Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Accept-Ranges
Expect-CT
X-XSS-Protection
Pragma
X-Powered-By
CF-RAY
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Xss-Protection
X-Served-By
X-Download-Options
CF-Ray
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
Access-Control-Allow-Credentials
X-FRAME-OPTIONS
X-Request-ID
X-Request-Id
X-Permitted-Cross-Domain-Policies
X-AspNet-Version
Alt-Svc
X-Runtime
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Generator
X-Cache-Status
X-Cacheable
Timing-Allow-Origin
X-Iinfo
X-Envoy-Upstream-Service-Time
X-Content-Security-Policy
X-Drupal-Dynamic-Cache
Feature-Policy
Content-Encoding
Access-Control-Expose-Headers
Upgrade
Status
X-CDN
X-AspNetMvc-Version
P3p
Access-Control-Max-Age
X-Via
Server-Timing
X-UA-Device
Request-Context
X-Robots-Tag
X-Turbo-Charged-By
X-Amz-Request-Id
X-Cache-Group
EagleId
X-Amz-Id-2
X-Backend
X-AH-Environment
X-Proxy-Cache
Keep-Alive
X-Server
X-Ua-Compatible
X-Ws-Request-Id
X-Age
Host-Header
X-Hacker
Cf-Edge-Cache
X-Vhost
X-Server-Powered-By
X-Rq
X-Dns-Prefetch-Control
X-Varnish-Cache
X-Dispatcher
X-Amz-Version-Id
Allow
Grace
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-OneAgent-JS-Injection
X-LiteSpeed-Cache
X-WebKit-CSP
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Page-Speed
Cf-Apo-Via
X-Device
Accept-CH
Cf-Railgun
X-Aws-Lambda-Call-Status
X-Node
X-Host
X-Pingback
X-Ruxit-JS-Agent
X-Server-Id
EagleEye-TraceId
X-Nginx-Cache-Status
X-Cache-Spec
Surrogate-Control
X-Akam-SW-Version
X-Backend-Server
Request-Id
X-Readtime
X-Cache-Lookup
X-HW
Accept-Ch-Lifetime
X-Content-Security-Policy-Report-Only
X-Cloud-Trace-Context
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Trace
X-Application-Context
X-Response-Time
Fastly-Restarts
Permissions-Policy
X-Nginx-Upstream-Cache-Status
X-Mod-Pagespeed
X-Edge
X-WebKit-CSP-Report-Only
X-Litespeed-Cache
Content-Location
X-CST
X-Mcache
X-Content-Type
X-Url
X-MS-InvokeApp
Accept-CH-Lifetime
X-Clacks-Overhead
X-Country
Rating
X-Midtier
X-Vname
X-TtlSet
X-Amz-Server-Side-Encryption
X-PC
RTSS
X-ECACHE
Cache-Tag
X-VARITI-CCR
X-ESI
X-D2id
X-Vcap-Request-Id
X-Element-Page-Cache
Verso
X-Server-Name
Origin-Trial
X-Cdn-Fetch
X-Kinja
X-GoogleNews-Bot
X-Kinja-Server
X-Exp-Id
X-Exp-Variant
X-Kinja-Build
X-Use-Magma
X-Kinja-Revision
X-Ac
X-Rack-Cache
X-Cnection
X-GitHub-Request-Id
X-Powered-By-Plesk
Service-Worker-Allowed
SPRequestGuid
X-SharePointHealthScore
X-Amz-Rid
X-Client-IP
Xkey
X-Navigation-Version
X-B3-TraceId
X-Cache-TTL
X-Ttl
X-Abt-Application-Version
Edge-Control
X-Varnish-TTL
X-NWS-LOG-UUID
SPRequestDuration
SPIisLatency
X-Upstream
Arr-Disable-Session-Affinity
X-Cached
X-Instrumentation
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Browser-Type
X-Mg-S
X-Dw-Request-Base-Id
X-Px
X-Cache-Key
X-Correlation-Id
Display
Pagespeed
X-Sol
X-Middleton-Display
X-SRCache-Store-Status
X-SRCache-Fetch-Status
Access-Control-Request-Method
Content-MD5
Edge-Cache-Tag
X-Forwarded-For
X-Goog-Hash
X-Country-Code
X-Webkit-Csp
X-NF-Request-ID
Front-End-Https
X-Powered-CMS
TCN
X-Id
X-Version
Public-Key-Pins
X-XRDS-Location
AR-ATIME
AR-CACHE
AR-PoweredBy
AR-Request-ID
AR-SID
X-Jurisdiction
X-HP-Webp
Accept-Ch
X-HP-Trace-Id
X-RateLimit-Remaining
X-T
X-Recruiting
X-MSEdge-Ref
X-Content-Digest
X-Daa-Tunnel
X-FastCGI-Cache
X-Ser
X-Accel-Expires
X-Fastcgi-Cache
X-Amzn-Trace-Id
X-Middleton-Response
Response
TP-Cache
TP-L2-Cache
X-Shield-Request-Id
S
MicrosoftSharePointTeamServices
Nginx-Cache
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
X-Request-Processing-Time
X-Request-Received
Cache-Status
X-Ratelimit-Limit
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Cache-Config
X-HS-Combine-CSS
Server-Node
X-Distributor
Cache-Tags
X-Hits
X-Edge-Location-Klb
X-Kinsta-Cache
Fastcgi-Cache
X-Ratelimit-Remaining
X-LB-Cache
X-Grace
X-DataDome
Server-Name
Alternate-Protocol
X-Origin-Server
Cross-Origin-Opener-Policy
X-Ezoic-Cdn
X-Ua-Browser
X-DIS-Request-ID
X-Ratelimit-Reset
X-Geo-Country
X-Protected-By
X-PressLabs-Stats
X-Request-Handler-Origin-Region
X-Microsite
X-Rid
Filterid
X-TEC-API-ORIGIN
Healthy
X-TEC-API-ROOT
X-TEC-API-VERSION
X-Varnish-Backend
X-Logged-In
X-Www-Served-By
X-Debug-Info
X-Frontend
Payment
X-Git-Hash
X-LLID
X-Hostname
X-FB-Debug
X-NGENIX-Cache
X-Forwarded-Proto
X-Load-Cache
X-Fastly-Request-ID
X-Page-Id
Cleartype
X-Origin-Cache
X-ASPNET-VERSION
X-Cluster-Name
Content-Disposition
DC
MS-Author-Via
Charset
X-TTL
X-B3-Sampled
Realpath
Access-Control-Allow-Method
X-Goog-Metageneration
X-GUploader-UploadID
X-Upgrade-Enabled
X-Proxy
X-F-Cache
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Oracle-Dms-Ecid
X-ORACLE-DMS-RID
X-Oracle-Dms-Rid
X-Az
X-ORACLE-DMS-ECID
X-Activity-Id
X-AppVersion
Retry-After
X-VCache
X-Amz-Replication-Status
Cross-Origin-Resource-Policy
X-Seen-By
X-Server-ID
X-Contextid
Accept-Charset
X-Type
X-Amz-Meta-S3cmd-Attrs
Paypal-Debug-Id
X-Aspnet-Duration-Ms
X-Hosted-By
Count-Hit
X-Signature
X-Is-Crawler
X-Providence-Cookie
X-Route-Name
X-Revision
X-Request-Guid
X-Fb-Rlafr
X-Flags
X-B-Cache
X-Varnish-Server
X-App-Environment
X-Aspnetmvc-Version
X-Azure-Ref
X-TT
X-Whom
Surrogate-Key
X-B
X-Wix-Request-Id
Amp-Access-Control-Allow-Source-Origin
Viewport
X-Akamai-Edgescape
X-DynaTrace
X-B3-Traceid
X-Language
X-RateLimit-Limit
X-Cache-Age
X-ECache
X-Source
X-App-Server
Referer-Policy
X-Fastly-Request-Id
X-Cache-Control
X-Mobile
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-COUNTRY
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Magnolia-Registration
Host
X-Varnish-Grace
X-Tt-Trace-Host
X-Tt-Trace-Tag
Version
X-HTML-Minification-Powered-By
X-Envoy-Decorator-Operation
X-Times
X-Cache-Rule
X-N
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
SRV
X-UUID
X-Tumblr-User
X-Response-Served-From
X-Original-Request-Id
X-Cache-Time
MS-CV
Ms-Operation-Id
X-Rule
X-RTag
X-Varnish-Age
Access-Control-Request-Headers
X-Content-Powered-By
X-Cache-Expired-At
X-Cache-Status-Check
X-EdgeConnect-Cache-Status
X-Framework
SD-X-WS
X-RemovedCookies
X-Template
X-Adobe-Content
X-Cacheable-TTL
WPO-Cache-Status
Section-Io-Cache
WPO-Cache-Message
X-Adobe-Loc
X-Device-Type
X-Backend-Name
X-Page-View
Protected
X-ProcessESI
Akamai-GRN
X-G
X-Servername
X-Status
GEO-INFO
X-User-Agent
X-NYM-Debug-Backend
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
Url
X-Trace-Id
X-Jobs
X-Cache-Grace
Refresh
X-Is-Bot
X-Akamai-Request-ID2
X-FW-Version
X-Rendered-As
X-Environment-Context
X-FW-Type
X-Drupal-Cache-Contexts
X-FW-Static
X-FW-Server
X-FW-Dynamic
X-FW-Serve
X-Instance
X-L-Path
X-Http-Reason
X-FW-Hash
CDN-RequestId
NGB
X-Drupal-Cache-Tags
From-Origin
X-CDN-Forward
X-Region
X-Amz-Apigw-Id
X-Amzn-RequestId
Front
X-Debug-IsConnected
X-Debug-IsPreview
Accept-Language
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Nginx-Cache
X-Cache-Hit
X-Unique-Id
Country
X-Content-Options
Backend
Fastly-SWR
Fastly-SIE
X-Tb
X-Zen-Fury
X-Varnish-Ttl
X-Air-Hostname
X-Air-Source
X-Air-Trace-Id
X-DynaTrace-JS-Agent
X-Tec-Api-Version
X-Tec-Api-Origin
X-Tec-Api-Root
X-Pinterest-Rid
X-Node-Name
X-Mode
Pinterest-Version
Liferay-Portal
Pinterest-Generated-By
X-Tt-Logid
X-Cache-Operation
X-Real-IP
X-Cache-Server
Meta-Geo
X-Ms-Version
Uber-Trace-Id
Webserver
X-Ms-Request-Id
X-Generation-Time
X-Rewrite-Enabled
Filters
X-Tumblr-Pixel-2
X-RN-RSRV
X-UPSTREAM-Address
X-Web-Node
X-PHP-Backend
X-Proxy-Build
X-Timing-Wait
X-Rocket-Nginx-Serving-Static
X-Section
X-Reqid
X-Proxy-Cache-Info
X-Format
Azure-SiteName
Azure-SlotName
Azure-RegionName
Azure-InstanceId
X-Content-Age
Azure-Version
Cache-Hits
X-Access
Selected-Fe
Onion-Location
CF-IPCountry
Content-Secure-Policy
X-Amzn-Remapped-Content-Length
X-VC-Cache
X-Time
X-TIME
X-Newrelic-App-Data
TWC-GeoIP-Country
TWC-Device-Class
TWC-GeoIP-LatLong
TWC-Privacy
Webcakes-App-Name
TWC-Connection-Speed
TWC-Locale-Group
X-Say-Cacheable
X-Soup
X-Sql-Count
Cache-Name
X-SayCDN-TTL
Webcakes-App-Version
X-Say-TTL
ServedBy
X-Adobe-Source
X-IPLB-Instance
X-Proxy-Cache-Status
X-Debug
X-IPLB-Request-ID
X-LJ-Flow-ID
X-Origin-Hint
X-Proto
X-ProxyCache-Key
X-Cms-Context
X-BYPASS-REASON
X-AWS-Id
X-Cache-TTL-Remaining
X-ProxyCache-Status
X-Cluster-Node
X-Cluster
Webcakes-Region
Property-Id
X-IPS-LoggedIn
X-UA-Device-Type
X-VWS-Id
X-R9-Blue-Green-Version
Node
X-Via-Fastly
X-Sql-Duration-Ms
X-Varnish-Beresp-Grace
X-Ua
Apigw-Requestid
DB-Nickname
X-Cache-Action
S-Rt
X-Buckets
X-Server-W
X-PHP-Host
X-Forwarded-Host
X-No-Session
X-Sucuri-ID
X-Sucuri-Cache
X-Skip-Cache
X-Labrador-Cache-Channel
X-Locale
X-Site-Version
X-Handled-By
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
Web-Mar-Node
X-FB-TRIP-ID
X-Proxied
X-Optimistic-Header
X-Cache-Host
X-Edge-Location
X-Zipkin-Id
X-Extlb
X-Detected-As
X-Xfnlog-Site
Mn-Server-Ip
X-Routing-Service
Cross-Origin-Window-Policy
X-Ruxit-Js-Agent
X-Tumblr-Pixel-3
Mime-Version
X-App-Version
X-Origin-Date
Locale
X-Urbn-Site-Id
X-Urbn-Context-Path
X-GeoCode
X-GeoCountry
X-LSADC-Cache
Fastcgi-Useragent
Countrycode
ServerID
WP-Super-Cache
Fastly-Drupal-HTML
X-Uri
X-LAGOON
X-SaId
X-XRDS-LOCATION
X-JoinUs
CDN-EdgeStorageId
CDN-Uid
CDN-RequestCountryCode
CDN-PullZone
CDN-CachedAt
CDN-Cache
Source
X-Oneagent-Js-Injection
X-Hl-Ver
X-ARC
CF-Cached-On
X-Director
Cache-Tv-Group
X-Request-Time
X-Mg-Request-UUID
Upgrade-Insecure-Requests
X-Generated-By
X-GEO
X-Varnish-Hits
X-Redis-Cache
X-Cache-Debug
X-Tx-Id
X-SRV
X-Loop
X-Webkit-CSP-Report-Only
X-TNCMS
X-Pass-Why
X-Akamai-Transformed
Xet-Cookie
X-Origin-TTL
Frame-Options
X-URL
X-FireWall-Port
X-Origin-CC
X-TA-CDN-Provider
X-Varnish-Cache-Hits
X-RM-Cache-TTL
X-Varnish-Hostname
X-Storefront-Renderer-Rendered
X-Alternate-Cache-Key
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-ShopId
X-ShardId
X-Shopify-Stage
X-ServerID
X-Newrelic-Synthetics
Xserver
X-Datadog-Sampling-Priority
X-Datadog-Trace-Id
X-B3-Spanid
X-Datadog-Sampled
X-Datadog-Parent-Id
X-CACHE-AGE
X-Service
X-NWS-UUID-VERIFY
X-Varnish-Beresp-Ttl
X-Request-Host
X-Pubstack
X-Served-From
X-Storage
X-Cache-Date
X-CMSURLCustom
X-Cache-NE
X-Cache-Info
X-Bip
X-Ec-GeoHdr
A
X-Epic-Correlation-Id
X-External-Request-Id
X-Frame-Option
X-Ec-Fail
X-Developer
X-Core-Value
X-CUA
X-D
X-Destination
X-Conf
BehaviorPad-Version
Sslversion
Req-Svc-Chain
Rendered-Blocks
Edge-Cache
DSUID
TDXMobile
T-Server
Surrogated-Key
Gannett-Cam-Experience-Id
Release
Meta-Geo-Continent
Memcached
MD5-Digest
Ngx.Var.Host
Host-ID
Redirect-Candidate
Origin
Odigeo-Trace-Id
DCR-Processing-Time-Ms
DCR-Decision-By
Cache-Host
X-Aed
X-A-Wwc
X-Generated-On
X-Application
X-Bc-Bl
X-BBC-Edge-Cache-Status
X-B-Cookie
X-A-Dgt
X-A-Dcw
Thinkindot-Control
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
WWW-Authenticate
X-A
Candidate-Md5Url
X-A-Dam
X-A-Ccd
X-BCube-Filmed-By
X-Gdpr
X-Nyt-Route
X-Rojux
X-Vdms-Path
X-Vdms-Version
Xc-Version
X-TIM-N
X-Mid
X-Mobile-URL
X-Thanos
X-Origin-Time
X-Platform-Cluster
X-VG-TLSProxy
X-Processor
X-WA-Info
Lang
X-Rocket-Build-Number
X-Platform-Processor
X-Platform-Router
X-Api-Version
X-Test
X-Thinkindot-L3
X-Httpd
X-Endurance-Cache-Level
X-SRCache-Key
X-Sigma-Backend
X-Sigma
X-ScT
X-S-Maxage
X-S-Cookie
X-S
Load-Balancing
X-Loc
X-Location
X-Level-Front-Cache
Server-Info
Tube-Return
Tube-Got-Results
Tube-Got-Eval
Magicmarker
X-Restarts
X-SD-PageType
Server-Host
Ssr
X-Vmg-Version
State
X-Varnish-Remaining-TTL
X-Varnish-CookieINHashed-On
X-SVT-ORM-RULES
X-Varnish-CookieHashed-On
X-Varnishpool
X-SVT-ORM-VERSION
X-Varnish-Beresp-Status
X-VServer
Tube-Get-Contents
X-Sn-Servicetimems
NM-Fastcgi-Cache
X-WP-CF-Super-Cache-Active
X-Ec-Custom-Error
X-JWT-State
X-Is-Gdpr
X-Developers
X-Mvc-Supplant-Cachable
X-DefElseHash
X-DefHash
X-Node-Id
X-INCAP-ABP
X-Human
X-GeoIP-City
X-GeoIP
X-Geo-Header
X-Has-Esi
X-Fmm-Version
X-HS-Content-Campaign-Id
X-Fetched-On
X-Hash
X-Mly-Id
X-NodeID
X-Worker
X-SB
X-Platform-Server
X-Auto-Login
X-We-Are-Hiring
X-Pool
X-Akamai-Device-Characteristics
X-WADP-Cache
X-Cache-Bucket
X-Origin-Response-Time
X-Clara-WADP
X-Old-Content-Length
X-Core-Mission
X-Org
X-Cdn-Srv
X-Origin
X-Cdn-Origin
X-Req
NGX
Environment
Gh-Request-Id
AKAMAI
Apple-News-Services-Handled
CloudFront-Viewer-Country
Country-Code
Decoy-Debug-TTL
Decoy-Debug-Status
Decoy-Debug-Key
Fastly-GeoIP-CountryCode
Apple-News-Services-Host
Click-Count-Error
Apple-News-Services-Request-Url
Click-Count-Action-Start
Apple-News-Services-Parsed-Url
CacheControlHeader
C-Via
X-Parent-Response-Time
X-Tid
X-Dispatcher-Number
X-Dispatcher-Server
X-DPWN-IS-SECURE
X-App
X-Ad-Defer-Variation
Cache-Key
X-CacheTTL
Adler-Geo
X-Azure-Ref-OriginShield
X-Block-Status
X-Cache-Id
X-Ckpd-Fst-Backend
X-Cache-Tags
X-Device-Os
X-FC-Vary-Parameters
X-Request-Start
X-Scale
X-Region-Sid
X-Qloud-Router
X-Op-Id-All
X-Platform
X-Server-IP
X-Slack-Backend
X-VarnishDD-TTL
X-Wix-Viewer-Type
X-Variation
X-Var-Ttl
X-Slack-Shared-Secret-Outcome
X-Nginx-Cache-Key
X-NCache
X-Gen-Mode
X-GeoIP-Country-Code
X-Gamma-Serve
X-Forwarded-Site
X-Fastly-Backend
X-Accel-Buffering
X-GeoIP-Region-Code
X-Gzip
X-Men
X-Minions-Version
X-Irp-Debug
X-Hnp-Log
X-HN
X-Esi-Check
X-LB-NoCache
Is-Eu
Platform
Origin-CC
Kp-EeAlive
User-Cache-Control
Cache-Provider
Cmstype
Sever-Int
Fastly-Backend-Name
Server-Hostname
Server-Ext
Producers
Cmsid
Vix-Hermes-Req-Id
Cluster
We-Hiring
Mail-Subject
CDCHOST
Canary
Origin-EX
L
Machine
Wxu-Next-Hostname
Wxu-Next-Commit
Wxu-Next-Region
Pics-Label
PFcat
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
Section-Io-Origin-Status
X-Presslabs-Stats
Section-Io-Id
X-DC
X-Refresh
HA-Ipaddr
Datacenter
X-Fastly-Cache
X-Planisys-CDN-Rules
X-Owner
X-Nananana
X-Planisys-CDN-Cache
X-Planisys-CDN-TTL
Fastly-SSL
On-Server
Ha-Gx-Prefs
X-Eu-Site
X-Csrf-Jwt
X-Cache-Backend
X-Cache-Remote
L5d-Success-Class
X-CGP
X-V-Cache
Web-Mar-Region
X-Accel-Expires-Debug
X-Date
X-CSRF-Token
X-NewRelic-App-Data
X-Cache-FS-Status
X-Microcachable
X-Instance-Name
X-Mvc-Supplant-OutputCached
X-Origin-Expires
X-Zone
HostName
X-Tb-Optimization-Total-Bytes-Saved
X-Up
X-Response-By
GeoIP-Latitude
X-Aicache-OS
SID
X-Release
Env
X-Servedbyhost
X-FL-QIT-DEBUG
Memory
X-FL-EDGE
Expect-Staple
X-Via-CDN
X-AIR-PT
Time
X-RCS-CacheZone
Locid
Srvid
X-ND-Cache
X-From
Svr
X-VC
X-Trace-ID
X-Nc
X-Cache-Enabled
X-Via-SSL
X-Via-Edge
X-Generated-In
Edge-Copy-Time
NtCoent-Length
X-Air-Pt
X-Provided-By
X-Cached-By
X-Wa
X-Edge-Pop
X-Via-Poph
X-Via-Popv
X-Via-Popn
Cache
Cdn
X-Webkit-CSP
X-NGINX-Cache
X-Dc
X-DataCenter
X-HA-Backend
X-Vc
X-Srv
X-Vcl-Version
Server-ID
X-HS-Status
X-Nf-Request-Id
X-Lambda-Id
X-Esi
X-ZONE
X-Correlation-ID
Sid
X-Debug-Cache-Fetch
X-Client-Ip
X-Vgn-Hpd-Ssi
X-Debug-Cache-Store
Cdncip
Cdnsip
X-Vgn-Hpd-Cached
X-Vgn-Hpd-Variations-Key
X-CCDN-Origin-Time
X-Hcs-Proxy-Type
X-CCDN-CacheTTL
X-AK-Request-ID
X-Check-Cacheable
X-Cs
Hostname
X-Gateway-Cache-Key
X-Gateway-Cache-Status
X-Vtex-Remote-Cache
X-Gateway-Request-Id
X-Via-NSCOPI
X-LB-ID
X-Fpc
GeoIp-Country-Code
X-Gateway-Skip-Cache
X-API-Version
X-CSRF-TOKEN
AMP-Access-Control-Allow-Source-Origin
X-Render-Time
CPC-Age
X-Amz-Meta-Cb-Modifiedtime
X-VCT
CPC-Cache
VNS-Age
VNS-Cache
X-Proxy-CacheRZ
X-Via-JSL
XkeyRZ
Fastly-Drupal-Html
True-Client-IP
X-TH-Server
X-CS
X-ATG-Version
X-Upstream-Ct
Eomportal-Instance
X-Upstream-Ht
X-Cache-Type
X-EC-Lua
True-Client-Ip
Uri
Ngx-Var-Key
Esi-Enabled
X-Micro-Cache
X-B3-SpanId
X-MSEdge-Flight
X-Varnish-Authentication
X-MSEdge-Features
X-Cache-ASPX
M-TraceId
X-Contensis-Viewer-Groups
X-VCL-Version
Srv
Resin-Trace
Path
X-RateLimit-Limit-Second
X-Request-URI
X-RateLimit-Remaining-Second
X-Varnish-Beresp-TTL
X-PAYTM-SRV-ID
X-Fastly-Country-Code
IsBot
X-CF-Lambda-Version
X-Cache-NGX
OT-Force-Account-Verify
X-CF-Lambda-Fn
X-SIPLIST1
Request-ID
XServer
X-Udemy-Cache-App-Namespace
X-APP-VERSION
X-Info
GeoIP-Country-Code
X-Lb-Id
X-FPC
X-RateLimit-Reset
YJS-ID
X-CLOUD-TRACE-CONTEXT
N-Cache
RNT-Time
X-Wikidot-Backend
RNT-Machine
X-MP-GENERATED-AT
CDN
X-Wikidot-Static-Cache
X-Orig-Expires
X-Bl-Debug
X-CDN-Cache-Status
X-Forwarded-Path
X-Tenant
LB
Location
X-Shop-Environment
X-Accel-Version
X-TX-ID
X-MCACHE
X-Service-Response-Time
Sm-Log-Id
X-Datacenter
Server-Id
X-Pod-Name
X-Cdn-Request-ID
X-Edge-POP
X-Oss-Storage-Class
X-Policy
X-App-Name
X-Oss-Hash-Crc64ecma
X-Datadome
X-Oss-Request-Id
X-Oss-Object-Type
X-Ha-Backend
X-B3-Trace-ID
HIT
Cross-Origin-Opener-Policy-Report-Only
X-Cache-Expires
Servername
X-Oss-Server-Time
X-Akamai-Pragma-Client-IP
X-SERVER-NAME
X-Via-PopN
X-Via-PopH
X-WA
X-Cdn-Cache-Status
X-Via-PopV
X-Geo
Timeexpire
X-CACHE-KEY
Lb
X-Srcache-Fetch-Status
Ohc-File-Size
X-Srcache-Store-Status
X-Xrds-Location
X-NC
FSS-Cache
Hit
Epwk-X-Cache
X-Snapshot-Date
Traceparent
X-TraceId
Proxy-Connection
X-Scheme
X-Moov-Xdn-Version
Yjs-Id
X-ServedByHost
X-Moov-T
ENV
Req-ID
X-Cdn-Diag
X-Ctl-Mach
Pramga
X-Viewer-Country
X-PERF
X-ApacheServer
X-UP
Geoip-Latitude
WZWS-RAY
X-Dw-Trace-Id
X-LiteSpeed-Cache-Control
X-Serial
X-Hyper-Cache
X-Cdn-Forward
X-Amz-Meta-Opti
X-Logging-Id
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-MiniProfiler-Ids
X-M-Reqid
X-M-Log
Content-Script-Type
X-Acquia-Application-Trace
X-Acquia-Application-UUID
Content-Style-Type
X-Acquia-Site
X-Fastly-Backend-Reqs
Cneonction
X-Swift-Error
Ec-Rule-Version
X-B3-Parentspanid
X-Lb-Nocache
X-Acquia-Purge-Tags
X-RAMCache
X-Qnm-Cache
X-Vcache
CountryCode
X-TT-LOGID
X-Wp-Cf-Super-Cache-Cache-Control
X-F-Status
X-Wp-Cf-Super-Cache
X-Lsadc-Cache
X-Tncms
X-Mg-Cache
X-Fastly-Cache-Hits
X-Webstats-RespID
X-Litespeed-Cache-Control
Powered-By
Ngx
X-Request-URL
Inserted-Into-Cache-At
X-Cache-Ngx
My-App
X-LiteSpeed-Tag
X-Mid-Debug-Cache-Key
X-Mid-Debug-Cache-Disk
X-NAPM-TraceId
Warning
X-IPS-Cached-Response
X-B3-ParentSpanId
X-Th-Server
X-Vgn-Hpd-Reason
MIME-Version