Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Accept-Ranges
Expect-CT
Pragma
X-Powered-By
X-XSS-Protection
CF-RAY
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-Xss-Protection
X-UA-Compatible
X-Served-By
X-Download-Options
CF-Ray
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Request-Id
Access-Control-Allow-Credentials
X-FRAME-OPTIONS
X-Request-ID
X-Permitted-Cross-Domain-Policies
X-AspNet-Version
Alt-Svc
X-Runtime
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Generator
X-Cache-Status
X-Cacheable
Timing-Allow-Origin
X-Envoy-Upstream-Service-Time
X-Iinfo
X-Content-Security-Policy
X-Drupal-Dynamic-Cache
Feature-Policy
Content-Encoding
Access-Control-Expose-Headers
Upgrade
Status
X-CDN
X-AspNetMvc-Version
P3p
X-Ua-Compatible
Access-Control-Max-Age
X-Via
Server-Timing
X-UA-Device
Request-Context
X-Robots-Tag
X-Turbo-Charged-By
X-Amz-Request-Id
X-Cache-Group
EagleId
X-Amz-Id-2
X-Backend
X-AH-Environment
X-Proxy-Cache
Keep-Alive
X-Server
X-Ws-Request-Id
X-Age
X-Dns-Prefetch-Control
Host-Header
Cf-Edge-Cache
X-Hacker
X-Vhost
X-Server-Powered-By
X-Rq
X-Varnish-Cache
X-Dispatcher
X-Amz-Version-Id
Grace
Allow
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-OneAgent-JS-Injection
X-LiteSpeed-Cache
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Page-Speed
X-Device
Cf-Apo-Via
X-WebKit-CSP
Accept-CH
Cf-Railgun
X-Aws-Lambda-Call-Status
X-Node
X-Pingback
X-Host
X-Ruxit-JS-Agent
X-Server-Id
EagleEye-TraceId
X-Nginx-Cache-Status
Surrogate-Control
X-Akam-SW-Version
X-Backend-Server
X-Readtime
Request-Id
X-Cache-Spec
X-Cache-Lookup
X-HW
X-Content-Security-Policy-Report-Only
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Cloud-Trace-Context
X-Trace
X-Application-Context
X-Response-Time
Accept-Ch-Lifetime
Fastly-Restarts
Permissions-Policy
X-Nginx-Upstream-Cache-Status
X-Edge
X-Mod-Pagespeed
X-WebKit-CSP-Report-Only
Accept-CH-Lifetime
X-Mcache
X-Content-Type
Content-Location
X-Url
X-MS-InvokeApp
X-CST
X-Clacks-Overhead
X-Country
Rating
X-Midtier
X-PC
X-Vname
X-Amz-Server-Side-Encryption
X-TtlSet
X-Litespeed-Cache
RTSS
Cache-Tag
X-ESI
X-Vcap-Request-Id
X-D2id
X-VARITI-CCR
X-Element-Page-Cache
Origin-Trial
Verso
X-Kinja-Build
X-Kinja-Server
X-Exp-Variant
X-Kinja
X-Kinja-Revision
X-Exp-Id
X-Cdn-Fetch
X-Use-Magma
X-GoogleNews-Bot
X-Server-Name
X-Rack-Cache
X-Ttl
X-Ac
X-ECACHE
X-Powered-By-Plesk
X-GitHub-Request-Id
X-Cnection
Service-Worker-Allowed
X-Amz-Rid
X-Client-IP
X-SharePointHealthScore
SPRequestGuid
X-Navigation-Version
Xkey
X-Abt-Application-Version
Edge-Control
X-B3-TraceId
SPRequestDuration
SPIisLatency
X-NWS-LOG-UUID
X-Cache-TTL
X-Upstream
Arr-Disable-Session-Affinity
X-Browser-Type
X-Server-Lifecycle-Phase
X-Instrumentation
X-Kraken-Loop-Name
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Mg-S
X-Cached
X-Varnish-TTL
X-Webkit-Csp
X-Dw-Request-Base-Id
X-Px
X-Cache-Key
X-FastCGI-Cache
Display
Pagespeed
X-Sol
X-Middleton-Display
X-SRCache-Fetch-Status
X-Correlation-Id
X-SRCache-Store-Status
X-NF-Request-ID
Access-Control-Request-Method
Edge-Cache-Tag
X-Forwarded-For
Content-MD5
X-Country-Code
X-Goog-Hash
Front-End-Https
X-Powered-CMS
TCN
X-Id
X-Version
AR-PoweredBy
AR-CACHE
AR-ATIME
AR-Request-ID
Public-Key-Pins
AR-SID
X-HP-Trace-Id
X-Jurisdiction
X-HP-Webp
X-MSEdge-Ref
X-Ratelimit-Limit
X-T
X-Content-Digest
X-Recruiting
X-XRDS-Location
X-Ser
Accept-Ch
X-Amzn-Trace-Id
X-RateLimit-Remaining
X-Middleton-Response
Response
X-Accel-Expires
X-Daa-Tunnel
TP-Cache
TP-L2-Cache
X-Shield-Request-Id
MicrosoftSharePointTeamServices
S
Nginx-Cache
Cache-Status
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
Server-Node
X-HS-Cache-Config
X-HS-Content-Id
X-Request-Received
X-Request-Processing-Time
X-HS-Hub-Id
X-HS-Combine-CSS
Cache-Tags
X-Distributor
X-Hits
X-Ratelimit-Remaining
X-Kinsta-Cache
X-Edge-Location-Klb
Cross-Origin-Opener-Policy
X-LB-Cache
X-Fastcgi-Cache
X-Origin-Server
Fastcgi-Cache
X-Ratelimit-Reset
X-Ua-Browser
Alternate-Protocol
X-Ezoic-Cdn
X-Grace
Server-Name
X-DIS-Request-ID
X-PressLabs-Stats
Filterid
X-TEC-API-ROOT
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-Request-Handler-Origin-Region
X-Microsite
X-Fastly-Request-ID
X-Geo-Country
X-Rid
X-Frontend
Healthy
X-Hostname
X-LLID
X-Protected-By
X-Logged-In
X-Git-Hash
Payment
X-FB-Debug
Cleartype
X-Debug-Info
X-Varnish-Backend
X-DataDome
X-Page-Id
X-Load-Cache
X-Forwarded-Proto
X-Www-Served-By
X-NGENIX-Cache
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-Cluster-Name
DC
X-Origin-Cache
MS-Author-Via
Content-Disposition
Realpath
Charset
X-ASPNET-VERSION
X-ECache
Access-Control-Allow-Method
X-B3-Sampled
X-Goog-Metageneration
X-GUploader-UploadID
X-Upgrade-Enabled
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Proxy
X-F-Cache
X-Activity-Id
X-AppVersion
X-Az
X-Seen-By
X-Amz-Replication-Status
Retry-After
X-B3-Traceid
Paypal-Debug-Id
X-Amz-Meta-S3cmd-Attrs
X-Type
Cross-Origin-Resource-Policy
X-Fb-Rlafr
X-Whom
X-Route-Name
X-Azure-Ref
X-Is-Crawler
X-Aspnet-Duration-Ms
Viewport
X-Contextid
X-Providence-Cookie
X-Request-Guid
X-Revision
X-Flags
Count-Hit
X-App-Environment
Surrogate-Key
X-Wix-Request-Id
Accept-Charset
Amp-Access-Control-Allow-Source-Origin
X-B-Cache
X-B
X-Hosted-By
X-Signature
X-Akamai-Edgescape
X-Server-ID
X-Varnish-Server
X-TTL
X-TT
X-DynaTrace
X-Aspnetmvc-Version
X-VCache
X-Oracle-Dms-Ecid
X-Oracle-Dms-Rid
X-Cache-Age
X-Language
X-Source
X-App-Server
X-Cache-Control
Referer-Policy
X-Mobile
X-Times
X-Goog-Storage-Class
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Fastly-Request-Id
X-Varnish-Grace
X-Magnolia-Registration
X-Envoy-Decorator-Operation
Host
Version
X-COUNTRY
X-HTML-Minification-Powered-By
X-N
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Cache-Rule
X-Response-Served-From
X-Tumblr-Pixel-0
WPO-Cache-Message
WPO-Cache-Status
X-Tumblr-Pixel
X-Tumblr-User
X-Tumblr-Pixel-1
Refresh
X-Original-Request-Id
Ms-Operation-Id
MS-CV
X-RTag
Access-Control-Request-Headers
X-Cache-Time
X-Rule
X-Varnish-Age
SRV
X-Varnish-Ttl
X-Framework
X-UUID
X-Cache-Status-Check
X-EdgeConnect-Cache-Status
SD-X-WS
X-Cache-Grace
X-Content-Powered-By
X-FW-Type
X-FW-Static
X-FW-Version
X-Page-View
X-RemovedCookies
X-ProcessESI
X-FW-Server
X-FW-Serve
X-Backend-Name
GEO-INFO
X-Cacheable-TTL
X-FW-Dynamic
X-FW-Hash
Akamai-GRN
Section-Io-Cache
X-User-Agent
X-Drupal-Cache-Tags
X-Device-Type
X-Cache-Expired-At
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Instance
X-G
X-Jobs
X-Rendered-As
X-Status
X-Is-Bot
Protected
X-Trace-Id
From-Origin
X-L-Path
X-Environment-Context
X-Drupal-Cache-Contexts
X-NYM-Debug-Backend
X-Http-Reason
X-Akamai-Request-ID2
CDN-RequestId
X-Adobe-Content
X-Servername
NGB
Url
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Adobe-Loc
X-Region
X-Template
Front
X-CDN-Forward
X-RateLimit-Limit
X-Debug-IsConnected
Accept-Language
X-Debug-IsPreview
X-Unique-Id
X-Nginx-Cache
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Cache-Hit
X-XRDS-LOCATION
X-Content-Options
Backend
Fastly-SWR
Fastly-SIE
X-Zen-Fury
Country
Liferay-Portal
X-Air-Trace-Id
X-TIME
X-Air-Source
X-Air-Hostname
Pinterest-Version
X-Pinterest-Rid
X-Tb
X-DynaTrace-JS-Agent
Pinterest-Generated-By
X-Mode
Content-Secure-Policy
X-Cache-Operation
X-Tt-Logid
X-Real-IP
Filters
Uber-Trace-Id
X-Proxy-Cache-Info
X-Generation-Time
X-UPSTREAM-Address
X-Amzn-Remapped-Content-Length
Webserver
X-Tumblr-Pixel-2
Meta-Geo
X-Rocket-Nginx-Serving-Static
X-RN-RSRV
X-Rewrite-Enabled
X-Cache-Server
X-Node-Name
X-Newrelic-App-Data
X-Format
X-Timing-Wait
X-Section
Azure-SlotName
X-Tec-Api-Root
X-IPS-LoggedIn
Selected-Fe
X-Tec-Api-Version
X-Content-Age
CF-IPCountry
X-PHP-Backend
Azure-Version
Azure-InstanceId
Azure-SiteName
Cache-Hits
X-Web-Node
X-Proxy-Build
Azure-RegionName
X-Tec-Api-Origin
Onion-Location
X-Access
X-Ms-Request-Id
X-R9-Blue-Green-Version
X-Say-Cacheable
X-Say-TTL
X-Server-W
X-SayCDN-TTL
X-Locale
Cache-Name
X-Origin-Hint
X-Ms-Version
Webcakes-Region
Webcakes-App-Version
Webcakes-App-Name
X-Proto
X-Soup
X-Cluster-Node
TWC-Locale-Group
TWC-Connection-Speed
X-Sql-Count
TWC-GeoIP-LatLong
TWC-GeoIP-Country
X-UA-Device-Type
Property-Id
TWC-Device-Class
ServedBy
X-Sql-Duration-Ms
Node
X-Sucuri-Cache
TWC-Privacy
X-Sucuri-ID
X-Debug
ServerID
X-BYPASS-REASON
X-Cache-Host
X-Cache-TTL-Remaining
X-Labrador-Cache-Channel
X-Cms-Context
X-Handled-By
DB-Nickname
Web-Mar-Node
X-Proxy-Cache-Status
X-VC-Cache
X-Ua
X-Uri
S-Rt
X-Forwarded-Host
X-Varnish-Beresp-Grace
X-Skip-Cache
X-Site-Version
X-Reqid
X-Via-Fastly
X-ProxyCache-Status
X-PHP-Host
X-ProxyCache-Key
X-Cache-Action
X-Routing-Service
X-Proxied
X-Edge-Location
X-Extlb
X-LJ-Flow-ID
X-Cluster
X-AWS-Id
X-Tumblr-Pixel-3
X-Origin-Date
X-Zipkin-Id
X-Adobe-Source
X-LAGOON
Cross-Origin-Window-Policy
X-IPLB-Instance
Mn-Server-Ip
X-JoinUs
X-Detected-As
X-SaId
X-VWS-Id
X-IPLB-Request-ID
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
X-FB-TRIP-ID
X-Urbn-Site-Id
X-Xfnlog-Site
X-Optimistic-Header
X-Urbn-Context-Path
X-No-Session
Locale
Apigw-Requestid
Mime-Version
X-GeoCountry
Fastcgi-Useragent
WP-Super-Cache
X-LSADC-Cache
X-GeoCode
Countrycode
X-Ruxit-Js-Agent
X-ARC
Source
X-Buckets
X-App-Version
Upgrade-Insecure-Requests
CDN-PullZone
CDN-CachedAt
CDN-Cache
X-Director
CDN-RequestCountryCode
CDN-EdgeStorageId
X-Time
CDN-Uid
Cache-Tv-Group
X-Hl-Ver
X-Varnish-Hits
X-Oneagent-Js-Injection
X-GEO
Fastly-Drupal-HTML
X-Generated-By
X-Mg-Request-UUID
X-Request-Time
X-Tx-Id
X-Cache-Debug
X-Redis-Cache
Xet-Cookie
Frame-Options
CF-Cached-On
X-Loop
X-FireWall-Port
X-Varnish-Cache-Hits
X-Origin-CC
X-Origin-TTL
X-URL
X-RM-Cache-TTL
X-Varnish-Hostname
X-Pass-Why
X-SRV
X-TNCMS
X-ServerID
X-Datadog-Sampling-Priority
X-Datadog-Sampled
X-Datadog-Parent-Id
X-Api-Version
X-Alternate-Cache-Key
X-Storefront-Renderer-Rendered
X-Datadog-Trace-Id
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-ShardId
X-TA-CDN-Provider
X-Shopify-Stage
X-ShopId
Load-Balancing
X-Akamai-Transformed
X-Served-From
X-Pubstack
X-CACHE-AGE
X-Newrelic-Synthetics
X-Endurance-Cache-Level
X-Location
X-Request-Host
Xserver
X-Service
X-NWS-UUID-VERIFY
Cache-Host
X-A
DCR-Decision-By
Candidate-Md5Url
Server-Info
WWW-Authenticate
BehaviorPad-Version
Thinkindot-CacheControl-Type
A
Thinkindot-Control
T-Server
Surrogated-Key
Thinkindot-CacheControl
Sslversion
Ngx.Var.Host
Odigeo-Trace-Id
Origin
X-A-Ccd
Lang
Memcached
MD5-Digest
Host-ID
Redirect-Candidate
Rendered-Blocks
Req-Svc-Chain
Meta-Geo-Continent
DSUID
Edge-Cache
Gannett-Cam-Experience-Id
Release
DCR-Processing-Time-Ms
X-Thinkindot-L3
X-Processor
X-Rocket-Build-Number
X-Platform-Router
X-Platform-Processor
X-Platform-Cluster
X-Rojux
X-S
X-S-Maxage
X-D
X-Destination
X-S-Cookie
X-Developer
X-Origin-Time
X-Nyt-Route
X-Generated-On
X-Httpd
X-Gdpr
X-External-Request-Id
X-Epic-Correlation-Id
X-INCAP-ABP
X-Level-Front-Cache
X-Mobile-URL
X-Ec-Fail
X-Ec-GeoHdr
X-Mid
X-Loc
X-ScT
X-Sigma
X-Bc-Bl
X-BBC-Edge-Cache-Status
X-BCube-Filmed-By
X-Bip
X-Cache-Date
X-B-Cookie
X-Application
X-A-Dgt
X-A-Dcw
X-A-Wwc
X-Aed
Xc-Version
X-We-Are-Hiring
X-Cache-Info
X-Test
X-Conf
X-CUA
X-SRCache-Key
X-Sigma-Backend
X-CMSURLCustom
X-Thanos
X-Cache-NE
X-Vdms-Version
X-Vdms-Path
X-TIM-N
X-A-Dam
TDXMobile
X-Storage
X-B3-Spanid
X-Restarts
X-Ec-Custom-Error
X-Developers
X-Clara-WADP
X-Fetched-On
X-Has-Esi
X-HS-Content-Campaign-Id
X-GeoIP-City
X-GeoIP
X-Geo-Header
X-Cdn-Srv
X-Cache-Bucket
NM-Fastcgi-Cache
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
Mail-Subject
Magicmarker
Section-Io-Origin-Status
Section-Io-Id
X-Akamai-Device-Characteristics
X-Auto-Login
We-Hiring
X-Varnish-Beresp-Ttl
Server-Host
X-Human
X-Mvc-Supplant-Cachable
X-WP-CF-Super-Cache-Active
Country-Code
X-Worker
X-WADP-Cache
X-VServer
X-Cdn-Origin
X-Core-Mission
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-Sn-Servicetimems
X-Hash
X-Vmg-Version
X-Varnishpool
X-Org
X-Node-Id
Gh-Request-Id
X-JWT-State
X-Origin
X-Origin-Response-Time
X-Varnish-Beresp-Status
X-Var-Ttl
X-SD-PageType
X-Pool
X-Is-Gdpr
X-Fmm-Version
Apple-News-Services-Host
Apple-News-Services-Handled
AKAMAI
Fastly-Backend-Name
Apple-News-Services-Parsed-Url
C-Via
CloudFront-Viewer-Country
CacheControlHeader
Cache-Key
Fastly-GeoIP-CountryCode
Apple-News-Services-Request-Url
X-Parent-Response-Time
X-Gen-Mode
CDCHOST
X-Frame-Option
X-Forwarded-Site
X-Esi-Check
X-FC-Vary-Parameters
Canary
X-GeoIP-Country-Code
X-HN
Cache-Provider
X-Slack-Backend
X-Gzip
X-GeoIP-Region-Code
X-Dispatcher-Server
X-Device-Os
X-Block-Status
X-Cache-Id
X-Azure-Ref-OriginShield
Datacenter
X-Ad-Defer-Variation
X-App
X-Cache-Tags
X-Slack-Shared-Secret-Outcome
X-DefHash
Click-Count-Action-Start
X-DefElseHash
X-Core-Value
Click-Count-Error
X-Server-IP
X-Irp-Debug
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-Variation
X-Scale
X-Req
X-Request-Start
X-Varnish-Remaining-TTL
X-VarnishDD-TTL
X-Wix-Viewer-Type
X-Men
X-WA-Info
X-CacheTTL
X-VG-TLSProxy
X-Date
X-Qloud-Router
Adler-Geo
X-Nginx-Cache-Key
X-Accel-Buffering
X-NCache
X-Mly-Id
X-Region-Sid
X-LB-NoCache
X-NodeID
X-Op-Id-All
X-Dispatcher-Number
X-Platform
X-Fastly-Backend
X-Fastly-Cache
X-Gamma-Serve
X-Accel-Expires-Debug
X-Hnp-Log
Server-Hostname
Origin-CC
Wxu-Next-Commit
Is-Eu
On-Server
Tube-Got-Eval
Vix-Hermes-Req-Id
Web-Mar-Region
Platform
PFcat
Origin-EX
Server-Ext
Wxu-Next-Hostname
Kp-EeAlive
L
Ssr
NGX
Tube-Got-Results
Tube-Return
Sever-Int
Tube-Get-Contents
Machine
User-Cache-Control
Wxu-Next-Region
X-Air-Pt
X-Minions-Version
X-Eu-Site
Producers
Fastly-SSL
X-DPWN-IS-SECURE
Ha-Gx-Prefs
X-Planisys-CDN-TTL
X-V-Cache
L5d-Success-Class
State
Cmstype
X-Origin-Expires
Cmsid
Environment
X-SB
X-Planisys-CDN-Cache
X-Owner
X-Planisys-CDN-Rules
HA-Ipaddr
X-Platform-Server
X-Old-Content-Length
X-Instance-Name
X-Cache-Remote
X-Csrf-Jwt
X-CGP
X-Ckpd-Fst-Backend
X-CSRF-Token
X-Presslabs-Stats
X-Microcachable
Decoy-Debug-Status
X-Tb-Optimization-Total-Bytes-Saved
X-Mvc-Supplant-OutputCached
Decoy-Debug-TTL
Cluster
X-Cache-Backend
X-Cache-FS-Status
X-Tid
X-Provided-By
Pics-Label
X-Nananana
X-Release
X-Response-By
Decoy-Debug-Key
X-Webkit-CSP-Report-Only
X-FL-QIT-DEBUG
X-Aicache-OS
X-Refresh
Expect-Staple
Srvid
Locid
GeoIP-Latitude
X-DC
Env
X-FL-EDGE
X-Via-CDN
X-Zone
Time
HostName
X-RCS-CacheZone
X-NewRelic-App-Data
Memory
X-Correlation-ID
X-Via-Edge
Edge-Copy-Time
X-Via-SSL
X-Vcl-Version
X-Cache-Enabled
X-Generated-In
X-Up
X-Dc
X-ND-Cache
X-Servedbyhost
X-From
X-Trace-ID
SID
X-Cached-By
Svr
X-Edge-Pop
X-DataCenter
NtCoent-Length
Cache
X-Srv
X-Vc
Sid
X-Debug-Cache-Fetch
X-VC
X-Debug-Cache-Store
X-Nc
X-Lambda-Id
X-Webkit-CSP
X-ZONE
X-Via-Poph
X-Vgn-Hpd-Variations-Key
X-Wa
X-Via-Popn
X-Via-Popv
X-Vgn-Hpd-Ssi
X-Vgn-Hpd-Cached
X-HS-Status
X-AIR-PT
X-NGINX-Cache
Cdn
X-Cs
VNS-Cache
X-Render-Time
X-VCT
VNS-Age
CPC-Cache
GeoIp-Country-Code
X-HA-Backend
CPC-Age
X-Vtex-Remote-Cache
X-Esi
Fastly-Drupal-Html
Hostname
X-Client-Ip
X-Hcs-Proxy-Type
X-CCDN-CacheTTL
Server-ID
X-CCDN-Origin-Time
X-CLOUD-TRACE-CONTEXT
X-Check-Cacheable
True-Client-IP
X-AK-Request-ID
Cdncip
Cdnsip
X-Upstream-Ht
X-LB-ID
X-Via-JSL
X-Upstream-Ct
X-Amz-Meta-Cb-Modifiedtime
X-TH-Server
X-B3-SpanId
X-Cache-Type
X-Via-NSCOPI
X-ATG-Version
X-Fpc
X-Gateway-Request-Id
X-Gateway-Skip-Cache
X-Gateway-Cache-Status
X-Gateway-Cache-Key
X-CSRF-TOKEN
AMP-Access-Control-Allow-Source-Origin
X-Proxy-CacheRZ
XkeyRZ
Uri
X-API-Version
X-Varnish-Authentication
X-Cache-ASPX
X-CS
X-Contensis-Viewer-Groups
XServer
M-TraceId
X-Nf-Request-Id
X-Varnish-Beresp-TTL
X-EC-Lua
X-Udemy-Cache-App-Namespace
Eomportal-Instance
Esi-Enabled
X-CF-Lambda-Version
Resin-Trace
OT-Force-Account-Verify
X-PAYTM-SRV-ID
X-CF-Lambda-Fn
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-APP-VERSION
X-FPC
X-MSEdge-Flight
X-Micro-Cache
True-Client-Ip
X-MP-GENERATED-AT
X-MSEdge-Features
Ngx-Var-Key
X-Datadome
Srv
X-Wikidot-Backend
N-Cache
CDN
X-CDN-Cache-Status
X-Wikidot-Static-Cache
Path
Request-ID
YJS-ID
X-Orig-Expires
X-Cache-NGX
X-Fastly-Country-Code
IsBot
RNT-Machine
RNT-Time
X-Lb-Id
X-Tenant
X-SIPLIST1
X-Shop-Environment
X-Bl-Debug
X-Forwarded-Path
X-Request-URI
X-VCL-Version
GeoIP-Country-Code
X-Cache-Ttl
X-Info
Server-Id
LB
X-B3-Trace-ID
X-Accel-Version
X-Service-Response-Time
Lb
X-App-Name
X-Policy
X-Ha-Backend
Sm-Log-Id
X-TX-ID
X-MCACHE
Location
X-Pod-Name
X-WA
HIT
X-Datacenter
X-RateLimit-Reset
X-Edge-POP
Cross-Origin-Opener-Policy-Report-Only
X-Akamai-Pragma-Client-IP
Hit
X-Cdn-Cache-Status
X-Oss-Hash-Crc64ecma
X-Oss-Storage-Class
X-Oss-Server-Time
X-Via-PopH
X-Via-PopN
X-Via-PopV
X-Oss-Request-Id
X-Oss-Object-Type
Servername
X-Cache-Expires
X-SERVER-NAME
X-Vcache
Ohc-File-Size
X-Cdn-Request-ID
X-NC
X-Logging-Id
X-Geo
X-Srcache-Store-Status
X-Cdn-Diag
X-Srcache-Fetch-Status
FSS-Cache
Pramga
X-CACHE-KEY
X-Snapshot-Date
Timeexpire
X-Git-Commit
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-Container-Uri
Warning
Epwk-X-Cache
ENV
Req-ID
X-ServedByHost
X-Ctl-Mach
Proxy-Connection
Yjs-Id
X-Moov-T
X-Moov-Xdn-Version
X-Amz-Meta-Opti
X-Cdn-Forward
Traceparent
X-UP
X-Serial
X-LiteSpeed-Cache-Control
X-Fastly-Backend-Reqs
X-Tncms
X-Scheme
XM
X-TraceId
WZWS-RAY
Geoip-Latitude
X-Hyper-Cache
X-Dw-Trace-Id
X-VG-WebCache
X-M-Reqid
X-M-Log
X-MiniProfiler-Ids
X-Acquia-Purge-Cdn-Unconfigured
V-Age
X-Acquia-Purge-Tags
X-Acquia-Site
X-Iauth-Set-Uid
True-Client-Country-4JS
X-Acquia-Application-UUID
CDN-RequestPullCode
X-Qnm-Cache
CDN-RequestPullSuccess
X-Acquia-Application-Trace
X-RAMCache
Content-Script-Type
X-B3-Parentspanid
Ec-Rule-Version
X-PERF
X-Viewer-Country
Cneonction
X-ApacheServer
X-Swift-Error
Content-Style-Type
X-Lb-Nocache
X-Wp-Cf-Super-Cache
X-Lsadc-Cache
X-TT-LOGID
CountryCode
X-Wp-Cf-Super-Cache-Cache-Control
X-F-Status
X-Request-URL
X-Mid-Debug-Cache-Key
X-Cache-Ngx
X-Mid-Debug-Cache-Disk
X-IPS-Cached-Response
Inserted-Into-Cache-At
Ohc-Cache-HIT
X-Webstats-RespID
Ngx
X-Fastly-Cache-Hits
X-Th-Server
X-B3-ParentSpanId
X-LiteSpeed-Tag
X-Mg-Cache
X-Litespeed-Cache-Control
My-App
MIME-Version