Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-Cache-Status
Link
Accept-Ranges
CF-RAY
X-XSS-Protection
ETag
Expect-CT
Pragma
X-Powered-By
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
Alt-Svc
P3P
X-UA-Compatible
X-Served-By
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
X-Varnish
X-Xss-Protection
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-DNS-Prefetch-Control
X-Drupal-Cache
X-Cache-Status
X-Check
X-Generator
X-Cacheable
Timing-Allow-Origin
X-Content-Security-Policy
X-Iinfo
Feature-Policy
Status
X-Envoy-Upstream-Service-Time
Content-Encoding
Access-Control-Expose-Headers
P3p
X-Drupal-Dynamic-Cache
X-AspNetMvc-Version
X-CDN
Upgrade
X-Via
CF-Ray
X-Ws-Request-Id
Access-Control-Max-Age
X-Request-ID
Report-To
Server-Timing
EagleId
X-Cache-Group
X-Turbo-Charged-By
Keep-Alive
X-UA-Device
Request-Context
X-Age
X-Backend
X-Proxy-Cache
X-Server-Powered-By
X-AH-Environment
X-Robots-Tag
X-Hacker
X-Server
X-Amz-Request-Id
Host-Header
X-Amz-Id-2
Grace
X-Rq
X-LiteSpeed-Cache
X-Swift-CacheTime
X-Swift-SaveTime
X-Varnish-Cache
X-Nginx-Cache-Status
NEL
Ali-Swift-Global-Savetime
X-WebKit-CSP
X-Page-Speed
EagleEye-TraceId
X-Vhost
X-Ua-Compatible
X-Amz-Version-Id
X-Pingback
X-OneAgent-JS-Injection
X-Dispatcher
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
Accept-CH
X-Cache-Spec
X-Host
X-Server-Id
X-Dns-Prefetch-Control
Cf-Railgun
X-Node
X-Backend-Server
X-Readtime
Surrogate-Control
X-Akam-SW-Version
Request-Id
X-Response-Time
X-HW
X-Application-Context
Xkey
Content-Location
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Rating
Accept-CH-Lifetime
X-B3-TraceId
X-Cloud-Trace-Context
X-Country
X-Ruxit-JS-Agent
Accept-Ch-Lifetime
X-Cache-Lookup
X-Trace
X-Url
Allow
X-Content-Type
X-Ac
X-PC
X-Vname
X-TtlSet
X-Aws-Lambda-Call-Status
X-Varnish-TTL
X-Clacks-Overhead
Edge-Control
X-Server-Name
Fastly-Restarts
X-ESI
X-Mod-Pagespeed
Cache-Tag
X-Rack-Cache
Service-Worker-Allowed
X-FastCGI-Cache
X-VARITI-CCR
Verso
X-Element-Page-Cache
MS-Author-Via
X-Vcap-Request-Id
X-Upstream
X-Amz-Rid
X-MS-InvokeApp
Public-Key-Pins
X-GitHub-Request-Id
X-Dw-Request-Base-Id
X-Cached
X-Client-IP
X-D2id
X-Abt-Application-Version
X-Cache-TTL
X-Cnection
RTSS
X-Px
X-Exp-Variant
X-Exp-Id
X-Cdn-Fetch
X-GoogleNews-Bot
X-Kinja-Server
X-Kinja
X-Use-Magma
X-Kinja-Revision
X-Kinja-Build
X-ORACLE-DMS-ECID
X-Navigation-Version
X-ORACLE-DMS-RID
Arr-Disable-Session-Affinity
Access-Control-Request-Method
X-Country-Code
X-Powered-By-Plesk
X-NF-Request-ID
X-Goog-Hash
X-Kraken-Loop-Name
X-Instrumentation
X-Server-Lifecycle-Phase
X-TTL
Pagespeed
Display
X-Middleton-Display
X-Sol
AR-Request-ID
AR-SID
AR-PoweredBy
AR-CACHE
AR-ATIME
X-Powered-CMS
X-Version
X-Origin-Cache
X-Middleton-Response
Response
X-LLID
X-CST
X-MSEdge-Ref
Nginx-Cache
TCN
X-Edge-Location-Klb
X-Kinsta-Cache
X-RateLimit-Remaining
X-Amz-Server-Side-Encryption
MRF-Tech
X-B3-TraceId-Primal
Mrf-Cache-Status
X-Edge
X-Protected-By
X-T
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Forwarded-For
X-Jurisdiction
X-HP-Trace-Id
X-HP-Webp
X-Content-Security-Policy-Report-Only
X-Shield-Request-Id
X-Mg-S
X-Id
X-Aspnetmvc-Version
X-Language
Edge-Cache-Tag
S
Content-MD5
SPIisLatency
SPRequestDuration
X-Ruxit-Js-Agent
Front-End-Https
Fastcgi-Cache
X-Mid
Realpath
X-Request-Processing-Time
X-Request-Received
Server-Node
Pinterest-Generated-By
X-Frontend
Pinterest-Version
Filters
X-Pinterest-Rid
X-Recruiting
Server-Name
X-Cache-Key
X-Ab
X-Content
X-Ua-Browser
X-Ser
X-NWS-LOG-UUID
X-MCACHE
X-Correlation-Id
X-Template
X-HS-Cache-Config
X-HS-Hub-Id
X-HS-Content-Id
X-DynaTrace
X-Yandex-Sdch-Disable
X-HS-Combine-CSS
X-Ezoic-Cdn
SPRequestGuid
X-SharePointHealthScore
X-Hits
X-ECACHE
X-Parallel-Accel
X-Kong-Upstream-Latency
X-Ttl
X-Kong-Proxy-Latency
MicrosoftSharePointTeamServices
X-Webkit-Csp
X-Tt-Trace-Host
X-Tt-Trace-Tag
Cache-Tags
Charset
X-Page-Id
Cleartype
X-B3-Sampled
Host
X-Daa-Tunnel
X-Git-Hash
X-Www-Served-By
X-Debug-Info
X-Geo-Country
Alternate-Protocol
X-Content-Options
Accept-Ch
X-DIS-Request-ID
X-Ratelimit-Limit
Fusion-Deployment-Id
Fusion-Content-Source
Fusion-Source
Fusion-Template-Id
Fusion-Component-Id
Fusion-Content-Id
X-Content-Digest
X-Hostname
X-Amzn-Trace-Id
Cross-Origin-Opener-Policy
X-Amz-Replication-Status
Filterid
X-Varnish-Age
X-FB-Debug
X-F-Cache
X-Grace
X-DataDome
X-Az
ServerID
X-AppVersion
X-Activity-Id
X-Upgrade-Enabled
X-VCache
X-Accel-Expires
X-N
X-Nginx-Upstream-Cache-Status
X-WebKit-CSP-Report-Only
X-Rid
X-Mobile-URL
X-Forwarded-Proto
X-Fastly-Request-Id
X-Aspnet-Duration-Ms
X-Is-Crawler
X-Providence-Cookie
Access-Control-Allow-Method
X-Flags
X-Route-Name
X-Request-Guid
X-Origin-Server
X-Server-ID
X-Type
X-LB-Cache
X-Whom
X-TT
X-Seen-By
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Tb
Payment
X-Varnish-Grace
Viewport
X-App-Environment
X-GUploader-UploadID
X-Goog-Generation
X-Goog-Stored-Content-Length
X-Goog-Metageneration
X-FW-Type
X-FW-Serve
X-FW-Hash
X-FW-Server
X-FW-Static
X-FW-Dynamic
X-User-Agent
X-Distributor
Node
Fastcgi-Useragent
Paypal-Debug-Id
DC
X-Ratelimit-Reset
X-Wix-Request-Id
X-Oneagent-Js-Injection
Accept-Charset
TP-Cache
Country
TP-L2-Cache
X-Fastly-Request-ID
X-XRDS-LOCATION
X-App-Server
X-Cache-Rule
X-Litespeed-Cache
X-Tec-Api-Version
X-Tec-Api-Root
X-Cache-Control
X-Tec-Api-Origin
X-Via-JSL
X-NGENIX-Cache
X-Cluster-Name
X-Fastcgi-Cache
X-Drupal-Cache-Tags
Version
X-Contextid
X-Request-Handler-Origin-Region
X-Cache-Age
X-Signature
X-Buckets
X-Microsite
X-B-Cache
Referer-Policy
Amp-Access-Control-Allow-Source-Origin
Cache-Status
X-Origin-Upstream-Status
X-Node-Name
X-Logged-In
Refresh
VIX-Pulpo-Node
X-Erf-Bev-Bev-Is-Generated
SD-X-WS
X-Original-Request-Id
VIX-Pulpo-Upstream-Status
X-Mobile
X-Response-Served-From
X-Erf-Bev-Bev
X-Browser-Type
X-Load-Cache
X-Real-IP
X-Rendered-As
X-IPLB-Instance
X-Cache-Expired-At
X-Page-View
X-Vgn-Hpd-Reason
X-Is-Bot
X-Jobs
X-Cacheable-TTL
X-Proxy-Cache-Status
X-B
X-Debug
Access-Control-Request-Headers
X-Varnish-Backend
NGB
X-Revision
X-ProcessESI
X-RemovedCookies
X-Cache-Action
X-Instance
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Device-Type
X-Proxy
X-UUID
X-Rule
X-Drupal-Cache-Contexts
X-G
X-Framework
Akamai-GRN
Surrogate-Key
X-Debug-IsConnected
X-FW-Version
X-Cache-Time
X-Debug-IsPreview
CF-IPCountry
X-Accel-Buffering
X-XRDS-Location
X-Oracle-Dms-Ecid
X-Oracle-Dms-Rid
X-Presslabs-Stats
GEO-INFO
SID
X-Air-Trace-Id
X-Air-Hostname
X-Air-Source
X-Cache-NGX
Count-Hit
Uber-Trace-Id
X-Cache-Operation
X-APP-VERSION
X-Source
X-Azure-Ref
X-Ms-Request-Id
X-Nginx-Cache
X-Ms-Version
X-Zen-Fury
DynaTrace
Protected
X-EdgeConnect-Cache-Status
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-TEC-API-ROOT
Liferay-Portal
Frame-Options
X-PressLabs-Stats
X-RTag
X-CDN-Forward
X-Trace-Id
WPO-Cache-Message
Ms-Operation-Id
MS-CV
WPO-Cache-Status
X-Cache-Hit
X-Servername
Healthy
X-Hyper-Cache
Ec-Rule-Version
X-Backend-Name
Countrycode
X-IPS-LoggedIn
X-Cache-TTL-Remaining
X-RateLimit-Limit
Cross-Origin-Window-Policy
Xserver
X-Mode
X-Tumblr-User
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-L-Path
X-Environment-Context
X-Ratelimit-Remaining
X-Adobe-Content
X-Adobe-Loc
Content-Disposition
X-Varnish-Server
Backend
Meta-Geo
X-JoinUs
LB
X-UPSTREAM-Address
X-Tid
X-Detected-As
X-Content-Age
X-SaId
X-Rewrite-Enabled
X-RN-RSRV
X-Uri
X-Sorting-Hat-ShopId
X-Debug-Cache
X-Format
X-Generation-Time
X-ShopId
X-Cache-Grace
X-ShardId
X-Hosted-By
X-Alternate-Cache-Key
Country-Code
Eomportal-Instance
Decoy-Debug-Key
Decoy-Debug-Status
Apigw-Requestid
Url
Decoy-Debug-TTL
X-Proxied
X-Routing-Service
X-Cache-Server
X-Extlb
X-Region
X-Sql-Count
X-Zipkin-Id
X-Shopify-Stage
X-Redis-Cache
X-Sql-Duration-Ms
X-Sorting-Hat-PodId
CDN-RequestId
Fastly-SSL
X-PHP-Backend
Cache-Name
CDN-Uid
CDN-PullZone
X-Access
X-Section
Mn-Server-Ip
CDN-Cache
X-ApacheServer
X-Site-Version
CDN-EdgeStorageId
CDN-CachedAt
CDN-RequestCountryCode
X-ServerID
X-Origin-Date
X-Microcachable
X-No-Session
X-OCL
X-Status
X-Varnish-Beresp-Grace
X-Human
X-NCache
X-PERF
X-UA-Device-Type
X-PCL
X-TIME
X-Forwarded-Host
X-Via-Fastly
X-FB-TRIP-ID
TWC-Device-Class
TWC-GeoIP-Country
TWC-Connection-Speed
X-Say-Cacheable
X-NYM-Debug-Backend
X-Say-TTL
X-Generated-By
Selected-Fe
X-BYPASS-REASON
X-Server-W
X-Cluster-Node
X-Cache-Type
X-Cache-Host
X-Content-Powered-By
X-Proxy-Build
X-ProxyCache-Key
X-ProxyCache-Status
X-Pubstack
X-Timing-Wait
X-Storage
Webcakes-App-Version
Webcakes-App-Name
TWC-Privacy
TWC-Locale-Group
Webcakes-Region
X-SayCDN-TTL
X-Web-Node
X-Akamai-Edgescape
X-Origin-Hint
TWC-GeoIP-LatLong
Property-Id
Cache-Tv-Group
Retry-After
X-Be
X-R9-Blue-Green-Version
Section-Io-Cache
X-Hl-Ver
X-Soup
X-Varnishpool
Azure-InstanceId
Azure-SiteName
Azure-RegionName
Azure-Version
Content-Secure-Policy
X-Nginx-Cache-Key
X-LSADC-Cache
Azure-SlotName
X-Webkit-CSP
X-Ua
X-NewRelic-App-Data
X-Unique-Id
DB-Nickname
X-Cache-Remote
OT-Force-Account-Verify
X-Cached-By
X-Dc
X-Platform-Server
X-Bc-Bl
X-Azure-Ref-OriginShield
Cache
X-Akamai-Transformed
X-Xfnlog-Site
Source
X-Auto-Login
X-GEO
X-Cache-Tags
X-TT-LOGID
ServedBy
Upgrade-Insecure-Requests
X-LAGOON
X-Cdn
From-Origin
SRV
X-Origin-CC
X-Origin-TTL
X-Varnish-Cache-Hits
X-Request-Time
Mime-Version
X-AOL-HN
Xet-Cookie
X-TNCMS
X-Varnish-Hits
Cache-Hits
X-Loop
X-Varnish-Hostname
X-NWS-UUID-VERIFY
X-HTML-Minification-Powered-By
HostName
X-SRV
X-Request-Host
WP-Super-Cache
X-S-Maxage
X-EC-Lua
Onion-Location
X-CSRF-Token
Webserver
X-ECache
X-FireWall-Port
Web-Mar-Node
X-Handled-By
X-Cache-Enabled
X-Tumblr-Pixel-3
X-Tumblr-Pixel-2
N-Cache
X-Proto
X-App-Version
X-Time
X-B3-SpanId
X-Endurance-Cache-Level
S-Rt
X-Correlation-ID
X-Adobe-Source
Nel
X-Akamai-Request-ID2
X-Http-Reason
X-Origin-Response-Time
X-Reqid
X-Tenant
X-RCS-CacheZone
Fastcgi-X-Cache-Version
Expiry
X-Gen-Mode
DCR-Processing-Time-Ms
X-Ftr-Request-Id
Odigeo-Trace-Id
Pramga
X-SRCache-Key
X-TIM-N
Mobile-Detection-Method
X-GG-Cache-Date
X-V-Cache
Meta-Geo-Continent
X-Planisys-CDN-Rules
X-NAPM-TraceId
X-Ig-Push-State
X-PBS-Appsvrname
X-PAYTM-SRV-ID
X-Vtex-Remote-Cache
Xc-Version
X-Orig-Expires
X-Planisys-CDN-Cache
X-Hnp-Log
X-VG-WebCache
X-Vdms-Version
DCR-Decision-By
Redirect-Candidate
BehaviorPad-Version
X-Vtex-Processado-Em
A
X-Vdms-Path
X-Slack-Backend
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-SD-PageType
X-Ckpd-Fst-Backend
X-Cache-NE
X-Block-Status
X-ARC
X-B-Cookie
X-Backend-TTL
X-Cluster
X-Developer
X-Rojux
X-D
X-Processor
X-S
X-S-Cookie
X-ScT
X-Conf
X-Destination
X-Session-Fingerprint
X-Application
V-Age
Vix-Hermes-Req-Id
X-A
X-External-Request-Id
X-Forwarded-Path
Sslversion
Surrogated-Key
User-Cache-Control
X-A-Ccd
X-Shop-Environment
X-A-Dgt
X-A-Wwc
X-Aed
X-A-Dcw
X-Epic-Correlation-Id
X-A-Dam
X-Planisys-CDN-TTL
X-ND-Cache
Rendered-Blocks
X-Connection-Hash
X-AWS-Id
X-VWS-Id
X-Amz-Meta-S3cmd-Attrs
X-LJ-Flow-ID
Server-Info
X-MP-GENERATED-AT
X-Magnolia-Registration
X-Mg-Request-UUID
X-Time-Microsecs
X-Edge-Location
X-Origin-Time
X-Origin-Expires
X-Scheme
X-Core-Mission
Gh-Request-Id
X-SVT-ORM-VERSION
X-Old-Content-Length
Traceparent
X-Device-Os
Cmstype
DSUID
X-Fastly-Backend
Host-ID
X-Date
X-Origin
Fastcgi-Cache-TTL
State
X-VServer
X-Webstats-RespID
X-Cache-Date
X-Viewer-Country
X-VG-TLSProxy
X-Request-URI
X-Cache-Bucket
Origin-EX
Origin-CC
X-Policy
X-Cdn-Srv
Cmsid
X-Proxy-Upstream
X-Rocket-Nginx-Serving-Static
Origin
X-Cache-Info
Svr
X-Nyt-Route
X-Geo-Header
X-Accel-Expires-Debug
X-GeoIP-Country-Code
X-Server-IP
X-Men
X-Forwarded-Site
X-Aicache-OS
X-Mvc-Supplant-Cachable
X-GeoIP-Region-Code
X-Location
X-Li-Pop
Wxu-Next-Region
X-Li-Fabric
Wxu-Next-Hostname
Wxu-Next-Commit
X-LI-UUID
X-Hash
X-Locale
X-Gdpr
X-Sucuri-ID
Arc-Country
Apple-News-Services-Request-Url
X-Fetched-On
X-SVT-ORM-RULES
X-NodeID
CDCHOST
True-Client-Country-4JS
CacheControlHeader
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
AKAMAI
X-Fastly-Cache
Apple-News-Services-Handled
X-Sucuri-Cache
CloudFront-Viewer-Country
X-Via-NSCOPI
Environment
X-Rocket-Build-Number
X-ATG-Version
X-Backend-State
X-Req
X-Served-From
X-BBC-Edge-Cache-Status
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Csrf-Jwt
X-Gamma-Serve
X-Generated-On
X-Node-Id
X-Eu-Site
X-Envoy-Decorator-Operation
X-Esi-Check
X-GeoIP
X-GeoIP-City
X-Irp-Debug
X-Labrador-Cache-Channel
X-HS-Content-Campaign-Id
X-HN
X-Gzip
X-Developers
X-Datadog-Trace-Id
X-RateLimit-Limit-Second
X-Platform
X-Cache-Id
X-Cache-Debug
X-Region-Sid
X-RateLimit-Remaining-Second
X-CGP
X-PHP-Host
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
X-Sigma
X-Core-Value
X-Owner
X-Branch-Name
Thinkindot-CacheControl
Machine
Locid
L5d-Success-Class
L
Magicmarker
Mail-Subject
X-VarnishDD-TTL
Release
PFcat
HA-Ipaddr
X-Sigma-Backend
X-JWT-State
X-Restarts
X-Sn-Servicetimems
Fastly-Drupal-Html
X-Is-Gdpr
X-Has-Esi
Fastly-GeoIP-CountryCode
X-Cdn-Origin
X-FC-Vary-Parameters
Req-Svc-Chain
Ha-Gx-Prefs
X-Level-Front-Cache
Thinkindot-CacheControl-Type
X-TH-Server
TDXMobile
Ssr
Thinkindot-Control
X-Varnish-Beresp-Status
X-Skip-Cache
X-Storefront-Renderer-Rendered
Web-Mar-Region
We-Hiring
X-Thinkindot-L3
X-Varnish-Beresp-Ttl
Server-Host
X-TrackingId
X-UnsetCookies
X-Xrds-Location
X-Rebelmouse-Cache-Control
X-Qloud-Router
X-NU-AKA-ACS-Version
NM-Fastcgi-Cache
X-Loc
Adler-Geo
X-Varnish-Remaining-TTL
X-Worker
X-Varnish-CookieINHashed-On
X-Varnish-CookieHashed-On
Cf-Device-Type
X-Variation
X-Response-By
X-Rebelmouse-Surrogate-Control
Memcached
Is-Eu
Platform
Kp-EeAlive
X-Cache-Var
X-Pod-Name
X-Amzn-Remapped-Content-Length
Fastly-SWR
X-Cache-Var-Map
X-DPWN-IS-SECURE
X-Tx-Id
Fastly-SIE
X-DefHash
X-Zone
X-DefElseHash
X-Ua-Device
X-TraceId
X-RSL
Edge-Cache
X-Cache-Backend
X-RPS
X-NC
X-Wix-Viewer-Type
X-DB
X-VC-Cache
X-Mvc-Supplant-OutputCached
X-Action
X-DI
X-DW
X-DSS
X-RPM
Accept-Language
AMP-Access-Control-Allow-Source-Origin
NGX
X-Request-Start
CDN
X-Up
X-Srv
X-CS
X-LB-NoCache
Ms-Author-Via
X-Thanos
X-Bip
Pics-Label
X-Optimistic-Header
X-Trace-ID
X-CacheTTL
X-LB-ID
X-Minions-Version
X-Generated-In
X-Tt-Logid
X-M-Log
X-Qnm-Cache
X-M-Reqid
X-Tb-Optimization-Total-Bytes-Saved
X-Urbn-Site-Id
Locale
Env
Time
X-API-Version
X-Urbn-Context-Path
Memory
X-Cache-Config
X-Refresh
X-Varnish-Ttl
WebServer
X-Edge-Pop
X-Via-Poph
X-Via-Popv
X-Via-Popn
GeoIp-Country-Code
Datacenter
X-TA-CDN-Provider
X-DC
X-CACHE-KEY
X-User
X-Ec-GeoHdr
X-Ec-Fail
X-HA-Backend
X-Parent-Response-Time
X-DynaTrace-JS-Agent
X-Cs
X-Servedbyhost
X-Esi
Candidate-Md5Url
Server-ID
NtCoent-Length
X-Vc
X-MSEdge-Flight
X-MSEdge-Features
X-ZONE
X-Dynatrace
X-CLOUD-TRACE-CONTEXT
X-AK-Request-ID
On-Server
WWW-Authenticate
Cdnsip
Cdncip
X-TX-ID
X-Datadome
Cluster
Geoip-Latitude
My-App
X-WADP-Cache
X-Fmm-Version
X-Clara-WADP
Esi-Enabled
X-Varnish-Beresp-TTL
X-VCL-Version
Tracecode
X-App
X-Fpc
X-Cache-Ttl
X-LI-Proto
X-Var-Ttl
X-CUA
X-Pass-Why
X-URL
X-From
T-Server
X-Service
X-Unique-ID
C-Via
X-Webkit-Csp-Report-Only
Lfy
X-Cache-PHP
X-Li-Proto
X-Traceid
DataCenter
X-Fragments
Lang
X-Newrelic-Synthetics
X-B3-Spanid
X-FPC
Fastly-Drupal-HTML
X-Webkit-CSP-Report-Only
X-NODE
Cf-Int-Pingora-Origin-Digest
X-VC
X-Vcl-Version
Geo-Info
Test
Target-Params
X-Mcache
X-Render-Time
Proxy-Connection
M-TraceId
X-WP-CF-Super-Cache-Cache-Control
X-CSRF-TOKEN
X-Cache-Status-Check
Resin-Trace
X-WP-CF-Super-Cache
X-Provided-By
Hostname
Server-Id
X-Api-Version
X-LiteSpeed-Cache-Control
X-RAMCache
X-Ha-Backend
Permissions-Policy
X-COUNTRY
X-ID
MIME-Version
X-Via-PopH
X-Proxy-Cache-Info
Hit
X-Via-PopV
X-Clientip
GeoIP-Country-Code
X-Via-PopN
X-Httpd
X-ServedByHost
X-NGINX-Cache
WZWS-RAY
Servername
X-Geo
X-Dynatrace-Js-Agent
X-Pad
X-Cdn-Forward
X-SB
Producers
X-Edge-POP
FSS-Cache
X-Oss-Object-Type
X-Fastly-Backend-Reqs
HIT
X-Pool
X-Platform-Cluster
X-LiteSpeed-Tag
X-Oss-Storage-Class
X-Oss-Hash-Crc64ecma
X-Oss-Server-Time
X-Oss-Request-Id
ENV
UCS
X-Platform-Router
X-Edge-Cache
X-Platform-Processor
X-Udemy-Cache-App-Namespace
Cache-Host
S-Cnection
Section-Io-Origin-Time-Seconds
X-Scale
X-Ucs
X-Info
Section-Io-Origin-Status
X-AIR-PT
X-Ec-Custom-Error
Section-Io-Id
Section-Origin-Responded
X-ElasticPress-Query
Server-Ext
X-UP
MD5-Digest
X-Acquia-Application-Trace
X-Acquia-Application-UUID
X-Acquia-Purge-Tags
X-Lb-Id
X-BBC-Origin-Response-Status
X-Dispatcher-Number
ServerName
X-Cache-Expires
X-HS-Status
PICS-Label
X-GoCache-CacheStatus
URI
Uri
X-Lb-Nocache
X-Cache-CFC
Server-Hostname
X-Acquia-Site
X-Check-Cacheable
Sever-Int
Ohc-File-Size
Sid
X-Srcache-Fetch-Status
X-Srcache-Store-Status
Cneonction
Server-Ttl
X-Via-Ucdn
X-SIPLIST1
X-Cdn-Request-ID
X-Fastly-Cache-Hits
X-Micro-Cache
Tcn
Fastly-Backend-Name
X-Release
X-Swift-Error
X-RateLimit-Reset
IsBot
User-Agent
X-Nc
Cteonnt-Length
X-Dw-Trace-Id
X-Akamai-ERRuleID
X-Akamai-ERPolicy
X-B3-ParentSpanId
X-Fetch-By
X-Vcache
Cf-Ipcountry
X-Yottaa-OS
Ngx
X-Cms-Context
Wpo-Cache-Message
Wpo-Cache-Status
X-Newrelic-App-Data
X-Backend-Host
CF-Cached-On
Vha6-Origin
Load-Balancing
X-ServerName
X-HostName
X-Air-Pt
X-Cache-Ngx
X-B3-Parentspanid
X-Via-CDN
X-Shopify-Generated-Cart-Token
X-Akamai-Request-ID
X-IN-APIGATEWAY
X-Litespeed-Cache-Control
Inserted-Into-Cache-At
X-IN-APIGATEWAYSSL
X-Akamai-Pragma-Client-IP
X-Apw-Hits
EpKe-Alive
X-Contensis-Viewer-Groups
X-Logging-Id
X-Apw-Access-Token
X-Apw-Access-Object
X-Varnish-Authentication
Shield-Pop
X-Cache-ASPX
X-Apw-Access-Action
X-BCube-Filmed-By
X-CacheKey
X-Http-Count
X-Http-Duration-Ms
X-Te-Count
X-Te-Duration-Ms
X-Sentry-ID
X-Snapshot-Date
X-UA
Req-ID
CountryCode
X-APP
X-Last-Modified