Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Accept-Ranges
X-XSS-Protection
Expect-CT
Pragma
X-Powered-By
X-Cache
CF-RAY
Via
Age
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
CF-Ray
X-Xss-Protection
X-Download-Options
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Request-Id
X-Adblock-Key
Access-Control-Allow-Credentials
X-FRAME-OPTIONS
X-Permitted-Cross-Domain-Policies
X-AspNet-Version
Alt-Svc
X-Request-ID
X-Runtime
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Generator
X-Cache-Status
X-Cacheable
Timing-Allow-Origin
X-Envoy-Upstream-Service-Time
X-Iinfo
X-Content-Security-Policy
X-Drupal-Dynamic-Cache
Feature-Policy
Content-Encoding
Access-Control-Expose-Headers
Upgrade
Status
X-CDN
X-AspNetMvc-Version
Access-Control-Max-Age
X-Via
X-UA-Device
Server-Timing
Request-Context
X-Robots-Tag
X-Turbo-Charged-By
X-Amz-Request-Id
X-Cache-Group
X-Amz-Id-2
EagleId
X-Backend
X-AH-Environment
P3p
X-Proxy-Cache
X-Dns-Prefetch-Control
Keep-Alive
X-Server
X-Ws-Request-Id
X-Age
Host-Header
Cf-Edge-Cache
X-Hacker
X-Vhost
X-Server-Powered-By
X-Rq
X-Varnish-Cache
X-Dispatcher
X-Amz-Version-Id
Grace
Allow
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-OneAgent-JS-Injection
X-LiteSpeed-Cache
X-Ua-Compatible
X-Page-Speed
X-WebKit-CSP
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
Cf-Apo-Via
Cf-Railgun
Accept-CH
X-Aws-Lambda-Call-Status
X-Node
X-Pingback
X-Server-Id
X-Host
X-Ruxit-JS-Agent
EagleEye-TraceId
Surrogate-Control
X-Nginx-Cache-Status
X-Akam-SW-Version
X-Readtime
Request-Id
X-Backend-Server
X-Cache-Spec
X-Content-Security-Policy-Report-Only
X-Cache-Lookup
X-HW
Accept-Ch-Lifetime
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Cloud-Trace-Context
X-Trace
X-Application-Context
X-Response-Time
Permissions-Policy
X-Nginx-Upstream-Cache-Status
Fastly-Restarts
X-Edge
X-Mod-Pagespeed
X-WebKit-CSP-Report-Only
X-Country
X-Litespeed-Cache
Content-Location
X-Mcache
X-Content-Type
X-MS-InvokeApp
X-Url
Accept-CH-Lifetime
X-Clacks-Overhead
X-PC
X-TtlSet
X-CST
X-Vname
X-Midtier
X-Amz-Server-Side-Encryption
Rating
RTSS
Cache-Tag
X-ESI
X-Vcap-Request-Id
X-D2id
X-Element-Page-Cache
X-Rack-Cache
Verso
X-Kinja
X-Kinja-Build
X-Kinja-Server
X-GoogleNews-Bot
X-Exp-Id
Origin-Trial
X-Use-Magma
X-Cdn-Fetch
X-Exp-Variant
X-Kinja-Revision
X-VARITI-CCR
X-Server-Name
X-Ac
X-GitHub-Request-Id
X-Powered-By-Plesk
Service-Worker-Allowed
X-ECACHE
X-Cnection
X-Amz-Rid
X-SharePointHealthScore
SPRequestGuid
X-Navigation-Version
X-Client-IP
Xkey
X-Ttl
X-Abt-Application-Version
Edge-Control
SPIisLatency
SPRequestDuration
X-Upstream
X-Cache-TTL
Arr-Disable-Session-Affinity
X-B3-TraceId
X-Cached
X-Dw-Request-Base-Id
X-NWS-LOG-UUID
X-Mg-S
X-Erf-Bev-Bev
X-Server-Lifecycle-Phase
X-Browser-Type
X-Instrumentation
X-Kraken-Loop-Name
X-Erf-Bev-Bev-Is-Generated
X-Varnish-TTL
X-Px
X-FastCGI-Cache
Pagespeed
X-Sol
X-Middleton-Display
Display
X-Cache-Key
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-NF-Request-ID
Access-Control-Request-Method
X-Forwarded-For
Edge-Cache-Tag
X-Country-Code
X-Goog-Hash
X-Correlation-Id
X-Webkit-Csp
TCN
X-Powered-CMS
X-Id
Content-MD5
Front-End-Https
X-Ser
AR-CACHE
AR-PoweredBy
AR-ATIME
AR-SID
AR-Request-ID
Public-Key-Pins
X-RateLimit-Remaining
X-Version
X-HP-Webp
Accept-Ch
X-Jurisdiction
X-HP-Trace-Id
X-Amzn-Trace-Id
X-Recruiting
X-MSEdge-Ref
X-Content-Digest
X-T
X-Ratelimit-Limit
X-Middleton-Response
Response
X-Accel-Expires
TP-L2-Cache
TP-Cache
X-Shield-Request-Id
MicrosoftSharePointTeamServices
S
Nginx-Cache
Cache-Status
X-Daa-Tunnel
X-XRDS-Location
Server-Node
X-Request-Processing-Time
X-Request-Received
X-HS-Content-Id
X-HS-Hub-Id
X-HS-Cache-Config
X-HS-Combine-CSS
MRF-Tech
Cache-Tags
Mrf-Cache-Status
X-B3-TraceId-Primal
X-Fastcgi-Cache
X-Fastly-Request-ID
Cross-Origin-Opener-Policy
X-Hits
X-Distributor
X-PressLabs-Stats
X-Kinsta-Cache
X-Edge-Location-Klb
X-LB-Cache
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-Origin-Server
X-Ratelimit-Remaining
X-Ua-Browser
X-Ezoic-Cdn
X-Ratelimit-Reset
Fastcgi-Cache
X-TEC-API-ROOT
Alternate-Protocol
X-TEC-API-VERSION
X-TEC-API-ORIGIN
Filterid
X-Grace
X-Hostname
X-Frontend
X-Microsite
Server-Name
X-LLID
X-Request-Handler-Origin-Region
X-Rid
X-DIS-Request-ID
X-Geo-Country
X-Logged-In
Healthy
X-Git-Hash
X-FB-Debug
Cleartype
X-Varnish-Backend
X-Www-Served-By
Payment
X-NGENIX-Cache
X-Debug-Info
X-Page-Id
X-Protected-By
X-Cluster-Name
Realpath
X-Load-Cache
DC
X-Forwarded-Proto
MS-Author-Via
X-ASPNET-VERSION
X-ECache
Content-Disposition
Access-Control-Allow-Method
X-Origin-Cache
X-DataDome
X-TTL
Charset
X-B3-Sampled
X-GUploader-UploadID
X-Goog-Metageneration
X-Upgrade-Enabled
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-AppVersion
X-Proxy
X-Activity-Id
X-Az
X-Seen-By
X-F-Cache
Count-Hit
X-Cache-Age
X-B3-Traceid
X-Amz-Meta-S3cmd-Attrs
X-Azure-Ref
X-Amz-Replication-Status
X-Whom
Paypal-Debug-Id
X-Fb-Rlafr
X-B
X-Type
Cross-Origin-Resource-Policy
X-Revision
X-Contextid
Surrogate-Key
X-App-Environment
Accept-Charset
Viewport
X-Aspnetmvc-Version
Retry-After
X-Akamai-Edgescape
X-Route-Name
X-Aspnet-Duration-Ms
X-Is-Crawler
X-Providence-Cookie
X-Request-Guid
X-Varnish-Server
X-Flags
X-TT
X-Hosted-By
X-Wix-Request-Id
X-Times
X-Language
X-Signature
X-B-Cache
X-DynaTrace
X-Cache-Control
X-Source
X-Envoy-Decorator-Operation
X-App-Server
X-VCache
X-Magnolia-Registration
X-Mobile
Amp-Access-Control-Allow-Source-Origin
X-Varnish-Grace
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
Host
X-XRDS-LOCATION
Version
X-Server-ID
WPO-Cache-Message
Referer-Policy
WPO-Cache-Status
X-Cache-Rule
X-N
Refresh
X-HTML-Minification-Powered-By
X-Oracle-Dms-Rid
X-Oracle-Dms-Ecid
Access-Control-Request-Headers
X-Tumblr-User
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Cache-Time
X-Varnish-Age
X-Response-Served-From
X-Tumblr-Pixel-1
X-Original-Request-Id
X-Amz-Apigw-Id
X-Rule
X-Varnish-Ttl
X-Cache-Status-Check
X-EdgeConnect-Cache-Status
X-Amzn-RequestId
X-Content-Powered-By
X-Cacheable-TTL
X-Framework
X-UUID
X-RTag
MS-CV
X-G
Protected
Ms-Operation-Id
X-Jobs
X-User-Agent
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Cache-Grace
X-RemovedCookies
X-L-Path
X-Backend-Name
GEO-INFO
X-ProcessESI
X-Environment-Context
X-Trace-Id
X-Tt-Trace-Tag
X-FW-Hash
X-FW-Version
X-FW-Serve
X-FW-Server
SD-X-WS
X-FW-Type
X-FW-Static
Akamai-GRN
X-Status
X-Tt-Trace-Host
From-Origin
X-FW-Dynamic
X-Device-Type
NGB
X-Region
X-Is-Bot
X-Rendered-As
X-Instance
X-Http-Reason
X-Nginx-Cache
X-Cache-Expired-At
X-Page-View
X-Akamai-Request-ID2
Section-Io-Cache
X-RateLimit-Limit
Front
X-Drupal-Cache-Contexts
X-Drupal-Cache-Tags
CDN-RequestId
X-NYM-Debug-Backend
X-Adobe-Content
X-Adobe-Loc
Url
X-Fastly-Request-Id
X-Servername
X-Unique-Id
Accept-Language
X-Template
X-Pinterest-Rid
Pinterest-Generated-By
Liferay-Portal
Pinterest-Version
X-Content-Options
X-CDN-Forward
SRV
X-Debug-IsPreview
X-Debug-IsConnected
Backend
X-Air-Source
Fastly-SWR
Fastly-SIE
X-Time
X-Newrelic-App-Data
X-Air-Trace-Id
X-Air-Hostname
X-Cache-Hit
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Zen-Fury
Country
X-DynaTrace-JS-Agent
X-Mode
X-COUNTRY
Content-Secure-Policy
X-Cache-Operation
X-Rocket-Nginx-Serving-Static
Node
X-Uri
S-Rt
X-Generation-Time
Filters
Onion-Location
X-RN-RSRV
X-Rewrite-Enabled
X-Cache-Server
X-Amzn-Remapped-Content-Length
Uber-Trace-Id
X-UPSTREAM-Address
Webserver
X-IPS-LoggedIn
Meta-Geo
X-Tumblr-Pixel-2
X-Edge-Location
X-Content-Age
Selected-Fe
X-Tumblr-Pixel-3
X-Proxy-Cache-Info
X-Timing-Wait
Azure-InstanceId
Azure-SiteName
Azure-SlotName
Cache-Hits
X-PHP-Backend
Azure-Version
CF-IPCountry
Azure-RegionName
X-Locale
X-Proxy-Build
X-Soup
X-ARC
X-Cache-Action
X-ProxyCache-Key
X-Site-Version
X-BYPASS-REASON
X-Access
X-Ms-Version
X-Real-IP
X-Sucuri-Cache
X-Server-W
X-Sucuri-ID
X-Skip-Cache
X-Format
X-Section
X-Varnish-Beresp-Grace
Cache-Name
X-Ms-Request-Id
X-Via-Fastly
X-Ua
X-Cms-Context
X-ProxyCache-Status
X-Tb
X-Web-Node
X-Cluster-Node
TWC-Device-Class
ServerID
TWC-GeoIP-Country
TWC-Connection-Speed
Cross-Origin-Window-Policy
Property-Id
DB-Nickname
ServedBy
X-Proxy-Cache-Status
X-Say-TTL
X-UA-Device-Type
X-Zipkin-Id
X-Reqid
X-SayCDN-TTL
X-Proxied
X-Origin-Hint
X-PHP-Host
X-Proto
X-Say-Cacheable
X-Labrador-Cache-Channel
Webcakes-App-Version
Webcakes-App-Name
TWC-Privacy
TWC-Locale-Group
X-Cache-Host
X-Extlb
X-Routing-Service
X-R9-Blue-Green-Version
X-Origin-Date
TWC-GeoIP-LatLong
Webcakes-Region
Countrycode
WP-Super-Cache
X-Handled-By
X-Forwarded-Host
X-VWS-Id
X-JoinUs
X-LAGOON
X-Optimistic-Header
X-SaId
X-IPLB-Request-ID
X-IPLB-Instance
Web-Mar-Node
X-LJ-Flow-ID
X-AWS-Id
X-VC-Cache
X-Debug
Apigw-Requestid
X-Ruxit-Js-Agent
Cache-Tv-Group
X-Sql-Duration-Ms
X-Sql-Count
X-Cluster
X-Cache-TTL-Remaining
X-FB-TRIP-ID
X-Detected-As
X-No-Session
Mn-Server-Ip
X-Urbn-Site-Id
X-Urbn-Context-Path
Locale
X-App-Version
X-Tec-Api-Root
X-Tec-Api-Origin
X-Tec-Api-Version
X-Node-Name
X-LSADC-Cache
X-Tt-Logid
X-Adobe-Source
X-Xfnlog-Site
X-Director
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
Mime-Version
X-GeoCountry
X-Oneagent-Js-Injection
X-GeoCode
Fastcgi-Useragent
Upgrade-Insecure-Requests
X-Varnish-Hits
Source
X-Buckets
Frame-Options
CDN-Uid
CDN-Cache
X-Hl-Ver
CDN-RequestCountryCode
CDN-PullZone
CDN-CachedAt
CDN-EdgeStorageId
Fastly-Drupal-HTML
X-Generated-By
X-GEO
X-TIME
X-Mg-Request-UUID
X-Request-Time
X-Varnish-Cache-Hits
X-FireWall-Port
Load-Balancing
Xet-Cookie
X-Api-Version
X-TA-CDN-Provider
X-Redis-Cache
X-Origin-TTL
X-Origin-CC
X-ServerID
X-Varnish-Hostname
X-URL
X-SRV
X-RM-Cache-TTL
X-Datadog-Sampled
X-Datadog-Trace-Id
CF-Cached-On
X-Cache-Debug
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
X-Loop
X-Akamai-Transformed
X-Sorting-Hat-ShopId
X-ShardId
X-Storefront-Renderer-Rendered
X-Shopify-Stage
X-ShopId
X-Sorting-Hat-PodId
X-Alternate-Cache-Key
X-Served-From
X-Pubstack
X-Tx-Id
X-Newrelic-Synthetics
X-Endurance-Cache-Level
X-Pass-Why
X-Storage
X-Request-Host
X-CSRF-Token
X-TNCMS
X-Restarts
X-Location
X-Service
X-Level-Front-Cache
X-A-Dgt
X-A-Dcw
X-A-Dam
X-INCAP-ABP
X-Provided-By
X-Mid
X-Men
Redirect-Candidate
X-A-Wwc
X-B-Cookie
DCR-Processing-Time-Ms
X-Core-Mission
X-Conf
X-CMSURLCustom
DCR-Decision-By
X-CUA
Memcached
MD5-Digest
X-D
DSUID
Edge-Cache
Host-ID
Lang
X-Cache-Date
X-Cache-Info
X-Cache-NE
X-Bc-Bl
X-BCube-Filmed-By
Gannett-Cam-Experience-Id
Candidate-Md5Url
X-Destination
Odigeo-Trace-Id
NM-Fastcgi-Cache
X-External-Request-Id
X-Application
X-Gdpr
X-Aed
Origin
X-Generated-On
X-Epic-Correlation-Id
X-Ec-GeoHdr
BehaviorPad-Version
Cache-Host
X-Developer
Meta-Geo-Continent
A
X-Ec-Fail
Ngx.Var.Host
X-Mobile-URL
X-Hash
X-A-Ccd
X-S
X-Rojux
X-Vdms-Path
X-Correlation-ID
X-S-Cookie
X-Vdms-Version
X-Thinkindot-L3
TDXMobile
X-Processor
T-Server
WWW-Authenticate
X-S-Maxage
Surrogated-Key
X-SVT-ORM-VERSION
X-Test
X-TIM-N
X-Thanos
Sslversion
X-SVT-ORM-RULES
X-ScT
X-Sigma
X-Sigma-Backend
X-SRCache-Key
Thinkindot-CacheControl
X-Rocket-Build-Number
X-Bip
X-A
Server-Host
Xserver
X-Origin
X-We-Are-Hiring
X-Origin-Time
Rendered-Blocks
X-Platform-Cluster
Thinkindot-CacheControl-Type
X-Platform-Router
Release
Xc-Version
Thinkindot-Control
X-Nyt-Route
X-Platform-Processor
HostName
Server-Info
X-Cache-Id
X-Var-Ttl
X-Date
Click-Count-Action-Start
X-Cdn-Origin
Magicmarker
Vix-Hermes-Req-Id
CacheControlHeader
X-Cache-Bucket
Fastly-Backend-Name
X-Response-By
Tube-Got-Eval
Click-Count-Error
X-Varnishpool
Country-Code
Fastly-GeoIP-CountryCode
Tube-Return
Mail-Subject
Cmstype
Cmsid
CloudFront-Viewer-Country
X-Varnish-Beresp-Status
X-CacheTTL
Gh-Request-Id
Tube-Got-Results
X-Slack-Backend
X-Pool
X-HS-Content-Campaign-Id
X-Httpd
X-Accel-Expires-Debug
X-Gzip
X-Akamai-Device-Characteristics
X-Req
X-Region-Sid
X-Human
X-Platform
X-Loc
X-Node-Id
Tube-Get-Contents
X-NodeID
X-Varnish-Beresp-Ttl
Req-Svc-Chain
X-Origin-Response-Time
X-Org
X-Geo-Header
X-Gamma-Serve
X-Ec-Custom-Error
X-Sn-Servicetimems
X-Slack-Shared-Secret-Outcome
AKAMAI
X-Dispatcher-Server
C-Via
X-BBC-Edge-Cache-Status
X-Dispatcher-Number
X-Mvc-Supplant-Cachable
X-Server-IP
X-Scale
X-Fetched-On
X-Auto-Login
X-Fastly-Cache
X-Fastly-Backend
We-Hiring
X-Esi-Check
Cache-Key
X-Parent-Response-Time
Environment
X-WP-CF-Super-Cache-Active
X-Planisys-CDN-TTL
X-Request-Start
Web-Mar-Region
X-SD-PageType
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
X-Mly-Id
X-Nginx-Cache-Key
X-Origin-Expires
X-Owner
X-V-Cache
X-Variation
X-VG-TLSProxy
X-Vmg-Version
X-VServer
X-WA-Info
X-Varnish-Remaining-TTL
X-Varnish-CookieINHashed-On
X-JWT-State
X-Varnish-CookieHashed-On
X-Worker
X-WADP-Cache
X-Irp-Debug
X-DefHash
X-Developers
X-Device-Os
X-Azure-Ref-OriginShield
X-DefElseHash
X-Core-Value
X-Cdn-Srv
X-Ckpd-Fst-Backend
X-Clara-WADP
X-FC-Vary-Parameters
X-Fmm-Version
X-GeoIP-Region-Code
X-Has-Esi
X-Instance-Name
X-Cache-FS-Status
X-GeoIP-Country-Code
X-GeoIP-City
X-Forwarded-Site
X-Frame-Option
X-GeoIP
X-Is-Gdpr
X-Ad-Defer-Variation
Is-Eu
Section-Origin-Responded
X-Air-Pt
Machine
On-Server
Origin-EX
Origin-CC
Datacenter
Section-Io-Origin-Time-Seconds
Apple-News-Services-Host
Apple-News-Services-Handled
Adler-Geo
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
Section-Io-Origin-Status
Canary
Platform
Kp-EeAlive
Section-Io-Id
Ssr
State
X-Vcl-Version
X-Via-CDN
Expect-Staple
X-VarnishDD-TTL
X-Cache-Tags
Wxu-Next-Hostname
Wxu-Next-Commit
X-Wix-Viewer-Type
Wxu-Next-Region
X-Minions-Version
X-Gen-Mode
X-Release
X-Qloud-Router
X-DPWN-IS-SECURE
User-Cache-Control
L
Cache-Provider
X-Op-Id-All
X-Old-Content-Length
Srvid
X-App
X-SB
X-FL-QIT-DEBUG
NGX
Locid
X-HN
X-Hnp-Log
Producers
X-Aicache-OS
X-Accel-Buffering
X-NCache
X-Block-Status
PFcat
X-FL-EDGE
X-Via-SSL
X-Via-Edge
X-Zone
Edge-Copy-Time
X-VC
X-Webkit-CSP-Report-Only
X-CACHE-AGE
X-Platform-Server
CDCHOST
X-Microcachable
Sever-Int
Server-Hostname
X-Cache-Remote
Server-Ext
X-From
Ha-Gx-Prefs
L5d-Success-Class
HA-Ipaddr
X-Nananana
X-B3-Spanid
X-Eu-Site
X-Csrf-Jwt
X-CGP
Fastly-SSL
X-LB-NoCache
X-Mvc-Supplant-OutputCached
X-Dc
X-Refresh
X-Cache-Backend
X-Up
X-Tb-Optimization-Total-Bytes-Saved
X-Cache-Enabled
Pics-Label
X-Debug-Cache-Store
X-Lambda-Id
X-Debug-Cache-Fetch
X-RCS-CacheZone
X-Generated-In
Decoy-Debug-Key
Cluster
Decoy-Debug-Status
Decoy-Debug-TTL
Env
X-ND-Cache
X-DC
X-Trace-ID
Sid
X-Via-Popv
X-Via-Popn
X-Via-Poph
X-NWS-UUID-VERIFY
X-Tid
GeoIP-Latitude
X-VCT
X-Cached-By
Cache
X-Cs
AMP-Access-Control-Allow-Source-Origin
NtCoent-Length
CPC-Cache
VNS-Age
X-Edge-Pop
X-Vtex-Remote-Cache
X-Render-Time
VNS-Cache
Time
CPC-Age
X-HS-Status
Memory
X-B3-SpanId
X-Webkit-CSP
X-Upstream-Ht
X-LB-ID
X-Hcs-Proxy-Type
X-CCDN-CacheTTL
X-CCDN-Origin-Time
X-Upstream-Ct
X-HA-Backend
SID
X-Srv
X-Servedbyhost
X-TH-Server
Svr
X-Esi
X-Vgn-Hpd-Cached
X-Vgn-Hpd-Variations-Key
X-Vgn-Hpd-Ssi
X-AIR-PT
X-Cache-Type
X-Presslabs-Stats
Srv
Fastly-Drupal-Html
X-DataCenter
X-NewRelic-App-Data
X-CLOUD-TRACE-CONTEXT
X-Client-Ip
X-ATG-Version
Server-ID
X-Nc
X-Wa
Cdn
X-Via-JSL
GeoIp-Country-Code
X-ZONE
X-Check-Cacheable
Uri
X-Varnish-Authentication
X-Contensis-Viewer-Groups
X-Cache-ASPX
X-Vc
X-Proxy-CacheRZ
XkeyRZ
Esi-Enabled
X-PAYTM-SRV-ID
X-RateLimit-Limit-Second
X-MP-GENERATED-AT
X-Amz-Meta-Cb-Modifiedtime
True-Client-IP
X-RateLimit-Remaining-Second
X-Fpc
X-CF-Lambda-Fn
X-CF-Lambda-Version
XServer
Cdncip
X-Gateway-Cache-Key
X-Gateway-Cache-Status
Cdnsip
X-Nf-Request-Id
X-Gateway-Skip-Cache
X-Varnish-Beresp-TTL
X-AK-Request-ID
M-TraceId
X-Gateway-Request-Id
X-NGINX-Cache
Hostname
X-EC-Lua
X-CS
X-Datadome
X-Wikidot-Static-Cache
Lb
X-Via-NSCOPI
Resin-Trace
N-Cache
True-Client-Ip
X-Wikidot-Backend
X-API-Version
X-CDN-Cache-Status
YJS-ID
X-Udemy-Cache-App-Namespace
X-CSRF-TOKEN
X-Shop-Environment
X-Tenant
OT-Force-Account-Verify
X-Bl-Debug
RNT-Time
X-MSEdge-Features
X-TX-ID
X-FPC
X-MSEdge-Flight
RNT-Machine
X-Orig-Expires
X-Forwarded-Path
X-Fastly-Country-Code
Eomportal-Instance
Request-ID
X-Policy
X-App-Name
X-B3-Trace-ID
X-APP-VERSION
CDN
Path
Ngx-Var-Key
Server-Id
X-CACHE-KEY
X-Cache-Ttl
X-Service-Response-Time
Sm-Log-Id
X-Micro-Cache
GeoIP-Country-Code
X-SIPLIST1
IsBot
X-Accel-Version
X-WA
X-Logging-Id
X-Lb-Id
Hit
X-VCL-Version
X-Datacenter
X-Cache-NGX
X-Ha-Backend
X-NC
X-MCACHE
X-Request-URI
X-Container-Uri
X-Git-Commit
X-Vcache
X-Edge-POP
LB
X-Cdn-Diag
HIT
X-Info
X-RateLimit-Reset
X-Geo
X-ServedByHost
X-SERVER-NAME
Pramga
Cross-Origin-Opener-Policy-Report-Only
X-Cdn-Cache-Status
Location
X-Akamai-Pragma-Client-IP
X-Srcache-Fetch-Status
X-Srcache-Store-Status
X-Snapshot-Date
X-Pod-Name
Ohc-File-Size
ENV
Timeexpire
X-VG-WebCache
X-Cdn-Forward
FSS-Cache
Yjs-Id
Epwk-X-Cache
X-Via-PopN
Geoip-Latitude
X-Via-PopV
Req-ID
X-Via-PopH
X-Tncms
X-Acquia-Purge-Cdn-Unconfigured
V-Age
XM
X-Ctl-Mach
X-Wp-Cf-Super-Cache-Cache-Control
X-TimeS
X-Iauth-Set-Uid
X-Wp-Cf-Super-Cache
X-TT-LOGID
X-Amz-Meta-Opti
X-Clientip
X-Hyper-Cache
CDN-RequestPullSuccess
CDN-RequestPullCode
X-LiteSpeed-Cache-Control
True-Client-Country-4JS
X-Oss-Hash-Crc64ecma
Proxy-Connection
X-Serial
X-Oss-Object-Type
X-Cdn-Request-ID
X-Lb-Nocache
X-Fastly-Backend-Reqs
X-Oss-Storage-Class
X-Cache-Expires
X-Oss-Request-Id
X-Dw-Trace-Id
X-Oss-Server-Time
Servername
X-M-Log
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-M-Reqid
Warning
X-Acquia-Site
X-RAMCache
Cdn-Requestid
Ec-Rule-Version
X-UP
X-Acquia-Purge-Tags
Cneonction
X-B3-Parentspanid
X-Swift-Error
Content-Script-Type
X-Akamai-ERRuleID
X-Akamai-ERPolicy
X-Acquia-Application-UUID
WZWS-RAY
X-Acquia-Application-Trace
X-Qnm-Cache
Content-Style-Type
X-Lsadc-Cache
X-MiniProfiler-Ids
CountryCode
X-F-Status
X-IPS-Cached-Response
Ohc-Cache-HIT
X-WP-CF-Super-Cache-Cookies-Bypass
PICS-Label
X-B3-ParentSpanId
W
X-Cached-Since
X-Fastly-Cache-Hits
X-Scheme
X-Moov-T
X-Moov-Xdn-Version
Ngx
X-Th-Server
X-LiteSpeed-Tag
My-App
X-Litespeed-Cache-Control
X-Cache-Ngx
X-Webstats-RespID
MIME-Version
X-Mg-Cache