Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-Cache-Status
Link
Accept-Ranges
CF-RAY
ETag
Expect-CT
Pragma
X-Powered-By
X-XSS-Protection
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
Alt-Svc
X-Served-By
X-Xss-Protection
X-Download-Options
X-Timer
X-Request-Id
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Cache-Status
X-Check
X-Generator
X-Cacheable
Timing-Allow-Origin
X-Content-Security-Policy
X-Iinfo
Feature-Policy
Status
X-Envoy-Upstream-Service-Time
Content-Encoding
Access-Control-Expose-Headers
P3p
X-Drupal-Dynamic-Cache
X-Request-ID
X-CDN
X-AspNetMvc-Version
Upgrade
X-Via
CF-Ray
X-Ws-Request-Id
Access-Control-Max-Age
Server-Timing
EagleId
X-Cache-Group
X-Turbo-Charged-By
Keep-Alive
Request-Context
X-UA-Device
Report-To
X-Age
X-Backend
X-Server-Powered-By
X-Proxy-Cache
X-AH-Environment
X-Robots-Tag
X-Hacker
X-Amz-Request-Id
X-Server
Host-Header
X-Amz-Id-2
Grace
X-LiteSpeed-Cache
X-Rq
X-Nginx-Cache-Status
X-Swift-SaveTime
X-Swift-CacheTime
X-Varnish-Cache
Ali-Swift-Global-Savetime
X-WebKit-CSP
X-Page-Speed
NEL
X-Vhost
X-Ua-Compatible
EagleEye-TraceId
X-Amz-Version-Id
X-Dns-Prefetch-Control
X-OneAgent-JS-Injection
X-Pingback
X-Dispatcher
X-Device
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Cache-Spec
X-Host
Cf-Railgun
X-Server-Id
Accept-CH
X-Backend-Server
X-Node
X-Readtime
Surrogate-Control
X-Akam-SW-Version
Request-Id
X-Response-Time
X-HW
Xkey
X-Application-Context
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Content-Location
Rating
Accept-Ch-Lifetime
X-Ruxit-JS-Agent
X-Country
X-B3-TraceId
X-Cloud-Trace-Context
Accept-CH-Lifetime
X-Cache-Lookup
X-Trace
X-Url
X-Ac
X-Content-Type
X-Vname
X-PC
X-TtlSet
Allow
X-Varnish-TTL
X-Clacks-Overhead
Edge-Control
X-Mod-Pagespeed
X-Server-Name
X-ESI
Fastly-Restarts
X-Aws-Lambda-Call-Status
Cache-Tag
Service-Worker-Allowed
X-VARITI-CCR
X-Rack-Cache
Verso
X-Element-Page-Cache
X-Upstream
MS-Author-Via
X-FastCGI-Cache
X-Vcap-Request-Id
X-MS-InvokeApp
X-GitHub-Request-Id
X-Amz-Rid
Public-Key-Pins
X-Dw-Request-Base-Id
X-Cached
X-Client-IP
X-D2id
X-Abt-Application-Version
X-Cnection
X-Px
RTSS
X-Cache-TTL
X-Navigation-Version
X-GoogleNews-Bot
X-Kinja-Server
X-Kinja
X-Kinja-Revision
X-Country-Code
X-Use-Magma
X-Kinja-Build
Arr-Disable-Session-Affinity
X-Cdn-Fetch
X-Exp-Id
X-Exp-Variant
Access-Control-Request-Method
X-Powered-By-Plesk
X-Goog-Hash
X-NF-Request-ID
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-Instrumentation
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-Powered-CMS
AR-Request-ID
AR-PoweredBy
AR-CACHE
AR-ATIME
AR-SID
X-Origin-Cache
X-Middleton-Display
Display
X-Sol
Pagespeed
X-Version
X-Middleton-Response
Response
Accept-Ch
X-TTL
X-LLID
X-Amz-Server-Side-Encryption
X-MSEdge-Ref
X-Edge-Location-Klb
X-Kinsta-Cache
TCN
Nginx-Cache
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Edge
X-B3-TraceId-Primal
X-RateLimit-Remaining
Mrf-Cache-Status
MRF-Tech
X-Protected-By
X-T
X-HP-Webp
X-HP-Trace-Id
X-Jurisdiction
X-Forwarded-For
X-Content-Security-Policy-Report-Only
X-Shield-Request-Id
X-Aspnetmvc-Version
X-Id
X-Mg-S
S
Content-MD5
Edge-Cache-Tag
X-CST
X-Language
SPIisLatency
SPRequestDuration
Fastcgi-Cache
X-Mid
Front-End-Https
X-DynaTrace
Realpath
X-Request-Processing-Time
X-Request-Received
Server-Node
X-Recruiting
Pinterest-Generated-By
X-Pinterest-Rid
Pinterest-Version
Filters
X-Frontend
Server-Name
X-MCACHE
X-Content
X-Ua-Browser
X-Ab
X-Ruxit-Js-Agent
X-Correlation-Id
X-Cache-Key
X-Ser
X-Ttl
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Cache-Config
X-HS-Combine-CSS
X-NWS-LOG-UUID
X-Yandex-Sdch-Disable
X-Template
X-Ezoic-Cdn
X-ECACHE
X-SharePointHealthScore
SPRequestGuid
X-Hits
X-Parallel-Accel
X-Server-ID
MicrosoftSharePointTeamServices
X-Tt-Trace-Host
X-Tt-Trace-Tag
Alternate-Protocol
Cache-Tags
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Page-Id
Charset
X-B3-Sampled
Fusion-Component-Id
Fusion-Source
Fusion-Template-Id
Host
Fusion-Deployment-Id
Fusion-Content-Source
Fusion-Content-Id
Cleartype
X-Git-Hash
X-Www-Served-By
X-Content-Options
X-Geo-Country
X-Debug-Info
X-Hostname
X-DIS-Request-ID
X-Daa-Tunnel
X-Amzn-Trace-Id
X-Content-Digest
X-Amz-Replication-Status
X-Varnish-Age
Filterid
Cross-Origin-Opener-Policy
X-Ratelimit-Limit
X-AppVersion
X-Activity-Id
X-Az
X-FB-Debug
X-Upgrade-Enabled
X-VCache
X-Grace
X-Accel-Expires
X-Nginx-Upstream-Cache-Status
X-N
X-Forwarded-Proto
X-Origin-Server
X-F-Cache
Access-Control-Allow-Method
X-Rid
X-Mobile-URL
X-Fastly-Request-Id
ServerID
X-Providence-Cookie
X-Is-Crawler
X-Aspnet-Duration-Ms
X-Request-Guid
X-Flags
X-Route-Name
X-Fastcgi-Cache
X-Type
TP-Cache
X-LB-Cache
TP-L2-Cache
X-TT
X-Whom
X-Varnish-Grace
X-GUploader-UploadID
X-Goog-Metageneration
X-App-Environment
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Seen-By
X-Goog-Generation
X-WebKit-CSP-Report-Only
X-Tb
Payment
X-DataDome
X-FW-Type
X-FW-Static
X-FW-Server
X-Distributor
Node
Viewport
X-FW-Dynamic
X-FW-Hash
X-FW-Serve
X-XRDS-LOCATION
X-User-Agent
DC
X-App-Server
Paypal-Debug-Id
X-Fastly-Request-ID
Country
Accept-Charset
Fastcgi-Useragent
X-Wix-Request-Id
X-Litespeed-Cache
X-NGENIX-Cache
X-Cache-Control
X-Cache-Rule
X-Origin-Upstream-Status
X-Webkit-CSP
Version
X-Webkit-Csp
X-Via-JSL
Referer-Policy
X-Logged-In
X-Drupal-Cache-Tags
X-Microsite
X-Request-Handler-Origin-Region
X-Oracle-Dms-Rid
X-Oracle-Dms-Ecid
X-Contextid
X-Cluster-Name
X-Cache-Age
Amp-Access-Control-Allow-Source-Origin
X-Buckets
X-Tec-Api-Root
X-Tec-Api-Version
X-Ratelimit-Reset
X-Tec-Api-Origin
X-B-Cache
X-Signature
X-Erf-Bev-Bev-Is-Generated
Refresh
Cache-Status
X-Browser-Type
X-Erf-Bev-Bev
X-Mobile
X-Original-Request-Id
X-Load-Cache
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Node-Name
X-Varnish-Backend
SD-X-WS
X-Response-Served-From
X-Page-View
X-Rendered-As
X-Real-IP
X-Is-Bot
X-Cache-Expired-At
X-Vgn-Hpd-Reason
X-Jobs
X-B
X-IPLB-Instance
NGB
X-Cacheable-TTL
X-Proxy-Cache-Status
X-Debug
Access-Control-Request-Headers
X-Revision
X-Cache-Action
X-UUID
X-Rule
X-Device-Type
X-RemovedCookies
X-ProcessESI
X-Proxy
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Instance
Surrogate-Key
Akamai-GRN
X-Debug-IsPreview
X-Debug-IsConnected
X-Cache-Time
X-Framework
X-Drupal-Cache-Contexts
X-FW-Version
X-G
CF-IPCountry
X-Air-Hostname
X-Air-Source
SID
X-Air-Trace-Id
GEO-INFO
X-Accel-Buffering
DynaTrace
X-Azure-Ref
X-PressLabs-Stats
X-TEC-API-ORIGIN
X-Oneagent-Js-Injection
X-TEC-API-ROOT
X-TEC-API-VERSION
X-Nginx-Cache
X-Cache-NGX
Liferay-Portal
Count-Hit
X-Ms-Version
X-Ms-Request-Id
Uber-Trace-Id
X-Source
X-Presslabs-Stats
X-Cache-Operation
X-XRDS-Location
Frame-Options
X-APP-VERSION
X-EdgeConnect-Cache-Status
X-Zen-Fury
Ms-Operation-Id
MS-CV
X-RTag
X-CDN-Forward
Healthy
X-RateLimit-Limit
X-Cache-Hit
Protected
Xserver
X-Backend-Name
X-Mode
X-Environment-Context
X-L-Path
Countrycode
X-IPS-LoggedIn
Cross-Origin-Window-Policy
X-Varnish-Server
Ec-Rule-Version
X-Tumblr-Pixel-1
X-Tumblr-User
X-Tumblr-Pixel
X-Tumblr-Pixel-0
LB
X-Cache-TTL-Remaining
X-Ratelimit-Remaining
Backend
X-Hyper-Cache
X-Adobe-Content
X-Tid
X-UPSTREAM-Address
X-SaId
X-Detected-As
X-Adobe-Loc
X-JoinUs
X-RN-RSRV
X-Forwarded-Host
X-Servername
Meta-Geo
X-Region
X-Rewrite-Enabled
X-Content-Age
X-Debug-Cache
X-Shopify-Stage
X-Hosted-By
X-Sql-Duration-Ms
X-Format
X-Extlb
X-Generation-Time
X-Sorting-Hat-PodId
X-Sql-Count
X-ShopId
WPO-Cache-Status
X-Zipkin-Id
Apigw-Requestid
X-Cache-Grace
X-Proxied
WPO-Cache-Message
Decoy-Debug-Key
X-Routing-Service
X-Uri
Country-Code
X-Sorting-Hat-ShopId
Decoy-Debug-Status
X-ShardId
Section-Io-Cache
X-Redis-Cache
Decoy-Debug-TTL
X-Alternate-Cache-Key
Eomportal-Instance
X-Cache-Server
Mn-Server-Ip
Cache-Name
Content-Disposition
X-Access
Url
X-ApacheServer
X-FB-TRIP-ID
X-Status
X-PHP-Backend
Fastly-SSL
X-PERF
X-Varnish-Beresp-Grace
X-Content-Powered-By
X-Human
X-Section
X-ServerID
X-PCL
X-Site-Version
X-No-Session
X-NCache
X-Microcachable
X-OCL
X-Via-Fastly
X-Origin-Date
TWC-Device-Class
TWC-GeoIP-Country
TWC-GeoIP-LatLong
CDN-Uid
TWC-Locale-Group
X-Say-TTL
X-Say-Cacheable
X-Proxy-Build
X-ProxyCache-Status
CDN-Cache
Property-Id
X-SayCDN-TTL
Selected-Fe
TWC-Connection-Speed
X-Server-W
CDN-RequestId
X-Cache-Type
CDN-RequestCountryCode
X-Cluster-Node
X-Storage
X-NYM-Debug-Backend
X-Origin-Hint
X-ProxyCache-Key
X-BYPASS-REASON
X-Timing-Wait
CDN-CachedAt
Webcakes-Region
Webcakes-App-Version
X-UA-Device-Type
CDN-EdgeStorageId
CDN-PullZone
X-Akamai-Edgescape
Webcakes-App-Name
TWC-Privacy
Cache-Tv-Group
X-Soup
X-Web-Node
X-Generated-By
X-Varnishpool
X-Be
X-R9-Blue-Green-Version
X-Cache-Host
X-Hl-Ver
X-NewRelic-App-Data
X-Pubstack
Azure-SiteName
Azure-InstanceId
Azure-SlotName
Azure-RegionName
Azure-Version
X-LSADC-Cache
DB-Nickname
X-Azure-Ref-OriginShield
X-Ua
X-TIME
X-Trace-Id
Content-Secure-Policy
OT-Force-Account-Verify
Retry-After
X-Nginx-Cache-Key
X-Cached-By
Source
X-TT-LOGID
X-Bc-Bl
Cache
SRV
X-Cache-Remote
X-Unique-Id
X-Auto-Login
X-Akamai-Transformed
X-Dc
X-Platform-Server
X-LAGOON
X-GEO
X-Xfnlog-Site
X-Cdn
Cache-Hits
X-Cache-Tags
HostName
X-EC-Lua
Upgrade-Insecure-Requests
X-Origin-CC
X-Origin-TTL
X-Varnish-Hits
ServedBy
X-Loop
X-Varnish-Hostname
Mime-Version
X-App-Version
X-SRV
X-TNCMS
X-HTML-Minification-Powered-By
X-S-Maxage
X-Varnish-Cache-Hits
X-CSRF-Token
Onion-Location
From-Origin
X-Request-Time
X-Time
X-AOL-HN
Xet-Cookie
X-Request-Host
Webserver
X-Amz-Meta-S3cmd-Attrs
WP-Super-Cache
N-Cache
X-Xrds-Location
X-Proto
X-ECache
X-B3-SpanId
X-Tumblr-Pixel-3
X-Tumblr-Pixel-2
X-NWS-UUID-VERIFY
Web-Mar-Node
X-Tenant
X-Endurance-Cache-Level
X-Cache-Enabled
X-FireWall-Port
X-AWS-Id
X-Handled-By
X-Correlation-ID
X-VWS-Id
Nel
X-LJ-Flow-ID
X-Time-Microsecs
X-Origin-Response-Time
X-GG-Cache-Date
X-A-Ccd
X-Developer
A
X-External-Request-Id
X-Gen-Mode
X-A
X-Epic-Correlation-Id
X-Vdms-Version
X-Ftr-Request-Id
X-Forwarded-Path
X-VG-WebCache
X-Ckpd-Fst-Backend
Xc-Version
X-A-Dcw
X-Vtex-Remote-Cache
X-Cache-NE
X-A-Dgt
X-Block-Status
X-Application
X-ARC
X-B-Cookie
X-Backend-TTL
X-A-Dam
X-CF-Lambda-Fn
X-Conf
X-Connection-Hash
X-D
X-Vtex-Processado-Em
X-Cluster
X-Aed
X-CF-Lambda-Version
Vix-Hermes-Req-Id
X-Aicache-OS
X-Destination
X-TIM-N
X-Edge-Location
X-PBS-Appsvrname
X-Planisys-CDN-Cache
X-SRCache-Key
X-Slack-Backend
X-PAYTM-SRV-ID
Meta-Geo-Continent
X-Orig-Expires
Redirect-Candidate
Odigeo-Trace-Id
Mobile-Detection-Method
X-Shop-Environment
X-Session-Fingerprint
X-S
X-Rojux
X-S-Cookie
X-SD-PageType
X-ScT
Fastcgi-X-Cache-Version
X-Processor
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
DCR-Decision-By
DCR-Processing-Time-Ms
Rendered-Blocks
Pramga
BehaviorPad-Version
X-Vdms-Path
Surrogated-Key
Sslversion
User-Cache-Control
X-V-Cache
X-A-Wwc
X-NAPM-TraceId
Expiry
V-Age
X-Hnp-Log
X-Ig-Push-State
X-Cache-Var-Map
X-Cache-Var
X-ND-Cache
X-RCS-CacheZone
X-Adobe-Source
X-MP-GENERATED-AT
X-Magnolia-Registration
X-Mg-Request-UUID
X-Reqid
Fastcgi-Cache-TTL
Wxu-Next-Hostname
Svr
Origin
Wxu-Next-Commit
State
Host-ID
Wxu-Next-Region
True-Client-Country-4JS
Gh-Request-Id
X-Fastly-Cache
X-Origin
X-SVT-ORM-VERSION
X-Origin-Expires
X-Old-Content-Length
X-Nyt-Route
X-Men
X-Mvc-Supplant-Cachable
X-NodeID
X-SVT-ORM-RULES
X-Origin-Time
X-Proxy-Upstream
X-Request-URI
X-Rocket-Nginx-Serving-Static
X-Policy
X-Server-IP
X-Sucuri-ID
X-Sucuri-Cache
X-Location
X-LI-UUID
X-Date
X-Viewer-Country
X-VG-TLSProxy
X-Cdn-Srv
X-Cache-Info
X-Cache-Bucket
X-Webstats-RespID
X-Scheme
X-Forwarded-Site
X-Hash
X-Li-Fabric
X-Li-Pop
X-GeoIP-Region-Code
X-GeoIP-Country-Code
X-Gdpr
X-Geo-Header
X-Accel-Expires-Debug
X-Cache-Date
AKAMAI
Arc-Country
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
Apple-News-Services-Request-Url
X-Labrador-Cache-Channel
X-PHP-Host
Cmsid
Cmstype
Apple-News-Services-Handled
CDCHOST
CacheControlHeader
X-Amz-Apigw-Id
X-Amzn-RequestId
CloudFront-Viewer-Country
DSUID
X-Via-NSCOPI
S-Rt
Environment
X-Datadog-Parent-Id
X-Eu-Site
X-Esi-Check
X-Datadog-Sampling-Priority
X-Envoy-Decorator-Operation
X-Device-Os
X-Developers
X-Datadog-Trace-Id
X-CGP
X-Branch-Name
X-Cache-Debug
X-BBC-Edge-Cache-Status
X-Backend-State
Server-Info
X-Cache-Id
X-Cdn-Origin
X-Core-Value
X-Core-Mission
Fastly-Drupal-Html
X-Fastly-Backend
X-Csrf-Jwt
X-GeoIP-City
X-Skip-Cache
X-Sn-Servicetimems
X-Sigma-Backend
X-Sigma
X-Rocket-Build-Number
X-Served-From
X-Storefront-Renderer-Rendered
X-TH-Server
X-VarnishDD-TTL
X-VServer
X-Varnish-Beresp-Status
X-UnsetCookies
X-TrackingId
X-Req
X-Region-Sid
X-HN
X-HS-Content-Campaign-Id
X-Gzip
X-GeoIP
X-Gamma-Serve
X-Generated-On
X-Irp-Debug
X-Level-Front-Cache
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Platform
X-Owner
X-Locale
X-Fetched-On
X-Varnish-Beresp-Ttl
Locid
L5d-Success-Class
L
Origin-EX
Machine
We-Hiring
Origin-CC
Ssr
Traceparent
Mail-Subject
HA-Ipaddr
PFcat
Server-Host
Fastly-GeoIP-CountryCode
Release
Req-Svc-Chain
Ha-Gx-Prefs
X-JWT-State
X-Node-Id
X-DefElseHash
Cf-Device-Type
X-DefHash
X-Loc
X-DPWN-IS-SECURE
X-NU-AKA-ACS-Version
X-Has-Esi
X-FC-Vary-Parameters
Platform
X-Tx-Id
X-Is-Gdpr
Memcached
Fastly-SIE
X-Variation
Fastly-SWR
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
Magicmarker
X-Worker
X-Varnish-Remaining-TTL
X-Thinkindot-L3
X-Http-Reason
X-Rebelmouse-Cache-Control
NM-Fastcgi-Cache
X-Qloud-Router
X-Rebelmouse-Surrogate-Control
X-Request-Start
X-Akamai-Request-ID2
Is-Eu
X-Response-By
Adler-Geo
X-Pod-Name
X-Amzn-Remapped-Content-Length
Web-Mar-Region
Thinkindot-CacheControl-Type
Thinkindot-Control
Thinkindot-CacheControl
X-ATG-Version
TDXMobile
X-VC-Cache
X-M-Reqid
X-M-Log
X-Qnm-Cache
X-Ua-Device
X-Trace-ID
X-NODE
AMP-Access-Control-Allow-Source-Origin
NGX
X-Bip
X-Restarts
X-Thanos
X-CS
X-Zone
X-Up
X-API-Version
Kp-EeAlive
X-LB-ID
X-Mvc-Supplant-OutputCached
X-LB-NoCache
X-RSL
Edge-Cache
X-NC
X-Action
X-DB
Ms-Author-Via
CDN
X-DI
X-Cache-Config
X-DW
X-DSS
X-RPS
X-RPM
X-Wix-Viewer-Type
X-Generated-In
Pics-Label
X-TraceId
X-Cache-Backend
Memory
Accept-Language
Time
Env
Datacenter
X-Tb-Optimization-Total-Bytes-Saved
X-CacheTTL
X-DC
X-Refresh
X-Minions-Version
WebServer
X-Edge-Pop
X-Via-Popn
X-Via-Poph
X-Optimistic-Header
X-Varnish-Ttl
X-Via-Popv
X-Srv
X-Tt-Logid
X-Cache-Ttl
X-HA-Backend
Candidate-Md5Url
NtCoent-Length
X-Urbn-Site-Id
GeoIp-Country-Code
X-CACHE-KEY
X-Urbn-Context-Path
Locale
X-ZONE
X-DynaTrace-JS-Agent
On-Server
X-Esi
X-Servedbyhost
Server-ID
WWW-Authenticate
X-Vc
X-Datadome
X-Unique-ID
Esi-Enabled
X-MSEdge-Features
X-Ec-GeoHdr
X-MSEdge-Flight
X-User
X-Ec-Fail
X-Cs
X-CLOUD-TRACE-CONTEXT
X-Parent-Response-Time
X-TA-CDN-Provider
X-TX-ID
X-Varnish-Beresp-TTL
X-VCL-Version
X-Webkit-CSP-Report-Only
X-Cache-PHP
X-Service
C-Via
X-Newrelic-Synthetics
X-App
Cdncip
Cdnsip
X-Traceid
X-Fpc
X-LI-Proto
X-AK-Request-ID
X-URL
X-LiteSpeed-Cache-Control
Test
X-WADP-Cache
X-Webkit-Csp-Report-Only
X-Li-Proto
X-Clara-WADP
X-Fmm-Version
My-App
Cluster
Proxy-Connection
X-B3-Spanid
X-Var-Ttl
X-Render-Time
Cf-Int-Pingora-Origin-Digest
X-FPC
Geoip-Latitude
X-Cache-Status-Check
Tracecode
X-CUA
X-Pass-Why
X-From
X-Vcl-Version
Lfy
T-Server
Fastly-Drupal-HTML
X-Mcache
Resin-Trace
X-Fragments
M-TraceId
Geo-Info
Lang
X-VC
X-Dynatrace
DataCenter
Server-Id
Target-Params
X-CSRF-TOKEN
X-Ha-Backend
GeoIP-Country-Code
X-WP-CF-Super-Cache-Cache-Control
X-Clientip
X-ID
X-WP-CF-Super-Cache
X-LiteSpeed-Tag
Hostname
MIME-Version
Hit
X-RAMCache
X-ServedByHost
X-Oss-Request-Id
X-Oss-Object-Type
X-AIR-PT
HIT
UCS
X-Oss-Server-Time
X-Oss-Storage-Class
X-Oss-Hash-Crc64ecma
X-Info
Cache-Host
X-Provided-By
X-Geo
X-Dynatrace-Js-Agent
X-RateLimit-Reset
X-Edge-POP
X-Via-PopV
Section-Origin-Responded
X-Via-PopN
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
X-Pad
S-Cnection
Section-Io-Id
X-Via-PopH
Permissions-Policy
X-Cdn-Forward
X-Check-Cacheable
X-Httpd
Ohc-File-Size
X-Api-Version
X-Edge-Cache
Servername
ENV
X-NGINX-Cache
X-Proxy-Cache-Info
WZWS-RAY
Producers
X-BBC-Origin-Response-Status
X-Ucs
Fastly-Backend-Name
FSS-Cache
X-HS-Status
X-Micro-Cache
User-Agent
X-SB
X-Cache-CFC
X-Fastly-Backend-Reqs
X-ElasticPress-Query
X-ServerName
Load-Balancing
X-Acquia-Purge-Tags
X-Acquia-Application-UUID
X-Acquia-Application-Trace
X-Platform-Router
Uri
X-GoCache-CacheStatus
X-Release
X-Udemy-Cache-App-Namespace
X-Lb-Nocache
X-Platform-Processor
PICS-Label
X-Backend-Host
X-Platform-Cluster
X-Nc
ServerName
X-UP
URI
X-Pool
X-Acquia-Site
X-TRACE-ID
Cneonction
X-BCube-Filmed-By
X-APP
EpKe-Alive
Cteonnt-Length
Server-Ttl
Cdn
X-Lb-Id
Tcn
X-Scale
X-Ec-Custom-Error
X-Cdn-Request-ID
X-Swift-Error
X-Fastly-Cache-Hits
X-Dw-Trace-Id
X-Cache-Expires
X-Akamai-ERPolicy
Cf-Ipcountry
X-Vcache
X-SIPLIST1
X-Dispatcher-Number
X-Akamai-ERRuleID
Sever-Int
Wpo-Cache-Message
Server-Ext
IsBot
Ohc-Cache-HIT
Path
MD5-Digest
Server-Hostname
X-B3-Parentspanid
X-Newrelic-App-Data
X-B3-ParentSpanId
Shield-Pop
X-Cache-ASPX
X-Contensis-Viewer-Groups
X-Snapshot-Date
Vha6-Origin
Wpo-Cache-Status
CF-Cached-On
X-Yottaa-OS
X-HostName
Sid
X-Cache-Ngx
X-Air-Pt
CPC-Cache
X-Sentry-ID
X-Shopify-Generated-Cart-Token
X-Logging-Id
X-Akamai-Pragma-Client-IP
X-IN-APIGATEWAYSSL
CountryCode
GeoIP-Latitude
X-IN-APIGATEWAY
Req-ID
X-UA
CPC-Age
X-CacheKey
VNS-Age
X-WA
X-WA-Info
X-Last-Modified
X-Te-Duration-Ms
X-Te-Count
X-Http-Count
X-Http-Duration-Ms
X-Varnish-Authentication
X-Apw-Access-Action
X-Apw-Access-Token
Ngx
X-Akamai-Request-ID
Cache-Key
VNS-Cache
X-Apw-Access-Object
X-Amz-Meta-Cb-Modifiedtime
X-Apw-Hits