Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
X-Powered-By
Pragma
CF-RAY
X-XSS-Protection
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
Alt-Svc
X-Xss-Protection
P3P
X-Cache-Hits
X-UA-Compatible
X-Served-By
CF-Ray
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Request-Id
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
Access-Control-Allow-Credentials
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
X-Drupal-Cache
X-Cache-Status
X-Generator
X-Check
X-Cacheable
X-Envoy-Upstream-Service-Time
X-FRAME-OPTIONS
X-Request-ID
Timing-Allow-Origin
X-Iinfo
X-Dns-Prefetch-Control
X-DNS-Prefetch-Control
X-Drupal-Dynamic-Cache
Feature-Policy
Server-Timing
X-Content-Security-Policy
Access-Control-Expose-Headers
Content-Encoding
Status
X-XSS-PROTECTION
X-CDN
Upgrade
X-AspNetMvc-Version
Access-Control-Max-Age
X-Amz-Request-Id
X-Via
X-Amz-Id-2
Request-Context
X-Turbo-Charged-By
X-Backend
X-Cache-Group
X-AH-Environment
X-Robots-Tag
Cf-Edge-Cache
Keep-Alive
Host-Header
X-Hacker
X-UA-Device
X-Proxy-Cache
X-Vhost
X-Server
X-Rq
X-Server-Powered-By
Allow
X-Ws-Request-Id
X-Age
X-Dispatcher
X-Varnish-Cache
EagleId
X-Amz-Version-Id
X-LiteSpeed-Cache
P3p
Nel
Grace
Cf-Apo-Via
Cf-Railgun
X-Page-Speed
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Device
EagleEye-TraceId
X-Swift-SaveTime
X-Swift-CacheTime
X-Aws-Lambda-Call-Status
Ali-Swift-Global-Savetime
X-OneAgent-JS-Injection
X-Pingback
X-Host
X-Node
Accept-CH
X-WebKit-CSP
X-Cache-Lookup
X-CST
X-Backend-Server
X-Server-Id
Surrogate-Control
X-Readtime
Permissions-Policy
X-Nginx-Cache-Status
X-Nginx-Upstream-Cache-Status
X-Akam-SW-Version
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Application-Context
Request-Id
X-Content-Security-Policy-Report-Only
Accept-CH-Lifetime
X-Cloud-Trace-Context
X-Ruxit-JS-Agent
X-Response-Time
X-HW
X-Ua-Compatible
X-Trace
Xkey
X-Edge
Content-Location
X-Clacks-Overhead
X-Mod-Pagespeed
Rating
X-Url
X-ESI
Accept-Ch-Lifetime
X-Midtier
X-Amz-Server-Side-Encryption
X-Oneagent-Js-Injection
X-ECACHE
X-Mcache
Cache-Tag
X-Country
X-MS-InvokeApp
X-Upstream
X-Rack-Cache
X-D2id
X-Powered-By-Plesk
X-Vcap-Request-Id
Verso
X-Kinja-Build
X-Exp-Variant
X-GoogleNews-Bot
X-Cdn-Fetch
X-Kinja-Revision
X-Kinja-Server
X-Use-Magma
X-Exp-Id
X-Kinja
X-Element-Page-Cache
Accept-Ch
Edge-Control
Service-Worker-Allowed
X-PC
X-Vname
X-TtlSet
RTSS
X-Ac
X-Country-Code
Origin-Trial
X-Goog-Hash
X-VARITI-CCR
X-Navigation-Version
X-Abt-Application-Version
Fastly-Restarts
X-Cache-TTL
X-WebKit-CSP-Report-Only
X-GitHub-Request-Id
X-Varnish-TTL
X-Browser-Type
X-Amz-Rid
X-Cached
X-Kinja-CCPA
X-Aspnetmvc-Version
Cross-Origin-Opener-Policy
X-Webkit-CSP
Pagespeed
X-Middleton-Display
X-Sol
Display
X-Ruxit-Js-Agent
X-NWS-LOG-UUID
X-Server-Name
X-Dw-Request-Base-Id
X-Amzn-Trace-Id
SPRequestGuid
X-SharePointHealthScore
X-Ttl
X-Content-Type
SPIisLatency
SPRequestDuration
X-Times
X-Instrumentation
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Powered-CMS
AR-ATIME
AR-Request-ID
AR-PoweredBy
AR-SID
X-Cache-Key
Pinterest-Version
X-Pinterest-Rid
X-Mg-S
Pinterest-Generated-By
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
X-B3-Traceid
Arr-Disable-Session-Affinity
Response
X-Middleton-Response
X-Litespeed-Cache
X-Client-IP
X-Fastly-Request-ID
X-Version
X-Cnection
X-Jurisdiction
X-Ser
X-HP-Webp
X-HP-Trace-Id
Nginx-Cache
AR-CACHE
X-FastCGI-Cache
X-Accel-Expires
Cache-Tags
X-T
X-SRCache-Fetch-Status
X-SRCache-Store-Status
Cache-Status
Edge-Cache-Tag
X-B3-TraceId
X-Hits
Front-End-Https
X-MSEdge-Ref
Public-Key-Pins
X-Px
X-NF-Request-ID
X-Recruiting
Payment
X-RateLimit-Remaining
X-Frontend
S
X-LLID
X-Ua-Browser
MRF-Tech
Mrf-Cache-Status
X-B3-TraceId-Primal
X-Shield-Request-Id
Server-Node
X-Request-Received
X-Request-Processing-Time
X-Server-ID
X-GUploader-UploadID
X-Goog-Metageneration
Content-MD5
X-Daa-Tunnel
X-DIS-Request-ID
X-RateLimit-Limit
MicrosoftSharePointTeamServices
Access-Control-Request-Method
X-PressLabs-Stats
X-Amzn-RequestId
X-Content-Digest
TP-Cache
X-Amz-Apigw-Id
X-Ratelimit-Remaining
Realpath
X-Webkit-CSP-Report-Only
X-Protected-By
X-HS-Cache-Config
X-HS-Combine-CSS
X-HS-Content-Id
X-HS-Hub-Id
X-Distributor
X-Forwarded-For
X-Microsite
X-Request-Handler-Origin-Region
Fastcgi-Cache
X-TTL
X-FB-Debug
Access-Control-Allow-Method
X-Fastcgi-Cache
X-LB-Cache
X-Page-Id
X-Cluster-Name
Accept-Charset
X-Rid
X-Geo-Country
TP-L2-Cache
X-Hostname
X-Erf-Stays-Pdp-Viaduct-Migration-Web
X-Goog-Storage-Class
X-Ratelimit-Limit
X-Goog-Generation
X-Goog-Stored-Content-Length
X-B3-Sampled
X-Goog-Stored-Content-Encoding
Count-Hit
X-Aspnet-Version
X-Seen-By
X-Ua-Device
Cross-Origin-Resource-Policy
X-Ezoic-Cdn
X-Correlation-Id
Cleartype
X-Edge-Location-Klb
TCN
X-Kinsta-Cache
X-Newrelic-App-Data
X-App-Server
X-Xrds-Location
Referer-Policy
X-Mobile
X-Logged-In
DC
X-Varnish-Backend
X-Content-Options
X-Id
X-Hosted-By
X-Git-Hash
X-TEC-API-VERSION
X-Origin-Cache
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Contextid
X-Flags
X-Fb-Rlafr
X-Request-Guid
X-Providence-Cookie
X-Is-Crawler
X-Debug-Info
X-Aspnet-Duration-Ms
X-Amz-Replication-Status
X-Route-Name
Surrogate-Key
X-Revision
X-Grace
Retry-After
X-TT
X-App-Environment
Frame-Options
X-Amz-Meta-S3cmd-Attrs
X-Varnish-Grace
X-Forwarded-Proto
X-Envoy-Decorator-Operation
X-IPS-LoggedIn
X-F-Cache
X-Azure-Ref
Section-Io-Cache
X-Wix-Request-Id
X-Magnolia-Registration
X-Whom
Healthy
MS-Author-Via
Charset
Alternate-Protocol
X-Proxy-Cache-Info
X-Akamai-Edgescape
X-App-Version
Viewport
X-Origin-Server
X-Www-Served-By
X-RateLimit-Reset
X-Nf-Request-Id
X-COUNTRY
X-Webkit-Csp
X-Language
X-Backend-Name
X-Az
X-Activity-Id
X-AppVersion
Amp-Access-Control-Allow-Source-Origin
Filterid
Paypal-Debug-Id
X-Varnish-Server
X-B
SRV
WPO-Cache-Message
WPO-Cache-Status
X-DataDome
Host
Server-Name
SD-X-WS
X-Datadog-Trace-Id
X-Cache-Rule
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
VIX-Pulpo-Upstream-Status
X-Original-Request-Id
X-Response-Served-From
VIX-Pulpo-Node
X-Http-Reason
X-Akamai-Request-ID2
X-Rule
X-Instance
Front
X-User-Agent
X-UUID
X-Edge-Location
Akamai-GRN
X-Cache-Grace
X-Unique-Id
X-Region
X-Status
X-Jobs
X-Environment-Context
Country
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-L-Path
From-Origin
X-Page-View
X-Cacheable-TTL
X-Time
X-Adobe-Content
Protected
Fastly-SWR
Fastly-SIE
X-Adobe-Loc
X-Is-Bot
X-Rocket-Nginx-Serving-Static
X-Varnish-Age
X-EdgeConnect-Cache-Status
X-Load-Cache
X-Framework
X-Rendered-As
X-N
X-Vcache
X-Type
X-ARC
ServerID
X-FW-Hash
X-FW-Dynamic
X-FW-Version
X-FW-Server
X-FW-Serve
X-FW-Static
X-FW-Type
X-Tumblr-Pixel-0
X-G
X-Tumblr-Pixel
X-Client-Ip
X-Yottaa-Metrics
X-Tumblr-Pixel-1
X-RemovedCookies
X-Yottaa-Optimizations
X-Tumblr-User
X-ProcessESI
Content-Disposition
X-Trace-Id
X-Proxy
X-Cache-Time
X-Datadog-Sampled
X-Mg-Request-UUID
Access-Control-Request-Headers
X-Signature
X-Debug-IsConnected
X-Debug-IsPreview
X-B-Cache
X-Amzn-Remapped-Content-Length
X-CDN-Forward
X-Cache-Age
X-Cache-Control
Backend
X-ECache
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
X-Tec-Api-Root
X-Tec-Api-Version
X-Tec-Api-Origin
Countrycode
Refresh
X-Drupal-Cache-Tags
X-Nginx-Cache
X-DynaTrace
X-Httpd
X-Servername
X-Erf-Web-Scheduler
Accept-Language
Xet-Cookie
X-Tt-Trace-Tag
X-Tt-Trace-Host
Url
X-DynaTrace-JS-Agent
X-Generated-By
CF-IPCountry
X-Source
X-HTML-Minification-Powered-By
X-Template
X-XRDS-Location
X-Device-Type
X-Mode
Xserver
X-NYM-Debug-Backend
X-Content-Powered-By
Version
X-Storage
X-Content-Age
GEO-INFO
Webserver
X-Urbn-Site-Id
X-LAGOON
X-Director
X-Cache-Action
X-SaId
X-Rn-Rsrv
X-Cache-Operation
OT-Force-Account-Verify
X-JoinUs
X-Say-Cacheable
X-GeoCountry
X-Say-TTL
Locale
Meta-Geo
X-UPSTREAM-Address
S-Rt
Load-Balancing
X-SayCDN-TTL
X-Rewrite-Enabled
X-ServerID
X-GeoCode
X-Urbn-Context-Path
Filters
X-Forwarded-Host
X-Git-Commit
X-Cluster-Node
Onion-Location
X-Tt-Logid
X-Soup
X-Varnish-Hostname
X-Container-Uri
Web-Mar-Node
X-Adobe-Source
X-Cache-Hit
X-Tncms
X-Detected-As
X-VCT
X-RM-Cache-TTL
X-Varnish-Cache-Hits
X-PHP-Host
X-VC-Cache
X-Sql-Duration-Ms
X-Served-From
X-Tb
X-Loop
X-Cache-Server
X-Ms-Version
X-Ms-Request-Id
X-Sql-Count
X-Labrador-Cache-Channel
X-Lambda-Id
Azure-RegionName
Azure-SiteName
Azure-SlotName
Azure-InstanceId
X-Proto
X-XRDS-LOCATION
X-CCDN-CacheTTL
Azure-Version
DB-Nickname
Mn-Server-Ip
Node
X-URL
X-Oracle-Dms-Rid
X-Skip-Cache
X-Zipkin-Id
X-Proxied
X-RCS-CacheZone
X-R9-Blue-Green-Version
X-Generation-Time
X-FB-TRIP-ID
X-Extlb
Cross-Origin-Window-Policy
X-Routing-Service
X-Hcs-Proxy-Type
X-Logging-Id
X-Oracle-Dms-Ecid
X-CCDN-Origin-Time
X-Timing-Wait
Selected-Fe
X-Fetched-On
X-Format
X-Tumblr-Pixel-3
Fastcgi-Useragent
X-Debug
X-Tumblr-Pixel-2
X-MCACHE
X-Proxy-Build
X-Uri
TWC-Privacy
TWC-Locale-Group
Uber-Trace-Id
Webcakes-Region
Webcakes-App-Version
X-Origin-Hint
TWC-GeoIP-LatLong
Webcakes-App-Name
TWC-GeoIP-Country
TWC-Connection-Speed
TWC-Device-Class
Property-Id
X-Zen-Fury
X-LSADC-Cache
Source
X-Redis-Cache
X-B3-SpanId
X-Endurance-Cache-Level
CDN-RequestId
X-Ratelimit-Reset
X-Sucuri-ID
X-Sucuri-Cache
X-NGENIX-Cache
X-Ua
X-Srv
Section-Io-Id
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
Section-Origin-Responded
X-Drupal-Cache-Contexts
X-S
X-Upgrade-Enabled
X-Pass-Why
X-Origin-Date
X-MP-GENERATED-AT
Fastly-Drupal-HTML
X-Varnish-Hits
X-FTR-Request-ID
X-Origin-CC
X-TimeS
X-Origin-TTL
X-Cache-Expired-At
Liferay-Portal
X-Newrelic-Synthetics
Upgrade-Insecure-Requests
NGB
X-Real-IP
X-Akamai-Transformed
X-Handled-By
X-CACHE-AGE
X-GEO
X-UA-Device-Type
X-Xfnlog-Site
X-Optimistic-Header
X-Cache-TTL-Remaining
X-Cms-Context
Apigw-Requestid
X-Reqid
X-Hl-Ver
X-Restarts
X-Node-Name
X-Via-JSL
X-Cache-Type
ServedBy
Ms-Operation-Id
X-Cache-Host
X-ProxyCache-Status
X-BYPASS-REASON
X-CSRF-Token
X-ProxyCache-Key
X-No-Session
X-RTag
MS-CV
CDN-Uid
X-Pubstack
CDN-CachedAt
CDN-Cache
CDN-PullZone
CDN-EdgeStorageId
CDN-RequestPullSuccess
CDN-RequestCountryCode
CDN-RequestPullCode
X-Tx-Id
X-ID
X-Varnish-Ttl
X-AWS-Id
X-Cluster
X-Server-W
X-IPLB-Instance
X-Parent-Response-Time
X-LJ-Flow-ID
X-IPLB-Request-ID
WP-Super-Cache
X-VWS-Id
Odigeo-Trace-Id
Ngx.Var.Host
DCR-Decision-By
DCR-Processing-Time-Ms
Fastly-SSL
Gannett-Cam-Experience-Id
Origin-Agent-Cluster
Candidate-Md5Url
BehaviorPad-Version
Canary
Ha-Gx-Prefs
HA-Ipaddr
MD5-Digest
Meta-Geo-Continent
Magicmarker
Lang
L
L5d-Success-Class
N-Cache
X-Aed
X-Epic-Correlation-Id
X-Ec-GeoHdr
X-Eu-Site
X-External-Request-Id
X-FC-Vary-Parameters
X-Fastly-Backend
X-Ec-Fail
X-Ec-Custom-Error
X-Debug-Cache-Store
X-Debug-Cache-Fetch
X-Destination
X-Developer
X-Dispatcher-Number
X-Request-Host
X-Rojux
X-Viewer-Country
X-Vdms-Version
X-Vtex-Remote-Cache
X-We-Are-Hiring
Xc-Version
X-Worker
X-Vdms-Path
X-SRCache-Key
X-ScT
X-S-Cookie
X-SD-PageType
X-Slack-Backend
X-Slack-Shared-Secret-Outcome
X-D
X-Csrf-Jwt
Web-Mar-Region
W
X-A
X-A-Ccd
X-A-Dcw
X-A-Dam
Vix-Hermes-Req-Id
True-Client-Country-4JS
Server-Host
Rendered-Blocks
Sslversion
Surrogated-Key
T-Server
X-A-Dgt
X-A-Wwc
X-CF-Lambda-Fn
X-CacheTTL
X-CF-Lambda-Version
X-CGP
X-Conf
X-Cache-NE
X-Bl-Debug
X-App-Name
X-App
X-Application
X-B-Cookie
X-Bc-Bl
Redirect-Candidate
X-BCube-Filmed-By
X-AB
X-Proxy-Cache-Status
Req-Svc-Chain
Release
Producers
X-Node-Id
Platform
X-Nitro-Cache
X-Nananana
X-Level-Front-Cache
X-Irp-Debug
TDXMobile
X-Loc
X-Mid
X-Mvc-Supplant-Cachable
X-Mly-Id
X-NodeID
X-Old-Content-Length
X-Pool
X-Policy
X-Qloud-Router
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
Is-Eu
X-Platform
Mail-Subject
Origin
Thinkindot-CacheControl
X-Org
X-Orig-Expires
X-PAYTM-SRV-ID
X-Owner
X-Nyt-Route
Thinkindot-CacheControl-Type
X-Core-Mission
X-CMSURLCustom
X-Core-Value
X-Date
X-DefHash
X-DefElseHash
X-Clientip
X-BBC-Edge-Cache-Status
X-Cache-Debug
X-Cache-Info
X-Cache-Bucket
X-Cdn-Diag
X-Cdn-Origin
X-Bip
X-Alternate-Cache-Key
X-DPWN-IS-SECURE
X-GeoIP-Country-Code
VNS-Age
X-GeoIP-Region-Code
X-Hash
Thinkindot-Control
X-Human
VNS-Cache
We-Hiring
X-Accel-Buffering
X-Accel-Expires-Debug
X-Forwarded-Path
X-Gdpr
X-Geo-Header
X-Generated-On
X-Refresh
X-Origin-Time
X-Tenant
Adler-Geo
X-Test
X-Thanos
X-Up
X-Thinkindot-L3
AKAMAI
X-Request-Time
Cache-Provider
X-Sn-Servicetimems
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-SVT-ORM-RULES
X-Storefront-Renderer-Rendered
X-Var-Ttl
X-Variation
X-Wikidot-Backend
X-VServer
X-Wikidot-Static-Cache
X-Wix-Viewer-Type
Host-ID
Content-Secure-Policy
X-Vmg-Version
X-VG-WebCache
X-Varnish-CookieINHashed-On
X-Varnish-CookieHashed-On
X-Varnish-Remaining-TTL
X-Cache-Status-Check
X-VG-TLSProxy
X-Varnishpool
X-Shopify-Stage
X-SVT-ORM-VERSION
X-ShardId
CPC-Cache
CPC-Age
X-Micro-Cache
Fastly-GeoIP-CountryCode
X-ShopId
Expect-Staple
Datacenter
Fastly-Backend-Name
Cmstype
X-Shop-Environment
Cmsid
Cf-Device-Type
X-S-Maxage
Environment
X-Server-IP
User-Cache-Control
X-TIME
X-Esi-Check
X-Cache-Id
X-Akamai-Device-Characteristics
X-Dispatcher-Server
Esi-Enabled
X-Device-Os
X-WA-Info
X-Cdn-Srv
X-Block-Status
Cache-Name
Gh-Request-Id
X-Geo-Region
X-Correlation-ID
X-Fmm-Version
X-WADP-Cache
X-Clara-WADP
Machine
X-Gen-Mode
Country-Code
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
X-Origin-Response-Time
CloudFront-Viewer-Country
Sever-Int
Server-Ext
X-Nginx-Cache-Key
Server-Hostname
X-Mvc-Supplant-OutputCached
X-Hnp-Log
Apple-News-Services-Host
CDCHOST
NM-Fastcgi-Cache
X-Origin
X-From
X-Forwarded-Site
Apple-News-Services-Handled
DSUID
X-Gzip
X-GeoIP
X-TraceId
X-Instance-Name
X-NCache
X-PERF
X-Section
X-INCAP-ABP
X-Op-Id-All
X-LB-NoCache
Wxu-Next-Hostname
Wxu-Next-Commit
Wxu-Next-Region
X-Access
X-ApacheServer
X-AIR-PT
Ssr
X-Cache-Enabled
C-Via
Pics-Label
Server-Info
X-Datadome
NGX
X-Auto-Login
X-B3-Spanid
X-Fastly-Request-Id
X-Via-Fastly
X-Amz-Meta-Cb-Modifiedtime
Server-ID
X-Vcl-Version
AMP-Access-Control-Allow-Source-Origin
X-Accel-Version
X-API-Version
X-Has-Esi
X-HA-Backend
X-Dc
X-CACHE-GROUP
X-JWT-State
X-Varnish-Beresp-Ttl
X-Varnish-Beresp-Grace
Memcached
X-Is-Gdpr
X-Vgn-Hpd-Reason
X-Is-Supported-Browser
X-Is-Desktop
X-Is-Mobile
X-Browser-Name
X-Buckets
X-Is-Tablet
X-Tcp-Rtt
Hostname
Memory
X-SIPLIST1
Time
IsBot
Origin-CC
Origin-EX
X-Platform-Cluster
X-Platform-Router
Cache-Hits
X-Platform-Processor
X-Scale
Sid
CF-Ctrl
X-Zone
Location
X-PHP-Backend
X-B3-Parentspanid
Cdn-Requestid
X-Air-Trace-Id
X-Air-Source
X-Tb-Optimization-Total-Bytes-Saved
X-Air-Hostname
YJS-ID
X-ZONE
X-Wp-Cf-Super-Cache-Active
X-TIM-N
X-Presslabs-Stats
X-WP-CF-Super-Cache-Active
X-Cached-By
X-Fpc
X-DC
X-Backend-Instance
X-Internal-Host
X-Frame-Option
X-Origin-Cache-Key
Resin-Trace
X-Hyper-Cache
X-Azure-Ref-OriginShield
X-Cs
X-TA-CDN-Provider
Uri
GeoIP-Latitude
X-VC
X-DataCenter
Epwk-X-Cache
X-Site-Version
Cache-Host
X-Origin-Expires
X-Webstats-RespID
X-Service
X-Microcachable
True-Client-Ip
X-LiteSpeed-Cache-Control
LB
X-NGINX-Cache
X-Info
X-FTR-Balancer
X-FTR-Backend-Server
XM
X-Nitro-Cache-From
X-FTR-Expires
GeoIP-Country-Code
X-FTR-Backend
X-Country-Code-Real
X-Nitro-Rev
X-FTR-Cache-Status
X-Web-Node
GeoIp-Country-Code
PFcat
X-VarnishDD-TTL
X-Locale
X-HN
Cdn
X-Pod-Name
X-VCache
User-Agent
X-CS
Cdn-Host
Cdn-Request-Time
X-Edge-Server
X-Cache-Ttl
XServer
NtCoent-Length
X-Ad-Defer-Variation
WebServer
X-CSRF-TOKEN
X-NewRelic-App-Data
A
True-Client-IP
Edge-Copy-Time
X-Via-Edge
Req-ID
Srvid
X-NMSegId
X-FL-QIT-DEBUG
X-FL-EDGE
X-Via-SSL
M-TraceId
WZWS-RAY
Locid
X-Via-CDN
X-Datacenter
X-Geo
X-Ad-Load-Variation
X-Vercel-Id
X-Vercel-Cache
X-TRACE-ID
X-SRV
SID
X-MSEdge-Flight
X-MSEdge-Features
X-Pad
X-Varnish-Authentication
X-Cache-ASPX
X-M-Reqid
X-FireWall-Port
X-Moov-Xdn-Version
Fastly-Drupal-Html
X-M-Log
Pramga
X-Request-Start
X-Contensis-Viewer-Groups
X-ATG-Version
X-Scope-Id
X-FPC
X-Moov-T
Tcn
X-Request-URI
X-HostName
X-Shield-Cache-Expires
X-NWS-UUID-VERIFY
X-Varnish-Beresp-Status
X-Qnm-Cache
Cluster
Cache-Key
X-LiteSpeed-Tag
X-Cdn-Request-ID
Cf-Ipcountry
HostName
X-Api-Version
X-APP-VERSION
CountryCode
X-Cache-Date
Cdncip
X-Air-Pt
Path
Content-Script-Type
Content-Style-Type
X-Amz-Meta-Opti
Edge-Cache
X-AK-Request-ID
X-Esi
Cdnsip
Cache-Tv-Group
X-TH-Server
X-Branch-Name
Wpo-Cache-Message
Wpo-Cache-Status
X-VCL-Version
X-Wp-Cf-Super-Cache-Cookies-Bypass
Click-Count-Action-Start
Click-Count-Error
Tube-Get-Contents
Tube-Got-Results
X-Aicache-OS
X-Acquia-Purge-Cdn-Unconfigured
Tube-Return
Tube-Got-Eval
X-Planisys-CDN-Rules
X-WP-CF-Super-Cache-Cookies-Bypass
State
X-HS-Content-Campaign-Id
X-Github-Request-Id
XkeyRZ
X-Proxy-CacheRZ
X-Planisys-CDN-TTL
X-B3-Trace-ID
X-Planisys-CDN-Cache
X-Platform-Server
Yak-Timeinfo
X-SB
X-Req
X-Servedbyhost
X-Via-Popn
X-V-Cache
X-Via-Popv
X-Wa
X-LB-ID
X-Via-Poph
X-Nc
X-Cache-FS-Status
X-Rebelmouse-Surrogate-Control
CDN
X-Upstream-Ct
X-Rebelmouse-Cache-Control
X-CACHE-KEY
X-UA
X-Upstream-Ht
X-Wp-Cf-Super-Cache-Cache-Control
X-Vary
Geoip-Latitude
On-Server
X-Vgn-Hpd-Cached
X-Vgn-Hpd-Variations-Key
X-Vgn-Hpd-Ssi
X-Men
X-Wp-Cf-Super-Cache
X-Akamai-Pragma-Client-IP
X-Release
X-Fastly-Cache
Srv
X-Cdn-Forward
X-Tim-N
X-Render-Time
V-Age
MIME-Version
Proxy-Connection
X-Lb-Cache
Ngx-Var-Key
X-User
X-Cache-Remote
Ohc-File-Size
X-Generated-In
X-Traceid
Server-Id
X-Rocket-Build-Number
X-Ha-Backend
Lb
CF-Cached-On
X-Sigma
X-Sigma-Backend
X-Dw-Trace-Id
X-HS-Status
X-TT-LOGID
X-Acquia-Application-Trace
Cache
X-Fastly-Backend-Reqs
X-Via-Ucdn
X-Acquia-Application-UUID
Warning
PICS-Label
My-App
X-Lb-Nocache
X-EC-Lua
X-Acquia-Site
X-Acquia-Purge-Tags
X-CUA
Ohc-Cache-HIT
Yjs-Id
X-Iplb-Request-Id
X-Iplb-Instance
X-Fastly-Cache-Hits
Inserted-Into-Cache-At
X-Snapshot-Date
CACHE-MISS-TO-ORIGIN
X-Litespeed-Cache-Control
X-RAMCache
X-CF-Cache-Header-Cache-Control
X-Miniprofiler-Ids
Cneonction
X-GeoIP-City
X-GoCache-CacheStatus
X-CF-Cache-Header-Vary
X-Udemy-Cache-App-Namespace
X-Cached-Since
Vha6-Origin
X-ElasticPress-Query
X-Gamma-Serve
Log-Origin
Ngx
X-Scheme