Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
X-Powered-By
Pragma
CF-RAY
X-XSS-Protection
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
Alt-Svc
X-Xss-Protection
P3P
X-Cache-Hits
X-UA-Compatible
X-Served-By
CF-Ray
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
Access-Control-Allow-Credentials
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
X-Drupal-Cache
X-Cache-Status
X-Check
X-Generator
X-Cacheable
X-Envoy-Upstream-Service-Time
X-FRAME-OPTIONS
X-Dns-Prefetch-Control
Timing-Allow-Origin
X-Iinfo
X-DNS-Prefetch-Control
Server-Timing
X-Drupal-Dynamic-Cache
Feature-Policy
X-Content-Security-Policy
Access-Control-Expose-Headers
Content-Encoding
X-Ua-Compatible
X-CDN
Status
X-XSS-PROTECTION
Upgrade
X-Request-ID
X-AspNetMvc-Version
Access-Control-Max-Age
X-Via
X-Amz-Request-Id
X-Amz-Id-2
Request-Context
X-Backend
X-Cache-Group
X-Turbo-Charged-By
X-Robots-Tag
Cf-Edge-Cache
Keep-Alive
Host-Header
X-AH-Environment
X-Vhost
X-UA-Device
X-Hacker
X-Proxy-Cache
X-Server
Allow
X-Rq
X-Server-Powered-By
X-Ws-Request-Id
X-Dispatcher
EagleId
X-Age
X-Varnish-Cache
X-Amz-Version-Id
P3p
X-LiteSpeed-Cache
Nel
Grace
Cf-Apo-Via
Cf-Railgun
X-Page-Speed
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
EagleEye-TraceId
X-Device
X-Swift-SaveTime
X-Swift-CacheTime
X-OneAgent-JS-Injection
X-Aws-Lambda-Call-Status
Ali-Swift-Global-Savetime
X-Pingback
X-Host
X-CST
X-Cache-Lookup
Accept-CH
X-WebKit-CSP
X-Node
X-Backend-Server
Surrogate-Control
X-Server-Id
Permissions-Policy
Accept-CH-Lifetime
X-Nginx-Upstream-Cache-Status
X-Readtime
X-Akam-SW-Version
X-Nginx-Cache-Status
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Xkey
X-Application-Context
Request-Id
X-Cloud-Trace-Context
X-Content-Security-Policy-Report-Only
X-Response-Time
X-Ruxit-JS-Agent
X-HW
X-Trace
Content-Location
X-Edge
X-Clacks-Overhead
X-Mod-Pagespeed
X-Url
Rating
X-Midtier
X-ESI
X-Amz-Server-Side-Encryption
X-ECACHE
Cache-Tag
X-Country
X-Mcache
X-Rack-Cache
X-Powered-By-Plesk
X-MS-InvokeApp
Service-Worker-Allowed
X-D2id
X-Exp-Id
X-Use-Magma
X-Exp-Variant
X-Kinja
X-GoogleNews-Bot
X-Kinja-Server
X-Kinja-Build
X-Kinja-Revision
X-Cdn-Fetch
X-Vcap-Request-Id
Verso
X-Oneagent-Js-Injection
X-Upstream
X-Element-Page-Cache
Accept-Ch
Edge-Control
X-Country-Code
Origin-Trial
X-Ac
X-Kinja-CCPA
RTSS
X-PC
X-Vname
X-TtlSet
Accept-Ch-Lifetime
X-Goog-Hash
X-Navigation-Version
X-VARITI-CCR
X-Abt-Application-Version
X-Browser-Type
X-Cache-TTL
X-NWS-LOG-UUID
Fastly-Restarts
X-Amz-Rid
Cross-Origin-Opener-Policy
X-GitHub-Request-Id
X-Ruxit-Js-Agent
X-Aspnetmvc-Version
X-Varnish-TTL
X-Server-Name
X-Cached
X-Litespeed-Cache
X-Webkit-CSP
X-Dw-Request-Base-Id
X-Amzn-Trace-Id
X-Middleton-Display
X-Sol
Display
Pagespeed
X-SharePointHealthScore
X-Ttl
SPRequestGuid
Pinterest-Generated-By
X-Pinterest-Rid
Pinterest-Version
X-Times
X-WebKit-CSP-Report-Only
SPIisLatency
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
SPRequestDuration
X-Instrumentation
X-Erf-Bev-Bev-Is-Generated
X-Server-Lifecycle-Phase
X-Content-Type
X-Erf-Bev-Bev
X-Kraken-Loop-Name
X-Server-ID
X-Cache-Key
X-Client-IP
AR-SID
AR-ATIME
AR-PoweredBy
AR-Request-ID
X-Powered-CMS
X-B3-Traceid
Arr-Disable-Session-Affinity
X-Version
X-Cnection
X-Mg-S
X-Ser
Response
Nginx-Cache
X-Middleton-Response
X-Jurisdiction
X-HP-Webp
X-HP-Trace-Id
X-FastCGI-Cache
X-Accel-Expires
Cache-Tags
X-T
AR-CACHE
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Fastly-Request-ID
Cache-Status
Edge-Cache-Tag
X-Hits
X-B3-TraceId
X-RateLimit-Remaining
X-NF-Request-ID
X-Px
Public-Key-Pins
X-MSEdge-Ref
S
X-Recruiting
X-Daa-Tunnel
Front-End-Https
X-Shield-Request-Id
Payment
X-LLID
X-Frontend
Server-Node
X-Ua-Browser
X-RateLimit-Limit
X-Request-Received
X-Request-Processing-Time
Content-MD5
MRF-Tech
X-B3-TraceId-Primal
Mrf-Cache-Status
X-Goog-Metageneration
X-GUploader-UploadID
X-Content-Digest
MicrosoftSharePointTeamServices
Access-Control-Request-Method
X-Amzn-RequestId
X-Amz-Apigw-Id
X-DIS-Request-ID
X-Forwarded-For
X-Protected-By
Realpath
TP-Cache
X-Fastcgi-Cache
X-Microsite
X-Webkit-CSP-Report-Only
X-Distributor
X-Request-Handler-Origin-Region
X-PressLabs-Stats
X-FB-Debug
Fastcgi-Cache
X-HS-Combine-CSS
X-TTL
X-HS-Cache-Config
X-HS-Content-Id
X-HS-Hub-Id
X-Page-Id
Access-Control-Allow-Method
Accept-Charset
X-Cluster-Name
X-Rid
X-LB-Cache
X-Id
X-Ratelimit-Remaining
Count-Hit
X-Kinsta-Cache
X-Edge-Location-Klb
X-B3-Sampled
X-Geo-Country
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Goog-Generation
Cross-Origin-Resource-Policy
X-Goog-Stored-Content-Length
X-Hostname
X-Xrds-Location
X-Aspnet-Version
X-Ua-Device
TP-L2-Cache
X-App-Server
X-Seen-By
TCN
X-Logged-In
X-Varnish-Backend
X-Git-Hash
Cleartype
X-Hosted-By
X-Mobile
X-Correlation-Id
X-Ezoic-Cdn
X-Ratelimit-Limit
X-Content-Options
Referer-Policy
Retry-After
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
DC
X-Fb-Rlafr
X-Newrelic-App-Data
X-Contextid
X-F-Cache
X-Request-Guid
X-Route-Name
X-Flags
X-Is-Crawler
X-Origin-Cache
X-Forwarded-Proto
X-Aspnet-Duration-Ms
X-Providence-Cookie
X-Grace
X-Revision
Surrogate-Key
X-Amz-Replication-Status
X-TT
X-Erf-Stays-Pdp-Viaduct-Migration-Web
X-App-Environment
X-Debug-Info
Frame-Options
X-Amz-Meta-S3cmd-Attrs
X-Varnish-Grace
X-IPS-LoggedIn
X-Azure-Ref
MS-Author-Via
X-Envoy-Decorator-Operation
X-RateLimit-Reset
Section-Io-Cache
X-Magnolia-Registration
X-Www-Served-By
X-Trace-Id
X-Proxy-Cache-Info
X-App-Version
X-Wix-Request-Id
X-Az
X-AppVersion
X-Activity-Id
Filterid
X-Whom
X-Language
Healthy
Charset
X-Kong-Proxy-Latency
X-Nf-Request-Id
X-Kong-Upstream-Latency
Server-Name
X-Akamai-Edgescape
X-COUNTRY
WPO-Cache-Status
X-Varnish-Server
X-Webkit-Csp
WPO-Cache-Message
Viewport
Alternate-Protocol
X-Origin-Server
X-Datadog-Parent-Id
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
X-Backend-Name
Paypal-Debug-Id
X-N
Host
VIX-Pulpo-Node
X-Cache-Rule
VIX-Pulpo-Upstream-Status
X-Http-Reason
X-Original-Request-Id
X-Response-Served-From
X-B
Content-Disposition
X-EdgeConnect-Cache-Status
Amp-Access-Control-Allow-Source-Origin
X-Yottaa-Optimizations
X-UUID
X-Rule
X-B-Cache
X-Edge-Location
X-Cacheable-TTL
X-Cache-Grace
X-Instance
SRV
X-Yottaa-Metrics
X-User-Agent
X-Akamai-Request-ID2
X-Signature
Front
X-Page-View
X-Time
X-L-Path
X-ARC
X-Region
X-Mg-Request-UUID
X-Jobs
SD-X-WS
X-Load-Cache
X-Environment-Context
From-Origin
Protected
X-Framework
X-Unique-Id
Country
X-Adobe-Content
Akamai-GRN
X-FW-Dynamic
X-Adobe-Loc
X-RemovedCookies
X-Status
X-Rocket-Nginx-Serving-Static
X-Varnish-Age
Fastly-SIE
X-Datadog-Sampled
Fastly-SWR
X-Rendered-As
X-ProcessESI
X-FW-Server
X-FW-Serve
X-FW-Static
X-FW-Version
X-Is-Bot
X-FW-Hash
X-FW-Type
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-Tumblr-User
X-Tec-Api-Version
X-Proxy
X-G
X-Tec-Api-Root
X-Tec-Api-Origin
X-Type
X-Tumblr-Pixel
X-Cache-Time
X-Amzn-Remapped-Content-Length
X-DataDome
X-Debug-IsConnected
X-Debug-IsPreview
X-Vcache
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
Access-Control-Request-Headers
ServerID
X-CDN-Forward
Backend
X-ECache
X-Nginx-Cache
X-Tt-Trace-Tag
X-Cache-Age
X-Tt-Trace-Host
X-Client-Ip
Refresh
X-Servername
X-FTR-Request-ID
Xet-Cookie
Countrycode
Url
X-Httpd
X-Cache-Control
X-DynaTrace
X-Erf-Web-Scheduler
CF-IPCountry
X-Template
Accept-Language
X-XRDS-LOCATION
X-Device-Type
X-Drupal-Cache-Tags
X-DynaTrace-JS-Agent
X-NYM-Debug-Backend
X-Content-Powered-By
X-Mode
X-Generated-By
Webserver
X-HTML-Minification-Powered-By
Xserver
X-Cache-Hit
X-NGENIX-Cache
X-Storage
X-CCDN-Origin-Time
X-CCDN-CacheTTL
X-Hcs-Proxy-Type
Version
X-Tt-Logid
GEO-INFO
X-Rewrite-Enabled
X-Rn-Rsrv
Meta-Geo
X-Urbn-Context-Path
X-SaId
X-Loop
X-Content-Age
X-Tncms
X-LAGOON
Locale
Load-Balancing
Filters
Cross-Origin-Window-Policy
X-GeoCode
X-Say-TTL
X-Director
X-Say-Cacheable
S-Rt
X-UPSTREAM-Address
X-Soup
X-SayCDN-TTL
X-ServerID
X-GeoCountry
X-Cache-Operation
X-JoinUs
X-Urbn-Site-Id
X-Git-Commit
X-Forwarded-Host
X-Container-Uri
X-Varnish-Cache-Hits
X-Cache-Action
X-Cluster-Node
Onion-Location
X-Served-From
OT-Force-Account-Verify
X-URL
Web-Mar-Node
X-R9-Blue-Green-Version
X-VC-Cache
X-Labrador-Cache-Channel
Azure-Version
X-Varnish-Hostname
X-Skip-Cache
X-Tb
X-Sql-Duration-Ms
X-Ms-Version
X-Sql-Count
Azure-SlotName
Azure-SiteName
X-Ms-Request-Id
X-Detected-As
X-PHP-Host
X-Source
Azure-InstanceId
X-Adobe-Source
X-Lambda-Id
Azure-RegionName
X-RM-Cache-TTL
X-VCT
Node
X-Cache-Server
X-Extlb
DB-Nickname
X-Zipkin-Id
Mn-Server-Ip
X-RCS-CacheZone
X-Redis-Cache
X-Routing-Service
X-FB-TRIP-ID
X-Proxied
X-Logging-Id
TWC-Privacy
X-Proxy-Build
Webcakes-App-Version
Webcakes-App-Name
X-Origin-Hint
X-Fetched-On
TWC-Locale-Group
X-Tumblr-Pixel-2
X-Tumblr-Pixel-3
TWC-GeoIP-Country
Webcakes-Region
Property-Id
X-Uri
X-Format
Selected-Fe
TWC-Connection-Speed
TWC-GeoIP-LatLong
X-Generation-Time
TWC-Device-Class
X-Timing-Wait
X-Debug
X-TimeS
Fastcgi-Useragent
X-MCACHE
X-Endurance-Cache-Level
X-Proto
X-B3-SpanId
Source
Uber-Trace-Id
X-LSADC-Cache
X-Zen-Fury
X-Ua
X-S
X-Sucuri-Cache
NGB
X-Sucuri-ID
CDN-RequestId
Section-Io-Origin-Status
Section-Io-Id
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
X-XRDS-Location
X-Varnish-Ttl
Upgrade-Insecure-Requests
X-Ratelimit-Reset
X-Origin-CC
X-TraceId
X-Origin-TTL
X-Real-IP
X-Oracle-Dms-Rid
X-Akamai-Transformed
X-Oracle-Dms-Ecid
X-Drupal-Cache-Contexts
X-Pass-Why
X-Handled-By
X-Newrelic-Synthetics
X-Varnish-Hits
X-Origin-Date
X-MP-GENERATED-AT
X-Srv
Fastly-Drupal-HTML
MS-CV
Ms-Operation-Id
X-RTag
X-Cms-Context
X-AB
X-No-Session
X-Reqid
X-Optimistic-Header
X-Cache-Expired-At
X-Xfnlog-Site
Apigw-Requestid
X-Restarts
ServedBy
X-BYPASS-REASON
X-Cache-Host
X-ProxyCache-Status
X-ProxyCache-Key
X-Geo-Region
Liferay-Portal
WP-Super-Cache
X-IPLB-Request-ID
X-CACHE-AGE
X-AWS-Id
X-LJ-Flow-ID
X-Hl-Ver
X-IPLB-Instance
X-Cluster
X-Correlation-ID
X-VWS-Id
CDN-PullZone
CDN-EdgeStorageId
X-GEO
X-CSRF-Token
CDN-Cache
CDN-CachedAt
CDN-RequestCountryCode
CDN-RequestPullSuccess
CDN-RequestPullCode
CDN-Uid
X-Cache-Type
X-Proxy-Cache-Status
Cache-Provider
X-Tx-Id
X-UA-Device-Type
X-Cache-TTL-Remaining
X-Upgrade-Enabled
X-Node-Name
X-Cache-Status-Check
X-Fastly-Request-Id
X-Via-JSL
X-Conf
X-Cache-NE
X-CacheTTL
Candidate-Md5Url
X-CF-Lambda-Version
X-CGP
Canary
X-CF-Lambda-Fn
Cache-Name
X-Application
X-B-Cookie
X-Debug-Cache-Store
X-Ec-Custom-Error
X-Ec-Fail
X-Ec-GeoHdr
X-Epic-Correlation-Id
X-BCube-Filmed-By
X-Bip
X-Level-Front-Cache
X-Developer
X-Dispatcher-Number
X-Bl-Debug
X-Eu-Site
X-External-Request-Id
X-FC-Vary-Parameters
BehaviorPad-Version
X-Bc-Bl
X-Csrf-Jwt
X-Micro-Cache
X-D
X-Fastly-Backend
X-Destination
X-Debug-Cache-Fetch
X-Generated-On
X-Owner
Magicmarker
X-Thanos
MD5-Digest
Meta-Geo-Continent
Ngx.Var.Host
N-Cache
True-Client-Country-4JS
Vix-Hermes-Req-Id
X-Slack-Shared-Secret-Outcome
X-Slack-Backend
L5d-Success-Class
X-SRCache-Key
Lang
Odigeo-Trace-Id
X-Vdms-Path
Server-Host
Sslversion
X-Worker
Xc-Version
Redirect-Candidate
Rendered-Blocks
X-We-Are-Hiring
X-Vtex-Remote-Cache
Origin-Agent-Cluster
X-Vdms-Version
X-Viewer-Country
T-Server
Surrogated-Key
W
L
X-A-Dam
X-PAYTM-SRV-ID
X-A-Ccd
X-Pool
X-Qloud-Router
X-Pubstack
X-A-Dcw
X-A-Dgt
X-Aed
X-App
DCR-Decision-By
DCR-Processing-Time-Ms
X-A-Wwc
Fastly-SSL
X-A
Web-Mar-Region
X-Rojux
X-ScT
Ha-Gx-Prefs
HA-Ipaddr
X-Request-Host
Gannett-Cam-Experience-Id
X-S-Cookie
X-B3-Spanid
VNS-Age
X-Accel-Expires-Debug
X-Cdn-Diag
X-ApacheServer
Req-Svc-Chain
X-Cache-Info
X-Alternate-Cache-Key
X-Cache-Debug
VNS-Cache
Thinkindot-Control
Thinkindot-CacheControl
X-Cache-Bucket
TDXMobile
We-Hiring
X-BBC-Edge-Cache-Status
Thinkindot-CacheControl-Type
X-App-Name
X-Irp-Debug
X-Storefront-Renderer-Rendered
X-Sorting-Hat-ShopId
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-Thinkindot-L3
X-Tenant
X-Sorting-Hat-PodId
X-Sn-Servicetimems
X-Server-IP
X-SD-PageType
X-ShardId
X-Shop-Environment
X-Shopify-Stage
X-ShopId
X-Up
X-Var-Ttl
X-Wikidot-Backend
X-VServer
X-Wikidot-Static-Cache
Datacenter
X-Hash
Origin
X-Vmg-Version
X-VG-WebCache
X-Varnish-CookieHashed-On
X-Variation
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
X-VG-TLSProxy
X-Varnishpool
X-Request-Time
X-Refresh
X-Gdpr
X-Forwarded-Path
X-Geo-Header
X-GeoIP-Country-Code
X-Human
X-GeoIP-Region-Code
X-DPWN-IS-SECURE
X-Dispatcher-Server
X-Core-Mission
X-CMSURLCustom
X-Core-Value
X-Date
X-DefHash
X-DefElseHash
Release
X-Loc
X-Orig-Expires
X-Old-Content-Length
X-Origin-Time
X-PERF
X-Policy
X-Platform
X-Nyt-Route
X-NodeID
X-Mly-Id
X-Mid
X-Mvc-Supplant-Cachable
X-Nananana
X-Nitro-Cache
X-Clientip
X-Cdn-Origin
Cmstype
CPC-Age
Cmsid
CloudFront-Viewer-Country
AKAMAI
CPC-Cache
Environment
Gh-Request-Id
Fastly-GeoIP-CountryCode
Fastly-Backend-Name
Expect-Staple
Adler-Geo
X-AIR-PT
X-Vgn-Hpd-Reason
X-Server-W
X-Datadome
Producers
X-Browser-Name
X-Is-Desktop
X-Parent-Response-Time
X-Tcp-Rtt
X-Is-Tablet
X-Is-Mobile
Host-ID
X-Is-Supported-Browser
Platform
Is-Eu
Machine
Mail-Subject
X-TIME
AMP-Access-Control-Allow-Source-Origin
X-Accel-Version
X-INCAP-ABP
X-Hnp-Log
X-Gzip
NM-Fastcgi-Cache
X-Mvc-Supplant-OutputCached
Apple-News-Services-Handled
X-Nginx-Cache-Key
X-NCache
Server-Hostname
X-Cache-Id
X-GeoIP
X-Clara-WADP
X-Test
X-Wix-Viewer-Type
X-Esi-Check
X-Device-Os
X-Org
X-Fmm-Version
Esi-Enabled
X-Block-Status
X-Gen-Mode
X-From
X-Forwarded-Site
Sever-Int
Apple-News-Services-Parsed-Url
Country-Code
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
Server-Ext
Apple-News-Services-Host
X-S-Maxage
X-WADP-Cache
User-Cache-Control
X-WA-Info
DSUID
X-Accel-Buffering
X-Origin-Response-Time
Cf-Device-Type
CDCHOST
X-Node-Id
X-Op-Id-All
Apple-News-Services-Request-Url
X-Auto-Login
X-Origin
X-Buckets
X-Vcl-Version
X-Origin-Cache-Key
X-Ah-Environment
Pics-Label
Wxu-Next-Commit
X-Via-Fastly
X-LB-NoCache
X-Section
X-Instance-Name
C-Via
X-Access
NGX
X-Cdn-Srv
Server-Info
Wxu-Next-Hostname
X-Cache-Enabled
Wxu-Next-Region
Ssr
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Ttl
X-Zone
X-Dc
Content-Secure-Policy
Server-ID
X-Amz-Meta-Cb-Modifiedtime
X-API-Version
IsBot
YJS-ID
X-SIPLIST1
X-HA-Backend
X-CACHE-GROUP
X-Akamai-Device-Characteristics
X-Presslabs-Stats
CF-Ctrl
Cdn-Requestid
X-WP-CF-Super-Cache-Active
X-B3-Parentspanid
X-Frame-Option
X-Cached-By
X-FTR-Backend-Server
X-Country-Code-Real
X-FTR-Backend
X-FTR-Cache-Status
X-FTR-Balancer
X-Platform-Cluster
X-FTR-Expires
X-Platform-Router
Sid
X-Platform-Processor
X-TA-CDN-Provider
X-JWT-State
Location
X-Is-Gdpr
X-Internal-Host
Memcached
X-Has-Esi
Cache-Hits
X-Air-Source
X-Air-Trace-Id
X-Air-Hostname
Memory
Hostname
X-TIM-N
X-LiteSpeed-Cache-Control
X-Fpc
Time
X-Wp-Cf-Super-Cache-Active
X-Scale
X-Hyper-Cache
X-Webstats-RespID
Origin-EX
Origin-CC
X-Tb-Optimization-Total-Bytes-Saved
X-Backend-Instance
X-Service
X-ID
X-DC
X-VC
X-Cs
X-SRV
X-PHP-Backend
X-ZONE
True-Client-Ip
X-Site-Version
Epwk-X-Cache
Resin-Trace
X-NewRelic-App-Data
X-VCache
X-DataCenter
LB
Cdn-Host
Cdn-Request-Time
X-NGINX-Cache
Uri
WZWS-RAY
X-Azure-Ref-OriginShield
X-Locale
Req-ID
X-Esi
X-NMSegId
GeoIp-Country-Code
X-Edge-Server
X-Webkit-Csp-Report-Only
X-Ad-Load-Variation
GeoIP-Latitude
X-Microcachable
X-Nitro-Cache-From
X-Nitro-Rev
X-NODE
X-Request-URI
GeoIP-Country-Code
X-Datacenter
XServer
X-Geo
X-M-Log
X-Request-Start
X-M-Reqid
X-Scope-Id
X-Origin-Expires
Pramga
X-Cache-Ttl
Cache-Host
HostName
X-CSRF-TOKEN
NtCoent-Length
True-Client-IP
M-TraceId
XM
Content-Style-Type
X-Shield-Cache-Expires
Cdn
Cluster
X-Vercel-Id
X-Info
X-Vercel-Cache
SID
X-Qnm-Cache
X-Varnish-Beresp-Status
Content-Script-Type
Cache-Tv-Group
X-Cache-Date
X-WP-CF-Super-Cache-Cookies-Bypass
WebServer
X-HN
X-Pad
PFcat
X-Github-Request-Id
X-VarnishDD-TTL
X-Pod-Name
Fastly-Drupal-Html
X-LiteSpeed-Tag
X-TH-Server
X-Ad-Defer-Variation
X-Web-Node
User-Agent
X-FPC
X-HostName
Tcn
A
X-V-Cache
X-Nc
X-LB-ID
X-Via-Poph
X-Servedbyhost
X-Wa
Locid
X-Via-Popv
X-Cache-FS-Status
X-Via-Popn
Edge-Copy-Time
Srvid
Tube-Return
X-FL-QIT-DEBUG
X-FL-EDGE
X-MSEdge-Features
X-MSEdge-Flight
X-Via-Edge
X-Via-CDN
Click-Count-Action-Start
Click-Count-Error
X-Acquia-Purge-Cdn-Unconfigured
X-Aicache-OS
X-Via-SSL
Tube-Got-Results
Tube-Get-Contents
Tube-Got-Eval
X-B3-Trace-ID
X-APP-VERSION
CountryCode
X-Api-Version
X-CS
Cf-Ipcountry
X-Cdn-Request-ID
Priority
X-Req
X-Vary
Edge-Cache
X-Men
X-SB
X-Amz-Meta-Opti
Cdnsip
Cdncip
X-AK-Request-ID
X-NWS-UUID-VERIFY
V-Age
On-Server
X-Contensis-Viewer-Groups
X-Cache-ASPX
X-Akamai-Pragma-Client-IP
X-Varnish-Authentication
X-Moov-T
Path
X-ATG-Version
X-FireWall-Port
Ngx-Var-Key
X-Branch-Name
X-Moov-Xdn-Version
MIME-Version
X-VCL-Version
X-Wp-Cf-Super-Cache-Cookies-Bypass
My-App
X-Fastly-Backend-Reqs
X-Proxy-CacheRZ
XkeyRZ
Yak-Timeinfo
Cache-Key
Lb
X-Provided-By
X-UA
CDN
X-CACHE-KEY
X-Tim-N
X-Render-Time
X-Acquia-Site
X-Fastly-Country-Code
X-Cdn-Forward
Proxy-Connection
Wpo-Cache-Message
X-Varnish-Director
Wpo-Cache-Status
Geoip-Latitude
Srv
X-Acquia-Application-Trace
X-Acquia-Application-UUID
X-Acquia-Purge-Tags
Cache
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-Lb-Cache
X-User
X-Air-Pt
X-Ha-Backend
Server-Id
X-Generated-In
X-TT-LOGID
X-TRACE-ID
PICS-Label
X-Wp-Cf-Super-Cache-Cache-Control
Cross-Origin-Embedder-Policy-Report-Only
Ohc-Cache-HIT
X-Wp-Cf-Super-Cache
X-Cdn-Cache-Status
X-Dw-Trace-Id
X-Via-Ucdn
X-Planisys-CDN-Cache
X-Check-Cacheable
Ohc-File-Size
State
X-Lb-Nocache
X-Platform-Server
X-Serial
CF-Cached-On
X-HS-Content-Campaign-Id
X-EC-Lua
X-Planisys-CDN-TTL
X-GoCache-CacheStatus
X-Planisys-CDN-Rules
X-CUA
X-GeoIP-City
X-Gamma-Serve
X-Upstream-Ht
X-Iplb-Instance
X-Iplb-Request-Id
Yjs-Id
X-TX-ID
X-Upstream-Ct
X-Release
X-Mg-Cache
Fusion-Component-Id
Vha6-Origin
Fusion-Content-Id
Fusion-Template-Id
Mime-Version
Warning
X-CDN-Cache-Status
Type
Fusion-Deployment-Id
Fusion-Source
Fusion-Content-Source
Log-Origin
X-Miniprofiler-Ids
X-Udemy-Cache-App-Namespace
X-Snapshot-Date
X-CF-Cache-Header-Vary
X-CF-Cache-Header-Cache-Control
Cneonction
X-Fastly-Cache-Hits
X-Fastly-Cache
X-RAMCache
X-HS-Status
X-Cache-Remote
X-Litespeed-Cache-Control
X-ElasticPress-Query
Ngx
X-Vgn-Hpd-Variations-Key
X-Vgn-Hpd-Cached
X-Vgn-Hpd-Ssi
Inserted-Into-Cache-At
X-Cached-Since