Threat Level: green Handler on Duty: Rob VandenBrink

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
X-Powered-By
Pragma
X-XSS-Protection
CF-RAY
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
Alt-Svc
P3P
X-Cache-Hits
X-UA-Compatible
X-Xss-Protection
CF-Ray
X-Served-By
X-Download-Options
X-Timer
X-Request-Id
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
Access-Control-Allow-Credentials
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
X-Drupal-Cache
X-Generator
X-Cache-Status
X-Check
X-Cacheable
X-Envoy-Upstream-Service-Time
X-FRAME-OPTIONS
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Iinfo
X-Dns-Prefetch-Control
X-Drupal-Dynamic-Cache
X-Request-ID
Feature-Policy
X-Content-Security-Policy
Content-Encoding
Access-Control-Expose-Headers
Upgrade
X-XSS-PROTECTION
Server-Timing
Status
X-CDN
X-AspNetMvc-Version
Access-Control-Max-Age
X-Amz-Request-Id
Request-Context
X-Amz-Id-2
X-Via
X-Turbo-Charged-By
X-AH-Environment
X-Backend
X-Cache-Group
X-Robots-Tag
Cf-Edge-Cache
Keep-Alive
Host-Header
X-Hacker
X-Proxy-Cache
X-UA-Device
X-Server
X-Rq
X-Vhost
X-Server-Powered-By
Allow
X-Age
X-Varnish-Cache
X-Ws-Request-Id
X-Dispatcher
X-Amz-Version-Id
EagleId
P3p
Nel
Grace
X-LiteSpeed-Cache
Cf-Apo-Via
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Page-Speed
X-Device
Cf-Railgun
EagleEye-TraceId
X-Aws-Lambda-Call-Status
X-Swift-CacheTime
X-Swift-SaveTime
X-Pingback
X-OneAgent-JS-Injection
Ali-Swift-Global-Savetime
X-Host
X-Node
Accept-CH
X-WebKit-CSP
X-CST
X-Backend-Server
Surrogate-Control
X-Cache-Lookup
X-Server-Id
X-Nginx-Cache-Status
X-Readtime
Permissions-Policy
X-Akam-SW-Version
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Nginx-Upstream-Cache-Status
Accept-CH-Lifetime
Request-Id
X-Application-Context
X-Content-Security-Policy-Report-Only
X-Cloud-Trace-Context
X-Ua-Compatible
X-Trace
X-Response-Time
X-HW
X-Edge
Content-Location
X-Clacks-Overhead
X-Mod-Pagespeed
Xkey
X-Midtier
Rating
X-ESI
X-Amz-Server-Side-Encryption
X-ECACHE
X-Ruxit-Js-Agent
X-Mcache
X-Url
X-Ruxit-JS-Agent
Accept-Ch-Lifetime
X-Upstream
X-Country
X-Vcap-Request-Id
X-Oneagent-Js-Injection
Cache-Tag
X-D2id
X-MS-InvokeApp
X-Cdn-Fetch
X-Kinja
X-Kinja-Server
X-Kinja-Revision
X-Use-Magma
X-GoogleNews-Bot
X-Exp-Id
X-Exp-Variant
X-Kinja-Build
X-Element-Page-Cache
Verso
X-Rack-Cache
X-Litespeed-Cache
X-Vname
X-PC
X-TtlSet
Accept-Ch
X-Powered-By-Plesk
Edge-Control
RTSS
X-Cache-TTL
Fastly-Restarts
X-Ac
X-VARITI-CCR
Origin-Trial
X-Navigation-Version
X-Abt-Application-Version
X-Country-Code
Service-Worker-Allowed
X-WebKit-CSP-Report-Only
X-Goog-Hash
X-Cached
Display
X-Sol
Pagespeed
X-Middleton-Display
X-Browser-Type
X-GitHub-Request-Id
X-Amz-Rid
X-Ttl
X-Varnish-TTL
Cross-Origin-Opener-Policy
X-Webkit-CSP
X-Content-Type
X-Dw-Request-Base-Id
SPRequestGuid
X-SharePointHealthScore
X-Mg-S
X-Server-Name
X-Amzn-Trace-Id
X-Powered-CMS
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
Arr-Disable-Session-Affinity
Response
X-Server-Lifecycle-Phase
X-Instrumentation
X-Kraken-Loop-Name
X-Middleton-Response
AR-ATIME
AR-PoweredBy
AR-Request-ID
AR-SID
SPIisLatency
SPRequestDuration
X-Cache-Key
X-Kinja-CCPA
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-B3-Traceid
X-B3-TraceId
X-Times
X-Version
AR-CACHE
X-SRCache-Fetch-Status
X-NWS-LOG-UUID
X-SRCache-Store-Status
X-HP-Trace-Id
X-Jurisdiction
X-HP-Webp
X-Pinterest-Rid
X-NF-Request-ID
Pinterest-Version
Pinterest-Generated-By
X-Accel-Expires
X-T
Cache-Tags
X-Fastly-Request-ID
Cache-Status
X-Cnection
Front-End-Https
Nginx-Cache
X-MSEdge-Ref
Edge-Cache-Tag
X-Server-ID
X-Aspnetmvc-Version
X-Client-IP
X-FastCGI-Cache
X-Hits
X-Ser
X-Px
Mrf-Cache-Status
Public-Key-Pins
X-B3-TraceId-Primal
MRF-Tech
Payment
X-Recruiting
X-LLID
X-Frontend
X-Request-Received
X-Request-Processing-Time
X-RateLimit-Remaining
Server-Node
X-Ua-Browser
X-Fastcgi-Cache
X-Erf-Stays-Pdp-Viaduct-Migration-Web
X-Shield-Request-Id
X-DIS-Request-ID
TP-Cache
S
X-RateLimit-Limit
MicrosoftSharePointTeamServices
Access-Control-Request-Method
X-Goog-Metageneration
X-GUploader-UploadID
X-HS-Cache-Config
X-HS-Hub-Id
X-HS-Combine-CSS
X-HS-Content-Id
X-Content-Digest
X-Amz-Apigw-Id
X-LB-Cache
X-Amzn-RequestId
X-Request-Handler-Origin-Region
X-Protected-By
Content-MD5
X-Microsite
X-Distributor
TP-L2-Cache
X-FB-Debug
Access-Control-Allow-Method
X-Page-Id
Realpath
Accept-Charset
X-Ratelimit-Remaining
X-Ezoic-Cdn
X-Cluster-Name
Fastcgi-Cache
X-PressLabs-Stats
X-Forwarded-For
X-Rid
X-Hostname
X-Geo-Country
X-B3-Sampled
X-Seen-By
X-Webkit-Csp
X-Aspnet-Version
Cleartype
X-Ua-Device
X-Ratelimit-Limit
X-TTL
X-Correlation-Id
Referer-Policy
X-Envoy-Decorator-Operation
X-Webkit-CSP-Report-Only
X-Mobile
X-Newrelic-App-Data
X-Goog-Stored-Content-Length
DC
TCN
X-Goog-Generation
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
Cross-Origin-Resource-Policy
X-Daa-Tunnel
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
X-Content-Options
X-Debug-Info
Count-Hit
X-Varnish-Backend
X-Contextid
X-Origin-Cache
X-Logged-In
X-Varnish-Grace
X-Amz-Replication-Status
Surrogate-Key
X-App-Server
X-App-Environment
X-Fb-Rlafr
X-Grace
X-Git-Hash
X-IPS-LoggedIn
X-Revision
X-Hosted-By
X-Request-Guid
X-Aspnet-Duration-Ms
X-Is-Crawler
X-Flags
X-Route-Name
X-Providence-Cookie
X-TT
X-Azure-Ref
X-Origin-Server
X-Amz-Meta-S3cmd-Attrs
Frame-Options
X-XRDS-Location
X-Forwarded-Proto
X-Client-Ip
Alternate-Protocol
X-Edge-Location-Klb
X-Kinsta-Cache
X-Wix-Request-Id
X-Whom
Retry-After
WPO-Cache-Status
WPO-Cache-Message
Healthy
Charset
X-F-Cache
X-Akamai-Edgescape
Viewport
Section-Io-Cache
X-Magnolia-Registration
X-Backend-Name
MS-Author-Via
Paypal-Debug-Id
X-RateLimit-Reset
X-B
X-App-Version
X-COUNTRY
X-Proxy-Cache-Info
SRV
X-Az
X-AppVersion
X-Activity-Id
X-Id
ServerID
X-Language
VIX-Pulpo-Node
SD-X-WS
X-Http-Reason
VIX-Pulpo-Upstream-Status
X-ARC
X-Original-Request-Id
X-Instance
X-Response-Served-From
X-N
X-Rule
Host
X-Cache-Rule
X-EdgeConnect-Cache-Status
Filterid
Akamai-GRN
X-User-Agent
X-Rocket-Nginx-Serving-Static
X-Edge-Location
Front
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
Protected
X-Varnish-Age
X-Akamai-Request-ID2
X-UUID
X-Cache-Grace
X-Status
X-Load-Cache
Fastly-SWR
X-Cacheable-TTL
From-Origin
Server-Name
X-Time
X-FW-Version
X-Region
X-L-Path
Amp-Access-Control-Allow-Source-Origin
X-Jobs
X-Rendered-As
Fastly-SIE
X-FW-Type
X-Is-Bot
X-FW-Serve
X-FW-Dynamic
X-FW-Hash
X-FW-Static
X-FW-Server
X-Framework
X-Unique-Id
X-Environment-Context
X-Cache-Time
X-Cache-Age
X-Adobe-Loc
X-Type
X-Varnish-Server
Access-Control-Request-Headers
X-Www-Served-By
X-Adobe-Content
X-Page-View
Country
X-Tumblr-Pixel-1
X-Tumblr-User
X-Tumblr-Pixel-0
X-Datadog-Trace-Id
X-Tumblr-Pixel
X-RemovedCookies
X-ProcessESI
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
X-Cache-Control
X-G
X-DataDome
X-Trace-Id
X-Proxy
Refresh
X-Vcache
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Xrds-Location
X-Mg-Request-UUID
X-Datadog-Sampled
X-CDN-Forward
X-Debug-IsPreview
X-Source
X-Amzn-Remapped-Content-Length
X-Debug-IsConnected
X-Drupal-Cache-Tags
X-ECache
X-Signature
Version
X-B-Cache
Accept-Language
X-URL
X-Oracle-Dms-Ecid
Content-Disposition
Countrycode
Backend
X-Oracle-Dms-Rid
Xet-Cookie
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
X-Nf-Request-Id
X-HTML-Minification-Powered-By
CF-IPCountry
X-Erf-Web-Scheduler
X-Generated-By
X-DynaTrace-JS-Agent
Webserver
X-DynaTrace
X-ID
X-Nginx-Cache
X-Servername
X-Mode
X-Httpd
Url
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Upgrade-Enabled
Xserver
X-Tec-Api-Version
X-Tec-Api-Root
X-Tec-Api-Origin
GEO-INFO
X-Content-Age
X-Varnish-Ttl
X-Storage
X-Template
Filters
X-Tb
X-GeoCode
Fastcgi-Useragent
Load-Balancing
X-GeoCountry
Azure-Version
X-LAGOON
X-JoinUs
Locale
X-Director
Azure-RegionName
Azure-SiteName
Azure-SlotName
S-Rt
Azure-InstanceId
X-Cache-Action
X-Cache-Operation
X-Device-Type
Meta-Geo
Onion-Location
X-Urbn-Context-Path
X-SayCDN-TTL
X-ServerID
X-Rewrite-Enabled
X-Say-TTL
X-Say-Cacheable
X-SaId
X-Proto
X-Varnish-Cache-Hits
X-NYM-Debug-Backend
X-UPSTREAM-Address
X-Urbn-Site-Id
Uber-Trace-Id
X-Cluster-Node
X-Varnish-Hostname
X-Content-Powered-By
X-VC-Cache
X-Soup
X-Container-Uri
X-Forwarded-Host
X-Tt-Logid
X-PHP-Host
X-Git-Commit
X-Labrador-Cache-Channel
X-RM-Cache-TTL
X-VCT
OT-Force-Account-Verify
X-Ms-Version
X-Cache-Server
X-Adobe-Source
X-Ms-Request-Id
X-Logging-Id
X-Detected-As
X-Served-From
X-Generation-Time
DB-Nickname
X-XRDS-LOCATION
Webcakes-App-Name
X-Zipkin-Id
Webcakes-App-Version
X-LSADC-Cache
TWC-GeoIP-LatLong
Webcakes-Region
TWC-Privacy
Web-Mar-Node
Mn-Server-Ip
Node
TWC-Device-Class
TWC-GeoIP-Country
Property-Id
X-Zen-Fury
TWC-Connection-Speed
X-Debug
X-RCS-CacheZone
X-Routing-Service
X-FB-TRIP-ID
X-R9-Blue-Green-Version
X-Proxied
X-Lambda-Id
X-Origin-Hint
X-Skip-Cache
X-Extlb
X-Sucuri-ID
TWC-Locale-Group
X-Sql-Count
X-Sucuri-Cache
X-Sql-Duration-Ms
X-Tumblr-Pixel-3
X-Uri
X-Tumblr-Pixel-2
X-Timing-Wait
X-Fetched-On
X-Format
X-Proxy-Build
Selected-Fe
X-Drupal-Cache-Contexts
X-MCACHE
Liferay-Portal
X-Tncms
X-Loop
CDN-RequestId
X-B3-SpanId
X-CCDN-Origin-Time
X-Rn-Rsrv
X-CCDN-CacheTTL
X-Hcs-Proxy-Type
X-Endurance-Cache-Level
X-Srv
Source
X-Cache-Hit
X-Redis-Cache
X-MP-GENERATED-AT
X-Origin-Date
X-Ratelimit-Reset
Cross-Origin-Window-Policy
X-Fastly-Request-Id
Fastly-Drupal-HTML
X-Ua
X-Varnish-Hits
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
Section-Io-Origin-Status
X-TimeS
Section-Io-Id
X-Cache-Expired-At
X-Pass-Why
Upgrade-Insecure-Requests
X-S
Content-Secure-Policy
X-Real-IP
X-UA-Device-Type
X-Cache-TTL-Remaining
X-Node-Name
X-Akamai-Transformed
X-Origin-CC
X-Origin-TTL
X-Pubstack
X-Newrelic-Synthetics
X-GEO
X-CACHE-AGE
CDN-Cache
CDN-Uid
CDN-EdgeStorageId
CDN-CachedAt
CDN-PullZone
CDN-RequestCountryCode
CDN-RequestPullCode
X-Server-W
CDN-RequestPullSuccess
X-Hl-Ver
X-Via-JSL
X-RTag
Cache-Provider
MS-CV
X-CSRF-Token
Ms-Operation-Id
X-AIR-PT
X-Handled-By
X-Cache-Host
X-Parent-Response-Time
X-A-Dgt
X-A-Dcw
X-A-Wwc
X-Bl-Debug
X-B-Cookie
X-Application
X-Bc-Bl
X-BCube-Filmed-By
X-Aed
X-App
X-Accel-Expires-Debug
T-Server
HA-Ipaddr
Ha-Gx-Prefs
Gh-Request-Id
L
L5d-Success-Class
Mail-Subject
Magicmarker
Lang
Gannett-Cam-Experience-Id
Fastly-SSL
CPC-Cache
CPC-Age
Candidate-Md5Url
DCR-Decision-By
DCR-Processing-Time-Ms
Fastly-GeoIP-CountryCode
Fastly-Backend-Name
MD5-Digest
Meta-Geo-Continent
VNS-Age
Vix-Hermes-Req-Id
True-Client-Country-4JS
VNS-Cache
W
X-A-Ccd
X-A
We-Hiring
Surrogated-Key
Sslversion
Ngx.Var.Host
NGB
N-Cache
Odigeo-Trace-Id
Redirect-Candidate
Server-Host
Rendered-Blocks
X-A-Dam
X-Destination
X-Rojux
X-Restarts
X-Request-Host
X-S-Cookie
X-ScT
X-Shop-Environment
X-SD-PageType
X-Reqid
X-RateLimit-Remaining-Second
X-Optimistic-Header
X-Nyt-Route
X-Orig-Expires
X-Origin-Time
X-RateLimit-Limit-Second
X-Policy
X-Slack-Backend
X-Slack-Shared-Secret-Outcome
X-Wikidot-Backend
X-We-Are-Hiring
X-Wikidot-Static-Cache
X-Worker
Xc-Version
X-Xfnlog-Site
X-Vtex-Remote-Cache
X-Viewer-Country
X-Tenant
X-SRCache-Key
X-Var-Ttl
X-Vdms-Path
X-VG-WebCache
X-Vdms-Version
X-Mvc-Supplant-Cachable
X-JWT-State
X-D
X-Csrf-Jwt
X-Date
X-Debug-Cache-Fetch
Canary
X-Debug-Cache-Store
X-Conf
X-Cms-Context
X-CacheTTL
X-Cache-NE
X-Cdn-Diag
X-CF-Lambda-Fn
X-CGP
X-CF-Lambda-Version
X-Developer
X-Dispatcher-Number
X-GeoIP-Region-Code
X-GeoIP-Country-Code
X-Has-Esi
X-IPLB-Instance
X-Is-Gdpr
X-IPLB-Request-ID
X-Gdpr
X-Forwarded-Path
X-Ec-Fail
X-Ec-Custom-Error
X-Ec-GeoHdr
X-Epic-Correlation-Id
X-External-Request-Id
X-Eu-Site
X-Cache-Info
X-Cache-Type
ServedBy
X-Presslabs-Stats
BehaviorPad-Version
WP-Super-Cache
Apigw-Requestid
Cache-Name
X-Geo-Header
X-Generated-On
X-Fastly-Backend
X-Esi-Check
X-Datadome
X-Gzip
X-FC-Vary-Parameters
X-Fmm-Version
X-Hash
X-NGENIX-Cache
X-Nitro-Cache
X-No-Session
X-Mid
X-Loc
X-INCAP-ABP
X-Level-Front-Cache
X-Human
X-DefHash
X-Bip
X-BYPASS-REASON
X-Cache-Bucket
X-BBC-Edge-Cache-Status
X-Auto-Login
X-Accel-Buffering
X-Alternate-Cache-Key
X-ApacheServer
X-Cache-Debug
X-Cache-Id
X-Core-Value
X-DefElseHash
X-Node-Id
X-Core-Mission
X-CMSURLCustom
X-Cdn-Origin
X-Clara-WADP
X-Clientip
X-DPWN-IS-SECURE
X-Owner
X-Up
X-Variation
X-Varnish-CookieHashed-On
X-Tx-Id
X-Thinkindot-L3
X-SVT-ORM-VERSION
X-Test
X-Thanos
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
X-Wix-Viewer-Type
Cache-Hits
Origin-Agent-Cluster
X-WADP-Cache
X-VServer
X-Varnishpool
X-VG-TLSProxy
X-Vmg-Version
X-SVT-ORM-RULES
X-Storefront-Renderer-Rendered
X-ProxyCache-Key
X-ProxyCache-Status
X-Qloud-Router
X-Pool
X-Platform
Web-Mar-Region
X-PAYTM-SRV-ID
X-PERF
X-Refresh
X-Request-Time
X-Sn-Servicetimems
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Shopify-Stage
X-ShopId
X-S-Maxage
X-Server-IP
X-ShardId
X-Org
X-Mly-Id
Host-ID
Hostname
Adler-Geo
AKAMAI
Expect-Staple
Thinkindot-CacheControl-Type
Is-Eu
Machine
Thinkindot-Control
Thinkindot-CacheControl
TDXMobile
Memcached
Origin
Environment
Platform
Release
Cmstype
Req-Svc-Chain
Cf-Device-Type
Datacenter
Cmsid
Producers
X-Correlation-ID
X-TIME
X-LJ-Flow-ID
X-Device-Os
Server-Hostname
NM-Fastcgi-Cache
Sever-Int
X-Dispatcher-Server
X-GeoIP
AMP-Access-Control-Allow-Source-Origin
X-From
Server-Ext
X-Irp-Debug
X-Origin-Response-Time
CloudFront-Viewer-Country
Country-Code
Apple-News-Services-Request-Url
DSUID
X-VWS-Id
X-WA-Info
X-Vcl-Version
X-NodeID
CDCHOST
Esi-Enabled
Apple-News-Services-Parsed-Url
X-Old-Content-Length
X-Nginx-Cache-Key
X-Nananana
X-Origin
X-Cluster
Apple-News-Services-Host
Apple-News-Services-Handled
X-Scale
X-Mvc-Supplant-OutputCached
X-PHP-Backend
X-App-Name
X-Cdn-Srv
X-AWS-Id
X-Akamai-Device-Characteristics
User-Cache-Control
X-Block-Status
X-NCache
X-Op-Id-All
X-Cache-Enabled
X-LB-NoCache
Pics-Label
X-Gen-Mode
Origin-EX
X-Hnp-Log
X-Instance-Name
Origin-CC
X-B3-Spanid
X-Proxy-Cache-Status
Wxu-Next-Hostname
Server-Info
X-Cache-Status-Check
Wxu-Next-Commit
X-Forwarded-Site
Wxu-Next-Region
X-Section
C-Via
Ssr
X-Access
X-API-Version
Time
Memory
X-TIM-N
X-Amz-Meta-Cb-Modifiedtime
Server-ID
X-Dc
X-CACHE-GROUP
X-Via-Fastly
NGX
X-HA-Backend
X-Micro-Cache
X-Cs
X-Air-Hostname
X-Internal-Host
X-FTR-Request-ID
X-Air-Source
X-Air-Trace-Id
X-Tb-Optimization-Total-Bytes-Saved
X-Wp-Cf-Super-Cache-Active
X-AB
X-Azure-Ref-OriginShield
X-Varnish-Beresp-Grace
X-Platform-Cluster
X-Platform-Router
X-Platform-Processor
X-Varnish-Beresp-Ttl
X-Vgn-Hpd-Reason
Cdn-Requestid
X-ZONE
X-Webkit-Csp-Report-Only
X-Zone
X-Geo-Region
GeoIP-Latitude
Location
X-Buckets
X-Web-Node
Cache-Host
X-Fpc
X-Microcachable
X-B3-Parentspanid
IsBot
X-SIPLIST1
X-Origin-Expires
X-Accel-Version
X-TraceId
X-WP-CF-Super-Cache-Active
Sid
X-DC
X-Github-Request-Id
XM
X-Backend-Instance
X-VarnishDD-TTL
Uri
X-DataCenter
X-Pod-Name
PFcat
X-HN
X-Is-Tablet
X-Is-Desktop
X-Browser-Name
X-Is-Supported-Browser
X-Tcp-Rtt
X-Is-Mobile
X-Ad-Defer-Variation
CF-Ctrl
Resin-Trace
YJS-ID
X-Info
User-Agent
X-LiteSpeed-Cache-Control
X-TA-CDN-Provider
X-FL-EDGE
A
X-Via-SSL
Locid
X-Cached-By
X-Site-Version
Edge-Copy-Time
X-Via-Edge
X-Via-CDN
X-FL-QIT-DEBUG
X-Locale
Srvid
True-Client-Ip
X-Nitro-Rev
X-Nitro-Cache-From
X-NGINX-Cache
GeoIP-Country-Code
Cdn
X-Moov-Xdn-Version
X-Contensis-Viewer-Groups
X-FireWall-Port
X-ATG-Version
X-Hyper-Cache
Epwk-X-Cache
X-Moov-T
X-Cache-ASPX
GeoIp-Country-Code
X-VCache
X-Frame-Option
X-CS
X-Varnish-Authentication
XServer
Cache-Key
X-CSRF-TOKEN
X-NewRelic-App-Data
SID
X-MSEdge-Features
X-Webstats-RespID
X-Service
True-Client-IP
X-MSEdge-Flight
X-Datacenter
X-Upstream-Ct
X-Upstream-Ht
X-Geo
X-TRACE-ID
NtCoent-Length
X-Platform-Server
State
X-FPC
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-HS-Content-Campaign-Id
X-VC
Fastly-Drupal-Html
X-Origin-Cache-Key
X-Planisys-CDN-Cache
Path
Tcn
X-HostName
LB
X-Vgn-Hpd-Variations-Key
X-Vgn-Hpd-Ssi
Cdn-Request-Time
X-SRV
X-Vgn-Hpd-Cached
X-Edge-Server
X-LiteSpeed-Tag
Cdn-Host
X-FTR-Cache-Status
X-FTR-Expires
X-Release
X-FTR-Balancer
X-FTR-Backend-Server
X-Vercel-Cache
X-Vercel-Id
X-Fastly-Cache
X-FTR-Backend
X-Country-Code-Real
CountryCode
X-APP-VERSION
X-Api-Version
Cf-Ipcountry
X-NMSegId
X-Generated-In
Req-ID
X-Sigma-Backend
X-Pad
M-TraceId
WZWS-RAY
Lb
Cdnsip
X-Rocket-Build-Number
X-AK-Request-ID
X-Esi
X-Cache-Remote
X-Sigma
X-Amz-Meta-Opti
Cdncip
X-Air-Pt
X-Cdn-Request-ID
X-Ad-Load-Variation
Cluster
X-Branch-Name
Cache
X-Traceid
X-Wp-Cf-Super-Cache
X-Wp-Cf-Super-Cache-Cache-Control
WebServer
X-Provided-By
X-HS-Status
X-UA
X-Cache-Ttl
X-WP-CF-Super-Cache-Cookies-Bypass
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-Scope-Id
Proxy-Connection
X-Scheme
X-Proxy-CacheRZ
X-NWS-UUID-VERIFY
Content-Script-Type
Content-Style-Type
Yak-Timeinfo
Pramga
X-Request-Start
X-M-Log
X-M-Reqid
X-Gamma-Serve
X-GoCache-CacheStatus
XkeyRZ
X-GeoIP-City
X-RN-RSRV
X-CACHE-KEY
CDN
X-Akamai-Pragma-Client-IP
Geoip-Latitude
X-Qnm-Cache
X-Cdn-Cache-Status
X-Varnish-Beresp-Status
X-Cdn-Forward
X-Tim-N
X-Shield-Cache-Expires
X-Vc
Srv
X-Lb-Cache
Edge-Cache
Server-Id
Env
Ngx
Ohc-File-Size
X-Request-URI
CF-Cached-On
X-Ha-Backend
X-Cache-Date
X-TT-LOGID
Serverid
X-Udemy-Cache-App-Namespace
X-User
X-CF-Cache-Header-Cache-Control
X-TH-Server
X-Render-Time
X-CUA
X-CF-Cache-Header-Vary
X-EC-Lua
X-Acquia-Application-Trace
X-Acquia-Site
X-Acquia-Application-UUID
Kp-EeAlive
X-Via-Ucdn
X-Dw-Trace-Id
X-Acquia-Purge-Tags
X-Edge-POP
X-VCL-Version
X-Lb-Nocache
PICS-Label
Yjs-Id
X-Snapshot-Date
X-Mobile-URL
X-Fastly-Cache-Hits
Inserted-Into-Cache-At
Cache-Tv-Group
CACHE-MISS-TO-ORIGIN
X-Litespeed-Cache-Control
X-Edge-Pop
Cneonction
X-Iauth-Set-Uid
X-Miniprofiler-Ids
X-Location
Log-Origin
X-Cached-Since
X-ElasticPress-Query
X-RAMCache
X-MiniProfiler-Ids
Vha6-Origin