ID
Cdn
X-SIPLIST1
X-VC
X-Apw-Hits
X-Acquia-Application-Trace
X-Cache-Expires
W
X-Apw-Access-Action
X-Apw-Access-Object
X-Acquia-Application-UUID
X-Apw-Access-Token
X-Acquia-Purge-Tags
Permissions-Policy
X-Httpd
X-Proxy-Cache-Info
FSS-Cache
X-Snapshot-Date
X-Cache-ASPX
Cf-Ipcountry
Cteonnt-Length
X-Acquia-Site
X-Newrelic-App-Data
CF-Cached-On
X-Swift-Error
Vha6-Origin
X-Contensis-Viewer-Groups
X-Yottaa-OS
X-Lb-Nocache
X-Cache-Ngx
X-Air-Pt
Producers
X-Platform-Router
CountryCode
Server-Ttl
X-Varnish-Authentication
X-Akamai-ERPolicy
X-Platform-Processor
ServerName
X-Te-Duration-Ms
X-Last-Modified
X-Akamai-ERRuleID
X-Platform-Cluster
X-Http-Count
X-Miniprofiler-Ids
X-Provided-By
X-Akamai-Request-ID
X-UA
Ngx
X-Logging-Id
HitType
X-CacheKey
X-Sentry-ID
X-Http-Duration-Ms
Req-ID
Dnion-Transfer-Encoding
X-B3-Parentspanid
X-Te-Count