Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Accept-Ranges
Expect-CT
X-XSS-Protection
Pragma
X-Powered-By
CF-RAY
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Xss-Protection
X-Served-By
X-Download-Options
CF-Ray
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
Access-Control-Allow-Credentials
X-FRAME-OPTIONS
X-Request-ID
X-Request-Id
X-Permitted-Cross-Domain-Policies
X-AspNet-Version
Alt-Svc
X-Runtime
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Generator
X-Cache-Status
X-Cacheable
Timing-Allow-Origin
X-Iinfo
X-Envoy-Upstream-Service-Time
X-Content-Security-Policy
X-Drupal-Dynamic-Cache
Feature-Policy
Content-Encoding
Access-Control-Expose-Headers
Upgrade
Status
X-CDN
X-AspNetMvc-Version
P3p
Access-Control-Max-Age
X-Via
Server-Timing
X-UA-Device
Request-Context
X-Robots-Tag
X-Turbo-Charged-By
X-Cache-Group
X-Amz-Request-Id
EagleId
X-Amz-Id-2
X-Backend
X-AH-Environment
X-Proxy-Cache
Keep-Alive
X-Ua-Compatible
X-Server
X-Ws-Request-Id
X-Age
Host-Header
Cf-Edge-Cache
X-Hacker
X-Vhost
X-Server-Powered-By
X-Rq
X-Dns-Prefetch-Control
X-Varnish-Cache
X-Dispatcher
X-Amz-Version-Id
Grace
Allow
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-OneAgent-JS-Injection
X-LiteSpeed-Cache
X-WebKit-CSP
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Page-Speed
Cf-Apo-Via
X-Device
Accept-CH
Cf-Railgun
X-Aws-Lambda-Call-Status
X-Node
X-Pingback
X-Host
X-Ruxit-JS-Agent
X-Server-Id
EagleEye-TraceId
X-Nginx-Cache-Status
Surrogate-Control
X-Akam-SW-Version
X-Cache-Spec
X-Backend-Server
Request-Id
X-Readtime
X-Cache-Lookup
X-HW
X-Content-Security-Policy-Report-Only
Accept-Ch-Lifetime
X-Cloud-Trace-Context
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Trace
X-Application-Context
X-Response-Time
Fastly-Restarts
Permissions-Policy
X-Nginx-Upstream-Cache-Status
X-Mod-Pagespeed
X-Edge
X-WebKit-CSP-Report-Only
X-Mcache
Content-Location
X-Content-Type
X-MS-InvokeApp
X-Url
X-CST
X-Country
Accept-CH-Lifetime
X-Clacks-Overhead
X-Midtier
X-Amz-Server-Side-Encryption
X-PC
X-TtlSet
X-Vname
Rating
X-Litespeed-Cache
RTSS
Cache-Tag
X-ESI
X-Vcap-Request-Id
X-D2id
X-VARITI-CCR
X-Element-Page-Cache
Verso
X-Server-Name
Origin-Trial
X-ECACHE
X-Exp-Id
X-Exp-Variant
X-Cdn-Fetch
X-GoogleNews-Bot
X-Kinja-Server
X-Kinja-Revision
X-Use-Magma
X-Kinja-Build
X-Kinja
X-Rack-Cache
X-Ac
X-Powered-By-Plesk
X-GitHub-Request-Id
X-Cnection
Service-Worker-Allowed
X-SharePointHealthScore
SPRequestGuid
X-Amz-Rid
X-Client-IP
Xkey
X-Navigation-Version
X-Ttl
X-Abt-Application-Version
X-B3-TraceId
Edge-Control
X-Cache-TTL
X-NWS-LOG-UUID
SPIisLatency
SPRequestDuration
X-Upstream
Arr-Disable-Session-Affinity
X-Varnish-TTL
X-Instrumentation
X-Browser-Type
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-Cached
X-Mg-S
X-Dw-Request-Base-Id
X-Px
X-Cache-Key
X-Sol
Display
Pagespeed
X-Middleton-Display
X-FastCGI-Cache
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Correlation-Id
Access-Control-Request-Method
Edge-Cache-Tag
Content-MD5
X-Forwarded-For
X-Country-Code
X-Webkit-Csp
X-NF-Request-ID
X-Goog-Hash
Front-End-Https
TCN
X-Powered-CMS
X-Id
X-Version
Public-Key-Pins
AR-ATIME
AR-PoweredBy
AR-SID
AR-Request-ID
AR-CACHE
Accept-Ch
X-HP-Trace-Id
X-HP-Webp
X-Jurisdiction
X-RateLimit-Remaining
X-MSEdge-Ref
X-T
X-Recruiting
X-Content-Digest
X-Ser
X-Amzn-Trace-Id
X-XRDS-Location
X-Daa-Tunnel
X-Accel-Expires
X-Middleton-Response
Response
TP-L2-Cache
TP-Cache
X-Shield-Request-Id
X-Ratelimit-Limit
S
MicrosoftSharePointTeamServices
Nginx-Cache
Cache-Status
Mrf-Cache-Status
MRF-Tech
X-B3-TraceId-Primal
X-Request-Processing-Time
X-Request-Received
Server-Node
X-HS-Combine-CSS
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Cache-Config
Cache-Tags
X-Distributor
X-Hits
X-Fastcgi-Cache
X-Kinsta-Cache
X-Edge-Location-Klb
X-LB-Cache
X-Ratelimit-Remaining
Fastcgi-Cache
X-Origin-Server
Cross-Origin-Opener-Policy
X-PressLabs-Stats
X-Ua-Browser
X-Ezoic-Cdn
Alternate-Protocol
Server-Name
X-Grace
X-DIS-Request-ID
X-Geo-Country
X-DataDome
X-Ratelimit-Reset
X-Request-Handler-Origin-Region
Filterid
X-Microsite
X-Protected-By
X-Rid
Healthy
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-TEC-API-ROOT
X-Frontend
X-Hostname
X-LLID
X-Logged-In
X-Debug-Info
X-Varnish-Backend
Payment
X-FB-Debug
X-Git-Hash
Cleartype
X-Forwarded-Proto
X-Fastly-Request-ID
X-Page-Id
X-Www-Served-By
X-ORACLE-DMS-RID
X-Load-Cache
X-ORACLE-DMS-ECID
X-NGENIX-Cache
X-Origin-Cache
X-Cluster-Name
X-ASPNET-VERSION
DC
MS-Author-Via
Charset
X-TTL
Content-Disposition
Realpath
X-B3-Sampled
Access-Control-Allow-Method
X-GUploader-UploadID
X-Goog-Metageneration
X-Proxy
X-Upgrade-Enabled
X-F-Cache
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-AppVersion
X-Az
X-Activity-Id
X-ECache
X-Seen-By
Retry-After
X-Amz-Replication-Status
Paypal-Debug-Id
Cross-Origin-Resource-Policy
X-Server-ID
X-Amz-Meta-S3cmd-Attrs
X-Type
X-Contextid
X-Route-Name
Count-Hit
X-Azure-Ref
X-Whom
X-Fb-Rlafr
X-Providence-Cookie
X-Request-Guid
X-Aspnet-Duration-Ms
X-Is-Crawler
X-Flags
Viewport
X-Hosted-By
X-B-Cache
X-Signature
X-Aspnetmvc-Version
X-Wix-Request-Id
X-Revision
X-B
X-Varnish-Server
Accept-Charset
Surrogate-Key
X-VCache
X-Akamai-Edgescape
X-App-Environment
X-TT
Amp-Access-Control-Allow-Source-Origin
X-Cache-Age
X-DynaTrace
X-B3-Traceid
X-Language
X-Source
X-Cache-Control
X-App-Server
X-Fastly-Request-Id
X-Oracle-Dms-Rid
X-Mobile
X-Oracle-Dms-Ecid
Referer-Policy
X-Magnolia-Registration
X-Goog-Storage-Class
X-Goog-Generation
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Times
X-Varnish-Grace
Host
X-RateLimit-Limit
X-Envoy-Decorator-Operation
Version
X-HTML-Minification-Powered-By
X-N
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Cache-Rule
X-Tumblr-Pixel
X-Response-Served-From
X-Original-Request-Id
X-Tumblr-User
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-UUID
Refresh
X-Varnish-Age
X-Cache-Time
Ms-Operation-Id
MS-CV
WPO-Cache-Status
X-RTag
WPO-Cache-Message
SRV
Access-Control-Request-Headers
Section-Io-Cache
X-Rule
SD-X-WS
X-Cache-Status-Check
X-Cache-Grace
X-Framework
X-User-Agent
X-Cacheable-TTL
X-Cache-Expired-At
X-FW-Hash
X-Content-Powered-By
X-FW-Dynamic
X-FW-Version
X-ProcessESI
X-FW-Serve
X-Page-View
X-RemovedCookies
X-FW-Type
X-FW-Static
X-FW-Server
X-Backend-Name
GEO-INFO
X-Jobs
Protected
X-Rendered-As
VIX-Pulpo-Node
Akamai-GRN
X-Instance
X-Drupal-Cache-Tags
X-Servername
X-Device-Type
Url
X-EdgeConnect-Cache-Status
VIX-Pulpo-Upstream-Status
X-Is-Bot
X-G
X-Drupal-Cache-Contexts
X-Adobe-Content
X-Akamai-Request-ID2
X-Adobe-Loc
X-Http-Reason
From-Origin
X-Environment-Context
X-L-Path
CDN-RequestId
X-Status
X-NYM-Debug-Backend
X-Trace-Id
X-Amz-Apigw-Id
NGB
X-Template
X-Amzn-RequestId
X-Region
Front
X-CDN-Forward
X-COUNTRY
X-Varnish-Ttl
X-Nginx-Cache
X-Debug-IsPreview
X-Debug-IsConnected
Accept-Language
X-Yottaa-Metrics
X-Unique-Id
X-Yottaa-Optimizations
X-Cache-Hit
X-Content-Options
Backend
Fastly-SWR
Country
Fastly-SIE
X-Zen-Fury
X-Air-Hostname
X-Air-Trace-Id
X-Air-Source
X-DynaTrace-JS-Agent
Liferay-Portal
X-Tb
X-XRDS-LOCATION
X-Pinterest-Rid
X-Newrelic-App-Data
Pinterest-Version
Pinterest-Generated-By
X-Mode
X-Cache-Operation
Content-Secure-Policy
X-Real-IP
X-Node-Name
X-Tt-Logid
X-Tec-Api-Origin
X-Tec-Api-Root
X-Tec-Api-Version
X-Proxy-Cache-Info
X-Generation-Time
X-Amzn-Remapped-Content-Length
X-UPSTREAM-Address
Filters
Meta-Geo
X-Tumblr-Pixel-2
X-Cache-Server
Uber-Trace-Id
X-Rewrite-Enabled
X-RN-RSRV
X-Rocket-Nginx-Serving-Static
X-Ms-Request-Id
X-Content-Age
Webserver
X-Format
X-Section
X-Ms-Version
X-PHP-Backend
X-IPS-LoggedIn
X-Access
Cache-Hits
Onion-Location
CF-IPCountry
X-Timing-Wait
Selected-Fe
X-Web-Node
X-Proxy-Build
TWC-GeoIP-Country
X-Debug
TWC-GeoIP-LatLong
TWC-Device-Class
Azure-RegionName
ServedBy
TWC-Connection-Speed
Azure-SiteName
Property-Id
TWC-Locale-Group
Webcakes-App-Version
Cache-Name
Azure-Version
Webcakes-App-Name
Webcakes-Region
Azure-SlotName
TWC-Privacy
Azure-InstanceId
X-Cluster-Node
X-Time
X-Sql-Count
X-Server-W
X-Say-Cacheable
X-SayCDN-TTL
X-Locale
X-Sql-Duration-Ms
X-R9-Blue-Green-Version
X-UA-Device-Type
X-Reqid
X-VC-Cache
X-Proto
X-Soup
X-Origin-Hint
Node
X-Say-TTL
X-TIME
X-Sucuri-Cache
X-IPLB-Request-ID
X-VWS-Id
X-Cms-Context
X-Via-Fastly
X-IPLB-Instance
X-Proxy-Cache-Status
X-ProxyCache-Key
ServerID
X-ProxyCache-Status
Web-Mar-Node
X-Sucuri-ID
X-Forwarded-Host
X-Adobe-Source
X-Ua
X-Cache-Host
X-AWS-Id
X-BYPASS-REASON
X-Cluster
X-Handled-By
X-LJ-Flow-ID
X-Cache-Action
X-Site-Version
X-Skip-Cache
X-Varnish-Beresp-Grace
S-Rt
X-Cache-TTL-Remaining
DB-Nickname
X-Ruxit-Js-Agent
X-Tumblr-Pixel-3
X-JoinUs
X-Labrador-Cache-Channel
X-Detected-As
X-WP-CF-Super-Cache-Cache-Control
X-Uri
Mn-Server-Ip
X-LAGOON
X-No-Session
X-Proxied
X-SaId
X-Extlb
X-Edge-Location
X-Routing-Service
Cross-Origin-Window-Policy
X-PHP-Host
X-WP-CF-Super-Cache
X-FB-TRIP-ID
X-Zipkin-Id
X-Origin-Date
Apigw-Requestid
X-Xfnlog-Site
X-Urbn-Site-Id
X-Optimistic-Header
X-App-Version
X-Urbn-Context-Path
X-Buckets
Locale
Countrycode
WP-Super-Cache
X-GeoCode
X-GeoCountry
X-LSADC-Cache
Fastcgi-Useragent
X-ARC
Source
CDN-RequestCountryCode
Mime-Version
CDN-Uid
CDN-EdgeStorageId
CDN-PullZone
CDN-Cache
CDN-CachedAt
X-Oneagent-Js-Injection
Cache-Tv-Group
X-Director
X-Hl-Ver
Fastly-Drupal-HTML
Upgrade-Insecure-Requests
X-Varnish-Hits
X-Mg-Request-UUID
X-Request-Time
X-GEO
X-Generated-By
X-Redis-Cache
CF-Cached-On
X-Tx-Id
X-Cache-Debug
X-Webkit-CSP-Report-Only
Xet-Cookie
X-Loop
X-Origin-TTL
X-Origin-CC
Frame-Options
X-URL
X-SRV
X-FireWall-Port
X-Varnish-Cache-Hits
X-TNCMS
X-Pass-Why
X-TA-CDN-Provider
X-Varnish-Hostname
X-RM-Cache-TTL
X-ServerID
X-ShopId
X-ShardId
X-Alternate-Cache-Key
X-Storefront-Renderer-Rendered
X-Shopify-Stage
X-Akamai-Transformed
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
X-Datadog-Sampled
X-Datadog-Parent-Id
X-Api-Version
Load-Balancing
X-Newrelic-Synthetics
X-Service
X-Pubstack
X-Request-Host
X-Served-From
X-Endurance-Cache-Level
Xserver
X-NWS-UUID-VERIFY
X-B3-Spanid
X-Origin-Time
X-Level-Front-Cache
Release
X-Mobile-URL
Redirect-Candidate
X-Nyt-Route
X-Location
Rendered-Blocks
Req-Svc-Chain
X-Loc
X-Mid
X-External-Request-Id
X-Developer
Gannett-Cam-Experience-Id
X-Destination
Ngx.Var.Host
Edge-Cache
X-Ec-GeoHdr
X-Ec-Fail
DSUID
X-Cache-Date
X-D
Lang
X-Cache-NE
MD5-Digest
Meta-Geo-Continent
X-CMSURLCustom
Host-ID
X-CUA
X-Conf
X-Epic-Correlation-Id
DCR-Processing-Time-Ms
Server-Info
X-Bip
A
X-BCube-Filmed-By
X-Bc-Bl
X-BBC-Edge-Cache-Status
X-INCAP-ABP
X-Httpd
BehaviorPad-Version
Cache-Host
Odigeo-Trace-Id
X-Application
DCR-Decision-By
Origin
X-Gdpr
X-Generated-On
Candidate-Md5Url
X-B-Cookie
X-S
X-Thanos
X-Test
X-Thinkindot-L3
X-TIM-N
Surrogated-Key
X-A-Dam
X-SRCache-Key
X-ScT
X-A
X-Sigma
X-A-Ccd
X-A-Wwc
T-Server
X-We-Are-Hiring
Thinkindot-Control
X-Vdms-Path
X-Vdms-Version
Thinkindot-CacheControl-Type
Xc-Version
X-Platform-Cluster
TDXMobile
X-A-Dcw
X-A-Dgt
Thinkindot-CacheControl
Sslversion
X-Sigma-Backend
X-Aed
X-Rocket-Build-Number
WWW-Authenticate
X-Processor
X-Platform-Processor
X-Platform-Router
X-Rojux
X-Varnish-Beresp-Ttl
Memcached
X-S-Cookie
X-S-Maxage
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
Section-Io-Origin-Status
Section-Io-Id
X-Restarts
X-Worker
We-Hiring
X-WP-CF-Super-Cache-Active
Country-Code
CloudFront-Viewer-Country
X-WA-Info
X-Frame-Option
X-Hash
X-Fetched-On
Gh-Request-Id
Magicmarker
X-Sn-Servicetimems
X-Cdn-Origin
X-Developers
X-Core-Mission
X-VServer
NM-Fastcgi-Cache
X-Core-Value
X-Cdn-Srv
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-Cache-Info
X-Ec-Custom-Error
Mail-Subject
X-Varnishpool
X-Mly-Id
X-SD-PageType
X-Storage
X-JWT-State
X-Human
X-Vmg-Version
X-Auto-Login
X-Node-Id
X-Origin
X-Origin-Response-Time
X-Pool
X-Org
X-Akamai-Device-Characteristics
Server-Host
X-Varnish-Beresp-Status
X-Is-Gdpr
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
X-Has-Esi
CacheControlHeader
C-Via
X-VG-TLSProxy
X-Geo-Header
Apple-News-Services-Handled
X-GeoIP-City
X-GeoIP
Apple-News-Services-Request-Url
AKAMAI
X-Parent-Response-Time
X-CACHE-AGE
X-App
X-Cache-Bucket
Wxu-Next-Region
X-Accel-Buffering
X-Azure-Ref-OriginShield
Wxu-Next-Hostname
X-Ad-Defer-Variation
Wxu-Next-Commit
X-Platform
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
X-VarnishDD-TTL
X-Variation
X-Var-Ttl
X-Req
X-Request-Start
X-SB
X-Scale
X-WADP-Cache
X-Wix-Viewer-Type
X-Server-IP
X-Slack-Backend
X-Slack-Shared-Secret-Outcome
X-Men
X-Region-Sid
X-Gamma-Serve
State
X-CacheTTL
X-Dispatcher-Number
X-Fastly-Backend
X-Qloud-Router
X-Platform-Server
X-Fmm-Version
X-Forwarded-Site
X-Gen-Mode
X-HN
X-FC-Vary-Parameters
X-Dispatcher-Server
X-Clara-WADP
X-DefElseHash
X-DefHash
X-Device-Os
X-Hnp-Log
X-HS-Content-Campaign-Id
X-NodeID
X-Old-Content-Length
X-Op-Id-All
Web-Mar-Region
X-Nginx-Cache-Key
X-NCache
X-Irp-Debug
X-LB-NoCache
X-Mvc-Supplant-Cachable
X-Cache-Tags
X-Block-Status
Adler-Geo
Cache-Key
Canary
NGX
On-Server
PFcat
Origin-EX
Fastly-GeoIP-CountryCode
CDCHOST
Click-Count-Action-Start
Is-Eu
Environment
Fastly-Backend-Name
Datacenter
Kp-EeAlive
Click-Count-Error
L
Platform
Origin-CC
Tube-Got-Eval
Tube-Got-Results
Tube-Get-Contents
Sever-Int
X-CSRF-Token
Vix-Hermes-Req-Id
Server-Hostname
User-Cache-Control
Tube-Return
Server-Ext
X-Origin-Expires
X-Planisys-CDN-Rules
Decoy-Debug-Key
X-Planisys-CDN-Cache
Cluster
X-Planisys-CDN-TTL
X-Esi-Check
X-DPWN-IS-SECURE
Decoy-Debug-Status
Decoy-Debug-TTL
Cache-Provider
X-Tid
X-Fastly-Cache
X-Date
X-Accel-Expires-Debug
X-Minions-Version
Cmstype
X-Gzip
X-GeoIP-Region-Code
X-V-Cache
Cmsid
X-Instance-Name
X-Nananana
X-GeoIP-Country-Code
X-Owner
X-Eu-Site
X-Cache-Remote
Machine
X-CGP
X-Ckpd-Fst-Backend
X-Cache-Id
Fastly-SSL
Ssr
Producers
Pics-Label
L5d-Success-Class
X-Cache-Backend
HA-Ipaddr
X-Csrf-Jwt
Ha-Gx-Prefs
X-Response-By
X-Release
X-Refresh
X-Cache-FS-Status
X-Microcachable
X-Zone
X-Provided-By
X-FL-EDGE
Srvid
Expect-Staple
X-Aicache-OS
GeoIP-Latitude
X-FL-QIT-DEBUG
Locid
X-Tb-Optimization-Total-Bytes-Saved
HostName
X-Mvc-Supplant-OutputCached
X-DC
X-Via-CDN
X-Correlation-ID
X-Air-Pt
Time
X-ND-Cache
X-Up
X-Servedbyhost
X-RCS-CacheZone
Env
Memory
X-From
X-Via-Edge
X-Via-SSL
X-VC
Edge-Copy-Time
SID
X-Presslabs-Stats
X-Dc
X-Trace-ID
X-Generated-In
Svr
X-NewRelic-App-Data
X-Cache-Enabled
X-AIR-PT
NtCoent-Length
X-Vcl-Version
X-Cached-By
X-HS-Status
X-Edge-Pop
X-Nc
Cache
X-Webkit-CSP
X-Srv
X-Debug-Cache-Store
X-Lambda-Id
X-Via-Popv
X-Wa
X-Via-Popn
X-DataCenter
X-Debug-Cache-Fetch
X-Via-Poph
Sid
Cdn
X-Nf-Request-Id
X-Vgn-Hpd-Cached
X-Vgn-Hpd-Ssi
X-Vgn-Hpd-Variations-Key
X-HA-Backend
X-Cs
X-Vc
X-Esi
X-ZONE
X-CCDN-CacheTTL
X-CCDN-Origin-Time
X-Hcs-Proxy-Type
Server-ID
X-Render-Time
X-Vtex-Remote-Cache
X-Client-Ip
X-Check-Cacheable
X-NGINX-Cache
X-VCT
Fastly-Drupal-Html
Cdncip
GeoIp-Country-Code
X-LB-ID
Hostname
Cdnsip
CPC-Age
VNS-Cache
X-AK-Request-ID
VNS-Age
CPC-Cache
X-Fpc
X-Amz-Meta-Cb-Modifiedtime
X-TH-Server
X-Gateway-Skip-Cache
X-Gateway-Cache-Status
X-Gateway-Cache-Key
AMP-Access-Control-Allow-Source-Origin
X-Via-NSCOPI
X-Gateway-Request-Id
XkeyRZ
X-Via-JSL
X-Upstream-Ht
X-Upstream-Ct
X-Proxy-CacheRZ
X-API-Version
X-Cache-Type
True-Client-IP
X-CSRF-TOKEN
X-ATG-Version
X-B3-SpanId
Uri
X-Contensis-Viewer-Groups
X-Cache-ASPX
X-Varnish-Authentication
X-EC-Lua
X-CS
M-TraceId
Eomportal-Instance
True-Client-Ip
Esi-Enabled
X-Varnish-Beresp-TTL
X-CF-Lambda-Fn
X-CF-Lambda-Version
XServer
X-PAYTM-SRV-ID
X-Micro-Cache
Resin-Trace
X-MSEdge-Flight
Ngx-Var-Key
OT-Force-Account-Verify
X-MSEdge-Features
Srv
X-Udemy-Cache-App-Namespace
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-FPC
Path
Request-ID
YJS-ID
X-MP-GENERATED-AT
X-Cache-NGX
X-CDN-Cache-Status
GeoIP-Country-Code
N-Cache
X-APP-VERSION
X-Request-URI
IsBot
CDN
X-Fastly-Country-Code
X-SIPLIST1
X-RateLimit-Reset
RNT-Machine
X-Info
RNT-Time
X-Orig-Expires
X-Wikidot-Backend
X-Forwarded-Path
X-Datadome
X-Shop-Environment
X-VCL-Version
X-CLOUD-TRACE-CONTEXT
X-Tenant
X-Lb-Id
X-Bl-Debug
X-Wikidot-Static-Cache
LB
Server-Id
X-Service-Response-Time
Sm-Log-Id
X-Accel-Version
X-TX-ID
X-B3-Trace-ID
Location
X-Datacenter
X-Ha-Backend
X-App-Name
X-MCACHE
X-Pod-Name
HIT
Lb
Cross-Origin-Opener-Policy-Report-Only
X-Policy
X-WA
X-Edge-POP
X-Akamai-Pragma-Client-IP
X-Via-PopH
X-Via-PopN
X-Oss-Request-Id
X-Oss-Server-Time
X-Via-PopV
Servername
X-Cdn-Cache-Status
X-Oss-Storage-Class
X-Cdn-Request-ID
X-SERVER-NAME
X-Cache-Expires
Ohc-File-Size
X-Oss-Object-Type
X-Snapshot-Date
X-Oss-Hash-Crc64ecma
X-Xrds-Location
X-Geo
Timeexpire
FSS-Cache
Hit
X-Cache-Ttl
X-Srcache-Store-Status
X-CACHE-KEY
X-Srcache-Fetch-Status
X-NC
X-Ctl-Mach
Yjs-Id
X-ServedByHost
Pramga
Epwk-X-Cache
X-Vcache
Proxy-Connection
X-LiteSpeed-Cache-Control
ENV
Req-ID
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-Logging-Id
X-Amz-Meta-Opti
X-Cdn-Diag
X-Hyper-Cache
X-UP
WZWS-RAY
X-Git-Commit
X-Serial
X-Scheme
X-Cdn-Forward
X-TraceId
X-Moov-Xdn-Version
X-Moov-T
Geoip-Latitude
X-Container-Uri
X-Dw-Trace-Id
Traceparent
X-M-Reqid
X-MiniProfiler-Ids
X-M-Log
X-PERF
X-Acquia-Application-Trace
MIME-Version
X-Tncms
X-Acquia-Application-UUID
Cneonction
X-Qnm-Cache
XM
Ec-Rule-Version
X-Swift-Error
X-Lb-Nocache
X-ApacheServer
X-RAMCache
X-Viewer-Country
X-Acquia-Site
Content-Style-Type
Content-Script-Type
X-B3-Parentspanid
X-Fastly-Backend-Reqs
X-Acquia-Purge-Tags
CountryCode
X-Lsadc-Cache
X-F-Status
X-Wp-Cf-Super-Cache-Cache-Control
X-TT-LOGID
X-Wp-Cf-Super-Cache
X-Webstats-RespID
X-Mg-Cache
X-VG-WebCache
Ohc-Cache-HIT
X-Iauth-Set-Uid
X-Litespeed-Cache-Control
X-Mid-Debug-Cache-Disk
X-IPS-Cached-Response
X-B3-ParentSpanId
Warning
Ngx
My-App
X-Th-Server
X-Cache-Ngx
X-LiteSpeed-Tag
X-Mid-Debug-Cache-Key
X-Request-URL
Inserted-Into-Cache-At
X-Fastly-Cache-Hits