Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
Strict-Transport-Security
X-Frame-Options
X-Content-Type-Options
Last-Modified
Link
CF-Cache-Status
Cf-Request-Id
Accept-Ranges
ETag
Expect-CT
Pragma
CF-RAY
X-Powered-By
X-Cache
Via
X-XSS-Protection
Age
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Amz-Cf-Pop
X-Xss-Protection
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-FRAME-OPTIONS
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-Adblock-Key
CF-Ray
X-Permitted-Cross-Domain-Policies
X-AspNet-Version
X-Runtime
Alt-Svc
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Check
X-Cache-Status
X-Generator
X-DNS-Prefetch-Control
X-Cacheable
Timing-Allow-Origin
X-Iinfo
X-Envoy-Upstream-Service-Time
Feature-Policy
Status
X-Content-Security-Policy
X-Drupal-Dynamic-Cache
Content-Encoding
X-CDN
Access-Control-Expose-Headers
X-AspNetMvc-Version
Upgrade
X-XSS-PROTECTION
X-Dns-Prefetch-Control
X-Ua-Compatible
Access-Control-Max-Age
X-Request-ID
X-Via
Server-Timing
X-Cache-Group
X-Robots-Tag
Request-Context
X-UA-Device
Keep-Alive
X-Amz-Request-Id
X-AH-Environment
X-Turbo-Charged-By
X-Backend
P3p
X-Amz-Id-2
X-Proxy-Cache
X-Ws-Request-Id
X-Age
Host-Header
X-Server-Powered-By
X-Hacker
X-Server
X-Akamai-Path-Stats
X-Rq
EagleId
X-Vhost
X-Varnish-Cache
Grace
X-Amz-Version-Id
X-Dispatcher
X-LiteSpeed-Cache
Cf-Edge-Cache
Allow
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Nginx-Cache-Status
X-Device
X-Page-Speed
X-WebKit-CSP
X-Aws-Lambda-Call-Status
X-Host
X-OneAgent-JS-Injection
X-Node
X-Server-Id
EagleEye-TraceId
X-Pingback
X-Cache-Spec
Request-Id
Surrogate-Control
Cf-Railgun
X-Akam-SW-Version
X-Backend-Server
Accept-CH
X-Readtime
X-Cache-Lookup
X-Response-Time
Accept-CH-Lifetime
X-HW
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Content-Security-Policy-Report-Only
Content-Location
X-Application-Context
Rating
X-Trace
Fastly-Restarts
X-Cloud-Trace-Context
X-WebKit-CSP-Report-Only
X-Clacks-Overhead
X-Url
Accept-Ch-Lifetime
X-Country
X-Edge
X-Amz-Server-Side-Encryption
X-MS-InvokeApp
X-Rack-Cache
X-B3-TraceId
Edge-Control
X-TtlSet
X-PC
X-Vname
Accept-Ch
X-Ruxit-JS-Agent
X-Content-Type
X-ESI
X-Vcap-Request-Id
X-Nginx-Upstream-Cache-Status
X-Mod-Pagespeed
X-Varnish-TTL
Xkey
X-FastCGI-Cache
X-Exp-Id
X-Cdn-Fetch
X-Amz-Rid
X-GoogleNews-Bot
X-D2id
X-Exp-Variant
X-Kinja
X-Kinja-Server
X-Use-Magma
X-Kinja-Revision
X-Kinja-Build
X-Mcache
X-VARITI-CCR
X-ASPNET-VERSION
X-CST
Verso
X-GitHub-Request-Id
Cache-Tag
RTSS
X-Powered-By-Plesk
X-Ruxit-Js-Agent
X-ECACHE
X-Oneagent-Js-Injection
Service-Worker-Allowed
X-Cached
X-Upstream
X-Version
X-Client-IP
X-Navigation-Version
X-Abt-Application-Version
X-Dw-Request-Base-Id
X-Px
X-Cnection
X-Ac
Public-Key-Pins
Arr-Disable-Session-Affinity
X-Ser
X-Instrumentation
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-SharePointHealthScore
SPRequestGuid
X-Element-Page-Cache
Display
X-Server-Name
X-Sol
X-Middleton-Display
Pagespeed
SPIisLatency
X-Country-Code
SPRequestDuration
X-Cache-TTL
X-Ttl
X-NWS-LOG-UUID
X-NF-Request-ID
X-RateLimit-Remaining
X-Midtier
X-Cache-Key
Permissions-Policy
Response
X-Middleton-Response
X-Kinsta-Cache
X-Goog-Hash
X-Edge-Location-Klb
X-Forwarded-For
Access-Control-Request-Method
Content-MD5
X-DataDome
X-Shield-Request-Id
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-MSEdge-Ref
Front-End-Https
X-Powered-CMS
X-Correlation-Id
Edge-Cache-Tag
X-T
TP-L2-Cache
TP-Cache
X-Recruiting
AR-CACHE
AR-PoweredBy
X-Jurisdiction
X-HP-Webp
X-HP-Trace-Id
AR-ATIME
AR-Request-ID
AR-SID
Nginx-Cache
X-Accel-Expires
X-RateLimit-Limit
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
TCN
X-Daa-Tunnel
MicrosoftSharePointTeamServices
X-Grace
MRF-Tech
X-B3-TraceId-Primal
Mrf-Cache-Status
X-Mg-S
X-Id
X-TEC-API-ROOT
X-TEC-API-VERSION
X-Hits
X-TEC-API-ORIGIN
X-Request-Processing-Time
Filters
X-Request-Received
X-Content-Digest
X-HS-Hub-Id
X-HS-Cache-Config
Server-Node
X-HS-Content-Id
X-HS-Combine-CSS
Server-Name
S
X-Frontend
X-LLID
X-Fastly-Request-Id
X-TTL
X-Amzn-Trace-Id
X-Distributor
X-Webkit-Csp
Cache-Status
X-Protected-By
MS-Author-Via
X-Geo-Country
Fastcgi-Cache
X-PressLabs-Stats
X-LB-Cache
X-Request-Handler-Origin-Region
X-Microsite
X-Language
Cross-Origin-Opener-Policy
X-Origin-Server
X-Ezoic-Cdn
X-Seen-By
X-F-Cache
X-Forwarded-Proto
X-FB-Debug
X-Ab
Filterid
Charset
X-B3-Sampled
X-Ua-Browser
X-Page-Id
Host
X-XRDS-Location
X-Git-Hash
X-Amz-Meta-S3cmd-Attrs
Payment
X-Litespeed-Cache
X-Ratelimit-Reset
Count-Hit
Realpath
X-Cache-Age
X-Browser-Type
X-Erf-Bev-Bev-Is-Generated
X-Cluster-Name
X-VCache
X-Erf-Bev-Bev
Accept-Charset
X-Origin-Cache
Cf-Apo-Via
Surrogate-Key
X-DynaTrace
Alternate-Protocol
Cache-Tags
X-NGENIX-Cache
X-Rid
Retry-After
Cleartype
X-Az
X-Activity-Id
X-AppVersion
X-Template
X-Aspnetmvc-Version
X-Fastcgi-Cache
X-Www-Served-By
Access-Control-Allow-Method
X-Node-Name
X-Route-Name
X-Varnish-Backend
X-Wix-Request-Id
X-Aspnet-Duration-Ms
X-Flags
X-Is-Crawler
X-Request-Guid
X-Providence-Cookie
X-TT
X-Upgrade-Enabled
X-Signature
X-Type
X-Tb
X-Amz-Replication-Status
X-App-Environment
X-B-Cache
X-Varnish-Grace
X-Debug
X-B
X-Content
X-DIS-Request-ID
ServerID
DC
Paypal-Debug-Id
X-Drupal-Cache-Tags
X-Proxy
X-Logged-In
X-Tt-Trace-Tag
Frame-Options
X-Tt-Trace-Host
X-Hostname
X-Envoy-Decorator-Operation
X-Source
X-Mobile
X-Content-Options
X-Load-Cache
X-Revision
X-COUNTRY
Pinterest-Generated-By
X-Pinterest-Rid
Pinterest-Version
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-Goog-Generation
X-Goog-Storage-Class
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-N
X-Cache-Control
Amp-Access-Control-Allow-Source-Origin
X-Contextid
Country
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Magnolia-Registration
Referer-Policy
X-User-Agent
X-Cache-Rule
X-Whom
Viewport
NGB
X-EdgeConnect-Cache-Status
X-Response-Served-From
X-Original-Request-Id
X-Ratelimit-Remaining
Node
Refresh
Content-Disposition
X-Varnish-Age
X-Fastly-Request-ID
X-Restarts
X-Cache-TTL-Remaining
X-Cacheable-TTL
X-L-Path
X-Framework
X-Environment-Context
X-Debug-IsConnected
X-Page-View
X-Debug-IsPreview
Access-Control-Request-Headers
X-Rendered-As
X-Adobe-Content
X-NYM-Debug-Backend
X-Real-IP
X-G
X-Yottaa-Metrics
Url
Uber-Trace-Id
VIX-Pulpo-Node
X-Yottaa-Optimizations
X-Mg-Request-UUID
X-Jobs
VIX-Pulpo-Upstream-Status
X-Is-Bot
X-Varnish-Server
X-Instance
X-Akamai-Request-ID2
X-Servername
X-Cache-Grace
X-Unique-Id
Akamai-GRN
X-Mid
X-Adobe-Loc
X-Cache-Time
X-Status
X-Drupal-Cache-Contexts
X-Server-ID
X-Content-Powered-By
Countrycode
Version
X-Webkit-CSP
X-RemovedCookies
X-App-Server
X-ProcessESI
X-APP-VERSION
X-Debug-Info
X-Http-Reason
Srv
X-Oracle-Dms-Ecid
X-XRDS-LOCATION
X-CDN-Forward
X-Oracle-Dms-Rid
Protected
X-IPLB-Request-ID
X-IPLB-Instance
X-Hosted-By
Accept-Language
X-Tt-Logid
X-Trace-Id
X-Ratelimit-Limit
X-Cache-Expired-At
X-Nginx-Cache-Key
Liferay-Portal
X-Via-JSL
Healthy
Fastcgi-Useragent
X-Device-Type
X-Time
X-Cache-Hit
X-FW-Dynamic
X-FW-Server
X-FW-Type
X-FW-Static
X-FW-Serve
X-FW-Hash
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-Tumblr-User
X-Azure-Ref
X-Tumblr-Pixel
Section-Io-Cache
MS-CV
X-Backend-Name
X-UUID
Backend
X-RTag
Ms-Operation-Id
X-Cache-NGX
X-Proxy-Cache-Status
X-Cache-Operation
X-Mobile-URL
Content-Secure-Policy
Server-Info
Load-Balancing
Meta-Geo
X-UPSTREAM-Address
X-Storage
X-RN-RSRV
CF-IPCountry
X-Sql-Count
X-Content-Age
X-Mode
X-Handled-By
X-Sql-Duration-Ms
X-Datadome
X-HTML-Minification-Powered-By
Webcakes-Region
Webcakes-App-Version
Onion-Location
CDN-CachedAt
CDN-EdgeStorageId
CDN-PullZone
TWC-Connection-Speed
TWC-Device-Class
TWC-GeoIP-LatLong
CDN-Cache
TWC-Locale-Group
CDN-RequestCountryCode
CDN-RequestId
Property-Id
TWC-Privacy
Web-Mar-Node
Locale
Eomportal-Instance
CDN-Uid
S-Rt
Webcakes-App-Name
X-Locale
X-Server-W
X-ShardId
X-ShopId
X-Shopify-Stage
X-Section
X-VWS-Id
X-Say-Cacheable
X-Say-TTL
X-SayCDN-TTL
Azure-Version
X-Site-Version
X-VC-Cache
X-Urbn-Context-Path
X-Storefront-Renderer-Rendered
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Urbn-Site-Id
X-Uri
X-Varnishpool
X-Varnish-Hostname
X-Varnish-Cache-Hits
X-Skip-Cache
X-Region
X-Redis-Cache
X-Cache-Host
X-Cache-Server
X-Cms-Context
X-Edge-Location
X-Cache-Enabled
X-AWS-Id
X-Access
X-Adobe-Source
X-Akamai-Edgescape
X-Alternate-Cache-Key
X-Format
X-Forwarded-Host
X-PCL
X-PHP-Backend
X-PHP-Host
X-Proto
X-Origin-Hint
X-Origin-Date
X-Labrador-Cache-Channel
X-LJ-Flow-ID
X-No-Session
X-OCL
WP-Super-Cache
TWC-GeoIP-Country
Azure-InstanceId
X-URL
GEO-INFO
Azure-SiteName
Azure-RegionName
X-Zen-Fury
Azure-SlotName
X-GeoCode
X-Generation-Time
X-Hl-Ver
X-GeoCountry
X-Generated-By
X-Debug-Cache
X-Cache-Type
X-BYPASS-REASON
X-JoinUs
X-Detected-As
X-Extlb
X-FB-TRIP-ID
X-ProxyCache-Status
X-UA-Device-Type
X-Timing-Wait
X-Via-Fastly
X-Web-Node
X-Xfnlog-Site
X-ServerID
X-SaId
X-Proxy-Build
X-ProxyCache-Key
X-Request-Time
X-Routing-Service
X-Proxied
X-Zipkin-Id
Mn-Server-Ip
DB-Nickname
Selected-Fe
Apigw-Requestid
X-Correlation-ID
X-Tid
X-Cache-Status-Check
X-SRV
X-Varnish-Beresp-Grace
ServedBy
X-Rule
X-Cache-Action
X-LSADC-Cache
X-ECache
X-Ua
X-R9-Blue-Green-Version
Cross-Origin-Resource-Policy
Cache-Name
X-Ms-Version
X-Dc
X-Ms-Request-Id
X-DynaTrace-JS-Agent
X-Human
X-FireWall-Port
Cache
X-Nginx-Cache
X-Cache-Tags
Xet-Cookie
SD-X-WS
X-Amzn-RequestId
X-Cached-By
X-Amz-Apigw-Id
Source
Xserver
LB
Cross-Origin-Window-Policy
X-WP-CF-Super-Cache
X-RCS-CacheZone
X-WP-CF-Super-Cache-Cache-Control
X-Cdn
X-Loop
X-Varnish-Hits
X-Via-NSCOPI
X-GEO
X-TNCMS
X-MP-GENERATED-AT
Origin
X-NewRelic-App-Data
WPO-Cache-Status
WPO-Cache-Message
X-GG-Cache-Date
X-Reqid
X-App-Version
X-IPS-LoggedIn
X-Origin-TTL
X-Origin-CC
X-Pubstack
X-TA-CDN-Provider
X-Soup
X-Amzn-Remapped-Content-Length
X-AOL-HN
X-B3-SpanId
X-Api-Version
Cache-Hits
X-FW-Version
X-Tumblr-Pixel-2
X-TIME
From-Origin
Rip
X-Platform-Server
X-Newrelic-Synthetics
X-Service
X-Cluster-Node
X-Vgn-Hpd-Reason
Upgrade-Insecure-Requests
Webserver
X-Request-Host
Expiry
X-Orig-Expires
X-Cache-NE
Environment
X-NAPM-TraceId
DCR-Decision-By
DCR-Processing-Time-Ms
X-User
Surrogated-Key
X-ScT
X-Bc-Bl
X-Owner
X-Accel-Buffering
X-Session-Fingerprint
X-BCube-Filmed-By
Xc-Version
X-Connection-Hash
X-D
X-External-Request-Id
A
X-Ec-GeoHdr
X-Forwarded-Path
X-Provided-By
X-VG-WebCache
X-SRCache-Key
X-Ec-Fail
BehaviorPad-Version
X-Vdms-Path
Cdnsip
X-Shop-Environment
Cdncip
X-Developer
X-Destination
X-B-Cookie
X-Served-From
Odigeo-Trace-Id
X-Tenant
X-A-Ccd
X-A-Dam
Ngx.Var.Host
X-S-Cookie
X-A-Dcw
X-A
X-Rewrite-Enabled
T-Server
X-Rojux
X-S
Sslversion
Rendered-Blocks
X-Vdms-Version
Redirect-Candidate
Host-ID
X-A-Dgt
X-Aed
X-PBS-Appsvrname
Lang
X-ARC
X-TIM-N
X-Application
X-AK-Request-ID
MD5-Digest
X-Origin-Response-Time
Meta-Geo-Continent
X-Processor
X-A-Wwc
X-Cluster
OT-Force-Account-Verify
X-Varnish-Beresp-Ttl
Fastly-SSL
X-Generated-On
X-Bip
Decoy-Debug-Status
Mobile-Detection-Method
Decoy-Debug-Key
Decoy-Debug-TTL
Machine
X-Dispatcher-Number
Candidate-Md5Url
X-Aicache-OS
X-Forwarded-Site
X-Pool
X-Thanos
X-Qloud-Router
X-Irp-Debug
X-Level-Front-Cache
X-Wix-Viewer-Type
X-Thinkindot-L3
X-Policy
X-Scale
X-SB
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-Ad-Defer-Variation
X-Cdn-Srv
X-Optimistic-Header
X-Cdn-Origin
X-S-Maxage
X-Planisys-CDN-Cache
X-Auto-Login
X-Cache-Bucket
X-Branch-Name
X-Cache-Id
X-Cache-Info
X-Origin
X-Origin-Expires
X-VG-TLSProxy
X-Worker
X-Parent-Response-Time
X-Proxy-Cache-Info
X-BBC-Edge-Cache-Status
X-Origin-Time
X-CacheTTL
X-RateLimit-Limit-Second
Tube-Got-Results
Tube-Got-Eval
X-SVT-ORM-VERSION
Tube-Return
X-Rocket-Nginx-Serving-Static
Tube-Get-Contents
Traceparent
TDXMobile
X-WA-Info
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
Thinkindot-Control
V-Age
Vix-Hermes-Req-Id
X-Region-Sid
X-Request-URI
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-RateLimit-Remaining-Second
Wxu-Next-Region
Wxu-Next-Hostname
VNS-Cache
VNS-Age
We-Hiring
Web-Mar-Region
X-Rocket-Build-Number
X-Nyt-Route
X-Ckpd-Fst-Backend
X-Hash
X-Fmm-Version
X-WADP-Cache
X-Gamma-Serve
X-Gateway-Cache-Key
X-Slack-Backend
X-Fetched-On
X-Fastly-Cache
X-INCAP-ABP
X-Epic-Correlation-Id
X-Esi-Check
X-Eu-Site
X-HS-Content-Campaign-Id
X-SplitTest
X-Gateway-Cache-Status
X-SIPLIST1
X-Viewer-Country
X-Sn-Servicetimems
X-Geo-Header
X-GeoIP
X-SVT-ORM-RULES
X-Gzip
X-Has-Esi
X-Gateway-Request-Id
X-Gateway-Skip-Cache
X-Gdpr
X-VServer
X-Is-Gdpr
X-Ec-Custom-Error
X-Loc
X-Clientip
X-Core-Mission
X-Core-Value
X-Datadog-Parent-Id
X-Csrf-Jwt
X-Minions-Version
X-Mvc-Supplant-Cachable
X-Clara-WADP
X-GeoIP-City
X-NodeID
X-V-Cache
X-Mvc-Supplant-OutputCached
X-Datadog-Sampling-Priority
X-Datadog-Trace-Id
X-Device-Os
X-Developers
X-Varnish-Remaining-TTL
X-Sigma-Backend
X-DPWN-IS-SECURE
X-Varnish-CookieINHashed-On
X-Varnish-CookieHashed-On
X-Variation
X-DefElseHash
X-JWT-State
X-DefHash
X-Sigma
X-CGP
Wxu-Next-Commit
L
L5d-Success-Class
Cmsid
Cmstype
Country-Code
Cluster
Mail-Subject
NM-Fastcgi-Cache
NGX
Click-Count-Error
Memcached
Kp-EeAlive
IsBot
DSUID
Datacenter
Fastly-Backend-Name
Fastly-SWR
Fastly-GeoIP-CountryCode
CPC-Cache
Gh-Request-Id
Is-Eu
CPC-Age
HA-Ipaddr
Ha-Gx-Prefs
Click-Count-Action-Start
Cache-Tv-Group
Release
X-Ua-Device
Fastly-SIE
Req-Svc-Chain
State
X-CSRF-Token
HostName
Server-Host
Producers
Adler-Geo
Origin-EX
Origin-CC
Cache-Host
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
Apple-News-Services-Handled
Servername
Platform
Apple-News-Services-Host
WebServer
X-Tx-Id
X-VC
X-Xrds-Location
X-Cache-Remote
Mime-Version
Sever-Int
X-Scheme
X-Hnp-Log
X-Gen-Mode
CloudFront-Viewer-Country
CDCHOST
X-Pod-Name
Svr
Server-Ext
X-Block-Status
AKAMAI
Server-Hostname
Fastcgi-Cache-TTL
X-NWS-UUID-VERIFY
User-Cache-Control
X-NCache
X-Varnish-Beresp-Status
X-LB-NoCache
X-Varnish-Ttl
X-Udemy-Cache-App-Namespace
Ec-Rule-Version
Canary
X-CMSURLCustom
SID
X-Cache-Date
X-Ig-Push-State
Pics-Label
X-ZONE
Ssr
X-Microcachable
X-Tb-Optimization-Total-Bytes-Saved
X-Yandex-Sdch-Disable
X-Conf
X-Sucuri-Cache
X-Sucuri-ID
Memory
Time
Sid
X-Var-Ttl
X-Azure-Ref-OriginShield
X-FC-Vary-Parameters
X-ATG-Version
X-Fastly-Backend
X-WP-CF-Super-Cache-Active
X-Generated-In
Fastly-Drupal-Html
X-Cache-Debug
X-ND-Cache
AMP-Access-Control-Allow-Source-Origin
X-Tec-Api-Version
X-B3-Traceid
X-Tec-Api-Root
X-Akamai-Transformed
X-Tec-Api-Origin
X-Presslabs-Stats
X-Dmc
X-TRACE-ID
X-Refresh
Server-ID
X-Edge-Pop
X-Via-Poph
X-Via-Popv
X-Via-Popn
X-Servedbyhost
X-Be
Env
X-Cs
X-Trace-ID
X-Air-Hostname
X-Fpc
X-CS
X-NC
X-Newrelic-App-Data
X-Air-Trace-Id
X-MSEdge-Features
Fastly-Drupal-HTML
X-MSEdge-Flight
X-Release
X-Air-Source
X-Buckets
X-Esi
X-PX
GeoIp-Country-Code
X-ID
X-MCACHE
X-Endurance-Cache-Level
Magicmarker
X-Wikidot-Static-Cache
X-Zone
X-Wikidot-Backend
X-EC-Lua
X-NGINX-Cache
CDN
X-DC
X-CACHE-AGE
True-Client-IP
X-Up
X-RateLimit-Reset
X-Tumblr-Pixel-3
X-TX-ID
X-Hyper-Cache
X-VCL-Version
My-App
X-Wa
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-Dispatch
X-Vc
X-Pass-Why
X-CSRF-TOKEN
X-Webkit-CSP-Report-Only
Hostname
X-Srv
X-M-Log
X-M-Reqid
Pramga
X-Micro-Cache
X-App
X-Lambda-Id
X-CACHE-KEY
C-Via
X-Alfa-Service
X-Qnm-Cache
N-Cache
X-TrackingId
X-Req
X-Varnish-Beresp-TTL
X-Edge-Origin-Shield-Region
X-PAYTM-SRV-ID
Path
On-Server
X-Edge-Origin-Shield-Bytes
X-Vcl-Version
Fastcgi-X-Cache-Version
X-Platform
X-Air-Pt
Resin-Trace
CacheControlHeader
X-TH-Server
X-Check-Cacheable
X-HS-Status
True-Client-Ip
Esi-Enabled
X-Vercel-Cache
Tcn
X-Vercel-Id
X-Vtex-Processado-Em
X-AIR-PT
X-LB-ID
True-Client-Country-4JS
GeoIP-Country-Code
GeoIP-Latitude
X-B3-Spanid
Tracecode
X-Vtex-Remote-Cache
X-Nf-Request-Id
X-SERVER-NAME
X-PERF
NtCoent-Length
X-ApacheServer
X-Node-Id
X-Request-Start
X-API-Version
X-SD-PageType
X-Op-Id-All
Proxy-Connection
X-LAGOON
X-Akamai-Pragma-Client-IP
X-CLOUD-TRACE-CONTEXT
Cdn
Cache-Key
Section-Io-Origin-Time-Seconds
X-FPC
X-Mly-Id
Section-Io-Origin-Status
HIT
Hit
Section-Io-Id
Section-Origin-Responded
DT-Hot-News
X-Webkit-Csp-Report-Only
X-Via-CDN
ENV
X-Geo
DynaTrace
X-Platform-Cluster
XkeyRZ
X-Platform-Processor
X-Platform-Router
X-Proxy-CacheRZ
X-Render-Time
X-Lb-Id
X-GeoIP-Country-Code
X-GeoIP-Region-Code
X-WA
X-Dw-Trace-Id
Server-Id
X-Via-PopV
X-Via-PopN
X-Proxy-Upstream
X-Edge-POP
X-Date
X-Via-PopH
X-Datacenter
XM
Lb
User-Agent
X-Via-Ucdn
X-ServedByHost
X-VarnishDD-TTL
PFcat
WWW-Authenticate
X-HN
X-Traceid
X-Accel-Expires-Debug
X-Cdn-Forward
YJS-ID
Server-Ttl
X-LiteSpeed-Cache-Control
X-RAMCache
X-Proxy-Cache-Hk
X-DB
X-Li-Pop
X-LI-UUID
X-LI-Proto
X-RSL
X-DW
X-DSS
X-RPM
X-RPS
X-DI
X-Li-Fabric
X-FORWARDED-FOR
X-Cache-Ttl
X-Wp-Cf-Super-Cache
X-CF-Powered-By
MIME-Version
X-LiteSpeed-Tag
SRV
X-Wp-Cf-Super-Cache-Cache-Control
X-CUA
Dnion-Transfer-Encoding
Yjs-Id
Geoip-Latitude
X-TT-LOGID
PICS-Label
Location
X-Cache-Backend
M-TraceId
Ohc-File-Size
Wpo-Cache-Status
Wpo-Cache-Message
XServer
X-Ftr-Request-Id
Nginx-CQVIP
X-Nc
X-Fastly-Backend-Reqs
Vha6-Origin
X-Instance-Name
X-Response-By
X-Akamai-ERRuleID
X-Akamai-ERPolicy
X-Old-Content-Length
X-Service-Response-Time
FSS-Cache
Sm-Log-Id
X-UA
X-Litespeed-Cache-Control
X-Fastly-Cache-Hits
Powered-By
X-Mg-Cache
X-Akamai-Request-ID
X-Cc-Via
X-B3-ParentSpanId
X-Lb-Nocache
X-HA-Backend
X-Httpd
X-Cdn-Request-ID
X-IN-APIGATEWAYSSL
X-IN-APIGATEWAY
X-HostName
X-Request-Url
CountryCode
X-Cache-Ngx
Warning
Locid
X-Moov-Xdn-Version
Srvid
X-FL-EDGE
X-Webstats-RespID
X-From
X-Moov-T
X-DataCenter
Req-ID
Uri
X-Serial
Ohc-Cache-HIT
X-Server-IP
X-MiniProfiler-Ids
WZWS-RAY
Fastcgi-Cache-Ttl
X-Snapshot-Date