Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Accept-Ranges
Expect-CT
Pragma
X-Powered-By
CF-RAY
X-XSS-Protection
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-Xss-Protection
X-UA-Compatible
P3P
X-Served-By
X-Download-Options
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
CF-Ray
X-Adblock-Key
Access-Control-Allow-Credentials
X-Request-Id
X-Request-ID
X-Permitted-Cross-Domain-Policies
X-AspNet-Version
Alt-Svc
Content-Security-Policy-Report-Only
X-Runtime
X-DNS-Prefetch-Control
X-Drupal-Cache
X-Check
X-Cache-Status
X-Generator
X-Cacheable
P3p
Timing-Allow-Origin
X-FRAME-OPTIONS
X-Iinfo
X-Envoy-Upstream-Service-Time
X-Content-Security-Policy
X-Drupal-Dynamic-Cache
Feature-Policy
Content-Encoding
Upgrade
Status
Access-Control-Expose-Headers
X-AspNetMvc-Version
X-CDN
X-Ua-Compatible
Access-Control-Max-Age
X-Via
Server-Timing
X-UA-Device
X-Robots-Tag
Request-Context
X-Turbo-Charged-By
X-Cache-Group
X-Amz-Request-Id
EagleId
X-Amz-Id-2
X-Backend
Keep-Alive
X-AH-Environment
X-Proxy-Cache
X-Ws-Request-Id
X-Server
X-Age
Host-Header
X-Hacker
Cf-Edge-Cache
X-Vhost
X-Server-Powered-By
X-Rq
Allow
X-Dispatcher
X-Varnish-Cache
Grace
X-Amz-Version-Id
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-LiteSpeed-Cache
X-OneAgent-JS-Injection
X-WebKit-CSP
Accept-CH
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Device
Cf-Apo-Via
X-Page-Speed
Cf-Railgun
X-Aws-Lambda-Call-Status
X-Host
X-Server-Id
X-Pingback
X-Node
X-Cache-Spec
X-Nginx-Cache-Status
X-Akam-SW-Version
Surrogate-Control
X-Dns-Prefetch-Control
X-Backend-Server
EagleEye-TraceId
Request-Id
X-Cache-Lookup
X-Readtime
X-Ruxit-JS-Agent
X-HW
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Cloud-Trace-Context
X-Content-Security-Policy-Report-Only
X-Trace
X-Application-Context
X-Response-Time
X-CST
Permissions-Policy
Accept-Ch-Lifetime
X-Mod-Pagespeed
X-Nginx-Upstream-Cache-Status
Fastly-Restarts
X-Edge
Accept-CH-Lifetime
X-Country
Content-Location
X-Content-Type
X-WebKit-CSP-Report-Only
X-Mcache
X-ECACHE
Rating
X-Url
X-MS-InvokeApp
X-Clacks-Overhead
X-TtlSet
X-Amz-Server-Side-Encryption
X-Vname
X-PC
X-Midtier
X-VARITI-CCR
RTSS
X-Vcap-Request-Id
Cache-Tag
X-Varnish-TTL
X-Ac
X-Element-Page-Cache
Verso
X-B3-TraceId
X-Exp-Variant
X-Cdn-Fetch
X-Exp-Id
X-GoogleNews-Bot
X-Kinja-Revision
Origin-Trial
X-Use-Magma
X-Kinja-Build
X-Kinja
X-Kinja-Server
X-Server-Name
X-Rack-Cache
X-D2id
X-Cnection
X-Litespeed-Cache
X-Cache-TTL
X-Powered-By-Plesk
Service-Worker-Allowed
X-ESI
Xkey
X-Client-IP
X-Abt-Application-Version
X-Fastcgi-Cache
X-Navigation-Version
Edge-Control
X-SharePointHealthScore
X-NWS-LOG-UUID
SPRequestGuid
X-GitHub-Request-Id
X-Amz-Rid
X-Cached
X-Ttl
X-Mg-S
X-Px
X-Instrumentation
X-Erf-Bev-Bev-Is-Generated
X-Browser-Type
X-Erf-Bev-Bev
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
Arr-Disable-Session-Affinity
SPIisLatency
SPRequestDuration
X-Correlation-Id
X-Upstream
X-Cache-Key
X-Sol
Display
Pagespeed
X-Middleton-Display
Content-MD5
X-Dw-Request-Base-Id
X-SRCache-Fetch-Status
X-SRCache-Store-Status
Access-Control-Request-Method
X-Goog-Hash
X-RateLimit-Remaining
X-XRDS-Location
X-Daa-Tunnel
Edge-Cache-Tag
Front-End-Https
X-NF-Request-ID
X-Country-Code
Public-Key-Pins
X-Version
X-Forwarded-For
AR-SID
AR-Request-ID
AR-CACHE
AR-PoweredBy
AR-ATIME
X-Powered-CMS
X-Id
TCN
X-HP-Trace-Id
X-Jurisdiction
X-HP-Webp
X-MSEdge-Ref
X-T
X-Recruiting
X-Content-Digest
X-Accel-Expires
X-Middleton-Response
Response
Mrf-Cache-Status
X-B3-TraceId-Primal
MRF-Tech
X-Ser
X-Shield-Request-Id
TP-L2-Cache
TP-Cache
S
X-Hits
X-Amzn-Trace-Id
Nginx-Cache
X-Request-Received
X-Request-Processing-Time
X-Kinsta-Cache
X-Edge-Location-Klb
Cache-Status
Server-Node
X-Distributor
X-HS-Content-Id
X-HS-Combine-CSS
X-HS-Hub-Id
X-HS-Cache-Config
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Fastly-Request-ID
X-TEC-API-VERSION
X-Grace
Alternate-Protocol
Cache-Tags
MicrosoftSharePointTeamServices
Server-Name
Fastcgi-Cache
X-Protected-By
X-DataDome
X-TTL
X-DIS-Request-ID
X-Ezoic-Cdn
X-Geo-Country
X-Ruxit-Js-Agent
X-Origin-Server
X-LB-Cache
X-Frontend
X-Request-Handler-Origin-Region
X-Microsite
X-Ua-Browser
X-Ratelimit-Limit
X-Debug-Info
X-Rid
Cross-Origin-Opener-Policy
Healthy
X-NGENIX-Cache
Filterid
X-Git-Hash
Payment
X-Forwarded-Proto
X-Www-Served-By
X-Varnish-Backend
X-FB-Debug
X-Page-Id
Cleartype
X-Logged-In
X-Ratelimit-Reset
X-B3-Sampled
X-Load-Cache
Charset
Content-Disposition
X-VCache
X-Webkit-Csp
X-ASPNET-VERSION
X-PressLabs-Stats
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Origin-Cache
X-LLID
X-Cluster-Name
MS-Author-Via
X-Oracle-Dms-Rid
X-Oracle-Dms-Ecid
DC
X-Hostname
X-GUploader-UploadID
X-Goog-Metageneration
X-Ratelimit-Remaining
Accept-Charset
X-RateLimit-Limit
X-Upgrade-Enabled
Access-Control-Allow-Method
Retry-After
Cross-Origin-Resource-Policy
X-Proxy
X-F-Cache
X-Contextid
X-Flags
X-Hosted-By
X-Az
X-AppVersion
X-Seen-By
X-Activity-Id
X-Amz-Replication-Status
X-Type
X-Request-Guid
X-Providence-Cookie
X-Revision
X-Route-Name
X-Signature
X-B-Cache
X-Is-Crawler
X-Aspnet-Duration-Ms
Accept-Ch
X-Wix-Request-Id
X-TT
X-B
X-Varnish-Server
X-Azure-Ref
X-Whom
Referer-Policy
X-Amz-Meta-S3cmd-Attrs
Amp-Access-Control-Allow-Source-Origin
X-App-Environment
Viewport
Surrogate-Key
Paypal-Debug-Id
X-DynaTrace
X-Source
X-Aspnetmvc-Version
Count-Hit
X-Fb-Rlafr
Realpath
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Akamai-Edgescape
X-App-Server
X-Mobile
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-ORACLE-DMS-RID
X-B3-Traceid
X-ORACLE-DMS-ECID
Host
X-FastCGI-Cache
X-Cache-Control
X-EdgeConnect-Cache-Status
X-Cache-Age
X-HTML-Minification-Powered-By
Version
X-N
X-Response-Served-From
X-Original-Request-Id
Refresh
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Nginx-Cache
X-Oneagent-Js-Injection
X-Varnish-Grace
X-Tumblr-User
X-Cache-Rule
X-Tumblr-Pixel-1
Section-Io-Cache
Access-Control-Request-Headers
VIX-Pulpo-Upstream-Status
X-Varnish-Age
SD-X-WS
X-Magnolia-Registration
VIX-Pulpo-Node
X-Envoy-Decorator-Operation
X-Page-View
X-Newrelic-App-Data
X-L-Path
X-Adobe-Loc
X-Cache-Expired-At
X-Cache-Status-Check
X-Environment-Context
X-Cache-Time
X-Adobe-Content
X-Cacheable-TTL
X-ProcessESI
X-Device-Type
X-Jobs
Protected
X-Is-Bot
X-Framework
X-G
NGB
MS-CV
Ms-Operation-Id
GEO-INFO
X-RemovedCookies
X-Rendered-As
X-UUID
X-RTag
X-Cache-Grace
X-Servername
X-Status
X-NYM-Debug-Backend
X-FW-Dynamic
X-Akamai-Request-ID2
X-Content-Powered-By
X-FW-Type
X-FW-Static
Url
X-FW-Server
X-FW-Hash
X-FW-Serve
Akamai-GRN
X-FW-Version
X-Http-Reason
X-Rule
X-Debug-IsConnected
X-Instance
X-User-Agent
X-Backend-Name
X-Debug-IsPreview
X-Yottaa-Metrics
X-CDN-Forward
X-Yottaa-Optimizations
X-Tb
X-Cache-Hit
X-Drupal-Cache-Contexts
CDN-RequestId
X-Drupal-Cache-Tags
X-Pinterest-Rid
SRV
X-Tt-Logid
Pinterest-Generated-By
Pinterest-Version
From-Origin
WPO-Cache-Message
WPO-Cache-Status
Country
X-Node-Name
Accept-Language
X-Region
Front
X-Trace-Id
X-URL
X-Real-IP
X-Time
X-VC-Cache
Fastly-Drupal-HTML
Backend
X-Fastly-Request-Id
Uber-Trace-Id
X-Mode
X-Template
X-Content-Options
X-Language
X-UPSTREAM-Address
Fastly-SIE
X-Cache-Operation
X-RN-RSRV
X-Rewrite-Enabled
X-Amzn-RequestId
X-Generation-Time
X-Amz-Apigw-Id
Filters
Fastly-SWR
Meta-Geo
X-Cache-TTL-Remaining
CDN-Uid
Webserver
CDN-CachedAt
X-Tumblr-Pixel-2
CDN-Cache
X-Web-Node
CDN-EdgeStorageId
Content-Secure-Policy
CDN-PullZone
CDN-RequestCountryCode
X-Section
X-Rocket-Nginx-Serving-Static
X-Proxy-Cache-Info
X-IPS-LoggedIn
X-Format
Cross-Origin-Window-Policy
X-Cache-Action
X-Adobe-Source
Apigw-Requestid
X-Say-Cacheable
X-Say-TTL
X-SayCDN-TTL
X-Cache-Server
Azure-InstanceId
Azure-RegionName
X-Sql-Count
X-Sql-Duration-Ms
X-WP-CF-Super-Cache-Cache-Control
X-Proxy-Cache-Status
Azure-SiteName
X-Cms-Context
X-Access
CF-IPCountry
Azure-Version
Azure-SlotName
X-WP-CF-Super-Cache
Cache-Name
ServerID
X-GeoCode
X-PHP-Host
X-Zen-Fury
X-UA-Device-Type
X-VWS-Id
X-Cache-Host
X-ProxyCache-Key
X-ProxyCache-Status
X-Skip-Cache
X-Soup
X-Debug
X-Via-Fastly
X-Varnish-Beresp-Grace
X-Edge-Location
X-Content-Age
X-Cluster
X-BYPASS-REASON
X-Forwarded-Host
X-GeoCountry
X-PHP-Backend
X-Ms-Version
X-Ms-Request-Id
X-LJ-Flow-ID
X-AWS-Id
X-Labrador-Cache-Channel
Node
X-DynaTrace-JS-Agent
X-Sucuri-ID
X-JoinUs
X-Urbn-Context-Path
X-Detected-As
X-Sucuri-Cache
Property-Id
TWC-GeoIP-Country
TWC-GeoIP-LatLong
TWC-Device-Class
TWC-Connection-Speed
X-LAGOON
X-Cluster-Node
X-No-Session
X-Site-Version
X-SaId
X-Zipkin-Id
X-Xfnlog-Site
X-Urbn-Site-Id
X-Routing-Service
Web-Mar-Node
TWC-Locale-Group
X-IPLB-Request-ID
X-IPLB-Instance
X-Proxied
X-Reqid
X-Extlb
Webcakes-App-Version
X-Server-W
X-Origin-Hint
Locale
Webcakes-Region
X-Locale
X-Unique-Id
Webcakes-App-Name
TWC-Privacy
Onion-Location
X-Timing-Wait
WP-Super-Cache
X-LSADC-Cache
X-Amzn-Remapped-Content-Length
S-Rt
X-Proxy-Build
X-Proto
X-R9-Blue-Green-Version
X-Handled-By
Mn-Server-Ip
Selected-Fe
Mime-Version
DB-Nickname
X-SRV
Fastcgi-Useragent
X-FB-TRIP-ID
Xserver
X-Request-Time
Cache-Hits
X-Cache-Debug
X-Ua
X-Redis-Cache
Liferay-Portal
X-Hl-Ver
ServedBy
X-TIME
X-Tumblr-Pixel-3
X-XRDS-LOCATION
X-Optimistic-Header
Upgrade-Insecure-Requests
X-Loop
X-TNCMS
X-NWS-UUID-VERIFY
Source
X-GEO
X-Generated-By
Countrycode
X-Mg-Request-UUID
X-Origin-Date
X-Varnish-Hits
X-Tid
X-Air-Trace-Id
X-Air-Hostname
X-Air-Source
CF-Cached-On
X-Tec-Api-Version
X-Storage
X-Tec-Api-Origin
X-Times
X-Uri
X-Tec-Api-Root
X-Director
X-Varnish-Beresp-Ttl
X-CACHE-AGE
X-Akamai-Transformed
X-Tx-Id
X-Cdn
X-COUNTRY
X-TA-CDN-Provider
Xet-Cookie
X-Pass-Why
Frame-Options
X-Trace-ID
X-Server-ID
X-Origin-TTL
X-Newrelic-Synthetics
X-Origin-CC
X-ARC
X-Presslabs-Stats
X-DC
X-B3-Spanid
X-Service
X-FireWall-Port
X-ECache
X-AIR-PT
X-App-Version
X-Esi
Environment
X-ShardId
X-Alternate-Cache-Key
SID
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Shopify-Stage
X-ShopId
X-Varnish-Cache-Hits
X-Storefront-Renderer-Rendered
X-Varnish-Hostname
Server-Info
Origin
X-ScT
Redirect-Candidate
X-Request-Host
X-Vdms-Version
X-Vdms-Path
X-TIM-N
X-SRCache-Key
Gannett-Cam-Experience-Id
DCR-Decision-By
DCR-Processing-Time-Ms
Candidate-Md5Url
BehaviorPad-Version
Xc-Version
A
Edge-Cache
Rendered-Blocks
Meta-Geo-Continent
Ngx.Var.Host
MD5-Digest
Lang
X-VG-TLSProxy
Odigeo-Trace-Id
Req-Svc-Chain
X-A-Wwc
X-Aed
X-Application
X-A-Dgt
X-A-Dcw
X-A-Dam
X-Ec-GeoHdr
X-Ec-Fail
X-B-Cookie
X-Developer
X-D
X-Datadog-Trace-Id
X-Cache-Info
X-BCube-Filmed-By
X-Bc-Bl
X-Destination
X-BBC-Edge-Cache-Status
X-Epic-Correlation-Id
X-A-Ccd
X-Platform-Processor
X-Cache-NE
X-Platform-Cluster
X-Platform-Router
X-Processor
X-S-Cookie
X-S
X-Rojux
X-Mobile-URL
Sslversion
X-External-Request-Id
WWW-Authenticate
X-A
X-Loc
T-Server
X-Mid
Surrogated-Key
X-S-Maxage
Release
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
X-Datadog-Sampled
X-ServerID
Fastly-GeoIP-CountryCode
X-WP-CF-Super-Cache-Active
X-Old-Content-Length
X-WA-Info
X-Varnish-Remaining-TTL
X-Origin-Time
X-Origin-Response-Time
X-VServer
X-WADP-Cache
X-Nyt-Route
Cache-Tv-Group
Cluster
Click-Count-Error
Click-Count-Action-Start
Decoy-Debug-Key
Decoy-Debug-Status
Magicmarker
X-NodeID
DSUID
Decoy-Debug-TTL
X-Akamai-Device-Characteristics
Memcached
X-Sigma-Backend
X-SB
X-Sn-Servicetimems
X-Rocket-Build-Number
X-Sigma
X-Pubstack
X-SD-PageType
X-Served-From
State
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
Vix-Hermes-Req-Id
X-Platform-Server
X-Varnish-CookieHashed-On
X-Cache-Bucket
Tube-Return
Tube-Got-Results
X-Req
Tube-Get-Contents
Tube-Got-Eval
X-Varnish-CookieINHashed-On
Country-Code
X-GeoIP-City
X-Fmm-Version
X-DefHash
X-Cdn-Origin
X-We-Are-Hiring
Apple-News-Services-Host
X-CUA
X-Endurance-Cache-Level
X-DefElseHash
X-INCAP-ABP
X-Gdpr
X-Core-Mission
X-Gamma-Serve
X-Clara-WADP
X-Frame-Option
Apple-News-Services-Parsed-Url
Apple-News-Services-Handled
Cache-Host
Apple-News-Services-Request-Url
X-Httpd
X-Ec-Custom-Error
C-Via
X-Human
X-Parent-Response-Time
Section-Io-Id
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
X-Pool
X-Fetched-On
X-Fastly-Backend
We-Hiring
X-Dispatcher-Number
User-Cache-Control
X-Request-Start
X-DPWN-IS-SECURE
X-Date
Svr
Ssr
X-Planisys-CDN-Cache
X-CSRF-Token
X-App
X-Node-Id
X-Hnp-Log
X-Scale
X-Minions-Version
X-Cache-FS-Status
X-Bip
X-Cache-Id
X-LB-NoCache
X-Hash
X-Gzip
X-Block-Status
X-Planisys-CDN-Rules
X-GeoIP
X-Gen-Mode
X-Accel-Buffering
X-Accel-Expires-Debug
X-GeoIP-Region-Code
X-GeoIP-Country-Code
X-Origin
X-Ad-Defer-Variation
X-Planisys-CDN-TTL
X-Thanos
X-Vmg-Version
CDCHOST
X-Wix-Viewer-Type
X-Location
X-Buckets
Is-Eu
X-Restarts
L
Kp-EeAlive
X-Cdn-Srv
X-JWT-State
X-Is-Gdpr
Cmstype
Cmsid
X-Developers
CloudFront-Viewer-Country
TDXMobile
X-Geo-Header
Host-ID
Thinkindot-CacheControl-Type
Sever-Int
X-Has-Esi
X-Test
Thinkindot-Control
Platform
Pics-Label
X-CMSURLCustom
X-Esi-Check
Producers
X-Auto-Login
Server-Hostname
Server-Ext
Adler-Geo
X-Slack-Backend
Origin-EX
Origin-CC
X-Variation
X-Varnish-Beresp-Status
X-Thinkindot-L3
Mail-Subject
X-Core-Value
X-Var-Ttl
X-Up
Cache-Key
Cache-Provider
NM-Fastcgi-Cache
Thinkindot-CacheControl
Cdn
X-RM-Cache-TTL
X-Generated-On
X-Level-Front-Cache
X-Conf
AKAMAI
X-HS-Content-Campaign-Id
X-Forwarded-Site
X-Worker
X-Nananana
X-Nginx-Cache-Key
X-Qloud-Router
X-Platform
X-VarnishDD-TTL
X-Varnishpool
X-Refresh
X-V-Cache
X-Server-IP
X-Slack-Shared-Secret-Outcome
X-Region-Sid
X-Owner
X-Op-Id-All
X-Mvc-Supplant-Cachable
X-Irp-Debug
Web-Mar-Region
X-HN
X-NCache
Server-Host
CacheControlHeader
Fastly-Backend-Name
Gh-Request-Id
X-Cache-Backend
X-FC-Vary-Parameters
X-Azure-Ref-OriginShield
X-CacheTTL
X-Ckpd-Fst-Backend
Fastly-SSL
Machine
PFcat
X-Aicache-OS
Wxu-Next-Region
Wxu-Next-Hostname
Wxu-Next-Commit
Datacenter
X-Cache-Tags
X-Device-Os
X-Dispatcher-Server
HostName
X-Tb-Optimization-Total-Bytes-Saved
HA-Ipaddr
X-Via-Poph
X-Men
On-Server
X-Varnish-Ttl
X-Eu-Site
NGX
X-Via-Popn
L5d-Success-Class
X-Via-Popv
Ha-Gx-Prefs
X-Csrf-Jwt
X-Org
X-CGP
X-Cache-Remote
Canary
X-Cached-By
X-Webkit-CSP-Report-Only
Cdnsip
X-HA-Backend
X-Mvc-Supplant-OutputCached
X-AK-Request-ID
GeoIP-Latitude
X-Servedbyhost
X-VC
Env
Cdncip
X-Cache-Date
X-API-Version
Server-ID
X-Gateway-Request-Id
X-Microcachable
X-LB-ID
X-Gateway-Cache-Key
X-RCS-CacheZone
X-Gateway-Skip-Cache
X-Gateway-Cache-Status
Cache
X-Wa
X-ZONE
X-Mly-Id
X-Fpc
X-APP-VERSION
X-Zone
X-Vgn-Hpd-Variations-Key
X-Vgn-Hpd-Ssi
X-DataCenter
X-Generated-In
Time
X-Vgn-Hpd-Cached
Memory
X-Webkit-CSP
Request-ID
X-Fastly-Cache
X-Nc
OT-Force-Account-Verify
Eomportal-Instance
X-Micro-Cache
Ngx-Var-Key
Load-Balancing
X-Via-NSCOPI
X-ND-Cache
X-Instance-Name
X-HS-Status
X-Origin-Expires
X-Correlation-ID
X-Response-By
IsBot
X-Vc
X-SIPLIST1
X-Release
X-Request-URI
X-Client-Ip
X-Check-Cacheable
X-Via-JSL
Srv
X-Nf-Request-Id
Locid
X-Info
X-VCL-Version
X-FL-EDGE
X-Cache-NGX
X-Hcs-Proxy-Type
X-FL-QIT-DEBUG
X-CCDN-CacheTTL
X-CCDN-Origin-Time
X-From
Srvid
Expect-Staple
NtCoent-Length
X-NewRelic-App-Data
AMP-Access-Control-Allow-Source-Origin
X-Via-CDN
X-Cache-Enabled
Hostname
X-Srv
True-Client-Ip
X-CS
X-Via-Edge
X-Via-SSL
X-MCACHE
Edge-Copy-Time
X-Edge-Pop
X-CSRF-TOKEN
X-Provided-By
GeoIp-Country-Code
X-Proxy-CacheRZ
XkeyRZ
X-Amz-Meta-Cb-Modifiedtime
X-NGINX-Cache
X-Lambda-Id
Location
Path
X-Cache-Expires
GeoIP-Country-Code
Uri
X-EC-Lua
X-Dc
X-Api-Version
X-Oss-Storage-Class
Sid
X-Edge-POP
X-Oss-Request-Id
X-Vcl-Version
Resin-Trace
True-Client-IP
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
X-Oss-Server-Time
X-Debug-Cache-Store
X-Debug-Cache-Fetch
X-RateLimit-Reset
X-Cs
CPC-Cache
CPC-Age
Servername
X-Fastly-Country-Code
Cross-Origin-Opener-Policy-Report-Only
VNS-Cache
X-Vtex-Remote-Cache
X-Render-Time
VNS-Age
X-NODE
X-B3-SpanId
X-Moov-T
X-Moov-Xdn-Version
Traceparent
X-Air-Pt
Fastly-Drupal-Html
X-Viewer-Country
X-CLOUD-TRACE-CONTEXT
X-TH-Server
X-Scheme
CDN
X-VCT
LB
X-Webkit-Csp-Report-Only
X-ApacheServer
X-Cdn-Request-ID
X-PERF
X-ATG-Version
X-TX-ID
Rip
Timeexpire
X-Pod-Name
Powered-By
X-Contensis-Viewer-Groups
FSS-Cache
X-MSEdge-Features
X-MSEdge-Flight
X-Varnish-Authentication
X-NAPM-TraceId
X-Cache-ASPX
Esi-Enabled
X-Varnish-Beresp-TTL
X-Akamai-Pragma-Client-IP
CountryCode
X-Datadome
M-TraceId
X-Datacenter
X-FPC
X-Cdn-Cache-Status
X-Accel-Version
YJS-ID
X-WA
X-Service-Response-Time
Sm-Log-Id
True-Client-Country-4JS
V-Age
X-CF-Lambda-Version
Tracecode
X-PAYTM-SRV-ID
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-Clientip
X-CF-Lambda-Fn
X-SERVER-NAME
X-Github-Request-Id
XServer
X-Cache-Type
X-Geo
X-NC
X-Srcache-Store-Status
X-CACHE-KEY
X-Srcache-Fetch-Status
HIT
XM
X-LiteSpeed-Cache-Control
X-VG-WebCache
Proxy-Connection
X-Udemy-Cache-App-Namespace
Server-Id
Ohc-File-Size
X-Lb-Id
X-Upstream-Ct
X-Upstream-Ht
ENV
X-Wikidot-Backend
N-Cache
RNT-Machine
RNT-Time
X-Wikidot-Static-Cache
X-B3-Parentspanid
Ngx
X-ServedByHost
X-TraceId
X-CDN-Cache-Status
X-Forwarded-Path
X-Orig-Expires
X-Ha-Backend
X-Shop-Environment
Geoip-Latitude
X-Rebelmouse-Surrogate-Control
X-Cdn-Forward
Yjs-Id
Epwk-X-Cache
X-Rebelmouse-Cache-Control
X-Bl-Debug
X-Tenant
X-Hyper-Cache
WZWS-RAY
X-Serial
X-Fastly-Backend-Reqs
X-Via-PopH
X-Cdn-Diag
Ec-Rule-Version
X-Connection-Hash
Content-Style-Type
X-Swift-Error
Pramga
Req-ID
Expiry
Content-Script-Type
X-MiniProfiler-Ids
X-Dw-Trace-Id
X-Via-PopN
X-MP-GENERATED-AT
X-B3-Trace-ID
X-B3-ParentSpanId
X-Via-PopV
Inserted-Into-Cache-At
X-Vgn-Hpd-Reason
User-Agent
X-Lb-Nocache
X-TT-LOGID
X-Lsadc-Cache
X-F-Status
X-M-Log
Lb
X-Amz-Meta-Opti
X-M-Reqid
X-Qnm-Cache
X-UA
X-Webstats-RespID
Cneonction
MIME-Version
My-App
X-UP
X-Cache-Ngx
X-IPS-Cached-Response
Warning
X-Request-URL
X-Mid-Debug-Cache-Key
X-Th-Server
X-Akamai-ERRuleID
X-Akamai-ERPolicy
X-Yottaa-OS
X-Stale
X-Mid-Debug-Cache-Disk
X-LiteSpeed-Tag
X-Snapshot-Date