Threat Level: green Handler on Duty: Rick Wanner

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
Strict-Transport-Security
X-Frame-Options
X-Content-Type-Options
Last-Modified
Link
CF-Cache-Status
Cf-Request-Id
Accept-Ranges
ETag
CF-RAY
Expect-CT
Pragma
X-Powered-By
X-Cache
Via
Age
X-XSS-Protection
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Xss-Protection
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-FRAME-OPTIONS
X-Download-Options
X-Timer
X-Request-Id
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-Adblock-Key
X-AspNet-Version
X-Permitted-Cross-Domain-Policies
Alt-Svc
X-Runtime
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Check
X-DNS-Prefetch-Control
X-Cache-Status
CF-Ray
X-Generator
X-Cacheable
X-Iinfo
Timing-Allow-Origin
X-Envoy-Upstream-Service-Time
Feature-Policy
Status
X-Content-Security-Policy
X-Drupal-Dynamic-Cache
X-Request-ID
Content-Encoding
X-AspNetMvc-Version
Access-Control-Expose-Headers
X-CDN
Upgrade
X-XSS-PROTECTION
X-Ua-Compatible
Access-Control-Max-Age
X-Dns-Prefetch-Control
X-Via
X-Cache-Group
X-Robots-Tag
Server-Timing
X-UA-Device
Request-Context
Keep-Alive
X-Amz-Request-Id
X-AH-Environment
X-Turbo-Charged-By
X-Amz-Id-2
X-Proxy-Cache
X-Backend
X-Ws-Request-Id
P3p
X-Age
Host-Header
X-Server-Powered-By
X-Hacker
X-Server
X-Rq
X-Vhost
EagleId
X-Varnish-Cache
Grace
X-Amz-Version-Id
X-Dispatcher
X-LiteSpeed-Cache
Cf-Edge-Cache
X-Akamai-Path-Stats
Allow
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-Device
X-Nginx-Cache-Status
X-WebKit-CSP
X-Page-Speed
X-Aws-Lambda-Call-Status
X-Host
X-Node
Accept-CH
X-Pingback
X-OneAgent-JS-Injection
X-Server-Id
Cf-Railgun
X-Cache-Spec
Request-Id
EagleEye-TraceId
Surrogate-Control
X-Akam-SW-Version
X-Backend-Server
X-Cache-Lookup
X-Response-Time
X-Readtime
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Accept-CH-Lifetime
X-HW
Content-Location
X-Content-Security-Policy-Report-Only
X-Application-Context
X-Trace
Rating
X-Cloud-Trace-Context
Fastly-Restarts
X-Clacks-Overhead
X-Url
X-WebKit-CSP-Report-Only
Accept-Ch-Lifetime
X-Country
X-MS-InvokeApp
X-Edge
X-Amz-Server-Side-Encryption
Edge-Control
X-Rack-Cache
X-Nginx-Upstream-Cache-Status
X-Vname
X-TtlSet
X-B3-TraceId
X-PC
X-Ruxit-JS-Agent
X-Content-Type
X-ESI
X-Mod-Pagespeed
X-Vcap-Request-Id
X-Oneagent-Js-Injection
X-Kinja
X-D2id
X-Kinja-Build
X-Cdn-Fetch
Xkey
X-Kinja-Revision
X-Use-Magma
X-Exp-Variant
X-Exp-Id
X-Kinja-Server
X-GoogleNews-Bot
Verso
X-Amz-Rid
X-GitHub-Request-Id
X-Varnish-TTL
Cache-Tag
X-Mcache
X-VARITI-CCR
X-Powered-By-Plesk
X-FastCGI-Cache
RTSS
X-CST
X-Ruxit-Js-Agent
Service-Worker-Allowed
X-ECACHE
X-Upstream
X-Navigation-Version
X-Abt-Application-Version
X-Client-IP
X-Version
X-Cached
X-Cnection
X-Dw-Request-Base-Id
X-Ac
X-Px
Public-Key-Pins
X-Server-Lifecycle-Phase
X-Element-Page-Cache
X-Ttl
X-Server-Name
X-Instrumentation
X-Kraken-Loop-Name
Arr-Disable-Session-Affinity
SPRequestGuid
X-SharePointHealthScore
X-Cache-TTL
SPIisLatency
SPRequestDuration
X-Middleton-Display
Accept-Ch
Display
X-Sol
Pagespeed
X-NWS-LOG-UUID
X-Country-Code
X-Ser
Permissions-Policy
X-Midtier
X-Cache-Key
X-Middleton-Response
Response
X-RateLimit-Remaining
X-Edge-Location-Klb
X-Kinsta-Cache
X-Goog-Hash
X-Forwarded-For
Content-MD5
Access-Control-Request-Method
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Correlation-Id
X-NF-Request-ID
X-DataDome
Front-End-Https
X-Shield-Request-Id
X-MSEdge-Ref
X-T
X-Jurisdiction
X-HP-Trace-Id
Edge-Cache-Tag
X-HP-Webp
TP-Cache
TP-L2-Cache
X-Recruiting
Nginx-Cache
AR-CACHE
AR-PoweredBy
AR-SID
X-Accel-Expires
AR-ATIME
AR-Request-ID
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
MicrosoftSharePointTeamServices
X-Daa-Tunnel
X-Powered-CMS
MRF-Tech
Mrf-Cache-Status
X-B3-TraceId-Primal
X-RateLimit-Limit
TCN
Cf-Apo-Via
X-Grace
X-Mg-S
X-Id
X-Content-Digest
X-Hits
X-Request-Processing-Time
Filters
X-Request-Received
X-HS-Hub-Id
X-HS-Cache-Config
X-HS-Content-Id
X-HS-Combine-CSS
Server-Node
X-TEC-API-VERSION
Server-Name
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Amzn-Trace-Id
X-Frontend
X-Distributor
MS-Author-Via
X-Geo-Country
S
Fastcgi-Cache
X-Protected-By
X-LLID
X-Fastly-Request-Id
X-Language
Cache-Status
X-XRDS-Location
X-PressLabs-Stats
X-Erf-Bev-Bev
X-Browser-Type
X-LB-Cache
X-Erf-Bev-Bev-Is-Generated
Cross-Origin-Opener-Policy
X-Origin-Server
X-Amz-Meta-S3cmd-Attrs
Count-Hit
X-Ezoic-Cdn
X-F-Cache
X-Forwarded-Proto
Charset
X-FB-Debug
X-Litespeed-Cache
X-B3-Sampled
Host
X-Request-Handler-Origin-Region
X-Microsite
X-Page-Id
X-Ua-Browser
X-Git-Hash
X-Ab
X-Seen-By
Payment
Filterid
X-ASPNET-VERSION
X-Ratelimit-Reset
X-TTL
X-Fastcgi-Cache
X-VCache
X-Cluster-Name
Surrogate-Key
Realpath
X-Origin-Cache
X-Rid
Cache-Tags
Accept-Charset
X-Cache-Age
X-Template
X-Webkit-Csp
X-NGENIX-Cache
Alternate-Protocol
X-Www-Served-By
Retry-After
Access-Control-Allow-Method
X-Az
X-Activity-Id
X-AppVersion
X-DynaTrace
X-Upgrade-Enabled
Cleartype
X-Logged-In
X-DIS-Request-ID
X-Amz-Replication-Status
X-Request-Guid
X-Tb
X-App-Environment
X-Flags
X-Aspnet-Duration-Ms
X-Route-Name
X-Providence-Cookie
X-Is-Crawler
X-TT
X-Varnish-Backend
X-Varnish-Grace
X-Type
X-Wix-Request-Id
X-Signature
X-B
X-B-Cache
X-Node-Name
X-Source
X-Envoy-Decorator-Operation
ServerID
Paypal-Debug-Id
DC
X-Hostname
X-Drupal-Cache-Tags
Frame-Options
X-Debug
X-Proxy
X-Revision
X-Content-Options
X-Mobile
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-COUNTRY
X-Contextid
X-Load-Cache
Pinterest-Version
Pinterest-Generated-By
X-Pinterest-Rid
X-Fastly-Request-ID
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Goog-Metageneration
X-GUploader-UploadID
X-Goog-Generation
Amp-Access-Control-Allow-Source-Origin
X-Goog-Stored-Content-Length
X-Cache-Rule
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-N
X-Cache-Control
X-Content
Country
X-Magnolia-Registration
Node
Refresh
X-Response-Served-From
X-Whom
X-Original-Request-Id
X-User-Agent
X-EdgeConnect-Cache-Status
Referer-Policy
NGB
Viewport
Access-Control-Request-Headers
X-Ratelimit-Remaining
X-Environment-Context
X-Cache-TTL-Remaining
X-Cacheable-TTL
X-Framework
X-Debug-IsConnected
X-L-Path
X-Debug-IsPreview
X-Page-View
X-Unique-Id
X-Status
X-Servername
Akamai-GRN
X-Varnish-Server
X-Yottaa-Metrics
X-NYM-Debug-Backend
X-Content-Powered-By
X-Yottaa-Optimizations
X-Mid
X-Real-IP
X-Jobs
Url
Uber-Trace-Id
Content-Disposition
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-G
X-Adobe-Content
X-Akamai-Request-ID2
X-Adobe-Loc
X-Varnish-Age
X-Rendered-As
X-Cache-Time
X-Is-Bot
X-Cache-Grace
X-ProcessESI
Srv
X-Instance
X-RemovedCookies
X-Server-ID
Countrycode
X-Drupal-Cache-Contexts
X-Mg-Request-UUID
X-APP-VERSION
Version
X-Restarts
X-Trace-Id
X-XRDS-LOCATION
X-Oracle-Dms-Rid
X-Http-Reason
X-CDN-Forward
X-Oracle-Dms-Ecid
X-App-Server
Accept-Language
X-Via-JSL
X-Time
X-Cache-Expired-At
Protected
X-Debug-Info
X-IPLB-Instance
X-IPLB-Request-ID
X-Hosted-By
X-Cache-Hit
X-Tumblr-User
Healthy
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-Tumblr-Pixel
X-Ratelimit-Limit
X-Nginx-Cache-Key
X-Cache-Operation
X-Azure-Ref
Cross-Origin-Resource-Policy
X-Device-Type
Liferay-Portal
X-Backend-Name
Section-Io-Cache
X-Tt-Logid
X-FW-Hash
X-FW-Type
X-FW-Static
X-FW-Server
X-FW-Dynamic
Backend
X-Akamai-Edgescape
X-FW-Serve
Server-Info
Fastcgi-Useragent
Content-Secure-Policy
X-Rule
Ms-Operation-Id
MS-CV
X-RTag
X-Storage
X-Mobile-URL
X-UPSTREAM-Address
X-Cache-Action
X-RN-RSRV
Load-Balancing
Meta-Geo
X-Proxy-Cache-Status
X-SRV
GEO-INFO
X-Mode
X-Cache-NGX
X-Handled-By
X-Content-Age
X-VC-Cache
X-Varnish-Beresp-Grace
X-UUID
X-Api-Version
X-Edge-Location
X-Cache-Server
X-ShopId
X-ShardId
X-Section
X-Cache-Enabled
X-PCL
X-Alternate-Cache-Key
X-PHP-Backend
Eomportal-Instance
X-Proto
X-PHP-Host
Locale
X-Adobe-Source
X-LJ-Flow-ID
X-Labrador-Cache-Channel
X-No-Session
X-OCL
S-Rt
CDN-Uid
CDN-RequestId
X-AWS-Id
X-Shopify-Stage
X-Region
X-Access
X-Say-TTL
X-Say-Cacheable
X-Forwarded-Host
X-Redis-Cache
CDN-PullZone
CDN-RequestCountryCode
CDN-EdgeStorageId
CDN-CachedAt
CDN-Cache
X-SayCDN-TTL
X-URL
X-Varnish-Hostname
X-Uri
X-Urbn-Site-Id
X-Varnishpool
X-VWS-Id
X-Format
X-Site-Version
CF-IPCountry
X-Urbn-Context-Path
Onion-Location
X-Sql-Duration-Ms
X-Sorting-Hat-PodId
X-Sql-Count
X-Skip-Cache
X-Cms-Context
X-Sorting-Hat-ShopId
Webcakes-Region
X-Cache-Host
TWC-Locale-Group
X-HTML-Minification-Powered-By
Webcakes-App-Version
Selected-Fe
Web-Mar-Node
X-Locale
Webcakes-App-Name
TWC-Privacy
Mn-Server-Ip
X-Hl-Ver
X-BYPASS-REASON
X-Extlb
X-Generation-Time
X-Cache-Type
X-Detected-As
X-FB-TRIP-ID
X-Varnish-Cache-Hits
X-GeoCountry
TWC-GeoIP-LatLong
X-GeoCode
X-Generated-By
X-Server-W
X-Origin-Hint
TWC-GeoIP-Country
X-Xfnlog-Site
X-Web-Node
X-ProxyCache-Status
X-Zipkin-Id
X-Timing-Wait
X-Request-Time
X-Routing-Service
X-Storefront-Renderer-Rendered
X-UA-Device-Type
X-ServerID
X-Datadome
X-Via-Fastly
Apigw-Requestid
X-ProxyCache-Key
Property-Id
X-Proxy-Build
DB-Nickname
TWC-Connection-Speed
TWC-Device-Class
Azure-SlotName
Azure-Version
Azure-SiteName
Azure-InstanceId
X-Proxied
Azure-RegionName
X-Cache-Status-Check
X-Origin-Date
X-Tid
X-R9-Blue-Green-Version
X-JoinUs
X-Ms-Version
X-SaId
X-Ms-Request-Id
WP-Super-Cache
Cache-Name
X-ECache
X-FireWall-Port
ServedBy
X-WP-CF-Super-Cache-Cache-Control
X-DynaTrace-JS-Agent
X-Zen-Fury
X-WP-CF-Super-Cache
X-LSADC-Cache
X-Nginx-Cache
X-Amzn-RequestId
X-Amz-Apigw-Id
Xserver
X-Ua
X-Debug-Cache
X-Dc
X-Human
X-TA-CDN-Provider
Xet-Cookie
X-MP-GENERATED-AT
X-Loop
X-Cache-Tags
Cache
X-TNCMS
X-Correlation-ID
X-Aspnetmvc-Version
X-RCS-CacheZone
X-Reqid
Source
X-Cdn
X-Cached-By
X-Varnish-Hits
X-GEO
X-Webkit-CSP
X-Pubstack
X-Soup
SD-X-WS
Origin
Cross-Origin-Window-Policy
X-Amzn-Remapped-Content-Length
X-Newrelic-Synthetics
WPO-Cache-Status
WPO-Cache-Message
X-App-Version
LB
X-Origin-TTL
X-Origin-CC
X-Tumblr-Pixel-2
X-Vgn-Hpd-Reason
X-Provided-By
X-Varnish-Beresp-Ttl
From-Origin
X-Service
X-IPS-LoggedIn
X-Varnish-Ttl
X-TIME
X-AOL-HN
X-Tec-Api-Origin
X-Via-NSCOPI
X-B3-SpanId
X-NewRelic-App-Data
X-Tec-Api-Version
X-Tec-Api-Root
X-GG-Cache-Date
Rip
X-FW-Version
X-Request-Host
X-Platform-Server
X-B3-Traceid
Webserver
Lang
X-Tenant
X-Cluster-Node
X-Bc-Bl
X-VG-WebCache
X-Forwarded-Path
Expiry
X-AK-Request-ID
X-B-Cookie
Environment
X-Application
X-External-Request-Id
X-Aed
X-A-Wwc
Host-ID
X-A
X-Ec-GeoHdr
X-A-Ccd
X-A-Dam
X-A-Dgt
X-A-Dcw
X-Ec-Fail
DCR-Processing-Time-Ms
X-Cache-NE
X-Rewrite-Enabled
T-Server
Xc-Version
X-D
DCR-Decision-By
X-Served-From
X-TIM-N
Surrogated-Key
X-Rojux
Cdncip
Sslversion
X-ScT
X-Connection-Hash
Cdnsip
A
X-S
X-S-Cookie
Rendered-Blocks
X-Vdms-Path
Meta-Geo-Continent
BehaviorPad-Version
X-Owner
X-Orig-Expires
X-BCube-Filmed-By
X-User
X-NAPM-TraceId
MD5-Digest
X-Shop-Environment
X-Vdms-Version
X-SRCache-Key
Odigeo-Trace-Id
X-Destination
X-Processor
X-Developer
Ngx.Var.Host
X-PBS-Appsvrname
X-ARC
OT-Force-Account-Verify
Mime-Version
CPC-Cache
X-Dispatcher-Number
VNS-Cache
VNS-Age
X-Bip
CPC-Age
Machine
X-Pool
X-Varnish-Beresp-Status
X-Parent-Response-Time
X-Accel-Buffering
Cache-Hits
Upgrade-Insecure-Requests
Redirect-Candidate
X-Level-Front-Cache
X-Qloud-Router
X-Aicache-OS
X-Thanos
X-Generated-On
X-WA-Info
Thinkindot-CacheControl
X-Ad-Defer-Variation
TDXMobile
X-Cache-Info
State
X-Variation
Servername
X-Varnish-CookieHashed-On
X-Cdn-Srv
X-Cdn-Origin
X-CacheTTL
X-Cache-Id
X-Cache-Bucket
Tube-Got-Eval
Wxu-Next-Commit
Tube-Got-Results
Tube-Return
Vix-Hermes-Req-Id
V-Age
Tube-Get-Contents
Wxu-Next-Hostname
Thinkindot-Control
X-BBC-Edge-Cache-Status
X-Branch-Name
Traceparent
Wxu-Next-Region
X-V-Cache
Thinkindot-CacheControl-Type
X-Gateway-Request-Id
X-Optimistic-Header
X-NodeID
X-SVT-ORM-VERSION
X-Origin
X-Origin-Response-Time
X-Planisys-CDN-Cache
X-SVT-ORM-RULES
X-Mvc-Supplant-OutputCached
X-Mvc-Supplant-Cachable
X-Irp-Debug
X-HS-Content-Campaign-Id
X-Thinkindot-L3
X-Is-Gdpr
X-JWT-State
X-Minions-Version
X-Loc
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-SB
X-S-Maxage
X-Rocket-Nginx-Serving-Static
X-Scale
X-Slack-Backend
X-Sigma-Backend
X-Sigma
X-Rocket-Build-Number
X-Request-URI
X-SplitTest
X-Policy
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Sn-Servicetimems
X-Region-Sid
X-Hash
X-Has-Esi
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
X-DefElseHash
X-DefHash
X-Device-Os
X-Developers
X-Csrf-Jwt
X-Core-Value
X-Clara-WADP
X-Ckpd-Fst-Backend
X-Clientip
X-Cluster
X-Core-Mission
X-CMSURLCustom
X-DPWN-IS-SECURE
X-Ec-Custom-Error
X-Gateway-Skip-Cache
Server-Host
X-Gateway-Cache-Status
X-Geo-Header
X-GeoIP
X-Gzip
X-GeoIP-City
X-Gateway-Cache-Key
X-Gamma-Serve
X-Esi-Check
X-Epic-Correlation-Id
X-Eu-Site
X-Fetched-On
X-Forwarded-Site
X-Fmm-Version
X-CGP
Fastly-SSL
Decoy-Debug-TTL
DSUID
Decoy-Debug-Status
Decoy-Debug-Key
Cmstype
Country-Code
X-Gdpr
X-Nyt-Route
Fastly-SWR
X-VG-TLSProxy
X-CSRF-Token
Fastly-SIE
X-Origin-Time
Fastly-Backend-Name
Cmsid
Click-Count-Error
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
Apple-News-Services-Host
Apple-News-Services-Handled
X-Worker
Adler-Geo
X-Wix-Viewer-Type
Cache-Host
X-VServer
Click-Count-Action-Start
Candidate-Md5Url
Canary
X-WADP-Cache
Ha-Gx-Prefs
Fastly-GeoIP-CountryCode
Origin-CC
HA-Ipaddr
Req-Svc-Chain
NM-Fastcgi-Cache
NGX
Release
Origin-EX
Producers
Platform
X-Varnish-Remaining-TTL
HostName
X-Varnish-CookieINHashed-On
Mobile-Detection-Method
Kp-EeAlive
IsBot
Is-Eu
L
L5d-Success-Class
X-SIPLIST1
Memcached
X-Cache-Debug
X-VC
Cache-Tv-Group
X-Tx-Id
WebServer
Ec-Rule-Version
Mail-Subject
Datacenter
Web-Mar-Region
X-INCAP-ABP
Server-Hostname
X-Gen-Mode
Cluster
X-Proxy-Cache-Info
X-Hnp-Log
X-Viewer-Country
We-Hiring
X-Scheme
X-Auto-Login
X-NCache
Gh-Request-Id
Sever-Int
User-Cache-Control
X-Block-Status
Fastcgi-Cache-TTL
Svr
Server-Ext
CloudFront-Viewer-Country
AKAMAI
CDCHOST
X-WP-CF-Super-Cache-Active
X-Cache-Remote
X-Sucuri-ID
X-Fastly-Cache
X-Sucuri-Cache
X-LB-NoCache
X-Session-Fingerprint
X-Origin-Expires
X-Rebelmouse-Surrogate-Control
X-ND-Cache
X-Rebelmouse-Cache-Control
X-Udemy-Cache-App-Namespace
X-FC-Vary-Parameters
X-ATG-Version
Time
X-Fastly-Backend
Pics-Label
Memory
Sid
X-Azure-Ref-OriginShield
Ssr
X-ZONE
X-Var-Ttl
X-Nf-Request-Id
Fastly-Drupal-HTML
X-Tb-Optimization-Total-Bytes-Saved
X-Pod-Name
X-Trace-ID
X-Newrelic-App-Data
X-NWS-UUID-VERIFY
X-Generated-In
SID
X-Presslabs-Stats
X-Akamai-Transformed
AMP-Access-Control-Allow-Source-Origin
X-Buckets
X-Refresh
X-Via-Popn
Env
X-Via-Poph
X-Via-Popv
X-Ig-Push-State
Server-ID
X-Xrds-Location
X-Cache-Date
X-Servedbyhost
X-Cs
X-Release
X-Conf
X-Edge-Pop
X-CACHE-AGE
X-Microcachable
X-Fpc
X-MSEdge-Features
X-NC
X-Up
X-MSEdge-Flight
X-DC
X-Pass-Why
X-EC-Lua
My-App
X-Dispatch
X-Dmc
X-Wa
X-Esi
Fastly-Drupal-Html
X-PX
X-Tumblr-Pixel-3
GeoIp-Country-Code
X-Endurance-Cache-Level
X-Zone
X-Lambda-Id
X-MCACHE
X-ID
X-NGINX-Cache
CDN
X-VCL-Version
Magicmarker
True-Client-IP
X-Be
X-CS
X-Vc
X-TX-ID
X-TRACE-ID
X-RateLimit-Reset
X-Req
X-Webkit-CSP-Report-Only
X-CSRF-TOKEN
Hostname
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-CACHE-KEY
CacheControlHeader
X-Air-Source
X-Air-Hostname
X-Air-Trace-Id
X-Hyper-Cache
X-Yandex-Sdch-Disable
X-CF-Lambda-Fn
X-TH-Server
X-LB-ID
True-Client-Country-4JS
X-CF-Lambda-Version
X-Srv
X-Micro-Cache
X-Air-Pt
X-M-Reqid
X-Op-Id-All
X-HS-Status
Resin-Trace
X-M-Log
X-Alfa-Service
X-App
Pramga
X-B3-Spanid
X-Vcl-Version
C-Via
X-Qnm-Cache
True-Client-Ip
Path
Tcn
X-TrackingId
GeoIP-Country-Code
N-Cache
Tracecode
X-Varnish-Beresp-TTL
X-SERVER-NAME
X-GeoIP-Region-Code
X-GeoIP-Country-Code
Proxy-Connection
Fastcgi-X-Cache-Version
X-Vercel-Id
X-Platform
Esi-Enabled
X-PAYTM-SRV-ID
X-Vercel-Cache
On-Server
X-Check-Cacheable
X-CLOUD-TRACE-CONTEXT
NtCoent-Length
X-Edge-Origin-Shield-Region
X-Edge-Origin-Shield-Bytes
Section-Io-Origin-Time-Seconds
Hit
X-Date
WWW-Authenticate
Section-Io-Id
X-FPC
Section-Origin-Responded
X-Datacenter
X-Akamai-Pragma-Client-IP
Section-Io-Origin-Status
X-Accel-Expires-Debug
X-Webkit-Csp-Report-Only
X-Platform-Processor
X-Platform-Cluster
X-RAMCache
X-Platform-Router
X-Geo
X-Vtex-Processado-Em
X-Via-CDN
X-Node-Id
X-Vtex-Remote-Cache
X-Mly-Id
X-Lb-Id
X-WA
GeoIP-Latitude
Yjs-Id
Server-Id
X-Via-PopN
X-Edge-POP
X-SD-PageType
YJS-ID
X-Via-PopV
ENV
X-API-Version
X-ServedByHost
X-Response-By
User-Agent
X-LAGOON
X-Via-PopH
Lb
X-Request-Start
FSS-Cache
X-Old-Content-Length
X-AIR-PT
X-Dw-Trace-Id
X-Cdn-Forward
HIT
Cache-Key
Powered-By
X-LiteSpeed-Cache-Control
X-ApacheServer
X-PERF
Cdn
XServer
X-Instance-Name
Locid
X-Location
X-Traceid
X-FORWARDED-FOR
Srvid
X-From
X-FL-EDGE
X-Akamai-ERRuleID
X-Proxy-CacheRZ
X-CUA
X-Akamai-ERPolicy
Dnion-Transfer-Encoding
XkeyRZ
X-Via-Ucdn
Server-Ttl
X-TT-LOGID
X-UA
DynaTrace
Geoip-Latitude
X-Render-Time
X-Li-Pop
X-LI-Proto
X-Cache-Ttl
X-LI-UUID
X-Li-Fabric
X-Service-Response-Time
Sm-Log-Id
X-DI
X-DSS
Ohc-File-Size
X-DB
X-Webstats-RespID
X-RPM
XM
PFcat
X-VarnishDD-TTL
X-HN
X-RSL
Nginx-CQVIP
X-RPS
X-DW
X-LiteSpeed-Tag
DT-Hot-News
Location
PICS-Label
X-CF-Powered-By
X-Proxy-Cache-Hk
X-Proxy-Upstream
X-Cache-Ngx
X-Wp-Cf-Super-Cache-Cache-Control
X-Litespeed-Cache-Control
X-Wp-Cf-Super-Cache
X-Contensis-Viewer-Groups
X-Varnish-Authentication
X-Fastly-Cache-Hits
X-HostName
X-Request-Url
X-B3-ParentSpanId
Vha6-Origin
Wpo-Cache-Status
X-Lb-Nocache
X-Cache-ASPX
Wpo-Cache-Message
X-Director
X-ElasticPress-Query
X-Fastly-Backend-Reqs
X-Cdn-Request-ID
CountryCode
X-Ips-Loggedin
Warning
Wp-Super-Cache
Req-ID
X-DataCenter
X-Yottaa-OS
Fastcgi-Cache-Ttl
X-Moov-T
WZWS-RAY
SRV
X-Mg-Cache
X-Moov-Xdn-Version