Threat Level: green Handler on Duty: Jan Kopriva

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Link
Cf-Request-Id
CF-Cache-Status
Accept-Ranges
CF-RAY
ETag
X-XSS-Protection
Expect-CT
Pragma
X-Powered-By
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-UA-Compatible
X-Cache-Hits
Alt-Svc
P3P
X-Served-By
X-Xss-Protection
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Request-Id
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Cache-Status
X-Generator
X-Cacheable
Timing-Allow-Origin
X-Content-Security-Policy
P3p
X-Iinfo
Status
Feature-Policy
X-Request-ID
X-Envoy-Upstream-Service-Time
Content-Encoding
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
X-CDN
X-AspNetMvc-Version
Upgrade
X-Via
CF-Ray
X-Ws-Request-Id
Access-Control-Max-Age
Server-Timing
EagleId
Keep-Alive
X-Cache-Group
X-Turbo-Charged-By
Request-Context
X-Age
X-Server-Powered-By
X-Proxy-Cache
X-AH-Environment
X-UA-Device
X-Backend
X-Hacker
X-Robots-Tag
Report-To
X-Amz-Request-Id
Host-Header
X-Server
X-LiteSpeed-Cache
X-Amz-Id-2
Grace
X-Rq
X-Nginx-Cache-Status
X-Varnish-Cache
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-WebKit-CSP
X-Dns-Prefetch-Control
X-Page-Speed
X-Vhost
X-OneAgent-JS-Injection
EagleEye-TraceId
X-Amz-Version-Id
X-Pingback
X-Device
X-Dispatcher
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Cache-Spec
NEL
X-Server-Id
X-Host
Cf-Railgun
X-Backend-Server
X-Node
Accept-CH
X-Readtime
X-Akam-SW-Version
Surrogate-Control
Request-Id
X-Response-Time
X-HW
Xkey
X-Ruxit-JS-Agent
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Application-Context
Content-Location
Rating
X-Country
X-B3-TraceId
X-Ua-Compatible
Accept-Ch-Lifetime
Accept-CH-Lifetime
X-Cache-Lookup
X-Cloud-Trace-Context
X-Language
X-Url
X-Ac
X-Trace
X-Content-Type
X-Template
Allow
X-TtlSet
X-Vname
X-PC
X-Varnish-TTL
X-Mod-Pagespeed
X-Clacks-Overhead
Edge-Control
X-FastCGI-Cache
X-ESI
Cache-Tag
Fastly-Restarts
X-Server-Name
Service-Worker-Allowed
X-Rack-Cache
X-VARITI-CCR
X-Element-Page-Cache
Verso
X-MS-InvokeApp
X-GitHub-Request-Id
X-Upstream
X-Buckets
MS-Author-Via
X-Amz-Rid
Public-Key-Pins
X-Vcap-Request-Id
X-Dw-Request-Base-Id
X-Cached
X-Client-IP
X-D2id
X-Abt-Application-Version
X-Origin-Cache
X-Cache-TTL
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-Px
Arr-Disable-Session-Affinity
X-Cnection
X-Aws-Lambda-Call-Status
X-Goog-Hash
X-Country-Code
X-Powered-By-Plesk
X-Navigation-Version
X-NF-Request-ID
Access-Control-Request-Method
X-Instrumentation
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
RTSS
X-Version
Accept-Ch
X-Powered-CMS
X-Amz-Server-Side-Encryption
Display
Pagespeed
X-Middleton-Display
X-Sol
X-Kinja-Revision
X-Kinja-Server
X-Use-Magma
X-Kinja
X-Kinja-Build
X-Cdn-Fetch
X-Exp-Id
X-Exp-Variant
X-GoogleNews-Bot
X-SRCache-Store-Status
X-SRCache-Fetch-Status
Response
X-Middleton-Response
X-MSEdge-Ref
X-LLID
X-Edge-Location-Klb
X-Kinsta-Cache
X-Edge
AR-ATIME
AR-Request-ID
AR-SID
AR-CACHE
AR-PoweredBy
Nginx-Cache
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
X-RateLimit-Remaining
X-Shield-Request-Id
X-HP-Trace-Id
S
X-Jurisdiction
X-Protected-By
X-HP-Webp
X-T
Content-MD5
X-Forwarded-For
TCN
X-Content-Security-Policy-Report-Only
X-Mg-S
X-TTL
X-Id
X-CST
Realpath
X-Aspnetmvc-Version
X-Mid
Fastcgi-Cache
X-MCACHE
Edge-Cache-Tag
SPRequestDuration
SPIisLatency
X-Ttl
Front-End-Https
X-Parallel-Accel
X-Recruiting
X-Request-Received
X-Request-Processing-Time
Filters
Fusion-Deployment-Id
Fusion-Template-Id
Server-Node
Fusion-Source
Fusion-Content-Source
Pinterest-Version
Pinterest-Generated-By
Fusion-Content-Id
X-Pinterest-Rid
Fusion-Component-Id
X-Ab
X-Content
X-Ua-Browser
X-DynaTrace
SPRequestGuid
X-SharePointHealthScore
Server-Name
X-Ezoic-Cdn
X-NWS-LOG-UUID
X-Frontend
X-Correlation-Id
X-HS-Hub-Id
X-HS-Combine-CSS
X-HS-Cache-Config
X-HS-Content-Id
Alternate-Protocol
X-Yandex-Sdch-Disable
X-Hits
X-Cache-Key
X-Accel-Expires
X-ECACHE
X-Content-Options
X-Tt-Trace-Tag
X-Tt-Trace-Host
MicrosoftSharePointTeamServices
Cache-Tags
X-Page-Id
X-Ser
X-Git-Hash
Host
Charset
X-Kong-Upstream-Latency
Cleartype
X-Kong-Proxy-Latency
X-Fastly-Request-Id
X-B3-Sampled
X-Www-Served-By
X-Ruxit-Js-Agent
X-Geo-Country
X-Content-Digest
X-XRDS-LOCATION
X-Daa-Tunnel
X-Amz-Replication-Status
Filterid
X-Amzn-Trace-Id
TP-L2-Cache
TP-Cache
X-DIS-Request-ID
X-Forwarded-Proto
X-VCache
X-Hostname
X-Varnish-Age
X-Activity-Id
X-Az
X-AppVersion
X-Debug-Info
X-Rid
X-N
X-Grace
X-Origin-Server
X-Upgrade-Enabled
Access-Control-Allow-Method
X-FB-Debug
X-LB-Cache
X-Origin-Upstream-Status
X-WebKit-CSP-Report-Only
X-Nginx-Upstream-Cache-Status
ServerID
X-Mobile-URL
Cross-Origin-Opener-Policy
X-F-Cache
X-Request-Guid
X-Route-Name
X-Flags
X-Aspnet-Duration-Ms
X-Providence-Cookie
X-Is-Crawler
X-Whom
X-TT
X-NGENIX-Cache
X-Goog-Generation
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-GUploader-UploadID
X-Varnish-Grace
X-App-Environment
X-App-Server
X-Tb
Viewport
X-Microsite
X-Request-Handler-Origin-Region
X-FW-Type
X-FW-Server
X-FW-Dynamic
Payment
X-Distributor
X-FW-Hash
X-FW-Serve
X-FW-Static
Paypal-Debug-Id
X-Server-ID
Node
DC
X-Ratelimit-Limit
X-Seen-By
X-Cache-Control
X-Type
Fastcgi-Useragent
X-Logged-In
X-User-Agent
Country
Accept-Charset
X-Cache-Age
X-Cache-Rule
X-Litespeed-Cache
X-Wix-Request-Id
X-DataDome
X-Varnish-Backend
X-Webkit-CSP
Version
X-Node-Name
X-Erf-Bev-Bev-Is-Generated
X-Browser-Type
X-Load-Cache
X-Erf-Bev-Bev
X-PressLabs-Stats
X-Cache-Action
X-Via-JSL
X-Drupal-Cache-Tags
Referer-Policy
Refresh
X-Tec-Api-Root
X-Tec-Api-Version
X-Tec-Api-Origin
X-IPLB-Instance
Cache-Status
SD-X-WS
X-Response-Served-From
X-Cluster-Name
Access-Control-Request-Headers
Amp-Access-Control-Allow-Source-Origin
X-Original-Request-Id
X-Contextid
X-Page-View
X-Proxy-Cache-Status
X-Signature
X-Rendered-As
X-Vgn-Hpd-Reason
X-Jobs
X-Mobile
X-Is-Bot
X-Cacheable-TTL
X-B-Cache
X-Real-IP
X-RemovedCookies
X-Revision
NGB
X-Debug
X-UUID
X-B
VIX-Pulpo-Node
X-Cache-Expired-At
X-ProcessESI
VIX-Pulpo-Upstream-Status
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Device-Type
X-Rule
X-Proxy
X-Drupal-Cache-Contexts
Surrogate-Key
X-Cache-Time
X-Framework
X-Fastly-Request-ID
X-G
Akamai-GRN
X-Instance
X-Debug-IsConnected
X-Debug-IsPreview
DynaTrace
X-Fastcgi-Cache
X-FW-Version
CF-IPCountry
X-Air-Trace-Id
X-Air-Source
X-Air-Hostname
Liferay-Portal
SID
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-TEC-API-VERSION
Healthy
X-Azure-Ref
X-Source
X-Oracle-Dms-Ecid
X-Oracle-Dms-Rid
X-Nginx-Cache
X-Ms-Version
X-Ms-Request-Id
Frame-Options
MS-CV
X-RTag
Ms-Operation-Id
X-Oneagent-Js-Injection
X-APP-VERSION
X-CDN-Forward
X-Cache-Hit
Count-Hit
X-Tumblr-User
X-Tumblr-Pixel-1
Countrycode
X-Tumblr-Pixel
X-Cache-Operation
X-Tumblr-Pixel-0
X-L-Path
GEO-INFO
X-Environment-Context
X-Ratelimit-Reset
Xserver
X-Varnish-Server
X-EdgeConnect-Cache-Status
Uber-Trace-Id
X-XRDS-Location
X-Region
X-Accel-Buffering
Section-Io-Cache
X-Servername
X-Backend-Name
X-Forwarded-Host
X-Content-Powered-By
X-Mode
X-Presslabs-Stats
X-IPS-LoggedIn
X-Zen-Fury
Cross-Origin-Window-Policy
Ec-Rule-Version
Backend
X-JoinUs
X-RN-RSRV
X-Detected-As
X-SaId
Meta-Geo
X-UPSTREAM-Address
Eomportal-Instance
X-Cache-NGX
Country-Code
X-Cache-Server
X-Cache-Grace
X-ShopId
X-Sorting-Hat-PodId
X-Varnish-Beresp-Grace
X-Sorting-Hat-ShopId
X-Generation-Time
X-Human
X-Tid
X-Hosted-By
X-Redis-Cache
X-Sql-Duration-Ms
X-Shopify-Stage
X-Adobe-Content
X-Adobe-Loc
X-Sql-Count
X-Uri
X-Debug-Cache
X-Cache-Type
X-ShardId
X-Alternate-Cache-Key
X-Site-Version
X-UA-Device-Type
Mn-Server-Ip
Decoy-Debug-Key
Cache-Tv-Group
Cache-Name
Apigw-Requestid
X-ServerID
DB-Nickname
Decoy-Debug-Status
X-ProxyCache-Key
X-Status
Decoy-Debug-TTL
Url
X-Cache-TTL-Remaining
X-PHP-Backend
X-ProxyCache-Status
X-NCache
X-Microcachable
X-No-Session
X-FB-TRIP-ID
X-Origin-Date
X-BYPASS-REASON
X-Say-Cacheable
X-Say-TTL
X-Via-Fastly
X-Format
Webcakes-Region
X-Proxy-Build
X-Cache-Host
X-SayCDN-TTL
X-Web-Node
X-Origin-Hint
Fastly-SSL
TWC-GeoIP-Country
TWC-Device-Class
Webcakes-App-Name
X-Akamai-Edgescape
TWC-Locale-Group
TWC-GeoIP-LatLong
TWC-Connection-Speed
Selected-Fe
TWC-Privacy
X-Rewrite-Enabled
X-Timing-Wait
Property-Id
Protected
X-Storage
Webcakes-App-Version
X-Proxied
X-R9-Blue-Green-Version
X-Soup
X-Extlb
X-ApacheServer
X-Varnishpool
X-Access
X-Pubstack
X-Routing-Service
X-OCL
X-NYM-Debug-Backend
X-Zipkin-Id
X-PCL
X-Hl-Ver
X-Server-W
X-PERF
OT-Force-Account-Verify
X-Section
Azure-Version
Azure-SlotName
Azure-SiteName
Azure-InstanceId
Azure-RegionName
Content-Secure-Policy
X-Cluster-Node
X-RateLimit-Limit
X-Be
X-Azure-Ref-OriginShield
X-Ua
X-Content-Age
X-LSADC-Cache
Source
X-NewRelic-App-Data
CDN-Cache
CDN-RequestCountryCode
CDN-Uid
CDN-RequestId
CDN-EdgeStorageId
CDN-PullZone
CDN-CachedAt
X-Webkit-Csp
SRV
Cache
X-Generated-By
X-Dc
X-Cached-By
X-Hyper-Cache
Content-Disposition
X-HTML-Minification-Powered-By
X-Unique-Id
X-ECache
X-Amz-Meta-S3cmd-Attrs
X-LAGOON
X-SRV
X-App-Version
X-Bc-Bl
X-Nginx-Cache-Key
X-Time
X-Loop
X-Cache-Var-Map
X-Varnish-Hits
X-Varnish-Hostname
X-TNCMS
X-Cache-Var
X-S-Maxage
Onion-Location
Xet-Cookie
X-Auto-Login
LB
X-GEO
X-TT-LOGID
Retry-After
X-Trace-Id
X-Origin-TTL
Cache-Hits
X-Origin-CC
X-Tumblr-Pixel-3
X-TIME
Web-Mar-Node
X-Tumblr-Pixel-2
X-Proto
Mime-Version
WPO-Cache-Message
X-Cdn
X-CSRF-Token
X-Platform-Server
HostName
WPO-Cache-Status
X-Correlation-ID
X-Time-Microsecs
X-Tenant
X-Qnm-Cache
X-Endurance-Cache-Level
X-M-Log
X-Akamai-Transformed
X-M-Reqid
X-Edge-Location
Webserver
X-GG-Cache-Date
X-Cache-Remote
X-LJ-Flow-ID
X-AWS-Id
X-VWS-Id
X-Cache-Tags
CloudFront-Viewer-Country
X-Xfnlog-Site
N-Cache
X-Mg-Request-UUID
X-Varnish-Cache-Hits
Upgrade-Insecure-Requests
X-Amz-Apigw-Id
X-CACHE-KEY
ServedBy
X-Request-Time
X-Amzn-RequestId
X-PHP-Host
X-Labrador-Cache-Channel
X-AOL-HN
X-Ratelimit-Remaining
X-RCS-CacheZone
X-Via-NSCOPI
X-B3-SpanId
X-Handled-By
X-Origin-Response-Time
X-Locale
X-A
User-Cache-Control
Surrogated-Key
Rendered-Blocks
Origin
Expiry
DSUID
X-A-Ccd
Fastcgi-X-Cache-Version
Meta-Geo-Continent
DCR-Processing-Time-Ms
DCR-Decision-By
Pramga
A
Odigeo-Trace-Id
BehaviorPad-Version
Redirect-Candidate
X-Developer
X-S
X-Rojux
X-S-Cookie
X-ScT
X-SD-PageType
X-Request-Host
X-Processor
X-PBS-Appsvrname
X-PAYTM-SRV-ID
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Session-Fingerprint
X-Shop-Environment
X-VG-WebCache
X-Vdms-Version
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
Xc-Version
X-Vdms-Path
X-V-Cache
X-SRCache-Key
X-Slack-Backend
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-TIM-N
X-Orig-Expires
X-ND-Cache
X-Cache-Date
X-Block-Status
X-Cache-NE
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-B-Cookie
X-ARC
X-A-Dgt
X-A-Dcw
X-A-Wwc
X-Aed
X-Application
X-Ckpd-Fst-Backend
X-Cluster
X-Gen-Mode
X-Ftr-Request-Id
X-Hnp-Log
X-Ig-Push-State
X-NAPM-TraceId
X-Forwarded-Path
X-External-Request-Id
X-Conf
X-Connection-Hash
X-D
X-Destination
X-A-Dam
Mobile-Detection-Method
X-Storefront-Renderer-Rendered
Nel
X-VC-Cache
X-MP-GENERATED-AT
X-Reqid
X-Cache-Info
X-Accel-Expires-Debug
X-Cache-Bucket
X-Date
X-Device-Os
X-Gdpr
X-Forwarded-Site
X-Fetched-On
X-Fastly-Cache
X-Epic-Correlation-Id
Wxu-Next-Hostname
Origin-EX
Release
Origin-CC
L
Host-ID
State
Traceparent
X-Geo-Header
Wxu-Next-Commit
Vix-Hermes-Req-Id
V-Age
Wxu-Next-Region
X-Li-Fabric
X-Served-From
X-Server-IP
X-Scheme
X-Adobe-Source
X-Rocket-Nginx-Serving-Static
Server-Info
X-Skip-Cache
X-VServer
X-Webstats-RespID
X-Varnish-Beresp-Status
X-Sucuri-ID
X-Sucuri-Cache
X-ATG-Version
X-Proxy-Upstream
X-Location
X-Men
X-LI-UUID
X-Li-Pop
Gh-Request-Id
X-Mvc-Supplant-Cachable
X-Nyt-Route
X-Owner
X-Policy
X-Origin-Time
X-Origin-Expires
X-Old-Content-Length
X-Hash
X-Core-Mission
From-Origin
Fastcgi-Cache-TTL
Arc-Country
AKAMAI
Cmsid
CDCHOST
Cmstype
CacheControlHeader
Environment
AMP-Access-Control-Allow-Source-Origin
X-FireWall-Port
X-Thanos
X-TrackingId
X-Thinkindot-L3
X-TH-Server
X-Datadog-Parent-Id
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
X-Cdn-Srv
X-Core-Value
X-Cache-Config
X-VarnishDD-TTL
Web-Mar-Region
We-Hiring
X-VG-TLSProxy
X-BBC-Edge-Cache-Status
X-Bip
X-Platform
X-Cache-Debug
X-Sn-Servicetimems
X-Branch-Name
X-Cdn-Origin
X-Fastly-Backend
X-Irp-Debug
X-Level-Front-Cache
X-HS-Content-Campaign-Id
X-HN
X-Gzip
X-Rocket-Build-Number
X-Node-Id
X-Region-Sid
X-Req
X-Request-Start
X-NodeID
X-GeoIP-City
X-GeoIP
X-Magnolia-Registration
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
True-Client-Country-4JS
X-Esi-Check
X-Sigma-Backend
X-Sigma
Apple-News-Services-Handled
X-Generated-On
Apple-News-Services-Host
X-Gamma-Serve
X-Developers
X-Cache-Id
X-Viewer-Country
Sslversion
X-Aicache-OS
Thinkindot-CacheControl-Type
TDXMobile
Server-Host
Svr
PFcat
Fastly-GeoIP-CountryCode
Req-Svc-Chain
Thinkindot-CacheControl
Machine
Locid
Mail-Subject
Thinkindot-Control
WP-Super-Cache
Fastly-Drupal-Html
X-Zone
X-Response-By
Platform
Ha-Gx-Prefs
X-NU-AKA-ACS-Version
X-Csrf-Jwt
HA-Ipaddr
X-JWT-State
X-Worker
X-UnsetCookies
X-Envoy-Decorator-Operation
X-Has-Esi
Adler-Geo
L5d-Success-Class
Ssr
X-Is-Gdpr
Is-Eu
Memcached
NGX
X-Loc
X-DefHash
X-DPWN-IS-SECURE
X-Eu-Site
NM-Fastcgi-Cache
X-FC-Vary-Parameters
X-DefElseHash
X-CGP
X-Varnish-Remaining-TTL
Fastly-SIE
X-Backend-State
X-Varnish-CookieINHashed-On
X-Pod-Name
X-RateLimit-Limit-Second
X-Amzn-Remapped-Content-Length
Cf-Device-Type
X-Rebelmouse-Cache-Control
X-RateLimit-Remaining-Second
X-Rebelmouse-Surrogate-Control
X-Varnish-CookieHashed-On
X-Qloud-Router
X-Origin
X-Variation
X-Request-URI
Fastly-SWR
X-EC-Lua
X-Xrds-Location
X-Mvc-Supplant-OutputCached
Candidate-Md5Url
Datacenter
X-Tx-Id
X-NWS-UUID-VERIFY
X-Ua-Device
X-Cache-Enabled
X-CLOUD-TRACE-CONTEXT
X-LB-ID
X-Trace-ID
X-API-Version
X-CS
X-NC
CDN
Pics-Label
X-Up
On-Server
X-Backend-TTL
X-Varnish-Beresp-Ttl
WWW-Authenticate
X-Vc
X-DynaTrace-JS-Agent
Time
Memory
X-Refresh
X-GeoIP-Region-Code
NtCoent-Length
Ms-Author-Via
X-GeoIP-Country-Code
Esi-Enabled
X-Tt-Logid
X-TraceId
X-Datadome
X-LB-NoCache
X-Generated-In
Magicmarker
X-Tb-Optimization-Total-Bytes-Saved
X-Edge-Pop
X-Via-Poph
GeoIp-Country-Code
X-Via-Popn
WebServer
C-Via
Env
X-Via-Popv
X-Service
X-Parent-Response-Time
X-TA-CDN-Provider
X-Dynatrace
X-Varnish-Ttl
X-Varnish-Beresp-TTL
S-Rt
X-CacheTTL
Kp-EeAlive
X-Restarts
X-Cache-PHP
X-Optimistic-Header
X-Srv
X-DC
X-DSS
X-DI
X-Render-Time
X-Esi
X-RPM
X-Wix-Viewer-Type
X-MSEdge-Flight
X-RPS
X-DW
X-RSL
X-Action
X-Servedbyhost
X-Cache-Backend
X-MSEdge-Features
X-Cache-Status-Check
X-Cs
Edge-Cache
X-DB
X-Unique-ID
X-ZONE
X-TX-ID
X-Http-Reason
X-Akamai-Request-ID2
Server-ID
X-Info
X-Minions-Version
X-Li-Proto
X-AIR-PT
X-FPC
X-Newrelic-Synthetics
X-Cache-Ttl
X-Clientip
X-HA-Backend
Accept-Language
X-App
Proxy-Connection
X-VCL-Version
X-URL
X-LiteSpeed-Cache-Control
X-B3-Spanid
X-LI-Proto
UCS
Test
Server-Id
HIT
X-Webkit-Csp-Report-Only
Cache-Host
X-Oss-Hash-Crc64ecma
X-Oss-Request-Id
X-Oss-Storage-Class
X-Oss-Server-Time
X-Fpc
X-Oss-Object-Type
X-Traceid
X-Ec-Fail
S-Cnection
X-Vcl-Version
Locale
X-Ec-GeoHdr
X-Urbn-Context-Path
X-User
X-Urbn-Site-Id
X-NODE
X-Webkit-CSP-Report-Only
Geo-Info
Tcn
Section-Origin-Responded
Section-Io-Origin-Status
Section-Io-Id
Section-Io-Origin-Time-Seconds
Lb
X-Micro-Cache
User-Agent
Fastly-Backend-Name
X-Pass-Why
M-TraceId
X-Backend-Host
X-Pad
Cf-Int-Pingora-Origin-Digest
X-Ha-Backend
X-LiteSpeed-Tag
X-HostName
Cdnsip
Cdncip
X-AK-Request-ID
Fastly-Drupal-HTML
X-CSRF-TOKEN
X-ID
X-WADP-Cache
Cluster
X-Clara-WADP
Geoip-Latitude
My-App
X-Release
X-Fmm-Version
X-APP
X-ServedByHost
X-BCube-Filmed-By
Resin-Trace
X-BBC-Origin-Response-Status
Hostname
Ohc-File-Size
X-Check-Cacheable
Tracecode
X-Via-PopN
X-Via-PopH
X-CUA
X-Via-PopV
X-Var-Ttl
Hit
GeoIP-Country-Code
X-Dynatrace-Js-Agent
X-ES-SERVER
X-Geo
X-From
X-ElasticPress-Query
Lfy
T-Server
X-Edge-POP
X-Amz-Meta-Cb-Modifiedtime
Cache-Key
CPC-Age
MIME-Version
X-Cdn-Forward
X-WA
X-WA-Info
CPC-Cache
EpKe-Alive
ENV
VNS-Cache
Path
VNS-Age
X-RAMCache
X-Api-Version
X-Edge-Cache
Load-Balancing
Lang
X-Fragments
X-HS-Status
X-NGINX-Cache
Srv
X-Akamai-Pragma-Client-IP
X-PJAX-URL
Target-Params
X-WP-CF-Super-Cache
X-Cms-Context
X-Wikidot-Backend
Shield-Pop
Servername
X-Fastly-Backend-Reqs
X-Wikidot-Static-Cache
X-UP
URI
X-ServerName
X-Ucs
X-WP-CF-Super-Cache-Cache-Control
Pagetype
DataCenter
Uri
MD5-Digest
X-GoCache-CacheStatus
X-CCDN-Origin-Time
X-Mcache
X-Via-Ucdn
X-Fastly-Cache-Hits
X-Hcs-Proxy-Type
X-CCDN-CacheTTL
X-TRACE-ID
X-Dw-Trace-Id
X-Lb-Id
Cdn
WZWS-RAY
X-RateLimit-Reset
X-Cdn-Request-ID
X-VC
Sever-Int
Ohc-Cache-HIT
X-Nc
Cneonction
X-B3-ParentSpanId
X-VG-WebServer
X-SIPLIST1
Server-Ext
Server-Hostname
IsBot
PICS-Label
X-Acquia-Application-Trace
X-Contensis-Viewer-Groups
X-Cache-ASPX
X-Apw-Access-Object
X-Snapshot-Date
Cteonnt-Length
X-Lb-Nocache
X-Apw-Access-Token
X-Swift-Error
X-Cache-Expires
Vha6-Origin
Permissions-Policy
X-Apw-Access-Action
X-Httpd
CF-Cached-On
X-Proxy-Cache-Info
FSS-Cache
X-Acquia-Site
Cf-Ipcountry
X-Apw-Hits
X-Newrelic-App-Data
X-Acquia-Application-UUID
X-Acquia-Purge-Tags
W
X-Yottaa-OS
X-Cache-Ngx
Sid
X-Air-Pt
Server-Ttl
X-Akamai-ERRuleID
X-Last-Modified
ServerName
X-Akamai-ERPolicy
X-Http-Duration-Ms
X-Te-Duration-Ms
X-Miniprofiler-Ids
X-Te-Count
Ngx
Dnion-Transfer-Encoding
X-Logging-Id
CountryCode
Req-ID
X-CacheKey
HitType
X-UA
X-Akamai-Request-ID
X-Platform-Cluster
X-Sentry-ID
X-B3-Parentspanid
X-Varnish-Authentication
X-Provided-By
X-Platform-Processor
X-Platform-Router
X-Http-Count