Threat Level: green Handler on Duty: Johannes Ullrich

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-Cache-Status
Link
Accept-Ranges
CF-RAY
ETag
Expect-CT
Pragma
X-Powered-By
X-XSS-Protection
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
Alt-Svc
X-Served-By
X-Xss-Protection
X-Download-Options
X-Timer
X-Request-Id
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Cache-Status
X-Generator
X-Cacheable
Timing-Allow-Origin
X-Content-Security-Policy
X-Iinfo
Feature-Policy
Status
X-Envoy-Upstream-Service-Time
Content-Encoding
Access-Control-Expose-Headers
P3p
X-Drupal-Dynamic-Cache
X-Request-ID
X-CDN
X-AspNetMvc-Version
Upgrade
X-Via
CF-Ray
X-Ws-Request-Id
Access-Control-Max-Age
Server-Timing
EagleId
X-Cache-Group
X-Turbo-Charged-By
Keep-Alive
Request-Context
X-UA-Device
X-Age
X-Server-Powered-By
X-Proxy-Cache
X-Backend
X-AH-Environment
Report-To
X-Robots-Tag
X-Hacker
X-Amz-Request-Id
Host-Header
X-Server
X-Amz-Id-2
Grace
X-LiteSpeed-Cache
X-Rq
X-Nginx-Cache-Status
X-Varnish-Cache
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-Dns-Prefetch-Control
X-WebKit-CSP
X-Page-Speed
X-Vhost
X-Ua-Compatible
EagleEye-TraceId
X-OneAgent-JS-Injection
X-Amz-Version-Id
X-Pingback
X-Dispatcher
NEL
X-Device
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Cache-Spec
X-Host
X-Server-Id
Cf-Railgun
X-Node
X-Backend-Server
Accept-CH
X-Readtime
Surrogate-Control
X-Akam-SW-Version
Request-Id
X-Response-Time
X-HW
Xkey
X-Application-Context
X-Ruxit-JS-Agent
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Content-Location
Rating
Accept-Ch-Lifetime
X-Country
X-B3-TraceId
X-Cloud-Trace-Context
Accept-CH-Lifetime
X-Cache-Lookup
X-Trace
X-Url
X-Ac
X-Content-Type
X-Vname
X-PC
X-TtlSet
Allow
X-Varnish-TTL
X-Clacks-Overhead
X-Mod-Pagespeed
Edge-Control
X-ESI
X-Server-Name
Fastly-Restarts
Cache-Tag
X-Aws-Lambda-Call-Status
X-FastCGI-Cache
X-VARITI-CCR
Service-Worker-Allowed
X-Rack-Cache
X-Element-Page-Cache
Verso
X-Upstream
MS-Author-Via
X-MS-InvokeApp
X-GitHub-Request-Id
X-Vcap-Request-Id
X-Amz-Rid
Public-Key-Pins
X-Cached
X-Dw-Request-Base-Id
X-Client-IP
X-D2id
X-Abt-Application-Version
X-Cache-TTL
X-Cnection
X-Px
Accept-Ch
RTSS
X-Navigation-Version
Arr-Disable-Session-Affinity
X-Country-Code
Access-Control-Request-Method
X-Powered-By-Plesk
X-NF-Request-ID
X-Exp-Id
X-Use-Magma
X-Kinja-Revision
X-Kinja-Server
X-Kinja-Build
X-Kinja
X-GoogleNews-Bot
X-Exp-Variant
X-Cdn-Fetch
X-Goog-Hash
X-Origin-Cache
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-Instrumentation
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
AR-CACHE
AR-Request-ID
AR-ATIME
AR-PoweredBy
X-Powered-CMS
AR-SID
X-Version
X-Middleton-Display
Display
X-Sol
Pagespeed
Response
X-Middleton-Response
X-Amz-Server-Side-Encryption
X-LLID
X-MSEdge-Ref
X-TTL
X-Edge-Location-Klb
X-Kinsta-Cache
X-SRCache-Store-Status
X-SRCache-Fetch-Status
Nginx-Cache
X-Edge
MRF-Tech
X-B3-TraceId-Primal
TCN
Mrf-Cache-Status
X-Protected-By
X-RateLimit-Remaining
X-T
X-HP-Webp
X-HP-Trace-Id
X-Jurisdiction
X-Forwarded-For
X-Shield-Request-Id
X-Content-Security-Policy-Report-Only
X-Aspnetmvc-Version
X-Id
X-Mg-S
Content-MD5
S
Edge-Cache-Tag
Fastcgi-Cache
X-Language
SPIisLatency
X-Mid
SPRequestDuration
Front-End-Https
Realpath
X-CST
X-Recruiting
X-Request-Processing-Time
X-Request-Received
X-Pinterest-Rid
Pinterest-Generated-By
X-DynaTrace
Filters
Pinterest-Version
Server-Node
X-MCACHE
Server-Name
X-Frontend
X-Ab
X-Content
X-Ua-Browser
X-Correlation-Id
X-Ttl
X-Ser
X-HS-Content-Id
X-HS-Hub-Id
X-HS-Cache-Config
X-NWS-LOG-UUID
X-HS-Combine-CSS
X-Yandex-Sdch-Disable
X-ECACHE
X-Ezoic-Cdn
SPRequestGuid
X-SharePointHealthScore
X-Cache-Key
X-Template
X-Hits
X-Parallel-Accel
Fusion-Source
Fusion-Content-Source
Fusion-Component-Id
Fusion-Content-Id
Fusion-Template-Id
Fusion-Deployment-Id
Alternate-Protocol
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Server-ID
Cache-Tags
MicrosoftSharePointTeamServices
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Ruxit-Js-Agent
Charset
Host
X-Page-Id
Cleartype
X-B3-Sampled
X-Content-Options
X-Git-Hash
X-Www-Served-By
X-Geo-Country
X-DIS-Request-ID
X-Debug-Info
X-Daa-Tunnel
X-Amzn-Trace-Id
X-Hostname
X-Amz-Replication-Status
X-Content-Digest
X-Fastly-Request-Id
X-Varnish-Age
X-Az
X-Ratelimit-Limit
X-AppVersion
X-Activity-Id
Filterid
X-FB-Debug
X-Upgrade-Enabled
X-VCache
X-Accel-Expires
X-Forwarded-Proto
Cross-Origin-Opener-Policy
X-Grace
X-N
X-Origin-Server
X-Rid
X-Nginx-Upstream-Cache-Status
ServerID
X-F-Cache
Access-Control-Allow-Method
TP-Cache
TP-L2-Cache
X-Mobile-URL
X-Route-Name
X-LB-Cache
X-Providence-Cookie
X-Is-Crawler
X-Request-Guid
X-Flags
X-Aspnet-Duration-Ms
X-TT
X-Whom
X-App-Environment
X-Varnish-Grace
X-Type
Viewport
X-Tb
X-WebKit-CSP-Report-Only
X-Seen-By
X-FW-Server
X-FW-Static
X-Goog-Metageneration
X-Goog-Storage-Class
X-XRDS-LOCATION
X-FW-Hash
X-Goog-Stored-Content-Encoding
X-FW-Dynamic
Node
Payment
X-FW-Type
X-Goog-Generation
X-FW-Serve
X-GUploader-UploadID
X-Goog-Stored-Content-Length
X-Distributor
DC
Paypal-Debug-Id
X-User-Agent
X-App-Server
Fastcgi-Useragent
X-DataDome
Accept-Charset
Country
X-Wix-Request-Id
X-NGENIX-Cache
X-Litespeed-Cache
X-Cache-Control
X-Origin-Upstream-Status
X-Fastcgi-Cache
X-Cache-Rule
X-Fastly-Request-ID
Version
X-Logged-In
X-Webkit-CSP
X-Request-Handler-Origin-Region
X-Via-JSL
X-Drupal-Cache-Tags
X-Microsite
Referer-Policy
X-Oracle-Dms-Rid
X-Oracle-Dms-Ecid
Amp-Access-Control-Allow-Source-Origin
X-Cache-Age
X-Cluster-Name
X-Signature
X-Buckets
Refresh
X-B-Cache
X-Erf-Bev-Bev
X-Browser-Type
X-Erf-Bev-Bev-Is-Generated
X-Load-Cache
Cache-Status
X-Varnish-Backend
X-Contextid
VIX-Pulpo-Upstream-Status
X-Original-Request-Id
X-Response-Served-From
SD-X-WS
VIX-Pulpo-Node
X-Node-Name
X-Vgn-Hpd-Reason
X-Real-IP
X-Page-View
X-Mobile
X-Cache-Expired-At
Access-Control-Request-Headers
X-B
X-Debug
X-Is-Bot
X-Rendered-As
X-Jobs
X-Cacheable-TTL
X-RemovedCookies
X-Device-Type
X-Yottaa-Optimizations
X-Instance
X-IPLB-Instance
X-Rule
X-UUID
X-Proxy-Cache-Status
X-Yottaa-Metrics
X-ProcessESI
X-Proxy
X-Revision
X-Ratelimit-Reset
X-Cache-Action
X-Tec-Api-Root
X-Tec-Api-Version
Surrogate-Key
X-Tec-Api-Origin
Akamai-GRN
X-Drupal-Cache-Contexts
NGB
X-Debug-IsPreview
X-Framework
X-Cache-Time
X-Debug-IsConnected
X-FW-Version
X-G
X-TEC-API-VERSION
X-Air-Trace-Id
CF-IPCountry
X-Air-Hostname
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Air-Source
SID
DynaTrace
GEO-INFO
X-Azure-Ref
X-PressLabs-Stats
Liferay-Portal
X-Accel-Buffering
X-Oneagent-Js-Injection
X-Nginx-Cache
X-Ms-Request-Id
X-Ms-Version
X-Source
X-Presslabs-Stats
Count-Hit
Uber-Trace-Id
Frame-Options
X-Cache-Operation
X-XRDS-Location
X-CDN-Forward
Ms-Operation-Id
Healthy
X-RTag
MS-CV
X-Cache-NGX
X-EdgeConnect-Cache-Status
X-APP-VERSION
X-Zen-Fury
Xserver
Countrycode
X-Mode
X-Cache-Hit
X-L-Path
X-Tumblr-Pixel
X-Varnish-Server
X-Environment-Context
X-Tumblr-User
X-Backend-Name
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
Cross-Origin-Window-Policy
Ec-Rule-Version
Protected
X-RateLimit-Limit
X-IPS-LoggedIn
X-Ratelimit-Remaining
X-Cache-TTL-Remaining
X-Region
X-Servername
X-Forwarded-Host
X-RN-RSRV
Backend
Meta-Geo
X-Tid
X-Detected-As
X-JoinUs
X-UPSTREAM-Address
X-Rewrite-Enabled
X-SaId
WPO-Cache-Message
Decoy-Debug-TTL
WPO-Cache-Status
X-Adobe-Loc
Eomportal-Instance
X-Sql-Count
X-Sql-Duration-Ms
LB
X-Cache-Server
X-Hyper-Cache
X-Extlb
X-Proxied
X-Cache-Grace
X-Debug-Cache
X-Generation-Time
X-Content-Age
X-Hosted-By
X-Content-Powered-By
X-ShardId
X-Uri
Decoy-Debug-Status
X-Shopify-Stage
X-Alternate-Cache-Key
X-Sorting-Hat-PodId
Country-Code
Decoy-Debug-Key
X-Adobe-Content
X-Sorting-Hat-ShopId
X-Zipkin-Id
X-Routing-Service
Apigw-Requestid
X-Redis-Cache
X-ShopId
Url
Mn-Server-Ip
Fastly-SSL
X-ApacheServer
Cache-Name
X-No-Session
X-Site-Version
X-Varnish-Beresp-Grace
X-PERF
X-Origin-Date
X-Format
X-FB-TRIP-ID
X-ServerID
X-PHP-Backend
X-Via-Fastly
X-Human
X-NCache
X-Status
Section-Io-Cache
X-Proxy-Build
Selected-Fe
X-NYM-Debug-Backend
X-ProxyCache-Key
TWC-Device-Class
TWC-Connection-Speed
X-Storage
TWC-GeoIP-Country
X-Origin-Hint
X-Pubstack
Property-Id
X-ProxyCache-Status
X-Server-W
X-OCL
X-Cache-Host
X-BYPASS-REASON
X-Akamai-Edgescape
X-UA-Device-Type
X-Timing-Wait
X-Cluster-Node
X-Cache-Type
X-Access
Webcakes-Region
TWC-Locale-Group
X-PCL
TWC-Privacy
X-Microcachable
Webcakes-App-Version
X-Section
TWC-GeoIP-LatLong
Webcakes-App-Name
Cache-Tv-Group
X-NewRelic-App-Data
CDN-RequestCountryCode
CDN-PullZone
CDN-RequestId
CDN-Uid
X-Varnishpool
CDN-EdgeStorageId
CDN-CachedAt
X-Say-TTL
X-Say-Cacheable
X-SayCDN-TTL
X-R9-Blue-Green-Version
CDN-Cache
X-Web-Node
X-Hl-Ver
Content-Disposition
X-Azure-Ref-OriginShield
Azure-SlotName
Azure-SiteName
Azure-RegionName
Azure-InstanceId
DB-Nickname
X-Generated-By
Content-Secure-Policy
Azure-Version
X-Be
X-Soup
X-Ua
X-Webkit-Csp
X-LSADC-Cache
X-TIME
X-Trace-Id
OT-Force-Account-Verify
X-Nginx-Cache-Key
X-Cached-By
Source
SRV
X-TT-LOGID
Retry-After
X-Bc-Bl
Cache
X-Unique-Id
X-Dc
X-Auto-Login
X-LAGOON
X-GEO
X-Platform-Server
X-SRV
X-Cache-Remote
X-Akamai-Transformed
Xet-Cookie
X-Varnish-Hits
X-Xfnlog-Site
Mime-Version
Cache-Hits
X-App-Version
X-Cdn
HostName
X-Loop
X-Origin-TTL
X-TNCMS
X-HTML-Minification-Powered-By
X-Origin-CC
X-Varnish-Hostname
X-S-Maxage
X-Cache-Tags
ServedBy
Onion-Location
X-CSRF-Token
X-Varnish-Cache-Hits
X-Amz-Meta-S3cmd-Attrs
Upgrade-Insecure-Requests
X-Time
X-Tumblr-Pixel-2
Web-Mar-Node
X-Tumblr-Pixel-3
X-Request-Time
Webserver
X-EC-Lua
X-Proto
From-Origin
X-AOL-HN
X-Request-Host
X-ECache
X-Xrds-Location
WP-Super-Cache
N-Cache
X-Endurance-Cache-Level
X-Tenant
X-Cache-Var-Map
X-FireWall-Port
X-LJ-Flow-ID
X-AWS-Id
X-VWS-Id
X-Cache-Var
Nel
X-Correlation-ID
X-Cache-Enabled
X-B3-SpanId
X-GG-Cache-Date
X-Time-Microsecs
X-NWS-UUID-VERIFY
X-Edge-Location
X-Handled-By
X-Origin-Response-Time
Vix-Hermes-Req-Id
Sslversion
V-Age
User-Cache-Control
Surrogated-Key
Mobile-Detection-Method
DCR-Processing-Time-Ms
DCR-Decision-By
BehaviorPad-Version
A
Expiry
Fastcgi-X-Cache-Version
Redirect-Candidate
Pramga
Odigeo-Trace-Id
Meta-Geo-Continent
Rendered-Blocks
X-Destination
X-Rojux
X-Processor
X-S
X-S-Cookie
X-ScT
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-Orig-Expires
X-ND-Cache
X-PAYTM-SRV-ID
X-PBS-Appsvrname
X-Planisys-CDN-Cache
X-SD-PageType
X-Session-Fingerprint
X-VG-WebCache
X-Vdms-Version
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
Xc-Version
X-Vdms-Path
X-V-Cache
X-Shop-Environment
X-Slack-Backend
X-SRCache-Key
X-TIM-N
X-NAPM-TraceId
X-Ig-Push-State
X-Application
X-Aicache-OS
X-ARC
X-B-Cookie
X-Block-Status
X-Aed
X-A-Wwc
X-A-Ccd
X-A-Dam
X-A-Dcw
X-A-Dgt
X-Cache-NE
X-CF-Lambda-Version
X-Forwarded-Path
X-External-Request-Id
X-Ftr-Request-Id
X-Gen-Mode
X-Hnp-Log
X-Developer
X-D
X-Ckpd-Fst-Backend
X-Cluster
X-Conf
X-Connection-Hash
X-A
X-CF-Lambda-Fn
X-Via-NSCOPI
X-Mg-Request-UUID
X-Amz-Apigw-Id
X-MP-GENERATED-AT
X-Labrador-Cache-Channel
X-Amzn-RequestId
X-PHP-Host
CloudFront-Viewer-Country
Gh-Request-Id
X-Nyt-Route
Host-ID
X-Men
X-Mvc-Supplant-Cachable
X-Old-Content-Length
X-Policy
DSUID
X-Request-URI
X-RCS-CacheZone
Fastcgi-Cache-TTL
X-Origin-Time
X-Location
X-Origin-Expires
X-Li-Fabric
X-Cdn-Srv
True-Client-Country-4JS
Svr
Wxu-Next-Commit
Wxu-Next-Hostname
X-Cache-Bucket
X-Cache-Date
Wxu-Next-Region
State
X-Fastly-Cache
X-Hash
X-Scheme
X-Li-Pop
Origin
X-Geo-Header
X-Forwarded-Site
X-Gdpr
X-LI-UUID
X-NodeID
X-Magnolia-Registration
X-SVT-ORM-RULES
X-Sucuri-ID
AKAMAI
Arc-Country
X-SVT-ORM-VERSION
X-Reqid
Fastly-Drupal-Html
X-Webstats-RespID
X-Backend-TTL
X-Epic-Correlation-Id
X-Sucuri-Cache
X-Adobe-Source
Cmsid
X-Server-IP
Cmstype
CDCHOST
CacheControlHeader
Environment
X-Date
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
X-Eu-Site
X-Qnm-Cache
X-Device-Os
X-Envoy-Decorator-Operation
Apple-News-Services-Request-Url
X-Datadog-Parent-Id
X-Esi-Check
X-Developers
X-Core-Value
X-Branch-Name
X-Cache-Debug
X-VG-TLSProxy
X-Rocket-Nginx-Serving-Static
X-GeoIP-Region-Code
X-Origin
X-Fastly-Backend
X-Cache-Id
X-Core-Mission
X-GeoIP-Country-Code
X-CGP
X-Cache-Info
X-Cdn-Origin
X-Backend-State
X-Csrf-Jwt
X-GeoIP
X-TH-Server
X-M-Log
X-Locale
X-TrackingId
X-Varnish-Beresp-Status
X-UnsetCookies
X-Accel-Expires-Debug
X-Storefront-Renderer-Rendered
X-Region-Sid
X-Request-Start
X-Skip-Cache
X-Proxy-Upstream
X-Platform
X-Sn-Servicetimems
X-Level-Front-Cache
X-Irp-Debug
X-Generated-On
X-Served-From
Apple-News-Services-Handled
X-Gamma-Serve
X-Fetched-On
Apple-News-Services-Host
X-GeoIP-City
X-Gzip
X-HS-Content-Campaign-Id
X-M-Reqid
X-VarnishDD-TTL
X-HN
X-VServer
X-Viewer-Country
Apple-News-Services-Parsed-Url
X-Owner
Locid
L5d-Success-Class
L
Release
Machine
PFcat
Web-Mar-Region
Server-Info
Origin-CC
Origin-EX
Ha-Gx-Prefs
HA-Ipaddr
Ssr
Server-Host
Traceparent
X-DPWN-IS-SECURE
TDXMobile
X-Thinkindot-L3
Thinkindot-CacheControl
X-Has-Esi
X-Varnish-Remaining-TTL
X-Variation
X-Thanos
Platform
X-Varnish-CookieINHashed-On
X-Qloud-Router
X-Varnish-CookieHashed-On
X-JWT-State
X-Req
X-Response-By
Fastly-SIE
Fastly-SWR
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-Pod-Name
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
Cf-Device-Type
X-NU-AKA-ACS-Version
Thinkindot-CacheControl-Type
X-Is-Gdpr
Adler-Geo
X-Tx-Id
Memcached
X-Node-Id
Is-Eu
Mail-Subject
NM-Fastcgi-Cache
X-FC-Vary-Parameters
S-Rt
X-BBC-Edge-Cache-Status
Req-Svc-Chain
X-Zone
Fastly-GeoIP-CountryCode
X-Sigma
We-Hiring
X-ATG-Version
X-Bip
X-VC-Cache
X-Sigma-Backend
X-Worker
X-Rocket-Build-Number
Thinkindot-Control
X-Amzn-Remapped-Content-Length
X-DefElseHash
X-DefHash
X-Varnish-Beresp-Ttl
X-Ua-Device
NGX
X-Loc
X-Mvc-Supplant-OutputCached
Magicmarker
X-CS
AMP-Access-Control-Allow-Source-Origin
X-CLOUD-TRACE-CONTEXT
X-LB-ID
X-Restarts
X-Up
X-API-Version
X-Akamai-Request-ID2
X-Cache-Config
X-Http-Reason
X-CACHE-KEY
X-NC
CDN
Kp-EeAlive
Ms-Author-Via
Pics-Label
X-Trace-ID
X-Generated-In
X-Action
X-DB
X-DI
X-RPS
X-DW
X-DSS
Env
X-LB-NoCache
X-TraceId
X-Wix-Viewer-Type
Memory
Time
X-RSL
X-RPM
Edge-Cache
X-Cache-Backend
X-Tb-Optimization-Total-Bytes-Saved
NtCoent-Length
Datacenter
X-Refresh
X-DC
X-Varnish-Ttl
X-Via-Popv
X-Via-Poph
X-Edge-Pop
WebServer
X-Via-Popn
Candidate-Md5Url
X-Optimistic-Header
X-Tt-Logid
X-Datadome
Accept-Language
X-Minions-Version
X-CacheTTL
X-Srv
X-DynaTrace-JS-Agent
X-HA-Backend
X-Vc
WWW-Authenticate
On-Server
GeoIp-Country-Code
X-Servedbyhost
X-Esi
Esi-Enabled
X-Urbn-Site-Id
Locale
X-Urbn-Context-Path
Server-ID
X-Unique-ID
X-ZONE
X-MSEdge-Flight
X-MSEdge-Features
X-Varnish-Beresp-TTL
X-Parent-Response-Time
X-Cs
X-Ec-Fail
X-Service
X-Ec-GeoHdr
X-User
C-Via
X-Newrelic-Synthetics
X-TA-CDN-Provider
X-TX-ID
X-Cache-PHP
X-VCL-Version
X-Webkit-CSP-Report-Only
X-App
X-Cache-Ttl
X-LI-Proto
X-Traceid
X-Fpc
X-Dynatrace
X-URL
Cdncip
Test
X-Render-Time
X-Webkit-Csp-Report-Only
X-Cache-Status-Check
X-AK-Request-ID
Cdnsip
X-Li-Proto
X-LiteSpeed-Cache-Control
X-Clara-WADP
X-Fmm-Version
X-WADP-Cache
My-App
X-FPC
X-B3-Spanid
Proxy-Connection
X-Pass-Why
X-NODE
X-Var-Ttl
Resin-Trace
X-Vcl-Version
Tracecode
Geoip-Latitude
Cluster
X-CUA
X-Mcache
T-Server
X-From
Lfy
Server-Id
M-TraceId
Geo-Info
DataCenter
Fastly-Drupal-HTML
X-Clientip
Cf-Int-Pingora-Origin-Digest
X-Fragments
Lang
X-Info
X-CSRF-TOKEN
X-AIR-PT
Target-Params
X-Ha-Backend
X-Oss-Storage-Class
X-Oss-Request-Id
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
GeoIP-Country-Code
X-Oss-Server-Time
X-ID
X-LiteSpeed-Tag
UCS
Cache-Host
HIT
X-VC
Hostname
X-WP-CF-Super-Cache
X-Pad
X-RAMCache
X-WP-CF-Super-Cache-Cache-Control
Hit
S-Cnection
X-ServedByHost
X-Geo
X-Dynatrace-Js-Agent
Tcn
X-Via-PopN
X-Via-PopH
X-Via-PopV
X-Cdn-Forward
Ohc-File-Size
MIME-Version
X-RateLimit-Reset
X-Edge-POP
X-Proxy-Cache-Info
X-Api-Version
ENV
Fastly-Backend-Name
Load-Balancing
X-Edge-Cache
X-NGINX-Cache
User-Agent
X-Check-Cacheable
X-ElasticPress-Query
Section-Io-Origin-Time-Seconds
X-HS-Status
Section-Io-Id
Permissions-Policy
Section-Origin-Responded
X-Micro-Cache
Section-Io-Origin-Status
X-Httpd
X-Provided-By
WZWS-RAY
X-ServerName
Producers
Servername
X-Ucs
X-Fastly-Backend-Reqs
X-BBC-Origin-Response-Status
X-Backend-Host
X-Release
X-HostName
Uri
X-APP
X-GoCache-CacheStatus
X-BCube-Filmed-By
X-UP
X-Nc
URI
X-SB
X-Lb-Nocache
X-Cache-CFC
PICS-Label
ServerName
FSS-Cache
X-TRACE-ID
Cneonction
Cteonnt-Length
X-Platform-Router
X-Acquia-Site
X-Platform-Processor
X-Platform-Cluster
Server-Ttl
X-Udemy-Cache-App-Namespace
X-Swift-Error
X-Acquia-Purge-Tags
Cdn
X-Acquia-Application-Trace
X-Acquia-Application-UUID
Ohc-Cache-HIT
EpKe-Alive
X-Fastly-Cache-Hits
X-Cdn-Request-ID
X-Lb-Id
X-Pool
X-Dw-Trace-Id
VNS-Age
X-Akamai-ERPolicy
X-Akamai-ERRuleID
X-Apw-Access-Action
VNS-Cache
X-Apw-Access-Object
X-Ec-Custom-Error
CF-Cached-On
Cf-Ipcountry
CPC-Age
X-Amz-Meta-Cb-Modifiedtime
X-WA-Info
CPC-Cache
X-Newrelic-App-Data
X-WA
X-B3-ParentSpanId
Vha6-Origin
X-Contensis-Viewer-Groups
X-Vcache
X-Cache-ASPX
Cache-Key
X-Snapshot-Date
X-Scale
X-Yottaa-OS
Shield-Pop
X-Apw-Hits
X-Apw-Access-Token
Path
Sid
X-Air-Pt
X-Cache-Ngx
Lb
X-Cache-Expires
X-SIPLIST1
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
MD5-Digest
IsBot
GeoIP-Latitude
X-Akamai-Request-ID
X-Dispatcher-Number
X-Shopify-Generated-Cart-Token
CountryCode
X-CacheKey
X-UA
X-Akamai-Pragma-Client-IP
X-Logging-Id
X-Wikidot-Backend
X-Varnish-Authentication
X-Wikidot-Static-Cache
Req-ID
X-ES-SERVER
X-Te-Count
X-Te-Duration-Ms
X-Http-Duration-Ms
X-Http-Count
X-Sentry-ID
Ngx
X-Last-Modified