Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-Cache-Status
Link
Accept-Ranges
CF-RAY
ETag
X-XSS-Protection
Expect-CT
Pragma
X-Powered-By
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
Alt-Svc
P3P
X-Served-By
X-Xss-Protection
X-Download-Options
X-Timer
X-Request-Id
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Cache-Status
X-Generator
X-Cacheable
Timing-Allow-Origin
P3p
X-Content-Security-Policy
X-Iinfo
Feature-Policy
Status
X-Envoy-Upstream-Service-Time
Content-Encoding
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
X-CDN
X-Request-ID
X-AspNetMvc-Version
Upgrade
X-Via
CF-Ray
X-Ws-Request-Id
Access-Control-Max-Age
Server-Timing
EagleId
X-Cache-Group
Keep-Alive
X-Turbo-Charged-By
Request-Context
X-Age
X-Server-Powered-By
X-Proxy-Cache
X-UA-Device
X-AH-Environment
X-Backend
X-Hacker
X-Robots-Tag
Report-To
X-Amz-Request-Id
Host-Header
X-Server
X-Dns-Prefetch-Control
X-Amz-Id-2
Grace
X-LiteSpeed-Cache
X-Rq
X-Nginx-Cache-Status
X-Varnish-Cache
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-WebKit-CSP
X-Page-Speed
X-Vhost
X-Ua-Compatible
EagleEye-TraceId
X-OneAgent-JS-Injection
X-Amz-Version-Id
X-Pingback
X-Dispatcher
X-Device
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Cache-Spec
NEL
X-Host
X-Server-Id
Cf-Railgun
X-Node
X-Backend-Server
X-Readtime
Accept-CH
X-Akam-SW-Version
Surrogate-Control
Request-Id
X-Response-Time
X-HW
Xkey
Accept-Ch-Lifetime
X-EdgeConnect-MidMile-RTT
X-Ruxit-JS-Agent
X-EdgeConnect-Origin-MEX-Latency
X-Application-Context
Content-Location
Rating
X-Country
X-B3-TraceId
X-Cloud-Trace-Context
X-Cache-Lookup
X-Trace
X-Url
X-Ac
Accept-CH-Lifetime
X-Content-Type
X-TtlSet
X-PC
X-Vname
Allow
X-Varnish-TTL
X-Clacks-Overhead
X-Mod-Pagespeed
Edge-Control
X-Server-Name
Cache-Tag
Fastly-Restarts
X-ESI
X-FastCGI-Cache
Service-Worker-Allowed
X-VARITI-CCR
X-Rack-Cache
X-Element-Page-Cache
Verso
X-MS-InvokeApp
MS-Author-Via
X-Upstream
X-GitHub-Request-Id
X-Amz-Rid
Accept-Ch
X-Aws-Lambda-Call-Status
Public-Key-Pins
X-Vcap-Request-Id
X-Cached
X-Dw-Request-Base-Id
X-Client-IP
X-D2id
X-Abt-Application-Version
X-Cache-TTL
X-Cnection
X-Aspnetmvc-Version
X-Origin-Cache
Arr-Disable-Session-Affinity
X-Px
X-Country-Code
RTSS
Access-Control-Request-Method
X-Goog-Hash
X-Powered-By-Plesk
X-Navigation-Version
X-Kraken-Loop-Name
X-NF-Request-ID
X-Instrumentation
X-Server-Lifecycle-Phase
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-Exp-Id
X-Use-Magma
X-Kinja-Server
X-Kinja-Build
X-Exp-Variant
X-Kinja
X-Cdn-Fetch
X-Kinja-Revision
X-GoogleNews-Bot
X-Powered-CMS
X-Version
X-Language
AR-PoweredBy
AR-SID
AR-CACHE
AR-Request-ID
AR-ATIME
Pagespeed
X-Sol
Display
X-Middleton-Display
X-Amz-Server-Side-Encryption
X-Middleton-Response
Response
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-MSEdge-Ref
X-LLID
X-Edge-Location-Klb
X-Kinsta-Cache
X-Edge
X-TTL
Nginx-Cache
X-Template
Mrf-Cache-Status
X-B3-TraceId-Primal
MRF-Tech
X-Protected-By
X-Jurisdiction
X-HP-Webp
X-HP-Trace-Id
X-Shield-Request-Id
TCN
X-T
X-RateLimit-Remaining
S
X-Mg-S
X-Content-Security-Policy-Report-Only
X-Id
Content-MD5
X-Forwarded-For
Edge-Cache-Tag
X-Mid
Realpath
Fastcgi-Cache
SPRequestDuration
X-MCACHE
SPIisLatency
Front-End-Https
X-CST
X-Recruiting
X-Request-Processing-Time
X-Request-Received
Filters
Pinterest-Generated-By
Pinterest-Version
X-Pinterest-Rid
Server-Node
X-DynaTrace
X-Ua-Browser
X-Ab
X-Content
Server-Name
X-Correlation-Id
X-Frontend
X-Ttl
X-ECACHE
X-HS-Cache-Config
X-NWS-LOG-UUID
X-HS-Hub-Id
X-HS-Content-Id
X-SharePointHealthScore
X-Parallel-Accel
SPRequestGuid
X-HS-Combine-CSS
X-Ezoic-Cdn
X-Yandex-Sdch-Disable
Fusion-Deployment-Id
Fusion-Content-Source
Fusion-Source
Fusion-Content-Id
Fusion-Component-Id
Fusion-Template-Id
X-Cache-Key
X-Hits
Alternate-Protocol
X-Ser
X-Buckets
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Content-Options
X-Ruxit-Js-Agent
Cache-Tags
X-B3-Sampled
X-Git-Hash
MicrosoftSharePointTeamServices
Cleartype
X-Page-Id
X-Kong-Upstream-Latency
Charset
X-Kong-Proxy-Latency
Host
X-Www-Served-By
X-Geo-Country
X-DIS-Request-ID
X-Daa-Tunnel
X-Content-Digest
X-Amz-Replication-Status
X-Amzn-Trace-Id
X-Accel-Expires
X-Debug-Info
Filterid
X-Varnish-Age
X-Fastly-Request-Id
X-Hostname
X-Az
X-AppVersion
X-Activity-Id
TP-Cache
TP-L2-Cache
X-VCache
X-Upgrade-Enabled
X-FB-Debug
X-Forwarded-Proto
X-N
X-Rid
Cross-Origin-Opener-Policy
Access-Control-Allow-Method
X-Origin-Server
X-Nginx-Upstream-Cache-Status
X-Grace
X-Ratelimit-Limit
X-F-Cache
X-LB-Cache
ServerID
X-Mobile-URL
X-Providence-Cookie
X-Route-Name
X-Aspnet-Duration-Ms
X-Flags
X-Request-Guid
X-Is-Crawler
X-XRDS-LOCATION
X-Server-ID
X-Goog-Generation
X-TT
X-GUploader-UploadID
X-Whom
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
X-Goog-Storage-Class
X-Tb
Viewport
X-FW-Server
X-FW-Type
X-FW-Serve
X-FW-Static
X-Distributor
Node
X-Type
X-WebKit-CSP-Report-Only
X-Seen-By
X-FW-Hash
X-Varnish-Grace
X-App-Environment
X-FW-Dynamic
X-App-Server
X-Origin-Upstream-Status
DC
Payment
Paypal-Debug-Id
X-NGENIX-Cache
X-User-Agent
Fastcgi-Useragent
Country
X-Cache-Control
Accept-Charset
X-Litespeed-Cache
X-Wix-Request-Id
X-Fastcgi-Cache
X-Cache-Rule
X-Microsite
X-Request-Handler-Origin-Region
X-Logged-In
X-Webkit-CSP
Version
X-DataDome
X-Cache-Age
X-Fastly-Request-ID
X-Via-JSL
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
Amp-Access-Control-Allow-Source-Origin
X-Browser-Type
X-Drupal-Cache-Tags
X-Oracle-Dms-Ecid
X-Varnish-Backend
Referer-Policy
X-Oracle-Dms-Rid
Refresh
X-B-Cache
X-Signature
X-Cluster-Name
X-Node-Name
Cache-Status
X-Mobile
SD-X-WS
X-Original-Request-Id
X-Contextid
Access-Control-Request-Headers
X-Load-Cache
X-Response-Served-From
X-Cache-Action
X-Proxy-Cache-Status
X-Vgn-Hpd-Reason
X-Rendered-As
X-Page-View
X-Is-Bot
X-Cacheable-TTL
X-Instance
NGB
X-UUID
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Real-IP
X-RemovedCookies
X-Cache-Expired-At
X-B
X-ProcessESI
X-Debug
X-Jobs
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-IPLB-Instance
X-Revision
X-Drupal-Cache-Contexts
X-Rule
X-Proxy
X-G
Akamai-GRN
X-Tec-Api-Version
X-Tec-Api-Origin
X-Tec-Api-Root
X-TEC-API-VERSION
X-TEC-API-ROOT
X-Debug-IsPreview
X-TEC-API-ORIGIN
X-Cache-Time
X-Framework
X-Device-Type
X-Debug-IsConnected
Surrogate-Key
CF-IPCountry
X-FW-Version
X-Air-Source
X-Air-Hostname
X-Air-Trace-Id
X-Ratelimit-Reset
SID
X-PressLabs-Stats
DynaTrace
Liferay-Portal
X-XRDS-Location
X-Azure-Ref
Healthy
X-Oneagent-Js-Injection
X-CDN-Forward
GEO-INFO
X-Source
Count-Hit
X-APP-VERSION
X-Nginx-Cache
Frame-Options
X-Cache-Operation
X-Presslabs-Stats
X-Ms-Version
X-Ms-Request-Id
X-Accel-Buffering
MS-CV
X-RTag
Ms-Operation-Id
X-EdgeConnect-Cache-Status
Uber-Trace-Id
Xserver
X-Tumblr-User
X-Tumblr-Pixel-1
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Environment-Context
X-L-Path
X-Cache-Hit
X-Varnish-Server
X-Zen-Fury
Countrycode
X-Mode
X-Cache-NGX
Cross-Origin-Window-Policy
X-Region
X-Forwarded-Host
Ec-Rule-Version
Backend
X-IPS-LoggedIn
X-Servername
X-Backend-Name
X-Content-Powered-By
X-Rewrite-Enabled
X-RN-RSRV
Meta-Geo
Protected
X-JoinUs
X-UPSTREAM-Address
X-Cache-Type
X-SaId
X-Cache-TTL-Remaining
X-Detected-As
X-Routing-Service
X-Sorting-Hat-PodId
X-Proxied
Decoy-Debug-Key
Country-Code
Apigw-Requestid
X-Cache-Grace
Decoy-Debug-Status
Decoy-Debug-TTL
X-Alternate-Cache-Key
X-Tid
Fastly-SSL
Eomportal-Instance
Section-Io-Cache
X-Debug-Cache
X-Sql-Count
X-Sorting-Hat-ShopId
X-Redis-Cache
X-Sql-Duration-Ms
X-Shopify-Stage
X-Human
X-Hosted-By
X-NewRelic-App-Data
X-ShopId
X-ShardId
X-Zipkin-Id
X-Extlb
X-Varnish-Beresp-Grace
X-Uri
X-Generation-Time
X-PERF
X-Microcachable
X-NCache
X-Status
X-Format
X-ApacheServer
X-Site-Version
X-RateLimit-Limit
X-NYM-Debug-Backend
X-Storage
X-Cache-Server
X-Via-Fastly
Cache-Name
Cache-Tv-Group
X-Soup
DB-Nickname
X-Section
X-Web-Node
X-SayCDN-TTL
X-Say-TTL
X-PCL
X-Cache-Host
X-Origin-Date
X-Say-Cacheable
X-ProxyCache-Key
X-OCL
X-BYPASS-REASON
X-Adobe-Loc
Mn-Server-Ip
X-ProxyCache-Status
Url
X-No-Session
X-UA-Device-Type
X-Access
X-PHP-Backend
X-Adobe-Content
SRV
X-Content-Age
TWC-GeoIP-Country
TWC-Privacy
TWC-Locale-Group
TWC-Device-Class
TWC-Connection-Speed
OT-Force-Account-Verify
Property-Id
Selected-Fe
Webcakes-App-Name
Webcakes-Region
X-Proxy-Build
X-Origin-Hint
X-Cluster-Node
X-R9-Blue-Green-Version
X-Akamai-Edgescape
X-Timing-Wait
X-Server-W
Webcakes-App-Version
TWC-GeoIP-LatLong
Azure-SlotName
Azure-Version
X-Pubstack
Azure-SiteName
Azure-RegionName
Azure-InstanceId
X-Ratelimit-Remaining
X-Hyper-Cache
X-FB-TRIP-ID
Content-Secure-Policy
X-ServerID
X-Varnishpool
X-Ua
CDN-Cache
X-LSADC-Cache
CDN-Uid
X-Be
CDN-EdgeStorageId
CDN-CachedAt
X-Webkit-Csp
CDN-PullZone
CDN-RequestId
CDN-RequestCountryCode
X-Hl-Ver
X-Generated-By
LB
X-Azure-Ref-OriginShield
Content-Disposition
X-Cached-By
Source
WPO-Cache-Message
Cache
WPO-Cache-Status
X-Nginx-Cache-Key
X-TIME
X-SRV
X-Unique-Id
X-LAGOON
X-Bc-Bl
X-TT-LOGID
X-Trace-Id
X-Dc
X-Auto-Login
Cache-Hits
X-HTML-Minification-Powered-By
X-Varnish-Hits
Xet-Cookie
X-Origin-CC
X-Origin-TTL
X-TNCMS
X-App-Version
X-Loop
X-Akamai-Transformed
Retry-After
Mime-Version
X-GEO
X-Cdn
Onion-Location
X-S-Maxage
X-Platform-Server
X-Time
X-Varnish-Hostname
X-Amz-Meta-S3cmd-Attrs
HostName
X-Xfnlog-Site
X-Tumblr-Pixel-2
Web-Mar-Node
X-Tumblr-Pixel-3
X-Cache-Var-Map
X-Cache-Var
X-Cache-Remote
X-CSRF-Token
X-EC-Lua
X-Edge-Location
X-Cache-Tags
Webserver
X-Tenant
Upgrade-Insecure-Requests
X-Time-Microsecs
X-Varnish-Cache-Hits
X-Endurance-Cache-Level
ServedBy
X-Proto
X-ECache
X-Request-Time
X-GG-Cache-Date
X-AOL-HN
X-VWS-Id
WP-Super-Cache
CloudFront-Viewer-Country
N-Cache
X-Request-Host
X-LJ-Flow-ID
X-FireWall-Port
X-AWS-Id
X-Mg-Request-UUID
X-B3-SpanId
From-Origin
Nel
X-Correlation-ID
X-M-Log
X-Qnm-Cache
X-M-Reqid
X-Via-NSCOPI
X-Amzn-RequestId
X-PHP-Host
X-Amz-Apigw-Id
X-Labrador-Cache-Channel
X-SD-PageType
X-ScT
X-Shop-Environment
X-External-Request-Id
DSUID
X-Ftr-Request-Id
Expiry
X-Ig-Push-State
DCR-Processing-Time-Ms
X-Forwarded-Path
X-Destination
X-Gen-Mode
X-S
X-Rojux
A
X-Hnp-Log
CDCHOST
X-Session-Fingerprint
X-Developer
DCR-Decision-By
BehaviorPad-Version
X-Cluster
X-A-Dam
X-A-Dcw
X-A-Dgt
X-CF-Lambda-Fn
X-A-Ccd
X-A
User-Cache-Control
V-Age
X-Origin-Response-Time
X-ND-Cache
X-Cache-NE
X-Application
X-ARC
X-B-Cookie
X-Block-Status
X-Orig-Expires
X-A-Wwc
X-Aed
X-Cache-Date
X-PAYTM-SRV-ID
X-CF-Lambda-Version
Mobile-Detection-Method
Odigeo-Trace-Id
X-Conf
Origin
Meta-Geo-Continent
X-Processor
L
X-D
X-Connection-Hash
X-Planisys-CDN-TTL
Pramga
Surrogated-Key
X-PBS-Appsvrname
X-NAPM-TraceId
Sslversion
X-Planisys-CDN-Cache
Redirect-Candidate
Rendered-Blocks
X-Planisys-CDN-Rules
Fastcgi-X-Cache-Version
X-S-Cookie
X-SRCache-Key
Xc-Version
X-Vtex-Remote-Cache
X-SVT-ORM-RULES
X-Vdms-Path
X-Vdms-Version
X-Slack-Backend
X-TIM-N
X-Vtex-Processado-Em
X-SVT-ORM-VERSION
X-VG-WebCache
X-RCS-CacheZone
X-Handled-By
X-Owner
X-Accel-Expires-Debug
X-Origin-Time
X-Origin-Expires
X-Li-Fabric
True-Client-Country-4JS
X-V-Cache
Origin-CC
X-UnsetCookies
Host-ID
X-Proxy-Upstream
Origin-EX
X-Varnish-Beresp-Status
Svr
X-Locale
State
Release
PFcat
X-VarnishDD-TTL
X-Cache-Bucket
X-Epic-Correlation-Id
X-Location
X-Envoy-Decorator-Operation
X-Men
X-Request-URI
X-Fastly-Cache
X-Forwarded-Site
X-HN
X-LI-UUID
X-Geo-Header
X-Gdpr
X-Date
X-Core-Mission
X-RateLimit-Limit-Second
X-Cache-Info
X-Nyt-Route
X-Backend-State
X-Old-Content-Length
X-NodeID
X-Cdn-Srv
X-Aicache-OS
Vix-Hermes-Req-Id
X-Ckpd-Fst-Backend
X-Webstats-RespID
X-VServer
Traceparent
X-Li-Pop
X-RateLimit-Remaining-Second
X-Server-IP
X-Sucuri-Cache
X-Served-From
X-Storefront-Renderer-Rendered
Arc-Country
AKAMAI
X-Scheme
Cmstype
X-Skip-Cache
X-Sucuri-ID
Fastcgi-Cache-TTL
Cmsid
X-Rocket-Nginx-Serving-Static
Fastly-Drupal-Html
X-MP-GENERATED-AT
Environment
X-Cache-Enabled
X-Zone
X-HS-Content-Campaign-Id
X-Core-Value
Wxu-Next-Region
Web-Mar-Region
X-VG-TLSProxy
CacheControlHeader
Server-Info
X-TH-Server
X-Thanos
Wxu-Next-Hostname
Wxu-Next-Commit
X-Csrf-Jwt
Apple-News-Services-Request-Url
X-CGP
X-Bip
X-Hash
X-Cdn-Origin
X-Cache-Id
X-Cache-Debug
X-BBC-Edge-Cache-Status
Apple-News-Services-Handled
X-Level-Front-Cache
X-Mvc-Supplant-Cachable
Fastly-GeoIP-CountryCode
X-ATG-Version
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
X-Adobe-Source
Thinkindot-CacheControl-Type
Machine
X-Thinkindot-L3
Locid
X-Device-Os
X-Developers
L5d-Success-Class
X-Sn-Servicetimems
Thinkindot-Control
X-Policy
X-Fastly-Backend
X-Gzip
X-Eu-Site
X-Esi-Check
X-TrackingId
X-VC-Cache
Req-Svc-Chain
X-Req
Gh-Request-Id
TDXMobile
X-Generated-On
X-Node-Id
Thinkindot-CacheControl
Ha-Gx-Prefs
X-Region-Sid
Server-Host
X-Viewer-Country
X-Gamma-Serve
Ssr
HA-Ipaddr
X-Fetched-On
X-NWS-UUID-VERIFY
X-Magnolia-Registration
X-Xrds-Location
X-DefElseHash
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
X-GeoIP
X-JWT-State
X-Datadog-Trace-Id
X-DefHash
X-GeoIP-City
X-DPWN-IS-SECURE
X-Has-Esi
X-Worker
X-Tx-Id
X-Is-Gdpr
X-Loc
X-Origin
Platform
X-Platform
X-Rebelmouse-Surrogate-Control
X-Backend-TTL
X-Varnish-CookieHashed-On
Cf-Device-Type
X-Irp-Debug
X-Varnish-Remaining-TTL
X-Rebelmouse-Cache-Control
X-Variation
X-Qloud-Router
Fastly-SWR
Fastly-SIE
Is-Eu
Mail-Subject
X-Pod-Name
NGX
We-Hiring
X-Varnish-CookieINHashed-On
X-Amzn-Remapped-Content-Length
X-Rocket-Build-Number
X-Reqid
X-NU-AKA-ACS-Version
X-Cache-Config
X-Branch-Name
Adler-Geo
X-Sigma-Backend
X-Sigma
X-Request-Start
X-Ua-Device
X-Varnish-Beresp-Ttl
AMP-Access-Control-Allow-Source-Origin
X-FC-Vary-Parameters
X-CLOUD-TRACE-CONTEXT
X-GeoIP-Country-Code
Memcached
X-Trace-ID
NM-Fastcgi-Cache
X-Response-By
X-CACHE-KEY
X-GeoIP-Region-Code
X-CS
X-NC
X-API-Version
Datacenter
X-Up
Pics-Label
X-Mvc-Supplant-OutputCached
X-Esi
S-Rt
X-LB-ID
X-Generated-In
Candidate-Md5Url
CDN
Ms-Author-Via
X-Datadome
X-Restarts
X-LB-NoCache
Magicmarker
X-DynaTrace-JS-Agent
X-Tb-Optimization-Total-Bytes-Saved
X-Vc
X-Via-Poph
X-Via-Popn
X-Via-Popv
Env
Kp-EeAlive
On-Server
X-DC
NtCoent-Length
X-TraceId
X-Varnish-Ttl
WebServer
WWW-Authenticate
X-Http-Reason
X-Tt-Logid
X-Cache-Backend
X-Akamai-Request-ID2
Time
X-Wix-Viewer-Type
X-DI
Memory
X-DB
X-Edge-Pop
X-RPM
X-TA-CDN-Provider
X-DW
X-DSS
X-RPS
X-Optimistic-Header
X-Action
X-RSL
Esi-Enabled
X-Refresh
X-CacheTTL
GeoIp-Country-Code
Edge-Cache
X-Minions-Version
X-Service
X-Servedbyhost
C-Via
X-Srv
X-HA-Backend
X-Unique-ID
X-Cache-PHP
X-MSEdge-Flight
X-MSEdge-Features
Accept-Language
X-Parent-Response-Time
X-Varnish-Beresp-TTL
Server-ID
X-Cs
X-Newrelic-Synthetics
X-ZONE
X-TX-ID
X-VCL-Version
X-Webkit-Csp-Report-Only
X-Urbn-Context-Path
Locale
X-Urbn-Site-Id
X-Render-Time
X-Cache-Status-Check
X-Dynatrace
X-Ec-GeoHdr
X-LI-Proto
X-Fpc
X-Cache-Ttl
X-Traceid
X-App
X-Ec-Fail
X-User
X-URL
Test
X-Pass-Why
X-Li-Proto
X-LiteSpeed-Cache-Control
Proxy-Connection
X-B3-Spanid
X-FPC
X-NODE
X-AIR-PT
X-Info
X-Webkit-CSP-Report-Only
X-AK-Request-ID
Cdncip
Server-Id
Cdnsip
Geo-Info
X-Vcl-Version
X-Clientip
Tcn
X-WADP-Cache
UCS
HIT
M-TraceId
X-Clara-WADP
X-Oss-Storage-Class
X-Oss-Server-Time
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
X-Oss-Request-Id
X-Fmm-Version
Cache-Host
Cluster
My-App
X-LiteSpeed-Tag
Resin-Trace
X-CUA
S-Cnection
Tracecode
Cf-Int-Pingora-Origin-Digest
Geoip-Latitude
Fastly-Drupal-HTML
X-HostName
X-Var-Ttl
X-CSRF-TOKEN
X-ID
X-Ha-Backend
T-Server
X-From
Hostname
X-Dynatrace-Js-Agent
X-Pad
GeoIP-Country-Code
Ohc-File-Size
X-Micro-Cache
Hit
X-Fragments
Lang
X-ServedByHost
X-RAMCache
Lfy
Fastly-Backend-Name
User-Agent
X-Mcache
X-Geo
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
X-Via-PopN
X-Via-PopV
X-Via-PopH
Target-Params
X-Edge-POP
X-BBC-Origin-Response-Status
ENV
X-Backend-Host
MIME-Version
X-Release
X-ElasticPress-Query
X-Check-Cacheable
X-APP
X-Cdn-Forward
X-Edge-Cache
X-Api-Version
DataCenter
Section-Origin-Responded
Load-Balancing
X-BCube-Filmed-By
X-NGINX-Cache
Section-Io-Origin-Status
Section-Io-Id
Section-Io-Origin-Time-Seconds
Lb
X-VC
EpKe-Alive
X-ServerName
URI
X-Fastly-Backend-Reqs
Servername
X-Ucs
X-HS-Status
VNS-Age
X-Proxy-Cache-Info
X-Amz-Meta-Cb-Modifiedtime
Uri
Path
Cache-Key
FSS-Cache
CPC-Age
CPC-Cache
X-GoCache-CacheStatus
X-Httpd
VNS-Cache
PICS-Label
X-WA-Info
X-Lb-Nocache
X-UP
X-WA
Permissions-Policy
X-TRACE-ID
X-Wikidot-Backend
X-Lb-Id
X-RateLimit-Reset
Cneonction
X-Nc
X-Wikidot-Static-Cache
X-Provided-By
X-B3-ParentSpanId
Cdn
Ohc-Cache-HIT
ServerName
X-ES-SERVER
Server-Ttl
Cteonnt-Length
Producers
X-Cdn-Request-ID
X-Fastly-Cache-Hits
WZWS-RAY
X-FORWARDED-FOR
X-Dw-Trace-Id
X-Acquia-Application-UUID
X-Akamai-ERPolicy
X-Acquia-Site
Cf-Ipcountry
X-Newrelic-App-Data
X-Acquia-Purge-Tags
X-Acquia-Application-Trace
X-Vcache
X-Akamai-ERRuleID
Vha6-Origin
Shield-Pop
X-PJAX-URL
X-Apw-Access-Token
X-Yottaa-OS
X-Apw-Access-Action
X-Contensis-Viewer-Groups
X-Apw-Access-Object
X-Cache-ASPX
X-SB
X-Cms-Context
CF-Cached-On
Pagetype
X-Swift-Error
X-Snapshot-Date
X-Apw-Hits
X-Pool
X-Cache-CFC
X-Cache-Ngx
Sid
X-Air-Pt
X-Platform-Cluster
X-Udemy-Cache-App-Namespace
GeoIP-Latitude
X-Platform-Processor
X-Platform-Router
X-Last-Modified
MD5-Digest
X-CCDN-Origin-Time
X-CCDN-CacheTTL
X-CacheKey
X-Logging-Id
X-Hcs-Proxy-Type
X-Varnish-Authentication
X-Via-Ucdn
X-Miniprofiler-Ids
X-UA
X-Akamai-Pragma-Client-IP
X-Http-Count
X-Http-Duration-Ms
X-Te-Count
Ngx
X-Sentry-ID
Req-ID
CountryCode
X-Te-Duration-Ms