Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-Cache-Status
Link
Accept-Ranges
CF-RAY
ETag
X-XSS-Protection
Expect-CT
Pragma
X-Powered-By
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
Alt-Svc
X-Served-By
X-Xss-Protection
X-Download-Options
X-Timer
X-Request-Id
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-DNS-Prefetch-Control
X-Drupal-Cache
X-Cache-Status
X-Check
X-Generator
X-Cacheable
Timing-Allow-Origin
X-Content-Security-Policy
X-Iinfo
Feature-Policy
Status
X-Envoy-Upstream-Service-Time
Content-Encoding
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
X-CDN
P3p
X-Request-ID
X-AspNetMvc-Version
Upgrade
X-Via
CF-Ray
X-Ws-Request-Id
Access-Control-Max-Age
Report-To
Server-Timing
EagleId
X-Cache-Group
X-Turbo-Charged-By
Keep-Alive
X-UA-Device
Request-Context
X-Age
X-Backend
X-Proxy-Cache
X-Server-Powered-By
X-AH-Environment
X-Robots-Tag
X-Hacker
X-Server
X-Amz-Request-Id
Host-Header
X-Amz-Id-2
Grace
X-Rq
X-LiteSpeed-Cache
X-Swift-CacheTime
X-Swift-SaveTime
X-Varnish-Cache
X-Nginx-Cache-Status
Ali-Swift-Global-Savetime
NEL
X-WebKit-CSP
X-Page-Speed
X-Vhost
EagleEye-TraceId
X-Amz-Version-Id
X-OneAgent-JS-Injection
X-Ua-Compatible
X-Pingback
X-Dispatcher
X-Pantheon-Styx-Hostname
X-Device
X-Styx-Req-Id
X-Cache-Spec
Accept-CH
X-Host
X-Server-Id
Cf-Railgun
X-Node
X-Dns-Prefetch-Control
X-Backend-Server
X-Readtime
Surrogate-Control
X-Akam-SW-Version
Request-Id
X-Response-Time
X-HW
X-Application-Context
Xkey
Content-Location
Accept-Ch-Lifetime
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Rating
X-Country
X-B3-TraceId
X-Cloud-Trace-Context
X-Cache-Lookup
X-Ruxit-JS-Agent
X-Trace
Accept-CH-Lifetime
X-Url
Allow
X-Ac
X-Content-Type
X-Vname
X-PC
X-TtlSet
X-Varnish-TTL
X-Aws-Lambda-Call-Status
X-Clacks-Overhead
Edge-Control
X-Server-Name
X-Mod-Pagespeed
X-ESI
Fastly-Restarts
Cache-Tag
X-Rack-Cache
Service-Worker-Allowed
X-VARITI-CCR
Verso
X-Element-Page-Cache
MS-Author-Via
X-Upstream
X-Vcap-Request-Id
X-MS-InvokeApp
X-Amz-Rid
Public-Key-Pins
X-GitHub-Request-Id
X-FastCGI-Cache
X-Dw-Request-Base-Id
X-Cached
X-Cache-TTL
X-D2id
X-Client-IP
X-Abt-Application-Version
X-Cnection
X-Px
RTSS
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-Navigation-Version
X-Aspnetmvc-Version
X-Exp-Variant
X-Kinja-Revision
X-Use-Magma
X-Kinja-Build
X-Kinja
X-Exp-Id
X-GoogleNews-Bot
X-Cdn-Fetch
X-Kinja-Server
Arr-Disable-Session-Affinity
Access-Control-Request-Method
X-Country-Code
X-Powered-By-Plesk
X-NF-Request-ID
X-Goog-Hash
X-TTL
X-Middleton-Display
X-Sol
Display
Pagespeed
AR-CACHE
X-Instrumentation
AR-ATIME
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
AR-PoweredBy
AR-SID
X-Powered-CMS
AR-Request-ID
X-Version
X-Origin-Cache
Response
X-Middleton-Response
X-LLID
X-MSEdge-Ref
Nginx-Cache
X-Amz-Server-Side-Encryption
X-RateLimit-Remaining
X-Kinsta-Cache
TCN
X-Edge-Location-Klb
X-CST
Mrf-Cache-Status
MRF-Tech
X-B3-TraceId-Primal
X-Edge
X-Protected-By
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-T
X-HP-Trace-Id
X-Jurisdiction
X-HP-Webp
X-Forwarded-For
X-Content-Security-Policy-Report-Only
X-Shield-Request-Id
X-Ruxit-Js-Agent
X-Mg-S
X-Id
Edge-Cache-Tag
S
X-Language
Content-MD5
SPIisLatency
SPRequestDuration
Fastcgi-Cache
Front-End-Https
X-Mid
X-Webkit-Csp
Realpath
X-Request-Received
Server-Node
X-Request-Processing-Time
X-Recruiting
Pinterest-Version
Filters
X-Pinterest-Rid
Pinterest-Generated-By
X-Frontend
X-Cache-Key
X-Ab
X-Content
X-Ua-Browser
Server-Name
X-MCACHE
X-Ser
X-Correlation-Id
X-NWS-LOG-UUID
X-HS-Hub-Id
X-HS-Cache-Config
X-HS-Content-Id
X-Template
X-HS-Combine-CSS
X-Yandex-Sdch-Disable
X-DynaTrace
X-Ezoic-Cdn
X-ECACHE
Accept-Ch
SPRequestGuid
X-SharePointHealthScore
X-Hits
X-Parallel-Accel
X-Tt-Trace-Host
X-Kong-Proxy-Latency
X-Tt-Trace-Tag
MicrosoftSharePointTeamServices
X-Kong-Upstream-Latency
Cache-Tags
Charset
X-Page-Id
Cleartype
Host
X-B3-Sampled
X-Www-Served-By
X-Ttl
X-Git-Hash
X-Daa-Tunnel
Alternate-Protocol
X-Geo-Country
X-Debug-Info
X-Content-Options
X-DIS-Request-ID
Fusion-Deployment-Id
Fusion-Component-Id
Fusion-Content-Source
Fusion-Content-Id
Fusion-Source
Fusion-Template-Id
X-Hostname
X-Content-Digest
X-Amzn-Trace-Id
Filterid
X-Amz-Replication-Status
Cross-Origin-Opener-Policy
X-Varnish-Age
X-Activity-Id
X-Grace
X-Az
X-AppVersion
X-Upgrade-Enabled
X-FB-Debug
ServerID
X-Fastly-Request-ID
X-Fastcgi-Cache
X-XRDS-LOCATION
X-F-Cache
X-Accel-Expires
X-VCache
X-WebKit-CSP-Report-Only
X-Ratelimit-Limit
X-N
X-Nginx-Upstream-Cache-Status
X-DataDome
X-Origin-Server
X-Rid
X-Forwarded-Proto
Access-Control-Allow-Method
X-Mobile-URL
X-Flags
X-Is-Crawler
X-Route-Name
X-Providence-Cookie
X-Aspnet-Duration-Ms
X-Request-Guid
X-Type
X-Whom
X-LB-Cache
X-TT
X-Varnish-Grace
X-Goog-Metageneration
X-Goog-Generation
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-App-Environment
Viewport
X-GUploader-UploadID
X-Seen-By
Payment
X-Tb
X-FW-Serve
X-FW-Type
X-FW-Static
X-FW-Server
X-Distributor
Node
DC
Paypal-Debug-Id
X-FW-Dynamic
X-FW-Hash
X-User-Agent
TP-L2-Cache
TP-Cache
X-Server-ID
X-Ratelimit-Reset
Accept-Charset
Country
Fastcgi-Useragent
X-Wix-Request-Id
X-App-Server
X-Tec-Api-Root
X-Tec-Api-Version
X-Tec-Api-Origin
X-Fastly-Request-Id
X-Cache-Rule
X-Cache-Control
X-NGENIX-Cache
X-Litespeed-Cache
X-Via-JSL
X-Cluster-Name
Version
X-Drupal-Cache-Tags
X-Request-Handler-Origin-Region
X-Microsite
X-Contextid
X-Cache-Age
X-Origin-Upstream-Status
Referer-Policy
X-B-Cache
X-Signature
X-Logged-In
Cache-Status
X-Buckets
X-Node-Name
X-Erf-Bev-Bev
X-Browser-Type
X-Erf-Bev-Bev-Is-Generated
Refresh
X-Original-Request-Id
VIX-Pulpo-Upstream-Status
X-Mobile
SD-X-WS
VIX-Pulpo-Node
X-Response-Served-From
X-Varnish-Backend
X-Vgn-Hpd-Reason
X-Page-View
X-Cache-Expired-At
X-Is-Bot
X-Real-IP
X-Rendered-As
X-Load-Cache
X-B
NGB
X-Cacheable-TTL
X-Proxy-Cache-Status
X-Jobs
X-Revision
X-IPLB-Instance
Access-Control-Request-Headers
X-Instance
X-Proxy
X-Device-Type
X-Cache-Action
X-Rule
X-Debug
X-UUID
Akamai-GRN
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-RemovedCookies
X-ProcessESI
X-Framework
X-Cache-Time
Surrogate-Key
X-Drupal-Cache-Contexts
Amp-Access-Control-Allow-Source-Origin
X-Debug-IsPreview
X-Debug-IsConnected
X-G
X-FW-Version
CF-IPCountry
SID
X-Accel-Buffering
X-PressLabs-Stats
X-RateLimit-Limit
X-Oracle-Dms-Ecid
X-Air-Source
X-Air-Trace-Id
X-Oracle-Dms-Rid
X-Air-Hostname
X-Nginx-Cache
DynaTrace
Count-Hit
Uber-Trace-Id
X-Cache-NGX
X-Cache-Operation
X-Source
X-Oneagent-Js-Injection
X-Azure-Ref
X-Ms-Version
X-Ms-Request-Id
Liferay-Portal
X-Zen-Fury
GEO-INFO
Protected
X-Presslabs-Stats
X-EdgeConnect-Cache-Status
Frame-Options
Ms-Operation-Id
MS-CV
X-RTag
X-CDN-Forward
X-XRDS-Location
X-Cache-Hit
X-APP-VERSION
Healthy
X-TEC-API-ORIGIN
X-Mode
X-Backend-Name
X-TEC-API-ROOT
X-TEC-API-VERSION
X-L-Path
X-Environment-Context
X-IPS-LoggedIn
WPO-Cache-Status
X-Cache-TTL-Remaining
X-Hyper-Cache
Ec-Rule-Version
Cross-Origin-Window-Policy
Countrycode
X-Trace-Id
Xserver
WPO-Cache-Message
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-Tumblr-User
X-Varnish-Server
X-Tumblr-Pixel
X-Servername
X-Adobe-Loc
LB
X-Adobe-Content
Backend
Content-Disposition
X-UPSTREAM-Address
X-RN-RSRV
X-SaId
X-Rewrite-Enabled
X-Content-Age
X-Tid
X-Region
X-JoinUs
Meta-Geo
X-Detected-As
Eomportal-Instance
X-Alternate-Cache-Key
Decoy-Debug-TTL
Apigw-Requestid
Decoy-Debug-Status
X-Debug-Cache
Decoy-Debug-Key
X-Extlb
X-Format
Country-Code
X-Cache-Server
X-Sorting-Hat-ShopId
X-Zipkin-Id
X-Routing-Service
X-Sql-Count
X-Uri
X-Sql-Duration-Ms
X-Proxied
X-ShardId
X-ShopId
X-Hosted-By
X-Generation-Time
X-Sorting-Hat-PodId
X-Shopify-Stage
X-Redis-Cache
X-Ratelimit-Remaining
X-Access
X-Forwarded-Host
X-Cache-Grace
X-Status
Mn-Server-Ip
CDN-Cache
CDN-CachedAt
CDN-EdgeStorageId
CDN-PullZone
CDN-RequestId
CDN-Uid
X-Varnish-Beresp-Grace
X-Via-Fastly
Fastly-SSL
X-ApacheServer
CDN-RequestCountryCode
X-OCL
X-Section
X-PHP-Backend
X-PERF
X-PCL
X-No-Session
X-Site-Version
X-NCache
X-Human
X-ServerID
X-Microcachable
X-ProxyCache-Key
Property-Id
X-Proxy-Build
X-FB-TRIP-ID
X-Origin-Hint
Selected-Fe
Url
Cache-Name
X-Origin-Date
X-Timing-Wait
X-Cluster-Node
Webcakes-App-Version
Webcakes-App-Name
Webcakes-Region
X-Server-W
X-Cache-Host
X-Cache-Type
TWC-Privacy
TWC-Locale-Group
X-Storage
X-BYPASS-REASON
X-Pubstack
X-Content-Powered-By
TWC-Device-Class
TWC-GeoIP-LatLong
TWC-GeoIP-Country
X-ProxyCache-Status
TWC-Connection-Speed
Cache-Tv-Group
X-UA-Device-Type
X-Akamai-Edgescape
X-Varnishpool
X-Soup
Section-Io-Cache
X-NYM-Debug-Backend
X-Say-Cacheable
X-Generated-By
X-Web-Node
X-SayCDN-TTL
X-Say-TTL
X-Hl-Ver
X-R9-Blue-Green-Version
Azure-RegionName
X-Be
Azure-SiteName
Azure-SlotName
Content-Secure-Policy
Azure-Version
Azure-InstanceId
Retry-After
X-Ua
X-LSADC-Cache
X-Nginx-Cache-Key
DB-Nickname
X-Webkit-CSP
X-Dc
X-NewRelic-App-Data
X-TIME
X-TT-LOGID
X-Unique-Id
X-Cache-Remote
OT-Force-Account-Verify
X-Bc-Bl
X-Cached-By
X-Azure-Ref-OriginShield
X-Platform-Server
X-Akamai-Transformed
X-Auto-Login
X-Xfnlog-Site
Source
SRV
Cache
X-LAGOON
ServedBy
Upgrade-Insecure-Requests
X-Cache-Tags
HostName
X-App-Version
X-Origin-CC
X-Time
X-Varnish-Cache-Hits
X-Origin-TTL
X-Request-Time
Cache-Hits
X-CSRF-Token
X-Varnish-Hits
X-Cdn
From-Origin
X-Loop
X-HTML-Minification-Powered-By
X-GEO
X-TNCMS
X-Varnish-Hostname
X-NWS-UUID-VERIFY
X-S-Maxage
X-AOL-HN
Xet-Cookie
Onion-Location
WP-Super-Cache
Webserver
X-EC-Lua
X-Request-Host
X-Tumblr-Pixel-2
X-Tumblr-Pixel-3
Web-Mar-Node
Mime-Version
X-Cache-Enabled
X-B3-SpanId
X-SRV
X-Handled-By
N-Cache
X-Proto
X-Endurance-Cache-Level
X-ECache
X-FireWall-Port
X-Amz-Meta-S3cmd-Attrs
X-Tenant
AMP-Access-Control-Allow-Source-Origin
X-VWS-Id
X-RCS-CacheZone
S-Rt
X-LJ-Flow-ID
X-Origin-Response-Time
X-AWS-Id
X-Reqid
Surrogated-Key
Redirect-Candidate
Sslversion
Rendered-Blocks
Xc-Version
X-Adobe-Source
DCR-Decision-By
BehaviorPad-Version
User-Cache-Control
A
DCR-Processing-Time-Ms
Expiry
Odigeo-Trace-Id
Mobile-Detection-Method
Meta-Geo-Continent
Fastcgi-X-Cache-Version
Pramga
X-CF-Lambda-Fn
X-PBS-Appsvrname
X-PAYTM-SRV-ID
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Orig-Expires
X-ND-Cache
X-GG-Cache-Date
X-Gen-Mode
X-Hnp-Log
X-Ig-Push-State
X-NAPM-TraceId
X-Processor
X-Rojux
X-TIM-N
X-SRCache-Key
X-V-Cache
X-Vdms-Path
X-Vdms-Version
X-Slack-Backend
X-Shop-Environment
X-S-Cookie
X-S
X-ScT
X-SD-PageType
X-Session-Fingerprint
X-Ftr-Request-Id
X-Forwarded-Path
X-Aed
X-A-Wwc
X-Application
X-ARC
X-B-Cookie
X-Vtex-Remote-Cache
X-A-Dgt
X-A
Vix-Hermes-Req-Id
X-A-Ccd
X-A-Dam
X-A-Dcw
X-Backend-TTL
X-Block-Status
X-Vtex-Processado-Em
X-Destination
X-Developer
X-Epic-Correlation-Id
X-External-Request-Id
X-D
X-Connection-Hash
X-VG-WebCache
X-Cache-NE
X-CF-Lambda-Version
X-Cluster
X-Conf
V-Age
X-Ckpd-Fst-Backend
X-Http-Reason
X-Time-Microsecs
X-Akamai-Request-ID2
X-Correlation-ID
Nel
X-Edge-Location
X-Mg-Request-UUID
X-MP-GENERATED-AT
X-Location
X-Nyt-Route
X-NodeID
X-Men
X-Old-Content-Length
X-Mvc-Supplant-Cachable
X-Policy
X-Request-URI
X-Rocket-Nginx-Serving-Static
DSUID
Fastcgi-Cache-TTL
Gh-Request-Id
X-Origin-Time
Host-ID
X-LI-UUID
X-Origin
Origin
Wxu-Next-Commit
X-Cache-Info
X-Cdn-Srv
True-Client-Country-4JS
Wxu-Next-Hostname
Wxu-Next-Region
X-Accel-Expires-Debug
X-Cache-Bucket
X-Cache-Date
Svr
X-Date
X-GeoIP-Country-Code
X-GeoIP-Region-Code
X-Hash
X-Li-Fabric
X-Geo-Header
X-Gdpr
State
X-Fastly-Cache
X-Forwarded-Site
X-Li-Pop
X-Proxy-Upstream
AKAMAI
X-Server-IP
Apple-News-Services-Handled
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
X-Locale
X-Sucuri-Cache
X-Viewer-Country
X-Webstats-RespID
X-VG-TLSProxy
X-SVT-ORM-RULES
X-Sucuri-ID
Apple-News-Services-Request-Url
X-SVT-ORM-VERSION
X-Scheme
CacheControlHeader
CDCHOST
Cmstype
Arc-Country
Cmsid
CloudFront-Viewer-Country
X-PHP-Host
X-Amzn-RequestId
X-Magnolia-Registration
X-Varnish-Beresp-Ttl
Environment
Server-Info
X-Via-NSCOPI
X-Amz-Apigw-Id
X-Labrador-Cache-Channel
X-Core-Value
X-Datadog-Trace-Id
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
X-Csrf-Jwt
X-Cache-Id
X-Origin-Expires
X-Fetched-On
X-VServer
X-Branch-Name
X-BBC-Edge-Cache-Status
X-Fastly-Backend
X-Cache-Debug
X-Device-Os
Origin-EX
Origin-CC
X-Developers
Traceparent
X-Core-Mission
X-CGP
X-Varnish-Beresp-Status
X-Skip-Cache
X-Sigma-Backend
X-Storefront-Renderer-Rendered
X-Req
X-Level-Front-Cache
X-Sigma
X-Served-From
X-RateLimit-Limit-Second
X-Platform
X-Owner
X-RateLimit-Remaining-Second
X-Region-Sid
X-Irp-Debug
X-HS-Content-Campaign-Id
X-Backend-State
X-Gamma-Serve
X-VarnishDD-TTL
X-Eu-Site
X-Esi-Check
X-UnsetCookies
X-Generated-On
X-HN
X-Gzip
X-TH-Server
X-TrackingId
X-Envoy-Decorator-Operation
X-Rocket-Build-Number
L
L5d-Success-Class
We-Hiring
HA-Ipaddr
Web-Mar-Region
Ha-Gx-Prefs
Machine
Magicmarker
Req-Svc-Chain
Server-Host
Release
PFcat
Mail-Subject
Ssr
Fastly-GeoIP-CountryCode
X-Aicache-OS
X-Cache-Var
X-Cache-Var-Map
NGX
Memcached
X-Has-Esi
X-FC-Vary-Parameters
NM-Fastcgi-Cache
X-Is-Gdpr
X-Sn-Servicetimems
X-Restarts
X-JWT-State
Thinkindot-CacheControl
X-Cdn-Origin
X-GeoIP-City
X-Amzn-Remapped-Content-Length
X-ATG-Version
Thinkindot-Control
X-Pod-Name
X-Node-Id
X-Thinkindot-L3
Thinkindot-CacheControl-Type
TDXMobile
Locid
X-GeoIP
X-Xrds-Location
X-CS
Platform
X-DefElseHash
X-DefHash
Kp-EeAlive
Is-Eu
Cf-Device-Type
Fastly-SIE
Fastly-SWR
X-DPWN-IS-SECURE
X-NU-AKA-ACS-Version
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
X-Worker
X-Variation
X-Response-By
X-Qloud-Router
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-Loc
Adler-Geo
X-Srv
Fastly-Drupal-Html
X-Ua-Device
X-TraceId
CDN
X-DB
X-DI
X-VC-Cache
Accept-Language
X-Request-Start
X-DSS
X-Mvc-Supplant-OutputCached
X-Up
X-Action
Edge-Cache
X-DW
X-Cache-Backend
X-Wix-Viewer-Type
X-NC
X-RSL
X-RPS
X-RPM
X-LB-ID
X-Zone
X-Tx-Id
X-Generated-In
X-Bip
Pics-Label
X-Qnm-Cache
X-LB-NoCache
X-M-Reqid
X-M-Log
X-Thanos
X-API-Version
Time
X-Trace-ID
Memory
X-Minions-Version
X-Optimistic-Header
X-CacheTTL
Ms-Author-Via
X-Tb-Optimization-Total-Bytes-Saved
X-Edge-Pop
X-Cache-Config
X-Via-Popv
X-Via-Popn
X-Urbn-Context-Path
Locale
X-Via-Poph
X-Urbn-Site-Id
X-Refresh
X-TA-CDN-Provider
X-Varnish-Ttl
X-Dynatrace
X-HA-Backend
WebServer
Env
GeoIp-Country-Code
X-Tt-Logid
X-ZONE
X-DynaTrace-JS-Agent
X-Ec-GeoHdr
X-User
X-Ec-Fail
Candidate-Md5Url
Datacenter
X-CACHE-KEY
NtCoent-Length
Server-ID
X-DC
X-Datadome
X-Parent-Response-Time
X-TX-ID
X-Esi
X-MSEdge-Flight
X-MSEdge-Features
X-Vc
On-Server
X-Servedbyhost
WWW-Authenticate
X-CLOUD-TRACE-CONTEXT
X-Cs
Esi-Enabled
Cdnsip
Cdncip
X-AK-Request-ID
Geo-Info
X-WADP-Cache
Geoip-Latitude
My-App
X-Clara-WADP
X-Fmm-Version
X-Varnish-Beresp-TTL
X-Unique-ID
Cluster
X-Li-Proto
X-Cache-Ttl
X-App
Tracecode
X-VCL-Version
Fastly-Drupal-HTML
X-Service
C-Via
X-Cache-PHP
X-Var-Ttl
X-CUA
DataCenter
X-Pass-Why
X-URL
T-Server
X-Fpc
Lfy
X-Newrelic-Synthetics
X-From
X-LI-Proto
X-FPC
X-Webkit-Csp-Report-Only
X-Vcl-Version
X-VC
X-Traceid
Test
Lang
X-Fragments
X-B3-Spanid
Cf-Int-Pingora-Origin-Digest
MIME-Version
X-NODE
X-Webkit-CSP-Report-Only
Proxy-Connection
X-Cache-Status-Check
Target-Params
X-Render-Time
X-Mcache
X-LiteSpeed-Cache-Control
Resin-Trace
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
M-TraceId
X-Geo
X-Provided-By
X-RAMCache
Server-Id
X-Api-Version
X-CSRF-TOKEN
X-ServedByHost
Permissions-Policy
X-ID
X-Ha-Backend
Hostname
Servername
GeoIP-Country-Code
X-Httpd
ENV
X-Proxy-Cache-Info
Hit
X-Clientip
WZWS-RAY
X-Dynatrace-Js-Agent
X-Cdn-Forward
FSS-Cache
X-SB
X-LiteSpeed-Tag
X-Via-PopN
Cache-Host
HIT
X-Oss-Hash-Crc64ecma
X-Oss-Server-Time
X-Oss-Request-Id
UCS
Producers
X-Oss-Object-Type
X-Pad
X-Edge-POP
X-Via-PopH
X-Oss-Storage-Class
X-Fastly-Backend-Reqs
X-Via-PopV
X-Info
X-AIR-PT
X-Platform-Processor
X-Platform-Cluster
Section-Io-Origin-Status
Section-Io-Id
S-Cnection
X-Platform-Router
X-NGINX-Cache
Section-Io-Origin-Time-Seconds
X-Edge-Cache
Section-Origin-Responded
X-Pool
X-Udemy-Cache-App-Namespace
X-ElasticPress-Query
X-Ucs
Ohc-File-Size
X-Scale
X-Check-Cacheable
X-Ec-Custom-Error
Sever-Int
X-GoCache-CacheStatus
Server-Hostname
X-Acquia-Application-UUID
MD5-Digest
X-Acquia-Site
Server-Ext
Uri
PICS-Label
X-Lb-Nocache
Fastly-Backend-Name
ServerName
X-Acquia-Purge-Tags
User-Agent
X-Acquia-Application-Trace
X-HS-Status
URI
X-UP
X-Dispatcher-Number
X-Cache-CFC
X-Micro-Cache
X-BBC-Origin-Response-Status
X-Srcache-Store-Status
X-Srcache-Fetch-Status
IsBot
Server-Ttl
X-Via-Ucdn
X-SIPLIST1
X-ServerName
X-Backend-Host
Cneonction
X-Release
Load-Balancing
Cteonnt-Length
X-Swift-Error
X-RateLimit-Reset
X-Nc
X-Cdn-Request-ID
X-Fastly-Cache-Hits
X-Lb-Id
Tcn
X-Cache-Expires
X-Dw-Trace-Id
X-Akamai-ERPolicy
X-Akamai-ERRuleID
Wpo-Cache-Status
X-Newrelic-App-Data
X-Fetch-By
EpKe-Alive
X-Cms-Context
X-Contensis-Viewer-Groups
X-Snapshot-Date
X-TRACE-ID
X-Vcache
Cf-Ipcountry
Wpo-Cache-Message
X-BCube-Filmed-By
X-Yottaa-OS
X-B3-ParentSpanId
CF-Cached-On
Vha6-Origin
Shield-Pop
X-APP
X-Cache-ASPX
Inserted-Into-Cache-At
Cdn
Sid
X-Cache-Ngx
X-HostName
X-Air-Pt
X-B3-Parentspanid
X-Shopify-Generated-Cart-Token
X-IN-APIGATEWAYSSL
X-Litespeed-Cache-Control
X-IN-APIGATEWAY
X-Apw-Access-Action
X-Apw-Hits
X-Logging-Id
X-CacheKey
X-UA
X-Apw-Access-Token
X-Apw-Access-Object
Path
Ohc-Cache-HIT
X-Varnish-Authentication
X-Akamai-Pragma-Client-IP
Req-ID
X-Te-Count
X-Te-Duration-Ms
X-Last-Modified
X-Http-Duration-Ms
X-Http-Count
CountryCode
X-Sentry-ID
Ngx
X-Akamai-Request-ID