Threat Level: green Handler on Duty: Guy Bruneau

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
Pragma
X-Powered-By
X-XSS-Protection
CF-RAY
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
Alt-Svc
X-Cache-Hits
X-UA-Compatible
P3P
X-Xss-Protection
X-Served-By
CF-Ray
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Request-Id
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
Access-Control-Allow-Credentials
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
X-Drupal-Cache
X-Generator
X-Cache-Status
X-Check
X-Cacheable
X-Envoy-Upstream-Service-Time
X-Request-ID
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-FRAME-OPTIONS
X-Iinfo
X-Dns-Prefetch-Control
X-Drupal-Dynamic-Cache
Feature-Policy
X-Content-Security-Policy
Content-Encoding
Access-Control-Expose-Headers
Upgrade
Status
X-CDN
X-AspNetMvc-Version
X-XSS-PROTECTION
Server-Timing
Access-Control-Max-Age
X-Amz-Request-Id
Request-Context
X-Amz-Id-2
X-Turbo-Charged-By
P3p
X-AH-Environment
X-Via
X-Robots-Tag
X-Backend
X-Cache-Group
Cf-Edge-Cache
Host-Header
Keep-Alive
X-Proxy-Cache
X-Hacker
X-Server
X-UA-Device
X-Rq
X-Server-Powered-By
X-Age
Allow
X-Vhost
X-Varnish-Cache
X-Ws-Request-Id
EagleId
X-Amz-Version-Id
X-Dispatcher
Grace
X-LiteSpeed-Cache
Cf-Apo-Via
Nel
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Page-Speed
Cf-Railgun
X-Device
EagleEye-TraceId
X-Aws-Lambda-Call-Status
X-Swift-SaveTime
X-Swift-CacheTime
X-WebKit-CSP
Ali-Swift-Global-Savetime
Accept-CH
X-Pingback
X-Host
X-Node
X-OneAgent-JS-Injection
X-Server-Id
Surrogate-Control
X-Backend-Server
X-CST
X-Readtime
X-Nginx-Cache-Status
X-Akam-SW-Version
X-Cache-Lookup
Permissions-Policy
X-Content-Security-Policy-Report-Only
Request-Id
X-Application-Context
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Nginx-Upstream-Cache-Status
X-Cloud-Trace-Context
X-Trace
Accept-Ch-Lifetime
X-Response-Time
X-Edge
X-HW
X-Ua-Compatible
Content-Location
X-Mod-Pagespeed
X-Clacks-Overhead
Accept-CH-Lifetime
X-Url
X-Ruxit-JS-Agent
X-Midtier
X-Oneagent-Js-Injection
X-ECACHE
X-ESI
Rating
X-Amz-Server-Side-Encryption
X-Mcache
X-Country
Xkey
X-Litespeed-Cache
X-Upstream
X-Vname
X-PC
X-TtlSet
X-Vcap-Request-Id
Cache-Tag
X-D2id
X-Rack-Cache
X-MS-InvokeApp
Verso
X-Exp-Variant
X-Exp-Id
X-GoogleNews-Bot
X-Kinja-Server
X-Cdn-Fetch
X-Kinja-Revision
X-Kinja-Build
X-Kinja
X-Element-Page-Cache
X-Use-Magma
X-Cache-TTL
Edge-Control
Fastly-Restarts
RTSS
X-Powered-By-Plesk
X-VARITI-CCR
Origin-Trial
X-Ac
X-Content-Type
X-Navigation-Version
Accept-Ch
X-Abt-Application-Version
X-Cached
X-Ruxit-Js-Agent
X-Goog-Hash
X-Ttl
Service-Worker-Allowed
X-Country-Code
X-GitHub-Request-Id
X-Sol
Pagespeed
Display
X-Amz-Rid
X-Middleton-Display
X-WebKit-CSP-Report-Only
X-Mg-S
X-Browser-Type
X-Dw-Request-Base-Id
X-B3-TraceId
SPRequestGuid
X-SharePointHealthScore
X-Server-Name
X-Varnish-TTL
Cross-Origin-Opener-Policy
Arr-Disable-Session-Affinity
X-Kraken-Loop-Name
X-Instrumentation
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Server-Lifecycle-Phase
X-Middleton-Response
AR-ATIME
X-Powered-CMS
AR-SID
Response
AR-PoweredBy
AR-Request-ID
X-Amzn-Trace-Id
SPRequestDuration
SPIisLatency
X-Cache-Key
AR-CACHE
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Fastly-Request-ID
X-Version
X-HP-Trace-Id
X-Jurisdiction
X-HP-Webp
X-Cnection
X-Times
X-Accel-Expires
Cache-Tags
Cache-Status
Front-End-Https
X-T
X-NF-Request-ID
X-Fastcgi-Cache
Edge-Cache-Tag
X-MSEdge-Ref
Pinterest-Version
X-Pinterest-Rid
Pinterest-Generated-By
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
X-Px
X-Ser
X-Hits
Public-Key-Pins
Nginx-Cache
X-Client-IP
X-Recruiting
X-NWS-LOG-UUID
X-B3-TraceId-Primal
X-Ua-Device
MRF-Tech
Mrf-Cache-Status
X-LLID
X-Frontend
X-Shield-Request-Id
Payment
X-Request-Received
X-Request-Processing-Time
Server-Node
X-Webkit-CSP
X-Ua-Browser
Access-Control-Request-Method
X-Kinja-CCPA
X-DIS-Request-ID
TP-Cache
X-Erf-Stays-Pdp-Viaduct-Migration-Web
X-B3-Traceid
X-RateLimit-Remaining
X-Goog-Metageneration
X-Ratelimit-Remaining
X-HS-Combine-CSS
X-HS-Cache-Config
X-HS-Hub-Id
X-HS-Content-Id
MicrosoftSharePointTeamServices
S
TP-L2-Cache
X-LB-Cache
X-Content-Digest
X-FastCGI-Cache
X-Distributor
Content-MD5
Realpath
X-PressLabs-Stats
X-Microsite
X-Request-Handler-Origin-Region
X-Server-ID
X-Webkit-CSP-Report-Only
X-Geo-Country
X-Ezoic-Cdn
Access-Control-Allow-Method
X-FB-Debug
X-Hostname
X-Page-Id
X-Forwarded-For
X-RateLimit-Limit
Accept-Charset
Fastcgi-Cache
X-GUploader-UploadID
X-Cluster-Name
X-Protected-By
X-Correlation-Id
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Rid
X-Seen-By
X-Ratelimit-Limit
X-Envoy-Decorator-Operation
X-TEC-API-ROOT
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-B3-Sampled
Cleartype
TCN
DC
X-Goog-Generation
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Newrelic-App-Data
X-Origin-Server
Referer-Policy
X-Mobile
X-Debug-Info
X-XRDS-Location
X-Webkit-Csp
X-Varnish-Backend
X-Origin-Cache
Cross-Origin-Resource-Policy
X-Aspnet-Version
X-Git-Hash
X-Logged-In
X-Azure-Ref
X-Varnish-Grace
X-Contextid
X-Edge-Location-Klb
X-Flags
X-Grace
Alternate-Protocol
X-Aspnet-Duration-Ms
X-Amz-Replication-Status
X-App-Environment
X-Is-Crawler
X-Fb-Rlafr
X-Providence-Cookie
Surrogate-Key
X-Kinsta-Cache
X-Revision
X-Route-Name
X-Request-Guid
X-Content-Options
X-TT
Count-Hit
Healthy
X-IPS-LoggedIn
X-Amz-Meta-S3cmd-Attrs
X-Client-Ip
X-Wix-Request-Id
X-Forwarded-Proto
X-Whom
Frame-Options
X-App-Server
X-TTL
X-Hosted-By
Charset
WPO-Cache-Message
WPO-Cache-Status
MS-Author-Via
X-Akamai-Edgescape
Viewport
Filterid
X-Daa-Tunnel
X-Id
Paypal-Debug-Id
X-Magnolia-Registration
X-Oracle-Dms-Ecid
X-B
X-Oracle-Dms-Rid
X-Backend-Name
Retry-After
X-Cache-Age
Section-Io-Cache
X-Kong-Proxy-Latency
X-F-Cache
X-Kong-Upstream-Latency
Amp-Access-Control-Allow-Source-Origin
SRV
X-AppVersion
X-Trace-Id
X-Cache-Control
X-Az
X-Activity-Id
X-Proxy-Cache-Info
Server-Name
X-Www-Served-By
X-Type
X-Varnish-Server
X-App-Version
X-Instance
Refresh
X-Rule
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
SD-X-WS
X-ARC
X-Response-Served-From
Akamai-GRN
X-Original-Request-Id
X-Http-Reason
X-Cache-Rule
X-Proxy
Protected
Front
X-User-Agent
X-Varnish-Age
X-EdgeConnect-Cache-Status
X-UUID
Version
Host
X-Status
X-Time
X-Rocket-Nginx-Serving-Static
X-Cache-Grace
X-Akamai-Request-ID2
X-Edge-Location
X-N
X-FW-Hash
X-Region
X-FW-Version
X-FW-Serve
X-Is-Bot
X-FW-Dynamic
X-FW-Static
X-FW-Type
X-FW-Server
From-Origin
X-L-Path
X-COUNTRY
X-Rendered-As
X-Page-View
X-Cacheable-TTL
X-Environment-Context
X-Jobs
Fastly-SIE
X-Framework
Fastly-SWR
X-Unique-Id
X-Adobe-Content
Access-Control-Request-Headers
X-Adobe-Loc
X-Cache-Time
X-G
X-Load-Cache
ServerID
X-Tumblr-Pixel-0
X-ProcessESI
X-Tumblr-User
X-Tumblr-Pixel-1
X-Tumblr-Pixel
X-RemovedCookies
X-Source
X-Upgrade-Enabled
X-Varnish-Ttl
X-Language
X-RateLimit-Reset
Country
X-Datadog-Sampling-Priority
Content-Disposition
X-Datadog-Parent-Id
X-Datadog-Trace-Id
X-CDN-Forward
X-Drupal-Cache-Tags
X-Vcache
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-DataDome
X-HTML-Minification-Powered-By
Accept-Language
X-Datadog-Sampled
X-Amzn-Remapped-Content-Length
X-Mg-Request-UUID
Countrycode
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Debug-IsPreview
X-Debug-IsConnected
X-DynaTrace
X-Nf-Request-Id
X-ID
X-Generated-By
X-DynaTrace-JS-Agent
X-Xrds-Location
X-B3-SpanId
X-ECache
Xet-Cookie
Backend
X-B-Cache
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
CF-IPCountry
X-Signature
Liferay-Portal
Xserver
X-Nginx-Cache
X-Httpd
X-Tt-Logid
X-NYM-Debug-Backend
X-Erf-Web-Scheduler
X-Mode
X-Device-Type
X-Drupal-Cache-Contexts
X-Content-Powered-By
X-Servername
Webserver
Url
X-Zen-Fury
X-Content-Age
Load-Balancing
Meta-Geo
Azure-InstanceId
Azure-RegionName
Locale
GEO-INFO
X-Proto
Azure-Version
X-Tb
X-Varnish-Cache-Hits
X-Urbn-Site-Id
Azure-SiteName
Filters
Fastcgi-Useragent
X-Director
Onion-Location
X-Say-TTL
X-Git-Commit
X-SayCDN-TTL
X-Cache-Operation
X-Say-Cacheable
X-SaId
X-Rewrite-Enabled
X-GeoCode
X-GeoCountry
X-Container-Uri
X-ServerID
S-Rt
X-Sucuri-Cache
X-Sucuri-ID
Azure-SlotName
X-UPSTREAM-Address
X-Urbn-Context-Path
X-Cache-Action
X-LAGOON
X-JoinUs
X-Labrador-Cache-Channel
X-Forwarded-Host
X-PHP-Host
Uber-Trace-Id
X-Ratelimit-Reset
X-VC-Cache
X-Cluster-Node
X-Soup
X-Varnish-Hostname
X-RM-Cache-TTL
X-Sql-Duration-Ms
X-Storage
X-Logging-Id
X-Sql-Count
X-Adobe-Source
CDN-RequestId
X-Served-From
X-Ms-Request-Id
X-VCT
X-Ms-Version
X-Generation-Time
X-Detected-As
Web-Mar-Node
TWC-Connection-Speed
TWC-Locale-Group
TWC-Device-Class
X-Extlb
TWC-GeoIP-Country
DB-Nickname
Property-Id
TWC-Privacy
Node
X-Debug
X-FB-TRIP-ID
Mn-Server-Ip
X-Origin-Hint
Webcakes-Region
X-R9-Blue-Green-Version
X-Zipkin-Id
X-Cache-Server
Webcakes-App-Name
X-Proxied
TWC-GeoIP-LatLong
Webcakes-App-Version
X-RCS-CacheZone
X-Routing-Service
X-LSADC-Cache
X-Timing-Wait
X-Uri
X-Format
Selected-Fe
X-Skip-Cache
X-Fetched-On
X-Proxy-Build
X-Lambda-Id
X-Tumblr-Pixel-3
X-Tumblr-Pixel-2
X-Template
OT-Force-Account-Verify
Fastly-Drupal-HTML
Source
X-Origin-Date
X-MP-GENERATED-AT
X-XRDS-LOCATION
X-Cache-Expired-At
X-MCACHE
X-Cache-Hit
X-Loop
X-Tncms
X-Tec-Api-Version
X-Tec-Api-Origin
X-Tec-Api-Root
X-Varnish-Hits
X-Via-JSL
X-Endurance-Cache-Level
X-Pass-Why
Content-Secure-Policy
X-Cache-TTL-Remaining
X-Srv
X-Ua
X-NGENIX-Cache
X-UA-Device-Type
X-Redis-Cache
Upgrade-Insecure-Requests
X-Node-Name
X-Fastly-Request-Id
Cross-Origin-Window-Policy
X-Pubstack
X-AIR-PT
X-Real-IP
X-Origin-TTL
X-Origin-CC
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
X-Server-W
Section-Origin-Responded
Section-Io-Id
X-Hcs-Proxy-Type
X-CCDN-CacheTTL
X-CCDN-Origin-Time
X-GEO
NGB
X-S
X-PHP-Backend
Cache-Provider
X-Rn-Rsrv
X-Cache-Host
CDN-Uid
X-RTag
CDN-CachedAt
CDN-Cache
CDN-EdgeStorageId
CDN-PullZone
CDN-RequestPullCode
CDN-RequestPullSuccess
CDN-RequestCountryCode
MS-CV
Cache-Hits
Ms-Operation-Id
Cache-Name
X-CSRF-Token
X-Cache-Type
X-Restarts
X-Xfnlog-Site
X-Reqid
Apigw-Requestid
X-IPLB-Instance
X-TimeS
X-Cms-Context
X-IPLB-Request-ID
X-Aspnetmvc-Version
X-Hl-Ver
X-Optimistic-Header
X-Akamai-Transformed
X-Datadome
X-TA-CDN-Provider
X-ProxyCache-Status
X-BYPASS-REASON
X-ProxyCache-Key
X-CACHE-AGE
X-Newrelic-Synthetics
X-Parent-Response-Time
X-Cache-NE
Canary
X-Cache-Info
X-Bl-Debug
DCR-Decision-By
DCR-Processing-Time-Ms
X-BCube-Filmed-By
CPC-Cache
CPC-Age
X-Cache-Bucket
X-AWS-Id
Candidate-Md5Url
X-Cdn-Diag
X-ScT
Xc-Version
X-Rojux
X-Request-Host
X-SD-PageType
X-Shop-Environment
Vix-Hermes-Req-Id
X-GeoIP-Country-Code
X-Slack-Backend
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-CacheTTL
X-Irp-Debug
X-Is-Gdpr
BehaviorPad-Version
X-Bc-Bl
X-CF-Lambda-Fn
X-Policy
X-CGP
X-CF-Lambda-Version
X-JWT-State
HA-Ipaddr
X-A-Dcw
X-A-Dam
X-A-Ccd
Sslversion
X-A-Dgt
X-A-Wwc
X-Accel-Expires-Debug
X-Accel-Buffering
Server-Host
X-A
X-Nyt-Route
We-Hiring
W
VNS-Cache
VNS-Age
Web-Mar-Region
True-Client-Country-4JS
Surrogated-Key
T-Server
X-Mvc-Supplant-Cachable
Rendered-Blocks
Redirect-Candidate
X-Origin-Time
L
L5d-Success-Class
Lang
Ha-Gx-Prefs
Gh-Request-Id
Fastly-GeoIP-CountryCode
Fastly-SSL
Gannett-Cam-Experience-Id
X-B-Cookie
Magicmarker
X-Application
Odigeo-Trace-Id
X-Orig-Expires
X-Aed
Ngx.Var.Host
N-Cache
Mail-Subject
MD5-Digest
Meta-Geo-Continent
Fastly-Backend-Name
X-S-Cookie
X-Developer
X-Cluster
X-Destination
X-Dispatcher-Number
X-Vdms-Path
X-Ec-Custom-Error
X-Vdms-Version
X-Forwarded-Path
X-TIM-N
X-Tenant
X-GeoIP-Region-Code
X-Date
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-Via-Fastly
X-VWS-Id
X-Ec-Fail
X-VG-WebCache
X-Wix-Viewer-Type
X-Wikidot-Static-Cache
X-No-Session
X-Worker
X-External-Request-Id
X-LJ-Flow-ID
X-Fastly-Backend
X-Wikidot-Backend
X-We-Are-Hiring
X-Viewer-Country
X-Epic-Correlation-Id
X-Ec-GeoHdr
X-FC-Vary-Parameters
X-Has-Esi
X-Eu-Site
X-Vtex-Remote-Cache
X-D
X-Var-Ttl
X-Conf
X-SRCache-Key
X-Csrf-Jwt
X-Gdpr
X-Slack-Shared-Secret-Outcome
X-Section
X-Handled-By
X-Access
Platform
Req-Svc-Chain
X-S-Maxage
Producers
X-Esi-Check
X-Mid
X-Clientip
Release
X-Org
X-Loc
X-VG-TLSProxy
X-Origin-Response-Time
X-Clara-WADP
X-Core-Mission
X-App-Name
Origin
X-Mly-Id
X-Hash
X-Human
X-Alternate-Cache-Key
X-Gzip
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
TDXMobile
X-ShopId
Thinkindot-Control
X-Shopify-Stage
X-Generated-On
X-Nitro-Cache
X-Node-Id
X-CMSURLCustom
X-Sn-Servicetimems
X-WADP-Cache
X-App
X-Sorting-Hat-PodId
X-Auto-Login
X-Old-Content-Length
X-Proxy-Cache-Status
X-Vmg-Version
X-ShardId
X-Server-IP
X-VServer
X-Fmm-Version
Memcached
X-Thanos
Datacenter
X-DefHash
X-Test
X-Thinkindot-L3
X-Bip
Environment
X-SVT-ORM-VERSION
X-Core-Value
Cmstype
Cmsid
X-SVT-ORM-RULES
X-Forwarded-Site
Adler-Geo
X-Cdn-Origin
X-Cache-Id
X-Cache-Debug
X-Platform
X-DefElseHash
X-Storefront-Renderer-Rendered
X-BBC-Edge-Cache-Status
X-Pool
X-Varnish-Remaining-TTL
Is-Eu
X-Request-Time
Expect-Staple
Machine
X-INCAP-ABP
X-Varnishpool
Host-ID
X-Sorting-Hat-ShopId
X-Variation
X-Up
X-Qloud-Router
X-Owner
X-Level-Front-Cache
X-Varnish-CookieINHashed-On
X-Varnish-CookieHashed-On
X-DPWN-IS-SECURE
ServedBy
User-Cache-Control
X-Geo-Header
X-Gen-Mode
X-Hnp-Log
X-Block-Status
X-Akamai-Device-Characteristics
X-Device-Os
X-ApacheServer
X-From
X-Cdn-Srv
Country-Code
X-GeoIP
CloudFront-Viewer-Country
X-PERF
DSUID
X-PAYTM-SRV-ID
NM-Fastcgi-Cache
Esi-Enabled
CDCHOST
Apple-News-Services-Request-Url
X-Scale
X-Presslabs-Stats
X-WA-Info
AKAMAI
X-Mvc-Supplant-OutputCached
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
X-Origin
Apple-News-Services-Handled
X-Nananana
Server-Hostname
X-NodeID
X-Nginx-Cache-Key
Server-Ext
Sever-Int
X-Vcl-Version
X-Webkit-Csp-Report-Only
X-Tx-Id
X-Web-Node
X-LB-NoCache
X-NCache
C-Via
X-Cache-Enabled
Wxu-Next-Commit
Pics-Label
WP-Super-Cache
X-Instance-Name
Ssr
Wxu-Next-Hostname
Wxu-Next-Region
X-Op-Id-All
Origin-CC
X-Dispatcher-Server
Origin-EX
Server-Info
X-Refresh
X-Air-Trace-Id
X-TIME
X-Air-Source
X-Air-Hostname
Server-ID
X-Cs
Memory
X-Azure-Ref-OriginShield
X-Amz-Meta-Cb-Modifiedtime
Time
X-Cache-Status-Check
X-HA-Backend
Hostname
X-ZONE
X-API-Version
Cache-Host
X-URL
X-Platform-Processor
X-Platform-Cluster
GeoIP-Latitude
X-Platform-Router
NGX
X-Origin-Expires
Cf-Device-Type
Origin-Agent-Cluster
X-Microcachable
AMP-Access-Control-Allow-Source-Origin
X-VHOST
X-Tb-Optimization-Total-Bytes-Saved
X-Correlation-ID
X-CACHE-GROUP
XM
X-Locale
X-Site-Version
X-DC
X-Dc
X-HN
X-VarnishDD-TTL
PFcat
X-Wp-Cf-Super-Cache-Active
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Ttl
X-Fpc
Resin-Trace
X-Ad-Defer-Variation
X-Via-SSL
Edge-Copy-Time
X-Micro-Cache
X-Vgn-Hpd-Reason
X-FL-QIT-DEBUG
X-Internal-Host
X-Via-CDN
A
X-FL-EDGE
Locid
Srvid
X-Via-Edge
YJS-ID
X-Zone
Cdn-Requestid
X-WP-CF-Super-Cache-Active
X-DataCenter
X-Pod-Name
X-Cache-ASPX
X-TraceId
X-Upstream-Ht
X-ATG-Version
X-Github-Request-Id
X-Contensis-Viewer-Groups
X-FireWall-Port
X-Upstream-Ct
Sid
X-Varnish-Authentication
User-Agent
X-Moov-T
IsBot
X-AB
X-Cached-By
X-SIPLIST1
Cache-Key
Uri
X-Moov-Xdn-Version
True-Client-Ip
Location
X-LiteSpeed-Cache-Control
X-Buckets
X-Info
X-B3-Parentspanid
GeoIP-Country-Code
X-Geo-Region
X-B3-Spanid
X-Backend-Instance
X-Planisys-CDN-Cache
X-Planisys-CDN-TTL
X-Platform-Server
State
X-NGINX-Cache
X-Nitro-Rev
X-HS-Content-Campaign-Id
X-Accel-Version
X-Nitro-Cache-From
X-FTR-Request-ID
X-Planisys-CDN-Rules
X-Provided-By
X-LiteSpeed-Tag
SID
GeoIp-Country-Code
CF-Ctrl
X-Fastly-Cache
X-MSEdge-Features
X-MSEdge-Flight
X-Release
X-CS
X-VCache
X-Is-Mobile
X-Is-Desktop
X-Is-Supported-Browser
X-Is-Tablet
X-Rocket-Build-Number
X-Tcp-Rtt
X-Browser-Name
Cdn
X-Datacenter
X-RN-RSRV
X-VC
XServer
X-Sigma
X-Sigma-Backend
X-Cache-Remote
X-NODE
NtCoent-Length
X-NewRelic-App-Data
X-CSRF-TOKEN
X-Vgn-Hpd-Cached
X-Vgn-Hpd-Ssi
True-Client-IP
X-Vgn-Hpd-Variations-Key
Cache
Path
X-Geo
Lb
X-Api-Version
X-Generated-In
X-GeoIP-City
X-Gamma-Serve
X-TRACE-ID
X-HS-Status
X-Scheme
X-SRV
Epwk-X-Cache
X-FPC
Fastly-Drupal-Html
X-Hyper-Cache
Tcn
X-HostName
X-GoCache-CacheStatus
X-Frame-Option
X-Webstats-RespID
Ohc-File-Size
X-Service
Cache-Tv-Group
WebServer
Serverid
Cf-Ipcountry
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-APP-VERSION
X-UA
CountryCode
Cdncip
Kp-EeAlive
X-AK-Request-ID
Cdnsip
X-Air-Pt
X-Esi
X-Amz-Meta-Opti
X-Guploader-Uploadid
Srv
X-Wp-Cf-Super-Cache
X-Mobile-URL
HostName
X-Branch-Name
X-EC-Lua
X-Wp-Cf-Super-Cache-Cache-Control
X-Location
X-Cache-Ttl
X-Traceid
LB
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-Pad
X-Men
X-Aicache-OS
X-Developers
Env
X-Region-Sid
X-Vercel-Cache
X-Edge-Server
X-Cdn-Cache-Status
Proxy-Connection
CacheControlHeader
X-Vc
Ohc-Cache-HIT
X-Vercel-Id
XkeyRZ
X-Proxy-CacheRZ
WZWS-RAY
X-Cache-Tags
Cdn-Host
On-Server
Cdn-Request-Time
Yak-Timeinfo
X-TX-ID
X-VCL-Version
X-CACHE-KEY
X-Origin-Cache-Key
CDN
X-FTR-Backend-Server
X-FTR-Balancer
X-FTR-Cache-Status
X-NMSegId
X-FTR-Expires
X-FTR-Backend
Req-ID
X-CDN-Cache-Status
X-Akamai-Pragma-Client-IP
Geoip-Latitude
M-TraceId
X-LB-ID
X-Country-Code-Real
X-NWS-UUID-VERIFY
RNT-Machine
X-Via-Popv
RNT-Time
X-Wa
X-Acquia-Purge-Cdn-Unconfigured
X-Servedbyhost
X-Edge-Pop
X-Cdn-Forward
Tube-Get-Contents
Tube-Got-Eval
Tube-Got-Results
X-Nc
Tube-Return
X-V-Cache
V-Age
X-Via-Popn
X-Via-Poph
X-SB
X-Minions-Version
X-Cache-FS-Status
X-B3-Trace-ID
Click-Count-Action-Start
Ngx
X-Cdn-Request-ID
Click-Count-Error
Mime-Version
X-Req
X-Lb-Cache
X-Ad-Load-Variation
Server-Id
X-Ha-Backend
X-WP-CF-Super-Cache-Cookies-Bypass
Content-Style-Type
WWW-Authenticate
X-Fastly-Country-Code
Cluster
ENV
CF-Cached-On
Content-Script-Type
X-TT-LOGID
X-Request-Start
X-Scope-Id
X-M-Log
PICS-Label
X-Lb-Nocache
Pramga
X-User
X-M-Reqid
X-Acquia-Application-Trace
X-Check-Cacheable
X-IN-APIGATEWAYSSL
X-Dw-Trace-Id
X-MiniProfiler-Ids
X-Edge-POP
X-Snapshot-Date
X-Acquia-Site
X-IN-APIGATEWAY
X-Via-Ucdn
X-Acquia-Purge-Tags
X-Acquia-Application-UUID
Yjs-Id
X-Varnish-Beresp-Status
Log-Origin
X-RAMCache
X-Fastly-Backend-Reqs
X-Iauth-Set-Uid
X-Qnm-Cache
X-Shield-Cache-Expires
X-Ckpd-Fst-Backend
X-Request-URI
X-Processor
Vha6-Origin
X-Cached-Since
X-Miniprofiler-Ids
X-ElasticPress-Query
X-Fastly-Cache-Hits
Cneonction
X-TH-Server
X-APP
X-Litespeed-Cache-Control
Inserted-Into-Cache-At
CACHE-MISS-TO-ORIGIN