Threat Level: green Handler on Duty: Rick Wanner

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Link
Cf-Request-Id
CF-Cache-Status
Accept-Ranges
CF-RAY
ETag
X-XSS-Protection
Expect-CT
Pragma
X-Powered-By
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-UA-Compatible
X-Cache-Hits
Alt-Svc
P3P
X-Served-By
X-Xss-Protection
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Cache-Status
X-Generator
X-Cacheable
Timing-Allow-Origin
X-Request-ID
P3p
X-Content-Security-Policy
X-Iinfo
Status
Feature-Policy
X-Envoy-Upstream-Service-Time
Content-Encoding
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
X-CDN
X-AspNetMvc-Version
Upgrade
X-Via
CF-Ray
Access-Control-Max-Age
X-Ws-Request-Id
Server-Timing
EagleId
Keep-Alive
X-Cache-Group
X-Turbo-Charged-By
Request-Context
X-Age
X-Proxy-Cache
X-Server-Powered-By
X-AH-Environment
X-Hacker
X-Backend
X-Robots-Tag
Report-To
X-UA-Device
X-Amz-Request-Id
Host-Header
X-Server
X-LiteSpeed-Cache
X-Amz-Id-2
Grace
X-Rq
X-Nginx-Cache-Status
X-Varnish-Cache
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-Dns-Prefetch-Control
X-WebKit-CSP
X-Page-Speed
X-Vhost
X-OneAgent-JS-Injection
X-Amz-Version-Id
EagleEye-TraceId
X-Device
X-Dispatcher
X-Pingback
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Cache-Spec
NEL
X-Server-Id
X-Host
X-Backend-Server
X-Node
Cf-Railgun
X-Readtime
Accept-CH
X-Akam-SW-Version
Surrogate-Control
Request-Id
X-Response-Time
X-HW
X-Language
Xkey
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Content-Location
X-Ruxit-JS-Agent
X-Template
X-Application-Context
Rating
X-Ua-Compatible
Accept-Ch-Lifetime
X-Country
X-B3-TraceId
X-Cloud-Trace-Context
X-Cache-Lookup
Accept-CH-Lifetime
X-Ac
X-Buckets
Allow
X-Url
X-Content-Type
X-Trace
X-TtlSet
X-PC
X-Vname
X-Mod-Pagespeed
X-Varnish-TTL
X-Clacks-Overhead
Edge-Control
X-FastCGI-Cache
X-ESI
Cache-Tag
Fastly-Restarts
X-Rack-Cache
Service-Worker-Allowed
X-VARITI-CCR
X-Server-Name
X-Element-Page-Cache
Verso
X-GitHub-Request-Id
X-MS-InvokeApp
X-Upstream
X-Amz-Rid
X-Vcap-Request-Id
X-Dw-Request-Base-Id
Public-Key-Pins
MS-Author-Via
X-D2id
X-Client-IP
X-Abt-Application-Version
X-Cached
X-Origin-Cache
X-Cache-TTL
Arr-Disable-Session-Affinity
Accept-Ch
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-Country-Code
X-Px
X-Cnection
X-Goog-Hash
X-Powered-By-Plesk
X-Navigation-Version
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-Instrumentation
Access-Control-Request-Method
X-NF-Request-ID
X-Version
X-Aws-Lambda-Call-Status
X-Amz-Server-Side-Encryption
X-Powered-CMS
RTSS
X-Sol
X-Middleton-Display
Display
Pagespeed
X-SRCache-Fetch-Status
X-SRCache-Store-Status
Response
X-Middleton-Response
X-Kinja-Server
X-Use-Magma
X-Kinja-Revision
X-Exp-Id
X-Cdn-Fetch
X-Kinja-Build
X-Exp-Variant
X-Kinja
X-GoogleNews-Bot
X-MSEdge-Ref
X-LLID
X-Edge
X-Edge-Location-Klb
X-Kinsta-Cache
X-CST
Nginx-Cache
X-Shield-Request-Id
AR-PoweredBy
AR-SID
AR-Request-ID
AR-CACHE
AR-ATIME
X-Jurisdiction
MRF-Tech
S
Mrf-Cache-Status
Content-MD5
X-HP-Webp
X-B3-TraceId-Primal
X-HP-Trace-Id
X-T
X-TTL
X-Protected-By
X-Content-Security-Policy-Report-Only
X-Forwarded-For
TCN
X-Aspnetmvc-Version
X-Mg-S
X-Id
X-RateLimit-Remaining
X-Mid
X-MCACHE
Fastcgi-Cache
Realpath
X-Parallel-Accel
Front-End-Https
SPIisLatency
SPRequestDuration
Edge-Cache-Tag
X-Recruiting
X-Ttl
Filters
X-Request-Received
X-Request-Processing-Time
Pinterest-Generated-By
Pinterest-Version
X-Pinterest-Rid
Server-Node
X-Content
X-Ua-Browser
Fusion-Component-Id
Fusion-Deployment-Id
Fusion-Source
Fusion-Content-Id
Fusion-Template-Id
X-Ab
Fusion-Content-Source
X-SharePointHealthScore
SPRequestGuid
X-DynaTrace
X-Ezoic-Cdn
X-Correlation-Id
Alternate-Protocol
Server-Name
X-Accel-Expires
X-NWS-LOG-UUID
X-Frontend
X-ECACHE
X-HS-Hub-Id
X-HS-Cache-Config
X-HS-Content-Id
X-Hits
X-HS-Combine-CSS
X-Yandex-Sdch-Disable
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Content-Options
X-Cache-Key
Cache-Tags
X-Ruxit-Js-Agent
X-Git-Hash
Host
Cleartype
MicrosoftSharePointTeamServices
X-Page-Id
Charset
X-B3-Sampled
X-Www-Served-By
X-Geo-Country
X-Fastly-Request-Id
X-Amz-Replication-Status
X-Content-Digest
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
TP-L2-Cache
Filterid
TP-Cache
X-XRDS-LOCATION
X-Ser
X-Forwarded-Proto
X-VCache
X-Varnish-Age
X-Hostname
X-Amzn-Trace-Id
X-AppVersion
X-Activity-Id
X-Az
X-Microsite
X-Request-Handler-Origin-Region
X-Rid
X-Daa-Tunnel
X-DIS-Request-ID
X-Origin-Server
X-Debug-Info
Access-Control-Allow-Method
X-Upgrade-Enabled
X-Grace
X-N
X-LB-Cache
X-FB-Debug
X-Origin-Upstream-Status
X-WebKit-CSP-Report-Only
ServerID
X-Nginx-Upstream-Cache-Status
X-Mobile-URL
X-Server-ID
X-Whom
X-GUploader-UploadID
X-Goog-Stored-Content-Length
X-Goog-Metageneration
X-Goog-Generation
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Providence-Cookie
X-Route-Name
X-Aspnet-Duration-Ms
X-Request-Guid
X-NGENIX-Cache
X-TT
X-Is-Crawler
X-Flags
X-App-Environment
X-App-Server
X-Varnish-Grace
X-F-Cache
Cross-Origin-Opener-Policy
Viewport
X-Tb
X-FW-Server
X-Logged-In
Payment
X-PressLabs-Stats
X-FW-Dynamic
X-FW-Hash
DC
Paypal-Debug-Id
X-FW-Static
X-Cache-Control
Node
X-FW-Type
X-Distributor
X-FW-Serve
Fastcgi-Useragent
X-Seen-By
X-Type
X-User-Agent
X-Cache-Age
X-Litespeed-Cache
Country
Accept-Charset
X-Webkit-CSP
X-Cache-Rule
X-Varnish-Backend
X-Node-Name
Version
X-Browser-Type
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-DataDome
X-Load-Cache
X-Wix-Request-Id
X-Cache-Action
X-Ratelimit-Limit
Refresh
X-IPLB-Instance
X-Via-JSL
X-Fastly-Request-ID
X-Original-Request-Id
Access-Control-Request-Headers
Cache-Status
X-Response-Served-From
SD-X-WS
X-Real-IP
X-Jobs
X-Tec-Api-Origin
X-Cacheable-TTL
X-Tec-Api-Version
X-Tec-Api-Root
X-Revision
Referer-Policy
X-RemovedCookies
X-ProcessESI
Liferay-Portal
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
NGB
X-Cluster-Name
X-B
X-Fastcgi-Cache
X-Debug
X-Page-View
X-Is-Bot
X-Proxy-Cache-Status
DynaTrace
X-Rendered-As
X-UUID
X-Proxy
X-Contextid
X-Drupal-Cache-Tags
X-Device-Type
X-Rule
X-Yottaa-Optimizations
X-Cache-Expired-At
X-Yottaa-Metrics
X-Cache-Time
X-Vgn-Hpd-Reason
X-Framework
X-Instance
X-G
X-Drupal-Cache-Contexts
X-Mobile
Surrogate-Key
Akamai-GRN
X-TEC-API-VERSION
X-TEC-API-ROOT
Amp-Access-Control-Allow-Source-Origin
X-TEC-API-ORIGIN
X-B-Cache
Healthy
X-Signature
X-Azure-Ref
X-Debug-IsConnected
CF-IPCountry
X-Debug-IsPreview
X-FW-Version
X-Source
SID
X-Oracle-Dms-Rid
X-Oracle-Dms-Ecid
X-Air-Hostname
X-Air-Source
X-Air-Trace-Id
X-Ms-Version
X-Ms-Request-Id
Frame-Options
X-Nginx-Cache
X-Oneagent-Js-Injection
Ms-Operation-Id
X-RTag
MS-CV
X-Cache-Hit
X-Tumblr-Pixel-0
X-APP-VERSION
X-Tumblr-Pixel-1
Countrycode
X-Tumblr-Pixel
X-Tumblr-User
Section-Io-Cache
Xserver
X-Varnish-Server
X-L-Path
X-Environment-Context
X-XRDS-Location
X-CDN-Forward
X-Region
Count-Hit
X-Servername
X-Cache-Operation
X-EdgeConnect-Cache-Status
X-Content-Powered-By
GEO-INFO
X-Forwarded-Host
Uber-Trace-Id
X-Backend-Name
X-IPS-LoggedIn
Cross-Origin-Window-Policy
X-Mode
Backend
X-Accel-Buffering
X-Adobe-Loc
X-Adobe-Content
X-Zen-Fury
Meta-Geo
X-JoinUs
X-RN-RSRV
X-Ua-Device
X-SaId
Ec-Rule-Version
X-UPSTREAM-Address
X-Cache-Server
X-Debug-Cache
X-Cache-Grace
Eomportal-Instance
Apigw-Requestid
X-Cache-Type
X-Human
X-No-Session
X-Redis-Cache
X-Varnish-Beresp-Grace
X-Generation-Time
X-Hosted-By
X-ShardId
X-Shopify-Stage
X-ShopId
X-ProxyCache-Status
X-Site-Version
X-Sorting-Hat-ShopId
X-Via-Fastly
X-Status
X-ProxyCache-Key
X-Sorting-Hat-PodId
X-ServerID
X-Origin-Date
X-Microcachable
Decoy-Debug-TTL
Url
X-Alternate-Cache-Key
X-BYPASS-REASON
X-NCache
Decoy-Debug-Key
X-Detected-As
X-FB-TRIP-ID
Cache-Name
Cache-Tv-Group
X-PHP-Backend
Decoy-Debug-Status
X-RateLimit-Limit
TWC-Device-Class
TWC-Connection-Speed
TWC-GeoIP-Country
TWC-Locale-Group
TWC-GeoIP-LatLong
Selected-Fe
Fastly-SSL
X-Cache-TTL-Remaining
X-Storage
X-SayCDN-TTL
X-Azure-Ref-OriginShield
TWC-Privacy
Protected
Webcakes-App-Name
X-Proxy-Build
X-Format
X-OCL
X-Origin-Hint
X-PCL
Mn-Server-Ip
X-Web-Node
Webcakes-App-Version
X-Timing-Wait
Webcakes-Region
X-Akamai-Edgescape
X-Say-Cacheable
X-Say-TTL
Property-Id
X-Sql-Count
X-Uri
Country-Code
X-Sql-Duration-Ms
Source
X-PERF
OT-Force-Account-Verify
X-Section
X-Cache-Host
X-Varnishpool
X-UA-Device-Type
X-Access
X-Pubstack
X-Hl-Ver
X-Proxied
X-Extlb
X-Routing-Service
X-Zipkin-Id
X-ApacheServer
DB-Nickname
X-Server-W
X-NYM-Debug-Backend
Azure-SlotName
Azure-Version
Azure-SiteName
Azure-RegionName
Azure-InstanceId
X-Time
X-LSADC-Cache
Content-Secure-Policy
X-Rewrite-Enabled
X-Be
X-Cluster-Node
X-R9-Blue-Green-Version
X-Cache-NGX
X-Cache-Var-Map
X-Webkit-Csp
X-Ua
X-Soup
X-Cache-Var
X-SRV
X-Tid
X-Content-Age
X-Amz-Meta-S3cmd-Attrs
Content-Disposition
SRV
X-Ratelimit-Reset
X-HTML-Minification-Powered-By
X-NewRelic-App-Data
X-Cached-By
X-LAGOON
X-App-Version
X-TNCMS
X-Varnish-Hostname
X-Loop
X-Generated-By
X-Varnish-Hits
X-Dc
Cache
CDN-CachedAt
CDN-EdgeStorageId
CDN-PullZone
CDN-RequestId
Onion-Location
CDN-Uid
X-Unique-Id
CDN-Cache
X-S-Maxage
CDN-RequestCountryCode
Retry-After
X-Bc-Bl
X-TT-LOGID
Webserver
X-Presslabs-Stats
X-Origin-TTL
X-Auto-Login
X-Origin-CC
X-Hyper-Cache
X-ECache
X-Tumblr-Pixel-2
X-Tumblr-Pixel-3
X-Proto
Web-Mar-Node
X-GEO
Cache-Hits
X-Cdn
X-Nginx-Cache-Key
Xet-Cookie
X-Trace-Id
X-M-Log
X-Tenant
X-Endurance-Cache-Level
X-M-Reqid
X-Qnm-Cache
X-Time-Microsecs
X-Edge-Location
X-VWS-Id
X-AWS-Id
X-GG-Cache-Date
X-CSRF-Token
X-LJ-Flow-ID
X-Akamai-Transformed
CloudFront-Viewer-Country
LB
Mime-Version
X-CACHE-KEY
X-Platform-Server
HostName
X-Mg-Request-UUID
X-Amz-Apigw-Id
X-PHP-Host
X-Labrador-Cache-Channel
X-Amzn-RequestId
N-Cache
X-Xfnlog-Site
X-RCS-CacheZone
X-Handled-By
X-Cache-Tags
X-Locale
X-B3-SpanId
Nel
X-Varnish-Cache-Hits
Upgrade-Insecure-Requests
X-Origin-Response-Time
X-Request-Time
X-VC-Cache
X-Storefront-Renderer-Rendered
ServedBy
Fastcgi-X-Cache-Version
BehaviorPad-Version
X-AOL-HN
Odigeo-Trace-Id
DCR-Decision-By
DCR-Processing-Time-Ms
Mobile-Detection-Method
Expiry
DSUID
Meta-Geo-Continent
A
X-Forwarded-Path
X-Request-Host
X-Processor
X-Rojux
Xc-Version
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-Orig-Expires
X-ND-Cache
X-PAYTM-SRV-ID
X-PBS-Appsvrname
X-Planisys-CDN-Cache
X-VG-WebCache
X-Vdms-Version
X-ScT
X-SRCache-Key
X-Slack-Backend
X-Shop-Environment
X-SD-PageType
X-Session-Fingerprint
X-S-Cookie
X-S
X-V-Cache
X-Vdms-Path
X-TIM-N
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-NAPM-TraceId
X-Ig-Push-State
X-A-Dgt
X-A-Dcw
X-A-Wwc
X-Aed
X-ARC
X-Application
X-A-Dam
X-A-Ccd
Redirect-Candidate
Pramga
Rendered-Blocks
Surrogated-Key
X-A
X-B-Cookie
X-Cache-Date
X-Destination
X-D
X-Developer
X-External-Request-Id
X-Ftr-Request-Id
X-Connection-Hash
X-Conf
X-CF-Lambda-Fn
X-Cache-NE
X-CF-Lambda-Version
X-Ckpd-Fst-Backend
X-Cluster
Origin
X-Adobe-Source
X-ATG-Version
X-Reqid
WPO-Cache-Status
WPO-Cache-Message
X-Correlation-ID
Server-Info
X-Cache-Remote
AMP-Access-Control-Allow-Source-Origin
X-MP-GENERATED-AT
X-Via-NSCOPI
X-TIME
L
X-Rocket-Nginx-Serving-Static
Host-ID
X-Cache-Info
X-Scheme
X-Cache-Bucket
X-Served-From
Gh-Request-Id
X-Proxy-Upstream
X-Device-Os
X-Epic-Correlation-Id
Datacenter
X-Date
X-Policy
X-Core-Mission
X-Server-IP
X-VServer
State
Wxu-Next-Commit
Wxu-Next-Hostname
X-Mvc-Supplant-Cachable
Vix-Hermes-Req-Id
X-Varnish-Beresp-Status
V-Age
Wxu-Next-Region
X-Sucuri-ID
X-Ratelimit-Remaining
X-Skip-Cache
X-Accel-Expires-Debug
X-Sucuri-Cache
Release
From-Origin
Cmstype
Fastcgi-Cache-TTL
X-Old-Content-Length
X-Forwarded-Site
X-Li-Fabric
X-Li-Pop
X-Geo-Header
X-Origin-Expires
AKAMAI
X-Gdpr
X-Nyt-Route
X-Origin-Time
X-Fetched-On
X-Men
X-Location
Candidate-Md5Url
X-Owner
Cmsid
CacheControlHeader
X-LI-UUID
X-Hash
Environment
X-HN
X-Gzip
X-Sigma-Backend
X-Sn-Servicetimems
X-Aicache-OS
X-Level-Front-Cache
We-Hiring
X-Thinkindot-L3
X-TrackingId
X-NodeID
X-Irp-Debug
X-NU-AKA-ACS-Version
X-Thanos
X-HS-Content-Campaign-Id
X-Cache-Config
True-Client-Country-4JS
X-EC-Lua
X-Region-Sid
X-Cdn-Origin
X-Fastly-Backend
X-Datadog-Parent-Id
X-Developers
X-Platform
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
X-Req
X-Request-Start
X-GeoIP
X-Branch-Name
X-Bip
X-GeoIP-City
X-Esi-Check
X-Cache-Id
X-Rocket-Build-Number
X-Gamma-Serve
X-Generated-On
X-Sigma
Web-Mar-Region
Fastly-GeoIP-CountryCode
Origin-CC
Traceparent
Locid
Machine
X-Viewer-Country
Arc-Country
Mail-Subject
User-Cache-Control
X-Magnolia-Registration
Apple-News-Services-Host
Apple-News-Services-Handled
X-Hnp-Log
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
X-Block-Status
X-Fastly-Cache
X-Gen-Mode
PFcat
Origin-EX
X-VG-TLSProxy
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
TDXMobile
Server-Host
X-VarnishDD-TTL
Thinkindot-Control
Svr
X-Xrds-Location
X-DefElseHash
X-Webstats-RespID
X-DefHash
X-BBC-Edge-Cache-Status
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
X-Csrf-Jwt
X-Loc
X-Pod-Name
Req-Svc-Chain
X-DPWN-IS-SECURE
X-Core-Value
X-Origin
X-Is-Gdpr
X-UnsetCookies
X-TH-Server
X-Has-Esi
X-JWT-State
X-Variation
Adler-Geo
X-Eu-Site
Cf-Device-Type
X-FC-Vary-Parameters
X-Cache-Debug
WWW-Authenticate
L5d-Success-Class
Is-Eu
X-Request-URI
HA-Ipaddr
Memcached
X-Worker
X-Amzn-Remapped-Content-Length
Platform
NM-Fastcgi-Cache
X-Backend-State
Ha-Gx-Prefs
CDCHOST
X-CGP
X-Qloud-Router
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-FireWall-Port
X-Zone
X-CS
Fastly-Drupal-Html
X-Rebelmouse-Cache-Control
Sslversion
X-Node-Id
X-Cdn-Srv
X-Rebelmouse-Surrogate-Control
Esi-Enabled
Fastly-SIE
X-Envoy-Decorator-Operation
Fastly-SWR
On-Server
NGX
CDN
X-Varnish-Beresp-Ttl
X-LB-ID
X-NC
Ssr
X-Response-By
X-API-Version
X-Up
X-Mvc-Supplant-OutputCached
X-Tx-Id
C-Via
X-Trace-ID
Pics-Label
WP-Super-Cache
X-Generated-In
Ms-Author-Via
X-Vc
X-Service
X-Datadome
X-Tt-Logid
X-Via-Popn
X-Via-Popv
X-Via-Poph
X-Refresh
Time
Memory
X-Cache-PHP
X-DynaTrace-JS-Agent
X-TA-CDN-Provider
NtCoent-Length
X-Cache-Enabled
X-Edge-Pop
X-Backend-TTL
X-Dynatrace
X-Varnish-Ttl
X-Tb-Optimization-Total-Bytes-Saved
X-Cache-Status-Check
Env
X-GeoIP-Region-Code
X-LB-NoCache
X-GeoIP-Country-Code
X-TraceId
GeoIp-Country-Code
X-Parent-Response-Time
Magicmarker
X-DC
X-Render-Time
X-Optimistic-Header
X-NWS-UUID-VERIFY
X-Varnish-Beresp-TTL
X-Info
X-TX-ID
X-Esi
X-Restarts
Kp-EeAlive
X-Servedbyhost
X-CacheTTL
X-Unique-ID
X-AIR-PT
X-Cs
X-ZONE
Server-ID
X-Clientip
X-CLOUD-TRACE-CONTEXT
X-Srv
S-Rt
X-Wix-Viewer-Type
X-DI
X-DSS
X-Action
X-Oss-Server-Time
X-Oss-Request-Id
UCS
X-Oss-Storage-Class
Cache-Host
X-DB
X-Oss-Object-Type
X-MSEdge-Features
X-RPS
X-Cache-Backend
X-RSL
Edge-Cache
HIT
X-MSEdge-Flight
X-RPM
X-Oss-Hash-Crc64ecma
WebServer
X-DW
S-Cnection
X-Newrelic-Synthetics
X-Li-Proto
X-VCL-Version
X-Cache-Ttl
X-App
Proxy-Connection
X-URL
Section-Io-Origin-Status
Lb
Section-Origin-Responded
Section-Io-Origin-Time-Seconds
Section-Io-Id
X-Fpc
Test
X-FPC
X-Webkit-Csp-Report-Only
X-HA-Backend
X-LI-Proto
X-LiteSpeed-Cache-Control
X-Traceid
X-Micro-Cache
Fastly-Backend-Name
Server-Id
X-Minions-Version
X-B3-Spanid
User-Agent
X-Vcl-Version
X-NODE
X-Webkit-CSP-Report-Only
Tcn
Geo-Info
X-Backend-Host
X-Http-Reason
X-Akamai-Request-ID2
X-BCube-Filmed-By
X-Pad
X-Pass-Why
X-Release
X-ES-SERVER
X-HostName
X-APP
X-User
X-Ec-Fail
X-Ec-GeoHdr
Cf-Int-Pingora-Origin-Digest
Accept-Language
X-ServedByHost
Resin-Trace
X-LiteSpeed-Tag
Fastly-Drupal-HTML
X-CSRF-TOKEN
Cache-Key
X-Amz-Meta-Cb-Modifiedtime
X-ID
VNS-Cache
VNS-Age
CPC-Age
CPC-Cache
X-BBC-Origin-Response-Status
EpKe-Alive
Path
X-Urbn-Site-Id
Locale
Hostname
X-Urbn-Context-Path
Ohc-File-Size
X-Check-Cacheable
X-WA
Srv
X-Akamai-Pragma-Client-IP
X-Ha-Backend
GeoIP-Country-Code
Hit
X-WA-Info
X-Dynatrace-Js-Agent
X-Geo
X-Wikidot-Static-Cache
X-Wikidot-Backend
MIME-Version
Pagetype
X-Cdn-Forward
X-Via-PopH
X-AK-Request-ID
M-TraceId
ENV
Cdnsip
X-Cms-Context
X-PJAX-URL
X-Via-PopV
Cdncip
Shield-Pop
X-Edge-POP
X-Via-PopN
X-ElasticPress-Query
X-Via-Ucdn
X-NGINX-Cache
X-Api-Version
X-Edge-Cache
X-CCDN-CacheTTL
X-CCDN-Origin-Time
MD5-Digest
My-App
Geoip-Latitude
X-Hcs-Proxy-Type
Load-Balancing
X-WADP-Cache
X-Fmm-Version
X-Clara-WADP
Cluster
X-HS-Status
X-VG-WebServer
URI
X-CUA
Tracecode
X-Ucs
X-Var-Ttl
X-ServerName
Lfy
X-From
X-SIPLIST1
X-Cache-Expires
X-Mcache
Sever-Int
W
Server-Hostname
Server-Ext
IsBot
PICS-Label
X-GoCache-CacheStatus
X-Fastly-Backend-Reqs
T-Server
X-TRACE-ID
X-Dw-Trace-Id
Lang
X-VC
X-Lb-Id
X-RateLimit-Reset
X-RAMCache
X-Cdn-Request-ID
X-Provided-By
X-UP
X-Nc
Cneonction
X-Fragments
X-B3-ParentSpanId
Ohc-Cache-HIT
Servername
Cdn
X-Fastly-Cache-Hits
WZWS-RAY
Cteonnt-Length
X-Apw-Access-Action
X-Acquia-Purge-Tags
X-Platform-Router
X-Apw-Access-Object
X-Platform-Cluster
X-Acquia-Site
X-Apw-Access-Token
Target-Params
X-WP-CF-Super-Cache
X-Swift-Error
X-Akamai-Request-ID
HitType
X-Yottaa-OS
Vha6-Origin
X-Platform-Processor
X-WP-CF-Super-Cache-Cache-Control
X-Newrelic-App-Data
X-Cc-Via
CF-Cached-On
X-Via-CDN
X-Acquia-Application-Trace
X-Acquia-Application-UUID
Dnion-Transfer-Encoding
X-Cache-ASPX
X-Contensis-Viewer-Groups
Cf-Ipcountry
X-Snapshot-Date
X-Apw-Hits
X-Cache-Ngx
Sid
X-Air-Pt
X-Last-Modified
X-Te-Duration-Ms
X-Te-Count
X-Http-Duration-Ms
Uri
FSS-Cache
X-Akamai-ERPolicy
Server-Ttl
X-Http-Count
X-Akamai-ERRuleID
X-B3-Parentspanid
X-UA
Req-ID
CountryCode
X-Sentry-ID
X-CacheKey
X-Logging-Id
X-Miniprofiler-Ids
X-Lb-Nocache
X-HTML-Edge-Cache
X-Varnish-Authentication
Ngx