Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
X-Powered-By
Pragma
X-XSS-Protection
CF-RAY
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
Alt-Svc
P3P
X-Cache-Hits
X-UA-Compatible
X-Xss-Protection
X-Served-By
CF-Ray
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
Access-Control-Allow-Credentials
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
X-Drupal-Cache
X-Cache-Status
X-Generator
X-Check
X-Cacheable
X-Envoy-Upstream-Service-Time
X-FRAME-OPTIONS
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Iinfo
X-Dns-Prefetch-Control
Server-Timing
X-Drupal-Dynamic-Cache
Feature-Policy
X-Content-Security-Policy
Access-Control-Expose-Headers
Content-Encoding
X-CDN
Status
X-XSS-PROTECTION
Upgrade
X-Request-ID
X-AspNetMvc-Version
Access-Control-Max-Age
X-Amz-Request-Id
X-Via
X-Amz-Id-2
Request-Context
X-Ua-Compatible
X-Backend
X-Cache-Group
X-Turbo-Charged-By
X-Robots-Tag
Cf-Edge-Cache
Keep-Alive
Host-Header
X-AH-Environment
X-UA-Device
X-Vhost
X-Hacker
X-Proxy-Cache
X-Server
Allow
X-Rq
X-Server-Powered-By
X-Ws-Request-Id
X-Dispatcher
X-Age
EagleId
X-Varnish-Cache
X-Amz-Version-Id
P3p
Nel
Grace
X-LiteSpeed-Cache
Cf-Apo-Via
Cf-Railgun
X-Page-Speed
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
EagleEye-TraceId
X-Device
X-Swift-CacheTime
X-Swift-SaveTime
X-OneAgent-JS-Injection
X-Aws-Lambda-Call-Status
Ali-Swift-Global-Savetime
X-Pingback
X-Host
Accept-CH
X-Cache-Lookup
X-CST
X-Node
X-WebKit-CSP
X-Backend-Server
Surrogate-Control
Permissions-Policy
Accept-CH-Lifetime
X-Readtime
X-Nginx-Upstream-Cache-Status
X-Nginx-Cache-Status
X-Akam-SW-Version
X-Server-Id
Request-Id
X-Application-Context
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Xkey
X-Cloud-Trace-Context
X-Content-Security-Policy-Report-Only
X-Response-Time
X-Ruxit-JS-Agent
X-HW
X-Trace
X-Edge
Content-Location
X-Clacks-Overhead
X-Mod-Pagespeed
X-Url
Rating
X-ESI
X-Midtier
X-Amz-Server-Side-Encryption
X-ECACHE
Cache-Tag
X-Mcache
X-Country
X-Rack-Cache
X-Powered-By-Plesk
X-MS-InvokeApp
X-D2id
Service-Worker-Allowed
X-Kinja-Revision
X-GoogleNews-Bot
X-Kinja-Build
X-Kinja
X-Exp-Variant
X-Use-Magma
X-Cdn-Fetch
X-Kinja-Server
X-Exp-Id
X-Vcap-Request-Id
Verso
Accept-Ch
X-Upstream
X-Element-Page-Cache
Edge-Control
X-Oneagent-Js-Injection
X-Country-Code
X-Litespeed-Cache
X-Ac
X-Goog-Hash
Origin-Trial
X-PC
RTSS
X-Vname
X-TtlSet
Accept-Ch-Lifetime
X-VARITI-CCR
X-Navigation-Version
X-Kinja-CCPA
X-Abt-Application-Version
X-Cache-TTL
X-Browser-Type
Fastly-Restarts
X-Amz-Rid
X-Varnish-TTL
X-NWS-LOG-UUID
X-GitHub-Request-Id
X-Server-ID
X-Aspnetmvc-Version
Cross-Origin-Opener-Policy
X-Cached
X-Ruxit-Js-Agent
X-Server-Name
X-Webkit-CSP
X-Amzn-Trace-Id
X-Dw-Request-Base-Id
Pagespeed
Display
X-Sol
X-Middleton-Display
X-Times
SPRequestGuid
X-WebKit-CSP-Report-Only
X-SharePointHealthScore
X-Ttl
Pinterest-Version
X-Pinterest-Rid
Pinterest-Generated-By
SPIisLatency
SPRequestDuration
X-Content-Type
X-Server-Lifecycle-Phase
X-Erf-Bev-Bev-Is-Generated
X-Instrumentation
X-Erf-Bev-Bev
X-Kraken-Loop-Name
X-Cache-Key
AR-ATIME
AR-PoweredBy
AR-SID
AR-Request-ID
X-Powered-CMS
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
Arr-Disable-Session-Affinity
X-Mg-S
X-Version
X-Cnection
X-Ser
X-Middleton-Response
Response
Nginx-Cache
X-HP-Trace-Id
X-Jurisdiction
X-HP-Webp
X-B3-Traceid
X-B3-TraceId
X-FastCGI-Cache
X-Accel-Expires
Cache-Tags
X-Client-IP
X-Fastly-Request-ID
X-T
AR-CACHE
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-NF-Request-ID
Cache-Status
Edge-Cache-Tag
X-Hits
X-MSEdge-Ref
X-Px
Public-Key-Pins
Front-End-Https
X-Recruiting
S
X-Shield-Request-Id
X-Daa-Tunnel
Payment
X-LLID
X-Frontend
X-RateLimit-Remaining
X-Ua-Browser
Server-Node
X-Request-Processing-Time
X-Request-Received
X-Goog-Metageneration
X-GUploader-UploadID
X-B3-TraceId-Primal
Mrf-Cache-Status
MRF-Tech
Content-MD5
X-Webkit-CSP-Report-Only
MicrosoftSharePointTeamServices
Access-Control-Request-Method
X-Content-Digest
X-RateLimit-Limit
X-Amz-Apigw-Id
X-Amzn-RequestId
X-DIS-Request-ID
X-Ratelimit-Remaining
X-Forwarded-For
TP-Cache
X-Protected-By
Realpath
X-Request-Handler-Origin-Region
X-Distributor
X-Microsite
X-FB-Debug
X-TTL
X-HS-Content-Id
X-HS-Combine-CSS
X-Fastcgi-Cache
X-Xrds-Location
Fastcgi-Cache
X-HS-Cache-Config
X-HS-Hub-Id
Access-Control-Allow-Method
X-Page-Id
Accept-Charset
X-LB-Cache
X-Rid
X-Cluster-Name
X-PressLabs-Stats
X-Webkit-Csp
X-Goog-Generation
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
Count-Hit
X-Goog-Stored-Content-Length
X-Hostname
X-Id
X-B3-Sampled
X-Edge-Location-Klb
X-Kinsta-Cache
X-Ratelimit-Limit
X-Geo-Country
Cross-Origin-Resource-Policy
X-Aspnet-Version
TP-L2-Cache
X-Ua-Device
X-Correlation-Id
X-Seen-By
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-App-Server
TCN
Cleartype
X-Varnish-Backend
X-Logged-In
X-Ezoic-Cdn
Referer-Policy
X-Git-Hash
X-Hosted-By
X-Erf-Stays-Pdp-Viaduct-Migration-Web
X-Content-Options
X-Mobile
DC
Retry-After
X-Newrelic-App-Data
X-Contextid
X-Origin-Cache
X-Fb-Rlafr
X-Providence-Cookie
X-Request-Guid
X-Is-Crawler
X-Aspnet-Duration-Ms
X-Route-Name
X-Flags
X-Revision
Surrogate-Key
X-Forwarded-Proto
X-F-Cache
X-TT
X-Grace
X-Amz-Replication-Status
X-Debug-Info
X-App-Environment
Frame-Options
X-IPS-LoggedIn
X-Varnish-Grace
X-Amz-Meta-S3cmd-Attrs
X-Envoy-Decorator-Operation
X-Azure-Ref
MS-Author-Via
Section-Io-Cache
X-Magnolia-Registration
X-Proxy-Cache-Info
X-Wix-Request-Id
X-Www-Served-By
X-Whom
X-Client-Ip
X-App-Version
Healthy
X-Activity-Id
X-Az
X-Language
X-AppVersion
Charset
X-Akamai-Edgescape
X-RateLimit-Reset
Filterid
X-COUNTRY
X-Trace-Id
Viewport
Alternate-Protocol
WPO-Cache-Status
Amp-Access-Control-Allow-Source-Origin
WPO-Cache-Message
Server-Name
X-Kong-Upstream-Latency
X-Backend-Name
X-Kong-Proxy-Latency
X-Origin-Server
X-Varnish-Server
X-EdgeConnect-Cache-Status
X-Datadog-Sampling-Priority
Paypal-Debug-Id
X-Datadog-Parent-Id
X-Datadog-Trace-Id
X-B
SRV
X-Response-Served-From
X-Http-Reason
Host
X-Cache-Rule
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-Original-Request-Id
Front
X-Rule
X-DataDome
X-Vcache
X-Edge-Location
X-User-Agent
X-UUID
X-Akamai-Request-ID2
X-Cache-Grace
X-L-Path
X-Region
X-Unique-Id
Country
From-Origin
Protected
X-Page-View
X-ARC
X-Instance
X-Environment-Context
SD-X-WS
X-Cacheable-TTL
X-Jobs
X-N
Content-Disposition
X-Yottaa-Metrics
X-Time
X-Yottaa-Optimizations
X-FW-Server
X-FW-Static
X-FW-Version
X-Is-Bot
X-FW-Serve
Fastly-SWR
X-B-Cache
X-Adobe-Loc
X-Adobe-Content
Fastly-SIE
Akamai-GRN
X-FW-Dynamic
X-Signature
X-FW-Hash
X-Load-Cache
X-FW-Type
X-RemovedCookies
X-Rendered-As
X-Varnish-Age
X-Framework
X-ProcessESI
X-Status
X-Rocket-Nginx-Serving-Static
X-Cache-Time
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-Tumblr-User
X-Datadog-Sampled
X-G
X-Proxy
X-Mg-Request-UUID
X-Type
X-Nf-Request-Id
X-Debug-IsPreview
X-Amzn-Remapped-Content-Length
X-Debug-IsConnected
Access-Control-Request-Headers
ServerID
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
X-CDN-Forward
Backend
X-ECache
X-Cache-Age
Refresh
X-Tec-Api-Version
X-Cache-Control
X-Tec-Api-Origin
X-Nginx-Cache
X-Tec-Api-Root
Xet-Cookie
Countrycode
X-Servername
X-DynaTrace
X-Tt-Trace-Tag
Url
X-Httpd
X-Tt-Trace-Host
X-Erf-Web-Scheduler
Accept-Language
X-Drupal-Cache-Tags
X-Template
CF-IPCountry
X-Mode
X-DynaTrace-JS-Agent
X-Device-Type
X-Content-Powered-By
X-NYM-Debug-Backend
X-Generated-By
X-HTML-Minification-Powered-By
Xserver
X-Cache-Hit
X-Storage
X-Source
GEO-INFO
X-Hcs-Proxy-Type
X-CCDN-CacheTTL
Version
X-CCDN-Origin-Time
Load-Balancing
X-Urbn-Context-Path
X-Say-Cacheable
X-Say-TTL
X-GeoCountry
X-GeoCode
X-FTR-Request-ID
X-SayCDN-TTL
X-ServerID
X-Urbn-Site-Id
Filters
X-Rn-Rsrv
Locale
X-Director
X-Content-Age
S-Rt
X-Loop
X-Cache-Operation
X-JoinUs
X-LAGOON
X-Rewrite-Enabled
X-SaId
X-UPSTREAM-Address
Meta-Geo
X-Tncms
OT-Force-Account-Verify
X-Forwarded-Host
X-Cluster-Node
X-Git-Commit
Onion-Location
X-Soup
X-Tt-Logid
Cross-Origin-Window-Policy
X-Container-Uri
X-Cache-Action
X-Varnish-Cache-Hits
Azure-SiteName
Azure-SlotName
Azure-RegionName
Azure-Version
Web-Mar-Node
X-Adobe-Source
X-Detected-As
Azure-InstanceId
X-Labrador-Cache-Channel
X-NGENIX-Cache
X-VCT
X-VC-Cache
X-Varnish-Hostname
X-Served-From
X-RM-Cache-TTL
X-Skip-Cache
X-Sql-Count
X-Sql-Duration-Ms
X-Tb
X-PHP-Host
X-B3-SpanId
X-Ms-Version
X-Ms-Request-Id
Webserver
X-Lambda-Id
X-URL
X-FB-TRIP-ID
X-Logging-Id
Node
X-R9-Blue-Green-Version
X-Routing-Service
Mn-Server-Ip
X-Zipkin-Id
X-RCS-CacheZone
X-Proxied
X-XRDS-LOCATION
X-Cache-Server
X-Extlb
DB-Nickname
Property-Id
X-Fetched-On
X-Redis-Cache
X-Format
X-Timing-Wait
X-Tumblr-Pixel-2
X-Generation-Time
TWC-Locale-Group
Webcakes-App-Version
X-Debug
X-Uri
Webcakes-Region
X-Proxy-Build
X-Tumblr-Pixel-3
Webcakes-App-Name
TWC-Device-Class
TWC-Connection-Speed
TWC-GeoIP-LatLong
X-Origin-Hint
TWC-Privacy
Selected-Fe
TWC-GeoIP-Country
Fastcgi-Useragent
X-MCACHE
X-Proto
X-Oracle-Dms-Rid
X-Endurance-Cache-Level
X-Oracle-Dms-Ecid
Uber-Trace-Id
Source
X-LSADC-Cache
X-Ratelimit-Reset
X-Zen-Fury
CDN-RequestId
X-Sucuri-ID
X-Sucuri-Cache
X-S
Section-Io-Id
Section-Origin-Responded
X-XRDS-Location
Section-Io-Origin-Time-Seconds
X-Ua
X-Newrelic-Synthetics
Section-Io-Origin-Status
X-Origin-TTL
NGB
X-Origin-CC
X-Drupal-Cache-Contexts
X-TimeS
X-Origin-Date
X-MP-GENERATED-AT
Upgrade-Insecure-Requests
X-Akamai-Transformed
Fastly-Drupal-HTML
X-Real-IP
X-Pass-Why
X-Handled-By
X-Cache-Expired-At
X-Varnish-Hits
X-Srv
X-Optimistic-Header
Ms-Operation-Id
Apigw-Requestid
X-Cms-Context
Liferay-Portal
X-No-Session
X-Xfnlog-Site
MS-CV
X-Reqid
X-RTag
ServedBy
X-CACHE-AGE
X-GEO
X-Cache-Host
X-AB
X-BYPASS-REASON
X-TraceId
X-ProxyCache-Key
X-ProxyCache-Status
X-Restarts
X-Hl-Ver
WP-Super-Cache
X-Tx-Id
CDN-EdgeStorageId
CDN-CachedAt
X-Cache-TTL-Remaining
CDN-RequestPullSuccess
CDN-Uid
CDN-RequestPullCode
CDN-RequestCountryCode
CDN-PullZone
X-Node-Name
X-Cluster
X-VWS-Id
X-LJ-Flow-ID
X-Upgrade-Enabled
X-Cache-Type
CDN-Cache
X-UA-Device-Type
X-CSRF-Token
X-AWS-Id
X-Varnish-Ttl
X-Geo-Region
X-IPLB-Instance
X-Via-JSL
X-Parent-Response-Time
X-IPLB-Request-ID
X-Proxy-Cache-Status
X-Fastly-Request-Id
Cache-Provider
X-Pubstack
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-Application
X-CGP
X-ScT
X-S-Cookie
L
Candidate-Md5Url
L5d-Success-Class
Fastly-SSL
X-Ec-GeoHdr
X-External-Request-Id
X-Fastly-Backend
BehaviorPad-Version
X-B-Cookie
X-App
DCR-Processing-Time-Ms
X-Bc-Bl
X-BCube-Filmed-By
DCR-Decision-By
X-Bl-Debug
X-PAYTM-SRV-ID
Gannett-Cam-Experience-Id
X-Request-Host
HA-Ipaddr
Canary
X-Micro-Cache
Ha-Gx-Prefs
X-CacheTTL
X-Cache-NE
X-FC-Vary-Parameters
X-Cache-Status-Check
X-Eu-Site
X-Rojux
X-Csrf-Jwt
X-Vdms-Version
X-Destination
X-A-Dam
X-A-Ccd
X-Viewer-Country
X-Developer
X-Vdms-Path
X-Conf
Redirect-Candidate
X-A-Wwc
Rendered-Blocks
X-A-Dgt
X-A-Dcw
X-A
Web-Mar-Region
W
Xc-Version
True-Client-Country-4JS
Vix-Hermes-Req-Id
X-Ec-Fail
X-Ec-Custom-Error
T-Server
Surrogated-Key
X-Dispatcher-Number
X-Vtex-Remote-Cache
X-We-Are-Hiring
Sslversion
X-Worker
X-Debug-Cache-Store
Server-Host
Odigeo-Trace-Id
Origin-Agent-Cluster
Magicmarker
X-SRCache-Key
X-Epic-Correlation-Id
X-Slack-Backend
X-Aed
Ngx.Var.Host
X-Slack-Shared-Secret-Outcome
MD5-Digest
X-Debug-Cache-Fetch
N-Cache
Meta-Geo-Continent
Lang
X-D
Cache-Name
X-Server-W
X-Alternate-Cache-Key
TDXMobile
CloudFront-Viewer-Country
Datacenter
CPC-Cache
X-Irp-Debug
X-App-Name
X-Forwarded-Path
Cmstype
Cmsid
VNS-Cache
X-Geo-Header
X-Mvc-Supplant-Cachable
Thinkindot-CacheControl-Type
Thinkindot-Control
Mail-Subject
CPC-Age
Thinkindot-CacheControl
Fastly-Backend-Name
X-Hash
Release
X-Accel-Expires-Debug
Req-Svc-Chain
Producers
Platform
X-Accel-Buffering
Gh-Request-Id
X-Mid
X-Mly-Id
X-Human
Origin
Expect-Staple
X-ApacheServer
We-Hiring
X-GeoIP-Country-Code
Is-Eu
Fastly-GeoIP-CountryCode
X-Gdpr
Host-ID
X-Loc
X-GeoIP-Region-Code
Environment
X-Request-Time
X-Var-Ttl
X-DefElseHash
X-Up
X-Variation
X-Varnish-CookieHashed-On
X-Varnish-Remaining-TTL
X-Varnish-CookieINHashed-On
X-DefHash
X-Thinkindot-L3
X-Date
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Shopify-Stage
X-Storefront-Renderer-Rendered
X-SVT-ORM-RULES
X-Tenant
X-SVT-ORM-VERSION
X-Varnishpool
X-VG-TLSProxy
X-Level-Front-Cache
X-Generated-On
X-Bip
X-Owner
X-Pool
X-Thanos
X-Qloud-Router
X-DPWN-IS-SECURE
X-Dispatcher-Server
X-VServer
X-Vmg-Version
X-VG-WebCache
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-AIR-PT
X-Wix-Viewer-Type
X-ShopId
X-Sn-Servicetimems
X-Origin-Time
X-Cache-Debug
X-Orig-Expires
X-PERF
X-Platform
X-Refresh
X-Policy
X-Cache-Bucket
X-Old-Content-Length
X-BBC-Edge-Cache-Status
X-Nitro-Cache
X-Nananana
AKAMAI
Adler-Geo
X-Nyt-Route
X-NodeID
VNS-Age
X-Cache-Info
X-Core-Mission
X-SD-PageType
X-CMSURLCustom
X-Cdn-Diag
X-Server-IP
X-Clientip
X-Core-Value
X-Cdn-Origin
X-Shop-Environment
X-ShardId
User-Cache-Control
X-Presslabs-Stats
X-TIME
X-Forwarded-Site
X-Fmm-Version
X-From
X-Auto-Login
X-Clara-WADP
X-Device-Os
X-Block-Status
X-Esi-Check
X-Cache-Id
X-Origin
Apple-News-Services-Parsed-Url
X-Nginx-Cache-Key
Apple-News-Services-Host
Apple-News-Services-Handled
X-Node-Id
X-NCache
CDCHOST
DSUID
Country-Code
Cf-Device-Type
X-Mvc-Supplant-OutputCached
X-Gen-Mode
X-Op-Id-All
X-WA-Info
X-Vgn-Hpd-Reason
X-Test
X-Correlation-ID
X-WADP-Cache
X-S-Maxage
X-Org
X-Origin-Response-Time
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
Esi-Enabled
Apple-News-Services-Request-Url
X-Hnp-Log
Server-Ext
Server-Hostname
X-INCAP-ABP
X-Gzip
Machine
X-GeoIP
Sever-Int
NM-Fastcgi-Cache
X-Is-Tablet
X-Tcp-Rtt
X-Is-Supported-Browser
X-Accel-Version
X-Is-Desktop
X-Is-Mobile
X-Browser-Name
Wxu-Next-Hostname
Wxu-Next-Commit
X-Section
X-Cdn-Srv
Server-Info
Wxu-Next-Region
X-Cache-Enabled
C-Via
NGX
X-Instance-Name
X-LB-NoCache
X-Datadome
X-Access
X-Ah-Environment
X-Via-Fastly
Pics-Label
Ssr
X-B3-Spanid
X-Buckets
X-Varnish-Beresp-Grace
X-Akamai-Device-Characteristics
Content-Secure-Policy
X-Varnish-Beresp-Ttl
Server-ID
X-Amz-Meta-Cb-Modifiedtime
AMP-Access-Control-Allow-Source-Origin
X-Vcl-Version
X-API-Version
IsBot
X-HA-Backend
X-Zone
X-Dc
X-SIPLIST1
X-CACHE-GROUP
X-Origin-Cache-Key
YJS-ID
X-B3-Parentspanid
X-WP-CF-Super-Cache-Active
X-JWT-State
X-Platform-Cluster
X-Is-Gdpr
X-Platform-Router
Memcached
X-Has-Esi
X-Platform-Processor
X-Cached-By
CF-Ctrl
X-ID
Memory
Cdn-Requestid
Location
X-Frame-Option
Hostname
Time
X-Tb-Optimization-Total-Bytes-Saved
X-Wp-Cf-Super-Cache-Active
Sid
X-TA-CDN-Provider
X-Air-Hostname
X-Internal-Host
X-Air-Source
Cache-Hits
X-Air-Trace-Id
X-Fpc
Origin-CC
X-Scale
X-Hyper-Cache
Origin-EX
X-FTR-Cache-Status
X-FTR-Expires
X-FTR-Balancer
X-FTR-Backend-Server
X-FTR-Backend
X-Backend-Instance
X-TIM-N
X-Country-Code-Real
X-DC
X-Webstats-RespID
X-ZONE
X-PHP-Backend
X-Cs
X-SRV
X-DataCenter
X-VC
X-LiteSpeed-Cache-Control
X-Service
Resin-Trace
LB
X-NewRelic-App-Data
Epwk-X-Cache
X-Azure-Ref-OriginShield
Uri
X-Site-Version
True-Client-Ip
WebServer
GeoIP-Country-Code
X-Locale
X-NGINX-Cache
X-Microcachable
GeoIP-Latitude
X-NODE
GeoIp-Country-Code
X-NMSegId
Req-ID
X-Edge-Server
WZWS-RAY
X-Nitro-Rev
Cache-Host
X-Origin-Expires
Cdn-Host
Cdn-Request-Time
X-Nitro-Cache-From
X-VCache
SID
Cdn
X-Info
XServer
X-Cache-Ttl
X-Ad-Load-Variation
XM
X-CSRF-TOKEN
X-Request-URI
X-Vercel-Id
X-Vercel-Cache
X-Scope-Id
True-Client-IP
X-VarnishDD-TTL
X-Request-Start
X-Pad
M-TraceId
X-Pod-Name
NtCoent-Length
X-M-Reqid
PFcat
X-M-Log
X-HN
Pramga
X-Datacenter
X-Web-Node
X-Geo
HostName
X-Qnm-Cache
X-Ad-Defer-Variation
X-Varnish-Beresp-Status
X-Shield-Cache-Expires
Content-Style-Type
Content-Script-Type
X-WP-CF-Super-Cache-Cookies-Bypass
User-Agent
X-Github-Request-Id
Cluster
Locid
X-MSEdge-Features
X-Via-SSL
X-Cache-Date
Srvid
Fastly-Drupal-Html
X-CS
X-Via-Edge
X-Via-CDN
X-MSEdge-Flight
Edge-Copy-Time
X-FL-QIT-DEBUG
X-FL-EDGE
Cache-Tv-Group
X-FPC
A
Tcn
X-HostName
Edge-Cache
X-TH-Server
Cf-Ipcountry
X-Cdn-Request-ID
X-Api-Version
X-APP-VERSION
CountryCode
X-AK-Request-ID
X-NWS-UUID-VERIFY
X-Contensis-Viewer-Groups
X-Amz-Meta-Opti
Cdncip
Cdnsip
Tube-Return
X-Nc
X-ATG-Version
X-VCL-Version
X-LB-ID
X-B3-Trace-ID
X-Cache-FS-Status
X-Servedbyhost
X-V-Cache
X-Via-Popv
X-Wa
X-FireWall-Port
X-Via-Popn
X-Via-Poph
X-Esi
X-Aicache-OS
X-Cache-ASPX
X-Moov-Xdn-Version
X-Varnish-Authentication
X-Moov-T
Tube-Get-Contents
Click-Count-Action-Start
Path
Click-Count-Error
X-Webkit-Csp-Report-Only
Tube-Got-Eval
X-Acquia-Purge-Cdn-Unconfigured
Tube-Got-Results
X-LiteSpeed-Tag
MIME-Version
X-Vary
X-UA
X-Men
Cache-Key
On-Server
X-Req
V-Age
X-SB
X-Branch-Name
X-Wp-Cf-Super-Cache-Cookies-Bypass
Priority
X-Proxy-CacheRZ
XkeyRZ
Yak-Timeinfo
Ngx-Var-Key
X-TRACE-ID
X-CACHE-KEY
CDN
X-Tim-N
My-App
X-Render-Time
Geoip-Latitude
Wpo-Cache-Status
X-Acquia-Purge-Tags
X-Acquia-Application-UUID
X-Acquia-Application-Trace
X-Wp-Cf-Super-Cache
X-Wp-Cf-Super-Cache-Cache-Control
X-Acquia-Site
Srv
Wpo-Cache-Message
Proxy-Connection
X-Akamai-Pragma-Client-IP
X-Cdn-Forward
X-Rebelmouse-Cache-Control
X-Lb-Cache
X-Rebelmouse-Surrogate-Control
X-Fastly-Backend-Reqs
X-Planisys-CDN-TTL
X-Provided-By
X-HS-Content-Campaign-Id
X-Fastly-Country-Code
X-Varnish-Director
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
Lb
X-Platform-Server
State
X-Air-Pt
X-User
X-Ha-Backend
X-Generated-In
Server-Id
X-TT-LOGID
X-Lb-Nocache
X-Fastly-Cache
Fusion-Template-Id
CF-Cached-On
X-Cdn-Cache-Status
Ohc-File-Size
X-Release
Ohc-Cache-HIT
X-EC-Lua
X-Vgn-Hpd-Cached
Type
Fusion-Component-Id
X-CUA
Fusion-Content-Id
Fusion-Content-Source
Fusion-Source
Fusion-Deployment-Id
X-Vgn-Hpd-Ssi
X-Dw-Trace-Id
X-Via-Ucdn
X-Vgn-Hpd-Variations-Key
PICS-Label
Yjs-Id
X-Upstream-Ct
X-Iplb-Instance
X-Upstream-Ht
X-Iplb-Request-Id
X-RAMCache
CACHE-MISS-TO-ORIGIN
Warning
Log-Origin
Ngx
X-Cached-Since
X-CF-Cache-Header-Cache-Control
X-CF-Cache-Header-Vary
Vha6-Origin
Cache
X-Fastly-Cache-Hits
X-Snapshot-Date
Inserted-Into-Cache-At
X-ElasticPress-Query
X-Udemy-Cache-App-Namespace
Cneonction
X-Cache-Remote
X-Rocket-Build-Number
X-Sigma
X-Sigma-Backend
X-HS-Status
X-Traceid
X-Litespeed-Cache-Control
X-Miniprofiler-Ids