Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
Strict-Transport-Security
X-Frame-Options
X-Content-Type-Options
Last-Modified
Link
CF-Cache-Status
Cf-Request-Id
Accept-Ranges
ETag
CF-RAY
Expect-CT
Pragma
X-Powered-By
X-Cache
Via
Age
X-XSS-Protection
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Xss-Protection
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-FRAME-OPTIONS
X-Download-Options
X-Timer
X-Request-Id
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-Adblock-Key
X-AspNet-Version
X-Permitted-Cross-Domain-Policies
X-Runtime
Alt-Svc
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Check
X-DNS-Prefetch-Control
X-Cache-Status
X-Generator
CF-Ray
X-Cacheable
Timing-Allow-Origin
X-Iinfo
X-Envoy-Upstream-Service-Time
Feature-Policy
Status
X-Content-Security-Policy
X-Drupal-Dynamic-Cache
Content-Encoding
X-AspNetMvc-Version
X-Request-ID
Access-Control-Expose-Headers
X-CDN
Upgrade
X-XSS-PROTECTION
Access-Control-Max-Age
X-Ua-Compatible
X-Via
X-Dns-Prefetch-Control
X-Cache-Group
Server-Timing
X-Robots-Tag
X-UA-Device
Request-Context
Keep-Alive
X-Amz-Request-Id
X-AH-Environment
X-Turbo-Charged-By
X-Amz-Id-2
X-Backend
X-Proxy-Cache
X-Ws-Request-Id
X-Age
Host-Header
P3p
X-Server-Powered-By
X-Hacker
X-Server
X-Rq
X-Vhost
EagleId
X-Varnish-Cache
X-Akamai-Path-Stats
Grace
X-Amz-Version-Id
X-Dispatcher
X-LiteSpeed-Cache
Cf-Edge-Cache
Allow
X-Swift-CacheTime
X-Swift-SaveTime
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
Ali-Swift-Global-Savetime
X-WebKit-CSP
X-Nginx-Cache-Status
X-Device
X-Page-Speed
X-Aws-Lambda-Call-Status
X-Host
X-OneAgent-JS-Injection
X-Node
X-Server-Id
X-Pingback
EagleEye-TraceId
X-Cache-Spec
Request-Id
Cf-Railgun
Surrogate-Control
Accept-CH
X-Akam-SW-Version
X-Backend-Server
X-Cache-Lookup
X-Readtime
X-Response-Time
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-HW
Content-Location
X-Content-Security-Policy-Report-Only
X-Application-Context
Accept-CH-Lifetime
Rating
X-Trace
Fastly-Restarts
Accept-Ch-Lifetime
X-Cloud-Trace-Context
X-Country
X-WebKit-CSP-Report-Only
X-Url
X-Clacks-Overhead
X-Edge
X-B3-TraceId
X-MS-InvokeApp
X-Amz-Server-Side-Encryption
X-Rack-Cache
Edge-Control
X-PC
X-Vname
X-TtlSet
X-Ruxit-JS-Agent
X-Nginx-Upstream-Cache-Status
Accept-Ch
X-Content-Type
X-ESI
X-Vcap-Request-Id
X-Mod-Pagespeed
X-Varnish-TTL
X-FastCGI-Cache
Xkey
X-GoogleNews-Bot
X-Exp-Id
X-Kinja-Revision
X-Use-Magma
X-D2id
X-Cdn-Fetch
X-Kinja-Server
X-Exp-Variant
X-Kinja-Build
X-Kinja
X-Mcache
X-Amz-Rid
Verso
X-GitHub-Request-Id
Cache-Tag
X-VARITI-CCR
X-CST
X-Powered-By-Plesk
RTSS
X-ECACHE
Service-Worker-Allowed
X-Upstream
X-Cached
X-Navigation-Version
X-Ruxit-Js-Agent
X-Client-IP
X-Abt-Application-Version
X-Version
X-Oneagent-Js-Injection
X-Dw-Request-Base-Id
X-Px
X-Cnection
X-Ac
Public-Key-Pins
X-Instrumentation
X-Kraken-Loop-Name
Arr-Disable-Session-Affinity
X-Server-Lifecycle-Phase
X-Element-Page-Cache
SPRequestGuid
X-SharePointHealthScore
X-Server-Name
X-Sol
Pagespeed
X-Middleton-Display
Display
X-Ser
SPRequestDuration
SPIisLatency
X-Cache-TTL
X-NWS-LOG-UUID
X-Country-Code
X-RateLimit-Remaining
Permissions-Policy
X-Midtier
X-Cache-Key
X-Middleton-Response
Response
X-Kinsta-Cache
X-Edge-Location-Klb
X-NF-Request-ID
X-Goog-Hash
X-Ttl
X-Forwarded-For
Access-Control-Request-Method
Content-MD5
X-DataDome
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Shield-Request-Id
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
Front-End-Https
X-MSEdge-Ref
X-Recruiting
X-T
X-Jurisdiction
Edge-Cache-Tag
Nginx-Cache
X-HP-Trace-Id
X-HP-Webp
TP-Cache
TP-L2-Cache
AR-SID
AR-Request-ID
AR-CACHE
AR-ATIME
AR-PoweredBy
X-Powered-CMS
X-RateLimit-Limit
X-Accel-Expires
X-Correlation-Id
X-Daa-Tunnel
MicrosoftSharePointTeamServices
Mrf-Cache-Status
X-B3-TraceId-Primal
MRF-Tech
X-Grace
TCN
X-TTL
X-Id
X-Hits
X-Mg-S
X-Content-Digest
Filters
X-Request-Received
X-Request-Processing-Time
Server-Node
X-HS-Cache-Config
X-HS-Content-Id
X-HS-Hub-Id
X-HS-Combine-CSS
Server-Name
X-Amzn-Trace-Id
X-Frontend
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
Cf-Apo-Via
S
X-LLID
X-Distributor
MS-Author-Via
X-Geo-Country
X-Protected-By
Fastcgi-Cache
X-PressLabs-Stats
Cache-Status
X-Language
X-LB-Cache
X-Fastly-Request-Id
X-Origin-Server
Cross-Origin-Opener-Policy
X-Ezoic-Cdn
X-FB-Debug
Host
X-Amz-Meta-S3cmd-Attrs
Charset
X-Forwarded-Proto
X-F-Cache
X-B3-Sampled
X-Page-Id
X-Seen-By
Count-Hit
X-Git-Hash
X-Ua-Browser
X-Ab
Filterid
X-Erf-Bev-Bev
X-Browser-Type
X-Erf-Bev-Bev-Is-Generated
Payment
X-Microsite
X-Request-Handler-Origin-Region
X-Litespeed-Cache
Realpath
X-Cache-Age
X-ASPNET-VERSION
X-Ratelimit-Reset
X-Cluster-Name
X-VCache
Surrogate-Key
Accept-Charset
Cache-Tags
X-Rid
X-Origin-Cache
Alternate-Protocol
X-XRDS-Location
X-Template
X-NGENIX-Cache
X-DynaTrace
Retry-After
X-AppVersion
X-Az
X-Activity-Id
X-Www-Served-By
Access-Control-Allow-Method
X-Webkit-Csp
Cleartype
X-Varnish-Backend
X-Amz-Replication-Status
X-Route-Name
X-Request-Guid
X-Providence-Cookie
X-Aspnet-Duration-Ms
X-Type
X-Flags
X-Varnish-Grace
X-TT
X-DIS-Request-ID
X-Upgrade-Enabled
X-Is-Crawler
X-Signature
X-Tb
X-Wix-Request-Id
X-B-Cache
X-Node-Name
X-B
X-Fastcgi-Cache
X-Logged-In
X-App-Environment
Paypal-Debug-Id
DC
ServerID
X-Proxy
X-Debug
X-Drupal-Cache-Tags
X-Envoy-Decorator-Operation
Frame-Options
X-Hostname
X-Source
X-Content-Options
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Mobile
X-Fastly-Request-ID
X-Revision
X-Content
X-Load-Cache
X-Contextid
Pinterest-Version
Pinterest-Generated-By
X-Pinterest-Rid
X-Goog-Generation
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Cache-Control
X-Cache-Rule
X-Kong-Upstream-Latency
Country
X-Kong-Proxy-Latency
X-N
X-Magnolia-Registration
Amp-Access-Control-Allow-Source-Origin
X-User-Agent
Referer-Policy
X-Whom
Node
X-Response-Served-From
X-Original-Request-Id
Refresh
Viewport
X-EdgeConnect-Cache-Status
Content-Disposition
NGB
X-Varnish-Age
X-L-Path
X-Cache-TTL-Remaining
X-Cacheable-TTL
X-Debug-IsConnected
X-Environment-Context
X-Debug-IsPreview
Access-Control-Request-Headers
X-Adobe-Loc
X-G
X-Framework
X-Jobs
X-Mid
X-Akamai-Request-ID2
X-Yottaa-Metrics
X-Varnish-Server
X-Real-IP
VIX-Pulpo-Node
Url
Uber-Trace-Id
X-Servername
X-Yottaa-Optimizations
X-Page-View
X-NYM-Debug-Backend
X-Adobe-Content
X-Unique-Id
VIX-Pulpo-Upstream-Status
X-Cache-Time
X-Cache-Grace
Akamai-GRN
X-Instance
X-Rendered-As
X-Status
X-Is-Bot
X-Mg-Request-UUID
X-XRDS-LOCATION
X-Content-Powered-By
X-Restarts
X-RemovedCookies
X-ProcessESI
X-Ratelimit-Remaining
Countrycode
X-Drupal-Cache-Contexts
Version
Srv
X-Server-ID
X-App-Server
X-COUNTRY
X-Http-Reason
X-Time
X-Debug-Info
X-CDN-Forward
Accept-Language
X-Trace-Id
Protected
X-IPLB-Instance
X-IPLB-Request-ID
X-Cache-Expired-At
Healthy
X-APP-VERSION
X-Hosted-By
X-Via-JSL
X-Tumblr-Pixel-0
X-Cache-Hit
X-Tumblr-Pixel
X-Tumblr-Pixel-1
X-Tumblr-User
X-Nginx-Cache-Key
Liferay-Portal
X-Device-Type
X-Azure-Ref
X-FW-Server
Fastcgi-Useragent
X-FW-Hash
X-Ratelimit-Limit
X-Cache-Operation
X-FW-Dynamic
X-FW-Static
X-FW-Serve
X-FW-Type
X-Backend-Name
Section-Io-Cache
X-Tt-Logid
X-Cache-NGX
X-RTag
MS-CV
Ms-Operation-Id
Server-Info
X-Proxy-Cache-Status
Content-Secure-Policy
X-Correlation-ID
Backend
X-Akamai-Edgescape
X-Oracle-Dms-Ecid
X-UUID
X-Oracle-Dms-Rid
X-Mobile-URL
X-Mode
X-UPSTREAM-Address
Load-Balancing
Meta-Geo
X-RN-RSRV
X-Storage
Cross-Origin-Resource-Policy
X-Handled-By
CF-IPCountry
Webcakes-App-Version
Webcakes-App-Name
TWC-Privacy
TWC-GeoIP-LatLong
TWC-Locale-Group
Webcakes-Region
X-Forwarded-Host
GEO-INFO
X-AWS-Id
X-Cms-Context
X-Cache-Server
X-Edge-Location
X-Alternate-Cache-Key
TWC-GeoIP-Country
X-Access
X-Adobe-Source
X-Format
Onion-Location
X-Cache-Action
X-OCL
X-No-Session
X-Origin-Date
X-Origin-Hint
X-PHP-Backend
X-PCL
X-Locale
X-LJ-Flow-ID
Property-Id
S-Rt
TWC-Connection-Speed
X-Proto
Locale
Eomportal-Instance
X-Content-Age
TWC-Device-Class
X-HTML-Minification-Powered-By
X-Urbn-Context-Path
X-Urbn-Site-Id
X-SayCDN-TTL
X-Server-W
X-Say-Cacheable
X-Say-TTL
X-Section
X-Varnish-Cache-Hits
X-Storefront-Renderer-Rendered
X-VWS-Id
X-Sql-Duration-Ms
X-Varnishpool
X-Varnish-Hostname
X-Sorting-Hat-ShopId
X-Sql-Count
X-ShopId
X-Site-Version
X-Shopify-Stage
X-Region
X-Skip-Cache
X-Sorting-Hat-PodId
X-ShardId
X-Varnish-Beresp-Grace
X-GeoCode
X-Generation-Time
CDN-RequestCountryCode
X-GeoCountry
X-Timing-Wait
X-Xfnlog-Site
CDN-Uid
X-Hl-Ver
Mn-Server-Ip
DB-Nickname
X-Zipkin-Id
X-UA-Device-Type
CDN-PullZone
X-Detected-As
X-Extlb
X-FB-TRIP-ID
X-ServerID
X-BYPASS-REASON
X-Cache-Enabled
X-Cache-Host
Selected-Fe
Web-Mar-Node
X-Generated-By
X-Cache-Type
CDN-RequestId
X-Routing-Service
X-Rule
CDN-EdgeStorageId
X-VC-Cache
Apigw-Requestid
X-Via-Fastly
X-Request-Time
X-PHP-Host
X-ProxyCache-Key
X-Proxy-Build
X-Proxied
X-ProxyCache-Status
X-Redis-Cache
Azure-InstanceId
X-Uri
Azure-SiteName
CDN-Cache
Azure-RegionName
Azure-SlotName
CDN-CachedAt
X-Web-Node
Azure-Version
X-Labrador-Cache-Channel
X-Nginx-Cache
X-Tid
X-Cache-Status-Check
WP-Super-Cache
X-Zen-Fury
X-URL
X-Datadome
X-SaId
X-JoinUs
X-R9-Blue-Green-Version
X-SRV
X-Ms-Version
X-Ms-Request-Id
ServedBy
Cache-Name
X-Ua
X-Dc
X-FireWall-Port
X-DynaTrace-JS-Agent
X-Debug-Cache
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
X-LSADC-Cache
X-App-Version
X-ECache
Xserver
X-Api-Version
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Human
Source
Cache
X-Cache-Tags
SD-X-WS
Xet-Cookie
X-Cached-By
X-MP-GENERATED-AT
X-TNCMS
X-Loop
X-TA-CDN-Provider
X-RCS-CacheZone
Cross-Origin-Window-Policy
X-Varnish-Hits
X-Reqid
LB
WPO-Cache-Message
X-Aspnetmvc-Version
WPO-Cache-Status
Origin
X-Cdn
X-GEO
X-Amzn-Remapped-Content-Length
X-Soup
X-Pubstack
X-Origin-TTL
X-Origin-CC
X-Webkit-CSP
X-B3-SpanId
X-Via-NSCOPI
X-IPS-LoggedIn
X-Tumblr-Pixel-2
X-Vgn-Hpd-Reason
From-Origin
X-AOL-HN
X-Service
X-NewRelic-App-Data
X-GG-Cache-Date
X-Newrelic-Synthetics
X-FW-Version
X-Xrds-Location
X-Provided-By
Rip
X-Platform-Server
X-Varnish-Beresp-Ttl
X-Tec-Api-Origin
Webserver
X-Cluster-Node
Cache-Hits
X-Tec-Api-Version
X-Tec-Api-Root
X-Request-Host
Cdnsip
X-Destination
X-Developer
X-Cache-NE
X-Processor
X-Rewrite-Enabled
Host-ID
T-Server
BehaviorPad-Version
A
X-Connection-Hash
Lang
MD5-Digest
X-D
Meta-Geo-Continent
Ngx.Var.Host
Odigeo-Trace-Id
Rendered-Blocks
X-NAPM-TraceId
X-External-Request-Id
X-PBS-Appsvrname
Cdncip
X-Owner
Sslversion
X-Forwarded-Path
X-Orig-Expires
Surrogated-Key
X-Rojux
X-A-Dgt
X-ARC
X-TIM-N
X-Application
X-Tenant
X-A-Dcw
X-A
X-A-Ccd
X-SRCache-Key
X-VG-WebCache
X-User
X-Bc-Bl
X-BCube-Filmed-By
HostName
X-Vdms-Version
Upgrade-Insecure-Requests
X-Vdms-Path
X-AK-Request-ID
X-A-Wwc
X-Ec-Fail
X-Aed
X-Ec-GeoHdr
X-A-Dam
DCR-Processing-Time-Ms
Xc-Version
Expiry
DCR-Decision-By
X-B-Cookie
X-S
X-S-Cookie
X-CSRF-Token
X-ScT
X-Shop-Environment
Environment
X-Served-From
X-VC
OT-Force-Account-Verify
X-Qloud-Router
Fastly-SSL
X-Dispatcher-Number
X-Generated-On
X-Bip
X-Level-Front-Cache
X-Cluster
X-Accel-Buffering
Cache-Tv-Group
X-Thanos
X-WA-Info
X-Pool
X-Aicache-OS
X-Origin-Response-Time
X-TIME
X-Datadog-Sampling-Priority
X-Datadog-Trace-Id
Memcached
Kp-EeAlive
X-Device-Os
Ha-Gx-Prefs
HA-Ipaddr
Gh-Request-Id
X-Developers
Fastly-SIE
Mobile-Detection-Method
X-DefHash
X-DPWN-IS-SECURE
L5d-Success-Class
X-DefElseHash
L
Fastly-SWR
Is-Eu
IsBot
Machine
TDXMobile
Tube-Get-Contents
Tube-Got-Eval
Tube-Got-Results
Tube-Return
Traceparent
Thinkindot-Control
X-Ec-Custom-Error
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
V-Age
Vix-Hermes-Req-Id
Wxu-Next-Region
X-Ad-Defer-Variation
X-Auto-Login
Wxu-Next-Hostname
Wxu-Next-Commit
VNS-Age
VNS-Cache
X-Branch-Name
X-CacheTTL
State
X-Core-Value
X-Core-Mission
Platform
Producers
X-Csrf-Jwt
Origin-EX
NGX
NM-Fastcgi-Cache
Origin-CC
X-Clientip
Redirect-Candidate
Servername
X-Cdn-Srv
X-Cdn-Origin
X-CGP
X-Ckpd-Fst-Backend
Release
Req-Svc-Chain
Server-Host
X-Datadog-Parent-Id
X-GeoIP-City
X-Rebelmouse-Cache-Control
X-Policy
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-Rebelmouse-Surrogate-Control
X-Region-Sid
X-Rocket-Nginx-Serving-Static
X-Rocket-Build-Number
X-Request-URI
X-Planisys-CDN-Cache
X-Parent-Response-Time
DSUID
X-Minions-Version
X-Loc
X-Nyt-Route
X-Optimistic-Header
X-Origin-Time
X-Origin-Expires
X-Origin
X-S-Maxage
X-SB
X-Varnish-CookieINHashed-On
X-Varnish-CookieHashed-On
X-Variation
X-V-Cache
X-Varnish-Remaining-TTL
X-VG-TLSProxy
X-Worker
X-Wix-Viewer-Type
X-VServer
X-Thinkindot-L3
X-SVT-ORM-VERSION
X-Sigma-Backend
X-Sigma
X-Scale
X-SIPLIST1
X-Slack-Backend
X-SVT-ORM-RULES
X-SplitTest
X-Sn-Servicetimems
X-JWT-State
X-NodeID
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
Cache-Host
X-Fetched-On
Apple-News-Services-Host
Apple-News-Services-Handled
X-Gateway-Cache-Key
X-Gamma-Serve
X-Is-Gdpr
X-Forwarded-Site
Click-Count-Action-Start
Click-Count-Error
X-Epic-Correlation-Id
Decoy-Debug-Key
Decoy-Debug-Status
Decoy-Debug-TTL
CPC-Cache
CPC-Age
X-Eu-Site
Cmsid
Cmstype
Country-Code
X-Gateway-Cache-Status
Adler-Geo
X-GeoIP
X-Geo-Header
X-Has-Esi
X-Hash
X-Irp-Debug
X-INCAP-ABP
X-Gdpr
X-BBC-Edge-Cache-Status
X-Gateway-Skip-Cache
X-Gateway-Request-Id
Mime-Version
X-NCache
X-Block-Status
X-Clara-WADP
X-Viewer-Country
X-WADP-Cache
X-Varnish-Beresp-Status
X-Mvc-Supplant-Cachable
X-HS-Content-Campaign-Id
X-Mvc-Supplant-OutputCached
X-RateLimit-Remaining-Second
X-Fmm-Version
X-Proxy-Cache-Info
X-Gen-Mode
X-Session-Fingerprint
X-RateLimit-Limit-Second
X-Cache-Info
X-Scheme
X-Esi-Check
X-Cache-Id
X-Gzip
X-Hnp-Log
X-Cache-Bucket
Fastly-GeoIP-CountryCode
Fastly-Backend-Name
Mail-Subject
X-Cache-Remote
Server-Hostname
Server-Ext
Fastcgi-Cache-TTL
Datacenter
AKAMAI
X-ZONE
Candidate-Md5Url
CloudFront-Viewer-Country
Cluster
Sever-Int
CDCHOST
We-Hiring
Web-Mar-Region
Svr
User-Cache-Control
X-Tx-Id
Ec-Rule-Version
WebServer
X-LB-NoCache
Canary
X-Fastly-Cache
X-CMSURLCustom
X-NWS-UUID-VERIFY
X-Udemy-Cache-App-Namespace
X-WP-CF-Super-Cache-Active
Pics-Label
Ssr
X-Varnish-Ttl
X-Cache-Debug
X-Pod-Name
AMP-Access-Control-Allow-Source-Origin
X-Sucuri-ID
Sid
SID
X-ND-Cache
Time
X-Sucuri-Cache
Memory
X-Azure-Ref-OriginShield
X-Generated-In
X-Via-Poph
X-Via-Popn
X-FC-Vary-Parameters
X-Newrelic-App-Data
X-Var-Ttl
X-ATG-Version
X-Buckets
X-Cache-Date
X-Ig-Push-State
X-Fastly-Backend
X-Via-Popv
X-Tb-Optimization-Total-Bytes-Saved
X-Refresh
X-Akamai-Transformed
X-Microcachable
Fastly-Drupal-Html
X-Edge-Pop
X-Conf
Server-ID
X-Presslabs-Stats
X-B3-Traceid
X-TRACE-ID
X-Servedbyhost
X-MSEdge-Flight
X-MSEdge-Features
X-Release
X-Cs
Fastly-Drupal-HTML
X-Dmc
X-Trace-ID
X-Yandex-Sdch-Disable
Env
X-Nf-Request-Id
X-NC
X-Be
X-RateLimit-Reset
X-Fpc
X-Pass-Why
X-Tumblr-Pixel-3
X-Up
X-Esi
X-Endurance-Cache-Level
X-EC-Lua
X-CS
X-PX
X-Air-Source
X-Air-Hostname
My-App
GeoIp-Country-Code
X-ID
X-Dispatch
Magicmarker
X-MCACHE
X-Air-Trace-Id
X-DC
CDN
X-TX-ID
X-CLOUD-TRACE-CONTEXT
True-Client-IP
X-Wikidot-Static-Cache
X-Wa
X-Wikidot-Backend
X-Lambda-Id
X-Srv
X-CACHE-AGE
X-Zone
X-NGINX-Cache
X-Hyper-Cache
X-Webkit-CSP-Report-Only
Tcn
X-VCL-Version
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-Req
X-Vc
X-CACHE-KEY
X-App
X-M-Log
X-Micro-Cache
Pramga
Hostname
X-Alfa-Service
X-CSRF-TOKEN
X-M-Reqid
CacheControlHeader
X-LB-ID
X-TH-Server
X-Vcl-Version
X-HS-Status
C-Via
X-Qnm-Cache
Resin-Trace
True-Client-Ip
X-TrackingId
True-Client-Country-4JS
N-Cache
X-Air-Pt
X-Varnish-Beresp-TTL
X-Vercel-Id
On-Server
X-Vercel-Cache
X-Edge-Origin-Shield-Region
Path
GeoIP-Country-Code
X-Platform
Fastcgi-X-Cache-Version
X-Op-Id-All
X-PAYTM-SRV-ID
X-Edge-Origin-Shield-Bytes
Esi-Enabled
Tracecode
X-Check-Cacheable
X-SERVER-NAME
X-FPC
Proxy-Connection
X-Datacenter
X-Vtex-Remote-Cache
X-Vtex-Processado-Em
GeoIP-Latitude
X-AIR-PT
X-B3-Spanid
NtCoent-Length
X-Geo
X-Akamai-Pragma-Client-IP
X-PERF
ENV
Section-Io-Origin-Status
Hit
X-WA
X-ApacheServer
X-Node-Id
Section-Origin-Responded
X-LAGOON
X-SD-PageType
X-Request-Start
Section-Io-Origin-Time-Seconds
Section-Io-Id
X-GeoIP-Country-Code
X-GeoIP-Region-Code
X-API-Version
X-Webkit-Csp-Report-Only
HIT
X-Accel-Expires-Debug
X-Date
X-Platform-Cluster
X-Platform-Processor
X-Platform-Router
Cache-Key
X-Mly-Id
WWW-Authenticate
Cdn
X-Via-CDN
Yjs-Id
X-ServedByHost
User-Agent
Server-Id
Lb
XkeyRZ
X-RAMCache
X-Lb-Id
X-Proxy-CacheRZ
YJS-ID
DynaTrace
X-Render-Time
X-Edge-POP
DT-Hot-News
X-TT-LOGID
X-Cdn-Forward
X-Dw-Trace-Id
X-Proxy-Upstream
X-VarnishDD-TTL
FSS-Cache
X-Instance-Name
X-Via-PopH
X-Traceid
X-Via-Ucdn
X-Via-PopV
X-Via-PopN
X-Response-By
X-Old-Content-Length
XM
Server-Ttl
X-HN
PFcat
X-FORWARDED-FOR
X-LI-UUID
X-CF-Powered-By
Powered-By
X-Cache-Ttl
X-LI-Proto
X-Proxy-Cache-Hk
X-CUA
Dnion-Transfer-Encoding
Geoip-Latitude
X-Li-Fabric
X-Li-Pop
X-Service-Response-Time
X-LiteSpeed-Cache-Control
Sm-Log-Id
X-DSS
X-DB
Ohc-File-Size
X-DI
X-RPS
XServer
X-RPM
PICS-Label
Location
X-RSL
Locid
X-Akamai-ERRuleID
Nginx-CQVIP
X-Akamai-ERPolicy
X-FL-EDGE
X-Fastly-Backend-Reqs
X-Location
Srvid
X-From
X-DW
X-LiteSpeed-Tag
X-Wp-Cf-Super-Cache-Cache-Control
MIME-Version
SRV
X-Litespeed-Cache-Control
X-UA
X-Wp-Cf-Super-Cache
X-Webstats-RespID
X-Request-Url
X-Contensis-Viewer-Groups
X-Varnish-Authentication
M-TraceId
X-Cache-ASPX
X-Lb-Nocache
X-Ftr-Request-Id
X-HostName
X-Nc
X-Cdn-Request-ID
X-B3-ParentSpanId
Wpo-Cache-Message
X-Cache-Backend
X-Fastly-Cache-Hits
Wpo-Cache-Status
Vha6-Origin
Wp-Super-Cache
X-Ips-Loggedin
CountryCode
X-Cache-Ngx
Warning
X-Moov-T
X-Httpd
X-Cc-Via
X-MiniProfiler-Ids
X-Snapshot-Date
X-Moov-Xdn-Version
X-Mg-Cache
X-IN-APIGATEWAYSSL
X-IN-APIGATEWAY
WZWS-RAY
Fastcgi-Cache-Ttl
Req-ID
X-HA-Backend
X-Akamai-Request-ID