Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
Strict-Transport-Security
X-Frame-Options
X-Content-Type-Options
Last-Modified
Link
CF-Cache-Status
Cf-Request-Id
Accept-Ranges
ETag
CF-RAY
Expect-CT
Pragma
X-Powered-By
X-Cache
X-XSS-Protection
Via
Age
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Xss-Protection
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-FRAME-OPTIONS
X-Download-Options
X-Timer
X-Request-Id
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-Adblock-Key
X-AspNet-Version
X-Permitted-Cross-Domain-Policies
X-Runtime
Alt-Svc
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Check
X-DNS-Prefetch-Control
X-Cache-Status
X-Generator
CF-Ray
X-Cacheable
Timing-Allow-Origin
X-Iinfo
X-Envoy-Upstream-Service-Time
Feature-Policy
Status
X-Content-Security-Policy
X-Drupal-Dynamic-Cache
Content-Encoding
X-AspNetMvc-Version
X-Request-ID
Access-Control-Expose-Headers
X-CDN
Upgrade
X-XSS-PROTECTION
Access-Control-Max-Age
X-Ua-Compatible
X-Via
X-Dns-Prefetch-Control
X-Cache-Group
Server-Timing
X-Robots-Tag
X-UA-Device
Request-Context
Keep-Alive
X-Amz-Request-Id
X-AH-Environment
X-Turbo-Charged-By
X-Amz-Id-2
X-Backend
X-Proxy-Cache
X-Ws-Request-Id
X-Age
Host-Header
P3p
X-Server-Powered-By
X-Hacker
X-Server
X-Rq
X-Vhost
EagleId
X-Akamai-Path-Stats
X-Varnish-Cache
Grace
X-Amz-Version-Id
X-Dispatcher
X-LiteSpeed-Cache
Cf-Edge-Cache
Allow
X-Swift-CacheTime
X-Swift-SaveTime
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
Ali-Swift-Global-Savetime
X-WebKit-CSP
X-Nginx-Cache-Status
X-Device
X-Page-Speed
X-Aws-Lambda-Call-Status
X-Host
X-OneAgent-JS-Injection
X-Node
X-Server-Id
X-Pingback
EagleEye-TraceId
Accept-CH
X-Cache-Spec
Cf-Railgun
Request-Id
Surrogate-Control
X-Backend-Server
X-Akam-SW-Version
X-Cache-Lookup
X-Readtime
X-Response-Time
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-HW
Accept-CH-Lifetime
Content-Location
X-Content-Security-Policy-Report-Only
X-Application-Context
Rating
X-Trace
X-Cloud-Trace-Context
Fastly-Restarts
X-Country
Accept-Ch-Lifetime
X-WebKit-CSP-Report-Only
X-Url
X-Clacks-Overhead
X-Edge
X-Ruxit-JS-Agent
X-MS-InvokeApp
X-B3-TraceId
X-Amz-Server-Side-Encryption
X-Rack-Cache
Edge-Control
X-TtlSet
X-PC
X-Vname
X-Nginx-Upstream-Cache-Status
X-Content-Type
X-Vcap-Request-Id
X-ESI
X-Mod-Pagespeed
X-Varnish-TTL
X-FastCGI-Cache
Xkey
X-D2id
X-Exp-Id
X-GoogleNews-Bot
X-Kinja-Server
X-Use-Magma
X-Kinja-Revision
X-Kinja-Build
X-Kinja
X-Exp-Variant
X-Cdn-Fetch
X-Mcache
X-Amz-Rid
X-GitHub-Request-Id
X-VARITI-CCR
Cache-Tag
Verso
Accept-Ch
X-CST
RTSS
X-Powered-By-Plesk
X-ECACHE
Service-Worker-Allowed
X-Navigation-Version
X-Cached
X-Version
X-Upstream
X-Abt-Application-Version
X-Client-IP
X-Oneagent-Js-Injection
X-Dw-Request-Base-Id
X-Px
X-Cnection
X-Ac
X-Ruxit-Js-Agent
Public-Key-Pins
X-Instrumentation
X-Element-Page-Cache
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
Arr-Disable-Session-Affinity
SPRequestGuid
X-SharePointHealthScore
X-Server-Name
Pagespeed
SPIisLatency
Display
X-Middleton-Display
SPRequestDuration
X-Sol
X-Cache-TTL
X-Ser
X-NWS-LOG-UUID
X-Country-Code
X-RateLimit-Remaining
Permissions-Policy
X-Midtier
X-Ttl
X-Middleton-Response
Response
X-Kinsta-Cache
X-Edge-Location-Klb
X-NF-Request-ID
X-Cache-Key
X-Forwarded-For
X-Goog-Hash
Content-MD5
Access-Control-Request-Method
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Shield-Request-Id
X-DataDome
Front-End-Https
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-MSEdge-Ref
X-T
X-HP-Webp
X-HP-Trace-Id
Nginx-Cache
X-Jurisdiction
X-Recruiting
Edge-Cache-Tag
TP-Cache
TP-L2-Cache
AR-SID
AR-ATIME
AR-CACHE
AR-PoweredBy
AR-Request-ID
X-Powered-CMS
X-RateLimit-Limit
X-Accel-Expires
X-Daa-Tunnel
MicrosoftSharePointTeamServices
X-Correlation-Id
TCN
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
X-Grace
X-Id
X-Mg-S
X-Hits
X-Content-Digest
X-Request-Processing-Time
X-Request-Received
Filters
X-HS-Cache-Config
X-HS-Combine-CSS
X-HS-Content-Id
X-HS-Hub-Id
Server-Node
X-TTL
X-Amzn-Trace-Id
Server-Name
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-LLID
Cf-Apo-Via
X-Frontend
S
X-Distributor
X-Protected-By
X-Geo-Country
Fastcgi-Cache
MS-Author-Via
X-PressLabs-Stats
Cache-Status
X-Language
X-LB-Cache
X-Fastly-Request-Id
X-Origin-Server
X-Ezoic-Cdn
X-FB-Debug
X-B3-Sampled
X-Amz-Meta-S3cmd-Attrs
Host
Cross-Origin-Opener-Policy
X-Page-Id
X-Seen-By
X-Forwarded-Proto
X-F-Cache
X-Git-Hash
X-Ua-Browser
X-Ab
Charset
X-Erf-Bev-Bev
X-Browser-Type
X-Erf-Bev-Bev-Is-Generated
Count-Hit
Filterid
Payment
X-Request-Handler-Origin-Region
X-Microsite
X-Litespeed-Cache
Realpath
X-ASPNET-VERSION
X-Cache-Age
X-Cluster-Name
X-Ratelimit-Reset
X-VCache
Surrogate-Key
X-Rid
Accept-Charset
X-XRDS-Location
X-Origin-Cache
Alternate-Protocol
Cache-Tags
X-Template
X-NGENIX-Cache
X-DynaTrace
Retry-After
X-Az
X-Activity-Id
X-AppVersion
X-Www-Served-By
X-Webkit-Csp
Cleartype
Access-Control-Allow-Method
X-Varnish-Backend
X-Amz-Replication-Status
X-Providence-Cookie
X-Is-Crawler
X-Flags
X-DIS-Request-ID
X-TT
X-Varnish-Grace
X-Request-Guid
X-Aspnet-Duration-Ms
X-Route-Name
X-Tb
X-B
X-Wix-Request-Id
X-Upgrade-Enabled
X-Node-Name
X-Fastcgi-Cache
X-Logged-In
X-Type
X-B-Cache
X-Signature
X-App-Environment
DC
Paypal-Debug-Id
ServerID
X-Drupal-Cache-Tags
X-Debug
X-Proxy
X-Envoy-Decorator-Operation
X-Source
X-Hostname
Frame-Options
X-Tt-Trace-Tag
X-Fastly-Request-ID
X-Tt-Trace-Host
X-Content-Options
X-Content
X-Mobile
X-Revision
X-Load-Cache
Pinterest-Version
X-Pinterest-Rid
Pinterest-Generated-By
X-Contextid
X-GUploader-UploadID
X-Goog-Stored-Content-Length
X-Kong-Upstream-Latency
X-Goog-Generation
X-Cache-Control
X-Kong-Proxy-Latency
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-N
X-Cache-Rule
Country
Amp-Access-Control-Allow-Source-Origin
X-Magnolia-Registration
X-Whom
X-User-Agent
Referer-Policy
Refresh
Node
Viewport
X-Original-Request-Id
X-Response-Served-From
X-EdgeConnect-Cache-Status
NGB
Content-Disposition
X-Debug-IsPreview
Access-Control-Request-Headers
X-Varnish-Age
X-Cache-TTL-Remaining
X-Cacheable-TTL
X-Debug-IsConnected
X-Framework
X-Page-View
X-Environment-Context
X-Real-IP
X-Adobe-Content
X-L-Path
X-Varnish-Server
X-Adobe-Loc
X-Jobs
X-Cache-Time
Url
X-Mid
X-G
X-Servername
X-Unique-Id
X-Is-Bot
X-Akamai-Request-ID2
X-Cache-Grace
Uber-Trace-Id
X-Rendered-As
X-NYM-Debug-Backend
VIX-Pulpo-Upstream-Status
Akamai-GRN
X-Mg-Request-UUID
VIX-Pulpo-Node
X-XRDS-LOCATION
X-Instance
X-Content-Powered-By
X-Yottaa-Optimizations
X-Status
X-Yottaa-Metrics
X-Ratelimit-Remaining
X-RemovedCookies
X-Restarts
Countrycode
X-ProcessESI
X-Drupal-Cache-Contexts
Version
X-Server-ID
X-App-Server
X-COUNTRY
X-Time
Srv
X-Http-Reason
X-Debug-Info
Accept-Language
Protected
X-APP-VERSION
X-CDN-Forward
X-IPLB-Request-ID
X-Trace-Id
X-IPLB-Instance
X-Cache-Expired-At
X-Hosted-By
Healthy
X-Via-JSL
X-Tumblr-Pixel-1
X-Tumblr-User
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Nginx-Cache-Key
X-Device-Type
X-Cache-Hit
Liferay-Portal
X-Azure-Ref
X-FW-Static
X-FW-Hash
X-Ratelimit-Limit
X-FW-Dynamic
X-FW-Serve
Fastcgi-Useragent
X-FW-Server
X-FW-Type
X-Cache-Operation
X-Backend-Name
Section-Io-Cache
X-Tt-Logid
MS-CV
Ms-Operation-Id
X-RTag
X-Cache-NGX
X-Correlation-ID
X-Proxy-Cache-Status
Server-Info
Content-Secure-Policy
X-Datadome
X-Mobile-URL
Backend
X-UUID
X-Oracle-Dms-Rid
X-Oracle-Dms-Ecid
X-RN-RSRV
X-Akamai-Edgescape
Load-Balancing
Meta-Geo
X-UPSTREAM-Address
X-Mode
X-Storage
X-Handled-By
CF-IPCountry
Cross-Origin-Resource-Policy
X-HTML-Minification-Powered-By
X-No-Session
X-LJ-Flow-ID
X-Varnish-Hostname
Onion-Location
Eomportal-Instance
X-Varnishpool
X-Origin-Date
X-Proto
X-Storefront-Renderer-Rendered
X-Content-Age
X-PHP-Backend
X-VWS-Id
X-Origin-Hint
Property-Id
S-Rt
X-Adobe-Source
Webcakes-Region
X-Alternate-Cache-Key
X-AWS-Id
X-Cache-Server
X-Cms-Context
Webcakes-App-Version
Webcakes-App-Name
TWC-Device-Class
TWC-Connection-Speed
TWC-GeoIP-Country
TWC-GeoIP-LatLong
TWC-Privacy
TWC-Locale-Group
X-Sql-Duration-Ms
X-Locale
X-Sorting-Hat-ShopId
X-ShardId
X-Skip-Cache
X-Sorting-Hat-PodId
X-Server-W
X-ShopId
X-Shopify-Stage
X-Site-Version
X-Sql-Count
X-Generation-Time
CDN-CachedAt
CDN-Cache
Locale
X-Generated-By
X-Urbn-Site-Id
X-Uri
X-Varnish-Cache-Hits
CDN-RequestId
X-ProxyCache-Key
CDN-RequestCountryCode
X-Hl-Ver
CDN-EdgeStorageId
X-Proxied
CDN-Uid
Selected-Fe
X-Detected-As
X-Region
X-Edge-Location
X-Request-Time
X-Redis-Cache
X-ProxyCache-Status
X-Cache-Host
X-Cache-Enabled
X-BYPASS-REASON
X-Extlb
X-FB-TRIP-ID
X-Forwarded-Host
X-Urbn-Context-Path
X-Labrador-Cache-Channel
X-SayCDN-TTL
X-UA-Device-Type
X-Routing-Service
X-Say-Cacheable
X-Say-TTL
X-ServerID
CDN-PullZone
X-Web-Node
X-Via-Fastly
X-PHP-Host
X-OCL
X-Proxy-Build
X-PCL
X-Rule
X-Zipkin-Id
X-Xfnlog-Site
X-Cache-Action
X-VC-Cache
X-Timing-Wait
GEO-INFO
Azure-SiteName
Azure-RegionName
X-Tid
Web-Mar-Node
Azure-Version
X-Varnish-Beresp-Grace
X-Cache-Status-Check
Azure-InstanceId
Azure-SlotName
DB-Nickname
X-Nginx-Cache
Apigw-Requestid
X-GeoCode
X-GeoCountry
Mn-Server-Ip
X-Access
X-Section
X-URL
X-Zen-Fury
WP-Super-Cache
X-Format
X-SaId
X-Cache-Type
X-JoinUs
X-R9-Blue-Green-Version
X-Ms-Request-Id
X-Ms-Version
X-SRV
X-DynaTrace-JS-Agent
X-Dc
X-FireWall-Port
X-Ua
Cache-Name
X-Debug-Cache
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
ServedBy
X-LSADC-Cache
X-ECache
X-Human
X-Api-Version
X-Amzn-RequestId
X-Amz-Apigw-Id
Xserver
X-Cache-Tags
Source
Cache
Xet-Cookie
SD-X-WS
X-Cached-By
X-Varnish-Hits
X-TA-CDN-Provider
X-RCS-CacheZone
X-Loop
X-MP-GENERATED-AT
X-App-Version
X-TNCMS
X-Reqid
X-GEO
X-Aspnetmvc-Version
Origin
WPO-Cache-Message
WPO-Cache-Status
Cross-Origin-Window-Policy
X-Amzn-Remapped-Content-Length
LB
X-Cdn
X-Soup
X-B3-SpanId
X-Origin-TTL
X-Origin-CC
X-Pubstack
X-NewRelic-App-Data
X-Webkit-CSP
X-Tumblr-Pixel-2
X-Via-NSCOPI
X-IPS-LoggedIn
X-Service
From-Origin
X-GG-Cache-Date
X-AOL-HN
X-Vgn-Hpd-Reason
X-FW-Version
X-Provided-By
X-Xrds-Location
X-Newrelic-Synthetics
Rip
X-Platform-Server
Webserver
Cache-Hits
X-Tec-Api-Root
X-Tec-Api-Origin
X-Tec-Api-Version
X-Request-Host
X-S
X-S-Cookie
A
BehaviorPad-Version
X-Rojux
X-ScT
X-Orig-Expires
X-PBS-Appsvrname
X-Owner
X-NAPM-TraceId
X-Processor
X-Rewrite-Enabled
Host-ID
X-B-Cookie
X-Bc-Bl
X-BCube-Filmed-By
X-ARC
X-Application
X-A-Wwc
X-Aed
X-AK-Request-ID
X-Cache-NE
X-Connection-Hash
X-Ec-GeoHdr
X-Forwarded-Path
X-External-Request-Id
X-Ec-Fail
X-Developer
X-D
X-Destination
X-A-Dgt
X-A-Dcw
Lang
MD5-Digest
Meta-Geo-Continent
X-Varnish-Beresp-Ttl
Expiry
DCR-Decision-By
DCR-Processing-Time-Ms
Environment
Ngx.Var.Host
Odigeo-Trace-Id
X-A
X-A-Ccd
X-A-Dam
T-Server
Surrogated-Key
Rendered-Blocks
Sslversion
Cdnsip
Cdncip
X-Tenant
X-Vdms-Path
X-CSRF-Token
X-Served-From
Xc-Version
X-User
X-SRCache-Key
X-TIM-N
X-Vdms-Version
X-VG-WebCache
X-Cluster-Node
X-Shop-Environment
HostName
X-VC
X-Aicache-OS
X-Level-Front-Cache
X-WA-Info
X-Qloud-Router
X-Generated-On
X-Cluster
X-Accel-Buffering
X-Bip
Cache-Tv-Group
X-Thanos
X-Dispatcher-Number
Upgrade-Insecure-Requests
X-Origin-Response-Time
X-TIME
OT-Force-Account-Verify
Server-Host
X-Has-Esi
Thinkindot-CacheControl
Traceparent
Tube-Get-Contents
Tube-Got-Eval
Thinkindot-Control
Thinkindot-CacheControl-Type
TDXMobile
Release
State
Origin-EX
L
X-Is-Gdpr
Machine
IsBot
Is-Eu
Fastly-SWR
Gh-Request-Id
X-JWT-State
Memcached
X-Irp-Debug
Platform
Producers
X-Hash
Tube-Got-Results
Origin-CC
NGX
NM-Fastcgi-Cache
X-INCAP-ABP
Redirect-Candidate
X-Worker
X-Gateway-Cache-Key
X-Core-Mission
X-Core-Value
X-Clientip
X-Ckpd-Fst-Backend
X-Gateway-Skip-Cache
X-Gateway-Request-Id
X-Gateway-Cache-Status
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
X-DPWN-IS-SECURE
X-Forwarded-Site
X-Fetched-On
X-Gamma-Serve
X-Device-Os
X-Datadog-Trace-Id
X-DefElseHash
X-DefHash
X-Cdn-Srv
X-Cdn-Origin
X-VServer
X-Wix-Viewer-Type
Fastly-SIE
Wxu-Next-Region
Wxu-Next-Hostname
VNS-Age
VNS-Cache
Wxu-Next-Commit
X-Ad-Defer-Variation
Fastly-SSL
X-Branch-Name
X-CacheTTL
X-Gdpr
X-Auto-Login
X-Geo-Header
X-GeoIP-City
X-GeoIP
Tube-Return
Mobile-Detection-Method
X-Origin-Expires
X-Origin
X-Variation
X-Origin-Time
X-V-Cache
X-Planisys-CDN-Cache
X-Parent-Response-Time
X-Optimistic-Header
X-Varnish-CookieHashed-On
Apple-News-Services-Request-Url
X-Varnish-CookieINHashed-On
Click-Count-Action-Start
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
Adler-Geo
Apple-News-Services-Handled
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Request-URI
X-Region-Sid
X-Rebelmouse-Surrogate-Control
X-SIPLIST1
X-S-Maxage
X-Scale
X-SB
X-Slack-Backend
X-Rebelmouse-Cache-Control
X-Pool
X-Policy
X-Thinkindot-L3
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-Sn-Servicetimems
X-SplitTest
Click-Count-Error
X-Nyt-Route
Country-Code
CPC-Age
Cmstype
X-Minions-Version
CPC-Cache
Cmsid
X-Varnish-Remaining-TTL
DSUID
Mime-Version
X-WADP-Cache
X-Csrf-Jwt
X-Developers
Decoy-Debug-Key
Datacenter
HA-Ipaddr
Fastcgi-Cache-TTL
Ha-Gx-Prefs
X-Rocket-Nginx-Serving-Static
X-Rocket-Build-Number
X-Sigma-Backend
CloudFront-Viewer-Country
X-Cache-Id
X-Cache-Remote
X-Cache-Bucket
X-Clara-WADP
L5d-Success-Class
Kp-EeAlive
X-CGP
X-Gen-Mode
X-Block-Status
Decoy-Debug-Status
X-VG-TLSProxy
X-BBC-Edge-Cache-Status
Decoy-Debug-TTL
X-Proxy-Cache-Info
X-Mvc-Supplant-Cachable
Mail-Subject
X-ZONE
Fastly-Backend-Name
Sever-Int
X-Eu-Site
Candidate-Md5Url
X-Epic-Correlation-Id
X-Esi-Check
Servername
X-Fmm-Version
X-Hnp-Log
Cluster
X-Scheme
Req-Svc-Chain
Server-Hostname
Server-Ext
X-Sigma
Cache-Host
Vix-Hermes-Req-Id
X-NCache
X-NodeID
We-Hiring
X-Mvc-Supplant-OutputCached
Web-Mar-Region
User-Cache-Control
V-Age
X-HS-Content-Campaign-Id
X-Loc
AKAMAI
X-Ec-Custom-Error
X-Session-Fingerprint
X-Gzip
WebServer
X-Tx-Id
X-RateLimit-Remaining-Second
X-Fastly-Cache
X-Varnish-Beresp-Status
X-CMSURLCustom
Fastly-GeoIP-CountryCode
X-Viewer-Country
Ec-Rule-Version
CDCHOST
Svr
X-RateLimit-Limit-Second
Canary
X-Cache-Info
X-NWS-UUID-VERIFY
X-Udemy-Cache-App-Namespace
X-Varnish-Ttl
X-WP-CF-Super-Cache-Active
X-LB-NoCache
X-Pod-Name
Ssr
X-Cache-Debug
AMP-Access-Control-Allow-Source-Origin
Time
X-ND-Cache
X-Sucuri-Cache
SID
Pics-Label
Sid
X-Sucuri-ID
Memory
X-Via-Popv
X-Var-Ttl
X-Fastly-Backend
X-FC-Vary-Parameters
X-ATG-Version
X-Via-Poph
X-Ig-Push-State
X-Via-Popn
X-Azure-Ref-OriginShield
X-Cache-Date
X-Buckets
X-Tb-Optimization-Total-Bytes-Saved
X-Akamai-Transformed
X-Refresh
Fastly-Drupal-Html
X-Generated-In
X-Microcachable
X-Conf
X-Edge-Pop
X-Presslabs-Stats
X-B3-Traceid
Server-ID
X-Newrelic-App-Data
X-TRACE-ID
X-Servedbyhost
X-Cs
Fastly-Drupal-HTML
X-Release
X-Dmc
X-MSEdge-Flight
X-MSEdge-Features
X-Yandex-Sdch-Disable
X-Trace-ID
X-Fpc
X-Nf-Request-Id
X-RateLimit-Reset
X-Pass-Why
X-Be
X-NC
Env
X-Tumblr-Pixel-3
X-Up
X-CACHE-KEY
X-EC-Lua
X-Esi
X-Endurance-Cache-Level
X-CS
X-PX
X-Dispatch
My-App
X-Air-Trace-Id
X-MCACHE
X-ID
X-Air-Hostname
GeoIp-Country-Code
X-Air-Source
Magicmarker
CDN
X-DC
X-TX-ID
X-Wikidot-Static-Cache
X-Lambda-Id
X-Wikidot-Backend
X-Wa
X-Srv
True-Client-IP
X-CACHE-AGE
X-Zone
X-Hyper-Cache
X-NGINX-Cache
X-Webkit-CSP-Report-Only
X-Req
X-VCL-Version
X-CF-Lambda-Version
X-CF-Lambda-Fn
X-Vc
Pramga
X-CSRF-TOKEN
X-App
X-Alfa-Service
Hostname
X-M-Log
X-Micro-Cache
X-M-Reqid
X-Vcl-Version
X-LB-ID
CacheControlHeader
C-Via
X-Varnish-Beresp-TTL
X-HS-Status
X-Qnm-Cache
X-TH-Server
Resin-Trace
X-Air-Pt
X-TrackingId
N-Cache
True-Client-Ip
Path
X-Edge-Origin-Shield-Region
X-Vercel-Id
Tcn
X-PAYTM-SRV-ID
True-Client-Country-4JS
X-Platform
On-Server
X-Vercel-Cache
GeoIP-Country-Code
Fastcgi-X-Cache-Version
X-Op-Id-All
X-Edge-Origin-Shield-Bytes
Esi-Enabled
Tracecode
X-Check-Cacheable
X-SERVER-NAME
X-Vtex-Processado-Em
Proxy-Connection
X-Vtex-Remote-Cache
X-FPC
GeoIP-Latitude
NtCoent-Length
X-AIR-PT
X-CLOUD-TRACE-CONTEXT
X-B3-Spanid
X-GeoIP-Region-Code
Hit
X-ApacheServer
X-Datacenter
Section-Io-Origin-Status
Section-Origin-Responded
X-WA
Section-Io-Origin-Time-Seconds
X-GeoIP-Country-Code
X-PERF
Section-Io-Id
X-Akamai-Pragma-Client-IP
X-Node-Id
X-Request-Start
X-API-Version
X-SD-PageType
X-LAGOON
X-Webkit-Csp-Report-Only
X-Date
X-Accel-Expires-Debug
HIT
X-Platform-Router
X-Platform-Cluster
X-Platform-Processor
WWW-Authenticate
ENV
X-ServedByHost
X-Mly-Id
X-Geo
X-Via-CDN
Cache-Key
Yjs-Id
X-Cdn-Forward
Cdn
X-Proxy-CacheRZ
YJS-ID
User-Agent
XkeyRZ
X-Lb-Id
Lb
Server-Id
DynaTrace
X-Render-Time
X-RAMCache
DT-Hot-News
X-Edge-POP
X-TT-LOGID
X-Dw-Trace-Id
X-Proxy-Upstream
X-Via-PopV
X-Via-PopN
X-Old-Content-Length
X-VarnishDD-TTL
X-Via-PopH
X-Via-Ucdn
PFcat
X-HN
X-Response-By
X-Instance-Name
FSS-Cache
Server-Ttl
XM
X-Traceid
X-Li-Pop
X-Li-Fabric
X-LI-UUID
X-Cache-Ttl
X-LI-Proto
Dnion-Transfer-Encoding
Powered-By
Geoip-Latitude
X-CUA
X-FORWARDED-FOR
X-Proxy-Cache-Hk
X-CF-Powered-By
X-Service-Response-Time
Sm-Log-Id
X-LiteSpeed-Cache-Control
X-RPS
X-Location
X-DI
X-DB
X-RSL
X-DSS
Ohc-File-Size
X-DW
Location
PICS-Label
X-RPM
X-LiteSpeed-Tag
X-Akamai-ERRuleID
XServer
X-Akamai-ERPolicy
X-Fastly-Backend-Reqs
Nginx-CQVIP
MIME-Version
X-Litespeed-Cache-Control
SRV
X-Wp-Cf-Super-Cache-Cache-Control
X-Wp-Cf-Super-Cache
X-UA
X-Contensis-Viewer-Groups
X-Cache-ASPX
X-Varnish-Authentication
X-Request-Url
M-TraceId
X-Webstats-RespID
X-HostName
Locid
Srvid
X-FL-EDGE
X-From
X-Nc
X-Ftr-Request-Id
Wpo-Cache-Message
Wpo-Cache-Status
Vha6-Origin
X-Cdn-Request-ID
X-Fastly-Cache-Hits
X-Lb-Nocache
X-Cache-Backend
X-B3-ParentSpanId
X-Ips-Loggedin
CountryCode
Wp-Super-Cache
Warning
X-Cache-Ngx
Fastcgi-Cache-Ttl
X-Director
Req-ID
X-Httpd
X-MiniProfiler-Ids
X-IN-APIGATEWAYSSL
X-IN-APIGATEWAY
WZWS-RAY
X-Cc-Via
X-Moov-T
X-Moov-Xdn-Version
X-Snapshot-Date
X-HA-Backend
X-Akamai-Request-ID
X-Mg-Cache