Threat Level: green Handler on Duty: Daniel Wesemann

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
Pragma
X-Powered-By
X-XSS-Protection
CF-RAY
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
P3P
X-Cache-Hits
X-UA-Compatible
Alt-Svc
X-Xss-Protection
X-Served-By
CF-Ray
X-Download-Options
X-Timer
X-Request-Id
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
Access-Control-Allow-Credentials
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
X-Drupal-Cache
X-Generator
X-Cache-Status
X-Check
X-Cacheable
X-Envoy-Upstream-Service-Time
X-DNS-Prefetch-Control
X-Request-ID
Timing-Allow-Origin
X-FRAME-OPTIONS
X-Iinfo
X-Dns-Prefetch-Control
X-Drupal-Dynamic-Cache
Feature-Policy
X-Content-Security-Policy
Content-Encoding
Access-Control-Expose-Headers
Upgrade
Status
X-CDN
X-AspNetMvc-Version
Server-Timing
X-XSS-PROTECTION
Access-Control-Max-Age
X-Amz-Request-Id
Request-Context
X-Amz-Id-2
X-Turbo-Charged-By
X-AH-Environment
X-Via
X-Robots-Tag
X-Backend
X-Cache-Group
Cf-Edge-Cache
Host-Header
Keep-Alive
X-Proxy-Cache
X-Hacker
X-Server
X-Rq
X-UA-Device
X-Age
X-Server-Powered-By
X-Vhost
Allow
X-Varnish-Cache
X-Ws-Request-Id
EagleId
X-Dispatcher
X-Amz-Version-Id
Grace
Cf-Apo-Via
P3p
X-LiteSpeed-Cache
Nel
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Page-Speed
X-Device
Cf-Railgun
EagleEye-TraceId
X-Swift-CacheTime
X-Swift-SaveTime
X-Aws-Lambda-Call-Status
Ali-Swift-Global-Savetime
Accept-CH
X-WebKit-CSP
X-Pingback
X-Node
X-Host
X-Server-Id
Surrogate-Control
X-OneAgent-JS-Injection
X-Backend-Server
X-CST
X-Readtime
X-Nginx-Cache-Status
X-Akam-SW-Version
X-Content-Security-Policy-Report-Only
Permissions-Policy
Request-Id
X-Cache-Lookup
X-Application-Context
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Nginx-Upstream-Cache-Status
X-Cloud-Trace-Context
X-Trace
X-Response-Time
X-Edge
Accept-Ch-Lifetime
X-HW
Accept-CH-Lifetime
X-Litespeed-Cache
X-Ua-Compatible
X-Mod-Pagespeed
Content-Location
X-Url
X-Clacks-Overhead
X-Oneagent-Js-Injection
X-Midtier
X-ECACHE
X-Ruxit-JS-Agent
X-ESI
Rating
X-Amz-Server-Side-Encryption
X-Country
X-Mcache
X-Upstream
X-Vname
X-TtlSet
X-PC
Xkey
X-Vcap-Request-Id
X-MS-InvokeApp
Cache-Tag
X-D2id
X-Rack-Cache
Verso
X-Element-Page-Cache
Fastly-Restarts
X-Cache-TTL
X-Use-Magma
X-Kinja-Build
X-Kinja
X-GoogleNews-Bot
X-Exp-Variant
X-Exp-Id
X-Kinja-Revision
X-Kinja-Server
X-Cdn-Fetch
Edge-Control
RTSS
X-Content-Type
X-Powered-By-Plesk
X-Ruxit-Js-Agent
X-VARITI-CCR
Origin-Trial
X-Ac
X-Navigation-Version
X-Cached
X-Abt-Application-Version
X-WebKit-CSP-Report-Only
X-Goog-Hash
Accept-Ch
Service-Worker-Allowed
X-GitHub-Request-Id
X-Ttl
X-Country-Code
X-Amz-Rid
Display
X-Sol
X-Middleton-Display
Pagespeed
X-Mg-S
X-Dw-Request-Base-Id
X-SharePointHealthScore
X-Browser-Type
SPRequestGuid
X-Server-Name
Arr-Disable-Session-Affinity
X-B3-TraceId
Cross-Origin-Opener-Policy
X-Varnish-TTL
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Instrumentation
X-Powered-CMS
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
AR-Request-ID
AR-PoweredBy
AR-SID
Response
X-Middleton-Response
AR-ATIME
X-Amzn-Trace-Id
SPIisLatency
SPRequestDuration
X-Cache-Key
X-Ua-Device
AR-CACHE
X-Fastly-Request-ID
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-ORACLE-DMS-ECID
X-Cnection
X-ORACLE-DMS-RID
X-Version
X-Jurisdiction
X-HP-Trace-Id
X-HP-Webp
X-NF-Request-ID
X-Accel-Expires
X-Fastcgi-Cache
X-T
Front-End-Https
Cache-Tags
X-Times
Cache-Status
Edge-Cache-Tag
X-Ser
X-Px
X-MSEdge-Ref
Pinterest-Generated-By
Pinterest-Version
X-Pinterest-Rid
Public-Key-Pins
X-Client-IP
X-Hits
Nginx-Cache
X-Recruiting
MRF-Tech
Mrf-Cache-Status
X-RateLimit-Remaining
X-B3-TraceId-Primal
X-Shield-Request-Id
X-Request-Processing-Time
X-Frontend
X-Request-Received
Access-Control-Request-Method
Server-Node
X-LLID
X-Ua-Browser
X-NWS-LOG-UUID
X-B3-Traceid
Payment
X-Webkit-CSP
X-DIS-Request-ID
TP-Cache
X-RateLimit-Limit
S
X-HS-Combine-CSS
X-HS-Hub-Id
X-HS-Cache-Config
X-HS-Content-Id
MicrosoftSharePointTeamServices
X-Goog-Metageneration
TP-L2-Cache
X-Content-Digest
X-LB-Cache
X-Webkit-Csp
Content-MD5
X-Distributor
X-Erf-Stays-Pdp-Viaduct-Migration-Web
Realpath
X-Kinja-CCPA
X-Hostname
X-Microsite
X-Request-Handler-Origin-Region
X-Geo-Country
X-Ezoic-Cdn
X-Forwarded-For
X-Page-Id
Access-Control-Allow-Method
X-FastCGI-Cache
Accept-Charset
X-FB-Debug
Fastcgi-Cache
X-Envoy-Decorator-Operation
X-PressLabs-Stats
X-GUploader-UploadID
X-Webkit-CSP-Report-Only
X-Cluster-Name
X-Rid
X-Correlation-Id
X-Protected-By
TCN
X-Seen-By
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Ratelimit-Remaining
Cleartype
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
X-B3-Sampled
DC
X-Origin-Server
X-Origin-Cache
X-XRDS-Location
X-Debug-Info
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Goog-Generation
X-Newrelic-App-Data
X-Mobile
Referer-Policy
X-Varnish-Backend
X-Git-Hash
X-Ratelimit-Limit
X-Logged-In
X-Kinsta-Cache
X-Edge-Location-Klb
Cross-Origin-Resource-Policy
X-Azure-Ref
Alternate-Protocol
X-Contextid
X-Varnish-Grace
X-TTL
X-Revision
X-App-Environment
Healthy
Surrogate-Key
X-Aspnet-Version
X-Fb-Rlafr
X-Amz-Replication-Status
X-Request-Guid
X-Route-Name
X-Providence-Cookie
X-Is-Crawler
X-Aspnet-Duration-Ms
X-Flags
X-Grace
X-TT
Count-Hit
X-Amz-Meta-S3cmd-Attrs
X-Content-Options
X-Server-ID
X-Forwarded-Proto
X-Wix-Request-Id
X-Whom
X-IPS-LoggedIn
MS-Author-Via
Charset
Filterid
X-Akamai-Edgescape
X-Client-Ip
Viewport
Frame-Options
WPO-Cache-Status
X-App-Server
WPO-Cache-Message
X-Id
X-Hosted-By
Paypal-Debug-Id
X-B
X-Magnolia-Registration
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Backend-Name
X-Trace-Id
X-Www-Served-By
X-Activity-Id
X-Az
X-Daa-Tunnel
X-AppVersion
X-Cache-Control
Retry-After
X-Cache-Age
Section-Io-Cache
Server-Name
X-F-Cache
Refresh
X-Type
Amp-Access-Control-Allow-Source-Origin
X-Varnish-Server
X-Varnish-Ttl
X-Proxy-Cache-Info
X-Upgrade-Enabled
Version
X-Proxy
Akamai-GRN
X-App-Version
SD-X-WS
X-Cache-Rule
VIX-Pulpo-Upstream-Status
X-Response-Served-From
X-Rule
X-Original-Request-Id
X-Http-Reason
X-ARC
VIX-Pulpo-Node
Host
X-User-Agent
X-Edge-Location
X-Status
X-Rocket-Nginx-Serving-Static
X-Varnish-Age
X-UUID
Front
X-Akamai-Request-ID2
X-Instance
Protected
X-Framework
X-Is-Bot
SRV
X-Environment-Context
X-Jobs
X-Cacheable-TTL
X-L-Path
X-Unique-Id
X-EdgeConnect-Cache-Status
X-Cache-Grace
X-Rendered-As
X-Region
From-Origin
Fastly-SWR
Access-Control-Request-Headers
X-Oracle-Dms-Ecid
X-N
Fastly-SIE
X-FW-Hash
X-FW-Serve
X-FW-Server
X-Cache-Time
X-FW-Static
X-FW-Type
X-Source
X-FW-Version
X-Page-View
X-FW-Dynamic
X-Tumblr-Pixel-1
X-Tumblr-User
X-Adobe-Content
X-Time
X-Oracle-Dms-Rid
X-Tumblr-Pixel-0
X-G
X-ProcessESI
X-RemovedCookies
X-Adobe-Loc
X-Tumblr-Pixel
X-Load-Cache
X-COUNTRY
ServerID
Content-Disposition
Country
X-Drupal-Cache-Tags
X-CDN-Forward
X-Language
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
X-Datadog-Trace-Id
X-RateLimit-Reset
X-HTML-Minification-Powered-By
X-Tt-Trace-Host
X-Tt-Trace-Tag
Accept-Language
X-Vcache
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-DynaTrace
X-Datadog-Sampled
Liferay-Portal
X-DataDome
X-Amzn-Remapped-Content-Length
Countrycode
X-Debug-IsPreview
X-DynaTrace-JS-Agent
X-Mg-Request-UUID
X-Debug-IsConnected
X-Generated-By
X-B3-SpanId
X-ID
Xet-Cookie
X-Nf-Request-Id
Backend
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
CF-IPCountry
Xserver
X-ECache
X-Tt-Logid
X-Drupal-Cache-Contexts
Webserver
X-Signature
X-B-Cache
X-NYM-Debug-Backend
X-Mode
X-Device-Type
X-Content-Powered-By
X-Zen-Fury
X-MCACHE
GEO-INFO
X-Httpd
X-Nginx-Cache
X-Content-Age
X-Erf-Web-Scheduler
X-Ratelimit-Reset
X-Servername
Url
X-JoinUs
X-Git-Commit
Locale
X-Director
X-Rewrite-Enabled
X-Sucuri-Cache
Load-Balancing
X-Container-Uri
S-Rt
X-ServerID
X-Sucuri-ID
Azure-RegionName
X-SaId
Azure-SiteName
Onion-Location
Azure-InstanceId
Azure-SlotName
Filters
Meta-Geo
X-LAGOON
Azure-Version
X-Cache-Operation
X-UPSTREAM-Address
X-Urbn-Context-Path
X-Varnish-Cache-Hits
X-Urbn-Site-Id
X-Cache-Action
X-Tb
X-Proto
X-Soup
Uber-Trace-Id
X-SayCDN-TTL
X-Say-TTL
X-Cluster-Node
X-Storage
X-Varnish-Hostname
X-Say-Cacheable
X-Ms-Request-Id
X-VC-Cache
X-PHP-Host
X-Ms-Version
X-Forwarded-Host
X-Generation-Time
X-RM-Cache-TTL
X-Labrador-Cache-Channel
X-XRDS-LOCATION
X-Xrds-Location
X-Logging-Id
X-Detected-As
X-VCT
X-Served-From
Web-Mar-Node
X-Sql-Count
DB-Nickname
X-Skip-Cache
TWC-Privacy
X-Sql-Duration-Ms
Fastcgi-Useragent
X-Extlb
X-GeoCountry
Webcakes-Region
Webcakes-App-Version
X-GeoCode
Property-Id
Webcakes-App-Name
X-Origin-Hint
X-Proxied
X-Routing-Service
Mn-Server-Ip
Node
X-Adobe-Source
TWC-Locale-Group
TWC-GeoIP-LatLong
X-Cache-Server
TWC-GeoIP-Country
X-RCS-CacheZone
TWC-Device-Class
X-Zipkin-Id
TWC-Connection-Speed
X-Format
X-Fetched-On
X-R9-Blue-Green-Version
X-Timing-Wait
X-LSADC-Cache
Selected-Fe
X-FB-TRIP-ID
X-Debug
X-Tumblr-Pixel-2
X-Proxy-Build
X-Uri
X-Tumblr-Pixel-3
CDN-RequestId
X-Tec-Api-Version
X-Tec-Api-Root
X-Tec-Api-Origin
Fastly-Drupal-HTML
X-MP-GENERATED-AT
X-Lambda-Id
X-Origin-Date
X-Cache-Expired-At
Source
X-NGENIX-Cache
X-Via-JSL
OT-Force-Account-Verify
X-Cache-Hit
X-Template
X-Varnish-Hits
Content-Secure-Policy
X-Node-Name
X-Loop
X-Cache-TTL-Remaining
X-AIR-PT
X-UA-Device-Type
X-Pass-Why
X-Tncms
X-Endurance-Cache-Level
X-Ua
X-Pubstack
Upgrade-Insecure-Requests
X-Srv
X-Redis-Cache
Cross-Origin-Window-Policy
NGB
X-Server-W
X-PHP-Backend
X-Real-IP
X-Origin-TTL
X-Origin-CC
X-Fastly-Request-Id
Cache-Hits
X-Hcs-Proxy-Type
X-CCDN-CacheTTL
X-CCDN-Origin-Time
Ms-Operation-Id
X-Cache-Host
MS-CV
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
Section-Io-Id
X-RTag
Section-Io-Origin-Status
Cache-Name
X-GEO
X-Xfnlog-Site
X-Restarts
X-Optimistic-Header
X-Reqid
X-S
X-Cms-Context
Apigw-Requestid
X-IPLB-Instance
X-IPLB-Request-ID
Cache-Provider
CDN-RequestPullSuccess
CDN-RequestCountryCode
X-Cache-Type
CDN-PullZone
CDN-CachedAt
CDN-RequestPullCode
CDN-Uid
CDN-Cache
X-CACHE-AGE
CDN-EdgeStorageId
X-Hl-Ver
X-No-Session
X-ProxyCache-Key
X-ProxyCache-Status
X-BYPASS-REASON
X-Datadome
X-CSRF-Token
X-Via-Fastly
X-AWS-Id
X-Aspnetmvc-Version
X-LJ-Flow-ID
X-Presslabs-Stats
X-VWS-Id
X-Cluster
X-Access
X-Section
X-Rn-Rsrv
DCR-Processing-Time-Ms
X-Application
X-Irp-Debug
Fastly-GeoIP-CountryCode
Gh-Request-Id
Server-Host
Gannett-Cam-Experience-Id
Fastly-Backend-Name
X-GeoIP-Region-Code
X-B-Cookie
X-Gdpr
X-GeoIP-Country-Code
X-Mvc-Supplant-Cachable
X-Forwarded-Path
X-Ec-GeoHdr
X-Bc-Bl
X-CGP
BehaviorPad-Version
CPC-Age
X-Conf
X-Csrf-Jwt
CPC-Cache
X-CF-Lambda-Version
X-BCube-Filmed-By
Canary
Candidate-Md5Url
X-Cache-NE
X-CacheTTL
X-CF-Lambda-Fn
X-Cdn-Diag
X-D
X-Date
DCR-Decision-By
X-Epic-Correlation-Id
X-Cache-Info
X-Eu-Site
X-Cache-Bucket
X-Fastly-Backend
X-External-Request-Id
X-Ec-Fail
Ha-Gx-Prefs
X-Debug-Cache-Store
X-Debug-Cache-Fetch
X-Destination
X-Developer
X-Ec-Custom-Error
X-Dispatcher-Number
X-FC-Vary-Parameters
X-Newrelic-Synthetics
X-TIM-N
VNS-Cache
W
Odigeo-Trace-Id
X-Var-Ttl
X-Vdms-Path
VNS-Age
Ngx.Var.Host
X-Tenant
X-Nyt-Route
X-A
X-SRCache-Key
Web-Mar-Region
We-Hiring
N-Cache
X-Proxy-Cache-Status
X-Vdms-Version
Redirect-Candidate
Xc-Version
T-Server
Rendered-Blocks
Sslversion
Surrogated-Key
X-Wikidot-Static-Cache
X-Wikidot-Backend
X-VG-WebCache
Vix-Hermes-Req-Id
X-Viewer-Country
X-Akamai-Transformed
X-We-Are-Hiring
X-Vtex-Remote-Cache
X-Slack-Shared-Secret-Outcome
Meta-Geo-Continent
X-Policy
X-Aed
X-Slack-Backend
X-A-Dgt
X-RateLimit-Limit-Second
X-Orig-Expires
X-Accel-Expires-Debug
X-A-Wwc
X-Origin-Time
L
L5d-Success-Class
Lang
X-RateLimit-Remaining-Second
HA-Ipaddr
Magicmarker
X-SD-PageType
Mail-Subject
X-Shop-Environment
X-A-Ccd
MD5-Digest
X-ScT
X-A-Dam
X-Bl-Debug
X-Request-Host
X-A-Dcw
X-Rojux
X-S-Cookie
X-Bip
TDXMobile
X-BBC-Edge-Cache-Status
X-App-Name
X-Auto-Login
X-ApacheServer
X-Alternate-Cache-Key
Thinkindot-CacheControl-Type
Thinkindot-Control
Thinkindot-CacheControl
X-Level-Front-Cache
X-SVT-ORM-RULES
X-Storefront-Renderer-Rendered
X-SVT-ORM-VERSION
X-Test
X-Thanos
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Server-IP
X-S-Maxage
X-ShardId
X-ShopId
X-Shopify-Stage
X-Thinkindot-L3
X-Up
X-Is-Gdpr
X-Has-Esi
X-JWT-State
X-Wix-Viewer-Type
X-Worker
X-Accel-Buffering
True-Client-Country-4JS
X-Varnishpool
X-VG-TLSProxy
X-WADP-Cache
Fastly-SSL
X-Request-Time
X-Pool
X-Generated-On
X-Forwarded-Site
X-Geo-Header
X-Gzip
X-Handled-By
X-Fmm-Version
X-Esi-Check
X-Clara-WADP
X-Cache-Id
X-CMSURLCustom
X-Core-Mission
X-Core-Value
X-Hash
X-Human
X-Owner
X-Origin-Response-Time
X-PAYTM-SRV-ID
X-PERF
X-Platform
X-Org
X-Old-Content-Length
X-INCAP-ABP
X-Mid
X-Mly-Id
X-Node-Id
X-Cache-Debug
X-Clientip
Machine
Memcached
Origin
Release
X-TimeS
Environment
AKAMAI
Cmsid
Cmstype
Datacenter
Req-Svc-Chain
Host-ID
X-TIME
WP-Super-Cache
X-Vcl-Version
X-Web-Node
User-Cache-Control
X-Block-Status
CloudFront-Viewer-Country
X-Origin
X-Mvc-Supplant-OutputCached
X-TA-CDN-Provider
X-Cdn-Origin
Server-Ext
Country-Code
DSUID
X-DPWN-IS-SECURE
X-DefElseHash
X-From
Server-Hostname
X-DefHash
X-Scale
Apple-News-Services-Parsed-Url
Expect-Staple
Apple-News-Services-Host
Apple-News-Services-Handled
X-WA-Info
ServedBy
Apple-News-Services-Request-Url
X-Device-Os
Producers
X-Nginx-Cache-Key
Platform
Is-Eu
X-Cdn-Srv
X-Dispatcher-Server
CDCHOST
X-Gen-Mode
X-Variation
NM-Fastcgi-Cache
X-Parent-Response-Time
Esi-Enabled
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-Hnp-Log
X-VServer
X-Vmg-Version
X-Varnish-Remaining-TTL
X-NodeID
X-Sn-Servicetimems
X-Qloud-Router
Adler-Geo
X-Loc
X-Nananana
Sever-Int
X-Air-Hostname
X-Air-Trace-Id
X-Air-Source
C-Via
X-App
Pics-Label
Ssr
X-GeoIP
Origin-EX
Origin-CC
X-Nitro-Cache
X-NCache
Wxu-Next-Commit
Wxu-Next-Hostname
Wxu-Next-Region
X-LB-NoCache
X-Akamai-Device-Characteristics
X-Azure-Ref-OriginShield
X-Instance-Name
X-Cs
X-Op-Id-All
Server-Info
X-Amz-Meta-Cb-Modifiedtime
Memory
X-Cache-Enabled
X-Refresh
Time
Server-ID
X-Tx-Id
AMP-Access-Control-Allow-Source-Origin
Cache-Host
X-Cache-Status-Check
X-HA-Backend
X-Platform-Cluster
X-Platform-Processor
X-Platform-Router
X-Microcachable
X-Site-Version
X-Locale
X-Correlation-ID
X-Origin-Expires
NGX
XM
Hostname
X-HN
PFcat
GeoIP-Latitude
X-VarnishDD-TTL
X-VHOST
X-Tb-Optimization-Total-Bytes-Saved
X-API-Version
X-Dc
Cf-Device-Type
X-CACHE-GROUP
Origin-Agent-Cluster
Resin-Trace
X-ZONE
X-DC
X-Via-CDN
X-Via-SSL
X-Via-Edge
Srvid
A
X-Varnish-Beresp-Ttl
X-Varnish-Beresp-Grace
Locid
X-FL-EDGE
Edge-Copy-Time
X-FL-QIT-DEBUG
X-Ad-Defer-Variation
X-Zone
X-Wp-Cf-Super-Cache-Active
X-Fpc
YJS-ID
X-Vgn-Hpd-Reason
X-Upstream-Ct
X-Upstream-Ht
Cdn-Requestid
X-Internal-Host
X-ATG-Version
X-FireWall-Port
X-Webkit-Csp-Report-Only
Sid
X-Contensis-Viewer-Groups
X-Micro-Cache
Cache-Key
X-Cache-ASPX
X-WP-CF-Super-Cache-Active
X-Moov-Xdn-Version
Uri
X-Pod-Name
X-Github-Request-Id
X-Varnish-Authentication
X-Cached-By
X-Moov-T
X-DataCenter
X-TraceId
True-Client-Ip
User-Agent
X-NGINX-Cache
X-LiteSpeed-Cache-Control
X-Provided-By
X-Info
X-SIPLIST1
State
IsBot
X-Planisys-CDN-Cache
X-HS-Content-Campaign-Id
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-B3-Spanid
X-AB
X-URL
X-Buckets
Location
GeoIP-Country-Code
X-Fastly-Cache
X-B3-Parentspanid
X-Platform-Server
X-RN-RSRV
X-Release
X-Sigma-Backend
X-VC
X-Cache-Remote
X-VCache
X-Sigma
X-Geo-Region
X-Rocket-Build-Number
X-Nitro-Rev
GeoIp-Country-Code
X-Backend-Instance
X-Nitro-Cache-From
X-LiteSpeed-Tag
SID
X-Api-Version
X-MSEdge-Flight
X-Accel-Version
X-CSRF-TOKEN
X-Datacenter
X-CS
X-MSEdge-Features
Cdn
Cache
XServer
X-FTR-Request-ID
X-Gamma-Serve
CF-Ctrl
X-Generated-In
X-Geo
NtCoent-Length
True-Client-IP
X-NewRelic-App-Data
Srv
X-GeoIP-City
X-Vgn-Hpd-Variations-Key
X-Vgn-Hpd-Cached
X-Vgn-Hpd-Ssi
Lb
Path
Cache-Tv-Group
X-Is-Mobile
X-Browser-Name
X-Is-Desktop
X-Tcp-Rtt
X-Is-Tablet
X-Is-Supported-Browser
X-SRV
X-Scheme
X-Rebelmouse-Surrogate-Control
X-TRACE-ID
X-Rebelmouse-Cache-Control
X-HS-Status
CountryCode
Epwk-X-Cache
X-Hyper-Cache
Kp-EeAlive
HostName
Fastly-Drupal-Html
X-FPC
X-Frame-Option
X-HostName
Tcn
X-Amz-Meta-Opti
X-GoCache-CacheStatus
Ohc-File-Size
X-Location
X-Mobile-URL
X-Service
Serverid
X-APP-VERSION
X-TX-ID
X-UA
Cf-Ipcountry
X-Men
X-AK-Request-ID
On-Server
Cdncip
Cdnsip
X-Webstats-RespID
X-Aicache-OS
X-Air-Pt
CacheControlHeader
X-Region-Sid
X-Esi
X-Developers
X-Guploader-Uploadid
Tube-Got-Results
Tube-Return
V-Age
X-LB-ID
Tube-Got-Eval
X-V-Cache
X-Traceid
X-Via-Popv
X-Via-Popn
X-Via-Poph
X-Branch-Name
Tube-Get-Contents
WebServer
X-CDN-Cache-Status
X-Cache-Ttl
X-Minions-Version
RNT-Time
X-Wp-Cf-Super-Cache
X-Acquia-Purge-Cdn-Unconfigured
X-Cache-Tags
Click-Count-Error
X-B3-Trace-ID
X-EC-Lua
RNT-Machine
Proxy-Connection
X-Wp-Cf-Super-Cache-Cache-Control
Mime-Version
X-Cache-FS-Status
Click-Count-Action-Start
X-SB
X-Req
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-Cdn-Cache-Status
X-Pad
Env
X-Vc
WZWS-RAY
WWW-Authenticate
X-Proxy-CacheRZ
XkeyRZ
ENV
X-Servedbyhost
X-Nc
Yak-Timeinfo
Ohc-Cache-HIT
X-Wa
CDN
X-VCL-Version
X-CACHE-KEY
X-Edge-Server
LB
X-Vercel-Cache
Cdn-Host
Geoip-Latitude
X-Fastly-Country-Code
Cdn-Request-Time
X-Vercel-Id
X-User
X-NWS-UUID-VERIFY
X-Edge-Pop
X-Akamai-Pragma-Client-IP
CF-Cached-On
Ngx
X-Cdn-Forward
X-Check-Cacheable
X-Lb-Cache
M-TraceId
Req-ID
X-Country-Code-Real
Content-Style-Type
X-Ha-Backend
X-Ckpd-Fst-Backend
Server-Id
X-Origin-Cache-Key
X-Processor
Content-Script-Type
X-FTR-Backend-Server
X-FTR-Cache-Status
X-NMSegId
X-FTR-Balancer
X-WP-CF-Super-Cache-Cookies-Bypass
X-FTR-Backend
X-FTR-Expires
X-TH-Server
X-TT-LOGID
X-MiniProfiler-Ids
X-Acquia-Site
PICS-Label
HIT
X-APP
X-Dw-Trace-Id
X-Lb-Nocache
X-Acquia-Purge-Tags
X-Litespeed-Cache-Control
X-Cdn-Request-ID
X-Edge-POP
X-Ad-Load-Variation
X-Render-Time
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
Cluster
X-Acquia-Application-UUID
X-Snapshot-Date
X-Acquia-Application-Trace
X-CUA
X-Via-Ucdn
Yjs-Id
X-Miniprofiler-Ids
X-Request-Start
Cneonction
Log-Origin
X-Response-By
CACHE-MISS-TO-ORIGIN
X-Fastly-Backend-Reqs
Sm-Log-Id
Edge-Cache
X-Service-Response-Time
X-Serial
X-Iauth-Set-Uid
Inserted-Into-Cache-At
X-Fastly-Cache-Hits
X-M-Reqid
X-RAMCache
X-Udemy-Cache-App-Namespace
X-M-Log
X-ElasticPress-Query
Vha6-Origin
X-Cached-Since
X-Cache-Date