Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
Strict-Transport-Security
X-Frame-Options
X-Content-Type-Options
Last-Modified
Link
CF-Cache-Status
Cf-Request-Id
Accept-Ranges
ETag
Expect-CT
Pragma
CF-RAY
X-Powered-By
X-Cache
Via
X-XSS-Protection
Age
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Amz-Cf-Pop
X-Xss-Protection
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-FRAME-OPTIONS
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-Adblock-Key
CF-Ray
X-Permitted-Cross-Domain-Policies
X-AspNet-Version
X-Runtime
Alt-Svc
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Check
X-Cache-Status
X-Generator
X-DNS-Prefetch-Control
X-Cacheable
Timing-Allow-Origin
X-Iinfo
X-Envoy-Upstream-Service-Time
Feature-Policy
Status
X-Content-Security-Policy
X-Drupal-Dynamic-Cache
Content-Encoding
X-CDN
Access-Control-Expose-Headers
X-AspNetMvc-Version
Upgrade
X-XSS-PROTECTION
X-Dns-Prefetch-Control
X-Ua-Compatible
Access-Control-Max-Age
X-Request-ID
X-Via
Server-Timing
X-Cache-Group
X-Robots-Tag
Request-Context
X-UA-Device
Keep-Alive
X-Amz-Request-Id
X-AH-Environment
X-Turbo-Charged-By
X-Backend
P3p
X-Amz-Id-2
X-Proxy-Cache
X-Ws-Request-Id
X-Age
Host-Header
X-Server-Powered-By
X-Hacker
X-Server
X-Akamai-Path-Stats
X-Rq
EagleId
X-Vhost
X-Varnish-Cache
Grace
X-Amz-Version-Id
X-Dispatcher
X-LiteSpeed-Cache
Cf-Edge-Cache
Allow
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Nginx-Cache-Status
X-Device
X-Page-Speed
X-WebKit-CSP
X-Aws-Lambda-Call-Status
X-Host
X-OneAgent-JS-Injection
X-Node
X-Server-Id
EagleEye-TraceId
X-Pingback
X-Cache-Spec
Request-Id
Surrogate-Control
Cf-Railgun
X-Akam-SW-Version
X-Backend-Server
Accept-CH
X-Readtime
X-Cache-Lookup
X-Response-Time
Accept-CH-Lifetime
X-HW
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Content-Security-Policy-Report-Only
Content-Location
X-Application-Context
Rating
X-Trace
Fastly-Restarts
X-Cloud-Trace-Context
X-WebKit-CSP-Report-Only
X-Clacks-Overhead
X-Url
Accept-Ch-Lifetime
X-Country
X-Edge
X-Amz-Server-Side-Encryption
X-Rack-Cache
X-MS-InvokeApp
X-B3-TraceId
Edge-Control
X-TtlSet
X-PC
X-Vname
Accept-Ch
X-Ruxit-JS-Agent
X-Content-Type
X-ESI
X-Vcap-Request-Id
X-Nginx-Upstream-Cache-Status
X-Mod-Pagespeed
X-Varnish-TTL
Xkey
X-Amz-Rid
X-FastCGI-Cache
X-Mcache
X-D2id
X-VARITI-CCR
X-Exp-Id
X-Cdn-Fetch
X-Exp-Variant
X-Use-Magma
X-GoogleNews-Bot
X-Kinja-Revision
X-Kinja-Server
X-Kinja-Build
X-Kinja
Verso
X-CST
X-GitHub-Request-Id
Cache-Tag
X-ASPNET-VERSION
RTSS
X-Powered-By-Plesk
X-Ruxit-Js-Agent
X-ECACHE
X-Oneagent-Js-Injection
Service-Worker-Allowed
X-Cached
X-Upstream
X-Version
X-Client-IP
X-Abt-Application-Version
X-Navigation-Version
X-Dw-Request-Base-Id
X-Px
X-Cnection
X-Ac
Public-Key-Pins
Arr-Disable-Session-Affinity
X-Ser
X-Kraken-Loop-Name
X-Instrumentation
X-Server-Lifecycle-Phase
X-SharePointHealthScore
SPRequestGuid
X-Element-Page-Cache
X-Server-Name
Pagespeed
X-Middleton-Display
Display
X-Sol
X-Country-Code
X-Cache-TTL
SPIisLatency
SPRequestDuration
X-NWS-LOG-UUID
X-Ttl
X-NF-Request-ID
X-RateLimit-Remaining
X-Midtier
X-Cache-Key
Permissions-Policy
Response
X-Middleton-Response
X-Kinsta-Cache
X-Goog-Hash
X-Edge-Location-Klb
X-Forwarded-For
Access-Control-Request-Method
Content-MD5
X-DataDome
X-Shield-Request-Id
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-MSEdge-Ref
Front-End-Https
X-Powered-CMS
X-Correlation-Id
X-T
TP-L2-Cache
TP-Cache
Edge-Cache-Tag
X-Recruiting
AR-CACHE
X-Jurisdiction
AR-PoweredBy
AR-Request-ID
X-HP-Webp
X-HP-Trace-Id
AR-ATIME
Nginx-Cache
AR-SID
X-Accel-Expires
X-RateLimit-Limit
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
TCN
MicrosoftSharePointTeamServices
X-Daa-Tunnel
X-Grace
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
X-Mg-S
X-Id
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-Hits
X-TEC-API-ROOT
X-Request-Processing-Time
X-Request-Received
Filters
X-Content-Digest
X-HS-Hub-Id
X-HS-Combine-CSS
Server-Node
X-HS-Content-Id
X-HS-Cache-Config
Server-Name
S
X-LLID
X-TTL
X-Fastly-Request-Id
X-Amzn-Trace-Id
X-Distributor
X-Frontend
Cache-Status
X-Protected-By
X-Webkit-Csp
MS-Author-Via
X-Geo-Country
Fastcgi-Cache
X-PressLabs-Stats
X-LB-Cache
X-Request-Handler-Origin-Region
X-Microsite
X-Language
Cross-Origin-Opener-Policy
X-Forwarded-Proto
X-F-Cache
X-Seen-By
X-Origin-Server
Host
X-Page-Id
Filterid
Charset
X-Ua-Browser
X-Ezoic-Cdn
X-Ab
X-B3-Sampled
X-Git-Hash
X-FB-Debug
X-XRDS-Location
X-Amz-Meta-S3cmd-Attrs
X-Ratelimit-Reset
X-Litespeed-Cache
Payment
Count-Hit
Realpath
X-Cache-Age
X-Browser-Type
X-Erf-Bev-Bev-Is-Generated
X-Cluster-Name
X-VCache
X-Erf-Bev-Bev
Accept-Charset
Cf-Apo-Via
X-Origin-Cache
Surrogate-Key
Alternate-Protocol
X-DynaTrace
Cache-Tags
X-NGENIX-Cache
X-Rid
Retry-After
X-AppVersion
Cleartype
X-Az
X-Activity-Id
X-Template
X-Fastcgi-Cache
X-Aspnetmvc-Version
X-Www-Served-By
Access-Control-Allow-Method
X-Node-Name
X-Aspnet-Duration-Ms
X-Route-Name
X-Request-Guid
X-Flags
X-Is-Crawler
X-Providence-Cookie
X-Wix-Request-Id
X-Type
X-Signature
X-TT
X-Tb
X-B-Cache
X-Varnish-Grace
X-Amz-Replication-Status
X-App-Environment
X-Varnish-Backend
X-Upgrade-Enabled
ServerID
X-DIS-Request-ID
X-Content
X-B
X-Debug
X-Drupal-Cache-Tags
DC
Paypal-Debug-Id
X-Proxy
X-Logged-In
X-Tt-Trace-Tag
X-Tt-Trace-Host
Frame-Options
X-Envoy-Decorator-Operation
X-Hostname
X-Mobile
X-Source
X-Content-Options
X-Load-Cache
X-Revision
X-COUNTRY
Pinterest-Generated-By
X-Pinterest-Rid
Pinterest-Version
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-Goog-Generation
X-Goog-Storage-Class
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-N
X-Cache-Control
Amp-Access-Control-Allow-Source-Origin
X-Contextid
Country
X-Magnolia-Registration
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-User-Agent
Referer-Policy
Viewport
X-Whom
X-Cache-Rule
X-EdgeConnect-Cache-Status
NGB
X-Ratelimit-Remaining
X-Original-Request-Id
X-Response-Served-From
Node
Refresh
X-Varnish-Age
Content-Disposition
X-Fastly-Request-ID
X-Restarts
Access-Control-Request-Headers
X-Debug-IsConnected
X-Cacheable-TTL
X-Cache-TTL-Remaining
X-Environment-Context
X-Debug-IsPreview
X-Page-View
X-Framework
X-L-Path
X-NYM-Debug-Backend
Akamai-GRN
Uber-Trace-Id
X-Mid
X-Real-IP
X-Unique-Id
X-Varnish-Server
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Rendered-As
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-Adobe-Content
X-Akamai-Request-ID2
X-Cache-Grace
X-Cache-Time
X-Is-Bot
X-Instance
X-Mg-Request-UUID
X-Adobe-Loc
X-G
X-Drupal-Cache-Contexts
X-Servername
Url
X-Status
X-Jobs
X-Server-ID
Version
Countrycode
X-Content-Powered-By
X-Webkit-CSP
X-ProcessESI
X-App-Server
X-RemovedCookies
X-APP-VERSION
X-Debug-Info
X-Http-Reason
Srv
X-CDN-Forward
X-XRDS-LOCATION
Protected
X-IPLB-Request-ID
X-IPLB-Instance
X-Oracle-Dms-Rid
X-Oracle-Dms-Ecid
X-Hosted-By
Accept-Language
X-Nginx-Cache-Key
X-Cache-Expired-At
X-Ratelimit-Limit
X-Tt-Logid
X-Trace-Id
Liferay-Portal
Healthy
Fastcgi-Useragent
X-Device-Type
X-Via-JSL
X-Time
X-Cache-Hit
X-FW-Server
X-FW-Serve
X-FW-Dynamic
X-Tumblr-Pixel
X-FW-Static
X-Tumblr-Pixel-0
X-Tumblr-User
X-Azure-Ref
X-Tumblr-Pixel-1
X-FW-Type
X-FW-Hash
Section-Io-Cache
X-Backend-Name
MS-CV
Backend
X-RTag
X-UUID
X-Cache-NGX
Ms-Operation-Id
X-Proxy-Cache-Status
X-Cache-Operation
Content-Secure-Policy
X-Mobile-URL
Server-Info
X-UPSTREAM-Address
Load-Balancing
X-RN-RSRV
X-Storage
Meta-Geo
CF-IPCountry
X-Handled-By
X-Sql-Count
X-HTML-Minification-Powered-By
X-Datadome
X-Content-Age
X-Sql-Duration-Ms
Web-Mar-Node
TWC-Privacy
Eomportal-Instance
CDN-PullZone
CDN-EdgeStorageId
Webcakes-App-Name
Azure-Version
TWC-GeoIP-LatLong
TWC-Device-Class
CDN-RequestId
Webcakes-App-Version
CDN-CachedAt
Locale
CDN-Cache
Onion-Location
TWC-Locale-Group
TWC-Connection-Speed
CDN-Uid
Property-Id
CDN-RequestCountryCode
Webcakes-Region
X-Locale
X-Server-W
X-ShardId
X-VC-Cache
X-ShopId
X-Section
X-VWS-Id
X-Say-Cacheable
X-Say-TTL
X-SayCDN-TTL
Azure-SlotName
X-Shopify-Stage
X-Site-Version
X-Urbn-Context-Path
X-Storefront-Renderer-Rendered
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Urbn-Site-Id
X-Uri
X-Varnishpool
X-Varnish-Hostname
X-Varnish-Cache-Hits
X-Skip-Cache
X-Region
X-Redis-Cache
X-Cache-Host
X-Cache-Server
X-Cms-Context
X-Edge-Location
X-Cache-Enabled
X-AWS-Id
X-Access
X-Adobe-Source
X-Akamai-Edgescape
X-Alternate-Cache-Key
X-Format
X-Forwarded-Host
X-PCL
X-PHP-Backend
X-PHP-Host
X-Proto
X-Origin-Hint
X-Origin-Date
X-Labrador-Cache-Channel
X-LJ-Flow-ID
X-No-Session
X-OCL
WP-Super-Cache
TWC-GeoIP-Country
X-URL
GEO-INFO
Azure-RegionName
Azure-InstanceId
X-Mode
Azure-SiteName
X-Zen-Fury
X-Generation-Time
X-GeoCountry
X-Generated-By
X-GeoCode
X-BYPASS-REASON
X-Hl-Ver
X-Cache-Type
X-Detected-As
X-FB-TRIP-ID
X-ProxyCache-Key
X-Timing-Wait
X-UA-Device-Type
X-Via-Fastly
X-Web-Node
X-ServerID
X-SaId
X-Proxy-Build
X-ProxyCache-Status
X-Request-Time
X-JoinUs
X-Xfnlog-Site
Selected-Fe
S-Rt
Mn-Server-Ip
Apigw-Requestid
DB-Nickname
X-Debug-Cache
X-Extlb
X-Proxied
X-Routing-Service
X-Varnish-Beresp-Grace
X-Zipkin-Id
X-Tid
X-Correlation-ID
X-SRV
ServedBy
X-Cache-Action
X-Cache-Status-Check
X-Rule
X-R9-Blue-Green-Version
X-Ua
X-ECache
X-LSADC-Cache
X-DynaTrace-JS-Agent
X-Ms-Request-Id
Cross-Origin-Resource-Policy
Cache-Name
X-Ms-Version
X-Dc
X-Nginx-Cache
X-FireWall-Port
Cache
X-Human
Xet-Cookie
X-Cache-Tags
SD-X-WS
X-Cached-By
X-Amz-Apigw-Id
X-Amzn-RequestId
Source
Xserver
LB
Cross-Origin-Window-Policy
X-RCS-CacheZone
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
X-Loop
X-GEO
X-Cdn
X-Varnish-Hits
X-Via-NSCOPI
X-TNCMS
Origin
X-NewRelic-App-Data
X-MP-GENERATED-AT
WPO-Cache-Status
X-Reqid
X-GG-Cache-Date
X-App-Version
WPO-Cache-Message
X-Pubstack
X-Origin-TTL
X-Origin-CC
X-IPS-LoggedIn
X-Soup
X-Amzn-Remapped-Content-Length
X-TA-CDN-Provider
X-AOL-HN
Cache-Hits
X-Api-Version
X-B3-SpanId
X-FW-Version
X-Tumblr-Pixel-2
X-TIME
From-Origin
Rip
X-Platform-Server
X-Newrelic-Synthetics
X-Service
X-Cluster-Node
X-Vgn-Hpd-Reason
Upgrade-Insecure-Requests
X-Request-Host
Webserver
X-Ec-Fail
X-AK-Request-ID
Surrogated-Key
Cdncip
X-Ec-GeoHdr
Xc-Version
X-D
BehaviorPad-Version
X-Owner
X-Developer
X-Application
X-Connection-Hash
X-Aed
X-Destination
A
X-BCube-Filmed-By
Environment
X-Forwarded-Path
Expiry
X-PBS-Appsvrname
X-Provided-By
X-Cache-NE
DCR-Processing-Time-Ms
X-Bc-Bl
X-ARC
Host-ID
X-NAPM-TraceId
X-B-Cookie
DCR-Decision-By
X-External-Request-Id
X-Orig-Expires
MD5-Digest
X-Served-From
X-Session-Fingerprint
X-User
X-TIM-N
X-Origin-Response-Time
X-S-Cookie
X-Vdms-Path
X-Rojux
X-S
X-Shop-Environment
Lang
X-VG-WebCache
T-Server
Rendered-Blocks
X-SRCache-Key
Redirect-Candidate
X-Tenant
X-Accel-Buffering
Sslversion
Odigeo-Trace-Id
X-ScT
X-A-Dam
X-A-Ccd
X-A-Dgt
X-Vdms-Version
Cdnsip
Meta-Geo-Continent
Ngx.Var.Host
X-A-Dcw
X-Rewrite-Enabled
X-A-Wwc
X-A
X-Processor
OT-Force-Account-Verify
X-Cluster
X-Varnish-Beresp-Ttl
Fastly-SSL
X-Pool
X-Qloud-Router
X-Generated-On
X-Thanos
Decoy-Debug-TTL
Machine
X-Wix-Viewer-Type
X-Level-Front-Cache
Candidate-Md5Url
X-Forwarded-Site
X-Aicache-OS
Decoy-Debug-Status
X-Irp-Debug
X-Bip
Mobile-Detection-Method
Decoy-Debug-Key
X-Ckpd-Fst-Backend
TDXMobile
Tube-Get-Contents
X-Core-Value
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
X-Csrf-Jwt
X-Clientip
Traceparent
Thinkindot-Control
X-Clara-WADP
VNS-Cache
Web-Mar-Region
X-Branch-Name
X-Cache-Bucket
X-Cache-Id
Wxu-Next-Hostname
X-BBC-Edge-Cache-Status
X-Ad-Defer-Variation
X-Auto-Login
Wxu-Next-Region
X-Cache-Info
We-Hiring
Tube-Got-Results
X-Cdn-Origin
X-Cdn-Srv
Tube-Got-Eval
Tube-Return
X-CacheTTL
VNS-Age
Vix-Hermes-Req-Id
V-Age
X-CGP
X-Minions-Version
X-Request-URI
X-Region-Sid
X-Rebelmouse-Surrogate-Control
X-Rocket-Build-Number
X-Rocket-Nginx-Serving-Static
X-Scale
X-SB
X-S-Maxage
X-Rebelmouse-Cache-Control
X-RateLimit-Remaining-Second
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
X-Worker
X-Policy
X-RateLimit-Limit-Second
X-Proxy-Cache-Info
X-Sigma
X-Sigma-Backend
X-V-Cache
X-Thinkindot-L3
X-SVT-ORM-VERSION
X-Variation
X-Varnish-CookieHashed-On
X-VG-TLSProxy
X-Varnish-Remaining-TTL
X-Varnish-CookieINHashed-On
X-SVT-ORM-RULES
X-SplitTest
X-SIPLIST1
X-WA-Info
X-WADP-Cache
X-VServer
X-Viewer-Country
X-Sn-Servicetimems
X-Slack-Backend
X-Parent-Response-Time
X-Origin-Time
X-Fmm-Version
X-Fetched-On
X-Fastly-Cache
X-Gamma-Serve
X-Gateway-Cache-Key
X-Gateway-Skip-Cache
X-Gateway-Request-Id
X-Gateway-Cache-Status
X-Eu-Site
X-Esi-Check
X-Device-Os
X-Developers
X-DefHash
X-Dispatcher-Number
X-DPWN-IS-SECURE
X-Epic-Correlation-Id
X-Ec-Custom-Error
X-Gdpr
X-Geo-Header
X-NodeID
X-Mvc-Supplant-OutputCached
X-Mvc-Supplant-Cachable
X-Nyt-Route
X-Optimistic-Header
State
X-Origin-Expires
X-Origin
X-Loc
X-JWT-State
X-Gzip
X-GeoIP-City
X-GeoIP
X-Has-Esi
X-HS-Content-Campaign-Id
X-Is-Gdpr
X-INCAP-ABP
X-DefElseHash
Wxu-Next-Commit
L5d-Success-Class
L
Kp-EeAlive
IsBot
CPC-Age
Mail-Subject
NM-Fastcgi-Cache
NGX
Country-Code
Memcached
CPC-Cache
Datacenter
HostName
Fastly-Backend-Name
Fastly-SWR
Fastly-GeoIP-CountryCode
Gh-Request-Id
Ha-Gx-Prefs
DSUID
Is-Eu
X-CSRF-Token
HA-Ipaddr
Cmstype
Cmsid
Release
Producers
Fastly-SIE
Req-Svc-Chain
Apple-News-Services-Handled
Servername
Server-Host
Adler-Geo
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
Apple-News-Services-Request-Url
Origin-CC
Cluster
Click-Count-Error
Origin-EX
Platform
Click-Count-Action-Start
Cache-Host
Cache-Tv-Group
Mime-Version
X-Tx-Id
X-Xrds-Location
X-VC
X-Cache-Remote
WebServer
X-NCache
Sever-Int
CDCHOST
User-Cache-Control
AKAMAI
CloudFront-Viewer-Country
X-Core-Mission
X-Scheme
Svr
Server-Hostname
X-Gen-Mode
Server-Ext
X-Block-Status
Fastcgi-Cache-TTL
X-Hash
X-Hnp-Log
X-NWS-UUID-VERIFY
X-Pod-Name
X-Ua-Device
X-Varnish-Ttl
X-Varnish-Beresp-Status
X-LB-NoCache
X-Udemy-Cache-App-Namespace
Ec-Rule-Version
Ssr
X-CMSURLCustom
X-Ig-Push-State
X-Cache-Date
Pics-Label
Canary
X-ZONE
SID
X-Microcachable
X-Tb-Optimization-Total-Bytes-Saved
X-Sucuri-Cache
Memory
Time
X-Conf
X-Yandex-Sdch-Disable
X-Sucuri-ID
Sid
X-WP-CF-Super-Cache-Active
X-Generated-In
X-ATG-Version
Fastly-Drupal-Html
X-Fastly-Backend
X-Var-Ttl
X-Azure-Ref-OriginShield
X-ND-Cache
X-FC-Vary-Parameters
X-Cache-Debug
X-Tec-Api-Origin
X-Tec-Api-Root
X-Akamai-Transformed
X-B3-Traceid
X-Tec-Api-Version
AMP-Access-Control-Allow-Source-Origin
X-Presslabs-Stats
X-Refresh
X-Dmc
X-Via-Poph
X-Via-Popv
X-TRACE-ID
X-Edge-Pop
X-Servedbyhost
Server-ID
X-Via-Popn
X-Be
Env
X-Trace-ID
X-Cs
X-Newrelic-App-Data
X-MSEdge-Flight
X-MSEdge-Features
X-Fpc
X-CS
X-Air-Hostname
X-Release
X-Air-Trace-Id
X-NC
Fastly-Drupal-HTML
X-Air-Source
X-Buckets
X-Esi
X-PX
X-MCACHE
X-Zone
X-EC-Lua
GeoIp-Country-Code
X-ID
X-Wikidot-Static-Cache
Magicmarker
X-Endurance-Cache-Level
X-Wikidot-Backend
X-NGINX-Cache
CDN
X-DC
X-Up
X-CACHE-AGE
X-Tumblr-Pixel-3
X-RateLimit-Reset
True-Client-IP
X-Hyper-Cache
X-TX-ID
X-Pass-Why
X-VCL-Version
X-Wa
X-CF-Lambda-Version
X-Vc
X-Dispatch
X-CF-Lambda-Fn
My-App
X-Srv
X-Webkit-CSP-Report-Only
Hostname
X-M-Reqid
X-M-Log
X-Micro-Cache
X-App
X-CSRF-TOKEN
Pramga
X-Lambda-Id
X-CACHE-KEY
X-Alfa-Service
C-Via
X-Qnm-Cache
X-Req
X-TrackingId
N-Cache
X-Varnish-Beresp-TTL
X-Edge-Origin-Shield-Region
X-Vcl-Version
X-Platform
X-PAYTM-SRV-ID
On-Server
X-Air-Pt
X-Edge-Origin-Shield-Bytes
Path
Resin-Trace
Fastcgi-X-Cache-Version
X-Check-Cacheable
Esi-Enabled
True-Client-Ip
X-HS-Status
X-Vercel-Id
CacheControlHeader
X-TH-Server
X-Vercel-Cache
Tcn
GeoIP-Latitude
GeoIP-Country-Code
X-AIR-PT
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
X-Nf-Request-Id
Tracecode
True-Client-Country-4JS
X-B3-Spanid
X-LB-ID
NtCoent-Length
X-PERF
X-SERVER-NAME
X-ApacheServer
X-LAGOON
Proxy-Connection
X-API-Version
X-Op-Id-All
X-Node-Id
X-Request-Start
X-Akamai-Pragma-Client-IP
X-SD-PageType
Cdn
X-CLOUD-TRACE-CONTEXT
HIT
Hit
X-FPC
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
Section-Origin-Responded
Section-Io-Id
Cache-Key
X-Mly-Id
DT-Hot-News
X-Webkit-Csp-Report-Only
X-GeoIP-Region-Code
X-Render-Time
X-WA
X-Via-CDN
X-Lb-Id
X-Geo
X-GeoIP-Country-Code
X-Platform-Router
X-Proxy-CacheRZ
X-Platform-Cluster
XkeyRZ
X-Platform-Processor
DynaTrace
ENV
X-Dw-Trace-Id
X-ServedByHost
Server-Id
PFcat
X-HN
Lb
X-Via-PopH
X-Via-Ucdn
X-Via-PopN
X-Via-PopV
XM
X-VarnishDD-TTL
X-Traceid
X-Edge-POP
X-Date
X-Datacenter
WWW-Authenticate
X-Accel-Expires-Debug
X-Proxy-Upstream
User-Agent
X-Cdn-Forward
YJS-ID
X-RAMCache
X-LiteSpeed-Cache-Control
X-Proxy-Cache-Hk
Server-Ttl
X-DB
X-Li-Pop
X-LI-Proto
X-Cache-Ttl
MIME-Version
X-Wp-Cf-Super-Cache-Cache-Control
X-Li-Fabric
X-LiteSpeed-Tag
SRV
X-Wp-Cf-Super-Cache
X-TT-LOGID
X-LI-UUID
X-DW
X-FORWARDED-FOR
X-CUA
X-RSL
X-CF-Powered-By
Yjs-Id
X-DSS
Geoip-Latitude
X-DI
X-RPM
X-RPS
Dnion-Transfer-Encoding
Nginx-CQVIP
Vha6-Origin
Sm-Log-Id
XServer
Wpo-Cache-Message
Wpo-Cache-Status
Ohc-File-Size
PICS-Label
X-Old-Content-Length
Location
FSS-Cache
X-Instance-Name
X-Ftr-Request-Id
X-Fastly-Backend-Reqs
X-Akamai-ERPolicy
X-Akamai-ERRuleID
X-Cache-Backend
M-TraceId
X-Service-Response-Time
X-Response-By
X-Nc
X-UA
X-Litespeed-Cache-Control
X-Lb-Nocache
X-IN-APIGATEWAY
X-Request-Url
X-Httpd
X-B3-ParentSpanId
X-Fastly-Cache-Hits
X-Mg-Cache
Powered-By
X-Cc-Via
X-Akamai-Request-ID
X-IN-APIGATEWAYSSL
X-Cdn-Request-ID
X-HostName
X-HA-Backend
X-Cache-Ngx
Warning
CountryCode
X-Webstats-RespID
X-From
X-DataCenter
Srvid
Locid
X-FL-EDGE
X-Snapshot-Date
Ohc-Cache-HIT
X-MiniProfiler-Ids
X-Server-IP
X-Serial
Uri
X-Moov-T
Fastcgi-Cache-Ttl
Req-ID
X-Moov-Xdn-Version
WZWS-RAY