Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Accept-Ranges
Expect-CT
Pragma
CF-RAY
X-Powered-By
X-XSS-Protection
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-Xss-Protection
X-UA-Compatible
P3P
X-Served-By
X-Download-Options
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Request-Id
Access-Control-Allow-Credentials
X-Request-ID
CF-Ray
X-Permitted-Cross-Domain-Policies
X-AspNet-Version
Alt-Svc
Content-Security-Policy-Report-Only
X-Runtime
X-DNS-Prefetch-Control
X-Drupal-Cache
X-Check
X-Cache-Status
X-Generator
X-Cacheable
P3p
Timing-Allow-Origin
X-FRAME-OPTIONS
X-Iinfo
X-Envoy-Upstream-Service-Time
X-Content-Security-Policy
X-Drupal-Dynamic-Cache
Feature-Policy
Content-Encoding
Upgrade
Status
Access-Control-Expose-Headers
X-AspNetMvc-Version
X-CDN
Access-Control-Max-Age
X-Ua-Compatible
X-Via
Server-Timing
X-UA-Device
X-Robots-Tag
Request-Context
X-Turbo-Charged-By
X-Cache-Group
X-Amz-Request-Id
EagleId
X-Amz-Id-2
X-Backend
Keep-Alive
X-AH-Environment
X-Ws-Request-Id
X-Proxy-Cache
X-Server
X-Age
X-Hacker
Host-Header
Cf-Edge-Cache
X-Vhost
X-Server-Powered-By
X-Rq
Allow
X-Dispatcher
X-Varnish-Cache
X-Amz-Version-Id
Grace
X-LiteSpeed-Cache
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-OneAgent-JS-Injection
X-WebKit-CSP
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
Accept-CH
X-Device
Cf-Apo-Via
X-Page-Speed
Cf-Railgun
X-Aws-Lambda-Call-Status
X-Server-Id
X-Host
X-Pingback
X-Node
X-Cache-Spec
X-Nginx-Cache-Status
X-Akam-SW-Version
Surrogate-Control
X-Dns-Prefetch-Control
X-Backend-Server
EagleEye-TraceId
Request-Id
X-Readtime
X-Cache-Lookup
X-Ruxit-JS-Agent
X-HW
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Cloud-Trace-Context
X-Content-Security-Policy-Report-Only
Accept-Ch-Lifetime
X-Application-Context
X-Trace
X-Response-Time
X-CST
Permissions-Policy
X-Nginx-Upstream-Cache-Status
X-Mod-Pagespeed
Fastly-Restarts
X-Edge
X-Country
Content-Location
X-WebKit-CSP-Report-Only
Accept-CH-Lifetime
X-Content-Type
X-Mcache
Rating
X-ECACHE
X-Clacks-Overhead
X-MS-InvokeApp
X-Url
X-TtlSet
X-Amz-Server-Side-Encryption
X-Vname
X-PC
X-Midtier
X-VARITI-CCR
RTSS
Cache-Tag
X-Vcap-Request-Id
X-Varnish-TTL
X-Element-Page-Cache
Origin-Trial
Verso
X-Ac
X-B3-TraceId
X-Cdn-Fetch
X-Exp-Id
X-GoogleNews-Bot
X-Exp-Variant
X-Kinja
X-Kinja-Server
X-Use-Magma
X-Kinja-Revision
X-Kinja-Build
X-Server-Name
X-D2id
X-Rack-Cache
X-Cnection
X-Cache-TTL
X-Powered-By-Plesk
Service-Worker-Allowed
Xkey
X-GitHub-Request-Id
X-Abt-Application-Version
X-Fastcgi-Cache
X-Navigation-Version
X-ESI
Edge-Control
X-NWS-LOG-UUID
X-Amz-Rid
X-SharePointHealthScore
SPRequestGuid
X-Cached
X-Client-IP
X-Px
X-Mg-S
X-Instrumentation
X-Erf-Bev-Bev-Is-Generated
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Browser-Type
X-Erf-Bev-Bev
Arr-Disable-Session-Affinity
X-Ttl
X-Correlation-Id
X-Upstream
SPIisLatency
SPRequestDuration
X-Cache-Key
Pagespeed
X-Middleton-Display
Display
X-Litespeed-Cache
X-Sol
Content-MD5
X-Dw-Request-Base-Id
X-SRCache-Store-Status
X-SRCache-Fetch-Status
Access-Control-Request-Method
X-Goog-Hash
X-XRDS-Location
Edge-Cache-Tag
X-Daa-Tunnel
Front-End-Https
X-NF-Request-ID
X-Country-Code
Public-Key-Pins
X-Version
X-RateLimit-Remaining
X-Forwarded-For
AR-SID
AR-Request-ID
AR-ATIME
AR-CACHE
AR-PoweredBy
X-Powered-CMS
X-Id
TCN
X-MSEdge-Ref
X-Recruiting
X-T
X-Content-Digest
X-HP-Webp
X-Accel-Expires
X-Jurisdiction
X-HP-Trace-Id
X-Middleton-Response
Response
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
X-Ser
X-Shield-Request-Id
TP-Cache
TP-L2-Cache
Nginx-Cache
X-Fastly-Request-ID
X-Hits
S
X-Request-Processing-Time
X-Request-Received
X-Amzn-Trace-Id
X-Edge-Location-Klb
X-Kinsta-Cache
Cache-Status
X-HS-Cache-Config
X-HS-Combine-CSS
X-Distributor
X-HS-Hub-Id
Server-Node
X-HS-Content-Id
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-TTL
X-TEC-API-VERSION
Cache-Tags
Alternate-Protocol
X-Grace
Server-Name
Fastcgi-Cache
MicrosoftSharePointTeamServices
X-Protected-By
X-Ratelimit-Limit
X-DataDome
X-DIS-Request-ID
X-Geo-Country
X-Ezoic-Cdn
X-Ruxit-Js-Agent
X-LB-Cache
Accept-Ch
X-Origin-Server
X-Microsite
X-Request-Handler-Origin-Region
X-Frontend
X-Ua-Browser
X-Debug-Info
X-Rid
X-Ratelimit-Reset
Cross-Origin-Opener-Policy
Filterid
X-NGENIX-Cache
X-Www-Served-By
X-Git-Hash
X-Forwarded-Proto
Payment
Healthy
X-Varnish-Backend
Cleartype
X-FB-Debug
X-Page-Id
X-Logged-In
X-Ratelimit-Remaining
X-B3-Sampled
X-Load-Cache
Charset
Content-Disposition
X-VCache
X-Webkit-Csp
X-ASPNET-VERSION
X-PressLabs-Stats
X-Origin-Cache
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-LLID
X-Cluster-Name
MS-Author-Via
DC
X-Oracle-Dms-Ecid
X-Oracle-Dms-Rid
X-Hostname
X-Goog-Metageneration
X-GUploader-UploadID
Accept-Charset
X-Upgrade-Enabled
Access-Control-Allow-Method
Retry-After
Cross-Origin-Resource-Policy
X-Proxy
X-F-Cache
X-Contextid
X-AppVersion
X-Activity-Id
X-Az
X-Amz-Replication-Status
X-Request-Guid
X-Providence-Cookie
X-Revision
X-Aspnet-Duration-Ms
X-Flags
X-Is-Crawler
X-Hosted-By
X-Route-Name
X-Seen-By
X-Signature
X-B-Cache
X-Type
X-Wix-Request-Id
X-B
X-TT
X-Varnish-Server
X-Azure-Ref
Referer-Policy
Amp-Access-Control-Allow-Source-Origin
Paypal-Debug-Id
X-Amz-Meta-S3cmd-Attrs
X-App-Environment
Viewport
X-Whom
Surrogate-Key
X-DynaTrace
X-Source
X-RateLimit-Limit
Count-Hit
X-Aspnetmvc-Version
X-Cdn
X-Tt-Trace-Host
Realpath
X-Tt-Trace-Tag
X-Fb-Rlafr
X-Akamai-Edgescape
X-Mobile
X-App-Server
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Goog-Generation
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-B3-Traceid
X-FastCGI-Cache
Host
X-Cache-Control
X-EdgeConnect-Cache-Status
X-N
X-Original-Request-Id
X-Response-Served-From
Refresh
X-HTML-Minification-Powered-By
Version
X-Varnish-Grace
X-Tumblr-Pixel-1
X-Tumblr-User
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Oneagent-Js-Injection
X-Cache-Rule
X-Nginx-Cache
X-URL
Section-Io-Cache
X-Varnish-Age
X-Envoy-Decorator-Operation
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
Access-Control-Request-Headers
SD-X-WS
X-Magnolia-Registration
X-Cache-Expired-At
X-Adobe-Loc
X-Adobe-Content
X-Cache-Status-Check
X-Page-View
X-Cache-Time
X-UUID
X-Newrelic-App-Data
X-Environment-Context
X-L-Path
X-Jobs
X-ProcessESI
X-Rendered-As
X-Is-Bot
X-G
NGB
X-Cacheable-TTL
X-Servername
MS-CV
X-Rule
X-Status
X-RTag
X-Cache-Grace
Ms-Operation-Id
Protected
GEO-INFO
X-RemovedCookies
X-FW-Serve
X-FW-Server
X-Device-Type
X-FW-Hash
X-Http-Reason
X-FW-Static
X-Cache-Age
X-FW-Version
X-Akamai-Request-ID2
Url
X-FW-Type
X-NYM-Debug-Backend
X-FW-Dynamic
X-Framework
Akamai-GRN
X-Content-Powered-By
X-User-Agent
X-Instance
X-Debug-IsConnected
X-Debug-IsPreview
X-Backend-Name
X-CDN-Forward
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Tb
X-Cache-Hit
X-Drupal-Cache-Contexts
CDN-RequestId
X-Drupal-Cache-Tags
SRV
X-Tt-Logid
Pinterest-Version
X-Pinterest-Rid
Pinterest-Generated-By
From-Origin
WPO-Cache-Status
WPO-Cache-Message
Country
X-Node-Name
X-Region
Accept-Language
Front
X-Trace-Id
X-Real-IP
Fastly-Drupal-HTML
X-VC-Cache
Uber-Trace-Id
Backend
X-Mode
X-Content-Options
X-Template
X-Time
Fastly-SWR
Fastly-SIE
X-Language
Filters
Meta-Geo
X-Cache-Operation
X-Rewrite-Enabled
X-RN-RSRV
X-UPSTREAM-Address
X-Generation-Time
CDN-Uid
CDN-PullZone
X-Cache-TTL-Remaining
X-Tumblr-Pixel-2
CDN-EdgeStorageId
Cross-Origin-Window-Policy
X-Web-Node
CDN-RequestCountryCode
X-DynaTrace-JS-Agent
CDN-Cache
CDN-CachedAt
Content-Secure-Policy
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Say-TTL
Apigw-Requestid
X-Proxy-Cache-Info
X-Section
Webserver
X-WP-CF-Super-Cache-Cache-Control
X-IPS-LoggedIn
X-Proxy-Cache-Status
X-Sql-Duration-Ms
X-Sql-Count
Azure-SlotName
X-Adobe-Source
X-Say-Cacheable
CF-IPCountry
X-SayCDN-TTL
X-Rocket-Nginx-Serving-Static
X-WP-CF-Super-Cache
X-Cache-Action
Azure-InstanceId
X-Cms-Context
X-Access
Azure-SiteName
Azure-RegionName
X-Format
Azure-Version
X-Forwarded-Host
X-Soup
X-Zen-Fury
X-Sucuri-ID
X-PHP-Backend
X-Sucuri-Cache
X-AWS-Id
X-Cache-Host
X-PHP-Host
Cache-Name
X-LJ-Flow-ID
X-Debug
X-GeoCountry
X-Via-Fastly
X-Varnish-Beresp-Grace
X-Content-Age
X-GeoCode
ServerID
X-Cache-Server
X-VWS-Id
X-Edge-Location
X-Skip-Cache
X-Labrador-Cache-Channel
X-TIME
X-Unique-Id
X-SaId
X-Routing-Service
X-Detected-As
X-Origin-Hint
Webcakes-Region
Webcakes-App-Version
X-Site-Version
X-ProxyCache-Status
X-Server-W
X-LAGOON
X-JoinUs
X-Ms-Request-Id
X-Ms-Version
X-UA-Device-Type
X-Proxied
X-Extlb
X-Urbn-Site-Id
Onion-Location
Property-Id
X-Zipkin-Id
S-Rt
Web-Mar-Node
X-Reqid
X-Amzn-Remapped-Content-Length
X-Xfnlog-Site
TWC-Connection-Speed
TWC-Privacy
Webcakes-App-Name
X-Cluster
TWC-Locale-Group
TWC-GeoIP-LatLong
TWC-Device-Class
TWC-GeoIP-Country
X-Urbn-Context-Path
X-ProxyCache-Key
X-Locale
Node
Locale
X-BYPASS-REASON
Mime-Version
Selected-Fe
X-Handled-By
X-Proxy-Build
WP-Super-Cache
Mn-Server-Ip
X-Ua
X-Proto
X-R9-Blue-Green-Version
X-LSADC-Cache
X-IPLB-Request-ID
X-No-Session
X-IPLB-Instance
X-Fastly-Request-Id
X-Timing-Wait
X-Cluster-Node
DB-Nickname
Fastcgi-Useragent
X-SRV
Xserver
X-FB-TRIP-ID
Cache-Hits
X-Request-Time
X-Redis-Cache
X-Hl-Ver
Liferay-Portal
X-Cache-Debug
ServedBy
X-Tumblr-Pixel-3
X-TNCMS
X-Loop
X-XRDS-LOCATION
Upgrade-Insecure-Requests
X-Optimistic-Header
X-NWS-UUID-VERIFY
X-CACHE-AGE
Source
X-Generated-By
X-GEO
X-Mg-Request-UUID
X-Air-Source
X-Air-Hostname
X-Varnish-Hits
X-Esi
X-Origin-Date
X-Air-Trace-Id
X-Tid
Countrycode
CF-Cached-On
X-Tec-Api-Root
X-Tec-Api-Origin
X-Uri
X-Times
X-Storage
X-Tec-Api-Version
X-Akamai-Transformed
X-Director
X-Varnish-Beresp-Ttl
X-Tx-Id
X-COUNTRY
Xet-Cookie
X-TA-CDN-Provider
X-Newrelic-Synthetics
Frame-Options
X-Trace-ID
X-Pass-Why
X-Presslabs-Stats
X-Origin-CC
X-Origin-TTL
X-ARC
X-DC
X-B3-Spanid
X-Service
X-FireWall-Port
X-ECache
X-App-Version
X-Sorting-Hat-ShopId
X-Varnish-Cache-Hits
X-Datadog-Sampled
X-Datadog-Parent-Id
Environment
X-Storefront-Renderer-Rendered
X-Sorting-Hat-PodId
SID
X-Datadog-Sampling-Priority
X-ShardId
X-Alternate-Cache-Key
X-Varnish-Hostname
X-ShopId
X-Datadog-Trace-Id
X-Shopify-Stage
Server-Info
Surrogated-Key
Sslversion
Candidate-Md5Url
DCR-Processing-Time-Ms
Edge-Cache
Gannett-Cam-Experience-Id
DCR-Decision-By
BehaviorPad-Version
X-Request-Host
A
Lang
MD5-Digest
Redirect-Candidate
Release
Rendered-Blocks
Origin
Odigeo-Trace-Id
Meta-Geo-Continent
Ngx.Var.Host
Req-Svc-Chain
X-Ec-Fail
X-Platform-Cluster
X-Platform-Processor
X-Platform-Router
X-Processor
X-Origin-Time
X-Nyt-Route
X-Loc
X-Mid
X-Mobile-URL
X-Rojux
X-S
X-Vdms-Path
X-Vdms-Version
X-VG-TLSProxy
Xc-Version
X-TIM-N
X-SRCache-Key
X-S-Cookie
X-S-Maxage
X-ScT
X-Gdpr
X-External-Request-Id
X-A-Dgt
X-A-Wwc
X-Aed
X-B-Cookie
X-A-Dcw
X-A-Dam
WWW-Authenticate
X-A
X-A-Ccd
X-BBC-Edge-Cache-Status
X-Bc-Bl
X-Developer
X-Ec-GeoHdr
X-Epic-Correlation-Id
X-Destination
X-D
X-BCube-Filmed-By
X-Cache-Info
X-Cache-NE
T-Server
X-Application
X-Endurance-Cache-Level
X-AIR-PT
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
Cache-Tv-Group
X-Cdn-Origin
X-INCAP-ABP
X-Cache-Bucket
Magicmarker
X-NodeID
X-Sn-Servicetimems
X-Clara-WADP
Fastly-GeoIP-CountryCode
X-CUA
X-Varnish-CookieHashed-On
Country-Code
X-DefElseHash
Decoy-Debug-Key
Decoy-Debug-Status
X-Sigma-Backend
Tube-Got-Results
DSUID
Decoy-Debug-TTL
X-Thinkindot-L3
X-Sigma
State
X-Core-Value
X-CMSURLCustom
X-Pubstack
Vix-Hermes-Req-Id
X-Platform-Server
Tube-Got-Eval
Tube-Get-Contents
Tube-Return
X-Req
X-Rocket-Build-Number
X-We-Are-Hiring
X-SD-PageType
X-Served-From
X-DefHash
X-Old-Content-Length
X-SB
X-Frame-Option
X-Akamai-Device-Characteristics
X-Origin-Response-Time
Memcached
X-Core-Mission
X-ServerID
Cluster
X-VServer
X-Fmm-Version
X-Httpd
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
Apple-News-Services-Handled
X-WA-Info
X-WADP-Cache
TDXMobile
X-GeoIP-City
Host-ID
Thinkindot-CacheControl
X-WP-CF-Super-Cache-Active
Thinkindot-CacheControl-Type
X-Gamma-Serve
Apple-News-Services-Request-Url
Thinkindot-Control
Click-Count-Action-Start
X-Varnish-Remaining-TTL
X-Varnish-CookieINHashed-On
X-Ec-Custom-Error
Click-Count-Error
X-Human
C-Via
Section-Io-Id
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
X-Parent-Response-Time
Section-Origin-Responded
X-Accel-Buffering
X-Accel-Expires-Debug
X-Date
X-Restarts
X-Gzip
X-Ad-Defer-Variation
X-Developers
X-Generated-On
X-JWT-State
User-Cache-Control
X-Gen-Mode
X-Planisys-CDN-TTL
X-GeoIP-Country-Code
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-GeoIP-Region-Code
X-Has-Esi
X-Hnp-Log
X-Fastly-Backend
X-Fetched-On
X-Test
X-LB-NoCache
X-Cache-FS-Status
X-Is-Gdpr
X-HS-Content-Campaign-Id
X-Node-Id
X-Cache-Id
X-Block-Status
X-DPWN-IS-SECURE
X-Origin
X-Location
X-App
X-Esi-Check
X-Worker
X-Dispatcher-Number
X-Hash
X-Bip
X-Minions-Version
X-Geo-Header
Server-Ext
X-Scale
NM-Fastcgi-Cache
CDCHOST
CloudFront-Viewer-Country
Origin-CC
Origin-EX
X-Up
Platform
Pics-Label
Cache-Provider
X-Slack-Backend
Cmsid
X-Auto-Login
X-Variation
X-Var-Ttl
X-Thanos
Is-Eu
X-Varnish-Beresp-Status
L
Cmstype
Kp-EeAlive
Cache-Host
Cache-Key
Svr
X-Vmg-Version
Ssr
X-Wix-Viewer-Type
Server-Host
X-Level-Front-Cache
X-Pool
Fastly-Backend-Name
X-Cdn-Srv
Sever-Int
Server-Hostname
Adler-Geo
X-Request-Start
Producers
X-GeoIP
Cdn
X-Buckets
X-RM-Cache-TTL
X-V-Cache
X-Nananana
Gh-Request-Id
Datacenter
X-Device-Os
X-Forwarded-Site
X-Dispatcher-Server
X-Varnishpool
Web-Mar-Region
X-NCache
Fastly-SSL
Wxu-Next-Commit
AKAMAI
X-Azure-Ref-OriginShield
X-Aicache-OS
X-Region-Sid
X-Qloud-Router
Wxu-Next-Region
Wxu-Next-Hostname
X-Refresh
X-Op-Id-All
X-Cache-Backend
X-Nginx-Cache-Key
We-Hiring
X-Conf
X-Ckpd-Fst-Backend
X-Owner
X-Slack-Shared-Secret-Outcome
X-Server-IP
Mail-Subject
Machine
X-Platform
X-CSRF-Token
CacheControlHeader
X-Cached-By
X-VarnishDD-TTL
X-Mvc-Supplant-Cachable
X-Tb-Optimization-Total-Bytes-Saved
X-Irp-Debug
X-Via-Poph
X-Via-Popn
X-HN
X-Via-Popv
X-CacheTTL
X-Varnish-Ttl
On-Server
X-Cache-Remote
NGX
X-Men
X-FC-Vary-Parameters
X-Org
PFcat
X-Cache-Tags
X-Webkit-CSP-Report-Only
Env
Cdnsip
Cdncip
Canary
X-Csrf-Jwt
X-CGP
GeoIP-Latitude
X-HA-Backend
L5d-Success-Class
HostName
HA-Ipaddr
Ha-Gx-Prefs
X-AK-Request-ID
X-Eu-Site
X-Servedbyhost
X-Client-Ip
X-Mvc-Supplant-OutputCached
X-Cache-Date
Server-ID
X-VC
X-RCS-CacheZone
X-Gateway-Skip-Cache
X-Gateway-Cache-Key
X-Microcachable
X-Gateway-Cache-Status
X-Gateway-Request-Id
X-LB-ID
X-API-Version
X-Mly-Id
X-APP-VERSION
X-ZONE
X-Fpc
Cache
X-Wa
X-Zone
X-DataCenter
X-Vgn-Hpd-Ssi
X-Vgn-Hpd-Variations-Key
Memory
X-Vgn-Hpd-Cached
X-Server-ID
Time
X-Webkit-CSP
Request-ID
Eomportal-Instance
X-Generated-In
X-Micro-Cache
OT-Force-Account-Verify
Ngx-Var-Key
X-Nc
Load-Balancing
X-Via-NSCOPI
X-Fastly-Cache
X-Vc
X-Origin-Expires
X-Instance-Name
X-ND-Cache
X-Correlation-ID
X-Release
X-Response-By
IsBot
X-SIPLIST1
X-Check-Cacheable
X-Request-URI
X-HS-Status
X-Nf-Request-Id
Srv
Hostname
X-Via-JSL
X-Cache-NGX
X-CCDN-CacheTTL
Locid
X-CCDN-Origin-Time
X-VCL-Version
X-FL-QIT-DEBUG
X-FL-EDGE
Srvid
X-Hcs-Proxy-Type
X-From
X-Info
X-CS
Expect-Staple
NtCoent-Length
X-Via-CDN
X-CSRF-TOKEN
AMP-Access-Control-Allow-Source-Origin
X-NewRelic-App-Data
X-Srv
X-Cache-Enabled
X-Via-Edge
Edge-Copy-Time
X-Edge-Pop
X-Via-SSL
X-MCACHE
True-Client-Ip
GeoIp-Country-Code
X-Provided-By
X-Api-Version
X-Proxy-CacheRZ
XkeyRZ
X-NGINX-Cache
True-Client-IP
X-Amz-Meta-Cb-Modifiedtime
Location
X-Lambda-Id
X-Debug-Cache-Store
Uri
X-Debug-Cache-Fetch
Path
X-Cache-Expires
X-Dc
X-EC-Lua
X-Edge-POP
X-Oss-Server-Time
X-Oss-Object-Type
X-Oss-Request-Id
X-Oss-Hash-Crc64ecma
Resin-Trace
X-Vcl-Version
GeoIP-Country-Code
X-Oss-Storage-Class
Sid
X-Air-Pt
VNS-Cache
X-Vtex-Remote-Cache
X-Fastly-Country-Code
Servername
VNS-Age
X-Render-Time
Cross-Origin-Opener-Policy-Report-Only
CPC-Age
CPC-Cache
X-B3-SpanId
X-NODE
X-Moov-T
Traceparent
X-Cs
X-Moov-Xdn-Version
LB
X-Scheme
X-TH-Server
CDN
X-Viewer-Country
Fastly-Drupal-Html
X-CLOUD-TRACE-CONTEXT
X-RateLimit-Reset
X-Cdn-Request-ID
X-ATG-Version
X-VCT
X-ApacheServer
X-PERF
X-Akamai-Pragma-Client-IP
Rip
X-TX-ID
X-Cache-ASPX
Powered-By
X-NAPM-TraceId
X-Varnish-Authentication
X-Pod-Name
Esi-Enabled
X-Contensis-Viewer-Groups
FSS-Cache
X-MSEdge-Flight
Timeexpire
X-MSEdge-Features
X-Varnish-Beresp-TTL
X-Datacenter
X-Datadome
X-Accel-Version
CountryCode
X-FPC
M-TraceId
YJS-ID
X-Cdn-Cache-Status
X-CF-Lambda-Fn
X-RateLimit-Remaining-Second
Sm-Log-Id
X-RateLimit-Limit-Second
X-CF-Lambda-Version
X-SERVER-NAME
X-Upstream-Ct
X-PAYTM-SRV-ID
V-Age
True-Client-Country-4JS
X-Clientip
Tracecode
X-WA
X-Service-Response-Time
X-Upstream-Ht
X-Udemy-Cache-App-Namespace
X-Cache-Type
X-Geo
XServer
X-Srcache-Store-Status
X-VG-WebCache
X-Srcache-Fetch-Status
Server-Id
X-CACHE-KEY
X-Lb-Id
Proxy-Connection
Ohc-File-Size
X-LiteSpeed-Cache-Control
XM
HIT
X-NC
ENV
X-Wikidot-Backend
X-TraceId
X-Wikidot-Static-Cache
X-B3-Parentspanid
Ngx
RNT-Machine
N-Cache
RNT-Time
X-CDN-Cache-Status
X-ServedByHost
Yjs-Id
X-Bl-Debug
X-Ha-Backend
X-Hyper-Cache
WZWS-RAY
X-Orig-Expires
X-Shop-Environment
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-Tenant
Epwk-X-Cache
X-Forwarded-Path
X-Cdn-Forward
Geoip-Latitude
X-Lb-Nocache
X-B3-ParentSpanId
Inserted-Into-Cache-At
Req-ID
X-Connection-Hash
X-MiniProfiler-Ids
Content-Style-Type
X-MP-GENERATED-AT
X-B3-Trace-ID
X-Cdn-Diag
User-Agent
Expiry
X-Via-PopH
X-Dw-Trace-Id
X-Via-PopN
X-Via-PopV
X-Serial
X-Fastly-Backend-Reqs
Content-Script-Type
Pramga
X-Vgn-Hpd-Reason
Ec-Rule-Version
X-Swift-Error
X-F-Status
X-Lsadc-Cache
X-TT-LOGID
X-UP
X-Stale
X-Mid-Debug-Cache-Disk
X-Mid-Debug-Cache-Key
X-Akamai-ERPolicy
X-Akamai-ERRuleID
X-Yottaa-OS
X-Webstats-RespID
X-Request-URL
X-Cache-Ngx
My-App
X-LiteSpeed-Tag
X-Th-Server
MIME-Version
Cneonction
X-IPS-Cached-Response
Warning
X-Snapshot-Date