Threat Level: green Handler on Duty: Jan Kopriva

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Link
Cf-Request-Id
CF-Cache-Status
Accept-Ranges
CF-RAY
ETag
X-XSS-Protection
Expect-CT
Pragma
X-Powered-By
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
Alt-Svc
P3P
X-Served-By
X-Xss-Protection
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Request-Id
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Cache-Status
X-Generator
X-Cacheable
Timing-Allow-Origin
P3p
X-Content-Security-Policy
X-Iinfo
Status
Feature-Policy
X-Request-ID
X-Envoy-Upstream-Service-Time
Content-Encoding
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
X-AspNetMvc-Version
X-CDN
Upgrade
X-Via
CF-Ray
X-Ws-Request-Id
Access-Control-Max-Age
Server-Timing
EagleId
Keep-Alive
X-Cache-Group
X-Turbo-Charged-By
Request-Context
X-Age
X-Server-Powered-By
X-Proxy-Cache
X-AH-Environment
X-UA-Device
X-Backend
X-Hacker
X-Robots-Tag
Report-To
X-Amz-Request-Id
Host-Header
X-Server
X-LiteSpeed-Cache
X-Amz-Id-2
Grace
X-Dns-Prefetch-Control
X-Rq
X-Nginx-Cache-Status
X-Varnish-Cache
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-WebKit-CSP
X-Page-Speed
X-Vhost
EagleEye-TraceId
X-Amz-Version-Id
X-OneAgent-JS-Injection
X-Ua-Compatible
X-Pingback
X-Dispatcher
X-Device
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Cache-Spec
NEL
X-Host
X-Server-Id
Cf-Railgun
X-Backend-Server
X-Node
Accept-CH
X-Readtime
X-Akam-SW-Version
Surrogate-Control
Request-Id
X-Response-Time
X-HW
Xkey
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Application-Context
Content-Location
X-Ruxit-JS-Agent
Rating
X-Country
Accept-Ch-Lifetime
X-B3-TraceId
X-Cache-Lookup
Accept-CH-Lifetime
X-Cloud-Trace-Context
X-Language
X-Url
X-Ac
X-Trace
X-Content-Type
Allow
X-Template
X-TtlSet
X-PC
X-Vname
X-Varnish-TTL
X-Mod-Pagespeed
X-Clacks-Overhead
Edge-Control
X-FastCGI-Cache
X-ESI
Cache-Tag
Fastly-Restarts
X-Server-Name
X-Rack-Cache
Service-Worker-Allowed
X-VARITI-CCR
X-Element-Page-Cache
Verso
X-MS-InvokeApp
X-GitHub-Request-Id
X-Upstream
X-Buckets
X-Amz-Rid
MS-Author-Via
X-Vcap-Request-Id
Public-Key-Pins
X-Dw-Request-Base-Id
X-Cached
X-Client-IP
X-Abt-Application-Version
X-D2id
X-Origin-Cache
X-Cache-TTL
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
X-Cnection
Arr-Disable-Session-Affinity
X-Px
X-Goog-Hash
Access-Control-Request-Method
X-Powered-By-Plesk
X-Country-Code
X-NF-Request-ID
X-Aws-Lambda-Call-Status
X-Instrumentation
X-Kraken-Loop-Name
X-Navigation-Version
X-Server-Lifecycle-Phase
RTSS
X-Version
Accept-Ch
X-Powered-CMS
X-Amz-Server-Side-Encryption
Pagespeed
X-Middleton-Display
X-Sol
Display
X-Kinja-Build
X-Kinja-Revision
X-Kinja-Server
X-Use-Magma
X-GoogleNews-Bot
X-Kinja
X-Exp-Id
X-Cdn-Fetch
X-Exp-Variant
X-SRCache-Store-Status
X-SRCache-Fetch-Status
Response
X-Middleton-Response
X-MSEdge-Ref
X-LLID
X-Kinsta-Cache
X-Edge-Location-Klb
AR-Request-ID
AR-SID
AR-PoweredBy
AR-CACHE
AR-ATIME
X-Edge
Nginx-Cache
X-RateLimit-Remaining
Mrf-Cache-Status
X-B3-TraceId-Primal
MRF-Tech
X-Shield-Request-Id
X-HP-Trace-Id
X-Jurisdiction
X-HP-Webp
S
X-Protected-By
X-T
TCN
Content-MD5
X-Forwarded-For
X-Content-Security-Policy-Report-Only
X-TTL
X-Mg-S
X-CST
X-Id
Realpath
X-Aspnetmvc-Version
X-Mid
Fastcgi-Cache
X-MCACHE
Edge-Cache-Tag
SPIisLatency
X-Ttl
SPRequestDuration
Front-End-Https
X-Recruiting
X-Parallel-Accel
X-Request-Received
X-Request-Processing-Time
Filters
Server-Node
Fusion-Deployment-Id
Fusion-Content-Source
Fusion-Content-Id
Fusion-Component-Id
Fusion-Template-Id
Fusion-Source
Pinterest-Version
X-Pinterest-Rid
Pinterest-Generated-By
X-Ab
X-Content
X-Ua-Browser
X-DynaTrace
X-SharePointHealthScore
SPRequestGuid
X-Correlation-Id
Server-Name
X-Ezoic-Cdn
X-Ruxit-Js-Agent
X-NWS-LOG-UUID
X-Frontend
X-HS-Combine-CSS
X-HS-Hub-Id
X-HS-Cache-Config
X-HS-Content-Id
Alternate-Protocol
X-Yandex-Sdch-Disable
X-Hits
X-Cache-Key
X-ECACHE
X-Content-Options
X-Accel-Expires
X-Tt-Trace-Tag
X-Tt-Trace-Host
MicrosoftSharePointTeamServices
X-Ser
X-Page-Id
Cache-Tags
X-Git-Hash
Host
Cleartype
Charset
X-Fastly-Request-Id
X-Server-ID
X-B3-Sampled
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Www-Served-By
X-Content-Digest
X-Daa-Tunnel
X-Geo-Country
X-Amz-Replication-Status
Filterid
X-Amzn-Trace-Id
X-Forwarded-Proto
X-DIS-Request-ID
TP-Cache
X-Varnish-Age
X-VCache
TP-L2-Cache
X-Activity-Id
X-Hostname
X-Az
X-AppVersion
X-Debug-Info
X-Rid
X-XRDS-LOCATION
X-Upgrade-Enabled
X-N
X-Origin-Server
X-Grace
Access-Control-Allow-Method
X-FB-Debug
X-LB-Cache
X-Origin-Upstream-Status
X-WebKit-CSP-Report-Only
ServerID
X-Nginx-Upstream-Cache-Status
X-Mobile-URL
Cross-Origin-Opener-Policy
X-Is-Crawler
X-Aspnet-Duration-Ms
X-Route-Name
X-Providence-Cookie
X-Request-Guid
X-Flags
X-F-Cache
X-Whom
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-Goog-Metageneration
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-Goog-Storage-Class
X-App-Server
X-Tb
X-App-Environment
X-Varnish-Grace
X-Microsite
Viewport
X-NGENIX-Cache
X-TT
X-Request-Handler-Origin-Region
Payment
X-FW-Serve
X-FW-Static
X-FW-Dynamic
X-FW-Server
X-FW-Hash
X-FW-Type
Paypal-Debug-Id
DC
X-Distributor
X-Ratelimit-Limit
X-Seen-By
Node
X-Cache-Control
X-Type
Fastcgi-Useragent
X-Logged-In
X-Oneagent-Js-Injection
X-User-Agent
Country
Accept-Charset
X-Cache-Age
X-Litespeed-Cache
X-Cache-Rule
X-Wix-Request-Id
X-DataDome
X-Varnish-Backend
X-Webkit-CSP
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
Version
X-Node-Name
X-Browser-Type
X-Load-Cache
X-PressLabs-Stats
Referer-Policy
X-Via-JSL
X-Drupal-Cache-Tags
Refresh
X-Cache-Action
X-Tec-Api-Version
X-IPLB-Instance
X-Tec-Api-Origin
X-Tec-Api-Root
SD-X-WS
X-Response-Served-From
Cache-Status
X-Cluster-Name
X-Original-Request-Id
Amp-Access-Control-Allow-Source-Origin
X-Contextid
X-Page-View
Access-Control-Request-Headers
X-Is-Bot
X-B-Cache
X-Rendered-As
X-Signature
X-Proxy-Cache-Status
X-Mobile
X-Real-IP
X-Cacheable-TTL
X-Cache-Expired-At
X-Jobs
X-Vgn-Hpd-Reason
X-ProcessESI
X-UUID
X-RemovedCookies
X-Debug
NGB
X-Rule
X-Proxy
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Device-Type
X-Revision
Akamai-GRN
VIX-Pulpo-Node
Surrogate-Key
VIX-Pulpo-Upstream-Status
X-Drupal-Cache-Contexts
X-Instance
X-Fastly-Request-ID
X-Framework
X-Cache-Time
DynaTrace
X-Fastcgi-Cache
X-B
CF-IPCountry
X-Debug-IsConnected
X-G
X-FW-Version
X-Debug-IsPreview
X-Air-Trace-Id
X-Air-Hostname
X-Air-Source
Liferay-Portal
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Azure-Ref
Healthy
SID
X-Source
X-Oracle-Dms-Rid
X-Oracle-Dms-Ecid
X-XRDS-Location
X-Ms-Version
X-Ms-Request-Id
Frame-Options
X-RTag
Ms-Operation-Id
MS-CV
X-APP-VERSION
X-Cache-Hit
X-Nginx-Cache
X-CDN-Forward
Count-Hit
X-Tumblr-Pixel
X-Tumblr-User
X-Cache-Operation
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
GEO-INFO
Countrycode
X-Ratelimit-Reset
X-Varnish-Server
X-Environment-Context
X-L-Path
Xserver
X-EdgeConnect-Cache-Status
Uber-Trace-Id
X-Accel-Buffering
X-Region
X-Servername
Section-Io-Cache
X-Forwarded-Host
X-Mode
X-Content-Powered-By
X-Backend-Name
X-Presslabs-Stats
Ec-Rule-Version
X-IPS-LoggedIn
X-Zen-Fury
Cross-Origin-Window-Policy
Backend
X-RN-RSRV
X-Detected-As
X-JoinUs
X-UPSTREAM-Address
Meta-Geo
X-SaId
X-Sql-Count
X-Generation-Time
X-Sql-Duration-Ms
X-Cache-NGX
Country-Code
X-Varnish-Beresp-Grace
X-Redis-Cache
Eomportal-Instance
X-Sorting-Hat-ShopId
X-Human
X-ShardId
X-Hosted-By
X-Cache-Server
X-Debug-Cache
X-Cache-Type
X-ShopId
X-Alternate-Cache-Key
X-Shopify-Stage
X-Sorting-Hat-PodId
X-Cache-Grace
X-Adobe-Loc
X-Adobe-Content
X-ProxyCache-Key
Decoy-Debug-Status
X-Site-Version
Url
X-BYPASS-REASON
X-PHP-Backend
Mn-Server-Ip
X-Cache-TTL-Remaining
X-ProxyCache-Status
X-Via-Fastly
Decoy-Debug-TTL
X-Microcachable
X-Tid
X-Origin-Date
X-FB-TRIP-ID
X-Status
Cache-Name
X-NCache
DB-Nickname
X-Uri
X-No-Session
X-UA-Device-Type
Decoy-Debug-Key
Property-Id
Cache-Tv-Group
Apigw-Requestid
Fastly-SSL
X-Storage
X-Origin-Hint
X-PCL
X-Proxy-Build
X-SayCDN-TTL
Webcakes-App-Version
X-ServerID
X-Format
X-OCL
Webcakes-Region
X-Say-TTL
X-Timing-Wait
TWC-GeoIP-Country
X-Say-Cacheable
TWC-Device-Class
TWC-Connection-Speed
TWC-GeoIP-LatLong
TWC-Locale-Group
X-Rewrite-Enabled
X-Web-Node
TWC-Privacy
Selected-Fe
Webcakes-App-Name
X-Varnishpool
OT-Force-Account-Verify
X-Section
X-Extlb
X-Proxied
X-Zipkin-Id
X-Server-W
X-Routing-Service
X-R9-Blue-Green-Version
X-Pubstack
X-ApacheServer
X-Cache-Host
X-Hl-Ver
X-NYM-Debug-Backend
X-Akamai-Edgescape
X-PERF
X-Access
X-Soup
Protected
Azure-SiteName
Azure-Version
Azure-SlotName
Azure-RegionName
Azure-InstanceId
X-RateLimit-Limit
X-Be
X-Cluster-Node
X-Azure-Ref-OriginShield
Content-Secure-Policy
X-Content-Age
X-LSADC-Cache
Source
X-Ua
X-NewRelic-App-Data
Content-Disposition
X-Webkit-Csp
CDN-PullZone
CDN-EdgeStorageId
SRV
CDN-RequestId
X-Hyper-Cache
CDN-Uid
Cache
CDN-RequestCountryCode
X-Dc
CDN-Cache
CDN-CachedAt
X-Generated-By
X-SRV
X-HTML-Minification-Powered-By
X-ECache
X-Cached-By
X-Unique-Id
X-Amz-Meta-S3cmd-Attrs
X-LAGOON
X-Trace-Id
X-Nginx-Cache-Key
X-Bc-Bl
X-App-Version
X-Varnish-Hostname
X-Cache-Var-Map
X-Loop
X-TNCMS
X-Varnish-Hits
X-Time
X-Cache-Var
X-Auto-Login
LB
Onion-Location
Xet-Cookie
X-TT-LOGID
Retry-After
X-GEO
X-Origin-CC
X-Origin-TTL
X-S-Maxage
Cache-Hits
X-Tumblr-Pixel-3
X-Tumblr-Pixel-2
X-TIME
Web-Mar-Node
Mime-Version
X-Proto
WPO-Cache-Status
X-Platform-Server
X-Cdn
WPO-Cache-Message
X-Akamai-Transformed
X-Endurance-Cache-Level
X-Tenant
X-M-Reqid
X-Qnm-Cache
X-M-Log
Webserver
X-Edge-Location
X-Cache-Remote
X-GG-Cache-Date
HostName
X-LJ-Flow-ID
X-AWS-Id
X-CSRF-Token
X-Time-Microsecs
X-Xfnlog-Site
X-VWS-Id
CloudFront-Viewer-Country
X-Cache-Tags
N-Cache
X-Mg-Request-UUID
Upgrade-Insecure-Requests
X-Varnish-Cache-Hits
X-Amzn-RequestId
X-Amz-Apigw-Id
X-CACHE-KEY
X-Request-Time
ServedBy
X-AOL-HN
X-Ratelimit-Remaining
X-Via-NSCOPI
X-Labrador-Cache-Channel
X-RCS-CacheZone
X-PHP-Host
X-Handled-By
X-Origin-Response-Time
X-Locale
X-B3-SpanId
DCR-Processing-Time-Ms
X-VG-WebCache
X-Vdms-Version
Xc-Version
DSUID
Expiry
X-SD-PageType
X-Vdms-Path
X-Vtex-Remote-Cache
X-Session-Fingerprint
X-SRCache-Key
X-SVT-ORM-VERSION
X-TIM-N
X-Vtex-Processado-Em
Fastcgi-X-Cache-Version
X-SVT-ORM-RULES
X-Slack-Backend
DCR-Decision-By
BehaviorPad-Version
A
X-Shop-Environment
X-A-Dam
X-Connection-Hash
X-PBS-Appsvrname
X-PAYTM-SRV-ID
X-Orig-Expires
X-Processor
X-Conf
X-CF-Lambda-Fn
X-Request-Host
X-CF-Lambda-Version
X-Ckpd-Fst-Backend
X-D
X-ND-Cache
X-Ftr-Request-Id
X-Gen-Mode
X-Hnp-Log
X-Ig-Push-State
X-Forwarded-Path
X-External-Request-Id
X-NAPM-TraceId
X-Destination
X-Developer
X-Cache-NE
X-Cache-Date
Redirect-Candidate
Rendered-Blocks
Surrogated-Key
User-Cache-Control
Pramga
Origin
Mobile-Detection-Method
X-ScT
Odigeo-Trace-Id
X-S-Cookie
X-A-Ccd
X-A-Dcw
X-Rojux
X-ARC
X-B-Cookie
X-Block-Status
X-Application
X-Aed
X-S
X-A-Dgt
X-A-Wwc
Meta-Geo-Continent
X-A
Nel
X-Correlation-ID
X-Storefront-Renderer-Rendered
X-VC-Cache
X-MP-GENERATED-AT
X-Adobe-Source
L
Host-ID
X-Forwarded-Site
X-Cluster
Origin-EX
Origin-CC
X-Reqid
X-Hash
X-Rocket-Nginx-Serving-Static
X-Server-IP
X-Core-Mission
X-Skip-Cache
X-Served-From
X-Scheme
X-Proxy-Upstream
Server-Info
Fastcgi-Cache-TTL
X-Cache-Bucket
X-Policy
X-Location
X-Accel-Expires-Debug
X-Nyt-Route
Traceparent
X-Fetched-On
Wxu-Next-Commit
X-Mvc-Supplant-Cachable
Wxu-Next-Region
Wxu-Next-Hostname
X-Fastly-Cache
State
X-Planisys-CDN-TTL
Release
CDCHOST
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
X-Origin-Expires
X-Origin-Time
X-ATG-Version
X-Men
Gh-Request-Id
X-Date
X-Gdpr
X-Device-Os
AKAMAI
X-Varnish-Beresp-Status
From-Origin
X-Cache-Info
X-Webstats-RespID
X-V-Cache
X-Geo-Header
Arc-Country
X-Epic-Correlation-Id
X-Sucuri-Cache
X-VServer
CacheControlHeader
X-Sucuri-ID
X-FireWall-Port
AMP-Access-Control-Allow-Source-Origin
X-LI-UUID
V-Age
Req-Svc-Chain
Vix-Hermes-Req-Id
X-Platform
Web-Mar-Region
X-Cdn-Origin
X-TrackingId
X-Node-Id
PFcat
X-GeoIP
We-Hiring
X-Generated-On
TDXMobile
X-Li-Fabric
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
X-Viewer-Country
Thinkindot-Control
Svr
X-VG-TLSProxy
X-Li-Pop
X-Level-Front-Cache
X-Owner
X-VarnishDD-TTL
X-Core-Value
X-Old-Content-Length
X-Aicache-OS
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
Apple-News-Services-Handled
Fastly-GeoIP-CountryCode
X-Rocket-Build-Number
X-Cache-Debug
X-Cache-Config
X-Thanos
X-Sigma
Cmstype
Cmsid
X-Gamma-Serve
X-Sn-Servicetimems
X-Magnolia-Registration
X-Sigma-Backend
X-TH-Server
X-Developers
X-Cdn-Srv
Sslversion
X-Irp-Debug
X-Req
X-Fastly-Backend
X-HS-Content-Campaign-Id
X-Region-Sid
Machine
Mail-Subject
Locid
X-Thinkindot-L3
X-Bip
X-HN
X-GeoIP-City
X-BBC-Edge-Cache-Status
X-Request-Start
Environment
WP-Super-Cache
Fastly-Drupal-Html
X-Zone
X-Is-Gdpr
X-Branch-Name
X-Loc
X-Gzip
X-Has-Esi
X-Backend-State
X-CGP
X-JWT-State
X-Cache-Id
X-Amzn-Remapped-Content-Length
NGX
Fastly-SIE
Cf-Device-Type
Fastly-SWR
Ha-Gx-Prefs
X-FC-Vary-Parameters
HA-Ipaddr
X-Csrf-Jwt
X-Esi-Check
X-Worker
Ssr
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
X-UnsetCookies
X-Request-URI
X-Response-By
X-Pod-Name
X-Eu-Site
Server-Host
True-Client-Country-4JS
X-NodeID
X-NU-AKA-ACS-Version
X-Envoy-Decorator-Operation
X-Qloud-Router
Memcached
L5d-Success-Class
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Xrds-Location
X-EC-Lua
X-DPWN-IS-SECURE
X-DefElseHash
X-DefHash
Platform
Adler-Geo
Candidate-Md5Url
X-Varnish-Remaining-TTL
X-Varnish-CookieINHashed-On
X-Varnish-CookieHashed-On
Datacenter
Is-Eu
X-Tx-Id
X-Mvc-Supplant-OutputCached
X-Origin
NM-Fastcgi-Cache
X-Variation
X-NWS-UUID-VERIFY
X-Ua-Device
X-Cache-Enabled
X-NC
X-CLOUD-TRACE-CONTEXT
X-API-Version
X-CS
Pics-Label
X-Backend-TTL
X-Vc
X-Up
X-LB-ID
WWW-Authenticate
X-Varnish-Beresp-Ttl
On-Server
CDN
Time
X-GeoIP-Region-Code
Esi-Enabled
Ms-Author-Via
Memory
NtCoent-Length
X-DynaTrace-JS-Agent
X-Refresh
X-GeoIP-Country-Code
X-Trace-ID
X-Tt-Logid
X-TraceId
X-Datadome
X-Tb-Optimization-Total-Bytes-Saved
X-LB-NoCache
X-Edge-Pop
Magicmarker
X-Generated-In
X-Service
Env
C-Via
X-Via-Popv
GeoIp-Country-Code
X-Via-Poph
WebServer
X-Via-Popn
X-TA-CDN-Provider
X-Varnish-Ttl
X-Dynatrace
X-Parent-Response-Time
X-CacheTTL
X-Varnish-Beresp-TTL
Kp-EeAlive
X-Optimistic-Header
S-Rt
X-Cache-PHP
X-Restarts
X-DC
X-Render-Time
X-MSEdge-Flight
X-RSL
X-RPM
X-Esi
X-Cache-Backend
Edge-Cache
X-MSEdge-Features
X-Cache-Status-Check
X-RPS
X-DI
X-Action
X-DSS
X-DW
X-Cs
X-DB
X-Servedbyhost
X-Wix-Viewer-Type
X-Srv
X-TX-ID
X-ZONE
X-Unique-ID
Server-ID
X-Minions-Version
X-Info
X-Http-Reason
X-Akamai-Request-ID2
X-AIR-PT
X-VCL-Version
X-Newrelic-Synthetics
X-Clientip
X-Li-Proto
X-App
Proxy-Connection
X-Cache-Ttl
X-HA-Backend
X-FPC
X-B3-Spanid
X-LiteSpeed-Cache-Control
X-URL
Accept-Language
HIT
Cache-Host
X-Oss-Hash-Crc64ecma
UCS
Test
X-Fpc
X-LI-Proto
X-Webkit-Csp-Report-Only
X-Oss-Object-Type
X-Oss-Request-Id
Server-Id
X-Oss-Server-Time
X-Oss-Storage-Class
X-Traceid
X-Ec-GeoHdr
X-Ec-Fail
X-User
X-Vcl-Version
S-Cnection
Locale
X-Urbn-Site-Id
X-Urbn-Context-Path
X-Webkit-CSP-Report-Only
X-NODE
Tcn
Geo-Info
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
Section-Io-Id
Lb
Section-Origin-Responded
Fastly-Backend-Name
User-Agent
X-Micro-Cache
X-Pass-Why
X-CSRF-TOKEN
Fastly-Drupal-HTML
X-Pad
X-Backend-Host
X-AK-Request-ID
X-LiteSpeed-Tag
X-HostName
Hostname
Cdnsip
M-TraceId
Cf-Int-Pingora-Origin-Digest
Cdncip
X-Ha-Backend
Resin-Trace
X-Fmm-Version
Geoip-Latitude
My-App
X-ServedByHost
X-Clara-WADP
Cluster
X-WADP-Cache
X-APP
X-Release
X-BCube-Filmed-By
X-BBC-Origin-Response-Status
X-ID
X-B3-Traceid
Ohc-File-Size
X-Var-Ttl
X-CUA
X-Via-PopN
X-Via-PopV
X-Check-Cacheable
Hit
X-Via-PopH
Tracecode
GeoIP-Country-Code
X-ES-SERVER
X-Geo
X-NGINX-Cache
X-Dynatrace-Js-Agent
X-From
VNS-Age
X-Amz-Meta-Cb-Modifiedtime
VNS-Cache
X-Edge-POP
Lfy
X-ElasticPress-Query
MIME-Version
X-WA-Info
T-Server
EpKe-Alive
X-WA
Path
X-Cdn-Forward
ENV
CPC-Cache
Cache-Key
CPC-Age
X-Edge-Cache
X-Fragments
Load-Balancing
X-RAMCache
Lang
X-Api-Version
X-HS-Status
Srv
X-Akamai-Pragma-Client-IP
X-WP-CF-Super-Cache-Cache-Control
X-ServerName
X-WP-CF-Super-Cache
Shield-Pop
X-UP
X-Wikidot-Backend
Pagetype
Servername
X-PJAX-URL
X-Cms-Context
X-Wikidot-Static-Cache
Target-Params
X-Fastly-Backend-Reqs
URI
X-Ucs
DataCenter
MD5-Digest
X-GoCache-CacheStatus
X-CCDN-Origin-Time
Uri
X-CCDN-CacheTTL
X-Hcs-Proxy-Type
X-Via-Ucdn
X-Fastly-Cache-Hits
X-Mcache
X-Lb-Id
X-Dw-Trace-Id
Sid
X-TRACE-ID
X-SIPLIST1
X-VC
Cdn
X-B3-ParentSpanId
Server-Ext
Cneonction
X-RateLimit-Reset
X-Cdn-Request-ID
WZWS-RAY
PICS-Label
IsBot
Ohc-Cache-HIT
X-Nc
Sever-Int
Server-Hostname
X-VG-WebServer
X-Acquia-Application-Trace
X-Swift-Error
X-Acquia-Application-UUID
X-Acquia-Purge-Tags
X-Acquia-Site
W
X-Apw-Access-Token
X-Httpd
X-Apw-Hits
X-Apw-Access-Object
X-Apw-Access-Action
X-Newrelic-App-Data
FSS-Cache
X-Lb-Nocache
X-Contensis-Viewer-Groups
X-Cache-ASPX
X-Cache-Expires
CF-Cached-On
Vha6-Origin
X-Yottaa-OS
X-Proxy-Cache-Info
Cf-Ipcountry
X-Snapshot-Date
Cteonnt-Length
X-Air-Pt
X-Cache-Ngx
X-Last-Modified
Permissions-Policy
X-Http-Duration-Ms
Server-Ttl
X-Http-Count
X-Te-Count
X-Te-Duration-Ms
X-Akamai-ERRuleID
X-Akamai-ERPolicy
ServerName
X-Akamai-Request-ID
X-Platform-Router
X-Provided-By
X-B3-Parentspanid
X-Platform-Processor
X-Platform-Cluster
Dnion-Transfer-Encoding
HitType
X-Miniprofiler-Ids
X-Varnish-Authentication
CountryCode
X-Sentry-ID
Req-ID
X-UA
X-Logging-Id
X-CacheKey
Ngx