Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
Link
CF-Cache-Status
Accept-Ranges
CF-RAY
ETag
X-XSS-Protection
Expect-CT
Pragma
X-Powered-By
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
Alt-Svc
P3P
X-Served-By
X-Xss-Protection
X-Download-Options
X-Timer
X-Request-Id
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Cache-Status
X-Generator
X-Cacheable
Timing-Allow-Origin
X-Content-Security-Policy
P3p
X-Iinfo
Feature-Policy
Status
X-Envoy-Upstream-Service-Time
Content-Encoding
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
X-CDN
X-AspNetMvc-Version
X-Request-ID
Upgrade
X-Via
CF-Ray
X-Ws-Request-Id
Access-Control-Max-Age
Server-Timing
EagleId
X-Cache-Group
Keep-Alive
X-Turbo-Charged-By
Request-Context
X-Age
X-Server-Powered-By
X-Proxy-Cache
X-UA-Device
X-AH-Environment
X-Backend
X-Hacker
X-Robots-Tag
Report-To
X-Amz-Request-Id
Host-Header
X-Server
X-Amz-Id-2
X-LiteSpeed-Cache
Grace
X-Rq
X-Nginx-Cache-Status
X-Varnish-Cache
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-WebKit-CSP
X-Dns-Prefetch-Control
X-Page-Speed
X-Vhost
X-OneAgent-JS-Injection
EagleEye-TraceId
X-Amz-Version-Id
X-Ua-Compatible
X-Pingback
X-Dispatcher
X-Device
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Cache-Spec
NEL
X-Server-Id
X-Host
Cf-Railgun
X-Node
X-Backend-Server
Accept-CH
X-Readtime
X-Akam-SW-Version
Surrogate-Control
Request-Id
X-Response-Time
X-HW
Xkey
X-EdgeConnect-Origin-MEX-Latency
X-Application-Context
X-EdgeConnect-MidMile-RTT
Content-Location
X-Ruxit-JS-Agent
Rating
X-Country
Accept-Ch-Lifetime
Accept-CH-Lifetime
X-B3-TraceId
X-Cache-Lookup
X-Cloud-Trace-Context
X-Trace
X-Url
X-Ac
X-Content-Type
Allow
X-Vname
X-PC
X-TtlSet
X-Varnish-TTL
X-Clacks-Overhead
X-Mod-Pagespeed
Edge-Control
X-FastCGI-Cache
X-ESI
X-Server-Name
Fastly-Restarts
Cache-Tag
Service-Worker-Allowed
X-VARITI-CCR
X-Rack-Cache
X-Element-Page-Cache
Verso
X-Language
X-MS-InvokeApp
X-Upstream
X-GitHub-Request-Id
MS-Author-Via
X-Amz-Rid
Public-Key-Pins
X-Vcap-Request-Id
X-Cached
X-Aws-Lambda-Call-Status
X-Dw-Request-Base-Id
X-Client-IP
X-D2id
X-Abt-Application-Version
X-Cache-TTL
X-Template
X-Cnection
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
X-Origin-Cache
X-Px
Arr-Disable-Session-Affinity
X-Navigation-Version
X-Country-Code
RTSS
X-Goog-Hash
X-Powered-By-Plesk
Access-Control-Request-Method
X-NF-Request-ID
X-Server-Lifecycle-Phase
X-Instrumentation
X-Kraken-Loop-Name
Accept-Ch
X-GoogleNews-Bot
X-Exp-Variant
X-Exp-Id
X-Cdn-Fetch
X-Kinja-Server
X-Use-Magma
X-Kinja
X-Kinja-Revision
X-Kinja-Build
X-Version
X-Powered-CMS
Display
Pagespeed
X-Sol
X-Middleton-Display
AR-PoweredBy
AR-SID
AR-CACHE
AR-Request-ID
AR-ATIME
X-Amz-Server-Side-Encryption
Response
X-Middleton-Response
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-MSEdge-Ref
X-LLID
X-Kinsta-Cache
X-Edge-Location-Klb
X-Edge
Nginx-Cache
X-TTL
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
X-Shield-Request-Id
X-RateLimit-Remaining
X-HP-Trace-Id
X-Protected-By
X-Jurisdiction
X-HP-Webp
TCN
X-T
X-Buckets
S
X-Forwarded-For
X-Content-Security-Policy-Report-Only
Content-MD5
X-Mg-S
X-Id
X-Aspnetmvc-Version
Edge-Cache-Tag
Realpath
X-Mid
Fastcgi-Cache
X-CST
Front-End-Https
SPRequestDuration
SPIisLatency
X-MCACHE
X-Recruiting
X-Request-Received
X-Request-Processing-Time
Pinterest-Generated-By
X-Ttl
X-Pinterest-Rid
Pinterest-Version
Server-Node
Filters
X-Ab
X-Ua-Browser
X-Content
X-Correlation-Id
X-DynaTrace
Server-Name
X-Frontend
X-ECACHE
X-Parallel-Accel
X-NWS-LOG-UUID
X-Ruxit-Js-Agent
SPRequestGuid
X-SharePointHealthScore
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Cache-Config
X-Ezoic-Cdn
Fusion-Component-Id
Fusion-Source
Fusion-Deployment-Id
Fusion-Content-Source
Fusion-Content-Id
Fusion-Template-Id
X-HS-Combine-CSS
X-Yandex-Sdch-Disable
Alternate-Protocol
X-Hits
X-Ser
X-Cache-Key
X-Content-Options
X-Page-Id
Cache-Tags
X-Tt-Trace-Host
MicrosoftSharePointTeamServices
X-Tt-Trace-Tag
X-B3-Sampled
Cleartype
X-Git-Hash
Host
Charset
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Www-Served-By
X-Daa-Tunnel
X-Geo-Country
X-Accel-Expires
X-Content-Digest
X-DIS-Request-ID
X-Fastly-Request-Id
Filterid
X-Amzn-Trace-Id
X-Amz-Replication-Status
X-Debug-Info
X-Varnish-Age
X-AppVersion
X-Activity-Id
X-Hostname
TP-Cache
X-Az
TP-L2-Cache
X-Forwarded-Proto
X-FB-Debug
X-Upgrade-Enabled
X-VCache
X-Rid
X-Origin-Server
X-Grace
Access-Control-Allow-Method
X-N
X-XRDS-LOCATION
Cross-Origin-Opener-Policy
X-WebKit-CSP-Report-Only
X-Nginx-Upstream-Cache-Status
X-LB-Cache
X-F-Cache
ServerID
X-Mobile-URL
X-Route-Name
X-Request-Guid
X-Flags
X-Aspnet-Duration-Ms
X-Providence-Cookie
X-Is-Crawler
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Whom
X-Goog-Metageneration
X-GUploader-UploadID
X-Goog-Generation
X-Goog-Stored-Content-Length
Viewport
X-Varnish-Grace
X-TT
X-App-Environment
X-Tb
X-Distributor
Node
X-Origin-Upstream-Status
X-App-Server
X-FW-Dynamic
X-FW-Serve
X-FW-Hash
Paypal-Debug-Id
DC
Payment
X-Server-ID
X-FW-Type
X-Seen-By
X-FW-Static
X-FW-Server
X-Ratelimit-Limit
X-Type
X-NGENIX-Cache
X-User-Agent
Fastcgi-Useragent
X-Cache-Control
Country
Accept-Charset
X-Logged-In
X-Request-Handler-Origin-Region
X-Microsite
X-Cache-Rule
X-Wix-Request-Id
X-Litespeed-Cache
X-Cache-Age
X-Webkit-CSP
Version
X-Via-JSL
Referer-Policy
X-Varnish-Backend
X-Drupal-Cache-Tags
X-DataDome
X-Erf-Bev-Bev
X-Browser-Type
X-Erf-Bev-Bev-Is-Generated
X-Fastly-Request-ID
X-Load-Cache
X-Cluster-Name
X-Node-Name
X-B-Cache
X-Signature
X-Contextid
Refresh
X-Original-Request-Id
X-Response-Served-From
SD-X-WS
X-Mobile
X-Cache-Action
Amp-Access-Control-Allow-Source-Origin
Cache-Status
X-Cacheable-TTL
X-IPLB-Instance
X-Is-Bot
Access-Control-Request-Headers
X-Jobs
X-Vgn-Hpd-Reason
X-Rendered-As
X-Proxy-Cache-Status
X-Page-View
X-Cache-Expired-At
X-TEC-API-VERSION
X-ProcessESI
NGB
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Debug
X-RemovedCookies
X-Real-IP
X-TEC-API-ORIGIN
X-UUID
X-TEC-API-ROOT
X-Revision
X-Instance
X-Device-Type
X-Rule
X-B
X-Proxy
Akamai-GRN
X-Framework
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-G
X-Drupal-Cache-Contexts
X-Cache-Time
X-Debug-IsPreview
Surrogate-Key
X-Debug-IsConnected
X-Fastcgi-Cache
CF-IPCountry
X-FW-Version
X-Air-Hostname
X-Tec-Api-Origin
X-Air-Source
X-Tec-Api-Version
SID
X-Tec-Api-Root
X-Air-Trace-Id
DynaTrace
Liferay-Portal
X-Ratelimit-Reset
X-PressLabs-Stats
X-Oracle-Dms-Ecid
X-Oracle-Dms-Rid
Healthy
X-Azure-Ref
X-Presslabs-Stats
X-XRDS-Location
X-Ms-Request-Id
X-Source
Frame-Options
X-Ms-Version
Count-Hit
X-Oneagent-Js-Injection
MS-CV
X-Nginx-Cache
Ms-Operation-Id
X-Cache-Operation
X-RTag
GEO-INFO
X-CDN-Forward
X-APP-VERSION
X-Accel-Buffering
Uber-Trace-Id
X-EdgeConnect-Cache-Status
X-L-Path
X-Environment-Context
Xserver
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Tumblr-User
X-Tumblr-Pixel-1
X-Cache-Hit
X-Varnish-Server
X-Zen-Fury
X-RateLimit-Limit
Countrycode
Ec-Rule-Version
X-Backend-Name
X-Mode
X-Servername
X-Forwarded-Host
X-Region
Cross-Origin-Window-Policy
X-Content-Powered-By
X-IPS-LoggedIn
Backend
X-Cache-NGX
Section-Io-Cache
X-SaId
X-Cache-Type
X-RN-RSRV
X-Cache-TTL-Remaining
Protected
X-JoinUs
X-UPSTREAM-Address
Meta-Geo
X-Detected-As
Decoy-Debug-Key
X-Extlb
Decoy-Debug-Status
Decoy-Debug-TTL
X-Debug-Cache
X-Cache-Server
X-Cache-Grace
X-Redis-Cache
X-Rewrite-Enabled
X-Proxied
X-Zipkin-Id
X-Uri
X-Varnish-Beresp-Grace
X-Routing-Service
Apigw-Requestid
X-Sql-Duration-Ms
X-Generation-Time
X-Hosted-By
X-Human
X-Sql-Count
X-Tid
X-ApacheServer
Cache-Tv-Group
Country-Code
Eomportal-Instance
Url
Mn-Server-Ip
X-Alternate-Cache-Key
X-BYPASS-REASON
X-Status
X-FB-TRIP-ID
X-Via-Fastly
X-Soup
X-No-Session
X-Storage
X-Microcachable
Fastly-SSL
X-Site-Version
X-UA-Device-Type
X-PERF
X-Sorting-Hat-ShopId
X-ShardId
X-ServerID
X-ProxyCache-Key
X-Sorting-Hat-PodId
X-ShopId
X-ProxyCache-Status
X-Shopify-Stage
Cache-Name
TWC-Connection-Speed
Property-Id
X-OCL
X-PHP-Backend
DB-Nickname
X-Web-Node
X-PCL
X-Origin-Hint
X-Origin-Date
TWC-GeoIP-LatLong
X-Akamai-Edgescape
X-NYM-Debug-Backend
X-Adobe-Content
X-Say-Cacheable
X-Server-W
X-Cache-Host
X-SayCDN-TTL
Webcakes-Region
Webcakes-App-Version
X-Say-TTL
TWC-GeoIP-Country
X-NCache
TWC-Locale-Group
TWC-Privacy
Webcakes-App-Name
X-Format
TWC-Device-Class
X-Adobe-Loc
X-Pubstack
X-R9-Blue-Green-Version
X-Section
OT-Force-Account-Verify
X-Cluster-Node
X-Hl-Ver
X-Access
Azure-InstanceId
X-Content-Age
Azure-Version
Azure-SlotName
Azure-SiteName
Azure-RegionName
Content-Secure-Policy
X-Varnishpool
X-Be
X-NewRelic-App-Data
X-Ua
SRV
X-LSADC-Cache
X-Timing-Wait
X-Proxy-Build
X-Hyper-Cache
Selected-Fe
CDN-PullZone
CDN-RequestId
CDN-Cache
CDN-Uid
CDN-RequestCountryCode
CDN-EdgeStorageId
CDN-CachedAt
X-Generated-By
X-Azure-Ref-OriginShield
X-TIME
Source
Content-Disposition
X-Webkit-Csp
X-Cached-By
X-Trace-Id
X-Unique-Id
LB
X-SRV
Cache
X-Nginx-Cache-Key
X-Ratelimit-Remaining
X-Dc
X-TT-LOGID
X-App-Version
WPO-Cache-Message
X-LAGOON
WPO-Cache-Status
X-HTML-Minification-Powered-By
X-Auto-Login
Retry-After
X-Varnish-Hits
X-Bc-Bl
Cache-Hits
X-Varnish-Hostname
X-Loop
X-Amz-Meta-S3cmd-Attrs
X-Akamai-Transformed
X-GEO
X-Origin-CC
X-TNCMS
X-Origin-TTL
X-S-Maxage
Mime-Version
Onion-Location
Xet-Cookie
X-Platform-Server
Web-Mar-Node
X-Cache-Var
X-Xfnlog-Site
X-Cache-Var-Map
X-Tumblr-Pixel-2
X-Tumblr-Pixel-3
X-Cdn
HostName
X-Proto
X-Time
Webserver
X-Cache-Tags
Upgrade-Insecure-Requests
X-Endurance-Cache-Level
X-Varnish-Cache-Hits
X-Edge-Location
X-Cache-Remote
X-CSRF-Token
X-Tenant
X-Time-Microsecs
ServedBy
X-Request-Time
X-AWS-Id
X-LJ-Flow-ID
X-VWS-Id
X-AOL-HN
N-Cache
X-GG-Cache-Date
X-EC-Lua
X-B3-SpanId
CloudFront-Viewer-Country
X-M-Log
X-M-Reqid
X-Mg-Request-UUID
X-Qnm-Cache
X-ECache
X-Request-Host
X-Labrador-Cache-Channel
From-Origin
X-Amzn-RequestId
X-PHP-Host
X-Amz-Apigw-Id
WP-Super-Cache
X-FireWall-Port
Surrogated-Key
Expiry
Sslversion
L
Fastcgi-X-Cache-Version
X-Ig-Push-State
X-Hnp-Log
X-Cache-Date
Meta-Geo-Continent
X-Forwarded-Path
X-Connection-Hash
Redirect-Candidate
Rendered-Blocks
X-A
Pramga
X-Gen-Mode
DCR-Processing-Time-Ms
Odigeo-Trace-Id
Origin
Mobile-Detection-Method
CDCHOST
X-Cache-NE
X-Processor
X-Origin-Response-Time
X-Rojux
X-Planisys-CDN-TTL
X-Block-Status
X-PAYTM-SRV-ID
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Orig-Expires
V-Age
BehaviorPad-Version
X-NAPM-TraceId
X-PBS-Appsvrname
X-External-Request-Id
User-Cache-Control
A
X-ND-Cache
X-Ckpd-Fst-Backend
DCR-Decision-By
Nel
X-Vtex-Remote-Cache
X-Vtex-Processado-Em
X-Conf
X-Aed
X-Correlation-ID
X-CACHE-KEY
X-A-Wwc
X-ARC
X-Application
X-Slack-Backend
X-RCS-CacheZone
X-D
X-Developer
X-Vdms-Path
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-V-Cache
X-Vdms-Version
X-TIM-N
X-VG-WebCache
X-Destination
X-A-Dgt
X-SRCache-Key
X-Session-Fingerprint
X-A-Dam
X-A-Ccd
X-Ftr-Request-Id
Xc-Version
X-ScT
X-Via-NSCOPI
X-S-Cookie
X-SD-PageType
X-S
X-A-Dcw
X-Cluster
X-B-Cookie
X-Shop-Environment
X-Locale
X-MP-GENERATED-AT
X-Handled-By
DSUID
CacheControlHeader
Traceparent
X-Location
X-LI-UUID
Fastcgi-Cache-TTL
Cmstype
X-Li-Pop
X-Li-Fabric
Cmsid
X-Gdpr
X-Mvc-Supplant-Cachable
Ssr
Origin-CC
X-Webstats-RespID
X-Fastly-Cache
X-Geo-Header
X-Fetched-On
X-Cache-Bucket
X-Hash
X-HN
Server-Info
Svr
PFcat
Gh-Request-Id
Origin-EX
Host-ID
X-VServer
Release
X-Varnish-Beresp-Status
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-Sucuri-ID
X-VarnishDD-TTL
X-Owner
Wxu-Next-Hostname
X-Origin-Time
X-Sucuri-Cache
X-Storefront-Renderer-Rendered
X-Proxy-Upstream
X-Core-Mission
X-Skip-Cache
X-Policy
X-Device-Os
Wxu-Next-Commit
X-Epic-Correlation-Id
Wxu-Next-Region
X-Rocket-Nginx-Serving-Static
X-NodeID
X-Cache-Info
AKAMAI
X-Served-From
Arc-Country
True-Client-Country-4JS
X-Cdn-Srv
X-Old-Content-Length
X-Nyt-Route
X-Aicache-OS
Vix-Hermes-Req-Id
X-Server-IP
AMP-Access-Control-Allow-Source-Origin
X-VC-Cache
Fastly-Drupal-Html
X-NWS-UUID-VERIFY
Environment
X-Forwarded-Site
X-Developers
X-ATG-Version
X-Datadog-Trace-Id
Server-Host
X-BBC-Edge-Cache-Status
X-Adobe-Source
Thinkindot-CacheControl-Type
X-Datadog-Parent-Id
Thinkindot-Control
X-Branch-Name
X-Esi-Check
Thinkindot-CacheControl
TDXMobile
We-Hiring
X-Accel-Expires-Debug
State
X-Date
Web-Mar-Region
X-Request-Start
X-Sigma-Backend
X-Sigma
X-UnsetCookies
X-Sn-Servicetimems
X-TH-Server
X-Scheme
X-Rocket-Build-Number
X-Request-URI
X-Region-Sid
X-Req
X-Reqid
X-Datadog-Sampling-Priority
X-Thinkindot-L3
X-TrackingId
X-CGP
X-Csrf-Jwt
Ha-Gx-Prefs
HA-Ipaddr
L5d-Success-Class
X-Envoy-Decorator-Operation
X-Eu-Site
X-VG-TLSProxy
X-Cdn-Origin
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-Viewer-Country
Req-Svc-Chain
X-Core-Value
Machine
Mail-Subject
Locid
X-HS-Content-Campaign-Id
X-Irp-Debug
X-Cache-Config
X-Gzip
X-Generated-On
X-Gamma-Serve
X-GeoIP
X-Backend-State
X-GeoIP-City
Fastly-GeoIP-CountryCode
X-Cache-Debug
Apple-News-Services-Handled
Apple-News-Services-Host
X-Node-Id
X-Cache-Enabled
X-Origin-Expires
X-Platform
Apple-News-Services-Parsed-Url
X-Level-Front-Cache
X-Cache-Id
X-Men
Apple-News-Services-Request-Url
X-Magnolia-Registration
X-Zone
X-Rebelmouse-Cache-Control
X-Thanos
X-Response-By
X-Rebelmouse-Surrogate-Control
X-Qloud-Router
X-Variation
X-Varnish-CookieHashed-On
X-Worker
X-Varnish-Remaining-TTL
X-Varnish-CookieINHashed-On
X-Pod-Name
X-NU-AKA-ACS-Version
X-Fastly-Backend
X-DPWN-IS-SECURE
X-DefHash
X-FC-Vary-Parameters
X-Has-Esi
X-Loc
X-JWT-State
X-Is-Gdpr
X-DefElseHash
NGX
Memcached
NM-Fastcgi-Cache
Platform
Is-Eu
Fastly-SWR
Adler-Geo
Cf-Device-Type
X-Amzn-Remapped-Content-Length
Fastly-SIE
X-Bip
X-CS
X-Xrds-Location
X-Origin
X-Tx-Id
X-Mvc-Supplant-OutputCached
X-Datadome
X-Ua-Device
Datacenter
X-Varnish-Beresp-Ttl
X-NC
X-GeoIP-Region-Code
X-GeoIP-Country-Code
X-CLOUD-TRACE-CONTEXT
X-Up
X-Backend-TTL
X-API-Version
CDN
Candidate-Md5Url
X-Generated-In
X-LB-ID
Pics-Label
X-Vc
S-Rt
Magicmarker
X-Trace-ID
Ms-Author-Via
X-Tb-Optimization-Total-Bytes-Saved
X-DynaTrace-JS-Agent
X-TraceId
Env
NtCoent-Length
On-Server
WWW-Authenticate
X-Edge-Pop
X-Restarts
X-LB-NoCache
Kp-EeAlive
WebServer
X-Via-Popv
Time
X-Varnish-Ttl
Memory
X-Via-Popn
X-Via-Poph
GeoIp-Country-Code
Esi-Enabled
X-Akamai-Request-ID2
X-Http-Reason
X-DC
X-Tt-Logid
X-DW
X-Wix-Viewer-Type
X-Optimistic-Header
X-TA-CDN-Provider
Edge-Cache
X-DI
X-DSS
X-RSL
X-RPS
X-DB
X-Refresh
X-RPM
X-Action
X-CacheTTL
C-Via
X-Cache-Backend
X-Dynatrace
X-Service
X-Varnish-Beresp-TTL
X-Newrelic-Synthetics
X-Cache-PHP
X-Minions-Version
X-Parent-Response-Time
X-Esi
X-Servedbyhost
X-Srv
Server-ID
X-MSEdge-Flight
X-Unique-ID
X-MSEdge-Features
Accept-Language
X-TX-ID
X-Cs
X-Render-Time
X-HA-Backend
X-Cache-Status-Check
X-ZONE
Locale
X-VCL-Version
X-Urbn-Site-Id
X-Urbn-Context-Path
X-Cache-Ttl
X-Ec-Fail
X-Li-Proto
X-LI-Proto
X-App
X-Fpc
X-User
X-Ec-GeoHdr
Proxy-Connection
X-URL
X-Info
X-AIR-PT
X-FPC
X-Webkit-Csp-Report-Only
X-Pass-Why
Test
X-LiteSpeed-Cache-Control
X-Traceid
Server-Id
X-Vcl-Version
X-B3-Spanid
X-Clientip
X-Webkit-CSP-Report-Only
X-NODE
UCS
HIT
Tcn
Geo-Info
Cache-Host
X-Oss-Server-Time
X-Oss-Object-Type
X-Oss-Request-Id
X-Oss-Hash-Crc64ecma
X-Oss-Storage-Class
Cdncip
Cdnsip
X-AK-Request-ID
My-App
S-Cnection
M-TraceId
X-WADP-Cache
X-CSRF-TOKEN
X-Fmm-Version
Cluster
X-Clara-WADP
Cf-Int-Pingora-Origin-Digest
Fastly-Drupal-HTML
Tracecode
Resin-Trace
X-HostName
Geoip-Latitude
Hostname
X-LiteSpeed-Tag
X-CUA
X-Ha-Backend
T-Server
User-Agent
X-Var-Ttl
X-ServedByHost
Lfy
X-ID
Fastly-Backend-Name
X-Micro-Cache
X-From
X-Dynatrace-Js-Agent
X-Fragments
Lang
GeoIP-Country-Code
X-RAMCache
X-Pad
Hit
X-Backend-Host
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
Section-Io-Id
X-Release
X-B3-Traceid
X-Mcache
X-NGINX-Cache
Section-Origin-Responded
X-BBC-Origin-Response-Status
Ohc-File-Size
Lb
X-Cdn-Forward
X-Geo
X-Edge-POP
X-Via-PopH
X-APP
X-BCube-Filmed-By
X-Via-PopN
MIME-Version
X-Check-Cacheable
X-Via-PopV
ENV
Target-Params
X-ElasticPress-Query
X-WP-CF-Super-Cache
X-HS-Status
X-WP-CF-Super-Cache-Cache-Control
DataCenter
X-Api-Version
X-Edge-Cache
Load-Balancing
VNS-Cache
CPC-Cache
Path
VNS-Age
CPC-Age
Cache-Key
URI
X-ServerName
Servername
X-Fastly-Backend-Reqs
X-Ucs
EpKe-Alive
X-WA-Info
X-Amz-Meta-Cb-Modifiedtime
X-WA
X-ES-SERVER
X-VC
Uri
PICS-Label
X-Wikidot-Backend
X-Lb-Id
X-Lb-Nocache
X-UP
X-Fastly-Cache-Hits
X-GoCache-CacheStatus
X-Wikidot-Static-Cache
X-Proxy-Cache-Info
FSS-Cache
X-Httpd
X-TRACE-ID
Pagetype
Ohc-Cache-HIT
WZWS-RAY
Cdn
Producers
X-Cms-Context
X-PJAX-URL
ServerName
Cteonnt-Length
X-Nc
Cneonction
X-Provided-By
X-B3-ParentSpanId
Shield-Pop
X-Cdn-Request-ID
X-RateLimit-Reset
Permissions-Policy
X-Dw-Trace-Id
X-Via-Ucdn
X-Newrelic-App-Data
X-SB
Cf-Ipcountry
X-Acquia-Application-UUID
Srv
Server-Ttl
X-Akamai-ERPolicy
X-Akamai-ERRuleID
X-Vcache
X-Acquia-Site
X-Cache-CFC
X-Acquia-Application-Trace
X-Acquia-Purge-Tags
X-Pool
X-Swift-Error
X-Contensis-Viewer-Groups
X-CCDN-CacheTTL
X-CCDN-Origin-Time
CountryCode
X-Akamai-Pragma-Client-IP
MD5-Digest
CF-Cached-On
X-Snapshot-Date
Vha6-Origin
X-Hcs-Proxy-Type
X-Cache-ASPX
X-Apw-Hits
X-Apw-Access-Object
X-Apw-Access-Action
X-Apw-Access-Token
X-Yottaa-OS
X-Cache-Ngx
X-Air-Pt
Sid
X-Logging-Id
IsBot
X-Varnish-Authentication
X-Platform-Router
Sever-Int
X-Udemy-Cache-App-Namespace
Server-Hostname
Server-Ext
X-B3-Parentspanid
X-Platform-Cluster
X-Platform-Processor
X-Te-Duration-Ms
W
X-Miniprofiler-Ids
X-SIPLIST1
Ngx
X-VG-WebServer
Req-ID
X-Http-Count
X-UA
X-CacheKey
X-Sentry-ID
X-Te-Count
X-Http-Duration-Ms
X-Last-Modified