Threat Level: green Handler on Duty: Rick Wanner

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
Strict-Transport-Security
X-Frame-Options
X-Content-Type-Options
Last-Modified
Link
CF-Cache-Status
Cf-Request-Id
Accept-Ranges
ETag
CF-RAY
Expect-CT
Pragma
X-Powered-By
X-Cache
Via
Age
X-XSS-Protection
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Xss-Protection
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-FRAME-OPTIONS
X-Download-Options
X-Timer
X-Request-Id
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-Adblock-Key
X-AspNet-Version
X-Permitted-Cross-Domain-Policies
Alt-Svc
X-Runtime
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Check
X-DNS-Prefetch-Control
X-Cache-Status
X-Generator
CF-Ray
X-Cacheable
X-Ua-Compatible
X-Iinfo
Timing-Allow-Origin
X-Envoy-Upstream-Service-Time
X-Request-ID
Feature-Policy
Status
X-Content-Security-Policy
X-Drupal-Dynamic-Cache
Content-Encoding
Access-Control-Expose-Headers
X-CDN
X-AspNetMvc-Version
Upgrade
X-XSS-PROTECTION
Access-Control-Max-Age
X-Via
X-Dns-Prefetch-Control
X-Cache-Group
X-Robots-Tag
Server-Timing
X-UA-Device
Request-Context
Keep-Alive
X-AH-Environment
X-Amz-Request-Id
X-Turbo-Charged-By
X-Backend
X-Proxy-Cache
X-Amz-Id-2
X-Ws-Request-Id
X-Age
Host-Header
P3p
X-Server-Powered-By
X-Hacker
X-Server
X-Rq
X-Vhost
EagleId
X-Varnish-Cache
Grace
X-Amz-Version-Id
X-Dispatcher
X-LiteSpeed-Cache
Cf-Edge-Cache
X-Akamai-Path-Stats
Allow
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-Device
X-Page-Speed
X-Nginx-Cache-Status
X-WebKit-CSP
X-Aws-Lambda-Call-Status
X-Host
X-Node
X-OneAgent-JS-Injection
Accept-CH
X-Pingback
X-Cache-Spec
Cf-Railgun
Request-Id
Surrogate-Control
EagleEye-TraceId
X-Server-Id
X-Akam-SW-Version
X-Backend-Server
X-Cache-Lookup
X-Response-Time
X-Readtime
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-HW
Accept-CH-Lifetime
Content-Location
X-Content-Security-Policy-Report-Only
X-Application-Context
Rating
X-Trace
X-Cloud-Trace-Context
Fastly-Restarts
X-Country
X-Url
X-WebKit-CSP-Report-Only
Accept-Ch-Lifetime
X-Clacks-Overhead
X-Edge
X-MS-InvokeApp
X-Amz-Server-Side-Encryption
X-Rack-Cache
X-Nginx-Upstream-Cache-Status
Edge-Control
X-B3-TraceId
X-Vname
X-TtlSet
X-PC
X-Content-Type
X-Mod-Pagespeed
X-ESI
X-Ruxit-JS-Agent
X-Vcap-Request-Id
X-D2id
X-Oneagent-Js-Injection
Xkey
Verso
X-Ruxit-Js-Agent
X-GitHub-Request-Id
X-Cdn-Fetch
X-Kinja-Server
X-Kinja
X-Kinja-Build
X-GoogleNews-Bot
X-Use-Magma
X-Kinja-Revision
X-Exp-Id
X-Exp-Variant
Cache-Tag
X-Amz-Rid
X-CST
X-Powered-By-Plesk
X-VARITI-CCR
X-Mcache
X-Varnish-TTL
RTSS
X-ECACHE
Service-Worker-Allowed
X-Upstream
X-Navigation-Version
X-Version
X-Cached
X-Abt-Application-Version
X-FastCGI-Cache
X-Client-IP
X-Dw-Request-Base-Id
X-Cnection
X-Ac
X-Px
Accept-Ch
X-Element-Page-Cache
X-Server-Name
X-SharePointHealthScore
Public-Key-Pins
SPRequestGuid
Arr-Disable-Session-Affinity
X-Server-Lifecycle-Phase
X-Instrumentation
X-Kraken-Loop-Name
SPIisLatency
SPRequestDuration
X-Cache-TTL
X-Sol
Pagespeed
X-Middleton-Display
Display
X-Ttl
X-Country-Code
X-NWS-LOG-UUID
Permissions-Policy
X-Ser
X-RateLimit-Remaining
Response
X-Middleton-Response
X-Midtier
X-Cache-Key
X-Kinsta-Cache
X-Edge-Location-Klb
X-Goog-Hash
X-Forwarded-For
Content-MD5
Access-Control-Request-Method
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-NF-Request-ID
X-Correlation-Id
X-DataDome
Front-End-Https
X-Shield-Request-Id
X-MSEdge-Ref
X-Recruiting
X-HP-Trace-Id
X-HP-Webp
X-Jurisdiction
Edge-Cache-Tag
Nginx-Cache
AR-Request-ID
AR-SID
AR-PoweredBy
X-T
AR-CACHE
AR-ATIME
TP-Cache
TP-L2-Cache
Cf-Apo-Via
X-Accel-Expires
X-B3-TraceId-Primal
MicrosoftSharePointTeamServices
MRF-Tech
Mrf-Cache-Status
X-RateLimit-Limit
X-Daa-Tunnel
X-Powered-CMS
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
TCN
X-Grace
X-Mg-S
X-Id
X-Content-Digest
X-Hits
X-HS-Hub-Id
X-HS-Cache-Config
X-HS-Content-Id
X-HS-Combine-CSS
Server-Node
Server-Name
Filters
X-Request-Received
X-Request-Processing-Time
X-Amzn-Trace-Id
X-TEC-API-ORIGIN
X-Frontend
X-TEC-API-ROOT
X-TEC-API-VERSION
MS-Author-Via
X-Fastcgi-Cache
X-Distributor
S
X-Geo-Country
X-Protected-By
Fastcgi-Cache
X-LLID
X-Language
X-Webkit-Csp
Cache-Status
X-Fastly-Request-Id
X-XRDS-Location
X-PressLabs-Stats
X-Origin-Server
X-LB-Cache
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
Count-Hit
X-Browser-Type
X-Ezoic-Cdn
Host
X-Microsite
X-Request-Handler-Origin-Region
X-Forwarded-Proto
Cross-Origin-Opener-Policy
X-TTL
X-F-Cache
X-Page-Id
X-Amz-Meta-S3cmd-Attrs
X-FB-Debug
X-Ab
X-B3-Sampled
X-Ua-Browser
Charset
X-Git-Hash
Payment
Filterid
X-Seen-By
X-Litespeed-Cache
X-ASPNET-VERSION
X-Ratelimit-Reset
X-VCache
X-Cache-Age
X-Cluster-Name
Realpath
Surrogate-Key
X-Rid
Accept-Charset
X-Origin-Cache
Cache-Tags
X-NGENIX-Cache
Alternate-Protocol
X-Template
Access-Control-Allow-Method
X-Www-Served-By
Retry-After
X-Logged-In
X-Activity-Id
X-AppVersion
X-Upgrade-Enabled
X-DynaTrace
X-Az
Cleartype
X-DIS-Request-ID
X-App-Environment
X-Amz-Replication-Status
X-Aspnet-Duration-Ms
X-B
X-Flags
X-Is-Crawler
X-Providence-Cookie
X-TT
X-Request-Guid
X-Varnish-Grace
X-Route-Name
X-Varnish-Backend
X-Type
X-Source
X-Signature
X-B-Cache
X-Tb
X-Wix-Request-Id
X-Node-Name
X-Envoy-Decorator-Operation
Paypal-Debug-Id
DC
X-Aspnetmvc-Version
ServerID
X-Hostname
Frame-Options
X-Drupal-Cache-Tags
X-Fastly-Request-ID
X-Revision
X-Proxy
X-Debug
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Mobile
X-Contextid
X-Server-ID
X-Content-Options
Pinterest-Version
Pinterest-Generated-By
X-Pinterest-Rid
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-Cache-Rule
X-Goog-Metageneration
X-Goog-Storage-Class
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Load-Cache
X-N
X-Cache-Control
Amp-Access-Control-Allow-Source-Origin
Country
X-Magnolia-Registration
Node
Refresh
X-Content
X-Response-Served-From
Referer-Policy
X-Whom
X-Original-Request-Id
X-User-Agent
X-EdgeConnect-Cache-Status
Viewport
NGB
X-L-Path
X-Environment-Context
Access-Control-Request-Headers
X-Cache-TTL-Remaining
X-Cacheable-TTL
VIX-Pulpo-Upstream-Status
Uber-Trace-Id
X-Unique-Id
VIX-Pulpo-Node
X-Content-Powered-By
X-Akamai-Request-ID2
X-Real-IP
X-Framework
X-Mid
X-Debug-IsConnected
X-Debug-IsPreview
X-Yottaa-Metrics
X-Varnish-Server
X-Status
Url
X-Rendered-As
X-Cache-Time
X-Is-Bot
Content-Disposition
X-Yottaa-Optimizations
X-Jobs
X-Page-View
X-Varnish-Age
X-G
X-Servername
X-NYM-Debug-Backend
X-Oracle-Dms-Ecid
Akamai-GRN
X-Oracle-Dms-Rid
Srv
X-Cache-Grace
X-Adobe-Content
X-Adobe-Loc
X-XRDS-LOCATION
X-ProcessESI
Countrycode
X-RemovedCookies
X-Ratelimit-Remaining
X-Instance
X-Time
X-Mg-Request-UUID
X-Drupal-Cache-Contexts
Version
X-COUNTRY
X-Restarts
X-CDN-Forward
X-Http-Reason
X-Via-JSL
X-Cache-Expired-At
X-App-Server
Accept-Language
X-Trace-Id
X-APP-VERSION
Protected
X-Cache-Hit
Healthy
X-Debug-Info
X-IPLB-Instance
X-IPLB-Request-ID
X-Hosted-By
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-Cache-Operation
X-Tumblr-User
Cross-Origin-Resource-Policy
X-Azure-Ref
X-Nginx-Cache-Key
X-Device-Type
X-Tt-Logid
X-Ratelimit-Limit
X-Backend-Name
Liferay-Portal
Content-Secure-Policy
Backend
X-Akamai-Edgescape
X-FW-Server
X-FW-Static
X-FW-Serve
Server-Info
X-FW-Hash
Section-Io-Cache
X-FW-Dynamic
X-FW-Type
Ms-Operation-Id
X-RTag
MS-CV
X-Cache-Action
X-Api-Version
X-Mobile-URL
X-Proxy-Cache-Status
X-Rule
Fastcgi-Useragent
X-Storage
X-UPSTREAM-Address
X-RN-RSRV
Load-Balancing
Meta-Geo
GEO-INFO
X-Cache-NGX
X-Mode
X-SRV
X-Varnish-Beresp-Grace
X-VC-Cache
X-Alternate-Cache-Key
X-Varnishpool
X-Varnish-Hostname
X-Cms-Context
X-Content-Age
X-VWS-Id
X-AWS-Id
X-No-Session
CDN-Cache
CDN-CachedAt
CF-IPCountry
S-Rt
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
CDN-EdgeStorageId
X-Shopify-Stage
X-Site-Version
X-ShopId
X-ShardId
CDN-PullZone
X-Region
X-Redis-Cache
X-PCL
X-Uri
X-OCL
X-LJ-Flow-ID
X-UUID
CDN-Uid
X-PHP-Backend
CDN-RequestId
CDN-RequestCountryCode
X-Urbn-Context-Path
Locale
X-Skip-Cache
X-Urbn-Site-Id
X-Access
Selected-Fe
Azure-SiteName
Mn-Server-Ip
Azure-SlotName
Azure-Version
Eomportal-Instance
Azure-RegionName
X-Edge-Location
X-Request-Time
X-Routing-Service
X-ProxyCache-Status
X-ProxyCache-Key
X-Proxied
X-Proxy-Build
X-Say-Cacheable
X-Say-TTL
X-Sql-Duration-Ms
X-Timing-Wait
X-Sql-Count
X-ServerID
X-SayCDN-TTL
X-Section
X-Proto
X-PHP-Host
X-Cache-Enabled
X-Cache-Server
X-BYPASS-REASON
X-Via-Fastly
X-Zipkin-Id
X-Xfnlog-Site
X-Cache-Type
X-Detected-As
X-HTML-Minification-Powered-By
X-Labrador-Cache-Channel
X-Hl-Ver
X-Forwarded-Host
DB-Nickname
X-Extlb
Azure-InstanceId
TWC-Device-Class
Web-Mar-Node
Webcakes-App-Name
X-Origin-Hint
TWC-Privacy
TWC-Locale-Group
X-Varnish-Cache-Hits
X-Locale
Webcakes-App-Version
X-Handled-By
X-Generation-Time
Webcakes-Region
X-Cache-Host
X-Format
TWC-GeoIP-LatLong
Property-Id
Apigw-Requestid
Onion-Location
TWC-GeoIP-Country
TWC-Connection-Speed
X-R9-Blue-Green-Version
X-Cache-Status-Check
X-Server-W
X-Generated-By
X-FB-TRIP-ID
X-Tid
X-UA-Device-Type
X-Nginx-Cache
X-Web-Node
X-Storefront-Renderer-Rendered
X-URL
X-Adobe-Source
X-SaId
WP-Super-Cache
X-Ms-Version
X-JoinUs
X-Ms-Request-Id
Cache-Name
X-Datadome
X-GeoCountry
X-GeoCode
Xserver
X-FireWall-Port
X-Origin-Date
X-DynaTrace-JS-Agent
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
X-Zen-Fury
ServedBy
X-ECache
X-App-Version
X-Amzn-RequestId
X-Amz-Apigw-Id
X-LSADC-Cache
X-Human
X-Varnish-Ttl
X-Ua
X-TNCMS
X-Dc
Source
X-Debug-Cache
X-Loop
Xet-Cookie
X-Reqid
X-Tec-Api-Root
X-TA-CDN-Provider
X-RCS-CacheZone
X-Tec-Api-Version
X-Tec-Api-Origin
X-Cache-Tags
X-Soup
X-Cached-By
X-Varnish-Hits
X-Pubstack
Cache
Origin
X-MP-GENERATED-AT
Cross-Origin-Window-Policy
X-Newrelic-Synthetics
X-Amzn-Remapped-Content-Length
SD-X-WS
X-Correlation-ID
X-GEO
X-Vgn-Hpd-Reason
X-Cdn
X-Webkit-CSP
X-Provided-By
X-Origin-CC
X-Origin-TTL
X-Service
X-Varnish-Beresp-Ttl
X-Tumblr-Pixel-2
LB
From-Origin
WPO-Cache-Message
WPO-Cache-Status
X-IPS-LoggedIn
Webserver
X-AOL-HN
X-B3-SpanId
Rip
X-NewRelic-App-Data
X-Via-NSCOPI
X-Request-Host
X-GG-Cache-Date
X-A-Ccd
X-A
Surrogated-Key
Sslversion
T-Server
X-A-Dcw
X-AK-Request-ID
X-Application
X-Aed
X-A-Wwc
Rendered-Blocks
X-A-Dgt
X-A-Dam
Meta-Geo-Continent
DCR-Decision-By
DCR-Processing-Time-Ms
Cdnsip
Cdncip
A
BehaviorPad-Version
Environment
Expiry
X-ARC
Ngx.Var.Host
MD5-Digest
Lang
Host-ID
Odigeo-Trace-Id
X-BCube-Filmed-By
X-Served-From
X-Shop-Environment
X-ScT
X-S-Cookie
X-Rojux
X-S
X-SRCache-Key
X-Tenant
X-VG-WebCache
Xc-Version
X-Vdms-Version
X-Vdms-Path
X-TIM-N
X-User
X-Rewrite-Enabled
X-Processor
X-Destination
X-Developer
X-D
X-Connection-Hash
X-Bc-Bl
X-Cache-NE
X-Ec-GeoHdr
X-External-Request-Id
X-Owner
X-PBS-Appsvrname
X-Orig-Expires
X-NAPM-TraceId
X-Forwarded-Path
X-B-Cookie
X-Ec-Fail
X-Cluster-Node
X-CSRF-Token
HostName
X-VC
OT-Force-Account-Verify
X-FW-Version
X-B3-Traceid
Mime-Version
X-Platform-Server
X-Bip
X-Varnish-Beresp-Status
X-Generated-On
X-Thanos
Redirect-Candidate
Machine
X-Pool
Upgrade-Insecure-Requests
X-Parent-Response-Time
X-Level-Front-Cache
X-Aicache-OS
CPC-Cache
VNS-Cache
X-Dispatcher-Number
CPC-Age
VNS-Age
X-WA-Info
X-TIME
X-Mvc-Supplant-Cachable
X-Csrf-Jwt
X-Minions-Version
Release
Req-Svc-Chain
X-Hash
State
X-Gzip
Servername
X-Irp-Debug
X-Mvc-Supplant-OutputCached
Server-Host
X-Core-Value
NM-Fastcgi-Cache
L5d-Success-Class
X-Accel-Buffering
X-Datadog-Trace-Id
L
Kp-EeAlive
HA-Ipaddr
X-Planisys-CDN-Cache
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
X-Optimistic-Header
Tube-Get-Contents
NGX
X-Origin
Memcached
Mobile-Detection-Method
X-NodeID
V-Age
X-Branch-Name
X-Clara-WADP
X-Clientip
X-Fmm-Version
Cache-Hits
X-BBC-Edge-Cache-Status
X-Cache-Bucket
X-Eu-Site
X-Epic-Correlation-Id
X-CGP
X-CacheTTL
X-Esi-Check
X-Cache-Id
X-Cache-Info
X-Cluster
X-Forwarded-Site
Wxu-Next-Commit
Wxu-Next-Hostname
Vix-Hermes-Req-Id
X-Ckpd-Fst-Backend
Tube-Got-Results
Tube-Return
Wxu-Next-Region
X-Ec-Custom-Error
X-Gateway-Cache-Key
X-Gamma-Serve
X-Gateway-Cache-Status
X-Gateway-Request-Id
X-Gateway-Skip-Cache
Ha-Gx-Prefs
Tube-Got-Eval
X-Origin-Response-Time
Canary
Candidate-Md5Url
X-Planisys-CDN-Rules
X-Sigma
X-Sigma-Backend
X-Scale
X-SB
X-Rocket-Nginx-Serving-Static
Cmsid
Click-Count-Error
Click-Count-Action-Start
X-S-Maxage
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
X-Cache-Debug
X-V-Cache
X-VG-TLSProxy
X-VServer
X-WADP-Cache
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
Apple-News-Services-Host
Apple-News-Services-Handled
X-Slack-Backend
X-SplitTest
Cmstype
Cache-Host
X-Qloud-Router
Decoy-Debug-TTL
X-Policy
X-RateLimit-Limit-Second
DSUID
Decoy-Debug-Key
Fastly-GeoIP-CountryCode
X-RateLimit-Remaining-Second
X-Region-Sid
X-Planisys-CDN-TTL
Country-Code
X-Rocket-Build-Number
X-Request-URI
Decoy-Debug-Status
Fastly-SWR
X-Varnish-CookieINHashed-On
Is-Eu
X-Varnish-Remaining-TTL
X-Variation
X-Thinkindot-L3
Ec-Rule-Version
Fastly-SIE
Fastly-SSL
X-Fetched-On
X-Block-Status
IsBot
X-Varnish-CookieHashed-On
X-Worker
X-Gdpr
X-Auto-Login
Web-Mar-Region
X-Nyt-Route
X-Origin-Time
X-Device-Os
X-DefHash
X-DefElseHash
X-Core-Mission
X-DPWN-IS-SECURE
Cluster
X-Wix-Viewer-Type
X-Cdn-Srv
Datacenter
Gh-Request-Id
We-Hiring
X-CMSURLCustom
Mail-Subject
X-Cdn-Origin
X-Ad-Defer-Variation
X-NCache
Thinkindot-Control
X-GeoIP
Traceparent
X-Scheme
X-Geo-Header
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
CDCHOST
X-HS-Content-Campaign-Id
Svr
X-GeoIP-City
TDXMobile
User-Cache-Control
X-ZONE
Platform
Origin-EX
Producers
X-Loc
Fastly-Backend-Name
X-Sn-Servicetimems
X-Gen-Mode
X-Developers
X-Viewer-Country
Origin-CC
X-SIPLIST1
Adler-Geo
X-Hnp-Log
X-Tx-Id
X-Cache-Remote
X-Trace-ID
Cache-Tv-Group
X-Sucuri-ID
X-Sucuri-Cache
X-Proxy-Cache-Info
X-LB-NoCache
X-INCAP-ABP
X-Has-Esi
X-Is-Gdpr
X-JWT-State
Server-Ext
AKAMAI
Fastcgi-Cache-TTL
Server-Hostname
Sever-Int
CloudFront-Viewer-Country
X-WP-CF-Super-Cache-Active
X-Udemy-Cache-App-Namespace
X-Rebelmouse-Surrogate-Control
Ssr
X-Rebelmouse-Cache-Control
Pics-Label
X-Presslabs-Stats
X-Origin-Expires
Memory
X-Session-Fingerprint
X-FC-Vary-Parameters
X-Var-Ttl
X-Azure-Ref-OriginShield
X-ND-Cache
Time
X-Fastly-Backend
X-ATG-Version
X-Fastly-Cache
WebServer
Fastly-Drupal-HTML
AMP-Access-Control-Allow-Source-Origin
Sid
X-Newrelic-App-Data
X-Nf-Request-Id
SID
X-Tb-Optimization-Total-Bytes-Saved
X-Via-Poph
X-Via-Popn
X-MCACHE
X-Via-Popv
X-Generated-In
X-Pod-Name
X-NWS-UUID-VERIFY
Server-ID
X-Refresh
X-Xrds-Location
X-Ig-Push-State
X-Akamai-Transformed
X-Cache-Date
X-Servedbyhost
X-Buckets
Env
X-Cs
X-DC
X-Pass-Why
X-Up
X-Edge-Pop
X-Release
X-Conf
X-MSEdge-Features
X-EC-Lua
X-Fpc
X-MSEdge-Flight
X-Dispatch
X-Microcachable
X-NC
My-App
X-Tumblr-Pixel-3
X-Dmc
X-Esi
X-Endurance-Cache-Level
X-Wa
X-RateLimit-Reset
X-Lambda-Id
Fastly-Drupal-Html
X-PX
X-ID
X-CS
X-TX-ID
CDN
X-Be
X-VCL-Version
X-Req
GeoIp-Country-Code
X-CACHE-AGE
Magicmarker
X-Zone
True-Client-IP
X-TRACE-ID
X-Webkit-CSP-Report-Only
X-NGINX-Cache
X-LB-ID
X-Wikidot-Static-Cache
X-Wikidot-Backend
X-CACHE-KEY
X-Vc
Hostname
X-Air-Source
X-TH-Server
CacheControlHeader
X-Air-Trace-Id
True-Client-Country-4JS
X-Air-Hostname
X-CSRF-TOKEN
X-Yandex-Sdch-Disable
X-Hyper-Cache
True-Client-Ip
X-CF-Lambda-Fn
X-Srv
X-Micro-Cache
X-CF-Lambda-Version
X-Op-Id-All
X-Alfa-Service
X-Vcl-Version
X-Air-Pt
X-HS-Status
Resin-Trace
Pramga
X-M-Reqid
X-M-Log
X-App
X-B3-Spanid
Path
X-Qnm-Cache
GeoIP-Country-Code
Tcn
C-Via
Tracecode
X-TrackingId
N-Cache
X-GeoIP-Region-Code
X-GeoIP-Country-Code
X-Varnish-Beresp-TTL
X-SERVER-NAME
WWW-Authenticate
X-Datacenter
X-PAYTM-SRV-ID
Esi-Enabled
X-Platform
X-Accel-Expires-Debug
X-Vercel-Cache
On-Server
X-Date
X-Vercel-Id
Fastcgi-X-Cache-Version
X-CLOUD-TRACE-CONTEXT
NtCoent-Length
X-Geo
X-Check-Cacheable
X-FPC
Proxy-Connection
X-Edge-Origin-Shield-Bytes
Yjs-Id
Section-Io-Origin-Time-Seconds
X-Akamai-Pragma-Client-IP
Hit
Section-Origin-Responded
Section-Io-Id
X-Edge-Origin-Shield-Region
Section-Io-Origin-Status
X-Webkit-Csp-Report-Only
X-Vtex-Remote-Cache
X-Via-CDN
X-Vtex-Processado-Em
X-Platform-Cluster
X-Platform-Router
X-Platform-Processor
X-WA
X-Old-Content-Length
FSS-Cache
X-RAMCache
GeoIP-Latitude
ENV
X-Edge-POP
X-Node-Id
X-Mly-Id
YJS-ID
Server-Id
X-LAGOON
X-Lb-Id
X-Response-By
Lb
X-SD-PageType
Powered-By
X-ServedByHost
User-Agent
X-Request-Start
X-API-Version
X-Cdn-Forward
X-AIR-PT
X-UA
X-Dw-Trace-Id
HIT
Cache-Key
X-Client-Ip
Cdn
X-PERF
X-LiteSpeed-Cache-Control
X-Via-PopN
X-Via-PopV
X-Via-PopH
X-Akamai-ERPolicy
X-Akamai-ERRuleID
X-From
X-ApacheServer
Srvid
X-Traceid
Locid
X-Instance-Name
X-FL-EDGE
X-Location
X-Via-Ucdn
X-Litespeed-Cache-Control
X-Proxy-CacheRZ
X-Render-Time
X-CUA
X-TT-LOGID
XkeyRZ
X-Cache-Ttl
X-FORWARDED-FOR
DynaTrace
Dnion-Transfer-Encoding
Server-Ttl
X-LI-UUID
X-LI-Proto
Geoip-Latitude
X-Li-Fabric
X-Li-Pop
X-Service-Response-Time
Sm-Log-Id
X-VarnishDD-TTL
X-Varnish-Authentication
X-RPM
X-RPS
Ohc-File-Size
X-HN
X-DW
X-DI
X-DSS
X-Director
X-RSL
X-LiteSpeed-Tag
X-Contensis-Viewer-Groups
X-Cache-ASPX
X-Webstats-RespID
PICS-Label
Location
X-CF-Powered-By
X-Proxy-Upstream
PFcat
X-DB
XServer
XM
X-Proxy-Cache-Hk
DT-Hot-News
Nginx-CQVIP
X-Wp-Cf-Super-Cache-Cache-Control
X-Wp-Cf-Super-Cache
X-Fastly-Cache-Hits
X-Fastly-Backend-Reqs
X-HostName
X-Cdn-Request-ID
X-Request-Url
X-Server-IP
X-B3-ParentSpanId
Wpo-Cache-Message
Vha6-Origin
X-Lb-Nocache
Wpo-Cache-Status
X-Ips-Loggedin
X-Cache-Ngx
Wp-Super-Cache
CountryCode
Warning
X-Yottaa-OS
CF-Cached-On
X-Test
X-Ramcache
X-DataCenter
X-ElasticPress-Query
SRV
Fastcgi-Cache-Ttl
Req-ID
X-Moov-Xdn-Version
X-Moov-T
WZWS-RAY
X-Mg-Cache