Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
X-Powered-By
Pragma
CF-RAY
X-Cache
Via
X-XSS-Protection
Age
Content-Security-Policy
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Xss-Protection
X-Amz-Cf-Pop
X-Amz-Cf-Id
Alt-Svc
P3P
X-Cache-Hits
X-UA-Compatible
X-Served-By
CF-Ray
X-Download-Options
X-Timer
X-Request-Id
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
Access-Control-Allow-Credentials
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
X-Drupal-Cache
X-Cache-Status
X-Generator
X-Check
X-Cacheable
X-Envoy-Upstream-Service-Time
X-FRAME-OPTIONS
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Iinfo
X-Dns-Prefetch-Control
X-Request-ID
X-Drupal-Dynamic-Cache
Server-Timing
Feature-Policy
X-Content-Security-Policy
Access-Control-Expose-Headers
Content-Encoding
X-CDN
X-XSS-PROTECTION
Status
Upgrade
X-AspNetMvc-Version
Access-Control-Max-Age
X-Amz-Request-Id
X-Via
X-Amz-Id-2
Request-Context
X-Backend
X-Turbo-Charged-By
X-Cache-Group
X-Robots-Tag
X-AH-Environment
Cf-Edge-Cache
Keep-Alive
Host-Header
X-Hacker
X-UA-Device
X-Vhost
X-Proxy-Cache
X-Server
X-Rq
Allow
X-Server-Powered-By
X-Ws-Request-Id
X-Age
X-Dispatcher
EagleId
X-Varnish-Cache
X-Amz-Version-Id
P3p
X-LiteSpeed-Cache
Nel
Grace
X-Ua-Compatible
Cf-Apo-Via
Cf-Railgun
X-OneAgent-JS-Injection
X-Page-Speed
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Device
EagleEye-TraceId
X-Swift-SaveTime
X-Swift-CacheTime
X-Aws-Lambda-Call-Status
Ali-Swift-Global-Savetime
X-Pingback
X-Host
X-Node
Accept-CH
X-WebKit-CSP
X-Cache-Lookup
X-CST
X-Backend-Server
Surrogate-Control
X-Server-Id
Permissions-Policy
Accept-CH-Lifetime
X-Readtime
X-Nginx-Cache-Status
X-Nginx-Upstream-Cache-Status
X-Akam-SW-Version
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
Request-Id
X-Application-Context
X-Ruxit-JS-Agent
X-Content-Security-Policy-Report-Only
X-Cloud-Trace-Context
X-Response-Time
Xkey
X-HW
X-Trace
X-Edge
Content-Location
X-Clacks-Overhead
X-Mod-Pagespeed
X-Url
Rating
X-ESI
X-Midtier
X-Amz-Server-Side-Encryption
X-ECACHE
X-Mcache
Cache-Tag
X-Country
X-MS-InvokeApp
X-Rack-Cache
X-Powered-By-Plesk
X-D2id
X-GoogleNews-Bot
X-Exp-Variant
X-Kinja
X-Kinja-Build
X-Kinja-Server
X-Kinja-Revision
X-Use-Magma
X-Exp-Id
X-Cdn-Fetch
X-Upstream
X-Element-Page-Cache
X-Vcap-Request-Id
Verso
Service-Worker-Allowed
Accept-Ch
Edge-Control
X-PC
X-Vname
X-TtlSet
RTSS
X-Country-Code
X-Ac
Origin-Trial
X-Goog-Hash
Accept-Ch-Lifetime
X-VARITI-CCR
X-Navigation-Version
X-Abt-Application-Version
X-Cache-TTL
Fastly-Restarts
X-Browser-Type
X-Kinja-CCPA
X-Amz-Rid
X-Varnish-TTL
X-Oneagent-Js-Injection
X-Cached
X-Litespeed-Cache
X-Aspnetmvc-Version
X-NWS-LOG-UUID
X-WebKit-CSP-Report-Only
Cross-Origin-Opener-Policy
X-GitHub-Request-Id
X-Server-Name
X-Webkit-CSP
Display
X-Sol
Pagespeed
X-Middleton-Display
X-Dw-Request-Base-Id
X-Amzn-Trace-Id
X-SharePointHealthScore
SPRequestGuid
X-Ttl
X-Times
X-Content-Type
SPIisLatency
SPRequestDuration
X-Erf-Bev-Bev
X-Server-ID
X-Server-Lifecycle-Phase
X-Instrumentation
X-Erf-Bev-Bev-Is-Generated
X-Kraken-Loop-Name
Pinterest-Version
X-Ruxit-Js-Agent
X-Pinterest-Rid
X-Cache-Key
Pinterest-Generated-By
AR-SID
AR-PoweredBy
AR-Request-ID
AR-ATIME
X-Powered-CMS
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
X-Mg-S
Arr-Disable-Session-Affinity
Response
X-Middleton-Response
X-Version
X-Ser
X-Cnection
X-HP-Trace-Id
X-Jurisdiction
X-HP-Webp
X-B3-TraceId
X-B3-Traceid
Nginx-Cache
X-FastCGI-Cache
X-Accel-Expires
Cache-Tags
X-Client-IP
X-T
AR-CACHE
X-SRCache-Store-Status
X-SRCache-Fetch-Status
Cache-Status
X-NF-Request-ID
Edge-Cache-Tag
X-Fastly-Request-ID
X-Hits
X-MSEdge-Ref
Front-End-Https
X-Px
Public-Key-Pins
X-Recruiting
S
Payment
X-Shield-Request-Id
X-LLID
X-Frontend
X-RateLimit-Remaining
X-Request-Received
X-Request-Processing-Time
Server-Node
X-Ua-Browser
X-Daa-Tunnel
X-B3-TraceId-Primal
Mrf-Cache-Status
MRF-Tech
X-Goog-Metageneration
X-GUploader-UploadID
Content-MD5
X-Webkit-CSP-Report-Only
X-DIS-Request-ID
Access-Control-Request-Method
MicrosoftSharePointTeamServices
X-RateLimit-Limit
X-Content-Digest
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Ratelimit-Remaining
TP-Cache
Realpath
X-Forwarded-For
X-Protected-By
X-Microsite
X-Request-Handler-Origin-Region
X-Distributor
X-HS-Combine-CSS
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Cache-Config
Access-Control-Allow-Method
Fastcgi-Cache
X-TTL
X-Fastcgi-Cache
X-FB-Debug
X-Page-Id
X-Rid
Accept-Charset
X-Cluster-Name
X-LB-Cache
X-PressLabs-Stats
X-Geo-Country
X-Hostname
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-Xrds-Location
X-B3-Sampled
Count-Hit
TP-L2-Cache
X-Ratelimit-Limit
X-Aspnet-Version
Cross-Origin-Resource-Policy
X-Ua-Device
X-Kinsta-Cache
X-Correlation-Id
X-Seen-By
X-Edge-Location-Klb
X-Id
X-Ezoic-Cdn
Cleartype
X-Erf-Stays-Pdp-Viaduct-Migration-Web
TCN
X-App-Server
X-Logged-In
X-Varnish-Backend
Referer-Policy
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Mobile
X-Content-Options
X-Git-Hash
X-Hosted-By
DC
X-Contextid
X-Origin-Cache
X-Request-Guid
Retry-After
X-Fb-Rlafr
X-Providence-Cookie
X-Route-Name
X-Flags
X-Aspnet-Duration-Ms
X-Is-Crawler
X-Revision
X-Amz-Replication-Status
X-Debug-Info
Surrogate-Key
X-Grace
X-TT
X-Forwarded-Proto
X-App-Environment
X-Newrelic-App-Data
Frame-Options
X-F-Cache
X-IPS-LoggedIn
X-Varnish-Grace
X-Amz-Meta-S3cmd-Attrs
X-Envoy-Decorator-Operation
X-Azure-Ref
X-Magnolia-Registration
Section-Io-Cache
MS-Author-Via
X-Wix-Request-Id
X-Proxy-Cache-Info
X-Whom
Healthy
X-Client-Ip
Charset
X-Www-Served-By
X-App-Version
Viewport
X-Akamai-Edgescape
Alternate-Protocol
X-Origin-Server
X-RateLimit-Reset
X-COUNTRY
Filterid
WPO-Cache-Message
X-Backend-Name
WPO-Cache-Status
X-AppVersion
X-Webkit-Csp
X-Activity-Id
X-Az
Amp-Access-Control-Allow-Source-Origin
X-Language
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Varnish-Server
X-B
Server-Name
Paypal-Debug-Id
SRV
X-Trace-Id
X-DataDome
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
X-Cache-Rule
X-Original-Request-Id
Host
X-Http-Reason
X-Response-Served-From
VIX-Pulpo-Upstream-Status
X-EdgeConnect-Cache-Status
SD-X-WS
VIX-Pulpo-Node
X-Rule
X-UUID
X-User-Agent
X-Edge-Location
X-Akamai-Request-ID2
X-Cache-Grace
X-Instance
Front
X-Time
X-ARC
X-Region
X-Unique-Id
X-Page-View
X-Varnish-Age
X-N
X-Jobs
X-Environment-Context
X-Cacheable-TTL
Protected
From-Origin
X-Vcache
X-L-Path
X-Rocket-Nginx-Serving-Static
X-FW-Dynamic
X-Is-Bot
X-FW-Version
X-FW-Serve
X-Yottaa-Optimizations
X-Tumblr-Pixel
X-Status
X-FW-Type
Akamai-GRN
Fastly-SIE
Fastly-SWR
X-FW-Server
X-FW-Hash
X-FW-Static
Country
X-Tumblr-Pixel-0
X-Rendered-As
X-Load-Cache
X-ProcessESI
X-Yottaa-Metrics
X-RemovedCookies
X-Tumblr-Pixel-1
X-Adobe-Loc
X-Framework
X-Adobe-Content
X-Tumblr-User
X-Type
Content-Disposition
X-Cache-Time
X-G
X-Mg-Request-UUID
X-Signature
X-Datadog-Sampled
X-B-Cache
X-Nf-Request-Id
X-Proxy
ServerID
X-Debug-IsPreview
Access-Control-Request-Headers
X-Debug-IsConnected
X-Amzn-Remapped-Content-Length
X-CDN-Forward
Backend
X-Cache-Control
X-Cache-Age
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
X-ECache
X-Tec-Api-Origin
X-Tec-Api-Root
X-Tec-Api-Version
Countrycode
X-Nginx-Cache
Refresh
X-Servername
X-DynaTrace
X-Httpd
X-Tt-Trace-Host
Url
Accept-Language
Xet-Cookie
X-Tt-Trace-Tag
X-Erf-Web-Scheduler
X-Drupal-Cache-Tags
CF-IPCountry
X-DynaTrace-JS-Agent
X-Generated-By
X-Device-Type
X-HTML-Minification-Powered-By
X-Template
X-NYM-Debug-Backend
X-Content-Powered-By
X-Mode
X-Source
Xserver
X-Storage
GEO-INFO
X-Rn-Rsrv
X-UPSTREAM-Address
X-Director
X-Cache-Operation
X-Content-Age
X-Rewrite-Enabled
OT-Force-Account-Verify
S-Rt
X-GeoCountry
X-ServerID
X-Urbn-Context-Path
X-Cache-Action
Locale
X-Say-Cacheable
X-LAGOON
X-Urbn-Site-Id
X-Cache-Hit
Load-Balancing
X-JoinUs
X-SaId
X-SayCDN-TTL
Meta-Geo
X-GeoCode
Filters
X-Say-TTL
Version
X-Varnish-Cache-Hits
X-Cluster-Node
Cross-Origin-Window-Policy
X-Container-Uri
X-Varnish-Hostname
X-Forwarded-Host
Onion-Location
X-Loop
X-Git-Commit
X-Tncms
X-Soup
X-Tt-Logid
X-Sql-Count
X-Ms-Version
X-Sql-Duration-Ms
X-Adobe-Source
X-VC-Cache
Web-Mar-Node
X-VCT
X-Tumblr-Pixel-3
Azure-SiteName
Azure-SlotName
Azure-Version
Azure-RegionName
Azure-InstanceId
X-Tb
X-Ms-Request-Id
X-Lambda-Id
X-PHP-Host
X-Cache-Server
X-Labrador-Cache-Channel
Webserver
X-RM-Cache-TTL
X-Served-From
X-Tumblr-Pixel-2
X-Detected-As
X-Hcs-Proxy-Type
X-CCDN-Origin-Time
X-CCDN-CacheTTL
X-Zipkin-Id
X-FB-TRIP-ID
X-R9-Blue-Green-Version
X-URL
X-RCS-CacheZone
X-Logging-Id
X-Proxied
Node
X-XRDS-LOCATION
X-Skip-Cache
X-Extlb
X-Routing-Service
DB-Nickname
Mn-Server-Ip
X-Timing-Wait
TWC-Device-Class
TWC-Connection-Speed
Selected-Fe
Webcakes-Region
X-Proto
X-Uri
X-Proxy-Build
X-Fetched-On
X-Debug
X-Origin-Hint
TWC-GeoIP-LatLong
TWC-Locale-Group
TWC-Privacy
Webcakes-App-Version
TWC-GeoIP-Country
Webcakes-App-Name
X-B3-SpanId
X-Oracle-Dms-Rid
X-Oracle-Dms-Ecid
X-MCACHE
Property-Id
Fastcgi-Useragent
X-Endurance-Cache-Level
X-Generation-Time
X-XRDS-Location
X-Format
X-Redis-Cache
X-NGENIX-Cache
Uber-Trace-Id
X-LSADC-Cache
X-Zen-Fury
Source
X-Ratelimit-Reset
CDN-RequestId
X-FTR-Request-ID
X-Sucuri-ID
X-Sucuri-Cache
X-Ua
Section-Io-Id
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
X-S
X-Drupal-Cache-Contexts
X-Origin-TTL
X-Origin-CC
X-Origin-Date
X-Pass-Why
X-MP-GENERATED-AT
NGB
X-TimeS
X-Real-IP
Upgrade-Insecure-Requests
X-Srv
Fastly-Drupal-HTML
X-Varnish-Hits
X-Akamai-Transformed
X-Cache-Expired-At
X-Fastly-Request-Id
Liferay-Portal
X-Upgrade-Enabled
X-Handled-By
X-GEO
X-CACHE-AGE
X-Reqid
X-Newrelic-Synthetics
X-Cms-Context
X-Optimistic-Header
X-Xfnlog-Site
Apigw-Requestid
X-Restarts
ServedBy
X-Hl-Ver
X-RTag
X-Tx-Id
Ms-Operation-Id
MS-CV
X-No-Session
X-UA-Device-Type
X-Cache-TTL-Remaining
X-BYPASS-REASON
X-Cache-Host
X-ProxyCache-Key
X-ProxyCache-Status
CDN-PullZone
CDN-EdgeStorageId
CDN-CachedAt
CDN-Cache
X-Via-JSL
WP-Super-Cache
X-CSRF-Token
CDN-Uid
X-Parent-Response-Time
CDN-RequestPullCode
X-Node-Name
CDN-RequestCountryCode
CDN-RequestPullSuccess
X-AWS-Id
X-AB
X-Cluster
X-Varnish-Ttl
X-LJ-Flow-ID
X-Pubstack
X-IPLB-Request-ID
X-VWS-Id
X-IPLB-Instance
X-Cache-Type
DCR-Decision-By
X-Proxy-Cache-Status
DCR-Processing-Time-Ms
Magicmarker
Ngx.Var.Host
Cache-Provider
BehaviorPad-Version
Canary
Candidate-Md5Url
Fastly-SSL
Gannett-Cam-Experience-Id
L5d-Success-Class
Lang
MD5-Digest
L
Host-ID
Ha-Gx-Prefs
HA-Ipaddr
Meta-Geo-Continent
N-Cache
X-A-Dcw
X-Epic-Correlation-Id
X-Ec-GeoHdr
X-Eu-Site
X-External-Request-Id
X-FC-Vary-Parameters
X-Fastly-Backend
X-Ec-Fail
X-Ec-Custom-Error
X-Debug-Cache-Store
X-Debug-Cache-Fetch
X-Destination
X-Developer
X-Dispatcher-Number
X-Request-Host
X-Rojux
X-Viewer-Country
X-Vdms-Version
X-Vtex-Remote-Cache
X-We-Are-Hiring
Xc-Version
X-Worker
X-Vdms-Path
X-SRCache-Key
X-ScT
X-S-Cookie
X-SD-PageType
X-Slack-Backend
X-Slack-Shared-Secret-Outcome
X-D
X-Csrf-Jwt
Vix-Hermes-Req-Id
True-Client-Country-4JS
W
Web-Mar-Region
X-A-Ccd
X-A
T-Server
Surrogated-Key
Redirect-Candidate
Origin-Agent-Cluster
Rendered-Blocks
Server-Host
Sslversion
X-A-Dam
X-A-Dgt
X-CacheTTL
X-Cache-NE
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-Conf
X-CGP
X-Bl-Debug
X-BCube-Filmed-By
X-Aed
X-A-Wwc
X-App
X-Application
X-Bc-Bl
Odigeo-Trace-Id
X-B-Cookie
X-Micro-Cache
X-Server-W
X-Geo-Region
X-TraceId
X-Cache-Status-Check
X-Varnish-CookieINHashed-On
X-Core-Mission
X-Gdpr
X-Varnish-CookieHashed-On
Mail-Subject
X-Thanos
X-Varnish-Remaining-TTL
Origin
X-ShardId
X-Server-IP
X-SVT-ORM-RULES
X-Core-Value
X-Wikidot-Backend
X-SVT-ORM-VERSION
X-Generated-On
X-Accel-Expires-Debug
X-Accel-Buffering
Is-Eu
X-GeoIP-Country-Code
X-Hash
Gh-Request-Id
X-Wikidot-Static-Cache
X-Policy
X-Variation
X-Wix-Viewer-Type
X-GeoIP-Region-Code
X-ShopId
X-VG-TLSProxy
X-Sorting-Hat-ShopId
X-DPWN-IS-SECURE
X-VG-WebCache
X-Sorting-Hat-PodId
VNS-Age
TDXMobile
Thinkindot-CacheControl
X-Storefront-Renderer-Rendered
X-Owner
X-DefHash
Thinkindot-Control
Thinkindot-CacheControl-Type
X-Sn-Servicetimems
VNS-Cache
Platform
Producers
X-Varnishpool
X-Shopify-Stage
X-CMSURLCustom
X-VServer
Release
X-Date
X-Origin-Time
We-Hiring
Req-Svc-Chain
X-Vmg-Version
X-Pool
X-Clientip
X-Mid
X-Cache-Debug
X-Mly-Id
X-Refresh
X-RateLimit-Remaining-Second
X-PAYTM-SRV-ID
X-Loc
Adler-Geo
X-Var-Ttl
X-Thinkindot-L3
X-Cache-Bucket
X-Level-Front-Cache
X-Mvc-Supplant-Cachable
X-Cdn-Diag
X-Nyt-Route
X-NodeID
X-Old-Content-Length
X-Org
X-Cache-Info
X-Node-Id
X-Qloud-Router
X-Nananana
X-Platform
X-Nitro-Cache
X-RateLimit-Limit-Second
X-Bip
X-Cdn-Origin
CPC-Cache
Datacenter
CPC-Age
X-BBC-Edge-Cache-Status
Cmstype
X-Alternate-Cache-Key
Environment
X-DefElseHash
Fastly-GeoIP-CountryCode
Fastly-Backend-Name
Expect-Staple
Cmsid
X-App-Name
X-Request-Time
X-Irp-Debug
X-Human
Cache-Name
X-Up
X-S-Maxage
User-Cache-Control
X-TIME
X-Presslabs-Stats
X-Correlation-ID
X-Block-Status
X-Auto-Login
X-Test
X-Clara-WADP
X-Tenant
X-Cache-Id
X-Akamai-Device-Characteristics
X-Forwarded-Site
X-ApacheServer
CDCHOST
X-INCAP-ABP
X-Instance-Name
Cf-Device-Type
Country-Code
AKAMAI
DSUID
CloudFront-Viewer-Country
X-Dispatcher-Server
Apple-News-Services-Request-Url
X-Mvc-Supplant-OutputCached
X-Nginx-Cache-Key
X-Orig-Expires
X-Origin
X-PERF
X-Geo-Header
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
Apple-News-Services-Handled
X-AIR-PT
Esi-Enabled
NM-Fastcgi-Cache
X-Fmm-Version
X-Forwarded-Path
X-Shop-Environment
X-Esi-Check
Server-Ext
X-Origin-Response-Time
Sever-Int
X-Hnp-Log
X-WA-Info
X-GeoIP
X-Gzip
X-Device-Os
Server-Hostname
X-Gen-Mode
X-From
X-WADP-Cache
Machine
Content-Secure-Policy
X-Cdn-Srv
X-Section
X-LB-NoCache
Wxu-Next-Commit
Server-Info
Ssr
Wxu-Next-Hostname
Wxu-Next-Region
X-Vgn-Hpd-Reason
X-Via-Fastly
C-Via
X-NCache
NGX
X-Op-Id-All
X-ID
Pics-Label
X-Access
X-Datadome
X-Cache-Enabled
X-Accel-Version
X-B3-Spanid
X-Browser-Name
X-Is-Supported-Browser
X-Is-Mobile
Server-ID
X-Tcp-Rtt
X-Is-Tablet
X-Is-Desktop
X-Buckets
X-API-Version
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Ttl
AMP-Access-Control-Allow-Source-Origin
X-Dc
X-SIPLIST1
X-Amz-Meta-Cb-Modifiedtime
IsBot
X-CACHE-GROUP
X-Vcl-Version
X-HA-Backend
X-JWT-State
X-Has-Esi
Memcached
X-Is-Gdpr
X-Zone
Memory
Hostname
YJS-ID
Time
X-Platform-Processor
X-Platform-Cluster
X-Platform-Router
X-B3-Parentspanid
X-Scale
Cache-Hits
X-Cached-By
Origin-CC
Cdn-Requestid
Location
X-TA-CDN-Provider
X-Origin-Cache-Key
X-Tb-Optimization-Total-Bytes-Saved
X-Wp-Cf-Super-Cache-Active
Origin-EX
CF-Ctrl
X-Air-Hostname
Sid
X-WP-CF-Super-Cache-Active
X-Air-Trace-Id
X-Air-Source
X-Fpc
X-Internal-Host
X-TIM-N
X-Frame-Option
X-PHP-Backend
X-NewRelic-App-Data
X-ZONE
X-Hyper-Cache
Resin-Trace
X-DC
X-Backend-Instance
X-Cs
X-LiteSpeed-Cache-Control
X-Webstats-RespID
X-VC
X-Azure-Ref-OriginShield
X-DataCenter
X-Service
X-FTR-Expires
X-FTR-Cache-Status
X-FTR-Backend-Server
X-Country-Code-Real
X-FTR-Backend
X-FTR-Balancer
X-Github-Request-Id
Epwk-X-Cache
LB
X-Site-Version
GeoIP-Latitude
True-Client-Ip
X-SRV
X-Microcachable
X-Locale
X-NGINX-Cache
X-Nitro-Cache-From
Cache-Host
Uri
GeoIP-Country-Code
X-Nitro-Rev
WebServer
X-Origin-Expires
XM
X-Info
GeoIp-Country-Code
X-VCache
Cdn-Request-Time
XServer
Cdn-Host
WZWS-RAY
X-HN
PFcat
Cdn
X-Edge-Server
X-NMSegId
X-Pod-Name
X-VarnishDD-TTL
Req-ID
X-Cache-Ttl
X-Web-Node
X-CSRF-TOKEN
SID
X-Pad
NtCoent-Length
X-Ad-Load-Variation
User-Agent
M-TraceId
True-Client-IP
X-Ad-Defer-Variation
X-Datacenter
X-Geo
X-CS
X-Vercel-Cache
A
X-Request-URI
Edge-Copy-Time
X-Vercel-Id
X-M-Reqid
X-Request-Start
Pramga
X-Via-SSL
X-Scope-Id
Srvid
Locid
Cluster
X-Via-CDN
X-M-Log
X-Via-Edge
X-FL-QIT-DEBUG
X-FL-EDGE
Fastly-Drupal-Html
Content-Script-Type
X-Shield-Cache-Expires
Content-Style-Type
X-FPC
X-Qnm-Cache
HostName
X-MSEdge-Features
X-MSEdge-Flight
X-Varnish-Beresp-Status
X-HostName
Tcn
X-Cache-Date
Edge-Cache
Cache-Tv-Group
X-LiteSpeed-Tag
X-Contensis-Viewer-Groups
X-Cache-ASPX
X-Varnish-Authentication
X-FireWall-Port
X-Moov-Xdn-Version
X-Moov-T
X-ATG-Version
X-Cdn-Request-ID
CountryCode
Cf-Ipcountry
X-TRACE-ID
X-APP-VERSION
X-Api-Version
X-Esi
X-Amz-Meta-Opti
X-VCL-Version
X-WP-CF-Super-Cache-Cookies-Bypass
X-TH-Server
Cdncip
X-AK-Request-ID
X-NWS-UUID-VERIFY
Cdnsip
Cache-Key
Path
X-Via-Poph
X-Via-Popn
X-Via-Popv
X-V-Cache
X-Wa
X-Req
X-B3-Trace-ID
X-Aicache-OS
X-Acquia-Purge-Cdn-Unconfigured
Tube-Return
X-Cache-FS-Status
X-LB-ID
X-Servedbyhost
X-SB
X-Nc
Tube-Got-Results
Tube-Got-Eval
Click-Count-Error
Click-Count-Action-Start
X-Branch-Name
X-UA
Tube-Get-Contents
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-Vary
XkeyRZ
X-Men
X-Proxy-CacheRZ
Yak-Timeinfo
MIME-Version
On-Server
X-Air-Pt
V-Age
CDN
X-CACHE-KEY
X-Planisys-CDN-Rules
X-Platform-Server
X-Wp-Cf-Super-Cache-Cache-Control
X-Render-Time
X-Cdn-Forward
Srv
X-Wp-Cf-Super-Cache
Geoip-Latitude
X-Planisys-CDN-Cache
Wpo-Cache-Message
X-Planisys-CDN-TTL
Wpo-Cache-Status
Proxy-Connection
State
Ngx-Var-Key
X-Fastly-Backend-Reqs
X-HS-Content-Campaign-Id
X-Akamai-Pragma-Client-IP
X-Tim-N
X-Rebelmouse-Cache-Control
X-Lb-Cache
X-Rebelmouse-Surrogate-Control
X-User
X-Release
X-Dw-Trace-Id
My-App
X-Vgn-Hpd-Cached
Lb
Priority
CF-Cached-On
X-Upstream-Ct
X-Fastly-Cache
X-Vgn-Hpd-Ssi
X-Upstream-Ht
X-Ha-Backend
X-Generated-In
Server-Id
X-Vgn-Hpd-Variations-Key
X-TT-LOGID
X-Varnish-Director
Ohc-Cache-HIT
Ohc-File-Size
X-Fastly-Country-Code
PICS-Label
X-Acquia-Purge-Tags
X-Acquia-Site
X-Lb-Nocache
X-Acquia-Application-Trace
X-Via-Ucdn
X-Traceid
X-Cache-Remote
X-Sigma-Backend
X-Acquia-Application-UUID
X-CUA
X-EC-Lua
X-Sigma
X-HS-Status
X-Rocket-Build-Number
X-Iplb-Request-Id
X-Iplb-Instance
Yjs-Id
X-Snapshot-Date
X-CF-Cache-Header-Vary
Cache
CACHE-MISS-TO-ORIGIN
Inserted-Into-Cache-At
Vha6-Origin
Warning
X-Fastly-Cache-Hits
Ngx
Cneonction
X-RAMCache
X-Miniprofiler-Ids
X-Udemy-Cache-App-Namespace
Log-Origin
X-ElasticPress-Query
X-Litespeed-Cache-Control
X-CF-Cache-Header-Cache-Control
X-Cached-Since