Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-Cache-Status
Link
Accept-Ranges
CF-RAY
ETag
X-XSS-Protection
Expect-CT
Pragma
X-Powered-By
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
Alt-Svc
X-UA-Compatible
X-Served-By
X-Xss-Protection
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-DNS-Prefetch-Control
X-Drupal-Cache
X-Cache-Status
X-Check
X-Generator
X-Cacheable
Timing-Allow-Origin
X-Content-Security-Policy
X-Iinfo
Feature-Policy
Status
X-Envoy-Upstream-Service-Time
Content-Encoding
Access-Control-Expose-Headers
P3p
X-Drupal-Dynamic-Cache
X-AspNetMvc-Version
X-CDN
Upgrade
X-Via
CF-Ray
X-Ws-Request-Id
Access-Control-Max-Age
X-Request-ID
Server-Timing
EagleId
X-Cache-Group
Report-To
X-Turbo-Charged-By
Keep-Alive
X-UA-Device
Request-Context
X-Age
X-Backend
X-Proxy-Cache
X-Server-Powered-By
X-AH-Environment
X-Robots-Tag
X-Hacker
X-Amz-Request-Id
X-Server
Host-Header
X-Amz-Id-2
Grace
X-Rq
X-LiteSpeed-Cache
X-Swift-CacheTime
X-Swift-SaveTime
X-Varnish-Cache
X-Nginx-Cache-Status
Ali-Swift-Global-Savetime
NEL
X-WebKit-CSP
X-Page-Speed
X-Vhost
EagleEye-TraceId
X-Ua-Compatible
X-Amz-Version-Id
X-Pingback
X-OneAgent-JS-Injection
X-Dispatcher
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Device
X-Cache-Spec
Accept-CH
X-Host
X-Server-Id
X-Dns-Prefetch-Control
Cf-Railgun
X-Node
X-Backend-Server
X-Readtime
Surrogate-Control
X-Akam-SW-Version
Request-Id
X-Response-Time
X-HW
X-Application-Context
Xkey
Content-Location
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Rating
X-Country
Accept-CH-Lifetime
X-B3-TraceId
X-Cloud-Trace-Context
X-Ruxit-JS-Agent
Accept-Ch-Lifetime
X-Cache-Lookup
X-Trace
X-Url
Allow
X-Ac
X-Content-Type
X-Vname
X-PC
X-TtlSet
X-Aws-Lambda-Call-Status
X-Clacks-Overhead
Edge-Control
X-Server-Name
X-Varnish-TTL
X-Mod-Pagespeed
X-ESI
Fastly-Restarts
Cache-Tag
X-Rack-Cache
Service-Worker-Allowed
X-FastCGI-Cache
X-VARITI-CCR
Verso
X-Element-Page-Cache
MS-Author-Via
X-Upstream
X-Vcap-Request-Id
X-MS-InvokeApp
X-Amz-Rid
X-GitHub-Request-Id
Public-Key-Pins
X-Dw-Request-Base-Id
X-Cached
X-Client-IP
X-Abt-Application-Version
X-D2id
X-Cnection
RTSS
X-Px
X-Cache-TTL
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
X-Kinja-Revision
X-Navigation-Version
X-Exp-Id
X-Cdn-Fetch
X-Kinja-Server
X-GoogleNews-Bot
X-Exp-Variant
X-Kinja-Build
X-Use-Magma
X-Kinja
Arr-Disable-Session-Affinity
X-Country-Code
Access-Control-Request-Method
X-Powered-By-Plesk
X-Goog-Hash
X-NF-Request-ID
X-TTL
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-Instrumentation
AR-SID
AR-CACHE
AR-Request-ID
AR-PoweredBy
AR-ATIME
X-Middleton-Display
Pagespeed
Display
X-Powered-CMS
X-Sol
X-Origin-Cache
X-Version
X-Middleton-Response
Response
X-LLID
X-MSEdge-Ref
X-Amz-Server-Side-Encryption
Nginx-Cache
TCN
X-Kinsta-Cache
X-Edge-Location-Klb
X-RateLimit-Remaining
X-Edge
Mrf-Cache-Status
MRF-Tech
X-B3-TraceId-Primal
X-Protected-By
X-CST
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-T
X-HP-Webp
X-HP-Trace-Id
X-Jurisdiction
X-Forwarded-For
X-Content-Security-Policy-Report-Only
X-Shield-Request-Id
X-Id
X-Aspnetmvc-Version
X-Mg-S
Edge-Cache-Tag
S
Content-MD5
X-Language
X-Ruxit-Js-Agent
SPRequestDuration
SPIisLatency
Fastcgi-Cache
Front-End-Https
X-Mid
Realpath
Server-Node
X-Request-Processing-Time
X-Request-Received
Filters
Pinterest-Version
X-Recruiting
Pinterest-Generated-By
X-Pinterest-Rid
X-Frontend
Server-Name
X-Ua-Browser
X-Content
X-Ab
X-MCACHE
X-Cache-Key
X-Ser
X-DynaTrace
X-NWS-LOG-UUID
X-HS-Cache-Config
X-HS-Hub-Id
X-HS-Content-Id
Accept-Ch
X-Yandex-Sdch-Disable
X-HS-Combine-CSS
X-Template
X-Ezoic-Cdn
X-Correlation-Id
SPRequestGuid
X-SharePointHealthScore
X-ECACHE
X-Hits
X-Parallel-Accel
X-Ttl
X-Tt-Trace-Host
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Tt-Trace-Tag
MicrosoftSharePointTeamServices
Cache-Tags
Charset
X-Page-Id
Cleartype
X-B3-Sampled
Host
Alternate-Protocol
X-Www-Served-By
X-Git-Hash
X-Content-Options
X-Geo-Country
Fusion-Content-Id
Fusion-Content-Source
X-Daa-Tunnel
Fusion-Component-Id
Fusion-Source
X-Debug-Info
Fusion-Template-Id
Fusion-Deployment-Id
X-DIS-Request-ID
X-Hostname
X-Amzn-Trace-Id
X-Content-Digest
X-Amz-Replication-Status
Cross-Origin-Opener-Policy
Filterid
X-Ratelimit-Limit
X-Varnish-Age
X-FB-Debug
X-Activity-Id
X-AppVersion
X-Az
X-Grace
X-Upgrade-Enabled
X-VCache
ServerID
X-F-Cache
X-N
X-Nginx-Upstream-Cache-Status
X-Accel-Expires
X-Forwarded-Proto
X-Origin-Server
X-Rid
X-Mobile-URL
Access-Control-Allow-Method
X-Fastly-Request-ID
X-Server-ID
X-Type
X-Aspnet-Duration-Ms
X-Flags
X-Route-Name
X-Providence-Cookie
X-Is-Crawler
X-LB-Cache
X-DataDome
X-Request-Guid
X-Whom
X-TT
X-GUploader-UploadID
X-Seen-By
Viewport
X-App-Environment
X-Goog-Generation
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
X-Varnish-Grace
Payment
X-Tb
X-WebKit-CSP-Report-Only
X-FW-Serve
X-FW-Dynamic
X-FW-Server
X-FW-Static
X-FW-Type
X-Distributor
X-FW-Hash
TP-L2-Cache
TP-Cache
X-User-Agent
Node
DC
Paypal-Debug-Id
X-Oneagent-Js-Injection
X-Fastly-Request-Id
Accept-Charset
X-Wix-Request-Id
X-XRDS-LOCATION
Country
X-App-Server
Fastcgi-Useragent
X-Ratelimit-Reset
X-Litespeed-Cache
X-Cache-Control
X-Cache-Rule
X-NGENIX-Cache
X-Tec-Api-Origin
X-Tec-Api-Version
X-Tec-Api-Root
X-Fastcgi-Cache
X-Webkit-Csp
X-Webkit-CSP
X-Origin-Upstream-Status
Version
X-Via-JSL
X-Drupal-Cache-Tags
X-Cluster-Name
X-Request-Handler-Origin-Region
X-Microsite
Referer-Policy
X-Buckets
X-Cache-Age
X-Logged-In
X-B-Cache
X-Signature
X-Contextid
Cache-Status
X-Erf-Bev-Bev-Is-Generated
X-Browser-Type
X-Erf-Bev-Bev
X-Node-Name
Refresh
X-Original-Request-Id
X-Response-Served-From
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
SD-X-WS
X-Mobile
X-Rendered-As
X-Vgn-Hpd-Reason
X-Real-IP
X-Varnish-Backend
X-Is-Bot
X-Cache-Expired-At
X-Load-Cache
X-Debug
X-IPLB-Instance
X-Jobs
X-Revision
Access-Control-Request-Headers
X-Page-View
X-Cacheable-TTL
X-B
X-Proxy-Cache-Status
NGB
Amp-Access-Control-Allow-Source-Origin
X-Device-Type
X-Proxy
X-Cache-Action
X-Yottaa-Optimizations
X-Instance
X-Yottaa-Metrics
X-RemovedCookies
X-ProcessESI
X-UUID
X-Rule
X-Drupal-Cache-Contexts
Surrogate-Key
Akamai-GRN
X-Framework
X-Debug-IsConnected
X-Debug-IsPreview
X-Cache-Time
X-FW-Version
X-G
X-Oracle-Dms-Rid
X-Oracle-Dms-Ecid
SID
X-Accel-Buffering
X-XRDS-Location
X-Air-Trace-Id
CF-IPCountry
X-Air-Source
X-Air-Hostname
X-PressLabs-Stats
X-Cache-NGX
DynaTrace
X-Nginx-Cache
Count-Hit
GEO-INFO
Uber-Trace-Id
X-Azure-Ref
X-Cache-Operation
X-Source
X-Presslabs-Stats
Liferay-Portal
X-Ms-Request-Id
X-Ms-Version
X-RateLimit-Limit
X-Zen-Fury
X-EdgeConnect-Cache-Status
X-APP-VERSION
Frame-Options
X-RTag
Ms-Operation-Id
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-CDN-Forward
MS-CV
Protected
Healthy
X-Cache-Hit
X-Backend-Name
X-Mode
Countrycode
Ec-Rule-Version
X-L-Path
X-IPS-LoggedIn
Cross-Origin-Window-Policy
X-Environment-Context
Xserver
X-Tumblr-Pixel-0
X-Hyper-Cache
X-Cache-TTL-Remaining
X-Servername
X-Tumblr-User
X-Tumblr-Pixel-1
X-Tumblr-Pixel
X-Varnish-Server
WPO-Cache-Status
WPO-Cache-Message
X-Trace-Id
X-Ratelimit-Remaining
Backend
LB
X-Adobe-Content
X-Adobe-Loc
X-Detected-As
X-Content-Age
X-RN-RSRV
X-JoinUs
X-Tid
X-Region
Meta-Geo
X-SaId
X-UPSTREAM-Address
Content-Disposition
X-Rewrite-Enabled
X-Shopify-Stage
X-ShardId
X-ShopId
X-Alternate-Cache-Key
X-Debug-Cache
X-Hosted-By
X-Format
X-Generation-Time
X-Extlb
X-Proxied
X-Cache-Server
X-Sorting-Hat-PodId
X-Uri
X-Zipkin-Id
X-Routing-Service
Apigw-Requestid
X-Sorting-Hat-ShopId
Decoy-Debug-TTL
X-Sql-Count
Country-Code
X-Redis-Cache
X-Sql-Duration-Ms
X-Forwarded-Host
Decoy-Debug-Status
Eomportal-Instance
Decoy-Debug-Key
CDN-RequestCountryCode
CDN-PullZone
CDN-Uid
CDN-EdgeStorageId
CDN-RequestId
Mn-Server-Ip
X-Access
X-Via-Fastly
X-ApacheServer
X-Cache-Grace
CDN-Cache
X-ServerID
CDN-CachedAt
Fastly-SSL
X-Site-Version
Url
Cache-Name
X-PHP-Backend
X-OCL
X-PCL
X-Origin-Date
X-PERF
X-Section
X-FB-TRIP-ID
X-NCache
X-Human
X-Varnish-Beresp-Grace
X-No-Session
X-Microcachable
X-Status
X-Web-Node
X-NYM-Debug-Backend
Property-Id
TWC-Connection-Speed
Selected-Fe
X-ProxyCache-Status
X-ProxyCache-Key
X-Storage
X-Generated-By
X-SayCDN-TTL
X-Say-Cacheable
X-Say-TTL
X-Proxy-Build
Webcakes-App-Name
X-Timing-Wait
X-Cache-Host
X-BYPASS-REASON
X-Cache-Type
X-Cluster-Node
X-Server-W
X-Content-Powered-By
X-UA-Device-Type
X-Akamai-Edgescape
X-Pubstack
TWC-Locale-Group
TWC-GeoIP-LatLong
TWC-Privacy
Webcakes-App-Version
X-Origin-Hint
Webcakes-Region
TWC-GeoIP-Country
TWC-Device-Class
Section-Io-Cache
Cache-Tv-Group
X-Hl-Ver
X-R9-Blue-Green-Version
X-Soup
X-Be
X-Varnishpool
Azure-SiteName
Azure-RegionName
Azure-InstanceId
Azure-SlotName
Content-Secure-Policy
Azure-Version
Retry-After
X-Ua
X-LSADC-Cache
X-NewRelic-App-Data
DB-Nickname
X-TIME
X-Nginx-Cache-Key
OT-Force-Account-Verify
X-Azure-Ref-OriginShield
X-Cached-By
X-Dc
X-Unique-Id
X-Cache-Remote
X-Bc-Bl
X-TT-LOGID
Source
X-Platform-Server
Cache
X-Auto-Login
X-Akamai-Transformed
SRV
X-Xfnlog-Site
X-LAGOON
X-Cdn
Upgrade-Insecure-Requests
ServedBy
HostName
X-Cache-Tags
X-GEO
X-Origin-TTL
X-Origin-CC
X-Correlation-ID
From-Origin
X-Varnish-Cache-Hits
X-Varnish-Hits
Cache-Hits
X-App-Version
X-EC-Lua
X-TNCMS
X-Loop
X-Request-Time
X-CSRF-Token
X-Varnish-Hostname
X-AOL-HN
X-S-Maxage
X-Time
Onion-Location
Xet-Cookie
WP-Super-Cache
Mime-Version
X-Request-Host
X-HTML-Minification-Powered-By
X-NWS-UUID-VERIFY
Webserver
X-SRV
X-ECache
Web-Mar-Node
X-Tumblr-Pixel-2
X-Tumblr-Pixel-3
N-Cache
X-Cache-Enabled
X-Proto
X-Amz-Meta-S3cmd-Attrs
X-B3-SpanId
X-Handled-By
X-FireWall-Port
X-Endurance-Cache-Level
X-Tenant
Nel
X-Origin-Response-Time
X-AWS-Id
X-VWS-Id
X-LJ-Flow-ID
Odigeo-Trace-Id
Fastcgi-X-Cache-Version
X-ND-Cache
X-Epic-Correlation-Id
X-Hnp-Log
X-Orig-Expires
Mobile-Detection-Method
BehaviorPad-Version
X-NAPM-TraceId
Expiry
X-S
X-Reqid
X-Developer
DCR-Processing-Time-Ms
X-Processor
X-Rojux
DCR-Decision-By
X-Gen-Mode
X-Planisys-CDN-TTL
A
X-Forwarded-Path
X-Planisys-CDN-Rules
X-Ftr-Request-Id
X-PBS-Appsvrname
X-Ig-Push-State
X-PAYTM-SRV-ID
X-Backend-TTL
S-Rt
X-GG-Cache-Date
Meta-Geo-Continent
X-RCS-CacheZone
X-External-Request-Id
X-Adobe-Source
X-Planisys-CDN-Cache
X-Time-Microsecs
X-Vtex-Remote-Cache
X-Vtex-Processado-Em
User-Cache-Control
Xc-Version
V-Age
X-Cache-NE
X-Vdms-Version
X-CF-Lambda-Fn
Surrogated-Key
X-V-Cache
X-Vdms-Path
Vix-Hermes-Req-Id
X-A
X-Block-Status
X-Application
X-ARC
X-B-Cookie
X-Aed
X-A-Wwc
X-A-Ccd
X-A-Dam
X-A-Dcw
X-A-Dgt
X-TIM-N
X-VG-WebCache
Rendered-Blocks
X-ScT
X-D
X-Slack-Backend
Sslversion
X-SD-PageType
X-Shop-Environment
Redirect-Candidate
Pramga
X-Session-Fingerprint
X-SRCache-Key
X-Connection-Hash
X-Conf
X-S-Cookie
X-Destination
X-Cluster
X-CF-Lambda-Version
X-Ckpd-Fst-Backend
X-Mg-Request-UUID
X-Edge-Location
X-Magnolia-Registration
X-MP-GENERATED-AT
X-Date
DSUID
CDCHOST
Arc-Country
Origin
X-Aicache-OS
Cmstype
Cmsid
X-Accel-Expires-Debug
X-Hash
CacheControlHeader
X-Cache-Bucket
X-Gdpr
True-Client-Country-4JS
X-Cache-Info
X-Forwarded-Site
X-Cdn-Srv
Host-ID
State
Svr
Gh-Request-Id
X-Geo-Header
Wxu-Next-Commit
Wxu-Next-Hostname
Wxu-Next-Region
Fastcgi-Cache-TTL
X-Cache-Date
X-GeoIP-Country-Code
X-Fastly-Cache
Apple-News-Services-Request-Url
X-GeoIP-Region-Code
X-Policy
X-Rocket-Nginx-Serving-Static
X-Scheme
Apple-News-Services-Parsed-Url
AMP-Access-Control-Allow-Source-Origin
X-Varnish-Ttl
X-Request-URI
X-Origin
X-Origin-Time
X-Proxy-Upstream
X-Sucuri-Cache
X-Sucuri-ID
X-Akamai-Request-ID2
X-Http-Reason
X-Origin-Expires
X-Webstats-RespID
X-Viewer-Country
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-VG-TLSProxy
X-Old-Content-Length
X-Server-IP
X-Li-Pop
Apple-News-Services-Host
X-Mvc-Supplant-Cachable
X-Men
X-Location
X-LI-UUID
X-Li-Fabric
Apple-News-Services-Handled
X-NodeID
AKAMAI
X-Nyt-Route
X-Cache-Var
X-Amzn-RequestId
X-Locale
X-Labrador-Cache-Channel
X-Via-NSCOPI
X-PHP-Host
X-Cache-Var-Map
Server-Info
CloudFront-Viewer-Country
Environment
X-Amz-Apigw-Id
Locid
X-VServer
X-Cache-Id
X-BBC-Edge-Cache-Status
X-HN
X-Sn-Servicetimems
X-Fastly-Backend
X-Cdn-Origin
X-Branch-Name
X-Cache-Debug
X-Fetched-On
X-Device-Os
Traceparent
X-Core-Mission
X-GeoIP
Origin-EX
X-VarnishDD-TTL
X-HS-Content-Campaign-Id
Origin-CC
X-GeoIP-City
X-Level-Front-Cache
X-Esi-Check
X-Eu-Site
X-Rocket-Build-Number
X-Envoy-Decorator-Operation
X-Gzip
X-Developers
X-Req
X-Region-Sid
X-Gamma-Serve
X-Owner
X-Platform
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Served-From
X-Datadog-Trace-Id
X-CGP
X-Generated-On
X-Irp-Debug
X-TH-Server
X-UnsetCookies
X-TrackingId
X-Storefront-Renderer-Rendered
X-Csrf-Jwt
X-Sigma
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
X-Sigma-Backend
X-Skip-Cache
X-Varnish-Beresp-Status
X-Core-Value
Release
HA-Ipaddr
PFcat
Req-Svc-Chain
Ha-Gx-Prefs
Server-Host
Fastly-GeoIP-CountryCode
Ssr
Web-Mar-Region
We-Hiring
L
X-Varnish-Beresp-Ttl
Fastly-Drupal-Html
Magicmarker
Mail-Subject
Machine
L5d-Success-Class
X-Xrds-Location
X-FC-Vary-Parameters
X-DPWN-IS-SECURE
X-Pod-Name
Memcached
X-Has-Esi
Is-Eu
X-ATG-Version
X-Node-Id
X-Backend-State
Thinkindot-Control
Thinkindot-CacheControl-Type
TDXMobile
Thinkindot-CacheControl
X-Thinkindot-L3
Adler-Geo
Platform
X-DefElseHash
X-JWT-State
Fastly-SWR
Cf-Device-Type
Fastly-SIE
X-DefHash
X-Is-Gdpr
X-Varnish-CookieHashed-On
X-Variation
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
X-Worker
NGX
X-Restarts
X-Response-By
X-NU-AKA-ACS-Version
X-Loc
NM-Fastcgi-Cache
X-Qloud-Router
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-Amzn-Remapped-Content-Length
X-Ua-Device
X-CS
X-Request-Start
X-VC-Cache
Kp-EeAlive
X-Zone
X-Tx-Id
X-Cache-Backend
X-Bip
CDN
X-M-Reqid
X-Wix-Viewer-Type
X-Qnm-Cache
X-Thanos
X-Up
X-M-Log
X-RPS
X-DSS
X-DW
X-DI
X-DB
X-Action
X-RPM
X-LB-ID
X-RSL
X-Mvc-Supplant-OutputCached
X-Srv
Accept-Language
Ms-Author-Via
Edge-Cache
Pics-Label
X-Generated-In
X-API-Version
X-Trace-ID
X-NC
X-TraceId
X-LB-NoCache
X-Tb-Optimization-Total-Bytes-Saved
X-CacheTTL
X-Minions-Version
X-Optimistic-Header
Time
Memory
X-Cache-Config
X-Via-Popv
X-Edge-Pop
WebServer
Env
X-Via-Popn
X-Via-Poph
X-Refresh
X-Urbn-Context-Path
X-Tt-Logid
Locale
X-Urbn-Site-Id
X-HA-Backend
X-Cache-Ttl
X-CACHE-KEY
GeoIp-Country-Code
X-DC
Datacenter
Candidate-Md5Url
NtCoent-Length
X-Datadome
X-ZONE
X-TA-CDN-Provider
X-User
X-Ec-Fail
X-Servedbyhost
X-Ec-GeoHdr
Server-ID
X-Esi
X-DynaTrace-JS-Agent
X-Parent-Response-Time
WWW-Authenticate
X-MSEdge-Features
On-Server
X-Dynatrace
X-TX-ID
X-MSEdge-Flight
X-Vc
X-CLOUD-TRACE-CONTEXT
X-Cs
Esi-Enabled
X-AK-Request-ID
Cdnsip
X-Varnish-Beresp-TTL
X-Unique-ID
Cdncip
X-Webkit-CSP-Report-Only
X-App
My-App
X-WADP-Cache
C-Via
Cluster
X-LI-Proto
X-Cache-PHP
X-Traceid
X-Clara-WADP
X-Fmm-Version
X-Fpc
X-VCL-Version
X-Service
X-URL
X-Webkit-Csp-Report-Only
X-Li-Proto
X-Newrelic-Synthetics
Tracecode
X-CUA
Geoip-Latitude
X-Pass-Why
Geo-Info
DataCenter
X-From
X-Var-Ttl
Lfy
X-B3-Spanid
X-FPC
X-Vcl-Version
T-Server
Test
Proxy-Connection
X-NODE
Cf-Int-Pingora-Origin-Digest
X-Fragments
Lang
X-Render-Time
X-Cache-Status-Check
X-VC
Fastly-Drupal-HTML
X-Mcache
X-LiteSpeed-Cache-Control
Target-Params
Resin-Trace
M-TraceId
MIME-Version
X-WP-CF-Super-Cache-Cache-Control
Server-Id
X-WP-CF-Super-Cache
X-CSRF-TOKEN
X-Geo
X-Ha-Backend
X-Provided-By
X-RAMCache
GeoIP-Country-Code
X-ID
Hostname
Hit
Permissions-Policy
X-Proxy-Cache-Info
X-ServedByHost
X-Httpd
X-Clientip
X-Api-Version
X-Dynatrace-Js-Agent
X-Oss-Storage-Class
X-Edge-POP
WZWS-RAY
Servername
X-Oss-Server-Time
X-Via-PopH
X-Oss-Object-Type
Producers
X-Via-PopN
X-Via-PopV
X-Cdn-Forward
X-LiteSpeed-Tag
Cache-Host
X-Oss-Request-Id
X-Pad
HIT
UCS
ENV
X-Oss-Hash-Crc64ecma
X-Info
X-AIR-PT
X-Edge-Cache
X-Fastly-Backend-Reqs
S-Cnection
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
X-SB
X-NGINX-Cache
FSS-Cache
Section-Origin-Responded
Section-Io-Id
X-Udemy-Cache-App-Namespace
X-Platform-Cluster
X-Ucs
X-ElasticPress-Query
X-Pool
X-Platform-Router
X-Platform-Processor
Ohc-File-Size
X-Check-Cacheable
X-Lb-Nocache
X-Ec-Custom-Error
X-Scale
ServerName
X-Micro-Cache
User-Agent
PICS-Label
X-GoCache-CacheStatus
X-HS-Status
X-Nc
X-BBC-Origin-Response-Status
URI
Cf-Ipcountry
X-Acquia-Application-Trace
X-Acquia-Application-UUID
X-Acquia-Purge-Tags
Fastly-Backend-Name
X-UP
X-Cache-CFC
X-Acquia-Site
Uri
X-Srcache-Store-Status
X-Srcache-Fetch-Status
X-RateLimit-Reset
Cteonnt-Length
X-Release
IsBot
Server-Ttl
Cneonction
MD5-Digest
Server-Ext
X-SIPLIST1
Load-Balancing
X-Cdn-Request-ID
X-Dispatcher-Number
X-Cache-Expires
Tcn
X-ServerName
X-Swift-Error
Sever-Int
X-Lb-Id
X-Fastly-Cache-Hits
Server-Hostname
X-Backend-Host
X-Dw-Trace-Id
X-Newrelic-App-Data
EpKe-Alive
X-Vcache
Wpo-Cache-Status
X-Akamai-ERRuleID
X-Akamai-ERPolicy
Wpo-Cache-Message
X-Via-Ucdn
X-Yottaa-OS
X-BCube-Filmed-By
X-Snapshot-Date
X-APP
CF-Cached-On
Vha6-Origin
X-B3-ParentSpanId
X-Cache-ASPX
X-Contensis-Viewer-Groups
Shield-Pop
X-TRACE-ID
X-Air-Pt
Sid
X-Cache-Ngx
X-HostName
Cdn
X-IN-APIGATEWAY
Inserted-Into-Cache-At
X-Cms-Context
X-Fetch-By
GeoIP-Latitude
X-Litespeed-Cache-Control
X-B3-Parentspanid
X-IN-APIGATEWAYSSL
X-Shopify-Generated-Cart-Token
X-Akamai-Pragma-Client-IP
Ohc-Cache-HIT
Path
X-Logging-Id
X-CacheKey
X-Apw-Hits
X-Apw-Access-Token
X-Varnish-Authentication
X-Apw-Access-Action
X-Apw-Access-Object
X-UA
Req-ID
X-Te-Count
X-Te-Duration-Ms
X-Last-Modified
X-Http-Duration-Ms
X-Http-Count
CountryCode
X-Sentry-ID
Ngx
X-Akamai-Request-ID