Threat Level: green Handler on Duty: Daniel Wesemann

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Accept-Ranges
X-XSS-Protection
Expect-CT
Pragma
X-Powered-By
CF-RAY
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
P3P
X-Cache-Hits
X-UA-Compatible
X-Served-By
CF-Ray
X-Xss-Protection
X-Download-Options
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Request-Id
X-Adblock-Key
Access-Control-Allow-Credentials
X-FRAME-OPTIONS
X-Permitted-Cross-Domain-Policies
X-Request-ID
X-AspNet-Version
Alt-Svc
X-Runtime
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Generator
X-Cache-Status
X-Check
X-Cacheable
Timing-Allow-Origin
X-Envoy-Upstream-Service-Time
X-Iinfo
X-Content-Security-Policy
X-Drupal-Dynamic-Cache
Feature-Policy
Content-Encoding
Access-Control-Expose-Headers
Status
Upgrade
X-AspNetMvc-Version
X-CDN
Access-Control-Max-Age
X-Dns-Prefetch-Control
X-Via
Server-Timing
Request-Context
X-Robots-Tag
X-Turbo-Charged-By
X-Amz-Request-Id
X-UA-Device
X-Cache-Group
X-Amz-Id-2
EagleId
X-Backend
X-AH-Environment
X-Proxy-Cache
X-Server
Keep-Alive
X-Ws-Request-Id
X-Age
Cf-Edge-Cache
Host-Header
X-Hacker
X-Vhost
X-Server-Powered-By
X-Rq
X-Varnish-Cache
X-Dispatcher
X-Amz-Version-Id
Grace
Allow
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-OneAgent-JS-Injection
P3p
X-Ua-Compatible
X-LiteSpeed-Cache
X-Page-Speed
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
Cf-Apo-Via
X-Device
Cf-Railgun
X-WebKit-CSP
Accept-CH
X-Aws-Lambda-Call-Status
X-Node
X-Pingback
EagleEye-TraceId
X-Host
X-Server-Id
X-Ruxit-JS-Agent
Surrogate-Control
X-Nginx-Cache-Status
X-Akam-SW-Version
X-Readtime
Request-Id
X-Backend-Server
Accept-Ch-Lifetime
X-Content-Security-Policy-Report-Only
X-HW
X-Cache-Lookup
X-Litespeed-Cache
X-Cloud-Trace-Context
X-Cache-Spec
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Application-Context
X-Trace
X-Response-Time
Permissions-Policy
X-Nginx-Upstream-Cache-Status
Fastly-Restarts
X-Edge
X-Mod-Pagespeed
X-WebKit-CSP-Report-Only
X-Country
X-Mcache
Content-Location
X-MS-InvokeApp
X-Content-Type
X-Url
X-Clacks-Overhead
X-PC
X-Vname
X-TtlSet
X-Midtier
X-Amz-Server-Side-Encryption
X-CST
Rating
RTSS
Accept-CH-Lifetime
X-ECACHE
Cache-Tag
X-ESI
X-Vcap-Request-Id
X-D2id
X-Rack-Cache
X-Element-Page-Cache
Verso
X-Kinja
X-Exp-Variant
X-Cdn-Fetch
X-Exp-Id
X-GoogleNews-Bot
X-Kinja-Build
X-Use-Magma
X-Kinja-Server
X-Kinja-Revision
Origin-Trial
X-Server-Name
X-VARITI-CCR
X-GitHub-Request-Id
Service-Worker-Allowed
X-Ac
X-Powered-By-Plesk
X-Amz-Rid
X-Cnection
SPRequestGuid
X-SharePointHealthScore
X-Client-IP
X-Navigation-Version
Xkey
Edge-Control
X-Upstream
SPIisLatency
SPRequestDuration
X-Abt-Application-Version
X-Cache-TTL
Arr-Disable-Session-Affinity
X-Ttl
X-Cached
X-Varnish-TTL
X-Dw-Request-Base-Id
X-Mg-S
X-Webkit-Csp
X-Server-Lifecycle-Phase
X-Erf-Bev-Bev
X-Kraken-Loop-Name
X-Instrumentation
X-Erf-Bev-Bev-Is-Generated
X-Browser-Type
X-NWS-LOG-UUID
X-B3-TraceId
X-Px
Accept-Ch
X-Sol
Display
Pagespeed
X-Middleton-Display
X-Correlation-Id
X-SRCache-Fetch-Status
X-SRCache-Store-Status
Edge-Cache-Tag
Access-Control-Request-Method
X-Forwarded-For
X-Cache-Key
X-NF-Request-ID
X-Country-Code
X-Goog-Hash
X-Ser
X-Powered-CMS
X-FastCGI-Cache
AR-Request-ID
AR-ATIME
AR-CACHE
AR-PoweredBy
AR-SID
Content-MD5
Front-End-Https
Public-Key-Pins
TCN
X-Id
X-Version
X-Amzn-Trace-Id
X-HP-Trace-Id
X-Jurisdiction
X-HP-Webp
X-Recruiting
X-T
X-MSEdge-Ref
X-Middleton-Response
X-Content-Digest
Response
X-Ratelimit-Limit
X-Accel-Expires
X-Fastcgi-Cache
TP-Cache
TP-L2-Cache
X-RateLimit-Remaining
X-Shield-Request-Id
MicrosoftSharePointTeamServices
X-XRDS-Location
X-Fastly-Request-ID
S
Cache-Status
Nginx-Cache
X-HS-Content-Id
X-HS-Combine-CSS
X-HS-Hub-Id
Cross-Origin-Opener-Policy
X-HS-Cache-Config
X-Request-Received
X-Request-Processing-Time
Cache-Tags
Server-Node
X-Ratelimit-Remaining
Mrf-Cache-Status
MRF-Tech
X-B3-TraceId-Primal
X-Daa-Tunnel
X-Distributor
X-Hits
X-PressLabs-Stats
X-Edge-Location-Klb
X-LB-Cache
X-Kinsta-Cache
X-Origin-Server
X-Ua-Browser
X-Ezoic-Cdn
X-TEC-API-ORIGIN
Filterid
X-Ratelimit-Reset
Fastcgi-Cache
X-TEC-API-VERSION
X-TEC-API-ROOT
Alternate-Protocol
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-LLID
X-Frontend
X-Hostname
X-Microsite
X-Request-Handler-Origin-Region
Realpath
X-Grace
X-Rid
Healthy
X-DIS-Request-ID
X-Logged-In
X-Varnish-Backend
Cleartype
X-TTL
X-Git-Hash
Server-Name
X-FB-Debug
X-NGENIX-Cache
X-Cluster-Name
X-Www-Served-By
X-Geo-Country
X-Page-Id
Payment
X-Debug-Info
MS-Author-Via
X-Forwarded-Proto
DC
X-Load-Cache
X-Protected-By
X-Origin-Cache
Access-Control-Allow-Method
Content-Disposition
X-B3-Traceid
X-B3-Sampled
X-Kong-Proxy-Latency
X-Upgrade-Enabled
X-Goog-Metageneration
X-GUploader-UploadID
X-Kong-Upstream-Latency
Charset
X-Proxy
X-AppVersion
X-Az
X-Activity-Id
X-Seen-By
X-DataDome
X-Times
Count-Hit
X-Cache-Age
X-Amz-Meta-S3cmd-Attrs
X-B
X-Azure-Ref
X-Amz-Replication-Status
X-Fb-Rlafr
X-F-Cache
X-Whom
Paypal-Debug-Id
Surrogate-Key
X-Revision
X-Akamai-Edgescape
X-Type
Accept-Charset
Cross-Origin-Resource-Policy
X-Contextid
Viewport
X-Varnish-Server
X-App-Environment
X-Aspnet-Duration-Ms
X-Is-Crawler
X-Route-Name
X-Request-Guid
X-Flags
X-Providence-Cookie
Retry-After
X-Wix-Request-Id
X-TT
X-Hosted-By
X-Language
X-Envoy-Decorator-Operation
X-DynaTrace
X-Cache-Control
X-ECache
X-B-Cache
X-Signature
X-Oracle-Dms-Ecid
X-Oracle-Dms-Rid
X-Magnolia-Registration
X-Varnish-Grace
X-App-Server
X-Mobile
X-Goog-Generation
Amp-Access-Control-Allow-Source-Origin
X-Goog-Storage-Class
X-Source
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
Version
WPO-Cache-Message
Host
WPO-Cache-Status
X-Server-ID
X-VCache
X-Amz-Apigw-Id
X-Amzn-RequestId
Refresh
X-N
X-HTML-Minification-Powered-By
X-Cache-Rule
X-Response-Served-From
X-Original-Request-Id
Referer-Policy
X-Cache-Time
Access-Control-Request-Headers
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-Tumblr-User
X-Tumblr-Pixel
X-Varnish-Age
X-EdgeConnect-Cache-Status
X-Rule
X-G
MS-CV
Ms-Operation-Id
X-Content-Powered-By
X-Environment-Context
X-Cacheable-TTL
X-Framework
X-RTag
SD-X-WS
X-User-Agent
X-Region
X-UUID
X-L-Path
Protected
X-Jobs
X-FW-Dynamic
X-Cache-Grace
X-FW-Hash
X-Backend-Name
X-FW-Version
X-FW-Serve
X-Status
X-RemovedCookies
X-Tt-Trace-Tag
X-Oneagent-Js-Injection
GEO-INFO
Akamai-GRN
X-ProcessESI
X-Tt-Trace-Host
X-FW-Server
X-FW-Static
X-FW-Type
X-Akamai-Request-ID2
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-Http-Reason
NGB
Section-Io-Cache
From-Origin
X-Is-Bot
X-Rendered-As
Front
X-Device-Type
X-Instance
X-Trace-Id
X-Page-View
X-Cache-Expired-At
X-Drupal-Cache-Tags
X-NYM-Debug-Backend
X-Cache-Status-Check
X-Adobe-Content
X-Drupal-Cache-Contexts
X-Adobe-Loc
X-RateLimit-Limit
CDN-RequestId
X-Unique-Id
X-Nginx-Cache
X-XRDS-LOCATION
Url
Pinterest-Version
Pinterest-Generated-By
X-Pinterest-Rid
Liferay-Portal
X-Servername
X-Time
X-Varnish-Ttl
X-Content-Options
Accept-Language
X-Template
X-CDN-Forward
Fastly-SWR
SRV
Fastly-SIE
X-Air-Hostname
X-Zen-Fury
X-Air-Trace-Id
X-Newrelic-App-Data
X-Air-Source
Backend
X-Debug-IsPreview
X-Debug-IsConnected
X-Cache-Hit
X-DynaTrace-JS-Agent
X-Mode
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Uri
Country
X-Rocket-Nginx-Serving-Static
X-App-Version
Content-Secure-Policy
X-COUNTRY
X-ARC
X-Fastly-Request-Id
X-Edge-Location
X-Cache-Operation
Node
X-UPSTREAM-Address
Webserver
X-Tumblr-Pixel-3
X-Tumblr-Pixel-2
X-Generation-Time
X-Zipkin-Id
Meta-Geo
X-RN-RSRV
X-Routing-Service
X-Rewrite-Enabled
Filters
S-Rt
X-Extlb
X-Cache-Server
X-Proxied
X-Amzn-Remapped-Content-Length
Onion-Location
X-Proxy-Cache-Info
Uber-Trace-Id
Azure-SlotName
X-Proxy-Build
Azure-InstanceId
Countrycode
Azure-SiteName
X-PHP-Backend
Azure-RegionName
Cache-Hits
X-Content-Age
Selected-Fe
X-Timing-Wait
X-Server-W
X-IPS-LoggedIn
CF-IPCountry
Azure-Version
Property-Id
TWC-Locale-Group
Mn-Server-Ip
TWC-Connection-Speed
TWC-Device-Class
Cache-Name
TWC-GeoIP-LatLong
TWC-GeoIP-Country
X-Web-Node
X-Reqid
WP-Super-Cache
X-Ms-Version
X-Ms-Request-Id
X-Section
X-Locale
X-ProxyCache-Status
X-ProxyCache-Key
X-BYPASS-REASON
X-AWS-Id
X-Cache-Action
X-Cms-Context
X-Origin-Hint
X-Proxy-Cache-Status
X-Site-Version
X-Skip-Cache
X-Via-Fastly
Webcakes-Region
X-LJ-Flow-ID
X-UA-Device-Type
X-Cluster-Node
Webcakes-App-Version
X-VWS-Id
X-Format
X-Sucuri-Cache
X-Soup
X-Sucuri-ID
X-Tb
X-Access
TWC-Privacy
Webcakes-App-Name
X-Labrador-Cache-Channel
Web-Mar-Node
X-Say-Cacheable
X-Say-TTL
Cache-Tv-Group
X-Origin-Date
X-IPLB-Request-ID
X-IPLB-Instance
X-Cluster
X-PHP-Host
X-Debug
X-SayCDN-TTL
X-Proto
X-Forwarded-Host
X-Cache-Host
DB-Nickname
X-LAGOON
X-Detected-As
X-Cache-TTL-Remaining
X-JoinUs
Cross-Origin-Window-Policy
X-No-Session
X-Optimistic-Header
X-R9-Blue-Green-Version
X-SaId
X-Xfnlog-Site
Locale
X-Urbn-Context-Path
X-Urbn-Site-Id
X-Ruxit-Js-Agent
Apigw-Requestid
X-Sql-Duration-Ms
X-VC-Cache
X-Sql-Count
X-Director
X-Adobe-Source
X-Ua
X-Varnish-Beresp-Grace
X-Handled-By
X-FB-TRIP-ID
X-LSADC-Cache
X-Real-IP
ServedBy
ServerID
X-Tec-Api-Version
Fastcgi-Useragent
X-Tec-Api-Origin
X-Tec-Api-Root
Frame-Options
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
X-GeoCode
X-GeoCountry
X-Node-Name
X-Varnish-Hits
X-Tt-Logid
Mime-Version
Upgrade-Insecure-Requests
Fastly-Drupal-HTML
Source
X-Api-Version
Load-Balancing
X-Aspnetmvc-Version
CDN-PullZone
X-Hl-Ver
CDN-Cache
X-Generated-By
CDN-Uid
X-Varnish-Cache-Hits
CDN-EdgeStorageId
CDN-CachedAt
CDN-RequestCountryCode
X-Buckets
X-GEO
X-Request-Time
X-FireWall-Port
X-Varnish-Hostname
Xet-Cookie
X-ServerID
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
X-Webkit-CSP-Report-Only
X-RM-Cache-TTL
X-Datadog-Sampled
X-Origin-TTL
X-URL
X-Origin-CC
X-Redis-Cache
X-Mg-Request-UUID
X-Cache-Debug
X-Akamai-Transformed
X-SRV
X-TA-CDN-Provider
X-TIME
CF-Cached-On
X-Loop
Xserver
X-Served-From
X-Provided-By
X-Storage
X-Pubstack
X-Alternate-Cache-Key
X-ShopId
X-Shopify-Stage
X-Sorting-Hat-PodId
X-ShardId
X-Sorting-Hat-ShopId
X-Storefront-Renderer-Rendered
X-Tx-Id
X-Restarts
X-Pass-Why
X-Newrelic-Synthetics
X-CSRF-Token
X-Endurance-Cache-Level
X-Request-Host
X-Location
Sslversion
X-We-Are-Hiring
X-Fetched-On
T-Server
C-Via
BehaviorPad-Version
X-Vdms-Path
A
Server-Host
X-Vdms-Version
Surrogated-Key
Cache-Host
Redirect-Candidate
DSUID
DCR-Processing-Time-Ms
DCR-Decision-By
Gannett-Cam-Experience-Id
Host-ID
Lang
Memcached
Meta-Geo-Continent
Ngx.Var.Host
Xc-Version
MD5-Digest
Release
Candidate-Md5Url
Origin
NM-Fastcgi-Cache
Odigeo-Trace-Id
Rendered-Blocks
X-Auto-Login
X-Gdpr
X-External-Request-Id
X-Generated-On
X-Hash
X-INCAP-ABP
X-Sigma
X-Epic-Correlation-Id
X-Sigma-Backend
X-Developer
X-Destination
X-Ec-Fail
X-Ec-GeoHdr
X-SRCache-Key
X-ScT
X-Level-Front-Cache
X-Origin-Time
X-Origin
X-S
X-Processor
X-Rocket-Build-Number
X-S-Cookie
X-Nyt-Route
X-Men
X-Scale
X-S-Maxage
X-Mid
X-Mobile-URL
X-D
X-CUA
X-Test
X-A
X-A-Ccd
X-A-Dam
X-A-Wwc
X-A-Dcw
WWW-Authenticate
X-Thanos
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
X-TIM-N
Thinkindot-Control
X-Thinkindot-L3
X-Aed
X-Application
X-Cache-NE
X-Cache-Info
X-CMSURLCustom
X-Conf
X-Core-Mission
X-Bip
X-SVT-ORM-RULES
X-B-Cookie
X-Rojux
X-Bc-Bl
X-BCube-Filmed-By
X-SVT-ORM-VERSION
TDXMobile
X-A-Dgt
X-Service
Server-Info
HostName
X-Httpd
X-Via-CDN
X-Varnish-Beresp-Ttl
X-Response-By
X-Req
We-Hiring
Tube-Return
Tube-Got-Eval
Tube-Got-Results
Gh-Request-Id
X-Accel-Expires-Debug
X-Platform-Router
X-Platform-Processor
X-Pool
X-Akamai-Device-Characteristics
X-Region-Sid
Tube-Get-Contents
X-SD-PageType
X-Varnishpool
Mail-Subject
Origin-EX
X-Var-Ttl
Origin-CC
X-Sn-Servicetimems
Req-Svc-Chain
Locid
X-Server-IP
X-BBC-Edge-Cache-Status
Srvid
X-Slack-Shared-Secret-Outcome
On-Server
X-Platform
X-Fastly-Cache
X-Loc
X-Fastly-Backend
X-Esi-Check
X-Ec-Custom-Error
X-Mvc-Supplant-Cachable
X-FL-EDGE
X-FL-QIT-DEBUG
X-Geo-Header
X-Gzip
X-HS-Content-Campaign-Id
X-Human
X-Gamma-Serve
X-Instance-Name
X-Dispatcher-Server
X-Dispatcher-Number
X-Origin-Response-Time
X-Org
X-Cache-Id
X-Cache-Date
Fastly-GeoIP-CountryCode
X-Cache-Bucket
X-CacheTTL
X-Cdn-Origin
X-Date
X-Developers
X-Nginx-Cache-Key
X-Node-Id
X-Cdn-Srv
X-Platform-Cluster
X-Slack-Backend
Country-Code
CacheControlHeader
Cache-Key
Edge-Cache
Cmstype
Cmsid
Click-Count-Action-Start
Click-Count-Error
Magicmarker
CloudFront-Viewer-Country
AKAMAI
Fastly-Backend-Name
X-WP-CF-Super-Cache-Active
X-Via-Edge
Section-Origin-Responded
Environment
Edge-Copy-Time
X-Via-SSL
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
Section-Io-Id
X-DefHash
Wxu-Next-Commit
Wxu-Next-Hostname
X-VC
Wxu-Next-Region
Adler-Geo
Web-Mar-Region
X-HN
X-Device-Os
X-Op-Id-All
X-Owner
User-Cache-Control
Vix-Hermes-Req-Id
Canary
X-Planisys-CDN-Cache
X-Cache-FS-Status
X-Origin-Expires
X-Irp-Debug
Apple-News-Services-Request-Url
X-Azure-Ref-OriginShield
X-NodeID
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
X-Block-Status
Apple-News-Services-Handled
PFcat
X-Core-Value
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Hnp-Log
X-Ad-Defer-Variation
X-NCache
X-Gen-Mode
L
X-DefElseHash
X-GeoIP
X-Frame-Option
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
X-Variation
X-WADP-Cache
X-Worker
X-Forwarded-Site
X-JWT-State
X-WA-Info
Machine
X-GeoIP-Region-Code
X-Is-Gdpr
X-Vmg-Version
X-GeoIP-Country-Code
Expect-Staple
X-VServer
Kp-EeAlive
Is-Eu
Cache-Provider
X-V-Cache
X-Has-Esi
State
Ssr
Sever-Int
X-Minions-Version
X-Clara-WADP
X-SB
X-Ckpd-Fst-Backend
X-Mly-Id
Datacenter
Server-Hostname
X-FC-Vary-Parameters
X-GeoIP-City
Platform
X-VarnishDD-TTL
Server-Ext
X-Fmm-Version
X-Zone
X-TNCMS
X-Eu-Site
X-Csrf-Jwt
X-DPWN-IS-SECURE
X-From
X-Microcachable
X-RCS-CacheZone
X-Old-Content-Length
X-Release
Ha-Gx-Prefs
NGX
X-Accel-Buffering
L5d-Success-Class
X-VG-TLSProxy
X-Ua-Device
X-CGP
HA-Ipaddr
X-Qloud-Router
X-Aicache-OS
Producers
X-Vcl-Version
X-Cache-Remote
X-Wix-Viewer-Type
X-App
CDCHOST
X-Cache-Tags
X-Air-Pt
X-CACHE-AGE
X-Lambda-Id
Fastly-SSL
X-VCT
X-LB-NoCache
X-Debug-Cache-Store
X-Request-Start
X-Platform-Server
X-Cache-Enabled
X-Mvc-Supplant-OutputCached
X-Nananana
X-Debug-Cache-Fetch
X-Varnish-Beresp-Status
X-Parent-Response-Time
X-B3-SpanId
X-DC
X-Up
Pics-Label
X-Vtex-Remote-Cache
X-Render-Time
VNS-Cache
VNS-Age
CPC-Cache
X-Upstream-Ct
X-Via-Popv
X-Tb-Optimization-Total-Bytes-Saved
X-Via-Poph
CPC-Age
X-AIR-PT
X-Refresh
X-Generated-In
X-Upstream-Ht
X-Via-Popn
X-B3-Spanid
X-Dc
X-Trace-ID
X-Cs
X-HA-Backend
Env
X-Cache-Backend
GeoIP-Latitude
X-Cached-By
AMP-Access-Control-Allow-Source-Origin
SID
X-Cache-Type
Memory
X-CCDN-CacheTTL
Decoy-Debug-Status
X-ND-Cache
X-CCDN-Origin-Time
Decoy-Debug-Key
X-TH-Server
Time
Cache
Sid
X-Hcs-Proxy-Type
Cluster
Decoy-Debug-TTL
NtCoent-Length
X-Webkit-CSP
X-Servedbyhost
X-ATG-Version
X-Correlation-ID
X-LB-ID
X-Tid
X-Nf-Request-Id
X-Esi
X-Srv
X-Wa
X-Nc
X-Edge-Pop
Server-ID
X-HS-Status
X-Presslabs-Stats
Cdn
X-NWS-UUID-VERIFY
Srv
X-Varnish-Authentication
X-NewRelic-App-Data
X-Cache-ASPX
X-Contensis-Viewer-Groups
X-DataCenter
X-Client-Ip
X-Via-JSL
X-MP-GENERATED-AT
X-Vgn-Hpd-Variations-Key
X-CF-Lambda-Version
X-Vgn-Hpd-Ssi
Fastly-Drupal-Html
X-Vgn-Hpd-Cached
X-RateLimit-Remaining-Second
Svr
X-RateLimit-Limit-Second
X-CF-Lambda-Fn
Esi-Enabled
X-PAYTM-SRV-ID
X-Amz-Meta-Cb-Modifiedtime
Uri
GeoIp-Country-Code
X-Fpc
X-Proxy-CacheRZ
XkeyRZ
X-ZONE
X-Datadome
YJS-ID
X-Check-Cacheable
N-Cache
X-Wikidot-Static-Cache
Lb
X-Wikidot-Backend
X-Udemy-Cache-App-Namespace
X-Vc
True-Client-Ip
Resin-Trace
True-Client-IP
X-CACHE-KEY
M-TraceId
X-Bl-Debug
RNT-Machine
RNT-Time
X-Forwarded-Path
X-Tenant
X-CDN-Cache-Status
X-Shop-Environment
X-Orig-Expires
X-CS
X-NGINX-Cache
Hostname
X-EC-Lua
X-CSRF-TOKEN
X-Policy
X-B3-Trace-ID
X-Gateway-Skip-Cache
Cdnsip
Cdncip
X-Via-NSCOPI
X-Varnish-Beresp-TTL
X-TX-ID
X-MSEdge-Flight
X-AK-Request-ID
X-Gateway-Cache-Status
OT-Force-Account-Verify
X-Fastly-Country-Code
X-MSEdge-Features
XServer
X-Gateway-Cache-Key
X-Gateway-Request-Id
X-App-Name
X-FPC
X-API-Version
X-Logging-Id
X-Service-Response-Time
Sm-Log-Id
GeoIP-Country-Code
Eomportal-Instance
X-Git-Commit
Path
X-Cache-Ttl
X-Container-Uri
X-Datacenter
X-VCL-Version
X-Vcache
CDN
Hit
X-CLOUD-TRACE-CONTEXT
X-Cdn-Diag
X-Accel-Version
Server-Id
X-Lb-Id
HIT
X-WA
X-SIPLIST1
Ngx-Var-Key
IsBot
X-Micro-Cache
X-MCACHE
X-APP-VERSION
X-Geo
LB
X-Cdn-Cache-Status
X-Cache-NGX
X-Request-URI
X-Ha-Backend
X-RateLimit-Reset
X-NC
X-Edge-POP
RATING
X-Info
X-Acquia-Purge-Cdn-Unconfigured
V-Age
X-SERVER-NAME
X-ServedByHost
Pramga
XM
X-Tncms
X-VG-WebCache
X-Rebelmouse-Surrogate-Control
X-Akamai-Pragma-Client-IP
X-Rebelmouse-Cache-Control
CDN-RequestPullCode
ENV
X-Snapshot-Date
X-Srcache-Store-Status
X-Srcache-Fetch-Status
FSS-Cache
X-Clientip
Timeexpire
CDN-RequestPullSuccess
Geoip-Latitude
X-Cdn-Forward
X-TT-LOGID
Tcn
X-ID
Yjs-Id
X-Via-PopH
X-Via-PopN
Epwk-X-Cache
X-Ctl-Mach
Location
X-Via-PopV
Req-ID
Cross-Origin-Opener-Policy-Report-Only
True-Client-Country-4JS
X-TimeS
X-Wp-Cf-Super-Cache
X-Wp-Cf-Super-Cache-Cache-Control
X-Iauth-Set-Uid
X-HostName
X-Pod-Name
X-Hyper-Cache
Proxy-Connection
X-Amz-Meta-Opti
Ohc-File-Size
X-Serial
X-Lb-Nocache
X-Dw-Trace-Id
W
X-M-Reqid
X-LiteSpeed-Tag
X-LiteSpeed-Cache-Control
Warning
X-M-Log
X-Viewer-Country
X-RAMCache
X-Acquia-Site
X-Vgn-Hpd-Reason
X-Acquia-Purge-Tags
X-User
X-UP
X-Cdn-Request-ID
X-Litespeed-Cache-Control
WZWS-RAY
Content-Style-Type
Content-Script-Type
Cneonction
X-Acquia-Application-UUID
X-Fastly-Backend-Reqs
Cdn-Requestid
X-Acquia-Application-Trace
Servername
X-Qnm-Cache
Serverid
X-UA
X-Lsadc-Cache
CountryCode
X-MiniProfiler-Ids
X-Moov-Xdn-Version
X-Akamai-ERRuleID
X-Akamai-ERPolicy
X-WP-CF-Super-Cache-Cookies-Bypass
X-Oss-Request-Id
X-Oss-Object-Type
X-Moov-T
PICS-Label
X-Oss-Hash-Crc64ecma
X-PERF
Inserted-Into-Cache-At
X-IPS-Cached-Response
X-ApacheServer
Ohc-Cache-HIT
X-B3-Parentspanid
My-App
Ngx
X-Th-Server
X-Webstats-RespID
MIME-Version
X-Mg-Cache
X-Cache-Expires
X-Oss-Storage-Class
X-B3-ParentSpanId
Ec-Rule-Version
X-Fastly-Cache-Hits
X-Oss-Server-Time