Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
X-Powered-By
Pragma
CF-RAY
X-XSS-Protection
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
Alt-Svc
X-Xss-Protection
P3P
X-Cache-Hits
X-UA-Compatible
X-Served-By
CF-Ray
X-Download-Options
X-Timer
X-Request-Id
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
Access-Control-Allow-Credentials
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
X-Drupal-Cache
X-Cache-Status
X-Generator
X-Check
X-Cacheable
X-Envoy-Upstream-Service-Time
X-FRAME-OPTIONS
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Iinfo
X-Dns-Prefetch-Control
X-Request-ID
X-Drupal-Dynamic-Cache
Server-Timing
Feature-Policy
X-Content-Security-Policy
Access-Control-Expose-Headers
Content-Encoding
X-CDN
X-XSS-PROTECTION
Status
Upgrade
X-AspNetMvc-Version
Access-Control-Max-Age
X-Amz-Request-Id
X-Via
X-Amz-Id-2
Request-Context
X-Backend
X-Turbo-Charged-By
X-Cache-Group
X-Robots-Tag
X-AH-Environment
Cf-Edge-Cache
Host-Header
Keep-Alive
X-Hacker
X-Vhost
X-Proxy-Cache
X-Server
X-Rq
X-UA-Device
Allow
X-Server-Powered-By
X-Ws-Request-Id
X-Age
X-Dispatcher
EagleId
X-Varnish-Cache
X-Amz-Version-Id
P3p
X-LiteSpeed-Cache
Nel
Grace
X-Ua-Compatible
Cf-Apo-Via
Cf-Railgun
X-Page-Speed
X-OneAgent-JS-Injection
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
EagleEye-TraceId
X-Device
X-Swift-SaveTime
X-Swift-CacheTime
X-Aws-Lambda-Call-Status
Ali-Swift-Global-Savetime
X-Pingback
X-Host
X-Node
X-WebKit-CSP
Accept-CH
X-Cache-Lookup
X-CST
X-Backend-Server
Surrogate-Control
X-Server-Id
Permissions-Policy
X-Readtime
X-Nginx-Cache-Status
Accept-CH-Lifetime
X-Nginx-Upstream-Cache-Status
X-Akam-SW-Version
Request-Id
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Application-Context
X-Ruxit-JS-Agent
X-Content-Security-Policy-Report-Only
X-Cloud-Trace-Context
X-Response-Time
Xkey
X-HW
X-Trace
X-Edge
Content-Location
X-Clacks-Overhead
X-Mod-Pagespeed
Rating
X-Url
X-ESI
X-Midtier
X-Amz-Server-Side-Encryption
X-ECACHE
X-Country
X-Mcache
Cache-Tag
X-MS-InvokeApp
X-Powered-By-Plesk
X-Rack-Cache
X-D2id
X-Upstream
Verso
X-Vcap-Request-Id
X-Element-Page-Cache
Accept-Ch
Service-Worker-Allowed
Edge-Control
X-GoogleNews-Bot
X-Kinja
X-Kinja-Server
X-Kinja-Build
X-Cdn-Fetch
X-Exp-Variant
X-Exp-Id
X-Kinja-Revision
X-Use-Magma
X-PC
X-TtlSet
X-Vname
X-Country-Code
X-Ac
RTSS
X-Goog-Hash
Accept-Ch-Lifetime
Origin-Trial
X-VARITI-CCR
X-Navigation-Version
X-Cache-TTL
X-Abt-Application-Version
Fastly-Restarts
X-Varnish-TTL
X-Browser-Type
X-Kinja-CCPA
X-WebKit-CSP-Report-Only
X-Amz-Rid
X-GitHub-Request-Id
X-Oneagent-Js-Injection
X-Cached
X-Litespeed-Cache
X-Aspnetmvc-Version
X-NWS-LOG-UUID
Cross-Origin-Opener-Policy
X-Webkit-CSP
X-Server-Name
Display
X-Middleton-Display
Pagespeed
X-Sol
X-Dw-Request-Base-Id
X-Amzn-Trace-Id
X-SharePointHealthScore
SPRequestGuid
X-Content-Type
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
SPIisLatency
SPRequestDuration
X-Pinterest-Rid
Pinterest-Generated-By
Pinterest-Version
X-Ruxit-Js-Agent
X-Cache-Key
X-Times
X-Powered-CMS
AR-Request-ID
AR-ATIME
X-Instrumentation
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
AR-PoweredBy
X-Ttl
AR-SID
X-Mg-S
Arr-Disable-Session-Affinity
Response
X-FastCGI-Cache
X-Middleton-Response
X-Version
X-Client-IP
X-Ser
X-Cnection
X-HP-Webp
X-Jurisdiction
X-HP-Trace-Id
X-B3-Traceid
X-B3-TraceId
Nginx-Cache
X-Accel-Expires
X-Fastly-Request-ID
X-T
Cache-Tags
AR-CACHE
X-Server-ID
X-SRCache-Store-Status
X-SRCache-Fetch-Status
Cache-Status
X-NF-Request-ID
Edge-Cache-Tag
X-Hits
X-RateLimit-Remaining
Front-End-Https
X-MSEdge-Ref
Public-Key-Pins
X-Px
X-Ua-Device
X-Recruiting
S
Payment
X-Shield-Request-Id
X-Frontend
X-Request-Received
X-LLID
X-Request-Processing-Time
Server-Node
X-Ua-Browser
X-RateLimit-Limit
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
X-Daa-Tunnel
X-GUploader-UploadID
X-Goog-Metageneration
Content-MD5
X-TTL
Access-Control-Request-Method
X-DIS-Request-ID
MicrosoftSharePointTeamServices
X-Content-Digest
X-Amzn-RequestId
X-Amz-Apigw-Id
Realpath
TP-Cache
X-Forwarded-For
X-Request-Handler-Origin-Region
X-Protected-By
X-Microsite
X-Webkit-CSP-Report-Only
X-Distributor
X-PressLabs-Stats
X-HS-Combine-CSS
X-HS-Cache-Config
X-HS-Content-Id
X-HS-Hub-Id
Fastcgi-Cache
Access-Control-Allow-Method
X-Page-Id
Accept-Charset
X-FB-Debug
X-Rid
X-LB-Cache
X-Cluster-Name
X-Ratelimit-Remaining
X-Goog-Storage-Class
X-Goog-Generation
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Geo-Country
X-B3-Sampled
Count-Hit
TP-L2-Cache
X-Fastcgi-Cache
X-Aspnet-Version
X-Hostname
X-Edge-Location-Klb
X-Seen-By
X-Kinsta-Cache
Cross-Origin-Resource-Policy
X-Ezoic-Cdn
X-Id
Cleartype
X-Correlation-Id
X-Erf-Stays-Pdp-Viaduct-Migration-Web
X-App-Server
X-Xrds-Location
X-Logged-In
Referer-Policy
X-Varnish-Backend
X-TEC-API-VERSION
X-Ratelimit-Limit
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Mobile
X-Content-Options
TCN
DC
X-Hosted-By
X-Newrelic-App-Data
X-Git-Hash
X-Contextid
X-Is-Crawler
X-Aspnet-Duration-Ms
X-Route-Name
X-Providence-Cookie
Retry-After
X-Origin-Cache
X-Flags
X-Request-Guid
Surrogate-Key
X-Fb-Rlafr
X-Revision
X-App-Environment
X-Forwarded-Proto
X-Amz-Replication-Status
X-Debug-Info
X-Grace
X-TT
X-F-Cache
Frame-Options
X-IPS-LoggedIn
X-Varnish-Grace
X-Amz-Meta-S3cmd-Attrs
X-Envoy-Decorator-Operation
X-Azure-Ref
X-RateLimit-Reset
X-Magnolia-Registration
Section-Io-Cache
MS-Author-Via
X-Wix-Request-Id
X-Proxy-Cache-Info
X-Whom
X-App-Version
Healthy
Charset
X-Www-Served-By
Viewport
Alternate-Protocol
X-Origin-Server
X-Akamai-Edgescape
X-COUNTRY
X-Az
X-Language
X-AppVersion
WPO-Cache-Message
X-Backend-Name
Filterid
WPO-Cache-Status
X-Webkit-Csp
X-Activity-Id
X-Varnish-Server
X-B
X-Kong-Proxy-Latency
Server-Name
X-Kong-Upstream-Latency
X-Trace-Id
SRV
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
Paypal-Debug-Id
X-Datadog-Parent-Id
X-Original-Request-Id
X-Response-Served-From
X-Http-Reason
Host
VIX-Pulpo-Upstream-Status
X-EdgeConnect-Cache-Status
VIX-Pulpo-Node
SD-X-WS
X-UUID
X-User-Agent
X-Instance
X-Rule
X-Akamai-Request-ID2
X-Environment-Context
X-Unique-Id
X-L-Path
Protected
Country
X-Edge-Location
X-Cache-Grace
X-Rocket-Nginx-Serving-Static
X-ARC
X-Page-View
X-N
X-Cache-Rule
Front
Amp-Access-Control-Allow-Source-Origin
X-Region
X-Jobs
X-Rendered-As
X-Status
X-Is-Bot
From-Origin
X-Cacheable-TTL
X-Yottaa-Optimizations
X-Time
X-Tumblr-Pixel
Akamai-GRN
X-Yottaa-Metrics
X-Client-Ip
X-Tumblr-Pixel-1
X-Tumblr-User
X-Varnish-Age
X-Tumblr-Pixel-0
X-FW-Serve
X-FW-Static
X-FW-Type
X-FW-Server
X-Type
Fastly-SIE
X-Adobe-Content
X-Adobe-Loc
X-DataDome
X-Framework
X-FW-Dynamic
Fastly-SWR
X-FW-Hash
X-FW-Version
X-Load-Cache
X-ProcessESI
X-RemovedCookies
X-Proxy
X-Signature
X-Cache-Time
X-B-Cache
X-Datadog-Sampled
Content-Disposition
X-Nf-Request-Id
X-G
ServerID
X-Amzn-Remapped-Content-Length
X-Vcache
X-Debug-IsPreview
Access-Control-Request-Headers
X-Debug-IsConnected
X-Mg-Request-UUID
X-CDN-Forward
Backend
X-WP-CF-Super-Cache
X-ECache
X-WP-CF-Super-Cache-Cache-Control
X-Cache-Control
X-Cache-Age
X-Tec-Api-Version
X-Tec-Api-Origin
X-Tec-Api-Root
Countrycode
X-DynaTrace
X-Httpd
X-Servername
Refresh
Xet-Cookie
Accept-Language
X-Drupal-Cache-Tags
X-Erf-Web-Scheduler
Url
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-XRDS-LOCATION
X-DynaTrace-JS-Agent
X-Nginx-Cache
X-HTML-Minification-Powered-By
X-Generated-By
X-Template
X-Mode
CF-IPCountry
X-Device-Type
X-Content-Powered-By
X-NYM-Debug-Backend
X-Source
Xserver
GEO-INFO
X-Storage
Webserver
Filters
Load-Balancing
X-Urbn-Context-Path
X-Rn-Rsrv
X-GeoCountry
Locale
Meta-Geo
X-Urbn-Site-Id
X-JoinUs
X-GeoCode
Version
X-Rewrite-Enabled
X-LAGOON
X-ServerID
X-UPSTREAM-Address
X-Content-Age
X-SaId
S-Rt
X-Cache-Action
X-Cluster-Node
Onion-Location
X-Container-Uri
OT-Force-Account-Verify
X-Director
X-Cache-Hit
Cross-Origin-Window-Policy
X-Tncms
X-Loop
X-Tumblr-Pixel-2
X-Git-Commit
X-Say-Cacheable
X-Say-TTL
X-Tumblr-Pixel-3
X-Soup
X-Varnish-Cache-Hits
X-SayCDN-TTL
X-CCDN-CacheTTL
X-Detected-As
X-Hcs-Proxy-Type
X-Varnish-Hostname
Web-Mar-Node
X-Ms-Version
X-Cache-Server
X-CCDN-Origin-Time
X-Ms-Request-Id
X-Sql-Duration-Ms
X-Sql-Count
X-Forwarded-Host
X-PHP-Host
X-Routing-Service
X-R9-Blue-Green-Version
DB-Nickname
X-RCS-CacheZone
Azure-Version
Azure-SlotName
X-Zipkin-Id
Azure-RegionName
X-URL
X-Proxied
Azure-SiteName
X-Extlb
X-VCT
X-RM-Cache-TTL
X-Lambda-Id
Mn-Server-Ip
Node
X-Labrador-Cache-Channel
X-VC-Cache
X-Cache-Operation
X-Served-From
Azure-InstanceId
X-Tb
X-Adobe-Source
X-Proxy-Build
TWC-Connection-Speed
Selected-Fe
TWC-Privacy
X-Timing-Wait
X-Skip-Cache
X-Uri
X-Format
X-Logging-Id
X-FB-TRIP-ID
Webcakes-App-Version
Webcakes-App-Name
X-Proto
TWC-GeoIP-Country
TWC-GeoIP-LatLong
TWC-Locale-Group
X-Generation-Time
X-Origin-Hint
TWC-Device-Class
Webcakes-Region
X-MCACHE
Property-Id
Fastcgi-Useragent
X-TimeS
X-Fetched-On
X-Endurance-Cache-Level
X-Debug
X-B3-SpanId
X-Tt-Logid
X-XRDS-Location
X-NGENIX-Cache
X-Redis-Cache
Uber-Trace-Id
Source
X-Zen-Fury
X-LSADC-Cache
X-Sucuri-Cache
X-Sucuri-ID
X-FTR-Request-ID
X-Ua
CDN-RequestId
X-S
X-Drupal-Cache-Contexts
X-Origin-CC
X-Ratelimit-Reset
Section-Origin-Responded
Section-Io-Id
X-Oracle-Dms-Ecid
Section-Io-Origin-Status
X-Oracle-Dms-Rid
Section-Io-Origin-Time-Seconds
X-Origin-TTL
X-Pass-Why
NGB
X-MP-GENERATED-AT
X-Real-IP
X-Akamai-Transformed
X-Srv
X-Origin-Date
Upgrade-Insecure-Requests
X-Cache-Expired-At
X-Varnish-Hits
Liferay-Portal
Fastly-Drupal-HTML
X-Handled-By
X-Upgrade-Enabled
X-Newrelic-Synthetics
X-CACHE-AGE
X-Reqid
Apigw-Requestid
X-Cms-Context
X-Optimistic-Header
X-Xfnlog-Site
ServedBy
X-Restarts
Ms-Operation-Id
X-Hl-Ver
X-Cache-TTL-Remaining
MS-CV
X-No-Session
X-RTag
X-Cache-Host
CDN-Cache
WP-Super-Cache
CDN-RequestPullCode
X-CSRF-Token
CDN-RequestCountryCode
CDN-PullZone
X-Cache-Type
X-BYPASS-REASON
CDN-CachedAt
CDN-EdgeStorageId
X-Parent-Response-Time
X-ProxyCache-Status
CDN-RequestPullSuccess
X-GEO
X-Node-Name
CDN-Uid
X-ProxyCache-Key
X-UA-Device-Type
X-AWS-Id
X-Cluster
X-LJ-Flow-ID
X-IPLB-Request-ID
X-Via-JSL
X-Pubstack
X-AB
X-Varnish-Ttl
X-IPLB-Instance
X-VWS-Id
X-Tx-Id
X-Fastly-Request-Id
X-Debug-Cache-Fetch
X-Micro-Cache
X-Application
X-Cache-NE
X-CacheTTL
X-CF-Lambda-Fn
X-SRCache-Key
Candidate-Md5Url
X-Slack-Shared-Secret-Outcome
X-Rojux
Canary
X-CF-Lambda-Version
X-App
X-Request-Host
X-Csrf-Jwt
X-D
DCR-Processing-Time-Ms
X-Conf
X-CGP
Sslversion
DCR-Decision-By
X-Aed
X-Vtex-Remote-Cache
X-A
N-Cache
Ngx.Var.Host
Web-Mar-Region
Odigeo-Trace-Id
Meta-Geo-Continent
X-A-Ccd
Magicmarker
X-Debug-Cache-Store
Xc-Version
MD5-Digest
X-A-Dam
X-Bc-Bl
Cache-Provider
Server-Host
X-BCube-Filmed-By
T-Server
Surrogated-Key
X-Bl-Debug
Rendered-Blocks
Redirect-Candidate
W
X-SD-PageType
Vix-Hermes-Req-Id
X-ScT
X-A-Dcw
X-Worker
Ha-Gx-Prefs
X-S-Cookie
X-Viewer-Country
HA-Ipaddr
X-Ec-GeoHdr
X-Ec-Fail
X-Slack-Backend
X-Vdms-Version
Fastly-SSL
X-Destination
X-Developer
X-Vdms-Path
X-Dispatcher-Number
X-FC-Vary-Parameters
Host-ID
X-B-Cookie
X-Eu-Site
L5d-Success-Class
Lang
X-A-Dgt
X-Fastly-Backend
X-A-Wwc
X-External-Request-Id
X-Server-W
BehaviorPad-Version
X-Proxy-Cache-Status
X-TraceId
X-Geo-Region
X-Cache-Status-Check
Cache-Name
X-BBC-Edge-Cache-Status
X-Mly-Id
X-Refresh
Mail-Subject
Origin
X-RateLimit-Limit-Second
L
X-Accel-Expires-Debug
X-Accel-Buffering
Origin-Agent-Cluster
We-Hiring
Req-Svc-Chain
X-Policy
True-Client-Country-4JS
VNS-Age
VNS-Cache
Gh-Request-Id
X-RateLimit-Remaining-Second
CPC-Cache
Datacenter
CPC-Age
Cmstype
X-App-Name
Cmsid
X-Alternate-Cache-Key
Environment
Gannett-Cam-Experience-Id
X-Bip
Fastly-GeoIP-CountryCode
Fastly-Backend-Name
X-Platform
X-Owner
X-Up
X-Org
X-VG-TLSProxy
X-VG-WebCache
X-Ec-Custom-Error
X-Varnishpool
X-Nitro-Cache
X-Nananana
X-Orig-Expires
X-Date
X-Irp-Debug
X-Epic-Correlation-Id
X-Gdpr
X-Nyt-Route
X-NodeID
X-Node-Id
X-Forwarded-Path
X-Wix-Viewer-Type
X-Wikidot-Static-Cache
X-Datadome
X-We-Are-Hiring
X-Old-Content-Length
X-Wikidot-Backend
X-Core-Value
X-Var-Ttl
X-Cache-Bucket
X-Hash
X-Cache-Debug
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Shopify-Stage
X-ShopId
X-Origin-Time
X-Server-IP
X-ShardId
X-Shop-Environment
X-Generated-On
X-Storefront-Renderer-Rendered
X-Mvc-Supplant-Cachable
X-Tenant
X-Thanos
X-GeoIP-Region-Code
X-GeoIP-Country-Code
X-Level-Front-Cache
X-Cache-Info
X-Cdn-Diag
X-PAYTM-SRV-ID
X-Clientip
User-Cache-Control
X-TIME
X-Hnp-Log
X-Nginx-Cache-Key
X-Instance-Name
TDXMobile
X-Loc
X-Mid
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
X-Mvc-Supplant-OutputCached
Thinkindot-Control
X-Human
X-Esi-Check
X-CMSURLCustom
X-Origin
X-Core-Mission
X-Clara-WADP
X-Cdn-Origin
X-Auto-Login
X-Cache-Id
X-DefElseHash
X-DefHash
X-From
X-Gen-Mode
X-Forwarded-Site
X-Fmm-Version
X-DPWN-IS-SECURE
X-Block-Status
X-Gzip
Apple-News-Services-Handled
X-Sn-Servicetimems
X-S-Maxage
Adler-Geo
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-Pool
X-Test
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
Country-Code
Esi-Enabled
Cf-Device-Type
X-Request-Time
Apple-News-Services-Request-Url
CDCHOST
X-Variation
X-Varnish-CookieHashed-On
AKAMAI
AMP-Access-Control-Allow-Source-Origin
X-ApacheServer
X-Dispatcher-Server
X-PERF
X-Geo-Header
X-WADP-Cache
X-Correlation-ID
X-Varnish-Remaining-TTL
X-Varnish-CookieINHashed-On
X-AIR-PT
X-Vmg-Version
X-WA-Info
X-VServer
Expect-Staple
X-Thinkindot-L3
Sever-Int
Release
Server-Hostname
Machine
Producers
Platform
Is-Eu
NM-Fastcgi-Cache
X-Qloud-Router
Server-Ext
Content-Secure-Policy
X-ID
X-Access
Pics-Label
X-Device-Os
Server-Info
X-INCAP-ABP
X-Via-Fastly
X-LB-NoCache
X-Op-Id-All
X-NCache
X-Cdn-Srv
X-GeoIP
CloudFront-Viewer-Country
X-Vgn-Hpd-Reason
Wxu-Next-Hostname
X-Cache-Enabled
X-Section
DSUID
X-Akamai-Device-Characteristics
Wxu-Next-Commit
Wxu-Next-Region
X-Origin-Response-Time
X-Dc
X-Vcl-Version
X-B3-Spanid
Server-ID
C-Via
X-Amz-Meta-Cb-Modifiedtime
Ssr
X-Browser-Name
X-Tcp-Rtt
NGX
X-Is-Tablet
X-Is-Supported-Browser
X-Is-Desktop
X-Is-Mobile
X-Varnish-Beresp-Ttl
X-API-Version
X-Accel-Version
X-Varnish-Beresp-Grace
X-Buckets
X-CACHE-GROUP
IsBot
X-SIPLIST1
X-Presslabs-Stats
X-HA-Backend
X-JWT-State
Memcached
X-Has-Esi
X-Is-Gdpr
Cdn-Requestid
X-Zone
X-Platform-Router
Time
YJS-ID
Sid
X-Platform-Processor
X-Platform-Cluster
Hostname
Memory
Location
Origin-CC
X-Wp-Cf-Super-Cache-Active
Cache-Hits
X-Scale
Origin-EX
X-Cached-By
CF-Ctrl
X-B3-Parentspanid
X-Air-Source
X-Air-Hostname
X-WP-CF-Super-Cache-Active
X-Air-Trace-Id
X-Origin-Cache-Key
X-TA-CDN-Provider
X-TIM-N
X-Tb-Optimization-Total-Bytes-Saved
X-ZONE
X-PHP-Backend
Resin-Trace
X-Hyper-Cache
X-Fpc
X-Backend-Instance
X-Internal-Host
X-Frame-Option
X-Cs
X-DC
X-Azure-Ref-OriginShield
X-NGINX-Cache
X-Service
X-VC
X-FTR-Balancer
X-FTR-Cache-Status
X-FTR-Backend-Server
X-FTR-Expires
X-FTR-Backend
X-LiteSpeed-Cache-Control
X-Country-Code-Real
X-Webstats-RespID
X-Site-Version
X-VCache
GeoIP-Latitude
X-NewRelic-App-Data
Epwk-X-Cache
X-DataCenter
Uri
True-Client-Ip
X-Locale
Cache-Host
X-Nitro-Rev
X-Origin-Expires
GeoIp-Country-Code
X-Nitro-Cache-From
X-Microcachable
LB
X-SRV
GeoIP-Country-Code
X-Info
XM
Cdn-Request-Time
Cdn-Host
X-VarnishDD-TTL
PFcat
X-Edge-Server
X-Cache-Ttl
X-NMSegId
X-HN
Req-ID
XServer
WebServer
X-Web-Node
X-Datacenter
X-Geo
X-Pod-Name
Cdn
X-CSRF-TOKEN
X-HostName
NtCoent-Length
User-Agent
M-TraceId
X-Ad-Defer-Variation
True-Client-IP
WZWS-RAY
Tcn
X-Pad
X-CS
Fastly-Drupal-Html
X-Via-SSL
X-Via-Edge
X-Vercel-Cache
X-M-Reqid
X-M-Log
X-Github-Request-Id
Edge-Copy-Time
Cluster
Srvid
Locid
A
X-Via-CDN
X-Request-Start
X-FL-EDGE
Pramga
X-Ad-Load-Variation
X-Vercel-Id
SID
X-FL-QIT-DEBUG
X-Request-URI
X-FPC
X-Qnm-Cache
X-Varnish-Beresp-Status
X-Scope-Id
Content-Style-Type
Cf-Ipcountry
Content-Script-Type
X-MSEdge-Features
X-MSEdge-Flight
HostName
X-CLOUD-TRACE-CONTEXT
Cache-Tv-Group
Edge-Cache
X-Moov-T
X-LiteSpeed-Tag
X-Moov-Xdn-Version
X-Contensis-Viewer-Groups
X-Cache-ASPX
X-ATG-Version
X-FireWall-Port
X-Varnish-Authentication
X-Shield-Cache-Expires
X-Api-Version
X-WP-CF-Super-Cache-Cookies-Bypass
CountryCode
X-APP-VERSION
X-Cdn-Request-ID
X-TRACE-ID
Cdncip
X-NWS-UUID-VERIFY
X-Amz-Meta-Opti
X-Cache-Date
Cache-Key
X-TH-Server
X-AK-Request-ID
Cdnsip
Path
X-Esi
X-B3-Trace-ID
X-SB
X-Branch-Name
X-LB-ID
X-Cache-FS-Status
X-Aicache-OS
X-V-Cache
X-Req
X-Via-Popv
X-Via-Poph
X-Via-Popn
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-VCL-Version
X-Acquia-Purge-Cdn-Unconfigured
Yak-Timeinfo
XkeyRZ
Tube-Return
X-Proxy-CacheRZ
X-Vary
Tube-Get-Contents
Click-Count-Action-Start
X-Men
Click-Count-Error
Tube-Got-Eval
Tube-Got-Results
V-Age
X-Servedbyhost
X-Nc
X-Air-Pt
X-Wa
CDN
X-CACHE-KEY
X-UA
Lb
Geoip-Latitude
X-Wp-Cf-Super-Cache-Cache-Control
X-HS-Content-Campaign-Id
Proxy-Connection
X-Wp-Cf-Super-Cache
State
X-Planisys-CDN-Cache
Ngx-Var-Key
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Platform-Server
X-Tim-N
Srv
Wpo-Cache-Message
X-TT-LOGID
MIME-Version
On-Server
X-Render-Time
X-Cdn-Forward
X-Akamai-Pragma-Client-IP
Wpo-Cache-Status
X-Fastly-Backend-Reqs
X-Rebelmouse-Surrogate-Control
X-Lb-Cache
X-Rebelmouse-Cache-Control
My-App
X-Dw-Trace-Id
X-User
X-Fastly-Cache
CF-Cached-On
X-Ha-Backend
X-Acquia-Application-UUID
X-Acquia-Purge-Tags
X-Acquia-Site
X-Vgn-Hpd-Ssi
X-Generated-In
X-Upstream-Ct
X-Upstream-Ht
X-Vgn-Hpd-Cached
Server-Id
X-Acquia-Application-Trace
X-Release
X-Vgn-Hpd-Variations-Key
Priority
X-Rocket-Build-Number
Ohc-File-Size
X-Cache-Remote
Ohc-Cache-HIT
X-Sigma-Backend
X-Sigma
X-Traceid
X-HS-Status
X-EC-Lua
X-Lb-Nocache
X-Varnish-Director
X-Via-Ucdn
X-CUA
X-Fastly-Country-Code
PICS-Label
X-Iplb-Request-Id
X-Provided-By
X-Iplb-Instance
X-TX-ID
Yjs-Id
Mime-Version
X-WA
Warning
X-CDN-Cache-Status
X-NC
CACHE-MISS-TO-ORIGIN
X-Litespeed-Cache-Control
X-CF-Cache-Header-Vary
X-Udemy-Cache-App-Namespace
X-CF-Cache-Header-Cache-Control
X-RAMCache
Cneonction
X-Miniprofiler-Ids
Log-Origin
Ngx
X-Snapshot-Date
X-Fastly-Cache-Hits
Cache
Vha6-Origin
X-ElasticPress-Query
X-Cached-Since
Inserted-Into-Cache-At