Threat Level: green Handler on Duty: Rick Wanner

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
Strict-Transport-Security
X-Frame-Options
X-Content-Type-Options
Last-Modified
Link
CF-Cache-Status
Cf-Request-Id
Accept-Ranges
ETag
CF-RAY
Expect-CT
Pragma
X-Powered-By
X-Cache
Via
Age
X-XSS-Protection
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Xss-Protection
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-FRAME-OPTIONS
X-Download-Options
X-Timer
X-Request-Id
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-Adblock-Key
X-AspNet-Version
X-Permitted-Cross-Domain-Policies
Alt-Svc
X-Runtime
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Cache-Status
X-Generator
CF-Ray
X-Cacheable
X-Iinfo
Timing-Allow-Origin
X-Envoy-Upstream-Service-Time
X-Request-ID
Feature-Policy
X-Ua-Compatible
X-Content-Security-Policy
Status
X-Drupal-Dynamic-Cache
Content-Encoding
X-AspNetMvc-Version
Access-Control-Expose-Headers
X-CDN
Upgrade
X-XSS-PROTECTION
Access-Control-Max-Age
X-Via
X-Robots-Tag
X-Cache-Group
Server-Timing
X-UA-Device
Request-Context
Keep-Alive
X-Amz-Request-Id
X-AH-Environment
X-Dns-Prefetch-Control
X-Turbo-Charged-By
X-Proxy-Cache
X-Backend
X-Amz-Id-2
X-Ws-Request-Id
X-Age
Host-Header
P3p
X-Server-Powered-By
X-Hacker
X-Server
X-Rq
X-Vhost
EagleId
X-Varnish-Cache
Grace
X-Amz-Version-Id
X-Dispatcher
X-LiteSpeed-Cache
Cf-Edge-Cache
Allow
X-Akamai-Path-Stats
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Swift-CacheTime
X-Swift-SaveTime
X-Device
Ali-Swift-Global-Savetime
X-WebKit-CSP
X-Nginx-Cache-Status
X-Page-Speed
X-Aws-Lambda-Call-Status
X-Host
Accept-CH
X-Node
X-OneAgent-JS-Injection
X-Pingback
Cf-Railgun
X-Cache-Spec
Request-Id
EagleEye-TraceId
Surrogate-Control
X-Server-Id
X-Akam-SW-Version
X-Backend-Server
X-Cache-Lookup
X-Response-Time
X-Readtime
Accept-CH-Lifetime
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-HW
Content-Location
X-Content-Security-Policy-Report-Only
X-Application-Context
Rating
X-Trace
Fastly-Restarts
X-Cloud-Trace-Context
X-Country
X-Url
X-WebKit-CSP-Report-Only
X-Clacks-Overhead
X-Edge
Accept-Ch-Lifetime
X-MS-InvokeApp
X-Amz-Server-Side-Encryption
X-Rack-Cache
Edge-Control
X-Nginx-Upstream-Cache-Status
X-B3-TraceId
X-PC
X-Ruxit-JS-Agent
X-TtlSet
X-Vname
X-Content-Type
X-Mod-Pagespeed
X-ESI
X-Vcap-Request-Id
X-D2id
X-GoogleNews-Bot
X-Exp-Variant
X-Oneagent-Js-Injection
X-Use-Magma
X-Kinja-Server
X-Exp-Id
X-Kinja
X-Cdn-Fetch
X-Kinja-Revision
X-Kinja-Build
Xkey
X-GitHub-Request-Id
X-Mcache
Verso
X-Amz-Rid
X-CST
Cache-Tag
X-VARITI-CCR
X-Powered-By-Plesk
RTSS
X-Varnish-TTL
Service-Worker-Allowed
X-FastCGI-Cache
X-Upstream
X-Ruxit-Js-Agent
X-Navigation-Version
X-Abt-Application-Version
X-Version
X-ECACHE
X-Cached
X-Client-IP
X-Cnection
X-Dw-Request-Base-Id
X-Ac
X-Px
X-Ttl
X-Element-Page-Cache
X-Server-Lifecycle-Phase
X-Instrumentation
X-Kraken-Loop-Name
X-Server-Name
Arr-Disable-Session-Affinity
Public-Key-Pins
X-SharePointHealthScore
SPRequestGuid
X-Cache-TTL
SPIisLatency
SPRequestDuration
X-Sol
Display
Pagespeed
X-Middleton-Display
X-Country-Code
X-NWS-LOG-UUID
Permissions-Policy
X-Ser
Accept-Ch
X-RateLimit-Remaining
X-Cache-Key
X-Middleton-Response
X-Midtier
Response
X-Kinsta-Cache
X-Edge-Location-Klb
X-Goog-Hash
X-Forwarded-For
Content-MD5
X-SRCache-Fetch-Status
X-SRCache-Store-Status
Access-Control-Request-Method
X-NF-Request-ID
X-DataDome
X-Shield-Request-Id
Front-End-Https
X-Correlation-Id
X-MSEdge-Ref
Cf-Apo-Via
X-HP-Webp
X-Jurisdiction
X-HP-Trace-Id
Edge-Cache-Tag
AR-SID
AR-ATIME
X-Recruiting
AR-CACHE
TP-L2-Cache
AR-Request-ID
AR-PoweredBy
TP-Cache
Nginx-Cache
X-Accel-Expires
X-T
MicrosoftSharePointTeamServices
X-Daa-Tunnel
X-RateLimit-Limit
Mrf-Cache-Status
X-B3-TraceId-Primal
MRF-Tech
X-Powered-CMS
X-ORACLE-DMS-ECID
TCN
X-ORACLE-DMS-RID
X-Grace
X-Mg-S
X-Content-Digest
X-Id
X-TEC-API-VERSION
X-Hits
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-HS-Cache-Config
X-HS-Combine-CSS
X-HS-Content-Id
X-HS-Hub-Id
Server-Node
Server-Name
Filters
X-Request-Processing-Time
X-Request-Received
X-Amzn-Trace-Id
X-Frontend
MS-Author-Via
X-Geo-Country
X-Distributor
S
Fastcgi-Cache
X-Protected-By
X-LLID
X-Language
Cache-Status
X-Browser-Type
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Fastly-Request-Id
X-XRDS-Location
X-PressLabs-Stats
X-LB-Cache
X-Origin-Server
Cross-Origin-Opener-Policy
X-Ezoic-Cdn
Count-Hit
X-Fastcgi-Cache
X-B3-Sampled
X-FB-Debug
Host
X-F-Cache
X-Ua-Browser
X-Amz-Meta-S3cmd-Attrs
X-Ab
Charset
X-Git-Hash
X-Forwarded-Proto
X-Page-Id
X-Seen-By
Filterid
Payment
X-Request-Handler-Origin-Region
X-Microsite
X-Litespeed-Cache
X-ASPNET-VERSION
X-Cluster-Name
X-VCache
X-Cache-Age
X-Ratelimit-Reset
Surrogate-Key
Realpath
X-TTL
X-Rid
X-Origin-Cache
Cache-Tags
Accept-Charset
X-NGENIX-Cache
X-Template
Alternate-Protocol
Access-Control-Allow-Method
Retry-After
X-Www-Served-By
X-Webkit-Csp
X-Logged-In
X-AppVersion
X-Activity-Id
X-DynaTrace
X-Upgrade-Enabled
Cleartype
X-DIS-Request-ID
X-Az
X-App-Environment
X-Route-Name
X-Varnish-Grace
X-Aspnet-Duration-Ms
X-Flags
X-Request-Guid
X-Providence-Cookie
X-Tb
X-Amz-Replication-Status
X-Varnish-Backend
X-Is-Crawler
X-Wix-Request-Id
X-TT
X-Signature
X-B
X-B-Cache
X-Source
X-Type
X-Node-Name
X-Envoy-Decorator-Operation
X-Hostname
Paypal-Debug-Id
DC
ServerID
Frame-Options
X-Drupal-Cache-Tags
X-Revision
X-Fastly-Request-ID
X-Debug
X-Proxy
X-Mobile
X-Server-ID
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Content-Options
X-Contextid
X-Pinterest-Rid
Amp-Access-Control-Allow-Source-Origin
Pinterest-Version
Pinterest-Generated-By
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-Load-Cache
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-Goog-Storage-Class
X-Cache-Rule
X-Goog-Generation
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-N
X-Cache-Control
Country
X-Magnolia-Registration
Refresh
Node
X-Content
Referer-Policy
X-Response-Served-From
X-User-Agent
X-Whom
X-Original-Request-Id
X-EdgeConnect-Cache-Status
NGB
Viewport
X-Environment-Context
X-Cacheable-TTL
Access-Control-Request-Headers
X-L-Path
X-Framework
X-Debug-IsConnected
X-G
X-Mid
X-Cache-TTL-Remaining
X-Servername
X-Unique-Id
X-Yottaa-Optimizations
X-Content-Powered-By
Url
X-Yottaa-Metrics
X-Jobs
X-Page-View
X-Debug-IsPreview
X-Akamai-Request-ID2
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Real-IP
Uber-Trace-Id
X-Cache-Time
X-Is-Bot
X-NYM-Debug-Backend
X-Cache-Grace
X-Status
Content-Disposition
X-Adobe-Content
X-Adobe-Loc
X-Rendered-As
X-Varnish-Server
X-Varnish-Age
X-ProcessESI
X-RemovedCookies
X-Oracle-Dms-Rid
Akamai-GRN
X-Oracle-Dms-Ecid
X-XRDS-LOCATION
X-Instance
X-Ratelimit-Remaining
Countrycode
Srv
X-Mg-Request-UUID
Version
X-Drupal-Cache-Contexts
X-COUNTRY
X-Time
X-APP-VERSION
X-Http-Reason
X-CDN-Forward
X-Via-JSL
X-App-Server
X-Restarts
X-Cache-Expired-At
X-Trace-Id
Accept-Language
Healthy
Protected
X-Cache-Hit
X-Tumblr-Pixel
X-Tumblr-User
X-IPLB-Instance
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-IPLB-Request-ID
X-Hosted-By
X-Debug-Info
X-Cache-Operation
X-Azure-Ref
Cross-Origin-Resource-Policy
X-Nginx-Cache-Key
X-Device-Type
X-Ratelimit-Limit
X-Tt-Logid
X-Backend-Name
Section-Io-Cache
X-Akamai-Edgescape
Content-Secure-Policy
X-FW-Dynamic
X-FW-Hash
X-FW-Serve
Backend
X-FW-Type
X-FW-Server
X-FW-Static
Server-Info
Fastcgi-Useragent
X-ECache
Liferay-Portal
X-RTag
Ms-Operation-Id
X-Cache-Action
MS-CV
X-Api-Version
X-Proxy-Cache-Status
X-RN-RSRV
X-UPSTREAM-Address
Load-Balancing
X-Mobile-URL
X-Rule
Meta-Geo
X-Cache-NGX
GEO-INFO
X-Storage
X-Mode
X-Varnish-Beresp-Grace
X-VC-Cache
X-Content-Age
CF-IPCountry
X-PHP-Host
X-PCL
X-Proto
Locale
X-OCL
X-PHP-Backend
X-Handled-By
S-Rt
X-SayCDN-TTL
X-No-Session
X-Cache-Enabled
X-Forwarded-Host
X-Skip-Cache
X-Urbn-Site-Id
X-Labrador-Cache-Channel
X-Site-Version
X-Redis-Cache
X-Uri
X-Edge-Location
X-Urbn-Context-Path
X-Region
X-Cms-Context
X-LJ-Flow-ID
X-Say-Cacheable
X-VWS-Id
X-Say-TTL
X-AWS-Id
X-Sql-Count
X-Varnishpool
X-Sql-Duration-Ms
X-Varnish-Hostname
X-Extlb
CDN-CachedAt
DB-Nickname
Azure-SiteName
CDN-Cache
CDN-RequestCountryCode
X-GeoCountry
X-Generated-By
CDN-PullZone
CDN-EdgeStorageId
CDN-RequestId
X-FB-TRIP-ID
CDN-Uid
Azure-InstanceId
X-Xfnlog-Site
X-Via-Fastly
X-Alternate-Cache-Key
Mn-Server-Ip
Selected-Fe
X-Access
X-Adobe-Source
X-BYPASS-REASON
X-Cache-Server
X-Web-Node
Eomportal-Instance
Azure-RegionName
X-Zipkin-Id
X-Hl-Ver
X-HTML-Minification-Powered-By
X-Cache-Type
X-Detected-As
Webcakes-App-Name
X-Proxy-Build
X-ProxyCache-Key
X-Varnish-Cache-Hits
X-ProxyCache-Status
X-Proxied
X-Sorting-Hat-PodId
X-Locale
X-Origin-Hint
TWC-Locale-Group
X-Shopify-Stage
X-Request-Time
X-Routing-Service
X-ServerID
X-Section
Web-Mar-Node
X-ShardId
TWC-Privacy
X-ShopId
X-Generation-Time
X-GeoCode
X-Sorting-Hat-ShopId
TWC-GeoIP-Country
Webcakes-App-Version
Webcakes-Region
X-Timing-Wait
TWC-Device-Class
Property-Id
TWC-Connection-Speed
Onion-Location
TWC-GeoIP-LatLong
X-Format
X-SRV
Azure-SlotName
Azure-Version
X-UA-Device-Type
X-Cache-Status-Check
X-Nginx-Cache
X-Cache-Host
Apigw-Requestid
X-Tid
X-Server-W
X-UUID
WP-Super-Cache
X-URL
X-SaId
X-Origin-Date
X-JoinUs
X-R9-Blue-Green-Version
X-Storefront-Renderer-Rendered
X-Ms-Request-Id
X-Datadome
X-Ms-Version
Cache-Name
X-Correlation-ID
X-FireWall-Port
X-WP-CF-Super-Cache
X-DynaTrace-JS-Agent
X-WP-CF-Super-Cache-Cache-Control
ServedBy
X-Zen-Fury
X-LSADC-Cache
X-Amzn-RequestId
X-Amz-Apigw-Id
Xserver
X-Human
X-Varnish-Ttl
X-Ua
X-TNCMS
X-Loop
X-Cache-Tags
Cache
Source
Xet-Cookie
X-Debug-Cache
X-RCS-CacheZone
X-Reqid
X-TA-CDN-Provider
X-GEO
X-Dc
X-Varnish-Hits
X-App-Version
X-Cached-By
X-Pubstack
X-Soup
X-MP-GENERATED-AT
X-Aspnetmvc-Version
Origin
Cross-Origin-Window-Policy
X-Amzn-Remapped-Content-Length
SD-X-WS
X-Cdn
X-Vgn-Hpd-Reason
X-Origin-CC
X-Newrelic-Synthetics
WPO-Cache-Message
WPO-Cache-Status
X-Webkit-CSP
X-Origin-TTL
X-Provided-By
From-Origin
X-Tumblr-Pixel-2
X-Service
X-IPS-LoggedIn
LB
X-Varnish-Beresp-Ttl
X-AOL-HN
X-NewRelic-App-Data
Rip
Webserver
X-Tec-Api-Version
X-B3-SpanId
X-Tec-Api-Root
X-Via-NSCOPI
X-TIME
X-Tec-Api-Origin
X-FW-Version
X-GG-Cache-Date
X-Request-Host
X-ScT
X-D
X-Connection-Hash
X-Served-From
X-Shop-Environment
Cdncip
DCR-Decision-By
X-Cluster-Node
X-Cache-NE
Cdnsip
BehaviorPad-Version
A
X-Forwarded-Path
X-External-Request-Id
X-Processor
X-NAPM-TraceId
X-PBS-Appsvrname
X-Orig-Expires
X-Ec-GeoHdr
X-Ec-Fail
X-Rojux
X-S
X-Destination
DCR-Processing-Time-Ms
X-Developer
X-Rewrite-Enabled
X-S-Cookie
X-SRCache-Key
X-A
Lang
MD5-Digest
X-VG-WebCache
X-A-Ccd
HostName
X-A-Dam
Meta-Geo-Continent
Ngx.Var.Host
Surrogated-Key
Sslversion
Rendered-Blocks
T-Server
Odigeo-Trace-Id
X-CSRF-Token
Xc-Version
X-BCube-Filmed-By
X-Vdms-Version
X-B-Cookie
X-ARC
X-TIM-N
X-Tenant
Expiry
X-Owner
X-Bc-Bl
X-Vdms-Path
X-User
X-A-Dcw
Host-ID
X-A-Dgt
X-A-Wwc
X-AK-Request-ID
X-Aed
X-Application
OT-Force-Account-Verify
X-B3-Traceid
X-VC
Mime-Version
X-Platform-Server
CPC-Age
X-Level-Front-Cache
Machine
X-Aicache-OS
X-Dispatcher-Number
X-Generated-On
Environment
X-Accel-Buffering
X-Bip
Upgrade-Insecure-Requests
VNS-Cache
X-Thanos
Redirect-Candidate
VNS-Age
CPC-Cache
X-Qloud-Router
X-Pool
X-Parent-Response-Time
X-Varnish-Beresp-Status
X-Variation
X-Ad-Defer-Variation
X-V-Cache
X-SplitTest
X-Cache-Info
X-Sn-Servicetimems
X-Slack-Backend
X-SIPLIST1
X-Cache-Id
X-Cache-Bucket
X-BBC-Edge-Cache-Status
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-Branch-Name
X-Thinkindot-L3
Wxu-Next-Hostname
Traceparent
Tube-Get-Contents
X-Worker
Tube-Got-Eval
Thinkindot-Control
Thinkindot-CacheControl-Type
Server-Host
Servername
TDXMobile
Thinkindot-CacheControl
Tube-Got-Results
Tube-Return
Wxu-Next-Region
X-VServer
X-Varnish-Remaining-TTL
X-Varnish-CookieINHashed-On
X-CacheTTL
Wxu-Next-Commit
X-Wix-Viewer-Type
V-Age
Vix-Hermes-Req-Id
X-WADP-Cache
X-Varnish-CookieHashed-On
X-Clara-WADP
Req-Svc-Chain
X-Gateway-Skip-Cache
X-GeoIP
X-GeoIP-City
X-Gzip
X-Gateway-Request-Id
X-Gateway-Cache-Status
X-Fmm-Version
X-Fetched-On
X-Forwarded-Site
X-Gamma-Serve
X-Gateway-Cache-Key
X-Hash
X-Irp-Debug
X-Planisys-CDN-TTL
X-Origin
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
X-Origin-Response-Time
X-Policy
X-Optimistic-Header
X-Minions-Version
X-Loc
X-Mvc-Supplant-Cachable
X-Mvc-Supplant-OutputCached
X-NodeID
X-RateLimit-Limit-Second
X-Eu-Site
X-Core-Mission
X-Scale
X-Csrf-Jwt
X-SB
X-S-Maxage
X-CMSURLCustom
X-Cluster
X-Ckpd-Fst-Backend
X-CGP
X-Sigma-Backend
X-Sigma
X-Clientip
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
X-Region-Sid
X-Ec-Custom-Error
X-RateLimit-Remaining-Second
X-Epic-Correlation-Id
X-Esi-Check
X-Device-Os
X-Request-URI
X-DefElseHash
X-Datadog-Trace-Id
X-DefHash
X-Rocket-Nginx-Serving-Static
X-Rocket-Build-Number
X-Cdn-Origin
X-DPWN-IS-SECURE
Fastly-SWR
Apple-News-Services-Parsed-Url
Fastly-SSL
Fastly-SIE
Apple-News-Services-Request-Url
Apple-News-Services-Host
Ha-Gx-Prefs
Kp-EeAlive
L5d-Success-Class
IsBot
Is-Eu
HA-Ipaddr
Fastly-GeoIP-CountryCode
Cache-Host
Cmstype
Country-Code
Cmsid
Click-Count-Action-Start
Click-Count-Error
Decoy-Debug-Key
Decoy-Debug-Status
Canary
Candidate-Md5Url
DSUID
Decoy-Debug-TTL
Apple-News-Services-Handled
L
Origin-CC
Producers
Origin-EX
X-Cache-Debug
Platform
Memcached
NM-Fastcgi-Cache
Cache-Hits
Adler-Geo
Mobile-Detection-Method
Release
X-Tx-Id
X-WA-Info
X-NCache
X-Geo-Header
X-ZONE
X-Has-Esi
CDCHOST
X-Is-Gdpr
X-Hnp-Log
X-HS-Content-Campaign-Id
X-JWT-State
X-Gen-Mode
Cluster
X-Developers
Datacenter
CloudFront-Viewer-Country
X-VG-TLSProxy
Server-Ext
Mail-Subject
X-Core-Value
Gh-Request-Id
X-Scheme
We-Hiring
X-Viewer-Country
X-Proxy-Cache-Info
X-Origin-Time
Server-Hostname
NGX
User-Cache-Control
Web-Mar-Region
Fastly-Backend-Name
X-Nyt-Route
X-Block-Status
State
X-Cdn-Srv
X-Auto-Login
X-Gdpr
Svr
Sever-Int
X-INCAP-ABP
Ec-Rule-Version
X-WP-CF-Super-Cache-Active
X-Trace-ID
Cache-Tv-Group
WebServer
X-Cache-Remote
X-Sucuri-Cache
X-Sucuri-ID
X-LB-NoCache
AKAMAI
X-Session-Fingerprint
X-ND-Cache
Fastcgi-Cache-TTL
X-Rebelmouse-Surrogate-Control
X-Presslabs-Stats
Ssr
X-Origin-Expires
X-Var-Ttl
X-Rebelmouse-Cache-Control
X-ATG-Version
X-FC-Vary-Parameters
Time
X-Azure-Ref-OriginShield
X-Fastly-Cache
X-Fastly-Backend
Memory
X-Udemy-Cache-App-Namespace
Sid
X-Newrelic-App-Data
Pics-Label
X-Nf-Request-Id
Fastly-Drupal-HTML
SID
X-Tb-Optimization-Total-Bytes-Saved
X-Pod-Name
X-Generated-In
X-NWS-UUID-VERIFY
X-Via-Popv
Env
X-Via-Popn
X-Via-Poph
AMP-Access-Control-Allow-Source-Origin
X-Servedbyhost
X-Xrds-Location
X-Cache-Date
X-Buckets
X-Refresh
X-Akamai-Transformed
Server-ID
X-Ig-Push-State
X-Cs
X-DC
X-Release
X-Conf
X-Edge-Pop
X-Pass-Why
X-MSEdge-Flight
X-Fpc
My-App
X-Up
X-Dispatch
X-NC
X-MSEdge-Features
Fastly-Drupal-Html
X-EC-Lua
X-Microcachable
X-Tumblr-Pixel-3
X-Endurance-Cache-Level
X-Wa
X-Lambda-Id
X-RateLimit-Reset
X-Dmc
X-Esi
CDN
X-PX
X-MCACHE
GeoIp-Country-Code
X-ID
X-CS
X-Be
X-CACHE-AGE
Magicmarker
X-Req
X-VCL-Version
True-Client-IP
X-Zone
X-CLOUD-TRACE-CONTEXT
X-TRACE-ID
X-TX-ID
X-Webkit-CSP-Report-Only
X-NGINX-Cache
X-LB-ID
X-Wikidot-Static-Cache
X-Wikidot-Backend
X-CACHE-KEY
X-Vc
X-Srv
Hostname
CacheControlHeader
X-Air-Trace-Id
X-Air-Source
X-CSRF-TOKEN
X-Air-Hostname
X-Yandex-Sdch-Disable
X-Hyper-Cache
X-B3-Spanid
True-Client-Country-4JS
X-Op-Id-All
X-Micro-Cache
X-TH-Server
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-M-Log
X-HS-Status
X-Vcl-Version
X-App
Pramga
Resin-Trace
X-Air-Pt
X-M-Reqid
True-Client-Ip
X-Alfa-Service
Path
X-Varnish-Beresp-TTL
C-Via
GeoIP-Country-Code
Tcn
X-Qnm-Cache
N-Cache
X-GeoIP-Region-Code
X-GeoIP-Country-Code
Tracecode
X-TrackingId
X-SERVER-NAME
Fastcgi-X-Cache-Version
Section-Io-Id
Section-Io-Origin-Status
Esi-Enabled
Section-Origin-Responded
X-Akamai-Pragma-Client-IP
X-Vercel-Cache
On-Server
X-Vercel-Id
X-Date
WWW-Authenticate
X-Accel-Expires-Debug
X-FPC
Section-Io-Origin-Time-Seconds
X-PAYTM-SRV-ID
X-Platform
X-Check-Cacheable
NtCoent-Length
Proxy-Connection
Hit
X-Edge-Origin-Shield-Bytes
X-RAMCache
X-Edge-Origin-Shield-Region
X-WA
Yjs-Id
X-Datacenter
X-Webkit-Csp-Report-Only
Server-Id
X-Platform-Processor
X-Vtex-Remote-Cache
X-Edge-POP
X-Mly-Id
X-Node-Id
X-Platform-Cluster
X-Platform-Router
X-Via-CDN
FSS-Cache
X-Vtex-Processado-Em
GeoIP-Latitude
X-Geo
Lb
X-LiteSpeed-Cache-Control
X-ServedByHost
X-Lb-Id
X-SD-PageType
X-API-Version
ENV
X-Request-Start
X-LAGOON
YJS-ID
Powered-By
X-Old-Content-Length
User-Agent
X-Response-By
X-Cdn-Forward
X-UA
X-Dw-Trace-Id
X-AIR-PT
HIT
X-Client-Ip
X-Via-PopH
X-Via-PopN
Cache-Key
X-PERF
X-Via-PopV
Cdn
X-ApacheServer
X-Akamai-ERPolicy
X-Akamai-ERRuleID
XServer
DynaTrace
X-Traceid
XkeyRZ
X-Webstats-RespID
X-Li-Pop
X-Location
X-FORWARDED-FOR
X-Instance-Name
X-Proxy-CacheRZ
Server-Ttl
Locid
Srvid
X-FL-EDGE
X-CUA
X-From
Geoip-Latitude
X-Li-Fabric
X-LI-UUID
X-LI-Proto
X-Cache-Ttl
Dnion-Transfer-Encoding
X-Render-Time
X-Via-Ucdn
X-TT-LOGID
X-Service-Response-Time
Sm-Log-Id
X-DB
X-RPM
X-Varnish-Authentication
X-RSL
X-Director
X-DW
X-DSS
X-DI
X-RPS
X-Contensis-Viewer-Groups
Ohc-File-Size
X-Cache-ASPX
X-LiteSpeed-Tag
X-CF-Powered-By
PFcat
X-HN
DT-Hot-News
X-VarnishDD-TTL
Nginx-CQVIP
Location
X-Proxy-Cache-Hk
XM
X-Proxy-Upstream
PICS-Label
X-Litespeed-Cache-Control
X-Wp-Cf-Super-Cache-Cache-Control
X-Wp-Cf-Super-Cache
X-HostName
X-Request-Url
X-Lb-Nocache
X-B3-ParentSpanId
X-DataCenter
X-Fastly-Cache-Hits
X-Server-IP
X-Cdn-Request-ID
Vha6-Origin
Wpo-Cache-Status
Wpo-Cache-Message
X-Fastly-Backend-Reqs
X-Cache-Ngx
Warning
X-Ips-Loggedin
Wp-Super-Cache
CountryCode
X-Yottaa-OS
X-Test
Swift-Performance
CF-Cached-On
X-ElasticPress-Query
WZWS-RAY
Fastcgi-Cache-Ttl
SRV
Req-ID
X-Moov-Xdn-Version
X-Moov-T
X-Mg-Cache