Threat Level: green Handler on Duty: Jan Kopriva

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Accept-Ranges
X-XSS-Protection
Expect-CT
Pragma
X-Powered-By
X-Cache
CF-RAY
Via
Age
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
CF-Ray
X-Xss-Protection
X-Download-Options
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Request-Id
X-Adblock-Key
Access-Control-Allow-Credentials
X-FRAME-OPTIONS
X-Permitted-Cross-Domain-Policies
X-AspNet-Version
Alt-Svc
X-Request-ID
X-Runtime
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Generator
X-Check
X-Cache-Status
X-Cacheable
Timing-Allow-Origin
X-Envoy-Upstream-Service-Time
X-Iinfo
X-Content-Security-Policy
X-Drupal-Dynamic-Cache
Feature-Policy
Content-Encoding
Access-Control-Expose-Headers
Upgrade
Status
X-CDN
X-AspNetMvc-Version
Access-Control-Max-Age
X-Via
Server-Timing
Request-Context
X-Dns-Prefetch-Control
X-Robots-Tag
X-Turbo-Charged-By
X-UA-Device
X-Amz-Request-Id
X-Cache-Group
X-Amz-Id-2
EagleId
X-Backend
X-AH-Environment
P3p
X-Proxy-Cache
Keep-Alive
X-Server
X-Ws-Request-Id
X-Age
Cf-Edge-Cache
Host-Header
X-Hacker
X-Vhost
X-Server-Powered-By
X-Rq
X-Varnish-Cache
X-Dispatcher
X-Amz-Version-Id
Grace
Allow
X-Swift-CacheTime
X-Swift-SaveTime
X-OneAgent-JS-Injection
Ali-Swift-Global-Savetime
X-LiteSpeed-Cache
X-Ua-Compatible
X-Page-Speed
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
Cf-Apo-Via
X-Device
X-WebKit-CSP
Cf-Railgun
Accept-CH
X-Aws-Lambda-Call-Status
X-Node
X-Pingback
X-Server-Id
X-Host
X-Ruxit-JS-Agent
EagleEye-TraceId
Surrogate-Control
X-Nginx-Cache-Status
X-Akam-SW-Version
X-Readtime
Request-Id
X-Backend-Server
Accept-Ch-Lifetime
X-Content-Security-Policy-Report-Only
X-HW
X-Cache-Lookup
X-Cache-Spec
X-Cloud-Trace-Context
X-Trace
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Response-Time
X-Application-Context
Permissions-Policy
X-Nginx-Upstream-Cache-Status
Fastly-Restarts
X-Litespeed-Cache
X-Edge
X-Mod-Pagespeed
X-WebKit-CSP-Report-Only
X-Country
Content-Location
X-Mcache
X-MS-InvokeApp
X-Content-Type
X-Url
X-Clacks-Overhead
X-Vname
X-PC
X-TtlSet
X-Midtier
X-Amz-Server-Side-Encryption
X-CST
Accept-CH-Lifetime
Rating
RTSS
Cache-Tag
X-ESI
X-Vcap-Request-Id
X-D2id
X-Rack-Cache
X-Element-Page-Cache
X-ECACHE
X-GoogleNews-Bot
X-Kinja-Revision
X-Exp-Variant
X-Kinja-Build
X-Kinja-Server
Origin-Trial
X-Kinja
Verso
X-Cdn-Fetch
X-Use-Magma
X-Exp-Id
X-VARITI-CCR
X-Server-Name
X-GitHub-Request-Id
X-Ac
Service-Worker-Allowed
X-Powered-By-Plesk
X-Cnection
X-SharePointHealthScore
X-Amz-Rid
SPRequestGuid
X-Navigation-Version
X-Client-IP
Xkey
SPIisLatency
Edge-Control
SPRequestDuration
X-Abt-Application-Version
X-Upstream
X-Cache-TTL
Arr-Disable-Session-Affinity
X-Ttl
X-Varnish-TTL
X-B3-TraceId
X-Cached
X-Mg-S
X-Dw-Request-Base-Id
X-Webkit-Csp
X-Instrumentation
X-Kraken-Loop-Name
X-Erf-Bev-Bev
X-Browser-Type
X-Server-Lifecycle-Phase
X-Erf-Bev-Bev-Is-Generated
X-NWS-LOG-UUID
X-Px
Accept-Ch
Pagespeed
Display
X-Middleton-Display
X-Sol
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-NF-Request-ID
Access-Control-Request-Method
X-Forwarded-For
Edge-Cache-Tag
X-Correlation-Id
X-FastCGI-Cache
X-Cache-Key
X-Country-Code
X-Goog-Hash
X-Powered-CMS
X-Ser
X-Id
Content-MD5
AR-ATIME
AR-CACHE
AR-PoweredBy
AR-Request-ID
AR-SID
Front-End-Https
Public-Key-Pins
TCN
X-Amzn-Trace-Id
X-HP-Webp
X-HP-Trace-Id
X-Jurisdiction
X-Version
X-RateLimit-Remaining
X-MSEdge-Ref
X-T
X-Recruiting
X-Content-Digest
X-Ratelimit-Limit
Response
X-Middleton-Response
X-Accel-Expires
TP-Cache
TP-L2-Cache
X-Shield-Request-Id
MicrosoftSharePointTeamServices
S
X-Fastcgi-Cache
Nginx-Cache
Cache-Status
X-XRDS-Location
X-Fastly-Request-ID
X-Request-Received
X-Request-Processing-Time
X-Daa-Tunnel
X-HS-Hub-Id
X-HS-Combine-CSS
X-HS-Cache-Config
X-HS-Content-Id
Server-Node
Cross-Origin-Opener-Policy
Cache-Tags
MRF-Tech
X-B3-TraceId-Primal
Mrf-Cache-Status
X-Distributor
X-Hits
X-PressLabs-Stats
X-LB-Cache
X-Edge-Location-Klb
X-ORACLE-DMS-ECID
X-Kinsta-Cache
X-ORACLE-DMS-RID
X-Origin-Server
X-Ratelimit-Remaining
X-Ua-Browser
X-Ezoic-Cdn
X-Ratelimit-Reset
Fastcgi-Cache
Filterid
Alternate-Protocol
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-TEC-API-ROOT
X-LLID
X-Grace
X-Frontend
X-Request-Handler-Origin-Region
X-Microsite
X-Rid
X-Hostname
Server-Name
X-Logged-In
X-DIS-Request-ID
Healthy
X-FB-Debug
X-Git-Hash
Realpath
X-Varnish-Backend
X-TTL
Cleartype
X-NGENIX-Cache
X-Www-Served-By
X-Cluster-Name
X-Geo-Country
Payment
X-Debug-Info
X-Page-Id
X-Load-Cache
X-Protected-By
DC
MS-Author-Via
X-Forwarded-Proto
X-ASPNET-VERSION
X-Origin-Cache
Access-Control-Allow-Method
Content-Disposition
Charset
X-GUploader-UploadID
X-Goog-Metageneration
X-B3-Sampled
X-Upgrade-Enabled
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Proxy
X-Activity-Id
X-AppVersion
X-Az
X-DataDome
X-Seen-By
X-ECache
Count-Hit
X-Amz-Meta-S3cmd-Attrs
X-B3-Traceid
X-Cache-Age
X-F-Cache
X-Azure-Ref
X-Fb-Rlafr
X-Whom
X-Amz-Replication-Status
Paypal-Debug-Id
X-B
X-Times
Cross-Origin-Resource-Policy
X-Revision
X-Type
X-Akamai-Edgescape
Surrogate-Key
X-Contextid
X-Aspnetmvc-Version
Accept-Charset
X-App-Environment
Viewport
X-Varnish-Server
X-Providence-Cookie
Retry-After
X-Request-Guid
X-Is-Crawler
X-Route-Name
X-Flags
X-Aspnet-Duration-Ms
X-TT
X-Wix-Request-Id
X-Hosted-By
X-Language
X-Signature
X-DynaTrace
X-B-Cache
X-Envoy-Decorator-Operation
X-Cache-Control
X-Source
X-App-Server
X-Magnolia-Registration
X-Mobile
X-Varnish-Grace
X-VCache
X-Goog-Generation
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
Host
Version
WPO-Cache-Status
X-Server-ID
WPO-Cache-Message
X-XRDS-LOCATION
Amp-Access-Control-Allow-Source-Origin
X-N
Refresh
X-Amzn-RequestId
X-Oracle-Dms-Ecid
X-Amz-Apigw-Id
X-Cache-Rule
X-HTML-Minification-Powered-By
Referer-Policy
X-Oracle-Dms-Rid
X-Tumblr-Pixel-0
X-Tumblr-User
X-Tumblr-Pixel-1
X-Response-Served-From
X-Cache-Time
X-Original-Request-Id
X-Varnish-Age
Access-Control-Request-Headers
X-Tumblr-Pixel
X-EdgeConnect-Cache-Status
X-Rule
X-Content-Powered-By
X-Framework
X-G
MS-CV
Protected
X-RTag
X-Cacheable-TTL
SD-X-WS
X-Jobs
X-UUID
Ms-Operation-Id
X-User-Agent
X-RemovedCookies
X-Cache-Status-Check
X-Cache-Grace
X-Backend-Name
X-ProcessESI
X-L-Path
X-Environment-Context
NGB
X-Tt-Trace-Tag
GEO-INFO
X-Region
X-Tt-Trace-Host
Akamai-GRN
From-Origin
X-FW-Version
X-FW-Serve
X-FW-Hash
X-FW-Dynamic
X-FW-Static
X-FW-Type
VIX-Pulpo-Upstream-Status
X-Status
X-Device-Type
VIX-Pulpo-Node
X-FW-Server
X-Trace-Id
X-Http-Reason
Front
X-Rendered-As
X-Is-Bot
X-Cache-Expired-At
X-Page-View
Section-Io-Cache
X-Akamai-Request-ID2
X-Adobe-Content
X-Adobe-Loc
X-Nginx-Cache
X-Instance
X-Drupal-Cache-Tags
X-RateLimit-Limit
X-NYM-Debug-Backend
X-Drupal-Cache-Contexts
CDN-RequestId
Url
X-Unique-Id
X-Servername
Pinterest-Version
X-Pinterest-Rid
Pinterest-Generated-By
X-Time
Liferay-Portal
Accept-Language
X-Content-Options
X-Varnish-Ttl
X-Template
Fastly-SWR
X-Fastly-Request-Id
Fastly-SIE
X-Air-Hostname
X-Air-Trace-Id
X-Air-Source
X-Newrelic-App-Data
Backend
X-Debug-IsConnected
X-Debug-IsPreview
X-CDN-Forward
X-Cache-Hit
X-Zen-Fury
X-Yottaa-Optimizations
SRV
X-Yottaa-Metrics
X-DynaTrace-JS-Agent
Country
X-Mode
Content-Secure-Policy
X-Rocket-Nginx-Serving-Static
X-COUNTRY
X-Uri
X-Cache-Operation
Node
S-Rt
X-Tumblr-Pixel-2
X-Cache-Server
X-Tumblr-Pixel-3
X-IPS-LoggedIn
Onion-Location
X-Edge-Location
Webserver
Filters
Meta-Geo
X-Generation-Time
X-Amzn-Remapped-Content-Length
X-Rewrite-Enabled
X-ARC
X-RN-RSRV
X-UPSTREAM-Address
X-Content-Age
X-Locale
Azure-RegionName
Azure-SlotName
Cache-Hits
Azure-Version
CF-IPCountry
X-Proxy-Cache-Info
X-Timing-Wait
X-PHP-Backend
X-App-Version
Azure-SiteName
Azure-InstanceId
X-Proxy-Build
Selected-Fe
Uber-Trace-Id
X-Tb
X-Via-Fastly
X-Ua
Countrycode
X-Sucuri-Cache
X-Web-Node
X-Site-Version
X-Ms-Version
X-Ms-Request-Id
X-ProxyCache-Key
X-ProxyCache-Status
X-Reqid
X-Cms-Context
X-Cache-Action
X-Soup
Cache-Name
X-Skip-Cache
X-BYPASS-REASON
WP-Super-Cache
X-Sucuri-ID
X-Server-W
X-Cluster-Node
X-Proxied
X-Labrador-Cache-Channel
Cache-Tv-Group
X-Zipkin-Id
X-AWS-Id
X-Format
X-IPLB-Request-ID
X-Say-Cacheable
X-IPLB-Instance
X-SayCDN-TTL
X-Extlb
X-Cache-Host
TWC-Privacy
ServerID
X-LJ-Flow-ID
X-Origin-Hint
X-Say-TTL
X-Section
TWC-GeoIP-LatLong
X-VWS-Id
X-PHP-Host
TWC-Connection-Speed
X-UA-Device-Type
X-Origin-Date
X-Proto
Webcakes-App-Version
X-Proxy-Cache-Status
Property-Id
X-Routing-Service
TWC-Device-Class
TWC-Locale-Group
Webcakes-Region
Webcakes-App-Name
TWC-GeoIP-Country
X-Access
X-Sql-Duration-Ms
X-Sql-Count
Web-Mar-Node
X-VC-Cache
X-Debug
X-SaId
X-Real-IP
X-Handled-By
X-R9-Blue-Green-Version
DB-Nickname
X-LAGOON
X-No-Session
X-Cluster
X-Optimistic-Header
X-Ruxit-Js-Agent
X-JoinUs
X-Forwarded-Host
Cross-Origin-Window-Policy
X-Varnish-Beresp-Grace
Apigw-Requestid
X-FB-TRIP-ID
X-Urbn-Context-Path
X-Urbn-Site-Id
X-Cache-TTL-Remaining
ServedBy
Locale
Mn-Server-Ip
X-Detected-As
X-Adobe-Source
X-Director
X-Tec-Api-Root
X-Tec-Api-Origin
X-Tec-Api-Version
X-LSADC-Cache
X-Xfnlog-Site
X-Node-Name
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
Fastcgi-Useragent
Mime-Version
X-Oneagent-Js-Injection
X-GeoCountry
X-GeoCode
Frame-Options
Upgrade-Insecure-Requests
X-Varnish-Hits
X-Tt-Logid
Source
CDN-Cache
X-Hl-Ver
CDN-PullZone
CDN-RequestCountryCode
X-Buckets
CDN-EdgeStorageId
CDN-CachedAt
CDN-Uid
Fastly-Drupal-HTML
X-Generated-By
Load-Balancing
X-Api-Version
X-Varnish-Cache-Hits
X-GEO
X-FireWall-Port
X-Request-Time
X-SRV
Xet-Cookie
X-ServerID
X-Mg-Request-UUID
X-TA-CDN-Provider
X-Varnish-Hostname
X-Origin-TTL
X-Datadog-Parent-Id
X-RM-Cache-TTL
X-Redis-Cache
X-Origin-CC
X-Datadog-Sampled
X-Datadog-Sampling-Priority
X-Datadog-Trace-Id
X-URL
CF-Cached-On
X-Cache-Debug
X-TIME
X-Loop
X-Akamai-Transformed
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Shopify-Stage
X-Storefront-Renderer-Rendered
X-Alternate-Cache-Key
X-Served-From
X-ShopId
X-ShardId
X-Pubstack
X-Storage
X-Endurance-Cache-Level
Xserver
X-Provided-By
X-Pass-Why
X-Tx-Id
X-Restarts
X-Request-Host
X-Newrelic-Synthetics
X-CSRF-Token
X-Service
X-Location
X-Origin
MD5-Digest
X-Epic-Correlation-Id
X-External-Request-Id
Lang
X-Developer
Memcached
X-Nyt-Route
A
Meta-Geo-Continent
X-Cache-NE
X-Ec-Fail
Cache-Host
BehaviorPad-Version
X-Origin-Time
X-Ec-GeoHdr
Candidate-Md5Url
X-Gdpr
X-CMSURLCustom
Host-ID
X-Hash
X-D
X-Level-Front-Cache
X-CUA
Gannett-Cam-Experience-Id
X-INCAP-ABP
X-Core-Mission
Edge-Cache
DSUID
X-Generated-On
X-Conf
X-Mobile-URL
DCR-Decision-By
X-Mid
X-Destination
DCR-Processing-Time-Ms
X-Men
Ngx.Var.Host
NM-Fastcgi-Cache
X-Bc-Bl
Surrogated-Key
T-Server
Thinkindot-CacheControl
X-Vdms-Version
X-Vdms-Path
X-BCube-Filmed-By
X-Bip
X-Test
X-SVT-ORM-VERSION
X-Thanos
X-Thinkindot-L3
X-TIM-N
Thinkindot-CacheControl-Type
Thinkindot-Control
X-A-Dcw
X-A-Dam
X-A-Dgt
X-A-Wwc
X-Aed
X-A-Ccd
X-A
X-We-Are-Hiring
X-B-Cookie
Xc-Version
X-Application
WWW-Authenticate
X-SVT-ORM-RULES
TDXMobile
X-Processor
X-S
X-S-Cookie
Release
X-Rojux
X-Rocket-Build-Number
Redirect-Candidate
X-Response-By
X-Cache-Date
X-SRCache-Key
Origin
X-S-Maxage
Rendered-Blocks
X-Sigma-Backend
Server-Host
Sslversion
Odigeo-Trace-Id
X-Sigma
X-ScT
X-Cache-Info
Server-Info
X-Fetched-On
HostName
CloudFront-Viewer-Country
X-Cache-Id
X-Ec-Custom-Error
X-Akamai-Device-Characteristics
X-Accel-Expires-Debug
Click-Count-Error
X-Dispatcher-Server
Click-Count-Action-Start
X-Dispatcher-Number
X-CacheTTL
Tube-Got-Eval
Fastly-GeoIP-CountryCode
Fastly-Backend-Name
Mail-Subject
CacheControlHeader
Magicmarker
X-Cache-Bucket
Req-Svc-Chain
Gh-Request-Id
X-BBC-Edge-Cache-Status
X-Date
Country-Code
Cmstype
We-Hiring
Tube-Return
Tube-Got-Results
Tube-Get-Contents
X-Cdn-Origin
Cmsid
X-Httpd
X-Origin-Response-Time
X-Varnishpool
Cache-Key
X-Platform
X-Org
X-Node-Id
X-Human
X-Var-Ttl
X-Loc
X-Mvc-Supplant-Cachable
X-Platform-Cluster
X-Platform-Processor
X-Server-IP
X-Slack-Backend
X-Slack-Shared-Secret-Outcome
X-Sn-Servicetimems
X-SD-PageType
X-Req
X-Platform-Router
X-Pool
X-Region-Sid
X-HS-Content-Campaign-Id
C-Via
X-Geo-Header
X-TNCMS
X-Fastly-Cache
X-Scale
X-Gamma-Serve
X-Fastly-Backend
X-Auto-Login
X-Esi-Check
X-Gzip
AKAMAI
X-Varnish-Beresp-Ttl
X-Via-CDN
Environment
X-WP-CF-Super-Cache-Active
X-FL-QIT-DEBUG
X-Varnish-CookieHashed-On
X-Variation
X-Nginx-Cache-Key
X-Instance-Name
X-Varnish-Remaining-TTL
Srvid
X-Worker
Locid
On-Server
X-Azure-Ref-OriginShield
Origin-EX
X-WADP-Cache
X-WA-Info
X-FL-EDGE
Origin-CC
X-Developers
X-Vmg-Version
X-VServer
X-Cdn-Srv
X-Varnish-CookieINHashed-On
X-Planisys-CDN-TTL
X-GeoIP-Country-Code
X-DefElseHash
X-GeoIP-Region-Code
X-Has-Esi
X-Core-Value
X-DefHash
X-GeoIP-City
X-Fmm-Version
X-FC-Vary-Parameters
X-Frame-Option
X-Device-Os
X-GeoIP
X-Ad-Defer-Variation
X-Irp-Debug
X-Planisys-CDN-Cache
X-Owner
X-Planisys-CDN-Rules
X-Cache-FS-Status
X-SB
X-Origin-Expires
X-NodeID
X-JWT-State
X-Is-Gdpr
X-Mly-Id
X-Clara-WADP
X-Ckpd-Fst-Backend
X-V-Cache
X-Forwarded-Site
X-VC
Datacenter
Expect-Staple
Is-Eu
Kp-EeAlive
Section-Io-Id
Section-Io-Origin-Status
Section-Origin-Responded
X-Vcl-Version
Section-Io-Origin-Time-Seconds
Adler-Geo
Canary
Platform
Machine
Ssr
State
Web-Mar-Region
Vix-Hermes-Req-Id
X-Via-Edge
Edge-Copy-Time
X-Via-SSL
X-From
X-Qloud-Router
X-Release
X-Op-Id-All
X-Request-Start
X-Ua-Device
Cache-Provider
X-Varnish-Beresp-Status
PFcat
L
X-VarnishDD-TTL
X-Old-Content-Length
X-HN
X-NCache
Wxu-Next-Commit
User-Cache-Control
Sever-Int
Wxu-Next-Hostname
Wxu-Next-Region
X-Block-Status
X-Hnp-Log
Server-Hostname
Server-Ext
Apple-News-Services-Handled
X-Gen-Mode
X-Wix-Viewer-Type
Apple-News-Services-Host
X-Minions-Version
X-Accel-Buffering
Apple-News-Services-Parsed-Url
X-VG-TLSProxy
Apple-News-Services-Request-Url
X-Cache-Tags
Producers
NGX
X-DPWN-IS-SECURE
X-App
X-Aicache-OS
X-CACHE-AGE
X-Air-Pt
X-Webkit-CSP-Report-Only
X-Zone
X-Parent-Response-Time
HA-Ipaddr
L5d-Success-Class
CDCHOST
X-Mvc-Supplant-OutputCached
X-Nananana
X-Cache-Remote
X-Microcachable
Ha-Gx-Prefs
X-Platform-Server
X-Csrf-Jwt
X-CGP
X-Eu-Site
AMP-Access-Control-Allow-Source-Origin
X-RCS-CacheZone
X-Cache-Enabled
X-Debug-Cache-Store
X-Up
X-Debug-Cache-Fetch
X-LB-NoCache
Fastly-SSL
X-Dc
X-Lambda-Id
X-Correlation-ID
X-VCT
X-B3-Spanid
X-Via-Popv
X-Via-Popn
X-Tb-Optimization-Total-Bytes-Saved
Pics-Label
X-Cache-Backend
X-Refresh
X-Via-Poph
X-DC
X-Trace-ID
X-B3-SpanId
Sid
Decoy-Debug-Status
Decoy-Debug-TTL
Cluster
VNS-Age
CPC-Cache
VNS-Cache
X-Render-Time
X-Vtex-Remote-Cache
CPC-Age
X-Generated-In
X-Cached-By
X-ND-Cache
Decoy-Debug-Key
X-Cs
Env
NtCoent-Length
X-Upstream-Ht
X-Upstream-Ct
Time
GeoIP-Latitude
X-Hcs-Proxy-Type
X-CCDN-CacheTTL
X-HA-Backend
X-CCDN-Origin-Time
Memory
X-AIR-PT
Cache
X-NWS-UUID-VERIFY
X-Cache-Type
X-Tid
X-Webkit-CSP
X-Edge-Pop
SID
Srv
X-HS-Status
X-TH-Server
X-LB-ID
X-Servedbyhost
X-Esi
X-Presslabs-Stats
Fastly-Drupal-Html
X-ATG-Version
Svr
Server-ID
X-DataCenter
X-Wa
X-Client-Ip
X-NewRelic-App-Data
X-Nc
X-Srv
Cdn
X-Via-JSL
X-Varnish-Authentication
X-Contensis-Viewer-Groups
GeoIp-Country-Code
X-Cache-ASPX
Uri
X-ZONE
X-Vgn-Hpd-Ssi
X-Vgn-Hpd-Variations-Key
X-Vgn-Hpd-Cached
X-Check-Cacheable
X-PAYTM-SRV-ID
X-MP-GENERATED-AT
X-CF-Lambda-Version
X-CF-Lambda-Fn
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
Esi-Enabled
XkeyRZ
X-Datadome
X-Proxy-CacheRZ
X-Amz-Meta-Cb-Modifiedtime
X-Fpc
True-Client-IP
X-Vc
M-TraceId
Lb
N-Cache
X-Wikidot-Static-Cache
X-CACHE-KEY
X-Nf-Request-Id
X-CDN-Cache-Status
X-Wikidot-Backend
YJS-ID
X-NGINX-Cache
Hostname
X-CS
X-Varnish-Beresp-TTL
X-TX-ID
X-Udemy-Cache-App-Namespace
Resin-Trace
X-Gateway-Skip-Cache
X-Gateway-Cache-Status
X-Gateway-Cache-Key
True-Client-Ip
X-AK-Request-ID
X-Gateway-Request-Id
Cdncip
X-Bl-Debug
RNT-Time
RNT-Machine
X-Forwarded-Path
X-Orig-Expires
X-Tenant
X-Shop-Environment
XServer
Cdnsip
X-EC-Lua
X-CSRF-TOKEN
X-MSEdge-Features
X-MSEdge-Flight
X-Fastly-Country-Code
X-API-Version
OT-Force-Account-Verify
X-Via-NSCOPI
X-FPC
X-Policy
X-B3-Trace-ID
X-App-Name
Eomportal-Instance
X-Service-Response-Time
Sm-Log-Id
CDN
Path
Server-Id
X-Cache-Ttl
GeoIP-Country-Code
X-Logging-Id
X-CLOUD-TRACE-CONTEXT
Hit
Ngx-Var-Key
X-Datacenter
X-WA
X-Micro-Cache
X-Accel-Version
X-APP-VERSION
X-Git-Commit
X-Container-Uri
X-VCL-Version
X-Cdn-Diag
X-NC
X-SIPLIST1
IsBot
X-MCACHE
X-Cache-NGX
X-Lb-Id
X-Edge-POP
X-Ha-Backend
LB
HIT
X-Request-URI
X-RateLimit-Reset
X-ServedByHost
X-Geo
X-Vcache
X-Cdn-Forward
X-Info
X-SERVER-NAME
RATING
X-Cdn-Cache-Status
Pramga
X-Akamai-Pragma-Client-IP
Geoip-Latitude
Timeexpire
X-Srcache-Store-Status
Location
Cross-Origin-Opener-Policy-Report-Only
X-Srcache-Fetch-Status
X-Snapshot-Date
X-Acquia-Purge-Cdn-Unconfigured
FSS-Cache
XM
ENV
X-VG-WebCache
V-Age
X-Tncms
X-TT-LOGID
Tcn
X-Clientip
Yjs-Id
X-Via-PopV
X-Via-PopH
CDN-RequestPullSuccess
CDN-RequestPullCode
Epwk-X-Cache
X-Pod-Name
X-Via-PopN
Req-ID
X-Ctl-Mach
Ohc-File-Size
X-Lb-Nocache
X-LiteSpeed-Cache-Control
X-HostName
X-Rebelmouse-Surrogate-Control
X-Wp-Cf-Super-Cache
X-TimeS
X-Wp-Cf-Super-Cache-Cache-Control
X-Iauth-Set-Uid
X-Rebelmouse-Cache-Control
X-Serial
X-Hyper-Cache
True-Client-Country-4JS
X-Dw-Trace-Id
X-Amz-Meta-Opti
X-M-Log
X-M-Reqid
X-LiteSpeed-Tag
Warning
X-Acquia-Purge-Tags
X-Acquia-Site
X-Cdn-Request-ID
X-Litespeed-Cache-Control
Proxy-Connection
X-UP
X-Acquia-Application-UUID
X-RAMCache
X-Oss-Server-Time
X-Acquia-Application-Trace
Content-Script-Type
Content-Style-Type
Ec-Rule-Version
W
WZWS-RAY
Cdn-Requestid
X-Cache-Expires
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
Cneonction
X-Qnm-Cache
X-Oss-Storage-Class
X-Oss-Request-Id
X-Fastly-Backend-Reqs
Servername
X-MiniProfiler-Ids
CountryCode
X-Lsadc-Cache
PICS-Label
X-Vgn-Hpd-Reason
X-Viewer-Country
X-ApacheServer
X-Akamai-ERRuleID
X-Akamai-ERPolicy
X-WP-CF-Super-Cache-Cookies-Bypass
X-PERF
X-User
X-Swift-Error
X-IPS-Cached-Response
X-B3-Parentspanid
My-App
MIME-Version
Ngx
X-B3-ParentSpanId
X-Mg-Cache
X-Webstats-RespID
X-Fastly-Cache-Hits
X-Th-Server
Ohc-Cache-HIT