Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
Link
CF-Cache-Status
Accept-Ranges
CF-RAY
ETag
X-XSS-Protection
Expect-CT
Pragma
X-Powered-By
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-UA-Compatible
X-Cache-Hits
Alt-Svc
P3P
X-Served-By
X-Xss-Protection
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Adblock-Key
X-Runtime
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Cache-Status
X-Generator
X-Cacheable
Timing-Allow-Origin
X-Request-ID
X-Content-Security-Policy
P3p
X-Iinfo
Status
Feature-Policy
X-Envoy-Upstream-Service-Time
Content-Encoding
Access-Control-Expose-Headers
X-CDN
X-Drupal-Dynamic-Cache
Upgrade
X-AspNetMvc-Version
X-Via
CF-Ray
Access-Control-Max-Age
X-Ws-Request-Id
Server-Timing
EagleId
Keep-Alive
X-Cache-Group
X-Turbo-Charged-By
Request-Context
X-Age
X-Proxy-Cache
X-Server-Powered-By
X-AH-Environment
X-Hacker
X-Backend
X-UA-Device
X-Robots-Tag
Report-To
X-Amz-Request-Id
X-LiteSpeed-Cache
Host-Header
X-Server
X-Amz-Id-2
Grace
X-Rq
X-Nginx-Cache-Status
X-Varnish-Cache
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-WebKit-CSP
X-Dns-Prefetch-Control
X-Page-Speed
X-Vhost
X-OneAgent-JS-Injection
X-Amz-Version-Id
EagleEye-TraceId
X-Device
X-Dispatcher
X-Pingback
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Cache-Spec
NEL
X-Server-Id
X-Host
X-Backend-Server
X-Node
Cf-Railgun
Accept-CH
X-Readtime
X-Akam-SW-Version
Surrogate-Control
Request-Id
X-Response-Time
X-HW
X-Language
Xkey
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Content-Location
X-Template
X-Application-Context
X-Ruxit-JS-Agent
Rating
X-B3-TraceId
X-Ua-Compatible
Accept-Ch-Lifetime
X-Country
Accept-CH-Lifetime
X-Cloud-Trace-Context
X-Cache-Lookup
Allow
X-Buckets
X-Ac
X-Url
X-Content-Type
X-Trace
X-TtlSet
X-PC
X-Vname
X-Mod-Pagespeed
X-Varnish-TTL
X-Clacks-Overhead
Edge-Control
X-FastCGI-Cache
X-ESI
Cache-Tag
Fastly-Restarts
X-Rack-Cache
Service-Worker-Allowed
X-VARITI-CCR
X-Element-Page-Cache
X-Server-Name
Verso
X-GitHub-Request-Id
X-MS-InvokeApp
X-Amz-Rid
X-Vcap-Request-Id
X-Upstream
X-Dw-Request-Base-Id
MS-Author-Via
Public-Key-Pins
X-D2id
X-Client-IP
X-Origin-Cache
X-Abt-Application-Version
X-Cached
X-Cache-TTL
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
X-Aspnetmvc-Version
Arr-Disable-Session-Affinity
X-Country-Code
X-Navigation-Version
X-Goog-Hash
X-Powered-By-Plesk
X-Px
X-Cnection
X-NF-Request-ID
X-Version
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-Instrumentation
Access-Control-Request-Method
X-Amz-Server-Side-Encryption
X-Aws-Lambda-Call-Status
Accept-Ch
RTSS
X-Powered-CMS
X-Middleton-Display
Pagespeed
X-Sol
Display
X-SRCache-Fetch-Status
X-SRCache-Store-Status
Response
X-Middleton-Response
X-MSEdge-Ref
X-Use-Magma
X-Kinja-Server
X-Exp-Variant
X-Exp-Id
X-Cdn-Fetch
X-Kinja-Revision
X-GoogleNews-Bot
X-Kinja-Build
X-Kinja
X-CST
X-LLID
X-Edge
X-Kinsta-Cache
X-Edge-Location-Klb
Nginx-Cache
X-Shield-Request-Id
MRF-Tech
X-B3-TraceId-Primal
X-TTL
Mrf-Cache-Status
S
X-HP-Trace-Id
Content-MD5
X-Jurisdiction
X-HP-Webp
X-T
AR-ATIME
AR-Request-ID
AR-CACHE
AR-PoweredBy
AR-SID
X-Forwarded-For
X-Content-Security-Policy-Report-Only
X-Protected-By
TCN
X-Mg-S
X-RateLimit-Remaining
X-Id
X-Mid
X-MCACHE
Fastcgi-Cache
X-Parallel-Accel
Realpath
Front-End-Https
SPRequestDuration
SPIisLatency
X-Recruiting
Edge-Cache-Tag
X-Ttl
X-Request-Processing-Time
X-Request-Received
Filters
Pinterest-Version
X-Pinterest-Rid
Pinterest-Generated-By
Fusion-Source
Server-Node
Fusion-Template-Id
Fusion-Deployment-Id
Fusion-Content-Id
Fusion-Component-Id
Fusion-Content-Source
SPRequestGuid
X-SharePointHealthScore
X-Ab
X-Content
X-Ua-Browser
X-Ezoic-Cdn
X-DynaTrace
X-Correlation-Id
Alternate-Protocol
X-Accel-Expires
Server-Name
X-Ruxit-Js-Agent
X-ECACHE
X-HS-Combine-CSS
X-HS-Hub-Id
X-HS-Content-Id
X-Frontend
X-HS-Cache-Config
X-NWS-LOG-UUID
X-Hits
X-Cache-Key
X-Yandex-Sdch-Disable
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Content-Options
Cache-Tags
X-Git-Hash
Host
X-Page-Id
MicrosoftSharePointTeamServices
Charset
X-Fastly-Request-Id
Cleartype
X-Www-Served-By
X-B3-Sampled
X-Geo-Country
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
TP-Cache
X-Amz-Replication-Status
TP-L2-Cache
X-Content-Digest
X-Forwarded-Proto
Filterid
X-Ser
X-Varnish-Age
X-Hostname
X-VCache
X-Amzn-Trace-Id
X-AppVersion
X-XRDS-LOCATION
X-Az
X-Activity-Id
X-Microsite
X-Request-Handler-Origin-Region
X-Rid
X-Debug-Info
X-DIS-Request-ID
X-Upgrade-Enabled
X-Daa-Tunnel
X-Origin-Server
Access-Control-Allow-Method
X-Grace
X-LB-Cache
X-N
X-FB-Debug
X-WebKit-CSP-Report-Only
ServerID
X-Origin-Upstream-Status
X-Nginx-Upstream-Cache-Status
X-Mobile-URL
X-Providence-Cookie
X-Whom
X-Is-Crawler
X-Flags
X-Request-Guid
X-Route-Name
X-Aspnet-Duration-Ms
X-Goog-Generation
X-TT
X-Goog-Metageneration
X-GUploader-UploadID
X-NGENIX-Cache
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-App-Environment
X-App-Server
X-PressLabs-Stats
X-Varnish-Grace
Viewport
X-F-Cache
X-Logged-In
X-Distributor
Cross-Origin-Opener-Policy
Payment
Node
DC
X-FW-Hash
X-FW-Server
X-FW-Static
X-FW-Serve
X-FW-Dynamic
X-Cache-Control
Paypal-Debug-Id
X-FW-Type
X-Server-ID
X-Tb
Fastcgi-Useragent
X-Cache-Age
X-Type
X-Seen-By
X-User-Agent
Country
Accept-Charset
X-Varnish-Backend
X-Cache-Rule
X-Node-Name
X-DataDome
X-Load-Cache
X-Webkit-CSP
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Browser-Type
Version
X-Tec-Api-Version
X-Ratelimit-Limit
X-Tec-Api-Origin
X-Tec-Api-Root
X-Cache-Action
X-Wix-Request-Id
Refresh
X-IPLB-Instance
X-Via-JSL
X-Response-Served-From
Liferay-Portal
SD-X-WS
Access-Control-Request-Headers
Cache-Status
X-Original-Request-Id
X-Jobs
X-Real-IP
Amp-Access-Control-Allow-Source-Origin
X-Cacheable-TTL
VIX-Pulpo-Node
X-Drupal-Cache-Tags
Referer-Policy
NGB
X-Debug
VIX-Pulpo-Upstream-Status
X-Vgn-Hpd-Reason
X-Proxy-Cache-Status
X-Is-Bot
X-ProcessESI
X-Page-View
X-RemovedCookies
X-UUID
X-Revision
X-B
X-Cluster-Name
X-Contextid
X-Rendered-As
X-Proxy
X-Rule
X-Yottaa-Optimizations
X-Cache-Expired-At
X-Device-Type
X-Yottaa-Metrics
X-Drupal-Cache-Contexts
X-Azure-Ref
X-Instance
X-Mobile
X-Fastly-Request-ID
X-G
X-Framework
X-Cache-Time
Healthy
DynaTrace
Akamai-GRN
X-B-Cache
X-Debug-IsPreview
X-Debug-IsConnected
X-Signature
Surrogate-Key
X-Fastcgi-Cache
X-FW-Version
X-Source
CF-IPCountry
X-TEC-API-ORIGIN
X-TEC-API-ROOT
SID
X-TEC-API-VERSION
X-Air-Trace-Id
X-Air-Source
X-Air-Hostname
X-Ms-Version
X-Ms-Request-Id
Frame-Options
X-Cache-Hit
X-XRDS-Location
X-Oracle-Dms-Rid
X-Oracle-Dms-Ecid
X-RTag
MS-CV
Ms-Operation-Id
Section-Io-Cache
X-APP-VERSION
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-Tumblr-Pixel
Countrycode
X-Tumblr-User
X-CDN-Forward
Xserver
X-L-Path
X-Nginx-Cache
X-Varnish-Server
X-Environment-Context
X-Oneagent-Js-Injection
X-Region
X-Servername
Count-Hit
GEO-INFO
X-EdgeConnect-Cache-Status
X-Forwarded-Host
X-Cache-Operation
X-Content-Powered-By
Uber-Trace-Id
X-Backend-Name
X-IPS-LoggedIn
Cross-Origin-Window-Policy
Backend
X-Litespeed-Cache
X-Mode
X-Adobe-Loc
X-Adobe-Content
X-Accel-Buffering
X-SaId
Meta-Geo
X-UPSTREAM-Address
X-Zen-Fury
Ec-Rule-Version
X-RN-RSRV
X-JoinUs
X-Detected-As
X-Cache-Type
X-Redis-Cache
X-Human
X-Debug-Cache
X-Sorting-Hat-PodId
X-Cache-Grace
Eomportal-Instance
X-Sorting-Hat-ShopId
X-Varnish-Beresp-Grace
X-Shopify-Stage
X-ShopId
X-ShardId
X-Generation-Time
X-Cache-Server
X-Hosted-By
X-Alternate-Cache-Key
Apigw-Requestid
X-Via-Fastly
X-Sql-Count
X-Sql-Duration-Ms
X-Site-Version
X-Cache-TTL-Remaining
X-No-Session
X-Microcachable
X-ServerID
X-Status
X-Uri
Decoy-Debug-TTL
X-Storage
Url
Decoy-Debug-Status
Decoy-Debug-Key
Cache-Name
Cache-Tv-Group
Country-Code
X-FB-TRIP-ID
X-BYPASS-REASON
X-NCache
X-ProxyCache-Key
X-Origin-Date
X-ProxyCache-Status
X-PHP-Backend
X-Timing-Wait
TWC-Locale-Group
X-Cache-Host
Webcakes-App-Name
Webcakes-App-Version
X-UA-Device-Type
Webcakes-Region
X-Akamai-Edgescape
X-Azure-Ref-OriginShield
X-Web-Node
X-Proxy-Build
Fastly-SSL
X-Origin-Hint
TWC-Device-Class
Mn-Server-Ip
Source
X-Say-TTL
X-Say-Cacheable
X-Format
TWC-GeoIP-LatLong
TWC-GeoIP-Country
TWC-Privacy
TWC-Connection-Speed
Property-Id
X-SayCDN-TTL
Protected
Selected-Fe
OT-Force-Account-Verify
Azure-InstanceId
X-PERF
X-NYM-Debug-Backend
X-Access
Azure-SlotName
X-Proxied
Azure-Version
Azure-SiteName
Azure-RegionName
X-ApacheServer
X-Hl-Ver
X-Extlb
X-Pubstack
X-Section
X-PCL
X-R9-Blue-Green-Version
X-Server-W
X-OCL
X-Zipkin-Id
X-Time
X-Routing-Service
X-Varnishpool
X-Cluster-Node
X-RateLimit-Limit
X-LSADC-Cache
Content-Secure-Policy
X-Be
X-SRV
X-Tid
X-Rewrite-Enabled
X-Cache-Var-Map
X-Cache-Var
X-Ua
X-HTML-Minification-Powered-By
X-Cache-NGX
X-Amz-Meta-S3cmd-Attrs
X-Soup
SRV
DB-Nickname
Content-Disposition
X-Webkit-Csp
X-NewRelic-App-Data
X-Content-Age
X-Dc
X-Ratelimit-Reset
X-Cached-By
X-LAGOON
X-Varnish-Hits
X-Varnish-Hostname
X-Loop
X-Unique-Id
Retry-After
X-TNCMS
CDN-Cache
CDN-CachedAt
CDN-RequestCountryCode
CDN-Uid
X-Generated-By
CDN-RequestId
X-S-Maxage
CDN-PullZone
CDN-EdgeStorageId
Cache
Onion-Location
X-App-Version
X-Bc-Bl
Webserver
X-Hyper-Cache
X-Auto-Login
X-Origin-CC
X-Origin-TTL
X-Tumblr-Pixel-2
X-Tumblr-Pixel-3
X-Proto
X-ECache
Web-Mar-Node
X-GEO
X-TT-LOGID
X-Presslabs-Stats
Cache-Hits
X-M-Log
X-M-Reqid
X-Tenant
X-Trace-Id
X-Qnm-Cache
X-Time-Microsecs
X-Nginx-Cache-Key
X-Endurance-Cache-Level
X-Cdn
X-Akamai-Transformed
X-Edge-Location
X-GG-Cache-Date
X-VWS-Id
X-LJ-Flow-ID
X-AWS-Id
Xet-Cookie
CloudFront-Viewer-Country
Mime-Version
X-Mg-Request-UUID
X-Amzn-RequestId
X-CSRF-Token
X-PHP-Host
X-Amz-Apigw-Id
X-Labrador-Cache-Channel
X-Platform-Server
X-CACHE-KEY
LB
N-Cache
X-Locale
X-Storefront-Renderer-Rendered
X-Handled-By
HostName
X-B3-SpanId
X-RCS-CacheZone
X-Xfnlog-Site
X-Cache-Tags
X-Varnish-Cache-Hits
Upgrade-Insecure-Requests
X-Origin-Response-Time
X-VC-Cache
X-Adobe-Source
ServedBy
X-Request-Time
X-Reqid
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
From-Origin
X-Connection-Hash
X-Conf
X-SD-PageType
X-Shop-Environment
X-NAPM-TraceId
X-Orig-Expires
Xc-Version
X-PBS-Appsvrname
X-Planisys-CDN-TTL
X-A-Dam
X-A-Dcw
X-Slack-Backend
X-Vtex-Processado-Em
X-A-Ccd
X-Vtex-Remote-Cache
X-Cluster
X-Processor
X-A
X-ScT
X-AOL-HN
X-Session-Fingerprint
Pramga
Redirect-Candidate
X-Forwarded-Path
X-Ftr-Request-Id
X-Developer
Meta-Geo-Continent
Odigeo-Trace-Id
Origin
X-External-Request-Id
Mobile-Detection-Method
Rendered-Blocks
X-Destination
X-Ig-Push-State
BehaviorPad-Version
X-D
A
Surrogated-Key
DCR-Decision-By
Fastcgi-X-Cache-Version
Expiry
DSUID
DCR-Processing-Time-Ms
X-A-Dgt
X-PAYTM-SRV-ID
X-VG-WebCache
X-Vdms-Version
X-S-Cookie
X-ARC
X-SVT-ORM-RULES
X-Aed
X-Vdms-Path
X-Application
X-ATG-Version
X-TIM-N
X-S
X-Cache-NE
X-Cache-Date
X-B-Cookie
X-SVT-ORM-VERSION
X-A-Wwc
Nel
X-Ckpd-Fst-Backend
X-Cache-Remote
X-Rojux
X-CF-Lambda-Version
X-V-Cache
X-Request-Host
Server-Info
X-CF-Lambda-Fn
X-SRCache-Key
X-Correlation-ID
X-Via-NSCOPI
X-MP-GENERATED-AT
Datacenter
X-Hnp-Log
X-Rocket-Nginx-Serving-Static
X-Hash
Candidate-Md5Url
X-Sucuri-Cache
CacheControlHeader
Cmsid
Cmstype
WPO-Cache-Message
L
WPO-Cache-Status
X-Forwarded-Site
X-Fetched-On
X-Fastly-Cache
X-Sucuri-ID
X-Device-Os
X-Block-Status
Host-ID
AKAMAI
X-Geo-Header
X-Date
X-Cache-Bucket
Gh-Request-Id
X-Gen-Mode
Release
X-Gdpr
Fastcgi-Cache-TTL
X-Varnish-Beresp-Status
X-Owner
X-Epic-Correlation-Id
X-Core-Mission
X-Cache-Info
X-Origin-Time
X-Origin-Expires
X-Nyt-Route
X-Old-Content-Length
User-Cache-Control
X-ND-Cache
State
X-Proxy-Upstream
X-Skip-Cache
X-Accel-Expires-Debug
X-Policy
X-VServer
Wxu-Next-Commit
Wxu-Next-Hostname
Wxu-Next-Region
Vix-Hermes-Req-Id
X-EC-Lua
X-Li-Pop
X-Server-IP
X-Location
X-Served-From
V-Age
X-LI-UUID
X-Scheme
X-Mvc-Supplant-Cachable
Environment
X-Li-Fabric
AMP-Access-Control-Allow-Source-Origin
X-TIME
TDXMobile
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
True-Client-Country-4JS
X-Cache-Debug
X-Datadog-Parent-Id
Thinkindot-Control
X-Aicache-OS
X-Developers
PFcat
We-Hiring
X-Cache-Id
X-Core-Value
X-Cache-Config
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
Server-Host
X-Bip
X-Cdn-Origin
X-BBC-Edge-Cache-Status
Svr
Req-Svc-Chain
Web-Mar-Region
X-Irp-Debug
X-Branch-Name
X-Level-Front-Cache
X-NodeID
X-Esi-Check
Apple-News-Services-Handled
Apple-News-Services-Host
X-Magnolia-Registration
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
X-VarnishDD-TTL
X-VG-TLSProxy
X-Request-Start
X-Sn-Servicetimems
X-Req
X-Region-Sid
X-Platform
X-Sigma-Backend
X-Viewer-Country
X-Men
X-Sigma
X-Rocket-Build-Number
Arc-Country
Machine
Locid
X-Gamma-Serve
X-Generated-On
Mail-Subject
X-Thinkindot-L3
X-Ratelimit-Remaining
X-TH-Server
X-Thanos
X-Fastly-Backend
X-GeoIP
X-GeoIP-City
X-HS-Content-Campaign-Id
X-Gzip
Fastly-GeoIP-CountryCode
CDCHOST
X-TrackingId
X-HN
X-Rebelmouse-Surrogate-Control
X-CGP
X-Request-URI
X-Varnish-Remaining-TTL
X-Varnish-CookieINHashed-On
X-UnsetCookies
X-Varnish-CookieHashed-On
X-Variation
Origin-EX
X-DefElseHash
X-Has-Esi
X-Is-Gdpr
X-JWT-State
X-DefHash
X-FC-Vary-Parameters
X-Envoy-Decorator-Operation
X-DPWN-IS-SECURE
X-Eu-Site
Traceparent
X-Csrf-Jwt
X-Worker
X-Qloud-Router
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Pod-Name
X-NU-AKA-ACS-Version
X-Loc
X-Origin
Origin-CC
X-Rebelmouse-Cache-Control
Fastly-SWR
HA-Ipaddr
Ha-Gx-Prefs
Fastly-SIE
Cf-Device-Type
Platform
Is-Eu
NM-Fastcgi-Cache
NGX
Memcached
L5d-Success-Class
Adler-Geo
WWW-Authenticate
X-Amzn-Remapped-Content-Length
X-Zone
X-Backend-State
X-Xrds-Location
X-Tx-Id
X-Webstats-RespID
Esi-Enabled
On-Server
Fastly-Drupal-Html
X-Varnish-Beresp-Ttl
X-FireWall-Port
CDN
X-NC
X-API-Version
X-CS
X-Mvc-Supplant-OutputCached
X-Up
X-Node-Id
Sslversion
X-Cdn-Srv
X-Tt-Logid
X-LB-ID
X-Service
X-Vc
X-Generated-In
C-Via
Pics-Label
X-Response-By
Ssr
X-CLOUD-TRACE-CONTEXT
X-Trace-ID
Time
Ms-Author-Via
Memory
WP-Super-Cache
X-Cache-PHP
X-Edge-Pop
X-Datadome
X-Refresh
X-DynaTrace-JS-Agent
X-TA-CDN-Provider
X-LB-NoCache
X-Cache-Status-Check
NtCoent-Length
X-TraceId
X-Tb-Optimization-Total-Bytes-Saved
X-Backend-TTL
X-Via-Popn
GeoIp-Country-Code
X-Via-Poph
X-Cache-Enabled
X-Via-Popv
X-Dynatrace
X-Varnish-Ttl
X-Render-Time
Env
X-GeoIP-Region-Code
X-GeoIP-Country-Code
X-Optimistic-Header
X-Info
X-Parent-Response-Time
Magicmarker
X-DC
X-Varnish-Beresp-TTL
X-Restarts
X-Esi
X-AIR-PT
X-Servedbyhost
X-Cs
X-Ua-Device
X-NWS-UUID-VERIFY
X-Unique-ID
X-Clientip
X-TX-ID
X-CacheTTL
Kp-EeAlive
Server-ID
X-ZONE
X-Oss-Storage-Class
X-Oss-Server-Time
HIT
UCS
Cache-Host
X-Oss-Hash-Crc64ecma
X-Oss-Request-Id
X-Oss-Object-Type
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
Section-Io-Id
Section-Origin-Responded
X-Srv
S-Rt
X-App
X-DW
Proxy-Connection
X-RPM
X-Action
Edge-Cache
X-MSEdge-Flight
X-DB
X-Cache-Backend
S-Cnection
X-MSEdge-Features
X-VCL-Version
X-Wix-Viewer-Type
X-Newrelic-Synthetics
X-DSS
WebServer
X-RSL
X-DI
X-RPS
Lb
X-Fpc
X-Li-Proto
X-LI-Proto
X-Cache-Ttl
X-URL
X-Minions-Version
User-Agent
X-HA-Backend
X-Webkit-Csp-Report-Only
X-Micro-Cache
Test
Fastly-Backend-Name
X-FPC
X-LiteSpeed-Cache-Control
X-Traceid
X-Pad
X-Vcl-Version
Server-Id
X-Backend-Host
X-B3-Spanid
X-NODE
X-Webkit-CSP-Report-Only
Geo-Info
X-BCube-Filmed-By
Tcn
X-ES-SERVER
X-Release
X-Pass-Why
X-Http-Reason
X-Akamai-Request-ID2
X-CSRF-TOKEN
Resin-Trace
X-BBC-Origin-Response-Status
X-Amz-Meta-Cb-Modifiedtime
CPC-Age
CPC-Cache
Fastly-Drupal-HTML
X-LiteSpeed-Tag
Hostname
X-User
Accept-Language
Cache-Key
VNS-Cache
VNS-Age
Path
X-HostName
X-APP
X-Ec-Fail
Cf-Int-Pingora-Origin-Digest
EpKe-Alive
X-Ec-GeoHdr
X-Akamai-Pragma-Client-IP
X-ServedByHost
X-WA-Info
X-ID
X-Dynatrace-Js-Agent
Locale
X-COUNTRY
X-Urbn-Context-Path
X-Urbn-Site-Id
Pagetype
Ohc-File-Size
X-PJAX-URL
X-NGINX-Cache
Hit
X-Cms-Context
X-WA
X-Check-Cacheable
Srv
GeoIP-Country-Code
X-Via-PopV
X-Ha-Backend
X-Via-PopH
X-Wikidot-Static-Cache
X-Wikidot-Backend
X-Via-PopN
X-Geo
X-Edge-POP
Cdnsip
X-WADP-Cache
X-Fmm-Version
X-Cdn-Forward
Shield-Pop
ENV
X-ElasticPress-Query
X-Clara-WADP
Cdncip
X-Via-Ucdn
M-TraceId
MIME-Version
MD5-Digest
X-AK-Request-ID
Cluster
My-App
X-Edge-Cache
Geoip-Latitude
URI
X-Api-Version
X-HS-Status
X-Hcs-Proxy-Type
X-CCDN-Origin-Time
X-CCDN-CacheTTL
X-VG-WebServer
Load-Balancing
X-Ucs
X-Fastly-Backend-Reqs
X-Cache-Expires
Tracecode
IsBot
X-SIPLIST1
Server-Hostname
Sever-Int
W
Server-Ext
X-Var-Ttl
X-CUA
X-Kraken-Routeconfig-Destination
X-From
X-ServerName
Lfy
T-Server
X-Provided-By
X-Mcache
X-UP
X-GoCache-CacheStatus
X-Lb-Id
X-TRACE-ID
X-Dw-Trace-Id
Vha6-Origin
X-Acquia-Application-UUID
WZWS-RAY
X-Acquia-Application-Trace
Lang
X-VC
X-Acquia-Purge-Tags
HitType
X-RateLimit-Reset
X-Cdn-Request-ID
Cdn
X-RAMCache
Servername
X-Fragments
Cteonnt-Length
X-Via-CDN
Cneonction
X-Acquia-Site
Ohc-Cache-HIT
X-Fastly-Cache-Hits
X-B3-ParentSpanId
X-Platform-Router
PICS-Label
X-Platform-Processor
X-Nc
X-Platform-Cluster
X-WP-CF-Super-Cache-Cache-Control
X-Apw-Access-Action
X-Apw-Access-Object
X-WP-CF-Super-Cache
Dnion-Transfer-Encoding
X-Akamai-Request-ID
Cf-Ipcountry
X-Newrelic-App-Data
X-Swift-Error
X-Apw-Access-Token
X-Apw-Hits
X-Contensis-Viewer-Groups
X-Cache-ASPX
X-Snapshot-Date
CF-Cached-On
Target-Params
FSS-Cache
Uri
X-Yottaa-OS
X-Cc-Via
X-Air-Pt
Sid
X-Cache-Ngx
X-Akamai-ERRuleID
X-Http-Count
X-Akamai-ERPolicy
X-Te-Duration-Ms
X-Te-Count
X-Http-Duration-Ms
PB-RID
X-Varnish-Authentication
X-Request-UUID
X-IN-APIGATEWAYSSL
X-IN-APIGATEWAY
X-Wa
X-Lb-Nocache
X-B3-Parentspanid
X-Miniprofiler-Ids
X-HTML-Edge-Cache
X-Edge-IP
X-Logging-Id
Arc-Version
CountryCode
X-Sentry-ID
Req-ID
PB-PID
X-77-NZT
X-CacheKey
X-UA
Ngx