Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Accept-Ranges
Expect-CT
Pragma
X-Powered-By
X-XSS-Protection
CF-RAY
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-Xss-Protection
P3P
X-UA-Compatible
X-Served-By
X-Download-Options
CF-Ray
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
Access-Control-Allow-Credentials
X-FRAME-OPTIONS
X-Request-Id
X-Request-ID
X-Permitted-Cross-Domain-Policies
X-AspNet-Version
Alt-Svc
X-Runtime
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Generator
X-Cache-Status
X-Cacheable
Timing-Allow-Origin
X-Iinfo
X-Envoy-Upstream-Service-Time
X-Content-Security-Policy
X-Drupal-Dynamic-Cache
Feature-Policy
Content-Encoding
Access-Control-Expose-Headers
Upgrade
Status
X-CDN
X-AspNetMvc-Version
P3p
Access-Control-Max-Age
X-Via
Server-Timing
X-UA-Device
Request-Context
X-Robots-Tag
X-Turbo-Charged-By
X-Amz-Request-Id
X-Cache-Group
EagleId
X-Amz-Id-2
X-Backend
X-AH-Environment
X-Proxy-Cache
Keep-Alive
X-Ua-Compatible
X-Server
X-Ws-Request-Id
X-Age
Host-Header
Cf-Edge-Cache
X-Hacker
X-Vhost
X-Server-Powered-By
X-Rq
X-Dns-Prefetch-Control
X-Varnish-Cache
X-Dispatcher
X-Amz-Version-Id
Grace
Allow
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-OneAgent-JS-Injection
X-LiteSpeed-Cache
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Page-Speed
Cf-Apo-Via
X-Device
X-WebKit-CSP
Accept-CH
Cf-Railgun
X-Aws-Lambda-Call-Status
X-Node
X-Pingback
X-Host
X-Ruxit-JS-Agent
EagleEye-TraceId
X-Nginx-Cache-Status
X-Server-Id
Surrogate-Control
X-Akam-SW-Version
X-Cache-Spec
Request-Id
X-Backend-Server
X-Readtime
X-Cache-Lookup
X-HW
X-Content-Security-Policy-Report-Only
X-Cloud-Trace-Context
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Trace
Accept-Ch-Lifetime
X-Application-Context
X-Response-Time
Fastly-Restarts
Permissions-Policy
X-Nginx-Upstream-Cache-Status
X-Mod-Pagespeed
X-Edge
Accept-CH-Lifetime
X-WebKit-CSP-Report-Only
X-Litespeed-Cache
X-Mcache
Content-Location
X-Content-Type
X-Url
X-MS-InvokeApp
X-CST
X-Country
X-Clacks-Overhead
Rating
X-Midtier
X-Amz-Server-Side-Encryption
X-TtlSet
X-Vname
X-PC
RTSS
Cache-Tag
X-ESI
X-Vcap-Request-Id
X-D2id
X-VARITI-CCR
X-Element-Page-Cache
Origin-Trial
Verso
X-Server-Name
X-ECACHE
X-Kinja
X-GoogleNews-Bot
X-Kinja-Build
X-Exp-Id
X-Cdn-Fetch
X-Exp-Variant
X-Use-Magma
X-Kinja-Revision
X-Kinja-Server
X-Rack-Cache
X-Ac
X-Ttl
X-Powered-By-Plesk
X-Cnection
Service-Worker-Allowed
SPRequestGuid
X-SharePointHealthScore
X-Amz-Rid
X-Client-IP
Xkey
X-Navigation-Version
X-GitHub-Request-Id
X-B3-TraceId
X-Abt-Application-Version
Edge-Control
X-Cache-TTL
X-NWS-LOG-UUID
SPRequestDuration
SPIisLatency
X-Upstream
Arr-Disable-Session-Affinity
X-Webkit-Csp
X-Varnish-TTL
X-Instrumentation
X-Kraken-Loop-Name
X-Erf-Bev-Bev
X-Server-Lifecycle-Phase
X-Erf-Bev-Bev-Is-Generated
X-Browser-Type
X-Cached
X-Mg-S
X-Dw-Request-Base-Id
X-Px
X-Cache-Key
X-Correlation-Id
X-Sol
X-Middleton-Display
Pagespeed
Display
X-SRCache-Fetch-Status
X-SRCache-Store-Status
Access-Control-Request-Method
X-NF-Request-ID
Edge-Cache-Tag
X-Forwarded-For
Content-MD5
X-Country-Code
X-Goog-Hash
X-FastCGI-Cache
Front-End-Https
TCN
X-Powered-CMS
X-Id
X-Version
Public-Key-Pins
AR-SID
X-XRDS-Location
AR-Request-ID
AR-ATIME
AR-PoweredBy
AR-CACHE
X-HP-Webp
X-HP-Trace-Id
X-RateLimit-Remaining
X-Jurisdiction
Accept-Ch
X-T
X-Content-Digest
X-MSEdge-Ref
X-Recruiting
X-Amzn-Trace-Id
X-Ser
X-Daa-Tunnel
X-Accel-Expires
X-Middleton-Response
Response
TP-L2-Cache
TP-Cache
X-Shield-Request-Id
X-Ratelimit-Limit
S
X-Fastcgi-Cache
Nginx-Cache
MicrosoftSharePointTeamServices
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
Cache-Status
X-Request-Received
X-Request-Processing-Time
Server-Node
X-HS-Content-Id
X-HS-Combine-CSS
X-HS-Hub-Id
X-HS-Cache-Config
Cache-Tags
X-Distributor
X-Hits
X-Edge-Location-Klb
X-Kinsta-Cache
X-LB-Cache
Cross-Origin-Opener-Policy
X-Ratelimit-Remaining
Fastcgi-Cache
X-Origin-Server
X-Ua-Browser
Alternate-Protocol
X-Ezoic-Cdn
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-Grace
Server-Name
X-TEC-API-ROOT
X-DataDome
X-DIS-Request-ID
X-Geo-Country
X-Ratelimit-Reset
Filterid
X-PressLabs-Stats
X-Microsite
X-Request-Handler-Origin-Region
X-Rid
X-Server-ID
X-Protected-By
Healthy
X-LLID
X-Frontend
X-Hostname
X-Varnish-Backend
X-Git-Hash
Payment
X-Debug-Info
X-Logged-In
Cleartype
X-FB-Debug
X-Page-Id
X-Www-Served-By
X-Forwarded-Proto
X-Load-Cache
X-NGENIX-Cache
X-Origin-Cache
X-Cluster-Name
X-ASPNET-VERSION
DC
MS-Author-Via
X-Fastly-Request-ID
Charset
X-ORACLE-DMS-ECID
Content-Disposition
X-ORACLE-DMS-RID
Realpath
Access-Control-Allow-Method
X-B3-Sampled
X-GUploader-UploadID
X-Goog-Metageneration
X-Upgrade-Enabled
X-Proxy
X-F-Cache
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Activity-Id
X-Az
X-AppVersion
X-Seen-By
X-ECache
X-Amz-Replication-Status
Retry-After
X-TTL
Paypal-Debug-Id
Cross-Origin-Resource-Policy
X-Amz-Meta-S3cmd-Attrs
X-Type
X-Contextid
X-Aspnet-Duration-Ms
X-Revision
X-Azure-Ref
X-Flags
X-Hosted-By
Viewport
X-Request-Guid
X-Fb-Rlafr
X-Route-Name
X-Whom
X-Providence-Cookie
X-Is-Crawler
Count-Hit
X-Signature
X-Wix-Request-Id
X-Aspnetmvc-Version
X-B-Cache
X-App-Environment
Surrogate-Key
Accept-Charset
X-B
X-Varnish-Server
X-VCache
Amp-Access-Control-Allow-Source-Origin
X-Akamai-Edgescape
X-Fastly-Request-Id
X-TT
X-Oracle-Dms-Ecid
X-Oracle-Dms-Rid
X-Cache-Age
X-DynaTrace
X-B3-Traceid
X-Language
X-Source
X-App-Server
X-Cache-Control
Referer-Policy
X-Mobile
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Magnolia-Registration
X-Times
X-Varnish-Grace
Host
X-RateLimit-Limit
X-Envoy-Decorator-Operation
Version
X-N
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-HTML-Minification-Powered-By
X-Cache-Rule
X-Tumblr-User
X-Original-Request-Id
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Response-Served-From
X-Tumblr-Pixel-1
Access-Control-Request-Headers
MS-CV
Refresh
X-Cache-Time
X-UUID
X-RTag
Section-Io-Cache
X-Varnish-Age
WPO-Cache-Message
SRV
Ms-Operation-Id
WPO-Cache-Status
SD-X-WS
X-Framework
X-Cache-Status-Check
GEO-INFO
Akamai-GRN
X-Backend-Name
X-FW-Hash
X-FW-Serve
X-Rule
X-User-Agent
X-FW-Dynamic
X-Page-View
X-ProcessESI
X-RemovedCookies
X-FW-Server
X-FW-Static
X-Content-Powered-By
X-Cacheable-TTL
X-Cache-Expired-At
X-Cache-Grace
X-FW-Version
X-FW-Type
X-EdgeConnect-Cache-Status
X-G
X-Instance
VIX-Pulpo-Node
X-Status
X-Is-Bot
Url
Protected
X-Jobs
X-Rendered-As
VIX-Pulpo-Upstream-Status
X-Drupal-Cache-Tags
X-Drupal-Cache-Contexts
X-Servername
X-Device-Type
X-NYM-Debug-Backend
X-Http-Reason
From-Origin
X-L-Path
X-Environment-Context
X-Akamai-Request-ID2
X-Adobe-Content
X-Adobe-Loc
CDN-RequestId
NGB
X-Trace-Id
X-Template
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Region
X-COUNTRY
Front
X-CDN-Forward
X-Varnish-Ttl
X-Nginx-Cache
X-Debug-IsConnected
X-Debug-IsPreview
Accept-Language
X-Yottaa-Optimizations
X-Unique-Id
X-Yottaa-Metrics
X-Cache-Hit
X-Content-Options
Backend
Fastly-SIE
Fastly-SWR
Country
X-Zen-Fury
X-Air-Hostname
X-Air-Trace-Id
Liferay-Portal
X-Air-Source
X-DynaTrace-JS-Agent
X-Tb
X-XRDS-LOCATION
Pinterest-Generated-By
X-Pinterest-Rid
Pinterest-Version
X-Newrelic-App-Data
X-Mode
X-Cache-Operation
Content-Secure-Policy
X-Real-IP
X-Tt-Logid
X-Node-Name
X-UPSTREAM-Address
Webserver
Filters
Meta-Geo
X-Tumblr-Pixel-2
X-Rewrite-Enabled
X-Generation-Time
X-RN-RSRV
X-Amzn-Remapped-Content-Length
Uber-Trace-Id
X-Proxy-Cache-Info
X-Cache-Server
X-IPS-LoggedIn
X-Timing-Wait
Azure-RegionName
Azure-SiteName
Azure-SlotName
Cache-Hits
Azure-Version
Azure-InstanceId
X-Ms-Request-Id
X-Content-Age
X-Rocket-Nginx-Serving-Static
X-Proxy-Build
X-Section
X-Ms-Version
X-PHP-Backend
X-Web-Node
X-Format
Selected-Fe
X-Time
CF-IPCountry
X-Access
Onion-Location
TWC-Locale-Group
X-Origin-Hint
TWC-Privacy
Webcakes-App-Name
TWC-GeoIP-LatLong
Webcakes-Region
Webcakes-App-Version
TWC-Connection-Speed
X-Cluster-Node
Cache-Name
Node
Property-Id
ServedBy
TWC-Device-Class
X-Debug
TWC-GeoIP-Country
X-Proto
X-Sql-Count
X-Soup
X-Server-W
X-TIME
X-Sucuri-Cache
X-VC-Cache
X-UA-Device-Type
X-Sucuri-ID
X-SayCDN-TTL
X-Sql-Duration-Ms
X-Locale
X-Say-Cacheable
X-Say-TTL
Web-Mar-Node
X-Skip-Cache
X-Cache-TTL-Remaining
X-Varnish-Beresp-Grace
X-Cluster
S-Rt
DB-Nickname
X-Site-Version
X-Cache-Action
X-Cms-Context
X-Adobe-Source
X-Forwarded-Host
X-AWS-Id
ServerID
X-BYPASS-REASON
X-Cache-Host
X-Handled-By
X-ProxyCache-Status
X-IPLB-Request-ID
X-IPLB-Instance
X-Labrador-Cache-Channel
X-LJ-Flow-ID
X-Proxy-Cache-Status
X-PHP-Host
X-ProxyCache-Key
X-Via-Fastly
X-VWS-Id
X-Reqid
X-R9-Blue-Green-Version
X-Origin-Date
X-Tumblr-Pixel-3
X-Ruxit-Js-Agent
X-Routing-Service
X-Zipkin-Id
X-Proxied
X-LAGOON
X-WP-CF-Super-Cache-Cache-Control
Cross-Origin-Window-Policy
X-Detected-As
X-SaId
X-Edge-Location
X-FB-TRIP-ID
X-JoinUs
X-WP-CF-Super-Cache
X-Extlb
X-No-Session
X-Uri
Apigw-Requestid
Mn-Server-Ip
Locale
X-App-Version
X-Urbn-Site-Id
X-Urbn-Context-Path
X-Buckets
X-Optimistic-Header
X-Xfnlog-Site
X-Ua
WP-Super-Cache
Fastcgi-Useragent
Mime-Version
Countrycode
X-Tec-Api-Origin
X-GeoCode
X-GeoCountry
X-Tec-Api-Root
X-LSADC-Cache
X-Tec-Api-Version
Source
X-ARC
CDN-RequestCountryCode
CDN-PullZone
CDN-Uid
CDN-EdgeStorageId
CDN-CachedAt
X-Oneagent-Js-Injection
CDN-Cache
X-Hl-Ver
X-Director
Cache-Tv-Group
Fastly-Drupal-HTML
Upgrade-Insecure-Requests
X-Varnish-Hits
X-Mg-Request-UUID
X-GEO
X-Generated-By
X-Request-Time
X-Redis-Cache
X-Cache-Debug
X-Tx-Id
CF-Cached-On
X-Loop
Xet-Cookie
X-Origin-CC
Frame-Options
X-Origin-TTL
X-SRV
X-URL
X-FireWall-Port
X-Varnish-Cache-Hits
X-TNCMS
X-Pass-Why
X-Varnish-Hostname
X-RM-Cache-TTL
X-TA-CDN-Provider
X-Sorting-Hat-ShopId
X-ServerID
X-Storefront-Renderer-Rendered
X-Sorting-Hat-PodId
X-Shopify-Stage
X-Alternate-Cache-Key
X-ShardId
X-ShopId
X-Akamai-Transformed
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
X-Datadog-Sampled
X-Datadog-Parent-Id
X-Newrelic-Synthetics
Load-Balancing
X-Service
Xserver
X-Served-From
X-Endurance-Cache-Level
X-Request-Host
X-Pubstack
X-NWS-UUID-VERIFY
X-B3-Spanid
BehaviorPad-Version
X-Generated-On
X-Gdpr
Req-Svc-Chain
Cache-Host
DCR-Decision-By
Candidate-Md5Url
Sslversion
A
Thinkindot-CacheControl
Server-Info
Thinkindot-CacheControl-Type
X-Httpd
T-Server
DCR-Processing-Time-Ms
Surrogated-Key
X-Ec-GeoHdr
Release
Thinkindot-Control
Edge-Cache
X-External-Request-Id
X-Ec-Fail
MD5-Digest
Host-ID
Lang
Memcached
Meta-Geo-Continent
Origin
Redirect-Candidate
Gannett-Cam-Experience-Id
X-Epic-Correlation-Id
Odigeo-Trace-Id
Ngx.Var.Host
DSUID
Rendered-Blocks
X-A-Dam
X-S-Maxage
X-ScT
X-Location
X-Mid
X-S-Cookie
X-CMSURLCustom
X-Sigma
X-Cache-Info
X-Developer
X-Sigma-Backend
X-Cache-NE
X-S
X-Conf
X-D
X-Platform-Processor
X-Platform-Router
X-Processor
X-Rojux
X-Platform-Cluster
X-Origin-Time
X-Mobile-URL
X-Nyt-Route
X-CUA
X-Destination
X-SRCache-Key
X-Test
X-A-Wwc
X-INCAP-ABP
X-Aed
X-Application
X-We-Are-Hiring
X-A-Dgt
Xc-Version
X-A
X-A-Ccd
X-Rocket-Build-Number
X-A-Dcw
X-B-Cookie
X-BBC-Edge-Cache-Status
X-TIM-N
X-Vdms-Path
X-Thinkindot-L3
X-Loc
X-Thanos
X-Vdms-Version
X-Cache-Date
X-Bc-Bl
X-BCube-Filmed-By
X-Level-Front-Cache
X-Bip
WWW-Authenticate
TDXMobile
X-Varnish-Beresp-Ttl
X-Api-Version
Section-Io-Id
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
X-Restarts
Section-Origin-Responded
X-Fmm-Version
X-Developers
X-Fetched-On
X-Ec-Custom-Error
X-Frame-Option
X-GeoIP
X-Human
X-Has-Esi
X-GeoIP-City
X-Core-Value
X-Geo-Header
X-Cache-Bucket
Server-Host
NM-Fastcgi-Cache
Mail-Subject
Magicmarker
We-Hiring
X-Akamai-Device-Characteristics
X-Cdn-Srv
X-Is-Gdpr
X-Auto-Login
X-Clara-WADP
X-Mly-Id
X-Worker
X-WP-CF-Super-Cache-Active
X-WADP-Cache
X-WA-Info
X-VServer
Country-Code
X-Cdn-Origin
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-Sn-Servicetimems
X-Hash
X-Core-Mission
X-Vmg-Version
X-VG-TLSProxy
X-Org
X-Origin
X-Node-Id
X-Mvc-Supplant-Cachable
Gh-Request-Id
X-Pool
X-SD-PageType
X-Varnishpool
X-Varnish-Beresp-Status
X-Var-Ttl
X-Storage
X-JWT-State
X-Origin-Response-Time
CloudFront-Viewer-Country
C-Via
Fastly-Backend-Name
Cache-Key
AKAMAI
Apple-News-Services-Handled
Fastly-GeoIP-CountryCode
Apple-News-Services-Host
Apple-News-Services-Request-Url
CacheControlHeader
Apple-News-Services-Parsed-Url
X-Parent-Response-Time
X-CACHE-AGE
X-Cache-Id
X-Cache-Tags
X-Variation
X-DefHash
X-Dispatcher-Server
Click-Count-Error
X-Device-Os
X-Varnish-CookieHashed-On
Adler-Geo
X-DefElseHash
Datacenter
X-VarnishDD-TTL
State
X-Accel-Buffering
X-Accel-Expires-Debug
X-CacheTTL
X-Date
X-Ad-Defer-Variation
X-Wix-Viewer-Type
X-Old-Content-Length
X-Block-Status
X-CSRF-Token
X-Azure-Ref-OriginShield
X-App
X-Varnish-CookieINHashed-On
Click-Count-Action-Start
X-Qloud-Router
X-Irp-Debug
Cache-Provider
X-HS-Content-Campaign-Id
X-Hnp-Log
X-Platform-Server
X-LB-NoCache
X-NodeID
X-Op-Id-All
X-Nginx-Cache-Key
X-NCache
X-Platform
X-HN
X-Gzip
Wxu-Next-Region
X-Forwarded-Site
X-FC-Vary-Parameters
X-SB
X-Esi-Check
X-Request-Start
X-Req
X-GeoIP-Country-Code
X-GeoIP-Region-Code
Canary
CDCHOST
X-Gen-Mode
X-Scale
X-Varnish-Remaining-TTL
NGX
Environment
On-Server
X-Slack-Backend
X-Server-IP
X-Region-Sid
X-Fastly-Backend
X-Fastly-Cache
X-Gamma-Serve
Origin-CC
Origin-EX
Wxu-Next-Hostname
Server-Hostname
Sever-Int
Server-Ext
X-Men
PFcat
X-Slack-Shared-Secret-Outcome
Platform
Tube-Get-Contents
Machine
Vix-Hermes-Req-Id
L
User-Cache-Control
Is-Eu
Web-Mar-Region
Wxu-Next-Commit
X-Dispatcher-Number
Tube-Return
Kp-EeAlive
Tube-Got-Results
Tube-Got-Eval
HA-Ipaddr
X-Eu-Site
X-Presslabs-Stats
X-DPWN-IS-SECURE
X-Planisys-CDN-Cache
Ha-Gx-Prefs
X-Origin-Expires
X-Planisys-CDN-TTL
Fastly-SSL
X-Planisys-CDN-Rules
X-Owner
X-Minions-Version
X-Refresh
X-Nananana
L5d-Success-Class
Pics-Label
Producers
X-Instance-Name
X-Ckpd-Fst-Backend
Cluster
X-Csrf-Jwt
Decoy-Debug-Status
Decoy-Debug-Key
X-V-Cache
X-Cache-Backend
X-Cache-Remote
Cmsid
X-CGP
Decoy-Debug-TTL
Ssr
Cmstype
X-Tid
X-Webkit-CSP-Report-Only
X-Mvc-Supplant-OutputCached
X-Microcachable
X-Cache-FS-Status
X-Tb-Optimization-Total-Bytes-Saved
X-DC
X-Release
X-Response-By
X-Provided-By
X-Zone
Locid
Srvid
X-FL-EDGE
HostName
GeoIP-Latitude
Env
Expect-Staple
X-FL-QIT-DEBUG
X-Aicache-OS
X-Via-CDN
X-Air-Pt
X-From
X-ND-Cache
X-Servedbyhost
X-RCS-CacheZone
X-Up
Memory
Time
X-VC
X-Trace-ID
X-Via-Edge
X-Via-SSL
Edge-Copy-Time
SID
X-Cache-Enabled
Svr
X-NewRelic-App-Data
X-Vcl-Version
X-Generated-In
X-Dc
NtCoent-Length
X-AIR-PT
X-Cached-By
X-DataCenter
X-Nc
X-HS-Status
X-Srv
X-Webkit-CSP
Cache
X-Via-Popn
X-Via-Poph
X-Wa
X-Edge-Pop
X-Via-Popv
X-Lambda-Id
X-Debug-Cache-Store
X-Debug-Cache-Fetch
Sid
Cdn
X-HA-Backend
X-Vc
X-Esi
X-Vgn-Hpd-Cached
X-Vgn-Hpd-Variations-Key
X-Vgn-Hpd-Ssi
X-Cs
X-ZONE
X-Correlation-ID
X-CCDN-CacheTTL
CPC-Cache
VNS-Age
CPC-Age
VNS-Cache
X-Hcs-Proxy-Type
X-Render-Time
X-CCDN-Origin-Time
X-Vtex-Remote-Cache
X-Client-Ip
Server-ID
X-NGINX-Cache
X-Check-Cacheable
X-VCT
Cdnsip
Fastly-Drupal-Html
X-LB-ID
Hostname
GeoIp-Country-Code
X-AK-Request-ID
Cdncip
X-API-Version
X-Gateway-Cache-Status
X-Via-NSCOPI
X-Gateway-Request-Id
X-Gateway-Cache-Key
X-Amz-Meta-Cb-Modifiedtime
X-TH-Server
X-Fpc
AMP-Access-Control-Allow-Source-Origin
X-Gateway-Skip-Cache
X-Upstream-Ct
X-Upstream-Ht
X-Via-JSL
X-Proxy-CacheRZ
XkeyRZ
X-ATG-Version
True-Client-IP
X-Cache-Type
X-B3-SpanId
X-CSRF-TOKEN
X-Varnish-Authentication
X-Contensis-Viewer-Groups
X-Cache-ASPX
X-Nf-Request-Id
Uri
X-EC-Lua
X-CS
Eomportal-Instance
Esi-Enabled
True-Client-Ip
M-TraceId
X-Varnish-Beresp-TTL
X-MSEdge-Flight
X-RateLimit-Remaining-Second
X-Micro-Cache
X-MSEdge-Features
Resin-Trace
X-RateLimit-Limit-Second
Ngx-Var-Key
X-PAYTM-SRV-ID
X-CF-Lambda-Fn
X-CF-Lambda-Version
XServer
OT-Force-Account-Verify
Srv
X-Udemy-Cache-App-Namespace
Path
X-FPC
X-MP-GENERATED-AT
Request-ID
YJS-ID
GeoIP-Country-Code
X-SIPLIST1
X-APP-VERSION
CDN
X-Request-URI
X-Wikidot-Static-Cache
X-Fastly-Country-Code
N-Cache
X-Cache-NGX
X-Wikidot-Backend
IsBot
X-RateLimit-Reset
X-Tenant
X-VCL-Version
X-Lb-Id
X-Bl-Debug
RNT-Machine
X-CDN-Cache-Status
RNT-Time
X-Info
X-Orig-Expires
X-Shop-Environment
X-Datadome
X-Forwarded-Path
X-CLOUD-TRACE-CONTEXT
X-Webkit-Csp-Report-Only
X-Accel-Version
X-Service-Response-Time
LB
Server-Id
Sm-Log-Id
X-TX-ID
Location
X-B3-Trace-ID
X-Policy
X-Ha-Backend
X-Edge-POP
X-App-Name
X-MCACHE
X-Pod-Name
HIT
X-Cdn-Cache-Status
X-Datacenter
X-WA
Lb
Cross-Origin-Opener-Policy-Report-Only
X-Akamai-Pragma-Client-IP
Ohc-File-Size
X-Cdn-Request-ID
X-Oss-Hash-Crc64ecma
X-SERVER-NAME
X-Via-PopV
X-Via-PopN
X-Oss-Storage-Class
X-Snapshot-Date
X-Via-PopH
X-Cache-Expires
X-Github-Request-Id
Servername
X-Oss-Request-Id
X-Oss-Object-Type
X-Oss-Server-Time
X-Geo
X-Cache-Ttl
Timeexpire
Hit
FSS-Cache
X-NC
X-Srcache-Store-Status
X-CACHE-KEY
X-Srcache-Fetch-Status
Req-ID
Proxy-Connection
X-Logging-Id
X-Cdn-Diag
X-ServedByHost
Pramga
X-Vcache
X-LiteSpeed-Cache-Control
Epwk-X-Cache
Yjs-Id
ENV
X-Ctl-Mach
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
Traceparent
X-Hyper-Cache
X-Amz-Meta-Opti
X-TraceId
X-Cdn-Forward
X-Scheme
X-Dw-Trace-Id
Geoip-Latitude
X-Serial
X-Moov-Xdn-Version
X-Moov-T
X-UP
WZWS-RAY
X-Container-Uri
X-MiniProfiler-Ids
X-M-Log
X-Git-Commit
X-M-Reqid
X-Fastly-Backend-Reqs
Cneonction
X-Qnm-Cache
X-Acquia-Application-Trace
X-Tncms
X-B3-Parentspanid
XM
X-VG-WebCache
X-PERF
X-Acquia-Application-UUID
X-Acquia-Purge-Tags
X-Lb-Nocache
Ec-Rule-Version
X-RAMCache
X-Viewer-Country
X-Swift-Error
X-Acquia-Site
Content-Style-Type
Content-Script-Type
X-ApacheServer
CountryCode
X-F-Status
X-Wp-Cf-Super-Cache
X-Wp-Cf-Super-Cache-Cache-Control
X-TT-LOGID
X-Lsadc-Cache
X-UA
X-Mg-Cache
X-Litespeed-Cache-Control
X-Request-URL
X-Mid-Debug-Cache-Key
X-MG-Cache
X-Iauth-Set-Uid
Ohc-Cache-HIT
Ngx
X-Mid-Debug-Cache-Disk
X-B3-ParentSpanId
MIME-Version
Inserted-Into-Cache-At
X-Cache-Ngx
Warning
My-App
X-Fastly-Cache-Hits
X-Th-Server
X-Webstats-RespID
X-IPS-Cached-Response
X-LiteSpeed-Tag