Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
Strict-Transport-Security
X-Frame-Options
X-Content-Type-Options
Last-Modified
Link
CF-Cache-Status
Cf-Request-Id
Accept-Ranges
ETag
CF-RAY
Expect-CT
Pragma
X-Powered-By
X-Cache
Via
X-XSS-Protection
Age
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Amz-Cf-Pop
X-Xss-Protection
X-Amz-Cf-Id
X-Cache-Hits
X-FRAME-OPTIONS
P3P
X-UA-Compatible
X-Served-By
X-Download-Options
X-Timer
X-Request-Id
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-Adblock-Key
X-AspNet-Version
X-Permitted-Cross-Domain-Policies
X-Runtime
Alt-Svc
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Check
X-DNS-Prefetch-Control
X-Cache-Status
CF-Ray
X-Generator
X-Cacheable
X-Iinfo
Timing-Allow-Origin
X-Envoy-Upstream-Service-Time
Feature-Policy
Status
X-Content-Security-Policy
X-Drupal-Dynamic-Cache
X-Request-ID
Content-Encoding
X-AspNetMvc-Version
Access-Control-Expose-Headers
X-CDN
Upgrade
X-XSS-PROTECTION
X-Ua-Compatible
Access-Control-Max-Age
X-Dns-Prefetch-Control
X-Via
X-Cache-Group
Server-Timing
X-Robots-Tag
X-UA-Device
Request-Context
Keep-Alive
X-AH-Environment
X-Amz-Request-Id
X-Turbo-Charged-By
X-Proxy-Cache
X-Backend
X-Amz-Id-2
X-Ws-Request-Id
P3p
X-Age
Host-Header
X-Server-Powered-By
X-Hacker
X-Server
X-Rq
X-Vhost
EagleId
X-Varnish-Cache
Grace
X-Amz-Version-Id
X-LiteSpeed-Cache
X-Dispatcher
X-Akamai-Path-Stats
Cf-Edge-Cache
Allow
X-Styx-Req-Id
X-Swift-SaveTime
X-Swift-CacheTime
X-Pantheon-Styx-Hostname
Ali-Swift-Global-Savetime
X-Device
X-Nginx-Cache-Status
X-Page-Speed
X-WebKit-CSP
X-Aws-Lambda-Call-Status
X-Host
X-Node
X-OneAgent-JS-Injection
X-Pingback
Accept-CH
X-Server-Id
EagleEye-TraceId
X-Cache-Spec
Request-Id
Cf-Railgun
Surrogate-Control
X-Akam-SW-Version
X-Backend-Server
X-Cache-Lookup
X-Response-Time
X-Readtime
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Accept-CH-Lifetime
X-HW
Content-Location
X-Content-Security-Policy-Report-Only
X-Application-Context
X-Trace
Rating
Fastly-Restarts
X-Cloud-Trace-Context
X-WebKit-CSP-Report-Only
X-Url
X-Clacks-Overhead
Accept-Ch-Lifetime
X-Country
X-Edge
X-MS-InvokeApp
X-Amz-Server-Side-Encryption
X-B3-TraceId
X-Rack-Cache
Edge-Control
X-Ruxit-JS-Agent
X-Vname
X-TtlSet
X-PC
X-Nginx-Upstream-Cache-Status
X-Content-Type
X-ESI
X-Vcap-Request-Id
X-Mod-Pagespeed
X-Varnish-TTL
X-FastCGI-Cache
Xkey
X-Kinja-Server
X-Use-Magma
X-Exp-Id
X-D2id
X-Kinja
X-Kinja-Revision
X-Kinja-Build
X-GoogleNews-Bot
X-Cdn-Fetch
X-Exp-Variant
X-Amz-Rid
Verso
X-Mcache
X-GitHub-Request-Id
Cache-Tag
X-VARITI-CCR
X-Powered-By-Plesk
RTSS
Service-Worker-Allowed
X-CST
X-ECACHE
X-Oneagent-Js-Injection
X-Upstream
X-Navigation-Version
X-Cached
X-Version
X-Client-IP
X-Abt-Application-Version
Accept-Ch
X-Dw-Request-Base-Id
X-Ruxit-Js-Agent
X-Cnection
X-Px
X-Ac
Public-Key-Pins
X-Kraken-Loop-Name
X-Instrumentation
SPRequestGuid
X-SharePointHealthScore
X-Element-Page-Cache
X-Server-Lifecycle-Phase
Arr-Disable-Session-Affinity
X-Server-Name
SPRequestDuration
SPIisLatency
X-Middleton-Display
X-Cache-TTL
X-Sol
Pagespeed
Display
X-Ser
X-NWS-LOG-UUID
X-Country-Code
X-Ttl
Permissions-Policy
X-RateLimit-Remaining
X-Midtier
X-Cache-Key
X-Middleton-Response
Response
X-Kinsta-Cache
X-Edge-Location-Klb
X-Goog-Hash
X-NF-Request-ID
X-Forwarded-For
Content-MD5
Access-Control-Request-Method
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-DataDome
Front-End-Https
X-Shield-Request-Id
X-MSEdge-Ref
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-Correlation-Id
X-T
X-Recruiting
X-HP-Webp
X-Jurisdiction
Nginx-Cache
X-HP-Trace-Id
Edge-Cache-Tag
TP-Cache
TP-L2-Cache
X-Accel-Expires
AR-SID
AR-CACHE
AR-PoweredBy
AR-ATIME
AR-Request-ID
X-Powered-CMS
X-Daa-Tunnel
MicrosoftSharePointTeamServices
X-RateLimit-Limit
Mrf-Cache-Status
X-B3-TraceId-Primal
MRF-Tech
TCN
X-Grace
X-Id
X-Hits
X-Mg-S
X-Content-Digest
X-Request-Processing-Time
X-Request-Received
Filters
Server-Node
X-HS-Combine-CSS
Cf-Apo-Via
X-HS-Content-Id
X-HS-Cache-Config
X-HS-Hub-Id
Server-Name
X-Amzn-Trace-Id
X-TEC-API-ORIGIN
X-Frontend
X-TEC-API-ROOT
X-TEC-API-VERSION
X-Webkit-Csp
S
X-LLID
X-Distributor
MS-Author-Via
X-Protected-By
X-Geo-Country
Fastcgi-Cache
X-Language
X-TTL
X-Fastly-Request-Id
Cache-Status
X-PressLabs-Stats
X-LB-Cache
X-Origin-Server
Cross-Origin-Opener-Policy
X-Ezoic-Cdn
X-Amz-Meta-S3cmd-Attrs
X-F-Cache
Charset
X-Request-Handler-Origin-Region
X-Forwarded-Proto
X-Microsite
X-FB-Debug
Host
X-B3-Sampled
X-XRDS-Location
X-Seen-By
Count-Hit
X-Page-Id
X-Ab
X-Browser-Type
X-Erf-Bev-Bev-Is-Generated
X-Ua-Browser
X-Git-Hash
X-Erf-Bev-Bev
Payment
Filterid
X-ASPNET-VERSION
X-Ratelimit-Reset
X-Cache-Age
X-Cluster-Name
X-VCache
Realpath
Surrogate-Key
Cache-Tags
Accept-Charset
X-Template
X-Rid
X-Origin-Cache
Alternate-Protocol
X-NGENIX-Cache
Retry-After
X-DynaTrace
X-AppVersion
X-Activity-Id
X-Www-Served-By
X-Az
X-Fastcgi-Cache
Access-Control-Allow-Method
Cleartype
X-Amz-Replication-Status
X-Varnish-Backend
X-Upgrade-Enabled
X-Providence-Cookie
X-Route-Name
X-Is-Crawler
X-Flags
X-DIS-Request-ID
X-Aspnet-Duration-Ms
X-TT
X-Request-Guid
X-Varnish-Grace
X-Type
X-Tb
X-B
X-Logged-In
X-Signature
X-B-Cache
X-Node-Name
X-Wix-Request-Id
X-App-Environment
DC
ServerID
Paypal-Debug-Id
X-Envoy-Decorator-Operation
X-Drupal-Cache-Tags
X-Debug
X-Proxy
X-Source
X-Hostname
Frame-Options
X-Content-Options
X-Revision
X-Mobile
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-COUNTRY
X-Content
X-Load-Cache
Pinterest-Generated-By
Pinterest-Version
X-Contextid
X-Pinterest-Rid
X-Fastly-Request-ID
Amp-Access-Control-Allow-Source-Origin
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-Cache-Rule
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-N
Country
X-Cache-Control
X-Magnolia-Registration
X-Litespeed-Cache
X-User-Agent
X-Whom
Node
Referer-Policy
Refresh
X-Original-Request-Id
X-Response-Served-From
X-EdgeConnect-Cache-Status
Viewport
NGB
X-Cacheable-TTL
Access-Control-Request-Headers
X-Debug-IsConnected
X-Debug-IsPreview
X-Environment-Context
X-L-Path
X-Cache-TTL-Remaining
X-Ratelimit-Remaining
Content-Disposition
X-G
X-Cache-Time
X-Jobs
X-NYM-Debug-Backend
X-Mid
X-Akamai-Request-ID2
X-Adobe-Content
Uber-Trace-Id
Url
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Adobe-Loc
X-Page-View
X-Varnish-Server
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Framework
X-Real-IP
X-Varnish-Age
X-Unique-Id
X-Servername
X-Status
X-Content-Powered-By
X-Rendered-As
Akamai-GRN
X-Instance
X-Is-Bot
X-Cache-Grace
X-Server-ID
Srv
X-RemovedCookies
X-ProcessESI
X-Mg-Request-UUID
Countrycode
X-Restarts
X-Drupal-Cache-Contexts
Version
X-APP-VERSION
X-App-Server
X-Trace-Id
X-Http-Reason
X-XRDS-LOCATION
X-CDN-Forward
Accept-Language
X-Debug-Info
X-Cache-Expired-At
Protected
X-IPLB-Request-ID
X-IPLB-Instance
X-Time
Healthy
X-Via-JSL
X-Hosted-By
X-Nginx-Cache-Key
X-Tumblr-Pixel-0
X-Tumblr-User
X-Cache-Hit
X-Ratelimit-Limit
X-Tumblr-Pixel
X-Tumblr-Pixel-1
X-Cache-Operation
X-Azure-Ref
X-Device-Type
Liferay-Portal
X-FW-Dynamic
X-Backend-Name
X-FW-Hash
Section-Io-Cache
X-Tt-Logid
X-FW-Static
X-FW-Server
X-FW-Serve
X-FW-Type
Fastcgi-Useragent
X-Oracle-Dms-Ecid
X-Oracle-Dms-Rid
Server-Info
Ms-Operation-Id
MS-CV
Content-Secure-Policy
Backend
X-RTag
X-Cache-NGX
Cross-Origin-Resource-Policy
X-Proxy-Cache-Status
X-Akamai-Edgescape
X-UPSTREAM-Address
X-UUID
X-RN-RSRV
Meta-Geo
X-Storage
Load-Balancing
X-Mobile-URL
X-Mode
CF-IPCountry
X-Content-Age
X-Cache-Action
GEO-INFO
X-Handled-By
X-Storefront-Renderer-Rendered
Property-Id
X-Varnish-Beresp-Grace
TWC-Connection-Speed
TWC-Device-Class
X-Site-Version
X-Urbn-Site-Id
S-Rt
X-Region
X-Urbn-Context-Path
X-ShopId
X-Proto
Locale
Eomportal-Instance
X-Shopify-Stage
X-VC-Cache
X-Format
X-AWS-Id
X-No-Session
Onion-Location
TWC-GeoIP-Country
X-OCL
X-Origin-Date
X-Sql-Duration-Ms
X-Edge-Location
X-Cms-Context
Webcakes-Region
X-Origin-Hint
X-Locale
X-Sql-Count
X-Varnishpool
X-VWS-Id
X-Sorting-Hat-ShopId
TWC-Privacy
X-Server-W
Webcakes-App-Name
X-Section
X-PCL
X-LJ-Flow-ID
TWC-Locale-Group
X-Forwarded-Host
X-Say-Cacheable
X-Varnish-Cache-Hits
X-Sorting-Hat-PodId
X-Adobe-Source
X-Skip-Cache
X-ShardId
X-Cache-Server
X-Access
X-SayCDN-TTL
TWC-GeoIP-LatLong
X-PHP-Backend
X-Varnish-Hostname
X-Say-TTL
X-Alternate-Cache-Key
Webcakes-App-Version
X-URL
X-Rule
X-Hl-Ver
X-GeoCountry
X-GeoCode
X-Generation-Time
X-HTML-Minification-Powered-By
X-Uri
X-PHP-Host
X-Redis-Cache
X-Generated-By
X-Labrador-Cache-Channel
X-Extlb
Azure-SlotName
X-Cache-Type
Azure-Version
X-Cache-Host
Azure-SiteName
Azure-RegionName
X-Proxied
X-Detected-As
X-Via-Fastly
X-FB-TRIP-ID
X-ProxyCache-Key
CDN-Cache
CDN-CachedAt
CDN-EdgeStorageId
X-Datadome
X-Timing-Wait
X-UA-Device-Type
X-Web-Node
X-Xfnlog-Site
X-Zipkin-Id
CDN-PullZone
CDN-RequestCountryCode
X-Cache-Enabled
X-ProxyCache-Status
X-BYPASS-REASON
X-Request-Time
X-Routing-Service
CDN-RequestId
X-ServerID
CDN-Uid
X-Proxy-Build
Azure-InstanceId
DB-Nickname
Mn-Server-Ip
Selected-Fe
Web-Mar-Node
Apigw-Requestid
X-Tid
X-Cache-Status-Check
X-SRV
WP-Super-Cache
X-Correlation-ID
X-R9-Blue-Green-Version
X-Zen-Fury
X-Ms-Request-Id
X-SaId
X-Ms-Version
X-JoinUs
X-ECache
Cache-Name
X-FireWall-Port
ServedBy
X-Ua
X-Api-Version
X-DynaTrace-JS-Agent
X-LSADC-Cache
X-Dc
X-Nginx-Cache
X-WP-CF-Super-Cache-Cache-Control
X-Debug-Cache
X-WP-CF-Super-Cache
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Human
Xet-Cookie
X-Cache-Tags
Xserver
Cache
Source
X-TA-CDN-Provider
X-Loop
SD-X-WS
X-Aspnetmvc-Version
X-TNCMS
X-Cached-By
X-RCS-CacheZone
X-MP-GENERATED-AT
X-GEO
X-Varnish-Hits
Cross-Origin-Window-Policy
X-Reqid
X-Cdn
Origin
X-Webkit-CSP
X-Amzn-Remapped-Content-Length
WPO-Cache-Message
LB
X-Pubstack
WPO-Cache-Status
X-Soup
X-NewRelic-App-Data
X-App-Version
X-Origin-TTL
X-Origin-CC
X-Tumblr-Pixel-2
X-Service
X-Via-NSCOPI
From-Origin
X-IPS-LoggedIn
X-Vgn-Hpd-Reason
X-AOL-HN
X-B3-SpanId
X-Provided-By
X-Newrelic-Synthetics
X-Varnish-Beresp-Ttl
X-GG-Cache-Date
X-TIME
X-Tec-Api-Version
X-Tec-Api-Origin
X-Tec-Api-Root
X-FW-Version
Rip
X-Platform-Server
X-Cluster-Node
X-Request-Host
Cache-Hits
X-Ec-Fail
X-Ec-GeoHdr
X-Forwarded-Path
X-Developer
X-Orig-Expires
X-PBS-Appsvrname
X-NAPM-TraceId
X-Owner
X-Destination
A
X-External-Request-Id
X-Served-From
Host-ID
X-User
X-A-Wwc
X-A-Dgt
X-A-Dcw
T-Server
X-TIM-N
Surrogated-Key
X-Tenant
BehaviorPad-Version
X-Aed
X-A-Dam
X-Vdms-Path
Meta-Geo-Continent
MD5-Digest
Xc-Version
Odigeo-Trace-Id
Ngx.Var.Host
X-A
Lang
X-Vdms-Version
Webserver
X-A-Ccd
X-VG-WebCache
Sslversion
X-AK-Request-ID
DCR-Decision-By
X-Connection-Hash
X-Rojux
X-S
X-S-Cookie
X-Rewrite-Enabled
Cdnsip
X-D
X-Processor
Rendered-Blocks
Cdncip
DCR-Processing-Time-Ms
X-Cache-NE
X-B-Cookie
X-Bc-Bl
X-ARC
X-SRCache-Key
X-Application
Environment
Expiry
X-Shop-Environment
X-BCube-Filmed-By
X-ScT
Upgrade-Insecure-Requests
OT-Force-Account-Verify
X-Generated-On
X-Accel-Buffering
Redirect-Candidate
X-Aicache-OS
X-Bip
X-Qloud-Router
X-Dispatcher-Number
X-Level-Front-Cache
Cache-Tv-Group
X-Thanos
X-Pool
X-WA-Info
Mime-Version
X-Cluster
Fastly-SSL
X-Ad-Defer-Variation
X-SVT-ORM-RULES
X-Thinkindot-L3
X-V-Cache
X-SVT-ORM-VERSION
X-Variation
X-VG-TLSProxy
X-Varnish-Remaining-TTL
X-Varnish-CookieINHashed-On
X-Varnish-CookieHashed-On
X-SplitTest
X-Auto-Login
X-Branch-Name
X-Scale
X-SB
X-CacheTTL
X-S-Maxage
X-Sigma
X-Sigma-Backend
X-Sn-Servicetimems
X-BBC-Edge-Cache-Status
X-Slack-Backend
X-SIPLIST1
X-VServer
Wxu-Next-Region
X-Varnish-Beresp-Status
CPC-Age
TDXMobile
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
State
CPC-Cache
VNS-Cache
Server-Host
VNS-Age
Servername
Thinkindot-Control
Traceparent
X-Worker
V-Age
Wxu-Next-Commit
Wxu-Next-Hostname
X-Rocket-Nginx-Serving-Static
Tube-Return
Tube-Got-Results
X-Parent-Response-Time
Tube-Get-Contents
Machine
Tube-Got-Eval
X-Wix-Viewer-Type
X-Cdn-Origin
X-Forwarded-Site
X-NodeID
X-Gamma-Serve
X-Gateway-Cache-Key
X-Gateway-Cache-Status
X-Fetched-On
X-Nyt-Route
X-Origin
X-Origin-Expires
X-Optimistic-Header
X-Epic-Correlation-Id
X-Eu-Site
X-Gateway-Request-Id
X-Minions-Version
X-GeoIP-City
X-GeoIP
X-Irp-Debug
X-INCAP-ABP
X-Hash
X-Is-Gdpr
X-Geo-Header
X-Gateway-Skip-Cache
X-Gdpr
X-Loc
X-JWT-State
X-Ec-Custom-Error
X-Origin-Response-Time
X-Request-URI
X-Core-Value
X-Region-Sid
X-Csrf-Jwt
X-Policy
X-Core-Mission
X-Rocket-Build-Number
X-Cdn-Srv
X-CGP
X-Ckpd-Fst-Backend
X-Clientip
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
X-Device-Os
X-Developers
X-Planisys-CDN-Cache
X-Origin-Time
X-DPWN-IS-SECURE
Req-Svc-Chain
X-Planisys-CDN-Rules
X-Datadog-Trace-Id
X-Planisys-CDN-TTL
X-DefElseHash
X-DefHash
X-Has-Esi
Vix-Hermes-Req-Id
Cache-Host
Apple-News-Services-Request-Url
L5d-Success-Class
L
Memcached
DSUID
Apple-News-Services-Parsed-Url
Candidate-Md5Url
Decoy-Debug-TTL
Kp-EeAlive
IsBot
Adler-Geo
Fastly-SWR
Apple-News-Services-Handled
Apple-News-Services-Host
Gh-Request-Id
Ha-Gx-Prefs
Is-Eu
Fastly-SIE
HA-Ipaddr
Decoy-Debug-Status
Mobile-Detection-Method
NGX
Click-Count-Error
Cmstype
Platform
Producers
HostName
Country-Code
X-CSRF-Token
NM-Fastcgi-Cache
Release
Decoy-Debug-Key
Cmsid
Origin-EX
Click-Count-Action-Start
Origin-CC
X-Xrds-Location
X-VC
WebServer
X-Tx-Id
CDCHOST
X-Mvc-Supplant-OutputCached
X-Mvc-Supplant-Cachable
CloudFront-Viewer-Country
X-Gzip
Fastly-Backend-Name
Fastly-GeoIP-CountryCode
X-Cache-Bucket
X-Gen-Mode
Canary
X-Viewer-Country
X-Hnp-Log
X-Session-Fingerprint
X-Cache-Id
X-Cache-Info
X-Fmm-Version
Cluster
X-HS-Content-Campaign-Id
Server-Ext
X-Esi-Check
X-Clara-WADP
X-CMSURLCustom
AKAMAI
Datacenter
Svr
User-Cache-Control
Sever-Int
X-Rebelmouse-Surrogate-Control
We-Hiring
X-NCache
Mail-Subject
Web-Mar-Region
X-Proxy-Cache-Info
Server-Hostname
X-WADP-Cache
X-Rebelmouse-Cache-Control
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-Scheme
X-Block-Status
Fastcgi-Cache-TTL
X-Cache-Remote
Ec-Rule-Version
X-Varnish-Ttl
X-Cache-Debug
X-LB-NoCache
X-Fastly-Cache
X-WP-CF-Super-Cache-Active
X-ND-Cache
Sid
X-Pod-Name
X-Udemy-Cache-App-Namespace
X-NWS-UUID-VERIFY
Ssr
X-ZONE
Pics-Label
X-Sucuri-Cache
X-Sucuri-ID
Memory
X-Var-Ttl
X-ATG-Version
X-Fastly-Backend
X-FC-Vary-Parameters
X-Azure-Ref-OriginShield
Time
X-Tb-Optimization-Total-Bytes-Saved
SID
Fastly-Drupal-HTML
X-Buckets
X-Generated-In
X-Ig-Push-State
X-Cache-Date
AMP-Access-Control-Allow-Source-Origin
X-B3-Traceid
X-Presslabs-Stats
X-Via-Poph
X-Newrelic-App-Data
X-Conf
X-Via-Popn
X-Refresh
Server-ID
X-Edge-Pop
X-Akamai-Transformed
X-Via-Popv
X-Servedbyhost
X-Microcachable
X-Cs
X-Release
Env
X-Trace-ID
X-Nf-Request-Id
X-Dmc
Fastly-Drupal-Html
X-NC
X-MSEdge-Features
X-Fpc
X-MSEdge-Flight
X-Up
X-TRACE-ID
X-Esi
X-Pass-Why
X-Be
X-PX
X-Wa
Magicmarker
X-ID
My-App
X-Dispatch
GeoIp-Country-Code
X-MCACHE
X-Zone
X-Endurance-Cache-Level
X-Tumblr-Pixel-3
X-DC
X-EC-Lua
X-NGINX-Cache
CDN
X-Yandex-Sdch-Disable
X-Lambda-Id
True-Client-IP
X-CACHE-AGE
X-CS
X-RateLimit-Reset
X-Air-Trace-Id
X-Air-Source
X-Air-Hostname
X-Vc
X-Wikidot-Backend
X-VCL-Version
X-TX-ID
X-Wikidot-Static-Cache
Hostname
X-CSRF-TOKEN
X-Webkit-CSP-Report-Only
X-Req
X-Srv
X-Hyper-Cache
X-CACHE-KEY
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-M-Log
X-M-Reqid
CacheControlHeader
Pramga
X-Micro-Cache
X-App
X-Alfa-Service
X-HS-Status
X-TH-Server
True-Client-Country-4JS
X-Air-Pt
C-Via
X-Qnm-Cache
Resin-Trace
X-LB-ID
True-Client-Ip
Path
N-Cache
X-Varnish-Beresp-TTL
Tcn
X-TrackingId
X-Op-Id-All
X-Vcl-Version
X-PAYTM-SRV-ID
On-Server
Tracecode
X-Platform
GeoIP-Country-Code
X-B3-Spanid
X-Vercel-Cache
Fastcgi-X-Cache-Version
X-Vercel-Id
X-Edge-Origin-Shield-Region
X-SERVER-NAME
X-Check-Cacheable
Esi-Enabled
X-Edge-Origin-Shield-Bytes
X-CLOUD-TRACE-CONTEXT
NtCoent-Length
Hit
X-Vtex-Processado-Em
X-GeoIP-Country-Code
X-Akamai-Pragma-Client-IP
Section-Io-Origin-Time-Seconds
X-Datacenter
GeoIP-Latitude
Section-Io-Id
Proxy-Connection
X-FPC
Section-Io-Origin-Status
Section-Origin-Responded
X-GeoIP-Region-Code
X-Vtex-Remote-Cache
X-Webkit-Csp-Report-Only
X-Date
WWW-Authenticate
X-Via-CDN
X-Platform-Router
X-Mly-Id
X-Lb-Id
X-Request-Start
X-Platform-Cluster
X-WA
X-API-Version
X-Accel-Expires-Debug
X-Platform-Processor
X-AIR-PT
X-LAGOON
X-SD-PageType
X-Geo
X-Node-Id
Yjs-Id
X-ApacheServer
X-PERF
X-RAMCache
X-Via-PopN
ENV
X-Via-PopV
Server-Id
YJS-ID
User-Agent
X-ServedByHost
Lb
X-Via-PopH
HIT
X-Edge-POP
Cache-Key
Cdn
X-Dw-Trace-Id
X-Cdn-Forward
X-Instance-Name
XkeyRZ
Server-Ttl
DynaTrace
FSS-Cache
X-Old-Content-Length
X-Response-By
X-Proxy-CacheRZ
X-Render-Time
XServer
DT-Hot-News
X-Proxy-Cache-Hk
X-Proxy-Upstream
X-Traceid
X-VarnishDD-TTL
X-Cache-Ttl
X-FORWARDED-FOR
X-Via-Ucdn
X-HN
XM
X-Li-Pop
X-LI-Proto
X-LI-UUID
X-Li-Fabric
Dnion-Transfer-Encoding
X-CUA
X-TT-LOGID
Powered-By
PFcat
Geoip-Latitude
X-LiteSpeed-Cache-Control
Sm-Log-Id
X-Service-Response-Time
X-FL-EDGE
Ohc-File-Size
X-Akamai-ERPolicy
X-DW
Srvid
X-DSS
X-Fastly-Backend-Reqs
X-DB
X-CF-Powered-By
X-DI
X-RPM
Locid
X-Akamai-ERRuleID
X-From
Location
X-Location
Nginx-CQVIP
X-RSL
X-RPS
X-LiteSpeed-Tag
PICS-Label
X-Wp-Cf-Super-Cache-Cache-Control
X-UA
X-Litespeed-Cache-Control
X-Wp-Cf-Super-Cache
X-Webstats-RespID
Vha6-Origin
X-Fastly-Cache-Hits
X-HostName
X-B3-ParentSpanId
X-Cdn-Request-ID
Wpo-Cache-Message
Wpo-Cache-Status
X-Lb-Nocache
X-Request-Url
Warning
Wp-Super-Cache
CountryCode
X-Ips-Loggedin
X-Cache-Ngx
X-Cache-Backend
X-Cache-ASPX
X-Contensis-Viewer-Groups
X-Director
X-DataCenter
X-Varnish-Authentication
M-TraceId
X-Mg-Cache
Req-ID
Fastcgi-Cache-Ttl
X-Nc
X-Snapshot-Date
WZWS-RAY
X-Moov-Xdn-Version
SRV
X-Ftr-Request-Id
X-Moov-T
MIME-Version