Threat Level: green Handler on Duty: Rick Wanner

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
Link
CF-Cache-Status
Accept-Ranges
CF-RAY
ETag
X-XSS-Protection
Expect-CT
Pragma
X-Powered-By
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-UA-Compatible
X-Cache-Hits
Alt-Svc
P3P
X-Served-By
X-Xss-Protection
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Cache-Status
X-Generator
X-Cacheable
Timing-Allow-Origin
X-Request-ID
X-Content-Security-Policy
P3p
X-Iinfo
Status
Feature-Policy
X-Envoy-Upstream-Service-Time
Content-Encoding
Access-Control-Expose-Headers
X-CDN
X-Drupal-Dynamic-Cache
X-AspNetMvc-Version
Upgrade
X-Via
CF-Ray
Access-Control-Max-Age
X-Ws-Request-Id
Server-Timing
EagleId
Keep-Alive
X-Cache-Group
X-Turbo-Charged-By
Request-Context
X-Age
X-Proxy-Cache
X-Server-Powered-By
X-AH-Environment
X-UA-Device
X-Backend
X-Hacker
X-Robots-Tag
Report-To
X-Amz-Request-Id
Host-Header
X-LiteSpeed-Cache
X-Server
X-Amz-Id-2
X-Dns-Prefetch-Control
Grace
X-Rq
X-Nginx-Cache-Status
X-Varnish-Cache
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-WebKit-CSP
X-Page-Speed
X-Vhost
X-OneAgent-JS-Injection
X-Amz-Version-Id
EagleEye-TraceId
X-Pingback
X-Device
X-Dispatcher
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Cache-Spec
NEL
X-Server-Id
X-Host
X-Backend-Server
X-Node
Cf-Railgun
Accept-CH
X-Readtime
X-Akam-SW-Version
Surrogate-Control
Request-Id
X-Response-Time
X-HW
X-Language
Xkey
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Ruxit-JS-Agent
X-Application-Context
Content-Location
X-Template
Accept-Ch-Lifetime
Rating
X-Country
X-B3-TraceId
X-Ua-Compatible
X-Cloud-Trace-Context
X-Cache-Lookup
X-Ac
X-Url
Allow
X-Content-Type
X-Buckets
X-Trace
Accept-CH-Lifetime
X-Vname
X-TtlSet
X-PC
X-Mod-Pagespeed
X-Varnish-TTL
X-Clacks-Overhead
Edge-Control
Cache-Tag
X-FastCGI-Cache
X-ESI
Fastly-Restarts
X-Rack-Cache
Service-Worker-Allowed
X-VARITI-CCR
X-Server-Name
X-Element-Page-Cache
Verso
X-GitHub-Request-Id
X-MS-InvokeApp
X-Upstream
X-Amz-Rid
MS-Author-Via
X-Vcap-Request-Id
X-Dw-Request-Base-Id
Public-Key-Pins
X-D2id
X-Client-IP
X-Cached
X-Abt-Application-Version
X-Origin-Cache
X-Cache-TTL
Arr-Disable-Session-Affinity
X-Cnection
X-Country-Code
X-Px
X-Goog-Hash
X-Powered-By-Plesk
X-Navigation-Version
Access-Control-Request-Method
X-NF-Request-ID
X-Kraken-Loop-Name
X-Aws-Lambda-Call-Status
X-Server-Lifecycle-Phase
X-Instrumentation
X-Version
Accept-Ch
RTSS
X-ORACLE-DMS-RID
X-Amz-Server-Side-Encryption
X-ORACLE-DMS-ECID
X-Powered-CMS
X-Sol
Display
X-Middleton-Display
Pagespeed
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Middleton-Response
Response
X-Kinja-Revision
X-Kinja-Server
X-Use-Magma
X-Kinja-Build
X-GoogleNews-Bot
X-Cdn-Fetch
X-Exp-Id
X-Kinja
X-Exp-Variant
X-MSEdge-Ref
X-LLID
X-Edge
X-Kinsta-Cache
X-Edge-Location-Klb
X-CST
Nginx-Cache
X-Shield-Request-Id
Mrf-Cache-Status
X-B3-TraceId-Primal
X-TTL
MRF-Tech
AR-SID
AR-ATIME
AR-CACHE
AR-PoweredBy
AR-Request-ID
S
Content-MD5
X-Jurisdiction
X-HP-Webp
X-HP-Trace-Id
X-T
X-Protected-By
TCN
X-Content-Security-Policy-Report-Only
X-Mg-S
X-Id
X-Forwarded-For
X-Mid
X-MCACHE
Fastcgi-Cache
X-Aspnetmvc-Version
X-RateLimit-Remaining
Realpath
Front-End-Https
X-Parallel-Accel
SPRequestDuration
SPIisLatency
Edge-Cache-Tag
X-Recruiting
X-Request-Received
X-Request-Processing-Time
Filters
X-Ttl
X-Pinterest-Rid
Pinterest-Generated-By
Pinterest-Version
Fusion-Template-Id
Fusion-Component-Id
Fusion-Source
Fusion-Content-Id
Fusion-Deployment-Id
Fusion-Content-Source
Server-Node
X-Ua-Browser
X-DynaTrace
X-Content
X-Ab
X-SharePointHealthScore
SPRequestGuid
X-Correlation-Id
X-Ezoic-Cdn
Server-Name
Alternate-Protocol
X-Accel-Expires
X-NWS-LOG-UUID
X-Frontend
X-ECACHE
X-HS-Combine-CSS
X-HS-Content-Id
X-HS-Cache-Config
X-HS-Hub-Id
X-Yandex-Sdch-Disable
X-Hits
X-Cache-Key
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Content-Options
Cache-Tags
MicrosoftSharePointTeamServices
X-Git-Hash
Host
X-Page-Id
Charset
Cleartype
X-B3-Sampled
X-Www-Served-By
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Geo-Country
X-Ruxit-Js-Agent
X-Content-Digest
X-Amz-Replication-Status
TP-Cache
TP-L2-Cache
X-Ser
Filterid
X-Forwarded-Proto
X-Fastly-Request-Id
X-VCache
X-Hostname
X-Amzn-Trace-Id
X-Varnish-Age
X-AppVersion
X-Az
X-Activity-Id
X-XRDS-LOCATION
X-Daa-Tunnel
X-Debug-Info
X-DIS-Request-ID
X-Rid
X-Upgrade-Enabled
X-Origin-Server
X-Grace
Access-Control-Allow-Method
X-N
X-Microsite
X-Request-Handler-Origin-Region
X-LB-Cache
X-Origin-Upstream-Status
X-FB-Debug
ServerID
X-Nginx-Upstream-Cache-Status
X-Mobile-URL
X-Flags
X-Whom
X-TT
X-Is-Crawler
X-Aspnet-Duration-Ms
X-Request-Guid
X-Route-Name
X-Providence-Cookie
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-NGENIX-Cache
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-F-Cache
X-Goog-Metageneration
X-App-Server
X-App-Environment
X-Varnish-Grace
Cross-Origin-Opener-Policy
X-WebKit-CSP-Report-Only
Viewport
X-PressLabs-Stats
Payment
X-Distributor
X-Tb
X-FW-Dynamic
X-FW-Type
X-FW-Static
X-Server-ID
DC
X-FW-Server
X-FW-Serve
Node
X-FW-Hash
Paypal-Debug-Id
X-Logged-In
X-Cache-Control
X-Seen-By
Fastcgi-Useragent
X-Type
X-User-Agent
X-Cache-Age
Country
Accept-Charset
X-Ratelimit-Limit
X-Fastcgi-Cache
X-Cache-Rule
X-Varnish-Backend
X-Erf-Bev-Bev-Is-Generated
X-Fastly-Request-ID
X-Webkit-CSP
X-DataDome
X-Erf-Bev-Bev
X-Node-Name
X-Browser-Type
X-Load-Cache
X-Wix-Request-Id
Version
X-Cache-Action
Refresh
X-IPLB-Instance
X-Via-JSL
X-Oracle-Dms-Rid
X-Oracle-Dms-Ecid
Access-Control-Request-Headers
SD-X-WS
Referer-Policy
Cache-Status
X-Original-Request-Id
X-Response-Served-From
X-Jobs
Amp-Access-Control-Allow-Source-Origin
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-Cacheable-TTL
X-TEC-API-ROOT
X-Real-IP
X-Drupal-Cache-Tags
X-Contextid
NGB
X-UUID
VIX-Pulpo-Node
X-Proxy-Cache-Status
X-Is-Bot
X-Page-View
VIX-Pulpo-Upstream-Status
X-Rendered-As
X-ProcessESI
X-Vgn-Hpd-Reason
X-Debug
X-Revision
X-B
X-RemovedCookies
X-Cluster-Name
X-B-Cache
X-Mobile
X-Yottaa-Metrics
X-Proxy
X-Signature
X-Cache-Expired-At
Liferay-Portal
X-Device-Type
DynaTrace
X-Drupal-Cache-Contexts
X-Yottaa-Optimizations
X-Rule
X-Instance
X-G
Surrogate-Key
X-Cache-Time
X-Framework
Akamai-GRN
X-Tec-Api-Origin
X-Debug-IsConnected
X-Tec-Api-Root
X-Debug-IsPreview
X-Tec-Api-Version
CF-IPCountry
X-Azure-Ref
Healthy
X-FW-Version
SID
X-Source
X-Air-Hostname
X-Air-Source
X-Air-Trace-Id
X-Ms-Request-Id
X-Ms-Version
Frame-Options
X-XRDS-Location
X-Nginx-Cache
X-RTag
X-Cache-Hit
Ms-Operation-Id
MS-CV
X-APP-VERSION
Section-Io-Cache
X-CDN-Forward
Countrycode
X-Oneagent-Js-Injection
X-Tumblr-Pixel-1
X-Tumblr-Pixel
X-Tumblr-User
X-Tumblr-Pixel-0
X-Varnish-Server
X-L-Path
Xserver
X-Environment-Context
Count-Hit
X-Region
X-Cache-Operation
GEO-INFO
X-Servername
Uber-Trace-Id
X-Forwarded-Host
X-Content-Powered-By
X-EdgeConnect-Cache-Status
X-Backend-Name
X-Mode
X-Accel-Buffering
Cross-Origin-Window-Policy
X-IPS-LoggedIn
Backend
X-Adobe-Content
X-Adobe-Loc
X-Litespeed-Cache
X-Zen-Fury
Ec-Rule-Version
Meta-Geo
X-JoinUs
X-RN-RSRV
X-SaId
X-UPSTREAM-Address
Eomportal-Instance
X-Varnish-Beresp-Grace
X-Shopify-Stage
X-Sorting-Hat-ShopId
X-ShardId
X-Cache-Server
X-Cache-Grace
X-Detected-As
X-Sorting-Hat-PodId
X-Alternate-Cache-Key
X-Cache-Type
X-ShopId
X-Microcachable
X-Redis-Cache
X-Human
X-Hosted-By
X-Generation-Time
X-Debug-Cache
Country-Code
X-PHP-Backend
X-ProxyCache-Key
X-ProxyCache-Status
X-Cache-TTL-Remaining
X-Storage
X-Status
X-Site-Version
X-ServerID
X-Origin-Date
X-NCache
Decoy-Debug-TTL
Url
X-FB-TRIP-ID
X-BYPASS-REASON
Decoy-Debug-Status
Decoy-Debug-Key
X-No-Session
Apigw-Requestid
Cache-Tv-Group
X-Via-Fastly
Cache-Name
X-Sql-Count
X-Sql-Duration-Ms
X-Uri
Property-Id
Mn-Server-Ip
Selected-Fe
TWC-GeoIP-Country
TWC-Connection-Speed
X-Origin-Hint
Protected
X-Web-Node
X-Time
X-Say-Cacheable
X-Say-TTL
X-SayCDN-TTL
Fastly-SSL
TWC-GeoIP-LatLong
X-PCL
TWC-Device-Class
X-OCL
X-Cache-Host
X-Akamai-Edgescape
X-Format
X-Proxy-Build
X-Timing-Wait
Webcakes-Region
X-UA-Device-Type
Webcakes-App-Name
X-Ratelimit-Reset
TWC-Privacy
Webcakes-App-Version
TWC-Locale-Group
Azure-Version
X-ApacheServer
X-Pubstack
Azure-SlotName
X-Extlb
X-Routing-Service
OT-Force-Account-Verify
X-Hl-Ver
X-Access
X-Proxied
DB-Nickname
X-NYM-Debug-Backend
X-PERF
X-Server-W
X-Zipkin-Id
Azure-SiteName
X-R9-Blue-Green-Version
X-Section
X-Azure-Ref-OriginShield
X-Varnishpool
Azure-InstanceId
Azure-RegionName
X-Rewrite-Enabled
Source
X-Cache-NGX
X-Be
X-LSADC-Cache
X-RateLimit-Limit
X-Tid
X-Cluster-Node
Content-Secure-Policy
X-Ua
X-Soup
X-SRV
X-HTML-Minification-Powered-By
X-Content-Age
Content-Disposition
X-NewRelic-App-Data
X-Cached-By
X-Cache-Var
X-Webkit-Csp
X-Cache-Var-Map
X-Amz-Meta-S3cmd-Attrs
SRV
CDN-RequestCountryCode
X-Unique-Id
CDN-RequestId
Cache
CDN-Cache
CDN-CachedAt
X-Generated-By
CDN-EdgeStorageId
CDN-Uid
CDN-PullZone
X-LAGOON
X-Varnish-Hits
X-Hyper-Cache
X-Loop
X-Varnish-Hostname
X-TNCMS
X-Bc-Bl
Webserver
X-TT-LOGID
Retry-After
Onion-Location
X-Dc
X-App-Version
X-S-Maxage
X-Origin-TTL
X-Origin-CC
X-Auto-Login
X-Tumblr-Pixel-3
X-Presslabs-Stats
X-Tumblr-Pixel-2
X-GEO
X-Nginx-Cache-Key
X-ECache
Cache-Hits
X-Proto
Web-Mar-Node
Xet-Cookie
X-Tenant
X-Time-Microsecs
X-Endurance-Cache-Level
X-Qnm-Cache
X-Ratelimit-Remaining
X-M-Log
X-M-Reqid
X-Cdn
X-CSRF-Token
X-Edge-Location
X-Akamai-Transformed
X-VWS-Id
X-AWS-Id
X-Platform-Server
X-LJ-Flow-ID
X-GG-Cache-Date
Mime-Version
LB
X-Trace-Id
CloudFront-Viewer-Country
HostName
X-Mg-Request-UUID
X-CACHE-KEY
X-Amz-Apigw-Id
X-Labrador-Cache-Channel
X-Amzn-RequestId
X-PHP-Host
N-Cache
X-Xfnlog-Site
X-B3-SpanId
X-Cache-Tags
X-Locale
X-RCS-CacheZone
X-Varnish-Cache-Hits
X-Storefront-Renderer-Rendered
X-Handled-By
Upgrade-Insecure-Requests
ServedBy
X-Origin-Response-Time
X-Request-Time
X-Adobe-Source
WPO-Cache-Status
WPO-Cache-Message
X-AOL-HN
X-VC-Cache
X-Cache-Remote
X-CF-Lambda-Fn
X-Aed
X-CF-Lambda-Version
X-Ckpd-Fst-Backend
X-Application
X-Cache-NE
X-B-Cookie
X-Cache-Date
X-Cluster
X-ARC
X-D
X-External-Request-Id
X-Forwarded-Path
X-Ftr-Request-Id
X-Reqid
X-Developer
X-Destination
X-Connection-Hash
X-NAPM-TraceId
X-ND-Cache
X-Conf
A
DCR-Processing-Time-Ms
DCR-Decision-By
Origin
Pramga
DSUID
Odigeo-Trace-Id
Fastcgi-X-Cache-Version
Expiry
Meta-Geo-Continent
Mobile-Detection-Method
Redirect-Candidate
Rendered-Blocks
X-A-Dcw
X-A-Dgt
X-Orig-Expires
X-A-Wwc
X-A-Dam
X-A-Ccd
State
Surrogated-Key
BehaviorPad-Version
X-A
Nel
X-Ig-Push-State
X-S
X-S-Cookie
X-ScT
X-Rojux
X-Vdms-Path
X-Planisys-CDN-TTL
X-Processor
X-Request-Host
X-SD-PageType
X-V-Cache
X-SVT-ORM-RULES
X-Slack-Backend
X-SRCache-Key
X-Shop-Environment
X-Session-Fingerprint
X-TIM-N
X-SVT-ORM-VERSION
X-Planisys-CDN-Rules
X-Vdms-Version
X-VG-WebCache
X-Via-NSCOPI
X-Vtex-Remote-Cache
X-ATG-Version
X-Planisys-CDN-Cache
X-PAYTM-SRV-ID
X-PBS-Appsvrname
X-Vtex-Processado-Em
Xc-Version
Datacenter
X-MP-GENERATED-AT
Server-Info
Environment
X-Correlation-ID
X-Gen-Mode
X-VServer
L
X-Sucuri-ID
X-Hnp-Log
Host-ID
Release
X-Block-Status
V-Age
Wxu-Next-Hostname
Wxu-Next-Commit
User-Cache-Control
Wxu-Next-Region
X-Varnish-Beresp-Status
Vix-Hermes-Req-Id
X-VG-TLSProxy
X-Fastly-Cache
X-Served-From
Gh-Request-Id
X-Li-Pop
X-Hash
X-Geo-Header
X-Forwarded-Site
X-Gdpr
X-LI-UUID
X-Location
X-Origin-Expires
X-Origin-Time
X-Old-Content-Length
X-Nyt-Route
X-Men
X-Mvc-Supplant-Cachable
X-Fetched-On
X-Policy
X-Owner
X-Cache-Info
X-Cache-Bucket
X-Server-IP
X-Accel-Expires-Debug
X-Skip-Cache
X-Scheme
X-Rocket-Nginx-Serving-Static
X-Device-Os
X-Epic-Correlation-Id
X-Proxy-Upstream
X-Date
X-Core-Mission
X-Sucuri-Cache
X-Li-Fabric
Cmsid
Cmstype
Fastcgi-Cache-TTL
CacheControlHeader
AKAMAI
From-Origin
AMP-Access-Control-Allow-Source-Origin
X-TIME
X-Gamma-Serve
X-Generated-On
X-Fastly-Backend
X-Esi-Check
X-Developers
X-GeoIP
X-GeoIP-City
X-Irp-Debug
X-HS-Content-Campaign-Id
X-HN
X-Gzip
X-Datadog-Trace-Id
X-Core-Value
X-Bip
X-Aicache-OS
X-TH-Server
Apple-News-Services-Handled
X-Branch-Name
X-Cache-Config
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
X-Cdn-Origin
X-Cache-Id
X-Level-Front-Cache
X-NodeID
X-EC-Lua
X-TrackingId
X-Thinkindot-L3
X-Thanos
X-VarnishDD-TTL
X-Viewer-Country
Origin-CC
CDCHOST
Arc-Country
Req-Svc-Chain
X-Sigma-Backend
X-Sigma
Apple-News-Services-Host
Traceparent
X-BBC-Edge-Cache-Status
X-Cache-Debug
X-Platform
X-Magnolia-Registration
X-Rocket-Build-Number
X-Request-Start
X-Req
X-Region-Sid
Origin-EX
X-Sn-Servicetimems
Candidate-Md5Url
Mail-Subject
We-Hiring
Web-Mar-Region
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
Machine
TDXMobile
Svr
Locid
Fastly-GeoIP-CountryCode
Thinkindot-Control
Apple-News-Services-Parsed-Url
PFcat
True-Client-Country-4JS
Apple-News-Services-Request-Url
Server-Host
X-Varnish-CookieHashed-On
X-Eu-Site
Fastly-SWR
X-Varnish-CookieINHashed-On
NGX
X-Csrf-Jwt
Fastly-SIE
X-Varnish-Remaining-TTL
X-Pod-Name
X-DefElseHash
X-DefHash
Memcached
X-UnsetCookies
X-Worker
X-DPWN-IS-SECURE
X-Variation
X-Origin
Is-Eu
X-RateLimit-Remaining-Second
X-Amzn-Remapped-Content-Length
X-JWT-State
X-Webstats-RespID
X-Is-Gdpr
X-RateLimit-Limit-Second
X-Loc
Platform
Adler-Geo
X-NU-AKA-ACS-Version
X-Qloud-Router
X-Backend-State
X-Zone
Ha-Gx-Prefs
X-Envoy-Decorator-Operation
HA-Ipaddr
X-FC-Vary-Parameters
L5d-Success-Class
X-CGP
X-Has-Esi
X-Request-URI
Cf-Device-Type
NM-Fastcgi-Cache
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-Xrds-Location
X-CS
X-FireWall-Port
Fastly-Drupal-Html
WWW-Authenticate
X-Cdn-Srv
X-Node-Id
X-Tx-Id
Sslversion
X-Trace-ID
X-Varnish-Beresp-Ttl
CDN
X-CLOUD-TRACE-CONTEXT
Ssr
X-LB-ID
X-API-Version
X-Response-By
On-Server
X-Up
X-Esi
Esi-Enabled
X-NC
X-Mvc-Supplant-OutputCached
WP-Super-Cache
X-Generated-In
Pics-Label
C-Via
X-Service
Ms-Author-Via
Memory
X-Vc
X-Refresh
Time
X-Datadome
X-Via-Poph
X-Backend-TTL
X-LB-NoCache
X-Cache-Enabled
NtCoent-Length
X-Via-Popv
X-Tt-Logid
X-Via-Popn
X-Cache-PHP
X-DynaTrace-JS-Agent
X-TA-CDN-Provider
X-DC
X-GeoIP-Region-Code
X-GeoIP-Country-Code
X-Tb-Optimization-Total-Bytes-Saved
Env
X-Edge-Pop
X-Varnish-Ttl
X-Dynatrace
X-NWS-UUID-VERIFY
X-TraceId
Magicmarker
X-Cache-Status-Check
X-Optimistic-Header
GeoIp-Country-Code
X-Parent-Response-Time
X-Render-Time
X-Info
X-Varnish-Beresp-TTL
Kp-EeAlive
X-Ua-Device
X-CacheTTL
X-Restarts
X-Servedbyhost
X-ZONE
X-Unique-ID
X-TX-ID
S-Rt
Server-ID
X-AIR-PT
X-Cs
X-Webkit-Csp-Report-Only
X-MSEdge-Features
X-Srv
X-RSL
X-Cache-Backend
X-MSEdge-Flight
Edge-Cache
X-Clientip
X-Wix-Viewer-Type
X-DW
X-Action
X-DB
X-RPM
X-DSS
X-DI
X-RPS
X-Oss-Hash-Crc64ecma
WebServer
X-Oss-Object-Type
X-Oss-Request-Id
X-Oss-Server-Time
X-Oss-Storage-Class
Proxy-Connection
X-VCL-Version
HIT
UCS
Cache-Host
X-Minions-Version
X-Traceid
X-Cache-Ttl
X-LI-Proto
S-Cnection
X-HA-Backend
X-Newrelic-Synthetics
X-Fpc
X-App
X-Li-Proto
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
X-URL
Lb
Section-Io-Id
Section-Origin-Responded
X-FPC
Test
X-LiteSpeed-Cache-Control
X-Akamai-Request-ID2
X-Http-Reason
X-Micro-Cache
Server-Id
User-Agent
Fastly-Backend-Name
X-B3-Spanid
X-Vcl-Version
X-NODE
X-Webkit-CSP-Report-Only
X-Backend-Host
Geo-Info
Tcn
Accept-Language
X-Ec-GeoHdr
X-Release
X-Ec-Fail
X-Pad
X-User
X-BCube-Filmed-By
X-Pass-Why
X-ES-SERVER
Locale
X-Check-Cacheable
X-APP
X-HostName
X-LiteSpeed-Tag
Cf-Int-Pingora-Origin-Digest
X-Urbn-Site-Id
Fastly-Drupal-HTML
X-Urbn-Context-Path
Resin-Trace
X-CSRF-TOKEN
CPC-Age
Cache-Key
X-ServedByHost
EpKe-Alive
X-ID
CPC-Cache
GeoIP-Country-Code
X-BBC-Origin-Response-Status
Path
VNS-Cache
VNS-Age
X-Amz-Meta-Cb-Modifiedtime
Hostname
X-Dynatrace-Js-Agent
Hit
X-WA
X-Edge-POP
X-WA-Info
X-Fmm-Version
X-Akamai-Pragma-Client-IP
M-TraceId
X-Clara-WADP
Srv
Ohc-File-Size
X-WADP-Cache
Cdnsip
X-AK-Request-ID
X-Ha-Backend
Cdncip
X-Geo
X-ElasticPress-Query
X-Via-PopH
X-Wikidot-Static-Cache
X-Wikidot-Backend
My-App
X-Cdn-Forward
Cluster
X-Cms-Context
X-Via-PopN
MIME-Version
Pagetype
X-PJAX-URL
ENV
X-Via-PopV
Shield-Pop
Tracecode
X-Api-Version
X-CUA
X-From
X-Hcs-Proxy-Type
X-Var-Ttl
Load-Balancing
X-Via-Ucdn
MD5-Digest
Lfy
X-CCDN-Origin-Time
X-HS-Status
X-Edge-Cache
X-NGINX-Cache
Geoip-Latitude
X-CCDN-CacheTTL
T-Server
URI
X-Ucs
X-Fastly-Cache-Hits
X-ServerName
X-VG-WebServer
X-GoCache-CacheStatus
X-Fragments
X-Fastly-Backend-Reqs
X-VC
X-RAMCache
X-UP
Lang
Servername
X-Cache-Expires
Sever-Int
W
Server-Hostname
Server-Ext
X-FORWARDED-FOR
X-Mcache
X-SIPLIST1
IsBot
X-TRACE-ID
X-Dw-Trace-Id
PICS-Label
Cteonnt-Length
Cneonction
X-Nc
X-Provided-By
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
Target-Params
Cdn
WZWS-RAY
X-Lb-Id
X-RateLimit-Reset
Ohc-Cache-HIT
X-Cdn-Request-ID
X-B3-ParentSpanId
CF-Cached-On
X-Newrelic-App-Data
X-Swift-Error
X-Apw-Hits
X-Via-CDN
X-Acquia-Application-Trace
X-Apw-Access-Object
Uri
X-Apw-Access-Token
X-Apw-Access-Action
X-Acquia-Site
X-Acquia-Application-UUID
X-Acquia-Purge-Tags
Dnion-Transfer-Encoding
Cf-Ipcountry
X-Contensis-Viewer-Groups
X-Snapshot-Date
X-Cc-Via
X-Akamai-Request-ID
HitType
X-Platform-Cluster
Vha6-Origin
X-Yottaa-OS
X-Platform-Router
X-Platform-Processor
X-Cache-ASPX
X-Cache-Ngx
Sid
X-Air-Pt
X-Te-Count
X-Last-Modified
GeoIP-Latitude
X-Akamai-ERRuleID
X-Te-Duration-Ms
Server-Ttl
X-Akamai-ERPolicy
X-Http-Duration-Ms
X-CacheKey
X-UA
Ngx
Req-ID
X-Sentry-ID
X-Varnish-Authentication
X-Miniprofiler-Ids
FSS-Cache
X-Lb-Nocache
CountryCode
X-B3-Parentspanid
X-Logging-Id
X-HTML-Edge-Cache
X-Http-Count