Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
Strict-Transport-Security
X-Frame-Options
X-Content-Type-Options
Last-Modified
Link
CF-Cache-Status
Cf-Request-Id
Accept-Ranges
ETag
CF-RAY
Expect-CT
Pragma
X-Powered-By
X-Cache
X-XSS-Protection
Via
Age
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Xss-Protection
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-FRAME-OPTIONS
X-Download-Options
X-Timer
X-Request-Id
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-Adblock-Key
X-AspNet-Version
X-Permitted-Cross-Domain-Policies
X-Runtime
Alt-Svc
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Check
X-DNS-Prefetch-Control
X-Cache-Status
X-Generator
CF-Ray
X-Cacheable
Timing-Allow-Origin
X-Iinfo
X-Envoy-Upstream-Service-Time
Feature-Policy
X-Ua-Compatible
Status
X-Content-Security-Policy
X-Drupal-Dynamic-Cache
Content-Encoding
X-Request-ID
X-CDN
Access-Control-Expose-Headers
X-AspNetMvc-Version
Upgrade
X-XSS-PROTECTION
P3p
Access-Control-Max-Age
X-Via
X-Dns-Prefetch-Control
Server-Timing
X-Cache-Group
X-Robots-Tag
X-UA-Device
Request-Context
Keep-Alive
X-AH-Environment
X-Amz-Request-Id
X-Turbo-Charged-By
X-Backend
X-Amz-Id-2
X-Ws-Request-Id
X-Proxy-Cache
X-Age
Host-Header
X-Server-Powered-By
X-Hacker
X-Akamai-Path-Stats
X-Server
X-Rq
EagleId
X-Vhost
X-Varnish-Cache
Grace
X-Amz-Version-Id
X-Dispatcher
X-LiteSpeed-Cache
Cf-Edge-Cache
Nel
Allow
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Nginx-Cache-Status
X-Device
X-Page-Speed
X-WebKit-CSP
X-Aws-Lambda-Call-Status
X-Host
X-Node
X-Server-Id
EagleEye-TraceId
X-OneAgent-JS-Injection
X-Pingback
X-Cache-Spec
Request-Id
Surrogate-Control
Cf-Railgun
Accept-CH
X-Akam-SW-Version
X-Backend-Server
X-Readtime
X-Cache-Lookup
X-Response-Time
Accept-CH-Lifetime
X-HW
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Content-Security-Policy-Report-Only
Content-Location
X-Application-Context
Rating
X-Trace
Fastly-Restarts
X-Cloud-Trace-Context
X-Country
X-WebKit-CSP-Report-Only
X-Url
X-Clacks-Overhead
X-Edge
X-Amz-Server-Side-Encryption
Accept-Ch-Lifetime
X-MS-InvokeApp
X-B3-TraceId
X-Rack-Cache
Edge-Control
X-Ruxit-JS-Agent
X-Vname
X-PC
X-TtlSet
Accept-Ch
X-ESI
X-Content-Type
X-Vcap-Request-Id
Xkey
X-Mod-Pagespeed
X-Nginx-Upstream-Cache-Status
X-CST
X-Mcache
X-Oneagent-Js-Injection
X-D2id
X-VARITI-CCR
X-Amz-Rid
X-Kinja-Revision
X-Kinja-Server
X-Use-Magma
X-Kinja-Build
X-Kinja
X-Cdn-Fetch
X-Exp-Variant
X-Exp-Id
X-GoogleNews-Bot
Verso
X-GitHub-Request-Id
Cache-Tag
RTSS
X-FastCGI-Cache
X-Powered-By-Plesk
X-Varnish-TTL
X-Cached
Service-Worker-Allowed
X-ECACHE
X-Upstream
X-Navigation-Version
X-Client-IP
X-Ruxit-Js-Agent
X-Version
X-Abt-Application-Version
X-Dw-Request-Base-Id
X-Px
X-Cnection
X-Ac
Public-Key-Pins
Arr-Disable-Session-Affinity
X-Ser
X-Server-Lifecycle-Phase
X-Instrumentation
X-Kraken-Loop-Name
X-SharePointHealthScore
SPRequestGuid
Pagespeed
Display
X-Sol
X-Middleton-Display
X-Element-Page-Cache
X-Server-Name
X-Ttl
X-Country-Code
SPIisLatency
SPRequestDuration
X-Cache-TTL
X-NWS-LOG-UUID
X-NF-Request-ID
X-Midtier
Response
X-Middleton-Response
X-Goog-Hash
X-Kinsta-Cache
Permissions-Policy
X-Cache-Key
X-Edge-Location-Klb
X-RateLimit-Remaining
X-Forwarded-For
Access-Control-Request-Method
Content-MD5
X-DataDome
X-Shield-Request-Id
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
X-MSEdge-Ref
X-Powered-CMS
Front-End-Https
Edge-Cache-Tag
AR-Request-ID
AR-PoweredBy
AR-CACHE
TP-Cache
TP-L2-Cache
X-T
X-Recruiting
AR-ATIME
AR-SID
X-HP-Trace-Id
Nginx-Cache
X-HP-Webp
X-Jurisdiction
X-Accel-Expires
X-Correlation-Id
TCN
X-Daa-Tunnel
X-Grace
MicrosoftSharePointTeamServices
X-RateLimit-Limit
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
X-Id
X-Mg-S
X-Request-Received
X-Hits
X-TEC-API-ROOT
Filters
X-TEC-API-VERSION
X-Request-Processing-Time
X-TEC-API-ORIGIN
X-HS-Combine-CSS
X-HS-Cache-Config
X-HS-Hub-Id
X-HS-Content-Id
X-Content-Digest
Server-Node
X-Fastly-Request-Id
X-LLID
S
X-Frontend
Server-Name
X-Distributor
X-Amzn-Trace-Id
Cache-Status
X-Protected-By
X-TTL
MS-Author-Via
X-Geo-Country
Fastcgi-Cache
X-PressLabs-Stats
X-LB-Cache
X-Request-Handler-Origin-Region
X-Microsite
X-Language
Cross-Origin-Opener-Policy
X-Ab
X-Ua-Browser
X-Ezoic-Cdn
X-Forwarded-Proto
X-Origin-Server
X-F-Cache
X-B3-Sampled
Filterid
Charset
Host
X-FB-Debug
X-Seen-By
X-Git-Hash
X-Page-Id
X-Amz-Meta-S3cmd-Attrs
Realpath
Payment
Count-Hit
X-Ratelimit-Reset
X-Litespeed-Cache
X-ASPNET-VERSION
X-Cache-Age
X-Cluster-Name
X-Erf-Bev-Bev
X-VCache
X-Browser-Type
Accept-Charset
X-Erf-Bev-Bev-Is-Generated
X-DynaTrace
Surrogate-Key
X-Fastcgi-Cache
X-Origin-Cache
Cache-Tags
X-NGENIX-Cache
X-XRDS-Location
X-Rid
Alternate-Protocol
Cf-Apo-Via
X-Activity-Id
X-AppVersion
X-Az
Retry-After
Cleartype
X-Template
X-Webkit-Csp
X-Www-Served-By
Access-Control-Allow-Method
X-Webkit-CSP
X-Varnish-Backend
X-Content
X-Amz-Replication-Status
X-Type
X-Tb
X-Node-Name
X-TT
X-DIS-Request-ID
X-B-Cache
X-Aspnetmvc-Version
X-Upgrade-Enabled
X-Signature
ServerID
X-Debug
X-B
X-App-Environment
X-Wix-Request-Id
Paypal-Debug-Id
DC
X-Varnish-Grace
X-Logged-In
X-Request-Guid
X-Route-Name
X-Providence-Cookie
X-Is-Crawler
X-Aspnet-Duration-Ms
X-Drupal-Cache-Tags
X-Proxy
X-Flags
X-Tt-Trace-Tag
X-Tt-Trace-Host
Frame-Options
X-Hostname
X-Envoy-Decorator-Operation
X-Mobile
X-Source
X-Content-Options
X-Load-Cache
X-Revision
X-Goog-Metageneration
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-GUploader-UploadID
X-Goog-Storage-Class
X-Pinterest-Rid
Pinterest-Generated-By
X-Cache-Control
X-N
Pinterest-Version
X-Ratelimit-Remaining
Country
X-Contextid
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Magnolia-Registration
X-User-Agent
Referer-Policy
X-EdgeConnect-Cache-Status
Amp-Access-Control-Allow-Source-Origin
Viewport
X-Whom
X-XRDS-LOCATION
X-Cache-Rule
NGB
X-Original-Request-Id
X-Response-Served-From
Node
X-Restarts
X-Varnish-Age
Refresh
Content-Disposition
X-Debug-IsPreview
X-Debug-IsConnected
X-Framework
X-L-Path
X-Cache-TTL-Remaining
X-Mid
X-Environment-Context
Access-Control-Request-Headers
X-Unique-Id
X-Mg-Request-UUID
X-Varnish-Server
Akamai-GRN
X-Cacheable-TTL
X-Cache-Time
Uber-Trace-Id
VIX-Pulpo-Upstream-Status
X-Jobs
Url
X-G
VIX-Pulpo-Node
X-Adobe-Content
X-Akamai-Request-ID2
X-Adobe-Loc
X-Instance
X-Real-IP
X-NYM-Debug-Backend
X-Yottaa-Metrics
X-Servername
X-Cache-Grace
X-Yottaa-Optimizations
X-Is-Bot
X-Status
X-Rendered-As
X-Fastly-Request-ID
X-Page-View
X-Drupal-Cache-Contexts
Version
X-App-Server
Countrycode
X-Content-Powered-By
X-RemovedCookies
X-ProcessESI
X-Debug-Info
X-Server-ID
X-COUNTRY
X-Ratelimit-Limit
X-Http-Reason
X-APP-VERSION
Protected
X-Time
X-IPLB-Instance
X-IPLB-Request-ID
X-Tt-Logid
Srv
X-CDN-Forward
X-Hosted-By
Accept-Language
X-Cache-Expired-At
Liferay-Portal
Healthy
X-Nginx-Cache-Key
X-Via-JSL
X-Device-Type
X-Trace-Id
X-FW-Static
X-Tumblr-Pixel-0
X-FW-Type
X-FW-Server
X-FW-Dynamic
X-FW-Hash
X-FW-Serve
X-Cache-Hit
X-Tumblr-Pixel
X-Tumblr-User
X-Tumblr-Pixel-1
Fastcgi-Useragent
X-Azure-Ref
Ms-Operation-Id
X-RTag
MS-CV
Backend
X-Backend-Name
X-UUID
Section-Io-Cache
X-Cache-NGX
X-Mobile-URL
X-ECache
X-Correlation-ID
X-Proxy-Cache-Status
Server-Info
Content-Secure-Policy
X-Cache-Operation
X-Oracle-Dms-Ecid
X-Oracle-Dms-Rid
X-UPSTREAM-Address
X-Storage
X-RN-RSRV
Load-Balancing
Meta-Geo
X-HTML-Minification-Powered-By
CF-IPCountry
X-Mode
X-Varnish-Cache-Hits
Azure-Version
X-VC-Cache
X-Alternate-Cache-Key
X-Akamai-Edgescape
X-Section
X-Sorting-Hat-ShopId
Eomportal-Instance
TWC-Privacy
TWC-Connection-Speed
X-Storefront-Renderer-Rendered
X-OCL
X-Handled-By
WP-Super-Cache
X-Edge-Location
Webcakes-Region
X-Access
Webcakes-App-Name
Azure-SiteName
Onion-Location
Azure-RegionName
Azure-InstanceId
X-PHP-Host
Azure-SlotName
X-Format
X-VWS-Id
X-Skip-Cache
X-Varnishpool
X-LJ-Flow-ID
X-Sorting-Hat-PodId
X-Origin-Hint
Property-Id
X-Cache-Server
X-Varnish-Hostname
S-Rt
X-Locale
X-No-Session
X-PCL
X-Shopify-Stage
TWC-Device-Class
X-Forwarded-Host
X-Cache-Enabled
TWC-GeoIP-LatLong
X-Region
X-Labrador-Cache-Channel
X-PHP-Backend
TWC-Locale-Group
X-Server-W
X-Uri
TWC-GeoIP-Country
X-Origin-Date
X-Cache-Host
X-ShopId
X-ShardId
X-AWS-Id
Webcakes-App-Version
X-Content-Age
X-Zen-Fury
Web-Mar-Node
Locale
X-Adobe-Source
DB-Nickname
X-Via-Fastly
X-Proxied
X-BYPASS-REASON
X-Cms-Context
X-Proxy-Build
X-ProxyCache-Status
X-Routing-Service
X-SaId
X-ServerID
X-Zipkin-Id
Selected-Fe
X-Extlb
X-JoinUs
Mn-Server-Ip
X-Request-Time
X-ProxyCache-Key
X-Redis-Cache
X-Cache-Type
X-UA-Device-Type
X-Hl-Ver
X-Xfnlog-Site
X-GeoCountry
X-GeoCode
X-Debug-Cache
X-FB-TRIP-ID
X-Generation-Time
X-Urbn-Site-Id
Apigw-Requestid
X-SayCDN-TTL
X-Say-TTL
X-Say-Cacheable
X-Timing-Wait
X-Site-Version
GEO-INFO
X-Urbn-Context-Path
X-Sql-Duration-Ms
X-Sql-Count
X-Proto
X-Generated-By
X-Cache-Status-Check
X-Web-Node
X-Nginx-Cache
X-Datadome
X-Tid
CDN-PullZone
ServedBy
CDN-EdgeStorageId
CDN-RequestCountryCode
CDN-RequestId
X-Varnish-Beresp-Grace
CDN-CachedAt
CDN-Uid
X-URL
CDN-Cache
X-Detected-As
X-Rule
X-Cache-Action
X-SRV
X-LSADC-Cache
X-Ua
X-Dc
X-R9-Blue-Green-Version
X-DynaTrace-JS-Agent
X-Ms-Version
Cache-Name
X-Ms-Request-Id
Cache
X-FireWall-Port
X-Human
SD-X-WS
Xet-Cookie
Cross-Origin-Resource-Policy
X-Cache-Tags
Source
X-Amz-Apigw-Id
X-Varnish-Ttl
X-Amzn-RequestId
Xserver
X-App-Version
Cross-Origin-Window-Policy
X-Cached-By
LB
X-Varnish-Hits
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
X-RCS-CacheZone
X-Via-NSCOPI
WPO-Cache-Message
WPO-Cache-Status
X-GG-Cache-Date
X-MP-GENERATED-AT
Origin
X-GEO
X-Cdn
X-IPS-LoggedIn
X-Reqid
X-TNCMS
X-Loop
X-Pubstack
X-Origin-TTL
X-Origin-CC
X-NewRelic-App-Data
X-AOL-HN
X-Amzn-Remapped-Content-Length
X-Soup
Cache-Hits
X-Api-Version
X-B3-SpanId
X-Newrelic-Synthetics
X-TA-CDN-Provider
X-Tumblr-Pixel-2
X-FW-Version
From-Origin
Rip
X-Platform-Server
X-Service
X-Cluster-Node
Webserver
Upgrade-Insecure-Requests
X-Vgn-Hpd-Reason
X-Origin-Response-Time
HostName
X-Vdms-Path
Rendered-Blocks
X-NAPM-TraceId
X-Cluster
X-Cache-NE
X-BCube-Filmed-By
Cdnsip
Xc-Version
X-Developer
X-Destination
X-Ec-Fail
X-Ec-GeoHdr
X-Session-Fingerprint
X-External-Request-Id
A
X-Bc-Bl
X-ScT
Cdncip
X-VG-WebCache
X-Connection-Hash
X-D
BehaviorPad-Version
X-Vdms-Version
X-Tenant
X-A-Dam
X-A-Ccd
X-A
Host-ID
X-A-Dcw
X-SRCache-Key
X-A-Wwc
X-Processor
X-A-Dgt
Lang
MD5-Digest
Sslversion
X-Rojux
Surrogated-Key
X-S
T-Server
Odigeo-Trace-Id
Meta-Geo-Continent
Ngx.Var.Host
X-Rewrite-Enabled
DCR-Decision-By
X-Aed
X-S-Cookie
X-Shop-Environment
X-PBS-Appsvrname
X-Forwarded-Path
X-Served-From
DCR-Processing-Time-Ms
X-User
X-TIM-N
X-ARC
X-B-Cookie
X-Orig-Expires
X-CSRF-Token
Redirect-Candidate
X-AK-Request-ID
Expiry
X-Owner
Environment
X-Application
Fastly-SSL
X-VC
X-Request-Host
OT-Force-Account-Verify
X-Forwarded-Site
Decoy-Debug-TTL
Machine
Mobile-Detection-Method
X-Provided-By
Decoy-Debug-Status
X-Bip
Decoy-Debug-Key
Candidate-Md5Url
X-Accel-Buffering
X-Level-Front-Cache
X-Thanos
X-Irp-Debug
X-Qloud-Router
X-Pool
X-Generated-On
X-TIME
X-Rebelmouse-Cache-Control
X-Proxy-Cache-Info
Wxu-Next-Commit
X-RateLimit-Limit-Second
Wxu-Next-Hostname
X-RateLimit-Remaining-Second
X-SplitTest
Wxu-Next-Region
X-Ad-Defer-Variation
X-Origin-Time
X-Thinkindot-L3
X-Optimistic-Header
X-V-Cache
X-Variation
X-BBC-Edge-Cache-Status
X-SVT-ORM-VERSION
X-Auto-Login
We-Hiring
X-Parent-Response-Time
X-Origin-Expires
X-Origin
X-SVT-ORM-RULES
X-Policy
Vix-Hermes-Req-Id
Thinkindot-CacheControl
TDXMobile
X-Rocket-Build-Number
Thinkindot-CacheControl-Type
X-Request-URI
X-Rocket-Nginx-Serving-Static
State
Req-Svc-Chain
X-Sigma
Server-Host
Servername
X-S-Maxage
Thinkindot-Control
Traceparent
Tube-Return
X-SIPLIST1
X-Sn-Servicetimems
X-Nyt-Route
VNS-Age
Tube-Got-Results
X-Sigma-Backend
X-Region-Sid
X-Rebelmouse-Surrogate-Control
Tube-Get-Contents
Tube-Got-Eval
VNS-Cache
X-Branch-Name
X-INCAP-ABP
X-Esi-Check
X-Eu-Site
X-HS-Content-Campaign-Id
X-Hash
X-Epic-Correlation-Id
X-Loc
X-Developers
X-Dispatcher-Number
X-Device-Os
X-DPWN-IS-SECURE
X-Minions-Version
X-Gzip
X-GeoIP-City
X-Gateway-Skip-Cache
X-SB
X-Gateway-Request-Id
X-Gateway-Cache-Status
X-Gamma-Serve
X-Wix-Viewer-Type
X-Gdpr
X-Geo-Header
X-GeoIP
X-Fastly-Cache
X-Fetched-On
X-Fmm-Version
X-Scale
X-DefHash
X-Mvc-Supplant-Cachable
X-Varnish-Remaining-TTL
X-Cdn-Srv
X-VG-TLSProxy
X-CGP
X-Cdn-Origin
X-CacheTTL
X-Gateway-Cache-Key
X-Varnish-CookieINHashed-On
X-Cache-Id
X-Cache-Info
X-NodeID
X-Ckpd-Fst-Backend
X-Clara-WADP
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
X-Aicache-OS
X-Datadog-Trace-Id
X-DefElseHash
X-WADP-Cache
X-Csrf-Jwt
X-Viewer-Country
X-WA-Info
X-Core-Mission
X-Core-Value
X-Varnish-CookieHashed-On
V-Age
DSUID
Fastly-Backend-Name
Datacenter
CPC-Cache
CPC-Age
Fastly-GeoIP-CountryCode
Fastly-SIE
HA-Ipaddr
Is-Eu
Ha-Gx-Prefs
Gh-Request-Id
Fastly-SWR
Cmstype
Cmsid
Apple-News-Services-Handled
Apple-News-Services-Host
Adler-Geo
Release
X-Cache-Remote
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
Cluster
Click-Count-Error
Click-Count-Action-Start
Cache-Host
IsBot
Cache-Tv-Group
Kp-EeAlive
NM-Fastcgi-Cache
Origin-CC
NGX
Platform
Mail-Subject
Memcached
L5d-Success-Class
L
Producers
Origin-EX
X-NWS-UUID-VERIFY
X-Is-Gdpr
X-JWT-State
X-NCache
CloudFront-Viewer-Country
CDCHOST
X-Ec-Custom-Error
X-Cache-Bucket
Web-Mar-Region
X-Scheme
X-Clientip
X-Varnish-Beresp-Ttl
AKAMAI
X-Has-Esi
Svr
X-Slack-Backend
X-Planisys-CDN-TTL
X-ZONE
X-VServer
Fastcgi-Cache-TTL
X-Pod-Name
X-Worker
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
Country-Code
X-Mvc-Supplant-OutputCached
Mime-Version
X-Yandex-Sdch-Disable
WebServer
X-Xrds-Location
X-Gen-Mode
Server-Ext
X-Block-Status
Sever-Int
X-Hnp-Log
Server-Hostname
User-Cache-Control
Ec-Rule-Version
X-Udemy-Cache-App-Namespace
X-Varnish-Beresp-Status
X-Microcachable
X-Tec-Api-Root
X-Tec-Api-Origin
X-Ig-Push-State
X-Tec-Api-Version
Ssr
X-LB-NoCache
X-Cache-Date
X-Tx-Id
X-Tb-Optimization-Total-Bytes-Saved
Pics-Label
AMP-Access-Control-Allow-Source-Origin
Time
X-TRACE-ID
X-Conf
Canary
Memory
SID
Sid
X-CMSURLCustom
Fastly-Drupal-Html
X-Via-Popv
X-Sucuri-Cache
X-Sucuri-ID
X-Via-Popn
X-Via-Poph
X-Generated-In
X-ATG-Version
X-Fastly-Backend
X-WP-CF-Super-Cache-Active
X-FC-Vary-Parameters
X-Azure-Ref-OriginShield
X-Edge-Pop
X-ND-Cache
X-Refresh
X-Dmc
X-Cache-Debug
X-Var-Ttl
X-Be
X-B3-Traceid
X-Presslabs-Stats
X-Akamai-Transformed
X-Newrelic-App-Data
X-Air-Trace-Id
X-Air-Source
X-Servedbyhost
X-Air-Hostname
Server-ID
X-CS
X-MSEdge-Features
Env
X-MSEdge-Flight
X-Trace-ID
X-Cs
X-Buckets
X-Fpc
X-NC
X-Release
Fastly-Drupal-HTML
X-TX-ID
X-Wikidot-Static-Cache
X-Esi
X-Endurance-Cache-Level
X-Wikidot-Backend
X-EC-Lua
X-PX
X-Tumblr-Pixel-3
Magicmarker
X-ID
GeoIp-Country-Code
X-MCACHE
X-Srv
X-DC
CDN
X-CACHE-AGE
X-RateLimit-Reset
X-CF-Lambda-Fn
X-Up
X-CF-Lambda-Version
True-Client-IP
X-Zone
X-Hyper-Cache
X-Micro-Cache
X-Dispatch
X-Pass-Why
X-M-Reqid
Pramga
My-App
X-M-Log
X-NGINX-Cache
X-Varnish-Beresp-TTL
X-Webkit-CSP-Report-Only
X-VCL-Version
X-Wa
X-Lambda-Id
X-Alfa-Service
X-App
X-Qnm-Cache
C-Via
X-Vc
X-CACHE-KEY
N-Cache
X-TrackingId
X-Vcl-Version
X-CSRF-TOKEN
Hostname
X-Edge-Origin-Shield-Region
X-Edge-Origin-Shield-Bytes
Path
Fastcgi-X-Cache-Version
On-Server
X-Platform
X-PAYTM-SRV-ID
X-Req
Esi-Enabled
X-Air-Pt
X-Check-Cacheable
True-Client-Ip
Resin-Trace
X-AIR-PT
X-Vercel-Cache
X-Vtex-Processado-Em
X-LB-ID
X-TH-Server
X-Vercel-Id
X-Vtex-Remote-Cache
X-HS-Status
X-ApacheServer
CacheControlHeader
Tcn
X-PERF
GeoIP-Latitude
X-SD-PageType
X-Nf-Request-Id
True-Client-Country-4JS
X-B3-Spanid
GeoIP-Country-Code
Tracecode
X-Node-Id
X-SERVER-NAME
NtCoent-Length
HIT
X-FPC
Cache-Key
Proxy-Connection
X-Request-Start
X-API-Version
X-Op-Id-All
X-LAGOON
Cdn
X-Akamai-Pragma-Client-IP
DT-Hot-News
X-CLOUD-TRACE-CONTEXT
ENV
Hit
X-WA
XkeyRZ
X-Render-Time
X-Mly-Id
DynaTrace
Section-Io-Origin-Status
Section-Origin-Responded
Section-Io-Origin-Time-Seconds
X-Geo
Section-Io-Id
X-Proxy-CacheRZ
X-Cdn-Forward
X-Webkit-Csp-Report-Only
X-Platform-Cluster
X-Platform-Processor
X-Proxy-Upstream
X-VarnishDD-TTL
X-ServedByHost
X-Via-Ucdn
X-HN
X-GeoIP-Country-Code
X-Traceid
Lb
X-Platform-Router
Server-Id
X-GeoIP-Region-Code
X-Via-CDN
XM
PFcat
X-Dw-Trace-Id
X-Edge-POP
Server-Ttl
X-Lb-Id
X-Proxy-Cache-Hk
WWW-Authenticate
X-Datacenter
X-Date
X-Accel-Expires-Debug
User-Agent
MIME-Version
SRV
X-Via-PopH
YJS-ID
X-LiteSpeed-Cache-Control
X-Via-PopV
X-Via-PopN
X-RAMCache
X-RPS
Yjs-Id
Geoip-Latitude
X-Li-Fabric
Dnion-Transfer-Encoding
X-LI-Proto
X-Wp-Cf-Super-Cache-Cache-Control
X-RSL
X-Cache-Ttl
X-TT-LOGID
X-DW
X-LI-UUID
X-Li-Pop
X-DI
X-Wp-Cf-Super-Cache
FSS-Cache
X-Ftr-Request-Id
X-CF-Powered-By
PICS-Label
X-DSS
X-RPM
X-Cache-Backend
X-DB
X-CUA
X-FORWARDED-FOR
M-TraceId
X-LiteSpeed-Tag
Sm-Log-Id
X-Lb-Nocache
X-Old-Content-Length
X-Instance-Name
Location
Wpo-Cache-Message
Wpo-Cache-Status
X-Response-By
X-Service-Response-Time
X-Nc
XServer
Vha6-Origin
X-Akamai-Request-ID
Warning
X-HITS
X-Httpd
X-HA-Backend
X-Request-Url
X-Fastly-Backend-Reqs
Ohc-File-Size
Nginx-CQVIP
X-Akamai-ERRuleID
X-Akamai-ERPolicy
X-Litespeed-Cache-Control
X-UA
X-Fastly-Cache-Hits
X-Server-IP
X-Cc-Via
X-IN-APIGATEWAY
X-Mg-Cache
X-Cdn-Request-ID
X-B3-ParentSpanId
X-HostName
Powered-By
X-IN-APIGATEWAYSSL
Cdn-Requestid
Cdn-Uid
Cdn-Requestcountrycode
CountryCode
Cdn-Pullzone
X-Cache-Ngx
Cdn-Cachedat
Cdn-Cache
Cdn-Edgestorageid
Locid
X-MiniProfiler-Ids
Srvid
X-From
X-Webstats-RespID
X-Serial
X-FL-EDGE
X-DataCenter
WZWS-RAY
Fastcgi-Cache-Ttl
Ohc-Cache-HIT
X-Moov-Xdn-Version
Uri
X-Snapshot-Date
X-Moov-T
Req-ID