Threat Level: green Handler on Duty: Daniel Wesemann

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
X-XSS-Protection
Accept-Ranges
Expect-CT
Pragma
X-Powered-By
CF-RAY
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
P3P
X-Cache-Hits
X-UA-Compatible
X-Served-By
CF-Ray
X-Xss-Protection
X-Download-Options
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Request-Id
X-Adblock-Key
Access-Control-Allow-Credentials
X-FRAME-OPTIONS
X-Permitted-Cross-Domain-Policies
X-AspNet-Version
Alt-Svc
X-Request-ID
X-Runtime
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Generator
X-Cache-Status
X-Check
X-Cacheable
Timing-Allow-Origin
X-Envoy-Upstream-Service-Time
X-Iinfo
X-Content-Security-Policy
X-Drupal-Dynamic-Cache
Feature-Policy
Content-Encoding
Access-Control-Expose-Headers
Upgrade
Status
X-AspNetMvc-Version
X-CDN
Access-Control-Max-Age
X-Dns-Prefetch-Control
X-Via
Server-Timing
Request-Context
X-Robots-Tag
X-Turbo-Charged-By
X-Amz-Request-Id
X-UA-Device
X-Cache-Group
X-Amz-Id-2
EagleId
X-Backend
X-AH-Environment
X-Proxy-Cache
Keep-Alive
X-Server
X-Ws-Request-Id
X-Age
Cf-Edge-Cache
Host-Header
X-Hacker
X-Vhost
X-Server-Powered-By
X-Rq
X-Varnish-Cache
X-Dispatcher
X-Amz-Version-Id
Grace
Allow
X-Swift-SaveTime
X-Swift-CacheTime
X-OneAgent-JS-Injection
Ali-Swift-Global-Savetime
P3p
X-LiteSpeed-Cache
X-Ua-Compatible
X-Page-Speed
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
Cf-Apo-Via
Cf-Railgun
X-WebKit-CSP
Accept-CH
X-Aws-Lambda-Call-Status
X-Node
X-Pingback
EagleEye-TraceId
X-Server-Id
X-Host
X-Ruxit-JS-Agent
Surrogate-Control
X-Nginx-Cache-Status
X-Akam-SW-Version
X-Readtime
Request-Id
X-Backend-Server
Accept-Ch-Lifetime
X-Content-Security-Policy-Report-Only
X-HW
X-Cache-Lookup
X-Cloud-Trace-Context
X-Cache-Spec
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Response-Time
X-Application-Context
X-Trace
Permissions-Policy
X-Nginx-Upstream-Cache-Status
Fastly-Restarts
X-Litespeed-Cache
X-Edge
X-Mod-Pagespeed
X-WebKit-CSP-Report-Only
X-Country
Content-Location
X-Mcache
X-MS-InvokeApp
X-Content-Type
X-Url
X-Clacks-Overhead
X-TtlSet
X-PC
X-Midtier
X-Vname
X-Amz-Server-Side-Encryption
X-CST
Rating
RTSS
Accept-CH-Lifetime
X-ECACHE
Cache-Tag
X-ESI
X-Vcap-Request-Id
X-D2id
X-Rack-Cache
X-Element-Page-Cache
Verso
X-Cdn-Fetch
X-Exp-Id
Origin-Trial
X-Exp-Variant
X-GoogleNews-Bot
X-Use-Magma
X-Kinja
X-Kinja-Server
X-Kinja-Revision
X-Kinja-Build
X-VARITI-CCR
X-Server-Name
X-GitHub-Request-Id
Service-Worker-Allowed
X-Ac
X-Powered-By-Plesk
X-Amz-Rid
X-Cnection
SPRequestGuid
X-SharePointHealthScore
X-Client-IP
X-Navigation-Version
Xkey
Edge-Control
SPRequestDuration
SPIisLatency
X-Upstream
X-Varnish-TTL
X-Abt-Application-Version
X-Cache-TTL
Arr-Disable-Session-Affinity
X-Cached
X-B3-TraceId
X-Dw-Request-Base-Id
X-Mg-S
X-Webkit-Csp
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Instrumentation
X-Kraken-Loop-Name
X-Browser-Type
X-Server-Lifecycle-Phase
X-Ttl
X-NWS-LOG-UUID
X-Px
Accept-Ch
Display
X-Sol
X-Middleton-Display
Pagespeed
X-SRCache-Fetch-Status
X-SRCache-Store-Status
Edge-Cache-Tag
Access-Control-Request-Method
X-Forwarded-For
X-FastCGI-Cache
X-Correlation-Id
X-Cache-Key
X-NF-Request-ID
X-Country-Code
X-Goog-Hash
X-Ser
X-Powered-CMS
X-Id
AR-SID
AR-Request-ID
AR-PoweredBy
AR-CACHE
AR-ATIME
Content-MD5
TCN
Public-Key-Pins
Front-End-Https
X-Amzn-Trace-Id
X-Version
X-HP-Webp
X-HP-Trace-Id
X-Jurisdiction
X-MSEdge-Ref
X-T
X-Recruiting
X-Content-Digest
Response
X-Middleton-Response
X-Ratelimit-Limit
X-Accel-Expires
TP-Cache
TP-L2-Cache
X-RateLimit-Remaining
X-Shield-Request-Id
MicrosoftSharePointTeamServices
X-Fastly-Request-ID
S
Cache-Status
Nginx-Cache
X-Fastcgi-Cache
X-XRDS-Location
X-HS-Content-Id
Cross-Origin-Opener-Policy
X-HS-Hub-Id
X-HS-Combine-CSS
X-HS-Cache-Config
X-Request-Received
X-Request-Processing-Time
Cache-Tags
Server-Node
X-Ratelimit-Remaining
Mrf-Cache-Status
MRF-Tech
X-B3-TraceId-Primal
X-Daa-Tunnel
X-Hits
X-Distributor
X-ORACLE-DMS-ECID
X-PressLabs-Stats
X-ORACLE-DMS-RID
X-LB-Cache
X-Kinsta-Cache
X-Origin-Server
X-Edge-Location-Klb
X-Ua-Browser
X-TTL
X-Ezoic-Cdn
X-Ratelimit-Reset
Fastcgi-Cache
Filterid
Alternate-Protocol
X-Frontend
X-LLID
X-Hostname
X-Request-Handler-Origin-Region
X-Microsite
Realpath
X-Rid
X-Grace
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-TEC-API-ROOT
Healthy
X-Logged-In
X-DIS-Request-ID
X-Varnish-Backend
X-Git-Hash
Cleartype
X-FB-Debug
Server-Name
X-Www-Served-By
X-NGENIX-Cache
X-Geo-Country
X-Cluster-Name
X-Page-Id
Payment
X-Debug-Info
X-Forwarded-Proto
DC
MS-Author-Via
X-Load-Cache
X-Protected-By
X-Origin-Cache
Access-Control-Allow-Method
Content-Disposition
X-B3-Sampled
X-Upgrade-Enabled
X-Kong-Upstream-Latency
X-GUploader-UploadID
X-Kong-Proxy-Latency
X-Goog-Metageneration
Charset
X-Proxy
X-AppVersion
X-Activity-Id
X-Az
X-Seen-By
X-Times
Count-Hit
X-DataDome
X-B3-Traceid
X-Amz-Meta-S3cmd-Attrs
Paypal-Debug-Id
X-Amz-Replication-Status
X-B
X-F-Cache
X-Fb-Rlafr
X-Azure-Ref
X-Cache-Age
X-Whom
X-Akamai-Edgescape
X-Revision
Accept-Charset
Cross-Origin-Resource-Policy
X-Type
Surrogate-Key
X-Contextid
X-Varnish-Server
Viewport
X-App-Environment
X-Aspnet-Duration-Ms
X-Flags
X-Route-Name
X-Providence-Cookie
X-Request-Guid
X-Is-Crawler
X-TT
Retry-After
X-Wix-Request-Id
X-Language
X-Hosted-By
X-Envoy-Decorator-Operation
X-ECache
X-DynaTrace
X-Cache-Control
X-Signature
X-B-Cache
X-Magnolia-Registration
X-Varnish-Grace
X-Mobile
X-App-Server
X-Source
Amp-Access-Control-Allow-Source-Origin
X-Goog-Storage-Class
Version
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Goog-Stored-Content-Encoding
Host
WPO-Cache-Status
WPO-Cache-Message
X-VCache
X-Server-ID
X-Amz-Apigw-Id
Refresh
X-Amzn-RequestId
X-N
X-HTML-Minification-Powered-By
X-Oracle-Dms-Rid
X-Oracle-Dms-Ecid
X-Cache-Rule
X-Tumblr-Pixel-0
X-Original-Request-Id
Referer-Policy
Access-Control-Request-Headers
X-Response-Served-From
X-Varnish-Age
X-Cache-Time
X-EdgeConnect-Cache-Status
X-Tumblr-User
X-Tumblr-Pixel-1
X-Tumblr-Pixel
X-Rule
Ms-Operation-Id
MS-CV
SD-X-WS
X-Environment-Context
X-Framework
X-Cacheable-TTL
X-Content-Powered-By
Protected
X-G
X-L-Path
X-Region
X-User-Agent
X-UUID
X-Jobs
X-RTag
X-Backend-Name
X-Cache-Grace
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-FW-Static
GEO-INFO
Akamai-GRN
X-FW-Type
X-Status
X-FW-Version
X-FW-Serve
X-FW-Dynamic
X-FW-Server
X-ProcessESI
X-FW-Hash
X-RemovedCookies
VIX-Pulpo-Upstream-Status
X-Http-Reason
X-Akamai-Request-ID2
VIX-Pulpo-Node
Section-Io-Cache
Front
X-Trace-Id
From-Origin
NGB
X-Is-Bot
X-Rendered-As
X-Device-Type
X-NYM-Debug-Backend
X-Instance
X-Cache-Status-Check
X-Page-View
X-Cache-Expired-At
X-Drupal-Cache-Tags
X-Drupal-Cache-Contexts
X-Adobe-Content
X-Adobe-Loc
X-RateLimit-Limit
X-Nginx-Cache
X-Unique-Id
X-XRDS-LOCATION
Pinterest-Generated-By
Url
Pinterest-Version
X-Pinterest-Rid
X-Servername
Liferay-Portal
CDN-RequestId
X-Time
X-Content-Options
Accept-Language
X-Template
X-CDN-Forward
Fastly-SWR
SRV
Fastly-SIE
X-Air-Trace-Id
X-Air-Source
X-Air-Hostname
X-Zen-Fury
X-Newrelic-App-Data
X-Debug-IsPreview
X-Debug-IsConnected
Backend
X-Cache-Hit
X-DynaTrace-JS-Agent
X-Mode
X-Yottaa-Optimizations
X-Yottaa-Metrics
Country
X-Uri
X-Rocket-Nginx-Serving-Static
Content-Secure-Policy
X-Tec-Api-Origin
X-Tec-Api-Root
X-Varnish-Ttl
X-App-Version
X-Tec-Api-Version
X-COUNTRY
X-Fastly-Request-Id
X-ARC
X-Edge-Location
Node
X-Cache-Operation
X-Tumblr-Pixel-3
X-UPSTREAM-Address
X-Amzn-Remapped-Content-Length
X-Zipkin-Id
Webserver
X-Tumblr-Pixel-2
X-Routing-Service
X-Generation-Time
X-Cache-Server
X-RN-RSRV
X-Proxy-Cache-Info
X-Rewrite-Enabled
X-Proxied
X-Extlb
S-Rt
Onion-Location
Meta-Geo
Filters
Azure-SiteName
Azure-SlotName
Azure-Version
Azure-InstanceId
Selected-Fe
Countrycode
Uber-Trace-Id
Azure-RegionName
Cache-Hits
X-Locale
X-Proxy-Build
X-IPS-LoggedIn
X-Server-W
X-Timing-Wait
X-PHP-Backend
Property-Id
X-Proxy-Cache-Status
Mn-Server-Ip
X-Cms-Context
X-Site-Version
TWC-Connection-Speed
X-Skip-Cache
X-Section
X-Origin-Hint
X-Reqid
X-ProxyCache-Status
X-LJ-Flow-ID
X-Format
TWC-Device-Class
CF-IPCountry
Cache-Name
X-ProxyCache-Key
TWC-GeoIP-LatLong
X-Via-Fastly
X-Tb
Webcakes-Region
X-Cluster-Node
X-Access
X-Ms-Request-Id
X-UA-Device-Type
X-Ua
X-AWS-Id
X-VWS-Id
X-BYPASS-REASON
TWC-Privacy
TWC-Locale-Group
X-Cache-Action
X-Ms-Version
X-Soup
X-Sucuri-Cache
Webcakes-App-Name
X-Web-Node
X-Sucuri-ID
TWC-GeoIP-Country
Webcakes-App-Version
X-Content-Age
WP-Super-Cache
X-IPLB-Request-ID
X-Labrador-Cache-Channel
X-PHP-Host
ServerID
X-IPLB-Instance
X-Debug
X-Cache-Host
X-Cluster
X-Say-Cacheable
Web-Mar-Node
X-Proto
X-SayCDN-TTL
Cache-Tv-Group
X-Say-TTL
X-Forwarded-Host
X-Urbn-Site-Id
X-Detected-As
X-Xfnlog-Site
Locale
X-Ruxit-Js-Agent
X-Cache-TTL-Remaining
X-Urbn-Context-Path
X-Sql-Count
X-Origin-Date
X-R9-Blue-Green-Version
X-SaId
X-Optimistic-Header
X-No-Session
X-JoinUs
X-LAGOON
X-Sql-Duration-Ms
X-VC-Cache
DB-Nickname
Cross-Origin-Window-Policy
Apigw-Requestid
X-Varnish-Beresp-Grace
X-Real-IP
X-Webkit-CSP
X-Handled-By
X-LSADC-Cache
X-Director
ServedBy
X-FB-TRIP-ID
X-Adobe-Source
Fastcgi-Useragent
X-Node-Name
Frame-Options
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
X-GeoCountry
X-GeoCode
X-Oneagent-Js-Injection
X-Varnish-Hits
Upgrade-Insecure-Requests
Mime-Version
X-Tt-Logid
Fastly-Drupal-HTML
Source
X-Api-Version
Load-Balancing
X-Aspnetmvc-Version
CDN-Cache
X-Hl-Ver
CDN-CachedAt
CDN-EdgeStorageId
CDN-RequestCountryCode
CDN-PullZone
CDN-Uid
X-Varnish-Cache-Hits
X-Generated-By
X-Buckets
X-GEO
X-Request-Time
X-ServerID
X-Varnish-Hostname
X-FireWall-Port
X-Datadog-Trace-Id
X-RM-Cache-TTL
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
X-Webkit-CSP-Report-Only
X-Datadog-Sampled
X-Origin-CC
X-URL
Xet-Cookie
X-Origin-TTL
X-Redis-Cache
X-Mg-Request-UUID
X-TIME
X-TA-CDN-Provider
X-Akamai-Transformed
X-SRV
X-Cache-Debug
CF-Cached-On
Xserver
X-Loop
X-Served-From
X-ShopId
X-ShardId
X-Shopify-Stage
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Alternate-Cache-Key
X-Provided-By
X-Pubstack
X-Storage
X-Storefront-Renderer-Rendered
X-Endurance-Cache-Level
X-Restarts
X-Pass-Why
X-Tx-Id
X-Newrelic-Synthetics
X-Request-Host
X-CSRF-Token
X-Location
X-External-Request-Id
X-ScT
C-Via
X-Ec-GeoHdr
X-Epic-Correlation-Id
X-Cache-Info
X-Thinkindot-L3
X-Rojux
X-Bip
Surrogated-Key
Sslversion
X-Fetched-On
T-Server
X-Sigma
Cache-Host
X-BCube-Filmed-By
X-Ec-Fail
BehaviorPad-Version
X-D
X-Application
Thinkindot-Control
X-CUA
A
X-Conf
X-Aed
X-CMSURLCustom
X-Destination
X-A
TDXMobile
X-Cache-NE
X-Core-Mission
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
X-Developer
X-B-Cookie
X-S
X-Auto-Login
X-Test
DCR-Processing-Time-Ms
X-Vdms-Path
X-Nyt-Route
Odigeo-Trace-Id
X-Origin
X-Vdms-Version
DCR-Decision-By
X-Men
X-Mid
X-Mobile-URL
X-A-Dam
X-Origin-Time
X-S-Cookie
Memcached
X-S-Maxage
MD5-Digest
Lang
X-Processor
Meta-Geo-Continent
DSUID
NM-Fastcgi-Cache
X-TIM-N
X-Sigma-Backend
Ngx.Var.Host
Origin
X-Level-Front-Cache
X-Generated-On
X-SVT-ORM-VERSION
Server-Host
X-A-Wwc
X-SVT-ORM-RULES
X-Bc-Bl
X-Scale
Xc-Version
X-Thanos
X-A-Ccd
X-Gdpr
Candidate-Md5Url
X-SRCache-Key
Host-ID
X-Rocket-Build-Number
X-A-Dgt
X-A-Dcw
X-INCAP-ABP
Rendered-Blocks
Redirect-Candidate
X-We-Are-Hiring
Gannett-Cam-Experience-Id
Release
X-Hash
X-Via-CDN
Server-Info
X-Varnish-Beresp-Ttl
HostName
X-Service
X-Httpd
Origin-CC
Origin-EX
On-Server
Mail-Subject
Gh-Request-Id
Locid
Srvid
Tube-Got-Results
Tube-Return
Tube-Got-Eval
WWW-Authenticate
We-Hiring
Tube-Get-Contents
Req-Svc-Chain
X-Server-IP
X-Mvc-Supplant-Cachable
X-Nginx-Cache-Key
X-Node-Id
X-Org
X-Loc
X-Instance-Name
X-Sn-Servicetimems
X-HS-Content-Campaign-Id
X-Slack-Shared-Secret-Outcome
X-Human
X-Varnishpool
X-Platform
X-Region-Sid
X-Req
X-Response-By
X-Var-Ttl
X-Pool
X-Slack-Backend
X-Platform-Cluster
X-Platform-Processor
X-Platform-Router
X-Gzip
X-Geo-Header
X-Cdn-Origin
X-Cdn-Srv
X-SD-PageType
X-Date
X-CacheTTL
X-Cache-Id
X-BBC-Edge-Cache-Status
X-Cache-Bucket
X-Cache-Date
X-Developers
X-Dispatcher-Number
X-FL-EDGE
X-FL-QIT-DEBUG
Magicmarker
X-Gamma-Serve
X-Fastly-Cache
X-Fastly-Backend
X-Dispatcher-Server
X-Ec-Custom-Error
X-Esi-Check
X-Akamai-Device-Characteristics
X-Accel-Expires-Debug
Cmsid
AKAMAI
Cmstype
Edge-Cache
Country-Code
CloudFront-Viewer-Country
Fastly-Backend-Name
CacheControlHeader
Cache-Key
Fastly-GeoIP-CountryCode
Click-Count-Error
Click-Count-Action-Start
Section-Io-Origin-Time-Seconds
Section-Io-Id
Section-Origin-Responded
X-Via-SSL
Section-Io-Origin-Status
X-WP-CF-Super-Cache-Active
X-Vcl-Version
Edge-Copy-Time
Environment
X-Via-Edge
X-Frame-Option
X-Block-Status
X-Gen-Mode
X-Cache-FS-Status
X-GeoIP
X-GeoIP-Country-Code
X-GeoIP-City
X-Azure-Ref-OriginShield
X-Forwarded-Site
X-Core-Value
X-DefElseHash
X-GeoIP-Region-Code
X-Device-Os
X-Clara-WADP
X-FC-Vary-Parameters
X-DefHash
X-Ckpd-Fst-Backend
X-Fmm-Version
L
X-JWT-State
X-Variation
X-Varnish-CookieHashed-On
X-V-Cache
X-SB
X-VarnishDD-TTL
X-HN
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
X-Worker
Cache-Provider
X-WADP-Cache
X-WA-Info
X-Vmg-Version
X-VServer
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-Minions-Version
X-Mly-Id
X-Is-Gdpr
X-Irp-Debug
X-VC
X-Hnp-Log
X-NCache
X-NodeID
X-Owner
X-Planisys-CDN-Cache
PFcat
X-Origin-Response-Time
X-Op-Id-All
X-Has-Esi
X-Zone
Server-Ext
Apple-News-Services-Handled
Vix-Hermes-Req-Id
User-Cache-Control
Platform
X-Ad-Defer-Variation
Web-Mar-Region
Wxu-Next-Region
Wxu-Next-Hostname
Adler-Geo
Datacenter
Wxu-Next-Commit
Server-Hostname
Machine
Apple-News-Services-Parsed-Url
Is-Eu
Apple-News-Services-Request-Url
Ssr
State
Kp-EeAlive
Canary
Apple-News-Services-Host
Expect-Staple
Sever-Int
X-TNCMS
Ha-Gx-Prefs
X-Microcachable
X-Qloud-Router
X-Release
X-Ua-Device
X-DPWN-IS-SECURE
X-Old-Content-Length
Producers
X-Origin-Expires
X-Cache-Tags
X-From
HA-Ipaddr
X-CGP
L5d-Success-Class
X-Aicache-OS
X-VG-TLSProxy
X-Csrf-Jwt
X-Cache-Remote
X-Eu-Site
X-App
CDCHOST
X-RCS-CacheZone
NGX
X-Air-Pt
X-CACHE-AGE
X-Nananana
X-Mvc-Supplant-OutputCached
X-Lambda-Id
Fastly-SSL
X-Debug-Cache-Fetch
X-LB-NoCache
X-VCT
X-Accel-Buffering
X-Cache-Enabled
X-Varnish-Beresp-Status
X-Request-Start
X-Wix-Viewer-Type
X-Correlation-ID
X-Debug-Cache-Store
X-Platform-Server
X-Parent-Response-Time
X-B3-SpanId
Pics-Label
X-Up
X-Dc
X-Generated-In
CPC-Age
X-Refresh
X-AIR-PT
X-Tb-Optimization-Total-Bytes-Saved
X-Via-Popn
X-Via-Poph
VNS-Age
VNS-Cache
X-Render-Time
X-Via-Popv
CPC-Cache
X-Upstream-Ct
X-Upstream-Ht
X-Vtex-Remote-Cache
X-Trace-ID
X-B3-Spanid
X-DC
X-Cs
X-Cached-By
GeoIP-Latitude
AMP-Access-Control-Allow-Source-Origin
X-HA-Backend
X-Cache-Backend
SID
X-Cache-Type
Cluster
Decoy-Debug-TTL
Decoy-Debug-Key
Decoy-Debug-Status
X-ND-Cache
X-CCDN-Origin-Time
Cache
Sid
Memory
Env
X-CCDN-CacheTTL
X-TH-Server
Time
X-Hcs-Proxy-Type
NtCoent-Length
X-ATG-Version
X-Servedbyhost
X-LB-ID
X-Nf-Request-Id
X-Tid
X-Srv
Server-ID
X-Presslabs-Stats
X-Edge-Pop
X-HS-Status
X-Wa
X-Esi
X-Nc
X-NWS-UUID-VERIFY
Srv
Cdn
X-Client-Ip
X-DataCenter
X-Contensis-Viewer-Groups
X-NewRelic-App-Data
X-Cache-ASPX
X-Via-JSL
X-Varnish-Authentication
X-MP-GENERATED-AT
Svr
X-RateLimit-Remaining-Second
X-PAYTM-SRV-ID
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-RateLimit-Limit-Second
Fastly-Drupal-Html
X-Datadome
X-Vgn-Hpd-Variations-Key
Esi-Enabled
X-Vgn-Hpd-Ssi
X-Vgn-Hpd-Cached
X-Fpc
X-Amz-Meta-Cb-Modifiedtime
GeoIp-Country-Code
Uri
X-Proxy-CacheRZ
YJS-ID
X-Check-Cacheable
XkeyRZ
X-ZONE
N-Cache
Lb
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-CDN-Cache-Status
X-Udemy-Cache-App-Namespace
X-Vc
X-Shop-Environment
X-Forwarded-Path
M-TraceId
X-CACHE-KEY
RNT-Time
True-Client-Ip
RNT-Machine
True-Client-IP
Resin-Trace
X-Bl-Debug
X-Orig-Expires
X-Tenant
X-NGINX-Cache
X-CS
Hostname
X-TX-ID
X-EC-Lua
X-CSRF-TOKEN
X-Fastly-Country-Code
X-Gateway-Cache-Key
X-B3-Trace-ID
X-Policy
Cdnsip
X-App-Name
X-Gateway-Cache-Status
X-AK-Request-ID
OT-Force-Account-Verify
X-MSEdge-Flight
X-Varnish-Beresp-TTL
XServer
X-Via-NSCOPI
X-MSEdge-Features
Cdncip
X-Gateway-Skip-Cache
X-Gateway-Request-Id
X-FPC
X-API-Version
X-Logging-Id
X-Service-Response-Time
Sm-Log-Id
GeoIP-Country-Code
X-Cache-Ttl
Eomportal-Instance
Path
X-Datacenter
X-Container-Uri
X-Git-Commit
X-Accel-Version
X-Vcache
CDN
Server-Id
X-Cdn-Diag
Hit
X-CLOUD-TRACE-CONTEXT
Ngx-Var-Key
X-Lb-Id
X-VCL-Version
X-MCACHE
HIT
IsBot
X-WA
X-Micro-Cache
X-SIPLIST1
X-APP-VERSION
LB
X-Geo
X-Cache-NGX
X-Edge-POP
X-NC
X-Ha-Backend
X-Request-URI
X-RateLimit-Reset
X-Akamai-Pragma-Client-IP
X-Cdn-Cache-Status
RATING
X-Info
V-Age
XM
X-ServedByHost
X-SERVER-NAME
ENV
X-Acquia-Purge-Cdn-Unconfigured
X-Tncms
X-VG-WebCache
Pramga
X-Xrds-Location
CDN-RequestPullSuccess
X-Snapshot-Date
X-Srcache-Fetch-Status
X-Cdn-Forward
X-Rebelmouse-Surrogate-Control
Geoip-Latitude
X-Clientip
X-Rebelmouse-Cache-Control
Timeexpire
X-Srcache-Store-Status
CDN-RequestPullCode
FSS-Cache
Tcn
X-TT-LOGID
X-Ctl-Mach
Epwk-X-Cache
Req-ID
X-Via-PopV
X-Via-PopN
X-Via-PopH
Yjs-Id
Location
True-Client-Country-4JS
Cross-Origin-Opener-Policy-Report-Only
Cdn-Requestid
X-HostName
X-Iauth-Set-Uid
X-TimeS
X-Wp-Cf-Super-Cache-Cache-Control
X-Wp-Cf-Super-Cache
W
X-Hyper-Cache
X-Amz-Meta-Opti
X-Pod-Name
Ohc-File-Size
X-Dw-Trace-Id
Proxy-Connection
X-Lb-Nocache
X-Serial
Warning
X-LiteSpeed-Cache-Control
X-M-Reqid
X-M-Log
X-LiteSpeed-Tag
X-Litespeed-Cache-Control
X-Viewer-Country
X-Cdn-Request-ID
X-UP
X-ApacheServer
X-PERF
X-RAMCache
X-Vgn-Hpd-Reason
Content-Script-Type
Cneonction
Servername
X-Fastly-Backend-Reqs
Content-Style-Type
WZWS-RAY
X-Qnm-Cache
X-Acquia-Site
X-Acquia-Purge-Tags
X-Acquia-Application-Trace
X-Acquia-Application-UUID
X-Lsadc-Cache
CountryCode
X-MiniProfiler-Ids
X-Akamai-ERRuleID
X-Oss-Request-Id
X-Akamai-ERPolicy
X-TraceId
X-WP-CF-Super-Cache-Cookies-Bypass
X-Oss-Server-Time
X-Oss-Storage-Class
X-Oss-Object-Type
X-Moov-T
X-Moov-Xdn-Version
X-User
X-Erf-Stays-Pdp-Viaduct-Migration-Web
X-IPS-Cached-Response
X-Th-Server
X-Mg-Cache
X-Cache-Expires
X-B3-ParentSpanId
X-Webstats-RespID
Ec-Rule-Version
Ngx
X-B3-Parentspanid
MIME-Version
X-Oss-Hash-Crc64ecma
Ohc-Cache-HIT
My-App
X-Fastly-Cache-Hits
PICS-Label