Threat Level: green Handler on Duty: Rob VandenBrink

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
X-XSS-Protection
Accept-Ranges
Expect-CT
Pragma
X-Powered-By
CF-RAY
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
CF-Ray
X-Download-Options
X-Xss-Protection
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Request-Id
X-Adblock-Key
Access-Control-Allow-Credentials
X-FRAME-OPTIONS
X-Permitted-Cross-Domain-Policies
X-Request-ID
Alt-Svc
X-AspNet-Version
X-Runtime
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Generator
X-Cache-Status
X-Cacheable
Timing-Allow-Origin
X-Envoy-Upstream-Service-Time
X-Iinfo
X-Content-Security-Policy
X-Drupal-Dynamic-Cache
Feature-Policy
Content-Encoding
Access-Control-Expose-Headers
Upgrade
Status
X-CDN
X-AspNetMvc-Version
Access-Control-Max-Age
X-Via
X-UA-Device
Server-Timing
Request-Context
X-Robots-Tag
X-Turbo-Charged-By
X-Amz-Request-Id
X-Cache-Group
X-Amz-Id-2
EagleId
X-Backend
X-AH-Environment
X-Proxy-Cache
P3p
Keep-Alive
X-Server
X-Ws-Request-Id
X-Age
Cf-Edge-Cache
Host-Header
X-Dns-Prefetch-Control
X-Hacker
X-Vhost
X-Server-Powered-By
X-Rq
X-Varnish-Cache
X-Dispatcher
X-Amz-Version-Id
Grace
Allow
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-OneAgent-JS-Injection
X-LiteSpeed-Cache
X-WebKit-CSP
X-Page-Speed
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Ua-Compatible
Cf-Apo-Via
X-Device
Cf-Railgun
Accept-CH
X-Aws-Lambda-Call-Status
X-Node
X-Pingback
X-Server-Id
X-Host
X-Ruxit-JS-Agent
EagleEye-TraceId
X-Nginx-Cache-Status
Surrogate-Control
X-Akam-SW-Version
X-Readtime
Request-Id
X-Backend-Server
X-Cache-Spec
X-Cache-Lookup
X-Content-Security-Policy-Report-Only
X-HW
Accept-Ch-Lifetime
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Cloud-Trace-Context
X-Trace
X-Application-Context
X-Response-Time
Permissions-Policy
X-Nginx-Upstream-Cache-Status
Fastly-Restarts
X-Edge
X-WebKit-CSP-Report-Only
X-Mod-Pagespeed
X-Country
Content-Location
X-Mcache
Accept-CH-Lifetime
X-Content-Type
X-MS-InvokeApp
X-Litespeed-Cache
X-Clacks-Overhead
X-Url
X-CST
X-PC
X-TtlSet
X-Vname
X-Amz-Server-Side-Encryption
X-Midtier
Rating
RTSS
Cache-Tag
X-Vcap-Request-Id
X-D2id
X-Element-Page-Cache
X-Kinja
X-Kinja-Build
Origin-Trial
X-Kinja-Revision
X-Rack-Cache
X-GoogleNews-Bot
X-Use-Magma
X-Exp-Id
X-Exp-Variant
X-Cdn-Fetch
X-Kinja-Server
Verso
X-ESI
X-VARITI-CCR
X-Server-Name
X-Ac
X-GitHub-Request-Id
X-Powered-By-Plesk
Service-Worker-Allowed
X-Cnection
X-Amz-Rid
X-SharePointHealthScore
SPRequestGuid
X-Navigation-Version
X-Ttl
Xkey
X-ECACHE
X-Abt-Application-Version
Edge-Control
X-Client-IP
SPIisLatency
SPRequestDuration
X-Cache-TTL
X-B3-TraceId
X-Upstream
Arr-Disable-Session-Affinity
X-Cached
X-NWS-LOG-UUID
X-Mg-S
X-Erf-Bev-Bev-Is-Generated
X-Instrumentation
X-Kraken-Loop-Name
X-Browser-Type
X-Server-Lifecycle-Phase
X-Erf-Bev-Bev
X-Dw-Request-Base-Id
X-Px
X-FastCGI-Cache
X-Varnish-TTL
Pagespeed
Display
X-Sol
X-Middleton-Display
X-Cache-Key
X-SRCache-Fetch-Status
X-SRCache-Store-Status
Accept-Ch
X-NF-Request-ID
Access-Control-Request-Method
Edge-Cache-Tag
X-Forwarded-For
X-Correlation-Id
X-Country-Code
X-Goog-Hash
Content-MD5
X-Ratelimit-Limit
X-Powered-CMS
TCN
X-Id
Front-End-Https
AR-ATIME
AR-Request-ID
AR-PoweredBy
AR-CACHE
AR-SID
X-Ser
Public-Key-Pins
X-Version
X-HP-Trace-Id
X-Jurisdiction
X-HP-Webp
X-MSEdge-Ref
X-Content-Digest
X-Recruiting
X-T
X-Amzn-Trace-Id
X-RateLimit-Remaining
Response
X-Middleton-Response
X-Accel-Expires
TP-Cache
TP-L2-Cache
MicrosoftSharePointTeamServices
X-Shield-Request-Id
S
Nginx-Cache
X-Daa-Tunnel
X-XRDS-Location
Cache-Status
X-Aspnetmvc-Version
X-Request-Received
Server-Node
X-Webkit-Csp
X-Request-Processing-Time
X-HS-Hub-Id
MRF-Tech
X-HS-Cache-Config
Mrf-Cache-Status
X-B3-TraceId-Primal
X-HS-Combine-CSS
X-HS-Content-Id
Cache-Tags
X-Distributor
Cross-Origin-Opener-Policy
X-Hits
X-Ratelimit-Remaining
X-TEC-API-ROOT
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-Edge-Location-Klb
X-Kinsta-Cache
X-LB-Cache
X-Fastcgi-Cache
X-Origin-Server
X-Ratelimit-Reset
X-PressLabs-Stats
X-Ua-Browser
X-Ezoic-Cdn
Fastcgi-Cache
Alternate-Protocol
Filterid
X-Grace
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-Hostname
X-Fastly-Request-ID
X-Frontend
Server-Name
X-Geo-Country
X-DIS-Request-ID
X-LLID
X-Microsite
X-Request-Handler-Origin-Region
X-Rid
X-ECache
Healthy
X-FB-Debug
X-Varnish-Backend
X-Git-Hash
X-Logged-In
X-Debug-Info
Payment
Cleartype
X-Protected-By
X-Load-Cache
X-Page-Id
X-Www-Served-By
X-Cluster-Name
X-Forwarded-Proto
X-Aspnet-Version
X-NGENIX-Cache
Realpath
DC
MS-Author-Via
X-DataDome
Content-Disposition
Access-Control-Allow-Method
X-ASPNET-VERSION
Charset
X-Origin-Cache
X-B3-Sampled
X-Goog-Metageneration
X-TTL
X-GUploader-UploadID
X-Kong-Proxy-Latency
X-Upgrade-Enabled
X-Kong-Upstream-Latency
X-Activity-Id
X-Az
X-Proxy
X-AppVersion
X-Seen-By
X-F-Cache
X-Amz-Meta-S3cmd-Attrs
X-Amz-Replication-Status
X-Whom
Cross-Origin-Resource-Policy
X-Azure-Ref
Paypal-Debug-Id
X-Fb-Rlafr
Count-Hit
X-B
X-Revision
X-Type
X-Contextid
Surrogate-Key
X-Request-Guid
X-Cache-Age
X-App-Environment
Viewport
Retry-After
Accept-Charset
X-Aspnet-Duration-Ms
X-Flags
X-Route-Name
X-Is-Crawler
X-Providence-Cookie
X-Akamai-Edgescape
X-Wix-Request-Id
X-Varnish-Server
X-B3-Traceid
X-Times
X-Hosted-By
X-TT
X-Signature
X-B-Cache
X-DynaTrace
X-Language
Amp-Access-Control-Allow-Source-Origin
X-Source
X-Cache-Control
X-Envoy-Decorator-Operation
X-App-Server
X-Mobile
X-VCache
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Varnish-Ttl
X-Oracle-Dms-Rid
X-Fastly-Request-Id
X-Varnish-Grace
X-Magnolia-Registration
X-Goog-Generation
X-Goog-Storage-Class
X-Oracle-Dms-Ecid
Host
Version
Referer-Policy
WPO-Cache-Status
WPO-Cache-Message
X-XRDS-LOCATION
X-N
X-Cache-Rule
X-Server-ID
Refresh
X-HTML-Minification-Powered-By
X-Original-Request-Id
Access-Control-Request-Headers
X-Varnish-Age
X-Response-Served-From
X-Cache-Time
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-EdgeConnect-Cache-Status
X-Tumblr-User
X-Rule
X-Cache-Status-Check
X-Cache-Grace
VIX-Pulpo-Upstream-Status
SD-X-WS
X-Framework
X-Cacheable-TTL
VIX-Pulpo-Node
X-Jobs
X-RTag
X-Amz-Apigw-Id
X-User-Agent
X-UUID
X-Tt-Trace-Host
X-Tt-Trace-Tag
Protected
X-Amzn-RequestId
X-G
MS-CV
Ms-Operation-Id
CDN-RequestId
Section-Io-Cache
GEO-INFO
From-Origin
X-Backend-Name
X-FW-Serve
X-FW-Version
X-FW-Type
X-L-Path
X-ProcessESI
X-RemovedCookies
X-FW-Server
X-FW-Static
X-FW-Hash
X-Content-Powered-By
X-Environment-Context
X-FW-Dynamic
X-Page-View
X-Nginx-Cache
X-Device-Type
X-Instance
Akamai-GRN
X-Status
X-Rendered-As
X-Http-Reason
X-Drupal-Cache-Contexts
X-Drupal-Cache-Tags
X-Akamai-Request-ID2
X-Is-Bot
X-Cache-Expired-At
X-Region
NGB
X-NYM-Debug-Backend
X-Adobe-Loc
X-Adobe-Content
Front
X-Servername
Url
X-Trace-Id
SRV
X-Unique-Id
Accept-Language
X-CDN-Forward
X-Template
Pinterest-Generated-By
Pinterest-Version
X-Debug-IsPreview
X-Debug-IsConnected
X-Pinterest-Rid
X-Content-Options
X-Newrelic-App-Data
Liferay-Portal
X-Yottaa-Metrics
X-Yottaa-Optimizations
Backend
Fastly-SIE
X-Cache-Hit
Fastly-SWR
X-Air-Hostname
X-Zen-Fury
X-Air-Source
X-Air-Trace-Id
X-RateLimit-Limit
Country
X-DynaTrace-JS-Agent
X-Mode
Content-Secure-Policy
X-Rocket-Nginx-Serving-Static
X-Cache-Operation
X-Time
Node
X-Tb
X-Rewrite-Enabled
X-Content-Age
X-Uri
X-COUNTRY
Uber-Trace-Id
X-Amzn-Remapped-Content-Length
X-Cache-Server
X-Generation-Time
Webserver
X-IPS-LoggedIn
X-RN-RSRV
S-Rt
X-UPSTREAM-Address
X-Tumblr-Pixel-2
Filters
Meta-Geo
X-Proxy-Cache-Info
Onion-Location
Azure-Version
Azure-SlotName
X-Locale
X-Timing-Wait
CF-IPCountry
Selected-Fe
X-Proxy-Build
Cache-Hits
Azure-SiteName
X-Real-IP
X-Edge-Location
X-PHP-Backend
Azure-InstanceId
X-Web-Node
Azure-RegionName
X-PHP-Host
Cache-Name
X-Cache-Action
X-Sucuri-Cache
X-Access
X-Cluster-Node
X-Proto
X-Origin-Date
X-Sucuri-ID
X-Section
X-Varnish-Beresp-Grace
X-Soup
X-Site-Version
X-SayCDN-TTL
X-Say-TTL
X-Format
X-Say-Cacheable
X-Server-W
X-Skip-Cache
X-Ms-Request-Id
X-Tumblr-Pixel-3
X-Ms-Version
X-Labrador-Cache-Channel
X-ProxyCache-Status
X-Ua
ServerID
X-ProxyCache-Key
ServedBy
X-Handled-By
Property-Id
TWC-Connection-Speed
Cross-Origin-Window-Policy
X-Via-Fastly
DB-Nickname
X-BYPASS-REASON
X-R9-Blue-Green-Version
TWC-Privacy
X-Proxied
X-Routing-Service
X-Sql-Duration-Ms
X-Sql-Count
X-Debug
X-UA-Device-Type
X-Cms-Context
X-Extlb
X-Forwarded-Host
X-Cache-Host
X-VC-Cache
TWC-Locale-Group
TWC-GeoIP-LatLong
TWC-GeoIP-Country
X-Reqid
X-Zipkin-Id
X-Origin-Hint
Webcakes-Region
Webcakes-App-Version
TWC-Device-Class
Webcakes-App-Name
X-ARC
Countrycode
X-JoinUs
X-LAGOON
X-LJ-Flow-ID
X-IPLB-Request-ID
X-FB-TRIP-ID
X-Adobe-Source
X-AWS-Id
Web-Mar-Node
X-IPLB-Instance
WP-Super-Cache
X-Proxy-Cache-Status
Apigw-Requestid
X-VWS-Id
X-SaId
X-URL
X-Optimistic-Header
Cache-Tv-Group
X-Cache-TTL-Remaining
X-Tt-Logid
X-Cluster
X-Urbn-Site-Id
X-Node-Name
X-Detected-As
X-Urbn-Context-Path
X-No-Session
Mn-Server-Ip
Locale
X-LSADC-Cache
X-GeoCountry
X-GeoCode
Fastcgi-Useragent
X-TIME
X-WP-CF-Super-Cache
X-Ruxit-Js-Agent
X-WP-CF-Super-Cache-Cache-Control
X-App-Version
X-Director
X-Xfnlog-Site
Mime-Version
Upgrade-Insecure-Requests
Source
X-Varnish-Hits
X-GEO
X-Oneagent-Js-Injection
CDN-RequestCountryCode
X-Hl-Ver
Frame-Options
CDN-Cache
CDN-PullZone
CDN-CachedAt
CDN-EdgeStorageId
X-Generated-By
CDN-Uid
X-Buckets
X-Mg-Request-UUID
Fastly-Drupal-HTML
X-Request-Time
X-FireWall-Port
X-Api-Version
X-Varnish-Cache-Hits
Xet-Cookie
X-Redis-Cache
X-Tec-Api-Version
X-Tec-Api-Root
X-Tec-Api-Origin
X-Loop
X-Origin-TTL
X-Cdn
X-Origin-CC
X-Varnish-Hostname
X-Cache-Debug
X-RM-Cache-TTL
X-ServerID
X-TA-CDN-Provider
Load-Balancing
X-Datadog-Sampled
X-Datadog-Sampling-Priority
CF-Cached-On
X-Datadog-Parent-Id
X-Datadog-Trace-Id
X-Tx-Id
X-SRV
X-Akamai-Transformed
X-Alternate-Cache-Key
X-ShopId
X-Sorting-Hat-ShopId
X-Storefront-Renderer-Rendered
X-Pass-Why
X-Shopify-Stage
X-Sorting-Hat-PodId
X-ShardId
X-Pubstack
X-Served-From
X-Storage
X-Service
X-TNCMS
X-Endurance-Cache-Level
X-Request-Host
X-Restarts
X-Air-Pt
Server-Info
X-Location
X-A-Dcw
Thinkindot-CacheControl-Type
WWW-Authenticate
Thinkindot-Control
X-A-Ccd
X-A-Dam
X-A
Meta-Geo-Continent
Cache-Host
Lang
BehaviorPad-Version
A
MD5-Digest
Candidate-Md5Url
DCR-Decision-By
Edge-Cache
DSUID
DCR-Processing-Time-Ms
Gannett-Cam-Experience-Id
Host-ID
X-A-Dgt
Memcached
Sslversion
Server-Host
Surrogated-Key
T-Server
TDXMobile
Rendered-Blocks
Release
NM-Fastcgi-Cache
Ngx.Var.Host
Odigeo-Trace-Id
Origin
Redirect-Candidate
Thinkindot-CacheControl
X-Gdpr
X-Rocket-Build-Number
X-Processor
X-Rojux
X-S
X-S-Maxage
X-S-Cookie
X-Platform-Router
X-Platform-Processor
X-Nyt-Route
X-Mobile-URL
X-Origin
X-Origin-Time
X-Platform-Cluster
X-ScT
X-Sigma
X-TIM-N
X-Thinkindot-L3
X-Vdms-Path
X-Vdms-Version
Xc-Version
X-We-Are-Hiring
X-Thanos
X-Test
X-Sn-Servicetimems
X-Sigma-Backend
X-SRCache-Key
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-Mid
X-Men
X-Cache-NE
X-Cache-Info
X-Cdn-Origin
X-CMSURLCustom
X-Core-Mission
X-Conf
X-Cache-Date
X-Bip
X-Akamai-Device-Characteristics
X-Aed
X-Application
X-Bc-Bl
X-BCube-Filmed-By
X-CUA
X-D
X-Httpd
X-Hash
X-INCAP-ABP
X-Level-Front-Cache
X-Loc
X-Generated-On
X-External-Request-Id
X-Developer
X-Destination
X-Ec-Fail
X-Ec-GeoHdr
X-Epic-Correlation-Id
X-A-Wwc
X-B-Cookie
X-Newrelic-Synthetics
X-CSRF-Token
Xserver
X-WP-CF-Super-Cache-Active
X-Dispatcher-Number
X-Date
X-CacheTTL
X-Cache-Id
X-Dispatcher-Server
X-Correlation-ID
X-Fetched-On
X-Gamma-Serve
X-Geo-Header
X-Fastly-Cache
X-Fastly-Backend
X-Cache-Bucket
X-Esi-Check
X-Ec-Custom-Error
X-Auto-Login
Section-Io-Origin-Status
Req-Svc-Chain
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
Mail-Subject
Platform
Section-Io-Id
X-Provided-By
X-Ad-Defer-Variation
X-GeoIP
X-Accel-Expires-Debug
We-Hiring
Vix-Hermes-Req-Id
X-BBC-Edge-Cache-Status
X-Has-Esi
X-Slack-Backend
X-Slack-Shared-Secret-Outcome
X-Server-IP
X-SD-PageType
X-Region-Sid
X-Scale
X-Var-Ttl
X-Variation
X-VServer
X-Worker
X-Vmg-Version
X-Varnishpool
X-Varnish-Beresp-Status
X-Pool
X-Platform
X-Human
X-Is-Gdpr
X-HS-Content-Campaign-Id
Magicmarker
X-Gzip
X-JWT-State
X-CACHE-AGE
X-Origin-Expires
X-Origin-Response-Time
X-Org
X-NodeID
X-Mvc-Supplant-Cachable
X-GeoIP-City
X-Node-Id
Is-Eu
Adler-Geo
Gh-Request-Id
AKAMAI
CacheControlHeader
C-Via
Cache-Key
CloudFront-Viewer-Country
Country-Code
Fastly-Backend-Name
Fastly-GeoIP-CountryCode
X-Parent-Response-Time
Environment
X-Cache-FS-Status
Canary
Datacenter
X-Irp-Debug
X-Mly-Id
X-FC-Vary-Parameters
X-Azure-Ref-OriginShield
X-Nginx-Cache-Key
X-Device-Os
X-Cache-Tags
X-Instance-Name
X-Core-Value
Apple-News-Services-Request-Url
X-Frame-Option
X-Forwarded-Site
X-Clara-WADP
X-GeoIP-Country-Code
X-Cdn-Srv
X-Developers
X-GeoIP-Region-Code
X-Fmm-Version
X-Planisys-CDN-Rules
Tube-Got-Eval
Tube-Got-Results
Tube-Get-Contents
Cmstype
Click-Count-Error
Cmsid
Tube-Return
X-DefElseHash
X-Varnish-Remaining-TTL
X-Response-By
X-Varnish-CookieINHashed-On
X-Varnish-CookieHashed-On
X-DefHash
X-Req
Click-Count-Action-Start
X-Wix-Viewer-Type
Apple-News-Services-Host
Apple-News-Services-Handled
Apple-News-Services-Parsed-Url
X-Planisys-CDN-TTL
X-Planisys-CDN-Cache
X-App
X-Qloud-Router
X-Release
X-WA-Info
X-WADP-Cache
X-VG-TLSProxy
X-V-Cache
Machine
X-Owner
X-Request-Start
X-Accel-Buffering
On-Server
Origin-CC
Origin-EX
Web-Mar-Region
Ssr
State
Kp-EeAlive
X-Varnish-Beresp-Ttl
Wxu-Next-Commit
X-Platform-Server
NGX
Wxu-Next-Hostname
Producers
X-Ckpd-Fst-Backend
PFcat
User-Cache-Control
X-NCache
Cache-Provider
X-Old-Content-Length
X-Op-Id-All
Expect-Staple
L
X-VarnishDD-TTL
X-SB
X-DPWN-IS-SECURE
X-HN
X-Hnp-Log
Sever-Int
X-Gen-Mode
Wxu-Next-Region
Server-Ext
Fastly-SSL
X-Aicache-OS
X-Block-Status
Server-Hostname
HostName
X-Vcl-Version
X-B3-Spanid
X-Via-CDN
X-Minions-Version
X-Eu-Site
X-FL-QIT-DEBUG
X-Cache-Remote
X-Microcachable
Ha-Gx-Prefs
CDCHOST
L5d-Success-Class
HA-Ipaddr
X-Esi
X-CGP
Locid
X-Nananana
X-Mvc-Supplant-OutputCached
Srvid
X-Csrf-Jwt
X-FL-EDGE
X-LB-NoCache
X-Via-SSL
Edge-Copy-Time
X-Zone
X-Webkit-CSP-Report-Only
X-Via-Edge
X-Cache-Backend
X-Tb-Optimization-Total-Bytes-Saved
Env
X-NWS-UUID-VERIFY
X-From
X-Client-Ip
Pics-Label
X-VC
Decoy-Debug-Key
Decoy-Debug-Status
X-Cache-Enabled
X-Refresh
Cluster
GeoIP-Latitude
X-Up
Decoy-Debug-TTL
X-DC
X-Dc
X-Tid
X-Cached-By
X-Debug-Cache-Store
X-Generated-In
X-RCS-CacheZone
X-Lambda-Id
X-ND-Cache
X-Debug-Cache-Fetch
X-Presslabs-Stats
Cache
Sid
NtCoent-Length
X-Trace-ID
X-Via-Poph
X-VCT
X-Via-Popv
X-HS-Status
X-Via-Popn
SID
X-Srv
X-Servedbyhost
CPC-Cache
CPC-Age
X-Render-Time
Memory
X-Edge-Pop
Time
X-DataCenter
Fastly-Drupal-Html
VNS-Age
X-Cs
VNS-Cache
X-Vtex-Remote-Cache
X-B3-SpanId
X-Webkit-CSP
X-HA-Backend
X-LB-ID
X-Vgn-Hpd-Ssi
X-Upstream-Ct
X-Hcs-Proxy-Type
X-CCDN-CacheTTL
X-Upstream-Ht
X-Vgn-Hpd-Cached
X-Vgn-Hpd-Variations-Key
Svr
X-CCDN-Origin-Time
X-Nc
X-Cache-Type
X-TH-Server
X-Wa
GeoIp-Country-Code
X-Vc
AMP-Access-Control-Allow-Source-Origin
X-ZONE
Cdn
Server-ID
X-Via-JSL
X-NewRelic-App-Data
X-ATG-Version
X-CLOUD-TRACE-CONTEXT
X-Varnish-Authentication
Uri
X-AIR-PT
True-Client-IP
X-Contensis-Viewer-Groups
X-Cache-ASPX
Srv
XServer
X-Amz-Meta-Cb-Modifiedtime
X-Fpc
Hostname
XkeyRZ
X-Check-Cacheable
X-Varnish-Beresp-TTL
X-Proxy-CacheRZ
X-Gateway-Cache-Status
X-Gateway-Cache-Key
X-RateLimit-Limit-Second
X-AK-Request-ID
X-CS
X-RateLimit-Remaining-Second
X-Gateway-Skip-Cache
Cdncip
X-PAYTM-SRV-ID
X-Gateway-Request-Id
Cdnsip
X-MP-GENERATED-AT
X-CF-Lambda-Fn
Esi-Enabled
X-CF-Lambda-Version
X-Via-NSCOPI
X-Nf-Request-Id
X-CSRF-TOKEN
M-TraceId
X-EC-Lua
X-NGINX-Cache
OT-Force-Account-Verify
X-API-Version
X-FPC
X-Wikidot-Static-Cache
Resin-Trace
X-CDN-Cache-Status
X-Wikidot-Backend
N-Cache
X-Udemy-Cache-App-Namespace
YJS-ID
Lb
X-Bl-Debug
X-MSEdge-Features
X-Forwarded-Path
X-Shop-Environment
X-APP-VERSION
Eomportal-Instance
X-Tenant
X-Orig-Expires
X-MSEdge-Flight
RNT-Machine
RNT-Time
True-Client-Ip
X-Datadome
X-Fastly-Country-Code
CDN
X-TX-ID
Request-ID
Path
X-B3-Trace-ID
X-Service-Response-Time
X-Micro-Cache
Sm-Log-Id
Ngx-Var-Key
X-Policy
X-App-Name
Server-Id
X-WA
IsBot
GeoIP-Country-Code
X-Cache-Ttl
X-CACHE-KEY
X-SIPLIST1
X-Vcache
X-Ha-Backend
X-Request-URI
LB
X-Accel-Version
X-Cache-NGX
X-Logging-Id
X-NC
X-MCACHE
Hit
X-Lb-Id
X-Info
X-Edge-POP
X-VCL-Version
X-Container-Uri
X-Git-Commit
HIT
Cross-Origin-Opener-Policy-Report-Only
X-RateLimit-Reset
Pramga
X-Cdn-Diag
X-Datacenter
X-Pod-Name
X-Cdn-Cache-Status
X-SERVER-NAME
X-ServedByHost
Location
Ohc-File-Size
X-Geo
X-Akamai-Pragma-Client-IP
X-Srcache-Store-Status
X-Snapshot-Date
X-Tncms
X-Srcache-Fetch-Status
X-Cdn-Forward
X-Via-PopH
X-Via-PopN
FSS-Cache
X-VG-WebCache
Timeexpire
X-Via-PopV
X-Oss-Request-Id
X-Oss-Object-Type
V-Age
X-Oss-Server-Time
X-Ctl-Mach
X-Acquia-Purge-Cdn-Unconfigured
X-Oss-Hash-Crc64ecma
Req-ID
Epwk-X-Cache
X-Cache-Expires
True-Client-Country-4JS
X-Cdn-Request-ID
XM
X-Oss-Storage-Class
Yjs-Id
Geoip-Latitude
Proxy-Connection
ENV
Servername
X-Wp-Cf-Super-Cache-Cache-Control
X-Iauth-Set-Uid
X-Wp-Cf-Super-Cache
WZWS-RAY
X-TT-LOGID
X-Hyper-Cache
X-Fastly-Backend-Reqs
X-Lb-Nocache
X-Clientip
X-Serial
CDN-RequestPullSuccess
X-LiteSpeed-Cache-Control
CDN-RequestPullCode
X-Amz-Meta-Opti
X-UP
X-TRACE-ID
X-Dw-Trace-Id
Warning
X-MiniProfiler-Ids
X-Rebelmouse-Cache-Control
X-M-Reqid
X-Rebelmouse-Surrogate-Control
X-M-Log
X-Acquia-Site
X-Acquia-Purge-Tags
X-Acquia-Application-UUID
X-Moov-Xdn-Version
Ec-Rule-Version
X-Swift-Error
X-Acquia-Application-Trace
X-Akamai-ERRuleID
X-Akamai-ERPolicy
X-B3-Parentspanid
X-RAMCache
X-Qnm-Cache
Cneonction
Content-Script-Type
X-Scheme
Content-Style-Type
X-Moov-T
X-F-Status
X-Lsadc-Cache
CountryCode
X-LiteSpeed-Tag
Ohc-Cache-HIT
Ngx
X-Cached-Since
My-App
X-WP-CF-Super-Cache-Cookies-Bypass
PICS-Label
Traceparent
X-Webstats-RespID
Inserted-Into-Cache-At
MIME-Version
X-Fastly-Cache-Hits
X-IPS-Cached-Response
X-B3-ParentSpanId
X-Th-Server
X-Mg-Cache
X-Litespeed-Cache-Control
X-Cache-Ngx
X-TraceId