Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Accept-Ranges
X-XSS-Protection
Expect-CT
Pragma
X-Powered-By
CF-RAY
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-Xss-Protection
X-Download-Options
CF-Ray
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Request-Id
Access-Control-Allow-Credentials
X-FRAME-OPTIONS
X-Permitted-Cross-Domain-Policies
X-Request-ID
X-AspNet-Version
Alt-Svc
X-Runtime
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Generator
X-Cache-Status
X-Cacheable
Timing-Allow-Origin
X-Envoy-Upstream-Service-Time
X-Iinfo
X-Content-Security-Policy
X-Drupal-Dynamic-Cache
Feature-Policy
Content-Encoding
Access-Control-Expose-Headers
Upgrade
Status
X-CDN
X-AspNetMvc-Version
Access-Control-Max-Age
X-Via
Server-Timing
X-UA-Device
Request-Context
X-Robots-Tag
X-Turbo-Charged-By
X-Amz-Request-Id
X-Cache-Group
EagleId
X-Amz-Id-2
X-Backend
X-AH-Environment
P3p
X-Proxy-Cache
Keep-Alive
X-Ua-Compatible
X-Server
X-Ws-Request-Id
X-Age
Host-Header
Cf-Edge-Cache
X-Hacker
X-Vhost
X-Server-Powered-By
X-Rq
X-Dns-Prefetch-Control
X-Varnish-Cache
X-Dispatcher
X-Amz-Version-Id
Grace
Allow
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-OneAgent-JS-Injection
X-LiteSpeed-Cache
X-WebKit-CSP
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Page-Speed
X-Device
Cf-Apo-Via
Accept-CH
Cf-Railgun
X-Aws-Lambda-Call-Status
X-Node
X-Pingback
X-Host
X-Ruxit-JS-Agent
EagleEye-TraceId
X-Nginx-Cache-Status
X-Server-Id
Surrogate-Control
X-Akam-SW-Version
X-Readtime
X-Backend-Server
Request-Id
X-Cache-Spec
X-Cache-Lookup
X-HW
X-Content-Security-Policy-Report-Only
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Cloud-Trace-Context
X-Trace
Accept-Ch-Lifetime
X-Application-Context
X-Response-Time
Permissions-Policy
Fastly-Restarts
X-Nginx-Upstream-Cache-Status
X-Edge
X-Mod-Pagespeed
X-WebKit-CSP-Report-Only
Accept-CH-Lifetime
X-Country
X-Mcache
X-Content-Type
Content-Location
X-MS-InvokeApp
X-Url
X-CST
X-Clacks-Overhead
X-Vname
X-PC
X-TtlSet
X-Amz-Server-Side-Encryption
Rating
X-Midtier
X-Litespeed-Cache
RTSS
Cache-Tag
X-ESI
X-Vcap-Request-Id
X-D2id
X-Element-Page-Cache
X-VARITI-CCR
Origin-Trial
X-Exp-Variant
X-Kinja-Build
X-Kinja-Server
X-Use-Magma
Verso
X-Kinja
X-Kinja-Revision
X-Cdn-Fetch
X-GoogleNews-Bot
X-Exp-Id
X-Rack-Cache
X-Server-Name
X-Ac
X-Powered-By-Plesk
X-Ttl
Service-Worker-Allowed
X-Cnection
X-ECACHE
X-Amz-Rid
SPRequestGuid
X-SharePointHealthScore
X-Client-IP
X-Navigation-Version
X-GitHub-Request-Id
Xkey
X-Abt-Application-Version
Edge-Control
SPRequestDuration
SPIisLatency
X-NWS-LOG-UUID
X-Cache-TTL
X-B3-TraceId
X-Upstream
Arr-Disable-Session-Affinity
X-Cached
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Instrumentation
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Browser-Type
X-Mg-S
X-Dw-Request-Base-Id
X-Px
X-Cache-Key
X-Sol
Pagespeed
X-Middleton-Display
Display
X-Varnish-TTL
X-FastCGI-Cache
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Correlation-Id
X-NF-Request-ID
Access-Control-Request-Method
Edge-Cache-Tag
X-Forwarded-For
X-Country-Code
X-Goog-Hash
Content-MD5
X-Webkit-Csp
TCN
X-Powered-CMS
Front-End-Https
AR-PoweredBy
AR-CACHE
AR-ATIME
AR-SID
AR-Request-ID
X-Version
Public-Key-Pins
X-RateLimit-Remaining
X-Jurisdiction
X-HP-Webp
X-HP-Trace-Id
Accept-Ch
X-T
X-MSEdge-Ref
X-Id
X-Content-Digest
X-Ser
X-Recruiting
X-Ratelimit-Limit
X-XRDS-Location
X-Amzn-Trace-Id
X-Middleton-Response
Response
X-Accel-Expires
X-Daa-Tunnel
TP-Cache
TP-L2-Cache
X-Shield-Request-Id
MicrosoftSharePointTeamServices
Nginx-Cache
S
Cache-Status
Mrf-Cache-Status
X-B3-TraceId-Primal
MRF-Tech
X-Request-Received
X-HS-Combine-CSS
X-HS-Content-Id
X-HS-Hub-Id
Server-Node
X-HS-Cache-Config
X-Request-Processing-Time
X-Fastcgi-Cache
Cache-Tags
X-Distributor
X-Hits
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-TEC-API-VERSION
Cross-Origin-Opener-Policy
X-Kinsta-Cache
X-Edge-Location-Klb
X-LB-Cache
X-Origin-Server
X-Ratelimit-Remaining
X-Ua-Browser
X-Ezoic-Cdn
Fastcgi-Cache
X-PressLabs-Stats
Alternate-Protocol
X-Grace
Server-Name
Filterid
X-Ratelimit-Reset
X-DIS-Request-ID
X-Frontend
X-Microsite
X-Request-Handler-Origin-Region
X-Server-ID
X-Hostname
X-Geo-Country
X-LLID
X-Rid
X-Protected-By
Healthy
X-FB-Debug
X-ORACLE-DMS-ECID
X-Varnish-Backend
X-Logged-In
X-ORACLE-DMS-RID
X-Git-Hash
Cleartype
Payment
X-Debug-Info
X-Page-Id
X-DataDome
X-Www-Served-By
X-Load-Cache
X-Forwarded-Proto
X-NGENIX-Cache
X-Cluster-Name
X-ASPNET-VERSION
DC
X-ECache
MS-Author-Via
X-Origin-Cache
X-Fastly-Request-ID
Realpath
Charset
Content-Disposition
Access-Control-Allow-Method
X-B3-Sampled
X-GUploader-UploadID
X-Goog-Metageneration
X-Upgrade-Enabled
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Proxy
X-F-Cache
X-Az
X-Activity-Id
X-AppVersion
X-B3-Traceid
X-Seen-By
X-Amz-Meta-S3cmd-Attrs
X-Amz-Replication-Status
Retry-After
X-Azure-Ref
X-Fb-Rlafr
X-Cache-Age
Paypal-Debug-Id
X-TTL
Count-Hit
Cross-Origin-Resource-Policy
X-Whom
X-Type
Viewport
Surrogate-Key
X-Is-Crawler
X-Route-Name
X-Revision
X-Request-Guid
X-Providence-Cookie
X-Contextid
X-Flags
X-Aspnet-Duration-Ms
X-B-Cache
X-B
X-Aspnetmvc-Version
X-Wix-Request-Id
X-Varnish-Server
X-App-Environment
X-Hosted-By
X-Signature
X-Akamai-Edgescape
Accept-Charset
Amp-Access-Control-Allow-Source-Origin
X-Fastly-Request-Id
X-TT
X-VCache
X-DynaTrace
X-Language
X-Varnish-Ttl
X-Times
X-Source
X-App-Server
X-Oracle-Dms-Ecid
X-Oracle-Dms-Rid
X-Cache-Control
X-Mobile
Referer-Policy
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Magnolia-Registration
X-Envoy-Decorator-Operation
X-Varnish-Grace
Host
Version
X-Cache-Rule
X-N
X-HTML-Minification-Powered-By
WPO-Cache-Message
WPO-Cache-Status
X-Tumblr-Pixel-0
Refresh
X-EdgeConnect-Cache-Status
X-Tt-Trace-Host
X-Tumblr-Pixel
X-Response-Served-From
X-Varnish-Age
X-Original-Request-Id
X-Tumblr-Pixel-1
X-Tt-Trace-Tag
X-Tumblr-User
X-Rule
MS-CV
Ms-Operation-Id
X-RTag
X-Cache-Status-Check
X-Cache-Time
Access-Control-Request-Headers
SRV
X-User-Agent
X-UUID
X-Framework
X-Cache-Grace
SD-X-WS
Section-Io-Cache
X-Cacheable-TTL
X-FW-Version
Protected
X-FW-Type
X-Page-View
X-RemovedCookies
X-ProcessESI
X-FW-Serve
GEO-INFO
X-Jobs
X-Backend-Name
X-Content-Powered-By
X-FW-Static
X-FW-Dynamic
X-FW-Server
Akamai-GRN
X-Status
X-FW-Hash
CDN-RequestId
X-Cache-Expired-At
X-Is-Bot
X-Instance
X-Drupal-Cache-Tags
X-Device-Type
X-Rendered-As
X-G
From-Origin
X-L-Path
VIX-Pulpo-Node
X-Environment-Context
VIX-Pulpo-Upstream-Status
X-RateLimit-Limit
X-Akamai-Request-ID2
Url
X-Servername
X-NYM-Debug-Backend
X-Drupal-Cache-Contexts
X-Amzn-RequestId
X-Http-Reason
X-Amz-Apigw-Id
X-Region
X-Adobe-Loc
NGB
X-Adobe-Content
X-Trace-Id
X-Nginx-Cache
Front
X-Template
X-CDN-Forward
X-Unique-Id
X-Debug-IsPreview
Accept-Language
X-XRDS-LOCATION
X-Debug-IsConnected
X-Yottaa-Optimizations
X-Cache-Hit
X-Yottaa-Metrics
X-Content-Options
Backend
Fastly-SWR
Fastly-SIE
Country
X-Zen-Fury
Liferay-Portal
X-Air-Trace-Id
X-Air-Source
X-Newrelic-App-Data
X-Air-Hostname
X-DynaTrace-JS-Agent
Pinterest-Version
Pinterest-Generated-By
X-Mode
X-Pinterest-Rid
X-Tb
X-COUNTRY
X-Cache-Operation
Content-Secure-Policy
X-Real-IP
Meta-Geo
Webserver
Uber-Trace-Id
S-Rt
Onion-Location
Filters
X-Content-Age
X-Amzn-Remapped-Content-Length
X-RN-RSRV
X-Rewrite-Enabled
X-Generation-Time
X-Rocket-Nginx-Serving-Static
X-Proxy-Cache-Info
X-Tt-Logid
X-Tumblr-Pixel-2
X-Cache-Server
X-UPSTREAM-Address
Selected-Fe
X-Web-Node
X-IPS-LoggedIn
X-Proxy-Build
Azure-SiteName
Azure-RegionName
Azure-InstanceId
Azure-SlotName
Azure-Version
CF-IPCountry
Cache-Hits
X-Timing-Wait
X-Section
X-Time
X-Locale
X-Node-Name
X-Format
X-PHP-Backend
X-Access
Property-Id
X-Origin-Hint
Webcakes-App-Name
Webcakes-Region
X-Ms-Version
X-R9-Blue-Green-Version
X-Soup
X-Proto
Cache-Name
X-Sql-Count
X-Forwarded-Host
X-Cluster-Node
X-Skip-Cache
ServedBy
X-Varnish-Beresp-Grace
Webcakes-App-Version
X-Sql-Duration-Ms
X-Server-W
TWC-Locale-Group
X-Sucuri-Cache
X-UA-Device-Type
TWC-Privacy
TWC-GeoIP-LatLong
X-SayCDN-TTL
TWC-Connection-Speed
X-Site-Version
X-Say-Cacheable
X-Say-TTL
X-Ms-Request-Id
TWC-GeoIP-Country
TWC-Device-Class
X-Sucuri-ID
X-Debug
Node
X-Uri
X-TIME
DB-Nickname
X-Proxied
X-Proxy-Cache-Status
ServerID
X-ProxyCache-Status
X-Handled-By
X-BYPASS-REASON
Web-Mar-Node
X-Cache-TTL-Remaining
X-Cms-Context
X-Extlb
X-Edge-Location
Cross-Origin-Window-Policy
X-ProxyCache-Key
X-Cache-Host
X-Labrador-Cache-Channel
X-Reqid
X-Cache-Action
X-Zipkin-Id
X-Via-Fastly
X-Origin-Date
X-PHP-Host
X-Tumblr-Pixel-3
X-VC-Cache
X-Routing-Service
X-AWS-Id
X-Detected-As
X-Cluster
X-FB-TRIP-ID
X-IPLB-Instance
X-Ruxit-Js-Agent
X-Adobe-Source
X-SaId
X-LJ-Flow-ID
X-LAGOON
X-IPLB-Request-ID
X-WP-CF-Super-Cache
X-JoinUs
X-WP-CF-Super-Cache-Cache-Control
X-VWS-Id
Mn-Server-Ip
X-Optimistic-Header
X-No-Session
X-Xfnlog-Site
Apigw-Requestid
X-Urbn-Site-Id
X-Urbn-Context-Path
Locale
X-App-Version
Countrycode
X-ARC
X-GeoCountry
X-LSADC-Cache
X-Ua
Fastcgi-Useragent
X-GeoCode
Mime-Version
WP-Super-Cache
X-Buckets
Cache-Tv-Group
Source
X-Oneagent-Js-Injection
X-Director
CDN-PullZone
CDN-EdgeStorageId
CDN-Cache
Upgrade-Insecure-Requests
CDN-RequestCountryCode
CDN-CachedAt
CDN-Uid
X-Varnish-Hits
X-Hl-Ver
X-Mg-Request-UUID
Fastly-Drupal-HTML
X-GEO
X-Generated-By
X-Request-Time
X-Tec-Api-Root
X-Tec-Api-Origin
X-Tec-Api-Version
X-Redis-Cache
Frame-Options
X-Cache-Debug
X-Tx-Id
X-FireWall-Port
Xet-Cookie
X-Webkit-CSP-Report-Only
X-Loop
CF-Cached-On
X-Origin-CC
X-Varnish-Cache-Hits
X-Origin-TTL
X-URL
X-Pass-Why
X-RM-Cache-TTL
X-Varnish-Hostname
X-Shopify-Stage
X-Sorting-Hat-PodId
X-ShopId
X-TA-CDN-Provider
X-Alternate-Cache-Key
X-Sorting-Hat-ShopId
X-ShardId
X-Storefront-Renderer-Rendered
X-ServerID
X-SRV
X-TNCMS
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
Load-Balancing
X-Datadog-Sampled
X-Akamai-Transformed
X-Api-Version
X-Newrelic-Synthetics
X-Pubstack
X-Service
X-Served-From
X-Location
X-Request-Host
X-Endurance-Cache-Level
Xserver
Server-Info
X-Application
X-CMSURLCustom
X-B-Cookie
X-BBC-Edge-Cache-Status
X-Conf
Candidate-Md5Url
Host-ID
Lang
X-Core-Mission
BehaviorPad-Version
X-Bc-Bl
Cache-Host
X-Generated-On
X-Vdms-Path
Edge-Cache
DSUID
DCR-Decision-By
MD5-Digest
X-Cache-NE
X-Cache-Date
X-Cache-Info
DCR-Processing-Time-Ms
X-Ec-GeoHdr
X-Epic-Correlation-Id
X-External-Request-Id
Country-Code
Gannett-Cam-Experience-Id
X-CUA
X-Cdn-Origin
A
X-Gdpr
X-Ec-Fail
X-Vdms-Version
X-Developer
X-Destination
X-Bip
X-D
X-BCube-Filmed-By
X-A-Wwc
X-A-Ccd
Req-Svc-Chain
X-A
X-Nyt-Route
Xc-Version
X-Platform-Cluster
Rendered-Blocks
Memcached
Redirect-Candidate
X-A-Dam
Release
X-Mobile-URL
X-Rojux
X-Processor
Sslversion
X-S
X-Thinkindot-L3
X-SVT-ORM-VERSION
X-Thanos
X-Test
X-TIM-N
X-S-Cookie
Thinkindot-Control
X-Origin-Time
Thinkindot-CacheControl-Type
WWW-Authenticate
X-S-Maxage
X-ScT
X-Mid
X-Sigma-Backend
X-INCAP-ABP
X-Platform-Router
X-We-Are-Hiring
X-Aed
Origin
Odigeo-Trace-Id
X-Httpd
Meta-Geo-Continent
Surrogated-Key
X-Hash
X-SRCache-Key
Ngx.Var.Host
X-SVT-ORM-RULES
X-Platform-Processor
T-Server
X-Loc
Thinkindot-CacheControl
X-Level-Front-Cache
X-A-Dcw
X-Sigma
X-Sn-Servicetimems
TDXMobile
X-A-Dgt
X-Rocket-Build-Number
X-Storage
X-Restarts
X-CSRF-Token
CloudFront-Viewer-Country
CacheControlHeader
X-Cdn-Srv
X-Clara-WADP
X-Cache-Bucket
X-Auto-Login
X-Accel-Expires-Debug
Gh-Request-Id
NM-Fastcgi-Cache
X-WADP-Cache
Mail-Subject
Magicmarker
X-Worker
We-Hiring
X-VServer
X-WP-CF-Super-Cache-Active
X-Vmg-Version
Server-Host
Fastly-Backend-Name
X-Slack-Backend
Fastly-GeoIP-CountryCode
X-CacheTTL
X-Has-Esi
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
Section-Io-Id
X-Geo-Header
Section-Origin-Responded
X-Pool
X-Mvc-Supplant-Cachable
X-Region-Sid
X-Gamma-Serve
X-JWT-State
X-Var-Ttl
X-GeoIP
X-Varnishpool
X-Org
X-Node-Id
X-Human
X-Varnish-Beresp-Ttl
Cache-Key
X-GeoIP-City
X-Is-Gdpr
X-Origin-Response-Time
X-HS-Content-Campaign-Id
X-Fmm-Version
X-Varnish-Beresp-Status
X-Akamai-Device-Characteristics
X-Date
X-Fetched-On
AKAMAI
Apple-News-Services-Handled
C-Via
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
X-SD-PageType
X-Server-IP
X-Fastly-Backend
X-Origin
X-Fastly-Cache
X-B3-Spanid
X-Developers
X-Men
X-Ec-Custom-Error
X-Slack-Shared-Secret-Outcome
X-Dispatcher-Number
X-Parent-Response-Time
X-Mly-Id
X-Nginx-Cache-Key
X-NCache
Web-Mar-Region
X-Req
User-Cache-Control
Tube-Return
X-Qloud-Router
X-Varnish-CookieHashed-On
X-Op-Id-All
Wxu-Next-Hostname
Wxu-Next-Commit
Wxu-Next-Region
X-GeoIP-Region-Code
X-Frame-Option
X-Forwarded-Site
X-Block-Status
X-VG-TLSProxy
X-Gen-Mode
X-FC-Vary-Parameters
X-Device-Os
X-Core-Value
X-DefElseHash
X-Cache-Tags
X-DefHash
X-Azure-Ref-OriginShield
X-App
X-Irp-Debug
X-Accel-Buffering
X-Varnish-Remaining-TTL
X-LB-NoCache
X-VarnishDD-TTL
X-Hnp-Log
X-GeoIP-Country-Code
X-WA-Info
Tube-Got-Results
X-HN
X-Varnish-CookieINHashed-On
Cache-Provider
X-Scale
X-Request-Start
CDCHOST
X-Ad-Defer-Variation
X-Cache-Id
Kp-EeAlive
Platform
X-Variation
L
X-Platform
Tube-Got-Eval
X-Origin-Expires
Click-Count-Error
X-NodeID
Cmsid
Cmstype
Vix-Hermes-Req-Id
X-Instance-Name
Datacenter
Machine
Canary
Sever-Int
Server-Hostname
Server-Ext
Ssr
State
Tube-Get-Contents
X-Wix-Viewer-Type
X-Dispatcher-Server
Click-Count-Action-Start
Adler-Geo
Origin-CC
On-Server
NGX
X-NWS-UUID-VERIFY
Origin-EX
PFcat
Is-Eu
X-Esi-Check
X-Gzip
X-DPWN-IS-SECURE
X-Eu-Site
X-V-Cache
X-Minions-Version
X-Old-Content-Length
X-Platform-Server
X-SB
X-Response-By
X-Provided-By
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Release
X-Owner
X-Planisys-CDN-TTL
X-Cache-Remote
X-CGP
X-Ckpd-Fst-Backend
Fastly-SSL
HA-Ipaddr
Producers
Environment
L5d-Success-Class
X-Csrf-Jwt
Ha-Gx-Prefs
X-Cache-FS-Status
HostName
X-CACHE-AGE
X-Air-Pt
X-Microcachable
Expect-Staple
Decoy-Debug-TTL
X-Aicache-OS
Decoy-Debug-Status
X-Tb-Optimization-Total-Bytes-Saved
Pics-Label
X-Mvc-Supplant-OutputCached
X-Cache-Backend
X-Nananana
Srvid
X-FL-EDGE
Cluster
X-FL-QIT-DEBUG
Locid
Decoy-Debug-Key
X-Tid
X-Via-CDN
Env
X-Refresh
X-DC
X-Correlation-ID
GeoIP-Latitude
X-Via-SSL
X-Via-Edge
Edge-Copy-Time
X-Zone
X-Cache-Enabled
X-ND-Cache
X-Dc
X-RCS-CacheZone
X-From
X-Presslabs-Stats
X-Trace-ID
X-VC
Time
X-Up
X-Generated-In
X-Servedbyhost
X-Vcl-Version
Memory
NtCoent-Length
SID
X-Srv
Svr
X-Cached-By
Sid
X-Debug-Cache-Fetch
X-DataCenter
X-Lambda-Id
X-Debug-Cache-Store
Cache
X-Cs
X-Webkit-CSP
X-AIR-PT
X-ZONE
X-Via-Popn
X-Edge-Pop
X-HS-Status
X-Via-Poph
X-Via-Popv
X-Nc
X-NewRelic-App-Data
X-Vgn-Hpd-Ssi
X-Vgn-Hpd-Cached
CPC-Cache
Fastly-Drupal-Html
VNS-Age
X-Vgn-Hpd-Variations-Key
X-Render-Time
X-Wa
X-Vtex-Remote-Cache
X-VCT
VNS-Cache
CPC-Age
X-HA-Backend
X-Esi
Cdn
X-Vc
X-Client-Ip
X-CCDN-CacheTTL
X-CLOUD-TRACE-CONTEXT
Server-ID
X-CCDN-Origin-Time
X-LB-ID
X-Hcs-Proxy-Type
GeoIp-Country-Code
X-Upstream-Ct
X-Upstream-Ht
X-TH-Server
X-B3-SpanId
X-Cache-Type
X-Check-Cacheable
X-ATG-Version
X-Fpc
X-AK-Request-ID
Cdncip
X-Gateway-Cache-Key
X-Gateway-Cache-Status
X-Gateway-Request-Id
Hostname
AMP-Access-Control-Allow-Source-Origin
Cdnsip
X-Via-JSL
X-Amz-Meta-Cb-Modifiedtime
X-Gateway-Skip-Cache
X-API-Version
XkeyRZ
X-Proxy-CacheRZ
Uri
X-Via-NSCOPI
True-Client-IP
X-Varnish-Authentication
X-Contensis-Viewer-Groups
X-NGINX-Cache
X-Cache-ASPX
X-Nf-Request-Id
XServer
M-TraceId
X-Varnish-Beresp-TTL
X-CSRF-TOKEN
X-CS
X-EC-Lua
True-Client-Ip
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-CF-Lambda-Version
Esi-Enabled
X-CF-Lambda-Fn
X-PAYTM-SRV-ID
Eomportal-Instance
X-Udemy-Cache-App-Namespace
OT-Force-Account-Verify
X-MSEdge-Features
X-FPC
X-MP-GENERATED-AT
X-MSEdge-Flight
Resin-Trace
X-Datadome
Srv
X-Micro-Cache
X-Wikidot-Static-Cache
N-Cache
CDN
X-Wikidot-Backend
Ngx-Var-Key
YJS-ID
Request-ID
RNT-Time
RNT-Machine
GeoIP-Country-Code
X-Fastly-Country-Code
X-CDN-Cache-Status
X-Bl-Debug
X-Tenant
X-Shop-Environment
X-Orig-Expires
X-Forwarded-Path
Path
X-APP-VERSION
X-VCL-Version
X-RateLimit-Reset
X-Cache-Ttl
X-SIPLIST1
X-Cache-NGX
Server-Id
IsBot
X-Request-URI
X-B3-Trace-ID
X-App-Name
X-Policy
X-Lb-Id
Sm-Log-Id
X-Info
LB
X-Service-Response-Time
X-Ha-Backend
Lb
X-Accel-Version
X-TX-ID
X-WA
X-MCACHE
X-Edge-POP
X-Pod-Name
Cross-Origin-Opener-Policy-Report-Only
X-Datacenter
Location
X-Cdn-Cache-Status
HIT
X-Github-Request-Id
Hit
X-Via-PopH
X-NC
X-Via-PopN
X-Via-PopV
Ohc-File-Size
X-Vcache
X-SERVER-NAME
X-Geo
X-Akamai-Pragma-Client-IP
X-Logging-Id
X-Srcache-Store-Status
X-Cache-Expires
Proxy-Connection
Pramga
X-Cdn-Request-ID
Timeexpire
X-Oss-Hash-Crc64ecma
X-Oss-Server-Time
Servername
X-Srcache-Fetch-Status
X-Snapshot-Date
FSS-Cache
X-Oss-Storage-Class
X-CACHE-KEY
X-Oss-Object-Type
X-Cdn-Diag
X-Oss-Request-Id
X-Git-Commit
X-ID
X-Container-Uri
Req-ID
X-Ctl-Mach
Yjs-Id
X-ServedByHost
Epwk-X-Cache
ENV
Warning
X-Amz-Meta-Opti
X-Hyper-Cache
WZWS-RAY
X-Tncms
X-Serial
X-Dw-Trace-Id
X-LiteSpeed-Cache-Control
X-Fastly-Backend-Reqs
XM
X-UP
X-Scheme
Geoip-Latitude
X-VG-WebCache
X-Cdn-Forward
X-MiniProfiler-Ids
X-M-Reqid
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-M-Log
X-Acquia-Application-UUID
X-Acquia-Application-Trace
X-Acquia-Purge-Cdn-Unconfigured
X-B3-Parentspanid
X-Moov-Xdn-Version
X-Qnm-Cache
X-Iauth-Set-Uid
X-Swift-Error
X-Acquia-Purge-Tags
X-RAMCache
X-Acquia-Site
CDN-RequestPullCode
Traceparent
X-Moov-T
Cneonction
X-TraceId
CDN-RequestPullSuccess
Content-Style-Type
V-Age
Content-Script-Type
X-Lb-Nocache
True-Client-Country-4JS
Ec-Rule-Version
CountryCode
X-F-Status
X-Wp-Cf-Super-Cache-Cache-Control
X-Lsadc-Cache
X-TT-LOGID
X-UA
X-Wp-Cf-Super-Cache
X-Viewer-Country
X-ApacheServer
MIME-Version
X-IPS-Cached-Response
X-B3-ParentSpanId
X-Clientip
X-Mg-Cache
Ohc-Cache-HIT
X-Cache-Ngx
My-App
X-Fastly-Cache-Hits
X-Th-Server
X-PERF
X-Request-URL
X-Mid-Debug-Cache-Key
X-Mid-Debug-Cache-Disk
X-LiteSpeed-Tag
Inserted-Into-Cache-At
Ngx
X-Webstats-RespID
X-Litespeed-Cache-Control