Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-Cache-Status
Link
Accept-Ranges
CF-RAY
ETag
X-XSS-Protection
Expect-CT
Pragma
X-Powered-By
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
Alt-Svc
X-UA-Compatible
X-Served-By
X-Xss-Protection
X-Download-Options
X-Timer
X-Request-Id
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-DNS-Prefetch-Control
X-Drupal-Cache
X-Cache-Status
X-Check
X-Generator
X-Cacheable
Timing-Allow-Origin
X-Content-Security-Policy
X-Iinfo
Feature-Policy
Status
X-Envoy-Upstream-Service-Time
Content-Encoding
Access-Control-Expose-Headers
P3p
X-Drupal-Dynamic-Cache
X-CDN
X-AspNetMvc-Version
X-Request-ID
Upgrade
X-Via
CF-Ray
X-Ws-Request-Id
Access-Control-Max-Age
Server-Timing
EagleId
X-Cache-Group
X-Turbo-Charged-By
Report-To
Keep-Alive
X-UA-Device
Request-Context
X-Age
X-Backend
X-Proxy-Cache
X-Server-Powered-By
X-AH-Environment
X-Robots-Tag
X-Hacker
X-Server
X-Amz-Request-Id
Host-Header
X-Amz-Id-2
Grace
X-Rq
X-Swift-SaveTime
X-Swift-CacheTime
X-Nginx-Cache-Status
X-Varnish-Cache
X-LiteSpeed-Cache
Ali-Swift-Global-Savetime
NEL
X-WebKit-CSP
X-Page-Speed
X-Vhost
EagleEye-TraceId
X-Ua-Compatible
X-Amz-Version-Id
X-OneAgent-JS-Injection
X-Pingback
X-Dispatcher
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
X-Cache-Spec
Accept-CH
X-Host
X-Server-Id
X-Dns-Prefetch-Control
Cf-Railgun
X-Node
X-Backend-Server
X-Readtime
Surrogate-Control
X-Akam-SW-Version
Request-Id
X-Response-Time
X-HW
Xkey
X-Application-Context
Content-Location
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Rating
X-Ruxit-JS-Agent
X-Country
X-B3-TraceId
Accept-CH-Lifetime
X-Cloud-Trace-Context
Accept-Ch-Lifetime
X-Cache-Lookup
X-Trace
X-Url
Allow
X-Ac
X-Content-Type
X-TtlSet
X-Vname
X-PC
X-Varnish-TTL
X-Aws-Lambda-Call-Status
Edge-Control
X-Clacks-Overhead
X-Server-Name
X-Mod-Pagespeed
X-ESI
Fastly-Restarts
Cache-Tag
X-Rack-Cache
X-VARITI-CCR
Service-Worker-Allowed
Verso
X-Element-Page-Cache
X-Upstream
X-Vcap-Request-Id
X-FastCGI-Cache
X-MS-InvokeApp
X-Amz-Rid
X-GitHub-Request-Id
MS-Author-Via
Public-Key-Pins
X-Cached
X-Dw-Request-Base-Id
X-Client-IP
X-Abt-Application-Version
X-D2id
X-Cnection
X-Px
RTSS
X-Cache-TTL
X-Use-Magma
X-Kinja-Build
X-Kinja-Server
X-Kinja
X-GoogleNews-Bot
X-Exp-Variant
X-Cdn-Fetch
X-Kinja-Revision
X-Exp-Id
Access-Control-Request-Method
X-Country-Code
Arr-Disable-Session-Affinity
X-Navigation-Version
X-Powered-By-Plesk
X-Goog-Hash
X-NF-Request-ID
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-Server-Lifecycle-Phase
X-Powered-CMS
X-Kraken-Loop-Name
X-Instrumentation
AR-SID
AR-CACHE
AR-Request-ID
AR-PoweredBy
AR-ATIME
Display
X-Sol
X-Middleton-Display
Pagespeed
X-Version
X-Origin-Cache
X-Middleton-Response
Response
X-TTL
X-LLID
X-MSEdge-Ref
X-Amz-Server-Side-Encryption
X-Edge-Location-Klb
TCN
X-Kinsta-Cache
Nginx-Cache
X-RateLimit-Remaining
X-Edge
X-B3-TraceId-Primal
Mrf-Cache-Status
MRF-Tech
X-Protected-By
X-CST
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-T
X-HP-Webp
X-HP-Trace-Id
X-Jurisdiction
X-Forwarded-For
X-Content-Security-Policy-Report-Only
X-Shield-Request-Id
X-Id
X-Aspnetmvc-Version
X-Mg-S
S
Content-MD5
X-Language
Edge-Cache-Tag
SPRequestDuration
SPIisLatency
Front-End-Https
X-Mid
Fastcgi-Cache
Realpath
X-Request-Received
X-Request-Processing-Time
Server-Node
Pinterest-Version
X-Pinterest-Rid
Pinterest-Generated-By
X-Frontend
X-DynaTrace
X-Recruiting
Filters
Server-Name
X-Ab
X-Content
X-Ua-Browser
X-MCACHE
X-Ser
X-Correlation-Id
X-Ttl
X-Ruxit-Js-Agent
X-Cache-Key
Accept-Ch
X-NWS-LOG-UUID
X-HS-Content-Id
X-HS-Hub-Id
X-Template
X-HS-Cache-Config
X-Yandex-Sdch-Disable
X-HS-Combine-CSS
X-Ezoic-Cdn
X-ECACHE
SPRequestGuid
X-SharePointHealthScore
X-Hits
X-Parallel-Accel
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
MicrosoftSharePointTeamServices
Cache-Tags
X-Page-Id
Cleartype
Charset
X-B3-Sampled
Host
X-Litespeed-Cache
Alternate-Protocol
X-Www-Served-By
X-Git-Hash
X-Webkit-Csp
Fusion-Template-Id
Fusion-Content-Id
Fusion-Content-Source
X-Content-Options
X-Debug-Info
Fusion-Deployment-Id
X-Geo-Country
Fusion-Source
Fusion-Component-Id
X-Daa-Tunnel
X-DIS-Request-ID
X-Hostname
X-Amzn-Trace-Id
X-Content-Digest
Cross-Origin-Opener-Policy
X-Amz-Replication-Status
X-Ratelimit-Limit
Filterid
X-Varnish-Age
X-FB-Debug
X-Grace
X-F-Cache
X-Upgrade-Enabled
X-VCache
X-Activity-Id
X-AppVersion
X-Az
X-N
ServerID
X-Accel-Expires
X-Nginx-Upstream-Cache-Status
X-Forwarded-Proto
X-Origin-Server
X-Rid
Access-Control-Allow-Method
X-Fastly-Request-ID
X-Mobile-URL
X-Flags
X-Providence-Cookie
X-Aspnet-Duration-Ms
X-Is-Crawler
X-Request-Guid
X-Route-Name
X-Type
X-Server-ID
X-TT
X-LB-Cache
X-Whom
Viewport
X-App-Environment
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-Seen-By
X-Goog-Storage-Class
X-Goog-Generation
X-Varnish-Grace
Payment
X-DataDome
X-Tb
X-WebKit-CSP-Report-Only
X-FW-Static
X-FW-Type
X-FW-Serve
X-FW-Dynamic
X-User-Agent
X-FW-Hash
X-FW-Server
TP-L2-Cache
TP-Cache
X-Fastcgi-Cache
Node
X-Distributor
Paypal-Debug-Id
DC
X-XRDS-LOCATION
Country
X-Wix-Request-Id
Accept-Charset
X-Fastly-Request-Id
X-App-Server
Fastcgi-Useragent
X-Cache-Rule
X-NGENIX-Cache
X-Cache-Control
X-Ratelimit-Reset
X-Via-JSL
Version
X-Origin-Upstream-Status
X-Drupal-Cache-Tags
X-Cluster-Name
X-Microsite
X-Buckets
X-Request-Handler-Origin-Region
Referer-Policy
X-Oracle-Dms-Rid
X-Oracle-Dms-Ecid
X-Contextid
X-Tec-Api-Origin
X-Tec-Api-Version
X-B-Cache
X-Cache-Age
X-Signature
X-Tec-Api-Root
Amp-Access-Control-Allow-Source-Origin
Cache-Status
X-Node-Name
Refresh
X-Logged-In
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Response-Served-From
X-Erf-Bev-Bev
X-Original-Request-Id
X-Erf-Bev-Bev-Is-Generated
SD-X-WS
X-Browser-Type
X-Mobile
X-Is-Bot
X-Rendered-As
X-Page-View
X-Vgn-Hpd-Reason
X-Real-IP
X-Cache-Expired-At
X-Varnish-Backend
X-Proxy-Cache-Status
X-IPLB-Instance
X-Revision
X-Debug
X-B
X-Jobs
X-Cacheable-TTL
Access-Control-Request-Headers
X-Load-Cache
NGB
X-Yottaa-Optimizations
X-Cache-Action
X-Proxy
X-Instance
X-Device-Type
X-Yottaa-Metrics
Akamai-GRN
X-UUID
X-RemovedCookies
Surrogate-Key
X-ProcessESI
X-Drupal-Cache-Contexts
X-Cache-Time
X-Framework
X-Rule
X-Debug-IsConnected
X-Debug-IsPreview
X-G
X-FW-Version
CF-IPCountry
SID
X-Accel-Buffering
X-Air-Source
X-Air-Hostname
GEO-INFO
X-Presslabs-Stats
X-Air-Trace-Id
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-TEC-API-ROOT
DynaTrace
X-Oneagent-Js-Injection
X-Cache-NGX
X-Nginx-Cache
Count-Hit
Uber-Trace-Id
X-Cache-Operation
X-Source
Liferay-Portal
X-Ms-Version
X-Azure-Ref
X-Ms-Request-Id
X-XRDS-Location
X-Zen-Fury
X-RateLimit-Limit
X-APP-VERSION
Frame-Options
X-EdgeConnect-Cache-Status
X-PressLabs-Stats
Protected
X-CDN-Forward
MS-CV
Ms-Operation-Id
X-RTag
X-Cache-Hit
Healthy
X-Backend-Name
X-Mode
X-L-Path
Ec-Rule-Version
Cross-Origin-Window-Policy
X-IPS-LoggedIn
Countrycode
X-Environment-Context
Xserver
X-Servername
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-Cache-TTL-Remaining
X-Hyper-Cache
X-Tumblr-User
WPO-Cache-Status
WPO-Cache-Message
X-Ratelimit-Remaining
X-Varnish-Server
Backend
X-Adobe-Content
LB
X-Adobe-Loc
X-SaId
X-Tid
X-UPSTREAM-Address
X-RN-RSRV
X-Rewrite-Enabled
X-Detected-As
Content-Disposition
Meta-Geo
X-JoinUs
X-Content-Age
X-Region
X-Extlb
X-Debug-Cache
X-Format
X-ShopId
X-ShardId
X-Cache-Grace
X-Routing-Service
Apigw-Requestid
X-Redis-Cache
X-Proxied
X-Cache-Server
X-Shopify-Stage
X-Forwarded-Host
X-Hosted-By
Country-Code
X-Zipkin-Id
X-Uri
X-Alternate-Cache-Key
X-Sql-Duration-Ms
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Sql-Count
X-ApacheServer
X-Via-Fastly
X-Human
CDN-Cache
CDN-RequestId
CDN-RequestCountryCode
CDN-Uid
Decoy-Debug-TTL
Decoy-Debug-Key
CDN-PullZone
CDN-EdgeStorageId
Mn-Server-Ip
Eomportal-Instance
X-FB-TRIP-ID
CDN-CachedAt
X-Access
X-Generation-Time
X-PERF
X-Site-Version
X-ServerID
X-Section
Url
Cache-Name
X-Status
X-PHP-Backend
X-No-Session
X-NCache
X-Microcachable
Decoy-Debug-Status
X-Origin-Date
X-Varnish-Beresp-Grace
Selected-Fe
Property-Id
X-Pubstack
TWC-Connection-Speed
TWC-Device-Class
X-UA-Device-Type
TWC-GeoIP-Country
X-Timing-Wait
X-Server-W
X-Storage
Fastly-SSL
X-Generated-By
X-Web-Node
X-Cache-Type
X-Cache-Host
X-BYPASS-REASON
X-Proxy-Build
X-Cluster-Node
X-PCL
X-OCL
X-Origin-Hint
X-NYM-Debug-Backend
X-ProxyCache-Key
X-ProxyCache-Status
X-Akamai-Edgescape
TWC-Privacy
TWC-Locale-Group
X-SayCDN-TTL
X-Say-Cacheable
Webcakes-Region
Webcakes-App-Version
Webcakes-App-Name
TWC-GeoIP-LatLong
X-Say-TTL
X-Trace-Id
Section-Io-Cache
X-Be
X-Varnishpool
X-Soup
Cache-Tv-Group
X-Content-Powered-By
Azure-RegionName
Azure-InstanceId
Content-Secure-Policy
Azure-SlotName
X-Hl-Ver
Azure-SiteName
Azure-Version
X-R9-Blue-Green-Version
X-LSADC-Cache
X-Webkit-CSP
Retry-After
DB-Nickname
X-TIME
X-NewRelic-App-Data
X-Nginx-Cache-Key
X-Ua
OT-Force-Account-Verify
X-Cached-By
X-Azure-Ref-OriginShield
X-Cache-Remote
X-Unique-Id
X-Bc-Bl
X-TT-LOGID
Source
X-Platform-Server
Cache
X-Auto-Login
X-Dc
X-Akamai-Transformed
X-GEO
X-Xfnlog-Site
SRV
X-LAGOON
ServedBy
X-Cdn
Upgrade-Insecure-Requests
X-Cache-Tags
HostName
X-Origin-TTL
Mime-Version
X-Origin-CC
X-Varnish-Cache-Hits
Cache-Hits
X-Varnish-Hits
X-SRV
From-Origin
X-TNCMS
X-Varnish-Hostname
X-CSRF-Token
X-Request-Time
X-EC-Lua
X-App-Version
X-Loop
X-HTML-Minification-Powered-By
X-Time
X-AOL-HN
X-S-Maxage
WP-Super-Cache
X-Request-Host
Xet-Cookie
Onion-Location
Webserver
X-ECache
X-Xrds-Location
Web-Mar-Node
X-Tumblr-Pixel-3
X-Tumblr-Pixel-2
X-NWS-UUID-VERIFY
X-Cache-Enabled
N-Cache
X-Proto
X-Handled-By
X-B3-SpanId
X-Amz-Meta-S3cmd-Attrs
X-FireWall-Port
Nel
X-Correlation-ID
X-Tenant
Ms-Author-Via
X-Endurance-Cache-Level
X-AWS-Id
X-Origin-Response-Time
X-LJ-Flow-ID
X-VWS-Id
X-Slack-Backend
DCR-Decision-By
X-S-Cookie
BehaviorPad-Version
A
X-ScT
X-Adobe-Source
X-Shop-Environment
X-SD-PageType
X-Session-Fingerprint
X-A
X-Destination
X-D
X-Developer
X-Epic-Correlation-Id
X-External-Request-Id
X-Connection-Hash
X-Conf
X-CF-Lambda-Fn
X-Cache-NE
X-CF-Lambda-Version
X-Ckpd-Fst-Backend
X-Cluster
X-Forwarded-Path
X-Ftr-Request-Id
X-NAPM-TraceId
X-Planisys-CDN-Cache
X-ND-Cache
X-Orig-Expires
X-PAYTM-SRV-ID
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Gen-Mode
X-GG-Cache-Date
X-Hnp-Log
X-Ig-Push-State
X-Processor
X-Block-Status
Redirect-Candidate
Pramga
Rendered-Blocks
Sslversion
Surrogated-Key
Odigeo-Trace-Id
Mobile-Detection-Method
Expiry
X-S
Fastcgi-X-Cache-Version
X-Rojux
Meta-Geo-Continent
User-Cache-Control
V-Age
X-Application
X-Aed
X-ARC
X-B-Cookie
X-Backend-TTL
X-A-Wwc
X-A-Dgt
Vix-Hermes-Req-Id
X-A-Ccd
X-A-Dam
X-A-Dcw
DCR-Processing-Time-Ms
X-RCS-CacheZone
X-V-Cache
X-SRCache-Key
X-Vtex-Remote-Cache
X-VG-WebCache
X-Vtex-Processado-Em
X-PBS-Appsvrname
X-Time-Microsecs
X-Vdms-Version
X-TIM-N
Xc-Version
X-Vdms-Path
X-Reqid
X-MP-GENERATED-AT
X-Edge-Location
X-Magnolia-Registration
S-Rt
Cmsid
Cmstype
CDCHOST
X-Akamai-Request-ID2
X-Rocket-Nginx-Serving-Static
X-Proxy-Upstream
X-Accel-Expires-Debug
Fastcgi-Cache-TTL
X-Viewer-Country
Gh-Request-Id
X-Li-Fabric
DSUID
X-Aicache-OS
Wxu-Next-Region
True-Client-Country-4JS
X-Http-Reason
Origin
Svr
X-Origin-Expires
State
X-Date
X-GeoIP-Region-Code
X-Men
X-Mg-Request-UUID
Wxu-Next-Hostname
X-Scheme
X-Li-Pop
Wxu-Next-Commit
X-Mvc-Supplant-Cachable
X-Request-URI
X-LI-UUID
X-Webstats-RespID
CacheControlHeader
X-Cache-Date
X-NodeID
X-Cache-Info
X-SVT-ORM-RULES
X-VG-TLSProxy
X-Cache-Bucket
X-Old-Content-Length
X-Server-IP
X-Hash
X-Origin
X-Forwarded-Site
X-Fastly-Cache
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
Arc-Country
X-Cdn-Srv
X-SVT-ORM-VERSION
Apple-News-Services-Host
X-Policy
Apple-News-Services-Handled
AKAMAI
X-GeoIP-Country-Code
Environment
X-Cache-Var
X-Via-NSCOPI
X-Labrador-Cache-Channel
CloudFront-Viewer-Country
Server-Info
X-PHP-Host
X-Cache-Var-Map
Origin-CC
X-Platform
X-Backend-State
X-Region-Sid
X-VServer
Origin-EX
X-Csrf-Jwt
Ssr
X-Irp-Debug
X-RateLimit-Remaining-Second
X-CGP
X-Cache-Debug
We-Hiring
X-Fastly-Backend
Web-Mar-Region
X-RateLimit-Limit-Second
X-VarnishDD-TTL
X-Branch-Name
X-Cdn-Origin
X-Cache-Id
Locid
X-BBC-Edge-Cache-Status
X-HN
X-Rocket-Build-Number
X-Varnish-Beresp-Ttl
X-Sucuri-ID
X-GeoIP
X-Sucuri-Cache
X-Varnish-Beresp-Status
X-Fetched-On
X-Device-Os
X-Datadog-Parent-Id
X-TH-Server
X-Sn-Servicetimems
X-Eu-Site
X-Storefront-Renderer-Rendered
X-Nyt-Route
X-Skip-Cache
X-Gdpr
X-Geo-Header
X-Owner
Fastly-Drupal-Html
X-Gamma-Serve
X-Sigma-Backend
X-Served-From
X-GeoIP-City
X-Origin-Time
X-Sigma
X-Esi-Check
X-Core-Mission
X-Locale
X-Location
PFcat
Traceparent
X-UnsetCookies
Release
X-Req
X-Datadog-Sampling-Priority
X-Datadog-Trace-Id
Req-Svc-Chain
X-Developers
X-Gzip
L
L5d-Success-Class
Host-ID
HA-Ipaddr
Fastly-GeoIP-CountryCode
Ha-Gx-Prefs
Magicmarker
Machine
X-Envoy-Decorator-Operation
X-TrackingId
Mail-Subject
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Core-Value
X-DefElseHash
X-Pod-Name
X-Generated-On
X-Rebelmouse-Cache-Control
X-Variation
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-ATG-Version
X-Restarts
NGX
Memcached
X-Varnish-Remaining-TTL
X-Node-Id
Fastly-SIE
Adler-Geo
Fastly-SWR
Is-Eu
Platform
X-Tx-Id
X-DefHash
NM-Fastcgi-Cache
X-Is-Gdpr
X-Response-By
X-Has-Esi
X-DPWN-IS-SECURE
X-Level-Front-Cache
X-FC-Vary-Parameters
X-JWT-State
Cf-Device-Type
X-Qloud-Router
X-Rebelmouse-Surrogate-Control
X-NU-AKA-ACS-Version
X-Loc
Server-Host
X-HS-Content-Campaign-Id
X-Trace-ID
X-Ua-Device
Kp-EeAlive
X-Thinkindot-L3
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
X-Request-Start
Thinkindot-Control
AMP-Access-Control-Allow-Source-Origin
X-Worker
X-VC-Cache
X-Amzn-Remapped-Content-Length
TDXMobile
X-CS
X-Zone
X-Bip
X-Wix-Viewer-Type
X-Cache-Backend
X-Action
X-Mvc-Supplant-OutputCached
X-RPM
X-RSL
X-DB
X-LB-ID
X-Thanos
X-NC
CDN
X-Qnm-Cache
X-M-Reqid
X-API-Version
X-DSS
X-DW
X-RPS
X-DI
X-M-Log
Edge-Cache
X-Up
Accept-Language
Pics-Label
X-LB-NoCache
X-Generated-In
X-TraceId
X-Tb-Optimization-Total-Bytes-Saved
Time
Memory
Env
X-Optimistic-Header
X-Cache-Config
X-Minions-Version
X-CacheTTL
X-Srv
WebServer
X-DC
X-Via-Popv
X-Via-Poph
X-Refresh
X-Varnish-Ttl
X-Via-Popn
Locale
X-Tt-Logid
X-Urbn-Context-Path
X-Urbn-Site-Id
Datacenter
X-Edge-Pop
X-HA-Backend
X-Cache-Ttl
GeoIp-Country-Code
X-CACHE-KEY
Candidate-Md5Url
NtCoent-Length
X-ZONE
X-Datadome
X-Ec-Fail
X-Esi
X-TA-CDN-Provider
X-Ec-GeoHdr
X-User
X-Servedbyhost
Server-ID
X-DynaTrace-JS-Agent
X-Parent-Response-Time
X-MSEdge-Features
X-Vc
On-Server
WWW-Authenticate
X-MSEdge-Flight
X-CLOUD-TRACE-CONTEXT
X-Cs
Esi-Enabled
X-TX-ID
X-VCL-Version
X-Varnish-Beresp-TTL
X-AK-Request-ID
X-Unique-ID
Cdnsip
Cdncip
X-Webkit-CSP-Report-Only
X-Traceid
Cluster
My-App
X-Fpc
X-LI-Proto
X-WADP-Cache
X-App
X-Fmm-Version
X-Clara-WADP
C-Via
X-Cache-PHP
X-Service
X-URL
Tracecode
X-CUA
Geoip-Latitude
X-Dynatrace
X-Webkit-Csp-Report-Only
X-Li-Proto
X-Var-Ttl
X-Newrelic-Synthetics
X-Pass-Why
X-B3-Spanid
Test
X-From
T-Server
X-FPC
Lfy
Proxy-Connection
Cf-Int-Pingora-Origin-Digest
X-NODE
X-Cache-Status-Check
Lang
DataCenter
X-Fragments
X-VC
Fastly-Drupal-HTML
X-Render-Time
X-Vcl-Version
X-Mcache
Geo-Info
X-LiteSpeed-Cache-Control
Resin-Trace
M-TraceId
Target-Params
Server-Id
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
X-CSRF-TOKEN
X-Provided-By
X-Ha-Backend
X-RAMCache
X-ID
GeoIP-Country-Code
Hostname
MIME-Version
X-Edge-POP
Hit
X-Proxy-Cache-Info
X-Httpd
X-Clientip
Permissions-Policy
X-ServedByHost
X-Geo
X-Dynatrace-Js-Agent
X-Via-PopN
X-Via-PopH
X-Via-PopV
Servername
WZWS-RAY
X-Cdn-Forward
Cache-Host
X-Oss-Hash-Crc64ecma
Producers
UCS
X-Oss-Object-Type
X-Oss-Request-Id
X-Oss-Storage-Class
X-Oss-Server-Time
X-Pad
X-LiteSpeed-Tag
HIT
X-AIR-PT
X-RateLimit-Reset
X-Info
X-SB
Section-Io-Id
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
S-Cnection
X-Edge-Cache
X-Fastly-Backend-Reqs
X-NGINX-Cache
ENV
Section-Io-Origin-Status
X-Api-Version
FSS-Cache
X-Udemy-Cache-App-Namespace
X-Platform-Cluster
X-ElasticPress-Query
X-Ucs
Ohc-File-Size
X-Platform-Processor
X-Pool
X-Platform-Router
X-Check-Cacheable
PICS-Label
X-Scale
X-Ec-Custom-Error
X-Acquia-Application-UUID
Uri
X-Lb-Nocache
X-Cache-CFC
X-UP
ServerName
X-Acquia-Purge-Tags
X-Acquia-Site
X-Acquia-Application-Trace
X-GoCache-CacheStatus
X-BBC-Origin-Response-Status
Fastly-Backend-Name
URI
X-HS-Status
X-Micro-Cache
User-Agent
X-Srcache-Store-Status
X-Srcache-Fetch-Status
X-Dispatcher-Number
IsBot
X-Cache-Expires
Sever-Int
Server-Ttl
MD5-Digest
X-Nc
Server-Ext
X-Release
Server-Hostname
X-Backend-Host
X-ServerName
Cneonction
Load-Balancing
X-Fastly-Cache-Hits
X-Swift-Error
X-Cdn-Request-ID
X-Lb-Id
Tcn
Cteonnt-Length
X-SIPLIST1
X-Dw-Trace-Id
X-Vcache
Vha6-Origin
Wpo-Cache-Message
Wpo-Cache-Status
X-Newrelic-App-Data
X-Akamai-ERRuleID
X-Akamai-ERPolicy
Shield-Pop
X-BCube-Filmed-By
X-TRACE-ID
X-Cache-ASPX
X-Contensis-Viewer-Groups
X-APP
X-B3-ParentSpanId
X-Snapshot-Date
Cf-Ipcountry
EpKe-Alive
X-UA
X-Yottaa-OS
CF-Cached-On
X-Via-Ucdn
Sid
X-Air-Pt
X-Cache-Ngx
Cdn
X-HostName
GeoIP-Latitude
X-Varnish-Authentication
X-Litespeed-Cache-Control
X-Shopify-Generated-Cart-Token
X-IN-APIGATEWAY
X-B3-Parentspanid
X-IN-APIGATEWAYSSL
X-Te-Duration-Ms
X-Logging-Id
X-Http-Count
X-Http-Duration-Ms
X-CacheKey
Ngx
Req-ID
X-Akamai-Pragma-Client-IP
X-Sentry-ID
X-Te-Count
CountryCode
X-Apw-Access-Token
X-Apw-Access-Object
X-Apw-Access-Action
X-Apw-Hits
X-Last-Modified
Ohc-Cache-HIT
Path
X-Akamai-Request-ID