Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
X-XSS-Protection
Accept-Ranges
Expect-CT
Pragma
X-Powered-By
CF-RAY
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-Download-Options
X-Xss-Protection
CF-Ray
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Request-Id
Access-Control-Allow-Credentials
X-FRAME-OPTIONS
X-Request-ID
X-Permitted-Cross-Domain-Policies
X-AspNet-Version
Alt-Svc
X-Runtime
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Generator
X-Cache-Status
X-Cacheable
Timing-Allow-Origin
X-Envoy-Upstream-Service-Time
X-Iinfo
X-Content-Security-Policy
X-Drupal-Dynamic-Cache
Feature-Policy
Content-Encoding
Access-Control-Expose-Headers
Upgrade
Status
X-CDN
X-AspNetMvc-Version
X-Ua-Compatible
Access-Control-Max-Age
X-Via
Server-Timing
X-UA-Device
Request-Context
X-Robots-Tag
X-Turbo-Charged-By
X-Amz-Request-Id
X-Cache-Group
EagleId
X-Amz-Id-2
X-Backend
X-AH-Environment
X-Proxy-Cache
Keep-Alive
P3p
X-Server
X-Ws-Request-Id
X-Age
X-Dns-Prefetch-Control
Host-Header
Cf-Edge-Cache
X-Hacker
X-Vhost
X-Server-Powered-By
X-Rq
X-Varnish-Cache
X-Dispatcher
X-Amz-Version-Id
Grace
Allow
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-OneAgent-JS-Injection
X-LiteSpeed-Cache
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Page-Speed
X-Device
Cf-Apo-Via
X-WebKit-CSP
Accept-CH
Cf-Railgun
X-Aws-Lambda-Call-Status
X-Node
X-Pingback
X-Host
X-Ruxit-JS-Agent
X-Server-Id
EagleEye-TraceId
X-Nginx-Cache-Status
Surrogate-Control
X-Akam-SW-Version
X-Readtime
X-Backend-Server
Request-Id
X-Cache-Spec
X-Cache-Lookup
X-HW
X-Content-Security-Policy-Report-Only
X-Cloud-Trace-Context
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Trace
X-Application-Context
X-Response-Time
Permissions-Policy
Accept-Ch-Lifetime
X-Nginx-Upstream-Cache-Status
Fastly-Restarts
X-Edge
X-Mod-Pagespeed
X-WebKit-CSP-Report-Only
Accept-CH-Lifetime
X-Mcache
X-Content-Type
Content-Location
X-Url
X-MS-InvokeApp
X-Country
X-Clacks-Overhead
X-CST
X-TtlSet
X-PC
X-Vname
X-Amz-Server-Side-Encryption
X-Midtier
Rating
X-Litespeed-Cache
RTSS
Cache-Tag
X-ESI
X-Vcap-Request-Id
X-D2id
X-Element-Page-Cache
X-Kinja-Revision
X-Kinja-Server
X-Use-Magma
X-Kinja-Build
X-Kinja
X-Exp-Id
X-Exp-Variant
X-GoogleNews-Bot
Origin-Trial
X-Cdn-Fetch
Verso
X-Rack-Cache
X-VARITI-CCR
X-Server-Name
X-Ac
X-Ttl
X-Powered-By-Plesk
X-GitHub-Request-Id
Service-Worker-Allowed
X-Cnection
X-Amz-Rid
X-Client-IP
SPRequestGuid
X-SharePointHealthScore
X-Navigation-Version
Xkey
X-ECACHE
X-Abt-Application-Version
Edge-Control
SPRequestDuration
SPIisLatency
X-Cache-TTL
X-Upstream
Arr-Disable-Session-Affinity
X-NWS-LOG-UUID
X-FastCGI-Cache
X-Cached
X-B3-TraceId
X-Erf-Bev-Bev
X-Browser-Type
X-Erf-Bev-Bev-Is-Generated
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-Instrumentation
X-Mg-S
X-Dw-Request-Base-Id
X-Webkit-Csp
X-Px
X-Cache-Key
X-Varnish-TTL
X-Sol
Display
Pagespeed
X-Middleton-Display
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-NF-Request-ID
Access-Control-Request-Method
Edge-Cache-Tag
X-Forwarded-For
X-Country-Code
X-Correlation-Id
X-Goog-Hash
Content-MD5
TCN
X-Powered-CMS
X-Ratelimit-Limit
Front-End-Https
AR-ATIME
X-Id
AR-SID
AR-Request-ID
AR-PoweredBy
AR-CACHE
Public-Key-Pins
X-Version
X-Ser
X-HP-Webp
X-Jurisdiction
X-HP-Trace-Id
X-MSEdge-Ref
X-Recruiting
X-Content-Digest
X-T
X-RateLimit-Remaining
X-Amzn-Trace-Id
Accept-Ch
Response
X-Middleton-Response
X-Accel-Expires
X-XRDS-Location
TP-Cache
TP-L2-Cache
X-Shield-Request-Id
X-Daa-Tunnel
MicrosoftSharePointTeamServices
S
Nginx-Cache
Cache-Status
MRF-Tech
Mrf-Cache-Status
Server-Node
X-Request-Received
X-B3-TraceId-Primal
X-Request-Processing-Time
X-HS-Cache-Config
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Combine-CSS
Cache-Tags
X-Hits
X-Distributor
X-Ratelimit-Remaining
Cross-Origin-Opener-Policy
X-Edge-Location-Klb
X-Kinsta-Cache
X-LB-Cache
X-Origin-Server
X-Ratelimit-Reset
X-Ua-Browser
X-PressLabs-Stats
X-TEC-API-ORIGIN
Fastcgi-Cache
X-Ezoic-Cdn
X-TEC-API-ROOT
X-TEC-API-VERSION
Alternate-Protocol
X-Grace
Filterid
Server-Name
X-Frontend
X-ORACLE-DMS-ECID
X-Fastly-Request-ID
X-ORACLE-DMS-RID
X-DIS-Request-ID
X-ECache
X-Request-Handler-Origin-Region
X-Hostname
X-Fastcgi-Cache
X-Microsite
X-Geo-Country
X-Rid
Healthy
X-LLID
X-Protected-By
X-FB-Debug
Cleartype
X-Git-Hash
X-Logged-In
X-Varnish-Backend
Payment
X-Debug-Info
X-Www-Served-By
X-Page-Id
X-Forwarded-Proto
X-Load-Cache
X-DataDome
X-Cluster-Name
X-NGENIX-Cache
DC
Realpath
MS-Author-Via
X-Origin-Cache
Content-Disposition
X-ASPNET-VERSION
Charset
Access-Control-Allow-Method
X-B3-Sampled
X-B3-Traceid
X-GUploader-UploadID
X-Upgrade-Enabled
X-Goog-Metageneration
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Proxy
X-Activity-Id
X-AppVersion
X-Az
X-Seen-By
X-F-Cache
X-Amz-Meta-S3cmd-Attrs
X-Amz-Replication-Status
Paypal-Debug-Id
X-Azure-Ref
X-Fb-Rlafr
Count-Hit
Cross-Origin-Resource-Policy
X-Whom
X-Type
X-Contextid
Viewport
Surrogate-Key
X-Revision
Retry-After
X-Request-Guid
X-Is-Crawler
X-Flags
X-Providence-Cookie
X-App-Environment
X-Wix-Request-Id
X-Route-Name
X-Varnish-Server
X-Aspnet-Duration-Ms
X-B
X-Hosted-By
Accept-Charset
X-Akamai-Edgescape
X-TTL
X-Cache-Age
X-Server-ID
X-B-Cache
Amp-Access-Control-Allow-Source-Origin
X-Signature
X-TT
X-Aspnetmvc-Version
X-DynaTrace
X-Language
X-VCache
X-Times
X-Source
X-Cache-Control
X-App-Server
X-Varnish-Ttl
X-Mobile
X-Envoy-Decorator-Operation
X-Oracle-Dms-Ecid
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-Oracle-Dms-Rid
X-Goog-Stored-Content-Encoding
X-Goog-Generation
Referer-Policy
X-Magnolia-Registration
X-Varnish-Grace
X-Fastly-Request-Id
Host
Version
X-Cache-Rule
X-N
X-HTML-Minification-Powered-By
Refresh
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Tt-Trace-Tag
X-Response-Served-From
X-Tumblr-Pixel-1
X-Tt-Trace-Host
X-Original-Request-Id
X-Tumblr-User
X-Varnish-Age
X-Rule
X-Cache-Time
X-Cache-Status-Check
X-EdgeConnect-Cache-Status
Access-Control-Request-Headers
X-Framework
Ms-Operation-Id
MS-CV
X-RTag
X-User-Agent
X-UUID
X-Cache-Grace
SD-X-WS
WPO-Cache-Message
X-Jobs
Section-Io-Cache
WPO-Cache-Status
X-Cacheable-TTL
Akamai-GRN
GEO-INFO
X-FW-Hash
Protected
X-ProcessESI
X-RemovedCookies
X-Status
X-FW-Version
X-FW-Static
X-Content-Powered-By
X-FW-Dynamic
X-FW-Serve
X-FW-Server
X-Backend-Name
X-FW-Type
From-Origin
VIX-Pulpo-Upstream-Status
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Trace-Id
X-Page-View
X-Device-Type
X-Cache-Expired-At
X-Instance
X-Environment-Context
VIX-Pulpo-Node
X-L-Path
X-G
X-Http-Reason
X-NYM-Debug-Backend
X-Rendered-As
X-Is-Bot
X-Akamai-Request-ID2
CDN-RequestId
X-Drupal-Cache-Tags
X-Drupal-Cache-Contexts
X-Adobe-Loc
X-Adobe-Content
Url
NGB
X-Region
X-Servername
SRV
X-XRDS-LOCATION
Front
X-Nginx-Cache
X-CDN-Forward
X-COUNTRY
X-Template
X-Unique-Id
Accept-Language
X-Debug-IsPreview
X-Content-Options
X-Debug-IsConnected
X-Yottaa-Optimizations
Backend
X-Yottaa-Metrics
X-Cache-Hit
Fastly-SWR
Fastly-SIE
Liferay-Portal
X-Zen-Fury
X-RateLimit-Limit
Country
X-Air-Trace-Id
X-Air-Hostname
X-Air-Source
X-DynaTrace-JS-Agent
Pinterest-Version
Pinterest-Generated-By
X-Pinterest-Rid
X-Mode
X-Newrelic-App-Data
X-Tb
X-Cache-Operation
Content-Secure-Policy
X-Rocket-Nginx-Serving-Static
X-Real-IP
X-Tt-Logid
Uber-Trace-Id
X-UPSTREAM-Address
Webserver
X-Tumblr-Pixel-2
X-Cache-Server
X-Proxy-Cache-Info
X-Generation-Time
Onion-Location
Meta-Geo
S-Rt
Filters
X-Amzn-Remapped-Content-Length
X-Content-Age
X-RN-RSRV
X-Rewrite-Enabled
X-TIME
X-IPS-LoggedIn
X-Edge-Location
X-Locale
X-Section
Azure-SlotName
Cache-Hits
X-PHP-Backend
X-Format
X-Timing-Wait
Selected-Fe
Azure-Version
CF-IPCountry
X-Access
Azure-RegionName
X-Proxy-Build
Azure-InstanceId
X-Web-Node
Azure-SiteName
X-Soup
TWC-GeoIP-LatLong
TWC-Device-Class
X-Uri
TWC-Locale-Group
Webcakes-App-Name
Node
X-Server-W
X-Cluster-Node
TWC-GeoIP-Country
Webcakes-Region
Webcakes-App-Version
TWC-Connection-Speed
X-Proto
X-Say-Cacheable
X-Varnish-Beresp-Grace
X-Say-TTL
X-SayCDN-TTL
Cache-Name
X-Skip-Cache
Property-Id
ServedBy
X-Node-Name
X-Ms-Request-Id
X-Site-Version
X-Forwarded-Host
X-Ms-Version
X-Sucuri-Cache
TWC-Privacy
X-Sucuri-ID
X-Origin-Hint
ServerID
X-ProxyCache-Key
X-PHP-Host
X-Tumblr-Pixel-3
X-VC-Cache
X-Proxied
X-Via-Fastly
X-Origin-Date
X-Zipkin-Id
X-R9-Blue-Green-Version
X-Cache-Action
X-Labrador-Cache-Channel
X-Routing-Service
X-Reqid
X-Handled-By
X-Extlb
X-Debug
X-BYPASS-REASON
X-ProxyCache-Status
X-UA-Device-Type
X-Ua
X-Sql-Count
X-Sql-Duration-Ms
Web-Mar-Node
X-Cms-Context
Cross-Origin-Window-Policy
DB-Nickname
X-Cache-TTL-Remaining
Countrycode
X-Cache-Host
X-JoinUs
X-LJ-Flow-ID
X-IPLB-Instance
X-Adobe-Source
X-VWS-Id
X-AWS-Id
X-Proxy-Cache-Status
Mn-Server-Ip
X-FB-TRIP-ID
X-IPLB-Request-ID
X-Time
X-Cluster
X-SaId
X-LAGOON
Locale
X-Urbn-Site-Id
X-No-Session
X-Detected-As
X-Xfnlog-Site
X-Urbn-Context-Path
X-Optimistic-Header
Apigw-Requestid
X-ARC
X-LSADC-Cache
X-GeoCode
Fastcgi-Useragent
WP-Super-Cache
X-GeoCountry
X-Ruxit-Js-Agent
Mime-Version
Cache-Tv-Group
X-App-Version
X-Tec-Api-Origin
X-Director
X-Tec-Api-Version
X-Tec-Api-Root
Upgrade-Insecure-Requests
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
X-Buckets
Source
X-Varnish-Hits
X-Hl-Ver
X-Oneagent-Js-Injection
CDN-Uid
CDN-PullZone
CDN-EdgeStorageId
CDN-Cache
CDN-CachedAt
X-GEO
CDN-RequestCountryCode
X-Generated-By
X-Mg-Request-UUID
X-Request-Time
Frame-Options
Fastly-Drupal-HTML
X-Redis-Cache
X-Loop
X-FireWall-Port
X-Cache-Debug
X-Tx-Id
CF-Cached-On
X-TA-CDN-Provider
Xet-Cookie
X-Varnish-Cache-Hits
X-Origin-TTL
X-Origin-CC
X-RM-Cache-TTL
X-Api-Version
X-Varnish-Hostname
X-URL
X-SRV
X-ServerID
Load-Balancing
X-Pass-Why
X-Datadog-Sampling-Priority
X-Datadog-Sampled
X-Datadog-Trace-Id
X-Datadog-Parent-Id
X-Newrelic-Synthetics
X-ShopId
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Shopify-Stage
X-Storefront-Renderer-Rendered
X-ShardId
X-Alternate-Cache-Key
X-TNCMS
X-Akamai-Transformed
X-Pubstack
X-Served-From
X-Request-Host
X-Endurance-Cache-Level
X-Location
X-Service
Server-Info
WWW-Authenticate
X-A
TDXMobile
X-A-Ccd
T-Server
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
Sslversion
Surrogated-Key
Thinkindot-Control
Xc-Version
Redirect-Candidate
Host-ID
Lang
X-A-Dam
MD5-Digest
Gannett-Cam-Experience-Id
Cache-Host
DCR-Processing-Time-Ms
DSUID
Candidate-Md5Url
Edge-Cache
Memcached
Meta-Geo-Continent
Rendered-Blocks
A
X-WP-CF-Super-Cache-Active
X-Storage
Release
DCR-Decision-By
Ngx.Var.Host
BehaviorPad-Version
Odigeo-Trace-Id
Origin
X-Restarts
X-Cache-NE
X-Loc
X-Level-Front-Cache
X-Mid
X-Mobile-URL
X-Origin-Time
X-Nyt-Route
X-INCAP-ABP
X-SVT-ORM-RULES
X-Generated-On
X-Gdpr
X-Hash
X-Httpd
X-SVT-ORM-VERSION
X-SRCache-Key
X-Platform-Cluster
X-S-Maxage
X-S-Cookie
X-Sigma-Backend
X-Sigma
X-ScT
X-S
X-Rojux
X-Platform-Router
X-Platform-Processor
X-Processor
X-Sn-Servicetimems
X-Rocket-Build-Number
X-External-Request-Id
X-Epic-Correlation-Id
X-Vdms-Version
X-BCube-Filmed-By
X-Cache-Date
X-Vdms-Path
X-Cache-Info
X-Bc-Bl
X-B-Cookie
X-A-Wwc
X-A-Dgt
X-Aed
X-Application
X-We-Are-Hiring
X-TIM-N
X-Cdn-Origin
X-Destination
X-D
X-Developer
X-Ec-Fail
X-Ec-GeoHdr
X-CUA
X-Test
X-Thinkindot-L3
X-CMSURLCustom
X-Conf
X-Thanos
X-Core-Mission
X-A-Dcw
X-Bip
Xserver
X-Air-Pt
Mail-Subject
Magicmarker
X-JWT-State
X-Mvc-Supplant-Cachable
Section-Io-Origin-Time-Seconds
X-Human
Section-Io-Origin-Status
X-Is-Gdpr
X-Node-Id
Section-Origin-Responded
X-CACHE-AGE
Fastly-Backend-Name
X-SD-PageType
X-Server-IP
X-Slack-Backend
Fastly-GeoIP-CountryCode
X-Region-Sid
X-Org
X-Origin-Response-Time
X-Pool
Section-Io-Id
X-HS-Content-Campaign-Id
X-Cdn-Srv
X-Date
X-Developers
X-Dispatcher-Number
X-CacheTTL
X-Cache-Bucket
We-Hiring
X-Accel-Expires-Debug
X-Auto-Login
X-BBC-Edge-Cache-Status
X-Ec-Custom-Error
X-Fastly-Backend
X-Geo-Header
X-GeoIP
X-GeoIP-City
X-Has-Esi
X-Correlation-ID
X-Gamma-Serve
X-Fastly-Cache
X-Fetched-On
Req-Svc-Chain
X-Slack-Shared-Secret-Outcome
Gh-Request-Id
C-Via
X-Men
Cache-Key
CacheControlHeader
X-Origin
X-Akamai-Device-Characteristics
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
NM-Fastcgi-Cache
Server-Host
AKAMAI
Apple-News-Services-Handled
Apple-News-Services-Host
X-VServer
X-Worker
X-Varnish-Beresp-Status
X-Varnishpool
X-Vmg-Version
Country-Code
X-Var-Ttl
CloudFront-Viewer-Country
X-Parent-Response-Time
X-CSRF-Token
X-Device-Os
X-Instance-Name
X-FC-Vary-Parameters
Wxu-Next-Region
X-Cache-Id
X-Dispatcher-Server
X-Accel-Buffering
X-Gzip
X-Esi-Check
X-Scale
X-NodeID
X-Clara-WADP
X-Platform
X-Cache-Tags
X-Origin-Expires
X-Azure-Ref-OriginShield
X-Request-Start
X-Variation
X-DefElseHash
X-App
X-Core-Value
X-DefHash
X-GeoIP-Country-Code
X-WA-Info
X-VG-TLSProxy
X-Nginx-Cache-Key
X-NCache
X-WADP-Cache
Wxu-Next-Hostname
X-Qloud-Router
X-Varnish-CookieINHashed-On
X-Varnish-CookieHashed-On
X-Varnish-Remaining-TTL
X-VarnishDD-TTL
X-Req
X-Mly-Id
X-Wix-Viewer-Type
Vix-Hermes-Req-Id
Platform
X-Frame-Option
X-Forwarded-Site
X-Ad-Defer-Variation
X-B3-Spanid
X-GeoIP-Region-Code
Adler-Geo
Is-Eu
X-Irp-Debug
X-HN
X-Fmm-Version
X-Op-Id-All
Origin-CC
Origin-EX
Click-Count-Error
On-Server
Tube-Got-Eval
Tube-Get-Contents
PFcat
Click-Count-Action-Start
Ssr
State
X-Varnish-Beresp-Ttl
Cache-Provider
Canary
Tube-Got-Results
Wxu-Next-Commit
Datacenter
L
Kp-EeAlive
Machine
Web-Mar-Region
Cmsid
Tube-Return
Cmstype
Environment
X-Provided-By
Ha-Gx-Prefs
X-Eu-Site
X-Planisys-CDN-Cache
Sever-Int
X-DPWN-IS-SECURE
X-SB
X-Planisys-CDN-TTL
Server-Hostname
HA-Ipaddr
X-Old-Content-Length
X-Planisys-CDN-Rules
CDCHOST
X-Release
X-NWS-UUID-VERIFY
NGX
X-Hnp-Log
X-LB-NoCache
L5d-Success-Class
X-Cache-FS-Status
Producers
X-Gen-Mode
Server-Ext
X-Owner
X-V-Cache
Fastly-SSL
X-Ckpd-Fst-Backend
X-Block-Status
X-Response-By
X-CGP
X-Csrf-Jwt
User-Cache-Control
X-Platform-Server
X-Nananana
X-Cache-Remote
X-Refresh
Srvid
X-Aicache-OS
X-Mvc-Supplant-OutputCached
Expect-Staple
X-Minions-Version
X-FL-QIT-DEBUG
X-FL-EDGE
X-Microcachable
Locid
X-Tb-Optimization-Total-Bytes-Saved
X-Via-CDN
HostName
X-Webkit-CSP-Report-Only
X-Cache-Backend
Pics-Label
Cluster
Decoy-Debug-TTL
Decoy-Debug-Status
Decoy-Debug-Key
GeoIP-Latitude
X-Vcl-Version
Env
Edge-Copy-Time
X-Via-Edge
X-Via-SSL
X-Tid
X-RCS-CacheZone
X-From
X-Zone
X-Dc
X-DC
X-Presslabs-Stats
X-Up
X-Cache-Enabled
X-Generated-In
X-ND-Cache
Sid
X-Trace-ID
NtCoent-Length
X-VC
X-Servedbyhost
X-DataCenter
X-Debug-Cache-Store
Time
X-NewRelic-App-Data
X-Debug-Cache-Fetch
X-Edge-Pop
X-Lambda-Id
Memory
X-Cached-By
SID
Cache
X-Srv
X-Via-Poph
Fastly-Drupal-Html
Svr
X-Via-Popv
X-Via-Popn
X-VCT
X-Webkit-CSP
X-Cs
X-HS-Status
VNS-Cache
X-Render-Time
X-Vtex-Remote-Cache
VNS-Age
CPC-Cache
X-Vgn-Hpd-Variations-Key
CPC-Age
X-Vgn-Hpd-Cached
X-Vgn-Hpd-Ssi
X-Nc
X-ZONE
X-Vc
X-HA-Backend
X-Esi
GeoIp-Country-Code
X-Wa
X-Upstream-Ht
X-Upstream-Ct
X-B3-SpanId
X-AIR-PT
Server-ID
X-TH-Server
X-Cache-Type
X-Hcs-Proxy-Type
X-CCDN-Origin-Time
X-CLOUD-TRACE-CONTEXT
X-Client-Ip
X-CCDN-CacheTTL
X-LB-ID
Hostname
Cdn
X-Via-JSL
X-NGINX-Cache
X-ATG-Version
True-Client-IP
X-Check-Cacheable
Cdnsip
X-Gateway-Cache-Status
X-Gateway-Request-Id
X-Gateway-Skip-Cache
X-Contensis-Viewer-Groups
X-Fpc
X-Amz-Meta-Cb-Modifiedtime
AMP-Access-Control-Allow-Source-Origin
X-Varnish-Authentication
X-AK-Request-ID
X-Gateway-Cache-Key
Uri
X-Cache-ASPX
Cdncip
XServer
X-Varnish-Beresp-TTL
XkeyRZ
X-Proxy-CacheRZ
X-CS
X-Via-NSCOPI
X-CSRF-TOKEN
X-Nf-Request-Id
Esi-Enabled
M-TraceId
X-RateLimit-Remaining-Second
X-CF-Lambda-Version
X-CF-Lambda-Fn
X-RateLimit-Limit-Second
Srv
X-API-Version
X-PAYTM-SRV-ID
X-MP-GENERATED-AT
X-EC-Lua
Eomportal-Instance
X-FPC
Resin-Trace
OT-Force-Account-Verify
X-Udemy-Cache-App-Namespace
N-Cache
True-Client-Ip
X-CDN-Cache-Status
CDN
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-APP-VERSION
X-MSEdge-Flight
X-MSEdge-Features
YJS-ID
X-Datadome
X-Orig-Expires
X-Fastly-Country-Code
X-Tenant
X-Bl-Debug
X-Shop-Environment
X-Forwarded-Path
RNT-Time
RNT-Machine
X-Micro-Cache
Ngx-Var-Key
Request-ID
Lb
Path
Server-Id
X-Request-URI
X-Cache-Ttl
X-SIPLIST1
X-B3-Trace-ID
X-Ha-Backend
X-TX-ID
X-Lb-Id
X-Cache-NGX
GeoIP-Country-Code
IsBot
X-Policy
X-App-Name
X-WA
Sm-Log-Id
X-VCL-Version
X-Info
X-Service-Response-Time
LB
X-Accel-Version
X-MCACHE
X-Vcache
Hit
X-Edge-POP
X-Datacenter
HIT
X-NC
X-Pod-Name
Location
Cross-Origin-Opener-Policy-Report-Only
X-Logging-Id
X-RateLimit-Reset
X-SERVER-NAME
Proxy-Connection
X-Git-Commit
X-Cdn-Cache-Status
X-Via-PopH
X-Via-PopN
X-Via-PopV
Ohc-File-Size
X-Container-Uri
X-Cdn-Diag
Pramga
X-Wp-Cf-Super-Cache-Cache-Control
X-Wp-Cf-Super-Cache
X-Akamai-Pragma-Client-IP
X-Geo
X-Cache-Expires
FSS-Cache
X-Oss-Storage-Class
X-ServedByHost
X-Srcache-Store-Status
X-Snapshot-Date
X-Oss-Hash-Crc64ecma
X-Srcache-Fetch-Status
Timeexpire
X-Oss-Request-Id
X-Cdn-Request-ID
X-Oss-Server-Time
X-Oss-Object-Type
Servername
X-CACHE-KEY
X-Ctl-Mach
Req-ID
X-VG-WebCache
X-Tncms
Epwk-X-Cache
Yjs-Id
ENV
XM
X-Iauth-Set-Uid
X-Serial
V-Age
X-Cdn-Forward
X-Acquia-Purge-Cdn-Unconfigured
X-Amz-Meta-Opti
X-Hyper-Cache
Geoip-Latitude
X-Dw-Trace-Id
X-Scheme
WZWS-RAY
X-LiteSpeed-Cache-Control
X-Fastly-Backend-Reqs
True-Client-Country-4JS
X-UP
Wpo-Cache-Status
Wpo-Cache-Message
X-M-Log
X-MiniProfiler-Ids
Warning
X-Rebelmouse-Surrogate-Control
X-M-Reqid
X-Rebelmouse-Cache-Control
X-Acquia-Purge-Tags
Content-Style-Type
X-Acquia-Site
X-RAMCache
X-Clientip
X-B3-Parentspanid
X-Acquia-Application-Trace
X-Qnm-Cache
X-WP-CF-Super-Cache-Cookies-Bypass
X-Swift-Error
X-Moov-Xdn-Version
X-Lb-Nocache
Content-Script-Type
Ec-Rule-Version
CDN-RequestPullSuccess
Traceparent
CDN-RequestPullCode
X-Moov-T
Cneonction
X-TraceId
X-Acquia-Application-UUID
X-F-Status
CountryCode
X-TT-LOGID
X-Lsadc-Cache
Ohc-Cache-HIT
X-Mg-Cache
PICS-Label
X-Litespeed-Cache-Control
X-Viewer-Country
MIME-Version
My-App
X-LiteSpeed-Tag
X-ApacheServer
X-IPS-Cached-Response
X-Cache-Ngx
X-B3-ParentSpanId
Inserted-Into-Cache-At
Ngx
X-Fastly-Cache-Hits
X-PERF
X-Request-URL
X-Mid-Debug-Cache-Key
X-Th-Server
X-Mid-Debug-Cache-Disk
X-Webstats-RespID