Threat Level: green Handler on Duty: Rick Wanner

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
Link
CF-Cache-Status
Accept-Ranges
CF-RAY
ETag
X-XSS-Protection
Expect-CT
Pragma
X-Powered-By
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-UA-Compatible
X-Cache-Hits
Alt-Svc
P3P
X-Served-By
X-Xss-Protection
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Cache-Status
X-Generator
X-Cacheable
Timing-Allow-Origin
X-Request-ID
X-Content-Security-Policy
P3p
X-Iinfo
Status
Feature-Policy
X-Envoy-Upstream-Service-Time
Content-Encoding
Access-Control-Expose-Headers
X-CDN
X-Drupal-Dynamic-Cache
X-AspNetMvc-Version
Upgrade
X-Via
CF-Ray
Access-Control-Max-Age
X-Ws-Request-Id
Server-Timing
EagleId
Keep-Alive
X-Cache-Group
X-Turbo-Charged-By
Request-Context
X-Age
X-Proxy-Cache
X-Server-Powered-By
X-AH-Environment
X-UA-Device
X-Hacker
X-Backend
X-Robots-Tag
Report-To
X-Amz-Request-Id
Host-Header
X-LiteSpeed-Cache
X-Server
X-Amz-Id-2
Grace
X-Rq
X-Nginx-Cache-Status
X-Varnish-Cache
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-WebKit-CSP
X-Dns-Prefetch-Control
X-Page-Speed
X-Vhost
X-OneAgent-JS-Injection
X-Amz-Version-Id
EagleEye-TraceId
X-Device
X-Dispatcher
X-Pingback
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Cache-Spec
NEL
X-Server-Id
X-Host
X-Backend-Server
X-Node
Cf-Railgun
Accept-CH
X-Readtime
X-Akam-SW-Version
Surrogate-Control
Request-Id
X-Response-Time
X-HW
X-Language
Xkey
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Ruxit-JS-Agent
X-Application-Context
Content-Location
X-Template
Rating
X-Country
X-B3-TraceId
X-Ua-Compatible
Accept-Ch-Lifetime
Accept-CH-Lifetime
X-Cache-Lookup
X-Cloud-Trace-Context
X-Ac
X-Url
Allow
X-Content-Type
X-Buckets
X-Trace
X-PC
X-TtlSet
X-Vname
X-Mod-Pagespeed
X-Varnish-TTL
X-Clacks-Overhead
Edge-Control
X-FastCGI-Cache
X-ESI
Cache-Tag
Fastly-Restarts
X-Rack-Cache
Service-Worker-Allowed
X-VARITI-CCR
X-Server-Name
X-Element-Page-Cache
Verso
X-GitHub-Request-Id
X-MS-InvokeApp
X-Upstream
X-Amz-Rid
MS-Author-Via
X-Vcap-Request-Id
X-Dw-Request-Base-Id
Public-Key-Pins
X-D2id
X-Client-IP
X-Cached
X-Abt-Application-Version
X-Origin-Cache
X-Cache-TTL
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
Arr-Disable-Session-Affinity
X-Cnection
X-Country-Code
X-Px
X-Goog-Hash
X-Navigation-Version
X-Powered-By-Plesk
Access-Control-Request-Method
X-Aws-Lambda-Call-Status
X-Instrumentation
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-NF-Request-ID
X-Version
Accept-Ch
RTSS
X-Amz-Server-Side-Encryption
X-Powered-CMS
Display
Pagespeed
X-Sol
X-Middleton-Display
X-SRCache-Fetch-Status
X-SRCache-Store-Status
Response
X-Middleton-Response
X-Use-Magma
X-Exp-Id
X-Kinja-Server
X-Cdn-Fetch
X-GoogleNews-Bot
X-Exp-Variant
X-Kinja-Revision
X-Kinja
X-Kinja-Build
X-MSEdge-Ref
X-LLID
X-Edge
X-Edge-Location-Klb
X-Kinsta-Cache
X-CST
Nginx-Cache
X-Shield-Request-Id
MRF-Tech
Mrf-Cache-Status
X-B3-TraceId-Primal
S
AR-Request-ID
AR-CACHE
AR-ATIME
AR-PoweredBy
AR-SID
Content-MD5
X-Jurisdiction
X-HP-Webp
X-HP-Trace-Id
X-T
X-RateLimit-Remaining
X-Protected-By
X-Forwarded-For
X-Content-Security-Policy-Report-Only
TCN
X-Mg-S
X-Id
X-TTL
X-Mid
X-Aspnetmvc-Version
Fastcgi-Cache
X-MCACHE
X-Ttl
Realpath
Front-End-Https
X-Parallel-Accel
SPRequestDuration
SPIisLatency
Edge-Cache-Tag
X-Recruiting
X-Request-Processing-Time
X-Request-Received
Filters
X-Pinterest-Rid
Pinterest-Generated-By
Pinterest-Version
Fusion-Component-Id
Fusion-Source
Fusion-Content-Id
Fusion-Content-Source
Fusion-Deployment-Id
Server-Node
Fusion-Template-Id
X-DynaTrace
X-Content
X-Ua-Browser
X-Ab
X-SharePointHealthScore
SPRequestGuid
X-Ezoic-Cdn
Alternate-Protocol
Server-Name
X-Correlation-Id
X-Accel-Expires
X-NWS-LOG-UUID
X-Frontend
X-HS-Content-Id
X-HS-Cache-Config
X-HS-Combine-CSS
X-HS-Hub-Id
X-Hits
X-Yandex-Sdch-Disable
X-Cache-Key
X-ECACHE
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Content-Options
Cache-Tags
X-Page-Id
Host
X-Git-Hash
MicrosoftSharePointTeamServices
Cleartype
X-Fastly-Request-Id
Charset
X-Www-Served-By
X-B3-Sampled
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-XRDS-LOCATION
X-Geo-Country
X-Ruxit-Js-Agent
X-Content-Digest
X-Amz-Replication-Status
X-Ser
TP-Cache
TP-L2-Cache
Filterid
X-Forwarded-Proto
X-Hostname
X-Amzn-Trace-Id
X-VCache
X-Varnish-Age
X-Activity-Id
X-Az
X-AppVersion
X-Daa-Tunnel
X-DIS-Request-ID
X-Rid
X-Debug-Info
X-Upgrade-Enabled
X-Origin-Server
X-Grace
Access-Control-Allow-Method
X-N
X-Request-Handler-Origin-Region
X-Microsite
X-LB-Cache
X-Origin-Upstream-Status
X-FB-Debug
X-WebKit-CSP-Report-Only
ServerID
X-Nginx-Upstream-Cache-Status
X-Mobile-URL
X-TT
X-Aspnet-Duration-Ms
X-Flags
X-Whom
X-Request-Guid
X-Providence-Cookie
X-Route-Name
X-Is-Crawler
X-Goog-Generation
X-F-Cache
X-NGENIX-Cache
X-Goog-Storage-Class
X-Goog-Metageneration
X-GUploader-UploadID
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
Cross-Origin-Opener-Policy
X-App-Server
X-App-Environment
X-Varnish-Grace
Viewport
X-Tb
X-Distributor
Payment
X-FW-Dynamic
Paypal-Debug-Id
X-FW-Hash
X-FW-Static
X-FW-Server
X-FW-Serve
X-FW-Type
DC
X-Server-ID
Node
X-Cache-Control
X-Logged-In
Fastcgi-Useragent
X-Seen-By
X-PressLabs-Stats
X-Type
X-User-Agent
X-Cache-Age
Country
Accept-Charset
X-Ratelimit-Limit
X-Cache-Rule
X-Varnish-Backend
Version
X-Erf-Bev-Bev-Is-Generated
X-Node-Name
X-DataDome
X-Erf-Bev-Bev
X-Webkit-CSP
X-Browser-Type
X-Load-Cache
X-Wix-Request-Id
X-Tec-Api-Origin
X-Tec-Api-Version
X-Cache-Action
X-Tec-Api-Root
X-Via-JSL
X-IPLB-Instance
Refresh
Access-Control-Request-Headers
X-Response-Served-From
Referer-Policy
SD-X-WS
X-Original-Request-Id
Cache-Status
X-Real-IP
X-Cacheable-TTL
X-Drupal-Cache-Tags
Amp-Access-Control-Allow-Source-Origin
X-Jobs
VIX-Pulpo-Upstream-Status
X-ProcessESI
VIX-Pulpo-Node
X-Vgn-Hpd-Reason
X-B
X-Cluster-Name
X-Debug
X-Contextid
X-Rendered-As
X-RemovedCookies
X-Revision
X-Is-Bot
NGB
X-Page-View
X-Proxy-Cache-Status
X-UUID
X-B-Cache
X-Yottaa-Metrics
X-Signature
X-Drupal-Cache-Contexts
X-Rule
X-Device-Type
DynaTrace
X-Yottaa-Optimizations
X-Proxy
Akamai-GRN
Surrogate-Key
X-Cache-Time
X-Instance
X-Cache-Expired-At
X-Fastly-Request-ID
Liferay-Portal
X-G
X-Framework
X-Mobile
X-Debug-IsConnected
X-Debug-IsPreview
CF-IPCountry
X-Azure-Ref
X-Fastcgi-Cache
X-FW-Version
Healthy
X-Source
SID
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Air-Hostname
X-Air-Trace-Id
X-TEC-API-VERSION
X-Air-Source
X-Ms-Version
X-Ms-Request-Id
Frame-Options
X-Oracle-Dms-Rid
X-Oracle-Dms-Ecid
X-Nginx-Cache
Ms-Operation-Id
X-Cache-Hit
X-RTag
MS-CV
X-APP-VERSION
Section-Io-Cache
X-Tumblr-Pixel-0
X-Tumblr-User
X-Tumblr-Pixel
Countrycode
X-CDN-Forward
X-Tumblr-Pixel-1
X-Oneagent-Js-Injection
Xserver
X-L-Path
X-Varnish-Server
X-Environment-Context
Count-Hit
X-Cache-Operation
X-Region
GEO-INFO
X-Servername
X-XRDS-Location
X-Forwarded-Host
Uber-Trace-Id
X-Content-Powered-By
X-EdgeConnect-Cache-Status
X-Backend-Name
X-Mode
Cross-Origin-Window-Policy
Backend
X-Accel-Buffering
X-IPS-LoggedIn
X-Litespeed-Cache
X-Adobe-Loc
X-Adobe-Content
Ec-Rule-Version
X-Zen-Fury
X-UPSTREAM-Address
X-SaId
X-RN-RSRV
Meta-Geo
X-JoinUs
X-Detected-As
X-Sorting-Hat-PodId
X-Shopify-Stage
X-ShopId
X-ShardId
X-Alternate-Cache-Key
Eomportal-Instance
X-Cache-Grace
X-Debug-Cache
X-Cache-Type
X-Generation-Time
X-Hosted-By
X-Microcachable
X-Human
X-Cache-Server
X-Varnish-Beresp-Grace
X-Sorting-Hat-ShopId
X-Redis-Cache
X-Site-Version
X-Status
X-Storage
X-ServerID
X-Origin-Date
X-PHP-Backend
X-ProxyCache-Status
X-NCache
X-ProxyCache-Key
X-Cache-TTL-Remaining
Cache-Tv-Group
Cache-Name
X-Via-Fastly
Decoy-Debug-Key
Decoy-Debug-Status
X-BYPASS-REASON
Url
Decoy-Debug-TTL
X-FB-TRIP-ID
Country-Code
X-Uri
X-Sql-Count
X-Sql-Duration-Ms
X-OCL
Property-Id
Protected
Selected-Fe
TWC-Device-Class
Fastly-SSL
X-UA-Device-Type
Mn-Server-Ip
X-Ratelimit-Reset
Apigw-Requestid
X-Say-Cacheable
X-Say-TTL
X-SayCDN-TTL
X-Origin-Hint
X-PCL
X-Web-Node
X-Cache-Host
TWC-Connection-Speed
TWC-GeoIP-Country
Webcakes-Region
X-Timing-Wait
X-No-Session
X-Proxy-Build
X-Format
Webcakes-App-Version
X-Akamai-Edgescape
TWC-Privacy
TWC-Locale-Group
TWC-GeoIP-LatLong
Webcakes-App-Name
X-Proxied
X-ApacheServer
X-Pubstack
Azure-Version
Azure-SlotName
X-Varnishpool
X-PERF
X-Access
X-Hl-Ver
X-Routing-Service
OT-Force-Account-Verify
X-Extlb
X-Azure-Ref-OriginShield
DB-Nickname
X-NYM-Debug-Backend
Azure-SiteName
X-Zipkin-Id
X-R9-Blue-Green-Version
X-Server-W
Azure-RegionName
X-Section
Azure-InstanceId
Content-Secure-Policy
X-RateLimit-Limit
X-Cluster-Node
X-Rewrite-Enabled
Source
X-Tid
X-Be
X-Cache-NGX
X-LSADC-Cache
X-Ua
X-Soup
X-Content-Age
X-NewRelic-App-Data
X-HTML-Minification-Powered-By
X-Time
X-Amz-Meta-S3cmd-Attrs
X-Cache-Var
X-Cache-Var-Map
Content-Disposition
X-Webkit-Csp
X-Cached-By
X-Presslabs-Stats
SRV
X-ECache
X-Dc
X-SRV
CDN-PullZone
X-Generated-By
CDN-Cache
X-LAGOON
CDN-RequestCountryCode
CDN-CachedAt
X-Unique-Id
CDN-RequestId
CDN-EdgeStorageId
Cache
CDN-Uid
X-Varnish-Hostname
X-Hyper-Cache
X-Bc-Bl
X-TNCMS
X-Varnish-Hits
X-Loop
X-App-Version
Onion-Location
X-S-Maxage
Retry-After
X-Origin-TTL
X-Auto-Login
X-Origin-CC
X-TT-LOGID
X-Tumblr-Pixel-2
X-Trace-Id
X-GEO
Webserver
X-Tumblr-Pixel-3
Web-Mar-Node
Cache-Hits
X-Nginx-Cache-Key
X-Proto
Xet-Cookie
X-Tenant
X-Time-Microsecs
X-Qnm-Cache
X-M-Reqid
X-Endurance-Cache-Level
X-M-Log
X-Cdn
X-Akamai-Transformed
X-Edge-Location
X-CSRF-Token
X-AWS-Id
X-VWS-Id
Mime-Version
X-LJ-Flow-ID
X-Platform-Server
LB
X-GG-Cache-Date
X-CLOUD-TRACE-CONTEXT
CloudFront-Viewer-Country
X-Correlation-ID
HostName
X-Mg-Request-UUID
X-CACHE-KEY
X-Amzn-RequestId
X-Labrador-Cache-Channel
X-Amz-Apigw-Id
X-PHP-Host
N-Cache
X-Xfnlog-Site
X-Cache-Tags
X-RCS-CacheZone
X-Handled-By
X-Locale
Upgrade-Insecure-Requests
X-Varnish-Cache-Hits
X-Storefront-Renderer-Rendered
X-Request-Time
ServedBy
X-Origin-Response-Time
X-Adobe-Source
X-TIME
WPO-Cache-Message
WPO-Cache-Status
X-Cache-Remote
X-VC-Cache
X-AOL-HN
X-B3-SpanId
X-Ckpd-Fst-Backend
X-CF-Lambda-Version
X-Cluster
X-ND-Cache
X-Connection-Hash
X-Conf
X-Orig-Expires
X-Processor
X-Planisys-CDN-TTL
X-B-Cookie
Surrogated-Key
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
X-NAPM-TraceId
X-PBS-Appsvrname
X-PAYTM-SRV-ID
X-A-Ccd
A
X-D
X-Ftr-Request-Id
X-Forwarded-Path
X-Aed
X-Developer
Nel
X-External-Request-Id
X-Application
X-A-Wwc
X-A-Dam
State
BehaviorPad-Version
X-A-Dcw
X-Reqid
X-A-Dgt
X-Ig-Push-State
X-A
X-Rojux
Odigeo-Trace-Id
X-VG-WebCache
Mobile-Detection-Method
X-Cache-NE
X-Vdms-Version
X-V-Cache
Origin
X-Vdms-Path
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
Fastcgi-X-Cache-Version
X-ARC
X-Cache-Date
Meta-Geo-Continent
Expiry
Xc-Version
X-ATG-Version
X-TIM-N
X-SVT-ORM-VERSION
X-ScT
X-SD-PageType
Redirect-Candidate
X-CF-Lambda-Fn
X-S-Cookie
Rendered-Blocks
X-Destination
X-S
Pramga
X-Session-Fingerprint
DCR-Processing-Time-Ms
DSUID
X-SVT-ORM-RULES
X-SRCache-Key
X-Slack-Backend
X-Shop-Environment
DCR-Decision-By
X-Request-Host
X-Via-NSCOPI
Environment
X-MP-GENERATED-AT
Server-Info
Release
L
Host-ID
V-Age
Wxu-Next-Commit
X-Accel-Expires-Debug
Wxu-Next-Region
Wxu-Next-Hostname
Vix-Hermes-Req-Id
X-Li-Pop
X-Served-From
X-Server-IP
X-Skip-Cache
X-Scheme
X-Rocket-Nginx-Serving-Static
X-Owner
X-Policy
X-Proxy-Upstream
X-Sucuri-Cache
X-Sucuri-ID
X-Fastly-Cache
X-Gen-Mode
X-Hnp-Log
X-Block-Status
User-Cache-Control
X-Varnish-Beresp-Status
X-VG-TLSProxy
X-VServer
X-Origin-Time
X-Origin-Expires
X-Fetched-On
X-Forwarded-Site
X-Gdpr
X-Epic-Correlation-Id
X-Device-Os
X-Cache-Info
X-Core-Mission
X-Date
X-Geo-Header
X-Hash
X-Mvc-Supplant-Cachable
X-Nyt-Route
X-Old-Content-Length
X-Men
X-Location
Gh-Request-Id
X-LI-UUID
X-Cache-Bucket
X-Li-Fabric
Datacenter
Fastcgi-Cache-TTL
Cmstype
Cmsid
AKAMAI
CacheControlHeader
From-Origin
AMP-Access-Control-Allow-Source-Origin
X-Gamma-Serve
X-Generated-On
X-Fastly-Backend
X-Esi-Check
X-Developers
X-GeoIP
X-GeoIP-City
X-BBC-Edge-Cache-Status
X-Cache-Debug
X-HN
X-Gzip
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
X-Core-Value
X-TH-Server
Apple-News-Services-Handled
Apple-News-Services-Host
X-Bip
X-Branch-Name
X-Datadog-Parent-Id
X-Cdn-Origin
X-Cache-Id
X-Cache-Config
X-HS-Content-Campaign-Id
X-Ratelimit-Remaining
Req-Svc-Chain
X-Thinkindot-L3
X-Thanos
X-Sigma-Backend
X-TrackingId
X-VarnishDD-TTL
CDCHOST
Arc-Country
Origin-EX
X-Viewer-Country
X-Sigma
X-Rocket-Build-Number
Apple-News-Services-Parsed-Url
X-NodeID
X-Level-Front-Cache
X-Irp-Debug
X-Platform
Traceparent
X-Request-Start
X-Req
X-Region-Sid
X-Magnolia-Registration
Origin-CC
X-Sn-Servicetimems
Thinkindot-Control
True-Client-Country-4JS
Web-Mar-Region
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
Apple-News-Services-Request-Url
Mail-Subject
Locid
Candidate-Md5Url
Fastly-GeoIP-CountryCode
Machine
TDXMobile
We-Hiring
PFcat
Svr
Server-Host
NM-Fastcgi-Cache
X-DefHash
X-JWT-State
X-Is-Gdpr
X-Request-URI
Cf-Device-Type
X-Csrf-Jwt
Fastly-SIE
X-Loc
X-Varnish-CookieHashed-On
X-Worker
X-DPWN-IS-SECURE
X-Varnish-Remaining-TTL
Fastly-SWR
X-EC-Lua
X-Variation
Memcached
X-FC-Vary-Parameters
X-RateLimit-Remaining-Second
X-Has-Esi
X-Eu-Site
X-UnsetCookies
X-Varnish-CookieINHashed-On
X-DefElseHash
X-Aicache-OS
Adler-Geo
X-Qloud-Router
X-Rebelmouse-Surrogate-Control
X-Pod-Name
NGX
Platform
X-Backend-State
X-Webstats-RespID
X-Amzn-Remapped-Content-Length
X-Rebelmouse-Cache-Control
X-Origin
Is-Eu
L5d-Success-Class
X-CGP
Ha-Gx-Prefs
HA-Ipaddr
X-RateLimit-Limit-Second
X-Envoy-Decorator-Operation
X-FireWall-Port
Fastly-Drupal-Html
X-Xrds-Location
X-Node-Id
WWW-Authenticate
Sslversion
X-Cdn-Srv
X-NU-AKA-ACS-Version
X-Zone
CDN
X-Tx-Id
X-CS
X-API-Version
X-LB-ID
X-NC
Esi-Enabled
X-Response-By
X-Mvc-Supplant-OutputCached
On-Server
Ssr
X-Tt-Logid
X-Up
WP-Super-Cache
X-Vc
X-Varnish-Beresp-Ttl
X-Generated-In
X-Trace-ID
C-Via
X-Service
Memory
Time
Pics-Label
X-Refresh
Ms-Author-Via
X-Datadome
X-DynaTrace-JS-Agent
X-Edge-Pop
X-Cache-Enabled
X-Backend-TTL
X-LB-NoCache
X-Cache-PHP
NtCoent-Length
X-TraceId
X-TA-CDN-Provider
X-GeoIP-Region-Code
GeoIp-Country-Code
X-GeoIP-Country-Code
X-Tb-Optimization-Total-Bytes-Saved
Env
X-Via-Popv
X-Via-Poph
X-Via-Popn
X-NWS-UUID-VERIFY
X-Dynatrace
X-Varnish-Ttl
Magicmarker
X-Varnish-Beresp-TTL
X-Cache-Status-Check
X-Parent-Response-Time
X-Optimistic-Header
X-DC
X-Render-Time
X-ZONE
X-Info
X-Esi
X-CacheTTL
X-Ua-Device
Kp-EeAlive
X-Cs
X-Srv
X-TX-ID
S-Rt
X-Restarts
X-Unique-ID
X-Servedbyhost
WebServer
X-AIR-PT
Edge-Cache
Server-ID
X-DW
X-Clientip
X-Cache-Backend
X-Wix-Viewer-Type
X-MSEdge-Features
X-RPM
X-DB
X-DI
X-DSS
X-RPS
X-Action
X-MSEdge-Flight
X-RSL
X-Oss-Request-Id
X-Li-Proto
X-Oss-Storage-Class
X-Oss-Server-Time
HIT
X-Oss-Hash-Crc64ecma
Cache-Host
X-Oss-Object-Type
UCS
X-FPC
S-Cnection
X-Minions-Version
X-VCL-Version
Proxy-Connection
X-Cache-Ttl
X-App
X-Newrelic-Synthetics
X-LiteSpeed-Cache-Control
X-B3-Spanid
X-URL
Section-Io-Origin-Status
Lb
Section-Origin-Responded
Section-Io-Origin-Time-Seconds
Section-Io-Id
Test
X-HA-Backend
X-Fpc
X-LI-Proto
X-Webkit-Csp-Report-Only
X-Vcl-Version
Server-Id
X-Http-Reason
X-Akamai-Request-ID2
X-Traceid
User-Agent
X-Micro-Cache
Fastly-Backend-Name
X-Webkit-CSP-Report-Only
X-NODE
Geo-Info
Tcn
X-Backend-Host
Accept-Language
X-BCube-Filmed-By
X-Release
X-Ec-GeoHdr
X-Ec-Fail
X-Pad
X-Pass-Why
X-User
X-ES-SERVER
X-APP
X-Check-Cacheable
X-Urbn-Site-Id
X-LiteSpeed-Tag
X-Urbn-Context-Path
Cf-Int-Pingora-Origin-Digest
X-HostName
Fastly-Drupal-HTML
Locale
Resin-Trace
X-CSRF-TOKEN
CPC-Age
X-ID
CPC-Cache
X-BBC-Origin-Response-Status
Path
X-ServedByHost
X-Amz-Meta-Cb-Modifiedtime
Cache-Key
EpKe-Alive
X-Ha-Backend
VNS-Age
VNS-Cache
Hostname
Cdnsip
X-Akamai-Pragma-Client-IP
GeoIP-Country-Code
X-Fmm-Version
X-Clara-WADP
X-WA-Info
Hit
Ohc-File-Size
M-TraceId
X-WADP-Cache
X-AK-Request-ID
Srv
Cdncip
X-WA
X-Geo
X-Dynatrace-Js-Agent
X-ElasticPress-Query
My-App
Geoip-Latitude
Shield-Pop
X-Via-PopN
X-Via-PopH
Cluster
X-Cms-Context
X-Cdn-Forward
ENV
X-Wikidot-Backend
X-Via-PopV
X-Wikidot-Static-Cache
MIME-Version
X-Edge-POP
Pagetype
X-PJAX-URL
Load-Balancing
X-Var-Ttl
X-From
Tracecode
X-HS-Status
MD5-Digest
Lfy
X-Edge-Cache
X-CCDN-Origin-Time
X-CCDN-CacheTTL
X-CUA
X-Via-Ucdn
X-Api-Version
X-NGINX-Cache
X-Hcs-Proxy-Type
X-Fastly-Cache-Hits
X-Ucs
X-ServerName
X-VG-WebServer
X-UP
URI
WZWS-RAY
X-Fragments
Servername
X-GoCache-CacheStatus
X-RAMCache
Lang
X-Fastly-Backend-Reqs
T-Server
X-Cache-Expires
Server-Hostname
X-SIPLIST1
Server-Ext
IsBot
X-Mcache
W
Sever-Int
X-Dw-Trace-Id
X-TRACE-ID
X-RateLimit-Reset
Cneonction
X-Lb-Id
Cdn
PICS-Label
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
Target-Params
Cteonnt-Length
X-Provided-By
X-B3-ParentSpanId
X-Nc
X-VC
X-Cdn-Request-ID
Ohc-Cache-HIT
X-Apw-Access-Action
X-Acquia-Application-Trace
X-Yottaa-OS
Cf-Ipcountry
X-Via-CDN
X-Acquia-Application-UUID
CF-Cached-On
X-Acquia-Purge-Tags
X-Akamai-ERPolicy
X-Akamai-ERRuleID
X-Last-Modified
Server-Ttl
X-Apw-Hits
X-Acquia-Site
X-Apw-Access-Object
X-Apw-Access-Token
Dnion-Transfer-Encoding
X-Newrelic-App-Data
X-Platform-Router
X-Platform-Cluster
X-Cc-Via
Vha6-Origin
X-Contensis-Viewer-Groups
X-Snapshot-Date
X-Akamai-Request-ID
X-Platform-Processor
HitType
X-Cache-ASPX
X-Swift-Error
X-Cache-Ngx
X-Air-Pt
Sid
Uri
CountryCode
X-Te-Duration-Ms
X-B3-Parentspanid
X-Miniprofiler-Ids
X-Te-Count
X-CacheKey
FSS-Cache
X-Sentry-ID
X-UA
X-Logging-Id
X-Varnish-Authentication
X-Lb-Nocache
Req-ID
X-Http-Count
X-HTML-Edge-Cache
Ngx
X-Http-Duration-Ms