Threat Level: green Handler on Duty: Rick Wanner

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Link
Cf-Request-Id
CF-Cache-Status
Accept-Ranges
CF-RAY
ETag
X-XSS-Protection
Expect-CT
Pragma
X-Powered-By
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-UA-Compatible
X-Cache-Hits
Alt-Svc
P3P
X-Served-By
X-Xss-Protection
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Cache-Status
X-Generator
X-Cacheable
Timing-Allow-Origin
P3p
X-Request-ID
X-Content-Security-Policy
X-Iinfo
Status
Feature-Policy
X-Envoy-Upstream-Service-Time
Content-Encoding
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
X-CDN
X-AspNetMvc-Version
Upgrade
X-Via
CF-Ray
Access-Control-Max-Age
X-Ws-Request-Id
Server-Timing
EagleId
Keep-Alive
X-Cache-Group
X-Turbo-Charged-By
Request-Context
X-Age
X-Proxy-Cache
X-Server-Powered-By
X-AH-Environment
X-Hacker
X-UA-Device
X-Backend
X-Robots-Tag
Report-To
X-Amz-Request-Id
X-LiteSpeed-Cache
Host-Header
X-Server
X-Dns-Prefetch-Control
X-Amz-Id-2
Grace
X-Rq
X-Nginx-Cache-Status
X-Varnish-Cache
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-WebKit-CSP
X-Page-Speed
X-Vhost
X-Amz-Version-Id
EagleEye-TraceId
X-OneAgent-JS-Injection
X-Device
X-Dispatcher
X-Pingback
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Cache-Spec
NEL
X-Server-Id
X-Host
X-Backend-Server
X-Node
Cf-Railgun
X-Readtime
X-Akam-SW-Version
Accept-CH
Surrogate-Control
Request-Id
X-Response-Time
X-HW
X-Language
Xkey
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
Accept-Ch-Lifetime
Content-Location
X-Template
X-Ruxit-JS-Agent
X-Application-Context
Rating
X-Ua-Compatible
X-Country
X-B3-TraceId
X-Cloud-Trace-Context
X-Cache-Lookup
X-Ac
X-Buckets
Allow
X-Url
X-Content-Type
X-Trace
X-PC
X-TtlSet
X-Vname
Accept-CH-Lifetime
X-Mod-Pagespeed
X-Clacks-Overhead
Edge-Control
X-Varnish-TTL
X-ESI
Cache-Tag
X-FastCGI-Cache
Fastly-Restarts
X-Rack-Cache
Service-Worker-Allowed
X-VARITI-CCR
X-Element-Page-Cache
X-Server-Name
Verso
X-GitHub-Request-Id
X-MS-InvokeApp
Accept-Ch
X-Amz-Rid
X-Upstream
X-Vcap-Request-Id
X-Dw-Request-Base-Id
MS-Author-Via
Public-Key-Pins
X-D2id
X-Client-IP
X-Abt-Application-Version
X-Cached
X-Origin-Cache
Arr-Disable-Session-Affinity
X-Powered-By-Plesk
X-Country-Code
X-Px
X-Goog-Hash
X-Navigation-Version
X-Cnection
Access-Control-Request-Method
X-NF-Request-ID
X-Instrumentation
X-Version
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Aws-Lambda-Call-Status
X-Cache-TTL
X-Amz-Server-Side-Encryption
RTSS
X-Powered-CMS
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
X-Sol
Pagespeed
Display
X-Middleton-Display
X-SRCache-Fetch-Status
X-SRCache-Store-Status
Response
X-Middleton-Response
X-Kinja-Server
X-Use-Magma
X-Kinja-Revision
X-Exp-Id
X-Cdn-Fetch
X-Exp-Variant
X-Kinja-Build
X-Kinja
X-GoogleNews-Bot
X-MSEdge-Ref
X-LLID
X-Edge
X-Edge-Location-Klb
X-Kinsta-Cache
X-CST
Nginx-Cache
X-Shield-Request-Id
X-B3-TraceId-Primal
Mrf-Cache-Status
MRF-Tech
S
AR-PoweredBy
AR-CACHE
AR-Request-ID
Content-MD5
AR-SID
AR-ATIME
X-Jurisdiction
X-HP-Trace-Id
X-HP-Webp
X-T
X-TTL
X-Protected-By
X-Forwarded-For
X-Content-Security-Policy-Report-Only
TCN
X-Aspnetmvc-Version
X-Mg-S
X-Id
X-RateLimit-Remaining
X-Mid
Fastcgi-Cache
X-MCACHE
Realpath
Front-End-Https
X-Parallel-Accel
SPIisLatency
SPRequestDuration
Edge-Cache-Tag
X-Recruiting
X-Ttl
X-Request-Processing-Time
X-Request-Received
Filters
X-Correlation-Id
Pinterest-Generated-By
Pinterest-Version
X-Pinterest-Rid
Fusion-Component-Id
Fusion-Deployment-Id
Fusion-Content-Source
Fusion-Template-Id
Server-Node
Fusion-Source
Fusion-Content-Id
X-Content
X-Ab
X-Ua-Browser
SPRequestGuid
X-SharePointHealthScore
X-Ezoic-Cdn
X-DynaTrace
Alternate-Protocol
X-ECACHE
Server-Name
X-Accel-Expires
X-NWS-LOG-UUID
X-Frontend
X-HS-Cache-Config
X-HS-Content-Id
X-HS-Hub-Id
X-HS-Combine-CSS
X-Hits
X-Yandex-Sdch-Disable
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Cache-Key
X-Content-Options
X-Ruxit-Js-Agent
Cache-Tags
X-Git-Hash
X-Page-Id
Host
Cleartype
Charset
X-Www-Served-By
X-B3-Sampled
MicrosoftSharePointTeamServices
X-Geo-Country
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Amz-Replication-Status
X-Content-Digest
TP-Cache
TP-L2-Cache
X-Forwarded-Proto
Filterid
X-Ser
X-VCache
X-Varnish-Age
X-Amzn-Trace-Id
X-Hostname
X-Activity-Id
X-AppVersion
X-Az
X-Rid
X-Daa-Tunnel
X-Request-Handler-Origin-Region
X-Microsite
X-Fastly-Request-Id
X-DIS-Request-ID
X-Debug-Info
X-Upgrade-Enabled
X-Origin-Server
Access-Control-Allow-Method
X-XRDS-LOCATION
X-Grace
X-LB-Cache
X-N
X-FB-Debug
X-Origin-Upstream-Status
X-Nginx-Upstream-Cache-Status
ServerID
X-Mobile-URL
X-PressLabs-Stats
X-TT
X-Aspnet-Duration-Ms
X-Route-Name
X-Request-Guid
X-Flags
X-Is-Crawler
X-Server-ID
X-Providence-Cookie
X-Whom
X-GUploader-UploadID
X-Goog-Stored-Content-Encoding
X-NGENIX-Cache
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Goog-Metageneration
X-Goog-Storage-Class
X-App-Server
X-Varnish-Grace
X-App-Environment
Cross-Origin-Opener-Policy
Viewport
X-F-Cache
Payment
X-Tb
X-WebKit-CSP-Report-Only
X-Distributor
Paypal-Debug-Id
DC
X-Logged-In
X-FW-Type
X-FW-Dynamic
Node
X-FW-Hash
X-FW-Serve
X-FW-Static
X-FW-Server
X-Cache-Control
X-Oneagent-Js-Injection
Fastcgi-Useragent
X-Seen-By
X-Type
X-Cache-Age
X-User-Agent
X-Fastcgi-Cache
Country
Accept-Charset
X-Webkit-CSP
X-Fastly-Request-ID
X-Cache-Rule
X-Varnish-Backend
Version
X-DataDome
X-Erf-Bev-Bev
X-Node-Name
X-Browser-Type
X-Erf-Bev-Bev-Is-Generated
X-Oracle-Dms-Rid
X-Oracle-Dms-Ecid
X-Load-Cache
X-Wix-Request-Id
Refresh
X-Cache-Action
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-TEC-API-ROOT
X-IPLB-Instance
X-Via-JSL
Cache-Status
SD-X-WS
Liferay-Portal
Access-Control-Request-Headers
X-Response-Served-From
X-Original-Request-Id
Referer-Policy
X-Jobs
X-Cacheable-TTL
X-Real-IP
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-B
X-Drupal-Cache-Tags
X-Vgn-Hpd-Reason
X-UUID
X-Rendered-As
NGB
X-Contextid
X-Page-View
X-Revision
X-Cache-Expired-At
X-RemovedCookies
X-ProcessESI
X-Is-Bot
X-Proxy-Cache-Status
X-Cluster-Name
X-Debug
X-Yottaa-Metrics
X-Drupal-Cache-Contexts
X-Device-Type
X-Rule
X-Proxy
X-Yottaa-Optimizations
Amp-Access-Control-Allow-Source-Origin
Surrogate-Key
DynaTrace
Akamai-GRN
X-Cache-Time
X-Instance
X-Mobile
X-Framework
X-G
X-B-Cache
X-Azure-Ref
X-Debug-IsPreview
X-Signature
X-Debug-IsConnected
Healthy
X-FW-Version
CF-IPCountry
X-Source
SID
X-Tec-Api-Root
X-Tec-Api-Origin
X-Tec-Api-Version
X-Ratelimit-Limit
X-Air-Hostname
X-Air-Source
X-Air-Trace-Id
X-Ms-Version
X-Ms-Request-Id
Frame-Options
Ms-Operation-Id
X-Cache-Hit
X-Nginx-Cache
X-RTag
MS-CV
X-Tumblr-Pixel
Countrycode
X-Tumblr-Pixel-0
X-Tumblr-User
X-Tumblr-Pixel-1
Section-Io-Cache
Xserver
X-L-Path
X-Environment-Context
X-Varnish-Server
X-CDN-Forward
X-XRDS-Location
X-RateLimit-Limit
Count-Hit
X-Region
X-Servername
X-APP-VERSION
X-Cache-Operation
X-Forwarded-Host
X-EdgeConnect-Cache-Status
X-Content-Powered-By
GEO-INFO
Uber-Trace-Id
X-Litespeed-Cache
X-Backend-Name
X-IPS-LoggedIn
Backend
Cross-Origin-Window-Policy
X-Accel-Buffering
X-Mode
X-Adobe-Loc
X-Adobe-Content
X-RN-RSRV
X-Zen-Fury
Ec-Rule-Version
Meta-Geo
X-SaId
X-UPSTREAM-Address
X-Time
X-JoinUs
X-Debug-Cache
Eomportal-Instance
X-Sorting-Hat-ShopId
X-Cache-Type
X-Microcachable
X-No-Session
X-Redis-Cache
X-Cache-Grace
X-Alternate-Cache-Key
X-Varnish-Beresp-Grace
X-Cache-Server
X-Generation-Time
X-Sorting-Hat-PodId
X-ShopId
X-Shopify-Stage
Apigw-Requestid
X-Hosted-By
X-ShardId
X-Detected-As
X-Human
X-ProxyCache-Key
X-Uri
Url
Cache-Tv-Group
X-Cache-TTL-Remaining
Decoy-Debug-Status
X-Storage
Decoy-Debug-Key
Cache-Name
Decoy-Debug-TTL
Country-Code
X-ProxyCache-Status
X-NCache
X-Site-Version
X-Sql-Duration-Ms
X-Sql-Count
X-FB-TRIP-ID
X-Via-Fastly
X-BYPASS-REASON
X-Status
X-ServerID
X-PHP-Backend
X-Origin-Date
X-Format
X-Timing-Wait
Fastly-SSL
X-Say-Cacheable
X-PCL
Property-Id
X-UA-Device-Type
X-SayCDN-TTL
X-Say-TTL
Protected
X-OCL
X-Web-Node
Mn-Server-Ip
Webcakes-App-Name
Webcakes-App-Version
X-Proxy-Build
Webcakes-Region
TWC-Privacy
TWC-Locale-Group
Selected-Fe
X-Origin-Hint
TWC-Connection-Speed
TWC-Device-Class
TWC-GeoIP-LatLong
TWC-GeoIP-Country
X-Cache-Host
X-Akamai-Edgescape
X-SRV
X-Azure-Ref-OriginShield
Source
X-Extlb
X-Varnishpool
OT-Force-Account-Verify
X-ApacheServer
X-Zipkin-Id
X-Server-W
X-Section
X-PERF
X-NYM-Debug-Backend
X-Proxied
X-Access
X-Routing-Service
X-Pubstack
DB-Nickname
X-R9-Blue-Green-Version
Azure-SlotName
Azure-SiteName
Azure-InstanceId
X-Hl-Ver
Azure-Version
Azure-RegionName
X-Tid
X-LSADC-Cache
X-Be
X-Rewrite-Enabled
X-Cluster-Node
Content-Secure-Policy
X-Soup
X-Cache-Var-Map
X-Cache-Var
X-App-Version
X-Cache-NGX
X-Webkit-Csp
X-HTML-Minification-Powered-By
X-Amz-Meta-S3cmd-Attrs
X-Content-Age
X-Cached-By
X-NewRelic-App-Data
SRV
Content-Disposition
X-Ratelimit-Reset
X-Ua
Webserver
X-TT-LOGID
X-LAGOON
X-Loop
X-Varnish-Hostname
CDN-RequestCountryCode
CDN-RequestId
CDN-Uid
X-Generated-By
CDN-PullZone
CDN-EdgeStorageId
Cache
CDN-Cache
CDN-CachedAt
X-Varnish-Hits
X-TNCMS
X-Unique-Id
Onion-Location
X-Bc-Bl
X-S-Maxage
X-Origin-CC
X-Auto-Login
X-Hyper-Cache
Retry-After
X-Origin-TTL
X-Dc
X-Tumblr-Pixel-3
X-Tumblr-Pixel-2
X-GEO
X-Proto
Web-Mar-Node
Cache-Hits
X-Nginx-Cache-Key
X-Cdn
Xet-Cookie
X-Qnm-Cache
X-M-Reqid
X-M-Log
X-Time-Microsecs
X-Endurance-Cache-Level
X-Tenant
X-Edge-Location
X-CSRF-Token
X-GG-Cache-Date
X-Akamai-Transformed
X-VWS-Id
X-AWS-Id
X-Presslabs-Stats
X-LJ-Flow-ID
CloudFront-Viewer-Country
Mime-Version
X-Platform-Server
X-CACHE-KEY
LB
X-ECache
HostName
X-Mg-Request-UUID
X-Trace-Id
X-Labrador-Cache-Channel
X-Amzn-RequestId
X-Amz-Apigw-Id
X-PHP-Host
X-B3-SpanId
N-Cache
X-Xrds-Location
X-Xfnlog-Site
X-Cache-Tags
X-RCS-CacheZone
X-Handled-By
X-Storefront-Renderer-Rendered
X-Locale
Upgrade-Insecure-Requests
X-Adobe-Source
Nel
X-Varnish-Cache-Hits
X-Origin-Response-Time
X-VC-Cache
ServedBy
X-Request-Time
X-V-Cache
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
BehaviorPad-Version
X-NAPM-TraceId
WPO-Cache-Status
A
Expiry
Fastcgi-X-Cache-Version
X-Rojux
DCR-Decision-By
X-ScT
X-ND-Cache
X-A
DCR-Processing-Time-Ms
DSUID
X-Ig-Push-State
X-SD-PageType
X-S
WPO-Cache-Message
X-TIM-N
X-SVT-ORM-VERSION
State
Origin
Odigeo-Trace-Id
X-SVT-ORM-RULES
Rendered-Blocks
Redirect-Candidate
X-SRCache-Key
X-Slack-Backend
Mobile-Detection-Method
X-A-Ccd
X-AOL-HN
Environment
Pramga
Meta-Geo-Continent
X-Processor
X-Shop-Environment
Surrogated-Key
X-Session-Fingerprint
X-Request-Host
X-Aed
X-Cache-Date
X-Vtex-Remote-Cache
X-S-Cookie
Xc-Version
X-External-Request-Id
X-A-Dam
X-Forwarded-Path
X-B-Cookie
X-PBS-Appsvrname
X-PAYTM-SRV-ID
X-Ftr-Request-Id
X-Cache-NE
X-Developer
X-Ckpd-Fst-Backend
X-D
X-Cluster
X-Conf
X-ATG-Version
X-CF-Lambda-Version
X-Reqid
X-Destination
X-Orig-Expires
X-CF-Lambda-Fn
X-ARC
X-Vtex-Processado-Em
X-Vdms-Path
X-Vdms-Version
X-VG-WebCache
X-A-Dcw
X-Cache-Remote
X-Planisys-CDN-Cache
X-Application
X-Connection-Hash
X-A-Wwc
X-A-Dgt
X-Via-NSCOPI
Server-Info
X-MP-GENERATED-AT
AMP-Access-Control-Allow-Source-Origin
Gh-Request-Id
Host-ID
L
X-Hash
Wxu-Next-Hostname
X-Core-Mission
X-Old-Content-Length
X-Nyt-Route
Datacenter
Wxu-Next-Region
X-Date
Wxu-Next-Commit
Fastcgi-Cache-TTL
X-Origin-Expires
X-Rocket-Nginx-Serving-Static
X-Epic-Correlation-Id
X-Li-Pop
X-Proxy-Upstream
X-Policy
X-Cache-Bucket
X-Forwarded-Site
X-Geo-Header
X-Men
X-Gdpr
X-LI-UUID
Release
X-Fetched-On
X-Location
X-Device-Os
X-Origin-Time
X-Cache-Info
X-Accel-Expires-Debug
V-Age
Vix-Hermes-Req-Id
X-Owner
X-Li-Fabric
X-Sucuri-ID
User-Cache-Control
X-Varnish-Ttl
X-Gen-Mode
X-Scheme
X-Hnp-Log
X-VServer
X-Skip-Cache
X-VG-TLSProxy
X-Mvc-Supplant-Cachable
X-Varnish-Beresp-Status
From-Origin
X-Sucuri-Cache
X-Fastly-Cache
X-Block-Status
AKAMAI
X-Server-IP
Candidate-Md5Url
CacheControlHeader
X-Served-From
Cmstype
Cmsid
X-Ratelimit-Remaining
X-Datadog-Trace-Id
X-TrackingId
X-Magnolia-Registration
X-BBC-Edge-Cache-Status
X-VarnishDD-TTL
X-Cdn-Origin
X-NodeID
X-Cache-Debug
X-Datadog-Parent-Id
X-Platform
X-EC-Lua
We-Hiring
Web-Mar-Region
X-Datadog-Sampling-Priority
X-Level-Front-Cache
X-Viewer-Country
X-Gzip
Arc-Country
X-Cache-Config
X-Branch-Name
X-GeoIP-City
X-TH-Server
Origin-EX
True-Client-Country-4JS
CDCHOST
Origin-CC
X-GeoIP
X-Aicache-OS
Traceparent
X-Cache-Id
Req-Svc-Chain
X-Bip
Svr
Machine
Locid
X-NU-AKA-ACS-Version
Mail-Subject
X-Req
X-Thinkindot-L3
X-Sigma
X-HS-Content-Campaign-Id
X-Request-Start
X-Esi-Check
Apple-News-Services-Request-Url
X-Fastly-Backend
X-Irp-Debug
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
Apple-News-Services-Handled
X-Rocket-Build-Number
Fastly-GeoIP-CountryCode
X-Sigma-Backend
X-Developers
X-Generated-On
X-Thanos
X-Core-Value
TDXMobile
Thinkindot-CacheControl
Thinkindot-Control
Thinkindot-CacheControl-Type
X-Region-Sid
Server-Host
X-HN
X-Sn-Servicetimems
PFcat
X-Gamma-Serve
X-CS
X-DefHash
X-FC-Vary-Parameters
X-Envoy-Decorator-Operation
NGX
X-CGP
X-DefElseHash
X-DPWN-IS-SECURE
X-Eu-Site
X-Csrf-Jwt
X-Rebelmouse-Surrogate-Control
WWW-Authenticate
X-Loc
NM-Fastcgi-Cache
Memcached
X-RateLimit-Remaining-Second
Platform
X-Qloud-Router
X-RateLimit-Limit-Second
L5d-Success-Class
Adler-Geo
X-JWT-State
Cf-Device-Type
X-Request-URI
Ha-Gx-Prefs
Is-Eu
HA-Ipaddr
X-Pod-Name
X-UnsetCookies
X-Backend-State
X-Has-Esi
X-Worker
Fastly-SIE
X-TIME
Fastly-SWR
X-Amzn-Remapped-Content-Length
X-Webstats-RespID
X-Rebelmouse-Cache-Control
X-Variation
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-Is-Gdpr
X-Varnish-Remaining-TTL
X-Origin
X-Zone
X-FireWall-Port
X-Varnish-Beresp-Ttl
X-Trace-ID
X-Node-Id
X-Cdn-Srv
Sslversion
X-Correlation-ID
Fastly-Drupal-Html
X-Tx-Id
On-Server
Esi-Enabled
X-Up
CDN
Pics-Label
X-API-Version
X-Response-By
Ssr
X-LB-ID
X-Mvc-Supplant-OutputCached
WP-Super-Cache
Ms-Author-Via
X-Service
X-Vc
X-NC
C-Via
X-Generated-In
X-Datadome
X-Refresh
X-Via-Popn
X-Via-Popv
X-Via-Poph
X-Cache-PHP
Time
Memory
X-DynaTrace-JS-Agent
X-TA-CDN-Provider
X-Cache-Enabled
X-DC
NtCoent-Length
X-Backend-TTL
X-LB-NoCache
X-Edge-Pop
X-Dynatrace
Env
X-Tt-Logid
X-GeoIP-Region-Code
X-Tb-Optimization-Total-Bytes-Saved
X-Cache-Ttl
X-GeoIP-Country-Code
X-Cache-Status-Check
X-Parent-Response-Time
GeoIp-Country-Code
Magicmarker
X-Render-Time
X-Optimistic-Header
X-Info
X-TraceId
X-NWS-UUID-VERIFY
X-Ua-Device
X-Restarts
X-Servedbyhost
X-Esi
X-TX-ID
X-ZONE
X-Unique-ID
Server-ID
X-Varnish-Beresp-TTL
Kp-EeAlive
X-CacheTTL
X-AIR-PT
X-Clientip
X-CLOUD-TRACE-CONTEXT
S-Rt
X-RSL
X-Webkit-CSP-Report-Only
X-VCL-Version
X-Oss-Hash-Crc64ecma
X-RPS
Edge-Cache
X-Wix-Viewer-Type
X-MSEdge-Flight
X-MSEdge-Features
X-Cache-Backend
X-Oss-Object-Type
X-Oss-Request-Id
X-DB
X-DI
X-Action
UCS
HIT
X-Cs
X-DSS
Cache-Host
X-Oss-Server-Time
X-Oss-Storage-Class
X-DW
X-RPM
Proxy-Connection
X-HA-Backend
X-LI-Proto
X-Fpc
X-App
X-Newrelic-Synthetics
X-Srv
S-Cnection
X-Traceid
X-URL
Lb
Section-Origin-Responded
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
Section-Io-Id
X-Webkit-Csp-Report-Only
X-Minions-Version
WebServer
X-Li-Proto
Test
X-FPC
Fastly-Backend-Name
User-Agent
X-Micro-Cache
X-LiteSpeed-Cache-Control
X-NODE
Tcn
Server-Id
X-Backend-Host
Geo-Info
X-Vcl-Version
X-B3-Spanid
X-Http-Reason
X-Akamai-Request-ID2
X-BCube-Filmed-By
X-Release
X-Pass-Why
X-Pad
X-ES-SERVER
X-User
X-Ec-Fail
Cf-Int-Pingora-Origin-Digest
X-BBC-Origin-Response-Status
X-APP
Resin-Trace
Accept-Language
Fastly-Drupal-HTML
X-LiteSpeed-Tag
X-Ec-GeoHdr
X-HostName
X-CSRF-TOKEN
Cache-Key
X-ServedByHost
VNS-Cache
GeoIP-Country-Code
CPC-Cache
VNS-Age
EpKe-Alive
Path
CPC-Age
X-Amz-Meta-Cb-Modifiedtime
X-ID
Hostname
X-Urbn-Site-Id
Locale
X-Urbn-Context-Path
X-WA
Hit
Srv
X-Akamai-Pragma-Client-IP
X-Check-Cacheable
X-WA-Info
Ohc-File-Size
X-Dynatrace-Js-Agent
X-Geo
ENV
X-Fmm-Version
Cdncip
X-WADP-Cache
Pagetype
M-TraceId
X-ElasticPress-Query
X-Via-PopV
X-Edge-POP
X-HS-Status
X-Ha-Backend
MIME-Version
Shield-Pop
X-AK-Request-ID
X-Cdn-Forward
X-Wikidot-Backend
Cdnsip
X-Wikidot-Static-Cache
X-PJAX-URL
X-Clara-WADP
X-Via-PopH
X-Via-PopN
X-Cms-Context
Load-Balancing
X-Edge-Cache
MD5-Digest
X-CCDN-Origin-Time
X-Api-Version
X-NGINX-Cache
X-Via-Ucdn
Cluster
X-CCDN-CacheTTL
X-Hcs-Proxy-Type
My-App
X-Ucs
X-Var-Ttl
X-ServerName
URI
X-From
Lfy
Geoip-Latitude
X-CUA
Tracecode
X-VG-WebServer
X-Cache-Expires
W
X-Nc
X-SIPLIST1
IsBot
X-Fastly-Backend-Reqs
X-Mcache
X-GoCache-CacheStatus
Server-Hostname
Server-Ext
T-Server
Sever-Int
X-TRACE-ID
X-Dw-Trace-Id
X-Lb-Id
X-VC
X-Cdn-Request-ID
Cteonnt-Length
Servername
X-Provided-By
WZWS-RAY
X-RateLimit-Reset
Cdn
X-Fragments
X-UP
Lang
Cneonction
PICS-Label
X-RAMCache
Ohc-Cache-HIT
X-B3-ParentSpanId
X-Fastly-Cache-Hits
X-UA
X-Acquia-Site
X-Swift-Error
X-Acquia-Application-Trace
X-Acquia-Application-UUID
X-Acquia-Purge-Tags
X-Apw-Access-Object
Target-Params
X-Apw-Access-Action
Dnion-Transfer-Encoding
X-Apw-Access-Token
X-Apw-Hits
HitType
X-Akamai-Request-ID
X-Platform-Router
Cf-Ipcountry
X-Platform-Cluster
X-Newrelic-App-Data
X-Platform-Processor
X-Cache-ASPX
X-Cc-Via
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
CF-Cached-On
X-Contensis-Viewer-Groups
X-Via-CDN
X-Snapshot-Date
X-Yottaa-OS
Vha6-Origin
X-Air-Pt
Sid
X-Cache-Ngx
X-Te-Duration-Ms
Server-Ttl
GeoIP-Latitude
Uri
X-Http-Duration-Ms
X-Te-Count
X-Akamai-ERRuleID
X-Akamai-ERPolicy
X-Last-Modified
FSS-Cache
X-Varnish-Authentication
X-Logging-Id
X-Lb-Nocache
X-Miniprofiler-Ids
X-B3-Parentspanid
X-CacheKey
X-HTML-Edge-Cache
Ngx
X-Sentry-ID
CountryCode
Req-ID
X-Http-Count