Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
X-XSS-Protection
Accept-Ranges
Expect-CT
Pragma
X-Powered-By
CF-RAY
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-Download-Options
X-Xss-Protection
CF-Ray
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
Access-Control-Allow-Credentials
X-Request-Id
X-FRAME-OPTIONS
X-Request-ID
X-Permitted-Cross-Domain-Policies
X-AspNet-Version
Alt-Svc
X-Runtime
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Cache-Status
X-Generator
X-Cacheable
Timing-Allow-Origin
X-Iinfo
X-Envoy-Upstream-Service-Time
X-Content-Security-Policy
X-Drupal-Dynamic-Cache
Feature-Policy
Content-Encoding
Access-Control-Expose-Headers
Upgrade
Status
X-CDN
X-AspNetMvc-Version
P3p
Access-Control-Max-Age
X-Via
Server-Timing
X-UA-Device
Request-Context
X-Robots-Tag
X-Turbo-Charged-By
X-Cache-Group
X-Amz-Request-Id
EagleId
X-Amz-Id-2
X-Backend
X-AH-Environment
X-Proxy-Cache
Keep-Alive
X-Server
X-Ws-Request-Id
X-Age
X-Ua-Compatible
Host-Header
X-Hacker
Cf-Edge-Cache
X-Vhost
X-Server-Powered-By
X-Rq
X-Varnish-Cache
X-Dns-Prefetch-Control
X-Dispatcher
X-Amz-Version-Id
Allow
Grace
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-OneAgent-JS-Injection
X-LiteSpeed-Cache
X-WebKit-CSP
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Page-Speed
X-Device
Cf-Apo-Via
Accept-CH
Cf-Railgun
X-Aws-Lambda-Call-Status
X-Node
X-Host
X-Pingback
X-Server-Id
X-Cache-Spec
X-Ruxit-JS-Agent
X-Nginx-Cache-Status
EagleEye-TraceId
X-Akam-SW-Version
Surrogate-Control
X-Backend-Server
Request-Id
X-Readtime
X-Cache-Lookup
X-HW
X-Content-Security-Policy-Report-Only
X-Cloud-Trace-Context
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Trace
X-Application-Context
X-Response-Time
Accept-Ch-Lifetime
Fastly-Restarts
Permissions-Policy
X-Nginx-Upstream-Cache-Status
X-Mod-Pagespeed
X-Edge
Accept-CH-Lifetime
X-WebKit-CSP-Report-Only
X-CST
Content-Location
X-Content-Type
X-Url
X-MS-InvokeApp
X-Mcache
X-Clacks-Overhead
Rating
X-Midtier
X-Country
X-Amz-Server-Side-Encryption
X-TtlSet
X-Vname
X-PC
X-Litespeed-Cache
RTSS
X-ECACHE
Cache-Tag
X-VARITI-CCR
X-ESI
X-Vcap-Request-Id
X-D2id
X-Server-Name
Origin-Trial
X-Element-Page-Cache
Verso
X-Cdn-Fetch
X-Exp-Id
X-Exp-Variant
X-Kinja
X-Kinja-Server
X-GoogleNews-Bot
X-Kinja-Revision
X-Use-Magma
X-Kinja-Build
X-Ttl
X-Ac
X-Rack-Cache
X-Cnection
X-Powered-By-Plesk
Service-Worker-Allowed
X-GitHub-Request-Id
X-B3-TraceId
X-Client-IP
SPRequestGuid
X-SharePointHealthScore
Xkey
X-Amz-Rid
X-Navigation-Version
X-Cache-TTL
X-Abt-Application-Version
Edge-Control
X-Varnish-TTL
X-NWS-LOG-UUID
SPIisLatency
SPRequestDuration
X-Upstream
Arr-Disable-Session-Affinity
X-Cached
X-Server-Lifecycle-Phase
X-Browser-Type
X-Erf-Bev-Bev
X-Kraken-Loop-Name
X-Erf-Bev-Bev-Is-Generated
X-Instrumentation
X-Mg-S
X-Px
X-Cache-Key
X-Dw-Request-Base-Id
X-Correlation-Id
X-Middleton-Display
Pagespeed
Display
X-Sol
X-SRCache-Fetch-Status
X-SRCache-Store-Status
Content-MD5
X-NF-Request-ID
Access-Control-Request-Method
Edge-Cache-Tag
X-Forwarded-For
X-Goog-Hash
X-XRDS-Location
X-Country-Code
Front-End-Https
X-Webkit-Csp
X-Version
X-Powered-CMS
X-Id
TCN
Public-Key-Pins
X-FastCGI-Cache
AR-PoweredBy
AR-ATIME
X-HP-Webp
X-HP-Trace-Id
X-Jurisdiction
AR-CACHE
AR-Request-ID
AR-SID
X-T
X-Recruiting
X-MSEdge-Ref
X-Daa-Tunnel
X-Content-Digest
Accept-Ch
X-Accel-Expires
X-RateLimit-Remaining
X-Amzn-Trace-Id
X-Ser
Response
X-Middleton-Response
X-Shield-Request-Id
TP-L2-Cache
TP-Cache
X-Fastcgi-Cache
S
Nginx-Cache
Mrf-Cache-Status
X-B3-TraceId-Primal
MRF-Tech
MicrosoftSharePointTeamServices
X-Ratelimit-Limit
X-Request-Processing-Time
X-Request-Received
Server-Node
X-HS-Combine-CSS
X-HS-Content-Id
X-HS-Hub-Id
X-HS-Cache-Config
Cache-Status
X-Distributor
Cache-Tags
X-Ratelimit-Remaining
X-Hits
X-Edge-Location-Klb
X-Kinsta-Cache
Fastcgi-Cache
X-Grace
X-DataDome
X-LB-Cache
Server-Name
Alternate-Protocol
X-Origin-Server
X-Ua-Browser
X-Ratelimit-Reset
X-Ezoic-Cdn
X-DIS-Request-ID
Cross-Origin-Opener-Policy
Filterid
X-Geo-Country
X-Microsite
X-Request-Handler-Origin-Region
X-Rid
X-Protected-By
X-Debug-Info
Healthy
X-Www-Served-By
X-Git-Hash
X-Varnish-Backend
X-Logged-In
Payment
X-LLID
X-Fastly-Request-ID
X-Frontend
X-Page-Id
Cleartype
X-NGENIX-Cache
X-Forwarded-Proto
X-Load-Cache
X-FB-Debug
X-Hostname
X-TEC-API-ROOT
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-Origin-Cache
X-PressLabs-Stats
X-Cluster-Name
DC
Charset
MS-Author-Via
X-ASPNET-VERSION
Content-Disposition
X-B3-Sampled
Realpath
X-Goog-Metageneration
X-GUploader-UploadID
Access-Control-Allow-Method
X-Proxy
X-Upgrade-Enabled
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
X-F-Cache
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Az
X-AppVersion
X-Activity-Id
X-VCache
Retry-After
X-Seen-By
Cross-Origin-Resource-Policy
X-Amz-Replication-Status
Paypal-Debug-Id
X-Contextid
X-Aspnet-Duration-Ms
X-Is-Crawler
X-Flags
X-B-Cache
Accept-Charset
X-Providence-Cookie
X-Request-Guid
X-Signature
X-Route-Name
X-Revision
X-Type
Viewport
X-Whom
X-Amz-Meta-S3cmd-Attrs
X-Oracle-Dms-Rid
X-App-Environment
X-Hosted-By
X-Wix-Request-Id
Count-Hit
X-Oracle-Dms-Ecid
X-Fb-Rlafr
Amp-Access-Control-Allow-Source-Origin
Surrogate-Key
X-Azure-Ref
X-Varnish-Server
X-TTL
X-TT
X-Server-ID
X-B
X-DynaTrace
X-COUNTRY
X-Aspnetmvc-Version
X-Akamai-Edgescape
X-B3-Traceid
X-Language
X-Source
Referer-Policy
X-Cache-Control
X-App-Server
X-ECache
X-Mobile
X-RateLimit-Limit
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Fastly-Request-Id
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Magnolia-Registration
Host
X-Varnish-Grace
X-Cache-Age
Version
X-HTML-Minification-Powered-By
X-N
SRV
X-Tumblr-Pixel
X-Tumblr-User
X-Cache-Rule
X-Tumblr-Pixel-1
X-Original-Request-Id
X-Tumblr-Pixel-0
X-Response-Served-From
X-RTag
X-UUID
Ms-Operation-Id
X-Rule
MS-CV
X-Cache-Time
SD-X-WS
Section-Io-Cache
X-Trace-Id
X-Cache-Expired-At
X-Framework
X-Content-Powered-By
X-EdgeConnect-Cache-Status
X-Template
X-Varnish-Age
X-Cache-Status-Check
Akamai-GRN
X-Adobe-Loc
X-Backend-Name
X-Device-Type
X-Adobe-Content
X-FW-Type
X-ProcessESI
X-Page-View
X-FW-Dynamic
Access-Control-Request-Headers
X-Envoy-Decorator-Operation
X-FW-Version
X-RemovedCookies
X-FW-Hash
X-FW-Static
X-FW-Serve
X-FW-Server
X-Rendered-As
X-G
X-Times
GEO-INFO
X-User-Agent
VIX-Pulpo-Node
Refresh
X-Cache-Grace
X-Is-Bot
X-Instance
NGB
VIX-Pulpo-Upstream-Status
Protected
X-NYM-Debug-Backend
X-Cacheable-TTL
Url
X-Drupal-Cache-Contexts
X-Servername
X-Akamai-Request-ID2
X-Status
X-Http-Reason
X-Drupal-Cache-Tags
X-Jobs
X-L-Path
CDN-RequestId
X-Environment-Context
From-Origin
X-CDN-Forward
WPO-Cache-Message
WPO-Cache-Status
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Region
X-Debug-IsPreview
X-Debug-IsConnected
X-Ruxit-Js-Agent
Accept-Language
Front
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Cache-Hit
X-Unique-Id
Country
Backend
X-Tec-Api-Root
Fastly-SIE
X-Tec-Api-Version
Fastly-SWR
X-Tec-Api-Origin
X-Content-Options
X-TIME
X-Tb
X-Nginx-Cache
X-Zen-Fury
X-Air-Trace-Id
X-Tt-Logid
X-Air-Source
X-Air-Hostname
X-DynaTrace-JS-Agent
X-Varnish-Ttl
X-Real-IP
Pinterest-Generated-By
X-Mode
Pinterest-Version
X-Pinterest-Rid
X-Cache-Operation
X-Node-Name
X-VC-Cache
Content-Secure-Policy
Uber-Trace-Id
Liferay-Portal
X-Ms-Request-Id
X-Rewrite-Enabled
X-Ms-Version
X-RN-RSRV
Meta-Geo
X-Tumblr-Pixel-2
X-UPSTREAM-Address
X-Generation-Time
Webserver
X-Amzn-Remapped-Content-Length
X-Cache-Server
Filters
X-Proxy-Cache-Info
Cache-Hits
X-IPS-LoggedIn
X-Format
X-Reqid
X-Rocket-Nginx-Serving-Static
X-Access
X-Web-Node
X-Section
Azure-Version
Azure-InstanceId
Azure-RegionName
CF-IPCountry
Azure-SiteName
Azure-SlotName
TWC-Locale-Group
TWC-GeoIP-Country
TWC-GeoIP-LatLong
TWC-Connection-Speed
ServedBy
TWC-Device-Class
Onion-Location
Webcakes-App-Name
Webcakes-Region
X-Adobe-Source
Property-Id
Webcakes-App-Version
TWC-Privacy
X-IPLB-Instance
X-Proto
X-Proxy-Cache-Status
X-UA-Device-Type
X-Ua
X-SayCDN-TTL
X-Say-TTL
X-ProxyCache-Key
X-Via-Fastly
X-Say-Cacheable
X-R9-Blue-Green-Version
X-PHP-Backend
X-VWS-Id
X-ProxyCache-Status
X-Server-W
X-Sucuri-ID
X-Cluster-Node
X-Cms-Context
X-Cluster
X-Cache-TTL-Remaining
X-BYPASS-REASON
X-Debug
X-IPLB-Request-ID
X-Sql-Duration-Ms
X-Sucuri-Cache
X-Origin-Hint
X-Sql-Count
X-LJ-Flow-ID
X-Soup
X-AWS-Id
X-Content-Age
Node
X-No-Session
Web-Mar-Node
ServerID
Cache-Name
DB-Nickname
X-PHP-Host
X-Locale
X-Handled-By
X-Labrador-Cache-Channel
X-Cache-Action
X-FB-TRIP-ID
X-JoinUs
X-LAGOON
Mn-Server-Ip
Apigw-Requestid
X-Skip-Cache
X-Site-Version
X-Varnish-Beresp-Grace
X-Cache-Host
X-Buckets
X-Xfnlog-Site
X-SaId
X-Forwarded-Host
X-Proxy-Build
Selected-Fe
X-Timing-Wait
X-Detected-As
X-Extlb
WP-Super-Cache
X-Newrelic-App-Data
X-Urbn-Site-Id
X-Urbn-Context-Path
X-Zipkin-Id
X-Routing-Service
X-WP-CF-Super-Cache
X-Proxied
X-WP-CF-Super-Cache-Cache-Control
X-Edge-Location
Locale
Mime-Version
Cross-Origin-Window-Policy
X-GeoCountry
X-GeoCode
Fastly-Drupal-HTML
S-Rt
X-Tumblr-Pixel-3
Fastcgi-Useragent
X-Origin-Date
X-LSADC-Cache
X-Optimistic-Header
CDN-PullZone
CDN-Uid
CDN-CachedAt
CDN-EdgeStorageId
X-App-Version
Source
CDN-Cache
CDN-RequestCountryCode
X-Hl-Ver
X-Uri
Countrycode
X-XRDS-LOCATION
X-Time
X-SRV
X-Request-Time
X-Director
X-Oneagent-Js-Injection
X-Varnish-Hits
X-ARC
CF-Cached-On
X-Generated-By
Upgrade-Insecure-Requests
X-GEO
X-Cache-Debug
X-Redis-Cache
X-Tx-Id
X-Mg-Request-UUID
Cache-Tv-Group
X-Akamai-Transformed
X-Loop
X-TNCMS
X-Pass-Why
Frame-Options
X-Origin-CC
X-Origin-TTL
X-CACHE-AGE
Xet-Cookie
X-FireWall-Port
X-URL
X-Varnish-Cache-Hits
X-TA-CDN-Provider
X-Presslabs-Stats
X-Varnish-Hostname
X-RM-Cache-TTL
X-Newrelic-Synthetics
Xserver
X-Datadog-Sampled
X-Datadog-Parent-Id
X-ShopId
X-ShardId
X-Alternate-Cache-Key
X-Shopify-Stage
X-Sorting-Hat-PodId
X-ServerID
X-Storefront-Renderer-Rendered
X-Sorting-Hat-ShopId
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
X-NWS-UUID-VERIFY
X-Service
X-Varnish-Beresp-Ttl
X-Endurance-Cache-Level
X-Storage
X-B3-Spanid
X-Pubstack
X-Mid
Ngx.Var.Host
X-Location
X-Mobile-URL
MD5-Digest
Memcached
Odigeo-Trace-Id
Meta-Geo-Continent
X-CMSURLCustom
X-Nyt-Route
Release
Req-Svc-Chain
X-Cache-Date
Xc-Version
Redirect-Candidate
X-Cache-Info
Origin
X-Loc
X-Request-Host
X-Cache-NE
X-Conf
X-D
Cache-Host
DCR-Processing-Time-Ms
BehaviorPad-Version
Edge-Cache
X-Epic-Correlation-Id
DCR-Decision-By
X-Generated-On
X-Frame-Option
X-Gdpr
X-External-Request-Id
Candidate-Md5Url
X-Ec-GeoHdr
A
X-INCAP-ABP
Lang
X-A-Dcw
X-Core-Value
X-Httpd
X-Destination
X-Ec-Fail
Gannett-Cam-Experience-Id
Host-ID
X-Developer
X-Level-Front-Cache
Rendered-Blocks
X-Rojux
X-S
X-S-Cookie
X-S-Maxage
X-A
X-Rocket-Build-Number
X-TIM-N
X-Aed
Thinkindot-Control
X-Application
X-Sigma-Backend
X-VG-TLSProxy
X-Vdms-Version
X-Served-From
X-Vdms-Path
WWW-Authenticate
X-A-Wwc
X-ScT
X-Sigma
X-A-Dgt
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
X-SRCache-Key
X-BBC-Edge-Cache-Status
X-Thinkindot-L3
X-Platform-Processor
X-Origin-Time
X-A-Dam
X-BCube-Filmed-By
X-Bc-Bl
Sslversion
X-Platform-Router
X-Platform-Cluster
X-B-Cookie
T-Server
X-We-Are-Hiring
TDXMobile
X-Test
X-Processor
Surrogated-Key
X-A-Ccd
Environment
Decoy-Debug-Key
We-Hiring
Fastly-Backend-Name
Fastly-GeoIP-CountryCode
X-Fmm-Version
Decoy-Debug-Status
X-Fetched-On
Decoy-Debug-TTL
Magicmarker
X-Clara-WADP
NM-Fastcgi-Cache
NGX
X-Auto-Login
X-Cdn-Srv
Cluster
Server-Host
X-Cache-Bucket
Ssr
Mail-Subject
Server-Info
X-DefHash
X-Developers
Gh-Request-Id
X-Ec-Custom-Error
Tube-Return
X-DefElseHash
Tube-Get-Contents
Tube-Got-Eval
Tube-Got-Results
X-Akamai-Device-Characteristics
Apple-News-Services-Host
X-Thanos
X-Mvc-Supplant-Cachable
X-Restarts
X-WADP-Cache
X-CUA
X-SB
X-WA-Info
X-Human
X-HS-Content-Campaign-Id
X-Vmg-Version
X-Is-Gdpr
X-VServer
X-Req
X-NodeID
X-Origin-Response-Time
X-Org
Load-Balancing
X-WP-CF-Super-Cache-Active
X-Worker
X-Old-Content-Length
X-Platform-Server
CloudFront-Viewer-Country
X-Bip
X-Pool
DSUID
X-SD-PageType
X-JWT-State
CacheControlHeader
Apple-News-Services-Handled
AKAMAI
X-GeoIP
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
X-Geo-Header
Cache-Key
C-Via
X-Varnish-Beresp-Status
X-GeoIP-City
Click-Count-Action-Start
X-Varnish-Remaining-TTL
X-Has-Esi
Click-Count-Error
X-Varnish-CookieINHashed-On
X-Tid
X-Varnish-CookieHashed-On
Section-Origin-Responded
X-Api-Version
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
Section-Io-Id
X-Parent-Response-Time
X-Sn-Servicetimems
X-SVT-ORM-VERSION
X-Platform
X-Variation
X-Mly-Id
X-Wix-Viewer-Type
X-VarnishDD-TTL
X-Scale
X-Accel-Buffering
X-App
X-Request-Start
X-Azure-Ref-OriginShield
X-Qloud-Router
X-Ckpd-Fst-Backend
X-Dispatcher-Server
X-Gzip
X-Device-Os
X-Hash
X-Hnp-Log
X-HN
X-DPWN-IS-SECURE
X-GeoIP-Region-Code
X-Gen-Mode
X-FC-Vary-Parameters
X-Esi-Check
X-SVT-ORM-RULES
X-GeoIP-Country-Code
X-Irp-Debug
X-LB-NoCache
X-Cdn-Origin
X-Nginx-Cache-Key
X-Cache-Tags
X-Cache-Id
X-Cache-Backend
X-Op-Id-All
X-NCache
X-Node-Id
X-Varnishpool
X-Minions-Version
X-Var-Ttl
X-Core-Mission
X-Origin
X-Block-Status
X-Ad-Defer-Variation
Pics-Label
Is-Eu
Platform
Producers
Sever-Int
Server-Ext
PFcat
Wxu-Next-Region
L
Machine
On-Server
Origin-CC
Kp-EeAlive
Origin-EX
State
Server-Hostname
Cache-Provider
User-Cache-Control
Canary
Adler-Geo
Vix-Hermes-Req-Id
Wxu-Next-Hostname
Wxu-Next-Commit
Web-Mar-Region
Datacenter
CDCHOST
Country-Code
X-DC
X-NewRelic-App-Data
X-Refresh
Fastly-SSL
X-Date
L5d-Success-Class
X-Region-Sid
Cmsid
X-Gamma-Serve
Cmstype
X-Eu-Site
HA-Ipaddr
X-Dispatcher-Number
Ha-Gx-Prefs
X-Slack-Backend
X-CacheTTL
X-Slack-Shared-Secret-Outcome
X-Mvc-Supplant-OutputCached
X-Forwarded-Site
X-Nananana
X-Fastly-Backend
X-Men
X-Csrf-Jwt
X-CGP
X-Accel-Expires-Debug
X-Microcachable
X-Server-IP
X-Fastly-Cache
X-Owner
X-Planisys-CDN-Rules
X-V-Cache
X-Planisys-CDN-Cache
X-Planisys-CDN-TTL
X-Cache-Remote
X-Webkit-CSP-Report-Only
SID
Env
X-Instance-Name
X-Origin-Expires
X-Aicache-OS
X-Tb-Optimization-Total-Bytes-Saved
X-Cache-FS-Status
X-Servedbyhost
GeoIP-Latitude
X-Zone
X-CSRF-Token
X-Response-By
X-RCS-CacheZone
X-NGINX-Cache
X-Release
X-Up
Svr
X-Air-Pt
X-From
Expect-Staple
X-Provided-By
X-ND-Cache
Time
Memory
X-Nc
HostName
X-Vc
X-Via-CDN
X-Trace-ID
X-AIR-PT
X-FL-QIT-DEBUG
X-Cache-Enabled
X-Generated-In
X-Edge-Pop
X-FL-EDGE
Locid
X-DataCenter
Cdn
X-Wa
Srvid
Edge-Copy-Time
X-Via-Edge
Cache
X-Via-SSL
X-Vcl-Version
X-Via-Popv
X-Via-Popn
X-VC
X-Cached-By
X-Via-Poph
X-Webkit-CSP
NtCoent-Length
X-HS-Status
X-Dc
Hostname
X-HA-Backend
X-Debug-Cache-Store
Cdncip
Cdnsip
Server-ID
X-Debug-Cache-Fetch
X-AK-Request-ID
GeoIp-Country-Code
X-Esi
X-ZONE
X-CSRF-TOKEN
X-Correlation-ID
X-Check-Cacheable
X-Vgn-Hpd-Ssi
X-Client-Ip
Sid
X-CCDN-CacheTTL
X-Vgn-Hpd-Variations-Key
X-Gateway-Cache-Key
X-Gateway-Request-Id
X-CCDN-Origin-Time
X-Lambda-Id
X-Vgn-Hpd-Cached
X-Gateway-Skip-Cache
X-Gateway-Cache-Status
X-Srv
X-Hcs-Proxy-Type
X-Via-NSCOPI
X-API-Version
X-Render-Time
X-Vtex-Remote-Cache
X-Amz-Meta-Cb-Modifiedtime
True-Client-IP
X-Fpc
X-Cs
X-LB-ID
AMP-Access-Control-Allow-Source-Origin
X-VCT
X-Via-JSL
CPC-Cache
CPC-Age
VNS-Age
VNS-Cache
X-CS
XkeyRZ
X-Proxy-CacheRZ
Eomportal-Instance
X-TH-Server
Fastly-Drupal-Html
X-MCACHE
X-EC-Lua
X-Upstream-Ct
Ngx-Var-Key
X-B3-SpanId
X-Upstream-Ht
X-Micro-Cache
X-Nf-Request-Id
X-Cache-Type
X-MSEdge-Features
Esi-Enabled
X-ATG-Version
X-MSEdge-Flight
X-Varnish-Authentication
X-Cache-ASPX
X-Contensis-Viewer-Groups
M-TraceId
Path
X-APP-VERSION
OT-Force-Account-Verify
X-SIPLIST1
Resin-Trace
IsBot
Uri
True-Client-Ip
X-Request-URI
Srv
X-Lb-Id
X-Cache-NGX
X-Fastly-Country-Code
X-CF-Lambda-Version
X-CF-Lambda-Fn
X-RateLimit-Limit-Second
X-Varnish-Beresp-TTL
X-PAYTM-SRV-ID
X-VCL-Version
X-RateLimit-Remaining-Second
X-Info
XServer
Request-ID
X-Udemy-Cache-App-Namespace
X-FPC
YJS-ID
RNT-Machine
RNT-Time
Location
GeoIP-Country-Code
X-CLOUD-TRACE-CONTEXT
CDN
X-CDN-Cache-Status
N-Cache
X-MP-GENERATED-AT
X-Wikidot-Static-Cache
X-Tenant
X-Shop-Environment
X-Wikidot-Backend
X-Accel-Version
X-Bl-Debug
X-Cdn-Request-ID
X-Forwarded-Path
X-Orig-Expires
LB
X-TX-ID
Cross-Origin-Opener-Policy-Report-Only
X-B3-Trace-ID
X-Oss-Hash-Crc64ecma
X-Service-Response-Time
X-Oss-Object-Type
Sm-Log-Id
X-Oss-Request-Id
X-Oss-Server-Time
X-Oss-Storage-Class
X-Cache-Expires
Server-Id
Servername
X-Pod-Name
X-Edge-POP
X-Datadome
X-Ha-Backend
X-Policy
X-Datacenter
X-RateLimit-Reset
X-App-Name
X-Akamai-Pragma-Client-IP
X-Via-PopV
X-Via-PopN
HIT
Timeexpire
X-Via-PopH
X-Cdn-Cache-Status
X-WA
X-SERVER-NAME
X-Geo
X-NC
X-Srcache-Fetch-Status
Traceparent
X-Moov-T
X-Moov-Xdn-Version
X-CACHE-KEY
Proxy-Connection
Ohc-File-Size
X-Scheme
Lb
FSS-Cache
X-Srcache-Store-Status
X-ApacheServer
Epwk-X-Cache
X-Snapshot-Date
X-Viewer-Country
X-ServedByHost
X-TraceId
Yjs-Id
ENV
X-PERF
Hit
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-Amz-Meta-Opti
WZWS-RAY
X-LiteSpeed-Cache-Control
X-Cdn-Forward
Pramga
X-Cdn-Diag
X-Ctl-Mach
X-Serial
CountryCode
X-UP
X-Dw-Trace-Id
Geoip-Latitude
X-Hyper-Cache
X-MiniProfiler-Ids
X-M-Reqid
X-M-Log
X-Logging-Id
Content-Style-Type
X-Vgn-Hpd-Reason
Req-ID
X-Fastly-Backend-Reqs
Content-Script-Type
X-RAMCache
X-Acquia-Purge-Tags
X-Swift-Error
Ec-Rule-Version
X-Acquia-Application-UUID
X-Qnm-Cache
X-Acquia-Site
Powered-By
X-B3-Parentspanid
Cneonction
X-Lb-Nocache
X-NAPM-TraceId
X-Acquia-Application-Trace
X-Wp-Cf-Super-Cache-Cache-Control
X-TT-LOGID
X-Lsadc-Cache
X-Vcache
X-Wp-Cf-Super-Cache
X-F-Status
X-Webstats-RespID
Warning
X-B3-ParentSpanId
X-Litespeed-Cache-Control
X-Fastly-Cache-Hits
X-IPS-Cached-Response
Inserted-Into-Cache-At
X-Request-URL
X-LiteSpeed-Tag
Ngx
X-Th-Server
X-Mid-Debug-Cache-Disk
X-Mid-Debug-Cache-Key
X-Cache-Ngx
MIME-Version
My-App
User-Agent