Threat Level: green Handler on Duty: Guy Bruneau

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Accept-Ranges
Expect-CT
CF-RAY
Pragma
X-Powered-By
X-XSS-Protection
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-Xss-Protection
X-UA-Compatible
P3P
X-Served-By
X-Download-Options
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Request-ID
Access-Control-Allow-Credentials
X-Request-Id
CF-Ray
X-Permitted-Cross-Domain-Policies
X-AspNet-Version
Alt-Svc
Content-Security-Policy-Report-Only
X-Runtime
X-DNS-Prefetch-Control
X-Drupal-Cache
X-Check
X-Cache-Status
X-Generator
X-Cacheable
P3p
Timing-Allow-Origin
X-FRAME-OPTIONS
X-Iinfo
X-Envoy-Upstream-Service-Time
X-Content-Security-Policy
X-Drupal-Dynamic-Cache
Feature-Policy
Content-Encoding
Upgrade
Access-Control-Expose-Headers
Status
X-AspNetMvc-Version
X-CDN
Access-Control-Max-Age
X-Via
Server-Timing
X-UA-Device
X-Robots-Tag
Request-Context
X-Turbo-Charged-By
X-Cache-Group
X-Amz-Request-Id
EagleId
X-Amz-Id-2
X-Backend
Keep-Alive
X-AH-Environment
X-Proxy-Cache
X-Ws-Request-Id
X-Server
X-Age
Host-Header
X-Hacker
X-Ua-Compatible
Cf-Edge-Cache
X-Vhost
X-Server-Powered-By
X-Rq
Allow
X-Varnish-Cache
X-Dispatcher
X-Amz-Version-Id
Grace
X-LiteSpeed-Cache
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-WebKit-CSP
X-OneAgent-JS-Injection
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
Accept-CH
X-Device
Cf-Apo-Via
X-Page-Speed
Cf-Railgun
X-Aws-Lambda-Call-Status
X-Server-Id
X-Host
X-Node
X-Pingback
X-Cache-Spec
X-Nginx-Cache-Status
X-Akam-SW-Version
Surrogate-Control
X-Dns-Prefetch-Control
EagleEye-TraceId
X-Backend-Server
Request-Id
X-Cache-Lookup
X-Readtime
X-HW
X-Ruxit-JS-Agent
X-Cloud-Trace-Context
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Content-Security-Policy-Report-Only
X-Application-Context
X-Trace
X-Response-Time
Accept-Ch-Lifetime
Permissions-Policy
X-CST
X-Nginx-Upstream-Cache-Status
X-Mod-Pagespeed
Fastly-Restarts
Accept-CH-Lifetime
X-Edge
X-WebKit-CSP-Report-Only
Content-Location
X-Country
X-Content-Type
X-Mcache
X-ECACHE
Rating
X-Clacks-Overhead
X-MS-InvokeApp
X-Url
X-TtlSet
X-Vname
X-PC
X-Amz-Server-Side-Encryption
X-Midtier
RTSS
X-VARITI-CCR
X-B3-TraceId
Cache-Tag
X-Vcap-Request-Id
X-Varnish-TTL
X-Element-Page-Cache
Verso
X-D2id
Origin-Trial
X-Ac
X-Server-Name
X-Cdn-Fetch
X-Exp-Variant
X-GoogleNews-Bot
X-Kinja
X-Kinja-Server
X-Kinja-Build
X-Exp-Id
X-Use-Magma
X-Kinja-Revision
X-Rack-Cache
X-Cnection
X-Cache-TTL
Service-Worker-Allowed
X-Powered-By-Plesk
X-GitHub-Request-Id
Xkey
X-Navigation-Version
X-Abt-Application-Version
X-NWS-LOG-UUID
X-ESI
X-Amz-Rid
X-SharePointHealthScore
SPRequestGuid
Edge-Control
X-Client-IP
X-Fastcgi-Cache
X-Cached
X-Ttl
X-Px
X-Mg-S
X-Erf-Bev-Bev-Is-Generated
X-Instrumentation
X-Kraken-Loop-Name
Arr-Disable-Session-Affinity
X-Erf-Bev-Bev
X-Server-Lifecycle-Phase
X-Browser-Type
X-Litespeed-Cache
SPRequestDuration
SPIisLatency
X-Upstream
X-Correlation-Id
X-Cache-Key
X-Middleton-Display
Pagespeed
X-Sol
Display
Content-MD5
X-Dw-Request-Base-Id
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-NF-Request-ID
Access-Control-Request-Method
Edge-Cache-Tag
X-Goog-Hash
X-XRDS-Location
X-Daa-Tunnel
Front-End-Https
X-Country-Code
Public-Key-Pins
X-Version
X-Forwarded-For
AR-PoweredBy
AR-ATIME
AR-Request-ID
AR-SID
AR-CACHE
X-Id
X-Powered-CMS
TCN
X-MSEdge-Ref
X-T
X-Recruiting
X-RateLimit-Remaining
X-Content-Digest
X-Accel-Expires
X-Jurisdiction
X-HP-Trace-Id
X-HP-Webp
X-Middleton-Response
Response
Mrf-Cache-Status
X-B3-TraceId-Primal
MRF-Tech
X-Shield-Request-Id
X-Ser
TP-Cache
TP-L2-Cache
Nginx-Cache
X-Amzn-Trace-Id
X-Fastly-Request-ID
S
X-Hits
X-Request-Processing-Time
X-Request-Received
X-HS-Hub-Id
X-HS-Combine-CSS
X-HS-Content-Id
X-HS-Cache-Config
X-Distributor
Server-Node
Cache-Status
X-Edge-Location-Klb
X-Kinsta-Cache
X-Ruxit-Js-Agent
X-Ratelimit-Limit
Cache-Tags
MicrosoftSharePointTeamServices
Fastcgi-Cache
Alternate-Protocol
X-Grace
Server-Name
X-DataDome
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Protected-By
X-TTL
X-DIS-Request-ID
X-Ezoic-Cdn
X-Ratelimit-Remaining
X-Origin-Server
X-Geo-Country
X-Ratelimit-Reset
X-LB-Cache
Accept-Ch
X-Ua-Browser
X-Request-Handler-Origin-Region
X-Microsite
X-Frontend
X-Debug-Info
X-Rid
Cross-Origin-Opener-Policy
X-Www-Served-By
Cleartype
X-Varnish-Backend
X-Logged-In
X-Forwarded-Proto
X-Git-Hash
X-NGENIX-Cache
Payment
Healthy
Filterid
X-Page-Id
X-FB-Debug
X-Load-Cache
Charset
X-B3-Sampled
Content-Disposition
X-Webkit-Csp
X-PressLabs-Stats
X-VCache
X-ASPNET-VERSION
X-Origin-Cache
X-LLID
X-Oracle-Dms-Ecid
X-Cluster-Name
X-Oracle-Dms-Rid
DC
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Hostname
MS-Author-Via
X-Goog-Metageneration
X-GUploader-UploadID
X-Upgrade-Enabled
X-Oneagent-Js-Injection
Retry-After
Accept-Charset
X-Proxy
Access-Control-Allow-Method
X-F-Cache
X-AppVersion
X-Az
X-Activity-Id
Cross-Origin-Resource-Policy
X-Type
X-Signature
X-Contextid
X-B-Cache
X-Amz-Replication-Status
X-Is-Crawler
X-Hosted-By
X-Flags
X-Providence-Cookie
X-Route-Name
X-Revision
Paypal-Debug-Id
X-Varnish-Server
X-Aspnet-Duration-Ms
X-Request-Guid
Viewport
X-B
X-Wix-Request-Id
X-Seen-By
X-TT
X-Amz-Meta-S3cmd-Attrs
X-Azure-Ref
X-Whom
X-App-Environment
Amp-Access-Control-Allow-Source-Origin
X-FastCGI-Cache
Referer-Policy
Surrogate-Key
Realpath
X-Fb-Rlafr
X-Source
X-DynaTrace
X-Aspnetmvc-Version
Count-Hit
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Akamai-Edgescape
X-RateLimit-Limit
X-Mobile
X-App-Server
X-Goog-Generation
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
Host
X-Cache-Control
X-EdgeConnect-Cache-Status
X-N
X-Cache-Rule
X-Response-Served-From
Version
X-HTML-Minification-Powered-By
X-Original-Request-Id
X-Tumblr-Pixel
X-Tumblr-User
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
Refresh
X-Magnolia-Registration
X-Varnish-Age
X-Varnish-Grace
X-UUID
VIX-Pulpo-Node
X-Envoy-Decorator-Operation
X-Rule
Section-Io-Cache
SD-X-WS
VIX-Pulpo-Upstream-Status
Access-Control-Request-Headers
X-Cache-Expired-At
X-FW-Server
MS-CV
X-Adobe-Content
Ms-Operation-Id
X-FW-Static
X-Cache-Time
X-Cache-Status-Check
X-Cache-Grace
X-FW-Version
X-FW-Type
X-Adobe-Loc
X-Content-Powered-By
Protected
Akamai-GRN
X-FW-Serve
X-Status
X-L-Path
X-Page-View
X-RTag
X-FW-Dynamic
X-Environment-Context
X-FW-Hash
X-G
X-Instance
X-Rendered-As
X-URL
X-Cacheable-TTL
X-NYM-Debug-Backend
NGB
GEO-INFO
X-RemovedCookies
X-Servername
X-ProcessESI
X-Is-Bot
X-Jobs
X-Http-Reason
Url
X-Device-Type
X-Framework
X-Akamai-Request-ID2
X-Nginx-Cache
X-Template
X-Backend-Name
X-User-Agent
X-Language
X-Debug-IsPreview
X-Debug-IsConnected
X-CDN-Forward
X-B3-Traceid
SRV
X-Newrelic-App-Data
X-Drupal-Cache-Contexts
X-Yottaa-Metrics
X-Cache-Age
X-Drupal-Cache-Tags
X-Yottaa-Optimizations
CDN-RequestId
X-Cache-Hit
WPO-Cache-Status
X-Tb
WPO-Cache-Message
From-Origin
X-Trace-Id
X-Pinterest-Rid
Pinterest-Generated-By
Pinterest-Version
Country
X-Region
X-Tt-Logid
Accept-Language
X-Node-Name
Front
X-Real-IP
Fastly-Drupal-HTML
Backend
X-VC-Cache
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Content-Options
Uber-Trace-Id
X-Mode
X-TIME
Content-Secure-Policy
Fastly-SWR
X-Cache-Operation
X-DynaTrace-JS-Agent
X-Unique-Id
Fastly-SIE
X-Tumblr-Pixel-2
Filters
X-Rewrite-Enabled
Meta-Geo
X-Generation-Time
X-RN-RSRV
X-UPSTREAM-Address
X-COUNTRY
Azure-RegionName
Azure-InstanceId
X-Zen-Fury
X-IPS-LoggedIn
Azure-SiteName
X-Section
X-Cache-TTL-Remaining
X-Format
X-Rocket-Nginx-Serving-Static
X-Access
Onion-Location
CF-IPCountry
X-Web-Node
Azure-SlotName
Azure-Version
X-Say-Cacheable
X-Say-TTL
X-Ua
X-Amzn-Remapped-Content-Length
X-Cache-Action
X-Cache-Server
X-Cache-Host
X-SayCDN-TTL
X-SRV
X-Sucuri-Cache
Apigw-Requestid
X-Sql-Duration-Ms
X-Sucuri-ID
Webserver
X-Sql-Count
X-Cms-Context
X-Adobe-Source
X-Proxy-Cache-Info
X-Proxy-Cache-Status
X-Debug
CDN-CachedAt
CDN-EdgeStorageId
CDN-PullZone
CDN-RequestCountryCode
TWC-Privacy
CDN-Cache
Cache-Name
X-Reqid
Webcakes-Region
TWC-Locale-Group
CDN-Uid
X-PHP-Host
X-Labrador-Cache-Channel
X-Via-Fastly
Web-Mar-Node
TWC-GeoIP-LatLong
X-Edge-Location
X-Content-Age
X-Forwarded-Host
X-Origin-Hint
X-GeoCountry
Webcakes-App-Version
S-Rt
ServerID
X-GeoCode
Webcakes-App-Name
Cross-Origin-Window-Policy
X-Soup
X-Skip-Cache
TWC-Connection-Speed
X-PHP-Backend
Property-Id
X-Server-W
X-Locale
X-Varnish-Beresp-Grace
TWC-Device-Class
TWC-GeoIP-Country
X-Detected-As
X-Extlb
X-VWS-Id
X-BYPASS-REASON
X-SaId
X-Urbn-Site-Id
X-Handled-By
X-JoinUs
X-Site-Version
X-Proxied
X-ProxyCache-Key
X-ProxyCache-Status
X-R9-Blue-Green-Version
X-Proto
X-Routing-Service
X-AWS-Id
X-IPLB-Request-ID
X-LAGOON
X-LJ-Flow-ID
X-LSADC-Cache
X-IPLB-Instance
X-Cluster
Locale
X-Xfnlog-Site
X-Urbn-Context-Path
X-UA-Device-Type
Node
X-Zipkin-Id
X-CACHE-AGE
X-Proxy-Build
X-Timing-Wait
Mn-Server-Ip
X-No-Session
X-WP-CF-Super-Cache-Cache-Control
Cache-Hits
X-WP-CF-Super-Cache
X-Time
X-Fastly-Request-Id
WP-Super-Cache
Mime-Version
Selected-Fe
X-Ms-Request-Id
DB-Nickname
Fastcgi-Useragent
X-Ms-Version
X-Cluster-Node
Liferay-Portal
X-Hl-Ver
X-FB-TRIP-ID
X-Request-Time
Xserver
X-Tumblr-Pixel-3
X-Tec-Api-Root
ServedBy
X-Times
X-Tec-Api-Origin
X-Tec-Api-Version
X-Cache-Debug
X-Optimistic-Header
X-Redis-Cache
X-Air-Hostname
X-Air-Source
X-Air-Trace-Id
X-XRDS-LOCATION
X-Loop
X-TNCMS
Source
X-GEO
Upgrade-Insecure-Requests
X-Generated-By
X-Buckets
X-NWS-UUID-VERIFY
X-Origin-Date
X-Mg-Request-UUID
X-Varnish-Hits
X-Esi
CF-Cached-On
X-Uri
X-Akamai-Transformed
Countrycode
X-Director
X-Pass-Why
X-Tid
X-Varnish-Beresp-Ttl
X-Storage
X-Cdn
X-Tx-Id
Xet-Cookie
X-TA-CDN-Provider
Frame-Options
X-ARC
X-Presslabs-Stats
X-Origin-CC
X-DC
X-Origin-TTL
X-FireWall-Port
X-Newrelic-Synthetics
X-Varnish-Cache-Hits
X-Service
X-ECache
X-App-Version
X-Trace-ID
X-ShardId
X-Sorting-Hat-ShopId
X-Varnish-Hostname
X-ShopId
X-Storefront-Renderer-Rendered
SID
X-Alternate-Cache-Key
X-Sorting-Hat-PodId
X-Shopify-Stage
X-Datadog-Trace-Id
Environment
X-B3-Spanid
X-Datadog-Parent-Id
X-Endurance-Cache-Level
X-Datadog-Sampled
X-Datadog-Sampling-Priority
Cache-Tv-Group
X-Request-Host
Thinkindot-CacheControl-Type
Thinkindot-Control
WWW-Authenticate
Thinkindot-CacheControl
TDXMobile
Sslversion
T-Server
Req-Svc-Chain
Rendered-Blocks
Surrogated-Key
Lang
DCR-Processing-Time-Ms
Edge-Cache
Gannett-Cam-Experience-Id
DCR-Decision-By
Candidate-Md5Url
A
BehaviorPad-Version
Host-ID
X-A
Origin
Redirect-Candidate
Odigeo-Trace-Id
Ngx.Var.Host
MD5-Digest
Meta-Geo-Continent
Release
X-Cache-NE
X-Platform-Router
X-Processor
X-Rojux
X-S
X-Platform-Processor
X-Platform-Cluster
X-Mid
X-Mobile-URL
X-Nyt-Route
X-Origin-Time
X-S-Cookie
X-S-Maxage
X-Vdms-Version
X-VG-TLSProxy
X-We-Are-Hiring
Xc-Version
X-Vdms-Path
X-TIM-N
X-ScT
X-SRCache-Key
X-Thinkindot-L3
X-Loc
X-INCAP-ABP
X-B-Cookie
X-BBC-Edge-Cache-Status
X-Bc-Bl
X-BCube-Filmed-By
X-Application
X-Aed
X-A-Dam
X-A-Dcw
X-A-Dgt
X-A-Wwc
X-Cache-Info
X-CMSURLCustom
X-Epic-Correlation-Id
X-External-Request-Id
X-Frame-Option
X-Gdpr
X-Ec-Fail
X-Developer
X-Core-Value
X-D
X-Destination
X-A-Ccd
X-Ec-GeoHdr
Server-Info
X-ServerID
X-Core-Mission
X-Clara-WADP
X-Cdn-Srv
X-SD-PageType
X-CUA
X-DefElseHash
X-Restarts
X-SB
X-Sn-Servicetimems
X-Req
Tube-Got-Eval
Tube-Got-Results
Tube-Return
Tube-Get-Contents
Fastly-Backend-Name
X-Geo-Header
X-SVT-ORM-VERSION
Fastly-GeoIP-CountryCode
X-SVT-ORM-RULES
X-DefHash
X-HS-Content-Campaign-Id
X-Human
X-Is-Gdpr
X-Fmm-Version
X-Has-Esi
X-GeoIP-City
X-Gamma-Serve
Server-Host
X-JWT-State
X-Pubstack
Magicmarker
X-Developers
Decoy-Debug-TTL
X-Origin-Response-Time
X-Old-Content-Length
X-Ec-Custom-Error
State
X-NodeID
X-Platform-Server
DSUID
Apple-News-Services-Host
Apple-News-Services-Handled
Decoy-Debug-Status
Apple-News-Services-Request-Url
X-WP-CF-Super-Cache-Active
C-Via
Vix-Hermes-Req-Id
X-Cache-Bucket
X-Served-From
X-Akamai-Device-Characteristics
X-Auto-Login
X-Level-Front-Cache
X-Generated-On
X-Worker
Apple-News-Services-Parsed-Url
Country-Code
Cluster
Decoy-Debug-Key
X-VServer
X-Varnish-CookieHashed-On
X-Varnish-Remaining-TTL
Click-Count-Action-Start
Click-Count-Error
X-Varnish-CookieINHashed-On
X-WADP-Cache
X-Cdn-Origin
X-WA-Info
X-RM-Cache-TTL
X-AIR-PT
Section-Origin-Responded
Section-Io-Origin-Time-Seconds
Section-Io-Id
Section-Io-Origin-Status
X-Ad-Defer-Variation
X-Gen-Mode
X-Fastly-Backend
X-App
X-DPWN-IS-SECURE
X-Cache-Id
X-Date
X-Cache-FS-Status
X-Dispatcher-Number
X-Block-Status
X-Cache-Backend
X-Esi-Check
X-Request-Start
AKAMAI
CloudFront-Viewer-Country
Memcached
X-Wix-Viewer-Type
X-Variation
X-Test
X-Up
X-Var-Ttl
Ssr
Svr
X-Varnish-Beresp-Status
X-Vmg-Version
X-Conf
X-Thanos
X-Pool
X-Bip
X-Fetched-On
X-Slack-Backend
X-Sigma-Backend
X-LB-NoCache
X-Location
X-Minions-Version
X-Httpd
X-Hnp-Log
X-GeoIP-Region-Code
X-Gzip
X-Nananana
X-Node-Id
X-Rocket-Build-Number
X-Scale
X-Sigma
X-Accel-Expires-Debug
X-Planisys-CDN-Rules
X-Origin
X-Planisys-CDN-Cache
X-GeoIP-Country-Code
X-Planisys-CDN-TTL
Cmsid
Cmstype
Gh-Request-Id
CDCHOST
Cache-Provider
Adler-Geo
Cache-Host
Server-Hostname
Is-Eu
L
Sever-Int
Producers
Server-Ext
Platform
Pics-Label
Origin-CC
Origin-EX
User-Cache-Control
X-Accel-Buffering
Web-Mar-Region
X-Parent-Response-Time
Mail-Subject
X-Op-Id-All
NM-Fastcgi-Cache
X-Platform
Kp-EeAlive
X-Nginx-Cache-Key
X-Owner
X-Qloud-Router
X-Varnishpool
X-GeoIP
X-Org
X-V-Cache
X-Hash
X-NCache
X-Region-Sid
X-Forwarded-Site
X-Men
Wxu-Next-Hostname
Cache-Key
Wxu-Next-Region
Datacenter
Machine
On-Server
NGX
X-Azure-Ref-OriginShield
CacheControlHeader
Fastly-SSL
X-Slack-Shared-Secret-Outcome
Wxu-Next-Commit
X-Dispatcher-Server
Cdn
X-Ckpd-Fst-Backend
X-Device-Os
X-Server-IP
X-Refresh
We-Hiring
X-Cached-By
PFcat
X-HN
X-Via-Poph
X-Irp-Debug
X-Mvc-Supplant-Cachable
X-Cache-Tags
X-VarnishDD-TTL
X-Via-Popn
X-Via-Popv
X-CacheTTL
X-Varnish-Ttl
X-FC-Vary-Parameters
X-Webkit-CSP-Report-Only
X-Servedbyhost
X-Aicache-OS
Env
X-CGP
X-Eu-Site
Ha-Gx-Prefs
X-Csrf-Jwt
GeoIP-Latitude
HA-Ipaddr
X-CSRF-Token
L5d-Success-Class
Canary
X-Cache-Date
X-HA-Backend
X-Client-Ip
X-RCS-CacheZone
Server-ID
X-Cache-Remote
X-Mvc-Supplant-OutputCached
X-Tb-Optimization-Total-Bytes-Saved
X-AK-Request-ID
X-Microcachable
Cdnsip
Cdncip
HostName
X-Mly-Id
X-VC
X-APP-VERSION
X-Wa
X-Gateway-Skip-Cache
X-Fpc
X-LB-ID
X-ZONE
X-Gateway-Cache-Status
X-Gateway-Cache-Key
X-API-Version
X-Gateway-Request-Id
X-DataCenter
Load-Balancing
X-Zone
X-Vc
Time
X-Nc
X-Fastly-Cache
Cache
Memory
Request-ID
X-Webkit-CSP
X-Check-Cacheable
X-Via-NSCOPI
X-Origin-Expires
X-ND-Cache
Eomportal-Instance
X-Generated-In
X-Instance-Name
X-Vgn-Hpd-Variations-Key
X-Vgn-Hpd-Ssi
X-Vgn-Hpd-Cached
X-Release
X-Response-By
X-Micro-Cache
Ngx-Var-Key
Hostname
OT-Force-Account-Verify
X-CS
X-Correlation-ID
Srvid
X-CCDN-Origin-Time
X-Hcs-Proxy-Type
X-FL-QIT-DEBUG
X-NewRelic-App-Data
Locid
X-From
X-CCDN-CacheTTL
Expect-Staple
X-HS-Status
X-FL-EDGE
X-CSRF-TOKEN
X-Request-URI
X-SIPLIST1
X-Via-CDN
X-Cache-Enabled
X-Api-Version
IsBot
NtCoent-Length
X-Info
X-Cache-NGX
AMP-Access-Control-Allow-Source-Origin
Edge-Copy-Time
X-Edge-Pop
X-Via-Edge
X-Via-SSL
X-VCL-Version
Srv
X-Via-JSL
X-NGINX-Cache
X-Provided-By
GeoIp-Country-Code
X-MCACHE
Uri
X-Srv
XkeyRZ
X-Proxy-CacheRZ
X-Amz-Meta-Cb-Modifiedtime
X-Air-Pt
X-Debug-Cache-Fetch
X-Nf-Request-Id
X-Lambda-Id
X-Debug-Cache-Store
True-Client-Ip
X-Vcl-Version
True-Client-IP
Location
X-Dc
X-B3-SpanId
X-EC-Lua
X-Vtex-Remote-Cache
X-Render-Time
Sid
X-Cache-Expires
CPC-Cache
VNS-Age
CPC-Age
X-Edge-POP
Servername
VNS-Cache
Path
X-Oss-Request-Id
X-Oss-Storage-Class
X-Oss-Server-Time
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
Resin-Trace
GeoIP-Country-Code
X-Server-ID
Cross-Origin-Opener-Policy-Report-Only
X-Fastly-Country-Code
X-TH-Server
X-Cs
X-Moov-Xdn-Version
Fastly-Drupal-Html
Traceparent
X-VCT
X-Moov-T
X-ATG-Version
X-CLOUD-TRACE-CONTEXT
CDN
LB
X-Contensis-Viewer-Groups
X-Cache-ASPX
X-Scheme
X-MSEdge-Flight
X-MSEdge-Features
X-Varnish-Authentication
X-Viewer-Country
X-Cdn-Request-ID
X-Accel-Version
X-TX-ID
M-TraceId
Timeexpire
X-Pod-Name
Esi-Enabled
YJS-ID
X-PERF
X-ApacheServer
X-Akamai-Pragma-Client-IP
X-Varnish-Beresp-TTL
X-Upstream-Ct
X-Upstream-Ht
X-Datacenter
X-FPC
X-Udemy-Cache-App-Namespace
FSS-Cache
CountryCode
Rip
X-NAPM-TraceId
X-Datadome
Powered-By
X-RateLimit-Remaining-Second
X-RateLimit-Reset
X-Cache-Type
X-CF-Lambda-Version
X-PAYTM-SRV-ID
X-CF-Lambda-Fn
X-RateLimit-Limit-Second
X-Lb-Id
X-WA
X-SERVER-NAME
X-Service-Response-Time
Sm-Log-Id
HIT
X-Cdn-Cache-Status
X-Geo
XServer
N-Cache
X-Srcache-Store-Status
X-CACHE-KEY
True-Client-Country-4JS
Tracecode
V-Age
X-Srcache-Fetch-Status
X-NC
X-Wikidot-Backend
RNT-Time
Ohc-File-Size
X-Clientip
Proxy-Connection
Server-Id
X-Wikidot-Static-Cache
RNT-Machine
X-Shop-Environment
X-Tenant
X-Bl-Debug
X-CDN-Cache-Status
Epwk-X-Cache
X-Forwarded-Path
X-Hyper-Cache
X-Orig-Expires
XM
X-TraceId
X-ServedByHost
X-LiteSpeed-Cache-Control
X-VG-WebCache
ENV
WZWS-RAY
X-B3-Trace-ID
Yjs-Id
X-Cdn-Forward
X-MP-GENERATED-AT
X-Ha-Backend
X-B3-Parentspanid
Geoip-Latitude
Ngx
X-M-Log
X-M-Reqid
X-Rebelmouse-Surrogate-Control
X-Lb-Nocache
X-Rebelmouse-Cache-Control
X-Qnm-Cache
Inserted-Into-Cache-At
Content-Style-Type
X-B3-ParentSpanId
X-Vgn-Hpd-Reason
User-Agent
Ec-Rule-Version
X-Via-PopV
X-Via-PopN
X-Serial
X-Fastly-Backend-Reqs
X-App-Name
X-Dw-Trace-Id
Content-Script-Type
X-MiniProfiler-Ids
X-Policy
X-Swift-Error
X-Cdn-Diag
X-Amz-Meta-Opti
X-Via-PopH
X-TT-LOGID
X-F-Status
X-Wp-Cf-Super-Cache
X-Lsadc-Cache
X-Wp-Cf-Super-Cache-Cache-Control
X-Ramcache
X-Connection-Hash
Req-ID
X-Th-Server
My-App
X-Cache-Ngx
MIME-Version
Cneonction
X-IPS-Cached-Response
Warning
X-UP
X-LiteSpeed-Tag
Pramga
X-Snapshot-Date
X-Stale
X-Mid-Debug-Cache-Disk
X-Request-URL
X-Mid-Debug-Cache-Key
Expiry