Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Accept-Ranges
Expect-CT
CF-RAY
Pragma
X-Powered-By
X-XSS-Protection
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-Xss-Protection
X-UA-Compatible
P3P
X-Served-By
X-Download-Options
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Request-Id
Access-Control-Allow-Credentials
X-Request-ID
CF-Ray
X-Permitted-Cross-Domain-Policies
X-AspNet-Version
Alt-Svc
Content-Security-Policy-Report-Only
X-Runtime
X-DNS-Prefetch-Control
X-Drupal-Cache
X-Check
X-Cache-Status
X-Generator
X-Cacheable
P3p
Timing-Allow-Origin
X-FRAME-OPTIONS
X-Iinfo
X-Envoy-Upstream-Service-Time
X-Content-Security-Policy
X-Drupal-Dynamic-Cache
Feature-Policy
Content-Encoding
Upgrade
Status
Access-Control-Expose-Headers
X-AspNetMvc-Version
X-CDN
Access-Control-Max-Age
X-Via
Server-Timing
X-UA-Device
X-Robots-Tag
Request-Context
X-Turbo-Charged-By
X-Cache-Group
X-Amz-Request-Id
EagleId
X-Amz-Id-2
X-Backend
Keep-Alive
X-AH-Environment
X-Proxy-Cache
X-Ws-Request-Id
X-Server
X-Age
Host-Header
X-Hacker
X-Ua-Compatible
Cf-Edge-Cache
X-Vhost
X-Server-Powered-By
X-Rq
Allow
X-Dispatcher
X-Varnish-Cache
Grace
X-Amz-Version-Id
X-LiteSpeed-Cache
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-OneAgent-JS-Injection
X-WebKit-CSP
Accept-CH
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
Cf-Apo-Via
X-Page-Speed
Cf-Railgun
X-Dns-Prefetch-Control
X-Aws-Lambda-Call-Status
X-Server-Id
X-Host
X-Pingback
X-Node
X-Cache-Spec
X-Nginx-Cache-Status
X-Akam-SW-Version
Surrogate-Control
X-Backend-Server
EagleEye-TraceId
Request-Id
X-Cache-Lookup
X-Readtime
X-Ruxit-JS-Agent
X-HW
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Cloud-Trace-Context
Accept-Ch-Lifetime
X-Content-Security-Policy-Report-Only
X-Application-Context
X-Trace
X-Response-Time
X-CST
Permissions-Policy
X-Mod-Pagespeed
X-Nginx-Upstream-Cache-Status
Fastly-Restarts
X-Edge
X-Country
Content-Location
Accept-CH-Lifetime
X-Content-Type
X-WebKit-CSP-Report-Only
X-Mcache
X-ECACHE
Rating
X-Url
X-Clacks-Overhead
X-MS-InvokeApp
X-PC
X-TtlSet
X-Vname
X-Amz-Server-Side-Encryption
X-Midtier
X-VARITI-CCR
RTSS
Cache-Tag
X-Vcap-Request-Id
X-Varnish-TTL
X-Element-Page-Cache
X-Ac
Verso
Origin-Trial
X-B3-TraceId
X-Kinja-Server
X-Use-Magma
X-D2id
X-Kinja-Revision
X-Kinja
X-GoogleNews-Bot
X-Exp-Id
X-Cdn-Fetch
X-Exp-Variant
X-Kinja-Build
X-Server-Name
X-Rack-Cache
X-Cnection
X-Cache-TTL
X-Powered-By-Plesk
Service-Worker-Allowed
X-ESI
Xkey
X-GitHub-Request-Id
X-Abt-Application-Version
X-Client-IP
X-Navigation-Version
X-NWS-LOG-UUID
Edge-Control
X-SharePointHealthScore
SPRequestGuid
X-Amz-Rid
X-Cached
X-Fastcgi-Cache
X-Px
X-Mg-S
X-Erf-Bev-Bev-Is-Generated
X-Instrumentation
X-Server-Lifecycle-Phase
X-Erf-Bev-Bev
X-Browser-Type
X-Kraken-Loop-Name
Arr-Disable-Session-Affinity
X-Ttl
X-Upstream
SPIisLatency
SPRequestDuration
X-Cache-Key
X-Sol
Display
X-Middleton-Display
Pagespeed
X-Litespeed-Cache
Content-MD5
X-Dw-Request-Base-Id
X-Correlation-Id
X-SRCache-Fetch-Status
X-SRCache-Store-Status
Access-Control-Request-Method
X-RateLimit-Remaining
Edge-Cache-Tag
X-Goog-Hash
X-Daa-Tunnel
Front-End-Https
X-Country-Code
Public-Key-Pins
X-XRDS-Location
X-Version
X-NF-Request-ID
X-Forwarded-For
AR-ATIME
X-Powered-CMS
AR-CACHE
AR-Request-ID
AR-SID
AR-PoweredBy
X-Id
X-Jurisdiction
X-HP-Trace-Id
X-HP-Webp
TCN
X-MSEdge-Ref
X-T
X-Recruiting
X-Content-Digest
X-Accel-Expires
Response
X-Middleton-Response
X-B3-TraceId-Primal
Mrf-Cache-Status
MRF-Tech
X-Ser
X-Shield-Request-Id
TP-L2-Cache
TP-Cache
X-Fastly-Request-ID
S
Nginx-Cache
X-Hits
X-Amzn-Trace-Id
X-Request-Processing-Time
X-Request-Received
Cache-Status
X-Edge-Location-Klb
X-Kinsta-Cache
X-HS-Content-Id
X-HS-Cache-Config
Server-Node
X-HS-Hub-Id
X-HS-Combine-CSS
X-Distributor
X-TTL
X-Grace
Cache-Tags
MicrosoftSharePointTeamServices
Alternate-Protocol
Server-Name
Fastcgi-Cache
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Protected-By
X-DataDome
X-DIS-Request-ID
X-Geo-Country
X-Ezoic-Cdn
X-Ruxit-Js-Agent
X-LB-Cache
X-Origin-Server
X-Microsite
X-Request-Handler-Origin-Region
X-Frontend
X-Ua-Browser
X-Ratelimit-Limit
X-Debug-Info
X-Rid
Healthy
Cross-Origin-Opener-Policy
Payment
X-Git-Hash
X-Forwarded-Proto
X-Varnish-Backend
X-NGENIX-Cache
X-Www-Served-By
Filterid
X-Logged-In
X-FB-Debug
X-Page-Id
Cleartype
X-PressLabs-Stats
X-Ratelimit-Reset
X-Load-Cache
Charset
X-B3-Sampled
X-VCache
Content-Disposition
X-Webkit-Csp
X-ASPNET-VERSION
X-Origin-Cache
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-LLID
X-Cluster-Name
MS-Author-Via
DC
X-Hostname
X-Goog-Metageneration
X-GUploader-UploadID
X-Ratelimit-Remaining
Accept-Charset
X-Upgrade-Enabled
X-RateLimit-Limit
Access-Control-Allow-Method
Retry-After
Cross-Origin-Resource-Policy
X-Proxy
X-Activity-Id
X-Az
X-Oracle-Dms-Ecid
X-F-Cache
X-AppVersion
X-Oracle-Dms-Rid
X-Contextid
X-Seen-By
X-B-Cache
X-Amz-Replication-Status
X-Signature
X-Type
X-Route-Name
X-Request-Guid
X-Hosted-By
X-Revision
X-Aspnet-Duration-Ms
Accept-Ch
X-Is-Crawler
X-Flags
X-Providence-Cookie
X-Varnish-Server
X-B
X-Wix-Request-Id
X-TT
X-Azure-Ref
Referer-Policy
X-Whom
X-Amz-Meta-S3cmd-Attrs
Viewport
Surrogate-Key
Paypal-Debug-Id
X-App-Environment
Amp-Access-Control-Allow-Source-Origin
X-DynaTrace
X-FastCGI-Cache
X-Source
X-Aspnetmvc-Version
Count-Hit
X-ORACLE-DMS-RID
X-Fb-Rlafr
X-Tt-Trace-Host
X-ORACLE-DMS-ECID
X-Tt-Trace-Tag
Realpath
X-Akamai-Edgescape
X-Mobile
X-App-Server
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-B3-Traceid
Host
X-Cache-Control
X-EdgeConnect-Cache-Status
X-Cache-Age
X-HTML-Minification-Powered-By
X-Original-Request-Id
X-N
X-Response-Served-From
Refresh
Version
X-Tumblr-Pixel-1
X-Nginx-Cache
X-Tumblr-User
X-Varnish-Grace
X-Tumblr-Pixel-0
X-Oneagent-Js-Injection
X-Cache-Rule
X-Tumblr-Pixel
X-Varnish-Age
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
SD-X-WS
Section-Io-Cache
Access-Control-Request-Headers
X-Magnolia-Registration
X-Envoy-Decorator-Operation
X-L-Path
X-Cache-Expired-At
X-Cache-Status-Check
X-Environment-Context
X-Adobe-Loc
Ms-Operation-Id
X-Adobe-Content
X-Page-View
MS-CV
X-RTag
X-Newrelic-App-Data
X-UUID
X-Cache-Time
X-Rule
X-Status
X-RemovedCookies
X-Jobs
X-Device-Type
GEO-INFO
NGB
X-Framework
X-G
X-Rendered-As
X-Is-Bot
X-ProcessESI
X-Cacheable-TTL
Protected
X-Content-Powered-By
X-Cache-Grace
X-Servername
X-FW-Type
Akamai-GRN
X-Http-Reason
X-FW-Version
X-FW-Static
X-FW-Hash
X-Akamai-Request-ID2
X-FW-Serve
X-FW-Server
X-NYM-Debug-Backend
Url
X-FW-Dynamic
X-User-Agent
X-Backend-Name
X-Debug-IsConnected
X-Instance
X-Debug-IsPreview
X-CDN-Forward
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Tb
X-Cache-Hit
X-Drupal-Cache-Contexts
X-Drupal-Cache-Tags
From-Origin
X-Tt-Logid
SRV
Pinterest-Generated-By
Pinterest-Version
X-Pinterest-Rid
WPO-Cache-Message
WPO-Cache-Status
Country
X-Region
Accept-Language
X-Node-Name
CDN-RequestId
Front
X-Trace-Id
X-URL
X-Real-IP
X-VC-Cache
Fastly-Drupal-HTML
X-Time
Backend
Uber-Trace-Id
X-Template
X-Mode
X-Language
X-Content-Options
X-Amz-Apigw-Id
X-Amzn-RequestId
Meta-Geo
X-UPSTREAM-Address
X-Cache-Operation
Fastly-SWR
X-Generation-Time
X-RN-RSRV
Filters
Fastly-SIE
X-Rewrite-Enabled
X-Tumblr-Pixel-2
X-Cache-TTL-Remaining
X-Web-Node
Webserver
X-DynaTrace-JS-Agent
Content-Secure-Policy
CDN-RequestCountryCode
X-Sql-Duration-Ms
CDN-PullZone
CDN-Cache
CDN-CachedAt
CDN-EdgeStorageId
X-Say-Cacheable
CDN-Uid
X-Adobe-Source
X-SayCDN-TTL
X-Say-TTL
Cross-Origin-Window-Policy
X-Cache-Action
X-Section
X-IPS-LoggedIn
X-Sql-Count
X-Rocket-Nginx-Serving-Static
X-Cms-Context
X-Cache-Server
Apigw-Requestid
Azure-Version
X-Access
X-Proxy-Cache-Status
CF-IPCountry
Azure-InstanceId
Azure-RegionName
Azure-SiteName
Azure-SlotName
X-WP-CF-Super-Cache
X-Proxy-Cache-Info
X-WP-CF-Super-Cache-Cache-Control
X-Format
X-Edge-Location
X-Content-Age
X-PHP-Backend
X-GeoCode
Cache-Name
X-GeoCountry
X-LJ-Flow-ID
X-Ms-Version
X-Ms-Request-Id
X-PHP-Host
X-Skip-Cache
X-ProxyCache-Status
X-Debug
X-UA-Device-Type
X-ProxyCache-Key
X-Sucuri-ID
X-Reqid
X-Sucuri-Cache
X-Cache-Host
X-Soup
X-Forwarded-Host
X-Via-Fastly
ServerID
X-Varnish-Beresp-Grace
X-AWS-Id
X-Cluster
X-BYPASS-REASON
X-VWS-Id
X-Labrador-Cache-Channel
X-Zen-Fury
X-Unique-Id
Node
X-Urbn-Context-Path
X-Site-Version
X-Urbn-Site-Id
X-Zipkin-Id
Web-Mar-Node
S-Rt
Onion-Location
X-Xfnlog-Site
Webcakes-App-Name
X-JoinUs
X-Extlb
X-Detected-As
X-LAGOON
X-No-Session
X-Amzn-Remapped-Content-Length
X-Proxied
X-SaId
X-IPLB-Request-ID
TWC-Device-Class
TWC-Connection-Speed
Property-Id
TWC-GeoIP-Country
TWC-GeoIP-LatLong
TWC-Privacy
TWC-Locale-Group
Webcakes-App-Version
Webcakes-Region
X-Proto
X-Cluster-Node
X-Server-W
X-R9-Blue-Green-Version
X-Locale
X-Origin-Hint
X-IPLB-Instance
X-Routing-Service
Locale
X-Proxy-Build
Selected-Fe
X-Fastly-Request-Id
X-Timing-Wait
WP-Super-Cache
X-LSADC-Cache
Mn-Server-Ip
X-Ua
X-Handled-By
Fastcgi-Useragent
DB-Nickname
X-Request-Time
Cache-Hits
X-Hl-Ver
X-FB-TRIP-ID
Xserver
X-Tec-Api-Root
X-Tec-Api-Version
X-Redis-Cache
Liferay-Portal
X-Tec-Api-Origin
Mime-Version
X-Cache-Debug
ServedBy
X-TIME
X-Tumblr-Pixel-3
X-TNCMS
X-NWS-UUID-VERIFY
X-XRDS-LOCATION
X-Loop
X-Optimistic-Header
X-SRV
Upgrade-Insecure-Requests
Source
X-GEO
X-Generated-By
Countrycode
X-Mg-Request-UUID
X-Origin-Date
X-Air-Trace-Id
X-Varnish-Hits
X-Air-Hostname
X-Air-Source
X-Tid
CF-Cached-On
X-Uri
X-Storage
X-Times
X-CACHE-AGE
X-Director
X-Akamai-Transformed
X-Varnish-Beresp-Ttl
Xet-Cookie
X-Tx-Id
X-Cdn
X-COUNTRY
X-TA-CDN-Provider
X-Webkit-CSP-Report-Only
Frame-Options
X-Trace-ID
X-Pass-Why
X-Origin-TTL
X-Origin-CC
X-ARC
X-Newrelic-Synthetics
X-B3-Spanid
X-Service
X-FireWall-Port
X-ECache
X-Esi
X-DC
X-App-Version
X-AIR-PT
X-Sorting-Hat-ShopId
X-Datadog-Sampled
X-ShardId
X-Storefront-Renderer-Rendered
X-Datadog-Trace-Id
X-Varnish-Cache-Hits
X-Alternate-Cache-Key
X-ShopId
X-Datadog-Sampling-Priority
X-Varnish-Hostname
Environment
X-Sorting-Hat-PodId
X-Datadog-Parent-Id
SID
X-Shopify-Stage
Server-Info
X-Presslabs-Stats
Gannett-Cam-Experience-Id
MD5-Digest
X-Request-Host
Lang
Edge-Cache
DCR-Processing-Time-Ms
Meta-Geo-Continent
Odigeo-Trace-Id
BehaviorPad-Version
A
Redirect-Candidate
Candidate-Md5Url
DCR-Decision-By
Release
Rendered-Blocks
Origin
Ngx.Var.Host
X-Destination
X-Platform-Cluster
X-Platform-Processor
X-Platform-Router
X-Processor
X-Origin-Time
X-Nyt-Route
X-Gdpr
X-Loc
X-Mid
X-Mobile-URL
X-Rojux
X-S
X-Vdms-Path
X-Vdms-Version
X-VG-TLSProxy
Xc-Version
X-TIM-N
X-SRCache-Key
X-S-Cookie
X-S-Maxage
X-ScT
X-External-Request-Id
X-Epic-Correlation-Id
X-A-Dam
X-A-Dcw
X-A-Dgt
X-A-Wwc
X-A-Ccd
X-A
Sslversion
Surrogated-Key
T-Server
X-Aed
X-Application
X-D
X-Developer
X-Ec-Fail
X-Ec-GeoHdr
X-Cache-NE
X-Cache-Info
X-B-Cookie
X-Bc-Bl
X-BCube-Filmed-By
Req-Svc-Chain
X-BBC-Edge-Cache-Status
X-Endurance-Cache-Level
X-ServerID
X-Varnish-CookieHashed-On
X-Thinkindot-L3
Fastly-GeoIP-CountryCode
X-Fmm-Version
X-Gamma-Serve
X-INCAP-ABP
X-Core-Value
X-CMSURLCustom
X-We-Are-Hiring
X-Platform-Server
Cache-Tv-Group
X-Varnish-Remaining-TTL
Country-Code
Cluster
Click-Count-Error
X-SVT-ORM-VERSION
X-Varnish-CookieINHashed-On
Decoy-Debug-TTL
Decoy-Debug-Status
X-Cache-Bucket
DSUID
Magicmarker
Tube-Got-Results
Tube-Return
Vix-Hermes-Req-Id
X-Frame-Option
Tube-Got-Eval
Tube-Get-Contents
X-Sn-Servicetimems
State
X-Buckets
WWW-Authenticate
X-Human
X-Sigma-Backend
X-Origin-Response-Time
Memcached
X-Akamai-Device-Characteristics
X-GeoIP-City
X-Old-Content-Length
X-Httpd
X-NodeID
X-Pubstack
Click-Count-Action-Start
Decoy-Debug-Key
Host-ID
X-WP-CF-Super-Cache-Active
TDXMobile
Thinkindot-CacheControl
X-Rocket-Build-Number
X-SD-PageType
X-Clara-WADP
X-Ec-Custom-Error
X-Core-Mission
X-DefElseHash
Thinkindot-CacheControl-Type
X-WADP-Cache
X-WA-Info
Thinkindot-Control
X-VServer
X-SB
X-CUA
X-Served-From
Apple-News-Services-Handled
C-Via
Cache-Host
X-Cdn-Origin
X-SVT-ORM-RULES
X-Req
X-Sigma
Apple-News-Services-Request-Url
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
X-DefHash
X-Parent-Response-Time
Section-Origin-Responded
Section-Io-Origin-Status
Section-Io-Id
Section-Io-Origin-Time-Seconds
X-Gzip
X-Generated-On
X-LB-NoCache
X-GeoIP-Region-Code
X-Dispatcher-Number
We-Hiring
User-Cache-Control
X-Thanos
X-Hnp-Log
X-Hash
X-Gen-Mode
X-JWT-State
X-Level-Front-Cache
X-Block-Status
X-Bip
X-Is-Gdpr
X-Esi-Check
X-Fetched-On
X-Fastly-Backend
X-Cache-Id
X-Cache-FS-Status
X-Restarts
X-Test
X-GeoIP
X-Ad-Defer-Variation
X-Accel-Expires-Debug
X-Accel-Buffering
X-Date
Fastly-Backend-Name
X-App
X-Worker
X-Location
X-DPWN-IS-SECURE
X-GeoIP-Country-Code
Origin-CC
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
X-Planisys-CDN-TTL
X-CSRF-Token
X-Pool
X-Cdn-Srv
X-HS-Content-Campaign-Id
Mail-Subject
X-Slack-Backend
X-Developers
L
Kp-EeAlive
Cmstype
Cmsid
Server-Host
X-Request-Start
X-Scale
X-Vmg-Version
X-Wix-Viewer-Type
Adler-Geo
Cache-Key
CloudFront-Viewer-Country
X-Auto-Login
CDCHOST
Cache-Provider
X-Varnish-Beresp-Status
Is-Eu
X-Has-Esi
X-Geo-Header
X-Origin
Producers
Server-Ext
Server-Hostname
Svr
Ssr
Sever-Int
X-Minions-Version
X-Node-Id
X-Up
X-Variation
Origin-EX
X-Var-Ttl
NM-Fastcgi-Cache
Pics-Label
Platform
Cdn
X-RM-Cache-TTL
X-Slack-Shared-Secret-Outcome
X-Server-IP
X-Op-Id-All
X-Dispatcher-Server
X-Device-Os
Web-Mar-Region
X-Region-Sid
X-NCache
X-Nginx-Cache-Key
X-Qloud-Router
X-HN
X-FC-Vary-Parameters
X-Cache-Backend
X-Irp-Debug
X-Platform
X-Refresh
X-Forwarded-Site
X-Owner
X-Aicache-OS
X-Azure-Ref-OriginShield
X-Varnishpool
Wxu-Next-Region
Machine
X-VarnishDD-TTL
Wxu-Next-Commit
AKAMAI
Datacenter
Wxu-Next-Hostname
X-Cache-Tags
Fastly-SSL
X-Conf
Gh-Request-Id
X-Ckpd-Fst-Backend
X-V-Cache
X-CacheTTL
PFcat
CacheControlHeader
X-Nananana
HostName
NGX
Ha-Gx-Prefs
HA-Ipaddr
L5d-Success-Class
X-Org
X-Men
X-Varnish-Ttl
On-Server
X-Cached-By
X-Via-Popv
X-Via-Popn
X-Cache-Remote
X-Eu-Site
X-Csrf-Jwt
X-CGP
Canary
X-Via-Poph
X-Mvc-Supplant-Cachable
X-AK-Request-ID
GeoIP-Latitude
X-HA-Backend
Cdncip
X-VC
X-Tb-Optimization-Total-Bytes-Saved
Cdnsip
X-Servedbyhost
Env
X-Cache-Date
X-Mvc-Supplant-OutputCached
X-Correlation-ID
Server-ID
X-Gateway-Cache-Status
X-Gateway-Request-Id
X-Gateway-Skip-Cache
X-Gateway-Cache-Key
X-Microcachable
X-API-Version
X-LB-ID
X-RCS-CacheZone
X-Nf-Request-Id
Cache
X-Fpc
X-ZONE
X-APP-VERSION
X-Wa
X-Mly-Id
X-Zone
X-Vgn-Hpd-Cached
X-Generated-In
Memory
X-Server-ID
Time
X-Vgn-Hpd-Variations-Key
X-Vgn-Hpd-Ssi
Request-ID
X-Webkit-CSP
Load-Balancing
X-Micro-Cache
Eomportal-Instance
Ngx-Var-Key
X-Via-NSCOPI
X-Nc
X-DataCenter
OT-Force-Account-Verify
X-ND-Cache
X-HS-Status
X-Fastly-Cache
X-Instance-Name
X-Origin-Expires
X-SIPLIST1
X-Release
X-Check-Cacheable
X-Vc
IsBot
X-Client-Ip
X-Request-URI
X-Srv
X-Response-By
X-Via-JSL
Srv
X-VCL-Version
X-Cache-NGX
X-CCDN-Origin-Time
X-CCDN-CacheTTL
X-From
Locid
Srvid
X-FL-QIT-DEBUG
X-FL-EDGE
Expect-Staple
X-Hcs-Proxy-Type
X-Info
NtCoent-Length
True-Client-Ip
X-NewRelic-App-Data
X-Cache-Enabled
X-Edge-Pop
AMP-Access-Control-Allow-Source-Origin
X-Via-CDN
Hostname
X-CS
Edge-Copy-Time
X-Api-Version
X-MCACHE
X-Via-Edge
X-Via-SSL
X-CSRF-TOKEN
X-Dc
GeoIp-Country-Code
X-Provided-By
X-Proxy-CacheRZ
XkeyRZ
X-Debug-Cache-Store
GeoIP-Country-Code
X-Amz-Meta-Cb-Modifiedtime
X-Cache-Expires
X-Lambda-Id
X-Debug-Cache-Fetch
X-NGINX-Cache
Path
Uri
Location
X-EC-Lua
True-Client-IP
X-Oss-Storage-Class
X-Oss-Request-Id
X-Oss-Server-Time
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
Resin-Trace
Sid
X-Vcl-Version
X-RateLimit-Reset
X-Cs
VNS-Age
VNS-Cache
X-Render-Time
Servername
X-Edge-POP
Cross-Origin-Opener-Policy-Report-Only
CPC-Cache
CPC-Age
X-Fastly-Country-Code
X-Vtex-Remote-Cache
X-NODE
X-B3-SpanId
Traceparent
X-Moov-T
X-Moov-Xdn-Version
X-Air-Pt
CDN
X-VCT
X-Scheme
X-TH-Server
X-Viewer-Country
Fastly-Drupal-Html
X-CLOUD-TRACE-CONTEXT
LB
X-PERF
X-ApacheServer
X-Cdn-Request-ID
X-ATG-Version
X-TX-ID
Rip
Timeexpire
Powered-By
X-NAPM-TraceId
Esi-Enabled
X-Datacenter
X-Pod-Name
X-Contensis-Viewer-Groups
X-MSEdge-Flight
X-MSEdge-Features
X-Varnish-Authentication
X-Cache-ASPX
FSS-Cache
X-Akamai-Pragma-Client-IP
X-Varnish-Beresp-TTL
X-Datadome
X-Accel-Version
M-TraceId
CountryCode
X-FPC
X-Upstream-Ht
V-Age
X-SERVER-NAME
X-PAYTM-SRV-ID
X-WA
X-Cdn-Cache-Status
X-Clientip
X-Upstream-Ct
True-Client-Country-4JS
X-RateLimit-Limit-Second
Sm-Log-Id
X-Service-Response-Time
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-RateLimit-Remaining-Second
Tracecode
X-Cache-Type
XServer
YJS-ID
X-Geo
X-Xrds-Location
X-VG-WebCache
X-LiteSpeed-Cache-Control
X-Srcache-Fetch-Status
ENV
X-Srcache-Store-Status
X-Udemy-Cache-App-Namespace
X-NC
Server-Id
X-Lb-Id
XM
HIT
Proxy-Connection
X-CACHE-KEY
Ohc-File-Size
Ngx
RNT-Time
X-TraceId
X-Wikidot-Static-Cache
X-ServedByHost
X-B3-Parentspanid
X-Wikidot-Backend
N-Cache
RNT-Machine
X-CDN-Cache-Status
Yjs-Id
X-Orig-Expires
Epwk-X-Cache
X-Hyper-Cache
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-Bl-Debug
X-Shop-Environment
X-Forwarded-Path
WZWS-RAY
X-Tenant
X-Ha-Backend
X-Cdn-Forward
Geoip-Latitude
MIME-Version
Content-Style-Type
X-Dw-Trace-Id
Content-Script-Type
X-Via-PopN
Inserted-Into-Cache-At
User-Agent
X-Vgn-Hpd-Reason
X-MiniProfiler-Ids
Pramga
Req-ID
Cdn-Requestid
X-Connection-Hash
X-Cdn-Diag
X-B3-ParentSpanId
X-Via-PopH
X-MP-GENERATED-AT
X-Serial
X-Fastly-Backend-Reqs
X-Swift-Error
Ec-Rule-Version
X-Lb-Nocache
X-Via-PopV
X-B3-Trace-ID
Expiry
X-Lsadc-Cache
X-TT-LOGID
X-F-Status
X-M-Reqid
X-Qnm-Cache
ServerName
Lb
X-Amz-Meta-Opti
X-App-Name
X-M-Log
X-Cache-Ngx
X-Stale
X-Mid-Debug-Cache-Disk
X-Mid-Debug-Cache-Key
X-Akamai-ERPolicy
X-Akamai-ERRuleID
X-Yottaa-OS
X-Webstats-RespID
X-Request-URL
X-UP
X-LiteSpeed-Tag
X-Th-Server
My-App
Cneonction
X-IPS-Cached-Response
Warning
X-Snapshot-Date