Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Link
CF-Cache-Status
Cf-Request-Id
Accept-Ranges
ETag
CF-RAY
Expect-CT
Pragma
X-Powered-By
X-Cache
X-XSS-Protection
Via
Age
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Xss-Protection
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
X-FRAME-OPTIONS
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-Adblock-Key
X-AspNet-Version
X-Permitted-Cross-Domain-Policies
X-Runtime
Alt-Svc
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Check
X-Cache-Status
X-Generator
X-DNS-Prefetch-Control
CF-Ray
X-Cacheable
Timing-Allow-Origin
X-Iinfo
X-Envoy-Upstream-Service-Time
Feature-Policy
Status
X-Content-Security-Policy
X-Drupal-Dynamic-Cache
Content-Encoding
X-AspNetMvc-Version
X-CDN
Access-Control-Expose-Headers
Upgrade
X-XSS-PROTECTION
P3p
Access-Control-Max-Age
X-Dns-Prefetch-Control
X-Ua-Compatible
X-Request-ID
X-Via
Server-Timing
X-Cache-Group
X-Robots-Tag
X-UA-Device
Request-Context
Keep-Alive
X-Amz-Request-Id
X-Turbo-Charged-By
X-AH-Environment
X-Backend
X-Ws-Request-Id
X-Amz-Id-2
X-Proxy-Cache
X-Akamai-Path-Stats
X-Age
Host-Header
X-Server-Powered-By
X-Hacker
X-Server
EagleId
X-Rq
X-Vhost
X-Varnish-Cache
Grace
X-Dispatcher
X-Amz-Version-Id
X-LiteSpeed-Cache
Cf-Edge-Cache
X-Swift-SaveTime
X-Swift-CacheTime
Allow
Ali-Swift-Global-Savetime
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Nginx-Cache-Status
X-Device
X-Page-Speed
X-WebKit-CSP
X-Aws-Lambda-Call-Status
X-Host
X-OneAgent-JS-Injection
X-Node
X-Server-Id
EagleEye-TraceId
X-Pingback
X-Cache-Spec
Request-Id
Surrogate-Control
Cf-Railgun
X-Akam-SW-Version
X-Backend-Server
X-Readtime
Accept-CH
X-Cache-Lookup
X-Response-Time
Accept-CH-Lifetime
X-HW
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Content-Security-Policy-Report-Only
X-Application-Context
Content-Location
Rating
X-Trace
Fastly-Restarts
X-Cloud-Trace-Context
X-WebKit-CSP-Report-Only
X-Url
X-Clacks-Overhead
X-Country
X-Edge
X-Amz-Server-Side-Encryption
X-B3-TraceId
X-MS-InvokeApp
Accept-Ch
X-Rack-Cache
Edge-Control
Accept-Ch-Lifetime
X-Ruxit-JS-Agent
X-Vname
X-TtlSet
X-PC
X-ESI
X-Content-Type
X-Vcap-Request-Id
Xkey
X-Mod-Pagespeed
X-CST
X-Mcache
X-Varnish-TTL
X-D2id
X-VARITI-CCR
X-Nginx-Upstream-Cache-Status
X-Amz-Rid
X-Kinja-Revision
X-Kinja-Build
X-Use-Magma
X-GoogleNews-Bot
X-Cdn-Fetch
X-Exp-Id
X-Exp-Variant
X-Kinja
X-Kinja-Server
X-GitHub-Request-Id
Verso
RTSS
Cache-Tag
X-Powered-By-Plesk
X-ECACHE
X-FastCGI-Cache
X-Cached
X-Upstream
X-Navigation-Version
Service-Worker-Allowed
X-Version
X-Client-IP
X-Dw-Request-Base-Id
X-Px
X-Abt-Application-Version
X-Ruxit-Js-Agent
X-Oneagent-Js-Injection
X-Cnection
Public-Key-Pins
X-Ac
X-Ser
Arr-Disable-Session-Affinity
X-Sol
X-Middleton-Display
Pagespeed
Display
X-Server-Name
SPRequestGuid
X-SharePointHealthScore
X-Element-Page-Cache
X-Kraken-Loop-Name
X-Instrumentation
X-Server-Lifecycle-Phase
X-NF-Request-ID
X-Ttl
SPRequestDuration
SPIisLatency
X-Country-Code
X-Cache-TTL
X-RateLimit-Remaining
X-NWS-LOG-UUID
X-Midtier
X-Goog-Hash
Response
X-Middleton-Response
X-Cache-Key
X-Edge-Location-Klb
X-Kinsta-Cache
Permissions-Policy
Access-Control-Request-Method
X-Forwarded-For
X-DataDome
Content-MD5
X-Correlation-Id
X-Powered-CMS
X-ORACLE-DMS-RID
X-Shield-Request-Id
X-ORACLE-DMS-ECID
X-MSEdge-Ref
Edge-Cache-Tag
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-T
X-RateLimit-Limit
Front-End-Https
X-HP-Trace-Id
X-Recruiting
X-Jurisdiction
X-HP-Webp
AR-Request-ID
AR-SID
AR-ATIME
AR-PoweredBy
AR-CACHE
TP-L2-Cache
TP-Cache
Nginx-Cache
X-Accel-Expires
X-Daa-Tunnel
MicrosoftSharePointTeamServices
X-Grace
MRF-Tech
Mrf-Cache-Status
X-B3-TraceId-Primal
TCN
X-Id
X-Mg-S
X-Request-Received
Filters
X-Request-Processing-Time
X-TEC-API-VERSION
X-HS-Content-Id
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-HS-Cache-Config
X-HS-Combine-CSS
Server-Node
X-Content-Digest
X-HS-Hub-Id
X-Hits
X-LLID
X-Fastly-Request-Id
S
X-Frontend
X-Distributor
X-Amzn-Trace-Id
Server-Name
Cache-Status
X-Protected-By
X-TTL
X-Webkit-Csp
X-PressLabs-Stats
X-Geo-Country
MS-Author-Via
Fastcgi-Cache
X-LB-Cache
X-Request-Handler-Origin-Region
X-Microsite
X-Language
X-Ua-Browser
X-Ab
X-Ezoic-Cdn
X-Origin-Server
X-Forwarded-Proto
Cross-Origin-Opener-Policy
Filterid
Charset
X-Seen-By
Host
X-F-Cache
X-FB-Debug
X-B3-Sampled
X-Page-Id
X-Git-Hash
X-Ratelimit-Reset
Realpath
X-Amz-Meta-S3cmd-Attrs
Payment
X-XRDS-Location
X-Litespeed-Cache
Count-Hit
X-ASPNET-VERSION
Accept-Charset
X-Cache-Age
X-Cluster-Name
X-VCache
X-Fastcgi-Cache
X-DynaTrace
Alternate-Protocol
X-Origin-Cache
Surrogate-Key
Cache-Tags
X-NGENIX-Cache
X-Browser-Type
X-Erf-Bev-Bev-Is-Generated
X-AppVersion
X-Erf-Bev-Bev
X-Activity-Id
Retry-After
X-Az
X-Content
Cleartype
X-Rid
X-Template
X-Www-Served-By
X-Webkit-CSP
X-Proxy
X-Node-Name
X-App-Environment
X-Varnish-Backend
ServerID
X-Signature
X-Upgrade-Enabled
X-Amz-Replication-Status
Access-Control-Allow-Method
X-B-Cache
X-Wix-Request-Id
X-Type
X-Route-Name
X-Aspnet-Duration-Ms
X-Drupal-Cache-Tags
X-Flags
X-Is-Crawler
Paypal-Debug-Id
X-Providence-Cookie
DC
X-Request-Guid
X-Varnish-Grace
X-Debug
X-Tb
X-TT
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-B
X-Logged-In
X-DIS-Request-ID
Frame-Options
X-Mobile
Cf-Apo-Via
X-Content-Options
X-Hostname
X-Envoy-Decorator-Operation
X-Load-Cache
X-Goog-Generation
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
X-GUploader-UploadID
X-Cache-Control
X-Source
X-Revision
Country
X-N
X-Pinterest-Rid
Pinterest-Version
Pinterest-Generated-By
X-Kong-Proxy-Latency
X-Contextid
X-Kong-Upstream-Latency
X-User-Agent
X-Magnolia-Registration
Referer-Policy
Amp-Access-Control-Allow-Source-Origin
Viewport
X-Whom
X-COUNTRY
X-XRDS-LOCATION
X-EdgeConnect-Cache-Status
X-Restarts
X-Response-Served-From
X-Original-Request-Id
X-Varnish-Age
X-Cache-Rule
X-Mid
NGB
Node
Refresh
Content-Disposition
X-Framework
X-Unique-Id
X-Cache-TTL-Remaining
X-Ratelimit-Remaining
Akamai-GRN
X-L-Path
X-Debug-IsPreview
X-Instance
X-Akamai-Request-ID2
X-Drupal-Cache-Contexts
X-Page-View
X-Real-IP
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Varnish-Server
Access-Control-Request-Headers
Url
Uber-Trace-Id
X-Debug-IsConnected
X-Environment-Context
X-Cache-Time
X-Jobs
VIX-Pulpo-Node
X-Servername
X-Cacheable-TTL
X-Fastly-Request-ID
X-Rendered-As
VIX-Pulpo-Upstream-Status
X-Is-Bot
X-NYM-Debug-Backend
X-Cache-Grace
X-Mg-Request-UUID
Countrycode
X-Adobe-Loc
X-Adobe-Content
X-Debug-Info
X-G
X-Status
X-App-Server
Version
X-Server-ID
X-Content-Powered-By
X-ProcessESI
X-RemovedCookies
X-Http-Reason
X-CDN-Forward
Protected
X-Tt-Logid
X-APP-VERSION
X-IPLB-Request-ID
X-IPLB-Instance
X-Trace-Id
X-Hosted-By
Accept-Language
Liferay-Portal
X-Device-Type
Healthy
X-Nginx-Cache-Key
X-Cache-Expired-At
Srv
X-Ratelimit-Limit
Fastcgi-Useragent
X-FW-Hash
X-Via-JSL
X-FW-Serve
X-FW-Dynamic
X-FW-Static
X-FW-Server
X-FW-Type
X-Time
X-RTag
MS-CV
Ms-Operation-Id
X-UUID
X-Cache-Hit
X-Tumblr-Pixel
X-Azure-Ref
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-Cache-NGX
X-Tumblr-User
X-Mobile-URL
Backend
X-Proxy-Cache-Status
X-Backend-Name
Section-Io-Cache
X-Oracle-Dms-Ecid
X-Oracle-Dms-Rid
X-HTML-Minification-Powered-By
Content-Secure-Policy
X-RN-RSRV
X-Cache-Operation
Load-Balancing
Meta-Geo
X-UPSTREAM-Address
X-Zen-Fury
CF-IPCountry
Server-Info
X-Storage
X-Mode
TWC-Privacy
X-PCL
Web-Mar-Node
Webcakes-App-Version
X-LJ-Flow-ID
X-Varnish-Cache-Hits
Webcakes-Region
TWC-Locale-Group
Webcakes-App-Name
X-Redis-Cache
TWC-Device-Class
Azure-RegionName
Azure-InstanceId
Azure-SiteName
Azure-SlotName
X-No-Session
Azure-Version
Property-Id
X-OCL
X-Origin-Hint
TWC-GeoIP-Country
X-Handled-By
X-Server-W
TWC-Connection-Speed
TWC-GeoIP-LatLong
X-Access
X-Section
X-Format
X-Sql-Count
X-VWS-Id
X-Sql-Duration-Ms
X-PHP-Backend
X-Cache-Server
X-Varnishpool
X-AWS-Id
Selected-Fe
X-Origin-Date
X-ShopId
X-Cms-Context
S-Rt
X-Hl-Ver
X-Shopify-Stage
X-Request-Time
X-Xfnlog-Site
Onion-Location
Locale
X-Extlb
X-Generation-Time
X-Cache-Enabled
Eomportal-Instance
X-Debug-Cache
X-Via-Fastly
X-Cache-Type
Mn-Server-Ip
X-Proxy-Build
X-ShardId
X-Proxied
X-Proto
DB-Nickname
X-Zipkin-Id
X-Urbn-Context-Path
X-Urbn-Site-Id
X-Timing-Wait
X-Routing-Service
X-SayCDN-TTL
X-Say-TTL
X-Uri
X-JoinUs
X-Say-Cacheable
X-Alternate-Cache-Key
X-Storefront-Renderer-Rendered
X-Varnish-Hostname
X-Locale
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-SaId
X-Cache-Host
X-Site-Version
X-Content-Age
X-VC-Cache
X-Region
X-Cache-Status-Check
X-FB-TRIP-ID
X-Akamai-Edgescape
X-BYPASS-REASON
ServedBy
X-Edge-Location
X-Datadome
X-Labrador-Cache-Channel
Apigw-Requestid
X-Forwarded-Host
X-UA-Device-Type
GEO-INFO
X-Adobe-Source
X-ServerID
X-ProxyCache-Status
X-PHP-Host
X-ProxyCache-Key
X-Generated-By
X-Tid
X-SRV
WP-Super-Cache
X-Detected-As
X-Web-Node
X-Skip-Cache
CDN-EdgeStorageId
CDN-Cache
X-GeoCode
CDN-PullZone
CDN-RequestCountryCode
CDN-Uid
CDN-RequestId
X-GeoCountry
CDN-CachedAt
X-Varnish-Beresp-Grace
X-Human
X-DynaTrace-JS-Agent
X-Cache-Action
X-Nginx-Cache
X-LSADC-Cache
X-Rule
X-Dc
X-Ua
SD-X-WS
X-R9-Blue-Green-Version
X-FireWall-Port
X-Ms-Request-Id
Cache-Name
X-Ms-Version
X-ECache
Cache
Xet-Cookie
X-Cache-Tags
Cross-Origin-Window-Policy
LB
WPO-Cache-Message
WPO-Cache-Status
X-Cached-By
X-Amz-Apigw-Id
X-App-Version
Source
X-Amzn-RequestId
X-GG-Cache-Date
X-Via-NSCOPI
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
X-Varnish-Hits
X-RCS-CacheZone
Cross-Origin-Resource-Policy
X-NewRelic-App-Data
X-Aspnetmvc-Version
X-Correlation-ID
Origin
X-Cdn
X-IPS-LoggedIn
X-MP-GENERATED-AT
X-Reqid
X-GEO
X-TNCMS
Cache-Hits
X-Loop
Xserver
X-AOL-HN
X-Origin-TTL
X-Pubstack
X-Origin-CC
X-Soup
X-Amzn-Remapped-Content-Length
X-B3-SpanId
X-Newrelic-Synthetics
X-URL
X-FW-Version
X-TA-CDN-Provider
X-Cluster-Node
X-Tumblr-Pixel-2
Rip
X-Platform-Server
X-TIME
X-Varnish-Ttl
X-Service
Upgrade-Insecure-Requests
X-Api-Version
X-Origin-Response-Time
X-Cluster
X-A-Dcw
X-ARC
X-B-Cookie
X-Application
X-AK-Request-ID
X-Aed
X-Bc-Bl
X-A-Dgt
X-A-Wwc
X-Connection-Hash
X-Ec-Fail
X-External-Request-Id
X-Forwarded-Path
X-NAPM-TraceId
X-Developer
X-Destination
X-Cache-NE
X-A-Dam
X-D
X-BCube-Filmed-By
X-A
Meta-Geo-Continent
Ngx.Var.Host
Odigeo-Trace-Id
Redirect-Candidate
DCR-Decision-By
DCR-Processing-Time-Ms
Host-ID
Expiry
Lang
MD5-Digest
Rendered-Blocks
Cdnsip
T-Server
A
From-Origin
X-Orig-Expires
Surrogated-Key
BehaviorPad-Version
Cdncip
Candidate-Md5Url
Sslversion
X-A-Ccd
X-Ec-GeoHdr
X-Vdms-Version
X-VG-WebCache
X-Vdms-Path
X-Rewrite-Enabled
X-ScT
X-Vgn-Hpd-Reason
X-Processor
X-S
Xc-Version
X-SRCache-Key
X-Rojux
X-S-Cookie
X-Served-From
X-User
X-PBS-Appsvrname
X-Tenant
X-Shop-Environment
X-TIM-N
X-Session-Fingerprint
Fastly-SSL
X-Request-Host
OT-Force-Account-Verify
Webserver
X-Owner
X-Accel-Buffering
X-Dispatcher-Number
Decoy-Debug-Key
Environment
X-Pool
X-Irp-Debug
X-Level-Front-Cache
X-NWS-UUID-VERIFY
Machine
X-Generated-On
X-Forwarded-Site
Decoy-Debug-TTL
Decoy-Debug-Status
HostName
X-Yandex-Sdch-Disable
X-CSRF-Token
Wxu-Next-Commit
We-Hiring
Web-Mar-Region
VNS-Cache
VNS-Age
X-Sigma-Backend
X-SplitTest
X-Viewer-Country
L5d-Success-Class
X-Qloud-Router
X-Bip
L
Kp-EeAlive
Ha-Gx-Prefs
HA-Ipaddr
X-Thanos
Mail-Subject
X-Wix-Viewer-Type
X-VG-TLSProxy
Req-Svc-Chain
Servername
X-Sigma
X-WA-Info
Memcached
X-WADP-Cache
Mobile-Detection-Method
State
X-Auto-Login
X-Gateway-Cache-Key
X-Gateway-Cache-Status
X-Gateway-Request-Id
X-Gateway-Skip-Cache
X-Policy
X-Fmm-Version
X-Epic-Correlation-Id
X-Eu-Site
X-Fastly-Cache
X-Gdpr
X-Geo-Header
X-Nyt-Route
X-Optimistic-Header
X-Origin-Time
X-Pod-Name
X-Mvc-Supplant-Cachable
X-Hash
X-HS-Content-Campaign-Id
X-Minions-Version
Gh-Request-Id
X-Developers
X-Cache-Bucket
X-Cache-Info
X-Rocket-Build-Number
X-Rocket-Nginx-Serving-Static
X-BBC-Edge-Cache-Status
Wxu-Next-Region
X-SB
X-Aicache-OS
X-CacheTTL
X-Cdn-Srv
X-Request-URI
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-Csrf-Jwt
X-Core-Value
X-CGP
X-Ckpd-Fst-Backend
X-Clara-WADP
Wxu-Next-Hostname
X-Clientip
WebServer
X-VC
CPC-Age
CPC-Cache
Cluster
Apple-News-Services-Handled
Cache-Host
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
Datacenter
Country-Code
Fastly-GeoIP-CountryCode
Fastly-Backend-Name
X-Cache-Remote
X-Origin
X-Planisys-CDN-TTL
X-GeoIP-City
X-GeoIP
X-Hnp-Log
X-NodeID
Origin-CC
X-INCAP-ABP
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
X-Rebelmouse-Cache-Control
X-Block-Status
X-Branch-Name
X-NCache
X-Parent-Response-Time
X-Loc
X-Origin-Expires
Origin-EX
X-Cache-Id
X-Proxy-Cache-Info
TDXMobile
Tube-Return
X-Gen-Mode
X-Gamma-Serve
X-Core-Mission
X-Esi-Check
Traceparent
X-Gzip
Tube-Get-Contents
Tube-Got-Eval
X-Has-Esi
Tube-Got-Results
X-Device-Os
X-Is-Gdpr
X-Datadog-Trace-Id
X-S-Maxage
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
X-Fetched-On
Thinkindot-CacheControl
X-V-Cache
X-JWT-State
Thinkindot-Control
X-Ec-Custom-Error
Thinkindot-CacheControl-Type
Release
X-Rebelmouse-Surrogate-Control
Server-Host
User-Cache-Control
V-Age
Cmstype
AKAMAI
Vix-Hermes-Req-Id
Svr
NGX
NM-Fastcgi-Cache
X-Region-Sid
Fastly-SIE
DSUID
Click-Count-Error
Click-Count-Action-Start
Fastly-SWR
IsBot
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-Slack-Backend
X-SIPLIST1
X-Thinkindot-L3
X-Worker
Cmsid
CDCHOST
X-Scale
Fastcgi-Cache-TTL
X-Scheme
Cache-Tv-Group
X-Varnish-Beresp-Ttl
X-Tx-Id
X-Ad-Defer-Variation
X-VServer
Adler-Geo
X-DefHash
X-Ig-Push-State
X-Cdn-Origin
X-Microcachable
CloudFront-Viewer-Country
X-DefElseHash
Server-Hostname
Is-Eu
X-Varnish-Remaining-TTL
X-Varnish-CookieINHashed-On
X-Varnish-CookieHashed-On
X-Sn-Servicetimems
X-Variation
Platform
X-Provided-By
X-DPWN-IS-SECURE
Sever-Int
Producers
Server-Ext
X-LB-NoCache
X-Mvc-Supplant-OutputCached
X-ZONE
SID
X-Udemy-Cache-App-Namespace
X-Conf
Ssr
X-Cache-Date
Pics-Label
Ec-Rule-Version
Mime-Version
AMP-Access-Control-Allow-Source-Origin
X-Tec-Api-Root
X-Tec-Api-Version
X-Tec-Api-Origin
X-Varnish-Beresp-Status
X-Tb-Optimization-Total-Bytes-Saved
X-Dmc
Sid
Memory
Canary
Time
X-Generated-In
X-Be
X-CMSURLCustom
X-Air-Hostname
X-Air-Source
X-Air-Trace-Id
X-Edge-Pop
X-CS
X-Sucuri-Cache
X-Sucuri-ID
X-Refresh
X-MSEdge-Features
Fastly-Drupal-Html
X-Via-Popn
X-Via-Poph
X-MSEdge-Flight
X-Via-Popv
X-ATG-Version
X-Presslabs-Stats
X-B3-Traceid
X-ND-Cache
X-Var-Ttl
X-FC-Vary-Parameters
X-Fastly-Backend
X-WP-CF-Super-Cache-Active
Server-ID
X-Azure-Ref-OriginShield
X-Servedbyhost
X-Cache-Debug
X-TRACE-ID
X-Buckets
X-Xrds-Location
X-NC
Env
X-Trace-ID
Fastly-Drupal-HTML
X-Newrelic-App-Data
X-Wikidot-Static-Cache
X-Wikidot-Backend
X-Cs
X-Akamai-Transformed
X-Release
GeoIp-Country-Code
X-Fpc
X-Esi
X-PX
CDN
X-CF-Lambda-Version
Magicmarker
X-CF-Lambda-Fn
X-TX-ID
X-Zone
X-EC-Lua
X-MCACHE
X-ID
X-Endurance-Cache-Level
X-DC
X-Hyper-Cache
X-Tumblr-Pixel-3
X-Micro-Cache
Pramga
X-NGINX-Cache
X-M-Reqid
X-CACHE-AGE
X-M-Log
X-RateLimit-Reset
True-Client-IP
X-Vc
X-VCL-Version
X-Qnm-Cache
X-Srv
X-Dispatch
X-Edge-Origin-Shield-Region
C-Via
X-Varnish-Beresp-TTL
Hostname
X-Pass-Why
My-App
X-Alfa-Service
X-CSRF-TOKEN
X-Up
X-App
X-TrackingId
N-Cache
X-CACHE-KEY
X-Edge-Origin-Shield-Bytes
Tcn
Fastcgi-X-Cache-Version
On-Server
X-Wa
X-Lambda-Id
X-Platform
X-PAYTM-SRV-ID
Path
Esi-Enabled
X-Vcl-Version
X-AIR-PT
X-PERF
X-ApacheServer
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
X-Air-Pt
X-HS-Status
Resin-Trace
X-Check-Cacheable
True-Client-Ip
X-SD-PageType
X-Vercel-Id
X-Req
X-Vercel-Cache
NtCoent-Length
CacheControlHeader
GeoIP-Latitude
Cache-Key
Proxy-Connection
X-LAGOON
Tracecode
HIT
X-Node-Id
X-TH-Server
X-SERVER-NAME
X-B3-Spanid
X-Request-Start
X-API-Version
GeoIP-Country-Code
True-Client-Country-4JS
XkeyRZ
X-Proxy-CacheRZ
DT-Hot-News
X-LB-ID
Cdn
X-Akamai-Pragma-Client-IP
X-Render-Time
X-Geo
X-CLOUD-TRACE-CONTEXT
X-Proxy-Upstream
X-Op-Id-All
DynaTrace
X-Webkit-CSP-Report-Only
X-VarnishDD-TTL
X-FPC
PFcat
ENV
XM
Hit
X-HN
X-Via-Ucdn
X-Webkit-Csp-Report-Only
Section-Io-Origin-Time-Seconds
Server-Ttl
SRV
X-Mly-Id
MIME-Version
Section-Origin-Responded
X-Platform-Processor
Section-Io-Origin-Status
X-Platform-Cluster
X-Platform-Router
Section-Io-Id
X-Via-CDN
X-Traceid
X-WA
X-Dw-Trace-Id
X-Via-PopV
User-Agent
X-ServedByHost
Server-Id
X-GeoIP-Country-Code
Lb
X-Proxy-Cache-Hk
X-Via-PopN
X-Lb-Id
X-GeoIP-Region-Code
X-Via-PopH
X-Edge-POP
X-Cdn-Forward
M-TraceId
FSS-Cache
X-Date
X-LiteSpeed-Cache-Control
Geoip-Latitude
X-Datacenter
XServer
WWW-Authenticate
X-Accel-Expires-Debug
X-Cache-Backend
X-Nf-Request-Id
X-Ftr-Request-Id
YJS-ID
Warning
X-LI-UUID
X-FORWARDED-FOR
Yjs-Id
X-LI-Proto
X-Li-Pop
X-Request-Url
X-HA-Backend
X-Li-Fabric
X-TT-LOGID
X-CUA
X-Cache-Ttl
X-CF-Powered-By
Dnion-Transfer-Encoding
X-LiteSpeed-Tag
X-RAMCache
X-RSL
X-Server-IP
X-RPS
X-DI
Location
PICS-Label
X-HITS
X-DB
X-Httpd
X-DW
X-DSS
X-RPM
X-Akamai-Request-ID
X-Akamai-ERRuleID
X-Akamai-ERPolicy
X-Old-Content-Length
Vha6-Origin
Nginx-CQVIP
X-Nc
X-Fastly-Backend-Reqs
X-Wp-Cf-Super-Cache
X-Litespeed-Cache-Control
X-UA
X-Wp-Cf-Super-Cache-Cache-Control
X-HostName
X-Response-By
Sm-Log-Id
X-Fastly-Cache-Hits
Wpo-Cache-Message
X-Lb-Nocache
Wpo-Cache-Status
WZWS-RAY
X-Cdn-Request-ID
X-IN-APIGATEWAY
X-Cc-Via
X-Instance-Name
X-B3-ParentSpanId
X-Service-Response-Time
Ohc-File-Size
X-IN-APIGATEWAYSSL
Cdn-Cache
Wp-Super-Cache
Cdn-Cachedat
X-Cache-Ngx
CountryCode
Cdn-Edgestorageid
Cdn-Requestid
Cdn-Uid
Cdn-Pullzone
Cdn-Requestcountrycode
X-Moov-T
X-Moov-Xdn-Version
Uri
X-DataCenter
Ohc-Cache-HIT
X-MiniProfiler-Ids
X-Serial
X-Contensis-Viewer-Groups
Dt-Hot-News
X-Snapshot-Date
X-APP
X-Cache-ASPX
Req-ID
Fastcgi-Cache-Ttl
X-Varnish-Authentication