Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Accept-Ranges
X-XSS-Protection
Pragma
Expect-CT
X-Powered-By
CF-RAY
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Xss-Protection
X-Served-By
X-Download-Options
CF-Ray
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Request-Id
Access-Control-Allow-Credentials
X-FRAME-OPTIONS
X-Permitted-Cross-Domain-Policies
X-Request-ID
X-AspNet-Version
Alt-Svc
X-Runtime
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Generator
X-Cache-Status
X-Cacheable
Timing-Allow-Origin
X-Envoy-Upstream-Service-Time
X-Iinfo
X-Content-Security-Policy
X-Drupal-Dynamic-Cache
Feature-Policy
Content-Encoding
Access-Control-Expose-Headers
Upgrade
Status
X-CDN
X-AspNetMvc-Version
Access-Control-Max-Age
X-Via
Expect-Ct
Server-Timing
X-UA-Device
Request-Context
X-Robots-Tag
X-Turbo-Charged-By
X-Amz-Request-Id
X-Cache-Group
EagleId
X-Amz-Id-2
X-Backend
X-AH-Environment
P3p
X-Proxy-Cache
Keep-Alive
X-Dns-Prefetch-Control
X-Ua-Compatible
X-Server
X-Ws-Request-Id
X-Age
Host-Header
Cf-Edge-Cache
X-Hacker
X-Vhost
X-Server-Powered-By
X-Rq
X-Varnish-Cache
X-Dispatcher
X-Amz-Version-Id
Grace
Allow
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-OneAgent-JS-Injection
X-LiteSpeed-Cache
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Page-Speed
X-Device
Cf-Apo-Via
X-WebKit-CSP
Accept-CH
Cf-Railgun
X-Aws-Lambda-Call-Status
X-Node
X-Pingback
X-Host
X-Ruxit-JS-Agent
X-Server-Id
EagleEye-TraceId
X-Nginx-Cache-Status
Surrogate-Control
X-Akam-SW-Version
X-Readtime
Request-Id
X-Backend-Server
X-Cache-Spec
X-Cache-Lookup
X-HW
X-Content-Security-Policy-Report-Only
Accept-Ch-Lifetime
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Cloud-Trace-Context
X-Trace
X-Application-Context
X-Response-Time
Permissions-Policy
Fastly-Restarts
X-Nginx-Upstream-Cache-Status
X-Edge
X-Mod-Pagespeed
X-WebKit-CSP-Report-Only
X-Country
X-Mcache
X-Content-Type
Content-Location
X-MS-InvokeApp
X-Url
Accept-CH-Lifetime
X-CST
X-Clacks-Overhead
X-Vname
X-TtlSet
X-PC
Rating
X-Amz-Server-Side-Encryption
X-Midtier
X-Litespeed-Cache
RTSS
Cache-Tag
X-ESI
X-Vcap-Request-Id
X-D2id
X-Element-Page-Cache
X-VARITI-CCR
Origin-Trial
X-Kinja-Revision
X-Cdn-Fetch
X-Exp-Variant
Verso
X-Kinja-Build
X-GoogleNews-Bot
X-Exp-Id
X-Kinja-Server
X-Use-Magma
X-Kinja
X-Rack-Cache
X-Server-Name
X-Ac
X-Powered-By-Plesk
X-GitHub-Request-Id
Service-Worker-Allowed
X-Cnection
X-ECACHE
X-Amz-Rid
X-SharePointHealthScore
SPRequestGuid
X-Client-IP
X-Navigation-Version
Xkey
X-Ttl
X-Abt-Application-Version
Edge-Control
SPRequestDuration
SPIisLatency
X-NWS-LOG-UUID
X-Cache-TTL
X-B3-TraceId
X-Upstream
Arr-Disable-Session-Affinity
X-Cached
X-Erf-Bev-Bev
X-Browser-Type
X-Erf-Bev-Bev-Is-Generated
X-Instrumentation
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Mg-S
X-FastCGI-Cache
X-Dw-Request-Base-Id
X-Varnish-TTL
X-Px
X-Cache-Key
Pagespeed
X-Middleton-Display
X-Sol
Display
X-SRCache-Fetch-Status
X-SRCache-Store-Status
Access-Control-Request-Method
Edge-Cache-Tag
X-Forwarded-For
X-Goog-Hash
X-Country-Code
X-NF-Request-ID
X-Correlation-Id
X-Webkit-Csp
Content-MD5
TCN
X-Powered-CMS
Front-End-Https
AR-SID
AR-Request-ID
AR-ATIME
X-Id
AR-PoweredBy
AR-CACHE
X-Version
Public-Key-Pins
X-RateLimit-Remaining
X-HP-Webp
X-Jurisdiction
Accept-Ch
X-HP-Trace-Id
X-T
X-MSEdge-Ref
X-Recruiting
X-Ser
X-Content-Digest
X-Ratelimit-Limit
X-Amzn-Trace-Id
Response
X-Middleton-Response
X-Accel-Expires
X-Daa-Tunnel
TP-L2-Cache
TP-Cache
X-Shield-Request-Id
X-XRDS-Location
MicrosoftSharePointTeamServices
Nginx-Cache
S
Cache-Status
Mrf-Cache-Status
MRF-Tech
X-B3-TraceId-Primal
X-HS-Content-Id
X-HS-Combine-CSS
X-Request-Processing-Time
X-HS-Hub-Id
X-HS-Cache-Config
X-Request-Received
Server-Node
Cache-Tags
X-Distributor
X-Hits
X-PressLabs-Stats
Cross-Origin-Opener-Policy
X-Edge-Location-Klb
X-LB-Cache
X-Kinsta-Cache
X-Origin-Server
X-Ratelimit-Remaining
X-Ua-Browser
X-Ezoic-Cdn
Fastcgi-Cache
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
Alternate-Protocol
X-Fastcgi-Cache
X-Grace
Server-Name
X-Ratelimit-Reset
Filterid
X-DIS-Request-ID
X-Frontend
X-Request-Handler-Origin-Region
X-Microsite
X-Rid
X-Protected-By
X-Geo-Country
X-Hostname
X-LLID
Healthy
X-Fastly-Request-ID
X-FB-Debug
X-Git-Hash
X-Logged-In
Cleartype
X-Varnish-Backend
Payment
X-Debug-Info
X-Page-Id
X-Www-Served-By
X-Forwarded-Proto
X-Load-Cache
X-Cluster-Name
X-NGENIX-Cache
X-DataDome
X-ASPNET-VERSION
DC
X-ECache
X-Origin-Cache
MS-Author-Via
Realpath
Content-Disposition
Charset
X-TTL
Access-Control-Allow-Method
X-B3-Sampled
X-GUploader-UploadID
X-Goog-Metageneration
X-Upgrade-Enabled
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-F-Cache
X-Proxy
X-AppVersion
X-Activity-Id
X-Az
X-B3-Traceid
X-Seen-By
X-Amz-Replication-Status
X-Amz-Meta-S3cmd-Attrs
X-Fb-Rlafr
X-Azure-Ref
Retry-After
X-Server-ID
Paypal-Debug-Id
Cross-Origin-Resource-Policy
X-Cache-Age
X-Type
X-Whom
Count-Hit
X-Revision
X-Request-Guid
Viewport
X-Aspnet-Duration-Ms
Surrogate-Key
X-Contextid
X-Flags
X-Is-Crawler
X-Providence-Cookie
X-Route-Name
X-Varnish-Server
X-B-Cache
X-B
X-App-Environment
X-Hosted-By
X-Aspnetmvc-Version
X-Signature
X-Akamai-Edgescape
Accept-Charset
X-Wix-Request-Id
Amp-Access-Control-Allow-Source-Origin
X-TT
X-DynaTrace
X-VCache
X-Language
X-Times
X-App-Server
X-Source
X-Cache-Control
X-Fastly-Request-Id
X-Mobile
X-Goog-Generation
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
Referer-Policy
X-Magnolia-Registration
X-Envoy-Decorator-Operation
X-Varnish-Grace
Host
Version
X-Varnish-Ttl
X-HTML-Minification-Powered-By
X-N
X-Cache-Rule
X-Oracle-Dms-Rid
X-Oracle-Dms-Ecid
WPO-Cache-Message
WPO-Cache-Status
X-Tumblr-Pixel-1
X-Varnish-Age
X-Tumblr-Pixel-0
X-Tumblr-User
X-Response-Served-From
X-Original-Request-Id
Refresh
X-EdgeConnect-Cache-Status
X-Tumblr-Pixel
MS-CV
X-Tt-Trace-Tag
X-Tt-Trace-Host
Access-Control-Request-Headers
X-Cache-Time
Ms-Operation-Id
X-Rule
X-RTag
X-Cache-Status-Check
SD-X-WS
X-Cache-Grace
X-User-Agent
X-UUID
X-Framework
SRV
X-FW-Dynamic
X-FW-Serve
X-FW-Server
X-Content-Powered-By
X-FW-Static
GEO-INFO
X-Backend-Name
Akamai-GRN
X-FW-Type
Protected
X-Cacheable-TTL
X-Jobs
X-Status
X-RemovedCookies
X-FW-Version
X-Page-View
X-ProcessESI
Section-Io-Cache
X-FW-Hash
X-Environment-Context
X-Instance
X-L-Path
VIX-Pulpo-Upstream-Status
X-Drupal-Cache-Tags
X-Is-Bot
X-Cache-Expired-At
X-G
From-Origin
X-Device-Type
VIX-Pulpo-Node
X-Rendered-As
Url
X-Akamai-Request-ID2
X-Servername
X-RateLimit-Limit
X-Http-Reason
X-NYM-Debug-Backend
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Drupal-Cache-Contexts
X-Trace-Id
X-Region
X-Adobe-Loc
X-Adobe-Content
NGB
X-Nginx-Cache
CDN-RequestId
Front
X-Template
X-CDN-Forward
X-Unique-Id
X-Debug-IsPreview
Accept-Language
X-Debug-IsConnected
X-XRDS-LOCATION
X-Content-Options
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Cache-Hit
Backend
Fastly-SIE
Fastly-SWR
Country
X-Zen-Fury
Liferay-Portal
X-Air-Hostname
X-Air-Source
X-Air-Trace-Id
X-Newrelic-App-Data
X-DynaTrace-JS-Agent
X-Mode
Pinterest-Version
Pinterest-Generated-By
X-Pinterest-Rid
X-COUNTRY
X-Tb
X-Cache-Operation
Content-Secure-Policy
X-Real-IP
X-Generation-Time
X-Rocket-Nginx-Serving-Static
Webserver
Onion-Location
Meta-Geo
X-Rewrite-Enabled
S-Rt
X-Amzn-Remapped-Content-Length
X-RN-RSRV
X-Cache-Server
Filters
Uber-Trace-Id
X-UPSTREAM-Address
X-Proxy-Cache-Info
X-Tumblr-Pixel-2
X-Format
X-Proxy-Build
X-Web-Node
X-IPS-LoggedIn
Cache-Hits
X-Tt-Logid
X-Timing-Wait
X-Locale
Selected-Fe
X-Content-Age
X-PHP-Backend
X-Node-Name
X-Time
Azure-SiteName
Azure-InstanceId
Azure-Version
X-Access
X-Section
Azure-SlotName
Azure-RegionName
X-Forwarded-Host
X-Uri
Webcakes-App-Name
TWC-GeoIP-Country
CF-IPCountry
TWC-Device-Class
Property-Id
ServedBy
TWC-Connection-Speed
Cache-Name
TWC-GeoIP-LatLong
X-Debug
Webcakes-Region
X-Cluster-Node
Webcakes-App-Version
TWC-Locale-Group
TWC-Privacy
X-Varnish-Beresp-Grace
X-Site-Version
X-SayCDN-TTL
X-Ms-Request-Id
X-Sql-Count
X-Soup
X-Skip-Cache
X-Say-Cacheable
X-R9-Blue-Green-Version
X-UA-Device-Type
X-Sucuri-ID
X-Sucuri-Cache
X-Sql-Duration-Ms
X-Server-W
X-Say-TTL
X-Ms-Version
X-Proto
X-Origin-Hint
Node
X-Cache-Host
X-BYPASS-REASON
Web-Mar-Node
X-Labrador-Cache-Channel
X-Cache-TTL-Remaining
X-Reqid
X-Ua
X-VC-Cache
ServerID
X-Routing-Service
X-Cache-Action
X-Zipkin-Id
DB-Nickname
Cross-Origin-Window-Policy
X-Cms-Context
X-ProxyCache-Status
X-Proxy-Cache-Status
X-ProxyCache-Key
X-Extlb
X-Edge-Location
X-Proxied
X-Via-Fastly
X-PHP-Host
X-TIME
X-Tumblr-Pixel-3
X-Handled-By
X-LAGOON
X-VWS-Id
X-SaId
X-LJ-Flow-ID
X-WP-CF-Super-Cache
X-IPLB-Request-ID
X-Origin-Date
X-IPLB-Instance
X-Cluster
X-FB-TRIP-ID
X-AWS-Id
X-Adobe-Source
X-WP-CF-Super-Cache-Cache-Control
X-JoinUs
X-Detected-As
X-Ruxit-Js-Agent
Mn-Server-Ip
X-Webkit-CSP
X-No-Session
X-Urbn-Context-Path
Locale
X-App-Version
X-Urbn-Site-Id
X-Optimistic-Header
Countrycode
X-Xfnlog-Site
Apigw-Requestid
X-GeoCode
X-GeoCountry
X-Tec-Api-Origin
X-Tec-Api-Version
Fastcgi-Useragent
X-ARC
WP-Super-Cache
X-LSADC-Cache
X-Tec-Api-Root
X-Buckets
Cache-Tv-Group
Source
X-Oneagent-Js-Injection
X-Director
Mime-Version
Upgrade-Insecure-Requests
X-Varnish-Hits
X-Hl-Ver
CDN-Uid
CDN-RequestCountryCode
CDN-PullZone
CDN-CachedAt
CDN-Cache
CDN-EdgeStorageId
X-Generated-By
X-Mg-Request-UUID
X-GEO
Fastly-Drupal-HTML
X-Request-Time
Frame-Options
X-Cache-Debug
X-Redis-Cache
X-Tx-Id
X-FireWall-Port
X-Loop
X-Webkit-CSP-Report-Only
CF-Cached-On
X-Varnish-Cache-Hits
X-Origin-CC
X-URL
X-Origin-TTL
Xet-Cookie
X-RM-Cache-TTL
X-Varnish-Hostname
X-Pass-Why
X-Alternate-Cache-Key
X-ShardId
X-Sorting-Hat-ShopId
X-Api-Version
X-Storefront-Renderer-Rendered
X-ShopId
X-Sorting-Hat-PodId
X-TA-CDN-Provider
X-Shopify-Stage
X-TNCMS
X-ServerID
X-SRV
Load-Balancing
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
X-Datadog-Trace-Id
X-Datadog-Sampled
X-Akamai-Transformed
X-Newrelic-Synthetics
X-Served-From
X-Pubstack
X-Service
X-Request-Host
X-Location
X-Endurance-Cache-Level
Server-Info
Xserver
X-Correlation-ID
Odigeo-Trace-Id
Origin
X-Nyt-Route
X-Origin-Time
Redirect-Candidate
X-Platform-Cluster
X-Processor
X-Platform-Router
X-Platform-Processor
Release
X-Mobile-URL
T-Server
TDXMobile
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
Surrogated-Key
Sslversion
X-Sigma-Backend
X-Sn-Servicetimems
Rendered-Blocks
Req-Svc-Chain
X-Rocket-Build-Number
Meta-Geo-Continent
Candidate-Md5Url
Country-Code
DCR-Decision-By
DCR-Processing-Time-Ms
Cache-Host
BehaviorPad-Version
X-Sigma
X-ScT
X-S-Maxage
A
DSUID
Edge-Cache
MD5-Digest
Memcached
X-Rojux
Thinkindot-Control
Lang
Host-ID
X-S-Cookie
Gannett-Cam-Experience-Id
X-S
Ngx.Var.Host
X-Loc
X-Conf
X-Thinkindot-L3
X-External-Request-Id
X-Core-Mission
X-TIM-N
X-Gdpr
X-Cache-NE
X-Vdms-Version
X-CMSURLCustom
X-Vdms-Path
X-Epic-Correlation-Id
X-CUA
X-SVT-ORM-RULES
X-Developer
X-SVT-ORM-VERSION
X-Test
X-SRCache-Key
X-Ec-Fail
X-D
X-Ec-GeoHdr
X-Thanos
X-Cache-Info
X-We-Are-Hiring
X-Httpd
X-Hash
X-A-Dam
X-A-Dcw
X-A-Ccd
X-A
X-Destination
X-Level-Front-Cache
X-INCAP-ABP
Xc-Version
X-A-Dgt
X-A-Wwc
X-BCube-Filmed-By
X-Bip
X-Generated-On
X-Cache-Date
X-Bc-Bl
X-BBC-Edge-Cache-Status
X-Aed
X-Application
X-B-Cookie
X-Mid
X-Cdn-Origin
X-Storage
X-Restarts
X-CSRF-Token
Fastly-Backend-Name
Fastly-GeoIP-CountryCode
X-Slack-Backend
X-Dispatcher-Number
X-SD-PageType
X-Server-IP
X-Slack-Shared-Secret-Outcome
X-B3-Spanid
X-Developers
X-Gamma-Serve
X-Varnishpool
Section-Io-Origin-Time-Seconds
Section-Io-Id
X-Var-Ttl
X-Varnish-Beresp-Status
Gh-Request-Id
X-Ec-Custom-Error
X-Fetched-On
X-Mvc-Supplant-Cachable
Mail-Subject
X-JWT-State
X-Is-Gdpr
X-Human
X-Fmm-Version
Magicmarker
X-Fastly-Cache
X-Varnish-Beresp-Ttl
X-Pool
X-Has-Esi
X-Org
Section-Io-Origin-Status
X-Fastly-Backend
X-Node-Id
X-Region-Sid
X-VServer
X-CacheTTL
X-Cache-Bucket
X-GeoIP-City
AKAMAI
Apple-News-Services-Handled
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
We-Hiring
X-Men
X-Geo-Header
X-Accel-Expires-Debug
X-Auto-Login
WWW-Authenticate
X-GeoIP
X-Origin
X-Vmg-Version
Apple-News-Services-Request-Url
X-Worker
X-WP-CF-Super-Cache-Active
NM-Fastcgi-Cache
CloudFront-Viewer-Country
X-WADP-Cache
X-HS-Content-Campaign-Id
X-Date
X-Akamai-Device-Characteristics
Section-Origin-Responded
Cache-Key
X-Cdn-Srv
C-Via
X-Clara-WADP
CacheControlHeader
Server-Host
X-Parent-Response-Time
X-Forwarded-Site
X-Frame-Option
X-DefHash
X-Block-Status
X-Azure-Ref-OriginShield
X-App
X-Cache-Tags
X-Core-Value
X-Device-Os
X-DefElseHash
X-FC-Vary-Parameters
X-NWS-UUID-VERIFY
Vix-Hermes-Req-Id
X-Ad-Defer-Variation
X-Cache-Id
Platform
Is-Eu
X-WA-Info
Adler-Geo
X-Dispatcher-Server
X-Esi-Check
X-Request-Start
X-Scale
X-Variation
X-Platform
X-NodeID
X-Gzip
X-Instance-Name
X-VG-TLSProxy
X-VarnishDD-TTL
X-Irp-Debug
X-LB-NoCache
X-Mly-Id
X-Hnp-Log
X-HN
X-GeoIP-Country-Code
X-GeoIP-Region-Code
X-NCache
X-Nginx-Cache-Key
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
X-Varnish-CookieHashed-On
X-Req
X-Op-Id-All
X-Qloud-Router
X-Gen-Mode
X-Origin-Response-Time
CDCHOST
Tube-Got-Results
Tube-Got-Eval
On-Server
State
User-Cache-Control
Tube-Return
Click-Count-Error
Origin-CC
Canary
Server-Hostname
Sever-Int
Ssr
Server-Ext
PFcat
Tube-Get-Contents
Origin-EX
Cache-Provider
NGX
Click-Count-Action-Start
Wxu-Next-Hostname
Machine
L
Cmsid
Kp-EeAlive
Wxu-Next-Commit
Wxu-Next-Region
Cmstype
Datacenter
Web-Mar-Region
X-Release
X-Planisys-CDN-TTL
X-Platform-Server
Ha-Gx-Prefs
X-Eu-Site
HA-Ipaddr
X-V-Cache
X-Planisys-CDN-Rules
X-DPWN-IS-SECURE
X-Origin-Expires
Fastly-SSL
L5d-Success-Class
X-Old-Content-Length
X-Minions-Version
X-Wix-Viewer-Type
X-SB
Environment
X-Cache-FS-Status
Producers
X-Owner
X-Planisys-CDN-Cache
X-Cache-Remote
X-Csrf-Jwt
X-Accel-Buffering
X-CGP
X-Provided-By
X-Response-By
X-Ckpd-Fst-Backend
X-Air-Pt
X-CACHE-AGE
HostName
Srvid
Pics-Label
Locid
X-Microcachable
X-Mvc-Supplant-OutputCached
X-Nananana
X-Refresh
Decoy-Debug-TTL
Decoy-Debug-Status
X-FL-QIT-DEBUG
X-Aicache-OS
Decoy-Debug-Key
X-FL-EDGE
Cluster
X-Tb-Optimization-Total-Bytes-Saved
Expect-Staple
X-Cache-Backend
X-Via-CDN
X-Tid
X-Dc
GeoIP-Latitude
X-Via-SSL
X-Vcl-Version
X-Via-Edge
Edge-Copy-Time
X-From
X-Cache-Enabled
Env
X-ND-Cache
X-Zone
X-RCS-CacheZone
X-VC
X-Trace-ID
X-DC
X-Up
Time
X-Servedbyhost
X-Generated-In
Memory
SID
NtCoent-Length
X-Srv
X-Edge-Pop
X-Lambda-Id
Svr
Sid
X-Cached-By
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-Cs
Cache
X-ZONE
X-AIR-PT
X-HS-Status
X-Via-Poph
X-Nc
X-Via-Popv
X-DataCenter
X-Via-Popn
X-Nf-Request-Id
X-NewRelic-App-Data
X-Render-Time
X-Vtex-Remote-Cache
VNS-Cache
X-Wa
X-Vgn-Hpd-Cached
X-VCT
X-Vgn-Hpd-Ssi
CPC-Age
X-HA-Backend
VNS-Age
CPC-Cache
Fastly-Drupal-Html
X-Vgn-Hpd-Variations-Key
X-Esi
X-Presslabs-Stats
Cdn
X-Vc
Server-ID
X-CLOUD-TRACE-CONTEXT
X-Client-Ip
X-CCDN-CacheTTL
X-LB-ID
X-Hcs-Proxy-Type
X-CCDN-Origin-Time
GeoIp-Country-Code
X-TH-Server
X-Upstream-Ct
X-Upstream-Ht
X-Check-Cacheable
X-B3-SpanId
X-Cache-Type
Cdncip
X-Gateway-Request-Id
Cdnsip
Hostname
X-Gateway-Cache-Key
AMP-Access-Control-Allow-Source-Origin
X-Fpc
X-Amz-Meta-Cb-Modifiedtime
X-AK-Request-ID
X-ATG-Version
X-Via-JSL
X-Gateway-Cache-Status
X-Gateway-Skip-Cache
X-Proxy-CacheRZ
XkeyRZ
X-Varnish-Authentication
X-Via-NSCOPI
X-Contensis-Viewer-Groups
Uri
X-NGINX-Cache
X-Cache-ASPX
True-Client-IP
X-Varnish-Beresp-TTL
X-API-Version
XServer
M-TraceId
X-CS
X-CSRF-TOKEN
X-EC-Lua
X-RateLimit-Limit-Second
X-CF-Lambda-Version
True-Client-Ip
X-Datadome
X-CF-Lambda-Fn
Esi-Enabled
X-RateLimit-Remaining-Second
Eomportal-Instance
X-PAYTM-SRV-ID
X-Udemy-Cache-App-Namespace
X-MSEdge-Flight
Resin-Trace
OT-Force-Account-Verify
X-FPC
X-MP-GENERATED-AT
X-MSEdge-Features
Srv
X-Wikidot-Static-Cache
X-Micro-Cache
Ngx-Var-Key
CDN
X-Wikidot-Backend
X-CDN-Cache-Status
N-Cache
Request-ID
YJS-ID
X-Bl-Debug
Path
X-APP-VERSION
X-Shop-Environment
X-Forwarded-Path
X-Tenant
RNT-Time
X-Fastly-Country-Code
GeoIP-Country-Code
RNT-Machine
X-Orig-Expires
X-RateLimit-Reset
X-Cache-NGX
Server-Id
X-SIPLIST1
X-Cache-Ttl
IsBot
X-Request-URI
X-Ha-Backend
X-B3-Trace-ID
X-Policy
Lb
X-App-Name
Sm-Log-Id
X-VCL-Version
X-Info
LB
X-Lb-Id
X-Accel-Version
X-Service-Response-Time
X-TX-ID
X-MCACHE
X-Datacenter
X-WA
X-Pod-Name
Location
HIT
Cross-Origin-Opener-Policy-Report-Only
X-Edge-POP
X-SERVER-NAME
X-Via-PopN
X-Via-PopH
Hit
X-Via-PopV
X-Cdn-Cache-Status
Ohc-File-Size
X-Vcache
X-NC
X-Logging-Id
X-Akamai-Pragma-Client-IP
X-Xrds-Location
X-Geo
Timeexpire
Proxy-Connection
X-Oss-Storage-Class
X-Cdn-Diag
X-Srcache-Store-Status
X-Srcache-Fetch-Status
X-CACHE-KEY
ENV
Pramga
X-Snapshot-Date
X-Oss-Server-Time
X-Cdn-Request-ID
X-Oss-Request-Id
X-Oss-Object-Type
Servername
X-Cache-Expires
X-Oss-Hash-Crc64ecma
FSS-Cache
X-Container-Uri
Epwk-X-Cache
X-Ctl-Mach
Req-ID
Yjs-Id
X-Git-Commit
X-ServedByHost
Warning
XM
X-Amz-Meta-Opti
X-Hyper-Cache
X-Tncms
X-VG-WebCache
X-Serial
X-LiteSpeed-Cache-Control
Geoip-Latitude
X-Fastly-Backend-Reqs
X-UP
X-Scheme
X-Cdn-Forward
WZWS-RAY
X-Dw-Trace-Id
X-Rebelmouse-Cache-Control
X-MiniProfiler-Ids
X-M-Log
X-Rebelmouse-Surrogate-Control
X-M-Reqid
MIME-Version
Traceparent
Cneonction
X-Acquia-Purge-Cdn-Unconfigured
V-Age
X-RAMCache
X-Iauth-Set-Uid
X-Qnm-Cache
X-Acquia-Site
X-Acquia-Purge-Tags
X-Acquia-Application-UUID
X-Acquia-Application-Trace
X-Moov-T
X-TraceId
Content-Script-Type
Content-Style-Type
True-Client-Country-4JS
X-Swift-Error
Ec-Rule-Version
X-Moov-Xdn-Version
X-Lb-Nocache
X-B3-Parentspanid
X-Lsadc-Cache
X-Wp-Cf-Super-Cache
X-Wp-Cf-Super-Cache-Cache-Control
X-TT-LOGID
Cdn-Requestid
X-F-Status
CountryCode
X-Mg-Cache
X-Litespeed-Cache-Control
CDN-RequestPullCode
Ohc-Cache-HIT
CDN-RequestPullSuccess
X-Request-URL
X-PERF
X-Clientip
X-Mid-Debug-Cache-Disk
X-ApacheServer
Ngx
X-B3-ParentSpanId
X-Th-Server
X-IPS-Cached-Response
My-App
X-Cache-Ngx
X-Fastly-Cache-Hits
X-Mid-Debug-Cache-Key
X-Viewer-Country
Inserted-Into-Cache-At
X-LiteSpeed-Tag
X-Webstats-RespID