Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Accept-Ranges
X-XSS-Protection
Expect-CT
Pragma
X-Powered-By
X-Cache
CF-RAY
Via
Age
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
CF-Ray
X-Xss-Protection
X-Download-Options
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Request-Id
X-Adblock-Key
Access-Control-Allow-Credentials
X-FRAME-OPTIONS
X-Permitted-Cross-Domain-Policies
X-AspNet-Version
Alt-Svc
X-Request-ID
X-Runtime
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Generator
X-Cache-Status
X-Cacheable
Timing-Allow-Origin
X-Envoy-Upstream-Service-Time
X-Iinfo
X-Content-Security-Policy
X-Drupal-Dynamic-Cache
Feature-Policy
Content-Encoding
Access-Control-Expose-Headers
Upgrade
Status
X-CDN
X-AspNetMvc-Version
Access-Control-Max-Age
X-Via
X-UA-Device
Server-Timing
Request-Context
X-Robots-Tag
X-Turbo-Charged-By
X-Amz-Request-Id
X-Cache-Group
X-Amz-Id-2
EagleId
X-Backend
X-AH-Environment
P3p
X-Proxy-Cache
X-Dns-Prefetch-Control
Keep-Alive
X-Server
X-Ws-Request-Id
X-Age
Cf-Edge-Cache
Host-Header
X-Hacker
X-Vhost
X-Server-Powered-By
X-Rq
X-Varnish-Cache
X-Dispatcher
X-Amz-Version-Id
Grace
Allow
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-OneAgent-JS-Injection
X-LiteSpeed-Cache
X-Ua-Compatible
X-Page-Speed
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-WebKit-CSP
X-Device
Cf-Apo-Via
Cf-Railgun
Accept-CH
X-Aws-Lambda-Call-Status
X-Node
X-Pingback
X-Host
X-Ruxit-JS-Agent
EagleEye-TraceId
X-Server-Id
X-Nginx-Cache-Status
Surrogate-Control
X-Akam-SW-Version
X-Readtime
Request-Id
X-Backend-Server
X-Cache-Spec
X-Content-Security-Policy-Report-Only
X-Cache-Lookup
X-HW
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Accept-Ch-Lifetime
X-Cloud-Trace-Context
X-Application-Context
X-Trace
X-Response-Time
Permissions-Policy
X-Nginx-Upstream-Cache-Status
Fastly-Restarts
X-Litespeed-Cache
X-Edge
X-WebKit-CSP-Report-Only
X-Mod-Pagespeed
Accept-CH-Lifetime
X-Country
Content-Location
X-Mcache
X-MS-InvokeApp
X-Content-Type
X-Url
X-Clacks-Overhead
X-Vname
X-TtlSet
X-PC
X-CST
X-Amz-Server-Side-Encryption
X-Midtier
Rating
RTSS
Cache-Tag
X-ESI
X-Vcap-Request-Id
X-D2id
X-Rack-Cache
X-Element-Page-Cache
X-Exp-Id
Origin-Trial
X-Use-Magma
X-Exp-Variant
X-Cdn-Fetch
X-Kinja-Server
X-Kinja-Revision
X-GoogleNews-Bot
X-Kinja-Build
X-Kinja
Verso
X-VARITI-CCR
X-Server-Name
X-Ac
X-Powered-By-Plesk
Service-Worker-Allowed
X-Ttl
X-Cnection
X-ECACHE
X-Amz-Rid
SPRequestGuid
X-SharePointHealthScore
X-Client-IP
X-Navigation-Version
X-GitHub-Request-Id
Xkey
X-Abt-Application-Version
Edge-Control
SPIisLatency
SPRequestDuration
X-Upstream
X-Cache-TTL
Arr-Disable-Session-Affinity
X-B3-TraceId
X-Cached
X-Dw-Request-Base-Id
X-Mg-S
X-Instrumentation
X-NWS-LOG-UUID
X-Kraken-Loop-Name
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Server-Lifecycle-Phase
X-Browser-Type
X-Varnish-TTL
X-Px
Accept-Ch
X-FastCGI-Cache
Display
X-Sol
X-Middleton-Display
Pagespeed
X-Cache-Key
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-NF-Request-ID
Access-Control-Request-Method
X-Forwarded-For
Edge-Cache-Tag
X-Country-Code
X-Correlation-Id
X-Goog-Hash
X-Webkit-Csp
TCN
X-Id
X-Powered-CMS
Content-MD5
Front-End-Https
X-Ser
AR-ATIME
AR-CACHE
AR-PoweredBy
AR-Request-ID
AR-SID
Public-Key-Pins
X-RateLimit-Remaining
X-Version
X-Jurisdiction
X-HP-Webp
X-HP-Trace-Id
X-Content-Digest
X-MSEdge-Ref
X-Amzn-Trace-Id
X-Recruiting
X-T
X-Ratelimit-Limit
X-Middleton-Response
Response
X-Accel-Expires
TP-L2-Cache
TP-Cache
X-Shield-Request-Id
MicrosoftSharePointTeamServices
X-XRDS-Location
S
Nginx-Cache
Cache-Status
X-Daa-Tunnel
Server-Node
X-Request-Received
X-Request-Processing-Time
X-HS-Content-Id
X-HS-Combine-CSS
X-HS-Hub-Id
X-HS-Cache-Config
MRF-Tech
Cache-Tags
X-B3-TraceId-Primal
Mrf-Cache-Status
Cross-Origin-Opener-Policy
X-Fastcgi-Cache
X-Distributor
X-Hits
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
X-PressLabs-Stats
X-LB-Cache
X-Kinsta-Cache
X-Edge-Location-Klb
X-Origin-Server
X-Ratelimit-Remaining
X-Ua-Browser
X-Ezoic-Cdn
Alternate-Protocol
X-Fastly-Request-ID
Fastcgi-Cache
Filterid
X-Grace
X-Hostname
X-Ratelimit-Reset
X-Frontend
X-LLID
X-Request-Handler-Origin-Region
X-Microsite
Server-Name
X-ORACLE-DMS-ECID
X-Geo-Country
X-ORACLE-DMS-RID
X-Rid
X-DIS-Request-ID
X-FB-Debug
Healthy
X-Logged-In
X-Varnish-Backend
X-Git-Hash
X-Debug-Info
X-NGENIX-Cache
Payment
X-Www-Served-By
Cleartype
Realpath
X-Page-Id
X-Protected-By
X-Cluster-Name
X-Load-Cache
X-Forwarded-Proto
DC
MS-Author-Via
X-ASPNET-VERSION
X-ECache
X-DataDome
Content-Disposition
Access-Control-Allow-Method
X-Origin-Cache
Charset
X-B3-Sampled
X-GUploader-UploadID
X-Goog-Metageneration
X-Upgrade-Enabled
X-Kong-Proxy-Latency
X-Server-ID
X-Kong-Upstream-Latency
X-Proxy
X-AppVersion
X-Activity-Id
X-Az
X-Seen-By
X-F-Cache
Count-Hit
X-Cache-Age
X-B3-Traceid
X-Amz-Meta-S3cmd-Attrs
X-Amz-Replication-Status
X-TTL
X-Azure-Ref
Cross-Origin-Resource-Policy
X-Whom
X-Fb-Rlafr
Paypal-Debug-Id
X-Times
X-Revision
X-B
X-Type
X-Akamai-Edgescape
X-Contextid
Surrogate-Key
X-Request-Guid
X-Providence-Cookie
X-Route-Name
X-App-Environment
Viewport
Accept-Charset
Retry-After
X-Is-Crawler
X-Aspnetmvc-Version
X-Flags
X-Aspnet-Duration-Ms
X-Varnish-Server
X-TT
X-Wix-Request-Id
X-Hosted-By
X-Signature
X-B-Cache
X-Language
X-DynaTrace
Amp-Access-Control-Allow-Source-Origin
X-Cache-Control
X-Envoy-Decorator-Operation
X-Oracle-Dms-Rid
X-Source
X-Oracle-Dms-Ecid
X-App-Server
X-Magnolia-Registration
X-Mobile
X-Varnish-Grace
X-Goog-Stored-Content-Length
X-VCache
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
Host
Version
WPO-Cache-Message
WPO-Cache-Status
Referer-Policy
X-Fastly-Request-Id
X-N
X-Cache-Rule
X-HTML-Minification-Powered-By
Refresh
Access-Control-Request-Headers
X-Tumblr-User
X-Varnish-Age
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Original-Request-Id
X-Response-Served-From
X-Cache-Time
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Cache-Status-Check
X-Rule
X-Varnish-Ttl
X-EdgeConnect-Cache-Status
CDN-RequestId
VIX-Pulpo-Upstream-Status
X-Jobs
X-G
X-RTag
X-User-Agent
X-UUID
X-Framework
X-Content-Powered-By
Protected
Ms-Operation-Id
SD-X-WS
VIX-Pulpo-Node
X-Cacheable-TTL
MS-CV
X-Cache-Grace
X-FW-Dynamic
X-FW-Hash
X-Environment-Context
X-Device-Type
GEO-INFO
X-Backend-Name
X-FW-Serve
X-FW-Server
X-ProcessESI
X-RemovedCookies
X-L-Path
X-FW-Version
X-FW-Static
From-Origin
X-FW-Type
Section-Io-Cache
Akamai-GRN
X-Tt-Trace-Tag
X-Status
X-Page-View
X-Instance
X-Trace-Id
NGB
X-Tt-Trace-Host
X-Http-Reason
X-Drupal-Cache-Contexts
X-RateLimit-Limit
X-Adobe-Content
X-Region
X-Rendered-As
X-Drupal-Cache-Tags
X-Adobe-Loc
X-Is-Bot
X-XRDS-LOCATION
X-Cache-Expired-At
X-NYM-Debug-Backend
X-Nginx-Cache
X-Akamai-Request-ID2
Front
Url
X-Servername
X-Unique-Id
SRV
Accept-Language
X-Template
Pinterest-Generated-By
Liferay-Portal
X-Content-Options
X-Pinterest-Rid
X-CDN-Forward
Pinterest-Version
X-Debug-IsConnected
X-Debug-IsPreview
Fastly-SIE
Fastly-SWR
Backend
X-Yottaa-Optimizations
X-Time
X-Yottaa-Metrics
X-Newrelic-App-Data
X-Air-Source
X-Cache-Hit
X-Air-Hostname
X-Air-Trace-Id
X-Zen-Fury
Country
X-DynaTrace-JS-Agent
X-Mode
Content-Secure-Policy
X-COUNTRY
X-Rocket-Nginx-Serving-Static
X-Cache-Operation
Node
X-Uri
X-RN-RSRV
S-Rt
X-Cache-Server
Uber-Trace-Id
Webserver
X-Rewrite-Enabled
X-UPSTREAM-Address
X-Tumblr-Pixel-2
X-Proxy-Cache-Info
X-IPS-LoggedIn
X-Amzn-Remapped-Content-Length
X-Generation-Time
Onion-Location
Meta-Geo
Filters
X-Content-Age
Azure-SiteName
X-Timing-Wait
X-Proxy-Build
X-Web-Node
X-Locale
Cache-Hits
Azure-RegionName
CF-IPCountry
Azure-InstanceId
X-Edge-Location
Selected-Fe
Azure-SlotName
X-PHP-Backend
X-Tumblr-Pixel-3
X-Tb
Azure-Version
X-Cluster-Node
X-Cache-Action
X-Server-W
X-BYPASS-REASON
X-Access
X-Format
X-ARC
X-Cms-Context
X-Origin-Date
X-Say-Cacheable
X-Via-Fastly
X-Sucuri-ID
X-Sucuri-Cache
X-Say-TTL
X-Varnish-Beresp-Grace
X-Proto
X-PHP-Host
Cache-Name
X-Labrador-Cache-Channel
X-Site-Version
X-Real-IP
X-ProxyCache-Key
X-Ms-Request-Id
X-ProxyCache-Status
X-SayCDN-TTL
X-Skip-Cache
X-Section
X-Ms-Version
X-Soup
TWC-Device-Class
DB-Nickname
TWC-Connection-Speed
Property-Id
Cross-Origin-Window-Policy
ServerID
ServedBy
X-Routing-Service
X-Origin-Hint
X-R9-Blue-Green-Version
X-Zipkin-Id
X-Reqid
X-VC-Cache
X-UA-Device-Type
X-Sql-Count
X-Sql-Duration-Ms
X-Proxied
X-Proxy-Cache-Status
X-Handled-By
Webcakes-App-Name
TWC-Privacy
TWC-Locale-Group
TWC-GeoIP-LatLong
Webcakes-Region
X-Cache-Host
X-Forwarded-Host
X-Extlb
X-Debug
TWC-GeoIP-Country
Webcakes-App-Version
WP-Super-Cache
Countrycode
X-VWS-Id
X-FB-TRIP-ID
Cache-Tv-Group
X-IPLB-Instance
X-SaId
X-AWS-Id
X-IPLB-Request-ID
X-LJ-Flow-ID
X-Optimistic-Header
X-LAGOON
X-JoinUs
X-Adobe-Source
X-Ruxit-Js-Agent
Web-Mar-Node
Apigw-Requestid
X-Cache-TTL-Remaining
X-Urbn-Context-Path
X-Ua
X-Urbn-Site-Id
X-Cluster
X-App-Version
X-No-Session
Mn-Server-Ip
Locale
X-Detected-As
X-Node-Name
X-LSADC-Cache
Fastcgi-Useragent
X-GeoCountry
X-GeoCode
X-WP-CF-Super-Cache
X-Xfnlog-Site
X-Tt-Logid
X-WP-CF-Super-Cache-Cache-Control
X-Director
Mime-Version
X-Oneagent-Js-Injection
Source
Upgrade-Insecure-Requests
X-Varnish-Hits
Frame-Options
X-GEO
X-Buckets
CDN-RequestCountryCode
CDN-PullZone
CDN-Cache
CDN-CachedAt
X-Hl-Ver
CDN-EdgeStorageId
X-Generated-By
CDN-Uid
Fastly-Drupal-HTML
X-TIME
X-Tec-Api-Root
X-Tec-Api-Version
X-Tec-Api-Origin
X-Mg-Request-UUID
X-Request-Time
X-FireWall-Port
X-Varnish-Cache-Hits
Xet-Cookie
Load-Balancing
X-Api-Version
X-Redis-Cache
X-TA-CDN-Provider
X-Origin-TTL
X-RM-Cache-TTL
X-ServerID
X-Varnish-Hostname
X-Origin-CC
X-Loop
X-URL
X-Datadog-Sampling-Priority
X-Datadog-Trace-Id
X-Cache-Debug
X-SRV
X-Datadog-Sampled
X-Datadog-Parent-Id
CF-Cached-On
X-Tx-Id
X-Akamai-Transformed
X-Alternate-Cache-Key
X-ShopId
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Shopify-Stage
X-Storefront-Renderer-Rendered
X-ShardId
X-Pubstack
X-Served-From
X-Pass-Why
X-Endurance-Cache-Level
X-Storage
X-CSRF-Token
X-Newrelic-Synthetics
X-Request-Host
X-Location
Xserver
Server-Info
X-Service
X-Restarts
X-TNCMS
Rendered-Blocks
Release
Server-Host
X-Developer
X-Nyt-Route
X-Destination
Redirect-Candidate
X-Loc
X-Level-Front-Cache
X-Men
X-Mid
X-Mobile-URL
X-Cache-NE
Surrogated-Key
Thinkindot-Control
Thinkindot-CacheControl-Type
X-Origin-Time
X-Thanos
X-Test
X-Thinkindot-L3
X-Origin
T-Server
Origin
TDXMobile
DCR-Decision-By
Thinkindot-CacheControl
Sslversion
Odigeo-Trace-Id
Cache-Host
X-Hash
Host-ID
BehaviorPad-Version
Lang
Gannett-Cam-Experience-Id
Candidate-Md5Url
X-Generated-On
DCR-Processing-Time-Ms
DSUID
Edge-Cache
X-Gdpr
X-External-Request-Id
A
X-Ec-GeoHdr
X-INCAP-ABP
Ngx.Var.Host
NM-Fastcgi-Cache
X-SVT-ORM-VERSION
X-Epic-Correlation-Id
X-Httpd
X-Vdms-Path
MD5-Digest
Memcached
Meta-Geo-Continent
X-Vdms-Version
X-Ec-Fail
X-TIM-N
X-A-Dcw
X-BCube-Filmed-By
X-A-Dgt
X-A-Wwc
X-Bip
X-Platform-Router
X-S
X-A-Dam
X-Platform-Processor
X-Rojux
X-Processor
X-Akamai-Device-Characteristics
X-Application
X-B-Cookie
X-D
X-Aed
Xc-Version
X-Correlation-ID
X-Bc-Bl
X-Platform-Cluster
X-Sn-Servicetimems
X-We-Are-Hiring
X-S-Maxage
X-S-Cookie
WWW-Authenticate
X-ScT
X-Provided-By
X-CUA
X-Cache-Info
X-Cache-Date
X-Core-Mission
X-Conf
X-Cdn-Origin
X-A
X-A-Ccd
X-SRCache-Key
X-Sigma-Backend
X-CMSURLCustom
X-Sigma
X-SVT-ORM-RULES
X-Rocket-Build-Number
X-WP-CF-Super-Cache-Active
HostName
Vix-Hermes-Req-Id
Tube-Return
X-Gamma-Serve
Gh-Request-Id
We-Hiring
X-Date
X-Fetched-On
Fastly-GeoIP-CountryCode
Fastly-Backend-Name
X-Geo-Header
X-GeoIP
Tube-Get-Contents
X-Cache-Id
Tube-Got-Eval
X-Cache-Bucket
Tube-Got-Results
X-DefElseHash
X-CacheTTL
X-Accel-Expires-Debug
X-Dispatcher-Server
Platform
X-Ec-Custom-Error
X-Esi-Check
X-BBC-Edge-Cache-Status
X-Ad-Defer-Variation
Mail-Subject
X-Dispatcher-Number
X-Fastly-Cache
Is-Eu
X-Fastly-Backend
X-DefHash
Magicmarker
Req-Svc-Chain
X-Auto-Login
X-Gzip
X-NodeID
X-Node-Id
X-Varnish-CookieHashed-On
X-Slack-Shared-Secret-Outcome
X-Varnish-Beresp-Status
X-Var-Ttl
X-Variation
X-Slack-Backend
X-Mvc-Supplant-Cachable
X-Human
X-HS-Content-Campaign-Id
X-Is-Gdpr
X-JWT-State
X-Scale
X-Varnish-Remaining-TTL
X-Org
X-Origin-Expires
X-Varnish-Beresp-Ttl
X-Platform
X-Response-By
X-Pool
X-Req
X-Region-Sid
X-Worker
X-VServer
Section-Origin-Responded
X-Origin-Response-Time
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
X-Vmg-Version
Section-Io-Id
X-Varnishpool
X-Varnish-CookieINHashed-On
Cmsid
Cmstype
AKAMAI
C-Via
CloudFront-Viewer-Country
Click-Count-Action-Start
Click-Count-Error
Country-Code
Cache-Key
CacheControlHeader
X-Has-Esi
X-GeoIP-City
X-Server-IP
X-SD-PageType
Adler-Geo
X-Parent-Response-Time
Environment
Web-Mar-Region
X-VG-TLSProxy
X-Planisys-CDN-Rules
X-GeoIP-Region-Code
X-Owner
X-Planisys-CDN-Cache
X-Core-Value
X-GeoIP-Country-Code
X-Clara-WADP
X-Azure-Ref-OriginShield
X-Release
X-Ckpd-Fst-Backend
X-App
X-Qloud-Router
X-Cdn-Srv
X-Planisys-CDN-TTL
Canary
Expect-Staple
X-Accel-Buffering
X-WA-Info
X-Air-Pt
X-Mly-Id
X-DPWN-IS-SECURE
Producers
Apple-News-Services-Handled
Apple-News-Services-Host
X-Request-Start
Machine
Origin-EX
X-Instance-Name
X-Cache-Tags
X-Irp-Debug
X-WADP-Cache
Origin-CC
On-Server
Apple-News-Services-Parsed-Url
X-Nginx-Cache-Key
State
Ssr
X-Fmm-Version
X-Cache-FS-Status
X-Forwarded-Site
X-V-Cache
Apple-News-Services-Request-Url
X-Wix-Viewer-Type
X-Developers
X-Device-Os
Kp-EeAlive
X-FC-Vary-Parameters
Datacenter
X-Frame-Option
X-Vcl-Version
X-Via-CDN
X-Minions-Version
X-VarnishDD-TTL
X-Hnp-Log
X-Gen-Mode
X-HN
X-NCache
X-Old-Content-Length
Srvid
X-SB
X-Platform-Server
X-FL-EDGE
X-Op-Id-All
X-FL-QIT-DEBUG
Locid
X-Aicache-OS
Sever-Int
User-Cache-Control
Wxu-Next-Commit
Wxu-Next-Hostname
Server-Hostname
Server-Ext
Cache-Provider
Fastly-SSL
L
PFcat
Wxu-Next-Region
NGX
X-Block-Status
X-Webkit-CSP-Report-Only
X-VC
Edge-Copy-Time
X-Zone
X-CACHE-AGE
X-Via-SSL
X-Via-Edge
X-Eu-Site
X-LB-NoCache
L5d-Success-Class
HA-Ipaddr
X-B3-Spanid
X-From
Ha-Gx-Prefs
X-Cache-Remote
X-Nananana
CDCHOST
X-Csrf-Jwt
X-Microcachable
X-Mvc-Supplant-OutputCached
X-CGP
X-Up
X-DC
X-Cache-Enabled
Env
X-Tb-Optimization-Total-Bytes-Saved
X-Cache-Backend
Decoy-Debug-TTL
X-Generated-In
Cluster
X-Refresh
X-Debug-Cache-Fetch
Decoy-Debug-Key
X-Debug-Cache-Store
X-RCS-CacheZone
GeoIP-Latitude
Pics-Label
Decoy-Debug-Status
X-ND-Cache
X-Lambda-Id
X-Trace-ID
X-Dc
X-NWS-UUID-VERIFY
X-Cached-By
X-VCT
X-Tid
X-Via-Popn
X-Via-Popv
X-Via-Poph
Cache
X-Cs
SID
NtCoent-Length
X-HS-Status
Sid
VNS-Age
VNS-Cache
CPC-Cache
CPC-Age
Time
X-Render-Time
Memory
X-Vtex-Remote-Cache
X-B3-SpanId
X-Webkit-CSP
X-Upstream-Ct
X-CCDN-CacheTTL
X-DataCenter
X-Upstream-Ht
X-Servedbyhost
X-LB-ID
X-HA-Backend
X-Hcs-Proxy-Type
X-CCDN-Origin-Time
X-Edge-Pop
X-Srv
X-TH-Server
X-Nc
X-Vgn-Hpd-Ssi
X-Vgn-Hpd-Cached
X-Vgn-Hpd-Variations-Key
X-AIR-PT
Fastly-Drupal-Html
X-Esi
X-Wa
X-Presslabs-Stats
X-Cache-Type
Svr
Cdn
AMP-Access-Control-Allow-Source-Origin
X-Client-Ip
X-CLOUD-TRACE-CONTEXT
X-NewRelic-App-Data
Server-ID
X-ATG-Version
X-ZONE
X-Contensis-Viewer-Groups
X-Cache-ASPX
GeoIp-Country-Code
X-Varnish-Authentication
X-Via-JSL
Srv
X-Fpc
Uri
X-Proxy-CacheRZ
X-Check-Cacheable
X-Vc
XkeyRZ
X-PAYTM-SRV-ID
X-RateLimit-Limit-Second
X-CF-Lambda-Fn
X-Amz-Meta-Cb-Modifiedtime
Esi-Enabled
X-MP-GENERATED-AT
True-Client-IP
X-CF-Lambda-Version
X-RateLimit-Remaining-Second
XServer
X-Nf-Request-Id
X-Gateway-Skip-Cache
X-AK-Request-ID
Cdnsip
X-Varnish-Beresp-TTL
X-Gateway-Request-Id
X-Gateway-Cache-Key
Cdncip
X-Gateway-Cache-Status
M-TraceId
X-Udemy-Cache-App-Namespace
X-EC-Lua
X-CS
Hostname
X-NGINX-Cache
X-Wikidot-Static-Cache
N-Cache
Resin-Trace
True-Client-Ip
X-API-Version
X-Wikidot-Backend
X-Via-NSCOPI
YJS-ID
X-CSRF-TOKEN
X-Forwarded-Path
X-Orig-Expires
X-MSEdge-Features
X-FPC
X-MSEdge-Flight
X-Tenant
X-Shop-Environment
Lb
X-Bl-Debug
RNT-Time
X-CDN-Cache-Status
OT-Force-Account-Verify
RNT-Machine
X-Datadome
X-Fastly-Country-Code
Eomportal-Instance
X-TX-ID
Request-ID
X-B3-Trace-ID
X-Policy
X-App-Name
GeoIP-Country-Code
X-APP-VERSION
CDN
X-RateLimit-Reset
X-Micro-Cache
X-Cache-Ttl
Server-Id
Path
X-Service-Response-Time
X-CACHE-KEY
Sm-Log-Id
Ngx-Var-Key
X-Accel-Version
X-Vcache
X-WA
X-SIPLIST1
IsBot
LB
X-Logging-Id
X-Edge-POP
X-NC
X-VCL-Version
Hit
X-Ha-Backend
X-Request-URI
X-Lb-Id
X-MCACHE
X-Cache-NGX
X-Container-Uri
X-Git-Commit
HIT
X-Info
X-Cdn-Cache-Status
X-Datacenter
X-Cdn-Diag
Pramga
X-Github-Request-Id
Cross-Origin-Opener-Policy-Report-Only
X-ServedByHost
X-SERVER-NAME
Location
X-Akamai-Pragma-Client-IP
X-Geo
X-Snapshot-Date
X-Tncms
X-VG-WebCache
Timeexpire
FSS-Cache
X-Srcache-Store-Status
X-Srcache-Fetch-Status
Ohc-File-Size
X-Cdn-Forward
X-Pod-Name
X-Via-PopV
ENV
XM
X-Via-PopN
Req-ID
X-Via-PopH
X-Acquia-Purge-Cdn-Unconfigured
Epwk-X-Cache
V-Age
Yjs-Id
Geoip-Latitude
True-Client-Country-4JS
X-Ctl-Mach
X-Iauth-Set-Uid
X-Wp-Cf-Super-Cache
X-Wp-Cf-Super-Cache-Cache-Control
CDN-RequestPullSuccess
X-Oss-Storage-Class
X-Oss-Request-Id
X-Oss-Object-Type
Proxy-Connection
X-LiteSpeed-Cache-Control
X-Hyper-Cache
Servername
X-Oss-Server-Time
X-Clientip
X-Serial
X-Amz-Meta-Opti
X-Lb-Nocache
X-TT-LOGID
X-Oss-Hash-Crc64ecma
X-Fastly-Backend-Reqs
X-Cache-Expires
X-Dw-Trace-Id
CDN-RequestPullCode
X-Cdn-Request-ID
X-M-Log
X-M-Reqid
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
Warning
X-Acquia-Site
X-Acquia-Purge-Tags
WZWS-RAY
X-UP
X-Swift-Error
X-Acquia-Application-UUID
X-RAMCache
X-Acquia-Application-Trace
Cneonction
X-Akamai-ERPolicy
X-Akamai-ERRuleID
Ec-Rule-Version
Content-Style-Type
X-Qnm-Cache
X-B3-Parentspanid
Content-Script-Type
X-Lsadc-Cache
CountryCode
X-MiniProfiler-Ids
X-F-Status
X-UA
PICS-Label
My-App
X-WP-CF-Super-Cache-Cookies-Bypass
MIME-Version
X-Scheme
X-Cached-Since
W
X-Moov-T
X-Cache-Ngx
X-Fastly-Cache-Hits
X-Mg-Cache
X-Litespeed-Cache-Control
X-Moov-Xdn-Version
X-Th-Server
Ngx
X-B3-ParentSpanId
X-Webstats-RespID
X-LiteSpeed-Tag
X-IPS-Cached-Response
Ohc-Cache-HIT