Threat Level: green Handler on Duty: Rick Wanner

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
Strict-Transport-Security
X-Frame-Options
X-Content-Type-Options
Last-Modified
Link
CF-Cache-Status
Cf-Request-Id
Accept-Ranges
ETag
CF-RAY
Expect-CT
Pragma
X-Powered-By
X-Cache
Via
Age
X-XSS-Protection
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Xss-Protection
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-FRAME-OPTIONS
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Request-Id
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-Adblock-Key
X-AspNet-Version
X-Permitted-Cross-Domain-Policies
Alt-Svc
X-Runtime
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Cache-Status
X-Generator
CF-Ray
X-Cacheable
X-Request-ID
X-Iinfo
Timing-Allow-Origin
X-Envoy-Upstream-Service-Time
Feature-Policy
X-Ua-Compatible
Status
X-Content-Security-Policy
X-Drupal-Dynamic-Cache
Content-Encoding
X-AspNetMvc-Version
Access-Control-Expose-Headers
X-CDN
Upgrade
X-XSS-PROTECTION
Access-Control-Max-Age
X-Via
X-Cache-Group
X-Robots-Tag
Server-Timing
Request-Context
X-UA-Device
Keep-Alive
X-Amz-Request-Id
X-AH-Environment
X-Dns-Prefetch-Control
X-Turbo-Charged-By
X-Proxy-Cache
X-Backend
X-Amz-Id-2
X-Ws-Request-Id
X-Age
Host-Header
P3p
X-Server-Powered-By
X-Hacker
X-Server
X-Rq
X-Vhost
EagleId
X-Varnish-Cache
Grace
X-Amz-Version-Id
X-Dispatcher
X-LiteSpeed-Cache
Cf-Edge-Cache
Allow
X-Akamai-Path-Stats
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Swift-SaveTime
X-Swift-CacheTime
X-Device
Ali-Swift-Global-Savetime
X-WebKit-CSP
X-Nginx-Cache-Status
X-Page-Speed
X-Aws-Lambda-Call-Status
X-Host
Accept-CH
X-Node
X-OneAgent-JS-Injection
X-Pingback
Cf-Railgun
X-Cache-Spec
Request-Id
EagleEye-TraceId
X-Server-Id
Surrogate-Control
X-Akam-SW-Version
X-Backend-Server
X-Cache-Lookup
X-Response-Time
X-Readtime
Accept-CH-Lifetime
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-HW
Content-Location
X-Content-Security-Policy-Report-Only
X-Application-Context
Rating
X-Trace
X-Cloud-Trace-Context
Fastly-Restarts
X-Country
X-Url
X-WebKit-CSP-Report-Only
X-Clacks-Overhead
X-Edge
X-MS-InvokeApp
Accept-Ch-Lifetime
X-Amz-Server-Side-Encryption
X-Rack-Cache
Edge-Control
X-Nginx-Upstream-Cache-Status
X-Ruxit-JS-Agent
X-B3-TraceId
X-Vname
X-TtlSet
X-PC
X-Content-Type
X-Mod-Pagespeed
X-ESI
X-Vcap-Request-Id
X-Cdn-Fetch
X-Kinja-Build
X-Oneagent-Js-Injection
X-Kinja-Revision
X-Kinja-Server
X-Use-Magma
X-Kinja
X-GoogleNews-Bot
X-D2id
X-Exp-Id
X-Exp-Variant
Xkey
X-Mcache
X-GitHub-Request-Id
X-Amz-Rid
X-CST
Verso
Cache-Tag
X-VARITI-CCR
X-Powered-By-Plesk
RTSS
X-Varnish-TTL
Service-Worker-Allowed
X-FastCGI-Cache
X-Upstream
X-Navigation-Version
X-Ruxit-Js-Agent
X-Abt-Application-Version
X-Version
X-Cached
X-ECACHE
X-Client-IP
X-Cnection
X-Dw-Request-Base-Id
X-Ac
X-Px
X-Ttl
X-Element-Page-Cache
X-Instrumentation
X-Kraken-Loop-Name
X-Server-Name
X-Server-Lifecycle-Phase
Arr-Disable-Session-Affinity
Public-Key-Pins
SPRequestGuid
X-SharePointHealthScore
X-Cache-TTL
SPIisLatency
SPRequestDuration
X-Middleton-Display
Pagespeed
Display
X-Sol
X-NWS-LOG-UUID
X-Country-Code
Permissions-Policy
X-Ser
Accept-Ch
X-Cache-Key
X-RateLimit-Remaining
X-Middleton-Response
X-Midtier
Response
X-Kinsta-Cache
X-Edge-Location-Klb
X-Goog-Hash
X-Forwarded-For
Content-MD5
X-SRCache-Store-Status
X-SRCache-Fetch-Status
Access-Control-Request-Method
X-NF-Request-ID
X-DataDome
Front-End-Https
X-Shield-Request-Id
X-Correlation-Id
X-MSEdge-Ref
Cf-Apo-Via
X-HP-Webp
X-Jurisdiction
X-HP-Trace-Id
TP-Cache
AR-ATIME
AR-PoweredBy
AR-CACHE
AR-SID
Edge-Cache-Tag
X-Recruiting
AR-Request-ID
TP-L2-Cache
Nginx-Cache
X-T
X-Accel-Expires
MicrosoftSharePointTeamServices
X-Daa-Tunnel
Mrf-Cache-Status
MRF-Tech
X-B3-TraceId-Primal
X-RateLimit-Limit
X-Powered-CMS
X-ORACLE-DMS-ECID
TCN
X-ORACLE-DMS-RID
X-Grace
X-Mg-S
X-Id
X-Content-Digest
X-Hits
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Cache-Config
Server-Node
X-HS-Combine-CSS
Server-Name
Filters
X-Request-Processing-Time
X-Request-Received
X-Amzn-Trace-Id
X-Frontend
MS-Author-Via
X-Geo-Country
X-Distributor
S
Fastcgi-Cache
X-Protected-By
X-LLID
X-Language
Cache-Status
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Browser-Type
X-Fastly-Request-Id
X-XRDS-Location
X-PressLabs-Stats
X-LB-Cache
X-Origin-Server
Cross-Origin-Opener-Policy
Count-Hit
X-Ezoic-Cdn
X-Fastcgi-Cache
X-Forwarded-Proto
X-F-Cache
Host
X-FB-Debug
X-B3-Sampled
Charset
X-Ab
X-Amz-Meta-S3cmd-Attrs
X-Ua-Browser
X-Seen-By
X-Page-Id
X-Git-Hash
Filterid
Payment
X-Request-Handler-Origin-Region
X-Microsite
X-Litespeed-Cache
X-Cache-Age
X-VCache
X-Cluster-Name
X-ASPNET-VERSION
X-Ratelimit-Reset
Surrogate-Key
X-TTL
Realpath
X-Rid
Accept-Charset
X-Origin-Cache
Cache-Tags
X-Template
X-NGENIX-Cache
Alternate-Protocol
Access-Control-Allow-Method
X-Www-Served-By
Retry-After
X-Webkit-Csp
X-Logged-In
X-Activity-Id
X-AppVersion
X-DynaTrace
X-Az
Cleartype
X-Upgrade-Enabled
X-DIS-Request-ID
X-Route-Name
X-Varnish-Backend
X-Request-Guid
X-Is-Crawler
X-App-Environment
X-Amz-Replication-Status
X-Tb
X-Aspnet-Duration-Ms
X-Flags
X-Providence-Cookie
X-Varnish-Grace
X-TT
X-B
X-Wix-Request-Id
X-Signature
X-B-Cache
X-Source
X-Type
X-Node-Name
X-Envoy-Decorator-Operation
X-Hostname
Paypal-Debug-Id
DC
ServerID
X-Drupal-Cache-Tags
Frame-Options
X-Revision
X-Debug
X-Fastly-Request-ID
X-Proxy
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Mobile
X-Contextid
X-Server-ID
X-Content-Options
X-Pinterest-Rid
Pinterest-Version
Amp-Access-Control-Allow-Source-Origin
Pinterest-Generated-By
X-Load-Cache
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Cache-Rule
X-Goog-Storage-Class
X-GUploader-UploadID
X-Goog-Metageneration
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Cache-Control
X-N
Country
X-Magnolia-Registration
Refresh
Node
X-Content
X-Response-Served-From
Referer-Policy
X-Whom
X-User-Agent
X-Original-Request-Id
X-EdgeConnect-Cache-Status
Viewport
NGB
X-L-Path
X-Cacheable-TTL
X-Environment-Context
X-Framework
Access-Control-Request-Headers
VIX-Pulpo-Node
Url
X-Cache-TTL-Remaining
X-Jobs
X-Mid
X-Debug-IsConnected
X-Adobe-Loc
X-Adobe-Content
X-Akamai-Request-ID2
Uber-Trace-Id
X-Debug-IsPreview
X-G
X-Page-View
VIX-Pulpo-Upstream-Status
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Content-Powered-By
X-Servername
X-Unique-Id
X-Real-IP
X-Cache-Grace
X-Rendered-As
X-Cache-Time
X-Is-Bot
X-NYM-Debug-Backend
X-Status
Content-Disposition
X-Varnish-Age
X-Varnish-Server
Akamai-GRN
Srv
X-Oracle-Dms-Rid
X-Instance
X-RemovedCookies
X-XRDS-LOCATION
X-ProcessESI
X-Oracle-Dms-Ecid
X-Ratelimit-Remaining
Countrycode
X-Time
X-Drupal-Cache-Contexts
Version
X-Mg-Request-UUID
X-COUNTRY
X-APP-VERSION
X-Restarts
X-Http-Reason
X-Cache-Expired-At
X-CDN-Forward
X-Via-JSL
X-App-Server
X-Trace-Id
Accept-Language
Healthy
X-Debug-Info
X-Cache-Hit
Protected
X-IPLB-Request-ID
X-Hosted-By
X-Tumblr-Pixel
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-IPLB-Instance
X-Tumblr-User
X-Cache-Operation
Cross-Origin-Resource-Policy
X-Azure-Ref
X-Nginx-Cache-Key
X-Tt-Logid
X-Ratelimit-Limit
X-Device-Type
X-Backend-Name
Section-Io-Cache
Content-Secure-Policy
X-Akamai-Edgescape
Liferay-Portal
X-ECache
Backend
X-FW-Type
Server-Info
X-FW-Static
X-FW-Server
X-FW-Dynamic
X-FW-Serve
Fastcgi-Useragent
X-FW-Hash
X-RTag
X-Cache-Action
MS-CV
Ms-Operation-Id
X-Api-Version
X-SRV
X-Mobile-URL
X-UPSTREAM-Address
X-Proxy-Cache-Status
X-Rule
Meta-Geo
Load-Balancing
X-RN-RSRV
GEO-INFO
X-VC-Cache
X-Mode
X-Cache-NGX
X-Storage
X-Varnish-Beresp-Grace
X-Content-Age
X-Uri
X-Redis-Cache
X-Proto
X-Urbn-Site-Id
X-Region
X-Labrador-Cache-Channel
X-Sql-Duration-Ms
X-Sql-Count
X-No-Session
X-LJ-Flow-ID
X-OCL
X-PCL
X-Varnish-Hostname
X-AWS-Id
X-Varnishpool
X-Cache-Enabled
Locale
X-SayCDN-TTL
S-Rt
X-PHP-Host
X-Adobe-Source
X-Say-TTL
X-Cms-Context
X-VWS-Id
X-Forwarded-Host
X-Handled-By
CF-IPCountry
X-Skip-Cache
X-Urbn-Context-Path
X-Site-Version
X-Edge-Location
X-Say-Cacheable
X-PHP-Backend
X-Via-Fastly
X-GeoCountry
X-Cache-Server
X-Cache-Type
X-BYPASS-REASON
X-Generation-Time
X-Access
X-Detected-As
X-Extlb
X-Hl-Ver
X-GeoCode
X-Generated-By
X-FB-TRIP-ID
X-HTML-Minification-Powered-By
X-Xfnlog-Site
Onion-Location
Web-Mar-Node
X-Section
Webcakes-App-Name
Webcakes-App-Version
X-Format
Webcakes-Region
X-Routing-Service
Property-Id
TWC-Privacy
X-Timing-Wait
X-Locale
X-Sorting-Hat-PodId
TWC-Device-Class
TWC-Connection-Speed
TWC-Locale-Group
TWC-GeoIP-LatLong
TWC-GeoIP-Country
Azure-Version
X-ServerID
X-ProxyCache-Status
X-Request-Time
X-UA-Device-Type
X-ProxyCache-Key
X-Proxy-Build
X-Web-Node
X-Shopify-Stage
Selected-Fe
X-Zipkin-Id
X-ShopId
Azure-RegionName
Azure-SiteName
Azure-SlotName
X-Sorting-Hat-ShopId
Azure-InstanceId
X-Origin-Hint
X-Varnish-Cache-Hits
X-ShardId
X-Proxied
X-Alternate-Cache-Key
CDN-RequestId
CDN-Uid
DB-Nickname
CDN-RequestCountryCode
CDN-PullZone
Apigw-Requestid
CDN-Cache
CDN-EdgeStorageId
Eomportal-Instance
CDN-CachedAt
Mn-Server-Ip
X-Cache-Status-Check
X-Server-W
X-Cache-Host
X-Tid
X-UUID
X-Nginx-Cache
X-SaId
WP-Super-Cache
X-R9-Blue-Green-Version
X-URL
X-Origin-Date
X-JoinUs
X-Ms-Request-Id
X-Ms-Version
X-Datadome
Cache-Name
X-Storefront-Renderer-Rendered
X-FireWall-Port
X-Correlation-ID
X-WP-CF-Super-Cache
X-DynaTrace-JS-Agent
X-WP-CF-Super-Cache-Cache-Control
ServedBy
X-Zen-Fury
X-Amzn-RequestId
X-Amz-Apigw-Id
Xserver
X-LSADC-Cache
X-Human
X-Varnish-Ttl
X-Loop
X-TNCMS
X-Ua
Cache
X-Debug-Cache
Xet-Cookie
Source
X-Cache-Tags
X-TA-CDN-Provider
X-Varnish-Hits
X-Reqid
X-Dc
X-GEO
X-RCS-CacheZone
X-App-Version
X-Pubstack
X-Cached-By
X-Soup
Origin
Cross-Origin-Window-Policy
X-Aspnetmvc-Version
SD-X-WS
X-MP-GENERATED-AT
X-Amzn-Remapped-Content-Length
X-Vgn-Hpd-Reason
X-Cdn
X-Newrelic-Synthetics
X-Webkit-CSP
X-Origin-CC
X-Origin-TTL
WPO-Cache-Message
WPO-Cache-Status
From-Origin
X-Tumblr-Pixel-2
X-Provided-By
X-Service
X-IPS-LoggedIn
LB
X-Varnish-Beresp-Ttl
X-AOL-HN
X-NewRelic-App-Data
Webserver
Rip
X-B3-SpanId
X-Via-NSCOPI
X-Tec-Api-Version
X-Tec-Api-Origin
X-Tec-Api-Root
X-GG-Cache-Date
X-Platform-Server
X-FW-Version
X-Request-Host
X-Processor
X-PBS-Appsvrname
Cdncip
DCR-Decision-By
A
Cdnsip
DCR-Processing-Time-Ms
BehaviorPad-Version
X-ScT
X-User
X-TIM-N
X-Vdms-Path
X-Vdms-Version
Xc-Version
X-VG-WebCache
X-Tenant
X-SRCache-Key
X-S
X-Rojux
X-S-Cookie
X-Owner
X-Shop-Environment
X-Served-From
X-Rewrite-Enabled
X-Forwarded-Path
X-Aed
X-AK-Request-ID
X-Application
X-A-Wwc
X-A-Dgt
X-External-Request-Id
X-Ec-GeoHdr
X-Ec-Fail
X-Developer
X-Cache-NE
X-D
X-Connection-Hash
X-BCube-Filmed-By
X-Bc-Bl
X-Destination
X-B-Cookie
X-A-Dcw
X-A-Dam
Lang
MD5-Digest
Meta-Geo-Continent
X-NAPM-TraceId
Host-ID
X-Orig-Expires
Expiry
Ngx.Var.Host
Odigeo-Trace-Id
X-A
X-A-Ccd
T-Server
Surrogated-Key
Rendered-Blocks
Sslversion
Environment
X-ARC
HostName
X-CSRF-Token
X-Cluster-Node
Mime-Version
X-VC
OT-Force-Account-Verify
X-B3-Traceid
CPC-Cache
X-Aicache-OS
VNS-Cache
VNS-Age
X-Thanos
X-Accel-Buffering
X-Bip
X-Parent-Response-Time
X-Pool
X-Qloud-Router
Machine
X-Dispatcher-Number
X-Level-Front-Cache
X-Generated-On
X-Varnish-Beresp-Status
Upgrade-Insecure-Requests
CPC-Age
Redirect-Candidate
X-TIME
X-CMSURLCustom
X-Clientip
X-Fmm-Version
X-Ckpd-Fst-Backend
X-Fetched-On
X-Eu-Site
X-Clara-WADP
X-Cluster
X-Epic-Correlation-Id
X-DefElseHash
X-DefHash
X-Device-Os
X-DPWN-IS-SECURE
X-Ec-Custom-Error
X-Datadog-Trace-Id
X-Csrf-Jwt
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
X-Esi-Check
X-Cache-Bucket
Tube-Get-Contents
Traceparent
Tube-Got-Eval
Tube-Got-Results
Tube-Return
Thinkindot-Control
Thinkindot-CacheControl-Type
Servername
State
TDXMobile
Thinkindot-CacheControl
V-Age
Vix-Hermes-Req-Id
X-Cache-Id
X-Forwarded-Site
X-Cache-Info
X-CacheTTL
X-Cdn-Origin
X-Branch-Name
X-BBC-Edge-Cache-Status
Wxu-Next-Commit
Wxu-Next-Hostname
Wxu-Next-Region
X-Ad-Defer-Variation
X-CGP
X-GeoIP
X-Sigma-Backend
X-Sigma
X-SIPLIST1
X-Slack-Backend
X-Sn-Servicetimems
X-Scale
X-SB
Cache-Hits
X-Rocket-Build-Number
X-Rocket-Nginx-Serving-Static
X-S-Maxage
X-SplitTest
X-SVT-ORM-RULES
X-VG-TLSProxy
X-Varnish-Remaining-TTL
X-VServer
X-WADP-Cache
X-Wix-Viewer-Type
X-Varnish-CookieINHashed-On
X-Varnish-CookieHashed-On
X-SVT-ORM-VERSION
X-Thinkindot-L3
X-V-Cache
X-Variation
X-Request-URI
X-Region-Sid
Server-Host
X-Gzip
X-Hash
X-Irp-Debug
X-Loc
X-GeoIP-City
X-Worker
X-Gateway-Cache-Key
X-Gateway-Cache-Status
X-Gateway-Request-Id
X-Gateway-Skip-Cache
X-Minions-Version
X-Mvc-Supplant-Cachable
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-Policy
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Planisys-CDN-Cache
X-Origin-Response-Time
X-Mvc-Supplant-OutputCached
X-NodeID
X-Optimistic-Header
X-Origin
X-Gamma-Serve
X-Core-Mission
Fastly-SSL
Fastly-SWR
Fastly-SIE
Fastly-GeoIP-CountryCode
Decoy-Debug-TTL
DSUID
Ha-Gx-Prefs
HA-Ipaddr
L5d-Success-Class
Memcached
L
Kp-EeAlive
Is-Eu
IsBot
Decoy-Debug-Status
Decoy-Debug-Key
Apple-News-Services-Parsed-Url
Cache-Host
Apple-News-Services-Host
Apple-News-Services-Handled
X-Cache-Debug
Adler-Geo
Canary
Candidate-Md5Url
Cmstype
Country-Code
Cmsid
Click-Count-Error
Click-Count-Action-Start
Mobile-Detection-Method
Apple-News-Services-Request-Url
Origin-EX
Origin-CC
Release
Producers
Platform
NM-Fastcgi-Cache
Req-Svc-Chain
X-WA-Info
CDCHOST
X-HS-Content-Campaign-Id
X-Hnp-Log
X-Has-Esi
X-INCAP-ABP
X-JWT-State
X-Is-Gdpr
User-Cache-Control
Svr
X-Core-Value
Fastly-Backend-Name
X-Proxy-Cache-Info
X-Viewer-Country
X-Origin-Time
X-Gen-Mode
X-Nyt-Route
X-Geo-Header
CloudFront-Viewer-Country
X-NCache
Server-Ext
Cluster
X-ZONE
X-Scheme
Datacenter
Gh-Request-Id
Web-Mar-Region
We-Hiring
Mail-Subject
Server-Hostname
X-Block-Status
X-Gdpr
Sever-Int
X-Cdn-Srv
X-Developers
NGX
X-Auto-Login
WebServer
X-Cache-Remote
Ec-Rule-Version
Cache-Tv-Group
X-WP-CF-Super-Cache-Active
X-Trace-ID
X-Tx-Id
X-Sucuri-ID
AKAMAI
X-LB-NoCache
X-Sucuri-Cache
X-FC-Vary-Parameters
X-Session-Fingerprint
X-Presslabs-Stats
X-ATG-Version
Fastcgi-Cache-TTL
X-Var-Ttl
X-Origin-Expires
Ssr
X-Fastly-Backend
X-Ua-Device
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-ND-Cache
X-Azure-Ref-OriginShield
Time
Memory
X-Fastly-Cache
X-Udemy-Cache-App-Namespace
Pics-Label
Sid
X-Newrelic-App-Data
X-Nf-Request-Id
X-Tb-Optimization-Total-Bytes-Saved
Fastly-Drupal-HTML
SID
X-Via-Popv
X-Pod-Name
X-Via-Poph
X-Via-Popn
X-Generated-In
X-NWS-UUID-VERIFY
Env
AMP-Access-Control-Allow-Source-Origin
X-Akamai-Transformed
Server-ID
X-Cache-Date
X-Servedbyhost
X-Refresh
X-Buckets
X-Ig-Push-State
X-Xrds-Location
X-DC
X-Cs
X-Edge-Pop
X-Conf
X-Release
X-Pass-Why
X-MSEdge-Features
X-EC-Lua
X-Microcachable
Fastly-Drupal-Html
My-App
X-Fpc
X-Up
X-Dispatch
X-NC
X-MSEdge-Flight
X-Tumblr-Pixel-3
X-Lambda-Id
X-RateLimit-Reset
X-Esi
X-Wa
X-Dmc
X-Endurance-Cache-Level
X-PX
CDN
X-MCACHE
X-ID
GeoIp-Country-Code
X-CS
X-TX-ID
X-Be
Magicmarker
True-Client-IP
X-Req
X-CACHE-AGE
X-VCL-Version
X-Zone
X-TRACE-ID
X-Webkit-CSP-Report-Only
X-NGINX-Cache
X-LB-ID
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-CACHE-KEY
X-Vc
X-Air-Trace-Id
CacheControlHeader
Hostname
X-Air-Source
X-CSRF-TOKEN
X-Air-Hostname
X-Hyper-Cache
X-Yandex-Sdch-Disable
X-TH-Server
X-B3-Spanid
X-Micro-Cache
X-Op-Id-All
True-Client-Country-4JS
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-Srv
X-HS-Status
X-M-Log
X-Alfa-Service
X-Air-Pt
X-App
Pramga
Path
True-Client-Ip
X-Vcl-Version
Resin-Trace
X-M-Reqid
X-Varnish-Beresp-TTL
X-Qnm-Cache
Tcn
GeoIP-Country-Code
C-Via
X-TrackingId
X-GeoIP-Region-Code
X-GeoIP-Country-Code
Tracecode
N-Cache
X-SERVER-NAME
Fastcgi-X-Cache-Version
X-Vercel-Id
Esi-Enabled
Section-Io-Origin-Status
X-FPC
X-Akamai-Pragma-Client-IP
X-Accel-Expires-Debug
Section-Io-Origin-Time-Seconds
X-Date
On-Server
X-Platform
X-Vercel-Cache
Section-Io-Id
WWW-Authenticate
X-PAYTM-SRV-ID
Section-Origin-Responded
NtCoent-Length
X-CLOUD-TRACE-CONTEXT
X-Check-Cacheable
X-RAMCache
X-Edge-Origin-Shield-Bytes
X-Edge-Origin-Shield-Region
X-WA
Proxy-Connection
X-Datacenter
Yjs-Id
Hit
X-Webkit-Csp-Report-Only
X-Via-CDN
GeoIP-Latitude
X-Platform-Cluster
X-Platform-Processor
X-ServedByHost
X-Platform-Router
X-Node-Id
Lb
X-Mly-Id
X-Vtex-Processado-Em
X-Old-Content-Length
X-Geo
Server-Id
X-Vtex-Remote-Cache
FSS-Cache
X-Edge-POP
X-LiteSpeed-Cache-Control
User-Agent
YJS-ID
ENV
X-Response-By
Powered-By
X-Lb-Id
X-LAGOON
X-SD-PageType
X-Request-Start
X-API-Version
X-Dw-Trace-Id
X-AIR-PT
X-UA
X-Cdn-Forward
X-Via-PopV
X-Via-PopH
X-Via-PopN
X-PERF
Cache-Key
X-Client-Ip
HIT
X-ApacheServer
Cdn
X-Akamai-ERPolicy
X-Akamai-ERRuleID
XServer
X-Li-Pop
X-TT-LOGID
X-Traceid
X-Render-Time
X-Proxy-CacheRZ
Server-Ttl
XkeyRZ
DynaTrace
X-FORWARDED-FOR
X-Cache-Ttl
X-Via-Ucdn
X-Instance-Name
X-Li-Fabric
X-From
X-Location
X-Webstats-RespID
X-LI-UUID
X-FL-EDGE
PICS-Label
Locid
X-CUA
Dnion-Transfer-Encoding
Geoip-Latitude
Srvid
X-LI-Proto
X-Service-Response-Time
Sm-Log-Id
X-RPS
X-RSL
X-CF-Powered-By
X-RPM
X-DW
X-DB
X-DI
PFcat
DT-Hot-News
Nginx-CQVIP
X-Contensis-Viewer-Groups
X-Varnish-Authentication
X-Director
X-Cache-ASPX
XM
X-LiteSpeed-Tag
X-VarnishDD-TTL
X-Proxy-Cache-Hk
X-DSS
X-Proxy-Upstream
X-HN
Ohc-File-Size
Location
X-Wp-Cf-Super-Cache-Cache-Control
X-Wp-Cf-Super-Cache
X-Litespeed-Cache-Control
X-Request-Url
X-B3-ParentSpanId
Wpo-Cache-Message
X-Fastly-Cache-Hits
Wpo-Cache-Status
X-Lb-Nocache
X-Cdn-Request-ID
X-Fastly-Backend-Reqs
X-DataCenter
X-HostName
Vha6-Origin
X-Server-IP
Wp-Super-Cache
X-Ips-Loggedin
CountryCode
Warning
X-Cache-Ngx
X-Moov-Xdn-Version
X-Yottaa-OS
CF-Cached-On
X-Test
Swift-Performance
SRV
Fastcgi-Cache-Ttl
X-Mg-Cache
WZWS-RAY
X-Moov-T
Req-ID
X-ElasticPress-Query