Threat Level: green Handler on Duty: Guy Bruneau

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
X-XSS-Protection
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Accept-Ranges
Expect-CT
CF-RAY
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
X-Served-By
P3P
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
X-Xss-Protection
X-FRAME-OPTIONS
Access-Control-Allow-Credentials
P3p
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
X-DNS-Prefetch-Control
Accept-CH
X-Cache-Status
X-Drupal-Cache
Accept-CH-Lifetime
X-Check
X-Generator
CF-Ray
X-Ua-Compatible
X-Cacheable
Server-Timing
X-Envoy-Upstream-Service-Time
Timing-Allow-Origin
X-Iinfo
X-Request-ID
X-Drupal-Dynamic-Cache
Access-Control-Expose-Headers
Feature-Policy
X-Content-Security-Policy
Content-Encoding
X-CDN
Status
Upgrade
X-AspNetMvc-Version
Access-Control-Max-Age
X-Via
X-Amz-Request-Id
X-Amz-Id-2
Host-Header
X-Backend
Allow
Cf-Edge-Cache
X-Cache-Group
Request-Context
X-Robots-Tag
X-Server
Keep-Alive
X-Hacker
X-UA-Device
X-AH-Environment
X-Turbo-Charged-By
X-Ws-Request-Id
X-Vhost
X-Proxy-Cache
X-Rq
X-Age
Xkey
EagleId
X-Dispatcher
X-Server-Powered-By
X-Amz-Version-Id
X-Varnish-Cache
Grace
Cf-Apo-Via
X-LiteSpeed-Cache
X-Page-Speed
Cf-Railgun
X-Pingback
EagleEye-TraceId
X-Device
X-Swift-CacheTime
X-Swift-SaveTime
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Aws-Lambda-Call-Status
Ali-Swift-Global-Savetime
X-Dns-Prefetch-Control
X-WebKit-CSP
X-CST
X-OneAgent-JS-Injection
X-Backend-Server
Permissions-Policy
X-Server-Id
X-Readtime
X-Host
X-Response-Time
X-Akam-SW-Version
Surrogate-Control
Request-Id
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Nginx-Upstream-Cache-Status
X-HW
X-Cloud-Trace-Context
X-Node
X-Nginx-Cache-Status
Accept-Ch-Lifetime
X-Application-Context
X-Country-Code
X-Trace
X-Oneagent-Js-Injection
X-Ruxit-JS-Agent
Content-Location
X-Cache-Lookup
Service-Worker-Allowed
X-Url
X-Country
X-Content-Type
X-Clacks-Overhead
X-ECACHE
X-Edge
X-Litespeed-Cache
X-Mod-Pagespeed
X-Amz-Server-Side-Encryption
X-Rack-Cache
X-Origin-Cache-Key
X-Midtier
Cache-Tag
X-FTR-Request-ID
Cross-Origin-Opener-Policy
Accept-Ch
X-MS-InvokeApp
X-Mcache
X-Powered-By-Plesk
X-Upstream
X-PC
Nginx-Cache
X-Vname
X-TtlSet
Rating
X-ESI
Edge-Control
X-D2id
X-Kinja-Build
X-Cdn-Fetch
X-Exp-Id
X-Exp-Variant
X-GoogleNews-Bot
X-Element-Page-Cache
X-Kinja
X-Kinja-Server
X-Browser-Type
X-Kinja-Revision
Verso
X-Times
X-Ruxit-Js-Agent
X-Ac
X-Server-Name
X-Cnection
SPIisLatency
SPRequestDuration
X-Vcap-Request-Id
AR-Request-ID
AR-PoweredBy
AR-SID
AR-ATIME
X-Navigation-Version
X-Abt-Application-Version
X-Dw-Request-Base-Id
SPRequestGuid
X-SharePointHealthScore
X-RateLimit-Remaining
X-B3-TraceId
X-Ser
X-VARITI-CCR
Pinterest-Version
Pinterest-Generated-By
X-Pinterest-Rid
Origin-Trial
X-GitHub-Request-Id
AR-CACHE
RTSS
X-NF-Request-ID
S
X-Cache-Key
X-Cache-TTL
X-Mg-S
X-Server-ID
X-Content-Security-Policy-Report-Only
Edge-Cache-Tag
X-Goog-Hash
X-Amz-Rid
Display
Pagespeed
X-Middleton-Display
X-Sol
Fastly-Restarts
X-Amzn-Trace-Id
X-Powered-CMS
X-NWS-LOG-UUID
X-Client-IP
X-Ttl
X-ARC
X-Server-Lifecycle-Phase
X-Version
X-Kraken-Loop-Name
X-Instrumentation
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Kinsta-Cache
X-Edge-Location-Klb
X-Varnish-TTL
Access-Control-Request-Method
X-Recruiting
Cache-Status
X-SRCache-Store-Status
X-SRCache-Fetch-Status
Arr-Disable-Session-Affinity
X-Content-Digest
X-T
X-MSEdge-Ref
Content-MD5
X-Middleton-Response
X-Forwarded-For
Response
X-Accel-Expires
MicrosoftSharePointTeamServices
X-Ua-Device
X-TraceId
X-Hits
TP-Cache
X-Shield-Request-Id
X-Cached
Public-Key-Pins
X-WebKit-CSP-Report-Only
X-Erf-Stays-Pdp-Viaduct-Migration-Web-V2
X-RateLimit-Limit
X-Id
X-Request-Received
X-Request-Processing-Time
X-FTR-Backend
X-Frontend
X-Country-Code-Real
X-FTR-Cache-Status
X-FTR-Balancer
X-FTR-Backend-Server
X-Ua-Browser
X-FTR-Expires
Server-Node
X-HS-Combine-CSS
X-HS-Cache-Config
X-HS-Hub-Id
X-Kinja-CCPA
X-HS-Content-Id
Payment
MS-Author-Via
X-Fastcgi-Cache
X-DIS-Request-ID
X-Webkit-Csp
Front-End-Https
Cross-Origin-Resource-Policy
X-LLID
X-Jurisdiction
X-Forwarded-Proto
X-HP-Webp
X-HP-Trace-Id
X-GUploader-UploadID
Cache-Tags
X-FastCGI-Cache
TP-L2-Cache
X-LB-Cache
X-TTL
X-Amzn-RequestId
X-Amz-Apigw-Id
Realpath
X-Protected-By
X-Origin-Server
X-PressLabs-Stats
Count-Hit
X-Distributor
X-Daa-Tunnel
X-ORACLE-DMS-RID
X-Request-Handler-Origin-Region
X-Microsite
X-F-Cache
MRF-Tech
X-Page-Id
X-B3-TraceId-Primal
X-Cluster-Name
Mrf-Cache-Status
Accept-Charset
X-Activity-Id
X-Varnish-Backend
X-Az
X-Correlation-Id
X-AppVersion
X-Www-Served-By
X-NGENIX-Cache
X-Geo-Country
X-App-Server
X-Rid
X-FB-Debug
X-Hostname
Referer-Policy
X-Debug-Info
X-Varnish-Server
X-Goog-Metageneration
Host
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
Fastcgi-Cache
X-Envoy-Decorator-Operation
X-Git-Hash
Access-Control-Allow-Method
X-ORACLE-DMS-ECID
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
Retry-After
X-Px
Server-Name
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-RateLimit-Reset
DC
X-Oracle-Dms-Ecid
X-B3-Sampled
X-Content-Options
X-Fastly-Request-ID
X-Ratelimit-Limit
X-Load-Cache
X-Aspnet-Duration-Ms
X-Request-Guid
X-Route-Name
X-Providence-Cookie
X-Is-Crawler
X-Flags
X-Contextid
X-Origin-Cache
X-Revision
X-B-Cache
X-Signature
X-App-Environment
Cleartype
X-Mobile
X-Type
TCN
X-Trace-Id
X-Webkit-CSP
X-TT
Paypal-Debug-Id
X-Grace
X-Language
X-Fb-Rlafr
Charset
X-B
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
X-Datadog-Trace-Id
X-Logged-In
X-Amz-Meta-S3cmd-Attrs
X-Newrelic-App-Data
Frame-Options
Section-Io-Cache
X-Goog-Generation
X-Oracle-Dms-Rid
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Cache-Control
X-Amz-Replication-Status
X-Goog-Stored-Content-Length
Filterid
X-ASPNET-VERSION
X-Seen-By
X-CSRF-Token
X-XRDS-LOCATION
X-EdgeConnect-Cache-Status
X-Whom
X-Wix-Request-Id
X-Magnolia-Registration
X-Ezoic-Cdn
X-Upgrade-Enabled
Healthy
X-Azure-Ref
X-App-Version
Content-Disposition
X-Varnish-Ttl
X-Node-Name
X-B3-Traceid
Backend
X-Ratelimit-Remaining
X-N
X-Proxy
Akamai-GRN
Upgrade-Insecure-Requests
X-Template
X-Use-Magma
X-Proxy-Cache-Info
X-Fastly-Request-Id
NGB
Refresh
X-Air-Pt
X-Response-Served-From
X-Original-Request-Id
X-Is-Bot
X-Rendered-As
X-Servername
X-RTag
X-Unique-Id
X-Tumblr-Pixel
X-RemovedCookies
VIX-Pulpo-Upstream-Status
Ms-Operation-Id
MS-CV
Liferay-Portal
SD-X-WS
X-Tumblr-User
VIX-Pulpo-Node
Url
X-Page-View
X-ProcessESI
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-Instance
X-Debug-IsConnected
X-Cacheable-TTL
X-Debug-IsPreview
X-UUID
X-Environment-Context
X-Cache-Grace
X-L-Path
X-Adobe-Content
X-Adobe-Loc
X-Datadog-Sampled
X-Jobs
Viewport
X-Yottaa-Metrics
X-Varnish-Grace
X-Amzn-Remapped-Content-Length
X-FW-Dynamic
X-FW-Hash
X-FW-Static
X-Yottaa-Optimizations
X-FW-Version
X-G
X-Region
X-FW-Type
X-FW-Serve
X-FW-Server
X-IPS-LoggedIn
X-B3-SpanId
From-Origin
X-Hosted-By
X-Cache-Hit
X-NYM-Debug-Backend
X-User-Agent
X-Debug
Country
X-Status
Fastly-SIE
Fastly-SWR
Amp-Access-Control-Allow-Source-Origin
X-Device-Type
X-Rule
Surrogate-Key
X-XRDS-Location
X-Air-Trace-Id
X-Air-Source
X-Air-Hostname
X-Hl-Ver
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
ServerID
Protected
X-Content-Powered-By
X-Http-Reason
X-Backend-Name
X-Akamai-Request-ID2
X-Origin-TTL
X-Origin-CC
Version
X-Cache-Age
Alternate-Protocol
X-VC-Cache
X-Time
X-Cache-Status-Check
X-NODE
X-Hcs-Proxy-Type
X-CCDN-Origin-Time
X-CCDN-CacheTTL
X-Akamai-Edgescape
WPO-Cache-Message
WPO-Cache-Status
X-CDN-Forward
Countrycode
X-Rocket-Nginx-Serving-Static
X-Framework
X-Nginx-Cache
X-Tec-Api-Origin
CF-IPCountry
X-INCAP-ABP
X-Tec-Api-Root
X-Edge-Location
Front
X-HTML-Minification-Powered-By
X-Tec-Api-Version
X-Cache-Rule
Access-Control-Request-Headers
SRV
X-Source
CDN-RequestId
GEO-INFO
X-Storage
X-Httpd
X-Endurance-Cache-Level
X-Via-JSL
X-Mode
X-Accel-Version
X-WP-CF-Super-Cache-Active
Accept-Language
X-Rewrite-Enabled
X-Cache-Operation
Filters
X-Rn-Rsrv
X-UPSTREAM-Address
X-Upstream-Ht
X-Upstream-Ct
X-Xfnlog-Site
Meta-Geo
X-Soup
Xet-Cookie
X-Vcache
X-JoinUs
X-Tumblr-Pixel-3
X-Tumblr-Pixel-2
X-SaId
OT-Force-Account-Verify
X-Loop
X-Lambda-Id
X-Director
Webserver
X-Real-IP
X-Detected-As
X-Varnish-Age
X-Tncms
X-Cache-Debug
X-Cache-Time
X-Say-Cacheable
X-Say-TTL
X-Skip-Cache
X-Sql-Count
X-Use-Mantle
Apigw-Requestid
Xserver
X-Redis-Cache
X-Sql-Duration-Ms
X-Served-From
X-SayCDN-TTL
X-Varnish-Cache-Hits
X-Adobe-Source
X-Cms-Context
Azure-Version
TWC-GeoIP-Country
TWC-Device-Class
X-GeoCode
X-GeoCountry
TWC-Locale-Group
DB-Nickname
TWC-GeoIP-LatLong
X-Format
TWC-Connection-Speed
X-Cache-Host
Webcakes-App-Version
Webcakes-App-Name
Azure-SiteName
Webcakes-Region
Property-Id
Azure-SlotName
Azure-InstanceId
Web-Mar-Node
Azure-RegionName
X-Origin-Hint
X-ProxyCache-Key
X-ProxyCache-Status
TWC-Privacy
X-BYPASS-REASON
X-PHP-Host
X-Handled-By
X-Uri
X-Varnish-Beresp-Grace
X-Restarts
ServedBy
X-Labrador-Cache-Channel
X-Logging-Id
X-VC
X-Browser-Name
Selected-Fe
X-AB
X-Proxy-Build
X-Timing-Wait
X-Worker
X-Server-W
X-S
X-Zipkin-Id
X-No-Session
X-Tcp-Rtt
X-Geo-Region
X-Generation-Time
X-Forwarded-Host
X-Origin
X-Git-Commit
X-Is-Supported-Browser
X-Is-Desktop
X-Extlb
X-Proxied
X-Vercel-Cache
X-Container-Uri
X-Is-Tablet
X-Tb
X-RCS-CacheZone
X-Routing-Service
X-Vercel-Id
X-Is-Mobile
Mn-Server-Ip
X-AWS-Id
X-Cache-Server
X-VCT
X-ServerID
X-Frame-Option
X-RM-Cache-TTL
Cache-Tv-Group
X-DynaTrace
X-Provided-By
X-LJ-Flow-ID
X-IPLB-Request-ID
X-IPLB-Instance
X-VWS-Id
X-Fetched-On
X-Cluster
Node
X-COUNTRY
X-Reqid
X-R9-Blue-Green-Version
Priority
X-FB-TRIP-ID
X-Ms-Request-Id
Section-Io-Id
X-Ms-Version
Content-Secure-Policy
X-Locale
X-Site-Version
X-Platform-Cluster
Fastcgi-Useragent
X-Platform-Router
X-Platform-Processor
Onion-Location
X-MP-GENERATED-AT
Source
AMP-Access-Control-Allow-Source-Origin
X-Drupal-Cache-Tags
S-Rt
X-Drupal-Cache-Contexts
WZWS-RAY
WP-Super-Cache
X-Ua
X-Urbn-Context-Path
X-Webstats-RespID
X-Content-Age
Locale
X-Urbn-Site-Id
X-Vcl-Version
X-Web-Node
CDN-RequestPullSuccess
CDN-EdgeStorageId
CDN-Cache
X-Storefront-Renderer-Rendered
X-Shopify-Stage
CDN-CachedAt
CDN-PullZone
CDN-Uid
CDN-RequestPullCode
X-Alternate-Cache-Key
CDN-RequestCountryCode
X-Generated-By
X-SRV
Cross-Origin-Embedder-Policy
X-Origin-Date
X-Cache-Action
X-Xrds-Location
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-ShardId
X-ShopId
X-Varnish-Beresp-Ttl
X-Pass-Why
X-Cluster-Node
X-Cdn-Origin
X-Sucuri-Cache
X-Mg-Request-UUID
X-Proxy-Cache-Status
X-Sucuri-ID
X-Buckets
Sid
X-DataDome
Fastly-Drupal-HTML
Cross-Origin-Window-Policy
X-Cache-Expired-At
X-Newrelic-Synthetics
X-Request-URI
X-Thinkindot-L3
X-GEO
X-CMSURLCustom
Cache
X-Scope-Id
X-Shield-Cache-Expires
Thinkindot-Control
TDXMobile
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
X-TT-LOGID
X-LSADC-Cache
X-Tt-Logid
X-Vtex-Remote-Cache
Cross-Origin-Embedder-Policy-Report-Only
X-Vdms-Path
X-Vdms-Version
X-Viewer-Country
X-Men
X-A-Ccd
X-A-Dam
Gannett-Cam-Experience-Id
X-A
V-Age
X-A-Dcw
X-A-Dgt
X-B-Cookie
X-Application
X-Aed
X-A-Wwc
Type
T-Server
Lang
Ngx.Var.Host
Ngx-Var-Key
Meta-Geo-Continent
MD5-Digest
Origin
Origin-Agent-Cluster
Surrogated-Key
Sslversion
Rendered-Blocks
Redirect-Candidate
X-Bc-Bl
Environment
X-External-Request-Id
X-PAYTM-SRV-ID
X-Epic-Correlation-Id
Candidate-Md5Url
DCR-Decision-By
X-Rojux
X-S-Cookie
X-TIM-N
X-SRCache-Key
X-ScT
X-Scheme
X-Ec-GeoHdr
X-Ec-Fail
X-Cache-Bucket
X-Bl-Debug
X-BCube-Filmed-By
DCR-Processing-Time-Ms
X-Cache-NE
X-Conf
X-Ec-Custom-Error
X-Developer
X-Destination
X-D
X-Up
CDCHOST
X-DC
HostName
X-Aspnetmvc-Version
X-Service
X-Cache-Info
X-B3-Trace-ID
X-Aicache-OS
X-BBC-Edge-Cache-Status
X-Core-Value
X-Fastly-Backend
X-Fastly-Cache
X-VCache
X-Dispatcher-Server
X-Acquia-Purge-Cdn-Unconfigured
X-Debug-Cache-Fetch
X-Core-Mission
X-Correlation-ID
Magicmarker
Pramga
L
Host-ID
Fastly-GeoIP-CountryCode
Fastly-SSL
Req-Svc-Chain
Server-Ext
Vix-Hermes-Req-Id
X-Gdpr
Ssr
Sever-Int
Server-Host
Server-Hostname
X-Access
X-GeoIP-Country-Code
X-Sigma-Backend
X-SVT-ORM-RULES
X-Sigma
X-Section
X-SB
X-SD-PageType
X-SVT-ORM-VERSION
X-V-Cache
X-VServer
X-We-Are-Hiring
X-VG-WebCache
X-VG-TLSProxy
X-Varnish-Director
X-Varnish-Hostname
X-Rocket-Build-Number
X-Request-Time
X-Level-Front-Cache
X-Loc
X-Instance-Name
X-Human
Country-Code
X-GeoIP-Region-Code
X-Mly-Id
X-Nyt-Route
X-Proxied-Request
X-Req
X-Pool
X-Origin-Time
X-Op-Id-All
X-Generated-On
X-Debug-Cache-Store
Apple-News-Services-Host
Apple-News-Services-Request-Url
Apple-News-Services-Handled
Apple-News-Services-Parsed-Url
Edge-Copy-Time
X-Parent-Response-Time
X-TimeS
X-Optimistic-Header
X-Datadome
X-Via-CDN
X-Via-SSL
User-Cache-Control
X-Via-Edge
X-Fmm-Version
X-From
X-Esi-Check
X-DPWN-IS-SECURE
Wxu-Next-Commit
X-Geo-Header
X-Gzip
X-HA-Backend
Click-Count-Error
X-GeoIP-City
Wxu-Next-Hostname
X-Gen-Mode
Adler-Geo
X-Block-Status
X-Clientip
X-Cache-TTL-Remaining
X-Cache-Id
X-Auto-Login
X-Hnp-Log
X-Cache-Date
X-Device-Os
X-Ad-Load-Variation
X-ApacheServer
Wxu-Next-Region
X-Nginx-Cache-Key
X-WA-Info
X-Zen-Fury
LB
X-Via-Popv
X-Via-Poph
X-Via-Popn
Release
X-Bip
X-Varnish-Beresp-Status
X-Server-IP
X-Thanos
X-Pubstack
X-Hash
X-Platform
X-UA-Device-Type
X-TH-Server
X-Org
X-Origin-Response-Time
X-Old-Content-Length
Web-Mar-Region
X-Micro-Cache
X-NCache
X-PERF
X-RateLimit-Limit-Second
X-Slack-Shared-Secret-Outcome
X-Sn-Servicetimems
X-Slack-Backend
X-Request-Host
X-RateLimit-Remaining-Second
X-HS-Content-Campaign-Id
X-GoCache-CacheStatus
Tube-Return
On-Server
X-Nf-Request-Id
Machine
True-Client-Country-4JS
Is-Eu
Click-Count-Action-Start
Tube-Got-Eval
Tube-Get-Contents
Tube-Got-Results
Producers
Platform
C-Via
Proxy-Firewall
Cache-Provider
DSUID
X-WP-CF-Super-Cache-Cookies-Bypass
N-Cache
X-Request-Start
X-FC-Vary-Parameters
X-Node-Id
X-Var-Ttl
X-Owner
X-Forwarded-Site
X-Edge-Server
Req-ID
Atl-Traceid
Gh-Request-Id
Esi-Enabled
Canary
X-Wikidot-Static-Cache
Mail-Subject
NM-Fastcgi-Cache
We-Hiring
Uber-Trace-Id
X-CacheTTL
X-Wikidot-Backend
Expect-Staple
IsBot
X-Policy
X-Date
Cdn-Host
X-NMSegId
X-Mvc-Supplant-OutputCached
Cf-Device-Type
Cdn-Request-Time
X-Mvc-Supplant-Cachable
X-SIPLIST1
Pics-Label
X-Irp-Debug
X-TA-CDN-Provider
X-Accel-Expires-Debug
X-CF-Lambda-Version
X-CF-Lambda-Fn
X-Varnishpool
X-Cdn-Srv
X-GeoIP
X-App-Name
AKAMAI
X-Client-Ip
X-Test
W
X-Forwarded-Path
X-Amz-Meta-Cb-Modifiedtime
X-Shop-Environment
X-Qloud-Router
X-Tenant
X-Cache-Type
X-Orig-Expires
Xc-Version
X-Ratelimit-Reset
X-Proto
NGX
X-ZONE
Fastly-Backend-Name
Datacenter
X-Tx-Id
X-LB-NoCache
X-Csrf-Jwt
X-Ah-Environment
X-Eu-Site
L5d-Success-Class
X-CGP
X-Gamma-Serve
HA-Ipaddr
Cluster
Ha-Gx-Prefs
SID
Expiry
X-Connection-Hash
X-Varnish-Authentication
X-Cache-Aspx
X-Contensis-Viewer-Groups
X-Moov-Xdn-Version
Cmsid
X-LAGOON
X-Moov-T
Cmstype
X-Branch-Name
A
Server-ID
Content-Script-Type
Content-Style-Type
Cdn
X-Dc
X-Refresh
Cache-Key
Locid
X-Varnish-Hits
CPC-Age
CPC-Cache
X-Servedbyhost
X-Wa
X-Vmg-Version
X-LB-ID
X-Nc
X-URL
RNT-Machine
RNT-Time
X-NGINX-Cache
X-Api-Version
Cdnsip
X-Fpc
X-AK-Request-ID
Yak-Timeinfo
Cdncip
X-ND-Cache
X-Cdn-Diag
X-Region-Sid
X-VHOST
X-TIME
X-DynaTrace-JS-Agent
X-MCACHE
X-HN
PFcat
X-Amz-Storage-Class
X-VarnishDD-TTL
X-Tb-Optimization-Total-Bytes-Saved
NtCoent-Length
RATING
Cdn-Requestid
X-Srv
X-CDN-Cache-Status
X-Nananana
GeoIp-Country-Code
CloudFront-Viewer-Country
X-Backend-Instance
X-CACHE-AGE
X-Akamai-Transformed
CacheControlHeader
XM
X-Variation
X-Azure-Ref-OriginShield
X-Via-Fastly
Resin-Trace
X-B3-Parentspanid
X-Hit
X-CSRF-TOKEN
X-Origin-Expires
Uri
X-API-Version
X-Cache-Backend
X-TX-ID
X-Zone
User-Agent
X-LiteSpeed-Tag
MIME-Version
VNS-Age
VNS-Cache
X-Fastly-Country-Code
Cache-Name
X-Vc
X-Proxy-CacheRZ
XkeyRZ
X-LiteSpeed-Cache-Control
X-Datacenter
True-Client-Ip
X-Amz-Meta-Opti
Cross-Origin-Opener-Policy-Report-Only
X-Lagoon
X-Info
Tcn
Hostname
Lb
X-Dynatrace-Js-Agent
X-B3-Spanid
X-Dispatcher-Number
X-DataCenter
X-HostName
DataCenter
GeoIP-Latitude
X-NewRelic-App-Data
X-Cached-By
X-Geo
True-Client-IP
X-Esi
X-AIR-PT
X-UA
Mime-Version
X-Traceid
X-Location
X-Ig-Origin-Region
Cache-Hits
Fusion-Content-Id
Fusion-Component-Id
Fusion-Content-Source
X-Mid
Fusion-Source
X-NWS-UUID-VERIFY
Fusion-Template-Id
Fusion-Deployment-Id
BehaviorPad-Version
Cf-Ipcountry
X-Presslabs-Stats
Powered-By
Fastly-Drupal-Html
X-Cdn-Forward
X-Webkit-Csp-Report-Only
Origin-CC
X-IAuth-Set-Uid
Origin-EX
X-CUA
X-Cloudmap
X-Jungle-Id
Srv
X-User
X-Segment-20210421
GeoIP-Country-Code
CountryCode
X-Varnish-Beresp-TTL
X-ECache
X-CS
X-Dispatch
X-Cdn-Cache-Status
Debug
Server-Info
Ohc-File-Size
Location
X-Cache-Enabled
X-Cs
X-Oracle-DMS-ECID
X-Internal-Host
CF-Ctrl
X-Wp-Cf-Super-Cache-Cache-Control
My-App
X-FPC
X-Wp-Cf-Super-Cache
X-Render-Time
Cl-Cache
Wpo-Cache-Message
CDN
Ohc-Cache-HIT
Wpo-Cache-Status
X-NC
Section-Origin-Responded
Section-Io-Origin-Time-Seconds
X-WA
X-VTEX-Cache-Time
X-Fastly-Backend-Reqs
X-App
X-VTEX-Cache-Server
X-ServedByHost
X-Lb-Id
Server-Id
X-VCL-Version
X-Litespeed-Tag
X-Nitro-Cache
X-Snapshot-Date
X-Powered-By-VTEX-Cache
X-Wormhole-Sdk
YJS-ID
Section-Io-Origin-Status
Load-Balancing
X-Cache-FS-Status
Edge-Cache
X-Lb-Nocache
X-Auth-Group-Type
X-Akamai-Pragma-Client-IP
X-MSEdge-Flight
X-MSEdge-Features
X-Litespeed-Cache-Control
X-ID
Ms-Author-Via
X-Cdn-Request-ID
Xkey-La3
X-Nitro-Rev
X-Nitro-Cache-From
Xkeylog
X-Proxy-Cache-La3
CF-Cached-On
X-MiniProfiler-Ids
X-Dw-Trace-Id
X-RID
X-DefHash
X-Serial
X-APP-VERSION
X-DefElseHash
Time
X-Varnish-CookieHashed-On
FSS-Cache
X-IN-APIGATEWAYSSL
X-IN-APIGATEWAY
OriginIP
Memory
X-Acquia-Application-Trace
X-Acquia-Application-UUID
X-FL-QIT-DEBUG
Memcached
X-FL-EDGE
X-Th-Server
X-Ig-Push-State
X-Varnish-Remaining-TTL
Ngx
X-NodeID
X-Check-Cacheable
X-Acquia-Purge-Tags
X-Acquia-Site
X-Varnish-CookieINHashed-On
Srvid
X-Shardid
X-Sorting-Hat-Shopid
X-Cache-Version
X-Sorting-Hat-Podid
X-Shopid
X-Http-Count
X-Te-Count
X-Pad
X-Http-Duration-Ms
X-Ha-Backend
X-Te-Duration-Ms
X-Vary
X-Lsadc-Cache
Inserted-Into-Cache-At
X-Fastly-Cache-Hits
X-Sucuri-Id
Akamai-Cache-Status
Geoip-Latitude
Yjs-Id
X-Via-PopV
Sm-Log-Id
X-Web-Server
X-Udemy-Cache-App-Namespace
X-RequestId
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-Service-Response-Time
X-Via-PopH
X-Via-PopN
X-Mg-Cache