Threat Level: green Handler on Duty: Rob VandenBrink

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
X-Powered-By
Pragma
X-XSS-Protection
CF-RAY
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
Alt-Svc
P3P
X-Cache-Hits
X-UA-Compatible
X-Xss-Protection
CF-Ray
X-Served-By
X-Download-Options
X-Timer
X-Request-Id
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
Access-Control-Allow-Credentials
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
X-Drupal-Cache
X-Generator
X-Cache-Status
X-Check
X-Cacheable
X-DNS-Prefetch-Control
X-Envoy-Upstream-Service-Time
X-FRAME-OPTIONS
Timing-Allow-Origin
X-Iinfo
X-Drupal-Dynamic-Cache
X-Request-ID
X-Dns-Prefetch-Control
Feature-Policy
X-Content-Security-Policy
Content-Encoding
Access-Control-Expose-Headers
Upgrade
X-XSS-PROTECTION
Server-Timing
X-CDN
Status
X-AspNetMvc-Version
Access-Control-Max-Age
X-Amz-Request-Id
Request-Context
X-Amz-Id-2
X-Via
X-Turbo-Charged-By
X-AH-Environment
X-Backend
X-Robots-Tag
X-Cache-Group
Cf-Edge-Cache
Keep-Alive
Host-Header
X-Hacker
X-Proxy-Cache
X-UA-Device
X-Server
X-Rq
X-Vhost
X-Server-Powered-By
Allow
X-Age
X-Varnish-Cache
X-Ws-Request-Id
X-Dispatcher
X-Amz-Version-Id
EagleId
P3p
Nel
Grace
X-LiteSpeed-Cache
Cf-Apo-Via
X-Page-Speed
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
Cf-Railgun
EagleEye-TraceId
X-Aws-Lambda-Call-Status
X-Swift-CacheTime
X-Swift-SaveTime
X-Pingback
X-OneAgent-JS-Injection
Ali-Swift-Global-Savetime
X-Host
X-Node
Accept-CH
X-WebKit-CSP
X-CST
X-Backend-Server
X-Server-Id
Surrogate-Control
X-Cache-Lookup
X-Nginx-Cache-Status
X-Readtime
Permissions-Policy
X-Akam-SW-Version
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Nginx-Upstream-Cache-Status
Accept-CH-Lifetime
Request-Id
X-Application-Context
X-Content-Security-Policy-Report-Only
X-Cloud-Trace-Context
X-Ua-Compatible
X-Trace
X-Response-Time
X-HW
X-Edge
Content-Location
X-Clacks-Overhead
X-Mod-Pagespeed
Xkey
X-Midtier
Rating
X-ESI
X-Amz-Server-Side-Encryption
X-ECACHE
X-Ruxit-Js-Agent
X-Mcache
X-Url
X-Ruxit-JS-Agent
Accept-Ch-Lifetime
X-Upstream
X-Vcap-Request-Id
X-Country
X-Oneagent-Js-Injection
Cache-Tag
X-D2id
X-MS-InvokeApp
X-GoogleNews-Bot
X-Exp-Variant
X-Exp-Id
X-Kinja
X-Cdn-Fetch
X-Use-Magma
X-Kinja-Revision
X-Kinja-Server
X-Kinja-Build
Verso
X-Element-Page-Cache
X-Rack-Cache
X-Litespeed-Cache
Accept-Ch
X-Powered-By-Plesk
X-TtlSet
X-PC
X-Vname
Edge-Control
RTSS
X-Cache-TTL
Fastly-Restarts
X-Ac
X-VARITI-CCR
Origin-Trial
X-Navigation-Version
X-Abt-Application-Version
X-Country-Code
Service-Worker-Allowed
X-WebKit-CSP-Report-Only
X-Goog-Hash
X-Cached
X-Sol
Display
X-Middleton-Display
Pagespeed
X-Browser-Type
X-GitHub-Request-Id
X-Amz-Rid
X-Ttl
X-Varnish-TTL
Cross-Origin-Opener-Policy
X-Webkit-CSP
X-Content-Type
SPRequestGuid
X-SharePointHealthScore
X-Dw-Request-Base-Id
X-Mg-S
X-Server-Name
X-Amzn-Trace-Id
X-Powered-CMS
X-Middleton-Response
Response
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Erf-Bev-Bev
Arr-Disable-Session-Affinity
X-Erf-Bev-Bev-Is-Generated
X-Instrumentation
AR-Request-ID
AR-SID
AR-ATIME
AR-PoweredBy
SPIisLatency
SPRequestDuration
X-Cache-Key
X-Kinja-CCPA
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-B3-Traceid
X-B3-TraceId
X-Version
X-Times
AR-CACHE
X-SRCache-Fetch-Status
X-NWS-LOG-UUID
X-SRCache-Store-Status
X-Jurisdiction
X-HP-Trace-Id
X-HP-Webp
X-Pinterest-Rid
Pinterest-Version
Pinterest-Generated-By
X-NF-Request-ID
X-Accel-Expires
X-T
Cache-Tags
X-Fastly-Request-ID
Cache-Status
Front-End-Https
X-Cnection
Nginx-Cache
X-MSEdge-Ref
Edge-Cache-Tag
X-Aspnetmvc-Version
X-Client-IP
X-Hits
X-Fastcgi-Cache
X-Ser
X-Px
X-RateLimit-Remaining
Mrf-Cache-Status
MRF-Tech
Public-Key-Pins
X-B3-TraceId-Primal
Payment
X-Recruiting
X-LLID
X-Request-Processing-Time
X-Request-Received
X-Frontend
Server-Node
X-Ua-Browser
X-FastCGI-Cache
X-Erf-Stays-Pdp-Viaduct-Migration-Web
X-RateLimit-Limit
X-Shield-Request-Id
X-DIS-Request-ID
TP-Cache
S
X-Server-ID
MicrosoftSharePointTeamServices
Access-Control-Request-Method
X-Goog-Metageneration
X-GUploader-UploadID
X-HS-Content-Id
X-HS-Cache-Config
X-HS-Combine-CSS
X-HS-Hub-Id
X-LB-Cache
X-Amz-Apigw-Id
X-Content-Digest
X-Amzn-RequestId
X-Protected-By
Content-MD5
X-Microsite
X-Request-Handler-Origin-Region
TP-L2-Cache
Access-Control-Allow-Method
X-Page-Id
X-Distributor
X-FB-Debug
Accept-Charset
X-Ezoic-Cdn
Realpath
X-Forwarded-For
Fastcgi-Cache
X-Cluster-Name
X-PressLabs-Stats
X-Rid
X-Hostname
X-Geo-Country
X-B3-Sampled
X-Seen-By
X-Webkit-Csp
X-Aspnet-Version
X-Ua-Device
X-Ratelimit-Remaining
Cleartype
X-TTL
X-Correlation-Id
Referer-Policy
X-Envoy-Decorator-Operation
X-Webkit-CSP-Report-Only
X-Mobile
Cross-Origin-Resource-Policy
X-Newrelic-App-Data
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Goog-Generation
DC
TCN
X-Daa-Tunnel
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Content-Options
Count-Hit
X-Debug-Info
X-Varnish-Backend
X-Ratelimit-Limit
X-Logged-In
X-Origin-Cache
X-Contextid
X-Varnish-Grace
X-IPS-LoggedIn
X-Grace
X-Fb-Rlafr
X-App-Server
Surrogate-Key
X-Amz-Replication-Status
X-Git-Hash
X-Revision
X-Flags
X-Aspnet-Duration-Ms
X-Route-Name
X-Request-Guid
X-App-Environment
X-Is-Crawler
X-Providence-Cookie
X-Origin-Server
X-TT
X-Azure-Ref
X-Hosted-By
X-Amz-Meta-S3cmd-Attrs
Frame-Options
X-XRDS-Location
X-Forwarded-Proto
X-Client-Ip
X-Kinsta-Cache
X-Edge-Location-Klb
Alternate-Protocol
X-Wix-Request-Id
WPO-Cache-Status
WPO-Cache-Message
X-Whom
Healthy
Retry-After
Charset
X-F-Cache
X-Akamai-Edgescape
Viewport
X-Backend-Name
X-Magnolia-Registration
Section-Io-Cache
MS-Author-Via
X-RateLimit-Reset
Paypal-Debug-Id
X-B
X-App-Version
X-COUNTRY
X-Proxy-Cache-Info
SRV
X-AppVersion
X-Az
X-Activity-Id
X-Id
ServerID
X-Language
VIX-Pulpo-Node
SD-X-WS
X-Rule
X-Cache-Rule
X-Original-Request-Id
VIX-Pulpo-Upstream-Status
X-ARC
Akamai-GRN
Filterid
Host
X-EdgeConnect-Cache-Status
X-Response-Served-From
X-Instance
X-N
X-UUID
Front
X-Kong-Upstream-Latency
X-Edge-Location
X-Cache-Grace
X-Kong-Proxy-Latency
X-Varnish-Age
X-User-Agent
X-Http-Reason
X-Rocket-Nginx-Serving-Static
X-Status
From-Origin
X-FW-Type
X-Is-Bot
X-Load-Cache
Protected
X-FW-Server
Fastly-SWR
X-FW-Static
X-Time
X-Rendered-As
Fastly-SIE
X-Akamai-Request-ID2
Server-Name
X-Region
X-FW-Serve
X-Cacheable-TTL
X-FW-Version
X-Unique-Id
X-Environment-Context
X-L-Path
X-Framework
X-FW-Hash
X-Jobs
X-FW-Dynamic
Amp-Access-Control-Allow-Source-Origin
X-Page-View
X-Cache-Age
Access-Control-Request-Headers
X-Cache-Time
X-Adobe-Loc
Country
X-Varnish-Server
X-Www-Served-By
X-Adobe-Content
X-Type
X-Tumblr-Pixel-0
X-Cache-Control
X-Tumblr-Pixel-1
X-ProcessESI
X-Tumblr-User
X-Tumblr-Pixel
X-Datadog-Sampling-Priority
X-Datadog-Trace-Id
X-RemovedCookies
X-Datadog-Parent-Id
X-G
X-Trace-Id
X-Proxy
Refresh
X-Vcache
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Datadog-Sampled
X-CDN-Forward
X-Mg-Request-UUID
X-Xrds-Location
X-DataDome
X-Amzn-Remapped-Content-Length
X-Debug-IsConnected
X-Debug-IsPreview
X-Source
X-ECache
X-Drupal-Cache-Tags
X-B-Cache
Version
X-Signature
Content-Disposition
X-Oracle-Dms-Ecid
X-URL
X-WP-CF-Super-Cache
X-Oracle-Dms-Rid
Xet-Cookie
X-WP-CF-Super-Cache-Cache-Control
Backend
Countrycode
Accept-Language
X-Nf-Request-Id
X-HTML-Minification-Powered-By
X-Erf-Web-Scheduler
CF-IPCountry
X-DynaTrace-JS-Agent
X-Generated-By
Webserver
X-DynaTrace
X-ID
X-Nginx-Cache
X-Mode
X-Servername
X-Httpd
Xserver
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Upgrade-Enabled
Url
X-Tec-Api-Root
X-Tec-Api-Version
X-Tec-Api-Origin
GEO-INFO
X-Varnish-Ttl
X-Storage
X-Template
X-Content-Age
X-Director
X-NYM-Debug-Backend
X-GeoCode
X-JoinUs
S-Rt
X-UPSTREAM-Address
X-Proto
Onion-Location
X-Device-Type
Azure-InstanceId
X-Cache-Action
Azure-RegionName
Azure-SiteName
Azure-SlotName
Fastcgi-Useragent
Filters
Meta-Geo
Load-Balancing
X-Cache-Operation
X-Tb
Azure-Version
X-GeoCountry
X-Rewrite-Enabled
X-ServerID
X-Varnish-Cache-Hits
X-SaId
X-Cluster-Node
X-Varnish-Hostname
X-Container-Uri
X-Content-Powered-By
X-Urbn-Site-Id
X-Tt-Logid
X-RM-Cache-TTL
X-Soup
X-Say-TTL
Locale
X-SayCDN-TTL
Uber-Trace-Id
X-Forwarded-Host
X-Say-Cacheable
X-VC-Cache
X-Urbn-Context-Path
X-Labrador-Cache-Channel
X-LAGOON
X-PHP-Host
X-Git-Commit
X-Logging-Id
X-Cache-Server
X-Served-From
OT-Force-Account-Verify
X-Adobe-Source
X-Ms-Version
X-Ms-Request-Id
X-Generation-Time
X-Detected-As
X-VCT
X-Proxied
DB-Nickname
Mn-Server-Ip
Web-Mar-Node
TWC-Connection-Speed
Webcakes-App-Name
TWC-Device-Class
X-Origin-Hint
X-XRDS-LOCATION
Node
TWC-Locale-Group
Property-Id
X-Lambda-Id
TWC-Privacy
TWC-GeoIP-LatLong
Webcakes-App-Version
Webcakes-Region
TWC-GeoIP-Country
X-Sql-Count
X-Routing-Service
X-Extlb
X-FB-TRIP-ID
X-R9-Blue-Green-Version
X-Debug
X-RCS-CacheZone
X-Skip-Cache
X-Sql-Duration-Ms
X-Zipkin-Id
X-LSADC-Cache
X-Zen-Fury
X-Tumblr-Pixel-2
X-Timing-Wait
X-Format
X-Fetched-On
X-Proxy-Build
X-Tumblr-Pixel-3
X-Uri
Selected-Fe
X-Drupal-Cache-Contexts
X-MCACHE
X-Sucuri-Cache
Liferay-Portal
X-Sucuri-ID
X-Loop
X-Tncms
CDN-RequestId
X-CCDN-Origin-Time
X-CCDN-CacheTTL
Source
X-Endurance-Cache-Level
X-Hcs-Proxy-Type
X-Rn-Rsrv
X-Srv
X-B3-SpanId
X-Cache-Hit
X-Origin-Date
Cross-Origin-Window-Policy
X-MP-GENERATED-AT
X-Redis-Cache
X-Fastly-Request-Id
Fastly-Drupal-HTML
X-Ua
X-Varnish-Hits
X-TimeS
Section-Origin-Responded
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
Section-Io-Id
Upgrade-Insecure-Requests
X-Pass-Why
X-Cache-Expired-At
X-Real-IP
Content-Secure-Policy
X-Ratelimit-Reset
X-S
X-Cache-TTL-Remaining
X-UA-Device-Type
X-Akamai-Transformed
X-Node-Name
X-Origin-CC
X-Origin-TTL
X-Pubstack
X-Newrelic-Synthetics
X-CACHE-AGE
X-Server-W
CDN-CachedAt
CDN-PullZone
CDN-RequestPullSuccess
CDN-RequestCountryCode
CDN-EdgeStorageId
CDN-Uid
CDN-RequestPullCode
CDN-Cache
X-Hl-Ver
X-Via-JSL
MS-CV
X-RTag
X-Datadome
Cache-Provider
Ms-Operation-Id
X-GEO
X-CSRF-Token
X-AIR-PT
X-Handled-By
X-Parent-Response-Time
X-Cache-Host
X-Worker
T-Server
CPC-Cache
X-A
X-Debug-Cache-Fetch
Canary
We-Hiring
Surrogated-Key
X-A-Ccd
X-Csrf-Jwt
Sslversion
X-Conf
X-D
X-Date
X-A-Dam
True-Client-Country-4JS
Candidate-Md5Url
CPC-Age
X-Destination
X-Gdpr
X-Forwarded-Path
X-External-Request-Id
X-Eu-Site
WP-Super-Cache
Vix-Hermes-Req-Id
X-Has-Esi
X-GeoIP-Region-Code
X-GeoIP-Country-Code
X-Epic-Correlation-Id
X-Ec-GeoHdr
X-Developer
BehaviorPad-Version
X-Cms-Context
W
VNS-Cache
X-Ec-Fail
Apigw-Requestid
X-Ec-Custom-Error
X-Debug-Cache-Store
X-CGP
X-Accel-Expires-Debug
Server-Host
X-Aed
Rendered-Blocks
MD5-Digest
X-A-Wwc
Magicmarker
X-A-Dgt
Mail-Subject
Meta-Geo-Continent
N-Cache
X-BCube-Filmed-By
X-Bc-Bl
X-App
X-B-Cookie
Odigeo-Trace-Id
X-Bl-Debug
NGB
Redirect-Candidate
Ngx.Var.Host
Lang
L5d-Success-Class
Fastly-GeoIP-CountryCode
Fastly-SSL
X-A-Dcw
Gannett-Cam-Experience-Id
Fastly-Backend-Name
X-CF-Lambda-Fn
DCR-Processing-Time-Ms
X-Application
X-CF-Lambda-Version
X-Cdn-Diag
X-CacheTTL
X-Cache-NE
X-Cache-Info
L
ServedBy
X-Cache-Type
Gh-Request-Id
Ha-Gx-Prefs
HA-Ipaddr
DCR-Decision-By
X-JWT-State
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-Vtex-Remote-Cache
X-Restarts
X-Rojux
X-We-Are-Hiring
X-Wikidot-Backend
X-Origin-Time
X-Orig-Expires
X-Policy
Cache-Name
X-Wikidot-Static-Cache
X-S-Cookie
X-Presslabs-Stats
X-Vdms-Version
X-VG-WebCache
X-Vdms-Path
X-Var-Ttl
Xc-Version
X-Tenant
X-Viewer-Country
X-ScT
X-SD-PageType
X-Shop-Environment
X-SRCache-Key
X-Optimistic-Header
X-Reqid
X-IPLB-Request-ID
X-Nyt-Route
X-Is-Gdpr
X-Mvc-Supplant-Cachable
X-IPLB-Instance
X-Xfnlog-Site
VNS-Age
X-BBC-Edge-Cache-Status
X-Vmg-Version
X-Sorting-Hat-PodId
X-INCAP-ABP
X-Sorting-Hat-ShopId
X-Storefront-Renderer-Rendered
X-Generated-On
X-Auto-Login
X-Sn-Servicetimems
X-Geo-Header
X-Shopify-Stage
X-ShopId
X-Level-Front-Cache
X-BYPASS-REASON
X-Slack-Backend
X-Bip
X-Slack-Shared-Secret-Outcome
X-Cache-Bucket
X-SVT-ORM-RULES
X-Tx-Id
X-Gzip
X-VG-TLSProxy
X-Varnish-Remaining-TTL
X-Up
Web-Mar-Region
X-Variation
X-Varnish-CookieINHashed-On
X-Varnishpool
X-Thinkindot-L3
X-SVT-ORM-VERSION
X-Alternate-Cache-Key
X-Varnish-CookieHashed-On
X-ShardId
X-Test
X-Thanos
X-Accel-Buffering
X-ApacheServer
X-Cache-Debug
X-Wix-Viewer-Type
X-ProxyCache-Key
X-CMSURLCustom
X-Pool
X-Node-Id
X-ProxyCache-Status
X-Qloud-Router
X-Clara-WADP
X-Clientip
X-Core-Mission
X-Core-Value
X-Dispatcher-Number
X-DefElseHash
X-DefHash
X-Owner
X-PAYTM-SRV-ID
X-DPWN-IS-SECURE
X-Platform
X-PERF
X-No-Session
X-Nitro-Cache
X-Fmm-Version
X-S-Maxage
X-VServer
X-FC-Vary-Parameters
Origin-Agent-Cluster
X-Mid
X-Loc
X-Org
X-Cache-Id
X-Fastly-Backend
X-Mly-Id
X-Esi-Check
X-NGENIX-Cache
X-Cdn-Origin
X-WADP-Cache
X-Refresh
X-Request-Time
X-Request-Host
X-Hash
X-Server-IP
TDXMobile
Origin
Cf-Device-Type
Memcached
AKAMAI
Platform
Release
Producers
Machine
Cmsid
Datacenter
Environment
Expect-Staple
Host-ID
Hostname
Cmstype
Is-Eu
Req-Svc-Chain
Adler-Geo
Thinkindot-Control
Cache-Hits
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
X-TIME
X-Correlation-ID
X-Mvc-Supplant-OutputCached
X-Origin-Response-Time
X-LJ-Flow-ID
CloudFront-Viewer-Country
X-Nginx-Cache-Key
X-Cluster
DSUID
X-Old-Content-Length
X-Irp-Debug
X-Nananana
Country-Code
CDCHOST
X-GeoIP
Esi-Enabled
X-Vcl-Version
X-From
AMP-Access-Control-Allow-Source-Origin
X-Scale
X-NodeID
Apple-News-Services-Handled
X-Human
Apple-News-Services-Request-Url
X-Device-Os
X-Origin
Apple-News-Services-Host
X-Dispatcher-Server
X-PHP-Backend
Apple-News-Services-Parsed-Url
X-AWS-Id
X-WA-Info
NM-Fastcgi-Cache
X-App-Name
X-Akamai-Device-Characteristics
Server-Hostname
X-Cdn-Srv
Server-Ext
X-VWS-Id
Sever-Int
User-Cache-Control
X-Cache-Enabled
Wxu-Next-Hostname
X-Section
Wxu-Next-Commit
X-Gen-Mode
X-NCache
Pics-Label
X-Op-Id-All
X-Access
X-Instance-Name
X-Forwarded-Site
Wxu-Next-Region
Ssr
X-B3-Spanid
Server-Info
X-LB-NoCache
X-Hnp-Log
X-Proxy-Cache-Status
X-Block-Status
X-Cache-Status-Check
C-Via
Origin-EX
Origin-CC
X-API-Version
Memory
X-TIM-N
Time
Server-ID
X-Amz-Meta-Cb-Modifiedtime
X-Dc
X-HA-Backend
X-Via-Fastly
NGX
X-Micro-Cache
X-CACHE-GROUP
X-Cs
X-Air-Hostname
X-Air-Source
X-Internal-Host
X-FTR-Request-ID
X-Air-Trace-Id
X-Tb-Optimization-Total-Bytes-Saved
X-Wp-Cf-Super-Cache-Active
X-AB
X-Vgn-Hpd-Reason
X-Platform-Cluster
X-Azure-Ref-OriginShield
X-Platform-Router
X-Platform-Processor
X-Varnish-Beresp-Ttl
X-Varnish-Beresp-Grace
Cdn-Requestid
X-Webkit-Csp-Report-Only
X-Geo-Region
X-Zone
GeoIP-Latitude
X-ZONE
X-Buckets
X-Web-Node
Location
X-Microcachable
IsBot
X-Origin-Expires
X-SIPLIST1
X-B3-Parentspanid
Cache-Host
X-Fpc
X-WP-CF-Super-Cache-Active
X-TraceId
X-Accel-Version
Sid
XM
X-DC
X-Backend-Instance
X-Github-Request-Id
X-VarnishDD-TTL
X-Pod-Name
PFcat
X-DataCenter
Uri
X-HN
X-Is-Tablet
X-Tcp-Rtt
X-Is-Mobile
X-Is-Supported-Browser
X-Is-Desktop
X-Browser-Name
CF-Ctrl
YJS-ID
Resin-Trace
X-Info
X-Ad-Defer-Variation
User-Agent
X-LiteSpeed-Cache-Control
X-TA-CDN-Provider
Edge-Copy-Time
X-FL-QIT-DEBUG
A
X-FL-EDGE
X-Via-Edge
Srvid
True-Client-Ip
Locid
X-Via-SSL
X-Cached-By
X-Via-CDN
X-Site-Version
X-Locale
X-NGINX-Cache
X-Nitro-Cache-From
X-Nitro-Rev
GeoIP-Country-Code
X-Cache-ASPX
GeoIp-Country-Code
X-Moov-Xdn-Version
X-Hyper-Cache
X-ATG-Version
X-Contensis-Viewer-Groups
Cdn
X-FireWall-Port
Epwk-X-Cache
X-Moov-T
X-VCache
X-Frame-Option
Cache-Key
X-Varnish-Authentication
XServer
X-CS
X-CSRF-TOKEN
X-Geo
X-NewRelic-App-Data
True-Client-IP
X-MSEdge-Features
X-MSEdge-Flight
X-Service
SID
X-Datacenter
X-Webstats-RespID
X-Upstream-Ht
X-Upstream-Ct
X-TRACE-ID
NtCoent-Length
X-Planisys-CDN-TTL
X-HS-Content-Campaign-Id
X-Platform-Server
X-FPC
State
Fastly-Drupal-Html
Path
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-VC
X-Origin-Cache-Key
X-HostName
Tcn
X-Vgn-Hpd-Cached
X-Vercel-Cache
X-FTR-Backend
X-Vgn-Hpd-Ssi
X-Vgn-Hpd-Variations-Key
X-Country-Code-Real
X-Release
X-SRV
X-LiteSpeed-Tag
X-Fastly-Cache
X-Vercel-Id
Cdn-Host
X-Edge-Server
X-FTR-Backend-Server
X-FTR-Expires
Cdn-Request-Time
X-FTR-Balancer
X-FTR-Cache-Status
X-Api-Version
X-APP-VERSION
CountryCode
Cf-Ipcountry
WZWS-RAY
X-Pad
X-AK-Request-ID
Cdncip
Cdnsip
Req-ID
M-TraceId
X-NMSegId
X-Amz-Meta-Opti
X-Cache-Remote
X-Generated-In
X-Air-Pt
X-Esi
X-Rocket-Build-Number
LB
X-Sigma-Backend
X-Sigma
Lb
X-UA
X-Cache-Ttl
Cache
X-WP-CF-Super-Cache-Cookies-Bypass
X-Branch-Name
X-Provided-By
X-Wp-Cf-Super-Cache-Cache-Control
WebServer
Cluster
X-Ad-Load-Variation
X-Traceid
X-HS-Status
X-Wp-Cf-Super-Cache
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-Cdn-Request-ID
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
Yak-Timeinfo
X-Request-Start
X-Scope-Id
Content-Script-Type
X-Proxy-CacheRZ
X-M-Log
X-NWS-UUID-VERIFY
XkeyRZ
X-M-Reqid
Content-Style-Type
Proxy-Connection
X-Gamma-Serve
X-GeoIP-City
X-GoCache-CacheStatus
X-Scheme
X-CACHE-KEY
X-RN-RSRV
CDN
X-Tim-N
Geoip-Latitude
X-Varnish-Beresp-Status
X-Shield-Cache-Expires
X-Qnm-Cache
Pramga
X-Vc
X-Cdn-Forward
Srv
X-Cdn-Cache-Status
X-Akamai-Pragma-Client-IP
X-Lb-Cache
X-Cache-Date
X-Request-URI
Edge-Cache
X-Ha-Backend
Ohc-File-Size
Ngx
Server-Id
Env
CF-Cached-On
X-TT-LOGID
Serverid
X-User
X-EC-Lua
X-CUA
X-Render-Time
Kp-EeAlive
X-Edge-POP
X-Udemy-Cache-App-Namespace
X-TH-Server
X-Lb-Nocache
X-Acquia-Application-Trace
X-Acquia-Application-UUID
X-CF-Cache-Header-Vary
X-CF-Cache-Header-Cache-Control
X-Via-Ucdn
X-Acquia-Purge-Tags
X-Acquia-Site
X-VCL-Version
X-Dw-Trace-Id
PICS-Label
Yjs-Id
X-Snapshot-Date
Inserted-Into-Cache-At
X-Litespeed-Cache-Control
CACHE-MISS-TO-ORIGIN
Log-Origin
X-ElasticPress-Query
X-Cached-Since
Cache-Tv-Group
Vha6-Origin
X-Edge-Pop
X-Fastly-Cache-Hits
Cneonction
X-MiniProfiler-Ids
X-Location
X-Iauth-Set-Uid
X-RAMCache
X-Miniprofiler-Ids
X-Mobile-URL