Threat Level: green Handler on Duty: Rick Wanner

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Link
Cf-Request-Id
CF-Cache-Status
Accept-Ranges
CF-RAY
ETag
X-XSS-Protection
Pragma
Expect-CT
X-Powered-By
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
Alt-Svc
P3P
X-Served-By
X-Xss-Protection
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Adblock-Key
X-Runtime
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Cache-Status
X-Generator
X-Cacheable
Timing-Allow-Origin
X-Request-ID
P3p
X-Content-Security-Policy
X-Iinfo
Status
Feature-Policy
X-Envoy-Upstream-Service-Time
Content-Encoding
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
X-CDN
X-AspNetMvc-Version
Upgrade
X-Via
CF-Ray
Access-Control-Max-Age
X-Ws-Request-Id
Server-Timing
EagleId
Keep-Alive
X-Cache-Group
X-Turbo-Charged-By
Request-Context
X-Age
X-Proxy-Cache
X-Server-Powered-By
X-AH-Environment
X-UA-Device
X-Backend
X-Hacker
X-Robots-Tag
Report-To
X-Amz-Request-Id
X-LiteSpeed-Cache
Host-Header
X-Server
X-Amz-Id-2
Grace
X-Rq
X-Nginx-Cache-Status
X-Varnish-Cache
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-Dns-Prefetch-Control
X-WebKit-CSP
X-Page-Speed
X-Vhost
X-Amz-Version-Id
EagleEye-TraceId
X-OneAgent-JS-Injection
X-Ua-Compatible
X-Pingback
X-Dispatcher
X-Device
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Cache-Spec
NEL
X-Server-Id
X-Host
X-Backend-Server
X-Node
Cf-Railgun
X-Readtime
Accept-CH
X-Akam-SW-Version
Surrogate-Control
Request-Id
X-Response-Time
X-HW
X-Language
Xkey
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Template
Content-Location
X-Application-Context
X-Ruxit-JS-Agent
Rating
Accept-Ch-Lifetime
X-Country
X-B3-TraceId
X-Cloud-Trace-Context
X-Cache-Lookup
X-Buckets
X-Ac
Allow
X-Url
Accept-CH-Lifetime
X-Content-Type
X-Trace
X-Vname
X-PC
X-TtlSet
X-Mod-Pagespeed
Edge-Control
X-Clacks-Overhead
X-Varnish-TTL
X-ESI
Cache-Tag
X-FastCGI-Cache
Fastly-Restarts
X-Rack-Cache
X-VARITI-CCR
Service-Worker-Allowed
X-Server-Name
X-Element-Page-Cache
Verso
X-GitHub-Request-Id
X-MS-InvokeApp
X-Amz-Rid
X-Upstream
X-Vcap-Request-Id
X-Dw-Request-Base-Id
Public-Key-Pins
X-Abt-Application-Version
X-Cached
X-D2id
X-Origin-Cache
MS-Author-Via
X-Client-IP
Accept-Ch
Arr-Disable-Session-Affinity
X-Goog-Hash
X-Country-Code
X-Px
X-Powered-By-Plesk
Access-Control-Request-Method
X-Cnection
X-Version
X-Aws-Lambda-Call-Status
X-Cache-TTL
X-Instrumentation
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-NF-Request-ID
X-Navigation-Version
X-Amz-Server-Side-Encryption
RTSS
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
X-Powered-CMS
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Sol
X-Middleton-Display
Pagespeed
Display
Response
X-Middleton-Response
X-Use-Magma
X-Kinja-Server
X-Kinja-Revision
X-Exp-Variant
X-Cdn-Fetch
X-Exp-Id
X-GoogleNews-Bot
X-Kinja-Build
X-Kinja
X-LLID
X-MSEdge-Ref
X-Edge
X-Edge-Location-Klb
X-Kinsta-Cache
X-CST
Nginx-Cache
X-Shield-Request-Id
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
S
AR-Request-ID
AR-SID
AR-PoweredBy
Content-MD5
AR-ATIME
AR-CACHE
X-HP-Webp
X-Jurisdiction
X-HP-Trace-Id
X-TTL
X-T
X-Forwarded-For
X-Protected-By
X-Content-Security-Policy-Report-Only
X-Aspnetmvc-Version
TCN
X-Mg-S
X-Id
X-RateLimit-Remaining
X-Mid
X-MCACHE
Fastcgi-Cache
Realpath
Front-End-Https
X-Parallel-Accel
SPRequestDuration
SPIisLatency
Edge-Cache-Tag
X-Recruiting
X-Ttl
X-Correlation-Id
X-Request-Received
X-Request-Processing-Time
X-Pinterest-Rid
Pinterest-Version
Pinterest-Generated-By
Filters
Server-Node
X-Content
X-Ua-Browser
X-Ab
Fusion-Content-Id
SPRequestGuid
Fusion-Content-Source
Fusion-Template-Id
Fusion-Component-Id
Fusion-Deployment-Id
Fusion-Source
X-SharePointHealthScore
X-Ezoic-Cdn
X-DynaTrace
Alternate-Protocol
X-ECACHE
Server-Name
X-Accel-Expires
X-Frontend
X-NWS-LOG-UUID
X-HS-Cache-Config
X-HS-Hub-Id
X-Hits
X-HS-Combine-CSS
X-HS-Content-Id
X-Yandex-Sdch-Disable
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Cache-Key
X-Content-Options
X-Ruxit-Js-Agent
Cache-Tags
Host
X-Page-Id
X-Git-Hash
Cleartype
MicrosoftSharePointTeamServices
X-B3-Sampled
Charset
X-Www-Served-By
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Geo-Country
X-Content-Digest
Filterid
X-Amz-Replication-Status
TP-L2-Cache
X-Forwarded-Proto
TP-Cache
X-Ser
X-VCache
X-Varnish-Age
X-Hostname
X-Amzn-Trace-Id
X-Request-Handler-Origin-Region
X-Microsite
X-Activity-Id
X-Daa-Tunnel
X-AppVersion
X-Debug-Info
X-Fastly-Request-Id
X-DIS-Request-ID
X-Rid
X-Az
X-Origin-Server
Access-Control-Allow-Method
X-Upgrade-Enabled
X-XRDS-LOCATION
X-LB-Cache
X-Grace
X-N
X-FB-Debug
ServerID
X-Mobile-URL
X-Nginx-Upstream-Cache-Status
X-Origin-Upstream-Status
X-Aspnet-Duration-Ms
X-Whom
X-Route-Name
X-Providence-Cookie
X-Flags
X-Request-Guid
X-Is-Crawler
X-TT
X-Server-ID
X-Goog-Storage-Class
X-NGENIX-Cache
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-Goog-Generation
X-Varnish-Grace
X-App-Environment
Viewport
Cross-Origin-Opener-Policy
X-App-Server
X-F-Cache
X-Distributor
X-Tb
Payment
X-WebKit-CSP-Report-Only
X-FW-Server
X-FW-Type
X-FW-Dynamic
X-FW-Serve
Node
X-FW-Static
X-PressLabs-Stats
X-FW-Hash
Paypal-Debug-Id
DC
X-Cache-Control
X-Logged-In
X-Seen-By
Fastcgi-Useragent
X-Oneagent-Js-Injection
X-Cache-Age
X-Type
X-User-Agent
Country
Accept-Charset
X-Fastly-Request-ID
X-Webkit-CSP
X-Fastcgi-Cache
X-Cache-Rule
X-Node-Name
X-Varnish-Backend
X-Erf-Bev-Bev-Is-Generated
X-Browser-Type
X-Erf-Bev-Bev
Version
X-Oracle-Dms-Ecid
X-Oracle-Dms-Rid
X-DataDome
X-Wix-Request-Id
X-Load-Cache
Refresh
X-Cache-Action
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Via-JSL
X-IPLB-Instance
Liferay-Portal
X-Response-Served-From
SD-X-WS
Access-Control-Request-Headers
X-Original-Request-Id
Cache-Status
X-Real-IP
Referer-Policy
X-Cacheable-TTL
X-Jobs
NGB
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Drupal-Cache-Tags
X-Cache-Expired-At
X-Proxy-Cache-Status
X-Page-View
X-Is-Bot
X-Vgn-Hpd-Reason
X-B
X-Revision
X-Rendered-As
X-Contextid
X-ProcessESI
X-UUID
X-Yottaa-Metrics
X-Device-Type
X-Drupal-Cache-Contexts
X-Yottaa-Optimizations
X-Debug
X-RemovedCookies
Amp-Access-Control-Allow-Source-Origin
X-Cluster-Name
X-Cache-Time
X-Proxy
X-G
DynaTrace
Surrogate-Key
X-Framework
X-Debug-IsPreview
X-Debug-IsConnected
X-Mobile
X-Azure-Ref
X-Instance
X-Signature
X-Rule
X-B-Cache
Healthy
X-FW-Version
Akamai-GRN
X-Source
CF-IPCountry
X-Ratelimit-Limit
X-Tec-Api-Version
X-Tec-Api-Origin
SID
X-Air-Source
X-Air-Trace-Id
X-Air-Hostname
X-Tec-Api-Root
X-Ms-Version
X-Ms-Request-Id
Frame-Options
X-Nginx-Cache
X-Cache-Hit
Ms-Operation-Id
MS-CV
X-RTag
Section-Io-Cache
Countrycode
Xserver
X-L-Path
X-Environment-Context
X-Tumblr-User
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Varnish-Server
X-XRDS-Location
X-CDN-Forward
X-RateLimit-Limit
X-Region
Count-Hit
X-Cache-Operation
X-Servername
X-APP-VERSION
GEO-INFO
X-Forwarded-Host
X-Content-Powered-By
X-EdgeConnect-Cache-Status
Uber-Trace-Id
X-Litespeed-Cache
X-Backend-Name
Cross-Origin-Window-Policy
X-IPS-LoggedIn
Backend
X-Accel-Buffering
X-Adobe-Loc
X-Mode
X-Adobe-Content
X-JoinUs
X-RN-RSRV
X-SaId
X-Time
X-UPSTREAM-Address
X-Zen-Fury
Ec-Rule-Version
Meta-Geo
X-ShopId
X-Cache-Type
X-No-Session
X-ShardId
X-Cache-Grace
X-Hosted-By
X-Generation-Time
X-Human
X-Detected-As
X-Redis-Cache
X-Shopify-Stage
X-Varnish-Beresp-Grace
X-Alternate-Cache-Key
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
Apigw-Requestid
X-Microcachable
X-Debug-Cache
Eomportal-Instance
X-NCache
Url
X-ServerID
Cache-Name
X-BYPASS-REASON
X-PHP-Backend
X-Sql-Duration-Ms
Country-Code
X-FB-TRIP-ID
X-ProxyCache-Status
X-Sql-Count
X-Site-Version
X-ProxyCache-Key
X-Cache-Server
X-Storage
X-Cache-TTL-Remaining
X-Origin-Date
X-Via-Fastly
X-Uri
X-Status
Decoy-Debug-Key
Decoy-Debug-TTL
X-Proxy-Build
X-Cache-Host
Decoy-Debug-Status
X-Timing-Wait
X-Origin-Hint
Cache-Tv-Group
X-Web-Node
TWC-Device-Class
Webcakes-Region
X-Say-Cacheable
Mn-Server-Ip
X-Say-TTL
Webcakes-App-Version
Webcakes-App-Name
X-SayCDN-TTL
TWC-Privacy
TWC-Locale-Group
Selected-Fe
Protected
TWC-Connection-Speed
X-UA-Device-Type
TWC-GeoIP-LatLong
TWC-GeoIP-Country
Property-Id
X-Akamai-Edgescape
X-SRV
X-Azure-Ref-OriginShield
Source
X-Server-W
X-Routing-Service
X-Extlb
X-Varnishpool
Fastly-SSL
X-Pubstack
X-Zipkin-Id
X-PERF
X-Hl-Ver
X-Format
X-ApacheServer
X-OCL
DB-Nickname
X-PCL
X-Proxied
OT-Force-Account-Verify
Azure-RegionName
Azure-InstanceId
Azure-Version
Azure-SlotName
Azure-SiteName
X-Cluster-Node
X-Section
X-Tid
X-Rewrite-Enabled
X-Access
Content-Secure-Policy
X-LSADC-Cache
X-R9-Blue-Green-Version
X-NYM-Debug-Backend
X-Webkit-Csp
X-Cache-Var-Map
X-Soup
X-Cache-NGX
X-Be
X-Cache-Var
X-App-Version
X-HTML-Minification-Powered-By
X-Amz-Meta-S3cmd-Attrs
X-Content-Age
X-NewRelic-App-Data
SRV
X-Ratelimit-Reset
X-Ua
X-Cached-By
Content-Disposition
Webserver
X-TT-LOGID
X-LAGOON
CDN-RequestId
X-Generated-By
CDN-Uid
Cache
CDN-Cache
X-Varnish-Hits
X-Varnish-Hostname
CDN-CachedAt
CDN-EdgeStorageId
CDN-RequestCountryCode
CDN-PullZone
X-Loop
X-TNCMS
X-S-Maxage
X-Bc-Bl
X-Origin-CC
X-Unique-Id
X-Hyper-Cache
X-Origin-TTL
X-Dc
X-Presslabs-Stats
Onion-Location
X-Auto-Login
Retry-After
X-GEO
Web-Mar-Node
X-Proto
Cache-Hits
X-Tumblr-Pixel-2
X-Cdn
X-Tumblr-Pixel-3
X-Nginx-Cache-Key
X-Time-Microsecs
X-Qnm-Cache
X-Tenant
X-M-Log
X-M-Reqid
Xet-Cookie
X-Edge-Location
X-VWS-Id
X-AWS-Id
X-GG-Cache-Date
X-LJ-Flow-ID
X-Endurance-Cache-Level
X-CSRF-Token
X-Akamai-Transformed
X-Platform-Server
X-CACHE-KEY
Mime-Version
CloudFront-Viewer-Country
LB
HostName
X-ECache
X-Labrador-Cache-Channel
X-PHP-Host
X-B3-SpanId
X-Trace-Id
X-Mg-Request-UUID
N-Cache
X-Xrds-Location
X-Amzn-RequestId
X-Xfnlog-Site
X-Amz-Apigw-Id
X-Storefront-Renderer-Rendered
X-Cache-Tags
X-RCS-CacheZone
X-Locale
Nel
X-Adobe-Source
Upgrade-Insecure-Requests
Ms-Author-Via
X-Origin-Response-Time
X-VC-Cache
X-Request-Time
ServedBy
X-Varnish-Cache-Hits
X-Handled-By
A
X-Cache-Remote
X-Forwarded-Path
X-Vtex-Remote-Cache
X-External-Request-Id
Environment
X-Developer
X-Ftr-Request-Id
X-Vtex-Processado-Em
X-A-Ccd
X-B-Cookie
X-Cache-Date
X-A-Dam
X-Cache-NE
X-ARC
X-Application
X-A-Dgt
X-A-Wwc
X-A-Dcw
X-Aed
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-Connection-Hash
X-AOL-HN
X-D
X-Destination
X-Conf
WPO-Cache-Message
X-Ckpd-Fst-Backend
X-Cluster
X-A
Xc-Version
WPO-Cache-Status
X-Orig-Expires
X-SVT-ORM-RULES
X-Request-Host
Meta-Geo-Continent
X-Rojux
X-S
Mobile-Detection-Method
X-SVT-ORM-VERSION
X-Ig-Push-State
Odigeo-Trace-Id
X-TIM-N
X-Processor
X-S-Cookie
Fastcgi-X-Cache-Version
X-SD-PageType
X-Session-Fingerprint
DCR-Decision-By
DCR-Processing-Time-Ms
X-Shop-Environment
Expiry
X-ScT
X-SRCache-Key
X-ATG-Version
X-Slack-Backend
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-ND-Cache
DSUID
Surrogated-Key
X-NAPM-TraceId
Rendered-Blocks
State
BehaviorPad-Version
X-VG-WebCache
Redirect-Candidate
X-Vdms-Version
Origin
X-V-Cache
X-PBS-Appsvrname
Pramga
X-Vdms-Path
X-Planisys-CDN-Cache
X-PAYTM-SRV-ID
X-Via-NSCOPI
Server-Info
AMP-Access-Control-Allow-Source-Origin
V-Age
Wxu-Next-Commit
Vix-Hermes-Req-Id
L
Wxu-Next-Region
Release
Host-ID
Wxu-Next-Hostname
X-Li-Pop
X-Varnish-Beresp-Status
X-Owner
X-Policy
X-Origin-Expires
X-Old-Content-Length
X-Mvc-Supplant-Cachable
X-VG-TLSProxy
X-Proxy-Upstream
X-Rocket-Nginx-Serving-Static
X-Server-IP
X-Served-From
X-Skip-Cache
X-Scheme
X-Sucuri-ID
X-Sucuri-Cache
X-Men
X-LI-UUID
X-Block-Status
User-Cache-Control
X-Core-Mission
X-Fastly-Cache
X-Gen-Mode
X-Cache-Bucket
X-Hnp-Log
X-Date
X-Device-Os
X-Hash
X-Li-Fabric
X-VServer
X-Forwarded-Site
X-Epic-Correlation-Id
X-Fetched-On
X-Accel-Expires-Debug
X-Cache-Info
X-Reqid
Cmstype
Cmsid
X-Ratelimit-Remaining
From-Origin
Candidate-Md5Url
Datacenter
X-Varnish-Ttl
X-MP-GENERATED-AT
X-Geo-Header
X-Gdpr
X-Gamma-Serve
X-GeoIP
X-GeoIP-City
X-Location
X-Irp-Debug
X-HN
X-Gzip
X-Magnolia-Registration
X-Esi-Check
X-Bip
X-Branch-Name
X-Aicache-OS
AKAMAI
Web-Mar-Region
X-Cache-Id
X-Cdn-Origin
X-NodeID
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
X-Fastly-Backend
X-NU-AKA-ACS-Version
X-VarnishDD-TTL
Traceparent
X-TrackingId
X-Thanos
X-Sn-Servicetimems
X-Viewer-Country
X-EC-Lua
Origin-EX
Origin-CC
CDCHOST
Arc-Country
X-Sigma-Backend
X-BBC-Edge-Cache-Status
X-TH-Server
We-Hiring
X-Origin-Time
X-Nyt-Route
X-Platform
X-Cache-Debug
X-Rocket-Build-Number
X-Request-Start
X-Req
X-Region-Sid
Req-Svc-Chain
X-Sigma
Locid
Svr
CacheControlHeader
Fastly-GeoIP-CountryCode
Mail-Subject
Machine
Fastcgi-Cache-TTL
Apple-News-Services-Request-Url
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
PFcat
Apple-News-Services-Handled
Gh-Request-Id
True-Client-Country-4JS
X-CS
Thinkindot-CacheControl-Type
X-Envoy-Decorator-Operation
X-Core-Value
X-Rebelmouse-Cache-Control
Thinkindot-Control
Thinkindot-CacheControl
X-DefElseHash
X-Generated-On
X-DPWN-IS-SECURE
TDXMobile
X-Qloud-Router
X-DefHash
X-Developers
X-FC-Vary-Parameters
X-HS-Content-Campaign-Id
HA-Ipaddr
Memcached
Fastly-SWR
X-RateLimit-Remaining-Second
Fastly-SIE
Ha-Gx-Prefs
NM-Fastcgi-Cache
X-RateLimit-Limit-Second
X-Origin
NGX
X-Csrf-Jwt
X-TIME
X-Thinkindot-L3
X-Level-Front-Cache
X-Request-URI
Platform
X-Loc
Server-Host
X-Eu-Site
X-Varnish-CookieHashed-On
L5d-Success-Class
X-UnsetCookies
Is-Eu
X-Varnish-CookieINHashed-On
X-Backend-State
X-Cache-Config
X-Varnish-Remaining-TTL
X-Webstats-RespID
X-CGP
X-Variation
WWW-Authenticate
X-Rebelmouse-Surrogate-Control
Adler-Geo
X-Varnish-Beresp-Ttl
X-Zone
X-Trace-ID
X-Worker
X-Has-Esi
Esi-Enabled
Cf-Device-Type
Sslversion
X-Pod-Name
X-Amzn-Remapped-Content-Length
X-Correlation-ID
Fastly-Drupal-Html
X-JWT-State
On-Server
X-Is-Gdpr
X-Up
X-Node-Id
X-Tx-Id
X-FireWall-Port
CDN
X-Response-By
Pics-Label
X-LB-ID
Ssr
X-Mvc-Supplant-OutputCached
X-Cdn-Srv
X-Vc
X-API-Version
X-Service
WP-Super-Cache
X-NC
X-Generated-In
C-Via
X-Datadome
X-Via-Poph
Memory
X-Via-Popn
X-Cache-PHP
Time
X-Via-Popv
X-TA-CDN-Provider
X-DynaTrace-JS-Agent
X-Cache-Enabled
X-Refresh
X-DC
NtCoent-Length
X-LB-NoCache
X-Dynatrace
X-Tt-Logid
X-Cache-Status-Check
X-Backend-TTL
X-Edge-Pop
Env
X-Tb-Optimization-Total-Bytes-Saved
X-GeoIP-Country-Code
X-GeoIP-Region-Code
X-Cache-Ttl
X-Parent-Response-Time
X-Optimistic-Header
X-Render-Time
GeoIp-Country-Code
Magicmarker
X-TraceId
X-Info
X-Esi
X-Ua-Device
X-Servedbyhost
X-NWS-UUID-VERIFY
X-Unique-ID
X-ZONE
Server-ID
Kp-EeAlive
X-AIR-PT
X-Restarts
X-TX-ID
X-Varnish-Beresp-TTL
X-CacheTTL
X-Clientip
X-CLOUD-TRACE-CONTEXT
X-DSS
UCS
X-DI
Edge-Cache
X-VCL-Version
X-DW
S-Rt
X-RPS
X-RSL
X-RPM
X-Cs
X-Cache-Backend
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
X-Oss-Request-Id
X-Oss-Server-Time
X-Oss-Storage-Class
X-Wix-Viewer-Type
X-MSEdge-Flight
X-Action
X-DB
HIT
Cache-Host
X-MSEdge-Features
X-Srv
X-Newrelic-Synthetics
X-Webkit-CSP-Report-Only
X-LI-Proto
X-HA-Backend
Proxy-Connection
S-Cnection
X-Fpc
X-App
X-Traceid
X-URL
Section-Io-Id
Section-Io-Origin-Time-Seconds
Lb
Section-Origin-Responded
Section-Io-Origin-Status
WebServer
X-Li-Proto
Test
X-Webkit-Csp-Report-Only
X-Minions-Version
X-FPC
X-Micro-Cache
User-Agent
Fastly-Backend-Name
X-NODE
X-LiteSpeed-Cache-Control
Server-Id
Geo-Info
X-Backend-Host
Tcn
X-Vcl-Version
X-B3-Spanid
X-Http-Reason
X-Akamai-Request-ID2
X-Pad
X-Pass-Why
X-Release
X-BCube-Filmed-By
X-ES-SERVER
X-Ec-Fail
Resin-Trace
X-Ec-GeoHdr
X-LiteSpeed-Tag
X-HostName
Cf-Int-Pingora-Origin-Digest
X-APP
X-User
Fastly-Drupal-HTML
Accept-Language
X-BBC-Origin-Response-Status
X-CSRF-TOKEN
EpKe-Alive
CPC-Cache
X-ServedByHost
CPC-Age
Path
VNS-Age
VNS-Cache
GeoIP-Country-Code
X-Amz-Meta-Cb-Modifiedtime
X-ID
Cache-Key
Hostname
X-Urbn-Site-Id
Locale
X-Urbn-Context-Path
Ohc-File-Size
X-WA
X-WA-Info
X-Akamai-Pragma-Client-IP
Hit
Srv
X-Check-Cacheable
X-Geo
X-Dynatrace-Js-Agent
X-ElasticPress-Query
Cdnsip
ENV
X-HS-Status
Shield-Pop
X-Ha-Backend
X-PJAX-URL
Pagetype
X-AK-Request-ID
X-Wikidot-Static-Cache
X-Via-PopN
M-TraceId
X-Wikidot-Backend
X-Clara-WADP
X-Fmm-Version
MIME-Version
X-Cms-Context
Cdncip
X-Edge-POP
X-Via-PopH
X-Via-PopV
X-WADP-Cache
X-Cdn-Forward
MD5-Digest
X-Api-Version
X-NGINX-Cache
X-CCDN-CacheTTL
My-App
Cluster
X-CCDN-Origin-Time
Load-Balancing
X-Via-Ucdn
X-Edge-Cache
X-Hcs-Proxy-Type
X-From
X-Var-Ttl
X-CUA
X-Ucs
Geoip-Latitude
Lfy
Tracecode
X-VG-WebServer
X-Client-Ip
URI
X-ServerName
Server-Hostname
Sever-Int
X-SIPLIST1
W
X-Fastly-Backend-Reqs
IsBot
Server-Ext
X-GoCache-CacheStatus
X-Mcache
T-Server
X-Cache-Expires
X-TRACE-ID
X-Dw-Trace-Id
X-VC
Lang
X-Cdn-Request-ID
X-Nc
X-Fragments
Cneonction
X-Lb-Id
X-Provided-By
Cteonnt-Length
PICS-Label
X-UP
Ohc-Cache-HIT
X-Fastly-Cache-Hits
Servername
X-B3-ParentSpanId
X-RateLimit-Reset
X-RAMCache
WZWS-RAY
Cdn
X-WP-CF-Super-Cache-Cache-Control
X-Cc-Via
X-WP-CF-Super-Cache
Cf-Ipcountry
X-Acquia-Application-Trace
X-Acquia-Site
X-Swift-Error
X-Acquia-Application-UUID
Target-Params
X-Acquia-Purge-Tags
X-Via-CDN
X-Contensis-Viewer-Groups
Dnion-Transfer-Encoding
X-Platform-Router
X-Platform-Processor
X-Apw-Access-Action
X-Apw-Access-Object
X-Cache-ASPX
X-Apw-Hits
X-Apw-Access-Token
X-Yottaa-OS
X-Platform-Cluster
X-Snapshot-Date
HitType
X-UA
CF-Cached-On
Vha6-Origin
X-Newrelic-App-Data
X-Akamai-Request-ID
X-Air-Pt
X-Cache-Ngx
Sid
X-Last-Modified
X-Akamai-ERPolicy
X-Te-Count
X-Akamai-ERRuleID
Server-Ttl
X-Varnish-Authentication
X-Http-Duration-Ms
Uri
GeoIP-Latitude
X-Te-Duration-Ms
X-Miniprofiler-Ids
X-HTML-Edge-Cache
Req-ID
FSS-Cache
CountryCode
X-Sentry-ID
Ngx
X-Lb-Nocache
X-Logging-Id
X-B3-Parentspanid
X-CacheKey
X-Http-Count