Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Accept-Ranges
Expect-CT
X-XSS-Protection
CF-RAY
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
P3P
X-Xss-Protection
X-Served-By
X-Download-Options
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Request-ID
Access-Control-Allow-Credentials
X-Request-Id
CF-Ray
X-Permitted-Cross-Domain-Policies
X-AspNet-Version
Alt-Svc
Content-Security-Policy-Report-Only
X-Runtime
X-DNS-Prefetch-Control
X-Drupal-Cache
X-Check
X-Cache-Status
X-Generator
X-Cacheable
P3p
Timing-Allow-Origin
X-FRAME-OPTIONS
X-Iinfo
X-Envoy-Upstream-Service-Time
X-Content-Security-Policy
X-Drupal-Dynamic-Cache
Feature-Policy
Content-Encoding
Upgrade
Status
Access-Control-Expose-Headers
X-AspNetMvc-Version
X-CDN
Access-Control-Max-Age
X-Via
Server-Timing
X-UA-Device
X-Robots-Tag
Request-Context
X-Turbo-Charged-By
X-Amz-Request-Id
X-Cache-Group
EagleId
X-Amz-Id-2
X-Backend
Keep-Alive
X-AH-Environment
X-Proxy-Cache
X-Ws-Request-Id
X-Server
X-Age
X-Hacker
Host-Header
X-Ua-Compatible
Cf-Edge-Cache
X-Vhost
X-Server-Powered-By
X-Rq
Allow
X-Dispatcher
X-Varnish-Cache
Grace
X-Amz-Version-Id
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-LiteSpeed-Cache
X-OneAgent-JS-Injection
X-WebKit-CSP
Accept-CH
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Device
Cf-Apo-Via
X-Page-Speed
Cf-Railgun
X-Aws-Lambda-Call-Status
X-Host
X-Server-Id
X-Pingback
X-Node
X-Cache-Spec
X-Nginx-Cache-Status
X-Akam-SW-Version
Surrogate-Control
X-Dns-Prefetch-Control
X-Backend-Server
EagleEye-TraceId
X-Cache-Lookup
Request-Id
X-Readtime
X-Ruxit-JS-Agent
X-HW
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Cloud-Trace-Context
Accept-Ch-Lifetime
X-Content-Security-Policy-Report-Only
X-Trace
X-Application-Context
X-Response-Time
X-CST
Permissions-Policy
X-Mod-Pagespeed
X-Nginx-Upstream-Cache-Status
Fastly-Restarts
X-Edge
X-Country
Content-Location
X-WebKit-CSP-Report-Only
Accept-CH-Lifetime
X-Content-Type
X-Mcache
X-ECACHE
Rating
X-Url
X-Clacks-Overhead
X-MS-InvokeApp
X-TtlSet
X-PC
X-Vname
X-Amz-Server-Side-Encryption
X-Midtier
X-VARITI-CCR
RTSS
Cache-Tag
X-Varnish-TTL
X-Vcap-Request-Id
X-Ac
X-Element-Page-Cache
Verso
Origin-Trial
X-B3-TraceId
X-Cdn-Fetch
X-Exp-Id
X-Kinja
X-Use-Magma
X-D2id
X-Kinja-Server
X-Kinja-Revision
X-GoogleNews-Bot
X-Exp-Variant
X-Kinja-Build
X-Server-Name
X-Rack-Cache
X-Cnection
X-Cache-TTL
X-Litespeed-Cache
X-Powered-By-Plesk
Service-Worker-Allowed
X-ESI
Xkey
X-Client-IP
X-Abt-Application-Version
X-Navigation-Version
X-Fastcgi-Cache
X-NWS-LOG-UUID
Edge-Control
SPRequestGuid
X-SharePointHealthScore
X-GitHub-Request-Id
X-Amz-Rid
X-Cached
X-Ttl
X-Px
X-Mg-S
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-Instrumentation
X-Browser-Type
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
Arr-Disable-Session-Affinity
X-Upstream
SPRequestDuration
SPIisLatency
X-Correlation-Id
X-Cache-Key
X-Middleton-Display
Pagespeed
Display
X-Sol
Content-MD5
X-Dw-Request-Base-Id
X-SRCache-Fetch-Status
X-SRCache-Store-Status
Access-Control-Request-Method
Edge-Cache-Tag
X-Goog-Hash
X-XRDS-Location
X-Daa-Tunnel
Front-End-Https
X-NF-Request-ID
X-Country-Code
Public-Key-Pins
X-Version
X-RateLimit-Remaining
X-Forwarded-For
X-Powered-CMS
AR-Request-ID
AR-ATIME
AR-CACHE
AR-SID
AR-PoweredBy
X-Id
X-HP-Trace-Id
TCN
X-Jurisdiction
X-HP-Webp
X-MSEdge-Ref
X-Recruiting
X-T
X-Content-Digest
X-Accel-Expires
X-Middleton-Response
Response
Mrf-Cache-Status
MRF-Tech
X-B3-TraceId-Primal
X-Ser
X-Shield-Request-Id
TP-Cache
TP-L2-Cache
Nginx-Cache
S
X-Hits
X-Amzn-Trace-Id
X-Request-Received
X-Request-Processing-Time
X-Edge-Location-Klb
Cache-Status
X-Kinsta-Cache
X-HS-Combine-CSS
X-HS-Cache-Config
X-HS-Hub-Id
X-HS-Content-Id
Server-Node
X-Distributor
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
X-Fastly-Request-ID
X-Grace
Cache-Tags
Alternate-Protocol
MicrosoftSharePointTeamServices
Server-Name
Fastcgi-Cache
X-Protected-By
X-Ratelimit-Limit
X-DataDome
X-TTL
X-DIS-Request-ID
X-Geo-Country
X-Ezoic-Cdn
X-Ruxit-Js-Agent
X-LB-Cache
X-Origin-Server
X-Microsite
X-Request-Handler-Origin-Region
X-Frontend
X-Ua-Browser
X-Rid
X-Debug-Info
X-Ratelimit-Reset
Cross-Origin-Opener-Policy
Healthy
Payment
X-Www-Served-By
X-NGENIX-Cache
X-Varnish-Backend
Filterid
X-Git-Hash
X-Forwarded-Proto
X-Logged-In
X-FB-Debug
Cleartype
X-Page-Id
X-PressLabs-Stats
X-Ratelimit-Remaining
X-Load-Cache
X-B3-Sampled
Charset
X-VCache
Content-Disposition
X-Webkit-Csp
X-ASPNET-VERSION
X-Origin-Cache
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-LLID
X-Cluster-Name
MS-Author-Via
X-Oracle-Dms-Ecid
X-Oracle-Dms-Rid
X-Hostname
DC
X-GUploader-UploadID
X-Goog-Metageneration
Accept-Charset
X-Upgrade-Enabled
Access-Control-Allow-Method
Retry-After
X-Proxy
Cross-Origin-Resource-Policy
X-F-Cache
X-Activity-Id
X-Az
X-AppVersion
X-Contextid
X-Type
X-Signature
X-Amz-Replication-Status
X-Flags
X-Is-Crawler
X-Hosted-By
X-Seen-By
X-Providence-Cookie
X-Request-Guid
X-Route-Name
X-Revision
X-B-Cache
X-Aspnet-Duration-Ms
Accept-Ch
X-Wix-Request-Id
X-Varnish-Server
X-B
X-TT
X-Amz-Meta-S3cmd-Attrs
X-Azure-Ref
X-Whom
Referer-Policy
Paypal-Debug-Id
Viewport
Amp-Access-Control-Allow-Source-Origin
X-App-Environment
Surrogate-Key
X-DynaTrace
X-RateLimit-Limit
X-Source
X-Aspnetmvc-Version
Count-Hit
Realpath
X-Tt-Trace-Host
X-Fb-Rlafr
X-Tt-Trace-Tag
X-Akamai-Edgescape
X-Mobile
X-App-Server
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
X-B3-Traceid
Host
X-FastCGI-Cache
X-Cache-Control
X-Cache-Age
X-EdgeConnect-Cache-Status
X-HTML-Minification-Powered-By
Version
X-Original-Request-Id
X-Response-Served-From
X-N
Refresh
X-Nginx-Cache
X-Varnish-Grace
X-Oneagent-Js-Injection
X-Cache-Rule
X-Tumblr-Pixel-1
X-Tumblr-User
X-Tumblr-Pixel-0
X-Tumblr-Pixel
SD-X-WS
VIX-Pulpo-Node
Access-Control-Request-Headers
X-Envoy-Decorator-Operation
X-Magnolia-Registration
X-Varnish-Age
VIX-Pulpo-Upstream-Status
Section-Io-Cache
X-Environment-Context
X-RTag
X-L-Path
X-UUID
X-Adobe-Loc
X-Newrelic-App-Data
X-Page-View
X-Cache-Expired-At
X-Cache-Status-Check
X-Cache-Time
X-Adobe-Content
MS-CV
Ms-Operation-Id
X-Rendered-As
X-Servername
X-RemovedCookies
Protected
X-Device-Type
X-Cacheable-TTL
X-Content-Powered-By
X-Framework
X-G
X-Jobs
X-Is-Bot
X-Status
X-Cache-Grace
GEO-INFO
NGB
X-Rule
X-ProcessESI
X-Akamai-Request-ID2
Url
X-FW-Type
X-FW-Hash
X-FW-Serve
X-Http-Reason
Akamai-GRN
X-FW-Server
X-NYM-Debug-Backend
X-FW-Static
X-FW-Version
X-FW-Dynamic
X-Instance
X-User-Agent
X-Debug-IsPreview
X-Backend-Name
X-Debug-IsConnected
X-CDN-Forward
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Tb
X-Cache-Hit
X-Drupal-Cache-Contexts
CDN-RequestId
X-Drupal-Cache-Tags
Pinterest-Generated-By
Pinterest-Version
From-Origin
SRV
X-Pinterest-Rid
X-Tt-Logid
WPO-Cache-Message
WPO-Cache-Status
Country
X-Region
X-Node-Name
Accept-Language
Front
X-Trace-Id
X-URL
X-Real-IP
X-VC-Cache
Fastly-Drupal-HTML
X-Time
X-Fastly-Request-Id
Uber-Trace-Id
Backend
X-Mode
X-Template
X-Content-Options
X-Language
X-Amzn-RequestId
X-Amz-Apigw-Id
X-UPSTREAM-Address
Fastly-SWR
Filters
Fastly-SIE
X-RN-RSRV
X-Generation-Time
X-Rewrite-Enabled
Meta-Geo
X-Cache-Operation
CDN-PullZone
CDN-Uid
CDN-RequestCountryCode
CDN-EdgeStorageId
X-Web-Node
Webserver
Content-Secure-Policy
CDN-Cache
X-DynaTrace-JS-Agent
X-Cache-TTL-Remaining
X-Tumblr-Pixel-2
CDN-CachedAt
X-Cms-Context
X-Cache-Action
X-Proxy-Cache-Status
X-Say-Cacheable
X-Proxy-Cache-Info
X-Format
Apigw-Requestid
X-Cache-Server
X-Rocket-Nginx-Serving-Static
X-Section
X-Say-TTL
X-SayCDN-TTL
X-Sql-Count
X-Sql-Duration-Ms
X-Access
Cross-Origin-Window-Policy
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
X-IPS-LoggedIn
X-Adobe-Source
Azure-RegionName
Azure-InstanceId
CF-IPCountry
Azure-Version
Azure-SlotName
Azure-SiteName
ServerID
Cache-Name
X-BYPASS-REASON
X-AWS-Id
X-Ms-Request-Id
X-Debug
X-Cache-Host
X-Varnish-Beresp-Grace
X-Via-Fastly
X-Reqid
X-Sucuri-Cache
X-Skip-Cache
X-Soup
X-UA-Device-Type
X-Sucuri-ID
X-VWS-Id
X-ProxyCache-Status
X-GeoCode
X-Forwarded-Host
X-Edge-Location
X-Content-Age
X-GeoCountry
X-LJ-Flow-ID
X-ProxyCache-Key
X-PHP-Host
X-PHP-Backend
X-Ms-Version
X-Cluster
X-Labrador-Cache-Channel
Node
X-Zen-Fury
X-Unique-Id
TWC-Privacy
Webcakes-App-Name
X-Site-Version
X-Urbn-Context-Path
X-Urbn-Site-Id
TWC-GeoIP-LatLong
TWC-Locale-Group
X-SaId
X-Routing-Service
X-JoinUs
X-Extlb
X-LAGOON
X-No-Session
Webcakes-App-Version
X-Proxied
TWC-GeoIP-Country
TWC-Device-Class
Web-Mar-Node
S-Rt
X-R9-Blue-Green-Version
X-Amzn-Remapped-Content-Length
X-Proto
X-IPLB-Instance
Onion-Location
X-Server-W
TWC-Connection-Speed
X-Detected-As
Property-Id
X-Origin-Hint
X-Zipkin-Id
X-Xfnlog-Site
X-IPLB-Request-ID
Webcakes-Region
X-Cluster-Node
X-Locale
Locale
WP-Super-Cache
Mn-Server-Ip
Mime-Version
Selected-Fe
X-Timing-Wait
X-Handled-By
X-LSADC-Cache
X-Proxy-Build
X-Ua
X-SRV
DB-Nickname
Fastcgi-Useragent
Cache-Hits
X-Hl-Ver
X-Request-Time
X-FB-TRIP-ID
Xserver
X-Redis-Cache
Liferay-Portal
X-Cache-Debug
X-TIME
X-Tumblr-Pixel-3
ServedBy
X-Optimistic-Header
X-NWS-UUID-VERIFY
X-XRDS-LOCATION
Upgrade-Insecure-Requests
X-TNCMS
X-Loop
Source
X-Generated-By
X-GEO
Countrycode
X-Mg-Request-UUID
X-Origin-Date
X-Air-Hostname
X-Varnish-Hits
X-Air-Source
X-Air-Trace-Id
X-Tid
CF-Cached-On
X-Tec-Api-Version
X-Storage
X-Tec-Api-Root
X-Times
X-Tec-Api-Origin
X-Uri
X-Server-ID
X-CACHE-AGE
X-Varnish-Beresp-Ttl
X-Director
X-Akamai-Transformed
Xet-Cookie
X-Cdn
X-COUNTRY
X-Tx-Id
X-Pass-Why
X-TA-CDN-Provider
X-Trace-ID
Frame-Options
X-Origin-TTL
X-Newrelic-Synthetics
X-Origin-CC
X-ARC
X-DC
X-B3-Spanid
X-Service
X-FireWall-Port
X-ECache
X-Esi
X-AIR-PT
X-App-Version
X-Sorting-Hat-ShopId
Environment
X-Storefront-Renderer-Rendered
X-Varnish-Cache-Hits
X-Alternate-Cache-Key
X-Varnish-Hostname
X-Sorting-Hat-PodId
X-Datadog-Sampling-Priority
X-Datadog-Sampled
X-Datadog-Parent-Id
SID
X-Datadog-Trace-Id
X-ShardId
X-Shopify-Stage
X-ShopId
Server-Info
X-Presslabs-Stats
Sslversion
Candidate-Md5Url
DCR-Processing-Time-Ms
Edge-Cache
Gannett-Cam-Experience-Id
DCR-Decision-By
BehaviorPad-Version
X-Request-Host
A
Lang
MD5-Digest
Redirect-Candidate
Release
Rendered-Blocks
Origin
Odigeo-Trace-Id
Meta-Geo-Continent
Ngx.Var.Host
Req-Svc-Chain
X-Destination
X-Platform-Cluster
X-Platform-Processor
X-Platform-Router
X-Processor
X-Origin-Time
X-Nyt-Route
X-Loc
X-Mid
X-Mobile-URL
X-Rojux
X-S
X-Vdms-Path
X-Vdms-Version
X-VG-TLSProxy
Xc-Version
X-TIM-N
X-SRCache-Key
X-S-Cookie
X-S-Maxage
X-ScT
X-Gdpr
X-External-Request-Id
X-A-Dcw
X-A-Dgt
X-A-Wwc
X-Aed
X-A-Dam
X-A-Ccd
T-Server
WWW-Authenticate
X-A
X-Application
X-B-Cookie
X-Developer
X-Ec-Fail
X-Ec-GeoHdr
X-Epic-Correlation-Id
X-D
X-Cache-NE
X-BBC-Edge-Cache-Status
X-BCube-Filmed-By
X-Cache-Info
Surrogated-Key
X-Bc-Bl
X-Endurance-Cache-Level
X-ServerID
X-WA-Info
X-NodeID
X-WADP-Cache
X-Old-Content-Length
X-VServer
X-Akamai-Device-Characteristics
Magicmarker
Cache-Tv-Group
X-WP-CF-Super-Cache-Active
Fastly-GeoIP-CountryCode
Decoy-Debug-Key
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
Thinkindot-Control
Decoy-Debug-Status
X-SB
Host-ID
X-Cache-Bucket
TDXMobile
DSUID
X-Origin-Response-Time
X-Varnish-Remaining-TTL
Tube-Got-Eval
X-Sigma
X-Sigma-Backend
Tube-Got-Results
Tube-Get-Contents
State
X-SD-PageType
X-Rocket-Build-Number
X-Served-From
Tube-Return
X-Req
X-Pubstack
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
Country-Code
X-Platform-Server
Vix-Hermes-Req-Id
X-Sn-Servicetimems
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
Memcached
Decoy-Debug-TTL
X-Clara-WADP
X-Frame-Option
X-GeoIP-City
Apple-News-Services-Handled
Apple-News-Services-Host
X-Core-Value
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
X-INCAP-ABP
X-CUA
X-We-Are-Hiring
X-Fmm-Version
X-Ec-Custom-Error
X-Thinkindot-L3
X-Gamma-Serve
X-DefElseHash
X-DefHash
C-Via
X-Core-Mission
X-Human
Cluster
Click-Count-Error
Click-Count-Action-Start
X-Httpd
X-CMSURLCustom
X-Cdn-Origin
Cache-Host
Section-Io-Origin-Time-Seconds
Section-Io-Id
X-Parent-Response-Time
Section-Io-Origin-Status
Section-Origin-Responded
X-Pool
We-Hiring
X-Fastly-Backend
X-Date
X-LB-NoCache
X-Fetched-On
X-DPWN-IS-SECURE
X-Dispatcher-Number
X-CSRF-Token
X-Cache-FS-Status
X-Request-Start
User-Cache-Control
X-Planisys-CDN-Rules
X-GeoIP-Region-Code
X-Gzip
X-Origin
X-GeoIP-Country-Code
X-App
X-Block-Status
X-Node-Id
X-Minions-Version
X-Bip
X-Cache-Id
X-GeoIP
X-Accel-Buffering
X-Buckets
X-Planisys-CDN-TTL
X-Accel-Expires-Debug
X-Ad-Defer-Variation
X-Hash
X-Hnp-Log
X-Planisys-CDN-Cache
X-Gen-Mode
X-Up
X-Scale
X-Location
X-JWT-State
Fastly-Backend-Name
X-Is-Gdpr
X-Wix-Viewer-Type
Is-Eu
X-Vmg-Version
Mail-Subject
X-Restarts
L
Kp-EeAlive
Server-Host
X-HS-Content-Campaign-Id
CDCHOST
X-Developers
X-Cdn-Srv
Cache-Provider
Cache-Key
X-Geo-Header
X-Auto-Login
Cmstype
Cmsid
X-Has-Esi
CloudFront-Viewer-Country
Adler-Geo
X-Test
X-Thanos
Producers
X-Level-Front-Cache
X-Generated-On
X-Slack-Backend
Server-Ext
Svr
Ssr
Sever-Int
Server-Hostname
Platform
X-Esi-Check
X-Variation
X-Var-Ttl
Origin-EX
Pics-Label
X-Varnish-Beresp-Status
NM-Fastcgi-Cache
Origin-CC
X-Worker
X-RM-Cache-TTL
Cdn
X-FC-Vary-Parameters
X-Forwarded-Site
X-Conf
X-Nananana
AKAMAI
X-Mvc-Supplant-Cachable
X-V-Cache
X-Platform
X-VarnishDD-TTL
X-Qloud-Router
X-Refresh
X-Server-IP
X-Slack-Shared-Secret-Outcome
X-Region-Sid
X-Varnishpool
X-Op-Id-All
Web-Mar-Region
X-Irp-Debug
X-Cache-Backend
Gh-Request-Id
CacheControlHeader
X-Nginx-Cache-Key
X-NCache
X-HN
X-Owner
X-Azure-Ref-OriginShield
X-Cache-Tags
X-CacheTTL
Fastly-SSL
Wxu-Next-Commit
Wxu-Next-Region
Datacenter
Wxu-Next-Hostname
X-Ckpd-Fst-Backend
Machine
X-Aicache-OS
X-Device-Os
PFcat
X-Dispatcher-Server
HostName
HA-Ipaddr
On-Server
X-Cache-Remote
Ha-Gx-Prefs
X-Eu-Site
X-Via-Poph
X-Men
X-Tb-Optimization-Total-Bytes-Saved
Canary
X-Csrf-Jwt
X-Via-Popv
X-Via-Popn
X-Cached-By
X-Org
NGX
X-CGP
X-Varnish-Ttl
L5d-Success-Class
X-Webkit-CSP-Report-Only
Cdncip
Cdnsip
X-Mvc-Supplant-OutputCached
X-AK-Request-ID
GeoIP-Latitude
X-VC
X-Servedbyhost
Env
X-HA-Backend
X-Cache-Date
Server-ID
X-Gateway-Request-Id
X-Gateway-Skip-Cache
X-Gateway-Cache-Key
X-RCS-CacheZone
X-LB-ID
X-Gateway-Cache-Status
X-API-Version
X-Microcachable
X-ZONE
X-Fpc
X-Wa
Cache
X-Mly-Id
X-APP-VERSION
X-Zone
Memory
X-Vgn-Hpd-Ssi
Time
X-Vgn-Hpd-Variations-Key
X-Vgn-Hpd-Cached
X-Generated-In
X-DataCenter
X-Webkit-CSP
Request-ID
OT-Force-Account-Verify
X-Micro-Cache
X-Nc
Load-Balancing
X-Via-NSCOPI
Ngx-Var-Key
X-Fastly-Cache
Eomportal-Instance
X-HS-Status
X-ND-Cache
X-Instance-Name
X-Origin-Expires
X-Correlation-ID
X-Check-Cacheable
X-Request-URI
X-Client-Ip
X-SIPLIST1
X-Vc
X-Response-By
IsBot
X-Release
X-Nf-Request-Id
Srv
X-Via-JSL
X-CCDN-Origin-Time
X-VCL-Version
Srvid
X-From
Expect-Staple
Locid
X-CCDN-CacheTTL
X-FL-EDGE
X-FL-QIT-DEBUG
X-Hcs-Proxy-Type
X-Info
X-Cache-NGX
NtCoent-Length
True-Client-Ip
X-Via-CDN
Hostname
X-NewRelic-App-Data
X-Srv
X-Cache-Enabled
AMP-Access-Control-Allow-Source-Origin
X-CS
Edge-Copy-Time
X-Via-Edge
X-Via-SSL
X-MCACHE
X-Edge-Pop
X-CSRF-TOKEN
X-Api-Version
X-Provided-By
GeoIp-Country-Code
X-Proxy-CacheRZ
XkeyRZ
Path
Location
X-NGINX-Cache
X-Lambda-Id
X-Debug-Cache-Store
X-Cache-Expires
X-Amz-Meta-Cb-Modifiedtime
Uri
X-Debug-Cache-Fetch
GeoIP-Country-Code
X-Dc
X-EC-Lua
X-Oss-Storage-Class
X-Edge-POP
X-Oss-Request-Id
X-Vcl-Version
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
X-Oss-Server-Time
Resin-Trace
True-Client-IP
Sid
X-Cs
VNS-Age
Servername
CPC-Cache
X-Render-Time
CPC-Age
X-Fastly-Country-Code
X-Vtex-Remote-Cache
Cross-Origin-Opener-Policy-Report-Only
VNS-Cache
X-B3-SpanId
X-NODE
Traceparent
X-Moov-T
X-Air-Pt
X-Moov-Xdn-Version
X-VCT
X-Scheme
X-TH-Server
Fastly-Drupal-Html
X-Viewer-Country
X-CLOUD-TRACE-CONTEXT
CDN
LB
X-RateLimit-Reset
X-ApacheServer
X-Cdn-Request-ID
X-ATG-Version
X-PERF
X-Akamai-Pragma-Client-IP
X-TX-ID
Rip
X-Varnish-Authentication
Esi-Enabled
X-Cache-ASPX
X-Contensis-Viewer-Groups
X-MSEdge-Features
X-MSEdge-Flight
X-Pod-Name
FSS-Cache
X-NAPM-TraceId
Powered-By
Timeexpire
X-Varnish-Beresp-TTL
X-Datacenter
X-Datadome
X-Cdn-Cache-Status
X-FPC
M-TraceId
CountryCode
X-Accel-Version
YJS-ID
X-CF-Lambda-Version
X-CF-Lambda-Fn
X-SERVER-NAME
X-PAYTM-SRV-ID
X-RateLimit-Remaining-Second
X-Clientip
X-WA
True-Client-Country-4JS
X-RateLimit-Limit-Second
V-Age
X-Service-Response-Time
X-Upstream-Ct
X-Github-Request-Id
X-Upstream-Ht
Tracecode
Sm-Log-Id
X-Cache-Type
XServer
X-Geo
X-VG-WebCache
X-Udemy-Cache-App-Namespace
X-Srcache-Store-Status
X-CACHE-KEY
XM
Proxy-Connection
X-Srcache-Fetch-Status
HIT
X-Lb-Id
Server-Id
X-LiteSpeed-Cache-Control
Ohc-File-Size
X-NC
RNT-Time
RNT-Machine
ENV
Ngx
X-TraceId
X-Wikidot-Static-Cache
X-Wikidot-Backend
X-ServedByHost
N-Cache
X-B3-Parentspanid
X-Orig-Expires
X-Ha-Backend
X-Cdn-Forward
X-Rebelmouse-Surrogate-Control
X-Tenant
X-Shop-Environment
X-Forwarded-Path
Epwk-X-Cache
Yjs-Id
Geoip-Latitude
WZWS-RAY
X-Bl-Debug
X-Rebelmouse-Cache-Control
X-CDN-Cache-Status
X-Hyper-Cache
X-MP-GENERATED-AT
Req-ID
X-B3-ParentSpanId
Content-Style-Type
Content-Script-Type
Pramga
Inserted-Into-Cache-At
X-B3-Trace-ID
Expiry
X-Serial
X-Swift-Error
Ec-Rule-Version
X-Connection-Hash
X-Fastly-Backend-Reqs
X-MiniProfiler-Ids
X-Vgn-Hpd-Reason
X-Via-PopH
X-Via-PopN
X-Via-PopV
User-Agent
X-Lb-Nocache
X-Cdn-Diag
X-Dw-Trace-Id
X-F-Status
X-Lsadc-Cache
X-TT-LOGID
X-Mid-Debug-Cache-Disk
X-Mid-Debug-Cache-Key
X-Request-URL
X-Akamai-ERRuleID
Lb
X-Qnm-Cache
X-M-Reqid
X-M-Log
X-Amz-Meta-Opti
X-LiteSpeed-Tag
X-UP
Warning
X-Webstats-RespID
X-Stale
X-Snapshot-Date
X-IPS-Cached-Response
Cneonction
X-Th-Server
My-App
X-Cache-Ngx
MIME-Version
X-Akamai-ERPolicy
X-Yottaa-OS