Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
Strict-Transport-Security
X-Frame-Options
X-Content-Type-Options
Last-Modified
Link
CF-Cache-Status
Cf-Request-Id
Accept-Ranges
ETag
CF-RAY
Expect-CT
Pragma
X-Powered-By
X-Cache
Via
X-XSS-Protection
Age
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Amz-Cf-Pop
X-Xss-Protection
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-FRAME-OPTIONS
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-Adblock-Key
X-AspNet-Version
X-Permitted-Cross-Domain-Policies
X-Runtime
Alt-Svc
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Check
X-DNS-Prefetch-Control
X-Cache-Status
X-Generator
CF-Ray
X-Cacheable
Timing-Allow-Origin
X-Iinfo
X-Envoy-Upstream-Service-Time
Feature-Policy
Status
X-Content-Security-Policy
X-Drupal-Dynamic-Cache
Content-Encoding
X-AspNetMvc-Version
Access-Control-Expose-Headers
Upgrade
X-XSS-PROTECTION
X-CDN
X-Ua-Compatible
Access-Control-Max-Age
X-Request-ID
X-Dns-Prefetch-Control
X-Via
Server-Timing
X-Cache-Group
X-Robots-Tag
X-UA-Device
Request-Context
Keep-Alive
X-Amz-Request-Id
X-AH-Environment
X-Turbo-Charged-By
X-Backend
P3p
X-Amz-Id-2
X-Proxy-Cache
X-Ws-Request-Id
X-Age
Host-Header
X-Server-Powered-By
X-Hacker
X-Server
X-Akamai-Path-Stats
X-Rq
EagleId
X-Vhost
X-Varnish-Cache
Grace
X-Amz-Version-Id
X-Dispatcher
X-LiteSpeed-Cache
Cf-Edge-Cache
Allow
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Nginx-Cache-Status
X-Device
X-Page-Speed
X-WebKit-CSP
X-Aws-Lambda-Call-Status
X-Host
X-Node
X-Server-Id
EagleEye-TraceId
X-OneAgent-JS-Injection
X-Pingback
X-Cache-Spec
Request-Id
Surrogate-Control
Cf-Railgun
X-Akam-SW-Version
X-Backend-Server
X-Readtime
Accept-CH
X-Cache-Lookup
X-Response-Time
X-HW
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
Accept-CH-Lifetime
X-Content-Security-Policy-Report-Only
Content-Location
X-Application-Context
Rating
X-Trace
Fastly-Restarts
X-Cloud-Trace-Context
Accept-Ch-Lifetime
X-Country
X-WebKit-CSP-Report-Only
X-Clacks-Overhead
Accept-Ch
X-Url
X-Edge
X-Amz-Server-Side-Encryption
X-Rack-Cache
X-MS-InvokeApp
X-B3-TraceId
Edge-Control
X-TtlSet
X-Vname
X-PC
X-Ruxit-JS-Agent
X-Content-Type
X-Vcap-Request-Id
X-Nginx-Upstream-Cache-Status
X-Mod-Pagespeed
X-Oneagent-Js-Injection
X-Varnish-TTL
Xkey
X-ESI
X-FastCGI-Cache
X-GoogleNews-Bot
X-Kinja
X-Exp-Variant
X-Kinja-Revision
X-D2id
X-Amz-Rid
X-Cdn-Fetch
X-Kinja-Server
X-Exp-Id
X-Kinja-Build
X-Use-Magma
X-Mcache
X-VARITI-CCR
X-CST
Verso
X-GitHub-Request-Id
Cache-Tag
RTSS
X-Powered-By-Plesk
X-Ruxit-Js-Agent
X-ECACHE
X-Cached
Service-Worker-Allowed
X-Upstream
X-Version
X-Client-IP
X-Navigation-Version
X-Abt-Application-Version
X-Dw-Request-Base-Id
X-Px
X-Cnection
X-Ac
Public-Key-Pins
X-Ser
Arr-Disable-Session-Affinity
X-Instrumentation
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-SharePointHealthScore
SPRequestGuid
X-Element-Page-Cache
Display
X-Middleton-Display
Pagespeed
X-Sol
X-Server-Name
X-Country-Code
SPRequestDuration
SPIisLatency
X-Cache-TTL
X-NWS-LOG-UUID
X-NF-Request-ID
X-RateLimit-Remaining
X-Midtier
X-Cache-Key
Permissions-Policy
Response
X-Middleton-Response
X-Ttl
X-Goog-Hash
X-Kinsta-Cache
X-Edge-Location-Klb
X-Forwarded-For
Access-Control-Request-Method
Content-MD5
X-DataDome
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Shield-Request-Id
Front-End-Https
X-MSEdge-Ref
X-Powered-CMS
Edge-Cache-Tag
X-Correlation-Id
X-T
TP-Cache
X-Recruiting
TP-L2-Cache
AR-Request-ID
AR-SID
X-HP-Trace-Id
X-HP-Webp
AR-ATIME
X-Jurisdiction
AR-CACHE
AR-PoweredBy
Nginx-Cache
X-Accel-Expires
X-RateLimit-Limit
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
TCN
MicrosoftSharePointTeamServices
X-Daa-Tunnel
X-Grace
X-B3-TraceId-Primal
Mrf-Cache-Status
MRF-Tech
X-TTL
X-Id
X-Mg-S
X-TEC-API-ROOT
X-TEC-API-VERSION
X-Hits
X-TEC-API-ORIGIN
Filters
X-Content-Digest
X-Request-Received
X-Request-Processing-Time
X-HS-Content-Id
X-HS-Hub-Id
X-HS-Combine-CSS
Server-Node
X-HS-Cache-Config
X-LLID
Server-Name
X-Frontend
S
X-Amzn-Trace-Id
X-Distributor
Cache-Status
X-Protected-By
X-Geo-Country
MS-Author-Via
Fastcgi-Cache
X-Fastly-Request-Id
X-LB-Cache
X-Language
X-Request-Handler-Origin-Region
X-Microsite
X-PressLabs-Stats
Cross-Origin-Opener-Policy
X-Forwarded-Proto
X-Ezoic-Cdn
X-F-Cache
X-Seen-By
X-Origin-Server
Filterid
X-Ua-Browser
X-FB-Debug
X-Page-Id
Host
Charset
X-Ab
X-B3-Sampled
X-XRDS-Location
X-Git-Hash
X-Amz-Meta-S3cmd-Attrs
X-Litespeed-Cache
X-Ratelimit-Reset
Payment
X-ASPNET-VERSION
Count-Hit
Realpath
X-Erf-Bev-Bev
X-VCache
X-Cluster-Name
X-Erf-Bev-Bev-Is-Generated
X-Browser-Type
Accept-Charset
Cf-Apo-Via
Surrogate-Key
X-Origin-Cache
Cache-Tags
Alternate-Protocol
X-DynaTrace
X-NGENIX-Cache
X-Rid
X-Cache-Age
X-Webkit-Csp
Retry-After
X-Az
X-Activity-Id
X-AppVersion
Cleartype
X-Template
X-Fastcgi-Cache
X-Www-Served-By
Access-Control-Allow-Method
X-Cdn
X-Wix-Request-Id
X-Request-Guid
X-Is-Crawler
X-Varnish-Backend
X-Node-Name
X-Aspnet-Duration-Ms
X-Providence-Cookie
X-Flags
X-Route-Name
X-TT
X-B-Cache
X-App-Environment
X-Upgrade-Enabled
X-Amz-Replication-Status
X-Varnish-Grace
X-Tb
X-Type
X-Signature
X-Content
X-B
X-Debug
ServerID
X-DIS-Request-ID
DC
Paypal-Debug-Id
X-Drupal-Cache-Tags
X-Proxy
X-Logged-In
Frame-Options
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Hostname
X-Envoy-Decorator-Operation
X-Source
X-Mobile
X-Content-Options
X-Load-Cache
X-Revision
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-Goog-Stored-Content-Encoding
Pinterest-Generated-By
X-Goog-Generation
X-Pinterest-Rid
X-Goog-Metageneration
X-Goog-Storage-Class
Pinterest-Version
X-Cache-Control
X-N
X-Fastly-Request-ID
X-Contextid
Amp-Access-Control-Allow-Source-Origin
Country
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Magnolia-Registration
X-User-Agent
Referer-Policy
X-Cache-Rule
X-Whom
Viewport
NGB
X-EdgeConnect-Cache-Status
X-Original-Request-Id
X-Response-Served-From
X-Ratelimit-Remaining
Refresh
Node
X-Varnish-Age
X-Restarts
Content-Disposition
Access-Control-Request-Headers
X-Cache-TTL-Remaining
X-Debug-IsPreview
X-Debug-IsConnected
X-Cacheable-TTL
X-Framework
X-Page-View
X-Environment-Context
X-L-Path
Uber-Trace-Id
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Real-IP
Url
X-Servername
X-Yottaa-Metrics
X-Yottaa-Optimizations
Akamai-GRN
X-Varnish-Server
X-Adobe-Content
X-Unique-Id
X-Rendered-As
X-NYM-Debug-Backend
X-Jobs
X-Cache-Grace
X-Cache-Time
X-Is-Bot
X-G
X-Instance
X-Adobe-Loc
X-Akamai-Request-ID2
X-Mg-Request-UUID
X-Mid
X-Status
X-Drupal-Cache-Contexts
X-Server-ID
Countrycode
X-Webkit-CSP
Version
X-Content-Powered-By
X-COUNTRY
X-RemovedCookies
X-ProcessESI
X-App-Server
X-Debug-Info
X-APP-VERSION
X-Http-Reason
X-CDN-Forward
X-XRDS-LOCATION
X-Oracle-Dms-Ecid
X-Oracle-Dms-Rid
Srv
Protected
X-URL
X-IPLB-Request-ID
X-IPLB-Instance
X-Hosted-By
Accept-Language
X-Cache-Expired-At
X-Ratelimit-Limit
X-Tt-Logid
X-Nginx-Cache-Key
Liferay-Portal
Healthy
X-Via-JSL
X-Device-Type
Fastcgi-Useragent
X-Time
X-Cache-Hit
X-FW-Dynamic
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-FW-Hash
X-FW-Serve
X-Azure-Ref
X-FW-Type
X-FW-Static
X-FW-Server
X-Tumblr-User
Section-Io-Cache
X-UUID
X-RTag
MS-CV
Ms-Operation-Id
X-Trace-Id
Backend
X-Cache-NGX
X-Backend-Name
X-Proxy-Cache-Status
X-Cache-Operation
Content-Secure-Policy
Server-Info
X-Mobile-URL
X-RN-RSRV
X-Storage
Load-Balancing
X-UPSTREAM-Address
Meta-Geo
CF-IPCountry
X-Sql-Count
X-Content-Age
X-Handled-By
X-Datadome
X-Mode
X-HTML-Minification-Powered-By
X-Sql-Duration-Ms
Web-Mar-Node
Webcakes-App-Name
CDN-CachedAt
X-PHP-Backend
X-PCL
Webcakes-Region
CDN-EdgeStorageId
Webcakes-App-Version
X-Origin-Hint
CDN-RequestCountryCode
X-PHP-Host
TWC-Connection-Speed
S-Rt
Property-Id
Onion-Location
CDN-RequestId
Locale
TWC-GeoIP-LatLong
TWC-Locale-Group
CDN-PullZone
TWC-Device-Class
Eomportal-Instance
CDN-Uid
TWC-Privacy
X-Section
X-AWS-Id
X-Cache-Enabled
X-Cache-Host
X-Cache-Server
X-Storefront-Renderer-Rendered
X-Urbn-Context-Path
X-Uri
X-Alternate-Cache-Key
X-Urbn-Site-Id
X-ShardId
X-Cms-Context
X-Edge-Location
X-Format
X-LJ-Flow-ID
X-Labrador-Cache-Channel
X-Sorting-Hat-PodId
X-Skip-Cache
X-ShopId
X-Shopify-Stage
X-Site-Version
X-Varnish-Cache-Hits
X-Varnish-Hostname
X-Say-Cacheable
X-Say-TTL
X-Origin-Date
X-SayCDN-TTL
X-Adobe-Source
X-Region
WP-Super-Cache
X-Access
X-Redis-Cache
X-Forwarded-Host
X-VWS-Id
X-Locale
CDN-Cache
X-Varnishpool
X-Sorting-Hat-ShopId
X-VC-Cache
X-Server-W
X-Akamai-Edgescape
X-OCL
X-No-Session
X-Proto
TWC-GeoIP-Country
Azure-InstanceId
GEO-INFO
X-Zen-Fury
Azure-SiteName
Azure-RegionName
Azure-SlotName
Azure-Version
X-Hl-Ver
X-Request-Time
X-JoinUs
X-Proxied
X-GeoCountry
X-Proxy-Build
X-ProxyCache-Status
X-FB-TRIP-ID
X-Detected-As
X-Debug-Cache
X-Cache-Type
X-BYPASS-REASON
X-Extlb
X-Generation-Time
X-Generated-By
Selected-Fe
X-GeoCode
X-ProxyCache-Key
Apigw-Requestid
X-UA-Device-Type
X-Xfnlog-Site
X-Zipkin-Id
X-Via-Fastly
DB-Nickname
X-ServerID
Mn-Server-Ip
X-Timing-Wait
X-SaId
X-Web-Node
X-Routing-Service
X-Correlation-ID
X-Tid
X-SRV
X-Cache-Status-Check
X-Varnish-Beresp-Grace
ServedBy
X-Nginx-Cache
X-Rule
X-Cache-Action
X-LSADC-Cache
X-R9-Blue-Green-Version
X-ECache
X-Ua
X-DynaTrace-JS-Agent
Cross-Origin-Resource-Policy
Cache-Name
X-Ms-Request-Id
X-Ms-Version
Cache
X-FireWall-Port
X-Human
X-Cache-Tags
SD-X-WS
Xet-Cookie
X-WP-CF-Super-Cache-Cache-Control
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Cached-By
X-Dc
X-WP-CF-Super-Cache
Xserver
Source
LB
Cross-Origin-Window-Policy
X-RCS-CacheZone
X-Aspnetmvc-Version
WPO-Cache-Message
WPO-Cache-Status
X-GEO
X-Varnish-Hits
X-Loop
X-TNCMS
X-Via-NSCOPI
X-MP-GENERATED-AT
Origin
X-App-Version
X-Reqid
X-GG-Cache-Date
X-Origin-TTL
X-IPS-LoggedIn
X-Pubstack
X-Origin-CC
X-Amzn-Remapped-Content-Length
X-Soup
X-TA-CDN-Provider
X-AOL-HN
X-NewRelic-App-Data
Cache-Hits
X-Api-Version
X-B3-SpanId
X-FW-Version
X-Tumblr-Pixel-2
Rip
Webserver
From-Origin
X-TIME
X-Service
X-Platform-Server
X-Vgn-Hpd-Reason
X-Newrelic-Synthetics
X-Cluster-Node
Upgrade-Insecure-Requests
X-Request-Host
Lang
BehaviorPad-Version
X-Cache-NE
T-Server
X-Destination
X-Owner
Cdnsip
Cdncip
X-AK-Request-ID
X-Developer
X-PBS-Appsvrname
X-D
X-Bc-Bl
X-External-Request-Id
DCR-Processing-Time-Ms
A
X-Forwarded-Path
Environment
X-Provided-By
X-BCube-Filmed-By
Expiry
Host-ID
X-B-Cookie
X-ARC
X-Application
X-Orig-Expires
X-Ec-GeoHdr
X-Connection-Hash
X-NAPM-TraceId
DCR-Decision-By
X-Ec-Fail
X-Rojux
X-Session-Fingerprint
X-Shop-Environment
X-Aed
Redirect-Candidate
X-Served-From
X-Origin-Response-Time
X-S-Cookie
X-A
X-ScT
X-Tenant
Rendered-Blocks
X-Accel-Buffering
Sslversion
Surrogated-Key
Xc-Version
X-VG-WebCache
X-Vdms-Version
X-TIM-N
X-User
X-Vdms-Path
X-S
X-SRCache-Key
X-A-Dgt
Odigeo-Trace-Id
Meta-Geo-Continent
X-A-Dcw
X-A-Wwc
Ngx.Var.Host
X-Rewrite-Enabled
X-Processor
MD5-Digest
X-A-Ccd
X-A-Dam
Fastly-SSL
OT-Force-Account-Verify
X-Cluster
X-Varnish-Beresp-Ttl
Mobile-Detection-Method
Machine
X-Thanos
X-Wix-Viewer-Type
Decoy-Debug-TTL
X-Pool
X-Aicache-OS
X-Dispatcher-Number
Candidate-Md5Url
Decoy-Debug-Key
X-Forwarded-Site
Decoy-Debug-Status
X-Qloud-Router
X-Generated-On
X-Level-Front-Cache
X-Bip
X-Irp-Debug
X-Core-Value
Thinkindot-CacheControl
Wxu-Next-Commit
X-Core-Mission
Web-Mar-Region
We-Hiring
X-Ad-Defer-Variation
Thinkindot-CacheControl-Type
X-Csrf-Jwt
X-Cdn-Origin
X-Datadog-Trace-Id
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
X-BBC-Edge-Cache-Status
Wxu-Next-Region
TDXMobile
X-Auto-Login
Thinkindot-Control
VNS-Cache
Tube-Got-Results
Tube-Got-Eval
X-Ckpd-Fst-Backend
X-CGP
Tube-Return
X-Cache-Info
Vix-Hermes-Req-Id
X-Cache-Id
Tube-Get-Contents
X-Clara-WADP
X-Branch-Name
V-Age
X-CacheTTL
X-Cache-Bucket
Traceparent
X-Clientip
VNS-Age
X-Cdn-Srv
X-Origin-Time
X-Rocket-Build-Number
X-Request-URI
X-Region-Sid
X-Rocket-Nginx-Serving-Static
X-S-Maxage
X-Sigma
X-Scale
X-SB
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
X-Policy
X-Proxy-Cache-Info
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-Sigma-Backend
X-SIPLIST1
X-VG-TLSProxy
X-Varnish-Remaining-TTL
X-Varnish-CookieINHashed-On
X-Viewer-Country
X-VServer
X-Worker
X-WADP-Cache
X-WA-Info
X-Varnish-CookieHashed-On
X-Variation
X-SplitTest
X-Sn-Servicetimems
X-Slack-Backend
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-V-Cache
X-Thinkindot-L3
X-Parent-Response-Time
X-Origin-Expires
X-Gamma-Serve
X-Fmm-Version
X-Fetched-On
X-Gateway-Cache-Key
X-Gateway-Cache-Status
X-Gdpr
X-Gateway-Skip-Cache
X-Gateway-Request-Id
X-Fastly-Cache
X-Eu-Site
X-Device-Os
X-Developers
X-DefHash
X-DPWN-IS-SECURE
X-Ec-Custom-Error
X-Esi-Check
X-Epic-Correlation-Id
X-Geo-Header
X-GeoIP
X-Mvc-Supplant-OutputCached
X-Mvc-Supplant-Cachable
X-Minions-Version
X-NodeID
X-Nyt-Route
X-Origin
X-Optimistic-Header
X-Loc
X-JWT-State
X-Has-Esi
X-Gzip
X-GeoIP-City
X-Hash
X-HS-Content-Campaign-Id
X-Is-Gdpr
X-INCAP-ABP
X-DefElseHash
Wxu-Next-Hostname
Kp-EeAlive
L
IsBot
Is-Eu
Ha-Gx-Prefs
HA-Ipaddr
Cache-Tv-Group
Cache-Host
Mail-Subject
Memcached
Apple-News-Services-Parsed-Url
L5d-Success-Class
Apple-News-Services-Request-Url
Gh-Request-Id
Click-Count-Action-Start
Country-Code
Cmstype
CPC-Age
CPC-Cache
Datacenter
Fastly-Backend-Name
Fastly-GeoIP-CountryCode
Cluster
Click-Count-Error
Cmsid
Fastly-SWR
Fastly-SIE
DSUID
Apple-News-Services-Host
Platform
Servername
X-CSRF-Token
Server-Host
NGX
Producers
Req-Svc-Chain
HostName
Apple-News-Services-Handled
NM-Fastcgi-Cache
State
Adler-Geo
Origin-EX
Origin-CC
Release
X-Cache-Remote
X-Xrds-Location
X-VC
X-Tx-Id
Mime-Version
X-Hnp-Log
X-Gen-Mode
AKAMAI
CDCHOST
X-NWS-UUID-VERIFY
X-Pod-Name
Svr
X-Scheme
CloudFront-Viewer-Country
X-NCache
Fastcgi-Cache-TTL
X-Block-Status
Sever-Int
User-Cache-Control
Server-Hostname
Server-Ext
X-Esi
X-Presslabs-Stats
X-Varnish-Ttl
X-Varnish-Beresp-Status
X-LB-NoCache
X-Udemy-Cache-App-Namespace
Ec-Rule-Version
WebServer
Ssr
SID
Canary
X-Ig-Push-State
X-ZONE
Pics-Label
X-CMSURLCustom
X-Cache-Date
X-Tb-Optimization-Total-Bytes-Saved
X-Microcachable
Memory
X-Conf
X-Sucuri-ID
X-Sucuri-Cache
X-Trace-ID
Time
X-Yandex-Sdch-Disable
Sid
X-Generated-In
X-Via-Poph
X-Fastly-Backend
X-ATG-Version
X-FC-Vary-Parameters
X-Var-Ttl
X-ND-Cache
X-Azure-Ref-OriginShield
X-Cache-Debug
X-WP-CF-Super-Cache-Active
X-Via-Popv
Fastly-Drupal-Html
X-Via-Popn
AMP-Access-Control-Allow-Source-Origin
X-Tec-Api-Root
X-B3-Traceid
X-Tec-Api-Version
X-Tec-Api-Origin
X-Newrelic-App-Data
X-Refresh
X-Dmc
X-Akamai-Transformed
X-Servedbyhost
X-TRACE-ID
Server-ID
X-Be
Env
X-CS
X-Edge-Pop
X-CACHE-AGE
X-NC
X-MSEdge-Features
X-Fpc
X-Release
X-Air-Source
X-MSEdge-Flight
Fastly-Drupal-HTML
X-Air-Trace-Id
X-Air-Hostname
X-Cs
X-Buckets
X-DC
X-PX
X-ID
X-Wikidot-Static-Cache
X-Zone
X-Wikidot-Backend
X-MCACHE
X-Endurance-Cache-Level
X-EC-Lua
GeoIp-Country-Code
Magicmarker
CDN
X-Up
X-Tumblr-Pixel-3
X-RateLimit-Reset
X-Hyper-Cache
X-TX-ID
X-Dispatch
X-Wa
X-CF-Lambda-Version
X-VCL-Version
X-Vc
X-CF-Lambda-Fn
True-Client-IP
My-App
X-Pass-Why
X-CSRF-TOKEN
Hostname
X-Srv
X-Webkit-CSP-Report-Only
X-NGINX-Cache
X-Lambda-Id
Pramga
X-App
X-M-Reqid
X-M-Log
X-Micro-Cache
X-CACHE-KEY
C-Via
X-Alfa-Service
X-Qnm-Cache
X-TrackingId
X-Req
N-Cache
X-Varnish-Beresp-TTL
X-Edge-Origin-Shield-Region
Resin-Trace
X-Vcl-Version
On-Server
Fastcgi-X-Cache-Version
X-Edge-Origin-Shield-Bytes
True-Client-Ip
X-Platform
X-PAYTM-SRV-ID
X-Air-Pt
Path
X-Vercel-Id
X-LB-ID
X-Check-Cacheable
CacheControlHeader
X-HS-Status
X-TH-Server
X-Vercel-Cache
Tcn
Esi-Enabled
Tracecode
X-AIR-PT
True-Client-Country-4JS
X-Vtex-Remote-Cache
X-B3-Spanid
GeoIP-Country-Code
X-Nf-Request-Id
GeoIP-Latitude
X-Vtex-Processado-Em
X-ApacheServer
NtCoent-Length
X-PERF
X-SERVER-NAME
X-Request-Start
X-Akamai-Pragma-Client-IP
X-Op-Id-All
X-LAGOON
Proxy-Connection
X-API-Version
X-Node-Id
X-SD-PageType
X-CLOUD-TRACE-CONTEXT
Cdn
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
Section-Io-Origin-Status
Hit
HIT
Section-Io-Id
Cache-Key
X-FPC
DT-Hot-News
X-Webkit-Csp-Report-Only
X-GeoIP-Region-Code
X-GeoIP-Country-Code
X-Platform-Cluster
XkeyRZ
X-Render-Time
X-Edge-POP
X-Mly-Id
ENV
X-Platform-Router
X-Platform-Processor
X-Via-CDN
X-Proxy-CacheRZ
X-WA
DynaTrace
X-Geo
X-Dw-Trace-Id
X-Date
Server-Id
X-HN
YJS-ID
X-Proxy-Upstream
X-ServedByHost
User-Agent
PFcat
X-Traceid
X-Accel-Expires-Debug
XM
X-Via-Ucdn
X-Datacenter
X-Lb-Id
WWW-Authenticate
Lb
X-VarnishDD-TTL
X-Cdn-Forward
X-Via-PopH
X-RAMCache
X-Via-PopN
X-LiteSpeed-Cache-Control
X-Via-PopV
X-Proxy-Cache-Hk
Server-Ttl
X-LI-Proto
Geoip-Latitude
X-Li-Pop
X-LI-UUID
Dnion-Transfer-Encoding
X-Li-Fabric
X-FORWARDED-FOR
X-LiteSpeed-Tag
X-CUA
X-Cache-Ttl
MIME-Version
X-CF-Powered-By
Yjs-Id
X-TT-LOGID
SRV
X-Nc
FSS-Cache
X-DB
Vha6-Origin
M-TraceId
PICS-Label
X-Ftr-Request-Id
Location
XServer
X-Cache-Backend
Ohc-File-Size
X-DW
Nginx-CQVIP
X-Service-Response-Time
X-Instance-Name
X-Response-By
X-Akamai-ERPolicy
X-Akamai-ERRuleID
X-Old-Content-Length
X-Fastly-Backend-Reqs
X-RPM
X-DSS
X-DI
X-RPS
X-RSL
Sm-Log-Id
X-Wp-Cf-Super-Cache-Cache-Control
X-Wp-Cf-Super-Cache
X-UA
X-Litespeed-Cache-Control
X-Httpd
X-Akamai-Request-ID
X-B3-ParentSpanId
X-IN-APIGATEWAYSSL
Powered-By
X-HostName
X-IN-APIGATEWAY
X-Lb-Nocache
X-HA-Backend
X-Fastly-Cache-Hits
X-Cdn-Request-ID
X-Mg-Cache
Wpo-Cache-Message
X-Request-Url
Wpo-Cache-Status
X-Cc-Via
CountryCode
Warning
X-Cache-Ngx
X-Moov-T
X-Webstats-RespID
X-From
X-FL-EDGE
X-DataCenter
Srvid
Locid
Fastcgi-Cache-Ttl
X-Moov-Xdn-Version
Uri
Ohc-Cache-HIT
X-Serial
Req-ID
X-Snapshot-Date
X-MiniProfiler-Ids
X-Server-IP
WZWS-RAY