Threat Level: green Handler on Duty: Johannes Ullrich

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-Cache-Status
Link
Accept-Ranges
CF-RAY
ETag
Expect-CT
Pragma
X-Powered-By
X-XSS-Protection
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
Alt-Svc
X-Served-By
X-Xss-Protection
X-Download-Options
X-Timer
X-Request-Id
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Cache-Status
X-Generator
X-Cacheable
Timing-Allow-Origin
X-Content-Security-Policy
X-Iinfo
Feature-Policy
Status
X-Envoy-Upstream-Service-Time
Content-Encoding
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
X-CDN
X-AspNetMvc-Version
P3p
X-Request-ID
Upgrade
X-Via
CF-Ray
X-Ws-Request-Id
Access-Control-Max-Age
Server-Timing
EagleId
X-Cache-Group
X-Turbo-Charged-By
Keep-Alive
Request-Context
X-UA-Device
Report-To
X-Age
X-Proxy-Cache
X-Server-Powered-By
X-Backend
X-AH-Environment
X-Robots-Tag
X-Hacker
X-Amz-Request-Id
Host-Header
X-Server
X-Amz-Id-2
Grace
X-LiteSpeed-Cache
X-Rq
X-Varnish-Cache
X-Nginx-Cache-Status
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-WebKit-CSP
X-Page-Speed
X-Vhost
NEL
EagleEye-TraceId
X-OneAgent-JS-Injection
X-Amz-Version-Id
X-Ua-Compatible
X-Pingback
X-Dns-Prefetch-Control
X-Dispatcher
X-Device
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Cache-Spec
X-Host
X-Server-Id
Accept-CH
Cf-Railgun
X-Node
X-Backend-Server
X-Readtime
Surrogate-Control
X-Akam-SW-Version
Request-Id
X-Response-Time
X-HW
Xkey
X-Application-Context
Content-Location
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Rating
X-Ruxit-JS-Agent
X-Country
X-B3-TraceId
Accept-Ch-Lifetime
Accept-CH-Lifetime
X-Cache-Lookup
X-Cloud-Trace-Context
X-Trace
X-Url
X-Ac
X-Content-Type
X-PC
X-Vname
X-TtlSet
Allow
X-Varnish-TTL
X-Clacks-Overhead
X-Mod-Pagespeed
Edge-Control
X-ESI
X-Server-Name
Fastly-Restarts
Cache-Tag
X-Aws-Lambda-Call-Status
X-FastCGI-Cache
Service-Worker-Allowed
X-VARITI-CCR
X-Rack-Cache
X-Element-Page-Cache
Verso
X-Upstream
MS-Author-Via
X-Vcap-Request-Id
X-GitHub-Request-Id
X-MS-InvokeApp
X-Amz-Rid
Public-Key-Pins
X-Dw-Request-Base-Id
X-Cached
X-Client-IP
X-D2id
X-Abt-Application-Version
X-Cache-TTL
X-Cnection
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-Px
RTSS
X-Navigation-Version
X-Country-Code
Arr-Disable-Session-Affinity
X-Use-Magma
X-Exp-Id
X-Kinja-Revision
X-Exp-Variant
X-Cdn-Fetch
X-GoogleNews-Bot
X-Kinja
X-Kinja-Build
X-Kinja-Server
Access-Control-Request-Method
X-Powered-By-Plesk
X-Goog-Hash
X-NF-Request-ID
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-Instrumentation
X-Origin-Cache
X-Powered-CMS
AR-SID
AR-Request-ID
AR-PoweredBy
AR-CACHE
AR-ATIME
X-Middleton-Display
Pagespeed
Display
X-Sol
X-Version
X-Middleton-Response
Response
X-Amz-Server-Side-Encryption
X-LLID
X-MSEdge-Ref
X-Kinsta-Cache
X-Edge-Location-Klb
X-SRCache-Store-Status
Nginx-Cache
X-SRCache-Fetch-Status
Accept-Ch
X-Edge
X-TTL
X-RateLimit-Remaining
TCN
MRF-Tech
Mrf-Cache-Status
X-B3-TraceId-Primal
X-Protected-By
X-HP-Trace-Id
X-Jurisdiction
X-HP-Webp
X-T
X-Shield-Request-Id
X-Forwarded-For
X-Content-Security-Policy-Report-Only
X-Mg-S
X-Id
Content-MD5
S
X-Aspnetmvc-Version
Edge-Cache-Tag
X-CST
X-Language
Fastcgi-Cache
SPRequestDuration
SPIisLatency
X-Mid
Front-End-Https
Realpath
X-Recruiting
Pinterest-Version
X-Pinterest-Rid
Filters
Pinterest-Generated-By
X-DynaTrace
X-Request-Received
X-Request-Processing-Time
X-Ttl
X-MCACHE
Server-Node
X-Frontend
Server-Name
X-Ab
X-Ua-Browser
X-Content
X-Ser
X-NWS-LOG-UUID
X-Ruxit-Js-Agent
X-HS-Cache-Config
X-Yandex-Sdch-Disable
X-HS-Hub-Id
X-HS-Content-Id
X-Correlation-Id
X-HS-Combine-CSS
X-Ezoic-Cdn
X-Cache-Key
SPRequestGuid
X-SharePointHealthScore
X-Template
X-Hits
X-ECACHE
X-Parallel-Accel
Alternate-Protocol
Cache-Tags
X-Tt-Trace-Host
X-Tt-Trace-Tag
Fusion-Component-Id
Fusion-Source
MicrosoftSharePointTeamServices
Fusion-Content-Id
Fusion-Content-Source
Fusion-Deployment-Id
Fusion-Template-Id
Cleartype
Charset
X-Kong-Proxy-Latency
Host
X-Kong-Upstream-Latency
X-B3-Sampled
X-Page-Id
X-Git-Hash
X-Www-Served-By
X-Content-Options
X-Geo-Country
X-Daa-Tunnel
X-Debug-Info
X-DIS-Request-ID
X-Amzn-Trace-Id
X-Fastly-Request-Id
X-Hostname
X-Content-Digest
X-Ratelimit-Limit
X-Amz-Replication-Status
X-Varnish-Age
Filterid
X-XRDS-LOCATION
X-Activity-Id
X-Az
X-AppVersion
X-VCache
Cross-Origin-Opener-Policy
X-Accel-Expires
X-FB-Debug
X-Grace
X-Upgrade-Enabled
X-WebKit-CSP-Report-Only
X-N
X-Origin-Server
ServerID
X-Rid
X-Forwarded-Proto
X-Nginx-Upstream-Cache-Status
X-F-Cache
Access-Control-Allow-Method
X-Mobile-URL
TP-Cache
TP-L2-Cache
X-LB-Cache
X-Aspnet-Duration-Ms
X-Route-Name
X-Flags
X-Request-Guid
X-Providence-Cookie
X-Is-Crawler
X-Whom
X-TT
X-Varnish-Grace
X-Seen-By
X-Type
Viewport
X-App-Environment
X-Goog-Metageneration
X-GUploader-UploadID
X-Goog-Generation
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
Node
X-Tb
X-FW-Type
X-Server-ID
Paypal-Debug-Id
X-Distributor
X-FW-Static
X-FW-Serve
X-FW-Server
Payment
DC
X-FW-Dynamic
X-FW-Hash
X-User-Agent
X-App-Server
X-DataDome
Fastcgi-Useragent
X-Wix-Request-Id
Accept-Charset
Country
X-Cache-Control
X-NGENIX-Cache
X-Cache-Rule
X-Origin-Upstream-Status
X-Litespeed-Cache
X-Fastcgi-Cache
Version
X-Via-JSL
X-Logged-In
X-Ratelimit-Reset
X-Microsite
X-Request-Handler-Origin-Region
X-Tec-Api-Version
X-Tec-Api-Origin
X-Tec-Api-Root
X-Drupal-Cache-Tags
X-Fastly-Request-ID
Referer-Policy
X-Cluster-Name
X-Webkit-Csp
X-Cache-Age
X-Webkit-CSP
X-Signature
X-B-Cache
Refresh
X-Erf-Bev-Bev-Is-Generated
X-Buckets
Cache-Status
X-Erf-Bev-Bev
X-Browser-Type
X-Contextid
X-Varnish-Backend
SD-X-WS
X-Node-Name
X-Load-Cache
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Original-Request-Id
X-Response-Served-From
X-Real-IP
X-Mobile
X-Is-Bot
X-Cacheable-TTL
X-Rendered-As
Amp-Access-Control-Allow-Source-Origin
NGB
X-B
X-Jobs
Access-Control-Request-Headers
X-Debug
X-Page-View
X-Vgn-Hpd-Reason
X-Rule
X-Revision
X-Cache-Expired-At
X-Device-Type
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Proxy-Cache-Status
X-Proxy
X-ProcessESI
X-RemovedCookies
X-Instance
X-IPLB-Instance
Akamai-GRN
Surrogate-Key
X-Cache-Action
X-UUID
X-Framework
X-Cache-Time
X-Drupal-Cache-Contexts
X-Debug-IsConnected
X-FW-Version
X-Debug-IsPreview
X-G
CF-IPCountry
X-Air-Trace-Id
X-Air-Source
X-Air-Hostname
SID
DynaTrace
X-Azure-Ref
X-Oracle-Dms-Ecid
X-Oracle-Dms-Rid
X-Accel-Buffering
X-Presslabs-Stats
X-Nginx-Cache
GEO-INFO
Liferay-Portal
X-Source
X-PressLabs-Stats
Count-Hit
X-TEC-API-VERSION
X-Ms-Version
X-Ms-Request-Id
X-Oneagent-Js-Injection
X-TEC-API-ROOT
X-TEC-API-ORIGIN
Uber-Trace-Id
X-Cache-Operation
X-Cache-NGX
X-APP-VERSION
Frame-Options
Healthy
X-EdgeConnect-Cache-Status
X-Zen-Fury
Ms-Operation-Id
X-RTag
MS-CV
X-XRDS-Location
X-CDN-Forward
Xserver
X-Cache-Hit
Countrycode
X-Tumblr-Pixel-1
X-Tumblr-User
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Mode
X-Backend-Name
X-Varnish-Server
Protected
Ec-Rule-Version
X-Environment-Context
Cross-Origin-Window-Policy
X-L-Path
X-IPS-LoggedIn
X-Region
X-Servername
X-Cache-TTL-Remaining
X-Forwarded-Host
Backend
X-Rewrite-Enabled
X-JoinUs
X-UPSTREAM-Address
X-RN-RSRV
X-SaId
Meta-Geo
X-RateLimit-Limit
X-Adobe-Loc
X-Adobe-Content
X-Zipkin-Id
X-Cache-Server
Decoy-Debug-Key
Decoy-Debug-TTL
Decoy-Debug-Status
LB
X-Debug-Cache
X-Content-Powered-By
X-Ratelimit-Remaining
X-Detected-As
X-Proxied
X-Content-Age
X-Hosted-By
X-Hyper-Cache
X-Redis-Cache
X-Routing-Service
X-Cache-Grace
X-Generation-Time
Eomportal-Instance
X-Extlb
X-Uri
X-Varnish-Beresp-Grace
Cache-Name
Apigw-Requestid
X-Sql-Duration-Ms
Country-Code
X-Shopify-Stage
X-Human
X-FB-TRIP-ID
X-ServerID
X-NCache
X-Origin-Date
X-PHP-Backend
X-PERF
X-ShardId
X-ShopId
Url
X-Sorting-Hat-ShopId
X-Sql-Count
X-Sorting-Hat-PodId
X-Alternate-Cache-Key
X-ApacheServer
X-Site-Version
Fastly-SSL
X-Status
X-Format
X-Via-Fastly
Section-Io-Cache
X-Timing-Wait
TWC-Privacy
X-Tid
TWC-Device-Class
TWC-GeoIP-Country
TWC-GeoIP-LatLong
TWC-Locale-Group
Content-Disposition
Selected-Fe
X-BYPASS-REASON
X-Access
Cache-Tv-Group
X-OCL
Mn-Server-Ip
Property-Id
X-Cluster-Node
TWC-Connection-Speed
X-Cache-Type
X-PCL
X-Pubstack
X-Origin-Hint
X-Akamai-Edgescape
X-Proxy-Build
X-NewRelic-App-Data
Webcakes-App-Version
Webcakes-Region
X-ProxyCache-Status
X-ProxyCache-Key
Webcakes-App-Name
X-No-Session
X-Section
X-NYM-Debug-Backend
X-Cache-Host
X-Say-TTL
X-Say-Cacheable
X-Trace-Id
X-Server-W
X-Microcachable
X-Hl-Ver
X-Web-Node
X-UA-Device-Type
X-Varnishpool
X-SayCDN-TTL
X-Storage
X-Soup
CDN-Cache
CDN-PullZone
CDN-CachedAt
X-R9-Blue-Green-Version
X-TIME
CDN-Uid
CDN-RequestId
CDN-RequestCountryCode
Content-Secure-Policy
X-Be
CDN-EdgeStorageId
Azure-InstanceId
Azure-RegionName
Azure-SiteName
X-Generated-By
Azure-SlotName
Azure-Version
X-Azure-Ref-OriginShield
DB-Nickname
X-Ua
X-LSADC-Cache
WPO-Cache-Status
WPO-Cache-Message
OT-Force-Account-Verify
Retry-After
X-Dc
X-Nginx-Cache-Key
X-Cached-By
SRV
Source
X-Bc-Bl
Cache
X-TT-LOGID
X-Auto-Login
X-LAGOON
X-Unique-Id
X-Platform-Server
X-Cache-Remote
X-Xfnlog-Site
X-GEO
X-Varnish-Hits
Cache-Hits
HostName
X-SRV
X-ECache
X-Origin-TTL
X-TNCMS
X-Loop
X-Cache-Tags
X-Origin-CC
X-Varnish-Hostname
ServedBy
X-Cdn
Mime-Version
X-Akamai-Transformed
X-App-Version
Onion-Location
X-S-Maxage
X-CSRF-Token
X-HTML-Minification-Powered-By
X-Varnish-Cache-Hits
Upgrade-Insecure-Requests
X-Amz-Meta-S3cmd-Attrs
Xet-Cookie
X-Request-Time
X-Correlation-ID
From-Origin
X-Tumblr-Pixel-2
X-AOL-HN
X-Tumblr-Pixel-3
Web-Mar-Node
Webserver
WP-Super-Cache
X-Proto
X-EC-Lua
X-CLOUD-TRACE-CONTEXT
X-Request-Host
X-Time
N-Cache
X-Endurance-Cache-Level
X-NWS-UUID-VERIFY
X-Tenant
X-Cache-Enabled
X-VWS-Id
X-FireWall-Port
X-LJ-Flow-ID
X-AWS-Id
X-Time-Microsecs
X-GG-Cache-Date
X-Handled-By
X-B3-SpanId
X-Origin-Response-Time
X-Cache-Var
X-Cache-Var-Map
X-Edge-Location
X-Ckpd-Fst-Backend
X-NAPM-TraceId
X-CF-Lambda-Version
X-PBS-Appsvrname
X-D
X-Orig-Expires
X-Planisys-CDN-Cache
X-PAYTM-SRV-ID
X-ND-Cache
X-Planisys-CDN-Rules
Redirect-Candidate
X-Aicache-OS
Rendered-Blocks
X-Aed
X-Connection-Hash
Pramga
X-Conf
X-Application
X-Processor
X-Cluster
X-CF-Lambda-Fn
X-ARC
DCR-Decision-By
BehaviorPad-Version
X-Ftr-Request-Id
A
X-Developer
Meta-Geo-Continent
X-External-Request-Id
X-Cache-NE
X-Forwarded-Path
DCR-Processing-Time-Ms
X-Rojux
Expiry
Vix-Hermes-Req-Id
Mobile-Detection-Method
X-B-Cookie
X-Ig-Push-State
Odigeo-Trace-Id
X-Destination
Nel
Fastcgi-X-Cache-Version
X-Planisys-CDN-TTL
X-V-Cache
X-A-Dam
X-S
Surrogated-Key
X-A-Dcw
X-Via-NSCOPI
X-TIM-N
X-Vdms-Version
X-VG-WebCache
X-A
V-Age
X-Mg-Request-UUID
Xc-Version
X-Vtex-Remote-Cache
X-A-Ccd
X-Vtex-Processado-Em
X-SRCache-Key
X-Vdms-Path
X-Shop-Environment
Sslversion
X-Slack-Backend
X-SD-PageType
X-S-Cookie
X-ScT
X-A-Wwc
X-A-Dgt
X-Session-Fingerprint
X-Magnolia-Registration
X-Amz-Apigw-Id
CloudFront-Viewer-Country
X-PHP-Host
X-Reqid
X-Amzn-RequestId
X-MP-GENERATED-AT
X-Labrador-Cache-Channel
X-Scheme
X-Request-URI
X-Cache-Date
CacheControlHeader
X-Forwarded-Site
X-Date
X-Epic-Correlation-Id
Host-ID
X-Webstats-RespID
Wxu-Next-Region
AKAMAI
Wxu-Next-Hostname
X-Backend-TTL
X-Accel-Expires-Debug
Gh-Request-Id
User-Cache-Control
X-Cdn-Srv
Cmstype
DSUID
Wxu-Next-Commit
Cmsid
Fastcgi-Cache-TTL
True-Client-Country-4JS
X-Gdpr
X-Men
X-Mvc-Supplant-Cachable
X-Location
X-LI-UUID
X-Li-Fabric
X-Li-Pop
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-Sucuri-Cache
X-Origin-Expires
X-Old-Content-Length
X-Nyt-Route
X-Sucuri-ID
X-NodeID
X-Adobe-Source
Svr
X-Gen-Mode
X-Proxy-Upstream
X-Viewer-Country
X-Geo-Header
X-Cache-Bucket
X-Server-IP
X-Policy
X-Hnp-Log
X-Origin-Time
X-Block-Status
X-Hash
Origin
X-Branch-Name
Web-Mar-Region
X-Cdn-Origin
X-Backend-State
X-Cache-Id
We-Hiring
X-CGP
X-Level-Front-Cache
X-Sn-Servicetimems
X-TrackingId
X-UnsetCookies
X-Varnish-Beresp-Status
X-Skip-Cache
X-Served-From
X-RCS-CacheZone
X-Region-Sid
X-Req
X-Request-Start
X-VarnishDD-TTL
X-VServer
X-GeoIP-Country-Code
X-GeoIP-Region-Code
X-Origin
X-Rocket-Nginx-Serving-Static
X-Cache-Info
Apple-News-Services-Request-Url
Apple-News-Services-Handled
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-Device-Os
X-Esi-Check
X-Eu-Site
X-Fastly-Backend
X-Developers
X-Datadog-Trace-Id
X-Csrf-Jwt
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
X-Fastly-Cache
X-Fetched-On
X-HS-Content-Campaign-Id
X-Irp-Debug
X-Locale
X-Platform
X-HN
X-Gzip
X-Generated-On
X-GeoIP
X-GeoIP-City
X-Core-Mission
X-Gamma-Serve
Arc-Country
CDCHOST
Release
Ssr
AMP-Access-Control-Allow-Source-Origin
Server-Info
PFcat
Fastly-Drupal-Html
HA-Ipaddr
State
Server-Host
Mail-Subject
Machine
Locid
Ha-Gx-Prefs
L5d-Success-Class
L
S-Rt
Environment
X-Is-Gdpr
X-Has-Esi
X-Core-Value
Adler-Geo
X-Envoy-Decorator-Operation
X-DefHash
X-JWT-State
Cf-Device-Type
X-FC-Vary-Parameters
X-DefElseHash
X-DPWN-IS-SECURE
X-Owner
X-M-Log
X-Qnm-Cache
Fastly-GeoIP-CountryCode
X-Worker
X-Rocket-Build-Number
X-M-Reqid
X-VG-TLSProxy
X-Sigma-Backend
X-Sigma
X-Varnish-Remaining-TTL
X-Varnish-CookieINHashed-On
X-Response-By
X-Qloud-Router
X-Pod-Name
X-Storefront-Renderer-Rendered
X-TH-Server
X-Varnish-CookieHashed-On
X-VC-Cache
X-Thinkindot-L3
X-Node-Id
X-Variation
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
X-ATG-Version
Thinkindot-Control
X-Amzn-Remapped-Content-Length
X-Cache-Debug
NM-Fastcgi-Cache
TDXMobile
Memcached
Platform
Traceparent
Origin-CC
Is-Eu
Origin-EX
X-Xrds-Location
Magicmarker
X-Rebelmouse-Cache-Control
X-Thanos
Req-Svc-Chain
X-Mvc-Supplant-OutputCached
X-Bip
X-BBC-Edge-Cache-Status
X-Zone
X-Loc
X-Rebelmouse-Surrogate-Control
Fastly-SIE
Fastly-SWR
X-NU-AKA-ACS-Version
X-Akamai-Request-ID2
X-Http-Reason
X-Tx-Id
X-Ua-Device
X-Varnish-Beresp-Ttl
X-CS
NGX
X-LB-ID
X-TraceId
X-NC
X-API-Version
X-Cache-Config
X-Up
X-Generated-In
X-Restarts
Kp-EeAlive
CDN
Pics-Label
X-DSS
X-DI
X-DW
Time
X-Wix-Viewer-Type
X-Action
X-RPS
Memory
X-Trace-ID
X-RSL
X-Cache-Backend
Ms-Author-Via
X-CACHE-KEY
X-RPM
X-DB
Edge-Cache
X-Tb-Optimization-Total-Bytes-Saved
X-Tt-Logid
X-LB-NoCache
X-Optimistic-Header
Accept-Language
X-Refresh
Env
X-Edge-Pop
X-Srv
X-Varnish-Ttl
Candidate-Md5Url
NtCoent-Length
WebServer
X-Via-Popv
X-Via-Poph
Datacenter
X-CacheTTL
GeoIp-Country-Code
X-Via-Popn
X-Datadome
X-Minions-Version
X-Vc
X-DynaTrace-JS-Agent
WWW-Authenticate
On-Server
X-Urbn-Context-Path
Locale
X-DC
X-HA-Backend
X-Urbn-Site-Id
X-ZONE
X-Esi
X-MSEdge-Flight
X-Varnish-Beresp-TTL
Esi-Enabled
X-MSEdge-Features
X-Cs
X-Parent-Response-Time
X-Unique-ID
X-User
X-TX-ID
X-Servedbyhost
X-Ec-GeoHdr
Server-ID
X-Ec-Fail
C-Via
X-Service
X-TA-CDN-Provider
X-Newrelic-Synthetics
X-Li-Proto
X-Cache-PHP
X-B3-Spanid
X-VCL-Version
Cdncip
Cdnsip
X-AK-Request-ID
X-App
X-FPC
X-Cache-Ttl
X-URL
X-Dynatrace
Geoip-Latitude
X-Vcl-Version
X-Cache-Status-Check
X-Webkit-Csp-Report-Only
My-App
Test
Cluster
X-Render-Time
X-Fpc
X-LI-Proto
X-Traceid
X-LiteSpeed-Cache-Control
X-CUA
X-Var-Ttl
Tracecode
X-WADP-Cache
X-Clara-WADP
X-Fmm-Version
Geo-Info
Proxy-Connection
X-Webkit-CSP-Report-Only
X-NODE
X-Pass-Why
Cf-Int-Pingora-Origin-Digest
Server-Id
DataCenter
T-Server
X-Mcache
Fastly-Drupal-HTML
Lfy
Lang
Resin-Trace
X-From
X-Fragments
M-TraceId
Target-Params
X-Clientip
X-LiteSpeed-Tag
X-Info
X-AIR-PT
X-CSRF-TOKEN
X-Oss-Hash-Crc64ecma
UCS
X-Oss-Object-Type
X-Oss-Storage-Class
X-Oss-Request-Id
X-Geo
X-ID
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
Cache-Host
X-ServedByHost
HIT
X-VC
X-Oss-Server-Time
X-Ha-Backend
MIME-Version
Hostname
X-RAMCache
GeoIP-Country-Code
X-Pad
S-Cnection
Hit
X-Provided-By
X-Dynatrace-Js-Agent
Permissions-Policy
X-Edge-POP
ENV
Ohc-File-Size
X-Proxy-Cache-Info
X-Httpd
Section-Io-Id
X-Via-PopH
X-Via-PopN
Tcn
X-Cdn-Forward
Section-Origin-Responded
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
X-Via-PopV
X-Edge-Cache
Servername
WZWS-RAY
X-NGINX-Cache
X-Api-Version
User-Agent
Load-Balancing
Producers
X-Micro-Cache
X-Check-Cacheable
X-ElasticPress-Query
Fastly-Backend-Name
X-HS-Status
X-Cache-CFC
X-Ucs
X-ServerName
X-Backend-Host
X-Release
X-Fastly-Backend-Reqs
X-BBC-Origin-Response-Status
X-HostName
URI
X-SB
X-Acquia-Application-Trace
X-APP
X-Acquia-Application-UUID
PICS-Label
ServerName
X-BCube-Filmed-By
X-GoCache-CacheStatus
FSS-Cache
X-UP
X-Acquia-Site
Uri
Wpo-Cache-Status
X-Lb-Nocache
X-Pool
Wpo-Cache-Message
X-Acquia-Purge-Tags
X-Udemy-Cache-App-Namespace
X-TRACE-ID
Server-Ttl
X-RateLimit-Reset
X-Swift-Error
X-Platform-Router
Cteonnt-Length
Ohc-Cache-HIT
Cneonction
X-Ec-Custom-Error
X-Lb-Id
X-Platform-Cluster
X-Nc
Cdn
X-Cdn-Request-ID
X-Platform-Processor
EpKe-Alive
X-Fastly-Cache-Hits
X-Dw-Trace-Id
X-SIPLIST1
X-Cache-Expires
X-Dispatcher-Number
MD5-Digest
X-Akamai-ERPolicy
X-Akamai-ERRuleID
IsBot
X-Scale
X-B3-Parentspanid
X-Litespeed-Cache-Control
Path
X-Apw-Hits
X-Apw-Access-Token
VNS-Cache
Shield-Pop
X-Contensis-Viewer-Groups
X-Cache-ASPX
X-WA-Info
X-WA
Cf-Ipcountry
X-Apw-Access-Object
X-Amz-Meta-Cb-Modifiedtime
VNS-Age
X-Vcache
X-Newrelic-App-Data
X-Apw-Access-Action
X-Snapshot-Date
CPC-Age
CF-Cached-On
X-B3-ParentSpanId
Cache-Key
Vha6-Origin
CPC-Cache
X-Yottaa-OS
X-Cache-Ngx
Sid
Lb
X-Air-Pt
X-IN-APIGATEWAYSSL
X-IN-APIGATEWAY
Sever-Int
Server-Ext
Server-Hostname
X-Shopify-Generated-Cart-Token
X-ES-SERVER
X-Wikidot-Static-Cache
X-UA
X-CacheKey
X-Http-Count
X-Akamai-Pragma-Client-IP
Req-ID
X-Sentry-ID
CountryCode
X-Http-Duration-Ms
X-Te-Count
Ngx
X-Wikidot-Backend
X-Last-Modified
X-Varnish-Authentication
X-Te-Duration-Ms
X-Logging-Id
X-Akamai-Request-ID