Threat Level: green Handler on Duty: Guy Bruneau

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Accept-Ranges
Expect-CT
Pragma
CF-RAY
X-Powered-By
X-XSS-Protection
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-Xss-Protection
X-UA-Compatible
P3P
X-Served-By
X-Download-Options
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Request-ID
Access-Control-Allow-Credentials
CF-Ray
X-Request-Id
X-Permitted-Cross-Domain-Policies
X-AspNet-Version
Alt-Svc
Content-Security-Policy-Report-Only
X-Runtime
X-DNS-Prefetch-Control
X-Drupal-Cache
X-Check
X-Cache-Status
X-Generator
X-Cacheable
P3p
X-FRAME-OPTIONS
Timing-Allow-Origin
X-Iinfo
X-Envoy-Upstream-Service-Time
X-Content-Security-Policy
X-Drupal-Dynamic-Cache
Feature-Policy
Content-Encoding
Upgrade
Status
Access-Control-Expose-Headers
X-AspNetMvc-Version
X-CDN
Access-Control-Max-Age
X-Via
Server-Timing
X-UA-Device
X-Robots-Tag
Request-Context
X-Turbo-Charged-By
X-Cache-Group
X-Amz-Request-Id
EagleId
X-Amz-Id-2
X-Backend
Keep-Alive
X-AH-Environment
X-Ws-Request-Id
X-Proxy-Cache
X-Server
X-Ua-Compatible
X-Age
Host-Header
X-Hacker
Cf-Edge-Cache
X-Vhost
X-Server-Powered-By
X-Rq
Allow
X-Varnish-Cache
X-Dispatcher
X-Amz-Version-Id
Grace
X-Swift-SaveTime
X-Swift-CacheTime
X-LiteSpeed-Cache
Ali-Swift-Global-Savetime
X-OneAgent-JS-Injection
X-WebKit-CSP
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
Accept-CH
X-Device
Cf-Apo-Via
X-Page-Speed
Cf-Railgun
X-Aws-Lambda-Call-Status
X-Server-Id
X-Host
X-Node
X-Pingback
X-Cache-Spec
X-Nginx-Cache-Status
X-Dns-Prefetch-Control
X-Akam-SW-Version
Surrogate-Control
X-Backend-Server
EagleEye-TraceId
X-Cache-Lookup
Request-Id
X-Readtime
X-Ruxit-JS-Agent
X-HW
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Cloud-Trace-Context
X-Content-Security-Policy-Report-Only
Accept-Ch-Lifetime
X-Trace
X-Application-Context
X-Response-Time
X-CST
Permissions-Policy
X-Mod-Pagespeed
X-Nginx-Upstream-Cache-Status
Fastly-Restarts
X-Edge
X-Country
Accept-CH-Lifetime
Content-Location
X-WebKit-CSP-Report-Only
X-Content-Type
X-Mcache
Rating
X-Clacks-Overhead
X-MS-InvokeApp
X-Url
X-ECACHE
X-PC
X-Vname
X-TtlSet
X-Midtier
X-Amz-Server-Side-Encryption
X-VARITI-CCR
RTSS
Cache-Tag
X-Vcap-Request-Id
X-Element-Page-Cache
Verso
X-D2id
X-Ac
Origin-Trial
X-Server-Name
X-Cdn-Fetch
X-Exp-Id
X-Kinja-Server
X-Use-Magma
X-Kinja-Revision
X-Kinja-Build
X-GoogleNews-Bot
X-Kinja
X-Exp-Variant
X-Rack-Cache
X-B3-TraceId
X-Cnection
X-Varnish-TTL
X-Powered-By-Plesk
X-Cache-TTL
Service-Worker-Allowed
X-ESI
Xkey
X-GitHub-Request-Id
X-Navigation-Version
X-Client-IP
X-Abt-Application-Version
X-NWS-LOG-UUID
X-Amz-Rid
Edge-Control
X-SharePointHealthScore
SPRequestGuid
X-Ttl
X-Cached
X-Px
X-Fastcgi-Cache
X-Mg-S
X-Litespeed-Cache
X-Server-Lifecycle-Phase
X-Instrumentation
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Kraken-Loop-Name
X-Browser-Type
Arr-Disable-Session-Affinity
X-Upstream
SPIisLatency
SPRequestDuration
X-Middleton-Display
X-Sol
Pagespeed
Display
X-Cache-Key
X-Correlation-Id
Content-MD5
X-Dw-Request-Base-Id
X-SRCache-Fetch-Status
X-SRCache-Store-Status
Access-Control-Request-Method
X-NF-Request-ID
Edge-Cache-Tag
X-Daa-Tunnel
X-Goog-Hash
X-RateLimit-Remaining
X-XRDS-Location
Front-End-Https
X-Country-Code
Public-Key-Pins
X-Version
X-Forwarded-For
X-Powered-CMS
AR-ATIME
AR-PoweredBy
AR-SID
AR-Request-ID
AR-CACHE
X-Id
TCN
X-MSEdge-Ref
X-HP-Webp
X-T
X-Recruiting
X-Jurisdiction
X-HP-Trace-Id
X-Content-Digest
X-Accel-Expires
X-Middleton-Response
Response
X-B3-TraceId-Primal
Mrf-Cache-Status
MRF-Tech
X-Shield-Request-Id
X-Ser
TP-L2-Cache
TP-Cache
Nginx-Cache
X-Webkit-Csp
X-Amzn-Trace-Id
S
X-Hits
X-Request-Received
X-Request-Processing-Time
X-HS-Combine-CSS
X-HS-Content-Id
X-HS-Hub-Id
X-HS-Cache-Config
Server-Node
Cache-Status
X-Edge-Location-Klb
X-Kinsta-Cache
X-Distributor
X-Grace
X-Fastly-Request-ID
Fastcgi-Cache
X-TEC-API-ROOT
Cache-Tags
X-TEC-API-ORIGIN
X-TEC-API-VERSION
MicrosoftSharePointTeamServices
Alternate-Protocol
Server-Name
X-Protected-By
Accept-Ch
X-Ruxit-Js-Agent
X-DataDome
X-DIS-Request-ID
X-Ezoic-Cdn
X-Geo-Country
X-Ratelimit-Limit
X-Origin-Server
X-Ratelimit-Reset
X-LB-Cache
X-Ua-Browser
X-Microsite
X-Request-Handler-Origin-Region
X-Frontend
X-Rid
X-TTL
X-Debug-Info
X-Varnish-Backend
X-Www-Served-By
X-Logged-In
Healthy
Cleartype
Filterid
X-Git-Hash
Cross-Origin-Opener-Policy
Payment
X-Forwarded-Proto
X-NGENIX-Cache
X-FB-Debug
X-Page-Id
X-PressLabs-Stats
X-Load-Cache
Charset
X-ASPNET-VERSION
X-B3-Sampled
X-VCache
Content-Disposition
X-Origin-Cache
X-LLID
X-Cluster-Name
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Ratelimit-Remaining
DC
MS-Author-Via
X-Hostname
X-Goog-Metageneration
X-GUploader-UploadID
X-Upgrade-Enabled
Accept-Charset
Access-Control-Allow-Method
X-Proxy
Retry-After
X-Activity-Id
X-Az
X-AppVersion
X-F-Cache
X-RateLimit-Limit
Cross-Origin-Resource-Policy
X-Amz-Replication-Status
X-Type
X-Contextid
X-Signature
X-B-Cache
X-Request-Guid
X-Route-Name
X-Hosted-By
X-Providence-Cookie
X-Is-Crawler
X-Aspnet-Duration-Ms
X-Amz-Meta-S3cmd-Attrs
X-FastCGI-Cache
X-Flags
Paypal-Debug-Id
X-Varnish-Server
Viewport
X-Revision
X-Azure-Ref
X-Whom
X-Aspnetmvc-Version
X-TT
X-Wix-Request-Id
X-Seen-By
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
X-B
X-Oracle-Dms-Rid
Surrogate-Key
X-Oracle-Dms-Ecid
X-App-Environment
X-Fb-Rlafr
Referer-Policy
X-DynaTrace
Amp-Access-Control-Allow-Source-Origin
X-Source
Count-Hit
Realpath
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Akamai-Edgescape
X-Mobile
X-App-Server
X-B3-Traceid
X-Goog-Generation
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
Host
X-Cache-Control
X-Oneagent-Js-Injection
X-EdgeConnect-Cache-Status
X-HTML-Minification-Powered-By
X-N
X-Original-Request-Id
X-Tumblr-User
X-Tumblr-Pixel
X-Response-Served-From
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-UUID
X-Varnish-Age
X-Cache-Rule
Refresh
Version
X-Magnolia-Registration
X-Cache-Age
MS-CV
Section-Io-Cache
X-Cache-Time
X-RTag
X-Rule
X-Envoy-Decorator-Operation
X-Varnish-Grace
Ms-Operation-Id
SD-X-WS
Access-Control-Request-Headers
X-Adobe-Content
Akamai-GRN
Protected
X-Adobe-Loc
X-Cache-Grace
X-Content-Powered-By
X-FW-Server
X-FW-Type
X-Cache-Status-Check
X-Page-View
X-Cache-Expired-At
X-FW-Static
X-FW-Version
X-Status
X-FW-Hash
X-FW-Dynamic
X-FW-Serve
X-Environment-Context
X-ProcessESI
X-Device-Type
X-Cacheable-TTL
X-L-Path
X-RemovedCookies
X-Is-Bot
X-Framework
X-NYM-Debug-Backend
VIX-Pulpo-Node
X-Rendered-As
X-Instance
X-G
X-Servername
VIX-Pulpo-Upstream-Status
GEO-INFO
NGB
X-Http-Reason
X-Akamai-Request-ID2
X-User-Agent
Url
X-Backend-Name
X-Jobs
X-Debug-IsConnected
X-Debug-IsPreview
X-Nginx-Cache
X-CDN-Forward
X-Newrelic-App-Data
X-Yottaa-Metrics
SRV
X-Yottaa-Optimizations
X-Drupal-Cache-Contexts
X-Drupal-Cache-Tags
X-Cache-Hit
X-Tb
CDN-RequestId
From-Origin
X-Trace-Id
Country
X-Region
WPO-Cache-Message
WPO-Cache-Status
Pinterest-Generated-By
X-Tt-Logid
X-URL
Pinterest-Version
X-Pinterest-Rid
X-Node-Name
Accept-Language
Front
X-Fastly-Request-Id
X-Template
X-Real-IP
X-VC-Cache
X-Language
Backend
Uber-Trace-Id
X-Amz-Apigw-Id
X-Mode
X-Amzn-RequestId
X-Content-Options
Content-Secure-Policy
Fastly-Drupal-HTML
Fastly-SWR
X-DynaTrace-JS-Agent
Fastly-SIE
Filters
X-UPSTREAM-Address
X-TIME
X-Unique-Id
X-Tumblr-Pixel-2
X-Cache-Operation
Meta-Geo
X-RN-RSRV
X-Generation-Time
X-Rewrite-Enabled
Azure-InstanceId
Azure-RegionName
X-Web-Node
X-Section
X-Proxy-Cache-Info
Webserver
X-IPS-LoggedIn
Azure-Version
X-Access
X-Amzn-Remapped-Content-Length
X-Cache-TTL-Remaining
X-Rocket-Nginx-Serving-Static
Onion-Location
X-Cache-Server
CF-IPCountry
X-Format
Azure-SlotName
Azure-SiteName
X-SayCDN-TTL
X-Time
X-Say-Cacheable
X-Sql-Count
X-Sql-Duration-Ms
X-Reqid
X-Sucuri-ID
X-Sucuri-Cache
CDN-Cache
CDN-CachedAt
X-Adobe-Source
X-Cms-Context
X-Debug
Cross-Origin-Window-Policy
CDN-Uid
CDN-EdgeStorageId
CDN-PullZone
CDN-RequestCountryCode
X-Ua
X-Say-TTL
X-Proxy-Cache-Status
Web-Mar-Node
X-LJ-Flow-ID
TWC-Privacy
X-ProxyCache-Key
TWC-Locale-Group
ServerID
X-AWS-Id
S-Rt
X-PHP-Backend
X-Origin-Hint
Webcakes-App-Name
X-Skip-Cache
X-VWS-Id
X-BYPASS-REASON
X-Cache-Action
X-Forwarded-Host
TWC-GeoIP-LatLong
X-IPLB-Instance
TWC-GeoIP-Country
X-GeoCountry
X-GeoCode
X-Edge-Location
X-ProxyCache-Status
X-Cache-Host
X-Labrador-Cache-Channel
X-R9-Blue-Green-Version
X-IPLB-Request-ID
X-Content-Age
X-Cluster
X-Locale
X-Server-W
X-UA-Device-Type
Node
X-Zen-Fury
X-Ms-Request-Id
Apigw-Requestid
X-Ms-Version
TWC-Device-Class
X-PHP-Host
X-Proto
X-Soup
Webcakes-Region
Property-Id
X-Varnish-Beresp-Grace
TWC-Connection-Speed
X-Via-Fastly
Cache-Name
Webcakes-App-Version
X-Site-Version
X-Proxied
X-No-Session
X-Routing-Service
X-Cluster-Node
X-Detected-As
X-Zipkin-Id
X-Extlb
X-Xfnlog-Site
X-Handled-By
X-JoinUs
Locale
X-LAGOON
X-SRV
X-Urbn-Context-Path
X-Urbn-Site-Id
Cache-Hits
X-SaId
X-LSADC-Cache
X-Proxy-Build
Mime-Version
Selected-Fe
X-WP-CF-Super-Cache
X-Timing-Wait
Mn-Server-Ip
WP-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
X-Hl-Ver
Fastcgi-Useragent
DB-Nickname
X-FB-TRIP-ID
X-XRDS-LOCATION
X-Request-Time
X-ECache
X-Cache-Debug
ServedBy
X-Tumblr-Pixel-3
Liferay-Portal
X-Redis-Cache
X-Optimistic-Header
X-NWS-UUID-VERIFY
X-Loop
X-TNCMS
Upgrade-Insecure-Requests
Source
Xserver
X-Air-Trace-Id
X-Air-Hostname
X-Air-Source
X-Origin-Date
X-GEO
X-Mg-Request-UUID
X-Generated-By
X-Times
X-Tec-Api-Root
Countrycode
X-Tec-Api-Version
X-Tec-Api-Origin
CF-Cached-On
X-Akamai-Transformed
X-CACHE-AGE
X-Tid
X-Varnish-Hits
X-Cdn
X-COUNTRY
X-Uri
X-Director
X-Storage
Xet-Cookie
X-Pass-Why
X-Tx-Id
X-Varnish-Beresp-Ttl
Frame-Options
X-TA-CDN-Provider
X-ARC
X-B3-Spanid
X-Origin-TTL
X-Varnish-Ttl
X-Newrelic-Synthetics
X-Origin-CC
X-FireWall-Port
X-Trace-ID
X-Service
X-Esi
X-Presslabs-Stats
X-Varnish-Cache-Hits
X-Datadog-Sampling-Priority
X-Datadog-Trace-Id
X-Datadog-Sampled
Environment
X-DC
X-ShopId
X-Endurance-Cache-Level
X-Datadog-Parent-Id
X-Buckets
X-Alternate-Cache-Key
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Shopify-Stage
X-Storefront-Renderer-Rendered
X-ShardId
X-App-Version
X-Varnish-Hostname
Rendered-Blocks
Release
Origin
Redirect-Candidate
WWW-Authenticate
Thinkindot-Control
TDXMobile
Thinkindot-CacheControl-Type
T-Server
Odigeo-Trace-Id
Req-Svc-Chain
Sslversion
Surrogated-Key
X-Vdms-Version
X-We-Are-Hiring
DCR-Decision-By
DCR-Processing-Time-Ms
Candidate-Md5Url
BehaviorPad-Version
Xc-Version
A
Edge-Cache
Gannett-Cam-Experience-Id
Meta-Geo-Continent
X-VG-TLSProxy
MD5-Digest
Lang
Host-ID
X-A
Ngx.Var.Host
X-A-Dgt
X-External-Request-Id
X-S-Cookie
X-S
X-Frame-Option
X-Epic-Correlation-Id
X-Ec-GeoHdr
X-Destination
X-Developer
X-Ec-Fail
X-Gdpr
X-Rojux
X-Platform-Router
X-Nyt-Route
X-Platform-Processor
X-Origin-Time
X-Mobile-URL
X-Mid
X-INCAP-ABP
X-Processor
X-Loc
X-S-Maxage
X-ScT
X-Application
X-B-Cookie
X-BBC-Edge-Cache-Status
X-Bc-Bl
X-Aed
X-A-Wwc
X-A-Dam
X-A-Dcw
X-Platform-Cluster
X-BCube-Filmed-By
X-Vdms-Path
X-Core-Value
X-SRCache-Key
X-D
X-CMSURLCustom
X-Cache-NE
X-Cache-Info
X-TIM-N
X-Thinkindot-L3
X-A-Ccd
Thinkindot-CacheControl
Server-Info
Cache-Tv-Group
X-AIR-PT
SID
X-Request-Host
Tube-Got-Results
X-Is-Gdpr
Tube-Return
X-JWT-State
Tube-Got-Eval
X-Location
Magicmarker
Tube-Get-Contents
X-Old-Content-Length
Fastly-Backend-Name
X-Level-Front-Cache
X-WP-CF-Super-Cache-Active
X-Developers
Fastly-GeoIP-CountryCode
X-Served-From
X-NodeID
X-Cdn-Origin
X-Origin-Response-Time
X-Cache-Bucket
X-Httpd
X-Pubstack
State
X-Fmm-Version
X-Gamma-Serve
Memcached
X-Ec-Custom-Error
X-DefHash
X-DefElseHash
Server-Host
X-Geo-Header
X-CUA
X-Cdn-Srv
X-HS-Content-Campaign-Id
X-Req
X-Clara-WADP
X-Has-Esi
X-GeoIP-City
X-Generated-On
X-Core-Mission
X-Human
X-Platform-Server
Apple-News-Services-Host
Apple-News-Services-Handled
X-Sigma-Backend
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
X-Sigma
DSUID
C-Via
X-Sn-Servicetimems
X-WA-Info
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
X-VServer
X-Test
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-ServerID
X-SD-PageType
Cache-Host
X-Restarts
X-Rocket-Build-Number
Country-Code
X-Auto-Login
Decoy-Debug-Key
Decoy-Debug-TTL
Decoy-Debug-Status
Cluster
X-Worker
X-SB
X-Akamai-Device-Characteristics
X-WADP-Cache
Click-Count-Error
Click-Count-Action-Start
Section-Io-Origin-Time-Seconds
X-RM-Cache-TTL
Section-Io-Id
X-Parent-Response-Time
Section-Io-Origin-Status
Section-Origin-Responded
X-Cache-Id
X-App
X-Pool
X-Accel-Expires-Debug
X-Cache-Backend
X-Date
X-Ad-Defer-Variation
X-Block-Status
X-Nananana
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Origin
X-Node-Id
AKAMAI
X-Accel-Buffering
X-Planisys-CDN-TTL
X-Request-Start
X-Var-Ttl
X-Variation
X-Slack-Backend
X-Scale
X-Wix-Viewer-Type
Cache-Key
X-Minions-Version
X-Gen-Mode
X-GeoIP
X-Fastly-Backend
X-Esi-Check
X-DPWN-IS-SECURE
X-GeoIP-Country-Code
X-GeoIP-Region-Code
CloudFront-Viewer-Country
X-LB-NoCache
X-Hnp-Log
X-Hash
X-Gzip
X-Dispatcher-Number
X-Cache-FS-Status
Platform
X-Conf
Pics-Label
Origin-EX
Origin-CC
Producers
X-Vmg-Version
X-Varnish-Beresp-Status
Sever-Int
Server-Hostname
Server-Ext
Mail-Subject
L
CacheControlHeader
CDCHOST
Cache-Provider
Adler-Geo
X-Fetched-On
Cmsid
Cmstype
Kp-EeAlive
Is-Eu
Gh-Request-Id
X-Bip
X-Thanos
NM-Fastcgi-Cache
User-Cache-Control
Vix-Hermes-Req-Id
Ssr
Web-Mar-Region
Svr
We-Hiring
X-Device-Os
X-HN
Wxu-Next-Hostname
X-Ckpd-Fst-Backend
X-Men
X-Irp-Debug
Wxu-Next-Commit
PFcat
X-NCache
Datacenter
X-Up
X-V-Cache
X-Cache-Tags
Wxu-Next-Region
X-Slack-Shared-Secret-Outcome
X-Org
X-Server-ID
Fastly-SSL
X-Platform
X-Azure-Ref-OriginShield
X-Refresh
X-CacheTTL
X-Server-IP
X-Region-Sid
X-Cached-By
X-Qloud-Router
X-Nginx-Cache-Key
X-Mvc-Supplant-Cachable
X-Forwarded-Site
X-Dispatcher-Server
X-Varnishpool
NGX
X-Op-Id-All
On-Server
Machine
X-VarnishDD-TTL
X-FC-Vary-Parameters
X-Webkit-CSP-Report-Only
X-CGP
L5d-Success-Class
Canary
Cdn
X-Csrf-Jwt
Ha-Gx-Prefs
HA-Ipaddr
X-Aicache-OS
X-Owner
X-Eu-Site
X-CSRF-Token
Cdnsip
X-Via-Popv
Cdncip
X-Mvc-Supplant-OutputCached
GeoIP-Latitude
X-AK-Request-ID
X-Servedbyhost
X-Cache-Remote
X-Via-Popn
X-Via-Poph
X-Tb-Optimization-Total-Bytes-Saved
X-Cache-Date
Env
HostName
X-RCS-CacheZone
X-HA-Backend
X-Microcachable
X-Gateway-Request-Id
X-Mly-Id
X-VC
X-Gateway-Cache-Key
Server-ID
X-APP-VERSION
X-Gateway-Cache-Status
X-API-Version
X-Gateway-Skip-Cache
X-Zone
Cache
X-DataCenter
Memory
X-Wa
X-LB-ID
Time
X-Webkit-CSP
X-ZONE
Request-ID
X-Via-NSCOPI
X-Fastly-Cache
X-Nc
X-Generated-In
Load-Balancing
Eomportal-Instance
X-Fpc
X-Vgn-Hpd-Cached
X-Vgn-Hpd-Ssi
X-Vc
X-Vgn-Hpd-Variations-Key
X-Instance-Name
X-Micro-Cache
X-ND-Cache
X-Origin-Expires
X-Check-Cacheable
Ngx-Var-Key
OT-Force-Account-Verify
X-Correlation-ID
X-NewRelic-App-Data
X-HS-Status
X-Response-By
X-Client-Ip
X-Release
Hostname
X-Hcs-Proxy-Type
X-CCDN-CacheTTL
X-From
Srvid
Locid
X-CCDN-Origin-Time
Expect-Staple
X-Request-URI
X-SIPLIST1
IsBot
X-FL-EDGE
X-FL-QIT-DEBUG
X-VCL-Version
X-Cache-Enabled
X-Cache-NGX
X-Via-CDN
X-Info
X-CSRF-TOKEN
X-Edge-Pop
AMP-Access-Control-Allow-Source-Origin
Srv
NtCoent-Length
X-Via-JSL
X-CS
X-Via-Edge
X-NGINX-Cache
Edge-Copy-Time
X-MCACHE
X-Via-SSL
GeoIp-Country-Code
X-Api-Version
X-Dc
X-Srv
X-Nf-Request-Id
X-Provided-By
True-Client-Ip
Sid
X-Proxy-CacheRZ
XkeyRZ
Uri
X-Debug-Cache-Fetch
Location
True-Client-IP
X-Amz-Meta-Cb-Modifiedtime
X-Debug-Cache-Store
X-Lambda-Id
X-EC-Lua
X-Air-Pt
X-Cache-Expires
X-Vcl-Version
Path
X-Cs
X-Vtex-Remote-Cache
X-Render-Time
VNS-Cache
VNS-Age
X-Oss-Object-Type
X-Oss-Storage-Class
CPC-Age
X-Oss-Server-Time
X-Oss-Request-Id
X-Oss-Hash-Crc64ecma
CPC-Cache
X-Edge-POP
Servername
GeoIP-Country-Code
Fastly-Drupal-Html
Resin-Trace
Cross-Origin-Opener-Policy-Report-Only
CDN
X-Fastly-Country-Code
Traceparent
X-TH-Server
X-VCT
X-CLOUD-TRACE-CONTEXT
X-Moov-Xdn-Version
X-Moov-T
X-B3-SpanId
X-ATG-Version
X-Viewer-Country
X-Varnish-Beresp-TTL
X-Cdn-Request-ID
X-Scheme
X-TX-ID
X-Akamai-Pragma-Client-IP
X-Cache-ASPX
X-Varnish-Authentication
X-MSEdge-Features
X-MSEdge-Flight
Esi-Enabled
LB
X-PERF
X-Pod-Name
X-ApacheServer
Timeexpire
X-FPC
X-Contensis-Viewer-Groups
X-Datacenter
CountryCode
Rip
XServer
X-NAPM-TraceId
X-RateLimit-Reset
X-Datadome
M-TraceId
Powered-By
FSS-Cache
X-Accel-Version
X-Cdn-Cache-Status
X-Service-Response-Time
Sm-Log-Id
X-Udemy-Cache-App-Namespace
X-CF-Lambda-Fn
X-PAYTM-SRV-ID
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-SERVER-NAME
X-Upstream-Ct
X-CF-Lambda-Version
Server-Id
X-WA
X-Upstream-Ht
X-Lb-Id
X-Geo
X-Cache-Type
YJS-ID
X-Srcache-Store-Status
X-Srcache-Fetch-Status
X-Clientip
V-Age
Ohc-File-Size
X-CACHE-KEY
X-NC
Tracecode
Proxy-Connection
True-Client-Country-4JS
ENV
X-Wikidot-Backend
X-CDN-Cache-Status
X-Wikidot-Static-Cache
RNT-Time
N-Cache
RNT-Machine
HIT
X-ServedByHost
X-TraceId
X-VG-WebCache
XM
X-Ha-Backend
X-LiteSpeed-Cache-Control
X-Via-PopV
WZWS-RAY
X-Cdn-Forward
X-Via-PopN
X-Via-PopH
Geoip-Latitude
Ngx
X-B3-Parentspanid
Epwk-X-Cache
Yjs-Id
X-Shop-Environment
X-Bl-Debug
X-Tenant
X-Orig-Expires
X-Hyper-Cache
X-Forwarded-Path
X-B3-Trace-ID
Inserted-Into-Cache-At
X-MP-GENERATED-AT
X-B3-ParentSpanId
X-Cdn-Diag
X-MiniProfiler-Ids
X-Rebelmouse-Cache-Control
Content-Style-Type
Content-Script-Type
User-Agent
X-Rebelmouse-Surrogate-Control
X-Lb-Nocache
X-Fastly-Backend-Reqs
Ec-Rule-Version
X-Dw-Trace-Id
X-Swift-Error
X-Vgn-Hpd-Reason
X-Serial
X-TT-LOGID
X-Wp-Cf-Super-Cache
X-Lsadc-Cache
X-F-Status
X-Wp-Cf-Super-Cache-Cache-Control
Warning
Cneonction
X-App-Name
X-Policy
X-Qnm-Cache
X-M-Reqid
X-M-Log
Lb
X-Amz-Meta-Opti
Hit
MIME-Version
Req-ID
X-Snapshot-Date
X-Mid-Debug-Cache-Disk
Expiry
X-Stale
X-Th-Server
X-Mid-Debug-Cache-Key
X-Request-URL
Pramga
X-UP
X-IPS-Cached-Response
My-App
X-LiteSpeed-Tag
X-Connection-Hash
X-Cache-Ngx