Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-Cache-Status
Link
Accept-Ranges
CF-RAY
ETag
Expect-CT
X-XSS-Protection
Pragma
X-Powered-By
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
Alt-Svc
P3P
X-UA-Compatible
X-Served-By
X-Xss-Protection
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-AspNet-Version
X-Adblock-Key
X-Runtime
X-Permitted-Cross-Domain-Policies
X-DNS-Prefetch-Control
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Cache-Status
X-Check
X-Generator
X-Cacheable
Timing-Allow-Origin
X-Content-Security-Policy
X-Iinfo
Feature-Policy
Status
X-Envoy-Upstream-Service-Time
Content-Encoding
Access-Control-Expose-Headers
P3p
X-Drupal-Dynamic-Cache
X-AspNetMvc-Version
X-CDN
Upgrade
X-Via
CF-Ray
Report-To
X-Ws-Request-Id
Access-Control-Max-Age
X-Request-ID
Server-Timing
EagleId
X-Cache-Group
X-Turbo-Charged-By
Keep-Alive
X-UA-Device
Request-Context
X-Ua-Compatible
X-Age
X-Backend
X-Proxy-Cache
X-Server-Powered-By
X-AH-Environment
X-Robots-Tag
X-Hacker
X-Server
X-Amz-Request-Id
Host-Header
NEL
X-Amz-Id-2
Grace
X-Rq
X-Swift-CacheTime
X-Swift-SaveTime
X-Varnish-Cache
X-Nginx-Cache-Status
X-LiteSpeed-Cache
Ali-Swift-Global-Savetime
X-WebKit-CSP
X-Page-Speed
X-Vhost
EagleEye-TraceId
X-Amz-Version-Id
X-OneAgent-JS-Injection
X-Pingback
X-Dispatcher
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
Accept-CH
X-Cache-Spec
X-Host
X-Server-Id
Cf-Railgun
X-Node
X-Backend-Server
X-Readtime
Surrogate-Control
X-Akam-SW-Version
X-Dns-Prefetch-Control
Request-Id
X-Response-Time
X-HW
X-Application-Context
Xkey
Content-Location
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Accept-Ch-Lifetime
Rating
X-Ruxit-JS-Agent
X-Country
X-B3-TraceId
X-Cloud-Trace-Context
X-Cache-Lookup
Accept-CH-Lifetime
X-Trace
X-Url
Allow
X-Content-Type
X-Ac
X-Vname
X-TtlSet
X-PC
X-Aws-Lambda-Call-Status
X-Varnish-TTL
X-Clacks-Overhead
Edge-Control
Fastly-Restarts
X-ESI
X-Mod-Pagespeed
X-Server-Name
Cache-Tag
X-Rack-Cache
Service-Worker-Allowed
X-VARITI-CCR
Verso
X-Element-Page-Cache
MS-Author-Via
X-Vcap-Request-Id
X-Upstream
X-FastCGI-Cache
X-Amz-Rid
X-MS-InvokeApp
X-GitHub-Request-Id
Public-Key-Pins
X-Dw-Request-Base-Id
X-Cached
X-Client-IP
X-D2id
X-Cache-TTL
X-Abt-Application-Version
RTSS
X-Cnection
X-Px
X-Exp-Id
X-Exp-Variant
X-Kinja-Build
X-Use-Magma
X-GoogleNews-Bot
X-Kinja-Server
X-Kinja-Revision
X-Kinja
X-Cdn-Fetch
X-Navigation-Version
X-TTL
Access-Control-Request-Method
X-Powered-By-Plesk
Arr-Disable-Session-Affinity
X-Country-Code
X-NF-Request-ID
X-Goog-Hash
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-Instrumentation
Display
X-Sol
Pagespeed
X-Middleton-Display
AR-Request-ID
AR-SID
AR-CACHE
AR-ATIME
AR-PoweredBy
X-Powered-CMS
X-Version
X-Origin-Cache
X-Middleton-Response
Response
X-CST
X-MSEdge-Ref
X-LLID
Nginx-Cache
TCN
X-Kinsta-Cache
X-Edge-Location-Klb
X-Amz-Server-Side-Encryption
Mrf-Cache-Status
MRF-Tech
X-B3-TraceId-Primal
X-Edge
X-Protected-By
X-RateLimit-Remaining
X-SRCache-Fetch-Status
X-T
X-SRCache-Store-Status
X-HP-Trace-Id
X-Jurisdiction
X-HP-Webp
X-Content-Security-Policy-Report-Only
X-Shield-Request-Id
X-Forwarded-For
X-Mg-S
X-Aspnetmvc-Version
X-Id
Edge-Cache-Tag
X-Language
S
Content-MD5
SPRequestDuration
SPIisLatency
Front-End-Https
Fastcgi-Cache
X-Mid
Realpath
Server-Node
X-Request-Processing-Time
X-Request-Received
Filters
X-Frontend
Pinterest-Version
Pinterest-Generated-By
X-Recruiting
X-Pinterest-Rid
Server-Name
X-Content
X-Ab
X-Cache-Key
X-Ua-Browser
X-Ser
X-NWS-LOG-UUID
X-MCACHE
X-Correlation-Id
X-HS-Cache-Config
X-HS-Content-Id
X-Template
X-HS-Hub-Id
X-Yandex-Sdch-Disable
X-HS-Combine-CSS
X-Ruxit-Js-Agent
X-DynaTrace
X-Ezoic-Cdn
X-SharePointHealthScore
SPRequestGuid
X-ECACHE
X-Hits
X-Parallel-Accel
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
MicrosoftSharePointTeamServices
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Page-Id
Charset
Cache-Tags
Host
Cleartype
X-B3-Sampled
X-Daa-Tunnel
X-Www-Served-By
X-Litespeed-Cache
X-Debug-Info
X-Geo-Country
X-Git-Hash
Alternate-Protocol
X-Content-Options
Accept-Ch
X-DIS-Request-ID
X-Ratelimit-Limit
Fusion-Content-Id
Fusion-Component-Id
Fusion-Deployment-Id
Fusion-Content-Source
Fusion-Template-Id
Fusion-Source
X-Content-Digest
X-Hostname
X-Amzn-Trace-Id
X-Ttl
Cross-Origin-Opener-Policy
Filterid
X-Amz-Replication-Status
X-Varnish-Age
X-F-Cache
X-Grace
X-FB-Debug
X-Activity-Id
X-AppVersion
ServerID
X-DataDome
X-Az
X-Upgrade-Enabled
X-VCache
X-Nginx-Upstream-Cache-Status
X-Accel-Expires
X-N
X-Rid
X-Mobile-URL
X-Fastly-Request-ID
X-Forwarded-Proto
X-Providence-Cookie
X-Request-Guid
X-Route-Name
X-Is-Crawler
X-Flags
X-Aspnet-Duration-Ms
Access-Control-Allow-Method
X-Origin-Server
X-LB-Cache
X-Server-ID
X-Type
X-Seen-By
X-TT
X-Whom
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-Goog-Storage-Class
X-Goog-Metageneration
Viewport
X-App-Environment
X-Goog-Generation
X-Varnish-Grace
Payment
X-Tb
X-FW-Serve
X-FW-Server
X-FW-Type
X-FW-Hash
X-FW-Static
X-WebKit-CSP-Report-Only
X-Fastcgi-Cache
X-FW-Dynamic
Node
X-Distributor
Fastcgi-Useragent
X-User-Agent
X-Ratelimit-Reset
X-Wix-Request-Id
DC
Paypal-Debug-Id
TP-Cache
Country
TP-L2-Cache
Accept-Charset
X-Fastly-Request-Id
X-XRDS-LOCATION
X-App-Server
X-Cache-Rule
X-Webkit-Csp
X-Tec-Api-Version
X-Tec-Api-Origin
X-Tec-Api-Root
X-Cache-Control
X-Via-JSL
X-NGENIX-Cache
X-Cluster-Name
Version
X-Drupal-Cache-Tags
X-Contextid
X-Signature
X-Microsite
X-B-Cache
X-Request-Handler-Origin-Region
X-Buckets
Referer-Policy
Amp-Access-Control-Allow-Source-Origin
Cache-Status
X-Oracle-Dms-Ecid
X-Origin-Upstream-Status
X-Node-Name
X-Logged-In
X-Oracle-Dms-Rid
Refresh
X-Cache-Age
X-Original-Request-Id
X-Erf-Bev-Bev-Is-Generated
SD-X-WS
VIX-Pulpo-Upstream-Status
X-Response-Served-From
X-Browser-Type
VIX-Pulpo-Node
X-Erf-Bev-Bev
X-Load-Cache
X-Rendered-As
X-IPLB-Instance
X-Vgn-Hpd-Reason
X-Is-Bot
X-Real-IP
X-Cache-Expired-At
X-Jobs
X-Page-View
X-Varnish-Backend
X-Revision
X-ProcessESI
X-Debug
X-B
X-RemovedCookies
Access-Control-Request-Headers
NGB
X-Proxy-Cache-Status
X-Mobile
X-Device-Type
X-Instance
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Cache-Action
X-Rule
X-Proxy
X-Cacheable-TTL
X-UUID
Surrogate-Key
X-Drupal-Cache-Contexts
X-G
Akamai-GRN
X-Cache-Time
X-Debug-IsPreview
X-FW-Version
X-Framework
X-Debug-IsConnected
CF-IPCountry
SID
X-Accel-Buffering
X-XRDS-Location
GEO-INFO
X-Air-Hostname
X-Air-Source
X-Air-Trace-Id
X-Oneagent-Js-Injection
X-Cache-NGX
Count-Hit
X-Ratelimit-Remaining
X-Nginx-Cache
X-PressLabs-Stats
Uber-Trace-Id
X-APP-VERSION
X-Cache-Operation
X-Source
X-Azure-Ref
X-Presslabs-Stats
DynaTrace
X-Zen-Fury
X-Ms-Version
X-Ms-Request-Id
X-EdgeConnect-Cache-Status
Protected
Liferay-Portal
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-TEC-API-ROOT
Frame-Options
X-RTag
MS-CV
WPO-Cache-Message
WPO-Cache-Status
X-CDN-Forward
Ms-Operation-Id
X-Servername
X-Cache-Hit
X-Hyper-Cache
Ec-Rule-Version
Healthy
X-Backend-Name
Countrycode
X-RateLimit-Limit
Cross-Origin-Window-Policy
X-IPS-LoggedIn
X-Cache-TTL-Remaining
X-L-Path
Xserver
X-Tumblr-Pixel-1
X-Tumblr-User
X-Mode
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Environment-Context
X-Adobe-Loc
X-Adobe-Content
X-Trace-Id
Content-Disposition
Backend
X-Varnish-Server
X-JoinUs
X-SaId
X-RN-RSRV
X-Detected-As
X-UPSTREAM-Address
X-Content-Age
X-Rewrite-Enabled
Meta-Geo
X-Tid
X-Generation-Time
X-Proxied
Decoy-Debug-TTL
X-Routing-Service
X-Hosted-By
Country-Code
Decoy-Debug-Status
X-Format
X-Sorting-Hat-PodId
X-Uri
X-Sorting-Hat-ShopId
X-Cache-Grace
X-Alternate-Cache-Key
X-Cache-Server
X-Debug-Cache
X-Redis-Cache
Apigw-Requestid
Url
Eomportal-Instance
X-Extlb
X-ShopId
X-Sql-Count
X-Region
Decoy-Debug-Key
X-Zipkin-Id
X-ShardId
X-Shopify-Stage
X-Sql-Duration-Ms
X-PERF
Fastly-SSL
X-No-Session
CDN-Cache
CDN-CachedAt
X-Origin-Date
Mn-Server-Ip
X-Status
X-Section
X-Access
X-PHP-Backend
X-ApacheServer
X-ServerID
Cache-Name
CDN-EdgeStorageId
X-OCL
X-Forwarded-Host
X-Via-Fastly
X-Microcachable
X-PCL
CDN-Uid
X-FB-TRIP-ID
CDN-PullZone
CDN-RequestCountryCode
X-UA-Device-Type
CDN-RequestId
X-NCache
TWC-Connection-Speed
TWC-Device-Class
TWC-GeoIP-Country
X-Say-TTL
Property-Id
TWC-GeoIP-LatLong
X-NYM-Debug-Backend
X-Generated-By
X-Say-Cacheable
Webcakes-App-Version
X-Origin-Hint
X-Content-Powered-By
X-Cluster-Node
X-Cache-Type
X-Timing-Wait
X-Server-W
X-Web-Node
X-Site-Version
X-Akamai-Edgescape
X-Varnish-Beresp-Grace
X-ProxyCache-Status
X-Cache-Host
TWC-Privacy
X-Storage
X-ProxyCache-Key
X-Proxy-Build
Webcakes-App-Name
X-Human
X-BYPASS-REASON
X-SayCDN-TTL
Webcakes-Region
TWC-Locale-Group
Selected-Fe
LB
Cache-Tv-Group
X-Hl-Ver
Section-Io-Cache
X-Pubstack
Retry-After
X-Be
X-Varnishpool
Azure-InstanceId
Content-Secure-Policy
X-Soup
Azure-RegionName
X-LSADC-Cache
X-R9-Blue-Green-Version
Azure-SlotName
Azure-Version
Azure-SiteName
X-NewRelic-App-Data
X-Nginx-Cache-Key
X-Ua
X-Webkit-CSP
X-TIME
X-Unique-Id
DB-Nickname
X-Cache-Remote
OT-Force-Account-Verify
X-Cached-By
X-Bc-Bl
X-Platform-Server
X-TT-LOGID
X-Azure-Ref-OriginShield
X-Auto-Login
Cache
X-Dc
X-Xfnlog-Site
X-Cache-Tags
X-GEO
Source
X-Akamai-Transformed
Upgrade-Insecure-Requests
X-Cdn
SRV
X-LAGOON
From-Origin
X-Origin-CC
X-Varnish-Cache-Hits
X-Origin-TTL
Xet-Cookie
HostName
Mime-Version
X-Request-Time
ServedBy
X-AOL-HN
X-Loop
Cache-Hits
X-Varnish-Hits
X-TNCMS
X-CSRF-Token
X-Time
X-Varnish-Hostname
X-NWS-UUID-VERIFY
X-HTML-Minification-Powered-By
WP-Super-Cache
X-S-Maxage
X-Request-Host
Onion-Location
X-SRV
X-EC-Lua
Webserver
X-FireWall-Port
X-ECache
X-Cache-Enabled
Web-Mar-Node
X-Tumblr-Pixel-3
X-Tumblr-Pixel-2
X-B3-SpanId
N-Cache
X-App-Version
X-Proto
X-Handled-By
S-Rt
X-Endurance-Cache-Level
X-Http-Reason
X-Correlation-ID
X-Akamai-Request-ID2
X-Adobe-Source
Nel
X-RCS-CacheZone
X-Tenant
X-Reqid
X-Origin-Response-Time
Vix-Hermes-Req-Id
Pramga
V-Age
X-A
Fastcgi-X-Cache-Version
Expiry
DCR-Decision-By
X-A-Ccd
Odigeo-Trace-Id
Meta-Geo-Continent
BehaviorPad-Version
Rendered-Blocks
Mobile-Detection-Method
Redirect-Candidate
Sslversion
Surrogated-Key
Xc-Version
DCR-Processing-Time-Ms
User-Cache-Control
A
X-Ckpd-Fst-Backend
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
X-Planisys-CDN-TTL
X-Processor
X-Rojux
X-PBS-Appsvrname
X-PAYTM-SRV-ID
X-NAPM-TraceId
X-Vtex-Processado-Em
X-ND-Cache
X-Orig-Expires
X-S
X-S-Cookie
X-V-Cache
X-TIM-N
X-Vdms-Path
X-Vdms-Version
X-VG-WebCache
X-SRCache-Key
X-Slack-Backend
X-ScT
X-SD-PageType
X-Session-Fingerprint
X-Shop-Environment
X-Ig-Push-State
X-Hnp-Log
X-Backend-TTL
X-B-Cookie
X-Block-Status
X-Cache-NE
X-CF-Lambda-Fn
X-ARC
X-Application
X-A-Dcw
X-A-Dgt
X-A-Wwc
X-Aed
X-CF-Lambda-Version
X-Cluster
X-Forwarded-Path
X-External-Request-Id
X-Ftr-Request-Id
X-Gen-Mode
X-GG-Cache-Date
X-Epic-Correlation-Id
X-Developer
X-Connection-Hash
X-D
X-Destination
X-Vtex-Remote-Cache
X-A-Dam
X-Conf
X-VWS-Id
X-Amz-Meta-S3cmd-Attrs
X-AWS-Id
X-LJ-Flow-ID
X-Mg-Request-UUID
X-MP-GENERATED-AT
X-Time-Microsecs
X-Edge-Location
Server-Info
X-Magnolia-Registration
X-Li-Pop
X-Hash
Origin-EX
Origin-CC
Origin
X-LI-UUID
X-Li-Fabric
X-Mvc-Supplant-Cachable
X-Origin-Expires
X-Origin-Time
Fastcgi-Cache-TTL
X-Policy
Gh-Request-Id
X-Origin
X-Men
X-NodeID
X-Nyt-Route
X-Old-Content-Length
X-Location
X-Gdpr
Wxu-Next-Commit
X-Cache-Info
X-Cdn-Srv
X-Core-Mission
Wxu-Next-Hostname
Wxu-Next-Region
X-Aicache-OS
X-Accel-Expires-Debug
X-Cache-Bucket
X-Cache-Date
True-Client-Country-4JS
Traceparent
X-Forwarded-Site
X-Proxy-Upstream
X-Geo-Header
X-GeoIP-Country-Code
X-Fetched-On
X-Fastly-Cache
X-Date
X-Device-Os
Svr
State
X-GeoIP-Region-Code
Host-ID
Apple-News-Services-Handled
AKAMAI
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
Arc-Country
Apple-News-Services-Request-Url
X-Sucuri-ID
X-SVT-ORM-RULES
X-Webstats-RespID
X-Fastly-Backend
X-VServer
X-Viewer-Country
X-SVT-ORM-VERSION
X-VG-TLSProxy
X-Server-IP
X-Sucuri-Cache
X-Rocket-Nginx-Serving-Static
DSUID
Cmstype
Cmsid
X-Request-URI
CDCHOST
X-Scheme
CacheControlHeader
X-Locale
Environment
X-Via-NSCOPI
X-CGP
X-Datadog-Sampling-Priority
X-Req
X-Csrf-Jwt
X-PHP-Host
X-Core-Value
X-VarnishDD-TTL
X-Datadog-Parent-Id
X-FC-Vary-Parameters
X-Restarts
X-Branch-Name
X-BBC-Edge-Cache-Status
X-Sn-Servicetimems
X-Backend-State
X-JWT-State
X-Is-Gdpr
X-Datadog-Trace-Id
X-RateLimit-Remaining-Second
X-Cache-Id
X-Cache-Debug
X-Has-Esi
X-Cdn-Origin
X-Thinkindot-L3
X-Amz-Apigw-Id
X-ATG-Version
X-Sigma
X-GeoIP-City
X-GeoIP
X-Gzip
X-Node-Id
X-Labrador-Cache-Channel
X-Irp-Debug
X-HS-Content-Campaign-Id
X-HN
X-Sigma-Backend
X-Skip-Cache
X-Amzn-RequestId
X-TH-Server
X-Envoy-Decorator-Operation
X-TrackingId
X-Developers
X-Esi-Check
X-Rocket-Build-Number
X-Gamma-Serve
X-Storefront-Renderer-Rendered
X-RateLimit-Limit-Second
X-Eu-Site
X-UnsetCookies
X-Platform
TDXMobile
Ssr
Server-Host
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
We-Hiring
Thinkindot-Control
Req-Svc-Chain
Release
HA-Ipaddr
Ha-Gx-Prefs
Fastly-GeoIP-CountryCode
L
L5d-Success-Class
Mail-Subject
Locid
Web-Mar-Region
PFcat
Fastly-Drupal-Html
X-Varnish-Beresp-Ttl
CloudFront-Viewer-Country
X-Xrds-Location
Machine
X-Served-From
Adler-Geo
X-Amzn-Remapped-Content-Length
Magicmarker
Cf-Device-Type
X-Generated-On
Fastly-SWR
Fastly-SIE
NM-Fastcgi-Cache
Memcached
X-Level-Front-Cache
X-Worker
Is-Eu
X-Varnish-Remaining-TTL
X-Region-Sid
X-Zone
X-Tx-Id
X-Cache-Var-Map
X-Varnish-CookieINHashed-On
X-Pod-Name
X-Loc
X-Cache-Var
X-Varnish-CookieHashed-On
X-NU-AKA-ACS-Version
X-Owner
X-Variation
X-Varnish-Beresp-Status
X-DefElseHash
X-Response-By
X-DefHash
Platform
X-Rebelmouse-Surrogate-Control
X-DPWN-IS-SECURE
X-Rebelmouse-Cache-Control
Accept-Language
X-Trace-ID
X-Ua-Device
X-NC
AMP-Access-Control-Allow-Source-Origin
NGX
Edge-Cache
X-CS
X-VC-Cache
X-Cache-Backend
X-Wix-Viewer-Type
Kp-EeAlive
X-Qloud-Router
X-Up
X-RPS
X-Mvc-Supplant-OutputCached
X-RSL
X-RPM
X-LB-ID
X-Request-Start
X-DB
CDN
X-Action
X-TraceId
X-DI
X-DW
X-DSS
X-Srv
X-Optimistic-Header
X-CacheTTL
X-Bip
Ms-Author-Via
X-Minions-Version
X-Generated-In
Pics-Label
X-Thanos
X-LB-NoCache
X-M-Reqid
X-Qnm-Cache
X-M-Log
X-Tb-Optimization-Total-Bytes-Saved
Locale
Time
Env
Memory
X-Urbn-Site-Id
X-API-Version
X-Urbn-Context-Path
X-Refresh
X-DC
X-Varnish-Ttl
X-Via-Poph
WebServer
X-Cache-Config
X-Via-Popn
X-Via-Popv
X-Tt-Logid
X-Edge-Pop
X-HA-Backend
X-TA-CDN-Provider
Datacenter
X-Ec-GeoHdr
X-Ec-Fail
GeoIp-Country-Code
X-CACHE-KEY
X-User
X-DynaTrace-JS-Agent
X-Parent-Response-Time
Candidate-Md5Url
NtCoent-Length
Server-ID
X-Esi
X-Servedbyhost
X-Dynatrace
X-MSEdge-Flight
X-MSEdge-Features
X-ZONE
X-Webkit-Csp-Report-Only
X-Cs
X-CLOUD-TRACE-CONTEXT
Cdnsip
On-Server
X-AK-Request-ID
X-Vc
Cdncip
WWW-Authenticate
X-TX-ID
X-Datadome
X-Varnish-Beresp-TTL
X-VCL-Version
X-Fmm-Version
Cluster
My-App
Esi-Enabled
X-Clara-WADP
X-WADP-Cache
X-Var-Ttl
X-App
X-Traceid
Tracecode
Geoip-Latitude
X-LI-Proto
X-Fpc
X-Cache-Ttl
X-CUA
X-URL
X-Pass-Why
X-Cache-PHP
Lfy
X-Unique-ID
T-Server
X-Li-Proto
C-Via
X-From
X-Service
X-VC
DataCenter
Lang
X-Fragments
X-Newrelic-Synthetics
X-FPC
X-B3-Spanid
X-Webkit-CSP-Report-Only
Cf-Int-Pingora-Origin-Digest
X-NODE
Fastly-Drupal-HTML
X-Vcl-Version
Geo-Info
Test
Target-Params
Proxy-Connection
X-Mcache
Resin-Trace
M-TraceId
X-Cache-Status-Check
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
X-Render-Time
X-Provided-By
X-LiteSpeed-Cache-Control
X-RAMCache
Server-Id
X-CSRF-TOKEN
X-Api-Version
X-Ha-Backend
Permissions-Policy
X-ID
GeoIP-Country-Code
MIME-Version
Hostname
X-Httpd
X-Clientip
WZWS-RAY
Hit
Servername
X-Edge-POP
X-Proxy-Cache-Info
X-ServedByHost
X-Dynatrace-Js-Agent
X-Geo
FSS-Cache
X-SB
X-Via-PopV
X-Via-PopN
X-Via-PopH
Producers
X-Pad
X-Cdn-Forward
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
HIT
X-Platform-Processor
X-Fastly-Backend-Reqs
X-Platform-Router
X-Edge-Cache
X-Oss-Request-Id
X-Platform-Cluster
UCS
X-SERVER-NAME
X-LiteSpeed-Tag
X-Oss-Server-Time
X-Oss-Storage-Class
X-Udemy-Cache-App-Namespace
Cache-Host
X-NGINX-Cache
ENV
Section-Io-Origin-Time-Seconds
X-Ec-Custom-Error
X-AIR-PT
X-Ucs
Section-Io-Id
X-Scale
Section-Origin-Responded
Section-Io-Origin-Status
X-ElasticPress-Query
X-Info
X-Pool
S-Cnection
Server-Hostname
Sever-Int
X-Cache-Expires
X-Acquia-Application-UUID
X-Acquia-Application-Trace
X-Acquia-Site
X-Acquia-Purge-Tags
X-Dispatcher-Number
Uri
X-Cache-CFC
X-UP
ServerName
PICS-Label
MD5-Digest
X-Lb-Nocache
Server-Ext
Cneonction
X-Check-Cacheable
X-BBC-Origin-Response-Status
X-GoCache-CacheStatus
X-HS-Status
URI
Ohc-File-Size
X-Srcache-Store-Status
X-Srcache-Fetch-Status
Cteonnt-Length
X-Lb-Id
X-RateLimit-Reset
X-Release
User-Agent
IsBot
X-SIPLIST1
X-Via-Ucdn
Tcn
X-CACHE-AGE
X-Micro-Cache
X-Nc
Fastly-Backend-Name
Server-Ttl
X-Cdn-Request-ID
X-Swift-Error
X-Fastly-Cache-Hits
X-Dw-Trace-Id
X-Vcache
X-Backend-Host
X-Akamai-ERPolicy
X-Newrelic-App-Data
Ngx
X-Snapshot-Date
Cf-Ipcountry
Wpo-Cache-Message
Vha6-Origin
CF-Cached-On
X-Akamai-ERRuleID
X-Yottaa-OS
X-Cms-Context
X-B3-ParentSpanId
Wpo-Cache-Status
X-Air-Pt
Sid
Load-Balancing
X-HostName
X-Cache-Ngx
X-ServerName
X-Fetch-By
X-BCube-Filmed-By
X-Cache-ASPX
GeoIP-Latitude
X-Via-CDN
X-B3-Parentspanid
X-IN-APIGATEWAYSSL
X-Shopify-Generated-Cart-Token
X-APP
Req-ID
X-Litespeed-Cache-Control
X-IN-APIGATEWAY
CountryCode
Inserted-Into-Cache-At
EpKe-Alive
X-Http-Count
X-Http-Duration-Ms
X-Te-Count
X-Logging-Id
X-Apw-Access-Action
X-Apw-Hits
X-Apw-Access-Token
X-Apw-Access-Object
X-Te-Duration-Ms
X-Varnish-Authentication
Shield-Pop
X-Akamai-Request-ID
X-Contensis-Viewer-Groups
X-Sentry-ID
X-UA
X-CacheKey
X-Last-Modified
X-Akamai-Pragma-Client-IP