Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
Strict-Transport-Security
X-Frame-Options
X-Content-Type-Options
Last-Modified
Link
CF-Cache-Status
Cf-Request-Id
Accept-Ranges
ETag
CF-RAY
Expect-CT
Pragma
X-Powered-By
X-Cache
Via
Age
X-XSS-Protection
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Xss-Protection
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-FRAME-OPTIONS
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-Adblock-Key
X-AspNet-Version
X-Permitted-Cross-Domain-Policies
Alt-Svc
X-Runtime
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Cache-Status
CF-Ray
X-Generator
X-Request-ID
X-Cacheable
X-Iinfo
Timing-Allow-Origin
X-Envoy-Upstream-Service-Time
Feature-Policy
X-Ua-Compatible
X-Content-Security-Policy
Status
X-Drupal-Dynamic-Cache
Content-Encoding
X-AspNetMvc-Version
Access-Control-Expose-Headers
X-CDN
Upgrade
X-XSS-PROTECTION
Access-Control-Max-Age
X-Via
X-Cache-Group
X-Robots-Tag
Server-Timing
X-UA-Device
Request-Context
X-Dns-Prefetch-Control
Keep-Alive
X-AH-Environment
X-Amz-Request-Id
X-Proxy-Cache
X-Turbo-Charged-By
X-Amz-Id-2
X-Backend
P3p
X-Age
X-Ws-Request-Id
Host-Header
X-Server-Powered-By
X-Hacker
X-Server
X-Rq
X-Vhost
X-Varnish-Cache
EagleId
Grace
X-Amz-Version-Id
X-Dispatcher
X-LiteSpeed-Cache
Cf-Edge-Cache
Allow
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
X-Swift-CacheTime
X-Swift-SaveTime
X-Page-Speed
X-Akamai-Path-Stats
X-Nginx-Cache-Status
Ali-Swift-Global-Savetime
X-WebKit-CSP
X-Aws-Lambda-Call-Status
Accept-CH
X-Host
X-Node
X-Pingback
Cf-Railgun
X-Server-Id
X-Cache-Spec
X-OneAgent-JS-Injection
Surrogate-Control
Request-Id
X-Akam-SW-Version
X-Backend-Server
EagleEye-TraceId
X-Response-Time
X-Cache-Lookup
X-Readtime
Accept-CH-Lifetime
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-HW
Content-Location
X-Content-Security-Policy-Report-Only
X-Application-Context
Rating
X-Trace
X-Cloud-Trace-Context
Fastly-Restarts
X-Country
X-Url
X-WebKit-CSP-Report-Only
X-Clacks-Overhead
X-Nginx-Upstream-Cache-Status
X-MS-InvokeApp
X-Edge
X-Amz-Server-Side-Encryption
X-Rack-Cache
Edge-Control
X-Oneagent-Js-Injection
X-B3-TraceId
X-Vname
X-TtlSet
X-PC
Accept-Ch-Lifetime
X-ESI
X-Mod-Pagespeed
X-Content-Type
X-Vcap-Request-Id
X-Ruxit-JS-Agent
X-CST
X-Ruxit-Js-Agent
X-Kinja-Server
X-Exp-Variant
X-Exp-Id
Verso
X-Use-Magma
Xkey
X-GoogleNews-Bot
X-Cdn-Fetch
X-Kinja
X-Kinja-Revision
X-Kinja-Build
X-GitHub-Request-Id
X-Amz-Rid
X-D2id
Cache-Tag
X-Powered-By-Plesk
X-FastCGI-Cache
X-VARITI-CCR
X-Varnish-TTL
Service-Worker-Allowed
RTSS
X-Mcache
X-ECACHE
X-Upstream
X-Version
X-Abt-Application-Version
X-Navigation-Version
X-Cached
X-Client-IP
X-Ac
X-Cnection
X-Dw-Request-Base-Id
X-Ttl
X-Px
X-Server-Name
SPRequestGuid
X-SharePointHealthScore
Arr-Disable-Session-Affinity
X-Element-Page-Cache
X-Instrumentation
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
SPIisLatency
SPRequestDuration
X-Cache-TTL
Public-Key-Pins
Permissions-Policy
X-Country-Code
X-Middleton-Display
X-Sol
Pagespeed
Display
X-NWS-LOG-UUID
X-Ser
Response
X-Middleton-Response
X-Midtier
X-Kinsta-Cache
X-Edge-Location-Klb
X-Cache-Key
X-Goog-Hash
X-RateLimit-Remaining
Cf-Apo-Via
X-Forwarded-For
X-SRCache-Store-Status
X-SRCache-Fetch-Status
Content-MD5
Accept-Ch
Access-Control-Request-Method
X-Correlation-Id
X-NF-Request-ID
X-Shield-Request-Id
Front-End-Https
X-DataDome
X-MSEdge-Ref
TP-Cache
TP-L2-Cache
X-T
X-Accel-Expires
AR-PoweredBy
AR-CACHE
AR-ATIME
AR-Request-ID
X-HP-Webp
AR-SID
X-Recruiting
X-Jurisdiction
MicrosoftSharePointTeamServices
X-HP-Trace-Id
Edge-Cache-Tag
MRF-Tech
X-B3-TraceId-Primal
Mrf-Cache-Status
Nginx-Cache
X-Powered-CMS
X-Daa-Tunnel
TCN
X-Mg-S
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-Grace
X-RateLimit-Limit
X-Content-Digest
X-Id
X-Hits
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Request-Processing-Time
X-Request-Received
Server-Node
Server-Name
Filters
X-HS-Combine-CSS
X-HS-Content-Id
X-HS-Cache-Config
X-HS-Hub-Id
X-Amzn-Trace-Id
X-XRDS-Location
MS-Author-Via
X-Geo-Country
X-Frontend
Fastcgi-Cache
X-Distributor
X-Browser-Type
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Webkit-Csp
S
X-Protected-By
X-LLID
X-Language
Cache-Status
X-Origin-Server
Count-Hit
X-Litespeed-Cache
X-Ezoic-Cdn
X-PressLabs-Stats
Cross-Origin-Opener-Policy
X-Ab
Filterid
X-Ua-Browser
X-LB-Cache
X-Fastly-Request-Id
X-Forwarded-Proto
X-F-Cache
X-Amz-Meta-S3cmd-Attrs
Payment
X-Seen-By
X-Request-Handler-Origin-Region
X-B3-Sampled
X-Microsite
X-Git-Hash
Charset
X-FB-Debug
X-Page-Id
Host
X-ASPNET-VERSION
X-Ratelimit-Reset
X-Fastcgi-Cache
X-Cluster-Name
X-VCache
Surrogate-Key
X-Rid
Realpath
Accept-Charset
Cache-Tags
X-Cache-Age
X-Template
X-Origin-Cache
X-Www-Served-By
Access-Control-Allow-Method
X-NGENIX-Cache
Alternate-Protocol
X-Upgrade-Enabled
Retry-After
X-TTL
X-DIS-Request-ID
Cleartype
X-Logged-In
X-Source
X-Signature
X-Aspnet-Duration-Ms
ServerID
X-AppVersion
X-Varnish-Backend
X-Amz-Replication-Status
X-Az
X-B-Cache
X-Activity-Id
X-App-Environment
X-TT
X-Request-Guid
X-Providence-Cookie
X-Type
X-Flags
X-Is-Crawler
X-Route-Name
X-Wix-Request-Id
X-Tb
X-Varnish-Grace
X-B
X-Envoy-Decorator-Operation
Paypal-Debug-Id
DC
X-Fastly-Request-ID
X-Node-Name
X-DynaTrace
X-Hostname
X-Drupal-Cache-Tags
Frame-Options
X-Revision
X-Proxy
X-Debug
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Contextid
Pinterest-Version
X-Cache-Rule
X-Pinterest-Rid
Pinterest-Generated-By
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Kong-Proxy-Latency
X-GUploader-UploadID
X-Kong-Upstream-Latency
X-Goog-Storage-Class
X-Mobile
X-Goog-Metageneration
X-Goog-Generation
X-Content-Options
Amp-Access-Control-Allow-Source-Origin
X-Load-Cache
Refresh
X-N
X-Cache-Control
Country
Node
X-Magnolia-Registration
X-EdgeConnect-Cache-Status
X-Response-Served-From
NGB
X-Original-Request-Id
X-Oracle-Dms-Ecid
X-Whom
Viewport
X-User-Agent
X-Oracle-Dms-Rid
X-Cache-TTL-Remaining
X-Ratelimit-Remaining
X-L-Path
X-Cacheable-TTL
X-Varnish-Age
X-Environment-Context
Access-Control-Request-Headers
Url
X-Adobe-Loc
X-Mid
X-Servername
X-Status
X-Adobe-Content
X-Debug-IsConnected
X-Yottaa-Optimizations
VIX-Pulpo-Upstream-Status
X-Yottaa-Metrics
X-Varnish-Server
X-G
VIX-Pulpo-Node
X-Debug-IsPreview
X-Akamai-Request-ID2
X-Instance
Referer-Policy
Akamai-GRN
Content-Disposition
X-Framework
X-Is-Bot
X-Jobs
X-Page-View
X-Rendered-As
X-Cache-Grace
X-NYM-Debug-Backend
X-Cache-Time
X-Real-IP
Uber-Trace-Id
X-Content-Powered-By
X-Content
X-Unique-Id
X-RemovedCookies
X-ProcessESI
Srv
X-COUNTRY
X-Drupal-Cache-Contexts
X-APP-VERSION
Countrycode
Version
X-Time
X-Mg-Request-UUID
X-Via-JSL
X-XRDS-LOCATION
X-Cache-Expired-At
Cross-Origin-Resource-Policy
Accept-Language
X-CDN-Forward
X-Http-Reason
X-Restarts
X-Cache-Hit
X-App-Server
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Tumblr-User
X-Tumblr-Pixel-1
X-Cache-Operation
Healthy
X-Trace-Id
Protected
X-Ratelimit-Limit
X-IPLB-Request-ID
X-IPLB-Instance
X-Azure-Ref
X-Hosted-By
X-Debug-Info
X-Nginx-Cache-Key
Section-Io-Cache
Content-Secure-Policy
X-Backend-Name
X-Akamai-Edgescape
X-Tt-Logid
X-Device-Type
X-Server-ID
Liferay-Portal
Backend
X-SRV
X-Cache-Action
Server-Info
X-FW-Serve
X-FW-Hash
X-FW-Server
X-FW-Static
X-Rule
X-FW-Type
X-FW-Dynamic
X-Api-Version
GEO-INFO
X-RN-RSRV
X-Mobile-URL
X-Storage
X-VC-Cache
X-UPSTREAM-Address
Load-Balancing
Meta-Geo
X-Generation-Time
Fastcgi-Useragent
X-Proxy-Cache-Status
X-RTag
MS-CV
X-Mode
Ms-Operation-Id
X-Content-Age
CF-IPCountry
X-Handled-By
X-HTML-Minification-Powered-By
X-Varnish-Beresp-Grace
X-Forwarded-Host
X-Format
X-Region
CDN-Uid
X-Generated-By
X-Urbn-Context-Path
X-Access
CDN-RequestId
X-Adobe-Source
X-Urbn-Site-Id
X-AWS-Id
Azure-RegionName
Azure-InstanceId
CDN-EdgeStorageId
Azure-SiteName
Azure-SlotName
CDN-Cache
Azure-Version
CDN-PullZone
CDN-RequestCountryCode
X-Sql-Duration-Ms
X-Origin-Hint
X-Cache-Enabled
X-Sql-Count
X-LJ-Flow-ID
X-JoinUs
X-Labrador-Cache-Channel
X-PHP-Host
X-Say-Cacheable
TWC-Connection-Speed
X-Sorting-Hat-ShopId
X-Edge-Location
TWC-Device-Class
X-No-Session
X-Varnish-Cache-Hits
TWC-GeoIP-LatLong
TWC-GeoIP-Country
Property-Id
X-SayCDN-TTL
X-ShardId
Locale
X-Section
X-ShopId
X-Shopify-Stage
X-Cache-Server
X-Sorting-Hat-PodId
TWC-Privacy
TWC-Locale-Group
X-Locale
X-Alternate-Cache-Key
X-Skip-Cache
X-Cache-Host
X-VWS-Id
X-SaId
CDN-CachedAt
X-URL
Webcakes-Region
X-Redis-Cache
Webcakes-App-Version
X-Site-Version
Webcakes-App-Name
Web-Mar-Node
X-Say-TTL
X-FB-TRIP-ID
Mn-Server-Ip
DB-Nickname
Selected-Fe
X-BYPASS-REASON
X-Extlb
X-Detected-As
X-Cache-Type
X-Cms-Context
X-PHP-Backend
X-Proto
X-R9-Blue-Green-Version
X-PCL
X-OCL
X-Zipkin-Id
X-Ms-Version
X-Datadome
X-FireWall-Port
X-Xfnlog-Site
X-Uri
X-UA-Device-Type
X-Timing-Wait
X-Web-Node
X-Via-Fastly
X-Varnish-Hostname
X-Varnishpool
Apigw-Requestid
Eomportal-Instance
X-Proxy-Build
X-ProxyCache-Key
X-ProxyCache-Status
Xserver
X-Proxied
X-GeoCode
X-GeoCountry
X-Request-Time
X-Routing-Service
X-Storefront-Renderer-Rendered
S-Rt
Onion-Location
X-Ms-Request-Id
X-ServerID
X-Cache-NGX
X-Server-W
X-Tid
Cache-Name
X-Cache-Status-Check
WP-Super-Cache
X-Nginx-Cache
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
X-Origin-Date
X-ECache
X-Amzn-RequestId
X-Hl-Ver
X-UUID
X-Amz-Apigw-Id
ServedBy
X-DynaTrace-JS-Agent
X-Varnish-Ttl
X-Zen-Fury
X-LSADC-Cache
X-TNCMS
X-Loop
X-Ua
X-Pubstack
X-Reqid
X-Human
Xet-Cookie
X-Amzn-Remapped-Content-Length
X-Soup
X-MP-GENERATED-AT
X-TA-CDN-Provider
X-Correlation-ID
X-Aspnetmvc-Version
X-RCS-CacheZone
X-Provided-By
X-GEO
X-Vgn-Hpd-Reason
Cache
Source
X-Cdn
X-Cache-Tags
X-Dc
Origin
X-Webkit-CSP
X-Debug-Cache
X-Tumblr-Pixel-2
X-Origin-CC
X-Origin-TTL
X-Varnish-Hits
X-Cached-By
Cross-Origin-Window-Policy
From-Origin
X-Service
WPO-Cache-Status
X-Newrelic-Synthetics
X-Varnish-Beresp-Ttl
SD-X-WS
X-App-Version
WPO-Cache-Message
Webserver
X-TIME
LB
X-Tec-Api-Origin
X-Tec-Api-Version
X-Tec-Api-Root
X-AOL-HN
X-IPS-LoggedIn
Rip
X-Trace-ID
X-Cache-Debug
X-NewRelic-App-Data
X-Request-Host
X-B3-Traceid
X-Ec-Fail
X-Ec-GeoHdr
X-Forwarded-Path
X-Owner
X-Orig-Expires
Rendered-Blocks
X-Developer
X-External-Request-Id
CPC-Age
X-A-Ccd
X-A
Host-ID
X-A-Dam
X-A-Dcw
X-Aed
X-A-Wwc
X-A-Dgt
VNS-Cache
Lang
T-Server
Surrogated-Key
Sslversion
Odigeo-Trace-Id
Ngx.Var.Host
VNS-Age
MD5-Digest
Meta-Geo-Continent
X-AK-Request-ID
X-Application
Cdnsip
X-Cache-NE
X-Parent-Response-Time
Cdncip
X-Connection-Hash
A
X-D
BehaviorPad-Version
CPC-Cache
DCR-Decision-By
Environment
X-ARC
Expiry
X-B-Cookie
X-Bc-Bl
DCR-Processing-Time-Ms
X-BCube-Filmed-By
X-Destination
X-NAPM-TraceId
X-ScT
X-S-Cookie
X-PBS-Appsvrname
X-S
X-Vdms-Path
X-Rewrite-Enabled
Xc-Version
X-VG-WebCache
X-Processor
X-Vdms-Version
X-Served-From
X-Tenant
X-FW-Version
X-SRCache-Key
X-Rojux
X-TIM-N
X-User
X-Shop-Environment
X-Cluster-Node
OT-Force-Account-Verify
X-Platform-Server
X-Dispatcher-Number
Machine
X-Qloud-Router
X-B3-SpanId
X-Thanos
Redirect-Candidate
X-Pool
X-Bip
X-Via-NSCOPI
X-Accel-Buffering
X-Varnish-Beresp-Status
X-Aicache-OS
X-WP-CF-Super-Cache-Active
X-Cluster
Upgrade-Insecure-Requests
X-GG-Cache-Date
Mime-Version
X-V-Cache
Tube-Get-Contents
Traceparent
X-Variation
X-BBC-Edge-Cache-Status
Tube-Got-Eval
X-Auto-Login
X-Geo-Header
X-Level-Front-Cache
State
Req-Svc-Chain
X-Cache-Id
X-Cache-Info
X-Cache-Bucket
Servername
X-Branch-Name
X-Region-Sid
X-Varnish-CookieHashed-On
X-Generated-On
Web-Mar-Region
We-Hiring
X-VServer
Wxu-Next-Commit
Wxu-Next-Hostname
Wxu-Next-Region
X-Viewer-Country
X-VG-TLSProxy
X-Ad-Defer-Variation
X-WADP-Cache
Tube-Return
Tube-Got-Results
X-Varnish-CookieINHashed-On
V-Age
X-Varnish-Remaining-TTL
X-Wix-Viewer-Type
Vix-Hermes-Req-Id
X-SVT-ORM-VERSION
X-Sn-Servicetimems
X-Request-URI
X-GeoIP-City
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-Has-Esi
X-Gzip
X-Rocket-Build-Number
X-GeoIP
X-Gateway-Cache-Key
X-Forwarded-Site
X-Gateway-Cache-Status
X-Gateway-Request-Id
X-Gateway-Skip-Cache
X-Hash
X-INCAP-ABP
X-Planisys-CDN-Rules
X-Optimistic-Header
X-Origin
X-Origin-Response-Time
X-Planisys-CDN-Cache
X-NodeID
X-Planisys-CDN-TTL
X-Proxy-Cache-Info
X-Is-Gdpr
X-JWT-State
X-Loc
X-Minions-Version
X-Scale
X-Fmm-Version
X-Csrf-Jwt
X-Core-Mission
X-Slack-Backend
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
X-SplitTest
X-Clientip
X-Cdn-Origin
X-SVT-ORM-RULES
X-Cdn-Srv
X-CGP
X-Clara-WADP
X-SIPLIST1
X-Datadog-Trace-Id
X-Epic-Correlation-Id
X-Sigma
X-Esi-Check
X-Eu-Site
X-Fetched-On
X-Ec-Custom-Error
X-DPWN-IS-SECURE
X-DefHash
X-DefElseHash
X-Sigma-Backend
X-Developers
X-Device-Os
X-CacheTTL
X-Ckpd-Fst-Backend
Decoy-Debug-TTL
DSUID
Decoy-Debug-Status
Decoy-Debug-Key
Datacenter
Fastly-GeoIP-CountryCode
Fastly-SIE
HA-Ipaddr
Is-Eu
Ha-Gx-Prefs
Fastly-SWR
Fastly-SSL
Country-Code
Cmstype
Apple-News-Services-Parsed-Url
Cache-Host
Apple-News-Services-Host
Apple-News-Services-Handled
Adler-Geo
X-CSRF-Token
Canary
Cmsid
Click-Count-Error
Click-Count-Action-Start
Candidate-Md5Url
IsBot
Apple-News-Services-Request-Url
Origin-CC
NM-Fastcgi-Cache
NGX
Release
Origin-EX
Kp-EeAlive
Producers
Platform
Mobile-Detection-Method
HostName
L5d-Success-Class
L
Mail-Subject
Fastly-Drupal-HTML
X-Worker
X-Thinkindot-L3
X-Sucuri-ID
X-Var-Ttl
Svr
Server-Ext
User-Cache-Control
X-Scheme
X-NCache
X-Sucuri-Cache
X-Azure-Ref-OriginShield
AKAMAI
X-FC-Vary-Parameters
Fastly-Backend-Name
X-Nyt-Route
Memcached
X-Gen-Mode
X-HS-Content-Campaign-Id
X-Hnp-Log
X-Origin-Time
X-Irp-Debug
X-S-Maxage
X-Fastly-Backend
X-Rocket-Nginx-Serving-Static
X-Gamma-Serve
Cluster
X-SB
Server-Hostname
CDCHOST
Server-Host
X-CMSURLCustom
Thinkindot-CacheControl
X-ATG-Version
X-Block-Status
X-Tx-Id
Thinkindot-CacheControl-Type
X-Mvc-Supplant-Cachable
Sever-Int
X-Policy
TDXMobile
X-Core-Value
X-Gdpr
X-Mvc-Supplant-OutputCached
Thinkindot-Control
Gh-Request-Id
X-VC
CloudFront-Viewer-Country
X-Newrelic-App-Data
Ec-Rule-Version
Cache-Tv-Group
X-WA-Info
X-Cache-Remote
X-LB-NoCache
Cache-Hits
X-Presslabs-Stats
X-ND-Cache
WebServer
Fastcgi-Cache-TTL
Pics-Label
X-Udemy-Cache-App-Namespace
Ssr
X-ZONE
X-MCACHE
X-Nf-Request-Id
X-Tb-Optimization-Total-Bytes-Saved
SID
X-Fastly-Cache
X-Origin-Expires
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-Session-Fingerprint
Sid
X-Via-Poph
Memory
X-Via-Popv
X-Generated-In
X-Pod-Name
X-Via-Popn
Time
AMP-Access-Control-Allow-Source-Origin
X-Up
Env
X-Servedbyhost
X-Pass-Why
X-Refresh
Server-ID
X-DC
X-Release
X-Akamai-Transformed
My-App
X-Wa
X-Dispatch
X-Cs
X-Tumblr-Pixel-3
X-CACHE-AGE
X-Buckets
X-Fpc
X-Edge-Pop
X-Cache-Date
X-Ig-Push-State
X-Lambda-Id
X-EC-Lua
X-MSEdge-Flight
X-MSEdge-Features
X-Conf
X-NC
X-Esi
X-NWS-UUID-VERIFY
X-PX
GeoIp-Country-Code
X-ID
X-Zone
X-Microcachable
CDN
True-Client-IP
X-Dmc
X-CS
X-Xrds-Location
X-Endurance-Cache-Level
X-VCL-Version
X-Req
X-LB-ID
X-Vc
X-TX-ID
X-Webkit-CSP-Report-Only
Hostname
X-NGINX-Cache
X-CSRF-TOKEN
Fastly-Drupal-Html
Magicmarker
True-Client-Country-4JS
X-B3-Spanid
X-CACHE-KEY
X-RateLimit-Reset
X-Be
X-Op-Id-All
X-TH-Server
X-Wikidot-Backend
X-Wikidot-Static-Cache
CacheControlHeader
X-TRACE-ID
X-HS-Status
Path
Resin-Trace
Request-ID
X-Hyper-Cache
X-Srv
X-Air-Source
X-Air-Hostname
X-Alfa-Service
X-Vcl-Version
X-GeoIP-Country-Code
X-GeoIP-Region-Code
Tcn
X-M-Reqid
X-Micro-Cache
True-Client-Ip
X-M-Log
X-Air-Trace-Id
X-CF-Lambda-Version
X-CF-Lambda-Fn
X-Air-Pt
X-Qnm-Cache
Tracecode
Pramga
X-Check-Cacheable
X-App
X-Varnish-Beresp-TTL
GeoIP-Country-Code
X-Accel-Expires-Debug
WWW-Authenticate
X-Date
X-SERVER-NAME
Section-Origin-Responded
X-Akamai-Pragma-Client-IP
Section-Io-Origin-Time-Seconds
C-Via
Section-Io-Id
X-RAMCache
X-Vercel-Id
X-Vercel-Cache
Section-Io-Origin-Status
NtCoent-Length
X-CLOUD-TRACE-CONTEXT
X-Edge-POP
X-FPC
Proxy-Connection
X-Datacenter
N-Cache
X-Old-Content-Length
X-TrackingId
X-LiteSpeed-Cache-Control
X-Webkit-Csp-Report-Only
YJS-ID
Yjs-Id
X-Platform-Router
Fastcgi-X-Cache-Version
Esi-Enabled
X-Platform-Processor
X-Geo
FSS-Cache
X-Yandex-Sdch-Disable
X-Platform
On-Server
X-Platform-Cluster
X-WA
Powered-By
X-PAYTM-SRV-ID
Hit
X-Mly-Id
X-Via-CDN
X-API-Version
X-Lb-Id
ENV
X-ServedByHost
Server-Id
X-Response-By
User-Agent
Lb
X-Dw-Trace-Id
X-Cdn-Forward
X-Location
X-Via-PopN
GeoIP-Latitude
X-Via-PopV
X-Via-PopH
HIT
X-Webstats-RespID
X-Client-Ip
X-Edge-Origin-Shield-Bytes
X-UA
X-Node-Id
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
X-Edge-Origin-Shield-Region
X-AIR-PT
X-Request-Start
X-Director
X-Varnish-Authentication
X-TT-LOGID
X-Contensis-Viewer-Groups
X-FL-EDGE
X-FORWARDED-FOR
Cdn
Locid
X-Instance-Name
X-Cache-Ttl
X-Traceid
Srvid
X-Cache-ASPX
X-SD-PageType
X-LAGOON
X-Akamai-ERRuleID
X-CUA
Dnion-Transfer-Encoding
X-From
Geoip-Latitude
X-LI-UUID
X-Akamai-ERPolicy
X-Li-Fabric
X-Li-Pop
X-LI-Proto
Sm-Log-Id
X-Service-Response-Time
X-CF-Powered-By
X-DataCenter
X-Render-Time
X-DI
X-Request-Url
X-DSS
Ohc-File-Size
X-DB
Nginx-CQVIP
X-RPM
X-RSL
XServer
Cache-Key
X-Via-Ucdn
X-Server-IP
CountryCode
X-DW
X-LiteSpeed-Tag
PICS-Label
Location
X-RPS
X-Wp-Cf-Super-Cache-Cache-Control
X-Litespeed-Cache-Control
X-Wp-Cf-Super-Cache
X-Fastly-Backend-Reqs
X-HostName
Wpo-Cache-Message
X-HA-Backend
X-Test
Swift-Performance
Uri
Vha6-Origin
X-ApacheServer
X-B3-ParentSpanId
X-Cdn-Request-ID
X-Lb-Nocache
DynaTrace
Wpo-Cache-Status
X-Fastly-Cache-Hits
X-PERF
X-Proxy-Upstream
Server-Ttl
X-Proxy-CacheRZ
X-Ips-Loggedin
Wp-Super-Cache
X-Cache-Ngx
XkeyRZ
Warning
X-IN-APIGATEWAYSSL
X-IN-APIGATEWAY
Cneonction
X-Serial
X-Th-Server
X-Cache-Expires
X-Cache-Backend
M-TraceId
CF-Cached-On
X-Proxy-Cache-Hk
Req-ID
X-Moov-Xdn-Version
Fastcgi-Cache-Ttl
SRV
WZWS-RAY
X-Moov-T
X-VarnishDD-TTL
X-ElasticPress-Query
X-Mg-Cache
XM
PFcat
X-HN
X-Yottaa-OS