Threat Level: green Handler on Duty: Rick Wanner

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
Strict-Transport-Security
X-Frame-Options
X-Content-Type-Options
Last-Modified
Link
CF-Cache-Status
Cf-Request-Id
Accept-Ranges
ETag
CF-RAY
Expect-CT
Pragma
X-Powered-By
X-Cache
Via
Age
X-XSS-Protection
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Xss-Protection
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-FRAME-OPTIONS
X-Download-Options
X-Timer
X-Request-Id
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-Adblock-Key
X-AspNet-Version
X-Permitted-Cross-Domain-Policies
Alt-Svc
X-Runtime
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Cache-Status
X-Generator
CF-Ray
X-Cacheable
X-Iinfo
Timing-Allow-Origin
X-Envoy-Upstream-Service-Time
X-Request-ID
Feature-Policy
X-Ua-Compatible
Status
X-Content-Security-Policy
X-Drupal-Dynamic-Cache
Content-Encoding
X-AspNetMvc-Version
Access-Control-Expose-Headers
X-CDN
Upgrade
X-XSS-PROTECTION
Access-Control-Max-Age
X-Via
X-Cache-Group
X-Robots-Tag
Server-Timing
X-UA-Device
Request-Context
Keep-Alive
X-AH-Environment
X-Amz-Request-Id
X-Dns-Prefetch-Control
X-Turbo-Charged-By
X-Proxy-Cache
X-Backend
X-Amz-Id-2
X-Ws-Request-Id
X-Age
Host-Header
P3p
X-Server-Powered-By
X-Hacker
X-Server
X-Rq
X-Vhost
EagleId
X-Varnish-Cache
Grace
X-Amz-Version-Id
X-Dispatcher
X-LiteSpeed-Cache
Cf-Edge-Cache
Allow
X-Akamai-Path-Stats
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Swift-SaveTime
X-Swift-CacheTime
X-Device
Ali-Swift-Global-Savetime
X-WebKit-CSP
X-Nginx-Cache-Status
X-Page-Speed
X-Aws-Lambda-Call-Status
X-Host
Accept-CH
X-Node
X-OneAgent-JS-Injection
X-Pingback
Cf-Railgun
X-Cache-Spec
Request-Id
EagleEye-TraceId
Surrogate-Control
X-Server-Id
X-Akam-SW-Version
X-Backend-Server
X-Cache-Lookup
X-Response-Time
X-Readtime
Accept-CH-Lifetime
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-HW
Content-Location
X-Content-Security-Policy-Report-Only
X-Application-Context
Rating
X-Trace
Fastly-Restarts
X-Cloud-Trace-Context
X-Country
X-Url
X-WebKit-CSP-Report-Only
X-Clacks-Overhead
X-MS-InvokeApp
X-Edge
Accept-Ch-Lifetime
X-Amz-Server-Side-Encryption
X-Rack-Cache
Edge-Control
X-Nginx-Upstream-Cache-Status
X-B3-TraceId
X-Ruxit-JS-Agent
X-Vname
X-PC
X-TtlSet
X-Content-Type
X-Mod-Pagespeed
X-ESI
X-Vcap-Request-Id
X-Oneagent-Js-Injection
X-Use-Magma
X-Kinja-Server
X-Kinja-Build
X-Exp-Variant
X-GoogleNews-Bot
X-Exp-Id
X-D2id
X-Cdn-Fetch
X-Kinja
X-Kinja-Revision
Xkey
X-Mcache
Verso
X-GitHub-Request-Id
X-CST
X-Amz-Rid
Cache-Tag
X-Powered-By-Plesk
X-VARITI-CCR
X-Varnish-TTL
RTSS
Service-Worker-Allowed
X-FastCGI-Cache
X-Upstream
X-Ruxit-Js-Agent
X-Navigation-Version
X-Version
X-Abt-Application-Version
X-Cached
X-ECACHE
X-Client-IP
X-Cnection
X-Dw-Request-Base-Id
X-Ac
X-Px
X-Ttl
X-Element-Page-Cache
X-Instrumentation
X-Kraken-Loop-Name
SPRequestGuid
X-Server-Lifecycle-Phase
X-Server-Name
X-SharePointHealthScore
Arr-Disable-Session-Affinity
Public-Key-Pins
X-Cache-TTL
SPIisLatency
SPRequestDuration
Display
Pagespeed
X-Sol
X-Middleton-Display
X-Country-Code
X-NWS-LOG-UUID
Permissions-Policy
X-Ser
Accept-Ch
X-Cache-Key
X-RateLimit-Remaining
Response
X-Middleton-Response
X-Midtier
X-Edge-Location-Klb
X-Kinsta-Cache
X-Goog-Hash
X-Forwarded-For
Content-MD5
X-SRCache-Fetch-Status
X-SRCache-Store-Status
Access-Control-Request-Method
X-NF-Request-ID
X-DataDome
Front-End-Https
X-Shield-Request-Id
X-Correlation-Id
X-MSEdge-Ref
Cf-Apo-Via
X-HP-Trace-Id
X-Recruiting
X-Jurisdiction
X-HP-Webp
AR-ATIME
AR-CACHE
TP-L2-Cache
Edge-Cache-Tag
AR-SID
TP-Cache
AR-PoweredBy
AR-Request-ID
Nginx-Cache
X-T
X-Accel-Expires
MicrosoftSharePointTeamServices
X-B3-TraceId-Primal
Mrf-Cache-Status
MRF-Tech
X-Daa-Tunnel
X-RateLimit-Limit
X-Powered-CMS
X-ORACLE-DMS-ECID
TCN
X-ORACLE-DMS-RID
X-Grace
X-Mg-S
X-Id
X-Content-Digest
X-TEC-API-VERSION
X-Hits
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Cache-Config
X-HS-Combine-CSS
Server-Node
Filters
X-Request-Processing-Time
X-Request-Received
Server-Name
X-Amzn-Trace-Id
X-Frontend
MS-Author-Via
X-Distributor
X-Geo-Country
S
Fastcgi-Cache
X-Protected-By
X-LLID
X-Language
Cache-Status
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Browser-Type
X-Fastly-Request-Id
X-XRDS-Location
X-LB-Cache
X-PressLabs-Stats
X-Origin-Server
Cross-Origin-Opener-Policy
Count-Hit
X-Ezoic-Cdn
X-Fastcgi-Cache
X-Microsite
X-Request-Handler-Origin-Region
X-F-Cache
X-FB-Debug
Host
X-Forwarded-Proto
X-B3-Sampled
X-Page-Id
X-Seen-By
X-Ua-Browser
X-Ab
X-Amz-Meta-S3cmd-Attrs
Charset
X-Git-Hash
Filterid
Payment
X-Litespeed-Cache
X-ASPNET-VERSION
X-Cache-Age
X-Cluster-Name
X-VCache
X-Ratelimit-Reset
Surrogate-Key
Realpath
X-TTL
X-Rid
Accept-Charset
X-Origin-Cache
Cache-Tags
X-Template
X-NGENIX-Cache
Alternate-Protocol
Access-Control-Allow-Method
X-Www-Served-By
Retry-After
X-Webkit-Csp
X-Logged-In
X-Az
X-Upgrade-Enabled
X-AppVersion
X-Activity-Id
Cleartype
X-DIS-Request-ID
X-DynaTrace
X-Providence-Cookie
X-Varnish-Grace
X-Is-Crawler
X-App-Environment
X-Aspnet-Duration-Ms
X-TT
X-Amz-Replication-Status
X-Tb
X-Request-Guid
X-Varnish-Backend
X-Route-Name
X-Flags
X-Wix-Request-Id
X-Signature
X-B
X-B-Cache
X-Type
X-Source
X-Node-Name
X-Envoy-Decorator-Operation
X-Hostname
DC
Paypal-Debug-Id
ServerID
X-Drupal-Cache-Tags
Frame-Options
X-Debug
X-Proxy
X-Revision
X-Fastly-Request-ID
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Server-ID
X-Contextid
X-Mobile
X-Content-Options
Amp-Access-Control-Allow-Source-Origin
Pinterest-Version
Pinterest-Generated-By
X-Pinterest-Rid
X-Goog-Metageneration
X-GUploader-UploadID
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Cache-Rule
X-Goog-Generation
X-Goog-Storage-Class
X-Load-Cache
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Cache-Control
X-N
Country
X-Magnolia-Registration
Node
Refresh
X-Content
X-Response-Served-From
X-Original-Request-Id
Referer-Policy
X-User-Agent
X-Whom
X-EdgeConnect-Cache-Status
NGB
Viewport
X-L-Path
X-Debug-IsConnected
X-Debug-IsPreview
X-Framework
X-Cacheable-TTL
X-Environment-Context
X-Cache-TTL-Remaining
Access-Control-Request-Headers
Url
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Adobe-Content
Uber-Trace-Id
X-Unique-Id
X-Content-Powered-By
X-Real-IP
X-Yottaa-Optimizations
X-Adobe-Loc
X-Mid
X-Page-View
X-Yottaa-Metrics
X-Servername
X-G
X-Akamai-Request-ID2
X-Jobs
X-NYM-Debug-Backend
X-Cache-Time
Content-Disposition
X-Rendered-As
X-Is-Bot
X-Varnish-Age
X-Status
X-Varnish-Server
X-Cache-Grace
X-XRDS-LOCATION
X-Instance
X-ProcessESI
Srv
Akamai-GRN
X-RemovedCookies
X-Oracle-Dms-Ecid
X-Oracle-Dms-Rid
X-Ratelimit-Remaining
Countrycode
X-Drupal-Cache-Contexts
X-Mg-Request-UUID
Version
X-COUNTRY
X-Time
X-Restarts
X-APP-VERSION
X-CDN-Forward
X-Http-Reason
X-Cache-Expired-At
X-Via-JSL
X-App-Server
Accept-Language
X-Trace-Id
Protected
X-Debug-Info
X-Cache-Hit
Healthy
X-Tumblr-User
X-Hosted-By
X-IPLB-Instance
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-IPLB-Request-ID
X-Tumblr-Pixel
X-Cache-Operation
Cross-Origin-Resource-Policy
X-Nginx-Cache-Key
X-Azure-Ref
X-Ratelimit-Limit
X-Backend-Name
Section-Io-Cache
X-Tt-Logid
X-Device-Type
Liferay-Portal
Content-Secure-Policy
X-Akamai-Edgescape
X-FW-Server
Backend
X-FW-Static
X-FW-Type
Server-Info
X-FW-Serve
X-FW-Hash
X-ECache
X-FW-Dynamic
Fastcgi-Useragent
X-Cache-Action
X-RTag
X-Api-Version
MS-CV
Ms-Operation-Id
X-UPSTREAM-Address
X-Storage
X-Mobile-URL
Load-Balancing
Meta-Geo
X-Proxy-Cache-Status
X-RN-RSRV
X-Rule
GEO-INFO
X-Mode
X-VC-Cache
X-Cache-NGX
X-Varnish-Beresp-Grace
X-Content-Age
CDN-Cache
X-Region
X-Shopify-Stage
X-Site-Version
X-Skip-Cache
X-Sorting-Hat-PodId
X-ShopId
X-ShardId
X-Say-Cacheable
X-Say-TTL
X-SayCDN-TTL
X-Sorting-Hat-ShopId
X-Sql-Count
X-Varnishpool
X-VWS-Id
CF-IPCountry
X-Handled-By
X-Varnish-Hostname
X-Uri
X-Sql-Duration-Ms
X-Urbn-Context-Path
X-Urbn-Site-Id
X-Redis-Cache
X-Proto
Locale
S-Rt
X-Adobe-Source
X-AWS-Id
CDN-Uid
CDN-RequestId
CDN-EdgeStorageId
CDN-PullZone
CDN-RequestCountryCode
X-Cache-Enabled
X-Cms-Context
X-OCL
X-PCL
X-PHP-Backend
X-PHP-Host
X-No-Session
X-LJ-Flow-ID
X-Edge-Location
X-Forwarded-Host
X-Labrador-Cache-Channel
CDN-CachedAt
X-Alternate-Cache-Key
X-UUID
X-Routing-Service
X-Request-Time
X-ProxyCache-Key
X-Section
X-ProxyCache-Status
X-ServerID
X-Web-Node
X-Via-Fastly
X-UA-Device-Type
X-Timing-Wait
X-Proxy-Build
X-HTML-Minification-Powered-By
X-Detected-As
X-Cache-Type
X-Cache-Server
X-BYPASS-REASON
X-Extlb
X-FB-TRIP-ID
X-Hl-Ver
X-GeoCountry
X-GeoCode
X-Generated-By
X-Proxied
X-Xfnlog-Site
Webcakes-App-Version
Webcakes-Region
Webcakes-App-Name
Web-Mar-Node
TWC-Privacy
X-Cache-Host
X-Format
X-Generation-Time
X-Varnish-Cache-Hits
X-Origin-Hint
X-Locale
TWC-GeoIP-LatLong
TWC-GeoIP-Country
Azure-SiteName
Azure-RegionName
Azure-InstanceId
X-Zipkin-Id
Azure-SlotName
Azure-Version
TWC-Device-Class
TWC-Connection-Speed
Property-Id
Onion-Location
X-Access
TWC-Locale-Group
Selected-Fe
Apigw-Requestid
DB-Nickname
Eomportal-Instance
Mn-Server-Ip
X-SRV
X-Cache-Status-Check
X-Storefront-Renderer-Rendered
X-Tid
X-Nginx-Cache
X-R9-Blue-Green-Version
X-Server-W
X-Ms-Version
X-Origin-Date
X-Ms-Request-Id
X-URL
X-JoinUs
X-SaId
WP-Super-Cache
X-Datadome
Cache-Name
X-FireWall-Port
X-Correlation-ID
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
X-DynaTrace-JS-Agent
X-Zen-Fury
ServedBy
Xserver
X-Amz-Apigw-Id
X-Amzn-RequestId
X-LSADC-Cache
X-Human
X-Varnish-Ttl
X-Ua
X-TNCMS
X-Loop
Cache
Xet-Cookie
Source
X-Dc
X-Debug-Cache
X-Cache-Tags
X-GEO
X-TA-CDN-Provider
X-Varnish-Hits
X-Reqid
X-RCS-CacheZone
X-App-Version
X-Soup
X-Pubstack
X-Cached-By
X-Amzn-Remapped-Content-Length
Cross-Origin-Window-Policy
Origin
X-MP-GENERATED-AT
SD-X-WS
X-Aspnetmvc-Version
X-Vgn-Hpd-Reason
X-Cdn
WPO-Cache-Message
X-Newrelic-Synthetics
WPO-Cache-Status
X-Origin-CC
X-Webkit-CSP
X-Origin-TTL
X-Provided-By
From-Origin
X-Tumblr-Pixel-2
X-Service
LB
X-IPS-LoggedIn
X-Varnish-Beresp-Ttl
X-AOL-HN
X-NewRelic-App-Data
Rip
Webserver
X-TIME
X-Tec-Api-Root
X-Tec-Api-Version
X-B3-SpanId
X-Via-NSCOPI
X-Tec-Api-Origin
X-Request-Host
X-FW-Version
X-GG-Cache-Date
X-Platform-Server
X-PBS-Appsvrname
DCR-Decision-By
X-Developer
X-A-Wwc
X-External-Request-Id
DCR-Processing-Time-Ms
X-Ec-GeoHdr
X-A-Dcw
X-Ec-Fail
Cdnsip
A
X-A-Dam
Cdncip
Lang
X-D
X-A-Dgt
Environment
X-B-Cookie
X-Bc-Bl
X-Connection-Hash
X-NAPM-TraceId
X-Application
X-Destination
X-ARC
X-AK-Request-ID
X-Orig-Expires
Host-ID
X-Cache-NE
X-Forwarded-Path
Expiry
X-Owner
X-BCube-Filmed-By
X-Aed
BehaviorPad-Version
Xc-Version
X-S
X-Vdms-Version
X-ScT
X-Vdms-Path
X-Rojux
X-Rewrite-Enabled
X-TIM-N
Ngx.Var.Host
Odigeo-Trace-Id
HostName
X-Served-From
X-SRCache-Key
Sslversion
X-Tenant
Rendered-Blocks
Surrogated-Key
X-Shop-Environment
T-Server
X-CSRF-Token
X-VG-WebCache
X-S-Cookie
Meta-Geo-Continent
MD5-Digest
X-A
X-Cluster-Node
X-User
X-Processor
X-A-Ccd
Mime-Version
OT-Force-Account-Verify
X-B3-Traceid
X-VC
CPC-Cache
X-Bip
CPC-Age
VNS-Cache
X-Dispatcher-Number
X-Qloud-Router
X-Parent-Response-Time
Redirect-Candidate
X-Accel-Buffering
X-Generated-On
VNS-Age
Machine
X-Aicache-OS
X-Thanos
X-Level-Front-Cache
Upgrade-Insecure-Requests
X-Pool
X-Varnish-Beresp-Status
X-WA-Info
Thinkindot-CacheControl
X-Clientip
TDXMobile
X-Ckpd-Fst-Backend
X-CMSURLCustom
State
X-Clara-WADP
X-Core-Mission
X-Cluster
X-Cache-Bucket
Tube-Return
X-BBC-Edge-Cache-Status
Tube-Got-Eval
Tube-Get-Contents
X-Ad-Defer-Variation
V-Age
Wxu-Next-Commit
Vix-Hermes-Req-Id
Wxu-Next-Hostname
Traceparent
Thinkindot-Control
X-Core-Value
X-CacheTTL
X-Cdn-Origin
X-Cache-Info
X-Cache-Id
X-Branch-Name
Thinkindot-CacheControl-Type
Wxu-Next-Region
X-CGP
X-Origin
X-WADP-Cache
X-Wix-Viewer-Type
X-Worker
X-VServer
X-VG-TLSProxy
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
Servername
X-Policy
X-Planisys-CDN-Cache
X-Varnish-Remaining-TTL
X-Planisys-CDN-Rules
X-Variation
X-V-Cache
X-Planisys-CDN-TTL
X-Region-Sid
X-Request-URI
X-Slack-Backend
X-SIPLIST1
X-Sn-Servicetimems
X-SplitTest
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-Sigma-Backend
X-Sigma
X-Rocket-Nginx-Serving-Static
X-Rocket-Build-Number
X-S-Maxage
X-SB
X-Scale
X-Thinkindot-L3
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-Eu-Site
X-Esi-Check
X-Epic-Correlation-Id
X-Fetched-On
X-Fmm-Version
X-Gamma-Serve
X-Forwarded-Site
X-Ec-Custom-Error
X-DPWN-IS-SECURE
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
X-Datadog-Trace-Id
X-DefElseHash
X-Device-Os
X-DefHash
X-Gateway-Cache-Key
X-Gateway-Cache-Status
X-Mvc-Supplant-Cachable
X-Minions-Version
X-Mvc-Supplant-OutputCached
X-NodeID
X-Origin-Response-Time
X-Optimistic-Header
X-Loc
X-Irp-Debug
X-Gateway-Skip-Cache
X-Gateway-Request-Id
X-GeoIP
X-GeoIP-City
X-Hash
X-Gzip
X-Csrf-Jwt
Tube-Got-Results
Fastly-GeoIP-CountryCode
Fastly-SIE
DSUID
Decoy-Debug-TTL
Decoy-Debug-Key
Decoy-Debug-Status
Fastly-SSL
Fastly-SWR
Kp-EeAlive
L
IsBot
Is-Eu
Ha-Gx-Prefs
HA-Ipaddr
Country-Code
Cmstype
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
Apple-News-Services-Handled
Adler-Geo
X-Tx-Id
X-Cache-Debug
Apple-News-Services-Request-Url
Cache-Hits
Click-Count-Error
Cmsid
Click-Count-Action-Start
Candidate-Md5Url
Canary
L5d-Success-Class
Cache-Host
Origin-CC
Producers
NM-Fastcgi-Cache
Req-Svc-Chain
Release
Server-Host
Origin-EX
Mobile-Detection-Method
Memcached
NGX
Platform
CDCHOST
X-JWT-State
Server-Hostname
CloudFront-Viewer-Country
X-Geo-Header
X-Gen-Mode
X-NCache
X-ZONE
X-Scheme
Web-Mar-Region
X-Developers
Sever-Int
X-Nyt-Route
X-INCAP-ABP
Server-Ext
Svr
X-Is-Gdpr
User-Cache-Control
X-Origin-Time
Fastly-Backend-Name
Gh-Request-Id
Mail-Subject
X-Proxy-Cache-Info
X-HS-Content-Campaign-Id
X-Hnp-Log
We-Hiring
X-Block-Status
X-Auto-Login
X-Gdpr
Cluster
X-Viewer-Country
X-Cdn-Srv
X-Has-Esi
Datacenter
Ec-Rule-Version
X-Cache-Remote
WebServer
X-Trace-ID
Cache-Tv-Group
X-WP-CF-Super-Cache-Active
X-LB-NoCache
AKAMAI
X-Sucuri-ID
X-Sucuri-Cache
X-Presslabs-Stats
X-Fastly-Cache
X-FC-Vary-Parameters
X-Var-Ttl
X-Fastly-Backend
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
Pics-Label
X-ND-Cache
Time
X-Origin-Expires
Memory
Fastcgi-Cache-TTL
Ssr
X-Azure-Ref-OriginShield
X-Session-Fingerprint
X-ATG-Version
X-Udemy-Cache-App-Namespace
X-Newrelic-App-Data
Sid
Fastly-Drupal-HTML
X-Tb-Optimization-Total-Bytes-Saved
X-Nf-Request-Id
SID
X-Pod-Name
X-Generated-In
X-NWS-UUID-VERIFY
X-Servedbyhost
X-Via-Poph
Env
X-Via-Popn
X-Via-Popv
AMP-Access-Control-Allow-Source-Origin
X-Ig-Push-State
X-Refresh
X-Cache-Date
X-Buckets
X-Akamai-Transformed
Server-ID
X-Xrds-Location
X-DC
X-Cs
X-Conf
X-Up
X-Release
X-Edge-Pop
X-Pass-Why
X-Microcachable
Fastly-Drupal-Html
X-Fpc
X-MSEdge-Flight
X-MSEdge-Features
My-App
X-NC
X-Dispatch
X-EC-Lua
X-Tumblr-Pixel-3
X-RateLimit-Reset
X-Esi
X-Wa
X-Lambda-Id
X-Dmc
X-Endurance-Cache-Level
CDN
X-PX
X-CLOUD-TRACE-CONTEXT
X-MCACHE
GeoIp-Country-Code
X-ID
X-CS
X-CACHE-AGE
X-VCL-Version
X-Req
X-Be
Magicmarker
True-Client-IP
X-Zone
X-TX-ID
X-TRACE-ID
X-NGINX-Cache
X-Webkit-CSP-Report-Only
X-Srv
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-LB-ID
X-CACHE-KEY
X-Vc
X-Air-Hostname
X-TH-Server
CacheControlHeader
True-Client-Country-4JS
X-Air-Source
X-Air-Trace-Id
Hostname
X-CSRF-TOKEN
X-Hyper-Cache
X-Yandex-Sdch-Disable
X-Micro-Cache
X-Op-Id-All
X-CF-Lambda-Version
X-CF-Lambda-Fn
X-B3-Spanid
X-Air-Pt
X-Vcl-Version
X-M-Log
X-HS-Status
Resin-Trace
Path
Pramga
X-M-Reqid
X-App
X-Alfa-Service
True-Client-Ip
X-Varnish-Beresp-TTL
Tcn
GeoIP-Country-Code
C-Via
X-Qnm-Cache
N-Cache
X-GeoIP-Region-Code
X-TrackingId
X-GeoIP-Country-Code
Tracecode
X-SERVER-NAME
X-Vercel-Id
WWW-Authenticate
Section-Origin-Responded
On-Server
X-FPC
Section-Io-Origin-Time-Seconds
X-Akamai-Pragma-Client-IP
X-Accel-Expires-Debug
X-PAYTM-SRV-ID
X-Vercel-Cache
X-Platform
Esi-Enabled
Fastcgi-X-Cache-Version
X-Date
Section-Io-Origin-Status
Section-Io-Id
NtCoent-Length
X-Check-Cacheable
Proxy-Connection
X-WA
X-RAMCache
X-Datacenter
X-Edge-Origin-Shield-Bytes
Yjs-Id
Hit
X-Edge-Origin-Shield-Region
X-Webkit-Csp-Report-Only
X-Node-Id
X-Platform-Cluster
X-Geo
X-Platform-Router
Server-Id
FSS-Cache
Lb
X-Edge-POP
X-Via-CDN
X-Platform-Processor
X-Old-Content-Length
X-Mly-Id
GeoIP-Latitude
X-Vtex-Remote-Cache
X-Vtex-Processado-Em
X-LiteSpeed-Cache-Control
X-API-Version
X-Request-Start
X-Via-PopV
X-Via-PopN
X-Lb-Id
X-Via-PopH
X-LAGOON
Powered-By
ENV
User-Agent
X-Response-By
X-ServedByHost
YJS-ID
X-SD-PageType
X-Dw-Trace-Id
X-AIR-PT
X-Cdn-Forward
X-UA
XServer
Cache-Key
HIT
X-Client-Ip
Cdn
X-PERF
X-ApacheServer
X-Akamai-ERPolicy
X-Akamai-ERRuleID
X-Location
X-Proxy-CacheRZ
X-CUA
X-FORWARDED-FOR
X-TT-LOGID
X-Via-Ucdn
X-Traceid
Server-Ttl
DynaTrace
X-Cache-Ttl
Locid
X-Li-Pop
X-LI-Proto
X-Li-Fabric
Srvid
Dnion-Transfer-Encoding
Geoip-Latitude
X-LI-UUID
X-Instance-Name
X-Webstats-RespID
X-From
X-Render-Time
XkeyRZ
X-FL-EDGE
Sm-Log-Id
X-Service-Response-Time
Ohc-File-Size
XM
X-DW
X-RPS
X-RSL
X-Proxy-Upstream
X-RPM
X-DSS
X-DB
X-DI
PFcat
PICS-Label
X-LiteSpeed-Tag
X-Contensis-Viewer-Groups
X-CF-Powered-By
X-HN
X-Varnish-Authentication
X-Proxy-Cache-Hk
X-Director
Location
DT-Hot-News
X-Cache-ASPX
Nginx-CQVIP
X-VarnishDD-TTL
X-Litespeed-Cache-Control
X-Wp-Cf-Super-Cache
X-Wp-Cf-Super-Cache-Cache-Control
X-Fastly-Cache-Hits
X-Server-IP
X-B3-ParentSpanId
X-Fastly-Backend-Reqs
X-Cdn-Request-ID
Wpo-Cache-Message
Wpo-Cache-Status
X-DataCenter
X-HostName
X-Request-Url
X-Lb-Nocache
Vha6-Origin
Warning
X-Cache-Ngx
CountryCode
Wp-Super-Cache
X-Ips-Loggedin
X-Test
X-Moov-T
X-Yottaa-OS
CF-Cached-On
Swift-Performance
X-Moov-Xdn-Version
Req-ID
WZWS-RAY
SRV
Fastcgi-Cache-Ttl
X-Mg-Cache
X-ElasticPress-Query