Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Accept-Ranges
Expect-CT
X-XSS-Protection
Pragma
X-Powered-By
CF-RAY
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Xss-Protection
X-Served-By
X-Download-Options
CF-Ray
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
Access-Control-Allow-Credentials
X-FRAME-OPTIONS
X-Request-Id
X-Request-ID
X-Permitted-Cross-Domain-Policies
X-AspNet-Version
Alt-Svc
X-Runtime
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Generator
X-Cache-Status
X-Cacheable
Timing-Allow-Origin
X-Iinfo
X-Envoy-Upstream-Service-Time
X-Content-Security-Policy
X-Drupal-Dynamic-Cache
Feature-Policy
Content-Encoding
Access-Control-Expose-Headers
Upgrade
Status
X-CDN
X-AspNetMvc-Version
P3p
Access-Control-Max-Age
X-Via
Server-Timing
X-UA-Device
Request-Context
X-Robots-Tag
X-Turbo-Charged-By
X-Amz-Request-Id
X-Cache-Group
EagleId
X-Amz-Id-2
X-Backend
X-AH-Environment
X-Proxy-Cache
Keep-Alive
X-Ua-Compatible
X-Server
X-Ws-Request-Id
X-Age
Host-Header
Cf-Edge-Cache
X-Hacker
X-Vhost
X-Server-Powered-By
X-Rq
X-Dns-Prefetch-Control
X-Varnish-Cache
X-Dispatcher
X-Amz-Version-Id
Grace
Allow
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-OneAgent-JS-Injection
X-LiteSpeed-Cache
X-WebKit-CSP
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Page-Speed
X-Device
Cf-Apo-Via
Accept-CH
Cf-Railgun
X-Aws-Lambda-Call-Status
X-Node
X-Pingback
X-Host
EagleEye-TraceId
X-Nginx-Cache-Status
X-Ruxit-JS-Agent
X-Server-Id
Surrogate-Control
X-Akam-SW-Version
X-Cache-Spec
X-Backend-Server
Request-Id
X-Readtime
X-Cache-Lookup
X-HW
Accept-Ch-Lifetime
X-Content-Security-Policy-Report-Only
X-Cloud-Trace-Context
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Trace
X-Application-Context
Fastly-Restarts
X-Response-Time
X-Nginx-Upstream-Cache-Status
Permissions-Policy
X-Mod-Pagespeed
X-Edge
X-WebKit-CSP-Report-Only
X-Litespeed-Cache
X-Mcache
Content-Location
X-Content-Type
X-MS-InvokeApp
X-Url
X-CST
X-Country
Accept-CH-Lifetime
X-Clacks-Overhead
Rating
X-Midtier
X-Amz-Server-Side-Encryption
X-PC
X-Vname
X-TtlSet
RTSS
Cache-Tag
X-ESI
X-Vcap-Request-Id
X-D2id
X-VARITI-CCR
Origin-Trial
Verso
X-Element-Page-Cache
X-Server-Name
X-ECACHE
X-Kinja
X-GoogleNews-Bot
X-Kinja-Build
X-Kinja-Server
X-Use-Magma
X-Exp-Variant
X-Kinja-Revision
X-Cdn-Fetch
X-Exp-Id
X-Rack-Cache
X-Ac
X-Ttl
X-Powered-By-Plesk
X-Cnection
Service-Worker-Allowed
X-SharePointHealthScore
SPRequestGuid
X-Amz-Rid
X-Navigation-Version
Xkey
X-Client-IP
X-GitHub-Request-Id
X-Abt-Application-Version
Edge-Control
X-Cache-TTL
X-NWS-LOG-UUID
SPRequestDuration
SPIisLatency
X-B3-TraceId
X-Upstream
Arr-Disable-Session-Affinity
X-Kraken-Loop-Name
X-Instrumentation
X-Erf-Bev-Bev-Is-Generated
X-Browser-Type
X-Erf-Bev-Bev
X-Server-Lifecycle-Phase
X-Cached
X-Mg-S
X-Dw-Request-Base-Id
X-Px
X-Varnish-TTL
X-Cache-Key
X-Correlation-Id
X-Sol
Pagespeed
X-Middleton-Display
Display
X-SRCache-Store-Status
X-SRCache-Fetch-Status
Access-Control-Request-Method
Edge-Cache-Tag
Content-MD5
X-Forwarded-For
X-Country-Code
X-Goog-Hash
X-Webkit-Csp
X-NF-Request-ID
X-FastCGI-Cache
Front-End-Https
X-Powered-CMS
TCN
X-Version
AR-SID
AR-CACHE
AR-Request-ID
Public-Key-Pins
AR-ATIME
AR-PoweredBy
X-XRDS-Location
Accept-Ch
X-RateLimit-Remaining
X-HP-Webp
X-Jurisdiction
X-HP-Trace-Id
X-Id
X-Content-Digest
X-MSEdge-Ref
X-Recruiting
X-T
X-Ser
X-Amzn-Trace-Id
X-Daa-Tunnel
X-Accel-Expires
Response
X-Middleton-Response
TP-Cache
TP-L2-Cache
X-Shield-Request-Id
X-Ratelimit-Limit
S
MicrosoftSharePointTeamServices
Nginx-Cache
X-Fastcgi-Cache
Cache-Status
Mrf-Cache-Status
MRF-Tech
X-B3-TraceId-Primal
X-HS-Content-Id
X-HS-Combine-CSS
X-HS-Hub-Id
X-HS-Cache-Config
Server-Node
X-Request-Received
X-Request-Processing-Time
Cache-Tags
X-Distributor
X-Hits
X-Edge-Location-Klb
X-Kinsta-Cache
X-LB-Cache
X-Ratelimit-Remaining
Fastcgi-Cache
Cross-Origin-Opener-Policy
X-Origin-Server
X-Ua-Browser
Alternate-Protocol
X-Ezoic-Cdn
Server-Name
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
X-Grace
X-DataDome
X-Geo-Country
X-DIS-Request-ID
X-Ratelimit-Reset
X-PressLabs-Stats
Filterid
X-Microsite
X-Request-Handler-Origin-Region
X-Rid
X-Protected-By
X-Server-ID
Healthy
X-LLID
X-Hostname
X-Frontend
X-Logged-In
X-Debug-Info
X-Git-Hash
Payment
Cleartype
X-Varnish-Backend
X-FB-Debug
X-Www-Served-By
X-Page-Id
X-Forwarded-Proto
X-Load-Cache
X-NGENIX-Cache
X-Origin-Cache
X-ASPNET-VERSION
X-Cluster-Name
DC
MS-Author-Via
X-Fastly-Request-ID
X-ORACLE-DMS-RID
Charset
X-ORACLE-DMS-ECID
Content-Disposition
Realpath
X-B3-Sampled
Access-Control-Allow-Method
X-Goog-Metageneration
X-GUploader-UploadID
X-Upgrade-Enabled
X-Proxy
X-F-Cache
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Az
X-AppVersion
X-Activity-Id
X-B3-Traceid
X-ECache
X-Seen-By
Retry-After
X-Amz-Replication-Status
X-TTL
Cross-Origin-Resource-Policy
Paypal-Debug-Id
X-Contextid
X-Amz-Meta-S3cmd-Attrs
X-Route-Name
X-Type
X-Fb-Rlafr
X-Whom
X-Hosted-By
X-Revision
X-Azure-Ref
X-Request-Guid
Viewport
Count-Hit
X-Flags
X-Aspnet-Duration-Ms
X-Providence-Cookie
X-Is-Crawler
X-Signature
Accept-Charset
X-App-Environment
X-B-Cache
Surrogate-Key
X-Wix-Request-Id
X-Aspnetmvc-Version
X-Varnish-Server
X-VCache
X-B
X-TT
Amp-Access-Control-Allow-Source-Origin
X-Akamai-Edgescape
X-Fastly-Request-Id
X-Oracle-Dms-Ecid
X-Oracle-Dms-Rid
X-Cache-Age
X-DynaTrace
X-Language
X-Source
X-Cache-Control
X-App-Server
Referer-Policy
X-Mobile
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-Goog-Generation
X-Magnolia-Registration
X-Times
Host
X-Varnish-Grace
X-RateLimit-Limit
Version
X-Envoy-Decorator-Operation
X-Varnish-Ttl
X-N
X-HTML-Minification-Powered-By
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Cache-Rule
X-Oneagent-Js-Injection
X-Tumblr-Pixel
X-Original-Request-Id
X-Tumblr-Pixel-0
X-Response-Served-From
X-Tumblr-Pixel-1
X-Tumblr-User
Refresh
Access-Control-Request-Headers
MS-CV
Ms-Operation-Id
X-UUID
Section-Io-Cache
WPO-Cache-Status
SRV
X-Rule
X-RTag
WPO-Cache-Message
X-Framework
SD-X-WS
X-Varnish-Age
X-Cache-Time
X-Cache-Status-Check
X-Cache-Expired-At
Akamai-GRN
X-FW-Static
X-ProcessESI
X-Page-View
X-RemovedCookies
X-Cache-Grace
X-User-Agent
X-FW-Version
X-FW-Type
X-FW-Dynamic
X-Content-Powered-By
X-FW-Hash
X-FW-Serve
X-FW-Server
X-Cacheable-TTL
GEO-INFO
X-EdgeConnect-Cache-Status
X-Device-Type
X-Drupal-Cache-Contexts
X-Backend-Name
VIX-Pulpo-Upstream-Status
X-G
X-Is-Bot
X-Status
X-Jobs
X-Servername
Url
X-Rendered-As
VIX-Pulpo-Node
X-Drupal-Cache-Tags
X-Adobe-Loc
X-Akamai-Request-ID2
X-Instance
X-Http-Reason
CDN-RequestId
X-Adobe-Content
X-Environment-Context
From-Origin
Protected
X-L-Path
X-Trace-Id
X-Template
X-Amz-Apigw-Id
X-Amzn-RequestId
NGB
X-NYM-Debug-Backend
X-Ruxit-Js-Agent
X-Region
Front
X-COUNTRY
X-CDN-Forward
X-Nginx-Cache
X-Debug-IsPreview
X-Debug-IsConnected
Accept-Language
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Unique-Id
X-Cache-Hit
X-Content-Options
Fastly-SWR
Fastly-SIE
Backend
Country
X-Zen-Fury
X-Air-Source
X-Air-Trace-Id
Liferay-Portal
X-Air-Hostname
X-Tb
X-DynaTrace-JS-Agent
X-XRDS-LOCATION
X-Pinterest-Rid
X-Mode
Pinterest-Version
Pinterest-Generated-By
X-Newrelic-App-Data
X-Cache-Operation
Content-Secure-Policy
X-Tt-Logid
X-Node-Name
X-Real-IP
X-Rewrite-Enabled
Filters
Webserver
X-UPSTREAM-Address
X-Amzn-Remapped-Content-Length
X-RN-RSRV
X-Tumblr-Pixel-2
Meta-Geo
X-Proxy-Cache-Info
X-Cache-Server
Uber-Trace-Id
X-IPS-LoggedIn
Selected-Fe
X-Ms-Request-Id
X-Ms-Version
X-Web-Node
X-PHP-Backend
X-Content-Age
X-Time
Cache-Hits
X-Generation-Time
X-Section
X-Format
X-Proxy-Build
X-Timing-Wait
X-Access
ServedBy
Azure-SiteName
Azure-SlotName
Node
X-Cluster-Node
Azure-InstanceId
CF-IPCountry
Cache-Name
Azure-Version
Azure-RegionName
X-Proto
X-SayCDN-TTL
X-Soup
X-UA-Device-Type
Onion-Location
X-Reqid
X-Server-W
X-Locale
X-R9-Blue-Green-Version
X-Sql-Count
X-VC-Cache
X-Sql-Duration-Ms
X-Say-Cacheable
X-Rocket-Nginx-Serving-Static
X-TIME
X-Say-TTL
X-Sucuri-ID
X-Sucuri-Cache
X-Site-Version
X-Skip-Cache
Property-Id
Web-Mar-Node
X-Forwarded-Host
TWC-Device-Class
X-Varnish-Beresp-Grace
TWC-Privacy
TWC-Locale-Group
Webcakes-App-Name
TWC-Connection-Speed
TWC-GeoIP-Country
TWC-GeoIP-LatLong
S-Rt
X-ProxyCache-Key
X-Debug
X-Cms-Context
X-Via-Fastly
X-Proxy-Cache-Status
X-Handled-By
X-Labrador-Cache-Channel
X-Origin-Hint
X-PHP-Host
X-Cluster
X-ProxyCache-Status
X-LJ-Flow-ID
X-Adobe-Source
Webcakes-Region
X-AWS-Id
X-BYPASS-REASON
X-VWS-Id
X-Cache-Host
X-Cache-Action
Webcakes-App-Version
X-Cache-TTL-Remaining
DB-Nickname
X-Detected-As
X-FB-TRIP-ID
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
X-Routing-Service
X-SaId
X-Extlb
X-Uri
X-IPLB-Request-ID
Cross-Origin-Window-Policy
X-No-Session
X-Edge-Location
X-Proxied
X-LAGOON
X-Origin-Date
X-JoinUs
X-IPLB-Instance
X-Zipkin-Id
X-Tumblr-Pixel-3
Mn-Server-Ip
Apigw-Requestid
X-Urbn-Site-Id
X-App-Version
X-Xfnlog-Site
Locale
X-Optimistic-Header
X-Buckets
X-Urbn-Context-Path
WP-Super-Cache
Countrycode
Fastcgi-Useragent
ServerID
X-Ua
Mime-Version
X-GeoCode
X-GeoCountry
X-Tec-Api-Version
X-Tec-Api-Origin
X-LSADC-Cache
X-Tec-Api-Root
Source
CDN-Uid
CDN-PullZone
CDN-CachedAt
CDN-Cache
CDN-EdgeStorageId
CDN-RequestCountryCode
X-Director
Cache-Tv-Group
X-ARC
X-Hl-Ver
Fastly-Drupal-HTML
Upgrade-Insecure-Requests
X-Varnish-Hits
X-Request-Time
X-GEO
X-Generated-By
X-Mg-Request-UUID
X-Tx-Id
CF-Cached-On
X-Cache-Debug
X-Redis-Cache
X-Loop
Frame-Options
Xet-Cookie
X-Origin-TTL
X-Origin-CC
X-SRV
X-URL
X-FireWall-Port
X-Varnish-Cache-Hits
X-TNCMS
X-Pass-Why
X-RM-Cache-TTL
X-Varnish-Hostname
X-TA-CDN-Provider
X-ShopId
X-Storefront-Renderer-Rendered
X-ShardId
X-Sorting-Hat-ShopId
X-Akamai-Transformed
X-Sorting-Hat-PodId
X-Shopify-Stage
X-ServerID
X-Alternate-Cache-Key
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
X-Datadog-Sampled
X-Service
Load-Balancing
X-Newrelic-Synthetics
X-Api-Version
Xserver
X-Request-Host
X-Served-From
X-Endurance-Cache-Level
X-Pubstack
X-B3-Spanid
X-NWS-UUID-VERIFY
Surrogated-Key
Gannett-Cam-Experience-Id
Sslversion
A
Lang
TDXMobile
Thinkindot-CacheControl-Type
Thinkindot-Control
Server-Info
Thinkindot-CacheControl
T-Server
Req-Svc-Chain
Host-ID
BehaviorPad-Version
Ngx.Var.Host
DSUID
Meta-Geo-Continent
Odigeo-Trace-Id
Origin
WWW-Authenticate
Release
Memcached
Edge-Cache
Cache-Host
Redirect-Candidate
Candidate-Md5Url
MD5-Digest
DCR-Processing-Time-Ms
DCR-Decision-By
Rendered-Blocks
X-Ec-Fail
X-Rocket-Build-Number
X-Processor
X-Rojux
X-S
X-S-Cookie
X-Platform-Router
X-Platform-Processor
X-Location
X-Loc
X-Mid
X-Mobile-URL
X-Platform-Cluster
X-S-Maxage
X-ScT
X-Vdms-Path
X-TIM-N
X-Vdms-Version
X-We-Are-Hiring
Xc-Version
X-Thinkindot-L3
X-Thanos
X-Sigma
X-Sigma-Backend
X-SRCache-Key
X-Test
X-Level-Front-Cache
X-INCAP-ABP
X-BBC-Edge-Cache-Status
X-B-Cookie
X-Bc-Bl
X-Bip
X-Cache-Date
X-Application
X-Aed
X-A-Dam
X-A-Ccd
X-A-Dcw
X-A-Dgt
X-A-Wwc
X-Cache-Info
X-Cache-NE
X-Epic-Correlation-Id
X-Ec-GeoHdr
X-External-Request-Id
X-Generated-On
X-Httpd
X-Developer
X-Destination
X-CMSURLCustom
X-Conf
X-CUA
X-D
X-A
X-BCube-Filmed-By
X-Varnish-Beresp-Ttl
Section-Io-Id
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
Section-Origin-Responded
X-Geo-Header
X-Gdpr
X-Frame-Option
X-Fmm-Version
X-GeoIP
X-HS-Content-Campaign-Id
X-Is-Gdpr
X-Human
X-Fetched-On
X-Has-Esi
X-GeoIP-City
X-Core-Value
Server-Host
We-Hiring
NM-Fastcgi-Cache
Mail-Subject
Magicmarker
X-Akamai-Device-Characteristics
X-Cache-Bucket
X-Developers
X-JWT-State
X-Clara-WADP
X-Cdn-Srv
X-Ec-Custom-Error
X-Mly-Id
X-Worker
X-WP-CF-Super-Cache-Active
X-WADP-Cache
X-WA-Info
X-VServer
Country-Code
X-Cdn-Origin
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-Sn-Servicetimems
X-Hash
X-Core-Mission
X-Vmg-Version
X-VG-TLSProxy
X-Origin-Response-Time
X-Origin-Time
X-Org
X-Nyt-Route
X-Node-Id
X-Pool
X-Restarts
X-Varnish-Beresp-Status
X-Varnishpool
X-Var-Ttl
X-Storage
X-SD-PageType
X-Mvc-Supplant-Cachable
X-Origin
Apple-News-Services-Request-Url
Apple-News-Services-Handled
Fastly-GeoIP-CountryCode
Fastly-Backend-Name
CloudFront-Viewer-Country
AKAMAI
Cache-Key
CacheControlHeader
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
C-Via
X-Parent-Response-Time
X-CACHE-AGE
X-Request-Start
X-Cache-Tags
X-SB
X-Scale
Datacenter
X-DefHash
X-Qloud-Router
Wxu-Next-Hostname
X-Cache-Id
X-DefElseHash
X-Req
X-Variation
X-Auto-Login
X-Wix-Viewer-Type
X-Accel-Buffering
X-App
X-VarnishDD-TTL
X-Azure-Ref-OriginShield
X-Device-Os
X-Ad-Defer-Variation
Wxu-Next-Region
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
X-Block-Status
X-Esi-Check
Cache-Provider
X-Op-Id-All
X-Hnp-Log
X-HN
X-Gzip
X-Old-Content-Length
X-Irp-Debug
X-NCache
X-Nginx-Cache-Key
X-LB-NoCache
X-NodeID
X-GeoIP-Region-Code
X-GeoIP-Country-Code
X-FC-Vary-Parameters
Click-Count-Error
Wxu-Next-Commit
X-Platform
X-Platform-Server
Click-Count-Action-Start
X-Forwarded-Site
Canary
CDCHOST
Adler-Geo
X-Gen-Mode
X-Dispatcher-Server
X-CSRF-Token
X-Gamma-Serve
Is-Eu
X-Men
Platform
X-Fastly-Cache
PFcat
X-Date
X-Dispatcher-Number
X-Region-Sid
X-Server-IP
State
X-Slack-Shared-Secret-Outcome
Server-Hostname
Sever-Int
X-Slack-Backend
Kp-EeAlive
L
Server-Ext
X-CacheTTL
X-Fastly-Backend
On-Server
Origin-CC
User-Cache-Control
Gh-Request-Id
Vix-Hermes-Req-Id
X-Accel-Expires-Debug
Origin-EX
Machine
Tube-Got-Eval
Tube-Get-Contents
Web-Mar-Region
Environment
NGX
Tube-Got-Results
Tube-Return
X-Presslabs-Stats
X-Instance-Name
Cluster
X-Owner
X-Origin-Expires
X-Eu-Site
X-Planisys-CDN-TTL
L5d-Success-Class
Pics-Label
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
Producers
X-DPWN-IS-SECURE
X-Ckpd-Fst-Backend
X-Tid
Ha-Gx-Prefs
X-Refresh
X-Cache-Backend
Decoy-Debug-Key
Decoy-Debug-Status
X-Nananana
Decoy-Debug-TTL
Cmstype
Cmsid
X-Minions-Version
HA-Ipaddr
X-V-Cache
X-CGP
X-Cache-Remote
Fastly-SSL
Ssr
X-Csrf-Jwt
X-Webkit-CSP-Report-Only
X-Mvc-Supplant-OutputCached
X-Response-By
X-DC
X-Cache-FS-Status
X-Release
X-Tb-Optimization-Total-Bytes-Saved
X-Microcachable
X-Provided-By
X-Zone
X-FL-QIT-DEBUG
Locid
Srvid
X-FL-EDGE
X-Aicache-OS
Expect-Staple
GeoIP-Latitude
Env
HostName
X-Via-CDN
X-Air-Pt
X-RCS-CacheZone
X-ND-Cache
X-From
X-Up
Time
X-Servedbyhost
Memory
Edge-Copy-Time
X-VC
X-Trace-ID
X-Via-Edge
X-Via-SSL
X-Cache-Enabled
X-NewRelic-App-Data
X-Generated-In
SID
Svr
X-AIR-PT
NtCoent-Length
X-Dc
X-HS-Status
X-Cached-By
X-Nc
X-Srv
Cache
X-Vcl-Version
X-Webkit-CSP
X-DataCenter
X-Debug-Cache-Store
X-Lambda-Id
X-Edge-Pop
X-Debug-Cache-Fetch
X-Via-Popn
X-Via-Poph
X-Via-Popv
X-Wa
Cdn
Sid
X-Cs
X-HA-Backend
X-Vc
X-Esi
X-Nf-Request-Id
X-ZONE
X-Correlation-ID
X-Vgn-Hpd-Cached
VNS-Age
VNS-Cache
X-Vtex-Remote-Cache
X-CCDN-CacheTTL
X-CCDN-Origin-Time
X-Hcs-Proxy-Type
X-Vgn-Hpd-Variations-Key
X-Render-Time
CPC-Cache
Server-ID
CPC-Age
X-Client-Ip
X-Vgn-Hpd-Ssi
X-Check-Cacheable
X-NGINX-Cache
X-VCT
X-LB-ID
X-AK-Request-ID
Cdncip
Fastly-Drupal-Html
GeoIp-Country-Code
Hostname
Cdnsip
X-Amz-Meta-Cb-Modifiedtime
X-Via-NSCOPI
X-Fpc
X-TH-Server
X-Gateway-Cache-Status
AMP-Access-Control-Allow-Source-Origin
X-Gateway-Cache-Key
X-Gateway-Skip-Cache
X-Gateway-Request-Id
X-Upstream-Ht
X-Upstream-Ct
X-Via-JSL
XkeyRZ
X-Proxy-CacheRZ
X-Cache-Type
X-API-Version
True-Client-IP
X-ATG-Version
X-CSRF-TOKEN
X-B3-SpanId
Uri
X-Cache-ASPX
X-Contensis-Viewer-Groups
X-Varnish-Authentication
X-EC-Lua
X-CS
M-TraceId
Eomportal-Instance
Esi-Enabled
True-Client-Ip
X-Varnish-Beresp-TTL
X-CF-Lambda-Version
X-RateLimit-Remaining-Second
Resin-Trace
X-PAYTM-SRV-ID
X-RateLimit-Limit-Second
XServer
X-MSEdge-Flight
OT-Force-Account-Verify
X-MSEdge-Features
Ngx-Var-Key
X-CF-Lambda-Fn
X-Micro-Cache
Srv
X-Udemy-Cache-App-Namespace
Path
X-FPC
X-MP-GENERATED-AT
X-VCL-Version
Request-ID
YJS-ID
X-Cache-NGX
N-Cache
GeoIP-Country-Code
X-Fastly-Country-Code
X-Wikidot-Backend
X-Request-URI
X-APP-VERSION
CDN
X-Wikidot-Static-Cache
IsBot
X-SIPLIST1
X-RateLimit-Reset
X-Lb-Id
X-CDN-Cache-Status
X-Tenant
X-CLOUD-TRACE-CONTEXT
X-Bl-Debug
X-Forwarded-Path
RNT-Time
X-Orig-Expires
X-Info
RNT-Machine
X-Shop-Environment
X-Datadome
X-Accel-Version
Sm-Log-Id
LB
X-Service-Response-Time
Server-Id
X-TX-ID
X-B3-Trace-ID
Location
X-Ha-Backend
X-Policy
X-App-Name
X-Pod-Name
X-MCACHE
X-Cdn-Cache-Status
Lb
X-WA
HIT
X-Edge-POP
Cross-Origin-Opener-Policy-Report-Only
X-Datacenter
X-Akamai-Pragma-Client-IP
X-Snapshot-Date
X-Via-PopV
X-Oss-Storage-Class
X-Github-Request-Id
X-Oss-Server-Time
X-Oss-Request-Id
Ohc-File-Size
X-Via-PopN
X-SERVER-NAME
Servername
X-Cache-Expires
X-Cdn-Request-ID
X-Via-PopH
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
X-Geo
FSS-Cache
Timeexpire
X-NC
X-Cache-Ttl
Hit
X-CACHE-KEY
X-Srcache-Fetch-Status
X-Srcache-Store-Status
X-ID
X-Ctl-Mach
Proxy-Connection
X-Logging-Id
Pramga
Epwk-X-Cache
Req-ID
X-Cdn-Diag
X-Vcache
X-LiteSpeed-Cache-Control
X-ServedByHost
Yjs-Id
ENV
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-Git-Commit
X-UP
X-Moov-T
X-Hyper-Cache
X-TraceId
X-Amz-Meta-Opti
X-Serial
X-Moov-Xdn-Version
Geoip-Latitude
X-Container-Uri
WZWS-RAY
Traceparent
X-Scheme
X-Dw-Trace-Id
X-Cdn-Forward
X-MiniProfiler-Ids
X-M-Log
X-M-Reqid
X-Acquia-Application-Trace
X-Acquia-Purge-Tags
X-Tncms
X-Acquia-Site
X-B3-Parentspanid
X-Qnm-Cache
X-Fastly-Backend-Reqs
X-Lb-Nocache
X-Viewer-Country
X-VG-WebCache
X-Swift-Error
XM
X-ApacheServer
X-RAMCache
Ec-Rule-Version
X-Acquia-Application-UUID
Cneonction
X-PERF
Content-Script-Type
Content-Style-Type
X-Lsadc-Cache
X-UA
X-Wp-Cf-Super-Cache
X-TT-LOGID
X-Wp-Cf-Super-Cache-Cache-Control
CountryCode
X-F-Status
MIME-Version
X-Mg-Cache
X-Iauth-Set-Uid
Serverid
Ohc-Cache-HIT
X-Webstats-RespID
X-Litespeed-Cache-Control
X-B3-ParentSpanId
Inserted-Into-Cache-At
X-Mid-Debug-Cache-Key
Warning
X-Th-Server
Ngx
X-IPS-Cached-Response
X-Request-URL
X-Fastly-Cache-Hits
X-LiteSpeed-Tag
X-Cache-Ngx
X-Mid-Debug-Cache-Disk
My-App