Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Accept-Ranges
X-XSS-Protection
Expect-CT
Pragma
X-Powered-By
X-Cache
CF-RAY
Via
Age
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
CF-Ray
X-Xss-Protection
X-Download-Options
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Request-Id
X-Adblock-Key
Access-Control-Allow-Credentials
X-FRAME-OPTIONS
X-Permitted-Cross-Domain-Policies
X-AspNet-Version
Alt-Svc
X-Request-ID
X-Runtime
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Generator
X-Cache-Status
X-Cacheable
Timing-Allow-Origin
X-Envoy-Upstream-Service-Time
X-Iinfo
X-Content-Security-Policy
X-Drupal-Dynamic-Cache
Feature-Policy
Content-Encoding
Access-Control-Expose-Headers
Upgrade
Status
X-CDN
X-AspNetMvc-Version
Access-Control-Max-Age
X-Via
X-UA-Device
Server-Timing
Request-Context
X-Robots-Tag
X-Turbo-Charged-By
X-Amz-Request-Id
X-Cache-Group
EagleId
X-Amz-Id-2
X-Backend
X-AH-Environment
P3p
X-Proxy-Cache
X-Dns-Prefetch-Control
Keep-Alive
X-Server
X-Ws-Request-Id
X-Age
Cf-Edge-Cache
Host-Header
X-Hacker
X-Vhost
X-Server-Powered-By
X-Rq
X-Varnish-Cache
X-Dispatcher
X-Amz-Version-Id
Grace
Allow
X-Swift-CacheTime
X-Swift-SaveTime
X-OneAgent-JS-Injection
Ali-Swift-Global-Savetime
X-LiteSpeed-Cache
X-WebKit-CSP
X-Ua-Compatible
X-Page-Speed
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Device
Cf-Apo-Via
Cf-Railgun
Accept-CH
X-Aws-Lambda-Call-Status
X-Node
X-Pingback
X-Server-Id
X-Host
X-Ruxit-JS-Agent
EagleEye-TraceId
X-Nginx-Cache-Status
Surrogate-Control
X-Akam-SW-Version
X-Readtime
Request-Id
X-Backend-Server
X-Cache-Spec
X-Content-Security-Policy-Report-Only
X-Cache-Lookup
X-HW
Accept-Ch-Lifetime
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Trace
X-Application-Context
X-Response-Time
Permissions-Policy
X-Cloud-Trace-Context
X-Nginx-Upstream-Cache-Status
Fastly-Restarts
X-WebKit-CSP-Report-Only
X-Mod-Pagespeed
X-Edge
X-Country
X-Litespeed-Cache
Content-Location
X-Mcache
X-Content-Type
X-MS-InvokeApp
X-Url
Accept-CH-Lifetime
X-Clacks-Overhead
X-TtlSet
X-Vname
X-PC
X-CST
X-Amz-Server-Side-Encryption
X-Midtier
Rating
RTSS
Cache-Tag
X-ESI
X-Vcap-Request-Id
X-D2id
X-Element-Page-Cache
X-Rack-Cache
X-Kinja-Build
X-Kinja-Revision
X-Kinja-Server
X-Use-Magma
X-Kinja
X-Exp-Variant
X-Cdn-Fetch
Verso
X-GoogleNews-Bot
X-Exp-Id
Origin-Trial
X-VARITI-CCR
X-Server-Name
X-Ac
X-GitHub-Request-Id
X-Powered-By-Plesk
Service-Worker-Allowed
X-Cnection
X-Amz-Rid
X-ECACHE
SPRequestGuid
X-SharePointHealthScore
X-Client-IP
X-Navigation-Version
Xkey
X-Abt-Application-Version
X-Ttl
Edge-Control
SPIisLatency
SPRequestDuration
X-Upstream
X-Cache-TTL
Arr-Disable-Session-Affinity
X-B3-TraceId
X-Cached
X-Mg-S
X-Dw-Request-Base-Id
X-NWS-LOG-UUID
X-Kraken-Loop-Name
X-Instrumentation
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Server-Lifecycle-Phase
X-Browser-Type
X-Varnish-TTL
X-Px
X-FastCGI-Cache
Accept-Ch
Pagespeed
X-Sol
X-Middleton-Display
Display
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-NF-Request-ID
Access-Control-Request-Method
X-Forwarded-For
Edge-Cache-Tag
X-Cache-Key
X-Correlation-Id
X-Country-Code
X-Goog-Hash
Content-MD5
X-Id
X-Powered-CMS
Front-End-Https
AR-SID
AR-CACHE
AR-Request-ID
AR-ATIME
X-Ser
AR-PoweredBy
Public-Key-Pins
TCN
X-RateLimit-Remaining
X-Version
X-HP-Trace-Id
X-HP-Webp
X-Jurisdiction
X-Amzn-Trace-Id
X-Content-Digest
X-T
X-Recruiting
X-Ratelimit-Limit
X-MSEdge-Ref
Response
X-Middleton-Response
X-Accel-Expires
TP-Cache
TP-L2-Cache
MicrosoftSharePointTeamServices
X-Shield-Request-Id
S
Nginx-Cache
X-Webkit-Csp
Cache-Status
X-Daa-Tunnel
X-XRDS-Location
X-Request-Processing-Time
X-Request-Received
Server-Node
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Combine-CSS
Cache-Tags
MRF-Tech
X-B3-TraceId-Primal
X-HS-Cache-Config
Mrf-Cache-Status
X-Distributor
X-Hits
Cross-Origin-Opener-Policy
X-Fastly-Request-ID
X-Fastcgi-Cache
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-PressLabs-Stats
X-Edge-Location-Klb
X-LB-Cache
X-Kinsta-Cache
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-Origin-Server
X-Ratelimit-Remaining
X-Ua-Browser
X-Ezoic-Cdn
X-Ratelimit-Reset
Alternate-Protocol
Fastcgi-Cache
Filterid
X-Grace
X-LLID
X-Frontend
Server-Name
X-Microsite
X-Request-Handler-Origin-Region
X-Geo-Country
X-DIS-Request-ID
X-Rid
X-Hostname
X-FB-Debug
Healthy
X-Varnish-Backend
X-Logged-In
Payment
X-Debug-Info
X-Www-Served-By
Cleartype
X-NGENIX-Cache
X-Git-Hash
Realpath
X-Page-Id
X-Protected-By
X-Load-Cache
DC
X-Forwarded-Proto
X-Cluster-Name
X-ASPNET-VERSION
X-ECache
MS-Author-Via
Content-Disposition
X-Origin-Cache
Access-Control-Allow-Method
X-TTL
X-DataDome
Charset
X-B3-Sampled
X-GUploader-UploadID
X-Goog-Metageneration
X-Upgrade-Enabled
X-Kong-Proxy-Latency
X-Az
X-Activity-Id
X-Proxy
X-AppVersion
X-Kong-Upstream-Latency
X-Seen-By
X-F-Cache
X-B3-Traceid
X-Cache-Age
X-Amz-Meta-S3cmd-Attrs
X-Amz-Replication-Status
Paypal-Debug-Id
X-Azure-Ref
X-Whom
X-Type
X-B
X-Fb-Rlafr
Count-Hit
X-Revision
X-Contextid
Cross-Origin-Resource-Policy
X-Akamai-Edgescape
Surrogate-Key
X-Is-Crawler
X-Providence-Cookie
X-Route-Name
X-Request-Guid
Accept-Charset
X-Flags
Retry-After
X-App-Environment
Viewport
X-Aspnetmvc-Version
X-Aspnet-Duration-Ms
X-TT
X-Wix-Request-Id
X-Varnish-Server
X-Hosted-By
X-Times
X-Signature
X-Language
X-B-Cache
X-DynaTrace
X-Cache-Control
X-Source
X-App-Server
X-VCache
X-Envoy-Decorator-Operation
X-Magnolia-Registration
X-Mobile
X-Varnish-Grace
Amp-Access-Control-Allow-Source-Origin
X-Goog-Generation
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
Host
X-XRDS-LOCATION
WPO-Cache-Status
WPO-Cache-Message
Version
X-Server-ID
Referer-Policy
X-N
X-HTML-Minification-Powered-By
X-Oracle-Dms-Rid
X-Oracle-Dms-Ecid
Refresh
X-Original-Request-Id
X-Cache-Rule
X-Response-Served-From
X-Amzn-RequestId
X-Tumblr-Pixel-1
X-Tumblr-User
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Varnish-Ttl
X-Rule
X-Amz-Apigw-Id
X-Cache-Time
X-Varnish-Age
Protected
VIX-Pulpo-Upstream-Status
X-RTag
VIX-Pulpo-Node
Access-Control-Request-Headers
SD-X-WS
X-Cache-Grace
X-UUID
X-User-Agent
MS-CV
Ms-Operation-Id
X-EdgeConnect-Cache-Status
X-Cache-Status-Check
X-FW-Version
X-Jobs
X-FW-Type
Section-Io-Cache
X-FW-Serve
X-Device-Type
X-Framework
X-FW-Dynamic
X-Content-Powered-By
X-Cacheable-TTL
X-Backend-Name
From-Origin
X-FW-Static
X-FW-Hash
X-FW-Server
X-Instance
X-G
NGB
Akamai-GRN
X-L-Path
X-ProcessESI
X-Status
X-Page-View
X-Environment-Context
X-RemovedCookies
GEO-INFO
X-Trace-Id
X-Http-Reason
X-Adobe-Content
X-Drupal-Cache-Tags
X-Drupal-Cache-Contexts
X-Adobe-Loc
X-Is-Bot
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Rendered-As
X-Akamai-Request-ID2
X-NYM-Debug-Backend
X-Cache-Expired-At
CDN-RequestId
X-Region
X-Nginx-Cache
Front
X-RateLimit-Limit
X-Fastly-Request-Id
X-Servername
Url
X-Unique-Id
Accept-Language
X-Template
X-CDN-Forward
X-Pinterest-Rid
X-Content-Options
Pinterest-Version
Pinterest-Generated-By
Liferay-Portal
X-Debug-IsConnected
SRV
X-Debug-IsPreview
Fastly-SWR
Fastly-SIE
X-Yottaa-Optimizations
X-Air-Trace-Id
X-Air-Source
X-Air-Hostname
Backend
X-Yottaa-Metrics
X-Cache-Hit
X-Newrelic-App-Data
X-Zen-Fury
X-Time
X-DynaTrace-JS-Agent
Country
X-Mode
Content-Secure-Policy
X-COUNTRY
X-Rocket-Nginx-Serving-Static
X-Uri
Node
Onion-Location
Uber-Trace-Id
X-Rewrite-Enabled
Meta-Geo
X-IPS-LoggedIn
Filters
S-Rt
X-Generation-Time
X-UPSTREAM-Address
X-RN-RSRV
X-Proxy-Cache-Info
X-Tumblr-Pixel-2
X-Content-Age
X-Cache-Server
X-Amzn-Remapped-Content-Length
Cache-Hits
X-Cache-Operation
X-Tb
X-Tumblr-Pixel-3
X-Proxy-Build
X-Timing-Wait
Webserver
X-Locale
Selected-Fe
X-PHP-Backend
X-Cache-Action
X-Edge-Location
X-Cms-Context
X-ARC
X-Format
X-Access
X-Cluster-Node
X-Section
X-SayCDN-TTL
Azure-SlotName
Azure-Version
Azure-SiteName
Azure-RegionName
X-Sucuri-ID
X-Sucuri-Cache
X-Site-Version
X-Ms-Version
X-Origin-Date
Cache-Name
X-PHP-Host
X-Proto
X-Server-W
CF-IPCountry
X-Ms-Request-Id
X-Ua
X-Say-TTL
X-Web-Node
X-Real-IP
X-Via-Fastly
X-Labrador-Cache-Channel
X-Say-Cacheable
Azure-InstanceId
X-Varnish-Beresp-Grace
TWC-GeoIP-Country
TWC-Device-Class
TWC-Connection-Speed
ServedBy
Property-Id
Cross-Origin-Window-Policy
TWC-GeoIP-LatLong
DB-Nickname
ServerID
X-Reqid
X-ProxyCache-Key
X-ProxyCache-Status
X-VC-Cache
X-Zipkin-Id
X-Sql-Duration-Ms
X-Proxied
X-Origin-Hint
X-Skip-Cache
X-Soup
X-Sql-Count
X-Handled-By
X-Routing-Service
X-BYPASS-REASON
Webcakes-Region
Webcakes-App-Version
TWC-Privacy
X-Cache-Host
X-Debug
X-R9-Blue-Green-Version
X-Forwarded-Host
X-Extlb
TWC-Locale-Group
Webcakes-App-Name
WP-Super-Cache
Countrycode
X-LAGOON
X-Optimistic-Header
X-JoinUs
Web-Mar-Node
X-Adobe-Source
X-FB-TRIP-ID
X-Proxy-Cache-Status
X-Ruxit-Js-Agent
X-AWS-Id
X-LJ-Flow-ID
X-VWS-Id
X-IPLB-Request-ID
X-IPLB-Instance
Apigw-Requestid
Cache-Tv-Group
X-UA-Device-Type
X-SaId
X-App-Version
X-Detected-As
X-No-Session
X-Urbn-Site-Id
Mn-Server-Ip
Locale
X-Urbn-Context-Path
X-Cluster
Fastcgi-Useragent
X-Node-Name
X-Cache-TTL-Remaining
X-Xfnlog-Site
X-GeoCountry
X-GeoCode
X-LSADC-Cache
X-Director
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
Mime-Version
X-Oneagent-Js-Injection
X-Tt-Logid
Source
X-Varnish-Hits
X-Buckets
CDN-Uid
Frame-Options
X-Hl-Ver
CDN-Cache
CDN-CachedAt
Upgrade-Insecure-Requests
CDN-RequestCountryCode
X-Generated-By
CDN-EdgeStorageId
CDN-PullZone
X-TIME
X-Tec-Api-Version
X-GEO
X-Tec-Api-Root
X-Tec-Api-Origin
X-Mg-Request-UUID
X-FireWall-Port
Fastly-Drupal-HTML
Xet-Cookie
X-TA-CDN-Provider
X-Redis-Cache
X-SRV
X-Api-Version
X-Varnish-Cache-Hits
X-Request-Time
Load-Balancing
X-Loop
X-Origin-TTL
X-RM-Cache-TTL
X-URL
X-ServerID
X-Origin-CC
X-Datadog-Parent-Id
X-Datadog-Sampled
X-Datadog-Sampling-Priority
X-Cache-Debug
CF-Cached-On
X-Varnish-Hostname
X-Datadog-Trace-Id
X-Akamai-Transformed
X-Sorting-Hat-ShopId
X-Alternate-Cache-Key
X-Storefront-Renderer-Rendered
X-ShopId
X-ShardId
X-Sorting-Hat-PodId
X-Shopify-Stage
X-Pubstack
X-Tx-Id
X-Newrelic-Synthetics
X-Pass-Why
X-Served-From
X-Endurance-Cache-Level
X-Request-Host
X-CSRF-Token
X-Storage
X-Service
X-Location
Xserver
X-Restarts
X-TNCMS
Server-Info
Redirect-Candidate
Sslversion
Rendered-Blocks
Server-Host
A
Candidate-Md5Url
Ngx.Var.Host
Gannett-Cam-Experience-Id
Meta-Geo-Continent
Memcached
Lang
Host-ID
Edge-Cache
NM-Fastcgi-Cache
DCR-Decision-By
MD5-Digest
Origin
Odigeo-Trace-Id
DCR-Processing-Time-Ms
BehaviorPad-Version
X-Bc-Bl
X-Men
X-Level-Front-Cache
X-Mobile-URL
X-TIM-N
X-Nyt-Route
X-Httpd
X-Hash
X-Ec-GeoHdr
X-External-Request-Id
X-Gdpr
X-Generated-On
X-Origin
X-Origin-Time
X-S-Cookie
X-S
X-ScT
X-Test
X-Sn-Servicetimems
X-Thanos
X-Rojux
X-Platform-Cluster
X-Platform-Processor
X-Platform-Router
X-Processor
X-Vdms-Path
X-Ec-Fail
X-A-Dcw
X-Vdms-Version
X-A-Dgt
X-A-Wwc
X-Akamai-Device-Characteristics
X-A-Dam
X-A-Ccd
Xc-Version
T-Server
WWW-Authenticate
X-A
X-Application
X-B-Cookie
X-Conf
X-D
X-Destination
X-Developer
X-Cdn-Origin
X-Cache-NE
X-SRCache-Key
X-BCube-Filmed-By
X-Bip
X-Cache-Info
Surrogated-Key
X-Aed
X-Provided-By
X-Correlation-ID
HostName
X-Loc
X-JWT-State
X-Mid
X-Mvc-Supplant-Cachable
X-Node-Id
X-Is-Gdpr
X-INCAP-ABP
X-HS-Content-Campaign-Id
Release
Platform
X-Gzip
X-NodeID
X-Has-Esi
Mail-Subject
DSUID
X-Region-Sid
X-Req
X-Rocket-Build-Number
Country-Code
X-S-Maxage
Fastly-Backend-Name
X-Platform
X-Varnish-Beresp-Ttl
Magicmarker
X-Origin-Expires
Is-Eu
Gh-Request-Id
X-GeoIP-City
X-Geo-Header
X-Date
X-CUA
X-DefElseHash
X-Ad-Defer-Variation
X-DefHash
X-Accel-Expires-Debug
X-Core-Mission
X-Auto-Login
X-Cache-Bucket
X-Cache-Date
X-Cache-Id
X-CacheTTL
X-CMSURLCustom
X-Dispatcher-Number
X-Dispatcher-Server
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
TDXMobile
X-Gamma-Serve
Cmstype
Thinkindot-Control
X-Fastly-Cache
X-Esi-Check
X-Epic-Correlation-Id
We-Hiring
Vix-Hermes-Req-Id
X-Fastly-Backend
X-GeoIP
X-Org
X-Varnish-CookieINHashed-On
X-Varnish-CookieHashed-On
X-Varnish-Beresp-Status
AKAMAI
X-Varnish-Remaining-TTL
X-Slack-Shared-Secret-Outcome
CacheControlHeader
X-Slack-Backend
Cache-Key
X-Varnishpool
X-Variation
Section-Origin-Responded
Cmsid
X-SVT-ORM-VERSION
Section-Io-Origin-Time-Seconds
X-Thinkindot-L3
Section-Io-Origin-Status
X-SVT-ORM-RULES
Adler-Geo
X-Var-Ttl
Section-Io-Id
X-Vmg-Version
Cache-Host
X-We-Are-Hiring
X-Worker
X-Response-By
X-Sigma
X-SD-PageType
X-Server-IP
X-Scale
X-Sigma-Backend
X-Parent-Response-Time
X-WP-CF-Super-Cache-Active
Environment
X-Azure-Ref-OriginShield
X-Fmm-Version
X-Fetched-On
X-BBC-Edge-Cache-Status
X-Cache-Tags
X-Frame-Option
X-Cdn-Srv
State
X-Forwarded-Site
X-Ckpd-Fst-Backend
X-Clara-WADP
X-FC-Vary-Parameters
X-DPWN-IS-SECURE
X-Ec-Custom-Error
X-WADP-Cache
X-WA-Info
X-VG-TLSProxy
X-VServer
X-Accel-Buffering
X-V-Cache
Web-Mar-Region
Tube-Get-Contents
X-Developers
X-Core-Value
Tube-Got-Eval
Tube-Got-Results
X-Wix-Viewer-Type
Tube-Return
X-App
X-GeoIP-Region-Code
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Owner
X-Air-Pt
X-Cache-FS-Status
X-Origin-Response-Time
Canary
Fastly-GeoIP-CountryCode
X-Pool
X-Request-Start
CloudFront-Viewer-Country
Datacenter
Click-Count-Error
X-Release
X-Qloud-Router
Click-Count-Action-Start
Machine
Kp-EeAlive
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
X-Instance-Name
Producers
On-Server
X-Irp-Debug
Apple-News-Services-Handled
X-Human
Apple-News-Services-Request-Url
Req-Svc-Chain
C-Via
X-GeoIP-Country-Code
X-Nginx-Cache-Key
X-Vcl-Version
X-CLOUD-TRACE-CONTEXT
X-Via-CDN
X-FL-QIT-DEBUG
X-HN
X-FL-EDGE
Srvid
Locid
X-Platform-Server
X-Device-Os
X-Gen-Mode
X-Op-Id-All
X-Old-Content-Length
X-NCache
X-Mly-Id
Expect-Staple
X-VarnishDD-TTL
X-Minions-Version
X-SB
X-Hnp-Log
Ssr
Origin-EX
X-Aicache-OS
PFcat
Origin-CC
Wxu-Next-Commit
Wxu-Next-Hostname
Wxu-Next-Region
Fastly-SSL
User-Cache-Control
Cache-Provider
X-Block-Status
Server-Ext
Sever-Int
Server-Hostname
X-VC
X-CACHE-AGE
X-Zone
X-Webkit-CSP-Report-Only
X-Via-SSL
X-Via-Edge
Edge-Copy-Time
HA-Ipaddr
X-B3-Spanid
X-Mvc-Supplant-OutputCached
L5d-Success-Class
Ha-Gx-Prefs
NGX
X-Eu-Site
X-Microcachable
X-CGP
L
CDCHOST
X-From
X-Csrf-Jwt
X-Nananana
X-Dc
X-Cache-Enabled
X-Cache-Remote
X-Cache-Backend
X-Up
X-Tb-Optimization-Total-Bytes-Saved
X-LB-NoCache
X-Refresh
Pics-Label
Env
X-RCS-CacheZone
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-Lambda-Id
X-ND-Cache
Cluster
X-Generated-In
Decoy-Debug-TTL
Decoy-Debug-Status
Decoy-Debug-Key
Sid
X-DC
X-Trace-ID
X-NWS-UUID-VERIFY
X-Via-Popn
X-Via-Poph
X-Tid
GeoIP-Latitude
X-Cached-By
X-Via-Popv
X-Cs
X-VCT
NtCoent-Length
Cache
VNS-Cache
VNS-Age
X-Edge-Pop
Memory
X-Render-Time
Time
CPC-Age
X-Vtex-Remote-Cache
CPC-Cache
AMP-Access-Control-Allow-Source-Origin
Fastly-Drupal-Html
X-Webkit-CSP
X-B3-SpanId
X-Hcs-Proxy-Type
SID
X-CCDN-Origin-Time
X-Upstream-Ht
X-Upstream-Ct
X-HA-Backend
X-CCDN-CacheTTL
X-LB-ID
X-HS-Status
Srv
X-Cache-Type
X-Vgn-Hpd-Cached
X-Esi
Svr
X-TH-Server
X-Servedbyhost
X-DataCenter
X-Vgn-Hpd-Ssi
X-Vgn-Hpd-Variations-Key
X-Presslabs-Stats
X-AIR-PT
X-Wa
GeoIp-Country-Code
X-NewRelic-App-Data
X-Nc
X-ATG-Version
X-Srv
X-Client-Ip
Cdn
Server-ID
X-Via-JSL
X-ZONE
X-Contensis-Viewer-Groups
X-Cache-ASPX
X-Varnish-Authentication
X-Check-Cacheable
Uri
X-Proxy-CacheRZ
XkeyRZ
X-Vc
X-MP-GENERATED-AT
X-RateLimit-Remaining-Second
X-Amz-Meta-Cb-Modifiedtime
X-CF-Lambda-Version
X-Fpc
X-CF-Lambda-Fn
X-RateLimit-Limit-Second
Esi-Enabled
True-Client-IP
XServer
X-Nf-Request-Id
Cdncip
X-Gateway-Cache-Status
X-Gateway-Cache-Key
M-TraceId
Cdnsip
X-AK-Request-ID
X-PAYTM-SRV-ID
X-Varnish-Beresp-TTL
X-Gateway-Request-Id
X-Gateway-Skip-Cache
X-Udemy-Cache-App-Namespace
Hostname
X-CACHE-KEY
X-EC-Lua
X-CS
X-Datadome
X-NGINX-Cache
X-CDN-Cache-Status
N-Cache
X-Wikidot-Backend
X-Via-NSCOPI
X-API-Version
X-Wikidot-Static-Cache
X-FPC
Lb
Resin-Trace
YJS-ID
X-CSRF-TOKEN
X-Shop-Environment
RNT-Machine
X-Forwarded-Path
X-MSEdge-Features
X-Tenant
X-MSEdge-Flight
X-TX-ID
OT-Force-Account-Verify
RNT-Time
X-Orig-Expires
True-Client-Ip
X-Bl-Debug
Eomportal-Instance
X-Fastly-Country-Code
CDN
Request-ID
X-APP-VERSION
X-B3-Trace-ID
X-Policy
X-App-Name
GeoIP-Country-Code
X-Micro-Cache
Ngx-Var-Key
Path
X-Cache-Ttl
Sm-Log-Id
X-WA
Server-Id
X-Service-Response-Time
IsBot
X-NC
X-SIPLIST1
X-Accel-Version
Hit
X-Datacenter
X-VCL-Version
X-Lb-Id
X-Logging-Id
X-Cache-NGX
X-Ha-Backend
X-Request-URI
X-MCACHE
X-Git-Commit
X-Container-Uri
LB
X-Edge-POP
X-Info
X-Geo
X-Cdn-Diag
X-ServedByHost
X-Vcache
X-RateLimit-Reset
HIT
X-Cdn-Cache-Status
Location
Pramga
X-SERVER-NAME
Cross-Origin-Opener-Policy-Report-Only
X-Akamai-Pragma-Client-IP
FSS-Cache
X-Pod-Name
Geoip-Latitude
X-Srcache-Store-Status
X-Tncms
X-Snapshot-Date
X-Srcache-Fetch-Status
ENV
Ohc-File-Size
Timeexpire
X-Cdn-Forward
X-VG-WebCache
Epwk-X-Cache
Req-ID
True-Client-Country-4JS
X-Via-PopV
X-Via-PopN
V-Age
X-Via-PopH
X-TT-LOGID
X-Ctl-Mach
X-LiteSpeed-Cache-Control
Yjs-Id
X-Wp-Cf-Super-Cache-Cache-Control
X-Wp-Cf-Super-Cache
Tcn
X-Iauth-Set-Uid
X-TimeS
Proxy-Connection
X-Clientip
X-Cache-Expires
X-Oss-Object-Type
X-Acquia-Purge-Cdn-Unconfigured
X-Dw-Trace-Id
X-Serial
X-Oss-Server-Time
X-Oss-Storage-Class
Servername
X-Hyper-Cache
X-Oss-Hash-Crc64ecma
X-Amz-Meta-Opti
CDN-RequestPullCode
X-Oss-Request-Id
X-Lb-Nocache
CDN-RequestPullSuccess
X-Fastly-Backend-Reqs
X-Cdn-Request-ID
X-HostName
XM
Warning
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-M-Reqid
X-M-Log
X-Acquia-Application-Trace
X-Acquia-Purge-Tags
X-RAMCache
X-Acquia-Site
X-Qnm-Cache
X-Acquia-Application-UUID
X-Swift-Error
WZWS-RAY
Cneonction
X-LiteSpeed-Tag
Ec-Rule-Version
Content-Script-Type
Cdn-Requestid
X-B3-Parentspanid
Content-Style-Type
X-UP
X-F-Status
X-MiniProfiler-Ids
X-Lsadc-Cache
CountryCode
PICS-Label
MIME-Version
X-Cache-Ngx
My-App
X-WP-CF-Super-Cache-Cookies-Bypass
X-Cached-Since
W
X-Akamai-ERRuleID
X-Akamai-ERPolicy
X-Th-Server
X-B3-ParentSpanId
Ngx
X-Fastly-Cache-Hits
X-Moov-Xdn-Version
X-Moov-T
X-Litespeed-Cache-Control
X-Mg-Cache
X-IPS-Cached-Response
X-Webstats-RespID
X-Scheme
Ohc-Cache-HIT