Threat Level: green Handler on Duty: Guy Bruneau

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
Strict-Transport-Security
X-Frame-Options
X-Content-Type-Options
Link
Last-Modified
CF-Cache-Status
Cf-Request-Id
CF-RAY
Accept-Ranges
ETag
Expect-CT
Pragma
X-Powered-By
X-Cache
Via
Age
X-XSS-Protection
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
X-Xss-Protection
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-FRAME-OPTIONS
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-Adblock-Key
X-AspNet-Version
X-Permitted-Cross-Domain-Policies
Alt-Svc
X-Runtime
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Request-ID
X-Cache-Status
X-Check
X-Generator
X-DNS-Prefetch-Control
X-Cacheable
X-Iinfo
X-Envoy-Upstream-Service-Time
Feature-Policy
Timing-Allow-Origin
X-Content-Security-Policy
Status
X-Drupal-Dynamic-Cache
Content-Encoding
Access-Control-Expose-Headers
X-AspNetMvc-Version
X-CDN
P3p
Upgrade
X-Ua-Compatible
Access-Control-Max-Age
CF-Ray
X-Dns-Prefetch-Control
X-Via
X-Robots-Tag
X-Cache-Group
Server-Timing
X-UA-Device
Keep-Alive
Request-Context
X-AH-Environment
X-Turbo-Charged-By
X-Amz-Request-Id
X-Proxy-Cache
X-Backend
X-Amz-Id-2
X-Age
X-Ws-Request-Id
Host-Header
X-Hacker
X-Server-Powered-By
X-Rq
X-Server
X-LiteSpeed-Cache
X-Vhost
X-Varnish-Cache
Grace
X-Amz-Version-Id
Cf-Edge-Cache
X-Dispatcher
Allow
EagleId
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
X-Page-Speed
Accept-CH
X-Nginx-Cache-Status
X-WebKit-CSP
X-Aws-Lambda-Call-Status
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
Cf-Railgun
X-Host
X-Node
X-OneAgent-JS-Injection
X-Pingback
X-Cache-Spec
X-Backend-Server
X-Akam-SW-Version
X-Server-Id
Surrogate-Control
Request-Id
X-Cache-Lookup
Accept-CH-Lifetime
X-Response-Time
EagleEye-TraceId
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Readtime
Content-Location
X-HW
X-Content-Security-Policy-Report-Only
X-Cloud-Trace-Context
Rating
X-Application-Context
X-Trace
X-Url
Fastly-Restarts
X-WebKit-CSP-Report-Only
X-Clacks-Overhead
X-Nginx-Upstream-Cache-Status
X-CST
X-Ruxit-Js-Agent
X-MS-InvokeApp
X-Edge
X-Amz-Server-Side-Encryption
X-ESI
X-Mod-Pagespeed
X-Rack-Cache
X-TtlSet
X-Vname
X-PC
X-Content-Type
X-B3-TraceId
Edge-Control
Cf-Apo-Via
X-Country
X-Vcap-Request-Id
X-FastCGI-Cache
X-Oneagent-Js-Injection
Accept-Ch-Lifetime
X-Akamai-Path-Stats
X-Mcache
Verso
X-D2id
X-GitHub-Request-Id
X-Ttl
Xkey
Cache-Tag
Service-Worker-Allowed
X-Powered-By-Plesk
X-Kinja-Revision
X-Use-Magma
X-Cdn-Fetch
X-Exp-Id
X-Kinja-Server
X-Kinja
X-Kinja-Build
X-GoogleNews-Bot
X-Exp-Variant
X-Amz-Rid
X-Server-Name
X-Navigation-Version
X-Abt-Application-Version
RTSS
X-VARITI-CCR
X-Client-IP
X-Version
X-Upstream
X-ECACHE
X-Cnection
X-Ac
X-Varnish-TTL
X-Cached
X-Element-Page-Cache
Arr-Disable-Session-Affinity
X-Ruxit-JS-Agent
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Instrumentation
Permissions-Policy
X-SharePointHealthScore
SPRequestGuid
X-Dw-Request-Base-Id
X-RateLimit-Remaining
X-Px
SPRequestDuration
SPIisLatency
Display
X-Middleton-Display
X-Sol
Pagespeed
X-Cache-TTL
X-NWS-LOG-UUID
Public-Key-Pins
X-Country-Code
X-Middleton-Response
Response
X-Midtier
X-Cache-Key
X-Kinsta-Cache
X-Edge-Location-Klb
X-Ser
X-Forwarded-For
Content-MD5
X-DataDome
X-Goog-Hash
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-NF-Request-ID
X-Correlation-Id
X-Shield-Request-Id
Access-Control-Request-Method
X-Jurisdiction
X-HP-Webp
X-HP-Trace-Id
X-MSEdge-Ref
X-RateLimit-Limit
X-ORACLE-DMS-ECID
Front-End-Https
X-ORACLE-DMS-RID
MRF-Tech
Mrf-Cache-Status
X-B3-TraceId-Primal
X-Recruiting
X-Daa-Tunnel
X-T
MicrosoftSharePointTeamServices
AR-ATIME
Edge-Cache-Tag
AR-CACHE
AR-PoweredBy
AR-SID
AR-Request-ID
TP-Cache
TP-L2-Cache
Nginx-Cache
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Browser-Type
X-Webkit-Csp
X-Mg-S
X-Accel-Expires
X-Content-Digest
TCN
X-Grace
X-Powered-CMS
X-Hits
X-Request-Processing-Time
X-Request-Received
X-Amzn-Trace-Id
X-HS-Combine-CSS
X-HS-Cache-Config
X-HS-Hub-Id
X-HS-Content-Id
Server-Node
Filters
Server-Name
MS-Author-Via
Fastcgi-Cache
X-Id
X-Geo-Country
Count-Hit
X-XRDS-Location
X-Fastly-Request-Id
Accept-Ch
X-Ua-Browser
X-Distributor
X-Origin-Server
X-Ezoic-Cdn
X-Frontend
Filterid
X-PressLabs-Stats
Cross-Origin-Opener-Policy
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-LLID
S
X-Forwarded-Proto
Payment
X-Request-Handler-Origin-Region
X-Page-Id
X-Microsite
X-Seen-By
X-Language
X-Git-Hash
X-LB-Cache
Charset
Host
X-FB-Debug
X-F-Cache
X-Protected-By
X-B3-Sampled
X-Ratelimit-Reset
X-ASPNET-VERSION
X-Amz-Meta-S3cmd-Attrs
X-VCache
X-Rid
X-Cluster-Name
Cache-Status
X-COUNTRY
Surrogate-Key
X-Www-Served-By
Cache-Tags
X-Logged-In
Access-Control-Allow-Method
X-Upgrade-Enabled
X-Origin-Cache
X-DIS-Request-ID
X-Ab
X-Varnish-Backend
Realpath
Retry-After
X-Az
X-AppVersion
Alternate-Protocol
X-Source
X-Activity-Id
Accept-Charset
X-Amz-Replication-Status
X-NGENIX-Cache
Cleartype
X-Cache-Age
Paypal-Debug-Id
DC
X-Type
X-Request-Guid
X-Varnish-Grace
X-Aspnet-Duration-Ms
X-Wix-Request-Id
X-Route-Name
X-Providence-Cookie
X-Template
X-Is-Crawler
X-Flags
X-App-Environment
X-Envoy-Decorator-Operation
X-Tb
X-Signature
X-B-Cache
X-Hostname
X-TT
X-Revision
X-B
X-DynaTrace
ServerID
X-Contextid
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
Frame-Options
X-Trace-Id
X-Cache-Rule
X-Fastly-Request-ID
X-Drupal-Cache-Tags
X-Node-Name
X-Tt-Trace-Host
Pinterest-Generated-By
X-Pinterest-Rid
X-Tt-Trace-Tag
Pinterest-Version
Refresh
X-Fastcgi-Cache
Cross-Origin-Resource-Policy
Amp-Access-Control-Allow-Source-Origin
X-Goog-Stored-Content-Encoding
X-GUploader-UploadID
X-Goog-Storage-Class
X-Goog-Generation
Referer-Policy
X-Goog-Metageneration
X-Goog-Stored-Content-Length
X-Proxy
X-Load-Cache
X-Mobile
X-Debug
Node
X-Content-Options
X-EdgeConnect-Cache-Status
NGB
X-Original-Request-Id
X-Response-Served-From
Viewport
X-Cache-Control
X-XRDS-LOCATION
Akamai-GRN
X-Varnish-Server
X-Content-Powered-By
X-Instance
X-Cache-Time
X-NYM-Debug-Backend
X-N
X-Varnish-Age
Country
X-Magnolia-Registration
X-Page-View
X-Framework
X-G
X-Is-Bot
X-Adobe-Loc
X-Adobe-Content
X-Debug-IsPreview
X-Whom
Uber-Trace-Id
X-Debug-IsConnected
X-Rendered-As
X-Yottaa-Optimizations
X-RemovedCookies
X-Status
X-Real-IP
Content-Disposition
X-ProcessESI
X-Yottaa-Metrics
X-Cacheable-TTL
X-Akamai-Request-ID2
X-Servername
X-User-Agent
Url
Srv
Access-Control-Request-Headers
X-Cache-Grace
X-L-Path
X-Environment-Context
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-Jobs
X-Mid
X-Cache-Expired-At
X-Cache-TTL-Remaining
Healthy
X-Via-JSL
Countrycode
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-Tumblr-User
X-Rule
X-CDN-Forward
X-Cache-Operation
X-Cache-Hit
X-Backend-Name
X-Unique-Id
X-Drupal-Cache-Contexts
X-APP-VERSION
Version
X-TTL
X-Debug-Info
Accept-Language
X-Oracle-Dms-Ecid
X-Akamai-Edgescape
X-Oracle-Dms-Rid
X-Litespeed-Cache
Section-Io-Cache
X-ECache
X-VC-Cache
X-Cache-Action
X-Mg-Request-UUID
X-Http-Reason
X-IPLB-Instance
X-HTML-Minification-Powered-By
X-IPLB-Request-ID
Content-Secure-Policy
X-Server-ID
Protected
X-Tt-Logid
X-Generation-Time
X-Hosted-By
X-Varnish-Ttl
X-FW-Type
X-FW-Static
X-Tec-Api-Origin
X-Tec-Api-Root
X-FW-Hash
X-FW-Dynamic
X-FW-Serve
Server-Info
Xserver
X-Tec-Api-Version
X-FW-Server
X-Azure-Ref
Backend
X-Time
X-Generated-By
X-RN-RSRV
X-Storage
Ms-Operation-Id
X-UPSTREAM-Address
Meta-Geo
MS-CV
X-RTag
X-Amzn-RequestId
X-Cache-Status-Check
X-Device-Type
X-Amz-Apigw-Id
X-Proto
X-Hl-Ver
Azure-InstanceId
X-Cache-Server
X-Cms-Context
X-Format
X-Access
Azure-RegionName
Webcakes-App-Name
Webcakes-App-Version
X-Handled-By
X-OCL
Liferay-Portal
X-Varnish-Cache-Hits
X-Section
X-PCL
X-Origin-Hint
TWC-Privacy
Webcakes-Region
TWC-Locale-Group
X-R9-Blue-Green-Version
GEO-INFO
Azure-Version
Property-Id
TWC-Connection-Speed
TWC-GeoIP-Country
TWC-GeoIP-LatLong
TWC-Device-Class
Azure-SiteName
Azure-SlotName
X-JoinUs
X-Server-W
X-Provided-By
X-Labrador-Cache-Channel
X-Mode
X-AWS-Id
X-Adobe-Source
CF-IPCountry
Web-Mar-Node
X-Proxy-Cache-Status
X-VWS-Id
X-Sql-Count
X-Say-TTL
X-PHP-Host
X-SayCDN-TTL
X-SaId
X-Varnish-Hostname
Onion-Location
X-Varnishpool
X-Dc
X-Mobile-URL
X-No-Session
X-Redis-Cache
X-LJ-Flow-ID
X-SRV
X-Say-Cacheable
X-Api-Version
X-Sql-Duration-Ms
X-Via-Fastly
Mn-Server-Ip
X-BYPASS-REASON
X-Xfnlog-Site
X-FireWall-Port
Cache-Name
X-Web-Node
X-Restarts
X-UA-Device-Type
Selected-Fe
X-FB-TRIP-ID
X-Timing-Wait
X-GeoCode
X-GeoCountry
X-Ms-Request-Id
X-Ms-Version
X-Detected-As
X-PHP-Backend
X-Request-Time
DB-Nickname
X-Cache-Type
X-ProxyCache-Status
X-ProxyCache-Key
X-Locale
X-Proxy-Build
CDN-Cache
X-Site-Version
CDN-PullZone
CDN-EdgeStorageId
CDN-CachedAt
CDN-RequestCountryCode
CDN-RequestId
X-Skip-Cache
CDN-Uid
Locale
X-App-Server
X-Region
X-Cache-Host
X-Varnish-Beresp-Grace
Eomportal-Instance
X-Content-Age
X-Forwarded-Host
X-Edge-Location
X-DynaTrace-JS-Agent
X-Urbn-Context-Path
X-Urbn-Site-Id
X-Proxied
X-Sorting-Hat-ShopId
X-Shopify-Stage
Apigw-Requestid
WP-Super-Cache
X-Extlb
X-ShopId
X-ServerID
X-Sorting-Hat-PodId
X-Routing-Service
X-Zipkin-Id
X-Alternate-Cache-Key
X-ShardId
X-Storefront-Renderer-Rendered
X-Reqid
X-Tid
X-Vgn-Hpd-Reason
X-Nginx-Cache-Key
X-WP-CF-Super-Cache
X-Amzn-Remapped-Content-Length
X-TIME
X-WP-CF-Super-Cache-Cache-Control
S-Rt
X-LSADC-Cache
X-Newrelic-Synthetics
X-Content
X-TNCMS
X-Loop
X-Cache-Enabled
X-Pubstack
Load-Balancing
Xet-Cookie
X-Ua
X-Soup
X-Tumblr-Pixel-2
X-Cdn
X-Origin-TTL
X-Origin-CC
X-B3-Traceid
X-Zen-Fury
X-TA-CDN-Provider
X-Uri
X-Cache-NGX
From-Origin
X-Origin-Date
X-Cache-Debug
X-MP-GENERATED-AT
X-Service
Fastcgi-Useragent
X-Aspnetmvc-Version
X-Ratelimit-Remaining
X-Correlation-ID
X-Varnish-Hits
Source
X-UUID
X-Webkit-CSP
ServedBy
Origin
X-GEO
X-NewRelic-App-Data
X-Human
X-Nginx-Cache
X-App-Version
Cache
X-Cache-Tags
X-Rewrite-Enabled
Upgrade-Insecure-Requests
SD-X-WS
Fastly-Drupal-HTML
X-Cluster
Rip
BehaviorPad-Version
X-Varnish-Beresp-Ttl
X-ScT
Rendered-Blocks
MD5-Digest
Host-ID
X-Cached-By
WPO-Cache-Message
X-Ratelimit-Limit
WPO-Cache-Status
Mime-Version
X-S
X-A-Wwc
X-A-Dgt
X-D
X-Parent-Response-Time
X-Rojux
X-Connection-Hash
X-SRCache-Key
X-Aed
X-B-Cookie
Sslversion
X-ARC
X-Application
X-AK-Request-ID
Xc-Version
X-TIM-N
X-Processor
X-PBS-Appsvrname
X-A-Dcw
X-Cache-NE
X-S-Cookie
A
X-BCube-Filmed-By
Cross-Origin-Window-Policy
X-Bc-Bl
X-Shop-Environment
X-Ec-Fail
X-NAPM-TraceId
X-Orig-Expires
X-Destination
X-Forwarded-Path
Expiry
T-Server
X-Vdms-Version
X-User
Surrogated-Key
Lang
X-Vdms-Path
DCR-Processing-Time-Ms
DCR-Decision-By
X-VG-WebCache
Meta-Geo-Continent
X-External-Request-Id
Odigeo-Trace-Id
X-FW-Version
X-Ec-GeoHdr
Ngx.Var.Host
X-A-Ccd
X-Tenant
X-Developer
Cdncip
Cdnsip
X-A
X-A-Dam
X-Cluster-Node
Webserver
X-Request-Host
X-Tumblr-Pixel-3
OT-Force-Account-Verify
X-Gdpr
Gh-Request-Id
Redirect-Candidate
X-Aicache-OS
X-Served-From
Release
X-Origin-Time
X-Nyt-Route
X-GeoIP-City
X-Accel-Buffering
X-Worker
X-Sucuri-ID
X-Sucuri-Cache
X-Cache-Remote
X-Thinkindot-L3
X-WP-CF-Super-Cache-Active
Thinkindot-Control
X-Core-Value
X-INCAP-ABP
X-CMSURLCustom
X-Cdn-Srv
X-Pass-Why
X-Developers
X-Has-Esi
X-Geo-Header
X-Generated-On
X-Is-Gdpr
X-RCS-CacheZone
TDXMobile
X-Level-Front-Cache
Fastly-Backend-Name
AKAMAI
Thinkindot-CacheControl
X-HS-Content-Campaign-Id
X-JWT-State
X-Auto-Login
Thinkindot-CacheControl-Type
X-Optimistic-Header
X-Sigma
L
L5d-Success-Class
Machine
Mail-Subject
Kp-EeAlive
IsBot
Ha-Gx-Prefs
HA-Ipaddr
X-SplitTest
Is-Eu
Memcached
Mobile-Detection-Method
Origin-EX
Platform
Producers
Req-Svc-Chain
Origin-CC
X-Sigma-Backend
X-SIPLIST1
NGX
NM-Fastcgi-Cache
Servername
X-Cache-Bucket
X-GeoIP
X-Fmm-Version
X-Gzip
X-Rocket-Build-Number
X-Request-URI
X-Fetched-On
X-FC-Vary-Parameters
X-Rocket-Nginx-Serving-Static
X-Ec-Custom-Error
X-Epic-Correlation-Id
X-Esi-Check
X-Eu-Site
X-Irp-Debug
X-Loc
X-Origin-Response-Time
X-NodeID
X-Proxy-Cache-Info
X-Pool
X-Policy
X-NCache
X-Mvc-Supplant-Cachable
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-Qloud-Router
X-Minions-Version
X-DPWN-IS-SECURE
X-Device-Os
Wxu-Next-Region
Wxu-Next-Hostname
X-Ad-Defer-Variation
X-AOL-HN
X-SB
Wxu-Next-Commit
Web-Mar-Region
Tube-Got-Eval
Tube-Get-Contents
Tube-Got-Results
Tube-Return
We-Hiring
X-ATG-Version
X-Azure-Ref-OriginShield
X-Clara-WADP
X-Ckpd-Fst-Backend
X-Csrf-Jwt
X-DefElseHash
X-DefHash
X-CGP
X-S-Maxage
X-BBC-Edge-Cache-Status
X-Bip
X-Cache-Id
X-Cache-Info
Traceparent
Candidate-Md5Url
Canary
Cache-Host
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
X-Platform-Server
Click-Count-Action-Start
Cluster
X-Var-Ttl
Click-Count-Error
X-VG-TLSProxy
Apple-News-Services-Host
X-Varnish-CookieHashed-On
X-Varnish-Beresp-Status
X-Variation
X-Varnish-CookieINHashed-On
X-Thanos
Apple-News-Services-Handled
Adler-Geo
X-Varnish-Remaining-TTL
X-Viewer-Country
CloudFront-Viewer-Country
Decoy-Debug-Status
Decoy-Debug-Key
Decoy-Debug-TTL
X-VServer
Environment
Fastly-SIE
Fastly-GeoIP-CountryCode
X-Wix-Viewer-Type
X-WADP-Cache
Datacenter
Fastly-SWR
Fastly-SSL
X-Tx-Id
WebServer
VNS-Age
X-Origin
User-Cache-Control
X-Dispatcher-Number
X-IPS-LoggedIn
DSUID
X-Gen-Mode
X-Clientip
X-Forwarded-Site
X-Block-Status
VNS-Cache
X-Hnp-Log
Server-Ext
CDCHOST
X-Mvc-Supplant-OutputCached
Server-Hostname
CPC-Age
CPC-Cache
X-Owner
Sever-Int
X-Debug-Cache
Server-Host
X-Udemy-Cache-App-Namespace
X-Sn-Servicetimems
Time
X-Gamma-Serve
X-Fastly-Backend
Memory
X-Presslabs-Stats
X-Datadog-Trace-Id
X-CacheTTL
X-Cdn-Origin
X-Datadog-Parent-Id
X-SVT-ORM-RULES
X-URL
X-Datadog-Sampling-Priority
X-Branch-Name
X-Dispatch
X-Gateway-Cache-Key
X-SVT-ORM-VERSION
Country-Code
Vix-Hermes-Req-Id
V-Age
X-Hash
X-Planisys-CDN-Rules
X-Akamai-Transformed
X-Region-Sid
X-LB-NoCache
Svr
X-Core-Mission
X-V-Cache
State
X-Planisys-CDN-Cache
Ec-Rule-Version
X-Gateway-Cache-Status
X-Slack-Backend
X-Planisys-CDN-TTL
X-Scale
Cmstype
X-Gateway-Skip-Cache
X-Scheme
X-Gateway-Request-Id
Cmsid
LB
X-Edge-Pop
Sid
Pics-Label
X-Up
X-CSRF-Token
X-Nf-Request-Id
X-Tb-Optimization-Total-Bytes-Saved
Ssr
HostName
X-B3-Spanid
X-Newrelic-App-Data
Request-ID
X-Req
X-VC
AMP-Access-Control-Allow-Source-Origin
X-NGINX-Cache
X-Servedbyhost
X-ND-Cache
My-App
X-Generated-In
Env
X-ZONE
X-Cs
X-Refresh
X-Lambda-Id
True-Client-Country-4JS
X-Wa
CacheControlHeader
X-Vc
Cache-Tv-Group
X-WA-Info
Fastcgi-Cache-TTL
X-B3-SpanId
X-Via-Poph
X-Via-Popn
X-Via-Popv
GeoIp-Country-Code
X-Datadome
X-Via-NSCOPI
X-Zone
X-GG-Cache-Date
True-Client-IP
Server-ID
X-Op-Id-All
X-Session-Fingerprint
SID
Hostname
X-PX
X-EC-Lua
X-Rebelmouse-Surrogate-Control
X-Origin-Expires
X-ID
X-Pod-Name
X-Rebelmouse-Cache-Control
X-Release
X-Fastly-Cache
Cache-Hits
X-Trace-ID
X-CACHE-AGE
X-GeoIP-Country-Code
X-GeoIP-Region-Code
X-Xrds-Location
X-LB-ID
X-Fpc
X-VCL-Version
X-NWS-UUID-VERIFY
X-TX-ID
WWW-Authenticate
X-Webkit-CSP-Report-Only
X-CSRF-TOKEN
X-TH-Server
X-Buckets
X-CACHE-KEY
X-Accel-Expires-Debug
X-Old-Content-Length
X-Date
X-Cache-Date
X-MSEdge-Flight
X-Ig-Push-State
X-MSEdge-Features
X-RAMCache
X-Srv
X-TRACE-ID
Resin-Trace
X-NC
CDN
X-HS-Status
X-Endurance-Cache-Level
X-DC
Fastly-Drupal-Html
X-Conf
X-Microcachable
X-Dmc
X-Varnish-Beresp-TTL
X-RateLimit-Reset
X-CS
Section-Io-Origin-Time-Seconds
Powered-By
Section-Io-Origin-Status
X-Webstats-RespID
Tcn
Path
X-Vcl-Version
X-Location
X-MCACHE
X-Lb-Id
Section-Io-Id
Section-Origin-Responded
X-API-Version
Magicmarker
X-Director
X-DataCenter
X-Akamai-Pragma-Client-IP
X-FPC
True-Client-Ip
X-Contensis-Viewer-Groups
X-Varnish-Authentication
X-LiteSpeed-Cache-Control
X-CLOUD-TRACE-CONTEXT
Yjs-Id
X-Cache-Ttl
X-Cache-ASPX
X-Check-Cacheable
X-Alfa-Service
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-Test
X-Datacenter
GeoIP-Country-Code
X-Esi
X-Geo
X-Be
X-Vercel-Id
X-Cache-Backend
X-Mly-Id
Server-Id
X-Cache-Expires
Proxy-Connection
M-TraceId
X-Via-CDN
X-Vercel-Cache
FSS-Cache
X-WA
Lb
X-PERF
X-Cc-Via
X-ApacheServer
YJS-ID
X-Hyper-Cache
User-Agent
X-Via-PopV
X-Response-By
X-Server-IP
X-We-Are-Hiring
Pramga
X-Micro-Cache
X-ServedByHost
X-Via-PopH
X-Via-PopN
Cdn
ENV
X-Dw-Trace-Id
X-Cdn-Forward
X-M-Log
X-Info
X-Frame-Option
X-Client-Ip
X-M-Reqid
X-CF-Lambda-Version
XServer
X-HA-Backend
Uri
HIT
XM
X-CF-Lambda-Fn
X-AIR-PT
Sm-Log-Id
X-Service-Response-Time
X-Edge-POP
Location
X-Traceid
Srvid
Swift-Performance
PFcat
X-Instance-Name
X-HN
Dnion-Transfer-Encoding
Tracecode
X-App
X-LI-UUID
X-Qnm-Cache
X-LI-Proto
X-Li-Pop
X-Li-Fabric
X-TrackingId
Geoip-Latitude
X-UA
X-From
X-FL-EDGE
Locid
X-Akamai-ERRuleID
X-VarnishDD-TTL
X-LiteSpeed-Tag
X-TT-LOGID
X-Akamai-ERPolicy
X-RPM
X-DI
X-DSS
Cache-Key
X-DB
X-Oss-Request-Id
X-Oss-Object-Type
CF-Cached-On
X-Oss-Hash-Crc64ecma
X-RSL
Cneonction
X-RPS
X-DW
X-Air-Source
X-Air-Trace-Id
X-Oss-Storage-Class
X-Air-Hostname
C-Via
N-Cache
Nginx-CQVIP
X-Platform
PICS-Label
X-Fastly-Backend-Reqs
CountryCode
X-Oss-Server-Time
Ohc-File-Size
X-Wp-Cf-Super-Cache-Cache-Control
X-Wp-Cf-Super-Cache
NtCoent-Length
X-Request-Url
X-Platform-Processor
X-LAGOON
X-Platform-Router
X-Platform-Cluster
X-Cache-Proxy
Timeexpire
Create-Date
X-SD-PageType
X-Conten-Type-Options
X-HostName
X-Cdn-Request-ID
X-CF-Powered-By
Wpo-Cache-Message
Esi-Enabled
Wpo-Cache-Status
Vha6-Origin
X-Lb-Nocache
X-Fastly-Cache-Hits
X-Ips-Loggedin
Wp-Super-Cache
X-Cache-Ngx
X-Air-Pt
X-Litespeed-Cache-Control
Warning
X-Newegg-Index
X-Newegg-Flow
X-NFL-Dma
X-NFL-Geo
X-Nerd
X-N-OperationId
X-Matched-Rule
X-Matome-Cached
X-MTS-Cache
X-Ee-Request-Date
X-NS-Authorization
X-NXG
X-OVcl
X-OVcl-Cache
X-PageType
X-Paywall
X-Origin-Ops
X-Onedio-Env
X-Loadbalancer
X-Nyt-Data-Last-Modified
X-Odoo-Frontend
X-Okws-Version
X-Ntj-Investigation-Id
X-Keep
X-Full-Ttl
X-GG-Cache-Status
X-Git-Commit
X-Global-Transaction-ID
X-Fstrz
X-ETag
X-F-Status
X-Farm
X-PG-ACCESS
X-Fastly-Is-Edge
X-GoCache-CacheStatus
X-Group
X-Ee-Request-Id
X-Kebab
X-Kebabable
X-Eventloop-Lag
X-Ittl
X-Is-SSL
X-Header-Sub
X-IBD-Cache
X-Eid
X-IBD-SID
X-LbNode
X-SSLProxy
X-Vary-Devices
X-V2-Infrastructure
X-Ver
X-Wag-Acs
X-Waitingroom
X-Utime
X-User-Auth
X-Tried-To-Kebabify
X-True-Client-Ip
X-U-Cache
X-Upstream-State
X-Web-Hosting
X-WP-Bypass
X-UP
X-Fastly-Country-Code
X-Ha-Backend
X-Request-URL
X-Ee-Origin
X-B3-Parentspanid
XV-H
X-WSR2
X-Xms-Page-Cache-Actions
X-YSpaceId
XV-Cache
X-Toujours-Debout-Location
X-Toujours-Debout-Branch
X-Route
X-Request-Origin
X-Route-Akamai
X-Ruby
X-Save-Cache
X-Render-Time
X-Render-Method
X-Pver
X-R-Cache
X-Reboot
X-Redis
X-Server-L
X-ServiceName
X-SVR-IIS
X-Svr-Proxy
X-Test-Nginx-Ingress
X-Timestamp
X-Stack-Name
X-Square
X-Sh
X-Site
X-Slack-Shared-Secret-Outcome
X-SMP-JWT
X-PGF-Deflate
Npm-Remaining
Npm-Cost
NLCacheNote
Ns
Ns-Ua
OK-Edge-Date
Ok-Cache-Status
Nikkei-App-Version
NB-ESI
HServer
H1
HTTPProtocol
Is-Https
Joe-X
Ok-Edge-Key
Origin-Site
Served
Selected-Route
Service-Uuid
SFRVia
Shieldsquare-Response
Scheme
Rt-Proxy-Cache
Proxy-Cache
Panzer-Cache-Control
RawURL
Region
Request-Uuid
Ec-Policy-Id
Deeplink
DynaTrace
SRV
WZWS-RAY
X-B3-ParentSpanId
X-ElasticPress-Query
X-Mg-Cache
Fastcgi-Cache-Ttl
Req-ID
X-CUA
X-PAYTM-SRV-ID
On-Server
Hit
Fastcgi-X-Cache-Version
X-Yottaa-OS
X-IN-APIGATEWAY
Cf-Locale
Cf-Device-Type
Cf-Wrk
Cluster-Host
CMS-200
Cdn-Country-Code
Cachekey
X-Serial
X-IN-APIGATEWAYSSL
X-Th-Server
Akamai-X-Url
Cache-Stat
SII
Store-Cloud-Cache
X-Cache-NPR
X-Cache-Length
X-Cache-Reason
X-Cache-ReqUri
X-CacheVersion
X-Cache-Response
X-Cache-IsMobileDevice
X-Cache-Cookie
X-Backend-TTL
X-AspNetWebPages-Version
X-Backside-Transport
X-BeanStalkRole
X-BeanStalkStage
X-CDN-Pop
X-CDN-Pop-IP
X-Developed-By
X-Delivery
X-Doge
X-DT-Node
X-Edge-IP
X-Dehri-Date
X-Dcm-Pdtf
X-Cms-Device
X-Cf-Node-Idx
X-Coindesk-Cache
X-Colour
X-Container-Uri
X-ASF-Cache
X-ARRRG1
TWC-Unit
TWC-Subs
Uniqueid
Userver
X-77-NZT
Vttl
TWC-PATH-LOCALE
TWC-AK-Req-ID
T-Request-Id
Sw
Technodrome
Time-Cloud-Cache
Ttl
X-77-NZT-Ray
X-Accel-Version
X-Amz-Meta-Cb-Modifiedtime
X-Akamai-Native
X-Apache-Server
X-Ar-Stats
X-Arena-Request-Id
X-Akamai-DeviceType
X-Akamai-DeviceOS
X-Accepted-Language
X-Accepted-Fulllang
X-Accor-Asset
X-AEO-Platform
X-Akamai-CacheKeyMod
X-Ee-Generated-By