Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-Cache-Status
Link
Accept-Ranges
CF-RAY
ETag
X-XSS-Protection
Expect-CT
Pragma
X-Powered-By
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
Alt-Svc
P3P
X-Served-By
X-Xss-Protection
X-Download-Options
X-Timer
X-Request-Id
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Cache-Status
X-Generator
X-Cacheable
Timing-Allow-Origin
X-Content-Security-Policy
P3p
X-Iinfo
Status
Feature-Policy
X-Envoy-Upstream-Service-Time
Content-Encoding
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
X-CDN
X-Request-ID
X-AspNetMvc-Version
Upgrade
X-Via
CF-Ray
X-Ws-Request-Id
Access-Control-Max-Age
Server-Timing
EagleId
X-Cache-Group
Keep-Alive
X-Turbo-Charged-By
Request-Context
X-Age
X-Server-Powered-By
X-Proxy-Cache
X-AH-Environment
X-Backend
X-UA-Device
X-Hacker
X-Robots-Tag
Report-To
X-Amz-Request-Id
Host-Header
X-Server
X-Amz-Id-2
X-LiteSpeed-Cache
Grace
X-Dns-Prefetch-Control
X-Rq
X-Nginx-Cache-Status
X-Varnish-Cache
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-WebKit-CSP
X-Page-Speed
X-Vhost
EagleEye-TraceId
X-OneAgent-JS-Injection
X-Amz-Version-Id
X-Ua-Compatible
X-Pingback
X-Dispatcher
X-Device
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Cache-Spec
NEL
X-Server-Id
X-Host
Cf-Railgun
X-Node
X-Backend-Server
Accept-CH
X-Readtime
X-Akam-SW-Version
Surrogate-Control
Request-Id
X-Response-Time
X-HW
Xkey
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Application-Context
Content-Location
X-Ruxit-JS-Agent
Rating
X-B3-TraceId
Accept-Ch-Lifetime
X-Country
Accept-CH-Lifetime
X-Cache-Lookup
X-Cloud-Trace-Context
X-Trace
X-Url
X-Ac
X-Content-Type
Allow
X-TtlSet
X-Vname
X-PC
X-Varnish-TTL
X-Clacks-Overhead
X-Mod-Pagespeed
Edge-Control
X-FastCGI-Cache
X-ESI
Fastly-Restarts
X-Server-Name
Cache-Tag
Service-Worker-Allowed
X-Rack-Cache
X-VARITI-CCR
X-Element-Page-Cache
Verso
X-Language
X-MS-InvokeApp
X-Upstream
X-GitHub-Request-Id
MS-Author-Via
X-Amz-Rid
Public-Key-Pins
X-Vcap-Request-Id
X-Aws-Lambda-Call-Status
X-Cached
X-Dw-Request-Base-Id
X-Client-IP
X-D2id
X-Abt-Application-Version
X-Cache-TTL
X-Template
X-Cnection
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-Origin-Cache
X-Aspnetmvc-Version
X-Px
Arr-Disable-Session-Affinity
X-Country-Code
RTSS
Access-Control-Request-Method
X-Navigation-Version
X-Powered-By-Plesk
X-Goog-Hash
X-NF-Request-ID
X-Kraken-Loop-Name
X-Instrumentation
X-Server-Lifecycle-Phase
Accept-Ch
X-Kinja
X-GoogleNews-Bot
X-Exp-Id
X-Exp-Variant
X-Kinja-Revision
X-Version
X-Kinja-Server
X-Cdn-Fetch
X-Kinja-Build
X-Use-Magma
X-Powered-CMS
Display
X-Middleton-Display
X-Sol
Pagespeed
AR-Request-ID
AR-PoweredBy
AR-CACHE
AR-SID
AR-ATIME
X-Amz-Server-Side-Encryption
Response
X-Middleton-Response
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-MSEdge-Ref
X-LLID
X-Edge-Location-Klb
X-Kinsta-Cache
X-Edge
Nginx-Cache
Mrf-Cache-Status
MRF-Tech
X-TTL
X-B3-TraceId-Primal
X-RateLimit-Remaining
X-Protected-By
X-Shield-Request-Id
X-Jurisdiction
X-HP-Webp
X-HP-Trace-Id
X-T
TCN
X-Buckets
S
X-Forwarded-For
X-Content-Security-Policy-Report-Only
Content-MD5
X-Mg-S
X-Id
Edge-Cache-Tag
X-Mid
Realpath
Fastcgi-Cache
X-CST
SPRequestDuration
SPIisLatency
X-MCACHE
Front-End-Https
X-Recruiting
X-Request-Processing-Time
X-Request-Received
X-Ttl
Pinterest-Generated-By
Filters
X-Pinterest-Rid
Pinterest-Version
Server-Node
X-Content
X-Ua-Browser
X-Ab
X-Correlation-Id
X-DynaTrace
Server-Name
X-ECACHE
X-Frontend
X-Parallel-Accel
X-NWS-LOG-UUID
X-SharePointHealthScore
SPRequestGuid
X-Ruxit-Js-Agent
X-HS-Cache-Config
X-HS-Hub-Id
X-HS-Content-Id
X-Ezoic-Cdn
Fusion-Deployment-Id
Fusion-Content-Id
Fusion-Component-Id
Fusion-Content-Source
Fusion-Template-Id
Fusion-Source
X-HS-Combine-CSS
X-Yandex-Sdch-Disable
X-Hits
Alternate-Protocol
X-Ser
X-Cache-Key
X-Content-Options
MicrosoftSharePointTeamServices
X-Tt-Trace-Host
X-Tt-Trace-Tag
Cache-Tags
X-Page-Id
Charset
Host
Cleartype
X-Kong-Upstream-Latency
X-Git-Hash
X-B3-Sampled
X-Kong-Proxy-Latency
X-Fastly-Request-Id
X-Www-Served-By
X-Daa-Tunnel
X-Accel-Expires
X-Geo-Country
X-ASPNET-VERSION
X-Content-Digest
X-DIS-Request-ID
X-Amz-Replication-Status
X-Amzn-Trace-Id
Filterid
X-Debug-Info
X-Varnish-Age
TP-L2-Cache
X-Forwarded-Proto
X-Hostname
TP-Cache
X-AppVersion
X-Az
X-Activity-Id
X-VCache
X-FB-Debug
X-Upgrade-Enabled
X-Rid
X-Grace
X-Origin-Server
Access-Control-Allow-Method
X-N
X-XRDS-LOCATION
Cross-Origin-Opener-Policy
X-Ratelimit-Limit
X-Nginx-Upstream-Cache-Status
X-LB-Cache
X-WebKit-CSP-Report-Only
X-F-Cache
X-Mobile-URL
ServerID
X-Request-Guid
X-Flags
X-Aspnet-Duration-Ms
X-Route-Name
X-Providence-Cookie
X-Is-Crawler
X-Whom
X-TT
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-Goog-Metageneration
X-GUploader-UploadID
X-Goog-Generation
X-Tb
X-Varnish-Grace
X-App-Environment
Viewport
Payment
Node
X-FW-Hash
X-FW-Static
X-FW-Type
X-FW-Server
X-FW-Dynamic
X-Distributor
X-App-Server
X-FW-Serve
X-Origin-Upstream-Status
DC
X-Seen-By
Paypal-Debug-Id
X-Server-ID
X-Type
X-NGENIX-Cache
X-User-Agent
Fastcgi-Useragent
X-Cache-Control
Country
Accept-Charset
X-Logged-In
X-Microsite
X-Request-Handler-Origin-Region
X-Wix-Request-Id
X-Cache-Rule
X-Cache-Age
X-Litespeed-Cache
Version
X-Webkit-Csp
X-Via-JSL
X-Webkit-CSP
X-Varnish-Backend
X-Drupal-Cache-Tags
Referer-Policy
X-DataDome
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Browser-Type
Refresh
X-Cluster-Name
X-Load-Cache
X-Node-Name
X-Signature
X-Contextid
X-B-Cache
Amp-Access-Control-Allow-Source-Origin
Access-Control-Request-Headers
X-Mobile
X-Response-Served-From
SD-X-WS
X-Cache-Action
X-Original-Request-Id
X-Tec-Api-Origin
X-Tec-Api-Root
Cache-Status
X-Tec-Api-Version
X-Cache-Expired-At
X-Is-Bot
X-Vgn-Hpd-Reason
X-Jobs
X-Real-IP
X-Cacheable-TTL
X-Page-View
X-Rendered-As
X-IPLB-Instance
X-Proxy-Cache-Status
X-UUID
NGB
VIX-Pulpo-Node
X-ProcessESI
X-RemovedCookies
X-Revision
X-B
X-Debug
VIX-Pulpo-Upstream-Status
X-Instance
X-Yottaa-Metrics
X-Device-Type
X-Rule
X-Yottaa-Optimizations
X-Proxy
X-Fastly-Request-ID
X-Cache-Time
X-Drupal-Cache-Contexts
Akamai-GRN
X-G
Surrogate-Key
X-Framework
X-Debug-IsPreview
X-Debug-IsConnected
X-FW-Version
CF-IPCountry
X-Fastcgi-Cache
X-Air-Hostname
X-Air-Source
X-Air-Trace-Id
SID
DynaTrace
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Ratelimit-Reset
Liferay-Portal
X-PressLabs-Stats
X-Azure-Ref
X-Oracle-Dms-Rid
Healthy
X-Oracle-Dms-Ecid
X-Presslabs-Stats
Frame-Options
X-Source
X-Ua-Device
X-Ms-Version
GEO-INFO
X-Ms-Request-Id
Count-Hit
X-Cache-Operation
Ms-Operation-Id
MS-CV
X-Oneagent-Js-Injection
X-CDN-Forward
X-RTag
X-Nginx-Cache
Uber-Trace-Id
X-Accel-Buffering
X-APP-VERSION
X-EdgeConnect-Cache-Status
X-L-Path
Xserver
X-Tumblr-Pixel
X-Tumblr-User
X-Cache-Hit
X-Environment-Context
Countrycode
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-Varnish-Server
X-XRDS-Location
X-Zen-Fury
X-Region
X-Backend-Name
X-Mode
Ec-Rule-Version
X-Servername
X-Forwarded-Host
Backend
Cross-Origin-Window-Policy
X-Cache-NGX
X-Content-Powered-By
X-IPS-LoggedIn
Section-Io-Cache
X-Cache-TTL-Remaining
X-Cache-Type
X-RN-RSRV
X-JoinUs
Meta-Geo
X-UPSTREAM-Address
Protected
X-SaId
X-Detected-As
X-Sql-Duration-Ms
X-Debug-Cache
X-Redis-Cache
Decoy-Debug-Status
Decoy-Debug-Key
Apigw-Requestid
Country-Code
Decoy-Debug-TTL
Eomportal-Instance
X-Routing-Service
X-Cache-Server
X-Alternate-Cache-Key
X-Cache-Grace
X-ShardId
X-Extlb
X-Generation-Time
X-Tid
X-Proxied
X-Varnish-Beresp-Grace
X-Hosted-By
X-Human
X-Zipkin-Id
X-ShopId
X-Sorting-Hat-ShopId
X-Sql-Count
X-Uri
X-Shopify-Stage
X-Rewrite-Enabled
X-Sorting-Hat-PodId
X-Soup
X-No-Session
X-Via-Fastly
X-Site-Version
X-PERF
X-NCache
Url
X-UA-Device-Type
X-Microcachable
X-Status
X-ProxyCache-Key
Mn-Server-Ip
X-ServerID
X-Storage
X-FB-TRIP-ID
Cache-Name
Cache-Tv-Group
X-PHP-Backend
X-Origin-Date
X-ProxyCache-Status
X-ApacheServer
Fastly-SSL
X-BYPASS-REASON
Selected-Fe
DB-Nickname
TWC-Connection-Speed
Property-Id
X-Origin-Hint
X-OCL
X-PCL
TWC-Device-Class
Webcakes-Region
X-NYM-Debug-Backend
X-Format
X-Cache-Host
X-SayCDN-TTL
X-Server-W
X-Proxy-Build
X-Say-TTL
X-Say-Cacheable
X-Akamai-Edgescape
X-Adobe-Loc
X-Web-Node
TWC-Locale-Group
TWC-GeoIP-LatLong
TWC-Privacy
Webcakes-App-Name
X-Timing-Wait
Webcakes-App-Version
TWC-GeoIP-Country
X-Adobe-Content
X-NewRelic-App-Data
X-R9-Blue-Green-Version
OT-Force-Account-Verify
X-Pubstack
X-Access
X-Hl-Ver
X-Section
X-Content-Age
X-Varnishpool
X-Cluster-Node
Azure-InstanceId
Azure-RegionName
Azure-SlotName
Azure-Version
Azure-SiteName
X-RateLimit-Limit
X-Be
Content-Secure-Policy
X-LSADC-Cache
X-Ua
SRV
X-Hyper-Cache
CDN-Uid
CDN-Cache
CDN-RequestId
CDN-CachedAt
CDN-PullZone
CDN-RequestCountryCode
CDN-EdgeStorageId
X-Generated-By
X-Azure-Ref-OriginShield
X-TIME
Content-Disposition
Source
X-Trace-Id
X-Cached-By
X-Unique-Id
LB
X-SRV
X-Dc
Cache
WPO-Cache-Message
X-Nginx-Cache-Key
WPO-Cache-Status
X-Bc-Bl
X-Ratelimit-Remaining
X-LAGOON
X-App-Version
X-HTML-Minification-Powered-By
Cache-Hits
Retry-After
X-Auto-Login
X-Varnish-Hits
X-Akamai-Transformed
X-Loop
X-Amz-Meta-S3cmd-Attrs
X-Varnish-Hostname
X-Origin-CC
X-Origin-TTL
X-TNCMS
Xet-Cookie
X-GEO
X-TT-LOGID
X-S-Maxage
Onion-Location
Mime-Version
X-Platform-Server
X-Cdn
X-Xfnlog-Site
Web-Mar-Node
X-Cache-Var
X-Tumblr-Pixel-2
X-Cache-Var-Map
X-Tumblr-Pixel-3
X-Proto
HostName
X-Time
X-Cache-Tags
X-Cache-Remote
Webserver
X-Endurance-Cache-Level
X-Varnish-Cache-Hits
X-Time-Microsecs
X-CSRF-Token
X-Edge-Location
X-Tenant
Upgrade-Insecure-Requests
X-Request-Time
X-VWS-Id
ServedBy
X-LJ-Flow-ID
X-AWS-Id
N-Cache
X-EC-Lua
X-GG-Cache-Date
X-AOL-HN
CloudFront-Viewer-Country
X-B3-SpanId
X-Xrds-Location
X-ECache
X-Request-Host
X-M-Log
X-M-Reqid
X-Mg-Request-UUID
X-Qnm-Cache
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Labrador-Cache-Channel
From-Origin
X-PHP-Host
X-FireWall-Port
WP-Super-Cache
X-Via-NSCOPI
X-Block-Status
Redirect-Candidate
Rendered-Blocks
X-CACHE-KEY
X-Cache-Date
Pramga
A
BehaviorPad-Version
X-Application
X-ARC
X-B-Cookie
X-Cache-NE
X-Gen-Mode
X-ScT
Xc-Version
X-SD-PageType
X-CF-Lambda-Fn
X-Forwarded-Path
X-S-Cookie
X-S
V-Age
X-ND-Cache
X-Rojux
X-Ftr-Request-Id
X-Processor
CDCHOST
X-A-Dam
X-A-Ccd
L
X-A-Dcw
X-PAYTM-SRV-ID
X-A
X-Origin-Response-Time
Origin
Odigeo-Trace-Id
Mobile-Detection-Method
Meta-Geo-Continent
X-PBS-Appsvrname
X-A-Dgt
DCR-Processing-Time-Ms
DSUID
DCR-Decision-By
X-Planisys-CDN-TTL
X-Aed
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
X-A-Wwc
X-Orig-Expires
Fastcgi-X-Cache-Version
Expiry
X-CF-Lambda-Version
X-Ig-Push-State
Nel
X-RCS-CacheZone
X-Conf
X-Connection-Hash
X-Vdms-Version
X-SRCache-Key
X-Cluster
X-Slack-Backend
X-Hnp-Log
Surrogated-Key
X-Developer
User-Cache-Control
X-Correlation-ID
X-NAPM-TraceId
X-TIM-N
X-D
X-V-Cache
X-Destination
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-VG-WebCache
X-Vdms-Path
X-Vtex-Remote-Cache
X-Vtex-Processado-Em
Sslversion
X-Ckpd-Fst-Backend
X-External-Request-Id
X-Session-Fingerprint
X-Shop-Environment
X-Locale
X-Handled-By
X-MP-GENERATED-AT
X-Sucuri-ID
Fastcgi-Cache-TTL
X-Origin-Expires
True-Client-Country-4JS
X-Server-IP
Cmsid
X-Aicache-OS
X-LI-UUID
Cmstype
X-Device-Os
X-Scheme
X-Hash
X-Sucuri-Cache
X-Varnish-Beresp-Status
X-Fastly-Cache
X-Date
X-Origin-Time
Wxu-Next-Region
Wxu-Next-Hostname
X-Fetched-On
Svr
X-Owner
X-Served-From
X-Rocket-Nginx-Serving-Static
Gh-Request-Id
X-Forwarded-Site
X-Core-Mission
Host-ID
X-Accel-Expires-Debug
X-Li-Fabric
Origin-CC
X-Nyt-Route
Server-Info
X-Geo-Header
X-Old-Content-Length
X-Men
X-Cache-Bucket
X-Mvc-Supplant-Cachable
Vix-Hermes-Req-Id
X-Gdpr
Origin-EX
State
X-NodeID
X-Cdn-Srv
X-Cache-Info
X-Skip-Cache
X-Epic-Correlation-Id
Release
X-Storefront-Renderer-Rendered
Arc-Country
X-VarnishDD-TTL
X-HN
X-Policy
CacheControlHeader
Wxu-Next-Commit
PFcat
X-Webstats-RespID
Ssr
X-Proxy-Upstream
Traceparent
X-VServer
AKAMAI
X-Location
X-Li-Pop
X-NWS-UUID-VERIFY
Fastly-Drupal-Html
X-VC-Cache
AMP-Access-Control-Allow-Source-Origin
Environment
We-Hiring
X-Cache-Config
X-Fastly-Backend
X-Esi-Check
X-Gamma-Serve
X-Cdn-Origin
X-Irp-Debug
X-HS-Content-Campaign-Id
X-Developers
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
X-Datadog-Trace-Id
X-Core-Value
X-Cache-Id
X-Cache-Debug
X-BBC-Edge-Cache-Status
X-Level-Front-Cache
X-ATG-Version
X-Adobe-Source
X-Gzip
X-Bip
X-Generated-On
X-GeoIP
X-GeoIP-City
X-Branch-Name
Web-Mar-Region
X-Req
X-Sigma
X-Rocket-Build-Number
X-Sigma-Backend
X-Sn-Servicetimems
X-Thanos
X-TH-Server
X-Reqid
X-Magnolia-Registration
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
Apple-News-Services-Handled
X-Cache-Enabled
X-Region-Sid
X-Thinkindot-L3
X-TrackingId
L5d-Success-Class
HA-Ipaddr
X-Eu-Site
X-Backend-State
X-Csrf-Jwt
X-CGP
Ha-Gx-Prefs
X-RateLimit-Limit-Second
X-Viewer-Country
X-VG-TLSProxy
X-Request-URI
X-UnsetCookies
X-RateLimit-Remaining-Second
Apple-News-Services-Request-Url
X-Request-Start
Mail-Subject
X-Envoy-Decorator-Operation
Machine
Locid
Fastly-GeoIP-CountryCode
Req-Svc-Chain
Server-Host
Thinkindot-CacheControl-Type
Thinkindot-Control
Thinkindot-CacheControl
TDXMobile
X-Node-Id
X-Platform
X-Zone
X-Varnish-CookieINHashed-On
X-DPWN-IS-SECURE
X-Varnish-Remaining-TTL
X-Varnish-CookieHashed-On
X-DefHash
NGX
NM-Fastcgi-Cache
X-DefElseHash
X-Loc
X-Origin
Cf-Device-Type
X-Amzn-Remapped-Content-Length
X-Pod-Name
X-NU-AKA-ACS-Version
X-Worker
Platform
X-FC-Vary-Parameters
Adler-Geo
Memcached
X-Variation
X-Response-By
X-Has-Esi
Fastly-SWR
X-Rebelmouse-Cache-Control
Is-Eu
X-Qloud-Router
Fastly-SIE
X-Is-Gdpr
X-Rebelmouse-Surrogate-Control
X-JWT-State
X-Tx-Id
X-Datadome
X-Backend-TTL
X-Mvc-Supplant-OutputCached
X-Varnish-Beresp-Ttl
Datacenter
X-API-Version
X-Up
X-GeoIP-Region-Code
X-NC
X-CS
X-CLOUD-TRACE-CONTEXT
X-GeoIP-Country-Code
Candidate-Md5Url
X-Generated-In
X-LB-ID
CDN
Pics-Label
X-Vc
X-TraceId
Magicmarker
Ms-Author-Via
X-Trace-ID
S-Rt
X-Tt-Logid
X-Tb-Optimization-Total-Bytes-Saved
X-DynaTrace-JS-Agent
On-Server
WWW-Authenticate
Env
X-Restarts
Kp-EeAlive
NtCoent-Length
X-LB-NoCache
X-Edge-Pop
X-Optimistic-Header
Time
X-Varnish-Ttl
GeoIp-Country-Code
Memory
X-Via-Popv
WebServer
X-Via-Poph
Esi-Enabled
X-Via-Popn
X-Http-Reason
X-Akamai-Request-ID2
X-RPS
X-Refresh
X-RPM
X-Cache-Backend
X-RSL
X-DW
Edge-Cache
X-Wix-Viewer-Type
X-TA-CDN-Provider
X-DB
X-DI
X-DSS
X-Action
X-CacheTTL
X-Service
X-DC
C-Via
X-Dynatrace
X-Varnish-Beresp-TTL
X-Cache-PHP
X-Parent-Response-Time
X-Minions-Version
X-Cs
X-Servedbyhost
X-Esi
X-Newrelic-Synthetics
X-Srv
X-MSEdge-Flight
X-Unique-ID
X-ZONE
Server-ID
X-MSEdge-Features
X-TX-ID
Accept-Language
X-Cache-Status-Check
X-HA-Backend
X-Render-Time
Locale
X-VCL-Version
X-Urbn-Context-Path
X-Urbn-Site-Id
X-Ec-GeoHdr
X-User
X-App
X-Li-Proto
X-Cache-Ttl
X-LI-Proto
X-Ec-Fail
X-Fpc
X-URL
Proxy-Connection
X-Info
X-Webkit-Csp-Report-Only
X-AIR-PT
X-Pass-Why
X-FPC
Test
X-LiteSpeed-Cache-Control
X-Traceid
X-Clientip
X-Vcl-Version
Server-Id
X-B3-Spanid
X-NODE
X-Webkit-CSP-Report-Only
Geo-Info
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
Tcn
UCS
X-Oss-Server-Time
X-Oss-Request-Id
X-Oss-Storage-Class
Cdnsip
Cdncip
Cache-Host
X-AK-Request-ID
HIT
Cluster
Geoip-Latitude
My-App
X-CSRF-TOKEN
X-Fmm-Version
X-WADP-Cache
X-Clara-WADP
S-Cnection
M-TraceId
X-Var-Ttl
X-LiteSpeed-Tag
Tracecode
Cf-Int-Pingora-Origin-Digest
X-CUA
Hostname
Fastly-Drupal-HTML
Resin-Trace
X-Ha-Backend
X-HostName
X-ServedByHost
User-Agent
Fastly-Backend-Name
X-Micro-Cache
X-From
Lfy
T-Server
X-ID
X-COUNTRY
X-Dynatrace-Js-Agent
X-Fragments
GeoIP-Country-Code
Lang
X-RAMCache
X-Pad
X-Via-PopV
X-Via-PopN
X-Via-PopH
Hit
X-BBC-Origin-Response-Status
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
Section-Io-Id
X-Mcache
Ohc-File-Size
X-Release
X-NGINX-Cache
Section-Origin-Responded
X-Backend-Host
X-Geo
Lb
X-Cdn-Forward
X-Edge-POP
ENV
MIME-Version
X-Check-Cacheable
X-BCube-Filmed-By
X-WP-CF-Super-Cache
Target-Params
X-APP
X-ElasticPress-Query
X-WP-CF-Super-Cache-Cache-Control
X-Edge-Cache
DataCenter
Load-Balancing
X-Api-Version
X-HS-Status
Uri
X-ServerName
Servername
Path
VNS-Age
CPC-Age
URI
X-Ucs
Cache-Key
VNS-Cache
CPC-Cache
X-Fastly-Backend-Reqs
X-Amz-Meta-Cb-Modifiedtime
X-WA-Info
EpKe-Alive
X-WA
X-VC
X-ES-SERVER
X-GoCache-CacheStatus
X-Wikidot-Static-Cache
X-Fastly-Cache-Hits
X-UP
X-Lb-Nocache
PICS-Label
X-Lb-Id
X-Wikidot-Backend
X-Proxy-Cache-Info
X-Httpd
Permissions-Policy
FSS-Cache
X-TRACE-ID
X-B3-ParentSpanId
X-RateLimit-Reset
X-Cms-Context
X-Nc
Shield-Pop
Producers
ServerName
Cdn
X-PJAX-URL
WZWS-RAY
X-Cdn-Request-ID
Cteonnt-Length
Pagetype
Cneonction
Ohc-Cache-HIT
X-Provided-By
X-Dw-Trace-Id
X-Akamai-ERPolicy
Cf-Ipcountry
X-Pool
X-SB
Srv
X-Cache-CFC
X-Acquia-Application-UUID
Server-Ttl
X-Newrelic-App-Data
X-Acquia-Site
X-Acquia-Application-Trace
X-Acquia-Purge-Tags
X-Akamai-ERRuleID
X-Vcache
X-Swift-Error
X-Snapshot-Date
X-Contensis-Viewer-Groups
Vha6-Origin
X-Apw-Access-Action
CF-Cached-On
MD5-Digest
X-CCDN-CacheTTL
X-CCDN-Origin-Time
X-Cache-ASPX
X-Yottaa-OS
X-Via-Ucdn
X-Apw-Hits
X-Apw-Access-Token
X-Hcs-Proxy-Type
X-Akamai-Pragma-Client-IP
X-Apw-Access-Object
X-Cache-Ngx
Sid
X-Air-Pt
X-Platform-Router
Server-Hostname
X-Logging-Id
X-Platform-Processor
Server-Ext
X-Udemy-Cache-App-Namespace
W
X-Last-Modified
X-Platform-Cluster
X-B3-Parentspanid
Sever-Int
X-Te-Duration-Ms
CountryCode
Req-ID
X-SIPLIST1
X-VG-WebServer
X-Sentry-ID
Ngx
X-Http-Count
X-Http-Duration-Ms
X-CacheKey
X-Varnish-Authentication
X-Miniprofiler-Ids
X-UA
X-Te-Count
IsBot