Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
X-Powered-By
Pragma
X-XSS-Protection
CF-RAY
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
Alt-Svc
X-Xss-Protection
P3P
X-Cache-Hits
X-UA-Compatible
CF-Ray
X-Served-By
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
Access-Control-Allow-Credentials
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
X-Drupal-Cache
X-Cache-Status
X-Generator
X-Check
X-Cacheable
X-Envoy-Upstream-Service-Time
X-FRAME-OPTIONS
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Iinfo
X-Dns-Prefetch-Control
Server-Timing
X-Drupal-Dynamic-Cache
Feature-Policy
X-Content-Security-Policy
Access-Control-Expose-Headers
Content-Encoding
X-CDN
Status
X-XSS-PROTECTION
Upgrade
X-Request-ID
X-AspNetMvc-Version
Access-Control-Max-Age
X-Amz-Request-Id
X-Via
X-Amz-Id-2
Request-Context
X-Ua-Compatible
X-Backend
X-Cache-Group
X-Turbo-Charged-By
X-Robots-Tag
Cf-Edge-Cache
Keep-Alive
Host-Header
X-AH-Environment
X-UA-Device
X-Vhost
X-Hacker
X-Proxy-Cache
X-Server
Allow
X-Rq
X-Server-Powered-By
X-Ws-Request-Id
X-Dispatcher
X-Age
EagleId
X-Varnish-Cache
X-Amz-Version-Id
P3p
Nel
Grace
X-LiteSpeed-Cache
Cf-Apo-Via
Cf-Railgun
X-Page-Speed
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
EagleEye-TraceId
X-Device
X-Swift-CacheTime
X-Swift-SaveTime
X-OneAgent-JS-Injection
X-Aws-Lambda-Call-Status
Ali-Swift-Global-Savetime
X-Pingback
X-Host
Accept-CH
X-Cache-Lookup
X-WebKit-CSP
X-CST
X-Node
X-Backend-Server
Surrogate-Control
Permissions-Policy
X-Readtime
X-Nginx-Upstream-Cache-Status
X-Nginx-Cache-Status
X-Akam-SW-Version
X-Server-Id
X-EdgeConnect-Origin-MEX-Latency
X-Application-Context
X-EdgeConnect-MidMile-RTT
Request-Id
Accept-CH-Lifetime
X-Ruxit-JS-Agent
Xkey
X-Cloud-Trace-Context
X-Content-Security-Policy-Report-Only
X-Response-Time
X-HW
X-Trace
X-Edge
Content-Location
X-Clacks-Overhead
X-Mod-Pagespeed
X-Url
Rating
X-ESI
X-Midtier
X-Amz-Server-Side-Encryption
X-ECACHE
Cache-Tag
X-Mcache
X-Country
Accept-Ch-Lifetime
X-Rack-Cache
X-MS-InvokeApp
X-Powered-By-Plesk
X-D2id
Service-Worker-Allowed
X-Exp-Variant
X-Cdn-Fetch
X-GoogleNews-Bot
X-Exp-Id
X-Kinja
X-Use-Magma
X-Kinja-Build
X-Kinja-Server
X-Kinja-Revision
Verso
X-Vcap-Request-Id
X-Element-Page-Cache
X-Upstream
Accept-Ch
Edge-Control
X-Oneagent-Js-Injection
X-Litespeed-Cache
X-Country-Code
X-Ac
X-Goog-Hash
Origin-Trial
X-PC
X-TtlSet
X-Vname
RTSS
X-VARITI-CCR
X-Navigation-Version
X-Kinja-CCPA
X-Abt-Application-Version
X-Cache-TTL
X-Browser-Type
Fastly-Restarts
X-Amz-Rid
X-Varnish-TTL
X-NWS-LOG-UUID
X-GitHub-Request-Id
Cross-Origin-Opener-Policy
X-Aspnetmvc-Version
X-Cached
X-Server-ID
X-Server-Name
X-Webkit-CSP
X-Dw-Request-Base-Id
X-Amzn-Trace-Id
Display
Pagespeed
X-Sol
X-Middleton-Display
X-Times
X-WebKit-CSP-Report-Only
SPRequestGuid
X-SharePointHealthScore
X-Ttl
X-Pinterest-Rid
Pinterest-Generated-By
Pinterest-Version
SPIisLatency
SPRequestDuration
X-Content-Type
X-Erf-Bev-Bev
X-Instrumentation
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-Erf-Bev-Bev-Is-Generated
X-Cache-Key
X-Ruxit-Js-Agent
AR-ATIME
AR-SID
AR-Request-ID
AR-PoweredBy
X-Powered-CMS
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
X-B3-Traceid
Arr-Disable-Session-Affinity
X-Mg-S
X-Version
X-Client-IP
X-Cnection
X-Ser
Response
X-Middleton-Response
Nginx-Cache
X-HP-Trace-Id
X-Jurisdiction
X-HP-Webp
X-FastCGI-Cache
X-Accel-Expires
Cache-Tags
AR-CACHE
X-T
X-Fastly-Request-ID
X-SRCache-Store-Status
X-SRCache-Fetch-Status
Cache-Status
Edge-Cache-Tag
X-B3-TraceId
X-Hits
X-MSEdge-Ref
X-Px
Public-Key-Pins
X-NF-Request-ID
Front-End-Https
X-Recruiting
S
X-Shield-Request-Id
X-Daa-Tunnel
Payment
X-RateLimit-Remaining
X-Frontend
X-LLID
Server-Node
X-Ua-Browser
X-Request-Received
X-Request-Processing-Time
X-B3-TraceId-Primal
Mrf-Cache-Status
X-GUploader-UploadID
X-Goog-Metageneration
MRF-Tech
Content-MD5
X-Webkit-CSP-Report-Only
MicrosoftSharePointTeamServices
Access-Control-Request-Method
X-RateLimit-Limit
X-Content-Digest
X-DIS-Request-ID
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Ratelimit-Remaining
X-Forwarded-For
TP-Cache
Realpath
X-Protected-By
X-Request-Handler-Origin-Region
X-Microsite
X-Distributor
X-Fastcgi-Cache
X-PressLabs-Stats
X-FB-Debug
X-HS-Hub-Id
X-HS-Content-Id
X-Xrds-Location
X-HS-Cache-Config
X-TTL
X-HS-Combine-CSS
Fastcgi-Cache
Access-Control-Allow-Method
X-Page-Id
X-LB-Cache
Accept-Charset
X-Cluster-Name
X-Rid
Count-Hit
X-Goog-Generation
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Hostname
X-B3-Sampled
X-Id
X-Edge-Location-Klb
X-Kinsta-Cache
X-Ratelimit-Limit
X-Geo-Country
TP-L2-Cache
X-Aspnet-Version
Cross-Origin-Resource-Policy
X-Ua-Device
X-Correlation-Id
X-Seen-By
X-TEC-API-ROOT
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-App-Server
TCN
X-Logged-In
X-Varnish-Backend
Cleartype
X-Ezoic-Cdn
X-Git-Hash
X-Content-Options
X-Hosted-By
X-Erf-Stays-Pdp-Viaduct-Migration-Web
Referer-Policy
DC
X-Mobile
X-Newrelic-App-Data
Retry-After
X-Fb-Rlafr
X-Origin-Cache
X-Contextid
X-Flags
X-Is-Crawler
X-Providence-Cookie
X-Request-Guid
X-Route-Name
X-Aspnet-Duration-Ms
X-Forwarded-Proto
Surrogate-Key
X-Grace
X-F-Cache
X-Revision
X-Amz-Replication-Status
X-Debug-Info
X-App-Environment
X-TT
Frame-Options
X-Varnish-Grace
X-Amz-Meta-S3cmd-Attrs
X-IPS-LoggedIn
X-Envoy-Decorator-Operation
X-Azure-Ref
MS-Author-Via
Section-Io-Cache
X-Magnolia-Registration
X-Www-Served-By
X-Wix-Request-Id
X-Proxy-Cache-Info
X-App-Version
Healthy
X-Whom
X-Language
X-Activity-Id
X-AppVersion
X-Az
Charset
X-RateLimit-Reset
X-Nf-Request-Id
X-Akamai-Edgescape
Filterid
X-COUNTRY
Alternate-Protocol
Viewport
WPO-Cache-Status
WPO-Cache-Message
Amp-Access-Control-Allow-Source-Origin
X-Webkit-Csp
X-Trace-Id
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Backend-Name
X-EdgeConnect-Cache-Status
X-Varnish-Server
Server-Name
X-Origin-Server
X-Datadog-Parent-Id
X-Datadog-Trace-Id
Paypal-Debug-Id
X-Datadog-Sampling-Priority
X-B
X-Cache-Rule
X-Response-Served-From
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-Original-Request-Id
Host
X-Http-Reason
SRV
X-Rule
X-User-Agent
Front
X-DataDome
X-Vcache
X-UUID
X-Akamai-Request-ID2
X-Instance
X-Edge-Location
X-Cache-Grace
X-Region
Content-Disposition
X-Page-View
X-Unique-Id
X-N
X-Jobs
X-L-Path
X-Yottaa-Optimizations
X-Time
X-Environment-Context
From-Origin
Country
X-Yottaa-Metrics
SD-X-WS
X-ARC
X-Cacheable-TTL
Protected
Fastly-SIE
Fastly-SWR
X-Rocket-Nginx-Serving-Static
X-Rendered-As
Akamai-GRN
X-Is-Bot
X-Signature
X-B-Cache
X-Status
X-Adobe-Content
X-ProcessESI
X-Load-Cache
X-Client-Ip
X-Varnish-Age
X-Adobe-Loc
X-RemovedCookies
X-Framework
X-FW-Serve
X-FW-Version
X-Tumblr-Pixel-0
X-FW-Dynamic
X-FW-Static
X-FW-Type
X-FW-Hash
X-Cache-Time
X-Proxy
X-Datadog-Sampled
X-G
X-Tumblr-Pixel
X-FW-Server
X-Mg-Request-UUID
X-Tumblr-User
X-Type
X-Tumblr-Pixel-1
X-Debug-IsPreview
X-Debug-IsConnected
X-Amzn-Remapped-Content-Length
Access-Control-Request-Headers
ServerID
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
X-CDN-Forward
Backend
X-ECache
X-Cache-Age
X-Tec-Api-Version
X-Tec-Api-Origin
X-Tec-Api-Root
X-Nginx-Cache
X-Cache-Control
Refresh
Xet-Cookie
X-Servername
Countrycode
X-DynaTrace
Url
X-Tt-Trace-Host
X-Httpd
X-Tt-Trace-Tag
X-Erf-Web-Scheduler
Accept-Language
X-Drupal-Cache-Tags
X-Template
CF-IPCountry
X-DynaTrace-JS-Agent
X-Mode
X-Device-Type
X-Content-Powered-By
X-NYM-Debug-Backend
X-Generated-By
X-HTML-Minification-Powered-By
Xserver
X-Cache-Hit
X-Storage
X-Source
X-Hcs-Proxy-Type
X-CCDN-CacheTTL
GEO-INFO
Version
X-CCDN-Origin-Time
X-Cache-Operation
S-Rt
X-Content-Age
X-GeoCode
X-GeoCountry
Load-Balancing
Filters
Meta-Geo
X-Director
X-LAGOON
X-Rn-Rsrv
X-Urbn-Context-Path
X-ServerID
Locale
X-UPSTREAM-Address
X-SaId
X-Rewrite-Enabled
X-Tncms
X-SayCDN-TTL
X-Urbn-Site-Id
X-Say-Cacheable
X-Say-TTL
X-Loop
X-JoinUs
X-FTR-Request-ID
OT-Force-Account-Verify
X-Cache-Action
X-Forwarded-Host
X-Cluster-Node
X-Container-Uri
X-Soup
X-Varnish-Cache-Hits
Onion-Location
X-Tt-Logid
Cross-Origin-Window-Policy
X-Git-Commit
X-Detected-As
X-Served-From
Azure-SiteName
Azure-RegionName
X-Tb
X-Sql-Duration-Ms
Web-Mar-Node
Azure-InstanceId
X-Adobe-Source
X-Sql-Count
Azure-SlotName
X-Skip-Cache
X-Varnish-Hostname
X-B3-SpanId
X-VCT
X-PHP-Host
X-Ms-Version
X-Labrador-Cache-Channel
X-Lambda-Id
X-Ms-Request-Id
X-NGENIX-Cache
X-VC-Cache
X-RM-Cache-TTL
Azure-Version
Webserver
X-R9-Blue-Green-Version
X-Proxied
X-Logging-Id
X-Routing-Service
X-FB-TRIP-ID
X-Cache-Server
X-RCS-CacheZone
X-XRDS-LOCATION
X-Extlb
Mn-Server-Ip
X-Zipkin-Id
DB-Nickname
Node
X-URL
TWC-Connection-Speed
Property-Id
TWC-Device-Class
Selected-Fe
X-Tumblr-Pixel-2
X-Format
X-Fetched-On
X-Tumblr-Pixel-3
X-Uri
X-Generation-Time
X-Origin-Hint
X-Proxy-Build
X-Debug
X-Redis-Cache
TWC-Privacy
TWC-Locale-Group
Webcakes-App-Name
Webcakes-App-Version
Webcakes-Region
X-Timing-Wait
TWC-GeoIP-LatLong
TWC-GeoIP-Country
X-MCACHE
Fastcgi-Useragent
X-Proto
X-Oracle-Dms-Ecid
X-Oracle-Dms-Rid
X-Endurance-Cache-Level
Uber-Trace-Id
Source
X-Zen-Fury
CDN-RequestId
X-LSADC-Cache
X-Ratelimit-Reset
X-Sucuri-ID
X-Sucuri-Cache
X-S
Section-Io-Id
Section-Io-Origin-Time-Seconds
X-XRDS-Location
X-Ua
X-Newrelic-Synthetics
Section-Origin-Responded
Section-Io-Origin-Status
NGB
X-Origin-CC
X-Origin-TTL
X-Drupal-Cache-Contexts
X-TimeS
X-Srv
Upgrade-Insecure-Requests
X-MP-GENERATED-AT
X-Akamai-Transformed
X-Origin-Date
Fastly-Drupal-HTML
X-Real-IP
X-Pass-Why
X-Cache-Expired-At
X-Handled-By
X-Varnish-Hits
X-Xfnlog-Site
Liferay-Portal
X-Reqid
MS-CV
X-Optimistic-Header
Apigw-Requestid
X-Cms-Context
Ms-Operation-Id
X-No-Session
X-RTag
X-CACHE-AGE
X-Restarts
ServedBy
X-GEO
X-BYPASS-REASON
X-ProxyCache-Key
X-ProxyCache-Status
X-Cache-Host
X-AB
X-TraceId
WP-Super-Cache
X-Hl-Ver
X-Tx-Id
CDN-RequestCountryCode
CDN-RequestPullCode
CDN-CachedAt
X-UA-Device-Type
CDN-Cache
CDN-RequestPullSuccess
CDN-EdgeStorageId
CDN-PullZone
X-Cache-TTL-Remaining
X-IPLB-Request-ID
X-LJ-Flow-ID
X-VWS-Id
X-Cluster
X-Cache-Type
X-CSRF-Token
X-AWS-Id
CDN-Uid
X-IPLB-Instance
X-Node-Name
X-Upgrade-Enabled
X-Via-JSL
X-Parent-Response-Time
X-Geo-Region
X-Varnish-Ttl
X-Fastly-Request-Id
X-Pubstack
Cache-Provider
X-Proxy-Cache-Status
X-B-Cookie
X-Fastly-Backend
X-Ec-Fail
X-FC-Vary-Parameters
X-Application
X-App
Candidate-Md5Url
Canary
X-Bc-Bl
BehaviorPad-Version
X-Ec-GeoHdr
X-PAYTM-SRV-ID
X-Worker
X-Cache-Status-Check
X-Cache-NE
X-Eu-Site
X-Destination
Xc-Version
X-Bl-Debug
X-Vdms-Version
DCR-Decision-By
X-Vdms-Path
X-BCube-Filmed-By
Fastly-SSL
X-A-Dam
X-A-Ccd
Rendered-Blocks
Redirect-Candidate
X-A-Dgt
X-A-Dcw
Server-Host
X-A
T-Server
True-Client-Country-4JS
Surrogated-Key
Sslversion
Web-Mar-Region
W
X-A-Wwc
Origin-Agent-Cluster
L
L5d-Success-Class
HA-Ipaddr
Ha-Gx-Prefs
X-Request-Host
Gannett-Cam-Experience-Id
Lang
Magicmarker
Ngx.Var.Host
Odigeo-Trace-Id
N-Cache
Meta-Geo-Continent
MD5-Digest
X-Aed
DCR-Processing-Time-Ms
X-External-Request-Id
X-Viewer-Country
X-Slack-Shared-Secret-Outcome
X-Ec-Custom-Error
X-S-Cookie
X-CGP
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-Dispatcher-Number
X-D
X-Debug-Cache-Store
X-Conf
X-Vtex-Remote-Cache
X-Epic-Correlation-Id
X-Csrf-Jwt
X-ScT
X-Developer
X-Slack-Backend
Vix-Hermes-Req-Id
X-Debug-Cache-Fetch
X-CacheTTL
X-Rojux
X-SRCache-Key
X-Micro-Cache
X-Server-W
Cache-Name
Host-ID
X-Core-Mission
X-Shop-Environment
Gh-Request-Id
TDXMobile
Is-Eu
X-Core-Value
X-VServer
X-Server-IP
X-Loc
X-Mid
Expect-Staple
X-Alternate-Cache-Key
X-Mvc-Supplant-Cachable
X-Forwarded-Path
VNS-Cache
Fastly-Backend-Name
X-Mly-Id
X-ShardId
X-ShopId
Fastly-GeoIP-CountryCode
Environment
X-Irp-Debug
X-Sorting-Hat-PodId
X-Hash
X-Human
X-Sn-Servicetimems
Origin
X-Thanos
X-Storefront-Renderer-Rendered
Req-Svc-Chain
X-Qloud-Router
X-Sorting-Hat-ShopId
Producers
Platform
X-Vmg-Version
X-Accel-Buffering
Mail-Subject
X-GeoIP-Region-Code
X-SVT-ORM-VERSION
X-Shopify-Stage
Release
X-SVT-ORM-RULES
X-Gdpr
X-Owner
X-Accel-Expires-Debug
Datacenter
We-Hiring
X-Tenant
X-App-Name
X-Dispatcher-Server
X-Date
X-AIR-PT
X-Varnish-CookieINHashed-On
X-Bip
X-DefHash
X-Varnish-Remaining-TTL
X-VG-TLSProxy
X-Origin-Time
X-We-Are-Hiring
X-Varnishpool
X-DPWN-IS-SECURE
X-Var-Ttl
X-Generated-On
X-Cdn-Origin
X-Cdn-Diag
X-Cache-Info
X-Wix-Viewer-Type
X-Wikidot-Static-Cache
X-Refresh
X-Wikidot-Backend
X-Geo-Header
X-Policy
X-Cache-Bucket
X-Varnish-CookieHashed-On
X-Variation
X-Platform
X-Cache-Debug
CPC-Cache
X-Pool
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
X-Nitro-Cache
X-Thinkindot-L3
X-Up
X-Nananana
X-Level-Front-Cache
Cmsid
Cmstype
CloudFront-Viewer-Country
X-GeoIP-Country-Code
X-VG-WebCache
CPC-Age
X-CMSURLCustom
X-Old-Content-Length
X-Nyt-Route
Thinkindot-Control
VNS-Age
X-Orig-Expires
X-SD-PageType
X-NodeID
AKAMAI
X-BBC-Edge-Cache-Status
Adler-Geo
X-DefElseHash
X-Clientip
X-Request-Time
X-TIME
User-Cache-Control
X-ApacheServer
X-Block-Status
X-Clara-WADP
X-Cache-Id
X-Device-Os
X-Auto-Login
X-Forwarded-Site
X-Esi-Check
X-Fmm-Version
X-From
X-Origin
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
Apple-News-Services-Handled
X-Node-Id
X-Gen-Mode
Apple-News-Services-Request-Url
X-Nginx-Cache-Key
Cf-Device-Type
X-Mvc-Supplant-OutputCached
CDCHOST
X-NCache
X-Org
X-Origin-Response-Time
X-Correlation-ID
X-WA-Info
X-WADP-Cache
Machine
X-Test
X-Vgn-Hpd-Reason
X-PERF
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-S-Maxage
Country-Code
X-Op-Id-All
X-Gzip
X-Hnp-Log
NM-Fastcgi-Cache
Server-Ext
Sever-Int
DSUID
X-GeoIP
Esi-Enabled
Server-Hostname
X-Accel-Version
X-Is-Mobile
X-Browser-Name
X-Is-Desktop
X-Is-Tablet
X-Tcp-Rtt
X-Is-Supported-Browser
X-Section
X-Via-Fastly
X-LB-NoCache
X-Instance-Name
Pics-Label
X-Ah-Environment
Server-Info
X-Datadome
Ssr
Wxu-Next-Commit
C-Via
Wxu-Next-Hostname
X-Cache-Enabled
X-Cdn-Srv
NGX
Wxu-Next-Region
X-INCAP-ABP
X-Access
X-B3-Spanid
X-Buckets
Content-Secure-Policy
Server-ID
X-Varnish-Beresp-Ttl
X-Amz-Meta-Cb-Modifiedtime
X-Varnish-Beresp-Grace
X-Akamai-Device-Characteristics
AMP-Access-Control-Allow-Source-Origin
X-Vcl-Version
X-API-Version
IsBot
X-Zone
X-Dc
X-HA-Backend
X-CACHE-GROUP
X-SIPLIST1
X-Presslabs-Stats
X-Origin-Cache-Key
YJS-ID
X-B3-Parentspanid
X-WP-CF-Super-Cache-Active
Sid
X-Platform-Cluster
X-JWT-State
X-Has-Esi
X-Is-Gdpr
Memcached
X-Platform-Processor
CF-Ctrl
X-Cached-By
X-ID
X-Platform-Router
Memory
Cdn-Requestid
Hostname
X-Tb-Optimization-Total-Bytes-Saved
X-Frame-Option
Location
X-Wp-Cf-Super-Cache-Active
Time
X-TA-CDN-Provider
Origin-CC
X-Air-Trace-Id
X-Air-Hostname
X-Fpc
Origin-EX
X-Hyper-Cache
Cache-Hits
X-Internal-Host
X-Air-Source
X-Scale
X-Country-Code-Real
X-TIM-N
X-FTR-Cache-Status
X-DC
X-FTR-Backend
X-FTR-Balancer
X-FTR-Backend-Server
X-FTR-Expires
X-Backend-Instance
X-ZONE
X-PHP-Backend
X-Webstats-RespID
X-Cs
X-VC
X-Service
Resin-Trace
X-LiteSpeed-Cache-Control
LB
X-Site-Version
X-Azure-Ref-OriginShield
Epwk-X-Cache
Uri
X-DataCenter
True-Client-Ip
X-NewRelic-App-Data
X-NGINX-Cache
X-SRV
X-Microcachable
GeoIP-Latitude
GeoIP-Country-Code
WebServer
X-Nitro-Rev
X-NMSegId
X-Nitro-Cache-From
Req-ID
X-Origin-Expires
X-Locale
Cache-Host
WZWS-RAY
X-Edge-Server
Cdn-Host
X-NODE
GeoIp-Country-Code
Cdn-Request-Time
X-VCache
X-Ad-Load-Variation
X-Datacenter
XM
X-Info
XServer
X-Cache-Ttl
Cdn
X-CSRF-TOKEN
X-Request-URI
X-Scope-Id
True-Client-IP
X-Vercel-Cache
X-Vercel-Id
X-VarnishDD-TTL
X-Request-Start
X-Pad
M-TraceId
X-Pod-Name
NtCoent-Length
X-M-Reqid
X-M-Log
Pramga
X-HN
PFcat
HostName
SID
X-Geo
X-Web-Node
X-Ad-Defer-Variation
Cluster
X-Shield-Cache-Expires
X-Varnish-Beresp-Status
X-WP-CF-Super-Cache-Cookies-Bypass
User-Agent
X-Qnm-Cache
Content-Script-Type
Content-Style-Type
X-Github-Request-Id
X-FL-EDGE
X-FL-QIT-DEBUG
X-CS
X-Cache-Date
X-Via-CDN
X-Via-Edge
Fastly-Drupal-Html
X-Via-SSL
X-MSEdge-Features
Srvid
Locid
A
X-FPC
Edge-Copy-Time
Cache-Tv-Group
X-MSEdge-Flight
Tcn
X-HostName
X-TH-Server
Edge-Cache
X-Cdn-Request-ID
X-APP-VERSION
CountryCode
Cf-Ipcountry
X-Api-Version
X-Contensis-Viewer-Groups
X-AK-Request-ID
Cdncip
X-Amz-Meta-Opti
X-NWS-UUID-VERIFY
Cdnsip
Tube-Return
X-VCL-Version
X-Nc
X-LB-ID
X-Cache-FS-Status
X-Wa
X-B3-Trace-ID
X-Servedbyhost
X-V-Cache
X-ATG-Version
X-Via-Popv
X-FireWall-Port
X-Via-Popn
X-Via-Poph
X-Esi
X-Aicache-OS
X-Moov-T
X-Cache-ASPX
X-Moov-Xdn-Version
Tube-Get-Contents
Click-Count-Error
Click-Count-Action-Start
Path
X-Webkit-Csp-Report-Only
X-Varnish-Authentication
X-Acquia-Purge-Cdn-Unconfigured
Tube-Got-Eval
Tube-Got-Results
X-LiteSpeed-Tag
X-Vary
On-Server
Cache-Key
X-Men
X-UA
MIME-Version
X-Req
V-Age
X-SB
X-Branch-Name
X-Wp-Cf-Super-Cache-Cookies-Bypass
Priority
X-Proxy-CacheRZ
XkeyRZ
Yak-Timeinfo
Ngx-Var-Key
X-TRACE-ID
X-CACHE-KEY
CDN
X-Tim-N
My-App
X-Render-Time
Geoip-Latitude
Wpo-Cache-Status
X-Acquia-Purge-Tags
X-Acquia-Application-UUID
X-Acquia-Application-Trace
X-Wp-Cf-Super-Cache
X-Wp-Cf-Super-Cache-Cache-Control
X-Acquia-Site
Srv
Wpo-Cache-Message
Proxy-Connection
X-Akamai-Pragma-Client-IP
X-Cdn-Forward
X-Rebelmouse-Cache-Control
X-Lb-Cache
X-Rebelmouse-Surrogate-Control
X-Fastly-Backend-Reqs
X-Planisys-CDN-TTL
X-Provided-By
X-HS-Content-Campaign-Id
X-Fastly-Country-Code
X-Varnish-Director
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
Lb
X-Platform-Server
State
X-Air-Pt
X-User
X-Ha-Backend
X-Generated-In
Server-Id
X-TT-LOGID
X-Lb-Nocache
X-Fastly-Cache
Fusion-Template-Id
CF-Cached-On
X-Cdn-Cache-Status
Ohc-File-Size
X-Release
Ohc-Cache-HIT
X-EC-Lua
X-Vgn-Hpd-Cached
Type
Fusion-Component-Id
X-CUA
Fusion-Content-Id
Fusion-Content-Source
Fusion-Source
Fusion-Deployment-Id
X-Vgn-Hpd-Ssi
X-Dw-Trace-Id
X-Via-Ucdn
X-Vgn-Hpd-Variations-Key
PICS-Label
Yjs-Id
X-Upstream-Ct
X-Iplb-Instance
X-Upstream-Ht
X-Iplb-Request-Id
X-RAMCache
CACHE-MISS-TO-ORIGIN
Warning
Log-Origin
Ngx
X-Cached-Since
X-CF-Cache-Header-Cache-Control
X-CF-Cache-Header-Vary
Vha6-Origin
Cache
X-Fastly-Cache-Hits
X-Snapshot-Date
Inserted-Into-Cache-At
X-ElasticPress-Query
X-Udemy-Cache-App-Namespace
Cneonction
X-Cache-Remote
X-Rocket-Build-Number
X-Sigma
X-Sigma-Backend
X-HS-Status
X-Traceid
X-Litespeed-Cache-Control
X-Miniprofiler-Ids