Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Accept-Ranges
Expect-CT
X-XSS-Protection
Pragma
X-Powered-By
CF-RAY
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Xss-Protection
X-Served-By
X-Download-Options
CF-Ray
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
Access-Control-Allow-Credentials
X-FRAME-OPTIONS
X-Request-ID
X-Request-Id
X-Permitted-Cross-Domain-Policies
X-AspNet-Version
Alt-Svc
X-Runtime
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Generator
X-Cache-Status
X-Cacheable
Timing-Allow-Origin
X-Iinfo
X-Envoy-Upstream-Service-Time
X-Content-Security-Policy
X-Drupal-Dynamic-Cache
Feature-Policy
Content-Encoding
Access-Control-Expose-Headers
Upgrade
Status
X-CDN
X-AspNetMvc-Version
P3p
Access-Control-Max-Age
X-Via
Server-Timing
X-UA-Device
Request-Context
X-Robots-Tag
X-Turbo-Charged-By
X-Amz-Request-Id
X-Cache-Group
EagleId
X-Amz-Id-2
X-Backend
X-AH-Environment
X-Proxy-Cache
Keep-Alive
X-Ua-Compatible
X-Server
X-Ws-Request-Id
X-Age
Host-Header
X-Hacker
Cf-Edge-Cache
X-Vhost
X-Server-Powered-By
X-Rq
X-Dns-Prefetch-Control
X-Varnish-Cache
X-Dispatcher
X-Amz-Version-Id
Grace
Allow
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-OneAgent-JS-Injection
X-LiteSpeed-Cache
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Page-Speed
X-Device
Cf-Apo-Via
X-WebKit-CSP
Accept-CH
Cf-Railgun
X-Aws-Lambda-Call-Status
X-Node
X-Pingback
X-Host
X-Server-Id
EagleEye-TraceId
X-Nginx-Cache-Status
X-Ruxit-JS-Agent
Surrogate-Control
X-Akam-SW-Version
X-Cache-Spec
X-Backend-Server
Request-Id
X-Readtime
X-Cache-Lookup
X-HW
X-Content-Security-Policy-Report-Only
X-Cloud-Trace-Context
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Accept-Ch-Lifetime
X-Trace
X-Application-Context
X-Response-Time
Fastly-Restarts
Permissions-Policy
X-Nginx-Upstream-Cache-Status
X-Mod-Pagespeed
X-Edge
X-WebKit-CSP-Report-Only
Accept-CH-Lifetime
X-Litespeed-Cache
X-Mcache
X-Content-Type
Content-Location
X-MS-InvokeApp
X-CST
X-Url
X-Country
X-Clacks-Overhead
Rating
X-Midtier
X-PC
X-TtlSet
X-Amz-Server-Side-Encryption
X-Vname
RTSS
Cache-Tag
X-ESI
X-Vcap-Request-Id
X-D2id
X-VARITI-CCR
X-Element-Page-Cache
Verso
Origin-Trial
X-ECACHE
X-Server-Name
X-Exp-Id
X-Kinja-Server
X-Use-Magma
X-Kinja-Revision
X-Kinja-Build
X-GoogleNews-Bot
X-Kinja
X-Cdn-Fetch
X-Exp-Variant
X-Rack-Cache
X-Ac
X-Powered-By-Plesk
X-Ttl
X-GitHub-Request-Id
X-Cnection
Service-Worker-Allowed
X-SharePointHealthScore
SPRequestGuid
X-Amz-Rid
X-Client-IP
X-Navigation-Version
Xkey
X-B3-TraceId
X-Abt-Application-Version
Edge-Control
X-Cache-TTL
X-NWS-LOG-UUID
SPRequestDuration
SPIisLatency
X-Upstream
Arr-Disable-Session-Affinity
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Browser-Type
X-Instrumentation
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-Cached
X-Mg-S
X-Dw-Request-Base-Id
X-Px
X-Varnish-TTL
X-Cache-Key
X-Correlation-Id
X-Sol
X-Middleton-Display
Display
Pagespeed
X-SRCache-Store-Status
X-SRCache-Fetch-Status
Access-Control-Request-Method
X-NF-Request-ID
Edge-Cache-Tag
X-Forwarded-For
Content-MD5
X-Country-Code
X-Goog-Hash
X-Webkit-Csp
X-FastCGI-Cache
Front-End-Https
TCN
X-Powered-CMS
X-Id
X-Version
AR-CACHE
AR-PoweredBy
Public-Key-Pins
AR-ATIME
AR-Request-ID
AR-SID
X-Jurisdiction
X-HP-Trace-Id
X-HP-Webp
X-RateLimit-Remaining
Accept-Ch
X-T
X-MSEdge-Ref
X-Recruiting
X-Content-Digest
X-Amzn-Trace-Id
X-Daa-Tunnel
X-XRDS-Location
X-Ser
Response
X-Middleton-Response
X-Accel-Expires
TP-Cache
TP-L2-Cache
X-Shield-Request-Id
X-Ratelimit-Limit
S
X-Fastcgi-Cache
Nginx-Cache
MicrosoftSharePointTeamServices
Cache-Status
Mrf-Cache-Status
X-B3-TraceId-Primal
MRF-Tech
X-Request-Processing-Time
X-Request-Received
X-HS-Content-Id
X-HS-Cache-Config
Server-Node
X-HS-Combine-CSS
X-HS-Hub-Id
Cache-Tags
X-Distributor
X-Hits
X-Kinsta-Cache
X-Edge-Location-Klb
X-LB-Cache
X-Ratelimit-Remaining
Cross-Origin-Opener-Policy
Fastcgi-Cache
X-PressLabs-Stats
X-Origin-Server
X-Ua-Browser
X-Ratelimit-Reset
X-Ezoic-Cdn
X-Grace
Alternate-Protocol
Server-Name
X-DIS-Request-ID
X-Geo-Country
Filterid
X-Request-Handler-Origin-Region
X-Microsite
X-Protected-By
X-Rid
X-TEC-API-ROOT
X-TEC-API-ORIGIN
Healthy
X-TEC-API-VERSION
X-Hostname
X-Frontend
X-LLID
X-ORACLE-DMS-RID
X-Debug-Info
X-Logged-In
Payment
X-ORACLE-DMS-ECID
X-Varnish-Backend
X-DataDome
Cleartype
X-Fastly-Request-ID
X-FB-Debug
X-Git-Hash
X-Forwarded-Proto
X-Www-Served-By
X-Page-Id
X-Load-Cache
X-NGENIX-Cache
X-Cluster-Name
X-Origin-Cache
X-ASPNET-VERSION
DC
MS-Author-Via
Charset
Content-Disposition
Realpath
X-B3-Sampled
Access-Control-Allow-Method
X-GUploader-UploadID
X-Goog-Metageneration
X-Upgrade-Enabled
X-Proxy
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Az
X-Activity-Id
X-AppVersion
X-F-Cache
X-ECache
X-Seen-By
X-Amz-Replication-Status
Retry-After
Paypal-Debug-Id
Cross-Origin-Resource-Policy
X-TTL
X-Server-ID
X-VCache
X-Amz-Meta-S3cmd-Attrs
X-Type
Viewport
X-Fb-Rlafr
X-Whom
Count-Hit
X-Revision
X-Contextid
X-Azure-Ref
X-Hosted-By
X-Aspnetmvc-Version
Surrogate-Key
X-App-Environment
X-Signature
Accept-Charset
X-B
X-B-Cache
X-Varnish-Server
X-Flags
X-TT
X-Wix-Request-Id
X-Akamai-Edgescape
X-Is-Crawler
X-Aspnet-Duration-Ms
X-Request-Guid
X-Providence-Cookie
X-Route-Name
X-Cache-Age
X-DynaTrace
X-B3-Traceid
Amp-Access-Control-Allow-Source-Origin
X-Language
X-Source
X-App-Server
X-Fastly-Request-Id
X-Cache-Control
Referer-Policy
X-Oracle-Dms-Ecid
X-Oracle-Dms-Rid
X-Mobile
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Magnolia-Registration
X-Times
Host
X-RateLimit-Limit
X-Envoy-Decorator-Operation
X-Varnish-Grace
Version
X-N
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Oneagent-Js-Injection
X-Varnish-Ttl
X-HTML-Minification-Powered-By
X-Cache-Rule
X-Response-Served-From
X-Original-Request-Id
X-Tumblr-Pixel
X-Tumblr-User
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
Refresh
X-Rule
X-RTag
Access-Control-Request-Headers
Ms-Operation-Id
X-UUID
MS-CV
X-Varnish-Age
X-Cache-Time
X-Cache-Status-Check
X-Framework
Section-Io-Cache
WPO-Cache-Status
WPO-Cache-Message
X-Backend-Name
X-FW-Static
Akamai-GRN
X-FW-Serve
X-FW-Type
X-FW-Version
X-User-Agent
X-RemovedCookies
X-ProcessESI
X-FW-Hash
X-FW-Server
X-EdgeConnect-Cache-Status
X-Content-Powered-By
GEO-INFO
X-FW-Dynamic
X-Cache-Expired-At
X-Status
Protected
X-Jobs
X-Cache-Grace
VIX-Pulpo-Upstream-Status
X-Device-Type
X-Cacheable-TTL
X-G
VIX-Pulpo-Node
Url
SD-X-WS
X-Ruxit-Js-Agent
X-Environment-Context
X-Page-View
X-Servername
X-L-Path
X-Instance
From-Origin
X-Drupal-Cache-Tags
X-Drupal-Cache-Contexts
X-Http-Reason
X-Akamai-Request-ID2
NGB
X-NYM-Debug-Backend
X-Is-Bot
X-Amzn-RequestId
X-Adobe-Content
X-Amz-Apigw-Id
X-Adobe-Loc
X-Rendered-As
SRV
X-Template
X-Trace-Id
X-Region
CDN-RequestId
X-CDN-Forward
X-COUNTRY
Front
X-Nginx-Cache
X-Debug-IsConnected
X-Debug-IsPreview
Accept-Language
X-Unique-Id
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-XRDS-LOCATION
X-Cache-Hit
X-Content-Options
Backend
Fastly-SWR
Fastly-SIE
Country
X-Zen-Fury
X-Air-Source
X-Air-Trace-Id
Liferay-Portal
X-Air-Hostname
X-Tb
X-DynaTrace-JS-Agent
X-Mode
Pinterest-Version
Pinterest-Generated-By
X-Pinterest-Rid
X-Newrelic-App-Data
X-Cache-Operation
Content-Secure-Policy
X-Tec-Api-Version
X-Tec-Api-Origin
X-Tec-Api-Root
X-Node-Name
X-Tt-Logid
X-RN-RSRV
X-Proxy-Cache-Info
X-UPSTREAM-Address
Webserver
X-Rewrite-Enabled
X-Real-IP
Filters
X-Cache-Server
X-Tumblr-Pixel-2
Uber-Trace-Id
X-Generation-Time
X-Amzn-Remapped-Content-Length
Meta-Geo
X-IPS-LoggedIn
X-Proxy-Build
X-PHP-Backend
X-Web-Node
Azure-InstanceId
X-Format
Azure-Version
Azure-SlotName
Cache-Hits
X-Access
Azure-SiteName
X-Ms-Request-Id
Azure-RegionName
X-Ms-Version
X-Section
CF-IPCountry
X-Timing-Wait
Selected-Fe
X-Time
X-Rocket-Nginx-Serving-Static
Onion-Location
X-Server-W
X-Content-Age
TWC-Connection-Speed
Cache-Name
X-Say-TTL
Property-Id
X-Locale
X-UA-Device-Type
ServedBy
X-Say-Cacheable
TWC-Device-Class
X-Cluster-Node
X-VC-Cache
X-Debug
TWC-GeoIP-Country
TWC-GeoIP-LatLong
X-Sucuri-Cache
TWC-Locale-Group
Webcakes-App-Name
X-SayCDN-TTL
TWC-Privacy
X-Reqid
X-Sucuri-ID
Node
Webcakes-Region
X-Origin-Hint
X-TIME
X-R9-Blue-Green-Version
Webcakes-App-Version
Web-Mar-Node
X-VWS-Id
X-Varnish-Beresp-Grace
X-ProxyCache-Key
X-Sql-Duration-Ms
X-Sql-Count
X-Soup
X-Skip-Cache
ServerID
S-Rt
X-Forwarded-Host
X-ProxyCache-Status
X-Site-Version
X-Proxy-Cache-Status
X-Via-Fastly
X-Cache-TTL-Remaining
X-IPLB-Instance
X-Cache-Host
X-Cache-Action
X-BYPASS-REASON
X-IPLB-Request-ID
X-Labrador-Cache-Channel
X-Proto
X-PHP-Host
X-Ua
X-LJ-Flow-ID
X-AWS-Id
X-Cluster
DB-Nickname
X-Handled-By
Apigw-Requestid
X-Adobe-Source
X-Cms-Context
X-No-Session
X-Proxied
Cross-Origin-Window-Policy
X-Zipkin-Id
X-Uri
X-Origin-Date
X-Tumblr-Pixel-3
X-JoinUs
X-Extlb
Mn-Server-Ip
X-Edge-Location
X-SaId
X-Routing-Service
X-FB-TRIP-ID
X-LAGOON
X-Buckets
X-Xfnlog-Site
X-Urbn-Site-Id
X-Urbn-Context-Path
Locale
X-Optimistic-Header
X-WP-CF-Super-Cache
X-App-Version
X-WP-CF-Super-Cache-Cache-Control
Countrycode
WP-Super-Cache
Mime-Version
X-LSADC-Cache
X-GeoCountry
X-Detected-As
X-GeoCode
X-ARC
Source
X-Webkit-CSP
CDN-RequestCountryCode
CDN-CachedAt
CDN-EdgeStorageId
CDN-Cache
CDN-PullZone
Fastcgi-Useragent
CDN-Uid
X-Hl-Ver
Fastly-Drupal-HTML
X-Director
Upgrade-Insecure-Requests
Cache-Tv-Group
X-Varnish-Hits
X-Generated-By
X-Mg-Request-UUID
X-Request-Time
CF-Cached-On
X-Redis-Cache
X-GEO
Xet-Cookie
X-Cache-Debug
Frame-Options
X-Tx-Id
X-Origin-CC
X-Origin-TTL
X-URL
X-SRV
X-Loop
X-FireWall-Port
X-Varnish-Cache-Hits
X-TNCMS
X-Pass-Why
X-RM-Cache-TTL
X-TA-CDN-Provider
X-Varnish-Hostname
X-Alternate-Cache-Key
X-Akamai-Transformed
X-ShardId
X-ServerID
X-Sorting-Hat-PodId
X-ShopId
X-Storefront-Renderer-Rendered
X-Shopify-Stage
X-Sorting-Hat-ShopId
X-Datadog-Parent-Id
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
X-Datadog-Sampled
X-Api-Version
Load-Balancing
X-Newrelic-Synthetics
X-Service
X-Endurance-Cache-Level
X-Request-Host
X-Pubstack
Xserver
X-Served-From
X-B3-Spanid
X-Location
X-NWS-UUID-VERIFY
X-Platform-Router
X-Destination
X-Platform-Processor
X-Processor
Host-ID
X-Ec-Fail
X-Developer
Gannett-Cam-Experience-Id
X-Varnish-Beresp-Ttl
Cache-Host
A
BehaviorPad-Version
Lang
X-Nyt-Route
X-Mobile-URL
X-Mid
X-Httpd
Server-Info
X-Level-Front-Cache
X-Loc
Candidate-Md5Url
X-Generated-On
DSUID
Edge-Cache
X-Epic-Correlation-Id
X-Ec-GeoHdr
X-External-Request-Id
X-Origin-Time
X-Gdpr
DCR-Decision-By
DCR-Processing-Time-Ms
X-Platform-Cluster
Odigeo-Trace-Id
X-BBC-Edge-Cache-Status
X-Bc-Bl
X-B-Cookie
Sslversion
Surrogated-Key
X-BCube-Filmed-By
X-Bip
X-We-Are-Hiring
Release
Rendered-Blocks
Req-Svc-Chain
Xc-Version
T-Server
TDXMobile
X-A-Dam
X-A-Dcw
X-A-Ccd
WWW-Authenticate
X-A
X-A-Dgt
X-A-Wwc
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
Thinkindot-Control
X-Application
X-Aed
X-Rocket-Build-Number
Redirect-Candidate
X-Sigma
MD5-Digest
X-Sigma-Backend
X-SRCache-Key
X-Test
X-ScT
X-CUA
X-S
X-Rojux
X-S-Cookie
X-S-Maxage
X-D
X-Cache-Date
X-Thanos
Origin
X-INCAP-ABP
X-Cache-NE
X-Vdms-Path
X-Cache-Info
X-Vdms-Version
Ngx.Var.Host
X-CMSURLCustom
Meta-Geo-Continent
X-Thinkindot-L3
X-TIM-N
X-Conf
Memcached
X-Storage
X-Restarts
Section-Io-Origin-Time-Seconds
Section-Io-Id
Section-Io-Origin-Status
Section-Origin-Responded
X-WA-Info
X-Varnish-Beresp-Status
X-WADP-Cache
X-VG-TLSProxy
X-Origin-Response-Time
X-Frame-Option
Magicmarker
CloudFront-Viewer-Country
X-Fmm-Version
X-Origin
X-Fetched-On
Fastly-GeoIP-CountryCode
X-Var-Ttl
X-Developers
Server-Host
Mail-Subject
Country-Code
X-Pool
X-Cdn-Origin
X-Auto-Login
X-Hash
X-Core-Mission
Gh-Request-Id
X-Core-Value
Fastly-Backend-Name
X-Org
X-Mvc-Supplant-Cachable
X-Mly-Id
X-Cdn-Srv
X-Vmg-Version
NM-Fastcgi-Cache
X-Clara-WADP
X-Sn-Servicetimems
We-Hiring
X-Varnishpool
X-Human
X-HS-Content-Campaign-Id
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
Apple-News-Services-Handled
AKAMAI
CacheControlHeader
X-GeoIP-City
X-GeoIP
X-Akamai-Device-Characteristics
X-Geo-Header
Apple-News-Services-Host
Cache-Key
Apple-News-Services-Parsed-Url
X-Node-Id
C-Via
X-Cache-Bucket
Apple-News-Services-Request-Url
X-Parent-Response-Time
X-CACHE-AGE
X-VServer
X-Cache-Id
X-Worker
X-Fastly-Cache
X-Ad-Defer-Variation
X-Region-Sid
X-App
X-Server-IP
X-Slack-Backend
X-Men
X-Slack-Shared-Secret-Outcome
X-Gamma-Serve
X-Fastly-Backend
X-Accel-Expires-Debug
State
X-CacheTTL
X-Azure-Ref-OriginShield
X-Dispatcher-Number
X-Date
X-WP-CF-Super-Cache-Active
X-DefHash
X-Op-Id-All
X-Old-Content-Length
X-NodeID
X-Gen-Mode
X-Forwarded-Site
Wxu-Next-Region
X-Platform
X-FC-Vary-Parameters
X-Gzip
X-Nginx-Cache-Key
X-Hnp-Log
X-JWT-State
X-Is-Gdpr
X-HN
X-Has-Esi
X-NCache
X-LB-NoCache
X-Esi-Check
X-Platform-Server
X-Variation
X-SD-PageType
X-Scale
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-VarnishDD-TTL
X-Varnish-Remaining-TTL
X-SB
X-Request-Start
X-Device-Os
X-Dispatcher-Server
X-Ec-Custom-Error
X-Qloud-Router
X-Req
X-DefElseHash
X-Irp-Debug
X-Cache-Tags
X-Block-Status
Machine
L
Kp-EeAlive
NGX
On-Server
PFcat
Origin-EX
Origin-CC
Is-Eu
Environment
Adler-Geo
Wxu-Next-Hostname
X-CSRF-Token
Cache-Provider
Canary
Click-Count-Error
Click-Count-Action-Start
CDCHOST
Platform
Datacenter
Tube-Return
User-Cache-Control
Tube-Got-Results
Tube-Got-Eval
Tube-Get-Contents
Web-Mar-Region
Vix-Hermes-Req-Id
Wxu-Next-Commit
Cluster
X-Planisys-CDN-Rules
X-Accel-Buffering
Decoy-Debug-Key
X-Origin-Expires
Decoy-Debug-Status
X-DPWN-IS-SECURE
Ha-Gx-Prefs
X-Planisys-CDN-TTL
X-Eu-Site
Decoy-Debug-TTL
X-Planisys-CDN-Cache
X-Owner
Cmsid
X-Tid
X-Wix-Viewer-Type
X-Nananana
Cmstype
X-Minions-Version
Server-Hostname
X-GeoIP-Region-Code
HA-Ipaddr
X-Instance-Name
X-V-Cache
X-GeoIP-Country-Code
X-Cache-Backend
X-Csrf-Jwt
Producers
Ssr
X-CGP
X-Cache-Remote
Sever-Int
Pics-Label
L5d-Success-Class
X-Ckpd-Fst-Backend
Server-Ext
X-Webkit-CSP-Report-Only
Fastly-SSL
X-Cache-FS-Status
X-Mvc-Supplant-OutputCached
X-Microcachable
X-Response-By
X-Tb-Optimization-Total-Bytes-Saved
X-Release
X-Refresh
X-Zone
X-Provided-By
X-FL-EDGE
Srvid
X-FL-QIT-DEBUG
HostName
X-Aicache-OS
Locid
Expect-Staple
X-Air-Pt
X-DC
X-Via-CDN
X-Servedbyhost
X-RCS-CacheZone
X-From
Time
GeoIP-Latitude
X-Up
X-Dc
Env
Memory
X-ND-Cache
X-VC
X-Trace-ID
X-Presslabs-Stats
X-Via-SSL
Edge-Copy-Time
X-Via-Edge
Svr
X-Vcl-Version
X-Generated-In
X-Cache-Enabled
X-NewRelic-App-Data
NtCoent-Length
X-AIR-PT
X-Cached-By
X-Edge-Pop
Sid
SID
X-HS-Status
Cache
X-Srv
X-Nc
X-Via-Popv
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-Via-Poph
X-Via-Popn
X-Lambda-Id
X-DataCenter
Cdn
X-Vgn-Hpd-Ssi
AMP-Access-Control-Allow-Source-Origin
X-Wa
X-Esi
X-Vgn-Hpd-Cached
X-HA-Backend
X-Vc
X-Vgn-Hpd-Variations-Key
X-Cs
X-ZONE
X-Correlation-ID
X-Vtex-Remote-Cache
X-CCDN-CacheTTL
X-Render-Time
VNS-Age
CPC-Cache
X-CCDN-Origin-Time
VNS-Cache
X-Hcs-Proxy-Type
Server-ID
X-Client-Ip
CPC-Age
X-VCT
X-NGINX-Cache
X-Check-Cacheable
Hostname
GeoIp-Country-Code
Cdnsip
X-LB-ID
X-AK-Request-ID
Cdncip
Fastly-Drupal-Html
X-Amz-Meta-Cb-Modifiedtime
X-Gateway-Skip-Cache
X-TH-Server
X-Gateway-Cache-Status
X-Fpc
X-Via-NSCOPI
X-Gateway-Request-Id
X-Gateway-Cache-Key
X-Upstream-Ht
X-Upstream-Ct
XkeyRZ
X-Via-JSL
X-Proxy-CacheRZ
X-API-Version
X-ATG-Version
True-Client-IP
X-Cache-Type
X-CSRF-TOKEN
X-B3-SpanId
Srv
X-Nf-Request-Id
Uri
X-CS
X-EC-Lua
X-Varnish-Authentication
M-TraceId
X-Cache-ASPX
X-Contensis-Viewer-Groups
Eomportal-Instance
True-Client-Ip
Esi-Enabled
X-Datadome
X-Varnish-Beresp-TTL
X-Micro-Cache
X-PAYTM-SRV-ID
X-RateLimit-Limit-Second
Resin-Trace
XServer
X-MSEdge-Features
X-MSEdge-Flight
X-CF-Lambda-Version
OT-Force-Account-Verify
Ngx-Var-Key
X-CF-Lambda-Fn
X-RateLimit-Remaining-Second
X-Udemy-Cache-App-Namespace
X-FPC
Path
YJS-ID
Request-ID
X-MP-GENERATED-AT
X-Wikidot-Backend
X-Cache-NGX
X-Fastly-Country-Code
X-Wikidot-Static-Cache
CDN
IsBot
X-Request-URI
X-SIPLIST1
X-CDN-Cache-Status
X-APP-VERSION
N-Cache
X-CLOUD-TRACE-CONTEXT
GeoIP-Country-Code
X-Lb-Id
RNT-Machine
X-TX-ID
X-Info
X-Bl-Debug
RNT-Time
X-Shop-Environment
X-VCL-Version
X-Orig-Expires
X-Tenant
X-Forwarded-Path
X-Accel-Version
Sm-Log-Id
Server-Id
X-Service-Response-Time
X-Policy
X-Pod-Name
X-B3-Trace-ID
X-App-Name
Lb
Location
X-Ha-Backend
X-Datacenter
X-MCACHE
LB
HIT
X-RateLimit-Reset
X-WA
X-Geo
Cross-Origin-Opener-Policy-Report-Only
X-Edge-POP
X-Akamai-Pragma-Client-IP
Servername
X-Oss-Request-Id
X-Oss-Storage-Class
X-Snapshot-Date
X-Cdn-Cache-Status
X-Oss-Server-Time
X-Oss-Object-Type
X-Cache-Expires
X-Oss-Hash-Crc64ecma
X-Cdn-Request-ID
X-Via-PopN
X-Via-PopV
Ohc-File-Size
X-SERVER-NAME
X-Via-PopH
FSS-Cache
Hit
X-Srcache-Store-Status
X-Srcache-Fetch-Status
X-NC
Timeexpire
X-Cache-Ttl
ENV
X-CACHE-KEY
Proxy-Connection
Yjs-Id
X-Cdn-Diag
X-Rebelmouse-Surrogate-Control
X-Ctl-Mach
X-Logging-Id
X-ServedByHost
X-Rebelmouse-Cache-Control
Req-ID
Epwk-X-Cache
X-LiteSpeed-Cache-Control
X-Moov-T
Traceparent
WZWS-RAY
X-Scheme
X-Container-Uri
Geoip-Latitude
X-Git-Commit
X-Serial
X-Hyper-Cache
X-Dw-Trace-Id
X-Moov-Xdn-Version
X-Amz-Meta-Opti
Pramga
X-TraceId
X-UP
X-Cdn-Forward
X-M-Log
X-MiniProfiler-Ids
X-M-Reqid
X-Qnm-Cache
X-VG-WebCache
XM
X-RAMCache
X-Acquia-Site
X-Acquia-Application-UUID
X-Acquia-Purge-Tags
X-Acquia-Application-Trace
X-Fastly-Backend-Reqs
X-Swift-Error
Ec-Rule-Version
X-Lb-Nocache
X-B3-Parentspanid
Cdn-Requestid
X-PERF
X-Viewer-Country
Content-Style-Type
X-ApacheServer
X-Vcache
Content-Script-Type
Cneonction
CountryCode
X-F-Status
X-Lsadc-Cache
X-Wp-Cf-Super-Cache
X-TT-LOGID
X-Wp-Cf-Super-Cache-Cache-Control
X-Tncms
X-Mg-Cache
X-Litespeed-Cache-Control
MIME-Version
Warning
X-B3-ParentSpanId
X-Iauth-Set-Uid
V-Age
Ohc-Cache-HIT
X-Cache-Ngx
My-App
X-Mid-Debug-Cache-Disk
X-Mid-Debug-Cache-Key
X-Request-URL
Ngx
X-Fastly-Cache-Hits
X-IPS-Cached-Response
X-Th-Server
X-Webstats-RespID
Inserted-Into-Cache-At
X-LiteSpeed-Tag