Threat Level: green Handler on Duty: Jim Clausing

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
Pragma
X-Powered-By
X-XSS-Protection
CF-RAY
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
P3P
X-Cache-Hits
X-UA-Compatible
Alt-Svc
X-Xss-Protection
X-Served-By
CF-Ray
X-Download-Options
X-Timer
X-Request-Id
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
Access-Control-Allow-Credentials
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
X-Drupal-Cache
X-Generator
X-Cache-Status
X-Check
X-Cacheable
X-Envoy-Upstream-Service-Time
X-DNS-Prefetch-Control
X-Request-ID
Timing-Allow-Origin
X-Iinfo
X-FRAME-OPTIONS
X-Dns-Prefetch-Control
X-Drupal-Dynamic-Cache
Feature-Policy
X-Content-Security-Policy
Content-Encoding
Access-Control-Expose-Headers
Upgrade
Status
X-CDN
X-AspNetMvc-Version
Server-Timing
X-XSS-PROTECTION
Access-Control-Max-Age
X-Amz-Request-Id
Request-Context
X-Amz-Id-2
X-Turbo-Charged-By
X-AH-Environment
X-Via
X-Robots-Tag
X-Backend
X-Cache-Group
Cf-Edge-Cache
Keep-Alive
Host-Header
X-Proxy-Cache
X-Hacker
X-Server
X-Rq
X-UA-Device
X-Server-Powered-By
X-Age
Allow
X-Vhost
X-Varnish-Cache
X-Ws-Request-Id
EagleId
X-Dispatcher
X-Amz-Version-Id
Grace
X-LiteSpeed-Cache
Cf-Apo-Via
P3p
Nel
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Page-Speed
X-Device
Cf-Railgun
EagleEye-TraceId
X-Swift-CacheTime
X-Swift-SaveTime
X-Aws-Lambda-Call-Status
Ali-Swift-Global-Savetime
X-Pingback
X-Node
X-Host
Accept-CH
X-WebKit-CSP
X-Server-Id
Surrogate-Control
X-OneAgent-JS-Injection
X-Backend-Server
X-CST
X-Readtime
X-Nginx-Cache-Status
X-Akam-SW-Version
X-Cache-Lookup
X-Content-Security-Policy-Report-Only
Permissions-Policy
Request-Id
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Application-Context
X-Nginx-Upstream-Cache-Status
X-Cloud-Trace-Context
X-Trace
X-Response-Time
X-Edge
Accept-Ch-Lifetime
X-HW
Accept-CH-Lifetime
X-Ua-Compatible
X-Mod-Pagespeed
Content-Location
X-Clacks-Overhead
X-Url
X-Oneagent-Js-Injection
X-Midtier
X-Litespeed-Cache
X-Ruxit-JS-Agent
X-ECACHE
Rating
X-ESI
X-Mcache
X-Amz-Server-Side-Encryption
X-Country
X-Upstream
Xkey
X-TtlSet
X-Vname
X-PC
X-Vcap-Request-Id
Cache-Tag
X-MS-InvokeApp
X-D2id
X-Rack-Cache
X-Kinja-Server
X-Cdn-Fetch
X-GoogleNews-Bot
X-Kinja-Revision
X-Element-Page-Cache
X-Exp-Id
X-Kinja-Build
X-Exp-Variant
X-Use-Magma
X-Kinja
Accept-Ch
Verso
X-Cache-TTL
Edge-Control
Fastly-Restarts
RTSS
X-Powered-By-Plesk
X-Ruxit-Js-Agent
X-VARITI-CCR
X-Content-Type
Origin-Trial
X-Ac
X-Navigation-Version
X-Cached
X-Abt-Application-Version
X-Goog-Hash
Service-Worker-Allowed
X-GitHub-Request-Id
X-Country-Code
X-Amz-Rid
Pagespeed
X-Sol
Display
X-Middleton-Display
X-WebKit-CSP-Report-Only
X-Ttl
X-Mg-S
X-Browser-Type
X-B3-TraceId
X-Dw-Request-Base-Id
X-SharePointHealthScore
SPRequestGuid
X-Server-Name
Cross-Origin-Opener-Policy
Arr-Disable-Session-Affinity
X-Server-Lifecycle-Phase
X-Instrumentation
X-Erf-Bev-Bev-Is-Generated
X-Kraken-Loop-Name
X-Erf-Bev-Bev
X-Varnish-TTL
X-Powered-CMS
AR-Request-ID
AR-SID
AR-ATIME
AR-PoweredBy
Response
X-Middleton-Response
X-Amzn-Trace-Id
SPRequestDuration
SPIisLatency
X-Ua-Device
X-Cache-Key
AR-CACHE
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Fastly-Request-ID
X-Cnection
X-Version
X-Jurisdiction
X-ORACLE-DMS-ECID
X-HP-Webp
X-HP-Trace-Id
X-ORACLE-DMS-RID
X-Webkit-CSP
X-Accel-Expires
X-T
Cache-Tags
Front-End-Https
Cache-Status
X-Times
X-Client-IP
Edge-Cache-Tag
X-NF-Request-ID
X-MSEdge-Ref
X-Ser
X-Px
Pinterest-Generated-By
X-Pinterest-Rid
Pinterest-Version
X-Fastcgi-Cache
X-Hits
Nginx-Cache
Public-Key-Pins
X-Recruiting
X-RateLimit-Remaining
Mrf-Cache-Status
X-B3-TraceId-Primal
X-NWS-LOG-UUID
MRF-Tech
X-LLID
X-Request-Processing-Time
X-Request-Received
X-Shield-Request-Id
X-Frontend
X-Ua-Browser
Server-Node
Payment
Access-Control-Request-Method
X-DIS-Request-ID
TP-Cache
X-RateLimit-Limit
X-FastCGI-Cache
X-Kinja-CCPA
X-Webkit-CSP-Report-Only
X-HS-Combine-CSS
X-HS-Hub-Id
X-Goog-Metageneration
X-Erf-Stays-Pdp-Viaduct-Migration-Web
X-HS-Content-Id
X-HS-Cache-Config
S
MicrosoftSharePointTeamServices
TP-L2-Cache
X-B3-Traceid
X-Content-Digest
X-LB-Cache
X-Webkit-Csp
Content-MD5
X-PressLabs-Stats
X-Distributor
Realpath
X-Request-Handler-Origin-Region
X-Microsite
X-Geo-Country
X-Forwarded-For
Access-Control-Allow-Method
X-Page-Id
X-FB-Debug
X-Ezoic-Cdn
X-GUploader-UploadID
Accept-Charset
Fastcgi-Cache
X-Cluster-Name
X-Rid
X-Protected-By
X-Hostname
X-Amz-Apigw-Id
X-Envoy-Decorator-Operation
X-Seen-By
X-Amzn-RequestId
X-Ratelimit-Remaining
X-Correlation-Id
Cleartype
X-B3-Sampled
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
TCN
X-TTL
DC
X-Goog-Generation
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Origin-Server
X-Newrelic-App-Data
Referer-Policy
X-Debug-Info
X-Mobile
X-Ratelimit-Limit
X-Varnish-Backend
X-Logged-In
X-Git-Hash
Cross-Origin-Resource-Policy
X-Origin-Cache
X-XRDS-Location
X-Kinsta-Cache
X-Edge-Location-Klb
X-Azure-Ref
Alternate-Protocol
X-Varnish-Grace
X-Is-Crawler
Surrogate-Key
X-App-Environment
X-Aspnet-Duration-Ms
X-Request-Guid
X-Flags
X-Fb-Rlafr
X-Providence-Cookie
X-Route-Name
X-Aspnet-Version
X-Grace
X-Amz-Replication-Status
X-Contextid
X-Revision
X-Content-Options
Healthy
X-TT
Count-Hit
X-Amz-Meta-S3cmd-Attrs
X-Server-ID
X-IPS-LoggedIn
X-Wix-Request-Id
X-Forwarded-Proto
X-Whom
MS-Author-Via
X-App-Server
X-Akamai-Edgescape
Frame-Options
X-Hosted-By
WPO-Cache-Status
Viewport
Filterid
WPO-Cache-Message
Charset
X-Id
X-Daa-Tunnel
X-Magnolia-Registration
X-B
Paypal-Debug-Id
X-Cache-Age
X-Backend-Name
Retry-After
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
Section-Io-Cache
X-Activity-Id
X-Cache-Control
X-Client-Ip
X-Trace-Id
X-AppVersion
X-Az
X-Www-Served-By
X-F-Cache
X-Proxy-Cache-Info
Server-Name
X-Varnish-Ttl
X-Varnish-Server
X-Type
Refresh
X-Time
SRV
Version
X-App-Version
X-Proxy
X-Instance
SD-X-WS
X-ARC
Akamai-GRN
X-Http-Reason
X-Original-Request-Id
X-Response-Served-From
Host
X-Rule
X-EdgeConnect-Cache-Status
X-User-Agent
X-UUID
X-Cache-Grace
X-Varnish-Age
X-Akamai-Request-ID2
X-Status
X-Edge-Location
X-Cache-Rule
Front
Protected
Fastly-SIE
X-Cacheable-TTL
Fastly-SWR
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
From-Origin
X-FW-Serve
X-Page-View
X-Jobs
X-FW-Version
X-Region
X-Rendered-As
Amp-Access-Control-Allow-Source-Origin
X-Rocket-Nginx-Serving-Static
X-FW-Type
X-Is-Bot
X-FW-Dynamic
X-Framework
X-FW-Static
X-FW-Hash
X-FW-Server
X-Cache-Time
X-N
X-Unique-Id
Access-Control-Request-Headers
X-L-Path
X-Adobe-Content
X-Environment-Context
X-Adobe-Loc
X-Oracle-Dms-Ecid
X-ProcessESI
X-RemovedCookies
X-Tumblr-Pixel
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-Tumblr-User
X-Oracle-Dms-Rid
X-G
X-Upgrade-Enabled
X-RateLimit-Reset
X-COUNTRY
X-Load-Cache
ServerID
Content-Disposition
X-Source
X-Language
X-Datadog-Trace-Id
X-Drupal-Cache-Tags
X-CDN-Forward
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
Country
X-Nf-Request-Id
X-HTML-Minification-Powered-By
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Vcache
Countrycode
X-Datadog-Sampled
Accept-Language
X-Amzn-Remapped-Content-Length
X-DynaTrace
X-Debug-IsPreview
X-Mg-Request-UUID
X-Debug-IsConnected
X-B3-SpanId
X-DynaTrace-JS-Agent
X-Generated-By
Liferay-Portal
X-ID
X-Xrds-Location
Xet-Cookie
Backend
X-B-Cache
X-DataDome
X-Signature
Webserver
Xserver
X-ECache
X-Mode
X-NYM-Debug-Backend
X-Httpd
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
X-Drupal-Cache-Contexts
X-Device-Type
X-Content-Powered-By
CF-IPCountry
X-Servername
X-Tt-Logid
X-Zen-Fury
X-Nginx-Cache
X-Content-Age
Url
GEO-INFO
X-Erf-Web-Scheduler
Azure-RegionName
X-GeoCode
X-LAGOON
X-Sucuri-ID
Azure-Version
X-Varnish-Cache-Hits
X-Proto
Azure-SlotName
X-Sucuri-Cache
Azure-SiteName
X-JoinUs
X-GeoCountry
Load-Balancing
Meta-Geo
X-Director
X-UPSTREAM-Address
X-Urbn-Context-Path
X-Urbn-Site-Id
S-Rt
X-Cache-Action
X-ServerID
Fastcgi-Useragent
X-Rewrite-Enabled
Filters
X-Tb
Onion-Location
Locale
X-SaId
Azure-InstanceId
X-Cache-Operation
X-RM-Cache-TTL
X-Say-Cacheable
X-Varnish-Hostname
X-VC-Cache
X-Say-TTL
X-SayCDN-TTL
X-Git-Commit
X-Forwarded-Host
X-Labrador-Cache-Channel
X-PHP-Host
X-Container-Uri
X-Cluster-Node
X-XRDS-LOCATION
X-VCT
X-Sql-Count
X-Cache-Server
X-Generation-Time
X-Storage
X-Sql-Duration-Ms
X-Detected-As
X-Ms-Request-Id
X-Soup
Web-Mar-Node
X-Logging-Id
X-Ms-Version
Uber-Trace-Id
X-Adobe-Source
X-Served-From
Webcakes-App-Version
Webcakes-App-Name
X-Extlb
Mn-Server-Ip
Webcakes-Region
X-Origin-Hint
X-R9-Blue-Green-Version
X-RCS-CacheZone
X-FB-TRIP-ID
X-Routing-Service
TWC-GeoIP-Country
TWC-Privacy
X-Zipkin-Id
TWC-Locale-Group
TWC-Device-Class
TWC-Connection-Speed
X-Skip-Cache
X-Proxied
Property-Id
X-Debug
Node
TWC-GeoIP-LatLong
X-Tumblr-Pixel-2
X-Tumblr-Pixel-3
X-Fetched-On
X-LSADC-Cache
X-Proxy-Build
Selected-Fe
X-Timing-Wait
DB-Nickname
X-Ratelimit-Reset
X-Format
X-Uri
X-Tec-Api-Version
X-Tec-Api-Root
X-Lambda-Id
X-Tec-Api-Origin
CDN-RequestId
Source
X-Origin-Date
OT-Force-Account-Verify
X-Template
Fastly-Drupal-HTML
X-MP-GENERATED-AT
X-Cache-Expired-At
X-Cache-Hit
X-Loop
X-Tncms
X-Varnish-Hits
X-NGENIX-Cache
X-MCACHE
X-Via-JSL
Content-Secure-Policy
X-Pass-Why
X-Endurance-Cache-Level
X-Cache-TTL-Remaining
X-Srv
X-Ua
X-UA-Device-Type
X-Node-Name
X-Redis-Cache
X-AIR-PT
Upgrade-Insecure-Requests
X-Real-IP
Cross-Origin-Window-Policy
X-Origin-TTL
X-Origin-CC
X-Server-W
X-Pubstack
X-Datadome
X-Fastly-Request-Id
X-CCDN-CacheTTL
Section-Origin-Responded
X-Hcs-Proxy-Type
Section-Io-Id
Section-Io-Origin-Status
NGB
X-CCDN-Origin-Time
Section-Io-Origin-Time-Seconds
Cache-Hits
X-PHP-Backend
X-Cache-Host
X-S
MS-CV
Ms-Operation-Id
X-RTag
Cache-Name
Cache-Provider
X-CSRF-Token
CDN-EdgeStorageId
CDN-PullZone
CDN-RequestCountryCode
X-Xfnlog-Site
X-Reqid
X-Optimistic-Header
CDN-RequestPullSuccess
CDN-RequestPullCode
CDN-CachedAt
X-Cms-Context
X-GEO
X-IPLB-Instance
CDN-Cache
X-IPLB-Request-ID
CDN-Uid
X-Cache-Type
X-Hl-Ver
X-Rn-Rsrv
X-ProxyCache-Key
X-Restarts
X-Akamai-Transformed
X-ProxyCache-Status
X-No-Session
X-BYPASS-REASON
Apigw-Requestid
X-Aspnetmvc-Version
X-TimeS
X-AWS-Id
X-Newrelic-Synthetics
X-VWS-Id
X-Via-Fastly
X-LJ-Flow-ID
X-Cluster
X-Application
X-Has-Esi
X-JWT-State
X-Is-Gdpr
Fastly-SSL
X-Irp-Debug
Gh-Request-Id
HA-Ipaddr
Ha-Gx-Prefs
X-FC-Vary-Parameters
DCR-Decision-By
BehaviorPad-Version
X-Conf
X-Csrf-Jwt
X-D
X-Debug-Cache-Store
X-Debug-Cache-Fetch
X-Date
CPC-Cache
CPC-Age
X-CF-Lambda-Fn
X-Cdn-Diag
X-CacheTTL
X-CF-Lambda-Version
Candidate-Md5Url
X-CGP
Canary
DCR-Processing-Time-Ms
X-Cache-Bucket
X-Bc-Bl
X-Fastly-Backend
X-External-Request-Id
X-Forwarded-Path
X-B-Cookie
X-GeoIP-Country-Code
Fastly-Backend-Name
X-Gdpr
X-Eu-Site
X-BCube-Filmed-By
X-Dispatcher-Number
X-Developer
X-Destination
X-Bl-Debug
X-Ec-Custom-Error
X-Ec-GeoHdr
X-Ec-Fail
X-GeoIP-Region-Code
X-RateLimit-Limit-Second
We-Hiring
Odigeo-Trace-Id
Web-Mar-Region
X-Tenant
W
VNS-Age
VNS-Cache
X-SRCache-Key
Ngx.Var.Host
Meta-Geo-Continent
X-Shop-Environment
X-A-Ccd
X-Slack-Backend
X-A
N-Cache
X-TIM-N
X-Var-Ttl
X-Wikidot-Backend
X-We-Are-Hiring
X-Wikidot-Static-Cache
X-Wix-Viewer-Type
Xc-Version
X-Worker
Sslversion
X-Vtex-Remote-Cache
X-Vdms-Path
Redirect-Candidate
X-Vdms-Version
Rendered-Blocks
Surrogated-Key
T-Server
X-A-Dam
X-Slack-Shared-Secret-Outcome
X-A-Dcw
X-Aed
X-Policy
X-Nyt-Route
X-A-Dgt
X-TA-CDN-Provider
X-Accel-Expires-Debug
X-Orig-Expires
X-Origin-Time
L5d-Success-Class
X-Accel-Buffering
Lang
X-A-Wwc
L
Magicmarker
MD5-Digest
X-S-Cookie
X-Mvc-Supplant-Cachable
X-ScT
X-SD-PageType
X-Cache-NE
X-Rojux
X-Request-Host
Server-Host
X-CACHE-AGE
Mail-Subject
X-RateLimit-Remaining-Second
X-Proxy-Cache-Status
X-Parent-Response-Time
X-Cache-Info
X-Cache-Id
True-Client-Country-4JS
Vix-Hermes-Req-Id
X-Bip
X-Auto-Login
X-Alternate-Cache-Key
Thinkindot-Control
Thinkindot-CacheControl-Type
X-Cache-Debug
TDXMobile
Thinkindot-CacheControl
X-ApacheServer
X-Node-Id
X-Sn-Servicetimems
X-Shopify-Stage
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-SVT-ORM-RULES
X-Storefront-Renderer-Rendered
X-ShopId
X-ShardId
X-Qloud-Router
X-Pool
X-Request-Time
X-S-Maxage
X-Server-IP
X-SVT-ORM-VERSION
X-Test
X-VG-WebCache
X-Varnishpool
X-Viewer-Country
X-Vmg-Version
X-WADP-Cache
X-VServer
X-Varnish-Remaining-TTL
X-Varnish-CookieINHashed-On
X-Thinkindot-L3
X-Thanos
X-Up
X-Variation
X-Varnish-CookieHashed-On
X-Platform
X-PERF
X-Epic-Correlation-Id
X-DPWN-IS-SECURE
X-Esi-Check
X-Fmm-Version
X-Generated-On
X-Forwarded-Site
X-DefHash
X-DefElseHash
X-Clientip
X-Clara-WADP
X-CMSURLCustom
X-Core-Mission
X-Core-Value
X-Geo-Header
X-Gzip
X-Org
X-Old-Content-Length
X-Origin-Response-Time
X-Owner
X-PAYTM-SRV-ID
X-Mly-Id
X-Mid
X-Hash
X-Handled-By
X-Human
X-INCAP-ABP
X-Level-Front-Cache
X-Cdn-Origin
X-App-Name
Fastly-GeoIP-CountryCode
Platform
Producers
Gannett-Cam-Experience-Id
Expect-Staple
Cmsid
Environment
Datacenter
Origin
Cmstype
Release
X-Access
Machine
X-Section
Is-Eu
Memcached
Host-ID
AKAMAI
Adler-Geo
AMP-Access-Control-Allow-Source-Origin
User-Cache-Control
X-WA-Info
X-Akamai-Device-Characteristics
X-Block-Status
X-Nitro-Cache
Esi-Enabled
X-GeoIP
X-Device-Os
X-From
X-Dispatcher-Server
X-Origin
X-Scale
X-Loc
X-Gen-Mode
CDCHOST
X-App
Country-Code
CloudFront-Viewer-Country
X-VG-TLSProxy
X-Cdn-Srv
DSUID
X-BBC-Edge-Cache-Status
X-Nananana
Sever-Int
X-Hnp-Log
Req-Svc-Chain
Server-Ext
NM-Fastcgi-Cache
X-Mvc-Supplant-OutputCached
X-Vcl-Version
Server-Hostname
X-Nginx-Cache-Key
X-Cs
WP-Super-Cache
X-Correlation-ID
X-Web-Node
X-Op-Id-All
Pics-Label
ServedBy
Server-Info
Apple-News-Services-Handled
Ssr
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
X-Cache-Enabled
C-Via
Apple-News-Services-Request-Url
X-NCache
X-Instance-Name
Wxu-Next-Hostname
Wxu-Next-Commit
Origin-CC
X-NodeID
X-Refresh
X-Presslabs-Stats
Origin-EX
Wxu-Next-Region
X-Tx-Id
X-LB-NoCache
X-Azure-Ref-OriginShield
Time
X-Air-Hostname
X-Amz-Meta-Cb-Modifiedtime
X-Air-Trace-Id
X-Air-Source
Memory
X-TIME
X-HA-Backend
Server-ID
X-Dc
X-Microcachable
X-Platform-Cluster
Hostname
NGX
Cache-Host
X-Cache-Status-Check
X-Platform-Processor
X-Origin-Expires
X-Platform-Router
X-API-Version
X-Tb-Optimization-Total-Bytes-Saved
X-Locale
Cf-Device-Type
GeoIP-Latitude
X-URL
X-Site-Version
XM
X-VHOST
X-VarnishDD-TTL
X-ZONE
X-Wp-Cf-Super-Cache-Active
X-HN
Origin-Agent-Cluster
PFcat
X-CACHE-GROUP
Resin-Trace
X-Ad-Defer-Variation
X-Zone
X-FL-QIT-DEBUG
X-Vgn-Hpd-Reason
X-DC
X-Fpc
X-Via-SSL
X-Via-Edge
X-FL-EDGE
X-Varnish-Beresp-Ttl
Edge-Copy-Time
Locid
Srvid
X-Internal-Host
X-Varnish-Beresp-Grace
X-Via-CDN
A
YJS-ID
Cdn-Requestid
X-Micro-Cache
Sid
X-Webkit-Csp-Report-Only
X-Upstream-Ht
X-Upstream-Ct
X-FireWall-Port
X-ATG-Version
X-Cache-ASPX
X-TraceId
X-Contensis-Viewer-Groups
X-WP-CF-Super-Cache-Active
X-Github-Request-Id
X-Moov-Xdn-Version
X-Moov-T
Cache-Key
X-Pod-Name
X-Varnish-Authentication
X-Cached-By
X-DataCenter
User-Agent
Uri
True-Client-Ip
IsBot
X-AB
X-SIPLIST1
X-Buckets
X-LiteSpeed-Cache-Control
Location
X-NGINX-Cache
X-Info
GeoIP-Country-Code
X-B3-Parentspanid
X-B3-Spanid
X-Geo-Region
X-Provided-By
X-Backend-Instance
X-VCache
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
X-Platform-Server
X-HS-Content-Campaign-Id
State
X-Fastly-Cache
X-Release
X-Datacenter
GeoIp-Country-Code
X-Nitro-Rev
X-FTR-Request-ID
X-Nitro-Cache-From
X-Accel-Version
X-RN-RSRV
X-LiteSpeed-Tag
X-VC
X-Sigma-Backend
X-Sigma
X-Rocket-Build-Number
CF-Ctrl
X-Cache-Remote
X-MSEdge-Flight
X-MSEdge-Features
Cdn
Lb
SID
X-Is-Tablet
X-Is-Supported-Browser
X-Is-Desktop
X-Geo
X-Is-Mobile
X-Tcp-Rtt
XServer
NtCoent-Length
X-CS
True-Client-IP
X-Api-Version
X-Browser-Name
Cache
X-HostName
X-CSRF-TOKEN
X-NewRelic-App-Data
Tcn
X-Gamma-Serve
X-Generated-In
X-GeoIP-City
X-Vgn-Hpd-Variations-Key
Path
X-Vgn-Hpd-Ssi
X-Vgn-Hpd-Cached
Fastly-Drupal-Html
X-SRV
X-FPC
Epwk-X-Cache
X-Scheme
X-HS-Status
X-Hyper-Cache
X-TRACE-ID
Cf-Ipcountry
Cache-Tv-Group
X-Frame-Option
X-Rebelmouse-Cache-Control
X-CACHE-KEY
X-Rebelmouse-Surrogate-Control
Srv
X-Wp-Cf-Super-Cache
X-Webstats-RespID
Ohc-File-Size
Kp-EeAlive
X-Service
X-Wp-Cf-Super-Cache-Cache-Control
X-GoCache-CacheStatus
Serverid
HostName
X-APP-VERSION
X-UA
CountryCode
X-Mobile-URL
X-Air-Pt
X-AK-Request-ID
X-Esi
X-Location
Cdncip
Cdnsip
X-Amz-Meta-Opti
X-Guploader-Uploadid
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-Cache-Ttl
X-Branch-Name
On-Server
X-EC-Lua
X-Traceid
Proxy-Connection
X-Aicache-OS
WebServer
CacheControlHeader
X-Cache-Tags
X-Men
X-Region-Sid
X-TX-ID
X-Developers
Cdn-Host
X-Cdn-Cache-Status
WZWS-RAY
Env
X-Proxy-CacheRZ
Mime-Version
Yak-Timeinfo
Tube-Got-Results
X-Vercel-Id
X-Vercel-Cache
Geoip-Latitude
Cdn-Request-Time
RNT-Time
RNT-Machine
Tube-Get-Contents
Tube-Got-Eval
Tube-Return
X-Vc
XkeyRZ
X-Pad
X-Edge-Server
V-Age
X-Acquia-Purge-Cdn-Unconfigured
Click-Count-Error
X-Via-Popn
X-Servedbyhost
X-Akamai-Pragma-Client-IP
X-Via-Popv
X-Wa
X-V-Cache
X-Cache-FS-Status
X-B3-Trace-ID
Ohc-Cache-HIT
X-SB
X-Minions-Version
X-LB-ID
X-Nc
Click-Count-Action-Start
X-Req
X-Via-Poph
X-CDN-Cache-Status
X-VCL-Version
CDN
X-NMSegId
M-TraceId
X-TT-LOGID
X-FTR-Backend
X-Country-Code-Real
Req-ID
X-FTR-Backend-Server
X-FTR-Balancer
X-FTR-Expires
X-FTR-Cache-Status
X-Origin-Cache-Key
X-Cdn-Request-ID
ENV
X-Edge-Pop
X-Cdn-Forward
LB
WWW-Authenticate
X-NWS-UUID-VERIFY
Ngx
X-Lb-Cache
X-Ad-Load-Variation
X-Fastly-Country-Code
Server-Id
Content-Style-Type
X-Ha-Backend
Content-Script-Type
Cluster
X-WP-CF-Super-Cache-Cookies-Bypass
X-User
CF-Cached-On
PICS-Label
X-M-Log
X-M-Reqid
X-Lb-Nocache
X-MiniProfiler-Ids
X-Snapshot-Date
X-Processor
X-IN-APIGATEWAYSSL
X-IN-APIGATEWAY
X-Scope-Id
X-Edge-POP
X-Check-Cacheable
X-APP
X-TH-Server
X-Dw-Trace-Id
X-Acquia-Site
X-Via-Ucdn
X-Acquia-Application-UUID
X-Acquia-Purge-Tags
X-Acquia-Application-Trace
Pramga
X-Request-Start
X-Ckpd-Fst-Backend
Yjs-Id
X-Qnm-Cache
X-Shield-Cache-Expires
X-Litespeed-Cache-Control
Inserted-Into-Cache-At
X-Fastly-Cache-Hits
X-CUA
CACHE-MISS-TO-ORIGIN
HIT
X-Fastly-Backend-Reqs
X-Iauth-Set-Uid
X-Udemy-Cache-App-Namespace
Vha6-Origin
X-Render-Time
X-Miniprofiler-Ids
X-RAMCache
Log-Origin
X-Cached-Since
X-ElasticPress-Query
Cneonction