Threat Level: green Handler on Duty: Johannes Ullrich

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-Cache-Status
Link
Accept-Ranges
CF-RAY
ETag
Expect-CT
X-XSS-Protection
Pragma
X-Powered-By
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
Alt-Svc
P3P
X-UA-Compatible
X-Served-By
X-Xss-Protection
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-AspNet-Version
X-Adblock-Key
X-Runtime
X-Permitted-Cross-Domain-Policies
X-DNS-Prefetch-Control
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Cache-Status
X-Check
X-Generator
X-Cacheable
Timing-Allow-Origin
Report-To
X-Content-Security-Policy
X-Iinfo
Feature-Policy
Status
X-Envoy-Upstream-Service-Time
Content-Encoding
Access-Control-Expose-Headers
NEL
P3p
X-Drupal-Dynamic-Cache
X-AspNetMvc-Version
X-CDN
Upgrade
X-Via
CF-Ray
X-Ws-Request-Id
Access-Control-Max-Age
X-Request-ID
Server-Timing
EagleId
X-Turbo-Charged-By
X-Cache-Group
Keep-Alive
X-UA-Device
Request-Context
X-Backend
X-Age
X-Proxy-Cache
X-Server-Powered-By
X-AH-Environment
X-Robots-Tag
X-Hacker
X-Server
Host-Header
X-Amz-Request-Id
X-Amz-Id-2
Grace
X-Rq
X-LiteSpeed-Cache
X-Swift-CacheTime
X-Swift-SaveTime
X-Varnish-Cache
Ali-Swift-Global-Savetime
X-Nginx-Cache-Status
X-WebKit-CSP
X-Page-Speed
EagleEye-TraceId
X-Vhost
X-Ua-Compatible
X-Amz-Version-Id
X-Pingback
X-OneAgent-JS-Injection
X-Dispatcher
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
Accept-CH
X-Device
X-Cache-Spec
X-Host
X-Server-Id
Cf-Railgun
X-Node
X-Backend-Server
X-Readtime
Surrogate-Control
X-Akam-SW-Version
X-Dns-Prefetch-Control
Request-Id
X-Response-Time
X-HW
Xkey
X-Application-Context
Accept-CH-Lifetime
Content-Location
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
Rating
X-Cloud-Trace-Context
X-Country
X-Cache-Lookup
X-B3-TraceId
X-Ruxit-JS-Agent
X-Trace
X-Url
Allow
Accept-Ch-Lifetime
X-Aws-Lambda-Call-Status
X-TtlSet
X-Content-Type
X-Vname
X-PC
X-Ac
X-Clacks-Overhead
Edge-Control
X-Server-Name
X-Varnish-TTL
Fastly-Restarts
X-ESI
X-Mod-Pagespeed
Cache-Tag
X-Rack-Cache
Service-Worker-Allowed
X-FastCGI-Cache
X-VARITI-CCR
Verso
X-Element-Page-Cache
MS-Author-Via
X-Vcap-Request-Id
X-Amz-Rid
X-Upstream
X-MS-InvokeApp
Public-Key-Pins
X-GitHub-Request-Id
X-Dw-Request-Base-Id
X-Abt-Application-Version
X-Client-IP
X-Cached
RTSS
X-D2id
X-Cnection
X-Cache-TTL
X-Exp-Variant
X-Exp-Id
X-Cdn-Fetch
X-GoogleNews-Bot
X-Kinja-Build
X-Kinja-Server
X-Use-Magma
X-Kinja-Revision
X-Kinja
X-Px
X-Navigation-Version
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-Powered-By-Plesk
Arr-Disable-Session-Affinity
X-Country-Code
Access-Control-Request-Method
X-NF-Request-ID
X-Goog-Hash
X-TTL
X-Kraken-Loop-Name
X-Instrumentation
X-Server-Lifecycle-Phase
X-Middleton-Display
Pagespeed
Display
X-CST
X-Sol
AR-PoweredBy
AR-ATIME
AR-CACHE
AR-Request-ID
AR-SID
X-Version
X-Powered-CMS
X-Middleton-Response
Response
X-Origin-Cache
X-RateLimit-Remaining
X-MSEdge-Ref
X-LLID
Nginx-Cache
TCN
X-Kinsta-Cache
X-Edge-Location-Klb
X-Amz-Server-Side-Encryption
Mrf-Cache-Status
MRF-Tech
X-B3-TraceId-Primal
X-Edge
X-Protected-By
X-T
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Forwarded-For
X-Jurisdiction
X-HP-Trace-Id
X-HP-Webp
X-Content-Security-Policy-Report-Only
X-Shield-Request-Id
X-Mg-S
X-Aspnetmvc-Version
X-Id
X-Language
Edge-Cache-Tag
S
SPRequestDuration
Content-MD5
SPIisLatency
X-Ruxit-Js-Agent
Front-End-Https
Fastcgi-Cache
X-Mid
Realpath
Pinterest-Generated-By
Pinterest-Version
X-Request-Received
Server-Node
X-Request-Processing-Time
X-Pinterest-Rid
Filters
X-Cache-Key
X-Frontend
X-Recruiting
X-NWS-LOG-UUID
Server-Name
X-Ser
X-Ab
X-Ua-Browser
X-Content
X-Correlation-Id
X-Template
X-Yandex-Sdch-Disable
X-HS-Cache-Config
X-HS-Hub-Id
X-HS-Content-Id
X-MCACHE
X-HS-Combine-CSS
X-DynaTrace
X-Ezoic-Cdn
SPRequestGuid
X-SharePointHealthScore
X-Hits
X-Parallel-Accel
X-Ttl
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
MicrosoftSharePointTeamServices
X-Tt-Trace-Tag
X-Daa-Tunnel
X-Tt-Trace-Host
Cache-Tags
X-ECACHE
Charset
X-Page-Id
X-B3-Sampled
Host
Cleartype
X-Debug-Info
X-Git-Hash
X-Www-Served-By
X-Geo-Country
X-DIS-Request-ID
X-Content-Options
Accept-Ch
X-Ratelimit-Limit
Alternate-Protocol
X-Content-Digest
Cross-Origin-Opener-Policy
X-ASPNET-VERSION
X-Amzn-Trace-Id
X-Hostname
X-DataDome
Fusion-Content-Id
Fusion-Deployment-Id
Fusion-Source
Fusion-Template-Id
Fusion-Component-Id
Fusion-Content-Source
X-Amz-Replication-Status
Filterid
X-Grace
X-F-Cache
X-FB-Debug
ServerID
X-Varnish-Age
X-Upgrade-Enabled
X-Az
X-AppVersion
X-Activity-Id
X-Accel-Expires
X-VCache
X-Nginx-Upstream-Cache-Status
X-N
X-WebKit-CSP-Report-Only
X-Mobile-URL
X-Rid
X-Fastly-Request-Id
X-Forwarded-Proto
X-Ratelimit-Reset
X-Server-ID
X-LB-Cache
X-Seen-By
Access-Control-Allow-Method
X-Type
X-TT
X-Origin-Server
X-Whom
X-Distributor
X-Tb
X-FW-Hash
X-App-Environment
X-FW-Dynamic
Payment
X-Goog-Stored-Content-Length
Viewport
X-GUploader-UploadID
X-FW-Type
X-Request-Guid
X-Route-Name
X-Providence-Cookie
X-Is-Crawler
X-Aspnet-Duration-Ms
X-Goog-Generation
X-FW-Static
X-Goog-Storage-Class
X-Goog-Metageneration
X-FW-Serve
X-FW-Server
X-Goog-Stored-Content-Encoding
X-Flags
Node
X-User-Agent
X-Varnish-Grace
X-Wix-Request-Id
Fastcgi-Useragent
DC
Paypal-Debug-Id
Country
Accept-Charset
X-Oneagent-Js-Injection
X-Fastly-Request-ID
TP-Cache
TP-L2-Cache
X-XRDS-LOCATION
X-App-Server
X-Tec-Api-Version
X-Litespeed-Cache
X-Tec-Api-Root
X-Cache-Rule
X-Tec-Api-Origin
X-Webkit-Csp
X-Via-JSL
X-Cluster-Name
X-Cache-Control
X-Drupal-Cache-Tags
X-NGENIX-Cache
Version
X-Cache-Age
X-Fastcgi-Cache
X-Buckets
X-B-Cache
X-Signature
X-Microsite
X-Request-Handler-Origin-Region
X-Contextid
Cache-Status
Amp-Access-Control-Allow-Source-Origin
Referer-Policy
X-Node-Name
Refresh
X-Logged-In
X-Origin-Upstream-Status
X-Mobile
VIX-Pulpo-Node
SD-X-WS
X-Original-Request-Id
X-Response-Served-From
VIX-Pulpo-Upstream-Status
X-Real-IP
X-Jobs
X-IPLB-Instance
X-Vgn-Hpd-Reason
X-Load-Cache
X-Cache-Expired-At
X-Is-Bot
X-Rendered-As
X-Erf-Bev-Bev
X-Cacheable-TTL
X-Debug
X-B
X-Erf-Bev-Bev-Is-Generated
NGB
Access-Control-Request-Headers
X-Yottaa-Metrics
X-Browser-Type
X-Varnish-Backend
X-Yottaa-Optimizations
X-Revision
X-Proxy-Cache-Status
X-Cache-Action
X-Page-View
Surrogate-Key
X-Drupal-Cache-Contexts
X-Proxy
X-Device-Type
X-Rule
X-UUID
Akamai-GRN
X-FW-Version
X-ProcessESI
X-RemovedCookies
X-Instance
X-Framework
X-Debug-IsPreview
X-Debug-IsConnected
X-G
X-Cache-Time
X-Accel-Buffering
X-XRDS-Location
X-Oracle-Dms-Rid
X-Oracle-Dms-Ecid
CF-IPCountry
X-Presslabs-Stats
GEO-INFO
X-Cache-NGX
SID
Count-Hit
Uber-Trace-Id
X-Air-Trace-Id
X-Air-Source
X-Air-Hostname
X-Cache-Operation
X-APP-VERSION
X-Azure-Ref
X-Source
X-Ms-Request-Id
X-Ms-Version
X-Zen-Fury
X-Nginx-Cache
Protected
X-EdgeConnect-Cache-Status
X-TEC-API-ROOT
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-Servername
X-RateLimit-Limit
WPO-Cache-Status
DynaTrace
WPO-Cache-Message
X-Trace-Id
Liferay-Portal
X-PressLabs-Stats
Frame-Options
X-RTag
Ms-Operation-Id
X-Hyper-Cache
X-Cache-Hit
Ec-Rule-Version
X-CDN-Forward
MS-CV
X-Backend-Name
X-Cache-TTL-Remaining
Countrycode
Healthy
X-IPS-LoggedIn
Cross-Origin-Window-Policy
Content-Disposition
X-L-Path
X-Adobe-Content
X-Tumblr-Pixel-1
X-Tumblr-User
X-Adobe-Loc
X-Environment-Context
X-Tumblr-Pixel
X-Mode
X-Tumblr-Pixel-0
Xserver
Backend
X-Ratelimit-Remaining
X-Cache-Grace
Url
X-Varnish-Server
X-RN-RSRV
X-Rewrite-Enabled
X-JoinUs
X-Detected-As
X-SaId
X-UPSTREAM-Address
X-Tid
Meta-Geo
X-Format
X-Content-Age
X-Generation-Time
X-Debug-Cache
X-Cache-Server
X-Uri
X-Extlb
X-Alternate-Cache-Key
X-Sorting-Hat-PodId
LB
Decoy-Debug-Key
Decoy-Debug-Status
X-Zipkin-Id
X-Routing-Service
Retry-After
X-Shopify-Stage
Country-Code
X-Proxied
Cache-Name
X-ShardId
X-ShopId
X-NewRelic-App-Data
X-Redis-Cache
X-Sorting-Hat-ShopId
X-FB-TRIP-ID
Decoy-Debug-TTL
Eomportal-Instance
Apigw-Requestid
Mn-Server-Ip
CDN-Uid
CDN-PullZone
X-Access
X-ApacheServer
X-Akamai-Edgescape
X-Say-Cacheable
CDN-Cache
CDN-RequestCountryCode
CDN-EdgeStorageId
CDN-CachedAt
CDN-RequestId
X-OCL
X-Region
X-PERF
X-UA-Device-Type
X-Site-Version
X-Say-TTL
X-Generated-By
X-PCL
X-SayCDN-TTL
X-Status
X-Section
X-Origin-Date
X-Forwarded-Host
X-Web-Node
X-NYM-Debug-Backend
X-Sql-Count
X-PHP-Backend
X-Microcachable
X-Human
X-ServerID
X-NCache
X-Sql-Duration-Ms
X-Via-Fastly
X-No-Session
Property-Id
TWC-Connection-Speed
X-Proxy-Build
X-Origin-Hint
X-ProxyCache-Key
X-Pubstack
X-Server-W
X-ProxyCache-Status
Webcakes-App-Name
X-Cache-Type
X-Cache-Host
X-BYPASS-REASON
X-Cluster-Node
X-Varnish-Beresp-Grace
X-Hosted-By
X-Content-Powered-By
X-Be
X-Timing-Wait
TWC-Locale-Group
TWC-GeoIP-LatLong
TWC-GeoIP-Country
TWC-Privacy
X-Storage
Webcakes-Region
Webcakes-App-Version
TWC-Device-Class
Selected-Fe
X-TIME
Cache-Tv-Group
Fastly-SSL
X-Varnishpool
X-Hl-Ver
X-Nginx-Cache-Key
X-R9-Blue-Green-Version
X-Soup
Azure-InstanceId
Content-Secure-Policy
Azure-RegionName
X-Unique-Id
Section-Io-Cache
Azure-Version
Azure-SiteName
Azure-SlotName
X-Ua
X-Webkit-CSP
X-LSADC-Cache
X-Cache-Remote
DB-Nickname
X-Platform-Server
X-Azure-Ref-OriginShield
X-Dc
X-Cached-By
X-Bc-Bl
Cache
X-Cache-Tags
X-Akamai-Transformed
X-Xfnlog-Site
X-Auto-Login
From-Origin
ServedBy
Source
X-GEO
Upgrade-Insecure-Requests
X-TT-LOGID
OT-Force-Account-Verify
X-AOL-HN
X-ECache
X-Varnish-Cache-Hits
X-Cdn
X-LAGOON
Xet-Cookie
X-Request-Time
X-Origin-TTL
X-Origin-CC
SRV
Mime-Version
X-NWS-UUID-VERIFY
WP-Super-Cache
X-Request-Host
Cache-Hits
X-Varnish-Hits
HostName
X-SRV
X-Varnish-Hostname
X-TNCMS
X-Loop
X-CSRF-Token
X-S-Maxage
Onion-Location
X-Akamai-Request-ID2
Webserver
S-Rt
X-Http-Reason
X-FireWall-Port
X-HTML-Minification-Powered-By
X-Cache-Enabled
X-Handled-By
X-EC-Lua
X-Tumblr-Pixel-2
X-Endurance-Cache-Level
X-Tumblr-Pixel-3
Web-Mar-Node
X-RCS-CacheZone
Nel
N-Cache
X-Correlation-ID
X-Reqid
Server-Info
X-Time
X-Adobe-Source
X-App-Version
X-Magnolia-Registration
X-Origin-Response-Time
X-Connection-Hash
Redirect-Candidate
X-Destination
Sslversion
Surrogated-Key
X-D
Rendered-Blocks
X-Epic-Correlation-Id
Odigeo-Trace-Id
Fastcgi-X-Cache-Version
Mobile-Detection-Method
Meta-Geo-Continent
Expiry
DCR-Processing-Time-Ms
DCR-Decision-By
X-Developer
X-External-Request-Id
Pramga
X-Cluster
X-Mg-Request-UUID
X-A-Dgt
X-A-Dcw
X-Cache-NE
X-A-Wwc
X-Aed
X-Block-Status
X-B-Cookie
X-ARC
X-Application
A
X-CF-Lambda-Fn
X-Backend-TTL
BehaviorPad-Version
X-Conf
V-Age
Vix-Hermes-Req-Id
X-Ckpd-Fst-Backend
X-A-Dam
X-CF-Lambda-Version
X-A-Ccd
X-A
User-Cache-Control
X-Hnp-Log
X-Orig-Expires
X-Session-Fingerprint
X-Rojux
X-Vdms-Path
X-S
X-Proto
X-NAPM-TraceId
X-ND-Cache
X-SRCache-Key
X-V-Cache
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Processor
X-Tenant
X-Planisys-CDN-Cache
X-PAYTM-SRV-ID
X-TIM-N
X-PBS-Appsvrname
X-S-Cookie
X-Vdms-Version
X-B3-SpanId
X-VG-WebCache
X-Vtex-Remote-Cache
X-Gen-Mode
Xc-Version
X-Forwarded-Path
X-Ftr-Request-Id
X-Shop-Environment
X-SD-PageType
X-Vtex-Processado-Em
X-ScT
X-GG-Cache-Date
X-Ig-Push-State
X-Locale
X-LJ-Flow-ID
X-AWS-Id
X-VWS-Id
X-Slack-Backend
Wxu-Next-Region
X-Sn-Servicetimems
X-SVT-ORM-RULES
Svr
Origin-CC
Origin-EX
Origin
X-Webstats-RespID
Host-ID
X-Forwarded-Site
X-Viewer-Country
X-VG-TLSProxy
X-SVT-ORM-VERSION
Wxu-Next-Commit
True-Client-Country-4JS
Traceparent
State
Wxu-Next-Hostname
X-Restarts
Gh-Request-Id
X-Hash
X-Core-Mission
X-Location
X-Men
X-NodeID
X-Mvc-Supplant-Cachable
X-GeoIP-Region-Code
X-Date
X-Fastly-Backend
X-Fastly-Cache
X-Gdpr
X-Device-Os
X-GeoIP-Country-Code
X-Geo-Header
X-Nyt-Route
X-Old-Content-Length
X-Fetched-On
X-Request-URI
X-Proxy-Upstream
X-Rocket-Nginx-Serving-Static
X-Aicache-OS
X-Accel-Expires-Debug
X-Scheme
X-Policy
X-Cache-Bucket
X-Cdn-Srv
X-Origin
X-Origin-Expires
X-Origin-Time
X-Cache-Date
X-Cache-Info
X-Server-IP
X-Cdn-Origin
Cmstype
Apple-News-Services-Handled
Apple-News-Services-Host
AKAMAI
X-MP-GENERATED-AT
Fastcgi-Cache-TTL
DSUID
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
X-Varnish-Ttl
CacheControlHeader
Arc-Country
CDCHOST
Cmsid
X-Time-Microsecs
X-Edge-Location
X-Zone
X-Amz-Meta-S3cmd-Attrs
Accept-Language
Environment
X-Core-Value
X-Gzip
X-GeoIP-City
X-Csrf-Jwt
X-Datadog-Parent-Id
X-Has-Esi
X-CGP
X-HN
X-Cache-Debug
X-Cache-Id
X-Datadog-Sampling-Priority
X-Is-Gdpr
X-HS-Content-Campaign-Id
X-Datadog-Trace-Id
X-FC-Vary-Parameters
X-JWT-State
X-Eu-Site
X-Esi-Check
X-DPWN-IS-SECURE
X-Developers
Fastly-Drupal-Html
X-Gamma-Serve
X-DefHash
X-DefElseHash
X-GeoIP
X-Generated-On
X-Via-NSCOPI
X-Envoy-Decorator-Operation
X-Loc
X-TH-Server
X-Thinkindot-L3
X-TrackingId
X-Sucuri-ID
X-Sucuri-Cache
X-Sigma-Backend
X-Skip-Cache
X-Storefront-Renderer-Rendered
X-UnsetCookies
X-Variation
X-VServer
X-Worker
X-Irp-Debug
X-VarnishDD-TTL
X-Varnish-Remaining-TTL
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-Sigma
X-Served-From
X-Node-Id
X-Owner
X-PHP-Host
X-Branch-Name
X-LI-UUID
X-Level-Front-Cache
X-Li-Fabric
X-Li-Pop
X-Platform
X-Qloud-Router
X-Req
X-Response-By
X-Rocket-Build-Number
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Labrador-Cache-Channel
X-Region-Sid
PFcat
Platform
Release
Req-Svc-Chain
Fastly-GeoIP-CountryCode
X-ATG-Version
Adler-Geo
Machine
Mail-Subject
Server-Host
Ssr
Thinkindot-Control
We-Hiring
Web-Mar-Region
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
CloudFront-Viewer-Country
Cf-Device-Type
TDXMobile
L5d-Success-Class
Locid
Fastly-SWR
L
X-BBC-Edge-Cache-Status
HA-Ipaddr
Ha-Gx-Prefs
Fastly-SIE
Is-Eu
X-Xrds-Location
X-Varnish-Beresp-Ttl
X-Amzn-RequestId
X-Amz-Apigw-Id
X-RPM
X-DW
X-DSS
X-Cache-Backend
X-RPS
X-RSL
X-Action
Memcached
X-VC-Cache
NM-Fastcgi-Cache
X-Pod-Name
X-NU-AKA-ACS-Version
X-DB
X-DI
X-Varnish-Beresp-Status
X-Tx-Id
X-Amzn-Remapped-Content-Length
X-Ua-Device
X-TraceId
X-Backend-State
Kp-EeAlive
X-NC
Edge-Cache
X-Wix-Viewer-Type
NGX
AMP-Access-Control-Allow-Source-Origin
Magicmarker
X-Cache-Var
X-Cache-Var-Map
CDN
X-Minions-Version
X-CacheTTL
X-API-Version
X-Srv
X-Tb-Optimization-Total-Bytes-Saved
Locale
X-Urbn-Site-Id
X-Urbn-Context-Path
X-CS
X-Up
X-Optimistic-Header
Ms-Author-Via
X-LB-ID
X-LB-NoCache
X-Request-Start
X-Generated-In
X-Trace-ID
X-Mvc-Supplant-OutputCached
Pics-Label
X-Tt-Logid
Time
Memory
X-Thanos
X-Bip
Env
X-M-Reqid
WebServer
X-Qnm-Cache
X-Refresh
X-Edge-Pop
X-M-Log
X-TA-CDN-Provider
X-Via-Poph
X-Ec-Fail
X-Via-Popv
X-Via-Popn
X-Ec-GeoHdr
X-User
X-Cache-Config
X-Parent-Response-Time
X-Servedbyhost
X-DC
GeoIp-Country-Code
X-HA-Backend
X-CACHE-KEY
X-Cs
NtCoent-Length
Server-ID
X-Esi
Datacenter
Cdncip
X-AK-Request-ID
X-MSEdge-Flight
X-MSEdge-Features
X-Dynatrace
Candidate-Md5Url
Cdnsip
X-CLOUD-TRACE-CONTEXT
X-Vc
My-App
X-Clara-WADP
Cluster
X-WADP-Cache
X-DynaTrace-JS-Agent
X-Fmm-Version
X-ZONE
X-TX-ID
DataCenter
X-Pass-Why
X-CUA
Tracecode
X-Varnish-Beresp-TTL
On-Server
Geoip-Latitude
X-VCL-Version
WWW-Authenticate
Lfy
X-Cache-Ttl
X-From
X-Var-Ttl
T-Server
X-Fpc
X-App
X-LI-Proto
X-Traceid
Esi-Enabled
X-B3-Spanid
X-URL
X-FPC
X-Fragments
Lang
X-Webkit-Csp-Report-Only
X-VC
X-Datadome
Cf-Int-Pingora-Origin-Digest
X-Service
Target-Params
C-Via
X-Cache-PHP
X-Li-Proto
X-NODE
X-Webkit-CSP-Report-Only
Fastly-Drupal-HTML
X-Newrelic-Synthetics
X-Unique-ID
X-WP-CF-Super-Cache
Proxy-Connection
X-WP-CF-Super-Cache-Cache-Control
X-Vcl-Version
Geo-Info
X-Provided-By
X-Mcache
X-CSRF-TOKEN
M-TraceId
X-RAMCache
Test
Server-Id
Permissions-Policy
Resin-Trace
X-LiteSpeed-Cache-Control
X-Render-Time
X-Ha-Backend
Hostname
X-Cache-Status-Check
X-Httpd
Servername
X-ID
MIME-Version
WZWS-RAY
X-COUNTRY
X-Proxy-Cache-Info
X-B3-Traceid
X-SB
Hit
X-ServedByHost
FSS-Cache
GeoIP-Country-Code
X-NGINX-Cache
Producers
X-Via-PopV
X-Via-PopN
X-Clientip
X-Via-PopH
X-Dynatrace-Js-Agent
X-Udemy-Cache-App-Namespace
X-Geo
X-Edge-POP
X-Platform-Router
X-Platform-Processor
X-Pool
X-Cdn-Forward
X-Pad
X-Platform-Cluster
X-Api-Version
ENV
X-Scale
X-Fastly-Backend-Reqs
X-Ec-Custom-Error
X-Edge-Cache
Section-Io-Id
X-Oss-Object-Type
X-Oss-Request-Id
X-Oss-Server-Time
X-LiteSpeed-Tag
MD5-Digest
HIT
X-Dispatcher-Number
Cneonction
X-ElasticPress-Query
UCS
X-Oss-Storage-Class
Cache-Host
Section-Io-Origin-Status
X-UP
X-Ucs
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
X-Oss-Hash-Crc64ecma
X-HS-Status
Sever-Int
X-Cache-Expires
X-Acquia-Application-UUID
X-Acquia-Application-Trace
Uri
X-Acquia-Purge-Tags
X-Acquia-Site
S-Cnection
Cf-Ipcountry
Server-Hostname
PICS-Label
X-Via-Ucdn
IsBot
ServerName
X-BBC-Origin-Response-Status
X-Cache-CFC
X-Lb-Nocache
URI
X-Check-Cacheable
Server-Ext
X-Lb-Id
X-GoCache-CacheStatus
X-SIPLIST1
X-Cms-Context
X-Srcache-Store-Status
X-AIR-PT
X-Srcache-Fetch-Status
X-Info
X-Snapshot-Date
Sid
X-RateLimit-Reset
X-Swift-Error
Tcn
Server-Ttl
X-Cdn-Request-ID
X-Fastly-Cache-Hits
X-Nc
X-Dw-Trace-Id
X-Akamai-Path-Stats
X-Akamai-ERRuleID
X-Akamai-ERPolicy
CF-Cached-On
Wpo-Cache-Message
Wpo-Cache-Status
X-Wikidot-Static-Cache
X-Yottaa-OS
X-Vcache
X-Micro-Cache
Ohc-File-Size
Fastly-Backend-Name
X-Newrelic-App-Data
User-Agent
X-Wikidot-Backend
Vha6-Origin
X-Release
Ngx
Cteonnt-Length
X-B3-ParentSpanId
X-Cache-Ngx
X-HostName
X-Air-Pt
X-Fetch-By
X-B3-Parentspanid
X-IN-APIGATEWAY
X-WA-Info
Inserted-Into-Cache-At
X-IN-APIGATEWAYSSL
X-Litespeed-Cache-Control
Req-ID
X-UA
X-Akamai-Pragma-Client-IP
CountryCode
X-Apw-Access-Token
X-CacheKey
X-Backend-Host
X-Apw-Hits
X-Logging-Id
X-Apw-Access-Object
X-Sentry-ID
X-Te-Duration-Ms
X-Last-Modified
X-Akamai-Request-ID
X-Te-Count
X-Http-Duration-Ms
X-Apw-Access-Action
X-Http-Count
X-Shopify-Generated-Cart-Token