Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Accept-Ranges
Expect-CT
X-XSS-Protection
Pragma
X-Powered-By
CF-RAY
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-Xss-Protection
X-Download-Options
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
CF-Ray
X-Adblock-Key
X-Request-ID
Access-Control-Allow-Credentials
X-FRAME-OPTIONS
X-Request-Id
X-Permitted-Cross-Domain-Policies
X-AspNet-Version
Alt-Svc
X-Runtime
Content-Security-Policy-Report-Only
X-DNS-Prefetch-Control
X-Drupal-Cache
X-Check
X-Cache-Status
X-Generator
X-Cacheable
Timing-Allow-Origin
X-Iinfo
X-Envoy-Upstream-Service-Time
X-Content-Security-Policy
P3p
X-Drupal-Dynamic-Cache
Feature-Policy
Content-Encoding
Upgrade
Access-Control-Expose-Headers
Status
X-CDN
X-AspNetMvc-Version
Access-Control-Max-Age
X-Ua-Compatible
X-Via
Server-Timing
X-UA-Device
X-Robots-Tag
Request-Context
X-Turbo-Charged-By
X-Cache-Group
X-Amz-Request-Id
EagleId
X-Amz-Id-2
X-Backend
Keep-Alive
X-AH-Environment
X-Proxy-Cache
X-Server
X-Ws-Request-Id
X-Age
Host-Header
X-Hacker
Cf-Edge-Cache
X-Vhost
X-Server-Powered-By
X-Rq
X-Varnish-Cache
Allow
X-Dispatcher
X-Amz-Version-Id
Grace
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-LiteSpeed-Cache
X-OneAgent-JS-Injection
X-WebKit-CSP
X-Dns-Prefetch-Control
Accept-CH
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Page-Speed
Cf-Apo-Via
X-Device
Cf-Railgun
X-Aws-Lambda-Call-Status
X-Server-Id
X-Host
X-Node
X-Pingback
X-Cache-Spec
X-Nginx-Cache-Status
X-Akam-SW-Version
Surrogate-Control
EagleEye-TraceId
X-Backend-Server
Request-Id
X-Readtime
X-Cache-Lookup
X-Ruxit-JS-Agent
X-HW
X-Cloud-Trace-Context
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Content-Security-Policy-Report-Only
X-Trace
X-Application-Context
Accept-CH-Lifetime
X-Response-Time
Permissions-Policy
Fastly-Restarts
X-Nginx-Upstream-Cache-Status
X-Mod-Pagespeed
X-Edge
X-CST
Accept-Ch-Lifetime
Content-Location
X-WebKit-CSP-Report-Only
X-Content-Type
X-Mcache
X-Url
X-MS-InvokeApp
X-Country
X-Clacks-Overhead
Rating
X-ECACHE
X-Midtier
X-Amz-Server-Side-Encryption
X-TtlSet
X-PC
X-Vname
X-Litespeed-Cache
RTSS
X-VARITI-CCR
Cache-Tag
X-Vcap-Request-Id
X-D2id
Origin-Trial
X-Element-Page-Cache
Verso
X-Server-Name
X-Cdn-Fetch
X-Kinja-Revision
X-Kinja-Server
X-Use-Magma
X-Kinja-Build
X-Kinja
X-Exp-Variant
X-GoogleNews-Bot
X-Exp-Id
X-Ac
X-ESI
X-Rack-Cache
X-Varnish-TTL
X-Cnection
X-Powered-By-Plesk
Service-Worker-Allowed
X-Ttl
X-Cache-TTL
X-B3-TraceId
X-GitHub-Request-Id
Xkey
X-Navigation-Version
X-Client-IP
X-Abt-Application-Version
X-SharePointHealthScore
SPRequestGuid
X-Amz-Rid
Edge-Control
X-NWS-LOG-UUID
X-Cached
Arr-Disable-Session-Affinity
X-Mg-S
X-Px
X-Instrumentation
SPIisLatency
SPRequestDuration
X-Kraken-Loop-Name
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Browser-Type
X-Server-Lifecycle-Phase
X-Upstream
X-Correlation-Id
X-Cache-Key
X-Dw-Request-Base-Id
Pagespeed
Display
X-Fastcgi-Cache
X-Sol
X-Middleton-Display
Content-MD5
X-SRCache-Fetch-Status
X-SRCache-Store-Status
Access-Control-Request-Method
Edge-Cache-Tag
X-Goog-Hash
X-XRDS-Location
X-NF-Request-ID
Front-End-Https
X-Country-Code
X-Forwarded-For
X-Daa-Tunnel
X-Version
Public-Key-Pins
AR-SID
AR-ATIME
AR-PoweredBy
AR-CACHE
AR-Request-ID
TCN
X-Powered-CMS
X-T
X-Jurisdiction
X-HP-Webp
X-HP-Trace-Id
X-RateLimit-Remaining
X-Recruiting
X-MSEdge-Ref
X-Id
X-Content-Digest
X-Accel-Expires
X-Middleton-Response
Response
X-Shield-Request-Id
X-Ser
TP-L2-Cache
TP-Cache
MRF-Tech
X-B3-TraceId-Primal
Mrf-Cache-Status
X-Amzn-Trace-Id
Nginx-Cache
S
X-Request-Processing-Time
X-Request-Received
X-HS-Cache-Config
X-HS-Hub-Id
Server-Node
X-HS-Combine-CSS
X-HS-Content-Id
Cache-Status
X-Fastly-Request-ID
X-Distributor
X-Hits
X-Ratelimit-Limit
MicrosoftSharePointTeamServices
X-Kinsta-Cache
X-Edge-Location-Klb
Cache-Tags
Fastcgi-Cache
X-Grace
Server-Name
Alternate-Protocol
X-DataDome
X-Protected-By
X-LB-Cache
X-Ezoic-Cdn
X-DIS-Request-ID
X-Ruxit-Js-Agent
X-Ua-Browser
X-Ratelimit-Remaining
X-Origin-Server
X-Geo-Country
X-TEC-API-ROOT
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-Microsite
X-Request-Handler-Origin-Region
X-Frontend
Cross-Origin-Opener-Policy
X-Rid
X-Ratelimit-Reset
Filterid
X-Debug-Info
X-Varnish-Backend
X-Www-Served-By
X-Git-Hash
X-FastCGI-Cache
Healthy
X-Logged-In
Cleartype
X-FB-Debug
Payment
X-Forwarded-Proto
X-NGENIX-Cache
X-Page-Id
X-Load-Cache
X-LLID
Charset
X-Origin-Cache
X-B3-Sampled
X-Webkit-Csp
X-Hostname
X-Cluster-Name
Content-Disposition
X-ASPNET-VERSION
DC
MS-Author-Via
X-VCache
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Goog-Metageneration
X-GUploader-UploadID
X-PressLabs-Stats
X-TTL
X-Upgrade-Enabled
X-Oracle-Dms-Rid
X-Oracle-Dms-Ecid
Access-Control-Allow-Method
X-Proxy
Retry-After
X-F-Cache
Realpath
Accept-Charset
Cross-Origin-Resource-Policy
X-Activity-Id
X-Type
Accept-Ch
X-Amz-Replication-Status
Paypal-Debug-Id
X-AppVersion
X-Az
X-B-Cache
X-Signature
X-Revision
X-Seen-By
X-Contextid
X-Is-Crawler
X-Request-Guid
X-Flags
X-Amz-Meta-S3cmd-Attrs
X-Hosted-By
X-Providence-Cookie
Viewport
X-Route-Name
X-Aspnet-Duration-Ms
X-Azure-Ref
X-B
X-Whom
X-App-Environment
X-TT
X-Wix-Request-Id
X-Fb-Rlafr
X-Varnish-Server
X-DynaTrace
Amp-Access-Control-Allow-Source-Origin
X-Language
Surrogate-Key
Count-Hit
X-ORACLE-DMS-RID
X-Aspnetmvc-Version
X-ORACLE-DMS-ECID
X-B3-Traceid
X-Source
Referer-Policy
X-Akamai-Edgescape
X-Template
X-RateLimit-Limit
X-App-Server
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Mobile
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-Goog-Generation
X-Cache-Control
Host
X-COUNTRY
X-EdgeConnect-Cache-Status
X-Varnish-Grace
Version
X-Cache-Rule
X-HTML-Minification-Powered-By
X-N
SRV
X-Magnolia-Registration
X-Oneagent-Js-Injection
X-Tumblr-Pixel-1
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Response-Served-From
X-Tumblr-User
X-Original-Request-Id
X-Varnish-Age
X-UUID
VIX-Pulpo-Node
X-Cache-Status-Check
SD-X-WS
X-RTag
X-Cache-Time
X-Cache-Expired-At
Access-Control-Request-Headers
Section-Io-Cache
X-Envoy-Decorator-Operation
X-Rule
VIX-Pulpo-Upstream-Status
MS-CV
Ms-Operation-Id
Refresh
X-ProcessESI
X-Jobs
X-RemovedCookies
Protected
X-Adobe-Content
Akamai-GRN
X-Cacheable-TTL
X-Page-View
X-Adobe-Loc
X-Cache-Grace
X-Framework
X-Content-Powered-By
Url
X-L-Path
X-NYM-Debug-Backend
X-Device-Type
X-Status
X-Http-Reason
GEO-INFO
NGB
X-FW-Hash
X-FW-Dynamic
X-G
X-FW-Static
X-Instance
X-FW-Server
X-FW-Serve
X-Is-Bot
X-FW-Type
X-Rendered-As
X-Environment-Context
X-FW-Version
X-Servername
X-Trace-Id
X-Backend-Name
X-User-Agent
X-Akamai-Request-ID2
X-Debug-IsConnected
X-Drupal-Cache-Contexts
X-CDN-Forward
X-Debug-IsPreview
X-Cache-Age
X-Drupal-Cache-Tags
CDN-RequestId
From-Origin
WPO-Cache-Message
WPO-Cache-Status
X-Newrelic-App-Data
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Region
X-Cache-Hit
X-Nginx-Cache
Accept-Language
Front
X-Tb
Country
Pinterest-Generated-By
X-Pinterest-Rid
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Tt-Logid
Pinterest-Version
X-Node-Name
X-Buckets
Backend
Fastly-Drupal-HTML
X-Content-Options
X-Times
Fastly-SWR
X-Real-IP
Fastly-SIE
X-Fastly-Request-Id
X-Unique-Id
X-VC-Cache
X-Mode
Uber-Trace-Id
X-DynaTrace-JS-Agent
X-Zen-Fury
X-Cache-Operation
X-TIME
Content-Secure-Policy
X-Tec-Api-Origin
X-Tec-Api-Root
X-Tec-Api-Version
X-RN-RSRV
X-UPSTREAM-Address
X-Tumblr-Pixel-2
Meta-Geo
Filters
X-Rewrite-Enabled
X-Generation-Time
CF-IPCountry
X-Content-Age
X-Rocket-Nginx-Serving-Static
X-Section
X-IPS-LoggedIn
X-Access
Onion-Location
X-Web-Node
X-Cache-Server
X-Proxy-Cache-Info
Webserver
X-Format
X-Soup
X-Via-Fastly
X-Sql-Duration-Ms
X-Sucuri-Cache
X-Sucuri-ID
Cache-Hits
Apigw-Requestid
Azure-SiteName
X-Cms-Context
Azure-RegionName
X-Sql-Count
X-Cache-Host
Azure-Version
X-Adobe-Source
X-Cache-Action
X-Debug
X-PHP-Backend
X-Reqid
X-Say-TTL
X-SayCDN-TTL
Azure-SlotName
X-Say-Cacheable
X-Proxy-Cache-Status
Azure-InstanceId
X-Amzn-Remapped-Content-Length
X-Cache-TTL-Remaining
X-SRV
X-Air-Source
X-Air-Trace-Id
X-Air-Hostname
Webcakes-App-Version
Webcakes-App-Name
Webcakes-Region
X-Forwarded-Host
Web-Mar-Node
X-Labrador-Cache-Channel
X-Handled-By
TWC-Locale-Group
TWC-Connection-Speed
S-Rt
Property-Id
TWC-Device-Class
TWC-GeoIP-Country
X-Locale
TWC-GeoIP-LatLong
TWC-Privacy
X-PHP-Host
X-Proto
X-Ms-Version
X-Ms-Request-Id
X-ProxyCache-Key
X-ProxyCache-Status
X-VWS-Id
X-UA-Device-Type
X-R9-Blue-Green-Version
X-LJ-Flow-ID
X-IPLB-Request-ID
X-Varnish-Beresp-Grace
X-Site-Version
X-Server-W
X-AWS-Id
X-BYPASS-REASON
X-IPLB-Instance
X-Cluster-Node
X-Cluster
X-Origin-Hint
X-Skip-Cache
Cache-Name
DB-Nickname
Node
X-No-Session
X-Time
X-LSADC-Cache
X-LAGOON
Locale
X-JoinUs
X-Routing-Service
X-Detected-As
X-Proxy-Build
X-Proxied
X-Timing-Wait
X-FB-TRIP-ID
X-Edge-Location
X-Extlb
ServedBy
X-Urbn-Site-Id
Selected-Fe
X-Urbn-Context-Path
X-SaId
X-Zipkin-Id
Mn-Server-Ip
Cross-Origin-Window-Policy
X-Xfnlog-Site
X-WP-CF-Super-Cache-Cache-Control
CDN-EdgeStorageId
X-Ua
CDN-Cache
X-GeoCode
X-WP-CF-Super-Cache
X-GeoCountry
WP-Super-Cache
CDN-PullZone
Liferay-Portal
CDN-Uid
CDN-CachedAt
Mime-Version
CDN-RequestCountryCode
X-URL
X-CACHE-AGE
ServerID
Fastcgi-Useragent
X-Optimistic-Header
X-Server-ID
X-Tumblr-Pixel-3
Source
X-Request-Time
X-Hl-Ver
X-ECache
X-XRDS-LOCATION
X-Redis-Cache
X-Origin-Date
X-Cache-Debug
X-Uri
X-TNCMS
X-Generated-By
Upgrade-Insecure-Requests
Xserver
X-GEO
X-Loop
X-Varnish-Hits
X-Akamai-Transformed
CF-Cached-On
X-Mg-Request-UUID
X-Presslabs-Stats
X-Director
Countrycode
X-ARC
Xet-Cookie
X-Tx-Id
X-Varnish-Beresp-Ttl
X-TA-CDN-Provider
X-Pass-Why
Frame-Options
X-App-Version
X-FireWall-Port
X-Webkit-CSP-Report-Only
X-NWS-UUID-VERIFY
X-Newrelic-Synthetics
X-Origin-TTL
X-Origin-CC
X-Storage
Cache-Tv-Group
X-Tid
X-Varnish-Cache-Hits
X-DC
X-Varnish-Ttl
X-Alternate-Cache-Key
X-ShopId
X-ShardId
X-Service
X-Shopify-Stage
X-Storefront-Renderer-Rendered
X-Varnish-Hostname
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-RM-Cache-TTL
X-Datadog-Parent-Id
X-Endurance-Cache-Level
X-Datadog-Sampling-Priority
X-ServerID
X-Datadog-Sampled
Environment
X-Datadog-Trace-Id
Release
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
Thinkindot-Control
WWW-Authenticate
X-A
TDXMobile
T-Server
Req-Svc-Chain
Sslversion
Surrogated-Key
Rendered-Blocks
Odigeo-Trace-Id
DCR-Processing-Time-Ms
Edge-Cache
Gannett-Cam-Experience-Id
DCR-Decision-By
Candidate-Md5Url
A
BehaviorPad-Version
X-Rojux
Host-ID
Ngx.Var.Host
X-A-Ccd
Origin
Meta-Geo-Continent
Memcached
Lang
MD5-Digest
Redirect-Candidate
X-A-Wwc
X-Level-Front-Cache
X-Generated-On
X-Gdpr
X-Frame-Option
X-SRCache-Key
X-Served-From
X-Cache-NE
X-Vdms-Path
X-TIM-N
X-CMSURLCustom
X-External-Request-Id
X-Epic-Correlation-Id
X-Developer
X-Core-Value
X-Destination
X-D
X-Ec-Fail
X-Thinkindot-L3
X-S
X-Ec-GeoHdr
X-Conf
X-Test
X-Vdms-Version
X-Loc
X-Platform-Processor
X-BBC-Edge-Cache-Status
X-S-Cookie
X-Bc-Bl
X-B-Cookie
X-Platform-Router
X-A-Dcw
X-Processor
X-A-Dgt
X-Aed
Xc-Version
X-BCube-Filmed-By
X-Nyt-Route
X-Mobile-URL
X-Mid
X-ScT
X-VG-TLSProxy
X-Origin-Time
X-S-Maxage
X-Cache-Info
X-Platform-Cluster
X-We-Are-Hiring
X-A-Dam
X-Application
Server-Info
SID
X-Request-Host
X-B3-Spanid
X-Ec-Custom-Error
X-Developers
X-DefHash
X-CUA
X-DefElseHash
X-Fetched-On
X-Geo-Header
X-Human
X-INCAP-ABP
X-HS-Content-Campaign-Id
X-Has-Esi
X-GeoIP-City
X-Fmm-Version
X-Core-Mission
Tube-Got-Results
Tube-Return
Tube-Got-Eval
Tube-Get-Contents
Ssr
State
Vix-Hermes-Req-Id
X-Akamai-Device-Characteristics
X-Cdn-Srv
X-Clara-WADP
X-Cdn-Origin
X-Cache-Bucket
X-Auto-Login
X-Bip
X-Is-Gdpr
X-Old-Content-Length
X-WA-Info
X-WADP-Cache
X-VServer
X-Vmg-Version
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
X-Worker
X-WP-CF-Super-Cache-Active
X-Sigma
X-Sigma-Backend
X-Rocket-Build-Number
X-Location
Cache-Host
X-Httpd
X-Varnish-CookieHashed-On
X-Varnish-Beresp-Status
X-Platform-Server
X-Req
X-Origin-Response-Time
X-Org
X-NodeID
Server-Host
X-Restarts
X-SB
X-SVT-ORM-VERSION
X-Thanos
X-SVT-ORM-RULES
X-Sn-Servicetimems
X-SD-PageType
X-JWT-State
X-Pool
Decoy-Debug-Key
Country-Code
Cluster
Decoy-Debug-Status
Decoy-Debug-TTL
Fastly-GeoIP-CountryCode
Fastly-Backend-Name
DSUID
CloudFront-Viewer-Country
Click-Count-Error
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
AKAMAI
Apple-News-Services-Request-Url
C-Via
Click-Count-Action-Start
Cache-Key
Magicmarker
Apple-News-Services-Handled
X-AIR-PT
Section-Io-Origin-Time-Seconds
X-Parent-Response-Time
Section-Io-Origin-Status
Section-Io-Id
Section-Origin-Responded
X-Minions-Version
X-Device-Os
X-Men
Cmsid
X-LB-NoCache
X-Nananana
X-Node-Id
Producers
X-Origin
X-Op-Id-All
X-Date
Cmstype
X-NCache
Datacenter
Server-Ext
X-Gamma-Serve
X-Fastly-Backend
X-Esi-Check
X-DPWN-IS-SECURE
X-Gen-Mode
X-GeoIP-Country-Code
X-Owner
X-Dispatcher-Number
X-Hnp-Log
X-Gzip
X-GeoIP-Region-Code
X-Dispatcher-Server
X-Region-Sid
X-Wix-Viewer-Type
CacheControlHeader
Sever-Int
X-Varnishpool
On-Server
Adler-Geo
Gh-Request-Id
Kp-EeAlive
X-Hash
X-Pubstack
X-GeoIP
We-Hiring
Mail-Subject
NM-Fastcgi-Cache
X-Variation
X-Var-Ttl
Platform
X-Scale
Cache-Provider
X-Request-Start
X-Qloud-Router
Server-Hostname
Pics-Label
X-Slack-Backend
X-Up
X-V-Cache
Origin-CC
Origin-EX
X-Slack-Shared-Secret-Outcome
CDCHOST
X-Nginx-Cache-Key
Wxu-Next-Commit
Wxu-Next-Hostname
NGX
X-Accel-Buffering
Machine
X-Block-Status
X-Cache-Backend
Is-Eu
X-Cache-Id
Wxu-Next-Region
X-App
User-Cache-Control
Web-Mar-Region
X-Ckpd-Fst-Backend
X-Azure-Ref-OriginShield
L
X-Accel-Expires-Debug
X-Ad-Defer-Variation
X-Refresh
X-CacheTTL
Fastly-SSL
X-HN
X-Planisys-CDN-Rules
X-FC-Vary-Parameters
PFcat
X-Planisys-CDN-Cache
X-Planisys-CDN-TTL
X-Cache-Tags
Svr
X-Forwarded-Site
X-Mvc-Supplant-Cachable
X-Server-IP
X-Cache-Date
X-Platform
X-VarnishDD-TTL
X-Irp-Debug
Canary
X-Cache-FS-Status
X-CGP
X-Microcachable
X-Eu-Site
HA-Ipaddr
X-Csrf-Jwt
X-Cache-Remote
Ha-Gx-Prefs
L5d-Success-Class
X-CSRF-Token
X-Trace-ID
X-Via-Popn
X-Via-Popv
X-Via-Poph
GeoIP-Latitude
Env
X-Esi
X-Servedbyhost
X-Mly-Id
X-Mvc-Supplant-OutputCached
Load-Balancing
X-Tb-Optimization-Total-Bytes-Saved
Cdn
HostName
X-RCS-CacheZone
X-Aicache-OS
X-Cached-By
X-HA-Backend
X-Zone
Server-ID
X-Fastly-Cache
X-Nc
X-Api-Version
X-VC
X-Instance-Name
X-Origin-Expires
X-AK-Request-ID
X-ND-Cache
Cdncip
X-Wa
Cdnsip
Time
Memory
X-Vc
X-DataCenter
X-Release
X-Response-By
X-Fpc
Cache
X-HS-Status
X-NGINX-Cache
X-Webkit-CSP
X-ZONE
X-Generated-In
X-Gateway-Request-Id
X-API-Version
X-From
Locid
Expect-Staple
X-Gateway-Cache-Key
X-Gateway-Skip-Cache
X-Gateway-Cache-Status
X-FL-EDGE
Srvid
X-LB-ID
X-FL-QIT-DEBUG
X-Edge-Pop
X-NewRelic-App-Data
X-Via-CDN
X-Via-NSCOPI
X-Check-Cacheable
Hostname
X-Cache-Enabled
X-Provided-By
NtCoent-Length
X-Correlation-ID
X-Nf-Request-Id
X-CS
X-Via-Edge
Eomportal-Instance
Edge-Copy-Time
X-Hcs-Proxy-Type
X-Client-Ip
X-Via-SSL
X-APP-VERSION
X-CCDN-CacheTTL
X-CCDN-Origin-Time
X-CSRF-TOKEN
X-Micro-Cache
X-Vgn-Hpd-Cached
X-Vgn-Hpd-Variations-Key
GeoIp-Country-Code
X-Vgn-Hpd-Ssi
Ngx-Var-Key
XkeyRZ
X-Proxy-CacheRZ
X-Lambda-Id
AMP-Access-Control-Allow-Source-Origin
OT-Force-Account-Verify
X-Via-JSL
X-Debug-Cache-Store
X-Air-Pt
X-Debug-Cache-Fetch
X-VCL-Version
True-Client-IP
X-Amz-Meta-Cb-Modifiedtime
X-Request-URI
X-MCACHE
X-Vcl-Version
X-SIPLIST1
IsBot
X-B3-SpanId
X-Srv
X-Dc
VNS-Cache
X-Cache-NGX
CPC-Age
X-Info
VNS-Age
CPC-Cache
X-Vtex-Remote-Cache
X-EC-Lua
Sid
X-Render-Time
True-Client-Ip
X-Cs
X-TH-Server
Uri
X-Fastly-Country-Code
Path
X-VCT
Srv
Resin-Trace
Location
X-ATG-Version
Request-ID
GeoIP-Country-Code
X-Cache-Expires
X-Oss-Object-Type
X-Oss-Storage-Class
Esi-Enabled
X-Oss-Request-Id
X-Oss-Server-Time
X-Oss-Hash-Crc64ecma
X-Upstream-Ct
X-RateLimit-Reset
X-Upstream-Ht
X-Contensis-Viewer-Groups
Fastly-Drupal-Html
X-Cache-Type
X-MSEdge-Flight
X-Cache-ASPX
X-CLOUD-TRACE-CONTEXT
X-MSEdge-Features
X-Accel-Version
CDN
X-Varnish-Authentication
Cross-Origin-Opener-Policy-Report-Only
M-TraceId
X-Edge-POP
Servername
YJS-ID
X-CF-Lambda-Version
X-CF-Lambda-Fn
X-Cdn-Request-ID
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-PAYTM-SRV-ID
X-Udemy-Cache-App-Namespace
X-TX-ID
X-Pod-Name
Timeexpire
X-Moov-Xdn-Version
X-Moov-T
X-Scheme
X-Lb-Id
X-FPC
Traceparent
X-Varnish-Beresp-TTL
X-Akamai-Pragma-Client-IP
X-ApacheServer
X-Service-Response-Time
XServer
X-Datacenter
Sm-Log-Id
X-Datadome
X-Viewer-Country
HIT
N-Cache
X-Cdn-Cache-Status
RNT-Time
RNT-Machine
X-PERF
X-Wikidot-Backend
CountryCode
X-Wikidot-Static-Cache
LB
X-Tenant
X-SERVER-NAME
X-Orig-Expires
X-Bl-Debug
X-Forwarded-Path
X-Shop-Environment
X-WA
X-CDN-Cache-Status
X-Geo
X-MP-GENERATED-AT
Powered-By
X-B3-Trace-ID
X-Srcache-Fetch-Status
X-Srcache-Store-Status
X-CACHE-KEY
X-NAPM-TraceId
X-ID
Ohc-File-Size
X-NC
Proxy-Connection
Server-Id
FSS-Cache
X-ServedByHost
X-Ha-Backend
X-App-Name
X-Policy
X-TraceId
Rip
ENV
X-LiteSpeed-Cache-Control
Yjs-Id
Epwk-X-Cache
X-Snapshot-Date
X-Via-PopH
X-Cdn-Forward
X-Dw-Trace-Id
V-Age
X-Via-PopV
Geoip-Latitude
X-Hyper-Cache
X-Amz-Meta-Opti
Tracecode
True-Client-Country-4JS
X-Via-PopN
WZWS-RAY
X-Clientip
X-M-Reqid
X-M-Log
X-VG-WebCache
X-Serial
Inserted-Into-Cache-At
X-Fastly-Backend-Reqs
Content-Script-Type
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
Content-Style-Type
X-Swift-Error
X-Vgn-Hpd-Reason
X-RAMCache
X-Lb-Nocache
X-Acquia-Application-UUID
User-Agent
X-B3-ParentSpanId
X-Acquia-Application-Trace
X-Acquia-Purge-Tags
X-Acquia-Site
XM
X-B3-Parentspanid
X-Qnm-Cache
Ngx
Ec-Rule-Version
X-Wp-Cf-Super-Cache
X-Wp-Cf-Super-Cache-Cache-Control
X-F-Status
X-UA
Serverid
X-Lsadc-Cache
X-TT-LOGID
X-Webstats-RespID
Hit
X-Fastly-Cache-Hits
Lb
X-Mid-Debug-Cache-Key
X-Cache-Ngx
X-UP
Cneonction
Warning
X-IPS-Cached-Response
MIME-Version
My-App
X-Th-Server
X-Mid-Debug-Cache-Disk
X-Request-URL
X-LiteSpeed-Tag
X-MiniProfiler-Ids
X-Stale