Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
Strict-Transport-Security
X-Frame-Options
X-Content-Type-Options
Last-Modified
Link
CF-Cache-Status
Cf-Request-Id
Accept-Ranges
ETag
CF-RAY
Expect-CT
Pragma
X-Powered-By
X-Cache
X-XSS-Protection
Via
Age
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Xss-Protection
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-FRAME-OPTIONS
X-Download-Options
X-Timer
X-Request-Id
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-Adblock-Key
X-AspNet-Version
X-Permitted-Cross-Domain-Policies
X-Runtime
Alt-Svc
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Check
X-DNS-Prefetch-Control
X-Cache-Status
X-Generator
CF-Ray
X-Cacheable
Timing-Allow-Origin
X-Iinfo
X-Envoy-Upstream-Service-Time
X-Request-ID
Feature-Policy
Status
X-Content-Security-Policy
X-Drupal-Dynamic-Cache
Content-Encoding
X-AspNetMvc-Version
X-CDN
Access-Control-Expose-Headers
Upgrade
X-XSS-PROTECTION
P3p
Access-Control-Max-Age
X-Ua-Compatible
X-Via
X-Dns-Prefetch-Control
Server-Timing
X-Cache-Group
X-Robots-Tag
X-UA-Device
Request-Context
Keep-Alive
X-Amz-Request-Id
X-AH-Environment
X-Turbo-Charged-By
X-Backend
X-Proxy-Cache
X-Amz-Id-2
X-Ws-Request-Id
X-Age
Host-Header
X-Server-Powered-By
X-Hacker
X-Server
X-Rq
X-Akamai-Path-Stats
EagleId
X-Vhost
X-Varnish-Cache
Grace
X-Amz-Version-Id
X-Dispatcher
X-LiteSpeed-Cache
Cf-Edge-Cache
Allow
X-Swift-SaveTime
X-Swift-CacheTime
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
Ali-Swift-Global-Savetime
X-Nginx-Cache-Status
X-Device
X-Page-Speed
X-WebKit-CSP
X-Aws-Lambda-Call-Status
X-Host
X-OneAgent-JS-Injection
X-Node
X-Server-Id
EagleEye-TraceId
X-Pingback
X-Cache-Spec
Request-Id
Surrogate-Control
Cf-Railgun
Accept-CH
X-Akam-SW-Version
X-Backend-Server
X-Readtime
X-Cache-Lookup
X-Response-Time
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-HW
Accept-CH-Lifetime
Content-Location
X-Content-Security-Policy-Report-Only
X-Application-Context
Rating
X-Trace
Fastly-Restarts
X-Cloud-Trace-Context
X-Country
Accept-Ch-Lifetime
X-WebKit-CSP-Report-Only
X-Clacks-Overhead
X-Url
X-Edge
X-Ruxit-JS-Agent
X-Amz-Server-Side-Encryption
X-MS-InvokeApp
X-B3-TraceId
X-Rack-Cache
Edge-Control
X-PC
X-TtlSet
X-Vname
Accept-Ch
X-Content-Type
X-Nginx-Upstream-Cache-Status
X-ESI
X-Vcap-Request-Id
X-Mod-Pagespeed
X-Varnish-TTL
Xkey
X-FastCGI-Cache
X-Cdn-Fetch
X-Mcache
X-Exp-Id
X-Exp-Variant
X-Kinja-Server
X-Use-Magma
X-Kinja-Revision
X-Kinja-Build
X-Kinja
X-GoogleNews-Bot
X-D2id
X-CST
X-Amz-Rid
X-VARITI-CCR
Cache-Tag
X-GitHub-Request-Id
Verso
RTSS
X-Powered-By-Plesk
Service-Worker-Allowed
X-Cached
X-Upstream
X-Navigation-Version
X-Client-IP
X-ECACHE
X-Version
X-Abt-Application-Version
X-Oneagent-Js-Injection
X-Dw-Request-Base-Id
X-Px
X-Cnection
X-Ac
X-Ruxit-Js-Agent
Public-Key-Pins
Arr-Disable-Session-Affinity
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Instrumentation
X-Ser
X-Element-Page-Cache
X-SharePointHealthScore
SPRequestGuid
X-Server-Name
Display
Pagespeed
X-Middleton-Display
X-Sol
SPIisLatency
SPRequestDuration
X-Cache-TTL
X-Country-Code
X-NWS-LOG-UUID
X-Midtier
Permissions-Policy
X-Ttl
X-Cache-Key
X-NF-Request-ID
X-Middleton-Response
Response
X-Edge-Location-Klb
X-Kinsta-Cache
X-Goog-Hash
X-Forwarded-For
Content-MD5
Access-Control-Request-Method
X-RateLimit-Remaining
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Shield-Request-Id
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
X-DataDome
Front-End-Https
X-MSEdge-Ref
X-Powered-CMS
Edge-Cache-Tag
TP-Cache
TP-L2-Cache
X-Recruiting
AR-ATIME
X-HP-Webp
AR-CACHE
Nginx-Cache
X-T
X-Jurisdiction
X-HP-Trace-Id
AR-PoweredBy
AR-SID
AR-Request-ID
X-Accel-Expires
X-Daa-Tunnel
TCN
MicrosoftSharePointTeamServices
X-Grace
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
X-Correlation-Id
X-Mg-S
X-Id
X-RateLimit-Limit
X-Hits
X-Content-Digest
X-TTL
X-TEC-API-ROOT
Filters
X-TEC-API-ORIGIN
X-TEC-API-VERSION
Server-Node
X-Request-Received
X-HS-Combine-CSS
X-HS-Content-Id
X-Request-Processing-Time
X-HS-Hub-Id
X-HS-Cache-Config
X-Frontend
Server-Name
S
X-Amzn-Trace-Id
X-LLID
X-Distributor
X-Protected-By
X-Language
Cache-Status
X-Geo-Country
X-Fastly-Request-Id
MS-Author-Via
Fastcgi-Cache
X-PressLabs-Stats
X-LB-Cache
X-Microsite
X-Request-Handler-Origin-Region
Cross-Origin-Opener-Policy
Cf-Apo-Via
X-Origin-Server
X-Ezoic-Cdn
X-Forwarded-Proto
X-F-Cache
Host
X-Page-Id
X-Seen-By
Charset
Filterid
X-B3-Sampled
X-Ab
X-FB-Debug
X-Ua-Browser
X-Git-Hash
X-Amz-Meta-S3cmd-Attrs
X-Ratelimit-Reset
Count-Hit
Payment
Realpath
X-Browser-Type
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Litespeed-Cache
X-Cache-Age
X-ASPNET-VERSION
X-VCache
X-Cluster-Name
X-Template
Accept-Charset
X-Origin-Cache
Surrogate-Key
Alternate-Protocol
Cache-Tags
X-XRDS-Location
X-Rid
X-NGENIX-Cache
X-DynaTrace
Retry-After
X-Activity-Id
X-Az
Cleartype
X-AppVersion
X-Webkit-Csp
X-Www-Served-By
Access-Control-Allow-Method
X-Varnish-Backend
X-Varnish-Grace
X-Flags
X-Wix-Request-Id
X-DIS-Request-ID
X-Aspnet-Duration-Ms
X-App-Environment
X-Upgrade-Enabled
X-Node-Name
X-B-Cache
X-Is-Crawler
X-Tb
X-TT
X-Signature
X-Route-Name
X-Providence-Cookie
X-Request-Guid
X-Type
X-Amz-Replication-Status
X-B
X-Fastcgi-Cache
X-Debug
ServerID
DC
Paypal-Debug-Id
X-Drupal-Cache-Tags
X-Logged-In
X-Proxy
X-Ratelimit-Remaining
X-Content
Frame-Options
X-Hostname
X-Envoy-Decorator-Operation
X-Source
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Content-Options
X-Mobile
X-Revision
X-Load-Cache
X-Pinterest-Rid
Pinterest-Version
Amp-Access-Control-Allow-Source-Origin
Pinterest-Generated-By
X-Goog-Storage-Class
X-GUploader-UploadID
X-Contextid
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-Goog-Metageneration
X-Cache-Control
X-N
Country
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Magnolia-Registration
X-Cache-Rule
X-Fastly-Request-ID
X-User-Agent
Referer-Policy
X-Whom
Viewport
X-EdgeConnect-Cache-Status
Node
X-Response-Served-From
X-Original-Request-Id
NGB
Refresh
Content-Disposition
X-Varnish-Age
X-Ratelimit-Limit
X-Cacheable-TTL
Access-Control-Request-Headers
X-L-Path
X-Environment-Context
X-Framework
X-Cache-TTL-Remaining
X-Instance
Akamai-GRN
Url
Uber-Trace-Id
X-Restarts
X-Is-Bot
X-Mid
X-Unique-Id
X-Mg-Request-UUID
X-Varnish-Server
X-Jobs
X-Page-View
X-NYM-Debug-Backend
X-Real-IP
X-Cache-Grace
X-Akamai-Request-ID2
X-Yottaa-Optimizations
X-Cache-Time
X-Yottaa-Metrics
X-Servername
X-Debug-IsPreview
X-Debug-IsConnected
X-G
X-Rendered-As
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-Adobe-Loc
X-Adobe-Content
X-Status
X-Drupal-Cache-Contexts
X-XRDS-LOCATION
Countrycode
X-Content-Powered-By
X-ProcessESI
Version
X-RemovedCookies
X-App-Server
X-Server-ID
X-Webkit-CSP
X-Debug-Info
X-Http-Reason
X-COUNTRY
X-APP-VERSION
Srv
X-Time
X-CDN-Forward
Protected
X-IPLB-Instance
X-IPLB-Request-ID
Accept-Language
X-Correlation-ID
X-Hosted-By
X-Cache-Expired-At
X-Via-JSL
X-URL
Healthy
X-Tt-Logid
X-Nginx-Cache-Key
Fastcgi-Useragent
Liferay-Portal
X-Device-Type
X-Cache-Hit
X-Tumblr-User
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-Trace-Id
X-Tumblr-Pixel
X-FW-Server
X-FW-Static
X-FW-Hash
X-FW-Serve
X-FW-Dynamic
X-FW-Type
X-Azure-Ref
X-Backend-Name
Section-Io-Cache
Backend
X-RTag
X-Datadome
MS-CV
X-Cache-Operation
Ms-Operation-Id
X-Proxy-Cache-Status
X-ECache
Content-Secure-Policy
X-UUID
X-Mobile-URL
Server-Info
X-Oracle-Dms-Rid
X-Oracle-Dms-Ecid
X-Cache-NGX
Load-Balancing
X-Storage
X-RN-RSRV
X-UPSTREAM-Address
Meta-Geo
X-Akamai-Edgescape
X-Mode
CF-IPCountry
X-Handled-By
X-HTML-Minification-Powered-By
Locale
TWC-Locale-Group
TWC-GeoIP-LatLong
Onion-Location
X-Sql-Count
TWC-Device-Class
S-Rt
TWC-Privacy
TWC-GeoIP-Country
Web-Mar-Node
Azure-RegionName
Property-Id
Webcakes-App-Version
Azure-SiteName
Azure-SlotName
Webcakes-Region
Azure-Version
Webcakes-App-Name
Eomportal-Instance
X-Format
X-Origin-Date
X-Varnish-Hostname
X-Varnishpool
X-Origin-Hint
X-Varnish-Cache-Hits
X-Server-W
X-No-Session
X-OCL
X-Urbn-Site-Id
X-Uri
X-Section
X-SayCDN-TTL
X-Proto
X-PHP-Host
X-PHP-Backend
X-PCL
X-Redis-Cache
X-Region
X-VC-Cache
X-Say-TTL
X-VWS-Id
X-Say-Cacheable
X-Urbn-Context-Path
Azure-InstanceId
X-Cache-Server
X-Cms-Context
X-Edge-Location
X-Forwarded-Host
X-Cache-Host
X-Cache-Enabled
X-Access
X-Adobe-Source
X-Alternate-Cache-Key
X-AWS-Id
X-Labrador-Cache-Channel
X-LJ-Flow-ID
X-Sql-Duration-Ms
X-Storefront-Renderer-Rendered
X-Sorting-Hat-ShopId
X-Locale
X-ShardId
X-ShopId
X-Sorting-Hat-PodId
X-Skip-Cache
X-Site-Version
X-Shopify-Stage
WP-Super-Cache
TWC-Connection-Speed
X-Content-Age
GEO-INFO
X-Generation-Time
X-Generated-By
X-GeoCode
X-Hl-Ver
X-FB-TRIP-ID
X-GeoCountry
X-Detected-As
X-BYPASS-REASON
X-Zen-Fury
X-Cache-Type
X-Debug-Cache
X-JoinUs
X-Extlb
X-Proxied
X-UA-Device-Type
X-Timing-Wait
X-Via-Fastly
X-Web-Node
Apigw-Requestid
X-Zipkin-Id
X-ServerID
X-SaId
X-ProxyCache-Key
X-Proxy-Build
X-ProxyCache-Status
X-Request-Time
X-Routing-Service
Selected-Fe
X-Xfnlog-Site
CDN-RequestCountryCode
CDN-PullZone
CDN-EdgeStorageId
CDN-RequestId
CDN-Uid
DB-Nickname
Mn-Server-Ip
CDN-Cache
CDN-CachedAt
X-Nginx-Cache
X-Cache-Action
X-Tid
X-Rule
X-Cache-Status-Check
X-Varnish-Beresp-Grace
ServedBy
Cross-Origin-Resource-Policy
X-Ua
X-Dc
X-SRV
X-LSADC-Cache
X-Ms-Request-Id
X-R9-Blue-Green-Version
X-DynaTrace-JS-Agent
X-Ms-Version
Cache-Name
X-FireWall-Port
Cache
X-Human
SD-X-WS
X-WP-CF-Super-Cache-Cache-Control
X-Cache-Tags
X-WP-CF-Super-Cache
Xet-Cookie
X-Amz-Apigw-Id
X-Amzn-RequestId
Source
X-App-Version
Cross-Origin-Window-Policy
X-Cached-By
Xserver
X-TNCMS
X-RCS-CacheZone
X-Varnish-Hits
X-Loop
X-GEO
WPO-Cache-Status
X-Via-NSCOPI
LB
WPO-Cache-Message
X-MP-GENERATED-AT
X-Reqid
X-Aspnetmvc-Version
Origin
X-TA-CDN-Provider
X-Cdn
X-Pubstack
X-Api-Version
X-Origin-TTL
X-Soup
X-Amzn-Remapped-Content-Length
X-Origin-CC
X-GG-Cache-Date
X-IPS-LoggedIn
X-B3-SpanId
X-AOL-HN
X-Tumblr-Pixel-2
X-Service
From-Origin
X-NewRelic-App-Data
X-FW-Version
X-Vgn-Hpd-Reason
Cache-Hits
X-Xrds-Location
X-Platform-Server
X-Newrelic-Synthetics
Rip
X-Cluster-Node
Webserver
Upgrade-Insecure-Requests
X-Request-Host
X-Provided-By
X-NAPM-TraceId
X-Destination
X-AK-Request-ID
X-Application
Host-ID
X-Ec-Fail
BehaviorPad-Version
Cdnsip
X-Aed
X-A-Dgt
MD5-Digest
X-Owner
X-A-Dcw
X-A-Wwc
X-Orig-Expires
X-ARC
Cdncip
X-Developer
Meta-Geo-Continent
X-Vdms-Version
A
Environment
X-SRCache-Key
X-D
X-External-Request-Id
X-Connection-Hash
DCR-Processing-Time-Ms
X-Forwarded-Path
Expiry
X-Ec-GeoHdr
X-CSRF-Token
DCR-Decision-By
X-VG-WebCache
X-B-Cookie
X-Bc-Bl
X-Cache-NE
X-A-Dam
X-BCube-Filmed-By
X-Vdms-Path
Lang
X-Tenant
Xc-Version
Rendered-Blocks
X-TIM-N
X-Processor
X-S-Cookie
X-Shop-Environment
X-Rewrite-Enabled
X-User
X-ScT
X-Served-From
X-Rojux
HostName
Surrogated-Key
X-A
X-S
Odigeo-Trace-Id
Sslversion
T-Server
X-A-Ccd
Ngx.Var.Host
X-PBS-Appsvrname
X-VC
OT-Force-Account-Verify
X-Cluster
Fastly-SSL
Mobile-Detection-Method
Redirect-Candidate
X-Bip
X-Thanos
X-Origin-Response-Time
X-Qloud-Router
X-Accel-Buffering
X-Dispatcher-Number
X-Pool
X-Generated-On
Machine
X-Aicache-OS
X-Level-Front-Cache
X-Varnish-Beresp-Ttl
Cache-Tv-Group
X-TIME
X-WA-Info
X-Core-Mission
Thinkindot-Control
X-Core-Value
Thinkindot-CacheControl-Type
X-Datadog-Sampling-Priority
X-DefElseHash
TDXMobile
X-DefHash
X-Datadog-Trace-Id
Thinkindot-CacheControl
X-Datadog-Parent-Id
X-Clientip
X-Csrf-Jwt
X-Cache-Info
Vix-Hermes-Req-Id
VNS-Age
V-Age
X-Auto-Login
Tube-Return
We-Hiring
Web-Mar-Region
Wxu-Next-Region
Wxu-Next-Hostname
Wxu-Next-Commit
X-Ad-Defer-Variation
X-BBC-Edge-Cache-Status
Tube-Got-Results
X-Cdn-Origin
Traceparent
X-Cdn-Srv
X-CGP
X-Ckpd-Fst-Backend
X-CacheTTL
Tube-Get-Contents
X-Branch-Name
X-Cache-Bucket
Tube-Got-Eval
X-Cache-Id
X-Clara-WADP
X-GeoIP
X-Viewer-Country
X-Parent-Response-Time
X-Varnish-CookieHashed-On
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Wix-Viewer-Type
X-Policy
X-Planisys-CDN-TTL
X-Slack-Backend
X-Sn-Servicetimems
X-Origin
X-Optimistic-Header
X-Nyt-Route
X-Origin-Expires
X-Origin-Time
State
X-Worker
X-SVT-ORM-RULES
X-Proxy-Cache-Info
X-RateLimit-Limit-Second
X-Scale
X-SB
X-S-Maxage
X-Session-Fingerprint
X-Sigma
X-SIPLIST1
X-Sigma-Backend
X-Thinkindot-L3
X-V-Cache
X-Rocket-Nginx-Serving-Static
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-RateLimit-Remaining-Second
X-Region-Sid
X-Request-URI
X-Rocket-Build-Number
X-Variation
X-Varnish-CookieINHashed-On
X-NodeID
X-Gateway-Cache-Key
X-Gamma-Serve
X-Forwarded-Site
X-Gateway-Cache-Status
X-Gateway-Request-Id
X-WADP-Cache
X-Gdpr
X-Gateway-Skip-Cache
X-Fmm-Version
X-Fetched-On
X-Ec-Custom-Error
X-DPWN-IS-SECURE
X-Device-Os
X-Epic-Correlation-Id
X-Esi-Check
X-Fastly-Cache
X-Eu-Site
X-Geo-Header
X-VServer
X-Loc
X-JWT-State
X-Is-Gdpr
X-SplitTest
X-Minions-Version
X-Mvc-Supplant-OutputCached
X-Mvc-Supplant-Cachable
X-Varnish-Remaining-TTL
X-Irp-Debug
X-INCAP-ABP
X-Gzip
X-SVT-ORM-VERSION
X-GeoIP-City
X-Has-Esi
X-Hash
X-VG-TLSProxy
X-HS-Content-Campaign-Id
X-Developers
VNS-Cache
Fastly-Backend-Name
Fastly-GeoIP-CountryCode
DSUID
Decoy-Debug-TTL
Decoy-Debug-Key
Decoy-Debug-Status
Fastly-SIE
Fastly-SWR
IsBot
Kp-EeAlive
Is-Eu
HA-Ipaddr
Gh-Request-Id
Ha-Gx-Prefs
Datacenter
CPC-Cache
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
Apple-News-Services-Host
Apple-News-Services-Handled
X-NWS-UUID-VERIFY
Adler-Geo
Cache-Host
Candidate-Md5Url
Country-Code
CPC-Age
Cmstype
Cmsid
Click-Count-Action-Start
Click-Count-Error
L
Cluster
Server-Host
Servername
Origin-EX
Req-Svc-Chain
Origin-CC
Platform
Producers
Release
NM-Fastcgi-Cache
L5d-Success-Class
NGX
Memcached
Mail-Subject
Mime-Version
X-Cache-Remote
CloudFront-Viewer-Country
X-NCache
X-Hnp-Log
User-Cache-Control
CDCHOST
Svr
Sever-Int
Server-Hostname
Server-Ext
X-Gen-Mode
X-Scheme
AKAMAI
Fastcgi-Cache-TTL
X-Block-Status
X-Tec-Api-Origin
X-Tec-Api-Version
X-Tec-Api-Root
WebServer
Ec-Rule-Version
X-Pod-Name
X-LB-NoCache
X-Varnish-Beresp-Status
X-Varnish-Ttl
Ssr
X-CMSURLCustom
Canary
X-Tx-Id
X-Tb-Optimization-Total-Bytes-Saved
X-Udemy-Cache-App-Namespace
X-TRACE-ID
X-Ig-Push-State
X-Buckets
Sid
Pics-Label
SID
X-Cache-Date
X-ZONE
X-Sucuri-ID
X-Sucuri-Cache
Fastly-Drupal-Html
X-Microcachable
X-Cache-Debug
X-Newrelic-App-Data
X-WP-CF-Super-Cache-Active
X-Via-Popv
X-Generated-In
X-Conf
X-Yandex-Sdch-Disable
X-ATG-Version
X-Var-Ttl
X-Via-Popn
X-Via-Poph
X-ND-Cache
X-Edge-Pop
X-FC-Vary-Parameters
Memory
X-Fastly-Backend
X-Azure-Ref-OriginShield
X-Refresh
Time
X-Presslabs-Stats
X-B3-Traceid
AMP-Access-Control-Allow-Source-Origin
X-Akamai-Transformed
Server-ID
X-Dmc
X-MSEdge-Flight
X-MSEdge-Features
X-Servedbyhost
X-Be
X-Cs
X-Release
Env
X-Trace-ID
Fastly-Drupal-HTML
X-Air-Source
X-Air-Trace-Id
X-NC
X-Fpc
X-CS
X-Air-Hostname
X-Zone
X-Endurance-Cache-Level
X-Esi
X-TX-ID
X-Tumblr-Pixel-3
X-Pass-Why
X-PX
CDN
GeoIp-Country-Code
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-Up
Magicmarker
X-MCACHE
X-EC-Lua
X-ID
X-DC
X-Srv
X-RateLimit-Reset
X-CACHE-AGE
True-Client-IP
My-App
X-Dispatch
X-Hyper-Cache
X-CF-Lambda-Fn
X-Wa
X-CF-Lambda-Version
X-Lambda-Id
X-Webkit-CSP-Report-Only
X-NGINX-Cache
X-VCL-Version
Pramga
X-App
X-Nf-Request-Id
X-M-Reqid
X-M-Log
X-Micro-Cache
X-CACHE-KEY
X-Vc
X-Varnish-Beresp-TTL
C-Via
X-Alfa-Service
X-Vcl-Version
X-CSRF-TOKEN
X-Req
X-Qnm-Cache
Hostname
X-TrackingId
N-Cache
X-Edge-Origin-Shield-Region
Resin-Trace
X-PAYTM-SRV-ID
X-Air-Pt
X-LB-ID
X-Edge-Origin-Shield-Bytes
X-Platform
CacheControlHeader
True-Client-Ip
Fastcgi-X-Cache-Version
X-HS-Status
Path
On-Server
X-Akamai-Pragma-Client-IP
X-Check-Cacheable
Esi-Enabled
GeoIP-Country-Code
X-Vercel-Cache
X-TH-Server
X-Vercel-Id
Tcn
True-Client-Country-4JS
X-B3-Spanid
X-Vtex-Remote-Cache
X-Vtex-Processado-Em
X-Op-Id-All
X-AIR-PT
Tracecode
GeoIP-Latitude
X-ApacheServer
NtCoent-Length
X-PERF
X-SERVER-NAME
X-Node-Id
X-LAGOON
X-FPC
X-API-Version
Proxy-Connection
X-Request-Start
X-SD-PageType
Cdn
X-CLOUD-TRACE-CONTEXT
Section-Io-Origin-Status
HIT
Section-Io-Id
ENV
Section-Io-Origin-Time-Seconds
Hit
X-GeoIP-Country-Code
Cache-Key
X-WA
X-GeoIP-Region-Code
Section-Origin-Responded
X-Webkit-Csp-Report-Only
DT-Hot-News
X-Accel-Expires-Debug
X-Render-Time
YJS-ID
X-Platform-Processor
X-Date
X-Platform-Cluster
X-Proxy-CacheRZ
WWW-Authenticate
X-Platform-Router
X-Geo
Lb
XkeyRZ
DynaTrace
X-Via-CDN
Server-Id
X-ServedByHost
X-Mly-Id
X-Datacenter
X-Dw-Trace-Id
X-RAMCache
User-Agent
X-Lb-Id
PFcat
X-Proxy-Upstream
X-Traceid
X-Via-Ucdn
X-VarnishDD-TTL
X-HN
X-Edge-POP
XM
X-Cdn-Forward
X-LiteSpeed-Cache-Control
Server-Ttl
X-Via-PopH
X-Via-PopV
X-Via-PopN
X-Proxy-Cache-Hk
XServer
X-Service-Response-Time
Sm-Log-Id
X-CF-Powered-By
X-LI-UUID
X-Li-Pop
X-Li-Fabric
X-LiteSpeed-Tag
X-Cache-Ttl
X-Response-By
MIME-Version
SRV
X-Old-Content-Length
PICS-Label
X-LI-Proto
X-TT-LOGID
Geoip-Latitude
X-CUA
Yjs-Id
Ohc-File-Size
X-Instance-Name
Dnion-Transfer-Encoding
X-FORWARDED-FOR
X-RPS
X-RSL
X-Cache-Ngx
X-Nc
X-DW
X-DI
X-Ftr-Request-Id
X-DB
Location
X-DSS
X-RPM
Powered-By
X-Akamai-ERPolicy
M-TraceId
X-Akamai-ERRuleID
FSS-Cache
X-Cache-Backend
X-Fastly-Backend-Reqs
Vha6-Origin
Nginx-CQVIP
X-UA
X-Litespeed-Cache-Control
X-Wp-Cf-Super-Cache-Cache-Control
X-Wp-Cf-Super-Cache
X-Request-Url
X-Location
X-FL-EDGE
X-From
X-IN-APIGATEWAY
X-Httpd
X-Akamai-Request-ID
X-IN-APIGATEWAYSSL
X-B3-ParentSpanId
Wpo-Cache-Status
X-Cc-Via
X-Lb-Nocache
X-HA-Backend
X-Cdn-Request-ID
Locid
X-Webstats-RespID
X-HostName
Wpo-Cache-Message
Srvid
X-Fastly-Cache-Hits
Warning
X-Ips-Loggedin
CountryCode
X-DataCenter
X-Mg-Cache
X-Snapshot-Date
Ohc-Cache-HIT
X-MiniProfiler-Ids
X-Server-IP
X-Serial
Uri
X-Moov-T
Fastcgi-Cache-Ttl
Req-ID
X-Moov-Xdn-Version
WZWS-RAY