Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
Strict-Transport-Security
X-Frame-Options
X-Content-Type-Options
Last-Modified
Link
CF-Cache-Status
Cf-Request-Id
Accept-Ranges
ETag
CF-RAY
Expect-CT
Pragma
X-Powered-By
X-Cache
X-XSS-Protection
Via
Age
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Xss-Protection
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-FRAME-OPTIONS
X-Download-Options
X-Timer
X-Request-Id
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
X-AspNet-Version
X-Runtime
Alt-Svc
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Check
X-DNS-Prefetch-Control
X-Cache-Status
X-Generator
CF-Ray
X-Cacheable
Timing-Allow-Origin
X-Iinfo
X-Envoy-Upstream-Service-Time
Feature-Policy
P3p
Status
X-Content-Security-Policy
X-Drupal-Dynamic-Cache
Content-Encoding
X-Request-ID
X-CDN
Access-Control-Expose-Headers
X-AspNetMvc-Version
Upgrade
X-XSS-PROTECTION
Access-Control-Max-Age
X-Ua-Compatible
X-Via
X-Dns-Prefetch-Control
Server-Timing
X-Cache-Group
X-Robots-Tag
X-UA-Device
Request-Context
Keep-Alive
X-AH-Environment
X-Amz-Request-Id
X-Turbo-Charged-By
X-Backend
X-Proxy-Cache
X-Amz-Id-2
X-Ws-Request-Id
X-Age
Host-Header
X-Server-Powered-By
X-Hacker
X-Server
X-Rq
X-Akamai-Path-Stats
EagleId
X-Vhost
X-Varnish-Cache
Grace
X-Amz-Version-Id
X-Dispatcher
X-LiteSpeed-Cache
Cf-Edge-Cache
Allow
X-Swift-SaveTime
X-Swift-CacheTime
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
Ali-Swift-Global-Savetime
X-Nginx-Cache-Status
X-Device
X-Page-Speed
X-WebKit-CSP
X-Aws-Lambda-Call-Status
X-Host
X-OneAgent-JS-Injection
X-Node
X-Server-Id
EagleEye-TraceId
X-Pingback
X-Cache-Spec
Request-Id
Surrogate-Control
Cf-Railgun
Accept-CH
X-Akam-SW-Version
X-Backend-Server
X-Readtime
X-Cache-Lookup
X-Response-Time
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-HW
Accept-CH-Lifetime
Content-Location
X-Content-Security-Policy-Report-Only
X-Application-Context
Rating
X-Trace
Fastly-Restarts
X-Cloud-Trace-Context
X-Country
Accept-Ch-Lifetime
X-WebKit-CSP-Report-Only
X-Clacks-Overhead
X-Url
X-Edge
X-Amz-Server-Side-Encryption
X-Ruxit-JS-Agent
X-MS-InvokeApp
X-B3-TraceId
X-Rack-Cache
Edge-Control
X-Vname
X-PC
X-TtlSet
Accept-Ch
X-Content-Type
X-ESI
X-Nginx-Upstream-Cache-Status
X-Vcap-Request-Id
X-Mod-Pagespeed
Xkey
X-FastCGI-Cache
X-Varnish-TTL
X-Kinja
X-Exp-Id
X-Cdn-Fetch
X-GoogleNews-Bot
X-Exp-Variant
X-D2id
X-Kinja-Revision
X-Kinja-Build
X-Use-Magma
X-Kinja-Server
X-Mcache
X-Amz-Rid
X-CST
X-VARITI-CCR
Verso
X-GitHub-Request-Id
Cache-Tag
RTSS
X-Powered-By-Plesk
Service-Worker-Allowed
X-Cached
X-Upstream
X-Client-IP
X-Navigation-Version
X-ECACHE
X-Abt-Application-Version
X-Version
X-ASPNET-VERSION
X-Oneagent-Js-Injection
X-Dw-Request-Base-Id
X-Px
X-Cnection
X-Ac
X-Ruxit-Js-Agent
Public-Key-Pins
X-Kraken-Loop-Name
Arr-Disable-Session-Affinity
X-Instrumentation
X-Server-Lifecycle-Phase
X-Ser
SPRequestGuid
X-Element-Page-Cache
X-SharePointHealthScore
X-Sol
Display
X-Middleton-Display
Pagespeed
X-Server-Name
X-Cache-TTL
SPIisLatency
SPRequestDuration
X-Country-Code
X-NWS-LOG-UUID
X-Midtier
X-Ttl
Permissions-Policy
X-NF-Request-ID
X-Middleton-Response
Response
X-Edge-Location-Klb
X-Kinsta-Cache
X-Goog-Hash
X-Cache-Key
X-Forwarded-For
X-RateLimit-Remaining
Content-MD5
Access-Control-Request-Method
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Shield-Request-Id
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-DataDome
X-MSEdge-Ref
Front-End-Https
X-Powered-CMS
TP-L2-Cache
TP-Cache
X-Recruiting
X-T
Edge-Cache-Tag
AR-SID
AR-Request-ID
AR-PoweredBy
AR-ATIME
Nginx-Cache
X-HP-Webp
AR-CACHE
X-Jurisdiction
X-HP-Trace-Id
X-Accel-Expires
X-Daa-Tunnel
TCN
MicrosoftSharePointTeamServices
X-Grace
MRF-Tech
X-B3-TraceId-Primal
Mrf-Cache-Status
X-Correlation-Id
X-Mg-S
X-Id
X-RateLimit-Limit
X-Hits
X-Content-Digest
X-TTL
X-Request-Received
Filters
X-Request-Processing-Time
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-TEC-API-ROOT
Server-Node
X-HS-Cache-Config
X-HS-Content-Id
X-HS-Combine-CSS
X-HS-Hub-Id
Server-Name
X-LLID
S
X-Amzn-Trace-Id
X-Frontend
X-Distributor
X-Language
MS-Author-Via
X-Protected-By
X-Fastly-Request-Id
X-Geo-Country
Cache-Status
X-PressLabs-Stats
Fastcgi-Cache
X-LB-Cache
X-Microsite
X-Request-Handler-Origin-Region
Cross-Origin-Opener-Policy
Cf-Apo-Via
X-Ezoic-Cdn
X-F-Cache
X-FB-Debug
X-Forwarded-Proto
Filterid
Charset
X-Page-Id
X-Git-Hash
Host
X-Origin-Server
X-Seen-By
X-Ab
X-Ua-Browser
X-Amz-Meta-S3cmd-Attrs
X-B3-Sampled
Count-Hit
X-Ratelimit-Reset
Payment
Realpath
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Browser-Type
X-Litespeed-Cache
X-Cache-Age
X-Cluster-Name
X-Template
X-VCache
Accept-Charset
X-Origin-Cache
Surrogate-Key
Alternate-Protocol
X-XRDS-Location
X-NGENIX-Cache
X-Rid
Cache-Tags
X-DynaTrace
Retry-After
X-Az
X-Activity-Id
X-AppVersion
Cleartype
X-Www-Served-By
X-Webkit-Csp
Access-Control-Allow-Method
X-Varnish-Backend
X-Amz-Replication-Status
X-B-Cache
X-Route-Name
X-Request-Guid
X-Signature
X-TT
X-Type
X-Providence-Cookie
X-Is-Crawler
X-Node-Name
X-Aspnet-Duration-Ms
X-Varnish-Grace
X-Flags
X-Upgrade-Enabled
X-App-Environment
ServerID
X-Fastcgi-Cache
X-DIS-Request-ID
X-Tb
X-Wix-Request-Id
X-Debug
Paypal-Debug-Id
DC
X-B
X-Logged-In
X-Drupal-Cache-Tags
X-Proxy
X-Ratelimit-Remaining
X-Content
Frame-Options
X-Envoy-Decorator-Operation
X-Source
X-Aspnetmvc-Version
X-Hostname
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Content-Options
X-Mobile
X-Revision
X-Load-Cache
X-Pinterest-Rid
Pinterest-Generated-By
Pinterest-Version
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Goog-Metageneration
X-Goog-Generation
X-Goog-Stored-Content-Length
X-Contextid
X-GUploader-UploadID
X-Cache-Control
Country
X-N
X-Kong-Proxy-Latency
X-Magnolia-Registration
X-Kong-Upstream-Latency
X-Cache-Rule
X-Fastly-Request-ID
Referer-Policy
Amp-Access-Control-Allow-Source-Origin
X-User-Agent
X-Whom
X-EdgeConnect-Cache-Status
Viewport
NGB
X-Response-Served-From
Refresh
X-Original-Request-Id
Node
X-Varnish-Age
X-Ratelimit-Limit
Content-Disposition
X-Framework
Access-Control-Request-Headers
X-Cacheable-TTL
X-Debug-IsConnected
X-Debug-IsPreview
X-Restarts
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Jobs
VIX-Pulpo-Node
Akamai-GRN
X-Cache-TTL-Remaining
VIX-Pulpo-Upstream-Status
X-Cache-Time
X-Akamai-Request-ID2
X-Adobe-Loc
X-Adobe-Content
X-Environment-Context
X-G
X-Mid
X-NYM-Debug-Backend
X-Page-View
X-Mg-Request-UUID
X-L-Path
X-Instance
X-Cache-Grace
X-Real-IP
Uber-Trace-Id
X-Varnish-Server
X-Rendered-As
X-Is-Bot
Url
X-Status
X-Servername
X-Drupal-Cache-Contexts
X-Unique-Id
X-XRDS-LOCATION
Countrycode
X-Content-Powered-By
X-RemovedCookies
X-ProcessESI
Version
X-App-Server
X-Server-ID
X-Debug-Info
X-Webkit-CSP
X-COUNTRY
X-Http-Reason
X-APP-VERSION
Srv
X-Time
Protected
X-IPLB-Request-ID
X-IPLB-Instance
Accept-Language
X-Hosted-By
X-CDN-Forward
X-Correlation-ID
X-Via-JSL
Healthy
X-Cache-Expired-At
X-URL
Liferay-Portal
Fastcgi-Useragent
X-Tt-Logid
X-Device-Type
X-Cache-Hit
X-Tumblr-User
X-Nginx-Cache-Key
X-Trace-Id
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-FW-Server
X-FW-Static
X-FW-Serve
X-FW-Dynamic
X-FW-Type
X-FW-Hash
X-Azure-Ref
Section-Io-Cache
X-Backend-Name
X-Datadome
Backend
X-Cache-Operation
Ms-Operation-Id
X-Proxy-Cache-Status
X-RTag
Content-Secure-Policy
X-UUID
MS-CV
X-Mobile-URL
X-ECache
X-Cache-NGX
X-Oracle-Dms-Ecid
Server-Info
X-Oracle-Dms-Rid
X-RN-RSRV
X-Storage
Meta-Geo
Load-Balancing
X-UPSTREAM-Address
X-Akamai-Edgescape
X-Handled-By
CF-IPCountry
X-Cache-Host
X-Proto
Eomportal-Instance
X-Urbn-Context-Path
X-Varnish-Cache-Hits
X-Cache-Server
X-Cache-Enabled
X-Cms-Context
X-Varnish-Hostname
GEO-INFO
X-Varnishpool
X-Site-Version
Locale
S-Rt
X-Edge-Location
CDN-Uid
CDN-RequestId
Azure-SlotName
Azure-SiteName
Azure-RegionName
Azure-Version
Web-Mar-Node
CDN-CachedAt
CDN-Cache
Azure-InstanceId
WP-Super-Cache
X-Alternate-Cache-Key
CDN-RequestCountryCode
CDN-PullZone
X-Adobe-Source
X-Format
X-Access
CDN-EdgeStorageId
X-Content-Age
X-ShopId
X-OCL
X-Sql-Count
X-ShardId
X-Section
X-Say-TTL
X-Origin-Date
X-SayCDN-TTL
X-Sorting-Hat-ShopId
X-Region
X-Labrador-Cache-Channel
X-Skip-Cache
Onion-Location
X-Locale
X-Shopify-Stage
X-No-Session
X-Sorting-Hat-PodId
X-HTML-Minification-Powered-By
X-Redis-Cache
X-Urbn-Site-Id
X-Storefront-Renderer-Rendered
X-PHP-Host
X-Say-Cacheable
X-Sql-Duration-Ms
X-Forwarded-Host
X-PCL
X-PHP-Backend
X-VC-Cache
X-Generated-By
X-LJ-Flow-ID
X-ProxyCache-Status
TWC-GeoIP-LatLong
X-JoinUs
X-Web-Node
X-Hl-Ver
Property-Id
X-FB-TRIP-ID
Selected-Fe
TWC-Device-Class
X-Generation-Time
X-SaId
TWC-GeoIP-Country
TWC-Privacy
X-Timing-Wait
X-Server-W
X-ProxyCache-Key
X-Proxy-Build
X-AWS-Id
X-Origin-Hint
X-BYPASS-REASON
X-Uri
Webcakes-Region
Webcakes-App-Version
X-GeoCode
X-Debug-Cache
X-GeoCountry
X-Via-Fastly
X-VWS-Id
Webcakes-App-Name
X-ServerID
TWC-Locale-Group
TWC-Connection-Speed
Apigw-Requestid
DB-Nickname
X-Cache-Type
X-Cache-Action
X-Nginx-Cache
X-Mode
X-Detected-As
X-Varnish-Beresp-Grace
X-Request-Time
X-Rule
X-Cache-Status-Check
Mn-Server-Ip
X-UA-Device-Type
X-Tid
X-Zen-Fury
X-Proxied
X-Xfnlog-Site
X-Routing-Service
X-Zipkin-Id
X-Extlb
Cross-Origin-Resource-Policy
ServedBy
X-R9-Blue-Green-Version
X-Dc
X-SRV
X-Ua
X-DynaTrace-JS-Agent
X-LSADC-Cache
X-Ms-Version
X-Ms-Request-Id
Cache-Name
X-FireWall-Port
Cache
X-Human
X-WP-CF-Super-Cache-Cache-Control
Xet-Cookie
SD-X-WS
X-Amzn-RequestId
X-WP-CF-Super-Cache
X-Amz-Apigw-Id
Xserver
X-Cache-Tags
Source
X-Cached-By
X-App-Version
Cross-Origin-Window-Policy
X-Loop
X-TNCMS
X-RCS-CacheZone
X-GEO
WPO-Cache-Message
LB
X-MP-GENERATED-AT
X-Varnish-Hits
WPO-Cache-Status
Origin
X-Reqid
X-Via-NSCOPI
X-Cdn
X-Api-Version
X-Pubstack
X-TA-CDN-Provider
X-Soup
X-Origin-TTL
X-Origin-CC
X-Amzn-Remapped-Content-Length
X-GG-Cache-Date
X-AOL-HN
X-B3-SpanId
X-IPS-LoggedIn
X-Tumblr-Pixel-2
From-Origin
X-Service
X-NewRelic-App-Data
X-FW-Version
X-Xrds-Location
Cache-Hits
X-Vgn-Hpd-Reason
X-Platform-Server
X-Newrelic-Synthetics
Rip
X-Varnish-Ttl
Webserver
X-Cluster-Node
X-Request-Host
Upgrade-Insecure-Requests
X-Provided-By
BehaviorPad-Version
Cdncip
Odigeo-Trace-Id
Rendered-Blocks
Surrogated-Key
A
Sslversion
T-Server
Cdnsip
HostName
Lang
Environment
Host-ID
DCR-Processing-Time-Ms
MD5-Digest
Ngx.Var.Host
Expiry
DCR-Decision-By
Meta-Geo-Continent
Xc-Version
X-Vdms-Version
X-NAPM-TraceId
X-Orig-Expires
X-Owner
X-PBS-Appsvrname
X-User
X-Forwarded-Path
X-A
X-Ec-Fail
X-Ec-GeoHdr
X-External-Request-Id
X-TIM-N
X-Processor
X-Served-From
X-Shop-Environment
X-SRCache-Key
X-Tenant
X-ScT
X-S-Cookie
X-CSRF-Token
X-Rewrite-Enabled
X-Rojux
X-S
X-Destination
X-Developer
X-Aed
X-Bc-Bl
X-Vdms-Path
X-B-Cookie
X-ARC
X-AK-Request-ID
X-VG-WebCache
X-Application
X-BCube-Filmed-By
X-A-Wwc
X-A-Ccd
X-Connection-Hash
X-D
X-Cache-NE
X-A-Dam
X-A-Dcw
X-A-Dgt
X-VC
OT-Force-Account-Verify
Fastly-SSL
X-Thanos
Mobile-Detection-Method
Machine
X-Bip
X-Dispatcher-Number
X-Generated-On
X-Level-Front-Cache
X-Qloud-Router
X-Pool
Redirect-Candidate
X-Aicache-OS
X-Origin-Response-Time
X-Accel-Buffering
Cache-Tv-Group
X-TIME
X-Cluster
X-Varnish-Beresp-Ttl
Req-Svc-Chain
X-Gdpr
X-Geo-Header
X-GeoIP-City
X-Gateway-Skip-Cache
X-GeoIP
Server-Host
X-Gateway-Request-Id
X-Gateway-Cache-Key
Tube-Get-Contents
Tube-Got-Eval
Thinkindot-Control
Thinkindot-CacheControl-Type
X-Gateway-Cache-Status
TDXMobile
Thinkindot-CacheControl
State
Release
X-Mvc-Supplant-OutputCached
NGX
X-Mvc-Supplant-Cachable
NM-Fastcgi-Cache
X-Ckpd-Fst-Backend
Memcached
X-Optimistic-Header
Mail-Subject
X-Nyt-Route
X-Loc
X-JWT-State
X-Hash
Producers
X-Has-Esi
Tube-Got-Results
Platform
X-HS-Content-Campaign-Id
X-Is-Gdpr
X-Irp-Debug
X-INCAP-ABP
X-Gzip
X-Forwarded-Site
X-Branch-Name
X-NWS-UUID-VERIFY
X-Cache-Bucket
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
X-DefElseHash
X-BBC-Edge-Cache-Status
X-Datadog-Trace-Id
X-Csrf-Jwt
X-Cache-Id
X-Clientip
X-Clara-WADP
X-CGP
X-Cdn-Origin
X-Core-Mission
X-Cache-Info
X-Core-Value
X-CacheTTL
X-DefHash
X-Developers
VNS-Age
VNS-Cache
We-Hiring
Vix-Hermes-Req-Id
X-Fmm-Version
X-Gamma-Serve
X-Origin
V-Age
Web-Mar-Region
X-Fetched-On
X-Ec-Custom-Error
X-DPWN-IS-SECURE
X-Device-Os
X-Epic-Correlation-Id
X-Esi-Check
X-Fastly-Cache
X-Eu-Site
X-Ad-Defer-Variation
Tube-Return
X-NodeID
Apple-News-Services-Handled
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
Adler-Geo
X-Rocket-Nginx-Serving-Static
X-Session-Fingerprint
X-SB
X-S-Maxage
X-Rocket-Build-Number
Cache-Host
Click-Count-Error
Cluster
Cmsid
Click-Count-Action-Start
X-Origin-Expires
X-Request-URI
Candidate-Md5Url
X-Region-Sid
X-Sigma
X-Sigma-Backend
X-Viewer-Country
X-VG-TLSProxy
X-Varnish-Remaining-TTL
X-VServer
X-WA-Info
X-Worker
X-Wix-Viewer-Type
X-WADP-Cache
X-Varnish-CookieINHashed-On
X-Varnish-CookieHashed-On
X-SplitTest
X-Sn-Servicetimems
X-Slack-Backend
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-Variation
X-V-Cache
X-Thinkindot-L3
Cmstype
X-Rebelmouse-Surrogate-Control
Gh-Request-Id
X-Proxy-Cache-Info
Ha-Gx-Prefs
HA-Ipaddr
X-Origin-Time
X-Parent-Response-Time
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
Fastly-GeoIP-CountryCode
Fastly-SIE
Fastly-Backend-Name
X-Planisys-CDN-TTL
Country-Code
Fastly-SWR
X-RateLimit-Limit-Second
Is-Eu
Datacenter
X-RateLimit-Remaining-Second
L
CPC-Cache
CPC-Age
L5d-Success-Class
Decoy-Debug-Key
X-Rebelmouse-Cache-Control
DSUID
Decoy-Debug-Status
Kp-EeAlive
Decoy-Debug-TTL
Mime-Version
X-Auto-Login
Origin-EX
X-Minions-Version
IsBot
Origin-CC
X-Cdn-Srv
X-Policy
Wxu-Next-Commit
Wxu-Next-Hostname
Wxu-Next-Region
Servername
Svr
Traceparent
CloudFront-Viewer-Country
X-SIPLIST1
AKAMAI
X-Scale
X-Scheme
X-Tec-Api-Origin
WebServer
X-Cache-Remote
X-Tec-Api-Version
X-Tec-Api-Root
X-Varnish-Beresp-Status
X-Pod-Name
X-Gen-Mode
X-NCache
X-Hnp-Log
Ec-Rule-Version
Fastcgi-Cache-TTL
X-Block-Status
User-Cache-Control
Server-Ext
CDCHOST
Server-Hostname
Sever-Int
Canary
Ssr
X-CMSURLCustom
X-LB-NoCache
X-Tx-Id
AMP-Access-Control-Allow-Source-Origin
X-Udemy-Cache-App-Namespace
X-Tb-Optimization-Total-Bytes-Saved
X-Sucuri-Cache
X-Sucuri-ID
X-ZONE
X-Buckets
Sid
SID
Pics-Label
X-Ig-Push-State
X-Cache-Date
X-TRACE-ID
X-Newrelic-App-Data
X-Cache-Debug
Fastly-Drupal-Html
X-Microcachable
X-WP-CF-Super-Cache-Active
X-ATG-Version
X-Var-Ttl
X-Generated-In
X-Via-Popv
X-ND-Cache
X-Yandex-Sdch-Disable
X-Via-Poph
X-Conf
X-Via-Popn
Time
X-Fastly-Backend
X-Refresh
X-Edge-Pop
Memory
X-FC-Vary-Parameters
X-Azure-Ref-OriginShield
X-B3-Traceid
X-Presslabs-Stats
X-Akamai-Transformed
X-Servedbyhost
X-MSEdge-Flight
X-MSEdge-Features
X-Dmc
Server-ID
X-Be
X-Cs
Env
X-Release
X-Trace-ID
Fastly-Drupal-HTML
X-CS
X-Air-Source
X-Fpc
X-Air-Trace-Id
X-Air-Hostname
X-NC
X-Zone
X-CACHE-KEY
X-TX-ID
X-Endurance-Cache-Level
X-Pass-Why
X-Esi
CDN
X-PX
X-Tumblr-Pixel-3
Magicmarker
X-EC-Lua
X-ID
GeoIp-Country-Code
X-Up
X-Wikidot-Backend
X-MCACHE
X-Wikidot-Static-Cache
X-Srv
X-DC
X-RateLimit-Reset
X-Dispatch
True-Client-IP
X-CACHE-AGE
My-App
X-Hyper-Cache
X-Lambda-Id
X-Wa
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-NGINX-Cache
X-Webkit-CSP-Report-Only
X-M-Log
X-VCL-Version
X-App
Pramga
X-Nf-Request-Id
X-Micro-Cache
X-M-Reqid
X-Vc
X-Varnish-Beresp-TTL
X-Vcl-Version
C-Via
Hostname
X-Qnm-Cache
X-Alfa-Service
X-Req
X-CSRF-TOKEN
X-TrackingId
N-Cache
X-Edge-Origin-Shield-Region
X-PAYTM-SRV-ID
X-TH-Server
X-LB-ID
X-Edge-Origin-Shield-Bytes
X-HS-Status
X-Platform
Fastcgi-X-Cache-Version
CacheControlHeader
True-Client-Ip
X-Air-Pt
Path
On-Server
Resin-Trace
X-Akamai-Pragma-Client-IP
X-Vercel-Id
GeoIP-Country-Code
X-Check-Cacheable
Tcn
X-Vercel-Cache
True-Client-Country-4JS
Esi-Enabled
X-Vtex-Remote-Cache
X-Vtex-Processado-Em
X-AIR-PT
Tracecode
GeoIP-Latitude
X-SERVER-NAME
X-PERF
X-B3-Spanid
NtCoent-Length
X-ApacheServer
X-FPC
X-Request-Start
X-SD-PageType
X-LAGOON
Proxy-Connection
X-Node-Id
X-Op-Id-All
X-API-Version
X-CLOUD-TRACE-CONTEXT
Cdn
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
X-GeoIP-Region-Code
ENV
X-WA
X-GeoIP-Country-Code
Hit
Section-Origin-Responded
Section-Io-Id
HIT
Cache-Key
X-Cdn-Forward
X-Webkit-Csp-Report-Only
DT-Hot-News
WWW-Authenticate
X-Via-CDN
X-Accel-Expires-Debug
Server-Id
X-Date
X-Datacenter
Lb
X-Platform-Router
YJS-ID
X-ServedByHost
X-Mly-Id
X-Platform-Processor
X-Platform-Cluster
X-Proxy-CacheRZ
DynaTrace
X-Render-Time
X-Geo
XkeyRZ
X-Dw-Trace-Id
X-VarnishDD-TTL
XM
X-Via-Ucdn
X-HN
X-Lb-Id
X-Traceid
User-Agent
X-RAMCache
PFcat
X-Edge-POP
X-Proxy-Upstream
X-LiteSpeed-Cache-Control
X-Via-PopV
X-Via-PopH
X-Proxy-Cache-Hk
X-Via-PopN
Server-Ttl
X-Service-Response-Time
Sm-Log-Id
MIME-Version
X-Instance-Name
X-LI-UUID
X-Li-Pop
X-LiteSpeed-Tag
X-LI-Proto
Ohc-File-Size
X-Old-Content-Length
X-Response-By
Yjs-Id
X-Li-Fabric
X-TT-LOGID
PICS-Label
X-CF-Powered-By
X-Cache-Ttl
X-CUA
SRV
X-FORWARDED-FOR
Dnion-Transfer-Encoding
Geoip-Latitude
M-TraceId
XServer
X-Ftr-Request-Id
Location
X-Cache-Ngx
FSS-Cache
Powered-By
X-Lb-Nocache
Nginx-CQVIP
X-DB
X-RSL
X-DSS
X-DI
X-DW
X-RPM
X-Akamai-ERPolicy
Vha6-Origin
X-Akamai-ERRuleID
X-Nc
X-Cache-Backend
X-Fastly-Backend-Reqs
X-RPS
X-Wp-Cf-Super-Cache
X-Wp-Cf-Super-Cache-Cache-Control
X-Litespeed-Cache-Control
X-UA
Wpo-Cache-Status
Wpo-Cache-Message
X-Request-Url
X-From
X-B3-ParentSpanId
X-Fastly-Cache-Hits
X-FL-EDGE
Srvid
X-Cc-Via
Locid
X-Location
X-Httpd
X-Akamai-Request-ID
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
X-Webstats-RespID
X-Cdn-Request-ID
X-HostName
X-HA-Backend
X-Ips-Loggedin
Warning
CountryCode
X-DataCenter
X-Mg-Cache
Fastcgi-Cache-Ttl
Uri
Ohc-Cache-HIT
X-MiniProfiler-Ids
X-Snapshot-Date
X-Moov-T
X-Moov-Xdn-Version
X-Serial
X-Server-IP
Req-ID
WZWS-RAY