Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
Strict-Transport-Security
X-Frame-Options
X-Content-Type-Options
Last-Modified
Link
CF-Cache-Status
Cf-Request-Id
Accept-Ranges
ETag
CF-RAY
Expect-CT
Pragma
X-Powered-By
X-Cache
Via
Age
X-XSS-Protection
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Xss-Protection
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-FRAME-OPTIONS
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Request-Id
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-Adblock-Key
X-AspNet-Version
X-Permitted-Cross-Domain-Policies
Alt-Svc
X-Runtime
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Cache-Status
CF-Ray
X-Generator
X-Cacheable
X-Request-ID
X-Iinfo
Timing-Allow-Origin
X-Envoy-Upstream-Service-Time
Feature-Policy
X-Ua-Compatible
X-Content-Security-Policy
Status
X-Drupal-Dynamic-Cache
Content-Encoding
X-AspNetMvc-Version
Access-Control-Expose-Headers
X-CDN
Upgrade
X-XSS-PROTECTION
Access-Control-Max-Age
X-Via
X-Cache-Group
X-Robots-Tag
Server-Timing
X-UA-Device
Request-Context
X-Dns-Prefetch-Control
Keep-Alive
X-AH-Environment
X-Amz-Request-Id
X-Turbo-Charged-By
X-Proxy-Cache
X-Backend
X-Amz-Id-2
P3p
X-Age
X-Ws-Request-Id
Host-Header
X-Server-Powered-By
X-Hacker
X-Server
X-Rq
X-Vhost
X-Varnish-Cache
EagleId
Grace
X-Amz-Version-Id
X-Dispatcher
X-LiteSpeed-Cache
Cf-Edge-Cache
Allow
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
X-Swift-CacheTime
X-Swift-SaveTime
X-Page-Speed
X-Akamai-Path-Stats
X-Nginx-Cache-Status
Ali-Swift-Global-Savetime
X-WebKit-CSP
X-Aws-Lambda-Call-Status
Accept-CH
X-Host
X-Node
X-OneAgent-JS-Injection
X-Pingback
Cf-Railgun
X-Cache-Spec
X-Server-Id
Surrogate-Control
Request-Id
X-Akam-SW-Version
X-Backend-Server
EagleEye-TraceId
X-Response-Time
X-Cache-Lookup
X-Readtime
Accept-CH-Lifetime
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-HW
Content-Location
X-Content-Security-Policy-Report-Only
X-Application-Context
Rating
X-Trace
X-Cloud-Trace-Context
Fastly-Restarts
X-Country
X-WebKit-CSP-Report-Only
X-Url
X-Clacks-Overhead
X-Nginx-Upstream-Cache-Status
X-MS-InvokeApp
X-Edge
X-Amz-Server-Side-Encryption
X-Rack-Cache
Edge-Control
X-B3-TraceId
X-PC
X-TtlSet
X-Vname
Accept-Ch-Lifetime
X-Ruxit-JS-Agent
X-ESI
X-Mod-Pagespeed
X-Content-Type
X-Vcap-Request-Id
X-Oneagent-Js-Injection
X-CST
X-Exp-Variant
X-Cdn-Fetch
X-GoogleNews-Bot
Xkey
Verso
X-Exp-Id
X-Use-Magma
X-Kinja-Revision
X-Kinja-Server
X-Kinja-Build
X-Kinja
X-GitHub-Request-Id
X-Mcache
X-Amz-Rid
X-D2id
Cache-Tag
X-Powered-By-Plesk
X-FastCGI-Cache
X-VARITI-CCR
X-Ruxit-Js-Agent
Service-Worker-Allowed
X-Varnish-TTL
RTSS
X-Upstream
X-Version
X-Abt-Application-Version
X-Navigation-Version
X-Cached
X-ECACHE
X-Client-IP
X-Ac
X-Cnection
X-Dw-Request-Base-Id
X-Ttl
X-Px
X-SharePointHealthScore
SPRequestGuid
X-Server-Name
Arr-Disable-Session-Affinity
X-Element-Page-Cache
X-Server-Lifecycle-Phase
X-Instrumentation
X-Kraken-Loop-Name
SPRequestDuration
SPIisLatency
X-Cache-TTL
Public-Key-Pins
Permissions-Policy
X-Country-Code
Display
Pagespeed
X-Sol
X-Middleton-Display
X-NWS-LOG-UUID
X-Ser
Response
X-Middleton-Response
X-Midtier
X-Kinsta-Cache
X-Edge-Location-Klb
X-Cache-Key
X-Goog-Hash
Cf-Apo-Via
X-RateLimit-Remaining
X-Forwarded-For
X-SRCache-Store-Status
X-SRCache-Fetch-Status
Content-MD5
Accept-Ch
Access-Control-Request-Method
X-NF-Request-ID
Front-End-Https
X-Shield-Request-Id
X-DataDome
X-MSEdge-Ref
X-Correlation-Id
TP-Cache
X-T
TP-L2-Cache
X-HP-Trace-Id
X-HP-Webp
MicrosoftSharePointTeamServices
X-Jurisdiction
AR-CACHE
AR-ATIME
AR-PoweredBy
AR-Request-ID
AR-SID
X-Accel-Expires
X-Recruiting
Edge-Cache-Tag
Mrf-Cache-Status
MRF-Tech
X-B3-TraceId-Primal
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
Nginx-Cache
X-Powered-CMS
X-Daa-Tunnel
TCN
X-Grace
X-RateLimit-Limit
X-Mg-S
X-Content-Digest
X-Id
X-Hits
X-TEC-API-ROOT
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-Request-Received
X-Request-Processing-Time
Server-Node
Server-Name
X-HS-Combine-CSS
X-HS-Cache-Config
X-HS-Content-Id
X-HS-Hub-Id
Filters
X-Amzn-Trace-Id
MS-Author-Via
X-Frontend
X-Geo-Country
Fastcgi-Cache
X-Distributor
X-Browser-Type
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
S
X-XRDS-Location
X-Webkit-Csp
X-Fastly-Request-Id
X-Protected-By
X-PressLabs-Stats
X-LLID
X-Language
Cache-Status
X-Origin-Server
X-Litespeed-Cache
Count-Hit
X-Ezoic-Cdn
X-LB-Cache
Cross-Origin-Opener-Policy
X-Ab
X-Ua-Browser
Filterid
X-F-Cache
X-Forwarded-Proto
X-Request-Handler-Origin-Region
X-FB-Debug
X-Seen-By
X-Page-Id
X-B3-Sampled
X-Amz-Meta-S3cmd-Attrs
Payment
X-Microsite
Host
Charset
X-Git-Hash
X-ASPNET-VERSION
X-Ratelimit-Reset
X-Fastcgi-Cache
X-Cluster-Name
X-VCache
Surrogate-Key
X-Cache-Age
X-Rid
Realpath
Cache-Tags
Accept-Charset
X-Origin-Cache
X-Template
Access-Control-Allow-Method
X-NGENIX-Cache
X-Www-Served-By
Alternate-Protocol
Retry-After
X-Upgrade-Enabled
X-TTL
X-DIS-Request-ID
X-Logged-In
Cleartype
X-Source
X-AppVersion
X-Az
X-Tb
X-Activity-Id
X-Wix-Request-Id
X-TT
X-Signature
X-Type
X-Request-Guid
X-Aspnet-Duration-Ms
ServerID
X-Varnish-Backend
X-B-Cache
X-Flags
X-Amz-Replication-Status
X-Providence-Cookie
X-Is-Crawler
X-Route-Name
X-App-Environment
X-Varnish-Grace
X-B
X-Envoy-Decorator-Operation
Paypal-Debug-Id
DC
X-DynaTrace
X-Node-Name
X-Hostname
Frame-Options
X-Drupal-Cache-Tags
X-Revision
X-Proxy
X-Debug
X-Contextid
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Fastly-Request-ID
Pinterest-Version
X-Pinterest-Rid
X-Cache-Rule
Pinterest-Generated-By
X-Goog-Generation
X-Kong-Proxy-Latency
X-Goog-Metageneration
X-GUploader-UploadID
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-Kong-Upstream-Latency
X-Mobile
X-Content-Options
Amp-Access-Control-Allow-Source-Origin
X-Load-Cache
Refresh
Country
X-Cache-Control
Node
X-Magnolia-Registration
X-N
NGB
X-Original-Request-Id
X-EdgeConnect-Cache-Status
X-Response-Served-From
X-User-Agent
X-Server-ID
X-Whom
X-XRDS-LOCATION
Viewport
X-Ratelimit-Remaining
X-Varnish-Age
Access-Control-Request-Headers
X-L-Path
X-Cache-TTL-Remaining
X-Cacheable-TTL
X-Environment-Context
X-Framework
Url
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-Status
Akamai-GRN
X-Real-IP
X-Yottaa-Optimizations
X-Varnish-Server
X-Adobe-Content
Referer-Policy
X-Servername
X-Jobs
X-Is-Bot
X-Rendered-As
X-NYM-Debug-Backend
X-Page-View
X-Instance
X-G
X-Cache-Grace
X-Akamai-Request-ID2
X-Debug-IsConnected
X-Cache-Time
X-Content-Powered-By
X-Adobe-Loc
X-Yottaa-Metrics
X-Debug-IsPreview
X-Mid
X-Content
Uber-Trace-Id
X-Unique-Id
X-RemovedCookies
Srv
X-ProcessESI
Content-Disposition
Countrycode
X-COUNTRY
X-Drupal-Cache-Contexts
X-APP-VERSION
X-Oracle-Dms-Ecid
X-Oracle-Dms-Rid
Version
X-Time
X-Mg-Request-UUID
X-Cache-Expired-At
X-Via-JSL
Cross-Origin-Resource-Policy
X-CDN-Forward
Accept-Language
X-Http-Reason
X-Restarts
X-Cache-Hit
X-App-Server
X-Tumblr-Pixel
X-Tumblr-User
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
Protected
X-Trace-Id
X-Cache-Operation
Healthy
X-Ratelimit-Limit
X-IPLB-Instance
X-IPLB-Request-ID
X-Backend-Name
X-Azure-Ref
X-Hosted-By
X-Debug-Info
X-ECache
Content-Secure-Policy
Section-Io-Cache
X-Nginx-Cache-Key
X-Tt-Logid
X-Akamai-Edgescape
X-Device-Type
X-Api-Version
Liferay-Portal
Backend
Server-Info
X-Rule
X-Cache-Action
X-FW-Server
X-FW-Type
X-FW-Serve
X-FW-Static
X-FW-Dynamic
X-FW-Hash
GEO-INFO
Meta-Geo
X-VC-Cache
X-RN-RSRV
X-UPSTREAM-Address
X-Generation-Time
X-Mobile-URL
Load-Balancing
X-Storage
X-SRV
X-Mode
Ms-Operation-Id
X-RTag
MS-CV
X-Proxy-Cache-Status
Fastcgi-Useragent
X-Content-Age
CF-IPCountry
X-HTML-Minification-Powered-By
X-Handled-By
X-Varnish-Beresp-Grace
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-PHP-Host
X-Region
CDN-CachedAt
CDN-EdgeStorageId
X-Sql-Count
CDN-PullZone
CDN-Uid
TWC-GeoIP-Country
X-Sql-Duration-Ms
CDN-RequestId
CDN-RequestCountryCode
CDN-Cache
Azure-Version
X-ShardId
X-Section
Azure-RegionName
Azure-InstanceId
TWC-Device-Class
Azure-SiteName
Azure-SlotName
X-Say-Cacheable
X-SaId
X-Say-TTL
X-SayCDN-TTL
X-Shopify-Stage
X-Urbn-Context-Path
X-Urbn-Site-Id
X-Cache-Enabled
X-Alternate-Cache-Key
X-Cache-Host
X-Edge-Location
X-Forwarded-Host
X-Format
X-Adobe-Source
Property-Id
Webcakes-App-Name
Web-Mar-Node
Webcakes-App-Version
X-ShopId
X-Access
X-Generated-By
TWC-Locale-Group
Locale
X-Varnish-Cache-Hits
TWC-Connection-Speed
X-Origin-Hint
TWC-GeoIP-LatLong
X-Cache-Server
X-Locale
X-Labrador-Cache-Channel
X-JoinUs
X-Skip-Cache
X-Site-Version
X-Redis-Cache
TWC-Privacy
Webcakes-Region
X-URL
X-Cache-NGX
X-ServerID
X-Server-W
X-Routing-Service
X-Datadome
X-Storefront-Renderer-Rendered
Mn-Server-Ip
X-BYPASS-REASON
X-UA-Device-Type
X-Timing-Wait
Selected-Fe
X-Request-Time
X-ProxyCache-Status
X-Extlb
X-FB-TRIP-ID
X-Detected-As
X-Cache-Type
X-AWS-Id
X-GeoCode
X-GeoCountry
X-ProxyCache-Key
X-Proxy-Build
X-Proxied
X-LJ-Flow-ID
X-VWS-Id
X-Uri
X-FireWall-Port
X-Cms-Context
X-Proto
X-Web-Node
X-Ms-Request-Id
X-No-Session
X-PHP-Backend
X-Ms-Version
Apigw-Requestid
S-Rt
X-Varnishpool
X-Zipkin-Id
DB-Nickname
X-Varnish-Hostname
Onion-Location
X-R9-Blue-Green-Version
Eomportal-Instance
X-Via-Fastly
X-PCL
X-Hl-Ver
X-Tid
Cache-Name
X-Xfnlog-Site
X-OCL
X-Correlation-ID
X-Cache-Status-Check
X-Nginx-Cache
WP-Super-Cache
X-WP-CF-Super-Cache
X-Origin-Date
X-WP-CF-Super-Cache-Cache-Control
X-Amz-Apigw-Id
X-UUID
Xserver
X-Amzn-RequestId
ServedBy
X-DynaTrace-JS-Agent
X-Varnish-Ttl
X-Zen-Fury
X-LSADC-Cache
X-Dc
X-TNCMS
X-Loop
X-Ua
X-Pubstack
X-Human
Xet-Cookie
X-MP-GENERATED-AT
Source
X-TA-CDN-Provider
X-RCS-CacheZone
X-Amzn-Remapped-Content-Length
X-Reqid
X-Aspnetmvc-Version
X-Provided-By
X-Soup
Cache
X-GEO
X-Cdn
X-Cache-Tags
X-Vgn-Hpd-Reason
X-Webkit-CSP
Origin
X-Origin-CC
X-Cached-By
X-Origin-TTL
X-Debug-Cache
X-Tumblr-Pixel-2
X-Varnish-Hits
Cross-Origin-Window-Policy
From-Origin
X-Newrelic-Synthetics
X-Service
WPO-Cache-Status
SD-X-WS
X-App-Version
WPO-Cache-Message
X-TIME
X-Varnish-Beresp-Ttl
X-Tec-Api-Root
X-Tec-Api-Version
X-Tec-Api-Origin
LB
X-AOL-HN
Rip
X-IPS-LoggedIn
X-Trace-ID
X-B3-Traceid
X-Cache-Debug
Webserver
X-Request-Host
X-Application
X-Owner
X-Orig-Expires
X-Aed
X-Vdms-Version
X-NAPM-TraceId
X-User
X-Tenant
X-A-Dgt
X-A-Wwc
X-TIM-N
X-ARC
X-Vdms-Path
X-VG-WebCache
X-Connection-Hash
X-Cache-NE
X-BCube-Filmed-By
X-D
X-Destination
X-Ec-GeoHdr
X-Developer
X-Bc-Bl
A
X-Forwarded-Path
X-B-Cookie
Cdnsip
Xc-Version
X-External-Request-Id
BehaviorPad-Version
Cdncip
X-A-Dcw
MD5-Digest
X-Rewrite-Enabled
X-Ec-Fail
Lang
Host-ID
T-Server
X-Rojux
Surrogated-Key
Sslversion
Odigeo-Trace-Id
X-PBS-Appsvrname
Ngx.Var.Host
X-Processor
Rendered-Blocks
Meta-Geo-Continent
Expiry
Environment
X-Served-From
X-A-Ccd
X-ScT
CPC-Age
X-Shop-Environment
X-Parent-Response-Time
X-A-Dam
CPC-Cache
DCR-Decision-By
VNS-Cache
VNS-Age
X-S
X-A
DCR-Processing-Time-Ms
X-S-Cookie
X-SRCache-Key
X-AK-Request-ID
X-FW-Version
X-CSRF-Token
X-NewRelic-App-Data
X-Platform-Server
X-Cluster-Node
HostName
OT-Force-Account-Verify
X-Thanos
X-Aicache-OS
X-Pool
X-Dispatcher-Number
X-B3-SpanId
X-Via-NSCOPI
X-Accel-Buffering
X-Qloud-Router
X-Bip
Machine
Redirect-Candidate
X-Varnish-Beresp-Status
Mime-Version
X-WP-CF-Super-Cache-Active
Upgrade-Insecure-Requests
X-GG-Cache-Date
X-Datadog-Parent-Id
X-Esi-Check
X-Datadog-Sampling-Priority
X-Datadog-Trace-Id
X-Csrf-Jwt
X-Clientip
X-Cluster
Tube-Got-Results
X-Core-Mission
X-Epic-Correlation-Id
X-DefHash
X-Device-Os
Traceparent
X-DPWN-IS-SECURE
X-Ec-Custom-Error
Tube-Get-Contents
X-Developers
State
Tube-Got-Eval
X-Clara-WADP
X-DefElseHash
X-Cdn-Origin
We-Hiring
X-BBC-Edge-Cache-Status
Vix-Hermes-Req-Id
V-Age
X-Auto-Login
Web-Mar-Region
Wxu-Next-Commit
Wxu-Next-Region
X-Ad-Defer-Variation
X-Branch-Name
X-Eu-Site
Wxu-Next-Hostname
X-Cdn-Srv
X-CGP
X-CacheTTL
X-Cache-Info
X-Cache-Bucket
X-Cache-Id
Tube-Return
X-Ckpd-Fst-Backend
X-Gateway-Request-Id
X-Slack-Backend
X-SIPLIST1
X-Sn-Servicetimems
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-Sigma-Backend
X-Sigma
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-Request-URI
X-Rocket-Build-Number
X-Scale
X-V-Cache
X-Variation
X-Generated-On
X-Wix-Viewer-Type
X-Geo-Header
X-Level-Front-Cache
X-Region-Sid
X-WADP-Cache
X-VServer
X-Varnish-CookieINHashed-On
X-Varnish-CookieHashed-On
X-Varnish-Remaining-TTL
X-VG-TLSProxy
X-Viewer-Country
X-Proxy-Cache-Info
X-Policy
X-Gzip
X-GeoIP-City
X-Has-Esi
X-Hash
X-INCAP-ABP
X-GeoIP
X-Gateway-Skip-Cache
X-Forwarded-Site
X-Fmm-Version
X-Gateway-Cache-Key
X-Gateway-Cache-Status
Servername
X-Irp-Debug
X-Is-Gdpr
X-Origin-Response-Time
X-Origin
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-NodeID
X-Mvc-Supplant-OutputCached
X-JWT-State
X-Loc
X-Minions-Version
X-Mvc-Supplant-Cachable
X-Fetched-On
X-Optimistic-Header
Fastly-SWR
Gh-Request-Id
Ha-Gx-Prefs
Fastly-SSL
Fastly-GeoIP-CountryCode
Decoy-Debug-TTL
DSUID
HA-Ipaddr
Is-Eu
Mail-Subject
Mobile-Detection-Method
L5d-Success-Class
L
IsBot
Kp-EeAlive
Decoy-Debug-Status
Decoy-Debug-Key
Apple-News-Services-Request-Url
Cache-Host
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
Adler-Geo
Apple-News-Services-Handled
Canary
Candidate-Md5Url
Country-Code
Datacenter
Cmstype
Cmsid
Click-Count-Action-Start
Click-Count-Error
NGX
Fastly-SIE
NM-Fastcgi-Cache
Platform
Producers
Origin-EX
Req-Svc-Chain
Origin-CC
Release
WebServer
X-SplitTest
X-ATG-Version
User-Cache-Control
X-Azure-Ref-OriginShield
X-Worker
AKAMAI
Svr
X-S-Maxage
X-HS-Content-Campaign-Id
X-Origin-Time
X-Hnp-Log
X-VC
Server-Hostname
Sever-Int
X-Nyt-Route
CDCHOST
X-Rocket-Nginx-Serving-Static
X-Var-Ttl
X-Gen-Mode
Server-Ext
X-Tx-Id
X-Scheme
X-NCache
X-Block-Status
X-Sucuri-ID
Memcached
X-Thinkindot-L3
X-Gamma-Serve
Fastly-Backend-Name
CloudFront-Viewer-Country
Cluster
X-Fastly-Backend
X-FC-Vary-Parameters
X-Sucuri-Cache
Server-Host
X-Core-Value
Thinkindot-Control
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
X-CMSURLCustom
TDXMobile
X-Gdpr
X-WA-Info
Ec-Rule-Version
Cache-Tv-Group
X-Newrelic-App-Data
X-Cache-Remote
X-LB-NoCache
X-ND-Cache
Fastly-Drupal-HTML
X-SB
Cache-Hits
Pics-Label
Sid
X-ZONE
X-Udemy-Cache-App-Namespace
Ssr
Fastcgi-Cache-TTL
X-Nf-Request-Id
X-Tb-Optimization-Total-Bytes-Saved
X-Session-Fingerprint
X-Origin-Expires
X-Fastly-Cache
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-Pod-Name
X-Generated-In
Time
Memory
AMP-Access-Control-Allow-Source-Origin
SID
X-Refresh
X-Via-Popv
X-Pass-Why
X-Via-Poph
Env
X-Servedbyhost
X-Presslabs-Stats
X-Via-Popn
X-Cs
X-Akamai-Transformed
Server-ID
X-Edge-Pop
X-Dispatch
My-App
X-Release
X-Up
X-Tumblr-Pixel-3
X-Wa
X-Lambda-Id
X-Cache-Date
X-Buckets
X-Ig-Push-State
X-DC
X-EC-Lua
X-NWS-UUID-VERIFY
X-MSEdge-Flight
X-MSEdge-Features
X-NC
X-Conf
X-Esi
X-Fpc
X-PX
X-Zone
X-MCACHE
GeoIp-Country-Code
X-ID
CDN
X-Microcachable
X-Xrds-Location
Fastly-Drupal-Html
X-CACHE-AGE
X-Req
True-Client-IP
X-Dmc
X-Endurance-Cache-Level
X-TX-ID
X-VCL-Version
X-LB-ID
X-CS
X-Vc
X-NGINX-Cache
X-Webkit-CSP-Report-Only
Magicmarker
True-Client-Country-4JS
CacheControlHeader
X-B3-Spanid
X-CACHE-KEY
X-RateLimit-Reset
X-Be
Hostname
X-Wikidot-Static-Cache
X-Op-Id-All
X-TH-Server
X-Wikidot-Backend
X-CSRF-TOKEN
X-Srv
X-TRACE-ID
X-HS-Status
Request-ID
Resin-Trace
Path
X-Hyper-Cache
X-Varnish-Beresp-TTL
True-Client-Ip
X-CF-Lambda-Version
X-M-Reqid
X-Micro-Cache
X-M-Log
X-Vcl-Version
Tcn
X-GeoIP-Country-Code
X-Alfa-Service
X-Air-Hostname
X-GeoIP-Region-Code
X-CF-Lambda-Fn
X-Air-Source
X-Air-Trace-Id
X-Air-Pt
X-App
X-Qnm-Cache
Tracecode
Pramga
GeoIP-Country-Code
X-Date
WWW-Authenticate
X-Accel-Expires-Debug
X-Check-Cacheable
X-SERVER-NAME
Section-Origin-Responded
Section-Io-Origin-Status
X-Akamai-Pragma-Client-IP
Section-Io-Id
X-RAMCache
X-Vercel-Cache
Section-Io-Origin-Time-Seconds
C-Via
X-FPC
X-Vercel-Id
X-CLOUD-TRACE-CONTEXT
NtCoent-Length
X-TrackingId
X-LiteSpeed-Cache-Control
X-Datacenter
X-Old-Content-Length
N-Cache
X-WA
Proxy-Connection
YJS-ID
X-Webkit-Csp-Report-Only
Yjs-Id
X-Platform-Router
X-Mly-Id
Lb
X-Via-CDN
FSS-Cache
Server-Id
X-Geo
Powered-By
Fastcgi-X-Cache-Version
X-Edge-POP
X-PAYTM-SRV-ID
X-Platform-Processor
X-Platform
Hit
Esi-Enabled
X-Platform-Cluster
On-Server
X-Yandex-Sdch-Disable
X-API-Version
X-Via-PopN
X-Via-PopH
X-Via-PopV
ENV
User-Agent
X-ServedByHost
X-Response-By
X-Lb-Id
X-Dw-Trace-Id
X-Cdn-Forward
X-UA
X-Edge-Origin-Shield-Region
XServer
X-Edge-Origin-Shield-Bytes
GeoIP-Latitude
X-Vtex-Remote-Cache
X-Vtex-Processado-Em
X-Node-Id
X-Client-Ip
HIT
X-Webstats-RespID
X-Location
X-AIR-PT
X-Contensis-Viewer-Groups
X-FL-EDGE
X-From
X-Request-Start
X-Director
X-LAGOON
X-TT-LOGID
X-SD-PageType
X-Cache-ASPX
Locid
X-Traceid
Dnion-Transfer-Encoding
X-Instance-Name
X-LI-UUID
X-CUA
X-LI-Proto
X-Li-Pop
Geoip-Latitude
X-Li-Fabric
X-FORWARDED-FOR
Srvid
X-Akamai-ERPolicy
X-Varnish-Authentication
X-Akamai-ERRuleID
X-Cache-Ttl
X-Service-Response-Time
Sm-Log-Id
PICS-Label
Ohc-File-Size
X-DataCenter
X-CF-Powered-By
X-Request-Url
X-RPM
X-RPS
X-DW
Nginx-CQVIP
X-Server-IP
X-Render-Time
X-LiteSpeed-Tag
X-DI
Cache-Key
Cdn
X-Via-Ucdn
X-DB
X-RSL
X-DSS
Location
X-Wp-Cf-Super-Cache-Cache-Control
X-Wp-Cf-Super-Cache
X-Litespeed-Cache-Control
X-IN-APIGATEWAY
Uri
Swift-Performance
X-PERF
X-IN-APIGATEWAYSSL
X-Test
X-ApacheServer
DynaTrace
X-Proxy-Upstream
Wpo-Cache-Status
X-Fastly-Cache-Hits
Vha6-Origin
X-Cdn-Request-ID
X-B3-ParentSpanId
X-HostName
X-Lb-Nocache
Server-Ttl
X-Fastly-Backend-Reqs
Wpo-Cache-Message
Warning
XkeyRZ
X-Ips-Loggedin
Wp-Super-Cache
CountryCode
X-Cache-Ngx
X-Proxy-CacheRZ
X-Proxy-Cache-Hk
X-HA-Backend
Cneonction
X-Th-Server
X-UP
X-Request-URL
X-Ha-Backend
X-Cache-Expires
M-TraceId
X-Yottaa-OS
Req-ID
X-Moov-Xdn-Version
Fastcgi-Cache-Ttl
SRV
WZWS-RAY
X-Moov-T
X-VarnishDD-TTL
X-ElasticPress-Query
X-Mg-Cache
XM
PFcat
X-HN
CF-Cached-On