Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
X-Powered-By
Pragma
X-XSS-Protection
CF-RAY
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
Alt-Svc
P3P
X-Cache-Hits
X-Xss-Protection
X-UA-Compatible
X-Served-By
CF-Ray
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
Access-Control-Allow-Credentials
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
X-Drupal-Cache
X-Cache-Status
X-Generator
X-Check
X-Cacheable
X-FRAME-OPTIONS
X-Envoy-Upstream-Service-Time
Timing-Allow-Origin
X-Iinfo
X-DNS-Prefetch-Control
X-Dns-Prefetch-Control
X-Drupal-Dynamic-Cache
Server-Timing
Feature-Policy
X-Content-Security-Policy
Access-Control-Expose-Headers
X-XSS-PROTECTION
Content-Encoding
X-CDN
Status
X-Request-ID
Upgrade
X-AspNetMvc-Version
Access-Control-Max-Age
X-Amz-Request-Id
X-Ua-Compatible
X-Via
X-Amz-Id-2
Request-Context
X-Backend
X-Turbo-Charged-By
X-Cache-Group
X-Robots-Tag
Cf-Edge-Cache
Keep-Alive
Host-Header
X-AH-Environment
X-Vhost
X-Hacker
X-UA-Device
X-Proxy-Cache
X-Server
Allow
X-Rq
X-Server-Powered-By
X-Ws-Request-Id
X-Age
X-Dispatcher
EagleId
X-Varnish-Cache
X-Amz-Version-Id
P3p
Nel
Grace
X-LiteSpeed-Cache
Cf-Apo-Via
Cf-Railgun
X-Page-Speed
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-OneAgent-JS-Injection
EagleEye-TraceId
X-Device
X-Swift-CacheTime
X-Swift-SaveTime
X-Aws-Lambda-Call-Status
Ali-Swift-Global-Savetime
X-Pingback
X-Host
X-Cache-Lookup
Accept-CH
X-CST
X-Node
X-WebKit-CSP
X-Backend-Server
Surrogate-Control
X-Server-Id
Permissions-Policy
X-Readtime
X-Nginx-Upstream-Cache-Status
X-Nginx-Cache-Status
Accept-CH-Lifetime
X-Akam-SW-Version
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Application-Context
Request-Id
X-Cloud-Trace-Context
X-Ruxit-JS-Agent
X-Content-Security-Policy-Report-Only
Xkey
X-Response-Time
X-HW
X-Trace
X-Edge
Content-Location
X-Clacks-Overhead
X-Mod-Pagespeed
X-Url
Rating
X-ESI
X-Midtier
X-Amz-Server-Side-Encryption
X-ECACHE
Cache-Tag
X-Mcache
X-Country
Accept-Ch
X-MS-InvokeApp
X-Rack-Cache
X-Powered-By-Plesk
X-D2id
X-Use-Magma
X-Exp-Variant
X-Kinja-Build
X-Kinja-Server
X-Cdn-Fetch
X-GoogleNews-Bot
X-Exp-Id
X-Kinja
X-Litespeed-Cache
X-Kinja-Revision
X-Vcap-Request-Id
Service-Worker-Allowed
Verso
X-Element-Page-Cache
X-Upstream
Edge-Control
Accept-Ch-Lifetime
X-Country-Code
RTSS
X-Vname
X-Ac
X-PC
X-TtlSet
Origin-Trial
X-Goog-Hash
X-VARITI-CCR
X-Navigation-Version
X-Abt-Application-Version
X-Kinja-CCPA
X-Cache-TTL
Fastly-Restarts
X-Browser-Type
X-Oneagent-Js-Injection
X-Amz-Rid
X-Aspnetmvc-Version
X-Varnish-TTL
X-NWS-LOG-UUID
X-GitHub-Request-Id
X-Webkit-CSP
X-Cached
Cross-Origin-Opener-Policy
X-Server-Name
X-WebKit-CSP-Report-Only
Display
X-Middleton-Display
X-Sol
Pagespeed
X-Amzn-Trace-Id
X-Dw-Request-Base-Id
SPRequestGuid
X-SharePointHealthScore
X-Server-ID
X-Times
X-Ruxit-Js-Agent
X-Ttl
X-Pinterest-Rid
Pinterest-Version
Pinterest-Generated-By
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
SPRequestDuration
SPIisLatency
X-Erf-Bev-Bev-Is-Generated
X-Instrumentation
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-Erf-Bev-Bev
X-Cache-Key
X-Content-Type
AR-PoweredBy
AR-SID
X-Powered-CMS
AR-ATIME
AR-Request-ID
Arr-Disable-Session-Affinity
X-Mg-S
Response
X-B3-Traceid
X-Middleton-Response
X-Version
X-FastCGI-Cache
X-Cnection
X-Ser
X-Client-IP
X-Jurisdiction
Nginx-Cache
X-HP-Trace-Id
X-HP-Webp
X-Accel-Expires
Cache-Tags
X-SRCache-Fetch-Status
AR-CACHE
X-T
X-Fastly-Request-ID
X-SRCache-Store-Status
X-B3-TraceId
Cache-Status
X-NF-Request-ID
Edge-Cache-Tag
X-Hits
X-MSEdge-Ref
X-Px
Public-Key-Pins
Front-End-Https
X-RateLimit-Remaining
X-Recruiting
S
X-Shield-Request-Id
Payment
X-Frontend
X-Daa-Tunnel
X-LLID
Server-Node
X-Ua-Browser
X-Request-Received
X-Request-Processing-Time
Mrf-Cache-Status
X-B3-TraceId-Primal
MRF-Tech
X-GUploader-UploadID
X-RateLimit-Limit
X-Goog-Metageneration
Content-MD5
MicrosoftSharePointTeamServices
X-Content-Digest
X-Amzn-RequestId
X-DIS-Request-ID
X-Amz-Apigw-Id
Access-Control-Request-Method
X-Webkit-CSP-Report-Only
X-TTL
X-Forwarded-For
TP-Cache
X-Protected-By
Realpath
X-Request-Handler-Origin-Region
X-Microsite
X-Distributor
X-FB-Debug
X-PressLabs-Stats
X-Ratelimit-Remaining
X-HS-Cache-Config
X-HS-Combine-CSS
X-HS-Content-Id
Fastcgi-Cache
X-HS-Hub-Id
X-Page-Id
Access-Control-Allow-Method
X-LB-Cache
Accept-Charset
X-Cluster-Name
X-Rid
X-Xrds-Location
X-Aspnet-Version
X-Fastcgi-Cache
X-Ua-Device
X-Goog-Stored-Content-Length
Count-Hit
X-Goog-Generation
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Hostname
X-Geo-Country
X-B3-Sampled
X-Id
TP-L2-Cache
Cross-Origin-Resource-Policy
X-Kinsta-Cache
X-Edge-Location-Klb
X-Seen-By
X-Correlation-Id
X-Erf-Stays-Pdp-Viaduct-Migration-Web
X-Ratelimit-Limit
X-Ezoic-Cdn
X-App-Server
Cleartype
TCN
X-Logged-In
X-Varnish-Backend
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Content-Options
Referer-Policy
X-Hosted-By
DC
X-Git-Hash
X-Mobile
X-Fb-Rlafr
Retry-After
X-Contextid
X-Newrelic-App-Data
X-Origin-Cache
X-Is-Crawler
X-Providence-Cookie
X-Route-Name
X-Request-Guid
X-Flags
X-Aspnet-Duration-Ms
X-Revision
Surrogate-Key
X-Grace
X-App-Environment
X-TT
X-Forwarded-Proto
X-F-Cache
X-Amz-Replication-Status
X-Debug-Info
Frame-Options
X-IPS-LoggedIn
X-Varnish-Grace
X-Amz-Meta-S3cmd-Attrs
X-Azure-Ref
X-Envoy-Decorator-Operation
Section-Io-Cache
X-Magnolia-Registration
MS-Author-Via
X-Wix-Request-Id
X-RateLimit-Reset
X-Whom
X-COUNTRY
X-Proxy-Cache-Info
X-Webkit-Csp
Healthy
X-App-Version
X-Www-Served-By
Charset
X-Language
X-Akamai-Edgescape
X-Az
X-Activity-Id
Viewport
X-AppVersion
Alternate-Protocol
X-Backend-Name
Filterid
X-Trace-Id
WPO-Cache-Status
WPO-Cache-Message
X-Origin-Server
X-Varnish-Server
Amp-Access-Control-Allow-Source-Origin
X-Kong-Proxy-Latency
Paypal-Debug-Id
X-Datadog-Sampling-Priority
X-Kong-Upstream-Latency
Server-Name
X-Datadog-Parent-Id
X-Datadog-Trace-Id
X-B
X-EdgeConnect-Cache-Status
X-Client-Ip
X-Original-Request-Id
SRV
Host
VIX-Pulpo-Upstream-Status
X-Cache-Rule
VIX-Pulpo-Node
X-Response-Served-From
X-Http-Reason
X-DataDome
X-Instance
X-Cache-Grace
X-Edge-Location
X-Akamai-Request-ID2
X-UUID
X-Nf-Request-Id
Front
X-Rule
X-User-Agent
SD-X-WS
Protected
X-Unique-Id
X-ARC
X-Vcache
From-Origin
X-Environment-Context
X-Yottaa-Metrics
X-Jobs
X-N
X-Region
Country
X-Cacheable-TTL
X-Page-View
X-Yottaa-Optimizations
X-L-Path
Akamai-GRN
X-Framework
Fastly-SWR
Fastly-SIE
X-FW-Serve
X-ProcessESI
X-Varnish-Age
X-RemovedCookies
X-Rendered-As
X-Status
X-Rocket-Nginx-Serving-Static
X-Is-Bot
X-FW-Version
X-FW-Hash
X-Adobe-Loc
X-FW-Server
X-FW-Static
X-FW-Type
X-Adobe-Content
X-FW-Dynamic
X-Load-Cache
X-Time
X-Proxy
X-G
X-Cache-Time
X-Tumblr-Pixel
X-Tumblr-User
Content-Disposition
X-Mg-Request-UUID
X-Datadog-Sampled
X-Type
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-Signature
X-B-Cache
X-Amzn-Remapped-Content-Length
X-Debug-IsConnected
X-Debug-IsPreview
Access-Control-Request-Headers
ServerID
X-ECache
X-CDN-Forward
X-WP-CF-Super-Cache-Cache-Control
X-Tec-Api-Root
X-Tec-Api-Origin
X-WP-CF-Super-Cache
X-Tec-Api-Version
Backend
X-Erf-Web-Scheduler
X-Cache-Control
Refresh
X-Cache-Age
X-DynaTrace
Countrycode
Xet-Cookie
X-Servername
X-Nginx-Cache
X-Httpd
Accept-Language
Url
X-Drupal-Cache-Tags
X-Tt-Trace-Host
X-Tt-Trace-Tag
CF-IPCountry
X-Template
X-DynaTrace-JS-Agent
X-Device-Type
X-Mode
X-Generated-By
X-NYM-Debug-Backend
X-Content-Powered-By
X-HTML-Minification-Powered-By
Xserver
X-Source
X-Storage
X-Hcs-Proxy-Type
X-CCDN-CacheTTL
GEO-INFO
X-Cache-Hit
X-CCDN-Origin-Time
Webserver
X-Cache-Operation
X-Loop
X-Director
X-Say-Cacheable
X-Content-Age
X-SaId
S-Rt
X-Rewrite-Enabled
X-Rn-Rsrv
X-LAGOON
X-XRDS-LOCATION
X-GeoCode
X-Urbn-Site-Id
Filters
X-GeoCountry
X-Say-TTL
Load-Balancing
X-Tncms
X-UPSTREAM-Address
X-URL
Version
OT-Force-Account-Verify
X-JoinUs
X-Urbn-Context-Path
Meta-Geo
Locale
X-SayCDN-TTL
X-ServerID
X-Cluster-Node
X-Container-Uri
X-Forwarded-Host
X-Cache-Action
Cross-Origin-Window-Policy
X-Git-Commit
X-Soup
Onion-Location
X-MCACHE
X-Varnish-Cache-Hits
X-Labrador-Cache-Channel
X-PHP-Host
X-RM-Cache-TTL
X-VC-Cache
Azure-Version
Azure-RegionName
X-VCT
X-Ms-Request-Id
X-Adobe-Source
Azure-SlotName
X-Sql-Count
Azure-SiteName
X-Varnish-Hostname
X-Tt-Logid
X-Ms-Version
Web-Mar-Node
Azure-InstanceId
X-Lambda-Id
X-Sql-Duration-Ms
X-Skip-Cache
X-Detected-As
X-Served-From
X-Tb
X-Proxied
X-R9-Blue-Green-Version
X-Cache-Server
X-Logging-Id
X-FB-TRIP-ID
Mn-Server-Ip
X-Extlb
X-Routing-Service
X-Zipkin-Id
Node
DB-Nickname
X-RCS-CacheZone
TWC-Device-Class
TWC-Connection-Speed
Selected-Fe
Property-Id
X-Proxy-Build
X-Proto
X-Origin-Hint
X-Generation-Time
X-Timing-Wait
X-Redis-Cache
X-Tumblr-Pixel-3
X-Tumblr-Pixel-2
X-Format
X-Uri
Webcakes-App-Name
TWC-Privacy
TWC-Locale-Group
Webcakes-App-Version
Webcakes-Region
X-Fetched-On
X-Debug
TWC-GeoIP-LatLong
TWC-GeoIP-Country
Fastcgi-Useragent
X-B3-SpanId
X-FTR-Request-ID
X-Endurance-Cache-Level
X-NGENIX-Cache
Uber-Trace-Id
Source
X-Zen-Fury
X-LSADC-Cache
CDN-RequestId
X-XRDS-Location
X-Sucuri-Cache
X-Ua
X-Sucuri-ID
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
X-S
Section-Origin-Responded
Section-Io-Id
X-Ratelimit-Reset
X-Oracle-Dms-Ecid
X-Oracle-Dms-Rid
X-TimeS
X-Origin-CC
X-Origin-TTL
X-Drupal-Cache-Contexts
NGB
X-MP-GENERATED-AT
X-Origin-Date
X-Akamai-Transformed
X-Srv
Upgrade-Insecure-Requests
X-Newrelic-Synthetics
Fastly-Drupal-HTML
X-Cache-Expired-At
X-Real-IP
X-Pass-Why
X-Handled-By
X-CACHE-AGE
X-Varnish-Hits
Liferay-Portal
X-Reqid
X-No-Session
X-Cms-Context
X-Optimistic-Header
Apigw-Requestid
X-Xfnlog-Site
MS-CV
ServedBy
X-RTag
X-Restarts
X-GEO
X-Upgrade-Enabled
Ms-Operation-Id
X-BYPASS-REASON
X-Hl-Ver
X-Cache-Host
X-AB
X-ProxyCache-Status
X-Varnish-Ttl
X-ProxyCache-Key
X-Cache-Type
CDN-RequestPullCode
CDN-Uid
CDN-RequestPullSuccess
WP-Super-Cache
CDN-RequestCountryCode
X-Node-Name
X-Cache-TTL-Remaining
X-Fastly-Request-Id
X-Tx-Id
CDN-PullZone
X-UA-Device-Type
CDN-EdgeStorageId
CDN-CachedAt
CDN-Cache
X-Parent-Response-Time
X-IPLB-Instance
X-LJ-Flow-ID
X-TraceId
X-CSRF-Token
X-IPLB-Request-ID
X-VWS-Id
X-AWS-Id
X-Cluster
X-Pubstack
X-Via-JSL
X-Geo-Region
Web-Mar-Region
Meta-Geo-Continent
X-ScT
L5d-Success-Class
BehaviorPad-Version
Magicmarker
L
MD5-Digest
Lang
Canary
DCR-Processing-Time-Ms
X-A
Fastly-SSL
Gannett-Cam-Experience-Id
Ha-Gx-Prefs
DCR-Decision-By
Candidate-Md5Url
X-S-Cookie
HA-Ipaddr
X-Micro-Cache
Rendered-Blocks
Redirect-Candidate
Origin-Agent-Cluster
X-Proxy-Cache-Status
T-Server
Server-Host
Sslversion
Surrogated-Key
Cache-Provider
Odigeo-Trace-Id
True-Client-Country-4JS
Vix-Hermes-Req-Id
W
X-PAYTM-SRV-ID
N-Cache
X-Request-Host
Ngx.Var.Host
X-Rojux
X-A-Wwc
X-Vdms-Path
X-CGP
X-Vdms-Version
X-Conf
X-External-Request-Id
X-Viewer-Country
X-A-Ccd
X-CF-Lambda-Fn
X-Bl-Debug
X-BCube-Filmed-By
X-FC-Vary-Parameters
X-Cache-NE
X-CacheTTL
X-Fastly-Backend
X-Vtex-Remote-Cache
X-Csrf-Jwt
X-Dispatcher-Number
X-Developer
X-Ec-Custom-Error
X-Ec-Fail
X-Epic-Correlation-Id
X-Ec-GeoHdr
X-Destination
Xc-Version
X-D
X-We-Are-Hiring
X-Eu-Site
X-Worker
X-Debug-Cache-Store
X-Debug-Cache-Fetch
X-Bc-Bl
X-CF-Lambda-Version
X-Aed
X-SRCache-Key
X-Slack-Backend
X-A-Dgt
X-App
X-Application
X-Slack-Shared-Secret-Outcome
X-A-Dcw
X-A-Dam
X-B-Cookie
X-Server-W
X-TIME
X-Cache-Status-Check
X-Geo-Header
Is-Eu
Host-ID
X-DefHash
Mail-Subject
X-Alternate-Cache-Key
X-Irp-Debug
We-Hiring
X-Gdpr
X-DefElseHash
Gh-Request-Id
Fastly-GeoIP-CountryCode
X-Mly-Id
Fastly-Backend-Name
Expect-Staple
Environment
X-Mid
X-Loc
X-Accel-Buffering
X-Dispatcher-Server
X-DPWN-IS-SECURE
X-Date
X-Accel-Expires-Debug
X-Human
Thinkindot-CacheControl
X-Cdn-Origin
Thinkindot-CacheControl-Type
Thinkindot-Control
X-GeoIP-Region-Code
X-Cdn-Diag
X-Forwarded-Path
X-Cache-Bucket
TDXMobile
Req-Svc-Chain
X-Cache-Debug
X-Cache-Info
X-Clientip
X-CMSURLCustom
X-GeoIP-Country-Code
X-BBC-Edge-Cache-Status
X-ApacheServer
Origin
VNS-Age
X-Hash
X-Core-Value
X-Core-Mission
X-App-Name
Release
Producers
Platform
VNS-Cache
X-Orig-Expires
X-Request-Time
X-Refresh
X-Policy
X-VServer
X-Vmg-Version
X-VG-TLSProxy
X-VG-WebCache
X-Correlation-ID
X-Wikidot-Backend
X-Platform
X-PERF
X-Origin-Time
X-Bip
X-Tenant
X-Wix-Viewer-Type
X-Wikidot-Static-Cache
X-Thinkindot-L3
X-Varnishpool
X-SD-PageType
X-Sn-Servicetimems
X-Shopify-Stage
X-Up
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-Storefront-Renderer-Rendered
X-Var-Ttl
X-Variation
X-Server-IP
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
X-ShardId
X-Varnish-CookieHashed-On
X-ShopId
X-Shop-Environment
X-Old-Content-Length
X-AIR-PT
X-Qloud-Router
X-Thanos
X-Nananana
X-Pool
X-Level-Front-Cache
Adler-Geo
AKAMAI
Cache-Name
X-Mvc-Supplant-Cachable
CPC-Cache
Datacenter
CPC-Age
Cmstype
CloudFront-Viewer-Country
Cmsid
X-Nitro-Cache
X-Owner
X-NodeID
X-Generated-On
X-Nyt-Route
User-Cache-Control
CDCHOST
X-From
X-Gen-Mode
X-INCAP-ABP
X-Mvc-Supplant-OutputCached
X-Test
X-Ah-Environment
Cf-Device-Type
X-Vgn-Hpd-Reason
Machine
X-Origin
X-Org
X-Op-Id-All
Esi-Enabled
X-Fmm-Version
X-Auto-Login
X-Forwarded-Site
Server-Ext
X-Cache-Id
X-Esi-Check
Country-Code
X-Origin-Response-Time
X-Block-Status
X-Node-Id
Apple-News-Services-Handled
X-WA-Info
X-GeoIP
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-Gzip
X-Device-Os
X-WADP-Cache
Sever-Int
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
Server-Hostname
X-Nginx-Cache-Key
X-NCache
NM-Fastcgi-Cache
X-Clara-WADP
DSUID
Apple-News-Services-Request-Url
X-Hnp-Log
X-S-Maxage
X-Datadome
X-Accel-Version
X-B3-Spanid
Content-Secure-Policy
X-Via-Fastly
X-Cdn-Srv
X-Cache-Enabled
Wxu-Next-Commit
X-Is-Tablet
Ssr
X-Is-Supported-Browser
X-Is-Mobile
X-Is-Desktop
Server-Info
Pics-Label
X-LB-NoCache
C-Via
X-Instance-Name
NGX
X-Browser-Name
X-Tcp-Rtt
X-Akamai-Device-Characteristics
X-Access
Wxu-Next-Hostname
X-Section
Wxu-Next-Region
X-Vcl-Version
X-Buckets
AMP-Access-Control-Allow-Source-Origin
Server-ID
X-CACHE-GROUP
X-Dc
X-Presslabs-Stats
X-Amz-Meta-Cb-Modifiedtime
X-API-Version
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Ttl
IsBot
X-HA-Backend
X-SIPLIST1
X-Zone
X-Has-Esi
YJS-ID
X-Is-Gdpr
X-JWT-State
X-B3-Parentspanid
Memcached
X-ID
X-Platform-Cluster
Cdn-Requestid
X-Platform-Processor
X-Platform-Router
X-Origin-Cache-Key
Memory
X-Cached-By
Hostname
CF-Ctrl
X-Wp-Cf-Super-Cache-Active
Time
Sid
X-TA-CDN-Provider
Origin-EX
X-WP-CF-Super-Cache-Active
Location
Origin-CC
Cache-Hits
X-Tb-Optimization-Total-Bytes-Saved
X-Scale
X-Frame-Option
X-Hyper-Cache
X-Backend-Instance
X-Internal-Host
X-Fpc
X-Air-Source
X-Air-Hostname
X-Air-Trace-Id
X-TIM-N
X-ZONE
X-PHP-Backend
X-Cs
X-DC
X-FTR-Backend
X-Country-Code-Real
X-FTR-Balancer
X-FTR-Cache-Status
X-Webstats-RespID
X-FTR-Expires
Resin-Trace
X-FTR-Backend-Server
X-DataCenter
X-NewRelic-App-Data
X-Azure-Ref-OriginShield
X-LiteSpeed-Cache-Control
Epwk-X-Cache
X-Service
X-VC
X-NGINX-Cache
True-Client-Ip
X-Site-Version
X-SRV
GeoIP-Latitude
LB
X-Microcachable
Uri
GeoIp-Country-Code
X-NODE
X-Locale
X-Nitro-Cache-From
X-Nitro-Rev
GeoIP-Country-Code
Cache-Host
X-Origin-Expires
X-VCache
Req-ID
X-Info
X-Edge-Server
Cdn-Request-Time
X-Cache-Ttl
Cdn
Cdn-Host
X-NMSegId
WebServer
WZWS-RAY
XM
XServer
X-CSRF-TOKEN
X-Pod-Name
X-HN
M-TraceId
NtCoent-Length
X-Pad
True-Client-IP
X-Ad-Load-Variation
PFcat
X-VarnishDD-TTL
X-Datacenter
SID
X-Geo
X-Web-Node
X-Vercel-Id
X-Request-URI
X-M-Reqid
X-Vercel-Cache
X-M-Log
X-Ad-Defer-Variation
User-Agent
X-Github-Request-Id
X-Scope-Id
Pramga
X-Request-Start
X-MSEdge-Features
X-Qnm-Cache
X-FL-EDGE
Srvid
Content-Script-Type
Content-Style-Type
X-Varnish-Beresp-Status
X-CS
X-Shield-Cache-Expires
X-Via-SSL
X-Via-CDN
X-Via-Edge
Cluster
X-FL-QIT-DEBUG
Locid
HostName
Edge-Copy-Time
X-MSEdge-Flight
A
X-FPC
Fastly-Drupal-Html
X-HostName
Tcn
X-Cache-Date
X-WP-CF-Super-Cache-Cookies-Bypass
X-APP-VERSION
Cache-Tv-Group
CountryCode
X-Api-Version
Cf-Ipcountry
X-Cdn-Request-ID
Cdncip
X-Moov-T
X-Cache-ASPX
X-Moov-Xdn-Version
X-AK-Request-ID
X-NWS-UUID-VERIFY
X-Varnish-Authentication
X-Webkit-Csp-Report-Only
X-Amz-Meta-Opti
X-ATG-Version
X-Esi
X-TH-Server
Edge-Cache
Path
X-Contensis-Viewer-Groups
Cdnsip
X-FireWall-Port
X-LiteSpeed-Tag
Cache-Key
Tube-Return
X-Acquia-Purge-Cdn-Unconfigured
X-B3-Trace-ID
Click-Count-Action-Start
Click-Count-Error
X-Aicache-OS
X-Cache-FS-Status
Tube-Got-Eval
X-Nc
Tube-Get-Contents
Tube-Got-Results
X-LB-ID
X-Via-Poph
X-Via-Popn
X-Via-Popv
X-Servedbyhost
X-V-Cache
X-Wa
X-Branch-Name
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-VCL-Version
X-Proxy-CacheRZ
XkeyRZ
MIME-Version
On-Server
X-TRACE-ID
V-Age
X-Men
Yak-Timeinfo
X-Req
X-SB
X-Vary
X-CACHE-KEY
X-UA
CDN
X-Tim-N
Geoip-Latitude
Ngx-Var-Key
X-Render-Time
X-Wp-Cf-Super-Cache
X-Akamai-Pragma-Client-IP
Wpo-Cache-Status
Srv
X-Cdn-Forward
Proxy-Connection
X-Wp-Cf-Super-Cache-Cache-Control
Wpo-Cache-Message
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
Priority
X-Lb-Cache
Lb
My-App
X-Air-Pt
X-Acquia-Application-Trace
X-Platform-Server
X-HS-Content-Campaign-Id
X-Planisys-CDN-TTL
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Fastly-Backend-Reqs
Server-Id
X-User
X-Acquia-Application-UUID
State
X-Ha-Backend
X-Generated-In
X-Acquia-Purge-Tags
X-Acquia-Site
X-TT-LOGID
X-CUA
Ohc-Cache-HIT
X-Fastly-Country-Code
X-Varnish-Director
Ohc-File-Size
X-Fastly-Cache
X-Dw-Trace-Id
X-Vgn-Hpd-Ssi
X-Vgn-Hpd-Cached
X-Lb-Nocache
X-Vgn-Hpd-Variations-Key
CF-Cached-On
X-Via-Ucdn
X-EC-Lua
X-Release
PICS-Label
X-Iplb-Instance
Yjs-Id
X-Upstream-Ht
X-Upstream-Ct
X-Iplb-Request-Id
X-Provided-By
Warning
Cneonction
X-CF-Cache-Header-Vary
X-Rocket-Build-Number
X-Sigma
X-Udemy-Cache-App-Namespace
X-Sigma-Backend
Fusion-Component-Id
Fusion-Content-Id
Type
X-Cdn-Cache-Status
Fusion-Template-Id
Fusion-Source
Fusion-Content-Source
Fusion-Deployment-Id
X-Miniprofiler-Ids
X-Traceid
Cache
X-Snapshot-Date
Vha6-Origin
X-Cached-Since
X-Litespeed-Cache-Control
X-ElasticPress-Query
X-CF-Cache-Header-Cache-Control
X-Fastly-Cache-Hits
X-RAMCache
CACHE-MISS-TO-ORIGIN
X-HS-Status
Log-Origin
Inserted-Into-Cache-At
Ngx
X-Cache-Remote