Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-Cache-Status
Link
Accept-Ranges
CF-RAY
ETag
Expect-CT
Pragma
X-Powered-By
X-XSS-Protection
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
Alt-Svc
P3P
X-Served-By
X-Xss-Protection
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Request-Id
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Cache-Status
X-Generator
X-Cacheable
Timing-Allow-Origin
X-Content-Security-Policy
P3p
X-Iinfo
Status
Feature-Policy
X-Envoy-Upstream-Service-Time
X-Request-ID
Content-Encoding
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
X-CDN
X-AspNetMvc-Version
Upgrade
X-Via
CF-Ray
X-Ws-Request-Id
Access-Control-Max-Age
Server-Timing
EagleId
X-Cache-Group
Keep-Alive
X-Turbo-Charged-By
Request-Context
X-Age
X-Server-Powered-By
X-Proxy-Cache
X-AH-Environment
X-UA-Device
X-Backend
X-Hacker
X-Robots-Tag
Report-To
X-Amz-Request-Id
X-Server
Host-Header
X-Amz-Id-2
X-LiteSpeed-Cache
Grace
X-Rq
X-Nginx-Cache-Status
X-Varnish-Cache
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-WebKit-CSP
X-Dns-Prefetch-Control
X-Page-Speed
X-Vhost
EagleEye-TraceId
X-Amz-Version-Id
X-Ua-Compatible
X-OneAgent-JS-Injection
X-Pingback
X-Dispatcher
X-Device
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Cache-Spec
NEL
X-Server-Id
X-Host
Cf-Railgun
X-Node
X-Backend-Server
X-Readtime
Accept-CH
Surrogate-Control
X-Akam-SW-Version
Request-Id
X-Response-Time
X-HW
Xkey
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Application-Context
Content-Location
Accept-Ch-Lifetime
X-Ruxit-JS-Agent
Rating
X-Country
X-B3-TraceId
X-Cache-Lookup
X-Cloud-Trace-Context
Accept-CH-Lifetime
X-Trace
X-Url
X-Ac
X-Content-Type
Allow
X-TtlSet
X-Vname
X-PC
X-Varnish-TTL
X-Clacks-Overhead
X-Mod-Pagespeed
Edge-Control
X-FastCGI-Cache
X-Server-Name
Fastly-Restarts
Cache-Tag
X-ESI
Service-Worker-Allowed
X-Rack-Cache
X-VARITI-CCR
X-Element-Page-Cache
Verso
X-Language
X-MS-InvokeApp
X-GitHub-Request-Id
X-Upstream
MS-Author-Via
X-Amz-Rid
Public-Key-Pins
X-Vcap-Request-Id
X-Aws-Lambda-Call-Status
X-Cached
X-Dw-Request-Base-Id
Accept-Ch
X-Client-IP
X-Abt-Application-Version
X-D2id
X-Cache-TTL
X-Template
X-Cnection
X-Origin-Cache
Arr-Disable-Session-Affinity
X-Px
X-Country-Code
RTSS
X-Goog-Hash
Access-Control-Request-Method
X-Powered-By-Plesk
X-Navigation-Version
X-NF-Request-ID
X-Instrumentation
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-Exp-Variant
X-Exp-Id
X-Version
X-Cdn-Fetch
X-Use-Magma
X-GoogleNews-Bot
X-Kinja-Build
X-Kinja-Server
X-Kinja
X-Kinja-Revision
X-Powered-CMS
Display
X-Middleton-Display
Pagespeed
X-Sol
AR-Request-ID
AR-SID
AR-CACHE
AR-ATIME
AR-PoweredBy
X-Amz-Server-Side-Encryption
Response
X-Middleton-Response
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-MSEdge-Ref
X-TTL
X-LLID
X-Kinsta-Cache
X-Edge-Location-Klb
X-Edge
Nginx-Cache
MRF-Tech
X-B3-TraceId-Primal
Mrf-Cache-Status
X-RateLimit-Remaining
X-Protected-By
X-Shield-Request-Id
X-HP-Webp
X-HP-Trace-Id
X-Jurisdiction
X-T
TCN
X-Buckets
X-Forwarded-For
S
X-Content-Security-Policy-Report-Only
X-Mg-S
Content-MD5
X-Id
X-Aspnetmvc-Version
X-Mid
Realpath
Edge-Cache-Tag
Fastcgi-Cache
X-CST
SPIisLatency
SPRequestDuration
X-MCACHE
Front-End-Https
X-Recruiting
X-Request-Processing-Time
X-Request-Received
Filters
Pinterest-Version
Pinterest-Generated-By
Server-Node
X-Pinterest-Rid
X-Ua-Browser
X-Content
X-Ab
X-Correlation-Id
X-DynaTrace
X-ECACHE
Server-Name
X-Frontend
X-Parallel-Accel
X-NWS-LOG-UUID
SPRequestGuid
X-SharePointHealthScore
X-Ruxit-Js-Agent
Fusion-Deployment-Id
Fusion-Template-Id
X-HS-Content-Id
X-HS-Cache-Config
Fusion-Component-Id
Fusion-Content-Id
Fusion-Source
X-HS-Hub-Id
Fusion-Content-Source
X-Ezoic-Cdn
X-Ttl
X-HS-Combine-CSS
X-Yandex-Sdch-Disable
Alternate-Protocol
X-Hits
X-Ser
X-Cache-Key
X-Tt-Trace-Host
X-Content-Options
X-Tt-Trace-Tag
MicrosoftSharePointTeamServices
Cache-Tags
X-Git-Hash
Cleartype
X-B3-Sampled
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
Charset
Host
X-Page-Id
X-Www-Served-By
X-Accel-Expires
X-Daa-Tunnel
X-Geo-Country
X-DIS-Request-ID
X-Content-Digest
X-Fastly-Request-Id
X-Amzn-Trace-Id
X-Amz-Replication-Status
Filterid
X-Debug-Info
X-Varnish-Age
X-Hostname
TP-Cache
TP-L2-Cache
X-Forwarded-Proto
X-AppVersion
X-Az
X-Activity-Id
X-VCache
X-Upgrade-Enabled
X-FB-Debug
X-Rid
X-Origin-Server
Access-Control-Allow-Method
X-N
X-XRDS-LOCATION
Cross-Origin-Opener-Policy
X-Grace
X-Nginx-Upstream-Cache-Status
X-LB-Cache
X-WebKit-CSP-Report-Only
X-F-Cache
X-Mobile-URL
ServerID
X-Is-Crawler
X-Request-Guid
X-Route-Name
X-Providence-Cookie
X-Flags
X-Aspnet-Duration-Ms
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-Whom
X-TT
X-GUploader-UploadID
X-Goog-Metageneration
X-Tb
X-App-Environment
Viewport
X-Origin-Upstream-Status
X-Varnish-Grace
X-FW-Hash
X-FW-Serve
X-FW-Server
X-FW-Dynamic
X-Distributor
X-FW-Static
X-App-Server
X-FW-Type
Node
Payment
Paypal-Debug-Id
X-Server-ID
DC
X-Seen-By
X-Ratelimit-Limit
X-Type
X-NGENIX-Cache
Fastcgi-Useragent
X-User-Agent
X-Cache-Control
Accept-Charset
Country
X-Oneagent-Js-Injection
X-Logged-In
X-Microsite
X-Request-Handler-Origin-Region
X-Wix-Request-Id
X-Cache-Rule
X-Cache-Age
X-Litespeed-Cache
Version
X-Fastly-Request-ID
X-Webkit-CSP
X-Via-JSL
X-Drupal-Cache-Tags
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
Referer-Policy
X-DataDome
X-Browser-Type
X-Varnish-Backend
Refresh
X-Node-Name
X-Load-Cache
X-Cluster-Name
X-Signature
X-B-Cache
X-Original-Request-Id
X-Cache-Action
Cache-Status
Access-Control-Request-Headers
SD-X-WS
Amp-Access-Control-Allow-Source-Origin
X-Mobile
X-Contextid
X-Response-Served-From
X-Page-View
X-Proxy-Cache-Status
X-Rendered-As
X-TEC-API-ORIGIN
X-Jobs
X-Vgn-Hpd-Reason
X-Cache-Expired-At
X-Cacheable-TTL
X-TEC-API-ROOT
X-TEC-API-VERSION
X-Is-Bot
X-IPLB-Instance
VIX-Pulpo-Node
NGB
X-RemovedCookies
X-Debug
X-UUID
X-Oracle-Dms-Rid
X-ProcessESI
X-Real-IP
X-Oracle-Dms-Ecid
X-B
VIX-Pulpo-Upstream-Status
X-Revision
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Proxy
X-Instance
X-Drupal-Cache-Contexts
X-Rule
X-G
Akamai-GRN
X-Cache-Time
Surrogate-Key
X-Debug-IsConnected
X-Device-Type
X-Debug-IsPreview
X-Framework
X-FW-Version
X-PressLabs-Stats
CF-IPCountry
X-Fastcgi-Cache
X-Air-Trace-Id
X-Air-Hostname
X-Air-Source
X-Tec-Api-Origin
X-Tec-Api-Root
DynaTrace
SID
X-Tec-Api-Version
X-Ratelimit-Reset
Liferay-Portal
X-Azure-Ref
Healthy
X-Nginx-Cache
X-XRDS-Location
GEO-INFO
X-Source
X-Ms-Version
X-Ms-Request-Id
Frame-Options
Count-Hit
X-Cache-Operation
X-CDN-Forward
Ms-Operation-Id
MS-CV
X-RTag
X-Accel-Buffering
X-APP-VERSION
X-Presslabs-Stats
Uber-Trace-Id
X-EdgeConnect-Cache-Status
X-Environment-Context
Xserver
X-L-Path
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-Tumblr-User
X-Cache-Hit
X-Varnish-Server
X-RateLimit-Limit
X-Zen-Fury
Countrycode
Ec-Rule-Version
X-Region
X-Mode
X-Servername
Cross-Origin-Window-Policy
X-Forwarded-Host
Backend
X-Cache-NGX
X-IPS-LoggedIn
Section-Io-Cache
X-Backend-Name
X-Content-Powered-By
X-SaId
X-Cache-TTL-Remaining
Protected
X-Detected-As
X-Cache-Type
X-RN-RSRV
X-UPSTREAM-Address
Meta-Geo
X-JoinUs
X-Proxied
X-Cache-Grace
X-Alternate-Cache-Key
X-Human
Country-Code
X-Extlb
X-Routing-Service
Apigw-Requestid
X-Debug-Cache
X-Hosted-By
X-Generation-Time
X-Redis-Cache
Decoy-Debug-Key
X-Shopify-Stage
X-Zipkin-Id
X-ShardId
X-Sql-Duration-Ms
X-Tid
Decoy-Debug-Status
Eomportal-Instance
Decoy-Debug-TTL
X-Varnish-Beresp-Grace
X-Sql-Count
X-ShopId
X-Uri
X-Sorting-Hat-PodId
X-Rewrite-Enabled
X-Sorting-Hat-ShopId
X-PHP-Backend
X-PERF
Fastly-SSL
X-FB-TRIP-ID
Url
X-Microcachable
X-NCache
X-Cache-Server
X-Via-Fastly
X-Storage
X-Status
Cache-Tv-Group
X-Soup
Cache-Name
X-Site-Version
X-ApacheServer
TWC-GeoIP-Country
TWC-Device-Class
TWC-GeoIP-LatLong
TWC-Locale-Group
Webcakes-App-Version
TWC-Privacy
DB-Nickname
X-Adobe-Content
X-Cache-Host
Property-Id
X-BYPASS-REASON
Mn-Server-Ip
Selected-Fe
Webcakes-Region
X-Adobe-Loc
TWC-Connection-Speed
X-ProxyCache-Key
X-SayCDN-TTL
X-Say-Cacheable
X-ProxyCache-Status
Webcakes-App-Name
X-Timing-Wait
X-UA-Device-Type
X-NYM-Debug-Backend
X-Format
X-Web-Node
X-Proxy-Build
X-Say-TTL
X-OCL
X-No-Session
X-Origin-Date
X-PCL
X-Origin-Hint
OT-Force-Account-Verify
X-Server-W
X-Content-Age
X-NewRelic-App-Data
X-Akamai-Edgescape
X-Section
X-R9-Blue-Green-Version
Azure-RegionName
Azure-InstanceId
X-Pubstack
Azure-SiteName
Azure-SlotName
X-Varnishpool
Azure-Version
X-Access
Content-Secure-Policy
X-ServerID
X-Cluster-Node
X-Hyper-Cache
X-Ua
X-LSADC-Cache
X-Be
SRV
CDN-RequestId
CDN-Uid
CDN-PullZone
CDN-Cache
X-Hl-Ver
CDN-CachedAt
CDN-EdgeStorageId
CDN-RequestCountryCode
X-Azure-Ref-OriginShield
X-Generated-By
Content-Disposition
X-Cached-By
Source
X-TIME
X-Webkit-Csp
X-Unique-Id
X-SRV
LB
Cache
X-Nginx-Cache-Key
WPO-Cache-Message
X-TT-LOGID
WPO-Cache-Status
X-Bc-Bl
X-Ratelimit-Remaining
X-Trace-Id
X-Dc
X-App-Version
X-LAGOON
X-HTML-Minification-Powered-By
Cache-Hits
Retry-After
X-Varnish-Hits
X-Auto-Login
X-Akamai-Transformed
X-Origin-TTL
X-Origin-CC
X-TNCMS
X-Loop
Xet-Cookie
X-GEO
Onion-Location
Mime-Version
X-S-Maxage
X-Varnish-Hostname
X-Amz-Meta-S3cmd-Attrs
X-Platform-Server
X-Cdn
Web-Mar-Node
X-Cache-Var
X-Tumblr-Pixel-2
X-Tumblr-Pixel-3
X-Xfnlog-Site
X-Cache-Var-Map
HostName
X-Time
X-Cache-Remote
X-Endurance-Cache-Level
X-CSRF-Token
X-Varnish-Cache-Hits
X-Proto
X-Edge-Location
X-Cache-Tags
X-Tenant
Webserver
X-Time-Microsecs
ServedBy
X-Request-Time
Upgrade-Insecure-Requests
X-EC-Lua
X-GG-Cache-Date
N-Cache
X-AOL-HN
X-VWS-Id
X-LJ-Flow-ID
X-AWS-Id
CloudFront-Viewer-Country
X-B3-SpanId
X-M-Reqid
X-ECache
X-Request-Host
X-M-Log
X-Qnm-Cache
X-Mg-Request-UUID
X-Amz-Apigw-Id
X-PHP-Host
From-Origin
X-Labrador-Cache-Channel
X-Amzn-RequestId
X-Via-NSCOPI
X-FireWall-Port
WP-Super-Cache
Rendered-Blocks
X-VG-WebCache
X-Processor
Meta-Geo-Continent
DCR-Decision-By
DSUID
Expiry
Xc-Version
CDCHOST
A
BehaviorPad-Version
Fastcgi-X-Cache-Version
X-Vtex-Remote-Cache
Origin
Pramga
Odigeo-Trace-Id
Mobile-Detection-Method
L
X-Vtex-Processado-Em
Redirect-Candidate
X-A-Wwc
X-Forwarded-Path
X-External-Request-Id
X-Ftr-Request-Id
X-Gen-Mode
X-Hnp-Log
X-Developer
X-Destination
X-SVT-ORM-RULES
X-Conf
X-Connection-Hash
X-D
X-SRCache-Key
X-Ig-Push-State
X-Shop-Environment
X-PAYTM-SRV-ID
X-PBS-Appsvrname
X-Session-Fingerprint
X-Slack-Backend
X-Origin-Response-Time
X-Planisys-CDN-Rules
X-NAPM-TraceId
X-ND-Cache
X-Orig-Expires
X-Cluster
X-SVT-ORM-VERSION
X-A-Dam
X-A-Ccd
X-A-Dcw
X-A-Dgt
X-Aed
X-A
V-Age
Sslversion
Surrogated-Key
X-Vdms-Path
User-Cache-Control
X-Application
X-ARC
X-Planisys-CDN-TTL
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-Ckpd-Fst-Backend
X-Cache-NE
X-Cache-Date
X-B-Cookie
X-V-Cache
X-TIM-N
X-Block-Status
X-Vdms-Version
DCR-Processing-Time-Ms
X-Correlation-ID
X-S-Cookie
X-SD-PageType
X-CACHE-KEY
X-S
Nel
X-Rojux
X-RCS-CacheZone
X-Planisys-CDN-Cache
X-ScT
X-Handled-By
X-Locale
Svr
Traceparent
State
Ssr
True-Client-Country-4JS
X-Men
X-VarnishDD-TTL
Wxu-Next-Hostname
Wxu-Next-Commit
X-LI-UUID
X-Zone
Vix-Hermes-Req-Id
Release
X-Old-Content-Length
X-Nyt-Route
X-Origin-Expires
X-Origin-Time
Host-ID
X-NodeID
X-Served-From
PFcat
X-VServer
Origin-EX
Origin-CC
Wxu-Next-Region
X-Li-Fabric
X-Fastly-Cache
X-Sucuri-ID
X-HN
X-Epic-Correlation-Id
X-Device-Os
X-Fetched-On
X-Storefront-Renderer-Rendered
X-Geo-Header
X-Gdpr
X-Sucuri-Cache
X-Forwarded-Site
X-Date
X-Core-Mission
X-Aicache-OS
X-Varnish-Beresp-Status
X-Accel-Expires-Debug
X-Scheme
X-Webstats-RespID
X-Server-IP
X-Cache-Bucket
X-Rocket-Nginx-Serving-Static
X-Cdn-Srv
Server-Info
X-Cache-Info
X-Li-Pop
X-Location
X-Proxy-Upstream
X-Owner
AKAMAI
Fastcgi-Cache-TTL
Arc-Country
Cmsid
Cmstype
X-Skip-Cache
Fastly-Drupal-Html
X-MP-GENERATED-AT
Environment
X-NWS-UUID-VERIFY
X-VC-Cache
AMP-Access-Control-Allow-Source-Origin
X-TH-Server
Thinkindot-Control
X-Region-Sid
X-Policy
Apple-News-Services-Request-Url
Web-Mar-Region
X-RateLimit-Limit-Second
CacheControlHeader
X-Backend-State
X-Core-Value
Apple-News-Services-Parsed-Url
X-RateLimit-Remaining-Second
X-UnsetCookies
X-ATG-Version
X-Cache-Debug
X-BBC-Edge-Cache-Status
X-Bip
X-TrackingId
X-Cache-Id
X-Thinkindot-L3
X-Level-Front-Cache
X-Adobe-Source
Thinkindot-CacheControl
Apple-News-Services-Host
Gh-Request-Id
X-Thanos
Apple-News-Services-Handled
X-Cdn-Origin
Thinkindot-CacheControl-Type
X-Fastly-Backend
X-Request-URI
X-Viewer-Country
X-Esi-Check
Req-Svc-Chain
X-HS-Content-Campaign-Id
Fastly-GeoIP-CountryCode
X-Gamma-Serve
Locid
X-Gzip
Machine
X-Envoy-Decorator-Operation
X-Hash
X-Generated-On
X-Developers
X-Node-Id
X-Mvc-Supplant-Cachable
X-VG-TLSProxy
X-Sn-Servicetimems
TDXMobile
X-Req
Server-Host
X-Cache-Enabled
X-Magnolia-Registration
X-Datadog-Sampling-Priority
X-Datadog-Trace-Id
X-DefHash
X-Cache-Config
Adler-Geo
X-GeoIP-City
X-DefElseHash
X-JWT-State
X-GeoIP
X-Platform
X-Branch-Name
X-Is-Gdpr
X-Irp-Debug
X-DPWN-IS-SECURE
X-Rocket-Build-Number
X-CGP
X-Pod-Name
X-Reqid
X-Qloud-Router
X-Csrf-Jwt
X-Datadog-Parent-Id
X-Varnish-CookieHashed-On
Ha-Gx-Prefs
Is-Eu
X-Rebelmouse-Surrogate-Control
X-Has-Esi
Cf-Device-Type
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
Mail-Subject
X-Request-Start
Platform
Fastly-SIE
X-Origin
Fastly-SWR
NGX
X-NU-AKA-ACS-Version
X-Sigma
X-Sigma-Backend
X-Worker
We-Hiring
X-Loc
X-Amzn-Remapped-Content-Length
X-Variation
X-Eu-Site
HA-Ipaddr
X-Rebelmouse-Cache-Control
L5d-Success-Class
X-CS
X-Xrds-Location
X-FC-Vary-Parameters
X-Tx-Id
X-Backend-TTL
NM-Fastcgi-Cache
X-Response-By
Memcached
X-Datadome
X-Varnish-Beresp-Ttl
Datacenter
X-Ua-Device
X-GeoIP-Region-Code
X-Up
X-Trace-ID
X-CLOUD-TRACE-CONTEXT
X-GeoIP-Country-Code
X-NC
X-Mvc-Supplant-OutputCached
X-API-Version
CDN
Pics-Label
X-LB-ID
Candidate-Md5Url
X-Esi
S-Rt
X-Generated-In
Ms-Author-Via
X-Tb-Optimization-Total-Bytes-Saved
X-DynaTrace-JS-Agent
X-Restarts
X-TraceId
X-Via-Popv
X-Via-Poph
X-Vc
On-Server
NtCoent-Length
Env
X-LB-NoCache
Magicmarker
WWW-Authenticate
X-Via-Popn
Memory
Time
WebServer
X-Varnish-Ttl
Kp-EeAlive
X-Edge-Pop
X-Optimistic-Header
Esi-Enabled
X-DC
X-Http-Reason
X-Tt-Logid
X-Refresh
X-Cache-Backend
X-Action
X-Akamai-Request-ID2
GeoIp-Country-Code
Edge-Cache
X-RSL
X-DI
X-DB
X-DSS
X-Wix-Viewer-Type
X-RPM
X-TA-CDN-Provider
X-RPS
X-DW
C-Via
X-Dynatrace
X-Service
X-CacheTTL
X-Varnish-Beresp-TTL
X-Parent-Response-Time
X-Minions-Version
X-Servedbyhost
X-Cache-PHP
X-Srv
Server-ID
Accept-Language
X-TX-ID
X-HA-Backend
X-Unique-ID
X-MSEdge-Features
X-MSEdge-Flight
X-Cs
X-Newrelic-Synthetics
X-Render-Time
X-Cache-Status-Check
X-ZONE
X-Urbn-Site-Id
X-VCL-Version
X-Urbn-Context-Path
Locale
X-Cache-Ttl
X-Ec-GeoHdr
X-Ec-Fail
X-LI-Proto
X-User
X-Traceid
X-App
X-Fpc
X-Li-Proto
X-URL
Proxy-Connection
Test
X-AIR-PT
X-Pass-Why
X-FPC
X-Info
X-Webkit-Csp-Report-Only
X-LiteSpeed-Cache-Control
X-Clientip
Server-Id
X-B3-Spanid
X-Vcl-Version
X-NODE
X-Webkit-CSP-Report-Only
Cdnsip
X-Oss-Request-Id
Cache-Host
Geo-Info
UCS
X-Oss-Storage-Class
X-Oss-Server-Time
HIT
Cdncip
Tcn
X-AK-Request-ID
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
Cluster
X-Clara-WADP
X-Fmm-Version
M-TraceId
X-WADP-Cache
X-CSRF-TOKEN
S-Cnection
My-App
Geoip-Latitude
X-Var-Ttl
Resin-Trace
Fastly-Drupal-HTML
X-HostName
Tracecode
Hostname
X-LiteSpeed-Tag
X-CUA
Cf-Int-Pingora-Origin-Digest
Fastly-Backend-Name
X-ID
X-Ha-Backend
X-ServedByHost
X-Micro-Cache
X-From
User-Agent
T-Server
Lfy
X-Dynatrace-Js-Agent
X-Backend-Host
X-BBC-Origin-Response-Status
X-Mcache
Ohc-File-Size
Hit
X-Fragments
Lang
X-RAMCache
X-Release
Section-Origin-Responded
Section-Io-Origin-Time-Seconds
Section-Io-Id
GeoIP-Country-Code
Section-Io-Origin-Status
X-Pad
X-Cdn-Forward
Lb
X-Geo
Target-Params
X-WP-CF-Super-Cache-Cache-Control
X-Edge-POP
X-WP-CF-Super-Cache
MIME-Version
X-Via-PopH
X-Via-PopV
X-APP
ENV
X-BCube-Filmed-By
X-Via-PopN
X-ElasticPress-Query
X-Check-Cacheable
X-NGINX-Cache
X-Edge-Cache
DataCenter
Load-Balancing
X-HS-Status
X-Api-Version
X-VC
X-ServerName
EpKe-Alive
VNS-Age
Path
VNS-Cache
X-Amz-Meta-Cb-Modifiedtime
Servername
X-WA
X-WA-Info
URI
X-Fastly-Backend-Reqs
Cache-Key
CPC-Age
CPC-Cache
X-Ucs
X-ES-SERVER
X-GoCache-CacheStatus
X-Httpd
X-Fastly-Cache-Hits
X-Proxy-Cache-Info
PICS-Label
FSS-Cache
X-Lb-Nocache
X-Wikidot-Static-Cache
X-Wikidot-Backend
X-UP
Uri
Permissions-Policy
X-TRACE-ID
ServerName
Producers
X-Lb-Id
Ohc-Cache-HIT
X-RateLimit-Reset
Pagetype
Cdn
Cneonction
X-Cms-Context
X-Nc
WZWS-RAY
X-Provided-By
Cteonnt-Length
X-Cdn-Request-ID
X-PJAX-URL
X-B3-ParentSpanId
Server-Ttl
Shield-Pop
X-Dw-Trace-Id
X-Acquia-Application-Trace
X-Acquia-Application-UUID
X-Swift-Error
X-CCDN-Origin-Time
X-CCDN-CacheTTL
Cf-Ipcountry
MD5-Digest
X-Akamai-Pragma-Client-IP
X-Via-Ucdn
X-Pool
X-Snapshot-Date
X-Contensis-Viewer-Groups
X-Cache-ASPX
X-Akamai-ERPolicy
X-Hcs-Proxy-Type
X-Vcache
X-Yottaa-OS
X-Newrelic-App-Data
Srv
X-Akamai-ERRuleID
CF-Cached-On
X-Apw-Access-Action
X-Acquia-Purge-Tags
X-Cache-CFC
X-Apw-Access-Object
X-SB
X-Apw-Hits
Vha6-Origin
X-Apw-Access-Token
X-Acquia-Site
X-Cache-Ngx
Sid
X-Air-Pt
X-Platform-Processor
X-Platform-Router
X-Platform-Cluster
GeoIP-Latitude
X-Udemy-Cache-App-Namespace
X-Last-Modified
Server-Ext
CountryCode
X-Miniprofiler-Ids
IsBot
Server-Hostname
Req-ID
X-UA
X-Logging-Id
X-Varnish-Authentication
X-CacheKey
X-Sentry-ID
X-VG-WebServer
X-Http-Duration-Ms
X-Te-Count
X-Te-Duration-Ms
X-Http-Count
X-B3-Parentspanid
Ngx
Sever-Int
W
X-SIPLIST1