Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
Strict-Transport-Security
X-Frame-Options
X-Content-Type-Options
Last-Modified
Link
CF-Cache-Status
Cf-Request-Id
Accept-Ranges
ETag
CF-RAY
Expect-CT
Pragma
X-Powered-By
X-Cache
Via
X-XSS-Protection
Age
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Amz-Cf-Pop
X-Xss-Protection
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-FRAME-OPTIONS
X-Download-Options
X-Timer
X-Request-Id
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-Adblock-Key
X-AspNet-Version
X-Permitted-Cross-Domain-Policies
X-Runtime
Alt-Svc
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Check
X-DNS-Prefetch-Control
X-Cache-Status
X-Generator
CF-Ray
X-Cacheable
Timing-Allow-Origin
X-Iinfo
X-Envoy-Upstream-Service-Time
Feature-Policy
Status
X-Content-Security-Policy
X-Drupal-Dynamic-Cache
X-Request-ID
Content-Encoding
X-AspNetMvc-Version
X-CDN
Access-Control-Expose-Headers
Upgrade
X-XSS-PROTECTION
P3p
X-Ua-Compatible
Access-Control-Max-Age
X-Dns-Prefetch-Control
X-Via
Server-Timing
X-Cache-Group
X-Robots-Tag
X-UA-Device
Request-Context
Keep-Alive
X-Amz-Request-Id
X-AH-Environment
X-Turbo-Charged-By
X-Backend
X-Amz-Id-2
X-Proxy-Cache
X-Ws-Request-Id
X-Age
Host-Header
X-Server-Powered-By
X-Hacker
X-Server
X-Akamai-Path-Stats
X-Rq
EagleId
X-Vhost
X-Varnish-Cache
Grace
X-Amz-Version-Id
X-Dispatcher
X-LiteSpeed-Cache
Cf-Edge-Cache
Allow
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Nginx-Cache-Status
X-Device
X-Page-Speed
X-WebKit-CSP
X-Aws-Lambda-Call-Status
X-Host
X-Node
X-OneAgent-JS-Injection
X-Server-Id
EagleEye-TraceId
X-Pingback
X-Cache-Spec
Request-Id
Surrogate-Control
Cf-Railgun
X-Akam-SW-Version
X-Backend-Server
Accept-CH
X-Readtime
X-Cache-Lookup
X-Response-Time
X-HW
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Accept-CH-Lifetime
X-Content-Security-Policy-Report-Only
Content-Location
X-Application-Context
Rating
X-Trace
Fastly-Restarts
X-Cloud-Trace-Context
Accept-Ch-Lifetime
X-Country
X-WebKit-CSP-Report-Only
X-Clacks-Overhead
X-Url
X-Edge
X-Amz-Server-Side-Encryption
X-MS-InvokeApp
X-Rack-Cache
X-B3-TraceId
Edge-Control
X-Ruxit-JS-Agent
X-TtlSet
X-PC
X-Vname
Accept-Ch
X-Content-Type
X-ESI
X-Vcap-Request-Id
X-Nginx-Upstream-Cache-Status
X-Mod-Pagespeed
X-Varnish-TTL
Xkey
X-FastCGI-Cache
X-D2id
X-Kinja-Build
X-Kinja-Revision
X-Use-Magma
X-Kinja
X-GoogleNews-Bot
X-Cdn-Fetch
X-Exp-Id
X-Exp-Variant
X-Amz-Rid
X-Kinja-Server
X-VARITI-CCR
X-Mcache
X-CST
Cache-Tag
Verso
X-GitHub-Request-Id
RTSS
X-Powered-By-Plesk
X-ECACHE
X-Oneagent-Js-Injection
X-Cached
Service-Worker-Allowed
X-Upstream
X-Version
X-Navigation-Version
X-Client-IP
X-Abt-Application-Version
X-Dw-Request-Base-Id
X-Px
X-Ruxit-Js-Agent
X-Cnection
X-Ac
Public-Key-Pins
X-Ser
Arr-Disable-Session-Affinity
X-Kraken-Loop-Name
X-Instrumentation
X-Server-Lifecycle-Phase
SPRequestGuid
X-SharePointHealthScore
X-Element-Page-Cache
Display
Pagespeed
X-Sol
X-Middleton-Display
X-Server-Name
SPIisLatency
SPRequestDuration
X-Country-Code
X-Cache-TTL
X-NWS-LOG-UUID
X-Midtier
Permissions-Policy
X-NF-Request-ID
X-Cache-Key
Response
X-Middleton-Response
X-Ttl
X-Kinsta-Cache
X-Edge-Location-Klb
X-RateLimit-Remaining
X-Goog-Hash
X-Forwarded-For
Access-Control-Request-Method
Content-MD5
X-SRCache-Store-Status
X-Shield-Request-Id
X-SRCache-Fetch-Status
Front-End-Https
X-DataDome
X-MSEdge-Ref
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-Powered-CMS
Edge-Cache-Tag
X-Recruiting
TP-L2-Cache
TP-Cache
X-T
Nginx-Cache
AR-ATIME
AR-CACHE
AR-PoweredBy
AR-SID
X-Jurisdiction
AR-Request-ID
X-HP-Trace-Id
X-HP-Webp
X-Accel-Expires
X-Daa-Tunnel
TCN
X-Correlation-Id
MicrosoftSharePointTeamServices
X-Grace
X-B3-TraceId-Primal
X-RateLimit-Limit
MRF-Tech
Mrf-Cache-Status
X-Id
X-Mg-S
X-TTL
X-Hits
X-Content-Digest
Filters
X-Request-Received
X-Request-Processing-Time
X-HS-Combine-CSS
Server-Node
X-HS-Hub-Id
X-HS-Cache-Config
X-HS-Content-Id
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-TEC-API-VERSION
S
X-LLID
X-Frontend
Server-Name
X-Distributor
X-Amzn-Trace-Id
Cache-Status
X-Protected-By
X-Geo-Country
MS-Author-Via
Fastcgi-Cache
X-Fastly-Request-Id
X-PressLabs-Stats
X-LB-Cache
X-Language
X-Microsite
X-Request-Handler-Origin-Region
Cross-Origin-Opener-Policy
X-Origin-Server
X-Forwarded-Proto
X-Ezoic-Cdn
X-F-Cache
X-Page-Id
Host
X-FB-Debug
X-Seen-By
Filterid
Charset
X-Ua-Browser
X-Ab
X-B3-Sampled
X-Git-Hash
X-Amz-Meta-S3cmd-Attrs
X-Litespeed-Cache
Count-Hit
X-Ratelimit-Reset
X-ASPNET-VERSION
Payment
Realpath
X-Cache-Age
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Browser-Type
X-VCache
X-XRDS-Location
X-Cluster-Name
Cf-Apo-Via
Accept-Charset
X-Origin-Cache
Surrogate-Key
Cache-Tags
Alternate-Protocol
X-NGENIX-Cache
X-Rid
X-DynaTrace
X-Webkit-Csp
Retry-After
X-Az
X-Template
Cleartype
X-AppVersion
X-Activity-Id
X-Fastcgi-Cache
X-Www-Served-By
Access-Control-Allow-Method
X-Node-Name
X-Varnish-Backend
X-Upgrade-Enabled
X-Aspnet-Duration-Ms
X-Tb
X-Signature
X-TT
X-Type
X-Wix-Request-Id
X-Varnish-Grace
X-Route-Name
X-Request-Guid
X-B-Cache
X-App-Environment
X-Flags
X-Is-Crawler
X-Providence-Cookie
X-Amz-Replication-Status
X-DIS-Request-ID
ServerID
X-Content
X-B
X-Debug
DC
X-Drupal-Cache-Tags
Paypal-Debug-Id
X-Proxy
X-Logged-In
Frame-Options
X-Hostname
X-Envoy-Decorator-Operation
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Source
X-Content-Options
X-Mobile
X-Ratelimit-Remaining
X-Revision
X-Load-Cache
Pinterest-Generated-By
X-Pinterest-Rid
Pinterest-Version
X-Goog-Metageneration
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-N
X-Cache-Control
X-Fastly-Request-ID
Amp-Access-Control-Allow-Source-Origin
X-Contextid
Country
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Magnolia-Registration
X-User-Agent
Referer-Policy
X-Whom
X-Cache-Rule
Viewport
X-EdgeConnect-Cache-Status
X-Response-Served-From
NGB
X-Original-Request-Id
Node
Refresh
X-Restarts
Content-Disposition
X-Varnish-Age
Access-Control-Request-Headers
X-Debug-IsPreview
X-Debug-IsConnected
X-Cacheable-TTL
X-Cache-TTL-Remaining
X-Framework
X-L-Path
X-Environment-Context
X-Page-View
X-NYM-Debug-Backend
X-Mid
X-Mg-Request-UUID
X-Real-IP
X-Rendered-As
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Varnish-Server
X-Unique-Id
X-Servername
Uber-Trace-Id
X-Cache-Time
X-Cache-Grace
X-Is-Bot
X-Instance
X-G
X-Akamai-Request-ID2
X-Adobe-Loc
Url
VIX-Pulpo-Node
X-Jobs
VIX-Pulpo-Upstream-Status
Akamai-GRN
X-Adobe-Content
X-Drupal-Cache-Contexts
X-Status
X-Server-ID
X-Content-Powered-By
Countrycode
X-Webkit-CSP
Version
X-App-Server
X-ProcessESI
X-RemovedCookies
X-COUNTRY
X-Ratelimit-Limit
X-Debug-Info
X-Http-Reason
X-XRDS-LOCATION
X-CDN-Forward
Srv
Protected
X-IPLB-Request-ID
X-Time
X-URL
X-APP-VERSION
X-IPLB-Instance
Accept-Language
X-Hosted-By
X-Nginx-Cache-Key
X-Cache-Expired-At
Healthy
X-Tt-Logid
Liferay-Portal
X-Via-JSL
Fastcgi-Useragent
X-Device-Type
X-Cache-Hit
X-FW-Serve
X-FW-Server
X-FW-Dynamic
X-FW-Hash
X-Tumblr-Pixel-0
X-Tumblr-User
X-FW-Static
X-Datadome
X-Tumblr-Pixel-1
X-FW-Type
X-Tumblr-Pixel
X-Correlation-ID
X-Azure-Ref
Section-Io-Cache
X-RTag
X-Oracle-Dms-Ecid
X-Trace-Id
X-UUID
X-Oracle-Dms-Rid
X-Backend-Name
MS-CV
Ms-Operation-Id
Backend
X-Cache-NGX
X-Cache-Operation
X-Proxy-Cache-Status
Content-Secure-Policy
Server-Info
X-Mobile-URL
X-RN-RSRV
Load-Balancing
Meta-Geo
X-UPSTREAM-Address
X-Storage
CF-IPCountry
X-Mode
X-Handled-By
X-HTML-Minification-Powered-By
WP-Super-Cache
Webcakes-Region
Webcakes-App-Name
Web-Mar-Node
Webcakes-App-Version
TWC-GeoIP-Country
CDN-RequestCountryCode
CDN-RequestId
CDN-Uid
CDN-PullZone
CDN-EdgeStorageId
CDN-Cache
CDN-CachedAt
Eomportal-Instance
Locale
X-ShopId
TWC-GeoIP-LatLong
TWC-Locale-Group
TWC-Connection-Speed
S-Rt
Onion-Location
Property-Id
TWC-Privacy
X-Locale
X-Urbn-Site-Id
X-Format
X-Urbn-Context-Path
X-Storefront-Renderer-Rendered
X-ShardId
X-Edge-Location
X-SayCDN-TTL
X-Section
X-Uri
X-Cms-Context
X-Forwarded-Host
X-Sql-Duration-Ms
X-Sorting-Hat-ShopId
X-Server-W
Azure-Version
X-Sql-Count
X-LJ-Flow-ID
X-Sorting-Hat-PodId
X-Shopify-Stage
X-Labrador-Cache-Channel
X-Site-Version
X-Skip-Cache
X-Cache-Server
X-Origin-Hint
X-Redis-Cache
X-Adobe-Source
X-Region
X-No-Session
X-OCL
X-Proto
X-Access
X-PCL
X-PHP-Backend
X-PHP-Host
X-VWS-Id
X-VC-Cache
X-AWS-Id
X-Cache-Enabled
X-Cache-Host
X-Varnish-Cache-Hits
X-Alternate-Cache-Key
X-Varnish-Hostname
X-Akamai-Edgescape
X-Say-Cacheable
X-Say-TTL
X-Varnishpool
X-Origin-Date
TWC-Device-Class
Azure-RegionName
GEO-INFO
X-Content-Age
Azure-SiteName
Azure-InstanceId
Azure-SlotName
X-Zen-Fury
Selected-Fe
X-Cache-Type
X-SaId
X-Debug-Cache
X-ServerID
X-Routing-Service
X-Proxy-Build
X-ProxyCache-Status
X-Timing-Wait
X-Proxied
Mn-Server-Ip
X-ProxyCache-Key
X-UA-Device-Type
X-BYPASS-REASON
X-Extlb
X-Web-Node
X-Hl-Ver
X-GeoCountry
X-Xfnlog-Site
Apigw-Requestid
X-JoinUs
X-Zipkin-Id
DB-Nickname
X-GeoCode
X-FB-TRIP-ID
X-Request-Time
X-Detected-As
X-Generated-By
X-Via-Fastly
X-Generation-Time
X-Tid
X-Cache-Status-Check
X-Varnish-Beresp-Grace
X-Nginx-Cache
X-Rule
X-Cache-Action
ServedBy
X-LSADC-Cache
X-Ua
X-ECache
X-R9-Blue-Green-Version
X-DynaTrace-JS-Agent
X-Dc
Cross-Origin-Resource-Policy
X-Ms-Version
X-Ms-Request-Id
X-SRV
Cache-Name
Cache
X-Human
X-FireWall-Port
SD-X-WS
X-Cache-Tags
X-App-Version
Xet-Cookie
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
X-Amz-Apigw-Id
X-Amzn-RequestId
Xserver
Source
Cross-Origin-Window-Policy
X-Cached-By
LB
X-RCS-CacheZone
X-Aspnetmvc-Version
WPO-Cache-Message
X-GEO
WPO-Cache-Status
X-Via-NSCOPI
X-Cdn
X-Varnish-Hits
X-TNCMS
X-Loop
X-MP-GENERATED-AT
Origin
X-GG-Cache-Date
X-Reqid
X-IPS-LoggedIn
X-Pubstack
X-B3-SpanId
X-Origin-TTL
X-Origin-CC
X-Soup
X-Amzn-Remapped-Content-Length
X-AOL-HN
X-TA-CDN-Provider
X-NewRelic-App-Data
Cache-Hits
X-Xrds-Location
X-Api-Version
X-Tumblr-Pixel-2
X-FW-Version
X-Service
From-Origin
Webserver
X-Platform-Server
X-Cluster-Node
Rip
X-Newrelic-Synthetics
X-Vgn-Hpd-Reason
Upgrade-Insecure-Requests
X-Request-Host
X-A-Dcw
Lang
X-Aed
Meta-Geo-Continent
X-A-Wwc
MD5-Digest
X-A-Dgt
X-A-Dam
Redirect-Candidate
X-A
Rendered-Blocks
Sslversion
T-Server
X-Owner
X-Orig-Expires
X-AK-Request-ID
X-NAPM-TraceId
Odigeo-Trace-Id
X-A-Ccd
Ngx.Var.Host
X-B-Cookie
Cdnsip
X-Developer
X-Destination
X-D
Cdncip
BehaviorPad-Version
X-Forwarded-Path
X-External-Request-Id
X-Ec-GeoHdr
X-Ec-Fail
DCR-Decision-By
DCR-Processing-Time-Ms
X-Provided-By
A
Host-ID
X-ARC
X-Bc-Bl
X-BCube-Filmed-By
X-Connection-Hash
Environment
Expiry
X-Cache-NE
X-Application
X-PBS-Appsvrname
X-S
X-S-Cookie
X-Rojux
X-Vdms-Version
X-Rewrite-Enabled
X-VG-WebCache
X-User
X-TIM-N
Surrogated-Key
X-SRCache-Key
X-Shop-Environment
X-Served-From
X-ScT
X-Tenant
X-Processor
X-Vdms-Path
Xc-Version
X-Cluster
HostName
OT-Force-Account-Verify
X-TIME
X-Varnish-Beresp-Ttl
Fastly-SSL
X-CSRF-Token
X-Origin-Response-Time
Candidate-Md5Url
X-Dispatcher-Number
X-Generated-On
Mobile-Detection-Method
X-Session-Fingerprint
Machine
X-Bip
X-Accel-Buffering
X-Thanos
X-Level-Front-Cache
X-Aicache-OS
X-Pool
X-VC
X-Qloud-Router
X-Cache-Bucket
X-Worker
Thinkindot-CacheControl
X-Branch-Name
X-Cache-Id
X-CacheTTL
X-Ckpd-Fst-Backend
X-CGP
X-Clara-WADP
X-Clientip
X-Core-Mission
X-Cdn-Srv
X-SVT-ORM-RULES
X-Cache-Info
X-SVT-ORM-VERSION
Thinkindot-CacheControl-Type
X-Cdn-Origin
TDXMobile
X-Variation
Wxu-Next-Hostname
Wxu-Next-Commit
Wxu-Next-Region
X-VServer
X-Viewer-Country
Tube-Return
X-WA-Info
We-Hiring
V-Age
X-WADP-Cache
Vix-Hermes-Req-Id
VNS-Age
VNS-Cache
X-Wix-Viewer-Type
X-VG-TLSProxy
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-V-Cache
X-Auto-Login
X-Thinkindot-L3
Thinkindot-Control
X-Ad-Defer-Variation
X-Varnish-Remaining-TTL
Tube-Got-Eval
Tube-Got-Results
Tube-Get-Contents
Traceparent
X-SplitTest
X-BBC-Edge-Cache-Status
X-Sigma
X-Rebelmouse-Surrogate-Control
X-Irp-Debug
X-Region-Sid
X-Is-Gdpr
X-JWT-State
X-Minions-Version
X-Loc
X-INCAP-ABP
X-Request-URI
X-Rocket-Nginx-Serving-Static
X-Gzip
X-Rocket-Build-Number
X-Has-Esi
X-HS-Content-Campaign-Id
X-Hash
X-Rebelmouse-Cache-Control
X-RateLimit-Remaining-Second
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Optimistic-Header
X-Origin
X-Origin-Expires
X-Parent-Response-Time
X-Origin-Time
X-Nyt-Route
X-NodeID
X-Proxy-Cache-Info
X-RateLimit-Limit-Second
X-Mvc-Supplant-Cachable
X-Policy
X-Planisys-CDN-TTL
X-Mvc-Supplant-OutputCached
X-GeoIP-City
X-S-Maxage
X-Developers
X-Sigma-Backend
X-SIPLIST1
X-Device-Os
X-DPWN-IS-SECURE
X-Epic-Correlation-Id
X-Ec-Custom-Error
X-Slack-Backend
X-DefHash
X-Sn-Servicetimems
X-Csrf-Jwt
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
X-DefElseHash
X-Datadog-Trace-Id
X-Esi-Check
X-Eu-Site
X-Gdpr
X-Gateway-Skip-Cache
X-Scale
X-SB
X-GeoIP
X-Geo-Header
X-Gateway-Request-Id
X-Gateway-Cache-Status
X-Fetched-On
X-Fastly-Cache
X-Fmm-Version
X-Forwarded-Site
X-Gateway-Cache-Key
X-Gamma-Serve
X-Core-Value
Web-Mar-Region
Fastly-Backend-Name
Fastly-GeoIP-CountryCode
Fastly-SIE
DSUID
Decoy-Debug-TTL
Decoy-Debug-Key
Decoy-Debug-Status
Fastly-SWR
Gh-Request-Id
Kp-EeAlive
L
IsBot
Is-Eu
Ha-Gx-Prefs
HA-Ipaddr
Datacenter
CPC-Cache
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
Apple-News-Services-Host
Apple-News-Services-Handled
X-NWS-UUID-VERIFY
Adler-Geo
Cache-Host
Cache-Tv-Group
Cmstype
Country-Code
Cmsid
Cluster
Click-Count-Action-Start
Click-Count-Error
L5d-Success-Class
CPC-Age
NM-Fastcgi-Cache
NGX
Origin-CC
Servername
Release
Origin-EX
State
Producers
Server-Host
Platform
Req-Svc-Chain
Memcached
Mail-Subject
X-Tec-Api-Origin
X-Cache-Remote
X-Tec-Api-Version
X-Tec-Api-Root
Mime-Version
X-Pod-Name
Server-Ext
CloudFront-Viewer-Country
User-Cache-Control
AKAMAI
X-Scheme
X-Gen-Mode
Svr
X-Hnp-Log
Server-Hostname
Sever-Int
CDCHOST
X-NCache
Fastcgi-Cache-TTL
X-Block-Status
X-LB-NoCache
X-Varnish-Ttl
X-Varnish-Beresp-Status
X-Tx-Id
Ec-Rule-Version
WebServer
X-Udemy-Cache-App-Namespace
X-Cache-Date
Pics-Label
SID
X-ZONE
X-CMSURLCustom
X-TRACE-ID
Ssr
X-Ig-Push-State
Canary
X-Microcachable
X-Tb-Optimization-Total-Bytes-Saved
X-Conf
X-Yandex-Sdch-Disable
X-Sucuri-Cache
X-Sucuri-ID
Sid
X-ATG-Version
X-Generated-In
X-WP-CF-Super-Cache-Active
X-Cache-Debug
Memory
X-ND-Cache
X-Via-Popn
Fastly-Drupal-Html
X-Via-Popv
X-Via-Poph
X-Var-Ttl
Time
X-B3-Traceid
X-Presslabs-Stats
AMP-Access-Control-Allow-Source-Origin
X-Refresh
X-Edge-Pop
X-Servedbyhost
X-Azure-Ref-OriginShield
X-FC-Vary-Parameters
X-Fastly-Backend
Server-ID
X-Dmc
X-Newrelic-App-Data
X-Be
X-Akamai-Transformed
X-MSEdge-Flight
X-MSEdge-Features
X-Cs
X-Trace-ID
Fastly-Drupal-HTML
X-CS
X-Fpc
X-NC
X-Air-Trace-Id
X-Air-Source
X-Air-Hostname
X-Release
Env
X-Buckets
X-Esi
X-PX
X-Wikidot-Backend
X-MCACHE
X-Wikidot-Static-Cache
X-Zone
X-EC-Lua
Magicmarker
X-ID
X-Endurance-Cache-Level
X-TX-ID
CDN
X-DC
X-Srv
GeoIp-Country-Code
X-RateLimit-Reset
X-Pass-Why
X-Tumblr-Pixel-3
X-CACHE-AGE
X-Up
X-Hyper-Cache
X-Wa
X-CF-Lambda-Fn
True-Client-IP
My-App
X-CF-Lambda-Version
X-Dispatch
X-Webkit-CSP-Report-Only
X-NGINX-Cache
X-App
X-VCL-Version
Pramga
X-Nf-Request-Id
X-M-Log
X-Micro-Cache
X-M-Reqid
X-Lambda-Id
X-Vc
X-CACHE-KEY
X-Alfa-Service
X-CSRF-TOKEN
X-Qnm-Cache
C-Via
Hostname
X-TrackingId
X-Varnish-Beresp-TTL
X-Req
N-Cache
X-Vcl-Version
X-Edge-Origin-Shield-Region
Resin-Trace
X-Edge-Origin-Shield-Bytes
X-Air-Pt
X-PAYTM-SRV-ID
Fastcgi-X-Cache-Version
Path
X-Platform
True-Client-Ip
On-Server
X-Vercel-Cache
Esi-Enabled
GeoIP-Country-Code
X-Check-Cacheable
X-HS-Status
X-Vercel-Id
Tcn
X-LB-ID
X-TH-Server
CacheControlHeader
Tracecode
X-Vtex-Remote-Cache
GeoIP-Latitude
X-Akamai-Pragma-Client-IP
X-AIR-PT
True-Client-Country-4JS
X-Vtex-Processado-Em
NtCoent-Length
X-ApacheServer
X-PERF
X-SERVER-NAME
X-Request-Start
X-API-Version
X-LAGOON
X-Op-Id-All
Proxy-Connection
X-Node-Id
X-SD-PageType
X-CLOUD-TRACE-CONTEXT
Cdn
X-B3-Spanid
HIT
Hit
Section-Io-Id
Cache-Key
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
ENV
X-FPC
X-Webkit-Csp-Report-Only
DT-Hot-News
X-GeoIP-Region-Code
X-Render-Time
X-GeoIP-Country-Code
X-Platform-Router
X-Via-CDN
X-Datacenter
X-Proxy-CacheRZ
X-Platform-Cluster
X-Platform-Processor
XkeyRZ
X-Mly-Id
X-WA
X-Geo
DynaTrace
X-Dw-Trace-Id
X-Accel-Expires-Debug
PFcat
WWW-Authenticate
X-Proxy-Upstream
X-Date
YJS-ID
X-Traceid
Lb
XM
X-VarnishDD-TTL
X-Edge-POP
X-HN
User-Agent
X-Lb-Id
Server-Id
X-Via-Ucdn
X-ServedByHost
X-Cdn-Forward
X-Via-PopN
X-RAMCache
X-Via-PopV
X-Via-PopH
Server-Ttl
X-LiteSpeed-Cache-Control
X-Proxy-Cache-Hk
SRV
X-LI-UUID
X-LI-Proto
X-Li-Pop
Dnion-Transfer-Encoding
X-Cache-Ttl
Geoip-Latitude
MIME-Version
X-CUA
X-CF-Powered-By
X-LiteSpeed-Tag
X-FORWARDED-FOR
X-Li-Fabric
X-TT-LOGID
Yjs-Id
X-Service-Response-Time
Sm-Log-Id
Location
PICS-Label
XServer
X-Ftr-Request-Id
X-Cache-Backend
FSS-Cache
Ohc-File-Size
X-Nc
X-RSL
X-RPS
X-RPM
M-TraceId
X-Old-Content-Length
Vha6-Origin
X-Response-By
X-Instance-Name
X-DW
X-DSS
X-DI
X-DB
X-Fastly-Backend-Reqs
Nginx-CQVIP
X-Akamai-ERPolicy
X-Akamai-ERRuleID
X-Litespeed-Cache-Control
X-UA
X-Wp-Cf-Super-Cache-Cache-Control
X-Wp-Cf-Super-Cache
X-Cc-Via
X-HostName
X-Request-Url
X-Cdn-Request-ID
X-IN-APIGATEWAY
X-Fastly-Cache-Hits
Powered-By
X-Akamai-Request-ID
X-B3-ParentSpanId
X-Httpd
X-IN-APIGATEWAYSSL
X-HA-Backend
Wpo-Cache-Status
Wpo-Cache-Message
X-Lb-Nocache
X-Cache-Ngx
CountryCode
Warning
Uri
X-Location
X-Webstats-RespID
X-Mg-Cache
X-From
X-FL-EDGE
Srvid
Locid
X-MiniProfiler-Ids
Fastcgi-Cache-Ttl
X-Serial
X-Server-IP
Req-ID
X-Moov-Xdn-Version
Ohc-Cache-HIT
X-Snapshot-Date
X-Moov-T
WZWS-RAY