Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
Pragma
X-Powered-By
X-XSS-Protection
CF-RAY
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
P3P
X-Cache-Hits
X-UA-Compatible
Alt-Svc
X-Xss-Protection
X-Served-By
X-Download-Options
CF-Ray
X-Timer
X-Request-Id
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
Access-Control-Allow-Credentials
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
X-Drupal-Cache
X-Generator
X-Cache-Status
X-Check
X-Envoy-Upstream-Service-Time
X-Cacheable
X-Request-ID
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Dns-Prefetch-Control
X-FRAME-OPTIONS
X-Iinfo
X-Drupal-Dynamic-Cache
Feature-Policy
X-Content-Security-Policy
Content-Encoding
Access-Control-Expose-Headers
Upgrade
Status
X-CDN
X-AspNetMvc-Version
X-XSS-PROTECTION
Server-Timing
Access-Control-Max-Age
X-Amz-Request-Id
Request-Context
X-Amz-Id-2
X-Turbo-Charged-By
X-AH-Environment
X-Via
X-Robots-Tag
X-Backend
X-Cache-Group
Cf-Edge-Cache
Host-Header
X-Proxy-Cache
Keep-Alive
X-Hacker
X-Server
X-Rq
X-Age
X-Server-Powered-By
X-Vhost
Allow
X-UA-Device
X-Varnish-Cache
X-Ws-Request-Id
EagleId
X-Dispatcher
X-Amz-Version-Id
Grace
Cf-Apo-Via
P3p
X-LiteSpeed-Cache
Nel
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Page-Speed
X-Device
Cf-Railgun
X-Swift-SaveTime
X-Swift-CacheTime
EagleEye-TraceId
X-Aws-Lambda-Call-Status
Ali-Swift-Global-Savetime
X-Pingback
X-WebKit-CSP
X-Node
X-Host
Accept-CH
X-Server-Id
X-OneAgent-JS-Injection
Surrogate-Control
X-Backend-Server
X-CST
X-Readtime
X-Nginx-Cache-Status
X-Akam-SW-Version
X-Content-Security-Policy-Report-Only
Request-Id
Permissions-Policy
X-Application-Context
X-Cache-Lookup
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Nginx-Upstream-Cache-Status
X-Cloud-Trace-Context
Accept-Ch-Lifetime
X-Trace
X-Response-Time
X-Edge
X-HW
X-Litespeed-Cache
X-Ua-Compatible
X-Mod-Pagespeed
Content-Location
X-Url
X-Clacks-Overhead
X-Ruxit-JS-Agent
Accept-CH-Lifetime
X-Midtier
X-ECACHE
X-Mcache
X-ESI
X-Amz-Server-Side-Encryption
X-Country
X-Oneagent-Js-Injection
Rating
X-Upstream
X-PC
X-Vname
X-TtlSet
X-Vcap-Request-Id
X-MS-InvokeApp
Cache-Tag
X-Rack-Cache
X-D2id
Xkey
X-Content-Type
Accept-Ch
Fastly-Restarts
X-Element-Page-Cache
X-Cache-TTL
Verso
X-Cdn-Fetch
X-GoogleNews-Bot
X-Kinja-Revision
X-Kinja-Server
X-Exp-Id
X-Kinja-Build
X-Use-Magma
X-Kinja
X-Exp-Variant
RTSS
Edge-Control
X-Powered-By-Plesk
X-WebKit-CSP-Report-Only
X-VARITI-CCR
X-Cached
Origin-Trial
X-Ac
X-Navigation-Version
X-Abt-Application-Version
X-Goog-Hash
X-Ua-Device
Service-Worker-Allowed
X-GitHub-Request-Id
X-Ruxit-Js-Agent
X-Amz-Rid
X-Country-Code
Display
X-Sol
X-Middleton-Display
Pagespeed
X-Mg-S
X-Ttl
X-Dw-Request-Base-Id
X-SharePointHealthScore
SPRequestGuid
X-Browser-Type
X-Varnish-TTL
X-Server-Name
Arr-Disable-Session-Affinity
X-B3-TraceId
Cross-Origin-Opener-Policy
X-Erf-Bev-Bev-Is-Generated
X-Instrumentation
X-Erf-Bev-Bev
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
AR-Request-ID
AR-PoweredBy
X-Powered-CMS
AR-SID
AR-ATIME
SPRequestDuration
SPIisLatency
X-Middleton-Response
Response
X-Amzn-Trace-Id
AR-CACHE
X-Cache-Key
X-NF-Request-ID
X-Fastly-Request-ID
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Cnection
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-Times
X-HP-Webp
X-HP-Trace-Id
X-Jurisdiction
X-Version
X-Accel-Expires
Front-End-Https
X-T
Cache-Status
X-Ser
X-Fastcgi-Cache
Cache-Tags
Edge-Cache-Tag
X-Px
X-Webkit-Csp
X-MSEdge-Ref
X-Pinterest-Rid
Pinterest-Generated-By
Pinterest-Version
Public-Key-Pins
X-Client-IP
X-Hits
Nginx-Cache
X-Recruiting
X-RateLimit-Remaining
X-Shield-Request-Id
Mrf-Cache-Status
MRF-Tech
X-B3-TraceId-Primal
Access-Control-Request-Method
X-Request-Received
X-Request-Processing-Time
X-LLID
X-Frontend
X-Ua-Browser
Server-Node
X-B3-Traceid
X-NWS-LOG-UUID
Payment
TP-Cache
X-DIS-Request-ID
X-HS-Hub-Id
X-HS-Cache-Config
TP-L2-Cache
S
X-HS-Combine-CSS
X-HS-Content-Id
MicrosoftSharePointTeamServices
X-Content-Digest
X-LB-Cache
X-Goog-Metageneration
X-Distributor
X-Correlation-Id
Realpath
Content-MD5
X-Forwarded-For
X-RateLimit-Limit
X-Request-Handler-Origin-Region
X-Microsite
X-Envoy-Decorator-Operation
X-Geo-Country
X-Page-Id
Access-Control-Allow-Method
X-Ezoic-Cdn
X-FastCGI-Cache
X-FB-Debug
Fastcgi-Cache
X-Cluster-Name
X-PressLabs-Stats
Accept-Charset
X-Hostname
X-Erf-Stays-Pdp-Viaduct-Migration-Web
X-Rid
X-GUploader-UploadID
X-Seen-By
X-TEC-API-ROOT
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-Ratelimit-Remaining
X-Protected-By
X-Kinja-CCPA
X-Amz-Apigw-Id
X-Amzn-RequestId
Cleartype
TCN
X-Origin-Server
X-Newrelic-App-Data
DC
X-B3-Sampled
X-Ratelimit-Limit
X-Webkit-CSP
X-TTL
X-XRDS-Location
X-Webkit-CSP-Report-Only
X-Debug-Info
X-Origin-Cache
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-Mobile
X-Logged-In
Referer-Policy
X-Git-Hash
X-Varnish-Backend
X-Kinsta-Cache
X-Edge-Location-Klb
X-Azure-Ref
Alternate-Protocol
Cross-Origin-Resource-Policy
Healthy
X-Varnish-Grace
X-Contextid
X-Revision
X-App-Environment
Surrogate-Key
X-Fb-Rlafr
X-Aspnet-Version
X-Providence-Cookie
X-Request-Guid
X-Route-Name
X-Is-Crawler
X-Aspnet-Duration-Ms
X-Flags
X-Amz-Replication-Status
X-Grace
X-Amz-Meta-S3cmd-Attrs
X-TT
X-Server-ID
Count-Hit
X-Wix-Request-Id
Filterid
X-Whom
X-Content-Options
X-Forwarded-Proto
MS-Author-Via
X-IPS-LoggedIn
Charset
X-Akamai-Edgescape
Viewport
X-Client-Ip
X-Id
Frame-Options
WPO-Cache-Status
WPO-Cache-Message
X-App-Server
Paypal-Debug-Id
X-B
X-Hosted-By
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Trace-Id
X-Az
X-Cache-Control
X-AppVersion
X-Www-Served-By
X-Activity-Id
X-Backend-Name
X-Cache-Age
X-Magnolia-Registration
X-Daa-Tunnel
Retry-After
Refresh
X-Upgrade-Enabled
Server-Name
Section-Io-Cache
Version
Amp-Access-Control-Allow-Source-Origin
X-Varnish-Server
X-Type
X-Proxy
X-F-Cache
X-Proxy-Cache-Info
X-ARC
X-Http-Reason
X-Original-Request-Id
X-Response-Served-From
X-Rule
Host
X-EdgeConnect-Cache-Status
SD-X-WS
Akamai-GRN
X-Akamai-Request-ID2
X-User-Agent
X-UUID
X-Load-Cache
X-Rocket-Nginx-Serving-Static
Protected
X-Cache-Rule
X-Status
X-App-Version
Front
X-Edge-Location
X-Varnish-Age
X-L-Path
X-Cache-Grace
X-Region
X-Jobs
VIX-Pulpo-Upstream-Status
X-Cacheable-TTL
X-Environment-Context
X-Framework
X-Instance
X-Is-Bot
X-Rendered-As
VIX-Pulpo-Node
X-FW-Hash
X-FW-Server
X-Unique-Id
X-FW-Serve
Fastly-SIE
X-Source
X-FW-Static
X-Oracle-Dms-Ecid
X-FW-Type
X-FW-Version
X-FW-Dynamic
Fastly-SWR
From-Origin
Access-Control-Request-Headers
X-Page-View
X-N
X-Cache-Time
X-ProcessESI
X-RemovedCookies
X-Adobe-Content
X-Tumblr-User
X-Adobe-Loc
X-Oracle-Dms-Rid
X-Tumblr-Pixel
X-Time
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-G
SRV
X-COUNTRY
Content-Disposition
ServerID
X-Varnish-Ttl
X-Drupal-Cache-Tags
Country
X-HTML-Minification-Powered-By
X-Datadog-Trace-Id
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Language
X-CDN-Forward
Accept-Language
Liferay-Portal
X-Vcache
X-DynaTrace
X-DataDome
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Datadog-Sampled
X-Amzn-Remapped-Content-Length
X-RateLimit-Reset
Countrycode
X-DynaTrace-JS-Agent
X-Debug-IsPreview
X-B3-SpanId
X-Debug-IsConnected
X-Mg-Request-UUID
X-ID
X-Generated-By
Xet-Cookie
X-Drupal-Cache-Contexts
Backend
X-Ratelimit-Reset
X-Device-Type
X-NYM-Debug-Backend
X-Content-Powered-By
X-WP-CF-Super-Cache
CF-IPCountry
X-WP-CF-Super-Cache-Cache-Control
X-ECache
X-Mode
Webserver
Xserver
X-Nginx-Cache
X-Zen-Fury
X-B-Cache
X-Tt-Logid
X-Signature
GEO-INFO
X-Erf-Web-Scheduler
X-Content-Age
X-Httpd
X-ServerID
X-Urbn-Context-Path
X-Storage
X-Director
X-Varnish-Cache-Hits
X-Urbn-Site-Id
X-Sucuri-ID
X-UPSTREAM-Address
X-Sucuri-Cache
X-Cache-Action
Azure-Version
Filters
Load-Balancing
Azure-SlotName
Azure-SiteName
X-Servername
Azure-InstanceId
Azure-RegionName
X-LAGOON
Locale
X-Rewrite-Enabled
Url
S-Rt
X-JoinUs
Meta-Geo
Onion-Location
X-SaId
X-Tb
X-Say-Cacheable
X-Cache-Operation
X-Proto
X-Varnish-Hostname
X-Say-TTL
X-SayCDN-TTL
X-Cache-Server
X-Git-Commit
X-Container-Uri
X-Soup
X-VCT
X-Cluster-Node
Uber-Trace-Id
X-Served-From
X-VC-Cache
X-RM-Cache-TTL
X-Generation-Time
X-Forwarded-Host
X-Detected-As
X-Labrador-Cache-Channel
X-Logging-Id
X-Ms-Version
X-Ms-Request-Id
X-PHP-Host
Web-Mar-Node
X-Xrds-Location
X-XRDS-LOCATION
X-Uri
X-Adobe-Source
X-Zipkin-Id
Webcakes-Region
X-Proxied
Property-Id
X-Skip-Cache
TWC-Privacy
X-Origin-Hint
Node
X-Sql-Duration-Ms
CDN-RequestId
Fastcgi-Useragent
X-GeoCountry
TWC-GeoIP-LatLong
TWC-Locale-Group
X-GeoCode
X-Extlb
TWC-GeoIP-Country
Webcakes-App-Name
X-Routing-Service
X-Sql-Count
TWC-Connection-Speed
TWC-Device-Class
Webcakes-App-Version
Mn-Server-Ip
X-Debug
X-R9-Blue-Green-Version
X-Nf-Request-Id
X-Proxy-Build
X-Timing-Wait
DB-Nickname
X-RCS-CacheZone
X-FB-TRIP-ID
X-LSADC-Cache
Selected-Fe
X-Tumblr-Pixel-2
X-Tumblr-Pixel-3
X-Via-JSL
X-NGENIX-Cache
X-Fetched-On
X-Format
X-Cache-Expired-At
X-Origin-Date
X-MP-GENERATED-AT
X-Lambda-Id
Source
Fastly-Drupal-HTML
OT-Force-Account-Verify
X-Cache-Hit
X-Node-Name
X-MCACHE
Content-Secure-Policy
X-AIR-PT
X-Varnish-Hits
X-UA-Device-Type
X-Cache-TTL-Remaining
X-Tec-Api-Origin
X-Tec-Api-Version
X-Template
X-Tec-Api-Root
X-Pass-Why
X-Loop
X-Tncms
X-Ua
X-Pubstack
X-Endurance-Cache-Level
NGB
X-PHP-Backend
X-Srv
Upgrade-Insecure-Requests
X-Server-W
Cross-Origin-Window-Policy
X-Redis-Cache
X-Fastly-Request-Id
X-Real-IP
MS-CV
X-RTag
X-Origin-CC
X-Origin-TTL
Cache-Hits
Ms-Operation-Id
X-Cache-Host
Cache-Name
X-CCDN-CacheTTL
X-Hcs-Proxy-Type
X-GEO
X-CCDN-Origin-Time
X-Xfnlog-Site
X-Reqid
X-Cms-Context
Section-Io-Id
X-IPLB-Instance
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
X-IPLB-Request-ID
Section-Io-Origin-Status
X-Optimistic-Header
Apigw-Requestid
X-Akamai-Transformed
Cache-Provider
X-Cache-Type
X-Restarts
CDN-Uid
X-S
X-BYPASS-REASON
CDN-RequestPullSuccess
CDN-RequestCountryCode
CDN-CachedAt
CDN-EdgeStorageId
CDN-PullZone
CDN-Cache
CDN-RequestPullCode
X-CACHE-AGE
X-ProxyCache-Status
X-No-Session
X-ProxyCache-Key
X-Hl-Ver
X-AWS-Id
X-CSRF-Token
X-Via-Fastly
X-Cluster
X-VWS-Id
X-LJ-Flow-ID
X-Presslabs-Stats
X-Aspnetmvc-Version
X-Proxy-Cache-Status
X-Datadome
X-Access
X-Section
X-Debug-Cache-Fetch
X-Debug-Cache-Store
Gannett-Cam-Experience-Id
X-Developer
X-Dispatcher-Number
X-Destination
X-Policy
Sslversion
Server-Host
X-Ec-GeoHdr
Surrogated-Key
X-Ec-Custom-Error
X-Orig-Expires
T-Server
Fastly-GeoIP-CountryCode
X-Ec-Fail
X-Origin-Time
X-RateLimit-Limit-Second
X-Eu-Site
Candidate-Md5Url
X-GeoIP-Region-Code
X-GeoIP-Country-Code
Canary
X-Forwarded-Path
Mail-Subject
Magicmarker
Lang
L5d-Success-Class
DCR-Decision-By
DCR-Processing-Time-Ms
HA-Ipaddr
X-Gdpr
CPC-Cache
L
CPC-Age
MD5-Digest
BehaviorPad-Version
X-Mvc-Supplant-Cachable
X-External-Request-Id
X-RateLimit-Remaining-Second
Ha-Gx-Prefs
X-Epic-Correlation-Id
X-Nyt-Route
Redirect-Candidate
Gh-Request-Id
X-Fastly-Backend
N-Cache
Meta-Geo-Continent
X-Irp-Debug
X-FC-Vary-Parameters
Odigeo-Trace-Id
Ngx.Var.Host
Rendered-Blocks
X-Rojux
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-Tenant
X-Wikidot-Backend
X-Application
X-We-Are-Hiring
X-SRCache-Key
X-Wikidot-Static-Cache
X-Accel-Expires-Debug
X-A-Wwc
X-Date
X-Aed
X-CGP
X-Vtex-Remote-Cache
X-B-Cookie
X-Cache-Bucket
X-Vdms-Path
X-CacheTTL
X-Cache-NE
X-Cache-Info
X-Cdn-Diag
X-Bl-Debug
X-Vdms-Version
X-Bc-Bl
X-BCube-Filmed-By
X-TIM-N
X-Var-Ttl
X-Slack-Shared-Secret-Outcome
Xc-Version
X-Web-Node
X-Conf
X-A
We-Hiring
X-S-Cookie
VNS-Cache
X-ScT
W
Web-Mar-Region
X-Csrf-Jwt
X-Slack-Backend
X-A-Ccd
X-SD-PageType
X-Request-Host
X-A-Dcw
X-D
X-Shop-Environment
VNS-Age
Fastly-Backend-Name
X-A-Dgt
X-A-Dam
X-Handled-By
WP-Super-Cache
TDXMobile
Thinkindot-CacheControl
X-Generated-On
Thinkindot-Control
X-Cache-Debug
Thinkindot-CacheControl-Type
Host-ID
X-Bip
X-App-Name
X-Esi-Check
X-Clara-WADP
Origin
X-Clientip
Release
X-Accel-Buffering
X-CMSURLCustom
Req-Svc-Chain
X-Alternate-Cache-Key
X-Auto-Login
Machine
X-BBC-Edge-Cache-Status
X-Core-Value
X-Core-Mission
X-Fmm-Version
Memcached
X-Forwarded-Site
X-Mly-Id
X-Request-Time
X-Cache-Id
X-Pool
X-S-Maxage
Vix-Hermes-Req-Id
X-Server-IP
X-Vcl-Version
X-Platform
X-PAYTM-SRV-ID
X-Org
X-Old-Content-Length
X-Viewer-Country
X-VG-WebCache
X-Owner
X-Rn-Rsrv
X-ShardId
X-ShopId
X-WADP-Cache
X-Test
X-Thanos
X-Thinkindot-L3
X-Newrelic-Synthetics
X-Up
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-Sorting-Hat-PodId
X-Shopify-Stage
X-Sorting-Hat-ShopId
X-Worker
X-Storefront-Renderer-Rendered
X-Wix-Viewer-Type
X-Node-Id
X-Origin-Response-Time
X-Mid
X-JWT-State
X-Gzip
X-Hash
Cmstype
X-Has-Esi
Cmsid
Datacenter
X-Varnishpool
AKAMAI
X-Is-Gdpr
X-Level-Front-Cache
Environment
X-INCAP-ABP
X-Geo-Header
X-Human
User-Cache-Control
X-TIME
X-Hnp-Log
X-Varnish-CookieHashed-On
X-Scale
X-ApacheServer
X-Block-Status
X-Sn-Servicetimems
X-WA-Info
X-Cdn-Srv
X-Azure-Ref-OriginShield
X-VServer
X-Cdn-Origin
DSUID
Country-Code
X-Gen-Mode
X-Variation
CloudFront-Viewer-Country
X-From
Is-Eu
CDCHOST
X-PERF
ServedBy
Fastly-SSL
Server-Ext
Server-Hostname
X-Dispatcher-Server
X-DPWN-IS-SECURE
True-Client-Country-4JS
X-Varnish-Remaining-TTL
Producers
Platform
X-Nginx-Cache-Key
X-Nananana
X-Mvc-Supplant-OutputCached
Sever-Int
X-Loc
X-DefElseHash
X-DefHash
X-Qloud-Router
X-Vmg-Version
Adler-Geo
X-Varnish-CookieINHashed-On
X-VG-TLSProxy
X-Device-Os
X-Origin
Expect-Staple
Esi-Enabled
NM-Fastcgi-Cache
X-Cs
X-Air-Hostname
X-Air-Source
X-Air-Trace-Id
X-NodeID
X-Instance-Name
X-Op-Id-All
X-NCache
Apple-News-Services-Handled
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
X-GeoIP
X-Akamai-Device-Characteristics
Ssr
X-App
X-TA-CDN-Provider
X-Cache-Status-Check
Wxu-Next-Hostname
Wxu-Next-Commit
Wxu-Next-Region
Pics-Label
C-Via
Origin-EX
X-Parent-Response-Time
Origin-CC
Cache-Host
Server-Info
X-Microcachable
X-Refresh
X-Locale
X-Site-Version
X-LB-NoCache
X-Nitro-Cache
X-Amz-Meta-Cb-Modifiedtime
X-Cache-Enabled
AMP-Access-Control-Allow-Source-Origin
X-Platform-Processor
X-HA-Backend
X-Platform-Cluster
X-Platform-Router
Memory
Time
XM
Server-ID
X-Origin-Expires
X-Tx-Id
PFcat
X-HN
X-VarnishDD-TTL
NGX
X-TimeS
X-ZONE
Resin-Trace
X-VHOST
X-API-Version
X-Dc
Locid
Hostname
X-Via-Edge
A
Edge-Copy-Time
X-Ad-Defer-Variation
X-Via-SSL
X-FL-QIT-DEBUG
Srvid
X-CACHE-GROUP
GeoIP-Latitude
X-Via-CDN
X-FL-EDGE
X-Upstream-Ht
X-Upstream-Ct
X-Tb-Optimization-Total-Bytes-Saved
X-DC
Cf-Device-Type
Origin-Agent-Cluster
X-Varnish-Beresp-Grace
X-Correlation-ID
X-Wp-Cf-Super-Cache-Active
YJS-ID
X-ATG-Version
X-FireWall-Port
X-Varnish-Beresp-Ttl
X-Zone
X-Webkit-Csp-Report-Only
Sid
X-Fpc
X-Contensis-Viewer-Groups
X-Vgn-Hpd-Reason
Cache-Key
X-Cache-ASPX
X-Internal-Host
X-Varnish-Authentication
Uri
Cdn-Requestid
X-Cached-By
X-LiteSpeed-Cache-Control
X-WP-CF-Super-Cache-Active
X-DataCenter
X-Moov-T
X-Pod-Name
X-Github-Request-Id
X-Moov-Xdn-Version
X-Provided-By
X-Micro-Cache
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Planisys-CDN-Cache
State
X-HS-Content-Campaign-Id
User-Agent
X-RN-RSRV
X-Fastly-Cache
X-Platform-Server
True-Client-Ip
X-Info
X-TraceId
X-URL
X-B3-Spanid
X-Rocket-Build-Number
X-SIPLIST1
X-Release
X-Cache-Remote
X-Sigma-Backend
IsBot
X-B3-Parentspanid
X-LiteSpeed-Tag
X-Sigma
GeoIp-Country-Code
X-VC
Location
X-Buckets
X-Nitro-Rev
Cache
GeoIP-Country-Code
X-Nitro-Cache-From
X-AB
X-NGINX-Cache
SID
X-VCache
X-Api-Version
X-Backend-Instance
X-CS
Tcn
True-Client-IP
X-CSRF-TOKEN
X-Datacenter
X-MSEdge-Features
X-Gamma-Serve
X-MSEdge-Flight
Cdn
Srv
Cache-Tv-Group
X-Geo-Region
X-Accel-Version
X-Generated-In
XServer
Lb
X-HostName
X-GeoIP-City
X-HS-Status
X-Vgn-Hpd-Variations-Key
NtCoent-Length
X-Vgn-Hpd-Ssi
CF-Ctrl
Fastly-Drupal-Html
X-Vgn-Hpd-Cached
HostName
X-Geo
Path
X-TRACE-ID
Kp-EeAlive
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-FPC
X-FTR-Request-ID
X-Scheme
X-CACHE-KEY
X-SRV
CountryCode
X-Browser-Name
X-Location
X-Frame-Option
X-Is-Desktop
X-Is-Tablet
X-Tcp-Rtt
X-TX-ID
X-Is-Supported-Browser
X-Is-Mobile
X-Mobile-URL
X-NewRelic-App-Data
X-Region-Sid
On-Server
X-Developers
X-GoCache-CacheStatus
X-Men
Epwk-X-Cache
X-Hyper-Cache
Ohc-File-Size
CacheControlHeader
X-Aicache-OS
X-APP-VERSION
Serverid
X-UA
Cf-Ipcountry
X-B3-Trace-ID
X-Air-Pt
X-Acquia-Purge-Cdn-Unconfigured
X-CDN-Cache-Status
X-Cache-Tags
Click-Count-Action-Start
Tube-Got-Eval
X-AK-Request-ID
X-Esi
Cdnsip
Click-Count-Error
Tube-Get-Contents
RNT-Time
X-SB
Mime-Version
X-Minions-Version
X-Req
RNT-Machine
Cdncip
X-V-Cache
V-Age
X-Amz-Meta-Opti
X-Via-Poph
X-Via-Popn
X-Via-Popv
Tube-Return
Tube-Got-Results
X-Service
X-LB-ID
X-Cache-FS-Status
X-Guploader-Uploadid
X-EC-Lua
Proxy-Connection
WebServer
X-Wp-Cf-Super-Cache-Cache-Control
X-Branch-Name
X-Wp-Cf-Super-Cache
X-Cache-Ttl
X-Webstats-RespID
X-Proxy-CacheRZ
XkeyRZ
X-Pad
RATING
X-Traceid
WWW-Authenticate
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-Cdn-Forward
CDN
X-Cdn-Cache-Status
Geoip-Latitude
Env
WZWS-RAY
ENV
Yak-Timeinfo
X-Servedbyhost
X-Nc
X-Wa
Ohc-Cache-HIT
X-Edge-Pop
X-Vc
X-VCL-Version
X-Check-Cacheable
LB
CF-Cached-On
X-Processor
X-User
X-Akamai-Pragma-Client-IP
X-Fastly-Country-Code
X-Ckpd-Fst-Backend
X-TT-LOGID
X-TH-Server
X-NWS-UUID-VERIFY
Ngx
Server-Id
X-Lb-Cache
Content-Script-Type
Content-Style-Type
X-Ha-Backend
X-Lb-Nocache
X-CUA
X-Render-Time
Cdn-Host
X-Vercel-Id
Cdn-Request-Time
X-Edge-Server
X-Vercel-Cache
X-FTR-Backend
X-Via-Ucdn
X-FTR-Backend-Server
X-FTR-Balancer
X-FTR-Expires
X-Country-Code-Real
X-FTR-Cache-Status
X-NMSegId
X-Acquia-Application-UUID
PICS-Label
Edge-Cache
X-Acquia-Site
X-Acquia-Purge-Tags
Req-ID
M-TraceId
X-Acquia-Application-Trace
X-Response-By
X-Dw-Trace-Id
X-APP
X-WP-CF-Super-Cache-Cookies-Bypass
HIT
X-Edge-POP
X-Litespeed-Cache-Control
X-Snapshot-Date
X-MiniProfiler-Ids
X-IN-APIGATEWAYSSL
X-Cache-Date
X-Udemy-Cache-App-Namespace
X-IN-APIGATEWAY
Yjs-Id
X-Origin-Cache-Key
X-Miniprofiler-Ids
X-Iauth-Set-Uid
X-Ad-Load-Variation
X-Service-Response-Time
X-Serial
Cneonction
X-RAMCache
Log-Origin
X-Fastly-Cache-Hits
Inserted-Into-Cache-At
X-ServedByHost
Vha6-Origin
X-Cached-Since
X-Fastly-Backend-Reqs
X-Varnish-Beresp-TTL
CACHE-MISS-TO-ORIGIN
Sm-Log-Id
X-ElasticPress-Query
X-M-Reqid
X-M-Log
X-WA
X-NC
Hit