Threat Level: green Handler on Duty: Daniel Wesemann

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
Pragma
X-Powered-By
X-XSS-Protection
CF-RAY
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
P3P
X-Cache-Hits
X-UA-Compatible
Alt-Svc
X-Xss-Protection
X-Served-By
X-Download-Options
CF-Ray
X-Timer
Access-Control-Allow-Headers
X-Request-Id
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
Access-Control-Allow-Credentials
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
X-Drupal-Cache
X-Generator
X-Cache-Status
X-Check
X-Cacheable
X-Envoy-Upstream-Service-Time
X-Request-ID
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-FRAME-OPTIONS
X-Iinfo
X-Dns-Prefetch-Control
X-Drupal-Dynamic-Cache
Feature-Policy
X-Content-Security-Policy
Content-Encoding
Access-Control-Expose-Headers
Upgrade
Status
X-CDN
X-AspNetMvc-Version
X-XSS-PROTECTION
Server-Timing
Access-Control-Max-Age
X-Amz-Request-Id
Request-Context
X-Amz-Id-2
X-Turbo-Charged-By
X-AH-Environment
X-Via
X-Robots-Tag
X-Backend
X-Cache-Group
Cf-Edge-Cache
Host-Header
Keep-Alive
X-Proxy-Cache
X-Hacker
X-Server
X-Rq
X-Age
X-Server-Powered-By
Allow
X-Vhost
X-Varnish-Cache
X-UA-Device
X-Ws-Request-Id
EagleId
X-Dispatcher
X-Amz-Version-Id
Grace
P3p
Nel
Cf-Apo-Via
X-LiteSpeed-Cache
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Page-Speed
X-Device
Cf-Railgun
EagleEye-TraceId
X-Swift-CacheTime
X-Swift-SaveTime
X-Aws-Lambda-Call-Status
Ali-Swift-Global-Savetime
Accept-CH
X-Pingback
X-Node
X-WebKit-CSP
X-Host
X-Server-Id
Surrogate-Control
X-Backend-Server
X-OneAgent-JS-Injection
X-CST
X-Readtime
X-Nginx-Cache-Status
X-Akam-SW-Version
X-Content-Security-Policy-Report-Only
Permissions-Policy
Request-Id
X-Application-Context
X-Cache-Lookup
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Nginx-Upstream-Cache-Status
X-Cloud-Trace-Context
X-Trace
X-Response-Time
X-Edge
Accept-Ch-Lifetime
X-HW
X-Litespeed-Cache
X-Ua-Compatible
X-Mod-Pagespeed
Content-Location
Accept-CH-Lifetime
X-Url
X-Clacks-Overhead
X-Oneagent-Js-Injection
X-Ruxit-JS-Agent
X-Midtier
X-ECACHE
X-ESI
X-Mcache
Rating
X-Amz-Server-Side-Encryption
X-Country
X-Upstream
X-TtlSet
X-Vname
X-PC
X-Vcap-Request-Id
X-Rack-Cache
X-D2id
Cache-Tag
X-MS-InvokeApp
Xkey
Verso
X-Element-Page-Cache
X-Content-Type
Fastly-Restarts
X-Cache-TTL
X-Cdn-Fetch
X-Exp-Id
X-Exp-Variant
X-Kinja-Server
X-Use-Magma
X-Kinja-Build
X-Kinja-Revision
X-GoogleNews-Bot
X-Kinja
RTSS
Edge-Control
X-Powered-By-Plesk
X-VARITI-CCR
X-Ac
X-Cached
Origin-Trial
X-Navigation-Version
Accept-Ch
X-Abt-Application-Version
X-Ruxit-Js-Agent
X-Ua-Device
X-Goog-Hash
X-WebKit-CSP-Report-Only
Service-Worker-Allowed
X-GitHub-Request-Id
X-Amz-Rid
X-Ttl
X-Country-Code
X-Sol
X-Middleton-Display
Pagespeed
Display
X-Mg-S
X-Dw-Request-Base-Id
X-B3-TraceId
SPRequestGuid
X-SharePointHealthScore
X-Browser-Type
X-Server-Name
Arr-Disable-Session-Affinity
Cross-Origin-Opener-Policy
X-Varnish-TTL
AR-PoweredBy
AR-Request-ID
AR-ATIME
X-Erf-Bev-Bev
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Erf-Bev-Bev-Is-Generated
X-Powered-CMS
X-Instrumentation
AR-SID
X-Middleton-Response
Response
SPIisLatency
X-Amzn-Trace-Id
SPRequestDuration
X-Cache-Key
AR-CACHE
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Fastly-Request-ID
X-Cnection
X-HP-Trace-Id
X-HP-Webp
X-Jurisdiction
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-Version
X-Accel-Expires
X-T
Front-End-Https
Cache-Tags
Cache-Status
X-NF-Request-ID
X-Times
X-Ser
Edge-Cache-Tag
X-Fastcgi-Cache
X-Px
X-MSEdge-Ref
X-Client-IP
Public-Key-Pins
Pinterest-Generated-By
Pinterest-Version
X-Pinterest-Rid
X-Hits
X-Recruiting
Nginx-Cache
MRF-Tech
X-B3-TraceId-Primal
Mrf-Cache-Status
X-Shield-Request-Id
X-Request-Processing-Time
X-Webkit-CSP
Access-Control-Request-Method
X-Frontend
X-Request-Received
X-RateLimit-Remaining
X-LLID
Server-Node
X-Ua-Browser
Payment
X-DIS-Request-ID
TP-Cache
X-NWS-LOG-UUID
X-B3-Traceid
X-Webkit-Csp
X-HS-Content-Id
X-HS-Combine-CSS
X-HS-Cache-Config
X-HS-Hub-Id
S
TP-L2-Cache
MicrosoftSharePointTeamServices
X-Content-Digest
X-LB-Cache
X-Goog-Metageneration
X-RateLimit-Limit
X-Distributor
Content-MD5
X-FastCGI-Cache
X-PressLabs-Stats
Realpath
X-Webkit-CSP-Report-Only
X-Geo-Country
X-Erf-Stays-Pdp-Viaduct-Migration-Web
X-Hostname
X-Microsite
X-Request-Handler-Origin-Region
X-Forwarded-For
X-Ezoic-Cdn
Access-Control-Allow-Method
X-Envoy-Decorator-Operation
X-Ratelimit-Remaining
X-FB-Debug
Fastcgi-Cache
X-Cluster-Name
X-Page-Id
Accept-Charset
X-Rid
X-GUploader-UploadID
X-Correlation-Id
X-Kinja-CCPA
X-Protected-By
X-Seen-By
TCN
X-Amz-Apigw-Id
X-Amzn-RequestId
Cleartype
X-B3-Sampled
X-Origin-Server
DC
X-TEC-API-ROOT
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-Debug-Info
X-Origin-Cache
X-Ratelimit-Limit
X-Newrelic-App-Data
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Mobile
Referer-Policy
X-XRDS-Location
X-Varnish-Backend
X-Logged-In
X-Git-Hash
X-TTL
X-Edge-Location-Klb
X-Kinsta-Cache
X-Aspnet-Version
X-Azure-Ref
Cross-Origin-Resource-Policy
Alternate-Protocol
X-Server-ID
Healthy
Surrogate-Key
X-Contextid
X-App-Environment
X-Fb-Rlafr
X-Revision
X-Varnish-Grace
X-Grace
X-Amz-Replication-Status
X-Request-Guid
X-TT
X-Providence-Cookie
X-Route-Name
X-Is-Crawler
X-Amz-Meta-S3cmd-Attrs
X-Flags
X-Aspnet-Duration-Ms
X-Content-Options
Count-Hit
X-Whom
X-Wix-Request-Id
X-Forwarded-Proto
X-IPS-LoggedIn
Charset
Filterid
MS-Author-Via
X-Akamai-Edgescape
Viewport
Frame-Options
WPO-Cache-Message
WPO-Cache-Status
X-App-Server
X-Id
Paypal-Debug-Id
X-B
X-Hosted-By
X-Cache-Age
X-Client-Ip
X-Kong-Proxy-Latency
X-Backend-Name
X-Kong-Upstream-Latency
X-Cache-Control
X-Magnolia-Registration
X-Trace-Id
X-AppVersion
X-Activity-Id
X-Az
X-Www-Served-By
Section-Io-Cache
Retry-After
Server-Name
Refresh
X-Varnish-Ttl
X-Upgrade-Enabled
X-Daa-Tunnel
X-Type
Version
X-Varnish-Server
X-F-Cache
X-Proxy-Cache-Info
X-Proxy
Amp-Access-Control-Allow-Source-Origin
X-Oracle-Dms-Ecid
X-ARC
VIX-Pulpo-Node
Akamai-GRN
X-Time
X-Cache-Rule
Host
VIX-Pulpo-Upstream-Status
X-Rule
X-Oracle-Dms-Rid
X-Original-Request-Id
X-Response-Served-From
X-Http-Reason
X-Akamai-Request-ID2
X-Status
Protected
X-App-Version
X-UUID
X-Varnish-Age
X-User-Agent
X-Rocket-Nginx-Serving-Static
X-Source
SRV
Front
X-Environment-Context
X-Region
X-Unique-Id
SD-X-WS
X-EdgeConnect-Cache-Status
X-L-Path
X-COUNTRY
X-Edge-Location
X-Jobs
X-Framework
X-Instance
X-FW-Server
X-FW-Serve
X-FW-Type
X-N
X-FW-Version
X-FW-Static
From-Origin
Fastly-SIE
X-Cache-Time
Fastly-SWR
X-Cache-Grace
X-FW-Dynamic
Access-Control-Request-Headers
X-FW-Hash
X-Cacheable-TTL
X-RemovedCookies
X-Is-Bot
X-Page-View
X-ProcessESI
X-Tumblr-Pixel-1
X-Tumblr-Pixel
X-Rendered-As
X-G
X-Load-Cache
X-Tumblr-User
X-Tumblr-Pixel-0
ServerID
X-Adobe-Content
X-Adobe-Loc
Content-Disposition
X-Drupal-Cache-Tags
Country
X-CDN-Forward
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
X-HTML-Minification-Powered-By
X-Language
X-Tt-Trace-Tag
X-Tt-Trace-Host
Accept-Language
X-RateLimit-Reset
Countrycode
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Vcache
Liferay-Portal
X-DynaTrace
X-Datadog-Sampled
X-ID
X-Amzn-Remapped-Content-Length
X-DynaTrace-JS-Agent
X-Nf-Request-Id
X-Debug-IsPreview
X-Mg-Request-UUID
X-Debug-IsConnected
X-Generated-By
X-DataDome
X-ECache
X-B3-SpanId
Xet-Cookie
Backend
X-Drupal-Cache-Contexts
X-Tt-Logid
CF-IPCountry
X-Content-Powered-By
X-Mode
X-WP-CF-Super-Cache
Webserver
X-WP-CF-Super-Cache-Cache-Control
Xserver
X-Device-Type
X-NYM-Debug-Backend
X-Ratelimit-Reset
X-Erf-Web-Scheduler
X-Nginx-Cache
X-Signature
X-B-Cache
X-Zen-Fury
GEO-INFO
X-Httpd
X-Xrds-Location
X-Varnish-Cache-Hits
X-SaId
Azure-Version
Onion-Location
Azure-SiteName
Azure-SlotName
Azure-RegionName
X-Sucuri-Cache
X-LAGOON
X-ServerID
X-Content-Age
X-Urbn-Site-Id
X-Container-Uri
X-JoinUs
X-Sucuri-ID
Azure-InstanceId
X-Urbn-Context-Path
X-UPSTREAM-Address
Locale
Url
Load-Balancing
Filters
X-Rewrite-Enabled
X-Servername
S-Rt
X-Cache-Operation
X-Git-Commit
Meta-Geo
X-Director
X-Storage
X-Tb
X-Say-TTL
Uber-Trace-Id
X-Proto
X-Varnish-Hostname
X-Cache-Action
X-XRDS-LOCATION
X-Cluster-Node
X-SayCDN-TTL
X-Say-Cacheable
X-Ms-Request-Id
X-Logging-Id
X-Ms-Version
Web-Mar-Node
X-RM-Cache-TTL
X-Served-From
X-VC-Cache
X-Forwarded-Host
X-VCT
X-PHP-Host
X-Generation-Time
X-Cache-Server
X-Labrador-Cache-Channel
X-Soup
Webcakes-App-Version
X-Extlb
TWC-Connection-Speed
X-Origin-Hint
Property-Id
Node
Mn-Server-Ip
TWC-Device-Class
TWC-GeoIP-Country
TWC-Privacy
Webcakes-App-Name
TWC-Locale-Group
TWC-GeoIP-LatLong
DB-Nickname
Webcakes-Region
X-GeoCountry
X-Skip-Cache
X-Tec-Api-Origin
X-Tec-Api-Version
X-GeoCode
Fastcgi-Useragent
X-Zipkin-Id
X-Sql-Duration-Ms
X-Tec-Api-Root
X-RCS-CacheZone
X-Routing-Service
X-Proxied
X-Sql-Count
X-Uri
X-Adobe-Source
X-Debug
X-Tumblr-Pixel-2
X-R9-Blue-Green-Version
X-Fetched-On
X-Tumblr-Pixel-3
Selected-Fe
X-FB-TRIP-ID
X-Timing-Wait
X-Format
X-LSADC-Cache
X-Proxy-Build
X-Detected-As
X-Via-JSL
CDN-RequestId
Fastly-Drupal-HTML
X-MP-GENERATED-AT
X-Cache-Expired-At
X-Origin-Date
X-Lambda-Id
X-NGENIX-Cache
OT-Force-Account-Verify
Source
X-MCACHE
X-Node-Name
X-Cache-Hit
X-Template
X-Varnish-Hits
Content-Secure-Policy
X-Cache-TTL-Remaining
X-AIR-PT
X-UA-Device-Type
X-Srv
X-Pass-Why
X-Endurance-Cache-Level
X-Tncms
X-Loop
X-Ua
X-Pubstack
X-PHP-Backend
Upgrade-Insecure-Requests
Cross-Origin-Window-Policy
X-Redis-Cache
X-Server-W
NGB
X-Fastly-Request-Id
X-Origin-CC
X-Origin-TTL
Cache-Hits
X-CCDN-Origin-Time
X-CCDN-CacheTTL
X-Real-IP
X-Hcs-Proxy-Type
Ms-Operation-Id
X-RTag
X-Cache-Host
MS-CV
Section-Io-Origin-Time-Seconds
Cache-Name
Section-Io-Origin-Status
Section-Origin-Responded
Section-Io-Id
X-Reqid
Apigw-Requestid
X-Restarts
Cache-Provider
X-Xfnlog-Site
X-IPLB-Instance
X-IPLB-Request-ID
X-Optimistic-Header
X-GEO
X-Cache-Type
CDN-RequestCountryCode
CDN-Uid
CDN-RequestPullSuccess
CDN-RequestPullCode
X-CSRF-Token
CDN-PullZone
X-Datadome
X-S
CDN-Cache
CDN-EdgeStorageId
CDN-CachedAt
X-Hl-Ver
X-BYPASS-REASON
X-Cms-Context
X-ProxyCache-Key
X-No-Session
X-Aspnetmvc-Version
X-ProxyCache-Status
X-VWS-Id
X-Via-Fastly
X-CACHE-AGE
X-Newrelic-Synthetics
X-Cluster
X-Akamai-Transformed
X-AWS-Id
X-LJ-Flow-ID
X-Section
X-Access
Xc-Version
X-Wikidot-Static-Cache
X-FC-Vary-Parameters
Redirect-Candidate
X-External-Request-Id
Sslversion
X-Fastly-Backend
CPC-Cache
Surrogated-Key
T-Server
X-Wikidot-Backend
X-Irp-Debug
X-Accel-Expires-Debug
Server-Host
X-Tenant
X-We-Are-Hiring
X-Aed
X-Application
X-Gdpr
X-Eu-Site
DCR-Decision-By
DCR-Processing-Time-Ms
X-Rn-Rsrv
X-Forwarded-Path
X-Ec-GeoHdr
BehaviorPad-Version
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-CGP
X-BCube-Filmed-By
X-Cdn-Diag
X-CacheTTL
Candidate-Md5Url
X-Bl-Debug
Canary
X-Cache-Info
X-Cache-NE
X-Conf
X-Bc-Bl
X-Dispatcher-Number
X-Developer
X-B-Cookie
X-Ec-Fail
X-Epic-Correlation-Id
X-Destination
X-Debug-Cache-Store
X-D
X-Csrf-Jwt
X-Date
Rendered-Blocks
X-Debug-Cache-Fetch
CPC-Age
Fastly-Backend-Name
X-Proxy-Cache-Status
X-Rojux
Odigeo-Trace-Id
X-Var-Ttl
X-S-Cookie
Lang
X-Vdms-Path
X-Request-Host
X-Cache-Bucket
X-VG-WebCache
Fastly-GeoIP-CountryCode
X-Vdms-Version
X-A-Dam
X-ScT
X-Slack-Backend
MD5-Digest
X-Slack-Shared-Secret-Outcome
VNS-Age
Vix-Hermes-Req-Id
Mail-Subject
Web-Mar-Region
X-A-Ccd
X-A
Magicmarker
X-Shop-Environment
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-TimeS
X-SRCache-Key
Gh-Request-Id
Ha-Gx-Prefs
X-Vtex-Remote-Cache
Meta-Geo-Continent
W
X-Mvc-Supplant-Cachable
N-Cache
Gannett-Cam-Experience-Id
X-Nyt-Route
X-Orig-Expires
VNS-Cache
Ngx.Var.Host
L
We-Hiring
X-Policy
L5d-Success-Class
X-TIM-N
X-Viewer-Country
HA-Ipaddr
X-Origin-Time
X-A-Wwc
X-A-Dgt
X-A-Dcw
X-Web-Node
Thinkindot-Control
X-ApacheServer
X-Alternate-Cache-Key
Thinkindot-CacheControl-Type
X-App-Name
X-Auto-Login
X-BBC-Edge-Cache-Status
TDXMobile
Thinkindot-CacheControl
X-Bip
X-Level-Front-Cache
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Storefront-Renderer-Rendered
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-Shopify-Stage
X-ShopId
X-S-Maxage
X-Request-Time
X-SD-PageType
X-Server-IP
X-ShardId
X-Test
X-Thanos
X-Is-Gdpr
X-Has-Esi
X-JWT-State
X-Wix-Viewer-Type
X-Worker
X-Accel-Buffering
True-Client-Country-4JS
X-Up
X-Thinkindot-L3
X-Varnishpool
X-VG-TLSProxy
X-WADP-Cache
X-Pool
X-Platform
X-Generated-On
X-Forwarded-Site
X-Geo-Header
X-GeoIP-Country-Code
X-GeoIP-Region-Code
X-Fmm-Version
X-Esi-Check
X-CMSURLCustom
X-Clara-WADP
X-Core-Mission
X-Core-Value
X-Ec-Custom-Error
X-Gzip
X-Hash
X-Origin-Response-Time
X-Org
X-Owner
X-PAYTM-SRV-ID
X-PERF
X-Old-Content-Length
X-Node-Id
X-Human
X-INCAP-ABP
X-Mid
X-Mly-Id
X-Cache-Id
X-Clientip
Cmstype
Release
Machine
Origin
Memcached
AKAMAI
Host-ID
Cmsid
Environment
Req-Svc-Chain
Datacenter
X-Vcl-Version
WP-Super-Cache
User-Cache-Control
DSUID
X-DefElseHash
Is-Eu
Expect-Staple
Fastly-SSL
Producers
Platform
X-Block-Status
X-Cdn-Srv
Country-Code
X-Cdn-Origin
CloudFront-Viewer-Country
X-Azure-Ref-OriginShield
X-Cache-Debug
Apple-News-Services-Host
X-Nginx-Cache-Key
X-Gen-Mode
X-NodeID
X-From
X-Nananana
X-Parent-Response-Time
X-Hnp-Log
X-Mvc-Supplant-OutputCached
X-Handled-By
X-Origin
X-Presslabs-Stats
X-DefHash
Adler-Geo
Apple-News-Services-Parsed-Url
Apple-News-Services-Handled
X-WA-Info
X-Scale
X-Dispatcher-Server
X-Device-Os
Apple-News-Services-Request-Url
CDCHOST
ServedBy
X-Varnish-CookieINHashed-On
X-Loc
X-Varnish-Remaining-TTL
X-Qloud-Router
X-Vmg-Version
X-Sn-Servicetimems
X-VServer
X-Varnish-CookieHashed-On
X-DPWN-IS-SECURE
X-Variation
X-Cs
NM-Fastcgi-Cache
Esi-Enabled
X-Air-Hostname
X-Air-Source
X-Air-Trace-Id
Server-Ext
Ssr
X-App
X-TA-CDN-Provider
Origin-EX
Pics-Label
Origin-CC
X-Nitro-Cache
X-NCache
Sever-Int
X-Op-Id-All
Server-Hostname
C-Via
X-Instance-Name
Wxu-Next-Region
X-LB-NoCache
X-Akamai-Device-Characteristics
Wxu-Next-Hostname
X-GeoIP
Wxu-Next-Commit
AMP-Access-Control-Allow-Source-Origin
X-TIME
X-Microcachable
Time
X-Cache-Enabled
X-Platform-Processor
X-Platform-Router
X-Amz-Meta-Cb-Modifiedtime
X-Platform-Cluster
Cache-Host
Memory
X-Cache-Status-Check
Server-Info
X-Refresh
Server-ID
X-Locale
X-Site-Version
X-Tx-Id
X-HA-Backend
XM
X-Origin-Expires
X-Correlation-ID
X-HN
X-VarnishDD-TTL
PFcat
NGX
X-VHOST
X-Dc
Hostname
GeoIP-Latitude
X-ZONE
X-CACHE-GROUP
Resin-Trace
X-Tb-Optimization-Total-Bytes-Saved
X-API-Version
X-FL-EDGE
Edge-Copy-Time
Cf-Device-Type
Locid
X-FL-QIT-DEBUG
Origin-Agent-Cluster
X-Ad-Defer-Variation
A
Srvid
X-Via-Edge
X-Via-CDN
X-Via-SSL
X-Wp-Cf-Super-Cache-Active
X-Varnish-Beresp-Ttl
X-DC
X-Upstream-Ct
X-Varnish-Beresp-Grace
X-Upstream-Ht
Cdn-Requestid
X-FireWall-Port
YJS-ID
X-Zone
X-ATG-Version
X-Webkit-Csp-Report-Only
X-Fpc
Sid
X-Internal-Host
X-Contensis-Viewer-Groups
X-Cache-ASPX
X-Vgn-Hpd-Reason
Cache-Key
X-Pod-Name
X-Varnish-Authentication
X-Github-Request-Id
X-Moov-Xdn-Version
X-Moov-T
Uri
X-Micro-Cache
X-DataCenter
X-Cached-By
User-Agent
True-Client-Ip
X-LiteSpeed-Cache-Control
X-Provided-By
X-Planisys-CDN-TTL
X-WP-CF-Super-Cache-Active
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
X-Info
State
X-HS-Content-Campaign-Id
X-TraceId
X-B3-Spanid
X-URL
IsBot
X-RN-RSRV
X-Platform-Server
X-Fastly-Cache
X-B3-Parentspanid
GeoIP-Country-Code
X-SIPLIST1
X-Buckets
Location
X-Sigma-Backend
X-Sigma
X-NGINX-Cache
X-Cache-Remote
X-Release
X-Nitro-Rev
X-Nitro-Cache-From
X-AB
X-Rocket-Build-Number
X-Api-Version
X-LiteSpeed-Tag
X-VCache
Cache
X-MSEdge-Features
X-MSEdge-Flight
Cdn
X-Datacenter
GeoIp-Country-Code
X-VC
X-Backend-Instance
X-Geo-Region
SID
XServer
X-Geo
X-CS
X-Accel-Version
X-Gamma-Serve
X-Generated-In
Srv
X-NewRelic-App-Data
X-CSRF-TOKEN
Cache-Tv-Group
CF-Ctrl
X-Vgn-Hpd-Ssi
X-GeoIP-City
Lb
True-Client-IP
X-Vgn-Hpd-Variations-Key
X-Vgn-Hpd-Cached
NtCoent-Length
X-HS-Status
X-TRACE-ID
X-Rebelmouse-Surrogate-Control
X-Scheme
Path
X-Rebelmouse-Cache-Control
HostName
Kp-EeAlive
X-FPC
X-FTR-Request-ID
X-Is-Mobile
X-Is-Tablet
X-Is-Desktop
Fastly-Drupal-Html
X-Browser-Name
X-Tcp-Rtt
X-Is-Supported-Browser
Tcn
X-HostName
Epwk-X-Cache
Ohc-File-Size
X-GoCache-CacheStatus
X-Mobile-URL
X-Location
X-Frame-Option
X-SRV
X-Hyper-Cache
Serverid
X-APP-VERSION
X-UA
Cf-Ipcountry
X-TX-ID
CountryCode
X-Air-Pt
CacheControlHeader
X-Aicache-OS
X-Service
X-AK-Request-ID
X-Men
Cdnsip
On-Server
Cdncip
X-Region-Sid
X-Amz-Meta-Opti
X-Developers
X-Esi
X-Guploader-Uploadid
X-Webstats-RespID
V-Age
RNT-Machine
Tube-Return
X-Branch-Name
RNT-Time
Tube-Get-Contents
Tube-Got-Eval
Tube-Got-Results
X-Traceid
X-Acquia-Purge-Cdn-Unconfigured
X-Via-Popv
X-Via-Popn
X-Via-Poph
X-CDN-Cache-Status
Proxy-Connection
Click-Count-Action-Start
X-Cache-FS-Status
X-V-Cache
WebServer
X-Cache-Ttl
X-Minions-Version
X-Req
X-SB
Mime-Version
X-Wp-Cf-Super-Cache
Click-Count-Error
X-Wp-Cf-Super-Cache-Cache-Control
X-LB-ID
X-Cache-Tags
X-EC-Lua
X-B3-Trace-ID
X-Wp-Cf-Super-Cache-Cookies-Bypass
Env
ENV
WWW-Authenticate
X-Proxy-CacheRZ
X-Vc
X-Cdn-Cache-Status
XkeyRZ
X-Pad
X-Servedbyhost
X-Nc
Ohc-Cache-HIT
Yak-Timeinfo
WZWS-RAY
X-Wa
X-VCL-Version
X-CACHE-KEY
CDN
X-Fastly-Country-Code
X-Cdn-Forward
LB
X-Akamai-Pragma-Client-IP
X-User
X-NWS-UUID-VERIFY
X-Edge-Pop
Ngx
Geoip-Latitude
X-Lb-Cache
X-Check-Cacheable
CF-Cached-On
Cdn-Host
Content-Script-Type
Content-Style-Type
X-Ha-Backend
X-TH-Server
Server-Id
X-Ckpd-Fst-Backend
X-Processor
X-Vercel-Id
X-Vercel-Cache
Cdn-Request-Time
X-Edge-Server
X-TT-LOGID
X-IN-APIGATEWAYSSL
X-IN-APIGATEWAY
X-Via-Ucdn
X-Acquia-Site
X-Acquia-Purge-Tags
X-Acquia-Application-UUID
X-Acquia-Application-Trace
M-TraceId
Req-ID
X-WP-CF-Super-Cache-Cookies-Bypass
X-Litespeed-Cache-Control
X-Dw-Trace-Id
X-CUA
X-Snapshot-Date
X-NMSegId
X-Edge-POP
X-MiniProfiler-Ids
HIT
X-Lb-Nocache
X-APP
X-Render-Time
PICS-Label
Yjs-Id
X-Origin-Cache-Key
X-Miniprofiler-Ids
X-FTR-Cache-Status
Cluster
X-Ad-Load-Variation
X-Cdn-Request-ID
X-FTR-Expires
X-FTR-Balancer
X-Country-Code-Real
X-FTR-Backend
X-FTR-Backend-Server
Cneonction
X-Response-By
CACHE-MISS-TO-ORIGIN
X-Service-Response-Time
Inserted-Into-Cache-At
X-Iauth-Set-Uid
Edge-Cache
X-Cache-Date
X-Fastly-Backend-Reqs
Sm-Log-Id
X-Fastly-Cache-Hits
X-Serial
Log-Origin
X-M-Log
X-M-Reqid
X-ElasticPress-Query
X-Cached-Since
X-Udemy-Cache-App-Namespace
Vha6-Origin
X-RAMCache