Threat Level: green Handler on Duty: Rick Wanner

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
Strict-Transport-Security
X-Frame-Options
X-Content-Type-Options
Last-Modified
Link
CF-Cache-Status
Cf-Request-Id
Accept-Ranges
ETag
CF-RAY
Expect-CT
Pragma
X-Powered-By
X-Cache
Via
Age
X-XSS-Protection
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Xss-Protection
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-FRAME-OPTIONS
X-Download-Options
X-Timer
X-Request-Id
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-Adblock-Key
X-AspNet-Version
X-Permitted-Cross-Domain-Policies
Alt-Svc
X-Runtime
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Cache-Status
X-Generator
CF-Ray
X-Cacheable
X-Iinfo
Timing-Allow-Origin
X-Envoy-Upstream-Service-Time
X-Request-ID
Feature-Policy
X-Ua-Compatible
Status
X-Content-Security-Policy
X-Drupal-Dynamic-Cache
Content-Encoding
X-AspNetMvc-Version
Access-Control-Expose-Headers
X-CDN
Upgrade
X-XSS-PROTECTION
Access-Control-Max-Age
X-Via
X-Cache-Group
X-Robots-Tag
Server-Timing
X-UA-Device
Request-Context
Keep-Alive
X-AH-Environment
X-Dns-Prefetch-Control
X-Amz-Request-Id
X-Turbo-Charged-By
X-Proxy-Cache
X-Backend
X-Amz-Id-2
X-Ws-Request-Id
X-Age
Host-Header
P3p
X-Server-Powered-By
X-Hacker
X-Server
X-Rq
X-Vhost
EagleId
X-Varnish-Cache
Grace
X-Amz-Version-Id
X-Dispatcher
Cf-Edge-Cache
X-LiteSpeed-Cache
X-Akamai-Path-Stats
Allow
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Swift-SaveTime
X-Swift-CacheTime
X-Device
Ali-Swift-Global-Savetime
X-WebKit-CSP
X-Page-Speed
X-Nginx-Cache-Status
X-Aws-Lambda-Call-Status
X-Host
Accept-CH
X-Node
X-OneAgent-JS-Injection
X-Pingback
Cf-Railgun
X-Cache-Spec
Request-Id
EagleEye-TraceId
Surrogate-Control
X-Server-Id
X-Akam-SW-Version
X-Backend-Server
X-Cache-Lookup
X-Response-Time
X-Readtime
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-HW
Accept-CH-Lifetime
Content-Location
X-Content-Security-Policy-Report-Only
X-Application-Context
X-Trace
Rating
X-Cloud-Trace-Context
Fastly-Restarts
X-Country
Accept-Ch-Lifetime
X-Url
X-WebKit-CSP-Report-Only
X-Clacks-Overhead
X-MS-InvokeApp
X-Edge
X-Amz-Server-Side-Encryption
Edge-Control
X-Rack-Cache
X-Nginx-Upstream-Cache-Status
X-B3-TraceId
X-Ruxit-JS-Agent
X-Vname
X-PC
X-TtlSet
X-Content-Type
X-ESI
X-Mod-Pagespeed
X-Vcap-Request-Id
X-Exp-Id
X-Kinja
X-Kinja-Server
X-Exp-Variant
X-Use-Magma
X-D2id
X-GoogleNews-Bot
X-Cdn-Fetch
X-Kinja-Revision
X-Oneagent-Js-Injection
X-Kinja-Build
Xkey
Verso
X-GitHub-Request-Id
X-Mcache
X-Amz-Rid
Cache-Tag
X-VARITI-CCR
X-Powered-By-Plesk
X-CST
RTSS
X-Varnish-TTL
Service-Worker-Allowed
X-ECACHE
X-FastCGI-Cache
X-Upstream
X-Ruxit-Js-Agent
X-Navigation-Version
X-Abt-Application-Version
X-Version
X-Cached
X-Client-IP
X-Cnection
X-Dw-Request-Base-Id
X-Ac
X-Px
X-Element-Page-Cache
X-SharePointHealthScore
SPRequestGuid
X-Server-Name
Public-Key-Pins
X-Server-Lifecycle-Phase
X-Instrumentation
X-Kraken-Loop-Name
Arr-Disable-Session-Affinity
X-Cache-TTL
SPIisLatency
SPRequestDuration
X-Sol
X-Middleton-Display
Display
Pagespeed
X-Ttl
X-NWS-LOG-UUID
X-Country-Code
Permissions-Policy
X-Ser
Accept-Ch
X-Cache-Key
Response
X-Midtier
X-Middleton-Response
X-Kinsta-Cache
X-Edge-Location-Klb
X-Goog-Hash
X-RateLimit-Remaining
X-Forwarded-For
Content-MD5
X-SRCache-Fetch-Status
X-SRCache-Store-Status
Access-Control-Request-Method
X-DataDome
Front-End-Https
X-Shield-Request-Id
X-Correlation-Id
X-NF-Request-ID
X-MSEdge-Ref
X-Jurisdiction
X-Recruiting
X-HP-Webp
X-HP-Trace-Id
Cf-Apo-Via
Edge-Cache-Tag
X-T
Nginx-Cache
AR-Request-ID
TP-Cache
TP-L2-Cache
AR-SID
AR-ATIME
AR-CACHE
AR-PoweredBy
X-Accel-Expires
MicrosoftSharePointTeamServices
Mrf-Cache-Status
X-B3-TraceId-Primal
MRF-Tech
X-Daa-Tunnel
X-Powered-CMS
TCN
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
X-Grace
X-RateLimit-Limit
X-Litespeed-Cache
X-Mg-S
X-Id
X-Hits
X-Content-Digest
Server-Node
X-HS-Cache-Config
X-HS-Content-Id
Server-Name
Filters
X-HS-Combine-CSS
X-Request-Received
X-HS-Hub-Id
X-Request-Processing-Time
X-Amzn-Trace-Id
X-TEC-API-ROOT
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-Frontend
X-Geo-Country
MS-Author-Via
X-Distributor
S
X-Protected-By
Fastcgi-Cache
X-LLID
X-Language
Cache-Status
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Browser-Type
X-XRDS-Location
X-PressLabs-Stats
X-LB-Cache
X-Origin-Server
X-Ezoic-Cdn
Cross-Origin-Opener-Policy
Count-Hit
X-Fastcgi-Cache
X-TTL
Host
X-B3-Sampled
X-Request-Handler-Origin-Region
X-FB-Debug
X-Microsite
X-Amz-Meta-S3cmd-Attrs
X-F-Cache
Charset
X-Forwarded-Proto
X-Ua-Browser
X-Git-Hash
X-Page-Id
Payment
X-Ab
X-Seen-By
X-Fastly-Request-Id
Filterid
X-Cluster-Name
X-ASPNET-VERSION
X-Cache-Age
X-VCache
X-Ratelimit-Reset
Surrogate-Key
Realpath
X-Rid
X-Origin-Cache
Cache-Tags
Accept-Charset
X-NGENIX-Cache
Alternate-Protocol
X-Template
Access-Control-Allow-Method
X-Www-Served-By
Retry-After
X-Webkit-Csp
X-Logged-In
X-Activity-Id
X-AppVersion
X-Az
X-DynaTrace
X-DIS-Request-ID
X-Upgrade-Enabled
X-Fastly-Request-ID
X-Providence-Cookie
X-Route-Name
X-Is-Crawler
X-Request-Guid
Cleartype
X-Aspnet-Duration-Ms
X-Flags
X-Amz-Replication-Status
X-Varnish-Backend
X-TT
X-Varnish-Grace
X-B
X-Tb
X-App-Environment
X-Type
X-B-Cache
X-Signature
X-Source
X-Node-Name
X-Envoy-Decorator-Operation
X-Wix-Request-Id
X-Hostname
DC
Paypal-Debug-Id
Frame-Options
X-Drupal-Cache-Tags
ServerID
X-Proxy
X-Debug
X-Revision
X-Contextid
X-Tt-Trace-Host
X-Mobile
X-Server-ID
X-Tt-Trace-Tag
X-Content-Options
Pinterest-Version
X-Pinterest-Rid
Pinterest-Generated-By
Amp-Access-Control-Allow-Source-Origin
X-Load-Cache
X-Cache-Rule
X-Kong-Proxy-Latency
X-Goog-Generation
X-Goog-Metageneration
X-Goog-Storage-Class
X-GUploader-UploadID
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Kong-Upstream-Latency
X-Cache-Control
X-N
Country
X-Ratelimit-Remaining
Node
X-Magnolia-Registration
X-Content
Refresh
X-Response-Served-From
X-Original-Request-Id
X-Whom
X-User-Agent
X-EdgeConnect-Cache-Status
Referer-Policy
X-Cache-TTL-Remaining
X-L-Path
X-Debug-IsPreview
Access-Control-Request-Headers
X-Environment-Context
X-Cacheable-TTL
X-Debug-IsConnected
X-Adobe-Content
X-Adobe-Loc
Viewport
VIX-Pulpo-Upstream-Status
X-Content-Powered-By
X-Yottaa-Optimizations
Url
X-Akamai-Request-ID2
X-Yottaa-Metrics
X-Unique-Id
X-Mid
X-Jobs
X-G
X-Page-View
X-Real-IP
X-Servername
Uber-Trace-Id
X-Framework
VIX-Pulpo-Node
NGB
Content-Disposition
X-Cache-Time
X-Varnish-Age
X-Varnish-Server
X-NYM-Debug-Backend
X-Oracle-Dms-Ecid
X-Oracle-Dms-Rid
X-Rendered-As
X-Is-Bot
X-Cache-Grace
Srv
X-Status
X-ProcessESI
X-RemovedCookies
X-Instance
Countrycode
Akamai-GRN
X-Time
X-Mg-Request-UUID
X-Drupal-Cache-Contexts
Version
X-COUNTRY
X-CDN-Forward
X-Restarts
X-Http-Reason
X-Cache-Expired-At
X-App-Server
Accept-Language
X-Ratelimit-Limit
X-Via-JSL
X-Trace-Id
X-XRDS-LOCATION
X-Debug-Info
Healthy
Protected
X-APP-VERSION
X-IPLB-Instance
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Tumblr-User
X-Cache-Hit
X-IPLB-Request-ID
X-Tumblr-Pixel-1
X-Cache-Operation
X-Hosted-By
Cross-Origin-Resource-Policy
X-Nginx-Cache-Key
X-Azure-Ref
X-Device-Type
X-Backend-Name
X-Tt-Logid
Section-Io-Cache
X-Akamai-Edgescape
Liferay-Portal
X-FW-Type
Server-Info
X-FW-Server
X-FW-Static
X-FW-Dynamic
Backend
X-FW-Hash
X-FW-Serve
Content-Secure-Policy
Fastcgi-Useragent
X-RTag
X-Cache-Action
X-Api-Version
Ms-Operation-Id
MS-CV
X-Mobile-URL
Load-Balancing
Meta-Geo
X-Proxy-Cache-Status
X-RN-RSRV
X-Storage
X-UPSTREAM-Address
X-Rule
X-Mode
X-Cache-NGX
GEO-INFO
X-VC-Cache
X-Varnish-Beresp-Grace
X-Varnishpool
X-Cms-Context
X-VWS-Id
X-AWS-Id
X-Varnish-Hostname
X-Adobe-Source
X-Forwarded-Host
X-Alternate-Cache-Key
X-Content-Age
X-LJ-Flow-ID
X-Edge-Location
X-Handled-By
X-PCL
X-ShopId
X-Shopify-Stage
X-ShardId
X-SayCDN-TTL
X-Say-TTL
X-Site-Version
X-Skip-Cache
X-Sql-Duration-Ms
X-Sql-Count
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-No-Session
X-Say-Cacheable
X-UUID
X-PHP-Backend
X-Proto
S-Rt
X-Urbn-Site-Id
X-Urbn-Context-Path
X-Region
X-OCL
Locale
X-Via-Fastly
CDN-RequestId
Selected-Fe
X-Web-Node
Mn-Server-Ip
CF-IPCountry
Eomportal-Instance
X-Xfnlog-Site
DB-Nickname
X-Zipkin-Id
CDN-Uid
X-Access
X-Hl-Ver
X-ProxyCache-Key
X-ProxyCache-Status
X-Proxy-Build
X-Proxied
X-PHP-Host
X-Redis-Cache
X-Request-Time
X-Timing-Wait
X-ServerID
X-Section
X-Routing-Service
X-Uri
X-Labrador-Cache-Channel
X-Detected-As
X-Extlb
X-Cache-Type
X-Cache-Server
X-Cache-Enabled
X-FB-TRIP-ID
X-Generated-By
X-HTML-Minification-Powered-By
CDN-RequestCountryCode
X-GeoCountry
X-GeoCode
X-BYPASS-REASON
CDN-EdgeStorageId
X-Varnish-Cache-Hits
X-Generation-Time
TWC-GeoIP-LatLong
TWC-Connection-Speed
Property-Id
Webcakes-App-Version
Webcakes-Region
X-SRV
TWC-Device-Class
TWC-Privacy
X-Format
TWC-GeoIP-Country
TWC-Locale-Group
Onion-Location
CDN-Cache
CDN-CachedAt
Webcakes-App-Name
CDN-PullZone
X-UA-Device-Type
X-Origin-Hint
X-Locale
Apigw-Requestid
X-Cache-Host
X-R9-Blue-Green-Version
X-Cache-Status-Check
Azure-RegionName
Azure-SiteName
X-Server-W
Azure-SlotName
Azure-InstanceId
X-Nginx-Cache
X-Storefront-Renderer-Rendered
X-Tid
Web-Mar-Node
Azure-Version
X-Origin-Date
X-URL
X-SaId
X-Ms-Version
X-JoinUs
X-Ms-Request-Id
WP-Super-Cache
X-Datadome
Xserver
Cache-Name
X-FireWall-Port
X-DynaTrace-JS-Agent
X-WP-CF-Super-Cache-Cache-Control
X-Correlation-ID
X-WP-CF-Super-Cache
ServedBy
X-Zen-Fury
X-LSADC-Cache
X-Amz-Apigw-Id
X-Amzn-RequestId
X-ECache
X-App-Version
X-Human
X-Varnish-Ttl
Source
X-Debug-Cache
X-Ua
X-Loop
X-TNCMS
X-Cache-Tags
X-RCS-CacheZone
X-Dc
X-TA-CDN-Provider
X-GEO
X-Reqid
X-Varnish-Hits
X-Tec-Api-Origin
Cache
X-Tec-Api-Root
Xet-Cookie
X-Tec-Api-Version
X-Soup
X-Cached-By
X-Pubstack
X-Amzn-Remapped-Content-Length
X-MP-GENERATED-AT
SD-X-WS
X-Aspnetmvc-Version
Cross-Origin-Window-Policy
Origin
X-Newrelic-Synthetics
X-Cdn
X-Vgn-Hpd-Reason
X-Webkit-CSP
WPO-Cache-Status
WPO-Cache-Message
X-Varnish-Beresp-Ttl
X-Origin-CC
X-Provided-By
X-Service
X-Tumblr-Pixel-2
X-Origin-TTL
From-Origin
LB
X-IPS-LoggedIn
Webserver
X-AOL-HN
X-B3-SpanId
X-Via-NSCOPI
X-FW-Version
X-GG-Cache-Date
Rip
X-Platform-Server
X-Request-Host
Sslversion
X-A-Ccd
X-A
X-A-Dam
T-Server
Surrogated-Key
X-A-Dgt
X-AK-Request-ID
X-Application
X-Aed
X-A-Wwc
Rendered-Blocks
X-A-Dcw
Meta-Geo-Continent
DCR-Decision-By
DCR-Processing-Time-Ms
Cdnsip
Cdncip
A
BehaviorPad-Version
Environment
Expiry
X-ARC
Ngx.Var.Host
MD5-Digest
Lang
Host-ID
Odigeo-Trace-Id
X-Cache-NE
X-Served-From
X-Shop-Environment
X-ScT
X-S-Cookie
X-Rojux
X-S
X-SRCache-Key
X-Tenant
X-VG-WebCache
Xc-Version
X-Vdms-Version
X-Vdms-Path
X-TIM-N
X-User
X-Rewrite-Enabled
X-Processor
X-Destination
X-Developer
X-D
X-Connection-Hash
X-Bc-Bl
X-BCube-Filmed-By
X-Ec-GeoHdr
X-External-Request-Id
X-Owner
X-PBS-Appsvrname
X-Orig-Expires
X-NAPM-TraceId
X-Forwarded-Path
X-B-Cookie
X-Ec-Fail
HostName
X-CSRF-Token
X-Cluster-Node
X-NewRelic-App-Data
OT-Force-Account-Verify
X-B3-Traceid
X-VC
X-Pool
Upgrade-Insecure-Requests
X-Qloud-Router
X-Level-Front-Cache
X-Aicache-OS
Redirect-Candidate
X-Bip
X-Dispatcher-Number
X-Thanos
X-Parent-Response-Time
X-Generated-On
CPC-Cache
X-Varnish-Beresp-Status
VNS-Age
CPC-Age
VNS-Cache
X-Nf-Request-Id
X-TIME
Mime-Version
X-WA-Info
X-Ckpd-Fst-Backend
X-Clientip
X-Cluster
X-CMSURLCustom
X-CGP
X-Cdn-Origin
X-Worker
X-Branch-Name
X-CacheTTL
X-Core-Value
X-Csrf-Jwt
X-DefHash
X-Accel-Buffering
X-Device-Os
X-VServer
X-DefElseHash
X-Datadog-Trace-Id
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
Producers
X-BBC-Edge-Cache-Status
Release
Tube-Got-Eval
Tube-Got-Results
Tube-Return
State
Tube-Get-Contents
Traceparent
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
Thinkindot-Control
Servername
V-Age
Server-Host
X-Ad-Defer-Variation
Req-Svc-Chain
X-DPWN-IS-SECURE
Wxu-Next-Region
Vix-Hermes-Req-Id
Wxu-Next-Commit
Wxu-Next-Hostname
TDXMobile
X-Eu-Site
X-Request-URI
X-Variation
X-Rocket-Build-Number
X-Rocket-Nginx-Serving-Static
X-Region-Sid
X-Varnish-CookieHashed-On
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Policy
X-S-Maxage
X-SB
X-Sn-Servicetimems
X-SplitTest
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-Slack-Backend
X-SIPLIST1
X-Scale
X-Sigma
X-Sigma-Backend
X-V-Cache
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
X-Gateway-Cache-Status
X-Gateway-Request-Id
X-Gateway-Skip-Cache
Platform
X-Gateway-Cache-Key
X-Gamma-Serve
X-Epic-Correlation-Id
X-Thinkindot-L3
X-Fetched-On
X-Forwarded-Site
X-GeoIP
X-GeoIP-City
Cache-Hits
X-NodeID
X-Optimistic-Header
X-Origin
X-Minions-Version
X-Loc
X-Hash
X-Irp-Debug
X-VG-TLSProxy
X-Ec-Custom-Error
X-Core-Mission
Kp-EeAlive
Cache-Host
IsBot
Canary
L
L5d-Success-Class
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
Memcached
Fastly-SIE
Is-Eu
Candidate-Md5Url
Country-Code
DSUID
Fastly-SWR
Fastly-SSL
Cmstype
Ha-Gx-Prefs
HA-Ipaddr
Click-Count-Action-Start
Click-Count-Error
Cmsid
Apple-News-Services-Host
Machine
NM-Fastcgi-Cache
Adler-Geo
Origin-EX
X-Cache-Debug
Origin-CC
Mobile-Detection-Method
Apple-News-Services-Handled
NGX
Decoy-Debug-Key
X-Gdpr
X-Esi-Check
X-Auto-Login
CloudFront-Viewer-Country
X-Fmm-Version
Decoy-Debug-TTL
Fastly-GeoIP-CountryCode
X-Nyt-Route
X-Origin-Time
X-Clara-WADP
X-INCAP-ABP
Decoy-Debug-Status
Gh-Request-Id
X-Developers
X-Scheme
X-Has-Esi
X-Origin-Response-Time
X-Gzip
X-NCache
X-Hnp-Log
X-JWT-State
X-Is-Gdpr
Ec-Rule-Version
X-Geo-Header
CDCHOST
X-WADP-Cache
X-Mvc-Supplant-Cachable
X-Gen-Mode
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Wix-Viewer-Type
X-Mvc-Supplant-OutputCached
X-Block-Status
Server-Hostname
X-ZONE
User-Cache-Control
X-Cache-Id
X-Cache-Bucket
Svr
Server-Ext
Sever-Int
X-Cdn-Srv
X-Cache-Info
Cache-Tv-Group
X-WP-CF-Super-Cache-Active
X-Tx-Id
X-Cache-Remote
X-Trace-ID
Web-Mar-Region
We-Hiring
X-LB-NoCache
AKAMAI
X-Xrds-Location
X-HS-Content-Campaign-Id
Cluster
Datacenter
Mail-Subject
Fastcgi-Cache-TTL
X-Viewer-Country
X-Proxy-Cache-Info
Fastly-Backend-Name
X-Newrelic-App-Data
X-Udemy-Cache-App-Namespace
X-Presslabs-Stats
X-Session-Fingerprint
X-Fastly-Backend
Fastly-Drupal-HTML
X-FC-Vary-Parameters
X-Sucuri-Cache
Time
Memory
X-Sucuri-ID
SID
Ssr
X-Origin-Expires
X-Fastly-Cache
X-Azure-Ref-OriginShield
X-Rebelmouse-Surrogate-Control
X-ND-Cache
X-Rebelmouse-Cache-Control
Pics-Label
WebServer
X-Var-Ttl
X-ATG-Version
X-Tb-Optimization-Total-Bytes-Saved
X-Via-Popn
X-Generated-In
X-Via-Poph
X-Via-Popv
X-Pod-Name
Sid
X-NWS-UUID-VERIFY
X-Servedbyhost
X-Akamai-Transformed
Server-ID
AMP-Access-Control-Allow-Source-Origin
X-Refresh
X-Ig-Push-State
X-Cache-Date
X-Buckets
Env
X-DC
X-Pass-Why
X-Release
X-Fpc
X-Conf
X-Edge-Pop
X-Up
X-Cs
X-MSEdge-Features
X-MSEdge-Flight
X-NC
X-Microcachable
X-EC-Lua
X-Dispatch
My-App
X-Wa
X-Tumblr-Pixel-3
X-Dmc
X-Lambda-Id
X-Esi
X-RateLimit-Reset
X-Endurance-Cache-Level
Fastly-Drupal-Html
X-PX
X-ID
X-MCACHE
CDN
X-CS
X-CACHE-AGE
GeoIp-Country-Code
X-Be
X-Req
X-VCL-Version
X-TX-ID
Magicmarker
X-Zone
X-TRACE-ID
True-Client-IP
X-Webkit-CSP-Report-Only
X-NGINX-Cache
X-Wikidot-Backend
X-LB-ID
X-Wikidot-Static-Cache
X-Vc
X-CACHE-KEY
X-Srv
Hostname
CacheControlHeader
X-TH-Server
X-CSRF-TOKEN
True-Client-Country-4JS
X-Air-Trace-Id
X-Air-Source
X-Air-Hostname
X-Hyper-Cache
X-Yandex-Sdch-Disable
X-CF-Lambda-Fn
X-Op-Id-All
X-Micro-Cache
X-CF-Lambda-Version
True-Client-Ip
Pramga
X-M-Reqid
X-M-Log
Resin-Trace
GeoIP-Country-Code
X-Alfa-Service
Path
X-App
X-Air-Pt
X-HS-Status
X-B3-Spanid
X-Vcl-Version
C-Via
X-Qnm-Cache
Tcn
X-Varnish-Beresp-TTL
Tracecode
X-TrackingId
N-Cache
X-SERVER-NAME
X-PAYTM-SRV-ID
X-Vercel-Id
On-Server
X-Datacenter
X-Vercel-Cache
Fastcgi-X-Cache-Version
Esi-Enabled
X-Platform
X-GeoIP-Country-Code
X-GeoIP-Region-Code
NtCoent-Length
X-CLOUD-TRACE-CONTEXT
X-Check-Cacheable
Section-Io-Origin-Time-Seconds
X-Date
Yjs-Id
Section-Origin-Responded
X-Akamai-Pragma-Client-IP
X-Edge-Origin-Shield-Bytes
WWW-Authenticate
Hit
Proxy-Connection
Section-Io-Origin-Status
Section-Io-Id
X-Accel-Expires-Debug
X-Edge-Origin-Shield-Region
X-FPC
X-Webkit-Csp-Report-Only
X-Vtex-Processado-Em
FSS-Cache
X-Vtex-Remote-Cache
X-Platform-Router
X-Platform-Processor
X-Platform-Cluster
X-RAMCache
GeoIP-Latitude
X-Old-Content-Length
X-Node-Id
X-Geo
X-Edge-POP
X-WA
X-Response-By
X-Via-CDN
X-Mly-Id
X-LiteSpeed-Cache-Control
ENV
YJS-ID
Lb
X-Lb-Id
Server-Id
X-ServedByHost
Powered-By
User-Agent
X-LAGOON
Cdn
X-Request-Start
X-SD-PageType
X-API-Version
X-Cdn-Forward
X-Dw-Trace-Id
X-UA
X-AIR-PT
X-PERF
X-Via-PopV
X-Via-PopH
X-From
X-Via-PopN
X-FL-EDGE
HIT
Locid
Srvid
Cache-Key
X-ApacheServer
X-Client-Ip
X-Akamai-ERRuleID
X-Akamai-ERPolicy
Geoip-Latitude
XkeyRZ
X-Traceid
Dnion-Transfer-Encoding
X-FORWARDED-FOR
Server-Ttl
X-Cache-Ttl
X-Location
DynaTrace
X-Render-Time
X-LI-Proto
X-LI-UUID
X-Proxy-CacheRZ
X-TT-LOGID
X-Li-Pop
X-CUA
X-Instance-Name
X-Li-Fabric
X-Via-Ucdn
X-Service-Response-Time
Sm-Log-Id
Ohc-File-Size
X-Webstats-RespID
X-DSS
X-RSL
X-Proxy-Upstream
X-CF-Powered-By
X-RPS
X-RPM
X-DB
X-DI
X-DW
XServer
X-Director
DT-Hot-News
X-HN
Location
X-Proxy-Cache-Hk
Nginx-CQVIP
XM
X-LiteSpeed-Tag
X-VarnishDD-TTL
PICS-Label
PFcat
X-Cache-ASPX
X-Contensis-Viewer-Groups
X-Varnish-Authentication
X-Wp-Cf-Super-Cache
X-Wp-Cf-Super-Cache-Cache-Control
X-Litespeed-Cache-Control
X-Yottaa-OS
Wpo-Cache-Message
X-Lb-Nocache
X-Fastly-Cache-Hits
X-B3-ParentSpanId
Vha6-Origin
X-HostName
X-Fastly-Backend-Reqs
X-Cdn-Request-ID
X-Request-Url
Wpo-Cache-Status
X-Server-IP
X-Cache-Ngx
Wp-Super-Cache
X-Ips-Loggedin
Warning
CountryCode
Fastcgi-Cache-Ttl
Req-ID
CF-Cached-On
X-Ramcache
X-Test
X-DataCenter
X-Moov-T
WZWS-RAY
SRV
X-Mg-Cache
X-Moov-Xdn-Version
X-ElasticPress-Query