Threat Level: green Handler on Duty: Jan Kopriva

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Link
Cf-Request-Id
CF-Cache-Status
Accept-Ranges
CF-RAY
ETag
X-XSS-Protection
Expect-CT
Pragma
X-Powered-By
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-UA-Compatible
X-Cache-Hits
Alt-Svc
P3P
X-Served-By
X-Xss-Protection
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Request-Id
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Cache-Status
X-Generator
X-Cacheable
Timing-Allow-Origin
P3p
X-Content-Security-Policy
X-Iinfo
X-Request-ID
Status
Feature-Policy
X-Envoy-Upstream-Service-Time
Content-Encoding
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
X-CDN
X-AspNetMvc-Version
Upgrade
X-Via
CF-Ray
X-Ws-Request-Id
Access-Control-Max-Age
Server-Timing
EagleId
Keep-Alive
X-Cache-Group
X-Turbo-Charged-By
Request-Context
X-Age
X-Server-Powered-By
X-Proxy-Cache
X-AH-Environment
X-UA-Device
X-Backend
X-Hacker
X-Robots-Tag
Report-To
X-Amz-Request-Id
Host-Header
X-Server
X-Dns-Prefetch-Control
X-LiteSpeed-Cache
X-Amz-Id-2
Grace
X-Rq
X-Nginx-Cache-Status
X-Varnish-Cache
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-WebKit-CSP
X-Page-Speed
X-Vhost
EagleEye-TraceId
X-Amz-Version-Id
X-OneAgent-JS-Injection
X-Pingback
X-Device
X-Dispatcher
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Cache-Spec
NEL
X-Server-Id
X-Host
X-Backend-Server
Cf-Railgun
X-Node
X-Readtime
Accept-CH
X-Akam-SW-Version
Surrogate-Control
Request-Id
X-Response-Time
X-HW
Xkey
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Accept-Ch-Lifetime
X-Application-Context
Content-Location
Rating
X-Ruxit-JS-Agent
X-Ua-Compatible
X-Country
X-B3-TraceId
X-Language
X-Cache-Lookup
X-Cloud-Trace-Context
X-Ac
X-Url
X-Content-Type
X-Trace
X-Template
Allow
X-Vname
X-TtlSet
X-PC
Accept-CH-Lifetime
X-Varnish-TTL
X-Mod-Pagespeed
X-Clacks-Overhead
Edge-Control
Cache-Tag
X-ESI
Fastly-Restarts
X-FastCGI-Cache
X-Server-Name
X-Rack-Cache
Service-Worker-Allowed
X-VARITI-CCR
X-Element-Page-Cache
Verso
X-MS-InvokeApp
X-Buckets
X-GitHub-Request-Id
X-Upstream
Accept-Ch
X-Amz-Rid
MS-Author-Via
X-Vcap-Request-Id
Public-Key-Pins
X-Dw-Request-Base-Id
X-Cached
X-Client-IP
X-D2id
X-Abt-Application-Version
X-Origin-Cache
Arr-Disable-Session-Affinity
X-Px
X-Cnection
X-Goog-Hash
X-Powered-By-Plesk
X-Country-Code
X-Aws-Lambda-Call-Status
Access-Control-Request-Method
X-Navigation-Version
X-NF-Request-ID
X-Cache-TTL
X-Instrumentation
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
RTSS
X-Version
X-Powered-CMS
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-Amz-Server-Side-Encryption
X-Sol
Display
X-Middleton-Display
Pagespeed
X-Kinja-Revision
X-Use-Magma
X-Kinja-Server
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Kinja-Build
X-Kinja
X-Exp-Id
X-Exp-Variant
X-Cdn-Fetch
X-GoogleNews-Bot
Response
X-Middleton-Response
X-MSEdge-Ref
X-LLID
X-Edge-Location-Klb
X-Kinsta-Cache
X-Edge
AR-PoweredBy
AR-CACHE
AR-Request-ID
AR-SID
AR-ATIME
X-RateLimit-Remaining
Nginx-Cache
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
X-Shield-Request-Id
X-Jurisdiction
S
X-HP-Webp
X-HP-Trace-Id
X-Protected-By
X-T
X-TTL
Content-MD5
X-Forwarded-For
TCN
X-Content-Security-Policy-Report-Only
X-Aspnetmvc-Version
X-Mg-S
X-Id
X-CST
Realpath
X-Mid
Fastcgi-Cache
X-MCACHE
Edge-Cache-Tag
SPIisLatency
SPRequestDuration
Front-End-Https
X-Recruiting
X-Parallel-Accel
X-Ttl
X-Request-Received
X-Request-Processing-Time
Filters
Pinterest-Version
Server-Node
Fusion-Deployment-Id
Fusion-Component-Id
Fusion-Content-Id
Fusion-Template-Id
Fusion-Source
X-Pinterest-Rid
Fusion-Content-Source
Pinterest-Generated-By
X-Ua-Browser
X-Ab
X-Content
X-Ruxit-Js-Agent
SPRequestGuid
X-DynaTrace
X-SharePointHealthScore
X-Correlation-Id
Server-Name
X-Ezoic-Cdn
X-ECACHE
X-NWS-LOG-UUID
Alternate-Protocol
X-Frontend
X-HS-Content-Id
X-HS-Hub-Id
X-HS-Combine-CSS
X-HS-Cache-Config
X-Cache-Key
X-Hits
X-Yandex-Sdch-Disable
X-Accel-Expires
X-Content-Options
MicrosoftSharePointTeamServices
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Page-Id
Cache-Tags
Host
X-Git-Hash
X-Ser
Charset
Cleartype
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Www-Served-By
X-B3-Sampled
X-Content-Digest
X-Amz-Replication-Status
Filterid
X-Daa-Tunnel
TP-L2-Cache
X-Geo-Country
TP-Cache
X-Forwarded-Proto
X-Amzn-Trace-Id
X-VCache
X-Varnish-Age
X-DIS-Request-ID
X-Hostname
X-Az
X-Activity-Id
X-AppVersion
X-Fastly-Request-Id
X-Debug-Info
X-Rid
X-N
X-Upgrade-Enabled
X-Origin-Server
Access-Control-Allow-Method
X-Grace
X-FB-Debug
X-LB-Cache
X-Nginx-Upstream-Cache-Status
X-XRDS-LOCATION
X-Origin-Upstream-Status
ServerID
X-Mobile-URL
X-Microsite
X-Request-Handler-Origin-Region
X-Providence-Cookie
X-Aspnet-Duration-Ms
Cross-Origin-Opener-Policy
X-Route-Name
X-Request-Guid
X-Flags
X-Is-Crawler
X-F-Cache
X-Whom
X-Server-ID
X-NGENIX-Cache
X-TT
X-GUploader-UploadID
X-Goog-Generation
X-Goog-Metageneration
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Varnish-Grace
X-App-Server
X-Tb
X-App-Environment
Viewport
X-FW-Type
X-FW-Static
X-Distributor
X-WebKit-CSP-Report-Only
X-FW-Serve
Payment
X-FW-Dynamic
X-FW-Server
X-FW-Hash
Node
DC
Paypal-Debug-Id
X-Oneagent-Js-Injection
X-Cache-Control
X-Seen-By
X-Type
Fastcgi-Useragent
X-Logged-In
X-User-Agent
X-Litespeed-Cache
Accept-Charset
X-Fastcgi-Cache
X-PressLabs-Stats
Country
X-Cache-Age
X-Fastly-Request-ID
X-Webkit-CSP
X-Cache-Rule
X-Wix-Request-Id
X-Varnish-Backend
Version
X-Oracle-Dms-Ecid
X-DataDome
X-Oracle-Dms-Rid
X-Node-Name
X-Erf-Bev-Bev
X-Browser-Type
X-Erf-Bev-Bev-Is-Generated
X-Load-Cache
Amp-Access-Control-Allow-Source-Origin
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Ratelimit-Limit
X-Cache-Action
Refresh
Referer-Policy
X-Drupal-Cache-Tags
X-Via-JSL
X-IPLB-Instance
Access-Control-Request-Headers
X-Response-Served-From
X-Original-Request-Id
Cache-Status
SD-X-WS
X-Real-IP
X-Page-View
X-Rendered-As
X-Is-Bot
X-Proxy-Cache-Status
X-Vgn-Hpd-Reason
X-Jobs
X-Cacheable-TTL
X-Debug
X-RemovedCookies
VIX-Pulpo-Node
X-B
VIX-Pulpo-Upstream-Status
X-Cluster-Name
X-Signature
X-UUID
X-Revision
X-Mobile
NGB
X-ProcessESI
X-Cache-Expired-At
X-B-Cache
X-Contextid
X-Device-Type
X-Rule
X-Proxy
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-G
X-Framework
X-Drupal-Cache-Contexts
DynaTrace
Akamai-GRN
Surrogate-Key
X-Instance
X-Cache-Time
X-Debug-IsPreview
X-Debug-IsConnected
Liferay-Portal
CF-IPCountry
X-FW-Version
X-Air-Source
X-Air-Hostname
X-Air-Trace-Id
SID
Healthy
X-Azure-Ref
X-Tec-Api-Origin
X-Tec-Api-Version
X-Source
X-Tec-Api-Root
X-Ms-Version
X-Ms-Request-Id
Frame-Options
X-CDN-Forward
X-Nginx-Cache
Ms-Operation-Id
MS-CV
X-RTag
X-Cache-Hit
Count-Hit
Countrycode
X-Tumblr-User
X-Tumblr-Pixel
X-L-Path
X-XRDS-Location
X-Tumblr-Pixel-0
X-Environment-Context
X-Tumblr-Pixel-1
X-Cache-Operation
X-Varnish-Server
X-RateLimit-Limit
Xserver
GEO-INFO
Uber-Trace-Id
Section-Io-Cache
X-Region
X-Servername
X-APP-VERSION
X-Accel-Buffering
X-EdgeConnect-Cache-Status
X-Forwarded-Host
X-Content-Powered-By
X-Backend-Name
X-Mode
X-IPS-LoggedIn
Cross-Origin-Window-Policy
X-Zen-Fury
Ec-Rule-Version
Backend
X-RN-RSRV
X-Detected-As
X-UPSTREAM-Address
X-JoinUs
X-SaId
Meta-Geo
X-Debug-Cache
X-Varnish-Beresp-Grace
X-Redis-Cache
X-Cache-Grace
X-Cache-Server
Country-Code
X-Alternate-Cache-Key
X-Cache-Type
X-Adobe-Content
X-Sql-Duration-Ms
X-Generation-Time
X-Uri
X-Tid
X-Sorting-Hat-PodId
X-Adobe-Loc
X-Sorting-Hat-ShopId
X-ShopId
X-ShardId
X-Hosted-By
X-Human
Eomportal-Instance
X-Sql-Count
X-Shopify-Stage
X-Cache-NGX
X-ServerID
X-UA-Device-Type
X-PHP-Backend
Url
X-Origin-Date
Mn-Server-Ip
X-BYPASS-REASON
X-No-Session
X-Microcachable
X-NCache
Decoy-Debug-TTL
Decoy-Debug-Status
Apigw-Requestid
X-ProxyCache-Key
Cache-Name
Cache-Tv-Group
Decoy-Debug-Key
DB-Nickname
X-ProxyCache-Status
X-Cache-TTL-Remaining
X-Status
X-FB-TRIP-ID
X-Via-Fastly
X-Site-Version
Property-Id
X-Cache-Host
Protected
Selected-Fe
TWC-Connection-Speed
X-Format
X-Origin-Hint
Fastly-SSL
X-Ratelimit-Reset
X-PCL
X-Proxy-Build
X-Web-Node
TWC-GeoIP-Country
X-Rewrite-Enabled
TWC-Device-Class
X-SayCDN-TTL
Webcakes-App-Version
X-OCL
X-Akamai-Edgescape
X-Timing-Wait
X-Storage
X-Say-TTL
Webcakes-Region
TWC-Locale-Group
TWC-GeoIP-LatLong
TWC-Privacy
X-Say-Cacheable
Webcakes-App-Name
X-Varnishpool
Azure-Version
Azure-SiteName
X-ApacheServer
X-Access
OT-Force-Account-Verify
X-NYM-Debug-Backend
X-Hl-Ver
Azure-SlotName
X-R9-Blue-Green-Version
X-Extlb
X-Server-W
X-Soup
X-Proxied
X-Zipkin-Id
Azure-RegionName
X-Section
X-Pubstack
X-PERF
X-Routing-Service
Azure-InstanceId
X-LSADC-Cache
Content-Secure-Policy
X-Azure-Ref-OriginShield
X-Be
X-Cluster-Node
Source
X-Content-Age
X-Webkit-Csp
X-App-Version
X-Presslabs-Stats
X-Time
SRV
CDN-CachedAt
CDN-PullZone
CDN-EdgeStorageId
CDN-Cache
CDN-Uid
CDN-RequestCountryCode
CDN-RequestId
X-Cached-By
X-Ua
Content-Disposition
X-HTML-Minification-Powered-By
X-TT-LOGID
Cache
X-Generated-By
X-Hyper-Cache
X-SRV
X-Cache-Var
X-Cache-Var-Map
X-LAGOON
X-NewRelic-App-Data
X-Amz-Meta-S3cmd-Attrs
X-Unique-Id
X-Bc-Bl
X-Varnish-Hostname
X-TNCMS
X-Varnish-Hits
X-Loop
X-Nginx-Cache-Key
X-Dc
X-Auto-Login
Onion-Location
X-S-Maxage
X-Origin-CC
X-Origin-TTL
LB
Webserver
Retry-After
Cache-Hits
X-GEO
X-Tumblr-Pixel-3
X-Tumblr-Pixel-2
Web-Mar-Node
Xet-Cookie
X-Cdn
X-Proto
X-Trace-Id
Mime-Version
X-Akamai-Transformed
X-M-Reqid
X-Qnm-Cache
X-Platform-Server
HostName
X-M-Log
X-Tenant
X-Time-Microsecs
X-Endurance-Cache-Level
X-CSRF-Token
WPO-Cache-Message
WPO-Cache-Status
X-Edge-Location
X-GG-Cache-Date
X-AWS-Id
X-VWS-Id
X-LJ-Flow-ID
CloudFront-Viewer-Country
X-B3-SpanId
X-Xfnlog-Site
X-Cache-Remote
X-Cache-Tags
X-ECache
X-Xrds-Location
X-Mg-Request-UUID
N-Cache
X-TIME
X-PHP-Host
X-Amz-Apigw-Id
X-Labrador-Cache-Channel
X-Varnish-Cache-Hits
X-Amzn-RequestId
Upgrade-Insecure-Requests
ServedBy
X-Request-Time
Nel
X-RCS-CacheZone
X-Correlation-ID
X-AOL-HN
X-Via-NSCOPI
X-Locale
X-Origin-Response-Time
X-Handled-By
X-ARC
X-A-Ccd
X-Application
X-Aed
X-A-Dam
X-A-Dgt
X-A-Wwc
X-A-Dcw
Odigeo-Trace-Id
Expiry
Fastcgi-X-Cache-Version
Meta-Geo-Continent
DSUID
DCR-Processing-Time-Ms
A
BehaviorPad-Version
DCR-Decision-By
Mobile-Detection-Method
X-B-Cookie
Xc-Version
Surrogated-Key
User-Cache-Control
Rendered-Blocks
Redirect-Candidate
Origin
Pramga
X-A
X-Conf
X-S
X-S-Cookie
X-ScT
X-SD-PageType
X-Rojux
X-Request-Host
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Processor
X-Session-Fingerprint
X-Shop-Environment
X-TIM-N
X-V-Cache
X-Vdms-Path
X-Vdms-Version
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-Slack-Backend
X-VG-WebCache
X-SRCache-Key
X-PBS-Appsvrname
X-PAYTM-SRV-ID
X-Cluster
X-D
X-Destination
X-Developer
X-Ckpd-Fst-Backend
X-CF-Lambda-Version
X-Cache-Date
X-Cache-NE
X-CF-Lambda-Fn
X-External-Request-Id
X-Vtex-Remote-Cache
X-Ig-Push-State
X-NAPM-TraceId
X-ND-Cache
X-Orig-Expires
X-Hnp-Log
X-Gen-Mode
X-Forwarded-Path
X-Vtex-Processado-Em
X-Ftr-Request-Id
X-Block-Status
X-Connection-Hash
X-Storefront-Renderer-Rendered
X-MP-GENERATED-AT
X-VC-Cache
X-Cache-Bucket
X-Date
X-CACHE-KEY
Origin-CC
Origin-EX
X-Proxy-Upstream
X-Forwarded-Site
X-Policy
X-Cache-Info
Fastcgi-Cache-TTL
X-Scheme
X-Served-From
X-Server-IP
X-Reqid
Gh-Request-Id
X-Fetched-On
X-Fastly-Cache
Host-ID
X-Rocket-Nginx-Serving-Static
Release
X-Origin-Time
Wxu-Next-Commit
X-Li-Pop
X-LI-UUID
X-Location
Wxu-Next-Hostname
Wxu-Next-Region
X-Hash
X-Accel-Expires-Debug
X-Geo-Header
X-Li-Fabric
Vix-Hermes-Req-Id
V-Age
X-Nyt-Route
X-Old-Content-Length
X-Origin-Expires
X-Skip-Cache
X-Gdpr
State
X-Men
X-Mvc-Supplant-Cachable
Traceparent
X-Owner
L
Arc-Country
X-Adobe-Source
CacheControlHeader
X-Epic-Correlation-Id
X-Device-Os
X-ATG-Version
X-Webstats-RespID
X-VServer
X-Core-Mission
X-Varnish-Beresp-Status
CDCHOST
AKAMAI
Server-Info
Cmstype
Cmsid
X-Sucuri-ID
X-Sucuri-Cache
X-FireWall-Port
Environment
Datacenter
Thinkindot-CacheControl
TDXMobile
Svr
Thinkindot-CacheControl-Type
Thinkindot-Control
X-Sigma
X-Node-Id
X-NodeID
Sslversion
Server-Host
X-Developers
X-Gamma-Serve
X-GeoIP
X-HS-Content-Campaign-Id
X-Cdn-Srv
True-Client-Country-4JS
X-VarnishDD-TTL
From-Origin
X-Sigma-Backend
X-Datadog-Parent-Id
X-Aicache-OS
X-Level-Front-Cache
X-Datadog-Sampling-Priority
Web-Mar-Region
We-Hiring
X-Core-Value
X-Magnolia-Registration
X-VG-TLSProxy
X-Irp-Debug
X-Viewer-Country
X-BBC-Edge-Cache-Status
X-GeoIP-City
X-Fastly-Backend
X-Request-Start
X-Cache-Id
X-Req
X-Region-Sid
X-Cache-Debug
X-Esi-Check
X-Thinkindot-L3
Mail-Subject
X-Datadog-Trace-Id
X-TH-Server
X-Gzip
X-Thanos
Machine
Locid
Fastly-GeoIP-CountryCode
X-Rocket-Build-Number
X-Bip
X-TrackingId
X-HN
X-Sn-Servicetimems
X-Cdn-Origin
Req-Svc-Chain
X-Platform
X-Cache-Config
PFcat
X-Branch-Name
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
X-Generated-On
Apple-News-Services-Handled
X-EC-Lua
X-CS
X-DPWN-IS-SECURE
X-FC-Vary-Parameters
X-Eu-Site
X-CGP
X-Envoy-Decorator-Operation
X-DefHash
X-Csrf-Jwt
X-DefElseHash
X-Backend-State
Platform
Cf-Device-Type
Candidate-Md5Url
Adler-Geo
Fastly-SIE
Fastly-SWR
X-Has-Esi
HA-Ipaddr
Ha-Gx-Prefs
X-UnsetCookies
WP-Super-Cache
X-Worker
Fastly-Drupal-Html
Ssr
X-Tx-Id
X-Varnish-Remaining-TTL
X-Variation
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-Response-By
Is-Eu
X-NU-AKA-ACS-Version
X-Origin
X-Pod-Name
X-Qloud-Router
X-Loc
X-Zone
X-Amzn-Remapped-Content-Length
X-Is-Gdpr
X-JWT-State
L5d-Success-Class
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
NM-Fastcgi-Cache
Memcached
X-Request-URI
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
NGX
X-Ua-Device
X-Varnish-Beresp-Ttl
AMP-Access-Control-Allow-Source-Origin
X-Trace-ID
X-Mvc-Supplant-OutputCached
X-CLOUD-TRACE-CONTEXT
X-Up
X-API-Version
On-Server
WWW-Authenticate
X-LB-ID
Pics-Label
X-Ratelimit-Remaining
CDN
X-Vc
X-NWS-UUID-VERIFY
X-Backend-TTL
Ms-Author-Via
Esi-Enabled
X-Generated-In
X-Cache-Enabled
X-NC
X-Datadome
Memory
X-Refresh
NtCoent-Length
Time
X-LB-NoCache
X-GeoIP-Region-Code
X-GeoIP-Country-Code
X-DynaTrace-JS-Agent
X-DC
C-Via
X-Via-Popv
X-Service
X-Via-Poph
X-Tb-Optimization-Total-Bytes-Saved
X-Edge-Pop
Magicmarker
X-Via-Popn
X-TA-CDN-Provider
X-Varnish-Ttl
X-Cache-Ttl
X-Dynatrace
X-Cache-PHP
Env
X-Parent-Response-Time
X-TraceId
Kp-EeAlive
X-CacheTTL
X-Restarts
X-Tt-Logid
GeoIp-Country-Code
X-Optimistic-Header
S-Rt
X-Cache-Status-Check
X-Esi
X-Servedbyhost
X-Render-Time
X-Srv
X-RPS
X-DW
X-RSL
Edge-Cache
X-Cache-Backend
X-DSS
X-MSEdge-Features
X-DI
WebServer
X-ZONE
Server-ID
X-Varnish-Beresp-TTL
X-DB
X-Action
X-Unique-ID
X-RPM
X-MSEdge-Flight
X-Wix-Viewer-Type
X-Info
X-TX-ID
X-Cs
X-Minions-Version
X-VCL-Version
X-Webkit-CSP-Report-Only
X-AIR-PT
X-Http-Reason
X-Akamai-Request-ID2
X-Fpc
X-HA-Backend
Proxy-Connection
X-Newrelic-Synthetics
X-App
X-Clientip
X-Traceid
X-LI-Proto
X-URL
X-Oss-Server-Time
X-Oss-Storage-Class
X-Oss-Hash-Crc64ecma
HIT
X-Webkit-Csp-Report-Only
X-Oss-Request-Id
Cache-Host
X-Oss-Object-Type
UCS
X-Li-Proto
Test
Accept-Language
X-FPC
S-Cnection
X-LiteSpeed-Cache-Control
X-NODE
X-Vcl-Version
X-Ec-Fail
Server-Id
X-Ec-GeoHdr
Geo-Info
X-User
Tcn
X-B3-Spanid
Locale
Section-Io-Origin-Status
Lb
Section-Origin-Responded
X-Urbn-Site-Id
X-Urbn-Context-Path
Section-Io-Id
Section-Io-Origin-Time-Seconds
X-Micro-Cache
X-Pass-Why
Fastly-Backend-Name
User-Agent
X-HostName
X-Pad
Cf-Int-Pingora-Origin-Digest
X-Backend-Host
X-LiteSpeed-Tag
Fastly-Drupal-HTML
X-CSRF-TOKEN
GeoIP-Country-Code
Cdncip
X-Ha-Backend
X-ID
Resin-Trace
X-Release
X-APP
X-BCube-Filmed-By
X-BBC-Origin-Response-Status
M-TraceId
Cdnsip
X-AK-Request-ID
Hostname
X-WADP-Cache
Cluster
X-Clara-WADP
X-Check-Cacheable
Hit
X-ServedByHost
My-App
X-Fmm-Version
Ohc-File-Size
X-ES-SERVER
X-Dynatrace-Js-Agent
X-Geo
X-Via-PopN
VNS-Age
X-Via-PopV
X-WA
X-Var-Ttl
VNS-Cache
MIME-Version
X-Edge-POP
Path
X-RateLimit-Reset
EpKe-Alive
X-Amz-Meta-Cb-Modifiedtime
X-Via-PopH
X-ElasticPress-Query
X-CUA
Cache-Key
Geoip-Latitude
CPC-Cache
ENV
CPC-Age
Tracecode
X-WA-Info
X-NGINX-Cache
X-From
Load-Balancing
Lfy
X-HS-Status
X-Edge-Cache
T-Server
X-Api-Version
Srv
X-Akamai-Pragma-Client-IP
Servername
X-RAMCache
X-PJAX-URL
Lang
Shield-Pop
X-ServerName
X-Fragments
X-Ucs
X-Cdn-Forward
Pagetype
X-Cms-Context
URI
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-WP-CF-Super-Cache-Cache-Control
X-Newrelic-App-Data
X-WP-CF-Super-Cache
X-Fastly-Backend-Reqs
X-GoCache-CacheStatus
MD5-Digest
X-Mcache
Target-Params
X-Hcs-Proxy-Type
X-Nc
X-Fastly-Cache-Hits
X-Via-Ucdn
X-CCDN-CacheTTL
X-CCDN-Origin-Time
X-UP
X-TRACE-ID
X-Dw-Trace-Id
X-SIPLIST1
WZWS-RAY
X-VC
X-Lb-Id
X-B3-ParentSpanId
Ohc-Cache-HIT
Sever-Int
Uri
Cdn
IsBot
Server-Ext
X-VG-WebServer
X-Cdn-Request-ID
Cneonction
Server-Hostname
X-UA
W
Cteonnt-Length
CF-Cached-On
X-Cache-Expires
X-Acquia-Site
X-Snapshot-Date
PICS-Label
X-Swift-Error
Cf-Ipcountry
X-Acquia-Application-Trace
Vha6-Origin
X-Cache-ASPX
X-Acquia-Purge-Tags
X-Acquia-Application-UUID
X-Apw-Hits
X-Apw-Access-Token
X-Yottaa-OS
X-Apw-Access-Action
X-Apw-Access-Object
X-Contensis-Viewer-Groups
DataCenter
X-Cache-Ngx
X-Air-Pt
Sid
X-Akamai-ERRuleID
FSS-Cache
Server-Ttl
X-Akamai-ERPolicy
X-Te-Count
X-Te-Duration-Ms
X-Http-Duration-Ms
X-Last-Modified
GeoIP-Latitude
Permissions-Policy
X-Http-Count
X-B3-Parentspanid
X-Akamai-Request-ID
HitType
Dnion-Transfer-Encoding
X-Provided-By
X-Platform-Router
X-Platform-Cluster
X-Platform-Processor
X-Miniprofiler-Ids
X-Lb-Nocache
CountryCode
X-Sentry-ID
Req-ID
X-CacheKey
X-Varnish-Authentication
X-Logging-Id
Ngx