Threat Level: green Handler on Duty: Guy Bruneau

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
Pragma
X-Powered-By
X-XSS-Protection
CF-RAY
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
P3P
Alt-Svc
X-Cache-Hits
X-UA-Compatible
X-Xss-Protection
X-Served-By
CF-Ray
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Request-Id
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
Access-Control-Allow-Credentials
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
X-Drupal-Cache
X-Generator
X-Cache-Status
X-Check
X-Cacheable
X-Envoy-Upstream-Service-Time
X-Request-ID
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-FRAME-OPTIONS
X-Iinfo
X-Dns-Prefetch-Control
X-Drupal-Dynamic-Cache
Feature-Policy
X-Content-Security-Policy
Content-Encoding
Access-Control-Expose-Headers
Upgrade
Status
X-CDN
X-AspNetMvc-Version
X-XSS-PROTECTION
Server-Timing
Access-Control-Max-Age
X-Amz-Request-Id
Request-Context
X-Amz-Id-2
X-Turbo-Charged-By
X-AH-Environment
X-Via
X-Robots-Tag
X-Backend
X-Cache-Group
Cf-Edge-Cache
Host-Header
Keep-Alive
X-Proxy-Cache
X-Hacker
X-Server
X-UA-Device
X-Rq
X-Server-Powered-By
X-Age
Allow
X-Vhost
X-Varnish-Cache
X-Ws-Request-Id
EagleId
X-Dispatcher
X-Amz-Version-Id
Grace
X-LiteSpeed-Cache
P3p
Cf-Apo-Via
Nel
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Page-Speed
X-Device
Cf-Railgun
EagleEye-TraceId
X-Aws-Lambda-Call-Status
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
Accept-CH
X-Pingback
X-Node
X-Host
X-WebKit-CSP
X-Server-Id
X-OneAgent-JS-Injection
Surrogate-Control
X-Backend-Server
X-CST
X-Readtime
X-Nginx-Cache-Status
X-Akam-SW-Version
X-Cache-Lookup
Permissions-Policy
X-Content-Security-Policy-Report-Only
Request-Id
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Application-Context
X-Nginx-Upstream-Cache-Status
X-Cloud-Trace-Context
X-Trace
X-Response-Time
X-Edge
X-HW
Accept-Ch-Lifetime
Accept-CH-Lifetime
X-Ua-Compatible
Content-Location
X-Mod-Pagespeed
X-Clacks-Overhead
X-Url
X-Midtier
X-Oneagent-Js-Injection
X-ECACHE
X-ESI
Rating
X-Ruxit-JS-Agent
X-Amz-Server-Side-Encryption
X-Mcache
X-Country
Xkey
X-Litespeed-Cache
X-Upstream
X-Vname
X-TtlSet
X-PC
X-Vcap-Request-Id
Cache-Tag
X-D2id
X-MS-InvokeApp
X-Rack-Cache
X-Exp-Id
X-Element-Page-Cache
X-Cdn-Fetch
Verso
X-Exp-Variant
X-Kinja-Server
X-Use-Magma
X-GoogleNews-Bot
X-Kinja-Revision
X-Kinja
X-Kinja-Build
X-Ruxit-Js-Agent
Edge-Control
X-Cache-TTL
RTSS
Fastly-Restarts
X-Powered-By-Plesk
X-VARITI-CCR
Origin-Trial
X-Ac
X-Content-Type
X-Navigation-Version
Accept-Ch
X-Abt-Application-Version
X-Cached
X-Goog-Hash
Service-Worker-Allowed
X-Country-Code
X-GitHub-Request-Id
X-Ttl
Pagespeed
X-Sol
X-Amz-Rid
X-Middleton-Display
Display
X-WebKit-CSP-Report-Only
X-Browser-Type
X-Mg-S
X-Dw-Request-Base-Id
SPRequestGuid
X-SharePointHealthScore
X-Server-Name
Cross-Origin-Opener-Policy
X-Varnish-TTL
X-B3-TraceId
Arr-Disable-Session-Affinity
X-Erf-Bev-Bev
X-Instrumentation
X-Server-Lifecycle-Phase
X-Erf-Bev-Bev-Is-Generated
X-Kraken-Loop-Name
X-Powered-CMS
AR-ATIME
Response
AR-Request-ID
AR-PoweredBy
AR-SID
X-Middleton-Response
X-Amzn-Trace-Id
SPRequestDuration
SPIisLatency
X-Cache-Key
AR-CACHE
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Fastly-Request-ID
X-Webkit-CSP
X-Version
X-HP-Trace-Id
X-HP-Webp
X-Jurisdiction
X-Cnection
X-Accel-Expires
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
Cache-Tags
X-T
Front-End-Https
Cache-Status
X-Fastcgi-Cache
Edge-Cache-Tag
X-Client-IP
X-MSEdge-Ref
Pinterest-Version
X-Pinterest-Rid
X-Times
Pinterest-Generated-By
X-Px
X-NF-Request-ID
X-Ser
X-Hits
Public-Key-Pins
Nginx-Cache
X-Recruiting
X-B3-TraceId-Primal
Mrf-Cache-Status
X-Ua-Device
MRF-Tech
X-NWS-LOG-UUID
X-B3-Traceid
X-LLID
X-Request-Received
X-Frontend
X-Request-Processing-Time
X-Shield-Request-Id
Server-Node
X-RateLimit-Remaining
Payment
X-Ua-Browser
Access-Control-Request-Method
X-Kinja-CCPA
X-DIS-Request-ID
TP-Cache
X-Erf-Stays-Pdp-Viaduct-Migration-Web
X-Webkit-CSP-Report-Only
X-Goog-Metageneration
MicrosoftSharePointTeamServices
S
X-HS-Content-Id
X-HS-Hub-Id
X-RateLimit-Limit
X-HS-Combine-CSS
X-HS-Cache-Config
TP-L2-Cache
X-LB-Cache
X-Content-Digest
X-FastCGI-Cache
Content-MD5
X-Distributor
X-PressLabs-Stats
Realpath
X-Microsite
X-Request-Handler-Origin-Region
X-Hostname
X-Ezoic-Cdn
X-Geo-Country
X-Forwarded-For
Access-Control-Allow-Method
X-Page-Id
X-FB-Debug
Accept-Charset
X-Ratelimit-Remaining
X-GUploader-UploadID
Fastcgi-Cache
X-Cluster-Name
X-Rid
X-Protected-By
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Seen-By
X-Envoy-Decorator-Operation
Cleartype
X-B3-Sampled
X-Correlation-Id
TCN
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-TEC-API-ROOT
DC
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Ratelimit-Limit
X-Newrelic-App-Data
Referer-Policy
X-Origin-Server
X-Mobile
X-Debug-Info
X-XRDS-Location
X-Origin-Cache
X-Webkit-Csp
Cross-Origin-Resource-Policy
X-TTL
X-Varnish-Backend
X-Logged-In
X-Git-Hash
X-Aspnet-Version
X-Azure-Ref
X-Server-ID
X-Edge-Location-Klb
X-Contextid
X-Varnish-Grace
X-Kinsta-Cache
X-Route-Name
Alternate-Protocol
X-Request-Guid
X-Revision
Surrogate-Key
X-Aspnet-Duration-Ms
X-Is-Crawler
X-Fb-Rlafr
X-Flags
X-Grace
X-Amz-Replication-Status
X-App-Environment
X-Providence-Cookie
X-Content-Options
Count-Hit
X-TT
Healthy
X-Amz-Meta-S3cmd-Attrs
X-IPS-LoggedIn
X-Wix-Request-Id
X-Forwarded-Proto
X-Whom
X-App-Server
Frame-Options
X-Hosted-By
Charset
X-Akamai-Edgescape
WPO-Cache-Status
WPO-Cache-Message
MS-Author-Via
Viewport
Filterid
X-Daa-Tunnel
X-Id
X-B
Paypal-Debug-Id
X-Magnolia-Registration
X-Client-Ip
X-Backend-Name
Retry-After
X-Cache-Age
Section-Io-Cache
X-F-Cache
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Az
X-AppVersion
X-Activity-Id
SRV
X-Cache-Control
X-Trace-Id
X-Proxy-Cache-Info
X-Www-Served-By
Server-Name
X-Type
Amp-Access-Control-Allow-Source-Origin
X-App-Version
X-Oracle-Dms-Ecid
Refresh
X-Varnish-Server
Akamai-GRN
X-Oracle-Dms-Rid
X-ARC
X-Http-Reason
X-Response-Served-From
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
SD-X-WS
X-Rule
X-Proxy
X-Time
X-Original-Request-Id
Host
X-Instance
X-Cache-Rule
X-User-Agent
X-Akamai-Request-ID2
Version
Protected
X-UUID
Front
X-Edge-Location
X-RateLimit-Reset
X-Rocket-Nginx-Serving-Static
X-Varnish-Age
X-Status
X-Cache-Grace
X-Rendered-As
Fastly-SWR
X-Cacheable-TTL
Fastly-SIE
From-Origin
X-Unique-Id
X-Environment-Context
X-Page-View
X-FW-Static
X-Is-Bot
X-Region
X-FW-Serve
X-EdgeConnect-Cache-Status
X-L-Path
X-FW-Type
X-FW-Version
X-FW-Server
X-Jobs
X-Framework
X-FW-Dynamic
X-COUNTRY
X-FW-Hash
X-Cache-Time
Access-Control-Request-Headers
X-Adobe-Loc
X-Adobe-Content
X-N
X-G
X-Tumblr-Pixel-1
X-Tumblr-Pixel
X-RemovedCookies
X-ProcessESI
X-Tumblr-User
X-Tumblr-Pixel-0
ServerID
X-Load-Cache
X-Upgrade-Enabled
X-Nf-Request-Id
X-Source
X-Varnish-Ttl
X-Language
Country
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
X-Datadog-Trace-Id
Content-Disposition
X-Vcache
X-CDN-Forward
X-Drupal-Cache-Tags
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-HTML-Minification-Powered-By
X-Datadog-Sampled
Accept-Language
X-Mg-Request-UUID
Countrycode
X-Tt-Trace-Host
X-Amzn-Remapped-Content-Length
X-Tt-Trace-Tag
X-Debug-IsConnected
X-DynaTrace
X-Debug-IsPreview
X-ID
X-Xrds-Location
X-Generated-By
X-DataDome
X-DynaTrace-JS-Agent
Backend
X-ECache
Xet-Cookie
Liferay-Portal
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
X-Signature
X-B-Cache
CF-IPCountry
Webserver
X-Nginx-Cache
Xserver
X-Httpd
X-Tt-Logid
X-B3-SpanId
X-NYM-Debug-Backend
X-Mode
X-Erf-Web-Scheduler
X-Drupal-Cache-Contexts
X-Device-Type
X-Content-Powered-By
X-Servername
X-Content-Age
Url
X-Zen-Fury
Azure-RegionName
Azure-SlotName
Azure-SiteName
GEO-INFO
Load-Balancing
Azure-Version
Filters
X-Cache-Operation
X-Tb
Fastcgi-Useragent
Azure-InstanceId
X-JoinUs
X-LAGOON
X-ServerID
X-Git-Commit
X-GeoCountry
X-GeoCode
X-SayCDN-TTL
Locale
X-SaId
X-Say-TTL
X-Rewrite-Enabled
X-Proto
X-Say-Cacheable
X-Varnish-Cache-Hits
X-UPSTREAM-Address
X-Cache-Action
X-Sucuri-ID
X-Sucuri-Cache
Onion-Location
X-Urbn-Context-Path
X-Director
X-Urbn-Site-Id
X-Container-Uri
Meta-Geo
S-Rt
X-VC-Cache
X-Varnish-Hostname
X-Soup
X-PHP-Host
X-RM-Cache-TTL
X-Cluster-Node
Uber-Trace-Id
X-Labrador-Cache-Channel
X-Forwarded-Host
X-Adobe-Source
X-Sql-Count
X-Sql-Duration-Ms
X-Storage
X-Ms-Version
X-Cache-Server
X-Served-From
X-Ms-Request-Id
X-Generation-Time
X-VCT
X-Detected-As
X-Logging-Id
Web-Mar-Node
TWC-Locale-Group
TWC-GeoIP-LatLong
TWC-Privacy
Webcakes-App-Name
Webcakes-App-Version
TWC-GeoIP-Country
TWC-Device-Class
Mn-Server-Ip
Node
Property-Id
TWC-Connection-Speed
Webcakes-Region
X-Debug
X-Tec-Api-Root
X-Tec-Api-Version
X-Tec-Api-Origin
X-Skip-Cache
X-Zipkin-Id
X-Routing-Service
X-R9-Blue-Green-Version
X-Extlb
X-FB-TRIP-ID
X-Origin-Hint
X-Proxied
DB-Nickname
X-RCS-CacheZone
X-Proxy-Build
X-Fetched-On
Selected-Fe
X-Tumblr-Pixel-3
X-Timing-Wait
X-Tumblr-Pixel-2
X-Format
X-Uri
X-LSADC-Cache
X-Lambda-Id
CDN-RequestId
X-Template
Fastly-Drupal-HTML
OT-Force-Account-Verify
X-Origin-Date
X-Ratelimit-Reset
Source
X-MP-GENERATED-AT
X-XRDS-LOCATION
X-MCACHE
X-Cache-Expired-At
X-Loop
X-Cache-Hit
X-Tncms
X-Srv
X-Varnish-Hits
X-Pass-Why
X-Endurance-Cache-Level
X-Via-JSL
X-TimeS
Content-Secure-Policy
X-Cache-TTL-Remaining
X-NGENIX-Cache
X-Redis-Cache
X-Ua
X-UA-Device-Type
X-Node-Name
Upgrade-Insecure-Requests
Cross-Origin-Window-Policy
X-Pubstack
X-Real-IP
X-Fastly-Request-Id
X-AIR-PT
X-Origin-CC
X-Origin-TTL
Section-Io-Origin-Status
X-CCDN-Origin-Time
Section-Origin-Responded
Section-Io-Id
X-CCDN-CacheTTL
X-Server-W
X-Hcs-Proxy-Type
Section-Io-Origin-Time-Seconds
X-Datadome
NGB
X-S
Cache-Hits
X-PHP-Backend
X-Rn-Rsrv
Cache-Provider
X-Cache-Host
CDN-RequestCountryCode
X-GEO
CDN-PullZone
X-URL
CDN-CachedAt
X-RTag
CDN-EdgeStorageId
CDN-Cache
CDN-RequestPullCode
Cache-Name
X-CSRF-Token
MS-CV
Ms-Operation-Id
CDN-RequestPullSuccess
CDN-Uid
X-Reqid
X-Restarts
X-Cms-Context
Apigw-Requestid
X-Xfnlog-Site
X-Aspnetmvc-Version
X-Cache-Type
X-Hl-Ver
X-IPLB-Instance
X-IPLB-Request-ID
X-Optimistic-Header
X-Akamai-Transformed
X-ProxyCache-Status
X-BYPASS-REASON
X-No-Session
X-CACHE-AGE
X-ProxyCache-Key
X-Newrelic-Synthetics
X-Parent-Response-Time
Surrogated-Key
X-A-Dcw
X-A-Dgt
Gannett-Cam-Experience-Id
Gh-Request-Id
X-A-Wwc
X-A-Dam
Fastly-SSL
DCR-Decision-By
CPC-Age
Candidate-Md5Url
Canary
X-Accel-Expires-Debug
CPC-Cache
Ha-Gx-Prefs
Fastly-Backend-Name
DCR-Processing-Time-Ms
X-Accel-Buffering
Fastly-GeoIP-CountryCode
L5d-Success-Class
N-Cache
Ngx.Var.Host
VNS-Age
VNS-Cache
Meta-Geo-Continent
Server-Host
Odigeo-Trace-Id
T-Server
Redirect-Candidate
True-Client-Country-4JS
Vix-Hermes-Req-Id
MD5-Digest
W
Web-Mar-Region
Rendered-Blocks
L
X-A
Lang
We-Hiring
Sslversion
Mail-Subject
X-Aed
Magicmarker
HA-Ipaddr
X-Debug-Cache-Fetch
X-Viewer-Country
X-Is-Gdpr
X-Irp-Debug
X-JWT-State
X-Mvc-Supplant-Cachable
X-Orig-Expires
X-Nyt-Route
X-Vtex-Remote-Cache
X-Has-Esi
X-FC-Vary-Parameters
X-Fastly-Backend
X-Forwarded-Path
X-Gdpr
X-GeoIP-Region-Code
X-GeoIP-Country-Code
X-Origin-Time
X-Policy
X-Var-Ttl
X-Vdms-Path
X-Vdms-Version
X-Tenant
X-Shop-Environment
X-Slack-Backend
X-SRCache-Key
X-SD-PageType
X-VG-WebCache
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-Request-Host
X-Rojux
X-ScT
X-S-Cookie
X-External-Request-Id
X-Eu-Site
X-CF-Lambda-Fn
X-Cdn-Diag
X-CacheTTL
X-CF-Lambda-Version
X-CGP
X-Csrf-Jwt
X-Conf
X-Cache-NE
X-Cache-Info
X-B-Cookie
X-Application
X-Bc-Bl
X-BCube-Filmed-By
X-Cache-Bucket
X-Bl-Debug
X-D
X-Date
X-Wikidot-Backend
X-Ec-Custom-Error
X-Wikidot-Static-Cache
X-Ec-Fail
X-We-Are-Hiring
X-Epic-Correlation-Id
X-Ec-GeoHdr
BehaviorPad-Version
X-Dispatcher-Number
X-Worker
X-Slack-Shared-Secret-Outcome
X-Debug-Cache-Store
X-Destination
X-Developer
X-Wix-Viewer-Type
Xc-Version
X-A-Ccd
X-LJ-Flow-ID
X-Via-Fastly
X-VWS-Id
X-AWS-Id
X-Cluster
X-Handled-By
X-Access
X-Section
X-Proxy-Cache-Status
X-Esi-Check
X-DPWN-IS-SECURE
X-DefHash
X-VServer
X-DefElseHash
X-TA-CDN-Provider
X-Fmm-Version
X-Human
X-INCAP-ABP
X-Level-Front-Cache
X-Hash
X-Gzip
X-Forwarded-Site
X-Generated-On
X-Geo-Header
X-Core-Value
X-Core-Mission
X-App-Name
X-Auto-Login
X-App
X-ApacheServer
X-Alternate-Cache-Key
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
Thinkindot-Control
X-BBC-Edge-Cache-Status
X-WADP-Cache
X-Clara-WADP
X-Clientip
X-CMSURLCustom
X-Cdn-Origin
X-Cache-Id
X-Bip
X-Cache-Debug
X-Mid
X-Nitro-Cache
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-Test
X-Storefront-Renderer-Rendered
X-Sorting-Hat-ShopId
X-Shopify-Stage
X-Sn-Servicetimems
X-Sorting-Hat-PodId
X-Thanos
X-Thinkindot-L3
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
X-Varnishpool
X-Varnish-CookieHashed-On
X-Variation
X-TIM-N
X-Up
X-ShopId
X-ShardId
X-Org
X-Origin-Response-Time
X-Owner
X-Old-Content-Length
TDXMobile
X-VG-TLSProxy
X-Node-Id
X-PAYTM-SRV-ID
X-PERF
X-Request-Time
X-S-Maxage
X-Server-IP
X-Qloud-Router
X-Pool
X-Platform
X-Vmg-Version
X-Mly-Id
X-Loc
Machine
Adler-Geo
Environment
Cmstype
Cmsid
Expect-Staple
Origin
AKAMAI
Platform
Is-Eu
Req-Svc-Chain
Release
Host-ID
Producers
Datacenter
Memcached
User-Cache-Control
ServedBy
X-Origin
X-Nananana
X-Mvc-Supplant-OutputCached
Apple-News-Services-Parsed-Url
Server-Ext
X-Block-Status
X-Cdn-Srv
Apple-News-Services-Host
X-Akamai-Device-Characteristics
CDCHOST
Apple-News-Services-Request-Url
NM-Fastcgi-Cache
X-NodeID
Esi-Enabled
X-Hnp-Log
X-Dispatcher-Server
Country-Code
Server-Hostname
X-GeoIP
X-Gen-Mode
Sever-Int
X-From
Apple-News-Services-Handled
X-Nginx-Cache-Key
CloudFront-Viewer-Country
X-WA-Info
X-Scale
DSUID
X-Presslabs-Stats
X-Device-Os
X-Correlation-ID
X-Vcl-Version
X-Tx-Id
Pics-Label
X-Instance-Name
X-Cache-Enabled
Origin-EX
Origin-CC
X-LB-NoCache
C-Via
X-Refresh
Wxu-Next-Hostname
Wxu-Next-Commit
Wxu-Next-Region
X-Cs
X-Web-Node
WP-Super-Cache
Ssr
X-Op-Id-All
X-NCache
Server-Info
X-TIME
AMP-Access-Control-Allow-Source-Origin
X-Air-Hostname
X-Air-Source
X-Air-Trace-Id
Time
Memory
X-Azure-Ref-OriginShield
Server-ID
X-Amz-Meta-Cb-Modifiedtime
X-Cache-Status-Check
X-HA-Backend
Hostname
X-API-Version
X-ZONE
Cf-Device-Type
X-Platform-Cluster
NGX
X-Microcachable
X-Platform-Router
X-Origin-Expires
Origin-Agent-Cluster
GeoIP-Latitude
X-Platform-Processor
Cache-Host
X-VHOST
X-Dc
X-Tb-Optimization-Total-Bytes-Saved
XM
X-CACHE-GROUP
X-Site-Version
X-Locale
X-HN
PFcat
X-VarnishDD-TTL
X-Wp-Cf-Super-Cache-Active
X-Varnish-Beresp-Ttl
X-Varnish-Beresp-Grace
X-Fpc
Resin-Trace
X-DC
X-Ad-Defer-Variation
Cdn-Requestid
X-FL-QIT-DEBUG
X-Via-CDN
X-Via-Edge
A
X-Micro-Cache
X-Internal-Host
Locid
Srvid
X-FL-EDGE
X-Vgn-Hpd-Reason
X-Via-SSL
X-Webkit-Csp-Report-Only
Edge-Copy-Time
YJS-ID
X-Zone
X-WP-CF-Super-Cache-Active
Sid
X-TraceId
X-Contensis-Viewer-Groups
X-ATG-Version
X-Cache-ASPX
X-Github-Request-Id
X-Upstream-Ht
X-Upstream-Ct
X-Pod-Name
X-FireWall-Port
X-B3-Spanid
X-AB
X-Cached-By
X-Moov-Xdn-Version
True-Client-Ip
Uri
User-Agent
X-DataCenter
X-Varnish-Authentication
Cache-Key
X-Moov-T
X-Buckets
X-LiteSpeed-Cache-Control
Location
X-Info
IsBot
GeoIP-Country-Code
X-B3-Parentspanid
X-SIPLIST1
X-Geo-Region
X-Backend-Instance
State
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Accel-Version
X-Nitro-Cache-From
X-NGINX-Cache
X-Planisys-CDN-Cache
X-HS-Content-Campaign-Id
X-Platform-Server
X-Nitro-Rev
X-FTR-Request-ID
X-Provided-By
X-LiteSpeed-Tag
X-MSEdge-Features
X-MSEdge-Flight
X-Release
X-Datacenter
X-Fastly-Cache
GeoIp-Country-Code
CF-Ctrl
SID
X-VCache
X-Cache-Remote
X-Sigma-Backend
X-Rocket-Build-Number
X-CS
XServer
X-VC
X-Sigma
Cdn
X-Tcp-Rtt
X-Is-Supported-Browser
X-Is-Mobile
X-Geo
X-Is-Desktop
X-Is-Tablet
X-RN-RSRV
Lb
NtCoent-Length
X-Browser-Name
X-CSRF-TOKEN
X-NewRelic-App-Data
True-Client-IP
X-Vgn-Hpd-Variations-Key
Path
X-Vgn-Hpd-Ssi
X-Vgn-Hpd-Cached
Cache
X-Api-Version
X-Generated-In
X-Gamma-Serve
Epwk-X-Cache
X-GeoIP-City
X-TRACE-ID
X-HS-Status
X-Hyper-Cache
X-Scheme
Fastly-Drupal-Html
X-FPC
X-HostName
Tcn
X-Service
X-SRV
Ohc-File-Size
X-GoCache-CacheStatus
X-Frame-Option
Cache-Tv-Group
X-Webstats-RespID
Serverid
X-Rebelmouse-Surrogate-Control
X-APP-VERSION
CountryCode
Cf-Ipcountry
X-UA
X-Rebelmouse-Cache-Control
X-Air-Pt
X-AK-Request-ID
Cdncip
X-Amz-Meta-Opti
Cdnsip
X-Esi
Kp-EeAlive
Srv
X-Guploader-Uploadid
X-Traceid
X-EC-Lua
X-Branch-Name
X-Wp-Cf-Super-Cache-Cache-Control
X-Pad
X-Wp-Cf-Super-Cache
WebServer
X-Location
X-Mobile-URL
HostName
X-Cache-Ttl
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-Region-Sid
Env
On-Server
X-Cache-Tags
X-Proxy-CacheRZ
Cdn-Request-Time
Cdn-Host
Ohc-Cache-HIT
X-Vercel-Cache
Yak-Timeinfo
WZWS-RAY
X-Men
X-Aicache-OS
X-Edge-Server
X-Vc
XkeyRZ
X-Cdn-Cache-Status
X-Developers
CacheControlHeader
X-Vercel-Id
Proxy-Connection
CDN
X-VCL-Version
X-Origin-Cache-Key
X-TX-ID
X-CACHE-KEY
X-FTR-Expires
X-NMSegId
X-SB
X-Acquia-Purge-Cdn-Unconfigured
X-Akamai-Pragma-Client-IP
X-Servedbyhost
X-FTR-Cache-Status
LB
X-Req
Tube-Got-Results
Tube-Return
Tube-Got-Eval
M-TraceId
Tube-Get-Contents
Req-ID
V-Age
RNT-Time
X-Edge-Pop
Click-Count-Action-Start
Click-Count-Error
X-FTR-Balancer
X-CDN-Cache-Status
X-Nc
X-Cdn-Forward
X-Wa
Mime-Version
X-Minions-Version
X-Via-Poph
X-Via-Popn
X-V-Cache
X-Via-Popv
X-Cache-FS-Status
X-FTR-Backend-Server
Geoip-Latitude
RNT-Machine
X-LB-ID
X-Country-Code-Real
X-B3-Trace-ID
Ngx
X-NWS-UUID-VERIFY
X-FTR-Backend
X-Lb-Cache
X-Cdn-Request-ID
Server-Id
X-WP-CF-Super-Cache-Cookies-Bypass
ENV
X-Fastly-Country-Code
X-Ha-Backend
CF-Cached-On
WWW-Authenticate
Content-Style-Type
X-Ad-Load-Variation
Content-Script-Type
Cluster
X-TT-LOGID
PICS-Label
X-M-Log
X-Lb-Nocache
X-M-Reqid
X-MiniProfiler-Ids
X-Snapshot-Date
X-Acquia-Site
X-Check-Cacheable
X-IN-APIGATEWAYSSL
X-User
X-IN-APIGATEWAY
X-Edge-POP
X-Dw-Trace-Id
X-Via-Ucdn
X-Acquia-Application-Trace
X-Acquia-Application-UUID
X-Acquia-Purge-Tags
Pramga
X-Scope-Id
X-Request-Start
Yjs-Id
X-Varnish-Beresp-Status
X-Tim-N
X-Qnm-Cache
X-Request-URI
X-Shield-Cache-Expires
X-Iauth-Set-Uid
X-APP
CACHE-MISS-TO-ORIGIN
Inserted-Into-Cache-At
X-Fastly-Backend-Reqs
X-Ckpd-Fst-Backend
X-Processor
X-TH-Server
X-Fastly-Cache-Hits
Vha6-Origin
X-RAMCache
X-Miniprofiler-Ids
Log-Origin
X-Litespeed-Cache-Control
X-Cached-Since
X-ElasticPress-Query
Cneonction