Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Accept-Ranges
Expect-CT
X-XSS-Protection
Pragma
CF-RAY
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
P3P
X-Xss-Protection
X-Served-By
X-Download-Options
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Request-ID
Access-Control-Allow-Credentials
X-Request-Id
CF-Ray
X-Permitted-Cross-Domain-Policies
X-AspNet-Version
Alt-Svc
Content-Security-Policy-Report-Only
X-Runtime
X-DNS-Prefetch-Control
X-Drupal-Cache
X-Check
X-Cache-Status
X-Generator
X-Cacheable
P3p
Timing-Allow-Origin
X-FRAME-OPTIONS
X-Iinfo
X-Envoy-Upstream-Service-Time
X-Content-Security-Policy
X-Drupal-Dynamic-Cache
Feature-Policy
Content-Encoding
Upgrade
Status
Access-Control-Expose-Headers
X-AspNetMvc-Version
X-CDN
Access-Control-Max-Age
X-Via
Server-Timing
X-UA-Device
X-Robots-Tag
Request-Context
X-Turbo-Charged-By
X-Cache-Group
X-Amz-Request-Id
EagleId
X-Amz-Id-2
X-Backend
Keep-Alive
X-AH-Environment
X-Proxy-Cache
X-Ws-Request-Id
X-Server
X-Age
Host-Header
X-Hacker
X-Ua-Compatible
Cf-Edge-Cache
X-Vhost
X-Server-Powered-By
X-Rq
Allow
X-Dispatcher
X-Varnish-Cache
Grace
X-Amz-Version-Id
X-LiteSpeed-Cache
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-OneAgent-JS-Injection
X-WebKit-CSP
Accept-CH
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
Cf-Apo-Via
X-Page-Speed
Cf-Railgun
X-Aws-Lambda-Call-Status
X-Server-Id
X-Host
X-Pingback
X-Node
X-Cache-Spec
X-Nginx-Cache-Status
X-Akam-SW-Version
Surrogate-Control
X-Dns-Prefetch-Control
X-Backend-Server
EagleEye-TraceId
X-Cache-Lookup
Request-Id
X-Readtime
X-Ruxit-JS-Agent
X-HW
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Cloud-Trace-Context
X-Content-Security-Policy-Report-Only
X-Trace
X-Application-Context
X-Response-Time
X-CST
Permissions-Policy
Accept-Ch-Lifetime
X-Mod-Pagespeed
X-Nginx-Upstream-Cache-Status
Fastly-Restarts
Accept-CH-Lifetime
X-Edge
X-Country
Content-Location
X-WebKit-CSP-Report-Only
X-Content-Type
X-Mcache
X-ECACHE
Rating
X-Clacks-Overhead
X-MS-InvokeApp
X-Url
X-Vname
X-PC
X-TtlSet
X-Amz-Server-Side-Encryption
X-Midtier
X-VARITI-CCR
RTSS
Cache-Tag
X-Varnish-TTL
X-Vcap-Request-Id
X-Ac
X-Element-Page-Cache
Verso
Origin-Trial
X-B3-TraceId
X-Kinja-Build
X-D2id
X-Kinja-Server
X-Kinja-Revision
X-GoogleNews-Bot
X-Use-Magma
X-Kinja
X-Exp-Variant
X-Exp-Id
X-Cdn-Fetch
X-Rack-Cache
X-Cnection
X-Server-Name
X-Cache-TTL
X-Powered-By-Plesk
Service-Worker-Allowed
Xkey
X-GitHub-Request-Id
X-Abt-Application-Version
X-Client-IP
X-Fastcgi-Cache
X-Navigation-Version
X-NWS-LOG-UUID
Edge-Control
X-ESI
SPRequestGuid
X-SharePointHealthScore
X-Amz-Rid
X-Cached
X-Px
X-Mg-S
X-Erf-Bev-Bev-Is-Generated
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-Instrumentation
X-Browser-Type
X-Erf-Bev-Bev
Arr-Disable-Session-Affinity
X-Ttl
X-Upstream
SPRequestDuration
SPIisLatency
X-Correlation-Id
X-Cache-Key
Display
X-Middleton-Display
X-Sol
Pagespeed
X-Litespeed-Cache
Content-MD5
X-Dw-Request-Base-Id
X-SRCache-Store-Status
X-SRCache-Fetch-Status
Access-Control-Request-Method
Edge-Cache-Tag
X-Goog-Hash
X-XRDS-Location
X-Daa-Tunnel
Front-End-Https
X-NF-Request-ID
X-Country-Code
Public-Key-Pins
X-Version
X-RateLimit-Remaining
X-Forwarded-For
AR-ATIME
AR-SID
AR-Request-ID
AR-CACHE
X-Powered-CMS
AR-PoweredBy
X-Id
X-Jurisdiction
X-HP-Trace-Id
TCN
X-HP-Webp
X-MSEdge-Ref
X-T
X-Recruiting
X-Content-Digest
X-Accel-Expires
Response
X-Middleton-Response
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
X-Ser
X-Shield-Request-Id
TP-L2-Cache
TP-Cache
Nginx-Cache
X-Fastly-Request-ID
S
X-Hits
X-Amzn-Trace-Id
X-Request-Processing-Time
Cache-Status
X-Request-Received
X-Kinsta-Cache
X-Edge-Location-Klb
X-HS-Hub-Id
X-HS-Cache-Config
X-HS-Combine-CSS
X-HS-Content-Id
Server-Node
X-Distributor
X-TTL
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-TEC-API-ROOT
X-Grace
Cache-Tags
MicrosoftSharePointTeamServices
Alternate-Protocol
Fastcgi-Cache
Server-Name
X-Protected-By
X-Ratelimit-Limit
X-DataDome
X-DIS-Request-ID
X-Ezoic-Cdn
X-Geo-Country
X-Ruxit-Js-Agent
X-Origin-Server
X-LB-Cache
X-Frontend
X-Microsite
X-Request-Handler-Origin-Region
X-Ua-Browser
X-Debug-Info
X-Rid
X-Ratelimit-Reset
Healthy
Cross-Origin-Opener-Policy
Payment
X-Www-Served-By
X-Git-Hash
Filterid
X-Forwarded-Proto
X-NGENIX-Cache
X-Varnish-Backend
X-Logged-In
X-FB-Debug
Cleartype
X-Page-Id
X-PressLabs-Stats
X-Ratelimit-Remaining
X-Load-Cache
Charset
X-B3-Sampled
Content-Disposition
X-VCache
X-Webkit-Csp
X-ASPNET-VERSION
X-Origin-Cache
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-LLID
X-Cluster-Name
MS-Author-Via
X-Oracle-Dms-Rid
X-Oracle-Dms-Ecid
X-Hostname
DC
X-Goog-Metageneration
X-GUploader-UploadID
X-Upgrade-Enabled
Accept-Charset
Access-Control-Allow-Method
Retry-After
X-Proxy
Cross-Origin-Resource-Policy
X-Activity-Id
X-AppVersion
X-F-Cache
X-Az
X-Contextid
X-Providence-Cookie
X-B-Cache
X-Type
Accept-Ch
X-Amz-Replication-Status
X-Aspnet-Duration-Ms
X-Signature
X-Seen-By
X-Revision
X-Is-Crawler
X-Request-Guid
X-Hosted-By
X-Route-Name
X-Flags
X-Varnish-Server
X-B
X-Wix-Request-Id
X-TT
X-Whom
X-Azure-Ref
Referer-Policy
X-Amz-Meta-S3cmd-Attrs
X-App-Environment
Surrogate-Key
Paypal-Debug-Id
Viewport
Amp-Access-Control-Allow-Source-Origin
X-DynaTrace
X-Source
Count-Hit
X-RateLimit-Limit
X-Aspnetmvc-Version
X-Tt-Trace-Host
X-Fb-Rlafr
Realpath
X-Tt-Trace-Tag
X-Akamai-Edgescape
X-Mobile
X-App-Server
X-Goog-Generation
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-B3-Traceid
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-FastCGI-Cache
Host
X-Cache-Control
X-EdgeConnect-Cache-Status
X-HTML-Minification-Powered-By
Version
X-N
X-Original-Request-Id
Refresh
X-Response-Served-From
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Varnish-Grace
X-Cache-Rule
X-Nginx-Cache
X-Tumblr-Pixel-1
X-URL
X-Tumblr-User
X-Oneagent-Js-Injection
X-Magnolia-Registration
SD-X-WS
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Envoy-Decorator-Operation
Access-Control-Request-Headers
Section-Io-Cache
X-Varnish-Age
Ms-Operation-Id
X-RTag
X-UUID
X-Newrelic-App-Data
X-Cache-Time
X-Adobe-Content
X-Page-View
X-Cache-Status-Check
X-L-Path
X-Cache-Expired-At
MS-CV
X-Adobe-Loc
X-Environment-Context
X-Rendered-As
X-RemovedCookies
X-Jobs
X-ProcessESI
X-Servername
X-Is-Bot
X-G
X-Cacheable-TTL
X-Cache-Grace
NGB
Protected
X-Content-Powered-By
X-Rule
X-Device-Type
GEO-INFO
X-Status
X-Framework
X-FW-Hash
X-FW-Serve
X-FW-Dynamic
Akamai-GRN
X-Akamai-Request-ID2
X-FW-Server
X-FW-Static
X-Cache-Age
X-NYM-Debug-Backend
X-FW-Version
X-FW-Type
Url
X-Http-Reason
X-Debug-IsPreview
X-Instance
X-Debug-IsConnected
X-Backend-Name
X-User-Agent
X-CDN-Forward
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Tb
CDN-RequestId
X-Cache-Hit
X-Drupal-Cache-Contexts
X-Drupal-Cache-Tags
Pinterest-Version
X-Pinterest-Rid
From-Origin
Pinterest-Generated-By
SRV
X-Tt-Logid
WPO-Cache-Status
WPO-Cache-Message
Country
X-Region
X-Node-Name
Accept-Language
Front
X-Trace-Id
X-Real-IP
Fastly-Drupal-HTML
X-Time
X-VC-Cache
Uber-Trace-Id
Backend
X-Mode
X-Template
X-Content-Options
X-Language
X-Amzn-RequestId
Meta-Geo
Filters
Fastly-SWR
X-Generation-Time
X-RN-RSRV
X-Amz-Apigw-Id
X-Rewrite-Enabled
X-Cache-Operation
X-UPSTREAM-Address
Fastly-SIE
Webserver
X-DynaTrace-JS-Agent
Content-Secure-Policy
X-Tumblr-Pixel-2
X-Web-Node
CDN-EdgeStorageId
CDN-Cache
Cross-Origin-Window-Policy
X-Cache-TTL-Remaining
CDN-RequestCountryCode
CDN-Uid
CDN-CachedAt
CDN-PullZone
X-WP-CF-Super-Cache
X-Say-TTL
X-Sql-Duration-Ms
X-Say-Cacheable
X-Sql-Count
X-Proxy-Cache-Status
X-Adobe-Source
X-Cache-Action
X-Cms-Context
X-Rocket-Nginx-Serving-Static
Apigw-Requestid
X-WP-CF-Super-Cache-Cache-Control
X-Access
X-IPS-LoggedIn
X-SayCDN-TTL
Azure-RegionName
Azure-SiteName
CF-IPCountry
Azure-InstanceId
X-Format
X-Proxy-Cache-Info
X-Section
X-Cache-Server
Azure-SlotName
Azure-Version
X-Ms-Request-Id
Node
X-Ms-Version
X-PHP-Host
X-VWS-Id
X-Via-Fastly
X-GeoCode
X-Debug
X-GeoCountry
X-Zen-Fury
X-ProxyCache-Key
X-Labrador-Cache-Channel
ServerID
Cache-Name
X-Varnish-Beresp-Grace
X-ProxyCache-Status
X-LJ-Flow-ID
X-Unique-Id
X-Sucuri-ID
X-Content-Age
X-UA-Device-Type
X-Cache-Host
X-Edge-Location
X-Cluster
X-Skip-Cache
X-Soup
X-Forwarded-Host
X-Sucuri-Cache
X-Reqid
X-AWS-Id
X-BYPASS-REASON
X-PHP-Backend
Webcakes-Region
X-Server-W
X-No-Session
X-Extlb
X-JoinUs
X-Locale
X-Origin-Hint
X-IPLB-Request-ID
TWC-GeoIP-Country
Property-Id
X-Site-Version
X-Detected-As
X-R9-Blue-Green-Version
Onion-Location
S-Rt
X-Zipkin-Id
TWC-Device-Class
TWC-Connection-Speed
Web-Mar-Node
X-Xfnlog-Site
X-SaId
TWC-Locale-Group
X-IPLB-Instance
TWC-Privacy
Webcakes-App-Name
X-Urbn-Site-Id
X-Proxied
X-Urbn-Context-Path
TWC-GeoIP-LatLong
X-Routing-Service
X-Proto
X-Amzn-Remapped-Content-Length
Webcakes-App-Version
X-LAGOON
X-Cluster-Node
Locale
X-Fastly-Request-Id
X-Handled-By
Mime-Version
X-Timing-Wait
WP-Super-Cache
X-Ua
X-Proxy-Build
Mn-Server-Ip
X-LSADC-Cache
Selected-Fe
X-SRV
Fastcgi-Useragent
DB-Nickname
X-FB-TRIP-ID
X-Hl-Ver
Cache-Hits
X-Request-Time
Xserver
Liferay-Portal
X-Cache-Debug
X-Redis-Cache
X-Tumblr-Pixel-3
X-TIME
ServedBy
X-TNCMS
X-NWS-UUID-VERIFY
X-XRDS-LOCATION
Upgrade-Insecure-Requests
X-Optimistic-Header
X-Loop
X-CACHE-AGE
Source
X-GEO
Countrycode
X-Generated-By
X-Esi
X-Mg-Request-UUID
X-Origin-Date
X-Varnish-Hits
X-Tid
X-Air-Trace-Id
X-Air-Hostname
X-Air-Source
CF-Cached-On
X-Times
X-Storage
X-Uri
X-Tec-Api-Version
X-Tec-Api-Root
X-Tec-Api-Origin
X-Director
X-Akamai-Transformed
X-Varnish-Beresp-Ttl
X-COUNTRY
Xet-Cookie
X-Cdn
X-Tx-Id
X-TA-CDN-Provider
X-Trace-ID
X-Pass-Why
Frame-Options
X-Newrelic-Synthetics
X-Origin-TTL
X-Origin-CC
X-ARC
X-DC
X-B3-Spanid
X-Service
X-FireWall-Port
X-ECache
X-App-Version
X-Varnish-Hostname
X-Sorting-Hat-PodId
X-Shopify-Stage
X-Storefront-Renderer-Rendered
X-Sorting-Hat-ShopId
X-ShardId
X-Alternate-Cache-Key
X-Varnish-Cache-Hits
X-Datadog-Parent-Id
SID
X-Datadog-Sampled
X-Datadog-Sampling-Priority
Environment
X-Datadog-Trace-Id
X-ShopId
X-Presslabs-Stats
Server-Info
X-Bc-Bl
X-BCube-Filmed-By
X-A-Dam
X-A-Dcw
X-BBC-Edge-Cache-Status
X-Nyt-Route
A
X-Mid
X-Mobile-URL
X-Loc
X-A-Wwc
X-Application
X-B-Cookie
X-Ec-Fail
X-D
X-Aed
X-Endurance-Cache-Level
X-Developer
X-Ec-GeoHdr
X-Epic-Correlation-Id
X-Request-Host
X-Gdpr
X-Cache-Info
X-Destination
X-External-Request-Id
X-Cache-NE
X-A-Dgt
T-Server
X-Vdms-Version
X-VG-TLSProxy
Rendered-Blocks
Release
X-Vdms-Path
Req-Svc-Chain
X-A-Ccd
X-TIM-N
Sslversion
Redirect-Candidate
Origin
DCR-Decision-By
DCR-Processing-Time-Ms
Lang
Gannett-Cam-Experience-Id
MD5-Digest
Meta-Geo-Continent
Xc-Version
Odigeo-Trace-Id
Ngx.Var.Host
Surrogated-Key
Candidate-Md5Url
Edge-Cache
WWW-Authenticate
X-Rojux
X-SRCache-Key
X-Processor
X-A
X-Origin-Time
X-Platform-Cluster
X-Platform-Processor
X-Platform-Router
X-S-Cookie
X-S
X-S-Maxage
BehaviorPad-Version
X-ScT
X-ServerID
X-AIR-PT
Magicmarker
Tube-Get-Contents
Fastly-GeoIP-CountryCode
Tube-Got-Eval
Memcached
X-Akamai-Device-Characteristics
Tube-Return
Tube-Got-Results
State
X-Req
X-VServer
X-WA-Info
X-WADP-Cache
X-WP-CF-Super-Cache-Active
X-Varnish-Remaining-TTL
X-Varnish-CookieINHashed-On
X-Sn-Servicetimems
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-Varnish-CookieHashed-On
Host-ID
TDXMobile
X-Frame-Option
X-INCAP-ABP
X-Thinkindot-L3
X-We-Are-Hiring
X-Core-Value
X-CMSURLCustom
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
Thinkindot-Control
X-Sigma-Backend
X-Sigma
X-DefHash
X-Ec-Custom-Error
X-Fmm-Version
X-Gamma-Serve
X-DefElseHash
X-CUA
X-Cdn-Origin
X-Clara-WADP
X-Core-Mission
X-GeoIP-City
X-Httpd
X-Rocket-Build-Number
X-SB
X-SD-PageType
X-Served-From
X-Platform-Server
X-Origin-Response-Time
X-Human
X-NodeID
X-Old-Content-Length
X-Cache-Bucket
Vix-Hermes-Req-Id
Decoy-Debug-Status
Apple-News-Services-Handled
Apple-News-Services-Host
Click-Count-Error
Country-Code
Click-Count-Action-Start
X-Pubstack
Cluster
Cache-Tv-Group
Decoy-Debug-Key
Cache-Host
C-Via
DSUID
Decoy-Debug-TTL
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
Section-Io-Origin-Status
X-Parent-Response-Time
Section-Origin-Responded
Section-Io-Id
Section-Io-Origin-Time-Seconds
X-Scale
X-Pool
X-Slack-Backend
X-App
X-Request-Start
X-Accel-Buffering
X-Esi-Check
We-Hiring
X-Var-Ttl
Adler-Geo
X-Up
X-Accel-Expires-Debug
X-Variation
X-Thanos
X-Ad-Defer-Variation
X-Cache-FS-Status
X-GeoIP-Region-Code
X-GeoIP-Country-Code
X-Date
X-Gzip
X-Hash
X-GeoIP
X-Dispatcher-Number
X-Fastly-Backend
X-Fetched-On
X-DPWN-IS-SECURE
X-Gen-Mode
X-Hnp-Log
X-CSRF-Token
X-Block-Status
X-Bip
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Origin
User-Cache-Control
X-LB-NoCache
X-Minions-Version
X-Node-Id
X-Cache-Id
X-Planisys-CDN-TTL
X-Varnish-Beresp-Status
NM-Fastcgi-Cache
Cmsid
Cmstype
X-Geo-Header
X-Has-Esi
Origin-CC
Origin-EX
Producers
X-Buckets
Pics-Label
X-Developers
X-HS-Content-Campaign-Id
X-Is-Gdpr
X-Test
X-Restarts
X-Worker
X-Generated-On
X-Level-Front-Cache
Is-Eu
Kp-EeAlive
Mail-Subject
X-JWT-State
X-Location
L
CloudFront-Viewer-Country
Platform
CDCHOST
Ssr
Server-Host
Server-Hostname
Fastly-Backend-Name
Svr
Cache-Key
X-Vmg-Version
X-Wix-Viewer-Type
Cache-Provider
Server-Ext
Sever-Int
X-Auto-Login
X-Cdn-Srv
Cdn
X-RM-Cache-TTL
X-Cache-Backend
X-Qloud-Router
CacheControlHeader
X-V-Cache
X-Nananana
AKAMAI
X-Varnishpool
X-Conf
X-FC-Vary-Parameters
X-Op-Id-All
X-Forwarded-Site
X-Owner
X-Server-IP
Gh-Request-Id
X-Platform
X-Region-Sid
Web-Mar-Region
X-Slack-Shared-Secret-Outcome
X-Irp-Debug
X-VarnishDD-TTL
X-Nginx-Cache-Key
X-HN
X-Refresh
X-NCache
X-Mvc-Supplant-Cachable
X-Cache-Tags
X-Azure-Ref-OriginShield
X-CacheTTL
X-Ckpd-Fst-Backend
X-Device-Os
X-Aicache-OS
Wxu-Next-Hostname
Machine
Fastly-SSL
Datacenter
PFcat
Wxu-Next-Commit
X-Dispatcher-Server
Wxu-Next-Region
HostName
HA-Ipaddr
L5d-Success-Class
X-Tb-Optimization-Total-Bytes-Saved
X-Org
Canary
Ha-Gx-Prefs
X-Cached-By
X-CGP
X-Eu-Site
X-Cache-Remote
X-Men
NGX
X-Via-Popv
X-Via-Popn
X-Varnish-Ttl
On-Server
X-Csrf-Jwt
X-Via-Poph
X-Webkit-CSP-Report-Only
X-Mvc-Supplant-OutputCached
GeoIP-Latitude
X-Servedbyhost
Env
X-AK-Request-ID
X-VC
Cdncip
X-HA-Backend
Cdnsip
Server-ID
X-Cache-Date
X-API-Version
X-LB-ID
X-Gateway-Request-Id
X-Gateway-Skip-Cache
X-Microcachable
X-Gateway-Cache-Status
X-RCS-CacheZone
X-Gateway-Cache-Key
X-APP-VERSION
X-Wa
X-Mly-Id
Cache
X-ZONE
X-Fpc
X-Zone
X-DataCenter
X-Server-ID
X-Vgn-Hpd-Ssi
Memory
Time
X-Vgn-Hpd-Variations-Key
X-Vgn-Hpd-Cached
X-Generated-In
Request-ID
X-Webkit-CSP
OT-Force-Account-Verify
Load-Balancing
X-Fastly-Cache
X-Via-NSCOPI
X-Nc
X-Micro-Cache
Eomportal-Instance
Ngx-Var-Key
X-Origin-Expires
X-Instance-Name
X-ND-Cache
X-HS-Status
X-Correlation-ID
X-Vc
X-Release
X-Response-By
X-Request-URI
X-Check-Cacheable
X-SIPLIST1
X-Client-Ip
IsBot
X-Nf-Request-Id
Srv
X-Via-JSL
X-VCL-Version
X-CCDN-CacheTTL
X-FL-EDGE
Locid
X-From
Expect-Staple
X-Info
Srvid
X-Cache-NGX
X-CCDN-Origin-Time
X-FL-QIT-DEBUG
X-CS
X-Hcs-Proxy-Type
NtCoent-Length
X-Cache-Enabled
X-Via-CDN
True-Client-Ip
X-Srv
Hostname
X-NewRelic-App-Data
AMP-Access-Control-Allow-Source-Origin
X-MCACHE
X-Via-SSL
X-Edge-Pop
X-Via-Edge
Edge-Copy-Time
X-CSRF-TOKEN
X-Api-Version
GeoIp-Country-Code
X-Provided-By
XkeyRZ
X-Proxy-CacheRZ
Location
Uri
Path
X-Cache-Expires
X-Debug-Cache-Store
X-NGINX-Cache
X-Amz-Meta-Cb-Modifiedtime
X-Debug-Cache-Fetch
X-Lambda-Id
GeoIP-Country-Code
X-Dc
X-EC-Lua
X-Edge-POP
Resin-Trace
X-Air-Pt
X-Oss-Storage-Class
True-Client-IP
X-Vcl-Version
Sid
X-Oss-Server-Time
X-Oss-Request-Id
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
X-Fastly-Country-Code
Cross-Origin-Opener-Policy-Report-Only
X-Render-Time
Servername
CPC-Age
VNS-Age
CPC-Cache
X-SERVER-NAME
X-Vtex-Remote-Cache
VNS-Cache
X-B3-SpanId
X-NODE
Traceparent
X-Moov-T
X-Cs
X-Moov-Xdn-Version
LB
CDN
X-VCT
X-Scheme
X-CLOUD-TRACE-CONTEXT
X-Viewer-Country
X-TH-Server
Fastly-Drupal-Html
X-RateLimit-Reset
X-ApacheServer
X-Cdn-Request-ID
X-PERF
X-ATG-Version
X-Akamai-Pragma-Client-IP
X-TX-ID
Rip
X-Cache-ASPX
Powered-By
X-MSEdge-Features
X-Varnish-Authentication
FSS-Cache
X-NAPM-TraceId
Timeexpire
X-Pod-Name
X-MSEdge-Flight
Esi-Enabled
X-Contensis-Viewer-Groups
X-Varnish-Beresp-TTL
X-Cdn-Cache-Status
X-Accel-Version
M-TraceId
CountryCode
X-Datadome
X-FPC
X-Datacenter
YJS-ID
X-CF-Lambda-Fn
X-WA
Sm-Log-Id
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-PAYTM-SRV-ID
X-Udemy-Cache-App-Namespace
X-Service-Response-Time
X-CF-Lambda-Version
X-Clientip
Tracecode
True-Client-Country-4JS
V-Age
X-Upstream-Ht
X-Upstream-Ct
XServer
X-Geo
X-Cache-Type
X-LiteSpeed-Cache-Control
XM
Proxy-Connection
HIT
X-Srcache-Fetch-Status
X-Lb-Id
X-CACHE-KEY
X-Srcache-Store-Status
X-VG-WebCache
Server-Id
X-NC
Ohc-File-Size
X-Wikidot-Static-Cache
ENV
RNT-Time
Ngx
N-Cache
X-B3-Parentspanid
X-ServedByHost
X-TraceId
X-Wikidot-Backend
RNT-Machine
X-Rebelmouse-Surrogate-Control
X-Bl-Debug
X-Rebelmouse-Cache-Control
Epwk-X-Cache
X-Ha-Backend
X-CDN-Cache-Status
X-Hyper-Cache
X-Shop-Environment
X-Forwarded-Path
X-Tenant
Geoip-Latitude
X-Cdn-Forward
WZWS-RAY
X-Orig-Expires
Yjs-Id
Content-Style-Type
X-Via-PopN
Expiry
Pramga
X-Via-PopV
X-MP-GENERATED-AT
Content-Script-Type
X-Via-PopH
Req-ID
X-Cdn-Diag
X-MiniProfiler-Ids
User-Agent
X-B3-ParentSpanId
X-Swift-Error
X-Vgn-Hpd-Reason
X-Lb-Nocache
X-Dw-Trace-Id
X-B3-Trace-ID
X-Fastly-Backend-Reqs
X-Connection-Hash
X-Serial
Ec-Rule-Version
Inserted-Into-Cache-At
X-Lsadc-Cache
X-F-Status
X-TT-LOGID
X-M-Log
X-M-Reqid
X-Qnm-Cache
X-Akamai-ERRuleID
X-Cache-Ngx
X-Stale
X-IPS-Cached-Response
X-UP
X-Mid-Debug-Cache-Disk
X-Request-URL
X-Mid-Debug-Cache-Key
Warning
X-Yottaa-OS
X-Akamai-ERPolicy
X-LiteSpeed-Tag
X-Th-Server
My-App
MIME-Version
X-Webstats-RespID
Cneonction
X-Snapshot-Date