Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
Link
CF-Cache-Status
Accept-Ranges
CF-RAY
ETag
Expect-CT
Pragma
X-Powered-By
X-XSS-Protection
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-UA-Compatible
X-Cache-Hits
Alt-Svc
P3P
X-Served-By
X-Xss-Protection
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Adblock-Key
X-Runtime
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Cache-Status
X-Generator
X-Cacheable
Timing-Allow-Origin
X-Request-ID
X-Content-Security-Policy
P3p
X-Iinfo
Status
Feature-Policy
X-Envoy-Upstream-Service-Time
Content-Encoding
Access-Control-Expose-Headers
X-CDN
X-AspNetMvc-Version
X-Drupal-Dynamic-Cache
Upgrade
X-Via
CF-Ray
Access-Control-Max-Age
X-Ws-Request-Id
Server-Timing
EagleId
Keep-Alive
X-Cache-Group
X-Turbo-Charged-By
Request-Context
X-Age
X-Proxy-Cache
X-Server-Powered-By
X-AH-Environment
X-Hacker
X-Backend
X-UA-Device
X-Robots-Tag
Report-To
X-Amz-Request-Id
X-LiteSpeed-Cache
Host-Header
X-Server
X-Amz-Id-2
Grace
X-Rq
X-Nginx-Cache-Status
X-Varnish-Cache
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-WebKit-CSP
X-Dns-Prefetch-Control
X-Page-Speed
X-Vhost
X-OneAgent-JS-Injection
X-Amz-Version-Id
EagleEye-TraceId
X-Device
X-Dispatcher
X-Pingback
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Cache-Spec
NEL
X-Server-Id
X-Host
X-Backend-Server
X-Node
Cf-Railgun
Accept-CH
X-Readtime
X-Akam-SW-Version
Surrogate-Control
Request-Id
X-Response-Time
X-HW
X-Language
Xkey
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Content-Location
X-Template
X-Application-Context
X-Ruxit-JS-Agent
Rating
X-Ua-Compatible
Accept-Ch-Lifetime
X-Country
X-B3-TraceId
Accept-CH-Lifetime
X-Cloud-Trace-Context
X-Cache-Lookup
X-Buckets
Allow
X-Ac
X-Url
X-Content-Type
X-Trace
X-Vname
X-TtlSet
X-PC
X-Mod-Pagespeed
X-Varnish-TTL
X-Clacks-Overhead
Edge-Control
X-FastCGI-Cache
X-ESI
Cache-Tag
Fastly-Restarts
X-Rack-Cache
Service-Worker-Allowed
X-VARITI-CCR
X-Element-Page-Cache
X-Server-Name
Verso
X-GitHub-Request-Id
X-MS-InvokeApp
X-Amz-Rid
X-Vcap-Request-Id
X-Upstream
MS-Author-Via
X-Dw-Request-Base-Id
Public-Key-Pins
X-D2id
X-Client-IP
X-Origin-Cache
X-Abt-Application-Version
X-Cached
X-Cache-TTL
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
Arr-Disable-Session-Affinity
X-Country-Code
X-Navigation-Version
X-Px
X-Powered-By-Plesk
X-Goog-Hash
X-Cnection
X-Version
X-NF-Request-ID
Access-Control-Request-Method
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Instrumentation
X-Amz-Server-Side-Encryption
X-Aws-Lambda-Call-Status
Accept-Ch
RTSS
X-Powered-CMS
Pagespeed
X-Middleton-Display
Display
X-Sol
X-SRCache-Store-Status
X-SRCache-Fetch-Status
Response
X-Middleton-Response
X-MSEdge-Ref
X-Use-Magma
X-Exp-Variant
X-Cdn-Fetch
X-Kinja-Server
X-Exp-Id
X-Kinja
X-Kinja-Revision
X-Kinja-Build
X-GoogleNews-Bot
X-CST
X-LLID
X-Edge
X-Edge-Location-Klb
X-Kinsta-Cache
Nginx-Cache
X-Shield-Request-Id
X-B3-TraceId-Primal
X-TTL
MRF-Tech
Mrf-Cache-Status
S
Content-MD5
X-Jurisdiction
X-HP-Webp
X-HP-Trace-Id
X-T
AR-ATIME
AR-SID
AR-PoweredBy
AR-CACHE
AR-Request-ID
X-Forwarded-For
X-Protected-By
X-Content-Security-Policy-Report-Only
TCN
X-Mg-S
X-RateLimit-Remaining
X-Id
X-Mid
Fastcgi-Cache
X-MCACHE
X-Aspnetmvc-Version
X-Parallel-Accel
Front-End-Https
Realpath
SPRequestDuration
SPIisLatency
X-Recruiting
Edge-Cache-Tag
X-Ttl
X-Request-Processing-Time
X-Request-Received
Filters
Pinterest-Generated-By
X-Pinterest-Rid
Pinterest-Version
Fusion-Content-Source
Server-Node
Fusion-Template-Id
Fusion-Deployment-Id
Fusion-Source
Fusion-Component-Id
Fusion-Content-Id
X-SharePointHealthScore
SPRequestGuid
X-Ab
X-Content
X-Ua-Browser
X-DynaTrace
X-Ezoic-Cdn
X-Correlation-Id
Alternate-Protocol
X-Accel-Expires
Server-Name
X-Ruxit-Js-Agent
X-ECACHE
X-HS-Content-Id
X-Frontend
X-HS-Cache-Config
X-HS-Combine-CSS
X-HS-Hub-Id
X-NWS-LOG-UUID
X-Hits
X-Cache-Key
X-Yandex-Sdch-Disable
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Content-Options
Cache-Tags
X-Git-Hash
X-Page-Id
Host
Cleartype
Charset
MicrosoftSharePointTeamServices
X-B3-Sampled
X-Www-Served-By
X-Geo-Country
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Content-Digest
X-Amz-Replication-Status
TP-L2-Cache
TP-Cache
Filterid
X-Forwarded-Proto
X-Ser
X-VCache
X-Varnish-Age
X-Hostname
X-Amzn-Trace-Id
X-Fastly-Request-Id
X-Activity-Id
X-AppVersion
X-Az
X-XRDS-LOCATION
X-Request-Handler-Origin-Region
X-Rid
X-Microsite
X-Daa-Tunnel
X-DIS-Request-ID
X-Upgrade-Enabled
X-Debug-Info
Access-Control-Allow-Method
X-Origin-Server
X-Grace
X-LB-Cache
X-N
X-FB-Debug
X-WebKit-CSP-Report-Only
ServerID
X-Origin-Upstream-Status
X-Nginx-Upstream-Cache-Status
X-Mobile-URL
X-Is-Crawler
X-Providence-Cookie
X-Route-Name
X-Flags
X-Request-Guid
X-Aspnet-Duration-Ms
X-Whom
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-NGENIX-Cache
X-Goog-Metageneration
X-GUploader-UploadID
X-TT
X-Goog-Generation
X-Goog-Stored-Content-Length
X-Varnish-Grace
X-App-Server
X-PressLabs-Stats
X-App-Environment
X-F-Cache
Viewport
X-Distributor
X-Logged-In
Payment
Cross-Origin-Opener-Policy
X-FW-Server
X-Cache-Control
X-Server-ID
X-FW-Type
Paypal-Debug-Id
X-FW-Hash
X-FW-Static
X-FW-Serve
DC
X-FW-Dynamic
Node
X-Tb
Fastcgi-Useragent
X-Seen-By
X-Cache-Age
X-Type
X-User-Agent
Country
Accept-Charset
X-Varnish-Backend
X-Cache-Rule
X-Node-Name
X-DataDome
X-Load-Cache
X-Browser-Type
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Fastly-Request-ID
X-Webkit-CSP
Version
X-Cache-Action
X-IPLB-Instance
Refresh
X-Wix-Request-Id
X-Via-JSL
Cache-Status
X-Original-Request-Id
SD-X-WS
Liferay-Portal
Access-Control-Request-Headers
X-Response-Served-From
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Cacheable-TTL
X-Jobs
X-Real-IP
Amp-Access-Control-Allow-Source-Origin
X-Proxy-Cache-Status
Referer-Policy
X-Drupal-Cache-Tags
X-Revision
X-Rendered-As
X-UUID
X-Debug
X-RemovedCookies
X-Vgn-Hpd-Reason
NGB
VIX-Pulpo-Upstream-Status
X-B
X-Cluster-Name
X-Contextid
X-Is-Bot
X-ProcessESI
VIX-Pulpo-Node
X-Page-View
X-Yottaa-Optimizations
X-Rule
X-Proxy
X-Device-Type
X-Yottaa-Metrics
X-Cache-Expired-At
X-Tec-Api-Version
Akamai-GRN
DynaTrace
X-Drupal-Cache-Contexts
X-Framework
X-G
Healthy
X-Azure-Ref
X-Tec-Api-Origin
X-Cache-Time
X-Tec-Api-Root
X-Mobile
X-Instance
X-Signature
X-B-Cache
X-Debug-IsConnected
X-Debug-IsPreview
Surrogate-Key
X-Source
X-FW-Version
CF-IPCountry
X-Fastcgi-Cache
X-Ratelimit-Limit
SID
X-Air-Source
X-Air-Hostname
X-Air-Trace-Id
X-Ms-Request-Id
X-Ms-Version
Frame-Options
X-Oracle-Dms-Ecid
X-XRDS-Location
X-Oracle-Dms-Rid
X-Cache-Hit
MS-CV
Ms-Operation-Id
X-RTag
X-APP-VERSION
Section-Io-Cache
X-Tumblr-Pixel-1
X-Tumblr-User
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-L-Path
X-Oneagent-Js-Injection
X-Nginx-Cache
X-Environment-Context
X-Varnish-Server
X-CDN-Forward
Xserver
Countrycode
X-Region
X-Servername
Count-Hit
X-Cache-Operation
X-Content-Powered-By
X-EdgeConnect-Cache-Status
X-Forwarded-Host
GEO-INFO
Uber-Trace-Id
X-RateLimit-Limit
X-Backend-Name
Backend
Cross-Origin-Window-Policy
X-IPS-LoggedIn
X-Litespeed-Cache
X-Mode
X-Adobe-Loc
X-Adobe-Content
X-Accel-Buffering
X-JoinUs
X-RN-RSRV
X-SaId
Meta-Geo
Ec-Rule-Version
X-Zen-Fury
X-UPSTREAM-Address
Eomportal-Instance
X-Sorting-Hat-PodId
X-ShardId
X-Human
X-Detected-As
X-Debug-Cache
X-Cache-Grace
X-Cache-Type
X-Varnish-Beresp-Grace
X-Sorting-Hat-ShopId
X-Generation-Time
X-Redis-Cache
X-Cache-Server
X-Hosted-By
X-ShopId
X-Shopify-Stage
X-Alternate-Cache-Key
X-FB-TRIP-ID
X-BYPASS-REASON
X-NCache
X-Origin-Date
X-PHP-Backend
Url
Decoy-Debug-TTL
Cache-Tv-Group
Country-Code
Decoy-Debug-Key
Decoy-Debug-Status
X-ProxyCache-Key
X-ProxyCache-Status
X-Via-Fastly
X-Uri
Apigw-Requestid
X-Microcachable
X-No-Session
X-Storage
X-Status
X-ServerID
X-Site-Version
X-Sql-Count
X-Sql-Duration-Ms
Cache-Name
X-Cache-TTL-Remaining
TWC-GeoIP-LatLong
TWC-GeoIP-Country
TWC-Locale-Group
TWC-Privacy
Webcakes-App-Name
TWC-Device-Class
TWC-Connection-Speed
Property-Id
Mn-Server-Ip
Protected
Selected-Fe
Source
Webcakes-App-Version
Webcakes-Region
X-Azure-Ref-OriginShield
X-SayCDN-TTL
X-Timing-Wait
X-UA-Device-Type
X-Web-Node
X-Say-TTL
X-Say-Cacheable
X-Akamai-Edgescape
X-Cache-Host
X-Origin-Hint
X-Proxy-Build
Fastly-SSL
X-Format
X-Proxied
X-Access
X-Varnishpool
X-PERF
Azure-Version
X-Hl-Ver
X-Extlb
X-Time
OT-Force-Account-Verify
X-Section
X-Routing-Service
X-R9-Blue-Green-Version
X-Pubstack
Azure-SlotName
X-Zipkin-Id
X-PCL
X-NYM-Debug-Backend
Azure-SiteName
X-OCL
X-ApacheServer
X-Server-W
Azure-RegionName
Azure-InstanceId
X-Be
X-LSADC-Cache
X-Cluster-Node
Content-Secure-Policy
X-Ua
X-HTML-Minification-Powered-By
X-Tid
X-Rewrite-Enabled
X-Cache-Var
X-SRV
X-Cache-Var-Map
X-Soup
SRV
X-Amz-Meta-S3cmd-Attrs
X-Cache-NGX
DB-Nickname
X-NewRelic-App-Data
X-Webkit-Csp
Content-Disposition
X-Content-Age
X-Ratelimit-Reset
X-Cached-By
Webserver
X-LAGOON
X-Loop
Retry-After
X-Varnish-Hostname
X-Varnish-Hits
X-TNCMS
X-Unique-Id
CDN-Cache
CDN-PullZone
CDN-Uid
Onion-Location
CDN-RequestCountryCode
CDN-RequestId
X-S-Maxage
X-TT-LOGID
Cache
X-Generated-By
CDN-CachedAt
CDN-EdgeStorageId
X-Dc
X-Bc-Bl
X-App-Version
X-Origin-TTL
X-Auto-Login
X-Hyper-Cache
X-Origin-CC
X-Tumblr-Pixel-2
X-Tumblr-Pixel-3
X-Proto
X-Presslabs-Stats
Web-Mar-Node
X-ECache
X-GEO
Cache-Hits
X-Qnm-Cache
X-Tenant
X-Time-Microsecs
X-Trace-Id
X-M-Reqid
X-M-Log
X-Nginx-Cache-Key
X-Endurance-Cache-Level
X-GG-Cache-Date
X-Edge-Location
X-Cdn
X-Akamai-Transformed
Xet-Cookie
X-LJ-Flow-ID
X-VWS-Id
X-AWS-Id
CloudFront-Viewer-Country
Mime-Version
X-Mg-Request-UUID
X-Amz-Apigw-Id
X-Labrador-Cache-Channel
X-CSRF-Token
X-Amzn-RequestId
X-PHP-Host
LB
X-Platform-Server
X-CACHE-KEY
N-Cache
X-Storefront-Renderer-Rendered
X-B3-SpanId
X-RCS-CacheZone
X-Xfnlog-Site
X-Locale
X-Handled-By
HostName
X-Cache-Tags
X-Adobe-Source
X-VC-Cache
Upgrade-Insecure-Requests
X-Origin-Response-Time
X-Varnish-Cache-Hits
X-Reqid
ServedBy
X-Request-Time
X-Planisys-CDN-Rules
Fastcgi-X-Cache-Version
X-Ftr-Request-Id
X-Application
X-A-Dam
X-A-Dcw
X-ARC
X-Processor
DCR-Processing-Time-Ms
DSUID
X-Planisys-CDN-TTL
X-B-Cookie
X-Forwarded-Path
X-External-Request-Id
Expiry
Meta-Geo-Continent
DCR-Decision-By
BehaviorPad-Version
X-AOL-HN
X-Cluster
Surrogated-Key
X-Ckpd-Fst-Backend
Rendered-Blocks
X-D
X-Conf
X-Planisys-CDN-Cache
X-Orig-Expires
X-PAYTM-SRV-ID
X-Connection-Hash
X-A-Wwc
X-PBS-Appsvrname
X-NAPM-TraceId
A
X-Cache-NE
Odigeo-Trace-Id
X-A-Ccd
X-Cache-Date
X-CF-Lambda-Version
X-Ig-Push-State
Mobile-Detection-Method
Origin
X-Developer
X-Aed
Redirect-Candidate
Pramga
X-A
X-CF-Lambda-Fn
X-Destination
X-A-Dgt
X-ATG-Version
X-ScT
X-SD-PageType
X-SRCache-Key
X-S-Cookie
X-S
X-SVT-ORM-VERSION
Nel
X-Vdms-Version
X-Session-Fingerprint
X-TIM-N
X-Slack-Backend
X-V-Cache
X-Shop-Environment
X-Vdms-Path
Server-Info
X-VG-WebCache
X-Rojux
X-Vtex-Remote-Cache
Xc-Version
X-Cache-Remote
From-Origin
X-SVT-ORM-RULES
X-Vtex-Processado-Em
X-Request-Host
X-Via-NSCOPI
X-MP-GENERATED-AT
X-Correlation-ID
Gh-Request-Id
Host-ID
CacheControlHeader
X-Gen-Mode
X-Hnp-Log
X-Forwarded-Site
Candidate-Md5Url
X-Hash
Datacenter
X-Fetched-On
WPO-Cache-Status
Fastcgi-Cache-TTL
WPO-Cache-Message
Cmsid
Cmstype
X-Geo-Header
X-Date
State
Wxu-Next-Region
Wxu-Next-Hostname
Wxu-Next-Commit
X-Accel-Expires-Debug
X-ND-Cache
X-Block-Status
X-Cache-Bucket
X-Cache-Info
X-VServer
Vix-Hermes-Req-Id
X-Varnish-Beresp-Status
X-Device-Os
X-Epic-Correlation-Id
X-Fastly-Cache
X-EC-Lua
Release
V-Age
User-Cache-Control
X-Core-Mission
L
X-Gdpr
X-Location
X-Mvc-Supplant-Cachable
X-Nyt-Route
X-Skip-Cache
X-LI-UUID
X-Li-Fabric
X-Li-Pop
X-Old-Content-Length
X-Origin-Time
X-Rocket-Nginx-Serving-Static
X-Policy
X-Proxy-Upstream
X-Scheme
X-Served-From
X-Owner
X-Server-IP
X-Sucuri-Cache
X-Origin-Expires
X-Sucuri-ID
AKAMAI
Environment
AMP-Access-Control-Allow-Source-Origin
X-TIME
X-Rocket-Build-Number
X-Core-Value
X-HN
Arc-Country
Apple-News-Services-Request-Url
True-Client-Country-4JS
CDCHOST
Thinkindot-Control
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
Server-Host
X-Datadog-Trace-Id
Apple-News-Services-Parsed-Url
Svr
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
TDXMobile
X-Viewer-Country
Web-Mar-Region
X-Cache-Id
X-Aicache-OS
X-Magnolia-Registration
X-Cache-Debug
X-VG-TLSProxy
X-Branch-Name
X-BBC-Edge-Cache-Status
X-Cache-Config
X-Cdn-Origin
X-Men
X-Bip
Apple-News-Services-Host
We-Hiring
X-Platform
X-Irp-Debug
X-HS-Content-Campaign-Id
X-Region-Sid
X-Req
X-Request-Start
X-VarnishDD-TTL
Machine
X-Thinkindot-L3
X-Thanos
Mail-Subject
X-Fastly-Backend
X-TrackingId
X-Sigma-Backend
X-Gamma-Serve
X-Sn-Servicetimems
Fastly-GeoIP-CountryCode
X-GeoIP
X-TH-Server
X-Level-Front-Cache
X-Generated-On
X-Gzip
X-GeoIP-City
X-Esi-Check
Locid
Apple-News-Services-Handled
PFcat
X-Sigma
X-Ratelimit-Remaining
Req-Svc-Chain
X-Developers
X-NodeID
X-Qloud-Router
X-NU-AKA-ACS-Version
X-DefHash
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-RateLimit-Limit-Second
X-Varnish-Remaining-TTL
X-RateLimit-Remaining-Second
Traceparent
Origin-EX
X-Rebelmouse-Cache-Control
Origin-CC
X-Origin
X-JWT-State
X-Has-Esi
X-DPWN-IS-SECURE
X-Variation
X-Eu-Site
X-Envoy-Decorator-Operation
X-UnsetCookies
X-Request-URI
X-Csrf-Jwt
X-DefElseHash
X-Loc
X-Worker
X-FC-Vary-Parameters
X-Is-Gdpr
X-Pod-Name
X-CGP
X-Rebelmouse-Surrogate-Control
Fastly-SIE
Memcached
L5d-Success-Class
NGX
Platform
X-Zone
Is-Eu
HA-Ipaddr
Adler-Geo
Cf-Device-Type
Fastly-SWR
Ha-Gx-Prefs
WWW-Authenticate
NM-Fastcgi-Cache
X-Amzn-Remapped-Content-Length
X-Backend-State
X-CS
X-Xrds-Location
On-Server
Esi-Enabled
X-Tx-Id
Fastly-Drupal-Html
X-Webstats-RespID
X-FireWall-Port
CDN
X-Varnish-Beresp-Ttl
X-API-Version
X-Node-Id
Sslversion
X-Up
X-NC
X-Mvc-Supplant-OutputCached
X-Cdn-Srv
X-Response-By
C-Via
X-Vc
X-LB-ID
X-Generated-In
Pics-Label
X-Service
Ssr
X-CLOUD-TRACE-CONTEXT
Ms-Author-Via
X-Trace-ID
WP-Super-Cache
X-Cache-PHP
Time
Memory
X-Datadome
X-Edge-Pop
X-Tt-Logid
X-Via-Popn
NtCoent-Length
X-Refresh
X-Via-Poph
X-Via-Popv
X-TA-CDN-Provider
X-DynaTrace-JS-Agent
X-DC
X-Cache-Status-Check
X-Cache-Enabled
X-Tb-Optimization-Total-Bytes-Saved
GeoIp-Country-Code
X-LB-NoCache
X-Backend-TTL
X-Varnish-Ttl
X-Dynatrace
X-GeoIP-Country-Code
X-GeoIP-Region-Code
Env
X-Render-Time
X-TraceId
X-Parent-Response-Time
X-Info
X-Optimistic-Header
Magicmarker
X-Varnish-Beresp-TTL
X-Esi
X-AIR-PT
X-Ua-Device
X-NWS-UUID-VERIFY
X-Restarts
X-Servedbyhost
Server-ID
X-CacheTTL
X-ZONE
X-Unique-ID
X-Clientip
Kp-EeAlive
X-TX-ID
X-Cs
X-Oss-Server-Time
X-Oss-Storage-Class
HIT
X-Oss-Request-Id
Cache-Host
X-Oss-Object-Type
UCS
X-Oss-Hash-Crc64ecma
Section-Io-Origin-Time-Seconds
S-Rt
Section-Io-Origin-Status
X-Srv
Section-Io-Id
Section-Origin-Responded
X-DSS
S-Cnection
Proxy-Connection
X-DI
X-DW
X-App
X-RPS
Edge-Cache
X-Cache-Backend
X-RSL
X-VCL-Version
X-RPM
X-Wix-Viewer-Type
X-MSEdge-Features
X-Newrelic-Synthetics
X-MSEdge-Flight
Lb
X-Action
X-DB
X-HA-Backend
X-Traceid
X-Fpc
X-Li-Proto
X-LI-Proto
X-Cache-Ttl
X-URL
Test
X-Micro-Cache
X-Minions-Version
WebServer
X-FPC
X-Webkit-Csp-Report-Only
User-Agent
Fastly-Backend-Name
X-LiteSpeed-Cache-Control
X-Pad
Server-Id
X-Vcl-Version
X-B3-Spanid
X-Backend-Host
X-Webkit-CSP-Report-Only
X-NODE
X-Pass-Why
Tcn
X-Release
X-ES-SERVER
X-BCube-Filmed-By
Geo-Info
X-Akamai-Request-ID2
X-Http-Reason
X-CSRF-TOKEN
X-BBC-Origin-Response-Status
Resin-Trace
Fastly-Drupal-HTML
X-Ec-GeoHdr
VNS-Cache
X-Amz-Meta-Cb-Modifiedtime
X-Ec-Fail
X-User
X-APP
X-LiteSpeed-Tag
Path
EpKe-Alive
CPC-Cache
Cache-Key
CPC-Age
VNS-Age
Hostname
Accept-Language
Cf-Int-Pingora-Origin-Digest
X-HostName
X-Dynatrace-Js-Agent
X-ServedByHost
X-WA-Info
X-ID
X-Akamai-Pragma-Client-IP
Locale
X-B3-Traceid
X-Urbn-Site-Id
X-Urbn-Context-Path
X-COUNTRY
Ohc-File-Size
X-Check-Cacheable
X-Cms-Context
GeoIP-Country-Code
X-WA
Hit
Pagetype
X-NGINX-Cache
Srv
X-Wikidot-Static-Cache
X-PJAX-URL
X-Wikidot-Backend
X-Geo
ENV
Cdnsip
X-Clara-WADP
X-Via-Ucdn
X-Via-PopN
M-TraceId
X-ElasticPress-Query
X-AK-Request-ID
X-Ha-Backend
X-Edge-POP
X-Fmm-Version
Cdncip
MIME-Version
X-WADP-Cache
X-Via-PopH
X-Via-PopV
X-Cdn-Forward
MD5-Digest
Shield-Pop
X-Edge-Cache
Cluster
X-HS-Status
My-App
URI
X-CCDN-CacheTTL
X-CCDN-Origin-Time
X-Hcs-Proxy-Type
Load-Balancing
X-VG-WebServer
X-Api-Version
Server-Ext
Server-Hostname
X-Fastly-Backend-Reqs
X-Cache-Expires
W
Sever-Int
X-Ucs
X-Kraken-Routeconfig-Destination
X-CUA
X-From
X-Var-Ttl
Tracecode
Lfy
Geoip-Latitude
X-ServerName
X-SIPLIST1
IsBot
X-Provided-By
X-Lb-Id
X-UP
X-GoCache-CacheStatus
T-Server
X-Mcache
X-TRACE-ID
X-Dw-Trace-Id
Vha6-Origin
PICS-Label
Cteonnt-Length
X-Acquia-Application-Trace
Cdn
Servername
X-VC
HitType
X-Fastly-Cache-Hits
X-Fragments
X-RateLimit-Reset
WZWS-RAY
X-Acquia-Application-UUID
X-Acquia-Purge-Tags
X-Platform-Cluster
X-Nc
X-Platform-Processor
X-Platform-Router
Lang
X-RAMCache
X-B3-ParentSpanId
Cneonction
X-Acquia-Site
X-Cdn-Request-ID
X-Via-CDN
Ohc-Cache-HIT
CountryCode
Cf-Ipcountry
X-Yottaa-OS
X-Swift-Error
X-Newrelic-App-Data
Target-Params
CF-Cached-On
X-Cache-ASPX
X-Akamai-Request-ID
Dnion-Transfer-Encoding
X-Snapshot-Date
X-Contensis-Viewer-Groups
X-Apw-Access-Object
X-Apw-Access-Action
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
X-Apw-Hits
X-Apw-Access-Token
X-Cc-Via
FSS-Cache
X-Air-Pt
X-Cache-Ngx
Sid
X-Last-Modified
X-Request-UUID
Uri
X-Varnish-Authentication
X-Akamai-ERRuleID
X-Akamai-ERPolicy
X-Te-Duration-Ms
X-Http-Duration-Ms
GeoIP-Latitude
X-Http-Count
X-Te-Count
X-IN-APIGATEWAY
PB-RID
X-CacheKey
X-77-NZT
Arc-Version
PB-PID
X-UA
Req-ID
X-Logging-Id
X-Wa
Ngx
X-Miniprofiler-Ids
X-IN-APIGATEWAYSSL
X-HTML-Edge-Cache
X-Sentry-ID
X-Edge-IP
X-Lb-Nocache
X-B3-Parentspanid