Threat Level: green Handler on Duty: Jan Kopriva

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Link
Cf-Request-Id
CF-Cache-Status
Accept-Ranges
CF-RAY
ETag
Expect-CT
Pragma
X-Powered-By
X-XSS-Protection
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-UA-Compatible
X-Cache-Hits
Alt-Svc
P3P
X-Served-By
X-Xss-Protection
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Request-Id
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Cache-Status
X-Generator
X-Cacheable
Timing-Allow-Origin
X-Content-Security-Policy
P3p
X-Iinfo
Status
Feature-Policy
X-Request-ID
X-Envoy-Upstream-Service-Time
Content-Encoding
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
X-CDN
X-AspNetMvc-Version
Upgrade
X-Via
CF-Ray
X-Ws-Request-Id
Access-Control-Max-Age
Server-Timing
EagleId
Keep-Alive
X-Cache-Group
X-Turbo-Charged-By
Request-Context
X-Age
X-Server-Powered-By
X-Proxy-Cache
X-AH-Environment
X-UA-Device
X-Backend
X-Hacker
X-Robots-Tag
Report-To
X-Amz-Request-Id
Host-Header
X-Server
X-LiteSpeed-Cache
X-Amz-Id-2
Grace
X-Rq
X-Nginx-Cache-Status
X-Varnish-Cache
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-WebKit-CSP
X-Dns-Prefetch-Control
X-Page-Speed
X-Vhost
EagleEye-TraceId
X-Amz-Version-Id
X-OneAgent-JS-Injection
X-Pingback
X-Device
X-Dispatcher
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Cache-Spec
NEL
X-Host
X-Server-Id
Cf-Railgun
X-Backend-Server
X-Node
Accept-CH
X-Readtime
X-Akam-SW-Version
Surrogate-Control
Request-Id
X-Response-Time
X-HW
Xkey
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Application-Context
Content-Location
X-Ruxit-JS-Agent
Rating
X-Country
X-Ua-Compatible
Accept-Ch-Lifetime
X-B3-TraceId
X-Cache-Lookup
Accept-CH-Lifetime
X-Cloud-Trace-Context
X-Language
X-Url
X-Ac
X-Trace
X-Content-Type
Allow
X-Template
X-PC
X-Vname
X-TtlSet
X-Varnish-TTL
X-Mod-Pagespeed
X-Clacks-Overhead
Edge-Control
X-FastCGI-Cache
X-ESI
Cache-Tag
Fastly-Restarts
X-Server-Name
X-Rack-Cache
Service-Worker-Allowed
X-VARITI-CCR
X-Element-Page-Cache
Verso
X-MS-InvokeApp
X-GitHub-Request-Id
X-Upstream
X-Buckets
X-Amz-Rid
MS-Author-Via
X-Vcap-Request-Id
Public-Key-Pins
X-Dw-Request-Base-Id
X-Cached
X-Client-IP
X-Abt-Application-Version
X-D2id
X-Origin-Cache
X-Cache-TTL
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
X-Cnection
Arr-Disable-Session-Affinity
X-Px
X-Goog-Hash
Access-Control-Request-Method
X-Powered-By-Plesk
X-Country-Code
X-Aws-Lambda-Call-Status
X-NF-Request-ID
X-Instrumentation
X-Kraken-Loop-Name
X-Navigation-Version
X-Server-Lifecycle-Phase
RTSS
X-Version
Accept-Ch
X-Powered-CMS
X-Amz-Server-Side-Encryption
Pagespeed
X-Middleton-Display
X-Sol
Display
X-Kinja-Build
X-Kinja-Revision
X-Kinja-Server
X-Use-Magma
X-GoogleNews-Bot
X-Kinja
X-Exp-Id
X-Cdn-Fetch
X-Exp-Variant
X-SRCache-Store-Status
X-SRCache-Fetch-Status
Response
X-Middleton-Response
X-MSEdge-Ref
X-LLID
X-Kinsta-Cache
X-Edge-Location-Klb
AR-Request-ID
AR-SID
AR-PoweredBy
AR-CACHE
AR-ATIME
X-Edge
Nginx-Cache
X-RateLimit-Remaining
Mrf-Cache-Status
X-B3-TraceId-Primal
MRF-Tech
X-Shield-Request-Id
X-HP-Trace-Id
X-Jurisdiction
X-HP-Webp
S
X-Protected-By
X-T
TCN
Content-MD5
X-Forwarded-For
X-Content-Security-Policy-Report-Only
X-TTL
X-CST
X-Mg-S
X-Id
X-Aspnetmvc-Version
Realpath
Fastcgi-Cache
X-Mid
X-MCACHE
Edge-Cache-Tag
SPIisLatency
SPRequestDuration
X-Ttl
Front-End-Https
X-Recruiting
X-Parallel-Accel
X-Request-Received
X-Request-Processing-Time
Filters
Server-Node
Fusion-Deployment-Id
Fusion-Content-Source
Fusion-Content-Id
Fusion-Component-Id
Fusion-Source
Fusion-Template-Id
Pinterest-Version
X-Pinterest-Rid
Pinterest-Generated-By
X-Ab
X-Content
X-Ua-Browser
X-DynaTrace
X-SharePointHealthScore
SPRequestGuid
X-Correlation-Id
Server-Name
X-Ezoic-Cdn
X-Ruxit-Js-Agent
X-NWS-LOG-UUID
X-Frontend
X-HS-Combine-CSS
X-HS-Hub-Id
X-HS-Cache-Config
X-HS-Content-Id
Alternate-Protocol
X-Yandex-Sdch-Disable
X-Hits
X-Cache-Key
X-Content-Options
X-ECACHE
X-Accel-Expires
X-Tt-Trace-Tag
X-Tt-Trace-Host
MicrosoftSharePointTeamServices
X-Page-Id
X-Ser
Cache-Tags
Host
X-Git-Hash
X-Server-ID
Cleartype
X-Fastly-Request-Id
Charset
X-B3-Sampled
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Www-Served-By
X-Daa-Tunnel
X-Content-Digest
X-Geo-Country
X-Amz-Replication-Status
Filterid
TP-Cache
TP-L2-Cache
X-Amzn-Trace-Id
X-DIS-Request-ID
X-Forwarded-Proto
X-Varnish-Age
X-VCache
X-Hostname
X-AppVersion
X-Activity-Id
X-Az
X-Debug-Info
X-Rid
X-XRDS-LOCATION
X-Upgrade-Enabled
X-N
X-Origin-Server
X-FB-Debug
Access-Control-Allow-Method
X-Grace
X-LB-Cache
X-Origin-Upstream-Status
X-WebKit-CSP-Report-Only
X-Nginx-Upstream-Cache-Status
ServerID
Cross-Origin-Opener-Policy
X-Mobile-URL
X-Providence-Cookie
X-Request-Guid
X-F-Cache
X-Route-Name
X-Is-Crawler
X-Aspnet-Duration-Ms
X-Flags
X-Whom
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
X-Goog-Generation
X-GUploader-UploadID
X-Goog-Storage-Class
X-App-Environment
X-App-Server
X-Tb
X-Varnish-Grace
X-TT
Viewport
X-Microsite
X-NGENIX-Cache
X-Request-Handler-Origin-Region
Payment
X-FW-Server
X-FW-Type
X-FW-Static
X-FW-Serve
X-FW-Hash
X-FW-Dynamic
X-Distributor
DC
Paypal-Debug-Id
X-Ratelimit-Limit
X-Seen-By
Node
X-Cache-Control
X-Type
Fastcgi-Useragent
X-Logged-In
X-Oneagent-Js-Injection
X-User-Agent
Accept-Charset
Country
X-Cache-Age
X-Cache-Rule
X-Litespeed-Cache
X-Wix-Request-Id
X-DataDome
X-Webkit-CSP
X-Varnish-Backend
Version
X-Load-Cache
X-Erf-Bev-Bev-Is-Generated
X-Node-Name
X-Erf-Bev-Bev
X-Browser-Type
X-PressLabs-Stats
Refresh
X-Via-JSL
Referer-Policy
X-Cache-Action
X-Drupal-Cache-Tags
X-Tec-Api-Version
X-IPLB-Instance
X-Tec-Api-Root
X-Tec-Api-Origin
Cache-Status
X-Cluster-Name
Access-Control-Request-Headers
X-Response-Served-From
Amp-Access-Control-Allow-Source-Origin
SD-X-WS
X-Original-Request-Id
X-Rendered-As
X-Contextid
X-Page-View
X-Mobile
X-Signature
X-B-Cache
X-Proxy-Cache-Status
X-Vgn-Hpd-Reason
X-Real-IP
X-Is-Bot
X-Cacheable-TTL
X-Cache-Expired-At
NGB
X-Jobs
X-UUID
X-Debug
X-ProcessESI
X-RemovedCookies
X-Rule
X-Yottaa-Optimizations
X-Revision
X-Yottaa-Metrics
X-Proxy
X-Device-Type
VIX-Pulpo-Upstream-Status
Surrogate-Key
VIX-Pulpo-Node
Akamai-GRN
X-B
X-Framework
X-Instance
X-Drupal-Cache-Contexts
X-Fastly-Request-ID
X-Cache-Time
DynaTrace
CF-IPCountry
X-G
X-FW-Version
X-Fastcgi-Cache
X-Debug-IsPreview
X-Debug-IsConnected
X-Air-Hostname
X-Air-Trace-Id
Liferay-Portal
X-Air-Source
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-Azure-Ref
Healthy
SID
X-Oracle-Dms-Rid
X-Source
X-Oracle-Dms-Ecid
X-XRDS-Location
X-Ms-Request-Id
X-Ms-Version
Frame-Options
MS-CV
X-RTag
Ms-Operation-Id
X-APP-VERSION
X-CDN-Forward
X-Cache-Hit
X-Nginx-Cache
Count-Hit
X-Tumblr-Pixel-0
X-Cache-Operation
X-Tumblr-User
X-Tumblr-Pixel-1
X-Tumblr-Pixel
GEO-INFO
Countrycode
X-Ratelimit-Reset
X-Varnish-Server
X-Environment-Context
X-L-Path
X-EdgeConnect-Cache-Status
Xserver
Uber-Trace-Id
X-Accel-Buffering
X-Region
X-Servername
Section-Io-Cache
X-Forwarded-Host
X-Mode
X-Content-Powered-By
X-Backend-Name
X-Presslabs-Stats
Ec-Rule-Version
X-IPS-LoggedIn
X-Zen-Fury
Cross-Origin-Window-Policy
Backend
X-SaId
X-Detected-As
X-RN-RSRV
X-JoinUs
Meta-Geo
X-UPSTREAM-Address
X-Sql-Count
X-Generation-Time
X-Redis-Cache
X-Sql-Duration-Ms
X-Uri
X-Cache-NGX
Country-Code
X-Varnish-Beresp-Grace
Eomportal-Instance
X-Sorting-Hat-ShopId
X-Human
X-ShardId
X-Hosted-By
X-Cache-Server
X-Debug-Cache
X-Cache-Type
X-ShopId
X-Alternate-Cache-Key
X-Cache-Grace
X-Shopify-Stage
X-Sorting-Hat-PodId
X-Adobe-Content
X-Adobe-Loc
Decoy-Debug-Status
X-ProxyCache-Key
Url
X-Site-Version
X-BYPASS-REASON
Mn-Server-Ip
X-PHP-Backend
X-Cache-TTL-Remaining
X-ProxyCache-Status
Decoy-Debug-TTL
X-Via-Fastly
X-Tid
DB-Nickname
X-FB-TRIP-ID
Cache-Name
X-Status
X-Microcachable
X-Origin-Date
X-NCache
Decoy-Debug-Key
Apigw-Requestid
X-UA-Device-Type
X-No-Session
Property-Id
Cache-Tv-Group
Fastly-SSL
X-Storage
X-Origin-Hint
X-PCL
X-Proxy-Build
X-SayCDN-TTL
Webcakes-App-Version
X-ServerID
X-Format
X-OCL
Webcakes-Region
X-Say-TTL
X-Timing-Wait
TWC-GeoIP-Country
X-Say-Cacheable
TWC-Device-Class
TWC-Connection-Speed
TWC-GeoIP-LatLong
TWC-Locale-Group
X-Rewrite-Enabled
X-Web-Node
TWC-Privacy
Selected-Fe
Webcakes-App-Name
X-Extlb
OT-Force-Account-Verify
Protected
X-Proxied
X-Routing-Service
X-Zipkin-Id
X-Server-W
X-Section
X-Access
X-PERF
X-Cache-Host
X-NYM-Debug-Backend
X-Pubstack
X-ApacheServer
X-Akamai-Edgescape
X-R9-Blue-Green-Version
X-Soup
X-Varnishpool
Azure-SiteName
Azure-RegionName
X-Hl-Ver
Azure-InstanceId
Azure-SlotName
Azure-Version
X-RateLimit-Limit
Content-Secure-Policy
X-Be
X-Cluster-Node
X-Content-Age
X-Azure-Ref-OriginShield
X-Ua
X-NewRelic-App-Data
X-LSADC-Cache
Source
X-Webkit-Csp
Content-Disposition
CDN-Uid
CDN-EdgeStorageId
CDN-PullZone
X-Generated-By
CDN-RequestCountryCode
Cache
X-Dc
X-Cached-By
CDN-RequestId
CDN-CachedAt
X-Hyper-Cache
CDN-Cache
SRV
X-HTML-Minification-Powered-By
X-SRV
X-Unique-Id
X-ECache
X-LAGOON
X-Trace-Id
X-Amz-Meta-S3cmd-Attrs
X-Nginx-Cache-Key
X-Bc-Bl
X-App-Version
X-Time
X-Cache-Var
X-Cache-Var-Map
X-Varnish-Hits
X-Loop
X-TNCMS
X-Varnish-Hostname
LB
Xet-Cookie
X-Auto-Login
Onion-Location
X-TT-LOGID
Retry-After
X-S-Maxage
Cache-Hits
X-Origin-TTL
X-GEO
X-Origin-CC
Web-Mar-Node
X-Tumblr-Pixel-3
X-TIME
X-Tumblr-Pixel-2
X-Proto
Mime-Version
X-Platform-Server
WPO-Cache-Message
WPO-Cache-Status
X-Cdn
X-M-Reqid
X-Akamai-Transformed
X-Qnm-Cache
X-M-Log
X-Tenant
X-Endurance-Cache-Level
X-Edge-Location
Webserver
X-LJ-Flow-ID
X-CSRF-Token
X-AWS-Id
X-Xfnlog-Site
X-GG-Cache-Date
X-Time-Microsecs
X-VWS-Id
X-Cache-Remote
HostName
CloudFront-Viewer-Country
X-Cache-Tags
Upgrade-Insecure-Requests
X-Mg-Request-UUID
X-Varnish-Cache-Hits
N-Cache
X-Amz-Apigw-Id
X-CACHE-KEY
X-Amzn-RequestId
X-Request-Time
ServedBy
X-AOL-HN
X-Ratelimit-Remaining
X-RCS-CacheZone
X-Via-NSCOPI
X-Labrador-Cache-Channel
X-PHP-Host
X-Origin-Response-Time
X-Locale
X-Handled-By
X-B3-SpanId
X-SVT-ORM-RULES
Expiry
X-Session-Fingerprint
Meta-Geo-Continent
Fastcgi-X-Cache-Version
X-Slack-Backend
DSUID
X-SRCache-Key
X-Shop-Environment
X-SD-PageType
X-Vdms-Version
X-Vdms-Path
A
X-VG-WebCache
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
X-Gen-Mode
X-Hnp-Log
X-Ig-Push-State
DCR-Decision-By
DCR-Processing-Time-Ms
X-TIM-N
BehaviorPad-Version
Xc-Version
X-V-Cache
X-SVT-ORM-VERSION
Rendered-Blocks
X-Processor
X-Ckpd-Fst-Backend
X-Conf
X-Connection-Hash
X-NAPM-TraceId
X-CF-Lambda-Version
X-Rojux
X-Cache-NE
X-Request-Host
X-CF-Lambda-Fn
X-ND-Cache
X-Planisys-CDN-TTL
X-PBS-Appsvrname
X-PAYTM-SRV-ID
X-Orig-Expires
X-External-Request-Id
X-Planisys-CDN-Cache
X-Developer
X-Planisys-CDN-Rules
X-D
X-Destination
X-Cache-Date
X-Block-Status
X-S-Cookie
X-Forwarded-Path
X-S
Surrogated-Key
Redirect-Candidate
Pramga
Mobile-Detection-Method
Odigeo-Trace-Id
Origin
User-Cache-Control
X-Ftr-Request-Id
X-Aed
X-Application
X-ARC
X-B-Cookie
X-A-Wwc
X-A-Dgt
X-A-Ccd
X-A-Dam
X-A-Dcw
X-ScT
X-A
Nel
X-Storefront-Renderer-Rendered
X-Correlation-ID
X-VC-Cache
X-MP-GENERATED-AT
X-Men
X-Location
Origin-CC
X-Cache-Bucket
State
X-Mvc-Supplant-Cachable
Origin-EX
X-Owner
X-Core-Mission
X-Origin-Expires
CacheControlHeader
X-Nyt-Route
CDCHOST
X-Hash
Fastcgi-Cache-TTL
Host-ID
X-Epic-Correlation-Id
X-Device-Os
X-Cluster
X-Date
L
X-Reqid
X-Fastly-Cache
X-Geo-Header
Arc-Country
X-Gdpr
X-Forwarded-Site
Gh-Request-Id
X-Fetched-On
X-Cache-Info
X-Origin-Time
Release
X-Skip-Cache
X-Policy
X-Server-IP
X-Served-From
X-Sucuri-Cache
X-Sucuri-ID
X-VServer
X-Webstats-RespID
X-Varnish-Beresp-Status
Traceparent
V-Age
Server-Info
Wxu-Next-Commit
Wxu-Next-Hostname
X-Proxy-Upstream
AKAMAI
X-Accel-Expires-Debug
X-ATG-Version
Wxu-Next-Region
X-Adobe-Source
From-Origin
X-Scheme
X-Rocket-Nginx-Serving-Static
X-FireWall-Port
AMP-Access-Control-Allow-Source-Origin
TDXMobile
Thinkindot-CacheControl-Type
X-Cdn-Srv
Thinkindot-CacheControl
Thinkindot-Control
X-BBC-Edge-Cache-Status
Web-Mar-Region
X-Cache-Debug
X-Cache-Config
X-Cdn-Origin
Svr
We-Hiring
X-Bip
Vix-Hermes-Req-Id
X-HN
X-Sigma-Backend
X-Sn-Servicetimems
X-TH-Server
X-Sigma
X-Rocket-Build-Number
X-Req
X-Request-Start
X-Thanos
X-Thinkindot-L3
X-Aicache-OS
Sslversion
X-Viewer-Country
X-VG-TLSProxy
X-TrackingId
X-VarnishDD-TTL
X-Region-Sid
X-Platform
X-Generated-On
X-GeoIP
X-Gamma-Serve
X-Fastly-Backend
X-Developers
X-Magnolia-Registration
X-GeoIP-City
X-HS-Content-Campaign-Id
X-Node-Id
X-Old-Content-Length
X-LI-UUID
X-Li-Pop
X-Irp-Debug
X-Level-Front-Cache
X-Core-Value
X-Li-Fabric
Fastly-GeoIP-CountryCode
Cmstype
Locid
Machine
PFcat
Mail-Subject
Cmsid
Apple-News-Services-Request-Url
Req-Svc-Chain
Apple-News-Services-Host
Apple-News-Services-Handled
Apple-News-Services-Parsed-Url
Fastly-Drupal-Html
WP-Super-Cache
Environment
X-Zone
HA-Ipaddr
X-Eu-Site
X-Esi-Check
Ha-Gx-Prefs
X-FC-Vary-Parameters
Fastly-SIE
Fastly-SWR
X-Envoy-Decorator-Operation
L5d-Success-Class
X-CGP
Memcached
NGX
X-Csrf-Jwt
X-Datadog-Parent-Id
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
X-Has-Esi
X-Is-Gdpr
X-Rebelmouse-Cache-Control
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-Rebelmouse-Surrogate-Control
X-UnsetCookies
X-Response-By
X-Request-URI
X-Qloud-Router
Server-Host
True-Client-Country-4JS
X-Loc
X-JWT-State
X-NodeID
X-NU-AKA-ACS-Version
X-Pod-Name
Cf-Device-Type
X-Cache-Id
X-Gzip
X-Amzn-Remapped-Content-Length
X-Branch-Name
X-Backend-State
X-Worker
Ssr
X-Xrds-Location
X-EC-Lua
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
Is-Eu
X-DefElseHash
X-DefHash
X-DPWN-IS-SECURE
X-Variation
Platform
Adler-Geo
X-Origin
Candidate-Md5Url
Datacenter
X-Mvc-Supplant-OutputCached
X-Tx-Id
X-Varnish-CookieHashed-On
NM-Fastcgi-Cache
X-Ua-Device
X-NWS-UUID-VERIFY
X-NC
X-API-Version
X-CLOUD-TRACE-CONTEXT
X-CS
X-Cache-Enabled
WWW-Authenticate
Pics-Label
X-LB-ID
X-Backend-TTL
X-Vc
On-Server
X-Varnish-Beresp-Ttl
X-Up
CDN
Esi-Enabled
X-GeoIP-Country-Code
Time
X-Refresh
Ms-Author-Via
X-DynaTrace-JS-Agent
X-GeoIP-Region-Code
NtCoent-Length
Memory
X-Trace-ID
X-Tt-Logid
X-Datadome
X-TraceId
X-Tb-Optimization-Total-Bytes-Saved
Magicmarker
X-LB-NoCache
X-Generated-In
X-Edge-Pop
X-Service
X-Via-Popv
WebServer
Env
C-Via
X-Via-Popn
X-Via-Poph
GeoIp-Country-Code
X-Dynatrace
X-Varnish-Ttl
X-Parent-Response-Time
X-TA-CDN-Provider
X-Restarts
X-Varnish-Beresp-TTL
X-Cache-PHP
X-Optimistic-Header
Kp-EeAlive
S-Rt
X-CacheTTL
X-DC
X-Action
X-Render-Time
X-DI
X-Cs
X-RSL
X-Servedbyhost
X-Esi
X-Wix-Viewer-Type
X-MSEdge-Flight
X-RPM
X-DW
X-DSS
X-DB
X-MSEdge-Features
X-RPS
Edge-Cache
X-Cache-Status-Check
X-Cache-Backend
X-Srv
X-TX-ID
X-Unique-ID
X-ZONE
X-Info
X-Akamai-Request-ID2
X-Http-Reason
Server-ID
X-Minions-Version
X-VCL-Version
X-AIR-PT
X-HA-Backend
X-App
X-Cache-Ttl
X-Newrelic-Synthetics
X-Clientip
X-FPC
X-Li-Proto
Proxy-Connection
X-LiteSpeed-Cache-Control
X-URL
X-B3-Spanid
Accept-Language
Server-Id
X-LI-Proto
X-Fpc
X-Oss-Storage-Class
UCS
X-Oss-Hash-Crc64ecma
HIT
Test
X-Webkit-Csp-Report-Only
X-Oss-Object-Type
Cache-Host
X-Oss-Request-Id
X-Oss-Server-Time
X-Traceid
X-Vcl-Version
X-Ec-Fail
X-Ec-GeoHdr
X-User
S-Cnection
X-Urbn-Site-Id
X-Urbn-Context-Path
Locale
X-NODE
X-Webkit-CSP-Report-Only
Geo-Info
Tcn
Section-Io-Origin-Status
Lb
Section-Io-Id
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
X-Pass-Why
X-Micro-Cache
Fastly-Backend-Name
User-Agent
X-CSRF-TOKEN
M-TraceId
Cdncip
X-Ha-Backend
X-AK-Request-ID
Fastly-Drupal-HTML
X-HostName
Cdnsip
Hostname
Cf-Int-Pingora-Origin-Digest
X-Pad
X-LiteSpeed-Tag
X-Backend-Host
X-ID
X-APP
X-BCube-Filmed-By
X-BBC-Origin-Response-Status
Resin-Trace
My-App
X-Release
X-Fmm-Version
X-WADP-Cache
X-Clara-WADP
Geoip-Latitude
Cluster
X-ServedByHost
X-B3-Traceid
X-Via-PopN
GeoIP-Country-Code
Ohc-File-Size
X-CUA
Tracecode
Hit
X-Via-PopV
X-Via-PopH
X-Check-Cacheable
X-Var-Ttl
X-Geo
X-NGINX-Cache
X-Dynatrace-Js-Agent
X-ES-SERVER
CPC-Age
Cache-Key
MIME-Version
X-WA-Info
X-WA
X-Edge-POP
X-Cdn-Forward
EpKe-Alive
X-From
T-Server
Lfy
VNS-Age
X-Amz-Meta-Cb-Modifiedtime
VNS-Cache
Path
CPC-Cache
ENV
X-ElasticPress-Query
Load-Balancing
X-RAMCache
Lang
X-Edge-Cache
X-HS-Status
X-Api-Version
X-Fragments
Srv
X-Akamai-Pragma-Client-IP
X-ServerName
X-Fastly-Backend-Reqs
X-UP
X-PJAX-URL
X-Wikidot-Backend
X-WP-CF-Super-Cache
X-Ucs
X-Wikidot-Static-Cache
X-WP-CF-Super-Cache-Cache-Control
Target-Params
Servername
URI
Pagetype
Shield-Pop
X-Cms-Context
DataCenter
X-CCDN-Origin-Time
X-Lb-Id
X-CCDN-CacheTTL
X-Hcs-Proxy-Type
X-GoCache-CacheStatus
Uri
X-Via-Ucdn
MD5-Digest
X-Mcache
X-Fastly-Cache-Hits
X-Dw-Trace-Id
X-TRACE-ID
Sid
X-Cdn-Request-ID
X-VC
IsBot
PICS-Label
Server-Ext
Cneonction
Ohc-Cache-HIT
WZWS-RAY
X-RateLimit-Reset
X-VG-WebServer
Cdn
X-SIPLIST1
Server-Hostname
X-B3-ParentSpanId
Sever-Int
X-Nc
X-Acquia-Purge-Tags
W
X-Acquia-Site
X-Acquia-Application-Trace
X-Swift-Error
X-Newrelic-App-Data
X-Acquia-Application-UUID
CF-Cached-On
Cteonnt-Length
Cf-Ipcountry
X-Yottaa-OS
X-Lb-Nocache
X-Snapshot-Date
X-Contensis-Viewer-Groups
X-Apw-Access-Token
X-Apw-Access-Object
X-Apw-Access-Action
X-Cache-ASPX
X-Cache-Expires
FSS-Cache
X-Proxy-Cache-Info
X-Apw-Hits
X-Httpd
Vha6-Origin
X-Air-Pt
X-Cache-Ngx
X-Http-Count
X-Last-Modified
Permissions-Policy
X-Te-Duration-Ms
X-Akamai-ERRuleID
X-Akamai-ERPolicy
X-Http-Duration-Ms
Server-Ttl
X-Te-Count
ServerName
X-Akamai-Request-ID
X-Platform-Router
X-Provided-By
X-B3-Parentspanid
X-Platform-Processor
X-Platform-Cluster
Dnion-Transfer-Encoding
HitType
X-Miniprofiler-Ids
X-Varnish-Authentication
CountryCode
X-Sentry-ID
Req-ID
X-UA
X-Logging-Id
X-CacheKey
Ngx