Threat Level: green Handler on Duty: Johannes Ullrich

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-Cache-Status
Link
Accept-Ranges
ETag
CF-RAY
X-XSS-Protection
Expect-CT
Pragma
X-Powered-By
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
Alt-Svc
X-Served-By
X-Xss-Protection
X-Download-Options
X-Timer
X-Request-Id
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
CF-Ray
X-Check
X-Cache-Status
X-Generator
X-Cacheable
Timing-Allow-Origin
X-Content-Security-Policy
X-Iinfo
Feature-Policy
Status
X-Envoy-Upstream-Service-Time
Content-Encoding
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
X-CDN
X-AspNetMvc-Version
P3p
X-Request-ID
Upgrade
X-Via
X-Ws-Request-Id
Access-Control-Max-Age
Server-Timing
EagleId
X-Cache-Group
X-Turbo-Charged-By
Keep-Alive
Request-Context
X-UA-Device
Report-To
X-Age
X-Backend
X-Server-Powered-By
X-Proxy-Cache
X-AH-Environment
X-Robots-Tag
X-Hacker
X-Amz-Request-Id
Host-Header
X-Server
X-Amz-Id-2
Grace
X-LiteSpeed-Cache
X-Rq
X-Nginx-Cache-Status
X-Varnish-Cache
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-Dns-Prefetch-Control
X-WebKit-CSP
X-Page-Speed
X-Vhost
NEL
EagleEye-TraceId
X-Amz-Version-Id
X-Ua-Compatible
X-OneAgent-JS-Injection
X-Pingback
X-Dispatcher
X-Device
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Cache-Spec
X-Host
X-Server-Id
Cf-Railgun
X-Node
X-Backend-Server
Accept-CH
X-Readtime
Surrogate-Control
X-Akam-SW-Version
Request-Id
X-Response-Time
X-HW
Xkey
X-Application-Context
Content-Location
Accept-Ch-Lifetime
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
Rating
X-B3-TraceId
X-Country
X-Ruxit-JS-Agent
X-Cloud-Trace-Context
X-Cache-Lookup
X-Trace
Accept-CH-Lifetime
X-Url
X-Ac
X-Content-Type
X-PC
X-Vname
X-TtlSet
Allow
X-Varnish-TTL
X-Clacks-Overhead
X-Mod-Pagespeed
Edge-Control
X-ESI
X-Server-Name
Fastly-Restarts
Cache-Tag
X-Aws-Lambda-Call-Status
X-FastCGI-Cache
Service-Worker-Allowed
X-VARITI-CCR
X-Rack-Cache
Verso
X-Element-Page-Cache
X-Upstream
MS-Author-Via
X-Vcap-Request-Id
X-MS-InvokeApp
X-GitHub-Request-Id
X-Amz-Rid
Public-Key-Pins
X-Dw-Request-Base-Id
X-Cached
X-D2id
X-Client-IP
X-Abt-Application-Version
X-Cache-TTL
X-Cnection
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-Px
RTSS
X-Navigation-Version
X-Country-Code
Arr-Disable-Session-Affinity
X-Cdn-Fetch
X-Use-Magma
X-Kinja-Revision
X-Kinja-Server
X-Kinja-Build
X-Kinja
X-GoogleNews-Bot
X-Exp-Id
X-Exp-Variant
X-Powered-By-Plesk
Access-Control-Request-Method
X-NF-Request-ID
X-Goog-Hash
Accept-Ch
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-Instrumentation
X-Origin-Cache
AR-Request-ID
AR-PoweredBy
X-Powered-CMS
AR-CACHE
AR-SID
AR-ATIME
Pagespeed
Display
X-Version
X-Middleton-Display
X-Sol
Response
X-Middleton-Response
X-Amz-Server-Side-Encryption
X-LLID
X-MSEdge-Ref
X-Kinsta-Cache
X-Edge-Location-Klb
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Edge
Nginx-Cache
X-TTL
X-RateLimit-Remaining
MRF-Tech
TCN
Mrf-Cache-Status
X-B3-TraceId-Primal
X-Protected-By
X-T
X-Jurisdiction
X-HP-Trace-Id
X-HP-Webp
X-Forwarded-For
X-Shield-Request-Id
X-Content-Security-Policy-Report-Only
X-Id
X-Mg-S
S
Content-MD5
Edge-Cache-Tag
X-Aspnetmvc-Version
Fastcgi-Cache
SPRequestDuration
SPIisLatency
X-CST
X-Mid
X-Language
Front-End-Https
X-Ruxit-Js-Agent
Realpath
X-Request-Received
X-Request-Processing-Time
X-Recruiting
X-DynaTrace
X-Ttl
Filters
Server-Node
Pinterest-Version
Pinterest-Generated-By
X-Pinterest-Rid
X-MCACHE
X-Frontend
Server-Name
X-Ab
X-Ua-Browser
X-Content
X-Correlation-Id
X-Ser
X-HS-Cache-Config
X-HS-Content-Id
X-HS-Hub-Id
X-NWS-LOG-UUID
X-Yandex-Sdch-Disable
X-HS-Combine-CSS
X-Ezoic-Cdn
SPRequestGuid
X-SharePointHealthScore
X-Cache-Key
X-Template
X-Hits
X-ECACHE
X-Parallel-Accel
Alternate-Protocol
X-Tt-Trace-Host
X-Tt-Trace-Tag
Cache-Tags
MicrosoftSharePointTeamServices
Fusion-Content-Id
Fusion-Component-Id
X-Page-Id
Fusion-Deployment-Id
Fusion-Content-Source
Fusion-Source
Fusion-Template-Id
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-B3-Sampled
Cleartype
Host
Charset
X-Git-Hash
X-Content-Options
X-Www-Served-By
X-Server-ID
X-Geo-Country
X-Debug-Info
X-Daa-Tunnel
X-DIS-Request-ID
X-Fastly-Request-Id
X-Amzn-Trace-Id
X-Ratelimit-Limit
X-Hostname
X-Content-Digest
X-Amz-Replication-Status
X-Varnish-Age
Filterid
X-Activity-Id
X-AppVersion
X-Az
X-VCache
Cross-Origin-Opener-Policy
X-Accel-Expires
X-Upgrade-Enabled
X-FB-Debug
X-Forwarded-Proto
X-WebKit-CSP-Report-Only
X-Grace
X-Rid
X-F-Cache
X-Origin-Server
ServerID
Access-Control-Allow-Method
X-Nginx-Upstream-Cache-Status
X-N
TP-Cache
TP-L2-Cache
X-Mobile-URL
X-Route-Name
X-Flags
X-Request-Guid
X-LB-Cache
X-Is-Crawler
X-Aspnet-Duration-Ms
X-Providence-Cookie
X-XRDS-LOCATION
X-TT
X-Varnish-Grace
X-Whom
X-Seen-By
X-Type
Viewport
X-App-Environment
X-Goog-Generation
X-Tb
X-Goog-Metageneration
X-GUploader-UploadID
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-FW-Hash
X-FW-Serve
X-FW-Dynamic
X-Distributor
X-FW-Type
Payment
X-FW-Static
X-FW-Server
DC
Paypal-Debug-Id
Node
X-User-Agent
X-App-Server
X-DataDome
Fastcgi-Useragent
X-Wix-Request-Id
Accept-Charset
Country
X-Cache-Control
X-Oneagent-Js-Injection
X-NGENIX-Cache
X-Cache-Rule
X-Origin-Upstream-Status
X-Litespeed-Cache
X-Fastcgi-Cache
Version
X-Ratelimit-Reset
X-Via-JSL
X-Request-Handler-Origin-Region
X-Microsite
X-Logged-In
X-Tec-Api-Version
X-Drupal-Cache-Tags
X-Tec-Api-Root
X-Tec-Api-Origin
Referer-Policy
X-Fastly-Request-ID
X-Cluster-Name
X-Webkit-Csp
X-Cache-Age
X-B-Cache
X-Webkit-CSP
X-Signature
X-Erf-Bev-Bev-Is-Generated
X-Browser-Type
Cache-Status
X-Erf-Bev-Bev
X-Contextid
Refresh
X-Load-Cache
X-Varnish-Backend
X-Buckets
X-Node-Name
SD-X-WS
X-Original-Request-Id
X-Response-Served-From
Amp-Access-Control-Allow-Source-Origin
X-Vgn-Hpd-Reason
X-Is-Bot
X-Real-IP
X-Page-View
X-Cache-Expired-At
X-Mobile
X-Rendered-As
Access-Control-Request-Headers
VIX-Pulpo-Upstream-Status
X-Cacheable-TTL
VIX-Pulpo-Node
X-Jobs
X-ProcessESI
X-Yottaa-Metrics
X-Proxy
X-RemovedCookies
X-UUID
X-Rule
X-Yottaa-Optimizations
X-Proxy-Cache-Status
X-Instance
X-Debug
X-IPLB-Instance
Surrogate-Key
X-B
X-Cache-Action
NGB
X-Drupal-Cache-Contexts
X-Revision
Akamai-GRN
X-Framework
X-Device-Type
X-Cache-Time
X-Debug-IsConnected
X-Debug-IsPreview
X-FW-Version
CF-IPCountry
X-G
X-Air-Hostname
X-Air-Source
X-Air-Trace-Id
DynaTrace
X-Azure-Ref
X-Oracle-Dms-Ecid
X-Oracle-Dms-Rid
SID
X-XRDS-Location
X-Presslabs-Stats
X-Accel-Buffering
X-Nginx-Cache
GEO-INFO
Liferay-Portal
X-PressLabs-Stats
X-Source
X-Ms-Request-Id
X-Ms-Version
X-TEC-API-ROOT
X-TEC-API-VERSION
Count-Hit
Uber-Trace-Id
X-TEC-API-ORIGIN
X-Cache-Operation
Frame-Options
X-APP-VERSION
X-Cache-NGX
Healthy
X-RTag
X-CDN-Forward
MS-CV
Ms-Operation-Id
X-Zen-Fury
X-EdgeConnect-Cache-Status
X-Cache-Hit
Countrycode
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Mode
X-Tumblr-User
X-Tumblr-Pixel-1
X-Varnish-Server
X-Backend-Name
Protected
Xserver
Cross-Origin-Window-Policy
X-Environment-Context
Ec-Rule-Version
X-L-Path
X-IPS-LoggedIn
X-Cache-TTL-Remaining
X-Region
X-Servername
X-Forwarded-Host
Meta-Geo
X-Detected-As
X-UPSTREAM-Address
X-Hyper-Cache
X-JoinUs
Backend
X-SaId
X-RateLimit-Limit
X-Rewrite-Enabled
X-RN-RSRV
X-ShopId
X-ShardId
LB
X-Content-Age
X-Sql-Count
X-Shopify-Stage
Section-Io-Cache
X-Zipkin-Id
X-Alternate-Cache-Key
X-Content-Powered-By
Decoy-Debug-TTL
X-Uri
X-Tid
X-Cache-Server
X-Cache-Grace
Decoy-Debug-Status
X-Generation-Time
X-Extlb
Apigw-Requestid
X-Sql-Duration-Ms
X-Proxied
X-Adobe-Loc
Decoy-Debug-Key
Country-Code
X-Adobe-Content
X-Sorting-Hat-ShopId
X-Hosted-By
Eomportal-Instance
X-Redis-Cache
X-Routing-Service
X-Sorting-Hat-PodId
X-Ratelimit-Remaining
Url
X-Varnish-Beresp-Grace
X-PERF
X-Site-Version
X-Human
X-Origin-Date
X-NCache
X-Status
Mn-Server-Ip
X-PHP-Backend
X-FB-TRIP-ID
Fastly-SSL
X-No-Session
X-Format
Cache-Name
X-ApacheServer
TWC-Privacy
Selected-Fe
TWC-GeoIP-LatLong
TWC-Device-Class
Property-Id
TWC-Connection-Speed
X-Timing-Wait
X-Storage
TWC-GeoIP-Country
TWC-Locale-Group
X-Cache-Host
X-Server-W
X-ServerID
X-Cache-Type
Webcakes-App-Name
X-Cluster-Node
X-Proxy-Build
X-Pubstack
X-NewRelic-App-Data
X-Microcachable
X-Section
Webcakes-Region
X-UA-Device-Type
Webcakes-App-Version
X-Origin-Hint
X-NYM-Debug-Backend
X-Access
X-Via-Fastly
X-R9-Blue-Green-Version
X-Hl-Ver
X-SayCDN-TTL
Cache-Tv-Group
X-ProxyCache-Key
X-PCL
X-Web-Node
X-Varnishpool
X-Akamai-Edgescape
X-BYPASS-REASON
X-OCL
X-Say-TTL
X-Debug-Cache
X-Say-Cacheable
X-ProxyCache-Status
CDN-EdgeStorageId
Content-Disposition
X-Be
Azure-InstanceId
CDN-Cache
X-Soup
Content-Secure-Policy
X-Azure-Ref-OriginShield
X-TIME
Azure-RegionName
CDN-CachedAt
CDN-RequestId
CDN-PullZone
X-Generated-By
Azure-Version
CDN-Uid
CDN-RequestCountryCode
Azure-SlotName
Azure-SiteName
X-Trace-Id
DB-Nickname
X-Ua
X-LSADC-Cache
WPO-Cache-Message
WPO-Cache-Status
OT-Force-Account-Verify
X-Nginx-Cache-Key
X-Dc
Retry-After
X-Cached-By
SRV
Source
X-Bc-Bl
Cache
X-Unique-Id
X-TT-LOGID
X-LAGOON
X-Platform-Server
X-Auto-Login
X-SRV
X-Cache-Remote
X-Akamai-Transformed
Cache-Hits
X-Varnish-Hits
X-Xfnlog-Site
X-Origin-CC
X-HTML-Minification-Powered-By
X-ECache
X-GEO
X-TNCMS
ServedBy
X-Varnish-Hostname
X-Cache-Tags
X-Origin-TTL
X-Loop
X-Cdn
Onion-Location
X-App-Version
Upgrade-Insecure-Requests
X-Varnish-Cache-Hits
Mime-Version
HostName
Xet-Cookie
X-Amz-Meta-S3cmd-Attrs
From-Origin
X-Request-Time
X-S-Maxage
X-Tumblr-Pixel-2
X-Tumblr-Pixel-3
X-AOL-HN
Web-Mar-Node
X-CSRF-Token
Webserver
WP-Super-Cache
X-EC-Lua
X-Time
X-Request-Host
X-Proto
N-Cache
X-Tenant
X-NWS-UUID-VERIFY
X-VWS-Id
X-Cache-Enabled
X-FireWall-Port
X-AWS-Id
X-LJ-Flow-ID
X-Endurance-Cache-Level
X-GG-Cache-Date
X-Handled-By
X-Edge-Location
X-B3-SpanId
X-Origin-Response-Time
X-Cache-Var-Map
X-Cache-Var
X-A
X-Developer
X-Gen-Mode
X-Ftr-Request-Id
X-Forwarded-Path
DCR-Decision-By
X-External-Request-Id
X-Hnp-Log
Redirect-Candidate
X-NAPM-TraceId
X-ND-Cache
Rendered-Blocks
Nel
X-Destination
X-Ig-Push-State
Sslversion
X-CF-Lambda-Fn
X-Aicache-OS
X-Application
X-ARC
X-B-Cookie
X-Aed
X-A-Ccd
X-A-Dcw
X-A-Dgt
X-A-Wwc
X-Block-Status
X-Cache-NE
X-Connection-Hash
X-D
X-Correlation-ID
X-Conf
User-Cache-Control
V-Age
X-A-Dam
X-CF-Lambda-Version
Surrogated-Key
X-PBS-Appsvrname
X-SRCache-Key
Meta-Geo-Continent
X-Time-Microsecs
X-Slack-Backend
X-Shop-Environment
Expiry
BehaviorPad-Version
X-Session-Fingerprint
Fastcgi-X-Cache-Version
X-TIM-N
Xc-Version
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
X-VG-WebCache
X-Vdms-Version
X-V-Cache
X-Vdms-Path
X-ScT
X-SD-PageType
Pramga
X-Orig-Expires
X-Processor
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-PAYTM-SRV-ID
X-Planisys-CDN-Cache
X-Mg-Request-UUID
X-Via-NSCOPI
X-S
X-S-Cookie
Mobile-Detection-Method
Odigeo-Trace-Id
DCR-Processing-Time-Ms
A
X-Rojux
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Magnolia-Registration
X-RCS-CacheZone
X-MP-GENERATED-AT
CloudFront-Viewer-Country
X-Adobe-Source
Vix-Hermes-Req-Id
DSUID
Svr
Origin
Wxu-Next-Commit
State
Host-ID
Gh-Request-Id
Fastcgi-Cache-TTL
X-Geo-Header
X-Scheme
X-Server-IP
X-Request-URI
X-Policy
X-Origin-Expires
X-Origin-Time
X-Sucuri-Cache
X-Sucuri-ID
X-Backend-TTL
X-Epic-Correlation-Id
X-Webstats-RespID
X-Viewer-Country
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-Nyt-Route
X-Mvc-Supplant-Cachable
X-Cdn-Srv
X-Ckpd-Fst-Backend
X-Cache-Date
X-Cache-Bucket
Wxu-Next-Region
X-Accel-Expires-Debug
X-Cluster
X-Date
X-Location
X-Men
X-Hash
X-Gdpr
X-Fastly-Cache
Wxu-Next-Hostname
X-Forwarded-Site
CDCHOST
CacheControlHeader
X-Reqid
AKAMAI
Arc-Country
X-PHP-Host
X-Labrador-Cache-Channel
X-Level-Front-Cache
X-HN
X-HS-Content-Campaign-Id
Web-Mar-Region
We-Hiring
X-Li-Fabric
X-Irp-Debug
True-Client-Country-4JS
X-VG-TLSProxy
X-Old-Content-Length
Server-Info
Ssr
AMP-Access-Control-Allow-Source-Origin
X-Locale
X-LI-UUID
X-Cache-Info
Traceparent
X-Li-Pop
X-Generated-On
X-Core-Value
X-Csrf-Jwt
X-TrackingId
X-Backend-State
X-Core-Mission
X-Cache-Debug
X-CGP
X-Cdn-Origin
Fastly-Drupal-Html
X-Rocket-Nginx-Serving-Static
X-Developers
X-Device-Os
X-GeoIP-Country-Code
X-Gamma-Serve
Apple-News-Services-Request-Url
X-GeoIP
X-Fetched-On
X-GeoIP-Region-Code
X-Envoy-Decorator-Operation
X-Eu-Site
X-Fastly-Backend
X-GeoIP-City
X-NodeID
L
X-Region-Sid
Cmstype
HA-Ipaddr
L5d-Success-Class
Apple-News-Services-Parsed-Url
X-RateLimit-Remaining-Second
Mail-Subject
Machine
Ha-Gx-Prefs
X-Request-Start
X-Varnish-Beresp-Status
Cmsid
X-UnsetCookies
X-TH-Server
X-Storefront-Renderer-Rendered
X-Sn-Servicetimems
X-VarnishDD-TTL
X-Served-From
X-Skip-Cache
X-RateLimit-Limit-Second
Locid
Apple-News-Services-Handled
Release
X-VServer
Origin-CC
PFcat
Origin-EX
Apple-News-Services-Host
X-Platform
X-Proxy-Upstream
Environment
S-Rt
X-Owner
X-Datadog-Trace-Id
X-Rocket-Build-Number
X-Thinkindot-L3
X-Sigma-Backend
Req-Svc-Chain
X-Origin
X-NU-AKA-ACS-Version
X-Worker
X-Node-Id
X-Sigma
Fastly-GeoIP-CountryCode
X-Datadog-Sampling-Priority
X-Esi-Check
X-Gzip
X-Is-Gdpr
X-JWT-State
X-Has-Esi
X-Rebelmouse-Cache-Control
X-Qloud-Router
X-BBC-Edge-Cache-Status
X-Pod-Name
X-M-Reqid
X-M-Log
X-Response-By
X-Req
X-FC-Vary-Parameters
X-Rebelmouse-Surrogate-Control
X-Qnm-Cache
X-VC-Cache
X-Datadog-Parent-Id
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
X-Amzn-Remapped-Content-Length
X-ATG-Version
TDXMobile
Server-Host
Cf-Device-Type
Fastly-SIE
Fastly-SWR
Memcached
X-Branch-Name
Thinkindot-Control
X-Cache-Id
X-Xrds-Location
NM-Fastcgi-Cache
X-Zone
Platform
X-Mvc-Supplant-OutputCached
NGX
Adler-Geo
Is-Eu
X-Variation
X-Thanos
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
Magicmarker
X-Tx-Id
X-DPWN-IS-SECURE
X-DefElseHash
X-DefHash
X-Loc
X-Bip
X-Akamai-Request-ID2
X-Http-Reason
X-Varnish-Beresp-Ttl
X-Ua-Device
X-CS
X-CLOUD-TRACE-CONTEXT
X-TraceId
X-Restarts
X-API-Version
X-NC
X-Up
Pics-Label
Kp-EeAlive
X-LB-ID
X-Cache-Config
X-Generated-In
Time
X-Action
X-DB
Memory
CDN
Ms-Author-Via
X-Wix-Viewer-Type
X-Trace-ID
X-LB-NoCache
Edge-Cache
X-RPM
X-RSL
X-CACHE-KEY
X-Cache-Backend
X-DW
X-DI
X-DSS
X-RPS
X-Tb-Optimization-Total-Bytes-Saved
X-Tt-Logid
X-Edge-Pop
Env
X-Refresh
Accept-Language
X-CacheTTL
X-Via-Popv
Datacenter
NtCoent-Length
X-Varnish-Ttl
Candidate-Md5Url
GeoIp-Country-Code
X-Via-Poph
WebServer
X-Via-Popn
X-Optimistic-Header
X-Datadome
X-Vc
X-Minions-Version
X-Srv
X-DynaTrace-JS-Agent
WWW-Authenticate
X-DC
X-HA-Backend
On-Server
X-Urbn-Site-Id
X-Urbn-Context-Path
Locale
X-ZONE
X-MSEdge-Flight
X-Cs
X-Varnish-Beresp-TTL
X-Esi
X-Servedbyhost
X-MSEdge-Features
Esi-Enabled
X-Parent-Response-Time
X-Unique-ID
Server-ID
X-Ec-GeoHdr
X-TX-ID
X-Ec-Fail
X-User
X-Service
C-Via
X-TA-CDN-Provider
X-Newrelic-Synthetics
X-Cache-PHP
X-Cache-Ttl
X-VCL-Version
Cdnsip
X-Li-Proto
X-App
X-FPC
Cdncip
X-B3-Spanid
X-AK-Request-ID
X-URL
X-Dynatrace
Test
Geoip-Latitude
My-App
X-Fpc
X-Clara-WADP
X-Fmm-Version
X-WADP-Cache
Cluster
X-LI-Proto
X-Render-Time
X-Webkit-Csp-Report-Only
X-Cache-Status-Check
X-LiteSpeed-Cache-Control
X-Traceid
X-Var-Ttl
Tracecode
Geo-Info
X-Vcl-Version
X-CUA
X-NODE
X-Webkit-CSP-Report-Only
X-Pass-Why
Proxy-Connection
DataCenter
Cf-Int-Pingora-Origin-Digest
Server-Id
T-Server
Lfy
X-From
X-Mcache
Fastly-Drupal-HTML
Resin-Trace
X-Fragments
M-TraceId
Lang
X-CSRF-TOKEN
X-LiteSpeed-Tag
Target-Params
X-Ha-Backend
X-Clientip
X-AIR-PT
X-Info
Hostname
X-ID
X-VC
UCS
Cache-Host
X-Oss-Storage-Class
X-Oss-Server-Time
X-Geo
X-ServedByHost
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
X-Oss-Request-Id
HIT
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
MIME-Version
X-Via-PopV
S-Cnection
GeoIP-Country-Code
X-RAMCache
X-Via-PopN
Hit
X-Pad
X-Via-PopH
X-Provided-By
X-Dynatrace-Js-Agent
X-Proxy-Cache-Info
ENV
X-Httpd
X-Edge-POP
Tcn
Ohc-File-Size
Section-Origin-Responded
Section-Io-Origin-Time-Seconds
Section-Io-Id
Section-Io-Origin-Status
X-Cdn-Forward
X-NGINX-Cache
User-Agent
X-Api-Version
WZWS-RAY
Fastly-Backend-Name
X-Edge-Cache
X-Micro-Cache
X-HS-Status
Load-Balancing
Servername
X-ElasticPress-Query
Permissions-Policy
X-Check-Cacheable
X-BBC-Origin-Response-Status
X-UP
FSS-Cache
Producers
X-Ucs
X-Fastly-Backend-Reqs
X-ServerName
X-SB
X-Cache-CFC
X-Backend-Host
X-Release
X-HostName
X-Pool
Uri
X-Udemy-Cache-App-Namespace
PICS-Label
X-GoCache-CacheStatus
X-APP
X-Platform-Router
X-Platform-Processor
X-Platform-Cluster
X-Lb-Nocache
ServerName
Wpo-Cache-Message
X-Acquia-Application-Trace
X-BCube-Filmed-By
X-Acquia-Application-UUID
Wpo-Cache-Status
X-Acquia-Purge-Tags
URI
X-Acquia-Site
X-TRACE-ID
EpKe-Alive
Ohc-Cache-HIT
Server-Ttl
Cdn
X-Ec-Custom-Error
X-Swift-Error
X-Nc
X-Fastly-Cache-Hits
Cteonnt-Length
Cneonction
X-Cdn-Request-ID
X-RateLimit-Reset
X-Lb-Id
Sid
X-Dw-Trace-Id
X-Vcache
Path
X-Scale
IsBot
X-Akamai-ERPolicy
X-Newrelic-App-Data
X-Amz-Meta-Cb-Modifiedtime
X-Apw-Access-Action
X-Yottaa-OS
Shield-Pop
X-Cache-ASPX
X-Litespeed-Cache-Control
X-Apw-Hits
X-Contensis-Viewer-Groups
X-Apw-Access-Object
X-Apw-Access-Token
X-Akamai-ERRuleID
VNS-Cache
CPC-Age
CPC-Cache
X-Cache-Expires
X-WA-Info
X-B3-Parentspanid
X-Dispatcher-Number
X-IN-APIGATEWAY
X-SIPLIST1
X-IN-APIGATEWAYSSL
Cache-Key
X-Snapshot-Date
VNS-Age
X-WA
MD5-Digest
Vha6-Origin
Server-Hostname
CF-Cached-On
Sever-Int
Cf-Ipcountry
X-B3-ParentSpanId
Server-Ext
X-Air-Pt
X-Cache-Ngx
Lb
X-Varnish-Authentication
X-Shopify-Generated-Cart-Token
X-Logging-Id
X-Sentry-ID
Ngx
X-Akamai-Pragma-Client-IP
X-Wikidot-Backend
Req-ID
CountryCode
X-Wikidot-Static-Cache
X-UA
X-CacheKey
X-Te-Duration-Ms
X-Last-Modified
X-Te-Count
X-Http-Duration-Ms
X-ES-SERVER
X-Http-Count
X-Akamai-Request-ID