Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
Strict-Transport-Security
X-Frame-Options
X-Content-Type-Options
Last-Modified
Link
CF-Cache-Status
Cf-Request-Id
Accept-Ranges
ETag
CF-RAY
Expect-CT
Pragma
X-Powered-By
X-Cache
Via
Age
X-XSS-Protection
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Xss-Protection
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-FRAME-OPTIONS
X-Download-Options
X-Timer
X-Request-Id
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-Adblock-Key
X-AspNet-Version
X-Permitted-Cross-Domain-Policies
Alt-Svc
X-Runtime
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Check
X-DNS-Prefetch-Control
X-Cache-Status
X-Generator
CF-Ray
X-Cacheable
X-Iinfo
Timing-Allow-Origin
X-Envoy-Upstream-Service-Time
Feature-Policy
Status
X-Content-Security-Policy
X-Drupal-Dynamic-Cache
Content-Encoding
X-AspNetMvc-Version
X-Request-ID
Access-Control-Expose-Headers
X-CDN
Upgrade
X-XSS-PROTECTION
Access-Control-Max-Age
X-Ua-Compatible
X-Via
X-Dns-Prefetch-Control
X-Cache-Group
X-Robots-Tag
Server-Timing
X-UA-Device
Request-Context
Keep-Alive
X-Amz-Request-Id
X-AH-Environment
X-Turbo-Charged-By
X-Amz-Id-2
X-Backend
X-Proxy-Cache
X-Ws-Request-Id
X-Age
Host-Header
P3p
X-Server-Powered-By
X-Hacker
X-Server
X-Rq
X-Vhost
EagleId
X-Varnish-Cache
Grace
X-Amz-Version-Id
X-Dispatcher
X-LiteSpeed-Cache
X-Akamai-Path-Stats
Cf-Edge-Cache
Allow
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-Device
X-WebKit-CSP
X-Nginx-Cache-Status
X-Page-Speed
X-Aws-Lambda-Call-Status
X-Host
X-Node
Accept-CH
X-OneAgent-JS-Injection
X-Pingback
X-Server-Id
Cf-Railgun
X-Cache-Spec
EagleEye-TraceId
Request-Id
Surrogate-Control
X-Akam-SW-Version
X-Backend-Server
X-Cache-Lookup
X-Response-Time
X-Readtime
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-HW
Accept-CH-Lifetime
Content-Location
X-Content-Security-Policy-Report-Only
X-Application-Context
X-Trace
Rating
X-Cloud-Trace-Context
Fastly-Restarts
Accept-Ch-Lifetime
X-Country
X-Url
X-WebKit-CSP-Report-Only
X-Clacks-Overhead
X-Edge
X-Amz-Server-Side-Encryption
X-MS-InvokeApp
X-Rack-Cache
Edge-Control
X-B3-TraceId
X-TtlSet
X-PC
X-Vname
X-Nginx-Upstream-Cache-Status
X-Ruxit-JS-Agent
X-Content-Type
X-ESI
X-Vcap-Request-Id
X-Mod-Pagespeed
X-Kinja
X-GoogleNews-Bot
X-Cdn-Fetch
X-Exp-Variant
X-Exp-Id
X-D2id
X-Use-Magma
X-Oneagent-Js-Injection
X-Kinja-Build
X-Kinja-Server
X-Kinja-Revision
X-Varnish-TTL
Xkey
X-Mcache
X-Amz-Rid
Verso
X-GitHub-Request-Id
Cache-Tag
X-FastCGI-Cache
X-VARITI-CCR
X-Powered-By-Plesk
RTSS
X-CST
X-ECACHE
Service-Worker-Allowed
X-Ruxit-Js-Agent
X-Navigation-Version
X-Upstream
X-Version
X-Abt-Application-Version
X-Cached
X-Client-IP
X-Dw-Request-Base-Id
Accept-Ch
X-Cnection
X-Ac
X-Px
Public-Key-Pins
X-Kraken-Loop-Name
X-Instrumentation
X-Server-Lifecycle-Phase
X-Server-Name
X-Element-Page-Cache
SPRequestGuid
X-SharePointHealthScore
Arr-Disable-Session-Affinity
X-Cache-TTL
SPRequestDuration
SPIisLatency
Pagespeed
X-Middleton-Display
X-Sol
Display
X-Ttl
X-Ser
X-NWS-LOG-UUID
X-Country-Code
Permissions-Policy
X-RateLimit-Remaining
X-Midtier
Response
X-Middleton-Response
X-Edge-Location-Klb
X-Kinsta-Cache
X-Goog-Hash
X-Cache-Key
X-Forwarded-For
Content-MD5
Access-Control-Request-Method
X-NF-Request-ID
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Shield-Request-Id
Front-End-Https
X-MSEdge-Ref
X-DataDome
X-Correlation-Id
X-T
X-HP-Trace-Id
X-Jurisdiction
X-Recruiting
Nginx-Cache
X-HP-Webp
Edge-Cache-Tag
TP-Cache
TP-L2-Cache
AR-ATIME
X-Accel-Expires
AR-CACHE
AR-SID
AR-PoweredBy
AR-Request-ID
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
X-Powered-CMS
X-RateLimit-Limit
MicrosoftSharePointTeamServices
MRF-Tech
X-B3-TraceId-Primal
Mrf-Cache-Status
X-Daa-Tunnel
TCN
X-Grace
Cf-Apo-Via
X-Mg-S
X-Id
X-Hits
X-Content-Digest
Filters
X-Request-Received
X-Request-Processing-Time
X-HS-Combine-CSS
X-HS-Cache-Config
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-HS-Hub-Id
X-HS-Content-Id
Server-Node
Server-Name
X-Amzn-Trace-Id
X-Frontend
S
X-Distributor
MS-Author-Via
X-Geo-Country
X-LLID
X-Protected-By
Fastcgi-Cache
Cache-Status
X-PressLabs-Stats
X-Language
X-Fastly-Request-Id
X-TTL
X-LB-Cache
Cross-Origin-Opener-Policy
X-Erf-Bev-Bev-Is-Generated
X-Browser-Type
X-Erf-Bev-Bev
X-Origin-Server
X-Amz-Meta-S3cmd-Attrs
X-FB-Debug
Host
X-F-Cache
X-Microsite
X-B3-Sampled
X-Request-Handler-Origin-Region
X-Ezoic-Cdn
X-Forwarded-Proto
Charset
X-Page-Id
X-Seen-By
Count-Hit
X-Git-Hash
X-Ab
X-Ua-Browser
Filterid
Payment
X-Litespeed-Cache
X-XRDS-Location
X-ASPNET-VERSION
X-Cache-Age
X-Ratelimit-Reset
X-Cluster-Name
X-VCache
Realpath
Surrogate-Key
X-Fastcgi-Cache
X-Rid
Cache-Tags
X-Origin-Cache
Accept-Charset
Alternate-Protocol
X-Template
X-NGENIX-Cache
Retry-After
X-Www-Served-By
X-DynaTrace
X-AppVersion
X-Az
X-Activity-Id
X-Webkit-Csp
Access-Control-Allow-Method
Cleartype
X-DIS-Request-ID
X-Amz-Replication-Status
X-Logged-In
X-Route-Name
X-TT
X-Varnish-Grace
X-Providence-Cookie
X-Flags
X-Aspnet-Duration-Ms
X-Varnish-Backend
X-Is-Crawler
X-Upgrade-Enabled
X-Request-Guid
X-B-Cache
X-Signature
X-Tb
X-B
X-Wix-Request-Id
X-Type
X-Node-Name
X-App-Environment
DC
Paypal-Debug-Id
ServerID
X-Envoy-Decorator-Operation
X-Source
X-Drupal-Cache-Tags
X-Hostname
X-Proxy
X-Debug
Frame-Options
X-Revision
X-Fastly-Request-ID
X-Mobile
X-Content-Options
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Contextid
X-Load-Cache
Pinterest-Generated-By
X-Pinterest-Rid
Pinterest-Version
X-GUploader-UploadID
X-Goog-Generation
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Metageneration
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Cache-Rule
X-Content
X-N
X-Cache-Control
Country
X-Magnolia-Registration
Amp-Access-Control-Allow-Source-Origin
Node
Refresh
X-Whom
X-User-Agent
X-Response-Served-From
X-Original-Request-Id
X-EdgeConnect-Cache-Status
Referer-Policy
Viewport
NGB
X-Debug-IsConnected
X-Debug-IsPreview
X-Cache-TTL-Remaining
X-L-Path
Access-Control-Request-Headers
Content-Disposition
X-Environment-Context
X-Cacheable-TTL
X-Yottaa-Optimizations
VIX-Pulpo-Upstream-Status
X-Framework
X-Unique-Id
Url
VIX-Pulpo-Node
Uber-Trace-Id
X-G
X-Servername
X-Adobe-Content
X-Yottaa-Metrics
X-Mid
X-Real-IP
X-Page-View
X-Adobe-Loc
X-Varnish-Server
X-Jobs
X-Cache-Grace
X-NYM-Debug-Backend
X-Content-Powered-By
X-Akamai-Request-ID2
X-Varnish-Age
X-Is-Bot
X-Rendered-As
X-Cache-Time
X-ProcessESI
X-RemovedCookies
X-XRDS-LOCATION
X-Status
Akamai-GRN
Countrycode
X-Instance
X-Ratelimit-Remaining
Srv
X-Drupal-Cache-Contexts
X-Mg-Request-UUID
Version
X-Server-ID
X-Time
X-Restarts
X-COUNTRY
X-App-Server
X-APP-VERSION
X-Http-Reason
Accept-Language
X-Debug-Info
X-Cache-Expired-At
X-Trace-Id
X-Oracle-Dms-Rid
X-CDN-Forward
X-Oracle-Dms-Ecid
Protected
X-Via-JSL
X-IPLB-Request-ID
X-IPLB-Instance
Healthy
X-Tumblr-User
X-Cache-Hit
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-Tumblr-Pixel
X-Hosted-By
X-Nginx-Cache-Key
X-Cache-Operation
X-Azure-Ref
X-Device-Type
Liferay-Portal
X-Ratelimit-Limit
Section-Io-Cache
X-Backend-Name
X-FW-Hash
X-FW-Dynamic
X-FW-Serve
X-FW-Server
X-FW-Static
Fastcgi-Useragent
X-FW-Type
Cross-Origin-Resource-Policy
Backend
Content-Secure-Policy
Server-Info
X-Datadome
X-RTag
X-Tt-Logid
Ms-Operation-Id
MS-CV
X-Akamai-Edgescape
X-Proxy-Cache-Status
X-Mobile-URL
X-UPSTREAM-Address
Load-Balancing
X-RN-RSRV
Meta-Geo
X-Storage
X-Cache-NGX
X-Cache-Action
X-UUID
X-Mode
X-Content-Age
X-VC-Cache
X-Handled-By
X-Rule
Onion-Location
X-PHP-Backend
S-Rt
X-PCL
X-Cms-Context
X-OCL
X-No-Session
X-LJ-Flow-ID
X-Cache-Server
CF-IPCountry
X-Adobe-Source
GEO-INFO
Eomportal-Instance
X-Alternate-Cache-Key
X-Proto
X-SayCDN-TTL
X-Site-Version
X-Sql-Count
X-Sorting-Hat-ShopId
X-AWS-Id
X-Varnish-Hostname
X-VWS-Id
X-Varnish-Beresp-Grace
X-Varnishpool
X-ShopId
X-Shopify-Stage
X-Say-TTL
X-Sorting-Hat-PodId
X-Say-Cacheable
X-Sql-Duration-Ms
X-Skip-Cache
X-ShardId
X-Storefront-Renderer-Rendered
X-Format
X-Urbn-Site-Id
X-FB-TRIP-ID
X-Extlb
X-Generation-Time
X-GeoCode
X-GeoCountry
Apigw-Requestid
Locale
X-Generated-By
X-Forwarded-Host
DB-Nickname
X-Varnish-Cache-Hits
Selected-Fe
Webcakes-App-Version
Webcakes-App-Name
TWC-Privacy
Webcakes-Region
X-Cache-Type
X-BYPASS-REASON
X-Cache-Host
X-Access
TWC-Locale-Group
TWC-GeoIP-LatLong
X-Timing-Wait
Property-Id
X-UA-Device-Type
X-Edge-Location
X-Detected-As
TWC-GeoIP-Country
TWC-Device-Class
TWC-Connection-Speed
X-Urbn-Context-Path
X-Locale
CDN-EdgeStorageId
X-ProxyCache-Status
CDN-PullZone
CDN-Uid
X-Cache-Enabled
X-PHP-Host
X-ProxyCache-Key
X-Labrador-Cache-Channel
CDN-RequestCountryCode
CDN-RequestId
X-Routing-Service
X-Server-W
X-Section
X-ServerID
X-Request-Time
X-SRV
X-Region
X-Proxied
X-Proxy-Build
X-Origin-Hint
X-Via-Fastly
X-HTML-Minification-Powered-By
CDN-CachedAt
X-Uri
X-Xfnlog-Site
X-Web-Node
X-Redis-Cache
X-Zipkin-Id
X-Hl-Ver
CDN-Cache
Azure-SlotName
X-Cache-Status-Check
X-Nginx-Cache
X-Api-Version
Azure-Version
Web-Mar-Node
X-Origin-Date
Mn-Server-Ip
Azure-SiteName
X-Tid
Azure-InstanceId
Azure-RegionName
X-R9-Blue-Green-Version
WP-Super-Cache
X-URL
X-Ms-Request-Id
X-SaId
X-JoinUs
X-Ms-Version
X-Zen-Fury
Cache-Name
X-LSADC-Cache
X-DynaTrace-JS-Agent
X-FireWall-Port
ServedBy
X-Correlation-ID
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
X-ECache
Xserver
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Ua
X-Debug-Cache
X-Human
X-Dc
Xet-Cookie
Cache
X-Cache-Tags
Source
X-MP-GENERATED-AT
X-TNCMS
X-Loop
SD-X-WS
X-TA-CDN-Provider
X-App-Version
X-Reqid
X-Varnish-Hits
X-GEO
X-RCS-CacheZone
X-Cached-By
Origin
X-Soup
X-Pubstack
X-Aspnetmvc-Version
Cross-Origin-Window-Policy
WPO-Cache-Status
WPO-Cache-Message
X-Amzn-Remapped-Content-Length
X-Cdn
X-Webkit-CSP
X-Origin-TTL
LB
X-Origin-CC
X-Tumblr-Pixel-2
X-IPS-LoggedIn
X-Service
X-Newrelic-Synthetics
From-Origin
X-Vgn-Hpd-Reason
X-B3-SpanId
X-Provided-By
X-AOL-HN
X-NewRelic-App-Data
X-Via-NSCOPI
X-Varnish-Ttl
X-GG-Cache-Date
X-Varnish-Beresp-Ttl
Rip
X-Platform-Server
X-FW-Version
X-Tec-Api-Version
X-Tec-Api-Root
Webserver
X-Tec-Api-Origin
X-Request-Host
Ngx.Var.Host
Lang
Meta-Geo-Continent
MD5-Digest
Cdnsip
Cdncip
BehaviorPad-Version
A
DCR-Decision-By
DCR-Processing-Time-Ms
Expiry
Environment
Host-ID
X-ARC
X-Rewrite-Enabled
X-Rojux
X-S
X-S-Cookie
X-Processor
X-PBS-Appsvrname
X-Forwarded-Path
X-NAPM-TraceId
X-Orig-Expires
X-Owner
X-ScT
X-Served-From
X-Vdms-Path
X-Vdms-Version
X-VG-WebCache
Xc-Version
X-User
X-TIM-N
X-Shop-Environment
X-SRCache-Key
X-Tenant
X-External-Request-Id
X-Ec-GeoHdr
X-A-Dam
X-A-Dcw
X-A-Dgt
X-A-Wwc
X-A-Ccd
X-A
Rendered-Blocks
Sslversion
Surrogated-Key
T-Server
X-Aed
X-AK-Request-ID
X-D
X-Destination
X-Developer
X-Ec-Fail
X-Connection-Hash
X-Cache-NE
X-Application
X-Bc-Bl
X-BCube-Filmed-By
Odigeo-Trace-Id
X-B-Cookie
X-CSRF-Token
HostName
X-Cluster-Node
Cache-Hits
OT-Force-Account-Verify
Upgrade-Insecure-Requests
X-B3-Traceid
X-VC
X-Qloud-Router
X-Pool
X-Accel-Buffering
Redirect-Candidate
X-Aicache-OS
X-Bip
X-Dispatcher-Number
X-Level-Front-Cache
X-Generated-On
X-Thanos
X-WA-Info
X-TIME
Mime-Version
Cache-Tv-Group
X-Cluster
X-Cdn-Srv
X-Ckpd-Fst-Backend
X-Clientip
X-Core-Mission
X-Cdn-Origin
X-CacheTTL
X-Worker
X-BBC-Edge-Cache-Status
X-Slack-Backend
X-Branch-Name
X-Core-Value
X-Datadog-Parent-Id
Producers
X-SIPLIST1
X-DPWN-IS-SECURE
X-Ec-Custom-Error
X-Device-Os
X-DefHash
X-Datadog-Sampling-Priority
X-Datadog-Trace-Id
X-DefElseHash
X-SplitTest
Release
Thinkindot-Control
Traceparent
Machine
Tube-Get-Contents
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
Server-Host
State
TDXMobile
Tube-Got-Eval
Tube-Got-Results
X-Ad-Defer-Variation
X-Epic-Correlation-Id
X-SVT-ORM-VERSION
X-Sn-Servicetimems
X-SVT-ORM-RULES
Wxu-Next-Hostname
Tube-Return
Vix-Hermes-Req-Id
Wxu-Next-Commit
Req-Svc-Chain
X-Forwarded-Site
X-Scale
X-Varnish-Remaining-TTL
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Origin-Time
X-Origin-Response-Time
X-Nyt-Route
X-Optimistic-Header
X-Sigma
X-Origin
X-Planisys-CDN-TTL
X-Varnish-CookieINHashed-On
X-V-Cache
X-Region-Sid
X-Rocket-Build-Number
X-Thinkindot-L3
X-S-Maxage
X-Variation
X-Policy
X-SB
X-Varnish-CookieHashed-On
X-NodeID
X-VG-TLSProxy
X-Gateway-Request-Id
X-Gateway-Skip-Cache
X-Gdpr
Platform
X-Gateway-Cache-Status
X-Gateway-Cache-Key
X-Fetched-On
X-Rocket-Nginx-Serving-Static
X-VServer
X-Gamma-Serve
X-Geo-Header
X-GeoIP
X-JWT-State
X-Sigma-Backend
X-Loc
X-Minions-Version
X-Is-Gdpr
X-Irp-Debug
X-GeoIP-City
X-Has-Esi
X-Hash
X-Wix-Viewer-Type
Wxu-Next-Region
NGX
Memcached
Adler-Geo
CPC-Age
Fastly-SIE
VNS-Age
CPC-Cache
Fastly-SWR
Click-Count-Error
Cache-Host
IsBot
Is-Eu
X-Varnish-Beresp-Status
Kp-EeAlive
Click-Count-Action-Start
Candidate-Md5Url
X-Parent-Response-Time
Mobile-Detection-Method
Country-Code
VNS-Cache
Origin-CC
Origin-EX
NM-Fastcgi-Cache
DSUID
Cmsid
Cmstype
Fastly-SSL
X-Gen-Mode
HA-Ipaddr
Decoy-Debug-TTL
Canary
Decoy-Debug-Key
X-Auto-Login
Datacenter
Decoy-Debug-Status
X-Scheme
X-WADP-Cache
X-Block-Status
X-CGP
X-Request-URI
X-Csrf-Jwt
CloudFront-Viewer-Country
Cluster
X-Mvc-Supplant-OutputCached
X-Mvc-Supplant-Cachable
Apple-News-Services-Request-Url
Gh-Request-Id
X-Eu-Site
Fastcgi-Cache-TTL
Ha-Gx-Prefs
X-Hnp-Log
X-NCache
Sever-Int
Servername
Svr
X-Proxy-Cache-Info
X-ZONE
X-Fmm-Version
X-Cache-Bucket
Ec-Rule-Version
X-CMSURLCustom
X-Cache-Info
X-Clara-WADP
X-Cache-Id
X-Esi-Check
Server-Hostname
Server-Ext
Fastly-Backend-Name
Mail-Subject
X-INCAP-ABP
Apple-News-Services-Handled
Fastly-GeoIP-CountryCode
X-Developers
X-Viewer-Country
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
AKAMAI
L
V-Age
User-Cache-Control
X-Gzip
X-HS-Content-Campaign-Id
We-Hiring
Web-Mar-Region
L5d-Success-Class
WebServer
X-Cache-Remote
X-Xrds-Location
X-Tx-Id
X-Rebelmouse-Cache-Control
X-Session-Fingerprint
X-RateLimit-Remaining-Second
CDCHOST
X-Cache-Debug
X-Origin-Expires
X-RateLimit-Limit-Second
X-Rebelmouse-Surrogate-Control
X-Udemy-Cache-App-Namespace
X-WP-CF-Super-Cache-Active
X-Fastly-Cache
X-ND-Cache
X-Sucuri-Cache
Ssr
X-Sucuri-ID
X-LB-NoCache
X-FC-Vary-Parameters
AMP-Access-Control-Allow-Source-Origin
X-Newrelic-App-Data
Memory
Pics-Label
Time
Sid
X-Azure-Ref-OriginShield
X-ATG-Version
X-Fastly-Backend
X-Var-Ttl
X-NWS-UUID-VERIFY
X-Pod-Name
SID
X-Nf-Request-Id
X-Tb-Optimization-Total-Bytes-Saved
X-Via-Popv
X-Via-Poph
X-Via-Popn
X-Trace-ID
X-Akamai-Transformed
Fastly-Drupal-HTML
X-Buckets
X-Generated-In
X-Refresh
X-Ig-Push-State
X-Cache-Date
X-Presslabs-Stats
X-Edge-Pop
X-Conf
Server-ID
X-Servedbyhost
Env
X-Cs
Fastly-Drupal-Html
X-Microcachable
X-Release
X-MSEdge-Features
X-MSEdge-Flight
X-Pass-Why
X-Up
X-Dmc
X-Fpc
X-NC
X-EC-Lua
X-RateLimit-Reset
X-CACHE-KEY
X-DC
X-Tumblr-Pixel-3
X-Dispatch
My-App
X-Endurance-Cache-Level
X-Esi
X-TRACE-ID
X-PX
X-Be
GeoIp-Country-Code
X-CS
X-ID
Magicmarker
X-MCACHE
X-Lambda-Id
X-Wa
CDN
X-TX-ID
X-CACHE-AGE
True-Client-IP
X-Yandex-Sdch-Disable
X-Zone
X-Wikidot-Backend
X-Air-Source
X-VCL-Version
X-Air-Hostname
X-Wikidot-Static-Cache
X-Req
X-Air-Trace-Id
X-Webkit-CSP-Report-Only
X-NGINX-Cache
X-Srv
X-Hyper-Cache
X-Vc
CacheControlHeader
X-CF-Lambda-Version
Hostname
X-CF-Lambda-Fn
X-LB-ID
X-CSRF-TOKEN
X-TH-Server
X-Micro-Cache
X-HS-Status
X-App
Pramga
X-M-Log
X-Alfa-Service
X-M-Reqid
X-Varnish-Beresp-TTL
True-Client-Country-4JS
X-Air-Pt
C-Via
X-Op-Id-All
X-Vcl-Version
Path
Resin-Trace
True-Client-Ip
X-Qnm-Cache
GeoIP-Country-Code
N-Cache
X-TrackingId
Tcn
X-Check-Cacheable
X-Platform
Tracecode
X-PAYTM-SRV-ID
On-Server
Fastcgi-X-Cache-Version
X-Vercel-Id
X-B3-Spanid
X-Vercel-Cache
X-SERVER-NAME
X-Edge-Origin-Shield-Region
Esi-Enabled
X-GeoIP-Country-Code
X-GeoIP-Region-Code
Proxy-Connection
X-FPC
X-Edge-Origin-Shield-Bytes
X-CLOUD-TRACE-CONTEXT
NtCoent-Length
X-Date
GeoIP-Latitude
Section-Origin-Responded
Section-Io-Id
X-WA
WWW-Authenticate
X-Accel-Expires-Debug
Hit
X-Datacenter
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
X-Akamai-Pragma-Client-IP
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
X-Webkit-Csp-Report-Only
X-Via-CDN
X-ServedByHost
X-Request-Start
Lb
Server-Id
X-Platform-Cluster
X-Platform-Router
X-Geo
X-SD-PageType
X-Cdn-Forward
X-LAGOON
X-AIR-PT
X-Node-Id
X-RAMCache
X-Mly-Id
X-Platform-Processor
X-API-Version
X-ApacheServer
X-PERF
YJS-ID
FSS-Cache
ENV
X-Lb-Id
Cache-Key
X-Response-By
X-Old-Content-Length
User-Agent
HIT
X-Edge-POP
X-TT-LOGID
Yjs-Id
Cdn
X-Dw-Trace-Id
X-Via-PopH
X-Via-PopN
X-Via-PopV
Powered-By
Server-Ttl
X-Proxy-CacheRZ
DynaTrace
XkeyRZ
X-Render-Time
DT-Hot-News
X-LiteSpeed-Cache-Control
X-UA
X-Location
X-Proxy-Upstream
X-Proxy-Cache-Hk
X-VarnishDD-TTL
X-Instance-Name
X-Traceid
X-Cache-Ttl
X-FORWARDED-FOR
PFcat
X-Via-Ucdn
X-CUA
X-From
XM
X-LI-Proto
X-LI-UUID
X-Li-Pop
X-Li-Fabric
Dnion-Transfer-Encoding
Geoip-Latitude
X-HN
Sm-Log-Id
X-Service-Response-Time
X-RPS
X-RSL
X-FL-EDGE
Srvid
X-RPM
X-DW
X-DB
X-DI
X-DSS
X-Lb-Nocache
Ohc-File-Size
X-CF-Powered-By
Nginx-CQVIP
XServer
X-Akamai-ERRuleID
X-Akamai-ERPolicy
Locid
X-Webstats-RespID
X-LiteSpeed-Tag
X-Fastly-Backend-Reqs
PICS-Label
Location
X-Wp-Cf-Super-Cache
X-Cache-Ngx
X-Litespeed-Cache-Control
X-Wp-Cf-Super-Cache-Cache-Control
X-Director
X-HostName
X-ElasticPress-Query
X-Cache-ASPX
Wpo-Cache-Message
Vha6-Origin
X-Cdn-Request-ID
Wpo-Cache-Status
X-Fastly-Cache-Hits
X-Varnish-Authentication
X-B3-ParentSpanId
X-Contensis-Viewer-Groups
X-Request-Url
Warning
CountryCode
X-Ips-Loggedin
Wp-Super-Cache
X-Yottaa-OS
ServerName
X-Cache-Backend
X-Nc
X-Snapshot-Date
X-Ftr-Request-Id
MIME-Version
M-TraceId
X-Moov-T
X-Moov-Xdn-Version
WZWS-RAY
SRV
Fastcgi-Cache-Ttl
Req-ID
X-Mg-Cache