Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
X-Powered-By
Pragma
X-XSS-Protection
CF-RAY
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
Alt-Svc
P3P
X-Cache-Hits
X-Xss-Protection
X-UA-Compatible
X-Served-By
CF-Ray
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
Access-Control-Allow-Credentials
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
X-Drupal-Cache
X-Cache-Status
X-Generator
X-Check
X-Cacheable
X-FRAME-OPTIONS
X-Envoy-Upstream-Service-Time
Timing-Allow-Origin
X-Iinfo
X-DNS-Prefetch-Control
X-Dns-Prefetch-Control
Server-Timing
X-Drupal-Dynamic-Cache
Feature-Policy
X-Content-Security-Policy
Access-Control-Expose-Headers
X-XSS-PROTECTION
Content-Encoding
X-CDN
Status
X-Request-ID
Upgrade
X-AspNetMvc-Version
Access-Control-Max-Age
X-Amz-Request-Id
X-Via
X-Ua-Compatible
X-Amz-Id-2
Request-Context
X-Backend
X-Cache-Group
X-Turbo-Charged-By
X-Robots-Tag
Cf-Edge-Cache
Keep-Alive
Host-Header
X-AH-Environment
X-Vhost
X-Hacker
X-Proxy-Cache
X-Server
Allow
X-Rq
X-UA-Device
X-Server-Powered-By
X-Ws-Request-Id
X-Dispatcher
EagleId
X-Age
X-Varnish-Cache
X-Amz-Version-Id
P3p
Nel
Grace
X-LiteSpeed-Cache
Cf-Apo-Via
Cf-Railgun
X-OneAgent-JS-Injection
X-Page-Speed
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
EagleEye-TraceId
X-Device
X-Swift-CacheTime
X-Swift-SaveTime
X-Aws-Lambda-Call-Status
Ali-Swift-Global-Savetime
X-Pingback
X-Cache-Lookup
X-CST
X-Host
Accept-CH
X-Node
X-WebKit-CSP
X-Backend-Server
Surrogate-Control
X-Server-Id
Permissions-Policy
X-Nginx-Upstream-Cache-Status
X-Readtime
X-Akam-SW-Version
X-Nginx-Cache-Status
Accept-CH-Lifetime
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Application-Context
Request-Id
Xkey
X-Ruxit-JS-Agent
X-Cloud-Trace-Context
X-Content-Security-Policy-Report-Only
X-Response-Time
X-HW
X-Trace
X-Edge
Content-Location
X-Clacks-Overhead
X-Mod-Pagespeed
X-Url
Rating
X-ESI
X-Midtier
X-Amz-Server-Side-Encryption
X-ECACHE
Cache-Tag
X-Mcache
Accept-Ch
X-MS-InvokeApp
X-Powered-By-Plesk
X-Rack-Cache
Service-Worker-Allowed
X-D2id
X-Cdn-Fetch
Verso
X-Exp-Id
X-Kinja-Revision
X-Kinja-Server
X-Use-Magma
X-Kinja-Build
X-Kinja
X-Exp-Variant
X-GoogleNews-Bot
X-Vcap-Request-Id
X-Element-Page-Cache
X-Upstream
Edge-Control
Accept-Ch-Lifetime
X-Country
X-Litespeed-Cache
X-Country-Code
Origin-Trial
RTSS
X-Ac
X-Kinja-CCPA
X-Vname
X-PC
X-TtlSet
X-Goog-Hash
X-VARITI-CCR
X-Navigation-Version
X-Abt-Application-Version
X-Browser-Type
X-Cache-TTL
X-Oneagent-Js-Injection
Fastly-Restarts
X-NWS-LOG-UUID
X-Amz-Rid
X-Aspnetmvc-Version
X-Varnish-TTL
X-Webkit-CSP
X-GitHub-Request-Id
Cross-Origin-Opener-Policy
X-Cached
X-Server-Name
X-Ttl
X-Amzn-Trace-Id
X-Dw-Request-Base-Id
X-WebKit-CSP-Report-Only
Pagespeed
Display
X-Sol
X-Middleton-Display
X-Times
SPRequestGuid
X-SharePointHealthScore
X-Ruxit-Js-Agent
X-Pinterest-Rid
Pinterest-Generated-By
Pinterest-Version
SPIisLatency
SPRequestDuration
X-ORACLE-DMS-RID
X-Erf-Bev-Bev-Is-Generated
X-Server-Lifecycle-Phase
X-ORACLE-DMS-ECID
X-Kraken-Loop-Name
X-Erf-Bev-Bev
X-Instrumentation
X-Cache-Key
X-FastCGI-Cache
X-Content-Type
AR-ATIME
AR-SID
AR-PoweredBy
AR-Request-ID
X-Powered-CMS
X-Client-IP
Arr-Disable-Session-Affinity
X-Version
X-B3-Traceid
X-Mg-S
X-Cnection
Response
X-Middleton-Response
X-Server-ID
Nginx-Cache
X-Ser
X-HP-Webp
X-HP-Trace-Id
X-Jurisdiction
X-Accel-Expires
Cache-Tags
X-T
X-SRCache-Store-Status
X-B3-TraceId
AR-CACHE
X-SRCache-Fetch-Status
X-Fastly-Request-ID
X-RateLimit-Remaining
X-Ua-Device
X-NF-Request-ID
Cache-Status
Edge-Cache-Tag
X-Hits
X-Px
X-MSEdge-Ref
Public-Key-Pins
X-Recruiting
S
Front-End-Https
X-RateLimit-Limit
X-Daa-Tunnel
X-Shield-Request-Id
Payment
X-LLID
Server-Node
X-Frontend
X-Ua-Browser
X-Request-Received
X-Request-Processing-Time
Content-MD5
X-B3-TraceId-Primal
Mrf-Cache-Status
MRF-Tech
X-GUploader-UploadID
X-Goog-Metageneration
MicrosoftSharePointTeamServices
Access-Control-Request-Method
X-Amz-Apigw-Id
X-Content-Digest
X-Amzn-RequestId
X-DIS-Request-ID
X-Webkit-CSP-Report-Only
X-Forwarded-For
TP-Cache
Realpath
X-Protected-By
X-Request-Handler-Origin-Region
X-Distributor
X-Microsite
X-FB-Debug
Fastcgi-Cache
X-Page-Id
X-HS-Cache-Config
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Combine-CSS
X-PressLabs-Stats
Access-Control-Allow-Method
Accept-Charset
X-LB-Cache
X-Rid
X-Cluster-Name
X-Id
X-Xrds-Location
Count-Hit
X-Aspnet-Version
X-Geo-Country
X-B3-Sampled
X-Edge-Location-Klb
X-Kinsta-Cache
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-Goog-Storage-Class
X-TTL
X-Goog-Stored-Content-Length
X-Hostname
Cross-Origin-Resource-Policy
X-Ratelimit-Remaining
TP-L2-Cache
X-Seen-By
X-App-Server
X-Correlation-Id
X-Logged-In
TCN
X-Varnish-Backend
Cleartype
X-Ezoic-Cdn
X-Fastcgi-Cache
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-Hosted-By
X-Git-Hash
X-Mobile
Referer-Policy
X-Content-Options
X-Erf-Stays-Pdp-Viaduct-Migration-Web
Retry-After
DC
X-COUNTRY
X-Fb-Rlafr
X-Contextid
X-Request-Guid
X-Flags
X-Aspnet-Duration-Ms
X-F-Cache
X-Providence-Cookie
X-Is-Crawler
X-Route-Name
X-Origin-Cache
X-Forwarded-Proto
X-Grace
X-Revision
X-Ratelimit-Limit
X-App-Environment
X-TT
Surrogate-Key
X-Amz-Replication-Status
X-Debug-Info
Frame-Options
X-Amz-Meta-S3cmd-Attrs
X-IPS-LoggedIn
X-Newrelic-App-Data
X-Varnish-Grace
X-RateLimit-Reset
X-Azure-Ref
MS-Author-Via
X-Magnolia-Registration
X-Envoy-Decorator-Operation
Section-Io-Cache
X-Www-Served-By
X-App-Version
X-Trace-Id
X-Wix-Request-Id
X-Proxy-Cache-Info
X-Webkit-Csp
X-Language
X-Activity-Id
X-AppVersion
X-Whom
Healthy
X-Az
Charset
Filterid
X-Akamai-Edgescape
WPO-Cache-Message
Viewport
WPO-Cache-Status
X-Origin-Server
Server-Name
Alternate-Protocol
X-Varnish-Server
X-Backend-Name
Amp-Access-Control-Allow-Source-Origin
X-Datadog-Sampling-Priority
X-Kong-Proxy-Latency
X-Datadog-Parent-Id
X-Datadog-Trace-Id
X-Kong-Upstream-Latency
Paypal-Debug-Id
X-EdgeConnect-Cache-Status
Host
X-Original-Request-Id
VIX-Pulpo-Node
X-N
X-Http-Reason
X-Cache-Rule
X-Response-Served-From
VIX-Pulpo-Upstream-Status
X-UUID
X-Nf-Request-Id
X-B
Front
X-Instance
SRV
X-Akamai-Request-ID2
X-Cacheable-TTL
X-Yottaa-Optimizations
X-Edge-Location
X-Cache-Grace
X-Rule
X-DataDome
X-Yottaa-Metrics
X-B-Cache
X-Page-View
Country
From-Origin
X-Signature
X-User-Agent
X-ARC
X-L-Path
X-Load-Cache
X-Framework
X-Environment-Context
X-Unique-Id
Content-Disposition
X-Mg-Request-UUID
SD-X-WS
X-FW-Server
X-Is-Bot
X-FW-Type
X-FW-Version
X-FW-Static
X-RemovedCookies
X-FW-Hash
X-Adobe-Loc
Fastly-SWR
Fastly-SIE
Protected
X-Jobs
X-Region
X-Adobe-Content
Akamai-GRN
X-Status
X-FW-Dynamic
X-Vcache
X-FW-Serve
X-ProcessESI
X-Rendered-As
X-Rocket-Nginx-Serving-Static
X-Tumblr-User
X-Cache-Time
X-Datadog-Sampled
X-G
X-Type
X-Tumblr-Pixel-0
X-Varnish-Age
X-Proxy
X-Tumblr-Pixel-1
X-Tumblr-Pixel
X-Debug-IsPreview
X-Debug-IsConnected
X-Amzn-Remapped-Content-Length
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
Access-Control-Request-Headers
ServerID
X-ECache
X-CDN-Forward
X-Time
X-Tec-Api-Origin
X-Tec-Api-Root
X-Tec-Api-Version
X-Client-Ip
Backend
X-Erf-Web-Scheduler
Refresh
X-Cache-Age
X-DynaTrace
X-Cache-Control
Countrycode
X-Servername
X-Httpd
Url
Xet-Cookie
X-Tt-Trace-Tag
X-Tt-Trace-Host
Accept-Language
X-Template
X-Drupal-Cache-Tags
CF-IPCountry
X-Device-Type
X-Nginx-Cache
X-DynaTrace-JS-Agent
X-Content-Powered-By
X-NYM-Debug-Backend
X-Mode
X-FTR-Request-ID
X-Generated-By
Webserver
X-HTML-Minification-Powered-By
Xserver
X-Cache-Hit
X-Storage
X-CCDN-CacheTTL
X-Hcs-Proxy-Type
GEO-INFO
X-CCDN-Origin-Time
X-Say-Cacheable
X-SayCDN-TTL
X-Content-Age
X-Rn-Rsrv
X-SaId
X-ServerID
X-Rewrite-Enabled
X-XRDS-LOCATION
Load-Balancing
Filters
X-GeoCode
X-GeoCountry
X-Soup
X-LAGOON
X-JoinUs
Meta-Geo
Locale
X-Cache-Operation
X-Say-TTL
X-UPSTREAM-Address
X-Urbn-Site-Id
X-Director
X-Urbn-Context-Path
X-Tncms
X-Source
Onion-Location
X-Container-Uri
X-Loop
X-Varnish-Cache-Hits
X-Git-Commit
X-MCACHE
X-NGENIX-Cache
X-Cache-Action
S-Rt
OT-Force-Account-Verify
X-Forwarded-Host
X-Cluster-Node
X-Served-From
X-Sql-Duration-Ms
X-Varnish-Hostname
Web-Mar-Node
X-Labrador-Cache-Channel
X-Ms-Request-Id
X-RM-Cache-TTL
X-Ms-Version
X-Tt-Logid
Version
X-Detected-As
Azure-RegionName
X-Skip-Cache
Azure-Version
X-Adobe-Source
X-VC-Cache
X-VCT
X-Sql-Count
X-Tb
Azure-InstanceId
X-PHP-Host
X-R9-Blue-Green-Version
Azure-SiteName
Azure-SlotName
Cross-Origin-Window-Policy
Node
DB-Nickname
X-FB-TRIP-ID
X-Zipkin-Id
X-RCS-CacheZone
X-Logging-Id
X-B3-SpanId
X-Extlb
X-Proxied
X-Routing-Service
Mn-Server-Ip
X-Cache-Server
X-Redis-Cache
X-Lambda-Id
X-Generation-Time
Fastcgi-Useragent
TWC-Device-Class
TWC-GeoIP-Country
TWC-Connection-Speed
Selected-Fe
TWC-Locale-Group
X-Format
Property-Id
TWC-Privacy
TWC-GeoIP-LatLong
X-Fetched-On
Webcakes-App-Version
X-Debug
Webcakes-App-Name
X-Tumblr-Pixel-3
X-Uri
X-Tumblr-Pixel-2
Webcakes-Region
X-Proxy-Build
X-Origin-Hint
X-Timing-Wait
X-Proto
X-Endurance-Cache-Level
Uber-Trace-Id
Source
X-Zen-Fury
X-LSADC-Cache
CDN-RequestId
X-Ua
X-Sucuri-ID
X-Sucuri-Cache
X-S
Section-Io-Id
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
Section-Io-Origin-Status
NGB
X-XRDS-Location
X-TimeS
X-Oracle-Dms-Rid
X-Oracle-Dms-Ecid
X-Origin-TTL
X-Origin-CC
X-Akamai-Transformed
X-URL
X-Newrelic-Synthetics
Upgrade-Insecure-Requests
X-Drupal-Cache-Contexts
X-Origin-Date
X-MP-GENERATED-AT
X-Real-IP
X-Pass-Why
X-Handled-By
X-Varnish-Hits
Fastly-Drupal-HTML
X-Cache-Expired-At
X-Ratelimit-Reset
X-TraceId
Apigw-Requestid
X-AB
X-Xfnlog-Site
X-Cms-Context
X-Reqid
X-Optimistic-Header
X-Srv
MS-CV
X-No-Session
X-RTag
Ms-Operation-Id
X-CACHE-AGE
X-Restarts
ServedBy
X-ProxyCache-Key
X-BYPASS-REASON
Liferay-Portal
X-GEO
X-ProxyCache-Status
X-Cache-Host
X-TIME
X-Hl-Ver
X-Geo-Region
X-Tx-Id
WP-Super-Cache
X-Varnish-Ttl
CDN-RequestPullSuccess
X-IPLB-Instance
X-Cluster
X-IPLB-Request-ID
X-VWS-Id
X-Fastly-Request-Id
X-LJ-Flow-ID
X-Cache-Type
X-AWS-Id
CDN-EdgeStorageId
CDN-CachedAt
CDN-PullZone
CDN-RequestCountryCode
CDN-Uid
CDN-RequestPullCode
CDN-Cache
X-Cache-TTL-Remaining
X-UA-Device-Type
Cache-Provider
X-Proxy-Cache-Status
X-Qloud-Router
X-Pubstack
X-CF-Lambda-Fn
X-Ec-GeoHdr
Ngx.Var.Host
X-Pool
X-Upgrade-Enabled
X-PAYTM-SRV-ID
MD5-Digest
Meta-Geo-Continent
N-Cache
Odigeo-Trace-Id
X-Request-Host
X-Ec-Custom-Error
X-ScT
X-Dispatcher-Number
X-Micro-Cache
Redirect-Candidate
X-Ec-Fail
X-Cache-Status-Check
Origin-Agent-Cluster
X-Rojux
X-Parent-Response-Time
X-S-Cookie
X-Owner
Magicmarker
Gannett-Cam-Experience-Id
Fastly-SSL
X-Level-Front-Cache
X-Aed
X-External-Request-Id
X-FC-Vary-Parameters
BehaviorPad-Version
Candidate-Md5Url
Canary
DCR-Decision-By
DCR-Processing-Time-Ms
Ha-Gx-Prefs
HA-Ipaddr
X-App
X-Conf
X-Epic-Correlation-Id
Rendered-Blocks
X-Application
Lang
L5d-Success-Class
X-CGP
X-Eu-Site
X-CF-Lambda-Version
L
X-Generated-On
X-B-Cookie
X-Cache-NE
X-We-Are-Hiring
W
Web-Mar-Region
X-Vtex-Remote-Cache
Vix-Hermes-Req-Id
X-Vdms-Path
X-Vdms-Version
X-D
X-Csrf-Jwt
X-A
X-Worker
X-Bip
X-Bl-Debug
X-A-Dgt
X-A-Wwc
X-BCube-Filmed-By
X-A-Dcw
Xc-Version
X-A-Ccd
X-A-Dam
X-Bc-Bl
True-Client-Country-4JS
X-Viewer-Country
X-Debug-Cache-Store
X-Developer
Sslversion
X-Slack-Backend
X-SRCache-Key
X-Slack-Shared-Secret-Outcome
X-Destination
Server-Host
X-Thanos
X-Debug-Cache-Fetch
T-Server
Surrogated-Key
X-Via-JSL
X-CSRF-Token
Cache-Name
X-Node-Name
CPC-Cache
Fastly-GeoIP-CountryCode
CPC-Age
X-Accel-Expires-Debug
Fastly-Backend-Name
X-DPWN-IS-SECURE
Environment
Platform
Producers
X-Accel-Buffering
X-Dispatcher-Server
Req-Svc-Chain
X-Fastly-Backend
Expect-Staple
We-Hiring
X-Date
Release
Machine
Mail-Subject
Thinkindot-Control
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
X-Core-Value
VNS-Age
Host-ID
TDXMobile
Gh-Request-Id
X-DefHash
Is-Eu
X-DefElseHash
VNS-Cache
X-Forwarded-Path
X-Mvc-Supplant-Cachable
X-Thinkindot-L3
X-Tenant
X-SVT-ORM-VERSION
X-Up
X-Var-Ttl
X-Varnish-CookieHashed-On
X-Variation
X-SVT-ORM-RULES
X-Storefront-Renderer-Rendered
X-Gdpr
X-Shop-Environment
X-ShardId
X-Shopify-Stage
X-Sn-Servicetimems
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
Datacenter
X-Wix-Viewer-Type
X-Wikidot-Static-Cache
X-BBC-Edge-Cache-Status
Origin
X-Cache-Bucket
X-Cache-Info
X-Wikidot-Backend
X-Server-W
X-VG-WebCache
X-VG-TLSProxy
X-Varnishpool
X-Vmg-Version
X-VServer
X-Vgn-Hpd-Reason
X-CacheTTL
X-SD-PageType
X-ShopId
X-Mid
X-Loc
X-Irp-Debug
X-Mly-Id
X-Nananana
X-Cdn-Diag
X-Nitro-Cache
X-Alternate-Cache-Key
Adler-Geo
AKAMAI
X-Geo-Header
X-CMSURLCustom
CloudFront-Viewer-Country
X-GeoIP-Country-Code
X-GeoIP-Region-Code
X-Human
X-Clientip
X-Cache-Debug
X-NodeID
X-ApacheServer
X-Policy
X-Platform
X-Nyt-Route
X-Refresh
X-Cdn-Origin
X-Correlation-ID
X-PERF
X-App-Name
X-Old-Content-Length
X-Origin-Time
X-Request-Time
X-Orig-Expires
X-Accel-Version
X-Tcp-Rtt
X-AIR-PT
X-Browser-Name
X-Is-Tablet
X-Is-Mobile
X-Is-Desktop
X-Is-Supported-Browser
X-Core-Mission
X-Clara-WADP
X-Cache-Id
X-Gzip
X-WADP-Cache
Esi-Enabled
X-WA-Info
X-Server-IP
X-S-Maxage
NM-Fastcgi-Cache
X-Device-Os
X-Org
X-Test
X-Hash
X-GeoIP
X-From
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-INCAP-ABP
X-Mvc-Supplant-OutputCached
X-Hnp-Log
X-Gen-Mode
X-Fmm-Version
X-NCache
X-Nginx-Cache-Key
X-Origin-Response-Time
X-Origin
X-Op-Id-All
X-Node-Id
X-Esi-Check
X-Forwarded-Site
Cmstype
Cmsid
DSUID
Server-Ext
Sever-Int
Server-Hostname
Cf-Device-Type
CDCHOST
X-Ah-Environment
X-Datadome
Apple-News-Services-Handled
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
User-Cache-Control
Apple-News-Services-Request-Url
X-Auto-Login
X-Block-Status
X-B3-Spanid
X-Buckets
Country-Code
X-Section
Server-Info
NGX
X-Cache-Enabled
X-Cdn-Srv
Wxu-Next-Region
X-Vcl-Version
X-LB-NoCache
X-Instance-Name
Wxu-Next-Hostname
C-Via
Wxu-Next-Commit
Ssr
Pics-Label
X-Access
X-Via-Fastly
AMP-Access-Control-Allow-Source-Origin
Content-Secure-Policy
X-Zone
X-CACHE-GROUP
Server-ID
X-Varnish-Beresp-Ttl
X-Varnish-Beresp-Grace
X-Akamai-Device-Characteristics
X-Presslabs-Stats
X-Dc
X-Amz-Meta-Cb-Modifiedtime
X-API-Version
X-Origin-Cache-Key
IsBot
YJS-ID
X-SIPLIST1
X-B3-Parentspanid
X-WP-CF-Super-Cache-Active
X-HA-Backend
CF-Ctrl
X-Platform-Processor
X-Frame-Option
X-Is-Gdpr
X-JWT-State
X-Platform-Router
Hostname
Memcached
X-Has-Esi
X-Platform-Cluster
X-Cached-By
Cdn-Requestid
Sid
Location
X-Internal-Host
Memory
Time
X-FTR-Backend
X-Country-Code-Real
X-FTR-Cache-Status
X-FTR-Expires
X-Wp-Cf-Super-Cache-Active
X-FTR-Balancer
X-FTR-Backend-Server
Origin-EX
X-Scale
X-Air-Trace-Id
Origin-CC
Cache-Hits
X-Air-Hostname
X-Tb-Optimization-Total-Bytes-Saved
X-NewRelic-App-Data
X-Air-Source
X-Hyper-Cache
X-Fpc
X-TIM-N
X-LiteSpeed-Cache-Control
X-TA-CDN-Provider
X-Webstats-RespID
X-Backend-Instance
X-Cs
X-ID
X-NGINX-Cache
X-DC
X-SRV
X-Service
X-ZONE
X-PHP-Backend
Uri
Epwk-X-Cache
X-DataCenter
Resin-Trace
X-VC
LB
X-Azure-Ref-OriginShield
X-Site-Version
GeoIp-Country-Code
X-Nitro-Rev
Cdn-Request-Time
Cdn-Host
X-Nitro-Cache-From
X-NODE
True-Client-Ip
X-Edge-Server
GeoIP-Latitude
X-NMSegId
Req-ID
X-Locale
X-HOST
X-Microcachable
WZWS-RAY
X-CSRF-TOKEN
X-VCache
True-Client-IP
Cache-Host
XServer
X-Ad-Load-Variation
X-Cache-Ttl
GeoIP-Country-Code
X-Origin-Expires
X-Request-URI
X-Scope-Id
M-TraceId
X-Info
X-Request-Start
Pramga
X-Datacenter
X-M-Log
NtCoent-Length
Cdn
X-M-Reqid
XM
X-Geo
X-Shield-Cache-Expires
X-Varnish-Beresp-Status
Cluster
PFcat
WebServer
X-Vercel-Id
X-Qnm-Cache
X-Vercel-Cache
X-Github-Request-Id
X-VarnishDD-TTL
X-Pod-Name
X-Pad
X-HN
SID
X-WP-CF-Super-Cache-Cookies-Bypass
X-FPC
X-Web-Node
User-Agent
Fastly-Drupal-Html
Cache-Tv-Group
Content-Style-Type
X-Ad-Defer-Variation
Content-Script-Type
HostName
X-Cache-Date
X-HostName
Tcn
X-TH-Server
X-LiteSpeed-Tag
Edge-Cache
X-Via-Edge
A
X-Via-CDN
X-Via-SSL
X-FL-QIT-DEBUG
X-FL-EDGE
Locid
Srvid
Edge-Copy-Time
X-MSEdge-Features
X-MSEdge-Flight
X-Cdn-Request-ID
Cf-Ipcountry
CountryCode
X-Api-Version
X-CS
X-APP-VERSION
X-NWS-UUID-VERIFY
X-Webkit-Csp-Report-Only
X-Amz-Meta-Opti
Click-Count-Error
X-B3-Trace-ID
X-Aicache-OS
X-Nc
X-Servedbyhost
X-Wa
X-Acquia-Purge-Cdn-Unconfigured
Tube-Return
X-AK-Request-ID
Tube-Get-Contents
Tube-Got-Eval
Tube-Got-Results
Click-Count-Action-Start
X-Esi
Cdnsip
Cdncip
X-Vary
X-Cache-FS-Status
X-LB-ID
MIME-Version
X-FireWall-Port
X-Branch-Name
X-Moov-Xdn-Version
X-Moov-T
X-Req
X-Cache-ASPX
X-Men
X-Contensis-Viewer-Groups
X-Via-Popv
X-ATG-Version
On-Server
X-Via-Poph
X-Via-Popn
X-V-Cache
X-SB
X-Varnish-Authentication
Path
Priority
X-VCL-Version
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-Proxy-CacheRZ
XkeyRZ
Ngx-Var-Key
V-Age
Cache-Key
Yak-Timeinfo
X-UA
X-CACHE-KEY
CDN
X-Render-Time
X-Tim-N
X-Acquia-Purge-Tags
X-Acquia-Application-UUID
X-Acquia-Application-Trace
X-Acquia-Site
Proxy-Connection
X-Fastly-Backend-Reqs
Srv
My-App
Geoip-Latitude
X-Akamai-Pragma-Client-IP
Wpo-Cache-Message
Wpo-Cache-Status
X-Cdn-Forward
X-Lb-Cache
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-Fastly-Country-Code
X-Generated-In
X-Ha-Backend
X-Provided-By
Lb
Server-Id
X-User
X-Varnish-Director
X-Air-Pt
X-TRACE-ID
X-TT-LOGID
X-CUA
Ohc-Cache-HIT
X-Wp-Cf-Super-Cache
X-Wp-Cf-Super-Cache-Cache-Control
Ohc-File-Size
CF-Cached-On
PICS-Label
X-Planisys-CDN-Rules
X-Lb-Nocache
State
X-Dw-Trace-Id
Fusion-Component-Id
X-Planisys-CDN-Cache
X-Via-Ucdn
X-Planisys-CDN-TTL
Fusion-Content-Source
X-HS-Content-Campaign-Id
Type
X-EC-Lua
X-Platform-Server
Fusion-Template-Id
Fusion-Deployment-Id
Fusion-Source
Fusion-Content-Id
X-Iplb-Instance
X-Iplb-Request-Id
Yjs-Id
Cross-Origin-Embedder-Policy-Report-Only
X-CDN-Cache-Status
Warning
X-Lb-Id
X-GoCache-CacheStatus
X-Cdn-Cache-Status
X-Miniprofiler-Ids
Vha6-Origin
X-Cached-Since
X-ElasticPress-Query
X-Litespeed-Cache-Control
Cache
X-Release
X-Vgn-Hpd-Variations-Key
X-Vgn-Hpd-Ssi
X-Vgn-Hpd-Cached
X-Snapshot-Date
X-Cache-Remote
Ngx
X-Fastly-Cache
Inserted-Into-Cache-At
X-CF-Cache-Header-Cache-Control
X-CF-Cache-Header-Vary
X-Fastly-Cache-Hits
Cneonction
Log-Origin
X-HS-Status
X-RAMCache
X-Udemy-Cache-App-Namespace