Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
Link
CF-Cache-Status
Accept-Ranges
CF-RAY
ETag
Expect-CT
Pragma
X-Powered-By
X-XSS-Protection
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
P3P
Alt-Svc
X-Served-By
X-Xss-Protection
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Cache-Status
X-Generator
X-Cacheable
Timing-Allow-Origin
X-Content-Security-Policy
X-Iinfo
Feature-Policy
Status
X-Envoy-Upstream-Service-Time
Content-Encoding
Access-Control-Expose-Headers
P3p
X-Drupal-Dynamic-Cache
X-CDN
X-AspNetMvc-Version
Upgrade
X-Via
CF-Ray
X-Ws-Request-Id
Access-Control-Max-Age
X-Request-ID
Server-Timing
EagleId
X-Cache-Group
Keep-Alive
X-Turbo-Charged-By
Request-Context
X-Age
X-Server-Powered-By
X-Proxy-Cache
X-UA-Device
X-AH-Environment
X-Backend
X-Hacker
X-Robots-Tag
Report-To
X-Amz-Request-Id
Host-Header
X-Server
X-Amz-Id-2
Grace
X-LiteSpeed-Cache
X-Rq
X-Nginx-Cache-Status
X-Varnish-Cache
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-Dns-Prefetch-Control
X-WebKit-CSP
X-Page-Speed
X-Vhost
X-Ua-Compatible
EagleEye-TraceId
X-OneAgent-JS-Injection
X-Amz-Version-Id
X-Pingback
X-Dispatcher
X-Device
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Cache-Spec
NEL
X-Host
X-Server-Id
Cf-Railgun
X-Node
X-Backend-Server
Accept-CH
X-Readtime
Surrogate-Control
X-Akam-SW-Version
Request-Id
X-Response-Time
X-HW
Xkey
Accept-Ch-Lifetime
X-Ruxit-JS-Agent
X-Application-Context
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
Content-Location
Rating
X-Country
X-B3-TraceId
X-Cache-Lookup
X-Cloud-Trace-Context
X-Trace
X-Url
X-Ac
X-Content-Type
Accept-CH-Lifetime
X-TtlSet
X-PC
X-Vname
Allow
X-Varnish-TTL
X-Clacks-Overhead
X-Mod-Pagespeed
Edge-Control
X-ESI
X-FastCGI-Cache
Fastly-Restarts
X-Server-Name
Cache-Tag
Service-Worker-Allowed
X-Rack-Cache
X-VARITI-CCR
Verso
X-Element-Page-Cache
X-MS-InvokeApp
X-GitHub-Request-Id
X-Upstream
MS-Author-Via
X-Amz-Rid
X-Aws-Lambda-Call-Status
X-Vcap-Request-Id
Public-Key-Pins
X-Cached
X-Dw-Request-Base-Id
X-Client-IP
X-D2id
X-Abt-Application-Version
X-Cache-TTL
X-Cnection
X-Origin-Cache
X-Px
Arr-Disable-Session-Affinity
Accept-Ch
Access-Control-Request-Method
X-Navigation-Version
RTSS
X-Goog-Hash
X-Country-Code
X-Powered-By-Plesk
X-Instrumentation
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-NF-Request-ID
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-Exp-Id
X-Exp-Variant
X-GoogleNews-Bot
X-Cdn-Fetch
X-Kinja-Revision
X-Use-Magma
X-Powered-CMS
X-Kinja-Build
X-Kinja
X-Kinja-Server
X-Version
X-Language
AR-ATIME
AR-CACHE
AR-SID
AR-PoweredBy
AR-Request-ID
Pagespeed
X-Sol
X-Middleton-Display
Display
X-Amz-Server-Side-Encryption
Response
X-Middleton-Response
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-MSEdge-Ref
X-LLID
X-Kinsta-Cache
X-Edge-Location-Klb
X-Edge
X-TTL
Nginx-Cache
X-Template
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
X-Protected-By
X-Shield-Request-Id
X-HP-Webp
X-Jurisdiction
X-HP-Trace-Id
TCN
X-RateLimit-Remaining
X-T
S
X-Content-Security-Policy-Report-Only
X-Forwarded-For
X-Aspnetmvc-Version
X-Mg-S
X-Id
Content-MD5
Edge-Cache-Tag
Fastcgi-Cache
X-Mid
Realpath
SPIisLatency
SPRequestDuration
Front-End-Https
X-MCACHE
X-Recruiting
X-CST
Filters
X-Request-Processing-Time
X-Request-Received
Pinterest-Version
Pinterest-Generated-By
X-Pinterest-Rid
Server-Node
X-DynaTrace
X-Ua-Browser
X-Content
X-Ab
Server-Name
X-Frontend
X-Correlation-Id
X-Ttl
X-NWS-LOG-UUID
X-ECACHE
SPRequestGuid
X-HS-Content-Id
X-HS-Hub-Id
X-HS-Cache-Config
X-SharePointHealthScore
Fusion-Template-Id
Fusion-Content-Source
Fusion-Component-Id
Fusion-Source
Fusion-Content-Id
Fusion-Deployment-Id
X-HS-Combine-CSS
X-Ezoic-Cdn
X-Parallel-Accel
X-Yandex-Sdch-Disable
X-Cache-Key
X-Hits
Alternate-Protocol
X-Ser
X-Content-Options
X-Buckets
X-Server-ID
X-Tt-Trace-Tag
MicrosoftSharePointTeamServices
X-Tt-Trace-Host
X-Page-Id
X-Ruxit-Js-Agent
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-B3-Sampled
Charset
Cache-Tags
Cleartype
Host
X-Git-Hash
X-Www-Served-By
X-Geo-Country
X-Daa-Tunnel
X-DIS-Request-ID
X-Accel-Expires
X-Content-Digest
X-Amzn-Trace-Id
X-Amz-Replication-Status
Filterid
X-Debug-Info
X-Varnish-Age
X-Fastly-Request-Id
X-Az
X-Activity-Id
X-AppVersion
X-Forwarded-Proto
X-Hostname
X-FB-Debug
TP-L2-Cache
TP-Cache
X-VCache
X-Upgrade-Enabled
X-Rid
Access-Control-Allow-Method
X-N
Cross-Origin-Opener-Policy
X-Grace
X-Nginx-Upstream-Cache-Status
X-Origin-Server
X-Ratelimit-Limit
X-F-Cache
X-LB-Cache
ServerID
X-Mobile-URL
X-Flags
X-Is-Crawler
X-Route-Name
X-Aspnet-Duration-Ms
X-Request-Guid
X-Providence-Cookie
X-XRDS-LOCATION
X-Whom
X-Goog-Storage-Class
X-GUploader-UploadID
X-TT
X-Goog-Generation
X-Goog-Stored-Content-Length
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-App-Environment
X-Tb
X-Varnish-Grace
Viewport
Node
Payment
X-Seen-By
X-FW-Serve
X-WebKit-CSP-Report-Only
X-App-Server
X-FW-Server
X-FW-Static
X-FW-Type
X-FW-Hash
X-Type
X-Distributor
X-FW-Dynamic
X-Origin-Upstream-Status
X-NGENIX-Cache
X-User-Agent
DC
Paypal-Debug-Id
Fastcgi-Useragent
X-Cache-Control
Accept-Charset
Country
X-Litespeed-Cache
X-Wix-Request-Id
X-Logged-In
X-Cache-Rule
X-Request-Handler-Origin-Region
X-Microsite
X-Webkit-CSP
X-Fastly-Request-ID
Version
X-Cache-Age
X-DataDome
X-Via-JSL
X-Oracle-Dms-Rid
X-Oracle-Dms-Ecid
X-Browser-Type
X-Erf-Bev-Bev-Is-Generated
X-Drupal-Cache-Tags
Referer-Policy
X-Erf-Bev-Bev
X-Varnish-Backend
Amp-Access-Control-Allow-Source-Origin
X-Cluster-Name
X-Signature
X-B-Cache
X-Contextid
Cache-Status
Refresh
X-Original-Request-Id
X-Load-Cache
Access-Control-Request-Headers
SD-X-WS
X-Node-Name
X-Response-Served-From
X-Cache-Action
X-Cache-Expired-At
X-Is-Bot
X-Vgn-Hpd-Reason
X-Rendered-As
X-Proxy-Cache-Status
X-Page-View
X-Jobs
X-B
X-Revision
X-Mobile
X-IPLB-Instance
X-UUID
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
NGB
X-Debug
X-Fastcgi-Cache
X-Cacheable-TTL
X-Instance
X-Real-IP
X-Yottaa-Metrics
X-Rule
X-Device-Type
X-Yottaa-Optimizations
X-Drupal-Cache-Contexts
X-ProcessESI
Akamai-GRN
X-Tec-Api-Version
X-G
X-Tec-Api-Root
X-Cache-Time
X-RemovedCookies
X-Tec-Api-Origin
Surrogate-Key
X-Debug-IsPreview
X-Proxy
X-Framework
X-Debug-IsConnected
X-FW-Version
X-Air-Source
X-Air-Trace-Id
X-Air-Hostname
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-TEC-API-ROOT
CF-IPCountry
X-Ratelimit-Reset
SID
DynaTrace
X-PressLabs-Stats
Liferay-Portal
X-Azure-Ref
X-CDN-Forward
X-Nginx-Cache
X-Oneagent-Js-Injection
Healthy
GEO-INFO
Frame-Options
X-Source
Count-Hit
X-Cache-Operation
X-Presslabs-Stats
X-Ms-Request-Id
X-Ms-Version
Ms-Operation-Id
X-Accel-Buffering
MS-CV
X-RTag
X-XRDS-Location
Uber-Trace-Id
X-EdgeConnect-Cache-Status
X-APP-VERSION
X-Environment-Context
X-Tumblr-Pixel
X-L-Path
X-Tumblr-Pixel-0
X-Tumblr-User
X-Tumblr-Pixel-1
Countrycode
Xserver
X-Zen-Fury
X-Cache-Hit
X-Varnish-Server
X-Mode
Ec-Rule-Version
X-Backend-Name
X-Forwarded-Host
X-Region
X-Cache-NGX
Cross-Origin-Window-Policy
X-Servername
Nel
Backend
X-IPS-LoggedIn
X-Content-Powered-By
X-Cache-Type
Protected
X-SaId
X-RN-RSRV
X-Cache-TTL-Remaining
X-UPSTREAM-Address
X-Rewrite-Enabled
X-JoinUs
Meta-Geo
X-Detected-As
X-Generation-Time
X-Uri
X-Extlb
X-Zipkin-Id
X-Routing-Service
X-Hosted-By
Section-Io-Cache
X-Sorting-Hat-ShopId
X-Cache-Grace
X-Alternate-Cache-Key
Fastly-SSL
Decoy-Debug-Status
X-Tid
Eomportal-Instance
X-Proxied
Decoy-Debug-Key
Decoy-Debug-TTL
Country-Code
X-NewRelic-App-Data
X-ShardId
X-ShopId
X-Sql-Count
Apigw-Requestid
X-Sorting-Hat-PodId
X-Sql-Duration-Ms
X-Shopify-Stage
X-Debug-Cache
Url
X-FB-TRIP-ID
X-BYPASS-REASON
X-Cache-Server
X-Format
X-Status
X-ProxyCache-Status
X-Origin-Date
Mn-Server-Ip
X-RateLimit-Limit
X-NYM-Debug-Backend
X-Varnish-Beresp-Grace
Cache-Tv-Group
X-ProxyCache-Key
X-ServerID
X-Human
X-UA-Device-Type
X-Storage
X-PHP-Backend
X-Redis-Cache
Webcakes-App-Name
TWC-Privacy
Property-Id
Webcakes-App-Version
TWC-GeoIP-Country
TWC-Device-Class
TWC-Connection-Speed
TWC-Locale-Group
Selected-Fe
TWC-GeoIP-LatLong
X-Microcachable
X-Section
X-No-Session
X-Site-Version
X-SayCDN-TTL
X-OCL
X-Origin-Hint
X-Proxy-Build
X-Server-W
X-PERF
X-PCL
X-Say-TTL
X-Soup
X-ApacheServer
X-Akamai-Edgescape
X-Adobe-Loc
X-Access
X-Cache-Host
X-Cluster-Node
X-NCache
X-Say-Cacheable
X-Timing-Wait
X-Web-Node
Webcakes-Region
X-Adobe-Content
SRV
Cache-Name
X-Content-Age
DB-Nickname
Azure-RegionName
X-Varnishpool
Azure-SiteName
X-Hl-Ver
Azure-InstanceId
Azure-SlotName
Azure-Version
Content-Secure-Policy
X-Ratelimit-Remaining
X-R9-Blue-Green-Version
OT-Force-Account-Verify
X-Via-Fastly
X-Be
X-Pubstack
CDN-PullZone
CDN-EdgeStorageId
CDN-Uid
X-LSADC-Cache
CDN-RequestId
CDN-Cache
X-Ua
X-Webkit-Csp
CDN-CachedAt
CDN-RequestCountryCode
X-Hyper-Cache
X-Azure-Ref-OriginShield
Content-Disposition
X-Generated-By
X-Cached-By
WPO-Cache-Message
WPO-Cache-Status
LB
Cache
X-Unique-Id
X-SRV
X-TIME
Source
X-Nginx-Cache-Key
X-Bc-Bl
X-LAGOON
X-App-Version
X-TT-LOGID
X-Trace-Id
X-Dc
X-Auto-Login
X-HTML-Minification-Powered-By
Xet-Cookie
X-Origin-CC
X-Origin-TTL
X-Varnish-Hits
X-TNCMS
X-Loop
X-GEO
Mime-Version
Cache-Hits
X-Varnish-Hostname
X-S-Maxage
Retry-After
Onion-Location
X-Platform-Server
X-Amz-Meta-S3cmd-Attrs
X-Cdn
HostName
X-Time
X-Akamai-Transformed
X-Xfnlog-Site
X-Cache-Var
Web-Mar-Node
X-Tumblr-Pixel-3
X-Cache-Var-Map
X-CSRF-Token
X-Tumblr-Pixel-2
X-Proto
X-Cache-Tags
X-Cache-Remote
X-Varnish-Cache-Hits
Webserver
X-Edge-Location
X-Endurance-Cache-Level
X-Time-Microsecs
Upgrade-Insecure-Requests
X-Tenant
X-Request-Time
X-AWS-Id
N-Cache
X-EC-Lua
X-AOL-HN
X-ECache
X-LJ-Flow-ID
X-VWS-Id
X-GG-Cache-Date
ServedBy
X-FireWall-Port
WP-Super-Cache
X-Request-Host
X-M-Reqid
X-B3-SpanId
X-Correlation-ID
X-Xrds-Location
X-Qnm-Cache
X-Mg-Request-UUID
X-M-Log
X-Via-NSCOPI
X-Amz-Apigw-Id
CloudFront-Viewer-Country
X-PHP-Host
X-Labrador-Cache-Channel
X-Amzn-RequestId
X-Planisys-CDN-Cache
BehaviorPad-Version
X-External-Request-Id
X-Planisys-CDN-Rules
DCR-Decision-By
X-Ftr-Request-Id
X-Orig-Expires
X-Origin-Response-Time
X-VG-WebCache
DSUID
X-PBS-Appsvrname
CDCHOST
DCR-Processing-Time-Ms
X-Forwarded-Path
X-CF-Lambda-Fn
X-PAYTM-SRV-ID
Expiry
Mobile-Detection-Method
X-D
X-Hnp-Log
X-NAPM-TraceId
X-Ig-Push-State
X-A-Wwc
X-Conf
L
Meta-Geo-Continent
A
X-Destination
X-Ckpd-Fst-Backend
Odigeo-Trace-Id
X-CF-Lambda-Version
X-Connection-Hash
X-Cluster
X-ND-Cache
X-Developer
Fastcgi-X-Cache-Version
X-Gen-Mode
Origin
Pramga
X-Vdms-Path
X-B-Cookie
X-Slack-Backend
User-Cache-Control
X-SRCache-Key
X-Shop-Environment
X-Block-Status
Surrogated-Key
X-S-Cookie
X-ScT
X-SD-PageType
V-Age
X-ARC
X-A
X-A-Ccd
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-TIM-N
X-V-Cache
X-Aed
Xc-Version
X-A-Dcw
X-A-Dam
X-Application
X-S
X-Session-Fingerprint
X-Vdms-Version
Redirect-Candidate
X-Cache-NE
From-Origin
X-A-Dgt
Rendered-Blocks
X-Vtex-Remote-Cache
X-Rojux
X-Cache-Date
X-Processor
Sslversion
X-Planisys-CDN-TTL
X-Vtex-Processado-Em
X-MP-GENERATED-AT
X-RCS-CacheZone
X-Device-Os
X-Cdn-Srv
Release
Wxu-Next-Region
PFcat
X-Date
X-Epic-Correlation-Id
X-Envoy-Decorator-Operation
X-Accel-Expires-Debug
Fastcgi-Cache-TTL
HA-Ipaddr
Traceparent
Wxu-Next-Commit
X-Core-Mission
X-Eu-Site
Ssr
X-CGP
State
X-Cache-Bucket
X-Csrf-Jwt
L5d-Success-Class
Origin-CC
Origin-EX
Ha-Gx-Prefs
X-Cache-Info
Wxu-Next-Hostname
True-Client-Country-4JS
X-Backend-State
Gh-Request-Id
X-Origin-Time
X-Li-Fabric
X-Li-Pop
X-LI-UUID
X-Proxy-Upstream
X-RateLimit-Limit-Second
X-Request-URI
X-RateLimit-Remaining-Second
X-Cache-Enabled
X-Location
X-Men
X-Nyt-Route
X-Old-Content-Length
X-VServer
Cmstype
X-NodeID
X-Mvc-Supplant-Cachable
X-Policy
X-Origin-Expires
X-Aicache-OS
X-Forwarded-Site
X-Webstats-RespID
X-Gdpr
X-Fetched-On
CacheControlHeader
X-UnsetCookies
X-Fastly-Cache
X-HN
X-Sucuri-ID
X-Server-IP
X-Hash
X-Storefront-Renderer-Rendered
X-Sucuri-Cache
X-VarnishDD-TTL
Vix-Hermes-Req-Id
Cmsid
X-NWS-UUID-VERIFY
X-Zone
Server-Info
Environment
X-Handled-By
Fastly-Drupal-Html
X-Gzip
X-GeoIP
X-GeoIP-City
X-Sn-Servicetimems
X-Skip-Cache
X-Sigma
X-Sigma-Backend
X-Developers
X-ATG-Version
X-Geo-Header
X-Fastly-Backend
X-Varnish-Beresp-Status
X-Esi-Check
X-VG-TLSProxy
X-TrackingId
X-Gamma-Serve
X-Datadog-Trace-Id
X-TH-Server
X-Thinkindot-L3
X-Adobe-Source
X-Served-From
X-Core-Value
X-Irp-Debug
X-Datadog-Parent-Id
X-Node-Id
X-Platform
X-Owner
X-Viewer-Country
X-Cdn-Origin
X-Req
X-Cache-Debug
X-Cache-Config
X-Scheme
X-Branch-Name
X-HS-Content-Campaign-Id
X-Rocket-Nginx-Serving-Static
X-Datadog-Sampling-Priority
X-Reqid
X-Rocket-Build-Number
X-BBC-Edge-Cache-Status
X-Cache-Id
X-Magnolia-Registration
AKAMAI
Apple-News-Services-Handled
Server-Host
Svr
Thinkindot-CacheControl
TDXMobile
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
Host-ID
Fastly-GeoIP-CountryCode
Locid
Mail-Subject
Apple-News-Services-Request-Url
Arc-Country
Thinkindot-CacheControl-Type
Req-Svc-Chain
We-Hiring
X-Locale
Web-Mar-Region
X-VC-Cache
Thinkindot-Control
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
X-Generated-On
X-Varnish-CookieHashed-On
X-FC-Vary-Parameters
X-Variation
X-Backend-TTL
X-DefHash
Fastly-SIE
X-DPWN-IS-SECURE
Cf-Device-Type
X-Worker
Adler-Geo
X-DefElseHash
X-Origin
X-Tx-Id
X-Pod-Name
X-Rebelmouse-Surrogate-Control
X-Region-Sid
X-NU-AKA-ACS-Version
X-Loc
X-Has-Esi
X-Rebelmouse-Cache-Control
X-Is-Gdpr
X-JWT-State
X-Request-Start
X-Level-Front-Cache
X-Response-By
X-Thanos
NGX
Memcached
NM-Fastcgi-Cache
X-Amzn-Remapped-Content-Length
X-Bip
Platform
Machine
Fastly-SWR
Is-Eu
X-Trace-ID
AMP-Access-Control-Allow-Source-Origin
X-Ua-Device
X-CLOUD-TRACE-CONTEXT
X-GeoIP-Country-Code
X-CACHE-KEY
X-Qloud-Router
X-CS
X-Varnish-Beresp-Ttl
X-Mvc-Supplant-OutputCached
X-GeoIP-Region-Code
Datacenter
X-Up
X-Generated-In
X-LB-ID
Pics-Label
X-API-Version
X-NC
CDN
Magicmarker
Ms-Author-Via
X-Datadome
S-Rt
Candidate-Md5Url
X-LB-NoCache
Kp-EeAlive
X-Restarts
X-DynaTrace-JS-Agent
X-Tb-Optimization-Total-Bytes-Saved
WWW-Authenticate
X-Via-Popv
X-Via-Poph
X-Vc
X-DC
WebServer
X-TraceId
X-Via-Popn
NtCoent-Length
Env
On-Server
Time
Memory
X-Varnish-Ttl
X-Akamai-Request-ID2
X-Http-Reason
X-Tt-Logid
X-Cache-Backend
Edge-Cache
Esi-Enabled
X-Wix-Viewer-Type
X-Optimistic-Header
X-TA-CDN-Provider
X-Edge-Pop
X-Refresh
X-RSL
X-DB
X-DI
X-RPS
X-Action
X-DSS
X-RPM
GeoIp-Country-Code
X-CacheTTL
X-DW
X-Service
X-Minions-Version
C-Via
X-Esi
X-Servedbyhost
Accept-Language
X-Srv
X-HA-Backend
X-Varnish-Beresp-TTL
X-Cache-PHP
X-Parent-Response-Time
Server-ID
X-MSEdge-Features
X-Unique-ID
X-MSEdge-Flight
X-Cs
X-Newrelic-Synthetics
X-Webkit-Csp-Report-Only
X-ZONE
X-TX-ID
X-Urbn-Site-Id
X-Urbn-Context-Path
X-Cache-Status-Check
Locale
X-Render-Time
X-VCL-Version
X-Dynatrace
X-Ec-Fail
X-Cache-Ttl
X-Traceid
X-Fpc
X-LI-Proto
X-User
X-App
X-Ec-GeoHdr
X-URL
Test
X-Li-Proto
X-Pass-Why
X-LiteSpeed-Cache-Control
Proxy-Connection
X-B3-Spanid
X-FPC
X-Info
X-AIR-PT
X-Webkit-CSP-Report-Only
X-NODE
Cdncip
Cdnsip
X-Vcl-Version
X-AK-Request-ID
Server-Id
Geo-Info
X-Clientip
Tcn
X-Oss-Storage-Class
X-Oss-Request-Id
X-Oss-Server-Time
X-Oss-Hash-Crc64ecma
X-Clara-WADP
HIT
Cache-Host
M-TraceId
X-WADP-Cache
X-Fmm-Version
X-Oss-Object-Type
My-App
UCS
X-Var-Ttl
S-Cnection
X-LiteSpeed-Tag
Fastly-Drupal-HTML
X-HostName
X-CUA
Geoip-Latitude
Resin-Trace
Cf-Int-Pingora-Origin-Digest
Cluster
Tracecode
X-CSRF-TOKEN
X-Ha-Backend
T-Server
X-ID
Lfy
X-From
GeoIP-Country-Code
X-Dynatrace-Js-Agent
Hostname
X-Edge-POP
X-Pad
Hit
X-ServedByHost
X-RAMCache
Ohc-File-Size
X-Mcache
X-Micro-Cache
Lang
Fastly-Backend-Name
X-Fragments
User-Agent
X-Geo
MIME-Version
Target-Params
X-Backend-Host
X-Release
X-BBC-Origin-Response-Status
X-ElasticPress-Query
X-WP-CF-Super-Cache
X-Via-PopN
ENV
X-WP-CF-Super-Cache-Cache-Control
X-Via-PopV
X-Via-PopH
X-Edge-Cache
X-NGINX-Cache
DataCenter
X-Check-Cacheable
X-VC
X-Api-Version
X-APP
Section-Origin-Responded
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
Load-Balancing
X-BCube-Filmed-By
Section-Io-Id
X-Cdn-Forward
Lb
X-ServerName
X-Ucs
X-Fastly-Backend-Reqs
Servername
EpKe-Alive
URI
X-HS-Status
X-Proxy-Cache-Info
X-Httpd
Uri
X-UP
X-GoCache-CacheStatus
PICS-Label
FSS-Cache
Permissions-Policy
X-WA
VNS-Age
VNS-Cache
X-Lb-Nocache
CPC-Cache
Path
Cache-Key
CPC-Age
X-Amz-Meta-Cb-Modifiedtime
X-WA-Info
X-TRACE-ID
Cteonnt-Length
Ohc-Cache-HIT
X-RateLimit-Reset
X-B3-ParentSpanId
X-Lb-Id
X-Wikidot-Static-Cache
Cdn
Producers
X-Wikidot-Backend
Cneonction
X-ES-SERVER
X-Nc
X-Provided-By
Server-Ttl
ServerName
X-Fastly-Cache-Hits
WZWS-RAY
X-Cdn-Request-ID
X-Dw-Trace-Id
X-Akamai-ERRuleID
CF-Cached-On
X-Acquia-Purge-Tags
X-Acquia-Application-UUID
X-Acquia-Application-Trace
X-PJAX-URL
X-Acquia-Site
X-Cache-CFC
Shield-Pop
X-Apw-Hits
X-Apw-Access-Token
X-Apw-Access-Object
X-SB
X-Cache-ASPX
X-Snapshot-Date
X-Contensis-Viewer-Groups
Vha6-Origin
Pagetype
X-Cms-Context
X-Yottaa-OS
X-Swift-Error
Cf-Ipcountry
X-Akamai-ERPolicy
X-Newrelic-App-Data
X-Apw-Access-Action
X-Vcache
X-Cache-Ngx
X-Air-Pt
Sid
X-Last-Modified
X-Platform-Processor
X-Pool
GeoIP-Latitude
X-Platform-Cluster
X-Udemy-Cache-App-Namespace
X-Platform-Router
MD5-Digest
Ngx
Req-ID
CountryCode
X-Via-Ucdn
X-Akamai-Pragma-Client-IP
X-UA
X-CacheKey
X-Varnish-Authentication
X-Sentry-ID
X-Logging-Id
X-Http-Duration-Ms
X-Te-Count
X-Te-Duration-Ms
X-Http-Count
X-CCDN-Origin-Time
X-Miniprofiler-Ids
X-CCDN-CacheTTL
X-Hcs-Proxy-Type