Threat Level: green Handler on Duty: Johannes Ullrich

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-Cache-Status
Link
Accept-Ranges
CF-RAY
ETag
X-XSS-Protection
Expect-CT
Pragma
X-Powered-By
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
Alt-Svc
X-Served-By
X-Xss-Protection
X-Download-Options
X-Timer
X-Request-Id
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Cache-Status
X-Generator
X-Cacheable
Timing-Allow-Origin
X-Content-Security-Policy
X-Iinfo
Feature-Policy
Status
X-Envoy-Upstream-Service-Time
Content-Encoding
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
X-CDN
X-AspNetMvc-Version
P3p
X-Request-ID
Upgrade
X-Via
CF-Ray
X-Ws-Request-Id
Access-Control-Max-Age
Server-Timing
EagleId
X-Cache-Group
X-Turbo-Charged-By
Keep-Alive
Request-Context
X-UA-Device
Report-To
X-Age
X-Proxy-Cache
X-Server-Powered-By
X-Backend
X-AH-Environment
X-Robots-Tag
X-Hacker
X-Amz-Request-Id
X-Server
Host-Header
X-Amz-Id-2
Grace
X-LiteSpeed-Cache
X-Rq
X-Nginx-Cache-Status
X-Varnish-Cache
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-WebKit-CSP
X-Page-Speed
X-Vhost
NEL
EagleEye-TraceId
X-OneAgent-JS-Injection
X-Amz-Version-Id
X-Ua-Compatible
X-Pingback
X-Dns-Prefetch-Control
X-Dispatcher
X-Device
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Cache-Spec
X-Host
X-Server-Id
Accept-CH
Cf-Railgun
X-Node
X-Backend-Server
X-Readtime
Surrogate-Control
X-Akam-SW-Version
Request-Id
X-Response-Time
X-HW
Xkey
X-Application-Context
Content-Location
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Rating
X-Ruxit-JS-Agent
X-Country
X-B3-TraceId
Accept-Ch-Lifetime
Accept-CH-Lifetime
X-Cache-Lookup
X-Cloud-Trace-Context
X-Trace
X-Url
X-Ac
X-Content-Type
X-TtlSet
Allow
X-Vname
X-PC
X-Varnish-TTL
X-Clacks-Overhead
X-Mod-Pagespeed
Edge-Control
X-Server-Name
X-ESI
Fastly-Restarts
X-Aws-Lambda-Call-Status
Cache-Tag
X-FastCGI-Cache
Service-Worker-Allowed
X-VARITI-CCR
X-Rack-Cache
X-Element-Page-Cache
Verso
X-Upstream
MS-Author-Via
X-Vcap-Request-Id
X-MS-InvokeApp
X-GitHub-Request-Id
X-Amz-Rid
Public-Key-Pins
X-Dw-Request-Base-Id
X-Cached
X-Client-IP
X-D2id
X-Cache-TTL
X-Abt-Application-Version
X-Cnection
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
X-Px
RTSS
X-Navigation-Version
X-Country-Code
Arr-Disable-Session-Affinity
Access-Control-Request-Method
X-Cdn-Fetch
X-Exp-Variant
X-Kinja-Server
X-Kinja-Revision
X-Kinja
X-Kinja-Build
X-GoogleNews-Bot
X-Use-Magma
X-Exp-Id
X-Powered-By-Plesk
X-NF-Request-ID
X-Goog-Hash
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Instrumentation
X-Origin-Cache
X-Powered-CMS
AR-SID
AR-Request-ID
AR-PoweredBy
AR-CACHE
AR-ATIME
X-Middleton-Display
X-Version
Pagespeed
X-Sol
Display
X-Middleton-Response
Response
X-Amz-Server-Side-Encryption
X-LLID
X-MSEdge-Ref
X-Kinsta-Cache
X-Edge-Location-Klb
X-SRCache-Store-Status
Nginx-Cache
X-SRCache-Fetch-Status
Accept-Ch
X-Edge
X-TTL
X-RateLimit-Remaining
MRF-Tech
Mrf-Cache-Status
X-B3-TraceId-Primal
TCN
X-Protected-By
X-T
X-Jurisdiction
X-HP-Webp
X-HP-Trace-Id
X-Forwarded-For
X-Shield-Request-Id
X-Content-Security-Policy-Report-Only
X-Id
X-Mg-S
Content-MD5
S
Edge-Cache-Tag
X-Aspnetmvc-Version
X-CST
X-Language
Fastcgi-Cache
SPIisLatency
SPRequestDuration
X-Mid
Front-End-Https
Realpath
X-Recruiting
X-Request-Received
X-Request-Processing-Time
X-Ttl
Pinterest-Version
Pinterest-Generated-By
Filters
X-Pinterest-Rid
X-DynaTrace
Server-Node
X-MCACHE
X-Frontend
Server-Name
X-Ab
X-Ua-Browser
X-Content
X-Ser
X-HS-Cache-Config
X-HS-Content-Id
X-HS-Hub-Id
X-NWS-LOG-UUID
X-Ruxit-Js-Agent
X-HS-Combine-CSS
X-Yandex-Sdch-Disable
X-Correlation-Id
X-Cache-Key
SPRequestGuid
X-SharePointHealthScore
X-Ezoic-Cdn
X-Template
X-Hits
X-ECACHE
X-Parallel-Accel
Alternate-Protocol
X-Tt-Trace-Tag
X-Tt-Trace-Host
MicrosoftSharePointTeamServices
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
Cache-Tags
Fusion-Content-Id
Fusion-Template-Id
Fusion-Source
Fusion-Content-Source
Fusion-Deployment-Id
Fusion-Component-Id
X-Page-Id
Cleartype
Host
X-B3-Sampled
Charset
X-Git-Hash
X-Www-Served-By
X-Content-Options
X-Geo-Country
X-Debug-Info
X-DIS-Request-ID
X-Daa-Tunnel
X-Amzn-Trace-Id
X-Ratelimit-Limit
X-Fastly-Request-Id
X-Hostname
X-Content-Digest
X-Amz-Replication-Status
X-Varnish-Age
Filterid
X-XRDS-LOCATION
X-Activity-Id
X-Az
X-AppVersion
X-Accel-Expires
X-Upgrade-Enabled
X-FB-Debug
Cross-Origin-Opener-Policy
X-VCache
X-Grace
X-Forwarded-Proto
X-N
X-WebKit-CSP-Report-Only
X-Origin-Server
ServerID
X-Rid
X-F-Cache
Access-Control-Allow-Method
X-Nginx-Upstream-Cache-Status
TP-Cache
TP-L2-Cache
X-Mobile-URL
X-Aspnet-Duration-Ms
X-LB-Cache
X-Flags
X-Is-Crawler
X-Route-Name
X-Providence-Cookie
X-Request-Guid
X-TT
X-Whom
Viewport
X-Seen-By
X-App-Environment
X-Varnish-Grace
X-Type
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Goog-Metageneration
X-GUploader-UploadID
X-Tb
X-Goog-Generation
X-Distributor
X-FW-Type
Node
X-FW-Dynamic
X-FW-Hash
X-FW-Server
X-FW-Static
Payment
X-FW-Serve
DC
X-Server-ID
Paypal-Debug-Id
X-User-Agent
X-App-Server
X-DataDome
Fastcgi-Useragent
Accept-Charset
X-Wix-Request-Id
Country
X-NGENIX-Cache
X-Cache-Control
X-Cache-Rule
X-Origin-Upstream-Status
X-Litespeed-Cache
X-Ratelimit-Reset
X-Fastcgi-Cache
Version
X-Request-Handler-Origin-Region
X-Logged-In
X-Microsite
X-Via-JSL
X-Drupal-Cache-Tags
X-Tec-Api-Version
X-Tec-Api-Root
Referer-Policy
X-Tec-Api-Origin
X-Fastly-Request-ID
X-Webkit-Csp
X-Cluster-Name
X-Cache-Age
X-Signature
X-B-Cache
X-Webkit-CSP
X-Contextid
Refresh
X-Erf-Bev-Bev-Is-Generated
X-Buckets
Cache-Status
X-Erf-Bev-Bev
X-Browser-Type
X-Varnish-Backend
X-Load-Cache
X-Original-Request-Id
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
SD-X-WS
X-Node-Name
X-Response-Served-From
Amp-Access-Control-Allow-Source-Origin
X-Page-View
X-Mobile
X-Vgn-Hpd-Reason
X-Cache-Expired-At
X-Real-IP
X-Rendered-As
X-Is-Bot
X-Proxy-Cache-Status
Access-Control-Request-Headers
X-Cacheable-TTL
X-Jobs
X-B
NGB
X-Debug
X-UUID
X-Revision
X-Rule
X-Device-Type
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Instance
X-IPLB-Instance
X-ProcessESI
X-RemovedCookies
X-Proxy
Surrogate-Key
X-Cache-Action
Akamai-GRN
X-Drupal-Cache-Contexts
X-Framework
X-Cache-Time
X-Debug-IsPreview
X-Debug-IsConnected
X-FW-Version
X-G
CF-IPCountry
X-Air-Trace-Id
SID
X-Air-Source
X-Air-Hostname
DynaTrace
X-Oracle-Dms-Rid
X-Azure-Ref
X-Oracle-Dms-Ecid
X-Accel-Buffering
X-Presslabs-Stats
GEO-INFO
Liferay-Portal
X-Nginx-Cache
X-Source
X-PressLabs-Stats
Count-Hit
X-Ms-Request-Id
X-Ms-Version
X-TEC-API-VERSION
X-Oneagent-Js-Injection
X-TEC-API-ORIGIN
X-TEC-API-ROOT
Uber-Trace-Id
X-Cache-Operation
X-Cache-NGX
X-APP-VERSION
Frame-Options
Healthy
X-RTag
Ms-Operation-Id
X-CDN-Forward
MS-CV
X-EdgeConnect-Cache-Status
X-Zen-Fury
X-XRDS-Location
X-Cache-Hit
Xserver
Countrycode
Protected
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-Mode
X-Environment-Context
X-L-Path
X-Tumblr-User
X-Backend-Name
X-Tumblr-Pixel
X-Varnish-Server
Cross-Origin-Window-Policy
Ec-Rule-Version
X-IPS-LoggedIn
X-Cache-TTL-Remaining
X-Region
X-Forwarded-Host
X-Servername
Backend
X-Detected-As
X-Adobe-Loc
X-Tid
X-SaId
X-RateLimit-Limit
X-Adobe-Content
X-Rewrite-Enabled
Meta-Geo
X-UPSTREAM-Address
X-JoinUs
X-RN-RSRV
X-Hyper-Cache
Apigw-Requestid
LB
X-Sorting-Hat-PodId
X-Shopify-Stage
X-Uri
Decoy-Debug-TTL
Eomportal-Instance
Decoy-Debug-Status
Decoy-Debug-Key
Country-Code
X-Sql-Duration-Ms
X-Sql-Count
X-Sorting-Hat-ShopId
X-Zipkin-Id
X-Content-Age
X-Cache-Grace
X-Alternate-Cache-Key
Section-Io-Cache
X-Proxied
X-Generation-Time
X-Debug-Cache
X-Extlb
X-Redis-Cache
X-Content-Powered-By
X-Routing-Service
X-Ratelimit-Remaining
X-Hosted-By
X-ShopId
X-ShardId
X-Cache-Server
Mn-Server-Ip
X-Origin-Date
X-Human
X-No-Session
X-Varnish-Beresp-Grace
X-NCache
Fastly-SSL
X-FB-TRIP-ID
Url
X-Status
X-Via-Fastly
X-Site-Version
X-ApacheServer
Cache-Name
X-ServerID
X-Format
X-PHP-Backend
X-PERF
X-NYM-Debug-Backend
X-Origin-Hint
X-Proxy-Build
Cache-Tv-Group
X-ProxyCache-Status
X-Pubstack
X-ProxyCache-Key
TWC-GeoIP-Country
Webcakes-Region
X-Server-W
Webcakes-App-Version
X-Akamai-Edgescape
X-Cluster-Node
X-Cache-Host
X-Cache-Type
Webcakes-App-Name
TWC-Privacy
TWC-Connection-Speed
Selected-Fe
TWC-Device-Class
X-BYPASS-REASON
TWC-Locale-Group
TWC-GeoIP-LatLong
Property-Id
Content-Disposition
X-Microcachable
X-Access
X-UA-Device-Type
X-OCL
X-Storage
X-Section
X-NewRelic-App-Data
X-Timing-Wait
X-PCL
CDN-Cache
X-Web-Node
CDN-Uid
X-R9-Blue-Green-Version
X-Hl-Ver
CDN-CachedAt
CDN-RequestCountryCode
CDN-PullZone
CDN-RequestId
CDN-EdgeStorageId
X-Trace-Id
X-Varnishpool
X-Say-Cacheable
X-Say-TTL
X-SayCDN-TTL
X-Generated-By
X-Soup
X-TIME
X-Azure-Ref-OriginShield
X-Be
Azure-Version
Azure-SiteName
Content-Secure-Policy
Azure-SlotName
Azure-InstanceId
Azure-RegionName
X-Ua
DB-Nickname
X-LSADC-Cache
WPO-Cache-Status
WPO-Cache-Message
OT-Force-Account-Verify
X-Nginx-Cache-Key
X-Dc
Retry-After
X-Cached-By
SRV
Source
X-Bc-Bl
X-Unique-Id
Cache
X-TT-LOGID
X-LAGOON
X-Platform-Server
X-Auto-Login
X-Cache-Remote
X-Xfnlog-Site
X-Varnish-Hits
HostName
X-Akamai-Transformed
Cache-Hits
X-GEO
X-SRV
X-HTML-Minification-Powered-By
X-Loop
X-Cache-Tags
X-Origin-CC
X-Origin-TTL
ServedBy
X-TNCMS
X-ECache
X-Varnish-Hostname
X-CSRF-Token
Onion-Location
Mime-Version
X-S-Maxage
X-App-Version
X-Cdn
X-Varnish-Cache-Hits
X-Correlation-ID
Upgrade-Insecure-Requests
From-Origin
X-Request-Time
Xet-Cookie
X-CLOUD-TRACE-CONTEXT
X-Amz-Meta-S3cmd-Attrs
X-Tumblr-Pixel-2
X-Tumblr-Pixel-3
X-AOL-HN
Web-Mar-Node
Webserver
X-Request-Host
X-EC-Lua
X-Proto
X-Time
WP-Super-Cache
N-Cache
X-Endurance-Cache-Level
X-Tenant
X-NWS-UUID-VERIFY
X-FireWall-Port
X-Cache-Enabled
X-VWS-Id
X-LJ-Flow-ID
X-AWS-Id
X-Time-Microsecs
X-Handled-By
X-GG-Cache-Date
X-Edge-Location
X-Cache-Var
X-Origin-Response-Time
X-Cache-Var-Map
X-B3-SpanId
X-Aed
X-A-Wwc
X-A-Dgt
X-Aicache-OS
DCR-Decision-By
X-Application
X-B-Cookie
X-Block-Status
A
X-ARC
X-Cache-NE
X-A-Dcw
BehaviorPad-Version
X-A
Mobile-Detection-Method
Odigeo-Trace-Id
Pramga
Meta-Geo-Continent
Fastcgi-X-Cache-Version
DCR-Processing-Time-Ms
Expiry
Redirect-Candidate
X-CF-Lambda-Fn
V-Age
Vix-Hermes-Req-Id
X-A-Ccd
User-Cache-Control
Surrogated-Key
Rendered-Blocks
Sslversion
X-A-Dam
X-Destination
X-SD-PageType
X-Session-Fingerprint
X-Shop-Environment
X-ScT
X-S-Cookie
X-Processor
X-Rojux
X-S
X-Slack-Backend
X-SRCache-Key
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
Xc-Version
X-VG-WebCache
X-Vdms-Version
X-TIM-N
X-V-Cache
X-Vdms-Path
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
Nel
X-Developer
X-External-Request-Id
X-D
X-Connection-Hash
X-Ckpd-Fst-Backend
X-Cluster
X-Conf
X-Forwarded-Path
X-Gen-Mode
X-PAYTM-SRV-ID
X-PBS-Appsvrname
X-Planisys-CDN-Cache
X-Orig-Expires
X-ND-Cache
X-Hnp-Log
X-Ig-Push-State
X-NAPM-TraceId
X-CF-Lambda-Version
X-Ftr-Request-Id
X-Via-NSCOPI
X-Mg-Request-UUID
X-Magnolia-Registration
X-Amzn-RequestId
X-RCS-CacheZone
X-Amz-Apigw-Id
X-Reqid
X-PHP-Host
CloudFront-Viewer-Country
X-Adobe-Source
X-Labrador-Cache-Channel
X-MP-GENERATED-AT
X-Sucuri-Cache
X-Sucuri-ID
X-Fastly-Cache
X-SVT-ORM-RULES
Cmsid
X-Policy
X-Forwarded-Site
X-LI-UUID
Wxu-Next-Region
Fastcgi-Cache-TTL
X-SVT-ORM-VERSION
Wxu-Next-Hostname
DSUID
Gh-Request-Id
Svr
X-Date
Origin
State
X-Scheme
X-Request-URI
X-Server-IP
X-Li-Pop
CDCHOST
X-Proxy-Upstream
Host-ID
True-Client-Country-4JS
X-Li-Fabric
X-Cache-Date
Wxu-Next-Commit
Cmstype
X-Cdn-Srv
X-Backend-TTL
X-Old-Content-Length
X-NodeID
X-Men
X-Viewer-Country
X-Epic-Correlation-Id
X-Origin-Time
X-Origin-Expires
X-Webstats-RespID
X-Hash
X-Geo-Header
X-Mvc-Supplant-Cachable
AKAMAI
X-Location
X-Cache-Bucket
CacheControlHeader
X-Gdpr
Arc-Country
X-Accel-Expires-Debug
X-Nyt-Route
Environment
X-Req
X-Cache-Debug
Server-Host
X-Branch-Name
X-Backend-State
X-Cache-Id
Ssr
X-Locale
X-Irp-Debug
X-Request-Start
X-RateLimit-Remaining-Second
X-Rocket-Nginx-Serving-Static
X-CGP
X-VG-TLSProxy
X-Core-Mission
X-Origin
X-Core-Value
X-Platform
AMP-Access-Control-Allow-Source-Origin
Web-Mar-Region
We-Hiring
X-Datadog-Sampling-Priority
X-Region-Sid
X-Datadog-Trace-Id
X-Datadog-Parent-Id
X-Cdn-Origin
X-Csrf-Jwt
X-RateLimit-Limit-Second
Traceparent
X-Skip-Cache
X-Varnish-Beresp-Status
X-Generated-On
Fastly-Drupal-Html
Server-Info
X-Gamma-Serve
X-Level-Front-Cache
X-TH-Server
Release
X-TrackingId
X-UnsetCookies
X-VarnishDD-TTL
X-GeoIP
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
X-HS-Content-Campaign-Id
Apple-News-Services-Handled
X-HN
X-GeoIP-City
X-VServer
X-Gzip
X-Cache-Info
X-Storefront-Renderer-Rendered
X-Fetched-On
X-Served-From
X-GeoIP-Country-Code
X-Fastly-Backend
Mail-Subject
X-GeoIP-Region-Code
Origin-CC
X-Developers
X-Device-Os
PFcat
Origin-EX
Machine
X-Envoy-Decorator-Operation
L
X-Esi-Check
Ha-Gx-Prefs
HA-Ipaddr
X-Sn-Servicetimems
Locid
X-Eu-Site
L5d-Success-Class
S-Rt
X-VC-Cache
X-Is-Gdpr
X-FC-Vary-Parameters
X-DefElseHash
X-DPWN-IS-SECURE
X-JWT-State
X-Node-Id
Req-Svc-Chain
X-DefHash
X-Has-Esi
X-NU-AKA-ACS-Version
Thinkindot-Control
Fastly-SWR
Fastly-SIE
X-Thinkindot-L3
Cf-Device-Type
Is-Eu
Memcached
Thinkindot-CacheControl
TDXMobile
X-Response-By
Platform
X-Variation
Adler-Geo
X-M-Reqid
X-BBC-Edge-Cache-Status
X-Worker
Fastly-GeoIP-CountryCode
X-Qnm-Cache
X-M-Log
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
Thinkindot-CacheControl-Type
NM-Fastcgi-Cache
X-Rocket-Build-Number
X-Pod-Name
X-Amzn-Remapped-Content-Length
X-Sigma-Backend
X-ATG-Version
X-Owner
X-Qloud-Router
X-Sigma
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-Xrds-Location
Magicmarker
X-Tx-Id
NGX
X-Mvc-Supplant-OutputCached
X-Zone
X-Loc
X-Http-Reason
X-Bip
X-Akamai-Request-ID2
X-Thanos
X-Varnish-Beresp-Ttl
X-Ua-Device
X-TraceId
X-LB-ID
X-API-Version
X-CS
X-NC
X-Restarts
Pics-Label
X-Cache-Config
Kp-EeAlive
X-Up
X-Generated-In
CDN
X-LB-NoCache
X-Action
X-RPS
X-DSS
X-RPM
X-DI
X-RSL
X-DB
X-Cache-Backend
Edge-Cache
X-DW
X-CACHE-KEY
Memory
Ms-Author-Via
X-Trace-ID
Time
X-Wix-Viewer-Type
X-Tb-Optimization-Total-Bytes-Saved
X-Tt-Logid
X-Optimistic-Header
X-Edge-Pop
X-Refresh
Accept-Language
Env
X-Srv
X-Via-Popv
X-Via-Poph
GeoIp-Country-Code
Datacenter
Candidate-Md5Url
X-Minions-Version
NtCoent-Length
X-Via-Popn
X-CacheTTL
X-Varnish-Ttl
WebServer
X-Datadome
X-Vc
X-DynaTrace-JS-Agent
WWW-Authenticate
Locale
X-HA-Backend
On-Server
X-Urbn-Site-Id
X-DC
X-Urbn-Context-Path
X-ZONE
X-Varnish-Beresp-TTL
X-MSEdge-Features
X-MSEdge-Flight
X-Esi
X-Servedbyhost
X-Cs
Esi-Enabled
X-Parent-Response-Time
X-Unique-ID
X-Ec-Fail
X-TX-ID
Server-ID
X-Ec-GeoHdr
X-User
X-Service
C-Via
X-TA-CDN-Provider
X-Newrelic-Synthetics
X-Cache-PHP
X-Li-Proto
X-Cache-Ttl
X-B3-Spanid
Cdnsip
X-App
Cdncip
X-AK-Request-ID
X-FPC
X-VCL-Version
X-Dynatrace
X-URL
X-Vcl-Version
X-Render-Time
X-Webkit-Csp-Report-Only
X-LI-Proto
X-Cache-Status-Check
Geoip-Latitude
X-Clara-WADP
Test
X-Fpc
My-App
X-Fmm-Version
Cluster
X-WADP-Cache
X-Traceid
X-LiteSpeed-Cache-Control
Tracecode
Geo-Info
X-Var-Ttl
X-CUA
X-Webkit-CSP-Report-Only
X-Pass-Why
X-NODE
Proxy-Connection
X-From
Server-Id
Lfy
DataCenter
Cf-Int-Pingora-Origin-Digest
T-Server
X-Mcache
Fastly-Drupal-HTML
M-TraceId
Resin-Trace
Lang
X-Fragments
X-Clientip
X-Ha-Backend
X-LiteSpeed-Tag
Target-Params
X-AIR-PT
X-Info
X-CSRF-TOKEN
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
X-Oss-Request-Id
Cache-Host
X-VC
X-Oss-Server-Time
HIT
X-ID
X-Oss-Storage-Class
X-Geo
X-ServedByHost
UCS
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
Hostname
MIME-Version
X-Via-PopN
X-Pad
X-Via-PopV
Hit
X-RAMCache
X-Via-PopH
GeoIP-Country-Code
S-Cnection
X-Provided-By
X-Dynatrace-Js-Agent
Ohc-File-Size
Section-Io-Id
X-Edge-POP
X-Cdn-Forward
X-Proxy-Cache-Info
Section-Origin-Responded
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
Permissions-Policy
X-Httpd
Tcn
ENV
Fastly-Backend-Name
X-Check-Cacheable
X-Edge-Cache
X-Api-Version
Servername
Producers
WZWS-RAY
User-Agent
Load-Balancing
X-ElasticPress-Query
X-HS-Status
X-NGINX-Cache
X-Micro-Cache
X-UP
FSS-Cache
X-Release
X-Fastly-Backend-Reqs
X-Ucs
X-SB
X-ServerName
X-BBC-Origin-Response-Status
X-Backend-Host
X-Cache-CFC
X-HostName
X-GoCache-CacheStatus
X-Acquia-Site
ServerName
X-Udemy-Cache-App-Namespace
X-Pool
X-Acquia-Application-Trace
X-Acquia-Application-UUID
X-Acquia-Purge-Tags
X-BCube-Filmed-By
URI
PICS-Label
X-Lb-Nocache
Uri
X-APP
Wpo-Cache-Status
Wpo-Cache-Message
X-Platform-Router
X-Platform-Cluster
X-Platform-Processor
X-TRACE-ID
Ohc-Cache-HIT
X-Swift-Error
Server-Ttl
EpKe-Alive
X-RateLimit-Reset
Cdn
X-Nc
X-Ec-Custom-Error
X-Cdn-Request-ID
X-Fastly-Cache-Hits
X-Scale
X-Lb-Id
Cteonnt-Length
Cneonction
X-Dw-Trace-Id
X-Cache-Expires
X-B3-Parentspanid
X-Dispatcher-Number
X-IN-APIGATEWAYSSL
X-SIPLIST1
Sever-Int
X-IN-APIGATEWAY
MD5-Digest
X-Akamai-ERPolicy
X-Akamai-ERRuleID
Path
IsBot
Server-Ext
Server-Hostname
CPC-Age
VNS-Age
Vha6-Origin
VNS-Cache
X-Snapshot-Date
X-WA-Info
Shield-Pop
X-Cache-ASPX
CF-Cached-On
X-Amz-Meta-Cb-Modifiedtime
X-Apw-Hits
X-Yottaa-OS
Cf-Ipcountry
X-Apw-Access-Token
X-Apw-Access-Object
X-Apw-Access-Action
X-B3-ParentSpanId
X-Newrelic-App-Data
X-Contensis-Viewer-Groups
Cache-Key
CPC-Cache
X-WA
X-Vcache
X-Litespeed-Cache-Control
X-Cache-Ngx
X-Air-Pt
Sid
Lb
X-Te-Duration-Ms
X-ES-SERVER
X-CacheKey
X-Http-Count
X-Logging-Id
X-Http-Duration-Ms
X-Te-Count
X-Akamai-Pragma-Client-IP
X-Varnish-Authentication
X-Sentry-ID
X-Last-Modified
X-Wikidot-Static-Cache
CountryCode
Req-ID
X-UA
Ngx
X-Wikidot-Backend
X-Akamai-Request-ID
X-Shopify-Generated-Cart-Token