Threat Level: green Handler on Duty: Rob VandenBrink

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
X-Powered-By
Pragma
X-XSS-Protection
CF-RAY
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
Alt-Svc
P3P
X-Cache-Hits
X-UA-Compatible
X-Xss-Protection
X-Served-By
CF-Ray
X-Download-Options
X-Timer
X-Request-Id
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
Access-Control-Allow-Credentials
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
X-Drupal-Cache
X-Generator
X-Cache-Status
X-Check
X-Cacheable
X-DNS-Prefetch-Control
X-FRAME-OPTIONS
X-Envoy-Upstream-Service-Time
Timing-Allow-Origin
X-Iinfo
X-Request-ID
X-Drupal-Dynamic-Cache
Feature-Policy
X-Dns-Prefetch-Control
X-Content-Security-Policy
Content-Encoding
X-XSS-PROTECTION
Access-Control-Expose-Headers
Upgrade
Status
X-CDN
Server-Timing
X-AspNetMvc-Version
Access-Control-Max-Age
X-Amz-Request-Id
Request-Context
X-Amz-Id-2
X-Turbo-Charged-By
X-Via
X-AH-Environment
X-Backend
X-Cache-Group
X-Robots-Tag
Cf-Edge-Cache
Host-Header
Keep-Alive
X-Hacker
X-Proxy-Cache
X-UA-Device
X-Server
X-Rq
X-Vhost
X-Server-Powered-By
Allow
X-Age
X-Varnish-Cache
X-Ws-Request-Id
X-Dispatcher
X-Amz-Version-Id
EagleId
P3p
Nel
Grace
X-LiteSpeed-Cache
Cf-Apo-Via
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Page-Speed
X-Device
Cf-Railgun
EagleEye-TraceId
X-Aws-Lambda-Call-Status
X-Swift-CacheTime
X-Swift-SaveTime
X-Pingback
Ali-Swift-Global-Savetime
X-Host
X-Node
X-OneAgent-JS-Injection
Accept-CH
X-WebKit-CSP
X-CST
X-Backend-Server
Surrogate-Control
X-Server-Id
X-Cache-Lookup
X-Nginx-Cache-Status
X-Readtime
Permissions-Policy
X-Akam-SW-Version
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
Request-Id
X-Nginx-Upstream-Cache-Status
X-Application-Context
X-Content-Security-Policy-Report-Only
Accept-CH-Lifetime
X-Cloud-Trace-Context
X-Ua-Compatible
X-Trace
X-Response-Time
X-Edge
X-HW
Content-Location
X-Clacks-Overhead
X-Mod-Pagespeed
Xkey
X-Midtier
Rating
X-ESI
X-Amz-Server-Side-Encryption
X-Url
X-Ruxit-JS-Agent
X-ECACHE
Accept-Ch-Lifetime
X-Mcache
X-Oneagent-Js-Injection
X-Upstream
X-Ruxit-Js-Agent
X-Litespeed-Cache
X-Vcap-Request-Id
Accept-Ch
X-Country
X-D2id
Cache-Tag
X-MS-InvokeApp
X-Kinja-Build
X-Kinja-Revision
X-Exp-Id
X-GoogleNews-Bot
X-Exp-Variant
X-Use-Magma
X-Kinja
X-Element-Page-Cache
X-Kinja-Server
Verso
X-Cdn-Fetch
X-Vname
X-TtlSet
X-PC
X-Rack-Cache
Edge-Control
X-Powered-By-Plesk
RTSS
X-Cache-TTL
Fastly-Restarts
X-VARITI-CCR
X-Ac
Origin-Trial
X-WebKit-CSP-Report-Only
X-Navigation-Version
X-Abt-Application-Version
X-Country-Code
X-Goog-Hash
Service-Worker-Allowed
X-Cached
X-Ttl
Display
Pagespeed
X-Middleton-Display
X-Sol
X-GitHub-Request-Id
X-Browser-Type
X-Amz-Rid
X-Content-Type
X-Varnish-TTL
Cross-Origin-Opener-Policy
X-SharePointHealthScore
SPRequestGuid
X-Dw-Request-Base-Id
X-Mg-S
X-Server-Name
X-Amzn-Trace-Id
X-Powered-CMS
X-Middleton-Response
Response
X-Erf-Bev-Bev-Is-Generated
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
Arr-Disable-Session-Affinity
X-Instrumentation
X-Erf-Bev-Bev
AR-SID
AR-PoweredBy
AR-Request-ID
AR-ATIME
SPIisLatency
SPRequestDuration
X-Cache-Key
X-B3-TraceId
X-Webkit-CSP
X-NF-Request-ID
X-Kinja-CCPA
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
AR-CACHE
X-Version
X-Times
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-HP-Trace-Id
X-HP-Webp
X-Jurisdiction
X-Accel-Expires
X-B3-Traceid
X-T
Pinterest-Generated-By
Cache-Tags
Pinterest-Version
X-Pinterest-Rid
X-NWS-LOG-UUID
Cache-Status
Front-End-Https
X-Fastly-Request-ID
X-Cnection
X-Aspnetmvc-Version
Edge-Cache-Tag
Nginx-Cache
X-MSEdge-Ref
X-Hits
X-Px
X-Client-IP
X-Ser
X-RateLimit-Remaining
MRF-Tech
Mrf-Cache-Status
X-B3-TraceId-Primal
Public-Key-Pins
X-FastCGI-Cache
Payment
X-Fastcgi-Cache
X-Recruiting
X-LLID
X-Frontend
X-Request-Processing-Time
X-Request-Received
Server-Node
X-Ua-Browser
X-Server-ID
X-Erf-Stays-Pdp-Viaduct-Migration-Web
X-DIS-Request-ID
X-Shield-Request-Id
X-RateLimit-Limit
TP-Cache
S
X-GUploader-UploadID
X-Goog-Metageneration
Access-Control-Request-Method
MicrosoftSharePointTeamServices
X-HS-Content-Id
X-HS-Combine-CSS
X-HS-Cache-Config
X-HS-Hub-Id
X-Amz-Apigw-Id
X-Amzn-RequestId
X-LB-Cache
TP-L2-Cache
X-Request-Handler-Origin-Region
X-Protected-By
X-Microsite
X-Content-Digest
Content-MD5
X-FB-Debug
X-Page-Id
X-Ezoic-Cdn
Access-Control-Allow-Method
X-Distributor
Accept-Charset
Realpath
Fastcgi-Cache
X-Cluster-Name
X-Forwarded-For
X-Geo-Country
X-PressLabs-Stats
X-Rid
X-Hostname
X-Webkit-Csp
X-B3-Sampled
X-Aspnet-Version
X-Seen-By
X-Ua-Device
X-Ratelimit-Remaining
X-Correlation-Id
Cleartype
X-Envoy-Decorator-Operation
Referer-Policy
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Goog-Storage-Class
X-Mobile
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-Newrelic-App-Data
DC
Cross-Origin-Resource-Policy
TCN
X-Ratelimit-Limit
X-Content-Options
X-Debug-Info
X-TTL
X-Origin-Cache
X-Varnish-Backend
X-Logged-In
Count-Hit
X-Varnish-Grace
X-Contextid
X-XRDS-Location
X-Daa-Tunnel
X-Flags
X-App-Environment
X-IPS-LoggedIn
X-Grace
Surrogate-Key
X-Git-Hash
X-Amz-Replication-Status
X-Is-Crawler
X-Route-Name
X-Aspnet-Duration-Ms
X-Fb-Rlafr
X-Azure-Ref
X-Providence-Cookie
X-Request-Guid
X-Origin-Server
X-App-Server
X-Revision
X-Webkit-CSP-Report-Only
X-Hosted-By
X-Client-Ip
X-TT
X-Amz-Meta-S3cmd-Attrs
Frame-Options
X-Forwarded-Proto
X-Wix-Request-Id
X-Kinsta-Cache
Alternate-Protocol
X-Edge-Location-Klb
X-Whom
WPO-Cache-Status
WPO-Cache-Message
Healthy
Retry-After
Charset
X-Akamai-Edgescape
Viewport
X-F-Cache
X-Backend-Name
X-RateLimit-Reset
X-Magnolia-Registration
Section-Io-Cache
MS-Author-Via
X-COUNTRY
X-B
Paypal-Debug-Id
SRV
X-Proxy-Cache-Info
X-App-Version
X-Az
X-AppVersion
X-Activity-Id
Amp-Access-Control-Allow-Source-Origin
X-EdgeConnect-Cache-Status
ServerID
Host
X-N
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
SD-X-WS
Akamai-GRN
X-Cache-Rule
X-Language
X-Instance
X-Http-Reason
X-Original-Request-Id
Filterid
X-Response-Served-From
X-ARC
X-Id
X-Varnish-Age
X-UUID
X-Cache-Grace
X-User-Agent
X-Akamai-Request-ID2
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Status
X-Rule
Protected
X-Edge-Location
X-Rocket-Nginx-Serving-Static
Front
X-Page-View
X-Jobs
From-Origin
X-L-Path
X-FW-Version
X-Rendered-As
Fastly-SIE
X-Region
Fastly-SWR
X-Unique-Id
X-FW-Dynamic
X-FW-Hash
X-FW-Serve
X-Framework
X-Environment-Context
Server-Name
X-Is-Bot
X-Cacheable-TTL
X-FW-Server
X-Cache-Control
X-FW-Static
X-FW-Type
X-Adobe-Content
X-Cache-Time
X-Type
Access-Control-Request-Headers
Country
X-Adobe-Loc
X-Www-Served-By
X-Varnish-Server
X-Tumblr-User
X-G
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-RemovedCookies
X-ProcessESI
X-Trace-Id
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
X-Datadog-Trace-Id
X-Cache-Age
X-Load-Cache
X-Proxy
X-Time
X-DataDome
Refresh
X-Vcache
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-ECache
X-Source
X-Datadog-Sampled
X-CDN-Forward
X-Mg-Request-UUID
X-Oracle-Dms-Ecid
X-Amzn-Remapped-Content-Length
X-Debug-IsConnected
X-Debug-IsPreview
X-Drupal-Cache-Tags
X-Oracle-Dms-Rid
Version
Accept-Language
X-Erf-Web-Scheduler
Xet-Cookie
X-Signature
X-B-Cache
Content-Disposition
X-HTML-Minification-Powered-By
Countrycode
X-ID
Backend
X-Generated-By
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
CF-IPCountry
X-Xrds-Location
X-DynaTrace
X-DynaTrace-JS-Agent
Webserver
X-Upgrade-Enabled
X-Httpd
X-Servername
X-Mode
X-Nginx-Cache
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Varnish-Ttl
Url
Xserver
X-Nf-Request-Id
X-Content-Age
GEO-INFO
X-GeoCountry
X-Git-Commit
X-GeoCode
X-Cache-Operation
X-JoinUs
X-Director
X-LAGOON
X-Proto
X-Say-TTL
X-SayCDN-TTL
X-Varnish-Cache-Hits
X-Say-Cacheable
X-Rewrite-Enabled
X-SaId
X-Urbn-Context-Path
X-Storage
Load-Balancing
Filters
Locale
Meta-Geo
S-Rt
Onion-Location
X-Cache-Action
Azure-Version
Azure-InstanceId
X-Container-Uri
Azure-RegionName
Azure-SiteName
Azure-SlotName
X-Device-Type
X-Template
X-Tb
X-XRDS-LOCATION
X-ServerID
X-UPSTREAM-Address
X-URL
X-Urbn-Site-Id
X-NYM-Debug-Backend
X-Varnish-Hostname
X-Tt-Logid
X-Cluster-Node
X-Soup
X-Forwarded-Host
X-Content-Powered-By
X-Labrador-Cache-Channel
X-VC-Cache
X-RM-Cache-TTL
X-PHP-Host
X-MCACHE
Fastcgi-Useragent
Uber-Trace-Id
X-Served-From
X-Sucuri-Cache
X-Sql-Duration-Ms
X-Sql-Count
X-Sucuri-ID
X-Cache-Server
X-Adobe-Source
Web-Mar-Node
X-Detected-As
X-Generation-Time
X-VCT
OT-Force-Account-Verify
X-Ms-Request-Id
X-Ms-Version
Mn-Server-Ip
Webcakes-App-Version
Webcakes-App-Name
X-Origin-Hint
X-Zipkin-Id
X-Lambda-Id
TWC-Privacy
Node
X-LSADC-Cache
TWC-GeoIP-LatLong
TWC-GeoIP-Country
TWC-Connection-Speed
TWC-Locale-Group
DB-Nickname
Property-Id
X-Logging-Id
TWC-Device-Class
Webcakes-Region
X-Extlb
X-FB-TRIP-ID
X-Skip-Cache
X-Zen-Fury
X-Debug
X-Tec-Api-Origin
X-Tec-Api-Root
X-Proxied
X-R9-Blue-Green-Version
X-RCS-CacheZone
X-Drupal-Cache-Contexts
X-Routing-Service
X-Tec-Api-Version
X-Fetched-On
X-Tumblr-Pixel-2
X-Tumblr-Pixel-3
X-Proxy-Build
X-Timing-Wait
X-Uri
X-Format
Selected-Fe
Liferay-Portal
CDN-RequestId
X-Loop
X-Tncms
X-B3-SpanId
Source
X-Endurance-Cache-Level
X-Rn-Rsrv
X-Fastly-Request-Id
X-Cache-Hit
X-Origin-Date
X-Hcs-Proxy-Type
X-MP-GENERATED-AT
X-CCDN-CacheTTL
X-CCDN-Origin-Time
X-Srv
X-Redis-Cache
Fastly-Drupal-HTML
Cross-Origin-Window-Policy
X-Varnish-Hits
X-TimeS
X-Ua
X-Ratelimit-Reset
X-Pass-Why
Section-Origin-Responded
X-Cache-Expired-At
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
Section-Io-Id
Content-Secure-Policy
Upgrade-Insecure-Requests
X-UA-Device-Type
X-Real-IP
X-Cache-TTL-Remaining
X-S
X-Node-Name
X-Origin-TTL
X-CACHE-AGE
X-Akamai-Transformed
X-Origin-CC
X-Pubstack
X-Newrelic-Synthetics
X-Server-W
X-GEO
X-Via-JSL
X-Hl-Ver
CDN-RequestCountryCode
CDN-RequestPullSuccess
CDN-Uid
CDN-Cache
CDN-RequestPullCode
CDN-PullZone
CDN-CachedAt
CDN-EdgeStorageId
MS-CV
X-Presslabs-Stats
X-RTag
X-CSRF-Token
Ms-Operation-Id
X-AIR-PT
X-Parent-Response-Time
X-Cache-Host
Cache-Provider
X-Handled-By
X-Tx-Id
X-Request-Host
X-BCube-Filmed-By
X-Conf
Candidate-Md5Url
X-Slack-Shared-Secret-Outcome
X-Csrf-Jwt
X-Var-Ttl
X-Slack-Backend
Canary
X-CF-Lambda-Fn
X-SRCache-Key
X-CacheTTL
X-Cache-NE
X-Restarts
X-Bc-Bl
X-Cache-Type
Apigw-Requestid
X-Cdn-Diag
X-Cms-Context
X-Rojux
X-CGP
X-CF-Lambda-Version
BehaviorPad-Version
X-Tenant
X-Bl-Debug
Gannett-Cam-Experience-Id
NGB
N-Cache
We-Hiring
Ngx.Var.Host
W
Meta-Geo-Continent
Web-Mar-Region
X-A
Magicmarker
Mail-Subject
MD5-Digest
X-SD-PageType
Odigeo-Trace-Id
T-Server
Server-Host
Surrogated-Key
Sslversion
Rendered-Blocks
Redirect-Candidate
VNS-Cache
VNS-Age
Vix-Hermes-Req-Id
True-Client-Country-4JS
X-A-Ccd
Lang
X-Aed
X-App
X-Accel-Expires-Debug
Fastly-Backend-Name
Fastly-GeoIP-CountryCode
DCR-Processing-Time-Ms
DCR-Decision-By
X-S-Cookie
CPC-Age
CPC-Cache
X-Application
Fastly-SSL
X-Shop-Environment
X-A-Dcw
X-A-Dam
L
L5d-Success-Class
X-A-Dgt
X-A-Wwc
X-Accel-Buffering
Gh-Request-Id
Ha-Gx-Prefs
HA-Ipaddr
X-B-Cookie
X-Ec-Fail
X-We-Are-Hiring
X-Gdpr
X-D
X-Datadome
X-Wix-Viewer-Type
X-Wikidot-Static-Cache
X-Forwarded-Path
X-RateLimit-Limit-Second
X-Fastly-Backend
X-External-Request-Id
X-Vtex-Remote-Cache
X-RateLimit-Remaining-Second
X-FC-Vary-Parameters
X-Worker
X-Xfnlog-Site
Cache-Hits
X-Nyt-Route
Cache-Name
X-Optimistic-Header
X-Orig-Expires
X-Origin-Time
X-JWT-State
X-Has-Esi
Xc-Version
X-IPLB-Instance
X-IPLB-Request-ID
X-Is-Gdpr
X-Eu-Site
X-Wikidot-Backend
X-Ec-GeoHdr
X-Destination
X-ScT
X-Developer
X-Debug-Cache-Fetch
X-Dispatcher-Number
X-Ec-Custom-Error
X-Epic-Correlation-Id
X-Vdms-Version
X-Reqid
X-Viewer-Country
X-Debug-Cache-Store
X-Vdms-Path
X-Date
X-TIME
ServedBy
WP-Super-Cache
X-PAYTM-SRV-ID
X-Loc
X-Level-Front-Cache
X-Irp-Debug
X-Owner
X-Platform
X-PERF
X-Mid
X-Mly-Id
X-Nitro-Cache
Thinkindot-CacheControl
X-Old-Content-Length
X-Core-Mission
TDXMobile
X-Org
X-Core-Value
Thinkindot-CacheControl-Type
Thinkindot-Control
X-NGENIX-Cache
X-Mvc-Supplant-OutputCached
X-CMSURLCustom
X-No-Session
X-S-Maxage
X-Node-Id
X-Mvc-Supplant-Cachable
X-Policy
X-BBC-Edge-Cache-Status
X-ProxyCache-Status
X-Auto-Login
X-ProxyCache-Key
X-Generated-On
X-Request-Time
X-Qloud-Router
X-Bip
X-Cache-Bucket
X-Cache-Debug
X-Cache-Info
X-Esi-Check
X-Refresh
X-BYPASS-REASON
X-Geo-Header
X-DPWN-IS-SECURE
X-Cache-Id
X-GeoIP-Region-Code
X-Gzip
X-DefElseHash
X-Human
X-Hash
X-Clientip
X-DefHash
X-Cdn-Origin
X-App-Name
X-ApacheServer
X-Alternate-Cache-Key
X-GeoIP-Country-Code
X-Pool
X-INCAP-ABP
Host-ID
Adler-Geo
AKAMAI
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-SVT-ORM-RULES
X-Storefront-Renderer-Rendered
X-Sn-Servicetimems
Cf-Device-Type
X-ShopId
Environment
X-Shopify-Stage
Datacenter
Cmsid
Cmstype
X-SVT-ORM-VERSION
X-Test
X-VG-WebCache
X-VG-TLSProxy
X-Vmg-Version
X-VServer
X-PHP-Backend
Origin-Agent-Cluster
X-Varnish-Remaining-TTL
X-Varnish-CookieINHashed-On
X-Thinkindot-L3
X-Thanos
X-Up
X-Variation
X-Varnish-CookieHashed-On
Expect-Staple
X-Varnishpool
Memcached
Hostname
Is-Eu
Machine
X-ShardId
X-Origin-Response-Time
Origin
Req-Svc-Chain
Release
Producers
Platform
X-Server-IP
User-Cache-Control
X-Device-Os
X-Dispatcher-Server
X-Scale
X-Fmm-Version
Server-Hostname
Server-Ext
X-Cluster
X-Akamai-Device-Characteristics
Esi-Enabled
Sever-Int
X-Forwarded-Site
X-From
X-LJ-Flow-ID
X-Nananana
X-Nginx-Cache-Key
X-Origin
X-NodeID
X-Hnp-Log
X-WA-Info
X-Gen-Mode
X-WADP-Cache
X-GeoIP
X-Clara-WADP
X-VWS-Id
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
Apple-News-Services-Handled
DSUID
Apple-News-Services-Request-Url
CDCHOST
X-AWS-Id
CloudFront-Viewer-Country
Country-Code
NM-Fastcgi-Cache
X-Block-Status
X-Cdn-Srv
X-Access
X-Instance-Name
Origin-EX
Wxu-Next-Hostname
Ssr
Wxu-Next-Commit
C-Via
X-Proxy-Cache-Status
Wxu-Next-Region
X-Cache-Enabled
Server-Info
X-Op-Id-All
X-NCache
Pics-Label
X-Section
X-Vcl-Version
X-LB-NoCache
Origin-CC
X-TIM-N
AMP-Access-Control-Allow-Source-Origin
X-Cache-Status-Check
X-API-Version
X-Amz-Meta-Cb-Modifiedtime
X-Via-Fastly
Time
X-CACHE-GROUP
Server-ID
Memory
X-B3-Spanid
NGX
X-Correlation-ID
X-HA-Backend
X-Micro-Cache
X-Tb-Optimization-Total-Bytes-Saved
X-Dc
X-Cs
X-Wp-Cf-Super-Cache-Active
X-Air-Trace-Id
X-Internal-Host
X-Air-Source
X-Air-Hostname
X-Azure-Ref-OriginShield
X-Platform-Processor
X-Vgn-Hpd-Reason
X-AB
X-Platform-Cluster
X-Platform-Router
X-ZONE
X-Webkit-Csp-Report-Only
GeoIP-Latitude
X-Varnish-Beresp-Ttl
X-Web-Node
X-Varnish-Beresp-Grace
X-FTR-Request-ID
X-Origin-Expires
X-Microcachable
Cache-Host
X-Geo-Region
Location
X-Zone
X-Buckets
X-Fpc
X-Github-Request-Id
XM
Cdn-Requestid
X-DC
IsBot
X-B3-Parentspanid
X-SIPLIST1
X-Backend-Instance
X-VarnishDD-TTL
X-Accel-Version
PFcat
X-HN
X-Pod-Name
X-DataCenter
X-TraceId
X-WP-CF-Super-Cache-Active
Sid
User-Agent
Resin-Trace
X-Info
Uri
X-Ad-Defer-Variation
X-TA-CDN-Provider
X-LiteSpeed-Cache-Control
X-Via-Edge
X-Via-SSL
X-Via-CDN
X-Site-Version
YJS-ID
CF-Ctrl
X-Cached-By
X-Is-Supported-Browser
X-Is-Mobile
X-Is-Desktop
X-Browser-Name
X-Is-Tablet
X-Tcp-Rtt
Edge-Copy-Time
Locid
Srvid
A
X-FL-QIT-DEBUG
X-FL-EDGE
X-Locale
X-NGINX-Cache
True-Client-Ip
X-Nitro-Cache-From
X-Nitro-Rev
X-Cache-ASPX
X-Moov-T
X-ATG-Version
GeoIp-Country-Code
X-Contensis-Viewer-Groups
X-Moov-Xdn-Version
GeoIP-Country-Code
X-FireWall-Port
X-VCache
X-Varnish-Authentication
Cache-Key
Cdn
X-Hyper-Cache
XServer
Epwk-X-Cache
X-CS
X-NewRelic-App-Data
X-CSRF-TOKEN
X-MSEdge-Features
X-MSEdge-Flight
True-Client-IP
SID
X-Geo
X-Upstream-Ht
X-Upstream-Ct
X-Frame-Option
X-Datacenter
X-Webstats-RespID
X-TRACE-ID
X-Service
Fastly-Drupal-Html
X-HS-Content-Campaign-Id
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
X-FPC
X-Planisys-CDN-TTL
NtCoent-Length
X-Platform-Server
Path
State
X-HostName
Tcn
X-Vgn-Hpd-Cached
X-Release
X-Vgn-Hpd-Variations-Key
X-Fastly-Cache
X-LiteSpeed-Tag
X-SRV
X-Vgn-Hpd-Ssi
X-VC
X-Origin-Cache-Key
CountryCode
X-Api-Version
X-APP-VERSION
Cf-Ipcountry
X-Edge-Server
X-Amz-Meta-Opti
Cdn-Request-Time
Cdn-Host
X-Generated-In
X-Pad
X-Sigma-Backend
X-Esi
X-Air-Pt
X-Vercel-Id
X-AK-Request-ID
X-Rocket-Build-Number
X-Sigma
LB
Cdnsip
Cdncip
X-Vercel-Cache
Lb
X-Cache-Remote
X-FTR-Cache-Status
X-FTR-Expires
X-FTR-Backend-Server
X-FTR-Balancer
X-Country-Code-Real
X-FTR-Backend
Cache
X-NMSegId
X-Wp-Cf-Super-Cache
M-TraceId
WebServer
Req-ID
WZWS-RAY
X-Wp-Cf-Super-Cache-Cache-Control
X-Traceid
X-Cache-Ttl
X-Provided-By
X-Branch-Name
X-UA
X-HS-Status
X-Cdn-Request-ID
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
XkeyRZ
Yak-Timeinfo
X-Proxy-CacheRZ
X-Scheme
X-GeoIP-City
X-Ad-Load-Variation
Proxy-Connection
X-GoCache-CacheStatus
X-Gamma-Serve
Cluster
X-WP-CF-Super-Cache-Cookies-Bypass
CDN
X-CACHE-KEY
X-RN-RSRV
X-Cdn-Cache-Status
X-Scope-Id
X-M-Log
X-Akamai-Pragma-Client-IP
Content-Style-Type
Content-Script-Type
X-Vc
X-M-Reqid
X-Request-Start
X-NWS-UUID-VERIFY
Srv
X-Cdn-Forward
Geoip-Latitude
Pramga
X-Lb-Cache
Server-Id
X-Shield-Cache-Expires
X-Qnm-Cache
X-Tim-N
X-Varnish-Beresp-Status
CF-Cached-On
Env
Ngx
X-Ha-Backend
Ohc-File-Size
X-TT-LOGID
Serverid
Edge-Cache
X-Cache-Date
X-Dw-Trace-Id
Kp-EeAlive
X-Acquia-Application-Trace
X-EC-Lua
X-VCL-Version
X-Request-URI
X-Acquia-Application-UUID
X-Edge-POP
X-Acquia-Purge-Tags
X-Lb-Nocache
PICS-Label
X-Acquia-Site
X-Via-Ucdn
Yjs-Id
X-CF-Cache-Header-Vary
X-Udemy-Cache-App-Namespace
X-User
X-TH-Server
X-Render-Time
X-CF-Cache-Header-Cache-Control
X-CUA
Cache-Tv-Group
Cneonction
X-Cached-Since
X-RAMCache
Vha6-Origin
X-ElasticPress-Query
X-Litespeed-Cache-Control
X-MiniProfiler-Ids
X-Mobile-URL
X-Snapshot-Date
X-Fastly-Cache-Hits
X-Iauth-Set-Uid
Log-Origin
X-Location
CACHE-MISS-TO-ORIGIN
Inserted-Into-Cache-At
X-Miniprofiler-Ids
X-Edge-Pop