Threat Level: green Handler on Duty: Jan Kopriva

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
X-XSS-Protection
Accept-Ranges
Expect-CT
Pragma
X-Powered-By
CF-RAY
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
CF-Ray
X-Download-Options
X-Xss-Protection
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Request-Id
X-Adblock-Key
Access-Control-Allow-Credentials
X-FRAME-OPTIONS
X-Permitted-Cross-Domain-Policies
X-AspNet-Version
Alt-Svc
X-Request-ID
X-Runtime
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Generator
X-Cache-Status
X-Check
X-Cacheable
Timing-Allow-Origin
X-Envoy-Upstream-Service-Time
X-Iinfo
X-Content-Security-Policy
X-Drupal-Dynamic-Cache
Feature-Policy
Content-Encoding
Access-Control-Expose-Headers
Status
Upgrade
X-CDN
X-AspNetMvc-Version
Access-Control-Max-Age
X-Via
Server-Timing
Request-Context
X-Robots-Tag
X-Turbo-Charged-By
X-UA-Device
X-Amz-Request-Id
X-Cache-Group
X-Dns-Prefetch-Control
X-Amz-Id-2
EagleId
X-Backend
X-AH-Environment
X-Proxy-Cache
P3p
Keep-Alive
X-Server
X-Ws-Request-Id
X-Age
Cf-Edge-Cache
Host-Header
X-Hacker
X-Vhost
X-Server-Powered-By
X-Rq
X-Varnish-Cache
X-Dispatcher
X-Amz-Version-Id
Grace
Allow
X-OneAgent-JS-Injection
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-LiteSpeed-Cache
X-Page-Speed
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Ua-Compatible
Cf-Apo-Via
X-Device
Cf-Railgun
X-WebKit-CSP
Accept-CH
X-Aws-Lambda-Call-Status
X-Node
X-Pingback
X-Server-Id
X-Host
X-Ruxit-JS-Agent
EagleEye-TraceId
Surrogate-Control
X-Nginx-Cache-Status
X-Akam-SW-Version
X-Readtime
Request-Id
X-Backend-Server
Accept-Ch-Lifetime
X-Content-Security-Policy-Report-Only
X-HW
X-Cache-Lookup
X-Cloud-Trace-Context
X-Cache-Spec
X-Trace
X-Response-Time
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Application-Context
Permissions-Policy
X-Nginx-Upstream-Cache-Status
Fastly-Restarts
X-Edge
X-Mod-Pagespeed
X-WebKit-CSP-Report-Only
X-Litespeed-Cache
X-Country
Content-Location
X-Mcache
X-MS-InvokeApp
X-Content-Type
X-Url
X-Clacks-Overhead
X-TtlSet
X-PC
X-Vname
X-Midtier
X-CST
X-Amz-Server-Side-Encryption
Rating
Accept-CH-Lifetime
RTSS
Cache-Tag
X-Vcap-Request-Id
X-ECACHE
X-ESI
X-D2id
X-Rack-Cache
X-Element-Page-Cache
X-Exp-Id
X-Kinja-Build
X-Kinja-Revision
X-Kinja-Server
X-Use-Magma
X-GoogleNews-Bot
X-Kinja
X-Cdn-Fetch
Origin-Trial
X-Exp-Variant
Verso
X-VARITI-CCR
X-Server-Name
X-GitHub-Request-Id
Service-Worker-Allowed
X-Ac
X-Powered-By-Plesk
X-SharePointHealthScore
SPRequestGuid
X-Cnection
X-Amz-Rid
X-Navigation-Version
X-Client-IP
X-Webkit-Csp
Xkey
Edge-Control
SPRequestDuration
SPIisLatency
X-Abt-Application-Version
X-Cache-TTL
X-Upstream
Accept-Ch
Arr-Disable-Session-Affinity
X-Varnish-TTL
X-B3-TraceId
X-Cached
X-Mg-S
X-Dw-Request-Base-Id
X-Ttl
X-Erf-Bev-Bev-Is-Generated
X-Server-Lifecycle-Phase
X-Browser-Type
X-Kraken-Loop-Name
X-Instrumentation
X-Erf-Bev-Bev
X-NWS-LOG-UUID
X-Px
Display
Pagespeed
X-Middleton-Display
X-Sol
X-NF-Request-ID
X-SRCache-Store-Status
X-SRCache-Fetch-Status
Edge-Cache-Tag
Access-Control-Request-Method
X-Correlation-Id
X-Forwarded-For
X-Country-Code
X-Goog-Hash
X-Ser
X-FastCGI-Cache
X-Cache-Key
X-Powered-CMS
X-Id
AR-CACHE
AR-ATIME
AR-PoweredBy
AR-SID
Content-MD5
AR-Request-ID
Front-End-Https
X-RateLimit-Remaining
Public-Key-Pins
X-Amzn-Trace-Id
X-Version
X-Jurisdiction
X-HP-Trace-Id
X-HP-Webp
X-MSEdge-Ref
X-T
X-Content-Digest
X-Recruiting
TCN
Response
X-Middleton-Response
X-Accel-Expires
TP-Cache
TP-L2-Cache
X-Ratelimit-Limit
X-Shield-Request-Id
MicrosoftSharePointTeamServices
X-Fastcgi-Cache
S
Cache-Status
Nginx-Cache
X-Fastly-Request-ID
X-Request-Received
X-Request-Processing-Time
X-HS-Content-Id
Cross-Origin-Opener-Policy
X-HS-Hub-Id
X-HS-Cache-Config
X-HS-Combine-CSS
X-XRDS-Location
Server-Node
Cache-Tags
X-Daa-Tunnel
X-B3-TraceId-Primal
MRF-Tech
X-ORACLE-DMS-ECID
Mrf-Cache-Status
X-Distributor
X-Hits
X-ORACLE-DMS-RID
X-PressLabs-Stats
X-LB-Cache
X-Kinsta-Cache
X-Edge-Location-Klb
X-Origin-Server
X-Ua-Browser
X-Ezoic-Cdn
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Ratelimit-Reset
X-TEC-API-VERSION
Filterid
Fastcgi-Cache
Alternate-Protocol
X-Ratelimit-Remaining
X-TTL
X-LLID
X-Frontend
X-Request-Handler-Origin-Region
X-Microsite
X-Grace
X-Rid
Realpath
X-DIS-Request-ID
X-Logged-In
Healthy
X-FB-Debug
X-Varnish-Backend
X-Git-Hash
Server-Name
X-NGENIX-Cache
Cleartype
X-Www-Served-By
X-Geo-Country
X-Cluster-Name
X-Page-Id
Payment
X-Debug-Info
X-Hostname
DC
X-Load-Cache
MS-Author-Via
X-Protected-By
X-Forwarded-Proto
X-Origin-Cache
Access-Control-Allow-Method
X-ASPNET-VERSION
Content-Disposition
X-Upgrade-Enabled
X-B3-Sampled
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Goog-Metageneration
X-GUploader-UploadID
X-Activity-Id
X-Az
X-AppVersion
Charset
X-Proxy
X-Seen-By
Count-Hit
X-Cache-Age
X-DataDome
X-Amz-Meta-S3cmd-Attrs
X-Amz-Replication-Status
Paypal-Debug-Id
X-Fb-Rlafr
X-Times
X-Whom
X-Azure-Ref
Cross-Origin-Resource-Policy
X-B
X-F-Cache
X-Revision
X-Akamai-Edgescape
Accept-Charset
X-ECache
Surrogate-Key
X-Contextid
X-App-Environment
X-Varnish-Server
Viewport
X-Type
X-Route-Name
X-Is-Crawler
X-Request-Guid
X-Providence-Cookie
X-Flags
X-Aspnet-Duration-Ms
X-B3-Traceid
X-TT
Retry-After
X-Wix-Request-Id
X-Aspnetmvc-Version
X-Hosted-By
X-Envoy-Decorator-Operation
X-Language
X-DynaTrace
X-Signature
X-B-Cache
X-Cache-Control
X-Mobile
X-Magnolia-Registration
X-Varnish-Grace
X-XRDS-LOCATION
X-App-Server
X-Source
X-VCache
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
Version
Host
WPO-Cache-Message
WPO-Cache-Status
Refresh
X-Amzn-RequestId
X-N
X-Amz-Apigw-Id
X-RateLimit-Limit
X-Server-ID
X-HTML-Minification-Powered-By
Referer-Policy
X-Tumblr-Pixel-1
X-Original-Request-Id
X-Cache-Rule
Access-Control-Request-Headers
X-Cache-Time
X-Response-Served-From
X-Tumblr-Pixel
X-Varnish-Age
X-Tumblr-User
X-Tumblr-Pixel-0
Amp-Access-Control-Allow-Source-Origin
X-EdgeConnect-Cache-Status
X-Rule
X-UUID
X-Framework
Protected
X-Content-Powered-By
X-Cacheable-TTL
X-G
X-Jobs
Ms-Operation-Id
MS-CV
X-User-Agent
X-RTag
SD-X-WS
X-Trace-Id
X-Backend-Name
X-Oracle-Dms-Rid
X-L-Path
X-Cache-Grace
X-Environment-Context
X-Oracle-Dms-Ecid
X-ProcessESI
X-RemovedCookies
X-FW-Server
Section-Io-Cache
X-FW-Static
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Device-Type
X-FW-Version
X-FW-Type
X-Status
Akamai-GRN
X-FW-Serve
NGB
X-Region
GEO-INFO
From-Origin
X-FW-Hash
X-FW-Dynamic
X-Is-Bot
X-Cache-Status-Check
X-Page-View
X-Cache-Expired-At
X-Rendered-As
X-Akamai-Request-ID2
Front
X-Http-Reason
X-Drupal-Cache-Tags
X-NYM-Debug-Backend
X-Adobe-Content
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Instance
X-Drupal-Cache-Contexts
X-Nginx-Cache
X-Adobe-Loc
X-Pinterest-Rid
Pinterest-Version
CDN-RequestId
Pinterest-Generated-By
X-Unique-Id
Url
X-Servername
X-Time
Liferay-Portal
Accept-Language
X-Content-Options
X-Template
Fastly-SIE
Fastly-SWR
X-Newrelic-App-Data
X-Varnish-Ttl
X-Zen-Fury
X-CDN-Forward
Backend
X-Debug-IsConnected
X-Debug-IsPreview
X-Air-Source
X-Air-Hostname
X-Cache-Hit
X-Air-Trace-Id
X-Fastly-Request-Id
SRV
X-DynaTrace-JS-Agent
X-Yottaa-Metrics
X-Yottaa-Optimizations
Country
X-Rocket-Nginx-Serving-Static
X-Mode
Content-Secure-Policy
X-Uri
X-ARC
Node
X-Edge-Location
Webserver
X-UPSTREAM-Address
S-Rt
Onion-Location
X-Amzn-Remapped-Content-Length
X-Cache-Server
X-Generation-Time
X-Rewrite-Enabled
Meta-Geo
X-RN-RSRV
X-COUNTRY
X-Tumblr-Pixel-2
Filters
X-Cache-Operation
X-Tumblr-Pixel-3
X-App-Version
X-IPS-LoggedIn
Azure-SiteName
Azure-SlotName
Azure-RegionName
X-Timing-Wait
Countrycode
WP-Super-Cache
Azure-Version
CF-IPCountry
X-Proxy-Build
X-Proxy-Cache-Info
X-PHP-Backend
X-Locale
X-Content-Age
Selected-Fe
Cache-Hits
Azure-InstanceId
X-Soup
X-Reqid
X-Ms-Request-Id
X-Skip-Cache
X-Site-Version
X-Server-W
X-Web-Node
X-Ua
X-Tb
X-Sucuri-ID
X-Via-Fastly
X-Sucuri-Cache
X-ProxyCache-Key
X-Ms-Version
X-ProxyCache-Status
Cache-Name
X-Cms-Context
X-BYPASS-REASON
X-Cache-Action
Uber-Trace-Id
X-Zipkin-Id
X-IPLB-Instance
X-SayCDN-TTL
X-Cluster-Node
TWC-GeoIP-Country
X-Say-TTL
Cache-Tv-Group
X-Origin-Hint
X-PHP-Host
X-Proto
Webcakes-App-Version
X-LJ-Flow-ID
X-VWS-Id
TWC-Privacy
X-Routing-Service
Property-Id
X-Say-Cacheable
ServerID
X-Origin-Date
TWC-Connection-Speed
X-Proxied
X-Extlb
X-Cache-Host
TWC-Device-Class
X-AWS-Id
X-Proxy-Cache-Status
TWC-GeoIP-LatLong
TWC-Locale-Group
X-Labrador-Cache-Channel
Webcakes-Region
X-IPLB-Request-ID
X-UA-Device-Type
Webcakes-App-Name
X-Access
Web-Mar-Node
X-Forwarded-Host
X-Section
X-Sql-Duration-Ms
X-No-Session
X-VC-Cache
X-LAGOON
X-Cluster
X-Optimistic-Header
X-Format
X-Debug
X-SaId
X-JoinUs
X-Sql-Count
X-Urbn-Context-Path
X-Adobe-Source
Apigw-Requestid
X-Urbn-Site-Id
X-R9-Blue-Green-Version
Locale
X-Detected-As
X-Cache-TTL-Remaining
X-FB-TRIP-ID
X-Handled-By
X-Real-IP
DB-Nickname
Mn-Server-Ip
Cross-Origin-Window-Policy
X-Director
X-LSADC-Cache
X-Ruxit-Js-Agent
X-Xfnlog-Site
X-Varnish-Beresp-Grace
X-Node-Name
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
ServedBy
Fastcgi-Useragent
Frame-Options
X-Tec-Api-Root
X-Tec-Api-Version
X-GeoCode
X-GeoCountry
X-Tec-Api-Origin
Upgrade-Insecure-Requests
Mime-Version
X-Varnish-Hits
Source
X-Oneagent-Js-Injection
X-Tt-Logid
X-Api-Version
CDN-Cache
CDN-PullZone
CDN-EdgeStorageId
CDN-CachedAt
Load-Balancing
CDN-RequestCountryCode
X-Hl-Ver
CDN-Uid
X-Varnish-Cache-Hits
X-Generated-By
X-GEO
Fastly-Drupal-HTML
Xet-Cookie
X-SRV
X-Buckets
X-Request-Time
X-FireWall-Port
X-Varnish-Hostname
X-ServerID
X-Datadog-Trace-Id
X-Datadog-Parent-Id
X-RM-Cache-TTL
X-Datadog-Sampling-Priority
X-Mg-Request-UUID
X-Datadog-Sampled
X-Origin-TTL
X-Redis-Cache
X-Origin-CC
X-TA-CDN-Provider
CF-Cached-On
X-URL
X-Cache-Debug
X-Loop
X-Storage
X-TIME
X-Akamai-Transformed
X-Served-From
X-ShopId
X-ShardId
X-Sorting-Hat-PodId
X-Storefront-Renderer-Rendered
X-Alternate-Cache-Key
X-Sorting-Hat-ShopId
X-Shopify-Stage
X-Pubstack
X-Provided-By
Xserver
X-Endurance-Cache-Level
X-Newrelic-Synthetics
X-Pass-Why
X-Restarts
X-CSRF-Token
X-Request-Host
X-Location
X-Tx-Id
X-Service
Memcached
Host-ID
X-Level-Front-Cache
X-Origin-Time
Sslversion
X-Men
X-Mid
X-Mobile-URL
X-Core-Mission
X-Conf
MD5-Digest
X-Nyt-Route
X-Generated-On
X-Ec-Fail
DCR-Decision-By
DCR-Processing-Time-Ms
X-Ec-GeoHdr
X-Epic-Correlation-Id
Cache-Host
Candidate-Md5Url
X-Developer
DSUID
Gannett-Cam-Experience-Id
X-D
NM-Fastcgi-Cache
Odigeo-Trace-Id
X-Destination
Edge-Cache
BehaviorPad-Version
X-External-Request-Id
Redirect-Candidate
X-Cache-Info
Release
Rendered-Blocks
X-INCAP-ABP
X-Hash
Lang
X-Gdpr
X-Fetched-On
A
Origin
X-CUA
X-Cache-NE
Ngx.Var.Host
Server-Host
X-Origin
X-Vdms-Path
X-A-Dcw
X-B-Cookie
X-SRCache-Key
X-Sigma-Backend
X-Sigma
X-BCube-Filmed-By
X-ScT
X-A-Dgt
X-Vdms-Version
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-Thinkindot-L3
X-TIM-N
X-Bip
X-Cache-Date
X-Thanos
X-A-Ccd
WWW-Authenticate
X-A
X-A-Dam
X-Test
X-S-Maxage
Thinkindot-Control
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
Xc-Version
X-Bc-Bl
X-Aed
TDXMobile
HostName
Surrogated-Key
X-We-Are-Hiring
T-Server
X-CMSURLCustom
X-S-Cookie
X-Processor
X-A-Wwc
Meta-Geo-Continent
X-Rocket-Build-Number
X-Rojux
X-S
X-Application
X-Response-By
Server-Info
CacheControlHeader
C-Via
Cache-Key
AKAMAI
X-Esi-Check
X-Dispatcher-Server
X-Date
X-Accel-Expires-Debug
X-Cdn-Origin
Fastly-Backend-Name
Fastly-GeoIP-CountryCode
Gh-Request-Id
X-Scale
X-Dispatcher-Number
X-Auto-Login
CloudFront-Viewer-Country
Click-Count-Error
Cmsid
Cmstype
X-Ec-Custom-Error
Country-Code
Click-Count-Action-Start
X-Geo-Header
X-SD-PageType
X-Mvc-Supplant-Cachable
X-Node-Id
X-Server-IP
X-Loc
X-Cache-Id
X-Slack-Shared-Secret-Outcome
X-Slack-Backend
X-Req
X-Region-Sid
X-Platform
X-Origin-Response-Time
X-Cache-Bucket
X-Org
Mail-Subject
X-Pool
Magicmarker
X-Sn-Servicetimems
X-Akamai-Device-Characteristics
X-CacheTTL
X-Varnishpool
Tube-Got-Results
Tube-Return
X-BBC-Edge-Cache-Status
X-Fastly-Cache
We-Hiring
X-Gamma-Serve
Tube-Got-Eval
X-HS-Content-Campaign-Id
X-Httpd
X-Human
Req-Svc-Chain
X-Gzip
Tube-Get-Contents
X-Var-Ttl
X-Fastly-Backend
Section-Origin-Responded
Section-Io-Origin-Status
Section-Io-Id
X-VC
Environment
Section-Io-Origin-Time-Seconds
X-WP-CF-Super-Cache-Active
X-Via-CDN
X-Vcl-Version
X-Azure-Ref-OriginShield
X-Cache-FS-Status
X-Ckpd-Fst-Backend
X-Irp-Debug
X-Vmg-Version
X-VServer
X-WA-Info
X-WADP-Cache
X-Varnish-Remaining-TTL
X-Varnish-CookieINHashed-On
X-SB
X-V-Cache
X-Variation
X-Varnish-CookieHashed-On
X-Worker
Locid
X-FL-EDGE
X-FL-QIT-DEBUG
X-Instance-Name
X-Nginx-Cache-Key
X-Developers
X-Cdn-Srv
On-Server
Origin-CC
Origin-EX
Srvid
X-Platform-Router
X-Platform-Processor
X-Frame-Option
X-GeoIP
X-GeoIP-City
X-GeoIP-Country-Code
X-Forwarded-Site
X-FC-Vary-Parameters
X-Core-Value
X-DefElseHash
X-DefHash
X-Device-Os
X-GeoIP-Region-Code
X-Has-Esi
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Platform-Cluster
X-Owner
X-Origin-Expires
X-Is-Gdpr
X-JWT-State
X-Mly-Id
X-Clara-WADP
X-Fmm-Version
Is-Eu
Expect-Staple
State
Kp-EeAlive
Machine
Ssr
Platform
Datacenter
X-Ad-Defer-Variation
Adler-Geo
X-TNCMS
Canary
Web-Mar-Region
Edge-Copy-Time
X-Varnish-Beresp-Ttl
X-Via-Edge
X-Via-SSL
AMP-Access-Control-Allow-Source-Origin
X-Op-Id-All
Vix-Hermes-Req-Id
X-Release
X-NCache
X-Minions-Version
Server-Hostname
Server-Ext
X-DPWN-IS-SECURE
X-Accel-Buffering
X-App
X-Aicache-OS
X-Zone
X-From
PFcat
X-Old-Content-Length
X-Qloud-Router
Cache-Provider
Sever-Int
X-Hnp-Log
Producers
X-Gen-Mode
NGX
Wxu-Next-Commit
X-NodeID
X-Wix-Viewer-Type
L
X-Cache-Tags
Wxu-Next-Region
X-Block-Status
User-Cache-Control
X-VarnishDD-TTL
Wxu-Next-Hostname
X-HN
L5d-Success-Class
X-Eu-Site
X-Csrf-Jwt
X-Mvc-Supplant-OutputCached
X-CGP
X-Cache-Remote
Apple-News-Services-Handled
X-VG-TLSProxy
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
X-Varnish-Beresp-Status
X-Ua-Device
X-Platform-Server
Ha-Gx-Prefs
CDCHOST
X-Request-Start
X-Microcachable
HA-Ipaddr
X-Nananana
X-RCS-CacheZone
X-Parent-Response-Time
X-Webkit-CSP-Report-Only
X-Dc
X-CACHE-AGE
X-Air-Pt
X-Lambda-Id
X-VCT
Fastly-SSL
X-Cache-Enabled
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-Up
X-B3-SpanId
X-Via-Popv
X-Tb-Optimization-Total-Bytes-Saved
X-Via-Poph
X-Via-Popn
Sid
X-LB-NoCache
Pics-Label
X-Correlation-ID
X-B3-Spanid
X-Cs
VNS-Age
CPC-Age
VNS-Cache
CPC-Cache
X-Refresh
X-Render-Time
X-AIR-PT
X-Upstream-Ht
X-Vtex-Remote-Cache
X-Cached-By
X-Upstream-Ct
X-Generated-In
X-Cache-Backend
X-DC
NtCoent-Length
X-Trace-ID
X-HA-Backend
Memory
Decoy-Debug-Key
Decoy-Debug-Status
Time
X-ND-Cache
X-Hcs-Proxy-Type
X-Cache-Type
Cluster
Env
Cache
X-CCDN-CacheTTL
X-CCDN-Origin-Time
Decoy-Debug-TTL
X-TH-Server
GeoIP-Latitude
X-LB-ID
Fastly-Drupal-Html
X-Webkit-CSP
X-NWS-UUID-VERIFY
X-Tid
X-Edge-Pop
X-HS-Status
SID
X-ATG-Version
Srv
X-Via-JSL
X-Servedbyhost
X-CACHE-KEY
X-Presslabs-Stats
X-Esi
X-NewRelic-App-Data
GeoIp-Country-Code
Svr
Uri
X-Contensis-Viewer-Groups
X-DataCenter
X-Cache-ASPX
Server-ID
X-Wa
X-Nc
X-Client-Ip
X-Check-Cacheable
X-Varnish-Authentication
X-MP-GENERATED-AT
Cdn
X-Srv
X-Datadome
X-Vgn-Hpd-Variations-Key
X-ZONE
X-Vgn-Hpd-Cached
X-CF-Lambda-Version
X-PAYTM-SRV-ID
X-RateLimit-Remaining-Second
Esi-Enabled
X-Vgn-Hpd-Ssi
X-CF-Lambda-Fn
X-RateLimit-Limit-Second
True-Client-IP
X-Amz-Meta-Cb-Modifiedtime
X-Proxy-CacheRZ
YJS-ID
XkeyRZ
N-Cache
X-TX-ID
X-Fpc
X-CDN-Cache-Status
X-Wikidot-Backend
X-Wikidot-Static-Cache
Lb
X-Vc
X-Udemy-Cache-App-Namespace
X-Orig-Expires
X-Shop-Environment
X-Tenant
X-Forwarded-Path
RNT-Machine
X-Nf-Request-Id
RNT-Time
Resin-Trace
X-Bl-Debug
M-TraceId
X-CS
Hostname
X-Varnish-Beresp-TTL
X-NGINX-Cache
Cdnsip
Cdncip
OT-Force-Account-Verify
X-MSEdge-Features
X-Gateway-Cache-Key
X-Gateway-Cache-Status
X-MSEdge-Flight
X-Gateway-Skip-Cache
X-Gateway-Request-Id
XServer
X-AK-Request-ID
X-FPC
X-Fastly-Country-Code
True-Client-Ip
X-EC-Lua
X-CSRF-TOKEN
X-Policy
X-Via-NSCOPI
X-App-Name
X-B3-Trace-ID
X-API-Version
X-Service-Response-Time
Sm-Log-Id
X-Logging-Id
Eomportal-Instance
Server-Id
CDN
X-Cache-Ttl
X-Datacenter
X-WA
Hit
GeoIP-Country-Code
Path
X-Container-Uri
X-Git-Commit
X-Cdn-Diag
X-Micro-Cache
X-APP-VERSION
X-CLOUD-TRACE-CONTEXT
Ngx-Var-Key
X-Accel-Version
Tcn
X-NC
IsBot
X-Cache-NGX
X-Lb-Id
X-VCL-Version
X-SIPLIST1
X-ServedByHost
X-MCACHE
X-Request-URI
X-Akamai-Pragma-Client-IP
X-Edge-POP
X-Geo
HIT
X-Ha-Backend
X-Vcache
X-HostName
X-RateLimit-Reset
LB
X-Cdn-Forward
X-Tncms
X-Info
Geoip-Latitude
X-Cdn-Cache-Status
X-SERVER-NAME
RATING
X-TT-LOGID
Pramga
XM
X-Acquia-Purge-Cdn-Unconfigured
V-Age
X-Srcache-Fetch-Status
Cross-Origin-Opener-Policy-Report-Only
FSS-Cache
X-Lb-Nocache
Location
X-Rebelmouse-Surrogate-Control
X-Snapshot-Date
X-Rebelmouse-Cache-Control
Timeexpire
X-Srcache-Store-Status
CDN-RequestPullCode
ENV
CDN-RequestPullSuccess
X-VG-WebCache
X-Clientip
X-Via-PopV
Epwk-X-Cache
X-Via-PopH
Req-ID
X-Via-PopN
X-Pod-Name
Yjs-Id
X-Serial
X-Ctl-Mach
Ohc-File-Size
X-LiteSpeed-Cache-Control
X-Iauth-Set-Uid
X-TimeS
X-Wp-Cf-Super-Cache
X-Wp-Cf-Super-Cache-Cache-Control
True-Client-Country-4JS
W
X-Amz-Meta-Opti
X-Hyper-Cache
X-Dw-Trace-Id
Warning
X-LiteSpeed-Tag
X-M-Reqid
X-M-Log
X-Acquia-Purge-Tags
X-Acquia-Site
X-Cdn-Request-ID
X-Acquia-Application-UUID
X-Litespeed-Cache-Control
Proxy-Connection
X-UP
X-RAMCache
X-Cache-Expires
WZWS-RAY
X-User
X-PERF
Ec-Rule-Version
X-ApacheServer
X-Oss-Hash-Crc64ecma
X-Oss-Storage-Class
X-Oss-Object-Type
X-Oss-Request-Id
X-Oss-Server-Time
X-Vgn-Hpd-Reason
X-Acquia-Application-Trace
Content-Script-Type
Servername
Content-Style-Type
Cdn-Requestid
X-Qnm-Cache
Cneonction
X-Fastly-Backend-Reqs
X-Lsadc-Cache
X-MiniProfiler-Ids
CountryCode
X-Viewer-Country
X-WP-CF-Super-Cache-Cookies-Bypass
X-Akamai-ERPolicy
X-Akamai-ERRuleID
PICS-Label
X-B3-ParentSpanId
X-Th-Server
Ngx
X-B3-Parentspanid
My-App
X-IPS-Cached-Response
MIME-Version
X-Mg-Cache
X-Webstats-RespID
X-Fastly-Cache-Hits
X-Swift-Error
Ohc-Cache-HIT