Threat Level: green Handler on Duty: Rick Wanner

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
Strict-Transport-Security
X-Frame-Options
X-Content-Type-Options
Last-Modified
Link
CF-Cache-Status
Cf-Request-Id
Accept-Ranges
ETag
Expect-CT
Pragma
CF-RAY
X-Powered-By
X-Cache
Via
Age
X-XSS-Protection
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Xss-Protection
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-FRAME-OPTIONS
X-Download-Options
X-Timer
X-Request-Id
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-Adblock-Key
CF-Ray
X-Permitted-Cross-Domain-Policies
X-AspNet-Version
Alt-Svc
X-Runtime
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Check
X-DNS-Prefetch-Control
X-Cache-Status
X-Generator
X-Cacheable
X-Iinfo
Timing-Allow-Origin
X-Envoy-Upstream-Service-Time
Feature-Policy
Status
X-Content-Security-Policy
X-Request-ID
X-Drupal-Dynamic-Cache
Content-Encoding
Access-Control-Expose-Headers
X-CDN
X-AspNetMvc-Version
Upgrade
X-XSS-PROTECTION
X-Ua-Compatible
Access-Control-Max-Age
X-Dns-Prefetch-Control
X-Via
X-Cache-Group
X-Robots-Tag
Server-Timing
Request-Context
X-UA-Device
Keep-Alive
X-Amz-Request-Id
X-AH-Environment
X-Turbo-Charged-By
X-Proxy-Cache
X-Amz-Id-2
X-Backend
X-Ws-Request-Id
P3p
X-Age
Host-Header
X-Server-Powered-By
X-Hacker
X-Server
X-Rq
X-Vhost
EagleId
X-Varnish-Cache
Grace
X-Amz-Version-Id
X-Dispatcher
X-LiteSpeed-Cache
Cf-Edge-Cache
X-Akamai-Path-Stats
Allow
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-Device
X-Nginx-Cache-Status
X-Page-Speed
X-WebKit-CSP
X-Aws-Lambda-Call-Status
X-Host
X-Node
Accept-CH
X-Pingback
X-OneAgent-JS-Injection
X-Server-Id
Cf-Railgun
X-Cache-Spec
Request-Id
Surrogate-Control
EagleEye-TraceId
X-Akam-SW-Version
X-Backend-Server
X-Cache-Lookup
X-Response-Time
X-Readtime
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Accept-CH-Lifetime
X-HW
Content-Location
X-Content-Security-Policy-Report-Only
X-Application-Context
X-Trace
Rating
X-Cloud-Trace-Context
Fastly-Restarts
X-Url
X-Clacks-Overhead
X-WebKit-CSP-Report-Only
Accept-Ch-Lifetime
X-Country
X-Edge
X-MS-InvokeApp
X-Amz-Server-Side-Encryption
Edge-Control
X-Rack-Cache
X-Nginx-Upstream-Cache-Status
X-TtlSet
X-Vname
X-PC
X-B3-TraceId
X-Content-Type
X-ESI
X-Mod-Pagespeed
X-Vcap-Request-Id
X-Oneagent-Js-Injection
X-Ruxit-JS-Agent
X-Ruxit-Js-Agent
Xkey
X-D2id
Verso
X-Kinja-Revision
X-GoogleNews-Bot
X-Exp-Id
X-Kinja-Build
X-Exp-Variant
X-Use-Magma
X-Cdn-Fetch
X-Amz-Rid
X-Kinja-Server
X-Kinja
X-GitHub-Request-Id
X-Varnish-TTL
X-Mcache
Cache-Tag
X-VARITI-CCR
X-Powered-By-Plesk
X-FastCGI-Cache
X-ASPNET-VERSION
RTSS
X-CST
Service-Worker-Allowed
X-ECACHE
X-Upstream
X-Abt-Application-Version
X-Version
X-Navigation-Version
X-Client-IP
X-Cached
X-Cnection
X-Dw-Request-Base-Id
X-Ac
X-Px
X-Server-Lifecycle-Phase
X-Instrumentation
X-Element-Page-Cache
X-Server-Name
X-Ttl
Public-Key-Pins
X-Kraken-Loop-Name
Arr-Disable-Session-Affinity
SPRequestGuid
X-SharePointHealthScore
X-Cache-TTL
SPIisLatency
SPRequestDuration
Pagespeed
Display
Accept-Ch
X-Middleton-Display
X-Sol
X-NWS-LOG-UUID
X-Country-Code
X-Ser
Permissions-Policy
X-Cache-Key
X-Midtier
X-RateLimit-Remaining
Response
X-Middleton-Response
X-Kinsta-Cache
X-Edge-Location-Klb
X-Goog-Hash
X-Forwarded-For
Access-Control-Request-Method
Content-MD5
X-Correlation-Id
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-NF-Request-ID
X-DataDome
Front-End-Https
X-Shield-Request-Id
X-MSEdge-Ref
X-T
X-HP-Webp
X-Jurisdiction
X-HP-Trace-Id
TP-Cache
TP-L2-Cache
X-Recruiting
Edge-Cache-Tag
Nginx-Cache
AR-ATIME
AR-PoweredBy
AR-SID
X-Accel-Expires
AR-CACHE
AR-Request-ID
MicrosoftSharePointTeamServices
X-Powered-CMS
X-B3-TraceId-Primal
X-Daa-Tunnel
Mrf-Cache-Status
MRF-Tech
X-RateLimit-Limit
Cf-Apo-Via
TCN
X-Grace
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
X-Mg-S
X-Id
X-Content-Digest
X-Hits
Filters
X-Request-Received
X-Request-Processing-Time
X-HS-Cache-Config
X-HS-Hub-Id
X-HS-Combine-CSS
X-HS-Content-Id
Server-Node
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
Server-Name
X-Amzn-Trace-Id
X-Distributor
MS-Author-Via
X-Frontend
X-Geo-Country
X-Webkit-Csp
S
X-Protected-By
Fastcgi-Cache
X-LLID
X-Fastly-Request-Id
X-Language
X-XRDS-Location
Cache-Status
X-PressLabs-Stats
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-LB-Cache
X-Browser-Type
Cross-Origin-Opener-Policy
X-Origin-Server
X-Ezoic-Cdn
Count-Hit
Host
X-Litespeed-Cache
Charset
X-B3-Sampled
X-Amz-Meta-S3cmd-Attrs
X-Request-Handler-Origin-Region
X-Forwarded-Proto
X-Microsite
X-F-Cache
X-Ab
X-Git-Hash
X-Seen-By
X-Page-Id
X-Ua-Browser
X-FB-Debug
Payment
Filterid
X-Ratelimit-Reset
X-TTL
X-Fastcgi-Cache
X-VCache
X-Cluster-Name
Surrogate-Key
Realpath
X-Origin-Cache
X-Rid
Accept-Charset
X-Cache-Age
Cache-Tags
X-Template
X-NGENIX-Cache
Alternate-Protocol
X-Www-Served-By
Retry-After
Access-Control-Allow-Method
X-Az
X-Activity-Id
X-AppVersion
X-DynaTrace
Cleartype
X-Upgrade-Enabled
X-Logged-In
X-Aspnetmvc-Version
X-Amz-Replication-Status
X-DIS-Request-ID
X-Route-Name
X-Providence-Cookie
X-Varnish-Grace
X-TT
X-Tb
X-Request-Guid
X-Aspnet-Duration-Ms
X-Flags
X-App-Environment
X-Is-Crawler
X-B
X-Varnish-Backend
X-B-Cache
X-Wix-Request-Id
X-Type
X-Signature
X-Node-Name
X-Envoy-Decorator-Operation
Paypal-Debug-Id
DC
ServerID
X-Source
X-Hostname
X-Drupal-Cache-Tags
Frame-Options
X-Debug
X-Proxy
X-Revision
X-Mobile
X-Content-Options
X-Contextid
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-COUNTRY
X-Load-Cache
Pinterest-Generated-By
Pinterest-Version
X-Pinterest-Rid
X-Fastly-Request-ID
X-GUploader-UploadID
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
Amp-Access-Control-Allow-Source-Origin
X-Goog-Storage-Class
X-Goog-Generation
X-Goog-Metageneration
X-Cache-Rule
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-N
X-Content
X-Cache-Control
Country
X-Magnolia-Registration
Node
Refresh
X-User-Agent
X-Whom
Referer-Policy
X-Response-Served-From
X-Original-Request-Id
X-EdgeConnect-Cache-Status
Viewport
X-Oracle-Dms-Ecid
X-Oracle-Dms-Rid
NGB
X-Framework
X-Ratelimit-Remaining
X-L-Path
X-Environment-Context
Access-Control-Request-Headers
X-Cacheable-TTL
X-Cache-TTL-Remaining
X-Debug-IsConnected
X-Debug-IsPreview
X-Page-View
X-Real-IP
X-Adobe-Content
X-G
X-Mid
X-Adobe-Loc
X-Status
X-Yottaa-Metrics
X-Varnish-Server
X-Yottaa-Optimizations
X-Content-Powered-By
X-NYM-Debug-Backend
Content-Disposition
Akamai-GRN
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
Uber-Trace-Id
X-Akamai-Request-ID2
X-Unique-Id
X-Rendered-As
X-Varnish-Age
X-Is-Bot
X-Servername
X-Jobs
X-Cache-Time
Url
X-Cache-Grace
Srv
X-RemovedCookies
X-ProcessESI
X-Server-ID
X-Instance
Countrycode
X-Drupal-Cache-Contexts
X-Mg-Request-UUID
X-APP-VERSION
Version
X-Restarts
X-Trace-Id
X-Http-Reason
X-CDN-Forward
X-XRDS-LOCATION
X-App-Server
Accept-Language
X-Cache-Expired-At
X-Time
X-Via-JSL
X-Debug-Info
X-Tumblr-Pixel-1
X-Cache-Hit
Protected
X-Tumblr-User
X-IPLB-Instance
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-IPLB-Request-ID
Healthy
X-Hosted-By
X-Ratelimit-Limit
X-Cache-Operation
X-Nginx-Cache-Key
X-Azure-Ref
X-Device-Type
Cross-Origin-Resource-Policy
Section-Io-Cache
Liferay-Portal
X-Backend-Name
X-Tt-Logid
X-Akamai-Edgescape
X-FW-Type
X-FW-Server
X-FW-Serve
Backend
X-FW-Static
X-FW-Dynamic
Server-Info
Content-Secure-Policy
X-FW-Hash
Fastcgi-Useragent
Ms-Operation-Id
X-Rule
X-RTag
MS-CV
X-RN-RSRV
Load-Balancing
X-Storage
X-Cache-Action
X-Proxy-Cache-Status
Meta-Geo
X-Mobile-URL
X-UPSTREAM-Address
GEO-INFO
X-SRV
X-Mode
X-VC-Cache
X-Handled-By
X-Api-Version
X-Content-Age
X-UUID
X-Cache-NGX
X-Varnish-Beresp-Grace
CDN-Cache
X-PHP-Backend
CDN-CachedAt
CDN-PullZone
CDN-RequestCountryCode
CDN-EdgeStorageId
X-Proto
X-Say-Cacheable
X-Say-TTL
X-SayCDN-TTL
CF-IPCountry
X-Region
CDN-RequestId
X-Redis-Cache
X-PHP-Host
X-PCL
X-Edge-Location
X-Alternate-Cache-Key
X-Forwarded-Host
X-AWS-Id
X-Cms-Context
X-Cache-Server
X-Cache-Enabled
X-Adobe-Source
X-Access
X-OCL
Eomportal-Instance
X-Section
X-No-Session
Locale
X-Labrador-Cache-Channel
X-LJ-Flow-ID
CDN-Uid
Onion-Location
X-Sorting-Hat-PodId
X-Varnishpool
X-Sorting-Hat-ShopId
X-Site-Version
X-Urbn-Context-Path
X-VWS-Id
X-Urbn-Site-Id
X-Shopify-Stage
X-Sql-Count
X-Varnish-Hostname
X-Skip-Cache
X-ShopId
X-Uri
X-URL
X-ShardId
X-Sql-Duration-Ms
X-Format
X-Locale
TWC-GeoIP-Country
TWC-Device-Class
Mn-Server-Ip
Webcakes-Region
X-Datadome
TWC-GeoIP-LatLong
X-HTML-Minification-Powered-By
X-Extlb
X-FB-TRIP-ID
X-Detected-As
X-Timing-Wait
X-Cache-Host
X-BYPASS-REASON
X-Generated-By
X-UA-Device-Type
DB-Nickname
Selected-Fe
X-Hl-Ver
X-GeoCountry
X-GeoCode
S-Rt
Webcakes-App-Name
Azure-Version
X-Routing-Service
X-Server-W
X-Varnish-Cache-Hits
X-Xfnlog-Site
X-Generation-Time
X-Zipkin-Id
Azure-SlotName
TWC-Privacy
X-ServerID
Azure-SiteName
Azure-InstanceId
X-Origin-Hint
X-Storefront-Renderer-Rendered
X-Request-Time
Web-Mar-Node
Apigw-Requestid
X-Via-Fastly
Azure-RegionName
Webcakes-App-Version
X-Cache-Type
TWC-Connection-Speed
X-Proxied
TWC-Locale-Group
X-Web-Node
Property-Id
X-ProxyCache-Status
X-Proxy-Build
X-ProxyCache-Key
X-Origin-Date
X-Tid
X-R9-Blue-Green-Version
X-Cache-Status-Check
X-Ms-Version
X-Ms-Request-Id
X-SaId
X-JoinUs
WP-Super-Cache
Cache-Name
Xserver
X-FireWall-Port
X-ECache
X-Zen-Fury
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
ServedBy
X-DynaTrace-JS-Agent
X-LSADC-Cache
X-Nginx-Cache
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Ua
X-Debug-Cache
X-Human
X-Dc
Xet-Cookie
X-TA-CDN-Provider
X-TNCMS
X-MP-GENERATED-AT
Cache
X-Loop
X-Cache-Tags
X-Correlation-ID
X-Reqid
X-RCS-CacheZone
Source
X-Cached-By
X-GEO
X-Cdn
X-Varnish-Hits
Cross-Origin-Window-Policy
X-Webkit-CSP
X-Pubstack
X-Soup
Origin
SD-X-WS
X-Newrelic-Synthetics
X-Amzn-Remapped-Content-Length
X-App-Version
WPO-Cache-Status
WPO-Cache-Message
X-Origin-CC
X-Provided-By
X-Vgn-Hpd-Reason
LB
X-Origin-TTL
X-Tumblr-Pixel-2
X-Varnish-Beresp-Ttl
X-Service
From-Origin
X-IPS-LoggedIn
X-Varnish-Ttl
X-TIME
X-AOL-HN
X-Tec-Api-Origin
X-B3-SpanId
X-Via-NSCOPI
X-NewRelic-App-Data
X-Tec-Api-Version
X-Tec-Api-Root
Rip
X-GG-Cache-Date
X-Request-Host
X-B3-Traceid
X-Platform-Server
X-FW-Version
Webserver
X-A-Wwc
X-Forwarded-Path
Expiry
X-ScT
X-A
X-D
Host-ID
X-VG-WebCache
X-A-Ccd
X-Served-From
X-A-Dcw
X-A-Dam
X-A-Dgt
X-External-Request-Id
DCR-Processing-Time-Ms
Rendered-Blocks
X-ARC
X-Application
DCR-Decision-By
X-Rojux
X-B-Cookie
X-Destination
X-Developer
X-Bc-Bl
BehaviorPad-Version
X-Connection-Hash
Environment
X-Rewrite-Enabled
X-AK-Request-ID
X-Ec-GeoHdr
X-BCube-Filmed-By
X-Shop-Environment
X-Ec-Fail
X-Aed
Cdnsip
X-Orig-Expires
A
Ngx.Var.Host
X-Vdms-Version
Meta-Geo-Continent
MD5-Digest
Cdncip
X-User
Surrogated-Key
X-Owner
X-Vdms-Path
X-SRCache-Key
X-Cache-NE
Odigeo-Trace-Id
X-PBS-Appsvrname
T-Server
X-Processor
X-Tenant
X-NAPM-TraceId
Lang
X-TIM-N
Xc-Version
X-Cluster-Node
X-S-Cookie
X-S
Sslversion
OT-Force-Account-Verify
Mime-Version
X-Qloud-Router
X-Pool
X-Parent-Response-Time
CPC-Cache
Upgrade-Insecure-Requests
VNS-Cache
VNS-Age
CPC-Age
X-Dispatcher-Number
X-Generated-On
X-Aicache-OS
X-Level-Front-Cache
X-Varnish-Beresp-Status
Redirect-Candidate
X-Thanos
Machine
X-Accel-Buffering
Cache-Hits
X-Bip
X-WA-Info
X-Branch-Name
X-Cache-Bucket
X-Cache-Id
X-BBC-Edge-Cache-Status
X-CacheTTL
X-Cache-Info
Tube-Return
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
Thinkindot-Control
Traceparent
TDXMobile
State
Server-Host
X-Varnish-CookieHashed-On
Servername
Tube-Get-Contents
Tube-Got-Eval
Wxu-Next-Hostname
Wxu-Next-Region
X-Ad-Defer-Variation
X-Variation
Wxu-Next-Commit
Vix-Hermes-Req-Id
Tube-Got-Results
X-Cdn-Origin
V-Age
X-V-Cache
X-Epic-Correlation-Id
X-Minions-Version
X-Loc
X-JWT-State
X-Mvc-Supplant-Cachable
X-Mvc-Supplant-OutputCached
X-NodeID
X-SVT-ORM-VERSION
X-Is-Gdpr
X-Irp-Debug
X-Scale
X-Gzip
X-Has-Esi
X-Thinkindot-L3
X-SB
X-HS-Content-Campaign-Id
X-Optimistic-Header
X-Origin
X-Region-Sid
X-S-Maxage
X-RateLimit-Remaining-Second
X-Sn-Servicetimems
X-Request-URI
X-Rocket-Nginx-Serving-Static
X-Rocket-Build-Number
X-RateLimit-Limit-Second
X-SplitTest
X-SVT-ORM-RULES
X-Origin-Response-Time
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Policy
X-Planisys-CDN-TTL
X-GeoIP-City
X-GeoIP
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
X-DefElseHash
X-DefHash
X-Device-Os
X-Developers
X-Csrf-Jwt
X-Core-Value
X-Ckpd-Fst-Backend
X-CGP
X-Clara-WADP
X-Clientip
X-CMSURLCustom
X-Cluster
X-DPWN-IS-SECURE
X-Ec-Custom-Error
Req-Svc-Chain
X-Gateway-Cache-Status
X-Gateway-Cache-Key
X-Gateway-Request-Id
X-Slack-Backend
X-Geo-Header
X-Gateway-Skip-Cache
X-Gamma-Serve
X-Forwarded-Site
X-Sigma
X-Sigma-Backend
X-Esi-Check
X-Eu-Site
X-Fmm-Version
X-Fetched-On
X-Cdn-Srv
Fastly-GeoIP-CountryCode
Cmstype
Country-Code
Cmsid
Click-Count-Error
X-VServer
Click-Count-Action-Start
Decoy-Debug-Key
Decoy-Debug-Status
Fastly-SSL
Fastly-SWR
Fastly-SIE
Fastly-Backend-Name
Decoy-Debug-TTL
DSUID
Candidate-Md5Url
Canary
X-Gdpr
X-Worker
HostName
X-Nyt-Route
X-SIPLIST1
X-Origin-Time
Apple-News-Services-Handled
Apple-News-Services-Host
Cache-Host
X-WADP-Cache
X-Wix-Viewer-Type
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
X-VG-TLSProxy
Adler-Geo
NGX
Platform
Ha-Gx-Prefs
Mobile-Detection-Method
Release
NM-Fastcgi-Cache
Origin-CC
X-Varnish-Remaining-TTL
X-Varnish-CookieINHashed-On
X-CSRF-Token
Origin-EX
L5d-Success-Class
Memcached
Kp-EeAlive
IsBot
Producers
Is-Eu
L
HA-Ipaddr
X-VC
Cache-Tv-Group
X-Tx-Id
WebServer
X-Cache-Debug
Datacenter
Gh-Request-Id
Web-Mar-Region
We-Hiring
Mail-Subject
X-INCAP-ABP
X-Proxy-Cache-Info
Server-Hostname
X-Gen-Mode
X-Viewer-Country
Server-Ext
X-Hash
Ec-Rule-Version
X-Scheme
X-Auto-Login
AKAMAI
Cluster
Svr
X-Block-Status
CloudFront-Viewer-Country
Fastcgi-Cache-TTL
User-Cache-Control
X-Hnp-Log
CDCHOST
X-Core-Mission
X-NCache
Sever-Int
X-Cache-Remote
X-WP-CF-Super-Cache-Active
X-LB-NoCache
X-Fastly-Cache
X-Rebelmouse-Cache-Control
X-Origin-Expires
X-Ua-Device
X-Rebelmouse-Surrogate-Control
X-ND-Cache
X-Sucuri-Cache
X-Session-Fingerprint
X-Sucuri-ID
X-Udemy-Cache-App-Namespace
X-ZONE
X-FC-Vary-Parameters
Ssr
X-Var-Ttl
Pics-Label
Time
Memory
X-Azure-Ref-OriginShield
X-Fastly-Backend
X-ATG-Version
Fastly-Drupal-HTML
X-Nf-Request-Id
X-Tb-Optimization-Total-Bytes-Saved
SID
X-Trace-ID
X-Pod-Name
X-NWS-UUID-VERIFY
X-Newrelic-App-Data
Sid
X-Generated-In
AMP-Access-Control-Allow-Source-Origin
X-Akamai-Transformed
X-Presslabs-Stats
X-Via-Popn
X-Xrds-Location
X-Via-Poph
X-Buckets
X-Ig-Push-State
X-Servedbyhost
Server-ID
X-Refresh
X-Cache-Date
X-Via-Popv
Env
X-Cs
X-Release
X-Edge-Pop
X-Conf
X-MSEdge-Flight
X-Microcachable
X-CACHE-AGE
X-Fpc
X-Up
X-MSEdge-Features
X-NC
X-DC
X-Pass-Why
X-EC-Lua
X-Dispatch
X-Dmc
X-Esi
X-Wa
My-App
Fastly-Drupal-Html
X-Tumblr-Pixel-3
X-PX
GeoIp-Country-Code
X-Zone
X-Endurance-Cache-Level
X-MCACHE
X-Lambda-Id
X-ID
CDN
X-NGINX-Cache
X-VCL-Version
X-Be
Magicmarker
True-Client-IP
X-CS
X-TX-ID
X-TRACE-ID
X-Vc
X-RateLimit-Reset
X-Req
Hostname
X-Webkit-CSP-Report-Only
X-Wikidot-Backend
X-CSRF-TOKEN
X-Wikidot-Static-Cache
X-CACHE-KEY
CacheControlHeader
X-Air-Trace-Id
X-Air-Hostname
X-Air-Source
X-Hyper-Cache
X-Yandex-Sdch-Disable
X-CF-Lambda-Fn
X-TH-Server
X-LB-ID
True-Client-Country-4JS
X-CF-Lambda-Version
X-Srv
X-Micro-Cache
X-Air-Pt
X-Op-Id-All
X-M-Reqid
X-M-Log
X-HS-Status
Resin-Trace
X-Alfa-Service
Pramga
X-App
X-B3-Spanid
C-Via
X-Qnm-Cache
X-Vcl-Version
True-Client-Ip
Tcn
Path
N-Cache
X-TrackingId
GeoIP-Country-Code
Tracecode
X-Varnish-Beresp-TTL
X-SERVER-NAME
X-Vercel-Cache
X-Vercel-Id
X-GeoIP-Country-Code
X-Platform
X-GeoIP-Region-Code
On-Server
X-PAYTM-SRV-ID
Fastcgi-X-Cache-Version
Proxy-Connection
Esi-Enabled
X-Check-Cacheable
NtCoent-Length
X-CLOUD-TRACE-CONTEXT
X-FPC
X-Akamai-Pragma-Client-IP
X-Edge-Origin-Shield-Bytes
X-Edge-Origin-Shield-Region
Section-Origin-Responded
WWW-Authenticate
X-Accel-Expires-Debug
X-Date
Section-Io-Id
Section-Io-Origin-Status
Hit
X-Datacenter
Section-Io-Origin-Time-Seconds
X-Webkit-Csp-Report-Only
X-Node-Id
X-Lb-Id
GeoIP-Latitude
X-Platform-Router
X-Vtex-Processado-Em
X-Platform-Processor
X-Platform-Cluster
X-Via-CDN
X-WA
X-Geo
X-Mly-Id
X-RAMCache
X-Vtex-Remote-Cache
Yjs-Id
YJS-ID
X-Via-PopN
X-Via-PopV
Server-Id
Lb
FSS-Cache
X-SD-PageType
X-LAGOON
X-API-Version
X-Edge-POP
X-ServedByHost
X-Old-Content-Length
X-Response-By
X-Via-PopH
ENV
X-Request-Start
User-Agent
X-Dw-Trace-Id
X-Cdn-Forward
X-AIR-PT
Cache-Key
Powered-By
HIT
Cdn
X-ApacheServer
X-LiteSpeed-Cache-Control
X-PERF
X-From
X-Location
X-FL-EDGE
X-FORWARDED-FOR
X-Traceid
Locid
X-Instance-Name
Srvid
X-Akamai-ERRuleID
X-Proxy-CacheRZ
X-CUA
X-Akamai-ERPolicy
Dnion-Transfer-Encoding
XkeyRZ
X-UA
Server-Ttl
X-TT-LOGID
X-Render-Time
DynaTrace
Geoip-Latitude
X-Via-Ucdn
X-LI-UUID
X-Cache-Ttl
X-Li-Pop
X-LI-Proto
X-Li-Fabric
X-Service-Response-Time
Sm-Log-Id
X-Proxy-Upstream
X-DI
X-DW
Nginx-CQVIP
X-DSS
X-LiteSpeed-Tag
X-Webstats-RespID
Ohc-File-Size
XServer
X-RPM
X-VarnishDD-TTL
Location
PFcat
X-HN
XM
X-CF-Powered-By
PICS-Label
X-Proxy-Cache-Hk
X-RSL
DT-Hot-News
X-RPS
X-DB
X-Cache-Ngx
X-Litespeed-Cache-Control
X-Wp-Cf-Super-Cache-Cache-Control
X-Wp-Cf-Super-Cache
X-Fastly-Cache-Hits
X-Cache-ASPX
X-Request-Url
X-HostName
X-B3-ParentSpanId
X-Contensis-Viewer-Groups
X-Varnish-Authentication
X-Cdn-Request-ID
Vha6-Origin
Wpo-Cache-Status
X-Lb-Nocache
Wpo-Cache-Message
X-ElasticPress-Query
X-Director
X-Fastly-Backend-Reqs
Warning
X-Ips-Loggedin
CountryCode
Wp-Super-Cache
Req-ID
X-DataCenter
X-Yottaa-OS
Fastcgi-Cache-Ttl
X-Moov-T
WZWS-RAY
SRV
X-Mg-Cache
X-Moov-Xdn-Version