Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Accept-Ranges
X-XSS-Protection
Expect-CT
Pragma
X-Powered-By
CF-RAY
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-Xss-Protection
X-Download-Options
CF-Ray
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
Access-Control-Allow-Credentials
X-FRAME-OPTIONS
X-Request-ID
X-Request-Id
X-Permitted-Cross-Domain-Policies
X-AspNet-Version
Alt-Svc
X-Runtime
Content-Security-Policy-Report-Only
X-DNS-Prefetch-Control
X-Drupal-Cache
X-Check
X-Cache-Status
X-Generator
X-Cacheable
Timing-Allow-Origin
X-Iinfo
X-Envoy-Upstream-Service-Time
X-Content-Security-Policy
X-Drupal-Dynamic-Cache
Feature-Policy
Content-Encoding
Access-Control-Expose-Headers
Upgrade
Status
X-CDN
X-AspNetMvc-Version
P3p
Access-Control-Max-Age
X-Via
Server-Timing
X-UA-Device
X-Robots-Tag
Request-Context
X-Turbo-Charged-By
X-Cache-Group
X-Amz-Request-Id
EagleId
X-Amz-Id-2
X-Backend
X-AH-Environment
Keep-Alive
X-Proxy-Cache
X-Ua-Compatible
X-Server
X-Ws-Request-Id
X-Age
Host-Header
X-Hacker
Cf-Edge-Cache
X-Vhost
X-Server-Powered-By
X-Rq
X-Varnish-Cache
X-Dispatcher
X-Amz-Version-Id
Allow
Grace
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-Dns-Prefetch-Control
X-OneAgent-JS-Injection
X-LiteSpeed-Cache
X-WebKit-CSP
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Page-Speed
Accept-CH
Cf-Apo-Via
X-Device
Cf-Railgun
X-Aws-Lambda-Call-Status
X-Node
X-Host
X-Pingback
X-Server-Id
X-Cache-Spec
X-Nginx-Cache-Status
EagleEye-TraceId
X-Akam-SW-Version
Surrogate-Control
X-Ruxit-JS-Agent
X-Backend-Server
Request-Id
X-Readtime
X-Cache-Lookup
X-HW
X-Cloud-Trace-Context
X-Content-Security-Policy-Report-Only
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
Accept-Ch-Lifetime
X-Trace
X-Application-Context
X-Response-Time
Fastly-Restarts
Permissions-Policy
X-Nginx-Upstream-Cache-Status
X-Mod-Pagespeed
X-Edge
X-WebKit-CSP-Report-Only
Accept-CH-Lifetime
X-CST
X-Litespeed-Cache
Content-Location
X-Content-Type
X-Url
X-MS-InvokeApp
X-Mcache
X-Clacks-Overhead
X-Country
Rating
X-Midtier
X-TtlSet
X-PC
X-Vname
X-Amz-Server-Side-Encryption
X-ECACHE
RTSS
X-VARITI-CCR
Cache-Tag
X-ESI
X-Vcap-Request-Id
X-D2id
X-Element-Page-Cache
Origin-Trial
X-Server-Name
Verso
X-Exp-Variant
X-GoogleNews-Bot
X-Exp-Id
X-Cdn-Fetch
X-Kinja
X-Kinja-Build
X-Use-Magma
X-Kinja-Server
X-Kinja-Revision
X-Ac
X-Rack-Cache
X-Ttl
X-Cnection
X-Powered-By-Plesk
Service-Worker-Allowed
SPRequestGuid
X-SharePointHealthScore
X-Cache-TTL
Xkey
X-Client-IP
X-Navigation-Version
X-B3-TraceId
X-Amz-Rid
X-Abt-Application-Version
X-GitHub-Request-Id
Edge-Control
X-Varnish-TTL
X-NWS-LOG-UUID
SPIisLatency
SPRequestDuration
Arr-Disable-Session-Affinity
X-Cached
X-Upstream
X-Erf-Bev-Bev-Is-Generated
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-Instrumentation
X-Erf-Bev-Bev
X-Browser-Type
X-Mg-S
X-Px
X-Dw-Request-Base-Id
X-Cache-Key
X-Correlation-Id
X-Middleton-Display
Display
X-Sol
Pagespeed
X-SRCache-Fetch-Status
X-SRCache-Store-Status
Content-MD5
Access-Control-Request-Method
Edge-Cache-Tag
X-Goog-Hash
X-Forwarded-For
X-Country-Code
X-NF-Request-ID
X-XRDS-Location
Front-End-Https
X-Version
TCN
X-Powered-CMS
X-Fastcgi-Cache
Public-Key-Pins
AR-ATIME
AR-Request-ID
AR-SID
AR-PoweredBy
AR-CACHE
X-Daa-Tunnel
X-HP-Webp
X-Jurisdiction
X-HP-Trace-Id
X-Recruiting
X-T
X-Content-Digest
X-MSEdge-Ref
X-RateLimit-Remaining
X-Id
X-Accel-Expires
X-Ser
X-Middleton-Response
Response
X-Amzn-Trace-Id
TP-Cache
TP-L2-Cache
X-Shield-Request-Id
X-FastCGI-Cache
S
Nginx-Cache
Mrf-Cache-Status
MRF-Tech
X-B3-TraceId-Primal
X-Webkit-Csp
MicrosoftSharePointTeamServices
X-Ratelimit-Limit
X-Request-Processing-Time
X-Request-Received
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Cache-Config
X-HS-Combine-CSS
Server-Node
Cache-Status
X-Distributor
Cache-Tags
Accept-Ch
X-Hits
X-Edge-Location-Klb
X-Kinsta-Cache
Fastcgi-Cache
X-Grace
X-Ratelimit-Remaining
Alternate-Protocol
X-DataDome
Server-Name
X-LB-Cache
X-Ezoic-Cdn
X-Origin-Server
X-Ua-Browser
X-DIS-Request-ID
X-Geo-Country
Cross-Origin-Opener-Policy
X-Protected-By
X-Microsite
X-Ratelimit-Reset
Filterid
X-Request-Handler-Origin-Region
X-Rid
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-TEC-API-VERSION
Healthy
X-Varnish-Backend
X-Frontend
X-Debug-Info
X-Logged-In
X-Git-Hash
X-Www-Served-By
X-FB-Debug
Payment
Cleartype
X-Page-Id
X-NGENIX-Cache
X-LLID
X-Forwarded-Proto
X-Hostname
X-Load-Cache
X-Fastly-Request-ID
X-ASPNET-VERSION
X-Origin-Cache
X-Cluster-Name
Charset
DC
X-PressLabs-Stats
MS-Author-Via
Content-Disposition
X-B3-Sampled
X-GUploader-UploadID
X-Goog-Metageneration
Access-Control-Allow-Method
Realpath
X-VCache
X-Upgrade-Enabled
X-Proxy
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-F-Cache
X-Oracle-Dms-Ecid
X-Oracle-Dms-Rid
Retry-After
X-Activity-Id
X-Az
X-AppVersion
X-Seen-By
Cross-Origin-Resource-Policy
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-Server-ID
X-Amz-Replication-Status
X-Contextid
Paypal-Debug-Id
X-TTL
X-Signature
X-Revision
Accept-Charset
X-Type
X-B-Cache
X-Amz-Meta-S3cmd-Attrs
X-Is-Crawler
X-Providence-Cookie
Viewport
X-Flags
X-Fb-Rlafr
X-Azure-Ref
X-Aspnet-Duration-Ms
X-Hosted-By
X-Whom
X-Request-Guid
X-Route-Name
X-Varnish-Server
X-Aspnetmvc-Version
X-Wix-Request-Id
Count-Hit
X-App-Environment
Surrogate-Key
X-B
X-TT
Amp-Access-Control-Allow-Source-Origin
X-DynaTrace
X-Ruxit-Js-Agent
X-Akamai-Edgescape
X-B3-Traceid
X-Language
X-Source
X-App-Server
Referer-Policy
X-RateLimit-Limit
X-Fastly-Request-Id
X-Cache-Control
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-Goog-Storage-Class
X-Mobile
X-COUNTRY
X-Cache-Age
X-Tt-Trace-Host
X-Tt-Trace-Tag
Host
X-Magnolia-Registration
X-Oneagent-Js-Injection
X-Varnish-Grace
Version
X-Template
X-HTML-Minification-Powered-By
X-N
X-Cache-Rule
X-Response-Served-From
SRV
X-Tumblr-User
X-Original-Request-Id
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-UUID
X-Rule
MS-CV
X-RTag
X-Cache-Time
X-Varnish-Age
Ms-Operation-Id
X-EdgeConnect-Cache-Status
X-Content-Powered-By
X-Framework
VIX-Pulpo-Upstream-Status
SD-X-WS
VIX-Pulpo-Node
X-Cache-Expired-At
X-Cache-Status-Check
Section-Io-Cache
X-Envoy-Decorator-Operation
Access-Control-Request-Headers
X-Cache-Grace
X-User-Agent
X-Backend-Name
X-Adobe-Content
Protected
X-Cacheable-TTL
X-Adobe-Loc
X-Device-Type
X-FW-Static
X-FW-Type
X-FW-Version
X-FW-Server
X-FW-Serve
X-FW-Dynamic
X-FW-Hash
X-ECache
Akamai-GRN
X-ProcessESI
X-Page-View
X-RemovedCookies
X-Trace-Id
NGB
X-Times
X-Jobs
X-NYM-Debug-Backend
X-Is-Bot
X-Instance
X-Akamai-Request-ID2
X-Http-Reason
X-Status
GEO-INFO
X-Rendered-As
X-G
Url
X-Servername
Refresh
X-Drupal-Cache-Contexts
X-L-Path
X-Environment-Context
X-Drupal-Cache-Tags
CDN-RequestId
From-Origin
X-CDN-Forward
WPO-Cache-Status
WPO-Cache-Message
X-Debug-IsPreview
X-Region
X-Debug-IsConnected
Front
Accept-Language
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Cache-Hit
Country
X-Unique-Id
Backend
X-Nginx-Cache
X-Content-Options
Fastly-SIE
X-Tb
Fastly-SWR
X-Zen-Fury
X-Varnish-Ttl
X-Air-Hostname
X-Air-Source
X-Node-Name
X-Air-Trace-Id
X-Tt-Logid
X-DynaTrace-JS-Agent
X-Tec-Api-Origin
X-Tec-Api-Root
X-Tec-Api-Version
X-Mode
Pinterest-Generated-By
Pinterest-Version
X-Real-IP
X-Pinterest-Rid
X-Newrelic-App-Data
X-Cache-Operation
Content-Secure-Policy
X-VC-Cache
Uber-Trace-Id
Liferay-Portal
X-Amzn-Remapped-Content-Length
X-Cache-Server
X-Generation-Time
Webserver
X-Ms-Version
Meta-Geo
X-Proxy-Cache-Info
X-Tumblr-Pixel-2
X-RN-RSRV
X-Rewrite-Enabled
X-UPSTREAM-Address
Filters
X-Ms-Request-Id
Azure-SlotName
X-Section
Azure-RegionName
X-Web-Node
X-Access
Azure-SiteName
X-IPS-LoggedIn
X-Rocket-Nginx-Serving-Static
X-Reqid
CF-IPCountry
Cache-Hits
X-TIME
Azure-Version
X-Buckets
X-Content-Age
Azure-InstanceId
X-Format
X-Time
Onion-Location
TWC-Privacy
TWC-Locale-Group
Webcakes-App-Version
Webcakes-App-Name
TWC-GeoIP-LatLong
X-BYPASS-REASON
TWC-Device-Class
Property-Id
Webcakes-Region
ServedBy
TWC-Connection-Speed
TWC-GeoIP-Country
X-AWS-Id
X-Locale
X-UA-Device-Type
X-Via-Fastly
X-ProxyCache-Key
X-Proxy-Cache-Status
X-Soup
X-VWS-Id
X-Server-W
X-Say-Cacheable
X-ProxyCache-Status
X-PHP-Backend
X-Say-TTL
X-SayCDN-TTL
X-Sucuri-ID
X-Sucuri-Cache
X-Debug
X-IPLB-Instance
X-Cms-Context
X-Cluster-Node
X-Cluster
X-IPLB-Request-ID
X-LJ-Flow-ID
X-Sql-Count
X-Sql-Duration-Ms
X-Proto
X-Origin-Hint
X-R9-Blue-Green-Version
X-Cache-TTL-Remaining
X-Adobe-Source
Fastly-Drupal-HTML
Node
X-No-Session
S-Rt
X-Labrador-Cache-Channel
X-Handled-By
X-Cache-Action
X-Cache-Host
Web-Mar-Node
X-Forwarded-Host
X-PHP-Host
Apigw-Requestid
X-Skip-Cache
DB-Nickname
X-Site-Version
X-Varnish-Beresp-Grace
Cache-Name
X-Extlb
X-Urbn-Context-Path
X-FB-TRIP-ID
X-Urbn-Site-Id
X-Zipkin-Id
X-Detected-As
X-Xfnlog-Site
X-Edge-Location
X-JoinUs
X-Timing-Wait
X-Proxied
X-Routing-Service
X-LSADC-Cache
X-Proxy-Build
X-SaId
Selected-Fe
X-LAGOON
X-GeoCountry
X-GeoCode
Locale
Cross-Origin-Window-Policy
Mn-Server-Ip
Mime-Version
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
X-Ua
WP-Super-Cache
ServerID
Fastcgi-Useragent
X-Origin-Date
X-Tumblr-Pixel-3
CDN-Uid
CDN-RequestCountryCode
CDN-CachedAt
X-Optimistic-Header
CDN-Cache
CDN-EdgeStorageId
CDN-PullZone
X-XRDS-LOCATION
X-Hl-Ver
Source
X-Uri
X-App-Version
Countrycode
X-Request-Time
X-SRV
X-ARC
X-Director
Upgrade-Insecure-Requests
X-Mg-Request-UUID
X-Cache-Debug
X-GEO
X-Varnish-Hits
X-Redis-Cache
X-Generated-By
CF-Cached-On
Cache-Tv-Group
X-TNCMS
X-Tx-Id
X-Loop
X-Akamai-Transformed
X-Pass-Why
Xet-Cookie
X-Presslabs-Stats
X-FireWall-Port
Frame-Options
X-URL
X-Origin-TTL
X-Origin-CC
X-Varnish-Cache-Hits
X-CACHE-AGE
Xserver
X-ShardId
X-Sorting-Hat-PodId
X-ShopId
X-Shopify-Stage
X-Sorting-Hat-ShopId
X-Alternate-Cache-Key
X-Storefront-Renderer-Rendered
X-Varnish-Hostname
X-RM-Cache-TTL
X-Varnish-Beresp-Ttl
X-NWS-UUID-VERIFY
X-Service
X-ServerID
X-Datadog-Sampled
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
X-Datadog-Trace-Id
X-Endurance-Cache-Level
X-Storage
X-Newrelic-Synthetics
X-Conf
X-BBC-Edge-Cache-Status
X-CMSURLCustom
X-Cache-NE
X-Bc-Bl
X-B-Cookie
X-Cache-Info
X-Request-Host
X-BCube-Filmed-By
X-Cache-Date
X-Core-Value
X-D
Candidate-Md5Url
Redirect-Candidate
X-Served-From
X-Vdms-Path
Edge-Cache
DCR-Processing-Time-Ms
DCR-Decision-By
Req-Svc-Chain
Rendered-Blocks
Release
X-Vdms-Version
X-VG-TLSProxy
Memcached
MD5-Digest
Host-ID
Meta-Geo-Continent
Ngx.Var.Host
Origin
Odigeo-Trace-Id
Gannett-Cam-Experience-Id
Sslversion
Surrogated-Key
X-A-Dam
X-A-Ccd
X-We-Are-Hiring
X-Pubstack
X-A-Dcw
Xc-Version
X-Aed
X-A-Wwc
X-A-Dgt
X-A
WWW-Authenticate
Thinkindot-CacheControl
TDXMobile
T-Server
Thinkindot-CacheControl-Type
Thinkindot-Control
A
BehaviorPad-Version
Cache-Host
X-Application
X-INCAP-ABP
X-Test
X-Mobile-URL
X-Origin-Time
X-TA-CDN-Provider
X-SRCache-Key
X-Mid
X-Thinkindot-L3
X-Level-Front-Cache
X-TIM-N
X-Loc
X-Location
X-Tid
X-Sigma-Backend
X-Platform-Cluster
X-S
X-Rojux
X-S-Cookie
X-S-Maxage
X-ScT
X-Rocket-Build-Number
X-B3-Spanid
X-Platform-Processor
X-Platform-Router
X-Processor
X-Sigma
Lang
X-Nyt-Route
X-Epic-Correlation-Id
X-Ec-Fail
X-Gdpr
X-Destination
X-Generated-On
X-Frame-Option
X-External-Request-Id
X-Httpd
X-Developer
X-Ec-GeoHdr
Environment
X-DC
X-Pool
X-Req
X-Ec-Custom-Error
X-Platform-Server
Server-Host
State
Ssr
X-Varnish-Remaining-TTL
Server-Info
X-Clara-WADP
X-DefHash
X-SB
X-SD-PageType
Mail-Subject
Magicmarker
NGX
X-Core-Mission
X-Cdn-Srv
X-Restarts
X-Sn-Servicetimems
X-Developers
NM-Fastcgi-Cache
X-Cdn-Origin
X-Fmm-Version
X-Geo-Header
X-GeoIP
X-Mvc-Supplant-Cachable
X-SVT-ORM-VERSION
We-Hiring
X-NodeID
X-GeoIP-City
X-Has-Esi
X-HS-Content-Campaign-Id
X-Auto-Login
X-Is-Gdpr
X-JWT-State
X-Hash
X-Akamai-Device-Characteristics
X-DefElseHash
Vix-Hermes-Req-Id
X-Varnish-CookieINHashed-On
X-Org
X-Origin-Response-Time
X-Cache-Bucket
X-SVT-ORM-RULES
X-Human
X-Varnish-CookieHashed-On
X-Old-Content-Length
Tube-Got-Results
Tube-Return
Tube-Got-Eval
Tube-Get-Contents
X-Varnish-Beresp-Status
X-Fetched-On
Decoy-Debug-Status
Decoy-Debug-TTL
X-Thanos
Cache-Key
X-VServer
X-Bip
Cluster
Decoy-Debug-Key
AKAMAI
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
Apple-News-Services-Host
Apple-News-Services-Handled
X-Vmg-Version
Country-Code
C-Via
Fastly-Backend-Name
Click-Count-Error
DSUID
Click-Count-Action-Start
X-WA-Info
X-CUA
CacheControlHeader
Gh-Request-Id
X-WP-CF-Super-Cache-Active
Fastly-GeoIP-CountryCode
X-WADP-Cache
CloudFront-Viewer-Country
X-Worker
Load-Balancing
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
Section-Io-Id
Section-Origin-Responded
X-Var-Ttl
X-Ckpd-Fst-Backend
X-Block-Status
X-Node-Id
X-Azure-Ref-OriginShield
X-App
X-Cache-Backend
X-Origin
X-CacheTTL
X-Cache-Tags
X-Cache-Id
L
X-Device-Os
X-Nginx-Cache-Key
X-Op-Id-All
X-NCache
X-Minions-Version
X-LB-NoCache
X-Men
X-Slack-Shared-Secret-Outcome
X-Slack-Backend
X-Request-Start
X-Scale
X-Region-Sid
X-Qloud-Router
X-Platform
X-Api-Version
X-Irp-Debug
X-Hnp-Log
X-Esi-Check
X-Fastly-Backend
X-DPWN-IS-SECURE
X-Dispatcher-Server
X-Mly-Id
X-Dispatcher-Number
X-FC-Vary-Parameters
X-Gamma-Serve
X-Gzip
X-HN
X-GeoIP-Region-Code
X-GeoIP-Country-Code
X-Gen-Mode
X-Varnishpool
X-Date
Web-Mar-Region
Cmstype
Adler-Geo
Kp-EeAlive
Wxu-Next-Commit
Wxu-Next-Region
Sever-Int
User-Cache-Control
X-Variation
Machine
Is-Eu
Cmsid
Server-Hostname
CDCHOST
Cache-Provider
Canary
Server-Ext
Wxu-Next-Hostname
Origin-CC
X-Ad-Defer-Variation
X-Wix-Viewer-Type
Platform
Origin-EX
Pics-Label
PFcat
X-Accel-Expires-Debug
X-VarnishDD-TTL
On-Server
X-Accel-Buffering
Producers
Datacenter
X-Parent-Response-Time
X-Mvc-Supplant-OutputCached
Fastly-SSL
X-Owner
X-Eu-Site
Ha-Gx-Prefs
HA-Ipaddr
X-Planisys-CDN-Cache
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
L5d-Success-Class
X-Nananana
X-CGP
X-Server-IP
X-Csrf-Jwt
X-Forwarded-Site
X-V-Cache
X-Refresh
X-Cache-FS-Status
X-Webkit-CSP-Report-Only
X-CSRF-Token
SID
X-Microcachable
X-Fastly-Cache
X-Up
X-AIR-PT
X-Origin-Expires
X-Aicache-OS
X-Tb-Optimization-Total-Bytes-Saved
Env
X-Instance-Name
X-Cache-Remote
HostName
X-Servedbyhost
X-NewRelic-App-Data
GeoIP-Latitude
Svr
X-Release
X-ND-Cache
X-Response-By
X-RCS-CacheZone
X-Trace-ID
X-NGINX-Cache
X-VC
Srvid
Expect-Staple
Locid
X-From
X-Via-Poph
X-Via-Popn
Memory
X-FL-QIT-DEBUG
Time
Cdn
X-Via-Popv
X-FL-EDGE
X-Nc
X-Zone
X-Provided-By
X-Via-CDN
X-Cache-Enabled
X-HA-Backend
X-Edge-Pop
X-Cached-By
X-Wa
X-Generated-In
Cache
NtCoent-Length
X-Webkit-CSP
X-Air-Pt
Edge-Copy-Time
X-Via-Edge
X-DataCenter
X-ZONE
Server-ID
X-HS-Status
X-Via-SSL
X-Vc
X-Check-Cacheable
X-Esi
Cdncip
X-AK-Request-ID
X-Nf-Request-Id
Cdnsip
X-Dc
X-Correlation-ID
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-Lambda-Id
X-Vcl-Version
X-Srv
X-Hcs-Proxy-Type
X-Gateway-Request-Id
X-Gateway-Cache-Key
X-Gateway-Cache-Status
X-Fpc
X-Gateway-Skip-Cache
X-CCDN-Origin-Time
X-Client-Ip
X-CCDN-CacheTTL
X-Via-NSCOPI
Hostname
X-LB-ID
X-API-Version
X-Vgn-Hpd-Ssi
X-Vgn-Hpd-Cached
X-Vgn-Hpd-Variations-Key
GeoIp-Country-Code
Sid
X-Vtex-Remote-Cache
CPC-Cache
CPC-Age
VNS-Age
VNS-Cache
X-Render-Time
X-Amz-Meta-Cb-Modifiedtime
X-Cs
X-CSRF-TOKEN
AMP-Access-Control-Allow-Source-Origin
X-Proxy-CacheRZ
XkeyRZ
X-CS
Eomportal-Instance
X-Via-JSL
X-MCACHE
True-Client-IP
X-B3-SpanId
Ngx-Var-Key
X-TH-Server
X-VCT
X-Micro-Cache
X-EC-Lua
Fastly-Drupal-Html
X-ATG-Version
True-Client-Ip
X-Upstream-Ct
X-VCL-Version
X-Upstream-Ht
IsBot
Esi-Enabled
X-Cache-ASPX
X-SIPLIST1
X-Cache-Type
X-Contensis-Viewer-Groups
X-Varnish-Authentication
X-APP-VERSION
X-Request-URI
X-MSEdge-Flight
Uri
OT-Force-Account-Verify
Path
X-MSEdge-Features
Srv
X-Fastly-Country-Code
X-Cache-NGX
M-TraceId
X-Info
Request-ID
Resin-Trace
GeoIP-Country-Code
X-CF-Lambda-Version
X-RateLimit-Remaining-Second
X-PAYTM-SRV-ID
X-RateLimit-Limit-Second
X-CF-Lambda-Fn
X-Varnish-Beresp-TTL
YJS-ID
X-RateLimit-Reset
X-FPC
Location
CDN
XServer
X-CLOUD-TRACE-CONTEXT
X-Lb-Id
X-Udemy-Cache-App-Namespace
RNT-Machine
X-Wikidot-Backend
Servername
N-Cache
LB
X-Cdn-Request-ID
RNT-Time
X-Wikidot-Static-Cache
X-Accel-Version
X-MP-GENERATED-AT
X-TX-ID
X-Shop-Environment
X-Forwarded-Path
X-Datacenter
X-Tenant
X-Bl-Debug
X-Orig-Expires
X-Service-Response-Time
X-Oss-Request-Id
Cross-Origin-Opener-Policy-Report-Only
X-Cache-Expires
X-Oss-Hash-Crc64ecma
X-Oss-Server-Time
X-Oss-Storage-Class
X-CDN-Cache-Status
X-Pod-Name
Sm-Log-Id
X-Oss-Object-Type
HIT
X-Edge-POP
X-Cdn-Cache-Status
X-Datadome
X-B3-Trace-ID
Server-Id
X-Akamai-Pragma-Client-IP
X-App-Name
X-Github-Request-Id
X-SERVER-NAME
X-WA
Timeexpire
X-Policy
X-Ha-Backend
X-Geo
Traceparent
X-Via-PopH
X-Via-PopN
Ohc-File-Size
X-Via-PopV
X-CACHE-KEY
X-Snapshot-Date
X-Scheme
X-NC
FSS-Cache
X-Moov-Xdn-Version
X-Srcache-Fetch-Status
X-Moov-T
X-Srcache-Store-Status
X-ID
X-ServedByHost
Yjs-Id
X-TraceId
X-PERF
X-Viewer-Country
ENV
X-ApacheServer
Proxy-Connection
Epwk-X-Cache
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
CountryCode
Hit
X-Dw-Trace-Id
X-Cdn-Forward
X-Amz-Meta-Opti
Geoip-Latitude
X-Serial
WZWS-RAY
Lb
X-Hyper-Cache
X-LiteSpeed-Cache-Control
X-M-Log
X-MiniProfiler-Ids
X-M-Reqid
X-Cdn-Diag
Content-Script-Type
X-Ctl-Mach
Pramga
X-RAMCache
X-Acquia-Application-UUID
X-Acquia-Purge-Tags
X-Acquia-Application-Trace
X-Acquia-Site
X-Qnm-Cache
Req-ID
Content-Style-Type
Ec-Rule-Version
X-Lb-Nocache
X-Vgn-Hpd-Reason
X-Fastly-Backend-Reqs
X-B3-Parentspanid
X-UP
Powered-By
X-Swift-Error
Cneonction
X-NAPM-TraceId
X-Wp-Cf-Super-Cache
Serverid
X-Lsadc-Cache
X-UA
X-TT-LOGID
X-Wp-Cf-Super-Cache-Cache-Control
X-F-Status
X-Litespeed-Cache-Control
X-Webstats-RespID
User-Agent
X-Litespeed-Tag
X-Fastly-Cache-Hits
X-Request-URL
MIME-Version
Warning
My-App
X-LiteSpeed-Tag
Ngx
X-IPS-Cached-Response
X-B3-ParentSpanId
X-Mid-Debug-Cache-Key
X-Th-Server
Inserted-Into-Cache-At
X-Cache-Ngx
X-Mid-Debug-Cache-Disk