Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Accept-Ranges
Expect-CT
X-XSS-Protection
Pragma
X-Powered-By
CF-RAY
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Xss-Protection
X-Served-By
X-Download-Options
CF-Ray
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
Access-Control-Allow-Credentials
X-FRAME-OPTIONS
X-Request-Id
X-Request-ID
X-Permitted-Cross-Domain-Policies
X-AspNet-Version
Alt-Svc
X-Runtime
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Generator
X-Cache-Status
X-Cacheable
Timing-Allow-Origin
X-Iinfo
X-Envoy-Upstream-Service-Time
X-Content-Security-Policy
X-Drupal-Dynamic-Cache
Feature-Policy
Content-Encoding
Access-Control-Expose-Headers
Upgrade
Status
X-CDN
X-AspNetMvc-Version
P3p
Access-Control-Max-Age
X-Via
Server-Timing
X-UA-Device
Request-Context
X-Robots-Tag
X-Turbo-Charged-By
X-Cache-Group
X-Amz-Request-Id
EagleId
X-Amz-Id-2
X-Backend
X-AH-Environment
X-Proxy-Cache
Keep-Alive
X-Ua-Compatible
X-Server
X-Ws-Request-Id
X-Age
Host-Header
Cf-Edge-Cache
X-Hacker
X-Vhost
X-Server-Powered-By
X-Rq
X-Dns-Prefetch-Control
X-Varnish-Cache
X-Dispatcher
X-Amz-Version-Id
Grace
Allow
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-OneAgent-JS-Injection
X-LiteSpeed-Cache
X-WebKit-CSP
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Page-Speed
Cf-Apo-Via
X-Device
Accept-CH
Cf-Railgun
X-Aws-Lambda-Call-Status
X-Node
X-Pingback
X-Host
X-Ruxit-JS-Agent
X-Server-Id
EagleEye-TraceId
X-Nginx-Cache-Status
Surrogate-Control
X-Akam-SW-Version
X-Cache-Spec
X-Backend-Server
Request-Id
X-Readtime
X-Cache-Lookup
X-HW
X-Content-Security-Policy-Report-Only
Accept-Ch-Lifetime
X-Cloud-Trace-Context
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Trace
X-Application-Context
X-Response-Time
Fastly-Restarts
Permissions-Policy
X-Nginx-Upstream-Cache-Status
X-Mod-Pagespeed
X-Edge
X-WebKit-CSP-Report-Only
X-Mcache
Content-Location
X-Content-Type
X-Url
X-MS-InvokeApp
X-CST
X-Country
Accept-CH-Lifetime
X-Clacks-Overhead
X-Midtier
X-Amz-Server-Side-Encryption
X-PC
X-TtlSet
X-Vname
Rating
X-Litespeed-Cache
RTSS
Cache-Tag
X-ESI
X-Vcap-Request-Id
X-D2id
X-VARITI-CCR
X-Element-Page-Cache
Verso
X-Server-Name
Origin-Trial
X-ECACHE
X-Exp-Id
X-Exp-Variant
X-Cdn-Fetch
X-GoogleNews-Bot
X-Kinja-Server
X-Kinja-Revision
X-Use-Magma
X-Kinja-Build
X-Kinja
X-Rack-Cache
X-Ac
X-Powered-By-Plesk
X-GitHub-Request-Id
X-Cnection
Service-Worker-Allowed
X-SharePointHealthScore
SPRequestGuid
X-Amz-Rid
X-Client-IP
Xkey
X-Navigation-Version
X-Ttl
X-Abt-Application-Version
X-B3-TraceId
Edge-Control
X-Cache-TTL
X-NWS-LOG-UUID
SPIisLatency
SPRequestDuration
X-Upstream
Arr-Disable-Session-Affinity
X-Varnish-TTL
X-Instrumentation
X-Browser-Type
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-Cached
X-Mg-S
X-Dw-Request-Base-Id
X-Px
X-Cache-Key
X-Sol
Display
Pagespeed
X-Middleton-Display
X-FastCGI-Cache
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Correlation-Id
Access-Control-Request-Method
Edge-Cache-Tag
Content-MD5
X-Forwarded-For
X-Country-Code
X-Webkit-Csp
X-NF-Request-ID
X-Goog-Hash
Front-End-Https
TCN
X-Powered-CMS
X-Id
X-Version
Public-Key-Pins
AR-ATIME
AR-PoweredBy
AR-SID
AR-Request-ID
AR-CACHE
Accept-Ch
X-HP-Trace-Id
X-HP-Webp
X-Jurisdiction
X-RateLimit-Remaining
X-MSEdge-Ref
X-T
X-Recruiting
X-Content-Digest
X-Ser
X-Amzn-Trace-Id
X-XRDS-Location
X-Daa-Tunnel
X-Accel-Expires
X-Middleton-Response
Response
TP-L2-Cache
TP-Cache
X-Shield-Request-Id
X-Ratelimit-Limit
S
MicrosoftSharePointTeamServices
Nginx-Cache
Cache-Status
Mrf-Cache-Status
MRF-Tech
X-B3-TraceId-Primal
X-Request-Processing-Time
X-Request-Received
Server-Node
X-HS-Combine-CSS
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Cache-Config
Cache-Tags
X-Distributor
X-Hits
X-Fastcgi-Cache
X-Kinsta-Cache
X-Edge-Location-Klb
X-LB-Cache
X-Ratelimit-Remaining
Fastcgi-Cache
X-Origin-Server
Cross-Origin-Opener-Policy
X-PressLabs-Stats
X-Ua-Browser
X-Ezoic-Cdn
Alternate-Protocol
Server-Name
X-Grace
X-DIS-Request-ID
X-Geo-Country
X-DataDome
X-Ratelimit-Reset
X-Request-Handler-Origin-Region
Filterid
X-Microsite
X-Protected-By
X-Rid
Healthy
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-TEC-API-ROOT
X-Frontend
X-Hostname
X-LLID
X-Logged-In
X-Debug-Info
X-Varnish-Backend
Payment
Cleartype
X-FB-Debug
X-Git-Hash
X-ORACLE-DMS-ECID
X-Forwarded-Proto
X-ORACLE-DMS-RID
X-Fastly-Request-ID
X-Www-Served-By
X-Page-Id
X-Load-Cache
X-NGENIX-Cache
X-Origin-Cache
X-Cluster-Name
X-ASPNET-VERSION
DC
MS-Author-Via
Charset
X-TTL
Content-Disposition
Realpath
X-B3-Sampled
Access-Control-Allow-Method
X-GUploader-UploadID
X-Goog-Metageneration
X-Proxy
X-Upgrade-Enabled
X-F-Cache
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-AppVersion
X-Az
X-Activity-Id
X-ECache
X-Seen-By
Retry-After
X-Amz-Replication-Status
Paypal-Debug-Id
Cross-Origin-Resource-Policy
X-Server-ID
X-Amz-Meta-S3cmd-Attrs
X-Type
X-Contextid
X-Route-Name
Count-Hit
X-Azure-Ref
X-Whom
X-Fb-Rlafr
X-Providence-Cookie
X-Request-Guid
X-Aspnet-Duration-Ms
X-Is-Crawler
X-Flags
Viewport
X-Hosted-By
X-B-Cache
X-Signature
X-Aspnetmvc-Version
X-Wix-Request-Id
X-Revision
X-B
X-Varnish-Server
Accept-Charset
Surrogate-Key
X-VCache
X-Akamai-Edgescape
X-App-Environment
X-TT
Amp-Access-Control-Allow-Source-Origin
X-Cache-Age
X-DynaTrace
X-B3-Traceid
X-Language
X-Source
X-Cache-Control
X-App-Server
X-Fastly-Request-Id
X-Oracle-Dms-Rid
X-Mobile
X-Oracle-Dms-Ecid
Referer-Policy
X-Magnolia-Registration
X-Goog-Storage-Class
X-Goog-Generation
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Times
X-Varnish-Grace
Host
X-RateLimit-Limit
X-Envoy-Decorator-Operation
Version
X-HTML-Minification-Powered-By
X-N
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Cache-Rule
X-Tumblr-Pixel
X-Response-Served-From
X-Original-Request-Id
X-Tumblr-Pixel-1
X-Tumblr-User
X-Tumblr-Pixel-0
X-UUID
Refresh
Ms-Operation-Id
X-Rule
X-Cache-Time
X-Varnish-Age
MS-CV
WPO-Cache-Status
X-RTag
WPO-Cache-Message
SRV
Access-Control-Request-Headers
Section-Io-Cache
X-Cache-Status-Check
SD-X-WS
X-Cache-Grace
X-FW-Hash
X-Cache-Expired-At
X-Framework
X-Cacheable-TTL
X-Content-Powered-By
X-User-Agent
X-FW-Dynamic
X-FW-Version
X-ProcessESI
X-FW-Serve
X-Page-View
X-RemovedCookies
X-FW-Type
X-FW-Static
X-FW-Server
X-Backend-Name
GEO-INFO
X-Jobs
Protected
X-Rendered-As
VIX-Pulpo-Node
Akamai-GRN
X-Instance
X-Drupal-Cache-Tags
X-Servername
X-Device-Type
Url
X-EdgeConnect-Cache-Status
VIX-Pulpo-Upstream-Status
X-Is-Bot
X-G
X-Drupal-Cache-Contexts
X-Adobe-Content
X-Akamai-Request-ID2
X-Adobe-Loc
X-Http-Reason
From-Origin
X-Environment-Context
X-L-Path
CDN-RequestId
X-Status
X-NYM-Debug-Backend
X-Trace-Id
X-Amz-Apigw-Id
NGB
X-Template
X-Amzn-RequestId
X-Region
Front
X-CDN-Forward
X-COUNTRY
X-Varnish-Ttl
X-Nginx-Cache
X-Debug-IsPreview
X-Debug-IsConnected
Accept-Language
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Unique-Id
X-Cache-Hit
X-Content-Options
Country
Fastly-SWR
Fastly-SIE
Backend
X-Zen-Fury
X-Air-Trace-Id
X-Air-Source
X-Air-Hostname
X-DynaTrace-JS-Agent
Liferay-Portal
X-Tb
X-XRDS-LOCATION
X-Mode
Pinterest-Generated-By
X-Newrelic-App-Data
Pinterest-Version
X-Pinterest-Rid
X-Cache-Operation
Content-Secure-Policy
X-Node-Name
X-Real-IP
X-Tt-Logid
X-Tec-Api-Origin
X-Tec-Api-Root
X-Tec-Api-Version
X-Proxy-Cache-Info
X-UPSTREAM-Address
X-RN-RSRV
Uber-Trace-Id
Filters
Meta-Geo
X-Amzn-Remapped-Content-Length
X-Cache-Server
X-Generation-Time
X-Rewrite-Enabled
X-Tumblr-Pixel-2
X-PHP-Backend
X-Format
X-Access
Cache-Hits
CF-IPCountry
X-Content-Age
X-Rocket-Nginx-Serving-Static
X-Ms-Version
X-Ms-Request-Id
Webserver
X-IPS-LoggedIn
X-Time
X-Section
X-Proxy-Build
Onion-Location
X-Timing-Wait
X-Web-Node
Selected-Fe
X-Cluster-Node
X-Reqid
TWC-Privacy
X-VC-Cache
X-Sql-Duration-Ms
TWC-Locale-Group
X-Debug
Webcakes-App-Name
Azure-SlotName
Webcakes-Region
Azure-InstanceId
Azure-RegionName
Azure-Version
X-UA-Device-Type
TWC-GeoIP-LatLong
Webcakes-App-Version
Cache-Name
X-R9-Blue-Green-Version
TWC-GeoIP-Country
X-SayCDN-TTL
X-Soup
X-Locale
ServedBy
Property-Id
X-Sql-Count
X-Origin-Hint
X-Say-Cacheable
X-Say-TTL
Azure-SiteName
Node
TWC-Device-Class
X-Server-W
TWC-Connection-Speed
X-TIME
X-Proto
Web-Mar-Node
X-Proxy-Cache-Status
X-ProxyCache-Key
X-ProxyCache-Status
ServerID
X-Cluster
S-Rt
X-IPLB-Request-ID
X-IPLB-Instance
X-Handled-By
X-LJ-Flow-ID
X-Forwarded-Host
X-Varnish-Beresp-Grace
X-Skip-Cache
X-Site-Version
X-VWS-Id
X-Via-Fastly
X-BYPASS-REASON
X-AWS-Id
X-Sucuri-ID
X-Cache-Action
X-Cache-Host
X-Cms-Context
X-Ua
X-Sucuri-Cache
X-Adobe-Source
X-Cache-TTL-Remaining
DB-Nickname
X-No-Session
X-Uri
X-PHP-Host
X-Tumblr-Pixel-3
X-Extlb
X-Zipkin-Id
X-LAGOON
X-Detected-As
X-JoinUs
X-Proxied
X-Labrador-Cache-Channel
X-Routing-Service
X-Origin-Date
X-FB-TRIP-ID
X-Ruxit-Js-Agent
X-Edge-Location
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
X-SaId
Apigw-Requestid
Cross-Origin-Window-Policy
Mn-Server-Ip
X-Buckets
X-Urbn-Site-Id
X-Urbn-Context-Path
Locale
X-App-Version
X-Optimistic-Header
X-Xfnlog-Site
WP-Super-Cache
Fastcgi-Useragent
Countrycode
X-GeoCountry
X-LSADC-Cache
X-GeoCode
Source
X-ARC
CDN-EdgeStorageId
CDN-PullZone
CDN-CachedAt
CDN-Cache
X-Oneagent-Js-Injection
CDN-RequestCountryCode
Mime-Version
CDN-Uid
X-Hl-Ver
Cache-Tv-Group
X-Director
Fastly-Drupal-HTML
Upgrade-Insecure-Requests
X-Varnish-Hits
X-Request-Time
X-Mg-Request-UUID
X-Generated-By
X-GEO
X-Redis-Cache
X-Cache-Debug
CF-Cached-On
X-Tx-Id
X-Loop
Xet-Cookie
X-Webkit-CSP-Report-Only
X-Origin-CC
Frame-Options
X-Origin-TTL
X-SRV
X-FireWall-Port
X-URL
X-Varnish-Cache-Hits
X-Pass-Why
X-TNCMS
X-Varnish-Hostname
X-TA-CDN-Provider
X-RM-Cache-TTL
X-Sorting-Hat-ShopId
X-ServerID
X-Storefront-Renderer-Rendered
X-Sorting-Hat-PodId
X-Alternate-Cache-Key
X-ShardId
X-Shopify-Stage
X-Akamai-Transformed
X-ShopId
X-Datadog-Sampling-Priority
X-Datadog-Sampled
X-Datadog-Trace-Id
X-Datadog-Parent-Id
X-Api-Version
X-Service
Load-Balancing
X-Newrelic-Synthetics
X-Request-Host
Xserver
X-Served-From
X-Endurance-Cache-Level
X-Pubstack
X-NWS-UUID-VERIFY
X-B3-Spanid
X-External-Request-Id
DCR-Processing-Time-Ms
X-Gdpr
DCR-Decision-By
X-Epic-Correlation-Id
BehaviorPad-Version
X-Loc
X-Location
Server-Info
X-Httpd
X-Level-Front-Cache
X-INCAP-ABP
X-Mid
X-Mobile-URL
X-Nyt-Route
X-Generated-On
Cache-Host
X-Ec-GeoHdr
A
Candidate-Md5Url
Ngx.Var.Host
X-Application
X-Aed
Sslversion
Surrogated-Key
Req-Svc-Chain
Rendered-Blocks
X-BBC-Edge-Cache-Status
X-B-Cookie
Redirect-Candidate
Release
T-Server
TDXMobile
X-A-Dcw
X-A-Dam
X-A-Ccd
X-A
X-A-Dgt
X-A-Wwc
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
Thinkindot-Control
X-Bc-Bl
X-BCube-Filmed-By
Host-ID
X-D
X-CUA
X-Conf
X-Destination
X-Developer
Edge-Cache
X-Ec-Fail
Gannett-Cam-Experience-Id
X-CMSURLCustom
Lang
Odigeo-Trace-Id
X-Cache-Date
Origin
X-Bip
X-Cache-Info
X-Cache-NE
MD5-Digest
Memcached
Meta-Geo-Continent
DSUID
X-Platform-Cluster
X-Vdms-Path
X-TIM-N
X-Rocket-Build-Number
X-Vdms-Version
X-ScT
Xc-Version
X-We-Are-Hiring
X-Processor
X-Rojux
X-Thinkindot-L3
X-SRCache-Key
X-Sigma-Backend
X-Sigma
X-S-Maxage
X-S-Cookie
X-Thanos
X-Test
X-S
X-Platform-Router
X-Varnish-Beresp-Ttl
WWW-Authenticate
X-Platform-Processor
X-Origin-Time
Section-Io-Id
Section-Origin-Responded
X-Restarts
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
X-Hash
Gh-Request-Id
X-Akamai-Device-Characteristics
X-Core-Mission
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
We-Hiring
X-SD-PageType
X-Storage
X-Org
X-Core-Value
X-Developers
X-Sn-Servicetimems
X-Cdn-Srv
X-WA-Info
X-VServer
X-Auto-Login
X-Cache-Bucket
X-WADP-Cache
X-WP-CF-Super-Cache-Active
X-Worker
Country-Code
X-Vmg-Version
NM-Fastcgi-Cache
Mail-Subject
Magicmarker
X-Clara-WADP
X-Varnishpool
Server-Host
X-VG-TLSProxy
X-Cdn-Origin
X-Varnish-Beresp-Status
X-Ec-Custom-Error
X-GeoIP-City
X-Has-Esi
AKAMAI
Apple-News-Services-Handled
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
X-Pool
X-Is-Gdpr
X-Origin-Response-Time
X-Origin
X-Node-Id
X-Mvc-Supplant-Cachable
X-JWT-State
X-Mly-Id
Apple-News-Services-Request-Url
X-Human
X-Fmm-Version
X-Frame-Option
X-Geo-Header
X-GeoIP
C-Via
CloudFront-Viewer-Country
CacheControlHeader
X-Fetched-On
X-CACHE-AGE
X-Parent-Response-Time
X-Fastly-Backend
X-Ad-Defer-Variation
X-Accel-Buffering
X-Fastly-Cache
X-Gamma-Serve
X-Dispatcher-Number
X-DefHash
X-Platform
X-NCache
X-App
X-Nginx-Cache-Key
X-NodeID
X-Region-Sid
Wxu-Next-Region
X-Men
Wxu-Next-Hostname
Wxu-Next-Commit
X-SB
X-FC-Vary-Parameters
X-Op-Id-All
X-Server-IP
X-Slack-Backend
X-Slack-Shared-Secret-Outcome
X-Old-Content-Length
X-Var-Ttl
X-CacheTTL
X-Hnp-Log
X-HN
X-Qloud-Router
X-HS-Content-Campaign-Id
X-Scale
X-Device-Os
X-Req
X-Request-Start
X-Varnish-Remaining-TTL
X-VarnishDD-TTL
X-Cache-Tags
X-Irp-Debug
X-Dispatcher-Server
X-Azure-Ref-OriginShield
X-Varnish-CookieHashed-On
X-Variation
State
X-DefElseHash
X-Platform-Server
X-Varnish-CookieINHashed-On
X-Forwarded-Site
X-Wix-Viewer-Type
X-LB-NoCache
X-Gen-Mode
X-Block-Status
Click-Count-Action-Start
Origin-CC
On-Server
Click-Count-Error
Origin-EX
CDCHOST
Platform
Cache-Provider
PFcat
Datacenter
NGX
Kp-EeAlive
Web-Mar-Region
Is-Eu
L
Fastly-GeoIP-CountryCode
X-CSRF-Token
Environment
Fastly-Backend-Name
Cache-Key
Canary
Tube-Got-Results
Tube-Got-Eval
Tube-Get-Contents
Adler-Geo
Sever-Int
Tube-Return
Server-Ext
Server-Hostname
Vix-Hermes-Req-Id
User-Cache-Control
Decoy-Debug-TTL
X-Minions-Version
X-V-Cache
X-Nananana
Fastly-SSL
X-DPWN-IS-SECURE
X-Eu-Site
X-Gzip
X-Planisys-CDN-TTL
X-GeoIP-Region-Code
X-GeoIP-Country-Code
Ha-Gx-Prefs
X-Planisys-CDN-Rules
Cluster
X-Esi-Check
Decoy-Debug-Key
X-Owner
X-Planisys-CDN-Cache
Decoy-Debug-Status
L5d-Success-Class
X-Cache-Id
X-Date
X-Cache-Remote
X-Accel-Expires-Debug
HA-Ipaddr
Pics-Label
Ssr
X-Origin-Expires
X-Instance-Name
Producers
Cmstype
X-Cache-Backend
X-Ckpd-Fst-Backend
Cmsid
X-Csrf-Jwt
X-CGP
X-Tid
Machine
X-Cache-FS-Status
X-DC
X-Release
X-Response-By
X-Mvc-Supplant-OutputCached
X-Refresh
X-Microcachable
X-Zone
X-Provided-By
Srvid
X-FL-EDGE
HostName
Locid
X-FL-QIT-DEBUG
GeoIP-Latitude
Expect-Staple
X-Aicache-OS
X-Tb-Optimization-Total-Bytes-Saved
X-Air-Pt
X-Correlation-ID
X-Via-CDN
X-ND-Cache
X-From
Time
X-RCS-CacheZone
Memory
Env
X-Servedbyhost
X-Up
X-Via-Edge
X-Presslabs-Stats
X-Trace-ID
X-VC
Edge-Copy-Time
SID
X-Via-SSL
X-Cache-Enabled
X-Generated-In
Svr
X-NewRelic-App-Data
NtCoent-Length
X-Vcl-Version
X-AIR-PT
X-Dc
X-Edge-Pop
X-Nc
X-HS-Status
X-Cached-By
X-Srv
X-Webkit-CSP
Cache
X-Via-Popn
X-Via-Popv
X-Wa
X-Debug-Cache-Store
X-Via-Poph
X-DataCenter
X-Lambda-Id
X-Debug-Cache-Fetch
Cdn
X-Nf-Request-Id
Sid
X-Vgn-Hpd-Cached
X-Vgn-Hpd-Ssi
X-Vgn-Hpd-Variations-Key
X-Vc
X-Cs
X-HA-Backend
X-Esi
X-ZONE
X-Render-Time
X-Hcs-Proxy-Type
X-CCDN-Origin-Time
X-Client-Ip
Server-ID
X-CCDN-CacheTTL
X-Vtex-Remote-Cache
X-Check-Cacheable
X-VCT
X-NGINX-Cache
Fastly-Drupal-Html
Cdnsip
X-LB-ID
CPC-Cache
Hostname
CPC-Age
GeoIp-Country-Code
X-AK-Request-ID
VNS-Age
VNS-Cache
Cdncip
X-Via-NSCOPI
AMP-Access-Control-Allow-Source-Origin
X-Amz-Meta-Cb-Modifiedtime
X-TH-Server
X-Fpc
X-Gateway-Request-Id
X-Gateway-Skip-Cache
X-Gateway-Cache-Status
X-Gateway-Cache-Key
X-Proxy-CacheRZ
XkeyRZ
X-Upstream-Ht
X-Upstream-Ct
X-Via-JSL
True-Client-IP
X-API-Version
X-Cache-Type
X-CSRF-TOKEN
X-Varnish-Authentication
X-Contensis-Viewer-Groups
X-ATG-Version
Uri
X-Cache-ASPX
X-B3-SpanId
X-CS
X-EC-Lua
M-TraceId
True-Client-Ip
Eomportal-Instance
Esi-Enabled
X-Varnish-Beresp-TTL
XServer
OT-Force-Account-Verify
Ngx-Var-Key
X-CF-Lambda-Version
X-Micro-Cache
X-MSEdge-Features
X-MSEdge-Flight
X-CF-Lambda-Fn
X-PAYTM-SRV-ID
Resin-Trace
Srv
X-Udemy-Cache-App-Namespace
Path
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-FPC
YJS-ID
X-MP-GENERATED-AT
Request-ID
X-Request-URI
IsBot
X-CDN-Cache-Status
GeoIP-Country-Code
X-SIPLIST1
X-Cache-NGX
X-Fastly-Country-Code
X-APP-VERSION
N-Cache
CDN
X-RateLimit-Reset
X-VCL-Version
X-Orig-Expires
X-Wikidot-Backend
X-Tenant
RNT-Time
RNT-Machine
X-Wikidot-Static-Cache
X-CLOUD-TRACE-CONTEXT
X-Forwarded-Path
X-Bl-Debug
X-Lb-Id
X-Shop-Environment
X-Info
X-Datadome
X-Accel-Version
Server-Id
X-Service-Response-Time
LB
Sm-Log-Id
X-TX-ID
X-Datacenter
Location
X-B3-Trace-ID
X-MCACHE
X-Policy
X-Pod-Name
X-Ha-Backend
X-App-Name
Lb
X-Edge-POP
HIT
X-WA
Cross-Origin-Opener-Policy-Report-Only
X-Akamai-Pragma-Client-IP
X-Oss-Server-Time
X-Snapshot-Date
X-Oss-Request-Id
X-Via-PopH
X-Via-PopV
X-Via-PopN
X-Oss-Object-Type
X-Oss-Storage-Class
Ohc-File-Size
X-Cdn-Cache-Status
X-Oss-Hash-Crc64ecma
X-SERVER-NAME
X-Cdn-Request-ID
X-Cache-Expires
Servername
X-Geo
X-Xrds-Location
Timeexpire
X-Cache-Ttl
Hit
X-Srcache-Store-Status
X-NC
X-CACHE-KEY
X-Srcache-Fetch-Status
FSS-Cache
Yjs-Id
Pramga
Proxy-Connection
Req-ID
X-Ctl-Mach
ENV
X-Vcache
X-Logging-Id
X-ServedByHost
X-LiteSpeed-Cache-Control
Epwk-X-Cache
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-Amz-Meta-Opti
X-Cdn-Diag
X-Hyper-Cache
Traceparent
X-Container-Uri
X-Moov-T
X-Moov-Xdn-Version
X-UP
WZWS-RAY
Geoip-Latitude
X-Scheme
X-Cdn-Forward
X-Dw-Trace-Id
X-Serial
X-Git-Commit
X-TraceId
X-M-Reqid
X-MiniProfiler-Ids
X-M-Log
X-B3-Parentspanid
X-ApacheServer
X-Acquia-Purge-Tags
X-Tncms
X-VG-WebCache
XM
X-RAMCache
X-Acquia-Site
X-Acquia-Application-Trace
X-Acquia-Application-UUID
X-Swift-Error
X-Qnm-Cache
X-Fastly-Backend-Reqs
Cneonction
Ec-Rule-Version
X-Viewer-Country
Content-Style-Type
Content-Script-Type
MIME-Version
X-Lb-Nocache
X-PERF
X-Wp-Cf-Super-Cache-Cache-Control
X-F-Status
CountryCode
X-Wp-Cf-Super-Cache
X-Lsadc-Cache
X-TT-LOGID
X-Litespeed-Cache-Control
X-Mg-Cache
Ngx
X-Cache-Ngx
My-App
X-Iauth-Set-Uid
Ohc-Cache-HIT
X-LiteSpeed-Tag
X-B3-ParentSpanId
X-Mid-Debug-Cache-Disk
X-Th-Server
X-Request-URL
Warning
X-Fastly-Cache-Hits
Inserted-Into-Cache-At
X-Webstats-RespID
X-Mid-Debug-Cache-Key
X-IPS-Cached-Response