Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
X-Powered-By
Pragma
CF-RAY
X-XSS-Protection
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
Alt-Svc
X-Xss-Protection
P3P
X-Cache-Hits
X-UA-Compatible
X-Served-By
CF-Ray
X-Download-Options
X-Timer
X-Request-Id
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
Access-Control-Allow-Credentials
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
X-Drupal-Cache
X-Cache-Status
X-Generator
X-Check
X-Cacheable
X-Envoy-Upstream-Service-Time
X-FRAME-OPTIONS
Timing-Allow-Origin
X-Iinfo
X-Dns-Prefetch-Control
X-DNS-Prefetch-Control
X-Request-ID
X-Drupal-Dynamic-Cache
Server-Timing
Feature-Policy
X-Content-Security-Policy
Access-Control-Expose-Headers
Content-Encoding
X-CDN
X-XSS-PROTECTION
Status
Upgrade
X-AspNetMvc-Version
Access-Control-Max-Age
X-Amz-Request-Id
X-Via
X-Amz-Id-2
Request-Context
X-Backend
X-Turbo-Charged-By
X-Cache-Group
X-AH-Environment
X-Robots-Tag
Cf-Edge-Cache
Keep-Alive
Host-Header
X-Hacker
X-UA-Device
X-Vhost
X-Proxy-Cache
X-Server
X-Rq
Allow
X-Server-Powered-By
X-Ws-Request-Id
X-Age
X-Dispatcher
EagleId
X-Varnish-Cache
X-Amz-Version-Id
P3p
X-LiteSpeed-Cache
Nel
Grace
X-Ua-Compatible
Cf-Apo-Via
Cf-Railgun
X-Page-Speed
X-OneAgent-JS-Injection
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
EagleEye-TraceId
X-Device
X-Swift-CacheTime
X-Swift-SaveTime
X-Aws-Lambda-Call-Status
Ali-Swift-Global-Savetime
X-Pingback
X-Host
X-Node
Accept-CH
X-WebKit-CSP
X-Cache-Lookup
X-CST
X-Backend-Server
Surrogate-Control
X-Server-Id
Permissions-Policy
X-Readtime
X-Nginx-Upstream-Cache-Status
X-Nginx-Cache-Status
X-Akam-SW-Version
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Application-Context
Request-Id
Accept-CH-Lifetime
X-Ruxit-JS-Agent
X-Content-Security-Policy-Report-Only
X-Cloud-Trace-Context
X-Response-Time
Xkey
X-HW
X-Trace
X-Edge
Content-Location
X-Clacks-Overhead
X-Mod-Pagespeed
X-Url
Rating
X-ESI
X-Midtier
X-Amz-Server-Side-Encryption
X-ECACHE
X-Mcache
Cache-Tag
X-Country
Accept-Ch-Lifetime
X-MS-InvokeApp
X-Rack-Cache
X-D2id
X-Powered-By-Plesk
X-Exp-Id
X-Cdn-Fetch
X-Exp-Variant
X-Kinja-Server
X-Use-Magma
X-GoogleNews-Bot
X-Kinja-Revision
X-Kinja
X-Kinja-Build
X-Upstream
Verso
X-Element-Page-Cache
X-Vcap-Request-Id
Accept-Ch
Edge-Control
Service-Worker-Allowed
X-Vname
X-TtlSet
X-PC
RTSS
X-Country-Code
X-Ac
Origin-Trial
X-Goog-Hash
X-VARITI-CCR
X-Navigation-Version
X-Abt-Application-Version
X-Cache-TTL
Fastly-Restarts
X-Browser-Type
X-Kinja-CCPA
X-Varnish-TTL
X-Amz-Rid
X-Oneagent-Js-Injection
X-GitHub-Request-Id
X-Cached
X-Litespeed-Cache
X-NWS-LOG-UUID
X-WebKit-CSP-Report-Only
X-Aspnetmvc-Version
Cross-Origin-Opener-Policy
X-Server-Name
X-Webkit-CSP
Pagespeed
X-Middleton-Display
Display
X-Sol
X-Dw-Request-Base-Id
X-Amzn-Trace-Id
X-SharePointHealthScore
SPRequestGuid
X-Times
X-Content-Type
SPIisLatency
SPRequestDuration
Pinterest-Version
Pinterest-Generated-By
X-Erf-Bev-Bev
X-Instrumentation
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Pinterest-Rid
X-Erf-Bev-Bev-Is-Generated
X-Cache-Key
X-Ruxit-Js-Agent
X-Server-ID
AR-Request-ID
AR-ATIME
AR-SID
AR-PoweredBy
X-Powered-CMS
X-Ttl
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
X-B3-Traceid
X-Mg-S
Arr-Disable-Session-Affinity
X-Middleton-Response
X-Client-IP
Response
X-Version
X-Cnection
X-Ser
X-HP-Trace-Id
X-HP-Webp
X-Jurisdiction
Nginx-Cache
X-FastCGI-Cache
AR-CACHE
X-Accel-Expires
X-T
Cache-Tags
X-Fastly-Request-ID
X-SRCache-Fetch-Status
X-SRCache-Store-Status
Cache-Status
Edge-Cache-Tag
X-B3-TraceId
Front-End-Https
X-MSEdge-Ref
X-Px
Public-Key-Pins
X-NF-Request-ID
X-Hits
X-Recruiting
S
Payment
X-Shield-Request-Id
X-RateLimit-Remaining
X-Frontend
X-Request-Received
X-LLID
X-Request-Processing-Time
Server-Node
X-Daa-Tunnel
X-Ua-Browser
X-B3-TraceId-Primal
Mrf-Cache-Status
MRF-Tech
Content-MD5
X-GUploader-UploadID
X-Goog-Metageneration
X-Webkit-CSP-Report-Only
X-TTL
X-DIS-Request-ID
Access-Control-Request-Method
MicrosoftSharePointTeamServices
X-RateLimit-Limit
X-Content-Digest
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Ratelimit-Remaining
TP-Cache
Realpath
X-Forwarded-For
X-Distributor
X-Microsite
X-Protected-By
X-Request-Handler-Origin-Region
X-HS-Content-Id
X-HS-Combine-CSS
X-PressLabs-Stats
X-HS-Hub-Id
X-HS-Cache-Config
X-Fastcgi-Cache
Access-Control-Allow-Method
X-FB-Debug
Fastcgi-Cache
X-Rid
X-Cluster-Name
X-LB-Cache
X-Page-Id
Accept-Charset
X-Hostname
X-Geo-Country
Count-Hit
X-B3-Sampled
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-Goog-Stored-Content-Length
X-Ratelimit-Limit
X-Goog-Storage-Class
X-Xrds-Location
TP-L2-Cache
X-Aspnet-Version
Cross-Origin-Resource-Policy
X-Ua-Device
X-Kinsta-Cache
X-Correlation-Id
X-Edge-Location-Klb
X-Seen-By
X-Id
X-Erf-Stays-Pdp-Viaduct-Migration-Web
TCN
X-Ezoic-Cdn
Cleartype
X-App-Server
X-Logged-In
Referer-Policy
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-TEC-API-ROOT
X-Varnish-Backend
X-Content-Options
X-Mobile
X-Hosted-By
X-Git-Hash
X-Origin-Cache
DC
X-Contextid
X-Is-Crawler
X-Fb-Rlafr
X-Flags
X-Aspnet-Duration-Ms
X-Providence-Cookie
X-Request-Guid
X-Route-Name
Retry-After
X-Debug-Info
X-Grace
X-Revision
Surrogate-Key
X-Amz-Replication-Status
X-TT
X-App-Environment
X-Newrelic-App-Data
X-Forwarded-Proto
X-F-Cache
X-Varnish-Grace
Frame-Options
X-Envoy-Decorator-Operation
X-Amz-Meta-S3cmd-Attrs
X-IPS-LoggedIn
X-Azure-Ref
X-Magnolia-Registration
MS-Author-Via
Section-Io-Cache
X-Wix-Request-Id
Healthy
X-Whom
X-Proxy-Cache-Info
Charset
X-App-Version
X-Www-Served-By
X-Akamai-Edgescape
Alternate-Protocol
X-RateLimit-Reset
X-Nf-Request-Id
Viewport
X-COUNTRY
X-AppVersion
X-Activity-Id
X-Language
X-Webkit-Csp
WPO-Cache-Status
X-Origin-Server
WPO-Cache-Message
X-Az
Filterid
X-Backend-Name
Amp-Access-Control-Allow-Source-Origin
X-Varnish-Server
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-B
Server-Name
SRV
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
X-DataDome
X-Datadog-Trace-Id
VIX-Pulpo-Node
Host
X-Trace-Id
SD-X-WS
X-Cache-Rule
VIX-Pulpo-Upstream-Status
X-Http-Reason
X-Original-Request-Id
X-EdgeConnect-Cache-Status
X-Response-Served-From
X-Rule
X-Time
Paypal-Debug-Id
X-Akamai-Request-ID2
X-Edge-Location
Front
X-UUID
X-Unique-Id
X-User-Agent
X-Cacheable-TTL
X-Cache-Grace
X-Tumblr-User
X-Tumblr-Pixel-1
X-N
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Rocket-Nginx-Serving-Static
X-Environment-Context
X-Jobs
Country
X-L-Path
From-Origin
X-Region
X-Page-View
X-Instance
X-Load-Cache
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Adobe-Content
X-Adobe-Loc
Akamai-GRN
Protected
X-Status
Fastly-SIE
X-ProcessESI
X-Varnish-Age
Fastly-SWR
X-Vcache
X-Framework
X-RemovedCookies
X-Client-Ip
Content-Disposition
X-G
X-Rendered-As
X-Is-Bot
X-ARC
X-Type
X-FW-Server
X-FW-Type
X-FW-Static
X-FW-Version
X-Mg-Request-UUID
X-Proxy
X-Datadog-Sampled
X-FW-Serve
X-FW-Hash
X-Cache-Time
X-FW-Dynamic
X-Signature
X-B-Cache
X-Debug-IsConnected
X-Debug-IsPreview
Access-Control-Request-Headers
ServerID
X-Amzn-Remapped-Content-Length
X-CDN-Forward
Backend
X-WP-CF-Super-Cache-Cache-Control
X-Cache-Control
X-WP-CF-Super-Cache
X-Cache-Age
X-ECache
X-Tec-Api-Origin
X-Tec-Api-Root
X-Tec-Api-Version
Countrycode
X-Nginx-Cache
X-Httpd
Xet-Cookie
X-DynaTrace
X-Servername
Url
X-Erf-Web-Scheduler
Refresh
Accept-Language
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Drupal-Cache-Tags
X-DynaTrace-JS-Agent
CF-IPCountry
X-Generated-By
X-Template
X-HTML-Minification-Powered-By
X-Device-Type
X-Mode
X-Content-Powered-By
X-NYM-Debug-Backend
Xserver
X-Source
X-Storage
Webserver
GEO-INFO
OT-Force-Account-Verify
X-Cache-Action
X-Rewrite-Enabled
Filters
X-ServerID
X-Rn-Rsrv
X-Say-Cacheable
X-Cache-Operation
Locale
Meta-Geo
Load-Balancing
Version
X-GeoCode
X-GeoCountry
X-SayCDN-TTL
X-UPSTREAM-Address
X-Urbn-Context-Path
X-Urbn-Site-Id
X-Say-TTL
S-Rt
X-Content-Age
X-Soup
X-Cluster-Node
Onion-Location
Cross-Origin-Window-Policy
X-Container-Uri
X-Tumblr-Pixel-2
X-Tumblr-Pixel-3
X-Tt-Logid
X-Varnish-Hostname
X-Forwarded-Host
X-Git-Commit
X-Cache-Hit
X-Director
X-Detected-As
X-Varnish-Cache-Hits
X-Hcs-Proxy-Type
X-Labrador-Cache-Channel
X-CCDN-Origin-Time
X-CCDN-CacheTTL
X-Lambda-Id
X-VCT
X-Tb
X-Adobe-Source
X-Cache-Server
X-Sql-Duration-Ms
X-Sql-Count
X-Loop
X-PHP-Host
X-Ms-Version
X-Ms-Request-Id
X-Tncms
X-Served-From
X-RM-Cache-TTL
Azure-Version
Azure-SlotName
DB-Nickname
Azure-SiteName
Azure-RegionName
Azure-InstanceId
X-RCS-CacheZone
X-Logging-Id
X-VC-Cache
X-LAGOON
X-JoinUs
X-FB-TRIP-ID
X-Extlb
X-Zipkin-Id
X-Proxied
X-SaId
Node
X-Routing-Service
X-Skip-Cache
X-R9-Blue-Green-Version
Mn-Server-Ip
Web-Mar-Node
X-XRDS-LOCATION
X-URL
X-Generation-Time
X-Fetched-On
X-Format
X-Oracle-Dms-Ecid
X-Uri
X-Timing-Wait
X-Proxy-Build
X-Proto
Selected-Fe
X-Oracle-Dms-Rid
X-Debug
X-MCACHE
Fastcgi-Useragent
TWC-Locale-Group
TWC-GeoIP-LatLong
TWC-Privacy
Webcakes-App-Name
Webcakes-Region
Webcakes-App-Version
TWC-GeoIP-Country
X-XRDS-Location
TWC-Device-Class
Property-Id
TWC-Connection-Speed
X-Origin-Hint
X-Endurance-Cache-Level
Uber-Trace-Id
X-NGENIX-Cache
X-Zen-Fury
X-Redis-Cache
Source
X-LSADC-Cache
CDN-RequestId
X-Ratelimit-Reset
X-FTR-Request-ID
X-B3-SpanId
X-Ua
X-Sucuri-ID
X-Sucuri-Cache
X-S
X-Srv
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
Section-Io-Origin-Status
X-Origin-CC
Section-Io-Id
X-Origin-TTL
X-Origin-Date
X-Pass-Why
X-Drupal-Cache-Contexts
X-TimeS
X-MP-GENERATED-AT
Upgrade-Insecure-Requests
X-Real-IP
X-Varnish-Hits
Fastly-Drupal-HTML
X-Akamai-Transformed
NGB
X-Cache-Expired-At
X-Upgrade-Enabled
X-Handled-By
Liferay-Portal
X-Newrelic-Synthetics
X-Xfnlog-Site
X-Cms-Context
X-GEO
X-Reqid
X-Optimistic-Header
Apigw-Requestid
X-CACHE-AGE
X-Restarts
ServedBy
Ms-Operation-Id
X-Hl-Ver
X-RTag
MS-CV
X-No-Session
X-UA-Device-Type
X-BYPASS-REASON
X-ProxyCache-Status
X-Cache-TTL-Remaining
X-Tx-Id
X-ProxyCache-Key
CDN-CachedAt
CDN-RequestCountryCode
CDN-EdgeStorageId
CDN-RequestPullCode
CDN-PullZone
CDN-Uid
CDN-RequestPullSuccess
CDN-Cache
X-Node-Name
WP-Super-Cache
X-CSRF-Token
X-Cache-Type
X-Parent-Response-Time
X-Cache-Host
X-Via-JSL
X-VWS-Id
X-LJ-Flow-ID
X-IPLB-Request-ID
X-Varnish-Ttl
X-Pubstack
X-AB
X-AWS-Id
X-Cluster
X-IPLB-Instance
X-Fastly-Request-Id
MD5-Digest
X-Proxy-Cache-Status
Lang
Magicmarker
Meta-Geo-Continent
Gannett-Cam-Experience-Id
Fastly-SSL
Ha-Gx-Prefs
HA-Ipaddr
L
DCR-Processing-Time-Ms
DCR-Decision-By
BehaviorPad-Version
Host-ID
Canary
Candidate-Md5Url
L5d-Success-Class
Cache-Provider
X-A-Dgt
X-Epic-Correlation-Id
X-Ec-GeoHdr
X-Eu-Site
X-External-Request-Id
X-FC-Vary-Parameters
X-Fastly-Backend
X-Ec-Fail
X-Ec-Custom-Error
X-D
X-Csrf-Jwt
X-Destination
X-Developer
X-Dispatcher-Number
X-Request-Host
X-Rojux
X-Viewer-Country
X-Vdms-Version
X-Vtex-Remote-Cache
X-Worker
Xc-Version
X-Vdms-Path
X-SRCache-Key
X-ScT
X-S-Cookie
X-SD-PageType
X-Slack-Backend
X-Slack-Shared-Secret-Outcome
X-Conf
X-CGP
T-Server
Surrogated-Key
True-Client-Country-4JS
Vix-Hermes-Req-Id
X-A
W
Sslversion
Server-Host
Odigeo-Trace-Id
Ngx.Var.Host
Origin-Agent-Cluster
Redirect-Candidate
Rendered-Blocks
X-A-Ccd
X-A-Dam
X-Cache-NE
X-Bl-Debug
X-CacheTTL
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-BCube-Filmed-By
X-Bc-Bl
X-A-Wwc
X-A-Dcw
X-App
X-Application
X-B-Cookie
N-Cache
X-Aed
X-Server-W
X-Geo-Region
X-TraceId
X-Cache-Status-Check
X-DefElseHash
X-DefHash
X-DPWN-IS-SECURE
X-Debug-Cache-Store
X-Core-Value
X-B3-Spanid
X-Core-Mission
X-Forwarded-Path
X-Debug-Cache-Fetch
X-Gdpr
X-Human
X-Irp-Debug
X-Loc
X-Mid
X-Hash
X-GeoIP-Region-Code
X-CMSURLCustom
X-Generated-On
X-GeoIP-Country-Code
X-Mly-Id
X-Cdn-Origin
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
Thinkindot-Control
Web-Mar-Region
TDXMobile
Req-Svc-Chain
Platform
Producers
Release
X-Accel-Buffering
X-Alternate-Cache-Key
X-Cache-Info
X-Cdn-Diag
X-Mvc-Supplant-Cachable
X-Cache-Debug
X-Cache-Bucket
X-App-Name
X-BBC-Edge-Cache-Status
X-Bip
X-Clientip
X-Node-Id
X-Thanos
X-Thinkindot-L3
X-Up
X-Variation
X-Tenant
X-SVT-ORM-VERSION
X-Sorting-Hat-ShopId
X-Storefront-Renderer-Rendered
X-SVT-ORM-RULES
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-VServer
X-We-Are-Hiring
X-Wix-Viewer-Type
X-PAYTM-SRV-ID
X-Vmg-Version
X-VG-WebCache
X-Varnish-Remaining-TTL
X-Varnishpool
X-VG-TLSProxy
X-Sorting-Hat-PodId
X-Sn-Servicetimems
X-Orig-Expires
X-Origin-Time
X-Owner
X-Platform
X-Org
X-Old-Content-Length
Origin
X-NodeID
X-Nyt-Route
X-Policy
X-Pool
X-ShardId
X-Shop-Environment
X-ShopId
X-Shopify-Stage
X-Server-IP
X-S-Maxage
X-Qloud-Router
X-Refresh
X-Request-Time
X-Nitro-Cache
X-Level-Front-Cache
Cmstype
Cmsid
Fastly-GeoIP-CountryCode
Expect-Staple
Environment
X-Micro-Cache
Is-Eu
Adler-Geo
Cache-Name
User-Cache-Control
X-TIME
Esi-Enabled
AKAMAI
X-Device-Os
X-Var-Ttl
X-Fmm-Version
X-Test
X-Esi-Check
Fastly-Backend-Name
X-Correlation-ID
X-Date
X-WA-Info
X-WADP-Cache
X-Cache-Id
Apple-News-Services-Request-Url
X-Forwarded-Site
X-Wikidot-Static-Cache
X-Block-Status
Gh-Request-Id
X-Wikidot-Backend
X-GeoIP
X-Nginx-Cache-Key
X-Nananana
X-Mvc-Supplant-OutputCached
X-RateLimit-Limit-Second
CDCHOST
Apple-News-Services-Handled
X-Origin-Response-Time
X-Origin
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
X-RateLimit-Remaining-Second
Cf-Device-Type
Datacenter
X-Akamai-Device-Characteristics
X-Gen-Mode
DSUID
X-Gzip
CPC-Cache
Country-Code
X-Instance-Name
CPC-Age
X-Hnp-Log
X-From
X-Clara-WADP
X-Geo-Header
Server-Hostname
Machine
CloudFront-Viewer-Country
Server-Ext
X-AIR-PT
We-Hiring
VNS-Cache
VNS-Age
X-Dispatcher-Server
X-Accel-Expires-Debug
NM-Fastcgi-Cache
Mail-Subject
Sever-Int
Content-Secure-Policy
X-INCAP-ABP
X-Section
Wxu-Next-Commit
Wxu-Next-Hostname
Ssr
Pics-Label
X-PERF
Server-Info
Wxu-Next-Region
X-NCache
X-Op-Id-All
X-LB-NoCache
X-Via-Fastly
NGX
C-Via
X-Cache-Enabled
X-Auto-Login
X-Access
X-ApacheServer
X-ID
X-Datadome
X-Cdn-Srv
X-Accel-Version
X-Tcp-Rtt
Server-ID
X-Is-Supported-Browser
X-Is-Tablet
X-Amz-Meta-Cb-Modifiedtime
X-Is-Mobile
X-Vgn-Hpd-Reason
X-Browser-Name
X-Is-Desktop
X-Varnish-Beresp-Ttl
X-Buckets
X-API-Version
X-Varnish-Beresp-Grace
AMP-Access-Control-Allow-Source-Origin
X-CACHE-GROUP
X-Vcl-Version
X-SIPLIST1
IsBot
X-Presslabs-Stats
X-HA-Backend
X-Dc
X-Has-Esi
Memcached
X-Is-Gdpr
X-JWT-State
X-Zone
Memory
Hostname
X-Platform-Cluster
X-B3-Parentspanid
X-Platform-Router
Time
X-Platform-Processor
YJS-ID
Sid
Origin-CC
CF-Ctrl
X-Wp-Cf-Super-Cache-Active
X-Cached-By
X-Origin-Cache-Key
Origin-EX
Location
X-Tb-Optimization-Total-Bytes-Saved
X-TA-CDN-Provider
Cache-Hits
X-Scale
Cdn-Requestid
X-Air-Hostname
X-Air-Trace-Id
X-Air-Source
X-WP-CF-Super-Cache-Active
X-Internal-Host
X-TIM-N
X-Fpc
X-NewRelic-App-Data
X-ZONE
X-PHP-Backend
X-Backend-Instance
X-Frame-Option
X-Hyper-Cache
Resin-Trace
X-DC
X-LiteSpeed-Cache-Control
X-Cs
X-Azure-Ref-OriginShield
X-VC
X-Service
X-Webstats-RespID
X-FTR-Balancer
X-FTR-Backend
X-FTR-Backend-Server
X-Country-Code-Real
X-FTR-Expires
X-FTR-Cache-Status
LB
X-Site-Version
True-Client-Ip
Epwk-X-Cache
X-DataCenter
GeoIP-Latitude
X-Microcachable
X-NGINX-Cache
X-Nitro-Rev
X-Nitro-Cache-From
Uri
Cache-Host
GeoIP-Country-Code
X-Origin-Expires
XM
X-Info
X-Locale
GeoIp-Country-Code
X-VCache
Cdn-Request-Time
WZWS-RAY
Cdn-Host
X-HN
X-VarnishDD-TTL
Cdn
X-SRV
X-Edge-Server
WebServer
X-Cache-Ttl
X-Web-Node
PFcat
XServer
X-Pod-Name
X-NMSegId
Req-ID
X-CSRF-TOKEN
True-Client-IP
X-Ad-Load-Variation
X-Ad-Defer-Variation
X-Vercel-Cache
X-Vercel-Id
X-Pad
M-TraceId
User-Agent
NtCoent-Length
X-Datacenter
X-Geo
X-CS
X-Scope-Id
X-Via-SSL
X-Via-Edge
X-Request-Start
Pramga
Locid
X-Github-Request-Id
A
X-FL-QIT-DEBUG
X-Via-CDN
Edge-Copy-Time
X-Request-URI
SID
X-M-Log
X-M-Reqid
X-FL-EDGE
Srvid
X-Varnish-Beresp-Status
HostName
Cluster
Fastly-Drupal-Html
X-Shield-Cache-Expires
Content-Style-Type
X-MSEdge-Features
Content-Script-Type
X-Qnm-Cache
X-FPC
X-MSEdge-Flight
X-HostName
Tcn
X-Cache-ASPX
X-Moov-T
Cache-Tv-Group
X-FireWall-Port
X-Varnish-Authentication
X-Contensis-Viewer-Groups
X-ATG-Version
X-LiteSpeed-Tag
X-Moov-Xdn-Version
Edge-Cache
X-Cache-Date
X-Cdn-Request-ID
Cf-Ipcountry
X-APP-VERSION
X-Api-Version
X-TRACE-ID
CountryCode
Cache-Key
X-Esi
X-TH-Server
Cdncip
X-AK-Request-ID
X-Amz-Meta-Opti
X-WP-CF-Super-Cache-Cookies-Bypass
X-NWS-UUID-VERIFY
Cdnsip
X-VCL-Version
Path
X-V-Cache
Click-Count-Action-Start
Click-Count-Error
X-Branch-Name
X-Via-Poph
X-Servedbyhost
X-Wa
X-Via-Popv
X-Via-Popn
Tube-Got-Eval
Tube-Get-Contents
X-Nc
X-Req
X-SB
X-LB-ID
X-Cache-FS-Status
Tube-Got-Results
Tube-Return
X-Acquia-Purge-Cdn-Unconfigured
X-Aicache-OS
X-Wp-Cf-Super-Cache-Cookies-Bypass
Yak-Timeinfo
X-Proxy-CacheRZ
XkeyRZ
X-B3-Trace-ID
MIME-Version
X-Air-Pt
X-Vary
X-Men
CDN
X-UA
X-CACHE-KEY
X-HS-Content-Campaign-Id
X-Wp-Cf-Super-Cache
On-Server
Geoip-Latitude
Ngx-Var-Key
Proxy-Connection
X-Tim-N
X-Planisys-CDN-Rules
X-Render-Time
X-Planisys-CDN-Cache
X-Platform-Server
X-Cdn-Forward
X-Planisys-CDN-TTL
Wpo-Cache-Status
V-Age
X-Fastly-Backend-Reqs
X-Akamai-Pragma-Client-IP
X-Wp-Cf-Super-Cache-Cache-Control
Srv
Wpo-Cache-Message
State
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-Lb-Cache
Lb
X-Ha-Backend
X-Vgn-Hpd-Variations-Key
X-HITS
X-Upstream-Ht
X-Dw-Trace-Id
X-Vgn-Hpd-Ssi
X-Acquia-Application-Trace
My-App
X-Vgn-Hpd-Cached
X-Acquia-Application-UUID
X-Fastly-Cache
Priority
Server-Id
X-User
X-Generated-In
CF-Cached-On
X-Acquia-Site
X-Upstream-Ct
X-Release
X-Acquia-Purge-Tags
X-TT-LOGID
X-Traceid
X-Fastly-Country-Code
X-Rocket-Build-Number
PICS-Label
X-Varnish-Director
Ohc-Cache-HIT
X-Via-Ucdn
Ohc-File-Size
X-CUA
X-Lb-Nocache
X-Sigma-Backend
X-EC-Lua
X-HS-Status
X-Cache-Remote
X-Sigma
X-Iplb-Instance
X-Iplb-Request-Id
Yjs-Id
Warning
X-Fastly-Cache-Hits
Vha6-Origin
X-Cached-Since
X-ElasticPress-Query
Cache
X-Snapshot-Date
CACHE-MISS-TO-ORIGIN
Inserted-Into-Cache-At
X-Litespeed-Cache-Control
Ngx
X-CF-Cache-Header-Cache-Control
X-CF-Cache-Header-Vary
Cneonction
X-Miniprofiler-Ids
Log-Origin
X-RAMCache
X-Udemy-Cache-App-Namespace