Threat Level: green Handler on Duty: Rick Wanner

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
Link
CF-Cache-Status
Accept-Ranges
CF-RAY
ETag
Expect-CT
Pragma
X-Powered-By
X-XSS-Protection
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-UA-Compatible
X-Cache-Hits
Alt-Svc
P3P
X-Served-By
X-Xss-Protection
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Cache-Status
X-Generator
X-Cacheable
Timing-Allow-Origin
X-Request-ID
X-Content-Security-Policy
P3p
X-Iinfo
Status
Feature-Policy
X-Envoy-Upstream-Service-Time
Content-Encoding
Access-Control-Expose-Headers
X-CDN
X-Drupal-Dynamic-Cache
X-AspNetMvc-Version
Upgrade
X-Via
CF-Ray
Access-Control-Max-Age
X-Ws-Request-Id
Server-Timing
EagleId
Keep-Alive
X-Cache-Group
X-Turbo-Charged-By
Request-Context
X-Age
X-Proxy-Cache
X-Server-Powered-By
X-AH-Environment
X-UA-Device
X-Backend
X-Hacker
X-Robots-Tag
Report-To
X-Amz-Request-Id
Host-Header
X-LiteSpeed-Cache
X-Server
X-Amz-Id-2
Grace
X-Rq
X-Nginx-Cache-Status
X-Varnish-Cache
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-WebKit-CSP
X-Dns-Prefetch-Control
X-Page-Speed
X-Vhost
X-OneAgent-JS-Injection
X-Amz-Version-Id
EagleEye-TraceId
X-Device
X-Pingback
X-Dispatcher
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Cache-Spec
NEL
X-Server-Id
X-Host
X-Backend-Server
X-Node
Cf-Railgun
Accept-CH
X-Readtime
X-Akam-SW-Version
Surrogate-Control
Request-Id
X-Response-Time
X-HW
X-Language
Xkey
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Application-Context
Content-Location
X-Template
X-Ruxit-JS-Agent
Rating
X-Country
X-Ua-Compatible
Accept-Ch-Lifetime
X-B3-TraceId
Accept-CH-Lifetime
X-Cloud-Trace-Context
X-Cache-Lookup
X-Ac
X-Url
Allow
X-Content-Type
X-Trace
X-Buckets
X-PC
X-TtlSet
X-Vname
X-Mod-Pagespeed
X-Varnish-TTL
X-Clacks-Overhead
Edge-Control
X-FastCGI-Cache
X-ESI
Cache-Tag
Fastly-Restarts
X-Rack-Cache
Service-Worker-Allowed
X-Server-Name
X-VARITI-CCR
X-Element-Page-Cache
Verso
X-GitHub-Request-Id
X-MS-InvokeApp
X-Upstream
X-Amz-Rid
MS-Author-Via
X-Vcap-Request-Id
X-Dw-Request-Base-Id
Public-Key-Pins
X-D2id
X-Client-IP
X-Cached
X-Abt-Application-Version
X-Origin-Cache
X-Cache-TTL
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
Arr-Disable-Session-Affinity
X-Cnection
X-Px
X-Country-Code
X-Powered-By-Plesk
X-Goog-Hash
X-Navigation-Version
Access-Control-Request-Method
X-Instrumentation
X-Aws-Lambda-Call-Status
X-Kraken-Loop-Name
X-NF-Request-ID
X-Server-Lifecycle-Phase
X-Version
Accept-Ch
RTSS
X-Amz-Server-Side-Encryption
X-Powered-CMS
Display
X-Sol
X-Middleton-Display
Pagespeed
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Middleton-Response
Response
X-Kinja-Server
X-Use-Magma
X-Kinja-Build
X-Kinja-Revision
X-Exp-Variant
X-Cdn-Fetch
X-GoogleNews-Bot
X-Kinja
X-Exp-Id
X-MSEdge-Ref
X-LLID
X-Edge
X-Kinsta-Cache
X-Edge-Location-Klb
X-CST
Nginx-Cache
X-Shield-Request-Id
MRF-Tech
X-TTL
Mrf-Cache-Status
X-B3-TraceId-Primal
AR-ATIME
AR-CACHE
S
AR-SID
AR-Request-ID
AR-PoweredBy
X-HP-Webp
Content-MD5
X-Jurisdiction
X-HP-Trace-Id
X-T
X-RateLimit-Remaining
X-Protected-By
X-Forwarded-For
TCN
X-Content-Security-Policy-Report-Only
X-Id
X-Mg-S
X-Mid
Fastcgi-Cache
X-MCACHE
X-Aspnetmvc-Version
Realpath
Front-End-Https
X-Parallel-Accel
SPRequestDuration
Edge-Cache-Tag
SPIisLatency
X-Recruiting
X-Request-Processing-Time
X-Request-Received
Filters
X-Ttl
Pinterest-Generated-By
X-Pinterest-Rid
Pinterest-Version
Fusion-Content-Source
Fusion-Deployment-Id
Fusion-Template-Id
Fusion-Content-Id
Fusion-Source
Fusion-Component-Id
Server-Node
X-Ab
X-Content
X-Ua-Browser
X-DynaTrace
X-SharePointHealthScore
SPRequestGuid
X-Correlation-Id
X-Ezoic-Cdn
X-Ruxit-Js-Agent
Alternate-Protocol
Server-Name
X-Accel-Expires
X-NWS-LOG-UUID
X-ECACHE
X-Frontend
X-HS-Combine-CSS
X-HS-Cache-Config
X-HS-Content-Id
X-HS-Hub-Id
X-Yandex-Sdch-Disable
X-Hits
X-Cache-Key
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Content-Options
Cache-Tags
Host
X-Page-Id
MicrosoftSharePointTeamServices
X-Git-Hash
Cleartype
Charset
X-Www-Served-By
X-B3-Sampled
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Geo-Country
X-Content-Digest
X-Ser
X-Amz-Replication-Status
TP-L2-Cache
TP-Cache
Filterid
X-Forwarded-Proto
X-VCache
X-Hostname
X-Fastly-Request-Id
X-Varnish-Age
X-Amzn-Trace-Id
X-Activity-Id
X-AppVersion
X-Az
X-XRDS-LOCATION
X-Daa-Tunnel
X-DIS-Request-ID
X-Rid
X-Debug-Info
X-Upgrade-Enabled
X-Origin-Server
X-Grace
Access-Control-Allow-Method
X-N
X-Microsite
X-Request-Handler-Origin-Region
X-LB-Cache
X-Origin-Upstream-Status
X-FB-Debug
X-WebKit-CSP-Report-Only
X-Nginx-Upstream-Cache-Status
ServerID
X-Mobile-URL
X-Flags
X-Route-Name
X-Is-Crawler
X-Request-Guid
X-TT
X-Aspnet-Duration-Ms
X-Whom
X-Providence-Cookie
X-Goog-Metageneration
X-Goog-Generation
X-F-Cache
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-NGENIX-Cache
X-App-Environment
X-App-Server
X-Varnish-Grace
Cross-Origin-Opener-Policy
Viewport
Payment
X-Tb
X-Distributor
X-FW-Hash
DC
X-FW-Serve
X-FW-Static
X-FW-Type
Node
Paypal-Debug-Id
X-FW-Dynamic
X-Server-ID
X-FW-Server
X-Cache-Control
X-Logged-In
Fastcgi-Useragent
X-Seen-By
X-Type
X-PressLabs-Stats
X-User-Agent
X-Cache-Age
Country
Accept-Charset
X-Cache-Rule
X-Varnish-Backend
X-Erf-Bev-Bev-Is-Generated
X-Node-Name
X-Fastly-Request-ID
X-Erf-Bev-Bev
X-Webkit-CSP
X-DataDome
X-Browser-Type
X-Wix-Request-Id
X-Load-Cache
Version
X-Cache-Action
X-IPLB-Instance
X-Via-JSL
Refresh
Access-Control-Request-Headers
X-Original-Request-Id
SD-X-WS
X-Response-Served-From
Cache-Status
Referer-Policy
X-Cacheable-TTL
X-Drupal-Cache-Tags
X-TEC-API-VERSION
X-Jobs
X-TEC-API-ORIGIN
Amp-Access-Control-Allow-Source-Origin
X-Ratelimit-Limit
X-Real-IP
X-TEC-API-ROOT
X-RemovedCookies
X-ProcessESI
X-Debug
X-Contextid
VIX-Pulpo-Upstream-Status
X-Is-Bot
X-B
X-Rendered-As
X-Proxy-Cache-Status
VIX-Pulpo-Node
X-Revision
NGB
X-Vgn-Hpd-Reason
X-UUID
X-Cluster-Name
X-Page-View
DynaTrace
X-Device-Type
X-Drupal-Cache-Contexts
X-Mobile
X-Cache-Expired-At
X-Rule
Liferay-Portal
X-Yottaa-Metrics
X-Proxy
X-Signature
X-B-Cache
X-Yottaa-Optimizations
X-G
Surrogate-Key
X-Framework
X-Instance
X-Cache-Time
Akamai-GRN
X-Tec-Api-Origin
X-Debug-IsPreview
X-Tec-Api-Root
X-Debug-IsConnected
X-Tec-Api-Version
X-Fastcgi-Cache
Healthy
X-Azure-Ref
X-FW-Version
CF-IPCountry
SID
X-Source
X-Air-Trace-Id
X-Air-Source
X-Air-Hostname
X-Ms-Version
X-Ms-Request-Id
Frame-Options
X-Oracle-Dms-Ecid
X-XRDS-Location
X-Oracle-Dms-Rid
Ms-Operation-Id
X-RTag
X-Cache-Hit
MS-CV
X-APP-VERSION
Section-Io-Cache
X-Nginx-Cache
X-CDN-Forward
X-Tumblr-User
X-Oneagent-Js-Injection
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Environment-Context
Xserver
X-L-Path
X-Varnish-Server
Count-Hit
Countrycode
X-Cache-Operation
X-Region
GEO-INFO
X-Servername
X-RateLimit-Limit
X-Content-Powered-By
Uber-Trace-Id
X-EdgeConnect-Cache-Status
X-Forwarded-Host
X-Backend-Name
X-Mode
X-IPS-LoggedIn
Cross-Origin-Window-Policy
Backend
X-Accel-Buffering
X-Litespeed-Cache
X-Adobe-Loc
X-Adobe-Content
X-Zen-Fury
Ec-Rule-Version
X-UPSTREAM-Address
Meta-Geo
X-JoinUs
X-SaId
X-RN-RSRV
X-Sorting-Hat-ShopId
X-Microcachable
X-Detected-As
X-Redis-Cache
X-Sorting-Hat-PodId
X-Hosted-By
X-Alternate-Cache-Key
X-Cache-Server
X-Shopify-Stage
X-Cache-Grace
X-Generation-Time
X-Human
X-ShopId
X-ShardId
Eomportal-Instance
X-Debug-Cache
X-Cache-Type
X-Varnish-Beresp-Grace
X-PHP-Backend
X-Origin-Date
X-Storage
X-No-Session
Country-Code
Decoy-Debug-TTL
X-BYPASS-REASON
X-FB-TRIP-ID
X-ServerID
Url
Apigw-Requestid
X-Cache-TTL-Remaining
Cache-Name
Cache-Tv-Group
X-Uri
X-ProxyCache-Key
Decoy-Debug-Key
Decoy-Debug-Status
X-ProxyCache-Status
X-NCache
X-Site-Version
X-Status
X-Sql-Count
X-Via-Fastly
X-Sql-Duration-Ms
TWC-Privacy
TWC-Locale-Group
TWC-Connection-Speed
Selected-Fe
Protected
Property-Id
Fastly-SSL
Webcakes-App-Name
TWC-Device-Class
Mn-Server-Ip
TWC-GeoIP-Country
X-Web-Node
TWC-GeoIP-LatLong
X-Origin-Hint
X-PCL
X-Say-Cacheable
X-Format
X-Say-TTL
X-SayCDN-TTL
X-Proxy-Build
X-Cache-Host
X-Ratelimit-Reset
X-UA-Device-Type
X-OCL
Webcakes-Region
Webcakes-App-Version
X-Akamai-Edgescape
X-Timing-Wait
Azure-RegionName
Azure-InstanceId
Azure-SiteName
Azure-Version
OT-Force-Account-Verify
X-Pubstack
X-Routing-Service
Azure-SlotName
X-Section
X-ApacheServer
X-Extlb
X-R9-Blue-Green-Version
X-NYM-Debug-Backend
X-Access
X-Zipkin-Id
X-PERF
X-Azure-Ref-OriginShield
X-Varnishpool
X-Hl-Ver
X-Server-W
X-Proxied
DB-Nickname
X-LSADC-Cache
X-Be
Source
X-Cluster-Node
X-Rewrite-Enabled
Content-Secure-Policy
X-Tid
X-Soup
X-Cache-NGX
X-SRV
X-Ua
X-HTML-Minification-Powered-By
X-Time
X-Content-Age
X-Cached-By
X-Cache-Var
Content-Disposition
X-Amz-Meta-S3cmd-Attrs
X-NewRelic-App-Data
X-Cache-Var-Map
X-Webkit-Csp
X-Presslabs-Stats
SRV
CDN-Cache
X-Unique-Id
Cache
CDN-CachedAt
CDN-RequestCountryCode
CDN-RequestId
X-LAGOON
CDN-Uid
X-Generated-By
CDN-PullZone
CDN-EdgeStorageId
X-Hyper-Cache
X-Varnish-Hits
X-Loop
X-Varnish-Hostname
Webserver
X-Bc-Bl
X-TNCMS
X-TT-LOGID
X-App-Version
Onion-Location
X-Dc
X-S-Maxage
Retry-After
X-Auto-Login
X-Origin-CC
X-Origin-TTL
X-Tumblr-Pixel-2
X-Tumblr-Pixel-3
X-Trace-Id
X-GEO
Cache-Hits
X-ECache
X-Proto
X-Nginx-Cache-Key
Web-Mar-Node
Xet-Cookie
X-Time-Microsecs
X-Qnm-Cache
X-M-Reqid
X-M-Log
X-Endurance-Cache-Level
X-Tenant
X-Edge-Location
X-Cdn
X-Akamai-Transformed
X-GG-Cache-Date
X-VWS-Id
LB
X-LJ-Flow-ID
X-Platform-Server
Mime-Version
X-AWS-Id
CloudFront-Viewer-Country
X-Mg-Request-UUID
X-CSRF-Token
X-PHP-Host
X-Amzn-RequestId
X-CACHE-KEY
X-Amz-Apigw-Id
X-Labrador-Cache-Channel
N-Cache
X-Xfnlog-Site
HostName
X-Cache-Tags
X-B3-SpanId
X-Handled-By
X-Varnish-Cache-Hits
X-Locale
X-Storefront-Renderer-Rendered
X-RCS-CacheZone
Upgrade-Insecure-Requests
ServedBy
X-Origin-Response-Time
X-Request-Time
X-Adobe-Source
X-TIME
WPO-Cache-Status
WPO-Cache-Message
X-VC-Cache
X-AOL-HN
X-Cache-Remote
X-Connection-Hash
X-Conf
X-S
X-Rojux
X-D
X-Planisys-CDN-TTL
X-Processor
X-Via-NSCOPI
X-S-Cookie
X-Request-Host
X-ScT
X-CF-Lambda-Fn
X-Session-Fingerprint
X-Shop-Environment
X-Ckpd-Fst-Backend
Mobile-Detection-Method
Meta-Geo-Continent
X-SD-PageType
X-Planisys-CDN-Rules
X-Cluster
X-PAYTM-SRV-ID
X-Ig-Push-State
X-Reqid
X-External-Request-Id
DCR-Decision-By
X-Forwarded-Path
Nel
BehaviorPad-Version
X-Ftr-Request-Id
A
DCR-Processing-Time-Ms
DSUID
X-Developer
X-Destination
X-PBS-Appsvrname
Fastcgi-X-Cache-Version
X-Orig-Expires
X-NAPM-TraceId
X-ND-Cache
Expiry
X-Planisys-CDN-Cache
X-CF-Lambda-Version
X-Cache-NE
Xc-Version
State
X-Vtex-Processado-Em
X-ARC
Rendered-Blocks
X-VG-WebCache
X-B-Cookie
Surrogated-Key
X-Application
X-A-Ccd
X-ATG-Version
X-A
X-A-Dam
X-A-Dcw
X-Aed
X-A-Wwc
X-A-Dgt
X-Vdms-Version
X-Vtex-Remote-Cache
X-TIM-N
Pramga
X-V-Cache
X-Cache-Date
X-SVT-ORM-RULES
X-Slack-Backend
X-SVT-ORM-VERSION
Odigeo-Trace-Id
Redirect-Candidate
X-SRCache-Key
X-Vdms-Path
Origin
Server-Info
Environment
X-MP-GENERATED-AT
Datacenter
X-Correlation-ID
X-Fetched-On
V-Age
Vix-Hermes-Req-Id
X-Forwarded-Site
Wxu-Next-Commit
X-Gdpr
Wxu-Next-Hostname
Wxu-Next-Region
Cmsid
CacheControlHeader
X-Epic-Correlation-Id
L
Release
X-Date
Gh-Request-Id
X-Core-Mission
X-Cache-Bucket
Fastcgi-Cache-TTL
X-Geo-Header
X-Cache-Info
Host-ID
X-Accel-Expires-Debug
X-Device-Os
Cmstype
X-Li-Pop
X-Rocket-Nginx-Serving-Static
X-Scheme
X-Server-IP
X-Skip-Cache
X-Proxy-Upstream
X-Policy
X-Origin-Expires
X-Origin-Time
X-Owner
X-Sucuri-Cache
X-Sucuri-ID
From-Origin
X-Fastly-Cache
X-Gen-Mode
X-Hnp-Log
X-Block-Status
User-Cache-Control
X-Varnish-Beresp-Status
X-VG-TLSProxy
X-VServer
X-Old-Content-Length
X-Served-From
X-Hash
X-Location
X-Li-Fabric
X-Nyt-Route
X-Men
X-LI-UUID
AKAMAI
X-Mvc-Supplant-Cachable
AMP-Access-Control-Allow-Source-Origin
X-GeoIP
X-HN
Arc-Country
CDCHOST
X-Viewer-Country
X-TH-Server
X-HS-Content-Campaign-Id
X-Branch-Name
X-Bip
Origin-CC
X-Aicache-OS
X-Core-Value
X-Gamma-Serve
X-BBC-Edge-Cache-Status
X-Gzip
X-VarnishDD-TTL
Traceparent
Origin-EX
X-GeoIP-City
Req-Svc-Chain
X-Cache-Debug
X-Thanos
X-Region-Sid
X-Req
X-Request-Start
X-Rocket-Build-Number
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
X-Developers
X-NodeID
X-Platform
X-Datadog-Trace-Id
X-Generated-On
X-Esi-Check
X-Cache-Id
X-Cache-Config
X-Thinkindot-L3
X-TrackingId
X-Fastly-Backend
X-Sn-Servicetimems
X-Cdn-Origin
X-Sigma
X-Sigma-Backend
Web-Mar-Region
X-Irp-Debug
X-Level-Front-Cache
X-Ratelimit-Remaining
Machine
PFcat
Server-Host
X-Magnolia-Registration
Locid
Fastly-GeoIP-CountryCode
Apple-News-Services-Host
Apple-News-Services-Handled
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
Candidate-Md5Url
Svr
Mail-Subject
TDXMobile
Thinkindot-Control
Thinkindot-CacheControl-Type
We-Hiring
Thinkindot-CacheControl
True-Client-Country-4JS
X-DefHash
X-NU-AKA-ACS-Version
X-DPWN-IS-SECURE
X-Eu-Site
X-DefElseHash
X-Origin
Ha-Gx-Prefs
X-Rebelmouse-Cache-Control
X-Amzn-Remapped-Content-Length
X-Rebelmouse-Surrogate-Control
HA-Ipaddr
Cf-Device-Type
X-EC-Lua
Fastly-SIE
Adler-Geo
X-Is-Gdpr
X-Has-Esi
X-JWT-State
Fastly-SWR
Is-Eu
X-FC-Vary-Parameters
NGX
X-Loc
X-Webstats-RespID
X-Worker
X-Csrf-Jwt
X-Envoy-Decorator-Operation
Platform
X-Request-URI
NM-Fastcgi-Cache
L5d-Success-Class
X-Zone
X-Backend-State
X-Varnish-Remaining-TTL
X-Varnish-CookieINHashed-On
X-Varnish-CookieHashed-On
X-Variation
X-UnsetCookies
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
Memcached
X-Qloud-Router
X-Pod-Name
X-CGP
Fastly-Drupal-Html
X-Xrds-Location
X-CS
X-FireWall-Port
X-Tx-Id
Sslversion
X-Node-Id
X-Cdn-Srv
WWW-Authenticate
CDN
X-Varnish-Beresp-Ttl
On-Server
X-Mvc-Supplant-OutputCached
Ssr
X-CLOUD-TRACE-CONTEXT
X-NC
X-Up
X-Response-By
Esi-Enabled
X-API-Version
X-LB-ID
X-Generated-In
Pics-Label
X-Vc
WP-Super-Cache
Memory
Ms-Author-Via
X-Trace-ID
Time
X-Service
X-Refresh
C-Via
X-Datadome
X-Backend-TTL
X-LB-NoCache
X-Cache-PHP
X-Via-Popn
X-Tt-Logid
X-Edge-Pop
X-Via-Popv
NtCoent-Length
X-Via-Poph
X-Cache-Enabled
X-DynaTrace-JS-Agent
X-TA-CDN-Provider
X-GeoIP-Region-Code
X-DC
X-Tb-Optimization-Total-Bytes-Saved
X-GeoIP-Country-Code
GeoIp-Country-Code
Env
X-Dynatrace
X-Varnish-Ttl
X-NWS-UUID-VERIFY
Magicmarker
X-TraceId
X-Cache-Status-Check
X-Optimistic-Header
X-Parent-Response-Time
X-Render-Time
X-Varnish-Beresp-TTL
X-Info
X-CacheTTL
X-Esi
Kp-EeAlive
X-Servedbyhost
X-Ua-Device
X-Restarts
X-ZONE
X-AIR-PT
X-TX-ID
X-Unique-ID
S-Rt
Server-ID
X-Cs
X-Wix-Viewer-Type
Edge-Cache
X-RSL
X-Action
X-RPM
X-RPS
X-DSS
X-MSEdge-Flight
X-Clientip
X-DI
X-MSEdge-Features
X-Srv
X-DW
X-Cache-Backend
X-DB
X-Oss-Request-Id
WebServer
X-Oss-Object-Type
HIT
X-Oss-Server-Time
X-VCL-Version
X-Oss-Hash-Crc64ecma
Cache-Host
X-Oss-Storage-Class
UCS
X-Fpc
X-LI-Proto
X-Newrelic-Synthetics
S-Cnection
X-Li-Proto
X-HA-Backend
Proxy-Connection
X-Minions-Version
X-Cache-Ttl
X-Traceid
X-App
X-URL
X-LiteSpeed-Cache-Control
Lb
Section-Io-Origin-Time-Seconds
Section-Io-Id
Section-Origin-Responded
Section-Io-Origin-Status
Test
X-Webkit-Csp-Report-Only
X-FPC
X-Http-Reason
X-Akamai-Request-ID2
X-B3-Spanid
Fastly-Backend-Name
X-Micro-Cache
User-Agent
Server-Id
X-Vcl-Version
X-NODE
X-Webkit-CSP-Report-Only
Tcn
Geo-Info
X-Backend-Host
Accept-Language
X-BCube-Filmed-By
X-Release
X-Ec-Fail
X-Ec-GeoHdr
X-Pad
X-Pass-Why
X-User
X-CSRF-TOKEN
X-ES-SERVER
X-LiteSpeed-Tag
X-Urbn-Context-Path
X-Check-Cacheable
X-HostName
X-APP
Fastly-Drupal-HTML
Hostname
Cf-Int-Pingora-Origin-Digest
Locale
X-Urbn-Site-Id
Resin-Trace
X-BBC-Origin-Response-Status
X-ID
Cache-Key
X-ServedByHost
X-Amz-Meta-Cb-Modifiedtime
VNS-Age
VNS-Cache
Path
CPC-Age
CPC-Cache
EpKe-Alive
X-Dynatrace-Js-Agent
X-B3-Traceid
X-Fmm-Version
X-WADP-Cache
GeoIP-Country-Code
X-WA-Info
X-WA
Cdncip
Cdnsip
X-Akamai-Pragma-Client-IP
Hit
X-Ha-Backend
X-NGINX-Cache
M-TraceId
Srv
X-AK-Request-ID
X-Clara-WADP
Ohc-File-Size
X-Geo
X-ElasticPress-Query
X-Cms-Context
X-Cdn-Forward
X-Via-PopV
X-Wikidot-Backend
X-Via-PopH
Shield-Pop
X-Via-PopN
Pagetype
X-Wikidot-Static-Cache
My-App
ENV
MIME-Version
Cluster
X-PJAX-URL
X-Edge-POP
X-From
X-Api-Version
Geoip-Latitude
X-Via-Ucdn
X-Edge-Cache
X-HS-Status
X-CCDN-CacheTTL
Tracecode
Lfy
X-Hcs-Proxy-Type
MD5-Digest
X-CCDN-Origin-Time
URI
Load-Balancing
T-Server
X-CUA
X-Ucs
X-Var-Ttl
X-VG-WebServer
X-ServerName
X-Fastly-Cache-Hits
X-UP
X-Cache-Expires
X-SIPLIST1
W
Sever-Int
Server-Hostname
X-Mcache
X-Lb-Id
IsBot
Server-Ext
X-Fastly-Backend-Reqs
X-GoCache-CacheStatus
Lang
X-RAMCache
X-Fragments
Servername
X-TRACE-ID
X-Dw-Trace-Id
X-VC
X-B3-ParentSpanId
X-RateLimit-Reset
X-Nc
Cdn
X-WP-CF-Super-Cache
Target-Params
X-Cdn-Request-ID
Cneonction
Ohc-Cache-HIT
PICS-Label
X-WP-CF-Super-Cache-Cache-Control
Cteonnt-Length
WZWS-RAY
X-Provided-By
CountryCode
Server-Ttl
X-Acquia-Site
X-Acquia-Application-Trace
X-Acquia-Application-UUID
X-Cc-Via
X-Swift-Error
X-Acquia-Purge-Tags
X-Via-CDN
X-Platform-Router
Cf-Ipcountry
X-Contensis-Viewer-Groups
X-Platform-Processor
X-Platform-Cluster
X-Cache-ASPX
X-Apw-Access-Action
X-Yottaa-OS
X-Apw-Hits
X-Apw-Access-Token
X-Apw-Access-Object
X-Newrelic-App-Data
X-Snapshot-Date
Vha6-Origin
CF-Cached-On
HitType
X-Akamai-Request-ID
Dnion-Transfer-Encoding
X-Cache-Ngx
Sid
X-Air-Pt
X-Te-Count
GeoIP-Latitude
Uri
X-Akamai-ERPolicy
X-Http-Duration-Ms
X-Akamai-ERRuleID
X-Last-Modified
X-Varnish-Authentication
X-Te-Duration-Ms
X-B3-Parentspanid
X-UA
X-Sentry-ID
X-HTML-Edge-Cache
Req-ID
Ngx
FSS-Cache
X-Logging-Id
X-Lb-Nocache
X-Miniprofiler-Ids
X-CacheKey
X-Http-Count