Threat Level: green Handler on Duty: Russ McRee

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Accept-Ranges
X-XSS-Protection
Expect-CT
Pragma
X-Powered-By
CF-RAY
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-Xss-Protection
X-Download-Options
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
CF-Ray
X-Adblock-Key
X-Request-ID
Access-Control-Allow-Credentials
X-FRAME-OPTIONS
X-Permitted-Cross-Domain-Policies
X-Request-Id
X-AspNet-Version
Alt-Svc
X-Runtime
Content-Security-Policy-Report-Only
X-DNS-Prefetch-Control
X-Drupal-Cache
X-Check
X-Cache-Status
X-Generator
X-Cacheable
Timing-Allow-Origin
X-Iinfo
X-Envoy-Upstream-Service-Time
X-Content-Security-Policy
X-Drupal-Dynamic-Cache
Feature-Policy
Content-Encoding
Upgrade
Access-Control-Expose-Headers
Status
X-CDN
X-AspNetMvc-Version
P3p
Access-Control-Max-Age
X-Via
Server-Timing
X-UA-Device
X-Robots-Tag
Request-Context
X-Turbo-Charged-By
X-Cache-Group
EagleId
X-Amz-Request-Id
X-Amz-Id-2
X-Backend
Keep-Alive
X-AH-Environment
X-Proxy-Cache
X-Ws-Request-Id
X-Server
X-Ua-Compatible
X-Age
Host-Header
X-Hacker
Cf-Edge-Cache
X-Vhost
X-Server-Powered-By
X-Rq
X-Varnish-Cache
Allow
X-Dispatcher
X-Amz-Version-Id
Grace
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-LiteSpeed-Cache
X-OneAgent-JS-Injection
X-WebKit-CSP
Accept-CH
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Page-Speed
Cf-Apo-Via
X-Device
Cf-Railgun
X-Aws-Lambda-Call-Status
X-Server-Id
X-Host
X-Node
X-Pingback
X-Cache-Spec
X-Nginx-Cache-Status
X-Dns-Prefetch-Control
X-Akam-SW-Version
Surrogate-Control
EagleEye-TraceId
X-Backend-Server
Request-Id
X-Ruxit-JS-Agent
X-Readtime
X-Cache-Lookup
X-HW
X-Cloud-Trace-Context
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Content-Security-Policy-Report-Only
Accept-CH-Lifetime
X-Trace
X-Application-Context
X-Response-Time
Permissions-Policy
Fastly-Restarts
X-Nginx-Upstream-Cache-Status
X-Mod-Pagespeed
X-Edge
X-CST
X-WebKit-CSP-Report-Only
Accept-Ch-Lifetime
Content-Location
X-Content-Type
X-Url
X-Mcache
X-MS-InvokeApp
X-Clacks-Overhead
X-Country
Rating
X-Midtier
X-PC
X-Vname
X-TtlSet
X-Amz-Server-Side-Encryption
X-ECACHE
RTSS
X-VARITI-CCR
Cache-Tag
X-D2id
X-Vcap-Request-Id
X-ESI
X-Element-Page-Cache
Origin-Trial
X-Litespeed-Cache
X-Server-Name
Verso
X-Ac
X-Kinja
X-Kinja-Build
X-Use-Magma
X-Exp-Variant
X-Exp-Id
X-Kinja-Server
X-Kinja-Revision
X-Cdn-Fetch
X-GoogleNews-Bot
X-Ttl
X-Rack-Cache
X-Varnish-TTL
X-Cnection
X-Powered-By-Plesk
Service-Worker-Allowed
X-GitHub-Request-Id
X-Cache-TTL
Xkey
X-Navigation-Version
X-B3-TraceId
X-Client-IP
X-SharePointHealthScore
SPRequestGuid
X-Abt-Application-Version
X-Amz-Rid
Edge-Control
X-NWS-LOG-UUID
X-Cached
Arr-Disable-Session-Affinity
SPIisLatency
SPRequestDuration
X-Px
X-Mg-S
X-Erf-Bev-Bev-Is-Generated
X-Browser-Type
X-Upstream
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-Instrumentation
X-Erf-Bev-Bev
X-Cache-Key
X-Correlation-Id
X-Dw-Request-Base-Id
X-Sol
X-Middleton-Display
Display
Pagespeed
Content-MD5
X-SRCache-Fetch-Status
X-SRCache-Store-Status
Access-Control-Request-Method
X-NF-Request-ID
Edge-Cache-Tag
X-Goog-Hash
X-XRDS-Location
Front-End-Https
X-Country-Code
X-Fastcgi-Cache
X-Forwarded-For
X-Daa-Tunnel
X-Version
Public-Key-Pins
X-Id
X-Powered-CMS
TCN
AR-CACHE
AR-PoweredBy
AR-SID
AR-ATIME
AR-Request-ID
X-HP-Webp
X-HP-Trace-Id
X-Jurisdiction
X-Recruiting
X-T
X-Content-Digest
X-MSEdge-Ref
X-RateLimit-Remaining
X-Accel-Expires
X-Middleton-Response
Response
X-Ser
X-Shield-Request-Id
TP-L2-Cache
TP-Cache
X-Amzn-Trace-Id
Mrf-Cache-Status
X-B3-TraceId-Primal
MRF-Tech
Nginx-Cache
S
X-Webkit-Csp
X-Request-Processing-Time
X-Ratelimit-Limit
X-Request-Received
X-HS-Hub-Id
X-HS-Cache-Config
Server-Node
X-HS-Combine-CSS
X-HS-Content-Id
MicrosoftSharePointTeamServices
X-Distributor
X-Hits
Cache-Status
X-FastCGI-Cache
Cache-Tags
X-Kinsta-Cache
X-Edge-Location-Klb
X-Grace
Fastcgi-Cache
Server-Name
Alternate-Protocol
X-Ratelimit-Remaining
X-Fastly-Request-ID
X-DataDome
X-Ezoic-Cdn
X-DIS-Request-ID
X-LB-Cache
X-Origin-Server
X-Protected-By
X-Ua-Browser
X-Ratelimit-Reset
X-Geo-Country
X-Request-Handler-Origin-Region
X-Microsite
X-Frontend
X-Rid
Cross-Origin-Opener-Policy
Filterid
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-TEC-API-ROOT
X-Debug-Info
X-Varnish-Backend
Healthy
X-Www-Served-By
X-Logged-In
X-Git-Hash
Payment
X-FB-Debug
Cleartype
X-Forwarded-Proto
X-Page-Id
X-NGENIX-Cache
X-Load-Cache
X-LLID
X-ASPNET-VERSION
Charset
X-Hostname
X-Cluster-Name
X-Origin-Cache
X-B3-Sampled
Content-Disposition
DC
MS-Author-Via
X-Goog-Metageneration
X-Ruxit-Js-Agent
X-GUploader-UploadID
X-VCache
Accept-Ch
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-ORACLE-DMS-RID
X-PressLabs-Stats
X-ORACLE-DMS-ECID
Access-Control-Allow-Method
X-Upgrade-Enabled
X-Proxy
Retry-After
Realpath
X-F-Cache
X-AppVersion
X-Az
Cross-Origin-Resource-Policy
X-Activity-Id
Accept-Charset
X-Amz-Replication-Status
Paypal-Debug-Id
X-Type
X-TTL
X-Contextid
X-B-Cache
X-Amz-Meta-S3cmd-Attrs
X-Revision
X-Signature
X-Seen-By
Viewport
X-Aspnet-Duration-Ms
X-Flags
X-Request-Guid
X-Route-Name
X-Whom
X-Providence-Cookie
X-Is-Crawler
X-B3-Traceid
X-Hosted-By
X-Fb-Rlafr
X-Azure-Ref
X-Wix-Request-Id
X-Aspnetmvc-Version
X-App-Environment
Surrogate-Key
X-TT
X-DynaTrace
X-B
X-Varnish-Server
Count-Hit
Amp-Access-Control-Allow-Source-Origin
X-Oracle-Dms-Ecid
X-Oracle-Dms-Rid
X-Source
X-Akamai-Edgescape
X-Language
Referer-Policy
X-App-Server
X-Mobile
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Goog-Generation
X-Template
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Cache-Control
X-RateLimit-Limit
X-COUNTRY
Host
X-Magnolia-Registration
X-Varnish-Grace
Version
X-EdgeConnect-Cache-Status
X-HTML-Minification-Powered-By
X-N
X-Cache-Rule
SRV
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Response-Served-From
X-Tumblr-User
X-Original-Request-Id
X-Tumblr-Pixel-1
MS-CV
X-UUID
X-Varnish-Age
X-RTag
X-Trace-Id
X-Cache-Time
Ms-Operation-Id
X-Rule
X-Envoy-Decorator-Operation
X-Cache-Expired-At
Section-Io-Cache
Access-Control-Request-Headers
VIX-Pulpo-Node
X-Framework
SD-X-WS
X-Cache-Status-Check
X-Content-Powered-By
VIX-Pulpo-Upstream-Status
Akamai-GRN
X-Backend-Name
X-Cache-Grace
X-Adobe-Loc
X-Adobe-Content
X-Cacheable-TTL
Protected
X-Device-Type
X-FW-Version
X-FW-Hash
X-Page-View
X-FW-Server
X-ProcessESI
X-RemovedCookies
X-Jobs
X-FW-Serve
X-User-Agent
Refresh
X-FW-Static
X-FW-Type
X-FW-Dynamic
X-Rendered-As
X-Servername
X-Instance
X-Is-Bot
GEO-INFO
NGB
X-Environment-Context
X-NYM-Debug-Backend
X-L-Path
Url
X-G
X-Status
X-Akamai-Request-ID2
X-Http-Reason
X-Cache-Age
X-Drupal-Cache-Contexts
X-Drupal-Cache-Tags
X-CDN-Forward
X-Debug-IsPreview
From-Origin
X-Debug-IsConnected
CDN-RequestId
WPO-Cache-Message
X-Fastly-Request-Id
WPO-Cache-Status
X-Region
X-Yottaa-Metrics
X-Cache-Hit
X-Yottaa-Optimizations
Front
Accept-Language
X-Nginx-Cache
X-Amz-Apigw-Id
X-Amzn-RequestId
Country
X-Tb
X-ECache
X-Newrelic-App-Data
X-Times
X-Tt-Logid
X-Node-Name
X-Pinterest-Rid
Pinterest-Version
Pinterest-Generated-By
Backend
X-Content-Options
Fastly-SIE
X-Unique-Id
Fastly-SWR
X-Real-IP
X-TIME
X-Tec-Api-Version
X-Tec-Api-Root
X-Tec-Api-Origin
X-Zen-Fury
Uber-Trace-Id
X-VC-Cache
X-DynaTrace-JS-Agent
X-Mode
X-Buckets
Fastly-Drupal-HTML
Content-Secure-Policy
X-Cache-Operation
X-Rewrite-Enabled
X-Proxy-Cache-Info
X-RN-RSRV
X-Ms-Request-Id
X-Ms-Version
X-Generation-Time
Meta-Geo
X-Air-Hostname
X-Air-Source
X-Air-Trace-Id
Webserver
Filters
X-Tumblr-Pixel-2
X-UPSTREAM-Address
X-Amzn-Remapped-Content-Length
X-Cache-Server
Onion-Location
X-Format
CF-IPCountry
X-Reqid
X-Rocket-Nginx-Serving-Static
X-Web-Node
X-Section
Cache-Hits
Azure-Version
Azure-InstanceId
X-Content-Age
Azure-RegionName
Azure-SiteName
Azure-SlotName
X-IPS-LoggedIn
X-Access
X-Cache-TTL-Remaining
X-Cache-Host
X-Cache-Action
X-BYPASS-REASON
X-Cluster
X-Cluster-Node
X-IPLB-Instance
X-Debug
X-Cms-Context
X-AWS-Id
X-Adobe-Source
TWC-GeoIP-LatLong
TWC-GeoIP-Country
TWC-Device-Class
TWC-Connection-Speed
TWC-Locale-Group
TWC-Privacy
Webcakes-Region
Webcakes-App-Version
Webcakes-App-Name
X-IPLB-Request-ID
X-LJ-Flow-ID
X-Sql-Duration-Ms
X-Sql-Count
X-Soup
X-Server-W
X-Sucuri-ID
X-Ua
X-VWS-Id
X-Via-Fastly
X-UA-Device-Type
X-SayCDN-TTL
X-Say-TTL
X-Proto
X-PHP-Backend
X-Origin-Hint
X-Locale
X-Proxy-Cache-Status
X-ProxyCache-Key
X-Say-Cacheable
X-R9-Blue-Green-Version
X-ProxyCache-Status
Property-Id
X-Sucuri-Cache
Apigw-Requestid
Node
S-Rt
ServerID
ServedBy
X-Skip-Cache
Cache-Name
X-No-Session
X-Varnish-Beresp-Grace
Web-Mar-Node
X-Site-Version
X-Labrador-Cache-Channel
X-Handled-By
DB-Nickname
X-PHP-Host
X-Forwarded-Host
Cross-Origin-Window-Policy
X-JoinUs
X-LSADC-Cache
X-SaId
X-GeoCode
X-Proxied
X-LAGOON
Liferay-Portal
X-FB-TRIP-ID
X-Routing-Service
X-Edge-Location
X-Detected-As
Mn-Server-Ip
X-GeoCountry
X-Timing-Wait
X-Proxy-Build
X-Extlb
X-Zipkin-Id
Selected-Fe
X-Xfnlog-Site
X-Urbn-Context-Path
X-Server-ID
X-WP-CF-Super-Cache
CDN-EdgeStorageId
CDN-CachedAt
X-Urbn-Site-Id
Mime-Version
Locale
WP-Super-Cache
CDN-RequestCountryCode
CDN-PullZone
CDN-Uid
X-WP-CF-Super-Cache-Cache-Control
CDN-Cache
Fastcgi-Useragent
X-Hl-Ver
X-Optimistic-Header
X-SRV
X-Time
X-XRDS-LOCATION
Source
X-Tumblr-Pixel-3
X-Origin-Date
X-Request-Time
X-Oneagent-Js-Injection
X-CACHE-AGE
CF-Cached-On
X-Cache-Debug
X-Presslabs-Stats
X-Redis-Cache
X-Uri
Upgrade-Insecure-Requests
X-GEO
X-TNCMS
X-Generated-By
X-Mg-Request-UUID
X-Loop
X-Akamai-Transformed
X-Director
X-Varnish-Hits
Countrycode
X-ARC
Xet-Cookie
X-App-Version
X-Tx-Id
Xserver
X-Pass-Why
X-NWS-UUID-VERIFY
Frame-Options
X-URL
X-Origin-TTL
X-Origin-CC
X-FireWall-Port
Cache-Tv-Group
X-Varnish-Beresp-Ttl
X-Varnish-Ttl
X-Varnish-Cache-Hits
X-Newrelic-Synthetics
X-Storage
X-Tid
X-TA-CDN-Provider
X-Storefront-Renderer-Rendered
X-ShopId
X-Service
X-Alternate-Cache-Key
X-ShardId
X-Shopify-Stage
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Varnish-Hostname
X-Datadog-Sampled
X-Datadog-Sampling-Priority
X-Datadog-Trace-Id
X-RM-Cache-TTL
X-Datadog-Parent-Id
X-ServerID
X-Endurance-Cache-Level
X-B3-Spanid
Environment
X-DC
X-Frame-Option
X-Gdpr
X-A
X-A-Ccd
X-Generated-On
X-Httpd
X-Thinkindot-L3
Cache-Host
X-BCube-Filmed-By
X-Bc-Bl
X-B-Cookie
DCR-Processing-Time-Ms
BehaviorPad-Version
DCR-Decision-By
WWW-Authenticate
X-Epic-Correlation-Id
X-D
X-A-Dam
X-Ec-Fail
X-Aed
X-A-Wwc
X-A-Dcw
X-A-Dgt
X-Destination
X-Developer
X-INCAP-ABP
X-Core-Value
X-Cache-NE
X-Ec-GeoHdr
X-Cache-Info
X-External-Request-Id
A
X-Application
Candidate-Md5Url
X-Conf
X-CMSURLCustom
X-Request-Host
X-Mid
Redirect-Candidate
Origin
MD5-Digest
X-BBC-Edge-Cache-Status
Release
Odigeo-Trace-Id
Gannett-Cam-Experience-Id
X-Sigma-Backend
T-Server
X-Sigma
X-Served-From
Xc-Version
X-Vdms-Path
X-ScT
Sslversion
X-S-Maxage
X-S-Cookie
Req-Svc-Chain
Host-ID
X-S
X-Rojux
X-We-Are-Hiring
X-Vdms-Version
Rendered-Blocks
X-VG-TLSProxy
X-Rocket-Build-Number
X-Processor
Surrogated-Key
X-Loc
Thinkindot-CacheControl
X-Level-Front-Cache
X-Origin-Time
Thinkindot-CacheControl-Type
Memcached
X-Mobile-URL
X-Nyt-Route
X-Location
Edge-Cache
Thinkindot-Control
X-Platform-Cluster
TDXMobile
X-SRCache-Key
Lang
X-TIM-N
X-Platform-Processor
Ngx.Var.Host
X-Platform-Router
X-Test
Meta-Geo-Continent
Server-Info
Tube-Get-Contents
Tube-Got-Results
Server-Host
Ssr
State
Tube-Got-Eval
We-Hiring
NM-Fastcgi-Cache
X-Akamai-Device-Characteristics
Tube-Return
X-Auto-Login
X-Pool
X-Worker
X-Restarts
X-WADP-Cache
X-WA-Info
X-WP-CF-Super-Cache-Active
X-Req
X-Org
X-Origin-Response-Time
X-Platform-Server
X-Pubstack
X-VServer
X-Vmg-Version
X-Sn-Servicetimems
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-Thanos
X-Varnish-Beresp-Status
X-Varnish-CookieHashed-On
X-SB
X-Varnish-Remaining-TTL
X-Varnish-CookieINHashed-On
X-SD-PageType
X-Old-Content-Length
X-NodeID
X-DefElseHash
X-DefHash
X-Developers
X-Ec-Custom-Error
X-CUA
X-Core-Mission
X-Cache-Bucket
X-Cdn-Origin
X-Cdn-Srv
X-Clara-WADP
X-Fetched-On
X-Fmm-Version
X-HS-Content-Campaign-Id
X-Human
X-Is-Gdpr
X-JWT-State
X-Hash
X-Has-Esi
X-Geo-Header
X-GeoIP
X-GeoIP-City
X-Bip
Vix-Hermes-Req-Id
Decoy-Debug-Key
Country-Code
Cluster
CloudFront-Viewer-Country
Decoy-Debug-Status
Decoy-Debug-TTL
Fastly-GeoIP-CountryCode
Fastly-Backend-Name
DSUID
Click-Count-Error
Click-Count-Action-Start
Apple-News-Services-Handled
AKAMAI
Mail-Subject
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
CacheControlHeader
C-Via
Apple-News-Services-Request-Url
Gh-Request-Id
Cache-Key
Magicmarker
Section-Io-Id
Section-Io-Origin-Time-Seconds
X-Parent-Response-Time
Section-Io-Origin-Status
Section-Origin-Responded
X-Ckpd-Fst-Backend
X-CacheTTL
X-Scale
X-Region-Sid
X-Device-Os
X-Platform
X-Date
X-Qloud-Router
X-Request-Start
X-Slack-Backend
L
X-Block-Status
X-Irp-Debug
X-Azure-Ref-OriginShield
Cache-Provider
X-Cache-Backend
X-Slack-Shared-Secret-Outcome
X-Dispatcher-Number
Adler-Geo
Machine
NGX
X-Cache-Tags
X-Owner
X-Men
X-Minions-Version
X-Gen-Mode
X-Mvc-Supplant-Cachable
X-LB-NoCache
X-GeoIP-Country-Code
X-Hnp-Log
X-HN
X-Gzip
X-GeoIP-Region-Code
X-Gamma-Serve
X-NCache
X-Op-Id-All
X-Origin
On-Server
X-DPWN-IS-SECURE
X-Esi-Check
X-Node-Id
X-FC-Vary-Parameters
X-Nginx-Cache-Key
X-Fastly-Backend
X-Dispatcher-Server
X-Cache-Id
Origin-EX
Producers
X-Varnishpool
Cmstype
X-Cache-Date
Origin-CC
X-Var-Ttl
X-VarnishDD-TTL
Wxu-Next-Region
Wxu-Next-Commit
Cmsid
Pics-Label
Platform
Wxu-Next-Hostname
Datacenter
X-Variation
Kp-EeAlive
X-App
Server-Hostname
X-Wix-Viewer-Type
Server-Ext
PFcat
SID
Canary
CDCHOST
Sever-Int
User-Cache-Control
X-V-Cache
X-Accel-Buffering
X-Accel-Expires-Debug
X-Ad-Defer-Variation
Is-Eu
Web-Mar-Region
X-Nananana
Ha-Gx-Prefs
HA-Ipaddr
Fastly-SSL
Svr
X-Forwarded-Site
X-Eu-Site
X-Planisys-CDN-Cache
X-CGP
X-Refresh
X-Planisys-CDN-Rules
X-Server-IP
X-Csrf-Jwt
X-Up
L5d-Success-Class
X-Planisys-CDN-TTL
X-AIR-PT
X-Webkit-CSP-Report-Only
X-Mvc-Supplant-OutputCached
X-Cache-FS-Status
X-Microcachable
X-Cache-Remote
X-Mly-Id
Load-Balancing
Env
X-CSRF-Token
X-Aicache-OS
X-Tb-Optimization-Total-Bytes-Saved
GeoIP-Latitude
X-Servedbyhost
X-RCS-CacheZone
X-Fastly-Cache
X-Via-Popv
X-Via-Popn
X-Via-Poph
X-Cached-By
Cdn
X-Trace-ID
X-Api-Version
HostName
X-Instance-Name
X-ND-Cache
X-Nc
X-Origin-Expires
X-HA-Backend
X-Zone
X-Vc
X-Release
X-Wa
Cdncip
Cdnsip
X-HS-Status
Server-ID
Memory
Time
X-VC
X-Response-By
X-AK-Request-ID
X-NewRelic-App-Data
X-DataCenter
X-ZONE
Cache
X-NGINX-Cache
X-Webkit-CSP
Expect-Staple
X-Generated-In
X-Gateway-Cache-Status
X-Gateway-Cache-Key
X-Gateway-Request-Id
Srvid
Locid
X-FL-EDGE
X-FL-QIT-DEBUG
X-Gateway-Skip-Cache
X-From
X-Esi
X-API-Version
Hostname
X-Via-CDN
X-Cache-Enabled
X-Via-NSCOPI
X-Edge-Pop
X-Fpc
X-Correlation-ID
NtCoent-Length
X-Provided-By
X-Hcs-Proxy-Type
X-LB-ID
Edge-Copy-Time
X-Via-Edge
X-Via-SSL
X-Client-Ip
X-CCDN-Origin-Time
X-CCDN-CacheTTL
GeoIp-Country-Code
X-Check-Cacheable
X-CSRF-TOKEN
X-CS
X-Air-Pt
X-Vgn-Hpd-Variations-Key
X-Vgn-Hpd-Cached
X-Vgn-Hpd-Ssi
Eomportal-Instance
X-Dc
X-Srv
X-Vcl-Version
True-Client-IP
X-APP-VERSION
X-Micro-Cache
X-Lambda-Id
AMP-Access-Control-Allow-Source-Origin
X-Debug-Cache-Store
X-Debug-Cache-Fetch
Ngx-Var-Key
X-Proxy-CacheRZ
XkeyRZ
X-Amz-Meta-Cb-Modifiedtime
X-Via-JSL
Sid
X-MCACHE
OT-Force-Account-Verify
CPC-Age
IsBot
CPC-Cache
X-Nf-Request-Id
VNS-Age
VNS-Cache
X-Render-Time
X-SIPLIST1
X-Request-URI
X-Vtex-Remote-Cache
X-Cs
X-VCL-Version
X-Info
X-Cache-NGX
Path
X-EC-Lua
X-B3-SpanId
X-VCT
X-TH-Server
X-Fastly-Country-Code
True-Client-Ip
Uri
Srv
Fastly-Drupal-Html
Location
X-ATG-Version
Request-ID
X-Cache-ASPX
X-MSEdge-Flight
X-MSEdge-Features
X-Contensis-Viewer-Groups
Resin-Trace
Esi-Enabled
X-Varnish-Authentication
X-Upstream-Ct
X-Upstream-Ht
X-Oss-Object-Type
CDN
X-Oss-Hash-Crc64ecma
M-TraceId
GeoIP-Country-Code
X-Cache-Type
X-CLOUD-TRACE-CONTEXT
X-Oss-Storage-Class
X-Cache-Expires
X-Oss-Server-Time
X-Oss-Request-Id
YJS-ID
X-Cdn-Request-ID
X-Accel-Version
X-PAYTM-SRV-ID
X-CF-Lambda-Version
X-FPC
Servername
X-Varnish-Beresp-TTL
X-CF-Lambda-Fn
X-Lb-Id
X-RateLimit-Remaining-Second
Cross-Origin-Opener-Policy-Report-Only
X-RateLimit-Limit-Second
X-Edge-POP
X-TX-ID
X-Udemy-Cache-App-Namespace
XServer
X-Pod-Name
X-Akamai-Pragma-Client-IP
RNT-Machine
RNT-Time
N-Cache
X-Service-Response-Time
X-Datadome
X-Wikidot-Backend
X-CDN-Cache-Status
X-Moov-Xdn-Version
Traceparent
LB
Sm-Log-Id
X-Datacenter
Timeexpire
X-RateLimit-Reset
X-Scheme
X-Wikidot-Static-Cache
X-Moov-T
CountryCode
HIT
X-Shop-Environment
X-Forwarded-Path
X-Bl-Debug
X-Tenant
Server-Id
X-Viewer-Country
X-PERF
X-Orig-Expires
X-ApacheServer
X-Cdn-Cache-Status
X-SERVER-NAME
X-WA
X-MP-GENERATED-AT
X-Geo
Proxy-Connection
X-B3-Trace-ID
X-Ha-Backend
FSS-Cache
X-CACHE-KEY
Ohc-File-Size
X-NC
X-Srcache-Fetch-Status
X-Srcache-Store-Status
X-LiteSpeed-Cache-Control
X-Policy
X-App-Name
Yjs-Id
ENV
X-Via-PopH
X-Via-PopN
X-Via-PopV
Epwk-X-Cache
X-ServedByHost
X-NAPM-TraceId
Powered-By
X-TraceId
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-Dw-Trace-Id
X-Cdn-Forward
X-Hyper-Cache
WZWS-RAY
X-Amz-Meta-Opti
Geoip-Latitude
X-M-Reqid
X-MiniProfiler-Ids
X-M-Log
Rip
X-Acquia-Site
X-Acquia-Purge-Tags
X-Acquia-Application-Trace
X-Acquia-Application-UUID
X-Qnm-Cache
Content-Style-Type
X-RAMCache
X-Snapshot-Date
Content-Script-Type
Hit
User-Agent
X-UP
X-B3-Parentspanid
X-Fastly-Backend-Reqs
Ngx
X-Clientip
V-Age
Inserted-Into-Cache-At
True-Client-Country-4JS
X-Vgn-Hpd-Reason
Tracecode
X-Serial
Cneonction
X-Swift-Error
X-Lb-Nocache
Ec-Rule-Version
X-Lsadc-Cache
X-TT-LOGID
X-Wp-Cf-Super-Cache-Cache-Control
X-F-Status
X-Wp-Cf-Super-Cache
X-VG-WebCache
Lb
X-Webstats-RespID
X-Fastly-Cache-Hits
X-Mid-Debug-Cache-Key
Warning
X-IPS-Cached-Response
MIME-Version
My-App
X-LiteSpeed-Tag
X-B3-ParentSpanId
X-Cache-Ngx
X-Stale
X-Mid-Debug-Cache-Disk
X-Th-Server
X-Request-URL
XM