Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
X-Powered-By
Pragma
CF-RAY
X-XSS-Protection
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
Alt-Svc
X-Xss-Protection
P3P
X-Cache-Hits
X-UA-Compatible
X-Served-By
CF-Ray
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
Access-Control-Allow-Credentials
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
X-Drupal-Cache
X-Cache-Status
X-Generator
X-Check
X-Cacheable
X-FRAME-OPTIONS
X-Envoy-Upstream-Service-Time
Timing-Allow-Origin
X-Iinfo
X-DNS-Prefetch-Control
X-Dns-Prefetch-Control
Server-Timing
X-Drupal-Dynamic-Cache
Feature-Policy
X-Content-Security-Policy
Access-Control-Expose-Headers
X-XSS-PROTECTION
Content-Encoding
X-CDN
Status
Upgrade
X-AspNetMvc-Version
Access-Control-Max-Age
X-Request-ID
X-Via
X-Amz-Request-Id
X-Ua-Compatible
X-Amz-Id-2
Request-Context
X-Backend
X-Cache-Group
X-Turbo-Charged-By
X-Robots-Tag
Cf-Edge-Cache
Keep-Alive
Host-Header
X-AH-Environment
X-Vhost
X-Hacker
X-UA-Device
X-Proxy-Cache
X-Server
Allow
X-Rq
X-Server-Powered-By
X-Ws-Request-Id
X-Dispatcher
EagleId
X-Age
X-Varnish-Cache
X-Amz-Version-Id
P3p
Nel
X-LiteSpeed-Cache
Grace
Cf-Apo-Via
Cf-Railgun
X-Page-Speed
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
EagleEye-TraceId
X-Device
X-Swift-CacheTime
X-Swift-SaveTime
X-OneAgent-JS-Injection
X-Aws-Lambda-Call-Status
Ali-Swift-Global-Savetime
X-Pingback
X-Host
X-CST
X-Cache-Lookup
Accept-CH
X-Node
X-WebKit-CSP
X-Backend-Server
Surrogate-Control
X-Server-Id
Permissions-Policy
X-Readtime
X-Nginx-Upstream-Cache-Status
X-Akam-SW-Version
X-Nginx-Cache-Status
Accept-CH-Lifetime
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Application-Context
Request-Id
Xkey
X-Cloud-Trace-Context
X-Content-Security-Policy-Report-Only
X-Response-Time
X-HW
X-Ruxit-JS-Agent
X-Trace
X-Edge
Content-Location
X-Clacks-Overhead
X-Mod-Pagespeed
X-Url
Rating
X-ESI
X-Midtier
X-Amz-Server-Side-Encryption
X-ECACHE
Cache-Tag
X-Powered-By-Plesk
X-Rack-Cache
X-Oneagent-Js-Injection
Accept-Ch
X-MS-InvokeApp
X-D2id
Service-Worker-Allowed
X-Kinja-Revision
X-Exp-Variant
X-Kinja
X-Cdn-Fetch
X-GoogleNews-Bot
X-Use-Magma
X-Exp-Id
X-Kinja-Build
X-Kinja-Server
Verso
X-Vcap-Request-Id
X-Element-Page-Cache
X-Mcache
Edge-Control
X-Upstream
Accept-Ch-Lifetime
X-Country-Code
X-Country
Origin-Trial
X-Ac
X-Kinja-CCPA
RTSS
X-TtlSet
X-PC
X-Vname
X-Goog-Hash
X-Navigation-Version
X-VARITI-CCR
X-Abt-Application-Version
X-Browser-Type
X-Cache-TTL
Fastly-Restarts
X-NWS-LOG-UUID
X-Amz-Rid
X-Aspnetmvc-Version
X-Ruxit-Js-Agent
X-Varnish-TTL
X-Litespeed-Cache
X-Webkit-CSP
Cross-Origin-Opener-Policy
X-GitHub-Request-Id
X-Cached
X-Server-Name
X-Ttl
X-Amzn-Trace-Id
X-Times
X-Dw-Request-Base-Id
Pagespeed
X-Middleton-Display
Display
X-Sol
X-WebKit-CSP-Report-Only
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
SPRequestGuid
X-SharePointHealthScore
X-Pinterest-Rid
Pinterest-Version
Pinterest-Generated-By
SPIisLatency
X-Server-Lifecycle-Phase
SPRequestDuration
X-Erf-Bev-Bev-Is-Generated
X-Instrumentation
X-Erf-Bev-Bev
X-Kraken-Loop-Name
X-B3-Traceid
X-Cache-Key
X-FastCGI-Cache
X-Content-Type
AR-Request-ID
AR-SID
AR-PoweredBy
AR-ATIME
X-Powered-CMS
Arr-Disable-Session-Affinity
X-Version
X-Cnection
X-Mg-S
Response
X-Middleton-Response
X-Ser
X-Server-ID
X-Client-IP
Nginx-Cache
X-Jurisdiction
X-HP-Webp
X-HP-Trace-Id
X-Accel-Expires
Cache-Tags
X-T
AR-CACHE
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-RateLimit-Remaining
X-Fastly-Request-ID
X-NF-Request-ID
Edge-Cache-Tag
Cache-Status
X-Hits
X-Px
Public-Key-Pins
X-MSEdge-Ref
X-Recruiting
Front-End-Https
X-B3-TraceId
S
X-Daa-Tunnel
X-RateLimit-Limit
X-Shield-Request-Id
Payment
X-Frontend
X-LLID
Server-Node
X-Ua-Browser
X-Request-Processing-Time
X-Request-Received
Content-MD5
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
X-Goog-Metageneration
X-GUploader-UploadID
X-Content-Digest
MicrosoftSharePointTeamServices
X-Amz-Apigw-Id
Access-Control-Request-Method
X-Amzn-RequestId
X-DIS-Request-ID
X-Webkit-CSP-Report-Only
X-Protected-By
X-Forwarded-For
TP-Cache
Realpath
X-Microsite
X-Distributor
X-Request-Handler-Origin-Region
X-FB-Debug
Fastcgi-Cache
X-PressLabs-Stats
X-HS-Hub-Id
X-HS-Content-Id
X-Page-Id
X-HS-Combine-CSS
Access-Control-Allow-Method
X-HS-Cache-Config
Accept-Charset
X-Cluster-Name
X-Rid
X-LB-Cache
X-Xrds-Location
X-Id
Count-Hit
X-Aspnet-Version
X-Ua-Device
X-Goog-Stored-Content-Length
X-B3-Sampled
X-Edge-Location-Klb
X-Geo-Country
X-Goog-Generation
X-Kinsta-Cache
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-TTL
X-Hostname
Cross-Origin-Resource-Policy
X-Ratelimit-Remaining
TP-L2-Cache
X-App-Server
X-Seen-By
X-Correlation-Id
X-Varnish-Backend
X-TEC-API-ROOT
X-TEC-API-ORIGIN
TCN
X-Logged-In
X-TEC-API-VERSION
X-Ezoic-Cdn
Cleartype
X-Fastcgi-Cache
X-Hosted-By
X-Git-Hash
X-Mobile
X-Content-Options
Referer-Policy
X-COUNTRY
DC
X-Erf-Stays-Pdp-Viaduct-Migration-Web
Retry-After
X-Fb-Rlafr
X-Contextid
X-Providence-Cookie
X-Is-Crawler
X-Request-Guid
X-F-Cache
X-Flags
X-Route-Name
X-Aspnet-Duration-Ms
Surrogate-Key
X-Revision
X-Grace
X-Ratelimit-Limit
X-Forwarded-Proto
X-App-Environment
X-Origin-Cache
X-TT
X-Amz-Replication-Status
X-Debug-Info
Frame-Options
X-Varnish-Grace
X-Newrelic-App-Data
X-Amz-Meta-S3cmd-Attrs
X-IPS-LoggedIn
X-RateLimit-Reset
X-Azure-Ref
MS-Author-Via
X-Envoy-Decorator-Operation
Section-Io-Cache
X-Magnolia-Registration
X-Www-Served-By
X-Wix-Request-Id
X-Proxy-Cache-Info
X-Trace-Id
X-App-Version
X-Whom
X-Webkit-Csp
X-Language
Healthy
X-Activity-Id
Filterid
X-AppVersion
X-Az
Charset
X-Akamai-Edgescape
WPO-Cache-Status
Viewport
WPO-Cache-Message
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Origin-Server
X-Varnish-Server
Alternate-Protocol
Server-Name
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
X-Datadog-Trace-Id
X-Backend-Name
Amp-Access-Control-Allow-Source-Origin
Paypal-Debug-Id
X-Client-Ip
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-Cache-Rule
X-B
X-N
X-EdgeConnect-Cache-Status
X-Response-Served-From
X-Http-Reason
X-Original-Request-Id
Host
X-DataDome
X-Rule
X-UUID
X-User-Agent
X-Edge-Location
SRV
X-Cacheable-TTL
X-Akamai-Request-ID2
Front
X-Instance
X-Nf-Request-Id
X-Cache-Grace
X-Region
X-Load-Cache
Protected
X-Yottaa-Metrics
X-Yottaa-Optimizations
Country
X-Unique-Id
X-Page-View
X-L-Path
SD-X-WS
X-ARC
X-Environment-Context
X-Framework
X-Signature
X-B-Cache
Content-Disposition
X-Mg-Request-UUID
From-Origin
X-Vcache
X-Jobs
X-FW-Static
X-FW-Server
X-FW-Type
X-FW-Version
X-Is-Bot
X-FW-Serve
X-FW-Hash
X-Adobe-Loc
X-Adobe-Content
Fastly-SIE
X-Datadog-Sampled
X-FW-Dynamic
Akamai-GRN
X-Varnish-Age
X-ProcessESI
X-Status
Fastly-SWR
X-Rendered-As
X-Rocket-Nginx-Serving-Static
X-RemovedCookies
X-Tumblr-Pixel-1
X-Tumblr-User
X-Cache-Time
X-Tumblr-Pixel-0
X-G
X-Type
X-Proxy
X-Tumblr-Pixel
X-Amzn-Remapped-Content-Length
X-Debug-IsConnected
X-Debug-IsPreview
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
Access-Control-Request-Headers
ServerID
X-ECache
X-CDN-Forward
X-Time
X-Tec-Api-Origin
Backend
X-Tec-Api-Root
X-Tec-Api-Version
X-MCACHE
X-Erf-Web-Scheduler
X-Servername
X-Cache-Age
X-DynaTrace
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Cache-Control
Xet-Cookie
Refresh
Url
X-Httpd
X-Template
Accept-Language
CF-IPCountry
X-Drupal-Cache-Tags
X-Nginx-Cache
X-Device-Type
X-DynaTrace-JS-Agent
Countrycode
X-NYM-Debug-Backend
X-Mode
X-Content-Powered-By
X-Generated-By
X-FTR-Request-ID
X-HTML-Minification-Powered-By
Webserver
X-Cache-Hit
Xserver
X-CCDN-Origin-Time
X-CCDN-CacheTTL
X-Hcs-Proxy-Type
X-Storage
GEO-INFO
Meta-Geo
Locale
X-UPSTREAM-Address
X-SayCDN-TTL
X-XRDS-LOCATION
X-Rewrite-Enabled
X-GeoCode
X-Say-TTL
X-Urbn-Context-Path
X-Rn-Rsrv
X-Loop
X-LAGOON
X-Content-Age
X-GeoCountry
X-JoinUs
Filters
X-SaId
X-Director
S-Rt
Cross-Origin-Window-Policy
X-Cache-Operation
X-ServerID
X-Urbn-Site-Id
X-Say-Cacheable
Load-Balancing
X-Soup
X-Tncms
Onion-Location
OT-Force-Account-Verify
X-Varnish-Cache-Hits
X-Served-From
X-Cluster-Node
X-Git-Commit
Version
X-Cache-Action
X-Forwarded-Host
X-Tt-Logid
X-Container-Uri
X-Source
X-Detected-As
Azure-SiteName
X-Ms-Version
X-VCT
Azure-SlotName
Azure-Version
Web-Mar-Node
X-Adobe-Source
X-Sql-Count
X-VC-Cache
X-RM-Cache-TTL
X-Labrador-Cache-Channel
Azure-InstanceId
X-Tb
X-Sql-Duration-Ms
X-Skip-Cache
X-R9-Blue-Green-Version
Azure-RegionName
X-NGENIX-Cache
X-Lambda-Id
X-Ms-Request-Id
X-PHP-Host
X-Varnish-Hostname
X-Zipkin-Id
X-Logging-Id
X-Proxied
X-Routing-Service
X-Extlb
X-FB-TRIP-ID
X-Cache-Server
Mn-Server-Ip
DB-Nickname
Node
X-B3-SpanId
X-RCS-CacheZone
X-Redis-Cache
TWC-Privacy
Fastcgi-Useragent
Property-Id
Selected-Fe
TWC-Locale-Group
TWC-Connection-Speed
TWC-GeoIP-Country
X-Timing-Wait
TWC-GeoIP-LatLong
X-Proxy-Build
X-Origin-Hint
Webcakes-App-Version
X-Tumblr-Pixel-3
X-Tumblr-Pixel-2
Webcakes-Region
X-Uri
Webcakes-App-Name
X-Format
X-Debug
X-Fetched-On
X-Generation-Time
TWC-Device-Class
X-Proto
X-Endurance-Cache-Level
Uber-Trace-Id
Source
X-LSADC-Cache
X-Zen-Fury
CDN-RequestId
X-Ua
X-Sucuri-Cache
X-Sucuri-ID
X-S
X-XRDS-Location
Section-Origin-Responded
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
Section-Io-Id
X-TimeS
NGB
X-Origin-CC
X-Origin-TTL
X-Newrelic-Synthetics
X-Akamai-Transformed
X-URL
Upgrade-Insecure-Requests
X-Drupal-Cache-Contexts
X-Origin-Date
X-MP-GENERATED-AT
X-Pass-Why
X-Handled-By
X-Varnish-Hits
X-Real-IP
X-TraceId
Fastly-Drupal-HTML
X-Cache-Expired-At
X-Ratelimit-Reset
X-Reqid
X-No-Session
X-Xfnlog-Site
X-RTag
X-Srv
MS-CV
Apigw-Requestid
X-Cms-Context
Ms-Operation-Id
X-AB
X-Restarts
ServedBy
X-CACHE-AGE
X-ProxyCache-Key
X-ProxyCache-Status
X-TIME
Liferay-Portal
X-Cache-Host
X-BYPASS-REASON
X-GEO
X-Optimistic-Header
X-Hl-Ver
X-Tx-Id
WP-Super-Cache
X-Varnish-Ttl
X-Cache-Type
CDN-RequestPullCode
X-IPLB-Instance
X-IPLB-Request-ID
CDN-RequestCountryCode
X-AWS-Id
CDN-Cache
X-Geo-Region
CDN-CachedAt
CDN-EdgeStorageId
CDN-PullZone
X-LJ-Flow-ID
X-Cluster
X-VWS-Id
CDN-RequestPullSuccess
CDN-Uid
X-Fastly-Request-Id
X-UA-Device-Type
X-Oracle-Dms-Ecid
X-Cache-TTL-Remaining
X-Oracle-Dms-Rid
X-Node-Name
Cache-Provider
X-Proxy-Cache-Status
X-A-Wwc
X-Micro-Cache
X-A-Dgt
X-Rojux
X-S-Cookie
Ha-Gx-Prefs
Origin-Agent-Cluster
X-ScT
X-A-Dcw
Candidate-Md5Url
Odigeo-Trace-Id
Canary
X-App
X-Aed
Web-Mar-Region
X-Level-Front-Cache
Sslversion
Vix-Hermes-Req-Id
Server-Host
X-Pool
True-Client-Country-4JS
Surrogated-Key
X-PAYTM-SRV-ID
Rendered-Blocks
T-Server
Redirect-Candidate
Ngx.Var.Host
X-Pubstack
X-Cache-Status-Check
X-External-Request-Id
X-A-Ccd
X-A-Dam
X-A
X-Parent-Response-Time
W
X-Qloud-Router
BehaviorPad-Version
X-Owner
X-Request-Host
Meta-Geo-Continent
X-Fastly-Backend
X-D
X-Upgrade-Enabled
X-SRCache-Key
X-Vdms-Path
X-Vdms-Version
X-Csrf-Jwt
L
X-Conf
Lang
X-Application
X-Viewer-Country
L5d-Success-Class
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-Ec-Fail
X-Ec-Custom-Error
X-Ec-GeoHdr
X-Epic-Correlation-Id
X-Eu-Site
X-Thanos
HA-Ipaddr
Gannett-Cam-Experience-Id
Fastly-SSL
X-Destination
X-Developer
X-Dispatcher-Number
X-Vtex-Remote-Cache
X-FC-Vary-Parameters
MD5-Digest
X-Bl-Debug
X-Slack-Backend
X-Slack-Shared-Secret-Outcome
X-Worker
X-Bip
X-BCube-Filmed-By
X-Generated-On
X-B-Cookie
N-Cache
X-Bc-Bl
Magicmarker
Xc-Version
X-CF-Lambda-Fn
X-We-Are-Hiring
DCR-Processing-Time-Ms
X-Cache-NE
X-CacheTTL
X-CF-Lambda-Version
DCR-Decision-By
X-CGP
X-CSRF-Token
X-Via-JSL
X-Mid
Platform
Req-Svc-Chain
X-Loc
Release
Producers
X-Nananana
Mail-Subject
X-Mly-Id
Is-Eu
X-Mvc-Supplant-Cachable
Machine
Host-ID
X-Human
X-Cdn-Diag
X-Cdn-Origin
X-Clientip
X-Cache-Info
X-Cache-Debug
X-Forwarded-Path
X-Cache-Bucket
X-CMSURLCustom
X-Core-Mission
X-Dispatcher-Server
X-DPWN-IS-SECURE
X-DefHash
X-DefElseHash
X-Core-Value
X-Date
X-BBC-Edge-Cache-Status
X-Gdpr
VNS-Age
VNS-Cache
We-Hiring
Thinkindot-Control
Thinkindot-CacheControl-Type
TDXMobile
Thinkindot-CacheControl
X-Accel-Buffering
X-Accel-Expires-Debug
X-ApacheServer
X-App-Name
X-Geo-Header
X-Alternate-Cache-Key
X-GeoIP-Region-Code
X-GeoIP-Country-Code
X-Irp-Debug
X-NodeID
X-PERF
X-Origin-Time
X-Sorting-Hat-PodId
X-Platform
X-Sn-Servicetimems
X-Hash
X-Sorting-Hat-ShopId
X-Orig-Expires
X-VG-TLSProxy
X-Old-Content-Length
X-VG-WebCache
X-Vmg-Version
Origin
X-Wikidot-Backend
X-Policy
X-ShopId
X-Shopify-Stage
Gh-Request-Id
X-Shop-Environment
X-SD-PageType
X-ShardId
Datacenter
X-Request-Time
X-Server-W
X-Wikidot-Static-Cache
X-Wix-Viewer-Type
X-Vgn-Hpd-Reason
X-Refresh
X-Nyt-Route
X-VServer
CPC-Age
CPC-Cache
X-Variation
Cmstype
X-Varnish-CookieHashed-On
Adler-Geo
X-Var-Ttl
X-Up
X-Thinkindot-L3
X-Nitro-Cache
Fastly-GeoIP-CountryCode
Fastly-Backend-Name
Environment
Expect-Staple
CloudFront-Viewer-Country
Cmsid
X-Varnish-CookieINHashed-On
X-SVT-ORM-VERSION
X-Varnish-Remaining-TTL
X-Storefront-Renderer-Rendered
AKAMAI
Cache-Name
X-SVT-ORM-RULES
X-Tenant
X-Correlation-ID
X-Accel-Version
X-AIR-PT
NM-Fastcgi-Cache
X-WA-Info
X-Auto-Login
X-Server-IP
X-Varnishpool
X-Gen-Mode
X-Ah-Environment
X-Datadome
X-Clara-WADP
X-Cache-Id
X-WADP-Cache
X-Esi-Check
Esi-Enabled
X-Block-Status
X-Fmm-Version
X-Is-Supported-Browser
Sever-Int
X-Op-Id-All
Server-Hostname
Server-Ext
X-Origin
X-Origin-Response-Time
User-Cache-Control
X-INCAP-ABP
X-Test
Apple-News-Services-Handled
Apple-News-Services-Host
Country-Code
DSUID
X-NCache
X-Nginx-Cache-Key
Cf-Device-Type
CDCHOST
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
X-Mvc-Supplant-OutputCached
X-GeoIP
X-Org
X-Is-Desktop
X-Browser-Name
X-S-Maxage
X-Gzip
X-Tcp-Rtt
X-Hnp-Log
X-Device-Os
X-Is-Tablet
X-Is-Mobile
X-From
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Buckets
X-B3-Spanid
X-Forwarded-Site
C-Via
NGX
Ssr
X-Section
X-Node-Id
Wxu-Next-Commit
Pics-Label
X-Vcl-Version
X-Cache-Enabled
Server-Info
X-Cdn-Srv
X-Instance-Name
Wxu-Next-Region
X-LB-NoCache
X-Access
X-Via-Fastly
Wxu-Next-Hostname
AMP-Access-Control-Allow-Source-Origin
Content-Secure-Policy
X-Akamai-Device-Characteristics
X-Dc
Server-ID
X-Varnish-Beresp-Ttl
X-Varnish-Beresp-Grace
X-CACHE-GROUP
X-Zone
X-Presslabs-Stats
X-Amz-Meta-Cb-Modifiedtime
X-API-Version
X-Origin-Cache-Key
IsBot
X-HA-Backend
X-SIPLIST1
YJS-ID
X-WP-CF-Super-Cache-Active
X-B3-Parentspanid
CF-Ctrl
Hostname
X-Platform-Cluster
X-Platform-Processor
X-Platform-Router
X-JWT-State
X-Frame-Option
X-Is-Gdpr
X-Has-Esi
Memcached
Cdn-Requestid
X-Cached-By
Sid
Time
Memory
Location
X-Internal-Host
X-Wp-Cf-Super-Cache-Active
X-FTR-Expires
X-FTR-Cache-Status
X-FTR-Backend-Server
X-Country-Code-Real
X-FTR-Balancer
X-FTR-Backend
X-NewRelic-App-Data
X-TIM-N
X-Tb-Optimization-Total-Bytes-Saved
X-Air-Hostname
X-Air-Source
X-Hyper-Cache
X-Fpc
Cache-Hits
X-Scale
X-Air-Trace-Id
Origin-EX
Origin-CC
X-TA-CDN-Provider
X-LiteSpeed-Cache-Control
X-Backend-Instance
X-Webstats-RespID
X-ID
X-Cs
X-DC
X-NGINX-Cache
X-Service
X-SRV
X-PHP-Backend
X-ZONE
Epwk-X-Cache
X-VC
X-DataCenter
Resin-Trace
LB
X-Site-Version
Uri
GeoIp-Country-Code
X-Azure-Ref-OriginShield
X-Nitro-Rev
X-CSRF-TOKEN
True-Client-Ip
GeoIP-Latitude
Cdn-Request-Time
Cdn-Host
X-Edge-Server
X-Nitro-Cache-From
X-NODE
X-NMSegId
WZWS-RAY
X-Microcachable
X-Locale
X-VCache
True-Client-IP
GeoIP-Country-Code
Req-ID
X-Ad-Load-Variation
Cache-Host
XServer
X-Cache-Ttl
X-Origin-Expires
X-Request-URI
X-M-Log
Cdn
SID
X-M-Reqid
X-Datacenter
M-TraceId
XM
NtCoent-Length
Pramga
X-Info
X-Scope-Id
X-Geo
Cluster
X-HN
X-Varnish-Beresp-Status
X-Shield-Cache-Expires
X-Qnm-Cache
X-Vercel-Cache
X-VarnishDD-TTL
X-Vercel-Id
X-Pad
WebServer
X-Pod-Name
Content-Style-Type
Content-Script-Type
PFcat
X-Github-Request-Id
X-Request-Start
CountryCode
X-WP-CF-Super-Cache-Cookies-Bypass
Cache-Tv-Group
Fastly-Drupal-Html
X-FPC
HostName
User-Agent
X-Ad-Defer-Variation
X-Web-Node
X-Cache-Date
X-HostName
Tcn
X-MSEdge-Features
X-MSEdge-Flight
X-FL-EDGE
Edge-Copy-Time
X-FL-QIT-DEBUG
X-Via-CDN
X-Via-Edge
Srvid
X-TH-Server
A
Locid
X-Via-SSL
X-Api-Version
X-LiteSpeed-Tag
X-CS
X-Cdn-Request-ID
Cf-Ipcountry
X-APP-VERSION
Edge-Cache
Tube-Got-Eval
X-NWS-UUID-VERIFY
X-AK-Request-ID
Tube-Return
X-Nc
X-Cache-FS-Status
X-Aicache-OS
Cdncip
X-B3-Trace-ID
X-Acquia-Purge-Cdn-Unconfigured
X-Amz-Meta-Opti
Tube-Get-Contents
Click-Count-Error
Cdnsip
X-Wa
Click-Count-Action-Start
X-Via-Popv
Tube-Got-Results
X-Via-Popn
X-Webkit-Csp-Report-Only
X-V-Cache
X-Servedbyhost
X-Via-Poph
X-Esi
V-Age
X-Men
X-Moov-T
X-Moov-Xdn-Version
X-Cache-ASPX
X-ATG-Version
X-Vary
On-Server
Path
X-LB-ID
X-Branch-Name
X-Varnish-Authentication
X-Req
X-SB
MIME-Version
X-Contensis-Viewer-Groups
X-FireWall-Port
Priority
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-VCL-Version
XkeyRZ
X-Proxy-CacheRZ
Cache-Key
Ngx-Var-Key
Yak-Timeinfo
X-UA
X-CACHE-KEY
CDN
X-Tim-N
My-App
Wpo-Cache-Message
X-Akamai-Pragma-Client-IP
X-Render-Time
X-Cdn-Forward
Wpo-Cache-Status
Srv
X-Acquia-Application-Trace
X-Acquia-Purge-Tags
X-Acquia-Site
Geoip-Latitude
X-Acquia-Application-UUID
Proxy-Connection
X-Fastly-Backend-Reqs
X-Lb-Cache
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-Provided-By
Lb
X-Fastly-Country-Code
X-User
X-Ha-Backend
Server-Id
X-Generated-In
X-Varnish-Director
X-Air-Pt
Yjs-Id
X-TT-LOGID
X-TRACE-ID
X-CUA
Ohc-Cache-HIT
Ohc-File-Size
X-Wp-Cf-Super-Cache-Cache-Control
X-Wp-Cf-Super-Cache
X-Via-Ucdn
X-Dw-Trace-Id
State
X-Platform-Server
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
PICS-Label
X-HS-Content-Campaign-Id
X-EC-Lua
CF-Cached-On
X-Lb-Nocache
X-Iplb-Instance
X-Iplb-Request-Id
Fusion-Content-Id
Fusion-Content-Source
Fusion-Component-Id
Warning
X-CF-Cache-Header-Cache-Control
Fusion-Deployment-Id
Inserted-Into-Cache-At
Fusion-Source
X-Gamma-Serve
X-GoCache-CacheStatus
X-Lb-Id
X-CDN-Cache-Status
Cross-Origin-Embedder-Policy-Report-Only
Fusion-Template-Id
Type
X-Cdn-Cache-Status
Cneonction
X-Udemy-Cache-App-Namespace
X-Cached-Since
Vha6-Origin
X-Fastly-Cache
X-ElasticPress-Query
X-Litespeed-Cache-Control
X-RAMCache
Ngx
X-Cache-Remote
Cache
X-Fastly-Cache-Hits
X-Vgn-Hpd-Cached
X-Snapshot-Date
X-HS-Status
X-Vgn-Hpd-Ssi
X-Vgn-Hpd-Variations-Key
X-Release
X-Miniprofiler-Ids
X-CF-Cache-Header-Vary
Log-Origin