Threat Level: green Handler on Duty: Rick Wanner

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
Strict-Transport-Security
X-Frame-Options
X-Content-Type-Options
Last-Modified
Link
CF-Cache-Status
Cf-Request-Id
Accept-Ranges
ETag
CF-RAY
Expect-CT
Pragma
X-Powered-By
X-Cache
Via
Age
X-XSS-Protection
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Xss-Protection
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-FRAME-OPTIONS
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Request-Id
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-Adblock-Key
X-AspNet-Version
X-Permitted-Cross-Domain-Policies
Alt-Svc
X-Runtime
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Cache-Status
X-Generator
CF-Ray
X-Cacheable
X-Request-ID
X-Iinfo
Timing-Allow-Origin
X-Envoy-Upstream-Service-Time
Feature-Policy
X-Ua-Compatible
X-Content-Security-Policy
Status
X-Drupal-Dynamic-Cache
Content-Encoding
X-AspNetMvc-Version
Access-Control-Expose-Headers
X-CDN
Upgrade
X-XSS-PROTECTION
Access-Control-Max-Age
X-Via
X-Cache-Group
X-Robots-Tag
Server-Timing
X-UA-Device
Request-Context
Keep-Alive
X-AH-Environment
X-Dns-Prefetch-Control
X-Amz-Request-Id
X-Turbo-Charged-By
X-Backend
X-Proxy-Cache
X-Amz-Id-2
X-Ws-Request-Id
X-Age
Host-Header
P3p
X-Server-Powered-By
X-Hacker
X-Server
X-Rq
X-Vhost
EagleId
X-Varnish-Cache
Grace
X-Amz-Version-Id
X-Dispatcher
X-LiteSpeed-Cache
Cf-Edge-Cache
Allow
X-Akamai-Path-Stats
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Swift-CacheTime
X-Swift-SaveTime
X-Device
Ali-Swift-Global-Savetime
X-WebKit-CSP
X-Nginx-Cache-Status
X-Page-Speed
X-Aws-Lambda-Call-Status
X-Host
Accept-CH
X-Node
X-OneAgent-JS-Injection
X-Pingback
Cf-Railgun
X-Cache-Spec
Request-Id
EagleEye-TraceId
X-Server-Id
Surrogate-Control
X-Akam-SW-Version
X-Backend-Server
X-Cache-Lookup
X-Response-Time
X-Readtime
Accept-CH-Lifetime
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-HW
Content-Location
X-Content-Security-Policy-Report-Only
X-Application-Context
Rating
X-Trace
X-Cloud-Trace-Context
Fastly-Restarts
X-Country
X-Url
X-Clacks-Overhead
X-WebKit-CSP-Report-Only
X-Edge
X-MS-InvokeApp
Accept-Ch-Lifetime
X-Amz-Server-Side-Encryption
X-Rack-Cache
Edge-Control
X-Nginx-Upstream-Cache-Status
X-B3-TraceId
X-TtlSet
X-Vname
X-PC
X-Ruxit-JS-Agent
X-Content-Type
X-ESI
X-Mod-Pagespeed
X-Vcap-Request-Id
X-Exp-Id
X-D2id
X-Cdn-Fetch
X-Use-Magma
X-Oneagent-Js-Injection
X-Exp-Variant
X-Kinja-Revision
X-Kinja-Server
X-GoogleNews-Bot
X-Kinja-Build
X-Kinja
Xkey
X-Mcache
X-GitHub-Request-Id
Verso
X-Amz-Rid
Cache-Tag
X-CST
X-VARITI-CCR
X-Powered-By-Plesk
RTSS
Service-Worker-Allowed
X-FastCGI-Cache
X-Upstream
X-Ruxit-Js-Agent
X-Navigation-Version
X-Varnish-TTL
X-Abt-Application-Version
X-Version
X-ECACHE
X-Cached
X-Client-IP
X-Dw-Request-Base-Id
X-Cnection
X-Ac
X-Px
X-Ttl
X-Element-Page-Cache
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Instrumentation
X-Server-Name
SPRequestGuid
X-SharePointHealthScore
Public-Key-Pins
Arr-Disable-Session-Affinity
X-Cache-TTL
SPIisLatency
SPRequestDuration
X-Middleton-Display
Pagespeed
Display
X-Sol
X-Country-Code
X-NWS-LOG-UUID
Permissions-Policy
X-Ser
Accept-Ch
X-RateLimit-Remaining
X-Cache-Key
Response
X-Middleton-Response
X-Midtier
X-Kinsta-Cache
X-Edge-Location-Klb
X-Goog-Hash
X-Forwarded-For
Content-MD5
X-SRCache-Fetch-Status
X-SRCache-Store-Status
Access-Control-Request-Method
X-DataDome
X-NF-Request-ID
Front-End-Https
X-Shield-Request-Id
X-Correlation-Id
X-MSEdge-Ref
X-Recruiting
X-HP-Webp
X-Jurisdiction
X-HP-Trace-Id
Cf-Apo-Via
AR-Request-ID
AR-PoweredBy
AR-SID
AR-ATIME
AR-CACHE
TP-Cache
X-T
TP-L2-Cache
X-Accel-Expires
Nginx-Cache
Edge-Cache-Tag
MicrosoftSharePointTeamServices
X-Daa-Tunnel
X-RateLimit-Limit
Mrf-Cache-Status
MRF-Tech
X-B3-TraceId-Primal
X-Powered-CMS
TCN
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
X-Grace
X-Mg-S
X-Id
X-Content-Digest
X-Hits
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-TEC-API-VERSION
Filters
X-Request-Received
Server-Name
X-Request-Processing-Time
X-HS-Combine-CSS
X-HS-Cache-Config
X-HS-Content-Id
X-HS-Hub-Id
Server-Node
X-Amzn-Trace-Id
X-Frontend
MS-Author-Via
X-Distributor
X-Geo-Country
S
X-Protected-By
X-LLID
Fastcgi-Cache
X-Language
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Browser-Type
Cache-Status
X-Fastly-Request-Id
X-XRDS-Location
X-LB-Cache
X-PressLabs-Stats
Count-Hit
X-Ezoic-Cdn
Cross-Origin-Opener-Policy
X-Fastcgi-Cache
X-Origin-Server
X-FB-Debug
X-Request-Handler-Origin-Region
X-Microsite
Host
X-Ab
X-Amz-Meta-S3cmd-Attrs
X-Ua-Browser
Charset
X-Git-Hash
X-Forwarded-Proto
X-F-Cache
X-Seen-By
X-Page-Id
X-B3-Sampled
Payment
Filterid
X-Litespeed-Cache
X-Cache-Age
X-ASPNET-VERSION
X-Cluster-Name
X-VCache
X-Ratelimit-Reset
Realpath
X-TTL
Surrogate-Key
X-Rid
X-Origin-Cache
Accept-Charset
Cache-Tags
X-NGENIX-Cache
X-Template
Alternate-Protocol
Access-Control-Allow-Method
X-Www-Served-By
X-Webkit-Csp
Retry-After
X-Logged-In
X-DynaTrace
X-Upgrade-Enabled
Cleartype
X-DIS-Request-ID
X-Az
X-AppVersion
X-Activity-Id
X-TT
X-Varnish-Grace
X-App-Environment
X-Amz-Replication-Status
X-Varnish-Backend
X-Request-Guid
X-Providence-Cookie
X-Flags
X-Aspnet-Duration-Ms
X-Route-Name
X-Is-Crawler
X-Tb
X-Wix-Request-Id
X-Source
X-Signature
X-B-Cache
X-B
X-Type
X-Node-Name
X-Envoy-Decorator-Operation
Paypal-Debug-Id
DC
X-Hostname
ServerID
Frame-Options
X-Drupal-Cache-Tags
X-Proxy
X-Revision
X-Fastly-Request-ID
X-Debug
X-Mobile
X-Tt-Trace-Tag
X-Contextid
X-Tt-Trace-Host
X-Server-ID
X-Content-Options
Pinterest-Generated-By
X-Pinterest-Rid
Pinterest-Version
X-Goog-Storage-Class
X-Goog-Metageneration
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Load-Cache
X-Cache-Rule
X-GUploader-UploadID
Amp-Access-Control-Allow-Source-Origin
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-N
X-Cache-Control
X-Magnolia-Registration
Country
Refresh
Node
X-Content
X-Response-Served-From
X-Whom
X-User-Agent
X-Original-Request-Id
Referer-Policy
X-EdgeConnect-Cache-Status
NGB
Viewport
X-Cache-TTL-Remaining
X-Debug-IsConnected
X-Framework
X-Cacheable-TTL
X-Debug-IsPreview
Access-Control-Request-Headers
Uber-Trace-Id
X-Real-IP
X-Yottaa-Metrics
X-Akamai-Request-ID2
X-L-Path
X-Content-Powered-By
X-Servername
X-Adobe-Loc
VIX-Pulpo-Node
X-Adobe-Content
Url
X-Jobs
X-G
X-Yottaa-Optimizations
X-Mid
VIX-Pulpo-Upstream-Status
X-Environment-Context
X-Varnish-Age
X-NYM-Debug-Backend
X-Cache-Time
X-Cache-Grace
X-Page-View
Content-Disposition
X-Status
X-Varnish-Server
X-XRDS-LOCATION
X-Oracle-Dms-Rid
X-Instance
X-Is-Bot
X-RemovedCookies
X-Oracle-Dms-Ecid
Akamai-GRN
X-Rendered-As
Srv
X-Unique-Id
X-ProcessESI
Countrycode
X-Ratelimit-Remaining
X-Time
X-Drupal-Cache-Contexts
X-Mg-Request-UUID
Version
X-COUNTRY
X-APP-VERSION
X-Restarts
X-Http-Reason
X-Via-JSL
X-Cache-Expired-At
X-App-Server
Accept-Language
X-Trace-Id
X-CDN-Forward
Healthy
X-Debug-Info
X-Cache-Hit
Protected
X-Hosted-By
X-IPLB-Instance
X-IPLB-Request-ID
X-Tumblr-Pixel
X-Tumblr-Pixel-1
X-Tumblr-User
X-Tumblr-Pixel-0
X-Cache-Operation
Cross-Origin-Resource-Policy
X-Azure-Ref
X-Device-Type
X-Ratelimit-Limit
Section-Io-Cache
X-Backend-Name
X-Tt-Logid
X-Nginx-Cache-Key
Liferay-Portal
X-Akamai-Edgescape
Content-Secure-Policy
Backend
X-ECache
Fastcgi-Useragent
X-FW-Serve
Server-Info
X-FW-Type
X-FW-Static
X-FW-Server
X-FW-Dynamic
X-FW-Hash
X-Cache-Action
X-Api-Version
X-RTag
X-Mobile-URL
X-SRV
X-Storage
Ms-Operation-Id
MS-CV
X-UPSTREAM-Address
X-Varnish-Ttl
X-RN-RSRV
Load-Balancing
X-Rule
Meta-Geo
X-Proxy-Cache-Status
X-Cache-NGX
GEO-INFO
X-VC-Cache
X-Content-Age
X-Varnish-Beresp-Grace
CDN-RequestCountryCode
CDN-RequestId
X-Urbn-Site-Id
CDN-CachedAt
CDN-Uid
CDN-Cache
CDN-PullZone
X-Edge-Location
X-Cache-Enabled
X-Adobe-Source
X-Varnishpool
X-Cms-Context
S-Rt
X-Varnish-Hostname
CF-IPCountry
X-Alternate-Cache-Key
Locale
X-Urbn-Context-Path
X-Forwarded-Host
X-Say-TTL
X-SayCDN-TTL
X-Say-Cacheable
X-Handled-By
X-Proto
X-Region
X-ShardId
X-ShopId
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Skip-Cache
X-Site-Version
X-Shopify-Stage
X-PHP-Host
X-Redis-Cache
X-PCL
X-No-Session
X-Labrador-Cache-Channel
CDN-EdgeStorageId
X-UUID
X-OCL
X-PHP-Backend
Azure-RegionName
DB-Nickname
Eomportal-Instance
Azure-InstanceId
X-Uri
X-Timing-Wait
X-Hl-Ver
X-GeoCountry
X-Sql-Count
X-Sql-Duration-Ms
X-Cache-Type
X-Generated-By
X-GeoCode
X-ServerID
X-Section
X-Via-Fastly
X-VWS-Id
X-FB-TRIP-ID
X-ProxyCache-Status
X-ProxyCache-Key
X-Access
X-Web-Node
X-BYPASS-REASON
X-LJ-Flow-ID
X-Cache-Server
Selected-Fe
X-AWS-Id
X-Proxy-Build
Azure-SiteName
TWC-Connection-Speed
Webcakes-Region
Property-Id
TWC-Locale-Group
X-Generation-Time
Webcakes-App-Version
X-Varnish-Cache-Hits
TWC-Device-Class
Web-Mar-Node
X-Format
X-Mode
TWC-GeoIP-LatLong
TWC-GeoIP-Country
TWC-Privacy
X-Cache-Host
X-Locale
X-Origin-Hint
Azure-Version
Apigw-Requestid
Onion-Location
Azure-SlotName
Webcakes-App-Name
X-Storefront-Renderer-Rendered
X-Nginx-Cache
X-Request-Time
X-UA-Device-Type
X-HTML-Minification-Powered-By
X-R9-Blue-Green-Version
X-Detected-As
Mn-Server-Ip
X-Cache-Status-Check
X-Xfnlog-Site
X-Origin-Date
X-Ms-Version
X-URL
WP-Super-Cache
X-JoinUs
X-Ms-Request-Id
X-SaId
X-Proxied
X-Extlb
Cache-Name
Xserver
X-Server-W
X-Zipkin-Id
X-Datadome
X-Routing-Service
X-FireWall-Port
X-Tid
X-WP-CF-Super-Cache
X-DynaTrace-JS-Agent
X-Correlation-ID
X-WP-CF-Super-Cache-Cache-Control
ServedBy
X-LSADC-Cache
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Zen-Fury
X-Human
X-TNCMS
X-Loop
X-Ua
X-Cache-Tags
Source
Cache
Xet-Cookie
X-Dc
X-Debug-Cache
X-Reqid
X-GEO
X-App-Version
X-TA-CDN-Provider
X-Varnish-Hits
X-Soup
X-Cached-By
X-Pubstack
X-Aspnetmvc-Version
X-RCS-CacheZone
Cross-Origin-Window-Policy
SD-X-WS
X-Amzn-Remapped-Content-Length
X-MP-GENERATED-AT
X-Vgn-Hpd-Reason
X-Cdn
WPO-Cache-Status
X-Origin-TTL
WPO-Cache-Message
X-Webkit-CSP
X-Newrelic-Synthetics
Origin
X-Origin-CC
From-Origin
X-Service
X-Tumblr-Pixel-2
X-Provided-By
LB
X-IPS-LoggedIn
X-Varnish-Beresp-Ttl
X-AOL-HN
X-NewRelic-App-Data
Webserver
Rip
X-Via-NSCOPI
X-Tec-Api-Root
X-Tec-Api-Origin
X-B3-SpanId
X-Tec-Api-Version
X-Request-Host
X-Platform-Server
X-FW-Version
X-GG-Cache-Date
X-Aed
Expiry
X-A-Dam
X-A-Dcw
X-NAPM-TraceId
X-Orig-Expires
X-A-Wwc
X-A-Dgt
X-A
X-Rewrite-Enabled
X-Rojux
X-S
Host-ID
X-CSRF-Token
Environment
X-Owner
X-PBS-Appsvrname
X-A-Ccd
X-AK-Request-ID
Cdnsip
X-Cache-NE
X-Destination
X-Developer
Cdncip
A
X-Connection-Hash
BehaviorPad-Version
X-D
X-Ec-Fail
X-Ec-GeoHdr
X-Bc-Bl
X-B-Cookie
X-ARC
X-Application
X-BCube-Filmed-By
DCR-Processing-Time-Ms
X-External-Request-Id
DCR-Decision-By
X-Forwarded-Path
X-S-Cookie
X-Processor
X-Cluster-Node
Surrogated-Key
MD5-Digest
Odigeo-Trace-Id
T-Server
Sslversion
Ngx.Var.Host
Meta-Geo-Continent
X-TIM-N
Lang
X-Tenant
X-User
X-SRCache-Key
X-Vdms-Version
X-Vdms-Path
X-Served-From
X-ScT
X-VG-WebCache
Xc-Version
Rendered-Blocks
X-Shop-Environment
HostName
OT-Force-Account-Verify
X-VC
Mime-Version
X-B3-Traceid
X-Generated-On
Redirect-Candidate
CPC-Age
X-Varnish-Beresp-Status
X-Dispatcher-Number
Upgrade-Insecure-Requests
X-Bip
X-Accel-Buffering
X-Aicache-OS
X-Thanos
X-Pool
VNS-Cache
VNS-Age
Machine
X-Parent-Response-Time
X-Qloud-Router
CPC-Cache
X-Level-Front-Cache
X-WA-Info
X-TIME
Tube-Got-Results
Tube-Return
V-Age
X-CacheTTL
Vix-Hermes-Req-Id
Release
X-Clientip
Tube-Got-Eval
X-Ckpd-Fst-Backend
X-CGP
Server-Host
X-Cdn-Origin
X-Cache-Info
Wxu-Next-Hostname
Wxu-Next-Commit
Wxu-Next-Region
State
Thinkindot-CacheControl-Type
Tube-Get-Contents
X-Branch-Name
X-Cache-Bucket
X-Ad-Defer-Variation
Thinkindot-Control
X-Cache-Id
TDXMobile
Thinkindot-CacheControl
X-CMSURLCustom
X-Gateway-Skip-Cache
X-Rocket-Nginx-Serving-Static
X-Rocket-Build-Number
X-S-Maxage
X-SB
X-Sigma-Backend
X-Sigma
X-Request-URI
X-Region-Sid
X-Planisys-CDN-Cache
X-Origin-Response-Time
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-Slack-Backend
X-Sn-Servicetimems
X-Varnish-Remaining-TTL
X-Varnish-CookieINHashed-On
X-VG-TLSProxy
X-VServer
X-Worker
X-Wix-Viewer-Type
X-Varnish-CookieHashed-On
X-Variation
X-SVT-ORM-RULES
X-SplitTest
X-SVT-ORM-VERSION
X-Thinkindot-L3
X-V-Cache
X-Origin
X-Optimistic-Header
X-Ec-Custom-Error
X-Device-Os
X-Epic-Correlation-Id
X-Esi-Check
X-Fetched-On
X-Eu-Site
X-DefHash
X-DefElseHash
X-Csrf-Jwt
X-Core-Value
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
X-Datadog-Trace-Id
X-Forwarded-Site
X-Gamma-Serve
X-Irp-Debug
X-Hash
X-Loc
X-Mvc-Supplant-Cachable
X-NodeID
X-Mvc-Supplant-OutputCached
X-Gzip
X-GeoIP-City
X-Gateway-Cache-Status
X-Gateway-Cache-Key
X-Gateway-Request-Id
Producers
X-GeoIP
X-Core-Mission
X-DPWN-IS-SECURE
Decoy-Debug-TTL
DSUID
Decoy-Debug-Status
Decoy-Debug-Key
Cmstype
Fastly-SSL
Ha-Gx-Prefs
L
Kp-EeAlive
Is-Eu
HA-Ipaddr
Cmsid
Click-Count-Error
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
Apple-News-Services-Handled
Adler-Geo
Apple-News-Services-Request-Url
Cache-Hits
Click-Count-Action-Start
Candidate-Md5Url
Canary
Cache-Host
L5d-Success-Class
Fastly-GeoIP-CountryCode
Mobile-Detection-Method
NM-Fastcgi-Cache
Memcached
NGX
Platform
X-Cache-Debug
X-Minions-Version
Mail-Subject
Servername
Gh-Request-Id
X-Cdn-Srv
X-NCache
X-Geo-Header
Origin-CC
Datacenter
CloudFront-Viewer-Country
X-JWT-State
X-SIPLIST1
X-WADP-Cache
X-HS-Content-Campaign-Id
Req-Svc-Chain
Origin-EX
X-Cluster
X-Is-Gdpr
Country-Code
X-Clara-WADP
Cluster
X-Has-Esi
X-Fmm-Version
Fastly-SWR
Fastly-SIE
X-Scheme
Fastly-Backend-Name
X-Origin-Time
X-Proxy-Cache-Info
IsBot
X-Scale
X-Policy
X-Nyt-Route
X-Developers
We-Hiring
Svr
X-BBC-Edge-Cache-Status
Web-Mar-Region
X-Viewer-Country
Traceparent
X-INCAP-ABP
X-Gdpr
WebServer
Ec-Rule-Version
X-WP-CF-Super-Cache-Active
X-Trace-ID
X-Tx-Id
Cache-Tv-Group
X-ZONE
X-Gen-Mode
X-Hnp-Log
X-Block-Status
X-Sucuri-ID
X-Sucuri-Cache
Sever-Int
AKAMAI
Server-Hostname
Server-Ext
CDCHOST
X-Auto-Login
User-Cache-Control
X-Cache-Remote
Ssr
X-LB-NoCache
X-Fastly-Cache
X-Azure-Ref-OriginShield
X-Var-Ttl
X-ND-Cache
X-FC-Vary-Parameters
Time
Memory
X-ATG-Version
X-Session-Fingerprint
Fastcgi-Cache-TTL
X-Presslabs-Stats
X-Rebelmouse-Surrogate-Control
X-Origin-Expires
X-Fastly-Backend
X-Rebelmouse-Cache-Control
X-Udemy-Cache-App-Namespace
Sid
X-Newrelic-App-Data
Pics-Label
X-Nf-Request-Id
Fastly-Drupal-HTML
SID
X-Tb-Optimization-Total-Bytes-Saved
X-Pod-Name
X-Generated-In
X-Via-Poph
X-Via-Popn
X-Via-Popv
X-NWS-UUID-VERIFY
Env
AMP-Access-Control-Allow-Source-Origin
X-Cache-Date
X-Buckets
Server-ID
X-Servedbyhost
X-Akamai-Transformed
X-Refresh
X-Xrds-Location
X-Ig-Push-State
X-Cs
X-DC
X-Release
X-Pass-Why
X-Edge-Pop
X-Up
X-Conf
X-NC
X-MSEdge-Flight
X-Microcachable
Fastly-Drupal-Html
X-EC-Lua
X-MSEdge-Features
My-App
X-Fpc
X-Dispatch
X-Tumblr-Pixel-3
X-Dmc
X-RateLimit-Reset
X-Lambda-Id
X-Endurance-Cache-Level
X-Esi
X-Wa
CDN
X-PX
GeoIp-Country-Code
X-ID
X-MCACHE
X-TX-ID
X-CS
X-Be
True-Client-IP
X-VCL-Version
X-Req
X-CACHE-AGE
Magicmarker
X-Zone
X-TRACE-ID
X-Webkit-CSP-Report-Only
X-NGINX-Cache
X-Wikidot-Static-Cache
X-Wikidot-Backend
X-LB-ID
X-CACHE-KEY
X-Vc
X-CSRF-TOKEN
X-TH-Server
X-Air-Trace-Id
True-Client-Country-4JS
X-Air-Source
Hostname
CacheControlHeader
X-Air-Hostname
X-Hyper-Cache
X-Yandex-Sdch-Disable
X-CF-Lambda-Version
X-CF-Lambda-Fn
X-Op-Id-All
X-Micro-Cache
X-Srv
X-B3-Spanid
True-Client-Ip
Pramga
X-HS-Status
X-M-Log
X-M-Reqid
Path
X-Vcl-Version
Resin-Trace
X-Alfa-Service
X-Air-Pt
X-App
X-Varnish-Beresp-TTL
X-Qnm-Cache
GeoIP-Country-Code
C-Via
Tcn
X-GeoIP-Country-Code
X-TrackingId
X-GeoIP-Region-Code
N-Cache
Tracecode
X-SERVER-NAME
Section-Io-Origin-Status
Esi-Enabled
On-Server
Section-Io-Origin-Time-Seconds
X-Platform
X-Vercel-Cache
X-PAYTM-SRV-ID
X-Vercel-Id
X-FPC
Fastcgi-X-Cache-Version
Section-Io-Id
Section-Origin-Responded
X-Accel-Expires-Debug
WWW-Authenticate
X-Akamai-Pragma-Client-IP
X-Date
NtCoent-Length
X-Check-Cacheable
X-CLOUD-TRACE-CONTEXT
X-Datacenter
X-WA
X-RAMCache
X-Edge-Origin-Shield-Bytes
Yjs-Id
Proxy-Connection
X-Edge-Origin-Shield-Region
Hit
X-Webkit-Csp-Report-Only
X-Cdn-Forward
X-Old-Content-Length
X-Platform-Router
X-Platform-Processor
X-Platform-Cluster
X-Mly-Id
X-ServedByHost
Server-Id
Lb
FSS-Cache
X-Via-CDN
X-Node-Id
X-Vtex-Remote-Cache
X-Edge-POP
X-Vtex-Processado-Em
X-Geo
GeoIP-Latitude
X-SD-PageType
X-Lb-Id
X-Request-Start
X-Response-By
Powered-By
X-API-Version
X-LiteSpeed-Cache-Control
User-Agent
ENV
YJS-ID
X-LAGOON
X-UA
X-Dw-Trace-Id
X-AIR-PT
X-Via-PopV
Cache-Key
X-PERF
X-Via-PopH
X-Via-PopN
Cdn
X-ApacheServer
X-Client-Ip
X-Akamai-ERPolicy
HIT
X-Akamai-ERRuleID
X-Proxy-CacheRZ
PICS-Label
X-TT-LOGID
X-Cache-Ttl
DynaTrace
X-FORWARDED-FOR
X-LI-Proto
X-Location
X-From
X-FL-EDGE
X-Webstats-RespID
X-Render-Time
Server-Ttl
X-CUA
X-Via-Ucdn
X-Traceid
Srvid
X-Li-Fabric
X-Li-Pop
X-LI-UUID
XkeyRZ
X-Instance-Name
Geoip-Latitude
Dnion-Transfer-Encoding
Locid
Sm-Log-Id
X-Service-Response-Time
DT-Hot-News
Ohc-File-Size
X-RSL
X-Cache-ASPX
X-VarnishDD-TTL
X-Contensis-Viewer-Groups
X-Varnish-Authentication
X-Director
XM
X-RPS
X-DI
X-DSS
X-DW
X-RPM
X-DB
Location
Nginx-CQVIP
XServer
X-LiteSpeed-Tag
X-HN
X-Proxy-Upstream
X-Proxy-Cache-Hk
PFcat
X-CF-Powered-By
X-Litespeed-Cache-Control
X-Wp-Cf-Super-Cache-Cache-Control
X-Wp-Cf-Super-Cache
Wpo-Cache-Status
X-HostName
X-Request-Url
Wpo-Cache-Message
X-B3-ParentSpanId
X-Lb-Nocache
X-Fastly-Cache-Hits
X-Cdn-Request-ID
Vha6-Origin
X-Server-IP
X-Fastly-Backend-Reqs
X-DataCenter
Warning
X-Cache-Ngx
CountryCode
X-Ips-Loggedin
Wp-Super-Cache
X-Yottaa-OS
Fastcgi-Cache-Ttl
CF-Cached-On
X-Test
Swift-Performance
Req-ID
WZWS-RAY
X-Moov-T
X-Mg-Cache
X-Moov-Xdn-Version
SRV
X-ElasticPress-Query