Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
X-Powered-By
Pragma
X-XSS-Protection
CF-RAY
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
Alt-Svc
P3P
X-Cache-Hits
X-UA-Compatible
X-Xss-Protection
X-Served-By
CF-Ray
X-Download-Options
X-Timer
X-Request-Id
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
Access-Control-Allow-Credentials
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
X-Drupal-Cache
X-Cache-Status
X-Generator
X-Check
X-Cacheable
X-FRAME-OPTIONS
X-Envoy-Upstream-Service-Time
Timing-Allow-Origin
X-Iinfo
X-DNS-Prefetch-Control
X-Dns-Prefetch-Control
X-Request-ID
X-Drupal-Dynamic-Cache
Server-Timing
Feature-Policy
X-Content-Security-Policy
Access-Control-Expose-Headers
X-XSS-PROTECTION
Content-Encoding
X-CDN
Status
Upgrade
X-AspNetMvc-Version
Access-Control-Max-Age
X-Amz-Request-Id
X-Via
X-Amz-Id-2
Request-Context
X-Backend
X-Turbo-Charged-By
X-Cache-Group
X-Robots-Tag
X-AH-Environment
Cf-Edge-Cache
Keep-Alive
Host-Header
X-Hacker
X-Vhost
X-UA-Device
X-Proxy-Cache
X-Server
X-Rq
Allow
X-Server-Powered-By
X-Ws-Request-Id
X-Age
X-Dispatcher
EagleId
X-Varnish-Cache
X-Amz-Version-Id
P3p
Nel
X-Ua-Compatible
Grace
X-LiteSpeed-Cache
Cf-Apo-Via
Cf-Railgun
X-Page-Speed
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-OneAgent-JS-Injection
EagleEye-TraceId
X-Device
X-Swift-SaveTime
X-Swift-CacheTime
X-Aws-Lambda-Call-Status
Ali-Swift-Global-Savetime
X-Pingback
X-Node
X-Host
X-Cache-Lookup
Accept-CH
X-CST
X-WebKit-CSP
X-Backend-Server
Surrogate-Control
X-Server-Id
Accept-CH-Lifetime
Permissions-Policy
X-Readtime
X-Nginx-Upstream-Cache-Status
X-Nginx-Cache-Status
X-Akam-SW-Version
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Application-Context
Request-Id
X-Ruxit-JS-Agent
X-Content-Security-Policy-Report-Only
X-Cloud-Trace-Context
Xkey
X-Response-Time
X-HW
X-Trace
X-Edge
Content-Location
X-Clacks-Overhead
X-Mod-Pagespeed
Rating
X-Url
X-ESI
X-Midtier
X-Amz-Server-Side-Encryption
X-ECACHE
Cache-Tag
X-Mcache
Accept-Ch
X-Rack-Cache
X-Powered-By-Plesk
X-MS-InvokeApp
X-Litespeed-Cache
X-D2id
X-Use-Magma
X-Exp-Variant
X-Kinja-Server
X-Kinja-Build
X-Kinja
X-Cdn-Fetch
X-GoogleNews-Bot
X-Kinja-Revision
X-Exp-Id
X-Element-Page-Cache
Service-Worker-Allowed
X-Vcap-Request-Id
Verso
X-Upstream
Edge-Control
X-Country
X-Country-Code
X-PC
X-Ac
X-TtlSet
X-Vname
RTSS
Origin-Trial
X-Goog-Hash
X-VARITI-CCR
X-Navigation-Version
X-Kinja-CCPA
X-Abt-Application-Version
X-Cache-TTL
X-Browser-Type
Fastly-Restarts
X-Oneagent-Js-Injection
Accept-Ch-Lifetime
X-Amz-Rid
X-Aspnetmvc-Version
X-Varnish-TTL
X-NWS-LOG-UUID
X-WebKit-CSP-Report-Only
X-GitHub-Request-Id
X-Webkit-CSP
X-Cached
Cross-Origin-Opener-Policy
X-Server-Name
X-Middleton-Display
X-Sol
Pagespeed
Display
X-Amzn-Trace-Id
X-Dw-Request-Base-Id
X-SharePointHealthScore
SPRequestGuid
X-Times
X-Ruxit-Js-Agent
X-Ttl
X-Pinterest-Rid
Pinterest-Version
Pinterest-Generated-By
SPIisLatency
X-ORACLE-DMS-RID
SPRequestDuration
X-ORACLE-DMS-ECID
X-Erf-Bev-Bev-Is-Generated
X-Instrumentation
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Erf-Bev-Bev
X-Content-Type
X-Cache-Key
AR-PoweredBy
AR-Request-ID
AR-SID
AR-ATIME
X-FastCGI-Cache
X-Powered-CMS
X-Client-IP
Arr-Disable-Session-Affinity
X-Mg-S
X-B3-Traceid
X-Middleton-Response
Response
X-Version
X-Ser
X-Cnection
X-Server-ID
X-HP-Webp
X-Jurisdiction
X-HP-Trace-Id
Nginx-Cache
X-Accel-Expires
Cache-Tags
AR-CACHE
X-T
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Fastly-Request-ID
X-B3-TraceId
X-RateLimit-Remaining
Cache-Status
Edge-Cache-Tag
X-NF-Request-ID
X-Hits
Front-End-Https
X-MSEdge-Ref
X-Px
Public-Key-Pins
X-Recruiting
S
X-RateLimit-Limit
Payment
X-Daa-Tunnel
X-Shield-Request-Id
X-Frontend
X-LLID
X-Request-Processing-Time
X-Ua-Browser
X-Request-Received
Server-Node
Mrf-Cache-Status
MRF-Tech
X-B3-TraceId-Primal
X-Goog-Metageneration
X-GUploader-UploadID
Content-MD5
X-DIS-Request-ID
MicrosoftSharePointTeamServices
X-Content-Digest
X-Amz-Apigw-Id
X-Amzn-RequestId
Access-Control-Request-Method
X-Webkit-CSP-Report-Only
X-TTL
X-Forwarded-For
TP-Cache
X-Protected-By
Realpath
X-Microsite
X-Distributor
X-Request-Handler-Origin-Region
X-PressLabs-Stats
X-FB-Debug
Fastcgi-Cache
Access-Control-Allow-Method
X-HS-Content-Id
X-HS-Cache-Config
X-HS-Hub-Id
X-HS-Combine-CSS
X-Page-Id
X-Rid
Accept-Charset
X-Cluster-Name
X-LB-Cache
X-Aspnet-Version
X-Goog-Storage-Class
X-Ua-Device
X-Goog-Generation
Count-Hit
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Hostname
X-Geo-Country
X-B3-Sampled
X-Id
X-Edge-Location-Klb
X-Kinsta-Cache
TP-L2-Cache
Cross-Origin-Resource-Policy
X-Ratelimit-Remaining
X-Xrds-Location
X-Seen-By
X-Correlation-Id
X-Erf-Stays-Pdp-Viaduct-Migration-Web
X-Ezoic-Cdn
X-App-Server
Cleartype
TCN
X-Fastcgi-Cache
X-Logged-In
X-Varnish-Backend
X-TEC-API-ROOT
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-Hosted-By
Referer-Policy
X-Content-Options
X-Mobile
DC
X-Git-Hash
X-COUNTRY
Retry-After
X-Contextid
X-Fb-Rlafr
X-Is-Crawler
X-Providence-Cookie
X-Request-Guid
X-Flags
X-Route-Name
X-Aspnet-Duration-Ms
X-Origin-Cache
X-Revision
X-Grace
X-Amz-Replication-Status
Surrogate-Key
X-App-Environment
X-TT
X-Ratelimit-Limit
X-F-Cache
X-Forwarded-Proto
X-Debug-Info
Frame-Options
X-Varnish-Grace
X-IPS-LoggedIn
X-Newrelic-App-Data
X-Amz-Meta-S3cmd-Attrs
X-RateLimit-Reset
X-Envoy-Decorator-Operation
X-Azure-Ref
Section-Io-Cache
X-Magnolia-Registration
MS-Author-Via
X-Wix-Request-Id
X-Proxy-Cache-Info
X-Whom
Healthy
X-App-Version
X-Webkit-Csp
X-Www-Served-By
Charset
X-Language
Viewport
X-Akamai-Edgescape
Alternate-Protocol
WPO-Cache-Message
X-Az
WPO-Cache-Status
X-Activity-Id
X-Trace-Id
Filterid
X-AppVersion
X-Backend-Name
X-Origin-Server
X-Varnish-Server
Amp-Access-Control-Allow-Source-Origin
Server-Name
X-Datadog-Parent-Id
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Datadog-Sampling-Priority
Paypal-Debug-Id
X-Datadog-Trace-Id
X-B
Host
X-EdgeConnect-Cache-Status
X-Original-Request-Id
X-Response-Served-From
SD-X-WS
VIX-Pulpo-Node
X-Http-Reason
VIX-Pulpo-Upstream-Status
SRV
X-Cache-Rule
X-Akamai-Request-ID2
X-Rule
Front
X-ProcessESI
X-Cache-Grace
X-Instance
X-Nf-Request-Id
X-UUID
X-Edge-Location
X-DataDome
X-User-Agent
X-RemovedCookies
X-Rocket-Nginx-Serving-Static
X-Vcache
X-Tumblr-Pixel-0
X-ARC
Protected
X-Jobs
X-N
X-Region
X-Yottaa-Optimizations
From-Origin
X-L-Path
X-Environment-Context
X-Varnish-Age
X-Unique-Id
X-Tumblr-Pixel-1
X-Cacheable-TTL
Country
X-Tumblr-Pixel
X-Tumblr-User
X-Page-View
X-Yottaa-Metrics
X-FW-Hash
X-FW-Serve
Fastly-SWR
X-FW-Dynamic
X-Is-Bot
Akamai-GRN
Fastly-SIE
X-Status
X-FW-Static
X-Framework
X-FW-Version
X-FW-Server
X-Adobe-Loc
X-Rendered-As
X-Adobe-Content
X-FW-Type
X-Load-Cache
X-Mg-Request-UUID
X-Datadog-Sampled
X-Cache-Time
X-Type
Content-Disposition
X-Proxy
X-G
X-B-Cache
X-Signature
X-Amzn-Remapped-Content-Length
X-Debug-IsPreview
X-Debug-IsConnected
Access-Control-Request-Headers
ServerID
X-Time
X-ECache
X-CDN-Forward
X-Tec-Api-Version
X-Tec-Api-Root
X-Tec-Api-Origin
X-Client-Ip
Backend
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
X-Erf-Web-Scheduler
Refresh
X-Cache-Control
X-Servername
Countrycode
Xet-Cookie
X-DynaTrace
Accept-Language
Url
X-Httpd
X-Tt-Trace-Tag
X-Drupal-Cache-Tags
X-Tt-Trace-Host
X-Template
CF-IPCountry
X-DynaTrace-JS-Agent
X-Cache-Age
X-Nginx-Cache
X-Generated-By
X-Device-Type
X-Mode
Webserver
X-Content-Powered-By
X-HTML-Minification-Powered-By
X-NYM-Debug-Backend
Xserver
X-Storage
X-Source
X-XRDS-Location
X-Hcs-Proxy-Type
X-CCDN-CacheTTL
GEO-INFO
X-CCDN-Origin-Time
X-Cache-Hit
X-GeoCode
X-Urbn-Context-Path
X-URL
S-Rt
X-GeoCountry
X-Tncms
X-UPSTREAM-Address
X-Urbn-Site-Id
Locale
X-Cache-Operation
Load-Balancing
X-Cache-Action
X-Director
X-JoinUs
Filters
X-XRDS-LOCATION
X-Content-Age
Meta-Geo
X-LAGOON
X-SaId
X-Say-Cacheable
X-Rewrite-Enabled
Version
X-Loop
OT-Force-Account-Verify
X-Say-TTL
X-Rn-Rsrv
X-SayCDN-TTL
X-ServerID
X-Tumblr-Pixel-2
X-Varnish-Hostname
X-Git-Commit
X-Forwarded-Host
Cross-Origin-Window-Policy
Onion-Location
X-Cluster-Node
X-Varnish-Cache-Hits
X-Tumblr-Pixel-3
X-Container-Uri
X-Soup
X-MCACHE
X-Lambda-Id
X-VCT
X-Cache-Server
Azure-InstanceId
X-VC-Cache
Azure-SlotName
Azure-Version
Web-Mar-Node
X-Ms-Request-Id
X-Adobe-Source
X-Tt-Logid
Azure-SiteName
X-PHP-Host
X-RM-Cache-TTL
X-Labrador-Cache-Channel
Azure-RegionName
X-Served-From
X-Skip-Cache
X-Tb
X-Sql-Count
X-Sql-Duration-Ms
X-Ms-Version
X-Detected-As
DB-Nickname
X-Routing-Service
Mn-Server-Ip
X-Redis-Cache
X-R9-Blue-Green-Version
X-Proxied
X-Logging-Id
X-Extlb
X-FB-TRIP-ID
Node
X-Zipkin-Id
X-RCS-CacheZone
Selected-Fe
TWC-Connection-Speed
TWC-Device-Class
X-Format
X-Generation-Time
X-Fetched-On
X-Timing-Wait
X-Proxy-Build
X-Origin-Hint
X-Proto
X-Debug
X-Uri
TWC-Locale-Group
TWC-GeoIP-LatLong
Webcakes-App-Name
Webcakes-App-Version
Webcakes-Region
TWC-GeoIP-Country
TWC-Privacy
Property-Id
Fastcgi-Useragent
X-FTR-Request-ID
X-NGENIX-Cache
X-B3-SpanId
X-Endurance-Cache-Level
Uber-Trace-Id
X-Zen-Fury
Source
X-LSADC-Cache
CDN-RequestId
X-Sucuri-Cache
X-Sucuri-ID
X-Ua
Section-Io-Id
Section-Io-Origin-Status
X-S
Section-Origin-Responded
Section-Io-Origin-Time-Seconds
X-Oracle-Dms-Rid
X-Oracle-Dms-Ecid
X-TimeS
X-Origin-TTL
X-Origin-CC
X-CACHE-AGE
NGB
X-Drupal-Cache-Contexts
X-Akamai-Transformed
X-Pass-Why
X-MP-GENERATED-AT
X-Origin-Date
X-Varnish-Hits
X-Srv
X-Real-IP
Upgrade-Insecure-Requests
X-Cache-Expired-At
Fastly-Drupal-HTML
X-Newrelic-Synthetics
X-Ratelimit-Reset
X-Handled-By
Liferay-Portal
X-Reqid
X-Cms-Context
Apigw-Requestid
X-Xfnlog-Site
X-No-Session
X-Optimistic-Header
X-Upgrade-Enabled
X-TIME
X-GEO
ServedBy
X-Restarts
X-ProxyCache-Key
X-ProxyCache-Status
X-Varnish-Ttl
MS-CV
X-BYPASS-REASON
X-RTag
Ms-Operation-Id
X-Cache-Host
X-Tx-Id
X-AB
X-Hl-Ver
CDN-EdgeStorageId
WP-Super-Cache
CDN-PullZone
CDN-CachedAt
X-Cache-Type
X-Fastly-Request-Id
CDN-Uid
CDN-RequestPullSuccess
CDN-RequestPullCode
CDN-RequestCountryCode
CDN-Cache
X-UA-Device-Type
X-Node-Name
X-Cache-TTL-Remaining
X-LJ-Flow-ID
X-IPLB-Instance
X-IPLB-Request-ID
X-Parent-Response-Time
X-VWS-Id
X-Cluster
X-AWS-Id
X-TraceId
X-Geo-Region
X-Via-JSL
X-Pubstack
X-Slack-Backend
X-Slack-Shared-Secret-Outcome
X-CF-Lambda-Version
X-SRCache-Key
X-CF-Lambda-Fn
Cache-Provider
X-CacheTTL
X-BCube-Filmed-By
DCR-Decision-By
X-Bl-Debug
X-Cache-NE
Canary
X-CGP
BehaviorPad-Version
X-Debug-Cache-Fetch
X-Ec-Fail
X-Ec-Custom-Error
X-Dispatcher-Number
X-Ec-GeoHdr
X-Epic-Correlation-Id
X-Fastly-Backend
X-External-Request-Id
X-Eu-Site
X-Developer
X-Destination
X-FC-Vary-Parameters
X-D
X-Csrf-Jwt
DCR-Processing-Time-Ms
X-Proxy-Cache-Status
X-Debug-Cache-Store
X-PAYTM-SRV-ID
X-Conf
X-B-Cookie
Web-Mar-Region
Odigeo-Trace-Id
W
Vix-Hermes-Req-Id
Ngx.Var.Host
X-A
Meta-Geo-Continent
N-Cache
X-A-Ccd
Origin-Agent-Cluster
X-S-Cookie
Sslversion
X-Request-Host
Surrogated-Key
True-Client-Country-4JS
Server-Host
X-Rojux
Redirect-Candidate
Rendered-Blocks
MD5-Digest
Magicmarker
X-Aed
X-A-Wwc
X-A-Dgt
X-App
X-Application
X-Bc-Bl
T-Server
Fastly-SSL
X-A-Dcw
Gannett-Cam-Experience-Id
L
L5d-Success-Class
Lang
Host-ID
HA-Ipaddr
X-ScT
Ha-Gx-Prefs
X-A-Dam
X-SD-PageType
Candidate-Md5Url
Xc-Version
X-Vdms-Version
X-Micro-Cache
X-Vdms-Path
X-We-Are-Hiring
X-Worker
X-Viewer-Country
X-Vtex-Remote-Cache
Cache-Name
X-Cache-Status-Check
X-CSRF-Token
X-Server-W
X-Wikidot-Static-Cache
X-Accel-Expires-Debug
X-Accel-Buffering
X-Wix-Viewer-Type
X-Alternate-Cache-Key
X-Generated-On
X-BBC-Edge-Cache-Status
X-Level-Front-Cache
X-Bip
X-Policy
We-Hiring
X-ApacheServer
X-App-Name
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
Release
Req-Svc-Chain
X-Request-Time
Producers
Platform
X-Vmg-Version
X-VServer
Origin
X-Correlation-ID
X-Wikidot-Backend
X-Refresh
X-Owner
X-SVT-ORM-VERSION
Thinkindot-Control
Thinkindot-CacheControl-Type
TDXMobile
Thinkindot-CacheControl
VNS-Cache
X-Cache-Info
X-Human
X-Orig-Expires
X-Irp-Debug
X-Hash
X-GeoIP-Region-Code
X-Gdpr
X-Geo-Header
X-GeoIP-Country-Code
X-Loc
X-Org
X-Node-Id
X-Mvc-Supplant-Cachable
X-Nananana
X-NodeID
X-Nyt-Route
X-Mid
X-Mly-Id
X-Old-Content-Length
X-Forwarded-Path
X-Origin-Time
X-Thanos
X-Clientip
X-CMSURLCustom
X-Qloud-Router
X-Cdn-Origin
X-Cache-Debug
X-Pool
X-Cdn-Diag
X-Core-Mission
X-Core-Value
X-DPWN-IS-SECURE
X-Platform
X-PERF
X-Dispatcher-Server
X-AIR-PT
X-Date
X-DefElseHash
X-DefHash
X-Cache-Bucket
VNS-Age
X-Variation
Environment
X-Sorting-Hat-PodId
X-Varnish-Remaining-TTL
Datacenter
X-Varnish-CookieINHashed-On
X-Sorting-Hat-ShopId
Expect-Staple
Gh-Request-Id
X-Var-Ttl
X-Storefront-Renderer-Rendered
Fastly-GeoIP-CountryCode
Fastly-Backend-Name
CPC-Cache
CPC-Age
X-Nitro-Cache
AKAMAI
X-Varnish-CookieHashed-On
X-Server-IP
X-Shop-Environment
X-ShardId
Adler-Geo
X-ShopId
Cmstype
X-Sn-Servicetimems
Cmsid
CloudFront-Viewer-Country
X-Shopify-Stage
Is-Eu
X-Varnishpool
X-VG-TLSProxy
X-Up
X-Thinkindot-L3
X-Tenant
Mail-Subject
X-VG-WebCache
X-SVT-ORM-RULES
X-S-Maxage
User-Cache-Control
Cf-Device-Type
X-Gzip
CDCHOST
X-Auto-Login
X-Hnp-Log
X-Test
X-Gen-Mode
X-Op-Id-All
X-WA-Info
X-Device-Os
X-Origin-Response-Time
NM-Fastcgi-Cache
X-Nginx-Cache-Key
X-Clara-WADP
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
X-Cache-Id
Apple-News-Services-Host
X-Block-Status
Apple-News-Services-Handled
X-Mvc-Supplant-OutputCached
X-NCache
X-Via-Fastly
Country-Code
X-Forwarded-Site
X-From
X-GeoIP
DSUID
X-Esi-Check
Server-Ext
X-Instance-Name
Sever-Int
X-INCAP-ABP
Esi-Enabled
Server-Hostname
X-Fmm-Version
X-Vgn-Hpd-Reason
X-WADP-Cache
Machine
X-Datadome
X-Origin
X-Accel-Version
X-B3-Spanid
X-Is-Desktop
X-Is-Tablet
X-Cdn-Srv
X-Is-Mobile
X-Tcp-Rtt
X-LB-NoCache
X-Is-Supported-Browser
Content-Secure-Policy
X-Browser-Name
X-Cache-Enabled
X-Akamai-Device-Characteristics
Ssr
X-Access
Wxu-Next-Commit
Wxu-Next-Hostname
C-Via
Wxu-Next-Region
Server-Info
X-Section
Pics-Label
NGX
X-Vcl-Version
X-Buckets
AMP-Access-Control-Allow-Source-Origin
X-CACHE-GROUP
X-Dc
X-Amz-Meta-Cb-Modifiedtime
Server-ID
X-Presslabs-Stats
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Ttl
X-API-Version
IsBot
X-HA-Backend
X-SIPLIST1
Hostname
X-Zone
Memcached
YJS-ID
X-ID
X-Is-Gdpr
X-B3-Parentspanid
X-JWT-State
X-Has-Esi
Time
Cdn-Requestid
CF-Ctrl
X-Platform-Processor
X-Platform-Router
Memory
X-Wp-Cf-Super-Cache-Active
X-Cached-By
X-Origin-Cache-Key
X-Platform-Cluster
Sid
X-TA-CDN-Provider
Origin-CC
Cache-Hits
X-Tb-Optimization-Total-Bytes-Saved
X-Scale
Origin-EX
Location
X-Frame-Option
X-WP-CF-Super-Cache-Active
X-Backend-Instance
X-TIM-N
X-Air-Source
X-Fpc
X-Air-Trace-Id
X-Internal-Host
X-Air-Hostname
X-NewRelic-App-Data
X-Hyper-Cache
X-ZONE
X-PHP-Backend
X-DC
X-NGINX-Cache
X-Cs
X-FTR-Expires
Resin-Trace
X-Webstats-RespID
X-Country-Code-Real
X-FTR-Backend-Server
X-FTR-Cache-Status
X-FTR-Balancer
X-Service
X-FTR-Backend
Epwk-X-Cache
X-Azure-Ref-OriginShield
X-VC
X-DataCenter
X-Site-Version
X-HOST
GeoIp-Country-Code
LB
X-SRV
X-LiteSpeed-Cache-Control
X-Microcachable
Uri
GeoIP-Latitude
True-Client-Ip
X-Nitro-Rev
Cache-Host
X-CSRF-TOKEN
X-Nitro-Cache-From
X-Locale
X-Origin-Expires
X-VCache
X-Edge-Server
Cdn
Cdn-Request-Time
Cdn-Host
Req-ID
WZWS-RAY
True-Client-IP
X-Cache-Ttl
XServer
X-NMSegId
X-Info
NtCoent-Length
GeoIP-Country-Code
XM
M-TraceId
X-VarnishDD-TTL
X-Ad-Load-Variation
X-Datacenter
X-Pad
X-HN
PFcat
X-Pod-Name
SID
X-Web-Node
X-Geo
X-M-Reqid
Pramga
X-Vercel-Cache
X-Vercel-Id
X-Scope-Id
X-Request-Start
Cluster
WebServer
X-M-Log
X-Ad-Defer-Variation
User-Agent
X-Request-URI
X-Github-Request-Id
X-Varnish-Beresp-Status
X-MSEdge-Features
X-Shield-Cache-Expires
X-MSEdge-Flight
X-Via-CDN
X-FL-EDGE
X-Via-SSL
X-Via-Edge
Edge-Copy-Time
X-FL-QIT-DEBUG
X-Qnm-Cache
X-CS
A
Content-Script-Type
Srvid
X-FPC
Content-Style-Type
Fastly-Drupal-Html
Locid
X-HostName
Tcn
X-Cache-Date
Edge-Cache
Cache-Tv-Group
HostName
CountryCode
X-APP-VERSION
X-Api-Version
Cf-Ipcountry
X-Cdn-Request-ID
X-WP-CF-Super-Cache-Cookies-Bypass
Path
X-Moov-Xdn-Version
X-Moov-T
X-ATG-Version
X-Varnish-Authentication
Cdnsip
X-Amz-Meta-Opti
Cdncip
X-FireWall-Port
X-AK-Request-ID
X-Cache-ASPX
X-Esi
X-Contensis-Viewer-Groups
X-NWS-UUID-VERIFY
X-TH-Server
X-LiteSpeed-Tag
X-Branch-Name
Tube-Got-Eval
X-Req
X-SB
X-Nc
X-Cache-FS-Status
X-Aicache-OS
X-Servedbyhost
Cache-Key
X-Via-Popv
X-Wa
X-Via-Popn
X-Via-Poph
X-V-Cache
X-Acquia-Purge-Cdn-Unconfigured
X-B3-Trace-ID
Click-Count-Error
Click-Count-Action-Start
Tube-Get-Contents
Tube-Got-Results
Tube-Return
X-VCL-Version
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-TRACE-ID
MIME-Version
X-Men
X-Vary
X-LB-ID
XkeyRZ
X-Proxy-CacheRZ
V-Age
On-Server
Yak-Timeinfo
X-UA
X-CACHE-KEY
CDN
X-Render-Time
Ngx-Var-Key
Wpo-Cache-Status
Geoip-Latitude
X-Tim-N
Wpo-Cache-Message
Srv
X-Wp-Cf-Super-Cache-Cache-Control
X-Wp-Cf-Super-Cache
X-Cdn-Forward
Proxy-Connection
X-Akamai-Pragma-Client-IP
X-Lb-Cache
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-User
X-Generated-In
X-Acquia-Purge-Tags
X-Fastly-Backend-Reqs
Server-Id
Lb
Priority
X-Platform-Server
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Acquia-Site
My-App
X-Air-Pt
X-Acquia-Application-Trace
X-Acquia-Application-UUID
State
X-Ha-Backend
X-HS-Content-Campaign-Id
X-Planisys-CDN-Cache
X-TT-LOGID
X-Vgn-Hpd-Cached
X-Vgn-Hpd-Ssi
X-CUA
X-Vgn-Hpd-Variations-Key
PICS-Label
Vha6-Origin
X-Release
Ohc-Cache-HIT
Ohc-File-Size
CF-Cached-On
X-Fastly-Country-Code
X-Fastly-Cache
X-Lb-Nocache
X-Dw-Trace-Id
X-EC-Lua
X-Varnish-Director
X-Via-Ucdn
Yjs-Id
X-Provided-By
X-Iplb-Request-Id
X-Iplb-Instance
X-Upstream-Ct
X-Upstream-Ht
X-Cache-Remote
Ngx
Cneonction
X-Litespeed-Cache-Control
X-ElasticPress-Query
X-Miniprofiler-Ids
Warning
X-Lb-Id
X-CDN-Cache-Status
X-RAMCache
Log-Origin
X-Cached-Since
X-Snapshot-Date
X-Sigma-Backend
X-Sigma
X-CF-Cache-Header-Vary
X-HS-Status
X-Udemy-Cache-App-Namespace
X-CF-Cache-Header-Cache-Control
CACHE-MISS-TO-ORIGIN
X-Traceid
X-Fastly-Cache-Hits
Inserted-Into-Cache-At
X-Rocket-Build-Number
Cache