Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Accept-Ranges
Link
Cf-Request-Id
CF-Cache-Status
CF-RAY
ETag
X-XSS-Protection
Pragma
Expect-CT
X-Powered-By
Via
X-Cache
Age
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
P3P
X-Served-By
Alt-Svc
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Varnish
X-Xss-Protection
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
X-AspNet-Version
X-Runtime
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
P3p
X-Cache-Status
X-Generator
X-Check
X-Cacheable
Timing-Allow-Origin
X-Request-ID
X-Iinfo
X-FRAME-OPTIONS
Feature-Policy
X-Content-Security-Policy
X-Envoy-Upstream-Service-Time
Content-Encoding
Status
X-Drupal-Dynamic-Cache
Access-Control-Expose-Headers
X-CDN
X-AspNetMvc-Version
X-CONTENT-TYPE-OPTIONS
Upgrade
X-Via
X-Akamai-Path-Stats
X-XSS-PROTECTION
Access-Control-Max-Age
CF-Ray
Server-Timing
X-Ws-Request-Id
X-Cache-Group
X-Turbo-Charged-By
Keep-Alive
Request-Context
X-Backend
X-Dns-Prefetch-Control
EagleId
X-Robots-Tag
X-Age
X-Server
X-Amz-Request-Id
X-AH-Environment
X-UA-Device
X-Amz-Id-2
Host-Header
X-Proxy-Cache
X-Hacker
X-Rq
Grace
X-Server-Powered-By
X-Varnish-Cache
X-Swift-CacheTime
X-Swift-SaveTime
X-Vhost
Ali-Swift-Global-Savetime
X-Dispatcher
X-Amz-Version-Id
X-LiteSpeed-Cache
Allow
EagleEye-TraceId
X-Ua-Compatible
X-Nginx-Cache-Status
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-OneAgent-JS-Injection
CONTENT-SECURITY-POLICY
X-WebKit-CSP
X-Device
X-Cache-Spec
Cf-Railgun
X-Host
X-Page-Speed
Cf-Edge-Cache
X-Node
X-Server-Id
X-Aws-Lambda-Call-Status
X-Pingback
Surrogate-Control
Request-Id
X-CST
X-Backend-Server
X-Readtime
X-Akam-SW-Version
Accept-CH
X-Cache-Lookup
X-Response-Time
X-HW
X-Application-Context
Accept-CH-Lifetime
Xkey
Content-Location
Rating
X-Cloud-Trace-Context
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Trace
X-Url
X-Country
X-Ruxit-JS-Agent
Fastly-Restarts
Accept-Ch
Accept-Ch-Lifetime
X-MS-InvokeApp
X-Rack-Cache
X-Clacks-Overhead
X-Mod-Pagespeed
X-Vname
X-PC
X-TtlSet
X-Amz-Server-Side-Encryption
RTSS
X-VARITI-CCR
Edge-Control
X-FastCGI-Cache
X-Varnish-TTL
X-ESI
X-Server-Name
X-Edge
Cache-Tag
X-B3-TraceId
X-Content-Type
X-Vcap-Request-Id
X-Cdn-Fetch
X-Use-Magma
X-Kinja
X-Kinja-Build
X-Exp-Id
X-Kinja-Server
X-GoogleNews-Bot
X-Kinja-Revision
X-Exp-Variant
X-Amz-Rid
X-Dw-Request-Base-Id
Public-Key-Pins
X-D2id
X-Px
X-Cnection
X-ASPNET-VERSION
X-Ser
X-Content-Security-Policy-Report-Only
X-Navigation-Version
X-Powered-By-Plesk
Display
Pagespeed
X-Middleton-Display
X-Sol
X-Abt-Application-Version
X-Ac
Verso
X-Client-IP
X-Element-Page-Cache
X-Version
X-RateLimit-Remaining
X-Ttl
Arr-Disable-Session-Affinity
X-Cache-TTL
X-GitHub-Request-Id
X-Country-Code
Service-Worker-Allowed
X-NF-Request-ID
X-Litespeed-Cache
X-Middleton-Response
X-Cached
Response
X-Goog-Hash
SPIisLatency
SPRequestDuration
Access-Control-Request-Method
X-Kinsta-Cache
X-SharePointHealthScore
X-Edge-Location-Klb
SPRequestGuid
X-Powered-CMS
X-Server-Lifecycle-Phase
X-Instrumentation
X-Kraken-Loop-Name
AR-Request-ID
X-Correlation-Id
AR-SID
AR-CACHE
X-Upstream
AR-ATIME
AR-PoweredBy
X-WebKit-CSP-Report-Only
X-LLID
Edge-Cache-Tag
X-Forwarded-For
X-NWS-LOG-UUID
Content-MD5
Nginx-Cache
X-Id
X-TTL
X-Cache-Key
X-RateLimit-Limit
X-ECACHE
X-Shield-Request-Id
TCN
X-MSEdge-Ref
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Recruiting
S
X-T
Mrf-Cache-Status
MRF-Tech
X-Daa-Tunnel
X-DataDome
X-Content-Digest
X-B3-TraceId-Primal
X-Mg-S
X-HP-Trace-Id
X-Ruxit-Js-Agent
X-HP-Webp
X-Jurisdiction
X-Mcache
X-SRCache-Fetch-Status
X-SRCache-Store-Status
TP-L2-Cache
TP-Cache
X-Grace
X-Accel-Expires
X-Ua-Device
X-HS-Cache-Config
X-Frontend
X-HS-Combine-CSS
X-HS-Hub-Id
X-Protected-By
Front-End-Https
X-HS-Content-Id
X-DynaTrace
Filters
X-Yandex-Sdch-Disable
X-Request-Received
X-Request-Processing-Time
MicrosoftSharePointTeamServices
Server-Node
X-Ezoic-Cdn
X-Content
X-Ua-Browser
X-Ab
X-Distributor
X-Origin-Server
X-PressLabs-Stats
X-Hits
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-Server-ID
Fastcgi-Cache
X-LB-Cache
X-Geo-Country
MS-Author-Via
X-Microsite
X-Request-Handler-Origin-Region
Charset
X-Cache-Age
Host
X-Amzn-Trace-Id
X-Tt-Trace-Host
X-Mid
X-Tt-Trace-Tag
X-Git-Hash
X-F-Cache
Cleartype
X-Page-Id
Cross-Origin-Opener-Policy
X-Forwarded-Proto
Cache-Status
Realpath
X-B3-Sampled
X-Seen-By
X-Debug-Info
X-Webkit-Csp
X-Fastly-Request-Id
X-Az
X-Activity-Id
X-AppVersion
Permissions-Policy
Access-Control-Allow-Method
X-DIS-Request-ID
X-Nginx-Upstream-Cache-Status
Accept-Charset
X-Www-Served-By
Filterid
X-Ratelimit-Reset
X-Webkit-CSP
ServerID
X-Content-Options
Cache-Tags
X-Varnish-Age
X-FB-Debug
X-Midtier
X-Cluster-Name
X-Rid
Pinterest-Version
X-Aspnetmvc-Version
Retry-After
X-Pinterest-Rid
Pinterest-Generated-By
X-Type
Server-Name
X-App-Environment
X-Varnish-Grace
X-Varnish-Backend
X-User-Agent
X-Request-Guid
X-Aspnet-Duration-Ms
X-Flags
X-Providence-Cookie
X-Is-Crawler
Country
X-Amz-Meta-S3cmd-Attrs
X-Route-Name
X-B
X-Language
X-Whom
X-TT
Viewport
X-B-Cache
X-Tb
X-Signature
X-Wix-Request-Id
X-Origin-Cache
X-Drupal-Cache-Tags
X-VCache
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-Goog-Metageneration
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
DC
X-GUploader-UploadID
Paypal-Debug-Id
X-Debug
Fastcgi-Useragent
Node
X-Upgrade-Enabled
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-NWS-UUID-VERIFY
X-Load-Cache
X-Logged-In
X-Oracle-Dms-Ecid
Payment
X-Oracle-Dms-Rid
X-XRDS-LOCATION
X-Amz-Replication-Status
Protected
X-Cache-NGX
X-Mobile-URL
X-N
Surrogate-Key
X-Cache-Control
Count-Hit
Amp-Access-Control-Allow-Source-Origin
Alternate-Protocol
WPO-Cache-Status
WPO-Cache-Message
X-NGENIX-Cache
X-Restarts
X-Contextid
Healthy
X-Node-Name
X-Mobile
X-XRDS-Location
X-Via-JSL
X-Browser-Type
X-Proxy
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Original-Request-Id
X-ECache
Content-Disposition
SD-X-WS
X-Response-Served-From
X-FW-Type
X-G
X-FW-Hash
Url
Refresh
X-FW-Dynamic
X-Jobs
X-FW-Server
X-FW-Serve
X-FW-Static
X-Page-View
X-Servername
X-Real-IP
X-Revision
X-UUID
X-Cache-Time
Uber-Trace-Id
X-Akamai-Request-ID2
X-Adobe-Loc
X-Adobe-Content
X-Cache-TTL-Remaining
X-Debug-IsPreview
X-Framework
X-Is-Bot
X-Device-Type
X-Zen-Fury
X-Debug-IsConnected
X-Cacheable-TTL
X-MCACHE
X-Mg-Request-UUID
Akamai-GRN
X-Rendered-As
VIX-Pulpo-Node
X-Http-Reason
VIX-Pulpo-Upstream-Status
X-Varnish-Server
X-Proxy-Cache-Status
Access-Control-Request-Headers
X-Yottaa-Optimizations
X-Template
X-Cache-Grace
X-Yottaa-Metrics
X-Drupal-Cache-Contexts
Frame-Options
X-Hostname
X-Instance
NGB
X-Environment-Context
X-L-Path
Referer-Policy
Version
X-HTML-Minification-Powered-By
X-IPLB-Instance
X-EdgeConnect-Cache-Status
X-Source
Countrycode
X-Ratelimit-Remaining
Ms-Operation-Id
X-RTag
MS-CV
Liferay-Portal
Accept-Language
X-Fastly-Request-ID
X-B3-Traceid
X-NYM-Debug-Backend
X-Trace-Id
X-App-Server
X-Cache-Rule
X-Oneagent-Js-Injection
X-Datadome
X-Cache-Expired-At
X-Cache-Hit
Cross-Origin-Window-Policy
X-Hosted-By
Backend
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Nginx-Cache
From-Origin
X-Tumblr-Pixel-1
X-Tumblr-User
X-IPS-LoggedIn
X-Vgn-Hpd-Reason
X-Unique-Id
X-RemovedCookies
X-ProcessESI
X-Status
X-RN-RSRV
X-APP-VERSION
Load-Balancing
X-UPSTREAM-Address
Meta-Geo
X-FW-Version
WP-Super-Cache
Section-Io-Cache
X-No-Session
Content-Secure-Policy
X-PCL
X-FB-TRIP-ID
X-Cache-Server
X-COUNTRY
X-Content-Powered-By
X-OCL
X-PHP-Backend
X-PHP-Host
X-Sql-Count
X-Via-Fastly
X-VWS-Id
X-UA-Device-Type
X-Sql-Duration-Ms
X-Region
X-Redis-Cache
X-LJ-Flow-ID
S-Rt
CF-IPCountry
Apigw-Requestid
Upgrade-Insecure-Requests
X-Akamai-Edgescape
X-Content-Age
X-Labrador-Cache-Channel
X-Cache-Enabled
X-AWS-Id
X-Origin-Date
X-AOL-HN
X-PERF
X-Human
X-Forwarded-Host
X-Format
X-Ratelimit-Limit
X-Platform-Server
X-Say-Cacheable
X-Request-Time
X-ProxyCache-Status
X-ProxyCache-Key
X-Debug-Cache
X-Cms-Context
X-Access
Mn-Server-Ip
Locale
Eomportal-Instance
X-Adobe-Source
X-ApacheServer
X-Cache-Tags
X-BYPASS-REASON
X-Be
X-Say-TTL
X-SayCDN-TTL
Webcakes-App-Name
TWC-Privacy
TWC-Locale-Group
TWC-GeoIP-Country
Webcakes-App-Version
Webcakes-Region
X-Varnish-Cache-Hits
X-Origin-Hint
X-Cluster-Node
TWC-Device-Class
TWC-Connection-Speed
X-Urbn-Context-Path
X-Storage
X-Site-Version
X-Section
X-Urbn-Site-Id
X-Uri
Property-Id
X-Xfnlog-Site
X-VC-Cache
X-Sorting-Hat-ShopId
TWC-GeoIP-LatLong
X-ShopId
X-Sorting-Hat-PodId
X-Alternate-Cache-Key
X-Shopify-Stage
X-ShardId
X-GeoCode
X-GeoCountry
X-Hl-Ver
X-JoinUs
X-GG-Cache-Date
X-Detected-As
X-Cache-Host
X-Locale
Azure-Version
X-Cache-Type
X-Edge-Location
X-Nginx-Cache-Key
Azure-SlotName
X-SaId
X-ServerID
X-Tid
X-Storefront-Renderer-Rendered
Azure-SiteName
X-Varnishpool
X-Web-Node
Azure-InstanceId
X-Server-W
Azure-RegionName
Fastly-SSL
X-Backend-Name
X-Proto
X-Mode
X-Handled-By
X-Generation-Time
X-App-Version
X-Generated-By
X-Ua
Selected-Fe
X-Proxy-Build
X-Timing-Wait
X-Zipkin-Id
X-Proxied
X-NewRelic-App-Data
X-Routing-Service
X-Dc
X-Extlb
ServedBy
CDN-EdgeStorageId
CDN-CachedAt
CDN-Uid
CDN-RequestId
CDN-RequestCountryCode
CDN-PullZone
CDN-Cache
Fastly-Drupal-Html
Webserver
X-IPLB-Request-ID
Web-Mar-Node
Ec-Rule-Version
Onion-Location
X-Magnolia-Registration
X-CDN-Forward
Cache-Tv-Group
X-LSADC-Cache
X-GEO
X-Varnish-Hostname
X-Cache-Action
X-Tt-Logid
Cache-Hits
X-Cached-By
X-Envoy-Decorator-Operation
SID
X-Cache-Operation
X-Air-Trace-Id
X-Air-Source
Mime-Version
X-Air-Hostname
X-Cache-Remote
X-Hyper-Cache
X-Cluster
X-Varnish-Hits
X-SRV
SRV
X-Rewrite-Enabled
X-Origin-CC
X-Soup
Xet-Cookie
X-Origin-TTL
LB
X-Rule
DB-Nickname
X-Cdn
Cache
X-Fastcgi-Cache
X-Varnish-Ttl
Server-Info
Source
Xserver
X-Parallel-Accel
X-Microcachable
X-CSRF-Token
X-Accel-Buffering
X-Reqid
X-TA-CDN-Provider
Country-Code
X-Via-NSCOPI
X-Time
X-Pubstack
X-MP-GENERATED-AT
X-Tumblr-Pixel-2
X-Buckets
X-Xrds-Location
X-Skip-Cache
X-Cache-Status-Check
Decoy-Debug-Key
Decoy-Debug-Status
Decoy-Debug-TTL
X-Newrelic-Synthetics
X-Origin-Response-Time
X-Request-Host
X-Endurance-Cache-Level
DynaTrace
Rendered-Blocks
X-Processor
X-ARC
X-PAYTM-SRV-ID
X-B-Cookie
X-Tumblr-Pixel-3
X-PBS-Appsvrname
Pramga
X-Azure-Ref
Cmsid
Cmstype
X-CF-Lambda-Version
X-CF-Lambda-Fn
Cdnsip
Candidate-Md5Url
Lang
Cdncip
X-Developer
X-Destination
X-D
X-Connection-Hash
X-Conf
Fastcgi-X-Cache-Version
Expiry
DCR-Decision-By
DCR-Processing-Time-Ms
X-Ec-Fail
X-Ec-GeoHdr
X-Hash
X-Cache-NE
X-Application
NM-Fastcgi-Cache
X-Ig-Push-State
X-NAPM-TraceId
X-BCube-Filmed-By
Odigeo-Trace-Id
Mobile-Detection-Method
Meta-Geo-Continent
X-Epic-Correlation-Id
BehaviorPad-Version
Cache-Key
X-External-Request-Id
A
MD5-Digest
X-Forwarded-Path
X-Orig-Expires
T-Server
XM
X-ScT
Xc-Version
X-Vdms-Version
X-A-Dcw
X-A
X-TIM-N
X-S-Cookie
X-Tx-Id
X-SD-PageType
X-VG-WebCache
X-A-Ccd
X-Shop-Environment
X-SplitTest
X-Vtex-Remote-Cache
X-Session-Fingerprint
X-A-Dam
X-SRCache-Key
X-Vtex-Processado-Em
X-S
X-Tenant
Host-ID
Datacenter
X-A-Dgt
Surrogated-Key
X-Vdms-Path
X-Aed
X-AK-Request-ID
X-User
X-Rojux
Sslversion
X-TrackingId
X-Amzn-RequestId
X-Amz-Apigw-Id
X-A-Wwc
X-B3-SpanId
X-TT-LOGID
X-Varnish-Beresp-Grace
X-DefElseHash
Memcached
Wxu-Next-Region
X-Fetched-On
Mail-Subject
Kp-EeAlive
Adler-Geo
X-Varnish-CookieHashed-On
X-DefHash
X-DPWN-IS-SECURE
X-V-Cache
We-Hiring
X-Device-Os
HostName
X-SVT-ORM-VERSION
X-Variation
Wxu-Next-Hostname
X-Esi-Check
X-TNCMS
Wxu-Next-Commit
X-SVT-ORM-RULES
X-Cdn-Srv
X-Varnish-CookieINHashed-On
X-SB
X-Bc-Bl
Redirect-Candidate
X-Scheme
X-Ms-Version
X-Core-Value
X-Ms-Request-Id
Platform
X-NodeID
X-Core-Mission
X-Rocket-Build-Number
X-Ad-Defer-Variation
Producers
State
X-Origin
X-Origin-Expires
X-Loop
Is-Eu
Server-Host
X-CacheTTL
X-Gzip
X-GeoIP
X-Sigma
X-CACHE-KEY
X-Geo-Header
X-Wix-Viewer-Type
Environment
X-Ckpd-Fst-Backend
X-Varnish-Remaining-TTL
X-Cache-Id
X-Irp-Debug
X-HS-Content-Campaign-Id
X-Worker
X-Sigma-Backend
X-AIR-PT
X-Block-Status
X-BBC-Edge-Cache-Status
VNS-Cache
X-Aicache-OS
X-Branch-Name
X-Cache-Bucket
X-CGP
X-Cache-Info
X-Cache-Date
X-Cdn-Origin
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-RateLimit-Remaining-Second
X-Region-Sid
X-Origin-Time
X-Request-URI
X-RateLimit-Limit-Second
X-Qloud-Router
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-Platform
X-Policy
X-Pool
X-Nyt-Route
VNS-Age
X-VServer
X-Sn-Servicetimems
X-VG-TLSProxy
X-Thinkindot-L3
X-VarnishDD-TTL
X-Slack-Backend
X-WADP-Cache
X-Amzn-Remapped-Content-Length
X-Gdpr
X-Rocket-Nginx-Serving-Static
Fastly-Backend-Name
X-Served-From
X-Planisys-CDN-Cache
X-Node-Id
X-Fastly-Cache
X-Eu-Site
X-Fmm-Version
X-Forwarded-Site
X-Gamma-Serve
X-Ec-Custom-Error
X-Dispatcher-Number
X-Datadog-Parent-Id
X-Csrf-Jwt
X-Datadog-Sampling-Priority
X-Datadog-Trace-Id
X-Developers
X-Gen-Mode
X-Generated-On
X-Loc
X-Level-Front-Cache
X-Minions-Version
X-Mvc-Supplant-Cachable
X-NCache
X-LAGOON
X-JWT-State
X-Has-Esi
X-GeoIP-City
X-HN
X-Hnp-Log
X-Is-Gdpr
X-Clara-WADP
TDXMobile
AKAMAI
L5d-Success-Class
L
HA-Ipaddr
Machine
NGX
Release
PFcat
Origin
Ha-Gx-Prefs
Vix-Hermes-Req-Id
CPC-Cache
CPC-Age
CloudFront-Viewer-Country
CDCHOST
Apple-News-Services-Request-Url
Fastly-GeoIP-CountryCode
Fastly-SWR
Apple-News-Services-Parsed-Url
Fastly-SIE
Req-Svc-Chain
N-Cache
Thinkindot-CacheControl
Apple-News-Services-Host
Ssr
Thinkindot-CacheControl-Type
Thinkindot-Control
V-Age
User-Cache-Control
Apple-News-Services-Handled
Sever-Int
Svr
Server-Hostname
Server-Ext
X-ZONE
DSUID
Traceparent
Fastcgi-Cache-TTL
X-Proxy-Upstream
X-VC
X-RCS-CacheZone
X-Optimistic-Header
X-Ftr-Request-Id
Cache-Name
X-Owner
X-R9-Blue-Green-Version
Origin-EX
Web-Mar-Region
X-Wikidot-Backend
X-WA-Info
IsBot
X-Proxy-Cache-Info
X-Viewer-Country
Cluster
X-Via-Ucdn
Origin-CC
X-Wikidot-Static-Cache
X-Micro-Cache
X-SIPLIST1
Gh-Request-Id
X-Pod-Name
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
Ohc-File-Size
X-Cache-Backend
X-Auto-Login
X-Scale
X-EC-Lua
X-Correlation-ID
Cache-Host
Ngx.Var.Host
X-CS
X-Refresh
GEO-INFO
CDN
Pics-Label
X-RateLimit-Reset
X-NC
Path
XkeyRZ
X-Httpd
X-Server-IP
X-Parent-Response-Time
X-Proxy-CacheRZ
X-LB-NoCache
Servername
Env
X-Ah-Environment
X-Mvc-Supplant-OutputCached
Lb
Ms-Author-Via
X-Tb-Optimization-Total-Bytes-Saved
X-Udemy-Cache-App-Namespace
Time
X-Cache-ASPX
X-Contensis-Viewer-Groups
X-Servedbyhost
Memory
X-Via-Popv
X-Via-Popn
X-Generated-In
X-Clientip
X-Webstats-RespID
X-From
X-Via-Poph
X-Edge-Pop
AMP-Access-Control-Allow-Source-Origin
X-Srv
X-Varnish-Authentication
X-Location
X-API-Version
X-Varnish-Beresp-TTL
X-TIME
Locid
X-S-Maxage
X-Amz-Meta-Cb-Modifiedtime
X-TraceId
Ohc-Cache-HIT
X-Dmc
X-Trace-ID
ITXSESSIONID
Arc-Country
X-Response-By
GeoIp-Country-Code
X-PX
X-Presslabs-Stats
X-Men
X-DynaTrace-JS-Agent
X-Akamai-Transformed
X-Cs
X-Old-Content-Length
True-Client-IP
X-MSEdge-Features
X-MSEdge-Flight
X-Render-Time
X-DB
X-RPS
X-DSS
X-Date
X-RSL
Client
X-RPM
X-DI
Geoip-Latitude
X-Vc
X-Accel-Expires-Debug
X-VCL-Version
X-DW
Server-ID
X-HA-Backend
X-VHOST
X-Service
X-Gateway-Request-Id
X-Fpc
X-Tec-Api-Origin
X-TRACE-ID
X-Gateway-Cache-Status
Rip
X-INCAP-ABP
X-Tec-Api-Version
C-Via
X-Tec-Api-Root
X-DC
X-Gateway-Skip-Cache
X-Gateway-Cache-Key
X-URL
X-Zone
X-GeoIP-Country-Code
Tube-Got-Results
Click-Count-Error
Click-Count-Action-Start
Tube-Got-Eval
Hostname
X-FireWall-Port
Tube-Get-Contents
Tube-Return
X-GeoIP-Region-Code
X-M-Reqid
On-Server
Esi-Enabled
X-M-Log
X-Qnm-Cache
X-TX-ID
FSS-Cache
NtCoent-Length
X-Cache-Debug
Fusion-Deployment-Id
Fusion-Source
Fusion-Template-Id
Fusion-Content-Id
Fusion-Component-Id
X-B3-Spanid
Fusion-Content-Source
Powered-By
Srv
HIT
X-Api-Version
X-Webkit-Csp-Report-Only
X-Edge-Origin-Shield-Region
X-Edge-Origin-Shield-Bytes
CacheControlHeader
Test
X-Proxy-Cache-Hk
OT-Force-Account-Verify
X-Alfa-Service
True-Client-Country-4JS
X-Action
Tcn
X-FPC
X-TH-Server
X-NGINX-Cache
Cdn
X-Backend-TTL
X-Vcl-Version
X-CSRF-TOKEN
X-Cdn-Request-ID
X-HS-Status
Server-Id
X-Traceid
X-Beluga-Cache-Status
X-Beluga-Response-Time
X-Beluga-Node
User-Agent
GeoIP-Latitude
X-Beluga-Status
X-Beluga-Trace
Edge-Cache
X-Check-Cacheable
GeoIP-Country-Code
Geo-Info
X-Beluga-Record
X-Pass-Why
X-Akamai-Pragma-Client-IP
Resin-Trace
X-Req
X-Varnish-Beresp-Ttl
DT-Hot-News
X-Origin-Upstream-Status
X-Via-PopN
X-Ha-Backend
My-App
X-Via-PopV
Uri
X-App
Server-Ttl
X-APP
X-Via-PopH
Proxy-Connection
Srvid
X-Cdn-Forward
X-CLOUD-TRACE-CONTEXT
WebServer
X-Thanos
X-ServedByHost
M-TraceId
Cf-Int-Pingora-Origin-Digest
X-Bip
MIME-Version
Sid
True-Client-Ip
Epwk-X-Cache
X-Request-Start
X-Hcs-Proxy-Type
X-CCDN-CacheTTL
X-CCDN-Origin-Time
X-Up
ENV
X-Edge-POP
X-Fastly-Backend-Reqs
X-Lb-Nocache
X-LB-ID
X-Backend-Host
X-Esi
X-Provided-By
Warning
PICS-Label
Magicmarker
ServerName
X-B3-Traceid-Primal
X-Geo
X-Li-Fabric
X-Li-Pop
XServer
X-LI-UUID
X-LI-Proto
X-HostName
X-ElasticPress-Query
X-Vercel-Cache
X-HITS
X-Webkit-CSP-Report-Only
X-Newrelic-App-Data
X-UnsetCookies
CF-Cached-On
Inserted-Into-Cache-At
Section-Io-Id
Section-Io-Origin-Status
X-Nc
X-Serial
Canary
X-Dw-Trace-Id
X-Varnish-Beresp-Status
X-CMSURLCustom
X-RAMCache
X-Akamai-Request-ID
X-Vercel-Id
Section-Origin-Responded
Section-Io-Origin-Time-Seconds
X-CF-Powered-By
X-Fetch-By
Dt-Hot-News
X-LiteSpeed-Cache-Control
Fastly-Drupal-HTML
X-ND-Cache
X-IN-APIGATEWAY
D-Url-Rewrites
WZWS-RAY
X-Iplb-Instance
X-Yottaa-OS
X-Request-Url
X-Time-Microsecs
X-Cc-Via
X-Iplb-Request-Id
X-Vcache
X-IN-APIGATEWAYSSL
Cdn-Requestid
Cdn-Uid
X-Air-Pt
X-UA
Cdn-Requestcountrycode
Cdn-Cache
Cdn-Pullzone
Wp-Super-Cache
Cdn-Edgestorageid
Cdn-Cachedat
Servedby
Hit
X-WP-CF-Super-Cache-Active
X-LiteSpeed-Tag
X-Th-Server
X-CUA
X-Azure-Ref-OriginShield
X-Snapshot-Date
CountryCode
X-Back
Content-Script-Type
X-MiniProfiler-Ids
X-BBC-Origin-Response-Status
X-Fastly-Cache-Hits
X-Wp-Cf-Super-Cache
Fastcgi-Cache-Ttl
Content-Style-Type
X-Request-URL
X-Wp-Cf-Super-Cache-Cache-Control
X-Storefront-Renderer-Verified
DataCenter
X-Dist-Code
Cf-Device-Type
X-Release
Vha6-Origin