Threat Level: green Handler on Duty: Daniel Wesemann

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
X-XSS-Protection
Accept-Ranges
Expect-CT
Pragma
X-Powered-By
CF-RAY
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
P3P
X-Cache-Hits
X-UA-Compatible
X-Served-By
CF-Ray
X-Xss-Protection
X-Download-Options
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Request-Id
Access-Control-Allow-Credentials
X-FRAME-OPTIONS
X-Permitted-Cross-Domain-Policies
X-Request-ID
X-AspNet-Version
Alt-Svc
X-Runtime
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Generator
X-Cache-Status
X-Check
X-Cacheable
Timing-Allow-Origin
X-Envoy-Upstream-Service-Time
X-Iinfo
X-Content-Security-Policy
X-Drupal-Dynamic-Cache
Feature-Policy
Content-Encoding
Access-Control-Expose-Headers
Upgrade
Status
X-AspNetMvc-Version
X-CDN
Access-Control-Max-Age
X-Dns-Prefetch-Control
X-Via
Server-Timing
Request-Context
X-Robots-Tag
X-Turbo-Charged-By
X-Amz-Request-Id
X-UA-Device
X-Cache-Group
X-Amz-Id-2
EagleId
X-Backend
X-AH-Environment
X-Proxy-Cache
Keep-Alive
X-Server
X-Ws-Request-Id
X-Age
Cf-Edge-Cache
Host-Header
X-Hacker
X-Vhost
X-Server-Powered-By
X-Rq
X-Varnish-Cache
X-Dispatcher
X-Amz-Version-Id
Grace
Allow
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-OneAgent-JS-Injection
P3p
X-Ua-Compatible
X-LiteSpeed-Cache
X-Page-Speed
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
Cf-Apo-Via
X-Device
Cf-Railgun
X-WebKit-CSP
Accept-CH
X-Aws-Lambda-Call-Status
X-Node
X-Pingback
EagleEye-TraceId
X-Host
X-Server-Id
X-Ruxit-JS-Agent
Surrogate-Control
X-Nginx-Cache-Status
X-Akam-SW-Version
X-Readtime
Request-Id
X-Backend-Server
Accept-Ch-Lifetime
X-Content-Security-Policy-Report-Only
X-HW
X-Cache-Lookup
X-Litespeed-Cache
X-Cloud-Trace-Context
X-Cache-Spec
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Response-Time
X-Trace
X-Application-Context
Permissions-Policy
X-Nginx-Upstream-Cache-Status
Fastly-Restarts
X-Edge
X-Mod-Pagespeed
X-WebKit-CSP-Report-Only
X-Country
X-Mcache
Content-Location
X-MS-InvokeApp
X-Content-Type
X-Url
X-Clacks-Overhead
X-PC
X-Vname
X-TtlSet
X-Midtier
X-Amz-Server-Side-Encryption
X-CST
Rating
RTSS
Accept-CH-Lifetime
X-ECACHE
Cache-Tag
X-ESI
X-Vcap-Request-Id
X-Rack-Cache
X-D2id
X-Element-Page-Cache
Verso
X-Kinja
X-Exp-Variant
X-Cdn-Fetch
X-Exp-Id
X-GoogleNews-Bot
X-Kinja-Build
X-Use-Magma
X-Kinja-Server
X-Kinja-Revision
Origin-Trial
X-Server-Name
X-VARITI-CCR
X-GitHub-Request-Id
Service-Worker-Allowed
X-Ac
X-Powered-By-Plesk
X-Amz-Rid
X-Cnection
SPRequestGuid
X-SharePointHealthScore
X-Client-IP
X-Navigation-Version
Xkey
Edge-Control
X-Upstream
SPIisLatency
SPRequestDuration
X-Abt-Application-Version
X-Cache-TTL
Arr-Disable-Session-Affinity
X-Ttl
X-Cached
X-Varnish-TTL
X-Dw-Request-Base-Id
X-Mg-S
X-Webkit-Csp
X-Server-Lifecycle-Phase
X-Erf-Bev-Bev
X-Kraken-Loop-Name
X-Instrumentation
X-Erf-Bev-Bev-Is-Generated
X-Browser-Type
X-NWS-LOG-UUID
X-B3-TraceId
X-Px
Accept-Ch
X-Sol
Display
Pagespeed
X-Middleton-Display
X-Correlation-Id
X-SRCache-Fetch-Status
X-SRCache-Store-Status
Edge-Cache-Tag
Access-Control-Request-Method
X-Forwarded-For
X-Cache-Key
X-NF-Request-ID
X-Country-Code
X-Goog-Hash
X-Ser
X-Powered-CMS
X-FastCGI-Cache
AR-Request-ID
AR-ATIME
AR-CACHE
AR-PoweredBy
AR-SID
Content-MD5
Front-End-Https
Public-Key-Pins
TCN
X-Id
X-Version
X-Amzn-Trace-Id
X-HP-Trace-Id
X-Jurisdiction
X-HP-Webp
X-MSEdge-Ref
X-Recruiting
X-Content-Digest
X-T
X-Middleton-Response
Response
X-Ratelimit-Limit
X-Accel-Expires
X-Fastcgi-Cache
TP-Cache
TP-L2-Cache
X-RateLimit-Remaining
X-Shield-Request-Id
MicrosoftSharePointTeamServices
X-XRDS-Location
X-Fastly-Request-ID
S
Cache-Status
Nginx-Cache
X-HS-Content-Id
X-HS-Combine-CSS
X-HS-Hub-Id
Cross-Origin-Opener-Policy
X-HS-Cache-Config
X-Request-Received
X-Request-Processing-Time
Cache-Tags
Server-Node
X-Ratelimit-Remaining
Mrf-Cache-Status
MRF-Tech
X-B3-TraceId-Primal
X-Daa-Tunnel
X-Distributor
X-Hits
X-PressLabs-Stats
X-Edge-Location-Klb
X-LB-Cache
X-Kinsta-Cache
X-Origin-Server
X-Ua-Browser
X-Ezoic-Cdn
X-TEC-API-ORIGIN
Filterid
X-Ratelimit-Reset
Fastcgi-Cache
X-TEC-API-VERSION
X-TEC-API-ROOT
Alternate-Protocol
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-LLID
X-Frontend
X-Hostname
X-Microsite
X-Request-Handler-Origin-Region
Realpath
X-Grace
X-Rid
Healthy
X-DIS-Request-ID
X-Logged-In
X-Varnish-Backend
Cleartype
X-TTL
X-Git-Hash
Server-Name
X-FB-Debug
X-NGENIX-Cache
X-Cluster-Name
X-Www-Served-By
X-Geo-Country
X-Page-Id
Payment
X-Debug-Info
MS-Author-Via
X-Forwarded-Proto
DC
X-Load-Cache
X-Protected-By
X-Origin-Cache
Access-Control-Allow-Method
Content-Disposition
X-B3-Traceid
X-B3-Sampled
X-Kong-Proxy-Latency
X-Upgrade-Enabled
X-Goog-Metageneration
X-GUploader-UploadID
X-Kong-Upstream-Latency
Charset
X-Proxy
X-AppVersion
X-Az
X-Activity-Id
X-Seen-By
X-DataDome
X-Times
Count-Hit
X-Cache-Age
X-Amz-Meta-S3cmd-Attrs
X-B
X-Azure-Ref
X-Amz-Replication-Status
X-Fb-Rlafr
X-F-Cache
X-Whom
Paypal-Debug-Id
Surrogate-Key
X-Revision
X-Akamai-Edgescape
X-Type
Accept-Charset
Cross-Origin-Resource-Policy
X-Contextid
Viewport
X-Varnish-Server
X-App-Environment
X-Aspnet-Duration-Ms
X-Is-Crawler
X-Route-Name
X-Request-Guid
X-Flags
X-Providence-Cookie
Retry-After
X-Wix-Request-Id
X-TT
X-Hosted-By
X-Language
X-Envoy-Decorator-Operation
X-DynaTrace
X-Cache-Control
X-ECache
X-B-Cache
X-Signature
X-Oracle-Dms-Ecid
X-Oracle-Dms-Rid
X-Magnolia-Registration
X-Varnish-Grace
X-Source
X-Mobile
X-App-Server
Amp-Access-Control-Allow-Source-Origin
X-Goog-Storage-Class
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
Version
Host
WPO-Cache-Message
WPO-Cache-Status
X-VCache
X-Server-ID
X-Amzn-RequestId
Refresh
X-Amz-Apigw-Id
X-N
X-HTML-Minification-Powered-By
X-Cache-Rule
X-EdgeConnect-Cache-Status
X-Varnish-Age
X-Tumblr-Pixel
Referer-Policy
Access-Control-Request-Headers
X-Response-Served-From
X-Cache-Time
X-Original-Request-Id
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-Tumblr-User
X-Rule
Ms-Operation-Id
X-Content-Powered-By
X-Cacheable-TTL
MS-CV
X-Region
X-Framework
X-Environment-Context
Protected
X-UUID
X-G
SD-X-WS
X-User-Agent
X-Jobs
X-L-Path
X-Oneagent-Js-Injection
X-RTag
X-FW-Dynamic
X-Cache-Grace
X-Backend-Name
X-FW-Version
X-FW-Hash
X-RemovedCookies
X-Tt-Trace-Host
X-Tt-Trace-Tag
GEO-INFO
Akamai-GRN
X-ProcessESI
X-Status
X-FW-Serve
X-FW-Server
X-FW-Type
X-FW-Static
Front
VIX-Pulpo-Node
From-Origin
NGB
VIX-Pulpo-Upstream-Status
X-Akamai-Request-ID2
X-Http-Reason
X-Trace-Id
X-Rendered-As
Section-Io-Cache
X-Device-Type
X-Is-Bot
X-Instance
X-NYM-Debug-Backend
X-Cache-Status-Check
X-Page-View
X-Cache-Expired-At
X-Drupal-Cache-Tags
X-Adobe-Content
X-Drupal-Cache-Contexts
X-Adobe-Loc
CDN-RequestId
X-RateLimit-Limit
X-Unique-Id
X-Nginx-Cache
X-XRDS-LOCATION
X-Pinterest-Rid
Url
Pinterest-Version
Pinterest-Generated-By
Liferay-Portal
X-Servername
X-Time
X-Varnish-Ttl
Accept-Language
X-Content-Options
X-CDN-Forward
X-Template
Fastly-SIE
SRV
Fastly-SWR
X-Air-Trace-Id
X-Newrelic-App-Data
X-Air-Source
X-Zen-Fury
X-Air-Hostname
X-Debug-IsPreview
Backend
X-Debug-IsConnected
X-Cache-Hit
X-Mode
X-DynaTrace-JS-Agent
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Uri
Country
X-Rocket-Nginx-Serving-Static
X-COUNTRY
X-App-Version
Content-Secure-Policy
X-ARC
X-Edge-Location
X-Fastly-Request-Id
X-Cache-Operation
Node
X-Tumblr-Pixel-2
X-Cache-Server
S-Rt
X-Generation-Time
X-Proxied
X-Zipkin-Id
X-Extlb
Webserver
Onion-Location
X-Routing-Service
X-RN-RSRV
X-Rewrite-Enabled
X-UPSTREAM-Address
Filters
Meta-Geo
X-Tumblr-Pixel-3
X-Amzn-Remapped-Content-Length
X-Proxy-Cache-Info
Uber-Trace-Id
X-Server-W
Azure-SlotName
Countrycode
Azure-Version
Cache-Hits
X-Proxy-Build
Azure-SiteName
Azure-InstanceId
X-PHP-Backend
Azure-RegionName
X-Locale
CF-IPCountry
X-Content-Age
X-Timing-Wait
X-IPS-LoggedIn
Selected-Fe
Property-Id
Mn-Server-Ip
TWC-Device-Class
Cache-Name
TWC-GeoIP-LatLong
TWC-GeoIP-Country
TWC-Connection-Speed
TWC-Locale-Group
X-Web-Node
WP-Super-Cache
X-ProxyCache-Status
X-Reqid
X-Ms-Version
X-Section
X-Ms-Request-Id
X-ProxyCache-Key
X-Origin-Hint
X-BYPASS-REASON
X-AWS-Id
X-Cache-Action
X-Cms-Context
X-Proxy-Cache-Status
X-Site-Version
X-Skip-Cache
X-Via-Fastly
Webcakes-Region
X-LJ-Flow-ID
X-UA-Device-Type
X-Cluster-Node
Webcakes-App-Version
X-VWS-Id
X-Format
X-Sucuri-Cache
X-Soup
X-Sucuri-ID
X-Tb
X-Access
TWC-Privacy
Webcakes-App-Name
X-Labrador-Cache-Channel
Web-Mar-Node
X-Say-Cacheable
X-Say-TTL
Cache-Tv-Group
X-Origin-Date
X-IPLB-Request-ID
X-IPLB-Instance
X-Cluster
X-PHP-Host
X-Debug
X-SayCDN-TTL
X-Proto
X-Forwarded-Host
X-Cache-Host
DB-Nickname
X-LAGOON
X-Detected-As
X-Cache-TTL-Remaining
X-JoinUs
Cross-Origin-Window-Policy
X-No-Session
X-Optimistic-Header
X-R9-Blue-Green-Version
X-SaId
X-Xfnlog-Site
Locale
X-Urbn-Context-Path
X-Urbn-Site-Id
X-Ruxit-Js-Agent
Apigw-Requestid
X-Sql-Duration-Ms
X-VC-Cache
X-Sql-Count
X-Director
X-Adobe-Source
X-Ua
X-Varnish-Beresp-Grace
X-Handled-By
X-FB-TRIP-ID
X-LSADC-Cache
X-Real-IP
ServedBy
ServerID
X-Tec-Api-Version
Fastcgi-Useragent
X-Tec-Api-Origin
X-Tec-Api-Root
Frame-Options
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
X-Node-Name
X-GeoCode
X-GeoCountry
X-Varnish-Hits
Mime-Version
X-Tt-Logid
Upgrade-Insecure-Requests
Fastly-Drupal-HTML
Source
X-Api-Version
Load-Balancing
X-Aspnetmvc-Version
CDN-PullZone
X-Hl-Ver
CDN-Cache
X-Generated-By
CDN-Uid
X-Varnish-Cache-Hits
CDN-EdgeStorageId
CDN-CachedAt
CDN-RequestCountryCode
X-Buckets
X-GEO
X-Request-Time
X-FireWall-Port
X-Varnish-Hostname
Xet-Cookie
X-ServerID
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
X-Webkit-CSP-Report-Only
X-RM-Cache-TTL
X-Datadog-Sampled
X-Origin-TTL
X-URL
X-Origin-CC
X-Redis-Cache
X-Mg-Request-UUID
X-Cache-Debug
X-Akamai-Transformed
X-SRV
X-TA-CDN-Provider
X-TIME
CF-Cached-On
X-Loop
Xserver
X-Served-From
X-Provided-By
X-Storage
X-Pubstack
X-Sorting-Hat-PodId
X-ShardId
X-Shopify-Stage
X-Storefront-Renderer-Rendered
X-Tx-Id
X-Sorting-Hat-ShopId
X-Alternate-Cache-Key
X-ShopId
X-Restarts
X-Endurance-Cache-Level
X-Newrelic-Synthetics
X-Pass-Why
X-CSRF-Token
X-Request-Host
X-Location
Sslversion
X-We-Are-Hiring
X-Fetched-On
T-Server
C-Via
BehaviorPad-Version
X-Vdms-Path
A
Server-Host
X-Vdms-Version
Surrogated-Key
Cache-Host
Redirect-Candidate
DSUID
DCR-Processing-Time-Ms
DCR-Decision-By
Gannett-Cam-Experience-Id
Host-ID
Lang
Memcached
Meta-Geo-Continent
Ngx.Var.Host
Xc-Version
MD5-Digest
Release
Candidate-Md5Url
Origin
NM-Fastcgi-Cache
Odigeo-Trace-Id
Rendered-Blocks
X-Auto-Login
X-Gdpr
X-External-Request-Id
X-Generated-On
X-Hash
X-INCAP-ABP
X-Sigma
X-Epic-Correlation-Id
X-Sigma-Backend
X-Developer
X-Destination
X-Ec-Fail
X-Ec-GeoHdr
X-SRCache-Key
X-ScT
X-Level-Front-Cache
X-Origin-Time
X-Origin
X-S
X-Processor
X-Rocket-Build-Number
X-S-Cookie
X-Nyt-Route
X-Men
X-Scale
X-S-Maxage
X-Mid
X-Mobile-URL
X-D
X-CUA
X-Test
X-A
X-A-Ccd
X-A-Dam
X-A-Wwc
X-A-Dcw
WWW-Authenticate
X-Thanos
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
X-TIM-N
Thinkindot-Control
X-Thinkindot-L3
X-Aed
X-Application
X-Cache-NE
X-Cache-Info
X-CMSURLCustom
X-Conf
X-Core-Mission
X-Bip
X-SVT-ORM-RULES
X-B-Cookie
X-Rojux
X-Bc-Bl
X-BCube-Filmed-By
X-SVT-ORM-VERSION
TDXMobile
X-A-Dgt
X-Service
Server-Info
HostName
X-Httpd
X-Via-CDN
X-Varnish-Beresp-Ttl
X-Response-By
X-Req
We-Hiring
Tube-Return
Tube-Got-Eval
Tube-Got-Results
Gh-Request-Id
X-Accel-Expires-Debug
X-Platform-Router
X-Platform-Processor
X-Pool
X-Akamai-Device-Characteristics
X-Region-Sid
Tube-Get-Contents
X-SD-PageType
X-Varnishpool
Mail-Subject
Origin-EX
X-Var-Ttl
Origin-CC
X-Sn-Servicetimems
Req-Svc-Chain
Locid
X-Server-IP
X-BBC-Edge-Cache-Status
Srvid
X-Slack-Shared-Secret-Outcome
On-Server
X-Platform
X-Fastly-Cache
X-Loc
X-Fastly-Backend
X-Esi-Check
X-Ec-Custom-Error
X-Mvc-Supplant-Cachable
X-FL-EDGE
X-FL-QIT-DEBUG
X-Geo-Header
X-Gzip
X-HS-Content-Campaign-Id
X-Human
X-Gamma-Serve
X-Instance-Name
X-Dispatcher-Server
X-Dispatcher-Number
X-Origin-Response-Time
X-Org
X-Cache-Id
X-Cache-Date
Fastly-GeoIP-CountryCode
X-Cache-Bucket
X-CacheTTL
X-Cdn-Origin
X-Date
X-Developers
X-Nginx-Cache-Key
X-Node-Id
X-Cdn-Srv
X-Platform-Cluster
X-Slack-Backend
Country-Code
CacheControlHeader
Cache-Key
Edge-Cache
Cmstype
Cmsid
Click-Count-Action-Start
Click-Count-Error
Magicmarker
CloudFront-Viewer-Country
AKAMAI
Fastly-Backend-Name
X-WP-CF-Super-Cache-Active
X-Via-Edge
Section-Origin-Responded
Environment
Edge-Copy-Time
X-Via-SSL
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
Section-Io-Id
X-DefHash
Wxu-Next-Commit
Wxu-Next-Hostname
X-VC
Wxu-Next-Region
Adler-Geo
Web-Mar-Region
X-HN
X-Device-Os
X-Op-Id-All
X-Owner
User-Cache-Control
Vix-Hermes-Req-Id
Canary
X-Planisys-CDN-Cache
X-Cache-FS-Status
X-Origin-Expires
X-Irp-Debug
Apple-News-Services-Request-Url
X-Azure-Ref-OriginShield
X-NodeID
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
X-Block-Status
Apple-News-Services-Handled
PFcat
X-Core-Value
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Hnp-Log
X-Ad-Defer-Variation
X-NCache
X-Gen-Mode
L
X-DefElseHash
X-GeoIP
X-Frame-Option
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
X-Variation
X-WADP-Cache
X-Worker
X-Forwarded-Site
X-JWT-State
X-WA-Info
Machine
X-GeoIP-Region-Code
X-Is-Gdpr
X-Vmg-Version
X-GeoIP-Country-Code
Expect-Staple
X-VServer
Kp-EeAlive
Is-Eu
Cache-Provider
X-V-Cache
X-Has-Esi
State
Ssr
Sever-Int
X-Minions-Version
X-Clara-WADP
X-SB
X-Ckpd-Fst-Backend
X-Mly-Id
Datacenter
Server-Hostname
X-FC-Vary-Parameters
X-GeoIP-City
Platform
X-VarnishDD-TTL
Server-Ext
X-Fmm-Version
X-Zone
X-TNCMS
X-Eu-Site
X-Csrf-Jwt
X-DPWN-IS-SECURE
X-From
X-Microcachable
X-RCS-CacheZone
X-Old-Content-Length
X-Release
Ha-Gx-Prefs
NGX
X-Accel-Buffering
L5d-Success-Class
X-VG-TLSProxy
X-Ua-Device
X-CGP
HA-Ipaddr
X-Qloud-Router
X-Aicache-OS
Producers
X-Vcl-Version
X-Cache-Remote
X-Wix-Viewer-Type
X-App
CDCHOST
X-Cache-Tags
X-Air-Pt
X-CACHE-AGE
X-Lambda-Id
Fastly-SSL
X-VCT
X-LB-NoCache
X-Debug-Cache-Store
X-Request-Start
X-Platform-Server
X-Cache-Enabled
X-Mvc-Supplant-OutputCached
X-Nananana
X-Debug-Cache-Fetch
X-Varnish-Beresp-Status
X-Parent-Response-Time
X-B3-SpanId
X-DC
X-Up
Pics-Label
X-Vtex-Remote-Cache
X-Render-Time
VNS-Cache
VNS-Age
CPC-Cache
X-Upstream-Ct
X-Via-Popv
X-Tb-Optimization-Total-Bytes-Saved
X-Via-Poph
CPC-Age
X-AIR-PT
X-Refresh
X-Generated-In
X-Upstream-Ht
X-Via-Popn
X-B3-Spanid
X-Dc
X-Trace-ID
X-Cs
X-Cache-Backend
X-HA-Backend
X-Cached-By
GeoIP-Latitude
AMP-Access-Control-Allow-Source-Origin
Env
X-Cache-Type
SID
Decoy-Debug-Key
X-CCDN-CacheTTL
Decoy-Debug-Status
X-CCDN-Origin-Time
Cluster
X-TH-Server
X-Hcs-Proxy-Type
Time
Decoy-Debug-TTL
X-ND-Cache
Sid
Memory
Cache
NtCoent-Length
X-Webkit-CSP
X-LB-ID
X-ATG-Version
X-Servedbyhost
X-Correlation-ID
X-Tid
X-Nf-Request-Id
X-Esi
X-Srv
X-Wa
X-Nc
X-Presslabs-Stats
X-Edge-Pop
Server-ID
X-HS-Status
Srv
Cdn
X-NWS-UUID-VERIFY
X-Contensis-Viewer-Groups
X-Varnish-Authentication
X-Cache-ASPX
X-NewRelic-App-Data
X-DataCenter
X-Client-Ip
X-Via-JSL
X-MP-GENERATED-AT
Esi-Enabled
X-CF-Lambda-Version
Svr
Fastly-Drupal-Html
X-Vgn-Hpd-Variations-Key
X-Vgn-Hpd-Ssi
X-Vgn-Hpd-Cached
X-CF-Lambda-Fn
X-PAYTM-SRV-ID
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
Uri
X-Fpc
X-Amz-Meta-Cb-Modifiedtime
GeoIp-Country-Code
YJS-ID
X-ZONE
X-Proxy-CacheRZ
X-Datadome
XkeyRZ
X-Check-Cacheable
X-Wikidot-Backend
X-Wikidot-Static-Cache
N-Cache
Lb
X-Udemy-Cache-App-Namespace
X-Vc
True-Client-Ip
Resin-Trace
True-Client-IP
X-CACHE-KEY
M-TraceId
X-Bl-Debug
RNT-Machine
RNT-Time
X-Forwarded-Path
X-Tenant
X-CDN-Cache-Status
X-Shop-Environment
X-Orig-Expires
Hostname
X-CS
X-NGINX-Cache
X-CSRF-TOKEN
X-EC-Lua
X-Gateway-Request-Id
X-B3-Trace-ID
Cdnsip
X-Gateway-Skip-Cache
Cdncip
X-Policy
X-Via-NSCOPI
X-Varnish-Beresp-TTL
X-MSEdge-Flight
X-AK-Request-ID
X-Fastly-Country-Code
OT-Force-Account-Verify
X-MSEdge-Features
X-App-Name
XServer
X-Gateway-Cache-Key
X-TX-ID
X-Gateway-Cache-Status
X-FPC
X-API-Version
X-Logging-Id
X-Service-Response-Time
Sm-Log-Id
GeoIP-Country-Code
Eomportal-Instance
X-Git-Commit
Path
X-Cache-Ttl
X-Container-Uri
X-Datacenter
X-VCL-Version
X-Vcache
CDN
X-CLOUD-TRACE-CONTEXT
Hit
X-Accel-Version
X-Cdn-Diag
Server-Id
X-Lb-Id
HIT
X-WA
X-Micro-Cache
IsBot
X-SIPLIST1
X-MCACHE
Ngx-Var-Key
X-APP-VERSION
X-Geo
LB
X-Cache-NGX
X-Ha-Backend
X-Request-URI
X-Edge-POP
X-RateLimit-Reset
X-NC
X-Cdn-Cache-Status
RATING
X-Info
Pramga
X-Acquia-Purge-Cdn-Unconfigured
X-SERVER-NAME
V-Age
X-ServedByHost
X-Tncms
XM
X-VG-WebCache
X-Akamai-Pragma-Client-IP
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-Clientip
Geoip-Latitude
Timeexpire
FSS-Cache
X-Snapshot-Date
ENV
CDN-RequestPullCode
CDN-RequestPullSuccess
X-Srcache-Store-Status
X-Cdn-Forward
X-Srcache-Fetch-Status
X-TT-LOGID
X-ID
Tcn
X-Via-PopN
Yjs-Id
Location
Cross-Origin-Opener-Policy-Report-Only
X-Via-PopH
X-Ctl-Mach
X-Via-PopV
Req-ID
True-Client-Country-4JS
Epwk-X-Cache
X-Iauth-Set-Uid
X-Wp-Cf-Super-Cache-Cache-Control
X-TimeS
X-Wp-Cf-Super-Cache
X-HostName
X-Amz-Meta-Opti
X-Lb-Nocache
X-Hyper-Cache
W
X-Serial
Ohc-File-Size
Proxy-Connection
X-Pod-Name
X-Dw-Trace-Id
X-LiteSpeed-Tag
X-LiteSpeed-Cache-Control
Warning
X-M-Log
X-M-Reqid
X-PERF
X-RAMCache
X-Viewer-Country
X-Vgn-Hpd-Reason
X-UP
X-Litespeed-Cache-Control
X-Acquia-Site
X-ApacheServer
X-User
X-Cdn-Request-ID
WZWS-RAY
Cneonction
Content-Style-Type
Content-Script-Type
Cdn-Requestid
Servername
X-Fastly-Backend-Reqs
X-Acquia-Purge-Tags
X-Qnm-Cache
X-Acquia-Application-UUID
X-Acquia-Application-Trace
CountryCode
X-Lsadc-Cache
X-UA
Serverid
X-MiniProfiler-Ids
X-Oss-Request-Id
X-Oss-Object-Type
X-Oss-Server-Time
X-Akamai-ERPolicy
X-Akamai-ERRuleID
X-Oss-Hash-Crc64ecma
X-IPS-Cached-Response
X-Moov-Xdn-Version
X-Moov-T
Inserted-Into-Cache-At
X-Webstats-RespID
X-WP-CF-Super-Cache-Cookies-Bypass
PICS-Label
X-Fastly-Cache-Hits
Ngx
X-B3-Parentspanid
X-Mg-Cache
MIME-Version
X-Th-Server
Ohc-Cache-HIT
My-App
X-Cache-Expires
X-B3-ParentSpanId
Ec-Rule-Version
X-Oss-Storage-Class