Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-Cache-Status
Link
Accept-Ranges
CF-RAY
ETag
X-XSS-Protection
Expect-CT
Pragma
X-Powered-By
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
Alt-Svc
X-Served-By
X-Xss-Protection
X-Download-Options
X-Timer
X-Request-Id
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Cache-Status
X-Check
X-Generator
X-Cacheable
Timing-Allow-Origin
X-FRAME-OPTIONS
X-Content-Security-Policy
X-Iinfo
Feature-Policy
Status
X-Envoy-Upstream-Service-Time
Content-Encoding
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
X-AspNetMvc-Version
X-CDN
P3p
X-Request-ID
Upgrade
X-Via
CF-Ray
X-Ws-Request-Id
Access-Control-Max-Age
Server-Timing
EagleId
X-Cache-Group
Report-To
X-Turbo-Charged-By
Keep-Alive
Request-Context
X-UA-Device
X-Age
X-Backend
X-Proxy-Cache
X-Server-Powered-By
X-AH-Environment
X-Robots-Tag
X-Hacker
X-Amz-Request-Id
X-Server
Host-Header
X-Amz-Id-2
Grace
X-LiteSpeed-Cache
X-Rq
X-Swift-CacheTime
X-Swift-SaveTime
X-Varnish-Cache
X-Nginx-Cache-Status
Ali-Swift-Global-Savetime
X-Dns-Prefetch-Control
NEL
X-WebKit-CSP
X-Page-Speed
X-Vhost
EagleEye-TraceId
X-Amz-Version-Id
X-Ua-Compatible
X-Pingback
X-OneAgent-JS-Injection
X-Dispatcher
X-Device
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Cache-Spec
X-Host
Accept-CH
X-Server-Id
Cf-Railgun
X-Node
X-Backend-Server
X-Readtime
Surrogate-Control
X-Akam-SW-Version
Request-Id
X-Response-Time
X-HW
Xkey
X-Application-Context
Content-Location
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Rating
X-B3-TraceId
X-Cloud-Trace-Context
Accept-Ch-Lifetime
Accept-CH-Lifetime
X-Country
X-Cache-Lookup
X-Ruxit-JS-Agent
X-Trace
X-Url
Allow
X-Ac
X-Content-Type
X-Vname
X-TtlSet
X-PC
X-Varnish-TTL
X-Clacks-Overhead
Edge-Control
X-Aws-Lambda-Call-Status
X-Mod-Pagespeed
X-Server-Name
X-ESI
Fastly-Restarts
Cache-Tag
Service-Worker-Allowed
X-VARITI-CCR
X-Rack-Cache
Verso
X-Element-Page-Cache
MS-Author-Via
X-Upstream
X-FastCGI-Cache
X-Vcap-Request-Id
X-MS-InvokeApp
X-Amz-Rid
X-GitHub-Request-Id
Public-Key-Pins
X-Dw-Request-Base-Id
X-Cached
X-Client-IP
X-Abt-Application-Version
X-D2id
X-Cache-TTL
X-Cnection
X-Px
RTSS
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
X-Navigation-Version
X-Exp-Id
X-Cdn-Fetch
X-Exp-Variant
X-Kinja-Build
X-Use-Magma
X-Kinja-Server
X-Kinja-Revision
X-GoogleNews-Bot
X-Kinja
Arr-Disable-Session-Affinity
X-Country-Code
Access-Control-Request-Method
X-Powered-By-Plesk
X-NF-Request-ID
X-Goog-Hash
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Instrumentation
X-Powered-CMS
AR-ATIME
AR-PoweredBy
AR-CACHE
AR-SID
AR-Request-ID
X-Sol
X-Middleton-Display
Pagespeed
Display
X-Version
X-Origin-Cache
Response
X-Middleton-Response
X-Amz-Server-Side-Encryption
X-LLID
X-MSEdge-Ref
X-Kinsta-Cache
Nginx-Cache
X-Edge-Location-Klb
X-TTL
TCN
X-RateLimit-Remaining
X-Edge
Mrf-Cache-Status
X-B3-TraceId-Primal
MRF-Tech
X-Protected-By
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-T
X-CST
X-Ruxit-Js-Agent
X-Jurisdiction
X-HP-Webp
X-HP-Trace-Id
X-Forwarded-For
X-Shield-Request-Id
X-Content-Security-Policy-Report-Only
X-Id
X-Mg-S
Content-MD5
S
Edge-Cache-Tag
X-Aspnetmvc-Version
Accept-Ch
X-Language
SPRequestDuration
SPIisLatency
Fastcgi-Cache
Front-End-Https
X-Mid
X-Webkit-Csp
Realpath
X-Request-Processing-Time
Server-Node
X-Request-Received
X-Recruiting
X-Ttl
X-DynaTrace
Pinterest-Version
Pinterest-Generated-By
Filters
X-Pinterest-Rid
X-Frontend
X-Ua-Browser
Server-Name
X-MCACHE
X-Ab
X-Content
X-Correlation-Id
X-Cache-Key
X-Ser
X-NWS-LOG-UUID
X-HS-Content-Id
X-HS-Hub-Id
X-HS-Cache-Config
X-Yandex-Sdch-Disable
X-HS-Combine-CSS
X-Ezoic-Cdn
X-ECACHE
X-Template
X-SharePointHealthScore
SPRequestGuid
X-Hits
X-Parallel-Accel
X-Tt-Trace-Host
MicrosoftSharePointTeamServices
X-Tt-Trace-Tag
Cache-Tags
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
Charset
X-Page-Id
Cleartype
X-B3-Sampled
Alternate-Protocol
Host
X-Git-Hash
X-Www-Served-By
Fusion-Content-Id
Fusion-Component-Id
X-Geo-Country
Fusion-Content-Source
Fusion-Deployment-Id
Fusion-Template-Id
Fusion-Source
X-Content-Options
X-Daa-Tunnel
X-Debug-Info
X-Hostname
X-DIS-Request-ID
X-Amzn-Trace-Id
X-Content-Digest
X-Ratelimit-Limit
X-Amz-Replication-Status
X-Varnish-Age
Filterid
Cross-Origin-Opener-Policy
X-Activity-Id
X-AppVersion
X-Az
X-FB-Debug
X-Accel-Expires
X-Grace
X-Upgrade-Enabled
X-VCache
X-Fastly-Request-Id
ServerID
X-WebKit-CSP-Report-Only
X-F-Cache
X-Forwarded-Proto
X-N
X-Nginx-Upstream-Cache-Status
X-Origin-Server
X-Rid
Access-Control-Allow-Method
X-Mobile-URL
X-Providence-Cookie
X-Route-Name
X-Aspnet-Duration-Ms
X-Flags
X-Is-Crawler
X-Request-Guid
X-LB-Cache
X-Type
X-XRDS-LOCATION
X-TT
X-Whom
TP-L2-Cache
TP-Cache
X-Seen-By
X-Varnish-Grace
X-Goog-Stored-Content-Length
Viewport
X-App-Environment
X-Goog-Metageneration
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-GUploader-UploadID
X-Goog-Generation
X-Tb
Payment
X-FW-Serve
Node
X-FW-Server
X-Distributor
X-FW-Static
X-FW-Hash
X-FW-Dynamic
X-FW-Type
DC
X-User-Agent
X-Fastcgi-Cache
X-Server-ID
Paypal-Debug-Id
X-DataDome
X-App-Server
X-Wix-Request-Id
Fastcgi-Useragent
Accept-Charset
Country
X-Tec-Api-Origin
X-Oneagent-Js-Injection
X-Tec-Api-Root
X-Tec-Api-Version
X-Fastly-Request-ID
X-Ratelimit-Reset
X-Cache-Control
X-Cache-Rule
X-NGENIX-Cache
X-Litespeed-Cache
X-Origin-Upstream-Status
X-Via-JSL
Version
X-Drupal-Cache-Tags
X-Request-Handler-Origin-Region
Referer-Policy
X-Microsite
X-Cluster-Name
X-Logged-In
X-Cache-Age
X-Contextid
X-Buckets
X-B-Cache
X-Signature
Cache-Status
Refresh
X-Node-Name
X-Browser-Type
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Original-Request-Id
X-Response-Served-From
VIX-Pulpo-Upstream-Status
X-Mobile
VIX-Pulpo-Node
X-Load-Cache
X-Varnish-Backend
SD-X-WS
Amp-Access-Control-Allow-Source-Origin
X-Cache-Expired-At
X-Rendered-As
X-Real-IP
X-Page-View
X-Is-Bot
X-Vgn-Hpd-Reason
X-Revision
X-B
X-Cacheable-TTL
X-Proxy-Cache-Status
X-IPLB-Instance
NGB
Access-Control-Request-Headers
X-Debug
X-Jobs
X-Rule
X-UUID
X-Cache-Action
X-Yottaa-Metrics
X-RemovedCookies
X-Proxy
X-Instance
X-Device-Type
X-ProcessESI
X-Yottaa-Optimizations
Surrogate-Key
Akamai-GRN
X-Drupal-Cache-Contexts
X-Cache-Time
X-Debug-IsConnected
X-Debug-IsPreview
X-Framework
X-FW-Version
X-G
CF-IPCountry
X-Air-Hostname
X-Air-Source
X-Air-Trace-Id
X-Accel-Buffering
X-Oracle-Dms-Rid
SID
DynaTrace
X-XRDS-Location
X-Oracle-Dms-Ecid
X-Presslabs-Stats
GEO-INFO
X-Cache-NGX
Count-Hit
X-Azure-Ref
Uber-Trace-Id
X-PressLabs-Stats
Liferay-Portal
X-Source
X-Ms-Version
X-Cache-Operation
X-Ms-Request-Id
X-Nginx-Cache
X-APP-VERSION
Frame-Options
X-Zen-Fury
MS-CV
X-CDN-Forward
X-EdgeConnect-Cache-Status
Ms-Operation-Id
X-RTag
Healthy
Protected
X-Cache-Hit
X-L-Path
X-Backend-Name
X-TEC-API-ROOT
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-Environment-Context
Xserver
X-Mode
Countrycode
X-Tumblr-Pixel
X-RateLimit-Limit
X-IPS-LoggedIn
Ec-Rule-Version
X-Varnish-Server
Cross-Origin-Window-Policy
X-Tumblr-User
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-Cache-TTL-Remaining
LB
X-Hyper-Cache
X-Adobe-Loc
Backend
X-Adobe-Content
Meta-Geo
X-JoinUs
X-Region
X-Servername
X-Content-Age
X-Detected-As
X-Forwarded-Host
WPO-Cache-Status
WPO-Cache-Message
X-Rewrite-Enabled
X-RN-RSRV
X-UPSTREAM-Address
X-Tid
X-SaId
X-Trace-Id
X-Uri
X-Hosted-By
Decoy-Debug-TTL
X-Alternate-Cache-Key
X-Cache-Server
X-Cache-Grace
X-Routing-Service
X-Extlb
X-Format
X-Sql-Duration-Ms
X-Debug-Cache
X-Zipkin-Id
X-Ratelimit-Remaining
X-Generation-Time
X-Sorting-Hat-ShopId
Apigw-Requestid
X-ShardId
X-Sql-Count
Eomportal-Instance
X-ShopId
X-Redis-Cache
X-Proxied
Decoy-Debug-Key
Decoy-Debug-Status
X-Shopify-Stage
X-Sorting-Hat-PodId
Content-Disposition
Country-Code
Cache-Name
X-ApacheServer
X-Varnish-Beresp-Grace
X-Access
Url
X-FB-TRIP-ID
Mn-Server-Ip
Fastly-SSL
X-Via-Fastly
X-PERF
X-Human
X-Status
X-Site-Version
X-ServerID
X-PHP-Backend
X-Content-Powered-By
Section-Io-Cache
X-Origin-Date
X-PCL
X-No-Session
X-Microcachable
X-Section
X-NCache
X-OCL
TWC-GeoIP-Country
TWC-Device-Class
CDN-Uid
TWC-Locale-Group
TWC-Connection-Speed
X-Pubstack
TWC-Privacy
Property-Id
X-Proxy-Build
X-Say-Cacheable
X-SayCDN-TTL
CDN-PullZone
X-ProxyCache-Key
Webcakes-App-Name
X-ProxyCache-Status
Selected-Fe
Webcakes-Region
CDN-RequestId
X-Cache-Host
X-BYPASS-REASON
X-Server-W
X-Cache-Type
X-UA-Device-Type
X-Cluster-Node
CDN-RequestCountryCode
CDN-CachedAt
X-Origin-Hint
X-Storage
X-Say-TTL
X-Timing-Wait
CDN-Cache
CDN-EdgeStorageId
X-NYM-Debug-Backend
X-Akamai-Edgescape
Webcakes-App-Version
TWC-GeoIP-LatLong
Cache-Tv-Group
X-Generated-By
X-Varnishpool
X-Hl-Ver
X-Soup
X-Web-Node
X-Be
X-R9-Blue-Green-Version
Azure-SiteName
Azure-SlotName
Azure-Version
Content-Secure-Policy
Azure-RegionName
Azure-InstanceId
X-TIME
X-Ua
X-LSADC-Cache
X-NewRelic-App-Data
DB-Nickname
Retry-After
X-Webkit-CSP
X-Nginx-Cache-Key
OT-Force-Account-Verify
X-Dc
X-Azure-Ref-OriginShield
X-Cached-By
X-Bc-Bl
Source
X-Cache-Remote
X-Unique-Id
Cache
X-Platform-Server
SRV
X-TT-LOGID
X-Akamai-Transformed
X-Auto-Login
X-LAGOON
X-Xfnlog-Site
X-EC-Lua
ServedBy
Upgrade-Insecure-Requests
X-GEO
X-SRV
X-Cache-Tags
Cache-Hits
X-Origin-CC
X-Varnish-Hits
X-Origin-TTL
X-HTML-Minification-Powered-By
X-Loop
X-Varnish-Cache-Hits
X-TNCMS
X-Varnish-Hostname
X-Cdn
From-Origin
X-S-Maxage
Onion-Location
Xet-Cookie
HostName
X-Request-Time
Mime-Version
X-AOL-HN
X-App-Version
X-NWS-UUID-VERIFY
Webserver
X-CSRF-Token
X-Request-Host
WP-Super-Cache
X-Tumblr-Pixel-2
X-Tumblr-Pixel-3
Web-Mar-Node
X-Amz-Meta-S3cmd-Attrs
X-Time
X-Proto
N-Cache
X-Cache-Enabled
X-B3-SpanId
X-Endurance-Cache-Level
X-FireWall-Port
X-ECache
X-Handled-By
X-Tenant
X-LJ-Flow-ID
X-VWS-Id
X-AWS-Id
X-GG-Cache-Date
X-Time-Microsecs
X-Origin-Response-Time
X-Shop-Environment
Vix-Hermes-Req-Id
X-Slack-Backend
X-Adobe-Source
X-Ckpd-Fst-Backend
X-SRCache-Key
X-Cluster
X-Connection-Hash
X-Epic-Correlation-Id
X-Reqid
Nel
X-External-Request-Id
X-Edge-Location
X-Developer
X-D
V-Age
X-Session-Fingerprint
X-Destination
X-Conf
X-CF-Lambda-Fn
X-Aed
Xc-Version
X-A-Ccd
X-Vdms-Version
X-A-Wwc
X-A-Dgt
X-Vtex-Processado-Em
X-A-Dcw
X-Vtex-Remote-Cache
X-VG-WebCache
X-Application
X-ARC
X-TIM-N
X-A
X-Cache-NE
X-A-Dam
X-Block-Status
X-Backend-TTL
X-Vdms-Path
X-V-Cache
X-B-Cookie
X-CF-Lambda-Version
User-Cache-Control
Meta-Geo-Continent
X-NAPM-TraceId
X-ND-Cache
Mobile-Detection-Method
BehaviorPad-Version
Redirect-Candidate
Pramga
X-Forwarded-Path
Fastcgi-X-Cache-Version
X-Orig-Expires
X-PBS-Appsvrname
X-PAYTM-SRV-ID
DCR-Processing-Time-Ms
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Processor
Expiry
X-Planisys-CDN-TTL
DCR-Decision-By
Odigeo-Trace-Id
Sslversion
X-ScT
X-Ig-Push-State
Rendered-Blocks
X-SD-PageType
Surrogated-Key
A
X-S-Cookie
X-Hnp-Log
X-RCS-CacheZone
X-Rojux
X-Correlation-ID
X-Gen-Mode
X-S
X-Ftr-Request-Id
X-Magnolia-Registration
X-Mg-Request-UUID
X-MP-GENERATED-AT
True-Client-Country-4JS
X-Webstats-RespID
DSUID
Gh-Request-Id
Wxu-Next-Hostname
Wxu-Next-Commit
Origin
Wxu-Next-Region
Host-ID
Fastcgi-Cache-TTL
State
Svr
X-Sucuri-Cache
X-Location
X-Rocket-Nginx-Serving-Static
X-Request-URI
X-LI-UUID
X-Li-Pop
X-GeoIP-Region-Code
X-Hash
X-Li-Fabric
X-Men
X-Mvc-Supplant-Cachable
X-Policy
X-Origin
X-Origin-Expires
X-Proxy-Upstream
X-Old-Content-Length
X-NodeID
X-Nyt-Route
X-GeoIP-Country-Code
X-Geo-Header
X-Cache-Date
X-SVT-ORM-RULES
X-Cache-Info
X-SVT-ORM-VERSION
X-Aicache-OS
X-Accel-Expires-Debug
X-VG-TLSProxy
X-Cdn-Srv
X-Sucuri-ID
X-Forwarded-Site
X-Gdpr
X-Scheme
X-Fastly-Cache
X-Server-IP
X-Origin-Time
X-Date
X-Viewer-Country
X-Cache-Bucket
Apple-News-Services-Handled
CacheControlHeader
X-Cache-Var
X-Amzn-RequestId
Apple-News-Services-Request-Url
X-Labrador-Cache-Channel
X-PHP-Host
AKAMAI
Arc-Country
S-Rt
X-Cache-Var-Map
Cmsid
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
X-Amz-Apigw-Id
Cmstype
CloudFront-Viewer-Country
CDCHOST
Server-Info
Environment
X-Varnish-Beresp-Ttl
X-Esi-Check
X-Envoy-Decorator-Operation
X-Fastly-Backend
X-Device-Os
X-Generated-On
X-Gamma-Serve
X-Fetched-On
X-Eu-Site
X-Core-Mission
X-Cache-Debug
X-Cache-Id
X-Branch-Name
X-BBC-Edge-Cache-Status
Web-Mar-Region
X-Backend-State
X-Cdn-Origin
X-CGP
X-Datadog-Sampling-Priority
X-Datadog-Trace-Id
X-Datadog-Parent-Id
X-Csrf-Jwt
X-Core-Value
X-Developers
X-Level-Front-Cache
X-Sn-Servicetimems
X-Http-Reason
X-Skip-Cache
X-Sigma-Backend
X-Akamai-Request-ID2
X-Sigma
X-Storefront-Renderer-Rendered
X-TH-Server
X-VarnishDD-TTL
X-VServer
X-Varnish-Beresp-Status
X-UnsetCookies
X-TrackingId
X-Served-From
X-Rocket-Build-Number
X-Irp-Debug
We-Hiring
X-HS-Content-Campaign-Id
X-HN
X-GeoIP-City
X-Gzip
X-Locale
AMP-Access-Control-Allow-Source-Origin
X-Region-Sid
X-Req
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-Owner
X-GeoIP
X-Platform
PFcat
Origin-EX
Release
Req-Svc-Chain
Ssr
Server-Host
Origin-CC
Mail-Subject
HA-Ipaddr
Fastly-GeoIP-CountryCode
L
L5d-Success-Class
Machine
Locid
Traceparent
Ha-Gx-Prefs
X-Via-NSCOPI
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
X-Variation
Cf-Device-Type
X-Thinkindot-L3
X-DPWN-IS-SECURE
X-FC-Vary-Parameters
Adler-Geo
Magicmarker
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
TDXMobile
X-Worker
X-DefHash
X-DefElseHash
Fastly-SIE
Platform
X-Node-Id
X-Rebelmouse-Cache-Control
X-Qloud-Router
X-NU-AKA-ACS-Version
NM-Fastcgi-Cache
X-Pod-Name
X-Rebelmouse-Surrogate-Control
Memcached
Is-Eu
X-Has-Esi
X-Is-Gdpr
X-JWT-State
X-Loc
X-Response-By
Fastly-SWR
X-Varnish-CookieHashed-On
Thinkindot-Control
Fastly-Drupal-Html
X-Amzn-Remapped-Content-Length
X-ATG-Version
X-Xrds-Location
X-VC-Cache
X-Request-Start
X-Restarts
X-Tx-Id
NGX
X-Ua-Device
X-TraceId
X-M-Log
X-Qnm-Cache
X-M-Reqid
X-Thanos
X-NC
X-CS
X-API-Version
X-Bip
Kp-EeAlive
X-Up
X-Zone
X-Generated-In
X-RPM
X-DW
Pics-Label
X-RPS
X-DSS
X-DI
X-RSL
X-Mvc-Supplant-OutputCached
X-Wix-Viewer-Type
CDN
X-DB
X-Cache-Backend
X-LB-NoCache
X-LB-ID
Edge-Cache
X-Action
Accept-Language
X-Trace-ID
Memory
Ms-Author-Via
X-Cache-Config
Time
X-Tt-Logid
X-Tb-Optimization-Total-Bytes-Saved
X-Edge-Pop
X-Refresh
X-CacheTTL
X-Minions-Version
Env
X-Optimistic-Header
X-Srv
Datacenter
X-Datadome
X-Via-Popn
X-Via-Poph
X-Via-Popv
WebServer
GeoIp-Country-Code
X-Varnish-Ttl
X-Urbn-Context-Path
Locale
X-Urbn-Site-Id
NtCoent-Length
X-HA-Backend
Candidate-Md5Url
X-ZONE
X-Vc
X-DC
Server-ID
X-CACHE-KEY
X-DynaTrace-JS-Agent
X-User
X-Servedbyhost
X-Ec-Fail
X-Ec-GeoHdr
WWW-Authenticate
X-Cs
X-Esi
On-Server
X-TA-CDN-Provider
X-Parent-Response-Time
X-TX-ID
X-MSEdge-Flight
X-MSEdge-Features
Esi-Enabled
X-Unique-ID
X-CLOUD-TRACE-CONTEXT
X-VCL-Version
Cdncip
X-Cache-PHP
C-Via
Cdnsip
X-Varnish-Beresp-TTL
X-Service
X-AK-Request-ID
X-Newrelic-Synthetics
X-Fpc
X-App
X-Cache-Ttl
X-Li-Proto
My-App
X-Fmm-Version
X-Clara-WADP
X-LI-Proto
X-WADP-Cache
Geoip-Latitude
Cluster
Proxy-Connection
X-URL
X-Dynatrace
X-CUA
X-Var-Ttl
Tracecode
X-Webkit-Csp-Report-Only
Test
X-FPC
X-Traceid
X-Pass-Why
Geo-Info
Lfy
X-Cache-Status-Check
X-B3-Spanid
X-Render-Time
Fastly-Drupal-HTML
T-Server
X-Vcl-Version
X-From
X-Webkit-CSP-Report-Only
X-LiteSpeed-Cache-Control
Cf-Int-Pingora-Origin-Digest
X-NODE
Lang
DataCenter
X-Fragments
X-Mcache
Target-Params
Resin-Trace
M-TraceId
X-CSRF-TOKEN
X-VC
X-WP-CF-Super-Cache-Cache-Control
MIME-Version
X-Ha-Backend
X-WP-CF-Super-Cache
Hostname
Server-Id
X-ServedByHost
X-Clientip
X-Geo
X-ID
X-RAMCache
X-Provided-By
X-COUNTRY
X-Oss-Server-Time
X-Oss-Object-Type
X-LiteSpeed-Tag
Hit
UCS
X-Httpd
X-Proxy-Cache-Info
Permissions-Policy
GeoIP-Country-Code
X-Oss-Request-Id
Cache-Host
X-Oss-Storage-Class
X-Info
X-Via-PopH
X-NGINX-Cache
HIT
X-Oss-Hash-Crc64ecma
X-Via-PopV
X-Via-PopN
X-AIR-PT
X-Dynatrace-Js-Agent
Producers
Section-Origin-Responded
Section-Io-Id
WZWS-RAY
Servername
X-Edge-POP
X-Cdn-Forward
S-Cnection
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
X-Pad
ENV
X-Check-Cacheable
X-SB
X-Edge-Cache
X-Fastly-Backend-Reqs
X-Api-Version
Ohc-File-Size
FSS-Cache
X-Udemy-Cache-App-Namespace
X-HS-Status
X-ElasticPress-Query
X-Pool
X-Micro-Cache
X-Ucs
X-ServerName
X-BBC-Origin-Response-Status
X-Platform-Processor
Fastly-Backend-Name
X-Platform-Router
X-Platform-Cluster
User-Agent
Load-Balancing
X-GoCache-CacheStatus
X-UP
X-Backend-Host
X-Lb-Id
PICS-Label
ServerName
Uri
X-Lb-Nocache
X-Ec-Custom-Error
X-Scale
URI
X-Cache-CFC
X-Acquia-Application-UUID
X-Acquia-Site
X-Release
X-Acquia-Application-Trace
X-Acquia-Purge-Tags
X-Srcache-Store-Status
Sid
X-TRACE-ID
X-Srcache-Fetch-Status
X-Cache-Expires
X-SIPLIST1
Sever-Int
X-Dispatcher-Number
MD5-Digest
Server-Ttl
IsBot
Server-Ext
Server-Hostname
X-Cdn-Request-ID
Cneonction
Cteonnt-Length
Cdn
X-Swift-Error
X-BCube-Filmed-By
X-Nc
X-RateLimit-Reset
X-APP
X-Fastly-Cache-Hits
EpKe-Alive
Tcn
X-Dw-Trace-Id
X-Newrelic-App-Data
Path
X-Akamai-ERPolicy
X-Via-Ucdn
X-Vcache
X-Yottaa-OS
Wpo-Cache-Message
Shield-Pop
X-Cache-ASPX
X-Snapshot-Date
X-Contensis-Viewer-Groups
Wpo-Cache-Status
X-Akamai-ERRuleID
Cf-Ipcountry
CF-Cached-On
X-B3-ParentSpanId
Ohc-Cache-HIT
Vha6-Origin
X-HostName
X-Air-Pt
X-Cache-Ngx
Ngx
CountryCode
X-Amz-Meta-Cb-Modifiedtime
X-Shopify-Generated-Cart-Token
VNS-Cache
Cache-Key
X-Litespeed-Cache-Control
CPC-Cache
X-IN-APIGATEWAYSSL
X-IN-APIGATEWAY
X-B3-Parentspanid
VNS-Age
X-Sentry-ID
Req-ID
CPC-Age
X-Apw-Access-Token
X-Logging-Id
X-Last-Modified
X-Apw-Hits
X-Http-Count
X-Te-Count
X-Http-Duration-Ms
X-Apw-Access-Object
X-Apw-Access-Action
X-Te-Duration-Ms
X-Akamai-Request-ID
X-WA-Info
X-Akamai-Pragma-Client-IP
X-UA
X-CacheKey
X-Varnish-Authentication
X-WA