Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
Strict-Transport-Security
X-Frame-Options
X-Content-Type-Options
Last-Modified
Link
CF-Cache-Status
Cf-Request-Id
Accept-Ranges
ETag
Expect-CT
Pragma
CF-RAY
X-Powered-By
X-Cache
Via
X-XSS-Protection
Age
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Amz-Cf-Pop
X-Xss-Protection
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-FRAME-OPTIONS
X-Download-Options
X-Timer
X-Request-Id
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-Adblock-Key
CF-Ray
X-AspNet-Version
X-Permitted-Cross-Domain-Policies
X-Runtime
Alt-Svc
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Check
X-DNS-Prefetch-Control
X-Cache-Status
X-Generator
X-Cacheable
Timing-Allow-Origin
X-Iinfo
X-Request-ID
X-Envoy-Upstream-Service-Time
Feature-Policy
Status
X-Content-Security-Policy
X-Drupal-Dynamic-Cache
Content-Encoding
X-AspNetMvc-Version
X-CDN
Access-Control-Expose-Headers
Upgrade
X-XSS-PROTECTION
X-Ua-Compatible
Access-Control-Max-Age
X-Dns-Prefetch-Control
X-Via
X-Cache-Group
Server-Timing
X-Robots-Tag
X-UA-Device
Request-Context
Keep-Alive
X-Amz-Request-Id
X-AH-Environment
X-Turbo-Charged-By
X-Backend
X-Amz-Id-2
X-Proxy-Cache
X-Ws-Request-Id
P3p
X-Age
Host-Header
X-Server-Powered-By
X-Hacker
X-Server
X-Rq
X-Vhost
EagleId
X-Akamai-Path-Stats
X-Varnish-Cache
Grace
X-Amz-Version-Id
X-Dispatcher
X-LiteSpeed-Cache
Cf-Edge-Cache
Allow
X-Swift-SaveTime
X-Swift-CacheTime
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
Ali-Swift-Global-Savetime
X-Nginx-Cache-Status
X-Device
X-WebKit-CSP
X-Page-Speed
X-Aws-Lambda-Call-Status
X-Host
X-Node
X-OneAgent-JS-Injection
X-Pingback
EagleEye-TraceId
X-Server-Id
X-Cache-Spec
Request-Id
Surrogate-Control
Accept-CH
Cf-Railgun
X-Akam-SW-Version
X-Backend-Server
X-Cache-Lookup
X-Readtime
X-Response-Time
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Accept-CH-Lifetime
X-HW
Content-Location
X-Content-Security-Policy-Report-Only
X-Application-Context
Rating
X-Trace
Fastly-Restarts
X-Cloud-Trace-Context
X-Country
X-WebKit-CSP-Report-Only
X-Url
X-Clacks-Overhead
Accept-Ch-Lifetime
X-Edge
X-B3-TraceId
X-MS-InvokeApp
X-Amz-Server-Side-Encryption
X-Rack-Cache
Edge-Control
X-Ruxit-JS-Agent
X-PC
X-TtlSet
X-Vname
X-Nginx-Upstream-Cache-Status
X-Content-Type
X-ESI
X-Vcap-Request-Id
X-Mod-Pagespeed
Xkey
Accept-Ch
X-GoogleNews-Bot
X-Kinja
X-D2id
X-Exp-Id
X-Kinja-Revision
X-Kinja-Build
X-Exp-Variant
X-Cdn-Fetch
X-Kinja-Server
X-Use-Magma
X-Varnish-TTL
X-Mcache
X-Amz-Rid
X-VARITI-CCR
X-GitHub-Request-Id
Cache-Tag
Verso
X-CST
RTSS
X-Powered-By-Plesk
X-FastCGI-Cache
X-ECACHE
X-Oneagent-Js-Injection
Service-Worker-Allowed
X-Cached
X-Upstream
X-Navigation-Version
X-Version
X-Client-IP
X-Abt-Application-Version
X-Dw-Request-Base-Id
X-Ruxit-Js-Agent
X-Px
X-Ac
X-Cnection
Public-Key-Pins
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
Arr-Disable-Session-Affinity
X-Instrumentation
X-Element-Page-Cache
X-SharePointHealthScore
SPRequestGuid
X-Server-Name
X-Ser
Display
Pagespeed
X-Middleton-Display
X-Sol
SPRequestDuration
SPIisLatency
X-Country-Code
X-Cache-TTL
X-NWS-LOG-UUID
X-Ttl
X-RateLimit-Remaining
Permissions-Policy
X-Midtier
X-Cache-Key
Response
X-NF-Request-ID
X-Middleton-Response
X-Kinsta-Cache
X-Edge-Location-Klb
X-Goog-Hash
X-Forwarded-For
Content-MD5
Access-Control-Request-Method
X-DataDome
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Shield-Request-Id
Front-End-Https
X-MSEdge-Ref
X-Correlation-Id
X-T
X-Recruiting
X-HP-Webp
TP-Cache
Nginx-Cache
X-HP-Trace-Id
Edge-Cache-Tag
TP-L2-Cache
X-Jurisdiction
AR-Request-ID
AR-ATIME
AR-SID
AR-CACHE
AR-PoweredBy
X-Accel-Expires
X-Powered-CMS
X-RateLimit-Limit
X-ORACLE-DMS-RID
X-Daa-Tunnel
X-ORACLE-DMS-ECID
MicrosoftSharePointTeamServices
TCN
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
X-Grace
X-Mg-S
X-Id
X-Hits
X-Content-Digest
X-Request-Received
X-Request-Processing-Time
X-TEC-API-VERSION
X-TEC-API-ROOT
Server-Node
X-TEC-API-ORIGIN
X-HS-Cache-Config
X-HS-Combine-CSS
X-HS-Content-Id
X-HS-Hub-Id
Filters
Server-Name
X-Frontend
S
X-Amzn-Trace-Id
X-LLID
X-Distributor
X-TTL
MS-Author-Via
X-Protected-By
X-Geo-Country
Cache-Status
X-Language
Fastcgi-Cache
X-LB-Cache
Cf-Apo-Via
X-PressLabs-Stats
Cross-Origin-Opener-Policy
X-Origin-Server
X-Forwarded-Proto
X-Fastly-Request-Id
X-Ezoic-Cdn
X-F-Cache
X-Request-Handler-Origin-Region
X-Seen-By
X-FB-Debug
X-B3-Sampled
Filterid
Host
X-Microsite
X-Page-Id
X-XRDS-Location
X-Git-Hash
Charset
X-Ab
X-Ua-Browser
Count-Hit
X-Amz-Meta-S3cmd-Attrs
Payment
X-Litespeed-Cache
X-ASPNET-VERSION
X-Browser-Type
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
Realpath
X-Fastcgi-Cache
X-Cache-Age
X-VCache
X-Cluster-Name
X-Ratelimit-Reset
Accept-Charset
X-Template
Surrogate-Key
X-Origin-Cache
Cache-Tags
Alternate-Protocol
X-Rid
X-NGENIX-Cache
X-Webkit-Csp
X-DynaTrace
Cleartype
Retry-After
X-AppVersion
X-Az
X-Activity-Id
X-Www-Served-By
Access-Control-Allow-Method
X-Varnish-Backend
X-Varnish-Grace
X-Wix-Request-Id
X-Is-Crawler
X-Node-Name
X-TT
X-B-Cache
X-Request-Guid
X-Aspnet-Duration-Ms
X-Signature
X-Route-Name
X-App-Environment
X-Flags
X-Providence-Cookie
X-Tb
X-DIS-Request-ID
X-Type
X-B
X-Upgrade-Enabled
X-Amz-Replication-Status
Paypal-Debug-Id
DC
X-Drupal-Cache-Tags
ServerID
X-Debug
X-Logged-In
X-Proxy
X-Fastly-Request-ID
X-Source
X-Envoy-Decorator-Operation
Frame-Options
X-Hostname
X-Server-ID
X-Content
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Mobile
X-Content-Options
X-Revision
Pinterest-Version
X-Pinterest-Rid
X-Load-Cache
Pinterest-Generated-By
X-Contextid
X-Goog-Generation
X-GUploader-UploadID
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
Amp-Access-Control-Allow-Source-Origin
X-Cache-Control
X-N
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Cache-Rule
X-Magnolia-Registration
Country
Referer-Policy
X-User-Agent
X-Whom
Viewport
X-EdgeConnect-Cache-Status
NGB
Refresh
X-Original-Request-Id
Node
X-Response-Served-From
Access-Control-Request-Headers
X-Framework
X-Debug-IsPreview
X-L-Path
X-Ratelimit-Remaining
X-Cacheable-TTL
X-Varnish-Age
X-Cache-TTL-Remaining
X-Debug-IsConnected
Content-Disposition
X-Environment-Context
VIX-Pulpo-Node
X-Is-Bot
VIX-Pulpo-Upstream-Status
X-Mid
X-Cache-Grace
X-Akamai-Request-ID2
X-Yottaa-Optimizations
Url
X-Adobe-Content
X-Cache-Time
X-Unique-Id
X-Servername
Uber-Trace-Id
X-Jobs
X-Page-View
X-Rendered-As
X-Real-IP
X-Yottaa-Metrics
X-G
X-Adobe-Loc
X-Instance
X-Varnish-Server
X-Mg-Request-UUID
X-NYM-Debug-Backend
X-Restarts
X-Status
Akamai-GRN
X-Content-Powered-By
X-Drupal-Cache-Contexts
X-ProcessESI
Countrycode
X-RemovedCookies
Version
X-COUNTRY
X-App-Server
Srv
X-Http-Reason
X-Debug-Info
X-Oracle-Dms-Rid
X-XRDS-LOCATION
X-Time
X-Oracle-Dms-Ecid
X-CDN-Forward
Accept-Language
Protected
X-APP-VERSION
X-IPLB-Request-ID
X-IPLB-Instance
X-Via-JSL
X-Cache-Expired-At
X-Hosted-By
Healthy
X-Nginx-Cache-Key
X-Ratelimit-Limit
X-Cache-Hit
Liferay-Portal
X-Device-Type
X-Tumblr-Pixel
Fastcgi-Useragent
X-Tumblr-Pixel-0
X-Tumblr-User
X-Tumblr-Pixel-1
X-Tt-Logid
X-Azure-Ref
X-FW-Hash
X-FW-Serve
X-FW-Static
X-FW-Server
X-FW-Type
X-FW-Dynamic
Section-Io-Cache
X-Cache-Operation
X-Backend-Name
X-Trace-Id
X-Cache-NGX
X-RTag
Backend
MS-CV
Content-Secure-Policy
Ms-Operation-Id
X-UUID
X-Proxy-Cache-Status
Server-Info
X-Mobile-URL
X-UPSTREAM-Address
Meta-Geo
X-Storage
Load-Balancing
X-RN-RSRV
X-Mode
X-Akamai-Edgescape
GEO-INFO
CF-IPCountry
X-PHP-Backend
X-PHP-Host
X-LJ-Flow-ID
X-Edge-Location
X-AWS-Id
X-Cache-Enabled
X-Handled-By
X-Alternate-Cache-Key
X-Adobe-Source
Webcakes-Region
Azure-SlotName
WP-Super-Cache
CDN-Uid
CDN-RequestId
CDN-CachedAt
CDN-Cache
X-Labrador-Cache-Channel
CDN-EdgeStorageId
CDN-PullZone
X-Cache-Host
CDN-RequestCountryCode
X-Cms-Context
Webcakes-App-Version
Locale
X-Content-Age
TWC-Connection-Speed
TWC-Device-Class
TWC-GeoIP-Country
Property-Id
Azure-Version
X-Origin-Date
X-No-Session
X-Locale
TWC-GeoIP-LatLong
TWC-Locale-Group
Web-Mar-Node
Azure-SiteName
Webcakes-App-Name
Azure-RegionName
X-Forwarded-Host
S-Rt
Azure-InstanceId
TWC-Privacy
X-Origin-Hint
X-Storefront-Renderer-Rendered
X-Urbn-Site-Id
X-Urbn-Context-Path
X-Server-W
X-Uri
X-SayCDN-TTL
X-Say-Cacheable
X-Varnish-Hostname
X-Varnish-Cache-Hits
X-ShardId
X-ShopId
X-Sql-Count
X-Sql-Duration-Ms
X-Proto
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Shopify-Stage
X-Site-Version
X-Skip-Cache
X-Varnishpool
X-Say-TTL
X-VWS-Id
X-VC-Cache
X-URL
X-Redis-Cache
X-HTML-Minification-Powered-By
X-Region
X-Extlb
X-GeoCode
X-Access
X-Via-Fastly
X-Varnish-Beresp-Grace
X-BYPASS-REASON
X-Cache-Server
Eomportal-Instance
X-GeoCountry
X-Timing-Wait
X-Detected-As
X-FB-TRIP-ID
X-Xfnlog-Site
X-Web-Node
Selected-Fe
X-Hl-Ver
X-Zipkin-Id
Mn-Server-Ip
X-UA-Device-Type
X-Format
X-Datadome
X-Generated-By
DB-Nickname
X-SaId
X-OCL
X-Cache-Action
Cross-Origin-Resource-Policy
X-Routing-Service
X-ProxyCache-Status
X-Proxied
X-Proxy-Build
X-ProxyCache-Key
X-PCL
Apigw-Requestid
X-Request-Time
X-Section
X-ServerID
X-Cache-Type
X-JoinUs
X-Correlation-ID
X-Zen-Fury
X-Tid
X-SRV
X-Cache-Status-Check
X-Rule
X-Nginx-Cache
Onion-Location
X-Generation-Time
ServedBy
X-Debug-Cache
X-Ms-Request-Id
X-Ms-Version
X-ECache
X-R9-Blue-Green-Version
X-DynaTrace-JS-Agent
X-LSADC-Cache
X-FireWall-Port
Cache-Name
X-WP-CF-Super-Cache-Cache-Control
X-Human
X-Ua
Cache
X-WP-CF-Super-Cache
Xserver
X-Dc
X-Cache-Tags
X-App-Version
X-Amz-Apigw-Id
X-Amzn-RequestId
Source
SD-X-WS
Xet-Cookie
X-Cached-By
X-Aspnetmvc-Version
X-RCS-CacheZone
X-Loop
X-TNCMS
Cross-Origin-Window-Policy
LB
X-Varnish-Hits
X-Cdn
X-GEO
X-MP-GENERATED-AT
X-Webkit-CSP
X-TA-CDN-Provider
X-Api-Version
Origin
WPO-Cache-Status
WPO-Cache-Message
X-Pubstack
X-Reqid
X-Origin-CC
X-Via-NSCOPI
X-Soup
X-Origin-TTL
X-Amzn-Remapped-Content-Length
X-NewRelic-App-Data
X-GG-Cache-Date
X-Service
From-Origin
X-IPS-LoggedIn
X-AOL-HN
X-B3-SpanId
X-Tumblr-Pixel-2
Webserver
X-FW-Version
X-Varnish-Ttl
X-Vgn-Hpd-Reason
Cache-Hits
X-Newrelic-Synthetics
X-Platform-Server
Rip
X-Varnish-Beresp-Ttl
X-Provided-By
X-Cluster-Node
X-Request-Host
Expiry
Environment
X-ARC
Rendered-Blocks
X-Application
X-A-Wwc
X-A-Ccd
X-A
X-Owner
X-PBS-Appsvrname
X-A-Dam
X-A-Dcw
X-Aed
X-A-Dgt
X-NAPM-TraceId
X-AK-Request-ID
Xc-Version
A
X-Destination
X-Developer
X-Ec-Fail
Cdnsip
Cdncip
X-Connection-Hash
BehaviorPad-Version
X-D
X-Ec-GeoHdr
X-Cache-NE
Upgrade-Insecure-Requests
X-BCube-Filmed-By
X-Bc-Bl
Host-ID
DCR-Processing-Time-Ms
DCR-Decision-By
X-External-Request-Id
X-Vdms-Path
X-Forwarded-Path
X-B-Cookie
X-Orig-Expires
X-VG-WebCache
MD5-Digest
Sslversion
X-User
Lang
X-Rewrite-Enabled
X-Served-From
X-S-Cookie
Meta-Geo-Continent
X-S
X-Rojux
X-ScT
X-TIM-N
X-Shop-Environment
Surrogated-Key
T-Server
Ngx.Var.Host
X-SRCache-Key
X-Processor
Odigeo-Trace-Id
X-Tenant
X-Vdms-Version
X-TIME
OT-Force-Account-Verify
X-CSRF-Token
HostName
X-Accel-Buffering
Redirect-Candidate
X-Bip
X-Cluster
Fastly-SSL
X-Dispatcher-Number
X-VC
X-Generated-On
X-Aicache-OS
X-Thanos
X-Qloud-Router
X-Pool
Machine
Mobile-Detection-Method
X-Level-Front-Cache
X-WA-Info
Mime-Version
X-Origin-Response-Time
Thinkindot-CacheControl
X-CGP
X-Cdn-Origin
Thinkindot-Control
Thinkindot-CacheControl-Type
X-CacheTTL
We-Hiring
TDXMobile
X-Clara-WADP
X-Clientip
Web-Mar-Region
Servername
Wxu-Next-Commit
Wxu-Next-Hostname
X-Ckpd-Fst-Backend
X-Core-Mission
X-Cache-Bucket
Tube-Get-Contents
X-Ad-Defer-Variation
V-Age
Server-Host
Tube-Return
Tube-Got-Eval
Tube-Got-Results
X-BBC-Edge-Cache-Status
Vix-Hermes-Req-Id
VNS-Age
State
X-Auto-Login
Traceparent
X-Branch-Name
Wxu-Next-Region
VNS-Cache
Req-Svc-Chain
X-Cache-Info
X-Wix-Viewer-Type
X-Region-Sid
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-Request-URI
X-Rocket-Build-Number
X-S-Maxage
X-Rocket-Nginx-Serving-Static
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
X-Parent-Response-Time
X-Planisys-CDN-TTL
X-Policy
X-Proxy-Cache-Info
X-Viewer-Country
X-SB
X-Scale
X-V-Cache
X-Thinkindot-L3
X-SVT-ORM-VERSION
X-Variation
X-Varnish-CookieHashed-On
X-Varnish-Remaining-TTL
X-Varnish-CookieINHashed-On
X-SVT-ORM-RULES
X-SplitTest
X-Sigma
X-VG-TLSProxy
X-Session-Fingerprint
X-Sigma-Backend
X-SIPLIST1
X-Sn-Servicetimems
X-Slack-Backend
X-Origin-Expires
X-Origin
X-Eu-Site
X-Esi-Check
X-Epic-Correlation-Id
X-Fetched-On
X-Fmm-Version
X-Gamma-Serve
X-Forwarded-Site
X-Ec-Custom-Error
X-DPWN-IS-SECURE
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
X-Csrf-Jwt
X-Datadog-Trace-Id
X-DefElseHash
X-Device-Os
X-DefHash
X-Gateway-Cache-Key
X-Gateway-Cache-Status
X-VServer
X-WADP-Cache
X-Minions-Version
X-Mvc-Supplant-Cachable
X-Mvc-Supplant-OutputCached
X-Optimistic-Header
X-NodeID
X-Loc
X-Irp-Debug
X-GeoIP
X-Gateway-Skip-Cache
X-Gateway-Request-Id
X-GeoIP-City
X-Gzip
X-INCAP-ABP
X-Hash
X-Core-Value
X-Cache-Id
Ha-Gx-Prefs
Gh-Request-Id
X-Xrds-Location
Fastly-SWR
HA-Ipaddr
Is-Eu
CPC-Cache
L
Kp-EeAlive
IsBot
Fastly-SIE
Fastly-GeoIP-CountryCode
Decoy-Debug-TTL
Decoy-Debug-Status
Decoy-Debug-Key
Datacenter
DSUID
CPC-Age
Cluster
Cmsid
Cmstype
Country-Code
Mail-Subject
L5d-Success-Class
Candidate-Md5Url
Apple-News-Services-Parsed-Url
Click-Count-Action-Start
Apple-News-Services-Host
Apple-News-Services-Request-Url
Producers
Cache-Host
Adler-Geo
Platform
Cache-Tv-Group
Origin-EX
Origin-CC
NGX
Release
NM-Fastcgi-Cache
Memcached
Click-Count-Error
Apple-News-Services-Handled
X-Tec-Api-Root
X-Tec-Api-Version
X-Tx-Id
X-Tec-Api-Origin
X-Has-Esi
X-Hnp-Log
CDCHOST
X-Gen-Mode
X-Fastly-Cache
X-Gdpr
X-Cdn-Srv
X-Geo-Header
CloudFront-Viewer-Country
X-Developers
Fastly-Backend-Name
X-Worker
Server-Hostname
X-Cache-Remote
User-Cache-Control
X-Block-Status
Svr
X-Scheme
X-Varnish-Beresp-Status
X-Origin-Time
X-Is-Gdpr
X-HS-Content-Campaign-Id
X-JWT-State
Server-Ext
X-Nyt-Route
X-NCache
Sever-Int
X-ZONE
X-NWS-UUID-VERIFY
X-CMSURLCustom
Canary
X-Presslabs-Stats
Fastcgi-Cache-TTL
X-LB-NoCache
AKAMAI
X-Pod-Name
WebServer
Ec-Rule-Version
X-Udemy-Cache-App-Namespace
Pics-Label
X-Sucuri-ID
X-Sucuri-Cache
Ssr
SID
X-Tb-Optimization-Total-Bytes-Saved
X-Cache-Debug
X-WP-CF-Super-Cache-Active
X-Trace-ID
X-ND-Cache
X-Ig-Push-State
X-Cache-Date
X-Var-Ttl
X-Buckets
X-ATG-Version
Time
Memory
Sid
X-Via-Popv
X-Via-Popn
X-Microcachable
X-Generated-In
X-Via-Poph
X-FC-Vary-Parameters
X-Fastly-Backend
X-Conf
X-Azure-Ref-OriginShield
X-B3-Traceid
AMP-Access-Control-Allow-Source-Origin
X-TRACE-ID
X-Refresh
X-Newrelic-App-Data
Server-ID
X-Servedbyhost
Fastly-Drupal-HTML
X-Akamai-Transformed
Fastly-Drupal-Html
Env
X-MSEdge-Flight
X-MSEdge-Features
X-Release
X-Edge-Pop
X-Dmc
X-Cs
X-Yandex-Sdch-Disable
X-NC
X-RateLimit-Reset
X-Fpc
X-Be
X-CS
X-DC
X-Esi
X-Pass-Why
X-PX
X-Air-Source
X-Up
X-Endurance-Cache-Level
X-ID
X-MCACHE
X-Air-Trace-Id
X-EC-Lua
X-Air-Hostname
Magicmarker
CDN
My-App
X-Wa
X-Dispatch
X-Tumblr-Pixel-3
X-Wikidot-Static-Cache
X-CACHE-AGE
GeoIp-Country-Code
X-Wikidot-Backend
X-Zone
X-TX-ID
True-Client-IP
X-Lambda-Id
X-VCL-Version
X-Hyper-Cache
X-NGINX-Cache
X-Srv
X-Webkit-CSP-Report-Only
X-Nf-Request-Id
X-CF-Lambda-Version
X-CF-Lambda-Fn
X-Vc
X-CACHE-KEY
X-CSRF-TOKEN
X-Alfa-Service
X-App
X-M-Reqid
X-Micro-Cache
X-M-Log
Hostname
Pramga
X-Req
C-Via
X-Qnm-Cache
X-HS-Status
N-Cache
X-TH-Server
X-Varnish-Beresp-TTL
X-Vcl-Version
Resin-Trace
X-Air-Pt
X-LB-ID
True-Client-Ip
X-TrackingId
X-Vercel-Id
X-Vercel-Cache
Path
X-Edge-Origin-Shield-Region
True-Client-Country-4JS
CacheControlHeader
X-Platform
On-Server
GeoIP-Country-Code
Tcn
X-PAYTM-SRV-ID
Fastcgi-X-Cache-Version
X-Edge-Origin-Shield-Bytes
X-B3-Spanid
Tracecode
X-Op-Id-All
Esi-Enabled
X-SERVER-NAME
X-Check-Cacheable
X-Vtex-Remote-Cache
X-Vtex-Processado-Em
GeoIP-Latitude
Proxy-Connection
X-Akamai-Pragma-Client-IP
X-CLOUD-TRACE-CONTEXT
NtCoent-Length
X-AIR-PT
X-GeoIP-Region-Code
X-ApacheServer
X-GeoIP-Country-Code
Hit
X-FPC
Section-Io-Origin-Status
X-LAGOON
Section-Io-Origin-Time-Seconds
Section-Io-Id
X-API-Version
X-Request-Start
X-Node-Id
X-PERF
X-SD-PageType
Section-Origin-Responded
X-Webkit-Csp-Report-Only
X-Date
X-WA
X-Edge-POP
HIT
X-Geo
X-Via-CDN
Cdn
X-Mly-Id
X-Platform-Router
ENV
X-Platform-Cluster
X-Accel-Expires-Debug
Cache-Key
WWW-Authenticate
X-Platform-Processor
X-Datacenter
XkeyRZ
X-Proxy-CacheRZ
YJS-ID
X-RAMCache
Server-Id
DynaTrace
DT-Hot-News
User-Agent
X-ServedByHost
Lb
X-Render-Time
X-Lb-Id
X-Cdn-Forward
Yjs-Id
X-Dw-Trace-Id
X-Via-PopV
X-Via-PopH
X-Via-PopN
X-VarnishDD-TTL
X-Via-Ucdn
X-Proxy-Upstream
PFcat
X-Traceid
XM
X-HN
Server-Ttl
Sm-Log-Id
X-Service-Response-Time
X-LI-UUID
X-LI-Proto
X-Cache-Ttl
X-Old-Content-Length
X-CF-Powered-By
X-Li-Pop
X-Response-By
X-TT-LOGID
X-FORWARDED-FOR
FSS-Cache
Dnion-Transfer-Encoding
X-CUA
X-Proxy-Cache-Hk
X-Instance-Name
X-Li-Fabric
Geoip-Latitude
X-UA
X-LiteSpeed-Cache-Control
X-RPS
XServer
Ohc-File-Size
PICS-Label
X-Fastly-Backend-Reqs
Location
X-RPM
Nginx-CQVIP
X-DB
X-DSS
X-LiteSpeed-Tag
X-DW
X-Akamai-ERRuleID
Powered-By
X-RSL
X-Akamai-ERPolicy
X-DI
MIME-Version
X-Litespeed-Cache-Control
SRV
X-Wp-Cf-Super-Cache-Cache-Control
X-Wp-Cf-Super-Cache
Wpo-Cache-Status
X-Request-Url
Wpo-Cache-Message
X-Lb-Nocache
Locid
X-Webstats-RespID
X-Nc
Vha6-Origin
M-TraceId
X-Fastly-Cache-Hits
X-HostName
X-Ftr-Request-Id
X-B3-ParentSpanId
X-From
X-Cache-Backend
Srvid
X-FL-EDGE
X-Cdn-Request-ID
Warning
X-Ips-Loggedin
X-Cache-Ngx
CountryCode
X-Location
X-Varnish-Authentication
X-DataCenter
X-Contensis-Viewer-Groups
X-Cache-ASPX
X-Mg-Cache
X-HA-Backend
Fastcgi-Cache-Ttl
X-Akamai-Request-ID
Req-ID
X-Moov-Xdn-Version
X-Moov-T
X-MiniProfiler-Ids
X-IN-APIGATEWAYSSL
X-Cc-Via
X-Snapshot-Date
X-Httpd
X-IN-APIGATEWAY
WZWS-RAY