Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
X-Powered-By
Pragma
X-XSS-Protection
CF-RAY
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
Alt-Svc
P3P
X-Cache-Hits
X-UA-Compatible
X-Xss-Protection
X-Served-By
CF-Ray
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
Access-Control-Allow-Credentials
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
X-Drupal-Cache
X-Cache-Status
X-Generator
X-Check
X-Cacheable
X-Envoy-Upstream-Service-Time
X-FRAME-OPTIONS
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Iinfo
X-Dns-Prefetch-Control
Server-Timing
X-Drupal-Dynamic-Cache
Feature-Policy
X-Content-Security-Policy
Access-Control-Expose-Headers
Content-Encoding
X-CDN
Status
X-XSS-PROTECTION
Upgrade
X-Request-ID
X-AspNetMvc-Version
Access-Control-Max-Age
X-Amz-Request-Id
X-Via
X-Amz-Id-2
Request-Context
X-Ua-Compatible
X-Backend
X-Cache-Group
X-Turbo-Charged-By
X-Robots-Tag
Cf-Edge-Cache
Keep-Alive
Host-Header
X-AH-Environment
X-UA-Device
X-Vhost
X-Hacker
X-Proxy-Cache
X-Server
Allow
X-Rq
X-Server-Powered-By
X-Ws-Request-Id
X-Dispatcher
X-Age
EagleId
X-Varnish-Cache
X-Amz-Version-Id
P3p
Nel
Grace
X-LiteSpeed-Cache
Cf-Apo-Via
Cf-Railgun
X-OneAgent-JS-Injection
X-Page-Speed
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
EagleEye-TraceId
X-Device
X-Swift-SaveTime
X-Swift-CacheTime
X-Aws-Lambda-Call-Status
Ali-Swift-Global-Savetime
X-Pingback
X-Host
Accept-CH
X-Cache-Lookup
X-CST
X-Node
X-WebKit-CSP
X-Backend-Server
Surrogate-Control
X-Server-Id
Permissions-Policy
X-Readtime
X-Nginx-Upstream-Cache-Status
X-Akam-SW-Version
X-Nginx-Cache-Status
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Request-Id
X-Application-Context
Accept-CH-Lifetime
Xkey
X-Cloud-Trace-Context
X-Content-Security-Policy-Report-Only
X-Response-Time
X-Ruxit-JS-Agent
X-HW
X-Trace
X-Edge
Content-Location
X-Clacks-Overhead
X-Mod-Pagespeed
Rating
X-ESI
X-Midtier
X-Url
X-Amz-Server-Side-Encryption
X-ECACHE
Cache-Tag
X-Mcache
X-Country
Accept-Ch-Lifetime
X-Rack-Cache
X-Powered-By-Plesk
X-MS-InvokeApp
X-D2id
Service-Worker-Allowed
X-Kinja-Build
X-Kinja-Server
X-Kinja-Revision
X-Kinja
X-GoogleNews-Bot
X-Cdn-Fetch
X-Use-Magma
X-Exp-Id
X-Exp-Variant
X-Vcap-Request-Id
Verso
X-Element-Page-Cache
X-Upstream
Accept-Ch
Edge-Control
X-Litespeed-Cache
X-Country-Code
X-Ac
Origin-Trial
RTSS
X-Vname
X-TtlSet
X-PC
X-Goog-Hash
X-Webkit-CSP
X-Navigation-Version
X-VARITI-CCR
X-Kinja-CCPA
X-Abt-Application-Version
X-Cache-TTL
X-Browser-Type
Fastly-Restarts
X-Amz-Rid
X-Varnish-TTL
X-NWS-LOG-UUID
X-Oneagent-Js-Injection
X-GitHub-Request-Id
Cross-Origin-Opener-Policy
X-Aspnetmvc-Version
X-Ruxit-Js-Agent
X-Cached
X-Server-Name
X-Amzn-Trace-Id
X-Dw-Request-Base-Id
Display
X-Sol
X-Middleton-Display
Pagespeed
X-SharePointHealthScore
X-WebKit-CSP-Report-Only
SPRequestGuid
Pinterest-Generated-By
Pinterest-Version
X-Pinterest-Rid
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-Content-Type
SPIisLatency
SPRequestDuration
X-Erf-Bev-Bev-Is-Generated
X-Instrumentation
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Erf-Bev-Bev
X-Cache-Key
X-Times
X-Server-ID
AR-SID
AR-Request-ID
AR-ATIME
AR-PoweredBy
X-Ttl
X-Powered-CMS
X-B3-Traceid
Arr-Disable-Session-Affinity
X-Mg-S
X-Version
X-Client-IP
X-Cnection
X-Middleton-Response
Response
X-Ser
Nginx-Cache
X-HP-Trace-Id
X-Jurisdiction
X-HP-Webp
X-FastCGI-Cache
X-Accel-Expires
Cache-Tags
X-Fastly-Request-ID
AR-CACHE
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-T
Cache-Status
Edge-Cache-Tag
X-B3-TraceId
X-Hits
X-RateLimit-Remaining
X-MSEdge-Ref
X-Px
X-NF-Request-ID
Public-Key-Pins
Front-End-Https
X-Recruiting
S
X-Shield-Request-Id
Payment
X-Daa-Tunnel
X-LLID
X-Frontend
Server-Node
X-Ua-Browser
X-RateLimit-Limit
X-Request-Received
X-Request-Processing-Time
Mrf-Cache-Status
X-B3-TraceId-Primal
MRF-Tech
Content-MD5
X-Goog-Metageneration
X-GUploader-UploadID
X-Webkit-CSP-Report-Only
X-TTL
MicrosoftSharePointTeamServices
Access-Control-Request-Method
X-Content-Digest
X-Amzn-RequestId
X-Amz-Apigw-Id
X-DIS-Request-ID
X-Forwarded-For
TP-Cache
X-Protected-By
Realpath
X-Microsite
X-PressLabs-Stats
X-Request-Handler-Origin-Region
X-Fastcgi-Cache
X-Distributor
X-FB-Debug
Fastcgi-Cache
X-HS-Content-Id
X-HS-Cache-Config
X-Xrds-Location
X-HS-Hub-Id
X-HS-Combine-CSS
Access-Control-Allow-Method
X-Page-Id
X-LB-Cache
Accept-Charset
X-Cluster-Name
X-Rid
X-Ratelimit-Remaining
Count-Hit
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-Hostname
X-Id
X-B3-Sampled
X-Kinsta-Cache
X-Edge-Location-Klb
X-Geo-Country
X-Aspnet-Version
Cross-Origin-Resource-Policy
TP-L2-Cache
X-Ua-Device
X-Seen-By
X-App-Server
TCN
X-Varnish-Backend
X-Ezoic-Cdn
X-Logged-In
Cleartype
Referer-Policy
X-Ratelimit-Limit
X-Content-Options
X-Erf-Stays-Pdp-Viaduct-Migration-Web
X-Hosted-By
X-Git-Hash
X-Correlation-Id
DC
X-Mobile
Retry-After
X-Newrelic-App-Data
X-Fb-Rlafr
X-Contextid
X-Origin-Cache
X-Request-Guid
X-Providence-Cookie
X-Flags
X-Aspnet-Duration-Ms
X-TEC-API-VERSION
X-Is-Crawler
X-Route-Name
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-F-Cache
Surrogate-Key
X-Forwarded-Proto
X-Revision
X-Grace
X-TT
X-Amz-Replication-Status
X-App-Environment
X-Debug-Info
Frame-Options
X-IPS-LoggedIn
X-Varnish-Grace
X-Amz-Meta-S3cmd-Attrs
X-Envoy-Decorator-Operation
X-Azure-Ref
MS-Author-Via
Section-Io-Cache
X-Magnolia-Registration
X-RateLimit-Reset
X-Www-Served-By
X-Proxy-Cache-Info
X-Wix-Request-Id
X-Whom
X-App-Version
Healthy
X-Language
X-Activity-Id
Charset
X-AppVersion
X-Az
X-Nf-Request-Id
X-Akamai-Edgescape
Alternate-Protocol
X-Trace-Id
Viewport
Filterid
X-COUNTRY
X-Webkit-Csp
WPO-Cache-Message
WPO-Cache-Status
Server-Name
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Backend-Name
X-Varnish-Server
X-Origin-Server
X-EdgeConnect-Cache-Status
X-Datadog-Sampling-Priority
X-Datadog-Trace-Id
X-Datadog-Parent-Id
Paypal-Debug-Id
X-B
X-Http-Reason
X-Response-Served-From
X-Original-Request-Id
Host
X-Cache-Rule
VIX-Pulpo-Node
SRV
VIX-Pulpo-Upstream-Status
X-User-Agent
X-UUID
X-Akamai-Request-ID2
X-Vcache
X-Cache-Grace
X-Edge-Location
X-Instance
X-Rule
Front
Amp-Access-Control-Allow-Source-Origin
X-Yottaa-Metrics
X-Page-View
X-Yottaa-Optimizations
X-L-Path
X-Jobs
Country
Content-Disposition
X-Unique-Id
X-N
X-Region
X-Cacheable-TTL
SD-X-WS
From-Origin
X-ARC
X-Time
X-Environment-Context
X-RemovedCookies
X-FW-Dynamic
X-Signature
X-Rendered-As
X-FW-Serve
X-FW-Server
X-FW-Hash
X-ProcessESI
X-B-Cache
Akamai-GRN
Fastly-SWR
X-Status
X-Adobe-Content
X-Is-Bot
Fastly-SIE
X-Adobe-Loc
Protected
X-FW-Type
X-FW-Version
X-FW-Static
X-Rocket-Nginx-Serving-Static
X-Load-Cache
X-Varnish-Age
X-Client-Ip
X-Framework
X-Tec-Api-Origin
X-Tumblr-User
X-Mg-Request-UUID
X-Tec-Api-Root
X-Cache-Time
X-G
X-Tec-Api-Version
X-Proxy
X-Datadog-Sampled
X-Type
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-DataDome
X-Amzn-Remapped-Content-Length
X-Debug-IsPreview
X-Debug-IsConnected
Access-Control-Request-Headers
ServerID
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
X-CDN-Forward
Backend
X-ECache
X-URL
X-Cache-Age
X-Cache-Control
Refresh
X-Nginx-Cache
Countrycode
Xet-Cookie
X-Servername
X-Tt-Trace-Tag
Url
X-Tt-Trace-Host
X-DynaTrace
X-Httpd
Accept-Language
X-Erf-Web-Scheduler
CF-IPCountry
X-Template
X-Drupal-Cache-Tags
X-Mode
X-DynaTrace-JS-Agent
X-Device-Type
X-NYM-Debug-Backend
X-Content-Powered-By
X-Generated-By
X-HTML-Minification-Powered-By
Xserver
X-Cache-Hit
X-Storage
X-Hcs-Proxy-Type
GEO-INFO
X-Source
X-CCDN-Origin-Time
X-CCDN-CacheTTL
Version
Webserver
X-SayCDN-TTL
X-Rn-Rsrv
X-Cache-Operation
X-Urbn-Context-Path
X-Urbn-Site-Id
X-GeoCode
X-GeoCountry
X-Director
X-Rewrite-Enabled
X-SaId
X-Content-Age
X-Tncms
X-Say-Cacheable
X-JoinUs
X-Say-TTL
X-FTR-Request-ID
OT-Force-Account-Verify
S-Rt
Locale
Meta-Geo
Load-Balancing
X-LAGOON
X-UPSTREAM-Address
X-ServerID
X-Loop
Filters
X-Cache-Action
Onion-Location
X-Container-Uri
X-Tt-Logid
X-Cluster-Node
Cross-Origin-Window-Policy
X-Varnish-Cache-Hits
X-Soup
X-Forwarded-Host
X-Git-Commit
X-VCT
X-Lambda-Id
X-Skip-Cache
X-VC-Cache
X-Labrador-Cache-Channel
X-Adobe-Source
X-Sql-Count
Azure-SiteName
Azure-SlotName
Azure-Version
Azure-RegionName
Azure-InstanceId
X-Ms-Version
X-Sql-Duration-Ms
Web-Mar-Node
X-Ms-Request-Id
X-Tb
X-NGENIX-Cache
X-Served-From
X-Varnish-Hostname
X-RM-Cache-TTL
X-Detected-As
X-PHP-Host
X-Extlb
X-R9-Blue-Green-Version
X-Routing-Service
X-FB-TRIP-ID
Node
Mn-Server-Ip
X-Zipkin-Id
X-RCS-CacheZone
X-Cache-Server
DB-Nickname
X-XRDS-LOCATION
X-Proxied
X-Logging-Id
X-Uri
Property-Id
X-Format
X-Timing-Wait
X-Redis-Cache
X-Fetched-On
TWC-Privacy
X-Debug
Webcakes-App-Name
Webcakes-App-Version
Webcakes-Region
X-Tumblr-Pixel-3
X-Generation-Time
X-Tumblr-Pixel-2
X-Proxy-Build
TWC-Device-Class
TWC-Connection-Speed
TWC-GeoIP-Country
TWC-GeoIP-LatLong
X-Origin-Hint
Selected-Fe
TWC-Locale-Group
X-MCACHE
Fastcgi-Useragent
X-TimeS
X-Proto
X-Endurance-Cache-Level
Uber-Trace-Id
Source
X-Zen-Fury
X-B3-SpanId
X-LSADC-Cache
X-Ua
X-S
CDN-RequestId
X-Sucuri-Cache
Section-Origin-Responded
Section-Io-Origin-Time-Seconds
X-XRDS-Location
X-Sucuri-ID
Section-Io-Id
Section-Io-Origin-Status
X-Newrelic-Synthetics
X-Origin-CC
NGB
X-Origin-TTL
X-Ratelimit-Reset
X-Oracle-Dms-Rid
X-Drupal-Cache-Contexts
X-Oracle-Dms-Ecid
X-Srv
Upgrade-Insecure-Requests
X-Akamai-Transformed
X-Origin-Date
X-MP-GENERATED-AT
Fastly-Drupal-HTML
X-Real-IP
X-Pass-Why
X-Handled-By
X-Cache-Expired-At
X-Varnish-Hits
Liferay-Portal
X-RTag
X-Cms-Context
Apigw-Requestid
MS-CV
Ms-Operation-Id
X-Xfnlog-Site
X-No-Session
X-Reqid
X-Optimistic-Header
X-CACHE-AGE
ServedBy
X-Restarts
X-ProxyCache-Status
X-Cache-Host
X-AB
X-TraceId
X-BYPASS-REASON
X-ProxyCache-Key
X-Correlation-ID
WP-Super-Cache
X-Hl-Ver
X-IPLB-Instance
X-Cache-Type
X-IPLB-Request-ID
X-LJ-Flow-ID
X-VWS-Id
X-UA-Device-Type
CDN-Cache
CDN-EdgeStorageId
CDN-Uid
X-AWS-Id
CDN-RequestPullSuccess
CDN-RequestPullCode
CDN-PullZone
CDN-RequestCountryCode
CDN-CachedAt
X-Cluster
X-GEO
X-CSRF-Token
X-Node-Name
X-Upgrade-Enabled
X-Cache-TTL-Remaining
X-Varnish-Ttl
X-Geo-Region
X-Via-JSL
X-Parent-Response-Time
X-Proxy-Cache-Status
X-Tx-Id
Cache-Provider
X-Fastly-Request-Id
X-Pubstack
X-CF-Lambda-Version
X-CF-Lambda-Fn
X-CGP
DCR-Processing-Time-Ms
DCR-Decision-By
X-Cache-NE
X-CacheTTL
Candidate-Md5Url
Canary
BehaviorPad-Version
X-D
X-ScT
X-Worker
Xc-Version
X-Debug-Cache-Fetch
X-Cache-Status-Check
X-Debug-Cache-Store
X-Viewer-Country
X-Vtex-Remote-Cache
X-Rojux
X-Csrf-Jwt
X-S-Cookie
X-PAYTM-SRV-ID
X-We-Are-Hiring
X-Conf
Ha-Gx-Prefs
Sslversion
Surrogated-Key
T-Server
X-Aed
X-App
X-Application
Server-Host
True-Client-Country-4JS
Vix-Hermes-Req-Id
X-A-Dcw
X-A
X-A-Ccd
X-A-Dgt
X-A-Wwc
W
Web-Mar-Region
Rendered-Blocks
Redirect-Candidate
Lang
X-Bl-Debug
Magicmarker
L5d-Success-Class
L
Gannett-Cam-Experience-Id
HA-Ipaddr
MD5-Digest
X-BCube-Filmed-By
Odigeo-Trace-Id
Origin-Agent-Cluster
X-B-Cookie
Ngx.Var.Host
N-Cache
X-Bc-Bl
Meta-Geo-Continent
Fastly-SSL
X-Request-Host
X-Slack-Shared-Secret-Outcome
X-Eu-Site
X-SRCache-Key
X-Dispatcher-Number
X-Ec-GeoHdr
X-Ec-Custom-Error
X-Ec-Fail
X-Fastly-Backend
X-FC-Vary-Parameters
X-External-Request-Id
X-Slack-Backend
X-Micro-Cache
X-Developer
X-Vdms-Path
X-Epic-Correlation-Id
X-Destination
X-A-Dam
X-Vdms-Version
X-Server-W
Cache-Name
X-B3-Spanid
X-Accel-Buffering
Expect-Staple
X-SVT-ORM-RULES
X-Mly-Id
X-SVT-ORM-VERSION
Fastly-Backend-Name
Mail-Subject
X-Storefront-Renderer-Rendered
Host-ID
X-Origin-Time
X-Varnish-CookieHashed-On
X-Sorting-Hat-ShopId
Gh-Request-Id
X-Qloud-Router
X-Cache-Bucket
X-Cache-Debug
X-AIR-PT
X-Nananana
Is-Eu
Fastly-GeoIP-CountryCode
Origin
X-Alternate-Cache-Key
X-Up
X-ApacheServer
X-Varnish-Remaining-TTL
X-App-Name
X-Varnishpool
X-Old-Content-Length
X-Var-Ttl
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
TDXMobile
X-Variation
X-Nitro-Cache
X-Nyt-Route
X-Level-Front-Cache
Req-Svc-Chain
X-Thinkindot-L3
X-NodeID
X-Pool
Environment
X-Tenant
X-Irp-Debug
X-Orig-Expires
X-Hash
Release
X-Owner
X-Mid
Producers
X-Accel-Expires-Debug
Platform
X-BBC-Edge-Cache-Status
CPC-Age
X-Geo-Header
X-Varnish-CookieINHashed-On
X-Dispatcher-Server
X-VServer
X-Vmg-Version
X-Shopify-Stage
X-DPWN-IS-SECURE
X-Mvc-Supplant-Cachable
X-Wikidot-Static-Cache
We-Hiring
X-Request-Time
X-GeoIP-Region-Code
X-Wikidot-Backend
X-Wix-Viewer-Type
X-Forwarded-Path
X-SD-PageType
X-Server-IP
X-DefElseHash
X-DefHash
X-Datadome
X-ShardId
X-Generated-On
X-Gdpr
X-GeoIP-Country-Code
X-ShopId
X-Shop-Environment
X-Date
X-Refresh
X-Human
X-PERF
CloudFront-Viewer-Country
X-Cdn-Diag
X-VG-TLSProxy
X-Cdn-Origin
X-Platform
Cmsid
Cmstype
Datacenter
X-Cache-Info
CPC-Cache
Thinkindot-Control
X-Bip
X-VG-WebCache
X-Sorting-Hat-PodId
VNS-Cache
Adler-Geo
AKAMAI
X-Policy
X-Core-Mission
X-Loc
X-Core-Value
X-Thanos
X-CMSURLCustom
X-Sn-Servicetimems
VNS-Age
X-Clientip
X-TIME
User-Cache-Control
AMP-Access-Control-Allow-Source-Origin
X-Fmm-Version
X-Cache-Id
X-Device-Os
X-GeoIP
X-Gen-Mode
X-INCAP-ABP
X-Forwarded-Site
X-From
X-Gzip
X-Hnp-Log
X-NCache
X-Auto-Login
X-Block-Status
X-Esi-Check
X-Mvc-Supplant-OutputCached
X-Clara-WADP
X-Nginx-Cache-Key
Apple-News-Services-Host
X-Origin
X-RateLimit-Limit-Second
Apple-News-Services-Handled
X-RateLimit-Remaining-Second
X-S-Maxage
X-Op-Id-All
NM-Fastcgi-Cache
X-Origin-Response-Time
Esi-Enabled
CDCHOST
Apple-News-Services-Request-Url
Cf-Device-Type
Apple-News-Services-Parsed-Url
DSUID
Country-Code
Server-Ext
X-Org
Sever-Int
X-Test
X-WA-Info
X-WADP-Cache
Machine
X-Node-Id
Server-Hostname
X-Vgn-Hpd-Reason
X-Is-Mobile
X-Is-Desktop
X-Is-Tablet
X-Tcp-Rtt
X-Is-Supported-Browser
X-Accel-Version
X-Browser-Name
C-Via
Content-Secure-Policy
X-Instance-Name
X-Ah-Environment
Wxu-Next-Region
X-LB-NoCache
X-Section
X-Via-Fastly
X-Vcl-Version
Ssr
NGX
Server-Info
Pics-Label
X-Cache-Enabled
X-Access
X-Cdn-Srv
Wxu-Next-Commit
Wxu-Next-Hostname
X-Dc
X-Buckets
X-Varnish-Beresp-Grace
X-Akamai-Device-Characteristics
X-Varnish-Beresp-Ttl
X-Amz-Meta-Cb-Modifiedtime
Server-ID
X-API-Version
X-SIPLIST1
IsBot
X-Zone
X-CACHE-GROUP
X-HA-Backend
X-Presslabs-Stats
X-Origin-Cache-Key
X-B3-Parentspanid
YJS-ID
Cdn-Requestid
X-WP-CF-Super-Cache-Active
Sid
X-Cached-By
X-ID
X-Platform-Cluster
X-JWT-State
X-Is-Gdpr
CF-Ctrl
X-Has-Esi
Memcached
X-Platform-Router
X-Platform-Processor
X-Frame-Option
Time
X-Wp-Cf-Super-Cache-Active
Hostname
Location
Memory
X-TA-CDN-Provider
Origin-EX
X-Scale
Origin-CC
X-Hyper-Cache
Cache-Hits
X-Air-Trace-Id
X-Internal-Host
X-Air-Hostname
X-TIM-N
X-Air-Source
X-Tb-Optimization-Total-Bytes-Saved
X-Fpc
X-Backend-Instance
X-FTR-Cache-Status
X-FTR-Balancer
X-FTR-Backend-Server
X-Country-Code-Real
X-FTR-Expires
X-FTR-Backend
X-PHP-Backend
X-Webstats-RespID
X-ZONE
X-Cs
X-DC
Resin-Trace
X-Service
X-VC
X-LiteSpeed-Cache-Control
Epwk-X-Cache
Uri
True-Client-Ip
X-NewRelic-App-Data
X-Site-Version
X-DataCenter
X-Azure-Ref-OriginShield
X-Locale
GeoIP-Latitude
GeoIP-Country-Code
X-NGINX-Cache
X-Microcachable
X-SRV
LB
X-NODE
X-Nitro-Cache-From
WZWS-RAY
Cdn-Host
GeoIp-Country-Code
Cdn-Request-Time
Req-ID
X-Edge-Server
X-NMSegId
X-Nitro-Rev
X-Origin-Expires
Cache-Host
X-VCache
X-Info
XServer
X-Datacenter
X-Geo
Cdn
X-Cache-Ttl
X-Ad-Load-Variation
WebServer
XM
X-Request-URI
X-CSRF-TOKEN
X-VarnishDD-TTL
X-Vercel-Cache
X-Vercel-Id
X-Pad
PFcat
X-Request-Start
X-Scope-Id
X-HN
M-TraceId
X-M-Reqid
NtCoent-Length
X-M-Log
True-Client-IP
X-Pod-Name
HostName
SID
X-Web-Node
X-Qnm-Cache
X-WP-CF-Super-Cache-Cookies-Bypass
X-Shield-Cache-Expires
Content-Style-Type
User-Agent
X-Ad-Defer-Variation
X-Varnish-Beresp-Status
X-Github-Request-Id
Content-Script-Type
Pramga
Cluster
X-Via-SSL
X-MSEdge-Flight
X-Via-Edge
A
X-MSEdge-Features
Locid
X-FL-EDGE
Srvid
Fastly-Drupal-Html
X-FL-QIT-DEBUG
X-CS
X-Cache-Date
X-Via-CDN
X-FPC
Cache-Tv-Group
Edge-Copy-Time
X-HostName
Tcn
Edge-Cache
X-TH-Server
X-Cdn-Request-ID
X-APP-VERSION
Cf-Ipcountry
X-Api-Version
CountryCode
X-Cache-ASPX
X-Moov-Xdn-Version
X-Moov-T
X-ATG-Version
Click-Count-Action-Start
X-Wa
Cdnsip
X-AK-Request-ID
X-NWS-UUID-VERIFY
Cdncip
Tube-Get-Contents
X-Amz-Meta-Opti
X-FireWall-Port
X-Contensis-Viewer-Groups
Click-Count-Error
X-LB-ID
X-Nc
X-Cache-FS-Status
X-B3-Trace-ID
X-Aicache-OS
X-Servedbyhost
X-V-Cache
X-Via-Popn
X-Via-Popv
X-Via-Poph
X-Esi
X-Webkit-Csp-Report-Only
X-Acquia-Purge-Cdn-Unconfigured
X-Varnish-Authentication
Tube-Got-Eval
Tube-Got-Results
Path
Tube-Return
X-LiteSpeed-Tag
On-Server
X-SB
X-Vary
X-Req
X-Men
Cache-Key
V-Age
X-Branch-Name
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-VCL-Version
Priority
Ngx-Var-Key
Yak-Timeinfo
MIME-Version
X-TRACE-ID
XkeyRZ
X-Proxy-CacheRZ
CDN
X-UA
X-CACHE-KEY
Wpo-Cache-Status
X-Akamai-Pragma-Client-IP
Geoip-Latitude
X-Acquia-Purge-Tags
X-Tim-N
X-Render-Time
X-Wp-Cf-Super-Cache-Cache-Control
Wpo-Cache-Message
Proxy-Connection
My-App
X-Acquia-Application-Trace
X-Cdn-Forward
X-Acquia-Site
X-Wp-Cf-Super-Cache
X-Acquia-Application-UUID
Srv
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-Lb-Cache
X-User
X-HS-Content-Campaign-Id
X-Platform-Server
X-Provided-By
X-Fastly-Backend-Reqs
X-Varnish-Director
X-Fastly-Country-Code
X-Ha-Backend
X-Air-Pt
State
X-Generated-In
Lb
Server-Id
X-Planisys-CDN-Cache
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-TT-LOGID
Fusion-Source
Fusion-Deployment-Id
CF-Cached-On
Type
X-Vgn-Hpd-Variations-Key
Fusion-Content-Id
X-Vgn-Hpd-Cached
Fusion-Template-Id
X-Vgn-Hpd-Ssi
Fusion-Content-Source
Fusion-Component-Id
X-Dw-Trace-Id
PICS-Label
X-Fastly-Cache
X-Lb-Nocache
X-Via-Ucdn
X-EC-Lua
Ohc-File-Size
X-CUA
X-Release
Ohc-Cache-HIT
X-Upstream-Ht
X-Upstream-Ct
Yjs-Id
X-TX-ID
X-Iplb-Request-Id
X-Iplb-Instance
X-GoCache-CacheStatus
Warning
X-CDN-Cache-Status
Mime-Version
X-Cdn-Cache-Status
X-ElasticPress-Query
X-Fastly-Cache-Hits
X-Snapshot-Date
Cache
Vha6-Origin
Inserted-Into-Cache-At
X-Traceid
X-Rocket-Build-Number
CACHE-MISS-TO-ORIGIN
X-Sigma
X-Sigma-Backend
X-Cached-Since
X-Litespeed-Cache-Control
X-Miniprofiler-Ids
Cneonction
X-CF-Cache-Header-Cache-Control
X-CF-Cache-Header-Vary
X-RAMCache
X-HS-Status
X-Cache-Remote
Ngx
Log-Origin
X-Udemy-Cache-App-Namespace