Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
Strict-Transport-Security
X-Frame-Options
X-Content-Type-Options
Last-Modified
Link
CF-Cache-Status
Cf-Request-Id
Accept-Ranges
ETag
CF-RAY
Expect-CT
Pragma
X-Powered-By
X-Cache
Via
X-XSS-Protection
Age
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Amz-Cf-Pop
X-Xss-Protection
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-FRAME-OPTIONS
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-Adblock-Key
X-AspNet-Version
X-Permitted-Cross-Domain-Policies
X-Runtime
Alt-Svc
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Check
X-DNS-Prefetch-Control
X-Cache-Status
X-Generator
CF-Ray
X-Cacheable
Timing-Allow-Origin
X-Iinfo
X-Envoy-Upstream-Service-Time
Feature-Policy
Status
X-Content-Security-Policy
X-Drupal-Dynamic-Cache
Content-Encoding
X-AspNetMvc-Version
X-CDN
Access-Control-Expose-Headers
Upgrade
X-XSS-PROTECTION
X-Ua-Compatible
Access-Control-Max-Age
X-Request-ID
X-Dns-Prefetch-Control
X-Via
Server-Timing
X-Cache-Group
X-Robots-Tag
X-UA-Device
Request-Context
Keep-Alive
X-AH-Environment
X-Amz-Request-Id
X-Turbo-Charged-By
X-Backend
P3p
X-Proxy-Cache
X-Amz-Id-2
X-Ws-Request-Id
X-Age
Host-Header
X-Server-Powered-By
X-Hacker
X-Server
X-Akamai-Path-Stats
X-Rq
EagleId
X-Vhost
X-Varnish-Cache
Grace
X-Dispatcher
X-Amz-Version-Id
X-LiteSpeed-Cache
Cf-Edge-Cache
Allow
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Nginx-Cache-Status
X-Device
X-Page-Speed
X-WebKit-CSP
X-Aws-Lambda-Call-Status
X-Host
X-Node
X-OneAgent-JS-Injection
EagleEye-TraceId
X-Pingback
X-Server-Id
X-Cache-Spec
Request-Id
Surrogate-Control
Cf-Railgun
X-Akam-SW-Version
X-Backend-Server
Accept-CH
X-Readtime
X-Cache-Lookup
X-Response-Time
X-HW
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
Accept-CH-Lifetime
Content-Location
X-Content-Security-Policy-Report-Only
X-Application-Context
Rating
X-Trace
Fastly-Restarts
X-Cloud-Trace-Context
X-Country
X-WebKit-CSP-Report-Only
X-Url
X-Clacks-Overhead
Accept-Ch-Lifetime
X-Edge
X-Amz-Server-Side-Encryption
X-Rack-Cache
X-Ruxit-JS-Agent
X-MS-InvokeApp
X-B3-TraceId
Edge-Control
X-PC
X-TtlSet
X-Vname
Accept-Ch
X-Content-Type
X-Vcap-Request-Id
X-ESI
X-Nginx-Upstream-Cache-Status
X-Mod-Pagespeed
X-Varnish-TTL
Xkey
X-Cdn-Fetch
X-Kinja-Server
X-Kinja-Revision
X-Exp-Id
X-Kinja-Build
X-Kinja
X-GoogleNews-Bot
X-Exp-Variant
X-Use-Magma
X-VARITI-CCR
X-Mcache
X-Amz-Rid
X-CST
X-GitHub-Request-Id
Verso
X-D2id
Cache-Tag
RTSS
X-Powered-By-Plesk
X-FastCGI-Cache
X-ECACHE
X-Oneagent-Js-Injection
X-Cached
Service-Worker-Allowed
X-Version
X-Upstream
X-Client-IP
X-Abt-Application-Version
X-Navigation-Version
X-Dw-Request-Base-Id
X-Px
X-Ruxit-Js-Agent
X-Cnection
X-Ac
Public-Key-Pins
X-Ser
Arr-Disable-Session-Affinity
X-SharePointHealthScore
SPRequestGuid
X-Instrumentation
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Element-Page-Cache
X-Server-Name
Display
Pagespeed
X-Sol
X-Middleton-Display
SPRequestDuration
SPIisLatency
X-Country-Code
X-Cache-TTL
X-NWS-LOG-UUID
X-Ttl
X-NF-Request-ID
X-RateLimit-Remaining
X-Midtier
X-Cache-Key
Permissions-Policy
X-Goog-Hash
Response
X-Edge-Location-Klb
X-Middleton-Response
X-Kinsta-Cache
X-Forwarded-For
Content-MD5
Access-Control-Request-Method
X-DataDome
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Shield-Request-Id
Front-End-Https
X-MSEdge-Ref
X-Powered-CMS
X-Correlation-Id
X-T
AR-ATIME
AR-SID
X-Jurisdiction
AR-PoweredBy
AR-Request-ID
Edge-Cache-Tag
AR-CACHE
TP-L2-Cache
X-HP-Trace-Id
X-HP-Webp
TP-Cache
X-Accel-Expires
X-Recruiting
Nginx-Cache
X-RateLimit-Limit
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
X-Daa-Tunnel
TCN
MicrosoftSharePointTeamServices
X-Grace
Mrf-Cache-Status
X-B3-TraceId-Primal
MRF-Tech
X-Mg-S
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Id
X-TEC-API-VERSION
X-Hits
X-Content-Digest
X-Request-Received
X-Request-Processing-Time
Server-Node
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Combine-CSS
X-HS-Cache-Config
Filters
Server-Name
S
X-Frontend
X-LLID
X-TTL
X-Distributor
X-Amzn-Trace-Id
Cache-Status
X-Protected-By
X-Geo-Country
MS-Author-Via
Fastcgi-Cache
X-Fastly-Request-Id
X-LB-Cache
X-Language
X-Microsite
X-Request-Handler-Origin-Region
X-PressLabs-Stats
Cross-Origin-Opener-Policy
X-Seen-By
X-Forwarded-Proto
X-Origin-Server
X-Ezoic-Cdn
X-F-Cache
Host
Filterid
X-Page-Id
X-FB-Debug
X-B3-Sampled
Charset
X-XRDS-Location
X-Git-Hash
X-Ua-Browser
X-Ab
Payment
X-Amz-Meta-S3cmd-Attrs
X-Litespeed-Cache
Count-Hit
X-ASPNET-VERSION
Realpath
X-Fastcgi-Cache
X-Ratelimit-Reset
X-Cache-Age
X-VCache
X-Cluster-Name
Accept-Charset
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Browser-Type
Surrogate-Key
X-Origin-Cache
Cf-Apo-Via
Alternate-Protocol
Cache-Tags
X-DynaTrace
X-NGENIX-Cache
X-Rid
X-Webkit-Csp
Cleartype
X-Template
Retry-After
X-Az
X-AppVersion
X-Activity-Id
Access-Control-Allow-Method
X-Www-Served-By
X-Wix-Request-Id
X-Route-Name
X-Request-Guid
X-Aspnet-Duration-Ms
X-Node-Name
X-Flags
X-Providence-Cookie
X-Is-Crawler
X-Varnish-Grace
X-App-Environment
X-TT
X-Tb
X-Varnish-Backend
X-B-Cache
X-Signature
X-DIS-Request-ID
X-Content
X-B
X-Debug
X-Upgrade-Enabled
X-Type
X-Amz-Replication-Status
ServerID
X-Drupal-Cache-Tags
X-Proxy
DC
Paypal-Debug-Id
X-Logged-In
X-Tt-Trace-Tag
Frame-Options
X-Tt-Trace-Host
X-Server-ID
X-Envoy-Decorator-Operation
X-Hostname
X-Source
X-Mobile
X-Content-Options
X-Revision
X-Load-Cache
X-Goog-Generation
Pinterest-Generated-By
Pinterest-Version
X-Pinterest-Rid
X-Goog-Storage-Class
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-Fastly-Request-ID
X-Cache-Control
X-Contextid
Amp-Access-Control-Allow-Source-Origin
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
Country
X-N
X-Magnolia-Registration
Referer-Policy
X-User-Agent
Viewport
X-Whom
X-Cache-Rule
NGB
X-EdgeConnect-Cache-Status
X-Response-Served-From
X-Ratelimit-Remaining
X-Original-Request-Id
Refresh
Node
X-Varnish-Age
X-Restarts
X-Framework
X-Debug-IsConnected
X-Cacheable-TTL
Access-Control-Request-Headers
X-Cache-TTL-Remaining
X-Debug-IsPreview
X-L-Path
X-Environment-Context
X-Page-View
Content-Disposition
X-Yottaa-Metrics
X-NYM-Debug-Backend
X-Is-Bot
X-Akamai-Request-ID2
X-Mid
VIX-Pulpo-Upstream-Status
X-Instance
X-Jobs
Url
X-Cache-Grace
X-Cache-Time
X-Rendered-As
X-Adobe-Loc
X-Servername
X-Yottaa-Optimizations
X-Adobe-Content
X-G
X-Real-IP
Uber-Trace-Id
VIX-Pulpo-Node
X-Varnish-Server
X-Drupal-Cache-Contexts
X-Unique-Id
X-Mg-Request-UUID
Akamai-GRN
X-Status
X-Content-Powered-By
X-Webkit-CSP
Countrycode
Version
X-App-Server
X-ProcessESI
X-RemovedCookies
X-COUNTRY
X-Debug-Info
X-Http-Reason
X-Oracle-Dms-Rid
X-XRDS-LOCATION
X-Oracle-Dms-Ecid
Srv
X-CDN-Forward
Protected
X-IPLB-Request-ID
X-IPLB-Instance
X-APP-VERSION
X-Time
Accept-Language
X-Hosted-By
X-Tt-Logid
X-Ratelimit-Limit
X-Cache-Expired-At
X-Nginx-Cache-Key
X-Via-JSL
Liferay-Portal
Healthy
X-Device-Type
Fastcgi-Useragent
X-Cache-Hit
X-Tumblr-Pixel
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-FW-Static
X-Azure-Ref
X-FW-Dynamic
X-FW-Hash
X-FW-Serve
X-Tumblr-User
X-FW-Server
X-FW-Type
Section-Io-Cache
Backend
X-Cache-NGX
X-Backend-Name
X-Trace-Id
X-RTag
X-Proxy-Cache-Status
MS-CV
Ms-Operation-Id
X-Cache-Operation
Content-Secure-Policy
X-Mobile-URL
Server-Info
X-UUID
Load-Balancing
X-RN-RSRV
X-UPSTREAM-Address
Meta-Geo
X-Storage
CF-IPCountry
X-Mode
X-Datadome
X-Sql-Duration-Ms
X-Content-Age
X-Sql-Count
X-Handled-By
X-HTML-Minification-Powered-By
Azure-RegionName
Azure-SiteName
Azure-SlotName
Azure-Version
CDN-PullZone
CDN-Uid
Locale
TWC-GeoIP-Country
TWC-Device-Class
CDN-RequestId
CDN-RequestCountryCode
CDN-CachedAt
CDN-EdgeStorageId
Property-Id
TWC-Connection-Speed
CDN-Cache
X-VWS-Id
X-PHP-Host
X-Locale
X-LJ-Flow-ID
X-Labrador-Cache-Channel
X-Cache-Host
X-No-Session
X-Origin-Date
X-Cache-Enabled
X-Shopify-Stage
X-Site-Version
X-Varnishpool
X-Varnish-Hostname
X-Sorting-Hat-PodId
X-Forwarded-Host
X-Edge-Location
X-Cms-Context
X-Storefront-Renderer-Rendered
X-Urbn-Context-Path
X-Varnish-Cache-Hits
X-Uri
X-Urbn-Site-Id
X-Skip-Cache
X-Origin-Hint
X-AWS-Id
TWC-Privacy
X-VC-Cache
Web-Mar-Node
Webcakes-App-Name
Azure-InstanceId
X-Say-TTL
X-Redis-Cache
X-Region
TWC-Locale-Group
X-Say-Cacheable
Webcakes-App-Version
Webcakes-Region
X-ShardId
X-ShopId
X-PHP-Backend
X-Alternate-Cache-Key
X-Server-W
X-SayCDN-TTL
WP-Super-Cache
X-Adobe-Source
X-Akamai-Edgescape
X-Sorting-Hat-ShopId
TWC-GeoIP-LatLong
X-Zen-Fury
GEO-INFO
X-URL
X-Proxied
X-Web-Node
X-BYPASS-REASON
X-Proxy-Build
Selected-Fe
S-Rt
X-Section
Mn-Server-Ip
Onion-Location
X-Xfnlog-Site
X-ProxyCache-Key
X-Via-Fastly
X-Timing-Wait
X-ServerID
X-Access
X-SaId
X-Routing-Service
X-UA-Device-Type
X-ProxyCache-Status
X-Request-Time
X-Generated-By
X-Proto
X-Zipkin-Id
X-GeoCountry
X-Hl-Ver
X-Detected-As
X-GeoCode
X-Extlb
Apigw-Requestid
X-Format
X-FB-TRIP-ID
X-JoinUs
X-Debug-Cache
X-Cache-Type
X-Cache-Server
X-PCL
Eomportal-Instance
X-OCL
DB-Nickname
X-Tid
X-Correlation-ID
X-Generation-Time
X-Varnish-Beresp-Grace
X-Cache-Status-Check
X-SRV
X-Cache-Action
X-Nginx-Cache
ServedBy
X-LSADC-Cache
X-ECache
X-Rule
X-Ms-Request-Id
Cache-Name
X-Ms-Version
X-R9-Blue-Green-Version
Cross-Origin-Resource-Policy
Cache
X-Human
X-FireWall-Port
X-Ua
X-Cache-Tags
X-DynaTrace-JS-Agent
SD-X-WS
X-Dc
X-App-Version
Xet-Cookie
X-Cached-By
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
Xserver
X-Amzn-RequestId
Source
X-Amz-Apigw-Id
LB
Cross-Origin-Window-Policy
X-RCS-CacheZone
X-Aspnetmvc-Version
X-GEO
X-TNCMS
X-Via-NSCOPI
X-Varnish-Hits
X-Loop
X-Cdn
WPO-Cache-Status
WPO-Cache-Message
Origin
X-GG-Cache-Date
X-MP-GENERATED-AT
X-Origin-TTL
X-TA-CDN-Provider
X-IPS-LoggedIn
X-Pubstack
X-Origin-CC
X-Reqid
X-Soup
X-NewRelic-App-Data
X-AOL-HN
X-Amzn-Remapped-Content-Length
X-B3-SpanId
Cache-Hits
X-FW-Version
X-Tumblr-Pixel-2
From-Origin
Webserver
Rip
X-Service
X-Platform-Server
X-Newrelic-Synthetics
X-Vgn-Hpd-Reason
X-Cluster-Node
X-Api-Version
X-Request-Host
Upgrade-Insecure-Requests
X-BCube-Filmed-By
X-Served-From
DCR-Processing-Time-Ms
X-Owner
X-Orig-Expires
X-NAPM-TraceId
X-Vdms-Path
Expiry
Rendered-Blocks
X-ARC
Xc-Version
X-Bc-Bl
DCR-Decision-By
Environment
X-Vdms-Version
Cdnsip
X-Ec-GeoHdr
X-Ec-Fail
A
X-External-Request-Id
X-Session-Fingerprint
X-Shop-Environment
X-Forwarded-Path
X-Developer
X-Destination
X-VG-WebCache
X-Connection-Hash
Cdncip
X-D
X-Accel-Buffering
BehaviorPad-Version
X-Cache-NE
X-B-Cookie
Ngx.Var.Host
Odigeo-Trace-Id
T-Server
X-Rewrite-Enabled
Meta-Geo-Continent
X-A
Lang
X-PBS-Appsvrname
X-Tenant
X-Rojux
X-SRCache-Key
X-S
X-S-Cookie
Redirect-Candidate
Sslversion
X-Origin-Response-Time
Surrogated-Key
X-A-Ccd
MD5-Digest
X-A-Dgt
X-TIM-N
X-A-Dcw
Host-ID
X-User
X-A-Wwc
X-Application
X-AK-Request-ID
X-Aed
X-A-Dam
X-Processor
X-ScT
OT-Force-Account-Verify
X-Provided-By
X-Varnish-Beresp-Ttl
HostName
X-CSRF-Token
X-Cluster
X-TIME
Fastly-SSL
X-Wix-Viewer-Type
Decoy-Debug-Status
X-Aicache-OS
Machine
Decoy-Debug-Key
Mobile-Detection-Method
X-Bip
X-Dispatcher-Number
Candidate-Md5Url
Decoy-Debug-TTL
X-Forwarded-Site
X-Thanos
X-VC
X-Irp-Debug
X-Qloud-Router
X-Pool
X-Ad-Defer-Variation
Wxu-Next-Region
X-Variation
X-V-Cache
X-RateLimit-Limit-Second
X-Planisys-CDN-TTL
X-Policy
X-Scale
X-Proxy-Cache-Info
X-Planisys-CDN-Rules
X-Origin-Expires
X-Varnish-Remaining-TTL
X-Origin
X-Branch-Name
X-Cache-Bucket
X-Varnish-CookieINHashed-On
X-Varnish-CookieHashed-On
X-Planisys-CDN-Cache
X-Parent-Response-Time
X-Auto-Login
X-BBC-Edge-Cache-Status
Wxu-Next-Hostname
X-RateLimit-Remaining-Second
Traceparent
X-Rocket-Nginx-Serving-Static
Tube-Get-Contents
Tube-Got-Eval
Tube-Got-Results
X-SplitTest
State
Req-Svc-Chain
X-SVT-ORM-RULES
Servername
X-SVT-ORM-VERSION
Tube-Return
V-Age
X-Rebelmouse-Surrogate-Control
We-Hiring
Web-Mar-Region
X-Rebelmouse-Cache-Control
Wxu-Next-Commit
X-Region-Sid
X-Request-URI
X-SB
Vix-Hermes-Req-Id
X-Rocket-Build-Number
VNS-Age
X-Optimistic-Header
X-NodeID
X-Epic-Correlation-Id
X-GeoIP
X-Esi-Check
X-Eu-Site
X-Generated-On
X-GeoIP-City
X-Ec-Custom-Error
X-Device-Os
X-Hash
X-Gzip
X-DPWN-IS-SECURE
X-Sigma
X-Fastly-Cache
X-Gamma-Serve
X-Gateway-Request-Id
X-Slack-Backend
X-Gateway-Cache-Status
X-Sn-Servicetimems
X-S-Maxage
X-Gateway-Skip-Cache
X-Sigma-Backend
X-Fetched-On
X-Fmm-Version
X-SIPLIST1
X-INCAP-ABP
X-WADP-Cache
X-Cdn-Origin
X-CacheTTL
X-CGP
X-Ckpd-Fst-Backend
X-Clara-WADP
X-Minions-Version
X-Cache-Info
X-VG-TLSProxy
X-Mvc-Supplant-OutputCached
X-Mvc-Supplant-Cachable
X-Cache-Id
X-Clientip
X-Loc
X-WA-Info
X-Datadog-Sampling-Priority
X-Datadog-Trace-Id
X-DefElseHash
X-DefHash
X-Datadog-Parent-Id
X-VServer
X-Level-Front-Cache
X-Core-Mission
X-Viewer-Country
X-Csrf-Jwt
X-Gateway-Cache-Key
VNS-Cache
Gh-Request-Id
Ha-Gx-Prefs
Fastly-SWR
Fastly-SIE
DSUID
Fastly-GeoIP-CountryCode
HA-Ipaddr
Is-Eu
L5d-Success-Class
Mail-Subject
L
Kp-EeAlive
IsBot
Datacenter
CPC-Cache
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
Apple-News-Services-Host
Apple-News-Services-Handled
X-NWS-UUID-VERIFY
Adler-Geo
Cache-Host
Click-Count-Action-Start
Cmstype
CPC-Age
Cmsid
Cluster
Click-Count-Error
Memcached
Country-Code
Release
Origin-CC
Platform
Producers
Origin-EX
NM-Fastcgi-Cache
NGX
X-Cache-Remote
X-Xrds-Location
X-Tx-Id
Mime-Version
Svr
X-Geo-Header
X-Cdn-Srv
X-Gdpr
Thinkindot-CacheControl
TDXMobile
X-NCache
Server-Ext
X-Nyt-Route
Server-Host
Server-Hostname
X-Origin-Time
Sever-Int
Cache-Tv-Group
X-Core-Value
X-Developers
CDCHOST
Thinkindot-CacheControl-Type
CloudFront-Viewer-Country
X-Pod-Name
X-Worker
X-Scheme
Thinkindot-Control
X-Has-Esi
X-Hnp-Log
User-Cache-Control
X-HS-Content-Campaign-Id
X-Thinkindot-L3
Fastly-Backend-Name
X-Block-Status
X-JWT-State
X-Gen-Mode
X-Is-Gdpr
Fastcgi-Cache-TTL
AKAMAI
X-Varnish-Beresp-Status
X-LB-NoCache
X-Presslabs-Stats
X-Varnish-Ttl
X-Udemy-Cache-App-Namespace
WebServer
X-ZONE
SID
Canary
X-Ig-Push-State
Ec-Rule-Version
X-Cache-Date
Pics-Label
Ssr
X-Microcachable
X-Tb-Optimization-Total-Bytes-Saved
X-Sucuri-Cache
X-Trace-ID
X-CMSURLCustom
X-Yandex-Sdch-Disable
X-Conf
Sid
X-WP-CF-Super-Cache-Active
X-Via-Popn
X-Generated-In
Time
X-Via-Popv
X-ND-Cache
X-Via-Poph
Memory
X-ATG-Version
Fastly-Drupal-Html
X-Azure-Ref-OriginShield
X-FC-Vary-Parameters
X-Var-Ttl
X-Cache-Debug
X-Sucuri-ID
X-Fastly-Backend
X-Tec-Api-Version
X-B3-Traceid
AMP-Access-Control-Allow-Source-Origin
X-Tec-Api-Origin
X-Tec-Api-Root
X-Refresh
X-Newrelic-App-Data
Server-ID
X-Dmc
X-Servedbyhost
X-TRACE-ID
X-Be
X-Akamai-Transformed
Env
X-Edge-Pop
X-CS
X-RateLimit-Reset
X-Fpc
X-MSEdge-Flight
X-Air-Hostname
X-Air-Trace-Id
X-Air-Source
X-MSEdge-Features
X-Release
X-NC
Fastly-Drupal-HTML
X-Buckets
X-Cs
X-DC
X-Esi
X-PX
X-MCACHE
X-Zone
X-Endurance-Cache-Level
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-ID
Magicmarker
X-EC-Lua
CDN
X-CACHE-AGE
X-Up
GeoIp-Country-Code
X-Tumblr-Pixel-3
X-Pass-Why
X-TX-ID
X-Hyper-Cache
X-Wa
X-Dispatch
True-Client-IP
My-App
X-VCL-Version
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-Srv
X-NGINX-Cache
X-Webkit-CSP-Report-Only
X-Lambda-Id
X-Micro-Cache
X-M-Reqid
Pramga
X-M-Log
X-App
X-Vc
X-CACHE-KEY
X-CSRF-TOKEN
X-Alfa-Service
Hostname
C-Via
X-Qnm-Cache
X-Varnish-Beresp-TTL
N-Cache
X-Req
X-TrackingId
X-Edge-Origin-Shield-Region
X-Edge-Origin-Shield-Bytes
Resin-Trace
X-PAYTM-SRV-ID
Fastcgi-X-Cache-Version
X-Air-Pt
X-Vcl-Version
X-Platform
On-Server
True-Client-Ip
Path
Esi-Enabled
CacheControlHeader
X-TH-Server
X-LB-ID
GeoIP-Country-Code
X-Check-Cacheable
X-HS-Status
Tcn
X-Vercel-Id
X-Vercel-Cache
X-API-Version
True-Client-Country-4JS
X-Vtex-Processado-Em
Tracecode
X-Vtex-Remote-Cache
X-Nf-Request-Id
GeoIP-Latitude
X-AIR-PT
X-B3-Spanid
NtCoent-Length
X-ApacheServer
X-PERF
X-SERVER-NAME
X-Op-Id-All
Proxy-Connection
X-Request-Start
X-Akamai-Pragma-Client-IP
X-SD-PageType
X-Node-Id
X-LAGOON
Cdn
X-CLOUD-TRACE-CONTEXT
Section-Io-Origin-Time-Seconds
Hit
Cache-Key
HIT
Section-Io-Origin-Status
Section-Io-Id
Section-Origin-Responded
X-FPC
X-Webkit-Csp-Report-Only
DT-Hot-News
X-Geo
X-Proxy-CacheRZ
XkeyRZ
X-GeoIP-Country-Code
X-Mly-Id
X-Platform-Processor
X-GeoIP-Region-Code
X-WA
X-Render-Time
DynaTrace
ENV
X-Platform-Cluster
X-Edge-POP
X-Via-CDN
X-Platform-Router
X-Dw-Trace-Id
WWW-Authenticate
X-Datacenter
PFcat
X-VarnishDD-TTL
X-Lb-Id
Server-Id
X-ServedByHost
X-Date
User-Agent
Lb
YJS-ID
X-Accel-Expires-Debug
X-Via-Ucdn
X-Traceid
XM
X-HN
X-Proxy-Upstream
X-Cdn-Forward
X-Via-PopV
X-Via-PopN
X-Proxy-Cache-Hk
Server-Ttl
X-Via-PopH
X-LiteSpeed-Cache-Control
X-RAMCache
SRV
Dnion-Transfer-Encoding
Geoip-Latitude
X-Li-Pop
X-Li-Fabric
MIME-Version
X-TT-LOGID
X-LI-Proto
X-LiteSpeed-Tag
X-CUA
X-LI-UUID
X-FORWARDED-FOR
X-Cache-Ttl
X-CF-Powered-By
Yjs-Id
X-UA
X-Instance-Name
X-Response-By
Vha6-Origin
Location
X-RPM
X-RPS
X-DW
X-DSS
X-DI
X-RSL
Sm-Log-Id
X-DB
PICS-Label
Ohc-File-Size
X-Old-Content-Length
X-Service-Response-Time
Nginx-CQVIP
FSS-Cache
X-Cache-Backend
X-Ftr-Request-Id
X-Fastly-Backend-Reqs
X-Nc
X-Akamai-ERPolicy
XServer
M-TraceId
X-Akamai-ERRuleID
X-Litespeed-Cache-Control
X-Wp-Cf-Super-Cache
X-Wp-Cf-Super-Cache-Cache-Control
X-Akamai-Request-ID
X-IN-APIGATEWAY
Powered-By
X-HostName
X-IN-APIGATEWAYSSL
X-Request-Url
X-Httpd
X-HA-Backend
X-Fastly-Cache-Hits
X-Cdn-Request-ID
X-Cc-Via
X-B3-ParentSpanId
X-Lb-Nocache
Wpo-Cache-Message
Wpo-Cache-Status
CountryCode
X-Cache-Ngx
Warning
X-DataCenter
Locid
X-Mg-Cache
Srvid
X-Location
Ohc-Cache-HIT
X-Sucuri-Id
X-Webstats-RespID
X-From
X-FL-EDGE
X-MiniProfiler-Ids
X-Moov-Xdn-Version
X-Moov-T
Req-ID
X-Snapshot-Date
Fastcgi-Cache-Ttl
X-Serial
WZWS-RAY
Uri
X-Server-IP