Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
Pragma
X-Powered-By
X-XSS-Protection
CF-RAY
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
Alt-Svc
P3P
X-Cache-Hits
X-UA-Compatible
X-Xss-Protection
X-Served-By
CF-Ray
X-Download-Options
X-Timer
X-Request-Id
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
Access-Control-Allow-Credentials
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
X-Drupal-Cache
X-Generator
X-Cache-Status
X-Check
X-Cacheable
X-Envoy-Upstream-Service-Time
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Iinfo
X-FRAME-OPTIONS
X-Request-ID
X-Dns-Prefetch-Control
X-Drupal-Dynamic-Cache
Feature-Policy
X-Content-Security-Policy
Content-Encoding
Access-Control-Expose-Headers
Upgrade
Status
X-CDN
Server-Timing
X-AspNetMvc-Version
X-XSS-PROTECTION
Access-Control-Max-Age
X-Amz-Request-Id
Request-Context
X-Amz-Id-2
X-Turbo-Charged-By
X-Via
X-AH-Environment
X-Backend
X-Robots-Tag
X-Cache-Group
Cf-Edge-Cache
Host-Header
Keep-Alive
X-Hacker
X-Proxy-Cache
X-UA-Device
X-Server
X-Rq
X-Server-Powered-By
Allow
X-Age
X-Vhost
X-Varnish-Cache
X-Ws-Request-Id
EagleId
X-Dispatcher
X-Amz-Version-Id
Grace
X-LiteSpeed-Cache
Cf-Apo-Via
P3p
Nel
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Page-Speed
Cf-Railgun
X-Device
EagleEye-TraceId
X-Aws-Lambda-Call-Status
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-Pingback
X-Node
X-Host
Accept-CH
X-OneAgent-JS-Injection
X-WebKit-CSP
X-Server-Id
Surrogate-Control
X-Backend-Server
X-CST
X-Nginx-Cache-Status
X-Readtime
X-Cache-Lookup
X-Akam-SW-Version
Permissions-Policy
X-Content-Security-Policy-Report-Only
Request-Id
X-Application-Context
X-Nginx-Upstream-Cache-Status
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Cloud-Trace-Context
X-Trace
X-Response-Time
X-Edge
X-HW
Accept-Ch-Lifetime
Accept-CH-Lifetime
X-Ua-Compatible
Content-Location
X-Mod-Pagespeed
X-Clacks-Overhead
X-Ruxit-JS-Agent
X-Midtier
X-ECACHE
X-Url
Rating
X-ESI
Xkey
X-Amz-Server-Side-Encryption
X-Country
X-Mcache
X-Upstream
X-Litespeed-Cache
X-Oneagent-Js-Injection
X-Vcap-Request-Id
X-PC
X-TtlSet
X-Vname
Cache-Tag
X-D2id
X-MS-InvokeApp
Verso
X-Element-Page-Cache
X-Rack-Cache
X-GoogleNews-Bot
X-Kinja-Build
X-Kinja-Server
X-Use-Magma
X-Kinja-Revision
Edge-Control
X-Exp-Variant
X-Exp-Id
X-Cdn-Fetch
X-Kinja
X-Cache-TTL
RTSS
X-Ruxit-Js-Agent
Accept-Ch
X-Powered-By-Plesk
Fastly-Restarts
X-VARITI-CCR
X-Ac
X-Navigation-Version
Origin-Trial
Service-Worker-Allowed
X-Abt-Application-Version
X-Cached
X-Goog-Hash
X-Country-Code
X-Content-Type
X-GitHub-Request-Id
Display
X-Middleton-Display
Pagespeed
X-Sol
X-WebKit-CSP-Report-Only
X-Amz-Rid
X-Ttl
X-Browser-Type
X-Varnish-TTL
X-Dw-Request-Base-Id
X-Mg-S
X-SharePointHealthScore
SPRequestGuid
X-Server-Name
Cross-Origin-Opener-Policy
Arr-Disable-Session-Affinity
X-Powered-CMS
Response
X-Amzn-Trace-Id
X-Middleton-Response
X-B3-TraceId
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Server-Lifecycle-Phase
X-Instrumentation
X-Kraken-Loop-Name
SPIisLatency
AR-SID
AR-PoweredBy
AR-Request-ID
SPRequestDuration
AR-ATIME
X-Cache-Key
AR-CACHE
X-SRCache-Fetch-Status
X-Fastly-Request-ID
X-SRCache-Store-Status
X-Version
X-HP-Trace-Id
X-Jurisdiction
X-HP-Webp
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-T
X-Accel-Expires
Cache-Tags
X-Cnection
Cache-Status
Pinterest-Version
Pinterest-Generated-By
X-Pinterest-Rid
X-Client-IP
Front-End-Https
X-Webkit-CSP
X-Times
Edge-Cache-Tag
X-MSEdge-Ref
X-NF-Request-ID
X-Px
X-B3-Traceid
X-NWS-LOG-UUID
Nginx-Cache
X-Hits
X-Ser
Public-Key-Pins
X-Kinja-CCPA
MRF-Tech
X-B3-TraceId-Primal
Mrf-Cache-Status
X-Fastcgi-Cache
X-Recruiting
X-FastCGI-Cache
X-LLID
X-Request-Processing-Time
X-Request-Received
X-Frontend
Server-Node
Payment
X-Ua-Browser
X-Shield-Request-Id
X-RateLimit-Remaining
X-DIS-Request-ID
Access-Control-Request-Method
X-Erf-Stays-Pdp-Viaduct-Migration-Web
TP-Cache
S
X-Ua-Device
X-Goog-Metageneration
X-HS-Hub-Id
X-HS-Cache-Config
X-HS-Content-Id
MicrosoftSharePointTeamServices
X-HS-Combine-CSS
X-Webkit-CSP-Report-Only
X-PressLabs-Stats
X-Webkit-Csp
X-LB-Cache
X-Ratelimit-Remaining
X-RateLimit-Limit
TP-L2-Cache
X-Content-Digest
X-Distributor
Content-MD5
X-Microsite
X-Request-Handler-Origin-Region
Realpath
X-Ezoic-Cdn
X-Forwarded-For
X-Page-Id
Access-Control-Allow-Method
X-FB-Debug
Accept-Charset
X-Geo-Country
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Protected-By
Fastcgi-Cache
X-GUploader-UploadID
X-Cluster-Name
X-Server-ID
X-Hostname
X-Seen-By
X-Rid
X-Envoy-Decorator-Operation
X-B3-Sampled
X-Ratelimit-Limit
Cleartype
X-Correlation-Id
X-TTL
DC
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
Referer-Policy
X-Goog-Stored-Content-Length
X-Newrelic-App-Data
X-Mobile
TCN
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
Cross-Origin-Resource-Policy
X-Origin-Server
X-Origin-Cache
X-Debug-Info
X-Varnish-Backend
X-Logged-In
X-XRDS-Location
X-Git-Hash
X-Content-Options
X-Azure-Ref
X-Contextid
X-Varnish-Grace
Surrogate-Key
X-App-Environment
X-Fb-Rlafr
X-Revision
X-Aspnet-Version
Count-Hit
X-Grace
X-Flags
X-Aspnet-Duration-Ms
X-Is-Crawler
X-Request-Guid
X-IPS-LoggedIn
X-Route-Name
X-Amz-Replication-Status
X-Providence-Cookie
X-Edge-Location-Klb
X-Kinsta-Cache
X-TT
X-Amz-Meta-S3cmd-Attrs
Alternate-Protocol
X-App-Server
X-Forwarded-Proto
Healthy
Frame-Options
X-Hosted-By
X-Wix-Request-Id
X-Whom
Charset
WPO-Cache-Message
X-Daa-Tunnel
MS-Author-Via
WPO-Cache-Status
Viewport
X-Akamai-Edgescape
Retry-After
Filterid
X-Magnolia-Registration
X-F-Cache
Paypal-Debug-Id
X-B
X-Id
X-Backend-Name
X-Aspnetmvc-Version
SRV
Section-Io-Cache
X-AppVersion
X-Az
X-Cache-Age
X-Client-Ip
X-Activity-Id
X-Proxy-Cache-Info
Amp-Access-Control-Allow-Source-Origin
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-App-Version
X-Trace-Id
X-Www-Served-By
Server-Name
X-Cache-Control
X-RateLimit-Reset
X-Time
X-Type
X-Original-Request-Id
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Http-Reason
X-Instance
SD-X-WS
Host
X-Varnish-Server
X-ARC
X-Cache-Rule
Akamai-GRN
X-Response-Served-From
X-Rule
X-UUID
X-N
X-User-Agent
Protected
X-EdgeConnect-Cache-Status
X-Proxy
Front
X-Akamai-Request-ID2
X-Rocket-Nginx-Serving-Static
X-Status
Refresh
X-L-Path
X-Environment-Context
X-Unique-Id
X-Cacheable-TTL
X-Rendered-As
X-Varnish-Age
X-Cache-Grace
X-Edge-Location
X-Region
X-Is-Bot
X-Jobs
X-FW-Static
X-FW-Type
X-FW-Dynamic
Fastly-SWR
X-Oracle-Dms-Ecid
X-Cache-Time
X-FW-Server
X-FW-Serve
From-Origin
Access-Control-Request-Headers
X-Framework
X-FW-Hash
X-Page-View
Fastly-SIE
X-FW-Version
X-Adobe-Loc
X-Language
X-Oracle-Dms-Rid
X-Adobe-Content
X-Load-Cache
X-RemovedCookies
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-Tumblr-User
X-ProcessESI
Version
ServerID
X-COUNTRY
X-G
Country
X-Datadog-Trace-Id
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
X-Nf-Request-Id
X-Source
X-CDN-Forward
Content-Disposition
X-Drupal-Cache-Tags
X-Vcache
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Datadog-Sampled
X-Amzn-Remapped-Content-Length
X-HTML-Minification-Powered-By
Accept-Language
Countrycode
X-Upgrade-Enabled
X-Debug-IsPreview
X-Debug-IsConnected
X-Mg-Request-UUID
X-DataDome
X-DynaTrace
Xet-Cookie
Backend
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Signature
X-B-Cache
X-Generated-By
CF-IPCountry
Webserver
X-ID
X-DynaTrace-JS-Agent
X-Nginx-Cache
X-Xrds-Location
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
X-Varnish-Ttl
Xserver
X-Mode
X-ECache
X-Httpd
Liferay-Portal
X-Servername
Url
X-Tec-Api-Version
X-Tec-Api-Root
X-Tec-Api-Origin
X-Tt-Logid
X-B3-SpanId
X-NYM-Debug-Backend
X-Content-Age
X-Content-Powered-By
X-Device-Type
X-Drupal-Cache-Contexts
GEO-INFO
X-Erf-Web-Scheduler
X-MCACHE
X-Zen-Fury
Azure-SlotName
X-UPSTREAM-Address
X-Urbn-Context-Path
X-Rewrite-Enabled
S-Rt
X-Cache-Operation
Onion-Location
X-LAGOON
X-Urbn-Site-Id
X-Cache-Action
X-Container-Uri
X-Git-Commit
X-JoinUs
X-Varnish-Cache-Hits
Meta-Geo
X-ServerID
Locale
Azure-RegionName
Azure-Version
X-Director
Azure-InstanceId
X-SaId
Load-Balancing
Filters
X-Storage
Azure-SiteName
X-Cluster-Node
X-Say-TTL
X-SayCDN-TTL
X-Soup
X-Proto
X-Say-Cacheable
Uber-Trace-Id
X-XRDS-LOCATION
X-Tb
X-Served-From
X-Generation-Time
X-Detected-As
X-Sucuri-Cache
X-Forwarded-Host
X-Sucuri-ID
X-Varnish-Hostname
X-VC-Cache
X-VCT
Web-Mar-Node
X-RM-Cache-TTL
X-Cache-Server
X-Ms-Request-Id
X-Logging-Id
X-Labrador-Cache-Channel
X-PHP-Host
X-Ms-Version
TWC-GeoIP-LatLong
Webcakes-Region
X-Adobe-Source
X-Zipkin-Id
X-Routing-Service
Webcakes-App-Version
TWC-Locale-Group
DB-Nickname
X-Origin-Hint
TWC-Privacy
Webcakes-App-Name
X-R9-Blue-Green-Version
X-Sql-Duration-Ms
X-Sql-Count
X-Proxied
Node
Property-Id
X-RCS-CacheZone
X-GeoCountry
X-GeoCode
X-Extlb
TWC-Connection-Speed
TWC-GeoIP-Country
Fastcgi-Useragent
X-Skip-Cache
Mn-Server-Ip
TWC-Device-Class
X-Proxy-Build
X-Uri
X-Tumblr-Pixel-2
X-Debug
X-FB-TRIP-ID
X-Format
X-Tumblr-Pixel-3
X-Template
X-Timing-Wait
Selected-Fe
X-Lambda-Id
X-LSADC-Cache
X-Fetched-On
OT-Force-Account-Verify
Source
CDN-RequestId
X-Loop
X-MP-GENERATED-AT
X-Ratelimit-Reset
X-Tncms
Fastly-Drupal-HTML
X-Cache-Hit
X-Pass-Why
X-Origin-Date
X-URL
X-Endurance-Cache-Level
X-Cache-Expired-At
X-Varnish-Hits
X-Srv
X-TimeS
X-Redis-Cache
X-Ua
Cross-Origin-Window-Policy
Content-Secure-Policy
Upgrade-Insecure-Requests
X-Cache-TTL-Remaining
X-Real-IP
X-Hcs-Proxy-Type
X-CCDN-CacheTTL
X-CCDN-Origin-Time
Section-Io-Id
X-UA-Device-Type
X-Pubstack
X-Origin-TTL
X-Origin-CC
Section-Origin-Responded
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
X-AIR-PT
X-NGENIX-Cache
X-Fastly-Request-Id
X-Via-JSL
X-Rn-Rsrv
X-Server-W
X-S
X-Datadome
X-Node-Name
X-Newrelic-Synthetics
NGB
MS-CV
Cache-Provider
X-GEO
X-RTag
X-CSRF-Token
Cache-Hits
Ms-Operation-Id
CDN-Uid
CDN-RequestPullSuccess
CDN-Cache
CDN-EdgeStorageId
CDN-CachedAt
CDN-PullZone
CDN-RequestCountryCode
CDN-RequestPullCode
X-Cache-Host
X-Akamai-Transformed
X-Hl-Ver
Cache-Name
X-Restarts
X-Reqid
X-Xfnlog-Site
X-Optimistic-Header
X-IPLB-Instance
X-Cms-Context
X-Cache-Type
X-IPLB-Request-ID
Apigw-Requestid
X-PHP-Backend
X-ProxyCache-Key
X-BYPASS-REASON
X-ProxyCache-Status
X-Parent-Response-Time
X-Handled-By
X-No-Session
Odigeo-Trace-Id
Redirect-Candidate
X-SRCache-Key
Rendered-Blocks
Ngx.Var.Host
X-Tenant
X-Vdms-Path
X-VG-WebCache
X-Viewer-Country
Server-Host
X-Var-Ttl
X-Vdms-Version
Sslversion
VNS-Cache
VNS-Age
W
We-Hiring
Web-Mar-Region
T-Server
X-SD-PageType
X-Slack-Backend
X-Vtex-Remote-Cache
X-Shop-Environment
Surrogated-Key
X-Slack-Shared-Secret-Outcome
N-Cache
Xc-Version
Fastly-Backend-Name
Fastly-GeoIP-CountryCode
Fastly-SSL
Gannett-Cam-Experience-Id
DCR-Processing-Time-Ms
DCR-Decision-By
Canary
BehaviorPad-Version
Candidate-Md5Url
CPC-Age
CPC-Cache
Gh-Request-Id
Ha-Gx-Prefs
X-Wikidot-Static-Cache
MD5-Digest
Meta-Geo-Continent
X-A
X-Wikidot-Backend
Mail-Subject
Magicmarker
HA-Ipaddr
L
L5d-Success-Class
Lang
X-We-Are-Hiring
X-Rojux
X-Csrf-Jwt
X-Cache-Bucket
X-Cache-Info
X-Ec-Fail
X-Ec-Custom-Error
X-Ec-GeoHdr
X-Epic-Correlation-Id
X-FC-Vary-Parameters
X-Bl-Debug
X-Fastly-Backend
X-External-Request-Id
X-Eu-Site
X-Cache-NE
X-CacheTTL
X-Debug-Cache-Store
X-CF-Lambda-Version
X-Debug-Cache-Fetch
X-Date
X-D
X-CF-Lambda-Fn
X-CGP
X-Cdn-Diag
X-Dispatcher-Number
X-Developer
X-Destination
X-Forwarded-Path
X-Gdpr
X-Policy
X-RateLimit-Limit-Second
X-A-Dcw
X-A-Dgt
X-A-Wwc
X-A-Dam
X-RateLimit-Remaining-Second
X-ScT
X-S-Cookie
X-Request-Host
X-Conf
X-Origin-Time
X-Accel-Expires-Debug
X-B-Cookie
X-Application
X-Bc-Bl
X-BCube-Filmed-By
X-GeoIP-Country-Code
X-GeoIP-Region-Code
X-App
X-Orig-Expires
X-Aed
X-Nyt-Route
X-Mvc-Supplant-Cachable
X-A-Ccd
Vix-Hermes-Req-Id
X-CACHE-AGE
X-Cluster
ServedBy
X-AWS-Id
X-VWS-Id
X-LJ-Flow-ID
X-Nitro-Cache
Memcached
X-Org
X-Node-Id
X-Old-Content-Length
X-Origin-Response-Time
X-Pool
Host-ID
X-Server-IP
X-Platform
X-PERF
X-Owner
Machine
X-PAYTM-SRV-ID
X-Esi-Check
X-Access
X-Human
X-Irp-Debug
Req-Svc-Chain
X-Generated-On
X-Hash
X-Gzip
X-Geo-Header
X-Has-Esi
X-Is-Gdpr
Release
X-Mly-Id
X-BBC-Edge-Cache-Status
X-Fmm-Version
Origin
X-Mid
X-JWT-State
X-Level-Front-Cache
True-Client-Country-4JS
X-ShardId
X-Request-Time
X-Section
X-Varnishpool
X-VG-TLSProxy
X-Cache-Id
X-ShopId
X-Up
Cmsid
X-Thanos
X-Clara-WADP
X-Alternate-Cache-Key
X-ApacheServer
X-WADP-Cache
X-Wix-Viewer-Type
X-Worker
X-Auto-Login
X-Bip
X-Cache-Debug
X-App-Name
AKAMAI
Cmstype
X-Accel-Buffering
X-Sorting-Hat-ShopId
X-Core-Value
X-Sorting-Hat-PodId
X-Clientip
Environment
Expect-Staple
X-Storefront-Renderer-Rendered
Datacenter
X-Test
X-Shopify-Stage
User-Cache-Control
X-Proxy-Cache-Status
X-Correlation-ID
X-Tx-Id
X-Block-Status
Thinkindot-CacheControl
X-Gen-Mode
X-DefHash
X-DefElseHash
TDXMobile
Thinkindot-Control
X-Forwarded-Site
X-Core-Mission
X-CMSURLCustom
X-Cdn-Srv
X-Cdn-Origin
X-DPWN-IS-SECURE
Thinkindot-CacheControl-Type
X-From
X-Dispatcher-Server
X-Mvc-Supplant-OutputCached
Esi-Enabled
DSUID
X-SVT-ORM-RULES
X-Sn-Servicetimems
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
X-S-Maxage
X-Scale
X-SVT-ORM-VERSION
Country-Code
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
Apple-News-Services-Request-Url
X-Variation
X-Thinkindot-L3
CDCHOST
X-Vmg-Version
Apple-News-Services-Handled
Producers
Platform
X-WA-Info
X-INCAP-ABP
Server-Ext
Sever-Int
Server-Hostname
X-Hnp-Log
Is-Eu
X-Loc
X-NodeID
Adler-Geo
X-Origin
X-Qloud-Router
NM-Fastcgi-Cache
X-Nginx-Cache-Key
X-Nananana
X-VServer
X-Via-Fastly
X-Cache-Enabled
X-Presslabs-Stats
X-Op-Id-All
X-NCache
X-LB-NoCache
X-Device-Os
X-Refresh
X-TIM-N
X-GeoIP
X-TA-CDN-Provider
X-Instance-Name
Wxu-Next-Commit
Wxu-Next-Hostname
Wxu-Next-Region
X-Vcl-Version
WP-Super-Cache
Ssr
CloudFront-Viewer-Country
Pics-Label
C-Via
X-Akamai-Device-Characteristics
Server-Info
X-Cs
X-Cache-Status-Check
X-Air-Hostname
Server-ID
Origin-CC
X-Amz-Meta-Cb-Modifiedtime
Time
X-Air-Source
Hostname
X-Air-Trace-Id
Origin-EX
Memory
X-TIME
X-API-Version
AMP-Access-Control-Allow-Source-Origin
Cf-Device-Type
Origin-Agent-Cluster
X-HA-Backend
X-ZONE
X-Web-Node
NGX
X-Azure-Ref-OriginShield
X-Dc
GeoIP-Latitude
X-Varnish-Beresp-Grace
X-Tb-Optimization-Total-Bytes-Saved
X-VHOST
X-Varnish-Beresp-Ttl
X-Microcachable
X-Platform-Cluster
X-Platform-Processor
Cache-Host
X-Platform-Router
X-Origin-Expires
X-CACHE-GROUP
Cdn-Requestid
XM
X-Vgn-Hpd-Reason
X-Micro-Cache
X-Wp-Cf-Super-Cache-Active
X-Fpc
PFcat
X-HN
X-Internal-Host
YJS-ID
X-Site-Version
X-Locale
X-DC
X-VarnishDD-TTL
X-AB
Resin-Trace
X-B3-Spanid
X-Webkit-Csp-Report-Only
X-Ad-Defer-Variation
X-TraceId
X-WP-CF-Super-Cache-Active
Edge-Copy-Time
X-Via-CDN
Sid
Locid
X-FL-QIT-DEBUG
X-FL-EDGE
Srvid
X-Via-SSL
X-Via-Edge
A
X-Zone
Location
X-Geo-Region
X-Buckets
X-FTR-Request-ID
X-LiteSpeed-Cache-Control
Uri
True-Client-Ip
IsBot
X-Pod-Name
X-SIPLIST1
X-Github-Request-Id
X-Moov-T
X-Moov-Xdn-Version
X-Accel-Version
X-Contensis-Viewer-Groups
X-B3-Parentspanid
User-Agent
X-ATG-Version
X-DataCenter
X-Cache-ASPX
X-Cached-By
X-FireWall-Port
X-Upstream-Ht
X-Upstream-Ct
GeoIP-Country-Code
X-Backend-Instance
X-Varnish-Authentication
Cache-Key
X-Info
X-Is-Tablet
CF-Ctrl
X-Tcp-Rtt
X-VCache
X-Browser-Name
X-Is-Supported-Browser
X-Is-Mobile
X-Is-Desktop
X-NGINX-Cache
X-Nitro-Rev
X-Datacenter
X-Nitro-Cache-From
X-Platform-Server
GeoIp-Country-Code
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
Cdn
NtCoent-Length
X-HS-Content-Campaign-Id
X-MSEdge-Flight
X-MSEdge-Features
State
X-VC
X-LiteSpeed-Tag
SID
Lb
X-CS
X-Fastly-Cache
X-Hyper-Cache
X-Release
Epwk-X-Cache
X-Geo
XServer
X-Provided-By
X-NewRelic-App-Data
X-CSRF-TOKEN
X-Rocket-Build-Number
X-Cache-Remote
X-HostName
Path
Tcn
True-Client-IP
X-Sigma-Backend
X-Sigma
X-RN-RSRV
X-HS-Status
X-TRACE-ID
Fastly-Drupal-Html
X-Frame-Option
Cache
X-Vgn-Hpd-Cached
X-Service
X-Vgn-Hpd-Ssi
X-Vgn-Hpd-Variations-Key
X-SRV
X-Webstats-RespID
X-FPC
X-Generated-In
X-GeoIP-City
X-Api-Version
X-Scheme
X-Gamma-Serve
X-GoCache-CacheStatus
X-Pad
X-Origin-Cache-Key
Cf-Ipcountry
X-APP-VERSION
X-UA
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
CountryCode
Serverid
X-Esi
Cdncip
X-Air-Pt
Cdnsip
X-AK-Request-ID
Ohc-File-Size
X-Amz-Meta-Opti
Cdn-Request-Time
Cdn-Host
X-Edge-Server
X-Guploader-Uploadid
Cache-Tv-Group
X-Traceid
X-Vercel-Cache
X-FTR-Backend
X-FTR-Backend-Server
X-FTR-Balancer
X-FTR-Expires
WebServer
X-NMSegId
X-Vercel-Id
X-Wp-Cf-Super-Cache-Cache-Control
X-FTR-Cache-Status
X-Cache-Ttl
X-Country-Code-Real
X-Wp-Cf-Super-Cache
X-EC-Lua
Req-ID
M-TraceId
X-Branch-Name
Kp-EeAlive
X-Cdn-Request-ID
X-Wp-Cf-Super-Cache-Cookies-Bypass
LB
X-Cdn-Cache-Status
Env
WZWS-RAY
Cluster
XkeyRZ
X-Proxy-CacheRZ
Yak-Timeinfo
X-Vc
Proxy-Connection
X-Location
X-Mobile-URL
X-CACHE-KEY
CDN
X-VCL-Version
HostName
X-Akamai-Pragma-Client-IP
X-Men
X-Ad-Load-Variation
Pramga
X-Edge-Pop
On-Server
Ngx
X-Cdn-Forward
X-M-Log
X-Aicache-OS
X-Request-Start
X-Developers
X-M-Reqid
X-Cache-Tags
X-Region-Sid
X-NWS-UUID-VERIFY
Geoip-Latitude
CacheControlHeader
Srv
Ohc-Cache-HIT
X-Lb-Cache
X-Minions-Version
Click-Count-Error
X-Cache-FS-Status
X-Ha-Backend
X-Nc
Server-Id
X-TX-ID
X-B3-Trace-ID
Mime-Version
X-V-Cache
Content-Script-Type
Content-Style-Type
Click-Count-Action-Start
X-Via-Poph
Tube-Get-Contents
X-Qnm-Cache
RNT-Time
X-Wa
V-Age
Tube-Got-Eval
Tube-Return
X-Varnish-Beresp-Status
X-Tim-N
Tube-Got-Results
X-Scope-Id
X-Servedbyhost
X-Acquia-Purge-Cdn-Unconfigured
X-CDN-Cache-Status
X-LB-ID
X-Req
X-Via-Popn
X-SB
RNT-Machine
X-Via-Popv
X-WP-CF-Super-Cache-Cookies-Bypass
CF-Cached-On
X-TT-LOGID
X-RID
X-IN-APIGATEWAYSSL
X-Edge-POP
WWW-Authenticate
X-Dw-Trace-Id
ENV
X-IN-APIGATEWAY
X-Snapshot-Date
Edge-Cache
X-Cache-Date
X-MiniProfiler-Ids
X-Shield-Cache-Expires
X-Request-URI
X-Acquia-Site
X-Check-Cacheable
X-Acquia-Application-Trace
X-Via-Ucdn
X-Lb-Nocache
X-Acquia-Application-UUID
PICS-Label
X-Acquia-Purge-Tags
X-Litespeed-Cache-Control
X-Fastly-Country-Code
Yjs-Id
X-ElasticPress-Query
X-Fastly-Backend-Reqs
Vha6-Origin
X-CUA
X-Cached-Since
X-RAMCache
X-Fastly-Cache-Hits
X-Miniprofiler-Ids
Inserted-Into-Cache-At
Cneonction
X-User
X-Iauth-Set-Uid
Log-Origin
CACHE-MISS-TO-ORIGIN