Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
Strict-Transport-Security
X-Frame-Options
X-Content-Type-Options
Last-Modified
Link
CF-Cache-Status
Cf-Request-Id
Accept-Ranges
ETag
CF-RAY
Expect-CT
Pragma
X-Powered-By
X-Cache
Via
Age
X-XSS-Protection
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Xss-Protection
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-FRAME-OPTIONS
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Request-Id
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-Adblock-Key
X-AspNet-Version
X-Permitted-Cross-Domain-Policies
Alt-Svc
X-Runtime
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Check
X-DNS-Prefetch-Control
X-Cache-Status
X-Generator
CF-Ray
X-Cacheable
X-Request-ID
X-Iinfo
Timing-Allow-Origin
X-Envoy-Upstream-Service-Time
Feature-Policy
X-Ua-Compatible
X-Content-Security-Policy
Status
X-Drupal-Dynamic-Cache
Content-Encoding
X-AspNetMvc-Version
Access-Control-Expose-Headers
X-CDN
Upgrade
X-XSS-PROTECTION
P3p
Access-Control-Max-Age
X-Via
X-Dns-Prefetch-Control
X-Robots-Tag
X-Cache-Group
Server-Timing
X-UA-Device
Request-Context
Keep-Alive
X-Amz-Request-Id
X-AH-Environment
X-Proxy-Cache
X-Turbo-Charged-By
X-Backend
X-Amz-Id-2
X-Age
X-Ws-Request-Id
Host-Header
X-Server-Powered-By
X-Hacker
X-Server
X-Rq
X-Vhost
X-Varnish-Cache
EagleId
Grace
X-Amz-Version-Id
X-Dispatcher
Cf-Edge-Cache
X-LiteSpeed-Cache
Allow
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Device
X-Swift-CacheTime
X-Swift-SaveTime
X-Page-Speed
X-Nginx-Cache-Status
Ali-Swift-Global-Savetime
X-Akamai-Path-Stats
X-WebKit-CSP
X-Aws-Lambda-Call-Status
Accept-CH
X-Host
X-Node
X-Pingback
Cf-Railgun
X-OneAgent-JS-Injection
X-Server-Id
X-Cache-Spec
Surrogate-Control
X-Akam-SW-Version
X-Backend-Server
Request-Id
EagleEye-TraceId
X-Response-Time
X-Cache-Lookup
X-Readtime
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Content-Location
X-HW
Accept-CH-Lifetime
X-Content-Security-Policy-Report-Only
X-Application-Context
Rating
X-Trace
X-Cloud-Trace-Context
Fastly-Restarts
X-Country
X-Url
Accept-Ch-Lifetime
X-WebKit-CSP-Report-Only
X-Clacks-Overhead
X-Nginx-Upstream-Cache-Status
X-MS-InvokeApp
X-Amz-Server-Side-Encryption
X-Edge
Edge-Control
X-Rack-Cache
X-Ruxit-JS-Agent
X-PC
X-TtlSet
X-Vname
X-B3-TraceId
X-Oneagent-Js-Injection
X-ESI
X-Mod-Pagespeed
X-Content-Type
X-Vcap-Request-Id
X-CST
X-Kinja-Build
X-GoogleNews-Bot
X-Kinja
X-Cdn-Fetch
Verso
Xkey
X-Exp-Id
X-Exp-Variant
X-Use-Magma
X-Kinja-Server
X-Kinja-Revision
X-GitHub-Request-Id
X-Mcache
X-Amz-Rid
Cache-Tag
X-Powered-By-Plesk
X-D2id
RTSS
X-VARITI-CCR
Service-Worker-Allowed
X-ECACHE
X-Version
X-Ruxit-Js-Agent
X-Varnish-TTL
X-Upstream
X-Abt-Application-Version
X-Cached
X-FastCGI-Cache
X-Client-IP
X-Navigation-Version
X-Ac
X-Cnection
X-Ttl
X-Dw-Request-Base-Id
SPRequestGuid
X-Server-Name
X-SharePointHealthScore
X-Px
Arr-Disable-Session-Affinity
X-Element-Page-Cache
X-Instrumentation
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
SPRequestDuration
SPIisLatency
Permissions-Policy
Public-Key-Pins
X-Country-Code
Pagespeed
X-Sol
Display
X-Middleton-Display
X-Cache-TTL
X-NWS-LOG-UUID
X-Ser
Cf-Apo-Via
X-Middleton-Response
Response
X-Midtier
X-Kinsta-Cache
X-Goog-Hash
X-Edge-Location-Klb
X-Cache-Key
X-SRCache-Store-Status
X-Forwarded-For
X-SRCache-Fetch-Status
Content-MD5
X-Correlation-Id
Access-Control-Request-Method
Front-End-Https
Accept-Ch
X-Shield-Request-Id
X-RateLimit-Remaining
X-NF-Request-ID
X-DataDome
X-HP-Webp
MicrosoftSharePointTeamServices
X-HP-Trace-Id
TP-L2-Cache
X-MSEdge-Ref
TP-Cache
X-Jurisdiction
AR-SID
AR-ATIME
AR-CACHE
AR-Request-ID
AR-PoweredBy
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
Edge-Cache-Tag
X-Recruiting
X-T
X-Accel-Expires
Nginx-Cache
X-Powered-CMS
X-Daa-Tunnel
X-Litespeed-Cache
TCN
X-Mg-S
X-Grace
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
X-Content-Digest
X-Id
X-TEC-API-ROOT
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-Hits
Server-Node
Server-Name
X-XRDS-Location
X-RateLimit-Limit
X-HS-Combine-CSS
X-HS-Content-Id
X-HS-Cache-Config
X-HS-Hub-Id
X-Request-Processing-Time
X-Request-Received
Filters
X-Amzn-Trace-Id
MS-Author-Via
X-Frontend
X-Fastcgi-Cache
X-Geo-Country
X-Erf-Bev-Bev-Is-Generated
X-Browser-Type
X-Erf-Bev-Bev
X-Distributor
Fastcgi-Cache
S
X-Protected-By
X-PressLabs-Stats
X-Webkit-Csp
Count-Hit
X-LLID
X-Language
Cache-Status
X-Origin-Server
Filterid
X-Ezoic-Cdn
Cross-Origin-Opener-Policy
X-LB-Cache
X-Forwarded-Proto
X-F-Cache
X-Ua-Browser
X-Ab
Payment
X-Microsite
X-B3-Sampled
X-Request-Handler-Origin-Region
X-Page-Id
X-Seen-By
X-Amz-Meta-S3cmd-Attrs
X-FB-Debug
Charset
Host
X-Git-Hash
X-Fastly-Request-Id
X-Ratelimit-Reset
X-VCache
X-Cluster-Name
X-ASPNET-VERSION
Surrogate-Key
X-Cache-Age
X-Rid
Realpath
Accept-Charset
Cache-Tags
Access-Control-Allow-Method
X-Www-Served-By
X-NGENIX-Cache
Alternate-Protocol
X-Template
X-Upgrade-Enabled
X-DIS-Request-ID
X-Origin-Cache
X-Source
X-Logged-In
Retry-After
Cleartype
X-Route-Name
X-Providence-Cookie
X-Signature
X-TT
X-Wix-Request-Id
X-Fastly-Request-ID
X-Is-Crawler
X-Tb
X-Request-Guid
X-Aspnet-Duration-Ms
X-B-Cache
X-Flags
X-Envoy-Decorator-Operation
X-TTL
X-B
X-Varnish-Grace
X-Amz-Replication-Status
X-Type
ServerID
X-App-Environment
X-Varnish-Backend
X-AppVersion
X-Activity-Id
X-Az
Paypal-Debug-Id
DC
X-DynaTrace
X-Hostname
X-Node-Name
Frame-Options
X-Revision
X-Drupal-Cache-Tags
X-Ratelimit-Remaining
X-Contextid
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Debug
X-Proxy
X-Goog-Generation
X-Pinterest-Rid
Pinterest-Version
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-Cache-Rule
X-GUploader-UploadID
X-Goog-Stored-Content-Length
Pinterest-Generated-By
X-Goog-Storage-Class
X-Oracle-Dms-Ecid
X-Kong-Proxy-Latency
Amp-Access-Control-Allow-Source-Origin
X-Kong-Upstream-Latency
X-Oracle-Dms-Rid
X-Content-Options
X-Mobile
X-Load-Cache
Refresh
X-Cache-Control
Node
X-Magnolia-Registration
Country
X-N
X-EdgeConnect-Cache-Status
X-Original-Request-Id
NGB
X-Response-Served-From
X-User-Agent
X-Whom
X-Environment-Context
Viewport
X-L-Path
X-Cache-TTL-Remaining
Access-Control-Request-Headers
X-Is-Bot
VIX-Pulpo-Upstream-Status
X-Cacheable-TTL
X-Framework
X-Rendered-As
X-Page-View
Referer-Policy
X-Yottaa-Optimizations
X-Akamai-Request-ID2
X-Cache-Grace
X-Servername
X-G
X-Adobe-Loc
X-Adobe-Content
X-Yottaa-Metrics
VIX-Pulpo-Node
Url
Uber-Trace-Id
X-Varnish-Server
X-NYM-Debug-Backend
X-Debug-IsConnected
X-Real-IP
X-Mid
X-Content-Powered-By
X-Instance
X-Status
X-Debug-IsPreview
X-Varnish-Age
X-Cache-Time
X-Jobs
Content-Disposition
Srv
Akamai-GRN
X-Unique-Id
X-Time
Countrycode
X-Ratelimit-Limit
X-Content
X-ProcessESI
X-RemovedCookies
X-Drupal-Cache-Contexts
X-COUNTRY
Version
Cross-Origin-Resource-Policy
X-Mg-Request-UUID
X-Via-JSL
Accept-Language
X-Cache-Expired-At
X-CDN-Forward
X-Cache-Hit
X-Http-Reason
X-XRDS-LOCATION
X-App-Server
X-APP-VERSION
X-Cache-Operation
Healthy
X-Tumblr-User
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Tumblr-Pixel-1
X-Restarts
Protected
X-IPLB-Request-ID
X-Hosted-By
X-Backend-Name
X-IPLB-Instance
X-Debug-Info
X-Azure-Ref
X-Trace-Id
X-Akamai-Edgescape
Content-Secure-Policy
Section-Io-Cache
X-Tt-Logid
X-SRV
X-Device-Type
X-Cache-Action
Backend
Liferay-Portal
X-Nginx-Cache-Key
X-Rule
Server-Info
X-FW-Static
X-FW-Server
X-VC-Cache
X-Server-ID
GEO-INFO
X-FW-Serve
X-FW-Type
X-FW-Hash
X-FW-Dynamic
X-UPSTREAM-Address
X-RN-RSRV
X-Generation-Time
Meta-Geo
X-Mobile-URL
X-Storage
Load-Balancing
X-Proxy-Cache-Status
X-Api-Version
Fastcgi-Useragent
X-Varnish-Ttl
X-Mode
X-HTML-Minification-Powered-By
MS-CV
X-Content-Age
X-RTag
Ms-Operation-Id
X-SaId
X-Varnish-Beresp-Grace
X-LJ-Flow-ID
X-Forwarded-Host
X-JoinUs
Xserver
X-Generated-By
X-Say-TTL
X-VWS-Id
X-Edge-Location
X-PHP-Host
X-Labrador-Cache-Channel
X-Say-Cacheable
CDN-Cache
Web-Mar-Node
X-Sql-Duration-Ms
X-Alternate-Cache-Key
X-AWS-Id
CF-IPCountry
X-Region
X-Adobe-Source
X-Sql-Count
X-ShopId
X-ShardId
X-Shopify-Stage
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
Locale
CDN-Uid
X-Urbn-Context-Path
CDN-PullZone
CDN-RequestCountryCode
CDN-RequestId
CDN-CachedAt
X-Cache-Host
X-SayCDN-TTL
CDN-EdgeStorageId
X-Urbn-Site-Id
Azure-Version
Azure-SlotName
Azure-InstanceId
X-GeoCode
Azure-RegionName
Apigw-Requestid
X-Cache-Type
X-Access
X-Extlb
X-Detected-As
Azure-SiteName
X-Format
X-BYPASS-REASON
X-ProxyCache-Key
X-ServerID
X-Routing-Service
X-No-Session
X-UA-Device-Type
X-ProxyCache-Status
X-Storefront-Renderer-Rendered
X-Varnish-Hostname
X-Skip-Cache
X-Site-Version
X-Redis-Cache
X-Ms-Request-Id
X-Ms-Version
X-GeoCountry
X-Zipkin-Id
X-Web-Node
X-Xfnlog-Site
X-Proxied
X-Handled-By
X-Section
X-Tid
TWC-Locale-Group
X-Timing-Wait
TWC-GeoIP-LatLong
X-Request-Time
Webcakes-App-Name
X-Cms-Context
X-Cache-Server
TWC-Privacy
Webcakes-App-Version
X-R9-Blue-Green-Version
X-Varnish-Cache-Hits
X-Locale
X-Proxy-Build
X-Origin-Hint
X-FireWall-Port
Eomportal-Instance
X-OCL
X-PCL
TWC-GeoIP-Country
X-Varnishpool
S-Rt
X-Proto
X-Uri
X-PHP-Backend
X-Cache-Enabled
Webcakes-Region
Property-Id
TWC-Device-Class
Mn-Server-Ip
Selected-Fe
X-Cache-NGX
TWC-Connection-Speed
X-URL
X-Server-W
Cache-Name
X-Nginx-Cache
X-Hl-Ver
WP-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
X-Datadome
DB-Nickname
X-FB-TRIP-ID
X-Via-Fastly
Onion-Location
X-Origin-Date
X-Cache-Status-Check
X-Amz-Apigw-Id
X-Amzn-RequestId
X-UUID
X-ECache
X-TNCMS
X-LSADC-Cache
X-Loop
X-App-Version
ServedBy
X-DynaTrace-JS-Agent
X-Pubstack
X-Zen-Fury
X-Reqid
X-Human
X-Vgn-Hpd-Reason
Xet-Cookie
X-B3-Traceid
X-Provided-By
Source
X-GEO
X-RCS-CacheZone
X-Ua
X-Soup
Cache
X-Cache-Tags
X-Correlation-ID
Origin
X-Aspnetmvc-Version
X-Origin-TTL
X-TA-CDN-Provider
X-Amzn-Remapped-Content-Length
X-Origin-CC
X-Cdn
X-Cached-By
X-Varnish-Hits
X-Dc
Cross-Origin-Window-Policy
X-MP-GENERATED-AT
X-Tumblr-Pixel-2
X-Webkit-CSP
From-Origin
X-Debug-Cache
X-Service
SD-X-WS
X-Varnish-Beresp-Ttl
X-Trace-ID
WPO-Cache-Message
WPO-Cache-Status
Webserver
X-Newrelic-Synthetics
LB
X-NewRelic-App-Data
Rip
X-Tec-Api-Version
X-Tec-Api-Origin
X-Tec-Api-Root
X-Cache-Debug
X-IPS-LoggedIn
X-AOL-HN
X-Request-Host
Xc-Version
CPC-Cache
X-VG-WebCache
X-S-Cookie
X-S
X-Rojux
X-Processor
X-Rewrite-Enabled
DCR-Processing-Time-Ms
X-Vdms-Version
DCR-Decision-By
CPC-Age
X-Tenant
X-ScT
X-Shop-Environment
A
X-SRCache-Key
BehaviorPad-Version
X-TIM-N
X-Vdms-Path
X-User
Cdnsip
Cdncip
X-PBS-Appsvrname
Ngx.Var.Host
X-NAPM-TraceId
X-Forwarded-Path
X-External-Request-Id
X-Application
X-AK-Request-ID
X-A-Dgt
X-A-Wwc
X-Aed
X-ARC
X-Ec-GeoHdr
X-BCube-Filmed-By
X-Destination
X-Connection-Hash
X-Bc-Bl
X-Developer
X-B-Cookie
X-Ec-Fail
X-A-Dcw
X-A-Dam
MD5-Digest
Meta-Geo-Continent
X-D
X-Orig-Expires
Lang
Expiry
X-Parent-Response-Time
Odigeo-Trace-Id
Rendered-Blocks
VNS-Cache
X-A
X-A-Ccd
VNS-Age
T-Server
Sslversion
Surrogated-Key
Environment
X-Cache-NE
HostName
X-CSRF-Token
X-Platform-Server
X-Aicache-OS
X-FW-Version
X-Cluster
X-Served-From
Host-ID
X-Dispatcher-Number
X-Owner
Redirect-Candidate
X-Accel-Buffering
Fastly-Drupal-HTML
X-TIME
X-Cluster-Node
OT-Force-Account-Verify
X-VC
X-WP-CF-Super-Cache-Active
Upgrade-Insecure-Requests
Mime-Version
X-CGP
X-Cdn-Origin
X-Clara-WADP
X-Csrf-Jwt
X-Epic-Correlation-Id
X-Ec-Custom-Error
X-Esi-Check
X-Eu-Site
X-Fmm-Version
X-DPWN-IS-SECURE
X-DefElseHash
X-CacheTTL
X-Core-Mission
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
X-Datadog-Trace-Id
X-Clientip
X-BBC-Edge-Cache-Status
X-Via-NSCOPI
State
Traceparent
Tube-Get-Contents
Servername
Req-Svc-Chain
Origin-EX
Platform
Producers
Release
Tube-Got-Eval
Tube-Got-Results
X-Forwarded-Site
X-Bip
X-Cache-Bucket
X-Cache-Id
X-Ad-Defer-Variation
Web-Mar-Region
Tube-Return
V-Age
Vix-Hermes-Req-Id
We-Hiring
X-Cache-Info
X-Hash
X-Slack-Backend
X-SIPLIST1
X-Sn-Servicetimems
X-SplitTest
X-SVT-ORM-RULES
X-Sigma-Backend
X-Sigma
X-Request-URI
X-Rocket-Build-Number
X-Scale
X-B3-SpanId
X-SVT-ORM-VERSION
X-Thanos
X-Viewer-Country
X-VServer
X-WADP-Cache
X-Wix-Viewer-Type
X-VG-TLSProxy
X-Varnish-Remaining-TTL
X-Variation
X-Varnish-Beresp-Status
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
Origin-CC
X-Irp-Debug
X-Loc
X-Minions-Version
X-Gzip
X-GeoIP-City
X-Gateway-Cache-Status
X-Gateway-Request-Id
X-Gateway-Skip-Cache
X-GeoIP
X-Mvc-Supplant-Cachable
X-NodeID
X-Policy
X-Pool
X-Proxy-Cache-Info
X-Qloud-Router
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-Optimistic-Header
X-Origin
X-Origin-Response-Time
X-Planisys-CDN-Cache
X-Gateway-Cache-Key
X-DefHash
Click-Count-Action-Start
Click-Count-Error
Cmsid
Cmstype
Candidate-Md5Url
Is-Eu
L5d-Success-Class
L
Kp-EeAlive
IsBot
Country-Code
HA-Ipaddr
Fastly-GeoIP-CountryCode
Fastly-SIE
Fastly-SSL
Fastly-SWR
DSUID
Decoy-Debug-TTL
Ha-Gx-Prefs
Decoy-Debug-Key
Decoy-Debug-Status
Machine
Cache-Host
NM-Fastcgi-Cache
Mobile-Detection-Method
Adler-Geo
NGX
Apple-News-Services-Handled
Mail-Subject
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
X-Tx-Id
X-GG-Cache-Date
Cluster
Datacenter
Memcached
X-Device-Os
X-Developers
X-Cdn-Srv
X-Gamma-Serve
X-FC-Vary-Parameters
X-Fastly-Backend
X-Ckpd-Fst-Backend
X-ATG-Version
X-Fetched-On
Canary
X-Var-Ttl
X-Has-Esi
X-Branch-Name
X-INCAP-ABP
X-Hnp-Log
X-Gen-Mode
CDCHOST
X-Rocket-Nginx-Serving-Static
X-V-Cache
X-Is-Gdpr
X-S-Maxage
X-SB
X-Region-Sid
X-JWT-State
Wxu-Next-Region
Server-Hostname
Gh-Request-Id
X-Nf-Request-Id
X-Auto-Login
Sever-Int
Server-Ext
Wxu-Next-Hostname
User-Cache-Control
Wxu-Next-Commit
X-Block-Status
X-Cache-Remote
X-Level-Front-Cache
X-Azure-Ref-OriginShield
X-Sucuri-Cache
X-Sucuri-ID
X-Worker
X-Mvc-Supplant-OutputCached
X-HS-Content-Campaign-Id
X-Origin-Time
Svr
X-Nyt-Route
X-LB-NoCache
X-Scheme
Thinkindot-Control
Thinkindot-CacheControl-Type
X-CMSURLCustom
X-Core-Value
X-Geo-Header
X-Generated-On
X-Gdpr
CloudFront-Viewer-Country
Thinkindot-CacheControl
Fastly-Backend-Name
X-Thinkindot-L3
TDXMobile
X-NCache
Server-Host
X-WA-Info
X-Newrelic-App-Data
Cache-Tv-Group
X-ND-Cache
X-Udemy-Cache-App-Namespace
Pics-Label
AKAMAI
Cache-Hits
WebServer
Ec-Rule-Version
X-Tb-Optimization-Total-Bytes-Saved
Ssr
X-ZONE
SID
Time
Memory
Fastcgi-Cache-TTL
X-Generated-In
X-Via-Popv
X-Via-Poph
X-Origin-Expires
X-Via-Popn
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-Session-Fingerprint
X-Fastly-Cache
Sid
X-DC
X-Up
X-Refresh
X-Servedbyhost
Server-ID
Request-ID
X-Pod-Name
Env
AMP-Access-Control-Allow-Source-Origin
X-Pass-Why
X-Presslabs-Stats
X-Wa
My-App
X-Dispatch
X-Fpc
X-Akamai-Transformed
X-Tumblr-Pixel-3
X-Release
X-Cs
X-Edge-Pop
X-Lambda-Id
X-Ig-Push-State
X-Cache-Date
X-Buckets
X-Zone
X-MSEdge-Flight
X-NWS-UUID-VERIFY
X-MSEdge-Features
X-Conf
X-Esi
X-NC
X-PX
X-EC-Lua
X-ID
X-MCACHE
X-CS
X-Req
X-VCL-Version
X-Microcachable
CDN
X-CACHE-AGE
GeoIp-Country-Code
X-Dmc
X-Xrds-Location
X-Endurance-Cache-Level
X-LB-ID
X-TX-ID
X-B3-Spanid
True-Client-Country-4JS
True-Client-IP
X-Webkit-CSP-Report-Only
X-NGINX-Cache
Fastly-Drupal-Html
CacheControlHeader
Magicmarker
X-Be
X-Vc
X-CACHE-KEY
X-RateLimit-Reset
X-CSRF-TOKEN
Hostname
X-Wikidot-Static-Cache
X-Wikidot-Backend
X-HS-Status
X-TH-Server
X-Op-Id-All
X-TRACE-ID
Path
True-Client-Ip
Resin-Trace
X-GeoIP-Region-Code
X-GeoIP-Country-Code
GeoIP-Country-Code
X-Hyper-Cache
X-Srv
X-Alfa-Service
X-M-Reqid
X-CF-Lambda-Fn
X-M-Log
Tcn
X-Date
X-Micro-Cache
X-CF-Lambda-Version
X-Vcl-Version
X-Check-Cacheable
WWW-Authenticate
X-Accel-Expires-Debug
X-Air-Source
X-Air-Trace-Id
X-Air-Hostname
X-Air-Pt
Tracecode
X-App
Pramga
X-Varnish-Beresp-TTL
X-Qnm-Cache
X-SERVER-NAME
X-LiteSpeed-Cache-Control
Section-Io-Id
X-Vercel-Cache
X-Vercel-Id
Section-Io-Origin-Status
X-Old-Content-Length
Section-Origin-Responded
Section-Io-Origin-Time-Seconds
X-Akamai-Pragma-Client-IP
C-Via
X-RAMCache
NtCoent-Length
Yjs-Id
X-CLOUD-TRACE-CONTEXT
X-Cache-Ttl
X-Datacenter
X-TrackingId
X-Edge-POP
Powered-By
N-Cache
X-FPC
Proxy-Connection
YJS-ID
X-Webkit-Csp-Report-Only
X-Mly-Id
On-Server
X-Via-CDN
X-Platform
Esi-Enabled
X-WA
Hit
X-Yandex-Sdch-Disable
Fastcgi-X-Cache-Version
X-Geo
X-PAYTM-SRV-ID
X-Platform-Processor
FSS-Cache
X-Platform-Cluster
X-Platform-Router
X-API-Version
Server-Id
X-Webstats-RespID
X-ServedByHost
X-UA
ENV
User-Agent
X-Lb-Id
X-Response-By
Lb
X-Dw-Trace-Id
X-Cdn-Forward
X-Via-PopV
Cdn
X-Director
X-Via-PopH
HIT
X-Location
X-Via-PopN
X-Node-Id
X-Vtex-Remote-Cache
GeoIP-Latitude
X-Vtex-Processado-Em
X-Edge-Origin-Shield-Bytes
X-Edge-Origin-Shield-Region
X-Client-Ip
X-AIR-PT
Geoip-Latitude
X-Traceid
X-Akamai-ERRuleID
X-Instance-Name
Locid
X-SD-PageType
X-Request-Start
X-Akamai-ERPolicy
X-LAGOON
Dnion-Transfer-Encoding
X-TT-LOGID
X-Li-Pop
Srvid
X-Server-IP
X-FORWARDED-FOR
X-Li-Fabric
X-LI-UUID
X-LI-Proto
X-FL-EDGE
X-Varnish-Authentication
X-Contensis-Viewer-Groups
X-From
X-CUA
X-Cache-ASPX
Sm-Log-Id
X-Service-Response-Time
Ohc-File-Size
X-DB
XServer
X-DataCenter
Swift-Performance
Uri
X-HA-Backend
X-RSL
X-RPS
X-DSS
X-DW
X-RPM
X-DI
Cache-Key
PICS-Label
X-CF-Powered-By
Location
X-Via-Ucdn
X-Render-Time
X-Request-Url
X-LiteSpeed-Tag
Nginx-CQVIP
X-Wp-Cf-Super-Cache
X-Wp-Cf-Super-Cache-Cache-Control
X-Litespeed-Cache-Control
M-TraceId
X-Cache-Backend
X-Cache-Expires
X-Test
X-Fastly-Cache-Hits
X-B3-ParentSpanId
X-Proxy-Upstream
Wpo-Cache-Status
Vha6-Origin
X-HostName
Server-Ttl
X-ApacheServer
Wpo-Cache-Message
DynaTrace
X-Lb-Nocache
X-Fastly-Backend-Reqs
X-Cdn-Request-ID
X-PERF
CountryCode
XkeyRZ
X-Proxy-CacheRZ
Wp-Super-Cache
X-Ips-Loggedin
X-Cache-Ngx
Warning
Cneonction
X-Mg-Cache
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
XM
X-Th-Server
X-Serial
WZWS-RAY
Fastcgi-Cache-Ttl
X-Moov-T
X-ElasticPress-Query
Req-ID
X-Proxy-Cache-Hk
X-HN
SRV
PFcat
X-VarnishDD-TTL
CF-Cached-On
X-Yottaa-OS
X-Moov-Xdn-Version