Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
X-Powered-By
Pragma
CF-RAY
X-XSS-Protection
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
Alt-Svc
X-Xss-Protection
P3P
X-Cache-Hits
X-UA-Compatible
X-Served-By
CF-Ray
X-Download-Options
X-Timer
X-Request-Id
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
Access-Control-Allow-Credentials
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
X-Drupal-Cache
X-Cache-Status
X-Generator
X-Check
X-Cacheable
X-Envoy-Upstream-Service-Time
X-FRAME-OPTIONS
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Iinfo
X-Dns-Prefetch-Control
X-Request-ID
X-Drupal-Dynamic-Cache
Feature-Policy
Server-Timing
X-Content-Security-Policy
Access-Control-Expose-Headers
Content-Encoding
Status
X-CDN
X-XSS-PROTECTION
Upgrade
X-AspNetMvc-Version
Access-Control-Max-Age
X-Amz-Request-Id
X-Via
X-Amz-Id-2
Request-Context
X-Turbo-Charged-By
X-Backend
X-Cache-Group
X-AH-Environment
X-Robots-Tag
Cf-Edge-Cache
Keep-Alive
Host-Header
X-Hacker
X-UA-Device
X-Proxy-Cache
X-Vhost
X-Server
X-Rq
X-Server-Powered-By
Allow
X-Ws-Request-Id
X-Age
X-Dispatcher
X-Varnish-Cache
EagleId
X-Amz-Version-Id
X-LiteSpeed-Cache
P3p
Nel
Grace
Cf-Apo-Via
Cf-Railgun
X-Page-Speed
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
EagleEye-TraceId
X-OneAgent-JS-Injection
X-Swift-CacheTime
X-Swift-SaveTime
X-Aws-Lambda-Call-Status
Ali-Swift-Global-Savetime
X-Pingback
X-Host
X-Node
Accept-CH
X-WebKit-CSP
X-Cache-Lookup
X-CST
X-Backend-Server
Surrogate-Control
X-Server-Id
X-Readtime
Permissions-Policy
X-Nginx-Cache-Status
X-Nginx-Upstream-Cache-Status
X-Akam-SW-Version
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Request-Id
X-Application-Context
X-Content-Security-Policy-Report-Only
X-Cloud-Trace-Context
Accept-CH-Lifetime
X-Ruxit-JS-Agent
X-Response-Time
X-HW
X-Ua-Compatible
X-Trace
Xkey
X-Edge
Content-Location
X-Clacks-Overhead
X-Mod-Pagespeed
X-Url
Accept-Ch-Lifetime
X-ESI
X-Midtier
Rating
X-Amz-Server-Side-Encryption
X-ECACHE
X-Mcache
Cache-Tag
X-Country
X-MS-InvokeApp
X-Rack-Cache
X-Upstream
X-D2id
X-Powered-By-Plesk
X-Vcap-Request-Id
X-Exp-Id
X-Kinja-Build
X-Exp-Variant
X-GoogleNews-Bot
X-Use-Magma
X-Cdn-Fetch
Verso
X-Kinja-Revision
X-Kinja-Server
X-Kinja
X-Element-Page-Cache
Accept-Ch
Edge-Control
Service-Worker-Allowed
X-Vname
X-PC
X-TtlSet
RTSS
X-Oneagent-Js-Injection
X-Country-Code
X-Ac
Origin-Trial
X-VARITI-CCR
X-Navigation-Version
X-Goog-Hash
Fastly-Restarts
X-Abt-Application-Version
X-Cache-TTL
X-WebKit-CSP-Report-Only
X-GitHub-Request-Id
X-Varnish-TTL
X-Browser-Type
X-Amz-Rid
X-Cached
X-Kinja-CCPA
X-Aspnetmvc-Version
Cross-Origin-Opener-Policy
X-Webkit-CSP
X-Sol
X-Middleton-Display
Display
Pagespeed
X-Server-Name
X-Ruxit-Js-Agent
X-NWS-LOG-UUID
X-Dw-Request-Base-Id
X-Amzn-Trace-Id
X-SharePointHealthScore
SPRequestGuid
X-Content-Type
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
SPIisLatency
SPRequestDuration
X-Times
X-Erf-Bev-Bev-Is-Generated
X-Server-Lifecycle-Phase
X-Erf-Bev-Bev
X-Kraken-Loop-Name
X-Instrumentation
X-Powered-CMS
AR-SID
AR-Request-ID
AR-PoweredBy
X-Cache-Key
AR-ATIME
X-Ttl
Pinterest-Version
X-Pinterest-Rid
Pinterest-Generated-By
X-B3-Traceid
X-Mg-S
Arr-Disable-Session-Affinity
X-Middleton-Response
Response
X-Litespeed-Cache
X-FastCGI-Cache
X-Client-IP
X-Version
X-Fastly-Request-ID
X-Cnection
X-Jurisdiction
X-HP-Trace-Id
X-Ser
X-HP-Webp
AR-CACHE
Nginx-Cache
X-Accel-Expires
Cache-Tags
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Server-ID
X-T
Cache-Status
Edge-Cache-Tag
X-B3-TraceId
X-MSEdge-Ref
Front-End-Https
X-Hits
Public-Key-Pins
X-Px
X-NF-Request-ID
X-Recruiting
Payment
X-RateLimit-Remaining
S
X-Frontend
X-LLID
X-Ua-Browser
MRF-Tech
Server-Node
Mrf-Cache-Status
X-B3-TraceId-Primal
X-Request-Processing-Time
X-Request-Received
X-Shield-Request-Id
X-Daa-Tunnel
Content-MD5
X-TTL
X-GUploader-UploadID
X-Goog-Metageneration
X-DIS-Request-ID
X-RateLimit-Limit
Access-Control-Request-Method
MicrosoftSharePointTeamServices
X-PressLabs-Stats
X-Amz-Apigw-Id
X-Amzn-RequestId
TP-Cache
X-Content-Digest
X-Ratelimit-Remaining
X-Webkit-CSP-Report-Only
Realpath
X-Protected-By
X-HS-Hub-Id
X-Microsite
X-HS-Cache-Config
X-HS-Combine-CSS
X-HS-Content-Id
X-Forwarded-For
X-Request-Handler-Origin-Region
X-Distributor
Fastcgi-Cache
Access-Control-Allow-Method
X-FB-Debug
X-Page-Id
X-LB-Cache
X-Cluster-Name
X-Rid
Accept-Charset
X-Geo-Country
X-Hostname
TP-L2-Cache
X-Erf-Stays-Pdp-Viaduct-Migration-Web
X-Ratelimit-Limit
X-B3-Sampled
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-Aspnet-Version
Count-Hit
X-Fastcgi-Cache
X-Ua-Device
X-Ezoic-Cdn
X-Seen-By
X-Correlation-Id
Cross-Origin-Resource-Policy
Cleartype
TCN
X-Edge-Location-Klb
X-Newrelic-App-Data
X-App-Server
X-Kinsta-Cache
X-Xrds-Location
X-Mobile
X-Varnish-Backend
X-Logged-In
Referer-Policy
DC
X-Content-Options
X-Id
X-Hosted-By
X-Origin-Cache
X-Git-Hash
X-Contextid
X-Providence-Cookie
X-Request-Guid
X-Route-Name
X-Aspnet-Duration-Ms
X-Is-Crawler
X-Fb-Rlafr
X-Debug-Info
X-Flags
X-Amz-Replication-Status
X-Grace
X-Revision
Retry-After
Surrogate-Key
X-TT
X-IPS-LoggedIn
X-Amz-Meta-S3cmd-Attrs
X-Forwarded-Proto
Frame-Options
X-Varnish-Grace
X-App-Environment
X-Envoy-Decorator-Operation
X-F-Cache
X-Azure-Ref
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
Section-Io-Cache
X-Magnolia-Registration
X-Wix-Request-Id
X-Whom
Healthy
Alternate-Protocol
X-Proxy-Cache-Info
Charset
X-Origin-Server
MS-Author-Via
X-Akamai-Edgescape
Viewport
X-App-Version
X-RateLimit-Reset
X-Nf-Request-Id
X-Www-Served-By
X-COUNTRY
X-Backend-Name
X-Webkit-Csp
X-AppVersion
Amp-Access-Control-Allow-Source-Origin
X-Activity-Id
X-Language
X-Az
X-Varnish-Server
Filterid
Paypal-Debug-Id
X-B
SRV
WPO-Cache-Status
X-DataDome
WPO-Cache-Message
X-Response-Served-From
X-Original-Request-Id
Server-Name
X-Datadog-Trace-Id
X-Cache-Rule
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Datadog-Parent-Id
SD-X-WS
X-Datadog-Sampling-Priority
X-Http-Reason
Host
X-Akamai-Request-ID2
X-Rule
X-UUID
X-Instance
Front
X-User-Agent
X-Cache-Grace
X-Edge-Location
X-Kong-Upstream-Latency
Country
Akamai-GRN
From-Origin
X-Unique-Id
X-Kong-Proxy-Latency
X-Time
X-Environment-Context
X-Varnish-Age
X-L-Path
X-Page-View
X-Region
X-ARC
X-Jobs
X-Cacheable-TTL
Protected
X-Is-Bot
X-Load-Cache
X-FW-Type
X-Vcache
X-Rocket-Nginx-Serving-Static
X-FW-Static
X-FW-Server
X-FW-Serve
X-Adobe-Loc
X-Adobe-Content
X-Status
X-FW-Hash
X-Rendered-As
X-FW-Version
X-FW-Dynamic
X-Cache-Time
X-G
Fastly-SIE
Fastly-SWR
X-Framework
X-Trace-Id
X-Type
X-N
X-RemovedCookies
ServerID
X-Tumblr-Pixel
X-Client-Ip
X-Tumblr-User
X-ProcessESI
X-EdgeConnect-Cache-Status
X-Yottaa-Metrics
X-Tumblr-Pixel-1
X-Yottaa-Optimizations
X-Tumblr-Pixel-0
Content-Disposition
X-Proxy
X-Mg-Request-UUID
X-Tec-Api-Origin
X-Datadog-Sampled
X-Tec-Api-Version
Access-Control-Request-Headers
X-Tec-Api-Root
X-B-Cache
X-Signature
X-Debug-IsPreview
X-Debug-IsConnected
X-Amzn-Remapped-Content-Length
X-CDN-Forward
X-Cache-Control
X-Cache-Age
X-ECache
Backend
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
Countrycode
Refresh
X-DynaTrace
X-Nginx-Cache
X-Drupal-Cache-Tags
X-Httpd
Xet-Cookie
X-Servername
X-Erf-Web-Scheduler
Accept-Language
Url
CF-IPCountry
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Generated-By
X-DynaTrace-JS-Agent
X-HTML-Minification-Powered-By
X-Source
X-XRDS-Location
X-Template
X-Mode
X-Device-Type
Webserver
X-Content-Powered-By
X-NYM-Debug-Backend
Xserver
Version
X-Storage
GEO-INFO
X-Content-Age
X-UPSTREAM-Address
OT-Force-Account-Verify
Meta-Geo
Locale
Load-Balancing
X-Urbn-Context-Path
X-Urbn-Site-Id
S-Rt
X-LAGOON
X-GeoCode
X-Director
X-Cache-Operation
X-GeoCountry
X-Cache-Action
Filters
X-Say-Cacheable
X-ServerID
X-Say-TTL
X-Rewrite-Enabled
X-Rn-Rsrv
X-SayCDN-TTL
X-Git-Commit
X-Varnish-Hostname
X-Cluster-Node
X-Container-Uri
X-Forwarded-Host
X-Varnish-Cache-Hits
X-JoinUs
Onion-Location
X-SaId
X-Soup
X-Tt-Logid
X-Cache-Server
X-Sql-Duration-Ms
X-Loop
X-Cache-Hit
Web-Mar-Node
X-Ms-Request-Id
X-Detected-As
X-Ms-Version
X-Tncms
X-Lambda-Id
X-Adobe-Source
X-VCT
X-Sql-Count
X-Served-From
X-VC-Cache
Mn-Server-Ip
Azure-SlotName
Node
Azure-RegionName
DB-Nickname
Azure-SiteName
Cross-Origin-Window-Policy
Azure-Version
Azure-InstanceId
X-R9-Blue-Green-Version
X-RCS-CacheZone
X-Proxied
X-Proto
X-PHP-Host
X-RM-Cache-TTL
X-Routing-Service
X-Tb
X-URL
X-Zipkin-Id
X-Skip-Cache
X-XRDS-LOCATION
X-Logging-Id
X-Hcs-Proxy-Type
X-CCDN-Origin-Time
X-Generation-Time
X-FB-TRIP-ID
X-Labrador-Cache-Channel
X-Extlb
X-CCDN-CacheTTL
X-Timing-Wait
TWC-GeoIP-Country
TWC-GeoIP-LatLong
X-Uri
TWC-Connection-Speed
X-Tumblr-Pixel-2
TWC-Device-Class
X-Proxy-Build
Webcakes-Region
X-Format
X-Fetched-On
Webcakes-App-Version
X-Origin-Hint
TWC-Locale-Group
TWC-Privacy
X-Debug
X-Tumblr-Pixel-3
Webcakes-App-Name
Fastcgi-Useragent
Property-Id
X-MCACHE
Selected-Fe
Uber-Trace-Id
X-Zen-Fury
X-LSADC-Cache
X-Endurance-Cache-Level
X-Redis-Cache
Source
X-Ua
CDN-RequestId
X-Ratelimit-Reset
X-Sucuri-ID
X-Sucuri-Cache
X-Srv
X-NGENIX-Cache
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
Section-Io-Origin-Status
X-B3-SpanId
Section-Io-Id
X-Drupal-Cache-Contexts
X-Oracle-Dms-Rid
X-S
X-Oracle-Dms-Ecid
X-Origin-Date
X-Upgrade-Enabled
X-Pass-Why
X-MP-GENERATED-AT
X-TimeS
X-FTR-Request-ID
Fastly-Drupal-HTML
X-Varnish-Hits
X-Origin-CC
X-Origin-TTL
X-Cache-Expired-At
Upgrade-Insecure-Requests
Liferay-Portal
NGB
X-Real-IP
X-Akamai-Transformed
X-Newrelic-Synthetics
X-Handled-By
X-CACHE-AGE
X-GEO
X-Cache-TTL-Remaining
X-Optimistic-Header
X-UA-Device-Type
X-Xfnlog-Site
Apigw-Requestid
X-Cms-Context
X-Reqid
X-Restarts
ServedBy
X-Hl-Ver
X-Node-Name
X-Via-JSL
X-Cache-Type
CDN-CachedAt
CDN-Cache
X-Cache-Host
CDN-PullZone
CDN-Uid
CDN-RequestPullSuccess
CDN-RequestPullCode
CDN-RequestCountryCode
CDN-EdgeStorageId
X-CSRF-Token
X-Pubstack
X-ProxyCache-Status
X-RTag
X-ProxyCache-Key
X-BYPASS-REASON
X-No-Session
MS-CV
Ms-Operation-Id
X-Tx-Id
X-Varnish-Ttl
X-ID
WP-Super-Cache
X-VWS-Id
X-Parent-Response-Time
X-LJ-Flow-ID
X-Server-W
X-IPLB-Instance
X-Cluster
X-IPLB-Request-ID
X-AWS-Id
N-Cache
Meta-Geo-Continent
BehaviorPad-Version
Ngx.Var.Host
MD5-Digest
Odigeo-Trace-Id
Canary
X-Worker
Ha-Gx-Prefs
HA-Ipaddr
Gannett-Cam-Experience-Id
Fastly-SSL
DCR-Processing-Time-Ms
L
L5d-Success-Class
DCR-Decision-By
X-We-Are-Hiring
Magicmarker
Lang
Xc-Version
Candidate-Md5Url
X-Viewer-Country
X-CF-Lambda-Version
X-CF-Lambda-Fn
X-CGP
X-Rojux
X-Conf
X-Request-Host
X-CacheTTL
X-S-Cookie
X-SD-PageType
X-BCube-Filmed-By
X-ScT
X-Bl-Debug
X-Cache-NE
X-FC-Vary-Parameters
X-Csrf-Jwt
X-Eu-Site
X-Dispatcher-Number
X-Ec-Custom-Error
X-Ec-Fail
X-Ec-GeoHdr
X-External-Request-Id
X-Fastly-Backend
X-Debug-Cache-Fetch
X-D
X-Debug-Cache-Store
X-Destination
X-Developer
X-Slack-Backend
X-B-Cookie
X-Epic-Correlation-Id
True-Client-Country-4JS
Vix-Hermes-Req-Id
W
Web-Mar-Region
T-Server
Surrogated-Key
Rendered-Blocks
Redirect-Candidate
Server-Host
Sslversion
X-Vtex-Remote-Cache
X-Vdms-Version
X-Vdms-Path
X-Aed
X-A-Wwc
X-App
X-App-Name
X-Application
X-A-Dgt
X-A-Dcw
X-SRCache-Key
X-A
X-Slack-Shared-Secret-Outcome
X-A-Ccd
X-A-Dam
Origin-Agent-Cluster
X-Bc-Bl
X-AB
X-Proxy-Cache-Status
X-Orig-Expires
X-Cache-Info
X-Origin-Time
X-PAYTM-SRV-ID
X-Owner
X-DefElseHash
X-Org
X-NodeID
X-Node-Id
X-Nyt-Route
X-Old-Content-Length
X-Alternate-Cache-Key
Origin
Mail-Subject
X-Date
X-Refresh
X-RateLimit-Remaining-Second
X-Request-Time
X-Gdpr
X-Core-Value
X-S-Maxage
Is-Eu
X-RateLimit-Limit-Second
X-Policy
X-Platform
X-Pool
X-B3-Spanid
X-Qloud-Router
X-Nitro-Cache
Platform
X-Hash
X-Forwarded-Path
Thinkindot-Control
Thinkindot-CacheControl-Type
TDXMobile
Thinkindot-CacheControl
X-GeoIP-Region-Code
X-GeoIP-Country-Code
X-Geo-Header
X-Generated-On
We-Hiring
VNS-Cache
VNS-Age
X-Human
X-DPWN-IS-SECURE
X-Nananana
X-Accel-Expires-Debug
Req-Svc-Chain
X-DefHash
Producers
Release
X-Mvc-Supplant-Cachable
X-Mly-Id
X-Level-Front-Cache
X-Irp-Debug
X-Loc
X-Mid
X-Accel-Buffering
X-Server-IP
Gh-Request-Id
X-Wix-Viewer-Type
X-Thanos
X-Thinkindot-L3
X-Up
X-Var-Ttl
X-Test
Adler-Geo
X-Bip
X-Wikidot-Backend
Content-Secure-Policy
X-ShardId
AKAMAI
X-Variation
X-Varnish-CookieHashed-On
X-VServer
X-Vmg-Version
X-Wikidot-Static-Cache
X-Cache-Bucket
X-Cache-Debug
X-Cdn-Origin
X-VG-WebCache
X-Varnish-Remaining-TTL
X-Varnish-CookieINHashed-On
X-Varnishpool
X-Cache-Status-Check
X-VG-TLSProxy
X-SVT-ORM-VERSION
X-Tenant
Datacenter
X-Micro-Cache
CPC-Cache
CPC-Age
Cmstype
X-Clientip
X-ShopId
X-CMSURLCustom
Fastly-Backend-Name
X-Core-Mission
Expect-Staple
Environment
X-Shop-Environment
X-SVT-ORM-RULES
Cmsid
Cache-Provider
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Storefront-Renderer-Rendered
X-BBC-Edge-Cache-Status
X-Sn-Servicetimems
X-Shopify-Stage
Cf-Device-Type
Host-ID
User-Cache-Control
X-TIME
X-Cdn-Diag
X-Forwarded-Site
X-From
X-Akamai-Device-Characteristics
X-Clara-WADP
X-ApacheServer
X-Auto-Login
X-Correlation-ID
X-Cdn-Srv
X-Dispatcher-Server
X-Device-Os
X-Block-Status
X-Fmm-Version
X-Origin
Country-Code
CloudFront-Viewer-Country
DSUID
Esi-Enabled
X-Gen-Mode
Fastly-GeoIP-CountryCode
CDCHOST
Apple-News-Services-Request-Url
X-WADP-Cache
Cache-Name
X-WA-Info
Apple-News-Services-Handled
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
X-PERF
X-Geo-Region
Sever-Int
X-Origin-Response-Time
X-INCAP-ABP
X-Hnp-Log
X-GeoIP
X-Mvc-Supplant-OutputCached
Server-Hostname
X-Nginx-Cache-Key
NM-Fastcgi-Cache
Server-Ext
X-TraceId
X-Section
X-Instance-Name
X-Gzip
X-Esi-Check
X-NCache
X-Op-Id-All
X-LB-NoCache
Server-Info
NGX
Machine
C-Via
X-Cache-Id
X-Access
X-Datadome
Wxu-Next-Region
X-Cache-Enabled
Ssr
X-AIR-PT
Pics-Label
Wxu-Next-Commit
Wxu-Next-Hostname
X-Vcl-Version
X-Vgn-Hpd-Reason
X-Via-Fastly
X-Amz-Meta-Cb-Modifiedtime
X-Fastly-Request-Id
Server-ID
X-API-Version
X-Accel-Version
AMP-Access-Control-Allow-Source-Origin
X-CACHE-GROUP
X-Varnish-Beresp-Ttl
X-Dc
Memcached
X-JWT-State
X-HA-Backend
X-Has-Esi
X-Is-Gdpr
X-Varnish-Beresp-Grace
X-Is-Desktop
X-Is-Tablet
X-Is-Mobile
X-Is-Supported-Browser
X-Browser-Name
X-Tcp-Rtt
Hostname
X-SIPLIST1
Time
IsBot
Memory
X-Buckets
X-Platform-Cluster
Cache-Hits
Origin-CC
Sid
X-Scale
Origin-EX
X-Platform-Processor
X-Platform-Router
Location
CF-Ctrl
X-PHP-Backend
YJS-ID
X-Air-Hostname
X-Air-Source
Cdn-Requestid
X-TIM-N
X-B3-Parentspanid
X-ZONE
X-Zone
X-Air-Trace-Id
X-Wp-Cf-Super-Cache-Active
X-Presslabs-Stats
X-Fpc
X-Cached-By
X-Tb-Optimization-Total-Bytes-Saved
X-WP-CF-Super-Cache-Active
X-DC
X-Backend-Instance
X-Internal-Host
X-Origin-Cache-Key
X-Frame-Option
X-Azure-Ref-OriginShield
X-Hyper-Cache
Resin-Trace
X-Cs
X-TA-CDN-Provider
Uri
GeoIP-Latitude
X-VC
Cache-Host
Epwk-X-Cache
X-Service
X-Webstats-RespID
X-Site-Version
X-Origin-Expires
X-Microcachable
X-DataCenter
True-Client-Ip
X-LiteSpeed-Cache-Control
LB
X-NGINX-Cache
X-FTR-Cache-Status
X-Country-Code-Real
X-Info
XM
X-FTR-Expires
X-FTR-Backend
GeoIP-Country-Code
X-FTR-Backend-Server
X-FTR-Balancer
X-Nitro-Rev
X-Nitro-Cache-From
X-Locale
X-Web-Node
X-HN
PFcat
GeoIp-Country-Code
X-VarnishDD-TTL
Cdn
X-Pod-Name
X-VCache
Cdn-Host
NtCoent-Length
X-CS
X-Datacenter
X-Cache-Ttl
XServer
X-Ad-Defer-Variation
X-Edge-Server
User-Agent
Cdn-Request-Time
X-CSRF-TOKEN
X-NewRelic-App-Data
True-Client-IP
X-Via-Edge
X-Via-SSL
A
X-FL-QIT-DEBUG
X-NMSegId
Req-ID
Locid
Srvid
WZWS-RAY
M-TraceId
Edge-Copy-Time
X-Via-CDN
X-FL-EDGE
X-Geo
X-Vercel-Id
WebServer
X-SRV
X-Vercel-Cache
X-TRACE-ID
X-Ad-Load-Variation
SID
X-M-Reqid
X-MSEdge-Flight
X-MSEdge-Features
X-Moov-T
X-FireWall-Port
Fastly-Drupal-Html
X-Pad
X-ATG-Version
X-Scope-Id
X-Cache-ASPX
X-FPC
Cluster
Pramga
X-Request-Start
X-M-Log
X-Contensis-Viewer-Groups
X-Moov-Xdn-Version
X-Varnish-Authentication
X-Request-URI
Tcn
X-HostName
Cache-Key
X-Varnish-Beresp-Status
X-NWS-UUID-VERIFY
X-Qnm-Cache
X-Shield-Cache-Expires
X-LiteSpeed-Tag
CountryCode
Cf-Ipcountry
HostName
X-Api-Version
X-Cdn-Request-ID
X-APP-VERSION
X-Esi
X-Amz-Meta-Opti
X-Cache-Date
Content-Style-Type
Cdnsip
Edge-Cache
X-Air-Pt
Cdncip
Path
X-AK-Request-ID
Content-Script-Type
Cache-Tv-Group
Wpo-Cache-Message
X-TH-Server
X-Branch-Name
Wpo-Cache-Status
X-VCL-Version
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-Proxy-CacheRZ
Tube-Return
Tube-Got-Results
X-Acquia-Purge-Cdn-Unconfigured
X-Planisys-CDN-TTL
X-B3-Trace-ID
XkeyRZ
X-Aicache-OS
Yak-Timeinfo
Click-Count-Action-Start
X-Planisys-CDN-Cache
X-Render-Time
Click-Count-Error
Tube-Get-Contents
Tube-Got-Eval
X-Planisys-CDN-Rules
X-Platform-Server
X-Cache-FS-Status
X-Wa
X-Via-Popv
X-LB-ID
X-Github-Request-Id
X-HS-Content-Campaign-Id
State
X-Via-Popn
X-WP-CF-Super-Cache-Cookies-Bypass
X-Nc
X-SB
X-Req
X-Servedbyhost
X-V-Cache
X-Via-Poph
CDN
X-Upstream-Ct
X-Upstream-Ht
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-CACHE-KEY
X-Wp-Cf-Super-Cache-Cache-Control
X-Wp-Cf-Super-Cache
Geoip-Latitude
X-Tim-N
Srv
X-Vgn-Hpd-Cached
On-Server
MIME-Version
X-Vgn-Hpd-Ssi
X-Vgn-Hpd-Variations-Key
X-Vary
X-Men
X-Akamai-Pragma-Client-IP
Proxy-Connection
X-Release
V-Age
X-Fastly-Cache
X-Cdn-Forward
X-Lb-Cache
Ngx-Var-Key
X-User
X-Cache-Remote
Ohc-File-Size
Server-Id
X-Traceid
X-Generated-In
X-Rocket-Build-Number
Lb
X-Ha-Backend
X-UA
X-Sigma
X-Sigma-Backend
X-Dw-Trace-Id
X-HS-Status
CF-Cached-On
X-TT-LOGID
X-Via-Ucdn
X-Fastly-Backend-Reqs
X-Acquia-Application-Trace
X-Acquia-Application-UUID
X-Lb-Nocache
PICS-Label
X-EC-Lua
My-App
Warning
Cache
X-Acquia-Site
Ohc-Cache-HIT
X-Acquia-Purge-Tags
X-CUA
X-Iplb-Request-Id
Yjs-Id
X-Iplb-Instance
Inserted-Into-Cache-At
X-Snapshot-Date
X-Fastly-Cache-Hits
CACHE-MISS-TO-ORIGIN
X-Litespeed-Cache-Control
X-RAMCache
X-CF-Cache-Header-Cache-Control
X-Miniprofiler-Ids
Cneonction
X-Gamma-Serve
X-GoCache-CacheStatus
X-CF-Cache-Header-Vary
X-Udemy-Cache-App-Namespace
X-Cached-Since
Vha6-Origin
X-ElasticPress-Query
X-GeoIP-City
Log-Origin
Ngx
X-Scheme