Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
X-Powered-By
Pragma
CF-RAY
X-XSS-Protection
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
Alt-Svc
X-Xss-Protection
P3P
X-Cache-Hits
X-UA-Compatible
X-Served-By
CF-Ray
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
Access-Control-Allow-Credentials
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
X-Drupal-Cache
X-Cache-Status
X-Generator
X-Check
X-Cacheable
X-FRAME-OPTIONS
X-Envoy-Upstream-Service-Time
Timing-Allow-Origin
X-Iinfo
X-DNS-Prefetch-Control
X-Dns-Prefetch-Control
X-Drupal-Dynamic-Cache
Nel
Server-Timing
Feature-Policy
X-Content-Security-Policy
Access-Control-Expose-Headers
X-XSS-PROTECTION
Content-Encoding
X-CDN
Status
X-Request-ID
Upgrade
X-AspNetMvc-Version
Access-Control-Max-Age
X-Amz-Request-Id
X-Via
X-Amz-Id-2
Request-Context
X-Backend
X-Turbo-Charged-By
X-Cache-Group
X-AH-Environment
X-Robots-Tag
Cf-Edge-Cache
Keep-Alive
Host-Header
X-Hacker
X-Vhost
X-UA-Device
X-Proxy-Cache
X-Server
X-Rq
Allow
X-Server-Powered-By
X-Ws-Request-Id
X-Age
X-Dispatcher
EagleId
X-Varnish-Cache
X-Amz-Version-Id
P3p
X-LiteSpeed-Cache
X-Ua-Compatible
Grace
Cf-Apo-Via
Cf-Railgun
X-Pantheon-Styx-Hostname
X-OneAgent-JS-Injection
X-Styx-Req-Id
X-Page-Speed
EagleEye-TraceId
X-Device
X-Swift-CacheTime
X-Swift-SaveTime
X-Aws-Lambda-Call-Status
Ali-Swift-Global-Savetime
X-Pingback
X-Host
X-Node
X-Cache-Lookup
X-CST
X-WebKit-CSP
X-Backend-Server
Accept-CH
Surrogate-Control
X-Server-Id
Accept-CH-Lifetime
Permissions-Policy
X-Readtime
X-Nginx-Upstream-Cache-Status
X-Nginx-Cache-Status
X-Akam-SW-Version
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
Request-Id
X-Application-Context
X-Ruxit-JS-Agent
X-Content-Security-Policy-Report-Only
X-Cloud-Trace-Context
Xkey
X-Response-Time
X-HW
X-Trace
X-Edge
Content-Location
X-Clacks-Overhead
X-Mod-Pagespeed
Rating
X-Url
Accept-Ch
X-ESI
X-Midtier
X-Amz-Server-Side-Encryption
X-Aspnetmvc-Version
Cache-Tag
X-Mcache
X-Country
X-Powered-By-Plesk
X-MS-InvokeApp
X-ECACHE
X-Rack-Cache
X-D2id
X-Use-Magma
X-Kinja-Server
X-Cdn-Fetch
X-Kinja
X-Exp-Id
X-GoogleNews-Bot
X-Kinja-Build
X-Kinja-Revision
X-Exp-Variant
X-Vcap-Request-Id
X-Element-Page-Cache
Verso
Service-Worker-Allowed
X-Upstream
Edge-Control
X-Country-Code
X-Aspnet-Version
RTSS
X-Vname
X-PC
X-Ac
X-TtlSet
Origin-Trial
X-Goog-Hash
X-VARITI-CCR
X-Navigation-Version
X-Kinja-CCPA
X-Abt-Application-Version
X-Cache-TTL
X-Browser-Type
Fastly-Restarts
X-Oneagent-Js-Injection
Accept-Ch-Lifetime
X-Litespeed-Cache
X-Amz-Rid
X-NWS-LOG-UUID
X-WebKit-CSP-Report-Only
X-GitHub-Request-Id
X-Webkit-CSP
X-Cached
Cross-Origin-Opener-Policy
X-Varnish-TTL
X-Server-Name
Pagespeed
X-Middleton-Display
X-Sol
Display
X-Amzn-Trace-Id
X-Dw-Request-Base-Id
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-SharePointHealthScore
SPRequestGuid
X-Times
X-Ruxit-Js-Agent
Pinterest-Version
Pinterest-Generated-By
X-Pinterest-Rid
X-Ttl
SPIisLatency
SPRequestDuration
X-Kraken-Loop-Name
X-Erf-Bev-Bev-Is-Generated
X-Server-Lifecycle-Phase
X-Instrumentation
X-Erf-Bev-Bev
X-Content-Type
AR-ATIME
AR-PoweredBy
X-Cache-Key
AR-SID
AR-Request-ID
X-FastCGI-Cache
X-Powered-CMS
X-Client-IP
Arr-Disable-Session-Affinity
X-Mg-S
Response
X-B3-Traceid
X-Middleton-Response
X-Version
X-Ser
X-Cnection
X-Server-ID
X-HP-Webp
Nginx-Cache
X-HP-Trace-Id
X-Jurisdiction
X-Accel-Expires
Cache-Tags
AR-CACHE
X-T
X-Fastly-Request-ID
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-B3-TraceId
Cache-Status
X-NF-Request-ID
Edge-Cache-Tag
X-Hits
X-MSEdge-Ref
Front-End-Https
X-Px
Public-Key-Pins
X-RateLimit-Remaining
X-Recruiting
S
X-Daa-Tunnel
Payment
X-Shield-Request-Id
X-Frontend
X-LLID
X-Request-Received
X-Ua-Browser
X-Request-Processing-Time
Server-Node
X-GUploader-UploadID
X-Goog-Metageneration
X-B3-TraceId-Primal
Mrf-Cache-Status
X-RateLimit-Limit
MRF-Tech
Content-MD5
MicrosoftSharePointTeamServices
X-Amzn-RequestId
X-DIS-Request-ID
X-Amz-Apigw-Id
X-Content-Digest
Access-Control-Request-Method
X-Webkit-CSP-Report-Only
X-TTL
TP-Cache
X-Protected-By
Realpath
X-Forwarded-For
X-Request-Handler-Origin-Region
X-Microsite
X-PressLabs-Stats
X-Distributor
X-FB-Debug
X-Ratelimit-Remaining
Access-Control-Allow-Method
Fastcgi-Cache
X-Rid
X-HS-Cache-Config
X-HS-Combine-CSS
X-HS-Content-Id
X-Cluster-Name
X-Page-Id
X-LB-Cache
X-HS-Hub-Id
Accept-Charset
X-Goog-Stored-Content-Encoding
X-Ua-Device
X-Goog-Generation
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
Count-Hit
X-Hostname
X-Geo-Country
X-Id
X-B3-Sampled
TP-L2-Cache
X-Kinsta-Cache
X-Edge-Location-Klb
Cross-Origin-Resource-Policy
X-Xrds-Location
X-Seen-By
X-Ezoic-Cdn
X-Ratelimit-Limit
X-Erf-Stays-Pdp-Viaduct-Migration-Web
X-App-Server
Cleartype
TCN
X-Correlation-Id
X-Fastcgi-Cache
X-Varnish-Backend
X-Logged-In
X-Hosted-By
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Content-Options
Referer-Policy
X-Mobile
DC
X-Git-Hash
X-Newrelic-App-Data
X-Contextid
X-Fb-Rlafr
Retry-After
X-Origin-Cache
X-Revision
X-Grace
X-Aspnet-Duration-Ms
X-Amz-Replication-Status
Surrogate-Key
X-Is-Crawler
X-Flags
X-Providence-Cookie
X-Request-Guid
X-Route-Name
X-Forwarded-Proto
X-F-Cache
X-App-Environment
X-TT
X-Debug-Info
Frame-Options
X-Varnish-Grace
X-IPS-LoggedIn
X-Amz-Meta-S3cmd-Attrs
X-RateLimit-Reset
X-Azure-Ref
X-Envoy-Decorator-Operation
X-Magnolia-Registration
Section-Io-Cache
MS-Author-Via
X-Wix-Request-Id
X-Proxy-Cache-Info
X-COUNTRY
X-Whom
X-Webkit-Csp
Healthy
Charset
X-Www-Served-By
X-Akamai-Edgescape
Viewport
X-ECache
X-Language
Alternate-Protocol
Filterid
WPO-Cache-Status
X-Backend-Name
WPO-Cache-Message
X-AppVersion
X-Origin-Server
X-Trace-Id
X-App-Version
X-Az
X-Activity-Id
Server-Name
X-Datadog-Parent-Id
X-Datadog-Trace-Id
Paypal-Debug-Id
X-Varnish-Server
Amp-Access-Control-Allow-Source-Origin
X-Datadog-Sampling-Priority
X-Kong-Proxy-Latency
Host
X-Kong-Upstream-Latency
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Response-Served-From
X-Cache-Rule
X-EdgeConnect-Cache-Status
X-Original-Request-Id
X-B
SD-X-WS
X-Http-Reason
Front
X-Cache-Grace
X-User-Agent
X-UUID
X-RemovedCookies
X-Akamai-Request-ID2
X-Rule
X-ProcessESI
X-Edge-Location
X-DataDome
X-Instance
X-Nf-Request-Id
X-N
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Unique-Id
X-Cacheable-TTL
X-Varnish-Age
X-Tumblr-Pixel
From-Origin
X-Jobs
X-ARC
Country
X-Region
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-Rocket-Nginx-Serving-Static
X-Tumblr-User
Protected
X-Vcache
X-Adobe-Content
Fastly-SIE
Akamai-GRN
X-Adobe-Loc
X-Environment-Context
X-Page-View
X-L-Path
X-Framework
Fastly-SWR
X-Load-Cache
X-Status
X-Time
X-FW-Dynamic
X-Signature
X-Datadog-Sampled
SRV
X-Mg-Request-UUID
X-B-Cache
X-Cache-Time
X-Rendered-As
X-G
X-Type
X-Is-Bot
X-FW-Version
X-FW-Type
X-FW-Serve
X-FW-Server
X-FW-Static
X-FW-Hash
X-Proxy
X-Amzn-Remapped-Content-Length
Content-Disposition
X-Debug-IsConnected
X-Debug-IsPreview
ServerID
Access-Control-Request-Headers
X-Tec-Api-Root
X-Tec-Api-Origin
X-Client-Ip
X-Tec-Api-Version
Backend
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
X-Cache-Control
X-Erf-Web-Scheduler
Refresh
X-CDN-Forward
X-Cache-Age
X-XRDS-LOCATION
X-Servername
Countrycode
X-DynaTrace
Xet-Cookie
Accept-Language
X-Httpd
Url
X-Drupal-Cache-Tags
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-DynaTrace-JS-Agent
X-Template
X-Generated-By
X-Nginx-Cache
X-Device-Type
X-Mode
Webserver
X-NYM-Debug-Backend
CF-IPCountry
X-HTML-Minification-Powered-By
X-Content-Powered-By
X-Storage
X-Source
X-Hcs-Proxy-Type
X-Cache-Hit
X-CCDN-CacheTTL
GEO-INFO
X-CCDN-Origin-Time
X-SayCDN-TTL
X-GeoCode
X-GeoCountry
X-Content-Age
Filters
Load-Balancing
Locale
Meta-Geo
S-Rt
X-ServerID
X-Director
X-Cache-Operation
X-Cache-Action
X-Say-TTL
X-Rn-Rsrv
X-Urbn-Context-Path
X-Rewrite-Enabled
X-JoinUs
X-URL
X-Urbn-Site-Id
X-Say-Cacheable
X-LAGOON
OT-Force-Account-Verify
X-UPSTREAM-Address
X-Loop
X-Tncms
X-SaId
Cross-Origin-Window-Policy
X-Varnish-Cache-Hits
X-Git-Commit
Xserver
X-Cluster-Node
X-Container-Uri
X-Forwarded-Host
X-Soup
Version
X-Tumblr-Pixel-3
Onion-Location
X-Tumblr-Pixel-2
X-Varnish-Hostname
X-MCACHE
X-Served-From
Azure-SlotName
Azure-Version
Azure-SiteName
X-Cache-Server
Azure-RegionName
Web-Mar-Node
X-Ms-Request-Id
X-VC-Cache
X-Tt-Logid
X-VCT
Azure-InstanceId
X-PHP-Host
X-Adobe-Source
X-Ms-Version
X-Tb
X-Skip-Cache
X-RM-Cache-TTL
X-Labrador-Cache-Channel
X-Lambda-Id
DB-Nickname
X-Proxied
X-Logging-Id
X-Routing-Service
X-Zipkin-Id
X-FB-TRIP-ID
X-Sql-Count
Node
X-Detected-As
X-Extlb
X-R9-Blue-Green-Version
X-RCS-CacheZone
X-Redis-Cache
X-Sql-Duration-Ms
X-Proxy-Build
Property-Id
X-Proto
Selected-Fe
TWC-Locale-Group
Webcakes-App-Version
X-Fetched-On
Webcakes-Region
X-Origin-Hint
X-Timing-Wait
X-Format
Webcakes-App-Name
TWC-Connection-Speed
TWC-Device-Class
TWC-GeoIP-Country
TWC-GeoIP-LatLong
X-Generation-Time
TWC-Privacy
Fastcgi-Useragent
Mn-Server-Ip
X-FTR-Request-ID
X-Debug
X-Endurance-Cache-Level
X-Uri
Uber-Trace-Id
X-LSADC-Cache
Source
X-Zen-Fury
X-NGENIX-Cache
CDN-RequestId
X-Sucuri-Cache
X-XRDS-Location
X-Sucuri-ID
X-Ua
X-B3-SpanId
X-Varnish-Ttl
X-S
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
Section-Origin-Responded
Section-Io-Id
X-TimeS
X-Origin-TTL
X-Origin-CC
X-Drupal-Cache-Contexts
X-Akamai-Transformed
X-MP-GENERATED-AT
X-Pass-Why
X-Origin-Date
X-Varnish-Hits
Upgrade-Insecure-Requests
NGB
X-Real-IP
X-Srv
X-Cache-Expired-At
X-Handled-By
X-Ratelimit-Reset
X-CACHE-AGE
X-Newrelic-Synthetics
Liferay-Portal
Fastly-Drupal-HTML
X-No-Session
X-Upgrade-Enabled
X-GEO
X-Reqid
ServedBy
X-Xfnlog-Site
X-Cms-Context
Apigw-Requestid
X-Optimistic-Header
X-Restarts
X-Cache-Host
X-AB
X-Hl-Ver
X-ProxyCache-Key
X-RTag
X-ProxyCache-Status
X-Tx-Id
X-Fastly-Request-Id
CDN-Cache
CDN-RequestPullSuccess
CDN-RequestPullCode
CDN-Uid
X-Cache-Type
X-BYPASS-REASON
CDN-RequestCountryCode
WP-Super-Cache
MS-CV
X-Oracle-Dms-Ecid
CDN-CachedAt
CDN-EdgeStorageId
CDN-PullZone
X-Oracle-Dms-Rid
Ms-Operation-Id
X-Cache-TTL-Remaining
X-Node-Name
X-CSRF-Token
X-Parent-Response-Time
X-TraceId
X-Geo-Region
X-Via-JSL
X-Pubstack
X-AWS-Id
X-IPLB-Request-ID
X-LJ-Flow-ID
X-VWS-Id
X-IPLB-Instance
X-Cluster
X-UA-Device-Type
Gannett-Cam-Experience-Id
Fastly-SSL
Ha-Gx-Prefs
X-Micro-Cache
X-Debug-Cache-Store
X-Debug-Cache-Fetch
L
X-Csrf-Jwt
Magicmarker
MD5-Digest
Lang
L5d-Success-Class
Host-ID
X-D
X-Destination
HA-Ipaddr
X-Dispatcher-Number
X-Eu-Site
BehaviorPad-Version
X-Epic-Correlation-Id
X-External-Request-Id
X-Fastly-Backend
X-Worker
Cache-Provider
X-FC-Vary-Parameters
X-We-Are-Hiring
X-Ec-GeoHdr
X-Developer
DCR-Decision-By
X-Vtex-Remote-Cache
X-Viewer-Country
Candidate-Md5Url
X-Ec-Fail
X-Ec-Custom-Error
Canary
DCR-Processing-Time-Ms
X-PAYTM-SRV-ID
Vix-Hermes-Req-Id
W
Web-Mar-Region
X-Application
X-B-Cookie
True-Client-Country-4JS
X-ScT
X-SD-PageType
T-Server
X-Bc-Bl
X-A
X-A-Ccd
X-A-Wwc
X-App
X-SRCache-Key
X-Aed
X-A-Dgt
X-A-Dcw
X-A-Dam
X-Slack-Backend
X-Slack-Shared-Secret-Outcome
Surrogated-Key
X-S-Cookie
Odigeo-Trace-Id
Origin-Agent-Cluster
X-CGP
X-CF-Lambda-Version
X-Vdms-Path
X-Vdms-Version
Meta-Geo-Continent
Xc-Version
N-Cache
Ngx.Var.Host
X-CF-Lambda-Fn
Redirect-Candidate
X-Request-Host
X-Bl-Debug
X-Rojux
X-BCube-Filmed-By
Sslversion
X-Cache-NE
Rendered-Blocks
X-CacheTTL
Server-Host
X-Conf
Cache-Name
X-B3-Spanid
X-TIME
X-Cache-Status-Check
Producers
X-Variation
Platform
X-Varnish-CookieHashed-On
X-Cdn-Origin
Release
X-Var-Ttl
X-Refresh
X-Cache-Info
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
Req-Svc-Chain
X-Cdn-Diag
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
X-Core-Mission
X-VG-WebCache
X-Vmg-Version
Mail-Subject
X-Core-Value
X-Origin-Time
X-VG-TLSProxy
X-PERF
Origin
X-Varnishpool
X-Policy
X-Clientip
X-CMSURLCustom
X-Platform
X-Cache-Debug
X-Up
X-Shopify-Stage
X-Sn-Servicetimems
X-ShopId
X-App-Name
X-SVT-ORM-VERSION
X-Thanos
X-SVT-ORM-RULES
X-Sorting-Hat-PodId
X-Correlation-ID
X-Alternate-Cache-Key
X-ApacheServer
X-Sorting-Hat-ShopId
X-Accel-Buffering
X-Accel-Expires-Debug
We-Hiring
X-Shop-Environment
TDXMobile
Thinkindot-CacheControl
X-Server-IP
X-S-Maxage
X-Org
X-Request-Time
Thinkindot-CacheControl-Type
Thinkindot-Control
VNS-Age
VNS-Cache
X-Tenant
X-ShardId
X-Thinkindot-L3
X-BBC-Edge-Cache-Status
X-Cache-Bucket
X-Orig-Expires
X-Pool
X-Mid
X-DPWN-IS-SECURE
X-GeoIP-Region-Code
X-Loc
X-Mly-Id
X-Dispatcher-Server
Cmsid
CloudFront-Viewer-Country
X-Wix-Viewer-Type
X-Mvc-Supplant-Cachable
X-Irp-Debug
X-Wikidot-Backend
X-Forwarded-Path
X-Geo-Header
X-Storefront-Renderer-Rendered
X-Gdpr
X-Wikidot-Static-Cache
X-AIR-PT
X-Qloud-Router
X-GeoIP-Country-Code
X-Human
AKAMAI
Adler-Geo
CPC-Age
Cmstype
X-VServer
Gh-Request-Id
X-Node-Id
X-Nitro-Cache
CPC-Cache
X-NodeID
X-Nyt-Route
Is-Eu
X-Bip
X-Date
X-Old-Content-Length
Fastly-GeoIP-CountryCode
X-Generated-On
X-Nananana
X-DefHash
X-Owner
X-Hash
Datacenter
Fastly-Backend-Name
X-Level-Front-Cache
Environment
X-DefElseHash
Expect-Staple
X-Proxy-Cache-Status
X-Server-W
X-From
X-Gzip
X-GeoIP
Machine
X-Cache-Id
X-Mvc-Supplant-OutputCached
X-WA-Info
X-Device-Os
X-Clara-WADP
X-NCache
X-Origin
X-Origin-Response-Time
X-Op-Id-All
X-WADP-Cache
X-Test
X-Fmm-Version
X-INCAP-ABP
X-Instance-Name
X-Akamai-Device-Characteristics
X-Esi-Check
X-Forwarded-Site
X-Auto-Login
Cf-Device-Type
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
DSUID
Esi-Enabled
X-Datadome
NM-Fastcgi-Cache
X-Vgn-Hpd-Reason
Apple-News-Services-Handled
Apple-News-Services-Request-Url
X-Accel-Version
User-Cache-Control
X-Dc
X-Nginx-Cache-Key
NGX
X-Gen-Mode
X-Hnp-Log
X-Cdn-Srv
X-Tcp-Rtt
Country-Code
Server-Ext
X-Is-Supported-Browser
X-Is-Desktop
X-Browser-Name
X-Is-Tablet
CDCHOST
X-Is-Mobile
X-Section
Ssr
X-Block-Status
X-Access
X-Via-Fastly
Content-Secure-Policy
Wxu-Next-Region
Wxu-Next-Hostname
Wxu-Next-Commit
X-Cache-Enabled
Sever-Int
Server-Info
Server-Hostname
X-Buckets
AMP-Access-Control-Allow-Source-Origin
Pics-Label
C-Via
X-LB-NoCache
X-Presslabs-Stats
X-Vcl-Version
X-CACHE-GROUP
X-API-Version
X-Varnish-Beresp-Grace
X-SIPLIST1
Server-ID
IsBot
X-Amz-Meta-Cb-Modifiedtime
X-Has-Esi
X-Zone
X-B3-Parentspanid
X-ID
Sid
YJS-ID
Memcached
Hostname
X-Is-Gdpr
X-JWT-State
X-HA-Backend
X-Varnish-Beresp-Ttl
X-Platform-Router
Cdn-Requestid
Memory
X-Wp-Cf-Super-Cache-Active
X-Cached-By
Time
X-Platform-Cluster
X-Platform-Processor
X-Origin-Cache-Key
X-TA-CDN-Provider
X-Scale
CF-Ctrl
X-Tb-Optimization-Total-Bytes-Saved
Origin-EX
Origin-CC
Cache-Hits
X-Frame-Option
X-WP-CF-Super-Cache-Active
X-Air-Trace-Id
X-Air-Source
X-Hyper-Cache
Location
X-Air-Hostname
X-TIM-N
X-Backend-Instance
X-Fpc
X-PHP-Backend
X-Internal-Host
X-ZONE
X-Cs
X-NGINX-Cache
X-Service
X-FTR-Expires
X-FTR-Cache-Status
X-FTR-Balancer
X-FTR-Backend-Server
X-Country-Code-Real
X-FTR-Backend
Resin-Trace
X-Webstats-RespID
Epwk-X-Cache
X-DC
X-NewRelic-App-Data
X-Azure-Ref-OriginShield
X-DataCenter
X-VC
XServer
X-Site-Version
GeoIP-Latitude
X-SRV
GeoIp-Country-Code
X-LiteSpeed-Cache-Control
X-Microcachable
X-Nitro-Cache-From
True-Client-Ip
X-Origin-Expires
Uri
X-Locale
X-Nitro-Rev
Cache-Host
LB
X-VCache
Req-ID
XM
X-Cache-Ttl
Cdn-Host
Cdn-Request-Time
X-Edge-Server
X-NMSegId
X-Info
True-Client-IP
WZWS-RAY
GeoIP-Country-Code
Cdn
X-CSRF-TOKEN
X-HN
X-Pad
NtCoent-Length
X-Ad-Load-Variation
PFcat
X-Datacenter
X-VarnishDD-TTL
X-Pod-Name
M-TraceId
X-Geo
Fastly-Drupal-Html
X-Web-Node
X-M-Log
User-Agent
X-Request-URI
X-M-Reqid
X-Vercel-Id
X-FPC
WebServer
X-Scope-Id
X-Ad-Defer-Variation
Cluster
X-Request-Start
X-Github-Request-Id
Pramga
X-Vercel-Cache
X-APP-VERSION
Cf-Ipcountry
X-Via-Edge
X-Via-SSL
Edge-Copy-Time
Content-Script-Type
X-FL-QIT-DEBUG
Content-Style-Type
X-MSEdge-Flight
SID
X-MSEdge-Features
X-FL-EDGE
A
X-Varnish-Beresp-Status
Srvid
X-Shield-Cache-Expires
X-Qnm-Cache
X-Via-CDN
Locid
X-CS
X-HostName
Tcn
X-Cache-Date
Edge-Cache
X-Cdn-Request-ID
HostName
Cache-Tv-Group
X-Api-Version
X-WP-CF-Super-Cache-Cookies-Bypass
CountryCode
X-FireWall-Port
X-ATG-Version
X-AK-Request-ID
Cdncip
Cdnsip
X-Esi
X-Contensis-Viewer-Groups
X-NWS-UUID-VERIFY
X-Moov-Xdn-Version
X-Cache-ASPX
X-Varnish-Authentication
Path
X-TH-Server
X-Moov-T
X-Amz-Meta-Opti
X-LiteSpeed-Tag
X-V-Cache
Cache-Key
X-Branch-Name
X-Cache-FS-Status
X-Aicache-OS
X-Cdn-Forward
Srv
X-VCL-Version
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-Vary
X-Proxy-CacheRZ
X-SB
Click-Count-Action-Start
X-Wa
Yak-Timeinfo
Tube-Got-Eval
X-TRACE-ID
XkeyRZ
X-Men
On-Server
X-Via-Popv
Tube-Got-Results
X-LB-ID
X-B3-Trace-ID
X-Nc
X-Req
X-Servedbyhost
X-Acquia-Purge-Cdn-Unconfigured
V-Age
X-Via-Popn
Tube-Return
X-Via-Poph
Click-Count-Error
Tube-Get-Contents
Lb
X-UA
X-CACHE-KEY
CDN
X-Render-Time
Ngx-Var-Key
X-Tim-N
MIME-Version
Geoip-Latitude
Wpo-Cache-Status
Wpo-Cache-Message
X-Wp-Cf-Super-Cache
Server-Id
Proxy-Connection
X-Akamai-Pragma-Client-IP
X-Wp-Cf-Super-Cache-Cache-Control
X-Rebelmouse-Cache-Control
X-Lb-Cache
X-Rebelmouse-Surrogate-Control
X-Planisys-CDN-Cache
X-Generated-In
X-Air-Pt
X-Planisys-CDN-TTL
X-Fastly-Backend-Reqs
State
X-Platform-Server
X-Planisys-CDN-Rules
X-Ha-Backend
X-Acquia-Site
My-App
X-Lb-Nocache
PICS-Label
X-Acquia-Purge-Tags
X-Acquia-Application-UUID
X-User
Priority
X-HS-Content-Campaign-Id
X-Acquia-Application-Trace
X-TT-LOGID
X-Fastly-Cache
X-Varnish-Director
Ohc-File-Size
Ohc-Cache-HIT
X-CUA
X-Release
X-Vgn-Hpd-Cached
X-Vgn-Hpd-Variations-Key
Vha6-Origin
X-EC-Lua
X-Via-Ucdn
X-Vgn-Hpd-Ssi
CF-Cached-On
X-Dw-Trace-Id
X-Provided-By
X-Varnish-Beresp-TTL
Yjs-Id
X-Iplb-Request-Id
X-Iplb-Instance
X-Upstream-Ht
X-Upstream-Ct
X-CDN-Cache-Status
X-Fastly-Country-Code
X-Cache-Remote
Warning
X-Miniprofiler-Ids
Log-Origin
X-RAMCache
Cneonction
Ngx
CACHE-MISS-TO-ORIGIN
Inserted-Into-Cache-At
X-Sigma-Backend
X-Traceid
X-Udemy-Cache-App-Namespace
X-HS-Status
X-CF-Cache-Header-Cache-Control
X-Sigma
X-Rocket-Build-Number
X-Cached-Since
X-ElasticPress-Query
X-CF-Cache-Header-Vary
Cache
X-Fastly-Cache-Hits
X-Snapshot-Date
X-Litespeed-Cache-Control