Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
X-Powered-By
Pragma
CF-RAY
X-XSS-Protection
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
Alt-Svc
X-Xss-Protection
P3P
X-Cache-Hits
X-UA-Compatible
X-Served-By
CF-Ray
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
Access-Control-Allow-Credentials
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
X-Drupal-Cache
X-Cache-Status
X-Generator
X-Check
X-Cacheable
X-Envoy-Upstream-Service-Time
X-FRAME-OPTIONS
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Iinfo
X-Dns-Prefetch-Control
X-Drupal-Dynamic-Cache
Feature-Policy
X-Content-Security-Policy
Server-Timing
Access-Control-Expose-Headers
Content-Encoding
X-XSS-PROTECTION
Status
X-CDN
Upgrade
X-Request-ID
X-AspNetMvc-Version
Access-Control-Max-Age
X-Amz-Request-Id
X-Amz-Id-2
Request-Context
X-Via
X-Turbo-Charged-By
X-Backend
X-Cache-Group
X-AH-Environment
X-Robots-Tag
Cf-Edge-Cache
Keep-Alive
Host-Header
X-Hacker
X-UA-Device
X-Proxy-Cache
X-Vhost
X-Server
X-Rq
X-Server-Powered-By
Allow
X-Ws-Request-Id
X-Age
X-Varnish-Cache
X-Dispatcher
EagleId
X-Amz-Version-Id
P3p
Nel
Grace
X-LiteSpeed-Cache
Cf-Apo-Via
Cf-Railgun
X-Page-Speed
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
EagleEye-TraceId
X-Swift-SaveTime
X-Swift-CacheTime
X-Aws-Lambda-Call-Status
Ali-Swift-Global-Savetime
X-Pingback
X-OneAgent-JS-Injection
X-Host
X-Node
Accept-CH
X-WebKit-CSP
X-CST
X-Cache-Lookup
X-Backend-Server
X-Server-Id
Surrogate-Control
X-Readtime
X-Nginx-Cache-Status
Permissions-Policy
X-Nginx-Upstream-Cache-Status
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Akam-SW-Version
Request-Id
X-Application-Context
Accept-CH-Lifetime
X-Content-Security-Policy-Report-Only
X-Cloud-Trace-Context
X-Response-Time
X-Ua-Compatible
X-HW
X-Trace
Xkey
X-Edge
Content-Location
X-Clacks-Overhead
X-Ruxit-JS-Agent
X-Mod-Pagespeed
Rating
X-Url
X-ESI
X-Midtier
X-Amz-Server-Side-Encryption
X-ECACHE
X-Oneagent-Js-Injection
X-Mcache
Accept-Ch-Lifetime
X-Country
Cache-Tag
X-Upstream
X-MS-InvokeApp
X-Vcap-Request-Id
X-Rack-Cache
X-D2id
X-Litespeed-Cache
X-Powered-By-Plesk
Verso
X-Exp-Id
X-Cdn-Fetch
X-Exp-Variant
X-Kinja-Build
X-Use-Magma
X-Kinja-Server
X-Kinja-Revision
X-Kinja
X-GoogleNews-Bot
X-Element-Page-Cache
Edge-Control
Accept-Ch
X-PC
X-TtlSet
X-Vname
RTSS
X-Ruxit-Js-Agent
Service-Worker-Allowed
X-Ac
X-Country-Code
Origin-Trial
X-WebKit-CSP-Report-Only
X-VARITI-CCR
Fastly-Restarts
X-Goog-Hash
X-Navigation-Version
X-Abt-Application-Version
X-Cache-TTL
X-GitHub-Request-Id
X-Cached
X-Browser-Type
X-Amz-Rid
X-Varnish-TTL
X-Aspnetmvc-Version
Cross-Origin-Opener-Policy
Pagespeed
X-Middleton-Display
Display
X-Sol
X-Kinja-CCPA
X-Webkit-CSP
X-Dw-Request-Base-Id
X-Server-Name
SPRequestGuid
X-SharePointHealthScore
X-Amzn-Trace-Id
X-Ttl
X-NWS-LOG-UUID
X-Content-Type
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-Powered-CMS
SPIisLatency
SPRequestDuration
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Server-Lifecycle-Phase
X-Mg-S
X-Kraken-Loop-Name
X-Instrumentation
AR-SID
AR-Request-ID
AR-PoweredBy
AR-ATIME
X-Cache-Key
Arr-Disable-Session-Affinity
X-Middleton-Response
Response
Pinterest-Version
Pinterest-Generated-By
X-Pinterest-Rid
X-Client-IP
X-Times
X-Fastly-Request-ID
X-Version
X-B3-TraceId
X-HP-Trace-Id
X-HP-Webp
X-B3-Traceid
X-Jurisdiction
X-Cnection
AR-CACHE
X-FastCGI-Cache
Nginx-Cache
X-T
X-Accel-Expires
X-SRCache-Store-Status
X-SRCache-Fetch-Status
Cache-Tags
X-Ser
Cache-Status
Edge-Cache-Tag
Front-End-Https
X-MSEdge-Ref
X-RateLimit-Remaining
X-Hits
X-Px
X-NF-Request-ID
Public-Key-Pins
X-Recruiting
Payment
MRF-Tech
X-LLID
X-B3-TraceId-Primal
X-Request-Processing-Time
X-Frontend
X-Request-Received
Mrf-Cache-Status
Server-Node
X-RateLimit-Limit
X-Ua-Browser
S
X-Shield-Request-Id
X-Server-ID
X-GUploader-UploadID
Content-MD5
X-DIS-Request-ID
X-Goog-Metageneration
MicrosoftSharePointTeamServices
Access-Control-Request-Method
X-PressLabs-Stats
TP-Cache
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Content-Digest
X-Daa-Tunnel
Realpath
X-Protected-By
X-HS-Content-Id
X-HS-Cache-Config
X-HS-Hub-Id
X-Fastcgi-Cache
X-HS-Combine-CSS
Fastcgi-Cache
X-Microsite
X-Request-Handler-Origin-Region
X-Distributor
X-TTL
X-LB-Cache
X-FB-Debug
Access-Control-Allow-Method
X-Forwarded-For
X-Page-Id
Accept-Charset
X-Cluster-Name
X-Rid
X-Erf-Stays-Pdp-Viaduct-Migration-Web
TP-L2-Cache
X-Hostname
X-Geo-Country
X-Ratelimit-Remaining
X-B3-Sampled
X-Ezoic-Cdn
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Seen-By
X-Aspnet-Version
X-Ua-Device
Cross-Origin-Resource-Policy
Count-Hit
Cleartype
X-Newrelic-App-Data
TCN
Referer-Policy
X-Mobile
DC
X-App-Server
X-Correlation-Id
X-Content-Options
X-Varnish-Backend
X-Kinsta-Cache
X-Edge-Location-Klb
X-Logged-In
X-Ratelimit-Limit
X-Origin-Cache
X-Git-Hash
X-Webkit-CSP-Report-Only
X-Hosted-By
X-Debug-Info
X-Contextid
X-Envoy-Decorator-Operation
X-Amz-Replication-Status
X-Fb-Rlafr
X-Revision
X-Request-Guid
X-Aspnet-Duration-Ms
X-Flags
Surrogate-Key
X-Grace
X-IPS-LoggedIn
X-Is-Crawler
X-Providence-Cookie
X-Route-Name
X-Varnish-Grace
X-App-Environment
X-TT
Frame-Options
X-Id
X-Amz-Meta-S3cmd-Attrs
Retry-After
X-Forwarded-Proto
X-Azure-Ref
X-F-Cache
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-TEC-API-VERSION
Section-Io-Cache
X-RateLimit-Reset
X-Wix-Request-Id
X-Magnolia-Registration
X-Whom
X-Origin-Server
Alternate-Protocol
Healthy
Charset
X-Xrds-Location
MS-Author-Via
X-Akamai-Edgescape
X-Proxy-Cache-Info
Viewport
WPO-Cache-Message
X-App-Version
WPO-Cache-Status
X-Nf-Request-Id
X-Backend-Name
X-COUNTRY
X-Www-Served-By
X-Az
X-Activity-Id
X-Language
Paypal-Debug-Id
X-AppVersion
X-B
SRV
X-Webkit-Csp
Filterid
X-Varnish-Server
X-Cache-Rule
X-Original-Request-Id
X-Response-Served-From
Host
SD-X-WS
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Http-Reason
X-Datadog-Trace-Id
X-Instance
X-Edge-Location
X-Rule
X-User-Agent
X-UUID
X-Cache-Grace
X-Akamai-Request-ID2
X-Datadog-Sampling-Priority
Server-Name
Akamai-GRN
Country
X-Datadog-Parent-Id
Front
ServerID
X-ARC
X-Cacheable-TTL
Protected
X-Time
X-EdgeConnect-Cache-Status
X-Environment-Context
From-Origin
X-L-Path
X-Unique-Id
X-Varnish-Age
X-Status
Amp-Access-Control-Allow-Source-Origin
X-Region
X-N
X-Jobs
Fastly-SIE
Fastly-SWR
X-Page-View
X-FW-Type
X-Rocket-Nginx-Serving-Static
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Adobe-Content
X-Adobe-Loc
X-FW-Serve
X-FW-Server
X-FW-Static
X-FW-Hash
X-FW-Dynamic
X-Is-Bot
X-FW-Version
X-Framework
X-Tumblr-User
X-Rendered-As
X-Load-Cache
X-Tec-Api-Version
X-Trace-Id
X-ProcessESI
X-DataDome
X-Tec-Api-Root
X-RemovedCookies
X-Kong-Upstream-Latency
X-Tec-Api-Origin
X-G
X-Cache-Time
X-Type
X-Kong-Proxy-Latency
X-Proxy
Access-Control-Request-Headers
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Client-Ip
Content-Disposition
X-Mg-Request-UUID
X-Datadog-Sampled
X-Amzn-Remapped-Content-Length
X-Cache-Age
X-Vcache
X-Debug-IsConnected
X-Debug-IsPreview
X-B-Cache
X-Cache-Control
X-Signature
X-CDN-Forward
X-XRDS-Location
X-ECache
Backend
Refresh
Countrycode
X-Drupal-Cache-Tags
X-DynaTrace
Accept-Language
Xet-Cookie
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
X-Nginx-Cache
X-Erf-Web-Scheduler
X-Source
X-Generated-By
X-Httpd
CF-IPCountry
X-DynaTrace-JS-Agent
X-Servername
Webserver
X-HTML-Minification-Powered-By
Url
X-XRDS-LOCATION
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Mode
Version
X-Template
X-NYM-Debug-Backend
Xserver
X-Device-Type
X-Storage
X-Content-Powered-By
X-Content-Age
GEO-INFO
X-Urbn-Context-Path
X-Rewrite-Enabled
X-JoinUs
X-LAGOON
X-Rn-Rsrv
Filters
Onion-Location
X-SaId
OT-Force-Account-Verify
X-Cache-Operation
X-Say-TTL
X-SayCDN-TTL
X-GeoCountry
X-UPSTREAM-Address
X-ServerID
X-Urbn-Site-Id
Load-Balancing
X-Director
X-Cache-Action
X-Say-Cacheable
X-GeoCode
Locale
S-Rt
Meta-Geo
X-Soup
X-Container-Uri
X-Forwarded-Host
X-Generation-Time
X-Varnish-Cache-Hits
X-Varnish-Hostname
X-Cluster-Node
X-Git-Commit
X-Tt-Logid
X-Detected-As
X-Cache-Server
X-VCT
X-Adobe-Source
Web-Mar-Node
X-Labrador-Cache-Channel
X-Ms-Version
Azure-Version
X-Ms-Request-Id
X-VC-Cache
X-Lambda-Id
X-Tb
X-Proto
Azure-SlotName
Azure-InstanceId
X-Served-From
X-RM-Cache-TTL
X-PHP-Host
Azure-RegionName
Azure-SiteName
DB-Nickname
Mn-Server-Ip
X-Format
X-Proxied
X-Tncms
X-R9-Blue-Green-Version
X-RCS-CacheZone
X-Loop
X-Zipkin-Id
X-URL
X-Sql-Count
X-Tumblr-Pixel-3
X-Skip-Cache
X-Routing-Service
Node
X-CCDN-CacheTTL
X-CCDN-Origin-Time
X-Hcs-Proxy-Type
X-Sql-Duration-Ms
X-FB-TRIP-ID
X-Extlb
X-Tumblr-Pixel-2
X-Logging-Id
TWC-Connection-Speed
X-Timing-Wait
Property-Id
Selected-Fe
TWC-Device-Class
TWC-GeoIP-LatLong
Webcakes-App-Version
X-Fetched-On
Webcakes-Region
X-Debug
Webcakes-App-Name
Uber-Trace-Id
X-Uri
X-Origin-Hint
TWC-Locale-Group
X-Proxy-Build
TWC-GeoIP-Country
TWC-Privacy
Fastcgi-Useragent
X-TimeS
X-MCACHE
X-Cache-Hit
Cross-Origin-Window-Policy
X-Zen-Fury
X-LSADC-Cache
X-Ua
X-Endurance-Cache-Level
X-Srv
Source
X-Sucuri-ID
X-Sucuri-Cache
X-Redis-Cache
X-B3-SpanId
X-Upgrade-Enabled
X-Drupal-Cache-Contexts
CDN-RequestId
Section-Io-Origin-Status
X-Oracle-Dms-Ecid
Section-Origin-Responded
Section-Io-Origin-Time-Seconds
Section-Io-Id
X-Oracle-Dms-Rid
X-MP-GENERATED-AT
X-Newrelic-Synthetics
X-Varnish-Ttl
X-NGENIX-Cache
X-Origin-Date
X-Varnish-Hits
Fastly-Drupal-HTML
X-S
Liferay-Portal
X-Ratelimit-Reset
X-Cache-Expired-At
X-Pass-Why
Upgrade-Insecure-Requests
X-Origin-TTL
X-Origin-CC
X-Real-IP
X-Akamai-Transformed
X-ID
NGB
X-Handled-By
X-Cache-TTL-Remaining
X-CACHE-AGE
X-FTR-Request-ID
X-UA-Device-Type
X-Via-JSL
X-Node-Name
Apigw-Requestid
X-Hl-Ver
X-Cache-Type
X-Pubstack
X-Cms-Context
X-Correlation-ID
X-Xfnlog-Site
X-Reqid
X-Optimistic-Header
CDN-RequestPullSuccess
X-RTag
Ms-Operation-Id
CDN-Uid
CDN-EdgeStorageId
X-CSRF-Token
CDN-Cache
CDN-RequestPullCode
MS-CV
ServedBy
X-Restarts
CDN-PullZone
X-GEO
CDN-CachedAt
CDN-RequestCountryCode
X-No-Session
X-BYPASS-REASON
X-Cache-Host
X-ProxyCache-Key
X-Server-W
X-ProxyCache-Status
WP-Super-Cache
X-Parent-Response-Time
Content-Secure-Policy
Surrogated-Key
Sslversion
Rendered-Blocks
Server-Host
Redirect-Candidate
L
Canary
Candidate-Md5Url
DCR-Decision-By
DCR-Processing-Time-Ms
BehaviorPad-Version
X-VWS-Id
X-Cluster
X-IPLB-Instance
X-IPLB-Request-ID
X-LJ-Flow-ID
Fastly-SSL
Gannett-Cam-Experience-Id
Meta-Geo-Continent
N-Cache
Ngx.Var.Host
Odigeo-Trace-Id
MD5-Digest
Magicmarker
Ha-Gx-Prefs
HA-Ipaddr
L5d-Success-Class
Lang
Origin-Agent-Cluster
X-BCube-Filmed-By
X-Nyt-Route
X-Gdpr
X-Orig-Expires
X-Origin-Time
X-Rojux
X-Request-Host
X-Forwarded-Path
X-FC-Vary-Parameters
X-Epic-Correlation-Id
X-Ec-GeoHdr
X-Eu-Site
X-External-Request-Id
X-Fastly-Backend
X-S-Cookie
X-ScT
X-Viewer-Country
X-Vdms-Version
X-Vtex-Remote-Cache
X-We-Are-Hiring
Xc-Version
X-Worker
X-Vdms-Path
X-Tenant
X-Shop-Environment
X-SD-PageType
X-Slack-Backend
X-Slack-Shared-Secret-Outcome
X-SRCache-Key
X-Ec-Fail
X-Ec-Custom-Error
X-A-Dgt
X-A-Dcw
X-A-Wwc
X-Aed
X-Application
X-App
X-A-Dam
X-A-Ccd
Vix-Hermes-Req-Id
True-Client-Country-4JS
W
Web-Mar-Region
X-A
X-Bc-Bl
X-Bl-Debug
X-Debug-Cache-Fetch
X-D
X-Debug-Cache-Store
X-Destination
X-Dispatcher-Number
X-Developer
X-Csrf-Jwt
X-Conf
X-CacheTTL
X-Cache-NE
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-CGP
T-Server
X-B-Cookie
X-AWS-Id
X-Datadome
X-Tx-Id
Release
Req-Svc-Chain
Producers
Platform
X-Node-Id
X-Nitro-Cache
X-Nananana
X-Level-Front-Cache
TDXMobile
X-Loc
X-Mid
X-Mvc-Supplant-Cachable
X-Mly-Id
X-Date
Origin
Is-Eu
X-Qloud-Router
X-RateLimit-Limit-Second
Host-ID
X-Refresh
X-RateLimit-Remaining-Second
X-Pool
X-Policy
X-Org
Thinkindot-CacheControl
X-Owner
X-PAYTM-SRV-ID
X-Platform
Mail-Subject
X-Old-Content-Length
Thinkindot-Control
X-DPWN-IS-SECURE
X-Cdn-Diag
X-Cache-Info
X-Cache-Debug
X-Bip
X-Cache-Bucket
X-Cdn-Origin
X-DefHash
X-Core-Mission
X-Core-Value
X-CMSURLCustom
X-Clientip
X-DefElseHash
X-BBC-Edge-Cache-Status
X-Generated-On
We-Hiring
X-Human
VNS-Cache
VNS-Age
Gh-Request-Id
X-Irp-Debug
X-Hash
X-GeoIP-Region-Code
X-Alternate-Cache-Key
X-Geo-Header
X-GeoIP-Country-Code
X-Accel-Expires-Debug
X-Accel-Buffering
Thinkindot-CacheControl-Type
X-NodeID
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-VServer
X-Request-Time
Adler-Geo
AKAMAI
X-Storefront-Renderer-Rendered
Cache-Provider
X-Shopify-Stage
Cf-Device-Type
X-Wikidot-Backend
X-Sn-Servicetimems
X-Sorting-Hat-PodId
X-Test
X-Proxy-Cache-Status
X-Varnish-CookieHashed-On
X-VG-TLSProxy
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
X-Varnishpool
X-VG-WebCache
X-Variation
X-Thanos
X-Vmg-Version
X-Thinkindot-L3
X-Up
X-Var-Ttl
X-Wikidot-Static-Cache
X-Sorting-Hat-ShopId
Datacenter
Fastly-Backend-Name
Fastly-GeoIP-CountryCode
CPC-Cache
Expect-Staple
Environment
X-ShardId
X-ShopId
X-Server-IP
CPC-Age
X-Wix-Viewer-Type
X-S-Maxage
Cmstype
Cmsid
X-App-Name
AMP-Access-Control-Allow-Source-Origin
X-Cache-Status-Check
User-Cache-Control
Cache-Name
X-Vcl-Version
X-TIME
X-PERF
Machine
X-Cache-Id
X-Gzip
X-Block-Status
X-GeoIP
X-Forwarded-Site
X-Micro-Cache
X-Auto-Login
X-Gen-Mode
X-Hnp-Log
X-Fmm-Version
X-From
X-Akamai-Device-Characteristics
Esi-Enabled
X-ApacheServer
X-Esi-Check
X-INCAP-ABP
Sever-Int
X-WADP-Cache
X-Mvc-Supplant-OutputCached
X-AB
X-Cdn-Srv
Server-Hostname
Server-Ext
X-Nginx-Cache-Key
X-Clara-WADP
CDCHOST
Country-Code
X-AIR-PT
X-WA-Info
Apple-News-Services-Handled
X-Origin-Response-Time
CloudFront-Viewer-Country
X-Dispatcher-Server
Apple-News-Services-Host
X-Device-Os
Apple-News-Services-Request-Url
NM-Fastcgi-Cache
Apple-News-Services-Parsed-Url
X-Origin
DSUID
X-Cache-Enabled
X-Instance-Name
Server-Info
Ssr
X-Fastly-Request-Id
X-NCache
Pics-Label
X-Section
NGX
X-Op-Id-All
X-LB-NoCache
C-Via
Wxu-Next-Region
X-Access
X-Amz-Meta-Cb-Modifiedtime
Wxu-Next-Hostname
Wxu-Next-Commit
X-B3-Spanid
X-Geo-Region
X-Dc
X-API-Version
X-JWT-State
X-Via-Fastly
X-Has-Esi
X-Is-Gdpr
Memcached
Server-ID
X-TraceId
X-ZONE
X-Accel-Version
Hostname
X-HA-Backend
X-CACHE-GROUP
X-Vgn-Hpd-Reason
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Ttl
Cache-Hits
Time
Memory
Origin-CC
X-Scale
Origin-EX
Cdn-Requestid
X-Buckets
X-PHP-Backend
X-Wp-Cf-Super-Cache-Active
X-TIM-N
X-Is-Mobile
X-Is-Tablet
X-Tcp-Rtt
X-Is-Supported-Browser
X-Is-Desktop
Sid
X-Platform-Cluster
IsBot
X-Browser-Name
X-Platform-Processor
X-Platform-Router
X-SIPLIST1
X-Air-Hostname
X-Air-Trace-Id
X-Air-Source
Location
X-Presslabs-Stats
X-Tb-Optimization-Total-Bytes-Saved
YJS-ID
CF-Ctrl
X-Internal-Host
X-Fpc
Resin-Trace
X-WP-CF-Super-Cache-Active
X-Azure-Ref-OriginShield
X-Cached-By
X-Cs
X-Backend-Instance
X-B3-Parentspanid
X-Zone
GeoIP-Latitude
X-DC
X-Origin-Expires
X-Microcachable
Cache-Host
Epwk-X-Cache
X-Hyper-Cache
X-TA-CDN-Provider
X-Frame-Option
X-VCache
X-Info
Uri
X-DataCenter
X-Site-Version
XM
True-Client-Ip
X-Web-Node
X-Origin-Cache-Key
X-LiteSpeed-Cache-Control
X-VarnishDD-TTL
X-Webstats-RespID
X-Pod-Name
X-Nitro-Cache-From
X-Nitro-Rev
X-Service
X-VC
X-NGINX-Cache
X-HN
X-Locale
PFcat
X-Ad-Defer-Variation
Cdn
User-Agent
GeoIP-Country-Code
GeoIp-Country-Code
X-FTR-Expires
X-FTR-Cache-Status
X-FTR-Backend
X-FTR-Balancer
X-Country-Code-Real
X-FTR-Backend-Server
Edge-Copy-Time
X-Geo
X-Via-Edge
X-Via-SSL
X-FL-QIT-DEBUG
A
X-Cache-Ttl
X-FL-EDGE
X-Via-CDN
X-CS
Locid
Srvid
XServer
X-Datacenter
X-NewRelic-App-Data
X-CSRF-TOKEN
LB
Cdn-Request-Time
NtCoent-Length
Cdn-Host
True-Client-IP
X-Edge-Server
X-ATG-Version
X-Varnish-Authentication
Req-ID
X-Vercel-Id
X-FireWall-Port
X-NMSegId
X-Cache-ASPX
X-Vercel-Cache
M-TraceId
X-Moov-Xdn-Version
WZWS-RAY
X-TRACE-ID
X-Webkit-Csp-Report-Only
X-Moov-T
X-Contensis-Viewer-Groups
Cache-Key
X-Pad
Fastly-Drupal-Html
X-MSEdge-Flight
X-Ad-Load-Variation
X-FPC
X-MSEdge-Features
SID
X-HostName
Tcn
Pramga
X-Request-Start
X-Scope-Id
Path
X-M-Reqid
X-SRV
WebServer
Content-Script-Type
X-M-Log
Content-Style-Type
Cluster
X-LiteSpeed-Tag
CountryCode
X-APP-VERSION
Cf-Ipcountry
X-Api-Version
X-Cdn-Request-ID
X-AK-Request-ID
X-Request-URI
Cdnsip
X-Amz-Meta-Opti
Cdncip
X-Air-Pt
X-Esi
X-Varnish-Beresp-Status
X-NWS-UUID-VERIFY
X-Shield-Cache-Expires
X-Qnm-Cache
X-Wp-Cf-Super-Cache-Cache-Control
X-Planisys-CDN-Cache
X-Upstream-Ht
X-Platform-Server
X-HS-Content-Campaign-Id
X-Wp-Cf-Super-Cache
X-Github-Request-Id
X-Cache-Date
X-Upstream-Ct
State
HostName
X-Planisys-CDN-TTL
Edge-Cache
X-Planisys-CDN-Rules
X-Branch-Name
Lb
X-Wp-Cf-Super-Cache-Cookies-Bypass
Yak-Timeinfo
X-Vgn-Hpd-Variations-Key
X-Proxy-CacheRZ
Ohc-File-Size
Cache-Tv-Group
X-Release
X-Vgn-Hpd-Cached
X-Vgn-Hpd-Ssi
XkeyRZ
X-WP-CF-Super-Cache-Cookies-Bypass
X-TH-Server
X-Fastly-Cache
X-CACHE-KEY
CDN
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
Tube-Got-Eval
Tube-Get-Contents
Tube-Got-Results
Tube-Return
X-Rocket-Build-Number
Geoip-Latitude
Srv
Click-Count-Action-Start
X-HS-Status
X-Cdn-Forward
X-Akamai-Pragma-Client-IP
Click-Count-Error
X-Nc
X-Via-Popn
X-Via-Poph
X-V-Cache
X-Servedbyhost
X-Via-Popv
X-Cache-Remote
X-Tim-N
X-Generated-In
X-Traceid
X-Wa
X-SB
X-Req
X-B3-Trace-ID
X-Aicache-OS
X-Sigma-Backend
X-Acquia-Purge-Cdn-Unconfigured
X-Cache-FS-Status
Proxy-Connection
X-Render-Time
X-LB-ID
X-Sigma
X-Lb-Cache
X-Fastly-Backend-Reqs
Ohc-Cache-HIT
X-VCL-Version
On-Server
X-Men
X-UA
X-Vary
X-User
CF-Cached-On
X-Dw-Trace-Id
Server-Id
X-Ha-Backend
V-Age
Cache
X-TT-LOGID
X-CUA
Ngx-Var-Key
MIME-Version
X-Scheme
X-Acquia-Application-Trace
X-GeoIP-City
X-Acquia-Purge-Tags
X-Gamma-Serve
X-Via-Ucdn
X-GoCache-CacheStatus
X-EC-Lua
X-Acquia-Site
X-Acquia-Application-UUID
Wpo-Cache-Status
PICS-Label
Wpo-Cache-Message
X-Lb-Nocache
X-TX-ID
Yjs-Id
X-Provided-By
X-Iplb-Request-Id
X-Iplb-Instance
X-Cdn-Cache-Status
X-Vc
Mime-Version
Warning
CACHE-MISS-TO-ORIGIN
My-App
Vha6-Origin
X-RAMCache
X-Udemy-Cache-App-Namespace
X-Miniprofiler-Ids
Cneonction
X-CF-Cache-Header-Cache-Control
X-CF-Cache-Header-Vary
Log-Origin
Ngx
X-Snapshot-Date
X-Fastly-Cache-Hits
X-Cached-Since
X-ElasticPress-Query
X-Litespeed-Cache-Control
Inserted-Into-Cache-At