Threat Level: green Handler on Duty: Johannes Ullrich

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
CF-RAY
Cf-Request-Id
CF-Cache-Status
Accept-Ranges
Link
ETag
Pragma
Expect-CT
X-XSS-Protection
X-Powered-By
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Report-To
NEL
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
Alt-Svc
P3P
X-Served-By
X-Xss-Protection
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Request-Id
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
X-Runtime
X-AspNet-Version
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Cache-Status
X-Generator
X-Check
X-Cacheable
Timing-Allow-Origin
X-FRAME-OPTIONS
X-Content-Security-Policy
Feature-Policy
X-Iinfo
X-Request-ID
X-Envoy-Upstream-Service-Time
Content-Encoding
Status
P3p
X-CDN
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
X-AspNetMvc-Version
X-CONTENT-TYPE-OPTIONS
Upgrade
X-Via
X-XSS-PROTECTION
X-Ws-Request-Id
Access-Control-Max-Age
Server-Timing
X-Cache-Group
X-Turbo-Charged-By
EagleId
X-Backend
Keep-Alive
Request-Context
X-Age
X-Robots-Tag
X-Server
X-AH-Environment
X-UA-Device
X-Proxy-Cache
Host-Header
X-Amz-Request-Id
X-Amz-Id-2
X-Hacker
Grace
X-Rq
X-Dns-Prefetch-Control
X-Swift-SaveTime
X-Swift-CacheTime
X-Server-Powered-By
Ali-Swift-Global-Savetime
X-Varnish-Cache
X-Vhost
X-LiteSpeed-Cache
X-Amz-Version-Id
CONTENT-SECURITY-POLICY
X-WebKit-CSP
EagleEye-TraceId
X-Nginx-Cache-Status
X-Dispatcher
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Cache-Spec
X-OneAgent-JS-Injection
X-Device
Cf-Railgun
X-Page-Speed
X-Host
Allow
X-Node
X-Akamai-Path-Stats
X-Pingback
X-Server-Id
Accept-CH
Surrogate-Control
X-Backend-Server
X-Aws-Lambda-Call-Status
Request-Id
X-CST
X-Akam-SW-Version
X-Readtime
X-HW
X-Cache-Lookup
X-Response-Time
Accept-CH-Lifetime
X-Application-Context
Xkey
Content-Location
X-ASPNET-VERSION
X-Cloud-Trace-Context
Rating
X-Ua-Compatible
X-Trace
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Url
X-Country
Cf-Edge-Cache
Fastly-Restarts
Accept-Ch-Lifetime
X-Vname
X-TtlSet
X-PC
X-Mod-Pagespeed
X-Ruxit-JS-Agent
X-Server-Name
X-Rack-Cache
X-MS-InvokeApp
X-Clacks-Overhead
Edge-Control
RTSS
X-Content-Type
X-ESI
X-Varnish-TTL
X-B3-TraceId
X-VARITI-CCR
Cache-Tag
X-Vcap-Request-Id
X-Px
X-Ac
X-Kinja-Build
X-Kinja-Server
X-Amz-Rid
X-Kinja-Revision
X-Kinja
X-Cdn-Fetch
X-Use-Magma
X-Exp-Variant
X-GoogleNews-Bot
X-Exp-Id
Public-Key-Pins
X-Cnection
X-Dw-Request-Base-Id
X-Element-Page-Cache
Verso
X-D2id
X-Cache-TTL
X-Amz-Server-Side-Encryption
X-Navigation-Version
X-RateLimit-Remaining
Accept-Ch
X-Abt-Application-Version
X-Client-IP
X-Powered-By-Plesk
Service-Worker-Allowed
X-FastCGI-Cache
X-Country-Code
X-GitHub-Request-Id
X-Middleton-Display
Pagespeed
Display
X-Sol
X-Ser
Arr-Disable-Session-Affinity
X-Version
X-Ruxit-Js-Agent
X-NF-Request-ID
Access-Control-Request-Method
X-Middleton-Response
Response
X-Goog-Hash
X-Edge
X-Upstream
X-Correlation-Id
AR-PoweredBy
AR-Request-ID
AR-ATIME
AR-CACHE
AR-SID
X-Kinsta-Cache
X-Ttl
X-Edge-Location-Klb
X-Cached
X-Webkit-Csp
MS-Author-Via
X-TTL
X-LLID
X-Kraken-Loop-Name
SPRequestDuration
X-Instrumentation
X-Server-Lifecycle-Phase
SPIisLatency
Nginx-Cache
X-NWS-LOG-UUID
X-Powered-CMS
X-RateLimit-Limit
Edge-Cache-Tag
TCN
X-Cache-Key
MRF-Tech
X-Litespeed-Cache
Mrf-Cache-Status
X-MSEdge-Ref
X-Forwarded-For
X-SharePointHealthScore
SPRequestGuid
Content-MD5
X-Shield-Request-Id
X-Id
X-B3-TraceId-Primal
X-Content-Security-Policy-Report-Only
X-T
X-Daa-Tunnel
X-Recruiting
S
X-Mg-S
X-Language
X-Protected-By
X-Content-Digest
X-HP-Trace-Id
X-HP-Webp
X-Jurisdiction
X-Ua-Device
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Frontend
X-HS-Cache-Config
X-HS-Content-Id
X-HS-Hub-Id
X-Yandex-Sdch-Disable
X-Ua-Browser
X-Ab
X-Content
Server-Node
X-HS-Combine-CSS
X-Request-Processing-Time
X-Ezoic-Cdn
Front-End-Https
X-Request-Received
X-TEC-API-ROOT
X-TEC-API-VERSION
Filters
X-TEC-API-ORIGIN
MicrosoftSharePointTeamServices
X-Grace
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
Fastcgi-Cache
X-Accel-Expires
X-Mid
X-DataDome
X-Server-ID
X-Template
X-ECACHE
Pinterest-Generated-By
X-Pinterest-Rid
Pinterest-Version
X-Geo-Country
X-Hits
X-Ratelimit-Reset
X-Debug-Info
X-Origin-Server
X-Distributor
TP-L2-Cache
TP-Cache
X-Amzn-Trace-Id
X-Tt-Trace-Host
X-Tt-Trace-Tag
Charset
Cleartype
Host
X-Page-Id
X-Git-Hash
X-DIS-Request-ID
X-F-Cache
Cross-Origin-Opener-Policy
X-B3-Sampled
X-Www-Served-By
X-DynaTrace
X-MCACHE
Cache-Tags
ServerID
X-Kong-Proxy-Latency
X-LB-Cache
X-Kong-Upstream-Latency
X-Forwarded-Proto
Access-Control-Allow-Method
X-PressLabs-Stats
Server-Name
X-Seen-By
X-Cache-Age
Realpath
X-Cluster-Name
X-AppVersion
X-Origin-Cache
X-Az
X-WebKit-CSP-Report-Only
X-Activity-Id
Accept-Charset
X-Varnish-Age
X-Aspnetmvc-Version
X-Oracle-Dms-Ecid
X-Rid
X-Oracle-Dms-Rid
X-Content-Options
Filterid
X-Type
X-Mobile-URL
X-App-Environment
X-Upgrade-Enabled
X-Request-Handler-Origin-Region
X-Microsite
Cache-Status
X-FB-Debug
X-Via-JSL
X-Varnish-Grace
Node
Viewport
Country
X-User-Agent
X-Tb
X-Wix-Request-Id
Paypal-Debug-Id
X-Flags
X-Drupal-Cache-Tags
DC
X-Aspnet-Duration-Ms
X-Request-Guid
X-Signature
X-Whom
X-Route-Name
X-B-Cache
X-Is-Crawler
X-Providence-Cookie
X-NWS-UUID-VERIFY
X-TT
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-VCache
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
X-Goog-Storage-Class
Protected
Fastcgi-Useragent
X-Fastly-Request-ID
X-XRDS-LOCATION
X-Nginx-Upstream-Cache-Status
X-Varnish-Backend
Retry-After
X-Oneagent-Js-Injection
X-Contextid
X-Amz-Replication-Status
Payment
X-Cache-NGX
X-B
X-Fastly-Request-Id
X-N
X-Fastcgi-Cache
X-Debug
X-FW-Serve
X-FW-Dynamic
X-FW-Server
X-FW-Hash
X-FW-Static
X-FW-Type
X-Logged-In
X-Parallel-Accel
X-XRDS-Location
X-Hostname
WPO-Cache-Status
WPO-Cache-Message
X-Load-Cache
Surrogate-Key
Amp-Access-Control-Allow-Source-Origin
X-Buckets
X-Node-Name
X-Cache-Control
X-Browser-Type
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Original-Request-Id
X-Response-Served-From
SD-X-WS
Count-Hit
X-Mobile
X-Proxy
Akamai-GRN
X-Is-Bot
X-Cache-Rule
X-UUID
X-Cache-Time
X-Akamai-Request-ID2
X-G
X-Jobs
X-Rendered-As
VIX-Pulpo-Upstream-Status
X-Revision
VIX-Pulpo-Node
Uber-Trace-Id
X-Zen-Fury
X-IPLB-Instance
Refresh
X-Real-IP
Healthy
X-Http-Reason
Alternate-Protocol
X-Page-View
X-Framework
X-Cacheable-TTL
X-Device-Type
X-Debug-IsConnected
NGB
X-Debug-IsPreview
X-Yottaa-Metrics
X-Instance
X-Drupal-Cache-Contexts
X-Yottaa-Optimizations
X-Proxy-Cache-Status
X-Vgn-Hpd-Reason
Access-Control-Request-Headers
X-Cache-TTL-Remaining
Content-Disposition
X-Trace-Id
From-Origin
X-Amz-Meta-S3cmd-Attrs
X-Adobe-Loc
X-Adobe-Content
X-Source
Url
X-Servername
Version
X-Cache-Expired-At
X-Cache-Grace
X-B3-Traceid
Referer-Policy
Accept-Language
X-Cache-Hit
X-Varnish-Server
X-App-Server
X-L-Path
X-Environment-Context
X-Ratelimit-Remaining
X-Cache-Action
X-EdgeConnect-Cache-Status
X-FW-Version
X-Mg-Request-UUID
X-NGENIX-Cache
MS-CV
Ms-Operation-Id
Permissions-Policy
X-RTag
Cross-Origin-Window-Policy
X-Tumblr-Pixel-0
X-RemovedCookies
X-Tumblr-Pixel
X-ProcessESI
X-Hyper-Cache
X-IPS-LoggedIn
X-Tumblr-User
X-Tumblr-Pixel-1
X-ECache
Countrycode
X-Restarts
CF-IPCountry
X-Nginx-Cache
Backend
Content-Secure-Policy
X-NYM-Debug-Backend
Liferay-Portal
X-Rule
X-COUNTRY
Ec-Rule-Version
WP-Super-Cache
X-Datadome
X-Unique-Id
X-RN-RSRV
X-Cache-Server
Upgrade-Insecure-Requests
X-OCL
X-Redis-Cache
Meta-Geo
X-UPSTREAM-Address
X-PCL
X-Mode
X-Section
X-Mcache
X-Content-Age
Cache-Tv-Group
X-Ua
X-FB-TRIP-ID
X-Format
X-Detected-As
X-Cluster-Node
X-Cache-Enabled
X-Access
X-HTML-Minification-Powered-By
Frame-Options
X-Generation-Time
Apigw-Requestid
X-No-Session
Azure-SlotName
X-Sql-Count
X-Server-W
X-Sql-Duration-Ms
X-Storage
Azure-InstanceId
X-UA-Device-Type
Azure-RegionName
Azure-SiteName
X-Origin-Hint
TWC-Device-Class
TWC-GeoIP-Country
X-Be
X-Generated-By
S-Rt
X-Hosted-By
Mn-Server-Ip
Property-Id
X-ApacheServer
X-AOL-HN
Webcakes-App-Version
Webcakes-App-Name
TWC-Privacy
Webcakes-Region
X-Site-Version
TWC-GeoIP-LatLong
X-Akamai-Edgescape
X-Human
Locale
X-Urbn-Context-Path
X-Region
X-PHP-Backend
X-Request-Time
Azure-Version
X-Say-TTL
X-Say-Cacheable
X-PERF
TWC-Locale-Group
X-Web-Node
X-Origin-Date
Fastly-SSL
X-Via-Fastly
X-Varnish-Cache-Hits
X-Urbn-Site-Id
X-Uri
X-SayCDN-TTL
TWC-Connection-Speed
X-Cache-Operation
X-APP-VERSION
X-Accel-Buffering
Section-Io-Cache
CDN-Uid
Eomportal-Instance
CDN-RequestCountryCode
CDN-CachedAt
CDN-EdgeStorageId
CDN-PullZone
X-BYPASS-REASON
CDN-RequestId
X-Cache-Type
X-ProxyCache-Key
X-ProxyCache-Status
X-Status
X-Xfnlog-Site
X-Platform-Server
X-Nginx-Cache-Key
CDN-Cache
X-Content-Powered-By
X-Debug-Cache
X-Forwarded-Host
X-Cache-Host
X-Cache-Tags
X-Extlb
X-Tid
X-SaId
X-ServerID
X-ShardId
X-Sorting-Hat-PodId
X-Shopify-Stage
X-ShopId
X-Sorting-Hat-ShopId
X-Routing-Service
X-JoinUs
X-Zipkin-Id
X-Hl-Ver
X-Proxied
X-Backend-Name
X-Varnishpool
X-Alternate-Cache-Key
ServedBy
X-Proxy-Build
Selected-Fe
X-Timing-Wait
X-Webkit-CSP
X-Cache-Remote
X-Adobe-Source
SID
X-Ratelimit-Limit
X-Rewrite-Enabled
X-NewRelic-App-Data
Xserver
X-Handled-By
Webserver
LB
SRV
X-TT-LOGID
X-GG-Cache-Date
X-Locale
X-Labrador-Cache-Channel
X-PHP-Host
X-Pubstack
X-Soup
X-LSADC-Cache
X-AWS-Id
X-VWS-Id
X-Dc
X-LJ-Flow-ID
X-Cached-By
X-VC-Cache
Country-Code
Fastly-Drupal-Html
Mime-Version
Decoy-Debug-TTL
Decoy-Debug-Key
X-CDN-Forward
Decoy-Debug-Status
X-GEO
X-Microcachable
X-Request-Host
X-Edge-Location
X-Reqid
X-Proto
Web-Mar-Node
X-Storefront-Renderer-Rendered
X-Origin-CC
X-Origin-TTL
X-Ms-Version
Xet-Cookie
X-Ms-Request-Id
Onion-Location
X-App-Version
X-Tec-Api-Origin
X-Tec-Api-Version
X-Tec-Api-Root
Server-Info
X-NCache
X-Varnish-Hostname
X-TA-CDN-Provider
X-Air-Trace-Id
X-Air-Hostname
X-Air-Source
X-TIME
X-R9-Blue-Green-Version
DynaTrace
X-SRV
X-Tumblr-Pixel-2
X-Tumblr-Pixel-3
Cache-Hits
X-MP-GENERATED-AT
X-Cms-Context
X-Bc-Bl
X-Cluster
X-Varnish-Beresp-Grace
Cache-Name
X-Varnish-Hits
X-Azure-Ref
X-B3-SpanId
X-CSRF-Token
X-Amzn-RequestId
DB-Nickname
X-Amz-Apigw-Id
X-RCS-CacheZone
X-Origin-Response-Time
X-Endurance-Cache-Level
DCR-Processing-Time-Ms
X-Envoy-Decorator-Operation
X-Gzip
DCR-Decision-By
X-Ec-GeoHdr
X-D
X-Developer
Load-Balancing
A
X-GeoCode
BehaviorPad-Version
X-Cdn-Srv
X-Conf
X-Geo-Header
X-CF-Lambda-Fn
X-Cache-NE
X-Hash
X-Forwarded-Path
X-CF-Lambda-Version
X-Esi-Check
Cdnsip
X-External-Request-Id
Cmsid
X-Ftr-Request-Id
X-GeoCountry
X-Epic-Correlation-Id
X-Destination
Cdncip
X-Magnolia-Registration
X-Ec-Fail
X-From
X-Cache-Id
X-Cache-Bucket
Cmstype
X-A-Dgt
T-Server
X-SRCache-Key
X-Tenant
X-TIM-N
X-TrackingId
Surrogated-Key
X-Shop-Environment
X-Session-Fingerprint
X-S
Lang
X-HS-Content-Campaign-Id
X-ScT
X-SD-PageType
X-User
Meta-Geo-Continent
Odigeo-Trace-Id
X-Vtex-Remote-Cache
X-Webstats-RespID
Rendered-Blocks
Xc-Version
Pramga
X-Vtex-Processado-Em
X-VG-WebCache
Sslversion
Mobile-Detection-Method
X-Vdms-Path
X-Vdms-Version
NM-Fastcgi-Cache
X-Rojux
X-S-Cookie
X-AK-Request-ID
X-NodeID
X-NAPM-TraceId
X-Aed
X-Presslabs-Stats
X-Connection-Hash
X-A-Wwc
X-Application
X-Men
X-B-Cookie
X-Ig-Push-State
X-Via-NSCOPI
Expiry
X-LAGOON
Fastcgi-X-Cache-Version
X-ARC
X-A-Dcw
X-Orig-Expires
X-A-Ccd
Host-ID
X-Processor
X-A
X-PBS-Appsvrname
X-A-Dam
X-PAYTM-SRV-ID
Environment
X-Tx-Id
User-Cache-Control
X-Ckpd-Fst-Backend
X-Clara-WADP
X-Block-Status
Wxu-Next-Hostname
Wxu-Next-Region
Wxu-Next-Commit
Server-Host
Ssr
State
X-Cache-Info
X-Amzn-Remapped-Content-Length
We-Hiring
Web-Mar-Region
V-Age
Svr
Vix-Hermes-Req-Id
X-Location
X-RSL
X-RPS
X-Scheme
X-Server-IP
X-Sigma-Backend
X-Sigma
X-RPM
X-Rocket-Build-Number
X-Planisys-CDN-Cache
X-Origin-Time
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Request-URI
X-Slack-Backend
X-SVT-ORM-RULES
X-Viewer-Country
X-VG-TLSProxy
X-WADP-Cache
X-Wix-Viewer-Type
X-Worker
X-Varnish-Remaining-TTL
X-Varnish-CookieINHashed-On
X-TNCMS
X-SVT-ORM-VERSION
X-V-Cache
X-Variation
X-Varnish-CookieHashed-On
X-Origin-Expires
X-Origin
X-DSS
X-DPWN-IS-SECURE
X-DW
X-Fastly-Cache
X-Fmm-Version
X-Fetched-On
X-DI
X-Device-Os
X-DB
X-Core-Value
X-DefElseHash
X-DefHash
X-Developers
X-Gdpr
X-Gen-Mode
X-Mvc-Supplant-Cachable
X-Loop
X-Node-Id
X-Nyt-Route
X-Old-Content-Length
Platform
X-JWT-State
X-Has-Esi
X-GeoIP
X-Hnp-Log
X-Irp-Debug
X-Is-Gdpr
X-Core-Mission
X-Cache-Backend
Apple-News-Services-Handled
Apple-News-Services-Host
Mail-Subject
Memcached
AKAMAI
Adler-Geo
Machine
Is-Eu
GEO-INFO
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
Fastly-GeoIP-CountryCode
X-Varnish-Ttl
Cache
CDN
Source
X-Branch-Name
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
X-Datadog-Trace-Id
X-Cdn-Origin
X-Csrf-Jwt
Cluster
X-CGP
X-Httpd
X-Skip-Cache
CloudFront-Viewer-Country
X-Cache-Date
Arc-Country
X-Date
PFcat
X-Forwarded-Site
X-Gamma-Serve
X-Platform
X-Pod-Name
X-Eu-Site
X-Generated-On
X-Minions-Version
X-HN
X-Level-Front-Cache
X-Loc
X-GeoIP-City
X-Policy
X-Proxy-Cache-Info
X-Region-Sid
X-Response-By
X-Rocket-Nginx-Serving-Static
X-Sn-Servicetimems
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-Proxy-Upstream
X-Qloud-Router
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Served-From
CDCHOST
L5d-Success-Class
Locid
Redirect-Candidate
Kp-EeAlive
HA-Ipaddr
X-VServer
Gh-Request-Id
Ha-Gx-Prefs
Origin-CC
Producers
TDXMobile
N-Cache
Origin-EX
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
Traceparent
Thinkindot-Control
Req-Svc-Chain
L
Fastcgi-Cache-TTL
Origin
X-Auto-Login
X-Accel-Expires-Debug
X-BBC-Edge-Cache-Status
X-Thinkindot-L3
Fastly-SIE
Release
X-Aicache-OS
X-VarnishDD-TTL
X-Akamai-Transformed
Fastly-SWR
X-EC-Lua
Fusion-Content-Id
Fusion-Content-Source
Fusion-Template-Id
X-TraceId
Fusion-Source
Fusion-Deployment-Id
Fusion-Component-Id
NGX
DSUID
X-GeoIP-Country-Code
X-GeoIP-Region-Code
HostName
X-SB
X-Optimistic-Header
X-Parent-Response-Time
X-CS
X-Midtier
X-NC
X-Owner
X-Pool
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
X-Ec-Custom-Error
AMP-Access-Control-Allow-Source-Origin
X-Tt-Logid
X-Srv
X-CacheTTL
X-Cache-Debug
X-API-Version
Env
Pics-Label
X-Tb-Optimization-Total-Bytes-Saved
X-Refresh
MD5-Digest
X-LB-NoCache
X-Ah-Environment
Time
Memory
CacheControlHeader
X-Udemy-Cache-App-Namespace
Servername
X-Dispatcher-Number
X-Mvc-Supplant-OutputCached
Ms-Author-Via
X-Newrelic-Synthetics
X-ZONE
IsBot
X-Time
True-Client-Country-4JS
X-Generated-In
Server-Ext
X-Edge-Pop
X-SIPLIST1
X-Via-Ucdn
Sever-Int
Server-Hostname
X-TH-Server
X-Scale
X-Action
X-Via-Popn
X-Via-Poph
GeoIp-Country-Code
Geo-Info
X-Via-Popv
X-VC
X-Backend-TTL
X-Vc
X-Xrds-Location
Ohc-File-Size
X-Servedbyhost
FSS-Cache
X-S-Maxage
X-HA-Backend
X-IPLB-Request-ID
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-Trace-ID
Client
Cache-Key
X-Amz-Meta-Cb-Modifiedtime
X-Req
X-Ad-Defer-Variation
Candidate-Md5Url
Datacenter
X-BCube-Filmed-By
X-CACHE-KEY
Edge-Cache
X-Zone
X-RateLimit-Reset
X-Contensis-Viewer-Groups
X-DC
X-VCL-Version
X-Varnish-Beresp-TTL
X-Cache-ASPX
VNS-Age
My-App
X-Origin-Upstream-Status
Geoip-Latitude
CPC-Age
CPC-Cache
XM
X-SplitTest
VNS-Cache
Server-ID
Fastly-Backend-Name
X-WA-Info
X-Provided-By
X-Varnish-Authentication
ITXSESSIONID
X-Dynatrace
DataCenter
X-VHOST
Hostname
X-Cs
X-Up
X-Micro-Cache
Path
X-AIR-PT
X-Cache-Status-Check
X-LB-ID
Ohc-Cache-HIT
X-FireWall-Port
NtCoent-Length
Cache-Host
X-TX-ID
OT-Force-Account-Verify
X-Fpc
X-Pass-Why
X-LI-UUID
X-Webkit-Csp-Report-Only
X-Li-Fabric
Ngx.Var.Host
X-Li-Pop
True-Client-IP
X-Traceid
X-Varnish-Beresp-Ttl
X-ND-Cache
Test
X-FPC
X-UnsetCookies
X-B3-Spanid
X-CSRF-TOKEN
X-Proxy-CacheRZ
X-Clientip
Lb
XkeyRZ
X-CUA
X-Time-Microsecs
X-NGINX-Cache
Cf-Int-Pingora-Origin-Digest
Powered-By
Tracecode
X-Api-Version
Target-Params
Cf-Device-Type
X-RAMCache
X-Fragments
X-Azure-Ref-OriginShield
X-Correlation-ID
Proxy-Connection
X-Beluga-Node
X-Beluga-Response-Time
X-Beluga-Record
X-Beluga-Trace
Server-Id
X-Beluga-Cache-Status
X-Sucuri-Cache
X-Beluga-Status
User-Agent
X-Webkit-CSP-Report-Only
X-Fastly-Backend
X-FC-Vary-Parameters
X-Vcl-Version
X-Var-Ttl
X-Cdn-Request-ID
X-Sucuri-ID
X-ATG-Version
Lfy
X-MSEdge-Features
X-MSEdge-Flight
X-DynaTrace-JS-Agent
X-CLOUD-TRACE-CONTEXT
X-URL
X-Li-Proto
X-ServedByHost
X-Ha-Backend
X-Via-PopH
X-M-Log
X-NU-AKA-ACS-Version
X-Qnm-Cache
GeoIP-Latitude
X-Varnish-Beresp-Status
Uri
Resin-Trace
X-Via-PopN
X-M-Reqid
WZWS-RAY
X-Platform-Processor
X-Platform-Cluster
X-B3-Traceid-Primal
X-INCAP-ABP
X-Platform-Router
X-Via-PopV
X-Dmc
X-Geo
X-Render-Time
GeoIP-Country-Code
Magicmarker
Sid
X-Backend-State
X-HS-Status
X-Fastly-Backend-Reqs
X-Cdn-Forward
MIME-Version
X-Check-Cacheable
X-Akamai-Pragma-Client-IP
X-Hcs-Proxy-Type
X-CCDN-CacheTTL
Epwk-X-Cache
X-CCDN-Origin-Time
X-Backend-Host
X-Request-Start
C-Via
X-LI-Proto
Srvid
X-Alfa-Service
X-Proxy-Cache-Hk
Rip
X-Fetch-By
X-TRACE-ID
Fastly-Drupal-HTML
X-Gateway-Skip-Cache
X-Service
X-Edge-POP
X-Gateway-Request-Id
Tube-Got-Eval
Tube-Get-Contents
X-Bip
ENV
Click-Count-Error
X-Newrelic-App-Data
Click-Count-Action-Start
Tube-Return
X-Gateway-Cache-Key
X-Thanos
Tube-Got-Results
X-Gateway-Cache-Status
X-Esi
Cdn
X-LiteSpeed-Cache-Control
WebServer
X-Cache-CFC
X-Lb-Nocache
X-ElasticPress-Query
ServerName
X-Cache-Expires
PICS-Label
X-App
Server-Ttl
XServer
Esi-Enabled
X-MG-S
X-Srcache-Fetch-Status
X-Srcache-Store-Status
Section-Origin-Responded
On-Server
CF-Cached-On
Section-Io-Origin-Time-Seconds
Section-Io-Id
CountryCode
X-Cache-Config
M-TraceId
HIT
Section-Io-Origin-Status
Tcn
X-Yottaa-OS
Srv
Wpo-Cache-Message
Cf-Ipcountry
X-Vcache
D-Url-Rewrites
X-Nc
X-BBC-Origin-Response-Status
X-Serial
Wpo-Cache-Status
Inserted-Into-Cache-At
X-Acquia-Application-UUID
X-Acquia-Application-Trace
X-Acquia-Site
X-Acquia-Purge-Tags
Servedby
X-HostName
Warning
Cteonnt-Length
Hit
X-Release
X-Request-Url
X-Akamai-ERPolicy
X-Dist-Code
X-Fastly-Cache-Hits
X-Wp-Cf-Super-Cache
Fastcgi-Cache-Ttl
X-Wp-Cf-Super-Cache-Cache-Control
X-APP
X-Request-URL
Content-Style-Type
X-Back
X-Litespeed-Cache-Control
Content-Script-Type
X-IN-APIGATEWAYSSL
X-B3-Parentspanid
X-IN-APIGATEWAY
X-Dw-Trace-Id
X-Th-Server
Cneonction
X-LiteSpeed-Tag
X-Akamai-Request-ID
X-Snapshot-Date
Ngx
X-Shopify-Generated-Cart-Token
X-Swift-Error
X-Storefront-Renderer-Verified
X-CF-Powered-By
X-Akamai-ERRuleID