Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Accept-Ranges
Expect-CT
X-XSS-Protection
Pragma
X-Powered-By
CF-RAY
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Xss-Protection
X-Served-By
X-Download-Options
CF-Ray
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
Access-Control-Allow-Credentials
X-FRAME-OPTIONS
X-Request-Id
X-Request-ID
X-Permitted-Cross-Domain-Policies
X-AspNet-Version
Alt-Svc
X-Runtime
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Generator
X-Cache-Status
X-Cacheable
Timing-Allow-Origin
X-Iinfo
X-Envoy-Upstream-Service-Time
X-Content-Security-Policy
X-Drupal-Dynamic-Cache
Feature-Policy
Content-Encoding
Access-Control-Expose-Headers
Upgrade
Status
X-CDN
X-AspNetMvc-Version
P3p
Access-Control-Max-Age
X-Via
Server-Timing
X-UA-Device
Request-Context
X-Robots-Tag
X-Turbo-Charged-By
X-Amz-Request-Id
X-Cache-Group
EagleId
X-Amz-Id-2
X-Backend
X-AH-Environment
X-Proxy-Cache
Keep-Alive
X-Ua-Compatible
X-Server
X-Ws-Request-Id
X-Age
Host-Header
Cf-Edge-Cache
X-Hacker
X-Vhost
X-Server-Powered-By
X-Rq
X-Dns-Prefetch-Control
X-Varnish-Cache
X-Dispatcher
X-Amz-Version-Id
Grace
Allow
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-OneAgent-JS-Injection
X-LiteSpeed-Cache
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Page-Speed
Cf-Apo-Via
X-Device
X-WebKit-CSP
Cf-Railgun
Accept-CH
X-Aws-Lambda-Call-Status
X-Node
X-Pingback
X-Host
X-Ruxit-JS-Agent
EagleEye-TraceId
X-Nginx-Cache-Status
X-Server-Id
Surrogate-Control
X-Akam-SW-Version
X-Cache-Spec
X-Backend-Server
Request-Id
X-Readtime
X-Cache-Lookup
X-HW
X-Content-Security-Policy-Report-Only
X-Cloud-Trace-Context
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Trace
Accept-Ch-Lifetime
X-Application-Context
X-Response-Time
Fastly-Restarts
Permissions-Policy
X-Nginx-Upstream-Cache-Status
X-Mod-Pagespeed
X-Edge
X-WebKit-CSP-Report-Only
Accept-CH-Lifetime
X-Litespeed-Cache
X-Mcache
Content-Location
X-Content-Type
X-MS-InvokeApp
X-Url
X-CST
X-Country
X-Clacks-Overhead
Rating
X-Midtier
X-Amz-Server-Side-Encryption
X-TtlSet
X-PC
X-Vname
RTSS
Cache-Tag
X-ESI
X-Vcap-Request-Id
X-D2id
X-VARITI-CCR
X-Element-Page-Cache
Verso
Origin-Trial
X-Server-Name
X-ECACHE
X-Cdn-Fetch
X-Exp-Variant
X-Kinja-Revision
X-Use-Magma
X-Kinja-Build
X-Kinja
X-GoogleNews-Bot
X-Exp-Id
X-Kinja-Server
X-Rack-Cache
X-Ac
X-Ttl
X-Powered-By-Plesk
X-Cnection
Service-Worker-Allowed
SPRequestGuid
X-SharePointHealthScore
X-Amz-Rid
X-Client-IP
Xkey
X-Navigation-Version
X-GitHub-Request-Id
X-B3-TraceId
X-Abt-Application-Version
Edge-Control
X-Cache-TTL
X-NWS-LOG-UUID
SPRequestDuration
SPIisLatency
X-Upstream
Arr-Disable-Session-Affinity
X-Webkit-Csp
X-Varnish-TTL
X-Erf-Bev-Bev
X-Instrumentation
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Erf-Bev-Bev-Is-Generated
X-Browser-Type
X-Cached
X-Mg-S
X-Dw-Request-Base-Id
X-Px
X-Cache-Key
X-Correlation-Id
Accept-Ch
Pagespeed
X-Sol
X-Middleton-Display
Display
X-SRCache-Store-Status
X-SRCache-Fetch-Status
Access-Control-Request-Method
X-NF-Request-ID
Edge-Cache-Tag
X-Forwarded-For
Content-MD5
X-Country-Code
X-Goog-Hash
X-FastCGI-Cache
Front-End-Https
TCN
X-Powered-CMS
X-Id
X-Version
AR-ATIME
AR-PoweredBy
AR-Request-ID
AR-CACHE
Public-Key-Pins
AR-SID
X-XRDS-Location
X-RateLimit-Remaining
X-Jurisdiction
X-HP-Trace-Id
X-HP-Webp
X-MSEdge-Ref
X-T
X-Content-Digest
X-Recruiting
X-Amzn-Trace-Id
X-Ser
X-Daa-Tunnel
X-Accel-Expires
Response
X-Middleton-Response
TP-L2-Cache
TP-Cache
X-Shield-Request-Id
X-Ratelimit-Limit
X-Fastcgi-Cache
S
MicrosoftSharePointTeamServices
Nginx-Cache
Cache-Status
Mrf-Cache-Status
X-B3-TraceId-Primal
MRF-Tech
X-Request-Processing-Time
X-Request-Received
X-HS-Content-Id
X-HS-Hub-Id
Server-Node
X-HS-Cache-Config
X-HS-Combine-CSS
Cache-Tags
X-Distributor
X-Hits
X-Kinsta-Cache
X-Edge-Location-Klb
X-LB-Cache
Fastcgi-Cache
X-Ratelimit-Remaining
Cross-Origin-Opener-Policy
X-Origin-Server
X-Ua-Browser
X-PressLabs-Stats
Alternate-Protocol
X-Ezoic-Cdn
Server-Name
X-TEC-API-ROOT
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-Grace
X-DIS-Request-ID
X-DataDome
X-Geo-Country
X-Ratelimit-Reset
Filterid
X-Microsite
X-Request-Handler-Origin-Region
X-Server-ID
X-Protected-By
X-Rid
Healthy
X-Hostname
X-LLID
X-Frontend
X-Logged-In
X-Git-Hash
Payment
X-Varnish-Backend
X-Debug-Info
X-FB-Debug
Cleartype
X-Www-Served-By
X-Page-Id
X-Forwarded-Proto
X-Load-Cache
X-NGENIX-Cache
X-Origin-Cache
X-Cluster-Name
X-ASPNET-VERSION
DC
MS-Author-Via
X-ORACLE-DMS-ECID
X-Fastly-Request-ID
Content-Disposition
X-ORACLE-DMS-RID
Charset
Realpath
X-B3-Sampled
Access-Control-Allow-Method
X-Goog-Metageneration
X-GUploader-UploadID
X-Upgrade-Enabled
X-Proxy
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-F-Cache
X-Az
X-Activity-Id
X-AppVersion
X-ECache
X-Seen-By
X-Amz-Replication-Status
Retry-After
X-TTL
Cross-Origin-Resource-Policy
Paypal-Debug-Id
X-Type
X-Contextid
X-Amz-Meta-S3cmd-Attrs
X-Route-Name
X-Fb-Rlafr
X-Whom
X-Hosted-By
X-Revision
X-Azure-Ref
X-Request-Guid
Viewport
Count-Hit
X-Flags
X-Aspnet-Duration-Ms
X-Providence-Cookie
X-Is-Crawler
X-Signature
Accept-Charset
X-App-Environment
X-B-Cache
X-Wix-Request-Id
Surrogate-Key
X-Aspnetmvc-Version
X-B
X-Varnish-Server
X-VCache
X-TT
X-Fastly-Request-Id
X-Akamai-Edgescape
Amp-Access-Control-Allow-Source-Origin
X-Oracle-Dms-Rid
X-Oracle-Dms-Ecid
X-DynaTrace
X-Cache-Age
X-B3-Traceid
X-Language
X-Source
X-Cache-Control
X-App-Server
Referer-Policy
X-Mobile
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Magnolia-Registration
X-Times
X-Varnish-Grace
Host
X-RateLimit-Limit
X-Envoy-Decorator-Operation
Version
X-N
X-Tt-Trace-Tag
X-HTML-Minification-Powered-By
X-Tt-Trace-Host
X-Cache-Rule
X-Tumblr-User
X-Tumblr-Pixel
X-Response-Served-From
X-Original-Request-Id
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
Access-Control-Request-Headers
X-Varnish-Age
MS-CV
Refresh
WPO-Cache-Status
Section-Io-Cache
X-Rule
X-RTag
WPO-Cache-Message
X-Cache-Time
SRV
X-UUID
Ms-Operation-Id
X-Framework
X-Cache-Status-Check
SD-X-WS
X-Page-View
X-FW-Version
X-FW-Type
X-ProcessESI
X-Cache-Grace
X-User-Agent
X-FW-Static
X-RemovedCookies
X-FW-Server
X-Cacheable-TTL
X-Cache-Expired-At
GEO-INFO
X-Content-Powered-By
X-FW-Dynamic
X-FW-Serve
X-FW-Hash
Akamai-GRN
X-Backend-Name
X-EdgeConnect-Cache-Status
X-Drupal-Cache-Contexts
X-Drupal-Cache-Tags
X-Status
Url
X-Is-Bot
X-Device-Type
X-Rendered-As
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
Protected
X-G
X-Servername
X-Instance
X-Jobs
X-Akamai-Request-ID2
X-Adobe-Content
X-Http-Reason
X-Environment-Context
X-Adobe-Loc
X-L-Path
CDN-RequestId
From-Origin
X-NYM-Debug-Backend
X-Template
X-Amz-Apigw-Id
NGB
X-Amzn-RequestId
X-Trace-Id
X-Region
X-CDN-Forward
Front
X-COUNTRY
X-Varnish-Ttl
X-Nginx-Cache
X-Debug-IsConnected
X-Debug-IsPreview
Accept-Language
X-Unique-Id
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Cache-Hit
X-Content-Options
Fastly-SIE
Backend
Fastly-SWR
Country
X-Zen-Fury
X-Air-Hostname
X-Air-Source
X-Air-Trace-Id
Liferay-Portal
X-DynaTrace-JS-Agent
X-Tb
X-XRDS-LOCATION
X-Mode
X-Newrelic-App-Data
Pinterest-Version
X-Pinterest-Rid
Pinterest-Generated-By
X-Cache-Operation
Content-Secure-Policy
X-Tt-Logid
X-Real-IP
X-Node-Name
X-Cache-Server
Uber-Trace-Id
X-Tumblr-Pixel-2
X-Amzn-Remapped-Content-Length
X-Rewrite-Enabled
X-UPSTREAM-Address
X-Proxy-Cache-Info
Webserver
Meta-Geo
X-Generation-Time
X-RN-RSRV
Filters
X-Section
X-Timing-Wait
X-Content-Age
X-Proxy-Build
Selected-Fe
X-Format
X-IPS-LoggedIn
X-Ms-Request-Id
X-Ms-Version
CF-IPCountry
X-Rocket-Nginx-Serving-Static
Onion-Location
Cache-Hits
X-Web-Node
Azure-Version
Azure-InstanceId
Azure-SiteName
Azure-SlotName
X-Access
X-PHP-Backend
X-Time
Azure-RegionName
Webcakes-App-Name
X-Debug
TWC-Device-Class
X-Sucuri-ID
Node
TWC-GeoIP-LatLong
Webcakes-App-Version
ServedBy
TWC-Connection-Speed
X-Cluster-Node
TWC-GeoIP-Country
Cache-Name
TWC-Privacy
Webcakes-Region
TWC-Locale-Group
X-Say-TTL
X-SayCDN-TTL
X-Proto
X-Server-W
X-VC-Cache
X-Reqid
X-Locale
Property-Id
X-R9-Blue-Green-Version
X-Origin-Hint
X-UA-Device-Type
X-Say-Cacheable
X-Sucuri-Cache
X-Sql-Duration-Ms
X-Soup
X-Sql-Count
X-TIME
X-PHP-Host
S-Rt
X-Proxy-Cache-Status
X-Forwarded-Host
X-VWS-Id
X-ProxyCache-Key
X-Via-Fastly
ServerID
Web-Mar-Node
X-LJ-Flow-ID
X-Cluster
X-Cache-Host
X-Labrador-Cache-Channel
X-Cms-Context
X-IPLB-Instance
X-IPLB-Request-ID
X-Cache-Action
X-BYPASS-REASON
X-Handled-By
X-Skip-Cache
X-ProxyCache-Status
X-Varnish-Beresp-Grace
X-AWS-Id
X-Adobe-Source
X-Site-Version
X-Cache-TTL-Remaining
DB-Nickname
X-Uri
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
Apigw-Requestid
X-FB-TRIP-ID
X-SaId
X-LAGOON
X-No-Session
X-JoinUs
X-Detected-As
X-Edge-Location
X-Zipkin-Id
Mn-Server-Ip
X-Origin-Date
X-Tumblr-Pixel-3
X-Ruxit-Js-Agent
X-Routing-Service
X-Extlb
X-Proxied
Cross-Origin-Window-Policy
X-App-Version
X-Xfnlog-Site
X-Urbn-Site-Id
X-Urbn-Context-Path
X-Optimistic-Header
X-Buckets
Locale
Fastcgi-Useragent
Countrycode
X-Ua
WP-Super-Cache
Mime-Version
X-LSADC-Cache
X-GeoCode
X-Tec-Api-Version
X-Tec-Api-Origin
X-Tec-Api-Root
X-GeoCountry
X-ARC
Source
CDN-PullZone
CDN-RequestCountryCode
CDN-Cache
CDN-CachedAt
CDN-EdgeStorageId
X-Oneagent-Js-Injection
CDN-Uid
Cache-Tv-Group
X-Hl-Ver
X-Director
Fastly-Drupal-HTML
Upgrade-Insecure-Requests
X-Varnish-Hits
X-Request-Time
X-Generated-By
X-GEO
X-Mg-Request-UUID
X-Tx-Id
X-Redis-Cache
X-Cache-Debug
CF-Cached-On
X-Loop
Xet-Cookie
X-Origin-TTL
Frame-Options
X-Origin-CC
X-URL
X-SRV
X-FireWall-Port
X-Varnish-Cache-Hits
X-Pass-Why
X-TNCMS
X-RM-Cache-TTL
X-Varnish-Hostname
X-TA-CDN-Provider
X-ShopId
X-Shopify-Stage
X-ShardId
X-Alternate-Cache-Key
X-Akamai-Transformed
X-Sorting-Hat-PodId
X-ServerID
X-Sorting-Hat-ShopId
X-Storefront-Renderer-Rendered
X-Datadog-Sampled
X-Datadog-Parent-Id
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
X-Newrelic-Synthetics
X-Service
Load-Balancing
X-Served-From
X-Pubstack
Xserver
X-Endurance-Cache-Level
X-Request-Host
X-B3-Spanid
X-NWS-UUID-VERIFY
Thinkindot-CacheControl-Type
WWW-Authenticate
X-A
Thinkindot-Control
DSUID
Cache-Host
T-Server
Surrogated-Key
Sslversion
TDXMobile
Server-Info
Thinkindot-CacheControl
Rendered-Blocks
MD5-Digest
Memcached
DCR-Decision-By
DCR-Processing-Time-Ms
Lang
Gannett-Cam-Experience-Id
Edge-Cache
Host-ID
BehaviorPad-Version
X-A-Ccd
Redirect-Candidate
Release
Req-Svc-Chain
Origin
Candidate-Md5Url
Meta-Geo-Continent
Ngx.Var.Host
Odigeo-Trace-Id
A
X-Aed
X-Generated-On
X-Gdpr
X-S-Cookie
X-Httpd
X-INCAP-ABP
X-S-Maxage
X-Vdms-Version
X-Ec-Fail
X-We-Are-Hiring
X-Ec-GeoHdr
X-Epic-Correlation-Id
X-External-Request-Id
X-Level-Front-Cache
X-Loc
X-Vdms-Path
X-Platform-Cluster
X-Platform-Processor
X-Rocket-Build-Number
X-Platform-Router
X-Origin-Time
X-Nyt-Route
X-S
X-Location
X-Rojux
X-Mid
X-Mobile-URL
Xc-Version
X-Developer
X-SRCache-Key
X-B-Cookie
X-Sigma-Backend
X-BBC-Edge-Cache-Status
X-Bc-Bl
X-Application
X-Processor
X-A-Dgt
X-A-Dcw
X-Thanos
X-A-Wwc
X-Test
X-BCube-Filmed-By
X-Cache-Date
X-CUA
X-Conf
X-D
X-Destination
X-ScT
X-CMSURLCustom
X-Thinkindot-L3
X-Cache-Info
X-Cache-NE
X-TIM-N
X-Sigma
X-A-Dam
X-Bip
X-Varnish-Beresp-Ttl
X-Api-Version
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
X-Restarts
Section-Io-Id
X-Pool
X-Cdn-Srv
X-Cdn-Origin
Magicmarker
Mail-Subject
We-Hiring
Country-Code
X-Clara-WADP
X-Core-Mission
X-Ec-Custom-Error
X-Origin-Response-Time
X-Origin
Fastly-Backend-Name
Fastly-GeoIP-CountryCode
X-Core-Value
X-Developers
X-Cache-Bucket
X-Varnish-Beresp-Status
X-WADP-Cache
X-Akamai-Device-Characteristics
X-Worker
Server-Host
X-WA-Info
X-VServer
X-Storage
X-SD-PageType
X-Vmg-Version
X-Varnishpool
NM-Fastcgi-Cache
X-Org
X-VG-TLSProxy
X-Auto-Login
X-WP-CF-Super-Cache-Active
X-Var-Ttl
Gh-Request-Id
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
Apple-News-Services-Handled
AKAMAI
X-Sn-Servicetimems
C-Via
X-Geo-Header
Cache-Key
X-GeoIP
X-GeoIP-City
X-SVT-ORM-RULES
X-JWT-State
X-Mvc-Supplant-Cachable
X-Mly-Id
X-Is-Gdpr
X-Human
X-SVT-ORM-VERSION
X-Has-Esi
X-HS-Content-Campaign-Id
CacheControlHeader
Apple-News-Services-Host
X-Fetched-On
CloudFront-Viewer-Country
X-Frame-Option
X-Hash
X-Node-Id
X-Fmm-Version
X-CACHE-AGE
X-Parent-Response-Time
X-NCache
X-Dispatcher-Server
X-Hnp-Log
X-HN
X-Accel-Buffering
X-Ad-Defer-Variation
X-FC-Vary-Parameters
X-LB-NoCache
Web-Mar-Region
X-Esi-Check
Vix-Hermes-Req-Id
User-Cache-Control
X-Variation
Wxu-Next-Commit
X-Gzip
X-Op-Id-All
Wxu-Next-Region
Wxu-Next-Hostname
X-Irp-Debug
X-Scale
X-Platform
X-Req
X-NodeID
Tube-Return
X-Cache-Id
X-Gen-Mode
X-Platform-Server
X-Cache-Tags
X-Nginx-Cache-Key
X-Qloud-Router
X-Block-Status
X-DefElseHash
X-Forwarded-Site
X-SB
X-App
X-GeoIP-Country-Code
X-Azure-Ref-OriginShield
X-CSRF-Token
X-Old-Content-Length
X-DefHash
X-Request-Start
X-Device-Os
X-GeoIP-Region-Code
X-Varnish-CookieINHashed-On
Click-Count-Error
NGX
Datacenter
X-Gamma-Serve
On-Server
Click-Count-Action-Start
X-Server-IP
X-Region-Sid
X-Date
Origin-CC
State
Machine
X-Fastly-Backend
Environment
Tube-Got-Results
X-Dispatcher-Number
Is-Eu
X-Fastly-Cache
X-Accel-Expires-Debug
X-CacheTTL
L
Kp-EeAlive
PFcat
Origin-EX
CDCHOST
Sever-Int
Adler-Geo
X-VarnishDD-TTL
X-Varnish-Remaining-TTL
Tube-Got-Eval
Tube-Get-Contents
X-Varnish-CookieHashed-On
Server-Hostname
X-Men
X-Wix-Viewer-Type
Canary
X-Slack-Backend
Platform
Server-Ext
Cache-Provider
X-Slack-Shared-Secret-Outcome
X-Instance-Name
X-Eu-Site
Fastly-SSL
X-Owner
Cluster
X-DPWN-IS-SECURE
X-Tid
X-Nananana
Decoy-Debug-Status
Decoy-Debug-Key
Decoy-Debug-TTL
X-Origin-Expires
X-Minions-Version
X-Csrf-Jwt
X-Cache-Backend
X-Refresh
X-Cache-Remote
L5d-Success-Class
Cmstype
Cmsid
Ssr
X-V-Cache
Pics-Label
X-CGP
Producers
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Ckpd-Fst-Backend
X-Planisys-CDN-TTL
Ha-Gx-Prefs
HA-Ipaddr
X-Webkit-CSP-Report-Only
X-Tb-Optimization-Total-Bytes-Saved
X-Microcachable
X-Release
X-DC
X-Response-By
X-Mvc-Supplant-OutputCached
X-Cache-FS-Status
X-Zone
X-Provided-By
X-FL-QIT-DEBUG
Locid
Srvid
Env
X-FL-EDGE
Expect-Staple
X-Aicache-OS
GeoIP-Latitude
HostName
X-Air-Pt
X-Via-CDN
X-RCS-CacheZone
X-Servedbyhost
Time
X-Up
Memory
X-From
X-ND-Cache
X-Trace-ID
X-Presslabs-Stats
X-Via-Edge
SID
X-VC
Edge-Copy-Time
X-Via-SSL
Svr
X-Generated-In
X-Cache-Enabled
X-NewRelic-App-Data
X-Vcl-Version
X-Dc
NtCoent-Length
X-AIR-PT
X-Cached-By
X-HS-Status
X-DataCenter
X-Nc
Cache
X-Srv
X-Webkit-CSP
X-Debug-Cache-Fetch
X-Lambda-Id
X-Wa
X-Via-Poph
X-Debug-Cache-Store
X-Via-Popn
X-Edge-Pop
X-Via-Popv
Cdn
Sid
X-HA-Backend
X-Vgn-Hpd-Ssi
X-Vc
X-Vgn-Hpd-Variations-Key
X-Vgn-Hpd-Cached
X-Cs
X-Esi
X-Correlation-ID
X-ZONE
CPC-Age
X-Client-Ip
CPC-Cache
X-CCDN-Origin-Time
X-Hcs-Proxy-Type
VNS-Cache
X-Vtex-Remote-Cache
X-Render-Time
Server-ID
VNS-Age
X-CCDN-CacheTTL
X-VCT
X-Check-Cacheable
X-NGINX-Cache
X-AK-Request-ID
Cdncip
Fastly-Drupal-Html
X-LB-ID
GeoIp-Country-Code
X-API-Version
Cdnsip
Hostname
X-Fpc
X-Gateway-Cache-Key
X-TH-Server
X-Via-NSCOPI
X-Gateway-Cache-Status
X-Gateway-Request-Id
X-Gateway-Skip-Cache
AMP-Access-Control-Allow-Source-Origin
X-Amz-Meta-Cb-Modifiedtime
X-Upstream-Ht
XkeyRZ
X-Proxy-CacheRZ
X-Via-JSL
X-Upstream-Ct
True-Client-IP
X-ATG-Version
X-Cache-Type
X-CSRF-TOKEN
X-B3-SpanId
X-Nf-Request-Id
Uri
X-Varnish-Authentication
X-Cache-ASPX
X-Contensis-Viewer-Groups
X-EC-Lua
X-CS
Eomportal-Instance
True-Client-Ip
M-TraceId
Esi-Enabled
X-Varnish-Beresp-TTL
X-CF-Lambda-Version
X-CF-Lambda-Fn
X-PAYTM-SRV-ID
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-MSEdge-Flight
XServer
Resin-Trace
X-Micro-Cache
OT-Force-Account-Verify
Ngx-Var-Key
X-MSEdge-Features
Srv
X-Udemy-Cache-App-Namespace
Path
X-FPC
X-MP-GENERATED-AT
Request-ID
YJS-ID
GeoIP-Country-Code
X-APP-VERSION
X-Request-URI
X-SIPLIST1
CDN
X-Wikidot-Backend
N-Cache
X-Wikidot-Static-Cache
X-Fastly-Country-Code
X-Cache-NGX
IsBot
X-RateLimit-Reset
RNT-Time
X-Orig-Expires
X-Shop-Environment
X-CLOUD-TRACE-CONTEXT
X-VCL-Version
X-Tenant
RNT-Machine
X-Datadome
X-Forwarded-Path
X-Bl-Debug
X-Info
X-Lb-Id
X-CDN-Cache-Status
X-Accel-Version
Sm-Log-Id
X-Service-Response-Time
LB
Server-Id
X-TX-ID
X-Policy
X-B3-Trace-ID
Location
X-Pod-Name
X-Edge-POP
X-Ha-Backend
X-App-Name
X-MCACHE
Cross-Origin-Opener-Policy-Report-Only
X-Datacenter
X-Cdn-Cache-Status
X-WA
Lb
HIT
X-Akamai-Pragma-Client-IP
X-Via-PopN
Servername
X-Cache-Expires
X-Via-PopH
X-Oss-Hash-Crc64ecma
X-Snapshot-Date
X-Oss-Object-Type
X-Via-PopV
X-Github-Request-Id
X-SERVER-NAME
Ohc-File-Size
X-Oss-Storage-Class
X-Oss-Request-Id
X-Cdn-Request-ID
X-Oss-Server-Time
X-Geo
Hit
Timeexpire
X-Srcache-Store-Status
X-CACHE-KEY
X-NC
FSS-Cache
X-Srcache-Fetch-Status
X-Cache-Ttl
X-Ctl-Mach
X-Vcache
Epwk-X-Cache
ENV
X-Cdn-Diag
X-Logging-Id
Yjs-Id
Proxy-Connection
Pramga
X-ServedByHost
X-LiteSpeed-Cache-Control
Req-ID
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
Traceparent
X-Cdn-Forward
X-Git-Commit
X-Moov-Xdn-Version
WZWS-RAY
X-TraceId
X-Serial
X-Scheme
Geoip-Latitude
X-Container-Uri
X-Moov-T
X-Dw-Trace-Id
X-Amz-Meta-Opti
X-Hyper-Cache
X-UP
X-M-Log
X-M-Reqid
X-MiniProfiler-Ids
X-Acquia-Application-Trace
X-Acquia-Site
X-Qnm-Cache
X-ApacheServer
X-RAMCache
Content-Style-Type
X-B3-Parentspanid
X-PERF
XM
X-Lb-Nocache
X-Viewer-Country
X-Acquia-Application-UUID
Ec-Rule-Version
X-Swift-Error
X-Tncms
X-VG-WebCache
X-Acquia-Purge-Tags
X-Fastly-Backend-Reqs
Cneonction
Content-Script-Type
X-UA
CountryCode
X-TT-LOGID
X-Lsadc-Cache
X-F-Status
X-Wp-Cf-Super-Cache-Cache-Control
X-Wp-Cf-Super-Cache
My-App
X-Mg-Cache
X-Litespeed-Cache-Control
MIME-Version
X-LiteSpeed-Tag
Ngx
X-MG-Cache
X-Iauth-Set-Uid
Ohc-Cache-HIT
X-Mid-Debug-Cache-Disk
X-Mid-Debug-Cache-Key
Inserted-Into-Cache-At
X-Cache-Ngx
X-B3-ParentSpanId
X-Fastly-Cache-Hits
Warning
X-Request-URL
X-Webstats-RespID
X-Th-Server
X-IPS-Cached-Response