Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-Cache-Status
Link
Accept-Ranges
CF-RAY
ETag
X-XSS-Protection
Expect-CT
Pragma
X-Powered-By
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
Alt-Svc
X-Served-By
X-Xss-Protection
X-Download-Options
X-Timer
X-Request-Id
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Cache-Status
X-Check
X-Generator
X-Cacheable
Timing-Allow-Origin
X-Content-Security-Policy
X-Iinfo
Feature-Policy
Status
X-Envoy-Upstream-Service-Time
Content-Encoding
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
X-AspNetMvc-Version
X-CDN
P3p
X-Request-ID
Upgrade
X-Via
CF-Ray
X-Ws-Request-Id
Access-Control-Max-Age
Server-Timing
EagleId
X-Cache-Group
X-Turbo-Charged-By
Report-To
Keep-Alive
Request-Context
X-UA-Device
X-Age
X-Backend
X-Proxy-Cache
X-Server-Powered-By
X-AH-Environment
X-Robots-Tag
X-Hacker
X-Amz-Request-Id
X-Server
Host-Header
X-Amz-Id-2
Grace
X-LiteSpeed-Cache
X-Rq
X-Swift-CacheTime
X-Swift-SaveTime
X-Varnish-Cache
X-Nginx-Cache-Status
Ali-Swift-Global-Savetime
NEL
X-WebKit-CSP
X-Page-Speed
X-Vhost
EagleEye-TraceId
X-OneAgent-JS-Injection
X-Amz-Version-Id
X-Ua-Compatible
X-Pingback
X-Dns-Prefetch-Control
X-Dispatcher
X-Device
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Cache-Spec
X-Host
Accept-CH
X-Server-Id
Cf-Railgun
X-Node
X-Backend-Server
X-Readtime
Surrogate-Control
X-Akam-SW-Version
Request-Id
X-Response-Time
X-HW
Xkey
X-Application-Context
X-EdgeConnect-MidMile-RTT
Content-Location
X-EdgeConnect-Origin-MEX-Latency
Rating
X-Country
X-B3-TraceId
X-Cloud-Trace-Context
Accept-Ch-Lifetime
X-Ruxit-JS-Agent
Accept-CH-Lifetime
X-Cache-Lookup
X-Trace
X-Url
Allow
X-Ac
X-Content-Type
X-Vname
X-PC
X-TtlSet
X-Varnish-TTL
X-Clacks-Overhead
Edge-Control
X-Aws-Lambda-Call-Status
X-Mod-Pagespeed
X-Server-Name
X-ESI
Fastly-Restarts
Cache-Tag
Service-Worker-Allowed
X-VARITI-CCR
X-Rack-Cache
Verso
X-Element-Page-Cache
MS-Author-Via
X-Upstream
X-FastCGI-Cache
X-Vcap-Request-Id
X-MS-InvokeApp
X-Amz-Rid
X-GitHub-Request-Id
Public-Key-Pins
X-Dw-Request-Base-Id
X-Cached
X-Client-IP
X-D2id
X-Abt-Application-Version
X-Cache-TTL
X-Px
X-Cnection
RTSS
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
X-Navigation-Version
X-Cdn-Fetch
X-Kinja-Server
X-Kinja-Revision
X-Use-Magma
X-Kinja-Build
X-Kinja
X-GoogleNews-Bot
X-Exp-Id
X-Exp-Variant
Arr-Disable-Session-Affinity
X-Country-Code
Access-Control-Request-Method
X-Powered-By-Plesk
X-Goog-Hash
X-NF-Request-ID
X-Instrumentation
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-Powered-CMS
AR-PoweredBy
AR-ATIME
AR-CACHE
AR-SID
AR-Request-ID
X-Middleton-Display
Pagespeed
Display
X-Sol
X-Version
X-TTL
X-Origin-Cache
Response
X-Middleton-Response
X-LLID
X-Amz-Server-Side-Encryption
X-MSEdge-Ref
X-Edge-Location-Klb
X-Kinsta-Cache
Nginx-Cache
TCN
X-Edge
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
X-Protected-By
X-RateLimit-Remaining
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-T
X-Jurisdiction
X-CST
X-HP-Trace-Id
X-HP-Webp
X-Forwarded-For
X-Content-Security-Policy-Report-Only
X-Shield-Request-Id
X-Id
X-Mg-S
S
Content-MD5
Edge-Cache-Tag
X-Aspnetmvc-Version
Accept-Ch
X-Language
SPIisLatency
SPRequestDuration
Fastcgi-Cache
X-Ruxit-Js-Agent
X-Mid
Front-End-Https
Realpath
X-Recruiting
X-Request-Processing-Time
X-Request-Received
Server-Node
Pinterest-Generated-By
Filters
X-Pinterest-Rid
Pinterest-Version
X-Frontend
X-Content
X-Ab
Server-Name
X-Ua-Browser
X-MCACHE
X-DynaTrace
X-Correlation-Id
X-Ser
X-NWS-LOG-UUID
X-HS-Content-Id
X-HS-Cache-Config
X-HS-Hub-Id
X-Yandex-Sdch-Disable
X-HS-Combine-CSS
X-Cache-Key
X-Ezoic-Cdn
X-Ttl
SPRequestGuid
X-SharePointHealthScore
X-Template
X-Hits
X-Parallel-Accel
X-ECACHE
X-Kong-Proxy-Latency
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Kong-Upstream-Latency
MicrosoftSharePointTeamServices
Cache-Tags
X-Page-Id
Charset
X-B3-Sampled
Host
Alternate-Protocol
Cleartype
X-Www-Served-By
X-Git-Hash
X-Geo-Country
Fusion-Component-Id
Fusion-Template-Id
Fusion-Content-Id
Fusion-Content-Source
Fusion-Source
Fusion-Deployment-Id
X-Content-Options
X-Daa-Tunnel
X-Debug-Info
X-Webkit-Csp
X-DIS-Request-ID
X-Hostname
X-Amzn-Trace-Id
X-Content-Digest
X-Ratelimit-Limit
X-Amz-Replication-Status
Cross-Origin-Opener-Policy
X-Varnish-Age
Filterid
X-XRDS-LOCATION
X-AppVersion
X-Activity-Id
X-Az
X-Grace
X-FB-Debug
X-Accel-Expires
X-Upgrade-Enabled
X-Fastly-Request-Id
X-VCache
ServerID
X-F-Cache
X-WebKit-CSP-Report-Only
X-N
X-Forwarded-Proto
X-Nginx-Upstream-Cache-Status
X-Origin-Server
X-Rid
Access-Control-Allow-Method
X-Mobile-URL
X-Providence-Cookie
X-Is-Crawler
X-Route-Name
X-Request-Guid
X-Aspnet-Duration-Ms
X-Flags
X-LB-Cache
X-Type
TP-L2-Cache
TP-Cache
X-TT
X-Whom
X-Varnish-Grace
X-Goog-Stored-Content-Encoding
Viewport
X-Seen-By
X-App-Environment
X-Goog-Generation
X-Goog-Stored-Content-Length
X-Goog-Metageneration
X-GUploader-UploadID
X-Goog-Storage-Class
X-Tb
Payment
X-FW-Dynamic
X-Distributor
Node
X-FW-Serve
X-FW-Hash
X-FW-Static
X-FW-Type
X-FW-Server
X-Fastcgi-Cache
X-User-Agent
DC
X-Server-ID
Paypal-Debug-Id
X-App-Server
Fastcgi-Useragent
X-Wix-Request-Id
Accept-Charset
Country
X-Fastly-Request-ID
X-Ratelimit-Reset
X-Cache-Control
X-Cache-Rule
X-DataDome
X-NGENIX-Cache
X-Litespeed-Cache
X-Origin-Upstream-Status
X-Via-JSL
Version
X-Microsite
X-Tec-Api-Version
X-Tec-Api-Root
X-Request-Handler-Origin-Region
X-Tec-Api-Origin
Referer-Policy
X-Drupal-Cache-Tags
X-Cluster-Name
X-Logged-In
X-Cache-Age
X-Contextid
X-Signature
X-B-Cache
X-Buckets
Cache-Status
X-Erf-Bev-Bev-Is-Generated
X-Node-Name
X-Erf-Bev-Bev
Refresh
X-Browser-Type
X-Response-Served-From
X-Load-Cache
VIX-Pulpo-Upstream-Status
X-Varnish-Backend
X-Mobile
VIX-Pulpo-Node
X-Original-Request-Id
SD-X-WS
X-Page-View
X-Is-Bot
X-Rendered-As
X-Real-IP
X-Cache-Expired-At
X-IPLB-Instance
X-Vgn-Hpd-Reason
Access-Control-Request-Headers
X-Debug
X-Jobs
NGB
X-Revision
X-Proxy-Cache-Status
X-B
X-Cacheable-TTL
X-Cache-Action
X-RemovedCookies
X-Proxy
X-Device-Type
X-Rule
X-ProcessESI
X-UUID
X-Yottaa-Optimizations
X-Instance
X-Yottaa-Metrics
X-Drupal-Cache-Contexts
Akamai-GRN
Surrogate-Key
X-Cache-Time
X-Debug-IsPreview
X-Debug-IsConnected
X-Framework
Amp-Access-Control-Allow-Source-Origin
X-FW-Version
X-G
CF-IPCountry
SID
X-PressLabs-Stats
X-Air-Hostname
X-Air-Trace-Id
X-Air-Source
X-Accel-Buffering
X-Oracle-Dms-Ecid
DynaTrace
X-Oracle-Dms-Rid
X-Nginx-Cache
GEO-INFO
X-Azure-Ref
Count-Hit
X-Cache-NGX
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Source
Liferay-Portal
Uber-Trace-Id
X-TEC-API-VERSION
X-Ms-Version
X-Ms-Request-Id
X-Ratelimit-Remaining
X-Cache-Operation
X-Oneagent-Js-Injection
X-Presslabs-Stats
Frame-Options
X-Zen-Fury
MS-CV
X-EdgeConnect-Cache-Status
Ms-Operation-Id
X-RTag
Protected
X-XRDS-Location
Healthy
X-Cache-Hit
X-CDN-Forward
X-APP-VERSION
X-Mode
X-L-Path
Countrycode
Xserver
X-Backend-Name
X-Environment-Context
X-Tumblr-Pixel-1
X-Tumblr-Pixel
X-Tumblr-Pixel-0
Ec-Rule-Version
Cross-Origin-Window-Policy
X-Varnish-Server
X-Tumblr-User
X-RateLimit-Limit
X-IPS-LoggedIn
X-Cache-TTL-Remaining
X-Hyper-Cache
LB
X-Adobe-Content
X-Adobe-Loc
Backend
X-Tid
X-UPSTREAM-Address
X-SaId
X-Region
X-Servername
X-Detected-As
X-RN-RSRV
X-Content-Age
Meta-Geo
X-JoinUs
WPO-Cache-Status
X-Forwarded-Host
WPO-Cache-Message
X-Rewrite-Enabled
X-Extlb
X-Sorting-Hat-PodId
X-ShopId
X-Debug-Cache
X-Format
X-Generation-Time
X-Sql-Duration-Ms
X-Cache-Grace
X-Sorting-Hat-ShopId
X-Sql-Count
X-Shopify-Stage
Decoy-Debug-Key
Decoy-Debug-Status
Decoy-Debug-TTL
Eomportal-Instance
Country-Code
Apigw-Requestid
X-Proxied
X-Alternate-Cache-Key
X-ShardId
Content-Disposition
X-Cache-Server
X-Hosted-By
X-Redis-Cache
X-Zipkin-Id
X-Uri
X-Routing-Service
X-Trace-Id
X-Site-Version
X-ApacheServer
X-Section
X-FB-TRIP-ID
Section-Io-Cache
X-PERF
X-Via-Fastly
X-Varnish-Beresp-Grace
X-Content-Powered-By
Mn-Server-Ip
Cache-Name
X-PCL
Url
X-Access
X-PHP-Backend
X-No-Session
Fastly-SSL
X-NCache
X-Human
X-Microcachable
X-ServerID
X-Status
X-Origin-Date
X-OCL
Webcakes-App-Name
TWC-GeoIP-LatLong
CDN-Uid
TWC-GeoIP-Country
TWC-Locale-Group
CDN-RequestCountryCode
X-NYM-Debug-Backend
X-Say-Cacheable
X-Pubstack
X-ProxyCache-Status
Property-Id
TWC-Connection-Speed
Webcakes-App-Version
Selected-Fe
TWC-Device-Class
X-Proxy-Build
CDN-EdgeStorageId
X-Cluster-Node
CDN-RequestId
CDN-CachedAt
X-Say-TTL
X-Server-W
X-Storage
X-SayCDN-TTL
X-Cache-Type
X-Origin-Hint
X-Timing-Wait
X-UA-Device-Type
CDN-PullZone
X-Akamai-Edgescape
X-ProxyCache-Key
X-Cache-Host
CDN-Cache
X-BYPASS-REASON
Webcakes-Region
TWC-Privacy
Cache-Tv-Group
X-Web-Node
X-Soup
X-R9-Blue-Green-Version
X-Generated-By
X-Hl-Ver
X-Varnishpool
X-Be
Azure-SiteName
Azure-RegionName
Azure-InstanceId
Azure-SlotName
Content-Secure-Policy
X-TIME
Azure-Version
X-Ua
X-LSADC-Cache
DB-Nickname
X-NewRelic-App-Data
Retry-After
X-Webkit-CSP
X-Nginx-Cache-Key
X-Dc
X-Cached-By
OT-Force-Account-Verify
X-TT-LOGID
X-Azure-Ref-OriginShield
Source
X-Bc-Bl
X-Cache-Remote
X-Unique-Id
Cache
X-Akamai-Transformed
SRV
X-Platform-Server
X-Auto-Login
X-Xfnlog-Site
X-LAGOON
X-EC-Lua
X-App-Version
HostName
ServedBy
X-GEO
X-SRV
X-Cache-Tags
Upgrade-Insecure-Requests
X-Origin-TTL
X-Origin-CC
X-ECache
Cache-Hits
X-Varnish-Hits
X-Loop
From-Origin
X-Cdn
X-TNCMS
X-Varnish-Hostname
X-Varnish-Cache-Hits
X-HTML-Minification-Powered-By
X-CSRF-Token
X-Request-Time
Onion-Location
Xet-Cookie
X-S-Maxage
Mime-Version
X-AOL-HN
Webserver
X-NWS-UUID-VERIFY
WP-Super-Cache
X-Request-Host
X-Tumblr-Pixel-3
X-Time
X-Amz-Meta-S3cmd-Attrs
Web-Mar-Node
X-Tumblr-Pixel-2
N-Cache
X-Proto
X-Cache-Enabled
X-B3-SpanId
X-FireWall-Port
X-Endurance-Cache-Level
X-Handled-By
X-Tenant
AMP-Access-Control-Allow-Source-Origin
X-AWS-Id
X-VWS-Id
X-LJ-Flow-ID
X-Time-Microsecs
X-GG-Cache-Date
X-Origin-Response-Time
X-CF-Lambda-Version
X-Rojux
X-Processor
BehaviorPad-Version
X-S-Cookie
X-A-Wwc
X-Ckpd-Fst-Backend
X-A-Dgt
X-Magnolia-Registration
Nel
Fastcgi-X-Cache-Version
X-Planisys-CDN-Cache
X-SRCache-Key
X-B-Cookie
A
X-Planisys-CDN-Rules
X-Aed
X-Planisys-CDN-TTL
X-Adobe-Source
X-S
X-Block-Status
X-Cluster
DCR-Decision-By
X-Shop-Environment
X-Aicache-OS
DCR-Processing-Time-Ms
X-Slack-Backend
X-Backend-TTL
Expiry
X-SD-PageType
X-ARC
X-ScT
X-Session-Fingerprint
X-RCS-CacheZone
X-Cache-NE
X-Reqid
X-Application
X-CF-Lambda-Fn
X-Destination
Vix-Hermes-Req-Id
X-External-Request-Id
X-Forwarded-Path
V-Age
X-Orig-Expires
X-TIM-N
Xc-Version
Mobile-Detection-Method
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
X-Epic-Correlation-Id
X-Ftr-Request-Id
X-Edge-Location
X-ND-Cache
Surrogated-Key
X-Hnp-Log
Sslversion
X-NAPM-TraceId
Rendered-Blocks
User-Cache-Control
X-Gen-Mode
Pramga
Redirect-Candidate
Meta-Geo-Continent
Odigeo-Trace-Id
X-A
X-A-Dam
X-PBS-Appsvrname
X-Developer
X-PAYTM-SRV-ID
X-A-Ccd
X-V-Cache
X-A-Dcw
X-Connection-Hash
X-Ig-Push-State
X-D
X-VG-WebCache
X-Correlation-ID
X-Vdms-Version
X-Vdms-Path
X-Conf
X-MP-GENERATED-AT
X-Mg-Request-UUID
CDCHOST
X-Proxy-Upstream
X-Li-Pop
CacheControlHeader
X-Accel-Expires-Debug
Svr
Arc-Country
Apple-News-Services-Request-Url
Gh-Request-Id
X-Mvc-Supplant-Cachable
X-Nyt-Route
X-NodeID
True-Client-Country-4JS
X-Old-Content-Length
X-Origin-Time
X-Policy
X-Origin-Expires
Wxu-Next-Region
X-Location
DSUID
Wxu-Next-Hostname
X-Origin
Origin
Cmstype
Cmsid
X-Men
Wxu-Next-Commit
Fastcgi-Cache-TTL
Apple-News-Services-Parsed-Url
Host-ID
X-LI-UUID
X-SVT-ORM-RULES
X-PHP-Host
X-Webstats-RespID
X-Labrador-Cache-Channel
X-Fastly-Cache
X-Viewer-Country
X-VG-TLSProxy
X-Sucuri-ID
State
X-SVT-ORM-VERSION
Apple-News-Services-Host
X-Forwarded-Site
X-Gdpr
X-GeoIP-Country-Code
X-GeoIP-Region-Code
CloudFront-Viewer-Country
X-Hash
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Cache-Var-Map
X-Cache-Var
X-Geo-Header
X-Sucuri-Cache
X-Date
X-Scheme
X-Server-IP
X-Request-URI
S-Rt
X-Cache-Date
X-Rocket-Nginx-Serving-Static
X-Cdn-Srv
AKAMAI
Apple-News-Services-Handled
X-Li-Fabric
X-Cache-Bucket
X-Cache-Info
Server-Info
Environment
X-Gamma-Serve
X-HS-Content-Campaign-Id
X-Fetched-On
X-Level-Front-Cache
X-GeoIP-City
X-Backend-State
X-Gzip
Traceparent
X-GeoIP
X-Branch-Name
X-BBC-Edge-Cache-Status
X-Generated-On
X-Esi-Check
X-Csrf-Jwt
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
X-Core-Value
X-Core-Mission
X-Cdn-Origin
X-CGP
X-Irp-Debug
X-Datadog-Trace-Id
X-Cache-Id
X-Locale
X-Envoy-Decorator-Operation
X-Eu-Site
We-Hiring
Web-Mar-Region
X-Developers
X-Device-Os
X-Cache-Debug
X-Fastly-Backend
X-Region-Sid
X-Req
X-HN
X-Rocket-Build-Number
X-Served-From
X-Sigma
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
HA-Ipaddr
Ha-Gx-Prefs
Fastly-GeoIP-CountryCode
X-Platform
X-Sigma-Backend
X-Skip-Cache
X-VarnishDD-TTL
X-VServer
X-Akamai-Request-ID2
X-Http-Reason
X-Varnish-Beresp-Status
X-UnsetCookies
Ssr
X-Storefront-Renderer-Rendered
X-TH-Server
X-TrackingId
L
X-Sn-Servicetimems
PFcat
X-Owner
Origin-EX
Mail-Subject
Origin-CC
Req-Svc-Chain
Release
L5d-Success-Class
Locid
Server-Host
Machine
X-Via-NSCOPI
X-Varnish-Beresp-Ttl
Thinkindot-CacheControl-Type
Is-Eu
X-Is-Gdpr
X-NU-AKA-ACS-Version
X-Variation
X-Thinkindot-L3
X-DefHash
X-Worker
TDXMobile
Magicmarker
X-FC-Vary-Parameters
X-Has-Esi
X-DPWN-IS-SECURE
X-Node-Id
X-JWT-State
X-DefElseHash
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
Thinkindot-CacheControl
Thinkindot-Control
Cf-Device-Type
X-Pod-Name
X-Amzn-Remapped-Content-Length
NM-Fastcgi-Cache
X-Rebelmouse-Surrogate-Control
X-ATG-Version
Adler-Geo
X-Rebelmouse-Cache-Control
Memcached
X-Qloud-Router
Platform
Fastly-Drupal-Html
Fastly-SIE
X-Loc
X-Response-By
Fastly-SWR
X-VC-Cache
X-CS
X-Xrds-Location
X-Restarts
NGX
X-Request-Start
X-Datadome
X-M-Reqid
X-M-Log
X-Qnm-Cache
X-Ua-Device
X-TraceId
Kp-EeAlive
X-NC
X-LB-ID
X-Thanos
X-API-Version
X-Up
X-Bip
X-Zone
X-Tx-Id
X-DSS
Edge-Cache
X-RPM
X-RSL
X-DI
X-RPS
X-DW
X-DB
CDN
X-Wix-Viewer-Type
X-Mvc-Supplant-OutputCached
X-Action
X-Cache-Backend
X-Generated-In
Accept-Language
X-CACHE-KEY
X-LB-NoCache
X-Cache-Config
Time
X-Trace-ID
Memory
Ms-Author-Via
Pics-Label
X-Tb-Optimization-Total-Bytes-Saved
X-CacheTTL
Env
X-Edge-Pop
X-Via-Poph
X-Minions-Version
X-Optimistic-Header
X-Via-Popn
X-Refresh
X-Via-Popv
X-Srv
WebServer
X-HA-Backend
GeoIp-Country-Code
X-Varnish-Ttl
X-Tt-Logid
Locale
X-Urbn-Site-Id
X-Urbn-Context-Path
Datacenter
X-ZONE
Candidate-Md5Url
NtCoent-Length
X-DC
X-DynaTrace-JS-Agent
X-TX-ID
On-Server
Server-ID
X-TA-CDN-Provider
X-Vc
X-Ec-GeoHdr
WWW-Authenticate
X-Ec-Fail
X-User
X-Esi
X-Parent-Response-Time
Esi-Enabled
X-Unique-ID
X-MSEdge-Features
X-Servedbyhost
X-MSEdge-Flight
X-Varnish-Beresp-TTL
X-Dynatrace
X-CLOUD-TRACE-CONTEXT
X-Cs
X-Cache-PHP
X-AK-Request-ID
Cdnsip
Cdncip
X-Li-Proto
C-Via
X-Service
X-Newrelic-Synthetics
X-Cache-Ttl
X-App
Cluster
My-App
X-VCL-Version
X-WADP-Cache
Geoip-Latitude
X-Fmm-Version
X-FPC
X-Clara-WADP
Proxy-Connection
X-URL
Tracecode
X-Vcl-Version
Test
X-Var-Ttl
X-Webkit-Csp-Report-Only
X-CUA
X-LI-Proto
X-Fpc
DataCenter
Cf-Int-Pingora-Origin-Digest
X-Traceid
X-Pass-Why
Geo-Info
X-Render-Time
X-Cache-Status-Check
Fastly-Drupal-HTML
X-B3-Spanid
X-From
Lfy
T-Server
X-NODE
X-LiteSpeed-Cache-Control
X-Webkit-CSP-Report-Only
X-Fragments
Lang
X-VC
X-Mcache
Target-Params
Resin-Trace
Server-Id
M-TraceId
X-WP-CF-Super-Cache-Cache-Control
MIME-Version
X-ServedByHost
X-WP-CF-Super-Cache
X-CSRF-TOKEN
X-Provided-By
X-RAMCache
X-ID
X-Geo
X-Clientip
X-Ha-Backend
X-Cdn-Forward
Hostname
X-Info
X-Oss-Request-Id
X-Oss-Storage-Class
X-LiteSpeed-Tag
GeoIP-Country-Code
Permissions-Policy
X-Oss-Server-Time
Cache-Host
Hit
UCS
X-Proxy-Cache-Info
HIT
X-Httpd
X-AIR-PT
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
X-Dynatrace-Js-Agent
Section-Origin-Responded
X-Pad
Section-Io-Origin-Time-Seconds
S-Cnection
X-Edge-POP
WZWS-RAY
Section-Io-Id
Section-Io-Origin-Status
X-Via-PopN
X-Srcache-Fetch-Status
X-Srcache-Store-Status
X-Check-Cacheable
X-Via-PopV
Producers
ENV
X-Via-PopH
Servername
X-SB
X-Fastly-Backend-Reqs
Ohc-File-Size
X-Edge-Cache
FSS-Cache
X-NGINX-Cache
X-Api-Version
X-Udemy-Cache-App-Namespace
X-ElasticPress-Query
X-ServerName
X-Pool
X-HS-Status
X-Lb-Nocache
X-Platform-Cluster
X-Platform-Processor
X-Platform-Router
X-Ucs
X-BBC-Origin-Response-Status
X-Micro-Cache
ServerName
User-Agent
Fastly-Backend-Name
PICS-Label
Load-Balancing
X-Backend-Host
X-GoCache-CacheStatus
X-Acquia-Application-UUID
Uri
X-Acquia-Site
X-Scale
X-Release
X-Cache-CFC
X-Ec-Custom-Error
X-UP
X-Acquia-Purge-Tags
URI
X-Acquia-Application-Trace
X-TRACE-ID
Server-Hostname
MD5-Digest
Server-Ext
X-SIPLIST1
Server-Ttl
IsBot
X-Dispatcher-Number
Sever-Int
X-Cache-Expires
X-Swift-Error
Cneonction
EpKe-Alive
X-RateLimit-Reset
X-Cdn-Request-ID
Cteonnt-Length
Cdn
X-Lb-Id
X-Nc
X-BCube-Filmed-By
X-Fastly-Cache-Hits
X-APP
Tcn
X-Dw-Trace-Id
Path
X-Snapshot-Date
X-Via-Ucdn
X-Akamai-ERRuleID
X-Contensis-Viewer-Groups
Ohc-Cache-HIT
Shield-Pop
X-Cache-ASPX
Cf-Ipcountry
X-Akamai-ERPolicy
CF-Cached-On
X-Newrelic-App-Data
X-B3-ParentSpanId
X-Vcache
Vha6-Origin
Wpo-Cache-Status
Wpo-Cache-Message
X-Yottaa-OS
X-Air-Pt
Sid
X-Cache-Ngx
X-HostName
CPC-Cache
Ngx
X-Shopify-Generated-Cart-Token
X-Akamai-Pragma-Client-IP
VNS-Age
X-IN-APIGATEWAYSSL
Req-ID
X-Litespeed-Cache-Control
CountryCode
X-IN-APIGATEWAY
X-Sentry-ID
VNS-Cache
X-B3-Parentspanid
X-Amz-Meta-Cb-Modifiedtime
CPC-Age
X-UA
X-Apw-Access-Object
X-Apw-Access-Action
X-Varnish-Authentication
X-Te-Duration-Ms
X-Te-Count
X-Http-Count
X-Http-Duration-Ms
X-Apw-Hits
X-Last-Modified
X-Apw-Access-Token
X-Akamai-Request-ID
X-CacheKey
X-WA
X-Logging-Id
X-WA-Info
Cache-Key