Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
X-Powered-By
Pragma
CF-RAY
X-XSS-Protection
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
Alt-Svc
X-Xss-Protection
X-Cache-Hits
X-UA-Compatible
P3P
X-Served-By
CF-Ray
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Request-Id
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
Access-Control-Allow-Credentials
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
X-Drupal-Cache
X-Cache-Status
X-Generator
X-Check
X-Cacheable
X-Envoy-Upstream-Service-Time
X-FRAME-OPTIONS
X-Request-ID
Timing-Allow-Origin
X-Iinfo
X-Dns-Prefetch-Control
X-DNS-Prefetch-Control
X-Drupal-Dynamic-Cache
Feature-Policy
Server-Timing
X-Content-Security-Policy
Access-Control-Expose-Headers
Content-Encoding
X-CDN
X-XSS-PROTECTION
Status
Upgrade
X-AspNetMvc-Version
P3p
Access-Control-Max-Age
X-Amz-Request-Id
X-Via
X-Amz-Id-2
Request-Context
X-Turbo-Charged-By
X-Backend
X-Cache-Group
X-AH-Environment
X-Robots-Tag
Cf-Edge-Cache
Keep-Alive
Host-Header
X-Hacker
X-UA-Device
X-Proxy-Cache
X-Vhost
X-Server
X-Rq
Allow
X-Server-Powered-By
X-Ws-Request-Id
X-Age
X-Dispatcher
X-Varnish-Cache
EagleId
X-Amz-Version-Id
X-LiteSpeed-Cache
Nel
Grace
Cf-Apo-Via
Cf-Railgun
X-Page-Speed
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Device
EagleEye-TraceId
X-OneAgent-JS-Injection
X-Swift-CacheTime
X-Swift-SaveTime
X-Aws-Lambda-Call-Status
Ali-Swift-Global-Savetime
X-Pingback
X-Host
X-Node
Accept-CH
X-Cache-Lookup
X-CST
X-WebKit-CSP
X-Backend-Server
X-Server-Id
Surrogate-Control
X-Readtime
Permissions-Policy
X-Nginx-Cache-Status
X-Nginx-Upstream-Cache-Status
X-Akam-SW-Version
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Application-Context
Accept-CH-Lifetime
Request-Id
X-Content-Security-Policy-Report-Only
X-Cloud-Trace-Context
X-Ruxit-JS-Agent
X-Response-Time
X-HW
X-Ua-Compatible
X-Trace
Xkey
X-Edge
Content-Location
X-Clacks-Overhead
X-Mod-Pagespeed
X-Url
Rating
X-ESI
X-Midtier
X-Amz-Server-Side-Encryption
X-ECACHE
X-Mcache
Accept-Ch-Lifetime
Cache-Tag
X-Country
X-MS-InvokeApp
X-Rack-Cache
X-Upstream
X-D2id
X-Powered-By-Plesk
X-Vcap-Request-Id
X-Exp-Variant
X-Kinja-Revision
X-GoogleNews-Bot
X-Kinja-Server
X-Use-Magma
X-Kinja
X-Cdn-Fetch
X-Exp-Id
Verso
X-Kinja-Build
X-Element-Page-Cache
Accept-Ch
Edge-Control
Service-Worker-Allowed
X-Vname
X-PC
X-TtlSet
RTSS
X-Oneagent-Js-Injection
X-Ac
X-Country-Code
Origin-Trial
X-WebKit-CSP-Report-Only
X-VARITI-CCR
X-Goog-Hash
X-Navigation-Version
X-Abt-Application-Version
Fastly-Restarts
X-Cache-TTL
X-GitHub-Request-Id
X-Varnish-TTL
X-Browser-Type
X-Amz-Rid
X-Cached
X-Kinja-CCPA
X-Aspnetmvc-Version
Cross-Origin-Opener-Policy
X-Webkit-CSP
Display
Pagespeed
X-Middleton-Display
X-Sol
X-Server-Name
X-Ruxit-Js-Agent
X-NWS-LOG-UUID
X-Dw-Request-Base-Id
X-Amzn-Trace-Id
X-SharePointHealthScore
SPRequestGuid
X-Content-Type
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
SPRequestDuration
X-Times
SPIisLatency
X-Erf-Bev-Bev-Is-Generated
X-Server-Lifecycle-Phase
X-Erf-Bev-Bev
X-Kraken-Loop-Name
X-Instrumentation
AR-ATIME
AR-SID
X-Powered-CMS
X-Cache-Key
AR-PoweredBy
AR-Request-ID
X-Ttl
X-Pinterest-Rid
Pinterest-Generated-By
Pinterest-Version
X-Mg-S
Arr-Disable-Session-Affinity
Response
X-Middleton-Response
X-FastCGI-Cache
X-Litespeed-Cache
X-Client-IP
X-Fastly-Request-ID
X-Version
X-Cnection
X-HP-Trace-Id
X-HP-Webp
X-Jurisdiction
X-Ser
X-B3-Traceid
X-B3-TraceId
AR-CACHE
Nginx-Cache
Cache-Tags
X-Accel-Expires
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-T
Cache-Status
X-NF-Request-ID
Edge-Cache-Tag
X-Hits
Front-End-Https
X-RateLimit-Remaining
X-MSEdge-Ref
X-Px
Public-Key-Pins
X-Recruiting
Payment
X-LLID
X-Frontend
X-Ua-Browser
S
MRF-Tech
Mrf-Cache-Status
X-Shield-Request-Id
Server-Node
X-B3-TraceId-Primal
X-RateLimit-Limit
X-Request-Received
X-Request-Processing-Time
X-Server-ID
X-Daa-Tunnel
Content-MD5
X-GUploader-UploadID
X-TTL
X-Goog-Metageneration
X-DIS-Request-ID
MicrosoftSharePointTeamServices
X-PressLabs-Stats
Access-Control-Request-Method
X-Amzn-RequestId
X-Content-Digest
X-Amz-Apigw-Id
TP-Cache
Realpath
X-Protected-By
X-HS-Cache-Config
X-Forwarded-For
X-Request-Handler-Origin-Region
X-Distributor
X-HS-Combine-CSS
X-Microsite
X-HS-Hub-Id
X-HS-Content-Id
Fastcgi-Cache
X-FB-Debug
Access-Control-Allow-Method
X-Page-Id
X-LB-Cache
X-Cluster-Name
Accept-Charset
X-Rid
X-Geo-Country
X-Ratelimit-Remaining
X-Webkit-Csp
TP-L2-Cache
X-Erf-Stays-Pdp-Viaduct-Migration-Web
X-Webkit-CSP-Report-Only
X-B3-Sampled
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-Fastcgi-Cache
X-Aspnet-Version
X-Ua-Device
X-Ezoic-Cdn
Count-Hit
X-Seen-By
X-Hostname
Cross-Origin-Resource-Policy
X-Correlation-Id
Cleartype
X-Newrelic-App-Data
X-Edge-Location-Klb
X-Kinsta-Cache
X-App-Server
Referer-Policy
X-Varnish-Backend
X-Logged-In
DC
X-Content-Options
X-Ratelimit-Limit
X-Mobile
X-Id
X-Git-Hash
TCN
X-Hosted-By
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Origin-Cache
X-Amz-Replication-Status
X-Fb-Rlafr
X-Debug-Info
X-Flags
X-Is-Crawler
X-Aspnet-Duration-Ms
X-Route-Name
X-Request-Guid
X-Providence-Cookie
X-Contextid
Surrogate-Key
X-Grace
Retry-After
X-TT
X-Revision
X-App-Environment
X-Forwarded-Proto
X-Amz-Meta-S3cmd-Attrs
X-Varnish-Grace
X-IPS-LoggedIn
X-Envoy-Decorator-Operation
X-Xrds-Location
Frame-Options
X-F-Cache
X-Azure-Ref
X-RateLimit-Reset
Section-Io-Cache
X-Wix-Request-Id
X-Magnolia-Registration
X-Whom
MS-Author-Via
Healthy
X-Proxy-Cache-Info
Alternate-Protocol
X-Origin-Server
X-Akamai-Edgescape
Charset
X-App-Version
Viewport
X-Www-Served-By
X-Backend-Name
X-COUNTRY
WPO-Cache-Status
X-Language
WPO-Cache-Message
X-Activity-Id
X-AppVersion
X-Az
X-B
Filterid
X-Varnish-Server
Paypal-Debug-Id
SRV
X-Original-Request-Id
SD-X-WS
X-Datadog-Trace-Id
X-Response-Served-From
VIX-Pulpo-Node
X-Datadog-Sampling-Priority
VIX-Pulpo-Upstream-Status
X-Http-Reason
Host
X-Datadog-Parent-Id
X-Cache-Rule
Server-Name
Front
Akamai-GRN
X-Rule
X-Instance
X-Cache-Grace
X-User-Agent
X-Akamai-Request-ID2
X-Edge-Location
X-UUID
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Page-View
X-Varnish-Age
X-Region
X-Status
X-Unique-Id
Amp-Access-Control-Allow-Source-Origin
X-Jobs
X-ARC
X-Time
Protected
X-Cacheable-TTL
X-EdgeConnect-Cache-Status
From-Origin
X-Framework
X-Environment-Context
X-FW-Hash
X-FW-Server
X-FW-Serve
X-FW-Type
X-FW-Dynamic
X-Adobe-Loc
X-FW-Static
X-L-Path
Fastly-SIE
X-Rendered-As
X-Is-Bot
Country
X-Adobe-Content
X-FW-Version
Fastly-SWR
X-N
X-Load-Cache
X-ProcessESI
X-Yottaa-Optimizations
ServerID
X-G
X-RemovedCookies
X-Cache-Time
X-Tumblr-Pixel-0
X-DataDome
X-Client-Ip
X-Type
X-Yottaa-Metrics
X-Rocket-Nginx-Serving-Static
X-Tumblr-Pixel-1
X-Tumblr-Pixel
X-Tumblr-User
X-Trace-Id
X-Proxy
X-Nf-Request-Id
Content-Disposition
Access-Control-Request-Headers
X-Mg-Request-UUID
X-Datadog-Sampled
X-Debug-IsPreview
X-Debug-IsConnected
X-B-Cache
X-Signature
X-Vcache
X-Amzn-Remapped-Content-Length
X-CDN-Forward
X-Cache-Age
X-Cache-Control
X-ECache
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
Backend
X-Tec-Api-Origin
X-Tec-Api-Version
X-Tec-Api-Root
Countrycode
Refresh
X-DynaTrace
X-Drupal-Cache-Tags
X-Servername
Xet-Cookie
X-Erf-Web-Scheduler
X-Httpd
Accept-Language
X-Tt-Trace-Host
X-Tt-Trace-Tag
Url
X-DynaTrace-JS-Agent
X-Generated-By
X-XRDS-LOCATION
X-Source
X-HTML-Minification-Powered-By
X-XRDS-Location
X-Template
X-Nginx-Cache
Webserver
CF-IPCountry
X-Device-Type
X-Mode
X-Content-Powered-By
X-NYM-Debug-Backend
Xserver
Version
X-Storage
GEO-INFO
X-Content-Age
X-Cache-Operation
Meta-Geo
Filters
X-ServerID
Locale
X-GeoCode
X-GeoCountry
Load-Balancing
X-Director
X-Cache-Action
X-Urbn-Context-Path
X-JoinUs
X-SaId
X-Urbn-Site-Id
X-UPSTREAM-Address
X-LAGOON
X-Rn-Rsrv
S-Rt
X-Rewrite-Enabled
Onion-Location
X-Cluster-Node
X-Container-Uri
OT-Force-Account-Verify
X-Forwarded-Host
X-Git-Commit
X-Varnish-Hostname
X-Say-Cacheable
X-Say-TTL
X-SayCDN-TTL
X-Ms-Request-Id
X-VC-Cache
X-Adobe-Source
X-Detected-As
X-Cache-Server
X-Lambda-Id
Web-Mar-Node
Azure-SiteName
Azure-SlotName
Azure-Version
X-PHP-Host
Azure-RegionName
Azure-InstanceId
X-Cache-Hit
X-Varnish-Cache-Hits
X-Ms-Version
X-Labrador-Cache-Channel
X-VCT
X-Tncms
X-Served-From
X-Tb
X-Sql-Duration-Ms
X-Soup
X-Sql-Count
X-RM-Cache-TTL
X-Loop
X-Extlb
X-R9-Blue-Green-Version
X-FB-TRIP-ID
X-CCDN-Origin-Time
X-RCS-CacheZone
DB-Nickname
X-Hcs-Proxy-Type
X-Generation-Time
X-CCDN-CacheTTL
X-URL
X-Proto
Cross-Origin-Window-Policy
X-Routing-Service
X-Zipkin-Id
X-Skip-Cache
X-Proxied
Mn-Server-Ip
X-Logging-Id
Node
Selected-Fe
TWC-Connection-Speed
TWC-Device-Class
X-Proxy-Build
TWC-Locale-Group
X-Format
Webcakes-App-Name
Webcakes-Region
X-Fetched-On
X-Tumblr-Pixel-2
X-Tumblr-Pixel-3
TWC-Privacy
X-Uri
TWC-GeoIP-LatLong
X-Origin-Hint
X-Timing-Wait
X-Debug
TWC-GeoIP-Country
Webcakes-App-Version
Fastcgi-Useragent
X-MCACHE
Property-Id
X-Tt-Logid
Uber-Trace-Id
X-Zen-Fury
X-Endurance-Cache-Level
X-LSADC-Cache
Source
X-Ua
X-Redis-Cache
X-B3-SpanId
X-Sucuri-ID
X-Sucuri-Cache
X-NGENIX-Cache
CDN-RequestId
X-Drupal-Cache-Contexts
Section-Origin-Responded
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
Section-Io-Id
X-Oracle-Dms-Ecid
X-Oracle-Dms-Rid
X-Srv
X-S
X-Origin-Date
X-Upgrade-Enabled
X-MP-GENERATED-AT
X-Ratelimit-Reset
X-TimeS
X-FTR-Request-ID
X-Origin-TTL
X-Varnish-Hits
X-Pass-Why
X-Origin-CC
Liferay-Portal
NGB
Upgrade-Insecure-Requests
X-Real-IP
Fastly-Drupal-HTML
X-Cache-Expired-At
X-Newrelic-Synthetics
X-Akamai-Transformed
X-Handled-By
X-CACHE-AGE
X-Xfnlog-Site
X-Reqid
X-Optimistic-Header
X-Cms-Context
X-Cache-TTL-Remaining
Apigw-Requestid
X-UA-Device-Type
X-Hl-Ver
X-Node-Name
ServedBy
X-Via-JSL
X-Restarts
CDN-RequestPullSuccess
X-Cache-Type
X-BYPASS-REASON
X-No-Session
X-ProxyCache-Key
X-Cache-Host
X-ProxyCache-Status
X-RTag
MS-CV
CDN-EdgeStorageId
CDN-CachedAt
CDN-PullZone
CDN-RequestCountryCode
CDN-Uid
CDN-RequestPullCode
CDN-Cache
Ms-Operation-Id
X-GEO
X-CSRF-Token
X-Pubstack
X-Parent-Response-Time
X-ID
X-Varnish-Ttl
X-AWS-Id
X-LJ-Flow-ID
X-VWS-Id
X-Cluster
X-Server-W
X-IPLB-Instance
X-IPLB-Request-ID
WP-Super-Cache
L
X-A-Dcw
BehaviorPad-Version
X-Conf
HA-Ipaddr
L5d-Success-Class
Ha-Gx-Prefs
X-Destination
X-A-Dgt
X-Debug-Cache-Store
X-A-Wwc
Vix-Hermes-Req-Id
Canary
X-Vdms-Version
X-Vdms-Path
Lang
Fastly-SSL
X-Aed
Web-Mar-Region
X-D
X-Debug-Cache-Fetch
DCR-Processing-Time-Ms
X-We-Are-Hiring
T-Server
DCR-Decision-By
Candidate-Md5Url
X-A
X-A-Ccd
Xc-Version
X-A-Dam
Magicmarker
X-Csrf-Jwt
X-Viewer-Country
X-Worker
X-Tx-Id
X-CGP
X-SRCache-Key
Server-Host
X-ScT
X-Ec-GeoHdr
X-Application
X-S-Cookie
X-Epic-Correlation-Id
X-Rojux
X-Dispatcher-Number
X-Bl-Debug
X-SD-PageType
X-B-Cookie
Surrogated-Key
X-Slack-Backend
X-Slack-Shared-Secret-Outcome
X-Ec-Custom-Error
Sslversion
X-Ec-Fail
X-BCube-Filmed-By
X-Bc-Bl
Rendered-Blocks
X-App-Name
Ngx.Var.Host
X-Developer
Odigeo-Trace-Id
X-Vtex-Remote-Cache
X-CF-Lambda-Fn
N-Cache
MD5-Digest
X-CF-Lambda-Version
Meta-Geo-Continent
True-Client-Country-4JS
X-FC-Vary-Parameters
X-Eu-Site
X-Request-Host
Redirect-Candidate
W
X-External-Request-Id
X-Fastly-Backend
X-CacheTTL
X-Cache-NE
X-App
X-AB
X-Proxy-Cache-Status
Cache-Provider
X-Datadome
X-DefHash
Cf-Device-Type
Gh-Request-Id
X-Cdn-Diag
Thinkindot-CacheControl-Type
Platform
Origin-Agent-Cluster
Origin
Thinkindot-Control
X-Cdn-Origin
Producers
Release
X-Bip
Content-Secure-Policy
TDXMobile
X-Cache-Bucket
Thinkindot-CacheControl
X-Cache-Debug
Mail-Subject
X-Clientip
Datacenter
X-Date
CPC-Cache
CPC-Age
Cmsid
Cmstype
Environment
Expect-Staple
Is-Eu
X-CMSURLCustom
X-Core-Mission
X-Core-Value
Fastly-Backend-Name
Gannett-Cam-Experience-Id
X-DefElseHash
X-Wikidot-Backend
X-Test
X-Thanos
X-Thinkindot-L3
X-Accel-Buffering
X-Accel-Expires-Debug
X-Pool
X-Policy
X-Platform
X-Up
X-Var-Ttl
X-Origin-Time
X-Varnish-Remaining-TTL
X-DPWN-IS-SECURE
X-Varnish-CookieINHashed-On
X-Owner
X-Variation
X-Varnish-CookieHashed-On
X-Tenant
X-Qloud-Router
X-Shop-Environment
X-ShardId
X-Server-IP
X-ShopId
X-Shopify-Stage
X-Sn-Servicetimems
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-S-Maxage
X-Refresh
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-Request-Time
X-SVT-ORM-VERSION
X-Storefront-Renderer-Rendered
X-SVT-ORM-RULES
X-Orig-Expires
X-Varnishpool
X-Generated-On
X-VServer
We-Hiring
X-Geo-Header
X-GeoIP-Country-Code
X-Org
X-Hash
X-GeoIP-Region-Code
VNS-Cache
X-Wikidot-Static-Cache
Host-ID
Adler-Geo
AKAMAI
X-Forwarded-Path
VNS-Age
X-Wix-Viewer-Type
X-Gdpr
X-Human
X-Alternate-Cache-Key
X-Nananana
X-Micro-Cache
X-Vmg-Version
X-Nitro-Cache
X-Node-Id
X-Old-Content-Length
X-Nyt-Route
X-NodeID
X-Mvc-Supplant-Cachable
X-VG-TLSProxy
X-Cache-Status-Check
X-Level-Front-Cache
X-VG-WebCache
X-Irp-Debug
X-Mid
User-Cache-Control
X-TIME
AMP-Access-Control-Allow-Source-Origin
X-Akamai-Device-Characteristics
X-Auto-Login
X-ApacheServer
X-Fmm-Version
X-INCAP-ABP
X-Loc
X-Hnp-Log
X-Gzip
X-GeoIP
X-Mly-Id
X-Mvc-Supplant-OutputCached
X-PAYTM-SRV-ID
X-PERF
X-Origin-Response-Time
X-Origin
X-Nginx-Cache-Key
X-Gen-Mode
X-WA-Info
X-Clara-WADP
X-Device-Os
X-Cdn-Srv
X-Cache-Info
X-Cache-Id
X-Dispatcher-Server
X-Esi-Check
X-WADP-Cache
Cache-Name
X-From
X-Forwarded-Site
X-Block-Status
X-BBC-Edge-Cache-Status
Sever-Int
Machine
Fastly-GeoIP-CountryCode
NM-Fastcgi-Cache
Server-Hostname
Req-Svc-Chain
X-Geo-Region
Server-Ext
Esi-Enabled
Apple-News-Services-Handled
Country-Code
CloudFront-Viewer-Country
CDCHOST
Apple-News-Services-Request-Url
Apple-News-Services-Host
DSUID
Apple-News-Services-Parsed-Url
X-Correlation-ID
X-Vcl-Version
X-TraceId
X-Op-Id-All
X-NCache
X-Instance-Name
NGX
Pics-Label
C-Via
Wxu-Next-Commit
X-AIR-PT
X-Section
Wxu-Next-Hostname
Ssr
X-Cache-Enabled
X-Access
Wxu-Next-Region
Server-Info
X-B3-Spanid
X-Dc
X-LB-NoCache
X-Fastly-Request-Id
X-Via-Fastly
X-Vgn-Hpd-Reason
X-Amz-Meta-Cb-Modifiedtime
X-API-Version
X-Accel-Version
X-HA-Backend
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Ttl
X-JWT-State
X-Is-Gdpr
X-CACHE-GROUP
X-Has-Esi
Memcached
Server-ID
X-Is-Supported-Browser
X-Is-Tablet
X-Is-Mobile
X-Browser-Name
X-Buckets
X-Is-Desktop
X-Tcp-Rtt
Hostname
IsBot
Memory
Cdn-Requestid
Time
X-SIPLIST1
Sid
Origin-CC
Cache-Hits
X-Scale
X-Platform-Router
X-Platform-Processor
X-Platform-Cluster
Origin-EX
YJS-ID
X-Wp-Cf-Super-Cache-Active
X-ZONE
X-Tb-Optimization-Total-Bytes-Saved
CF-Ctrl
X-TIM-N
X-Air-Trace-Id
X-PHP-Backend
Location
X-Air-Hostname
X-B3-Parentspanid
X-Air-Source
X-Zone
X-Presslabs-Stats
X-WP-CF-Super-Cache-Active
X-Cached-By
X-TA-CDN-Provider
X-Fpc
X-Internal-Host
X-Backend-Instance
Resin-Trace
X-Frame-Option
X-Azure-Ref-OriginShield
X-Hyper-Cache
X-Origin-Cache-Key
X-Cs
X-DC
X-NGINX-Cache
Uri
GeoIP-Latitude
X-VC
X-LiteSpeed-Cache-Control
X-Site-Version
Cache-Host
X-Origin-Expires
Epwk-X-Cache
X-DataCenter
X-VCache
X-Microcachable
X-Webstats-RespID
X-Service
X-Info
X-Country-Code-Real
X-FTR-Backend
X-FTR-Balancer
X-FTR-Backend-Server
GeoIp-Country-Code
X-Nitro-Cache-From
True-Client-Ip
X-FTR-Expires
X-Nitro-Rev
X-Locale
X-FTR-Cache-Status
XM
X-Web-Node
X-VarnishDD-TTL
X-Pod-Name
GeoIP-Country-Code
LB
PFcat
X-HN
X-Edge-Server
True-Client-IP
Cdn
Cdn-Request-Time
XServer
User-Agent
X-Ad-Defer-Variation
Cdn-Host
X-Datacenter
X-SRV
X-CS
X-Cache-Ttl
NtCoent-Length
X-Geo
X-HostName
X-CSRF-TOKEN
X-NewRelic-App-Data
Tcn
Edge-Copy-Time
X-FL-EDGE
Req-ID
A
M-TraceId
Locid
Srvid
X-NMSegId
X-Via-CDN
WZWS-RAY
X-Via-Edge
X-Via-SSL
X-FL-QIT-DEBUG
Fastly-Drupal-Html
WebServer
X-FPC
X-Ad-Load-Variation
X-Vercel-Cache
X-Vercel-Id
X-TRACE-ID
X-CLOUD-TRACE-CONTEXT
SID
Cf-Ipcountry
Request-ID
X-LiteSpeed-Tag
X-MSEdge-Features
Pramga
X-FireWall-Port
X-ATG-Version
X-Cache-ASPX
X-MSEdge-Flight
Cluster
X-Contensis-Viewer-Groups
X-Pad
X-Moov-T
X-M-Reqid
X-M-Log
X-Varnish-Authentication
X-Moov-Xdn-Version
X-Request-Start
X-Scope-Id
X-Varnish-Beresp-Status
X-NWS-UUID-VERIFY
X-Request-URI
Cache-Key
X-Qnm-Cache
X-Shield-Cache-Expires
X-Api-Version
CountryCode
HostName
X-Cdn-Request-ID
X-APP-VERSION
Content-Style-Type
X-Amz-Meta-Opti
Content-Script-Type
X-Air-Pt
Path
Cdncip
X-Esi
Edge-Cache
X-Cache-Date
Cdnsip
X-AK-Request-ID
Cache-Tv-Group
X-TH-Server
X-Branch-Name
CDN
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-Via-Popv
X-LB-ID
X-V-Cache
Yak-Timeinfo
X-Req
X-SB
X-Render-Time
X-Via-Poph
X-Via-Popn
X-Proxy-CacheRZ
Tube-Got-Eval
X-Platform-Server
X-Planisys-CDN-TTL
Tube-Get-Contents
Click-Count-Error
Click-Count-Action-Start
X-Github-Request-Id
State
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
X-Aicache-OS
X-B3-Trace-ID
X-WP-CF-Super-Cache-Cookies-Bypass
X-HS-Content-Campaign-Id
X-Acquia-Purge-Cdn-Unconfigured
Tube-Got-Results
XkeyRZ
Tube-Return
X-Cache-FS-Status
X-VCL-Version
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-Upstream-Ht
Lb
X-TT-LOGID
X-CACHE-KEY
X-Upstream-Ct
Srv
X-Cdn-Forward
Wpo-Cache-Message
Geoip-Latitude
X-Vgn-Hpd-Variations-Key
X-Wp-Cf-Super-Cache
X-Tim-N
X-Wp-Cf-Super-Cache-Cache-Control
X-Vgn-Hpd-Cached
V-Age
X-Vgn-Hpd-Ssi
X-Release
Wpo-Cache-Status
X-Men
X-Fastly-Cache
X-Wa
Proxy-Connection
X-Nc
X-Servedbyhost
X-Akamai-Pragma-Client-IP
On-Server
X-Vary
X-Lb-Cache
X-Ha-Backend
X-HS-Status
CF-Cached-On
X-Dw-Trace-Id
X-Sigma
X-User
X-Sigma-Backend
X-Generated-In
X-Traceid
MIME-Version
X-Cache-Remote
Ohc-File-Size
X-UA
X-Rocket-Build-Number
Ngx-Var-Key
Server-Id
My-App
Ohc-Cache-HIT
X-Fastly-Backend-Reqs
X-Via-Ucdn
PICS-Label
X-Lb-Nocache
X-Acquia-Purge-Tags
X-Acquia-Application-UUID
X-CUA
X-Acquia-Application-Trace
Cache
X-Acquia-Site
X-EC-Lua
X-TX-ID
X-Iplb-Instance
X-Iplb-Request-Id
Yjs-Id
X-Gamma-Serve
X-GeoIP-City
Warning
X-Scheme
Inserted-Into-Cache-At
X-GoCache-CacheStatus
X-WA
X-NC
X-ServedByHost
Mime-Version
CACHE-MISS-TO-ORIGIN
X-Fastly-Cache-Hits
X-Litespeed-Cache-Control
Cneonction
X-Miniprofiler-Ids
X-CF-Cache-Header-Cache-Control
X-Udemy-Cache-App-Namespace
X-CF-Cache-Header-Vary
X-RAMCache
Log-Origin
Vha6-Origin
X-Cached-Since
X-ElasticPress-Query
Ngx
X-Snapshot-Date