Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
Pragma
X-Powered-By
X-XSS-Protection
CF-RAY
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
Alt-Svc
X-Cache-Hits
X-UA-Compatible
P3P
X-Xss-Protection
X-Served-By
CF-Ray
X-Download-Options
X-Timer
X-Request-Id
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
Access-Control-Allow-Credentials
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
X-Drupal-Cache
X-Generator
X-Cache-Status
X-Check
X-Cacheable
X-Envoy-Upstream-Service-Time
X-DNS-Prefetch-Control
X-Request-ID
Timing-Allow-Origin
X-Iinfo
X-FRAME-OPTIONS
X-Dns-Prefetch-Control
X-Drupal-Dynamic-Cache
Feature-Policy
X-Content-Security-Policy
Content-Encoding
Access-Control-Expose-Headers
Upgrade
Status
X-CDN
Server-Timing
X-AspNetMvc-Version
X-XSS-PROTECTION
Access-Control-Max-Age
X-Amz-Request-Id
Request-Context
X-Amz-Id-2
X-Turbo-Charged-By
X-Via
X-AH-Environment
P3p
X-Backend
X-Robots-Tag
X-Cache-Group
Cf-Edge-Cache
Host-Header
Keep-Alive
X-UA-Device
X-Proxy-Cache
X-Hacker
X-Server
X-Rq
X-Server-Powered-By
X-Age
Allow
X-Vhost
X-Varnish-Cache
X-Ws-Request-Id
X-Dispatcher
EagleId
X-Amz-Version-Id
Grace
X-LiteSpeed-Cache
Cf-Apo-Via
Nel
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Page-Speed
Cf-Railgun
X-Device
EagleEye-TraceId
X-Aws-Lambda-Call-Status
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-Pingback
X-WebKit-CSP
X-Host
X-Node
Accept-CH
X-OneAgent-JS-Injection
X-Server-Id
X-Backend-Server
Surrogate-Control
X-CST
X-Readtime
X-Nginx-Cache-Status
X-Cache-Lookup
X-Akam-SW-Version
Permissions-Policy
X-Content-Security-Policy-Report-Only
Request-Id
X-Application-Context
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Nginx-Upstream-Cache-Status
X-Cloud-Trace-Context
X-Trace
X-Response-Time
X-Edge
Accept-Ch-Lifetime
X-HW
Accept-CH-Lifetime
X-Ua-Compatible
Content-Location
X-Clacks-Overhead
X-Mod-Pagespeed
X-Ruxit-JS-Agent
X-Midtier
X-Url
Rating
Xkey
X-ESI
X-Amz-Server-Side-Encryption
X-Mcache
X-ECACHE
X-Country
X-Upstream
X-Litespeed-Cache
X-Oneagent-Js-Injection
X-Vcap-Request-Id
X-Vname
X-TtlSet
X-PC
Cache-Tag
X-D2id
X-MS-InvokeApp
X-Rack-Cache
X-Cdn-Fetch
X-Exp-Variant
X-Kinja-Revision
X-Exp-Id
X-Element-Page-Cache
X-GoogleNews-Bot
X-Use-Magma
X-Kinja-Server
X-Kinja-Build
X-Kinja
Verso
Accept-Ch
Edge-Control
RTSS
X-Ruxit-Js-Agent
X-Powered-By-Plesk
Fastly-Restarts
X-Cache-TTL
X-VARITI-CCR
Origin-Trial
X-Ac
X-Navigation-Version
X-Abt-Application-Version
Service-Worker-Allowed
X-Cached
X-Goog-Hash
X-Country-Code
X-Content-Type
X-Ttl
X-GitHub-Request-Id
Display
Pagespeed
X-Middleton-Display
X-Sol
X-WebKit-CSP-Report-Only
X-Amz-Rid
X-Browser-Type
X-Dw-Request-Base-Id
X-Mg-S
SPRequestGuid
X-SharePointHealthScore
Cross-Origin-Opener-Policy
X-Server-Name
X-Varnish-TTL
X-Erf-Bev-Bev
X-Instrumentation
Arr-Disable-Session-Affinity
X-Erf-Bev-Bev-Is-Generated
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Powered-CMS
X-Amzn-Trace-Id
X-Middleton-Response
Response
AR-SID
AR-ATIME
AR-Request-ID
AR-PoweredBy
SPRequestDuration
SPIisLatency
X-Cache-Key
X-B3-TraceId
AR-CACHE
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Fastly-Request-ID
X-Version
X-HP-Webp
X-HP-Trace-Id
X-Jurisdiction
X-Times
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-Cnection
X-Accel-Expires
Cache-Tags
X-B3-Traceid
X-T
Cache-Status
X-Client-IP
Front-End-Https
Pinterest-Version
Pinterest-Generated-By
X-Pinterest-Rid
X-Webkit-CSP
X-MSEdge-Ref
X-NF-Request-ID
Edge-Cache-Tag
X-Px
Nginx-Cache
X-NWS-LOG-UUID
X-Hits
X-Ser
X-Kinja-CCPA
Public-Key-Pins
X-FastCGI-Cache
X-Recruiting
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
X-Fastcgi-Cache
X-LLID
X-Frontend
X-Request-Processing-Time
X-Request-Received
Payment
Server-Node
X-Ua-Browser
X-Shield-Request-Id
X-Erf-Stays-Pdp-Viaduct-Migration-Web
X-DIS-Request-ID
Access-Control-Request-Method
X-Ratelimit-Remaining
TP-Cache
S
X-Goog-Metageneration
MicrosoftSharePointTeamServices
X-HS-Cache-Config
X-HS-Combine-CSS
X-HS-Content-Id
X-HS-Hub-Id
X-Webkit-CSP-Report-Only
X-RateLimit-Remaining
X-LB-Cache
X-PressLabs-Stats
TP-L2-Cache
X-Content-Digest
Content-MD5
X-Distributor
X-Microsite
X-Request-Handler-Origin-Region
Realpath
X-Forwarded-For
X-Ezoic-Cdn
X-Page-Id
X-FB-Debug
X-Ratelimit-Limit
X-Hostname
Access-Control-Allow-Method
Accept-Charset
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Geo-Country
Fastcgi-Cache
X-Cluster-Name
X-GUploader-UploadID
X-Protected-By
X-Rid
X-Server-ID
X-RateLimit-Limit
X-Seen-By
X-Correlation-Id
X-Envoy-Decorator-Operation
X-B3-Sampled
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
Cleartype
TCN
DC
X-Goog-Storage-Class
Referer-Policy
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Newrelic-App-Data
X-Mobile
Cross-Origin-Resource-Policy
X-Debug-Info
X-Origin-Cache
X-Origin-Server
X-Varnish-Backend
X-Git-Hash
X-Logged-In
X-XRDS-Location
X-Azure-Ref
X-Content-Options
X-Webkit-Csp
X-Contextid
X-Varnish-Grace
X-Aspnet-Version
X-Providence-Cookie
X-Route-Name
X-Request-Guid
X-TTL
X-Revision
X-Fb-Rlafr
Surrogate-Key
X-App-Environment
X-Grace
X-Amz-Replication-Status
X-Aspnet-Duration-Ms
Count-Hit
X-Is-Crawler
X-Flags
X-Edge-Location-Klb
X-Ua-Device
X-IPS-LoggedIn
X-Kinsta-Cache
X-TT
Alternate-Protocol
X-Amz-Meta-S3cmd-Attrs
X-App-Server
X-Hosted-By
Healthy
X-Forwarded-Proto
X-Wix-Request-Id
Frame-Options
X-Whom
WPO-Cache-Status
WPO-Cache-Message
X-Daa-Tunnel
Charset
MS-Author-Via
X-Akamai-Edgescape
Viewport
Retry-After
X-F-Cache
X-Magnolia-Registration
X-Id
Filterid
X-B
Section-Io-Cache
X-Backend-Name
Paypal-Debug-Id
X-Aspnetmvc-Version
Amp-Access-Control-Allow-Source-Origin
SRV
X-Cache-Age
X-Client-Ip
X-AppVersion
X-Az
X-Activity-Id
X-Proxy-Cache-Info
X-Www-Served-By
X-Kong-Proxy-Latency
X-Trace-Id
X-Kong-Upstream-Latency
X-RateLimit-Reset
Server-Name
X-Cache-Control
X-Type
VIX-Pulpo-Node
SD-X-WS
Akamai-GRN
X-Rule
VIX-Pulpo-Upstream-Status
X-Original-Request-Id
X-ARC
X-Http-Reason
X-Instance
X-Cache-Rule
X-Varnish-Server
X-Response-Served-From
Host
X-Proxy
Protected
X-N
X-Status
X-Rocket-Nginx-Serving-Static
Front
X-Akamai-Request-ID2
X-Varnish-Age
X-Edge-Location
X-EdgeConnect-Cache-Status
X-UUID
X-User-Agent
X-Cache-Grace
X-FW-Hash
X-Rendered-As
X-FW-Server
X-FW-Static
X-FW-Serve
X-Unique-Id
X-L-Path
X-App-Version
X-Jobs
X-Is-Bot
X-FW-Version
X-FW-Type
X-FW-Dynamic
X-Framework
From-Origin
X-Cacheable-TTL
X-Page-View
Refresh
Fastly-SWR
X-Environment-Context
Fastly-SIE
X-Region
Access-Control-Request-Headers
X-Time
X-Adobe-Loc
X-Cache-Time
X-Oracle-Dms-Ecid
X-Adobe-Content
X-Tumblr-Pixel
X-ProcessESI
X-RemovedCookies
X-Load-Cache
X-G
X-Tumblr-Pixel-1
X-Tumblr-User
X-Language
X-Tumblr-Pixel-0
X-Oracle-Dms-Rid
Version
X-COUNTRY
ServerID
Country
X-Vcache
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
X-Datadog-Trace-Id
X-ECache
X-Nf-Request-Id
X-CDN-Forward
X-Source
Content-Disposition
X-DataDome
X-Drupal-Cache-Tags
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Varnish-Ttl
X-Datadog-Sampled
X-Mg-Request-UUID
X-Amzn-Remapped-Content-Length
Accept-Language
X-HTML-Minification-Powered-By
X-Upgrade-Enabled
X-Debug-IsPreview
X-Debug-IsConnected
Countrycode
X-DynaTrace
X-Signature
X-B-Cache
Xet-Cookie
X-Tt-Trace-Tag
Backend
X-Generated-By
X-Tt-Trace-Host
CF-IPCountry
Webserver
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
X-DynaTrace-JS-Agent
X-Nginx-Cache
X-Xrds-Location
X-ID
X-Mode
X-Httpd
X-Servername
Liferay-Portal
Url
Xserver
X-Tt-Logid
X-NYM-Debug-Backend
X-Device-Type
X-Content-Age
X-Content-Powered-By
GEO-INFO
X-Erf-Web-Scheduler
X-Zen-Fury
X-Drupal-Cache-Contexts
Fastcgi-Useragent
Filters
X-Storage
Azure-InstanceId
Azure-Version
Azure-SiteName
X-Tb
Azure-RegionName
Azure-SlotName
X-ServerID
X-Urbn-Context-Path
Load-Balancing
X-Urbn-Site-Id
X-LAGOON
X-GeoCountry
X-Git-Commit
X-Proto
X-Rewrite-Enabled
X-UPSTREAM-Address
X-Cache-Operation
X-SayCDN-TTL
X-Say-TTL
X-SaId
X-Say-Cacheable
X-GeoCode
X-JoinUs
S-Rt
X-Varnish-Cache-Hits
Onion-Location
Meta-Geo
Locale
X-Container-Uri
X-Cache-Action
X-Director
X-Labrador-Cache-Channel
X-XRDS-LOCATION
X-Forwarded-Host
X-Soup
X-Cluster-Node
Uber-Trace-Id
X-PHP-Host
X-Varnish-Hostname
X-VC-Cache
X-RM-Cache-TTL
X-Sucuri-Cache
X-Sucuri-ID
X-VCT
X-Ms-Version
X-Detected-As
X-Cache-Server
X-Adobe-Source
X-Generation-Time
X-Logging-Id
X-Sql-Count
X-Served-From
X-Ms-Request-Id
X-Sql-Duration-Ms
Web-Mar-Node
X-B3-SpanId
TWC-Locale-Group
TWC-GeoIP-LatLong
TWC-Privacy
Webcakes-App-Name
TWC-GeoIP-Country
TWC-Device-Class
Mn-Server-Ip
Node
Property-Id
TWC-Connection-Speed
Webcakes-App-Version
Webcakes-Region
X-RCS-CacheZone
X-Routing-Service
X-Skip-Cache
X-Zipkin-Id
X-Proxied
X-Origin-Hint
X-Debug
X-Extlb
X-FB-TRIP-ID
DB-Nickname
X-R9-Blue-Green-Version
X-Tumblr-Pixel-2
X-Tumblr-Pixel-3
Selected-Fe
X-Uri
X-Timing-Wait
X-Format
X-Fetched-On
X-LSADC-Cache
X-Proxy-Build
X-Lambda-Id
X-Template
CDN-RequestId
X-Tec-Api-Root
X-Tec-Api-Version
OT-Force-Account-Verify
X-Tec-Api-Origin
Source
X-Srv
X-Loop
X-Ratelimit-Reset
X-Tncms
X-Origin-Date
X-MP-GENERATED-AT
X-Cache-Hit
Fastly-Drupal-HTML
X-Pass-Why
X-URL
X-Varnish-Hits
X-Endurance-Cache-Level
X-MCACHE
X-Cache-Expired-At
X-Redis-Cache
X-Ua
Content-Secure-Policy
Upgrade-Insecure-Requests
Cross-Origin-Window-Policy
X-UA-Device-Type
X-Real-IP
X-Cache-TTL-Remaining
Section-Io-Id
X-CCDN-Origin-Time
Section-Origin-Responded
X-Hcs-Proxy-Type
Section-Io-Origin-Time-Seconds
X-CCDN-CacheTTL
Section-Io-Origin-Status
X-Origin-CC
X-Origin-TTL
X-Pubstack
X-Fastly-Request-Id
X-NGENIX-Cache
X-Rn-Rsrv
X-Via-JSL
X-AIR-PT
X-GEO
X-S
X-Server-W
X-Node-Name
X-Newrelic-Synthetics
X-CSRF-Token
NGB
X-TimeS
X-RTag
Ms-Operation-Id
Cache-Provider
MS-CV
Cache-Hits
X-Cache-Host
CDN-CachedAt
CDN-Cache
CDN-PullZone
CDN-EdgeStorageId
CDN-RequestCountryCode
CDN-Uid
CDN-RequestPullSuccess
CDN-RequestPullCode
Cache-Name
X-Akamai-Transformed
X-Hl-Ver
X-Cms-Context
X-Xfnlog-Site
X-IPLB-Instance
X-Restarts
X-Cache-Type
Apigw-Requestid
X-Optimistic-Header
X-Reqid
X-IPLB-Request-ID
X-PHP-Backend
X-Datadome
X-Handled-By
X-Parent-Response-Time
X-BYPASS-REASON
X-No-Session
X-ProxyCache-Status
X-ProxyCache-Key
X-A-Wwc
DCR-Processing-Time-Ms
X-A-Dam
DCR-Decision-By
X-A-Dgt
X-A-Dcw
Fastly-Backend-Name
Odigeo-Trace-Id
X-Aed
Ngx.Var.Host
X-Accel-Expires-Debug
Sslversion
Rendered-Blocks
Server-Host
Canary
Candidate-Md5Url
CPC-Age
X-Accel-Buffering
Redirect-Candidate
Surrogated-Key
CPC-Cache
Fastly-SSL
W
True-Client-Country-4JS
Magicmarker
Lang
Vix-Hermes-Req-Id
N-Cache
VNS-Age
Meta-Geo-Continent
MD5-Digest
Mail-Subject
L5d-Success-Class
L
Gannett-Cam-Experience-Id
X-A-Ccd
T-Server
VNS-Cache
X-A
Gh-Request-Id
HA-Ipaddr
Web-Mar-Region
Ha-Gx-Prefs
Fastly-GeoIP-CountryCode
X-Debug-Cache-Fetch
X-Nyt-Route
X-Mvc-Supplant-Cachable
X-JWT-State
X-Orig-Expires
X-Origin-Time
X-RateLimit-Limit-Second
X-Policy
X-We-Are-Hiring
X-Is-Gdpr
X-GeoIP-Country-Code
X-Gdpr
X-GeoIP-Region-Code
X-Has-Esi
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-RateLimit-Remaining-Second
X-Request-Host
X-Tenant
X-SD-PageType
X-Var-Ttl
X-SRCache-Key
X-Slack-Shared-Secret-Outcome
X-Slack-Backend
X-Shop-Environment
X-Vdms-Path
X-Vdms-Version
X-S-Cookie
X-Rojux
X-Vtex-Remote-Cache
X-Viewer-Country
X-VG-WebCache
X-ScT
X-Forwarded-Path
X-FC-Vary-Parameters
X-CF-Lambda-Fn
X-Cdn-Diag
X-CacheTTL
X-CF-Lambda-Version
X-CGP
X-Csrf-Jwt
X-Conf
X-Cache-NE
X-Cache-Info
X-B-Cookie
X-Application
X-Bc-Bl
X-BCube-Filmed-By
X-Cache-Bucket
X-Bl-Debug
X-D
X-Date
X-Wix-Viewer-Type
X-Ec-GeoHdr
X-Ec-Fail
X-Epic-Correlation-Id
X-Eu-Site
X-Fastly-Backend
X-External-Request-Id
X-Ec-Custom-Error
X-Worker
X-Destination
X-Debug-Cache-Store
X-Developer
Xc-Version
X-Dispatcher-Number
BehaviorPad-Version
X-App
We-Hiring
X-CACHE-AGE
X-AWS-Id
ServedBy
X-LJ-Flow-ID
X-VWS-Id
X-Cluster
X-DPWN-IS-SECURE
X-Level-Front-Cache
X-DefHash
X-DefElseHash
X-Section
X-Loc
X-Esi-Check
X-Irp-Debug
X-Geo-Header
X-Gzip
X-Generated-On
X-Core-Value
X-Human
X-Fmm-Version
X-Hash
X-CMSURLCustom
Thinkindot-Control
X-Alternate-Cache-Key
X-ApacheServer
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
Release
Req-Svc-Chain
TDXMobile
X-App-Name
X-Auto-Login
X-Cdn-Origin
X-Clara-WADP
X-Clientip
X-Cache-Id
X-Cache-Debug
X-BBC-Edge-Cache-Status
X-Bip
X-Core-Mission
X-Mly-Id
X-SVT-ORM-VERSION
X-Test
X-Thanos
X-SVT-ORM-RULES
X-Storefront-Renderer-Rendered
X-Sn-Servicetimems
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Thinkindot-L3
X-Variation
X-Vmg-Version
X-VServer
X-WADP-Cache
X-VG-TLSProxy
X-Varnishpool
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
X-Shopify-Stage
X-ShopId
X-Origin-Response-Time
X-Owner
X-PAYTM-SRV-ID
X-Org
X-Old-Content-Length
Producers
X-Nitro-Cache
X-Node-Id
X-PERF
X-Platform
X-S-Maxage
X-Server-IP
X-ShardId
X-Access
X-Request-Time
X-Pool
X-Qloud-Router
X-Mid
X-INCAP-ABP
Host-ID
Is-Eu
Machine
Memcached
Expect-Staple
Environment
Adler-Geo
AKAMAI
Cmsid
Cmstype
Origin
Datacenter
Platform
User-Cache-Control
X-Proxy-Cache-Status
X-TIME
X-Tx-Id
X-Nginx-Cache-Key
X-Nananana
X-Mvc-Supplant-OutputCached
Esi-Enabled
X-Akamai-Device-Characteristics
Sever-Int
NM-Fastcgi-Cache
X-Origin
X-NodeID
X-GeoIP
X-Dispatcher-Server
X-Cdn-Srv
X-Device-Os
Server-Hostname
X-Forwarded-Site
X-From
X-Hnp-Log
Country-Code
Server-Ext
X-Gen-Mode
X-Block-Status
DSUID
Apple-News-Services-Request-Url
CDCHOST
X-Scale
Apple-News-Services-Parsed-Url
X-Up
X-WA-Info
Apple-News-Services-Handled
CloudFront-Viewer-Country
Apple-News-Services-Host
X-Via-Fastly
WP-Super-Cache
Wxu-Next-Hostname
X-Instance-Name
X-LB-NoCache
X-Cache-Enabled
X-Vcl-Version
Server-Info
X-Presslabs-Stats
Ssr
Wxu-Next-Region
Origin-EX
Origin-CC
X-TIM-N
X-Op-Id-All
Wxu-Next-Commit
X-Refresh
C-Via
Pics-Label
X-TA-CDN-Provider
X-NCache
X-Cs
X-Cache-Status-Check
X-Air-Source
Time
X-Air-Hostname
X-Correlation-ID
X-Amz-Meta-Cb-Modifiedtime
X-Air-Trace-Id
Hostname
Memory
X-API-Version
Origin-Agent-Cluster
Cf-Device-Type
Server-ID
X-ZONE
X-Web-Node
X-HA-Backend
X-Dc
X-Azure-Ref-OriginShield
NGX
X-Tb-Optimization-Total-Bytes-Saved
X-Platform-Processor
GeoIP-Latitude
X-Platform-Router
X-Platform-Cluster
AMP-Access-Control-Allow-Source-Origin
X-Varnish-Beresp-Grace
X-VHOST
X-CACHE-GROUP
X-Microcachable
Cache-Host
X-Origin-Expires
X-B3-Spanid
XM
X-Vgn-Hpd-Reason
X-Varnish-Beresp-Ttl
X-Micro-Cache
X-Internal-Host
X-Wp-Cf-Super-Cache-Active
X-Site-Version
X-HN
X-DC
X-Locale
PFcat
YJS-ID
X-Fpc
X-VarnishDD-TTL
X-TraceId
Cdn-Requestid
X-AB
X-Ad-Defer-Variation
X-WP-CF-Super-Cache-Active
X-Webkit-Csp-Report-Only
Resin-Trace
X-Via-CDN
X-Via-Edge
X-Via-SSL
Edge-Copy-Time
Srvid
X-FTR-Request-ID
Sid
Locid
A
X-FL-QIT-DEBUG
X-FL-EDGE
Location
X-Buckets
X-Zone
X-Geo-Region
X-Pod-Name
X-LiteSpeed-Cache-Control
Uri
X-DataCenter
X-SIPLIST1
X-B3-Parentspanid
IsBot
X-Github-Request-Id
X-Moov-Xdn-Version
X-ATG-Version
X-Moov-T
X-Backend-Instance
X-Cached-By
X-Accel-Version
X-Contensis-Viewer-Groups
True-Client-Ip
User-Agent
X-Cache-ASPX
X-FireWall-Port
X-Upstream-Ct
X-Upstream-Ht
GeoIP-Country-Code
X-Info
Cache-Key
X-Varnish-Authentication
X-Tcp-Rtt
X-Is-Mobile
X-Is-Supported-Browser
X-Is-Tablet
X-Browser-Name
X-Is-Desktop
CF-Ctrl
XServer
X-Nitro-Rev
X-Nitro-Cache-From
GeoIp-Country-Code
X-NGINX-Cache
Cdn
X-Planisys-CDN-TTL
X-HS-Content-Campaign-Id
X-Planisys-CDN-Rules
State
X-Platform-Server
X-MSEdge-Features
NtCoent-Length
X-MSEdge-Flight
X-Datacenter
X-Planisys-CDN-Cache
X-VCache
SID
X-LiteSpeed-Tag
Lb
X-VC
X-Provided-By
X-Hyper-Cache
True-Client-IP
Epwk-X-Cache
X-CS
X-Fastly-Cache
X-Release
X-Cache-Ttl
X-CSRF-TOKEN
X-NewRelic-App-Data
X-Rocket-Build-Number
Path
X-Cache-Remote
X-Sigma-Backend
X-Sigma
X-Frame-Option
Fastly-Drupal-Html
X-Geo
X-RN-RSRV
Cache
X-HS-Status
X-Vgn-Hpd-Variations-Key
X-Vgn-Hpd-Ssi
X-Vgn-Hpd-Cached
X-Service
X-FPC
X-Webstats-RespID
X-TRACE-ID
X-APP-VERSION
X-Api-Version
X-Gamma-Serve
X-Scheme
X-GeoIP-City
X-Generated-In
X-HostName
Tcn
X-Pad
X-GoCache-CacheStatus
X-SRV
Cf-Ipcountry
Serverid
X-Rebelmouse-Surrogate-Control
CountryCode
X-UA
X-Rebelmouse-Cache-Control
X-Origin-Cache-Key
X-Air-Pt
X-Amz-Meta-Opti
X-Edge-Server
X-Esi
Cdn-Request-Time
Cdn-Host
X-Vercel-Cache
Ohc-File-Size
X-AK-Request-ID
Cdnsip
Cdncip
X-Vercel-Id
X-FTR-Expires
X-FTR-Backend
X-FTR-Cache-Status
Cache-Tv-Group
X-FTR-Backend-Server
X-FTR-Balancer
X-Country-Code-Real
X-Guploader-Uploadid
M-TraceId
Req-ID
X-Traceid
X-NMSegId
X-Branch-Name
WZWS-RAY
X-Wp-Cf-Super-Cache-Cache-Control
WebServer
X-Wp-Cf-Super-Cache
Kp-EeAlive
X-EC-Lua
LB
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-Cdn-Request-ID
CDN
Env
X-Ad-Load-Variation
X-Location
X-Mobile-URL
X-Cdn-Cache-Status
Proxy-Connection
X-Vc
XkeyRZ
Cluster
Yak-Timeinfo
X-Akamai-Pragma-Client-IP
X-Proxy-CacheRZ
X-VCL-Version
X-CACHE-KEY
HostName
X-NWS-UUID-VERIFY
X-Edge-Pop
X-M-Reqid
On-Server
Server-Id
X-M-Log
X-Scope-Id
X-Cache-Tags
X-Aicache-OS
X-Ha-Backend
X-Developers
X-Men
Geoip-Latitude
X-Request-Start
Pramga
Ohc-Cache-HIT
X-WP-CF-Super-Cache-Cookies-Bypass
X-Region-Sid
CacheControlHeader
Ngx
X-Cdn-Forward
Srv
X-Lb-Cache
Content-Script-Type
Content-Style-Type
X-Via-Popn
X-Cache-FS-Status
X-TX-ID
Mime-Version
V-Age
Tube-Get-Contents
X-Wa
X-Via-Popv
Tube-Got-Eval
X-CDN-Cache-Status
X-Servedbyhost
Tube-Return
Tube-Got-Results
X-V-Cache
X-SB
X-Req
X-Varnish-Beresp-Status
X-Nc
CF-Cached-On
RNT-Machine
X-Acquia-Purge-Cdn-Unconfigured
X-Shield-Cache-Expires
X-Tim-N
X-Qnm-Cache
X-B3-Trace-ID
Click-Count-Action-Start
X-LB-ID
X-Via-Poph
X-Check-Cacheable
Click-Count-Error
X-Minions-Version
RNT-Time
X-TT-LOGID
X-Request-URI
X-Lb-Nocache
Edge-Cache
X-Cache-Date
PICS-Label
X-IN-APIGATEWAY
X-Edge-POP
ENV
X-Snapshot-Date
WWW-Authenticate
X-Fastly-Country-Code
X-MiniProfiler-Ids
X-Dw-Trace-Id
X-IN-APIGATEWAYSSL
X-Acquia-Application-UUID
X-Acquia-Purge-Tags
X-Acquia-Site
X-Acquia-Application-Trace
X-Via-Ucdn
X-Varnish-Beresp-TTL
Yjs-Id
X-Fastly-Backend-Reqs
X-Miniprofiler-Ids
X-ElasticPress-Query
X-CF-Cache-Header-Cache-Control
X-CUA
X-UP
X-Serial
X-Cached-Since
X-CF-Cache-Header-Vary
X-Iauth-Set-Uid
Inserted-Into-Cache-At
X-Fastly-Cache-Hits
X-User
CACHE-MISS-TO-ORIGIN
X-Litespeed-Cache-Control
Cneonction
Vha6-Origin
Log-Origin
X-RAMCache