Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Accept-Ranges
X-XSS-Protection
Expect-CT
Pragma
X-Powered-By
CF-RAY
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
P3P
X-Served-By
X-Xss-Protection
X-Download-Options
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
CF-Ray
X-Adblock-Key
Access-Control-Allow-Credentials
X-FRAME-OPTIONS
X-Request-ID
X-Request-Id
X-Permitted-Cross-Domain-Policies
X-AspNet-Version
Alt-Svc
X-Runtime
Content-Security-Policy-Report-Only
X-DNS-Prefetch-Control
X-Drupal-Cache
X-Check
X-Cache-Status
X-Generator
X-Cacheable
Timing-Allow-Origin
X-Iinfo
X-Envoy-Upstream-Service-Time
P3p
X-Content-Security-Policy
X-Drupal-Dynamic-Cache
Feature-Policy
Content-Encoding
Access-Control-Expose-Headers
Upgrade
Status
X-CDN
X-AspNetMvc-Version
Access-Control-Max-Age
X-Via
Server-Timing
X-UA-Device
X-Robots-Tag
Request-Context
X-Turbo-Charged-By
X-Cache-Group
X-Amz-Request-Id
EagleId
X-Amz-Id-2
X-Backend
X-AH-Environment
Keep-Alive
X-Proxy-Cache
X-Server
X-Ua-Compatible
X-Ws-Request-Id
X-Age
Host-Header
X-Hacker
Cf-Edge-Cache
X-Vhost
X-Server-Powered-By
X-Rq
X-Varnish-Cache
X-Dispatcher
Allow
X-Amz-Version-Id
Grace
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-OneAgent-JS-Injection
X-LiteSpeed-Cache
X-WebKit-CSP
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Page-Speed
Accept-CH
Cf-Apo-Via
X-Device
X-Dns-Prefetch-Control
Cf-Railgun
X-Aws-Lambda-Call-Status
X-Node
X-Host
X-Pingback
X-Server-Id
X-Cache-Spec
X-Nginx-Cache-Status
X-Akam-SW-Version
Surrogate-Control
EagleEye-TraceId
X-Ruxit-JS-Agent
X-Backend-Server
Request-Id
X-Readtime
X-Cache-Lookup
X-HW
X-Cloud-Trace-Context
X-Content-Security-Policy-Report-Only
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Trace
X-Application-Context
X-Response-Time
Permissions-Policy
Fastly-Restarts
X-Nginx-Upstream-Cache-Status
X-Mod-Pagespeed
Accept-CH-Lifetime
Accept-Ch-Lifetime
X-Edge
X-WebKit-CSP-Report-Only
X-CST
Content-Location
X-Content-Type
X-Url
X-Mcache
X-MS-InvokeApp
X-Clacks-Overhead
X-Country
Rating
X-Midtier
X-PC
X-TtlSet
X-Vname
X-Amz-Server-Side-Encryption
X-Litespeed-Cache
X-ECACHE
RTSS
X-VARITI-CCR
Cache-Tag
X-ESI
X-Vcap-Request-Id
X-D2id
X-Element-Page-Cache
Origin-Trial
X-Server-Name
Verso
X-Cdn-Fetch
X-GoogleNews-Bot
X-Kinja-Revision
X-Kinja-Server
X-Kinja-Build
X-Exp-Id
X-Exp-Variant
X-Kinja
X-Use-Magma
X-Ac
X-Ttl
X-Rack-Cache
X-Cnection
X-Powered-By-Plesk
Service-Worker-Allowed
X-GitHub-Request-Id
X-SharePointHealthScore
X-Cache-TTL
SPRequestGuid
X-Varnish-TTL
Xkey
X-Navigation-Version
X-B3-TraceId
X-Client-IP
X-Amz-Rid
X-Abt-Application-Version
Edge-Control
X-NWS-LOG-UUID
SPRequestDuration
SPIisLatency
X-Cached
Arr-Disable-Session-Affinity
X-Upstream
X-Server-Lifecycle-Phase
X-Browser-Type
X-Kraken-Loop-Name
X-Erf-Bev-Bev-Is-Generated
X-Instrumentation
X-Erf-Bev-Bev
X-Mg-S
X-Px
X-Cache-Key
X-Dw-Request-Base-Id
X-Correlation-Id
X-Middleton-Display
Pagespeed
X-Sol
Display
Content-MD5
X-SRCache-Store-Status
X-SRCache-Fetch-Status
Access-Control-Request-Method
X-NF-Request-ID
Edge-Cache-Tag
X-Goog-Hash
X-XRDS-Location
X-Country-Code
Front-End-Https
X-Forwarded-For
X-Version
X-Daa-Tunnel
X-Powered-CMS
X-Id
TCN
Public-Key-Pins
AR-PoweredBy
AR-Request-ID
AR-SID
AR-ATIME
AR-CACHE
X-Fastcgi-Cache
X-Jurisdiction
X-HP-Trace-Id
X-HP-Webp
X-Recruiting
X-T
X-MSEdge-Ref
X-Content-Digest
X-RateLimit-Remaining
X-Accel-Expires
X-Middleton-Response
Response
X-Ser
X-Amzn-Trace-Id
TP-Cache
X-Shield-Request-Id
TP-L2-Cache
X-FastCGI-Cache
MRF-Tech
Mrf-Cache-Status
X-B3-TraceId-Primal
S
Nginx-Cache
X-Webkit-Csp
X-Request-Processing-Time
X-Ratelimit-Limit
X-Request-Received
MicrosoftSharePointTeamServices
X-HS-Hub-Id
X-HS-Combine-CSS
X-HS-Content-Id
X-HS-Cache-Config
Server-Node
Cache-Status
X-Distributor
X-Hits
Cache-Tags
Accept-Ch
X-Kinsta-Cache
X-Edge-Location-Klb
X-Grace
Fastcgi-Cache
Alternate-Protocol
X-Ratelimit-Remaining
Server-Name
X-DataDome
X-LB-Cache
X-Ezoic-Cdn
X-Origin-Server
X-Ratelimit-Reset
X-Ua-Browser
X-DIS-Request-ID
X-Geo-Country
X-Protected-By
Cross-Origin-Opener-Policy
X-Fastly-Request-ID
X-Request-Handler-Origin-Region
X-Microsite
Filterid
X-Rid
X-TEC-API-ROOT
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-Frontend
X-Varnish-Backend
Healthy
X-Debug-Info
X-Logged-In
X-Www-Served-By
X-Git-Hash
Cleartype
Payment
X-FB-Debug
X-Page-Id
X-NGENIX-Cache
X-Forwarded-Proto
X-LLID
X-Load-Cache
X-Hostname
X-ASPNET-VERSION
X-Origin-Cache
Charset
X-Cluster-Name
X-PressLabs-Stats
DC
X-B3-Sampled
Content-Disposition
MS-Author-Via
X-GUploader-UploadID
X-Goog-Metageneration
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-VCache
Access-Control-Allow-Method
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Upgrade-Enabled
X-Proxy
Realpath
X-F-Cache
Retry-After
X-Activity-Id
X-AppVersion
X-Az
Cross-Origin-Resource-Policy
X-Contextid
X-TTL
Accept-Charset
X-Amz-Replication-Status
X-Seen-By
Paypal-Debug-Id
X-B-Cache
X-Signature
X-Revision
X-Amz-Meta-S3cmd-Attrs
X-Type
X-Hosted-By
X-Fb-Rlafr
X-Azure-Ref
X-Aspnet-Duration-Ms
X-Is-Crawler
X-Providence-Cookie
X-Whom
X-Route-Name
X-Request-Guid
Viewport
X-Flags
X-App-Environment
X-Aspnetmvc-Version
Surrogate-Key
X-Varnish-Server
X-Wix-Request-Id
X-B
X-DynaTrace
X-TT
Count-Hit
X-B3-Traceid
Amp-Access-Control-Allow-Source-Origin
X-Akamai-Edgescape
X-Oracle-Dms-Rid
X-Oracle-Dms-Ecid
X-Language
X-Source
Referer-Policy
X-Ruxit-Js-Agent
X-App-Server
X-Mobile
X-RateLimit-Limit
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-Goog-Stored-Content-Length
X-Cache-Control
X-COUNTRY
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Template
Host
X-Magnolia-Registration
X-Varnish-Grace
Version
X-HTML-Minification-Powered-By
X-N
X-Cache-Age
X-Cache-Rule
X-Fastly-Request-Id
X-EdgeConnect-Cache-Status
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-Response-Served-From
X-Tumblr-User
X-Original-Request-Id
SRV
X-Tumblr-Pixel
X-Cache-Time
X-Varnish-Age
X-RTag
X-Rule
MS-CV
X-UUID
Ms-Operation-Id
X-Cache-Expired-At
X-Trace-Id
Access-Control-Request-Headers
X-Cache-Status-Check
X-Framework
VIX-Pulpo-Upstream-Status
Section-Io-Cache
VIX-Pulpo-Node
X-Content-Powered-By
SD-X-WS
X-Envoy-Decorator-Operation
X-ECache
X-ProcessESI
X-Cache-Grace
X-Device-Type
X-RemovedCookies
X-Page-View
X-FW-Serve
X-FW-Static
X-Cacheable-TTL
X-User-Agent
X-FW-Type
X-FW-Version
X-Adobe-Loc
X-Adobe-Content
X-FW-Dynamic
X-FW-Server
Protected
X-Backend-Name
Akamai-GRN
X-FW-Hash
X-Status
GEO-INFO
Refresh
NGB
Url
X-Rendered-As
X-L-Path
X-Instance
X-Jobs
X-Is-Bot
X-G
X-Server-ID
X-NYM-Debug-Backend
X-Servername
X-Environment-Context
X-Http-Reason
X-Akamai-Request-ID2
X-Drupal-Cache-Contexts
X-Drupal-Cache-Tags
CDN-RequestId
X-CDN-Forward
From-Origin
WPO-Cache-Status
WPO-Cache-Message
X-Debug-IsConnected
X-Debug-IsPreview
X-Region
X-Times
Front
X-Yottaa-Metrics
X-Cache-Hit
X-Yottaa-Optimizations
Accept-Language
X-Amz-Apigw-Id
X-Amzn-RequestId
Country
X-Tb
X-Nginx-Cache
Backend
X-Content-Options
X-Unique-Id
X-Node-Name
X-Tt-Logid
Fastly-SIE
Fastly-SWR
Pinterest-Generated-By
X-Pinterest-Rid
X-TIME
X-Zen-Fury
Pinterest-Version
X-Tec-Api-Origin
X-Real-IP
X-Tec-Api-Root
X-Tec-Api-Version
X-Newrelic-App-Data
X-DynaTrace-JS-Agent
X-Mode
X-Air-Hostname
X-Air-Source
X-Air-Trace-Id
X-Cache-Operation
Content-Secure-Policy
Uber-Trace-Id
X-VC-Cache
X-Buckets
X-Ms-Version
X-RN-RSRV
X-Rewrite-Enabled
X-Proxy-Cache-Info
X-Generation-Time
X-Ms-Request-Id
Meta-Geo
X-Amzn-Remapped-Content-Length
X-Cache-Server
Filters
X-UPSTREAM-Address
X-Tumblr-Pixel-2
Webserver
CF-IPCountry
X-Rocket-Nginx-Serving-Static
Onion-Location
X-Format
X-Section
X-Web-Node
X-Content-Age
Azure-SiteName
Azure-RegionName
X-IPS-LoggedIn
Azure-Version
Azure-InstanceId
X-Reqid
Azure-SlotName
Cache-Hits
X-Access
X-Cluster
X-Cache-TTL-Remaining
X-BYPASS-REASON
X-AWS-Id
X-Cluster-Node
X-Debug
X-LJ-Flow-ID
X-IPLB-Request-ID
X-IPLB-Instance
X-Adobe-Source
Webcakes-Region
TWC-GeoIP-Country
TWC-Device-Class
TWC-Connection-Speed
ServedBy
TWC-GeoIP-LatLong
TWC-Locale-Group
Webcakes-App-Version
Webcakes-App-Name
TWC-Privacy
X-Locale
X-Origin-Hint
X-Sucuri-Cache
X-Sql-Duration-Ms
X-Sql-Count
X-Soup
X-Sucuri-ID
X-Ua
X-VWS-Id
X-Via-Fastly
X-UA-Device-Type
X-Server-W
X-SayCDN-TTL
X-Proxy-Cache-Status
X-Proto
X-PHP-Backend
X-ProxyCache-Key
X-ProxyCache-Status
X-Say-TTL
X-Say-Cacheable
X-R9-Blue-Green-Version
Property-Id
X-Cms-Context
Fastly-Drupal-HTML
Node
Liferay-Portal
X-Labrador-Cache-Channel
Apigw-Requestid
ServerID
X-Site-Version
S-Rt
X-Cache-Action
X-Cache-Host
X-Forwarded-Host
X-No-Session
Cache-Name
X-Skip-Cache
X-PHP-Host
X-Handled-By
Web-Mar-Node
DB-Nickname
X-Varnish-Beresp-Grace
X-Proxy-Build
X-Proxied
Cross-Origin-Window-Policy
X-Timing-Wait
X-LAGOON
X-Xfnlog-Site
X-Detected-As
X-GeoCountry
X-LSADC-Cache
X-JoinUs
X-GeoCode
X-FB-TRIP-ID
X-Edge-Location
X-Extlb
X-Routing-Service
X-Zipkin-Id
Mn-Server-Ip
X-SaId
Selected-Fe
X-Urbn-Site-Id
WP-Super-Cache
X-Urbn-Context-Path
Locale
Mime-Version
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
CDN-Cache
CDN-CachedAt
CDN-EdgeStorageId
CDN-PullZone
CDN-Uid
CDN-RequestCountryCode
Fastcgi-Useragent
X-Hl-Ver
X-XRDS-LOCATION
X-Tumblr-Pixel-3
X-Optimistic-Header
X-SRV
X-Origin-Date
X-Time
X-Varnish-Ttl
Source
X-Oneagent-Js-Injection
X-Uri
X-Request-Time
X-Redis-Cache
CF-Cached-On
Countrycode
X-Cache-Debug
X-Varnish-Hits
X-App-Version
X-Director
X-Mg-Request-UUID
X-Generated-By
X-GEO
Upgrade-Insecure-Requests
X-TNCMS
Xet-Cookie
X-Loop
X-ARC
X-Akamai-Transformed
X-CACHE-AGE
X-Tx-Id
X-Pass-Why
Cache-Tv-Group
Frame-Options
X-URL
X-FireWall-Port
X-Presslabs-Stats
X-Origin-CC
X-Origin-TTL
Xserver
X-NWS-UUID-VERIFY
X-Varnish-Cache-Hits
X-Service
X-Storefront-Renderer-Rendered
X-ShardId
X-Shopify-Stage
X-Alternate-Cache-Key
X-Sorting-Hat-PodId
X-Varnish-Beresp-Ttl
X-Varnish-Hostname
X-Sorting-Hat-ShopId
X-ShopId
X-Newrelic-Synthetics
X-RM-Cache-TTL
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
X-Datadog-Sampled
X-Storage
X-Datadog-Trace-Id
X-ServerID
X-Tid
X-B3-Spanid
X-TA-CDN-Provider
X-Endurance-Cache-Level
X-A-Dgt
X-A-Dam
X-A-Dcw
X-A-Wwc
WWW-Authenticate
X-A-Ccd
Thinkindot-CacheControl-Type
Thinkindot-Control
X-A
Gannett-Cam-Experience-Id
MD5-Digest
Lang
X-Aed
Release
Redirect-Candidate
Origin
Memcached
Meta-Geo-Continent
Ngx.Var.Host
Odigeo-Trace-Id
Rendered-Blocks
Req-Svc-Chain
Thinkindot-CacheControl
DCR-Decision-By
Candidate-Md5Url
Cache-Host
TDXMobile
DCR-Processing-Time-Ms
Host-ID
Surrogated-Key
Edge-Cache
T-Server
BehaviorPad-Version
X-Generated-On
X-Rojux
X-Rocket-Build-Number
X-S
X-S-Cookie
X-S-Maxage
X-Processor
X-Platform-Router
X-Nyt-Route
X-Origin-Time
X-Platform-Cluster
X-Platform-Processor
X-ScT
X-Served-From
X-Vdms-Version
X-Vdms-Path
X-VG-TLSProxy
X-We-Are-Hiring
Xc-Version
X-TIM-N
X-Thinkindot-L3
X-Sigma
X-Sigma-Backend
X-SRCache-Key
X-Test
X-Mobile-URL
X-Mid
X-Conf
X-CMSURLCustom
X-Core-Value
X-D
X-Destination
X-Cache-NE
X-Cache-Info
X-B-Cookie
X-BBC-Edge-Cache-Status
X-Bc-Bl
X-BCube-Filmed-By
X-Developer
X-Ec-Fail
X-INCAP-ABP
X-Httpd
X-Level-Front-Cache
X-Loc
X-Location
A
X-Gdpr
X-Ec-GeoHdr
X-Epic-Correlation-Id
X-External-Request-Id
X-Frame-Option
X-Application
Sslversion
Environment
X-Request-Host
X-Pubstack
X-CUA
X-DefElseHash
X-Core-Mission
X-Cdn-Srv
X-Clara-WADP
X-DefHash
X-Ec-Custom-Error
X-GeoIP
X-GeoIP-City
X-Geo-Header
X-Fmm-Version
X-Cdn-Origin
X-Fetched-On
X-Developers
X-Bip
State
Tube-Get-Contents
Ssr
Server-Info
NM-Fastcgi-Cache
Server-Host
Tube-Got-Eval
Tube-Got-Results
X-Auto-Login
X-Has-Esi
X-Akamai-Device-Characteristics
We-Hiring
Tube-Return
Vix-Hermes-Req-Id
X-Cache-Bucket
X-Human
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-Varnish-Beresp-Status
X-Thanos
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-Varnish-Remaining-TTL
X-Vmg-Version
X-WP-CF-Super-Cache-Active
X-Cache-Date
X-Worker
X-WADP-Cache
X-VServer
X-WA-Info
X-DC
X-Sn-Servicetimems
X-Old-Content-Length
X-Org
X-NodeID
X-JWT-State
NGX
X-Is-Gdpr
X-Origin-Response-Time
X-Platform-Server
X-SB
X-SD-PageType
X-Restarts
X-Req
X-Pool
X-HS-Content-Campaign-Id
X-Hash
Apple-News-Services-Handled
CloudFront-Viewer-Country
Cluster
Gh-Request-Id
Magicmarker
Apple-News-Services-Request-Url
Country-Code
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
CacheControlHeader
Click-Count-Action-Start
C-Via
DSUID
Decoy-Debug-Key
Decoy-Debug-Status
Decoy-Debug-TTL
AKAMAI
Fastly-Backend-Name
Cache-Key
Click-Count-Error
Fastly-GeoIP-CountryCode
Mail-Subject
X-Parent-Response-Time
Section-Io-Id
Section-Origin-Responded
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
X-Date
X-Nginx-Cache-Key
X-FC-Vary-Parameters
X-Origin
X-Azure-Ref-OriginShield
X-App
Cmsid
X-Ad-Defer-Variation
X-Node-Id
X-Accel-Expires-Debug
X-Op-Id-All
X-Accel-Buffering
X-LB-NoCache
X-CacheTTL
X-HN
X-Cache-Tags
X-Gzip
X-GeoIP-Region-Code
X-Gen-Mode
X-GeoIP-Country-Code
X-Ckpd-Fst-Backend
X-Hnp-Log
Datacenter
X-Block-Status
X-Men
X-Minions-Version
X-Cache-Backend
X-Esi-Check
X-Irp-Debug
X-Cache-Id
Cmstype
X-NCache
X-Qloud-Router
X-Variation
Server-Hostname
Server-Ext
Producers
Sever-Int
X-Var-Ttl
Cache-Provider
X-DPWN-IS-SECURE
Machine
X-VarnishDD-TTL
Platform
On-Server
Adler-Geo
X-Wix-Viewer-Type
X-Mvc-Supplant-Cachable
Origin-CC
Origin-EX
Pics-Label
PFcat
X-Varnishpool
Wxu-Next-Region
X-Slack-Shared-Secret-Outcome
X-Gamma-Serve
User-Cache-Control
X-Fastly-Backend
Kp-EeAlive
Is-Eu
Web-Mar-Region
Wxu-Next-Hostname
Wxu-Next-Commit
X-Platform
L
X-Device-Os
X-Dispatcher-Number
X-Slack-Backend
X-Dispatcher-Server
X-Scale
Canary
X-Region-Sid
CDCHOST
X-Request-Start
X-Csrf-Jwt
X-Forwarded-Site
X-Eu-Site
X-Planisys-CDN-TTL
L5d-Success-Class
X-Refresh
X-Server-IP
Load-Balancing
X-Mly-Id
X-V-Cache
Fastly-SSL
X-Planisys-CDN-Rules
Ha-Gx-Prefs
X-CGP
X-Nananana
HA-Ipaddr
X-Planisys-CDN-Cache
X-Owner
X-Webkit-CSP-Report-Only
SID
X-Microcachable
X-Cache-FS-Status
Svr
X-Api-Version
X-Mvc-Supplant-OutputCached
X-Cache-Remote
X-Up
X-CSRF-Token
X-Tb-Optimization-Total-Bytes-Saved
X-Fastly-Cache
Env
X-AIR-PT
X-Aicache-OS
GeoIP-Latitude
X-Servedbyhost
X-NewRelic-App-Data
X-ND-Cache
X-RCS-CacheZone
X-Instance-Name
X-Origin-Expires
X-NGINX-Cache
HostName
X-Trace-ID
X-Via-Popv
X-Nc
X-Via-Popn
X-Via-Poph
Time
X-Cached-By
X-Release
Memory
X-Response-By
X-Zone
Cdn
Locid
Srvid
X-FL-QIT-DEBUG
X-VC
X-DataCenter
X-Wa
X-FL-EDGE
X-From
Expect-Staple
X-HA-Backend
X-Generated-In
X-HS-Status
X-Vc
Cache
X-ZONE
X-Webkit-CSP
Cdnsip
X-AK-Request-ID
X-Via-CDN
X-Cache-Enabled
X-Provided-By
Cdncip
X-Edge-Pop
Server-ID
X-Air-Pt
NtCoent-Length
X-Gateway-Skip-Cache
X-Esi
X-Gateway-Request-Id
X-Gateway-Cache-Status
X-Via-SSL
X-Via-Edge
Edge-Copy-Time
X-Gateway-Cache-Key
Hostname
X-Via-NSCOPI
X-Check-Cacheable
X-Dc
X-Correlation-ID
X-API-Version
X-CCDN-CacheTTL
GeoIp-Country-Code
X-Hcs-Proxy-Type
X-Client-Ip
X-Vcl-Version
X-CCDN-Origin-Time
X-Fpc
X-CSRF-TOKEN
X-Debug-Cache-Store
X-Lambda-Id
X-LB-ID
X-Debug-Cache-Fetch
X-Vgn-Hpd-Ssi
X-Vgn-Hpd-Cached
X-Vgn-Hpd-Variations-Key
Sid
X-Srv
X-CS
AMP-Access-Control-Allow-Source-Origin
Eomportal-Instance
True-Client-IP
XkeyRZ
X-Proxy-CacheRZ
Ngx-Var-Key
X-Vtex-Remote-Cache
CPC-Cache
X-Via-JSL
X-Render-Time
VNS-Age
CPC-Age
VNS-Cache
X-Micro-Cache
X-MCACHE
X-Amz-Meta-Cb-Modifiedtime
X-Cs
X-APP-VERSION
X-Nf-Request-Id
X-VCT
IsBot
OT-Force-Account-Verify
X-TH-Server
Fastly-Drupal-Html
X-Request-URI
X-SIPLIST1
X-B3-SpanId
X-EC-Lua
X-VCL-Version
True-Client-Ip
Uri
Path
X-Fastly-Country-Code
X-ATG-Version
X-Cache-NGX
X-Info
Srv
X-MSEdge-Flight
X-Upstream-Ct
X-Cache-ASPX
X-Contensis-Viewer-Groups
X-MSEdge-Features
X-Upstream-Ht
X-Varnish-Authentication
Esi-Enabled
Request-ID
X-Cache-Type
M-TraceId
Resin-Trace
Location
X-Varnish-Beresp-TTL
GeoIP-Country-Code
X-CF-Lambda-Version
X-FPC
X-Lb-Id
CDN
XServer
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-Cdn-Request-ID
X-CF-Lambda-Fn
X-CLOUD-TRACE-CONTEXT
X-PAYTM-SRV-ID
YJS-ID
X-Oss-Storage-Class
Cross-Origin-Opener-Policy-Report-Only
X-Accel-Version
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
Servername
X-Cache-Expires
X-Oss-Server-Time
X-Oss-Request-Id
X-Udemy-Cache-App-Namespace
X-TX-ID
X-Service-Response-Time
Sm-Log-Id
RNT-Machine
N-Cache
RNT-Time
X-CDN-Cache-Status
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-Edge-POP
X-Pod-Name
X-Akamai-Pragma-Client-IP
Timeexpire
Server-Id
X-Tenant
LB
X-Datadome
X-MP-GENERATED-AT
X-Bl-Debug
X-RateLimit-Reset
X-Datacenter
X-Orig-Expires
X-Forwarded-Path
X-Shop-Environment
X-Moov-Xdn-Version
X-Moov-T
X-SERVER-NAME
X-Cdn-Cache-Status
HIT
X-Scheme
X-Ha-Backend
X-B3-Trace-ID
Traceparent
X-WA
X-Geo
X-Srcache-Fetch-Status
X-ApacheServer
X-Srcache-Store-Status
X-App-Name
CountryCode
X-Policy
X-Via-PopH
Ohc-File-Size
X-Via-PopV
X-NC
X-Via-PopN
X-PERF
X-Viewer-Country
FSS-Cache
X-CACHE-KEY
X-TraceId
Proxy-Connection
Yjs-Id
X-LiteSpeed-Cache-Control
Epwk-X-Cache
X-ServedByHost
ENV
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-NAPM-TraceId
Hit
X-Snapshot-Date
Powered-By
Lb
X-Dw-Trace-Id
X-Hyper-Cache
X-Cdn-Forward
Geoip-Latitude
X-Serial
WZWS-RAY
X-Amz-Meta-Opti
X-M-Log
X-M-Reqid
X-MiniProfiler-Ids
X-Acquia-Site
X-Acquia-Application-UUID
X-RAMCache
X-Acquia-Purge-Tags
Content-Script-Type
Content-Style-Type
X-Acquia-Application-Trace
X-Qnm-Cache
User-Agent
X-Fastly-Backend-Reqs
Ec-Rule-Version
X-B3-Parentspanid
X-UP
X-Vgn-Hpd-Reason
X-Lb-Nocache
X-Swift-Error
Cneonction
X-Wp-Cf-Super-Cache
X-Wp-Cf-Super-Cache-Cache-Control
X-TT-LOGID
X-Lsadc-Cache
X-F-Status
Tracecode
True-Client-Country-4JS
X-Ctl-Mach
Rip
Req-ID
X-Webstats-RespID
V-Age
Pramga
X-Fastly-Cache-Hits
X-Cdn-Diag
X-Mid-Debug-Cache-Key
Warning
X-IPS-Cached-Response
MIME-Version
My-App
Ngx
X-LiteSpeed-Tag
X-B3-ParentSpanId
X-Cache-Ngx
X-Mid-Debug-Cache-Disk
X-Stale
X-Th-Server
X-Request-URL
Inserted-Into-Cache-At
X-Clientip