Threat Level: green Handler on Duty: Guy Bruneau

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
Pragma
X-Powered-By
X-XSS-Protection
CF-RAY
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
P3P
Alt-Svc
X-Cache-Hits
X-UA-Compatible
X-Xss-Protection
X-Served-By
CF-Ray
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Request-Id
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
Access-Control-Allow-Credentials
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
X-Drupal-Cache
X-Generator
X-Cache-Status
X-Check
X-Cacheable
X-Envoy-Upstream-Service-Time
X-Request-ID
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-FRAME-OPTIONS
X-Iinfo
X-Dns-Prefetch-Control
X-Drupal-Dynamic-Cache
Feature-Policy
X-Content-Security-Policy
Content-Encoding
Access-Control-Expose-Headers
Upgrade
Status
X-CDN
X-AspNetMvc-Version
X-XSS-PROTECTION
Server-Timing
Access-Control-Max-Age
X-Amz-Request-Id
Request-Context
X-Amz-Id-2
X-Turbo-Charged-By
X-AH-Environment
X-Via
X-Robots-Tag
X-Backend
X-Cache-Group
Cf-Edge-Cache
Keep-Alive
Host-Header
X-Proxy-Cache
X-Hacker
X-Server
X-UA-Device
X-Rq
X-Server-Powered-By
X-Age
Allow
X-Vhost
X-Varnish-Cache
X-Ws-Request-Id
EagleId
X-Dispatcher
X-Amz-Version-Id
Grace
X-LiteSpeed-Cache
P3p
Cf-Apo-Via
Nel
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Ua-Compatible
X-Page-Speed
X-Device
Cf-Railgun
EagleEye-TraceId
X-Aws-Lambda-Call-Status
X-Swift-SaveTime
X-Swift-CacheTime
X-WebKit-CSP
Ali-Swift-Global-Savetime
X-Pingback
X-Node
X-Host
Accept-CH
X-Server-Id
Surrogate-Control
X-Backend-Server
X-CST
X-OneAgent-JS-Injection
X-Readtime
X-Nginx-Cache-Status
X-Akam-SW-Version
X-Cache-Lookup
X-Content-Security-Policy-Report-Only
Permissions-Policy
Request-Id
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Application-Context
X-Nginx-Upstream-Cache-Status
X-Cloud-Trace-Context
X-Trace
Accept-Ch-Lifetime
X-Response-Time
X-Edge
X-HW
Content-Location
X-Oneagent-Js-Injection
X-Mod-Pagespeed
Accept-CH-Lifetime
X-Clacks-Overhead
X-Url
X-Midtier
X-ECACHE
Rating
X-Ruxit-JS-Agent
X-Amz-Server-Side-Encryption
X-Mcache
X-ESI
X-Country
Xkey
X-Litespeed-Cache
X-Upstream
X-TtlSet
X-PC
X-Vname
X-Vcap-Request-Id
Accept-Ch
Cache-Tag
X-MS-InvokeApp
X-Rack-Cache
X-D2id
X-Use-Magma
X-Cdn-Fetch
X-Element-Page-Cache
X-Exp-Variant
X-Exp-Id
X-GoogleNews-Bot
X-Kinja
X-Kinja-Revision
X-Kinja-Server
X-Kinja-Build
Verso
X-Cache-TTL
X-Ruxit-Js-Agent
RTSS
Fastly-Restarts
Edge-Control
X-Powered-By-Plesk
X-VARITI-CCR
Origin-Trial
X-Content-Type
X-Ac
X-Navigation-Version
X-Abt-Application-Version
X-Cached
X-Goog-Hash
Service-Worker-Allowed
X-WebKit-CSP-Report-Only
X-Country-Code
X-GitHub-Request-Id
X-Ttl
X-Amz-Rid
X-Middleton-Display
Pagespeed
X-Sol
Display
X-Browser-Type
X-Mg-S
X-Dw-Request-Base-Id
X-B3-TraceId
X-SharePointHealthScore
SPRequestGuid
X-Server-Name
Cross-Origin-Opener-Policy
X-Varnish-TTL
Arr-Disable-Session-Affinity
X-Instrumentation
X-Erf-Bev-Bev-Is-Generated
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Erf-Bev-Bev
AR-SID
AR-ATIME
AR-Request-ID
AR-PoweredBy
X-Powered-CMS
Response
X-Middleton-Response
X-Amzn-Trace-Id
SPRequestDuration
SPIisLatency
X-Cache-Key
AR-CACHE
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Fastly-Request-ID
X-Version
X-Cnection
X-Accel-Expires
X-Times
X-T
Cache-Tags
Cache-Status
Front-End-Https
X-NF-Request-ID
X-HP-Trace-Id
X-Jurisdiction
X-HP-Webp
X-Fastcgi-Cache
X-MSEdge-Ref
Edge-Cache-Tag
Pinterest-Generated-By
X-Pinterest-Rid
Pinterest-Version
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
X-Px
X-Ser
X-Hits
Public-Key-Pins
Nginx-Cache
X-Client-IP
X-Recruiting
X-NWS-LOG-UUID
MRF-Tech
X-B3-TraceId-Primal
Mrf-Cache-Status
X-Ua-Device
X-Request-Processing-Time
X-LLID
X-Request-Received
X-RateLimit-Remaining
X-Shield-Request-Id
X-Frontend
Server-Node
Payment
X-Webkit-CSP
X-Ua-Browser
Access-Control-Request-Method
X-Kinja-CCPA
X-DIS-Request-ID
TP-Cache
X-Erf-Stays-Pdp-Viaduct-Migration-Web
X-B3-Traceid
MicrosoftSharePointTeamServices
X-Goog-Metageneration
X-RateLimit-Limit
S
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Combine-CSS
X-HS-Cache-Config
TP-L2-Cache
X-LB-Cache
X-Content-Digest
X-FastCGI-Cache
X-Distributor
Content-MD5
Realpath
X-PressLabs-Stats
X-Microsite
X-Request-Handler-Origin-Region
X-Webkit-CSP-Report-Only
X-Geo-Country
X-Page-Id
X-FB-Debug
X-Ezoic-Cdn
X-Hostname
X-Forwarded-For
Access-Control-Allow-Method
X-Ratelimit-Remaining
Accept-Charset
Fastcgi-Cache
X-GUploader-UploadID
X-Cluster-Name
X-Correlation-Id
X-Rid
X-Protected-By
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Envoy-Decorator-Operation
X-Seen-By
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-TEC-API-ROOT
Cleartype
X-B3-Sampled
TCN
X-XRDS-Location
DC
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Goog-Storage-Class
X-Newrelic-App-Data
X-Ratelimit-Limit
Referer-Policy
X-Origin-Server
X-Debug-Info
X-Mobile
X-Webkit-Csp
Cross-Origin-Resource-Policy
X-Logged-In
X-TTL
X-Aspnet-Version
X-Git-Hash
X-Varnish-Backend
X-Origin-Cache
X-Azure-Ref
X-Contextid
X-Kinsta-Cache
X-Server-ID
X-Edge-Location-Klb
X-Aspnet-Duration-Ms
Alternate-Protocol
X-Request-Guid
X-Flags
X-Fb-Rlafr
X-Amz-Replication-Status
X-Is-Crawler
Surrogate-Key
X-Revision
X-App-Environment
X-Providence-Cookie
X-Route-Name
X-Varnish-Grace
X-Grace
X-Content-Options
X-TT
Count-Hit
X-Amz-Meta-S3cmd-Attrs
X-IPS-LoggedIn
Healthy
X-Wix-Request-Id
X-Client-Ip
X-Forwarded-Proto
X-Whom
Frame-Options
X-App-Server
Charset
X-Hosted-By
WPO-Cache-Message
MS-Author-Via
WPO-Cache-Status
X-Akamai-Edgescape
Viewport
X-Daa-Tunnel
Filterid
X-Oracle-Dms-Ecid
X-B
X-Id
X-Magnolia-Registration
Paypal-Debug-Id
X-Oracle-Dms-Rid
X-Backend-Name
Retry-After
Section-Io-Cache
X-F-Cache
Amp-Access-Control-Allow-Source-Origin
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Activity-Id
X-Trace-Id
SRV
X-Az
X-AppVersion
X-Www-Served-By
X-Cache-Control
Server-Name
X-Cache-Age
X-Proxy-Cache-Info
X-Type
X-App-Version
Refresh
X-Varnish-Server
X-Cache-Rule
Akamai-GRN
X-Proxy
SD-X-WS
Host
VIX-Pulpo-Upstream-Status
X-Instance
X-Original-Request-Id
X-Response-Served-From
X-Rule
VIX-Pulpo-Node
X-Http-Reason
X-ARC
X-Rocket-Nginx-Serving-Static
Front
Protected
Version
X-RateLimit-Reset
X-UUID
X-Status
X-EdgeConnect-Cache-Status
X-Cache-Grace
X-Varnish-Age
X-Edge-Location
X-FW-Hash
X-Rendered-As
X-N
X-Page-View
X-FW-Dynamic
X-Environment-Context
X-Cacheable-TTL
X-User-Agent
X-Unique-Id
X-COUNTRY
X-Framework
X-Akamai-Request-ID2
X-FW-Version
X-FW-Type
X-FW-Static
X-FW-Server
X-FW-Serve
X-Jobs
X-L-Path
X-Is-Bot
X-Region
Fastly-SWR
Access-Control-Request-Headers
From-Origin
Fastly-SIE
X-Adobe-Loc
X-Adobe-Content
X-G
X-Cache-Time
X-RemovedCookies
X-ProcessESI
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Tumblr-Pixel-1
X-Tumblr-User
ServerID
X-Load-Cache
X-Source
X-Time
X-Upgrade-Enabled
X-Varnish-Ttl
X-Language
X-Datadog-Sampling-Priority
Content-Disposition
X-Datadog-Trace-Id
X-Datadog-Parent-Id
Country
X-Drupal-Cache-Tags
X-CDN-Forward
X-Vcache
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-DataDome
X-HTML-Minification-Powered-By
Accept-Language
X-Datadog-Sampled
Countrycode
X-Mg-Request-UUID
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Debug-IsPreview
X-DynaTrace
X-Debug-IsConnected
X-Amzn-Remapped-Content-Length
X-ID
X-Nf-Request-Id
X-Generated-By
X-DynaTrace-JS-Agent
X-B3-SpanId
X-ECache
Backend
Xet-Cookie
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
Liferay-Portal
X-B-Cache
X-Signature
CF-IPCountry
X-Nginx-Cache
Xserver
X-Tt-Logid
X-Erf-Web-Scheduler
X-NYM-Debug-Backend
X-Mode
X-Device-Type
X-Drupal-Cache-Contexts
X-Content-Powered-By
X-Servername
Webserver
X-Content-Age
Url
X-Httpd
X-Zen-Fury
X-Xrds-Location
X-UPSTREAM-Address
X-Git-Commit
S-Rt
X-JoinUs
X-Rewrite-Enabled
X-LAGOON
X-Director
GEO-INFO
X-Cache-Operation
X-Cache-Action
Onion-Location
X-ServerID
X-Proto
Azure-Version
Azure-SlotName
Azure-SiteName
X-Say-TTL
X-Varnish-Cache-Hits
Fastcgi-Useragent
X-Say-Cacheable
X-Container-Uri
X-SaId
Load-Balancing
X-Sucuri-Cache
Azure-RegionName
X-Urbn-Site-Id
Meta-Geo
X-GeoCode
X-GeoCountry
X-Urbn-Context-Path
X-SayCDN-TTL
Filters
X-Sucuri-ID
Locale
Azure-InstanceId
X-Tb
X-PHP-Host
X-Forwarded-Host
X-Varnish-Hostname
X-VC-Cache
X-Labrador-Cache-Channel
X-Soup
X-Adobe-Source
X-Served-From
X-Cluster-Node
X-Sql-Count
CDN-RequestId
X-Sql-Duration-Ms
Uber-Trace-Id
X-Generation-Time
X-Detected-As
X-Logging-Id
Web-Mar-Node
X-RM-Cache-TTL
X-Storage
DB-Nickname
X-Extlb
TWC-Device-Class
Webcakes-App-Name
TWC-Privacy
TWC-Locale-Group
TWC-GeoIP-LatLong
Webcakes-App-Version
X-Routing-Service
X-Cache-Server
Webcakes-Region
X-VCT
X-Zipkin-Id
TWC-GeoIP-Country
X-FB-TRIP-ID
X-Skip-Cache
X-RCS-CacheZone
X-R9-Blue-Green-Version
X-Origin-Hint
Property-Id
TWC-Connection-Speed
X-Debug
Mn-Server-Ip
X-Proxied
Node
Selected-Fe
X-Tumblr-Pixel-3
X-Uri
X-Tumblr-Pixel-2
X-LSADC-Cache
X-Proxy-Build
X-Timing-Wait
X-Format
X-Lambda-Id
X-Ms-Request-Id
X-Fetched-On
X-Ms-Version
Fastly-Drupal-HTML
X-Ratelimit-Reset
X-Template
Source
X-Origin-Date
OT-Force-Account-Verify
X-MP-GENERATED-AT
X-XRDS-LOCATION
X-Cache-Expired-At
X-MCACHE
X-Tncms
X-Loop
X-Cache-Hit
X-Tec-Api-Origin
X-Tec-Api-Version
X-Tec-Api-Root
X-Varnish-Hits
X-Via-JSL
X-Pass-Why
X-Endurance-Cache-Level
Content-Secure-Policy
X-NGENIX-Cache
X-Ua
X-Cache-TTL-Remaining
X-Redis-Cache
X-UA-Device-Type
X-Srv
Upgrade-Insecure-Requests
X-Node-Name
X-AIR-PT
X-Pubstack
Cross-Origin-Window-Policy
X-Real-IP
X-Fastly-Request-Id
X-Origin-TTL
X-Origin-CC
X-Server-W
Section-Origin-Responded
X-CCDN-CacheTTL
Section-Io-Id
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
X-Hcs-Proxy-Type
X-CCDN-Origin-Time
NGB
X-GEO
X-PHP-Backend
X-S
X-CACHE-AGE
Cache-Provider
X-Cache-Host
X-Rn-Rsrv
Ms-Operation-Id
MS-CV
CDN-Cache
CDN-CachedAt
CDN-EdgeStorageId
Cache-Name
CDN-RequestPullSuccess
CDN-Uid
Cache-Hits
X-RTag
CDN-RequestCountryCode
CDN-RequestPullCode
CDN-PullZone
X-TimeS
X-Cache-Type
X-Restarts
X-Cms-Context
X-Hl-Ver
X-Xfnlog-Site
X-IPLB-Request-ID
X-URL
X-IPLB-Instance
X-Aspnetmvc-Version
Apigw-Requestid
X-Optimistic-Header
X-Datadome
X-Reqid
X-Akamai-Transformed
X-BYPASS-REASON
X-ProxyCache-Status
X-No-Session
X-TA-CDN-Provider
X-CSRF-Token
X-ProxyCache-Key
X-Newrelic-Synthetics
X-Parent-Response-Time
Magicmarker
Meta-Geo-Continent
Ngx.Var.Host
N-Cache
X-Origin-Time
MD5-Digest
X-Orig-Expires
Odigeo-Trace-Id
Redirect-Candidate
Fastly-SSL
X-Policy
Canary
Candidate-Md5Url
X-GeoIP-Country-Code
BehaviorPad-Version
X-RateLimit-Limit-Second
X-S-Cookie
X-Rojux
X-Request-Host
X-RateLimit-Remaining-Second
CPC-Cache
DCR-Decision-By
Ha-Gx-Prefs
HA-Ipaddr
L
L5d-Success-Class
Gh-Request-Id
Gannett-Cam-Experience-Id
DCR-Processing-Time-Ms
Fastly-Backend-Name
Fastly-GeoIP-CountryCode
Rendered-Blocks
Lang
X-A-Dgt
X-D
X-Csrf-Jwt
X-Date
X-Debug-Cache-Fetch
X-Destination
X-Debug-Cache-Store
X-Conf
X-CGP
X-CacheTTL
X-Is-Gdpr
X-Irp-Debug
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-Developer
X-Dispatcher-Number
X-FC-Vary-Parameters
X-Has-Esi
X-Forwarded-Path
X-Gdpr
X-GeoIP-Region-Code
X-Fastly-Backend
X-External-Request-Id
X-Ec-Fail
X-Ec-Custom-Error
X-Ec-GeoHdr
X-Epic-Correlation-Id
X-Eu-Site
X-JWT-State
X-Cache-NE
Web-Mar-Region
VNS-Cache
X-A
X-A-Ccd
X-A-Dam
VNS-Age
Vix-Hermes-Req-Id
Surrogated-Key
Sslversion
T-Server
True-Client-Country-4JS
X-Nyt-Route
X-A-Dcw
X-ScT
X-BCube-Filmed-By
X-Bc-Bl
X-Bl-Debug
X-Cache-Bucket
X-Cache-Info
X-B-Cookie
X-Application
X-Accel-Buffering
X-A-Wwc
X-Accel-Expires-Debug
X-Mvc-Supplant-Cachable
X-Aed
Server-Host
CPC-Age
X-Vdms-Version
X-Slack-Backend
X-VG-WebCache
X-TIM-N
X-We-Are-Hiring
X-Vdms-Path
X-Tenant
X-Vtex-Remote-Cache
Xc-Version
X-Wikidot-Backend
X-Viewer-Country
X-Wix-Viewer-Type
X-SD-PageType
X-Wikidot-Static-Cache
X-Worker
X-Via-Fastly
X-SRCache-Key
X-Shop-Environment
X-Slack-Shared-Secret-Outcome
X-Var-Ttl
X-Handled-By
X-Section
X-Access
X-TIME
X-Alternate-Cache-Key
X-ApacheServer
X-Mly-Id
X-VG-TLSProxy
X-Varnishpool
We-Hiring
W
X-Varnish-CookieHashed-On
Req-Svc-Chain
X-Org
X-Old-Content-Length
X-Thinkindot-L3
Release
Producers
X-Thanos
X-Up
TDXMobile
X-Nitro-Cache
X-Mid
X-Varnish-CookieINHashed-On
X-Node-Id
Thinkindot-Control
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
X-Varnish-Remaining-TTL
X-Proxy-Cache-Status
X-App
X-DefElseHash
X-DefHash
X-Human
X-LJ-Flow-ID
X-Core-Mission
X-Core-Value
X-DPWN-IS-SECURE
X-Esi-Check
X-AWS-Id
X-Generated-On
X-Geo-Header
X-Gzip
X-Forwarded-Site
X-Cluster
X-Fmm-Version
X-INCAP-ABP
X-CMSURLCustom
X-Vmg-Version
Platform
X-Cache-Debug
X-Bip
X-BBC-Edge-Cache-Status
X-Auto-Login
X-Loc
X-Level-Front-Cache
X-Cache-Id
X-Clara-WADP
X-Clientip
X-Cdn-Origin
X-Cdn-Diag
X-VServer
X-WADP-Cache
X-App-Name
X-Variation
Is-Eu
X-Owner
X-Storefront-Renderer-Rendered
X-Sorting-Hat-ShopId
X-PERF
Adler-Geo
AKAMAI
X-Sn-Servicetimems
X-SVT-ORM-RULES
Machine
Cmstype
Datacenter
Cmsid
X-SVT-ORM-VERSION
Mail-Subject
X-Platform
X-Sorting-Hat-PodId
Environment
X-ShardId
Host-ID
X-Request-Time
Origin
X-PAYTM-SRV-ID
X-S-Maxage
X-Server-IP
X-Origin-Response-Time
X-ShopId
X-Qloud-Router
X-Pool
Expect-Staple
X-Shopify-Stage
X-VWS-Id
User-Cache-Control
ServedBy
X-Block-Status
X-Akamai-Device-Characteristics
X-Cdn-Srv
X-Device-Os
X-Hnp-Log
X-Dispatcher-Server
X-Hash
X-Gen-Mode
X-From
Apple-News-Services-Handled
Apple-News-Services-Host
X-WA-Info
CloudFront-Viewer-Country
CDCHOST
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
Country-Code
DSUID
X-Presslabs-Stats
X-Test
X-Mvc-Supplant-OutputCached
Memcached
X-Scale
X-Nananana
X-Nginx-Cache-Key
X-NodeID
Server-Hostname
Sever-Int
X-Origin
Server-Ext
X-Tx-Id
X-Vcl-Version
X-LB-NoCache
Origin-EX
X-GeoIP
X-NCache
Pics-Label
X-Refresh
Ssr
Server-Info
X-Op-Id-All
X-Web-Node
NM-Fastcgi-Cache
X-Instance-Name
C-Via
WP-Super-Cache
Esi-Enabled
Wxu-Next-Hostname
Wxu-Next-Region
Origin-CC
Wxu-Next-Commit
X-Air-Source
X-Air-Hostname
X-Air-Trace-Id
X-Cache-Enabled
Server-ID
X-Cs
X-Azure-Ref-OriginShield
X-Amz-Meta-Cb-Modifiedtime
X-Cache-Status-Check
Time
Hostname
X-HA-Backend
Memory
X-API-Version
X-ZONE
X-Platform-Cluster
Cf-Device-Type
GeoIP-Latitude
Origin-Agent-Cluster
X-Origin-Expires
NGX
X-Microcachable
Cache-Host
X-Platform-Router
X-Platform-Processor
X-Tb-Optimization-Total-Bytes-Saved
AMP-Access-Control-Allow-Source-Origin
X-VHOST
X-Correlation-ID
X-CACHE-GROUP
XM
X-DC
X-Locale
X-Site-Version
X-HN
X-Dc
PFcat
X-VarnishDD-TTL
X-Wp-Cf-Super-Cache-Active
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Ttl
X-Fpc
X-Ad-Defer-Variation
Resin-Trace
X-Via-CDN
X-Vgn-Hpd-Reason
X-Internal-Host
Srvid
X-Micro-Cache
X-Via-Edge
Locid
A
X-Webkit-Csp-Report-Only
X-Via-SSL
X-FL-EDGE
Edge-Copy-Time
X-FL-QIT-DEBUG
YJS-ID
X-WP-CF-Super-Cache-Active
Cdn-Requestid
X-Zone
X-DataCenter
X-Pod-Name
X-Cache-ASPX
X-ATG-Version
X-Upstream-Ct
X-Upstream-Ht
X-Github-Request-Id
X-Contensis-Viewer-Groups
X-TraceId
X-FireWall-Port
Sid
User-Agent
X-Moov-Xdn-Version
Uri
X-Varnish-Authentication
IsBot
Cache-Key
X-Moov-T
X-AB
X-SIPLIST1
X-Cached-By
Location
X-Buckets
X-LiteSpeed-Cache-Control
X-Info
True-Client-Ip
X-B3-Parentspanid
X-B3-Spanid
X-Geo-Region
GeoIP-Country-Code
X-Backend-Instance
State
X-Esi
X-Accel-Version
X-Platform-Server
X-HS-Content-Campaign-Id
X-Nitro-Cache-From
X-Planisys-CDN-Rules
X-Nitro-Rev
X-Planisys-CDN-Cache
X-Planisys-CDN-TTL
X-NGINX-Cache
X-FTR-Request-ID
X-LiteSpeed-Tag
X-Provided-By
SID
X-MSEdge-Features
X-MSEdge-Flight
X-Fastly-Cache
GeoIp-Country-Code
X-Release
X-CS
X-CSRF-TOKEN
CF-Ctrl
X-VCache
X-Is-Tablet
X-Is-Supported-Browser
XServer
X-Tcp-Rtt
Cdn
X-Is-Mobile
X-Is-Desktop
X-Sigma-Backend
X-VC
X-Rocket-Build-Number
X-Browser-Name
X-Sigma
X-RN-RSRV
X-Cache-Remote
NtCoent-Length
X-Datacenter
X-NewRelic-App-Data
X-Vgn-Hpd-Cached
Cache
X-Vgn-Hpd-Ssi
True-Client-IP
Path
X-Vgn-Hpd-Variations-Key
X-Geo
Lb
X-Api-Version
X-Hyper-Cache
X-Gamma-Serve
X-HS-Status
X-SRV
X-Generated-In
X-GeoIP-City
Epwk-X-Cache
X-TRACE-ID
X-Scheme
Fastly-Drupal-Html
X-FPC
Tcn
X-HostName
X-Webstats-RespID
Cache-Tv-Group
WebServer
X-Frame-Option
Ohc-File-Size
X-Service
X-GoCache-CacheStatus
X-UA
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-APP-VERSION
Serverid
CountryCode
Cf-Ipcountry
X-Amz-Meta-Opti
X-Air-Pt
X-AK-Request-ID
Kp-EeAlive
Cdncip
Cdnsip
X-Guploader-Uploadid
Srv
X-Cache-Ttl
X-Wp-Cf-Super-Cache
X-Branch-Name
X-Mobile-URL
X-Location
X-Traceid
HostName
X-Wp-Cf-Super-Cache-Cache-Control
LB
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-Region-Sid
X-Men
X-Developers
X-EC-Lua
Ohc-Cache-HIT
X-Pad
Proxy-Connection
X-Edge-Server
X-Vercel-Id
X-Vercel-Cache
Env
Cdn-Request-Time
X-Cache-Tags
Cdn-Host
X-Aicache-OS
Yak-Timeinfo
CacheControlHeader
X-Cdn-Cache-Status
WZWS-RAY
X-Proxy-CacheRZ
X-Vc
On-Server
XkeyRZ
CDN
X-CACHE-KEY
X-VCL-Version
X-Origin-Cache-Key
X-TX-ID
X-FTR-Cache-Status
X-LB-ID
X-FTR-Expires
X-FTR-Backend
Req-ID
M-TraceId
Geoip-Latitude
X-Akamai-Pragma-Client-IP
X-Country-Code-Real
X-FTR-Balancer
X-FTR-Backend-Server
X-CDN-Cache-Status
X-B3-Trace-ID
Mime-Version
X-Nc
RNT-Machine
X-Wa
V-Age
Click-Count-Error
X-Edge-Pop
X-Cdn-Forward
X-V-Cache
Tube-Return
Tube-Got-Eval
X-Via-Poph
Tube-Got-Results
Tube-Get-Contents
X-Via-Popn
X-Via-Popv
RNT-Time
Click-Count-Action-Start
X-Acquia-Purge-Cdn-Unconfigured
X-Req
X-NWS-UUID-VERIFY
Ngx
X-Servedbyhost
X-Cache-FS-Status
X-SB
X-Minions-Version
X-Cdn-Request-ID
X-Lb-Cache
X-WP-CF-Super-Cache-Cookies-Bypass
Server-Id
Cluster
Content-Style-Type
X-Ad-Load-Variation
X-Ha-Backend
Content-Script-Type
CF-Cached-On
X-Fastly-Country-Code
X-NMSegId
ENV
WWW-Authenticate
X-TT-LOGID
X-Request-Start
X-Scope-Id
X-M-Reqid
Pramga
X-User
X-Lb-Nocache
X-M-Log
PICS-Label
X-Acquia-Application-Trace
X-Dw-Trace-Id
X-IN-APIGATEWAYSSL
X-Check-Cacheable
X-MiniProfiler-Ids
X-Snapshot-Date
X-Edge-POP
X-Acquia-Site
X-IN-APIGATEWAY
X-Via-Ucdn
X-Acquia-Purge-Tags
X-Acquia-Application-UUID
Yjs-Id
X-Fastly-Backend-Reqs
Log-Origin
X-RAMCache
X-Varnish-Beresp-Status
X-Iauth-Set-Uid
X-Shield-Cache-Expires
X-Ckpd-Fst-Backend
X-Request-URI
X-Qnm-Cache
X-APP
Vha6-Origin
X-TH-Server
X-Miniprofiler-Ids
X-Cached-Since
X-Fastly-Cache-Hits
Cneonction
CACHE-MISS-TO-ORIGIN
X-Processor
X-Litespeed-Cache-Control
Inserted-Into-Cache-At
X-ElasticPress-Query