Threat Level: green Handler on Duty: Jan Kopriva

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
Strict-Transport-Security
X-Frame-Options
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Accept-Ranges
X-XSS-Protection
Expect-CT
Pragma
X-Powered-By
X-Cache
CF-RAY
Via
Age
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
P3P
X-Served-By
CF-Ray
X-Xss-Protection
X-Download-Options
X-Timer
X-FRAME-OPTIONS
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Request-Id
X-Adblock-Key
Access-Control-Allow-Credentials
X-Permitted-Cross-Domain-Policies
X-AspNet-Version
Alt-Svc
X-Request-ID
X-Runtime
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Generator
X-Check
X-Cache-Status
X-Cacheable
Timing-Allow-Origin
X-Envoy-Upstream-Service-Time
X-Iinfo
X-Content-Security-Policy
X-Drupal-Dynamic-Cache
Feature-Policy
Content-Encoding
Access-Control-Expose-Headers
Upgrade
Status
X-CDN
X-AspNetMvc-Version
P3p
Access-Control-Max-Age
X-Via
Server-Timing
Request-Context
X-Dns-Prefetch-Control
X-Robots-Tag
X-Turbo-Charged-By
X-Amz-Request-Id
X-UA-Device
X-Cache-Group
X-Amz-Id-2
EagleId
X-AH-Environment
X-Backend
X-Proxy-Cache
X-Server
Keep-Alive
X-Ws-Request-Id
X-Age
Cf-Edge-Cache
Host-Header
X-Hacker
X-Vhost
X-Server-Powered-By
X-Rq
X-Varnish-Cache
X-Dispatcher
X-Amz-Version-Id
Grace
Allow
X-OneAgent-JS-Injection
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-LiteSpeed-Cache
X-Ua-Compatible
X-Page-Speed
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-WebKit-CSP
Cf-Apo-Via
X-Device
Cf-Railgun
Accept-CH
X-Aws-Lambda-Call-Status
X-Node
X-Pingback
X-Server-Id
X-Host
X-Ruxit-JS-Agent
EagleEye-TraceId
Surrogate-Control
X-Nginx-Cache-Status
X-Akam-SW-Version
Request-Id
X-Readtime
X-Backend-Server
Accept-Ch-Lifetime
X-Content-Security-Policy-Report-Only
X-HW
X-Cache-Lookup
X-Cache-Spec
X-Cloud-Trace-Context
X-Trace
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Response-Time
X-Application-Context
Permissions-Policy
X-Nginx-Upstream-Cache-Status
Fastly-Restarts
X-Mod-Pagespeed
X-WebKit-CSP-Report-Only
X-Edge
X-Country
X-Litespeed-Cache
Content-Location
X-Mcache
X-MS-InvokeApp
X-Content-Type
X-Url
X-Clacks-Overhead
X-PC
X-TtlSet
X-Vname
X-Midtier
X-Amz-Server-Side-Encryption
X-CST
Accept-CH-Lifetime
Rating
RTSS
Cache-Tag
X-ESI
X-Vcap-Request-Id
X-Rack-Cache
X-D2id
X-Element-Page-Cache
Origin-Trial
X-Exp-Variant
X-Cdn-Fetch
X-Exp-Id
X-Kinja
X-GoogleNews-Bot
X-ECACHE
X-Kinja-Build
X-Kinja-Server
X-Use-Magma
X-Kinja-Revision
Verso
X-VARITI-CCR
X-Server-Name
X-Ac
X-GitHub-Request-Id
Service-Worker-Allowed
X-Powered-By-Plesk
X-Amz-Rid
X-Cnection
SPRequestGuid
X-SharePointHealthScore
X-Client-IP
X-Navigation-Version
Xkey
X-Abt-Application-Version
X-Ttl
SPRequestDuration
Edge-Control
SPIisLatency
X-Cache-TTL
X-Upstream
Arr-Disable-Session-Affinity
X-Varnish-TTL
X-Cached
X-B3-TraceId
X-Mg-S
X-Dw-Request-Base-Id
X-Erf-Bev-Bev
X-Server-Lifecycle-Phase
X-Browser-Type
X-Kraken-Loop-Name
X-Instrumentation
X-Erf-Bev-Bev-Is-Generated
X-NWS-LOG-UUID
X-Px
Accept-Ch
X-Middleton-Display
Pagespeed
Display
X-Sol
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-NF-Request-ID
X-Correlation-Id
Access-Control-Request-Method
Edge-Cache-Tag
X-Forwarded-For
X-FastCGI-Cache
X-Cache-Key
X-Goog-Hash
X-Country-Code
X-Webkit-Csp
X-Powered-CMS
X-Ser
X-Id
Content-MD5
AR-SID
AR-ATIME
Front-End-Https
AR-CACHE
AR-PoweredBy
AR-Request-ID
Public-Key-Pins
X-Ratelimit-Limit
TCN
X-HP-Webp
X-Version
X-Jurisdiction
X-HP-Trace-Id
X-Amzn-Trace-Id
X-MSEdge-Ref
X-Content-Digest
X-Recruiting
X-T
X-Middleton-Response
Response
X-Accel-Expires
TP-L2-Cache
TP-Cache
X-RateLimit-Remaining
X-Shield-Request-Id
MicrosoftSharePointTeamServices
X-XRDS-Location
S
X-Fastcgi-Cache
Cache-Status
Nginx-Cache
X-Fastly-Request-ID
X-HS-Content-Id
X-HS-Hub-Id
X-HS-Combine-CSS
X-HS-Cache-Config
Cross-Origin-Opener-Policy
X-Request-Processing-Time
X-Request-Received
X-Daa-Tunnel
Server-Node
Cache-Tags
X-Ratelimit-Remaining
X-Distributor
MRF-Tech
Mrf-Cache-Status
X-B3-TraceId-Primal
X-Hits
X-PressLabs-Stats
X-LB-Cache
X-Edge-Location-Klb
X-Kinsta-Cache
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
X-Origin-Server
X-Ezoic-Cdn
X-Ua-Browser
X-Ratelimit-Reset
Fastcgi-Cache
Filterid
Alternate-Protocol
X-Grace
X-Frontend
X-ORACLE-DMS-ECID
X-LLID
X-ORACLE-DMS-RID
X-Request-Handler-Origin-Region
X-Microsite
X-Rid
X-Varnish-Backend
X-Hostname
X-Logged-In
X-DIS-Request-ID
Server-Name
Healthy
Realpath
X-FB-Debug
X-NGENIX-Cache
X-Geo-Country
X-Cluster-Name
X-Git-Hash
X-Debug-Info
Cleartype
X-Www-Served-By
X-Page-Id
Payment
X-Load-Cache
X-Forwarded-Proto
MS-Author-Via
X-Protected-By
DC
X-ASPNET-VERSION
Access-Control-Allow-Method
Content-Disposition
X-Origin-Cache
X-TTL
Charset
X-B3-Sampled
X-Goog-Metageneration
X-DataDome
X-GUploader-UploadID
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Upgrade-Enabled
X-Activity-Id
X-Az
X-AppVersion
X-Proxy
X-Seen-By
X-Times
Count-Hit
X-ECache
X-F-Cache
X-B3-Traceid
X-Cache-Age
X-Amz-Meta-S3cmd-Attrs
Cross-Origin-Resource-Policy
X-Amz-Replication-Status
X-Whom
X-Fb-Rlafr
X-Revision
X-Azure-Ref
X-B
X-Akamai-Edgescape
Surrogate-Key
X-Type
Paypal-Debug-Id
X-Contextid
X-Flags
X-Varnish-Server
X-Aspnet-Duration-Ms
X-Providence-Cookie
X-Is-Crawler
X-Request-Guid
X-App-Environment
X-Route-Name
Accept-Charset
X-Aspnetmvc-Version
Viewport
Retry-After
X-Wix-Request-Id
X-TT
X-Hosted-By
X-Language
X-Signature
X-B-Cache
X-Envoy-Decorator-Operation
X-DynaTrace
X-Cache-Control
X-Oracle-Dms-Ecid
X-Oracle-Dms-Rid
X-App-Server
X-Source
X-Magnolia-Registration
X-Varnish-Grace
Amp-Access-Control-Allow-Source-Origin
X-Mobile
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Generation
WPO-Cache-Status
X-VCache
WPO-Cache-Message
Version
Host
X-Server-ID
X-N
X-Cache-Rule
Referer-Policy
X-HTML-Minification-Powered-By
X-Cache-Time
X-Original-Request-Id
X-Response-Served-From
X-Varnish-Age
Access-Control-Request-Headers
X-Amz-Apigw-Id
X-Amzn-RequestId
Refresh
X-Tumblr-Pixel
X-EdgeConnect-Cache-Status
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-Tumblr-User
X-Rule
X-RTag
Ms-Operation-Id
MS-CV
X-UUID
Protected
SD-X-WS
X-Cache-Grace
X-Content-Powered-By
X-G
X-Jobs
X-User-Agent
X-Device-Type
X-Framework
X-Cacheable-TTL
X-Cache-Status-Check
Section-Io-Cache
X-Backend-Name
X-Environment-Context
X-FW-Dynamic
X-FW-Type
X-FW-Version
X-FW-Static
X-FW-Server
X-FW-Hash
X-FW-Serve
CDN-RequestId
X-L-Path
X-Page-View
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
NGB
X-Status
X-Tt-Trace-Host
X-Region
GEO-INFO
X-Tt-Trace-Tag
From-Origin
Akamai-GRN
X-Is-Bot
X-Cache-Expired-At
X-Adobe-Loc
X-Rendered-As
X-Akamai-Request-ID2
Front
X-NYM-Debug-Backend
X-Instance
X-Adobe-Content
X-Http-Reason
X-Drupal-Cache-Contexts
X-XRDS-LOCATION
X-Drupal-Cache-Tags
X-Nginx-Cache
X-ProcessESI
X-RemovedCookies
Url
X-Servername
X-Unique-Id
X-Trace-Id
X-Pinterest-Rid
Pinterest-Generated-By
Pinterest-Version
Liferay-Portal
Accept-Language
X-Time
X-Varnish-Ttl
X-Content-Options
Fastly-SWR
SRV
Fastly-SIE
X-RateLimit-Limit
X-Template
X-Fastly-Request-Id
X-Debug-IsPreview
X-Debug-IsConnected
Backend
X-Newrelic-App-Data
X-Air-Source
X-Air-Hostname
X-Air-Trace-Id
X-Zen-Fury
X-CDN-Forward
X-Cache-Hit
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-DynaTrace-JS-Agent
Country
X-Mode
X-COUNTRY
Content-Secure-Policy
X-Uri
X-Rocket-Nginx-Serving-Static
Node
X-Cache-Operation
Meta-Geo
S-Rt
X-UPSTREAM-Address
X-Generation-Time
X-RN-RSRV
Webserver
X-Rewrite-Enabled
X-ARC
X-Content-Age
Filters
Onion-Location
X-IPS-LoggedIn
X-Edge-Location
X-Proxy-Cache-Info
X-Amzn-Remapped-Content-Length
X-Tumblr-Pixel-2
X-Proxy-Build
Selected-Fe
Azure-Version
X-Timing-Wait
X-Tb
X-Tumblr-Pixel-3
Azure-SlotName
Azure-SiteName
Azure-InstanceId
Uber-Trace-Id
X-Cache-Server
Azure-RegionName
X-Web-Node
CF-IPCountry
X-PHP-Backend
X-App-Version
X-PHP-Host
X-Proto
Countrycode
X-Reqid
X-ProxyCache-Status
X-ProxyCache-Key
WP-Super-Cache
X-Server-W
X-Ms-Request-Id
X-Say-TTL
X-Locale
X-Cache-Action
X-BYPASS-REASON
X-Labrador-Cache-Channel
X-SayCDN-TTL
X-Ms-Version
X-Say-Cacheable
X-Cms-Context
Cache-Hits
X-Sucuri-ID
X-Sucuri-Cache
X-Ua
X-Origin-Date
X-Cache-Host
X-IPLB-Request-ID
X-Debug
X-LJ-Flow-ID
X-Format
X-IPLB-Instance
Cache-Name
X-Origin-Hint
ServerID
X-Proxied
X-Extlb
X-Proxy-Cache-Status
X-VWS-Id
Webcakes-App-Name
Property-Id
X-Skip-Cache
X-Soup
X-AWS-Id
X-Sql-Count
X-Routing-Service
TWC-Device-Class
TWC-GeoIP-LatLong
TWC-GeoIP-Country
TWC-Locale-Group
TWC-Privacy
X-Site-Version
Webcakes-Region
X-Cluster-Node
X-Sql-Duration-Ms
X-Forwarded-Host
X-Zipkin-Id
X-Access
Webcakes-App-Version
TWC-Connection-Speed
X-VC-Cache
X-Section
X-UA-Device-Type
DB-Nickname
X-LAGOON
X-R9-Blue-Green-Version
Web-Mar-Node
X-Handled-By
X-FB-TRIP-ID
Cache-Tv-Group
Apigw-Requestid
X-Cluster
X-Ruxit-Js-Agent
X-SaId
X-JoinUs
X-Adobe-Source
X-Optimistic-Header
X-Varnish-Beresp-Grace
X-Cache-TTL-Remaining
Mn-Server-Ip
X-Urbn-Site-Id
X-Urbn-Context-Path
X-Via-Fastly
Locale
X-Detected-As
Cross-Origin-Window-Policy
X-No-Session
ServedBy
X-LSADC-Cache
X-Real-IP
X-GeoCountry
X-Director
X-GeoCode
Fastcgi-Useragent
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
X-Xfnlog-Site
X-Oneagent-Js-Injection
Mime-Version
X-Node-Name
Upgrade-Insecure-Requests
Source
X-Varnish-Hits
X-Tt-Logid
Frame-Options
X-GEO
X-Buckets
CDN-Cache
X-Hl-Ver
CDN-EdgeStorageId
CDN-CachedAt
X-Generated-By
CDN-RequestCountryCode
CDN-Uid
CDN-PullZone
Fastly-Drupal-HTML
Load-Balancing
X-Tec-Api-Root
X-Tec-Api-Origin
X-Tec-Api-Version
X-Varnish-Cache-Hits
X-SRV
X-Request-Time
X-FireWall-Port
Xet-Cookie
X-ServerID
X-Api-Version
X-TA-CDN-Provider
X-RM-Cache-TTL
X-Mg-Request-UUID
X-Varnish-Hostname
X-Datadog-Sampled
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
X-Origin-TTL
X-Origin-CC
X-Datadog-Trace-Id
X-URL
X-Loop
X-Redis-Cache
X-Cache-Debug
X-TIME
CF-Cached-On
X-Akamai-Transformed
X-Sorting-Hat-PodId
X-Shopify-Stage
X-ShopId
X-ShardId
X-Alternate-Cache-Key
X-Tx-Id
X-Storefront-Renderer-Rendered
X-Sorting-Hat-ShopId
X-Served-From
X-Pubstack
X-Storage
X-Endurance-Cache-Level
Xserver
X-Provided-By
X-Newrelic-Synthetics
X-Pass-Why
X-Restarts
X-Request-Host
X-CSRF-Token
X-Location
Server-Info
X-Service
X-Application
X-B-Cookie
X-BCube-Filmed-By
X-Bc-Bl
X-Akamai-Device-Characteristics
X-Aed
X-A-Dam
A
X-A-Dcw
X-A-Dgt
X-A-Wwc
X-Cache-Date
X-Cache-Info
X-Ec-GeoHdr
X-Developer
X-Epic-Correlation-Id
X-External-Request-Id
X-Hash
X-Gdpr
X-Destination
X-D
X-Cdn-Origin
X-Cache-NE
X-CMSURLCustom
X-Conf
X-CUA
X-Core-Mission
X-A-Ccd
BehaviorPad-Version
Origin
Odigeo-Trace-Id
Edge-Cache
Redirect-Candidate
Release
DSUID
NM-Fastcgi-Cache
Ngx.Var.Host
MD5-Digest
Lang
Host-ID
Memcached
Gannett-Cam-Experience-Id
Meta-Geo-Continent
Rendered-Blocks
DCR-Processing-Time-Ms
Thinkindot-Control
Thinkindot-CacheControl-Type
Candidate-Md5Url
WWW-Authenticate
X-Httpd
Cache-Host
Thinkindot-CacheControl
TDXMobile
Server-Host
DCR-Decision-By
Sslversion
Surrogated-Key
T-Server
X-A
X-Ec-Fail
X-S-Cookie
X-S-Maxage
X-ScT
X-Sigma
X-S
X-Rojux
X-Origin
X-Origin-Time
X-Processor
X-Response-By
X-Sigma-Backend
X-Sn-Servicetimems
X-Vdms-Path
X-Vdms-Version
X-We-Are-Hiring
Xc-Version
X-TIM-N
X-Thinkindot-L3
X-SRCache-Key
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-Test
X-Nyt-Route
X-Rocket-Build-Number
X-Men
X-Loc
X-INCAP-ABP
X-Mid
X-Mobile-URL
HostName
X-WP-CF-Super-Cache-Active
X-Fetched-On
X-Generated-On
X-Var-Ttl
X-Thanos
X-JWT-State
X-Slack-Shared-Secret-Outcome
Tube-Get-Contents
X-Esi-Check
X-Is-Gdpr
X-Gamma-Serve
X-Fastly-Backend
Req-Svc-Chain
X-Varnish-CookieINHashed-On
X-Has-Esi
X-Worker
X-Gzip
C-Via
X-Auto-Login
X-Scale
Mail-Subject
X-VServer
X-Vmg-Version
Tube-Got-Eval
X-Varnish-CookieHashed-On
X-Varnish-Remaining-TTL
X-GeoIP
X-GeoIP-City
Platform
X-Variation
We-Hiring
X-BBC-Edge-Cache-Status
X-Platform
X-Platform-Cluster
X-Platform-Processor
X-Date
X-Platform-Router
X-Bip
X-Cache-Bucket
X-Org
X-Mvc-Supplant-Cachable
X-CacheTTL
X-Origin-Expires
X-Origin-Response-Time
X-Cache-Id
X-Req
X-Ad-Defer-Variation
Magicmarker
X-Server-IP
X-Level-Front-Cache
X-Node-Id
X-Slack-Backend
Tube-Return
X-SD-PageType
X-Ec-Custom-Error
X-DefElseHash
X-Accel-Expires-Debug
X-Human
X-DefHash
X-Dispatcher-Number
Tube-Got-Results
X-HS-Content-Campaign-Id
Cache-Key
Click-Count-Action-Start
Country-Code
Click-Count-Error
Adler-Geo
Cmstype
Cmsid
X-TNCMS
Fastly-Backend-Name
Expect-Staple
Gh-Request-Id
Is-Eu
Section-Io-Id
Fastly-GeoIP-CountryCode
Section-Io-Origin-Status
Section-Origin-Responded
CacheControlHeader
Section-Io-Origin-Time-Seconds
Environment
X-Varnish-Beresp-Ttl
X-Via-CDN
X-Air-Pt
X-Vcl-Version
X-Dispatcher-Server
X-DPWN-IS-SECURE
X-Device-Os
X-Core-Value
X-Mly-Id
X-Cache-Tags
X-Cdn-Srv
X-Developers
X-FL-EDGE
Srvid
X-Ckpd-Fst-Backend
On-Server
Origin-CC
Origin-EX
X-Clara-WADP
Locid
X-FC-Vary-Parameters
X-Pool
X-GeoIP-Region-Code
X-GeoIP-Country-Code
X-Region-Sid
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-NodeID
X-Irp-Debug
X-Planisys-CDN-Cache
X-Geo-Header
X-Release
X-V-Cache
X-Varnishpool
X-WA-Info
X-WADP-Cache
X-Fastly-Cache
X-Fmm-Version
X-SB
X-Frame-Option
X-Forwarded-Site
X-Wix-Viewer-Type
X-Cache-FS-Status
Vix-Hermes-Req-Id
Web-Mar-Region
Producers
X-Accel-Buffering
Kp-EeAlive
X-VC
Datacenter
Ssr
State
CloudFront-Viewer-Country
X-Instance-Name
AKAMAI
X-App
X-FL-QIT-DEBUG
Edge-Copy-Time
X-Via-Edge
X-Via-SSL
X-Azure-Ref-OriginShield
X-Owner
NGX
X-Old-Content-Length
X-Hnp-Log
X-Varnish-Beresp-Status
X-VG-TLSProxy
Machine
PFcat
X-Platform-Server
X-Qloud-Router
X-Request-Start
X-HN
X-Gen-Mode
X-VarnishDD-TTL
L
X-From
Cache-Provider
X-Minions-Version
Wxu-Next-Hostname
X-Ua-Device
Canary
Server-Ext
Server-Hostname
Sever-Int
X-Aicache-OS
Wxu-Next-Commit
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
Apple-News-Services-Handled
X-Block-Status
User-Cache-Control
X-Nginx-Cache-Key
Wxu-Next-Region
Apple-News-Services-Host
X-Zone
X-Parent-Response-Time
X-Webkit-CSP-Report-Only
X-CACHE-AGE
X-Mvc-Supplant-OutputCached
X-Eu-Site
X-Nananana
CDCHOST
Fastly-SSL
Ha-Gx-Prefs
X-Op-Id-All
X-NCache
X-Cache-Remote
X-Csrf-Jwt
HA-Ipaddr
X-Cache-Enabled
L5d-Success-Class
X-CGP
X-Lambda-Id
X-Microcachable
X-LB-NoCache
X-Up
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-DC
X-RCS-CacheZone
X-Refresh
X-Correlation-ID
X-VCT
X-B3-Spanid
X-Cache-Backend
X-Via-Popv
X-Via-Poph
X-Tb-Optimization-Total-Bytes-Saved
Env
X-Via-Popn
Pics-Label
X-Dc
X-Trace-ID
X-B3-SpanId
VNS-Age
VNS-Cache
X-Vtex-Remote-Cache
CPC-Cache
X-Render-Time
CPC-Age
Decoy-Debug-Key
Decoy-Debug-Status
Cluster
X-Generated-In
GeoIP-Latitude
Decoy-Debug-TTL
X-Cached-By
X-ND-Cache
NtCoent-Length
X-Upstream-Ht
X-Upstream-Ct
AMP-Access-Control-Allow-Source-Origin
SID
X-HA-Backend
Sid
Cache
X-Webkit-CSP
X-NWS-UUID-VERIFY
X-Cache-Type
X-Cs
X-Tid
X-HS-Status
X-Hcs-Proxy-Type
X-Edge-Pop
Memory
X-CCDN-CacheTTL
X-CCDN-Origin-Time
Time
X-LB-ID
X-TH-Server
X-Servedbyhost
X-Nc
X-DataCenter
X-Wa
Fastly-Drupal-Html
X-AIR-PT
X-Presslabs-Stats
X-Esi
X-ATG-Version
Svr
X-Cache-ASPX
X-Contensis-Viewer-Groups
X-Client-Ip
Server-ID
X-Vgn-Hpd-Cached
X-Vgn-Hpd-Ssi
X-Varnish-Authentication
X-NewRelic-App-Data
X-Vgn-Hpd-Variations-Key
Srv
X-Via-JSL
Cdn
X-Srv
Uri
X-ZONE
GeoIp-Country-Code
X-Check-Cacheable
X-RateLimit-Limit-Second
X-MP-GENERATED-AT
X-RateLimit-Remaining-Second
X-Fpc
X-CF-Lambda-Fn
Esi-Enabled
X-CF-Lambda-Version
X-Proxy-CacheRZ
XkeyRZ
X-PAYTM-SRV-ID
X-CS
X-Amz-Meta-Cb-Modifiedtime
True-Client-IP
X-Vc
X-Udemy-Cache-App-Namespace
X-Nf-Request-Id
X-Wikidot-Static-Cache
M-TraceId
X-Wikidot-Backend
X-CACHE-KEY
X-Datadome
X-Varnish-Beresp-TTL
X-NGINX-Cache
Hostname
YJS-ID
XServer
Lb
Resin-Trace
X-CDN-Cache-Status
Cdnsip
X-AK-Request-ID
X-Tenant
Cdncip
True-Client-Ip
X-Gateway-Cache-Status
X-API-Version
X-Gateway-Skip-Cache
N-Cache
X-Bl-Debug
X-Forwarded-Path
RNT-Machine
X-Orig-Expires
X-Gateway-Request-Id
X-Gateway-Cache-Key
X-Shop-Environment
RNT-Time
X-CSRF-TOKEN
X-EC-Lua
X-Via-NSCOPI
X-TX-ID
X-FPC
X-MSEdge-Features
OT-Force-Account-Verify
X-MSEdge-Flight
X-Fastly-Country-Code
X-B3-Trace-ID
X-Policy
X-App-Name
Eomportal-Instance
X-Service-Response-Time
Sm-Log-Id
GeoIP-Country-Code
CDN
X-Logging-Id
X-Cache-Ttl
Server-Id
Path
X-Micro-Cache
Ngx-Var-Key
X-Accel-Version
X-APP-VERSION
X-WA
Hit
X-Vcache
X-CLOUD-TRACE-CONTEXT
X-Container-Uri
X-Git-Commit
X-Lb-Id
X-SIPLIST1
X-Cache-NGX
X-MCACHE
X-Edge-POP
X-VCL-Version
LB
X-NC
IsBot
X-Cdn-Diag
X-Datacenter
X-Request-URI
X-Ha-Backend
X-RateLimit-Reset
X-ServedByHost
HIT
X-Cdn-Cache-Status
X-Cdn-Forward
RATING
X-SERVER-NAME
X-Info
X-Tncms
Pramga
X-LiteSpeed-Cache-Control
X-Geo
Cross-Origin-Opener-Policy-Report-Only
Location
Geoip-Latitude
X-Srcache-Store-Status
FSS-Cache
Timeexpire
X-Acquia-Purge-Cdn-Unconfigured
X-Snapshot-Date
V-Age
X-Srcache-Fetch-Status
X-VG-WebCache
XM
X-TT-LOGID
Tcn
X-Akamai-Pragma-Client-IP
Req-ID
X-Ctl-Mach
CDN-RequestPullCode
X-Via-PopV
X-Via-PopN
X-Pod-Name
X-Via-PopH
CDN-RequestPullSuccess
True-Client-Country-4JS
Ohc-File-Size
Epwk-X-Cache
X-Lb-Nocache
X-Clientip
X-LiteSpeed-Tag
ENV
Yjs-Id
X-Wp-Cf-Super-Cache
X-Wp-Cf-Super-Cache-Cache-Control
X-HostName
X-Rebelmouse-Cache-Control
X-Iauth-Set-Uid
X-Rebelmouse-Surrogate-Control
X-Amz-Meta-Opti
X-Hyper-Cache
X-TRACE-ID
X-Serial
X-Dw-Trace-Id
X-M-Reqid
X-M-Log
Warning
X-Oss-Storage-Class
X-Fastly-Backend-Reqs
Content-Style-Type
X-Oss-Request-Id
X-Cdn-Request-ID
X-Oss-Server-Time
X-Oss-Object-Type
X-Cache-Expires
Proxy-Connection
X-UP
X-Oss-Hash-Crc64ecma
Content-Script-Type
X-RAMCache
X-Qnm-Cache
WZWS-RAY
Cneonction
W
X-Acquia-Application-Trace
Servername
X-Acquia-Purge-Tags
X-Acquia-Site
X-Acquia-Application-UUID
Ec-Rule-Version
X-MiniProfiler-Ids
CountryCode
X-Lsadc-Cache
X-Akamai-ERRuleID
X-Akamai-ERPolicy
PICS-Label
X-WP-CF-Super-Cache-Cookies-Bypass
Ohc-Cache-HIT
X-Webstats-RespID
X-B3-ParentSpanId
X-IPS-Cached-Response
MIME-Version
X-B3-Parentspanid
X-Fastly-Cache-Hits
X-Swift-Error
X-Mg-Cache
X-Litespeed-Cache-Control
Ngx
My-App
X-Th-Server