Threat Level: green Handler on Duty: Russ McRee

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
X-Powered-By
Pragma
X-XSS-Protection
X-Cache
CF-RAY
Via
Age
Content-Security-Policy
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
Alt-Svc
P3P
X-Cache-Hits
X-UA-Compatible
X-Xss-Protection
CF-Ray
X-Served-By
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
Access-Control-Allow-Credentials
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
X-Drupal-Cache
X-Generator
X-Cache-Status
X-Check
X-Cacheable
X-FRAME-OPTIONS
X-Envoy-Upstream-Service-Time
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Iinfo
X-Dns-Prefetch-Control
X-Drupal-Dynamic-Cache
Feature-Policy
X-Content-Security-Policy
Content-Encoding
X-XSS-PROTECTION
Access-Control-Expose-Headers
Upgrade
Server-Timing
X-CDN
Status
X-Request-ID
X-AspNetMvc-Version
Access-Control-Max-Age
X-Amz-Request-Id
Request-Context
X-Amz-Id-2
X-Via
X-Turbo-Charged-By
X-Backend
X-Cache-Group
X-Robots-Tag
Cf-Edge-Cache
Keep-Alive
Host-Header
X-AH-Environment
X-Hacker
X-Proxy-Cache
X-UA-Device
X-Server
X-Vhost
X-Rq
X-Server-Powered-By
Allow
X-Age
X-Varnish-Cache
X-Ws-Request-Id
X-Dispatcher
X-Amz-Version-Id
EagleId
P3p
Nel
Grace
Cf-Apo-Via
X-LiteSpeed-Cache
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Page-Speed
X-Device
Cf-Railgun
EagleEye-TraceId
X-Aws-Lambda-Call-Status
X-Swift-SaveTime
X-Swift-CacheTime
X-OneAgent-JS-Injection
X-Pingback
Ali-Swift-Global-Savetime
X-Host
X-Node
X-WebKit-CSP
Accept-CH
X-CST
X-Backend-Server
Surrogate-Control
X-Cache-Lookup
X-Server-Id
X-Nginx-Cache-Status
X-Readtime
Permissions-Policy
X-Akam-SW-Version
X-Nginx-Upstream-Cache-Status
Request-Id
X-Application-Context
X-Content-Security-Policy-Report-Only
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
Accept-CH-Lifetime
X-Cloud-Trace-Context
X-Ua-Compatible
X-Trace
X-Response-Time
X-HW
X-Edge
Content-Location
X-Clacks-Overhead
X-Mod-Pagespeed
Xkey
X-Litespeed-Cache
Rating
X-Midtier
Accept-Ch
X-ESI
X-Ruxit-JS-Agent
X-Url
X-Amz-Server-Side-Encryption
X-ECACHE
Accept-Ch-Lifetime
X-Mcache
X-Upstream
X-Ruxit-Js-Agent
X-Vcap-Request-Id
X-Country
Cache-Tag
X-D2id
X-MS-InvokeApp
X-Kinja
X-GoogleNews-Bot
X-Exp-Variant
X-Kinja-Build
X-Kinja-Revision
Verso
X-Use-Magma
X-Kinja-Server
X-Cdn-Fetch
X-Exp-Id
X-Rack-Cache
X-Element-Page-Cache
X-TtlSet
X-PC
X-Powered-By-Plesk
X-Vname
Edge-Control
RTSS
Fastly-Restarts
X-Cache-TTL
X-Oneagent-Js-Injection
X-Ac
X-VARITI-CCR
X-WebKit-CSP-Report-Only
Origin-Trial
X-Navigation-Version
X-Abt-Application-Version
X-Country-Code
Service-Worker-Allowed
X-Goog-Hash
X-Cached
X-Ttl
X-Varnish-TTL
X-Sol
X-Middleton-Display
Pagespeed
X-Amz-Rid
Display
X-Browser-Type
Cross-Origin-Opener-Policy
X-GitHub-Request-Id
X-Dw-Request-Base-Id
X-SharePointHealthScore
SPRequestGuid
X-Server-Name
X-Content-Type
X-Mg-S
X-Amzn-Trace-Id
X-B3-TraceId
X-Powered-CMS
Arr-Disable-Session-Affinity
AR-PoweredBy
AR-ATIME
AR-SID
X-Middleton-Response
AR-Request-ID
Response
X-Server-Lifecycle-Phase
X-Erf-Bev-Bev
X-Instrumentation
X-Kraken-Loop-Name
X-Erf-Bev-Bev-Is-Generated
X-Kinja-CCPA
X-NF-Request-ID
SPIisLatency
SPRequestDuration
X-Webkit-CSP
X-Cache-Key
X-Times
X-NWS-LOG-UUID
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-Version
Pinterest-Generated-By
X-Pinterest-Rid
Pinterest-Version
AR-CACHE
X-Jurisdiction
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-HP-Trace-Id
X-HP-Webp
X-Accel-Expires
X-T
Cache-Tags
X-Cnection
X-Server-ID
Cache-Status
X-Aspnetmvc-Version
Front-End-Https
Nginx-Cache
X-MSEdge-Ref
Edge-Cache-Tag
X-Hits
X-B3-Traceid
X-Ser
X-Fastly-Request-ID
X-Px
X-RateLimit-Remaining
MRF-Tech
Mrf-Cache-Status
X-B3-TraceId-Primal
X-Fastcgi-Cache
X-FastCGI-Cache
Payment
Public-Key-Pins
X-Recruiting
X-LLID
X-Request-Received
X-Request-Processing-Time
X-Frontend
Server-Node
X-Ua-Browser
X-Client-IP
X-Shield-Request-Id
X-RateLimit-Limit
X-DIS-Request-ID
X-Erf-Stays-Pdp-Viaduct-Migration-Web
S
TP-Cache
X-GUploader-UploadID
X-Goog-Metageneration
MicrosoftSharePointTeamServices
Access-Control-Request-Method
X-Amzn-RequestId
Content-MD5
X-Amz-Apigw-Id
X-HS-Cache-Config
X-HS-Content-Id
X-HS-Hub-Id
X-HS-Combine-CSS
X-Content-Digest
X-Request-Handler-Origin-Region
X-Distributor
X-Microsite
X-Protected-By
X-LB-Cache
X-FB-Debug
Access-Control-Allow-Method
X-Page-Id
Realpath
TP-L2-Cache
Accept-Charset
X-Geo-Country
Fastcgi-Cache
X-Ezoic-Cdn
X-Cluster-Name
X-Forwarded-For
X-Rid
X-PressLabs-Stats
X-Webkit-Csp
X-Hostname
X-B3-Sampled
X-Aspnet-Version
X-Ratelimit-Remaining
X-Ua-Device
X-Seen-By
X-Correlation-Id
Cleartype
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
Referer-Policy
X-Client-Ip
X-Daa-Tunnel
X-Goog-Storage-Class
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Envoy-Decorator-Operation
X-Newrelic-App-Data
Cross-Origin-Resource-Policy
X-Mobile
DC
TCN
X-Ratelimit-Limit
X-Content-Options
Count-Hit
X-Debug-Info
X-Varnish-Backend
X-TTL
X-Origin-Cache
X-Logged-In
X-Varnish-Grace
X-Contextid
X-App-Server
X-Route-Name
X-App-Environment
X-Amz-Replication-Status
Surrogate-Key
X-Hosted-By
X-Revision
X-Request-Guid
X-Git-Hash
X-IPS-LoggedIn
X-Providence-Cookie
X-Flags
X-Aspnet-Duration-Ms
X-Fb-Rlafr
X-Is-Crawler
X-Grace
X-Azure-Ref
X-TT
Frame-Options
X-Amz-Meta-S3cmd-Attrs
X-Origin-Server
X-Edge-Location-Klb
X-Kinsta-Cache
X-Forwarded-Proto
Retry-After
Alternate-Protocol
X-Wix-Request-Id
WPO-Cache-Message
WPO-Cache-Status
X-XRDS-Location
X-Whom
X-F-Cache
Healthy
Charset
X-Magnolia-Registration
X-Akamai-Edgescape
Viewport
X-RateLimit-Reset
X-Backend-Name
Section-Io-Cache
MS-Author-Via
X-COUNTRY
X-B
Paypal-Debug-Id
X-Id
X-Proxy-Cache-Info
ServerID
X-App-Version
X-Webkit-CSP-Report-Only
SRV
X-Activity-Id
X-AppVersion
X-Az
Amp-Access-Control-Allow-Source-Origin
X-Language
X-N
X-Rule
X-Cache-Rule
Akamai-GRN
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-Original-Request-Id
X-Http-Reason
X-Instance
X-ARC
X-Response-Served-From
SD-X-WS
Host
Front
Protected
X-DataDome
X-Cache-Grace
X-Edge-Location
X-Status
X-Rocket-Nginx-Serving-Static
Filterid
X-Www-Served-By
X-Varnish-Age
X-User-Agent
X-Akamai-Request-ID2
X-Load-Cache
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Framework
X-Environment-Context
X-FW-Dynamic
X-Unique-Id
X-Cacheable-TTL
X-Varnish-Server
Country
Fastly-SIE
X-FW-Version
X-FW-Type
Fastly-SWR
X-Rendered-As
X-Is-Bot
X-Page-View
X-L-Path
X-Jobs
X-FW-Hash
From-Origin
X-FW-Static
X-FW-Server
X-FW-Serve
X-UUID
X-Region
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
X-Type
X-EdgeConnect-Cache-Status
Server-Name
X-Cache-Time
X-Datadog-Parent-Id
X-Adobe-Loc
X-Adobe-Content
Access-Control-Request-Headers
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-Tumblr-Pixel
X-Cache-Control
X-G
X-ProcessESI
X-RemovedCookies
X-Trace-Id
X-Time
X-Tumblr-User
X-Cache-Age
X-Proxy
X-Xrds-Location
X-Yottaa-Optimizations
X-Vcache
X-Yottaa-Metrics
Refresh
X-Datadog-Sampled
X-Mg-Request-UUID
X-ECache
X-Amzn-Remapped-Content-Length
X-CDN-Forward
X-Debug-IsPreview
X-Debug-IsConnected
X-Source
X-Oracle-Dms-Ecid
Content-Disposition
X-B-Cache
X-Signature
X-Oracle-Dms-Rid
X-Drupal-Cache-Tags
X-Erf-Web-Scheduler
Backend
Xet-Cookie
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
Accept-Language
Version
X-Generated-By
Countrycode
X-HTML-Minification-Powered-By
X-DynaTrace
CF-IPCountry
X-DynaTrace-JS-Agent
X-Servername
Webserver
X-Nginx-Cache
X-Httpd
X-Mode
Url
X-Upgrade-Enabled
X-Tt-Trace-Host
X-Tt-Trace-Tag
Xserver
X-ID
GEO-INFO
X-Storage
X-Device-Type
X-Content-Age
X-NYM-Debug-Backend
X-Template
X-Fastly-Request-Id
Azure-SlotName
Azure-Version
Meta-Geo
Filters
Load-Balancing
Locale
X-Cache-Action
Azure-InstanceId
X-UPSTREAM-Address
X-GeoCode
X-Tb
X-Cache-Operation
X-Director
Azure-RegionName
Onion-Location
S-Rt
Azure-SiteName
X-JoinUs
X-URL
Fastcgi-Useragent
X-Varnish-Cache-Hits
X-Urbn-Site-Id
X-Urbn-Context-Path
X-Rewrite-Enabled
X-SaId
X-Say-Cacheable
X-Say-TTL
X-SayCDN-TTL
X-ServerID
X-XRDS-LOCATION
X-Proto
X-GeoCountry
X-LAGOON
X-PHP-Host
X-VC-Cache
X-Container-Uri
X-Forwarded-Host
X-RM-Cache-TTL
Uber-Trace-Id
X-MCACHE
X-Content-Powered-By
X-Soup
X-Cluster-Node
X-Git-Commit
OT-Force-Account-Verify
X-Labrador-Cache-Channel
X-Varnish-Hostname
X-Ms-Request-Id
X-Logging-Id
Web-Mar-Node
X-Detected-As
X-Ms-Version
X-Sql-Duration-Ms
X-LSADC-Cache
X-VCT
X-Generation-Time
X-Cache-Server
X-Sql-Count
X-Tt-Logid
X-Served-From
X-Adobe-Source
Property-Id
X-Routing-Service
X-Lambda-Id
Mn-Server-Ip
X-Zen-Fury
X-Skip-Cache
Node
X-Zipkin-Id
X-Proxied
X-Sucuri-Cache
Webcakes-Region
Webcakes-App-Version
X-Debug
X-Sucuri-ID
X-Extlb
X-FB-TRIP-ID
Webcakes-App-Name
X-Origin-Hint
TWC-GeoIP-Country
TWC-Device-Class
X-RCS-CacheZone
X-R9-Blue-Green-Version
TWC-Privacy
TWC-Locale-Group
TWC-Connection-Speed
TWC-GeoIP-LatLong
X-Tec-Api-Root
DB-Nickname
X-Tec-Api-Origin
X-Tec-Api-Version
Selected-Fe
X-Proxy-Build
X-Fetched-On
X-Timing-Wait
X-Tumblr-Pixel-3
X-Tumblr-Pixel-2
X-Format
X-Uri
X-Drupal-Cache-Contexts
X-B3-SpanId
X-Tncms
X-Loop
CDN-RequestId
X-Rn-Rsrv
Liferay-Portal
X-Cache-Hit
X-Endurance-Cache-Level
X-CCDN-CacheTTL
Source
X-CCDN-Origin-Time
X-Hcs-Proxy-Type
X-Nf-Request-Id
X-Redis-Cache
X-Ua
Cross-Origin-Window-Policy
X-Varnish-Ttl
X-MP-GENERATED-AT
X-Origin-Date
X-TimeS
Fastly-Drupal-HTML
X-Srv
X-Varnish-Hits
Section-Io-Origin-Status
Section-Io-Id
Section-Io-Origin-Time-Seconds
X-Ratelimit-Reset
Section-Origin-Responded
X-Pass-Why
X-Cache-Expired-At
Upgrade-Insecure-Requests
X-S
X-Real-IP
Content-Secure-Policy
X-Origin-TTL
X-Origin-CC
X-UA-Device-Type
X-CACHE-AGE
X-Akamai-Transformed
X-Cache-TTL-Remaining
X-Newrelic-Synthetics
X-Node-Name
X-Pubstack
CDN-EdgeStorageId
CDN-CachedAt
CDN-Cache
CDN-PullZone
X-GEO
CDN-RequestPullSuccess
CDN-RequestCountryCode
CDN-RequestPullCode
CDN-Uid
X-Server-W
X-Via-JSL
X-Webkit-Csp-Report-Only
Cache-Provider
X-Handled-By
NGB
X-Presslabs-Stats
Ms-Operation-Id
MS-CV
X-NGENIX-Cache
X-Hl-Ver
X-RTag
X-CSRF-Token
WP-Super-Cache
Apigw-Requestid
X-Reqid
X-Xfnlog-Site
X-IPLB-Request-ID
X-IPLB-Instance
X-Restarts
X-Cache-Type
X-Optimistic-Header
Canary
X-Conf
X-CF-Lambda-Fn
X-Destination
X-Developer
X-Dispatcher-Number
X-Epic-Correlation-Id
X-Ec-GeoHdr
X-Ec-Fail
X-Ec-Custom-Error
X-Csrf-Jwt
X-D
BehaviorPad-Version
Candidate-Md5Url
X-Date
X-External-Request-Id
X-CGP
X-CF-Lambda-Version
X-FC-Vary-Parameters
X-Eu-Site
X-Cms-Context
X-Fastly-Backend
X-B-Cookie
X-A-Dcw
Ngx.Var.Host
X-A-Dam
Odigeo-Trace-Id
X-A-Ccd
X-A-Dgt
N-Cache
Mail-Subject
Magicmarker
MD5-Digest
X-A-Wwc
Meta-Geo-Continent
Origin-Agent-Cluster
X-A
True-Client-Country-4JS
Rendered-Blocks
Server-Host
T-Server
Surrogated-Key
Vix-Hermes-Req-Id
Redirect-Candidate
We-Hiring
Web-Mar-Region
W
VNS-Cache
VNS-Age
X-Accel-Expires-Debug
X-Aed
DCR-Processing-Time-Ms
DCR-Decision-By
X-Bl-Debug
X-BCube-Filmed-By
X-Bc-Bl
X-Cache-Bucket
CPC-Cache
X-Cache-NE
X-CacheTTL
X-Cache-Info
X-Cache-Host
CPC-Age
X-Forwarded-Path
Fastly-Backend-Name
X-App
HA-Ipaddr
L
L5d-Success-Class
Lang
Ha-Gx-Prefs
Gh-Request-Id
Fastly-GeoIP-CountryCode
Fastly-SSL
Gannett-Cam-Experience-Id
X-Application
X-Cdn-Diag
X-Mvc-Supplant-Cachable
X-S-Cookie
X-Rojux
X-ScT
X-SD-PageType
X-Slack-Backend
X-Shop-Environment
ServedBy
X-RateLimit-Remaining-Second
X-Origin-Time
X-Orig-Expires
X-Policy
X-Parent-Response-Time
X-RateLimit-Limit-Second
X-Slack-Shared-Secret-Outcome
X-SRCache-Key
X-We-Are-Hiring
X-Vtex-Remote-Cache
X-Wikidot-Backend
X-Wikidot-Static-Cache
Xc-Version
X-Worker
X-Viewer-Country
X-VG-WebCache
X-AIR-PT
X-Tenant
X-Var-Ttl
X-Vdms-Path
X-Vdms-Version
X-Nyt-Route
X-Request-Host
X-Has-Esi
X-Is-Gdpr
X-GeoIP-Region-Code
X-GeoIP-Country-Code
X-Gdpr
Sslversion
X-JWT-State
X-ProxyCache-Status
X-No-Session
X-Tx-Id
X-BYPASS-REASON
X-Vcl-Version
X-TIME
Cache-Name
X-ProxyCache-Key
X-Up
X-Accel-Buffering
X-Human
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-Thinkindot-L3
X-Variation
X-INCAP-ABP
X-Test
X-SVT-ORM-RULES
X-DPWN-IS-SECURE
X-Varnish-Remaining-TTL
X-Thanos
X-SVT-ORM-VERSION
X-Storefront-Renderer-Rendered
X-Alternate-Cache-Key
X-NodeID
Thinkindot-Control
X-Wix-Viewer-Type
X-Generated-On
X-Fmm-Version
Thinkindot-CacheControl-Type
X-Nitro-Cache
TDXMobile
Thinkindot-CacheControl
X-Geo-Header
X-Node-Id
X-VG-TLSProxy
X-ApacheServer
X-Hash
X-Esi-Check
X-Gzip
X-WADP-Cache
X-VServer
X-Vmg-Version
X-Varnishpool
X-Sorting-Hat-PodId
X-Pool
X-Cdn-Origin
X-Platform
X-Debug-Cache-Fetch
X-Qloud-Router
X-Cache-Id
X-Mid
X-Mly-Id
X-PERF
X-PAYTM-SRV-ID
X-Mvc-Supplant-OutputCached
X-Core-Mission
X-Core-Value
X-CMSURLCustom
X-Clientip
X-Owner
X-Clara-WADP
X-Refresh
X-Cache-Debug
X-ShopId
X-Level-Front-Cache
X-ShardId
X-Shopify-Stage
X-Sn-Servicetimems
X-App-Name
X-Sorting-Hat-ShopId
X-Old-Content-Length
X-BBC-Edge-Cache-Status
X-Server-IP
X-Loc
X-Request-Time
X-Debug-Cache-Store
X-S-Maxage
X-DefElseHash
X-DefHash
X-Bip
X-Irp-Debug
X-Auto-Login
X-Ah-Environment
Is-Eu
Machine
Memcached
Origin
Environment
Datacenter
AKAMAI
Adler-Geo
Cf-Device-Type
Cmsid
Cmstype
Platform
Expect-Staple
Req-Svc-Chain
Producers
Release
Cache-Hits
User-Cache-Control
X-LJ-Flow-ID
X-Cluster
X-AWS-Id
X-VWS-Id
CDCHOST
X-Block-Status
X-Nananana
CloudFront-Viewer-Country
Country-Code
X-WA-Info
Server-Hostname
Sever-Int
Apple-News-Services-Parsed-Url
X-Gen-Mode
X-From
X-Forwarded-Site
X-Device-Os
X-GeoIP
X-Hnp-Log
Apple-News-Services-Request-Url
DSUID
Apple-News-Services-Host
Apple-News-Services-Handled
X-Cdn-Srv
X-Nginx-Cache-Key
Hostname
X-Origin-Response-Time
X-Akamai-Device-Characteristics
NM-Fastcgi-Cache
X-Datadome
X-Origin
Host-ID
X-Dispatcher-Server
Server-Ext
X-Org
Esi-Enabled
X-PHP-Backend
X-Proxy-Cache-Status
Origin-CC
X-Scale
Ssr
Pics-Label
Wxu-Next-Region
Origin-EX
X-Section
Wxu-Next-Commit
X-Cache-Status-Check
Wxu-Next-Hostname
Memory
X-Instance-Name
Time
X-NCache
Server-Info
X-Cache-Enabled
X-Op-Id-All
X-LB-NoCache
C-Via
X-Access
X-Github-Request-Id
AMP-Access-Control-Allow-Source-Origin
X-API-Version
X-Via-Fastly
X-Micro-Cache
X-CACHE-GROUP
X-TIM-N
X-Amz-Meta-Cb-Modifiedtime
NGX
Server-ID
X-B3-Spanid
X-Correlation-ID
X-FTR-Request-ID
X-Dc
X-HA-Backend
X-Wp-Cf-Super-Cache-Active
X-AB
X-Internal-Host
X-Vgn-Hpd-Reason
X-Air-Source
X-Air-Trace-Id
X-Air-Hostname
X-Tb-Optimization-Total-Bytes-Saved
X-Azure-Ref-OriginShield
X-Platform-Processor
X-Varnish-Beresp-Grace
X-Platform-Router
X-Geo-Region
X-Cs
X-Varnish-Beresp-Ttl
X-Platform-Cluster
X-ZONE
X-Buckets
Location
X-SIPLIST1
GeoIP-Latitude
IsBot
X-Zone
Cdn-Requestid
X-Microcachable
X-Origin-Expires
X-Accel-Version
X-Backend-Instance
X-DC
Cache-Host
X-B3-Parentspanid
X-DataCenter
X-Fpc
X-Web-Node
X-TraceId
X-WP-CF-Super-Cache-Active
XM
X-Browser-Name
X-Is-Desktop
X-Tcp-Rtt
X-Is-Mobile
X-Is-Tablet
X-Is-Supported-Browser
X-Pod-Name
Uri
CF-Ctrl
Resin-Trace
YJS-ID
X-VarnishDD-TTL
X-Info
X-HN
PFcat
Sid
X-LiteSpeed-Cache-Control
X-TA-CDN-Provider
X-Cached-By
X-Ad-Defer-Variation
User-Agent
Locid
X-Via-SSL
X-Via-Edge
X-NGINX-Cache
X-FL-EDGE
X-Nitro-Rev
X-Site-Version
A
X-Locale
X-Via-CDN
Edge-Copy-Time
X-FL-QIT-DEBUG
Srvid
X-Nitro-Cache-From
True-Client-Ip
X-NODE
GeoIp-Country-Code
GeoIP-Country-Code
Epwk-X-Cache
X-Hyper-Cache
X-VCache
SID
X-Frame-Option
X-Cache-ASPX
Cdn
X-Contensis-Viewer-Groups
X-CS
X-Moov-T
X-FireWall-Port
X-Moov-Xdn-Version
X-ATG-Version
XServer
X-NewRelic-App-Data
X-CSRF-TOKEN
X-MSEdge-Features
X-MSEdge-Flight
Cache-Key
True-Client-IP
X-Varnish-Authentication
X-Service
X-Webstats-RespID
X-Geo
X-SRV
X-TRACE-ID
X-VC
X-Origin-Cache-Key
X-Datacenter
X-FPC
X-Upstream-Ct
X-Upstream-Ht
NtCoent-Length
Fastly-Drupal-Html
Path
X-HostName
Tcn
LB
X-Vercel-Cache
X-Platform-Server
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
X-FTR-Backend
X-FTR-Balancer
X-FTR-Cache-Status
State
X-Country-Code-Real
X-Planisys-CDN-TTL
X-FTR-Backend-Server
X-LiteSpeed-Tag
X-FTR-Expires
X-Edge-Server
Cdn-Host
Cdn-Request-Time
X-HS-Content-Campaign-Id
X-Vercel-Id
WebServer
X-Api-Version
Cf-Ipcountry
CountryCode
X-APP-VERSION
X-AK-Request-ID
X-Amz-Meta-Opti
WZWS-RAY
X-Vgn-Hpd-Variations-Key
X-Fastly-Cache
M-TraceId
X-NMSegId
Req-ID
Cdncip
Cdnsip
X-Vgn-Hpd-Cached
X-Vgn-Hpd-Ssi
X-Air-Pt
X-Pad
X-Release
X-Esi
X-Cdn-Request-ID
X-Ad-Load-Variation
Cluster
X-Branch-Name
X-Rocket-Build-Number
X-Cache-Remote
X-Generated-In
X-Sigma
Lb
X-Cache-Ttl
X-WP-CF-Super-Cache-Cookies-Bypass
X-Traceid
X-Sigma-Backend
X-Wp-Cf-Super-Cache-Cache-Control
X-Wp-Cf-Super-Cache
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-Wp-Cf-Super-Cache-Cookies-Bypass
XkeyRZ
X-NWS-UUID-VERIFY
Cache
X-Proxy-CacheRZ
Pramga
Content-Style-Type
X-HS-Status
Yak-Timeinfo
X-Scope-Id
X-M-Reqid
Content-Script-Type
Proxy-Connection
X-M-Log
X-Request-Start
X-CACHE-KEY
X-Provided-By
CDN
X-UA
Geoip-Latitude
X-Gamma-Serve
X-Qnm-Cache
X-GeoIP-City
X-Akamai-Pragma-Client-IP
X-GoCache-CacheStatus
X-Varnish-Beresp-Status
X-Scheme
Srv
X-Tim-N
X-Shield-Cache-Expires
X-Cdn-Forward
X-Lb-Cache
X-RN-RSRV
X-Cdn-Cache-Status
Ohc-File-Size
X-Vc
CF-Cached-On
X-Cache-Date
X-Ha-Backend
Server-Id
Edge-Cache
X-Request-URI
X-TT-LOGID
X-EC-Lua
X-User
Ngx
X-TH-Server
X-CUA
Env
X-Render-Time
X-Acquia-Site
X-Acquia-Application-Trace
X-Via-Ucdn
X-Dw-Trace-Id
Inserted-Into-Cache-At
X-Acquia-Purge-Tags
X-Acquia-Application-UUID
PICS-Label
X-Edge-POP
X-Lb-Nocache
Yjs-Id
HostName
X-Aicache-OS
X-Via-Popv
X-Acquia-Purge-Cdn-Unconfigured
V-Age
Tube-Return
X-B3-Trace-ID
Tube-Got-Results
Tube-Got-Eval
X-Wa
X-SB
X-Nc
X-Cache-FS-Status
Tube-Get-Contents
X-Fastly-Backend-Reqs
X-Req
X-LB-ID
X-Via-Poph
X-V-Cache
X-Servedbyhost
X-Via-Popn
X-RAMCache
X-Cached-Since
X-ElasticPress-Query
X-Litespeed-Cache-Control
Vha6-Origin
X-Snapshot-Date
X-VCL-Version
CACHE-MISS-TO-ORIGIN
X-Fastly-Cache-Hits
Log-Origin
X-Miniprofiler-Ids
Cache-Tv-Group
Click-Count-Action-Start
Click-Count-Error
X-Udemy-Cache-App-Namespace
X-CF-Cache-Header-Vary
Cneonction
Kp-EeAlive
X-CF-Cache-Header-Cache-Control
MIME-Version