Threat Level: green Handler on Duty: Guy Bruneau

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Accept-Ranges
Expect-CT
X-XSS-Protection
CF-RAY
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
P3P
X-Xss-Protection
X-Served-By
X-Download-Options
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Request-ID
Access-Control-Allow-Credentials
X-Request-Id
X-FRAME-OPTIONS
CF-Ray
X-Permitted-Cross-Domain-Policies
X-AspNet-Version
Alt-Svc
Content-Security-Policy-Report-Only
X-DNS-Prefetch-Control
X-Runtime
X-Drupal-Cache
X-Check
X-Cache-Status
X-Generator
X-Cacheable
P3p
Timing-Allow-Origin
X-Iinfo
X-Envoy-Upstream-Service-Time
X-Content-Security-Policy
X-Drupal-Dynamic-Cache
Feature-Policy
Content-Encoding
Upgrade
Access-Control-Expose-Headers
Status
X-AspNetMvc-Version
X-CDN
Access-Control-Max-Age
X-Via
Server-Timing
X-UA-Device
X-Robots-Tag
Request-Context
X-Turbo-Charged-By
X-Cache-Group
X-Amz-Request-Id
EagleId
X-Amz-Id-2
X-Backend
Keep-Alive
X-AH-Environment
X-Proxy-Cache
X-Ws-Request-Id
X-Server
X-Age
Host-Header
X-Hacker
X-Ua-Compatible
Cf-Edge-Cache
X-Vhost
X-Server-Powered-By
X-Rq
Allow
X-Varnish-Cache
X-Dispatcher
Grace
X-Amz-Version-Id
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-LiteSpeed-Cache
X-WebKit-CSP
X-OneAgent-JS-Injection
Accept-CH
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
Cf-Apo-Via
X-Device
X-Page-Speed
Cf-Railgun
X-Aws-Lambda-Call-Status
X-Server-Id
X-Host
X-Node
X-Pingback
X-Cache-Spec
X-Nginx-Cache-Status
X-Akam-SW-Version
Surrogate-Control
X-Dns-Prefetch-Control
X-Backend-Server
EagleEye-TraceId
X-Cache-Lookup
Request-Id
X-Readtime
X-HW
X-Ruxit-JS-Agent
X-Cloud-Trace-Context
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Content-Security-Policy-Report-Only
X-Trace
X-Application-Context
X-Response-Time
Accept-CH-Lifetime
Permissions-Policy
X-CST
X-Mod-Pagespeed
X-Nginx-Upstream-Cache-Status
Fastly-Restarts
X-Edge
Accept-Ch-Lifetime
X-WebKit-CSP-Report-Only
Content-Location
X-Country
X-Content-Type
X-Mcache
X-ECACHE
Rating
X-Clacks-Overhead
X-Url
X-MS-InvokeApp
X-Vname
X-PC
X-TtlSet
X-Midtier
X-Amz-Server-Side-Encryption
X-VARITI-CCR
RTSS
Cache-Tag
X-B3-TraceId
X-Vcap-Request-Id
X-Varnish-TTL
X-Element-Page-Cache
X-D2id
Origin-Trial
X-Ac
Verso
X-Server-Name
X-Cdn-Fetch
X-Kinja
X-GoogleNews-Bot
X-Kinja-Build
X-Kinja-Revision
X-Use-Magma
X-Exp-Variant
X-Kinja-Server
X-Exp-Id
X-Rack-Cache
X-Litespeed-Cache
X-Cnection
X-Cache-TTL
X-Powered-By-Plesk
Service-Worker-Allowed
X-ESI
Xkey
X-Navigation-Version
X-GitHub-Request-Id
X-Abt-Application-Version
X-NWS-LOG-UUID
X-Ttl
Edge-Control
X-Amz-Rid
SPRequestGuid
X-SharePointHealthScore
X-Client-IP
X-Cached
X-Fastcgi-Cache
X-Px
X-Mg-S
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Instrumentation
X-Browser-Type
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
Arr-Disable-Session-Affinity
X-Upstream
SPRequestDuration
SPIisLatency
X-Correlation-Id
Pagespeed
X-Cache-Key
Display
X-Sol
X-Middleton-Display
Content-MD5
X-Dw-Request-Base-Id
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-NF-Request-ID
Access-Control-Request-Method
Edge-Cache-Tag
X-Goog-Hash
X-XRDS-Location
X-Daa-Tunnel
Front-End-Https
X-Country-Code
Public-Key-Pins
X-Version
X-Forwarded-For
AR-SID
AR-ATIME
X-Powered-CMS
AR-Request-ID
AR-PoweredBy
AR-CACHE
X-Id
X-MSEdge-Ref
X-Recruiting
TCN
X-T
X-HP-Trace-Id
X-Jurisdiction
X-HP-Webp
X-RateLimit-Remaining
X-Content-Digest
X-Accel-Expires
Response
X-Middleton-Response
Mrf-Cache-Status
X-B3-TraceId-Primal
MRF-Tech
X-Shield-Request-Id
X-Ser
TP-L2-Cache
TP-Cache
Nginx-Cache
X-Amzn-Trace-Id
X-Hits
X-Fastly-Request-ID
S
X-Ruxit-Js-Agent
X-Request-Received
X-Request-Processing-Time
X-HS-Hub-Id
X-HS-Combine-CSS
X-HS-Cache-Config
X-HS-Content-Id
Server-Node
X-Distributor
X-Edge-Location-Klb
X-Kinsta-Cache
Cache-Status
X-Ratelimit-Limit
X-Grace
Cache-Tags
Fastcgi-Cache
MicrosoftSharePointTeamServices
Alternate-Protocol
Server-Name
X-DataDome
X-Protected-By
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-Ezoic-Cdn
X-DIS-Request-ID
X-Origin-Server
X-Ratelimit-Remaining
X-Geo-Country
X-Ratelimit-Reset
X-Ua-Browser
X-LB-Cache
X-Microsite
X-Request-Handler-Origin-Region
X-Frontend
X-Rid
X-Debug-Info
X-Varnish-Backend
X-Logged-In
Cross-Origin-Opener-Policy
Healthy
Cleartype
X-Git-Hash
X-Www-Served-By
Filterid
Payment
X-Forwarded-Proto
X-FB-Debug
X-NGENIX-Cache
X-TTL
X-Load-Cache
X-Page-Id
Charset
X-B3-Sampled
Content-Disposition
X-Webkit-Csp
X-VCache
X-ASPNET-VERSION
X-LLID
X-Cluster-Name
DC
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Oracle-Dms-Ecid
X-Hostname
MS-Author-Via
X-Oracle-Dms-Rid
X-Origin-Cache
X-Oneagent-Js-Injection
X-PressLabs-Stats
X-GUploader-UploadID
X-Goog-Metageneration
X-Upgrade-Enabled
Retry-After
Accept-Charset
X-Proxy
Access-Control-Allow-Method
X-F-Cache
X-Az
Cross-Origin-Resource-Policy
X-AppVersion
X-Activity-Id
X-Type
X-B-Cache
X-Signature
X-Flags
X-Contextid
Accept-Ch
X-Revision
X-Providence-Cookie
X-Request-Guid
X-Route-Name
X-Hosted-By
X-Is-Crawler
X-Varnish-Server
X-Amz-Replication-Status
X-Amz-Meta-S3cmd-Attrs
Paypal-Debug-Id
Viewport
X-Aspnet-Duration-Ms
X-Azure-Ref
X-B
X-TT
X-Whom
X-Wix-Request-Id
X-Seen-By
Amp-Access-Control-Allow-Source-Origin
X-Fb-Rlafr
X-App-Environment
Referer-Policy
X-FastCGI-Cache
X-DynaTrace
Surrogate-Key
X-Source
Count-Hit
Realpath
X-Aspnetmvc-Version
X-Akamai-Edgescape
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Mobile
X-RateLimit-Limit
X-App-Server
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-Goog-Storage-Class
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
Host
X-Cache-Control
X-EdgeConnect-Cache-Status
X-N
X-Tumblr-Pixel-0
X-Cache-Rule
X-HTML-Minification-Powered-By
X-Tumblr-Pixel
X-Tumblr-Pixel-1
X-Response-Served-From
X-Varnish-Grace
X-Original-Request-Id
X-Tumblr-User
X-Varnish-Age
Version
X-UUID
Access-Control-Request-Headers
X-Cache-Time
VIX-Pulpo-Upstream-Status
X-Magnolia-Registration
Refresh
Section-Io-Cache
SD-X-WS
VIX-Pulpo-Node
X-Status
X-Page-View
X-L-Path
Akamai-GRN
X-FW-Version
X-Cache-Expired-At
X-Cache-Status-Check
X-Content-Powered-By
X-Cache-Grace
X-FW-Server
X-FW-Static
X-Environment-Context
X-Envoy-Decorator-Operation
X-RTag
X-FW-Hash
X-FW-Dynamic
X-Adobe-Loc
X-Adobe-Content
Protected
X-FW-Type
X-FW-Serve
Ms-Operation-Id
MS-CV
X-Rule
NGB
X-NYM-Debug-Backend
X-Is-Bot
X-Instance
X-G
X-Cacheable-TTL
X-Framework
X-ProcessESI
X-Servername
X-RemovedCookies
X-Rendered-As
X-Jobs
X-Device-Type
X-Akamai-Request-ID2
X-Http-Reason
GEO-INFO
Url
X-Debug-IsPreview
X-Debug-IsConnected
X-Backend-Name
X-User-Agent
X-Nginx-Cache
X-CDN-Forward
X-B3-Traceid
X-Language
X-Template
X-Newrelic-App-Data
SRV
X-Drupal-Cache-Contexts
X-Drupal-Cache-Tags
X-Cache-Age
X-Yottaa-Optimizations
CDN-RequestId
X-Yottaa-Metrics
X-Tb
X-Cache-Hit
From-Origin
X-Pinterest-Rid
Pinterest-Generated-By
Pinterest-Version
Country
WPO-Cache-Status
X-Region
WPO-Cache-Message
X-Trace-Id
X-Tt-Logid
Accept-Language
X-Node-Name
Front
X-URL
X-Amzn-RequestId
Fastly-Drupal-HTML
X-Amz-Apigw-Id
X-Real-IP
X-VC-Cache
Backend
Uber-Trace-Id
X-Content-Options
X-Mode
X-TIME
Fastly-SIE
Fastly-SWR
Content-Secure-Policy
X-Cache-Operation
X-Unique-Id
X-DynaTrace-JS-Agent
X-COUNTRY
X-Rewrite-Enabled
X-RN-RSRV
Filters
X-Tumblr-Pixel-2
Meta-Geo
X-UPSTREAM-Address
X-Generation-Time
Webserver
Azure-InstanceId
X-Web-Node
X-IPS-LoggedIn
CF-IPCountry
X-Cache-Server
X-Cache-TTL-Remaining
X-Format
X-Proxy-Cache-Info
X-Amzn-Remapped-Content-Length
X-Access
Azure-SlotName
Azure-Version
Onion-Location
X-Section
Azure-SiteName
Azure-RegionName
X-Rocket-Nginx-Serving-Static
X-Ua
X-Say-TTL
X-SRV
X-Proxy-Cache-Status
X-Sucuri-Cache
X-Cms-Context
X-Cache-Host
X-Say-Cacheable
X-Sucuri-ID
X-Zen-Fury
X-Cache-Action
X-Sql-Duration-Ms
X-Adobe-Source
X-Reqid
Apigw-Requestid
X-SayCDN-TTL
X-Debug
X-Sql-Count
Webcakes-App-Name
Web-Mar-Node
TWC-Privacy
TWC-Connection-Speed
X-Origin-Hint
CDN-EdgeStorageId
X-GeoCountry
TWC-GeoIP-LatLong
X-GeoCode
TWC-GeoIP-Country
TWC-Device-Class
ServerID
S-Rt
X-IPLB-Instance
X-IPLB-Request-ID
CDN-PullZone
CDN-CachedAt
CDN-RequestCountryCode
CDN-Uid
Cross-Origin-Window-Policy
TWC-Locale-Group
CDN-Cache
Webcakes-App-Version
X-ProxyCache-Key
X-ProxyCache-Status
Property-Id
X-Content-Age
X-VWS-Id
X-R9-Blue-Green-Version
X-Server-W
X-Via-Fastly
X-Edge-Location
X-Varnish-Beresp-Grace
X-Soup
X-Skip-Cache
X-Proto
X-PHP-Host
X-LJ-Flow-ID
X-Locale
X-BYPASS-REASON
Node
X-Labrador-Cache-Channel
Webcakes-Region
X-Ms-Request-Id
X-Forwarded-Host
X-Cluster
X-PHP-Backend
X-UA-Device-Type
X-AWS-Id
X-Ms-Version
X-Detected-As
X-Xfnlog-Site
X-Urbn-Site-Id
X-Urbn-Context-Path
X-Cluster-Node
X-SaId
X-Proxied
X-Site-Version
X-Routing-Service
X-No-Session
X-Handled-By
X-Zipkin-Id
X-CACHE-AGE
Cache-Name
Locale
X-Extlb
X-LSADC-Cache
X-LAGOON
X-JoinUs
Mn-Server-Ip
X-Time
Mime-Version
WP-Super-Cache
Cache-Hits
X-Fastly-Request-Id
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
Fastcgi-Useragent
DB-Nickname
Liferay-Portal
X-Hl-Ver
X-FB-TRIP-ID
X-Tec-Api-Root
X-Tec-Api-Version
X-Proxy-Build
Xserver
X-Tec-Api-Origin
X-Timing-Wait
Selected-Fe
X-Request-Time
X-Tumblr-Pixel-3
ServedBy
X-Redis-Cache
X-Times
X-Cache-Debug
X-XRDS-LOCATION
X-Air-Trace-Id
X-Air-Hostname
X-Air-Source
Upgrade-Insecure-Requests
X-Loop
X-TNCMS
X-Optimistic-Header
Source
X-Origin-Date
X-GEO
X-Generated-By
X-NWS-UUID-VERIFY
X-Mg-Request-UUID
X-Presslabs-Stats
X-Varnish-Hits
X-Buckets
X-Uri
X-Akamai-Transformed
X-Director
Countrycode
X-Varnish-Beresp-Ttl
X-Tid
X-Pass-Why
CF-Cached-On
X-Cdn
X-Storage
X-Tx-Id
X-TA-CDN-Provider
Xet-Cookie
Frame-Options
X-ARC
X-Origin-TTL
X-Origin-CC
X-DC
X-FireWall-Port
X-Newrelic-Synthetics
X-Service
X-Varnish-Cache-Hits
X-ECache
X-Sorting-Hat-ShopId
X-ShardId
X-App-Version
X-Sorting-Hat-PodId
X-Shopify-Stage
X-Esi
X-Alternate-Cache-Key
X-Storefront-Renderer-Rendered
X-ShopId
X-Trace-ID
SID
X-Varnish-Hostname
X-Datadog-Parent-Id
X-B3-Spanid
X-Datadog-Trace-Id
Environment
X-Datadog-Sampled
X-Endurance-Cache-Level
X-Datadog-Sampling-Priority
X-Request-Host
Cache-Tv-Group
T-Server
Thinkindot-Control
Thinkindot-CacheControl
X-A
Req-Svc-Chain
Sslversion
Surrogated-Key
Rendered-Blocks
TDXMobile
MD5-Digest
DCR-Processing-Time-Ms
X-A-Ccd
X-ServerID
DCR-Decision-By
A
Candidate-Md5Url
Gannett-Cam-Experience-Id
Host-ID
Odigeo-Trace-Id
Origin
Ngx.Var.Host
Meta-Geo-Continent
Lang
BehaviorPad-Version
Redirect-Candidate
X-CMSURLCustom
X-Platform-Router
X-Processor
X-Rojux
X-S
X-Platform-Processor
X-Platform-Cluster
X-Loc
X-Mobile-URL
X-Nyt-Route
X-Origin-Time
X-S-Cookie
X-S-Maxage
X-Vdms-Version
X-VG-TLSProxy
X-We-Are-Hiring
Xc-Version
X-Vdms-Path
X-TIM-N
X-ScT
X-SRCache-Key
X-Thinkindot-L3
X-INCAP-ABP
X-Gdpr
X-B-Cookie
X-BBC-Edge-Cache-Status
X-Bc-Bl
X-BCube-Filmed-By
X-Application
X-Aed
X-A-Dcw
X-A-Dgt
X-A-Wwc
X-Cache-Info
X-Cache-NE
X-Ec-GeoHdr
X-Epic-Correlation-Id
X-External-Request-Id
X-Frame-Option
X-Ec-Fail
X-Developer
X-Core-Value
X-D
X-Destination
X-A-Dam
Thinkindot-CacheControl-Type
Server-Info
Tube-Get-Contents
X-SD-PageType
X-Served-From
X-Sigma-Backend
X-Sigma
Tube-Got-Eval
Tube-Return
X-SB
X-Rocket-Build-Number
WWW-Authenticate
Vix-Hermes-Req-Id
State
Tube-Got-Results
X-Geo-Header
Magicmarker
X-Varnish-Remaining-TTL
X-VServer
X-WA-Info
X-WADP-Cache
X-Varnish-CookieINHashed-On
X-Varnish-CookieHashed-On
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
Server-Host
X-Test
Release
X-Restarts
X-Req
X-Is-Gdpr
X-Developers
X-DefHash
X-DefElseHash
X-JWT-State
X-Ec-Custom-Error
X-Human
X-Has-Esi
X-Gamma-Serve
X-Fmm-Version
X-HS-Content-Campaign-Id
X-Httpd
X-Location
X-Mid
X-Origin-Response-Time
X-Cache-Bucket
X-Auto-Login
X-Akamai-Device-Characteristics
X-Platform-Server
X-Old-Content-Length
X-NodeID
X-Core-Mission
X-Clara-WADP
X-Cdn-Srv
X-Cdn-Origin
X-Worker
X-Sn-Servicetimems
Apple-News-Services-Parsed-Url
X-RM-Cache-TTL
Apple-News-Services-Host
Apple-News-Services-Handled
Decoy-Debug-TTL
Memcached
Cache-Host
Apple-News-Services-Request-Url
Edge-Cache
DSUID
C-Via
Decoy-Debug-Status
Decoy-Debug-Key
X-Generated-On
Country-Code
Cluster
Click-Count-Error
Click-Count-Action-Start
X-WP-CF-Super-Cache-Active
Fastly-GeoIP-CountryCode
X-Level-Front-Cache
Fastly-Backend-Name
Section-Io-Id
Section-Origin-Responded
Section-Io-Origin-Status
X-AIR-PT
Section-Io-Origin-Time-Seconds
CDCHOST
X-Accel-Buffering
User-Cache-Control
X-Conf
We-Hiring
X-DPWN-IS-SECURE
Web-Mar-Region
CacheControlHeader
Cache-Provider
X-Planisys-CDN-TTL
X-LB-NoCache
X-Pool
X-Date
Adler-Geo
X-Nananana
Ssr
Svr
X-Minions-Version
X-CUA
X-Cache-Id
X-Cache-FS-Status
X-Scale
X-App
X-Dispatcher-Number
X-Ad-Defer-Variation
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
X-Origin
X-Cache-Backend
X-Block-Status
X-Accel-Expires-Debug
Cmsid
Origin-EX
Origin-CC
Cache-Key
X-GeoIP-City
X-GeoIP
X-Variation
Platform
Pics-Label
AKAMAI
NM-Fastcgi-Cache
L
Mail-Subject
X-GeoIP-Country-Code
Kp-EeAlive
X-Vmg-Version
Is-Eu
X-Hash
X-GeoIP-Region-Code
Producers
X-Fetched-On
X-Hnp-Log
X-Slack-Backend
X-Esi-Check
X-Pubstack
X-Gen-Mode
Cmstype
X-Wix-Viewer-Type
CloudFront-Viewer-Country
X-Varnish-Beresp-Status
X-Up
X-Fastly-Backend
Server-Ext
Server-Hostname
X-Gzip
Sever-Int
X-Parent-Response-Time
Wxu-Next-Commit
Wxu-Next-Hostname
X-Irp-Debug
X-Azure-Ref-OriginShield
X-HN
X-Bip
X-FC-Vary-Parameters
X-Ckpd-Fst-Backend
X-Dispatcher-Server
X-Device-Os
X-Forwarded-Site
Wxu-Next-Region
X-Refresh
X-Var-Ttl
PFcat
X-Slack-Shared-Secret-Outcome
X-Org
X-Thanos
X-Mvc-Supplant-Cachable
X-VarnishDD-TTL
Cdn
X-NCache
Gh-Request-Id
Fastly-SSL
X-Nginx-Cache-Key
X-Op-Id-All
Datacenter
X-V-Cache
X-Cache-Tags
X-Node-Id
X-Cached-By
X-CacheTTL
X-Owner
X-Men
X-Region-Sid
On-Server
X-Request-Start
Machine
NGX
X-Qloud-Router
X-Server-IP
X-Platform
X-Via-Popn
X-Via-Poph
Canary
X-Via-Popv
X-Csrf-Jwt
X-Varnish-Ttl
X-Varnishpool
X-Eu-Site
X-CGP
HA-Ipaddr
L5d-Success-Class
Ha-Gx-Prefs
X-Webkit-CSP-Report-Only
X-Mvc-Supplant-OutputCached
X-Cache-Date
X-Aicache-OS
GeoIP-Latitude
X-CSRF-Token
Env
X-Servedbyhost
X-HA-Backend
Cdnsip
X-Cache-Remote
X-Microcachable
X-RCS-CacheZone
X-Tb-Optimization-Total-Bytes-Saved
Cdncip
Server-ID
X-AK-Request-ID
X-Client-Ip
HostName
X-Mly-Id
X-APP-VERSION
Memory
X-Gateway-Cache-Key
X-Gateway-Cache-Status
X-DataCenter
X-ZONE
X-Fpc
X-VC
Time
X-Gateway-Request-Id
X-API-Version
X-Wa
X-Gateway-Skip-Cache
X-Zone
Load-Balancing
X-Generated-In
X-Fastly-Cache
X-Nc
Cache
X-LB-ID
X-Vc
Request-ID
X-Webkit-CSP
X-Instance-Name
X-Via-NSCOPI
Eomportal-Instance
X-Check-Cacheable
X-ND-Cache
X-Origin-Expires
X-Vgn-Hpd-Ssi
X-Vgn-Hpd-Variations-Key
X-Vgn-Hpd-Cached
X-Response-By
X-Micro-Cache
Ngx-Var-Key
X-Release
Hostname
X-HS-Status
X-Correlation-ID
OT-Force-Account-Verify
X-CS
Locid
Expect-Staple
X-Hcs-Proxy-Type
X-CCDN-CacheTTL
X-From
X-CCDN-Origin-Time
X-FL-QIT-DEBUG
X-FL-EDGE
X-NewRelic-App-Data
Srvid
X-CSRF-TOKEN
X-Api-Version
X-Via-CDN
IsBot
X-Request-URI
X-Cache-Enabled
X-SIPLIST1
X-Edge-Pop
Edge-Copy-Time
X-Via-SSL
GeoIp-Country-Code
AMP-Access-Control-Allow-Source-Origin
X-Info
X-VCL-Version
X-Via-Edge
X-Cache-NGX
X-NGINX-Cache
NtCoent-Length
X-Provided-By
Srv
X-Via-JSL
Uri
X-MCACHE
X-Proxy-CacheRZ
XkeyRZ
X-Srv
X-Nf-Request-Id
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-Lambda-Id
X-Amz-Meta-Cb-Modifiedtime
X-Air-Pt
True-Client-IP
True-Client-Ip
X-Vcl-Version
Location
X-EC-Lua
X-B3-SpanId
X-Dc
CPC-Age
VNS-Cache
Sid
X-Vtex-Remote-Cache
CPC-Cache
VNS-Age
X-Cache-Expires
Servername
X-Render-Time
Path
X-Oss-Storage-Class
X-Oss-Server-Time
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
X-Oss-Request-Id
X-Edge-POP
Resin-Trace
GeoIP-Country-Code
X-Server-ID
X-TH-Server
X-VCT
X-Fastly-Country-Code
X-Cs
Cross-Origin-Opener-Policy-Report-Only
CDN
LB
Fastly-Drupal-Html
X-CLOUD-TRACE-CONTEXT
X-ATG-Version
Traceparent
X-Moov-T
X-Moov-Xdn-Version
X-Cdn-Request-ID
X-Viewer-Country
X-Varnish-Authentication
X-MSEdge-Flight
X-MSEdge-Features
Esi-Enabled
X-Cache-ASPX
X-Scheme
X-Contensis-Viewer-Groups
X-Accel-Version
X-TX-ID
CountryCode
M-TraceId
X-Pod-Name
X-ApacheServer
X-PERF
YJS-ID
Timeexpire
X-Upstream-Ht
X-Upstream-Ct
X-Varnish-Beresp-TTL
X-Akamai-Pragma-Client-IP
X-Datadome
X-RateLimit-Reset
Powered-By
FSS-Cache
X-RateLimit-Remaining-Second
Rip
X-Udemy-Cache-App-Namespace
X-PAYTM-SRV-ID
X-RateLimit-Limit-Second
X-CF-Lambda-Version
X-CF-Lambda-Fn
X-NAPM-TraceId
X-FPC
X-Datacenter
X-Cache-Type
X-Service-Response-Time
Sm-Log-Id
X-Cdn-Cache-Status
HIT
X-Lb-Id
X-WA
X-SERVER-NAME
XServer
X-Geo
True-Client-Country-4JS
Tracecode
N-Cache
Server-Id
X-CACHE-KEY
X-Srcache-Fetch-Status
RNT-Time
X-Srcache-Store-Status
X-Wikidot-Static-Cache
X-CDN-Cache-Status
X-Wikidot-Backend
V-Age
RNT-Machine
Ohc-File-Size
X-Clientip
Proxy-Connection
X-NC
XM
X-TraceId
X-Tenant
X-Forwarded-Path
X-Orig-Expires
X-Hyper-Cache
X-LiteSpeed-Cache-Control
ENV
X-Bl-Debug
X-Shop-Environment
X-ServedByHost
Epwk-X-Cache
X-VG-WebCache
X-B3-Trace-ID
X-B3-Parentspanid
Ngx
WZWS-RAY
X-Ha-Backend
X-Cdn-Forward
Geoip-Latitude
X-MP-GENERATED-AT
Yjs-Id
X-M-Log
X-M-Reqid
X-Vgn-Hpd-Reason
X-App-Name
X-MiniProfiler-Ids
X-Rebelmouse-Surrogate-Control
X-Via-PopN
X-Via-PopH
X-Rebelmouse-Cache-Control
X-Qnm-Cache
X-Via-PopV
Content-Script-Type
X-Serial
X-Lb-Nocache
X-Amz-Meta-Opti
User-Agent
X-B3-ParentSpanId
Inserted-Into-Cache-At
X-Dw-Trace-Id
X-Fastly-Backend-Reqs
X-Swift-Error
Ec-Rule-Version
Content-Style-Type
X-Cdn-Diag
X-Lsadc-Cache
X-F-Status
X-TT-LOGID
X-Wp-Cf-Super-Cache
X-Wp-Cf-Super-Cache-Cache-Control
X-Mid-Debug-Cache-Disk
X-Stale
Expiry
Pramga
X-Ramcache
X-Policy
X-Connection-Hash
Req-ID
X-Mid-Debug-Cache-Key
X-UP
MIME-Version
My-App
X-LiteSpeed-Tag
X-Th-Server
Cneonction
Warning
X-Snapshot-Date
X-Cache-Ngx
X-IPS-Cached-Response
X-Request-URL