Threat Level: green Handler on Duty: Daniel Wesemann

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
Pragma
X-Powered-By
X-XSS-Protection
CF-RAY
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
P3P
X-Cache-Hits
X-UA-Compatible
Alt-Svc
X-Xss-Protection
X-Served-By
CF-Ray
X-Download-Options
X-Timer
X-Request-Id
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
Access-Control-Allow-Credentials
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
X-Drupal-Cache
X-Generator
X-Cache-Status
X-Check
X-Cacheable
X-Envoy-Upstream-Service-Time
X-Request-ID
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Dns-Prefetch-Control
X-FRAME-OPTIONS
X-Iinfo
X-Drupal-Dynamic-Cache
Feature-Policy
X-Content-Security-Policy
Content-Encoding
Access-Control-Expose-Headers
Upgrade
Status
X-CDN
X-AspNetMvc-Version
Server-Timing
X-XSS-PROTECTION
Access-Control-Max-Age
X-Amz-Request-Id
Request-Context
X-Amz-Id-2
X-Turbo-Charged-By
X-AH-Environment
X-Via
X-Robots-Tag
X-Backend
X-Cache-Group
Cf-Edge-Cache
Host-Header
Keep-Alive
X-Proxy-Cache
X-Hacker
X-Server
X-Rq
X-Age
X-Server-Powered-By
Allow
X-Vhost
X-UA-Device
X-Varnish-Cache
X-Ws-Request-Id
EagleId
X-Dispatcher
X-Amz-Version-Id
Grace
Cf-Apo-Via
P3p
X-LiteSpeed-Cache
Nel
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Page-Speed
X-Device
Cf-Railgun
EagleEye-TraceId
X-Swift-CacheTime
X-Swift-SaveTime
X-Aws-Lambda-Call-Status
Ali-Swift-Global-Savetime
X-Pingback
X-Node
X-Host
Accept-CH
X-WebKit-CSP
X-Server-Id
Surrogate-Control
X-OneAgent-JS-Injection
X-Backend-Server
X-CST
X-Readtime
X-Nginx-Cache-Status
X-Akam-SW-Version
X-Content-Security-Policy-Report-Only
Permissions-Policy
X-Cache-Lookup
Request-Id
X-EdgeConnect-Origin-MEX-Latency
X-Application-Context
X-EdgeConnect-MidMile-RTT
X-Nginx-Upstream-Cache-Status
X-Cloud-Trace-Context
X-Trace
Accept-Ch-Lifetime
X-Response-Time
X-Edge
X-HW
X-Litespeed-Cache
X-Ua-Compatible
X-Mod-Pagespeed
Content-Location
X-Url
X-Clacks-Overhead
X-Ruxit-JS-Agent
Accept-CH-Lifetime
X-Oneagent-Js-Injection
X-Midtier
X-ECACHE
X-ESI
Rating
X-Amz-Server-Side-Encryption
X-Country
X-Mcache
X-Upstream
X-TtlSet
X-Vname
X-PC
Xkey
X-Vcap-Request-Id
X-MS-InvokeApp
Cache-Tag
X-Rack-Cache
X-D2id
Verso
Fastly-Restarts
Accept-Ch
X-Element-Page-Cache
X-Cache-TTL
X-Cdn-Fetch
X-Exp-Id
X-Kinja-Server
X-Use-Magma
X-Kinja-Revision
X-Kinja-Build
X-Kinja
X-Exp-Variant
X-GoogleNews-Bot
RTSS
Edge-Control
X-Content-Type
X-Powered-By-Plesk
X-VARITI-CCR
X-Ac
Origin-Trial
X-Navigation-Version
X-Cached
X-Abt-Application-Version
X-WebKit-CSP-Report-Only
X-Goog-Hash
X-GitHub-Request-Id
Service-Worker-Allowed
X-Ua-Device
X-Ruxit-Js-Agent
X-Country-Code
X-Amz-Rid
X-Middleton-Display
X-Sol
Pagespeed
Display
X-Mg-S
X-Ttl
X-B3-TraceId
X-Dw-Request-Base-Id
SPRequestGuid
X-SharePointHealthScore
X-Browser-Type
X-Server-Name
Arr-Disable-Session-Affinity
Cross-Origin-Opener-Policy
X-Varnish-TTL
X-Powered-CMS
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Instrumentation
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
AR-PoweredBy
AR-ATIME
X-Middleton-Response
AR-SID
Response
AR-Request-ID
X-Amzn-Trace-Id
SPIisLatency
SPRequestDuration
X-Cache-Key
AR-CACHE
X-Fastly-Request-ID
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-ORACLE-DMS-ECID
X-Cnection
X-ORACLE-DMS-RID
X-Jurisdiction
X-HP-Trace-Id
X-Version
X-HP-Webp
X-Accel-Expires
X-NF-Request-ID
X-T
Cache-Status
Front-End-Https
Cache-Tags
Edge-Cache-Tag
X-Ser
X-Client-IP
X-Px
X-MSEdge-Ref
X-Times
X-Webkit-Csp
Pinterest-Generated-By
X-Pinterest-Rid
Pinterest-Version
X-Fastcgi-Cache
Public-Key-Pins
X-Hits
Nginx-Cache
X-Recruiting
X-RateLimit-Remaining
X-B3-TraceId-Primal
Mrf-Cache-Status
MRF-Tech
X-Shield-Request-Id
X-Request-Received
X-Frontend
X-Request-Processing-Time
Server-Node
X-LLID
Access-Control-Request-Method
X-NWS-LOG-UUID
X-Ua-Browser
Payment
X-Webkit-CSP
X-DIS-Request-ID
TP-Cache
X-FastCGI-Cache
X-RateLimit-Limit
MicrosoftSharePointTeamServices
S
X-HS-Cache-Config
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Combine-CSS
X-Goog-Metageneration
TP-L2-Cache
X-Content-Digest
X-LB-Cache
X-B3-Traceid
Content-MD5
X-Distributor
X-PressLabs-Stats
X-Erf-Stays-Pdp-Viaduct-Migration-Web
Realpath
X-Geo-Country
X-Kinja-CCPA
X-Request-Handler-Origin-Region
X-Microsite
X-Ezoic-Cdn
X-Page-Id
Access-Control-Allow-Method
X-Forwarded-For
X-FB-Debug
Accept-Charset
Fastcgi-Cache
X-GUploader-UploadID
X-Envoy-Decorator-Operation
X-Webkit-CSP-Report-Only
X-Cluster-Name
X-Correlation-Id
X-Hostname
X-Protected-By
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Seen-By
X-Ratelimit-Remaining
X-Rid
Cleartype
TCN
X-B3-Sampled
DC
X-TTL
X-Origin-Cache
X-Origin-Server
X-Goog-Generation
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Debug-Info
X-Mobile
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-TEC-API-ROOT
Referer-Policy
X-Varnish-Backend
X-Logged-In
X-Newrelic-App-Data
X-Git-Hash
X-Ratelimit-Limit
X-Kinsta-Cache
X-Edge-Location-Klb
Cross-Origin-Resource-Policy
X-Azure-Ref
X-XRDS-Location
Alternate-Protocol
X-Contextid
X-Varnish-Grace
Healthy
X-Aspnet-Version
Surrogate-Key
X-App-Environment
X-Fb-Rlafr
X-Revision
X-Aspnet-Duration-Ms
X-Request-Guid
X-Route-Name
X-Is-Crawler
X-Grace
X-Amz-Replication-Status
X-Providence-Cookie
X-Flags
X-Amz-Meta-S3cmd-Attrs
Count-Hit
X-TT
X-Content-Options
X-Server-ID
X-Whom
X-Wix-Request-Id
X-Forwarded-Proto
X-IPS-LoggedIn
Filterid
Charset
MS-Author-Via
Viewport
X-Akamai-Edgescape
Frame-Options
X-Id
WPO-Cache-Status
X-App-Server
WPO-Cache-Message
X-Hosted-By
X-B
Paypal-Debug-Id
X-Cache-Age
X-Backend-Name
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Magnolia-Registration
X-Trace-Id
X-Daa-Tunnel
X-Activity-Id
X-Az
X-Cache-Control
X-AppVersion
X-Www-Served-By
Retry-After
X-Client-Ip
Section-Io-Cache
Server-Name
X-F-Cache
X-Type
Refresh
X-Upgrade-Enabled
X-Proxy-Cache-Info
X-Varnish-Server
Version
X-Varnish-Ttl
X-Time
X-Proxy
Host
X-App-Version
Akamai-GRN
VIX-Pulpo-Upstream-Status
X-Response-Served-From
X-Rule
X-Original-Request-Id
X-Http-Reason
VIX-Pulpo-Node
X-ARC
SD-X-WS
X-Cache-Rule
X-Rocket-Nginx-Serving-Static
X-Edge-Location
X-Akamai-Request-ID2
X-Status
X-User-Agent
X-Instance
X-Varnish-Age
X-UUID
Protected
Front
X-Cacheable-TTL
X-Environment-Context
Amp-Access-Control-Allow-Source-Origin
X-Unique-Id
X-N
X-Framework
X-Is-Bot
X-Rendered-As
X-Region
X-L-Path
X-Jobs
SRV
X-Cache-Grace
X-Source
X-FW-Hash
X-FW-Serve
X-FW-Server
X-FW-Static
X-FW-Dynamic
X-Page-View
X-Oracle-Dms-Ecid
Access-Control-Request-Headers
From-Origin
Fastly-SWR
Fastly-SIE
X-FW-Type
X-Cache-Time
X-FW-Version
X-EdgeConnect-Cache-Status
X-RemovedCookies
X-Tumblr-Pixel-1
X-ProcessESI
X-Tumblr-User
X-G
X-Adobe-Loc
X-Oracle-Dms-Rid
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Adobe-Content
X-Load-Cache
X-COUNTRY
ServerID
Content-Disposition
X-Drupal-Cache-Tags
Country
X-CDN-Forward
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
X-Datadog-Trace-Id
X-RateLimit-Reset
X-Language
X-HTML-Minification-Powered-By
X-Tt-Trace-Host
X-Tt-Trace-Tag
Accept-Language
X-Yottaa-Optimizations
Countrycode
X-Yottaa-Metrics
X-DynaTrace
X-Datadog-Sampled
X-Amzn-Remapped-Content-Length
Liferay-Portal
X-Mg-Request-UUID
X-Debug-IsPreview
X-Vcache
X-DynaTrace-JS-Agent
X-Debug-IsConnected
X-B3-SpanId
X-Generated-By
X-ID
X-XRDS-LOCATION
Xet-Cookie
X-Nf-Request-Id
Backend
CF-IPCountry
X-DataDome
X-Mode
X-Tt-Logid
Xserver
X-ECache
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
Webserver
X-Drupal-Cache-Contexts
X-Nginx-Cache
X-NYM-Debug-Backend
X-Content-Powered-By
X-B-Cache
X-Device-Type
X-Signature
X-Tec-Api-Version
X-Tec-Api-Root
X-Tec-Api-Origin
X-Zen-Fury
GEO-INFO
X-MCACHE
X-Httpd
Url
X-Ratelimit-Reset
X-Erf-Web-Scheduler
X-Servername
X-Content-Age
Load-Balancing
X-JoinUs
X-Rewrite-Enabled
X-Sucuri-Cache
X-Sucuri-ID
Filters
Azure-Version
Azure-SiteName
Azure-SlotName
X-UPSTREAM-Address
X-Urbn-Context-Path
X-Git-Commit
Locale
X-Varnish-Cache-Hits
X-Urbn-Site-Id
X-SaId
X-Director
X-ServerID
Onion-Location
X-Container-Uri
X-LAGOON
X-Cache-Action
X-Cache-Operation
S-Rt
Azure-RegionName
Azure-InstanceId
Meta-Geo
X-Say-Cacheable
X-Varnish-Hostname
X-Tb
X-SayCDN-TTL
X-Proto
X-Cluster-Node
X-Soup
X-Say-TTL
Uber-Trace-Id
X-Storage
X-Xrds-Location
X-Generation-Time
X-Forwarded-Host
X-VCT
Web-Mar-Node
X-PHP-Host
X-VC-Cache
X-Detected-As
X-Ms-Version
X-RM-Cache-TTL
X-Labrador-Cache-Channel
X-Ms-Request-Id
X-Served-From
X-Logging-Id
X-Adobe-Source
DB-Nickname
X-RCS-CacheZone
TWC-Device-Class
Property-Id
TWC-GeoIP-Country
X-GeoCountry
Mn-Server-Ip
Node
X-GeoCode
Webcakes-Region
X-Extlb
X-Uri
X-Skip-Cache
X-Origin-Hint
X-Routing-Service
X-Proxied
X-Cache-Server
X-Zipkin-Id
TWC-Privacy
TWC-Locale-Group
Webcakes-App-Name
Webcakes-App-Version
Fastcgi-Useragent
TWC-GeoIP-LatLong
TWC-Connection-Speed
X-Sql-Duration-Ms
X-Sql-Count
X-Format
X-Fetched-On
X-FB-TRIP-ID
Selected-Fe
X-Debug
X-Tumblr-Pixel-2
X-Tumblr-Pixel-3
X-Timing-Wait
X-LSADC-Cache
X-R9-Blue-Green-Version
X-Proxy-Build
X-Lambda-Id
X-MP-GENERATED-AT
X-Origin-Date
X-Cache-Expired-At
X-NGENIX-Cache
OT-Force-Account-Verify
X-Via-JSL
Fastly-Drupal-HTML
Source
CDN-RequestId
X-Cache-Hit
X-Template
X-Varnish-Hits
X-Node-Name
Content-Secure-Policy
X-Loop
X-Cache-TTL-Remaining
X-AIR-PT
X-UA-Device-Type
X-Tncms
X-Ua
X-Pass-Why
X-Endurance-Cache-Level
Upgrade-Insecure-Requests
X-Pubstack
X-Srv
X-Redis-Cache
Cross-Origin-Window-Policy
X-Server-W
NGB
X-Origin-TTL
X-PHP-Backend
X-Origin-CC
X-Real-IP
X-Fastly-Request-Id
X-CCDN-CacheTTL
X-CCDN-Origin-Time
X-TimeS
X-Datadome
Cache-Hits
X-Hcs-Proxy-Type
Section-Io-Id
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
X-RTag
Section-Io-Origin-Status
Ms-Operation-Id
MS-CV
X-Cache-Host
Cache-Name
X-S
X-Reqid
X-Restarts
X-Optimistic-Header
Cache-Provider
Apigw-Requestid
X-CSRF-Token
X-Cms-Context
X-Xfnlog-Site
X-IPLB-Request-ID
X-IPLB-Instance
CDN-Cache
CDN-PullZone
CDN-RequestCountryCode
X-Cache-Type
CDN-RequestPullCode
CDN-RequestPullSuccess
CDN-Uid
CDN-CachedAt
CDN-EdgeStorageId
X-Hl-Ver
X-ProxyCache-Key
X-BYPASS-REASON
X-No-Session
X-ProxyCache-Status
X-GEO
X-Via-Fastly
X-Cluster
X-AWS-Id
X-Newrelic-Synthetics
X-LJ-Flow-ID
X-VWS-Id
X-Aspnetmvc-Version
X-Section
X-Access
X-Rn-Rsrv
Redirect-Candidate
Rendered-Blocks
X-SRCache-Key
X-Tenant
X-TIM-N
X-Var-Ttl
X-VG-WebCache
X-Vdms-Version
X-Vdms-Path
Server-Host
Odigeo-Trace-Id
Sslversion
Web-Mar-Region
We-Hiring
X-Slack-Backend
X-Shop-Environment
BehaviorPad-Version
W
VNS-Cache
Surrogated-Key
X-Viewer-Country
T-Server
Vix-Hermes-Req-Id
VNS-Age
X-Slack-Shared-Secret-Outcome
X-Vtex-Remote-Cache
Xc-Version
Fastly-GeoIP-CountryCode
Gannett-Cam-Experience-Id
Gh-Request-Id
Ha-Gx-Prefs
Fastly-Backend-Name
DCR-Processing-Time-Ms
Candidate-Md5Url
Canary
CPC-Age
CPC-Cache
DCR-Decision-By
HA-Ipaddr
L
N-Cache
X-Wikidot-Static-Cache
Ngx.Var.Host
X-Wikidot-Backend
X-We-Are-Hiring
Meta-Geo-Continent
MD5-Digest
L5d-Success-Class
Lang
Magicmarker
Mail-Subject
X-A
X-SD-PageType
X-Epic-Correlation-Id
X-Bc-Bl
X-BCube-Filmed-By
X-CF-Lambda-Version
X-Ec-GeoHdr
X-B-Cookie
X-Application
X-D
X-External-Request-Id
X-CGP
X-Date
X-Eu-Site
X-Bl-Debug
X-Cache-Bucket
X-Debug-Cache-Store
X-Destination
X-CacheTTL
X-CF-Lambda-Fn
X-Cdn-Diag
X-Developer
X-Cache-NE
X-Cache-Info
X-Ec-Fail
X-Ec-Custom-Error
X-Dispatcher-Number
X-Fastly-Backend
X-FC-Vary-Parameters
X-A-Dgt
X-A-Dcw
X-Request-Host
X-RateLimit-Remaining-Second
X-Accel-Expires-Debug
X-Csrf-Jwt
X-Rojux
X-Debug-Cache-Fetch
X-A-Dam
X-ScT
X-S-Cookie
X-RateLimit-Limit-Second
X-Aed
X-Conf
X-GeoIP-Region-Code
X-GeoIP-Country-Code
X-Gdpr
X-Forwarded-Path
X-Irp-Debug
X-Mvc-Supplant-Cachable
X-Policy
X-Origin-Time
X-Orig-Expires
X-Nyt-Route
X-A-Ccd
X-A-Wwc
X-Akamai-Transformed
X-Proxy-Cache-Status
X-CACHE-AGE
X-Gzip
X-Geo-Header
X-Forwarded-Site
X-Esi-Check
X-Fmm-Version
X-Generated-On
X-Handled-By
X-Mly-Id
X-Node-Id
X-Mid
X-Level-Front-Cache
X-Human
X-INCAP-ABP
X-Hash
X-Core-Value
X-ApacheServer
X-App-Name
X-Auto-Login
X-Alternate-Cache-Key
Thinkindot-Control
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
X-BBC-Edge-Cache-Status
X-Bip
X-CMSURLCustom
X-Core-Mission
X-Clientip
X-Clara-WADP
X-Cache-Debug
X-Cache-Id
X-Old-Content-Length
X-Org
X-Varnishpool
X-VG-TLSProxy
X-WADP-Cache
X-Up
X-Thinkindot-L3
X-Test
X-Thanos
Fastly-SSL
True-Client-Country-4JS
X-Wix-Viewer-Type
X-Worker
X-JWT-State
X-Is-Gdpr
X-Accel-Buffering
X-Has-Esi
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-Pool
X-Request-Time
X-Platform
X-PERF
X-Origin-Response-Time
X-PAYTM-SRV-ID
X-S-Maxage
X-Server-IP
X-Sorting-Hat-ShopId
X-Storefront-Renderer-Rendered
X-Sorting-Hat-PodId
X-Shopify-Stage
X-ShardId
X-ShopId
TDXMobile
X-Owner
Environment
AKAMAI
Machine
Req-Svc-Chain
Host-ID
Memcached
Release
Origin
Datacenter
Cmstype
Cmsid
X-Vcl-Version
AMP-Access-Control-Allow-Source-Origin
User-Cache-Control
X-Web-Node
WP-Super-Cache
X-Qloud-Router
NM-Fastcgi-Cache
X-DefHash
Esi-Enabled
X-DefElseHash
X-DPWN-IS-SECURE
X-TA-CDN-Provider
X-Variation
X-Cdn-Origin
DSUID
X-Block-Status
X-Sn-Servicetimems
X-Cdn-Srv
X-Loc
Platform
X-WA-Info
X-Gen-Mode
X-Nananana
X-Hnp-Log
X-Mvc-Supplant-OutputCached
CloudFront-Viewer-Country
Country-Code
CDCHOST
X-From
Adler-Geo
X-Dispatcher-Server
Producers
X-Device-Os
X-Cs
Is-Eu
Expect-Staple
Apple-News-Services-Handled
X-Nginx-Cache-Key
X-NodeID
Apple-News-Services-Parsed-Url
X-Scale
X-Varnish-CookieINHashed-On
X-Parent-Response-Time
X-Varnish-Remaining-TTL
X-Vmg-Version
X-Origin
X-VServer
X-Varnish-CookieHashed-On
Server-Ext
ServedBy
Apple-News-Services-Host
Server-Hostname
Sever-Int
Apple-News-Services-Request-Url
X-Air-Trace-Id
X-Air-Source
X-Air-Hostname
Wxu-Next-Commit
X-Instance-Name
Wxu-Next-Hostname
Wxu-Next-Region
X-LB-NoCache
X-Presslabs-Stats
X-Nitro-Cache
Pics-Label
Ssr
X-NCache
X-Akamai-Device-Characteristics
X-GeoIP
X-App
X-Azure-Ref-OriginShield
X-Op-Id-All
Origin-CC
C-Via
Origin-EX
Memory
Server-Info
X-Cache-Enabled
Server-ID
X-Refresh
Time
X-Amz-Meta-Cb-Modifiedtime
X-TIME
X-Tx-Id
X-Platform-Router
X-Cache-Status-Check
X-HA-Backend
Cache-Host
X-Platform-Cluster
X-Microcachable
X-Platform-Processor
X-Site-Version
X-Locale
X-Origin-Expires
NGX
X-Dc
X-Correlation-ID
XM
X-HN
PFcat
X-VarnishDD-TTL
Hostname
X-Tb-Optimization-Total-Bytes-Saved
X-API-Version
X-VHOST
Resin-Trace
Cf-Device-Type
GeoIP-Latitude
X-CACHE-GROUP
Origin-Agent-Cluster
X-ZONE
Cdn-Requestid
X-Via-Edge
Srvid
X-Via-CDN
Locid
X-FL-QIT-DEBUG
X-Ad-Defer-Variation
A
Edge-Copy-Time
X-FL-EDGE
X-Via-SSL
X-Zone
X-Wp-Cf-Super-Cache-Active
X-Varnish-Beresp-Ttl
X-Upstream-Ct
X-Upstream-Ht
X-DC
X-Varnish-Beresp-Grace
X-Vgn-Hpd-Reason
Sid
X-Internal-Host
X-Webkit-Csp-Report-Only
X-Fpc
X-FireWall-Port
YJS-ID
X-ATG-Version
X-Contensis-Viewer-Groups
X-Cache-ASPX
Uri
Cache-Key
X-Micro-Cache
X-Github-Request-Id
X-Varnish-Authentication
True-Client-Ip
X-Moov-Xdn-Version
X-Cached-By
X-Moov-T
X-Pod-Name
X-WP-CF-Super-Cache-Active
X-LiteSpeed-Cache-Control
X-TraceId
X-DataCenter
User-Agent
X-VCache
X-Provided-By
X-Info
X-SIPLIST1
State
IsBot
X-Planisys-CDN-TTL
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-HS-Content-Campaign-Id
Location
X-B3-Spanid
X-URL
X-AB
X-Buckets
X-Fastly-Cache
X-RN-RSRV
X-B3-Parentspanid
GeoIP-Country-Code
X-Platform-Server
X-NewRelic-App-Data
X-Geo-Region
X-NGINX-Cache
X-Datacenter
X-Sigma
GeoIp-Country-Code
X-Backend-Instance
X-Nitro-Rev
X-Nitro-Cache-From
X-Sigma-Backend
X-Cache-Remote
X-VC
X-Rocket-Build-Number
X-Release
X-Api-Version
X-LiteSpeed-Tag
X-Geo
X-MSEdge-Flight
Cdn
X-Accel-Version
Cache
X-MSEdge-Features
SID
XServer
CF-Ctrl
X-Generated-In
X-Gamma-Serve
X-CS
X-FTR-Request-ID
X-CSRF-TOKEN
X-HostName
Tcn
Srv
X-Vgn-Hpd-Cached
Path
X-Vgn-Hpd-Ssi
X-Vgn-Hpd-Variations-Key
Cache-Tv-Group
True-Client-IP
X-GeoIP-City
NtCoent-Length
Lb
Fastly-Drupal-Html
X-Browser-Name
X-Is-Supported-Browser
X-Is-Mobile
X-Is-Tablet
X-Tcp-Rtt
X-Is-Desktop
X-Rebelmouse-Surrogate-Control
X-HS-Status
X-FPC
X-Rebelmouse-Cache-Control
X-Scheme
X-SRV
X-TRACE-ID
X-Frame-Option
HostName
Kp-EeAlive
Epwk-X-Cache
X-Hyper-Cache
Ohc-File-Size
X-GoCache-CacheStatus
X-Service
X-Mobile-URL
X-Location
X-Amz-Meta-Opti
X-APP-VERSION
X-UA
X-TX-ID
Cf-Ipcountry
Serverid
CountryCode
X-Aicache-OS
X-Region-Sid
X-Webstats-RespID
On-Server
X-Developers
X-Air-Pt
X-AK-Request-ID
X-Men
CacheControlHeader
X-Esi
Cdnsip
Cdncip
X-Guploader-Uploadid
Tube-Got-Eval
Tube-Got-Results
Tube-Return
V-Age
RNT-Time
X-Acquia-Purge-Cdn-Unconfigured
X-Branch-Name
X-Traceid
X-B3-Trace-ID
Tube-Get-Contents
X-Cache-FS-Status
Mime-Version
X-Req
X-LB-ID
X-Wp-Cf-Super-Cache-Cache-Control
X-Cache-Tags
Proxy-Connection
X-Via-Poph
WebServer
X-Wp-Cf-Super-Cache
X-Via-Popv
X-Via-Popn
Click-Count-Action-Start
X-V-Cache
Click-Count-Error
X-Cache-Ttl
X-SB
X-CDN-Cache-Status
RNT-Machine
X-Minions-Version
X-EC-Lua
X-Wp-Cf-Super-Cache-Cookies-Bypass
Env
WZWS-RAY
Yak-Timeinfo
X-Proxy-CacheRZ
XkeyRZ
X-Pad
X-Vc
X-Cdn-Cache-Status
ENV
CF-Cached-On
Ohc-Cache-HIT
WWW-Authenticate
X-Wa
X-Nc
X-Servedbyhost
Geoip-Latitude
X-VCL-Version
CDN
X-CACHE-KEY
LB
Cdn-Request-Time
X-Akamai-Pragma-Client-IP
X-Cdn-Forward
X-NWS-UUID-VERIFY
Cdn-Host
X-User
X-Edge-Server
X-Edge-Pop
X-Fastly-Country-Code
Ngx
X-Lb-Cache
X-Check-Cacheable
M-TraceId
Req-ID
X-Origin-Cache-Key
X-Processor
X-FTR-Balancer
X-FTR-Expires
X-FTR-Cache-Status
X-NMSegId
Content-Style-Type
X-Vercel-Cache
Server-Id
X-FTR-Backend
X-FTR-Backend-Server
X-Vercel-Id
X-Ha-Backend
X-Ckpd-Fst-Backend
X-TH-Server
X-RID
Content-Script-Type
X-Country-Code-Real
X-TT-LOGID
X-Acquia-Application-UUID
X-Render-Time
PICS-Label
X-Acquia-Site
X-Acquia-Purge-Tags
X-Lb-Nocache
X-Acquia-Application-Trace
X-Edge-POP
X-MiniProfiler-Ids
X-Snapshot-Date
X-IN-APIGATEWAYSSL
X-IN-APIGATEWAY
X-CUA
X-APP
X-Litespeed-Cache-Control
X-Ad-Load-Variation
HIT
Cluster
X-Dw-Trace-Id
X-Cdn-Request-ID
X-WP-CF-Super-Cache-Cookies-Bypass
X-Via-Ucdn
Yjs-Id
X-Service-Response-Time
X-Udemy-Cache-App-Namespace
X-Fastly-Backend-Reqs
X-Iauth-Set-Uid
Edge-Cache
X-Serial
Sm-Log-Id
X-Cache-Date
X-Response-By
CACHE-MISS-TO-ORIGIN
Inserted-Into-Cache-At
X-Miniprofiler-Ids
Log-Origin
X-M-Log
X-M-Reqid
X-ElasticPress-Query
X-Cached-Since
X-Fastly-Cache-Hits
Cneonction
Vha6-Origin
X-RAMCache