Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
Strict-Transport-Security
X-Frame-Options
X-Content-Type-Options
Last-Modified
Link
CF-Cache-Status
Cf-Request-Id
Accept-Ranges
ETag
CF-RAY
Expect-CT
Pragma
X-Powered-By
X-Cache
Via
X-XSS-Protection
Age
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Amz-Cf-Pop
X-Xss-Protection
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-FRAME-OPTIONS
X-Download-Options
X-Timer
X-Request-Id
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-Adblock-Key
X-AspNet-Version
X-Permitted-Cross-Domain-Policies
X-Runtime
Alt-Svc
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Cache-Status
CF-Ray
X-Generator
X-Cacheable
X-Iinfo
Timing-Allow-Origin
X-Request-ID
X-Envoy-Upstream-Service-Time
Feature-Policy
Status
X-Content-Security-Policy
X-Drupal-Dynamic-Cache
Content-Encoding
X-AspNetMvc-Version
Access-Control-Expose-Headers
X-CDN
Upgrade
X-XSS-PROTECTION
X-Ua-Compatible
Access-Control-Max-Age
X-Via
X-Cache-Group
Server-Timing
X-Robots-Tag
X-UA-Device
Request-Context
X-Dns-Prefetch-Control
Keep-Alive
X-AH-Environment
X-Amz-Request-Id
X-Turbo-Charged-By
X-Proxy-Cache
X-Backend
X-Amz-Id-2
X-Ws-Request-Id
P3p
X-Age
Host-Header
X-Server-Powered-By
X-Hacker
X-Server
X-Rq
X-Vhost
EagleId
X-Varnish-Cache
Grace
X-Amz-Version-Id
X-LiteSpeed-Cache
X-Dispatcher
X-Akamai-Path-Stats
Cf-Edge-Cache
Allow
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-Device
X-WebKit-CSP
X-Nginx-Cache-Status
X-Page-Speed
X-Aws-Lambda-Call-Status
X-Host
X-Node
X-OneAgent-JS-Injection
X-Pingback
Accept-CH
X-Server-Id
EagleEye-TraceId
X-Cache-Spec
Request-Id
Cf-Railgun
Surrogate-Control
X-Akam-SW-Version
X-Backend-Server
X-Cache-Lookup
X-Response-Time
X-Readtime
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Accept-CH-Lifetime
X-HW
Content-Location
X-Content-Security-Policy-Report-Only
X-Application-Context
X-Trace
Rating
X-Cloud-Trace-Context
Fastly-Restarts
X-Country
X-WebKit-CSP-Report-Only
X-Clacks-Overhead
X-Url
Accept-Ch-Lifetime
X-MS-InvokeApp
X-Edge
X-Amz-Server-Side-Encryption
X-Rack-Cache
Edge-Control
X-TtlSet
X-PC
X-Vname
X-B3-TraceId
X-Nginx-Upstream-Cache-Status
X-Ruxit-JS-Agent
X-Content-Type
X-ESI
X-Vcap-Request-Id
X-Mod-Pagespeed
X-Varnish-TTL
X-FastCGI-Cache
Xkey
X-Exp-Id
X-Cdn-Fetch
X-Kinja
X-Kinja-Server
X-Kinja-Revision
X-Kinja-Build
X-D2id
X-GoogleNews-Bot
X-Exp-Variant
X-Use-Magma
X-Amz-Rid
Verso
X-GitHub-Request-Id
Cache-Tag
X-VARITI-CCR
X-Powered-By-Plesk
RTSS
X-Ruxit-Js-Agent
X-Mcache
X-CST
Service-Worker-Allowed
X-ECACHE
X-Oneagent-Js-Injection
X-Upstream
X-Navigation-Version
X-Client-IP
X-Abt-Application-Version
X-Version
Accept-Ch
X-Cached
X-Dw-Request-Base-Id
X-Cnection
X-Px
X-Ac
Public-Key-Pins
X-Element-Page-Cache
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-Instrumentation
SPRequestGuid
X-SharePointHealthScore
Arr-Disable-Session-Affinity
X-Server-Name
SPRequestDuration
SPIisLatency
X-Cache-TTL
X-Middleton-Display
X-Sol
Pagespeed
Display
X-Ser
X-NWS-LOG-UUID
X-Country-Code
X-Ttl
Permissions-Policy
X-RateLimit-Remaining
X-Midtier
X-Cache-Key
X-Middleton-Response
Response
X-Kinsta-Cache
X-Edge-Location-Klb
X-Goog-Hash
X-NF-Request-ID
X-Forwarded-For
Access-Control-Request-Method
Content-MD5
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-DataDome
X-Shield-Request-Id
Front-End-Https
X-MSEdge-Ref
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
X-Correlation-Id
X-Recruiting
X-T
Nginx-Cache
X-HP-Trace-Id
X-Jurisdiction
X-HP-Webp
TP-L2-Cache
TP-Cache
Edge-Cache-Tag
X-Accel-Expires
AR-Request-ID
AR-SID
AR-PoweredBy
AR-CACHE
AR-ATIME
X-Powered-CMS
MicrosoftSharePointTeamServices
X-Daa-Tunnel
X-RateLimit-Limit
MRF-Tech
Mrf-Cache-Status
X-B3-TraceId-Primal
TCN
X-Grace
X-Id
X-Mg-S
X-Hits
X-Content-Digest
X-Request-Processing-Time
X-Request-Received
Filters
Server-Node
Cf-Apo-Via
X-HS-Cache-Config
X-HS-Content-Id
X-HS-Combine-CSS
X-HS-Hub-Id
Server-Name
X-Amzn-Trace-Id
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Frontend
S
X-Distributor
X-LLID
MS-Author-Via
X-Protected-By
X-Geo-Country
Fastcgi-Cache
X-Language
Cache-Status
X-TTL
X-LB-Cache
X-PressLabs-Stats
X-Origin-Server
Cross-Origin-Opener-Policy
X-Amz-Meta-S3cmd-Attrs
X-Fastly-Request-Id
X-Ezoic-Cdn
X-Request-Handler-Origin-Region
X-Microsite
Charset
X-B3-Sampled
Host
X-FB-Debug
X-F-Cache
Count-Hit
X-Forwarded-Proto
X-XRDS-Location
X-Page-Id
X-Seen-By
X-Ab
X-Browser-Type
X-Erf-Bev-Bev-Is-Generated
X-Ua-Browser
X-Git-Hash
X-Erf-Bev-Bev
Payment
Filterid
X-ASPNET-VERSION
X-Ratelimit-Reset
X-Cluster-Name
X-VCache
Realpath
Surrogate-Key
X-Cache-Age
Cache-Tags
X-Template
X-Rid
Accept-Charset
X-Origin-Cache
Alternate-Protocol
X-Webkit-Csp
X-NGENIX-Cache
Retry-After
X-DynaTrace
X-Www-Served-By
Access-Control-Allow-Method
X-Fastcgi-Cache
X-AppVersion
X-Activity-Id
X-Az
Cleartype
X-Varnish-Backend
X-Amz-Replication-Status
X-Upgrade-Enabled
X-Providence-Cookie
X-Type
X-DIS-Request-ID
X-Is-Crawler
X-Flags
X-Logged-In
X-Request-Guid
X-TT
X-Varnish-Grace
X-Aspnet-Duration-Ms
X-Route-Name
X-Signature
X-Tb
X-B
X-Node-Name
X-Wix-Request-Id
X-B-Cache
X-App-Environment
ServerID
Paypal-Debug-Id
DC
X-Envoy-Decorator-Operation
X-Debug
X-Drupal-Cache-Tags
X-Proxy
X-Fastly-Request-ID
X-Hostname
X-Source
Frame-Options
X-Content-Options
X-Revision
X-Mobile
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Content
X-Load-Cache
X-Contextid
Pinterest-Version
Pinterest-Generated-By
X-Pinterest-Rid
Amp-Access-Control-Allow-Source-Origin
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Cache-Rule
X-GUploader-UploadID
X-Goog-Metageneration
X-Goog-Storage-Class
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Cache-Control
Country
X-N
X-Magnolia-Registration
X-Litespeed-Cache
X-User-Agent
X-Whom
Node
X-EdgeConnect-Cache-Status
Referer-Policy
X-Response-Served-From
X-Original-Request-Id
Refresh
Viewport
NGB
Content-Disposition
X-Cacheable-TTL
X-Environment-Context
X-L-Path
X-Debug-IsPreview
X-Debug-IsConnected
Access-Control-Request-Headers
X-Ratelimit-Remaining
X-Cache-TTL-Remaining
Url
X-Varnish-Server
X-Yottaa-Metrics
X-Jobs
X-Yottaa-Optimizations
X-NYM-Debug-Backend
X-Page-View
X-Servername
X-Unique-Id
X-Varnish-Age
X-G
X-Framework
X-Adobe-Content
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
Uber-Trace-Id
X-Adobe-Loc
X-Akamai-Request-ID2
X-Cache-Time
Akamai-GRN
X-Status
X-Rendered-As
X-Content-Powered-By
X-Mid
X-Cache-Grace
X-Is-Bot
X-Real-IP
X-Instance
X-Server-ID
Srv
X-ProcessESI
X-RemovedCookies
X-Mg-Request-UUID
X-Drupal-Cache-Contexts
X-Restarts
X-COUNTRY
Version
X-APP-VERSION
Countrycode
X-App-Server
X-Http-Reason
X-Trace-Id
X-CDN-Forward
X-XRDS-LOCATION
Accept-Language
X-Debug-Info
X-Cache-Expired-At
Protected
X-IPLB-Request-ID
X-IPLB-Instance
X-Time
Healthy
X-Hosted-By
X-Via-JSL
X-Cache-Hit
X-Tumblr-User
X-Ratelimit-Limit
X-Tumblr-Pixel-1
X-Tumblr-Pixel
X-Nginx-Cache-Key
X-Tumblr-Pixel-0
Liferay-Portal
X-Azure-Ref
X-Cache-Operation
X-Device-Type
X-FW-Hash
X-FW-Server
X-FW-Type
X-Backend-Name
X-FW-Serve
X-FW-Dynamic
X-Tt-Logid
X-FW-Static
Section-Io-Cache
X-Oracle-Dms-Ecid
X-Oracle-Dms-Rid
Fastcgi-Useragent
Backend
Content-Secure-Policy
X-Cache-NGX
Server-Info
Ms-Operation-Id
X-Akamai-Edgescape
Cross-Origin-Resource-Policy
MS-CV
X-Proxy-Cache-Status
X-RTag
X-UUID
Load-Balancing
X-Storage
X-UPSTREAM-Address
X-Mobile-URL
Meta-Geo
X-RN-RSRV
X-Mode
X-Cache-Action
CF-IPCountry
X-Handled-By
X-Content-Age
GEO-INFO
X-PHP-Backend
X-PCL
Locale
Onion-Location
TWC-Device-Class
Eomportal-Instance
X-VC-Cache
X-No-Session
X-OCL
TWC-Connection-Speed
X-LJ-Flow-ID
S-Rt
Property-Id
X-Origin-Hint
X-Server-W
X-Sql-Duration-Ms
X-Sql-Count
Webcakes-App-Name
X-Storefront-Renderer-Rendered
X-Cms-Context
TWC-Privacy
X-Shopify-Stage
X-Edge-Location
X-Sorting-Hat-ShopId
Webcakes-Region
X-Skip-Cache
X-Locale
X-Site-Version
X-Sorting-Hat-PodId
X-Adobe-Source
X-Cache-Server
X-AWS-Id
X-Access
TWC-Locale-Group
TWC-GeoIP-LatLong
TWC-GeoIP-Country
X-Say-Cacheable
X-Say-TTL
X-VWS-Id
X-Varnish-Beresp-Grace
X-Format
X-Proto
X-Region
X-SayCDN-TTL
X-Section
X-Urbn-Site-Id
X-Urbn-Context-Path
X-ShopId
X-Varnish-Cache-Hits
X-ShardId
X-Alternate-Cache-Key
X-Varnishpool
X-Varnish-Hostname
X-Forwarded-Host
Webcakes-App-Version
X-Rule
X-URL
X-ProxyCache-Key
X-Proxy-Build
X-Proxied
X-Origin-Date
X-ProxyCache-Status
X-Request-Time
X-Datadome
X-ServerID
X-Routing-Service
X-HTML-Minification-Powered-By
X-Hl-Ver
X-Extlb
X-Detected-As
X-Cache-Type
X-Cache-Host
X-FB-TRIP-ID
X-Generated-By
X-GeoCountry
X-GeoCode
X-Generation-Time
X-Timing-Wait
X-UA-Device-Type
X-Redis-Cache
X-PHP-Host
X-Labrador-Cache-Channel
X-Cache-Enabled
X-Uri
Azure-InstanceId
Azure-SiteName
Azure-RegionName
Azure-Version
CDN-RequestId
CDN-RequestCountryCode
X-Xfnlog-Site
X-Web-Node
X-Via-Fastly
X-BYPASS-REASON
X-Zipkin-Id
CDN-Cache
CDN-PullZone
CDN-EdgeStorageId
CDN-CachedAt
Azure-SlotName
CDN-Uid
Mn-Server-Ip
Selected-Fe
Web-Mar-Node
Apigw-Requestid
DB-Nickname
X-Tid
X-Cache-Status-Check
X-SRV
WP-Super-Cache
X-Correlation-ID
X-R9-Blue-Green-Version
X-Nginx-Cache
X-Zen-Fury
X-Ms-Version
X-SaId
X-Ms-Request-Id
X-JoinUs
X-FireWall-Port
Cache-Name
ServedBy
X-ECache
X-LSADC-Cache
X-Ua
X-DynaTrace-JS-Agent
X-Api-Version
Xserver
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
X-Debug-Cache
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Human
Xet-Cookie
Source
X-TA-CDN-Provider
Cache
X-Dc
X-Cache-Tags
X-RCS-CacheZone
X-Loop
X-Cached-By
X-MP-GENERATED-AT
X-Aspnetmvc-Version
X-TNCMS
SD-X-WS
X-Cdn
Cross-Origin-Window-Policy
X-Varnish-Hits
X-GEO
X-Reqid
Origin
X-Webkit-CSP
X-Soup
X-Amzn-Remapped-Content-Length
X-Pubstack
WPO-Cache-Message
LB
WPO-Cache-Status
X-App-Version
X-Origin-TTL
X-Origin-CC
X-Tumblr-Pixel-2
X-Vgn-Hpd-Reason
From-Origin
X-Via-NSCOPI
X-Service
X-IPS-LoggedIn
X-NewRelic-App-Data
X-B3-SpanId
X-Newrelic-Synthetics
X-Provided-By
X-AOL-HN
X-GG-Cache-Date
X-TIME
X-Varnish-Beresp-Ttl
X-Tec-Api-Root
X-Tec-Api-Origin
X-FW-Version
Webserver
X-Tec-Api-Version
Rip
X-Platform-Server
X-B3-Traceid
X-Cluster-Node
X-Request-Host
Cache-Hits
X-D
X-Orig-Expires
X-Ec-Fail
X-Vdms-Version
X-SRCache-Key
X-Ec-GeoHdr
X-Aed
X-A-Wwc
A
X-A-Dam
BehaviorPad-Version
X-A-Ccd
X-A-Dcw
X-A-Dgt
X-Developer
X-TIM-N
X-Destination
Cdncip
X-Application
X-Tenant
X-BCube-Filmed-By
X-Bc-Bl
X-External-Request-Id
X-Cache-NE
X-Connection-Hash
DCR-Decision-By
DCR-Processing-Time-Ms
Environment
X-Owner
X-NAPM-TraceId
X-Forwarded-Path
X-AK-Request-ID
X-ARC
Cdnsip
Expiry
X-B-Cookie
X-Vdms-Path
Host-ID
X-Served-From
X-A
X-Shop-Environment
X-VG-WebCache
Rendered-Blocks
Ngx.Var.Host
X-Processor
Odigeo-Trace-Id
X-Rojux
Xc-Version
X-ScT
X-User
X-S
X-S-Cookie
Sslversion
T-Server
X-PBS-Appsvrname
Surrogated-Key
MD5-Digest
Meta-Geo-Continent
Lang
X-Rewrite-Enabled
Upgrade-Insecure-Requests
OT-Force-Account-Verify
X-Bip
X-Thanos
X-Qloud-Router
X-Generated-On
X-Pool
X-Level-Front-Cache
Redirect-Candidate
X-Aicache-OS
X-Dispatcher-Number
Cache-Tv-Group
X-Accel-Buffering
Mime-Version
X-Cluster
Fastly-SSL
X-WA-Info
State
X-Core-Value
Req-Svc-Chain
X-Ckpd-Fst-Backend
X-Clientip
X-Datadog-Sampling-Priority
Servername
X-Datadog-Parent-Id
X-Csrf-Jwt
Server-Host
X-Core-Mission
X-Branch-Name
X-Ad-Defer-Variation
Tube-Return
Tube-Got-Results
Tube-Got-Eval
Vix-Hermes-Req-Id
Wxu-Next-Commit
Wxu-Next-Region
Wxu-Next-Hostname
X-Datadog-Trace-Id
Tube-Get-Contents
X-Auto-Login
TDXMobile
X-CacheTTL
X-Cdn-Origin
X-Cdn-Srv
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
Traceparent
X-BBC-Edge-Cache-Status
Thinkindot-Control
X-CGP
X-GeoIP
CPC-Age
CPC-Cache
X-Sigma-Backend
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Varnish-Beresp-Status
X-Sigma
X-SIPLIST1
X-Slack-Backend
VNS-Cache
X-Origin-Response-Time
VNS-Age
X-SplitTest
X-Sn-Servicetimems
X-Origin-Time
X-Planisys-CDN-TTL
X-Parent-Response-Time
X-Rocket-Build-Number
X-Scale
X-Request-URI
X-Rocket-Nginx-Serving-Static
X-Wix-Viewer-Type
X-SB
X-S-Maxage
X-Variation
X-Worker
X-VG-TLSProxy
Machine
X-Varnish-CookieHashed-On
X-Policy
X-Region-Sid
X-V-Cache
X-Origin
X-Optimistic-Header
X-Gateway-Cache-Key
X-Gamma-Serve
X-Forwarded-Site
X-Gateway-Cache-Status
X-Gateway-Request-Id
X-Gdpr
X-Gateway-Skip-Cache
X-Fetched-On
X-Eu-Site
X-Developers
X-DefHash
X-Device-Os
X-DPWN-IS-SECURE
X-Epic-Correlation-Id
X-Ec-Custom-Error
X-Geo-Header
X-VServer
X-Minions-Version
X-Loc
X-SVT-ORM-RULES
X-NodeID
X-Nyt-Route
X-Thinkindot-L3
X-Varnish-Remaining-TTL
X-JWT-State
X-Is-Gdpr
X-Varnish-CookieINHashed-On
X-Has-Esi
X-SVT-ORM-VERSION
X-Hash
X-Irp-Debug
X-INCAP-ABP
X-DefElseHash
V-Age
Adler-Geo
Gh-Request-Id
Fastly-SWR
Fastly-SIE
Apple-News-Services-Handled
Ha-Gx-Prefs
HA-Ipaddr
L
Click-Count-Error
Kp-EeAlive
IsBot
Is-Eu
Apple-News-Services-Host
DSUID
Cmstype
Country-Code
Candidate-Md5Url
Cmsid
Click-Count-Action-Start
Cache-Host
Decoy-Debug-Key
Decoy-Debug-TTL
Apple-News-Services-Parsed-Url
Decoy-Debug-Status
Apple-News-Services-Request-Url
Memcached
L5d-Success-Class
NM-Fastcgi-Cache
NGX
HostName
Origin-EX
X-CSRF-Token
Producers
Platform
Mobile-Detection-Method
Origin-CC
X-Xrds-Location
X-Tx-Id
X-VC
X-Mvc-Supplant-Cachable
X-Cache-Bucket
Release
X-Scheme
X-Session-Fingerprint
X-Proxy-Cache-Info
X-Rebelmouse-Surrogate-Control
CDCHOST
X-Rebelmouse-Cache-Control
X-Mvc-Supplant-OutputCached
X-Origin-Expires
Fastly-GeoIP-CountryCode
X-Cache-Id
X-CMSURLCustom
X-Esi-Check
X-Gen-Mode
X-Viewer-Country
X-Clara-WADP
Canary
X-Fmm-Version
X-Gzip
AKAMAI
X-NCache
X-Cache-Info
Fastly-Backend-Name
X-Hnp-Log
X-GeoIP-City
X-HS-Content-Campaign-Id
Web-Mar-Region
Server-Hostname
Server-Ext
Sever-Int
We-Hiring
User-Cache-Control
Svr
X-Block-Status
Fastcgi-Cache-TTL
Cluster
Datacenter
X-RateLimit-Remaining-Second
Mail-Subject
X-WADP-Cache
X-RateLimit-Limit-Second
CloudFront-Viewer-Country
Ec-Rule-Version
X-ZONE
X-Presslabs-Stats
X-Cache-Remote
X-Cache-Debug
X-LB-NoCache
X-Varnish-Ttl
X-Fastly-Cache
WebServer
X-WP-CF-Super-Cache-Active
X-NWS-UUID-VERIFY
Pics-Label
X-Udemy-Cache-App-Namespace
SID
X-ND-Cache
X-Sucuri-Cache
X-Pod-Name
Ssr
X-Sucuri-ID
X-Azure-Ref-OriginShield
X-MCACHE
X-ATG-Version
Time
X-Fastly-Backend
X-Var-Ttl
X-FC-Vary-Parameters
Memory
X-Tb-Optimization-Total-Bytes-Saved
Sid
X-Newrelic-App-Data
X-Via-Poph
Fastly-Drupal-HTML
X-Buckets
X-Via-Popn
X-Generated-In
X-Cache-Date
X-Via-Popv
X-Ig-Push-State
AMP-Access-Control-Allow-Source-Origin
X-Servedbyhost
Server-ID
X-Akamai-Transformed
X-Refresh
X-Conf
X-Microcachable
X-Edge-Pop
X-Release
Env
X-Cs
X-Trace-ID
X-NC
X-Nf-Request-Id
X-Dmc
X-CACHE-AGE
X-MSEdge-Flight
X-Fpc
X-MSEdge-Features
Fastly-Drupal-Html
X-DC
X-Pass-Why
X-Esi
X-Up
X-TRACE-ID
X-PX
X-Be
GeoIp-Country-Code
X-CS
X-Dispatch
X-ID
X-Endurance-Cache-Level
My-App
X-Wa
Magicmarker
X-Tumblr-Pixel-3
X-EC-Lua
CDN
True-Client-IP
X-Yandex-Sdch-Disable
X-Lambda-Id
X-RateLimit-Reset
X-Zone
X-VCL-Version
X-Air-Source
X-Air-Hostname
X-Vc
X-TX-ID
X-Air-Trace-Id
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-Webkit-CSP-Report-Only
X-NGINX-Cache
X-CSRF-TOKEN
Hostname
X-Srv
X-Req
X-CACHE-KEY
X-Hyper-Cache
X-CF-Lambda-Version
X-CF-Lambda-Fn
X-LB-ID
CacheControlHeader
Pramga
X-M-Log
X-M-Reqid
X-HS-Status
X-TH-Server
X-Micro-Cache
X-App
X-Alfa-Service
Resin-Trace
X-Air-Pt
True-Client-Country-4JS
X-Qnm-Cache
C-Via
Path
X-Vcl-Version
X-Varnish-Beresp-TTL
X-Op-Id-All
X-TrackingId
True-Client-Ip
Tcn
N-Cache
Fastcgi-X-Cache-Version
GeoIP-Country-Code
X-B3-Spanid
Tracecode
On-Server
X-Vercel-Id
X-Vercel-Cache
X-PAYTM-SRV-ID
X-Platform
X-Edge-Origin-Shield-Region
X-Check-Cacheable
X-SERVER-NAME
X-Edge-Origin-Shield-Bytes
Esi-Enabled
NtCoent-Length
X-CLOUD-TRACE-CONTEXT
Section-Io-Origin-Time-Seconds
X-Datacenter
Hit
X-Akamai-Pragma-Client-IP
X-GeoIP-Country-Code
GeoIP-Latitude
X-GeoIP-Region-Code
Section-Io-Origin-Status
Section-Origin-Responded
X-Vtex-Remote-Cache
X-Vtex-Processado-Em
X-FPC
Section-Io-Id
Proxy-Connection
X-Webkit-Csp-Report-Only
X-Platform-Router
X-Date
X-Accel-Expires-Debug
X-Platform-Processor
WWW-Authenticate
X-Mly-Id
X-WA
X-Via-CDN
X-API-Version
X-Request-Start
X-Platform-Cluster
X-AIR-PT
X-LAGOON
X-Geo
X-Node-Id
X-SD-PageType
X-ApacheServer
X-PERF
HIT
YJS-ID
Server-Id
X-Lb-Id
X-ServedByHost
ENV
X-RAMCache
User-Agent
Lb
X-Edge-POP
Cache-Key
X-Cdn-Forward
X-Dw-Trace-Id
Cdn
Yjs-Id
X-Response-By
X-Via-PopN
X-Via-PopV
Server-Ttl
X-Instance-Name
XkeyRZ
X-Render-Time
DynaTrace
X-Proxy-CacheRZ
X-Via-PopH
X-Old-Content-Length
FSS-Cache
DT-Hot-News
X-FORWARDED-FOR
XM
X-Traceid
X-Proxy-Cache-Hk
Powered-By
X-HN
X-Via-Ucdn
X-CUA
X-VarnishDD-TTL
X-Cache-Ttl
X-TT-LOGID
X-Proxy-Upstream
X-Li-Fabric
X-Li-Pop
X-LI-UUID
Geoip-Latitude
Dnion-Transfer-Encoding
X-LI-Proto
PFcat
Sm-Log-Id
CountryCode
X-Service-Response-Time
X-LiteSpeed-Cache-Control
X-CF-Powered-By
X-RPM
Ohc-File-Size
PICS-Label
X-DI
X-DSS
X-DW
X-RSL
X-DB
X-Fastly-Backend-Reqs
X-FL-EDGE
Srvid
XServer
X-RPS
X-Location
X-From
Nginx-CQVIP
X-LiteSpeed-Tag
X-Akamai-ERPolicy
Location
Locid
X-Akamai-ERRuleID
X-UA
X-Wp-Cf-Super-Cache
X-Wp-Cf-Super-Cache-Cache-Control
X-Litespeed-Cache-Control
X-Request-Url
X-Webstats-RespID
X-Cdn-Request-ID
X-Cache-ASPX
X-Fastly-Cache-Hits
X-Varnish-Authentication
X-Contensis-Viewer-Groups
Wpo-Cache-Status
Wpo-Cache-Message
Vha6-Origin
X-HostName
X-Lb-Nocache
X-B3-ParentSpanId
Wp-Super-Cache
X-Cache-Ngx
Warning
X-Ips-Loggedin
X-Director
X-Moov-T
X-Ftr-Request-Id
MIME-Version
X-Moov-Xdn-Version
X-DataCenter
M-TraceId
Fastcgi-Cache-Ttl
WZWS-RAY
X-Snapshot-Date
X-Nc
X-Mg-Cache
SRV
X-Cache-Backend
Req-ID