Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Accept-Ranges
Expect-CT
Pragma
X-Powered-By
X-XSS-Protection
CF-RAY
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-Xss-Protection
X-UA-Compatible
X-Served-By
X-Download-Options
CF-Ray
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Request-ID
Access-Control-Allow-Credentials
X-FRAME-OPTIONS
X-Request-Id
X-Permitted-Cross-Domain-Policies
X-AspNet-Version
Alt-Svc
X-Runtime
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Generator
X-Cache-Status
X-Cacheable
Timing-Allow-Origin
X-Iinfo
X-Envoy-Upstream-Service-Time
X-Content-Security-Policy
X-Drupal-Dynamic-Cache
Feature-Policy
Content-Encoding
Access-Control-Expose-Headers
Upgrade
Status
X-CDN
X-AspNetMvc-Version
P3p
X-Ua-Compatible
Access-Control-Max-Age
X-Via
Server-Timing
X-UA-Device
Request-Context
X-Robots-Tag
X-Turbo-Charged-By
X-Amz-Request-Id
X-Cache-Group
EagleId
X-Amz-Id-2
X-Backend
X-AH-Environment
X-Proxy-Cache
Keep-Alive
X-Server
X-Ws-Request-Id
X-Age
X-Dns-Prefetch-Control
Host-Header
X-Hacker
Cf-Edge-Cache
X-Vhost
X-Server-Powered-By
X-Rq
X-Varnish-Cache
X-Dispatcher
X-Amz-Version-Id
Allow
Grace
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-OneAgent-JS-Injection
X-LiteSpeed-Cache
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Page-Speed
Cf-Apo-Via
X-Device
X-WebKit-CSP
Accept-CH
Cf-Railgun
X-Aws-Lambda-Call-Status
X-Node
X-Pingback
X-Host
X-Ruxit-JS-Agent
X-Server-Id
EagleEye-TraceId
X-Nginx-Cache-Status
X-Akam-SW-Version
Surrogate-Control
X-Cache-Spec
X-Backend-Server
Request-Id
X-Readtime
X-Cache-Lookup
X-HW
X-Content-Security-Policy-Report-Only
X-Cloud-Trace-Context
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Trace
X-Application-Context
X-Response-Time
Accept-Ch-Lifetime
Fastly-Restarts
Permissions-Policy
X-Nginx-Upstream-Cache-Status
X-Mod-Pagespeed
X-Edge
X-WebKit-CSP-Report-Only
Accept-CH-Lifetime
X-Mcache
Content-Location
X-CST
X-Content-Type
X-Url
X-MS-InvokeApp
X-Clacks-Overhead
Rating
X-Midtier
X-Country
X-Amz-Server-Side-Encryption
X-PC
X-Vname
X-TtlSet
X-Litespeed-Cache
RTSS
Cache-Tag
X-ESI
X-ECACHE
X-Vcap-Request-Id
X-D2id
X-VARITI-CCR
X-Element-Page-Cache
Verso
Origin-Trial
X-Server-Name
X-Kinja-Server
X-Use-Magma
X-GoogleNews-Bot
X-Exp-Id
X-Kinja-Revision
X-Cdn-Fetch
X-Kinja-Build
X-Kinja
X-Exp-Variant
X-Rack-Cache
X-Ttl
X-Ac
X-Powered-By-Plesk
X-Cnection
X-GitHub-Request-Id
Service-Worker-Allowed
X-B3-TraceId
X-Client-IP
X-SharePointHealthScore
SPRequestGuid
X-Amz-Rid
X-Navigation-Version
Xkey
X-Abt-Application-Version
Edge-Control
X-Cache-TTL
X-NWS-LOG-UUID
SPIisLatency
SPRequestDuration
X-Varnish-TTL
X-Upstream
Arr-Disable-Session-Affinity
X-Server-Lifecycle-Phase
X-Instrumentation
X-Kraken-Loop-Name
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Browser-Type
X-Cached
X-Mg-S
X-Webkit-Csp
X-Px
X-Dw-Request-Base-Id
X-Cache-Key
X-Correlation-Id
X-Sol
Pagespeed
Display
X-Middleton-Display
X-SRCache-Store-Status
X-SRCache-Fetch-Status
Access-Control-Request-Method
X-NF-Request-ID
Edge-Cache-Tag
X-FastCGI-Cache
Content-MD5
X-Forwarded-For
X-Country-Code
X-Goog-Hash
Front-End-Https
X-Powered-CMS
TCN
X-Version
X-XRDS-Location
X-Id
Public-Key-Pins
AR-PoweredBy
AR-SID
AR-Request-ID
AR-CACHE
AR-ATIME
X-HP-Trace-Id
X-HP-Webp
X-Jurisdiction
X-T
X-MSEdge-Ref
X-Recruiting
X-Content-Digest
Accept-Ch
X-Daa-Tunnel
X-RateLimit-Remaining
X-Amzn-Trace-Id
X-Accel-Expires
X-Ser
Response
X-Middleton-Response
X-Ratelimit-Limit
TP-L2-Cache
TP-Cache
X-Shield-Request-Id
S
Nginx-Cache
MicrosoftSharePointTeamServices
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
Cache-Status
X-Request-Received
X-Request-Processing-Time
Server-Node
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Combine-CSS
X-HS-Cache-Config
X-Fastcgi-Cache
Cache-Tags
X-Distributor
X-Ratelimit-Remaining
X-Hits
X-Kinsta-Cache
X-Edge-Location-Klb
X-LB-Cache
Fastcgi-Cache
Cross-Origin-Opener-Policy
X-Origin-Server
Alternate-Protocol
X-Ratelimit-Reset
X-Ua-Browser
X-Grace
Server-Name
X-Ezoic-Cdn
X-DIS-Request-ID
X-DataDome
X-Geo-Country
Filterid
X-Microsite
X-Protected-By
X-Request-Handler-Origin-Region
X-Rid
X-Fastly-Request-ID
Healthy
X-Frontend
X-Varnish-Backend
X-Debug-Info
X-Hostname
X-Logged-In
X-Git-Hash
X-LLID
Payment
X-PressLabs-Stats
Cleartype
X-FB-Debug
X-Page-Id
X-Www-Served-By
X-Forwarded-Proto
X-Origin-Cache
X-Load-Cache
X-TEC-API-ROOT
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-NGENIX-Cache
X-Cluster-Name
DC
MS-Author-Via
Charset
X-ASPNET-VERSION
Content-Disposition
X-B3-Sampled
Realpath
Access-Control-Allow-Method
X-GUploader-UploadID
X-ORACLE-DMS-RID
X-Goog-Metageneration
X-ORACLE-DMS-ECID
X-Upgrade-Enabled
X-Proxy
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-F-Cache
X-Activity-Id
X-Az
X-AppVersion
X-Seen-By
Retry-After
X-Amz-Replication-Status
Cross-Origin-Resource-Policy
Paypal-Debug-Id
X-Contextid
X-Type
X-Oracle-Dms-Rid
X-Oracle-Dms-Ecid
X-Amz-Meta-S3cmd-Attrs
X-Request-Guid
X-Whom
X-Providence-Cookie
X-Route-Name
X-Revision
X-Aspnet-Duration-Ms
Viewport
X-Azure-Ref
X-Fb-Rlafr
X-Flags
X-Hosted-By
X-Is-Crawler
Accept-Charset
X-ECache
X-VCache
X-App-Environment
Surrogate-Key
X-Signature
X-B-Cache
X-Wix-Request-Id
Count-Hit
Amp-Access-Control-Allow-Source-Origin
X-Varnish-Server
X-B
X-Server-ID
X-COUNTRY
X-TT
X-TTL
X-Akamai-Edgescape
X-DynaTrace
X-Aspnetmvc-Version
X-Language
X-Source
X-B3-Traceid
X-App-Server
Referer-Policy
X-Cache-Control
X-Mobile
X-Cache-Age
X-Goog-Storage-Class
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Fastly-Request-Id
X-Magnolia-Registration
X-Varnish-Grace
Host
Version
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Envoy-Decorator-Operation
X-N
X-Times
X-HTML-Minification-Powered-By
X-Cache-Rule
SRV
X-Tumblr-Pixel-0
X-Tumblr-User
X-Tumblr-Pixel-1
X-Tumblr-Pixel
X-Original-Request-Id
X-Response-Served-From
X-Cache-Time
X-Varnish-Age
MS-CV
Ms-Operation-Id
X-UUID
Refresh
Section-Io-Cache
Access-Control-Request-Headers
X-Rule
X-RateLimit-Limit
X-RTag
WPO-Cache-Message
WPO-Cache-Status
SD-X-WS
X-Cache-Status-Check
X-Framework
X-Cacheable-TTL
X-EdgeConnect-Cache-Status
X-FW-Static
X-Cache-Expired-At
X-Page-View
X-FW-Server
X-RemovedCookies
X-FW-Dynamic
X-FW-Hash
X-FW-Serve
X-Content-Powered-By
X-ProcessESI
Akamai-GRN
X-User-Agent
X-Backend-Name
GEO-INFO
X-Cache-Grace
X-FW-Type
X-FW-Version
X-Servername
X-Is-Bot
X-Status
VIX-Pulpo-Upstream-Status
X-Instance
X-Rendered-As
Protected
X-G
X-Jobs
VIX-Pulpo-Node
X-Device-Type
Url
X-Trace-Id
X-Environment-Context
X-Akamai-Request-ID2
X-Adobe-Loc
X-Http-Reason
X-L-Path
X-Drupal-Cache-Tags
X-Drupal-Cache-Contexts
X-Adobe-Content
X-NYM-Debug-Backend
From-Origin
NGB
CDN-RequestId
X-Amz-Apigw-Id
X-Template
X-Amzn-RequestId
X-Region
X-CDN-Forward
Front
X-Debug-IsConnected
X-Debug-IsPreview
X-Varnish-Ttl
Accept-Language
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Cache-Hit
X-Unique-Id
X-Nginx-Cache
Backend
X-Content-Options
Fastly-SWR
Country
X-Tec-Api-Version
X-Tec-Api-Root
X-Tec-Api-Origin
Fastly-SIE
X-Zen-Fury
X-TIME
X-Tb
Liferay-Portal
X-Air-Trace-Id
X-Air-Hostname
X-Air-Source
X-DynaTrace-JS-Agent
Pinterest-Version
X-Pinterest-Rid
Pinterest-Generated-By
X-Tt-Logid
X-Mode
X-Node-Name
X-Real-IP
X-Cache-Operation
Content-Secure-Policy
X-XRDS-LOCATION
X-RN-RSRV
X-Amzn-Remapped-Content-Length
X-UPSTREAM-Address
X-Rewrite-Enabled
X-Proxy-Cache-Info
Meta-Geo
X-Tumblr-Pixel-2
X-Generation-Time
Filters
Uber-Trace-Id
X-Cache-Server
Webserver
X-Proxy-Build
X-VC-Cache
X-PHP-Backend
X-IPS-LoggedIn
X-Access
X-Format
X-Rocket-Nginx-Serving-Static
X-Ms-Version
Azure-RegionName
Onion-Location
X-Content-Age
Azure-SiteName
X-Timing-Wait
Selected-Fe
Azure-SlotName
Azure-Version
Cache-Hits
Azure-InstanceId
X-Ms-Request-Id
X-Web-Node
X-Section
CF-IPCountry
Webcakes-App-Version
Node
X-Debug
X-Sql-Duration-Ms
Cache-Name
Webcakes-Region
X-Cluster-Node
TWC-Device-Class
X-Proto
X-UA-Device-Type
ServedBy
Webcakes-App-Name
X-Server-W
X-Sucuri-ID
X-Locale
X-Sql-Count
X-Sucuri-Cache
X-Origin-Hint
TWC-Connection-Speed
Property-Id
TWC-GeoIP-LatLong
TWC-Locale-Group
TWC-Privacy
X-Say-Cacheable
X-Say-TTL
X-Reqid
TWC-GeoIP-Country
X-SayCDN-TTL
X-Soup
ServerID
Web-Mar-Node
S-Rt
X-R9-Blue-Green-Version
X-Varnish-Beresp-Grace
X-Via-Fastly
X-ProxyCache-Status
X-VWS-Id
X-ProxyCache-Key
X-Proxy-Cache-Status
X-PHP-Host
X-Skip-Cache
X-Site-Version
X-Ua
X-LJ-Flow-ID
X-Labrador-Cache-Channel
X-Cache-TTL-Remaining
X-Cache-Host
X-BYPASS-REASON
X-AWS-Id
X-Cluster
X-Cms-Context
X-IPLB-Request-ID
X-IPLB-Instance
X-Handled-By
X-Forwarded-Host
X-Adobe-Source
X-Cache-Action
DB-Nickname
X-Extlb
X-FB-TRIP-ID
X-Edge-Location
X-WP-CF-Super-Cache
X-Zipkin-Id
X-WP-CF-Super-Cache-Cache-Control
X-JoinUs
X-LAGOON
X-SaId
X-Routing-Service
X-Newrelic-App-Data
X-Proxied
Apigw-Requestid
X-No-Session
Mn-Server-Ip
X-Detected-As
Cross-Origin-Window-Policy
X-Urbn-Site-Id
WP-Super-Cache
X-Origin-Date
X-Xfnlog-Site
X-Optimistic-Header
X-Uri
Locale
X-Urbn-Context-Path
X-Tumblr-Pixel-3
Countrycode
Mime-Version
X-Buckets
Fastcgi-Useragent
X-Ruxit-Js-Agent
X-GeoCountry
X-LSADC-Cache
X-GeoCode
Source
X-App-Version
CDN-Cache
Fastly-Drupal-HTML
CDN-CachedAt
CDN-Uid
X-ARC
CDN-PullZone
CDN-RequestCountryCode
CDN-EdgeStorageId
X-Hl-Ver
X-Time
X-Director
Upgrade-Insecure-Requests
X-Oneagent-Js-Injection
X-GEO
Cache-Tv-Group
X-Request-Time
X-Generated-By
X-Varnish-Hits
X-Tx-Id
X-Mg-Request-UUID
CF-Cached-On
X-Redis-Cache
X-Cache-Debug
X-Loop
Xet-Cookie
X-SRV
X-Origin-TTL
Frame-Options
X-Origin-CC
X-FireWall-Port
X-Pass-Why
X-Akamai-Transformed
X-TNCMS
X-Varnish-Cache-Hits
X-URL
X-Varnish-Hostname
X-RM-Cache-TTL
X-CACHE-AGE
X-ShopId
X-ShardId
X-Shopify-Stage
X-Sorting-Hat-PodId
X-ServerID
X-Storefront-Renderer-Rendered
X-Alternate-Cache-Key
X-Sorting-Hat-ShopId
X-TA-CDN-Provider
X-Newrelic-Synthetics
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
X-Datadog-Sampled
Xserver
X-Service
X-Request-Host
X-B3-Spanid
X-Pubstack
X-Api-Version
X-Endurance-Cache-Level
X-Served-From
X-Varnish-Beresp-Ttl
Load-Balancing
X-Presslabs-Stats
X-NWS-UUID-VERIFY
X-Cache-NE
Meta-Geo-Continent
X-CMSURLCustom
Ngx.Var.Host
Edge-Cache
MD5-Digest
X-Conf
X-CUA
X-Ec-Fail
Lang
X-Cache-Info
X-Developer
X-Destination
Memcached
DSUID
X-D
Host-ID
X-Bc-Bl
X-A-Ccd
X-A
WWW-Authenticate
X-A-Dam
X-A-Dcw
A
X-A-Dgt
BehaviorPad-Version
Cache-Host
T-Server
Candidate-Md5Url
X-Ec-GeoHdr
TDXMobile
Thinkindot-CacheControl
Thinkindot-Control
Thinkindot-CacheControl-Type
Surrogated-Key
X-A-Wwc
Odigeo-Trace-Id
Origin
Redirect-Candidate
DCR-Decision-By
DCR-Processing-Time-Ms
X-Bip
X-BCube-Filmed-By
Release
X-BBC-Edge-Cache-Status
Sslversion
X-Aed
Req-Svc-Chain
X-Application
X-B-Cookie
Rendered-Blocks
X-Cache-Date
X-Location
X-Rojux
X-Rocket-Build-Number
X-Processor
X-INCAP-ABP
X-S
X-Nyt-Route
X-Httpd
X-Level-Front-Cache
X-Loc
X-Mobile-URL
X-Platform-Cluster
X-Origin-Time
X-Mid
Gannett-Cam-Experience-Id
X-Platform-Router
X-Platform-Processor
X-S-Maxage
X-S-Cookie
X-External-Request-Id
X-Vdms-Path
X-TIM-N
X-Epic-Correlation-Id
X-Vdms-Version
Xc-Version
X-We-Are-Hiring
X-ScT
X-Thinkindot-L3
X-SRCache-Key
X-Sigma-Backend
X-Sigma
X-Thanos
X-Generated-On
X-Test
X-Gdpr
X-Restarts
Section-Io-Id
X-Storage
Server-Info
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
Section-Origin-Responded
X-Var-Ttl
X-Varnish-Beresp-Status
X-Fetched-On
X-Fmm-Version
X-Varnishpool
X-Ec-Custom-Error
X-SVT-ORM-VERSION
X-Developers
X-Frame-Option
Server-Host
NM-Fastcgi-Cache
X-VG-TLSProxy
Mail-Subject
Magicmarker
X-WP-CF-Super-Cache-Active
Gh-Request-Id
X-Worker
X-WADP-Cache
X-Vmg-Version
X-VServer
X-WA-Info
X-SVT-ORM-RULES
X-Geo-Header
X-Cdn-Srv
X-Cdn-Origin
X-Pool
X-Clara-WADP
X-JWT-State
X-Akamai-Device-Characteristics
X-Cache-Bucket
X-Origin
X-Origin-Response-Time
X-Node-Id
X-Mvc-Supplant-Cachable
X-Is-Gdpr
X-Core-Mission
X-SD-PageType
X-GeoIP-City
X-GeoIP
X-Sn-Servicetimems
We-Hiring
X-Has-Esi
X-Core-Value
X-Human
X-HS-Content-Campaign-Id
X-Hash
X-Org
X-Auto-Login
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
C-Via
Apple-News-Services-Handled
CloudFront-Viewer-Country
Country-Code
AKAMAI
Fastly-Backend-Name
Apple-News-Services-Request-Url
Cache-Key
CacheControlHeader
Fastly-GeoIP-CountryCode
X-Parent-Response-Time
Tube-Get-Contents
X-Nginx-Cache-Key
Adler-Geo
X-Ad-Defer-Variation
X-Accel-Expires-Debug
X-Accel-Buffering
X-NCache
Tube-Got-Eval
Tube-Got-Results
Tube-Return
Vix-Hermes-Req-Id
Web-Mar-Region
X-Men
Wxu-Next-Region
Wxu-Next-Hostname
Wxu-Next-Commit
User-Cache-Control
X-Hnp-Log
X-Dispatcher-Server
X-Dispatcher-Number
X-Cache-Id
X-Esi-Check
X-Fastly-Backend
X-Device-Os
X-Cache-Tags
X-Date
X-DefElseHash
X-CacheTTL
X-DefHash
X-FC-Vary-Parameters
X-Block-Status
X-HN
X-Gzip
X-App
X-NodeID
X-Irp-Debug
X-Azure-Ref-OriginShield
X-GeoIP-Region-Code
X-Forwarded-Site
X-Gamma-Serve
X-Gen-Mode
X-GeoIP-Country-Code
X-LB-NoCache
X-Old-Content-Length
X-Server-IP
NGX
X-Slack-Backend
X-Slack-Shared-Secret-Outcome
X-Scale
Datacenter
X-Request-Start
Origin-CC
X-SB
On-Server
Environment
X-Variation
Is-Eu
X-VarnishDD-TTL
X-Wix-Viewer-Type
X-Mly-Id
X-Varnish-Remaining-TTL
Kp-EeAlive
Machine
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
L
PFcat
Origin-EX
Sever-Int
X-Platform
X-Platform-Server
Click-Count-Action-Start
State
X-Op-Id-All
Cache-Provider
Canary
CDCHOST
Server-Ext
Server-Hostname
Click-Count-Error
Platform
X-Region-Sid
X-Req
X-Qloud-Router
X-NewRelic-App-Data
X-Tid
X-Nananana
X-Csrf-Jwt
X-Fastly-Cache
X-Planisys-CDN-Cache
X-Ckpd-Fst-Backend
X-DPWN-IS-SECURE
X-Minions-Version
X-V-Cache
X-Eu-Site
X-Refresh
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-Owner
Producers
Pics-Label
Cmstype
Cmsid
Cluster
X-Cache-Remote
Ssr
Decoy-Debug-Key
Decoy-Debug-Status
Ha-Gx-Prefs
Fastly-SSL
HA-Ipaddr
L5d-Success-Class
Decoy-Debug-TTL
X-CGP
X-Cache-Backend
X-DC
X-Origin-Expires
X-Instance-Name
X-Zone
X-Microcachable
X-Cache-FS-Status
X-CSRF-Token
X-Webkit-CSP-Report-Only
X-Air-Pt
X-Aicache-OS
X-Release
X-Response-By
X-Mvc-Supplant-OutputCached
Env
X-Tb-Optimization-Total-Bytes-Saved
GeoIP-Latitude
X-Provided-By
Locid
X-FL-EDGE
Srvid
X-Up
X-RCS-CacheZone
X-Servedbyhost
X-FL-QIT-DEBUG
Memory
SID
Expect-Staple
Time
X-Via-CDN
X-From
X-ND-Cache
X-Generated-In
Svr
NtCoent-Length
Edge-Copy-Time
X-Via-SSL
X-Trace-ID
HostName
X-Via-Edge
X-DataCenter
X-NGINX-Cache
X-Vcl-Version
X-Cache-Enabled
X-Nc
X-Vc
X-Edge-Pop
X-Cached-By
Cache
X-Dc
X-HS-Status
X-AIR-PT
X-Via-Popv
X-VC
X-Via-Popn
X-Wa
X-Via-Poph
X-Srv
X-Webkit-CSP
Cdn
X-Debug-Cache-Store
X-Debug-Cache-Fetch
Hostname
X-HA-Backend
X-Lambda-Id
Sid
GeoIp-Country-Code
Server-ID
X-Vgn-Hpd-Variations-Key
X-Esi
X-Vgn-Hpd-Cached
X-Vgn-Hpd-Ssi
X-ZONE
X-Correlation-ID
Cdnsip
VNS-Age
VNS-Cache
X-Render-Time
X-Vtex-Remote-Cache
X-Client-Ip
CPC-Cache
CPC-Age
Cdncip
X-CCDN-Origin-Time
X-AK-Request-ID
X-Hcs-Proxy-Type
X-CCDN-CacheTTL
X-VCT
X-Cs
X-Check-Cacheable
X-CSRF-TOKEN
X-Gateway-Cache-Key
X-Gateway-Request-Id
X-Gateway-Skip-Cache
True-Client-IP
Fastly-Drupal-Html
X-Amz-Meta-Cb-Modifiedtime
X-Gateway-Cache-Status
X-Via-JSL
X-Via-NSCOPI
X-Fpc
AMP-Access-Control-Allow-Source-Origin
X-API-Version
X-LB-ID
X-CS
X-TH-Server
X-Upstream-Ct
X-Proxy-CacheRZ
XkeyRZ
X-Upstream-Ht
X-ATG-Version
X-Cache-Type
X-B3-SpanId
X-Cache-ASPX
X-Nf-Request-Id
Uri
X-Contensis-Viewer-Groups
Eomportal-Instance
X-Varnish-Authentication
X-EC-Lua
X-Micro-Cache
M-TraceId
OT-Force-Account-Verify
Esi-Enabled
Ngx-Var-Key
X-Varnish-Beresp-TTL
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-PAYTM-SRV-ID
True-Client-Ip
X-CF-Lambda-Version
X-MSEdge-Features
X-APP-VERSION
X-MSEdge-Flight
Resin-Trace
X-CF-Lambda-Fn
XServer
X-Udemy-Cache-App-Namespace
Srv
Path
X-FPC
X-SIPLIST1
X-Cache-NGX
X-Request-URI
X-Lb-Id
IsBot
X-Fastly-Country-Code
X-MP-GENERATED-AT
Request-ID
YJS-ID
X-Info
X-Wikidot-Backend
CDN
N-Cache
X-Wikidot-Static-Cache
X-VCL-Version
X-CDN-Cache-Status
X-Orig-Expires
X-Datadome
X-Forwarded-Path
RNT-Time
RNT-Machine
X-Shop-Environment
X-Tenant
GeoIP-Country-Code
X-CLOUD-TRACE-CONTEXT
X-Bl-Debug
Location
LB
X-Service-Response-Time
X-Accel-Version
Sm-Log-Id
Server-Id
X-TX-ID
X-App-Name
X-MCACHE
X-Policy
X-Pod-Name
X-Ha-Backend
X-B3-Trace-ID
X-Cdn-Request-ID
X-Oss-Object-Type
X-Cache-Expires
X-Edge-POP
X-Datacenter
X-Oss-Request-Id
X-Oss-Hash-Crc64ecma
X-Oss-Storage-Class
Cross-Origin-Opener-Policy-Report-Only
HIT
X-RateLimit-Reset
Lb
X-WA
Servername
X-Oss-Server-Time
X-Akamai-Pragma-Client-IP
X-Cdn-Cache-Status
X-Via-PopV
X-Via-PopN
X-Via-PopH
X-SERVER-NAME
X-Snapshot-Date
Ohc-File-Size
X-Geo
Timeexpire
X-Cache-Ttl
X-Srcache-Store-Status
X-Srcache-Fetch-Status
Hit
X-CACHE-KEY
FSS-Cache
X-NC
Traceparent
X-Cdn-Diag
X-TraceId
X-Ctl-Mach
X-Vcache
X-Scheme
Epwk-X-Cache
Req-ID
Proxy-Connection
X-Moov-Xdn-Version
X-Moov-T
X-Logging-Id
ENV
Yjs-Id
X-ServedByHost
Pramga
X-Amz-Meta-Opti
X-Hyper-Cache
X-Viewer-Country
X-LiteSpeed-Cache-Control
X-Serial
X-Container-Uri
X-UP
WZWS-RAY
Geoip-Latitude
X-ApacheServer
X-Cdn-Forward
X-PERF
X-Git-Commit
X-Dw-Trace-Id
X-MiniProfiler-Ids
X-M-Reqid
X-M-Log
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-Acquia-Site
X-RAMCache
X-Acquia-Purge-Tags
X-Qnm-Cache
X-Acquia-Application-UUID
X-Acquia-Application-Trace
X-B3-Parentspanid
X-Tncms
X-Mg-Cache
Cneonction
X-VG-WebCache
XM
X-Lb-Nocache
Ec-Rule-Version
Content-Script-Type
Content-Style-Type
X-Fastly-Backend-Reqs
X-Swift-Error
X-F-Status
X-TT-LOGID
X-Lsadc-Cache
CountryCode
X-Wp-Cf-Super-Cache-Cache-Control
X-Wp-Cf-Super-Cache
X-IPS-Cached-Response
X-Litespeed-Cache-Control
Ngx
X-B3-ParentSpanId
Warning
MIME-Version
X-Iauth-Set-Uid
My-App
X-Th-Server
Ohc-Cache-HIT
X-Webstats-RespID
X-Mid-Debug-Cache-Disk
X-Vgn-Hpd-Reason
X-LiteSpeed-Tag
Powered-By
X-Mid-Debug-Cache-Key
X-Fastly-Cache-Hits
X-NAPM-TraceId
Inserted-Into-Cache-At
X-Request-URL
X-Cache-Ngx