Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
X-Powered-By
Pragma
CF-RAY
X-XSS-Protection
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
Alt-Svc
X-Xss-Protection
P3P
X-Cache-Hits
X-UA-Compatible
X-Served-By
CF-Ray
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Request-Id
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
Access-Control-Allow-Credentials
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
X-Drupal-Cache
X-Cache-Status
X-Generator
X-Check
X-Cacheable
X-Envoy-Upstream-Service-Time
X-FRAME-OPTIONS
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Request-ID
X-Iinfo
X-Dns-Prefetch-Control
X-Drupal-Dynamic-Cache
Server-Timing
Feature-Policy
X-Content-Security-Policy
Access-Control-Expose-Headers
Content-Encoding
X-CDN
Status
X-XSS-PROTECTION
Upgrade
X-AspNetMvc-Version
Access-Control-Max-Age
X-Amz-Request-Id
X-Via
X-Amz-Id-2
Request-Context
X-Backend
X-Turbo-Charged-By
X-Cache-Group
X-AH-Environment
X-Robots-Tag
Cf-Edge-Cache
Keep-Alive
Host-Header
X-Hacker
X-UA-Device
X-Vhost
X-Proxy-Cache
X-Server
X-Rq
Allow
X-Server-Powered-By
X-Ws-Request-Id
X-Age
X-Dispatcher
EagleId
X-Varnish-Cache
X-Amz-Version-Id
P3p
X-LiteSpeed-Cache
Nel
Grace
X-Ua-Compatible
Cf-Apo-Via
Cf-Railgun
X-OneAgent-JS-Injection
X-Page-Speed
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Device
EagleEye-TraceId
X-Swift-CacheTime
X-Swift-SaveTime
X-Aws-Lambda-Call-Status
Ali-Swift-Global-Savetime
X-Pingback
X-Host
X-Node
Accept-CH
X-WebKit-CSP
X-Cache-Lookup
X-CST
X-Backend-Server
Surrogate-Control
X-Server-Id
Permissions-Policy
X-Readtime
X-Nginx-Cache-Status
X-Nginx-Upstream-Cache-Status
X-Akam-SW-Version
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Request-Id
X-Application-Context
Accept-CH-Lifetime
X-Ruxit-JS-Agent
X-Content-Security-Policy-Report-Only
X-Cloud-Trace-Context
X-Response-Time
Xkey
X-HW
X-Trace
X-Edge
Content-Location
X-Clacks-Overhead
X-Mod-Pagespeed
X-Url
Rating
X-ESI
X-Midtier
X-Amz-Server-Side-Encryption
X-ECACHE
X-Mcache
Cache-Tag
Accept-Ch-Lifetime
X-Country
X-Rack-Cache
X-MS-InvokeApp
X-Powered-By-Plesk
X-D2id
X-Kinja-Revision
X-Cdn-Fetch
X-Kinja-Build
X-Kinja
X-Exp-Id
X-Use-Magma
X-Kinja-Server
X-Exp-Variant
X-GoogleNews-Bot
X-Vcap-Request-Id
X-Upstream
Verso
X-Element-Page-Cache
Accept-Ch
Service-Worker-Allowed
Edge-Control
X-PC
X-TtlSet
X-Vname
RTSS
X-Country-Code
X-Ac
Origin-Trial
X-Goog-Hash
X-VARITI-CCR
X-Navigation-Version
X-Abt-Application-Version
X-Cache-TTL
Fastly-Restarts
X-Browser-Type
X-Kinja-CCPA
X-Varnish-TTL
X-Amz-Rid
X-Oneagent-Js-Injection
X-GitHub-Request-Id
X-Cached
X-Litespeed-Cache
X-NWS-LOG-UUID
X-WebKit-CSP-Report-Only
X-Aspnetmvc-Version
Cross-Origin-Opener-Policy
X-Server-Name
X-Webkit-CSP
X-Sol
X-Middleton-Display
Pagespeed
Display
X-Amzn-Trace-Id
X-Dw-Request-Base-Id
SPRequestGuid
X-SharePointHealthScore
X-Times
X-Content-Type
SPRequestDuration
X-Server-ID
SPIisLatency
X-Erf-Bev-Bev
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Erf-Bev-Bev-Is-Generated
X-Instrumentation
X-Pinterest-Rid
Pinterest-Generated-By
Pinterest-Version
X-Cache-Key
X-Ruxit-Js-Agent
AR-PoweredBy
AR-SID
AR-Request-ID
AR-ATIME
X-Powered-CMS
X-Ttl
X-B3-Traceid
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-Mg-S
Arr-Disable-Session-Affinity
X-FastCGI-Cache
X-Client-IP
X-Middleton-Response
Response
X-Version
X-Ser
X-Cnection
X-HP-Trace-Id
X-HP-Webp
X-Jurisdiction
Nginx-Cache
X-Accel-Expires
Cache-Tags
AR-CACHE
X-Fastly-Request-ID
X-T
X-SRCache-Fetch-Status
X-SRCache-Store-Status
Cache-Status
Edge-Cache-Tag
X-B3-TraceId
X-Hits
X-MSEdge-Ref
Front-End-Https
X-Px
Public-Key-Pins
X-NF-Request-ID
X-Recruiting
S
Payment
X-Shield-Request-Id
X-LLID
X-Frontend
X-RateLimit-Remaining
X-Request-Received
X-Request-Processing-Time
X-Ua-Browser
Server-Node
X-Daa-Tunnel
X-B3-TraceId-Primal
Mrf-Cache-Status
MRF-Tech
Content-MD5
X-GUploader-UploadID
X-Goog-Metageneration
X-Webkit-CSP-Report-Only
X-TTL
X-DIS-Request-ID
X-RateLimit-Limit
Access-Control-Request-Method
MicrosoftSharePointTeamServices
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Content-Digest
X-Ratelimit-Remaining
TP-Cache
Realpath
X-Forwarded-For
X-Protected-By
X-PressLabs-Stats
X-Microsite
X-Request-Handler-Origin-Region
X-HS-Cache-Config
X-HS-Combine-CSS
X-HS-Hub-Id
X-HS-Content-Id
X-Distributor
Fastcgi-Cache
Access-Control-Allow-Method
X-FB-Debug
X-Page-Id
X-Rid
X-Cluster-Name
X-LB-Cache
Accept-Charset
X-Hostname
X-Geo-Country
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Xrds-Location
Count-Hit
X-B3-Sampled
X-Goog-Generation
X-Goog-Storage-Class
X-Ratelimit-Limit
TP-L2-Cache
X-Fastcgi-Cache
X-Aspnet-Version
Cross-Origin-Resource-Policy
X-Ua-Device
X-Seen-By
X-Correlation-Id
X-Kinsta-Cache
X-Edge-Location-Klb
X-Ezoic-Cdn
X-Id
TCN
Cleartype
X-Erf-Stays-Pdp-Viaduct-Migration-Web
X-App-Server
X-Logged-In
X-Varnish-Backend
X-Mobile
Referer-Policy
X-Content-Options
X-Hosted-By
X-Git-Hash
DC
X-Contextid
X-Aspnet-Duration-Ms
X-Providence-Cookie
Retry-After
X-Flags
X-Request-Guid
X-Route-Name
X-Fb-Rlafr
X-Is-Crawler
X-Origin-Cache
X-Revision
X-Grace
X-Amz-Replication-Status
X-Debug-Info
X-Forwarded-Proto
Surrogate-Key
X-TT
X-Newrelic-App-Data
X-F-Cache
X-App-Environment
Frame-Options
X-IPS-LoggedIn
X-Varnish-Grace
X-Envoy-Decorator-Operation
X-TEC-API-ROOT
X-Amz-Meta-S3cmd-Attrs
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-Azure-Ref
X-Magnolia-Registration
Section-Io-Cache
MS-Author-Via
X-Wix-Request-Id
X-Proxy-Cache-Info
X-Whom
Healthy
X-App-Version
Charset
Viewport
X-Akamai-Edgescape
X-Www-Served-By
Alternate-Protocol
X-RateLimit-Reset
X-Nf-Request-Id
X-Origin-Server
X-COUNTRY
WPO-Cache-Message
X-Backend-Name
WPO-Cache-Status
Filterid
X-AppVersion
X-Az
X-Activity-Id
X-Webkit-Csp
X-Language
Amp-Access-Control-Allow-Source-Origin
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Varnish-Server
X-B
Server-Name
X-DataDome
X-Trace-Id
SRV
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
X-Datadog-Trace-Id
Paypal-Debug-Id
X-Http-Reason
X-Original-Request-Id
X-Cache-Rule
Host
X-Response-Served-From
VIX-Pulpo-Node
SD-X-WS
X-EdgeConnect-Cache-Status
VIX-Pulpo-Upstream-Status
X-Akamai-Request-ID2
X-Rule
Front
X-Instance
X-User-Agent
X-Edge-Location
X-Cache-Grace
X-UUID
X-Time
X-Varnish-Age
Protected
X-Tumblr-Pixel
X-Vcache
X-ARC
X-Cacheable-TTL
X-Tumblr-Pixel-0
X-Environment-Context
X-Rocket-Nginx-Serving-Static
X-Unique-Id
X-Page-View
Country
X-Tumblr-User
X-Region
X-Tumblr-Pixel-1
From-Origin
X-L-Path
X-Jobs
Fastly-SWR
Fastly-SIE
X-Adobe-Content
X-Adobe-Loc
X-Client-Ip
X-Framework
X-FW-Type
X-RemovedCookies
X-FW-Static
X-FW-Version
X-Is-Bot
X-Rendered-As
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Load-Cache
X-FW-Server
X-N
X-FW-Dynamic
X-FW-Hash
X-FW-Serve
X-ProcessESI
X-Cache-Time
X-G
X-Status
Content-Disposition
Akamai-GRN
X-Type
X-Mg-Request-UUID
X-Tec-Api-Root
X-Tec-Api-Version
X-B-Cache
X-Datadog-Sampled
X-Tec-Api-Origin
X-Signature
X-Proxy
ServerID
X-Amzn-Remapped-Content-Length
X-Debug-IsPreview
Access-Control-Request-Headers
X-Debug-IsConnected
X-CDN-Forward
X-ECache
X-Cache-Age
X-Cache-Control
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
Backend
X-Nginx-Cache
Countrycode
Refresh
X-Servername
X-Httpd
X-DynaTrace
Xet-Cookie
X-Drupal-Cache-Tags
Url
X-Erf-Web-Scheduler
Accept-Language
X-Tt-Trace-Host
X-Tt-Trace-Tag
CF-IPCountry
X-DynaTrace-JS-Agent
X-Generated-By
X-Device-Type
X-HTML-Minification-Powered-By
X-Mode
X-NYM-Debug-Backend
X-Content-Powered-By
X-Template
X-Source
Xserver
X-Storage
GEO-INFO
Webserver
X-ServerID
X-Content-Age
X-Cache-Hit
X-Cache-Action
X-GeoCode
OT-Force-Account-Verify
X-Director
X-GeoCountry
X-Cache-Operation
Version
X-Say-TTL
X-Say-Cacheable
X-SayCDN-TTL
X-Urbn-Context-Path
Meta-Geo
Filters
Locale
Load-Balancing
X-Rn-Rsrv
X-Urbn-Site-Id
X-Rewrite-Enabled
S-Rt
X-UPSTREAM-Address
X-LAGOON
X-Varnish-Hostname
X-Container-Uri
X-JoinUs
X-Varnish-Cache-Hits
X-Forwarded-Host
X-Git-Commit
X-Soup
X-SaId
Cross-Origin-Window-Policy
X-Tt-Logid
X-Tumblr-Pixel-3
X-Cluster-Node
Onion-Location
X-Tumblr-Pixel-2
X-Loop
X-Tncms
X-Hcs-Proxy-Type
X-Labrador-Cache-Channel
X-Adobe-Source
X-CCDN-Origin-Time
X-Ms-Request-Id
X-CCDN-CacheTTL
X-RM-Cache-TTL
X-Lambda-Id
X-Detected-As
X-Cache-Server
X-Ms-Version
X-VC-Cache
X-VCT
X-PHP-Host
X-Sql-Duration-Ms
X-Served-From
Web-Mar-Node
X-Sql-Count
Azure-SiteName
Azure-InstanceId
Azure-RegionName
Azure-Version
DB-Nickname
Mn-Server-Ip
Azure-SlotName
Node
X-Logging-Id
X-Skip-Cache
X-R9-Blue-Green-Version
X-URL
X-Routing-Service
X-Proxied
X-Zipkin-Id
X-RCS-CacheZone
X-Tb
X-XRDS-LOCATION
X-Extlb
X-FB-TRIP-ID
TWC-GeoIP-LatLong
TWC-Connection-Speed
TWC-Device-Class
TWC-GeoIP-Country
X-Timing-Wait
X-Proxy-Build
X-Format
X-Fetched-On
Webcakes-App-Version
Webcakes-Region
X-Generation-Time
X-Origin-Hint
X-Uri
X-Debug
X-Proto
TWC-Privacy
TWC-Locale-Group
Webcakes-App-Name
X-Oracle-Dms-Ecid
X-Oracle-Dms-Rid
X-MCACHE
Fastcgi-Useragent
Selected-Fe
Property-Id
X-XRDS-Location
X-Endurance-Cache-Level
X-Redis-Cache
X-NGENIX-Cache
Uber-Trace-Id
Source
X-Zen-Fury
X-LSADC-Cache
CDN-RequestId
X-Ratelimit-Reset
X-Ua
X-FTR-Request-ID
X-B3-SpanId
X-Sucuri-Cache
X-Sucuri-ID
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
Section-Io-Id
Section-Origin-Responded
X-Srv
X-S
X-Drupal-Cache-Contexts
X-Origin-CC
X-Origin-TTL
X-Origin-Date
X-Pass-Why
X-TimeS
NGB
X-MP-GENERATED-AT
Upgrade-Insecure-Requests
X-Varnish-Hits
Fastly-Drupal-HTML
X-Real-IP
X-Akamai-Transformed
X-Cache-Expired-At
Liferay-Portal
X-Upgrade-Enabled
X-Handled-By
X-CACHE-AGE
Apigw-Requestid
X-Newrelic-Synthetics
X-GEO
X-Reqid
X-Cms-Context
X-Optimistic-Header
X-Xfnlog-Site
X-Restarts
ServedBy
Ms-Operation-Id
X-ProxyCache-Status
X-RTag
X-Cache-TTL-Remaining
X-No-Session
MS-CV
X-ProxyCache-Key
X-UA-Device-Type
X-Cache-Host
X-Tx-Id
X-Hl-Ver
X-BYPASS-REASON
X-CSRF-Token
X-Parent-Response-Time
X-Cache-Type
CDN-Cache
CDN-EdgeStorageId
X-Via-JSL
CDN-Uid
CDN-CachedAt
CDN-RequestPullSuccess
CDN-RequestPullCode
X-Node-Name
CDN-PullZone
CDN-RequestCountryCode
X-Varnish-Ttl
X-AWS-Id
X-Cluster
X-Pubstack
X-IPLB-Instance
X-IPLB-Request-ID
X-VWS-Id
X-LJ-Flow-ID
X-AB
X-Fastly-Request-Id
Cache-Provider
X-Bc-Bl
Candidate-Md5Url
X-BCube-Filmed-By
X-D
X-Conf
X-Csrf-Jwt
X-CF-Lambda-Fn
X-B-Cookie
Redirect-Candidate
X-Debug-Cache-Fetch
X-FC-Vary-Parameters
X-Ec-Custom-Error
X-CF-Lambda-Version
X-Ec-Fail
X-Ec-GeoHdr
BehaviorPad-Version
X-Dispatcher-Number
X-CacheTTL
X-Destination
X-Developer
X-Application
WP-Super-Cache
X-Epic-Correlation-Id
X-Debug-Cache-Store
X-Cache-NE
X-Bl-Debug
X-Micro-Cache
X-CGP
X-Fastly-Backend
X-Proxy-Cache-Status
X-Eu-Site
X-External-Request-Id
Canary
X-A-Ccd
True-Client-Country-4JS
Vix-Hermes-Req-Id
Magicmarker
MD5-Digest
N-Cache
Meta-Geo-Continent
X-SRCache-Key
Lang
X-Server-W
W
X-Slack-Shared-Secret-Outcome
L
L5d-Success-Class
Ngx.Var.Host
T-Server
X-We-Are-Hiring
X-Vtex-Remote-Cache
Server-Host
Rendered-Blocks
Xc-Version
X-Worker
Sslversion
Origin-Agent-Cluster
X-Vdms-Version
X-Vdms-Path
Odigeo-Trace-Id
Surrogated-Key
X-Viewer-Country
Host-ID
X-Slack-Backend
X-A-Dgt
DCR-Decision-By
Gannett-Cam-Experience-Id
X-Request-Host
X-A
X-Aed
DCR-Processing-Time-Ms
X-A-Wwc
Web-Mar-Region
Fastly-SSL
X-ScT
X-SD-PageType
X-A-Dcw
X-App
X-A-Dam
X-Rojux
X-S-Cookie
Ha-Gx-Prefs
HA-Ipaddr
X-TraceId
X-B3-Spanid
X-Cache-Status-Check
X-Geo-Region
X-Alternate-Cache-Key
Release
Req-Svc-Chain
X-Accel-Expires-Debug
X-Accel-Buffering
Thinkindot-CacheControl
VNS-Age
X-Cdn-Origin
X-App-Name
VNS-Cache
We-Hiring
X-Cache-Info
Thinkindot-Control
X-Clientip
TDXMobile
X-Cache-Bucket
Thinkindot-CacheControl-Type
X-Cache-Debug
X-Bip
X-Mly-Id
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Sn-Servicetimems
X-Storefront-Renderer-Rendered
X-SVT-ORM-RULES
X-Tenant
X-SVT-ORM-VERSION
X-Shopify-Stage
X-ShopId
X-Request-Time
X-Refresh
X-S-Maxage
X-Server-IP
X-Shop-Environment
X-ShardId
X-Thanos
X-Thinkindot-L3
X-VServer
X-Vmg-Version
X-VG-WebCache
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-PAYTM-SRV-ID
X-Wix-Viewer-Type
X-VG-TLSProxy
X-Varnishpool
X-Var-Ttl
X-Up
X-Variation
X-Varnish-CookieHashed-On
X-Varnish-Remaining-TTL
X-Varnish-CookieINHashed-On
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-GeoIP-Region-Code
X-GeoIP-Country-Code
X-Generated-On
X-Hash
X-Human
X-Level-Front-Cache
X-Irp-Debug
X-Gdpr
X-Forwarded-Path
X-Core-Value
X-Core-Mission
X-Date
X-DefElseHash
X-DPWN-IS-SECURE
X-DefHash
X-Loc
X-Mid
X-Owner
X-Origin-Time
X-Orig-Expires
X-Platform
X-Policy
X-Qloud-Router
X-Pool
X-Org
X-Old-Content-Length
X-Nananana
X-Mvc-Supplant-Cachable
X-Nitro-Cache
X-Node-Id
X-Nyt-Route
X-NodeID
X-CMSURLCustom
X-BBC-Edge-Cache-Status
Expect-Staple
Environment
Fastly-Backend-Name
Gh-Request-Id
Mail-Subject
Is-Eu
Datacenter
CPC-Age
Adler-Geo
Producers
Cache-Name
Cmsid
Cmstype
Origin
CPC-Cache
Platform
User-Cache-Control
X-TIME
Country-Code
X-Auto-Login
X-WADP-Cache
X-WA-Info
X-Nginx-Cache-Key
DSUID
X-Akamai-Device-Characteristics
Server-Hostname
X-Correlation-ID
Server-Ext
X-Esi-Check
X-Cache-Id
Apple-News-Services-Handled
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
X-Fmm-Version
X-Test
X-Clara-WADP
Cf-Device-Type
CDCHOST
X-Block-Status
X-Hnp-Log
X-Forwarded-Site
AKAMAI
X-Device-Os
X-Geo-Header
X-Dispatcher-Server
X-GeoIP
X-Instance-Name
X-Origin-Response-Time
NM-Fastcgi-Cache
X-Origin
X-Gzip
X-INCAP-ABP
X-Mvc-Supplant-OutputCached
X-Gen-Mode
Sever-Int
X-ApacheServer
CloudFront-Viewer-Country
Esi-Enabled
X-AIR-PT
X-From
Fastly-GeoIP-CountryCode
X-PERF
X-Cdn-Diag
Content-Secure-Policy
X-Section
X-Cdn-Srv
X-Vgn-Hpd-Reason
X-Datadome
Pics-Label
X-ID
X-Op-Id-All
Wxu-Next-Commit
Wxu-Next-Hostname
Wxu-Next-Region
X-NCache
Machine
NGX
Ssr
X-Access
Server-Info
X-LB-NoCache
X-Via-Fastly
X-Cache-Enabled
C-Via
X-Accel-Version
X-Tcp-Rtt
X-Is-Supported-Browser
X-Is-Tablet
X-Browser-Name
X-Is-Desktop
Server-ID
X-Is-Mobile
X-Amz-Meta-Cb-Modifiedtime
X-API-Version
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Ttl
AMP-Access-Control-Allow-Source-Origin
X-HA-Backend
X-Vcl-Version
X-CACHE-GROUP
X-SIPLIST1
X-Presslabs-Stats
IsBot
X-Dc
X-Buckets
Memcached
X-JWT-State
X-Is-Gdpr
X-Has-Esi
X-Zone
X-B3-Parentspanid
Sid
Memory
Time
X-Platform-Cluster
Hostname
YJS-ID
X-Platform-Router
X-Platform-Processor
CF-Ctrl
X-Wp-Cf-Super-Cache-Active
X-Scale
Cdn-Requestid
X-Origin-Cache-Key
X-Cached-By
X-TA-CDN-Provider
Location
Cache-Hits
Origin-CC
Origin-EX
X-Air-Hostname
X-WP-CF-Super-Cache-Active
X-Air-Source
X-Air-Trace-Id
X-TIM-N
X-Tb-Optimization-Total-Bytes-Saved
X-Fpc
X-Internal-Host
X-Frame-Option
X-PHP-Backend
X-ZONE
X-NewRelic-App-Data
X-DC
Resin-Trace
X-Backend-Instance
X-Hyper-Cache
X-Cs
X-LiteSpeed-Cache-Control
X-Webstats-RespID
X-Azure-Ref-OriginShield
X-VC
X-Service
X-FTR-Backend-Server
X-FTR-Cache-Status
X-FTR-Balancer
X-FTR-Expires
X-FTR-Backend
X-Country-Code-Real
GeoIP-Latitude
X-DataCenter
LB
Epwk-X-Cache
True-Client-Ip
X-Site-Version
Uri
Cache-Host
X-NGINX-Cache
X-Locale
X-Nitro-Cache-From
X-Nitro-Rev
GeoIP-Country-Code
X-Origin-Expires
X-Microcachable
XM
GeoIp-Country-Code
X-Info
X-VCache
WebServer
Req-ID
X-NMSegId
X-Edge-Server
Cdn-Host
X-Datacenter
X-HN
WZWS-RAY
X-SRV
Cdn-Request-Time
X-VarnishDD-TTL
XServer
PFcat
Cdn
X-Pod-Name
X-Cache-Ttl
X-Web-Node
X-CSRF-TOKEN
X-Ad-Defer-Variation
X-Vercel-Id
X-Vercel-Cache
M-TraceId
X-Pad
True-Client-IP
NtCoent-Length
User-Agent
X-Ad-Load-Variation
X-Geo
X-CS
X-Request-URI
Edge-Copy-Time
A
X-Via-SSL
X-Github-Request-Id
Pramga
X-Request-Start
X-Via-Edge
X-Via-CDN
SID
X-Scope-Id
Locid
Cluster
X-FL-QIT-DEBUG
X-FL-EDGE
X-M-Log
Srvid
X-M-Reqid
X-FPC
Content-Script-Type
X-Varnish-Beresp-Status
X-Shield-Cache-Expires
Content-Style-Type
HostName
X-MSEdge-Flight
Fastly-Drupal-Html
X-MSEdge-Features
X-Qnm-Cache
X-HostName
Tcn
Edge-Cache
X-Moov-T
X-FireWall-Port
X-Varnish-Authentication
X-Moov-Xdn-Version
X-Contensis-Viewer-Groups
X-LiteSpeed-Tag
X-Cache-ASPX
Cache-Tv-Group
X-ATG-Version
X-Cache-Date
X-TRACE-ID
CountryCode
X-Cdn-Request-ID
X-Api-Version
X-APP-VERSION
Cf-Ipcountry
X-TH-Server
X-Esi
X-VCL-Version
X-NWS-UUID-VERIFY
X-Amz-Meta-Opti
Cache-Key
Cdncip
Path
Cdnsip
X-WP-CF-Super-Cache-Cookies-Bypass
X-AK-Request-ID
Tube-Got-Results
Tube-Return
X-SB
X-Acquia-Purge-Cdn-Unconfigured
X-Req
X-V-Cache
X-Cache-FS-Status
X-B3-Trace-ID
X-Aicache-OS
X-Via-Popn
X-Via-Poph
X-Via-Popv
X-LB-ID
Click-Count-Error
Tube-Get-Contents
Click-Count-Action-Start
X-Nc
X-Wa
Tube-Got-Eval
X-Branch-Name
X-Servedbyhost
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-Proxy-CacheRZ
MIME-Version
XkeyRZ
X-Vary
V-Age
X-Air-Pt
X-Men
Yak-Timeinfo
On-Server
X-UA
CDN
X-CACHE-KEY
X-Planisys-CDN-TTL
X-HS-Content-Campaign-Id
X-Planisys-CDN-Rules
Wpo-Cache-Status
Srv
X-Wp-Cf-Super-Cache-Cache-Control
X-Wp-Cf-Super-Cache
X-Fastly-Backend-Reqs
X-Render-Time
Geoip-Latitude
X-Platform-Server
X-Cdn-Forward
X-Tim-N
Wpo-Cache-Message
X-Planisys-CDN-Cache
Ngx-Var-Key
Proxy-Connection
X-Akamai-Pragma-Client-IP
State
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-Lb-Cache
CF-Cached-On
X-Release
X-Acquia-Application-Trace
X-Vgn-Hpd-Variations-Key
X-Vgn-Hpd-Ssi
X-User
X-Upstream-Ct
X-Generated-In
Priority
X-Fastly-Cache
X-Acquia-Application-UUID
X-Upstream-Ht
X-Ha-Backend
X-Vgn-Hpd-Cached
My-App
Server-Id
Lb
X-Dw-Trace-Id
X-Acquia-Site
X-Acquia-Purge-Tags
X-TT-LOGID
X-Fastly-Country-Code
Ohc-File-Size
X-Cache-Remote
X-Lb-Nocache
X-Sigma
X-Sigma-Backend
Ohc-Cache-HIT
X-HS-Status
X-EC-Lua
X-CUA
X-Rocket-Build-Number
X-Via-Ucdn
X-Varnish-Director
X-Traceid
PICS-Label
X-Iplb-Request-Id
Yjs-Id
X-Iplb-Instance
Warning
Vha6-Origin
Cache
X-Cached-Since
X-ElasticPress-Query
X-Snapshot-Date
X-Fastly-Cache-Hits
CACHE-MISS-TO-ORIGIN
Inserted-Into-Cache-At
X-Litespeed-Cache-Control
Ngx
X-CF-Cache-Header-Cache-Control
X-CF-Cache-Header-Vary
Cneonction
X-Miniprofiler-Ids
Log-Origin
X-RAMCache
X-Udemy-Cache-App-Namespace