Threat Level: green Handler on Duty: Daniel Wesemann

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
Pragma
X-Powered-By
X-XSS-Protection
CF-RAY
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
P3P
X-Cache-Hits
X-UA-Compatible
Alt-Svc
X-Xss-Protection
X-Served-By
CF-Ray
X-Download-Options
X-Timer
X-Request-Id
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
Access-Control-Allow-Credentials
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
X-Drupal-Cache
X-Generator
X-Cache-Status
X-Check
X-Cacheable
X-Envoy-Upstream-Service-Time
X-DNS-Prefetch-Control
X-Request-ID
Timing-Allow-Origin
X-FRAME-OPTIONS
X-Iinfo
X-Dns-Prefetch-Control
X-Drupal-Dynamic-Cache
Feature-Policy
X-Content-Security-Policy
Content-Encoding
Access-Control-Expose-Headers
Upgrade
Status
X-CDN
X-AspNetMvc-Version
Server-Timing
X-XSS-PROTECTION
Access-Control-Max-Age
X-Amz-Request-Id
Request-Context
X-Amz-Id-2
X-Turbo-Charged-By
X-AH-Environment
X-Via
X-Robots-Tag
X-Backend
X-Cache-Group
Cf-Edge-Cache
Host-Header
Keep-Alive
X-Proxy-Cache
X-Hacker
X-Server
X-Rq
X-UA-Device
X-Age
X-Server-Powered-By
X-Vhost
Allow
X-Varnish-Cache
X-Ws-Request-Id
EagleId
X-Dispatcher
X-Amz-Version-Id
Grace
Cf-Apo-Via
P3p
X-LiteSpeed-Cache
Nel
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Page-Speed
X-Device
Cf-Railgun
EagleEye-TraceId
X-Swift-CacheTime
X-Swift-SaveTime
X-Aws-Lambda-Call-Status
Ali-Swift-Global-Savetime
Accept-CH
X-WebKit-CSP
X-Pingback
X-Node
X-Host
X-Server-Id
Surrogate-Control
X-OneAgent-JS-Injection
X-Backend-Server
X-CST
X-Readtime
X-Nginx-Cache-Status
X-Akam-SW-Version
X-Content-Security-Policy-Report-Only
Permissions-Policy
Request-Id
X-Cache-Lookup
X-Application-Context
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Nginx-Upstream-Cache-Status
X-Cloud-Trace-Context
X-Trace
X-Response-Time
X-Edge
Accept-Ch-Lifetime
X-HW
Accept-CH-Lifetime
X-Litespeed-Cache
X-Ua-Compatible
X-Mod-Pagespeed
Content-Location
X-Url
X-Clacks-Overhead
X-Oneagent-Js-Injection
X-Midtier
X-ECACHE
X-Ruxit-JS-Agent
X-ESI
X-Mcache
Rating
X-Amz-Server-Side-Encryption
X-Country
X-Upstream
X-Vname
X-PC
X-TtlSet
Xkey
X-Vcap-Request-Id
X-MS-InvokeApp
Cache-Tag
X-D2id
X-Rack-Cache
Verso
X-Element-Page-Cache
Fastly-Restarts
X-Cache-TTL
X-Use-Magma
X-Kinja-Build
X-Kinja
X-GoogleNews-Bot
X-Exp-Variant
X-Exp-Id
X-Kinja-Revision
X-Kinja-Server
X-Cdn-Fetch
Edge-Control
RTSS
X-Content-Type
X-Powered-By-Plesk
X-Ruxit-Js-Agent
X-VARITI-CCR
Origin-Trial
X-Ac
X-Navigation-Version
X-Cached
X-Abt-Application-Version
X-WebKit-CSP-Report-Only
X-Goog-Hash
Accept-Ch
Service-Worker-Allowed
X-GitHub-Request-Id
X-Ttl
X-Country-Code
X-Amz-Rid
Display
X-Sol
X-Middleton-Display
Pagespeed
X-Mg-S
X-Dw-Request-Base-Id
X-SharePointHealthScore
X-Browser-Type
SPRequestGuid
X-Server-Name
Arr-Disable-Session-Affinity
X-B3-TraceId
Cross-Origin-Opener-Policy
X-Varnish-TTL
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Instrumentation
X-Powered-CMS
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
AR-Request-ID
AR-PoweredBy
AR-SID
Response
X-Middleton-Response
AR-ATIME
X-Amzn-Trace-Id
SPIisLatency
SPRequestDuration
X-Cache-Key
X-Ua-Device
AR-CACHE
X-Fastly-Request-ID
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-ORACLE-DMS-ECID
X-Cnection
X-ORACLE-DMS-RID
X-Version
X-Jurisdiction
X-HP-Trace-Id
X-HP-Webp
X-NF-Request-ID
X-Accel-Expires
X-Fastcgi-Cache
X-T
Front-End-Https
Cache-Tags
X-Times
Cache-Status
Edge-Cache-Tag
X-Ser
X-Px
X-MSEdge-Ref
Pinterest-Generated-By
Pinterest-Version
X-Pinterest-Rid
Public-Key-Pins
X-Client-IP
X-Hits
Nginx-Cache
X-Recruiting
MRF-Tech
Mrf-Cache-Status
X-RateLimit-Remaining
X-B3-TraceId-Primal
X-Shield-Request-Id
X-Request-Processing-Time
X-Frontend
X-Request-Received
Access-Control-Request-Method
Server-Node
X-LLID
X-Ua-Browser
X-NWS-LOG-UUID
X-B3-Traceid
Payment
X-Webkit-CSP
X-DIS-Request-ID
TP-Cache
X-RateLimit-Limit
S
X-HS-Combine-CSS
X-HS-Hub-Id
X-HS-Cache-Config
X-HS-Content-Id
MicrosoftSharePointTeamServices
X-Goog-Metageneration
TP-L2-Cache
X-Content-Digest
X-LB-Cache
X-Webkit-Csp
Content-MD5
X-Distributor
X-Erf-Stays-Pdp-Viaduct-Migration-Web
Realpath
X-Kinja-CCPA
X-Hostname
X-Microsite
X-Request-Handler-Origin-Region
X-Geo-Country
X-Ezoic-Cdn
X-Forwarded-For
X-Page-Id
Access-Control-Allow-Method
X-FastCGI-Cache
Accept-Charset
X-FB-Debug
Fastcgi-Cache
X-Envoy-Decorator-Operation
X-PressLabs-Stats
X-GUploader-UploadID
X-Webkit-CSP-Report-Only
X-Cluster-Name
X-Rid
X-Correlation-Id
X-Protected-By
TCN
X-Seen-By
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Ratelimit-Remaining
Cleartype
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
X-B3-Sampled
DC
X-Origin-Server
X-Origin-Cache
X-XRDS-Location
X-Debug-Info
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Goog-Generation
X-Newrelic-App-Data
X-Mobile
Referer-Policy
X-Varnish-Backend
X-Logged-In
X-Git-Hash
X-Ratelimit-Limit
X-Edge-Location-Klb
X-Kinsta-Cache
Cross-Origin-Resource-Policy
X-Azure-Ref
Alternate-Protocol
X-TTL
X-Contextid
X-Varnish-Grace
X-Revision
X-Aspnet-Version
Surrogate-Key
X-Fb-Rlafr
X-App-Environment
Healthy
X-Providence-Cookie
X-Request-Guid
X-Is-Crawler
X-Route-Name
X-Amz-Replication-Status
X-Grace
X-Aspnet-Duration-Ms
X-Flags
X-TT
X-Content-Options
X-Amz-Meta-S3cmd-Attrs
Count-Hit
X-Server-ID
X-Forwarded-Proto
X-Whom
X-Wix-Request-Id
X-IPS-LoggedIn
Charset
Filterid
MS-Author-Via
X-Akamai-Edgescape
Viewport
Frame-Options
X-Client-Ip
X-App-Server
X-Id
WPO-Cache-Message
WPO-Cache-Status
X-Hosted-By
X-B
Paypal-Debug-Id
X-Magnolia-Registration
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Backend-Name
X-Trace-Id
X-AppVersion
X-Activity-Id
X-Cache-Control
X-Az
X-Www-Served-By
X-Daa-Tunnel
X-Cache-Age
Retry-After
Section-Io-Cache
Server-Name
X-F-Cache
X-Type
Refresh
Amp-Access-Control-Allow-Source-Origin
X-Proxy-Cache-Info
X-Upgrade-Enabled
X-Varnish-Ttl
X-Varnish-Server
Version
X-Proxy
X-Http-Reason
X-Rule
X-Cache-Rule
Akamai-GRN
X-ARC
Host
SD-X-WS
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Original-Request-Id
X-Response-Served-From
X-App-Version
X-Varnish-Age
X-User-Agent
Protected
Front
X-Akamai-Request-ID2
X-Edge-Location
X-Instance
X-UUID
X-Status
X-Rocket-Nginx-Serving-Static
X-Environment-Context
X-Framework
X-Unique-Id
X-Cacheable-TTL
X-L-Path
X-Region
X-EdgeConnect-Cache-Status
X-Is-Bot
X-Jobs
SRV
X-Rendered-As
X-Cache-Grace
X-FW-Serve
X-FW-Hash
Fastly-SWR
Access-Control-Request-Headers
X-Source
From-Origin
X-Cache-Time
X-N
X-Oracle-Dms-Ecid
X-FW-Dynamic
X-FW-Type
X-FW-Static
X-FW-Server
X-Page-View
X-FW-Version
Fastly-SIE
X-G
X-Oracle-Dms-Rid
X-Adobe-Content
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Time
X-Tumblr-User
X-Adobe-Loc
X-Tumblr-Pixel-1
X-ProcessESI
X-RemovedCookies
X-Load-Cache
ServerID
X-COUNTRY
Content-Disposition
X-Drupal-Cache-Tags
X-CDN-Forward
Country
X-Language
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
X-Datadog-Trace-Id
X-RateLimit-Reset
X-HTML-Minification-Powered-By
X-Tt-Trace-Host
X-Tt-Trace-Tag
Accept-Language
X-Vcache
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-DynaTrace
X-Datadog-Sampled
X-Amzn-Remapped-Content-Length
X-DataDome
Liferay-Portal
X-DynaTrace-JS-Agent
X-Debug-IsConnected
X-Mg-Request-UUID
Countrycode
X-Debug-IsPreview
X-Generated-By
X-B3-SpanId
X-ID
X-Nf-Request-Id
Backend
Xet-Cookie
CF-IPCountry
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
X-ECache
X-Nginx-Cache
X-Drupal-Cache-Contexts
Xserver
X-Tt-Logid
Webserver
X-B-Cache
X-Device-Type
X-Mode
X-NYM-Debug-Backend
X-Signature
X-Content-Powered-By
X-Zen-Fury
X-Httpd
GEO-INFO
X-Servername
X-Ratelimit-Reset
Url
X-Erf-Web-Scheduler
X-Content-Age
X-Cache-Operation
X-Urbn-Context-Path
X-LAGOON
X-JoinUs
X-Git-Commit
X-Urbn-Site-Id
X-SaId
X-Cache-Action
X-Sucuri-ID
X-Sucuri-Cache
X-ServerID
X-UPSTREAM-Address
Azure-InstanceId
Azure-RegionName
Meta-Geo
Locale
Onion-Location
S-Rt
X-Container-Uri
Load-Balancing
X-Director
Azure-SiteName
Azure-SlotName
Azure-Version
Filters
X-Varnish-Cache-Hits
X-Rewrite-Enabled
X-Soup
X-Tb
X-Say-Cacheable
X-Say-TTL
X-SayCDN-TTL
X-Storage
X-Proto
X-Varnish-Hostname
Uber-Trace-Id
X-Cluster-Node
X-Labrador-Cache-Channel
X-Served-From
X-Ms-Request-Id
X-Xrds-Location
X-Detected-As
Web-Mar-Node
X-VC-Cache
X-Forwarded-Host
X-XRDS-LOCATION
X-Generation-Time
X-Logging-Id
X-Ms-Version
X-PHP-Host
X-RM-Cache-TTL
X-VCT
X-Sql-Count
X-Sql-Duration-Ms
DB-Nickname
Mn-Server-Ip
X-GeoCode
Webcakes-App-Version
X-GeoCountry
Node
X-Extlb
Property-Id
TWC-Locale-Group
TWC-Privacy
X-Adobe-Source
TWC-GeoIP-LatLong
TWC-GeoIP-Country
X-Cache-Server
TWC-Connection-Speed
TWC-Device-Class
Fastcgi-Useragent
X-Zipkin-Id
X-Skip-Cache
X-RCS-CacheZone
X-Routing-Service
X-Proxied
Webcakes-App-Name
X-Origin-Hint
Webcakes-Region
X-R9-Blue-Green-Version
X-LSADC-Cache
X-Proxy-Build
X-Tumblr-Pixel-3
X-Timing-Wait
X-Fetched-On
X-Tumblr-Pixel-2
X-FB-TRIP-ID
X-Uri
X-Debug
X-Format
Selected-Fe
CDN-RequestId
X-Tec-Api-Root
Fastly-Drupal-HTML
X-Tec-Api-Origin
X-Tec-Api-Version
X-MP-GENERATED-AT
X-Lambda-Id
X-Cache-Expired-At
X-Origin-Date
X-Via-JSL
OT-Force-Account-Verify
Source
X-NGENIX-Cache
X-Template
X-Cache-Hit
X-Varnish-Hits
X-MCACHE
X-Node-Name
Content-Secure-Policy
X-Cache-TTL-Remaining
X-AIR-PT
X-Pass-Why
X-UA-Device-Type
X-Tncms
X-Loop
X-Ua
X-Endurance-Cache-Level
X-Pubstack
Upgrade-Insecure-Requests
X-Srv
Cross-Origin-Window-Policy
X-Redis-Cache
NGB
X-Server-W
X-Origin-CC
X-Origin-TTL
X-PHP-Backend
X-Real-IP
X-Fastly-Request-Id
Cache-Hits
X-CCDN-CacheTTL
X-CCDN-Origin-Time
X-Hcs-Proxy-Type
Section-Origin-Responded
Section-Io-Origin-Time-Seconds
Section-Io-Id
X-RTag
X-Cache-Host
MS-CV
Section-Io-Origin-Status
Ms-Operation-Id
Cache-Name
X-GEO
Cache-Provider
X-Restarts
X-S
X-Cms-Context
X-Reqid
X-Xfnlog-Site
X-IPLB-Instance
Apigw-Requestid
X-Optimistic-Header
X-IPLB-Request-ID
X-CACHE-AGE
X-Cache-Type
CDN-RequestPullCode
CDN-RequestPullSuccess
CDN-Uid
CDN-EdgeStorageId
CDN-RequestCountryCode
CDN-CachedAt
CDN-Cache
CDN-PullZone
X-ProxyCache-Key
X-BYPASS-REASON
X-No-Session
X-ProxyCache-Status
X-Hl-Ver
X-CSRF-Token
X-Datadome
X-Aspnetmvc-Version
X-Presslabs-Stats
X-VWS-Id
X-Via-Fastly
X-Newrelic-Synthetics
X-LJ-Flow-ID
X-Cluster
X-AWS-Id
X-Access
X-Section
X-Rn-Rsrv
X-Eu-Site
Redirect-Candidate
DCR-Decision-By
X-Epic-Correlation-Id
T-Server
Rendered-Blocks
Surrogated-Key
DCR-Processing-Time-Ms
X-Fastly-Backend
X-FC-Vary-Parameters
X-External-Request-Id
X-Forwarded-Path
Fastly-Backend-Name
X-GeoIP-Region-Code
Fastly-GeoIP-CountryCode
X-Tenant
Server-Host
X-GeoIP-Country-Code
X-Application
X-Ec-GeoHdr
X-B-Cookie
X-Wikidot-Static-Cache
X-Gdpr
Xc-Version
X-Ec-Custom-Error
X-CF-Lambda-Fn
X-Cdn-Diag
X-CF-Lambda-Version
BehaviorPad-Version
X-CGP
X-CacheTTL
X-Cache-NE
X-BCube-Filmed-By
X-Cache-Bucket
X-Cache-Info
Candidate-Md5Url
Canary
X-Bc-Bl
CPC-Age
X-Destination
X-Debug-Cache-Store
X-Developer
X-Dispatcher-Number
Gannett-Cam-Experience-Id
Sslversion
X-Debug-Cache-Fetch
CPC-Cache
X-Conf
X-Csrf-Jwt
X-D
X-Date
X-Ec-Fail
X-Irp-Debug
X-A-Dam
X-Var-Ttl
X-ScT
X-SD-PageType
Mail-Subject
Magicmarker
VNS-Age
X-Vdms-Path
Vix-Hermes-Req-Id
X-VG-WebCache
X-Vdms-Version
X-Proxy-Cache-Status
X-S-Cookie
X-Rojux
X-Shop-Environment
MD5-Digest
W
X-SRCache-Key
Ngx.Var.Host
Web-Mar-Region
We-Hiring
N-Cache
Meta-Geo-Continent
VNS-Cache
X-Slack-Backend
X-A-Ccd
X-Slack-Shared-Secret-Outcome
X-A
X-TIM-N
Odigeo-Trace-Id
X-Wikidot-Backend
X-A-Dcw
X-Accel-Expires-Debug
X-Orig-Expires
X-Origin-Time
X-Bl-Debug
L
X-Aed
HA-Ipaddr
Gh-Request-Id
X-We-Are-Hiring
X-Mvc-Supplant-Cachable
Ha-Gx-Prefs
X-Nyt-Route
L5d-Success-Class
X-A-Wwc
X-Viewer-Country
X-Akamai-Transformed
X-A-Dgt
X-RateLimit-Limit-Second
X-Request-Host
X-RateLimit-Remaining-Second
X-Vtex-Remote-Cache
X-Policy
Lang
TDXMobile
Thinkindot-CacheControl
X-Bip
Thinkindot-Control
Thinkindot-CacheControl-Type
X-Alternate-Cache-Key
X-BBC-Edge-Cache-Status
X-App-Name
X-ApacheServer
X-Auto-Login
X-Level-Front-Cache
X-SVT-ORM-RULES
X-Storefront-Renderer-Rendered
X-SVT-ORM-VERSION
X-Test
X-Thanos
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Server-IP
X-S-Maxage
X-ShardId
X-ShopId
X-Shopify-Stage
X-Thinkindot-L3
X-Up
X-Is-Gdpr
X-Has-Esi
X-JWT-State
X-Wix-Viewer-Type
X-Worker
X-Accel-Buffering
True-Client-Country-4JS
X-Varnishpool
X-VG-TLSProxy
X-WADP-Cache
Fastly-SSL
X-Request-Time
X-Pool
X-Generated-On
X-Forwarded-Site
X-Geo-Header
X-Gzip
X-Handled-By
X-Fmm-Version
X-Esi-Check
X-Clara-WADP
X-Cache-Id
X-CMSURLCustom
X-Core-Mission
X-Core-Value
X-Hash
X-Human
X-Owner
X-Origin-Response-Time
X-PAYTM-SRV-ID
X-PERF
X-Platform
X-Org
X-Old-Content-Length
X-INCAP-ABP
X-Mid
X-Mly-Id
X-Node-Id
X-Cache-Debug
X-Clientip
Machine
Memcached
Origin
Release
X-TimeS
Environment
AKAMAI
Cmsid
Cmstype
Datacenter
Req-Svc-Chain
Host-ID
X-TIME
WP-Super-Cache
X-Vcl-Version
X-Web-Node
User-Cache-Control
X-Block-Status
CloudFront-Viewer-Country
X-Origin
X-Mvc-Supplant-OutputCached
X-TA-CDN-Provider
X-Cdn-Origin
Server-Ext
Country-Code
DSUID
X-DPWN-IS-SECURE
X-DefElseHash
X-From
Server-Hostname
X-DefHash
X-Scale
Apple-News-Services-Parsed-Url
Expect-Staple
Apple-News-Services-Host
Apple-News-Services-Handled
X-WA-Info
ServedBy
Apple-News-Services-Request-Url
X-Device-Os
Producers
X-Nginx-Cache-Key
Platform
Is-Eu
X-Cdn-Srv
X-Dispatcher-Server
CDCHOST
X-Gen-Mode
X-Variation
NM-Fastcgi-Cache
X-Parent-Response-Time
Esi-Enabled
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-Hnp-Log
X-VServer
X-Vmg-Version
X-Varnish-Remaining-TTL
X-NodeID
X-Sn-Servicetimems
X-Qloud-Router
Adler-Geo
X-Loc
X-Nananana
Sever-Int
X-Air-Hostname
X-Air-Trace-Id
X-Air-Source
C-Via
X-App
Pics-Label
Ssr
X-GeoIP
Origin-EX
Origin-CC
X-Nitro-Cache
X-NCache
Wxu-Next-Commit
Wxu-Next-Hostname
Wxu-Next-Region
X-LB-NoCache
X-Akamai-Device-Characteristics
X-Azure-Ref-OriginShield
X-Instance-Name
X-Cs
X-Op-Id-All
Server-Info
X-Amz-Meta-Cb-Modifiedtime
Memory
X-Cache-Enabled
X-Refresh
Time
Server-ID
X-Tx-Id
AMP-Access-Control-Allow-Source-Origin
Cache-Host
X-Cache-Status-Check
X-HA-Backend
X-Platform-Cluster
X-Platform-Processor
X-Platform-Router
X-Microcachable
X-Site-Version
X-Locale
X-Correlation-ID
X-Origin-Expires
NGX
XM
Hostname
X-HN
PFcat
GeoIP-Latitude
X-VarnishDD-TTL
X-VHOST
X-Tb-Optimization-Total-Bytes-Saved
X-API-Version
X-Dc
Cf-Device-Type
X-CACHE-GROUP
Origin-Agent-Cluster
Resin-Trace
X-ZONE
X-DC
X-Via-CDN
X-Via-SSL
X-Via-Edge
Srvid
A
X-Varnish-Beresp-Ttl
X-Varnish-Beresp-Grace
Locid
X-FL-EDGE
Edge-Copy-Time
X-FL-QIT-DEBUG
X-Ad-Defer-Variation
X-Zone
X-Wp-Cf-Super-Cache-Active
X-Fpc
YJS-ID
X-Vgn-Hpd-Reason
X-Upstream-Ct
X-Upstream-Ht
Cdn-Requestid
X-FireWall-Port
X-Internal-Host
X-Webkit-Csp-Report-Only
X-ATG-Version
Sid
Cache-Key
X-Micro-Cache
X-Contensis-Viewer-Groups
X-Cache-ASPX
X-WP-CF-Super-Cache-Active
X-Github-Request-Id
Uri
X-DataCenter
X-Varnish-Authentication
X-Moov-Xdn-Version
X-Moov-T
X-Cached-By
X-Pod-Name
X-TraceId
User-Agent
True-Client-Ip
X-LiteSpeed-Cache-Control
X-Provided-By
X-SIPLIST1
State
X-Planisys-CDN-TTL
X-Planisys-CDN-Cache
X-HS-Content-Campaign-Id
IsBot
X-Info
X-Planisys-CDN-Rules
X-AB
Location
X-B3-Spanid
X-URL
X-Buckets
X-B3-Parentspanid
X-Fastly-Cache
GeoIP-Country-Code
X-RN-RSRV
X-Platform-Server
X-Sigma
X-NGINX-Cache
X-Release
X-Cache-Remote
X-VC
X-VCache
X-Sigma-Backend
X-Geo-Region
X-Backend-Instance
X-Nitro-Rev
GeoIp-Country-Code
X-Nitro-Cache-From
X-Rocket-Build-Number
X-LiteSpeed-Tag
SID
X-Api-Version
X-CS
X-Accel-Version
X-CSRF-TOKEN
X-Datacenter
X-MSEdge-Features
X-MSEdge-Flight
Cdn
Cache
X-FTR-Request-ID
CF-Ctrl
NtCoent-Length
XServer
X-Geo
X-Gamma-Serve
X-Generated-In
True-Client-IP
Srv
X-NewRelic-App-Data
X-Vgn-Hpd-Ssi
X-Vgn-Hpd-Variations-Key
X-GeoIP-City
X-Vgn-Hpd-Cached
Lb
Path
Cache-Tv-Group
X-Is-Mobile
X-Browser-Name
X-Is-Desktop
X-Tcp-Rtt
X-Is-Tablet
X-Is-Supported-Browser
X-SRV
X-Scheme
X-Rebelmouse-Surrogate-Control
X-TRACE-ID
X-Rebelmouse-Cache-Control
X-HS-Status
CountryCode
X-Hyper-Cache
Kp-EeAlive
HostName
X-FPC
Epwk-X-Cache
Fastly-Drupal-Html
X-Frame-Option
X-HostName
Tcn
X-Amz-Meta-Opti
X-GoCache-CacheStatus
Ohc-File-Size
X-Service
X-Mobile-URL
X-Location
X-APP-VERSION
Serverid
X-TX-ID
X-UA
Cf-Ipcountry
X-Men
X-AK-Request-ID
On-Server
Cdncip
Cdnsip
X-Webstats-RespID
X-Aicache-OS
X-Air-Pt
CacheControlHeader
X-Region-Sid
X-Esi
X-Developers
X-Guploader-Uploadid
Tube-Got-Results
Tube-Got-Eval
Tube-Return
V-Age
X-LB-ID
X-Traceid
X-V-Cache
X-Cache-Ttl
X-Via-Popv
X-Via-Popn
X-Branch-Name
Tube-Get-Contents
WebServer
X-CDN-Cache-Status
X-Via-Poph
X-Minions-Version
RNT-Time
X-Wp-Cf-Super-Cache
X-Acquia-Purge-Cdn-Unconfigured
X-Cache-Tags
Click-Count-Error
X-B3-Trace-ID
X-EC-Lua
RNT-Machine
Proxy-Connection
X-Wp-Cf-Super-Cache-Cache-Control
Mime-Version
X-Req
X-SB
X-Cache-FS-Status
Click-Count-Action-Start
X-Wp-Cf-Super-Cache-Cookies-Bypass
Env
X-Vc
X-Cdn-Cache-Status
X-Pad
WZWS-RAY
WWW-Authenticate
X-Proxy-CacheRZ
XkeyRZ
ENV
X-Servedbyhost
X-Nc
Yak-Timeinfo
Ohc-Cache-HIT
X-Wa
CDN
X-VCL-Version
X-CACHE-KEY
X-Edge-Server
LB
X-Vercel-Cache
Cdn-Host
Geoip-Latitude
X-Fastly-Country-Code
Cdn-Request-Time
X-Vercel-Id
X-User
X-NWS-UUID-VERIFY
X-Edge-Pop
X-Akamai-Pragma-Client-IP
CF-Cached-On
Ngx
X-Cdn-Forward
X-Check-Cacheable
X-Lb-Cache
M-TraceId
Req-ID
X-Country-Code-Real
Content-Style-Type
X-Ha-Backend
X-Ckpd-Fst-Backend
Server-Id
X-Origin-Cache-Key
X-Processor
Content-Script-Type
X-FTR-Backend-Server
X-FTR-Balancer
X-TH-Server
X-NMSegId
X-FTR-Expires
X-WP-CF-Super-Cache-Cookies-Bypass
X-FTR-Backend
X-FTR-Cache-Status
X-TT-LOGID
X-Acquia-Site
X-MiniProfiler-Ids
PICS-Label
HIT
X-APP
X-Dw-Trace-Id
X-Lb-Nocache
X-Acquia-Purge-Tags
X-Litespeed-Cache-Control
X-Cdn-Request-ID
X-Edge-POP
X-Ad-Load-Variation
X-Render-Time
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
Cluster
X-Acquia-Application-UUID
X-Snapshot-Date
X-Acquia-Application-Trace
X-CUA
X-Via-Ucdn
Yjs-Id
X-Miniprofiler-Ids
X-Request-Start
Cneonction
Log-Origin
X-Fastly-Backend-Reqs
X-Response-By
CACHE-MISS-TO-ORIGIN
Sm-Log-Id
Edge-Cache
X-Service-Response-Time
X-Serial
X-Iauth-Set-Uid
Inserted-Into-Cache-At
X-Fastly-Cache-Hits
X-M-Reqid
X-RAMCache
X-Udemy-Cache-App-Namespace
X-M-Log
X-ElasticPress-Query
Vha6-Origin
X-Cached-Since
X-Cache-Date