Threat Level: green Handler on Duty: Guy Bruneau

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
X-XSS-Protection
Last-Modified
Cf-Request-Id
CF-Cache-Status
CF-RAY
ETag
Accept-Ranges
Expect-CT
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
X-Served-By
P3P
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
X-Xss-Protection
X-FRAME-OPTIONS
Access-Control-Allow-Credentials
Content-Security-Policy-Report-Only
X-Runtime
X-AspNet-Version
P3p
X-DNS-Prefetch-Control
X-Cache-Status
Accept-CH
X-Drupal-Cache
Accept-CH-Lifetime
X-Check
X-Generator
X-Ua-Compatible
X-Cacheable
Server-Timing
X-Envoy-Upstream-Service-Time
Timing-Allow-Origin
X-Iinfo
X-Drupal-Dynamic-Cache
Access-Control-Expose-Headers
Feature-Policy
X-Content-Security-Policy
Content-Encoding
X-Request-ID
X-CDN
Status
Upgrade
X-AspNetMvc-Version
Access-Control-Max-Age
X-Via
X-Amz-Request-Id
X-Amz-Id-2
Host-Header
CF-Ray
X-Backend
Allow
X-Cache-Group
Cf-Edge-Cache
Request-Context
X-Robots-Tag
X-Server
Keep-Alive
X-Hacker
X-UA-Device
X-AH-Environment
X-Turbo-Charged-By
X-Ws-Request-Id
X-Vhost
X-Proxy-Cache
X-Rq
X-Age
Xkey
EagleId
X-Dispatcher
X-Server-Powered-By
X-Amz-Version-Id
X-Varnish-Cache
Grace
Cf-Apo-Via
X-LiteSpeed-Cache
X-Page-Speed
Cf-Railgun
X-Pingback
EagleEye-TraceId
X-Device
X-Swift-CacheTime
X-Swift-SaveTime
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-WebKit-CSP
X-Aws-Lambda-Call-Status
X-Dns-Prefetch-Control
Ali-Swift-Global-Savetime
X-CST
X-OneAgent-JS-Injection
X-Backend-Server
Permissions-Policy
X-Server-Id
Accept-Ch-Lifetime
X-Readtime
X-Host
X-Response-Time
X-Akam-SW-Version
Surrogate-Control
Request-Id
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Nginx-Upstream-Cache-Status
X-HW
X-Cloud-Trace-Context
X-Node
X-Nginx-Cache-Status
Accept-Ch
X-Application-Context
X-Country-Code
X-Trace
X-Oneagent-Js-Injection
Content-Location
X-Ruxit-JS-Agent
X-Cache-Lookup
Service-Worker-Allowed
X-Country
X-Content-Type
X-Clacks-Overhead
X-ECACHE
X-Url
X-Edge
X-Litespeed-Cache
X-Mod-Pagespeed
X-Rack-Cache
X-Amz-Server-Side-Encryption
X-Origin-Cache-Key
Cache-Tag
X-Midtier
X-FTR-Request-ID
Cross-Origin-Opener-Policy
X-MS-InvokeApp
X-Mcache
X-Powered-By-Plesk
X-Upstream
X-Vname
X-TtlSet
Nginx-Cache
X-PC
Rating
Edge-Control
X-ESI
X-D2id
X-Browser-Type
X-Exp-Variant
X-Element-Page-Cache
X-GoogleNews-Bot
X-Exp-Id
X-Cdn-Fetch
X-Kinja-Revision
X-Kinja-Server
X-Kinja-Build
X-Kinja
Verso
X-Times
X-Ruxit-Js-Agent
X-Ac
X-Server-Name
X-Cnection
SPRequestDuration
SPIisLatency
X-Vcap-Request-Id
AR-ATIME
AR-PoweredBy
AR-Request-ID
AR-SID
X-Navigation-Version
X-Abt-Application-Version
X-RateLimit-Remaining
X-Dw-Request-Base-Id
X-B3-TraceId
X-SharePointHealthScore
SPRequestGuid
X-NF-Request-ID
X-Ser
X-VARITI-CCR
Pinterest-Generated-By
Pinterest-Version
X-Pinterest-Rid
Origin-Trial
X-GitHub-Request-Id
RTSS
AR-CACHE
S
X-Cache-TTL
X-Cache-Key
X-Mg-S
X-Content-Security-Policy-Report-Only
X-Amz-Rid
Edge-Cache-Tag
X-Goog-Hash
Fastly-Restarts
X-Sol
Display
X-Middleton-Display
Pagespeed
X-Amzn-Trace-Id
X-Varnish-TTL
X-Powered-CMS
X-NWS-LOG-UUID
X-Ttl
X-Kraken-Loop-Name
X-Erf-Bev-Bev
X-ARC
X-Erf-Bev-Bev-Is-Generated
X-Server-Lifecycle-Phase
X-Version
X-Instrumentation
X-Kinsta-Cache
X-Edge-Location-Klb
Access-Control-Request-Method
X-Recruiting
X-Server-ID
X-Client-IP
Cache-Status
X-SRCache-Store-Status
X-SRCache-Fetch-Status
Arr-Disable-Session-Affinity
X-Content-Digest
X-T
X-MSEdge-Ref
Content-MD5
X-Accel-Expires
Response
X-Middleton-Response
X-Forwarded-For
MicrosoftSharePointTeamServices
X-Ua-Device
X-TraceId
X-Hits
TP-Cache
X-RateLimit-Limit
X-Shield-Request-Id
X-Cached
Public-Key-Pins
X-Erf-Stays-Pdp-Viaduct-Migration-Web-V2
X-WebKit-CSP-Report-Only
X-Id
X-Request-Processing-Time
X-FTR-Backend-Server
X-Frontend
X-Country-Code-Real
X-FTR-Balancer
X-FTR-Cache-Status
X-Request-Received
X-FTR-Backend
X-FTR-Expires
X-Ua-Browser
X-Kinja-CCPA
Server-Node
X-HS-Combine-CSS
X-HS-Cache-Config
X-HS-Content-Id
X-HS-Hub-Id
Payment
MS-Author-Via
X-Fastcgi-Cache
X-DIS-Request-ID
X-LLID
Cross-Origin-Resource-Policy
Front-End-Https
X-Webkit-Csp
X-HP-Webp
X-Jurisdiction
X-Forwarded-Proto
X-HP-Trace-Id
X-GUploader-UploadID
X-FastCGI-Cache
Cache-Tags
TP-L2-Cache
Realpath
X-Amz-Apigw-Id
X-LB-Cache
X-Amzn-RequestId
X-TTL
X-Protected-By
X-PressLabs-Stats
X-Origin-Server
Count-Hit
X-Distributor
X-ORACLE-DMS-RID
X-Daa-Tunnel
X-Request-Handler-Origin-Region
X-Microsite
X-F-Cache
Mrf-Cache-Status
MRF-Tech
X-B3-TraceId-Primal
Accept-Charset
X-Correlation-Id
X-Az
X-Varnish-Backend
X-Cluster-Name
X-Activity-Id
X-AppVersion
X-Www-Served-By
X-Page-Id
X-NGENIX-Cache
X-Geo-Country
X-App-Server
X-Hostname
X-Rid
Referer-Policy
X-FB-Debug
X-Debug-Info
X-Goog-Metageneration
X-Varnish-Server
Host
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
Fastcgi-Cache
X-TEC-API-ROOT
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-Envoy-Decorator-Operation
X-Git-Hash
X-ORACLE-DMS-ECID
Access-Control-Allow-Method
X-RateLimit-Reset
Retry-After
Server-Name
X-Px
X-Tt-Trace-Host
X-Tt-Trace-Tag
DC
X-Content-Options
X-B3-Sampled
X-Fastly-Request-ID
X-Oracle-Dms-Ecid
X-Load-Cache
X-Providence-Cookie
X-Route-Name
X-Is-Crawler
X-Aspnet-Duration-Ms
X-Flags
X-Request-Guid
X-Revision
X-Contextid
X-Mobile
X-Origin-Cache
X-App-Environment
X-B-Cache
X-Signature
Cleartype
TCN
X-TT
Paypal-Debug-Id
X-Trace-Id
X-Type
Charset
X-Language
X-Fb-Rlafr
X-B
X-Grace
X-Datadog-Trace-Id
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
Section-Io-Cache
Frame-Options
X-Newrelic-App-Data
X-Goog-Stored-Content-Encoding
X-Amz-Replication-Status
X-Goog-Storage-Class
X-Logged-In
X-Amz-Meta-S3cmd-Attrs
X-Cache-Control
X-Goog-Generation
X-Goog-Stored-Content-Length
X-ASPNET-VERSION
Filterid
X-Seen-By
X-XRDS-LOCATION
X-Oracle-Dms-Rid
X-EdgeConnect-Cache-Status
X-Wix-Request-Id
X-Whom
X-Ratelimit-Limit
Healthy
X-Magnolia-Registration
X-Upgrade-Enabled
X-Ezoic-Cdn
X-App-Version
Content-Disposition
X-Azure-Ref
X-CSRF-Token
X-Node-Name
Backend
X-Proxy
X-N
Akamai-GRN
X-Air-Pt
X-Template
Upgrade-Insecure-Requests
NGB
X-Fastly-Request-Id
X-Use-Magma
X-XRDS-Location
X-Proxy-Cache-Info
X-B3-SpanId
Refresh
X-Varnish-Ttl
X-Response-Served-From
X-Original-Request-Id
X-Rendered-As
X-Is-Bot
X-Servername
Url
X-RTag
Ms-Operation-Id
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Unique-Id
X-Tumblr-User
X-Tumblr-Pixel-1
SD-X-WS
MS-CV
X-ProcessESI
X-RemovedCookies
X-Page-View
X-Tumblr-Pixel
Liferay-Portal
X-Tumblr-Pixel-0
X-UUID
X-Cacheable-TTL
X-Datadog-Sampled
X-Adobe-Content
Viewport
X-Adobe-Loc
X-Cache-Grace
X-Debug-IsConnected
X-Instance
X-Debug-IsPreview
X-L-Path
X-Jobs
X-Environment-Context
X-G
X-Region
X-Varnish-Grace
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-FW-Version
X-IPS-LoggedIn
X-Amzn-Remapped-Content-Length
X-FW-Type
X-FW-Dynamic
X-FW-Serve
X-FW-Hash
X-FW-Server
X-FW-Static
Fastly-SIE
Fastly-SWR
From-Origin
X-Debug
X-Cache-Hit
X-NYM-Debug-Backend
X-Hosted-By
X-Status
X-User-Agent
Country
X-B3-Traceid
Amp-Access-Control-Allow-Source-Origin
X-Ratelimit-Remaining
X-Rule
X-Device-Type
X-Air-Trace-Id
X-Air-Source
X-Air-Hostname
Surrogate-Key
X-Hl-Ver
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
ServerID
Protected
X-Http-Reason
X-Origin-TTL
X-Akamai-Request-ID2
X-Content-Powered-By
X-Webkit-CSP
X-Origin-CC
X-Backend-Name
Version
Alternate-Protocol
X-VC-Cache
X-Cache-Status-Check
X-NODE
X-CCDN-CacheTTL
X-Hcs-Proxy-Type
X-Akamai-Edgescape
X-CCDN-Origin-Time
X-Cache-Age
WPO-Cache-Message
WPO-Cache-Status
X-CDN-Forward
X-Nginx-Cache
X-Rocket-Nginx-Serving-Static
X-Edge-Location
CF-IPCountry
X-INCAP-ABP
X-HTML-Minification-Powered-By
X-Time
X-Framework
Front
Countrycode
X-Cache-Rule
SRV
CDN-RequestId
Access-Control-Request-Headers
X-Source
GEO-INFO
X-Storage
X-Endurance-Cache-Level
X-Httpd
X-Via-JSL
X-Mode
X-Accel-Version
X-WP-CF-Super-Cache-Active
X-Cache-Operation
Filters
X-Rewrite-Enabled
X-UPSTREAM-Address
Xet-Cookie
X-Rn-Rsrv
Meta-Geo
X-Upstream-Ht
X-Upstream-Ct
X-Xfnlog-Site
X-Tec-Api-Origin
X-Tncms
X-Tumblr-Pixel-2
X-Cache-Time
X-Varnish-Age
X-Tumblr-Pixel-3
X-Director
X-Tec-Api-Version
X-Tec-Api-Root
Accept-Language
X-SaId
X-Vcache
X-Lambda-Id
X-Detected-As
X-Soup
X-JoinUs
X-Cache-Debug
X-Loop
X-Real-IP
Apigw-Requestid
X-Say-TTL
X-Sql-Count
X-Skip-Cache
X-SayCDN-TTL
X-Sql-Duration-Ms
X-Say-Cacheable
OT-Force-Account-Verify
X-Varnish-Cache-Hits
Xserver
X-Redis-Cache
X-Adobe-Source
X-Use-Mantle
X-Cms-Context
X-Served-From
TWC-GeoIP-LatLong
Azure-SlotName
X-Origin-Hint
Azure-Version
X-Format
Azure-SiteName
X-GeoCountry
X-Varnish-Beresp-Grace
X-Handled-By
X-GeoCode
X-Labrador-Cache-Channel
Azure-RegionName
Azure-InstanceId
X-Cache-Host
X-Logging-Id
Web-Mar-Node
X-Uri
TWC-Device-Class
TWC-Privacy
TWC-Locale-Group
TWC-GeoIP-Country
ServedBy
X-PHP-Host
TWC-Connection-Speed
Property-Id
X-Restarts
Webcakes-App-Name
DB-Nickname
Webcakes-Region
Webcakes-App-Version
X-Is-Tablet
X-RCS-CacheZone
X-Extlb
X-Container-Uri
Mn-Server-Ip
X-Browser-Name
X-AB
X-Proxied
X-Forwarded-Host
X-Origin
X-Is-Desktop
X-Is-Mobile
X-Git-Commit
X-Geo-Region
X-Generation-Time
X-Is-Supported-Browser
X-Tb
X-Zipkin-Id
X-ProxyCache-Status
Selected-Fe
X-ProxyCache-Key
X-S
X-Vercel-Cache
X-Timing-Wait
X-Vercel-Id
X-Worker
X-Server-W
X-BYPASS-REASON
X-RM-Cache-TTL
X-Routing-Service
Webserver
X-No-Session
X-Tcp-Rtt
X-Proxy-Build
X-VWS-Id
X-Frame-Option
X-VCT
Cache-Tv-Group
X-Cache-Server
X-Fetched-On
Priority
X-AWS-Id
X-Provided-By
X-LJ-Flow-ID
X-Reqid
X-ServerID
X-DynaTrace
Node
X-COUNTRY
X-IPLB-Instance
X-IPLB-Request-ID
X-Cluster
X-VC
X-FB-TRIP-ID
X-R9-Blue-Green-Version
X-Ms-Version
X-Ms-Request-Id
Section-Io-Id
Content-Secure-Policy
X-Site-Version
X-Locale
Fastcgi-Useragent
X-Platform-Router
X-Platform-Processor
X-Platform-Cluster
X-MP-GENERATED-AT
X-Vcl-Version
Source
Onion-Location
S-Rt
WZWS-RAY
X-Drupal-Cache-Contexts
X-Drupal-Cache-Tags
WP-Super-Cache
X-SRV
AMP-Access-Control-Allow-Source-Origin
X-Urbn-Context-Path
X-Webstats-RespID
X-Ua
X-Urbn-Site-Id
X-Content-Age
Locale
CDN-RequestPullCode
CDN-Uid
X-Web-Node
CDN-Cache
CDN-RequestCountryCode
X-Alternate-Cache-Key
CDN-RequestPullSuccess
X-Storefront-Renderer-Rendered
CDN-EdgeStorageId
CDN-CachedAt
X-Shopify-Stage
CDN-PullZone
X-Generated-By
X-Origin-Date
Cross-Origin-Embedder-Policy
X-Pass-Why
X-Sorting-Hat-PodId
X-ShardId
X-ShopId
X-Sorting-Hat-ShopId
X-Cache-Action
X-Varnish-Beresp-Ttl
X-Cluster-Node
X-Mg-Request-UUID
X-Proxy-Cache-Status
X-Cdn-Origin
X-Sucuri-Cache
X-Sucuri-ID
X-Buckets
X-DataDome
Cross-Origin-Window-Policy
Fastly-Drupal-HTML
X-TT-LOGID
X-Cache-Expired-At
X-Newrelic-Synthetics
Sid
X-Client-Ip
X-Request-URI
Thinkindot-CacheControl
TDXMobile
X-Xrds-Location
Thinkindot-Control
Thinkindot-CacheControl-Type
Cache
X-CMSURLCustom
X-Shield-Cache-Expires
X-Scope-Id
X-GEO
X-Thinkindot-L3
X-LSADC-Cache
X-URL
X-Ec-GeoHdr
X-Ec-Fail
X-Developer
X-Ec-Custom-Error
X-External-Request-Id
X-Up
X-TIM-N
X-SRCache-Key
X-Vdms-Path
X-Vdms-Version
X-Vtex-Remote-Cache
X-Viewer-Country
X-ScT
X-Scheme
Cross-Origin-Embedder-Policy-Report-Only
X-Destination
X-Men
X-PAYTM-SRV-ID
X-S-Cookie
X-Rojux
X-Epic-Correlation-Id
Candidate-Md5Url
Type
X-BCube-Filmed-By
V-Age
T-Server
Surrogated-Key
Rendered-Blocks
Sslversion
X-A
X-A-Ccd
X-A-Dgt
X-A-Wwc
X-Aed
X-B-Cookie
X-Bc-Bl
X-A-Dam
X-A-Dcw
X-Bl-Debug
Redirect-Candidate
DCR-Processing-Time-Ms
Environment
Gannett-Cam-Experience-Id
DCR-Decision-By
CDCHOST
X-Application
X-Cache-NE
Lang
MD5-Digest
Origin
Origin-Agent-Cluster
Ngx.Var.Host
Ngx-Var-Key
X-Cache-Bucket
Meta-Geo-Continent
X-Conf
X-D
X-DC
X-Aspnetmvc-Version
X-Service
X-BBC-Edge-Cache-Status
X-Cache-Info
X-B3-Trace-ID
X-Aicache-OS
X-Access
X-Acquia-Purge-Cdn-Unconfigured
X-Core-Mission
X-Core-Value
X-Debug-Cache-Store
X-Dispatcher-Server
X-Fastly-Cache
X-Debug-Cache-Fetch
X-VCache
X-Fastly-Backend
Ssr
Magicmarker
X-Correlation-ID
L
Host-ID
Fastly-GeoIP-CountryCode
Fastly-SSL
Pramga
Req-Svc-Chain
Sever-Int
X-Gdpr
Server-Hostname
Server-Host
Server-Ext
Vix-Hermes-Req-Id
X-GeoIP-Region-Code
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-Sigma-Backend
X-Sigma
X-SD-PageType
X-Section
X-V-Cache
X-Varnish-Director
X-VServer
X-We-Are-Hiring
X-VG-WebCache
X-VG-TLSProxy
X-Varnish-Hostname
X-SB
X-Rocket-Build-Number
X-Level-Front-Cache
X-Loc
X-Instance-Name
X-Human
X-GeoIP-Country-Code
Country-Code
X-Mly-Id
X-Nyt-Route
X-Req
X-Request-Time
X-Proxied-Request
X-Pool
X-Op-Id-All
X-Generated-On
X-Origin-Time
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
Apple-News-Services-Handled
Apple-News-Services-Host
X-Parent-Response-Time
Edge-Copy-Time
X-TimeS
X-Via-Edge
X-Optimistic-Header
HostName
X-Via-CDN
X-Via-SSL
X-Datadome
X-Tt-Logid
X-Cache-Id
X-Clientip
X-Via-Popv
X-WA-Info
X-Cache-Date
X-Zen-Fury
X-Cache-TTL-Remaining
X-Auto-Login
Wxu-Next-Region
Adler-Geo
Wxu-Next-Hostname
Wxu-Next-Commit
Web-Mar-Region
X-Bip
X-Ad-Load-Variation
X-Block-Status
X-Via-Popn
X-ApacheServer
X-Old-Content-Length
LB
X-UA-Device-Type
X-Request-Host
X-RateLimit-Remaining-Second
X-HS-Content-Campaign-Id
X-Hnp-Log
X-Gzip
X-HA-Backend
X-RateLimit-Limit-Second
X-PERF
X-Nginx-Cache-Key
X-Org
X-NCache
X-Origin-Response-Time
X-Micro-Cache
X-GoCache-CacheStatus
X-GeoIP-City
X-TH-Server
Click-Count-Error
X-Esi-Check
X-Hash
X-Device-Os
X-DPWN-IS-SECURE
X-Sn-Servicetimems
X-Fmm-Version
X-Gen-Mode
X-Geo-Header
X-Slack-Backend
X-From
X-Slack-Shared-Secret-Outcome
X-Via-Poph
Release
X-Varnish-Beresp-Status
Platform
Tube-Get-Contents
Is-Eu
True-Client-Country-4JS
Proxy-Firewall
User-Cache-Control
Producers
Machine
Cache-Provider
Tube-Got-Eval
DSUID
C-Via
Click-Count-Action-Start
X-Server-IP
X-Thanos
On-Server
Tube-Got-Results
Tube-Return
X-WP-CF-Super-Cache-Cookies-Bypass
Pics-Label
Req-ID
X-Wikidot-Backend
X-CF-Lambda-Version
X-Var-Ttl
X-Wikidot-Static-Cache
X-Forwarded-Site
N-Cache
Cdn-Request-Time
IsBot
Cf-Device-Type
Expect-Staple
Datacenter
X-Owner
X-SIPLIST1
Cdn-Host
X-Edge-Server
X-Node-Id
X-Request-Start
X-CF-Lambda-Fn
X-Varnishpool
X-TA-CDN-Provider
Atl-Traceid
X-Date
X-Cdn-Srv
X-App-Name
Uber-Trace-Id
X-CacheTTL
X-Accel-Expires-Debug
We-Hiring
Mail-Subject
NM-Fastcgi-Cache
X-NMSegId
Canary
AKAMAI
Esi-Enabled
X-GeoIP
X-Pubstack
X-Platform
SID
X-Mvc-Supplant-OutputCached
X-Tenant
X-Shop-Environment
X-Qloud-Router
X-FC-Vary-Parameters
X-Orig-Expires
X-Irp-Debug
X-Mvc-Supplant-Cachable
X-Amz-Meta-Cb-Modifiedtime
Fastly-Backend-Name
X-Forwarded-Path
W
X-ZONE
X-Test
X-Cache-Type
Gh-Request-Id
NGX
Xc-Version
X-Policy
X-LB-NoCache
X-Proto
X-Ah-Environment
X-Gamma-Serve
X-Tx-Id
Cluster
X-Connection-Hash
Expiry
Content-Script-Type
A
Content-Style-Type
Cmstype
X-Branch-Name
Cmsid
X-Moov-Xdn-Version
L5d-Success-Class
X-CGP
X-Cache-Aspx
X-TIME
Server-ID
X-Varnish-Authentication
X-Contensis-Viewer-Groups
Ha-Gx-Prefs
HA-Ipaddr
X-Eu-Site
X-Csrf-Jwt
X-Moov-T
X-Dc
Cdn
X-Wa
Locid
CPC-Age
X-Refresh
X-Vmg-Version
RNT-Time
X-Varnish-Hits
X-Servedbyhost
X-LB-ID
CPC-Cache
RNT-Machine
X-Api-Version
X-NGINX-Cache
X-Nc
Cache-Key
X-LAGOON
X-Ratelimit-Reset
X-Region-Sid
X-Nf-Request-Id
X-ND-Cache
X-Fpc
X-AK-Request-ID
Cdnsip
X-CACHE-AGE
Cdncip
X-Cdn-Diag
Yak-Timeinfo
X-VHOST
X-Amz-Storage-Class
X-CSRF-TOKEN
PFcat
GeoIp-Country-Code
RATING
X-HN
X-Tb-Optimization-Total-Bytes-Saved
X-VarnishDD-TTL
X-MCACHE
NtCoent-Length
X-CDN-Cache-Status
Cdn-Requestid
CloudFront-Viewer-Country
X-DynaTrace-JS-Agent
X-Backend-Instance
X-Nananana
X-Akamai-Transformed
X-B3-Parentspanid
X-Via-Fastly
XM
Resin-Trace
X-Variation
CacheControlHeader
X-Azure-Ref-OriginShield
X-Srv
X-Hit
X-Cache-Backend
X-API-Version
Uri
X-Origin-Expires
X-TX-ID
X-Esi
X-Vc
X-Zone
MIME-Version
VNS-Cache
User-Agent
X-Fastly-Country-Code
VNS-Age
X-LiteSpeed-Tag
Cache-Name
X-Lagoon
XkeyRZ
Hostname
X-LiteSpeed-Cache-Control
X-Proxy-CacheRZ
X-Info
X-Dynatrace-Js-Agent
X-DataCenter
Cross-Origin-Opener-Policy-Report-Only
X-Amz-Meta-Opti
Tcn
True-Client-IP
Lb
True-Client-Ip
X-Datacenter
X-Dispatcher-Number
X-HostName
GeoIP-Latitude
X-NewRelic-App-Data
X-Cached-By
X-Geo
X-UA
X-Ig-Origin-Region
Mime-Version
DataCenter
X-Traceid
X-Location
X-B3-Spanid
Cache-Hits
Fusion-Source
Fusion-Component-Id
Fusion-Content-Id
Fusion-Content-Source
Fusion-Deployment-Id
Fusion-Template-Id
X-NWS-UUID-VERIFY
X-Mid
Cf-Ipcountry
X-AIR-PT
X-Presslabs-Stats
Powered-By
Fastly-Drupal-Html
BehaviorPad-Version
X-Cdn-Forward
X-Webkit-Csp-Report-Only
Origin-CC
X-CS
X-Cloudmap
Origin-EX
X-Jungle-Id
X-IAuth-Set-Uid
X-CUA
Srv
X-User
X-Segment-20210421
CountryCode
X-ECache
Ohc-File-Size
X-Varnish-Beresp-TTL
Location
GeoIP-Country-Code
Debug
X-Dispatch
X-Cache-Enabled
Server-Info
CF-Ctrl
My-App
X-FPC
X-Wp-Cf-Super-Cache
X-Internal-Host
X-Cdn-Cache-Status
X-Oracle-DMS-ECID
X-Wp-Cf-Super-Cache-Cache-Control
Cl-Cache
X-Litespeed-Tag
X-Render-Time
X-Wormhole-Sdk
Wpo-Cache-Message
Wpo-Cache-Status
Ohc-Cache-HIT
CDN
X-VTEX-Cache-Server
X-VTEX-Cache-Time
X-Powered-By-VTEX-Cache
X-WA
X-NC
X-Nitro-Cache
X-ServedByHost
X-Fastly-Backend-Reqs
Section-Origin-Responded
X-App
Section-Io-Origin-Time-Seconds
X-Snapshot-Date
X-Lb-Id
Section-Io-Origin-Status
Server-Id
YJS-ID
X-Cs
Load-Balancing
X-Lb-Nocache
Edge-Cache
X-Cache-FS-Status
X-Auth-Group-Type
X-Akamai-Pragma-Client-IP
X-MSEdge-Flight
X-MSEdge-Features
Ms-Author-Via
X-ID
X-VCL-Version
X-Litespeed-Cache-Control
Xkey-La3
CF-Cached-On
X-Cdn-Request-ID
X-Proxy-Cache-La3
X-Nitro-Rev
X-MiniProfiler-Ids
Xkeylog
X-Nitro-Cache-From
X-RID
X-Dw-Trace-Id
X-FL-EDGE
Memory
X-Acquia-Application-Trace
Time
X-Acquia-Purge-Tags
X-IN-APIGATEWAYSSL
OriginIP
X-FL-QIT-DEBUG
X-Acquia-Site
X-IN-APIGATEWAY
Memcached
X-Th-Server
X-Ig-Push-State
X-Serial
X-NodeID
X-Check-Cacheable
X-Varnish-CookieHashed-On
X-Varnish-Remaining-TTL
FSS-Cache
X-Varnish-CookieINHashed-On
X-DefElseHash
Srvid
X-Acquia-Application-UUID
X-DefHash
Ngx
X-APP-VERSION
WebServer
X-Sorting-Hat-Shopid
X-Shardid
X-Sorting-Hat-Podid
X-Shopid
X-Cache-Version
X-Mg-Cache
X-Vary
Yjs-Id
Akamai-Cache-Status
X-Te-Duration-Ms
X-Ha-Backend
Inserted-Into-Cache-At
X-Sucuri-Id
X-Via-PopH
X-Via-PopN
X-Fastly-Cache-Hits
X-Via-PopV
X-Lsadc-Cache
X-Wp-Cf-Super-Cache-Cookies-Bypass
Geoip-Latitude
X-Http-Count
Sm-Log-Id
X-Service-Response-Time
X-Http-Duration-Ms
X-Pad
X-RequestId
X-Udemy-Cache-App-Namespace
X-Te-Count
X-Web-Server