Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
X-Powered-By
Pragma
CF-RAY
X-XSS-Protection
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
Alt-Svc
X-Xss-Protection
P3P
X-Cache-Hits
X-UA-Compatible
X-Served-By
CF-Ray
X-Download-Options
X-Timer
X-Request-Id
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
Access-Control-Allow-Credentials
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
X-Drupal-Cache
X-Cache-Status
X-Generator
X-Check
X-Cacheable
X-Envoy-Upstream-Service-Time
X-FRAME-OPTIONS
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Iinfo
X-Dns-Prefetch-Control
X-Request-ID
X-Drupal-Dynamic-Cache
Server-Timing
Feature-Policy
X-Content-Security-Policy
Access-Control-Expose-Headers
Content-Encoding
X-CDN
X-XSS-PROTECTION
Status
Upgrade
X-AspNetMvc-Version
Access-Control-Max-Age
X-Amz-Request-Id
X-Via
X-Amz-Id-2
Request-Context
X-Backend
X-Turbo-Charged-By
X-Cache-Group
X-Robots-Tag
X-AH-Environment
Cf-Edge-Cache
Keep-Alive
Host-Header
X-Hacker
X-Vhost
X-UA-Device
X-Proxy-Cache
X-Server
X-Rq
Allow
X-Server-Powered-By
X-Ws-Request-Id
X-Age
X-Dispatcher
EagleId
X-Varnish-Cache
X-Amz-Version-Id
P3p
X-LiteSpeed-Cache
Nel
Grace
X-Ua-Compatible
Cf-Apo-Via
Cf-Railgun
X-Page-Speed
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Device
EagleEye-TraceId
X-Swift-SaveTime
X-Swift-CacheTime
X-OneAgent-JS-Injection
X-Aws-Lambda-Call-Status
Ali-Swift-Global-Savetime
X-Pingback
X-Host
X-Node
Accept-CH
X-Cache-Lookup
X-CST
X-WebKit-CSP
X-Backend-Server
Surrogate-Control
X-Server-Id
Permissions-Policy
Accept-CH-Lifetime
X-Readtime
X-Nginx-Cache-Status
X-Nginx-Upstream-Cache-Status
X-Akam-SW-Version
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
Request-Id
X-Application-Context
X-Content-Security-Policy-Report-Only
X-Cloud-Trace-Context
X-Response-Time
X-Ruxit-JS-Agent
Xkey
X-HW
X-Trace
X-Edge
Content-Location
X-Clacks-Overhead
X-Mod-Pagespeed
X-Url
Rating
X-ESI
X-Midtier
X-Amz-Server-Side-Encryption
X-ECACHE
X-Mcache
Cache-Tag
X-Country
X-MS-InvokeApp
X-Rack-Cache
X-Powered-By-Plesk
X-D2id
X-Kinja-Revision
X-Kinja-Build
X-Kinja-Server
X-Exp-Variant
X-Use-Magma
X-GoogleNews-Bot
X-Exp-Id
X-Cdn-Fetch
X-Kinja
X-Oneagent-Js-Injection
X-Upstream
X-Vcap-Request-Id
X-Element-Page-Cache
Verso
Accept-Ch
Service-Worker-Allowed
Edge-Control
X-Vname
X-PC
X-TtlSet
RTSS
X-Country-Code
X-Ac
Origin-Trial
X-Goog-Hash
Accept-Ch-Lifetime
X-VARITI-CCR
X-Navigation-Version
X-Abt-Application-Version
X-Cache-TTL
Fastly-Restarts
X-Browser-Type
X-Kinja-CCPA
X-Amz-Rid
X-Varnish-TTL
X-Litespeed-Cache
X-Cached
X-WebKit-CSP-Report-Only
X-NWS-LOG-UUID
X-Aspnetmvc-Version
X-Ruxit-Js-Agent
Cross-Origin-Opener-Policy
X-GitHub-Request-Id
X-Server-Name
X-Webkit-CSP
X-Middleton-Display
X-Sol
Display
Pagespeed
X-Amzn-Trace-Id
X-Dw-Request-Base-Id
X-SharePointHealthScore
SPRequestGuid
X-Ttl
X-Times
X-Content-Type
SPRequestDuration
SPIisLatency
X-Erf-Bev-Bev-Is-Generated
X-Kraken-Loop-Name
X-Instrumentation
X-Server-Lifecycle-Phase
X-Server-ID
X-Erf-Bev-Bev
X-Pinterest-Rid
Pinterest-Generated-By
Pinterest-Version
X-Cache-Key
AR-SID
AR-Request-ID
AR-PoweredBy
AR-ATIME
X-Powered-CMS
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
X-Mg-S
Arr-Disable-Session-Affinity
Response
X-Middleton-Response
X-Version
X-Ser
X-Cnection
X-HP-Trace-Id
X-Jurisdiction
X-HP-Webp
X-B3-Traceid
X-B3-TraceId
Nginx-Cache
X-FastCGI-Cache
X-Accel-Expires
Cache-Tags
AR-CACHE
X-Client-IP
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-T
Cache-Status
X-NF-Request-ID
X-Fastly-Request-ID
Edge-Cache-Tag
X-Hits
Front-End-Https
X-MSEdge-Ref
X-Px
Public-Key-Pins
X-Recruiting
S
X-Shield-Request-Id
Payment
X-Frontend
X-RateLimit-Remaining
X-LLID
X-Ua-Browser
Server-Node
X-Daa-Tunnel
MRF-Tech
X-B3-TraceId-Primal
X-Request-Received
X-Request-Processing-Time
Mrf-Cache-Status
X-Goog-Metageneration
X-GUploader-UploadID
Content-MD5
X-Webkit-CSP-Report-Only
X-DIS-Request-ID
X-RateLimit-Limit
Access-Control-Request-Method
MicrosoftSharePointTeamServices
X-Content-Digest
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Ratelimit-Remaining
TP-Cache
Realpath
X-Forwarded-For
X-Protected-By
X-Request-Handler-Origin-Region
X-Distributor
X-Microsite
X-HS-Content-Id
X-HS-Cache-Config
X-HS-Hub-Id
X-HS-Combine-CSS
X-FB-Debug
Fastcgi-Cache
Access-Control-Allow-Method
X-TTL
X-Page-Id
X-Fastcgi-Cache
X-LB-Cache
Accept-Charset
X-Rid
X-Cluster-Name
X-PressLabs-Stats
X-Webkit-Csp
X-Geo-Country
X-Hostname
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-Goog-Generation
X-Goog-Stored-Content-Encoding
Count-Hit
X-B3-Sampled
X-Xrds-Location
TP-L2-Cache
X-Ratelimit-Limit
X-Aspnet-Version
X-Ua-Device
Cross-Origin-Resource-Policy
X-Edge-Location-Klb
X-Seen-By
X-Correlation-Id
X-Kinsta-Cache
X-Ezoic-Cdn
X-Id
Cleartype
X-Erf-Stays-Pdp-Viaduct-Migration-Web
TCN
X-App-Server
X-Logged-In
X-Varnish-Backend
X-TEC-API-ROOT
X-TEC-API-VERSION
Referer-Policy
X-TEC-API-ORIGIN
X-Mobile
X-Content-Options
X-Hosted-By
X-Git-Hash
DC
X-Contextid
X-Origin-Cache
X-Request-Guid
Retry-After
X-Aspnet-Duration-Ms
X-Fb-Rlafr
X-Route-Name
X-Providence-Cookie
X-Is-Crawler
X-Flags
Surrogate-Key
X-Debug-Info
X-Revision
X-Amz-Replication-Status
X-TT
X-Forwarded-Proto
X-App-Environment
X-Grace
X-Newrelic-App-Data
X-F-Cache
Frame-Options
X-Varnish-Grace
X-IPS-LoggedIn
X-Envoy-Decorator-Operation
X-Amz-Meta-S3cmd-Attrs
X-Azure-Ref
X-Magnolia-Registration
Section-Io-Cache
MS-Author-Via
X-Wix-Request-Id
X-Proxy-Cache-Info
X-Whom
Healthy
X-Client-Ip
Charset
X-Www-Served-By
X-App-Version
Viewport
X-Akamai-Edgescape
Alternate-Protocol
X-RateLimit-Reset
X-Origin-Server
X-COUNTRY
X-Backend-Name
X-Activity-Id
WPO-Cache-Message
WPO-Cache-Status
X-Az
X-AppVersion
Filterid
Amp-Access-Control-Allow-Source-Origin
X-Language
X-Varnish-Server
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
Server-Name
X-B
SRV
Paypal-Debug-Id
X-Datadog-Parent-Id
X-Trace-Id
X-DataDome
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
X-Cache-Rule
X-Http-Reason
X-EdgeConnect-Cache-Status
Host
X-Original-Request-Id
VIX-Pulpo-Upstream-Status
SD-X-WS
X-Response-Served-From
VIX-Pulpo-Node
X-Cache-Grace
X-Akamai-Request-ID2
Front
X-Rule
X-Time
X-UUID
X-Edge-Location
X-User-Agent
Protected
X-Cacheable-TTL
From-Origin
X-N
X-Instance
X-Region
X-Page-View
X-L-Path
X-Jobs
X-Unique-Id
X-Vcache
X-Environment-Context
X-ARC
X-Varnish-Age
X-FW-Version
X-Tumblr-Pixel-0
Country
Fastly-SIE
X-ProcessESI
X-Yottaa-Optimizations
X-RemovedCookies
X-Tumblr-User
X-Yottaa-Metrics
X-Is-Bot
X-Rendered-As
Akamai-GRN
X-FW-Type
X-Rocket-Nginx-Serving-Static
X-Tumblr-Pixel-1
X-FW-Dynamic
X-Tumblr-Pixel
X-Status
X-FW-Hash
X-FW-Serve
X-Framework
X-Adobe-Content
X-FW-Static
X-FW-Server
X-Adobe-Loc
Fastly-SWR
X-Load-Cache
X-G
X-Cache-Time
Content-Disposition
X-Nf-Request-Id
X-Signature
X-B-Cache
X-Proxy
X-Datadog-Sampled
X-Type
X-Mg-Request-UUID
ServerID
Access-Control-Request-Headers
X-Debug-IsPreview
X-Amzn-Remapped-Content-Length
X-Debug-IsConnected
X-CDN-Forward
Backend
X-Cache-Control
X-ECache
X-Cache-Age
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
X-Tec-Api-Version
X-Tec-Api-Root
X-Tec-Api-Origin
Countrycode
X-Nginx-Cache
X-Servername
X-DynaTrace
X-Httpd
Refresh
X-Drupal-Cache-Tags
Accept-Language
Url
X-Tt-Trace-Host
X-Erf-Web-Scheduler
Xet-Cookie
X-Tt-Trace-Tag
CF-IPCountry
X-DynaTrace-JS-Agent
X-Generated-By
X-Template
X-HTML-Minification-Powered-By
X-Device-Type
X-Mode
X-Content-Powered-By
X-NYM-Debug-Backend
Xserver
X-Source
X-Storage
GEO-INFO
Load-Balancing
S-Rt
X-Content-Age
X-Director
X-GeoCode
Filters
X-ServerID
Version
Locale
Meta-Geo
OT-Force-Account-Verify
X-LAGOON
X-SayCDN-TTL
X-Rn-Rsrv
X-UPSTREAM-Address
X-Cache-Operation
X-Cache-Hit
X-GeoCountry
X-Urbn-Context-Path
X-JoinUs
X-Rewrite-Enabled
X-Urbn-Site-Id
X-Say-TTL
X-Say-Cacheable
X-SaId
X-Cache-Action
X-Forwarded-Host
X-Container-Uri
X-Cluster-Node
Cross-Origin-Window-Policy
X-Soup
X-Tncms
X-Varnish-Hostname
X-Tt-Logid
X-Git-Commit
X-Loop
X-Varnish-Cache-Hits
X-Lambda-Id
X-RM-Cache-TTL
X-CCDN-Origin-Time
X-Hcs-Proxy-Type
Web-Mar-Node
X-Adobe-Source
X-VCT
Azure-SiteName
Azure-SlotName
Azure-Version
Azure-RegionName
Azure-InstanceId
X-VC-Cache
X-Labrador-Cache-Channel
X-CCDN-CacheTTL
X-Cache-Server
X-Tumblr-Pixel-2
X-Ms-Version
Webserver
Onion-Location
X-PHP-Host
X-Served-From
X-Tb
X-Sql-Count
X-Ms-Request-Id
X-Detected-As
X-Sql-Duration-Ms
X-Tumblr-Pixel-3
Node
DB-Nickname
X-FB-TRIP-ID
X-Proxied
X-R9-Blue-Green-Version
X-RCS-CacheZone
X-Extlb
X-Logging-Id
X-URL
Mn-Server-Ip
X-Routing-Service
X-Skip-Cache
X-XRDS-LOCATION
X-Zipkin-Id
TWC-Device-Class
Selected-Fe
X-Uri
TWC-Connection-Speed
Webcakes-Region
Webcakes-App-Version
X-Fetched-On
X-Origin-Hint
X-Timing-Wait
X-Proto
X-Proxy-Build
TWC-GeoIP-LatLong
TWC-Locale-Group
TWC-Privacy
TWC-GeoIP-Country
Webcakes-App-Name
X-B3-SpanId
X-MCACHE
X-Oracle-Dms-Rid
X-Oracle-Dms-Ecid
Property-Id
Fastcgi-Useragent
X-Format
X-Debug
X-XRDS-Location
X-Endurance-Cache-Level
X-Redis-Cache
X-NGENIX-Cache
Uber-Trace-Id
Source
X-Generation-Time
X-LSADC-Cache
X-Zen-Fury
CDN-RequestId
X-Ratelimit-Reset
X-Sucuri-Cache
X-Sucuri-ID
X-FTR-Request-ID
Section-Origin-Responded
Section-Io-Origin-Time-Seconds
X-S
Section-Io-Origin-Status
X-Ua
Section-Io-Id
X-Drupal-Cache-Contexts
X-Origin-TTL
X-Origin-CC
X-TimeS
NGB
X-MP-GENERATED-AT
X-Pass-Why
X-Origin-Date
X-Varnish-Hits
X-Real-IP
Fastly-Drupal-HTML
X-Srv
Upgrade-Insecure-Requests
X-Akamai-Transformed
X-Fastly-Request-Id
X-Cache-Expired-At
Liferay-Portal
X-Upgrade-Enabled
X-Handled-By
X-Optimistic-Header
X-Reqid
X-Cms-Context
X-CACHE-AGE
X-Xfnlog-Site
X-GEO
X-Newrelic-Synthetics
Apigw-Requestid
ServedBy
X-ProxyCache-Status
X-Cache-TTL-Remaining
X-ProxyCache-Key
X-No-Session
X-UA-Device-Type
X-Cache-Host
X-Restarts
X-Tx-Id
X-RTag
MS-CV
X-Hl-Ver
Ms-Operation-Id
X-BYPASS-REASON
CDN-Cache
CDN-RequestPullSuccess
X-CSRF-Token
X-Node-Name
CDN-PullZone
CDN-EdgeStorageId
CDN-CachedAt
CDN-RequestCountryCode
X-Via-JSL
X-Parent-Response-Time
CDN-Uid
WP-Super-Cache
CDN-RequestPullCode
X-AB
X-Varnish-Ttl
X-VWS-Id
X-Cluster
X-LJ-Flow-ID
X-Pubstack
X-AWS-Id
X-IPLB-Instance
X-IPLB-Request-ID
X-Cache-Type
Meta-Geo-Continent
N-Cache
Candidate-Md5Url
Ngx.Var.Host
DCR-Decision-By
DCR-Processing-Time-Ms
Canary
BehaviorPad-Version
X-Proxy-Cache-Status
Cache-Provider
Fastly-SSL
Gannett-Cam-Experience-Id
L5d-Success-Class
Lang
Magicmarker
L
Host-ID
Ha-Gx-Prefs
HA-Ipaddr
MD5-Digest
X-A-Dgt
X-Epic-Correlation-Id
X-Ec-GeoHdr
X-Eu-Site
X-External-Request-Id
X-FC-Vary-Parameters
X-Fastly-Backend
X-Ec-Fail
X-Ec-Custom-Error
X-Debug-Cache-Store
X-Debug-Cache-Fetch
X-Destination
X-Developer
X-Dispatcher-Number
X-Request-Host
X-Rojux
X-Viewer-Country
X-Vdms-Version
X-Vtex-Remote-Cache
X-We-Are-Hiring
Xc-Version
X-Worker
X-Vdms-Path
X-SRCache-Key
X-ScT
X-S-Cookie
X-SD-PageType
X-Slack-Backend
X-Slack-Shared-Secret-Outcome
X-D
X-Csrf-Jwt
Vix-Hermes-Req-Id
True-Client-Country-4JS
W
Web-Mar-Region
X-A-Ccd
X-A
T-Server
Surrogated-Key
Redirect-Candidate
Origin-Agent-Cluster
Rendered-Blocks
Server-Host
Sslversion
X-A-Dam
X-A-Dcw
X-CacheTTL
X-Cache-NE
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-Conf
X-CGP
X-Bl-Debug
X-BCube-Filmed-By
X-Aed
X-A-Wwc
X-App
X-Application
X-Bc-Bl
Odigeo-Trace-Id
X-B-Cookie
X-Micro-Cache
X-Server-W
X-Geo-Region
X-TraceId
X-Cache-Status-Check
X-Varnish-CookieINHashed-On
X-Wikidot-Backend
X-Varnish-CookieHashed-On
Mail-Subject
X-Core-Mission
X-Pool
X-Varnishpool
X-SVT-ORM-RULES
X-Thanos
X-Varnish-Remaining-TTL
X-Core-Value
X-Wikidot-Static-Cache
X-Wix-Viewer-Type
X-Hash
X-Accel-Buffering
Gh-Request-Id
X-Policy
X-Accel-Expires-Debug
X-GeoIP-Region-Code
X-GeoIP-Country-Code
X-Server-IP
X-Generated-On
X-Variation
Is-Eu
X-SVT-ORM-VERSION
X-ShardId
X-VG-WebCache
X-Sorting-Hat-ShopId
X-Storefront-Renderer-Rendered
X-DPWN-IS-SECURE
X-Sorting-Hat-PodId
X-VG-TLSProxy
X-DefHash
Thinkindot-Control
X-DefElseHash
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
TDXMobile
X-Sn-Servicetimems
VNS-Age
X-Shopify-Stage
X-Date
X-ShopId
We-Hiring
X-CMSURLCustom
Platform
Producers
Req-Svc-Chain
VNS-Cache
X-Vmg-Version
Release
X-VServer
Origin
Fastly-GeoIP-CountryCode
X-Request-Time
X-Loc
X-PAYTM-SRV-ID
X-Cache-Bucket
X-Mid
X-Level-Front-Cache
X-Thinkindot-L3
X-Bip
X-Cdn-Origin
X-Var-Ttl
Adler-Geo
X-Mly-Id
X-Refresh
X-Nitro-Cache
X-RateLimit-Limit-Second
X-Qloud-Router
X-Node-Id
X-Platform
X-Cdn-Diag
X-RateLimit-Remaining-Second
X-Mvc-Supplant-Cachable
X-Cache-Debug
X-Nananana
X-BBC-Edge-Cache-Status
X-NodeID
CPC-Cache
CPC-Age
Fastly-Backend-Name
Cmstype
Datacenter
X-Cache-Info
X-Clientip
X-Alternate-Cache-Key
Expect-Staple
Cmsid
X-App-Name
X-Old-Content-Length
X-Owner
X-Irp-Debug
Cache-Name
X-Human
X-Org
X-Up
X-S-Maxage
Environment
X-Presslabs-Stats
X-TIME
User-Cache-Control
X-Cache-Id
X-Origin-Time
X-Block-Status
X-Clara-WADP
X-Akamai-Device-Characteristics
X-Tenant
X-Auto-Login
X-Test
X-Correlation-ID
X-Forwarded-Site
CDCHOST
X-INCAP-ABP
X-Instance-Name
X-Dispatcher-Server
X-ApacheServer
Cf-Device-Type
AKAMAI
DSUID
CloudFront-Viewer-Country
Country-Code
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
X-Nginx-Cache-Key
X-Nyt-Route
X-Orig-Expires
X-Origin
X-Mvc-Supplant-OutputCached
X-PERF
Apple-News-Services-Host
Apple-News-Services-Handled
X-Geo-Header
X-AIR-PT
Esi-Enabled
X-Fmm-Version
X-Forwarded-Path
X-WA-Info
X-Hnp-Log
NM-Fastcgi-Cache
X-Shop-Environment
Server-Ext
X-Origin-Response-Time
X-Esi-Check
X-From
Sever-Int
X-GeoIP
X-Gzip
X-Device-Os
Server-Hostname
X-Gen-Mode
X-Gdpr
X-WADP-Cache
Machine
Content-Secure-Policy
X-Cdn-Srv
X-Section
X-LB-NoCache
Wxu-Next-Commit
Server-Info
Ssr
Wxu-Next-Hostname
Wxu-Next-Region
X-Vgn-Hpd-Reason
X-Via-Fastly
C-Via
NGX
X-NCache
X-Op-Id-All
X-ID
Pics-Label
X-Cache-Enabled
X-Datadome
X-Access
X-Accel-Version
X-B3-Spanid
X-Tcp-Rtt
X-Is-Supported-Browser
Server-ID
X-Browser-Name
X-Is-Mobile
X-Is-Tablet
X-Is-Desktop
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Ttl
AMP-Access-Control-Allow-Source-Origin
X-Buckets
X-HA-Backend
X-SIPLIST1
X-CACHE-GROUP
X-Dc
X-Vcl-Version
X-Amz-Meta-Cb-Modifiedtime
IsBot
X-API-Version
Memcached
X-Has-Esi
X-Is-Gdpr
X-JWT-State
X-Zone
Time
Hostname
X-Platform-Processor
X-Platform-Cluster
Memory
YJS-ID
X-B3-Parentspanid
X-Platform-Router
X-Wp-Cf-Super-Cache-Active
Cache-Hits
X-Scale
X-Cached-By
Origin-CC
Location
X-Tb-Optimization-Total-Bytes-Saved
X-TA-CDN-Provider
X-Origin-Cache-Key
Cdn-Requestid
CF-Ctrl
Origin-EX
X-Air-Hostname
X-Air-Source
Sid
X-WP-CF-Super-Cache-Active
X-Air-Trace-Id
X-Fpc
X-Internal-Host
X-TIM-N
X-Frame-Option
X-PHP-Backend
X-NewRelic-App-Data
X-ZONE
X-Hyper-Cache
Resin-Trace
X-DC
X-Backend-Instance
X-Cs
X-LiteSpeed-Cache-Control
X-Webstats-RespID
X-VC
X-Azure-Ref-OriginShield
X-DataCenter
X-Service
X-FTR-Expires
X-FTR-Cache-Status
X-FTR-Backend-Server
X-Country-Code-Real
X-FTR-Backend
X-FTR-Balancer
X-Github-Request-Id
Epwk-X-Cache
LB
X-Site-Version
GeoIP-Latitude
True-Client-Ip
X-SRV
X-Microcachable
X-Locale
X-NGINX-Cache
X-Nitro-Cache-From
Cache-Host
Uri
GeoIP-Country-Code
X-Nitro-Rev
WebServer
X-Origin-Expires
X-Info
XM
GeoIp-Country-Code
X-VCache
Cdn-Host
Cdn-Request-Time
XServer
PFcat
X-HN
WZWS-RAY
Cdn
X-Edge-Server
X-Pod-Name
X-Web-Node
Req-ID
X-NMSegId
X-Cache-Ttl
X-VarnishDD-TTL
X-CSRF-TOKEN
SID
NtCoent-Length
X-Ad-Load-Variation
M-TraceId
User-Agent
True-Client-IP
X-Pad
X-Ad-Defer-Variation
X-Datacenter
X-Geo
X-CS
X-Vercel-Cache
A
X-Request-URI
Edge-Copy-Time
X-Vercel-Id
X-M-Reqid
X-Request-Start
Pramga
X-Via-SSL
X-Scope-Id
Srvid
Locid
Cluster
X-Via-CDN
X-M-Log
X-Via-Edge
X-FL-QIT-DEBUG
X-FL-EDGE
Fastly-Drupal-Html
Content-Script-Type
X-Shield-Cache-Expires
Content-Style-Type
X-FPC
X-Qnm-Cache
HostName
X-MSEdge-Features
X-MSEdge-Flight
X-Varnish-Beresp-Status
X-HostName
Tcn
X-Cache-Date
Edge-Cache
Cache-Tv-Group
X-LiteSpeed-Tag
X-Contensis-Viewer-Groups
X-Cache-ASPX
X-Varnish-Authentication
X-FireWall-Port
X-Moov-Xdn-Version
X-Moov-T
X-ATG-Version
X-Cdn-Request-ID
CountryCode
Cf-Ipcountry
X-TRACE-ID
X-APP-VERSION
X-Api-Version
X-Esi
X-Amz-Meta-Opti
X-VCL-Version
X-WP-CF-Super-Cache-Cookies-Bypass
X-TH-Server
Cdncip
X-AK-Request-ID
X-NWS-UUID-VERIFY
Cdnsip
Cache-Key
Path
X-Via-Poph
X-Via-Popn
X-Via-Popv
X-V-Cache
X-Wa
X-Req
X-B3-Trace-ID
X-Aicache-OS
X-Acquia-Purge-Cdn-Unconfigured
Tube-Return
X-Cache-FS-Status
X-LB-ID
X-Servedbyhost
X-SB
X-Nc
Tube-Got-Results
Tube-Got-Eval
Click-Count-Error
Click-Count-Action-Start
X-Branch-Name
X-UA
Tube-Get-Contents
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-Vary
XkeyRZ
X-Men
X-Proxy-CacheRZ
Yak-Timeinfo
MIME-Version
On-Server
X-Air-Pt
V-Age
CDN
X-CACHE-KEY
X-Planisys-CDN-Rules
X-Platform-Server
X-Wp-Cf-Super-Cache-Cache-Control
X-Render-Time
X-Cdn-Forward
Srv
X-Wp-Cf-Super-Cache
Geoip-Latitude
X-Planisys-CDN-Cache
Wpo-Cache-Message
X-Planisys-CDN-TTL
Wpo-Cache-Status
Proxy-Connection
State
Ngx-Var-Key
X-Fastly-Backend-Reqs
X-HS-Content-Campaign-Id
X-Akamai-Pragma-Client-IP
X-Tim-N
X-Rebelmouse-Cache-Control
X-Lb-Cache
X-Rebelmouse-Surrogate-Control
X-User
X-Release
X-Dw-Trace-Id
My-App
X-Vgn-Hpd-Cached
Lb
Priority
CF-Cached-On
X-Upstream-Ct
X-Fastly-Cache
X-Vgn-Hpd-Ssi
X-Upstream-Ht
X-Ha-Backend
X-Generated-In
Server-Id
X-Vgn-Hpd-Variations-Key
X-TT-LOGID
X-Varnish-Director
Ohc-Cache-HIT
Ohc-File-Size
X-Fastly-Country-Code
PICS-Label
X-Acquia-Purge-Tags
X-Acquia-Site
X-Lb-Nocache
X-Acquia-Application-Trace
X-Via-Ucdn
X-Traceid
X-Cache-Remote
X-Sigma-Backend
X-Acquia-Application-UUID
X-CUA
X-EC-Lua
X-Sigma
X-HS-Status
X-Rocket-Build-Number
X-Iplb-Request-Id
X-Iplb-Instance
Yjs-Id
X-Snapshot-Date
X-CF-Cache-Header-Vary
Cache
CACHE-MISS-TO-ORIGIN
Inserted-Into-Cache-At
Vha6-Origin
Warning
X-Fastly-Cache-Hits
Ngx
Cneonction
X-RAMCache
X-Miniprofiler-Ids
X-Udemy-Cache-App-Namespace
Log-Origin
X-ElasticPress-Query
X-Litespeed-Cache-Control
X-CF-Cache-Header-Cache-Control
X-Cached-Since