Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
Strict-Transport-Security
X-Frame-Options
X-Content-Type-Options
Last-Modified
Link
CF-Cache-Status
Cf-Request-Id
Accept-Ranges
ETag
CF-RAY
Expect-CT
Pragma
X-Powered-By
X-Cache
X-XSS-Protection
Via
Age
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Xss-Protection
X-Cache-Hits
P3P
X-FRAME-OPTIONS
X-UA-Compatible
X-Served-By
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-Adblock-Key
X-AspNet-Version
X-Permitted-Cross-Domain-Policies
X-Runtime
Alt-Svc
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Check
X-Cache-Status
X-Generator
X-DNS-Prefetch-Control
CF-Ray
X-Cacheable
Timing-Allow-Origin
X-Iinfo
X-Envoy-Upstream-Service-Time
Feature-Policy
Status
X-Content-Security-Policy
X-Drupal-Dynamic-Cache
Content-Encoding
X-AspNetMvc-Version
X-CDN
Access-Control-Expose-Headers
Upgrade
X-XSS-PROTECTION
P3p
Access-Control-Max-Age
X-Dns-Prefetch-Control
X-Ua-Compatible
X-Request-ID
X-Via
Server-Timing
X-Cache-Group
X-Robots-Tag
X-UA-Device
Request-Context
Keep-Alive
X-Amz-Request-Id
X-AH-Environment
X-Turbo-Charged-By
X-Backend
X-Amz-Id-2
X-Ws-Request-Id
X-Proxy-Cache
X-Age
Host-Header
X-Server-Powered-By
X-Hacker
X-Akamai-Path-Stats
X-Server
X-Rq
EagleId
X-Vhost
X-Varnish-Cache
Grace
X-Amz-Version-Id
X-Dispatcher
X-LiteSpeed-Cache
Cf-Edge-Cache
Allow
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Nginx-Cache-Status
X-Device
X-Page-Speed
X-WebKit-CSP
X-Aws-Lambda-Call-Status
X-Host
X-Node
X-Server-Id
EagleEye-TraceId
X-OneAgent-JS-Injection
X-Pingback
X-Cache-Spec
Request-Id
Surrogate-Control
Cf-Railgun
Accept-CH
X-Akam-SW-Version
X-Backend-Server
X-Readtime
X-Cache-Lookup
X-Response-Time
Accept-CH-Lifetime
X-HW
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Content-Security-Policy-Report-Only
Content-Location
X-Application-Context
Rating
X-Trace
Fastly-Restarts
X-Cloud-Trace-Context
X-WebKit-CSP-Report-Only
X-Url
X-Clacks-Overhead
X-Country
X-Edge
X-Amz-Server-Side-Encryption
X-B3-TraceId
Accept-Ch-Lifetime
X-MS-InvokeApp
X-Rack-Cache
Edge-Control
X-Ruxit-JS-Agent
X-Vname
X-PC
X-TtlSet
Accept-Ch
X-ESI
X-Vcap-Request-Id
X-Content-Type
Xkey
X-Mod-Pagespeed
X-Nginx-Upstream-Cache-Status
X-CST
X-Varnish-TTL
X-Mcache
X-D2id
X-Oneagent-Js-Injection
X-Exp-Variant
X-Amz-Rid
X-Exp-Id
X-VARITI-CCR
X-Cdn-Fetch
X-GoogleNews-Bot
X-Use-Magma
X-Kinja-Build
X-Kinja-Server
X-Kinja
X-Kinja-Revision
Verso
Cache-Tag
X-GitHub-Request-Id
RTSS
X-FastCGI-Cache
X-Powered-By-Plesk
X-ECACHE
X-Cached
Service-Worker-Allowed
X-Upstream
X-Navigation-Version
X-Client-IP
X-Version
X-Ruxit-Js-Agent
X-Abt-Application-Version
X-Dw-Request-Base-Id
X-Px
X-Cnection
X-Ac
Public-Key-Pins
Arr-Disable-Session-Affinity
X-Ser
X-Instrumentation
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
SPRequestGuid
X-SharePointHealthScore
X-Sol
Pagespeed
Display
X-Middleton-Display
X-Server-Name
X-Element-Page-Cache
X-Ttl
X-Country-Code
SPRequestDuration
SPIisLatency
X-Cache-TTL
X-NWS-LOG-UUID
X-NF-Request-ID
X-RateLimit-Remaining
X-Midtier
Response
X-Middleton-Response
Permissions-Policy
X-Goog-Hash
X-Cache-Key
X-Edge-Location-Klb
X-Kinsta-Cache
X-Forwarded-For
Access-Control-Request-Method
Content-MD5
X-DataDome
X-Shield-Request-Id
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-MSEdge-Ref
X-Powered-CMS
Front-End-Https
X-Correlation-Id
Edge-Cache-Tag
AR-SID
AR-Request-ID
AR-PoweredBy
TP-Cache
TP-L2-Cache
X-T
X-Recruiting
AR-ATIME
AR-CACHE
Nginx-Cache
X-HP-Webp
X-HP-Trace-Id
X-Jurisdiction
X-Accel-Expires
X-RateLimit-Limit
TCN
X-Daa-Tunnel
X-Grace
MicrosoftSharePointTeamServices
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
X-Id
X-Mg-S
X-Hits
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Request-Processing-Time
X-Request-Received
X-TEC-API-VERSION
Filters
X-HS-Cache-Config
X-Content-Digest
X-HS-Combine-CSS
X-HS-Content-Id
Server-Node
X-HS-Hub-Id
X-Fastly-Request-Id
X-LLID
S
X-Frontend
Server-Name
X-Distributor
X-Amzn-Trace-Id
Cache-Status
X-Protected-By
X-TTL
MS-Author-Via
X-Geo-Country
Fastcgi-Cache
X-PressLabs-Stats
X-LB-Cache
X-Request-Handler-Origin-Region
X-Microsite
X-Language
Cross-Origin-Opener-Policy
X-Ab
X-Forwarded-Proto
X-Ezoic-Cdn
X-Origin-Server
X-Ua-Browser
Charset
X-B3-Sampled
Filterid
Host
X-F-Cache
X-FB-Debug
X-Seen-By
X-Git-Hash
X-Page-Id
X-Amz-Meta-S3cmd-Attrs
Realpath
Payment
Count-Hit
X-XRDS-Location
X-Ratelimit-Reset
X-Litespeed-Cache
X-ASPNET-VERSION
X-Cache-Age
X-Cluster-Name
X-VCache
Accept-Charset
X-Browser-Type
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-DynaTrace
Surrogate-Key
X-Fastcgi-Cache
Cache-Tags
X-NGENIX-Cache
X-Origin-Cache
Alternate-Protocol
X-Rid
Cf-Apo-Via
X-Activity-Id
Retry-After
X-Az
X-AppVersion
Cleartype
X-Template
X-Webkit-Csp
X-Www-Served-By
Access-Control-Allow-Method
X-Webkit-CSP
X-Content
X-Varnish-Backend
X-Amz-Replication-Status
X-Node-Name
X-Type
X-TT
X-Tb
X-DIS-Request-ID
X-Upgrade-Enabled
X-Debug
X-Signature
X-Wix-Request-Id
X-App-Environment
X-B-Cache
X-B
ServerID
X-Varnish-Grace
Paypal-Debug-Id
X-Route-Name
X-Providence-Cookie
X-Aspnet-Duration-Ms
DC
X-Is-Crawler
X-Request-Guid
X-Flags
X-Logged-In
X-Drupal-Cache-Tags
X-Proxy
X-Tt-Trace-Tag
X-Tt-Trace-Host
Frame-Options
X-Hostname
X-Mobile
X-Envoy-Decorator-Operation
X-Content-Options
X-Source
X-Load-Cache
X-Revision
X-Goog-Storage-Class
X-Goog-Metageneration
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-Pinterest-Rid
X-Cache-Control
Pinterest-Generated-By
Pinterest-Version
X-N
Country
X-Contextid
X-COUNTRY
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-User-Agent
X-Magnolia-Registration
X-EdgeConnect-Cache-Status
Amp-Access-Control-Allow-Source-Origin
Referer-Policy
X-Whom
Viewport
X-Cache-Rule
NGB
X-Response-Served-From
X-Original-Request-Id
Node
X-Varnish-Age
Refresh
X-Restarts
Content-Disposition
X-Cache-TTL-Remaining
X-Debug-IsConnected
X-Environment-Context
X-Debug-IsPreview
X-L-Path
X-Mid
X-Framework
Access-Control-Request-Headers
X-Varnish-Server
X-Unique-Id
X-Jobs
X-Ratelimit-Remaining
Akamai-GRN
X-Cache-Time
X-G
X-Cacheable-TTL
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
Url
Uber-Trace-Id
X-Mg-Request-UUID
X-Real-IP
X-Servername
X-Page-View
X-Cache-Grace
X-Akamai-Request-ID2
X-Yottaa-Optimizations
X-Instance
X-Adobe-Content
X-Yottaa-Metrics
X-Adobe-Loc
X-NYM-Debug-Backend
X-Is-Bot
X-Rendered-As
X-Status
X-Fastly-Request-ID
X-Drupal-Cache-Contexts
Version
X-App-Server
Countrycode
X-Content-Powered-By
X-RemovedCookies
X-XRDS-LOCATION
X-Debug-Info
X-ProcessESI
X-Server-ID
X-Http-Reason
X-CDN-Forward
X-APP-VERSION
Protected
X-IPLB-Request-ID
X-Tt-Logid
X-IPLB-Instance
X-Hosted-By
Srv
Accept-Language
Healthy
X-Cache-Expired-At
X-Nginx-Cache-Key
Liferay-Portal
X-Device-Type
X-Via-JSL
X-Time
X-Ratelimit-Limit
X-Trace-Id
X-FW-Server
X-FW-Static
X-FW-Serve
X-FW-Hash
X-FW-Dynamic
X-Cache-Hit
X-FW-Type
X-Tumblr-Pixel-1
X-Tumblr-User
X-Tumblr-Pixel
X-Tumblr-Pixel-0
Fastcgi-Useragent
X-Azure-Ref
Ms-Operation-Id
MS-CV
X-RTag
X-Cache-NGX
X-UUID
X-Proxy-Cache-Status
X-Backend-Name
Backend
Section-Io-Cache
X-Mobile-URL
X-Cache-Operation
Server-Info
Content-Secure-Policy
X-Oracle-Dms-Ecid
X-Oracle-Dms-Rid
X-RN-RSRV
X-Storage
Load-Balancing
X-UPSTREAM-Address
Meta-Geo
CF-IPCountry
X-HTML-Minification-Powered-By
X-Mode
Azure-Version
Azure-SiteName
Azure-InstanceId
Azure-RegionName
Azure-SlotName
Eomportal-Instance
Webcakes-App-Version
X-Edge-Location
X-Shopify-Stage
X-Cache-Enabled
X-Section
X-Skip-Cache
X-AWS-Id
X-Alternate-Cache-Key
X-Akamai-Edgescape
X-PHP-Host
X-Region
X-Format
X-Cache-Host
X-ShopId
X-Varnish-Cache-Hits
X-VWS-Id
X-Cache-Server
X-Varnish-Hostname
X-Varnishpool
X-Uri
X-Storefront-Renderer-Rendered
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Server-W
X-ShardId
X-Forwarded-Host
X-Handled-By
TWC-Privacy
TWC-Locale-Group
X-VC-Cache
Webcakes-Region
WP-Super-Cache
TWC-GeoIP-LatLong
TWC-GeoIP-Country
Property-Id
S-Rt
TWC-Connection-Speed
TWC-Device-Class
X-Access
X-OCL
X-Sql-Count
X-PHP-Backend
X-LJ-Flow-ID
X-Labrador-Cache-Channel
X-No-Session
X-Sql-Duration-Ms
X-Origin-Date
X-Locale
X-Origin-Hint
X-PCL
Onion-Location
Webcakes-App-Name
X-Zen-Fury
X-Content-Age
X-Say-Cacheable
Selected-Fe
X-Say-TTL
X-SayCDN-TTL
X-Via-Fastly
X-Redis-Cache
Web-Mar-Node
X-ProxyCache-Key
X-ProxyCache-Status
X-Proxy-Build
X-Cache-Type
Mn-Server-Ip
X-Adobe-Source
X-Site-Version
X-Extlb
X-FB-TRIP-ID
X-UA-Device-Type
X-Cms-Context
X-Debug-Cache
X-BYPASS-REASON
X-Generation-Time
X-GeoCode
X-Urbn-Site-Id
X-Urbn-Context-Path
X-JoinUs
X-Hl-Ver
X-GeoCountry
X-Proto
X-Proxied
Apigw-Requestid
X-ServerID
X-Timing-Wait
GEO-INFO
DB-Nickname
X-Zipkin-Id
Locale
X-Routing-Service
X-Request-Time
X-Xfnlog-Site
X-SaId
X-Web-Node
X-Generated-By
X-Tid
X-Datadome
X-Cache-Status-Check
CDN-RequestCountryCode
CDN-PullZone
CDN-Uid
ServedBy
X-URL
CDN-Cache
CDN-EdgeStorageId
CDN-CachedAt
CDN-RequestId
X-Varnish-Beresp-Grace
X-Cache-Action
X-Rule
X-Detected-As
X-Ua
X-LSADC-Cache
X-Correlation-ID
X-SRV
X-Dc
X-Nginx-Cache
X-R9-Blue-Green-Version
X-DynaTrace-JS-Agent
X-Ms-Request-Id
X-Ms-Version
Cache-Name
X-Human
X-ECache
X-FireWall-Port
Cache
SD-X-WS
Cross-Origin-Resource-Policy
Xet-Cookie
X-Cache-Tags
X-Cached-By
X-Amzn-RequestId
LB
X-Amz-Apigw-Id
Source
Cross-Origin-Window-Policy
X-App-Version
X-WP-CF-Super-Cache
X-Via-NSCOPI
X-NewRelic-App-Data
X-WP-CF-Super-Cache-Cache-Control
X-RCS-CacheZone
X-Varnish-Hits
X-MP-GENERATED-AT
Origin
Xserver
X-Aspnetmvc-Version
WPO-Cache-Status
WPO-Cache-Message
X-GG-Cache-Date
X-GEO
X-TNCMS
X-Reqid
X-Loop
X-Cdn
X-IPS-LoggedIn
X-Pubstack
X-Origin-TTL
X-Origin-CC
X-AOL-HN
X-Amzn-Remapped-Content-Length
X-Soup
Cache-Hits
X-B3-SpanId
X-Api-Version
X-TA-CDN-Provider
X-Newrelic-Synthetics
X-FW-Version
X-Tumblr-Pixel-2
From-Origin
Rip
X-Cluster-Node
X-Platform-Server
X-Service
X-Vgn-Hpd-Reason
Webserver
X-TIME
X-Varnish-Ttl
Upgrade-Insecure-Requests
X-Origin-Response-Time
X-AK-Request-ID
Rendered-Blocks
X-B-Cookie
Cdncip
Cdnsip
X-Ec-Fail
X-Ec-GeoHdr
X-Developer
X-Destination
BehaviorPad-Version
X-Connection-Hash
X-D
A
X-Cache-NE
X-External-Request-Id
X-NAPM-TraceId
X-ARC
Environment
X-Application
DCR-Processing-Time-Ms
DCR-Decision-By
X-Forwarded-Path
X-BCube-Filmed-By
X-Bc-Bl
Expiry
X-A
X-Shop-Environment
X-Session-Fingerprint
Meta-Geo-Continent
X-SRCache-Key
X-Tenant
X-Served-From
X-Cluster
X-Rojux
X-S
X-S-Cookie
X-ScT
Ngx.Var.Host
X-TIM-N
X-VG-WebCache
Sslversion
Xc-Version
Redirect-Candidate
Surrogated-Key
X-Vdms-Version
X-User
Odigeo-Trace-Id
T-Server
X-Vdms-Path
Lang
MD5-Digest
X-A-Dam
X-A-Dcw
X-Owner
X-PBS-Appsvrname
Host-ID
X-Processor
X-A-Dgt
X-A-Ccd
X-Rewrite-Enabled
X-Orig-Expires
X-A-Wwc
X-Aed
Fastly-SSL
OT-Force-Account-Verify
X-Request-Host
Candidate-Md5Url
X-Forwarded-Site
Mobile-Detection-Method
X-Provided-By
X-Qloud-Router
X-Thanos
X-Accel-Buffering
X-Pool
X-Bip
Decoy-Debug-Key
Decoy-Debug-Status
Decoy-Debug-TTL
Machine
X-Irp-Debug
X-Generated-On
X-Level-Front-Cache
X-CSRF-Token
HostName
X-Varnish-Beresp-Ttl
State
X-Cdn-Origin
VNS-Age
X-Auto-Login
Tube-Got-Results
Servername
X-Cdn-Srv
X-Ckpd-Fst-Backend
X-CGP
X-Clara-WADP
Req-Svc-Chain
Server-Host
X-Ad-Defer-Variation
Tube-Return
Thinkindot-CacheControl
Wxu-Next-Hostname
Wxu-Next-Commit
We-Hiring
Tube-Got-Eval
Thinkindot-Control
Wxu-Next-Region
X-BBC-Edge-Cache-Status
Traceparent
Vix-Hermes-Req-Id
X-Branch-Name
X-Cache-Info
Tube-Get-Contents
TDXMobile
VNS-Cache
Thinkindot-CacheControl-Type
X-Cache-Id
X-Core-Mission
X-CacheTTL
X-Mvc-Supplant-Cachable
X-S-Maxage
X-Rocket-Nginx-Serving-Static
X-Rocket-Build-Number
X-SB
X-Scale
X-Sigma-Backend
X-Sigma
X-Request-URI
X-Region-Sid
X-Proxy-Cache-Info
X-Policy
X-Parent-Response-Time
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-SIPLIST1
X-Sn-Servicetimems
X-WA-Info
X-Viewer-Country
X-VG-TLSProxy
X-WADP-Cache
X-Aicache-OS
X-Wix-Viewer-Type
X-Dispatcher-Number
X-Varnish-Remaining-TTL
X-Varnish-CookieINHashed-On
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-SplitTest
X-Thinkindot-L3
X-V-Cache
X-Varnish-CookieHashed-On
X-Variation
X-Origin-Time
X-Origin-Expires
X-Eu-Site
X-Esi-Check
X-Epic-Correlation-Id
X-Fastly-Cache
X-Fetched-On
X-Gamma-Serve
X-Fmm-Version
X-DPWN-IS-SECURE
X-Device-Os
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
X-Csrf-Jwt
X-Datadog-Trace-Id
X-DefElseHash
X-Developers
X-DefHash
X-Gateway-Cache-Key
X-Gateway-Cache-Status
X-Minions-Version
X-Loc
X-INCAP-ABP
X-NodeID
X-Nyt-Route
X-Origin
X-Optimistic-Header
X-HS-Content-Campaign-Id
X-Hash
X-Gdpr
X-Gateway-Skip-Cache
X-Gateway-Request-Id
X-Geo-Header
X-GeoIP
X-Gzip
X-GeoIP-City
X-Core-Value
V-Age
Datacenter
DSUID
CPC-Cache
CPC-Age
Country-Code
Fastly-Backend-Name
Fastly-GeoIP-CountryCode
Ha-Gx-Prefs
HA-Ipaddr
Gh-Request-Id
Fastly-SWR
Fastly-SIE
Cmstype
Cmsid
Adler-Geo
Apple-News-Services-Handled
Release
X-Cache-Remote
X-VC
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
Click-Count-Error
Cluster
Click-Count-Action-Start
Cache-Host
Apple-News-Services-Request-Url
Is-Eu
Cache-Tv-Group
NM-Fastcgi-Cache
Memcached
NGX
IsBot
Platform
Origin-EX
Mail-Subject
Kp-EeAlive
Origin-CC
L
L5d-Success-Class
Producers
X-NWS-UUID-VERIFY
X-Is-Gdpr
X-JWT-State
CDCHOST
Svr
X-Mvc-Supplant-OutputCached
X-Clientip
X-Scheme
X-Pod-Name
X-NCache
Web-Mar-Region
X-Cache-Bucket
X-Has-Esi
CloudFront-Viewer-Country
AKAMAI
X-Ec-Custom-Error
X-Worker
X-Planisys-CDN-TTL
X-Slack-Backend
X-Planisys-CDN-Rules
Fastcgi-Cache-TTL
X-VServer
X-Planisys-CDN-Cache
X-Xrds-Location
WebServer
X-Yandex-Sdch-Disable
Mime-Version
X-Tx-Id
Sever-Int
Server-Ext
Server-Hostname
X-Gen-Mode
User-Cache-Control
X-Block-Status
X-LB-NoCache
X-Hnp-Log
X-ZONE
Ec-Rule-Version
X-Udemy-Cache-App-Namespace
X-Tec-Api-Root
X-Ig-Push-State
X-Cache-Date
X-Varnish-Beresp-Status
X-Tec-Api-Version
X-Tec-Api-Origin
Pics-Label
Ssr
X-Microcachable
X-Tb-Optimization-Total-Bytes-Saved
Canary
SID
Time
X-TRACE-ID
Memory
X-CMSURLCustom
X-Conf
AMP-Access-Control-Allow-Source-Origin
Sid
X-Generated-In
X-Sucuri-Cache
X-Sucuri-ID
X-WP-CF-Super-Cache-Active
Fastly-Drupal-Html
X-Refresh
X-Via-Popv
X-Cache-Debug
X-Dmc
X-Edge-Pop
X-Azure-Ref-OriginShield
X-Var-Ttl
X-FC-Vary-Parameters
X-Fastly-Backend
X-ATG-Version
X-Via-Popn
X-Servedbyhost
X-Via-Poph
X-ND-Cache
Server-ID
X-Be
X-Presslabs-Stats
X-B3-Traceid
X-Akamai-Transformed
X-Air-Trace-Id
X-Air-Hostname
X-Air-Source
X-CS
X-Fpc
Env
Fastly-Drupal-HTML
X-MSEdge-Flight
X-MSEdge-Features
X-Buckets
X-Cs
X-Trace-ID
X-Newrelic-App-Data
X-NC
X-Release
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-Endurance-Cache-Level
X-Esi
X-EC-Lua
X-PX
X-Tumblr-Pixel-3
Magicmarker
X-ID
X-Zone
X-TX-ID
GeoIp-Country-Code
X-MCACHE
X-NGINX-Cache
CDN
X-Srv
X-DC
X-CACHE-AGE
X-Up
X-CF-Lambda-Version
True-Client-IP
X-CF-Lambda-Fn
X-RateLimit-Reset
X-Hyper-Cache
X-Pass-Why
X-Vc
X-VCL-Version
Pramga
X-Dispatch
X-M-Reqid
X-M-Log
My-App
X-Wa
X-Micro-Cache
X-Webkit-CSP-Report-Only
X-CSRF-TOKEN
Hostname
X-Qnm-Cache
X-App
X-Lambda-Id
X-Alfa-Service
C-Via
X-CACHE-KEY
X-Edge-Origin-Shield-Region
X-Varnish-Beresp-TTL
X-TrackingId
N-Cache
X-Edge-Origin-Shield-Bytes
X-Req
X-Vcl-Version
X-PAYTM-SRV-ID
On-Server
Path
Fastcgi-X-Cache-Version
X-Platform
Esi-Enabled
Resin-Trace
X-Air-Pt
X-Check-Cacheable
True-Client-Ip
X-AIR-PT
X-Vtex-Remote-Cache
X-Vtex-Processado-Em
CacheControlHeader
X-ApacheServer
X-HS-Status
Tcn
X-PERF
X-Vercel-Id
X-TH-Server
X-Vercel-Cache
GeoIP-Latitude
X-LB-ID
GeoIP-Country-Code
Tracecode
True-Client-Country-4JS
X-B3-Spanid
X-Node-Id
X-Nf-Request-Id
Cdn
X-SD-PageType
NtCoent-Length
X-SERVER-NAME
X-API-Version
X-Op-Id-All
HIT
Cache-Key
X-Akamai-Pragma-Client-IP
Proxy-Connection
X-LAGOON
X-Request-Start
DT-Hot-News
X-CLOUD-TRACE-CONTEXT
Section-Io-Id
X-FPC
ENV
DynaTrace
Section-Origin-Responded
Hit
X-Geo
X-Render-Time
X-Proxy-CacheRZ
Section-Io-Origin-Status
X-Mly-Id
XkeyRZ
Section-Io-Origin-Time-Seconds
X-Webkit-Csp-Report-Only
PFcat
X-Platform-Router
X-Platform-Processor
X-Traceid
X-Proxy-Upstream
XM
X-Via-CDN
X-Platform-Cluster
X-WA
X-GeoIP-Country-Code
X-GeoIP-Region-Code
X-Via-Ucdn
X-VarnishDD-TTL
X-Lb-Id
X-HN
X-Dw-Trace-Id
X-Date
X-Edge-POP
Server-Id
X-Accel-Expires-Debug
Lb
X-ServedByHost
X-Via-PopV
WWW-Authenticate
X-Datacenter
X-Proxy-Cache-Hk
X-Via-PopH
User-Agent
Server-Ttl
X-Via-PopN
SRV
MIME-Version
X-Cdn-Forward
X-LiteSpeed-Cache-Control
X-RAMCache
YJS-ID
XServer
X-Li-Fabric
Dnion-Transfer-Encoding
X-Li-Pop
X-LI-Proto
X-LI-UUID
Geoip-Latitude
X-Ftr-Request-Id
X-DI
X-DSS
X-LiteSpeed-Tag
Yjs-Id
X-TT-LOGID
X-Wp-Cf-Super-Cache
X-Wp-Cf-Super-Cache-Cache-Control
X-DB
X-DW
X-Cache-Backend
X-Cache-Ttl
M-TraceId
X-FORWARDED-FOR
FSS-Cache
X-RSL
X-RPM
X-CF-Powered-By
X-RPS
X-CUA
Sm-Log-Id
PICS-Label
Wpo-Cache-Message
Wpo-Cache-Status
X-Old-Content-Length
X-Service-Response-Time
X-Response-By
X-Instance-Name
Location
X-Nc
Warning
Vha6-Origin
X-Akamai-Request-ID
X-HITS
X-Request-Url
X-Httpd
X-HA-Backend
X-Fastly-Backend-Reqs
Ohc-File-Size
X-Akamai-ERPolicy
X-Akamai-ERRuleID
Nginx-CQVIP
X-UA
X-Litespeed-Cache-Control
X-Mg-Cache
X-Cdn-Request-ID
X-B3-ParentSpanId
X-Server-IP
X-Cc-Via
X-Lb-Nocache
Powered-By
X-Fastly-Cache-Hits
X-HostName
X-IN-APIGATEWAYSSL
X-IN-APIGATEWAY
Cdn-Requestcountrycode
Cdn-Requestid
Cdn-Uid
Cdn-Pullzone
Cdn-Edgestorageid
X-Cache-Ngx
CountryCode
Cdn-Cache
Cdn-Cachedat
Srvid
X-MiniProfiler-Ids
Locid
X-From
X-Webstats-RespID
X-Moov-T
X-FL-EDGE
X-DataCenter
WZWS-RAY
Fastcgi-Cache-Ttl
Ohc-Cache-HIT
Uri
X-Moov-Xdn-Version
X-Serial
X-Snapshot-Date
Req-ID