Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Accept-Ranges
Expect-CT
X-XSS-Protection
CF-RAY
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
P3P
X-Xss-Protection
X-Served-By
X-Download-Options
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Request-ID
Access-Control-Allow-Credentials
X-Request-Id
CF-Ray
X-Permitted-Cross-Domain-Policies
X-AspNet-Version
Alt-Svc
Content-Security-Policy-Report-Only
X-Runtime
X-DNS-Prefetch-Control
X-Drupal-Cache
X-Check
X-Cache-Status
X-Generator
X-Cacheable
P3p
Timing-Allow-Origin
X-FRAME-OPTIONS
X-Iinfo
X-Envoy-Upstream-Service-Time
X-Content-Security-Policy
X-Drupal-Dynamic-Cache
Feature-Policy
Content-Encoding
Upgrade
Status
Access-Control-Expose-Headers
X-AspNetMvc-Version
X-CDN
Access-Control-Max-Age
X-Via
Server-Timing
X-UA-Device
X-Robots-Tag
Request-Context
X-Turbo-Charged-By
X-Amz-Request-Id
X-Cache-Group
EagleId
X-Amz-Id-2
X-Backend
Keep-Alive
X-AH-Environment
X-Proxy-Cache
X-Ws-Request-Id
X-Server
X-Age
Host-Header
X-Hacker
X-Ua-Compatible
Cf-Edge-Cache
X-Vhost
X-Server-Powered-By
X-Rq
Allow
X-Dispatcher
X-Varnish-Cache
Grace
X-Amz-Version-Id
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-LiteSpeed-Cache
X-OneAgent-JS-Injection
X-WebKit-CSP
Accept-CH
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
Cf-Apo-Via
X-Page-Speed
Cf-Railgun
X-Aws-Lambda-Call-Status
X-Host
X-Server-Id
X-Pingback
X-Node
X-Cache-Spec
X-Nginx-Cache-Status
X-Akam-SW-Version
Surrogate-Control
X-Dns-Prefetch-Control
X-Backend-Server
EagleEye-TraceId
Request-Id
X-Cache-Lookup
X-Readtime
X-Ruxit-JS-Agent
X-HW
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Cloud-Trace-Context
Accept-Ch-Lifetime
X-Content-Security-Policy-Report-Only
X-Trace
X-Application-Context
X-Response-Time
X-CST
Permissions-Policy
X-Mod-Pagespeed
X-Nginx-Upstream-Cache-Status
Fastly-Restarts
X-Edge
X-Country
Content-Location
X-WebKit-CSP-Report-Only
Accept-CH-Lifetime
X-Content-Type
X-Mcache
X-ECACHE
Rating
X-Url
X-Clacks-Overhead
X-MS-InvokeApp
X-TtlSet
X-PC
X-Vname
X-Amz-Server-Side-Encryption
X-Midtier
X-VARITI-CCR
RTSS
Cache-Tag
X-Vcap-Request-Id
X-Varnish-TTL
X-Ac
X-Element-Page-Cache
Verso
Origin-Trial
X-B3-TraceId
X-D2id
X-Kinja-Build
X-Kinja
X-Exp-Id
X-Exp-Variant
X-Kinja-Revision
X-Kinja-Server
X-GoogleNews-Bot
X-Cdn-Fetch
X-Use-Magma
X-Server-Name
X-Rack-Cache
X-Cnection
X-Cache-TTL
X-Litespeed-Cache
X-Powered-By-Plesk
Service-Worker-Allowed
X-ESI
Xkey
X-Abt-Application-Version
X-Client-IP
X-Fastcgi-Cache
X-Navigation-Version
Edge-Control
X-NWS-LOG-UUID
SPRequestGuid
X-GitHub-Request-Id
X-SharePointHealthScore
X-Amz-Rid
X-Cached
X-Px
X-Ttl
X-Mg-S
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-Browser-Type
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Instrumentation
Arr-Disable-Session-Affinity
X-Upstream
SPIisLatency
SPRequestDuration
X-Correlation-Id
X-Cache-Key
X-Sol
X-Middleton-Display
Pagespeed
Display
Content-MD5
X-Dw-Request-Base-Id
X-SRCache-Store-Status
X-SRCache-Fetch-Status
Access-Control-Request-Method
X-Goog-Hash
Edge-Cache-Tag
X-XRDS-Location
X-Daa-Tunnel
Front-End-Https
X-NF-Request-ID
X-Country-Code
Public-Key-Pins
X-Version
X-RateLimit-Remaining
X-Forwarded-For
AR-CACHE
AR-PoweredBy
AR-SID
X-Powered-CMS
AR-ATIME
AR-Request-ID
X-Id
X-HP-Webp
X-Jurisdiction
TCN
X-HP-Trace-Id
X-MSEdge-Ref
X-Recruiting
X-T
X-Content-Digest
X-Accel-Expires
X-Middleton-Response
Response
X-B3-TraceId-Primal
Mrf-Cache-Status
MRF-Tech
X-Ser
X-Shield-Request-Id
TP-Cache
TP-L2-Cache
S
Nginx-Cache
X-Hits
X-Amzn-Trace-Id
Cache-Status
X-Kinsta-Cache
X-Request-Received
X-Request-Processing-Time
X-Edge-Location-Klb
X-HS-Cache-Config
X-HS-Combine-CSS
Server-Node
X-HS-Content-Id
X-HS-Hub-Id
X-Distributor
X-Fastly-Request-ID
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
X-Grace
Alternate-Protocol
MicrosoftSharePointTeamServices
Cache-Tags
Server-Name
Fastcgi-Cache
X-Protected-By
X-Ratelimit-Limit
X-DataDome
X-TTL
X-DIS-Request-ID
X-Geo-Country
X-Ezoic-Cdn
X-Ruxit-Js-Agent
X-LB-Cache
X-Origin-Server
X-Request-Handler-Origin-Region
X-Frontend
X-Microsite
X-Ua-Browser
X-Debug-Info
X-Rid
X-Ratelimit-Reset
Cross-Origin-Opener-Policy
Healthy
X-NGENIX-Cache
X-Forwarded-Proto
X-Varnish-Backend
X-Git-Hash
X-Www-Served-By
Filterid
Payment
X-FB-Debug
X-Logged-In
X-Page-Id
Cleartype
X-PressLabs-Stats
X-Load-Cache
X-Ratelimit-Remaining
X-B3-Sampled
Charset
Content-Disposition
X-VCache
X-Webkit-Csp
X-ASPNET-VERSION
X-Origin-Cache
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-LLID
X-Cluster-Name
MS-Author-Via
X-Oracle-Dms-Ecid
X-Oracle-Dms-Rid
X-Hostname
DC
X-Goog-Metageneration
X-GUploader-UploadID
Accept-Charset
X-Upgrade-Enabled
Access-Control-Allow-Method
Retry-After
X-Proxy
Cross-Origin-Resource-Policy
X-AppVersion
X-F-Cache
X-Activity-Id
X-Az
X-Contextid
X-Signature
X-Amz-Replication-Status
X-Type
X-Aspnet-Duration-Ms
X-Hosted-By
X-Flags
X-Seen-By
X-Is-Crawler
X-Providence-Cookie
X-Route-Name
X-Revision
X-B-Cache
X-Request-Guid
Accept-Ch
X-Wix-Request-Id
X-B
X-TT
X-Varnish-Server
X-Azure-Ref
X-Amz-Meta-S3cmd-Attrs
X-Whom
Referer-Policy
Viewport
Amp-Access-Control-Allow-Source-Origin
X-App-Environment
Surrogate-Key
Paypal-Debug-Id
X-DynaTrace
X-Source
X-RateLimit-Limit
X-Aspnetmvc-Version
Count-Hit
Realpath
X-Fb-Rlafr
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Akamai-Edgescape
X-Mobile
X-App-Server
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Goog-Generation
X-B3-Traceid
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
Host
X-FastCGI-Cache
X-Cache-Control
X-EdgeConnect-Cache-Status
X-Cache-Age
X-HTML-Minification-Powered-By
X-Response-Served-From
Refresh
X-Original-Request-Id
Version
X-N
X-Tumblr-User
X-Nginx-Cache
X-Varnish-Grace
X-Oneagent-Js-Injection
X-Tumblr-Pixel-1
X-Cache-Rule
X-Tumblr-Pixel-0
X-Tumblr-Pixel
SD-X-WS
Access-Control-Request-Headers
X-Magnolia-Registration
Section-Io-Cache
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Envoy-Decorator-Operation
X-Varnish-Age
X-L-Path
X-Page-View
X-Newrelic-App-Data
X-Environment-Context
X-Cache-Status-Check
X-Adobe-Content
X-Adobe-Loc
X-Cache-Expired-At
MS-CV
Ms-Operation-Id
X-Cache-Time
X-UUID
X-RTag
X-RemovedCookies
X-Framework
X-Status
X-G
Protected
X-Device-Type
X-ProcessESI
X-Rule
X-Cacheable-TTL
NGB
GEO-INFO
X-Cache-Grace
X-Content-Powered-By
X-Servername
X-Jobs
X-Rendered-As
X-Is-Bot
Url
X-FW-Dynamic
X-FW-Type
X-FW-Hash
X-FW-Static
X-Akamai-Request-ID2
X-NYM-Debug-Backend
X-FW-Server
Akamai-GRN
X-Http-Reason
X-FW-Version
X-FW-Serve
X-User-Agent
X-Debug-IsConnected
X-Debug-IsPreview
X-Backend-Name
X-Instance
X-CDN-Forward
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Tb
CDN-RequestId
X-Cache-Hit
X-Drupal-Cache-Contexts
X-Drupal-Cache-Tags
Pinterest-Version
From-Origin
X-Tt-Logid
X-Pinterest-Rid
SRV
Pinterest-Generated-By
Country
WPO-Cache-Status
WPO-Cache-Message
Accept-Language
X-Node-Name
X-Region
Front
X-Trace-Id
X-URL
X-Real-IP
X-Time
Fastly-Drupal-HTML
X-VC-Cache
Backend
Uber-Trace-Id
X-Fastly-Request-Id
X-Mode
X-Template
X-Content-Options
X-Language
Fastly-SWR
X-Cache-Operation
Meta-Geo
Filters
Fastly-SIE
X-Generation-Time
X-Amz-Apigw-Id
X-UPSTREAM-Address
X-Rewrite-Enabled
X-Amzn-RequestId
X-RN-RSRV
X-Web-Node
Webserver
CDN-Cache
Content-Secure-Policy
X-DynaTrace-JS-Agent
X-Tumblr-Pixel-2
CDN-CachedAt
CDN-RequestCountryCode
CDN-PullZone
CDN-EdgeStorageId
CDN-Uid
X-Cache-TTL-Remaining
X-Cms-Context
X-Section
X-Proxy-Cache-Info
X-Format
X-Rocket-Nginx-Serving-Static
X-Sql-Count
X-Say-TTL
Cross-Origin-Window-Policy
X-SayCDN-TTL
X-IPS-LoggedIn
X-Sql-Duration-Ms
X-Adobe-Source
X-Cache-Action
X-Say-Cacheable
X-WP-CF-Super-Cache-Cache-Control
Azure-SlotName
Azure-SiteName
Apigw-Requestid
Azure-InstanceId
Azure-RegionName
Azure-Version
CF-IPCountry
X-Cache-Server
X-Proxy-Cache-Status
X-WP-CF-Super-Cache
X-Access
X-Skip-Cache
X-ProxyCache-Key
X-ProxyCache-Status
X-Edge-Location
X-Ms-Version
X-LJ-Flow-ID
X-GeoCountry
Cache-Name
X-Forwarded-Host
X-Ms-Request-Id
X-PHP-Backend
X-Soup
X-PHP-Host
X-AWS-Id
X-Cluster
X-Sucuri-Cache
X-Reqid
X-GeoCode
X-Debug
X-Cache-Host
X-UA-Device-Type
X-Sucuri-ID
X-Varnish-Beresp-Grace
X-Via-Fastly
ServerID
X-Content-Age
X-BYPASS-REASON
X-VWS-Id
X-Labrador-Cache-Channel
Node
X-Zen-Fury
X-Unique-Id
TWC-Privacy
Webcakes-App-Name
X-Site-Version
X-Urbn-Context-Path
X-Urbn-Site-Id
TWC-GeoIP-LatLong
TWC-Locale-Group
X-SaId
X-Routing-Service
X-JoinUs
X-Extlb
X-LAGOON
X-No-Session
Webcakes-App-Version
X-Proxied
TWC-GeoIP-Country
TWC-Device-Class
Web-Mar-Node
S-Rt
X-R9-Blue-Green-Version
X-Amzn-Remapped-Content-Length
X-Proto
X-IPLB-Instance
Onion-Location
X-Server-W
TWC-Connection-Speed
X-Detected-As
Property-Id
X-Origin-Hint
X-Zipkin-Id
X-Xfnlog-Site
X-IPLB-Request-ID
Webcakes-Region
X-Cluster-Node
X-Locale
Locale
WP-Super-Cache
Mn-Server-Ip
Mime-Version
Selected-Fe
X-Timing-Wait
X-Handled-By
X-LSADC-Cache
X-Proxy-Build
X-Ua
X-SRV
DB-Nickname
Fastcgi-Useragent
Cache-Hits
X-Hl-Ver
X-Request-Time
X-FB-TRIP-ID
Xserver
X-Redis-Cache
Liferay-Portal
X-Cache-Debug
X-TIME
X-Tumblr-Pixel-3
ServedBy
X-Optimistic-Header
X-NWS-UUID-VERIFY
X-XRDS-LOCATION
Upgrade-Insecure-Requests
X-TNCMS
X-Loop
Source
X-Generated-By
X-GEO
Countrycode
X-Mg-Request-UUID
X-Origin-Date
X-Air-Hostname
X-Varnish-Hits
X-Air-Source
X-Air-Trace-Id
X-Tid
CF-Cached-On
X-Tec-Api-Version
X-Storage
X-Tec-Api-Root
X-Times
X-Tec-Api-Origin
X-Uri
X-Server-ID
X-CACHE-AGE
X-Varnish-Beresp-Ttl
X-Director
X-Akamai-Transformed
Xet-Cookie
X-Cdn
X-COUNTRY
X-Tx-Id
X-Pass-Why
X-TA-CDN-Provider
X-Trace-ID
Frame-Options
X-Origin-TTL
X-Newrelic-Synthetics
X-Origin-CC
X-ARC
X-DC
X-B3-Spanid
X-Service
X-FireWall-Port
X-ECache
X-Esi
X-AIR-PT
X-App-Version
X-Sorting-Hat-ShopId
Environment
X-Storefront-Renderer-Rendered
X-Varnish-Cache-Hits
X-Alternate-Cache-Key
X-Varnish-Hostname
X-Sorting-Hat-PodId
X-Datadog-Sampling-Priority
X-Datadog-Sampled
X-Datadog-Parent-Id
SID
X-Datadog-Trace-Id
X-ShardId
X-Shopify-Stage
X-ShopId
Server-Info
X-Presslabs-Stats
Sslversion
Candidate-Md5Url
DCR-Processing-Time-Ms
Edge-Cache
Gannett-Cam-Experience-Id
DCR-Decision-By
BehaviorPad-Version
X-Request-Host
A
Lang
MD5-Digest
Redirect-Candidate
Release
Rendered-Blocks
Origin
Odigeo-Trace-Id
Meta-Geo-Continent
Ngx.Var.Host
Req-Svc-Chain
X-Destination
X-Platform-Cluster
X-Platform-Processor
X-Platform-Router
X-Processor
X-Origin-Time
X-Nyt-Route
X-Loc
X-Mid
X-Mobile-URL
X-Rojux
X-S
X-Vdms-Path
X-Vdms-Version
X-VG-TLSProxy
Xc-Version
X-TIM-N
X-SRCache-Key
X-S-Cookie
X-S-Maxage
X-ScT
X-Gdpr
X-External-Request-Id
X-A-Dcw
X-A-Dgt
X-A-Wwc
X-Aed
X-A-Dam
X-A-Ccd
T-Server
WWW-Authenticate
X-A
X-Application
X-B-Cookie
X-Developer
X-Ec-Fail
X-Ec-GeoHdr
X-Epic-Correlation-Id
X-D
X-Cache-NE
X-Bc-Bl
X-BCube-Filmed-By
X-Cache-Info
Surrogated-Key
X-BBC-Edge-Cache-Status
X-Endurance-Cache-Level
X-ServerID
Magicmarker
Cache-Tv-Group
X-DefElseHash
X-SB
X-Rocket-Build-Number
X-Core-Value
X-CMSURLCustom
X-Cdn-Origin
X-SD-PageType
Memcached
X-Served-From
DSUID
X-SVT-ORM-RULES
Decoy-Debug-TTL
Decoy-Debug-Status
Decoy-Debug-Key
X-Sn-Servicetimems
Fastly-GeoIP-CountryCode
X-DefHash
X-Sigma
X-Sigma-Backend
X-Fmm-Version
X-Platform-Server
X-Gamma-Serve
X-Akamai-Device-Characteristics
X-INCAP-ABP
X-Clara-WADP
X-Pubstack
X-Human
X-Httpd
X-GeoIP-City
X-Thinkindot-L3
X-Cache-Bucket
X-We-Are-Hiring
X-NodeID
X-Old-Content-Length
X-Origin-Response-Time
X-Frame-Option
State
X-SVT-ORM-VERSION
Tube-Get-Contents
Tube-Got-Eval
X-Core-Mission
Vix-Hermes-Req-Id
Tube-Return
Tube-Got-Results
X-CUA
X-Req
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
Apple-News-Services-Handled
X-Varnish-CookieINHashed-On
C-Via
X-Ec-Custom-Error
Cache-Host
X-Varnish-Remaining-TTL
X-WP-CF-Super-Cache-Active
Thinkindot-CacheControl-Type
X-VServer
Thinkindot-CacheControl
X-WA-Info
X-WADP-Cache
TDXMobile
Thinkindot-Control
Host-ID
Apple-News-Services-Host
Country-Code
X-Varnish-CookieHashed-On
Cluster
Click-Count-Action-Start
Click-Count-Error
Section-Io-Origin-Status
X-Parent-Response-Time
Section-Io-Origin-Time-Seconds
Section-Io-Id
Section-Origin-Responded
X-Restarts
X-Node-Id
X-GeoIP
X-Test
X-Has-Esi
X-Vmg-Version
X-Gzip
X-Wix-Viewer-Type
Server-Host
User-Cache-Control
X-Generated-On
X-GeoIP-Country-Code
We-Hiring
X-GeoIP-Region-Code
X-Accel-Expires-Debug
X-App
X-Hash
X-Cache-FS-Status
X-Cache-Id
X-Block-Status
X-Bip
X-Buckets
X-Worker
X-Hnp-Log
X-Location
X-Origin
X-DPWN-IS-SECURE
X-Ad-Defer-Variation
X-Gen-Mode
X-Accel-Buffering
X-Minions-Version
X-Is-Gdpr
X-LB-NoCache
X-JWT-State
Fastly-Backend-Name
X-HS-Content-Campaign-Id
Ssr
L
Kp-EeAlive
X-Auto-Login
Is-Eu
X-Scale
Cache-Key
NM-Fastcgi-Cache
X-Date
X-Request-Start
Mail-Subject
Cache-Provider
X-Varnish-Beresp-Status
CloudFront-Viewer-Country
Cmsid
Cmstype
X-Thanos
X-Fetched-On
X-Var-Ttl
CDCHOST
X-Variation
X-Slack-Backend
X-Level-Front-Cache
X-Cdn-Srv
Server-Hostname
X-Planisys-CDN-Cache
Server-Ext
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Fastly-Backend
Sever-Int
X-Geo-Header
Svr
X-Developers
X-Up
Origin-CC
X-Dispatcher-Number
Platform
Pics-Label
Origin-EX
X-Esi-Check
Adler-Geo
X-CSRF-Token
Producers
X-Pool
X-RM-Cache-TTL
Cdn
X-Forwarded-Site
X-FC-Vary-Parameters
X-Qloud-Router
Web-Mar-Region
X-Slack-Shared-Secret-Outcome
X-Server-IP
X-V-Cache
X-VarnishDD-TTL
Gh-Request-Id
CacheControlHeader
X-Varnishpool
X-Cache-Backend
X-Region-Sid
X-NCache
X-Mvc-Supplant-Cachable
X-Irp-Debug
X-Nginx-Cache-Key
X-Op-Id-All
X-Refresh
X-Platform
X-Owner
X-HN
X-CacheTTL
Datacenter
X-Azure-Ref-OriginShield
Wxu-Next-Commit
Machine
X-Ckpd-Fst-Backend
X-Aicache-OS
X-Cache-Tags
Fastly-SSL
PFcat
X-Conf
Wxu-Next-Region
Wxu-Next-Hostname
X-Nananana
X-Dispatcher-Server
AKAMAI
X-Device-Os
HostName
Ha-Gx-Prefs
HA-Ipaddr
X-Cached-By
NGX
X-Varnish-Ttl
X-Men
L5d-Success-Class
X-CGP
X-Via-Poph
X-Via-Popn
X-Eu-Site
X-Via-Popv
Canary
X-Csrf-Jwt
X-Cache-Remote
X-Org
X-Tb-Optimization-Total-Bytes-Saved
On-Server
X-Webkit-CSP-Report-Only
X-Mvc-Supplant-OutputCached
X-AK-Request-ID
X-Servedbyhost
Cdnsip
Cdncip
X-VC
Env
GeoIP-Latitude
X-HA-Backend
Server-ID
X-Cache-Date
X-API-Version
X-Microcachable
X-Gateway-Cache-Status
X-RCS-CacheZone
X-Gateway-Request-Id
X-Gateway-Skip-Cache
X-Gateway-Cache-Key
X-LB-ID
X-APP-VERSION
X-Fpc
Cache
X-ZONE
X-Mly-Id
X-Wa
X-Zone
Memory
X-Vgn-Hpd-Cached
X-Generated-In
X-DataCenter
X-Vgn-Hpd-Variations-Key
X-Vgn-Hpd-Ssi
Time
Request-ID
X-Webkit-CSP
OT-Force-Account-Verify
Ngx-Var-Key
X-Fastly-Cache
X-Nc
X-Micro-Cache
X-Via-NSCOPI
Eomportal-Instance
Load-Balancing
X-Origin-Expires
X-ND-Cache
X-HS-Status
X-Instance-Name
X-Correlation-ID
X-SIPLIST1
X-Check-Cacheable
IsBot
X-Response-By
X-Client-Ip
X-Vc
X-Request-URI
X-Release
Srv
X-Via-JSL
X-Nf-Request-Id
X-FL-QIT-DEBUG
X-CCDN-Origin-Time
X-Hcs-Proxy-Type
X-VCL-Version
Srvid
X-FL-EDGE
Locid
X-CCDN-CacheTTL
X-From
X-Info
Expect-Staple
X-Cache-NGX
NtCoent-Length
X-Via-CDN
X-Cache-Enabled
True-Client-Ip
X-Srv
Hostname
X-NewRelic-App-Data
AMP-Access-Control-Allow-Source-Origin
X-CS
X-Edge-Pop
X-MCACHE
Edge-Copy-Time
X-Via-SSL
X-Via-Edge
X-CSRF-TOKEN
X-Api-Version
X-Provided-By
GeoIp-Country-Code
X-Proxy-CacheRZ
XkeyRZ
X-Debug-Cache-Store
X-Lambda-Id
Path
X-NGINX-Cache
X-Debug-Cache-Fetch
X-Amz-Meta-Cb-Modifiedtime
Uri
Location
GeoIP-Country-Code
X-Cache-Expires
X-Dc
X-EC-Lua
True-Client-IP
X-Edge-POP
X-Oss-Storage-Class
X-Oss-Request-Id
X-Oss-Server-Time
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
Resin-Trace
Sid
X-Vcl-Version
X-Cs
VNS-Age
Servername
VNS-Cache
X-Vtex-Remote-Cache
X-Fastly-Country-Code
X-Render-Time
Cross-Origin-Opener-Policy-Report-Only
CPC-Age
CPC-Cache
X-B3-SpanId
X-NODE
X-Moov-Xdn-Version
X-Moov-T
Traceparent
X-Air-Pt
X-CLOUD-TRACE-CONTEXT
X-VCT
X-Viewer-Country
X-Scheme
Fastly-Drupal-Html
CDN
X-TH-Server
X-RateLimit-Reset
LB
X-PERF
X-ATG-Version
X-ApacheServer
X-Cdn-Request-ID
X-TX-ID
X-Akamai-Pragma-Client-IP
Rip
X-Varnish-Authentication
FSS-Cache
X-Contensis-Viewer-Groups
X-Cache-ASPX
X-MSEdge-Features
X-Pod-Name
Esi-Enabled
Powered-By
X-MSEdge-Flight
Timeexpire
X-NAPM-TraceId
X-Varnish-Beresp-TTL
X-FPC
CountryCode
X-Accel-Version
X-Datadome
X-Datacenter
M-TraceId
X-Cdn-Cache-Status
YJS-ID
X-CF-Lambda-Version
X-Upstream-Ht
X-SERVER-NAME
X-Clientip
X-WA
X-Github-Request-Id
X-RateLimit-Remaining-Second
True-Client-Country-4JS
X-Service-Response-Time
X-PAYTM-SRV-ID
X-CF-Lambda-Fn
Tracecode
Sm-Log-Id
V-Age
X-RateLimit-Limit-Second
X-Upstream-Ct
XServer
X-Cache-Type
X-Geo
HIT
X-Srcache-Store-Status
X-Srcache-Fetch-Status
X-VG-WebCache
X-LiteSpeed-Cache-Control
X-Udemy-Cache-App-Namespace
X-NC
Ohc-File-Size
X-Lb-Id
Proxy-Connection
X-CACHE-KEY
XM
Server-Id
ENV
RNT-Machine
RNT-Time
X-TraceId
X-B3-Parentspanid
X-Wikidot-Static-Cache
Ngx
N-Cache
X-Wikidot-Backend
X-ServedByHost
X-Rebelmouse-Cache-Control
Yjs-Id
X-Bl-Debug
X-CDN-Cache-Status
X-Rebelmouse-Surrogate-Control
Epwk-X-Cache
X-Shop-Environment
Geoip-Latitude
X-Cdn-Forward
X-Orig-Expires
X-Ha-Backend
WZWS-RAY
X-Forwarded-Path
X-Tenant
X-Hyper-Cache
X-Dw-Trace-Id
Content-Style-Type
Content-Script-Type
X-Via-PopN
Inserted-Into-Cache-At
User-Agent
X-MP-GENERATED-AT
Pramga
Req-ID
X-B3-ParentSpanId
X-Cdn-Diag
X-MiniProfiler-Ids
X-Connection-Hash
X-B3-Trace-ID
X-Vgn-Hpd-Reason
X-Swift-Error
X-Via-PopH
Expiry
X-Lb-Nocache
X-Serial
Ec-Rule-Version
X-Fastly-Backend-Reqs
X-Via-PopV
X-Lsadc-Cache
X-F-Status
X-TT-LOGID
X-Qnm-Cache
X-M-Reqid
X-M-Log
Lb
X-Cache-Ngx
X-Stale
X-Mid-Debug-Cache-Disk
X-Mid-Debug-Cache-Key
X-Akamai-ERPolicy
X-Akamai-ERRuleID
X-Yottaa-OS
X-Webstats-RespID
X-Request-URL
X-UP
My-App
X-LiteSpeed-Tag
X-Th-Server
MIME-Version
Cneonction
X-IPS-Cached-Response
Warning
X-Snapshot-Date