Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Accept-Ranges
Expect-CT
X-XSS-Protection
Pragma
X-Powered-By
CF-RAY
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Xss-Protection
X-Served-By
X-Download-Options
CF-Ray
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
Access-Control-Allow-Credentials
X-FRAME-OPTIONS
X-Request-Id
X-Request-ID
X-Permitted-Cross-Domain-Policies
X-AspNet-Version
Alt-Svc
X-Runtime
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Generator
X-Cache-Status
X-Cacheable
Timing-Allow-Origin
X-Iinfo
X-Envoy-Upstream-Service-Time
X-Content-Security-Policy
X-Drupal-Dynamic-Cache
Feature-Policy
Content-Encoding
Access-Control-Expose-Headers
Upgrade
Status
X-CDN
X-AspNetMvc-Version
P3p
Access-Control-Max-Age
X-Via
Server-Timing
X-UA-Device
Request-Context
X-Robots-Tag
X-Turbo-Charged-By
X-Amz-Request-Id
X-Cache-Group
EagleId
X-Amz-Id-2
X-Backend
X-AH-Environment
X-Proxy-Cache
Keep-Alive
X-Ua-Compatible
X-Server
X-Ws-Request-Id
X-Age
Host-Header
Cf-Edge-Cache
X-Hacker
X-Vhost
X-Server-Powered-By
X-Rq
X-Dns-Prefetch-Control
X-Varnish-Cache
X-Dispatcher
X-Amz-Version-Id
Grace
Allow
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-OneAgent-JS-Injection
X-LiteSpeed-Cache
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-WebKit-CSP
X-Page-Speed
Cf-Apo-Via
X-Device
Accept-CH
Cf-Railgun
X-Aws-Lambda-Call-Status
X-Node
X-Pingback
X-Host
X-Ruxit-JS-Agent
X-Server-Id
EagleEye-TraceId
X-Nginx-Cache-Status
Surrogate-Control
X-Akam-SW-Version
X-Cache-Spec
X-Backend-Server
X-Readtime
Request-Id
X-Cache-Lookup
X-HW
X-Content-Security-Policy-Report-Only
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Cloud-Trace-Context
X-Trace
Accept-Ch-Lifetime
X-Application-Context
X-Response-Time
Fastly-Restarts
Permissions-Policy
X-Nginx-Upstream-Cache-Status
X-Mod-Pagespeed
X-Edge
X-WebKit-CSP-Report-Only
Accept-CH-Lifetime
X-Mcache
Content-Location
X-Content-Type
X-Url
X-MS-InvokeApp
X-CST
X-Country
X-Clacks-Overhead
Rating
X-Midtier
X-Vname
X-TtlSet
X-Amz-Server-Side-Encryption
X-PC
X-Litespeed-Cache
RTSS
Cache-Tag
X-ESI
X-Vcap-Request-Id
X-D2id
X-VARITI-CCR
X-Element-Page-Cache
Verso
Origin-Trial
X-Kinja
X-Exp-Variant
X-GoogleNews-Bot
X-Use-Magma
X-Server-Name
X-Cdn-Fetch
X-Exp-Id
X-Kinja-Server
X-Kinja-Build
X-Kinja-Revision
X-Rack-Cache
X-Ac
X-Ttl
X-Powered-By-Plesk
X-GitHub-Request-Id
X-Cnection
Service-Worker-Allowed
X-ECACHE
X-Amz-Rid
X-Client-IP
SPRequestGuid
X-SharePointHealthScore
X-Navigation-Version
Xkey
X-Abt-Application-Version
Edge-Control
X-NWS-LOG-UUID
SPRequestDuration
SPIisLatency
X-B3-TraceId
X-Cache-TTL
X-Upstream
Arr-Disable-Session-Affinity
X-Instrumentation
X-Erf-Bev-Bev
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Browser-Type
X-Erf-Bev-Bev-Is-Generated
X-Cached
X-Mg-S
X-Dw-Request-Base-Id
X-Px
X-Varnish-TTL
X-Cache-Key
Pagespeed
X-Sol
X-Middleton-Display
Display
X-FastCGI-Cache
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Correlation-Id
X-NF-Request-ID
Access-Control-Request-Method
Edge-Cache-Tag
X-Forwarded-For
Content-MD5
X-Goog-Hash
X-Country-Code
X-Webkit-Csp
Front-End-Https
X-Powered-CMS
TCN
X-Version
X-Id
AR-PoweredBy
AR-SID
AR-Request-ID
AR-CACHE
AR-ATIME
Public-Key-Pins
X-Jurisdiction
X-HP-Webp
Accept-Ch
X-RateLimit-Remaining
X-HP-Trace-Id
X-MSEdge-Ref
X-Content-Digest
X-T
X-Recruiting
X-Ratelimit-Limit
X-Ser
X-XRDS-Location
X-Daa-Tunnel
X-Amzn-Trace-Id
X-Accel-Expires
Response
X-Middleton-Response
TP-Cache
TP-L2-Cache
X-Shield-Request-Id
MicrosoftSharePointTeamServices
Nginx-Cache
S
Cache-Status
MRF-Tech
Mrf-Cache-Status
X-B3-TraceId-Primal
X-Request-Processing-Time
X-Request-Received
Server-Node
X-HS-Cache-Config
X-HS-Content-Id
X-HS-Hub-Id
X-HS-Combine-CSS
Cache-Tags
X-Distributor
X-Hits
X-Fastcgi-Cache
X-Edge-Location-Klb
X-Kinsta-Cache
X-LB-Cache
X-Ratelimit-Remaining
Cross-Origin-Opener-Policy
Fastcgi-Cache
X-Origin-Server
X-PressLabs-Stats
X-Ratelimit-Reset
X-Ua-Browser
Alternate-Protocol
X-Ezoic-Cdn
X-TEC-API-ROOT
X-Grace
Server-Name
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-DIS-Request-ID
Filterid
X-Geo-Country
X-Microsite
X-Request-Handler-Origin-Region
X-Rid
X-Protected-By
Healthy
X-Frontend
X-LLID
X-Hostname
X-Git-Hash
Payment
X-ORACLE-DMS-RID
X-Logged-In
X-ORACLE-DMS-ECID
X-DataDome
Cleartype
X-FB-Debug
X-Varnish-Backend
X-Fastly-Request-ID
X-Debug-Info
X-Page-Id
X-Www-Served-By
X-Load-Cache
X-Forwarded-Proto
X-NGENIX-Cache
X-ASPNET-VERSION
X-Origin-Cache
X-Cluster-Name
X-ECache
DC
MS-Author-Via
Charset
Content-Disposition
Realpath
Access-Control-Allow-Method
X-B3-Sampled
X-GUploader-UploadID
X-Goog-Metageneration
X-Upgrade-Enabled
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Proxy
X-F-Cache
X-Az
X-Activity-Id
X-AppVersion
X-B3-Traceid
X-Seen-By
X-Amz-Replication-Status
Retry-After
Paypal-Debug-Id
X-TTL
X-Server-ID
Cross-Origin-Resource-Policy
X-Type
X-Amz-Meta-S3cmd-Attrs
X-Request-Guid
X-Revision
X-Providence-Cookie
X-Fb-Rlafr
X-Is-Crawler
X-Route-Name
X-Contextid
X-Aspnet-Duration-Ms
Viewport
X-Azure-Ref
X-Flags
Count-Hit
X-Whom
X-App-Environment
X-Aspnetmvc-Version
X-Signature
X-Wix-Request-Id
X-Hosted-By
Surrogate-Key
X-B-Cache
X-VCache
X-B
Accept-Charset
X-Varnish-Server
Amp-Access-Control-Allow-Source-Origin
X-Akamai-Edgescape
X-TT
X-DynaTrace
X-Cache-Age
X-Language
X-Source
X-App-Server
X-Fastly-Request-Id
Referer-Policy
X-Cache-Control
X-Oracle-Dms-Ecid
X-Mobile
X-Oracle-Dms-Rid
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-Goog-Generation
X-Times
X-Varnish-Grace
Host
X-Magnolia-Registration
Version
X-Varnish-Ttl
X-Envoy-Decorator-Operation
X-HTML-Minification-Powered-By
X-N
X-Cache-Rule
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Tumblr-Pixel
X-Tumblr-User
X-Tumblr-Pixel-1
X-Original-Request-Id
X-Tumblr-Pixel-0
X-Response-Served-From
X-Cache-Time
X-RTag
X-Rule
Ms-Operation-Id
WPO-Cache-Message
WPO-Cache-Status
Refresh
X-Varnish-Age
Access-Control-Request-Headers
MS-CV
X-UUID
X-Framework
X-Cache-Status-Check
SD-X-WS
SRV
X-EdgeConnect-Cache-Status
X-FW-Dynamic
X-FW-Hash
X-FW-Serve
X-Content-Powered-By
X-Cacheable-TTL
Akamai-GRN
GEO-INFO
X-Backend-Name
X-FW-Server
X-RemovedCookies
X-Cache-Grace
X-User-Agent
X-ProcessESI
X-FW-Version
X-FW-Static
X-FW-Type
Section-Io-Cache
X-Page-View
X-G
X-Drupal-Cache-Tags
X-Status
X-Jobs
Protected
X-Device-Type
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Is-Bot
X-Instance
X-Cache-Expired-At
X-Rendered-As
X-NYM-Debug-Backend
X-Servername
X-Akamai-Request-ID2
Url
From-Origin
CDN-RequestId
X-Drupal-Cache-Contexts
X-L-Path
X-Http-Reason
X-Environment-Context
X-Adobe-Loc
X-Template
NGB
X-Adobe-Content
X-Trace-Id
X-Amz-Apigw-Id
X-Amzn-RequestId
X-RateLimit-Limit
X-Region
X-COUNTRY
Front
X-CDN-Forward
X-Nginx-Cache
X-Debug-IsConnected
X-Debug-IsPreview
X-XRDS-LOCATION
Accept-Language
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Unique-Id
X-Cache-Hit
X-Content-Options
Fastly-SWR
Fastly-SIE
Backend
Country
X-Zen-Fury
X-Air-Source
X-Air-Hostname
X-Air-Trace-Id
X-DynaTrace-JS-Agent
X-Tb
Liferay-Portal
X-Pinterest-Rid
X-TIME
X-Mode
Pinterest-Version
Pinterest-Generated-By
X-Newrelic-App-Data
Content-Secure-Policy
X-Cache-Operation
X-Real-IP
X-Tt-Logid
X-Node-Name
X-RN-RSRV
X-Generation-Time
Webserver
X-UPSTREAM-Address
X-Proxy-Cache-Info
X-Rewrite-Enabled
Filters
X-Amzn-Remapped-Content-Length
Meta-Geo
Uber-Trace-Id
X-Tumblr-Pixel-2
X-Cache-Server
Azure-SlotName
X-Section
X-IPS-LoggedIn
Azure-RegionName
X-Content-Age
X-Access
Azure-InstanceId
X-Rocket-Nginx-Serving-Static
X-Proxy-Build
X-Format
Azure-SiteName
CF-IPCountry
Azure-Version
X-Timing-Wait
Onion-Location
Selected-Fe
Cache-Hits
X-PHP-Backend
X-Web-Node
X-UA-Device-Type
Node
TWC-GeoIP-Country
X-Cluster-Node
ServedBy
Webcakes-App-Version
Webcakes-App-Name
TWC-Privacy
Webcakes-Region
TWC-Connection-Speed
TWC-GeoIP-LatLong
TWC-Locale-Group
X-R9-Blue-Green-Version
X-Say-Cacheable
X-Debug
X-Ms-Version
X-Ms-Request-Id
X-Sql-Count
X-Proto
Property-Id
TWC-Device-Class
X-Server-W
X-Say-TTL
X-Sql-Duration-Ms
Cache-Name
X-SayCDN-TTL
X-Soup
X-Sucuri-ID
X-Locale
X-Sucuri-Cache
X-Origin-Hint
ServerID
X-VC-Cache
X-Forwarded-Host
X-Proxy-Cache-Status
X-ProxyCache-Status
X-Reqid
X-PHP-Host
X-Varnish-Beresp-Grace
X-Skip-Cache
X-Site-Version
S-Rt
X-Via-Fastly
X-Cache-Host
X-Cache-Action
X-BYPASS-REASON
X-Cache-TTL-Remaining
X-Handled-By
X-Ua
X-ProxyCache-Key
X-Labrador-Cache-Channel
Web-Mar-Node
X-Cms-Context
DB-Nickname
X-JoinUs
X-LAGOON
X-LJ-Flow-ID
X-IPLB-Request-ID
X-SaId
X-FB-TRIP-ID
X-AWS-Id
X-Cluster
X-Detected-As
X-WP-CF-Super-Cache
X-IPLB-Instance
X-WP-CF-Super-Cache-Cache-Control
X-Ruxit-Js-Agent
X-Zipkin-Id
X-Origin-Date
X-Tumblr-Pixel-3
X-Routing-Service
X-Proxied
Cross-Origin-Window-Policy
X-Edge-Location
X-Extlb
X-Adobe-Source
X-VWS-Id
X-Uri
Mn-Server-Ip
X-Urbn-Context-Path
X-Urbn-Site-Id
X-Optimistic-Header
X-No-Session
X-Buckets
Apigw-Requestid
X-Xfnlog-Site
Locale
X-GeoCode
X-GeoCountry
Mime-Version
WP-Super-Cache
Fastcgi-Useragent
Countrycode
X-LSADC-Cache
X-Tec-Api-Version
X-Time
X-Tec-Api-Root
X-Tec-Api-Origin
Source
X-ARC
CDN-Uid
CDN-RequestCountryCode
CDN-CachedAt
CDN-Cache
CDN-EdgeStorageId
X-Oneagent-Js-Injection
CDN-PullZone
X-App-Version
X-Director
X-Hl-Ver
Cache-Tv-Group
Upgrade-Insecure-Requests
X-Varnish-Hits
X-Request-Time
X-Mg-Request-UUID
X-GEO
X-Generated-By
Fastly-Drupal-HTML
X-Cache-Debug
X-Redis-Cache
X-Tx-Id
CF-Cached-On
Xet-Cookie
X-Loop
Frame-Options
X-FireWall-Port
X-Origin-TTL
X-URL
X-SRV
X-Origin-CC
X-Varnish-Cache-Hits
X-TNCMS
X-Pass-Why
X-Varnish-Hostname
X-RM-Cache-TTL
X-TA-CDN-Provider
X-ShardId
X-Storefront-Renderer-Rendered
X-ServerID
X-Akamai-Transformed
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-ShopId
X-Shopify-Stage
X-Alternate-Cache-Key
X-Datadog-Trace-Id
X-Datadog-Parent-Id
X-Datadog-Sampled
X-Datadog-Sampling-Priority
X-Api-Version
X-Service
Load-Balancing
X-Served-From
X-Endurance-Cache-Level
X-Newrelic-Synthetics
X-Request-Host
X-Pubstack
X-Location
X-B3-Spanid
X-NWS-UUID-VERIFY
X-Platform-Processor
X-Platform-Cluster
Ngx.Var.Host
X-Platform-Router
Meta-Geo-Continent
Lang
MD5-Digest
X-Processor
Memcached
Odigeo-Trace-Id
Origin
X-Origin-Time
X-Nyt-Route
X-Vdms-Version
Surrogated-Key
Sslversion
Release
Rendered-Blocks
Req-Svc-Chain
Redirect-Candidate
X-Sigma-Backend
Cache-Host
X-Sigma
Candidate-Md5Url
X-ScT
BehaviorPad-Version
A
Server-Info
Xc-Version
X-We-Are-Hiring
DCR-Decision-By
DCR-Processing-Time-Ms
X-S-Cookie
X-S
X-Rojux
X-Rocket-Build-Number
Host-ID
Gannett-Cam-Experience-Id
DSUID
Edge-Cache
X-S-Maxage
X-Mobile-URL
X-Mid
X-Cache-Info
X-Epic-Correlation-Id
X-Cache-NE
X-CMSURLCustom
X-Cache-Date
X-External-Request-Id
X-BCube-Filmed-By
X-Gdpr
X-TIM-N
X-Conf
X-Ec-GeoHdr
X-CUA
X-D
X-Vdms-Path
X-Developer
X-Ec-Fail
X-SRCache-Key
X-Thinkindot-L3
X-Thanos
X-Test
X-Bc-Bl
X-BBC-Edge-Cache-Status
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
Thinkindot-Control
WWW-Authenticate
X-INCAP-ABP
X-Level-Front-Cache
X-Loc
T-Server
TDXMobile
X-A
X-A-Ccd
X-Application
X-Httpd
X-B-Cookie
X-Generated-On
X-Aed
X-A-Wwc
X-A-Dam
X-A-Dcw
X-A-Dgt
X-Destination
X-Bip
Xserver
Magicmarker
X-Node-Id
X-Org
Mail-Subject
X-JWT-State
NM-Fastcgi-Cache
Section-Origin-Responded
X-Is-Gdpr
X-Mvc-Supplant-Cachable
X-Origin-Response-Time
X-SD-PageType
X-Storage
X-Var-Ttl
Fastly-Backend-Name
Fastly-GeoIP-CountryCode
X-Pool
Gh-Request-Id
X-Restarts
Section-Io-Origin-Time-Seconds
X-Human
X-Clara-WADP
X-Developers
X-Ec-Custom-Error
X-Cdn-Srv
X-Cache-Bucket
X-Akamai-Device-Characteristics
We-Hiring
X-Auto-Login
X-Fetched-On
Server-Host
X-Has-Esi
X-HS-Content-Campaign-Id
Section-Io-Origin-Status
X-GeoIP-City
Section-Io-Id
X-Fmm-Version
X-Geo-Header
X-GeoIP
X-Varnish-Beresp-Status
X-Origin
Apple-News-Services-Request-Url
X-Sn-Servicetimems
Apple-News-Services-Parsed-Url
X-VServer
X-WADP-Cache
C-Via
CacheControlHeader
Cache-Key
Country-Code
X-Worker
Apple-News-Services-Host
Apple-News-Services-Handled
X-Varnishpool
X-Cdn-Origin
X-Hash
X-Core-Mission
X-WP-CF-Super-Cache-Active
X-SVT-ORM-VERSION
AKAMAI
X-Vmg-Version
X-SVT-ORM-RULES
CloudFront-Viewer-Country
X-Parent-Response-Time
X-Varnish-Beresp-Ttl
X-CACHE-AGE
X-Region-Sid
X-Men
X-Dispatcher-Server
X-App
X-Esi-Check
X-FC-Vary-Parameters
X-Fastly-Cache
X-Forwarded-Site
X-Gamma-Serve
X-Accel-Buffering
X-Ad-Defer-Variation
X-Azure-Ref-OriginShield
X-CSRF-Token
X-DefElseHash
X-Slack-Shared-Secret-Outcome
X-Slack-Backend
X-Core-Value
X-DefHash
X-Cache-Tags
X-Block-Status
X-Cache-Id
X-Device-Os
X-Server-IP
X-Gen-Mode
X-Hnp-Log
X-Qloud-Router
X-Req
X-WA-Info
X-Platform
X-Op-Id-All
X-Wix-Viewer-Type
X-Request-Start
X-VG-TLSProxy
X-Variation
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
X-VarnishDD-TTL
X-Scale
X-NodeID
X-Nginx-Cache-Key
X-Gzip
X-HN
X-GeoIP-Region-Code
X-GeoIP-Country-Code
X-Dispatcher-Number
X-Date
X-Varnish-CookieHashed-On
X-CacheTTL
X-Mly-Id
X-NCache
X-LB-NoCache
X-Accel-Expires-Debug
X-Irp-Debug
X-Fastly-Backend
X-Frame-Option
Tube-Got-Eval
Click-Count-Error
Click-Count-Action-Start
Sever-Int
Tube-Got-Results
Wxu-Next-Region
Tube-Return
Tube-Get-Contents
Adler-Geo
Canary
CDCHOST
Cache-Provider
Server-Hostname
Machine
Server-Ext
Platform
PFcat
On-Server
NGX
Wxu-Next-Commit
Wxu-Next-Hostname
Is-Eu
Ssr
Origin-CC
Origin-EX
L
User-Cache-Control
Vix-Hermes-Req-Id
Datacenter
Kp-EeAlive
Web-Mar-Region
X-Eu-Site
X-DPWN-IS-SECURE
X-SB
Environment
L5d-Success-Class
X-Platform-Server
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
X-Owner
Producers
X-V-Cache
X-Old-Content-Length
Ha-Gx-Prefs
HA-Ipaddr
Fastly-SSL
Decoy-Debug-Key
Cmsid
X-CGP
X-Ckpd-Fst-Backend
Cluster
X-Cache-Remote
Cmstype
X-Tid
X-Minions-Version
State
X-Cache-Backend
X-Csrf-Jwt
X-Instance-Name
Decoy-Debug-Status
Decoy-Debug-TTL
X-Origin-Expires
X-Air-Pt
X-Webkit-CSP-Report-Only
X-Response-By
Pics-Label
X-Cache-FS-Status
X-Release
X-Nananana
X-Microcachable
X-Refresh
X-Tb-Optimization-Total-Bytes-Saved
X-Mvc-Supplant-OutputCached
X-Zone
X-Provided-By
X-Correlation-ID
Srvid
Locid
Expect-Staple
X-FL-EDGE
X-FL-QIT-DEBUG
X-Aicache-OS
GeoIP-Latitude
HostName
Env
X-Via-CDN
X-DC
Memory
X-Dc
X-RCS-CacheZone
Time
X-ND-Cache
Edge-Copy-Time
X-Via-SSL
X-Trace-ID
X-Via-Edge
X-Presslabs-Stats
X-Up
X-Servedbyhost
X-Cache-Enabled
Svr
X-Vcl-Version
X-Generated-In
X-From
X-NewRelic-App-Data
NtCoent-Length
Sid
X-Edge-Pop
X-DataCenter
X-Cached-By
SID
X-VC
Cache
X-Webkit-CSP
X-Debug-Cache-Fetch
X-Lambda-Id
X-Srv
X-HS-Status
X-Nc
X-Debug-Cache-Store
X-Vc
X-AIR-PT
X-Via-Poph
X-Esi
X-Vgn-Hpd-Cached
X-Via-Popv
X-Via-Popn
X-Cs
X-Wa
X-Vgn-Hpd-Variations-Key
Fastly-Drupal-Html
X-Vgn-Hpd-Ssi
Cdn
X-ZONE
CPC-Cache
X-CLOUD-TRACE-CONTEXT
CPC-Age
VNS-Cache
X-Vtex-Remote-Cache
X-HA-Backend
X-CCDN-CacheTTL
X-Client-Ip
VNS-Age
GeoIp-Country-Code
X-Hcs-Proxy-Type
X-CCDN-Origin-Time
X-Render-Time
X-VCT
X-Check-Cacheable
X-NGINX-Cache
X-AK-Request-ID
X-LB-ID
Hostname
Server-ID
Cdnsip
Cdncip
AMP-Access-Control-Allow-Source-Origin
True-Client-IP
X-Gateway-Skip-Cache
X-Amz-Meta-Cb-Modifiedtime
X-Gateway-Request-Id
X-Gateway-Cache-Key
X-Via-NSCOPI
X-Gateway-Cache-Status
X-TH-Server
X-Proxy-CacheRZ
X-Via-JSL
XkeyRZ
X-Upstream-Ct
X-Upstream-Ht
X-ATG-Version
X-Cache-Type
X-API-Version
X-Fpc
X-CSRF-TOKEN
X-B3-SpanId
X-Cache-ASPX
Uri
X-Varnish-Beresp-TTL
X-Varnish-Authentication
X-Contensis-Viewer-Groups
XServer
X-Nf-Request-Id
X-CS
X-EC-Lua
Eomportal-Instance
M-TraceId
True-Client-Ip
X-PAYTM-SRV-ID
Esi-Enabled
OT-Force-Account-Verify
X-MSEdge-Flight
X-CF-Lambda-Version
X-FPC
X-CF-Lambda-Fn
X-Micro-Cache
X-RateLimit-Limit-Second
X-MSEdge-Features
X-APP-VERSION
X-RateLimit-Remaining-Second
Resin-Trace
Ngx-Var-Key
X-Udemy-Cache-App-Namespace
Srv
X-Datadome
Path
CDN
X-MP-GENERATED-AT
YJS-ID
Request-ID
X-CDN-Cache-Status
X-Cache-NGX
X-Wikidot-Static-Cache
X-SIPLIST1
X-Wikidot-Backend
X-Fastly-Country-Code
X-Request-URI
N-Cache
IsBot
X-Orig-Expires
RNT-Time
X-Bl-Debug
Server-Id
X-Shop-Environment
X-Lb-Id
X-Cache-Ttl
X-Forwarded-Path
X-VCL-Version
GeoIP-Country-Code
X-Tenant
X-Info
RNT-Machine
X-Service-Response-Time
X-Ha-Backend
X-Accel-Version
Lb
Sm-Log-Id
X-TX-ID
X-MCACHE
X-App-Name
Location
X-Pod-Name
X-B3-Trace-ID
X-WA
X-Policy
X-Edge-POP
LB
Cross-Origin-Opener-Policy-Report-Only
X-Datacenter
X-RateLimit-Reset
X-Akamai-Pragma-Client-IP
HIT
X-Cdn-Cache-Status
Hit
X-Oss-Server-Time
X-Oss-Storage-Class
X-Via-PopH
X-Via-PopN
X-Via-PopV
X-Oss-Request-Id
X-Oss-Object-Type
Servername
X-Cache-Expires
X-SERVER-NAME
X-Oss-Hash-Crc64ecma
Ohc-File-Size
X-Cdn-Request-ID
X-NC
X-Geo
X-Srcache-Store-Status
X-Srcache-Fetch-Status
FSS-Cache
X-CACHE-KEY
X-Snapshot-Date
Timeexpire
Epwk-X-Cache
X-Vcache
Yjs-Id
ENV
X-ServedByHost
X-Logging-Id
Proxy-Connection
X-Cdn-Diag
X-Ctl-Mach
Pramga
Req-ID
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-UP
WZWS-RAY
X-Moov-T
X-Git-Commit
X-Container-Uri
X-Hyper-Cache
X-Moov-Xdn-Version
X-Amz-Meta-Opti
X-Cdn-Forward
Traceparent
X-Dw-Trace-Id
X-TraceId
X-LiteSpeed-Cache-Control
X-Serial
X-Fastly-Backend-Reqs
X-Scheme
Geoip-Latitude
X-M-Log
Warning
X-M-Reqid
X-MiniProfiler-Ids
X-Lb-Nocache
X-Qnm-Cache
X-Viewer-Country
X-VG-WebCache
X-Acquia-Application-Trace
X-Tncms
Content-Script-Type
Ec-Rule-Version
X-RAMCache
X-PERF
X-Swift-Error
Cneonction
X-Acquia-Site
X-ApacheServer
Content-Style-Type
XM
X-B3-Parentspanid
X-Acquia-Purge-Tags
X-Acquia-Application-UUID
X-Wp-Cf-Super-Cache
X-F-Status
X-TT-LOGID
X-Lsadc-Cache
X-Wp-Cf-Super-Cache-Cache-Control
CountryCode
X-Litespeed-Cache-Control
V-Age
X-Acquia-Purge-Cdn-Unconfigured
X-Iauth-Set-Uid
X-Mg-Cache
Ohc-Cache-HIT
CDN-RequestPullCode
True-Client-Country-4JS
CDN-RequestPullSuccess
X-Mid-Debug-Cache-Disk
X-LiteSpeed-Tag
Inserted-Into-Cache-At
X-B3-ParentSpanId
X-Th-Server
X-Cache-Ngx
X-IPS-Cached-Response
Ngx
X-Fastly-Cache-Hits
X-Request-URL
X-Mid-Debug-Cache-Key
MIME-Version
My-App
X-Webstats-RespID