Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Accept-Ranges
Expect-CT
Pragma
X-Powered-By
X-XSS-Protection
CF-RAY
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-Xss-Protection
X-UA-Compatible
X-Served-By
X-Download-Options
CF-Ray
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Request-ID
Access-Control-Allow-Credentials
X-FRAME-OPTIONS
X-Request-Id
X-Permitted-Cross-Domain-Policies
X-AspNet-Version
Alt-Svc
X-Runtime
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Generator
X-Cache-Status
X-Cacheable
Timing-Allow-Origin
X-Iinfo
X-Envoy-Upstream-Service-Time
X-Content-Security-Policy
X-Drupal-Dynamic-Cache
Feature-Policy
Content-Encoding
Access-Control-Expose-Headers
Upgrade
Status
X-CDN
X-AspNetMvc-Version
P3p
Access-Control-Max-Age
X-Ua-Compatible
X-Via
Server-Timing
X-UA-Device
Request-Context
X-Robots-Tag
X-Turbo-Charged-By
X-Amz-Request-Id
X-Cache-Group
EagleId
X-Amz-Id-2
X-Backend
X-Proxy-Cache
Keep-Alive
X-AH-Environment
X-Server
X-Ws-Request-Id
X-Age
X-Dns-Prefetch-Control
Host-Header
X-Hacker
Cf-Edge-Cache
X-Vhost
X-Server-Powered-By
X-Rq
X-Varnish-Cache
X-Dispatcher
X-Amz-Version-Id
Allow
Grace
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-OneAgent-JS-Injection
X-LiteSpeed-Cache
X-WebKit-CSP
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Page-Speed
Cf-Apo-Via
X-Device
Accept-CH
Cf-Railgun
X-Aws-Lambda-Call-Status
X-Node
X-Pingback
X-Host
X-Ruxit-JS-Agent
EagleEye-TraceId
X-Nginx-Cache-Status
X-Server-Id
Surrogate-Control
X-Akam-SW-Version
X-Cache-Spec
Request-Id
X-Backend-Server
X-Readtime
X-Cache-Lookup
X-HW
X-Content-Security-Policy-Report-Only
X-Cloud-Trace-Context
Accept-Ch-Lifetime
X-Trace
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Application-Context
X-Response-Time
Fastly-Restarts
Permissions-Policy
X-Nginx-Upstream-Cache-Status
X-Mod-Pagespeed
X-Edge
X-WebKit-CSP-Report-Only
Accept-CH-Lifetime
X-Mcache
Content-Location
X-CST
X-Content-Type
X-Url
X-MS-InvokeApp
X-Litespeed-Cache
X-Clacks-Overhead
X-Country
Rating
X-Midtier
X-TtlSet
X-PC
X-Amz-Server-Side-Encryption
X-Vname
RTSS
Cache-Tag
X-ESI
X-Vcap-Request-Id
X-D2id
X-ECACHE
X-VARITI-CCR
Verso
Origin-Trial
X-Element-Page-Cache
X-Server-Name
X-Exp-Variant
X-Kinja-Build
X-Kinja
X-Kinja-Revision
X-Kinja-Server
X-Use-Magma
X-Exp-Id
X-GoogleNews-Bot
X-Cdn-Fetch
X-Rack-Cache
X-Ac
X-Ttl
X-Powered-By-Plesk
X-Cnection
Service-Worker-Allowed
X-Client-IP
X-B3-TraceId
SPRequestGuid
X-SharePointHealthScore
X-Amz-Rid
X-Navigation-Version
X-GitHub-Request-Id
Xkey
X-Abt-Application-Version
Edge-Control
X-Cache-TTL
X-NWS-LOG-UUID
SPIisLatency
SPRequestDuration
X-Varnish-TTL
X-Upstream
Arr-Disable-Session-Affinity
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-Browser-Type
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Instrumentation
X-Cached
X-Mg-S
X-Px
X-Dw-Request-Base-Id
X-Correlation-Id
X-Cache-Key
X-Middleton-Display
Display
Pagespeed
X-Sol
X-SRCache-Store-Status
X-SRCache-Fetch-Status
Access-Control-Request-Method
X-NF-Request-ID
Edge-Cache-Tag
Content-MD5
X-Forwarded-For
X-Goog-Hash
X-Country-Code
Front-End-Https
X-Webkit-Csp
X-Version
TCN
X-Powered-CMS
X-Id
X-FastCGI-Cache
Public-Key-Pins
X-RateLimit-Remaining
X-XRDS-Location
AR-CACHE
AR-Request-ID
AR-PoweredBy
AR-ATIME
AR-SID
X-HP-Trace-Id
X-Jurisdiction
X-HP-Webp
X-MSEdge-Ref
X-Recruiting
X-Content-Digest
X-T
Accept-Ch
X-Daa-Tunnel
X-Amzn-Trace-Id
X-Accel-Expires
X-Ser
Response
X-Middleton-Response
TP-L2-Cache
TP-Cache
X-Fastcgi-Cache
X-Shield-Request-Id
S
Nginx-Cache
X-Ratelimit-Limit
MicrosoftSharePointTeamServices
MRF-Tech
X-B3-TraceId-Primal
Mrf-Cache-Status
Cache-Status
X-HS-Combine-CSS
X-HS-Content-Id
X-HS-Hub-Id
X-HS-Cache-Config
Server-Node
X-Request-Received
X-Request-Processing-Time
Cache-Tags
X-Distributor
X-Hits
X-Edge-Location-Klb
X-Kinsta-Cache
X-LB-Cache
Fastcgi-Cache
Cross-Origin-Opener-Policy
Alternate-Protocol
X-Origin-Server
X-Ezoic-Cdn
X-Grace
X-Ua-Browser
Server-Name
X-Ratelimit-Remaining
X-DIS-Request-ID
X-DataDome
Filterid
X-Ratelimit-Reset
X-PressLabs-Stats
X-Geo-Country
X-Request-Handler-Origin-Region
X-Microsite
X-Protected-By
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-Frontend
X-Rid
Healthy
X-LLID
Payment
X-Varnish-Backend
X-Logged-In
X-Debug-Info
Cleartype
X-Git-Hash
X-Page-Id
X-Forwarded-Proto
X-FB-Debug
X-Www-Served-By
X-Hostname
X-Origin-Cache
X-Server-ID
X-Load-Cache
X-NGENIX-Cache
X-Fastly-Request-ID
X-Cluster-Name
DC
MS-Author-Via
Charset
Content-Disposition
X-ASPNET-VERSION
X-B3-Sampled
Realpath
Access-Control-Allow-Method
X-Goog-Metageneration
X-GUploader-UploadID
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-Upgrade-Enabled
X-Proxy
X-Kong-Upstream-Latency
X-F-Cache
X-Kong-Proxy-Latency
X-Activity-Id
X-AppVersion
X-Az
X-Seen-By
Retry-After
Cross-Origin-Resource-Policy
X-Amz-Replication-Status
X-Oracle-Dms-Rid
X-Type
X-Contextid
X-Amz-Meta-S3cmd-Attrs
X-Oracle-Dms-Ecid
Paypal-Debug-Id
X-Azure-Ref
X-Aspnet-Duration-Ms
Accept-Charset
X-Flags
X-Hosted-By
X-Route-Name
X-Is-Crawler
X-Revision
X-Request-Guid
X-Providence-Cookie
X-Whom
X-ECache
Viewport
Surrogate-Key
X-App-Environment
X-VCache
X-Signature
X-Wix-Request-Id
Count-Hit
X-Fb-Rlafr
X-B-Cache
X-Varnish-Server
X-B
X-TTL
X-TT
Amp-Access-Control-Allow-Source-Origin
X-Akamai-Edgescape
X-DynaTrace
X-Aspnetmvc-Version
X-Fastly-Request-Id
X-Cache-Age
X-Language
X-Source
X-B3-Traceid
X-App-Server
Referer-Policy
X-Cache-Control
X-RateLimit-Limit
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Mobile
X-Goog-Generation
X-Magnolia-Registration
Version
X-COUNTRY
X-Varnish-Grace
Host
X-Tt-Trace-Tag
X-Envoy-Decorator-Operation
X-Tt-Trace-Host
X-Times
X-N
X-HTML-Minification-Powered-By
X-Cache-Rule
X-Original-Request-Id
X-Response-Served-From
SRV
X-Rule
Section-Io-Cache
Access-Control-Request-Headers
X-RTag
X-Cache-Time
Ms-Operation-Id
MS-CV
X-Tumblr-Pixel-0
X-Tumblr-Pixel
WPO-Cache-Message
X-Tumblr-Pixel-1
WPO-Cache-Status
X-UUID
X-Varnish-Age
X-Tumblr-User
X-FW-Serve
X-FW-Hash
GEO-INFO
X-FW-Type
X-FW-Static
X-FW-Dynamic
Refresh
X-Cache-Grace
X-FW-Version
X-Cache-Expired-At
X-Backend-Name
Akamai-GRN
X-Framework
X-FW-Server
X-User-Agent
X-Page-View
X-EdgeConnect-Cache-Status
X-Status
X-Cache-Status-Check
X-Rendered-As
X-Cacheable-TTL
Protected
SD-X-WS
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Content-Powered-By
Url
X-Servername
X-Jobs
X-Device-Type
X-Is-Bot
X-Instance
X-G
X-Adobe-Loc
X-Drupal-Cache-Contexts
X-Adobe-Content
X-L-Path
X-Drupal-Cache-Tags
X-NYM-Debug-Backend
X-Akamai-Request-ID2
X-Http-Reason
X-Environment-Context
From-Origin
NGB
CDN-RequestId
X-Amz-Apigw-Id
X-Template
X-Amzn-RequestId
X-ProcessESI
X-RemovedCookies
X-Region
X-Trace-Id
X-CDN-Forward
Front
X-Debug-IsPreview
X-Debug-IsConnected
Accept-Language
X-Varnish-Ttl
X-Nginx-Cache
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Cache-Hit
X-Unique-Id
Backend
X-Content-Options
Fastly-SIE
Fastly-SWR
Country
X-Zen-Fury
X-Tb
Liferay-Portal
Pinterest-Generated-By
X-DynaTrace-JS-Agent
X-Air-Source
X-Pinterest-Rid
X-Air-Trace-Id
X-Air-Hostname
Pinterest-Version
X-Tt-Logid
X-Mode
Content-Secure-Policy
X-Cache-Operation
X-Tec-Api-Root
X-Tec-Api-Version
X-XRDS-LOCATION
X-Tec-Api-Origin
X-Real-IP
X-TIME
Filters
X-Rewrite-Enabled
Meta-Geo
X-Newrelic-App-Data
X-Generation-Time
X-UPSTREAM-Address
X-Node-Name
X-Proxy-Cache-Info
X-RN-RSRV
X-Amzn-Remapped-Content-Length
Webserver
X-Proxy-Build
X-VC-Cache
X-Access
X-Content-Age
Azure-InstanceId
X-Ms-Version
X-IPS-LoggedIn
X-Timing-Wait
X-Ms-Request-Id
Selected-Fe
Onion-Location
CF-IPCountry
Azure-Version
Azure-SlotName
X-Web-Node
X-Format
X-Cache-Server
Uber-Trace-Id
X-Section
Azure-SiteName
Azure-RegionName
Node
TWC-Locale-Group
TWC-Device-Class
TWC-Connection-Speed
ServedBy
Property-Id
Cache-Hits
TWC-GeoIP-Country
Webcakes-App-Version
Webcakes-App-Name
TWC-Privacy
TWC-GeoIP-LatLong
Webcakes-Region
X-Proto
X-Say-Cacheable
X-PHP-Backend
X-Sql-Duration-Ms
X-Say-TTL
X-SayCDN-TTL
X-Server-W
X-Origin-Hint
X-UA-Device-Type
X-Reqid
X-Rocket-Nginx-Serving-Static
X-Cluster-Node
X-Debug
X-Sql-Count
X-Soup
ServerID
X-Cluster
X-Sucuri-ID
X-Tumblr-Pixel-2
X-Sucuri-Cache
X-Handled-By
X-Locale
X-LJ-Flow-ID
X-IPLB-Request-ID
X-IPLB-Instance
S-Rt
X-Ua
X-ProxyCache-Key
X-PHP-Host
Web-Mar-Node
X-R9-Blue-Green-Version
X-Labrador-Cache-Channel
X-AWS-Id
X-Cache-TTL-Remaining
X-VWS-Id
X-Proxy-Cache-Status
X-Adobe-Source
X-Forwarded-Host
X-Varnish-Beresp-Grace
X-Cache-Host
X-ProxyCache-Status
X-BYPASS-REASON
DB-Nickname
Cache-Name
X-Cache-Action
X-WP-CF-Super-Cache-Cache-Control
X-Zipkin-Id
X-Skip-Cache
X-Site-Version
X-Cms-Context
X-Proxied
X-SaId
X-JoinUs
X-LAGOON
X-FB-TRIP-ID
X-Extlb
X-Detected-As
X-Edge-Location
Apigw-Requestid
X-WP-CF-Super-Cache
Cross-Origin-Window-Policy
X-Routing-Service
Mn-Server-Ip
X-Urbn-Site-Id
X-Optimistic-Header
X-Xfnlog-Site
WP-Super-Cache
X-Uri
X-Origin-Date
X-Time
Locale
X-Urbn-Context-Path
X-No-Session
Fastcgi-Useragent
X-Buckets
Countrycode
Mime-Version
X-Via-Fastly
X-Ruxit-Js-Agent
X-GeoCountry
X-GeoCode
X-Tumblr-Pixel-3
X-App-Version
Source
X-LSADC-Cache
X-ARC
CDN-CachedAt
Fastly-Drupal-HTML
CDN-EdgeStorageId
CDN-PullZone
CDN-RequestCountryCode
CDN-Cache
CDN-Uid
X-Director
Upgrade-Insecure-Requests
X-Oneagent-Js-Injection
X-Hl-Ver
X-Request-Time
X-GEO
X-Generated-By
Cache-Tv-Group
X-Varnish-Hits
X-Mg-Request-UUID
CF-Cached-On
X-Cache-Debug
X-Tx-Id
X-Redis-Cache
Xet-Cookie
X-Loop
X-SRV
Frame-Options
X-Origin-CC
X-Origin-TTL
X-FireWall-Port
X-Varnish-Cache-Hits
X-TNCMS
X-URL
X-Pass-Why
X-RM-Cache-TTL
X-Akamai-Transformed
X-Varnish-Hostname
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-ServerID
X-ShopId
X-Alternate-Cache-Key
X-ShardId
X-Shopify-Stage
X-Storefront-Renderer-Rendered
X-TA-CDN-Provider
X-Newrelic-Synthetics
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
X-Datadog-Sampled
X-Datadog-Parent-Id
Xserver
X-NWS-UUID-VERIFY
X-Pubstack
X-Api-Version
X-Request-Host
X-Endurance-Cache-Level
X-B3-Spanid
Load-Balancing
X-Varnish-Beresp-Ttl
X-CACHE-AGE
X-Service
X-Served-From
Gannett-Cam-Experience-Id
DCR-Processing-Time-Ms
DSUID
X-Developer
X-ScT
Host-ID
X-D
MD5-Digest
Lang
X-Test
X-Vdms-Version
X-Destination
DCR-Decision-By
X-CUA
Server-Info
X-TIM-N
BehaviorPad-Version
A
X-External-Request-Id
X-Vdms-Path
X-Ec-Fail
X-Ec-GeoHdr
X-Epic-Correlation-Id
Candidate-Md5Url
X-Thinkindot-L3
X-SRCache-Key
X-A-Dgt
X-A-Wwc
X-Aed
X-A-Dcw
X-A-Dam
WWW-Authenticate
X-A
X-A-Ccd
X-Sigma
X-Application
X-Cache-Date
X-Cache-Info
X-Cache-NE
X-BCube-Filmed-By
X-Bc-Bl
X-B-Cookie
X-BBC-Edge-Cache-Status
X-Sigma-Backend
Thinkindot-Control
Redirect-Candidate
Release
Rendered-Blocks
X-Processor
Origin
Ngx.Var.Host
Odigeo-Trace-Id
Req-Svc-Chain
Sslversion
TDXMobile
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
T-Server
X-CMSURLCustom
X-Conf
Surrogated-Key
Meta-Geo-Continent
Cache-Host
X-INCAP-ABP
X-S
Xc-Version
X-Mid
X-Loc
X-Rocket-Build-Number
X-Rojux
X-We-Are-Hiring
X-Origin-Time
X-Location
X-Gdpr
X-S-Cookie
X-Mobile-URL
X-Nyt-Route
X-Httpd
Section-Io-Id
X-Storage
X-Restarts
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
X-Worker
X-Platform-Router
X-Ec-Custom-Error
X-SVT-ORM-RULES
X-Level-Front-Cache
Cache-Key
CacheControlHeader
NM-Fastcgi-Cache
Country-Code
X-HS-Content-Campaign-Id
We-Hiring
Edge-Cache
X-SVT-ORM-VERSION
Gh-Request-Id
X-GeoIP-City
X-Clara-WADP
X-Origin-Response-Time
X-Origin
X-Is-Gdpr
X-JWT-State
X-GeoIP
X-Developers
Mail-Subject
Memcached
X-Generated-On
Magicmarker
X-Thanos
Fastly-GeoIP-CountryCode
Fastly-Backend-Name
X-WP-CF-Super-Cache-Active
X-Has-Esi
X-Varnishpool
X-Platform-Cluster
X-VG-TLSProxy
X-Mvc-Supplant-Cachable
X-Fmm-Version
X-Varnish-Beresp-Status
X-Auto-Login
Server-Host
X-Bip
X-Frame-Option
X-Vmg-Version
X-Core-Value
X-VServer
X-Sn-Servicetimems
X-Cdn-Origin
X-Cdn-Srv
X-Cache-Bucket
X-Human
C-Via
X-Var-Ttl
Apple-News-Services-Parsed-Url
X-WADP-Cache
Apple-News-Services-Host
X-Hash
Apple-News-Services-Handled
X-Akamai-Device-Characteristics
X-WA-Info
Apple-News-Services-Request-Url
X-S-Maxage
X-Core-Mission
X-Platform-Processor
X-Fetched-On
X-Parent-Response-Time
Sever-Int
X-Old-Content-Length
State
Server-Hostname
Server-Ext
X-Slack-Shared-Secret-Outcome
X-NodeID
Wxu-Next-Hostname
X-App
X-Men
X-Ad-Defer-Variation
X-Accel-Expires-Debug
X-Accel-Buffering
X-Azure-Ref-OriginShield
X-Block-Status
X-CacheTTL
X-Request-Start
X-Cache-Id
X-Server-IP
X-LB-NoCache
Wxu-Next-Region
Tube-Got-Eval
Tube-Got-Results
Tube-Get-Contents
X-Slack-Backend
X-Node-Id
Tube-Return
User-Cache-Control
Wxu-Next-Commit
X-Nginx-Cache-Key
Web-Mar-Region
Vix-Hermes-Req-Id
X-Irp-Debug
X-Date
AKAMAI
Cache-Provider
Adler-Geo
X-Esi-Check
X-Fastly-Backend
Canary
X-Hnp-Log
Click-Count-Error
CloudFront-Viewer-Country
Click-Count-Action-Start
X-Wix-Viewer-Type
CDCHOST
X-SD-PageType
X-FC-Vary-Parameters
X-Cache-Tags
X-Scale
X-Qloud-Router
X-Platform-Server
X-Pool
X-Forwarded-Site
X-Platform
X-Varnish-CookieHashed-On
X-Variation
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
X-VarnishDD-TTL
Datacenter
X-Gen-Mode
X-Gzip
X-Org
X-GeoIP-Region-Code
X-GeoIP-Country-Code
Kp-EeAlive
NGX
On-Server
PFcat
Platform
X-HN
Origin-EX
Origin-CC
X-Mly-Id
L
X-Geo-Header
Environment
X-DefElseHash
X-Dispatcher-Number
X-Device-Os
Is-Eu
X-DefHash
X-Tid
X-Gamma-Serve
X-Minions-Version
X-Planisys-CDN-TTL
X-Dispatcher-Server
X-Csrf-Jwt
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Nananana
X-DPWN-IS-SECURE
X-Eu-Site
X-CGP
X-Ckpd-Fst-Backend
X-SB
X-Req
X-Refresh
X-NCache
X-Region-Sid
X-Op-Id-All
Cmsid
Ha-Gx-Prefs
Fastly-SSL
HA-Ipaddr
L5d-Success-Class
Machine
Decoy-Debug-TTL
Decoy-Debug-Status
X-V-Cache
Cluster
Cmstype
Decoy-Debug-Key
Pics-Label
X-Cache-Remote
X-Fastly-Cache
X-Cache-Backend
X-CSRF-Token
Ssr
Producers
X-DC
X-Presslabs-Stats
X-Mvc-Supplant-OutputCached
X-Owner
X-Origin-Expires
X-Cache-FS-Status
X-NewRelic-App-Data
X-Webkit-CSP-Report-Only
X-Release
X-Aicache-OS
X-Microcachable
GeoIP-Latitude
Env
X-Response-By
X-Instance-Name
X-Tb-Optimization-Total-Bytes-Saved
X-Provided-By
X-Ah-Environment
X-Zone
HostName
Srvid
Expect-Staple
Locid
X-FL-QIT-DEBUG
X-Up
X-RCS-CacheZone
X-FL-EDGE
X-Servedbyhost
SID
X-Via-CDN
X-Air-Pt
Svr
Memory
X-ND-Cache
X-From
X-Generated-In
Time
X-AIR-PT
X-Via-SSL
Edge-Copy-Time
X-Trace-ID
X-Via-Edge
X-Nc
X-Cache-Enabled
X-VC
X-Vcl-Version
X-Cached-By
X-DataCenter
X-Dc
Cache
NtCoent-Length
X-Wa
X-Edge-Pop
X-Via-Poph
X-Via-Popv
X-Via-Popn
X-HS-Status
X-Webkit-CSP
X-Vc
X-Srv
Cdn
X-Debug-Cache-Store
X-Debug-Cache-Fetch
X-ZONE
X-HA-Backend
X-NGINX-Cache
X-Lambda-Id
Sid
Server-ID
X-Vgn-Hpd-Ssi
X-Vgn-Hpd-Cached
X-Esi
X-Vgn-Hpd-Variations-Key
X-Correlation-ID
X-Cs
Hostname
GeoIp-Country-Code
CPC-Cache
VNS-Cache
X-AK-Request-ID
VNS-Age
Cdncip
X-Vtex-Remote-Cache
X-CCDN-Origin-Time
X-CCDN-CacheTTL
X-Hcs-Proxy-Type
X-Render-Time
Cdnsip
X-Client-Ip
CPC-Age
X-Check-Cacheable
X-VCT
X-Via-NSCOPI
X-LB-ID
X-Amz-Meta-Cb-Modifiedtime
X-Gateway-Request-Id
X-Gateway-Cache-Status
X-Gateway-Cache-Key
X-Fpc
X-Gateway-Skip-Cache
X-Via-JSL
Fastly-Drupal-Html
X-CSRF-TOKEN
X-API-Version
X-TH-Server
True-Client-IP
AMP-Access-Control-Allow-Source-Origin
X-Upstream-Ht
X-Upstream-Ct
X-Proxy-CacheRZ
XkeyRZ
X-Cache-Type
X-ATG-Version
X-CS
X-B3-SpanId
X-Cache-ASPX
X-Nf-Request-Id
X-Varnish-Authentication
Uri
X-Contensis-Viewer-Groups
Eomportal-Instance
X-EC-Lua
M-TraceId
X-Micro-Cache
Esi-Enabled
True-Client-Ip
Ngx-Var-Key
OT-Force-Account-Verify
X-Varnish-Beresp-TTL
X-APP-VERSION
X-CF-Lambda-Fn
Resin-Trace
XServer
X-MSEdge-Features
X-CF-Lambda-Version
X-MSEdge-Flight
Srv
X-Cache-NGX
X-PAYTM-SRV-ID
Path
X-Fastly-Country-Code
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
IsBot
X-SIPLIST1
X-FPC
X-Request-URI
X-Udemy-Cache-App-Namespace
Request-ID
X-MP-GENERATED-AT
YJS-ID
GeoIP-Country-Code
X-Lb-Id
CDN
X-Info
N-Cache
X-VCL-Version
X-Wikidot-Static-Cache
X-Wikidot-Backend
X-Tenant
X-Forwarded-Path
X-Orig-Expires
X-CDN-Cache-Status
RNT-Time
X-CLOUD-TRACE-CONTEXT
X-Shop-Environment
RNT-Machine
X-RateLimit-Reset
X-Datadome
X-Bl-Debug
X-Accel-Version
Location
Server-Id
X-TX-ID
LB
Sm-Log-Id
X-B3-Trace-ID
X-Edge-POP
X-Service-Response-Time
X-MCACHE
X-Policy
X-App-Name
X-Pod-Name
X-Ha-Backend
X-Cdn-Request-ID
X-Oss-Object-Type
X-Oss-Server-Time
Servername
Cross-Origin-Opener-Policy-Report-Only
X-Oss-Request-Id
Lb
HIT
X-Datacenter
X-Oss-Hash-Crc64ecma
X-Cdn-Cache-Status
X-Oss-Storage-Class
X-Cache-Expires
X-WA
X-Akamai-Pragma-Client-IP
Ohc-File-Size
X-Via-PopN
X-Via-PopV
X-Via-PopH
X-SERVER-NAME
X-Snapshot-Date
X-Geo
X-Github-Request-Id
Timeexpire
Hit
X-CACHE-KEY
X-NC
X-Cache-Ttl
X-Srcache-Fetch-Status
FSS-Cache
X-Srcache-Store-Status
Req-ID
Epwk-X-Cache
X-Cdn-Diag
X-Ctl-Mach
Pramga
X-Vcache
X-LiteSpeed-Cache-Control
X-Logging-Id
X-TraceId
Yjs-Id
Proxy-Connection
Traceparent
X-ServedByHost
X-Moov-T
ENV
X-Moov-Xdn-Version
X-Scheme
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-Cdn-Forward
WZWS-RAY
X-Container-Uri
X-Amz-Meta-Opti
X-UP
X-Git-Commit
X-ApacheServer
X-Hyper-Cache
X-Viewer-Country
X-Serial
Geoip-Latitude
X-PERF
X-Dw-Trace-Id
X-M-Log
X-MiniProfiler-Ids
X-TRACE-ID
X-M-Reqid
X-Qnm-Cache
X-B3-Parentspanid
Ec-Rule-Version
X-Acquia-Application-Trace
X-Swift-Error
X-Acquia-Purge-Tags
X-VG-WebCache
XM
X-Tncms
X-RAMCache
X-Acquia-Site
X-Acquia-Application-UUID
X-Lb-Nocache
Cneonction
X-Fastly-Backend-Reqs
Content-Style-Type
Content-Script-Type
X-Lsadc-Cache
X-F-Status
X-Wp-Cf-Super-Cache-Cache-Control
X-TT-LOGID
CountryCode
X-Wp-Cf-Super-Cache
X-Litespeed-Cache-Control
Warning
X-NAPM-TraceId
X-Mg-Cache
X-Mid-Debug-Cache-Disk
X-Iauth-Set-Uid
Ohc-Cache-HIT
X-Mid-Debug-Cache-Key
X-IPS-Cached-Response
X-Cache-Ngx
MIME-Version
Ngx
My-App
Powered-By
X-B3-ParentSpanId
X-Request-URL
X-LiteSpeed-Tag
X-Th-Server
Inserted-Into-Cache-At
X-Fastly-Cache-Hits
X-Vgn-Hpd-Reason
X-Webstats-RespID