Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Accept-Ranges
Expect-CT
X-XSS-Protection
CF-RAY
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
P3P
X-Xss-Protection
X-Served-By
X-Download-Options
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Request-Id
Access-Control-Allow-Credentials
X-Request-ID
CF-Ray
X-Permitted-Cross-Domain-Policies
X-AspNet-Version
Alt-Svc
Content-Security-Policy-Report-Only
X-Runtime
X-DNS-Prefetch-Control
X-Drupal-Cache
X-Check
X-Cache-Status
X-Generator
X-Cacheable
P3p
Timing-Allow-Origin
X-FRAME-OPTIONS
X-Iinfo
X-Envoy-Upstream-Service-Time
X-Content-Security-Policy
X-Drupal-Dynamic-Cache
Feature-Policy
Content-Encoding
Upgrade
Status
Access-Control-Expose-Headers
X-AspNetMvc-Version
X-CDN
Access-Control-Max-Age
X-Via
Server-Timing
X-UA-Device
X-Robots-Tag
Request-Context
X-Turbo-Charged-By
X-Cache-Group
X-Amz-Request-Id
EagleId
X-Amz-Id-2
X-Backend
Keep-Alive
X-AH-Environment
X-Proxy-Cache
X-Ws-Request-Id
X-Server
X-Age
X-Hacker
Host-Header
X-Ua-Compatible
Cf-Edge-Cache
X-Vhost
X-Server-Powered-By
X-Rq
Allow
X-Dispatcher
X-Varnish-Cache
Grace
X-Amz-Version-Id
X-LiteSpeed-Cache
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-OneAgent-JS-Injection
X-WebKit-CSP
Accept-CH
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
Cf-Apo-Via
X-Page-Speed
Cf-Railgun
X-Aws-Lambda-Call-Status
X-Server-Id
X-Host
X-Pingback
X-Node
X-Cache-Spec
X-Nginx-Cache-Status
X-Akam-SW-Version
Surrogate-Control
X-Dns-Prefetch-Control
X-Backend-Server
EagleEye-TraceId
X-Cache-Lookup
Request-Id
X-Readtime
X-Ruxit-JS-Agent
X-HW
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Cloud-Trace-Context
Accept-Ch-Lifetime
X-Content-Security-Policy-Report-Only
X-Application-Context
X-Trace
X-Response-Time
X-CST
Permissions-Policy
X-Mod-Pagespeed
X-Nginx-Upstream-Cache-Status
Fastly-Restarts
X-Edge
X-Country
Content-Location
Accept-CH-Lifetime
X-Content-Type
X-WebKit-CSP-Report-Only
X-Mcache
X-ECACHE
Rating
X-Url
X-Clacks-Overhead
X-MS-InvokeApp
X-TtlSet
X-Vname
X-PC
X-Amz-Server-Side-Encryption
X-Midtier
X-VARITI-CCR
RTSS
Cache-Tag
X-Varnish-TTL
X-Vcap-Request-Id
X-Element-Page-Cache
X-Ac
Verso
Origin-Trial
X-B3-TraceId
X-Kinja-Build
X-Exp-Variant
X-Cdn-Fetch
X-Exp-Id
X-Use-Magma
X-D2id
X-Kinja-Revision
X-Kinja-Server
X-GoogleNews-Bot
X-Kinja
X-Server-Name
X-Rack-Cache
X-Cnection
X-Cache-TTL
X-Powered-By-Plesk
Service-Worker-Allowed
X-ESI
Xkey
X-GitHub-Request-Id
X-Abt-Application-Version
X-Client-IP
X-Navigation-Version
X-NWS-LOG-UUID
Edge-Control
X-SharePointHealthScore
SPRequestGuid
X-Amz-Rid
X-Cached
X-Fastcgi-Cache
X-Px
X-Mg-S
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Browser-Type
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-Instrumentation
Arr-Disable-Session-Affinity
X-Ttl
X-Upstream
SPIisLatency
SPRequestDuration
X-Cache-Key
X-Middleton-Display
Display
Pagespeed
X-Sol
X-Litespeed-Cache
Content-MD5
X-Dw-Request-Base-Id
X-Correlation-Id
X-SRCache-Store-Status
X-SRCache-Fetch-Status
Access-Control-Request-Method
X-RateLimit-Remaining
Edge-Cache-Tag
X-Goog-Hash
X-Daa-Tunnel
Front-End-Https
X-Country-Code
Public-Key-Pins
X-XRDS-Location
X-Version
X-NF-Request-ID
X-Forwarded-For
X-Powered-CMS
AR-CACHE
AR-PoweredBy
AR-Request-ID
AR-ATIME
AR-SID
X-Id
X-Jurisdiction
X-HP-Webp
TCN
X-HP-Trace-Id
X-MSEdge-Ref
X-Recruiting
X-T
X-Content-Digest
X-Accel-Expires
Response
X-Middleton-Response
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
X-Ser
X-Shield-Request-Id
TP-Cache
TP-L2-Cache
Nginx-Cache
S
X-Fastly-Request-ID
X-Hits
X-Amzn-Trace-Id
X-Request-Received
X-Request-Processing-Time
X-Kinsta-Cache
X-Edge-Location-Klb
Cache-Status
Server-Node
X-HS-Hub-Id
X-HS-Combine-CSS
X-HS-Content-Id
X-HS-Cache-Config
X-Distributor
X-TTL
X-Grace
Cache-Tags
Alternate-Protocol
MicrosoftSharePointTeamServices
Server-Name
Fastcgi-Cache
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-Protected-By
X-DataDome
X-DIS-Request-ID
X-Ezoic-Cdn
X-Geo-Country
X-Ruxit-Js-Agent
X-LB-Cache
X-Origin-Server
X-Microsite
X-Frontend
X-Request-Handler-Origin-Region
X-Ua-Browser
X-Rid
X-Ratelimit-Limit
X-Debug-Info
Cross-Origin-Opener-Policy
Healthy
X-Forwarded-Proto
X-Git-Hash
X-Varnish-Backend
X-NGENIX-Cache
X-Www-Served-By
Payment
Filterid
X-Logged-In
X-FB-Debug
Cleartype
X-Page-Id
X-PressLabs-Stats
X-Ratelimit-Reset
X-Load-Cache
Charset
X-B3-Sampled
X-VCache
Content-Disposition
X-Webkit-Csp
X-ASPNET-VERSION
X-Origin-Cache
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-LLID
X-Cluster-Name
MS-Author-Via
DC
X-Hostname
X-Goog-Metageneration
X-GUploader-UploadID
X-Ratelimit-Remaining
X-RateLimit-Limit
Accept-Charset
X-Upgrade-Enabled
Access-Control-Allow-Method
Retry-After
Cross-Origin-Resource-Policy
X-Proxy
X-F-Cache
X-Oracle-Dms-Rid
X-Oracle-Dms-Ecid
X-Activity-Id
X-Az
X-AppVersion
X-Contextid
X-Route-Name
X-Signature
X-B-Cache
X-Type
Accept-Ch
X-Providence-Cookie
X-Seen-By
X-Amz-Replication-Status
X-Aspnet-Duration-Ms
X-Flags
X-Hosted-By
X-Revision
X-Request-Guid
X-Is-Crawler
X-Varnish-Server
X-TT
X-Wix-Request-Id
X-B
X-Amz-Meta-S3cmd-Attrs
Referer-Policy
X-Azure-Ref
X-Whom
X-App-Environment
Paypal-Debug-Id
Amp-Access-Control-Allow-Source-Origin
Viewport
Surrogate-Key
X-DynaTrace
X-FastCGI-Cache
X-Source
X-Aspnetmvc-Version
Count-Hit
X-Fb-Rlafr
X-ORACLE-DMS-ECID
Realpath
X-Tt-Trace-Tag
X-ORACLE-DMS-RID
X-Tt-Trace-Host
X-Akamai-Edgescape
X-Mobile
X-App-Server
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Goog-Generation
X-B3-Traceid
Host
X-Cache-Control
X-EdgeConnect-Cache-Status
X-Cache-Age
X-HTML-Minification-Powered-By
X-Original-Request-Id
Refresh
X-Response-Served-From
X-N
Version
X-Nginx-Cache
X-Varnish-Grace
X-Cache-Rule
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Tumblr-User
X-Tumblr-Pixel-1
X-Oneagent-Js-Injection
Access-Control-Request-Headers
Section-Io-Cache
X-Varnish-Age
SD-X-WS
X-Envoy-Decorator-Operation
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Magnolia-Registration
X-Cache-Expired-At
X-UUID
X-Cache-Time
X-Cache-Status-Check
X-Adobe-Loc
X-RTag
X-Environment-Context
X-Page-View
MS-CV
Ms-Operation-Id
X-Adobe-Content
X-L-Path
X-Newrelic-App-Data
X-G
X-Jobs
X-Is-Bot
X-Framework
NGB
X-Cacheable-TTL
X-Device-Type
X-ProcessESI
X-RemovedCookies
X-Rule
X-Status
X-Content-Powered-By
Protected
X-Rendered-As
X-Servername
GEO-INFO
X-Cache-Grace
X-FW-Hash
X-FW-Dynamic
Akamai-GRN
X-Akamai-Request-ID2
X-FW-Serve
X-FW-Server
X-NYM-Debug-Backend
X-Http-Reason
X-FW-Version
X-FW-Type
Url
X-FW-Static
X-Debug-IsPreview
X-Backend-Name
X-User-Agent
X-Debug-IsConnected
X-Instance
X-CDN-Forward
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Tb
CDN-RequestId
X-Cache-Hit
X-Drupal-Cache-Contexts
X-Drupal-Cache-Tags
X-Tt-Logid
SRV
Pinterest-Generated-By
From-Origin
X-Pinterest-Rid
Pinterest-Version
WPO-Cache-Status
Country
WPO-Cache-Message
X-Node-Name
X-Region
Accept-Language
X-Trace-Id
Front
X-URL
X-Real-IP
Fastly-Drupal-HTML
X-Time
X-VC-Cache
Uber-Trace-Id
X-Template
Backend
X-Mode
X-Content-Options
X-Language
X-Amz-Apigw-Id
X-Amzn-RequestId
Meta-Geo
X-Generation-Time
X-Cache-Operation
Filters
X-RN-RSRV
X-Rewrite-Enabled
X-UPSTREAM-Address
Fastly-SIE
Fastly-SWR
Webserver
CDN-PullZone
X-DynaTrace-JS-Agent
CDN-CachedAt
CDN-RequestCountryCode
CDN-Uid
X-Cache-TTL-Remaining
X-Web-Node
CDN-Cache
CDN-EdgeStorageId
X-Tumblr-Pixel-2
Content-Secure-Policy
X-Say-Cacheable
X-Cache-Action
X-Cms-Context
X-IPS-LoggedIn
X-Sql-Count
X-Adobe-Source
Cross-Origin-Window-Policy
X-Say-TTL
Apigw-Requestid
CF-IPCountry
X-Proxy-Cache-Status
X-SayCDN-TTL
X-Format
Azure-Version
X-WP-CF-Super-Cache
Azure-SlotName
X-Proxy-Cache-Info
X-Sql-Duration-Ms
X-Cache-Server
X-WP-CF-Super-Cache-Cache-Control
X-Access
Azure-RegionName
X-Rocket-Nginx-Serving-Static
Azure-SiteName
X-Section
Azure-InstanceId
X-ProxyCache-Key
X-Reqid
X-Cache-Host
X-ProxyCache-Status
Node
X-PHP-Host
X-PHP-Backend
X-Ms-Request-Id
X-Varnish-Beresp-Grace
X-Ms-Version
Cache-Name
X-LJ-Flow-ID
X-Zen-Fury
X-Via-Fastly
X-Unique-Id
X-Labrador-Cache-Channel
X-Sucuri-Cache
X-AWS-Id
X-GeoCountry
X-Skip-Cache
X-Soup
X-BYPASS-REASON
X-Sucuri-ID
X-Edge-Location
X-UA-Device-Type
X-Content-Age
X-GeoCode
X-Debug
X-VWS-Id
ServerID
X-Cluster
X-Forwarded-Host
X-IPLB-Request-ID
TWC-Privacy
Webcakes-App-Name
X-No-Session
X-JoinUs
X-Extlb
X-Detected-As
X-Locale
X-Site-Version
Onion-Location
Property-Id
TWC-Connection-Speed
X-Urbn-Context-Path
X-Xfnlog-Site
X-Zipkin-Id
TWC-GeoIP-LatLong
S-Rt
TWC-GeoIP-Country
X-IPLB-Instance
X-SaId
X-Routing-Service
X-Proto
X-Proxied
Webcakes-Region
X-Urbn-Site-Id
Webcakes-App-Version
TWC-Locale-Group
Web-Mar-Node
TWC-Device-Class
X-Server-W
X-Origin-Hint
X-R9-Blue-Green-Version
X-Amzn-Remapped-Content-Length
X-LAGOON
X-Cluster-Node
Locale
X-Handled-By
Mn-Server-Ip
X-Ua
X-Fastly-Request-Id
X-Proxy-Build
WP-Super-Cache
X-Timing-Wait
Selected-Fe
X-LSADC-Cache
Fastcgi-Useragent
DB-Nickname
Cache-Hits
X-Request-Time
X-Hl-Ver
X-FB-TRIP-ID
Xserver
X-Tec-Api-Version
X-Tec-Api-Root
X-Tec-Api-Origin
Liferay-Portal
X-Redis-Cache
X-Cache-Debug
Mime-Version
ServedBy
X-Tumblr-Pixel-3
X-TIME
Upgrade-Insecure-Requests
X-SRV
X-TNCMS
X-Optimistic-Header
X-NWS-UUID-VERIFY
X-XRDS-LOCATION
X-Loop
Source
X-Generated-By
X-GEO
Countrycode
X-Origin-Date
X-Mg-Request-UUID
X-Air-Hostname
X-Air-Trace-Id
X-Varnish-Hits
X-Tid
X-Air-Source
CF-Cached-On
X-Storage
X-Uri
X-Times
X-Varnish-Beresp-Ttl
X-Director
X-CACHE-AGE
X-Akamai-Transformed
X-Cdn
Xet-Cookie
X-COUNTRY
X-Tx-Id
X-TA-CDN-Provider
X-Webkit-CSP-Report-Only
X-Pass-Why
Frame-Options
X-Trace-ID
X-Origin-TTL
X-Origin-CC
X-Newrelic-Synthetics
X-ARC
X-DC
X-B3-Spanid
X-Service
X-FireWall-Port
X-ECache
X-AIR-PT
X-Esi
X-App-Version
X-Alternate-Cache-Key
X-Varnish-Cache-Hits
Environment
X-ShopId
X-Storefront-Renderer-Rendered
X-ShardId
X-Shopify-Stage
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Datadog-Trace-Id
X-Varnish-Hostname
X-Datadog-Parent-Id
X-Datadog-Sampled
X-Datadog-Sampling-Priority
SID
X-Presslabs-Stats
Server-Info
X-Endurance-Cache-Level
X-B-Cookie
X-Destination
X-Vdms-Path
X-Ec-Fail
X-Developer
X-BBC-Edge-Cache-Status
X-Bc-Bl
X-Cache-Info
X-Cache-NE
X-D
Ngx.Var.Host
X-Request-Host
X-BCube-Filmed-By
DCR-Processing-Time-Ms
Edge-Cache
DCR-Decision-By
Odigeo-Trace-Id
T-Server
Surrogated-Key
BehaviorPad-Version
Origin
A
Sslversion
Req-Svc-Chain
Release
MD5-Digest
Rendered-Blocks
Candidate-Md5Url
WWW-Authenticate
X-A
X-A-Wwc
X-Epic-Correlation-Id
X-Aed
Meta-Geo-Continent
X-Application
Gannett-Cam-Experience-Id
X-A-Dgt
X-A-Ccd
Lang
X-A-Dam
X-A-Dcw
Redirect-Candidate
X-Ec-GeoHdr
X-Processor
X-Rojux
X-External-Request-Id
X-Platform-Router
X-Platform-Processor
X-Origin-Time
X-Platform-Cluster
X-S-Cookie
X-S-Maxage
X-VG-TLSProxy
X-Vdms-Version
X-TIM-N
X-SRCache-Key
X-ScT
Xc-Version
X-Nyt-Route
X-S
X-Mid
X-Gdpr
X-Mobile-URL
X-Loc
X-ServerID
State
X-Sigma-Backend
X-Fmm-Version
X-Sn-Servicetimems
X-WP-CF-Super-Cache-Active
Host-ID
X-Sigma
Tube-Got-Results
Tube-Return
Tube-Got-Eval
Tube-Get-Contents
X-Served-From
X-Gamma-Serve
X-SVT-ORM-RULES
X-Varnish-CookieINHashed-On
Memcached
Magicmarker
X-Varnish-Remaining-TTL
X-WA-Info
X-Ec-Custom-Error
X-Varnish-CookieHashed-On
Vix-Hermes-Req-Id
X-WADP-Cache
X-SVT-ORM-VERSION
Fastly-GeoIP-CountryCode
X-Thinkindot-L3
X-VServer
X-GeoIP-City
X-CUA
X-Origin-Response-Time
X-CMSURLCustom
X-DefElseHash
X-Platform-Server
X-Old-Content-Length
X-Core-Value
X-NodeID
X-Cdn-Origin
X-Core-Mission
X-Cache-Bucket
X-Frame-Option
DSUID
X-Req
X-DefHash
Thinkindot-CacheControl
X-SB
X-We-Are-Hiring
TDXMobile
Thinkindot-CacheControl-Type
X-Httpd
X-Akamai-Device-Characteristics
X-Rocket-Build-Number
X-Human
X-INCAP-ABP
Thinkindot-Control
X-SD-PageType
X-Clara-WADP
Cache-Host
C-Via
Click-Count-Action-Start
Click-Count-Error
Cluster
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
Decoy-Debug-TTL
X-Buckets
Cache-Tv-Group
Apple-News-Services-Handled
Apple-News-Services-Host
Country-Code
X-Pubstack
Decoy-Debug-Status
Decoy-Debug-Key
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
X-Parent-Response-Time
Section-Io-Id
X-JWT-State
X-Location
X-App
X-Restarts
X-Is-Gdpr
X-Bip
X-Cache-FS-Status
X-HS-Content-Campaign-Id
Fastly-Backend-Name
X-Block-Status
X-Test
X-Node-Id
X-Origin
X-Gen-Mode
X-GeoIP-Country-Code
We-Hiring
X-Worker
X-Accel-Buffering
X-GeoIP
X-Ad-Defer-Variation
X-Accel-Expires-Debug
X-Cache-Id
X-GeoIP-Region-Code
X-Auto-Login
X-DPWN-IS-SECURE
X-Dispatcher-Number
X-LB-NoCache
X-Esi-Check
X-Wix-Viewer-Type
X-Fetched-On
X-Fastly-Backend
Server-Host
X-Cdn-Srv
X-Minions-Version
X-Geo-Header
Adler-Geo
X-Has-Esi
X-Gzip
X-Developers
X-Vmg-Version
X-Hash
X-Date
X-Scale
X-Hnp-Log
X-CSRF-Token
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
Server-Hostname
Server-Ext
Sever-Int
Cache-Provider
CloudFront-Viewer-Country
Cache-Key
Pics-Label
X-Planisys-CDN-TTL
NM-Fastcgi-Cache
Producers
Origin-CC
Origin-EX
Platform
X-Pool
X-Thanos
X-Up
CDCHOST
X-Generated-On
X-Slack-Backend
Ssr
X-Request-Start
X-Level-Front-Cache
X-Varnish-Beresp-Status
Mail-Subject
Kp-EeAlive
User-Cache-Control
L
X-Variation
Cmstype
Svr
X-Var-Ttl
Is-Eu
Cmsid
Cdn
X-RM-Cache-TTL
Machine
X-Device-Os
PFcat
X-Irp-Debug
X-Refresh
X-Server-IP
X-FC-Vary-Parameters
Web-Mar-Region
X-Forwarded-Site
CacheControlHeader
Gh-Request-Id
X-Cache-Backend
X-HN
X-Region-Sid
X-Dispatcher-Server
X-CacheTTL
Datacenter
AKAMAI
X-Conf
X-Aicache-OS
X-Nginx-Cache-Key
X-Op-Id-All
Fastly-SSL
Wxu-Next-Hostname
Wxu-Next-Commit
Wxu-Next-Region
X-VarnishDD-TTL
X-Varnishpool
X-Owner
X-NCache
X-Cache-Tags
X-Ckpd-Fst-Backend
X-Qloud-Router
X-Slack-Shared-Secret-Outcome
X-Platform
X-Mvc-Supplant-Cachable
X-V-Cache
X-Nananana
X-Azure-Ref-OriginShield
HostName
X-Via-Poph
X-Via-Popn
X-Varnish-Ttl
X-Via-Popv
X-Csrf-Jwt
On-Server
X-Cache-Remote
X-CGP
X-Cached-By
X-Men
X-Org
L5d-Success-Class
HA-Ipaddr
Ha-Gx-Prefs
Canary
X-Eu-Site
NGX
X-HA-Backend
Cdncip
X-Mvc-Supplant-OutputCached
GeoIP-Latitude
X-AK-Request-ID
X-Tb-Optimization-Total-Bytes-Saved
Cdnsip
X-Servedbyhost
X-VC
Env
X-Cache-Date
X-Correlation-ID
Server-ID
X-Gateway-Cache-Key
X-Gateway-Cache-Status
X-Gateway-Skip-Cache
X-Gateway-Request-Id
X-Microcachable
X-RCS-CacheZone
X-API-Version
X-LB-ID
X-Nf-Request-Id
Cache
X-Wa
X-APP-VERSION
X-ZONE
X-Mly-Id
X-Fpc
X-Zone
X-Vgn-Hpd-Variations-Key
X-Server-ID
X-Vgn-Hpd-Cached
X-Generated-In
Memory
X-Vgn-Hpd-Ssi
Time
Request-ID
X-Webkit-CSP
Ngx-Var-Key
X-Micro-Cache
X-DataCenter
X-Via-NSCOPI
X-Nc
Eomportal-Instance
OT-Force-Account-Verify
X-Fastly-Cache
Load-Balancing
X-Origin-Expires
X-ND-Cache
X-HS-Status
X-Instance-Name
X-VCL-Version
X-Release
X-Response-By
X-Srv
X-SIPLIST1
X-Request-URI
X-Check-Cacheable
X-Vc
X-Client-Ip
IsBot
X-Via-JSL
Srv
X-From
X-Cache-NGX
Srvid
Expect-Staple
X-CCDN-CacheTTL
X-Hcs-Proxy-Type
X-FL-EDGE
X-CCDN-Origin-Time
Locid
X-Info
X-FL-QIT-DEBUG
NtCoent-Length
True-Client-Ip
X-Edge-Pop
Hostname
X-NewRelic-App-Data
X-Cache-Enabled
AMP-Access-Control-Allow-Source-Origin
X-Via-CDN
X-CS
X-Via-Edge
X-Via-SSL
X-MCACHE
X-Api-Version
Edge-Copy-Time
X-CSRF-TOKEN
X-Provided-By
GeoIp-Country-Code
X-Proxy-CacheRZ
XkeyRZ
X-Debug-Cache-Fetch
Path
Location
X-Debug-Cache-Store
X-Lambda-Id
Uri
X-Cache-Expires
GeoIP-Country-Code
X-Amz-Meta-Cb-Modifiedtime
X-NGINX-Cache
X-Dc
X-EC-Lua
X-Oss-Request-Id
X-Oss-Server-Time
X-Oss-Storage-Class
Resin-Trace
X-RateLimit-Reset
Sid
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
True-Client-IP
X-Cs
Cross-Origin-Opener-Policy-Report-Only
VNS-Cache
X-Render-Time
X-Edge-POP
VNS-Age
X-Vtex-Remote-Cache
Servername
CPC-Age
X-Fastly-Country-Code
CPC-Cache
X-B3-SpanId
X-NODE
X-Vcl-Version
Traceparent
X-Moov-T
X-Moov-Xdn-Version
X-Air-Pt
Fastly-Drupal-Html
X-CLOUD-TRACE-CONTEXT
X-Viewer-Country
X-Scheme
CDN
X-TH-Server
X-VCT
LB
X-ATG-Version
X-ApacheServer
X-Cdn-Request-ID
X-PERF
X-TX-ID
Rip
FSS-Cache
Timeexpire
X-Varnish-Authentication
X-MSEdge-Flight
X-Cache-ASPX
Esi-Enabled
Powered-By
X-NAPM-TraceId
X-Pod-Name
X-Contensis-Viewer-Groups
X-Datacenter
X-MSEdge-Features
X-Varnish-Beresp-TTL
X-Akamai-Pragma-Client-IP
X-Datadome
X-FPC
M-TraceId
CountryCode
X-Accel-Version
X-WA
X-Upstream-Ct
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-Cdn-Cache-Status
X-CF-Lambda-Fn
X-Service-Response-Time
Sm-Log-Id
X-SERVER-NAME
X-Upstream-Ht
X-Clientip
X-PAYTM-SRV-ID
V-Age
True-Client-Country-4JS
X-CF-Lambda-Version
Tracecode
XServer
X-Geo
X-Xrds-Location
X-Cache-Type
YJS-ID
X-Lb-Id
Proxy-Connection
X-Srcache-Store-Status
X-VG-WebCache
HIT
X-LiteSpeed-Cache-Control
Ohc-File-Size
X-Udemy-Cache-App-Namespace
XM
X-Srcache-Fetch-Status
Server-Id
X-NC
X-CACHE-KEY
X-CDN-Cache-Status
ENV
RNT-Machine
N-Cache
X-Wikidot-Backend
RNT-Time
X-ServedByHost
Ngx
X-Wikidot-Static-Cache
X-TraceId
X-B3-Parentspanid
X-Cdn-Forward
X-Tenant
Epwk-X-Cache
X-Hyper-Cache
WZWS-RAY
X-Rebelmouse-Cache-Control
X-Bl-Debug
X-Ha-Backend
X-Orig-Expires
X-Rebelmouse-Surrogate-Control
X-Forwarded-Path
Geoip-Latitude
X-Shop-Environment
Yjs-Id
MIME-Version
Content-Style-Type
X-Dw-Trace-Id
Content-Script-Type
X-MP-GENERATED-AT
User-Agent
X-Lb-Nocache
X-Vgn-Hpd-Reason
Inserted-Into-Cache-At
X-B3-ParentSpanId
X-Cdn-Diag
X-Connection-Hash
X-MiniProfiler-Ids
Req-ID
Expiry
X-Fastly-Backend-Reqs
X-Serial
X-Swift-Error
Ec-Rule-Version
Pramga
X-B3-Trace-ID
X-Via-PopH
X-Via-PopV
X-Via-PopN
X-TT-LOGID
X-Lsadc-Cache
X-F-Status
X-M-Reqid
X-Qnm-Cache
X-Amz-Meta-Opti
Lb
ServerName
X-App-Name
X-M-Log
X-UP
X-Stale
X-Mid-Debug-Cache-Disk
X-Mid-Debug-Cache-Key
X-Akamai-ERPolicy
X-Akamai-ERRuleID
X-Yottaa-OS
X-Webstats-RespID
X-Request-URL
X-Cache-Ngx
X-LiteSpeed-Tag
X-Th-Server
My-App
Cneonction
X-IPS-Cached-Response
Warning
X-Snapshot-Date