Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
X-Powered-By
Pragma
X-XSS-Protection
CF-RAY
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
Alt-Svc
P3P
X-Cache-Hits
X-UA-Compatible
X-Xss-Protection
X-Served-By
CF-Ray
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
Access-Control-Allow-Credentials
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
X-Drupal-Cache
X-Cache-Status
X-Generator
X-Check
X-Cacheable
X-Envoy-Upstream-Service-Time
X-FRAME-OPTIONS
Timing-Allow-Origin
X-Iinfo
X-Dns-Prefetch-Control
X-DNS-Prefetch-Control
Server-Timing
X-Drupal-Dynamic-Cache
Feature-Policy
X-Content-Security-Policy
Access-Control-Expose-Headers
Content-Encoding
X-CDN
Status
X-XSS-PROTECTION
Upgrade
X-Request-ID
X-AspNetMvc-Version
Access-Control-Max-Age
X-Amz-Request-Id
X-Via
X-Amz-Id-2
Request-Context
X-Ua-Compatible
X-Backend
X-Cache-Group
X-Turbo-Charged-By
X-Robots-Tag
Cf-Edge-Cache
Keep-Alive
Host-Header
X-AH-Environment
X-UA-Device
X-Vhost
X-Hacker
X-Proxy-Cache
X-Server
Allow
X-Rq
X-Server-Powered-By
X-Ws-Request-Id
X-Dispatcher
X-Age
EagleId
X-Varnish-Cache
X-Amz-Version-Id
P3p
Nel
Grace
X-LiteSpeed-Cache
Cf-Apo-Via
Cf-Railgun
X-OneAgent-JS-Injection
X-Page-Speed
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
EagleEye-TraceId
X-Device
X-Swift-CacheTime
X-Swift-SaveTime
X-Aws-Lambda-Call-Status
Ali-Swift-Global-Savetime
X-Pingback
X-Host
Accept-CH
X-Cache-Lookup
X-WebKit-CSP
X-CST
X-Node
X-Backend-Server
Surrogate-Control
Permissions-Policy
X-Readtime
X-Nginx-Upstream-Cache-Status
X-Nginx-Cache-Status
X-Akam-SW-Version
X-Server-Id
X-EdgeConnect-Origin-MEX-Latency
X-Application-Context
X-EdgeConnect-MidMile-RTT
Request-Id
Accept-CH-Lifetime
X-Ruxit-JS-Agent
Xkey
X-Cloud-Trace-Context
X-Content-Security-Policy-Report-Only
X-Response-Time
X-HW
X-Trace
X-Edge
Content-Location
X-Clacks-Overhead
X-Mod-Pagespeed
X-Url
Rating
X-ESI
X-Midtier
X-Amz-Server-Side-Encryption
X-ECACHE
Cache-Tag
X-Mcache
X-Country
Accept-Ch-Lifetime
X-Rack-Cache
X-MS-InvokeApp
X-Powered-By-Plesk
X-D2id
Service-Worker-Allowed
X-Exp-Variant
X-Cdn-Fetch
X-GoogleNews-Bot
X-Exp-Id
X-Kinja
X-Use-Magma
X-Kinja-Build
X-Kinja-Server
X-Kinja-Revision
Verso
X-Vcap-Request-Id
X-Upstream
X-Element-Page-Cache
Accept-Ch
Edge-Control
X-Litespeed-Cache
X-Country-Code
X-Ac
X-TtlSet
Origin-Trial
X-Vname
X-PC
RTSS
X-Goog-Hash
X-VARITI-CCR
X-Navigation-Version
X-Kinja-CCPA
X-Abt-Application-Version
X-Cache-TTL
X-Browser-Type
Fastly-Restarts
X-Amz-Rid
X-Varnish-TTL
X-NWS-LOG-UUID
X-Oneagent-Js-Injection
X-GitHub-Request-Id
Cross-Origin-Opener-Policy
X-Aspnetmvc-Version
X-Cached
X-Server-ID
X-Webkit-CSP
X-Server-Name
X-Dw-Request-Base-Id
X-Amzn-Trace-Id
X-Middleton-Display
Display
Pagespeed
X-Sol
X-Times
SPRequestGuid
X-WebKit-CSP-Report-Only
X-SharePointHealthScore
Pinterest-Version
Pinterest-Generated-By
X-Pinterest-Rid
SPIisLatency
X-Content-Type
SPRequestDuration
X-Cache-Key
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Erf-Bev-Bev
X-Instrumentation
X-Erf-Bev-Bev-Is-Generated
X-Ruxit-Js-Agent
AR-SID
AR-PoweredBy
AR-ATIME
X-Ttl
AR-Request-ID
X-Powered-CMS
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
X-B3-Traceid
Arr-Disable-Session-Affinity
X-Mg-S
X-Client-IP
X-Cnection
X-Version
X-Ser
Response
X-Middleton-Response
X-Jurisdiction
X-HP-Webp
Nginx-Cache
X-HP-Trace-Id
X-FastCGI-Cache
Cache-Tags
X-Accel-Expires
AR-CACHE
X-T
X-Fastly-Request-ID
X-SRCache-Fetch-Status
X-SRCache-Store-Status
Cache-Status
Edge-Cache-Tag
X-B3-TraceId
X-MSEdge-Ref
X-NF-Request-ID
Public-Key-Pins
X-Px
Front-End-Https
X-Recruiting
X-Hits
S
Payment
X-Daa-Tunnel
X-Shield-Request-Id
X-Frontend
X-RateLimit-Remaining
X-LLID
Server-Node
X-Request-Received
X-Ua-Browser
X-Request-Processing-Time
Mrf-Cache-Status
X-B3-TraceId-Primal
MRF-Tech
Content-MD5
X-GUploader-UploadID
X-Goog-Metageneration
X-Webkit-CSP-Report-Only
MicrosoftSharePointTeamServices
X-TTL
Access-Control-Request-Method
X-RateLimit-Limit
X-Content-Digest
X-DIS-Request-ID
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Ratelimit-Remaining
X-Forwarded-For
TP-Cache
Realpath
X-Protected-By
X-Request-Handler-Origin-Region
X-Microsite
X-Distributor
X-PressLabs-Stats
X-Fastcgi-Cache
X-FB-Debug
X-HS-Cache-Config
X-HS-Content-Id
X-HS-Combine-CSS
Fastcgi-Cache
X-HS-Hub-Id
Access-Control-Allow-Method
X-Xrds-Location
X-Page-Id
Accept-Charset
X-Cluster-Name
X-LB-Cache
X-Rid
Count-Hit
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-Goog-Generation
X-B3-Sampled
X-Hostname
X-Id
X-Edge-Location-Klb
X-Kinsta-Cache
X-Ratelimit-Limit
X-Geo-Country
X-Aspnet-Version
Cross-Origin-Resource-Policy
X-Ua-Device
TP-L2-Cache
X-Correlation-Id
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Seen-By
X-TEC-API-VERSION
X-App-Server
TCN
X-Logged-In
X-Varnish-Backend
X-Ezoic-Cdn
Cleartype
X-Git-Hash
X-Content-Options
X-Hosted-By
Referer-Policy
X-Erf-Stays-Pdp-Viaduct-Migration-Web
X-Mobile
Retry-After
DC
X-Newrelic-App-Data
X-Fb-Rlafr
X-Origin-Cache
X-Contextid
X-Flags
X-Providence-Cookie
X-Aspnet-Duration-Ms
X-Is-Crawler
X-Route-Name
X-Request-Guid
Surrogate-Key
X-F-Cache
X-Grace
X-Revision
X-App-Environment
X-Debug-Info
X-Forwarded-Proto
X-TT
X-Amz-Replication-Status
Frame-Options
X-Varnish-Grace
X-Amz-Meta-S3cmd-Attrs
X-IPS-LoggedIn
X-Envoy-Decorator-Operation
X-Azure-Ref
MS-Author-Via
X-Magnolia-Registration
Section-Io-Cache
X-Www-Served-By
X-Proxy-Cache-Info
X-Wix-Request-Id
Healthy
X-Whom
X-App-Version
X-Az
X-AppVersion
X-Activity-Id
X-Language
Charset
X-RateLimit-Reset
X-Akamai-Edgescape
X-Nf-Request-Id
X-COUNTRY
Alternate-Protocol
Filterid
X-Trace-Id
Amp-Access-Control-Allow-Source-Origin
WPO-Cache-Message
WPO-Cache-Status
X-Webkit-Csp
X-EdgeConnect-Cache-Status
Viewport
X-Backend-Name
Server-Name
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Varnish-Server
X-Origin-Server
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
X-Datadog-Trace-Id
X-B
X-Response-Served-From
X-Http-Reason
VIX-Pulpo-Node
Paypal-Debug-Id
Host
X-Cache-Rule
SRV
X-Original-Request-Id
VIX-Pulpo-Upstream-Status
X-Edge-Location
X-DataDome
X-Akamai-Request-ID2
X-Rule
Front
X-UUID
X-Page-View
X-Vcache
X-Region
X-L-Path
Protected
Country
X-User-Agent
SD-X-WS
X-Cache-Grace
X-ARC
X-Cacheable-TTL
X-Yottaa-Metrics
X-Environment-Context
X-Yottaa-Optimizations
X-Jobs
X-Unique-Id
X-Instance
X-N
From-Origin
X-Time
Content-Disposition
Fastly-SWR
X-B-Cache
X-Framework
X-Adobe-Loc
X-Adobe-Content
X-Varnish-Age
Fastly-SIE
X-Client-Ip
X-RemovedCookies
X-Signature
X-Status
X-ProcessESI
X-Load-Cache
Akamai-GRN
X-Rocket-Nginx-Serving-Static
X-Mg-Request-UUID
X-Type
X-Tumblr-Pixel
X-Proxy
X-Rendered-As
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-G
X-Tumblr-User
X-Is-Bot
X-Cache-Time
X-Datadog-Sampled
X-FW-Serve
X-FW-Dynamic
X-FW-Server
X-FW-Hash
X-FW-Version
X-FW-Type
X-FW-Static
X-Debug-IsConnected
X-Debug-IsPreview
X-Amzn-Remapped-Content-Length
Access-Control-Request-Headers
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
ServerID
X-CDN-Forward
Backend
X-ECache
X-Cache-Age
X-Tec-Api-Root
X-Tec-Api-Version
X-Nginx-Cache
X-Tec-Api-Origin
X-Cache-Control
X-Servername
Refresh
Countrycode
Xet-Cookie
Url
X-Httpd
X-DynaTrace
X-Tt-Trace-Tag
X-Tt-Trace-Host
Accept-Language
X-Erf-Web-Scheduler
CF-IPCountry
X-Template
X-Drupal-Cache-Tags
X-DynaTrace-JS-Agent
X-Mode
X-Device-Type
X-NYM-Debug-Backend
X-Content-Powered-By
X-Generated-By
X-HTML-Minification-Powered-By
Xserver
Version
X-Storage
X-Source
X-Cache-Hit
Webserver
X-Hcs-Proxy-Type
X-CCDN-CacheTTL
X-CCDN-Origin-Time
X-Say-Cacheable
Meta-Geo
Load-Balancing
Locale
S-Rt
X-ServerID
GEO-INFO
X-Content-Age
X-SayCDN-TTL
X-Cache-Operation
X-FTR-Request-ID
X-Say-TTL
Filters
X-GeoCountry
OT-Force-Account-Verify
X-Rewrite-Enabled
X-GeoCode
X-Rn-Rsrv
X-UPSTREAM-Address
X-Urbn-Site-Id
X-Urbn-Context-Path
X-Tncms
X-Git-Commit
Cross-Origin-Window-Policy
X-Cluster-Node
X-Loop
X-Container-Uri
X-Director
X-Cache-Action
Onion-Location
X-Varnish-Cache-Hits
X-Forwarded-Host
X-Tt-Logid
X-Soup
X-Sql-Count
Azure-InstanceId
X-Lambda-Id
X-Sql-Duration-Ms
X-Detected-As
X-Tb
X-Served-From
Azure-RegionName
X-Ms-Version
X-Adobe-Source
X-PHP-Host
Azure-SlotName
X-Varnish-Hostname
X-NGENIX-Cache
X-VCT
Azure-Version
X-RM-Cache-TTL
X-Labrador-Cache-Channel
X-Skip-Cache
Azure-SiteName
X-Ms-Request-Id
X-VC-Cache
Mn-Server-Ip
Node
X-XRDS-LOCATION
Web-Mar-Node
X-LAGOON
X-RCS-CacheZone
X-R9-Blue-Green-Version
X-Routing-Service
X-SaId
DB-Nickname
X-Proxied
X-Zipkin-Id
X-URL
X-Cache-Server
X-FB-TRIP-ID
X-Logging-Id
X-JoinUs
X-Extlb
TWC-Connection-Speed
Property-Id
Selected-Fe
X-Proxy-Build
X-Timing-Wait
X-Tumblr-Pixel-2
X-Debug
X-Fetched-On
X-Format
X-Uri
X-Generation-Time
Webcakes-Region
Webcakes-App-Version
TWC-Locale-Group
TWC-GeoIP-LatLong
X-Tumblr-Pixel-3
TWC-Privacy
Webcakes-App-Name
X-Origin-Hint
TWC-GeoIP-Country
TWC-Device-Class
X-MCACHE
Fastcgi-Useragent
X-Oracle-Dms-Ecid
X-Proto
X-Oracle-Dms-Rid
X-Redis-Cache
X-Endurance-Cache-Level
Source
Uber-Trace-Id
X-Ratelimit-Reset
X-B3-SpanId
CDN-RequestId
X-LSADC-Cache
X-Zen-Fury
X-Ua
X-S
X-XRDS-Location
X-Sucuri-ID
X-Sucuri-Cache
X-Origin-CC
X-Origin-TTL
X-Newrelic-Synthetics
Section-Origin-Responded
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
Section-Io-Id
X-TimeS
X-Srv
NGB
X-Origin-Date
Upgrade-Insecure-Requests
X-MP-GENERATED-AT
X-Akamai-Transformed
X-Drupal-Cache-Contexts
Fastly-Drupal-HTML
X-Real-IP
X-Cache-Expired-At
X-Pass-Why
X-Handled-By
X-Varnish-Hits
X-Reqid
Ms-Operation-Id
MS-CV
X-Optimistic-Header
Apigw-Requestid
X-No-Session
X-Cms-Context
X-Xfnlog-Site
X-RTag
X-CACHE-AGE
ServedBy
X-GEO
X-Restarts
X-AB
X-ProxyCache-Key
Liferay-Portal
X-TraceId
X-ProxyCache-Status
X-BYPASS-REASON
X-Hl-Ver
X-Cache-Host
WP-Super-Cache
X-Tx-Id
CDN-RequestCountryCode
CDN-PullZone
CDN-RequestPullCode
CDN-RequestPullSuccess
X-Node-Name
X-UA-Device-Type
X-Cache-TTL-Remaining
CDN-CachedAt
X-Cache-Type
X-AWS-Id
X-Cluster
CDN-Cache
X-CSRF-Token
CDN-EdgeStorageId
CDN-Uid
X-IPLB-Request-ID
X-LJ-Flow-ID
X-VWS-Id
X-Upgrade-Enabled
X-IPLB-Instance
X-Varnish-Ttl
X-Via-JSL
X-Geo-Region
X-Parent-Response-Time
Cache-Provider
X-Proxy-Cache-Status
X-Fastly-Request-Id
X-Pubstack
HA-Ipaddr
Lang
L
L5d-Success-Class
Magicmarker
X-Worker
Xc-Version
Canary
DCR-Processing-Time-Ms
Candidate-Md5Url
DCR-Decision-By
BehaviorPad-Version
Gannett-Cam-Experience-Id
Fastly-SSL
Ha-Gx-Prefs
Sslversion
X-CF-Lambda-Fn
X-CacheTTL
X-CF-Lambda-Version
X-CGP
X-Csrf-Jwt
X-Conf
X-Cache-NE
X-Bl-Debug
X-ScT
X-Application
X-Bc-Bl
X-BCube-Filmed-By
X-S-Cookie
X-D
X-Destination
X-Fastly-Backend
X-External-Request-Id
X-FC-Vary-Parameters
X-PAYTM-SRV-ID
X-Request-Host
X-Eu-Site
X-Epic-Correlation-Id
X-Dispatcher-Number
X-Developer
X-Ec-Custom-Error
X-Ec-Fail
X-Ec-GeoHdr
X-App
X-Aed
X-Vdms-Version
X-Viewer-Country
X-Vdms-Path
Rendered-Blocks
X-Rojux
Server-Host
Redirect-Candidate
Origin-Agent-Cluster
N-Cache
Meta-Geo-Continent
Ngx.Var.Host
X-Vtex-Remote-Cache
Odigeo-Trace-Id
X-SRCache-Key
Surrogated-Key
X-Slack-Backend
X-A-Dam
X-A-Dcw
X-A-Dgt
X-A-Wwc
X-A-Ccd
X-A
True-Client-Country-4JS
T-Server
Vix-Hermes-Req-Id
X-Slack-Shared-Secret-Outcome
W
MD5-Digest
X-B-Cookie
X-Cache-Status-Check
X-Server-W
Cache-Name
Platform
Producers
X-Nitro-Cache
X-NodeID
X-Old-Content-Length
X-Nyt-Route
Release
Req-Svc-Chain
X-Irp-Debug
X-Human
X-Loc
X-Mid
X-Mvc-Supplant-Cachable
X-Mly-Id
Origin
X-Orig-Expires
Gh-Request-Id
X-Server-IP
X-ShardId
X-Shop-Environment
X-Shopify-Stage
X-ShopId
Host-ID
X-SD-PageType
X-Cache-Info
X-Origin-Time
X-Policy
X-Refresh
Is-Eu
X-Request-Time
TDXMobile
Thinkindot-CacheControl
X-App-Name
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-DefElseHash
X-DefHash
X-Alternate-Cache-Key
X-Core-Value
X-Core-Mission
X-B3-Spanid
X-Cdn-Origin
X-BBC-Edge-Cache-Status
X-Cache-Debug
X-CMSURLCustom
X-Clientip
X-Dispatcher-Server
X-DPWN-IS-SECURE
X-GeoIP-Region-Code
X-GeoIP-Country-Code
X-Hash
Thinkindot-Control
Fastly-GeoIP-CountryCode
Thinkindot-CacheControl-Type
Web-Mar-Region
X-Geo-Header
X-Accel-Buffering
X-AIR-PT
X-Forwarded-Path
X-Cdn-Diag
X-Gdpr
X-Cache-Bucket
X-Platform
X-Varnish-CookieINHashed-On
X-Varnish-CookieHashed-On
X-Varnish-Remaining-TTL
X-Varnishpool
X-VG-TLSProxy
Adler-Geo
X-Variation
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-Tenant
X-Thinkindot-L3
X-Up
X-VG-WebCache
X-Vmg-Version
X-Owner
X-Level-Front-Cache
X-Pool
X-Qloud-Router
X-Thanos
X-Generated-On
X-Bip
X-VServer
X-We-Are-Hiring
X-Micro-Cache
X-Wix-Viewer-Type
X-Storefront-Renderer-Rendered
AKAMAI
Expect-Staple
X-Sorting-Hat-ShopId
Cmstype
Environment
X-Sorting-Hat-PodId
Cmsid
X-Sn-Servicetimems
CloudFront-Viewer-Country
X-TIME
User-Cache-Control
We-Hiring
X-GeoIP
X-WA-Info
VNS-Cache
X-Forwarded-Site
X-Org
X-From
X-Correlation-ID
X-Gen-Mode
X-S-Maxage
X-WADP-Cache
X-Esi-Check
X-Auto-Login
X-Date
Machine
DSUID
X-Block-Status
X-Clara-WADP
X-Wikidot-Static-Cache
Datacenter
CPC-Cache
X-Fmm-Version
X-Device-Os
X-ApacheServer
X-Wikidot-Backend
X-Accel-Expires-Debug
VNS-Age
Server-Ext
Cf-Device-Type
X-Mvc-Supplant-OutputCached
X-Vgn-Hpd-Reason
CDCHOST
Server-Hostname
X-Origin
X-Node-Id
X-Nginx-Cache-Key
X-Test
X-PERF
X-NCache
X-Nananana
X-Var-Ttl
Apple-News-Services-Request-Url
Sever-Int
X-Hnp-Log
X-Op-Id-All
NM-Fastcgi-Cache
Country-Code
CPC-Age
X-Gzip
Esi-Enabled
Mail-Subject
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
Apple-News-Services-Handled
X-Cache-Id
Fastly-Backend-Name
X-Origin-Response-Time
X-Is-Mobile
X-Accel-Version
X-Browser-Name
X-Is-Desktop
X-Is-Supported-Browser
X-Is-Tablet
X-Tcp-Rtt
X-Via-Fastly
X-INCAP-ABP
X-Instance-Name
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Section
X-Cdn-Srv
X-LB-NoCache
X-Access
Wxu-Next-Region
X-Ah-Environment
Server-Info
C-Via
Wxu-Next-Hostname
X-Datadome
Wxu-Next-Commit
Ssr
Pics-Label
X-Cache-Enabled
NGX
X-Buckets
X-Akamai-Device-Characteristics
Server-ID
Content-Secure-Policy
X-Varnish-Beresp-Grace
X-Amz-Meta-Cb-Modifiedtime
X-Varnish-Beresp-Ttl
X-API-Version
AMP-Access-Control-Allow-Source-Origin
X-Vcl-Version
X-Dc
X-HA-Backend
X-Presslabs-Stats
IsBot
X-Zone
X-CACHE-GROUP
X-SIPLIST1
X-Origin-Cache-Key
X-B3-Parentspanid
YJS-ID
X-WP-CF-Super-Cache-Active
X-Is-Gdpr
X-JWT-State
Sid
X-Platform-Cluster
CF-Ctrl
Memcached
X-Cached-By
X-Has-Esi
X-ID
X-Platform-Processor
X-Platform-Router
X-Tb-Optimization-Total-Bytes-Saved
Cdn-Requestid
Memory
Hostname
Time
X-Wp-Cf-Super-Cache-Active
Location
X-TA-CDN-Provider
X-Frame-Option
Origin-CC
X-Air-Trace-Id
Origin-EX
X-Hyper-Cache
X-Air-Hostname
X-Fpc
X-Scale
X-Internal-Host
Cache-Hits
X-Air-Source
X-FTR-Backend
X-Country-Code-Real
X-TIM-N
X-FTR-Expires
X-FTR-Cache-Status
X-FTR-Backend-Server
X-FTR-Balancer
X-DC
X-Backend-Instance
X-ZONE
X-PHP-Backend
X-Webstats-RespID
X-Cs
X-LiteSpeed-Cache-Control
X-Service
Resin-Trace
X-VC
LB
X-DataCenter
X-Azure-Ref-OriginShield
True-Client-Ip
Uri
Epwk-X-Cache
X-Site-Version
X-NewRelic-App-Data
X-SRV
GeoIP-Latitude
GeoIP-Country-Code
X-Microcachable
X-NGINX-Cache
Cache-Host
X-NODE
Cdn-Request-Time
X-Edge-Server
Req-ID
X-NMSegId
Cdn-Host
WZWS-RAY
X-Origin-Expires
X-Nitro-Rev
X-Locale
GeoIp-Country-Code
X-Nitro-Cache-From
X-VCache
X-Datacenter
XM
XServer
X-Cache-Ttl
WebServer
X-Info
X-Ad-Load-Variation
Cdn
X-Request-URI
X-CSRF-TOKEN
X-Pad
X-Vercel-Cache
X-Vercel-Id
X-VarnishDD-TTL
X-M-Reqid
Pramga
X-Request-Start
X-Scope-Id
M-TraceId
PFcat
X-M-Log
NtCoent-Length
X-HN
True-Client-IP
X-Pod-Name
X-Geo
X-Web-Node
SID
HostName
X-Shield-Cache-Expires
X-WP-CF-Super-Cache-Cookies-Bypass
X-Varnish-Beresp-Status
Content-Style-Type
Content-Script-Type
X-Qnm-Cache
X-Github-Request-Id
User-Agent
Cluster
X-Ad-Defer-Variation
Srvid
Cache-Tv-Group
X-CS
X-MSEdge-Features
X-Via-CDN
X-Via-Edge
X-FL-EDGE
X-Cache-Date
Fastly-Drupal-Html
X-FPC
X-Via-SSL
X-FL-QIT-DEBUG
Edge-Copy-Time
A
X-MSEdge-Flight
Locid
X-HostName
Tcn
Edge-Cache
X-TH-Server
X-Cdn-Request-ID
Cf-Ipcountry
X-APP-VERSION
X-Api-Version
CountryCode
X-AK-Request-ID
X-NWS-UUID-VERIFY
X-LB-ID
Cdnsip
X-FireWall-Port
X-Wa
X-Moov-T
Cdncip
X-Webkit-Csp-Report-Only
X-Esi
X-Cache-ASPX
X-V-Cache
X-Amz-Meta-Opti
X-Servedbyhost
X-Nc
X-Varnish-Authentication
X-ATG-Version
X-Via-Popv
X-Via-Poph
X-Via-Popn
X-Acquia-Purge-Cdn-Unconfigured
X-Cache-FS-Status
Click-Count-Action-Start
Click-Count-Error
X-Moov-Xdn-Version
Tube-Get-Contents
X-Aicache-OS
Tube-Got-Eval
Path
Tube-Got-Results
Tube-Return
X-Contensis-Viewer-Groups
X-VCL-Version
X-LiteSpeed-Tag
X-SB
X-Vary
X-Men
Cache-Key
X-Req
X-Branch-Name
X-B3-Trace-ID
MIME-Version
Priority
X-Wp-Cf-Super-Cache-Cookies-Bypass
XkeyRZ
X-TRACE-ID
V-Age
Yak-Timeinfo
Ngx-Var-Key
X-Proxy-CacheRZ
On-Server
X-CACHE-KEY
CDN
X-UA
Geoip-Latitude
Wpo-Cache-Message
X-Cdn-Forward
Wpo-Cache-Status
Proxy-Connection
X-Akamai-Pragma-Client-IP
Srv
X-Wp-Cf-Super-Cache-Cache-Control
X-Render-Time
My-App
X-Wp-Cf-Super-Cache
X-Tim-N
X-Acquia-Site
X-Acquia-Application-UUID
X-Acquia-Purge-Tags
X-Acquia-Application-Trace
X-Rebelmouse-Surrogate-Control
X-Lb-Cache
X-Rebelmouse-Cache-Control
X-User
X-Fastly-Backend-Reqs
X-Generated-In
Server-Id
X-Planisys-CDN-Cache
X-Varnish-Director
X-HS-Content-Campaign-Id
X-Ha-Backend
X-Fastly-Country-Code
State
X-HITS
X-Planisys-CDN-TTL
Lb
X-Platform-Server
X-Air-Pt
X-Provided-By
X-Planisys-CDN-Rules
X-TT-LOGID
X-Vgn-Hpd-Ssi
Fusion-Deployment-Id
Fusion-Source
Fusion-Template-Id
Type
Fusion-Content-Source
X-Vgn-Hpd-Cached
X-Vgn-Hpd-Variations-Key
Fusion-Content-Id
X-Lb-Nocache
PICS-Label
X-Release
Ohc-File-Size
X-Cdn-Cache-Status
CF-Cached-On
X-Fastly-Cache
X-Dw-Trace-Id
X-EC-Lua
X-CUA
Fusion-Component-Id
Ohc-Cache-HIT
X-Via-Ucdn
X-Upstream-Ht
X-Upstream-Ct
X-Iplb-Request-Id
X-Iplb-Instance
Yjs-Id
Warning
X-ElasticPress-Query
X-Fastly-Cache-Hits
X-Snapshot-Date
Cache
Vha6-Origin
Inserted-Into-Cache-At
X-Traceid
X-Rocket-Build-Number
X-Sigma
X-Sigma-Backend
CACHE-MISS-TO-ORIGIN
X-Cached-Since
X-Litespeed-Cache-Control
X-Miniprofiler-Ids
Cneonction
X-CF-Cache-Header-Cache-Control
X-CF-Cache-Header-Vary
X-RAMCache
X-HS-Status
X-Cache-Remote
Ngx
Log-Origin
X-Udemy-Cache-App-Namespace