Threat Level: green Handler on Duty: Guy Bruneau

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Accept-Ranges
Expect-CT
X-XSS-Protection
CF-RAY
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
P3P
X-Xss-Protection
X-Served-By
X-Download-Options
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Request-ID
X-Adblock-Key
Access-Control-Allow-Credentials
CF-Ray
X-Permitted-Cross-Domain-Policies
X-AspNet-Version
X-Request-Id
Alt-Svc
X-Runtime
Content-Security-Policy-Report-Only
X-DNS-Prefetch-Control
X-Drupal-Cache
X-Check
X-Cache-Status
X-Generator
X-Cacheable
P3p
Timing-Allow-Origin
X-FRAME-OPTIONS
X-Iinfo
X-Envoy-Upstream-Service-Time
X-Content-Security-Policy
X-Drupal-Dynamic-Cache
Feature-Policy
Content-Encoding
Upgrade
Status
Access-Control-Expose-Headers
X-AspNetMvc-Version
X-CDN
Access-Control-Max-Age
X-Via
Server-Timing
X-UA-Device
X-Robots-Tag
Request-Context
X-Turbo-Charged-By
X-Amz-Request-Id
X-Cache-Group
EagleId
X-Amz-Id-2
X-Backend
Keep-Alive
X-AH-Environment
X-Proxy-Cache
X-Ws-Request-Id
X-Server
X-Age
Host-Header
X-Hacker
X-Ua-Compatible
Cf-Edge-Cache
X-Vhost
X-Server-Powered-By
X-Rq
Allow
X-Varnish-Cache
X-Dispatcher
X-Amz-Version-Id
Grace
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-LiteSpeed-Cache
X-OneAgent-JS-Injection
X-WebKit-CSP
Accept-CH
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
Cf-Apo-Via
X-Page-Speed
X-Device
Cf-Railgun
X-Aws-Lambda-Call-Status
X-Server-Id
X-Host
X-Node
X-Pingback
X-Cache-Spec
X-Nginx-Cache-Status
X-Akam-SW-Version
Surrogate-Control
X-Dns-Prefetch-Control
X-Backend-Server
EagleEye-TraceId
Request-Id
X-Cache-Lookup
X-Readtime
X-Ruxit-JS-Agent
X-HW
X-Cloud-Trace-Context
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Content-Security-Policy-Report-Only
X-Trace
X-Application-Context
X-Response-Time
Accept-Ch-Lifetime
Permissions-Policy
X-CST
X-Nginx-Upstream-Cache-Status
X-Mod-Pagespeed
Fastly-Restarts
Accept-CH-Lifetime
X-Edge
X-WebKit-CSP-Report-Only
Content-Location
X-Country
X-Content-Type
X-Mcache
X-ECACHE
Rating
X-Clacks-Overhead
X-MS-InvokeApp
X-Url
X-PC
X-Vname
X-TtlSet
X-Amz-Server-Side-Encryption
X-Midtier
RTSS
X-VARITI-CCR
X-B3-TraceId
Cache-Tag
X-Varnish-TTL
X-Vcap-Request-Id
X-D2id
Verso
X-Ac
Origin-Trial
X-Element-Page-Cache
X-Kinja-Build
X-Kinja-Revision
X-Kinja
X-Exp-Id
X-GoogleNews-Bot
X-Kinja-Server
X-Use-Magma
X-Cdn-Fetch
X-Exp-Variant
X-Server-Name
X-Rack-Cache
X-Cnection
X-Litespeed-Cache
X-Cache-TTL
X-Powered-By-Plesk
Service-Worker-Allowed
X-ESI
Xkey
X-Navigation-Version
X-Client-IP
X-Abt-Application-Version
X-NWS-LOG-UUID
X-Ttl
SPRequestGuid
X-Amz-Rid
X-SharePointHealthScore
X-GitHub-Request-Id
Edge-Control
X-Cached
X-Fastcgi-Cache
X-Px
X-Mg-S
X-Browser-Type
X-Erf-Bev-Bev
Arr-Disable-Session-Affinity
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-Instrumentation
X-Erf-Bev-Bev-Is-Generated
X-Upstream
SPIisLatency
SPRequestDuration
X-Correlation-Id
X-Middleton-Display
X-Sol
Display
Pagespeed
X-Cache-Key
Content-MD5
X-Dw-Request-Base-Id
X-SRCache-Store-Status
X-SRCache-Fetch-Status
Access-Control-Request-Method
X-NF-Request-ID
Edge-Cache-Tag
X-Goog-Hash
X-XRDS-Location
X-Daa-Tunnel
Front-End-Https
X-Country-Code
Public-Key-Pins
X-Version
X-Forwarded-For
X-Id
X-Powered-CMS
AR-PoweredBy
AR-SID
AR-ATIME
AR-Request-ID
AR-CACHE
TCN
X-MSEdge-Ref
X-HP-Trace-Id
X-Recruiting
X-Jurisdiction
X-HP-Webp
X-T
X-Content-Digest
X-RateLimit-Remaining
X-Accel-Expires
X-Middleton-Response
Response
MRF-Tech
Mrf-Cache-Status
X-B3-TraceId-Primal
X-Shield-Request-Id
X-Ser
TP-Cache
TP-L2-Cache
X-Amzn-Trace-Id
Nginx-Cache
X-Hits
S
X-Request-Processing-Time
X-Request-Received
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Combine-CSS
X-HS-Cache-Config
Cache-Status
X-Distributor
Server-Node
X-Kinsta-Cache
X-Edge-Location-Klb
X-Fastly-Request-ID
X-Ratelimit-Limit
Cache-Tags
MicrosoftSharePointTeamServices
X-Grace
Fastcgi-Cache
Alternate-Protocol
Server-Name
X-Protected-By
X-DataDome
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Ezoic-Cdn
X-DIS-Request-ID
X-Origin-Server
X-Ratelimit-Remaining
X-Ratelimit-Reset
X-Geo-Country
X-LB-Cache
X-Ruxit-Js-Agent
X-Ua-Browser
X-Frontend
X-Request-Handler-Origin-Region
X-Microsite
X-Varnish-Backend
X-Rid
X-Debug-Info
Cross-Origin-Opener-Policy
X-Logged-In
X-Www-Served-By
Cleartype
X-Git-Hash
Payment
Healthy
X-NGENIX-Cache
X-Forwarded-Proto
Filterid
X-FB-Debug
X-Page-Id
X-TTL
X-Load-Cache
Charset
X-B3-Sampled
Content-Disposition
X-Webkit-Csp
X-PressLabs-Stats
X-VCache
X-ASPNET-VERSION
X-LLID
X-Origin-Cache
X-Oracle-Dms-Rid
X-Oracle-Dms-Ecid
X-Cluster-Name
DC
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
MS-Author-Via
X-Hostname
X-Goog-Metageneration
X-GUploader-UploadID
X-Upgrade-Enabled
Retry-After
Accept-Charset
Access-Control-Allow-Method
X-Proxy
X-Az
X-AppVersion
X-F-Cache
X-Activity-Id
Cross-Origin-Resource-Policy
X-Type
X-Contextid
X-Signature
X-B-Cache
X-Flags
X-Varnish-Server
X-Hosted-By
X-Route-Name
X-Providence-Cookie
X-Is-Crawler
Paypal-Debug-Id
X-Request-Guid
X-Aspnet-Duration-Ms
X-Amz-Meta-S3cmd-Attrs
X-Revision
X-Amz-Replication-Status
Accept-Ch
X-Seen-By
X-TT
X-Whom
Viewport
X-B
X-Wix-Request-Id
X-Azure-Ref
X-Fb-Rlafr
X-App-Environment
Surrogate-Key
Amp-Access-Control-Allow-Source-Origin
Referer-Policy
X-FastCGI-Cache
Realpath
X-Source
X-DynaTrace
Count-Hit
X-Aspnetmvc-Version
X-Tt-Trace-Host
X-Akamai-Edgescape
X-Tt-Trace-Tag
X-RateLimit-Limit
X-Mobile
X-App-Server
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Goog-Generation
X-Goog-Stored-Content-Length
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-Cache-Control
Host
X-EdgeConnect-Cache-Status
X-HTML-Minification-Powered-By
X-N
X-Response-Served-From
X-Original-Request-Id
X-Cache-Rule
Version
X-Varnish-Grace
X-Magnolia-Registration
X-Oneagent-Js-Injection
X-UUID
MS-CV
Access-Control-Request-Headers
X-Tumblr-Pixel-1
X-Tumblr-Pixel
X-Tumblr-User
X-Tumblr-Pixel-0
VIX-Pulpo-Upstream-Status
Section-Io-Cache
Refresh
X-Cache-Time
X-Rule
Ms-Operation-Id
X-RTag
X-Envoy-Decorator-Operation
X-Varnish-Age
VIX-Pulpo-Node
X-Content-Powered-By
Protected
Akamai-GRN
X-Adobe-Loc
X-Adobe-Content
X-Cache-Grace
X-FW-Version
X-Page-View
X-FW-Type
X-L-Path
X-Cache-Expired-At
X-Environment-Context
X-FW-Static
X-Status
X-FW-Server
X-FW-Hash
X-FW-Dynamic
X-FW-Serve
GEO-INFO
X-Cache-Status-Check
X-Cache-Age
NGB
X-Is-Bot
X-Servername
SD-X-WS
X-Rendered-As
X-NYM-Debug-Backend
X-Cacheable-TTL
X-Device-Type
X-Instance
X-G
X-Framework
X-Http-Reason
X-Jobs
X-User-Agent
X-Akamai-Request-ID2
Url
X-Backend-Name
X-RemovedCookies
X-Language
X-Template
X-Debug-IsPreview
X-Nginx-Cache
X-ProcessESI
X-Debug-IsConnected
X-CDN-Forward
X-B3-Traceid
X-Newrelic-App-Data
SRV
X-Drupal-Cache-Contexts
X-Yottaa-Optimizations
X-Drupal-Cache-Tags
X-Yottaa-Metrics
CDN-RequestId
X-Cache-Hit
From-Origin
WPO-Cache-Status
X-Tb
WPO-Cache-Message
X-Trace-Id
Pinterest-Generated-By
Pinterest-Version
X-Region
X-Pinterest-Rid
Country
Accept-Language
X-Tt-Logid
Front
X-Node-Name
X-URL
X-Real-IP
X-Amzn-RequestId
X-Amz-Apigw-Id
Fastly-Drupal-HTML
X-VC-Cache
Backend
X-Fastly-Request-Id
X-Content-Options
Uber-Trace-Id
X-Mode
Content-Secure-Policy
Fastly-SWR
Fastly-SIE
X-Cache-Operation
X-DynaTrace-JS-Agent
X-Unique-Id
X-RN-RSRV
Meta-Geo
X-COUNTRY
X-UPSTREAM-Address
X-Time
Filters
X-Rewrite-Enabled
X-Generation-Time
X-Format
X-Cache-TTL-Remaining
X-Zen-Fury
Webserver
X-IPS-LoggedIn
Azure-InstanceId
X-Proxy-Cache-Info
Azure-RegionName
X-Section
X-Amzn-Remapped-Content-Length
Onion-Location
X-Web-Node
CF-IPCountry
Azure-SlotName
Azure-Version
X-Access
Azure-SiteName
X-Adobe-Source
X-Proxy-Cache-Status
X-Sql-Count
X-SayCDN-TTL
Apigw-Requestid
X-Say-TTL
X-Say-Cacheable
X-Sql-Duration-Ms
X-Ua
X-Sucuri-ID
X-SRV
X-Sucuri-Cache
X-Debug
X-Reqid
X-Cache-Server
X-Cache-Host
X-Rocket-Nginx-Serving-Static
CDN-Uid
CDN-RequestCountryCode
CDN-PullZone
CDN-Cache
TWC-GeoIP-LatLong
X-Edge-Location
X-GeoCountry
Cross-Origin-Window-Policy
CDN-CachedAt
CDN-EdgeStorageId
S-Rt
X-IPLB-Request-ID
X-Cache-Action
X-BYPASS-REASON
X-IPLB-Instance
X-Cluster
X-Content-Age
X-Cms-Context
X-AWS-Id
Webcakes-App-Name
X-LJ-Flow-ID
Webcakes-Region
Webcakes-App-Version
ServerID
Web-Mar-Node
X-Labrador-Cache-Channel
TWC-Connection-Speed
TWC-GeoIP-Country
X-Soup
X-UA-Device-Type
TWC-Device-Class
X-ProxyCache-Status
X-R9-Blue-Green-Version
X-ProxyCache-Key
Property-Id
X-Locale
X-VWS-Id
X-Origin-Hint
TWC-Locale-Group
X-Forwarded-Host
X-Proto
X-Ms-Request-Id
TWC-Privacy
X-GeoCode
Node
X-Ms-Version
X-Tumblr-Pixel-2
X-PHP-Host
X-Varnish-Beresp-Grace
X-TIME
X-Server-W
X-JoinUs
X-PHP-Backend
X-Xfnlog-Site
X-Site-Version
X-LAGOON
X-Routing-Service
X-Proxied
X-SaId
Cache-Name
X-Cluster-Node
X-Zipkin-Id
Locale
X-Urbn-Context-Path
X-Handled-By
X-Skip-Cache
X-Detected-As
X-Urbn-Site-Id
X-Extlb
Mn-Server-Ip
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
X-Proxy-Build
Selected-Fe
WP-Super-Cache
X-Timing-Wait
Cache-Hits
X-LSADC-Cache
X-No-Session
Mime-Version
Fastcgi-Useragent
X-Via-Fastly
DB-Nickname
X-FB-TRIP-ID
Liferay-Portal
X-Hl-Ver
X-Tec-Api-Root
X-Tec-Api-Origin
X-Times
Xserver
ServedBy
X-Request-Time
X-Tec-Api-Version
X-Optimistic-Header
X-Cache-Debug
X-XRDS-LOCATION
X-Redis-Cache
X-CACHE-AGE
X-Air-Trace-Id
Source
Upgrade-Insecure-Requests
X-Loop
X-TNCMS
X-Air-Hostname
X-Air-Source
X-Tumblr-Pixel-3
X-Origin-Date
X-GEO
X-Buckets
X-NWS-UUID-VERIFY
X-Generated-By
Countrycode
X-Mg-Request-UUID
X-Akamai-Transformed
CF-Cached-On
X-Uri
X-Varnish-Hits
X-Director
X-Varnish-Beresp-Ttl
X-Tid
X-Cdn
X-Storage
X-Pass-Why
Xet-Cookie
X-TA-CDN-Provider
X-Tx-Id
X-ARC
Frame-Options
X-Presslabs-Stats
X-Origin-TTL
X-FireWall-Port
X-DC
X-Origin-CC
X-Newrelic-Synthetics
X-Varnish-Cache-Hits
X-ECache
SID
X-App-Version
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Shopify-Stage
X-ShopId
X-ShardId
X-Storefront-Renderer-Rendered
X-Esi
X-Service
X-Trace-ID
X-Alternate-Cache-Key
Environment
X-B3-Spanid
X-Datadog-Sampling-Priority
X-Datadog-Trace-Id
X-Varnish-Hostname
X-Datadog-Parent-Id
X-Datadog-Sampled
X-Endurance-Cache-Level
X-Request-Host
Rendered-Blocks
WWW-Authenticate
Thinkindot-Control
Thinkindot-CacheControl
T-Server
Surrogated-Key
TDXMobile
Req-Svc-Chain
Thinkindot-CacheControl-Type
BehaviorPad-Version
DCR-Decision-By
DCR-Processing-Time-Ms
Candidate-Md5Url
X-A
X-ServerID
A
Gannett-Cam-Experience-Id
Lang
Origin
Redirect-Candidate
Odigeo-Trace-Id
Ngx.Var.Host
MD5-Digest
Meta-Geo-Continent
Release
X-BCube-Filmed-By
X-Nyt-Route
X-Origin-Time
X-Processor
X-Rojux
X-Mobile-URL
X-Mid
X-Gdpr
X-INCAP-ABP
X-Loc
X-S
X-S-Cookie
X-Vdms-Version
X-VG-TLSProxy
X-We-Are-Hiring
Xc-Version
X-Vdms-Path
X-TIM-N
X-ScT
X-SRCache-Key
X-Thinkindot-L3
X-Frame-Option
X-External-Request-Id
X-Application
X-B-Cookie
X-BBC-Edge-Cache-Status
X-Bc-Bl
X-Aed
X-A-Wwc
X-A-Dam
X-A-Dcw
X-A-Dgt
X-Cache-Info
X-Cache-NE
X-Ec-Fail
X-Ec-GeoHdr
X-Epic-Correlation-Id
X-Developer
X-Destination
X-CMSURLCustom
X-Core-Value
X-D
X-A-Ccd
Sslversion
X-AIR-PT
Server-Info
Cache-Tv-Group
Server-Host
X-Served-From
X-Human
X-Httpd
State
X-Restarts
X-Developers
X-Rocket-Build-Number
X-S-Maxage
X-Ec-Custom-Error
X-Pubstack
X-HS-Content-Campaign-Id
X-Varnish-CookieHashed-On
Host-ID
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
Fastly-GeoIP-CountryCode
X-Test
X-SVT-ORM-VERSION
X-Level-Front-Cache
X-Sigma
X-Sn-Servicetimems
X-SVT-ORM-RULES
Magicmarker
Tube-Get-Contents
Tube-Got-Results
X-JWT-State
X-CUA
X-Cache-Bucket
X-DefElseHash
X-NodeID
X-Location
X-Core-Mission
X-Clara-WADP
X-Cdn-Srv
X-Cdn-Origin
X-Generated-On
X-DefHash
X-Old-Content-Length
Vix-Hermes-Req-Id
X-Platform-Router
X-Platform-Server
Tube-Return
Fastly-Backend-Name
X-Platform-Processor
X-Platform-Cluster
X-Auto-Login
X-Akamai-Device-Characteristics
X-Origin-Response-Time
X-Is-Gdpr
Tube-Got-Eval
X-Sigma-Backend
X-WA-Info
X-GeoIP-City
X-Worker
Cache-Host
Decoy-Debug-Key
C-Via
Country-Code
X-WP-CF-Super-Cache-Active
Click-Count-Error
Click-Count-Action-Start
X-VServer
Apple-News-Services-Host
X-Has-Esi
Decoy-Debug-Status
X-Fmm-Version
Edge-Cache
DSUID
Decoy-Debug-TTL
Apple-News-Services-Handled
X-RM-Cache-TTL
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
X-WADP-Cache
Section-Origin-Responded
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
Section-Io-Id
X-Accel-Buffering
X-Accel-Expires-Debug
Adler-Geo
X-Ad-Defer-Variation
User-Cache-Control
X-Planisys-CDN-TTL
We-Hiring
AKAMAI
Web-Mar-Region
X-Wix-Viewer-Type
X-Planisys-CDN-Rules
X-Gzip
X-Cache-Id
X-Cache-FS-Status
X-Gen-Mode
X-GeoIP
X-Nananana
X-LB-NoCache
Svr
X-Fetched-On
Ssr
X-Minions-Version
X-Cache-Backend
X-Block-Status
X-App
CloudFront-Viewer-Country
X-Gamma-Serve
X-Planisys-CDN-Cache
X-Origin
X-GeoIP-Region-Code
X-Date
X-GeoIP-Country-Code
Memcached
Cache-Key
X-Request-Start
X-Slack-Backend
X-Esi-Check
X-Varnish-Beresp-Status
X-Hash
NM-Fastcgi-Cache
Cmstype
Cmsid
Origin-EX
Origin-CC
Mail-Subject
X-Up
Gh-Request-Id
X-Hnp-Log
X-Vmg-Version
X-Fastly-Backend
X-Variation
Is-Eu
L
Kp-EeAlive
X-Var-Ttl
X-Dispatcher-Number
Cluster
CacheControlHeader
CDCHOST
Sever-Int
Cache-Provider
X-Conf
X-Pool
X-DPWN-IS-SECURE
X-Req
Pics-Label
X-Geo-Header
Producers
X-Thanos
Platform
X-Bip
X-SD-PageType
X-Scale
Server-Hostname
Server-Ext
X-SB
X-Parent-Response-Time
X-HN
X-Irp-Debug
X-Forwarded-Site
X-FC-Vary-Parameters
X-Region-Sid
Fastly-SSL
X-VarnishDD-TTL
X-Varnishpool
X-Slack-Shared-Secret-Outcome
PFcat
X-V-Cache
Cdn
X-Azure-Ref-OriginShield
Wxu-Next-Region
Wxu-Next-Hostname
On-Server
NGX
Datacenter
Machine
Wxu-Next-Commit
X-Server-IP
X-CacheTTL
X-Ckpd-Fst-Backend
X-Cached-By
X-NCache
X-Mvc-Supplant-Cachable
X-Cache-Tags
X-Node-Id
X-Nginx-Cache-Key
X-Owner
X-Men
X-Qloud-Router
X-Refresh
X-Op-Id-All
X-Device-Os
X-Platform
X-CSRF-Token
X-Via-Poph
X-Dispatcher-Server
X-Via-Popn
X-Via-Popv
Canary
X-CGP
X-Csrf-Jwt
X-Org
X-Server-ID
Ha-Gx-Prefs
L5d-Success-Class
HA-Ipaddr
X-Eu-Site
X-Varnish-Ttl
X-Webkit-CSP-Report-Only
X-HA-Backend
GeoIP-Latitude
X-Aicache-OS
Env
X-Mvc-Supplant-OutputCached
X-Cache-Date
X-Servedbyhost
HostName
Cdncip
Cdnsip
X-AK-Request-ID
X-Cache-Remote
X-RCS-CacheZone
X-Tb-Optimization-Total-Bytes-Saved
Server-ID
X-VC
X-Microcachable
X-Mly-Id
X-API-Version
X-Gateway-Request-Id
X-ZONE
X-Gateway-Skip-Cache
X-Gateway-Cache-Status
X-APP-VERSION
X-Fpc
X-Wa
X-DataCenter
X-Gateway-Cache-Key
X-LB-ID
X-Zone
Load-Balancing
X-Nc
X-Fastly-Cache
Memory
X-Generated-In
Time
Cache
Request-ID
X-Webkit-CSP
X-Check-Cacheable
Eomportal-Instance
X-ND-Cache
X-Via-NSCOPI
X-Origin-Expires
X-Vgn-Hpd-Variations-Key
X-Vgn-Hpd-Cached
X-Vc
X-Vgn-Hpd-Ssi
X-HS-Status
X-Micro-Cache
X-Instance-Name
X-Response-By
X-Release
Ngx-Var-Key
OT-Force-Account-Verify
X-Correlation-ID
Expect-Staple
X-From
Locid
X-Client-Ip
Srvid
X-FL-EDGE
X-NewRelic-App-Data
X-FL-QIT-DEBUG
X-Api-Version
Hostname
IsBot
X-Via-CDN
X-SIPLIST1
X-Cache-Enabled
X-Request-URI
X-CCDN-Origin-Time
X-CS
X-Hcs-Proxy-Type
X-CCDN-CacheTTL
NtCoent-Length
X-Cache-NGX
X-Info
X-CSRF-TOKEN
AMP-Access-Control-Allow-Source-Origin
X-Via-SSL
X-Via-Edge
Edge-Copy-Time
X-Edge-Pop
X-VCL-Version
X-NGINX-Cache
Srv
X-Via-JSL
X-Provided-By
X-MCACHE
GeoIp-Country-Code
True-Client-Ip
Uri
XkeyRZ
X-Srv
X-Proxy-CacheRZ
X-Nf-Request-Id
X-Amz-Meta-Cb-Modifiedtime
X-Debug-Cache-Store
X-Lambda-Id
X-Debug-Cache-Fetch
X-Vcl-Version
Location
True-Client-IP
X-EC-Lua
X-Dc
X-B3-SpanId
X-Render-Time
VNS-Age
VNS-Cache
CPC-Cache
X-Vtex-Remote-Cache
CPC-Age
X-Edge-POP
Servername
X-Cache-Expires
Sid
Path
X-Air-Pt
GeoIP-Country-Code
X-Oss-Hash-Crc64ecma
Resin-Trace
X-Cs
X-Oss-Storage-Class
X-Oss-Server-Time
X-Oss-Object-Type
X-Oss-Request-Id
X-TH-Server
X-Fastly-Country-Code
X-VCT
Cross-Origin-Opener-Policy-Report-Only
Traceparent
Fastly-Drupal-Html
X-ATG-Version
X-CLOUD-TRACE-CONTEXT
CDN
X-Moov-Xdn-Version
X-Moov-T
X-Contensis-Viewer-Groups
LB
X-MSEdge-Features
X-MSEdge-Flight
X-Varnish-Authentication
X-Cache-ASPX
X-Viewer-Country
X-Cdn-Request-ID
X-Scheme
Esi-Enabled
X-TX-ID
YJS-ID
X-Accel-Version
X-Pod-Name
X-ApacheServer
M-TraceId
Timeexpire
X-PERF
X-Upstream-Ht
X-Upstream-Ct
X-Akamai-Pragma-Client-IP
X-Varnish-Beresp-TTL
CountryCode
X-CF-Lambda-Fn
X-FPC
X-Datadome
X-Cdn-Cache-Status
X-Udemy-Cache-App-Namespace
Rip
X-CF-Lambda-Version
X-RateLimit-Reset
X-Datacenter
FSS-Cache
X-NAPM-TraceId
Powered-By
X-Cache-Type
X-Lb-Id
X-SERVER-NAME
X-PAYTM-SRV-ID
X-WA
HIT
Sm-Log-Id
X-RateLimit-Limit-Second
X-Service-Response-Time
X-RateLimit-Remaining-Second
X-Geo
X-Github-Request-Id
XServer
X-Wikidot-Static-Cache
X-CACHE-KEY
X-Srcache-Fetch-Status
X-Clientip
X-Srcache-Store-Status
X-Wikidot-Backend
V-Age
X-NC
Server-Id
N-Cache
Proxy-Connection
RNT-Machine
Tracecode
Ohc-File-Size
RNT-Time
True-Client-Country-4JS
ENV
XM
X-VG-WebCache
X-CDN-Cache-Status
X-LiteSpeed-Cache-Control
X-TraceId
X-ServedByHost
X-Shop-Environment
X-Forwarded-Path
X-Bl-Debug
X-Orig-Expires
X-Tenant
Epwk-X-Cache
X-Ha-Backend
Ngx
X-B3-Trace-ID
X-MP-GENERATED-AT
Geoip-Latitude
X-Hyper-Cache
WZWS-RAY
X-Cdn-Forward
Yjs-Id
X-B3-Parentspanid
X-M-Log
X-M-Reqid
X-Dw-Trace-Id
Content-Style-Type
X-Via-PopN
X-B3-ParentSpanId
X-Amz-Meta-Opti
Inserted-Into-Cache-At
User-Agent
X-App-Name
X-Cdn-Diag
X-Qnm-Cache
X-MiniProfiler-Ids
X-Policy
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-Serial
X-Swift-Error
Ec-Rule-Version
X-Fastly-Backend-Reqs
X-Via-PopV
X-Vgn-Hpd-Reason
X-Via-PopH
Content-Script-Type
X-Lb-Nocache
X-Lsadc-Cache
X-Wp-Cf-Super-Cache
X-Wp-Cf-Super-Cache-Cache-Control
X-F-Status
X-TT-LOGID
X-Th-Server
X-LiteSpeed-Tag
X-Stale
Expiry
Req-ID
X-Ramcache
Pramga
X-Connection-Hash
X-Mid-Debug-Cache-Disk
X-Mid-Debug-Cache-Key
X-IPS-Cached-Response
Warning
Cneonction
My-App
X-Cache-Ngx
X-Request-URL
X-Snapshot-Date
X-UP
MIME-Version