Threat Level: green Handler on Duty: Jan Kopriva

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Link
Cf-Request-Id
CF-Cache-Status
Accept-Ranges
CF-RAY
ETag
X-XSS-Protection
Expect-CT
Pragma
X-Powered-By
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-UA-Compatible
X-Cache-Hits
Alt-Svc
P3P
X-Served-By
X-Xss-Protection
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Request-Id
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Cache-Status
X-Generator
X-Cacheable
Timing-Allow-Origin
P3p
X-Content-Security-Policy
X-Iinfo
X-Request-ID
Status
Feature-Policy
X-Envoy-Upstream-Service-Time
Content-Encoding
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
X-CDN
X-AspNetMvc-Version
Upgrade
X-Via
CF-Ray
X-Ws-Request-Id
Access-Control-Max-Age
Server-Timing
EagleId
Keep-Alive
X-Cache-Group
X-Turbo-Charged-By
Request-Context
X-Age
X-Server-Powered-By
X-Proxy-Cache
X-AH-Environment
X-UA-Device
X-Backend
X-Hacker
X-Robots-Tag
Report-To
X-Amz-Request-Id
X-Server
Host-Header
X-Dns-Prefetch-Control
X-LiteSpeed-Cache
X-Amz-Id-2
Grace
X-Rq
X-Nginx-Cache-Status
X-Varnish-Cache
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-WebKit-CSP
X-Page-Speed
X-Vhost
EagleEye-TraceId
X-OneAgent-JS-Injection
X-Amz-Version-Id
X-Pingback
X-Dispatcher
X-Device
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Cache-Spec
NEL
X-Server-Id
X-Host
X-Backend-Server
Cf-Railgun
X-Node
X-Readtime
Accept-CH
X-Akam-SW-Version
Surrogate-Control
Request-Id
X-Response-Time
X-HW
Xkey
Accept-Ch-Lifetime
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Application-Context
Content-Location
X-Ruxit-JS-Agent
X-Ua-Compatible
Rating
X-Country
X-B3-TraceId
X-Language
X-Cloud-Trace-Context
X-Cache-Lookup
X-Ac
X-Content-Type
X-Template
X-Trace
X-Url
Allow
X-Varnish-TTL
X-TtlSet
X-Vname
X-PC
Accept-CH-Lifetime
X-Mod-Pagespeed
X-Clacks-Overhead
Edge-Control
X-FastCGI-Cache
X-ESI
Cache-Tag
Fastly-Restarts
X-Server-Name
X-Rack-Cache
Service-Worker-Allowed
X-VARITI-CCR
X-Element-Page-Cache
Verso
X-MS-InvokeApp
X-Buckets
X-GitHub-Request-Id
X-Upstream
Accept-Ch
X-Amz-Rid
X-Vcap-Request-Id
MS-Author-Via
Public-Key-Pins
X-Dw-Request-Base-Id
X-Cached
X-Client-IP
X-D2id
X-Abt-Application-Version
X-Origin-Cache
X-Cache-TTL
Arr-Disable-Session-Affinity
X-Px
X-ORACLE-DMS-RID
X-Cnection
X-ORACLE-DMS-ECID
X-Aws-Lambda-Call-Status
Access-Control-Request-Method
X-Powered-By-Plesk
X-Navigation-Version
X-NF-Request-ID
X-Country-Code
X-Kraken-Loop-Name
X-Instrumentation
X-Goog-Hash
X-Server-Lifecycle-Phase
RTSS
X-Version
X-Powered-CMS
X-Amz-Server-Side-Encryption
X-Middleton-Display
Display
Pagespeed
X-Sol
X-Kinja-Build
X-Kinja-Revision
X-Use-Magma
X-Kinja
X-Kinja-Server
X-GoogleNews-Bot
X-SRCache-Store-Status
X-Cdn-Fetch
X-Exp-Id
X-Exp-Variant
X-SRCache-Fetch-Status
X-Middleton-Response
Response
X-MSEdge-Ref
X-LLID
X-Edge
X-Kinsta-Cache
X-Edge-Location-Klb
AR-CACHE
AR-PoweredBy
AR-ATIME
AR-SID
AR-Request-ID
X-TTL
Nginx-Cache
MRF-Tech
X-B3-TraceId-Primal
Mrf-Cache-Status
X-Shield-Request-Id
X-HP-Trace-Id
X-Jurisdiction
X-HP-Webp
S
X-Protected-By
X-T
X-RateLimit-Remaining
TCN
X-Forwarded-For
Content-MD5
X-Content-Security-Policy-Report-Only
X-Aspnetmvc-Version
X-Id
X-CST
X-Mg-S
Realpath
X-Mid
Fastcgi-Cache
X-MCACHE
Edge-Cache-Tag
SPRequestDuration
SPIisLatency
Front-End-Https
X-Recruiting
X-Parallel-Accel
X-Request-Processing-Time
X-Request-Received
Filters
Server-Node
X-Pinterest-Rid
Pinterest-Version
Pinterest-Generated-By
Fusion-Source
Fusion-Template-Id
Fusion-Content-Source
Fusion-Deployment-Id
Fusion-Content-Id
Fusion-Component-Id
X-Ua-Browser
X-Content
X-Ab
X-SharePointHealthScore
SPRequestGuid
X-Ruxit-Js-Agent
Server-Name
X-Ttl
X-ECACHE
X-Ezoic-Cdn
X-DynaTrace
X-NWS-LOG-UUID
X-Frontend
Alternate-Protocol
X-HS-Content-Id
X-HS-Cache-Config
X-HS-Hub-Id
X-HS-Combine-CSS
X-Correlation-Id
X-Cache-Key
X-Yandex-Sdch-Disable
X-Hits
X-Accel-Expires
MicrosoftSharePointTeamServices
X-Content-Options
X-Tt-Trace-Host
X-Tt-Trace-Tag
Cache-Tags
Host
X-Page-Id
Charset
X-Git-Hash
X-Www-Served-By
X-B3-Sampled
X-Ser
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
Cleartype
X-Amz-Replication-Status
X-Daa-Tunnel
X-Geo-Country
X-Content-Digest
X-Forwarded-Proto
TP-L2-Cache
TP-Cache
X-Amzn-Trace-Id
Filterid
X-DIS-Request-ID
X-Varnish-Age
X-VCache
X-AppVersion
X-Activity-Id
X-Az
X-Hostname
X-Fastly-Request-Id
X-Debug-Info
X-N
X-Rid
X-Origin-Server
X-Upgrade-Enabled
Access-Control-Allow-Method
X-FB-Debug
X-Grace
X-LB-Cache
X-Nginx-Upstream-Cache-Status
X-XRDS-LOCATION
X-Origin-Upstream-Status
X-Microsite
X-Mobile-URL
X-Request-Handler-Origin-Region
Cross-Origin-Opener-Policy
X-Server-ID
X-Route-Name
X-Is-Crawler
X-Aspnet-Duration-Ms
X-Request-Guid
X-Flags
X-Providence-Cookie
ServerID
X-Whom
X-NGENIX-Cache
X-F-Cache
X-TT
X-App-Server
X-Varnish-Grace
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-GUploader-UploadID
X-Tb
X-Goog-Metageneration
X-FW-Serve
X-FW-Server
X-FW-Type
X-FW-Hash
X-FW-Dynamic
Payment
X-App-Environment
X-WebKit-CSP-Report-Only
X-FW-Static
X-Distributor
Node
Viewport
Paypal-Debug-Id
DC
X-Type
X-Logged-In
X-Cache-Control
X-Seen-By
Fastcgi-Useragent
X-Litespeed-Cache
X-User-Agent
Country
X-PressLabs-Stats
X-Ratelimit-Limit
Accept-Charset
X-Cache-Age
X-Webkit-CSP
X-Cache-Rule
X-Fastly-Request-ID
Version
X-Wix-Request-Id
X-Varnish-Backend
X-Node-Name
X-Erf-Bev-Bev
X-Load-Cache
X-Browser-Type
X-Erf-Bev-Bev-Is-Generated
Refresh
X-Cache-Action
X-IPLB-Instance
X-Drupal-Cache-Tags
Referer-Policy
Access-Control-Request-Headers
X-Response-Served-From
X-Original-Request-Id
SD-X-WS
X-Via-JSL
Cache-Status
X-Vgn-Hpd-Reason
X-DataDome
X-Jobs
X-Real-IP
X-Cacheable-TTL
VIX-Pulpo-Upstream-Status
X-B
X-Proxy-Cache-Status
X-ProcessESI
X-Cache-Expired-At
X-Debug
X-Cluster-Name
X-Is-Bot
X-Rendered-As
X-Page-View
X-RemovedCookies
Amp-Access-Control-Allow-Source-Origin
X-UUID
X-Fastcgi-Cache
X-Mobile
VIX-Pulpo-Node
X-Contextid
X-B-Cache
X-Yottaa-Optimizations
X-Revision
X-Proxy
X-Device-Type
X-Signature
X-Yottaa-Metrics
X-G
DynaTrace
X-Cache-Time
X-Rule
NGB
X-Tec-Api-Root
X-Drupal-Cache-Contexts
Surrogate-Key
X-Debug-IsConnected
X-Debug-IsPreview
X-Instance
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Tec-Api-Version
X-Tec-Api-Origin
Akamai-GRN
X-TEC-API-VERSION
X-Framework
Liferay-Portal
X-FW-Version
X-Air-Trace-Id
X-Air-Source
SID
X-Air-Hostname
X-Azure-Ref
Healthy
X-Oracle-Dms-Rid
X-Oracle-Dms-Ecid
CF-IPCountry
X-Source
X-Ms-Version
X-Ms-Request-Id
X-CDN-Forward
Frame-Options
X-Oneagent-Js-Injection
X-Nginx-Cache
MS-CV
X-RTag
Ms-Operation-Id
X-Cache-Hit
X-Environment-Context
X-L-Path
Countrycode
Count-Hit
X-XRDS-Location
X-Tumblr-Pixel-0
Xserver
X-Tumblr-Pixel-1
X-Varnish-Server
X-Tumblr-User
X-Tumblr-Pixel
X-Cache-Operation
GEO-INFO
Uber-Trace-Id
X-Region
Section-Io-Cache
X-Servername
X-APP-VERSION
X-Content-Powered-By
X-EdgeConnect-Cache-Status
X-Backend-Name
X-Forwarded-Host
X-Ratelimit-Reset
X-Accel-Buffering
X-Mode
X-IPS-LoggedIn
Cross-Origin-Window-Policy
X-Zen-Fury
Ec-Rule-Version
Backend
X-UPSTREAM-Address
Meta-Geo
X-RN-RSRV
X-JoinUs
X-SaId
X-Detected-As
X-ShardId
X-Cache-Server
X-Shopify-Stage
X-Cache-Grace
X-Cache-Type
X-Alternate-Cache-Key
X-Varnish-Beresp-Grace
X-Adobe-Content
X-Adobe-Loc
X-Tid
X-Sorting-Hat-ShopId
X-Generation-Time
X-Debug-Cache
X-Sorting-Hat-PodId
Eomportal-Instance
X-ShopId
X-Origin-Date
X-Sql-Duration-Ms
X-Sql-Count
X-NCache
X-UA-Device-Type
X-Cache-NGX
Country-Code
X-PHP-Backend
X-RateLimit-Limit
X-Uri
Cache-Tv-Group
X-BYPASS-REASON
Mn-Server-Ip
X-Cache-TTL-Remaining
X-No-Session
Cache-Name
DB-Nickname
X-FB-TRIP-ID
X-ProxyCache-Status
X-Microcachable
X-Via-Fastly
X-ServerID
Url
X-Human
Apigw-Requestid
X-ProxyCache-Key
X-Hosted-By
Decoy-Debug-Key
Fastly-SSL
Decoy-Debug-Status
Decoy-Debug-TTL
Webcakes-Region
X-Origin-Hint
X-PCL
X-Status
X-Akamai-Edgescape
X-Proxy-Build
X-Format
X-Storage
X-Timing-Wait
X-Site-Version
Webcakes-App-Version
X-Rewrite-Enabled
TWC-Device-Class
TWC-Connection-Speed
Selected-Fe
Protected
TWC-GeoIP-Country
TWC-GeoIP-LatLong
TWC-Privacy
X-OCL
TWC-Locale-Group
Property-Id
Webcakes-App-Name
X-Server-W
X-Routing-Service
X-Proxied
X-Redis-Cache
X-Section
X-Zipkin-Id
OT-Force-Account-Verify
X-PERF
X-Soup
X-Extlb
X-ApacheServer
X-Say-TTL
X-SayCDN-TTL
X-NYM-Debug-Backend
X-Hl-Ver
X-Say-Cacheable
X-Web-Node
X-Varnishpool
X-Cache-Host
X-R9-Blue-Green-Version
X-Access
Azure-SiteName
Azure-SlotName
Azure-Version
Azure-RegionName
Azure-InstanceId
X-LSADC-Cache
X-Azure-Ref-OriginShield
X-Cluster-Node
X-Pubstack
X-Be
Source
X-Webkit-Csp
X-App-Version
X-Ua
X-Presslabs-Stats
X-Content-Age
Content-Secure-Policy
X-Time
Content-Disposition
SRV
CDN-Cache
CDN-RequestId
CDN-PullZone
CDN-CachedAt
CDN-EdgeStorageId
X-HTML-Minification-Powered-By
Cache
CDN-Uid
CDN-RequestCountryCode
X-Cached-By
X-TT-LOGID
X-Hyper-Cache
X-Generated-By
X-Cache-Var-Map
X-Dc
X-LAGOON
X-NewRelic-App-Data
X-Cache-Var
X-Unique-Id
X-Amz-Meta-S3cmd-Attrs
X-TNCMS
X-Nginx-Cache-Key
X-Loop
X-Varnish-Hostname
X-Varnish-Hits
X-Bc-Bl
X-Auto-Login
X-SRV
Onion-Location
X-S-Maxage
X-Origin-TTL
LB
X-Trace-Id
X-Origin-CC
X-GEO
Cache-Hits
Webserver
Xet-Cookie
Retry-After
X-Cdn
X-Proto
Web-Mar-Node
X-Correlation-ID
X-Tumblr-Pixel-3
X-Tumblr-Pixel-2
X-Akamai-Transformed
HostName
X-Platform-Server
X-Tenant
X-Endurance-Cache-Level
X-CSRF-Token
X-Time-Microsecs
WPO-Cache-Status
X-Edge-Location
WPO-Cache-Message
X-Qnm-Cache
X-AWS-Id
X-VWS-Id
Mime-Version
X-GG-Cache-Date
X-LJ-Flow-ID
X-M-Log
X-M-Reqid
CloudFront-Viewer-Country
X-Xfnlog-Site
X-Cache-Remote
N-Cache
X-Cache-Tags
X-ECache
X-Xrds-Location
X-Mg-Request-UUID
X-B3-SpanId
Upgrade-Insecure-Requests
X-Amzn-RequestId
X-Varnish-Cache-Hits
X-Amz-Apigw-Id
X-TIME
X-Request-Time
X-Ratelimit-Remaining
ServedBy
X-AOL-HN
X-PHP-Host
X-Labrador-Cache-Channel
X-RCS-CacheZone
Nel
X-Handled-By
X-Locale
X-Via-NSCOPI
X-Rojux
X-PAYTM-SRV-ID
X-NAPM-TraceId
A
X-ND-Cache
X-Orig-Expires
X-PBS-Appsvrname
X-Processor
X-S
X-Vdms-Version
X-Vdms-Path
X-V-Cache
X-VG-WebCache
X-Vtex-Processado-Em
Xc-Version
X-Vtex-Remote-Cache
X-TIM-N
X-SVT-ORM-VERSION
X-SD-PageType
X-ScT
X-S-Cookie
X-Session-Fingerprint
X-Shop-Environment
X-SVT-ORM-RULES
X-SRCache-Key
X-Ig-Push-State
X-External-Request-Id
X-Ckpd-Fst-Backend
X-A-Ccd
X-CF-Lambda-Version
X-Cluster
X-A
Redirect-Candidate
Rendered-Blocks
Surrogated-Key
X-CF-Lambda-Fn
X-Cache-NE
X-B-Cookie
X-ARC
X-Application
X-A-Dgt
X-A-Dcw
X-A-Dam
X-Cache-Date
Pramga
Origin
DCR-Processing-Time-Ms
X-Developer
DSUID
X-A-Wwc
X-Forwarded-Path
DCR-Decision-By
X-Ftr-Request-Id
Expiry
X-Destination
X-Conf
Mobile-Detection-Method
Odigeo-Trace-Id
Meta-Geo-Continent
X-Connection-Hash
Fastcgi-X-Cache-Version
X-D
BehaviorPad-Version
X-Aed
X-Storefront-Renderer-Rendered
X-VC-Cache
X-Origin-Response-Time
X-MP-GENERATED-AT
X-Device-Os
X-Gen-Mode
X-Geo-Header
X-Gdpr
X-Fetched-On
Gh-Request-Id
Fastcgi-Cache-TTL
X-Epic-Correlation-Id
X-Li-Fabric
Cmsid
CDCHOST
CacheControlHeader
Cmstype
X-Location
Host-ID
X-Li-Pop
X-LI-UUID
X-Hash
X-Core-Mission
Wxu-Next-Commit
Wxu-Next-Hostname
X-CACHE-KEY
Vix-Hermes-Req-Id
V-Age
State
Traceparent
User-Cache-Control
Release
Wxu-Next-Region
X-Cache-Bucket
AMP-Access-Control-Allow-Source-Origin
X-Nyt-Route
Origin-CC
Origin-EX
X-Reqid
X-Block-Status
L
X-Hnp-Log
X-Scheme
X-Server-IP
Server-Info
X-Rocket-Nginx-Serving-Static
X-Request-Host
X-Skip-Cache
X-Slack-Backend
X-VServer
X-Varnish-Beresp-Status
X-Sucuri-ID
X-Sucuri-Cache
X-Policy
X-Served-From
X-Planisys-CDN-Rules
X-Owner
X-Origin-Expires
X-Origin-Time
X-Planisys-CDN-TTL
X-Planisys-CDN-Cache
AKAMAI
Arc-Country
X-Adobe-Source
X-FireWall-Port
Environment
X-BBC-Edge-Cache-Status
X-Bip
X-Accel-Expires-Debug
X-Sn-Servicetimems
X-Sigma-Backend
X-Mvc-Supplant-Cachable
X-Cache-Config
X-Branch-Name
X-ATG-Version
X-Thinkindot-L3
Thinkindot-Control
X-Aicache-OS
Thinkindot-CacheControl-Type
Sslversion
Thinkindot-CacheControl
True-Client-Country-4JS
X-Webstats-RespID
X-TrackingId
X-Cache-Debug
X-NodeID
X-VarnishDD-TTL
X-VG-TLSProxy
X-Thanos
X-Cdn-Srv
X-Gamma-Serve
X-Region-Sid
X-Forwarded-Site
X-Request-Start
X-Rocket-Build-Number
X-Generated-On
X-Proxy-Upstream
TDXMobile
X-Level-Front-Cache
X-HN
X-GeoIP-City
X-GeoIP
X-Fastly-Cache
X-Fastly-Backend
X-Magnolia-Registration
X-Core-Value
X-Platform
X-Cdn-Origin
X-Sigma
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
X-Developers
X-Date
X-Old-Content-Length
X-Datadog-Trace-Id
X-Cache-Info
X-Men
Apple-News-Services-Host
Req-Svc-Chain
Apple-News-Services-Handled
Svr
Apple-News-Services-Request-Url
PFcat
Locid
Server-Host
Apple-News-Services-Parsed-Url
From-Origin
X-EC-Lua
X-Irp-Debug
X-Is-Gdpr
Mail-Subject
X-Csrf-Jwt
L5d-Success-Class
Fastly-GeoIP-CountryCode
Machine
X-Worker
Memcached
Datacenter
X-UnsetCookies
NGX
Ssr
X-Gzip
X-Viewer-Country
X-JWT-State
X-CGP
X-Cache-Id
X-DefElseHash
X-Esi-Check
X-Varnish-CookieHashed-On
X-Envoy-Decorator-Operation
X-Eu-Site
HA-Ipaddr
X-Varnish-CookieINHashed-On
X-FC-Vary-Parameters
Ha-Gx-Prefs
X-Has-Esi
X-HS-Content-Campaign-Id
Fastly-SWR
X-DefHash
X-Varnish-Remaining-TTL
X-Variation
Is-Eu
X-DPWN-IS-SECURE
Fastly-Drupal-Html
Fastly-SIE
X-Loc
Candidate-Md5Url
X-CS
X-Response-By
X-Request-URI
Platform
X-Backend-State
X-NU-AKA-ACS-Version
X-Amzn-Remapped-Content-Length
X-Node-Id
NM-Fastcgi-Cache
Web-Mar-Region
We-Hiring
X-TH-Server
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-Qloud-Router
X-Pod-Name
X-Zone
Adler-Geo
Cf-Device-Type
X-Req
X-Origin
X-Ua-Device
X-Varnish-Beresp-Ttl
X-RateLimit-Limit-Second
X-Datadome
X-RateLimit-Remaining-Second
X-CLOUD-TRACE-CONTEXT
WP-Super-Cache
X-Tx-Id
WWW-Authenticate
Pics-Label
On-Server
X-Up
X-Mvc-Supplant-OutputCached
X-LB-ID
X-API-Version
CDN
X-Dynatrace
X-NC
Esi-Enabled
X-Backend-TTL
X-Vc
X-Generated-In
Ms-Author-Via
X-NWS-UUID-VERIFY
X-Trace-ID
NtCoent-Length
Time
Memory
X-LB-NoCache
X-Refresh
X-DynaTrace-JS-Agent
X-Cache-Enabled
C-Via
X-Service
X-Via-Popv
X-Via-Popn
X-GeoIP-Country-Code
Magicmarker
X-Edge-Pop
X-GeoIP-Region-Code
X-Via-Poph
X-URL
X-TA-CDN-Provider
X-Cache-PHP
X-Tb-Optimization-Total-Bytes-Saved
X-TraceId
X-Parent-Response-Time
X-DC
Kp-EeAlive
Env
GeoIp-Country-Code
X-Restarts
X-CacheTTL
X-Optimistic-Header
X-Tt-Logid
X-Srv
S-Rt
X-Servedbyhost
X-Render-Time
X-Cache-Status-Check
X-Esi
X-DSS
X-DB
X-DI
X-DW
WebServer
X-RPS
X-MSEdge-Features
X-MSEdge-Flight
Edge-Cache
X-RSL
X-RPM
X-ZONE
X-Action
X-Varnish-Beresp-TTL
X-Unique-ID
Server-ID
X-TX-ID
X-Info
X-Cache-Backend
X-Wix-Viewer-Type
X-Cs
X-Minions-Version
X-Webkit-CSP-Report-Only
X-AIR-PT
X-Http-Reason
X-Akamai-Request-ID2
X-HA-Backend
X-LI-Proto
X-Fpc
X-Traceid
X-App
X-VCL-Version
X-Newrelic-Synthetics
Proxy-Connection
X-Clientip
X-Cache-Ttl
X-Oss-Object-Type
X-Oss-Request-Id
UCS
X-Oss-Server-Time
X-Oss-Hash-Crc64ecma
X-Webkit-Csp-Report-Only
HIT
X-Varnish-Ttl
X-Li-Proto
Test
X-Oss-Storage-Class
Cache-Host
Accept-Language
S-Cnection
X-FPC
X-LiteSpeed-Cache-Control
X-NODE
X-Ec-GeoHdr
X-User
X-Vcl-Version
Server-Id
Tcn
X-Ec-Fail
Geo-Info
Section-Io-Origin-Time-Seconds
X-B3-Spanid
X-Urbn-Context-Path
Locale
Section-Io-Origin-Status
Lb
Section-Origin-Responded
Section-Io-Id
X-Urbn-Site-Id
Fastly-Backend-Name
User-Agent
X-Micro-Cache
X-Pass-Why
X-LiteSpeed-Tag
Cf-Int-Pingora-Origin-Digest
Fastly-Drupal-HTML
X-Backend-Host
X-Pad
X-HostName
X-CSRF-TOKEN
Cdnsip
Cdncip
X-AK-Request-ID
X-APP
M-TraceId
Resin-Trace
X-ID
GeoIP-Country-Code
X-BBC-Origin-Response-Status
X-Ha-Backend
X-BCube-Filmed-By
X-Release
Hostname
My-App
X-Check-Cacheable
Ohc-File-Size
Hit
X-ServedByHost
MIME-Version
X-Geo
X-Dynatrace-Js-Agent
X-ES-SERVER
X-Via-PopN
CPC-Cache
X-Edge-POP
X-WA-Info
CPC-Age
Path
X-CUA
X-Via-PopH
X-Var-Ttl
Tracecode
X-ElasticPress-Query
X-Via-PopV
ENV
VNS-Cache
VNS-Age
Cache-Key
X-Amz-Meta-Cb-Modifiedtime
X-WA
Geoip-Latitude
X-Clara-WADP
X-WADP-Cache
Cluster
EpKe-Alive
X-Fmm-Version
X-Edge-Cache
Lfy
T-Server
X-From
X-Api-Version
X-NGINX-Cache
X-HS-Status
Load-Balancing
Srv
X-Akamai-Pragma-Client-IP
Shield-Pop
X-Wikidot-Static-Cache
X-PJAX-URL
X-Wikidot-Backend
X-Cms-Context
X-Fragments
X-ServerName
Servername
URI
X-Cdn-Forward
X-Ucs
Lang
Pagetype
X-GoCache-CacheStatus
X-Fastly-Backend-Reqs
X-WP-CF-Super-Cache-Cache-Control
X-Via-Ucdn
X-WP-CF-Super-Cache
X-Newrelic-App-Data
X-Hcs-Proxy-Type
X-CCDN-CacheTTL
X-CCDN-Origin-Time
X-Fastly-Cache-Hits
Target-Params
X-UP
X-RAMCache
X-Nc
MD5-Digest
X-Mcache
X-Dw-Trace-Id
Cf-Ipcountry
X-TRACE-ID
X-Lb-Id
WZWS-RAY
X-Cdn-Request-ID
Uri
X-VC
Server-Ext
X-RateLimit-Reset
X-SIPLIST1
Cdn
Cneonction
X-B3-ParentSpanId
Ohc-Cache-HIT
X-VG-WebServer
IsBot
Sever-Int
Server-Hostname
DataCenter
X-Cache-Expires
CF-Cached-On
X-Cache-ASPX
PICS-Label
X-Apw-Hits
X-Apw-Access-Object
X-Acquia-Purge-Tags
X-Acquia-Site
X-Acquia-Application-UUID
X-Acquia-Application-Trace
X-Snapshot-Date
X-Apw-Access-Action
X-Apw-Access-Token
X-Contensis-Viewer-Groups
X-Swift-Error
W
Vha6-Origin
X-Yottaa-OS
Cteonnt-Length
X-Air-Pt
Sid
X-Cache-Ngx
X-Akamai-ERPolicy
X-Http-Count
X-Akamai-ERRuleID
HitType
X-Last-Modified
Server-Ttl
X-Http-Duration-Ms
X-B3-Parentspanid
GeoIP-Latitude
FSS-Cache
X-Te-Duration-Ms
Permissions-Policy
X-Te-Count
X-Provided-By
X-Platform-Cluster
CountryCode
X-Logging-Id
Req-ID
X-UA
X-CacheKey
X-Platform-Processor
X-Akamai-Request-ID
Dnion-Transfer-Encoding
X-Lb-Nocache
Ngx
X-Sentry-ID
X-Platform-Router
X-Varnish-Authentication
X-Miniprofiler-Ids