Threat Level: green Handler on Duty: Rob VandenBrink

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
X-XSS-Protection
Accept-Ranges
Expect-CT
Pragma
X-Powered-By
CF-RAY
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
CF-Ray
X-Download-Options
X-Xss-Protection
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Request-Id
Access-Control-Allow-Credentials
X-FRAME-OPTIONS
X-Request-ID
X-Permitted-Cross-Domain-Policies
X-AspNet-Version
Alt-Svc
X-Runtime
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Generator
X-Cache-Status
X-Cacheable
Timing-Allow-Origin
X-Envoy-Upstream-Service-Time
X-Iinfo
X-Content-Security-Policy
X-Drupal-Dynamic-Cache
Feature-Policy
Content-Encoding
Access-Control-Expose-Headers
Upgrade
Status
X-CDN
X-AspNetMvc-Version
Access-Control-Max-Age
X-Via
X-UA-Device
Server-Timing
Request-Context
X-Robots-Tag
X-Turbo-Charged-By
X-Amz-Request-Id
X-Cache-Group
X-Dns-Prefetch-Control
X-Amz-Id-2
EagleId
X-Backend
X-AH-Environment
X-Proxy-Cache
P3p
Keep-Alive
X-Server
X-Ws-Request-Id
X-Ua-Compatible
X-Age
Cf-Edge-Cache
Host-Header
X-Hacker
X-Vhost
X-Server-Powered-By
X-Rq
X-Varnish-Cache
X-Dispatcher
X-Amz-Version-Id
Grace
Allow
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-OneAgent-JS-Injection
X-LiteSpeed-Cache
X-WebKit-CSP
X-Page-Speed
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
Cf-Apo-Via
Accept-CH
Cf-Railgun
X-Aws-Lambda-Call-Status
X-Pingback
X-Node
X-Server-Id
X-Host
X-Ruxit-JS-Agent
EagleEye-TraceId
X-Nginx-Cache-Status
Surrogate-Control
X-Akam-SW-Version
X-Readtime
Request-Id
X-Backend-Server
X-Cache-Spec
X-Cache-Lookup
X-Content-Security-Policy-Report-Only
X-HW
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Cloud-Trace-Context
X-Trace
X-Application-Context
X-Response-Time
Accept-Ch-Lifetime
Permissions-Policy
X-Nginx-Upstream-Cache-Status
Fastly-Restarts
X-WebKit-CSP-Report-Only
X-Edge
X-Mod-Pagespeed
Accept-CH-Lifetime
Content-Location
X-Mcache
X-Content-Type
X-MS-InvokeApp
X-Country
X-Url
X-Litespeed-Cache
X-Clacks-Overhead
X-CST
X-TtlSet
X-Vname
X-PC
X-Amz-Server-Side-Encryption
X-Midtier
Rating
RTSS
Cache-Tag
X-ESI
X-Vcap-Request-Id
X-D2id
X-Element-Page-Cache
X-Kinja-Server
X-Cdn-Fetch
X-Rack-Cache
X-Kinja-Revision
X-Exp-Id
Origin-Trial
X-Exp-Variant
X-Kinja
X-Use-Magma
X-GoogleNews-Bot
X-Kinja-Build
Verso
X-VARITI-CCR
X-Server-Name
X-Ttl
X-Ac
X-GitHub-Request-Id
X-Powered-By-Plesk
Service-Worker-Allowed
X-Cnection
X-Amz-Rid
X-SharePointHealthScore
SPRequestGuid
X-Navigation-Version
X-Client-IP
Xkey
X-ECACHE
X-Abt-Application-Version
Edge-Control
SPRequestDuration
SPIisLatency
X-Cache-TTL
X-B3-TraceId
X-Upstream
Arr-Disable-Session-Affinity
X-Cached
X-NWS-LOG-UUID
X-Mg-S
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Instrumentation
X-Browser-Type
X-Erf-Bev-Bev
X-FastCGI-Cache
X-Erf-Bev-Bev-Is-Generated
X-Dw-Request-Base-Id
X-Px
X-Varnish-TTL
X-Sol
X-Middleton-Display
Display
Pagespeed
X-Cache-Key
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-NF-Request-ID
X-Forwarded-For
Access-Control-Request-Method
Edge-Cache-Tag
X-Correlation-Id
X-Country-Code
X-Goog-Hash
Content-MD5
TCN
X-Powered-CMS
X-Ratelimit-Limit
X-Id
Front-End-Https
AR-PoweredBy
AR-SID
AR-Request-ID
AR-CACHE
AR-ATIME
X-Ser
X-Webkit-Csp
Public-Key-Pins
X-Version
X-HP-Webp
X-Jurisdiction
X-HP-Trace-Id
X-MSEdge-Ref
X-Recruiting
X-T
X-Content-Digest
X-RateLimit-Remaining
X-Amzn-Trace-Id
X-Middleton-Response
Response
Accept-Ch
X-Accel-Expires
TP-L2-Cache
TP-Cache
MicrosoftSharePointTeamServices
X-Shield-Request-Id
S
Nginx-Cache
X-XRDS-Location
Cache-Status
X-Daa-Tunnel
Server-Node
X-Request-Processing-Time
X-Request-Received
X-HS-Hub-Id
MRF-Tech
X-B3-TraceId-Primal
X-HS-Content-Id
X-HS-Cache-Config
X-HS-Combine-CSS
Mrf-Cache-Status
Cache-Tags
X-Distributor
X-Hits
Cross-Origin-Opener-Policy
X-Ratelimit-Remaining
X-Edge-Location-Klb
X-Kinsta-Cache
X-LB-Cache
X-Fastly-Request-ID
X-Origin-Server
X-Ratelimit-Reset
X-Ua-Browser
X-Ezoic-Cdn
X-PressLabs-Stats
X-TEC-API-ROOT
X-TEC-API-ORIGIN
Fastcgi-Cache
X-TEC-API-VERSION
Alternate-Protocol
Filterid
X-Grace
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-Frontend
X-Hostname
Server-Name
X-LLID
X-Request-Handler-Origin-Region
X-Fastcgi-Cache
X-Geo-Country
X-DIS-Request-ID
X-Microsite
X-Rid
X-ECache
X-FB-Debug
Healthy
X-Logged-In
X-Git-Hash
X-Varnish-Backend
Cleartype
Payment
X-Debug-Info
X-Protected-By
X-Www-Served-By
X-Load-Cache
X-Page-Id
X-Forwarded-Proto
X-Cluster-Name
X-NGENIX-Cache
Realpath
DC
MS-Author-Via
X-DataDome
Access-Control-Allow-Method
Content-Disposition
X-ASPNET-VERSION
X-Origin-Cache
Charset
X-B3-Sampled
X-GUploader-UploadID
X-Goog-Metageneration
X-Upgrade-Enabled
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Activity-Id
X-Proxy
X-AppVersion
X-Az
X-Seen-By
X-F-Cache
X-Amz-Meta-S3cmd-Attrs
X-Amz-Replication-Status
X-Fb-Rlafr
Count-Hit
Cross-Origin-Resource-Policy
X-Azure-Ref
Paypal-Debug-Id
X-Whom
X-B
X-Type
X-Revision
Surrogate-Key
X-Contextid
X-Aspnet-Duration-Ms
X-Cache-Age
X-Providence-Cookie
X-Request-Guid
Viewport
X-Akamai-Edgescape
Accept-Charset
X-Route-Name
X-App-Environment
Retry-After
X-Flags
X-Is-Crawler
X-Wix-Request-Id
X-B3-Traceid
X-Varnish-Server
X-TTL
X-TT
X-Hosted-By
X-Times
X-Aspnetmvc-Version
X-B-Cache
X-Signature
X-DynaTrace
X-Language
Amp-Access-Control-Allow-Source-Origin
X-Cache-Control
X-Source
X-Envoy-Decorator-Operation
X-App-Server
X-Mobile
X-VCache
X-Goog-Stored-Content-Length
X-Varnish-Ttl
X-Varnish-Grace
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Magnolia-Registration
X-Oracle-Dms-Rid
X-Goog-Generation
X-Oracle-Dms-Ecid
Version
Host
Referer-Policy
WPO-Cache-Message
WPO-Cache-Status
X-XRDS-LOCATION
X-N
X-Cache-Rule
X-Server-ID
X-HTML-Minification-Powered-By
Refresh
X-Cache-Time
X-Tumblr-Pixel
X-Original-Request-Id
X-Response-Served-From
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
Access-Control-Request-Headers
X-Varnish-Age
X-EdgeConnect-Cache-Status
X-Tumblr-User
X-Cache-Status-Check
X-Rule
X-UUID
X-User-Agent
X-RTag
X-Framework
SD-X-WS
Protected
Ms-Operation-Id
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-G
X-Cacheable-TTL
X-Cache-Grace
X-Jobs
MS-CV
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Tt-Trace-Host
X-Fastly-Request-Id
X-Tt-Trace-Tag
X-FW-Static
X-FW-Server
X-FW-Type
X-FW-Version
Section-Io-Cache
X-ProcessESI
X-Backend-Name
X-FW-Hash
From-Origin
GEO-INFO
X-RemovedCookies
X-Environment-Context
X-FW-Dynamic
CDN-RequestId
X-FW-Serve
X-Content-Powered-By
X-L-Path
X-Device-Type
Akamai-GRN
X-Status
X-Page-View
X-Trace-Id
X-Instance
X-Rendered-As
X-Akamai-Request-ID2
X-Cache-Expired-At
X-Drupal-Cache-Tags
X-Drupal-Cache-Contexts
X-Http-Reason
X-Is-Bot
X-Region
X-NYM-Debug-Backend
X-Adobe-Loc
NGB
X-Adobe-Content
Front
X-Nginx-Cache
X-Servername
Url
SRV
X-Unique-Id
X-COUNTRY
Accept-Language
X-CDN-Forward
X-Template
X-Debug-IsConnected
X-Debug-IsPreview
Pinterest-Generated-By
X-Content-Options
X-Pinterest-Rid
Pinterest-Version
Liferay-Portal
Fastly-SWR
Fastly-SIE
Backend
X-Cache-Hit
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Air-Hostname
X-Zen-Fury
X-RateLimit-Limit
X-Air-Source
X-Air-Trace-Id
X-Newrelic-App-Data
Country
X-DynaTrace-JS-Agent
X-Mode
Content-Secure-Policy
X-Time
X-Cache-Operation
X-Rocket-Nginx-Serving-Static
Node
X-Tb
X-Real-IP
Webserver
X-IPS-LoggedIn
X-Cache-Server
X-Generation-Time
Meta-Geo
X-Content-Age
S-Rt
Filters
X-Proxy-Cache-Info
X-Tumblr-Pixel-2
X-UPSTREAM-Address
X-Rewrite-Enabled
Onion-Location
X-RN-RSRV
Uber-Trace-Id
X-Uri
X-Amzn-Remapped-Content-Length
Azure-RegionName
CF-IPCountry
Azure-SlotName
Azure-Version
Cache-Hits
Azure-SiteName
X-Timing-Wait
X-Web-Node
Selected-Fe
X-PHP-Backend
X-Edge-Location
X-Locale
Azure-InstanceId
X-Proxy-Build
X-Skip-Cache
Cache-Name
X-Access
X-Cache-Action
X-Cluster-Node
X-Format
X-Ms-Request-Id
X-Say-Cacheable
X-Origin-Date
X-Sucuri-Cache
X-Varnish-Beresp-Grace
X-Server-W
X-PHP-Host
X-Proto
X-Site-Version
X-Soup
X-Ms-Version
X-Section
X-Say-TTL
X-Labrador-Cache-Channel
X-Tumblr-Pixel-3
X-SayCDN-TTL
X-Sucuri-ID
Cross-Origin-Window-Policy
Property-Id
X-Sql-Duration-Ms
ServedBy
ServerID
X-Proxied
TWC-Connection-Speed
X-VC-Cache
X-Zipkin-Id
DB-Nickname
X-R9-Blue-Green-Version
X-UA-Device-Type
X-Reqid
X-Sql-Count
X-Origin-Hint
X-ProxyCache-Status
X-ProxyCache-Key
X-Cache-Host
X-Debug
X-Ua
X-Forwarded-Host
X-Via-Fastly
X-Extlb
X-Cms-Context
X-Routing-Service
TWC-GeoIP-LatLong
TWC-GeoIP-Country
TWC-Device-Class
TWC-Locale-Group
TWC-Privacy
Webcakes-App-Version
Webcakes-App-Name
X-Handled-By
X-BYPASS-REASON
Webcakes-Region
X-ARC
Countrycode
X-FB-TRIP-ID
WP-Super-Cache
Web-Mar-Node
X-SaId
Apigw-Requestid
X-VWS-Id
X-Adobe-Source
X-LJ-Flow-ID
X-LAGOON
X-JoinUs
X-Proxy-Cache-Status
X-IPLB-Request-ID
X-AWS-Id
X-IPLB-Instance
X-Cluster
X-Tt-Logid
X-Node-Name
X-No-Session
X-Detected-As
X-Optimistic-Header
Locale
Mn-Server-Ip
X-Urbn-Site-Id
X-Cache-TTL-Remaining
X-Urbn-Context-Path
Cache-Tv-Group
X-LSADC-Cache
Fastcgi-Useragent
X-GeoCode
X-GeoCountry
X-TIME
X-Ruxit-Js-Agent
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
X-Director
X-Xfnlog-Site
X-App-Version
X-Tec-Api-Version
Mime-Version
X-Tec-Api-Root
X-Tec-Api-Origin
Upgrade-Insecure-Requests
X-Varnish-Hits
Source
X-GEO
X-Oneagent-Js-Injection
X-Buckets
CDN-PullZone
CDN-Cache
CDN-CachedAt
X-Hl-Ver
CDN-Uid
X-Generated-By
CDN-RequestCountryCode
Frame-Options
CDN-EdgeStorageId
X-Mg-Request-UUID
Fastly-Drupal-HTML
X-Request-Time
X-Api-Version
X-FireWall-Port
X-Varnish-Cache-Hits
Xet-Cookie
X-Redis-Cache
CF-Cached-On
X-Loop
X-Origin-TTL
X-Cache-Debug
X-ServerID
X-Varnish-Hostname
X-RM-Cache-TTL
X-Origin-CC
X-TA-CDN-Provider
X-Datadog-Trace-Id
Load-Balancing
X-Datadog-Parent-Id
X-Datadog-Sampled
X-Datadog-Sampling-Priority
X-URL
X-Tx-Id
X-SRV
X-Akamai-Transformed
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Pass-Why
X-Storefront-Renderer-Rendered
X-Shopify-Stage
X-ShopId
X-ShardId
X-Alternate-Cache-Key
X-Served-From
X-Pubstack
X-Service
X-Storage
X-Request-Host
X-TNCMS
X-Endurance-Cache-Level
X-Air-Pt
Server-Info
X-Restarts
X-Location
X-Bc-Bl
X-BCube-Filmed-By
X-Cache-Date
X-Bip
X-Epic-Correlation-Id
X-B-Cookie
X-Thanos
X-Ec-Fail
X-Sigma-Backend
X-Cache-Info
X-CUA
X-CSRF-Token
X-Developer
X-Destination
X-Core-Mission
X-Conf
X-Cache-NE
X-Test
X-Cdn-Origin
X-CMSURLCustom
X-D
X-Aed
DSUID
Edge-Cache
Redirect-Candidate
Release
Rendered-Blocks
Server-Host
DCR-Decision-By
DCR-Processing-Time-Ms
Origin
Odigeo-Trace-Id
Memcached
MD5-Digest
Host-ID
Meta-Geo-Continent
Ngx.Var.Host
NM-Fastcgi-Cache
Gannett-Cam-Experience-Id
Sslversion
Surrogated-Key
X-A-Dam
BehaviorPad-Version
X-A-Ccd
X-A-Dcw
X-A-Dgt
X-Akamai-Device-Characteristics
A
X-A-Wwc
Cache-Host
X-A
Thinkindot-CacheControl
TDXMobile
T-Server
Thinkindot-CacheControl-Type
Thinkindot-Control
WWW-Authenticate
Candidate-Md5Url
X-Application
X-Ec-GeoHdr
X-Sn-Servicetimems
X-Newrelic-Synthetics
X-Thinkindot-L3
X-Nyt-Route
X-We-Are-Hiring
X-Origin
Lang
X-SRCache-Key
X-Men
X-Loc
X-Mid
X-Mobile-URL
X-SVT-ORM-RULES
X-Origin-Time
X-Platform-Cluster
X-S-Cookie
X-S
X-S-Maxage
X-ScT
X-Sigma
X-Vdms-Path
X-Rojux
X-Platform-Router
X-Platform-Processor
X-Vdms-Version
X-Processor
X-Rocket-Build-Number
X-Level-Front-Cache
Xc-Version
X-Httpd
X-Generated-On
X-Hash
X-External-Request-Id
X-Gdpr
X-INCAP-ABP
X-SVT-ORM-VERSION
X-TIM-N
X-WP-CF-Super-Cache-Active
Xserver
X-Gamma-Serve
Req-Svc-Chain
X-Region-Sid
X-Vmg-Version
X-GeoIP
X-Geo-Header
X-Pool
X-Ec-Custom-Error
X-Request-Start
X-Fetched-On
X-Server-IP
X-SD-PageType
X-Varnish-Beresp-Status
Mail-Subject
Magicmarker
X-Esi-Check
X-Slack-Backend
X-Scale
X-VServer
X-Varnishpool
Platform
X-Fastly-Cache
X-Fastly-Backend
X-Variation
X-Platform
X-Has-Esi
X-Auto-Login
X-Node-Id
X-NodeID
X-Gzip
X-HS-Content-Campaign-Id
X-Mvc-Supplant-Cachable
X-CacheTTL
X-Cache-Id
X-Is-Gdpr
X-Cache-Bucket
X-Human
X-Date
X-GeoIP-City
X-Dispatcher-Number
X-Var-Ttl
X-JWT-State
We-Hiring
Vix-Hermes-Req-Id
X-Worker
X-Slack-Shared-Secret-Outcome
X-Ad-Defer-Variation
X-Org
X-Accel-Expires-Debug
X-Origin-Expires
X-Origin-Response-Time
X-Dispatcher-Server
X-BBC-Edge-Cache-Status
CacheControlHeader
Fastly-GeoIP-CountryCode
X-Correlation-ID
X-Provided-By
CloudFront-Viewer-Country
Fastly-Backend-Name
Section-Io-Id
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
X-CACHE-AGE
Country-Code
AKAMAI
Is-Eu
Adler-Geo
Cache-Key
C-Via
Gh-Request-Id
Environment
X-Parent-Response-Time
X-Forwarded-Site
X-Frame-Option
X-Varnish-Beresp-Ttl
X-GeoIP-Region-Code
X-Device-Os
X-Cache-Tags
X-Cache-FS-Status
X-Azure-Ref-OriginShield
X-App
X-Cdn-Srv
X-Clara-WADP
X-FC-Vary-Parameters
X-Instance-Name
X-Developers
X-Core-Value
X-Fmm-Version
X-Owner
Tube-Get-Contents
Tube-Got-Eval
X-Varnish-Remaining-TTL
Cmstype
Click-Count-Error
Cmsid
Tube-Got-Results
Tube-Return
X-DefHash
X-Req
X-DefElseHash
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
Click-Count-Action-Start
X-Wix-Viewer-Type
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Planisys-CDN-Cache
X-Nginx-Cache-Key
X-Mly-Id
X-Qloud-Router
X-Release
X-WA-Info
X-WADP-Cache
X-Response-By
X-VG-TLSProxy
X-V-Cache
X-Irp-Debug
X-GeoIP-Country-Code
On-Server
Ssr
Apple-News-Services-Request-Url
Origin-CC
Origin-EX
Datacenter
X-Accel-Buffering
Machine
State
Apple-News-Services-Host
Kp-EeAlive
Web-Mar-Region
Canary
Apple-News-Services-Parsed-Url
Apple-News-Services-Handled
X-NCache
X-Old-Content-Length
Sever-Int
X-HN
X-Op-Id-All
User-Cache-Control
X-Gen-Mode
X-Hnp-Log
X-VarnishDD-TTL
NGX
Producers
X-Ckpd-Fst-Backend
L
X-DPWN-IS-SECURE
Fastly-SSL
Expect-Staple
X-Platform-Server
Server-Ext
X-SB
Cache-Provider
PFcat
HostName
Server-Hostname
X-Block-Status
Wxu-Next-Commit
Wxu-Next-Region
Wxu-Next-Hostname
X-Aicache-OS
X-Via-CDN
X-Vcl-Version
X-B3-Spanid
CDCHOST
X-LB-NoCache
X-Microcachable
X-Mvc-Supplant-OutputCached
X-Cache-Remote
X-CGP
X-Nananana
X-FL-QIT-DEBUG
X-Eu-Site
X-FL-EDGE
L5d-Success-Class
Srvid
Locid
X-Csrf-Jwt
X-Minions-Version
HA-Ipaddr
Ha-Gx-Prefs
Edge-Copy-Time
X-Via-Edge
X-Via-SSL
X-Zone
X-Webkit-CSP-Report-Only
Env
X-Tb-Optimization-Total-Bytes-Saved
X-Cache-Backend
X-NWS-UUID-VERIFY
X-From
X-Up
X-VC
X-Refresh
Pics-Label
X-Dc
X-DC
X-Cache-Enabled
GeoIP-Latitude
Decoy-Debug-TTL
Decoy-Debug-Key
Decoy-Debug-Status
Cluster
X-Tid
X-Debug-Cache-Fetch
X-Lambda-Id
X-Debug-Cache-Store
X-Presslabs-Stats
X-Cached-By
X-RCS-CacheZone
X-Generated-In
X-ND-Cache
NtCoent-Length
X-Trace-ID
Sid
Cache
X-Via-Popn
X-Edge-Pop
X-Via-Poph
X-Via-Popv
X-HS-Status
X-VCT
SID
X-Srv
CPC-Cache
CPC-Age
X-Servedbyhost
Fastly-Drupal-Html
VNS-Age
VNS-Cache
Memory
Time
X-Cs
X-Vtex-Remote-Cache
X-Render-Time
X-DataCenter
X-NewRelic-App-Data
X-Webkit-CSP
X-B3-SpanId
X-CCDN-Origin-Time
Svr
X-HA-Backend
X-Hcs-Proxy-Type
X-CCDN-CacheTTL
X-Upstream-Ht
X-Vgn-Hpd-Ssi
X-Upstream-Ct
X-Vgn-Hpd-Cached
X-Vgn-Hpd-Variations-Key
X-Wa
X-LB-ID
X-TH-Server
X-Nc
GeoIp-Country-Code
X-Cache-Type
X-Esi
X-ZONE
X-Vc
AMP-Access-Control-Allow-Source-Origin
Cdn
X-Via-JSL
Server-ID
X-ATG-Version
X-Client-Ip
X-CLOUD-TRACE-CONTEXT
X-Contensis-Viewer-Groups
X-Cache-ASPX
True-Client-IP
X-Varnish-Authentication
Uri
X-AIR-PT
Srv
XServer
X-Fpc
X-Amz-Meta-Cb-Modifiedtime
Hostname
X-NGINX-Cache
X-Check-Cacheable
X-Proxy-CacheRZ
X-Varnish-Beresp-TTL
XkeyRZ
X-RateLimit-Limit-Second
X-CS
Esi-Enabled
X-AK-Request-ID
X-CF-Lambda-Fn
X-PAYTM-SRV-ID
X-CF-Lambda-Version
X-RateLimit-Remaining-Second
X-Gateway-Cache-Key
X-Gateway-Cache-Status
X-Gateway-Skip-Cache
X-Gateway-Request-Id
X-MP-GENERATED-AT
Cdnsip
Cdncip
X-CSRF-TOKEN
M-TraceId
X-Via-NSCOPI
X-Nf-Request-Id
X-EC-Lua
X-FPC
X-Wikidot-Static-Cache
OT-Force-Account-Verify
Resin-Trace
X-CDN-Cache-Status
N-Cache
X-Wikidot-Backend
X-API-Version
X-Udemy-Cache-App-Namespace
YJS-ID
X-Bl-Debug
Eomportal-Instance
True-Client-Ip
X-Shop-Environment
RNT-Time
X-Tenant
X-MSEdge-Flight
X-APP-VERSION
X-MSEdge-Features
X-Forwarded-Path
Lb
RNT-Machine
X-Orig-Expires
X-Datadome
CDN
X-Fastly-Country-Code
Request-ID
X-TX-ID
Server-Id
Path
X-B3-Trace-ID
Sm-Log-Id
X-Policy
X-Service-Response-Time
Ngx-Var-Key
X-Micro-Cache
X-App-Name
GeoIP-Country-Code
X-CACHE-KEY
X-Cache-Ttl
X-SIPLIST1
IsBot
X-WA
X-Lb-Id
X-Ha-Backend
X-Request-URI
LB
X-Vcache
X-Accel-Version
X-Cache-NGX
X-Logging-Id
X-VCL-Version
X-MCACHE
X-NC
Hit
X-Info
X-Git-Commit
X-Container-Uri
HIT
X-Edge-POP
X-RateLimit-Reset
Cross-Origin-Opener-Policy-Report-Only
Pramga
X-Datacenter
X-Cdn-Diag
X-SERVER-NAME
X-Cdn-Cache-Status
Location
X-ServedByHost
X-Pod-Name
Ohc-File-Size
X-Akamai-Pragma-Client-IP
X-Geo
X-Snapshot-Date
X-Via-PopN
X-Tncms
X-VG-WebCache
X-Via-PopH
X-Cdn-Forward
X-Via-PopV
X-Srcache-Fetch-Status
X-Srcache-Store-Status
Timeexpire
FSS-Cache
True-Client-Country-4JS
X-Acquia-Purge-Cdn-Unconfigured
Proxy-Connection
V-Age
XM
X-Ctl-Mach
Req-ID
Epwk-X-Cache
X-Cache-Expires
Servername
X-Cdn-Request-ID
Yjs-Id
Geoip-Latitude
ENV
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
X-Oss-Server-Time
X-Oss-Request-Id
X-Oss-Storage-Class
X-Wp-Cf-Super-Cache-Cache-Control
X-Wp-Cf-Super-Cache
X-Iauth-Set-Uid
X-Clientip
X-UP
X-LiteSpeed-Cache-Control
CDN-RequestPullSuccess
X-Hyper-Cache
X-Fastly-Backend-Reqs
X-Serial
X-TT-LOGID
X-Dw-Trace-Id
CDN-RequestPullCode
X-Lb-Nocache
X-Amz-Meta-Opti
WZWS-RAY
Warning
X-Rebelmouse-Cache-Control
X-MiniProfiler-Ids
X-M-Log
X-Rebelmouse-Surrogate-Control
X-M-Reqid
X-Acquia-Application-UUID
X-Acquia-Application-Trace
X-RAMCache
X-B3-Parentspanid
Ec-Rule-Version
X-Qnm-Cache
X-Acquia-Site
X-Acquia-Purge-Tags
X-Scheme
X-Akamai-ERPolicy
X-Swift-Error
X-Moov-Xdn-Version
X-Moov-T
X-Akamai-ERRuleID
Content-Style-Type
Content-Script-Type
Cneonction
X-Lsadc-Cache
X-F-Status
CountryCode
X-Cached-Since
X-WP-CF-Super-Cache-Cookies-Bypass
X-Cache-Ngx
Ohc-Cache-HIT
PICS-Label
X-TraceId
My-App
MIME-Version
X-Th-Server
Ngx
X-LiteSpeed-Tag
Traceparent
X-IPS-Cached-Response
X-Webstats-RespID
X-Litespeed-Cache-Control
X-Fastly-Cache-Hits
Inserted-Into-Cache-At
X-B3-ParentSpanId
X-Mg-Cache