Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-Cache-Status
Link
Accept-Ranges
CF-RAY
ETag
X-XSS-Protection
Expect-CT
Pragma
X-Powered-By
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
Alt-Svc
X-Served-By
X-Xss-Protection
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Cache-Status
X-Check
X-Generator
X-Cacheable
Timing-Allow-Origin
X-Content-Security-Policy
X-Iinfo
Feature-Policy
Status
X-Envoy-Upstream-Service-Time
Content-Encoding
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
X-AspNetMvc-Version
X-CDN
P3p
Upgrade
X-Via
CF-Ray
X-Ws-Request-Id
Access-Control-Max-Age
Report-To
X-Request-ID
Server-Timing
EagleId
X-Cache-Group
X-Turbo-Charged-By
Keep-Alive
X-UA-Device
Request-Context
X-Age
X-Backend
X-Proxy-Cache
X-Server-Powered-By
X-AH-Environment
X-Robots-Tag
X-Hacker
X-Server
X-Amz-Request-Id
Host-Header
X-Amz-Id-2
Grace
X-Rq
X-LiteSpeed-Cache
X-Swift-SaveTime
X-Swift-CacheTime
X-Varnish-Cache
X-Nginx-Cache-Status
Ali-Swift-Global-Savetime
NEL
X-WebKit-CSP
X-Page-Speed
X-Vhost
EagleEye-TraceId
X-Amz-Version-Id
X-Ua-Compatible
X-Dns-Prefetch-Control
X-Pingback
X-OneAgent-JS-Injection
X-Dispatcher
X-Device
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Cache-Spec
Accept-CH
X-Host
X-Server-Id
Cf-Railgun
X-Node
X-Backend-Server
X-Readtime
Surrogate-Control
X-Akam-SW-Version
Request-Id
X-Response-Time
X-HW
X-Application-Context
Xkey
Content-Location
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
Rating
X-B3-TraceId
X-Cloud-Trace-Context
Accept-Ch-Lifetime
X-Country
Accept-CH-Lifetime
X-Cache-Lookup
X-Ruxit-JS-Agent
X-Trace
X-Url
Allow
X-Ac
X-Content-Type
X-TtlSet
X-PC
X-Vname
X-Aws-Lambda-Call-Status
X-Varnish-TTL
X-Clacks-Overhead
Edge-Control
X-Server-Name
X-Mod-Pagespeed
X-ESI
Fastly-Restarts
Cache-Tag
X-Rack-Cache
Service-Worker-Allowed
X-VARITI-CCR
Verso
X-Element-Page-Cache
MS-Author-Via
X-Upstream
X-FastCGI-Cache
X-Vcap-Request-Id
X-MS-InvokeApp
X-Amz-Rid
Public-Key-Pins
X-GitHub-Request-Id
X-Dw-Request-Base-Id
X-Cached
X-D2id
X-Cache-TTL
X-Client-IP
X-Abt-Application-Version
X-Cnection
X-Px
RTSS
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-Navigation-Version
X-Exp-Variant
X-Cdn-Fetch
X-Kinja
X-Exp-Id
X-Use-Magma
X-Kinja-Server
X-GoogleNews-Bot
X-Kinja-Revision
X-Kinja-Build
Arr-Disable-Session-Affinity
Access-Control-Request-Method
X-Country-Code
X-Goog-Hash
X-NF-Request-ID
X-Powered-By-Plesk
AR-CACHE
X-Sol
AR-PoweredBy
Display
Pagespeed
AR-SID
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
AR-ATIME
X-Middleton-Display
X-Powered-CMS
X-Instrumentation
AR-Request-ID
X-Version
X-Origin-Cache
X-TTL
X-Middleton-Response
Response
X-LLID
X-MSEdge-Ref
Nginx-Cache
X-Amz-Server-Side-Encryption
X-CST
X-Edge-Location-Klb
X-RateLimit-Remaining
X-Kinsta-Cache
TCN
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
X-Edge
X-Protected-By
X-SRCache-Store-Status
X-T
X-SRCache-Fetch-Status
X-HP-Trace-Id
X-HP-Webp
X-Jurisdiction
X-Content-Security-Policy-Report-Only
X-Forwarded-For
X-Shield-Request-Id
X-Ruxit-Js-Agent
X-Id
X-Mg-S
Edge-Cache-Tag
S
X-Language
X-Aspnetmvc-Version
Content-MD5
SPIisLatency
SPRequestDuration
Fastcgi-Cache
Front-End-Https
X-Mid
X-Webkit-Csp
Realpath
X-Request-Processing-Time
Server-Node
X-Request-Received
Pinterest-Generated-By
Filters
X-Recruiting
Pinterest-Version
X-Pinterest-Rid
X-Frontend
X-Cache-Key
X-Content
X-Ua-Browser
X-Ab
Server-Name
X-MCACHE
X-Ser
X-Correlation-Id
X-NWS-LOG-UUID
X-DynaTrace
X-HS-Hub-Id
X-HS-Cache-Config
X-HS-Content-Id
X-HS-Combine-CSS
X-Template
X-Yandex-Sdch-Disable
X-Ttl
X-Ezoic-Cdn
Accept-Ch
X-ECACHE
SPRequestGuid
X-SharePointHealthScore
X-Hits
X-Parallel-Accel
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
MicrosoftSharePointTeamServices
X-Tt-Trace-Host
X-Tt-Trace-Tag
Cache-Tags
X-Page-Id
Charset
Host
Cleartype
X-Www-Served-By
X-Git-Hash
X-Daa-Tunnel
X-B3-Sampled
Alternate-Protocol
X-Geo-Country
X-Content-Options
X-Debug-Info
X-DIS-Request-ID
Fusion-Content-Source
Fusion-Content-Id
Fusion-Component-Id
Fusion-Deployment-Id
Fusion-Template-Id
Fusion-Source
X-Hostname
X-Content-Digest
X-Amzn-Trace-Id
X-Ratelimit-Limit
X-Amz-Replication-Status
Filterid
Cross-Origin-Opener-Policy
X-Varnish-Age
X-Grace
X-Activity-Id
X-Az
X-AppVersion
X-Upgrade-Enabled
X-F-Cache
X-Accel-Expires
ServerID
X-WebKit-CSP-Report-Only
X-VCache
X-FB-Debug
X-N
X-Nginx-Upstream-Cache-Status
X-Rid
X-DataDome
X-Forwarded-Proto
X-Origin-Server
Access-Control-Allow-Method
X-Mobile-URL
X-Providence-Cookie
X-Request-Guid
X-Aspnet-Duration-Ms
X-Flags
X-Route-Name
X-Is-Crawler
X-Type
X-Whom
X-LB-Cache
Viewport
X-App-Environment
X-Goog-Metageneration
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-Goog-Generation
X-Varnish-Grace
X-Goog-Storage-Class
X-TT
X-Goog-Stored-Content-Encoding
Payment
X-Seen-By
X-Fastly-Request-Id
X-XRDS-LOCATION
X-Fastly-Request-ID
X-Tb
X-Distributor
TP-L2-Cache
X-FW-Static
X-FW-Server
TP-Cache
X-FW-Hash
X-FW-Dynamic
X-FW-Serve
DC
X-FW-Type
Paypal-Debug-Id
X-Server-ID
X-User-Agent
Node
X-Fastcgi-Cache
X-Ratelimit-Reset
Country
Accept-Charset
Fastcgi-Useragent
X-Wix-Request-Id
X-App-Server
X-Oneagent-Js-Injection
X-Cache-Rule
X-Cache-Control
X-NGENIX-Cache
X-Litespeed-Cache
X-Via-JSL
Version
X-Tec-Api-Root
X-Tec-Api-Origin
X-Tec-Api-Version
X-Cluster-Name
X-Drupal-Cache-Tags
X-Request-Handler-Origin-Region
X-Microsite
X-Contextid
X-Cache-Age
X-Signature
X-B-Cache
X-Origin-Upstream-Status
Referer-Policy
Cache-Status
X-Buckets
X-Logged-In
Refresh
X-Node-Name
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Browser-Type
VIX-Pulpo-Upstream-Status
Amp-Access-Control-Allow-Source-Origin
X-Original-Request-Id
SD-X-WS
VIX-Pulpo-Node
X-Response-Served-From
X-Mobile
X-Page-View
X-Real-IP
X-Is-Bot
X-Vgn-Hpd-Reason
X-Varnish-Backend
X-Rendered-As
X-Cache-Expired-At
X-Load-Cache
X-IPLB-Instance
X-Jobs
X-Proxy-Cache-Status
X-B
X-Revision
X-Cacheable-TTL
NGB
Access-Control-Request-Headers
X-Cache-Action
X-Device-Type
X-Instance
X-Proxy
X-Rule
X-Debug
X-UUID
X-ProcessESI
X-RemovedCookies
X-Yottaa-Optimizations
X-Yottaa-Metrics
Akamai-GRN
X-Cache-Time
X-Drupal-Cache-Contexts
X-Framework
Surrogate-Key
X-Debug-IsConnected
X-Debug-IsPreview
X-G
X-FW-Version
CF-IPCountry
X-Accel-Buffering
X-Air-Trace-Id
X-Air-Source
X-Air-Hostname
X-XRDS-Location
X-Oracle-Dms-Rid
SID
X-Oracle-Dms-Ecid
X-Presslabs-Stats
Count-Hit
GEO-INFO
X-Cache-NGX
Uber-Trace-Id
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-Cache-Operation
X-PressLabs-Stats
X-Source
DynaTrace
X-Azure-Ref
X-Nginx-Cache
X-Ms-Version
X-Ms-Request-Id
X-Zen-Fury
Liferay-Portal
X-APP-VERSION
X-EdgeConnect-Cache-Status
Protected
Frame-Options
X-RateLimit-Limit
X-CDN-Forward
MS-CV
Ms-Operation-Id
X-RTag
X-Cache-Hit
Healthy
X-Backend-Name
X-Mode
Xserver
Ec-Rule-Version
X-IPS-LoggedIn
Cross-Origin-Window-Policy
X-L-Path
X-Hyper-Cache
X-Environment-Context
Countrycode
WPO-Cache-Status
X-Trace-Id
WPO-Cache-Message
X-Cache-TTL-Remaining
X-Varnish-Server
X-Servername
X-Tumblr-User
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-Tumblr-Pixel
Backend
X-Adobe-Loc
X-Adobe-Content
LB
X-SaId
X-Rewrite-Enabled
X-RN-RSRV
X-JoinUs
X-Region
X-UPSTREAM-Address
Meta-Geo
X-Tid
X-Detected-As
Content-Disposition
X-Sql-Duration-Ms
X-Routing-Service
X-Debug-Cache
X-Content-Age
X-Uri
X-Cache-Server
X-Ratelimit-Remaining
Country-Code
X-Sql-Count
Apigw-Requestid
Decoy-Debug-TTL
X-Extlb
Decoy-Debug-Key
X-Redis-Cache
Decoy-Debug-Status
X-Format
X-Zipkin-Id
X-Generation-Time
X-Proxied
CDN-PullZone
CDN-EdgeStorageId
CDN-CachedAt
CDN-RequestCountryCode
CDN-Uid
X-Via-Fastly
X-ShopId
CDN-RequestId
CDN-Cache
Fastly-SSL
X-Sorting-Hat-ShopId
Eomportal-Instance
X-Sorting-Hat-PodId
Mn-Server-Ip
Url
X-Shopify-Stage
X-Alternate-Cache-Key
X-Microcachable
X-ServerID
X-No-Session
X-Human
X-Hosted-By
X-Section
X-ApacheServer
X-OCL
X-NCache
X-ShardId
X-Access
X-PHP-Backend
X-PERF
X-PCL
X-Forwarded-Host
Section-Io-Cache
X-Content-Powered-By
X-Status
X-Proxy-Build
X-Storage
X-Pubstack
X-Cluster-Node
Cache-Tv-Group
X-ProxyCache-Key
X-ProxyCache-Status
X-Origin-Hint
X-Site-Version
X-Cache-Host
X-Varnish-Beresp-Grace
X-UA-Device-Type
TWC-GeoIP-Country
TWC-Device-Class
TWC-GeoIP-LatLong
TWC-Locale-Group
Webcakes-App-Version
X-Origin-Date
Webcakes-App-Name
TWC-Privacy
TWC-Connection-Speed
X-Cache-Grace
X-Timing-Wait
X-FB-TRIP-ID
X-BYPASS-REASON
Webcakes-Region
X-Cache-Type
X-Server-W
Selected-Fe
Property-Id
Cache-Name
X-Hl-Ver
X-R9-Blue-Green-Version
X-Soup
X-Say-Cacheable
X-Akamai-Edgescape
X-Say-TTL
X-SayCDN-TTL
X-Generated-By
X-Web-Node
X-Varnishpool
X-NYM-Debug-Backend
Azure-RegionName
Azure-InstanceId
Azure-SiteName
Azure-SlotName
X-TIME
Azure-Version
Content-Secure-Policy
X-Be
Retry-After
X-NewRelic-App-Data
X-Ua
X-LSADC-Cache
X-Nginx-Cache-Key
DB-Nickname
X-Webkit-CSP
X-Unique-Id
OT-Force-Account-Verify
X-Cache-Remote
X-Dc
X-Bc-Bl
X-Cached-By
X-Azure-Ref-OriginShield
X-TT-LOGID
X-Platform-Server
X-Auto-Login
Source
X-Xfnlog-Site
X-Akamai-Transformed
SRV
ServedBy
Upgrade-Insecure-Requests
X-LAGOON
Cache
X-Cache-Tags
X-GEO
X-Varnish-Cache-Hits
X-Origin-TTL
X-Origin-CC
From-Origin
X-Varnish-Hits
X-Cdn
X-Request-Time
Cache-Hits
X-HTML-Minification-Powered-By
X-Varnish-Hostname
HostName
X-TNCMS
X-Loop
Xet-Cookie
X-NWS-UUID-VERIFY
X-S-Maxage
X-SRV
Mime-Version
Onion-Location
X-AOL-HN
X-EC-Lua
X-Request-Host
X-CSRF-Token
WP-Super-Cache
Webserver
X-App-Version
X-Time
X-Tumblr-Pixel-2
X-Tumblr-Pixel-3
Web-Mar-Node
X-Handled-By
X-Cache-Enabled
X-Proto
N-Cache
X-Endurance-Cache-Level
X-B3-SpanId
X-ECache
X-Amz-Meta-S3cmd-Attrs
X-FireWall-Port
X-Tenant
X-AWS-Id
X-Origin-Response-Time
X-LJ-Flow-ID
X-Reqid
X-RCS-CacheZone
X-VWS-Id
X-A-Dgt
X-A-Dcw
X-A
X-A-Ccd
X-A-Dam
X-B-Cookie
X-Block-Status
X-Cache-NE
X-CF-Lambda-Fn
X-Backend-TTL
Vix-Hermes-Req-Id
X-Aed
X-Application
X-ARC
X-A-Wwc
Sslversion
DCR-Processing-Time-Ms
Expiry
Fastcgi-X-Cache-Version
DCR-Decision-By
BehaviorPad-Version
X-Adobe-Source
A
Meta-Geo-Continent
Mobile-Detection-Method
X-CF-Lambda-Version
Surrogated-Key
Rendered-Blocks
Redirect-Candidate
Odigeo-Trace-Id
Pramga
User-Cache-Control
X-Connection-Hash
X-ScT
X-SD-PageType
X-Session-Fingerprint
X-S-Cookie
X-S
X-Planisys-CDN-TTL
X-Processor
X-Rojux
X-Shop-Environment
X-SRCache-Key
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
Xc-Version
X-VG-WebCache
X-Vdms-Version
X-TIM-N
X-V-Cache
X-Vdms-Path
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
X-Epic-Correlation-Id
X-External-Request-Id
X-Forwarded-Path
X-Developer
X-Destination
X-Cluster
X-Conf
X-D
X-Ftr-Request-Id
X-Gen-Mode
X-Orig-Expires
X-PAYTM-SRV-ID
X-PBS-Appsvrname
X-ND-Cache
X-NAPM-TraceId
X-GG-Cache-Date
X-Hnp-Log
X-Ig-Push-State
X-Ckpd-Fst-Backend
V-Age
Nel
X-Correlation-ID
X-Akamai-Request-ID2
X-Http-Reason
X-Time-Microsecs
S-Rt
X-Mg-Request-UUID
X-Edge-Location
X-MP-GENERATED-AT
Cmstype
Cmsid
X-Fastly-Cache
CDCHOST
X-Forwarded-Site
Apple-News-Services-Host
Apple-News-Services-Handled
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
Arc-Country
CacheControlHeader
DSUID
Wxu-Next-Commit
Wxu-Next-Hostname
Wxu-Next-Region
Host-ID
True-Client-Country-4JS
State
Svr
Gh-Request-Id
X-Accel-Expires-Debug
AKAMAI
X-Cdn-Srv
X-Cache-Info
X-Cache-Bucket
X-Aicache-OS
Fastcgi-Cache-TTL
X-Date
X-Geo-Header
X-Scheme
X-Server-IP
X-Rocket-Nginx-Serving-Static
X-Request-URI
X-Policy
X-Gdpr
X-Slack-Backend
X-Sucuri-Cache
X-Viewer-Country
X-Webstats-RespID
X-VG-TLSProxy
X-SVT-ORM-VERSION
X-Sucuri-ID
X-SVT-ORM-RULES
X-Origin-Time
X-Proxy-Upstream
X-Li-Fabric
X-Li-Pop
X-LI-UUID
X-Hash
X-GeoIP-Region-Code
Origin
X-GeoIP-Country-Code
X-Origin
X-Location
X-Nyt-Route
X-Old-Content-Length
X-NodeID
X-Mvc-Supplant-Cachable
X-Men
X-PHP-Host
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Labrador-Cache-Channel
X-Via-NSCOPI
CloudFront-Viewer-Country
Environment
X-Locale
Server-Info
X-Magnolia-Registration
X-Esi-Check
X-Developers
X-Varnish-Beresp-Ttl
X-Envoy-Decorator-Operation
X-Generated-On
X-HS-Content-Campaign-Id
X-HN
Mail-Subject
X-Eu-Site
X-Datadog-Trace-Id
X-Cache-Date
X-Cache-Debug
X-Branch-Name
X-BBC-Edge-Cache-Status
X-Backend-State
X-Cache-Id
X-CGP
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
X-Csrf-Jwt
X-Core-Value
X-Fastly-Backend
X-Irp-Debug
X-Owner
AMP-Access-Control-Allow-Source-Origin
Origin-CC
X-VarnishDD-TTL
X-Varnish-Beresp-Status
X-UnsetCookies
Origin-EX
Traceparent
X-Origin-Expires
X-Fetched-On
X-Device-Os
X-Core-Mission
X-TrackingId
X-TH-Server
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-Platform
Fastly-GeoIP-CountryCode
X-Req
X-Rocket-Build-Number
X-Skip-Cache
X-Sigma-Backend
X-Sigma
X-Served-From
X-Level-Front-Cache
X-Gzip
Ssr
Server-Host
Magicmarker
Machine
L
L5d-Success-Class
X-VServer
Ha-Gx-Prefs
We-Hiring
Release
HA-Ipaddr
Req-Svc-Chain
PFcat
Web-Mar-Region
X-Cache-Var-Map
X-Cache-Var
X-Gamma-Serve
X-Node-Id
Thinkindot-Control
X-Restarts
X-ATG-Version
X-Region-Sid
X-Pod-Name
X-Storefront-Renderer-Rendered
Memcached
X-GeoIP-City
X-GeoIP
Thinkindot-CacheControl-Type
X-JWT-State
Thinkindot-CacheControl
TDXMobile
NM-Fastcgi-Cache
X-Has-Esi
X-Amzn-Remapped-Content-Length
X-Is-Gdpr
Locid
X-FC-Vary-Parameters
X-Thinkindot-L3
X-Xrds-Location
Fastly-Drupal-Html
NGX
X-Sn-Servicetimems
X-DefElseHash
Fastly-SWR
X-Worker
X-Cdn-Origin
Adler-Geo
X-NU-AKA-ACS-Version
Kp-EeAlive
X-Zone
Is-Eu
X-Response-By
X-Varnish-CookieHashed-On
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-Tx-Id
Cf-Device-Type
X-Qloud-Router
X-Varnish-CookieINHashed-On
Platform
X-DefHash
Fastly-SIE
X-DPWN-IS-SECURE
X-Variation
X-Loc
X-Varnish-Remaining-TTL
X-Ua-Device
X-TraceId
X-DB
Edge-Cache
X-DW
X-RPS
X-NC
Accept-Language
X-DSS
X-RSL
X-Request-Start
X-Wix-Viewer-Type
X-Cache-Backend
X-DI
X-CS
X-Mvc-Supplant-OutputCached
X-VC-Cache
X-RPM
X-Generated-In
X-Bip
X-M-Log
CDN
X-Thanos
X-Qnm-Cache
X-Up
X-Action
X-LB-NoCache
X-M-Reqid
X-LB-ID
Pics-Label
X-Srv
X-Trace-ID
X-Minions-Version
X-Optimistic-Header
Ms-Author-Via
Memory
X-CacheTTL
Time
X-API-Version
X-Tb-Optimization-Total-Bytes-Saved
X-Tt-Logid
X-Refresh
X-Urbn-Context-Path
X-Urbn-Site-Id
X-Edge-Pop
Env
X-Cache-Config
Locale
X-Via-Popv
GeoIp-Country-Code
X-Via-Poph
WebServer
X-Varnish-Ttl
X-Via-Popn
X-HA-Backend
Datacenter
X-TA-CDN-Provider
X-DynaTrace-JS-Agent
X-Ec-GeoHdr
X-Ec-Fail
NtCoent-Length
X-User
X-CACHE-KEY
X-DC
Candidate-Md5Url
X-Parent-Response-Time
X-Datadome
X-ZONE
X-Vc
X-Cs
X-Servedbyhost
Server-ID
X-Esi
X-MSEdge-Flight
On-Server
X-TX-ID
WWW-Authenticate
X-Dynatrace
X-MSEdge-Features
X-CLOUD-TRACE-CONTEXT
X-AK-Request-ID
Cdnsip
Esi-Enabled
Cdncip
X-WADP-Cache
Geoip-Latitude
X-VCL-Version
X-Fmm-Version
Cluster
My-App
X-Clara-WADP
X-Unique-ID
X-Varnish-Beresp-TTL
X-Newrelic-Synthetics
X-Cache-PHP
X-Cache-Ttl
X-Service
Tracecode
X-App
X-CUA
X-Li-Proto
X-LI-Proto
X-Var-Ttl
C-Via
X-Pass-Why
X-URL
X-From
Geo-Info
T-Server
X-Fpc
Lfy
X-Webkit-Csp-Report-Only
X-Traceid
Fastly-Drupal-HTML
DataCenter
X-Fragments
Lang
Test
X-B3-Spanid
X-FPC
X-Vcl-Version
Proxy-Connection
Cf-Int-Pingora-Origin-Digest
X-NODE
X-Webkit-CSP-Report-Only
X-VC
X-Render-Time
X-Cache-Status-Check
Target-Params
X-LiteSpeed-Cache-Control
X-Mcache
X-WP-CF-Super-Cache-Cache-Control
M-TraceId
X-WP-CF-Super-Cache
X-CSRF-TOKEN
Resin-Trace
MIME-Version
Hostname
Server-Id
X-RAMCache
X-Ha-Backend
X-Api-Version
X-Provided-By
X-Geo
X-ID
Permissions-Policy
X-COUNTRY
X-Via-PopH
X-Via-PopV
X-ServedByHost
X-Httpd
X-Proxy-Cache-Info
WZWS-RAY
Hit
X-Clientip
X-NGINX-Cache
X-Via-PopN
GeoIP-Country-Code
Servername
X-Dynatrace-Js-Agent
UCS
X-LiteSpeed-Tag
X-Oss-Server-Time
X-Oss-Hash-Crc64ecma
X-SB
X-Edge-POP
X-Oss-Object-Type
X-Oss-Request-Id
Producers
X-Oss-Storage-Class
ENV
X-Cdn-Forward
FSS-Cache
X-Pad
HIT
Cache-Host
X-AIR-PT
X-Info
Section-Io-Origin-Status
X-Platform-Router
S-Cnection
X-Platform-Processor
X-Pool
X-Udemy-Cache-App-Namespace
Section-Origin-Responded
Section-Io-Id
X-Edge-Cache
X-Platform-Cluster
X-Fastly-Backend-Reqs
Section-Io-Origin-Time-Seconds
X-Ec-Custom-Error
X-Ucs
X-ElasticPress-Query
Ohc-File-Size
X-Check-Cacheable
X-Scale
Fastly-Backend-Name
X-Cache-Expires
URI
Sever-Int
Server-Hostname
X-Dispatcher-Number
ServerName
User-Agent
X-Acquia-Purge-Tags
X-Acquia-Site
X-Acquia-Application-UUID
X-Acquia-Application-Trace
Server-Ext
X-UP
Uri
PICS-Label
X-HS-Status
X-Micro-Cache
X-Cache-CFC
MD5-Digest
X-GoCache-CacheStatus
X-Lb-Nocache
X-Lb-Id
X-BBC-Origin-Response-Status
X-Srcache-Fetch-Status
X-Srcache-Store-Status
Sid
X-Via-Ucdn
X-Fastly-Cache-Hits
X-Cdn-Request-ID
X-Backend-Host
X-RateLimit-Reset
Cteonnt-Length
X-ServerName
Load-Balancing
IsBot
X-Nc
X-Swift-Error
Cneonction
Server-Ttl
X-Release
Tcn
X-SIPLIST1
X-Dw-Trace-Id
X-Akamai-ERPolicy
X-Fetch-By
X-Akamai-ERRuleID
X-Cms-Context
Wpo-Cache-Message
Wpo-Cache-Status
X-Contensis-Viewer-Groups
X-Vcache
Vha6-Origin
EpKe-Alive
X-B3-ParentSpanId
CF-Cached-On
X-Yottaa-OS
X-Newrelic-App-Data
Shield-Pop
X-Cache-ASPX
X-BCube-Filmed-By
X-APP
X-Snapshot-Date
Ngx
X-TRACE-ID
Cf-Ipcountry
Cdn
X-HostName
X-Cache-Ngx
X-Air-Pt
X-Via-CDN
Ohc-Cache-HIT
Inserted-Into-Cache-At
X-Litespeed-Cache-Control
X-Logging-Id
X-IN-APIGATEWAYSSL
Path
X-IN-APIGATEWAY
X-B3-Parentspanid
X-Akamai-Pragma-Client-IP
X-Apw-Access-Action
X-Last-Modified
X-Apw-Access-Object
X-Sentry-ID
X-Te-Duration-Ms
X-Http-Duration-Ms
X-Te-Count
X-Apw-Access-Token
X-Apw-Hits
X-Akamai-Request-ID
X-UA
X-CacheKey
X-Http-Count
Req-ID
CountryCode
X-Varnish-Authentication
X-Shopify-Generated-Cart-Token