Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Accept-Ranges
Expect-CT
X-XSS-Protection
Pragma
X-Powered-By
CF-RAY
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Xss-Protection
X-Served-By
X-Download-Options
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
CF-Ray
X-Adblock-Key
X-Request-ID
Access-Control-Allow-Credentials
X-FRAME-OPTIONS
X-Permitted-Cross-Domain-Policies
X-Request-Id
X-AspNet-Version
Alt-Svc
X-Runtime
Content-Security-Policy-Report-Only
X-DNS-Prefetch-Control
X-Drupal-Cache
X-Check
X-Cache-Status
X-Generator
X-Cacheable
Timing-Allow-Origin
X-Iinfo
X-Envoy-Upstream-Service-Time
P3p
X-Content-Security-Policy
X-Drupal-Dynamic-Cache
Feature-Policy
Content-Encoding
Upgrade
Access-Control-Expose-Headers
Status
X-CDN
X-AspNetMvc-Version
X-Ua-Compatible
Access-Control-Max-Age
X-Via
Server-Timing
X-UA-Device
X-Robots-Tag
Request-Context
X-Turbo-Charged-By
X-Cache-Group
EagleId
X-Amz-Request-Id
X-Amz-Id-2
X-Backend
Keep-Alive
X-AH-Environment
X-Proxy-Cache
X-Ws-Request-Id
X-Server
X-Age
Host-Header
X-Hacker
Cf-Edge-Cache
X-Vhost
X-Server-Powered-By
X-Rq
Allow
X-Varnish-Cache
X-Dispatcher
X-Amz-Version-Id
Grace
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-LiteSpeed-Cache
X-OneAgent-JS-Injection
X-WebKit-CSP
Accept-CH
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Page-Speed
Cf-Apo-Via
X-Device
Cf-Railgun
X-Dns-Prefetch-Control
X-Aws-Lambda-Call-Status
X-Server-Id
X-Host
X-Node
X-Pingback
X-Cache-Spec
X-Nginx-Cache-Status
X-Akam-SW-Version
Surrogate-Control
EagleEye-TraceId
X-Backend-Server
Request-Id
X-Ruxit-JS-Agent
X-Readtime
X-Cache-Lookup
X-HW
X-Cloud-Trace-Context
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Content-Security-Policy-Report-Only
Accept-CH-Lifetime
X-Trace
X-Application-Context
X-Response-Time
Permissions-Policy
Fastly-Restarts
X-Nginx-Upstream-Cache-Status
X-Mod-Pagespeed
X-CST
X-Edge
X-WebKit-CSP-Report-Only
Accept-Ch-Lifetime
Content-Location
X-Content-Type
X-Mcache
X-Url
X-MS-InvokeApp
X-Clacks-Overhead
X-Country
Rating
X-ECACHE
X-Midtier
X-TtlSet
X-Amz-Server-Side-Encryption
X-Vname
X-PC
RTSS
X-VARITI-CCR
Cache-Tag
X-Vcap-Request-Id
X-D2id
X-Varnish-TTL
X-Litespeed-Cache
X-Element-Page-Cache
Origin-Trial
Verso
X-Server-Name
X-Cdn-Fetch
X-Exp-Id
X-Exp-Variant
X-GoogleNews-Bot
X-Kinja-Revision
X-Kinja-Server
X-Kinja-Build
X-Use-Magma
X-Kinja
X-Ac
X-Rack-Cache
X-ESI
X-B3-TraceId
X-Cnection
X-Powered-By-Plesk
Service-Worker-Allowed
X-Cache-TTL
X-GitHub-Request-Id
X-Ttl
Xkey
X-Navigation-Version
X-Client-IP
X-Abt-Application-Version
X-SharePointHealthScore
SPRequestGuid
X-Amz-Rid
X-NWS-LOG-UUID
Edge-Control
X-Cached
X-Px
Arr-Disable-Session-Affinity
X-Mg-S
X-Kraken-Loop-Name
X-Instrumentation
X-Server-Lifecycle-Phase
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Browser-Type
SPIisLatency
SPRequestDuration
X-Upstream
X-Cache-Key
X-Correlation-Id
Display
Pagespeed
Content-MD5
X-Dw-Request-Base-Id
X-Middleton-Display
X-Sol
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Fastcgi-Cache
Access-Control-Request-Method
X-NF-Request-ID
Edge-Cache-Tag
X-Goog-Hash
Front-End-Https
X-Country-Code
X-XRDS-Location
X-Daa-Tunnel
X-Forwarded-For
X-Version
Public-Key-Pins
AR-SID
X-Id
AR-PoweredBy
AR-CACHE
AR-ATIME
X-Powered-CMS
AR-Request-ID
TCN
X-HP-Trace-Id
X-HP-Webp
X-T
X-Recruiting
X-Jurisdiction
X-MSEdge-Ref
X-Content-Digest
X-RateLimit-Remaining
X-Accel-Expires
X-Middleton-Response
Response
X-Shield-Request-Id
X-Ser
X-B3-TraceId-Primal
Mrf-Cache-Status
MRF-Tech
TP-Cache
TP-L2-Cache
X-Amzn-Trace-Id
Nginx-Cache
S
X-Ratelimit-Limit
X-Request-Received
X-Request-Processing-Time
X-HS-Hub-Id
X-HS-Combine-CSS
Server-Node
X-HS-Cache-Config
X-HS-Content-Id
X-Hits
Cache-Status
X-Distributor
X-Fastly-Request-ID
MicrosoftSharePointTeamServices
X-Edge-Location-Klb
X-Kinsta-Cache
Cache-Tags
Fastcgi-Cache
X-Grace
Server-Name
Alternate-Protocol
X-Ratelimit-Remaining
X-DataDome
X-Protected-By
X-Ezoic-Cdn
X-DIS-Request-ID
X-LB-Cache
X-Origin-Server
X-Ua-Browser
X-Ratelimit-Reset
X-Geo-Country
X-FastCGI-Cache
X-Microsite
X-Frontend
X-Request-Handler-Origin-Region
X-Rid
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
X-Debug-Info
Cross-Origin-Opener-Policy
X-Www-Served-By
X-Git-Hash
Filterid
X-Varnish-Backend
Healthy
X-Logged-In
Cleartype
X-NGENIX-Cache
Payment
X-FB-Debug
X-Forwarded-Proto
X-Page-Id
X-Load-Cache
X-Webkit-Csp
X-ASPNET-VERSION
Charset
X-LLID
X-B3-Sampled
X-Hostname
Content-Disposition
DC
X-Origin-Cache
X-Cluster-Name
X-VCache
X-TTL
MS-Author-Via
X-Ruxit-Js-Agent
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-GUploader-UploadID
X-Goog-Metageneration
X-PressLabs-Stats
X-Upgrade-Enabled
Accept-Ch
Access-Control-Allow-Method
Retry-After
X-Proxy
X-F-Cache
Accept-Charset
Cross-Origin-Resource-Policy
Realpath
X-Activity-Id
X-Type
X-AppVersion
X-Az
Paypal-Debug-Id
X-Amz-Replication-Status
X-B-Cache
X-Oracle-Dms-Rid
X-Revision
X-Contextid
X-Oracle-Dms-Ecid
X-Signature
X-Azure-Ref
X-Aspnet-Duration-Ms
Viewport
X-Amz-Meta-S3cmd-Attrs
X-Flags
X-Request-Guid
X-Providence-Cookie
X-Is-Crawler
X-Hosted-By
X-Route-Name
X-Seen-By
X-ORACLE-DMS-ECID
X-Aspnetmvc-Version
X-ORACLE-DMS-RID
X-B
X-Whom
X-TT
X-Varnish-Server
X-Fb-Rlafr
X-Wix-Request-Id
X-App-Environment
X-DynaTrace
Amp-Access-Control-Allow-Source-Origin
Surrogate-Key
Count-Hit
X-Source
Referer-Policy
X-Akamai-Edgescape
X-Language
X-Mobile
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-App-Server
X-Template
X-B3-Traceid
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Generation
X-COUNTRY
X-Cache-Control
X-RateLimit-Limit
Host
X-Varnish-Grace
X-EdgeConnect-Cache-Status
Version
X-N
X-HTML-Minification-Powered-By
X-Cache-Rule
X-Magnolia-Registration
X-Tumblr-Pixel
X-Response-Served-From
X-Original-Request-Id
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
SRV
X-Tumblr-User
X-Varnish-Age
X-UUID
X-Cache-Time
VIX-Pulpo-Node
SD-X-WS
X-Cache-Expired-At
X-Cache-Status-Check
Access-Control-Request-Headers
X-Envoy-Decorator-Operation
Refresh
VIX-Pulpo-Upstream-Status
X-RTag
X-Rule
Section-Io-Cache
Ms-Operation-Id
MS-CV
X-FW-Dynamic
X-FW-Serve
X-FW-Server
X-FW-Hash
X-Cache-Grace
X-FW-Static
Protected
X-Adobe-Content
X-Adobe-Loc
Akamai-GRN
X-Cacheable-TTL
X-FW-Version
X-FW-Type
X-RemovedCookies
X-Content-Powered-By
X-Framework
X-Page-View
X-ProcessESI
X-Jobs
NGB
X-Http-Reason
X-Device-Type
GEO-INFO
X-G
X-Status
X-Servername
X-Is-Bot
X-NYM-Debug-Backend
X-Instance
X-Rendered-As
X-L-Path
Url
X-Environment-Context
X-Backend-Name
X-User-Agent
X-Akamai-Request-ID2
X-Trace-Id
X-Debug-IsPreview
X-Debug-IsConnected
X-Drupal-Cache-Contexts
X-CDN-Forward
X-Drupal-Cache-Tags
CDN-RequestId
From-Origin
WPO-Cache-Message
WPO-Cache-Status
X-Yottaa-Metrics
X-Cache-Age
X-Yottaa-Optimizations
X-Region
X-Cache-Hit
X-Newrelic-App-Data
Accept-Language
Front
X-Nginx-Cache
Country
X-Tb
X-Node-Name
Pinterest-Generated-By
Pinterest-Version
X-Pinterest-Rid
X-Tt-Logid
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Fastly-Request-Id
Backend
X-Content-Options
Fastly-Drupal-HTML
X-Real-IP
Fastly-SIE
X-TIME
Fastly-SWR
X-Buckets
X-Mode
X-Tec-Api-Version
X-Tec-Api-Root
X-VC-Cache
Uber-Trace-Id
X-Tec-Api-Origin
X-Unique-Id
X-DynaTrace-JS-Agent
Content-Secure-Policy
X-Times
X-Cache-Operation
X-Zen-Fury
Meta-Geo
X-Tumblr-Pixel-2
X-Rewrite-Enabled
X-RN-RSRV
X-Generation-Time
Filters
X-UPSTREAM-Address
X-Access
Azure-SlotName
X-Amzn-Remapped-Content-Length
Azure-RegionName
Azure-SiteName
Azure-InstanceId
Webserver
X-Cache-Server
X-Format
X-IPS-LoggedIn
X-Section
Azure-Version
CF-IPCountry
X-Rocket-Nginx-Serving-Static
X-Proxy-Cache-Info
X-Web-Node
Onion-Location
X-Content-Age
TWC-Connection-Speed
Apigw-Requestid
TWC-Device-Class
Property-Id
X-Sucuri-Cache
X-Debug
Webcakes-App-Version
X-Server-W
X-Say-Cacheable
X-Origin-Hint
X-Reqid
X-Cms-Context
X-Proxy-Cache-Status
X-Adobe-Source
X-Cache-Action
Webcakes-Region
X-PHP-Backend
X-Cache-Host
X-Sql-Count
X-Sql-Duration-Ms
TWC-Locale-Group
X-Say-TTL
TWC-GeoIP-LatLong
X-Ua
X-Via-Fastly
X-Sucuri-ID
Cache-Hits
X-Soup
X-Locale
Webcakes-App-Name
TWC-Privacy
X-SayCDN-TTL
TWC-GeoIP-Country
X-Cache-TTL-Remaining
X-CACHE-AGE
X-Labrador-Cache-Channel
X-PHP-Host
X-Site-Version
X-Varnish-Beresp-Grace
X-Skip-Cache
X-Handled-By
X-Forwarded-Host
Web-Mar-Node
ServerID
X-SRV
X-Air-Trace-Id
X-Air-Hostname
X-Air-Source
X-URL
X-AWS-Id
X-ProxyCache-Key
X-Proto
X-ProxyCache-Status
X-R9-Blue-Green-Version
X-VWS-Id
X-UA-Device-Type
X-Ms-Version
X-Ms-Request-Id
X-Cluster
X-BYPASS-REASON
X-Cluster-Node
X-IPLB-Instance
X-IPLB-Request-ID
S-Rt
X-LJ-Flow-ID
DB-Nickname
Node
Cache-Name
Cross-Origin-Window-Policy
X-LSADC-Cache
CDN-Cache
X-JoinUs
X-LAGOON
X-GeoCode
X-Edge-Location
X-Extlb
X-FB-TRIP-ID
CDN-Uid
X-Proxied
CDN-EdgeStorageId
CDN-CachedAt
X-Timing-Wait
X-Urbn-Site-Id
X-Urbn-Context-Path
CDN-PullZone
CDN-RequestCountryCode
X-Routing-Service
X-Proxy-Build
X-SaId
X-Zipkin-Id
X-Xfnlog-Site
X-Detected-As
X-GeoCountry
Selected-Fe
Locale
ServedBy
Mn-Server-Ip
X-No-Session
WP-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
Mime-Version
Liferay-Portal
Fastcgi-Useragent
X-Optimistic-Header
X-XRDS-LOCATION
X-ECache
X-Time
X-Tumblr-Pixel-3
X-Request-Time
X-Hl-Ver
X-Oneagent-Js-Injection
Source
X-Cache-Debug
X-Redis-Cache
X-Origin-Date
X-Presslabs-Stats
X-TNCMS
Upgrade-Insecure-Requests
X-Loop
Xserver
X-GEO
X-Generated-By
CF-Cached-On
X-Uri
X-Mg-Request-UUID
X-Varnish-Hits
X-Akamai-Transformed
X-Director
Countrycode
Xet-Cookie
X-TA-CDN-Provider
X-ARC
X-Varnish-Beresp-Ttl
X-NWS-UUID-VERIFY
X-Pass-Why
X-Tx-Id
X-Newrelic-Synthetics
Frame-Options
X-FireWall-Port
X-App-Version
X-Tid
X-Origin-TTL
X-Origin-CC
X-Storage
X-Varnish-Cache-Hits
Cache-Tv-Group
X-Service
X-Shopify-Stage
X-ShopId
X-ShardId
X-Sorting-Hat-PodId
X-Storefront-Renderer-Rendered
X-DC
X-Alternate-Cache-Key
X-Varnish-Hostname
X-Sorting-Hat-ShopId
X-RM-Cache-TTL
X-Datadog-Trace-Id
X-Datadog-Parent-Id
X-Datadog-Sampled
Environment
X-Endurance-Cache-Level
X-Datadog-Sampling-Priority
X-ServerID
X-B3-Spanid
X-CMSURLCustom
X-Conf
A
BehaviorPad-Version
X-Cache-Info
X-Cache-NE
X-Gdpr
X-Destination
X-Epic-Correlation-Id
X-Request-Host
X-Ec-GeoHdr
X-BCube-Filmed-By
X-Frame-Option
X-D
X-Ec-Fail
X-Developer
X-Core-Value
X-BBC-Edge-Cache-Status
Surrogated-Key
Lang
Sslversion
Host-ID
T-Server
TDXMobile
Gannett-Cam-Experience-Id
MD5-Digest
Memcached
Odigeo-Trace-Id
Release
Origin
Ngx.Var.Host
Rendered-Blocks
Meta-Geo-Continent
Req-Svc-Chain
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
X-Aed
X-A-Wwc
X-A-Dgt
X-Application
X-B-Cookie
X-Generated-On
Candidate-Md5Url
X-A-Dcw
X-A-Dam
DCR-Processing-Time-Ms
Edge-Cache
Thinkindot-Control
DCR-Decision-By
WWW-Authenticate
X-A-Ccd
X-A
X-Bc-Bl
X-External-Request-Id
Xc-Version
X-VG-TLSProxy
Redirect-Candidate
X-Vdms-Version
X-We-Are-Hiring
X-Platform-Router
X-Origin-Time
X-Platform-Cluster
X-Platform-Processor
X-Vdms-Path
X-Rojux
X-Test
X-ScT
X-SRCache-Key
X-Served-From
X-Thinkindot-L3
X-TIM-N
X-S
X-S-Cookie
X-S-Maxage
Server-Info
X-Processor
X-Mobile-URL
X-Mid
X-Loc
X-INCAP-ABP
X-Nyt-Route
X-Level-Front-Cache
SID
X-Human
X-Httpd
X-HS-Content-Campaign-Id
X-Varnish-CookieINHashed-On
X-Varnish-Beresp-Status
X-Varnish-CookieHashed-On
X-Location
Tube-Get-Contents
Tube-Return
Vix-Hermes-Req-Id
Tube-Got-Results
Tube-Got-Eval
X-Origin-Response-Time
X-WP-CF-Super-Cache-Active
Ssr
X-Fmm-Version
X-SB
X-SVT-ORM-RULES
X-Worker
X-GeoIP-City
X-Sn-Servicetimems
X-SVT-ORM-VERSION
X-Fetched-On
X-Has-Esi
X-Varnish-Remaining-TTL
X-SD-PageType
Server-Host
X-Thanos
State
X-Rocket-Build-Number
X-DefElseHash
X-Cdn-Origin
X-DefHash
X-Bip
X-WADP-Cache
X-Pool
X-Cdn-Srv
X-Clara-WADP
X-NodeID
X-CUA
X-Core-Mission
X-Old-Content-Length
X-Platform-Server
X-Geo-Header
X-Req
X-Vmg-Version
Cache-Host
X-Org
X-Ec-Custom-Error
X-Developers
X-JWT-State
X-VServer
X-WA-Info
X-Restarts
X-Sigma-Backend
X-Auto-Login
X-Sigma
X-Akamai-Device-Characteristics
X-Is-Gdpr
X-Cache-Bucket
Cluster
DSUID
Decoy-Debug-TTL
CloudFront-Viewer-Country
Click-Count-Action-Start
Click-Count-Error
Fastly-GeoIP-CountryCode
Fastly-Backend-Name
Magicmarker
Decoy-Debug-Status
AKAMAI
Apple-News-Services-Handled
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
Decoy-Debug-Key
Apple-News-Services-Request-Url
Cache-Key
Country-Code
C-Via
X-Parent-Response-Time
Section-Io-Id
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
X-GeoIP-Country-Code
X-Date
Adler-Geo
X-Ckpd-Fst-Backend
X-Gzip
X-GeoIP-Region-Code
X-Device-Os
X-Dispatcher-Server
X-Esi-Check
X-Hnp-Log
X-Gamma-Serve
X-DPWN-IS-SECURE
X-Fastly-Backend
X-Gen-Mode
X-Dispatcher-Number
X-Minions-Version
X-Wix-Viewer-Type
CacheControlHeader
X-Varnishpool
Origin-EX
X-V-Cache
X-Var-Ttl
Gh-Request-Id
Kp-EeAlive
X-Hash
X-Pubstack
X-GeoIP
We-Hiring
Mail-Subject
NM-Fastcgi-Cache
X-Up
X-Slack-Shared-Secret-Outcome
X-Nginx-Cache-Key
X-Node-Id
X-NCache
X-Nananana
X-Men
X-Cache-Id
X-Op-Id-All
X-Origin
X-Scale
X-Slack-Backend
X-Request-Start
X-Region-Sid
X-Owner
X-Qloud-Router
X-LB-NoCache
X-Variation
Wxu-Next-Commit
Wxu-Next-Hostname
Pics-Label
Datacenter
Web-Mar-Region
Wxu-Next-Region
Cmstype
X-Ad-Defer-Variation
X-Accel-Expires-Debug
X-Accel-Buffering
Cmsid
User-Cache-Control
Producers
Machine
Sever-Int
Server-Ext
Server-Hostname
L
NGX
Origin-CC
On-Server
Svr
Is-Eu
X-App
Platform
X-Azure-Ref-OriginShield
CDCHOST
X-Block-Status
Cache-Provider
X-Cache-Backend
X-AIR-PT
X-CacheTTL
X-Planisys-CDN-Cache
X-FC-Vary-Parameters
X-Planisys-CDN-Rules
X-Irp-Debug
X-Platform
X-Mvc-Supplant-Cachable
X-Planisys-CDN-TTL
X-HN
Fastly-SSL
X-Server-ID
X-Cache-FS-Status
X-Server-IP
Canary
X-VarnishDD-TTL
X-Varnish-Ttl
X-Refresh
PFcat
X-Cache-Tags
X-Forwarded-Site
X-Cache-Date
X-Webkit-CSP-Report-Only
Ha-Gx-Prefs
L5d-Success-Class
X-Cache-Remote
X-Esi
X-Microcachable
X-Trace-ID
X-Csrf-Jwt
X-CGP
X-Eu-Site
HA-Ipaddr
X-Servedbyhost
X-Mly-Id
Env
X-Aicache-OS
X-CSRF-Token
Cdn
X-Cached-By
X-Via-Popn
X-Via-Popv
GeoIP-Latitude
X-Via-Poph
X-Mvc-Supplant-OutputCached
X-Tb-Optimization-Total-Bytes-Saved
X-HA-Backend
Load-Balancing
X-RCS-CacheZone
HostName
X-AK-Request-ID
Cdncip
Server-ID
X-Fastly-Cache
Cdnsip
X-Nc
X-Zone
X-ND-Cache
X-Wa
X-DataCenter
X-Origin-Expires
X-VC
X-Instance-Name
X-Vc
X-NGINX-Cache
X-Webkit-CSP
X-ZONE
X-Release
X-HS-Status
X-Fpc
X-Api-Version
Memory
X-Gateway-Skip-Cache
Time
X-Gateway-Cache-Key
X-Gateway-Request-Id
X-Gateway-Cache-Status
X-API-Version
X-Response-By
Cache
X-NewRelic-App-Data
Locid
Hostname
X-LB-ID
X-From
X-FL-EDGE
X-FL-QIT-DEBUG
X-Via-NSCOPI
Expect-Staple
X-Generated-In
Srvid
X-Correlation-ID
X-CS
X-CCDN-Origin-Time
X-CCDN-CacheTTL
X-APP-VERSION
X-Cache-Enabled
Eomportal-Instance
X-Edge-Pop
X-Hcs-Proxy-Type
X-Via-CDN
X-Client-Ip
X-Check-Cacheable
NtCoent-Length
X-CSRF-TOKEN
X-Via-SSL
X-Vgn-Hpd-Ssi
X-Vgn-Hpd-Cached
X-Vgn-Hpd-Variations-Key
GeoIp-Country-Code
X-Provided-By
Ngx-Var-Key
Edge-Copy-Time
X-Micro-Cache
X-Via-Edge
OT-Force-Account-Verify
AMP-Access-Control-Allow-Source-Origin
X-Air-Pt
XkeyRZ
X-Proxy-CacheRZ
X-Amz-Meta-Cb-Modifiedtime
True-Client-IP
X-MCACHE
IsBot
X-Request-URI
X-Lambda-Id
X-Vcl-Version
X-SIPLIST1
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-Via-JSL
X-Dc
X-Srv
X-Info
X-VCL-Version
X-Cache-NGX
X-Nf-Request-Id
Sid
VNS-Cache
VNS-Age
X-Vtex-Remote-Cache
X-Render-Time
CPC-Cache
CPC-Age
X-EC-Lua
X-B3-SpanId
Uri
True-Client-Ip
Path
Srv
X-Cs
Location
Resin-Trace
X-Fastly-Country-Code
X-VCT
X-TH-Server
Request-ID
X-Oss-Storage-Class
X-Cache-Expires
X-ATG-Version
X-Oss-Object-Type
X-Oss-Server-Time
X-Oss-Hash-Crc64ecma
X-Oss-Request-Id
Servername
X-CLOUD-TRACE-CONTEXT
Fastly-Drupal-Html
Esi-Enabled
X-Edge-POP
X-Cache-ASPX
Cross-Origin-Opener-Policy-Report-Only
X-Contensis-Viewer-Groups
X-Varnish-Authentication
GeoIP-Country-Code
CDN
X-MSEdge-Features
X-MSEdge-Flight
X-Upstream-Ct
X-Accel-Version
M-TraceId
X-Upstream-Ht
YJS-ID
X-TX-ID
X-Cache-Type
X-CF-Lambda-Fn
X-Lb-Id
X-Pod-Name
X-Cdn-Request-ID
X-PAYTM-SRV-ID
Traceparent
X-RateLimit-Limit-Second
Timeexpire
X-RateLimit-Remaining-Second
X-CF-Lambda-Version
X-FPC
X-Moov-T
X-Moov-Xdn-Version
X-Scheme
X-Varnish-Beresp-TTL
X-Udemy-Cache-App-Namespace
Sm-Log-Id
X-Service-Response-Time
X-Datacenter
X-Viewer-Country
X-PERF
XServer
X-Datadome
LB
X-RateLimit-Reset
CountryCode
X-ApacheServer
X-Akamai-Pragma-Client-IP
RNT-Machine
N-Cache
HIT
RNT-Time
X-CDN-Cache-Status
X-Wikidot-Static-Cache
X-SERVER-NAME
X-WA
X-Wikidot-Backend
X-Cdn-Cache-Status
X-Geo
X-Tenant
Powered-By
X-Srcache-Store-Status
X-CACHE-KEY
X-Srcache-Fetch-Status
X-Shop-Environment
X-NAPM-TraceId
Proxy-Connection
Server-Id
X-Orig-Expires
X-NC
X-Bl-Debug
Ohc-File-Size
FSS-Cache
X-Forwarded-Path
X-B3-Trace-ID
X-TraceId
X-LiteSpeed-Cache-Control
X-Ha-Backend
ENV
X-ServedByHost
Epwk-X-Cache
Yjs-Id
X-MP-GENERATED-AT
Rip
True-Client-Country-4JS
X-Dw-Trace-Id
WZWS-RAY
X-Via-PopN
X-Via-PopV
X-Cdn-Forward
V-Age
Geoip-Latitude
X-Via-PopH
X-App-Name
X-Clientip
X-Hyper-Cache
Tracecode
X-Amz-Meta-Opti
X-Policy
X-M-Log
X-M-Reqid
X-RAMCache
X-Acquia-Purge-Tags
X-Acquia-Site
X-Qnm-Cache
X-Snapshot-Date
Content-Style-Type
Content-Script-Type
X-Acquia-Application-Trace
X-Acquia-Application-UUID
Inserted-Into-Cache-At
X-VG-WebCache
X-B3-Parentspanid
X-Fastly-Backend-Reqs
XM
Ngx
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-Vgn-Hpd-Reason
User-Agent
X-Serial
X-Lb-Nocache
X-B3-ParentSpanId
Ec-Rule-Version
X-Swift-Error
X-Wp-Cf-Super-Cache-Cache-Control
X-Wp-Cf-Super-Cache
X-F-Status
X-Lsadc-Cache
X-TT-LOGID
X-Webstats-RespID
Hit
X-Fastly-Cache-Hits
X-Mid-Debug-Cache-Key
Cneonction
Warning
MIME-Version
My-App
X-LiteSpeed-Tag
X-IPS-Cached-Response
X-Cache-Ngx
X-Th-Server
X-Mid-Debug-Cache-Disk
X-Request-URL
X-MiniProfiler-Ids
X-UP
X-Stale