Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
X-Powered-By
Pragma
CF-RAY
X-XSS-Protection
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
Alt-Svc
X-Xss-Protection
P3P
X-Cache-Hits
X-UA-Compatible
X-Served-By
CF-Ray
X-Download-Options
X-Timer
X-Request-Id
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
Access-Control-Allow-Credentials
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
X-Drupal-Cache
X-Cache-Status
X-Generator
X-Check
X-Cacheable
X-Envoy-Upstream-Service-Time
X-FRAME-OPTIONS
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Iinfo
X-Dns-Prefetch-Control
X-Request-ID
X-Drupal-Dynamic-Cache
Feature-Policy
Server-Timing
X-Content-Security-Policy
Access-Control-Expose-Headers
Content-Encoding
X-CDN
Status
X-XSS-PROTECTION
Upgrade
X-AspNetMvc-Version
Access-Control-Max-Age
X-Amz-Request-Id
X-Via
X-Amz-Id-2
Request-Context
X-Turbo-Charged-By
X-Backend
X-Cache-Group
X-AH-Environment
X-Robots-Tag
Cf-Edge-Cache
Keep-Alive
Host-Header
X-Hacker
X-UA-Device
X-Proxy-Cache
X-Server
X-Rq
X-Server-Powered-By
X-Vhost
Allow
X-Ws-Request-Id
X-Age
X-Dispatcher
EagleId
X-Varnish-Cache
X-Amz-Version-Id
X-LiteSpeed-Cache
P3p
Nel
Grace
Cf-Apo-Via
Cf-Railgun
X-Page-Speed
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Device
EagleEye-TraceId
X-OneAgent-JS-Injection
X-Swift-CacheTime
X-Swift-SaveTime
X-Aws-Lambda-Call-Status
Ali-Swift-Global-Savetime
X-Pingback
X-Host
X-Node
Accept-CH
X-WebKit-CSP
X-Cache-Lookup
X-CST
X-Backend-Server
Surrogate-Control
X-Server-Id
X-Readtime
Permissions-Policy
X-Nginx-Cache-Status
X-Nginx-Upstream-Cache-Status
X-Akam-SW-Version
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Application-Context
Request-Id
X-Content-Security-Policy-Report-Only
Accept-CH-Lifetime
X-Cloud-Trace-Context
X-Ruxit-JS-Agent
X-Response-Time
X-HW
X-Ua-Compatible
X-Trace
Xkey
X-Edge
Content-Location
X-Clacks-Overhead
X-Mod-Pagespeed
Rating
X-Url
X-ESI
Accept-Ch-Lifetime
X-Midtier
X-Amz-Server-Side-Encryption
X-ECACHE
X-Mcache
Cache-Tag
X-Country
X-MS-InvokeApp
X-Upstream
X-Rack-Cache
X-D2id
X-Vcap-Request-Id
X-Powered-By-Plesk
X-Kinja-Revision
X-Kinja-Server
X-Kinja-Build
X-GoogleNews-Bot
Verso
X-Cdn-Fetch
X-Exp-Id
X-Exp-Variant
X-Kinja
X-Use-Magma
X-Element-Page-Cache
Accept-Ch
Edge-Control
Service-Worker-Allowed
X-TtlSet
X-PC
X-Vname
RTSS
X-Oneagent-Js-Injection
X-Country-Code
X-Ac
Origin-Trial
X-VARITI-CCR
X-Navigation-Version
X-Goog-Hash
X-Abt-Application-Version
Fastly-Restarts
X-Cache-TTL
X-WebKit-CSP-Report-Only
X-GitHub-Request-Id
X-Varnish-TTL
X-Browser-Type
X-Amz-Rid
X-Cached
X-Kinja-CCPA
X-Aspnetmvc-Version
Cross-Origin-Opener-Policy
X-Webkit-CSP
X-Sol
Display
X-Middleton-Display
Pagespeed
X-Server-Name
X-NWS-LOG-UUID
X-Ruxit-Js-Agent
X-Dw-Request-Base-Id
X-Amzn-Trace-Id
X-SharePointHealthScore
SPRequestGuid
X-Content-Type
SPIisLatency
SPRequestDuration
X-Times
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Server-Lifecycle-Phase
X-Instrumentation
X-Kraken-Loop-Name
X-Powered-CMS
AR-ATIME
AR-PoweredBy
AR-SID
X-Cache-Key
AR-Request-ID
X-Ttl
X-Mg-S
X-Pinterest-Rid
Pinterest-Version
Pinterest-Generated-By
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
X-B3-Traceid
Arr-Disable-Session-Affinity
Response
X-Middleton-Response
X-Litespeed-Cache
X-Client-IP
X-Version
X-Fastly-Request-ID
X-Cnection
X-Jurisdiction
X-HP-Webp
X-HP-Trace-Id
X-Ser
X-FastCGI-Cache
AR-CACHE
X-Accel-Expires
Cache-Tags
Nginx-Cache
X-T
X-SRCache-Fetch-Status
X-SRCache-Store-Status
Cache-Status
X-Server-ID
Edge-Cache-Tag
X-B3-TraceId
X-Hits
Front-End-Https
X-MSEdge-Ref
Public-Key-Pins
X-Px
X-NF-Request-ID
X-Recruiting
Payment
S
X-LLID
X-RateLimit-Remaining
X-Frontend
X-Ua-Browser
Server-Node
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
X-Request-Received
X-Request-Processing-Time
X-Shield-Request-Id
Content-MD5
X-Daa-Tunnel
X-DIS-Request-ID
X-GUploader-UploadID
X-TTL
X-Goog-Metageneration
X-RateLimit-Limit
Access-Control-Request-Method
MicrosoftSharePointTeamServices
X-PressLabs-Stats
X-Content-Digest
TP-Cache
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Ratelimit-Remaining
Realpath
X-Webkit-CSP-Report-Only
X-Request-Handler-Origin-Region
X-HS-Cache-Config
X-HS-Content-Id
X-HS-Combine-CSS
X-Distributor
X-HS-Hub-Id
X-Protected-By
X-Microsite
Fastcgi-Cache
X-Forwarded-For
X-Fastcgi-Cache
Access-Control-Allow-Method
X-FB-Debug
X-Page-Id
X-LB-Cache
Accept-Charset
X-Cluster-Name
X-Rid
TP-L2-Cache
X-Hostname
X-Geo-Country
X-Erf-Stays-Pdp-Viaduct-Migration-Web
X-Ratelimit-Limit
X-B3-Sampled
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Generation
Count-Hit
X-Aspnet-Version
X-Ua-Device
X-Seen-By
X-Ezoic-Cdn
Cross-Origin-Resource-Policy
X-Correlation-Id
X-Kinsta-Cache
TCN
X-Edge-Location-Klb
X-Newrelic-App-Data
X-App-Server
Cleartype
Referer-Policy
X-Mobile
X-Logged-In
X-Varnish-Backend
X-Content-Options
X-Id
DC
X-Hosted-By
X-Git-Hash
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-TEC-API-ROOT
X-Origin-Cache
X-Contextid
X-Flags
X-Fb-Rlafr
X-Aspnet-Duration-Ms
X-Debug-Info
X-Is-Crawler
X-Request-Guid
X-Amz-Replication-Status
X-Providence-Cookie
X-Route-Name
X-Revision
X-Grace
Surrogate-Key
X-App-Environment
Retry-After
X-TT
X-Varnish-Grace
X-Forwarded-Proto
X-Amz-Meta-S3cmd-Attrs
Frame-Options
X-Envoy-Decorator-Operation
X-Xrds-Location
X-IPS-LoggedIn
X-F-Cache
X-Azure-Ref
Section-Io-Cache
X-Magnolia-Registration
X-Wix-Request-Id
Healthy
X-Whom
MS-Author-Via
Alternate-Protocol
Charset
X-Proxy-Cache-Info
X-Akamai-Edgescape
X-Origin-Server
X-Www-Served-By
X-App-Version
X-RateLimit-Reset
Viewport
X-Nf-Request-Id
X-COUNTRY
X-Webkit-Csp
X-Language
X-Backend-Name
X-Az
Amp-Access-Control-Allow-Source-Origin
X-AppVersion
X-Activity-Id
X-B
X-Varnish-Server
Filterid
SRV
WPO-Cache-Message
Paypal-Debug-Id
X-DataDome
WPO-Cache-Status
Host
VIX-Pulpo-Upstream-Status
X-Http-Reason
X-Original-Request-Id
X-Response-Served-From
SD-X-WS
Server-Name
X-Datadog-Sampling-Priority
X-Datadog-Trace-Id
X-Cache-Rule
X-Datadog-Parent-Id
VIX-Pulpo-Node
X-Edge-Location
X-Akamai-Request-ID2
X-Rule
Front
X-UUID
Akamai-GRN
X-Page-View
X-Region
X-Environment-Context
X-L-Path
X-Status
X-Time
X-Jobs
X-Instance
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
From-Origin
Country
X-User-Agent
X-Cache-Grace
X-Unique-Id
X-Cacheable-TTL
X-Adobe-Content
X-Adobe-Loc
X-Load-Cache
X-EdgeConnect-Cache-Status
Fastly-SIE
Fastly-SWR
Protected
X-N
X-Is-Bot
X-Rocket-Nginx-Serving-Static
X-Rendered-As
X-Varnish-Age
X-Framework
X-ProcessESI
X-RemovedCookies
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Tumblr-User
X-Tumblr-Pixel
X-Type
X-ARC
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-G
X-Vcache
X-Client-Ip
X-FW-Hash
X-FW-Dynamic
ServerID
X-Cache-Time
X-Trace-Id
X-FW-Serve
X-Proxy
X-FW-Static
X-FW-Server
X-FW-Type
X-FW-Version
Content-Disposition
Access-Control-Request-Headers
X-Datadog-Sampled
X-Mg-Request-UUID
X-B-Cache
X-Signature
X-Debug-IsPreview
X-Debug-IsConnected
X-Amzn-Remapped-Content-Length
X-CDN-Forward
X-Cache-Age
X-Cache-Control
X-XRDS-Location
X-ECache
Backend
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
X-Tec-Api-Version
X-Tec-Api-Origin
X-Tec-Api-Root
Countrycode
Refresh
X-Nginx-Cache
X-DynaTrace
X-Drupal-Cache-Tags
Xet-Cookie
X-Erf-Web-Scheduler
Accept-Language
X-Servername
X-Httpd
X-Tt-Trace-Tag
X-Tt-Trace-Host
Url
X-Generated-By
CF-IPCountry
X-DynaTrace-JS-Agent
X-Source
X-HTML-Minification-Powered-By
X-Template
X-Mode
X-Device-Type
Webserver
X-NYM-Debug-Backend
X-Content-Powered-By
Xserver
Version
X-Storage
X-Content-Age
GEO-INFO
X-GeoCountry
X-Urbn-Site-Id
X-JoinUs
X-SayCDN-TTL
X-Urbn-Context-Path
OT-Force-Account-Verify
X-Rewrite-Enabled
X-ServerID
Load-Balancing
Locale
Meta-Geo
Filters
X-Cache-Action
S-Rt
X-UPSTREAM-Address
X-Cache-Operation
X-GeoCode
X-Rn-Rsrv
X-Say-TTL
X-Say-Cacheable
X-SaId
X-Tt-Logid
Onion-Location
X-Cluster-Node
X-Varnish-Hostname
X-Soup
X-Git-Commit
X-Forwarded-Host
X-Director
X-Container-Uri
X-Detected-As
X-Sql-Duration-Ms
X-Sql-Count
X-Tb
X-Ms-Request-Id
X-Served-From
X-PHP-Host
X-Adobe-Source
X-VCT
X-RM-Cache-TTL
X-Varnish-Cache-Hits
X-Lambda-Id
X-Ms-Version
X-Cache-Server
X-Labrador-Cache-Channel
X-VC-Cache
Azure-SlotName
Azure-Version
X-Proxied
X-Cache-Hit
Azure-SiteName
Azure-RegionName
Azure-InstanceId
Cross-Origin-Window-Policy
DB-Nickname
X-Routing-Service
Mn-Server-Ip
X-RCS-CacheZone
X-Loop
X-Zipkin-Id
X-XRDS-LOCATION
X-LAGOON
X-Logging-Id
X-Skip-Cache
X-Oracle-Dms-Ecid
X-Oracle-Dms-Rid
X-Extlb
Web-Mar-Node
X-Tncms
X-FB-TRIP-ID
X-CCDN-CacheTTL
X-CCDN-Origin-Time
X-Proto
X-Generation-Time
X-URL
X-R9-Blue-Green-Version
Node
X-Hcs-Proxy-Type
Fastcgi-Useragent
Selected-Fe
X-Uri
X-Format
X-Tumblr-Pixel-3
X-Tumblr-Pixel-2
X-Fetched-On
X-Timing-Wait
X-MCACHE
X-Proxy-Build
X-Debug
TWC-Privacy
TWC-Locale-Group
Uber-Trace-Id
Webcakes-Region
TWC-GeoIP-LatLong
Webcakes-App-Version
X-Origin-Hint
Webcakes-App-Name
Property-Id
TWC-GeoIP-Country
TWC-Connection-Speed
TWC-Device-Class
X-Zen-Fury
X-LSADC-Cache
X-Endurance-Cache-Level
Source
X-Ua
X-Ratelimit-Reset
X-Redis-Cache
CDN-RequestId
X-Sucuri-ID
X-Sucuri-Cache
X-NGENIX-Cache
X-Srv
X-B3-SpanId
Section-Io-Id
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
Section-Origin-Responded
X-S
X-Drupal-Cache-Contexts
X-MP-GENERATED-AT
X-Origin-Date
X-Pass-Why
X-Upgrade-Enabled
X-FTR-Request-ID
X-TimeS
X-Cache-Expired-At
X-Origin-CC
Fastly-Drupal-HTML
X-Origin-TTL
X-Varnish-Hits
Liferay-Portal
Upgrade-Insecure-Requests
X-Real-IP
X-Akamai-Transformed
X-Newrelic-Synthetics
NGB
X-Handled-By
X-CACHE-AGE
X-GEO
Apigw-Requestid
X-Optimistic-Header
X-Reqid
X-Cms-Context
X-Cache-TTL-Remaining
X-UA-Device-Type
X-Xfnlog-Site
X-Restarts
X-Node-Name
X-Cache-Type
X-Via-JSL
X-Hl-Ver
ServedBy
CDN-RequestPullSuccess
Ms-Operation-Id
X-CSRF-Token
CDN-Uid
X-BYPASS-REASON
CDN-RequestCountryCode
MS-CV
X-RTag
CDN-PullZone
X-No-Session
X-Tx-Id
CDN-RequestPullCode
X-Pubstack
CDN-Cache
X-ProxyCache-Key
CDN-EdgeStorageId
X-ProxyCache-Status
CDN-CachedAt
X-Varnish-Ttl
X-ID
X-Cache-Host
X-AWS-Id
X-Parent-Response-Time
X-Cluster
X-LJ-Flow-ID
X-IPLB-Request-ID
X-IPLB-Instance
WP-Super-Cache
X-VWS-Id
X-Server-W
Meta-Geo-Continent
MD5-Digest
N-Cache
Candidate-Md5Url
DCR-Decision-By
DCR-Processing-Time-Ms
Ngx.Var.Host
Canary
BehaviorPad-Version
Fastly-SSL
Gannett-Cam-Experience-Id
L5d-Success-Class
Lang
L
HA-Ipaddr
Ha-Gx-Prefs
Magicmarker
X-A-Dgt
X-Epic-Correlation-Id
X-Ec-GeoHdr
X-Eu-Site
X-External-Request-Id
X-FC-Vary-Parameters
X-Fastly-Backend
X-Ec-Fail
X-Ec-Custom-Error
X-D
X-Csrf-Jwt
X-Destination
X-Developer
X-Dispatcher-Number
X-Request-Host
X-Rojux
X-Viewer-Country
X-Vdms-Version
X-Vtex-Remote-Cache
X-Worker
Xc-Version
X-Vdms-Path
X-SRCache-Key
X-ScT
X-S-Cookie
X-SD-PageType
X-Slack-Backend
X-Slack-Shared-Secret-Outcome
X-Conf
X-CGP
Vix-Hermes-Req-Id
True-Client-Country-4JS
W
X-A
X-A-Ccd
T-Server
Surrogated-Key
Redirect-Candidate
Origin-Agent-Cluster
Rendered-Blocks
Server-Host
Sslversion
X-A-Dam
X-A-Dcw
X-Cache-NE
X-Bl-Debug
X-CacheTTL
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-Bc-Bl
X-B-Cookie
X-Aed
X-A-Wwc
X-App
X-App-Name
X-Application
Odigeo-Trace-Id
X-BCube-Filmed-By
X-Proxy-Cache-Status
X-AB
X-DPWN-IS-SECURE
X-Forwarded-Path
X-Gdpr
X-DefHash
X-Debug-Cache-Store
X-Core-Value
X-Date
X-Debug-Cache-Fetch
X-Generated-On
X-DefElseHash
X-Geo-Header
X-Mly-Id
X-Mid
X-Mvc-Supplant-Cachable
X-Nitro-Cache
X-Node-Id
X-Loc
X-Level-Front-Cache
X-GeoIP-Country-Code
X-GeoIP-Region-Code
X-Hash
X-Human
X-Core-Mission
X-Clientip
Thinkindot-Control
VNS-Age
VNS-Cache
We-Hiring
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
Producers
Release
Req-Svc-Chain
TDXMobile
Web-Mar-Region
X-Accel-Buffering
X-Cache-Info
X-Cdn-Diag
X-Cdn-Origin
X-NodeID
X-Cache-Debug
X-Cache-Bucket
X-Accel-Expires-Debug
X-Alternate-Cache-Key
X-BBC-Edge-Cache-Status
X-Bip
X-CMSURLCustom
X-Old-Content-Length
X-Var-Ttl
X-Up
X-Variation
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-Thinkindot-L3
X-Thanos
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-Tenant
X-Test
X-Varnish-Remaining-TTL
X-Varnishpool
X-Wikidot-Static-Cache
X-Wix-Viewer-Type
Content-Secure-Policy
Host-ID
X-Wikidot-Backend
X-We-Are-Hiring
X-VG-TLSProxy
X-VG-WebCache
X-Vmg-Version
X-VServer
X-Storefront-Renderer-Rendered
X-Sorting-Hat-ShopId
X-Platform
X-Policy
X-Pool
X-Qloud-Router
X-PAYTM-SRV-ID
X-Owner
Platform
X-Org
X-Orig-Expires
X-Origin-Time
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-ShopId
X-Shopify-Stage
X-Sn-Servicetimems
X-Sorting-Hat-PodId
X-Shop-Environment
X-ShardId
X-Refresh
X-Request-Time
X-S-Maxage
X-Server-IP
X-Nyt-Route
X-Irp-Debug
Origin
Is-Eu
Mail-Subject
Environment
X-Cache-Status-Check
Adler-Geo
CPC-Age
CPC-Cache
AKAMAI
Cmsid
Cmstype
Cache-Provider
Fastly-GeoIP-CountryCode
Cf-Device-Type
Fastly-Backend-Name
Expect-Staple
X-TIME
X-B3-Spanid
User-Cache-Control
X-Block-Status
X-Fmm-Version
CDCHOST
X-Origin
X-Nananana
CloudFront-Viewer-Country
Country-Code
X-Cache-Id
X-Mvc-Supplant-OutputCached
Machine
X-Nginx-Cache-Key
Datacenter
X-Geo-Region
X-Dispatcher-Server
X-Device-Os
X-Gen-Mode
X-From
X-Forwarded-Site
X-Esi-Check
X-GeoIP
Esi-Enabled
X-Clara-WADP
X-Origin-Response-Time
DSUID
X-Hnp-Log
X-Gzip
Gh-Request-Id
X-Cdn-Srv
X-Correlation-ID
X-Akamai-Device-Characteristics
X-Micro-Cache
Apple-News-Services-Handled
NM-Fastcgi-Cache
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
X-WA-Info
Sever-Int
Cache-Name
X-VHOST
X-WADP-Cache
Server-Ext
Server-Hostname
Apple-News-Services-Request-Url
X-TraceId
X-LB-NoCache
X-Datadome
X-ApacheServer
X-AIR-PT
X-Access
X-INCAP-ABP
Ssr
X-Auto-Login
X-Op-Id-All
Server-Info
X-Section
X-PERF
NGX
Wxu-Next-Hostname
X-Cache-Enabled
Wxu-Next-Region
X-NCache
Wxu-Next-Commit
C-Via
X-Instance-Name
Pics-Label
X-Vcl-Version
Server-ID
X-Amz-Meta-Cb-Modifiedtime
X-Fastly-Request-Id
X-Via-Fastly
X-Accel-Version
X-API-Version
AMP-Access-Control-Allow-Source-Origin
X-CACHE-GROUP
X-Vgn-Hpd-Reason
X-Dc
X-Varnish-Beresp-Grace
Memcached
X-HA-Backend
X-JWT-State
X-Has-Esi
X-Varnish-Beresp-Ttl
X-Is-Gdpr
X-Tcp-Rtt
X-Browser-Name
X-Is-Tablet
X-Is-Desktop
X-Is-Mobile
X-Is-Supported-Browser
X-Buckets
X-SIPLIST1
Hostname
IsBot
Memory
Time
X-Scale
Origin-EX
Origin-CC
X-Platform-Processor
X-Platform-Cluster
X-Platform-Router
Cache-Hits
Sid
X-TIM-N
Cdn-Requestid
X-ZONE
Location
X-Zone
X-Tb-Optimization-Total-Bytes-Saved
X-Air-Trace-Id
X-Wp-Cf-Super-Cache-Active
YJS-ID
CF-Ctrl
X-Air-Hostname
X-Air-Source
X-PHP-Backend
X-B3-Parentspanid
X-Presslabs-Stats
X-Fpc
X-Cached-By
X-WP-CF-Super-Cache-Active
X-Backend-Instance
X-DC
X-Internal-Host
X-Origin-Cache-Key
X-Frame-Option
Resin-Trace
X-Hyper-Cache
X-Azure-Ref-OriginShield
X-Cs
X-TA-CDN-Provider
GeoIP-Latitude
Uri
X-VC
X-Webstats-RespID
X-Origin-Expires
Epwk-X-Cache
True-Client-Ip
X-Site-Version
Cache-Host
X-Service
X-Microcachable
X-DataCenter
X-LiteSpeed-Cache-Control
LB
GeoIP-Country-Code
X-Info
X-FTR-Expires
X-FTR-Backend
X-FTR-Balancer
X-Nitro-Rev
X-NGINX-Cache
X-Nitro-Cache-From
XM
X-FTR-Cache-Status
X-FTR-Backend-Server
X-Country-Code-Real
X-Web-Node
X-Locale
PFcat
GeoIp-Country-Code
X-HN
X-Pod-Name
Cdn
X-VarnishDD-TTL
X-VCache
X-Edge-Server
X-Ad-Defer-Variation
X-Cache-Ttl
User-Agent
X-CS
XServer
Cdn-Request-Time
NtCoent-Length
Cdn-Host
X-NewRelic-App-Data
X-CSRF-TOKEN
M-TraceId
True-Client-IP
X-Via-CDN
WZWS-RAY
X-Via-SSL
X-Via-Edge
Edge-Copy-Time
X-FL-QIT-DEBUG
X-FL-EDGE
A
Locid
X-NMSegId
X-Datacenter
Srvid
Req-ID
X-Geo
X-Vercel-Cache
X-Vercel-Id
X-TRACE-ID
X-Ad-Load-Variation
X-SRV
WebServer
SID
X-Contensis-Viewer-Groups
Fastly-Drupal-Html
X-ATG-Version
X-Scope-Id
X-FireWall-Port
X-Moov-T
X-Moov-Xdn-Version
X-Varnish-Authentication
X-Request-Start
X-Cache-ASPX
Pramga
X-M-Log
X-FPC
X-MSEdge-Features
X-MSEdge-Flight
X-Pad
X-M-Reqid
Tcn
X-Request-URI
X-HostName
X-Shield-Cache-Expires
X-Qnm-Cache
Cluster
X-Varnish-Beresp-Status
X-NWS-UUID-VERIFY
Cache-Key
X-LiteSpeed-Tag
Cf-Ipcountry
CountryCode
HostName
X-Api-Version
X-APP-VERSION
X-Cdn-Request-ID
Edge-Cache
Path
X-Esi
X-Amz-Meta-Opti
X-Cache-Date
Content-Script-Type
X-AK-Request-ID
X-Air-Pt
Cdnsip
Cdncip
Content-Style-Type
Cache-Tv-Group
X-Branch-Name
X-TH-Server
X-VCL-Version
Wpo-Cache-Status
Wpo-Cache-Message
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-Via-Popv
X-Github-Request-Id
Click-Count-Error
X-Platform-Server
Yak-Timeinfo
Click-Count-Action-Start
XkeyRZ
X-V-Cache
Tube-Get-Contents
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Via-Poph
X-Wa
X-Servedbyhost
X-Proxy-CacheRZ
X-Via-Popn
X-SB
X-Req
X-LB-ID
Tube-Return
X-Aicache-OS
X-WP-CF-Super-Cache-Cookies-Bypass
X-Acquia-Purge-Cdn-Unconfigured
State
Tube-Got-Results
X-Cache-FS-Status
X-HS-Content-Campaign-Id
X-Planisys-CDN-Cache
X-Nc
Tube-Got-Eval
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-CACHE-KEY
X-Upstream-Ct
CDN
X-Upstream-Ht
X-Wp-Cf-Super-Cache-Cache-Control
Geoip-Latitude
X-Release
X-Wp-Cf-Super-Cache
X-Vgn-Hpd-Variations-Key
Srv
X-Cdn-Forward
X-Vgn-Hpd-Cached
X-B3-Trace-ID
X-Render-Time
X-Fastly-Cache
Proxy-Connection
X-Vgn-Hpd-Ssi
X-Men
X-Akamai-Pragma-Client-IP
X-Vary
MIME-Version
X-Tim-N
V-Age
X-Lb-Cache
On-Server
Ngx-Var-Key
X-User
X-Rocket-Build-Number
X-Generated-In
X-HS-Status
X-Traceid
Ohc-File-Size
X-Cache-Remote
X-UA
X-Sigma
CF-Cached-On
Lb
X-Dw-Trace-Id
X-Sigma-Backend
Server-Id
X-Ha-Backend
X-TT-LOGID
X-Acquia-Site
X-EC-Lua
X-Fastly-Backend-Reqs
PICS-Label
X-Lb-Nocache
Warning
My-App
X-Via-Ucdn
Cache
X-CUA
X-Acquia-Purge-Tags
Ohc-Cache-HIT
X-Acquia-Application-UUID
X-Acquia-Application-Trace
Yjs-Id
X-Iplb-Instance
X-Iplb-Request-Id
X-GeoIP-City
X-Gamma-Serve
X-GoCache-CacheStatus
X-Scheme
X-Fastly-Cache-Hits
X-CF-Cache-Header-Vary
Ngx
X-CF-Cache-Header-Cache-Control
Log-Origin
X-Miniprofiler-Ids
X-RAMCache
X-Litespeed-Cache-Control
X-Udemy-Cache-App-Namespace
Cneonction
Inserted-Into-Cache-At
X-Snapshot-Date
Vha6-Origin
X-ElasticPress-Query
X-Cached-Since
CACHE-MISS-TO-ORIGIN