Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-Cache-Status
Link
Accept-Ranges
CF-RAY
ETag
X-XSS-Protection
Expect-CT
Pragma
X-Powered-By
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
Alt-Svc
P3P
X-Served-By
X-Xss-Protection
X-Download-Options
X-Timer
X-Request-Id
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Cache-Status
X-Check
X-Generator
X-Cacheable
Timing-Allow-Origin
P3p
X-Content-Security-Policy
X-Iinfo
Feature-Policy
Status
X-Envoy-Upstream-Service-Time
Content-Encoding
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
X-CDN
X-Request-ID
X-AspNetMvc-Version
Upgrade
X-Via
CF-Ray
X-Ws-Request-Id
Access-Control-Max-Age
Server-Timing
EagleId
X-Cache-Group
X-Turbo-Charged-By
Keep-Alive
Request-Context
X-UA-Device
Report-To
X-Age
X-Backend
X-Server-Powered-By
X-Proxy-Cache
X-AH-Environment
X-Robots-Tag
X-Hacker
X-Amz-Request-Id
X-Server
Host-Header
X-Amz-Id-2
Grace
X-Rq
X-Nginx-Cache-Status
X-Swift-SaveTime
X-Swift-CacheTime
X-Varnish-Cache
X-LiteSpeed-Cache
Ali-Swift-Global-Savetime
X-WebKit-CSP
X-Page-Speed
NEL
X-Vhost
X-Ua-Compatible
EagleEye-TraceId
X-Amz-Version-Id
X-OneAgent-JS-Injection
X-Dns-Prefetch-Control
X-Pingback
X-Dispatcher
X-Device
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Cache-Spec
X-Host
X-Server-Id
Cf-Railgun
Accept-CH
X-Node
X-Backend-Server
X-Readtime
Surrogate-Control
X-Akam-SW-Version
Request-Id
X-Response-Time
X-HW
Xkey
X-Application-Context
X-EdgeConnect-Origin-MEX-Latency
Content-Location
X-EdgeConnect-MidMile-RTT
Rating
X-Ruxit-JS-Agent
X-Country
X-B3-TraceId
Accept-CH-Lifetime
X-Cloud-Trace-Context
Accept-Ch-Lifetime
X-Cache-Lookup
X-Trace
X-Url
X-Ac
X-Content-Type
X-Vname
X-PC
Allow
X-TtlSet
X-Varnish-TTL
X-Clacks-Overhead
Edge-Control
X-Mod-Pagespeed
X-Server-Name
X-ESI
Fastly-Restarts
X-Aws-Lambda-Call-Status
Cache-Tag
X-FastCGI-Cache
X-VARITI-CCR
Service-Worker-Allowed
X-Rack-Cache
Verso
X-Element-Page-Cache
X-Upstream
X-Vcap-Request-Id
X-MS-InvokeApp
X-GitHub-Request-Id
X-Amz-Rid
MS-Author-Via
Public-Key-Pins
X-Dw-Request-Base-Id
X-Cached
X-Client-IP
X-Abt-Application-Version
X-Cache-TTL
X-D2id
X-Cnection
RTSS
X-Px
X-Kinja-Build
X-GoogleNews-Bot
X-Kinja
X-Use-Magma
X-Exp-Id
X-Cdn-Fetch
X-Exp-Variant
X-Country-Code
X-Kinja-Revision
X-Kinja-Server
Access-Control-Request-Method
Arr-Disable-Session-Affinity
X-Powered-By-Plesk
X-Goog-Hash
X-Navigation-Version
X-NF-Request-ID
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Instrumentation
X-Powered-CMS
AR-PoweredBy
AR-ATIME
AR-CACHE
AR-Request-ID
AR-SID
X-Origin-Cache
Pagespeed
X-Middleton-Display
X-Version
Display
X-Sol
X-Middleton-Response
Response
X-TTL
X-LLID
X-Amz-Server-Side-Encryption
X-MSEdge-Ref
Accept-Ch
X-Kinsta-Cache
X-Edge-Location-Klb
TCN
X-SRCache-Fetch-Status
Nginx-Cache
X-SRCache-Store-Status
X-Edge
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
X-RateLimit-Remaining
X-Protected-By
X-T
X-HP-Webp
X-HP-Trace-Id
X-Jurisdiction
X-Forwarded-For
X-Content-Security-Policy-Report-Only
X-Shield-Request-Id
X-Aspnetmvc-Version
X-Id
X-Mg-S
S
Content-MD5
Edge-Cache-Tag
X-CST
X-Language
SPIisLatency
SPRequestDuration
Front-End-Https
Fastcgi-Cache
X-Mid
X-DynaTrace
Realpath
X-Request-Processing-Time
X-Request-Received
Server-Node
Pinterest-Version
Pinterest-Generated-By
X-Pinterest-Rid
Filters
X-Recruiting
X-Frontend
Server-Name
X-MCACHE
X-Ab
X-Content
X-Ua-Browser
X-Ruxit-Js-Agent
X-Correlation-Id
X-Ser
X-Cache-Key
X-Ttl
X-HS-Content-Id
X-HS-Cache-Config
X-HS-Hub-Id
X-Yandex-Sdch-Disable
X-HS-Combine-CSS
X-NWS-LOG-UUID
X-Template
X-Ezoic-Cdn
X-ECACHE
X-SharePointHealthScore
SPRequestGuid
X-Hits
X-Parallel-Accel
X-Tt-Trace-Host
MicrosoftSharePointTeamServices
X-Tt-Trace-Tag
Cache-Tags
X-Kong-Upstream-Latency
Alternate-Protocol
X-Kong-Proxy-Latency
Charset
X-Page-Id
X-B3-Sampled
Fusion-Source
Fusion-Template-Id
Host
Cleartype
Fusion-Deployment-Id
Fusion-Content-Source
Fusion-Component-Id
Fusion-Content-Id
X-Litespeed-Cache
X-Www-Served-By
X-Git-Hash
X-Content-Options
X-Geo-Country
X-Webkit-Csp
X-Debug-Info
X-Hostname
X-DIS-Request-ID
X-Daa-Tunnel
X-Amzn-Trace-Id
X-Amz-Replication-Status
X-Content-Digest
Filterid
X-Varnish-Age
Cross-Origin-Opener-Policy
X-Ratelimit-Limit
X-FB-Debug
X-Activity-Id
X-Az
X-AppVersion
X-Upgrade-Enabled
X-VCache
X-Accel-Expires
X-Grace
X-N
X-F-Cache
X-Nginx-Upstream-Cache-Status
X-Forwarded-Proto
ServerID
X-Origin-Server
X-Rid
Access-Control-Allow-Method
X-Mobile-URL
X-Fastly-Request-Id
X-Request-Guid
X-Aspnet-Duration-Ms
X-Providence-Cookie
X-Is-Crawler
X-Flags
X-Route-Name
TP-L2-Cache
X-Server-ID
X-LB-Cache
TP-Cache
X-Type
X-TT
X-Whom
X-Goog-Storage-Class
X-Goog-Metageneration
X-Varnish-Grace
Viewport
X-GUploader-UploadID
X-Goog-Stored-Content-Length
X-App-Environment
X-Seen-By
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-Tb
Payment
X-WebKit-CSP-Report-Only
X-FW-Server
X-FW-Hash
X-FW-Serve
X-FW-Dynamic
Node
X-FW-Static
X-Distributor
X-FW-Type
X-DataDome
Paypal-Debug-Id
X-User-Agent
DC
X-XRDS-LOCATION
X-App-Server
X-Fastly-Request-ID
Accept-Charset
Country
Fastcgi-Useragent
X-Wix-Request-Id
X-NGENIX-Cache
X-Cache-Control
X-Cache-Rule
X-Fastcgi-Cache
X-Origin-Upstream-Status
Version
X-Via-JSL
Referer-Policy
X-Drupal-Cache-Tags
X-Microsite
X-Request-Handler-Origin-Region
X-Oracle-Dms-Rid
X-Oracle-Dms-Ecid
X-Cluster-Name
X-Logged-In
Amp-Access-Control-Allow-Source-Origin
X-Contextid
X-Buckets
X-Cache-Age
X-Tec-Api-Root
X-Tec-Api-Origin
X-Signature
X-Ratelimit-Reset
X-B-Cache
X-Tec-Api-Version
X-Erf-Bev-Bev
Cache-Status
Refresh
X-Browser-Type
X-Erf-Bev-Bev-Is-Generated
SD-X-WS
X-Node-Name
X-Original-Request-Id
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-Load-Cache
X-Mobile
X-Response-Served-From
X-Varnish-Backend
X-Cache-Expired-At
X-Real-IP
X-Page-View
X-Is-Bot
X-Rendered-As
X-Vgn-Hpd-Reason
X-B
X-Proxy-Cache-Status
NGB
X-Debug
Access-Control-Request-Headers
X-IPLB-Instance
X-Revision
X-Cacheable-TTL
X-Jobs
X-Yottaa-Metrics
X-Device-Type
X-Yottaa-Optimizations
X-Rule
X-Cache-Action
X-Proxy
X-Instance
X-Drupal-Cache-Contexts
Akamai-GRN
X-ProcessESI
X-UUID
X-RemovedCookies
Surrogate-Key
X-Cache-Time
X-Framework
X-Debug-IsConnected
X-FW-Version
X-G
X-Debug-IsPreview
CF-IPCountry
SID
X-Air-Trace-Id
X-Air-Hostname
X-Air-Source
GEO-INFO
DynaTrace
X-Accel-Buffering
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-PressLabs-Stats
X-TEC-API-ROOT
X-Oneagent-Js-Injection
X-Azure-Ref
X-Nginx-Cache
X-Cache-NGX
Count-Hit
Liferay-Portal
X-Source
X-Ms-Request-Id
X-Ms-Version
X-Presslabs-Stats
Uber-Trace-Id
X-Cache-Operation
X-XRDS-Location
Frame-Options
X-Zen-Fury
X-CDN-Forward
X-APP-VERSION
X-EdgeConnect-Cache-Status
Healthy
X-RTag
MS-CV
Ms-Operation-Id
Protected
X-Cache-Hit
X-RateLimit-Limit
X-L-Path
X-Environment-Context
Countrycode
X-Backend-Name
Xserver
X-Mode
X-IPS-LoggedIn
X-Tumblr-User
Cross-Origin-Window-Policy
X-Varnish-Server
Ec-Rule-Version
X-Tumblr-Pixel-1
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Cache-TTL-Remaining
LB
X-Ratelimit-Remaining
X-Hyper-Cache
Backend
X-Region
X-Tid
Meta-Geo
X-UPSTREAM-Address
X-Servername
X-Content-Age
X-Adobe-Loc
X-Detected-As
X-SaId
X-Adobe-Content
X-JoinUs
X-Rewrite-Enabled
X-Forwarded-Host
X-RN-RSRV
X-Extlb
X-Sorting-Hat-PodId
X-ShopId
X-Format
X-Debug-Cache
X-Routing-Service
X-Hosted-By
X-Sql-Duration-Ms
X-Sql-Count
X-Cache-Grace
X-Sorting-Hat-ShopId
X-Alternate-Cache-Key
Decoy-Debug-Key
Decoy-Debug-Status
Decoy-Debug-TTL
Eomportal-Instance
X-Proxied
Country-Code
X-Redis-Cache
X-Shopify-Stage
Section-Io-Cache
Apigw-Requestid
X-Cache-Server
X-Generation-Time
WPO-Cache-Status
X-ShardId
X-Zipkin-Id
WPO-Cache-Message
X-Uri
X-FB-TRIP-ID
X-ServerID
Content-Disposition
Cache-Name
X-PERF
X-PCL
Url
X-Site-Version
X-Section
X-ApacheServer
X-Access
Mn-Server-Ip
X-Varnish-Beresp-Grace
Fastly-SSL
X-NCache
X-No-Session
X-OCL
X-Origin-Date
X-Microcachable
X-Human
X-Status
X-PHP-Backend
X-Via-Fastly
Webcakes-App-Version
Webcakes-App-Name
CDN-Cache
Selected-Fe
Webcakes-Region
Property-Id
X-Say-TTL
TWC-Connection-Speed
TWC-Device-Class
TWC-Locale-Group
TWC-GeoIP-LatLong
TWC-GeoIP-Country
CDN-Uid
X-Cache-Host
CDN-RequestCountryCode
CDN-PullZone
X-Say-Cacheable
X-Origin-Hint
X-ProxyCache-Status
X-Storage
CDN-RequestId
X-NYM-Debug-Backend
X-Pubstack
CDN-EdgeStorageId
X-ProxyCache-Key
X-BYPASS-REASON
X-Akamai-Edgescape
X-Timing-Wait
X-UA-Device-Type
X-SayCDN-TTL
X-Cache-Type
X-Server-W
CDN-CachedAt
X-Cluster-Node
X-Proxy-Build
TWC-Privacy
Cache-Tv-Group
X-Content-Powered-By
X-Soup
X-NewRelic-App-Data
X-Web-Node
X-Varnishpool
X-Be
X-R9-Blue-Green-Version
X-Generated-By
Azure-SiteName
Azure-RegionName
Content-Secure-Policy
X-Hl-Ver
Azure-InstanceId
Azure-SlotName
Azure-Version
X-Ua
X-LSADC-Cache
X-Webkit-CSP
DB-Nickname
X-TIME
X-Trace-Id
X-Azure-Ref-OriginShield
OT-Force-Account-Verify
X-Nginx-Cache-Key
X-Cached-By
Retry-After
Source
X-TT-LOGID
X-Bc-Bl
X-Unique-Id
SRV
Cache
X-Cache-Remote
X-Auto-Login
X-Dc
X-Akamai-Transformed
X-Platform-Server
X-SRV
X-LAGOON
X-GEO
X-Xfnlog-Site
X-Cdn
X-Cache-Tags
X-Varnish-Hits
X-EC-Lua
Upgrade-Insecure-Requests
ServedBy
Cache-Hits
HostName
X-Origin-TTL
X-Origin-CC
X-Loop
Mime-Version
X-HTML-Minification-Powered-By
X-Varnish-Hostname
X-App-Version
X-TNCMS
X-S-Maxage
Onion-Location
X-Varnish-Cache-Hits
X-CSRF-Token
X-Request-Time
X-Time
From-Origin
X-AOL-HN
Xet-Cookie
X-Tumblr-Pixel-3
X-Request-Host
X-Tumblr-Pixel-2
WP-Super-Cache
X-Amz-Meta-S3cmd-Attrs
Webserver
Web-Mar-Node
N-Cache
X-ECache
X-Xrds-Location
X-Proto
X-B3-SpanId
X-Cache-Enabled
X-Tenant
X-NWS-UUID-VERIFY
X-FireWall-Port
X-LJ-Flow-ID
X-Correlation-ID
X-VWS-Id
X-AWS-Id
Ms-Author-Via
Nel
X-Handled-By
X-Time-Microsecs
X-Endurance-Cache-Level
X-Origin-Response-Time
X-GG-Cache-Date
X-V-Cache
X-TIM-N
X-D
X-A-Dcw
X-Vtex-Processado-Em
X-Vdms-Path
X-Aed
X-Connection-Hash
X-Vtex-Remote-Cache
X-A-Wwc
X-External-Request-Id
X-Cache-Var-Map
Xc-Version
X-Cache-Var
X-Epic-Correlation-Id
X-Destination
DCR-Processing-Time-Ms
X-Developer
X-Vdms-Version
X-Conf
X-Backend-TTL
X-Forwarded-Path
X-B-Cookie
X-Cache-NE
X-A-Ccd
X-Block-Status
DCR-Decision-By
X-VG-WebCache
X-A
Expiry
X-CF-Lambda-Version
X-Ckpd-Fst-Backend
X-Cluster
X-Aicache-OS
X-Application
X-CF-Lambda-Fn
X-ARC
X-A-Dam
X-Gen-Mode
X-NAPM-TraceId
X-ND-Cache
Surrogated-Key
Rendered-Blocks
Redirect-Candidate
Fastcgi-X-Cache-Version
V-Age
User-Cache-Control
X-ScT
Meta-Geo-Continent
Sslversion
Mobile-Detection-Method
BehaviorPad-Version
Odigeo-Trace-Id
X-Rojux
X-S
X-S-Cookie
X-Orig-Expires
X-A-Dgt
A
X-SD-PageType
X-Planisys-CDN-Rules
Vix-Hermes-Req-Id
X-Processor
X-PBS-Appsvrname
X-PAYTM-SRV-ID
X-Planisys-CDN-Cache
X-Ftr-Request-Id
X-SRCache-Key
X-Planisys-CDN-TTL
X-Edge-Location
X-Ig-Push-State
X-Session-Fingerprint
X-Slack-Backend
X-Hnp-Log
X-Shop-Environment
Pramga
X-Magnolia-Registration
X-Adobe-Source
X-Reqid
X-RCS-CacheZone
X-MP-GENERATED-AT
True-Client-Country-4JS
Wxu-Next-Commit
Wxu-Next-Hostname
Wxu-Next-Region
Fastcgi-Cache-TTL
Gh-Request-Id
State
Svr
Origin
X-Li-Fabric
X-Origin-Time
X-Policy
X-Proxy-Upstream
X-Origin-Expires
X-Origin
X-Nyt-Route
X-Old-Content-Length
X-Request-URI
X-Rocket-Nginx-Serving-Static
X-VG-TLSProxy
X-Viewer-Country
X-Webstats-RespID
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-Scheme
X-Server-IP
X-NodeID
X-Mvc-Supplant-Cachable
X-Fastly-Cache
X-Forwarded-Site
X-Gdpr
X-Date
X-Cdn-Srv
X-Cache-Bucket
X-Cache-Info
X-Geo-Header
X-GeoIP-Country-Code
X-LI-UUID
X-Men
X-Li-Pop
DSUID
X-GeoIP-Region-Code
X-Hash
X-Accel-Expires-Debug
X-Cache-Date
Arc-Country
X-Amzn-RequestId
CacheControlHeader
CDCHOST
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
X-PHP-Host
AKAMAI
Apple-News-Services-Handled
Apple-News-Services-Host
X-Amz-Apigw-Id
X-Labrador-Cache-Channel
Cmsid
CloudFront-Viewer-Country
Cmstype
Environment
X-Via-NSCOPI
X-Mg-Request-UUID
X-Backend-State
X-BBC-Edge-Cache-Status
X-Platform
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Owner
X-Branch-Name
X-Location
S-Rt
X-Cache-Id
X-Cache-Debug
X-Region-Sid
L5d-Success-Class
X-Sigma
Web-Mar-Region
We-Hiring
X-Sigma-Backend
X-Served-From
X-Gamma-Serve
X-VServer
Ha-Gx-Prefs
X-Rocket-Build-Number
Server-Info
X-Locale
X-Cdn-Origin
X-Gzip
X-Envoy-Decorator-Operation
X-Device-Os
X-Developers
X-Esi-Check
X-Eu-Site
X-GeoIP
X-Fetched-On
X-GeoIP-City
X-Fastly-Backend
X-Varnish-Beresp-Ttl
X-HN
X-HS-Content-Campaign-Id
X-Irp-Debug
X-CGP
Fastly-Drupal-Html
X-Core-Mission
X-Csrf-Jwt
HA-Ipaddr
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
X-Skip-Cache
X-Req
X-Sucuri-Cache
Ssr
L
Req-Svc-Chain
Origin-CC
X-Sucuri-ID
Host-ID
Fastly-GeoIP-CountryCode
Locid
X-TrackingId
Machine
X-TH-Server
X-VarnishDD-TTL
X-Sn-Servicetimems
X-Varnish-Beresp-Status
Origin-EX
Mail-Subject
Traceparent
X-UnsetCookies
PFcat
X-Storefront-Renderer-Rendered
Release
X-DPWN-IS-SECURE
X-Node-Id
X-Akamai-Request-ID2
X-JWT-State
Platform
X-Tx-Id
X-Variation
X-Core-Value
Fastly-SIE
X-Is-Gdpr
X-Level-Front-Cache
Fastly-SWR
X-NU-AKA-ACS-Version
X-Loc
Server-Host
X-Response-By
X-DefHash
X-Request-Start
Cf-Device-Type
Magicmarker
X-Varnish-CookieHashed-On
Memcached
Adler-Geo
X-Generated-On
X-FC-Vary-Parameters
X-Varnish-CookieINHashed-On
X-Rebelmouse-Surrogate-Control
X-Amzn-Remapped-Content-Length
X-DefElseHash
NM-Fastcgi-Cache
X-Varnish-Remaining-TTL
X-Http-Reason
Is-Eu
X-Pod-Name
X-Rebelmouse-Cache-Control
X-Worker
X-Qloud-Router
X-ATG-Version
X-Has-Esi
X-Trace-ID
X-M-Log
X-M-Reqid
X-VC-Cache
X-Qnm-Cache
X-Ua-Device
X-Thanos
Thinkindot-CacheControl-Type
Thinkindot-Control
NGX
X-CS
Thinkindot-CacheControl
TDXMobile
X-Thinkindot-L3
AMP-Access-Control-Allow-Source-Origin
X-Bip
X-Restarts
X-Zone
X-Mvc-Supplant-OutputCached
Kp-EeAlive
X-Up
X-LB-ID
X-NC
X-API-Version
X-DI
X-DSS
X-RPM
X-DB
X-DW
X-Action
X-Cache-Config
Pics-Label
X-LB-NoCache
X-RPS
CDN
X-Generated-In
X-Wix-Viewer-Type
X-Cache-Backend
Edge-Cache
X-RSL
X-TraceId
Accept-Language
Time
Env
Memory
X-Tb-Optimization-Total-Bytes-Saved
Datacenter
X-Via-Popn
X-Via-Poph
X-Refresh
X-Minions-Version
X-Via-Popv
WebServer
X-Optimistic-Header
X-DC
X-Varnish-Ttl
X-CacheTTL
X-Tt-Logid
X-HA-Backend
NtCoent-Length
Candidate-Md5Url
X-Edge-Pop
X-Srv
X-CACHE-KEY
X-Urbn-Site-Id
Locale
X-Urbn-Context-Path
GeoIp-Country-Code
X-DynaTrace-JS-Agent
X-ZONE
Server-ID
X-Vc
X-MSEdge-Flight
X-Servedbyhost
X-MSEdge-Features
WWW-Authenticate
On-Server
X-Esi
X-Datadome
X-Ec-GeoHdr
X-Ec-Fail
Esi-Enabled
X-User
X-Unique-ID
X-Parent-Response-Time
X-CLOUD-TRACE-CONTEXT
X-Cs
X-Webkit-Csp-Report-Only
X-TX-ID
X-TA-CDN-Provider
X-Cache-PHP
X-Varnish-Beresp-TTL
X-Service
C-Via
X-VCL-Version
X-Newrelic-Synthetics
X-AK-Request-ID
X-App
X-Traceid
X-Cache-Ttl
X-LI-Proto
X-Fpc
Cdnsip
Cdncip
X-URL
X-Fmm-Version
X-WADP-Cache
X-Clara-WADP
Test
My-App
X-LiteSpeed-Cache-Control
Cluster
X-Li-Proto
Proxy-Connection
X-Render-Time
X-CUA
X-FPC
X-Cache-Status-Check
Tracecode
X-B3-Spanid
X-Var-Ttl
Geoip-Latitude
X-Webkit-CSP-Report-Only
X-NODE
Cf-Int-Pingora-Origin-Digest
X-Vcl-Version
X-From
Lfy
T-Server
Fastly-Drupal-HTML
X-Pass-Why
X-Mcache
M-TraceId
Lang
Resin-Trace
Geo-Info
X-Fragments
DataCenter
X-VC
X-Dynatrace
Server-Id
Target-Params
X-CSRF-TOKEN
X-ID
X-Ha-Backend
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
GeoIP-Country-Code
X-LiteSpeed-Tag
X-Clientip
Hostname
MIME-Version
X-Oss-Storage-Class
X-RAMCache
X-Oss-Server-Time
Hit
X-Oss-Object-Type
X-Info
X-ServedByHost
UCS
X-Oss-Request-Id
Cache-Host
HIT
X-Edge-POP
X-AIR-PT
X-Oss-Hash-Crc64ecma
X-Dynatrace-Js-Agent
X-Geo
X-Provided-By
X-Via-PopH
X-Pad
X-Via-PopN
X-Via-PopV
X-Httpd
Section-Io-Id
Section-Io-Origin-Time-Seconds
X-Cdn-Forward
X-Proxy-Cache-Info
S-Cnection
Section-Origin-Responded
Section-Io-Origin-Status
Permissions-Policy
X-RateLimit-Reset
ENV
Producers
X-Api-Version
Ohc-File-Size
X-Edge-Cache
X-Check-Cacheable
Servername
WZWS-RAY
X-NGINX-Cache
X-ElasticPress-Query
X-SB
X-Cache-CFC
X-Micro-Cache
FSS-Cache
X-ServerName
User-Agent
X-Fastly-Backend-Reqs
X-Ucs
X-HS-Status
Fastly-Backend-Name
X-BBC-Origin-Response-Status
Load-Balancing
URI
X-Udemy-Cache-App-Namespace
X-Lb-Nocache
X-Pool
X-Acquia-Application-UUID
X-Platform-Router
X-Acquia-Application-Trace
X-Backend-Host
PICS-Label
X-UP
X-Release
X-Platform-Processor
ServerName
X-Platform-Cluster
X-Acquia-Purge-Tags
Uri
X-GoCache-CacheStatus
X-Acquia-Site
X-TRACE-ID
X-APP
X-BCube-Filmed-By
Cneonction
Tcn
X-Cdn-Request-ID
X-Ec-Custom-Error
X-Nc
X-Scale
X-Swift-Error
Server-Ttl
Cdn
X-Lb-Id
X-Fastly-Cache-Hits
EpKe-Alive
Cteonnt-Length
X-Dw-Trace-Id
MD5-Digest
X-B3-Parentspanid
Sever-Int
X-Akamai-ERRuleID
Server-Ext
X-Akamai-ERPolicy
X-Dispatcher-Number
X-SIPLIST1
Server-Hostname
IsBot
X-Cache-Expires
Cf-Ipcountry
Shield-Pop
X-Contensis-Viewer-Groups
X-Snapshot-Date
X-Yottaa-OS
Wpo-Cache-Status
Wpo-Cache-Message
Ohc-Cache-HIT
Path
X-Newrelic-App-Data
X-Vcache
X-B3-ParentSpanId
X-Cache-ASPX
CF-Cached-On
Vha6-Origin
Sid
X-HostName
X-Cache-Ngx
X-Air-Pt
Req-ID
X-Amz-Meta-Cb-Modifiedtime
X-Shopify-Generated-Cart-Token
VNS-Cache
Cache-Key
X-IN-APIGATEWAYSSL
CPC-Cache
GeoIP-Latitude
X-IN-APIGATEWAY
CPC-Age
CountryCode
X-Sentry-ID
VNS-Age
X-Akamai-Request-ID
X-Apw-Access-Token
X-Apw-Access-Object
X-Apw-Access-Action
X-Last-Modified
X-Apw-Hits
X-UA
X-Logging-Id
X-Varnish-Authentication
X-Te-Duration-Ms
X-WA
X-Http-Count
X-Akamai-Pragma-Client-IP
X-WA-Info
X-Http-Duration-Ms
X-Te-Count
Ngx
X-CacheKey