Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
Strict-Transport-Security
X-Frame-Options
X-Content-Type-Options
Last-Modified
Link
CF-Cache-Status
Cf-Request-Id
Accept-Ranges
ETag
CF-RAY
Expect-CT
Pragma
X-Powered-By
X-Cache
Via
Age
X-XSS-Protection
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Xss-Protection
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-FRAME-OPTIONS
X-Download-Options
X-Timer
X-Request-Id
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-Adblock-Key
X-AspNet-Version
X-Permitted-Cross-Domain-Policies
X-Runtime
Alt-Svc
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Check
X-DNS-Prefetch-Control
X-Cache-Status
X-Generator
CF-Ray
X-Cacheable
Timing-Allow-Origin
X-Iinfo
X-Envoy-Upstream-Service-Time
Feature-Policy
X-Ua-Compatible
Status
X-Content-Security-Policy
X-Drupal-Dynamic-Cache
X-Request-ID
Content-Encoding
X-AspNetMvc-Version
Access-Control-Expose-Headers
X-CDN
Upgrade
X-XSS-PROTECTION
Access-Control-Max-Age
X-Dns-Prefetch-Control
X-Via
Server-Timing
X-Cache-Group
X-Robots-Tag
X-UA-Device
Request-Context
Keep-Alive
X-Amz-Request-Id
X-Turbo-Charged-By
X-Backend
X-Amz-Id-2
X-Proxy-Cache
X-Ws-Request-Id
P3p
X-AH-Environment
X-Age
Host-Header
X-Server-Powered-By
X-Hacker
X-Server
X-Rq
X-Vhost
EagleId
X-Akamai-Path-Stats
X-Varnish-Cache
Grace
X-Amz-Version-Id
X-Dispatcher
X-LiteSpeed-Cache
Cf-Edge-Cache
Allow
X-Swift-SaveTime
X-Swift-CacheTime
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
Ali-Swift-Global-Savetime
X-Nginx-Cache-Status
X-Device
X-WebKit-CSP
X-Page-Speed
X-Aws-Lambda-Call-Status
X-Host
X-Node
X-OneAgent-JS-Injection
X-Pingback
EagleEye-TraceId
X-Server-Id
X-Cache-Spec
Accept-CH
Surrogate-Control
Cf-Railgun
Request-Id
X-Akam-SW-Version
X-Backend-Server
X-Cache-Lookup
X-Readtime
X-Response-Time
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-HW
Content-Location
Accept-CH-Lifetime
X-Content-Security-Policy-Report-Only
X-Application-Context
Rating
X-Trace
Fastly-Restarts
X-Cloud-Trace-Context
Accept-Ch-Lifetime
X-Country
X-WebKit-CSP-Report-Only
X-Url
X-Clacks-Overhead
X-Edge
X-MS-InvokeApp
X-B3-TraceId
X-Amz-Server-Side-Encryption
X-Rack-Cache
Edge-Control
X-Ruxit-JS-Agent
X-TtlSet
X-Vname
X-PC
X-Nginx-Upstream-Cache-Status
X-Content-Type
X-Vcap-Request-Id
X-ESI
X-Mod-Pagespeed
X-Varnish-TTL
Xkey
Accept-Ch
X-FastCGI-Cache
X-Cdn-Fetch
X-Kinja-Build
X-Kinja
X-Kinja-Revision
X-Kinja-Server
X-Use-Magma
X-Exp-Variant
X-GoogleNews-Bot
X-D2id
X-Exp-Id
X-Amz-Rid
X-Mcache
Verso
X-VARITI-CCR
Cache-Tag
X-GitHub-Request-Id
X-CST
X-Powered-By-Plesk
RTSS
X-ECACHE
X-Oneagent-Js-Injection
Service-Worker-Allowed
X-Upstream
X-Cached
X-Client-IP
X-Navigation-Version
X-Version
X-Abt-Application-Version
X-Dw-Request-Base-Id
X-Ruxit-Js-Agent
X-Px
X-Cnection
X-Ac
Public-Key-Pins
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Instrumentation
Arr-Disable-Session-Affinity
X-SharePointHealthScore
SPRequestGuid
X-Element-Page-Cache
X-Ser
X-Middleton-Display
Pagespeed
Display
X-Sol
X-Server-Name
SPRequestDuration
SPIisLatency
X-Cache-TTL
X-Country-Code
X-NWS-LOG-UUID
X-Ttl
X-RateLimit-Remaining
X-Midtier
Permissions-Policy
X-NF-Request-ID
X-Cache-Key
Response
X-Middleton-Response
X-Edge-Location-Klb
X-Kinsta-Cache
X-Goog-Hash
X-Forwarded-For
Access-Control-Request-Method
Content-MD5
X-DataDome
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Shield-Request-Id
X-MSEdge-Ref
Front-End-Https
X-Correlation-Id
Edge-Cache-Tag
TP-Cache
X-Recruiting
TP-L2-Cache
X-HP-Webp
X-HP-Trace-Id
X-Jurisdiction
X-T
X-Powered-CMS
X-Accel-Expires
Nginx-Cache
AR-Request-ID
AR-PoweredBy
AR-CACHE
AR-ATIME
AR-SID
X-RateLimit-Limit
X-ORACLE-DMS-ECID
X-Daa-Tunnel
X-ORACLE-DMS-RID
MicrosoftSharePointTeamServices
TCN
X-Grace
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
X-Mg-S
X-Id
X-Hits
X-Content-Digest
Filters
Server-Node
X-HS-Cache-Config
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-HS-Combine-CSS
X-TEC-API-VERSION
X-Request-Processing-Time
X-Request-Received
X-HS-Hub-Id
X-HS-Content-Id
Server-Name
X-Frontend
X-Amzn-Trace-Id
S
X-LLID
X-Distributor
X-TTL
MS-Author-Via
X-Protected-By
Cache-Status
X-Geo-Country
X-Language
Fastcgi-Cache
X-PressLabs-Stats
X-LB-Cache
Cf-Apo-Via
X-Origin-Server
Cross-Origin-Opener-Policy
X-Fastly-Request-Id
X-Forwarded-Proto
X-F-Cache
X-Ezoic-Cdn
Charset
X-B3-Sampled
X-Microsite
X-FB-Debug
Filterid
X-Request-Handler-Origin-Region
X-Page-Id
X-Seen-By
X-Git-Hash
X-Ab
X-Amz-Meta-S3cmd-Attrs
X-XRDS-Location
Host
X-Ua-Browser
Count-Hit
X-Litespeed-Cache
Payment
X-ASPNET-VERSION
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Browser-Type
Realpath
X-Cache-Age
X-Ratelimit-Reset
X-Cluster-Name
X-VCache
Surrogate-Key
X-Origin-Cache
X-Template
Accept-Charset
Cache-Tags
Alternate-Protocol
X-Rid
X-NGENIX-Cache
X-Webkit-Csp
X-DynaTrace
Retry-After
X-Az
Cleartype
X-AppVersion
X-Activity-Id
X-Www-Served-By
X-Fastcgi-Cache
Access-Control-Allow-Method
X-Varnish-Backend
X-App-Environment
X-Signature
X-TT
X-Request-Guid
X-Aspnet-Duration-Ms
X-Tb
X-Type
X-Wix-Request-Id
X-Node-Name
X-B-Cache
X-Upgrade-Enabled
X-Route-Name
X-DIS-Request-ID
X-Flags
X-Is-Crawler
X-Providence-Cookie
X-Varnish-Grace
X-Amz-Replication-Status
X-B
ServerID
DC
Paypal-Debug-Id
X-Debug
X-Proxy
X-Logged-In
X-Drupal-Cache-Tags
X-Source
X-Envoy-Decorator-Operation
Frame-Options
X-Fastly-Request-ID
X-Content
X-Hostname
X-Server-ID
X-Tt-Trace-Host
X-Content-Options
X-Tt-Trace-Tag
X-Mobile
X-Revision
X-Load-Cache
Pinterest-Generated-By
Pinterest-Version
X-Pinterest-Rid
X-Contextid
X-Goog-Generation
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-Goog-Metageneration
Amp-Access-Control-Allow-Source-Origin
X-N
X-Cache-Control
Country
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Magnolia-Registration
X-Cache-Rule
Referer-Policy
X-User-Agent
Viewport
X-Whom
X-EdgeConnect-Cache-Status
X-Original-Request-Id
NGB
X-Response-Served-From
Node
Refresh
Content-Disposition
X-L-Path
X-Ratelimit-Remaining
X-Cacheable-TTL
X-Cache-TTL-Remaining
X-Environment-Context
X-Framework
Access-Control-Request-Headers
X-Mg-Request-UUID
X-NYM-Debug-Backend
X-Mid
X-Varnish-Age
X-Is-Bot
X-Cache-Time
X-Debug-IsConnected
X-G
X-Debug-IsPreview
X-Instance
Akamai-GRN
VIX-Pulpo-Upstream-Status
X-Jobs
X-Page-View
X-Akamai-Request-ID2
X-Yottaa-Metrics
X-Adobe-Loc
VIX-Pulpo-Node
Url
X-Adobe-Content
X-Cache-Grace
X-Yottaa-Optimizations
X-Rendered-As
X-Unique-Id
X-Status
X-Varnish-Server
X-Real-IP
X-Servername
Uber-Trace-Id
X-Restarts
X-Drupal-Cache-Contexts
X-Content-Powered-By
Countrycode
X-ProcessESI
Version
X-RemovedCookies
X-COUNTRY
X-App-Server
Srv
X-Http-Reason
X-Debug-Info
X-Oracle-Dms-Rid
X-Time
X-CDN-Forward
X-XRDS-LOCATION
X-Oracle-Dms-Ecid
Accept-Language
X-APP-VERSION
Protected
X-IPLB-Instance
X-IPLB-Request-ID
X-Via-JSL
X-Cache-Expired-At
X-Hosted-By
X-Nginx-Cache-Key
X-Cache-Hit
X-Ratelimit-Limit
Liferay-Portal
Healthy
X-Device-Type
X-Azure-Ref
Fastcgi-Useragent
X-Tumblr-Pixel-0
X-Tumblr-User
X-Tumblr-Pixel-1
X-Tt-Logid
X-Tumblr-Pixel
X-FW-Type
X-FW-Dynamic
X-FW-Hash
X-FW-Serve
X-FW-Static
X-FW-Server
Section-Io-Cache
X-Backend-Name
X-Cache-Operation
X-Trace-Id
X-Cache-NGX
Ms-Operation-Id
X-RTag
Backend
MS-CV
Content-Secure-Policy
X-Proxy-Cache-Status
Server-Info
X-UUID
X-Mobile-URL
X-RN-RSRV
X-Storage
Load-Balancing
X-UPSTREAM-Address
Meta-Geo
X-Mode
X-Akamai-Edgescape
GEO-INFO
X-Handled-By
CF-IPCountry
X-Cache-Server
Azure-Version
X-Content-Age
Eomportal-Instance
X-Edge-Location
CDN-Cache
X-Cache-Enabled
Azure-SlotName
X-Labrador-Cache-Channel
X-AWS-Id
X-Server-W
X-LJ-Flow-ID
Azure-RegionName
Webcakes-App-Name
X-Section
Azure-InstanceId
X-SayCDN-TTL
X-Cache-Host
CDN-PullZone
CDN-RequestCountryCode
X-Origin-Hint
CDN-EdgeStorageId
X-PCL
X-Format
X-Forwarded-Host
X-Say-Cacheable
CDN-RequestId
X-Say-TTL
X-Proto
X-Origin-Date
CDN-CachedAt
CDN-Uid
X-Locale
X-PHP-Host
X-Alternate-Cache-Key
X-Storefront-Renderer-Rendered
X-Access
X-HTML-Minification-Powered-By
WP-Super-Cache
X-Sql-Duration-Ms
X-Sql-Count
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
S-Rt
TWC-Connection-Speed
X-Varnish-Cache-Hits
TWC-GeoIP-LatLong
TWC-Locale-Group
TWC-Privacy
X-Urbn-Context-Path
TWC-GeoIP-Country
X-Uri
TWC-Device-Class
X-Urbn-Site-Id
X-Region
Property-Id
X-Site-Version
Azure-SiteName
Locale
Webcakes-App-Version
X-Shopify-Stage
X-Redis-Cache
Webcakes-Region
X-ShardId
X-ShopId
X-VWS-Id
X-No-Session
Web-Mar-Node
X-OCL
X-Skip-Cache
Onion-Location
X-URL
X-Adobe-Source
DB-Nickname
Mn-Server-Ip
X-BYPASS-REASON
Selected-Fe
X-Cache-Type
X-JoinUs
X-ProxyCache-Status
X-Varnish-Beresp-Grace
Apigw-Requestid
X-ServerID
X-Request-Time
X-UA-Device-Type
X-Zipkin-Id
X-Xfnlog-Site
X-Via-Fastly
X-VC-Cache
X-Varnish-Hostname
X-Timing-Wait
X-Web-Node
X-Datadome
X-PHP-Backend
Cross-Origin-Resource-Policy
X-Extlb
X-FB-TRIP-ID
X-Detected-As
X-Proxy-Build
X-Cms-Context
X-Proxied
X-ProxyCache-Key
X-Routing-Service
X-Rule
X-GeoCountry
X-GeoCode
X-Generation-Time
X-SaId
X-Generated-By
X-Varnishpool
X-Zen-Fury
X-Hl-Ver
X-Cache-Action
X-Cache-Status-Check
X-Tid
X-SRV
X-Correlation-ID
X-Nginx-Cache
X-Debug-Cache
X-R9-Blue-Green-Version
ServedBy
X-ECache
X-Ms-Request-Id
X-Ua
X-Ms-Version
X-DynaTrace-JS-Agent
X-FireWall-Port
Cache-Name
X-LSADC-Cache
X-Human
Cache
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
X-Amz-Apigw-Id
X-Amzn-RequestId
Xserver
X-Dc
X-App-Version
X-Cache-Tags
SD-X-WS
Source
Xet-Cookie
X-Cached-By
X-TNCMS
X-Loop
X-RCS-CacheZone
X-Aspnetmvc-Version
Cross-Origin-Window-Policy
X-GEO
X-Api-Version
LB
X-MP-GENERATED-AT
X-Cdn
X-Reqid
X-Varnish-Hits
X-TA-CDN-Provider
WPO-Cache-Status
X-Webkit-CSP
Origin
WPO-Cache-Message
X-Pubstack
X-Via-NSCOPI
X-Origin-CC
X-Origin-TTL
X-Amzn-Remapped-Content-Length
X-Soup
X-NewRelic-App-Data
X-GG-Cache-Date
X-B3-SpanId
X-IPS-LoggedIn
X-AOL-HN
From-Origin
X-Service
X-Tumblr-Pixel-2
X-FW-Version
X-Vgn-Hpd-Reason
Webserver
X-Newrelic-Synthetics
Cache-Hits
X-Platform-Server
X-Provided-By
Rip
X-Varnish-Beresp-Ttl
X-Cluster-Node
X-Request-Host
X-Application
X-AK-Request-ID
X-ARC
X-TIM-N
Expiry
X-B-Cookie
Upgrade-Insecure-Requests
X-Aed
X-User
X-A-Dgt
X-Vdms-Version
X-Orig-Expires
Lang
X-A
X-A-Ccd
Host-ID
X-A-Dam
X-NAPM-TraceId
X-A-Wwc
X-Bc-Bl
Cdncip
Cdnsip
X-Ec-Fail
X-Ec-GeoHdr
A
X-Developer
BehaviorPad-Version
X-D
X-Destination
X-Connection-Hash
X-External-Request-Id
Xc-Version
X-BCube-Filmed-By
Environment
DCR-Processing-Time-Ms
DCR-Decision-By
X-Forwarded-Path
X-Vdms-Path
X-Cache-NE
X-Owner
X-A-Dcw
X-Rewrite-Enabled
X-SRCache-Key
T-Server
Odigeo-Trace-Id
X-Processor
Surrogated-Key
X-Rojux
X-S
X-ScT
X-Served-From
X-VG-WebCache
X-S-Cookie
X-Shop-Environment
X-Tenant
Ngx.Var.Host
X-PBS-Appsvrname
Sslversion
Meta-Geo-Continent
Rendered-Blocks
MD5-Digest
OT-Force-Account-Verify
X-TIME
HostName
X-CSRF-Token
X-Accel-Buffering
X-Thanos
Machine
X-Generated-On
X-Bip
X-Dispatcher-Number
X-Level-Front-Cache
X-Cluster
X-Pool
Fastly-SSL
Redirect-Candidate
Mobile-Detection-Method
X-Qloud-Router
X-Aicache-OS
X-WA-Info
X-VC
Cache-Tv-Group
Mime-Version
X-Origin-Response-Time
Thinkindot-CacheControl
X-CGP
X-Ckpd-Fst-Backend
X-Core-Mission
X-Csrf-Jwt
X-Cdn-Srv
X-Core-Value
TDXMobile
State
X-Clientip
X-Datadog-Parent-Id
X-Clara-WADP
Traceparent
X-Ad-Defer-Variation
X-Datadog-Sampling-Priority
Vix-Hermes-Req-Id
V-Age
Tube-Return
VNS-Age
VNS-Cache
Wxu-Next-Commit
We-Hiring
Wxu-Next-Hostname
Wxu-Next-Region
Tube-Got-Results
Tube-Got-Eval
X-Cache-Info
Thinkindot-Control
Thinkindot-CacheControl-Type
X-CacheTTL
X-Cache-Id
X-Cache-Bucket
X-BBC-Edge-Cache-Status
Tube-Get-Contents
Web-Mar-Region
X-Branch-Name
X-Cdn-Origin
X-Forwarded-Site
X-VG-TLSProxy
X-Parent-Response-Time
X-Origin-Time
X-WADP-Cache
X-Planisys-CDN-Cache
X-Policy
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-Origin-Expires
X-Origin
X-Mvc-Supplant-OutputCached
X-Mvc-Supplant-Cachable
X-Minions-Version
X-Thinkindot-L3
X-NodeID
X-Optimistic-Header
X-Nyt-Route
X-Proxy-Cache-Info
X-RateLimit-Limit-Second
X-SplitTest
X-Sigma
X-Session-Fingerprint
X-Viewer-Country
X-Sn-Servicetimems
X-SIPLIST1
X-VServer
X-Slack-Backend
X-Scale
X-SVT-ORM-RULES
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-RateLimit-Remaining-Second
X-Region-Sid
X-Request-URI
X-Rocket-Build-Number
X-SVT-ORM-VERSION
X-Loc
X-Wix-Viewer-Type
X-Sigma-Backend
X-Fmm-Version
X-Fetched-On
X-Gateway-Cache-Key
X-Varnish-Remaining-TTL
X-Gateway-Skip-Cache
X-Gateway-Request-Id
X-Gateway-Cache-Status
X-Eu-Site
X-Esi-Check
X-Developers
X-DefHash
X-DefElseHash
X-Device-Os
X-DPWN-IS-SECURE
X-Epic-Correlation-Id
X-Ec-Custom-Error
X-Gdpr
X-Varnish-CookieINHashed-On
X-Irp-Debug
X-INCAP-ABP
X-HS-Content-Campaign-Id
X-Is-Gdpr
X-JWT-State
X-Worker
Servername
X-Hash
X-Has-Esi
X-V-Cache
X-Variation
X-Varnish-CookieHashed-On
X-Geo-Header
X-GeoIP
X-Gzip
X-GeoIP-City
X-Datadog-Trace-Id
X-Auto-Login
Apple-News-Services-Parsed-Url
Gh-Request-Id
Apple-News-Services-Request-Url
Fastly-SWR
Candidate-Md5Url
Cache-Host
Ha-Gx-Prefs
HA-Ipaddr
Kp-EeAlive
L
IsBot
Is-Eu
Apple-News-Services-Host
Click-Count-Action-Start
Fastly-SIE
Decoy-Debug-TTL
CPC-Age
CPC-Cache
Decoy-Debug-Status
Decoy-Debug-Key
DSUID
Country-Code
Fastly-Backend-Name
Fastly-GeoIP-CountryCode
Click-Count-Error
Cmsid
Cmstype
Datacenter
L5d-Success-Class
Req-Svc-Chain
Origin-EX
Release
Apple-News-Services-Handled
Producers
Platform
X-Xrds-Location
Origin-CC
Adler-Geo
Mail-Subject
NGX
Server-Host
NM-Fastcgi-Cache
X-Tec-Api-Root
X-Tec-Api-Version
X-Tec-Api-Origin
X-Cache-Remote
X-Hnp-Log
X-NCache
X-Tx-Id
X-Rocket-Nginx-Serving-Static
X-Scheme
X-Gamma-Serve
X-Fastly-Cache
AKAMAI
X-SB
X-S-Maxage
Server-Hostname
CDCHOST
X-Gen-Mode
CloudFront-Viewer-Country
Cluster
Fastcgi-Cache-TTL
Sever-Int
Server-Ext
X-Varnish-Beresp-Status
X-Block-Status
User-Cache-Control
Memcached
Svr
X-ZONE
X-NWS-UUID-VERIFY
X-CMSURLCustom
Ec-Rule-Version
X-Pod-Name
X-LB-NoCache
Canary
X-Ah-Environment
X-Varnish-Ttl
WebServer
X-Udemy-Cache-App-Namespace
SID
Ssr
Pics-Label
X-Cache-Debug
X-WP-CF-Super-Cache-Active
X-Tb-Optimization-Total-Bytes-Saved
X-Cache-Date
X-Buckets
X-Sucuri-ID
X-Trace-ID
X-Var-Ttl
X-ATG-Version
X-ND-Cache
X-Ig-Push-State
X-Sucuri-Cache
Sid
X-Via-Popn
X-Azure-Ref-OriginShield
X-Generated-In
Time
X-Via-Poph
X-Via-Popv
X-Microcachable
X-Fastly-Backend
X-FC-Vary-Parameters
Memory
X-Conf
X-Presslabs-Stats
AMP-Access-Control-Allow-Source-Origin
X-B3-Traceid
X-Refresh
Server-ID
X-Newrelic-App-Data
X-TRACE-ID
X-Servedbyhost
X-Akamai-Transformed
Fastly-Drupal-HTML
Fastly-Drupal-Html
X-MSEdge-Features
X-Edge-Pop
X-MSEdge-Flight
X-Dmc
Env
X-Release
X-Yandex-Sdch-Disable
X-Cs
X-Be
X-NC
X-Fpc
X-CS
X-DC
X-RateLimit-Reset
X-Esi
X-Pass-Why
X-PX
X-Up
X-Air-Hostname
X-Air-Trace-Id
X-MCACHE
Magicmarker
X-EC-Lua
X-Air-Source
X-ID
CDN
My-App
X-Endurance-Cache-Level
X-Dispatch
X-Wikidot-Backend
X-Wikidot-Static-Cache
GeoIp-Country-Code
X-Tumblr-Pixel-3
X-CACHE-AGE
X-Wa
X-Zone
X-Lambda-Id
X-TX-ID
True-Client-IP
X-VCL-Version
X-Hyper-Cache
X-NGINX-Cache
X-Webkit-CSP-Report-Only
X-Srv
X-Nf-Request-Id
X-CF-Lambda-Version
X-CF-Lambda-Fn
X-CACHE-KEY
X-Vc
X-App
Pramga
X-Alfa-Service
X-CSRF-TOKEN
X-M-Log
Hostname
X-M-Reqid
X-Micro-Cache
X-Req
X-Qnm-Cache
C-Via
Request-ID
True-Client-Ip
X-Varnish-Beresp-TTL
Resin-Trace
N-Cache
X-Air-Pt
X-LB-ID
X-TH-Server
X-HS-Status
X-Vcl-Version
X-TrackingId
CacheControlHeader
X-Vercel-Id
X-Vercel-Cache
Fastcgi-X-Cache-Version
GeoIP-Country-Code
X-Edge-Origin-Shield-Region
Tcn
True-Client-Country-4JS
X-Platform
Path
X-PAYTM-SRV-ID
On-Server
X-Edge-Origin-Shield-Bytes
Tracecode
X-Op-Id-All
Esi-Enabled
X-B3-Spanid
X-Check-Cacheable
X-SERVER-NAME
GeoIP-Latitude
Proxy-Connection
X-Vtex-Remote-Cache
X-Akamai-Pragma-Client-IP
X-Vtex-Processado-Em
X-CLOUD-TRACE-CONTEXT
X-AIR-PT
NtCoent-Length
Hit
X-GeoIP-Country-Code
X-GeoIP-Region-Code
Section-Io-Id
Section-Io-Origin-Time-Seconds
X-FPC
X-ApacheServer
Section-Origin-Responded
Section-Io-Origin-Status
X-API-Version
X-Node-Id
X-PERF
X-Request-Start
X-SD-PageType
X-LAGOON
X-Webkit-Csp-Report-Only
WWW-Authenticate
X-Accel-Expires-Debug
X-Via-CDN
X-Edge-POP
HIT
X-Date
X-Platform-Cluster
X-WA
X-Mly-Id
X-Geo
X-Platform-Processor
X-Datacenter
X-Platform-Router
ENV
Cache-Key
Cdn
User-Agent
X-RAMCache
YJS-ID
X-ServedByHost
X-Lb-Id
Server-Id
Lb
X-Render-Time
DynaTrace
DT-Hot-News
X-Proxy-CacheRZ
XkeyRZ
X-Dw-Trace-Id
Yjs-Id
X-Cdn-Forward
XM
X-VarnishDD-TTL
X-Via-Ucdn
X-Via-PopH
Server-Ttl
PFcat
X-Proxy-Upstream
X-HN
X-Via-PopV
X-Traceid
X-Via-PopN
X-Proxy-Cache-Hk
X-Li-Fabric
FSS-Cache
X-LI-Proto
Geoip-Latitude
X-Response-By
X-LI-UUID
X-Li-Pop
Dnion-Transfer-Encoding
X-CF-Powered-By
X-CUA
X-Old-Content-Length
X-Cache-Ttl
X-TT-LOGID
X-FORWARDED-FOR
X-Service-Response-Time
Sm-Log-Id
X-LiteSpeed-Cache-Control
Ohc-File-Size
X-DW
X-Instance-Name
Powered-By
X-RSL
X-DB
X-RPS
PICS-Label
X-DI
X-DSS
X-RPM
Location
X-LiteSpeed-Tag
X-Akamai-ERRuleID
X-Akamai-ERPolicy
Nginx-CQVIP
X-Fastly-Backend-Reqs
XServer
SRV
X-UA
X-Litespeed-Cache-Control
X-Wp-Cf-Super-Cache
X-Wp-Cf-Super-Cache-Cache-Control
MIME-Version
X-From
X-Location
X-Ftr-Request-Id
X-Webstats-RespID
X-FL-EDGE
Srvid
X-HostName
X-Cache-Backend
Locid
X-Request-Url
M-TraceId
X-B3-ParentSpanId
X-Fastly-Cache-Hits
Vha6-Origin
Wpo-Cache-Message
X-Cdn-Request-ID
X-Lb-Nocache
Wpo-Cache-Status
X-Nc
CountryCode
Warning
X-Ips-Loggedin
X-Cache-Ngx
X-DataCenter
X-Varnish-Authentication
X-IN-APIGATEWAYSSL
X-Contensis-Viewer-Groups
Fastcgi-Cache-Ttl
X-IN-APIGATEWAY
X-Cache-ASPX
X-Httpd
Req-ID
X-MiniProfiler-Ids
X-Akamai-Request-ID
X-HA-Backend
X-Snapshot-Date
X-Moov-T
X-Cc-Via
WZWS-RAY
X-Moov-Xdn-Version
X-Mg-Cache