Threat Level: green Handler on Duty: Daniel Wesemann

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
Pragma
X-Powered-By
X-XSS-Protection
X-Cache
CF-RAY
Via
Age
Content-Security-Policy
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
P3P
X-Cache-Hits
X-UA-Compatible
Alt-Svc
CF-Ray
X-Xss-Protection
X-Served-By
X-Download-Options
X-Timer
X-Request-Id
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
Access-Control-Allow-Credentials
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
X-Drupal-Cache
X-Generator
X-Cache-Status
X-Check
X-Cacheable
X-Envoy-Upstream-Service-Time
X-DNS-Prefetch-Control
X-Request-ID
Timing-Allow-Origin
X-FRAME-OPTIONS
X-Iinfo
X-Dns-Prefetch-Control
X-Drupal-Dynamic-Cache
Feature-Policy
X-Content-Security-Policy
Content-Encoding
Access-Control-Expose-Headers
Upgrade
Status
X-CDN
X-AspNetMvc-Version
Server-Timing
X-XSS-PROTECTION
Access-Control-Max-Age
X-Amz-Request-Id
Request-Context
X-Amz-Id-2
X-Turbo-Charged-By
X-AH-Environment
X-Via
X-Robots-Tag
X-Backend
X-Cache-Group
Cf-Edge-Cache
Host-Header
Keep-Alive
X-Proxy-Cache
X-Hacker
X-Server
X-Rq
X-UA-Device
X-Age
X-Server-Powered-By
Allow
X-Vhost
X-Varnish-Cache
X-Ws-Request-Id
EagleId
X-Dispatcher
X-Amz-Version-Id
Grace
Cf-Apo-Via
P3p
X-LiteSpeed-Cache
Nel
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Page-Speed
X-Device
Cf-Railgun
EagleEye-TraceId
X-Swift-SaveTime
X-Swift-CacheTime
X-Aws-Lambda-Call-Status
Ali-Swift-Global-Savetime
Accept-CH
X-Pingback
X-Node
X-Host
X-WebKit-CSP
X-Server-Id
Surrogate-Control
X-Backend-Server
X-CST
X-OneAgent-JS-Injection
X-Readtime
X-Nginx-Cache-Status
X-Akam-SW-Version
X-Content-Security-Policy-Report-Only
Permissions-Policy
X-Cache-Lookup
Request-Id
X-Application-Context
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Nginx-Upstream-Cache-Status
X-Cloud-Trace-Context
X-Trace
X-Response-Time
X-Edge
Accept-Ch-Lifetime
X-HW
X-Oneagent-Js-Injection
Accept-CH-Lifetime
X-Litespeed-Cache
X-Ua-Compatible
X-Mod-Pagespeed
Content-Location
X-Url
X-Clacks-Overhead
X-Midtier
X-ECACHE
X-Ruxit-JS-Agent
X-ESI
X-Mcache
Rating
X-Amz-Server-Side-Encryption
X-Country
X-Upstream
X-Vname
X-TtlSet
X-PC
Xkey
X-Vcap-Request-Id
X-MS-InvokeApp
Cache-Tag
X-Rack-Cache
X-D2id
Verso
X-Element-Page-Cache
Fastly-Restarts
X-Cache-TTL
X-Exp-Id
X-Cdn-Fetch
X-Exp-Variant
X-GoogleNews-Bot
X-Kinja-Server
X-Use-Magma
X-Kinja-Build
X-Kinja-Revision
X-Kinja
RTSS
Edge-Control
X-Content-Type
X-Powered-By-Plesk
X-Ruxit-Js-Agent
X-VARITI-CCR
X-Ac
Origin-Trial
X-Navigation-Version
X-Cached
X-Abt-Application-Version
X-Goog-Hash
Accept-Ch
Service-Worker-Allowed
X-Ttl
X-GitHub-Request-Id
X-Country-Code
X-Amz-Rid
X-WebKit-CSP-Report-Only
X-Sol
Display
Pagespeed
X-Middleton-Display
X-Mg-S
X-Dw-Request-Base-Id
X-B3-TraceId
SPRequestGuid
X-SharePointHealthScore
X-Browser-Type
X-Server-Name
Arr-Disable-Session-Affinity
Cross-Origin-Opener-Policy
X-Server-Lifecycle-Phase
X-Erf-Bev-Bev
X-Instrumentation
X-Erf-Bev-Bev-Is-Generated
X-Powered-CMS
X-Kraken-Loop-Name
AR-SID
AR-Request-ID
AR-PoweredBy
X-Middleton-Response
Response
AR-ATIME
X-Amzn-Trace-Id
SPIisLatency
SPRequestDuration
X-Cache-Key
X-Ua-Device
X-Varnish-TTL
AR-CACHE
X-Fastly-Request-ID
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-ORACLE-DMS-ECID
X-Cnection
X-ORACLE-DMS-RID
X-HP-Webp
X-HP-Trace-Id
X-Jurisdiction
X-Version
X-Webkit-CSP
X-Accel-Expires
X-Fastcgi-Cache
X-T
Cache-Status
Front-End-Https
Cache-Tags
X-Ser
Edge-Cache-Tag
X-Client-IP
X-Px
X-MSEdge-Ref
X-NF-Request-ID
X-Times
X-Pinterest-Rid
Pinterest-Version
Pinterest-Generated-By
Public-Key-Pins
X-Hits
Nginx-Cache
X-Recruiting
Mrf-Cache-Status
MRF-Tech
X-RateLimit-Remaining
X-B3-TraceId-Primal
X-Shield-Request-Id
X-Frontend
X-Request-Received
X-Request-Processing-Time
X-LLID
Access-Control-Request-Method
Server-Node
X-Ua-Browser
X-NWS-LOG-UUID
Payment
X-DIS-Request-ID
TP-Cache
X-RateLimit-Limit
X-HS-Hub-Id
X-HS-Cache-Config
X-Webkit-CSP-Report-Only
X-HS-Content-Id
S
MicrosoftSharePointTeamServices
X-HS-Combine-CSS
TP-L2-Cache
X-Goog-Metageneration
X-LB-Cache
X-Content-Digest
X-B3-Traceid
X-Webkit-Csp
Content-MD5
X-PressLabs-Stats
X-Distributor
X-Erf-Stays-Pdp-Viaduct-Migration-Web
Realpath
X-Geo-Country
X-Kinja-CCPA
X-Hostname
X-Microsite
X-Request-Handler-Origin-Region
X-Ezoic-Cdn
X-FastCGI-Cache
X-Forwarded-For
X-Page-Id
Access-Control-Allow-Method
Fastcgi-Cache
X-FB-Debug
Accept-Charset
X-Envoy-Decorator-Operation
X-GUploader-UploadID
X-Cluster-Name
X-Rid
X-Protected-By
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Seen-By
TCN
X-Ratelimit-Remaining
X-Correlation-Id
Cleartype
X-B3-Sampled
DC
X-Origin-Server
X-Origin-Cache
X-Debug-Info
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-TEC-API-ROOT
X-Mobile
X-TEC-API-ORIGIN
X-TEC-API-VERSION
Referer-Policy
X-Varnish-Backend
X-Git-Hash
X-Logged-In
X-Ratelimit-Limit
X-Newrelic-App-Data
X-Kinsta-Cache
X-Edge-Location-Klb
Cross-Origin-Resource-Policy
X-Azure-Ref
X-XRDS-Location
Alternate-Protocol
X-TTL
X-Varnish-Grace
X-Contextid
Healthy
X-Aspnet-Version
X-Revision
Surrogate-Key
X-Fb-Rlafr
X-App-Environment
X-Request-Guid
X-Route-Name
X-Providence-Cookie
X-Is-Crawler
X-Aspnet-Duration-Ms
X-Flags
X-Grace
X-Amz-Replication-Status
Count-Hit
X-Amz-Meta-S3cmd-Attrs
X-TT
X-Server-ID
X-Content-Options
X-Wix-Request-Id
X-Whom
X-IPS-LoggedIn
X-Forwarded-Proto
MS-Author-Via
Filterid
Charset
Frame-Options
X-Akamai-Edgescape
Viewport
WPO-Cache-Message
X-App-Server
WPO-Cache-Status
X-Id
X-Hosted-By
X-Varnish-Ttl
X-B
Paypal-Debug-Id
X-Cache-Age
X-Magnolia-Registration
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Backend-Name
X-Trace-Id
X-Activity-Id
X-AppVersion
X-Az
X-Cache-Control
X-Daa-Tunnel
X-Www-Served-By
Retry-After
X-Client-Ip
Section-Io-Cache
Server-Name
X-F-Cache
X-Type
Refresh
X-Proxy-Cache-Info
X-Upgrade-Enabled
X-Varnish-Server
Version
X-Time
X-Proxy
X-Original-Request-Id
X-Http-Reason
X-Response-Served-From
X-Rule
VIX-Pulpo-Upstream-Status
X-Cache-Rule
X-App-Version
Host
Akamai-GRN
SD-X-WS
VIX-Pulpo-Node
X-ARC
Protected
Front
X-UUID
X-Status
X-Rocket-Nginx-Serving-Static
X-Edge-Location
X-Akamai-Request-ID2
X-Varnish-Age
X-User-Agent
X-Instance
X-Unique-Id
X-Jobs
X-L-Path
Amp-Access-Control-Allow-Source-Origin
X-Region
X-N
X-Rendered-As
X-Is-Bot
X-Cache-Grace
X-Cacheable-TTL
SRV
X-Environment-Context
X-Framework
X-EdgeConnect-Cache-Status
X-Source
X-Page-View
X-FW-Static
Fastly-SWR
Fastly-SIE
From-Origin
Access-Control-Request-Headers
X-Oracle-Dms-Ecid
X-FW-Version
X-FW-Hash
X-FW-Type
X-FW-Dynamic
X-FW-Server
X-FW-Serve
X-Cache-Time
X-Load-Cache
X-Tumblr-Pixel-0
X-Adobe-Content
X-Adobe-Loc
X-Tumblr-User
X-Tumblr-Pixel
X-ProcessESI
X-RemovedCookies
X-G
X-Tumblr-Pixel-1
X-Oracle-Dms-Rid
ServerID
X-COUNTRY
Content-Disposition
Country
X-Drupal-Cache-Tags
X-CDN-Forward
X-Datadog-Trace-Id
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
X-Nf-Request-Id
X-Language
X-RateLimit-Reset
X-HTML-Minification-Powered-By
X-Tt-Trace-Tag
X-Tt-Trace-Host
Accept-Language
Countrycode
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-DynaTrace
X-Datadog-Sampled
X-Amzn-Remapped-Content-Length
Liferay-Portal
X-DynaTrace-JS-Agent
X-Vcache
X-Mg-Request-UUID
X-Debug-IsConnected
X-Debug-IsPreview
X-B3-SpanId
X-Generated-By
X-XRDS-LOCATION
Xet-Cookie
X-ID
Backend
CF-IPCountry
X-DataDome
Xserver
X-Drupal-Cache-Contexts
X-ECache
Webserver
X-Tt-Logid
X-Mode
X-Nginx-Cache
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
X-NYM-Debug-Backend
X-Signature
X-B-Cache
X-Device-Type
X-Content-Powered-By
X-Tec-Api-Version
X-Tec-Api-Root
X-Zen-Fury
X-Tec-Api-Origin
X-Httpd
GEO-INFO
X-Servername
Url
X-Content-Age
X-Erf-Web-Scheduler
X-Ratelimit-Reset
X-Git-Commit
Azure-Version
Azure-SlotName
X-ServerID
Meta-Geo
Onion-Location
X-SaId
Load-Balancing
X-Urbn-Site-Id
X-Sucuri-Cache
Filters
X-Urbn-Context-Path
X-Container-Uri
X-Sucuri-ID
Locale
Azure-SiteName
Azure-InstanceId
X-Cache-Action
X-JoinUs
X-LAGOON
Azure-RegionName
X-Rewrite-Enabled
X-Director
S-Rt
X-Varnish-Cache-Hits
X-Cache-Operation
X-UPSTREAM-Address
Uber-Trace-Id
X-SayCDN-TTL
X-Tb
X-Soup
X-Storage
X-Say-Cacheable
X-Varnish-Hostname
X-Say-TTL
X-Proto
X-Cluster-Node
X-Generation-Time
X-VCT
X-Ms-Version
X-Served-From
X-Logging-Id
X-Forwarded-Host
X-Detected-As
X-Labrador-Cache-Channel
X-PHP-Host
X-VC-Cache
X-Ms-Request-Id
X-RM-Cache-TTL
Web-Mar-Node
X-Xrds-Location
Webcakes-App-Version
TWC-GeoIP-LatLong
TWC-Locale-Group
TWC-Privacy
TWC-GeoIP-Country
Webcakes-App-Name
TWC-Connection-Speed
Mn-Server-Ip
X-Extlb
X-Cache-Server
Node
Property-Id
DB-Nickname
Webcakes-Region
TWC-Device-Class
X-Uri
X-Sql-Duration-Ms
Fastcgi-Useragent
X-Skip-Cache
X-Adobe-Source
X-Sql-Count
X-GeoCountry
X-GeoCode
X-Routing-Service
X-Zipkin-Id
X-Origin-Hint
X-RCS-CacheZone
X-Proxied
X-FB-TRIP-ID
Selected-Fe
X-Proxy-Build
X-R9-Blue-Green-Version
X-Tumblr-Pixel-2
X-Tumblr-Pixel-3
X-LSADC-Cache
X-Timing-Wait
X-Debug
X-Format
X-Fetched-On
Fastly-Drupal-HTML
X-Lambda-Id
X-MP-GENERATED-AT
X-Origin-Date
X-Cache-Expired-At
X-Via-JSL
OT-Force-Account-Verify
CDN-RequestId
X-NGENIX-Cache
Source
X-Cache-Hit
X-Template
X-Varnish-Hits
X-MCACHE
X-Srv
X-Node-Name
Content-Secure-Policy
X-Tncms
X-Cache-TTL-Remaining
X-AIR-PT
X-UA-Device-Type
X-Loop
X-Endurance-Cache-Level
X-Ua
X-Pass-Why
X-Pubstack
Upgrade-Insecure-Requests
Cross-Origin-Window-Policy
X-Redis-Cache
X-Server-W
NGB
X-PHP-Backend
X-Origin-CC
X-Real-IP
X-Fastly-Request-Id
X-Origin-TTL
X-CCDN-CacheTTL
X-TimeS
X-Hcs-Proxy-Type
X-CCDN-Origin-Time
X-Datadome
Cache-Hits
MS-CV
Section-Origin-Responded
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
Section-Io-Id
X-RTag
Ms-Operation-Id
X-Cache-Host
Cache-Name
X-Cms-Context
X-Restarts
X-Xfnlog-Site
Cache-Provider
X-CSRF-Token
X-IPLB-Instance
X-Optimistic-Header
X-S
X-Reqid
X-IPLB-Request-ID
Apigw-Requestid
CDN-CachedAt
X-Cache-Type
CDN-Cache
CDN-PullZone
CDN-EdgeStorageId
CDN-RequestCountryCode
CDN-Uid
CDN-RequestPullCode
CDN-RequestPullSuccess
X-ProxyCache-Key
X-No-Session
X-BYPASS-REASON
X-ProxyCache-Status
X-Hl-Ver
X-GEO
X-Via-Fastly
X-AWS-Id
X-Cluster
X-LJ-Flow-ID
X-VWS-Id
X-Aspnetmvc-Version
X-Newrelic-Synthetics
X-Section
X-Access
X-Rn-Rsrv
X-CGP
X-Cache-NE
X-Conf
X-Csrf-Jwt
X-Cdn-Diag
X-CacheTTL
BehaviorPad-Version
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-Ec-Custom-Error
X-Epic-Correlation-Id
X-Ec-GeoHdr
X-Ec-Fail
X-Eu-Site
X-External-Request-Id
X-FC-Vary-Parameters
X-Fastly-Backend
Canary
X-Dispatcher-Number
X-Debug-Cache-Fetch
Surrogated-Key
X-Date
Sslversion
X-Debug-Cache-Store
X-Developer
X-Destination
X-D
X-Bl-Debug
X-A-Dgt
X-A-Dcw
X-A-Dam
Magicmarker
Lang
L5d-Success-Class
X-Accel-Expires-Debug
Odigeo-Trace-Id
X-A-Wwc
L
VNS-Cache
W
Meta-Geo-Continent
Web-Mar-Region
N-Cache
We-Hiring
X-A
X-A-Ccd
Mail-Subject
Ngx.Var.Host
MD5-Digest
X-Aed
HA-Ipaddr
X-Bc-Bl
CPC-Age
CPC-Cache
DCR-Decision-By
X-BCube-Filmed-By
X-Cache-Bucket
T-Server
Candidate-Md5Url
X-Cache-Info
DCR-Processing-Time-Ms
X-B-Cookie
Gannett-Cam-Experience-Id
VNS-Age
Gh-Request-Id
Ha-Gx-Prefs
Fastly-GeoIP-CountryCode
Vix-Hermes-Req-Id
X-Application
Fastly-Backend-Name
Redirect-Candidate
Rendered-Blocks
X-Irp-Debug
X-CACHE-AGE
X-Policy
X-Vdms-Path
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Proxy-Cache-Status
X-Vdms-Version
X-Origin-Time
X-Vtex-Remote-Cache
X-Akamai-Transformed
X-VG-WebCache
X-Request-Host
X-Rojux
X-Tenant
X-Slack-Backend
X-Slack-Shared-Secret-Outcome
X-SRCache-Key
X-Shop-Environment
X-SD-PageType
X-S-Cookie
X-Var-Ttl
X-TIM-N
X-ScT
X-We-Are-Hiring
X-Viewer-Country
X-GeoIP-Region-Code
X-Mvc-Supplant-Cachable
Server-Host
X-Orig-Expires
X-GeoIP-Country-Code
Xc-Version
X-Gdpr
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-Forwarded-Path
X-Nyt-Route
X-Thanos
X-Thinkindot-L3
X-Sorting-Hat-ShopId
X-Test
X-SVT-ORM-VERSION
X-Storefront-Renderer-Rendered
X-SVT-ORM-RULES
X-Worker
X-Wix-Viewer-Type
X-JWT-State
TDXMobile
Fastly-SSL
True-Client-Country-4JS
X-VG-TLSProxy
X-Sorting-Hat-PodId
X-WADP-Cache
X-Accel-Buffering
Thinkindot-Control
X-Has-Esi
X-Up
Thinkindot-CacheControl
X-Varnishpool
Thinkindot-CacheControl-Type
X-Is-Gdpr
X-Server-IP
X-Node-Id
X-Mly-Id
X-Mid
X-Old-Content-Length
X-Org
X-Core-Value
X-Owner
X-Origin-Response-Time
X-Level-Front-Cache
X-Esi-Check
X-Geo-Header
X-Generated-On
X-Forwarded-Site
X-Gzip
X-Handled-By
X-INCAP-ABP
X-Human
X-Hash
X-Core-Mission
X-PAYTM-SRV-ID
X-BBC-Edge-Cache-Status
X-ShardId
X-Fmm-Version
X-ShopId
X-Shopify-Stage
X-ApacheServer
X-App-Name
X-Auto-Login
X-Bip
X-S-Maxage
X-Clara-WADP
X-PERF
X-CMSURLCustom
X-Platform
X-Pool
X-Cache-Debug
X-Cache-Id
X-Request-Time
X-Alternate-Cache-Key
X-Clientip
Machine
Memcached
Origin
Release
Host-ID
Environment
AKAMAI
Cmstype
Datacenter
Req-Svc-Chain
Cmsid
User-Cache-Control
X-Web-Node
AMP-Access-Control-Allow-Source-Origin
X-Vcl-Version
WP-Super-Cache
CDCHOST
X-WA-Info
X-Cdn-Srv
Adler-Geo
Expect-Staple
Is-Eu
X-Block-Status
DSUID
X-Cdn-Origin
X-DefElseHash
X-Cs
Country-Code
Apple-News-Services-Request-Url
CloudFront-Viewer-Country
Server-Ext
Producers
Apple-News-Services-Handled
X-Mvc-Supplant-OutputCached
X-Nananana
X-Nginx-Cache-Key
X-Hnp-Log
X-Parent-Response-Time
X-Gen-Mode
X-From
X-NodeID
X-Dispatcher-Server
Server-Hostname
Apple-News-Services-Host
ServedBy
X-Scale
X-Origin
X-Device-Os
Apple-News-Services-Parsed-Url
Platform
Sever-Int
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-Variation
X-Sn-Servicetimems
X-Qloud-Router
NM-Fastcgi-Cache
X-Varnish-Remaining-TTL
X-Loc
X-DPWN-IS-SECURE
Esi-Enabled
X-VServer
X-DefHash
X-Vmg-Version
X-Correlation-ID
X-Air-Trace-Id
X-Air-Hostname
X-Air-Source
C-Via
Origin-CC
Origin-EX
X-Op-Id-All
X-Presslabs-Stats
Wxu-Next-Commit
X-NCache
X-Nitro-Cache
Wxu-Next-Hostname
Pics-Label
X-GeoIP
Ssr
X-Instance-Name
X-App
X-Azure-Ref-OriginShield
Wxu-Next-Region
X-Akamai-Device-Characteristics
X-LB-NoCache
X-TA-CDN-Provider
Server-ID
Time
X-Amz-Meta-Cb-Modifiedtime
X-Cache-Enabled
X-Refresh
Memory
Server-Info
X-TIME
X-Tx-Id
X-Cache-Status-Check
Cache-Host
X-Microcachable
X-Platform-Router
X-HA-Backend
X-Platform-Processor
X-Platform-Cluster
X-Site-Version
X-Locale
XM
X-Origin-Expires
X-Dc
NGX
X-HN
Resin-Trace
Hostname
PFcat
X-VarnishDD-TTL
GeoIP-Latitude
X-VHOST
X-Tb-Optimization-Total-Bytes-Saved
X-API-Version
Origin-Agent-Cluster
X-CACHE-GROUP
X-ZONE
Cf-Device-Type
Cdn-Requestid
A
X-FL-QIT-DEBUG
X-Via-SSL
X-Via-Edge
X-Via-CDN
X-Ad-Defer-Variation
X-FL-EDGE
Srvid
Locid
Edge-Copy-Time
X-Wp-Cf-Super-Cache-Active
X-Zone
X-Varnish-Beresp-Ttl
X-Varnish-Beresp-Grace
X-DC
X-Upstream-Ht
X-Vgn-Hpd-Reason
X-Fpc
X-Upstream-Ct
Sid
X-Internal-Host
YJS-ID
X-ATG-Version
X-FireWall-Port
X-Webkit-Csp-Report-Only
X-Contensis-Viewer-Groups
Uri
X-Cache-ASPX
Cache-Key
X-Micro-Cache
X-Cached-By
True-Client-Ip
X-Moov-Xdn-Version
X-Moov-T
X-Github-Request-Id
X-WP-CF-Super-Cache-Active
X-Varnish-Authentication
X-Pod-Name
X-LiteSpeed-Cache-Control
X-TraceId
X-DataCenter
User-Agent
X-VCache
X-Provided-By
X-HS-Content-Campaign-Id
IsBot
X-SIPLIST1
X-Info
State
X-Planisys-CDN-Rules
GeoIP-Country-Code
X-Planisys-CDN-Cache
X-Planisys-CDN-TTL
Location
X-AB
X-URL
X-Buckets
X-B3-Spanid
X-B3-Parentspanid
X-RN-RSRV
X-Platform-Server
X-Fastly-Cache
X-NewRelic-App-Data
X-Sigma-Backend
X-VC
X-Sigma
X-Nitro-Rev
X-NGINX-Cache
X-Cache-Remote
X-Geo-Region
X-Release
X-Backend-Instance
X-Rocket-Build-Number
X-Nitro-Cache-From
X-Datacenter
X-LiteSpeed-Tag
X-Api-Version
X-Geo
Cdn
X-MSEdge-Flight
GeoIp-Country-Code
X-Accel-Version
X-MSEdge-Features
Cache
SID
CF-Ctrl
XServer
X-FTR-Request-ID
X-Gamma-Serve
X-CS
X-Generated-In
Srv
X-CSRF-TOKEN
X-Vgn-Hpd-Ssi
True-Client-IP
X-GeoIP-City
Lb
Path
NtCoent-Length
X-Vgn-Hpd-Cached
X-Vgn-Hpd-Variations-Key
Cache-Tv-Group
X-Is-Desktop
X-Browser-Name
X-Tcp-Rtt
X-Is-Mobile
X-Is-Tablet
X-Is-Supported-Browser
X-HS-Status
X-Rebelmouse-Surrogate-Control
X-TRACE-ID
X-Rebelmouse-Cache-Control
X-Scheme
X-Hyper-Cache
Epwk-X-Cache
X-FPC
HostName
X-Frame-Option
Kp-EeAlive
Fastly-Drupal-Html
Tcn
X-HostName
X-GoCache-CacheStatus
X-Service
X-Location
Ohc-File-Size
X-SRV
X-Amz-Meta-Opti
X-Mobile-URL
Cf-Ipcountry
X-UA
X-APP-VERSION
CountryCode
Serverid
X-TX-ID
On-Server
X-Aicache-OS
X-Men
X-Air-Pt
X-AK-Request-ID
X-Esi
CacheControlHeader
X-Webstats-RespID
Cdnsip
Cdncip
X-Region-Sid
X-Developers
X-Guploader-Uploadid
Tube-Got-Results
V-Age
Tube-Got-Eval
X-Wp-Cf-Super-Cache-Cache-Control
X-Wp-Cf-Super-Cache
Tube-Return
X-CDN-Cache-Status
X-Cache-Ttl
X-Branch-Name
X-Traceid
RNT-Machine
RNT-Time
X-SB
Tube-Get-Contents
X-Req
X-V-Cache
X-Cache-FS-Status
Click-Count-Action-Start
X-Via-Popv
X-Minions-Version
X-Via-Popn
X-Acquia-Purge-Cdn-Unconfigured
Proxy-Connection
X-EC-Lua
Mime-Version
X-LB-ID
X-Cache-Tags
X-B3-Trace-ID
Click-Count-Error
WebServer
X-Via-Poph
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-Pad
XkeyRZ
Env
WWW-Authenticate
X-Servedbyhost
X-Cdn-Cache-Status
ENV
X-Nc
X-Wa
X-Vc
Yak-Timeinfo
CF-Cached-On
Ohc-Cache-HIT
X-Proxy-CacheRZ
WZWS-RAY
CDN
X-VCL-Version
X-CACHE-KEY
X-User
X-NWS-UUID-VERIFY
X-Akamai-Pragma-Client-IP
Ngx
X-Edge-Pop
X-Edge-Server
Geoip-Latitude
Cdn-Host
Cdn-Request-Time
LB
X-Fastly-Country-Code
X-Cdn-Forward
X-Lb-Cache
X-Check-Cacheable
Content-Script-Type
X-Country-Code-Real
Req-ID
X-Vercel-Id
Content-Style-Type
Server-Id
X-Origin-Cache-Key
X-TH-Server
X-Ckpd-Fst-Backend
X-Ha-Backend
M-TraceId
X-FTR-Balancer
X-Processor
X-FTR-Expires
X-NMSegId
X-Vercel-Cache
X-FTR-Cache-Status
X-FTR-Backend-Server
X-FTR-Backend
X-TT-LOGID
X-APP
X-Cdn-Request-ID
X-Acquia-Site
X-Acquia-Purge-Tags
X-Litespeed-Cache-Control
X-Dw-Trace-Id
X-Acquia-Application-UUID
PICS-Label
X-WP-CF-Super-Cache-Cookies-Bypass
X-Lb-Nocache
X-Snapshot-Date
X-Via-Ucdn
X-Edge-POP
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
X-CUA
X-Acquia-Application-Trace
X-Render-Time
X-Ad-Load-Variation
X-MiniProfiler-Ids
Cluster
HIT
Yjs-Id
X-Miniprofiler-Ids
Cneonction
X-Serial
X-Udemy-Cache-App-Namespace
X-Fastly-Backend-Reqs
Inserted-Into-Cache-At
Edge-Cache
CACHE-MISS-TO-ORIGIN
Sm-Log-Id
X-Iauth-Set-Uid
X-Response-By
X-Fastly-Cache-Hits
X-Cache-Date
X-Service-Response-Time
X-M-Log
X-M-Reqid
Log-Origin
X-ElasticPress-Query
Vha6-Origin
X-Cached-Since
X-RAMCache