Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Accept-Ranges
X-XSS-Protection
Expect-CT
Pragma
X-Powered-By
CF-RAY
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-Xss-Protection
X-Download-Options
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
CF-Ray
X-Adblock-Key
Access-Control-Allow-Credentials
X-FRAME-OPTIONS
X-Request-ID
X-Request-Id
X-Permitted-Cross-Domain-Policies
X-AspNet-Version
Alt-Svc
X-Runtime
Content-Security-Policy-Report-Only
X-DNS-Prefetch-Control
X-Drupal-Cache
X-Check
X-Cache-Status
X-Generator
X-Cacheable
Timing-Allow-Origin
X-Iinfo
X-Envoy-Upstream-Service-Time
X-Content-Security-Policy
X-Drupal-Dynamic-Cache
Feature-Policy
Content-Encoding
Access-Control-Expose-Headers
Upgrade
Status
X-CDN
X-AspNetMvc-Version
P3p
Access-Control-Max-Age
X-Via
Server-Timing
X-UA-Device
X-Robots-Tag
Request-Context
X-Turbo-Charged-By
X-Cache-Group
EagleId
X-Amz-Request-Id
X-Amz-Id-2
X-Backend
X-AH-Environment
Keep-Alive
X-Proxy-Cache
X-Server
X-Ua-Compatible
X-Ws-Request-Id
X-Age
Host-Header
X-Hacker
Cf-Edge-Cache
X-Vhost
X-Server-Powered-By
X-Rq
X-Varnish-Cache
X-Dispatcher
Allow
X-Amz-Version-Id
Grace
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-OneAgent-JS-Injection
X-LiteSpeed-Cache
Accept-CH
X-WebKit-CSP
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Page-Speed
X-Device
Cf-Apo-Via
X-Dns-Prefetch-Control
Cf-Railgun
X-Aws-Lambda-Call-Status
X-Server-Id
X-Node
X-Host
X-Pingback
X-Cache-Spec
X-Nginx-Cache-Status
X-Akam-SW-Version
Surrogate-Control
EagleEye-TraceId
X-Backend-Server
Request-Id
X-Ruxit-JS-Agent
X-Readtime
X-Cache-Lookup
X-HW
X-Cloud-Trace-Context
X-Content-Security-Policy-Report-Only
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Trace
X-Application-Context
X-Response-Time
Permissions-Policy
Fastly-Restarts
X-Nginx-Upstream-Cache-Status
Accept-CH-Lifetime
X-Mod-Pagespeed
Accept-Ch-Lifetime
X-Edge
X-CST
X-WebKit-CSP-Report-Only
Content-Location
X-Content-Type
X-Mcache
X-MS-InvokeApp
X-Url
X-Clacks-Overhead
X-Country
Rating
X-Midtier
X-Amz-Server-Side-Encryption
X-TtlSet
X-Vname
X-PC
X-Litespeed-Cache
X-ECACHE
RTSS
X-VARITI-CCR
Cache-Tag
X-ESI
X-Vcap-Request-Id
X-D2id
X-Element-Page-Cache
Origin-Trial
X-Server-Name
Verso
X-Kinja-Revision
X-Exp-Id
X-Kinja-Build
X-GoogleNews-Bot
X-Kinja
X-Exp-Variant
X-Use-Magma
X-Cdn-Fetch
X-Kinja-Server
X-Ac
X-Rack-Cache
X-B3-TraceId
X-Varnish-TTL
X-Cnection
X-Powered-By-Plesk
Service-Worker-Allowed
X-GitHub-Request-Id
X-Cache-TTL
X-SharePointHealthScore
Xkey
SPRequestGuid
X-Ttl
X-Navigation-Version
X-Client-IP
X-Abt-Application-Version
X-Amz-Rid
Edge-Control
X-NWS-LOG-UUID
SPIisLatency
SPRequestDuration
X-Cached
Arr-Disable-Session-Affinity
X-Upstream
X-Browser-Type
X-Mg-S
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-Instrumentation
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Px
X-Cache-Key
X-Dw-Request-Base-Id
Display
Pagespeed
X-Middleton-Display
X-Sol
Content-MD5
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Correlation-Id
Access-Control-Request-Method
Edge-Cache-Tag
X-Goog-Hash
X-NF-Request-ID
X-Country-Code
Front-End-Https
X-Forwarded-For
X-Version
X-Daa-Tunnel
X-XRDS-Location
TCN
X-Id
X-Powered-CMS
Public-Key-Pins
AR-SID
AR-ATIME
AR-Request-ID
AR-PoweredBy
AR-CACHE
X-HP-Trace-Id
X-Fastcgi-Cache
X-HP-Webp
X-Jurisdiction
X-Recruiting
X-T
X-MSEdge-Ref
X-Content-Digest
X-RateLimit-Remaining
X-Accel-Expires
X-Middleton-Response
Response
X-Ser
TP-Cache
X-Amzn-Trace-Id
X-Shield-Request-Id
TP-L2-Cache
X-B3-TraceId-Primal
Mrf-Cache-Status
MRF-Tech
X-FastCGI-Cache
Nginx-Cache
S
X-Webkit-Csp
X-Request-Received
X-Ratelimit-Limit
X-Request-Processing-Time
MicrosoftSharePointTeamServices
X-HS-Combine-CSS
X-HS-Content-Id
Server-Node
X-HS-Cache-Config
X-HS-Hub-Id
Cache-Status
X-Distributor
X-Hits
Cache-Tags
X-Edge-Location-Klb
X-Kinsta-Cache
Fastcgi-Cache
X-Grace
X-Fastly-Request-ID
X-Ratelimit-Remaining
Server-Name
Alternate-Protocol
X-Ezoic-Cdn
X-LB-Cache
X-Origin-Server
X-DIS-Request-ID
X-Ua-Browser
X-Geo-Country
X-DataDome
X-Protected-By
X-Ratelimit-Reset
Cross-Origin-Opener-Policy
X-Microsite
X-Request-Handler-Origin-Region
Filterid
X-Rid
X-Frontend
Healthy
X-Varnish-Backend
X-Logged-In
X-Git-Hash
X-Www-Served-By
Payment
Cleartype
X-FB-Debug
X-Debug-Info
X-Forwarded-Proto
X-Page-Id
X-NGENIX-Cache
X-Load-Cache
X-LLID
X-Hostname
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-ASPNET-VERSION
X-TEC-API-VERSION
X-Origin-Cache
Charset
X-Cluster-Name
DC
X-Ruxit-Js-Agent
Content-Disposition
X-TTL
X-B3-Sampled
X-PressLabs-Stats
MS-Author-Via
X-GUploader-UploadID
X-Goog-Metageneration
Accept-Ch
X-VCache
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
X-Kong-Upstream-Latency
Access-Control-Allow-Method
X-Kong-Proxy-Latency
X-Upgrade-Enabled
X-Proxy
Realpath
X-F-Cache
Retry-After
X-AppVersion
X-Activity-Id
X-Az
Cross-Origin-Resource-Policy
X-Amz-Replication-Status
X-Seen-By
Paypal-Debug-Id
X-Contextid
Accept-Charset
X-Type
X-Amz-Meta-S3cmd-Attrs
X-B-Cache
X-Revision
X-Signature
X-Request-Guid
X-Providence-Cookie
X-Hosted-By
X-Whom
X-Fb-Rlafr
X-Flags
X-Aspnet-Duration-Ms
X-Is-Crawler
Viewport
X-Azure-Ref
X-Route-Name
X-Aspnetmvc-Version
X-Varnish-Server
Surrogate-Key
X-Wix-Request-Id
Count-Hit
X-App-Environment
X-TT
X-B
X-DynaTrace
X-Akamai-Edgescape
X-Oracle-Dms-Rid
X-Oracle-Dms-Ecid
X-Language
Amp-Access-Control-Allow-Source-Origin
X-Source
Referer-Policy
X-App-Server
X-Mobile
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Goog-Generation
X-Cache-Control
X-Tt-Trace-Tag
X-Template
X-B3-Traceid
X-Tt-Trace-Host
X-COUNTRY
X-RateLimit-Limit
X-Magnolia-Registration
Host
X-Varnish-Grace
Version
X-N
X-EdgeConnect-Cache-Status
X-HTML-Minification-Powered-By
X-Cache-Rule
X-Cache-Age
X-Tumblr-User
X-Tumblr-Pixel-1
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Response-Served-From
X-Original-Request-Id
MS-CV
Ms-Operation-Id
X-Cache-Time
X-Varnish-Age
X-UUID
X-RTag
X-Rule
VIX-Pulpo-Node
Section-Io-Cache
VIX-Pulpo-Upstream-Status
X-Cache-Expired-At
X-Content-Powered-By
X-Cache-Status-Check
SD-X-WS
Access-Control-Request-Headers
X-Framework
X-Trace-Id
X-Envoy-Decorator-Operation
X-Adobe-Content
X-Adobe-Loc
Akamai-GRN
X-RemovedCookies
X-Cacheable-TTL
X-FW-Static
X-FW-Server
X-ProcessESI
X-FW-Type
X-User-Agent
X-Page-View
X-FW-Version
X-FW-Hash
X-FW-Serve
X-Cache-Grace
X-Device-Type
X-Backend-Name
X-FW-Dynamic
X-G
X-Instance
X-Is-Bot
X-L-Path
X-Jobs
Url
X-Environment-Context
NGB
Refresh
GEO-INFO
Protected
X-NYM-Debug-Backend
X-Rendered-As
X-Servername
X-Status
SRV
X-Http-Reason
X-Akamai-Request-ID2
X-Drupal-Cache-Contexts
X-Drupal-Cache-Tags
X-CDN-Forward
From-Origin
X-Debug-IsConnected
WPO-Cache-Status
WPO-Cache-Message
X-Debug-IsPreview
X-Fastly-Request-Id
X-Region
CDN-RequestId
Front
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Cache-Hit
Accept-Language
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Tec-Api-Version
X-Tec-Api-Root
X-Tec-Api-Origin
Country
X-Times
X-Tb
X-ECache
X-Nginx-Cache
Backend
X-Unique-Id
X-Content-Options
X-Node-Name
X-Newrelic-App-Data
Fastly-SIE
Fastly-SWR
X-Tt-Logid
Pinterest-Version
X-Zen-Fury
Pinterest-Generated-By
X-Pinterest-Rid
X-Real-IP
X-Mode
X-Air-Trace-Id
X-Air-Source
X-DynaTrace-JS-Agent
X-Air-Hostname
X-Cache-Operation
Uber-Trace-Id
X-VC-Cache
Content-Secure-Policy
Fastly-Drupal-HTML
X-Buckets
Filters
Webserver
Meta-Geo
X-Amzn-Remapped-Content-Length
X-Generation-Time
X-Rewrite-Enabled
X-Ms-Version
X-Proxy-Cache-Info
X-RN-RSRV
X-UPSTREAM-Address
X-Ms-Request-Id
X-Tumblr-Pixel-2
X-Cache-Server
X-Section
X-Access
X-Reqid
Azure-InstanceId
X-IPS-LoggedIn
Onion-Location
Azure-Version
X-TIME
Azure-SlotName
Azure-SiteName
Azure-RegionName
X-Format
Cache-Hits
X-Content-Age
X-Rocket-Nginx-Serving-Static
CF-IPCountry
X-Time
X-R9-Blue-Green-Version
X-ProxyCache-Status
TWC-GeoIP-Country
X-Sql-Duration-Ms
X-Sql-Count
ServedBy
TWC-Device-Class
Property-Id
X-Server-W
X-Soup
TWC-Connection-Speed
Webcakes-App-Name
X-Locale
X-BYPASS-REASON
X-AWS-Id
X-Origin-Hint
X-PHP-Backend
X-LJ-Flow-ID
X-Debug
X-Cache-TTL-Remaining
X-Cluster
X-Cluster-Node
X-Cms-Context
X-Proto
X-Proxy-Cache-Status
X-Ua
TWC-Privacy
TWC-Locale-Group
TWC-GeoIP-LatLong
X-UA-Device-Type
Webcakes-App-Version
X-Web-Node
X-VWS-Id
X-Adobe-Source
X-Via-Fastly
X-ProxyCache-Key
Webcakes-Region
Liferay-Portal
Node
X-URL
X-Cache-Host
X-Forwarded-Host
X-Labrador-Cache-Channel
X-Varnish-Beresp-Grace
S-Rt
ServerID
DB-Nickname
X-No-Session
X-Say-Cacheable
X-PHP-Host
Apigw-Requestid
X-Skip-Cache
X-Sucuri-Cache
X-Sucuri-ID
Web-Mar-Node
X-Say-TTL
X-SayCDN-TTL
X-Handled-By
Cache-Name
X-LSADC-Cache
X-Proxied
X-Proxy-Build
X-JoinUs
X-Cache-Action
X-GeoCountry
Selected-Fe
X-Timing-Wait
X-Extlb
Mn-Server-Ip
X-FB-TRIP-ID
X-Xfnlog-Site
X-Site-Version
X-GeoCode
X-SaId
X-Edge-Location
X-Server-ID
X-Zipkin-Id
Cross-Origin-Window-Policy
X-Detected-As
X-Routing-Service
X-IPLB-Instance
X-IPLB-Request-ID
X-WP-CF-Super-Cache-Cache-Control
WP-Super-Cache
X-Webkit-CSP
Locale
X-Urbn-Context-Path
X-WP-CF-Super-Cache
X-Urbn-Site-Id
X-LAGOON
Mime-Version
Fastcgi-Useragent
CDN-EdgeStorageId
CDN-RequestCountryCode
CDN-PullZone
CDN-CachedAt
CDN-Uid
CDN-Cache
X-Tumblr-Pixel-3
X-SRV
X-XRDS-LOCATION
X-Origin-Date
X-Hl-Ver
X-Optimistic-Header
Source
CF-Cached-On
X-Oneagent-Js-Injection
X-Uri
X-Request-Time
X-Cache-Debug
Countrycode
Upgrade-Insecure-Requests
X-App-Version
X-Varnish-Hits
X-Mg-Request-UUID
X-Director
X-Generated-By
X-Loop
X-ARC
X-TNCMS
X-Redis-Cache
Xet-Cookie
X-CACHE-AGE
X-Akamai-Transformed
X-GEO
X-Webkit-CSP-Report-Only
Cache-Tv-Group
X-Origin-TTL
X-Origin-CC
Xserver
X-Pass-Why
Frame-Options
X-Presslabs-Stats
X-FireWall-Port
X-Tx-Id
X-Varnish-Beresp-Ttl
X-NWS-UUID-VERIFY
X-Varnish-Ttl
X-Varnish-Cache-Hits
X-Service
X-Sorting-Hat-ShopId
X-Storefront-Renderer-Rendered
X-Varnish-Hostname
X-Sorting-Hat-PodId
X-ShardId
X-Shopify-Stage
X-Alternate-Cache-Key
X-ShopId
X-ServerID
X-Newrelic-Synthetics
X-RM-Cache-TTL
X-Datadog-Parent-Id
X-Datadog-Trace-Id
X-Datadog-Sampled
X-Datadog-Sampling-Priority
X-Storage
X-Tid
X-Endurance-Cache-Level
Redirect-Candidate
Release
Req-Svc-Chain
X-Mobile-URL
Rendered-Blocks
X-Conf
X-Epic-Correlation-Id
Environment
X-External-Request-Id
X-CMSURLCustom
X-We-Are-Hiring
Gannett-Cam-Experience-Id
Surrogated-Key
X-Cache-Info
T-Server
TDXMobile
X-Nyt-Route
X-Generated-On
X-Core-Value
X-Cache-NE
Sslversion
Candidate-Md5Url
X-Mid
X-Ec-Fail
X-Destination
X-Httpd
Ngx.Var.Host
Meta-Geo-Continent
X-Developer
Lang
A
MD5-Digest
Memcached
X-INCAP-ABP
BehaviorPad-Version
X-Loc
X-Location
Host-ID
Xc-Version
X-D
X-Level-Front-Cache
Odigeo-Trace-Id
X-Ec-GeoHdr
Origin
Cache-Host
Thinkindot-CacheControl
X-VG-TLSProxy
X-S-Maxage
X-TA-CDN-Provider
X-A-Ccd
X-A-Dam
X-TIM-N
X-A
X-Application
X-S-Cookie
X-Frame-Option
WWW-Authenticate
DCR-Decision-By
X-Thinkindot-L3
X-A-Dcw
X-Aed
X-Sigma-Backend
X-Sigma
X-Served-From
X-SRCache-Key
DCR-Processing-Time-Ms
X-Test
X-A-Dgt
X-A-Wwc
X-ScT
Thinkindot-CacheControl-Type
X-S
X-BCube-Filmed-By
X-Vdms-Version
X-Vdms-Path
X-Platform-Router
X-Platform-Processor
Thinkindot-Control
X-Origin-Time
X-Platform-Cluster
X-Processor
Edge-Cache
X-BBC-Edge-Cache-Status
X-Rocket-Build-Number
X-Rojux
X-Bc-Bl
X-B-Cookie
X-Gdpr
X-B3-Spanid
X-Pubstack
X-Fetched-On
X-Ec-Custom-Error
X-Developers
Decoy-Debug-Status
X-Fmm-Version
Gh-Request-Id
DSUID
Decoy-Debug-TTL
Fastly-Backend-Name
Fastly-GeoIP-CountryCode
X-Cdn-Srv
Tube-Get-Contents
Tube-Got-Eval
X-Bip
X-Cache-Bucket
State
Tube-Got-Results
Tube-Return
X-Akamai-Device-Characteristics
X-Auto-Login
We-Hiring
Vix-Hermes-Req-Id
Ssr
Server-Info
X-DefHash
X-DefElseHash
NM-Fastcgi-Cache
NGX
Mail-Subject
X-CUA
X-Core-Mission
X-Cdn-Origin
Server-Host
Decoy-Debug-Key
X-Clara-WADP
Magicmarker
CacheControlHeader
X-Restarts
X-JWT-State
X-Cache-Date
X-Req
X-WP-CF-Super-Cache-Active
X-Is-Gdpr
X-HS-Content-Campaign-Id
X-Has-Esi
X-Hash
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-Worker
X-DC
X-VServer
X-Old-Content-Length
X-Origin-Response-Time
X-Vmg-Version
X-Org
X-NodeID
X-WA-Info
X-Pool
X-WADP-Cache
X-Request-Host
X-Platform-Server
X-Varnish-Beresp-Status
X-Varnish-Remaining-TTL
X-SVT-ORM-VERSION
X-Thanos
Click-Count-Error
C-Via
Click-Count-Action-Start
X-SD-PageType
X-Geo-Header
X-SVT-ORM-RULES
X-GeoIP
X-GeoIP-City
Apple-News-Services-Request-Url
Cache-Key
Apple-News-Services-Host
Country-Code
Apple-News-Services-Handled
AKAMAI
Cluster
X-Sn-Servicetimems
CloudFront-Viewer-Country
Apple-News-Services-Parsed-Url
X-SB
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
X-Parent-Response-Time
Section-Io-Id
Section-Origin-Responded
X-Block-Status
X-Cache-Backend
X-Cache-Id
X-Qloud-Router
X-Origin
X-Azure-Ref-OriginShield
X-Var-Ttl
X-Variation
X-VarnishDD-TTL
X-Request-Start
X-Scale
X-App
X-Region-Sid
X-Varnishpool
X-Platform
X-Nginx-Cache-Key
X-GeoIP-Region-Code
X-Device-Os
X-Gzip
X-HN
X-Human
X-Hnp-Log
X-Dispatcher-Server
X-DPWN-IS-SECURE
X-FC-Vary-Parameters
X-Gen-Mode
X-Fastly-Backend
X-Esi-Check
X-GeoIP-Country-Code
X-Irp-Debug
X-LB-NoCache
X-CacheTTL
X-Ckpd-Fst-Backend
X-Cache-Tags
X-Node-Id
X-Ad-Defer-Variation
X-Gamma-Serve
X-NCache
X-Date
X-Mvc-Supplant-Cachable
X-Men
X-Minions-Version
X-Wix-Viewer-Type
X-Op-Id-All
X-Accel-Buffering
Platform
Origin-CC
Cmstype
Cmsid
Pics-Label
Sever-Int
L
Server-Hostname
Server-Ext
Is-Eu
Producers
Datacenter
CDCHOST
Canary
PFcat
Wxu-Next-Region
Machine
On-Server
Origin-EX
Wxu-Next-Hostname
Wxu-Next-Commit
Adler-Geo
Cache-Provider
X-Accel-Expires-Debug
User-Cache-Control
Web-Mar-Region
X-Dispatcher-Number
HA-Ipaddr
Kp-EeAlive
X-Server-IP
Load-Balancing
X-Mly-Id
X-Nananana
X-Up
X-V-Cache
X-Slack-Shared-Secret-Outcome
X-Slack-Backend
X-Eu-Site
Fastly-SSL
X-Forwarded-Site
X-Owner
Ha-Gx-Prefs
L5d-Success-Class
X-Refresh
X-CGP
X-Cache-Remote
X-AIR-PT
X-Csrf-Jwt
X-Cache-FS-Status
X-CSRF-Token
SID
Svr
X-Planisys-CDN-Cache
X-Microcachable
X-Api-Version
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-Mvc-Supplant-OutputCached
X-Servedbyhost
X-Aicache-OS
HostName
GeoIP-Latitude
X-Tb-Optimization-Total-Bytes-Saved
X-Fastly-Cache
X-Correlation-ID
X-Origin-Expires
X-Via-Popv
X-Via-Poph
X-Via-Popn
X-ND-Cache
X-Instance-Name
X-RCS-CacheZone
Env
X-Trace-ID
X-VC
X-NGINX-Cache
X-HA-Backend
X-Response-By
X-Cached-By
Time
Memory
X-Release
X-Nc
X-HS-Status
X-Zone
Cdn
X-NewRelic-App-Data
X-FL-QIT-DEBUG
X-FL-EDGE
X-Generated-In
Server-ID
X-Wa
Expect-Staple
X-From
Srvid
Locid
Cache
X-ZONE
X-Provided-By
X-Edge-Pop
Cdnsip
X-DataCenter
Cdncip
X-Cache-Enabled
X-Via-CDN
X-AK-Request-ID
NtCoent-Length
X-Vc
X-Via-SSL
X-Gateway-Request-Id
X-Via-Edge
X-Esi
Edge-Copy-Time
X-Via-NSCOPI
X-Fpc
X-Gateway-Cache-Key
X-Gateway-Cache-Status
X-Gateway-Skip-Cache
X-Nf-Request-Id
AMP-Access-Control-Allow-Source-Origin
X-Check-Cacheable
X-Dc
X-Hcs-Proxy-Type
X-CCDN-Origin-Time
X-CCDN-CacheTTL
X-Air-Pt
X-LB-ID
X-Vcl-Version
X-Client-Ip
X-API-Version
Hostname
X-Lambda-Id
X-Vgn-Hpd-Variations-Key
X-Vgn-Hpd-Ssi
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-Vgn-Hpd-Cached
GeoIp-Country-Code
X-Srv
Sid
X-CS
X-CSRF-TOKEN
Eomportal-Instance
X-Proxy-CacheRZ
XkeyRZ
X-MCACHE
X-Vtex-Remote-Cache
X-Via-JSL
X-Amz-Meta-Cb-Modifiedtime
X-Micro-Cache
VNS-Age
VNS-Cache
CPC-Cache
Ngx-Var-Key
True-Client-IP
X-Render-Time
CPC-Age
X-Cs
X-B3-SpanId
X-APP-VERSION
Srv
True-Client-Ip
X-VCT
IsBot
Path
X-TH-Server
X-Request-URI
X-SIPLIST1
OT-Force-Account-Verify
X-EC-Lua
X-Fastly-Country-Code
X-VCL-Version
X-Info
X-Cache-NGX
Uri
X-ATG-Version
Fastly-Drupal-Html
X-Contensis-Viewer-Groups
X-Upstream-Ht
X-Upstream-Ct
Esi-Enabled
X-Cache-ASPX
X-Varnish-Authentication
X-MSEdge-Flight
X-MSEdge-Features
Request-ID
X-Cache-Type
GeoIP-Country-Code
Resin-Trace
Location
M-TraceId
X-TX-ID
X-Datadome
X-CLOUD-TRACE-CONTEXT
X-CF-Lambda-Fn
X-CF-Lambda-Version
CDN
X-Cdn-Request-ID
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-PAYTM-SRV-ID
YJS-ID
X-Udemy-Cache-App-Namespace
X-Lb-Id
X-FPC
X-Oss-Server-Time
Cross-Origin-Opener-Policy-Report-Only
X-Varnish-Beresp-TTL
X-Accel-Version
X-Cache-Expires
X-Oss-Request-Id
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
X-Oss-Storage-Class
XServer
X-Wikidot-Static-Cache
Sm-Log-Id
X-Edge-POP
X-CDN-Cache-Status
RNT-Machine
RNT-Time
N-Cache
Servername
X-Service-Response-Time
X-Datacenter
X-Pod-Name
X-Wikidot-Backend
X-Akamai-Pragma-Client-IP
X-Forwarded-Path
X-Tenant
X-Shop-Environment
Timeexpire
X-Orig-Expires
X-Bl-Debug
X-MP-GENERATED-AT
X-RateLimit-Reset
HIT
LB
X-Geo
X-Scheme
X-SERVER-NAME
Traceparent
X-WA
X-Cdn-Cache-Status
X-Moov-Xdn-Version
X-Moov-T
Server-Id
X-B3-Trace-ID
X-Xrds-Location
X-Policy
X-App-Name
ENV
FSS-Cache
X-Srcache-Fetch-Status
X-Viewer-Country
X-Ha-Backend
Ohc-File-Size
X-Srcache-Store-Status
X-CACHE-KEY
X-ApacheServer
X-PERF
X-NC
CountryCode
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-Via-PopN
X-LiteSpeed-Cache-Control
X-TraceId
X-Via-PopV
Yjs-Id
X-Via-PopH
Proxy-Connection
Epwk-X-Cache
X-ServedByHost
X-Snapshot-Date
X-Amz-Meta-Opti
X-TimeS
X-NAPM-TraceId
X-Serial
X-Dw-Trace-Id
Geoip-Latitude
Cneonction
WZWS-RAY
X-Cdn-Forward
Powered-By
X-Hyper-Cache
X-MiniProfiler-Ids
X-M-Log
X-M-Reqid
X-Lb-Nocache
Content-Script-Type
Content-Style-Type
X-Qnm-Cache
X-Acquia-Site
X-Vgn-Hpd-Reason
Cdn-Requestid
X-RAMCache
Hit
X-B3-Parentspanid
Lb
X-Acquia-Application-UUID
X-Acquia-Purge-Tags
Ec-Rule-Version
X-Fastly-Backend-Reqs
User-Agent
X-Acquia-Application-Trace
X-Swift-Error
X-Miniprofiler-Ids
X-Lsadc-Cache
X-Wp-Cf-Super-Cache-Cache-Control
X-Iplb-Instance
X-Iplb-Request-Id
X-Wp-Cf-Super-Cache
X-TT-LOGID
X-F-Status
V-Age
ServerName
Req-ID
X-Cdn-Diag
X-Ctl-Mach
X-Fastly-Cache-Hits
X-Webstats-RespID
X-Th-Server
Inserted-Into-Cache-At
X-Request-URL
X-Mid-Debug-Cache-Key
Warning
X-UP
X-B3-ParentSpanId
X-IPS-Cached-Response
X-Cache-Ngx
MIME-Version
My-App
X-Clientip
Rip
Tracecode
Ngx
X-Stale
X-Mid-Debug-Cache-Disk
X-LiteSpeed-Tag
True-Client-Country-4JS