Threat Level: green Handler on Duty: Jan Kopriva

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Accept-Ranges
Expect-CT
X-XSS-Protection
Pragma
X-Powered-By
X-Cache
CF-RAY
Via
Age
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Xss-Protection
X-Served-By
CF-Ray
X-Download-Options
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Request-Id
X-Adblock-Key
Access-Control-Allow-Credentials
X-FRAME-OPTIONS
X-Permitted-Cross-Domain-Policies
X-AspNet-Version
Alt-Svc
X-Request-ID
X-Runtime
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Generator
X-Check
X-Cache-Status
X-Cacheable
Timing-Allow-Origin
X-Envoy-Upstream-Service-Time
X-Iinfo
X-Content-Security-Policy
X-Drupal-Dynamic-Cache
Feature-Policy
Content-Encoding
Access-Control-Expose-Headers
Status
Upgrade
X-CDN
X-AspNetMvc-Version
Access-Control-Max-Age
X-Via
Server-Timing
Request-Context
X-Dns-Prefetch-Control
X-Robots-Tag
X-Turbo-Charged-By
X-UA-Device
X-Amz-Request-Id
X-Cache-Group
X-Amz-Id-2
EagleId
X-Backend
X-AH-Environment
P3p
X-Proxy-Cache
Keep-Alive
X-Server
X-Ws-Request-Id
X-Age
Cf-Edge-Cache
Host-Header
X-Hacker
X-Vhost
X-Server-Powered-By
X-Rq
X-Varnish-Cache
X-Dispatcher
X-Amz-Version-Id
Grace
Allow
X-OneAgent-JS-Injection
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-LiteSpeed-Cache
X-Ua-Compatible
X-Page-Speed
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-WebKit-CSP
Cf-Apo-Via
X-Device
Cf-Railgun
Accept-CH
X-Aws-Lambda-Call-Status
X-Node
X-Pingback
X-Host
X-Ruxit-JS-Agent
EagleEye-TraceId
X-Server-Id
Surrogate-Control
X-Nginx-Cache-Status
X-Akam-SW-Version
X-Readtime
Request-Id
X-Backend-Server
X-Content-Security-Policy-Report-Only
X-HW
X-Cache-Lookup
Accept-Ch-Lifetime
X-Cache-Spec
X-Cloud-Trace-Context
X-Trace
X-Response-Time
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Application-Context
Permissions-Policy
X-Nginx-Upstream-Cache-Status
Fastly-Restarts
X-Litespeed-Cache
X-Edge
X-Mod-Pagespeed
X-WebKit-CSP-Report-Only
X-Country
Content-Location
X-Mcache
X-MS-InvokeApp
X-Content-Type
X-Url
X-Clacks-Overhead
Accept-CH-Lifetime
X-Vname
X-PC
X-TtlSet
X-Midtier
X-Amz-Server-Side-Encryption
X-CST
Rating
RTSS
Cache-Tag
X-ESI
X-Vcap-Request-Id
X-D2id
X-Rack-Cache
X-Element-Page-Cache
X-Exp-Id
Origin-Trial
X-GoogleNews-Bot
X-Cdn-Fetch
X-Kinja-Build
X-Use-Magma
X-Kinja-Server
X-Kinja-Revision
X-Kinja
X-Exp-Variant
X-ECACHE
Verso
X-VARITI-CCR
X-Server-Name
X-Ac
Service-Worker-Allowed
X-Powered-By-Plesk
X-Amz-Rid
X-Cnection
SPRequestGuid
X-SharePointHealthScore
X-GitHub-Request-Id
X-Client-IP
X-Navigation-Version
Xkey
X-Abt-Application-Version
X-Ttl
Edge-Control
SPIisLatency
SPRequestDuration
X-Cache-TTL
X-Upstream
Arr-Disable-Session-Affinity
X-Varnish-TTL
X-B3-TraceId
X-Cached
X-Mg-S
X-Dw-Request-Base-Id
X-Server-Lifecycle-Phase
X-Erf-Bev-Bev-Is-Generated
X-Browser-Type
X-Kraken-Loop-Name
X-Erf-Bev-Bev
X-Instrumentation
X-NWS-LOG-UUID
X-Px
Accept-Ch
X-Sol
Pagespeed
X-Middleton-Display
Display
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-NF-Request-ID
Access-Control-Request-Method
X-Correlation-Id
X-Forwarded-For
Edge-Cache-Tag
X-FastCGI-Cache
X-Cache-Key
X-Country-Code
X-Goog-Hash
X-Webkit-Csp
X-Ser
X-Powered-CMS
X-Id
Content-MD5
AR-ATIME
AR-Request-ID
AR-CACHE
AR-SID
AR-PoweredBy
Front-End-Https
Public-Key-Pins
X-Ratelimit-Limit
TCN
X-HP-Trace-Id
X-HP-Webp
X-Jurisdiction
X-Version
X-Amzn-Trace-Id
X-Content-Digest
X-MSEdge-Ref
X-Recruiting
X-T
Response
X-Middleton-Response
X-Accel-Expires
TP-L2-Cache
TP-Cache
X-RateLimit-Remaining
MicrosoftSharePointTeamServices
X-Shield-Request-Id
X-XRDS-Location
S
X-Fastcgi-Cache
Cache-Status
Nginx-Cache
X-Request-Received
X-Request-Processing-Time
X-HS-Cache-Config
X-HS-Combine-CSS
X-Daa-Tunnel
Cross-Origin-Opener-Policy
X-HS-Hub-Id
X-HS-Content-Id
X-Ratelimit-Remaining
Server-Node
Cache-Tags
X-B3-TraceId-Primal
X-Distributor
MRF-Tech
Mrf-Cache-Status
X-Fastly-Request-ID
X-Hits
X-TEC-API-ORIGIN
X-LB-Cache
X-TEC-API-ROOT
X-TEC-API-VERSION
X-Kinsta-Cache
X-Edge-Location-Klb
X-Origin-Server
X-Ua-Browser
X-Ezoic-Cdn
X-Ratelimit-Reset
X-PressLabs-Stats
Alternate-Protocol
Filterid
Fastcgi-Cache
X-LLID
X-Grace
X-ORACLE-DMS-ECID
X-Frontend
X-ORACLE-DMS-RID
X-Microsite
X-Request-Handler-Origin-Region
X-Rid
X-Hostname
X-DIS-Request-ID
X-Varnish-Backend
X-Logged-In
Healthy
Realpath
Server-Name
X-FB-Debug
X-Git-Hash
X-Geo-Country
X-NGENIX-Cache
Cleartype
X-Www-Served-By
X-Debug-Info
X-Cluster-Name
X-Page-Id
Payment
X-Load-Cache
MS-Author-Via
DC
X-Protected-By
X-Forwarded-Proto
X-ASPNET-VERSION
Access-Control-Allow-Method
X-Origin-Cache
Content-Disposition
X-TTL
Charset
X-B3-Sampled
X-DataDome
X-Upgrade-Enabled
X-GUploader-UploadID
X-Goog-Metageneration
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Proxy
X-Az
X-Server-ID
X-AppVersion
X-Activity-Id
X-Seen-By
X-Times
X-ECache
Count-Hit
X-F-Cache
X-Cache-Age
X-Amz-Meta-S3cmd-Attrs
X-B3-Traceid
X-Azure-Ref
X-Fb-Rlafr
X-Amz-Replication-Status
X-Whom
Cross-Origin-Resource-Policy
Paypal-Debug-Id
X-Revision
X-Akamai-Edgescape
X-B
X-Contextid
Surrogate-Key
X-Type
X-Request-Guid
X-Aspnet-Duration-Ms
X-App-Environment
Accept-Charset
X-Flags
X-Is-Crawler
Viewport
X-Providence-Cookie
X-Varnish-Server
X-Route-Name
X-Aspnetmvc-Version
Retry-After
X-Wix-Request-Id
X-TT
X-Hosted-By
X-Language
X-B-Cache
X-Signature
X-DynaTrace
X-Envoy-Decorator-Operation
X-Cache-Control
X-Oracle-Dms-Ecid
X-Oracle-Dms-Rid
X-App-Server
X-Magnolia-Registration
X-Source
X-Varnish-Grace
X-Mobile
Amp-Access-Control-Allow-Source-Origin
X-Goog-Generation
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
Version
X-VCache
WPO-Cache-Status
Host
WPO-Cache-Message
Refresh
Referer-Policy
X-HTML-Minification-Powered-By
X-N
X-Amzn-RequestId
X-Cache-Rule
X-Amz-Apigw-Id
X-Tumblr-Pixel-0
X-Original-Request-Id
Access-Control-Request-Headers
X-Response-Served-From
X-Tumblr-User
X-Tumblr-Pixel-1
X-Tumblr-Pixel
X-Varnish-Age
X-Cache-Time
X-Rule
Protected
X-UUID
MS-CV
Ms-Operation-Id
X-RTag
X-User-Agent
X-Jobs
X-Cache-Grace
X-Cacheable-TTL
X-Content-Powered-By
X-G
SD-X-WS
X-Framework
X-EdgeConnect-Cache-Status
X-FW-Dynamic
CDN-RequestId
From-Origin
X-FW-Serve
X-FW-Server
Section-Io-Cache
X-FW-Static
X-Environment-Context
X-Cache-Status-Check
X-Backend-Name
X-Device-Type
X-ProcessESI
X-RemovedCookies
X-FW-Type
X-FW-Hash
X-FW-Version
X-L-Path
X-Trace-Id
X-Region
VIX-Pulpo-Node
NGB
VIX-Pulpo-Upstream-Status
X-Page-View
X-Tt-Trace-Host
GEO-INFO
X-Tt-Trace-Tag
X-Adobe-Loc
X-Is-Bot
X-Adobe-Content
X-Status
Front
X-Rendered-As
X-NYM-Debug-Backend
X-Akamai-Request-ID2
X-Http-Reason
X-Drupal-Cache-Contexts
X-Instance
X-Cache-Expired-At
X-Drupal-Cache-Tags
X-Nginx-Cache
Akamai-GRN
X-XRDS-LOCATION
X-Fastly-Request-Id
Url
X-Servername
X-Unique-Id
X-Pinterest-Rid
Pinterest-Version
Pinterest-Generated-By
Liferay-Portal
X-Time
Accept-Language
X-Template
X-Varnish-Ttl
X-Content-Options
Fastly-SWR
Fastly-SIE
SRV
X-RateLimit-Limit
X-Debug-IsPreview
X-Debug-IsConnected
X-Air-Trace-Id
X-Zen-Fury
X-Air-Source
X-Newrelic-App-Data
Backend
X-Air-Hostname
X-Cache-Hit
X-CDN-Forward
X-Yottaa-Metrics
X-DynaTrace-JS-Agent
X-Yottaa-Optimizations
Country
X-Mode
X-COUNTRY
Content-Secure-Policy
X-Rocket-Nginx-Serving-Static
X-Uri
X-Cache-Operation
Node
Meta-Geo
X-Tumblr-Pixel-3
X-UPSTREAM-Address
X-Tumblr-Pixel-2
Onion-Location
Filters
X-Edge-Location
X-Content-Age
X-Rewrite-Enabled
X-Proxy-Cache-Info
X-Amzn-Remapped-Content-Length
X-IPS-LoggedIn
Webserver
S-Rt
X-ARC
X-RN-RSRV
X-Cache-Server
X-PHP-Backend
X-Proxy-Build
Selected-Fe
X-Locale
X-Generation-Time
Azure-SlotName
X-Tb
Cache-Hits
X-App-Version
Uber-Trace-Id
X-Web-Node
Azure-SiteName
Azure-Version
Azure-InstanceId
CF-IPCountry
X-Timing-Wait
Azure-RegionName
X-Ms-Version
X-Server-W
X-Reqid
Countrycode
X-Skip-Cache
X-Soup
X-Cms-Context
X-Cache-Action
X-ProxyCache-Key
X-ProxyCache-Status
X-BYPASS-REASON
X-Proto
X-PHP-Host
X-Say-Cacheable
X-Ms-Request-Id
X-Origin-Date
X-Labrador-Cache-Channel
X-Site-Version
WP-Super-Cache
X-Sucuri-ID
X-Say-TTL
X-SayCDN-TTL
X-Sucuri-Cache
Cache-Name
X-Via-Fastly
X-IPLB-Request-ID
ServerID
Cache-Tv-Group
X-Cache-Host
X-IPLB-Instance
X-Debug
X-LJ-Flow-ID
TWC-GeoIP-Country
TWC-GeoIP-LatLong
X-Section
TWC-Device-Class
TWC-Connection-Speed
TWC-Privacy
X-Routing-Service
Property-Id
X-Sql-Count
X-Sql-Duration-Ms
X-UA-Device-Type
TWC-Locale-Group
X-VWS-Id
X-Zipkin-Id
X-Cluster-Node
X-VC-Cache
X-Forwarded-Host
X-Proxied
X-Proxy-Cache-Status
Webcakes-App-Version
X-AWS-Id
X-Access
Webcakes-Region
Webcakes-App-Name
X-Extlb
X-Format
X-Origin-Hint
X-No-Session
X-Real-IP
X-SaId
X-Varnish-Beresp-Grace
X-R9-Blue-Green-Version
X-Cluster
Web-Mar-Node
X-Handled-By
X-JoinUs
X-Optimistic-Header
X-LAGOON
X-Adobe-Source
X-FB-TRIP-ID
Apigw-Requestid
X-Ruxit-Js-Agent
DB-Nickname
Cross-Origin-Window-Policy
Mn-Server-Ip
X-Ua
ServedBy
X-Detected-As
X-Urbn-Context-Path
X-Urbn-Site-Id
Locale
X-Cache-TTL-Remaining
X-LSADC-Cache
Fastcgi-Useragent
X-Director
X-GeoCode
X-GeoCountry
X-Xfnlog-Site
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
X-Node-Name
X-Oneagent-Js-Injection
Mime-Version
Upgrade-Insecure-Requests
Source
Frame-Options
X-Tt-Logid
X-Varnish-Hits
X-GEO
Fastly-Drupal-HTML
CDN-CachedAt
X-Hl-Ver
CDN-Uid
CDN-Cache
X-Generated-By
CDN-RequestCountryCode
X-Buckets
CDN-EdgeStorageId
CDN-PullZone
X-Tec-Api-Origin
X-Tec-Api-Version
Load-Balancing
X-Tec-Api-Root
X-Varnish-Cache-Hits
X-Request-Time
X-FireWall-Port
Xet-Cookie
X-SRV
X-TA-CDN-Provider
X-RM-Cache-TTL
X-Api-Version
X-Mg-Request-UUID
X-ServerID
X-Varnish-Hostname
X-Datadog-Sampled
X-Webkit-CSP-Report-Only
X-Origin-TTL
X-Origin-CC
X-Datadog-Sampling-Priority
X-Datadog-Trace-Id
X-URL
X-Datadog-Parent-Id
X-Redis-Cache
X-Loop
X-Cache-Debug
X-TIME
CF-Cached-On
X-Akamai-Transformed
X-Tx-Id
X-Served-From
X-ShopId
X-Alternate-Cache-Key
X-Storefront-Renderer-Rendered
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Shopify-Stage
X-ShardId
X-Pubstack
X-Storage
Xserver
X-Endurance-Cache-Level
X-Newrelic-Synthetics
X-Restarts
X-Pass-Why
X-Request-Host
X-CSRF-Token
X-Provided-By
Server-Info
X-Service
X-Location
WWW-Authenticate
X-A
Thinkindot-CacheControl
TDXMobile
Thinkindot-Control
X-A-Ccd
Thinkindot-CacheControl-Type
Meta-Geo-Continent
Edge-Cache
DSUID
Gannett-Cam-Experience-Id
Host-ID
Lang
DCR-Processing-Time-Ms
DCR-Decision-By
A
BehaviorPad-Version
Cache-Host
Candidate-Md5Url
MD5-Digest
Memcached
Rendered-Blocks
Release
Server-Host
Sslversion
Surrogated-Key
Redirect-Candidate
Origin
Xc-Version
Ngx.Var.Host
NM-Fastcgi-Cache
Odigeo-Trace-Id
T-Server
X-Cdn-Origin
X-Processor
X-Origin-Time
X-Response-By
X-Rocket-Build-Number
X-S
X-Rojux
X-Origin
X-Nyt-Route
X-Loc
X-Level-Front-Cache
X-Men
X-Mid
X-Mobile-URL
X-S-Cookie
X-S-Maxage
X-Thanos
X-Test
X-Thinkindot-L3
X-TIM-N
X-Vdms-Version
X-Vdms-Path
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-Sigma
X-ScT
X-Sigma-Backend
X-Sn-Servicetimems
X-SRCache-Key
X-INCAP-ABP
X-Httpd
X-Bc-Bl
X-B-Cookie
X-BCube-Filmed-By
X-Bip
X-Cache-Info
X-Cache-Date
X-Application
X-Akamai-Device-Characteristics
X-A-Dcw
X-A-Dam
X-A-Dgt
X-A-Wwc
X-Aed
X-Cache-NE
X-CMSURLCustom
X-External-Request-Id
X-Epic-Correlation-Id
X-Gdpr
X-Generated-On
X-Hash
X-Ec-GeoHdr
X-Ec-Fail
X-CUA
X-Core-Mission
X-D
X-Destination
X-Developer
X-We-Are-Hiring
X-Conf
X-WP-CF-Super-Cache-Active
HostName
X-Fetched-On
X-Org
X-Node-Id
X-Mvc-Supplant-Cachable
Platform
Section-Origin-Responded
X-Human
Section-Io-Id
Req-Svc-Chain
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
X-TNCMS
X-Platform-Processor
Is-Eu
Gh-Request-Id
X-Platform-Router
X-Pool
X-Platform-Cluster
X-Platform
X-Origin-Expires
X-Origin-Response-Time
Mail-Subject
X-Cache-Bucket
X-HS-Content-Campaign-Id
X-GeoIP
X-Accel-Expires-Debug
X-DefHash
X-Dispatcher-Number
X-Dispatcher-Server
X-Ad-Defer-Variation
X-DefElseHash
X-BBC-Edge-Cache-Status
X-Cache-Id
X-CacheTTL
X-Date
X-Ec-Custom-Error
X-Esi-Check
Tube-Get-Contents
X-Gamma-Serve
Fastly-GeoIP-CountryCode
X-GeoIP-City
Tube-Got-Eval
Tube-Got-Results
X-Fastly-Backend
We-Hiring
X-Fastly-Cache
Tube-Return
X-Gzip
Magicmarker
Click-Count-Action-Start
X-Varnish-Remaining-TTL
X-Varnishpool
Click-Count-Error
CloudFront-Viewer-Country
Cmstype
Cmsid
X-Varnish-CookieINHashed-On
X-Vmg-Version
Fastly-Backend-Name
C-Via
X-Auto-Login
X-Scale
X-Worker
Adler-Geo
CacheControlHeader
Cache-Key
Country-Code
X-VServer
X-Server-IP
X-Region-Sid
X-Slack-Shared-Secret-Outcome
X-SD-PageType
X-Slack-Backend
X-Req
X-Var-Ttl
X-Varnish-CookieHashed-On
Expect-Staple
X-Variation
Environment
X-Varnish-Beresp-Ttl
X-Via-CDN
X-Device-Os
Srvid
Origin-CC
On-Server
X-DPWN-IS-SECURE
Origin-EX
X-Instance-Name
X-Ckpd-Fst-Backend
X-Nginx-Cache-Key
X-Cache-Tags
X-Cache-FS-Status
X-Clara-WADP
X-Core-Value
X-FL-EDGE
X-FL-QIT-DEBUG
Locid
X-Developers
X-Wix-Viewer-Type
X-Planisys-CDN-Cache
X-Irp-Debug
X-Planisys-CDN-Rules
X-Has-Esi
X-Owner
X-V-Cache
X-Mly-Id
X-VC
X-JWT-State
X-Is-Gdpr
X-Planisys-CDN-TTL
X-GeoIP-Region-Code
X-WADP-Cache
X-NodeID
X-SB
X-FC-Vary-Parameters
X-Fmm-Version
X-Forwarded-Site
X-GeoIP-Country-Code
X-Geo-Header
X-WA-Info
X-Release
X-Qloud-Router
X-App
AKAMAI
X-Azure-Ref-OriginShield
Web-Mar-Region
Ssr
Vix-Hermes-Req-Id
X-Accel-Buffering
State
Canary
Producers
Machine
Datacenter
Kp-EeAlive
X-Via-Edge
Edge-Copy-Time
X-Via-SSL
X-Cdn-Srv
X-Block-Status
Wxu-Next-Region
X-Request-Start
X-Gen-Mode
X-From
Wxu-Next-Hostname
X-Hnp-Log
X-Frame-Option
Wxu-Next-Commit
Apple-News-Services-Request-Url
X-VG-TLSProxy
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
X-Varnish-Beresp-Status
Server-Ext
Server-Hostname
X-Platform-Server
NGX
X-Old-Content-Length
Sever-Int
Apple-News-Services-Handled
User-Cache-Control
X-NCache
X-Op-Id-All
Cache-Provider
X-Ua-Device
X-VarnishDD-TTL
X-Minions-Version
PFcat
X-HN
L
X-Aicache-OS
X-Parent-Response-Time
X-CACHE-AGE
X-Air-Pt
X-Vcl-Version
X-Zone
L5d-Success-Class
HA-Ipaddr
X-Mvc-Supplant-OutputCached
X-Microcachable
X-Nananana
X-Cache-Enabled
X-CGP
X-Cache-Remote
X-Eu-Site
CDCHOST
X-Csrf-Jwt
Fastly-SSL
Ha-Gx-Prefs
X-RCS-CacheZone
X-DC
X-Debug-Cache-Fetch
X-Lambda-Id
X-Up
X-Debug-Cache-Store
X-LB-NoCache
X-Refresh
X-VCT
X-Correlation-ID
X-B3-Spanid
X-Cache-Backend
X-Tb-Optimization-Total-Bytes-Saved
Pics-Label
X-Via-Poph
Env
X-Via-Popn
X-Presslabs-Stats
X-Via-Popv
X-B3-SpanId
X-Trace-ID
X-Dc
X-Vtex-Remote-Cache
Cluster
Decoy-Debug-Key
X-Generated-In
X-Cs
Decoy-Debug-TTL
VNS-Cache
VNS-Age
CPC-Cache
GeoIP-Latitude
X-ND-Cache
X-Cached-By
CPC-Age
X-Render-Time
Decoy-Debug-Status
NtCoent-Length
SID
AMP-Access-Control-Allow-Source-Origin
X-Upstream-Ct
X-Upstream-Ht
X-HA-Backend
Time
X-CCDN-CacheTTL
Cache
X-CCDN-Origin-Time
X-Hcs-Proxy-Type
Memory
Sid
X-AIR-PT
X-NWS-UUID-VERIFY
X-Webkit-CSP
X-Cache-Type
X-Tid
X-Edge-Pop
X-Servedbyhost
X-HS-Status
X-LB-ID
X-TH-Server
X-DataCenter
X-ATG-Version
X-Wa
X-Esi
Fastly-Drupal-Html
X-Nc
X-Vgn-Hpd-Variations-Key
Svr
X-Varnish-Authentication
X-NewRelic-App-Data
Server-ID
X-Vgn-Hpd-Cached
X-Contensis-Viewer-Groups
X-Cache-ASPX
X-Client-Ip
X-Vgn-Hpd-Ssi
X-Via-JSL
Cdn
X-Srv
Srv
Uri
GeoIp-Country-Code
X-ZONE
X-Check-Cacheable
X-MP-GENERATED-AT
X-RateLimit-Remaining-Second
X-CF-Lambda-Version
X-Fpc
X-RateLimit-Limit-Second
Esi-Enabled
X-PAYTM-SRV-ID
X-CF-Lambda-Fn
X-Proxy-CacheRZ
XkeyRZ
True-Client-IP
X-Amz-Meta-Cb-Modifiedtime
X-Udemy-Cache-App-Namespace
X-Vc
X-Nf-Request-Id
Lb
X-Wikidot-Static-Cache
M-TraceId
X-Wikidot-Backend
X-CACHE-KEY
N-Cache
X-API-Version
X-Datadome
X-Varnish-Beresp-TTL
X-CS
YJS-ID
Hostname
X-NGINX-Cache
Cdnsip
Cdncip
X-Gateway-Cache-Key
RNT-Time
XServer
X-Bl-Debug
X-Shop-Environment
Resin-Trace
X-Forwarded-Path
X-AK-Request-ID
X-Tenant
X-Gateway-Cache-Status
X-CDN-Cache-Status
RNT-Machine
True-Client-Ip
X-Gateway-Skip-Cache
X-Orig-Expires
X-Gateway-Request-Id
X-EC-Lua
X-CSRF-TOKEN
X-MSEdge-Features
X-TX-ID
X-Via-NSCOPI
X-MSEdge-Flight
X-FPC
OT-Force-Account-Verify
X-Fastly-Country-Code
X-B3-Trace-ID
X-App-Name
X-Policy
Sm-Log-Id
X-Service-Response-Time
Eomportal-Instance
GeoIP-Country-Code
CDN
Server-Id
Path
X-Logging-Id
X-Cache-Ttl
X-VCL-Version
Ngx-Var-Key
Hit
X-APP-VERSION
X-WA
X-Vcache
X-CLOUD-TRACE-CONTEXT
X-Accel-Version
X-Micro-Cache
X-Container-Uri
X-Git-Commit
X-Cdn-Diag
X-Lb-Id
X-Edge-POP
IsBot
X-SIPLIST1
X-MCACHE
X-Datacenter
X-Cache-NGX
X-NC
X-ServedByHost
X-Cdn-Cache-Status
LB
HIT
X-Request-URI
X-RateLimit-Reset
X-Ha-Backend
X-Cdn-Forward
Pramga
RATING
X-Github-Request-Id
X-SERVER-NAME
X-Info
X-Tncms
X-Geo
X-LiteSpeed-Cache-Control
V-Age
Timeexpire
X-Acquia-Purge-Cdn-Unconfigured
X-Srcache-Fetch-Status
Location
X-Srcache-Store-Status
Geoip-Latitude
X-VG-WebCache
XM
X-Snapshot-Date
Cross-Origin-Opener-Policy-Report-Only
FSS-Cache
X-Akamai-Pragma-Client-IP
Tcn
X-TT-LOGID
Ohc-File-Size
Yjs-Id
X-Clientip
CDN-RequestPullCode
X-Via-PopV
Req-ID
X-Ctl-Mach
X-Via-PopN
X-Via-PopH
True-Client-Country-4JS
CDN-RequestPullSuccess
Epwk-X-Cache
X-Lb-Nocache
X-Pod-Name
X-LiteSpeed-Tag
ENV
X-Iauth-Set-Uid
X-Wp-Cf-Super-Cache-Cache-Control
X-Wp-Cf-Super-Cache
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-HostName
X-Amz-Meta-Opti
X-Serial
X-Hyper-Cache
X-Dw-Trace-Id
X-M-Log
X-M-Reqid
Warning
X-Acquia-Site
X-RAMCache
Content-Script-Type
X-UP
WZWS-RAY
W
Cneonction
Proxy-Connection
X-Acquia-Purge-Tags
X-Cdn-Request-ID
X-Cache-Expires
X-Fastly-Backend-Reqs
X-Acquia-Application-UUID
X-Oss-Storage-Class
X-Oss-Server-Time
X-Oss-Object-Type
X-Oss-Request-Id
Ec-Rule-Version
X-Oss-Hash-Crc64ecma
Content-Style-Type
Servername
X-Qnm-Cache
X-Acquia-Application-Trace
X-MiniProfiler-Ids
X-UA
CountryCode
X-Lsadc-Cache
X-Akamai-ERPolicy
X-Viewer-Country
X-WP-CF-Super-Cache-Cookies-Bypass
X-IPS-Cached-Response
PICS-Label
X-Akamai-ERRuleID
Ohc-Cache-HIT
X-Litespeed-Cache-Control
X-Swift-Error
X-Webstats-RespID
X-B3-Parentspanid
X-Fastly-Cache-Hits
My-App
MIME-Version
X-Th-Server
X-Mg-Cache
Ngx
X-B3-ParentSpanId