Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-Cache-Status
Link
Accept-Ranges
CF-RAY
ETag
X-XSS-Protection
Expect-CT
Pragma
X-Powered-By
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
Alt-Svc
P3P
X-Served-By
X-Xss-Protection
X-Download-Options
X-Timer
X-Request-Id
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Cache-Status
X-Check
X-Generator
X-Cacheable
Timing-Allow-Origin
P3p
X-Content-Security-Policy
X-Iinfo
Feature-Policy
Status
X-Envoy-Upstream-Service-Time
Content-Encoding
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
X-Request-ID
X-CDN
X-AspNetMvc-Version
Upgrade
X-Via
CF-Ray
X-Ws-Request-Id
Access-Control-Max-Age
Server-Timing
EagleId
X-Cache-Group
X-Turbo-Charged-By
Keep-Alive
Request-Context
X-UA-Device
Report-To
X-Age
X-Backend
X-Proxy-Cache
X-Server-Powered-By
X-AH-Environment
X-Robots-Tag
X-Hacker
X-Amz-Request-Id
X-Server
Host-Header
X-Amz-Id-2
Grace
X-LiteSpeed-Cache
X-Rq
X-Swift-CacheTime
X-Swift-SaveTime
X-Nginx-Cache-Status
X-Varnish-Cache
Ali-Swift-Global-Savetime
X-Dns-Prefetch-Control
X-WebKit-CSP
X-Page-Speed
NEL
X-Vhost
EagleEye-TraceId
X-Ua-Compatible
X-Amz-Version-Id
X-Pingback
X-OneAgent-JS-Injection
X-Dispatcher
X-Device
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Cache-Spec
X-Host
X-Server-Id
Cf-Railgun
Accept-CH
X-Node
X-Backend-Server
X-Readtime
Surrogate-Control
X-Akam-SW-Version
Request-Id
X-Response-Time
X-HW
Xkey
X-Application-Context
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
Content-Location
Rating
Accept-Ch-Lifetime
X-Country
X-B3-TraceId
X-Cloud-Trace-Context
X-Ruxit-JS-Agent
Accept-CH-Lifetime
X-Cache-Lookup
X-Trace
X-Url
X-Ac
X-Content-Type
X-PC
X-TtlSet
X-Vname
Allow
X-Clacks-Overhead
Edge-Control
X-Mod-Pagespeed
X-Varnish-TTL
X-Server-Name
X-ESI
Fastly-Restarts
X-Aws-Lambda-Call-Status
Cache-Tag
X-VARITI-CCR
Service-Worker-Allowed
X-Rack-Cache
Verso
X-Element-Page-Cache
X-Upstream
MS-Author-Via
X-FastCGI-Cache
X-MS-InvokeApp
X-Vcap-Request-Id
X-Amz-Rid
X-GitHub-Request-Id
Public-Key-Pins
X-Dw-Request-Base-Id
X-Cached
X-Abt-Application-Version
X-D2id
X-Client-IP
X-Cnection
X-Px
RTSS
X-Cache-TTL
X-Navigation-Version
X-Kinja-Server
X-Country-Code
X-Exp-Id
X-Exp-Variant
X-Kinja
X-Use-Magma
X-Kinja-Revision
X-Kinja-Build
X-GoogleNews-Bot
X-Cdn-Fetch
Arr-Disable-Session-Affinity
Access-Control-Request-Method
X-Powered-By-Plesk
X-Goog-Hash
X-NF-Request-ID
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Instrumentation
AR-Request-ID
AR-SID
AR-PoweredBy
AR-ATIME
AR-CACHE
X-Origin-Cache
X-Powered-CMS
Pagespeed
X-Middleton-Display
Display
X-Sol
X-Version
Response
X-Middleton-Response
Accept-Ch
X-Amz-Server-Side-Encryption
X-LLID
X-MSEdge-Ref
X-Kinsta-Cache
X-Edge-Location-Klb
TCN
Nginx-Cache
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Edge
MRF-Tech
X-RateLimit-Remaining
X-B3-TraceId-Primal
Mrf-Cache-Status
X-TTL
X-Protected-By
X-HP-Webp
X-HP-Trace-Id
X-Jurisdiction
X-Forwarded-For
X-T
X-Shield-Request-Id
X-Content-Security-Policy-Report-Only
X-Aspnetmvc-Version
X-Id
X-Mg-S
S
Content-MD5
Edge-Cache-Tag
X-Ruxit-Js-Agent
X-CST
X-Language
SPRequestDuration
SPIisLatency
Fastcgi-Cache
X-Mid
Front-End-Https
X-DynaTrace
Realpath
X-Ttl
X-Recruiting
Pinterest-Generated-By
X-Pinterest-Rid
Filters
Server-Node
Pinterest-Version
X-Request-Received
X-Request-Processing-Time
X-Frontend
Server-Name
X-Ua-Browser
X-MCACHE
X-Content
X-Ab
X-Correlation-Id
X-Cache-Key
X-Ser
X-HS-Cache-Config
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Combine-CSS
X-NWS-LOG-UUID
X-Yandex-Sdch-Disable
X-Template
X-ECACHE
X-Ezoic-Cdn
SPRequestGuid
X-SharePointHealthScore
X-Hits
X-Parallel-Accel
X-Tt-Trace-Tag
MicrosoftSharePointTeamServices
X-Tt-Trace-Host
Alternate-Protocol
X-Kong-Proxy-Latency
X-Server-ID
X-Kong-Upstream-Latency
X-Page-Id
Charset
Cache-Tags
Fusion-Component-Id
Fusion-Template-Id
Fusion-Source
Fusion-Deployment-Id
Fusion-Content-Source
Fusion-Content-Id
Cleartype
Host
X-B3-Sampled
X-Git-Hash
X-Www-Served-By
X-Content-Options
X-Geo-Country
X-Hostname
X-Debug-Info
X-DIS-Request-ID
X-Daa-Tunnel
X-Content-Digest
X-Amzn-Trace-Id
X-Amz-Replication-Status
Filterid
X-Varnish-Age
Cross-Origin-Opener-Policy
X-Ratelimit-Limit
X-Activity-Id
X-AppVersion
X-Az
X-FB-Debug
X-Upgrade-Enabled
X-VCache
X-Accel-Expires
X-Grace
X-Forwarded-Proto
X-F-Cache
X-Nginx-Upstream-Cache-Status
ServerID
X-N
Access-Control-Allow-Method
X-Rid
X-Fastly-Request-Id
X-Mobile-URL
X-Origin-Server
X-Request-Guid
X-Route-Name
X-Flags
X-Aspnet-Duration-Ms
X-Is-Crawler
X-Providence-Cookie
X-LB-Cache
X-Whom
TP-L2-Cache
TP-Cache
X-TT
X-Fastcgi-Cache
X-App-Environment
X-Type
X-Goog-Generation
X-Varnish-Grace
X-Goog-Metageneration
X-Goog-Storage-Class
X-GUploader-UploadID
X-Goog-Stored-Content-Encoding
X-Seen-By
Viewport
X-Goog-Stored-Content-Length
X-Tb
Payment
X-DataDome
X-WebKit-CSP-Report-Only
Node
X-Distributor
X-FW-Server
X-FW-Static
X-FW-Type
X-FW-Serve
X-User-Agent
X-FW-Dynamic
X-FW-Hash
DC
X-XRDS-LOCATION
Paypal-Debug-Id
X-App-Server
X-Oneagent-Js-Injection
Fastcgi-Useragent
X-Fastly-Request-ID
X-Wix-Request-Id
Accept-Charset
Country
X-Cache-Control
X-Litespeed-Cache
X-NGENIX-Cache
X-Cache-Rule
X-Origin-Upstream-Status
X-Webkit-Csp
Version
X-Via-JSL
Referer-Policy
X-Drupal-Cache-Tags
X-Logged-In
X-Microsite
X-Request-Handler-Origin-Region
X-Oracle-Dms-Rid
X-Oracle-Dms-Ecid
X-Cluster-Name
Amp-Access-Control-Allow-Source-Origin
X-Contextid
X-Buckets
X-Cache-Age
X-Tec-Api-Root
X-Signature
X-Tec-Api-Origin
X-B-Cache
X-Ratelimit-Reset
X-Tec-Api-Version
Refresh
Cache-Status
X-Browser-Type
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
VIX-Pulpo-Upstream-Status
X-Mobile
X-Response-Served-From
VIX-Pulpo-Node
X-Load-Cache
SD-X-WS
X-Node-Name
X-Original-Request-Id
X-Varnish-Backend
X-Cache-Expired-At
X-Is-Bot
X-Page-View
X-Rendered-As
X-Real-IP
X-Vgn-Hpd-Reason
X-Revision
Access-Control-Request-Headers
X-Cacheable-TTL
NGB
X-Proxy-Cache-Status
X-Jobs
X-B
X-ProcessESI
X-Rule
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-UUID
X-RemovedCookies
X-IPLB-Instance
X-Cache-Action
X-Debug
X-Device-Type
Surrogate-Key
X-Instance
X-Drupal-Cache-Contexts
X-Proxy
X-Debug-IsConnected
X-Debug-IsPreview
X-Framework
X-Cache-Time
X-G
Akamai-GRN
X-FW-Version
CF-IPCountry
X-Air-Trace-Id
X-Air-Hostname
X-Air-Source
SID
GEO-INFO
DynaTrace
X-Accel-Buffering
X-Azure-Ref
X-TEC-API-ROOT
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-PressLabs-Stats
X-Nginx-Cache
Liferay-Portal
X-Source
X-Cache-NGX
Count-Hit
X-Ms-Request-Id
Uber-Trace-Id
X-Presslabs-Stats
X-Ms-Version
X-Cache-Operation
X-XRDS-Location
Frame-Options
X-Zen-Fury
MS-CV
X-CDN-Forward
X-APP-VERSION
Ms-Operation-Id
X-RTag
X-EdgeConnect-Cache-Status
Healthy
X-RateLimit-Limit
X-Cache-Hit
Protected
Xserver
Countrycode
X-Environment-Context
X-Mode
X-L-Path
X-Backend-Name
X-Varnish-Server
Cross-Origin-Window-Policy
Ec-Rule-Version
X-IPS-LoggedIn
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-Tumblr-Pixel
X-Tumblr-User
X-Ratelimit-Remaining
LB
X-Cache-TTL-Remaining
Backend
X-Hyper-Cache
X-JoinUs
X-Adobe-Loc
X-Rewrite-Enabled
X-Adobe-Content
X-Detected-As
X-Forwarded-Host
X-RN-RSRV
Meta-Geo
X-Servername
X-Region
X-Content-Age
X-UPSTREAM-Address
X-Tid
X-SaId
X-Extlb
X-Cache-Grace
X-Proxied
X-Debug-Cache
X-Sql-Duration-Ms
X-Hosted-By
Country-Code
Decoy-Debug-TTL
X-Routing-Service
X-Zipkin-Id
Decoy-Debug-Status
X-Uri
X-ShardId
X-Sorting-Hat-PodId
X-Redis-Cache
X-ShopId
X-Shopify-Stage
Section-Io-Cache
Apigw-Requestid
Decoy-Debug-Key
WPO-Cache-Status
X-Sorting-Hat-ShopId
X-Alternate-Cache-Key
X-Sql-Count
WPO-Cache-Message
Eomportal-Instance
Mn-Server-Ip
X-ServerID
X-FB-TRIP-ID
X-Format
X-No-Session
X-Microcachable
Fastly-SSL
X-NCache
X-Human
X-Varnish-Beresp-Grace
X-Site-Version
Url
X-Content-Powered-By
Cache-Name
X-Cache-Server
X-ApacheServer
X-PHP-Backend
X-Status
X-PERF
X-OCL
X-Via-Fastly
X-PCL
X-Origin-Date
Selected-Fe
X-BYPASS-REASON
X-Cache-Host
X-Access
Content-Disposition
X-Cache-Type
Cache-Tv-Group
X-Akamai-Edgescape
X-ProxyCache-Status
X-Say-Cacheable
X-Say-TTL
CDN-Uid
X-UA-Device-Type
CDN-RequestId
CDN-RequestCountryCode
CDN-EdgeStorageId
CDN-Cache
CDN-PullZone
CDN-CachedAt
X-Timing-Wait
X-ProxyCache-Key
X-Proxy-Build
X-Section
X-SayCDN-TTL
X-Storage
X-Pubstack
TWC-Connection-Speed
TWC-GeoIP-Country
X-Server-W
TWC-GeoIP-LatLong
X-Varnishpool
X-R9-Blue-Green-Version
TWC-Device-Class
Webcakes-App-Name
X-Origin-Hint
X-Web-Node
X-NYM-Debug-Backend
X-Cluster-Node
X-Hl-Ver
X-Soup
Property-Id
X-Generated-By
X-Generation-Time
Webcakes-App-Version
Webcakes-Region
TWC-Locale-Group
TWC-Privacy
X-NewRelic-App-Data
X-Be
Content-Secure-Policy
Azure-SiteName
Azure-SlotName
Azure-Version
X-LSADC-Cache
DB-Nickname
Azure-RegionName
X-Azure-Ref-OriginShield
Azure-InstanceId
X-Webkit-CSP
X-TIME
X-Trace-Id
OT-Force-Account-Verify
X-Nginx-Cache-Key
X-Ua
Retry-After
X-Cached-By
Source
X-TT-LOGID
X-Bc-Bl
X-Cache-Remote
X-Unique-Id
Cache
SRV
X-Akamai-Transformed
X-Dc
X-Platform-Server
X-LAGOON
X-SRV
X-GEO
X-Xfnlog-Site
X-Auto-Login
X-Cdn
X-Varnish-Hits
Cache-Hits
X-Cache-Tags
HostName
X-Origin-TTL
X-EC-Lua
ServedBy
X-Origin-CC
Upgrade-Insecure-Requests
X-Loop
X-App-Version
X-HTML-Minification-Powered-By
X-Varnish-Hostname
Mime-Version
X-TNCMS
X-S-Maxage
X-CSRF-Token
From-Origin
X-Time
X-Varnish-Cache-Hits
X-Request-Time
X-AOL-HN
Xet-Cookie
Onion-Location
Webserver
X-Request-Host
Web-Mar-Node
WP-Super-Cache
X-Amz-Meta-S3cmd-Attrs
X-Proto
X-ECache
X-Xrds-Location
N-Cache
X-Tumblr-Pixel-3
X-NWS-UUID-VERIFY
X-Tumblr-Pixel-2
X-B3-SpanId
X-Endurance-Cache-Level
X-Tenant
X-Cache-Enabled
X-VWS-Id
X-LJ-Flow-ID
X-Correlation-ID
X-AWS-Id
Nel
X-Handled-By
X-FireWall-Port
X-GG-Cache-Date
X-Time-Microsecs
X-Origin-Response-Time
X-Application
X-B-Cookie
X-Block-Status
X-ARC
X-Vdms-Version
X-Planisys-CDN-TTL
X-Cache-Var-Map
X-Conf
X-Connection-Hash
X-D
X-TIM-N
X-Cluster
X-Cache-Var
X-CF-Lambda-Fn
X-Cache-NE
X-CF-Lambda-Version
X-Ckpd-Fst-Backend
X-Vdms-Path
X-VG-WebCache
X-A-Wwc
Redirect-Candidate
Pramga
Rendered-Blocks
Sslversion
Surrogated-Key
BehaviorPad-Version
Odigeo-Trace-Id
Expiry
DCR-Processing-Time-Ms
Fastcgi-X-Cache-Version
Meta-Geo-Continent
Mobile-Detection-Method
A
User-Cache-Control
X-Vtex-Processado-Em
X-A-Dcw
X-A-Dgt
X-Destination
X-Aed
X-Vtex-Remote-Cache
X-A-Dam
Vix-Hermes-Req-Id
V-Age
X-A
X-A-Ccd
Xc-Version
X-Aicache-OS
X-V-Cache
X-ND-Cache
X-Orig-Expires
X-SD-PageType
X-NAPM-TraceId
X-Shop-Environment
X-SRCache-Key
X-Slack-Backend
DCR-Decision-By
X-ScT
X-PAYTM-SRV-ID
X-Processor
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-PBS-Appsvrname
X-Rojux
X-S-Cookie
X-S
X-Ig-Push-State
X-Session-Fingerprint
X-Ftr-Request-Id
X-Forwarded-Path
X-External-Request-Id
X-Hnp-Log
X-Edge-Location
X-Developer
X-Gen-Mode
X-Epic-Correlation-Id
X-RCS-CacheZone
X-Magnolia-Registration
X-Reqid
X-Adobe-Source
X-Mg-Request-UUID
X-Scheme
True-Client-Country-4JS
X-Forwarded-Site
Svr
X-Rocket-Nginx-Serving-Static
X-SVT-ORM-VERSION
Host-ID
X-Policy
DSUID
X-Proxy-Upstream
X-Request-URI
X-Fastly-Cache
X-Origin-Expires
Origin
State
Wxu-Next-Hostname
X-Cache-Date
X-LI-UUID
X-Hash
X-Accel-Expires-Debug
X-Men
X-VG-TLSProxy
X-SVT-ORM-RULES
X-Backend-TTL
X-Sucuri-ID
X-Li-Fabric
X-Sucuri-Cache
X-Li-Pop
X-Mvc-Supplant-Cachable
X-Viewer-Country
X-Origin
X-Geo-Header
X-Server-IP
Wxu-Next-Region
X-Cache-Bucket
X-Old-Content-Length
X-Webstats-RespID
X-Date
X-GeoIP-Region-Code
X-GeoIP-Country-Code
X-NodeID
Wxu-Next-Commit
X-Cache-Info
Arc-Country
CDCHOST
X-PHP-Host
X-Labrador-Cache-Channel
Apple-News-Services-Handled
X-Varnish-Ttl
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
Cmstype
Apple-News-Services-Request-Url
Cmsid
CloudFront-Viewer-Country
Environment
X-MP-GENERATED-AT
X-Via-NSCOPI
S-Rt
X-Device-Os
X-Datadog-Trace-Id
X-Esi-Check
X-Gdpr
X-Gamma-Serve
X-Fetched-On
X-Fastly-Backend
X-Eu-Site
X-Envoy-Decorator-Operation
X-Core-Value
X-Branch-Name
X-Cache-Debug
X-BBC-Edge-Cache-Status
X-Backend-State
Web-Mar-Region
Server-Info
X-Cache-Id
Fastly-Drupal-Html
X-Csrf-Jwt
X-Datadog-Parent-Id
X-Core-Mission
X-CGP
X-Cdn-Origin
X-Cdn-Srv
X-Datadog-Sampling-Priority
X-Gzip
X-Skip-Cache
X-Sn-Servicetimems
X-Storefront-Renderer-Rendered
X-Sigma-Backend
X-Sigma
X-Rocket-Build-Number
X-Served-From
X-TH-Server
X-TrackingId
X-Amz-Apigw-Id
X-VServer
X-Amzn-RequestId
X-VarnishDD-TTL
X-UnsetCookies
X-Varnish-Beresp-Status
X-Req
X-Region-Sid
X-HS-Content-Campaign-Id
X-Varnish-Beresp-Ttl
X-Irp-Debug
X-HN
We-Hiring
X-GeoIP
X-GeoIP-City
X-Level-Front-Cache
X-Locale
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Owner
X-Origin-Time
X-Location
X-Nyt-Route
X-Generated-On
X-Platform
Mail-Subject
Origin-CC
Machine
L5d-Success-Class
CacheControlHeader
L
Origin-EX
Traceparent
Ssr
AKAMAI
Server-Host
Req-Svc-Chain
PFcat
Release
HA-Ipaddr
Locid
Fastcgi-Cache-TTL
Ha-Gx-Prefs
Gh-Request-Id
Fastly-GeoIP-CountryCode
X-Varnish-CookieINHashed-On
X-Varnish-CookieHashed-On
Platform
X-Variation
X-FC-Vary-Parameters
X-Developers
X-Worker
Magicmarker
Adler-Geo
X-Varnish-Remaining-TTL
X-DefElseHash
X-Thinkindot-L3
X-DefHash
X-DPWN-IS-SECURE
NM-Fastcgi-Cache
X-Rebelmouse-Cache-Control
Fastly-SWR
X-Rebelmouse-Surrogate-Control
Is-Eu
X-Response-By
X-Request-Start
TDXMobile
X-Qloud-Router
X-NU-AKA-ACS-Version
X-Node-Id
Memcached
X-Http-Reason
X-Akamai-Request-ID2
X-Loc
Fastly-SIE
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
Thinkindot-Control
X-Tx-Id
X-ATG-Version
X-M-Reqid
X-VC-Cache
X-Ua-Device
X-Trace-ID
X-Qnm-Cache
X-M-Log
X-Amzn-Remapped-Content-Length
X-CS
AMP-Access-Control-Allow-Source-Origin
NGX
X-Thanos
X-Has-Esi
X-Pod-Name
X-Bip
X-JWT-State
Cf-Device-Type
X-Is-Gdpr
X-Zone
X-Mvc-Supplant-OutputCached
X-LB-ID
X-Up
X-Restarts
Kp-EeAlive
X-RSL
Ms-Author-Via
X-API-Version
X-Action
X-DB
X-Cache-Backend
X-Wix-Viewer-Type
Edge-Cache
X-DI
X-DW
X-Cache-Config
CDN
X-NC
X-LB-NoCache
Pics-Label
X-RPM
X-DSS
X-RPS
X-Generated-In
X-TraceId
Env
Memory
Accept-Language
Time
Datacenter
X-Tb-Optimization-Total-Bytes-Saved
X-Minions-Version
WebServer
X-Optimistic-Header
X-Via-Popn
X-CacheTTL
X-Via-Popv
X-DC
X-Refresh
X-Via-Poph
X-Tt-Logid
X-Edge-Pop
Candidate-Md5Url
X-Cache-Ttl
NtCoent-Length
X-HA-Backend
X-Srv
X-Urbn-Site-Id
Locale
X-Urbn-Context-Path
X-CACHE-KEY
GeoIp-Country-Code
X-DynaTrace-JS-Agent
X-ZONE
WWW-Authenticate
Server-ID
X-Servedbyhost
X-Vc
X-Esi
On-Server
X-Datadome
X-Unique-ID
Esi-Enabled
X-User
X-MSEdge-Features
X-Ec-Fail
X-MSEdge-Flight
X-Ec-GeoHdr
X-Cs
X-CLOUD-TRACE-CONTEXT
X-Parent-Response-Time
X-TA-CDN-Provider
X-TX-ID
C-Via
X-Service
X-Cache-PHP
X-Varnish-Beresp-TTL
X-VCL-Version
X-Webkit-CSP-Report-Only
X-Newrelic-Synthetics
X-LI-Proto
X-App
Cdnsip
X-Fpc
X-Traceid
X-AK-Request-ID
Cdncip
X-URL
X-Clara-WADP
Test
X-Fmm-Version
X-LiteSpeed-Cache-Control
X-WADP-Cache
My-App
Cluster
X-Li-Proto
X-Webkit-Csp-Report-Only
Proxy-Connection
Tracecode
X-CUA
X-FPC
X-B3-Spanid
X-Var-Ttl
X-Render-Time
Geoip-Latitude
X-Cache-Status-Check
Cf-Int-Pingora-Origin-Digest
X-Pass-Why
X-NODE
T-Server
X-From
Lfy
X-Vcl-Version
Fastly-Drupal-HTML
X-Mcache
Resin-Trace
Geo-Info
M-TraceId
X-Fragments
Lang
X-VC
X-Dynatrace
DataCenter
Server-Id
Target-Params
X-CSRF-TOKEN
GeoIP-Country-Code
X-LiteSpeed-Tag
X-WP-CF-Super-Cache
X-ID
X-WP-CF-Super-Cache-Cache-Control
X-Clientip
X-Ha-Backend
Hostname
MIME-Version
Hit
X-ServedByHost
Cache-Host
X-Info
UCS
X-Oss-Request-Id
HIT
X-Oss-Storage-Class
X-AIR-PT
X-RAMCache
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
X-Oss-Server-Time
X-Dynatrace-Js-Agent
X-Geo
X-Httpd
X-Proxy-Cache-Info
Permissions-Policy
X-Pad
X-Via-PopH
X-Via-PopV
X-Via-PopN
X-Edge-POP
Section-Origin-Responded
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
S-Cnection
X-Cdn-Forward
X-RateLimit-Reset
Section-Io-Id
X-Provided-By
X-Edge-Cache
Producers
ENV
X-Check-Cacheable
Ohc-File-Size
WZWS-RAY
X-Api-Version
Servername
X-NGINX-Cache
X-SB
X-HS-Status
X-Cache-CFC
X-ServerName
X-Fastly-Backend-Reqs
X-ElasticPress-Query
X-BBC-Origin-Response-Status
Fastly-Backend-Name
X-Micro-Cache
X-Ucs
FSS-Cache
User-Agent
Load-Balancing
ServerName
X-Acquia-Application-UUID
PICS-Label
URI
X-Acquia-Application-Trace
X-Lb-Nocache
X-Platform-Processor
X-Platform-Cluster
X-Backend-Host
X-UP
X-GoCache-CacheStatus
X-Platform-Router
X-Acquia-Purge-Tags
X-Pool
X-Udemy-Cache-App-Namespace
X-Release
Uri
X-Acquia-Site
X-TRACE-ID
X-Swift-Error
Server-Ttl
X-Cdn-Request-ID
Cneonction
X-APP
X-BCube-Filmed-By
X-Scale
X-Ec-Custom-Error
X-Fastly-Cache-Hits
Tcn
EpKe-Alive
Cdn
X-Lb-Id
Cteonnt-Length
X-Nc
X-Dw-Trace-Id
X-UA
X-Akamai-ERRuleID
X-Akamai-ERPolicy
X-SIPLIST1
X-B3-Parentspanid
X-Cache-Expires
Sever-Int
Server-Hostname
Server-Ext
CF-Cached-On
X-B3-ParentSpanId
Shield-Pop
X-Snapshot-Date
X-Yottaa-OS
X-Contensis-Viewer-Groups
X-Dispatcher-Number
X-Cache-ASPX
Ohc-Cache-HIT
MD5-Digest
Cf-Ipcountry
X-Newrelic-App-Data
Path
X-Vcache
Wpo-Cache-Message
Vha6-Origin
Wpo-Cache-Status
IsBot
X-Cache-Ngx
Sid
X-HostName
X-Air-Pt
X-Shopify-Generated-Cart-Token
GeoIP-Latitude
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
X-Akamai-Request-ID
X-Sentry-ID
X-WA-Info
X-CacheKey
X-WA
X-Akamai-Pragma-Client-IP
CPC-Cache
VNS-Age
X-Logging-Id
X-Apw-Access-Token
X-Apw-Access-Object
X-Apw-Access-Action
X-Varnish-Authentication
Req-ID
CountryCode
X-Http-Duration-Ms
X-Te-Count
X-Te-Duration-Ms
X-Last-Modified
X-Http-Count
CPC-Age
VNS-Cache
X-Amz-Meta-Cb-Modifiedtime
X-Apw-Hits
Ngx
Cache-Key