Threat Level: green Handler on Duty: Jan Kopriva

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Accept-Ranges
X-XSS-Protection
Expect-CT
Pragma
X-Powered-By
X-Cache
CF-RAY
Via
Age
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
CF-Ray
X-Xss-Protection
X-Download-Options
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Request-Id
X-Adblock-Key
Access-Control-Allow-Credentials
X-FRAME-OPTIONS
X-Permitted-Cross-Domain-Policies
X-AspNet-Version
Alt-Svc
X-Request-ID
X-Runtime
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Generator
X-Check
X-Cache-Status
X-Cacheable
Timing-Allow-Origin
X-Envoy-Upstream-Service-Time
X-Iinfo
X-Content-Security-Policy
X-Drupal-Dynamic-Cache
Feature-Policy
Content-Encoding
Access-Control-Expose-Headers
Status
Upgrade
X-CDN
X-AspNetMvc-Version
Access-Control-Max-Age
X-Via
Server-Timing
Request-Context
X-Dns-Prefetch-Control
X-Robots-Tag
X-Turbo-Charged-By
X-UA-Device
X-Amz-Request-Id
X-Cache-Group
X-Amz-Id-2
EagleId
X-Backend
X-AH-Environment
P3p
X-Proxy-Cache
Keep-Alive
X-Server
X-Ws-Request-Id
X-Age
Cf-Edge-Cache
Host-Header
X-Hacker
X-Vhost
X-Server-Powered-By
X-Rq
X-Varnish-Cache
X-Dispatcher
X-Amz-Version-Id
Grace
Allow
X-OneAgent-JS-Injection
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-LiteSpeed-Cache
X-Ua-Compatible
X-Page-Speed
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Device
Cf-Apo-Via
X-WebKit-CSP
Cf-Railgun
Accept-CH
X-Aws-Lambda-Call-Status
X-Node
X-Pingback
X-Host
X-Ruxit-JS-Agent
EagleEye-TraceId
X-Server-Id
Surrogate-Control
X-Nginx-Cache-Status
X-Akam-SW-Version
X-Readtime
Request-Id
X-Backend-Server
X-Content-Security-Policy-Report-Only
X-HW
X-Cache-Lookup
Accept-Ch-Lifetime
X-Cache-Spec
X-Cloud-Trace-Context
X-Trace
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Response-Time
X-Application-Context
Permissions-Policy
X-Nginx-Upstream-Cache-Status
Fastly-Restarts
X-Litespeed-Cache
X-Edge
X-Mod-Pagespeed
X-WebKit-CSP-Report-Only
X-Country
Content-Location
X-Mcache
X-MS-InvokeApp
X-Content-Type
X-Url
X-Clacks-Overhead
Accept-CH-Lifetime
X-PC
X-Vname
X-TtlSet
X-Midtier
X-Amz-Server-Side-Encryption
X-CST
Rating
RTSS
Cache-Tag
X-ESI
X-Vcap-Request-Id
X-D2id
X-Rack-Cache
X-Element-Page-Cache
Origin-Trial
X-Cdn-Fetch
X-Kinja
X-Kinja-Server
X-Use-Magma
X-Kinja-Revision
X-Kinja-Build
X-Exp-Variant
X-GoogleNews-Bot
X-Exp-Id
X-ECACHE
Verso
X-VARITI-CCR
X-Server-Name
X-Ac
Service-Worker-Allowed
X-Powered-By-Plesk
X-Amz-Rid
X-Cnection
X-SharePointHealthScore
SPRequestGuid
X-Client-IP
X-GitHub-Request-Id
X-Navigation-Version
Xkey
X-Abt-Application-Version
X-Ttl
Accept-Ch
Edge-Control
SPIisLatency
SPRequestDuration
X-Cache-TTL
X-Upstream
Arr-Disable-Session-Affinity
X-Varnish-TTL
X-B3-TraceId
X-Cached
X-Mg-S
X-Webkit-Csp
X-Dw-Request-Base-Id
X-Erf-Bev-Bev
X-Browser-Type
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Erf-Bev-Bev-Is-Generated
X-Instrumentation
X-NWS-LOG-UUID
X-Px
X-Middleton-Display
Pagespeed
X-Sol
Display
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-NF-Request-ID
X-Correlation-Id
Access-Control-Request-Method
X-Forwarded-For
Edge-Cache-Tag
X-FastCGI-Cache
X-Cache-Key
X-Country-Code
X-Goog-Hash
X-Ser
X-Powered-CMS
X-Id
Content-MD5
AR-PoweredBy
AR-CACHE
AR-Request-ID
AR-SID
AR-ATIME
Front-End-Https
Public-Key-Pins
X-Ratelimit-Limit
TCN
X-HP-Webp
X-Jurisdiction
X-Version
X-HP-Trace-Id
X-Amzn-Trace-Id
X-Content-Digest
X-MSEdge-Ref
X-Recruiting
X-T
X-Middleton-Response
Response
X-Accel-Expires
TP-Cache
TP-L2-Cache
X-RateLimit-Remaining
X-Shield-Request-Id
MicrosoftSharePointTeamServices
X-XRDS-Location
S
Nginx-Cache
X-Fastcgi-Cache
Cache-Status
X-Request-Received
X-Request-Processing-Time
X-Daa-Tunnel
X-HS-Cache-Config
Cross-Origin-Opener-Policy
X-HS-Content-Id
X-HS-Hub-Id
X-HS-Combine-CSS
X-Ratelimit-Remaining
Server-Node
Cache-Tags
Mrf-Cache-Status
X-B3-TraceId-Primal
MRF-Tech
X-Distributor
X-Fastly-Request-ID
X-Hits
X-PressLabs-Stats
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-LB-Cache
X-TEC-API-ROOT
X-Kinsta-Cache
X-Edge-Location-Klb
X-Origin-Server
X-Ua-Browser
X-Ezoic-Cdn
X-Ratelimit-Reset
Fastcgi-Cache
Alternate-Protocol
Filterid
X-LLID
X-Grace
X-Frontend
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
X-Microsite
X-Request-Handler-Origin-Region
X-Rid
X-Hostname
X-DIS-Request-ID
X-Varnish-Backend
Realpath
X-FB-Debug
X-Logged-In
Server-Name
Healthy
X-Git-Hash
X-Geo-Country
X-NGENIX-Cache
X-Www-Served-By
Cleartype
X-Debug-Info
X-Cluster-Name
X-Page-Id
Payment
X-Load-Cache
DC
X-Forwarded-Proto
MS-Author-Via
X-Protected-By
X-ASPNET-VERSION
Access-Control-Allow-Method
Content-Disposition
X-Origin-Cache
X-TTL
Charset
X-B3-Sampled
X-DataDome
X-Goog-Metageneration
X-GUploader-UploadID
X-Upgrade-Enabled
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Proxy
X-Server-ID
X-Az
X-Activity-Id
X-AppVersion
X-Times
X-Seen-By
X-ECache
Count-Hit
X-Cache-Age
X-F-Cache
X-B3-Traceid
X-Amz-Replication-Status
X-Amz-Meta-S3cmd-Attrs
Paypal-Debug-Id
X-Fb-Rlafr
X-Azure-Ref
Cross-Origin-Resource-Policy
X-Whom
X-Revision
X-Akamai-Edgescape
X-B
X-Type
Surrogate-Key
X-Contextid
X-Request-Guid
Accept-Charset
X-Varnish-Server
X-Providence-Cookie
X-Aspnet-Duration-Ms
X-Aspnetmvc-Version
X-Flags
X-App-Environment
X-Is-Crawler
Viewport
X-Route-Name
X-TT
X-Wix-Request-Id
Retry-After
X-Hosted-By
X-Language
X-B-Cache
X-Signature
X-DynaTrace
X-Envoy-Decorator-Operation
X-Cache-Control
X-Oracle-Dms-Ecid
X-Oracle-Dms-Rid
X-App-Server
X-Magnolia-Registration
X-Source
X-Varnish-Grace
Amp-Access-Control-Allow-Source-Origin
X-Mobile
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Generation
Version
X-VCache
Host
WPO-Cache-Message
WPO-Cache-Status
Refresh
X-Cache-Rule
Referer-Policy
X-N
X-HTML-Minification-Powered-By
X-Tumblr-Pixel-1
X-Varnish-Age
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Cache-Time
X-Original-Request-Id
X-Response-Served-From
Access-Control-Request-Headers
X-Tumblr-User
X-Amz-Apigw-Id
X-Amzn-RequestId
X-EdgeConnect-Cache-Status
X-Rule
X-Jobs
X-User-Agent
X-UUID
X-Cache-Grace
X-Framework
X-G
X-Cacheable-TTL
Protected
SD-X-WS
X-Content-Powered-By
From-Origin
X-Cache-Status-Check
MS-CV
Ms-Operation-Id
X-RemovedCookies
X-Environment-Context
X-Device-Type
Section-Io-Cache
CDN-RequestId
X-ProcessESI
X-Backend-Name
X-FW-Serve
X-L-Path
X-FW-Dynamic
X-RTag
X-FW-Type
X-FW-Version
X-FW-Hash
X-FW-Static
X-FW-Server
GEO-INFO
Akamai-GRN
VIX-Pulpo-Node
X-Tt-Trace-Tag
X-Region
NGB
X-Page-View
VIX-Pulpo-Upstream-Status
X-Tt-Trace-Host
X-Trace-Id
X-Status
X-Adobe-Loc
X-Adobe-Content
X-Drupal-Cache-Tags
X-Http-Reason
X-NYM-Debug-Backend
Front
X-Akamai-Request-ID2
X-Rendered-As
X-Cache-Expired-At
X-Is-Bot
X-Drupal-Cache-Contexts
X-Instance
X-XRDS-LOCATION
X-Nginx-Cache
X-Fastly-Request-Id
X-Servername
Url
X-Unique-Id
Pinterest-Version
Pinterest-Generated-By
X-Pinterest-Rid
X-Time
Liferay-Portal
Accept-Language
X-Varnish-Ttl
X-Content-Options
X-RateLimit-Limit
SRV
Fastly-SWR
X-Template
Fastly-SIE
X-Debug-IsConnected
X-Debug-IsPreview
X-Air-Hostname
X-Air-Trace-Id
X-Air-Source
X-Newrelic-App-Data
Backend
X-Zen-Fury
X-Cache-Hit
X-CDN-Forward
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-DynaTrace-JS-Agent
Country
X-Mode
X-Rocket-Nginx-Serving-Static
X-COUNTRY
Content-Secure-Policy
X-Uri
Node
X-Cache-Operation
X-Generation-Time
X-Content-Age
Meta-Geo
X-UPSTREAM-Address
Filters
Webserver
X-ARC
X-Rewrite-Enabled
X-IPS-LoggedIn
X-RN-RSRV
X-Cache-Server
X-Tumblr-Pixel-2
X-Tumblr-Pixel-3
X-Proxy-Cache-Info
X-Edge-Location
Azure-SiteName
Azure-RegionName
Azure-InstanceId
X-Amzn-Remapped-Content-Length
Azure-SlotName
X-Locale
X-Tb
Cache-Hits
Azure-Version
X-Proxy-Build
Uber-Trace-Id
Selected-Fe
S-Rt
X-PHP-Backend
Onion-Location
X-App-Version
X-Timing-Wait
CF-IPCountry
X-Web-Node
X-BYPASS-REASON
Countrycode
X-Server-W
X-Cache-Action
WP-Super-Cache
X-Cms-Context
X-ProxyCache-Status
X-ProxyCache-Key
X-Sucuri-ID
X-SayCDN-TTL
X-Say-TTL
X-Ms-Request-Id
X-Sucuri-Cache
X-Site-Version
X-Soup
X-Ms-Version
X-Skip-Cache
X-Via-Fastly
X-Labrador-Cache-Channel
X-Say-Cacheable
X-PHP-Host
X-Reqid
Cache-Name
X-Origin-Date
X-Extlb
Cache-Tv-Group
X-Proto
Property-Id
ServerID
X-Debug
X-Format
X-Origin-Hint
X-Proxied
X-LJ-Flow-ID
X-Proxy-Cache-Status
X-Cache-Host
X-AWS-Id
TWC-GeoIP-Country
Webcakes-App-Version
X-Routing-Service
TWC-Privacy
TWC-Locale-Group
X-IPLB-Instance
X-IPLB-Request-ID
TWC-Device-Class
Webcakes-App-Name
X-Sql-Count
X-Sql-Duration-Ms
TWC-Connection-Speed
X-Cluster-Node
TWC-GeoIP-LatLong
X-VWS-Id
Webcakes-Region
X-Access
X-UA-Device-Type
X-Section
X-Forwarded-Host
X-Zipkin-Id
X-VC-Cache
X-Varnish-Beresp-Grace
X-Adobe-Source
Apigw-Requestid
X-R9-Blue-Green-Version
X-LAGOON
X-Cluster
X-Real-IP
X-FB-TRIP-ID
X-SaId
X-Optimistic-Header
Web-Mar-Node
X-JoinUs
X-No-Session
X-Ruxit-Js-Agent
DB-Nickname
Cross-Origin-Window-Policy
X-Handled-By
X-Cache-TTL-Remaining
X-Ua
Mn-Server-Ip
Locale
X-Urbn-Site-Id
X-Detected-As
X-Urbn-Context-Path
ServedBy
X-GeoCode
X-LSADC-Cache
X-GeoCountry
Fastcgi-Useragent
X-Director
X-WP-CF-Super-Cache-Cache-Control
X-Xfnlog-Site
X-WP-CF-Super-Cache
X-Node-Name
X-Oneagent-Js-Injection
Mime-Version
Upgrade-Insecure-Requests
Source
Frame-Options
X-Tt-Logid
X-Varnish-Hits
Fastly-Drupal-HTML
X-GEO
X-Hl-Ver
X-Buckets
CDN-Cache
X-Generated-By
CDN-CachedAt
CDN-PullZone
CDN-Uid
CDN-EdgeStorageId
CDN-RequestCountryCode
X-Tec-Api-Root
X-Tec-Api-Origin
X-Tec-Api-Version
Load-Balancing
X-Varnish-Cache-Hits
X-FireWall-Port
X-SRV
X-Request-Time
X-ServerID
Xet-Cookie
X-Api-Version
X-RM-Cache-TTL
X-TA-CDN-Provider
X-Mg-Request-UUID
X-Varnish-Hostname
X-URL
X-Origin-TTL
X-Origin-CC
X-Redis-Cache
X-Loop
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
X-Datadog-Sampled
X-Datadog-Trace-Id
X-Cache-Debug
X-TIME
CF-Cached-On
X-Akamai-Transformed
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Storefront-Renderer-Rendered
X-Served-From
X-ShopId
X-Shopify-Stage
X-Tx-Id
X-ShardId
X-Alternate-Cache-Key
X-Storage
X-Pubstack
Xserver
X-Restarts
X-Provided-By
X-Pass-Why
X-Newrelic-Synthetics
X-Request-Host
X-Endurance-Cache-Level
X-CSRF-Token
X-Location
X-Service
Server-Info
X-B-Cookie
X-BCube-Filmed-By
X-Bip
X-Bc-Bl
X-Application
X-A-Wwc
X-A-Dgt
A
X-Aed
X-Akamai-Device-Characteristics
X-Cache-Date
X-Cache-Info
X-Ec-Fail
X-Developer
X-Ec-GeoHdr
X-External-Request-Id
X-Httpd
X-Hash
X-Destination
X-D
X-Cdn-Origin
X-Cache-NE
X-Conf
X-Core-Mission
X-CUA
BehaviorPad-Version
X-A-Dcw
Origin
Odigeo-Trace-Id
Gannett-Cam-Experience-Id
Redirect-Candidate
Rendered-Blocks
Release
Host-ID
NM-Fastcgi-Cache
Memcached
MD5-Digest
Meta-Geo-Continent
Lang
Ngx.Var.Host
Edge-Cache
Server-Host
Candidate-Md5Url
X-A
X-A-Ccd
X-A-Dam
X-INCAP-ABP
WWW-Authenticate
DCR-Decision-By
Sslversion
DSUID
Surrogated-Key
T-Server
DCR-Processing-Time-Ms
Cache-Host
X-Epic-Correlation-Id
X-S-Maxage
X-ScT
X-Sigma
X-Sigma-Backend
X-S-Cookie
X-S
X-Processor
X-Response-By
X-Rocket-Build-Number
X-Sn-Servicetimems
X-SRCache-Key
X-Vdms-Path
X-Vdms-Version
X-We-Are-Hiring
Xc-Version
X-TIM-N
X-Thanos
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-Test
X-Origin
X-Rojux
X-Mid
X-Mobile-URL
X-Loc
X-Men
X-Fetched-On
X-WP-CF-Super-Cache-Active
HostName
Tube-Get-Contents
TDXMobile
Thinkindot-CacheControl
X-Scale
Tube-Got-Eval
Thinkindot-Control
Thinkindot-CacheControl-Type
Tube-Got-Results
X-Geo-Header
X-Slack-Shared-Secret-Outcome
X-GeoIP
X-GeoIP-City
Tube-Return
We-Hiring
X-Gzip
X-Auto-Login
X-Human
Platform
X-Varnishpool
C-Via
X-Vmg-Version
X-Is-Gdpr
X-VServer
X-Varnish-Remaining-TTL
X-Varnish-CookieINHashed-On
X-Slack-Backend
X-Thinkindot-L3
X-JWT-State
X-Var-Ttl
X-Variation
Req-Svc-Chain
X-Varnish-CookieHashed-On
X-Has-Esi
X-Gdpr
X-CMSURLCustom
X-Origin-Time
X-Origin-Response-Time
X-Platform
X-CacheTTL
X-Cache-Id
X-Platform-Processor
X-Platform-Cluster
X-Origin-Expires
X-Node-Id
X-Nyt-Route
X-Dispatcher-Number
X-Dispatcher-Server
X-Org
X-DefHash
X-Date
X-DefElseHash
X-Platform-Router
X-Cache-Bucket
X-Fastly-Cache
X-Accel-Expires-Debug
X-Ad-Defer-Variation
X-Gamma-Serve
X-SD-PageType
X-Ec-Custom-Error
X-Server-IP
X-Fastly-Backend
X-Level-Front-Cache
X-Region-Sid
X-Mvc-Supplant-Cachable
X-Pool
X-Req
X-BBC-Edge-Cache-Status
X-Esi-Check
Mail-Subject
X-Generated-On
X-HS-Content-Campaign-Id
Cache-Key
Expect-Staple
Fastly-Backend-Name
AKAMAI
CacheControlHeader
Click-Count-Action-Start
Cmstype
Cmsid
CloudFront-Viewer-Country
Click-Count-Error
Fastly-GeoIP-CountryCode
Adler-Geo
Section-Origin-Responded
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
Section-Io-Id
Country-Code
Magicmarker
X-TNCMS
Gh-Request-Id
Is-Eu
Environment
X-Varnish-Beresp-Ttl
X-Via-CDN
X-Device-Os
Locid
On-Server
X-DPWN-IS-SECURE
X-Vcl-Version
X-WADP-Cache
X-Wix-Viewer-Type
X-Worker
Origin-CC
Origin-EX
X-Mly-Id
X-Cache-FS-Status
X-Cdn-Srv
X-Cache-Tags
X-Ckpd-Fst-Backend
X-Core-Value
X-Clara-WADP
X-WA-Info
X-FC-Vary-Parameters
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Qloud-Router
X-Planisys-CDN-Cache
X-Owner
Machine
X-NodeID
X-Irp-Debug
X-GeoIP-Region-Code
X-GeoIP-Country-Code
X-Frame-Option
X-Forwarded-Site
X-Fmm-Version
X-V-Cache
Kp-EeAlive
X-Release
X-SB
X-Developers
Srvid
X-FL-EDGE
Canary
Producers
X-Accel-Buffering
X-App
X-Nginx-Cache-Key
Web-Mar-Region
State
Ssr
X-VC
Vix-Hermes-Req-Id
X-Azure-Ref-OriginShield
Datacenter
X-FL-QIT-DEBUG
X-Instance-Name
Edge-Copy-Time
X-Via-Edge
X-Via-SSL
X-VG-TLSProxy
X-Op-Id-All
Wxu-Next-Hostname
X-HN
X-Varnish-Beresp-Status
NGX
X-Old-Content-Length
PFcat
Cache-Provider
X-Platform-Server
X-Request-Start
X-Gen-Mode
X-From
X-VarnishDD-TTL
X-Hnp-Log
X-Block-Status
Apple-News-Services-Handled
X-Ua-Device
X-Minions-Version
Server-Hostname
Sever-Int
Wxu-Next-Commit
User-Cache-Control
L
X-Aicache-OS
Server-Ext
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
Apple-News-Services-Host
X-NCache
Wxu-Next-Region
X-Zone
X-Webkit-CSP-Report-Only
X-CACHE-AGE
X-Parent-Response-Time
X-Air-Pt
X-Mvc-Supplant-OutputCached
HA-Ipaddr
Ha-Gx-Prefs
Fastly-SSL
L5d-Success-Class
X-Nananana
X-Eu-Site
CDCHOST
X-Microcachable
X-Cache-Remote
X-CGP
X-Csrf-Jwt
X-Cache-Enabled
X-RCS-CacheZone
X-Refresh
X-Lambda-Id
X-LB-NoCache
X-Debug-Cache-Fetch
X-DC
X-Debug-Cache-Store
X-Up
X-Correlation-ID
X-VCT
X-B3-Spanid
X-Cache-Backend
Env
Pics-Label
X-Tb-Optimization-Total-Bytes-Saved
X-Via-Popv
X-Via-Popn
X-Via-Poph
X-B3-SpanId
X-Dc
X-Trace-ID
VNS-Cache
VNS-Age
X-Render-Time
CPC-Cache
CPC-Age
X-Vtex-Remote-Cache
Decoy-Debug-Status
GeoIP-Latitude
X-Cached-By
Decoy-Debug-TTL
X-ND-Cache
Decoy-Debug-Key
X-Cs
X-Generated-In
Cluster
X-Upstream-Ct
SID
AMP-Access-Control-Allow-Source-Origin
NtCoent-Length
X-Upstream-Ht
X-AIR-PT
X-Hcs-Proxy-Type
X-CCDN-CacheTTL
Memory
Time
Sid
X-HA-Backend
X-CCDN-Origin-Time
Cache
X-Cache-Type
X-NWS-UUID-VERIFY
X-Tid
X-Webkit-CSP
X-Servedbyhost
X-LB-ID
X-Edge-Pop
X-TH-Server
X-HS-Status
X-Wa
X-Nc
X-Esi
X-ATG-Version
X-DataCenter
Fastly-Drupal-Html
X-Presslabs-Stats
X-Varnish-Authentication
X-Vgn-Hpd-Ssi
X-Contensis-Viewer-Groups
X-Client-Ip
X-NewRelic-App-Data
X-Vgn-Hpd-Cached
X-Vgn-Hpd-Variations-Key
Server-ID
Svr
X-Cache-ASPX
X-Via-JSL
Cdn
Srv
X-Srv
Uri
X-ZONE
GeoIp-Country-Code
X-Check-Cacheable
X-MP-GENERATED-AT
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-RateLimit-Remaining-Second
X-Fpc
X-RateLimit-Limit-Second
Esi-Enabled
X-PAYTM-SRV-ID
XkeyRZ
X-Proxy-CacheRZ
X-Amz-Meta-Cb-Modifiedtime
True-Client-IP
X-Vc
X-Udemy-Cache-App-Namespace
X-Wikidot-Static-Cache
Lb
X-CACHE-KEY
X-Wikidot-Backend
M-TraceId
X-Nf-Request-Id
N-Cache
X-Datadome
X-NGINX-Cache
Hostname
X-CS
X-Varnish-Beresp-TTL
YJS-ID
X-Bl-Debug
X-Tenant
Cdnsip
Cdncip
X-API-Version
X-Shop-Environment
X-Gateway-Cache-Status
X-Orig-Expires
X-Forwarded-Path
True-Client-Ip
X-Gateway-Skip-Cache
Resin-Trace
RNT-Machine
XServer
X-Gateway-Request-Id
X-AK-Request-ID
X-Gateway-Cache-Key
X-CDN-Cache-Status
RNT-Time
X-EC-Lua
X-CSRF-TOKEN
X-MSEdge-Flight
OT-Force-Account-Verify
X-MSEdge-Features
X-Via-NSCOPI
X-TX-ID
X-Fastly-Country-Code
X-FPC
X-App-Name
X-Policy
X-B3-Trace-ID
GeoIP-Country-Code
X-Service-Response-Time
Sm-Log-Id
Eomportal-Instance
CDN
X-Cache-Ttl
Server-Id
X-Logging-Id
Path
X-WA
X-Accel-Version
X-CLOUD-TRACE-CONTEXT
X-APP-VERSION
X-Vcache
Hit
Ngx-Var-Key
X-Micro-Cache
X-Container-Uri
X-Git-Commit
IsBot
X-SIPLIST1
X-MCACHE
X-Cdn-Diag
X-Cache-NGX
X-Datacenter
X-NC
X-Lb-Id
X-Edge-POP
X-VCL-Version
LB
HIT
X-Ha-Backend
X-RateLimit-Reset
X-Cdn-Cache-Status
X-Request-URI
X-ServedByHost
X-Cdn-Forward
X-Tncms
RATING
Pramga
X-Github-Request-Id
X-SERVER-NAME
X-Info
X-Geo
X-LiteSpeed-Cache-Control
XM
Geoip-Latitude
Timeexpire
X-Srcache-Fetch-Status
Location
FSS-Cache
V-Age
X-Snapshot-Date
X-Srcache-Store-Status
X-Acquia-Purge-Cdn-Unconfigured
Cross-Origin-Opener-Policy-Report-Only
X-VG-WebCache
X-Akamai-Pragma-Client-IP
X-TT-LOGID
Tcn
Epwk-X-Cache
X-Clientip
Yjs-Id
X-Via-PopN
X-Ctl-Mach
ENV
Req-ID
True-Client-Country-4JS
X-Via-PopV
CDN-RequestPullSuccess
CDN-RequestPullCode
X-LiteSpeed-Tag
X-Lb-Nocache
X-Via-PopH
X-Pod-Name
Ohc-File-Size
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-HostName
X-Wp-Cf-Super-Cache
X-Iauth-Set-Uid
X-Wp-Cf-Super-Cache-Cache-Control
X-Hyper-Cache
X-Dw-Trace-Id
X-Amz-Meta-Opti
X-Serial
X-M-Log
Warning
X-M-Reqid
W
X-Acquia-Purge-Tags
X-Acquia-Site
X-RAMCache
X-Acquia-Application-UUID
Proxy-Connection
X-Cdn-Request-ID
X-UP
WZWS-RAY
Content-Style-Type
X-Fastly-Backend-Reqs
Cneonction
Content-Script-Type
X-Acquia-Application-Trace
X-Oss-Storage-Class
X-Oss-Server-Time
X-Oss-Object-Type
X-Oss-Request-Id
X-Qnm-Cache
Servername
X-Cache-Expires
X-Oss-Hash-Crc64ecma
Ec-Rule-Version
X-MiniProfiler-Ids
CountryCode
X-Lsadc-Cache
PICS-Label
X-B3-Parentspanid
X-WP-CF-Super-Cache-Cookies-Bypass
MIME-Version
X-Akamai-ERPolicy
X-Akamai-ERRuleID
X-UA
X-Litespeed-Cache-Control
X-Webstats-RespID
My-App
X-B3-ParentSpanId
X-Fastly-Cache-Hits
X-IPS-Cached-Response
X-Mg-Cache
Ngx
X-Swift-Error
X-Th-Server
Ohc-Cache-HIT