Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-Cache-Status
Link
Accept-Ranges
CF-RAY
ETag
X-XSS-Protection
Expect-CT
Pragma
X-Powered-By
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
Alt-Svc
X-UA-Compatible
X-Served-By
X-Xss-Protection
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-DNS-Prefetch-Control
X-Drupal-Cache
X-Cache-Status
X-Check
X-Generator
X-Cacheable
Timing-Allow-Origin
X-Content-Security-Policy
X-Iinfo
Feature-Policy
Status
X-Envoy-Upstream-Service-Time
Content-Encoding
Access-Control-Expose-Headers
P3p
X-Drupal-Dynamic-Cache
X-AspNetMvc-Version
X-CDN
Upgrade
X-Via
CF-Ray
X-Ws-Request-Id
Access-Control-Max-Age
X-Request-ID
Server-Timing
EagleId
X-Cache-Group
Report-To
X-Turbo-Charged-By
Keep-Alive
X-UA-Device
Request-Context
X-Age
X-Backend
X-Server-Powered-By
X-Proxy-Cache
X-AH-Environment
X-Robots-Tag
X-Hacker
X-Server
X-Amz-Request-Id
Host-Header
X-Amz-Id-2
Grace
X-LiteSpeed-Cache
X-Rq
X-Swift-CacheTime
X-Swift-SaveTime
X-Nginx-Cache-Status
X-Varnish-Cache
Ali-Swift-Global-Savetime
X-WebKit-CSP
NEL
X-Page-Speed
X-Vhost
EagleEye-TraceId
X-Ua-Compatible
X-Amz-Version-Id
X-Pingback
X-OneAgent-JS-Injection
X-Dispatcher
X-Device
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Cache-Spec
X-Host
X-Server-Id
Accept-CH
X-Dns-Prefetch-Control
Cf-Railgun
X-Node
X-Backend-Server
X-Readtime
Surrogate-Control
X-Akam-SW-Version
Request-Id
X-Response-Time
X-HW
Xkey
X-Application-Context
Content-Location
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
Rating
Accept-Ch-Lifetime
X-Country
X-B3-TraceId
X-Cloud-Trace-Context
X-Ruxit-JS-Agent
X-Cache-Lookup
Accept-CH-Lifetime
X-Trace
X-Url
Allow
X-Content-Type
X-Ac
X-PC
X-Vname
X-TtlSet
X-Varnish-TTL
X-Aws-Lambda-Call-Status
X-Clacks-Overhead
Edge-Control
X-Server-Name
X-Mod-Pagespeed
Fastly-Restarts
Cache-Tag
X-ESI
Service-Worker-Allowed
X-FastCGI-Cache
X-Rack-Cache
X-VARITI-CCR
Verso
X-Element-Page-Cache
MS-Author-Via
X-Upstream
X-Vcap-Request-Id
X-MS-InvokeApp
X-Amz-Rid
X-GitHub-Request-Id
Public-Key-Pins
X-Dw-Request-Base-Id
X-Cached
X-Client-IP
X-Abt-Application-Version
X-Cache-TTL
X-D2id
X-Cnection
RTSS
X-Px
X-Exp-Id
X-Cdn-Fetch
X-Exp-Variant
X-Kinja-Build
X-Use-Magma
X-Kinja-Server
X-Kinja-Revision
X-GoogleNews-Bot
X-Kinja
X-Navigation-Version
Arr-Disable-Session-Affinity
X-Country-Code
Access-Control-Request-Method
X-Goog-Hash
X-Powered-By-Plesk
X-NF-Request-ID
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-Instrumentation
AR-PoweredBy
AR-Request-ID
AR-SID
AR-CACHE
X-TTL
AR-ATIME
X-Powered-CMS
X-Sol
Pagespeed
Display
X-Middleton-Display
X-Version
X-Origin-Cache
X-Middleton-Response
Response
X-MSEdge-Ref
X-LLID
X-Amz-Server-Side-Encryption
Nginx-Cache
TCN
X-Kinsta-Cache
X-Edge-Location-Klb
X-RateLimit-Remaining
X-Edge
MRF-Tech
Mrf-Cache-Status
X-B3-TraceId-Primal
X-Protected-By
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-CST
X-T
X-HP-Trace-Id
X-HP-Webp
X-Jurisdiction
X-Forwarded-For
X-Shield-Request-Id
X-Content-Security-Policy-Report-Only
X-Aspnetmvc-Version
X-Id
X-Mg-S
Accept-Ch
Edge-Cache-Tag
S
Content-MD5
X-Language
SPRequestDuration
SPIisLatency
X-Ruxit-Js-Agent
Fastcgi-Cache
Front-End-Https
X-Mid
Realpath
X-Request-Processing-Time
X-Request-Received
Server-Node
Filters
X-Recruiting
X-Frontend
X-Pinterest-Rid
Pinterest-Version
Pinterest-Generated-By
X-DynaTrace
X-Ua-Browser
X-Ab
X-Content
Server-Name
X-MCACHE
X-Ser
X-Correlation-Id
X-Cache-Key
X-NWS-LOG-UUID
X-HS-Cache-Config
X-HS-Hub-Id
X-HS-Content-Id
X-Yandex-Sdch-Disable
X-Template
X-HS-Combine-CSS
X-Ezoic-Cdn
X-ECACHE
X-SharePointHealthScore
SPRequestGuid
X-Hits
X-Parallel-Accel
X-Ttl
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
MicrosoftSharePointTeamServices
Cache-Tags
Cleartype
X-B3-Sampled
Charset
Host
Alternate-Protocol
X-Page-Id
X-Git-Hash
X-Www-Served-By
X-Geo-Country
X-Content-Options
Fusion-Deployment-Id
Fusion-Source
Fusion-Content-Source
Fusion-Content-Id
X-Debug-Info
Fusion-Template-Id
Fusion-Component-Id
X-Daa-Tunnel
X-DIS-Request-ID
X-Hostname
X-Amzn-Trace-Id
X-Content-Digest
X-Amz-Replication-Status
Cross-Origin-Opener-Policy
X-Varnish-Age
X-Ratelimit-Limit
Filterid
X-AppVersion
X-Activity-Id
X-Az
X-FB-Debug
X-Upgrade-Enabled
X-N
X-F-Cache
X-VCache
ServerID
X-Nginx-Upstream-Cache-Status
X-Grace
X-Accel-Expires
X-Origin-Server
X-Forwarded-Proto
X-Rid
X-WebKit-CSP-Report-Only
X-Mobile-URL
X-Fastly-Request-ID
Access-Control-Allow-Method
X-Is-Crawler
X-Providence-Cookie
X-Route-Name
X-Request-Guid
X-Aspnet-Duration-Ms
X-Flags
X-Server-ID
X-Type
X-DataDome
X-TT
X-App-Environment
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-Seen-By
Viewport
X-LB-Cache
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-Whom
X-Goog-Storage-Class
X-Goog-Metageneration
X-Tb
X-FW-Static
X-FW-Type
X-FW-Server
X-FW-Hash
Payment
X-FW-Serve
TP-Cache
TP-L2-Cache
X-Varnish-Grace
X-Distributor
X-FW-Dynamic
Paypal-Debug-Id
DC
Node
X-User-Agent
Accept-Charset
Country
X-App-Server
X-XRDS-LOCATION
X-Wix-Request-Id
X-Fastly-Request-Id
Fastcgi-Useragent
X-Ratelimit-Reset
X-Oneagent-Js-Injection
X-Litespeed-Cache
X-Cache-Rule
X-NGENIX-Cache
X-Cache-Control
X-Fastcgi-Cache
X-Webkit-Csp
X-Origin-Upstream-Status
X-Via-JSL
Version
X-Drupal-Cache-Tags
Referer-Policy
X-Microsite
X-Request-Handler-Origin-Region
X-Cluster-Name
X-Buckets
Amp-Access-Control-Allow-Source-Origin
X-Tec-Api-Root
X-Tec-Api-Origin
X-Cache-Age
X-Tec-Api-Version
X-B-Cache
X-Signature
X-Contextid
X-Logged-In
Cache-Status
X-Oracle-Dms-Ecid
Refresh
X-Oracle-Dms-Rid
X-Node-Name
X-Mobile
X-Browser-Type
X-Response-Served-From
VIX-Pulpo-Upstream-Status
X-Original-Request-Id
X-Erf-Bev-Bev
VIX-Pulpo-Node
SD-X-WS
X-Erf-Bev-Bev-Is-Generated
X-Real-IP
X-Is-Bot
X-Cache-Expired-At
X-Page-View
X-Rendered-As
X-Vgn-Hpd-Reason
X-Revision
X-Debug
X-Varnish-Backend
X-Cacheable-TTL
X-Jobs
NGB
X-B
Access-Control-Request-Headers
X-Load-Cache
X-Proxy-Cache-Status
X-Cache-Action
X-IPLB-Instance
X-UUID
X-ProcessESI
X-Proxy
X-Yottaa-Metrics
X-RemovedCookies
X-Instance
X-Yottaa-Optimizations
Akamai-GRN
X-Rule
X-Drupal-Cache-Contexts
X-Device-Type
Surrogate-Key
X-Debug-IsPreview
X-Debug-IsConnected
X-Cache-Time
X-FW-Version
X-G
X-Framework
CF-IPCountry
SID
X-Accel-Buffering
GEO-INFO
X-XRDS-Location
X-Air-Source
X-Air-Hostname
X-Air-Trace-Id
X-TEC-API-ROOT
X-TEC-API-VERSION
X-TEC-API-ORIGIN
DynaTrace
X-Cache-NGX
X-PressLabs-Stats
X-Nginx-Cache
Count-Hit
X-Azure-Ref
X-APP-VERSION
X-Cache-Operation
X-Presslabs-Stats
Uber-Trace-Id
X-Source
Liferay-Portal
X-Ms-Version
X-Ms-Request-Id
X-RateLimit-Limit
X-Zen-Fury
X-EdgeConnect-Cache-Status
Ms-Operation-Id
X-RTag
MS-CV
X-CDN-Forward
Protected
Frame-Options
Healthy
X-Cache-Hit
X-Mode
Cross-Origin-Window-Policy
X-IPS-LoggedIn
Ec-Rule-Version
X-L-Path
Xserver
X-Environment-Context
X-Tumblr-Pixel-1
X-Cache-TTL-Remaining
X-Hyper-Cache
X-Tumblr-Pixel
X-Varnish-Server
X-Tumblr-User
X-Tumblr-Pixel-0
X-Servername
WPO-Cache-Message
X-Backend-Name
X-Ratelimit-Remaining
WPO-Cache-Status
LB
Backend
Countrycode
X-Adobe-Content
X-Adobe-Loc
X-RN-RSRV
X-Detected-As
X-JoinUs
X-Tid
X-Content-Age
X-SaId
Content-Disposition
Meta-Geo
X-Region
X-UPSTREAM-Address
X-Rewrite-Enabled
X-Sql-Count
X-Sql-Duration-Ms
X-Format
X-Forwarded-Host
X-Sorting-Hat-PodId
X-ShopId
Decoy-Debug-TTL
Eomportal-Instance
Decoy-Debug-Status
Decoy-Debug-Key
Country-Code
Apigw-Requestid
X-ShardId
X-Shopify-Stage
X-Debug-Cache
X-Routing-Service
X-Alternate-Cache-Key
X-Cache-Grace
X-Extlb
X-Sorting-Hat-ShopId
X-Hosted-By
X-Proxied
X-Uri
X-Generation-Time
X-Zipkin-Id
X-Redis-Cache
X-PCL
X-Access
X-ApacheServer
Cache-Name
Url
Fastly-SSL
X-NCache
X-Via-Fastly
Mn-Server-Ip
X-PHP-Backend
X-Section
X-Cache-Server
X-PERF
X-Microcachable
CDN-EdgeStorageId
X-Site-Version
CDN-CachedAt
X-OCL
CDN-RequestCountryCode
CDN-PullZone
X-Status
CDN-RequestId
CDN-Cache
X-TIME
X-FB-TRIP-ID
X-Varnish-Beresp-Grace
CDN-Uid
X-Human
X-Origin-Hint
X-Generated-By
Property-Id
X-No-Session
X-Proxy-Build
X-Origin-Date
X-NYM-Debug-Backend
X-Cache-Type
X-Cache-Host
X-Say-Cacheable
X-Say-TTL
X-Timing-Wait
X-Web-Node
X-SayCDN-TTL
Webcakes-Region
Webcakes-App-Version
TWC-GeoIP-Country
TWC-Device-Class
TWC-Connection-Speed
TWC-GeoIP-LatLong
TWC-Locale-Group
X-Storage
Webcakes-App-Name
TWC-Privacy
X-Pubstack
Selected-Fe
X-Trace-Id
Cache-Tv-Group
Section-Io-Cache
X-Soup
X-R9-Blue-Green-Version
X-Content-Powered-By
X-Akamai-Edgescape
X-BYPASS-REASON
X-UA-Device-Type
X-Varnishpool
X-ProxyCache-Status
X-Cluster-Node
X-Server-W
X-ProxyCache-Key
X-Be
Azure-SiteName
Azure-RegionName
Azure-InstanceId
X-ServerID
Azure-SlotName
Azure-Version
Content-Secure-Policy
X-Ua
X-LSADC-Cache
Retry-After
X-Webkit-CSP
DB-Nickname
X-NewRelic-App-Data
X-Hl-Ver
X-Nginx-Cache-Key
OT-Force-Account-Verify
X-Azure-Ref-OriginShield
X-Cached-By
X-Unique-Id
X-Cache-Remote
X-TT-LOGID
X-Bc-Bl
Source
X-Akamai-Transformed
X-Platform-Server
X-Dc
Cache
X-Auto-Login
X-Xfnlog-Site
SRV
X-GEO
X-EC-Lua
X-LAGOON
X-Cdn
ServedBy
X-Origin-TTL
Upgrade-Insecure-Requests
Mime-Version
X-Cache-Tags
X-Origin-CC
X-Varnish-Cache-Hits
X-SRV
X-Varnish-Hits
Cache-Hits
From-Origin
X-Loop
X-TNCMS
X-Request-Time
X-HTML-Minification-Powered-By
HostName
X-S-Maxage
X-AOL-HN
Onion-Location
X-Varnish-Hostname
X-Request-Host
WP-Super-Cache
Xet-Cookie
X-NWS-UUID-VERIFY
X-CSRF-Token
X-ECache
X-Tumblr-Pixel-2
Web-Mar-Node
Webserver
X-Tumblr-Pixel-3
N-Cache
X-Cache-Enabled
X-App-Version
X-B3-SpanId
X-Endurance-Cache-Level
X-Handled-By
X-FireWall-Port
X-Time
X-Correlation-ID
X-Tenant
Nel
X-Proto
X-Origin-Response-Time
X-Amz-Meta-S3cmd-Attrs
Fastcgi-X-Cache-Version
X-PBS-Appsvrname
X-Slack-Backend
Expiry
X-PAYTM-SRV-ID
X-SRCache-Key
Meta-Geo-Continent
Pramga
Redirect-Candidate
X-Vdms-Version
Odigeo-Trace-Id
X-Vdms-Path
X-V-Cache
Mobile-Detection-Method
X-TIM-N
X-Shop-Environment
X-S
X-Rojux
Rendered-Blocks
X-RCS-CacheZone
X-Adobe-Source
X-S-Cookie
X-ScT
A
BehaviorPad-Version
X-Session-Fingerprint
X-Planisys-CDN-Rules
DCR-Decision-By
X-Planisys-CDN-TTL
X-Processor
X-SD-PageType
X-Planisys-CDN-Cache
X-ND-Cache
X-Gen-Mode
X-Ftr-Request-Id
X-Vtex-Processado-Em
X-Forwarded-Path
X-Vtex-Remote-Cache
X-GG-Cache-Date
X-Ig-Push-State
X-Cache-NE
X-Hnp-Log
X-CF-Lambda-Fn
X-External-Request-Id
X-Ckpd-Fst-Backend
X-Connection-Hash
X-Conf
X-CF-Lambda-Version
X-D
X-Epic-Correlation-Id
X-Developer
X-Destination
X-Block-Status
Xc-Version
X-Cluster
Vix-Hermes-Req-Id
X-A
X-NAPM-TraceId
X-Orig-Expires
X-VG-WebCache
Surrogated-Key
User-Cache-Control
V-Age
X-A-Ccd
X-A-Dam
X-ARC
X-B-Cookie
X-Backend-TTL
X-Application
X-Aed
X-A-Dcw
X-A-Dgt
X-A-Wwc
Sslversion
DCR-Processing-Time-Ms
X-Time-Microsecs
S-Rt
X-VWS-Id
X-Mg-Request-UUID
X-LJ-Flow-ID
X-Reqid
X-Edge-Location
X-AWS-Id
X-NodeID
X-Li-Fabric
X-Men
Host-ID
X-Cdn-Srv
X-LI-UUID
X-Li-Pop
X-Old-Content-Length
DSUID
Cmstype
Cmsid
X-VG-TLSProxy
X-Origin-Time
Origin
X-Origin
Fastcgi-Cache-TTL
X-Nyt-Route
X-Geo-Header
X-Date
X-Aicache-OS
X-Accel-Expires-Debug
X-Fastly-Cache
X-Webstats-RespID
X-Cache-Bucket
X-Cache-Info
X-Cache-Date
X-Viewer-Country
X-Forwarded-Site
Wxu-Next-Region
State
CDCHOST
X-GeoIP-Country-Code
Svr
True-Client-Country-4JS
Wxu-Next-Hostname
Wxu-Next-Commit
X-Gdpr
X-GeoIP-Region-Code
X-Location
X-Server-IP
Apple-News-Services-Handled
X-Origin-Expires
AKAMAI
X-SVT-ORM-VERSION
X-Proxy-Upstream
X-Scheme
X-SVT-ORM-RULES
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
X-Sucuri-Cache
X-Request-URI
Arc-Country
X-Rocket-Nginx-Serving-Static
X-Http-Reason
Apple-News-Services-Request-Url
X-Sucuri-ID
Environment
X-Magnolia-Registration
Server-Info
X-Cache-Var-Map
CloudFront-Viewer-Country
X-MP-GENERATED-AT
X-Akamai-Request-ID2
X-Labrador-Cache-Channel
X-Cache-Var
X-Via-NSCOPI
X-PHP-Host
X-Amzn-RequestId
X-Amz-Apigw-Id
Web-Mar-Region
X-Varnish-Beresp-Ttl
X-Cdn-Origin
X-Fastly-Backend
X-Gamma-Serve
Origin-EX
Origin-CC
X-Served-From
X-Cache-Debug
X-Generated-On
X-Storefront-Renderer-Rendered
Locid
X-Envoy-Decorator-Operation
X-Developers
X-Sn-Servicetimems
X-BBC-Edge-Cache-Status
X-Backend-State
X-Esi-Check
Ssr
X-TrackingId
Fastly-Drupal-Html
X-TH-Server
X-Skip-Cache
X-Core-Value
X-Varnish-Beresp-Status
Req-Svc-Chain
X-RateLimit-Limit-Second
X-Mvc-Supplant-Cachable
Magicmarker
X-RateLimit-Remaining-Second
X-Locale
X-VarnishDD-TTL
X-Region-Sid
Machine
L
X-GeoIP-City
X-Owner
Fastly-GeoIP-CountryCode
Gh-Request-Id
X-Fetched-On
X-Policy
X-VServer
X-Req
X-Hash
X-Device-Os
X-Gzip
X-Cache-Id
CacheControlHeader
Server-Host
X-HN
Traceparent
X-Level-Front-Cache
X-Core-Mission
X-UnsetCookies
PFcat
X-HS-Content-Campaign-Id
Release
X-Xrds-Location
X-CGP
X-Csrf-Jwt
X-Restarts
X-Datadog-Parent-Id
X-Rocket-Build-Number
X-Irp-Debug
X-Varnish-Remaining-TTL
X-Worker
X-Pod-Name
X-Platform
X-Varnish-CookieINHashed-On
X-Sigma
X-Eu-Site
X-Datadog-Trace-Id
X-Variation
X-Sigma-Backend
X-Varnish-CookieHashed-On
X-Datadog-Sampling-Priority
X-Qloud-Router
X-DPWN-IS-SECURE
NGX
L5d-Success-Class
HA-Ipaddr
X-ATG-Version
Thinkindot-Control
We-Hiring
TDXMobile
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
Ha-Gx-Prefs
X-GeoIP
Cf-Device-Type
Fastly-SIE
Fastly-SWR
Platform
Adler-Geo
X-Tx-Id
X-DefHash
X-Node-Id
X-DefElseHash
X-Thinkindot-L3
X-Has-Esi
Mail-Subject
X-JWT-State
X-NU-AKA-ACS-Version
X-Amzn-Remapped-Content-Length
X-Is-Gdpr
Is-Eu
X-Branch-Name
X-Loc
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-Ua-Device
X-VC-Cache
X-CS
X-Request-Start
AMP-Access-Control-Allow-Source-Origin
Memcached
X-Response-By
NM-Fastcgi-Cache
X-Trace-ID
X-FC-Vary-Parameters
X-Zone
X-DW
X-Bip
X-Qnm-Cache
X-M-Log
X-Thanos
X-Action
X-Esi
Edge-Cache
X-M-Reqid
X-Wix-Viewer-Type
X-RSL
X-Up
X-RPS
X-DB
X-DI
X-NC
X-API-Version
X-RPM
X-DSS
CDN
X-Cache-Backend
Kp-EeAlive
Accept-Language
X-TraceId
X-LB-NoCache
X-LB-ID
Pics-Label
Ms-Author-Via
X-Mvc-Supplant-OutputCached
X-Tb-Optimization-Total-Bytes-Saved
X-Generated-In
X-Optimistic-Header
Env
X-Cache-Config
X-Minions-Version
X-Srv
X-CacheTTL
X-Refresh
X-Varnish-Ttl
Memory
X-Via-Poph
X-Via-Popn
X-Via-Popv
X-DC
WebServer
Time
Locale
X-Urbn-Context-Path
Datacenter
X-Urbn-Site-Id
X-Tt-Logid
X-Edge-Pop
X-HA-Backend
NtCoent-Length
Candidate-Md5Url
GeoIp-Country-Code
X-CACHE-KEY
X-ZONE
X-Vc
X-Datadome
X-Ec-Fail
X-User
X-Ec-GeoHdr
X-Servedbyhost
X-TA-CDN-Provider
Server-ID
X-Parent-Response-Time
X-DynaTrace-JS-Agent
WWW-Authenticate
X-MSEdge-Features
X-MSEdge-Flight
On-Server
X-Cs
X-CLOUD-TRACE-CONTEXT
Esi-Enabled
X-TX-ID
X-VCL-Version
Cdnsip
Cdncip
X-AK-Request-ID
X-Unique-ID
X-Varnish-Beresp-TTL
X-App
X-Clara-WADP
X-WADP-Cache
My-App
C-Via
Cluster
X-Traceid
X-Fmm-Version
X-Service
X-Cache-Ttl
X-Cache-PHP
X-Fpc
X-LI-Proto
X-URL
X-Newrelic-Synthetics
X-Dynatrace
Geoip-Latitude
X-Webkit-Csp-Report-Only
X-CUA
X-Var-Ttl
Tracecode
X-Li-Proto
X-Pass-Why
Lfy
T-Server
X-B3-Spanid
X-FPC
X-From
Test
Proxy-Connection
Cf-Int-Pingora-Origin-Digest
X-NODE
X-Webkit-CSP-Report-Only
DataCenter
X-Fragments
X-Render-Time
Lang
X-Vcl-Version
X-Cache-Status-Check
Fastly-Drupal-HTML
X-LiteSpeed-Cache-Control
X-Mcache
Geo-Info
M-TraceId
Resin-Trace
X-CSRF-TOKEN
Target-Params
X-VC
X-WP-CF-Super-Cache-Cache-Control
Server-Id
X-WP-CF-Super-Cache
Hostname
X-Provided-By
X-ID
X-Ha-Backend
X-RAMCache
MIME-Version
Hit
X-Edge-POP
GeoIP-Country-Code
X-Httpd
X-Proxy-Cache-Info
Permissions-Policy
X-Clientip
X-ServedByHost
X-Geo
X-Dynatrace-Js-Agent
Producers
X-Cdn-Forward
X-Oss-Object-Type
X-Via-PopH
WZWS-RAY
X-Via-PopN
Cache-Host
UCS
X-Via-PopV
HIT
X-LiteSpeed-Tag
X-Oss-Hash-Crc64ecma
X-Oss-Server-Time
Servername
X-Pad
X-Oss-Request-Id
X-Oss-Storage-Class
X-Info
X-AIR-PT
X-SB
X-Edge-Cache
FSS-Cache
X-Fastly-Backend-Reqs
X-Check-Cacheable
Section-Io-Id
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
X-NGINX-Cache
S-Cnection
Section-Origin-Responded
ENV
X-Api-Version
X-Udemy-Cache-App-Namespace
X-Platform-Cluster
X-ElasticPress-Query
X-Ucs
X-Platform-Processor
X-Platform-Router
X-Pool
Ohc-File-Size
PICS-Label
Uri
X-Micro-Cache
X-Acquia-Application-UUID
Fastly-Backend-Name
X-UP
X-Acquia-Application-Trace
User-Agent
X-Acquia-Purge-Tags
X-Acquia-Site
ServerName
X-Ec-Custom-Error
X-Scale
X-GoCache-CacheStatus
X-BBC-Origin-Response-Status
URI
X-Lb-Nocache
X-HS-Status
X-Cache-CFC
X-Srcache-Store-Status
X-Srcache-Fetch-Status
X-Dispatcher-Number
X-SIPLIST1
X-Cache-Expires
MD5-Digest
X-ServerName
Tcn
Server-Ttl
Load-Balancing
IsBot
Server-Hostname
Server-Ext
Sever-Int
X-RateLimit-Reset
Cteonnt-Length
X-Release
X-Backend-Host
X-Fastly-Cache-Hits
X-Lb-Id
X-Cdn-Request-ID
X-Swift-Error
Cneonction
X-Nc
X-Dw-Trace-Id
X-Vcache
X-Newrelic-App-Data
X-Contensis-Viewer-Groups
X-Akamai-ERPolicy
X-Akamai-ERRuleID
Wpo-Cache-Message
X-Yottaa-OS
Cf-Ipcountry
Vha6-Origin
X-B3-ParentSpanId
Wpo-Cache-Status
CF-Cached-On
X-Via-Ucdn
X-Snapshot-Date
X-BCube-Filmed-By
Shield-Pop
X-Cache-ASPX
X-APP
EpKe-Alive
X-TRACE-ID
Sid
X-HostName
X-Cache-Ngx
X-Air-Pt
Cdn
X-Apw-Hits
X-B3-Parentspanid
X-CacheKey
X-Apw-Access-Token
X-Apw-Access-Object
X-Te-Duration-Ms
X-IN-APIGATEWAY
X-Litespeed-Cache-Control
GeoIP-Latitude
CountryCode
X-IN-APIGATEWAYSSL
X-Apw-Access-Action
X-Last-Modified
X-Shopify-Generated-Cart-Token
Path
Ohc-Cache-HIT
X-Te-Count
X-Http-Duration-Ms
Req-ID
X-Akamai-Pragma-Client-IP
X-Akamai-Request-ID
X-UA
X-Logging-Id
X-Varnish-Authentication
X-Sentry-ID
Ngx
X-Http-Count