Threat Level: green Handler on Duty: Guy Bruneau

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
Strict-Transport-Security
X-Frame-Options
X-Content-Type-Options
Link
Last-Modified
CF-Cache-Status
Cf-Request-Id
CF-RAY
Accept-Ranges
ETag
Expect-CT
Pragma
X-Powered-By
X-Cache
Via
Age
X-XSS-Protection
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
X-Xss-Protection
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-FRAME-OPTIONS
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Request-Id
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-Adblock-Key
X-AspNet-Version
X-Permitted-Cross-Domain-Policies
Alt-Svc
X-Runtime
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Cache-Status
X-Check
X-Generator
X-DNS-Prefetch-Control
X-Request-ID
X-Cacheable
X-Iinfo
X-Envoy-Upstream-Service-Time
Feature-Policy
Timing-Allow-Origin
X-Content-Security-Policy
Status
X-Drupal-Dynamic-Cache
Content-Encoding
Access-Control-Expose-Headers
X-AspNetMvc-Version
X-CDN
P3p
Upgrade
X-Ua-Compatible
Access-Control-Max-Age
CF-Ray
X-Dns-Prefetch-Control
X-Via
X-Robots-Tag
X-Cache-Group
X-UA-Device
Server-Timing
Keep-Alive
Request-Context
X-AH-Environment
X-Turbo-Charged-By
X-Amz-Request-Id
X-Proxy-Cache
X-Backend
X-Amz-Id-2
X-Age
X-Ws-Request-Id
Host-Header
X-Hacker
X-Server-Powered-By
X-Rq
X-Server
X-Vhost
X-LiteSpeed-Cache
X-Varnish-Cache
X-Amz-Version-Id
Grace
Cf-Edge-Cache
X-Dispatcher
Allow
EagleId
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
X-Page-Speed
Accept-CH
X-Nginx-Cache-Status
X-WebKit-CSP
X-Aws-Lambda-Call-Status
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
Cf-Railgun
X-Node
X-Host
X-OneAgent-JS-Injection
X-Pingback
X-Cache-Spec
X-Backend-Server
X-Akam-SW-Version
X-Server-Id
Surrogate-Control
Request-Id
X-Cache-Lookup
Accept-CH-Lifetime
X-Response-Time
EagleEye-TraceId
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Readtime
Content-Location
X-HW
X-Content-Security-Policy-Report-Only
X-Cloud-Trace-Context
X-Application-Context
Rating
X-Trace
X-Url
Fastly-Restarts
X-WebKit-CSP-Report-Only
X-Clacks-Overhead
X-Nginx-Upstream-Cache-Status
X-CST
X-Ruxit-Js-Agent
X-MS-InvokeApp
X-Edge
X-Amz-Server-Side-Encryption
X-Rack-Cache
X-Mod-Pagespeed
X-ESI
X-Country
X-PC
X-Vname
X-TtlSet
X-Content-Type
Cf-Apo-Via
Edge-Control
X-Vcap-Request-Id
X-FastCGI-Cache
X-B3-TraceId
X-Oneagent-Js-Injection
Accept-Ch-Lifetime
X-Akamai-Path-Stats
X-Mcache
X-D2id
X-Ttl
Verso
Xkey
X-GitHub-Request-Id
X-Exp-Id
X-Kinja-Server
Cache-Tag
X-Kinja-Revision
X-Use-Magma
X-Exp-Variant
X-GoogleNews-Bot
X-Kinja
X-Cdn-Fetch
X-Kinja-Build
Service-Worker-Allowed
X-Powered-By-Plesk
X-Amz-Rid
X-Server-Name
X-Navigation-Version
RTSS
X-VARITI-CCR
X-Abt-Application-Version
X-Ac
X-Client-IP
X-Version
X-Varnish-TTL
X-Upstream
X-Cnection
X-ECACHE
X-Element-Page-Cache
X-Cached
Arr-Disable-Session-Affinity
X-Ruxit-JS-Agent
Permissions-Policy
X-Kraken-Loop-Name
X-Instrumentation
X-Server-Lifecycle-Phase
X-RateLimit-Remaining
SPRequestGuid
X-SharePointHealthScore
X-Dw-Request-Base-Id
X-Px
X-Sol
X-Middleton-Display
Display
SPRequestDuration
X-Cache-TTL
Pagespeed
SPIisLatency
X-NWS-LOG-UUID
Public-Key-Pins
X-Country-Code
X-Middleton-Response
Response
X-Midtier
X-Cache-Key
X-Kinsta-Cache
X-Edge-Location-Klb
X-Ser
X-Forwarded-For
X-Goog-Hash
X-DataDome
Content-MD5
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-NF-Request-ID
X-Correlation-Id
X-Shield-Request-Id
X-RateLimit-Limit
X-MSEdge-Ref
Access-Control-Request-Method
X-HP-Trace-Id
X-HP-Webp
Front-End-Https
X-Jurisdiction
MRF-Tech
Mrf-Cache-Status
X-B3-TraceId-Primal
X-T
X-Recruiting
AR-ATIME
AR-Request-ID
AR-SID
AR-PoweredBy
AR-CACHE
X-Daa-Tunnel
Edge-Cache-Tag
MicrosoftSharePointTeamServices
TP-Cache
TP-L2-Cache
Nginx-Cache
X-Webkit-Csp
X-Erf-Bev-Bev
X-Browser-Type
X-Erf-Bev-Bev-Is-Generated
X-Mg-S
X-Accel-Expires
X-Content-Digest
X-Grace
TCN
X-Powered-CMS
X-Hits
X-Request-Received
X-Request-Processing-Time
X-Amzn-Trace-Id
X-HS-Combine-CSS
X-HS-Cache-Config
X-HS-Hub-Id
Server-Node
X-HS-Content-Id
Filters
Server-Name
MS-Author-Via
X-Id
Fastcgi-Cache
X-Geo-Country
Count-Hit
X-XRDS-Location
X-TEC-API-ROOT
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-Fastly-Request-Id
Accept-Ch
X-Origin-Server
X-Ua-Browser
X-Frontend
X-Ezoic-Cdn
X-Distributor
Filterid
X-PressLabs-Stats
Cross-Origin-Opener-Policy
X-LLID
S
X-Forwarded-Proto
Payment
X-Seen-By
X-Request-Handler-Origin-Region
X-Page-Id
Charset
X-Microsite
X-Protected-By
X-F-Cache
X-FB-Debug
X-Git-Hash
X-LB-Cache
Host
X-Language
X-B3-Sampled
X-Ratelimit-Reset
X-Amz-Meta-S3cmd-Attrs
X-ASPNET-VERSION
X-VCache
X-Cluster-Name
X-Rid
Cache-Status
Surrogate-Key
X-Www-Served-By
Cache-Tags
X-Logged-In
Access-Control-Allow-Method
X-Upgrade-Enabled
X-DIS-Request-ID
X-Ab
X-Varnish-Backend
X-Source
X-Origin-Cache
Realpath
Alternate-Protocol
Retry-After
Accept-Charset
X-Activity-Id
X-AppVersion
X-Az
Cleartype
X-COUNTRY
DC
X-Amz-Replication-Status
Paypal-Debug-Id
X-NGENIX-Cache
X-Cache-Age
X-Type
X-Aspnet-Duration-Ms
X-App-Environment
X-Request-Guid
X-Route-Name
X-Providence-Cookie
X-Is-Crawler
X-Flags
X-Varnish-Grace
X-Wix-Request-Id
X-Envoy-Decorator-Operation
X-B-Cache
X-Template
X-Tb
X-Signature
X-TT
X-B
X-Revision
X-Hostname
X-DynaTrace
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
ServerID
X-Contextid
Frame-Options
X-Cache-Rule
X-Fastcgi-Cache
X-Drupal-Cache-Tags
X-Node-Name
X-Tt-Trace-Tag
X-Fastly-Request-ID
X-Tt-Trace-Host
X-Pinterest-Rid
Pinterest-Generated-By
Pinterest-Version
Cross-Origin-Resource-Policy
Refresh
Amp-Access-Control-Allow-Source-Origin
X-Trace-Id
X-GUploader-UploadID
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
Referer-Policy
X-Proxy
X-Load-Cache
X-Debug
X-Mobile
Node
X-Content-Options
X-EdgeConnect-Cache-Status
X-Response-Served-From
NGB
X-Varnish-Server
X-Original-Request-Id
Viewport
X-Cache-Control
X-Content-Powered-By
X-Varnish-Age
Country
X-Whom
Akamai-GRN
X-XRDS-LOCATION
X-N
X-Instance
X-Magnolia-Registration
X-NYM-Debug-Backend
X-Debug-IsConnected
X-Debug-IsPreview
X-Cache-Time
X-Is-Bot
X-Framework
X-Adobe-Loc
X-G
X-Page-View
X-Rendered-As
Content-Disposition
X-Status
Uber-Trace-Id
X-Adobe-Content
X-Cache-Grace
Url
X-Akamai-Request-ID2
X-Environment-Context
X-Cacheable-TTL
X-RemovedCookies
X-Servername
X-User-Agent
X-Real-IP
X-ProcessESI
X-L-Path
Access-Control-Request-Headers
X-Yottaa-Optimizations
X-Yottaa-Metrics
Srv
X-Jobs
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-Cache-Expired-At
X-Via-JSL
X-Cache-TTL-Remaining
Healthy
X-Mid
X-Tumblr-Pixel-1
X-Tumblr-User
X-Tumblr-Pixel
X-Cache-Hit
X-Rule
X-Tumblr-Pixel-0
X-CDN-Forward
X-Cache-Operation
X-Backend-Name
X-APP-VERSION
Countrycode
X-Unique-Id
X-Drupal-Cache-Contexts
X-TTL
Version
X-Debug-Info
Accept-Language
X-Akamai-Edgescape
X-Litespeed-Cache
X-Cache-Action
Section-Io-Cache
X-VC-Cache
X-Http-Reason
X-ECache
X-Mg-Request-UUID
X-B3-Traceid
Content-Secure-Policy
Protected
X-Tt-Logid
X-IPLB-Request-ID
X-Hosted-By
X-IPLB-Instance
X-Server-ID
X-Generation-Time
X-HTML-Minification-Powered-By
Xserver
X-Varnish-Ttl
X-FW-Server
X-FW-Hash
X-FW-Type
Backend
X-Azure-Ref
X-Generated-By
X-FW-Serve
Server-Info
X-FW-Dynamic
X-FW-Static
X-Time
X-Storage
X-RN-RSRV
X-Cache-Status-Check
Meta-Geo
X-UPSTREAM-Address
MS-CV
X-RTag
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Oracle-Dms-Ecid
Ms-Operation-Id
TWC-Privacy
TWC-Locale-Group
X-Oracle-Dms-Rid
TWC-GeoIP-LatLong
Webcakes-App-Version
Webcakes-Region
X-Access
X-R9-Blue-Green-Version
TWC-GeoIP-Country
X-Section
X-SRV
Webcakes-App-Name
TWC-Device-Class
X-Handled-By
X-Device-Type
X-OCL
X-Cache-Server
Azure-SiteName
Azure-SlotName
Property-Id
Liferay-Portal
Azure-Version
Azure-InstanceId
Azure-RegionName
Onion-Location
X-Varnish-Cache-Hits
X-Mode
X-Cms-Context
X-Format
X-PCL
X-Origin-Hint
X-Proto
TWC-Connection-Speed
Web-Mar-Node
X-Adobe-Source
X-AWS-Id
X-Varnish-Hostname
CF-IPCountry
X-LJ-Flow-ID
X-Say-TTL
X-SayCDN-TTL
X-Say-Cacheable
X-SaId
X-App-Server
X-Locale
X-Sql-Count
X-PHP-Host
X-Sql-Duration-Ms
X-Api-Version
X-No-Session
X-Provided-By
X-FireWall-Port
X-Redis-Cache
X-Labrador-Cache-Channel
X-JoinUs
X-Server-W
X-Hl-Ver
X-Mobile-URL
X-Proxy-Cache-Status
X-VWS-Id
GEO-INFO
CDN-RequestId
Mn-Server-Ip
CDN-CachedAt
CDN-Uid
CDN-Cache
CDN-EdgeStorageId
Locale
CDN-RequestCountryCode
CDN-PullZone
DB-Nickname
X-Skip-Cache
X-Site-Version
X-UA-Device-Type
X-Region
X-ProxyCache-Status
X-ProxyCache-Key
X-Restarts
X-Urbn-Context-Path
X-Urbn-Site-Id
X-Xfnlog-Site
X-PHP-Backend
X-Web-Node
X-Via-Fastly
X-Varnish-Beresp-Grace
X-Varnishpool
X-Ms-Version
X-Request-Time
X-Detected-As
X-Edge-Location
X-Cache-Type
X-Cache-Host
Eomportal-Instance
X-BYPASS-REASON
X-FB-TRIP-ID
X-Content-Age
X-GeoCountry
X-Ms-Request-Id
X-GeoCode
X-Forwarded-Host
X-Sorting-Hat-ShopId
X-Proxied
X-Alternate-Cache-Key
X-Sorting-Hat-PodId
X-Shopify-Stage
Cache-Name
X-ShardId
X-ShopId
S-Rt
Apigw-Requestid
X-Routing-Service
X-Extlb
X-Zipkin-Id
X-ServerID
X-DynaTrace-JS-Agent
X-Storefront-Renderer-Rendered
WP-Super-Cache
X-Tid
X-Dc
X-Vgn-Hpd-Reason
X-Nginx-Cache-Key
Selected-Fe
X-Proxy-Build
X-TIME
X-Reqid
X-Tec-Api-Root
X-Timing-Wait
X-Tec-Api-Version
X-Amzn-Remapped-Content-Length
X-Tec-Api-Origin
X-WP-CF-Super-Cache-Cache-Control
X-LSADC-Cache
X-Newrelic-Synthetics
X-Loop
X-WP-CF-Super-Cache
X-TNCMS
Load-Balancing
Xet-Cookie
X-Cache-Enabled
X-Pubstack
X-Content
X-Ua
X-Cdn
X-Soup
X-Tumblr-Pixel-2
X-Uri
X-Origin-CC
X-Origin-TTL
X-TA-CDN-Provider
X-Zen-Fury
X-Service
X-Origin-Date
From-Origin
X-MP-GENERATED-AT
X-Cache-Debug
X-Cache-NGX
X-Ratelimit-Remaining
X-Correlation-ID
X-Aspnetmvc-Version
Fastcgi-Useragent
X-Varnish-Hits
Source
X-Nginx-Cache
ServedBy
X-Webkit-CSP
X-UUID
X-GEO
Origin
X-Human
X-App-Version
X-NewRelic-App-Data
Cache
X-Cache-Tags
Fastly-Drupal-HTML
X-Rewrite-Enabled
Upgrade-Insecure-Requests
X-Cluster
SD-X-WS
X-Cached-By
X-Varnish-Beresp-Ttl
Rip
Cross-Origin-Window-Policy
X-ScT
BehaviorPad-Version
Rendered-Blocks
MD5-Digest
Mime-Version
Host-ID
X-Ratelimit-Limit
Surrogated-Key
X-Orig-Expires
T-Server
X-Ec-Fail
X-Shop-Environment
X-B-Cookie
X-Parent-Response-Time
A
X-A-Dam
X-A-Ccd
Expiry
Sslversion
X-Ec-GeoHdr
X-Tenant
Cdncip
X-SRCache-Key
X-External-Request-Id
X-Forwarded-Path
Cdnsip
X-TIM-N
Ngx.Var.Host
X-NAPM-TraceId
X-Vdms-Version
X-A
Xc-Version
X-PBS-Appsvrname
X-Developer
X-Aed
Odigeo-Trace-Id
X-Rojux
X-Cache-NE
Meta-Geo-Continent
X-S
X-BCube-Filmed-By
X-S-Cookie
X-Bc-Bl
X-FW-Version
Lang
X-Vdms-Path
X-AK-Request-ID
X-Connection-Hash
X-A-Dgt
X-User
X-Destination
X-Application
X-ARC
X-Processor
DCR-Decision-By
X-D
X-A-Dcw
X-VG-WebCache
DCR-Processing-Time-Ms
X-A-Wwc
X-Cluster-Node
X-Tumblr-Pixel-3
X-Request-Host
WPO-Cache-Message
WPO-Cache-Status
OT-Force-Account-Verify
Webserver
Redirect-Candidate
Environment
X-Aicache-OS
X-Accel-Buffering
X-Served-From
X-Gdpr
X-Nyt-Route
X-Origin-Time
Gh-Request-Id
X-JWT-State
X-Core-Value
X-INCAP-ABP
X-RCS-CacheZone
X-WP-CF-Super-Cache-Active
X-Sucuri-Cache
X-Sucuri-ID
X-Thinkindot-L3
X-Worker
X-Developers
X-Is-Gdpr
X-Generated-On
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
X-HS-Content-Campaign-Id
AKAMAI
Fastly-Backend-Name
TDXMobile
X-Has-Esi
Thinkindot-Control
X-Cdn-Srv
X-CMSURLCustom
X-Level-Front-Cache
X-Auto-Login
X-Pass-Why
X-Geo-Header
X-Cache-Remote
Tube-Got-Results
Origin-EX
L5d-Success-Class
Platform
Producers
Release
Origin-CC
Machine
NGX
Mobile-Detection-Method
NM-Fastcgi-Cache
Memcached
Mail-Subject
L
Req-Svc-Chain
Web-Mar-Region
We-Hiring
Wxu-Next-Commit
Wxu-Next-Hostname
Wxu-Next-Region
Tube-Return
Tube-Got-Eval
Kp-EeAlive
Servername
Traceparent
Tube-Get-Contents
X-Ad-Defer-Variation
X-Fmm-Version
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-Request-URI
X-Rocket-Build-Number
X-S-Maxage
X-Rocket-Nginx-Serving-Static
X-Qloud-Router
X-Proxy-Cache-Info
X-Owner
X-Origin-Response-Time
X-Platform-Server
X-Policy
X-Pool
X-SB
X-Sigma
X-VG-TLSProxy
X-Varnish-Remaining-TTL
X-Viewer-Country
X-VServer
X-Wix-Viewer-Type
X-WADP-Cache
X-Varnish-CookieINHashed-On
X-Varnish-CookieHashed-On
X-SIPLIST1
X-Sigma-Backend
X-SplitTest
X-Variation
X-Varnish-Beresp-Status
X-NodeID
X-NCache
X-Clara-WADP
X-Ckpd-Fst-Backend
X-Csrf-Jwt
X-DefElseHash
X-Device-Os
X-DefHash
X-CGP
X-Cache-Info
X-Azure-Ref-OriginShield
X-ATG-Version
X-BBC-Edge-Cache-Status
X-Cache-Bucket
X-Cache-Id
X-Dispatcher-Number
X-DPWN-IS-SECURE
X-GeoIP-City
X-GeoIP
X-Gzip
X-Irp-Debug
X-Minions-Version
X-Loc
IsBot
X-Fetched-On
X-Epic-Correlation-Id
X-Ec-Custom-Error
X-Esi-Check
X-Eu-Site
X-FC-Vary-Parameters
X-AOL-HN
X-Mvc-Supplant-Cachable
Click-Count-Action-Start
Candidate-Md5Url
Canary
Is-Eu
Click-Count-Error
CloudFront-Viewer-Country
Datacenter
Decoy-Debug-Status
Decoy-Debug-TTL
Cluster
Decoy-Debug-Key
Fastly-GeoIP-CountryCode
Apple-News-Services-Handled
Apple-News-Services-Host
Ha-Gx-Prefs
HA-Ipaddr
Adler-Geo
Cache-Host
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
Fastly-SIE
Fastly-SSL
Fastly-SWR
Server-Host
X-Optimistic-Header
WebServer
X-Tx-Id
X-Var-Ttl
X-Gen-Mode
X-Bip
X-Block-Status
X-Gateway-Skip-Cache
X-CacheTTL
X-Branch-Name
X-Hash
X-Hnp-Log
X-Planisys-CDN-Cache
DSUID
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Region-Sid
X-Mvc-Supplant-OutputCached
X-Gateway-Request-Id
X-Gateway-Cache-Status
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
X-Slack-Backend
X-Datadog-Trace-Id
X-Gamma-Serve
X-Scale
X-Scheme
X-Sn-Servicetimems
X-IPS-LoggedIn
X-Gateway-Cache-Key
X-Cdn-Origin
X-Thanos
X-SVT-ORM-VERSION
X-Core-Mission
X-SVT-ORM-RULES
X-Fastly-Backend
X-V-Cache
Server-Ext
Server-Hostname
CPC-Cache
User-Cache-Control
VNS-Age
V-Age
CDCHOST
CPC-Age
Cmstype
State
Country-Code
Cmsid
Sever-Int
X-Clientip
Vix-Hermes-Req-Id
X-Forwarded-Site
X-Origin
VNS-Cache
X-Udemy-Cache-App-Namespace
X-Debug-Cache
LB
X-Presslabs-Stats
X-Dispatch
Time
Svr
X-LB-NoCache
X-Akamai-Transformed
Ec-Rule-Version
X-Up
X-URL
Memory
Sid
Pics-Label
X-Newrelic-App-Data
X-CSRF-Token
X-Nf-Request-Id
Ssr
X-Edge-Pop
X-Tb-Optimization-Total-Bytes-Saved
X-ZONE
HostName
X-B3-Spanid
X-Req
Request-ID
X-VC
AMP-Access-Control-Allow-Source-Origin
X-ND-Cache
Env
My-App
X-Generated-In
X-Servedbyhost
X-Cs
X-Via-Poph
True-Client-Country-4JS
X-Wa
X-Via-Popv
X-Lambda-Id
X-Refresh
X-Via-Popn
CacheControlHeader
X-NGINX-Cache
X-WA-Info
X-Vc
Cache-Tv-Group
Server-ID
GeoIp-Country-Code
X-Via-NSCOPI
X-Datadome
Fastcgi-Cache-TTL
X-Trace-ID
X-B3-SpanId
Hostname
X-GG-Cache-Date
SID
True-Client-IP
X-Session-Fingerprint
X-Op-Id-All
X-PX
X-EC-Lua
X-CACHE-AGE
X-Zone
X-Pod-Name
X-Origin-Expires
X-Fastly-Cache
X-ID
X-Release
X-Rebelmouse-Surrogate-Control
X-Fpc
X-Rebelmouse-Cache-Control
Cache-Hits
X-VCL-Version
X-Xrds-Location
X-LB-ID
X-GeoIP-Region-Code
X-GeoIP-Country-Code
X-CSRF-TOKEN
X-NWS-UUID-VERIFY
X-TX-ID
X-Webkit-CSP-Report-Only
WWW-Authenticate
X-DC
X-Accel-Expires-Debug
X-TH-Server
X-Date
X-CACHE-KEY
X-Buckets
X-Ig-Push-State
X-Cache-Date
X-Old-Content-Length
X-MSEdge-Features
X-MSEdge-Flight
X-TRACE-ID
X-Srv
X-RAMCache
X-Endurance-Cache-Level
Resin-Trace
X-HS-Status
Fastly-Drupal-Html
X-NC
X-Conf
CDN
X-Microcachable
Powered-By
X-Dmc
X-CS
X-Varnish-Beresp-TTL
X-RateLimit-Reset
Path
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
Section-Origin-Responded
X-Location
X-MCACHE
X-Webstats-RespID
Tcn
X-Vcl-Version
Section-Io-Id
X-API-Version
X-Lb-Id
Magicmarker
X-Director
X-Varnish-Authentication
X-Cache-ASPX
X-Contensis-Viewer-Groups
X-DataCenter
True-Client-Ip
X-Akamai-Pragma-Client-IP
X-FPC
X-CLOUD-TRACE-CONTEXT
X-Check-Cacheable
Yjs-Id
X-LiteSpeed-Cache-Control
X-Cache-Ttl
X-Test
GeoIP-Country-Code
X-Alfa-Service
X-Wikidot-Backend
X-Datacenter
X-Wikidot-Static-Cache
X-Esi
M-TraceId
X-Vercel-Id
Lb
FSS-Cache
Cdn
Server-Id
X-Via-CDN
X-Be
X-Vercel-Cache
X-Mly-Id
X-Cache-Backend
Proxy-Connection
X-Cache-Expires
X-Geo
X-WA
X-PERF
X-ApacheServer
YJS-ID
X-Cc-Via
X-Response-By
X-Hyper-Cache
User-Agent
X-Via-PopH
X-ServedByHost
X-Via-PopV
X-Via-PopN
X-We-Are-Hiring
Pramga
X-Micro-Cache
Uri
X-HA-Backend
X-Server-IP
ENV
X-Cdn-Forward
X-Dw-Trace-Id
X-Info
X-M-Reqid
X-Client-Ip
XM
X-M-Log
X-Frame-Option
HIT
X-CF-Lambda-Version
XServer
CountryCode
X-CF-Lambda-Fn
X-Edge-POP
Sm-Log-Id
X-Service-Response-Time
X-AIR-PT
Swift-Performance
Locid
Srvid
X-VarnishDD-TTL
PFcat
X-From
X-HN
X-Instance-Name
X-Traceid
X-FL-EDGE
Location
X-Li-Fabric
X-TT-LOGID
X-Li-Pop
X-LI-Proto
X-Qnm-Cache
X-LI-UUID
X-UA
X-App
Dnion-Transfer-Encoding
Geoip-Latitude
Tracecode
X-Air-Hostname
X-Air-Trace-Id
X-TrackingId
X-Air-Source
X-Akamai-ERPolicy
X-Akamai-ERRuleID
X-LiteSpeed-Tag
Cneonction
X-RSL
X-Oss-Object-Type
C-Via
N-Cache
X-Oss-Storage-Class
X-Oss-Hash-Crc64ecma
X-Oss-Request-Id
X-Oss-Server-Time
CF-Cached-On
X-RPM
Cache-Key
X-RPS
Nginx-CQVIP
X-DW
Ohc-File-Size
X-Platform
X-Fastly-Backend-Reqs
X-DSS
PICS-Label
X-DI
X-DB
X-Wp-Cf-Super-Cache
X-Wp-Cf-Super-Cache-Cache-Control
X-Cache-Proxy
Timeexpire
X-Cdn-Request-ID
Esi-Enabled
X-SD-PageType
X-Conten-Type-Options
NtCoent-Length
Vha6-Origin
X-Platform-Cluster
Wpo-Cache-Status
Wpo-Cache-Message
X-HostName
X-Platform-Router
X-LAGOON
X-Request-Url
X-Lb-Nocache
Create-Date
X-Platform-Processor
X-CF-Powered-By
X-Fastly-Cache-Hits
X-Cache-Ngx
Warning
X-Litespeed-Cache-Control
Wp-Super-Cache
X-Ips-Loggedin
X-Air-Pt
X-Newegg-Index
X-Loadbalancer
X-NFL-Dma
X-NFL-Geo
X-Newegg-Flow
X-Matched-Rule
X-MTS-Cache
X-Nerd
X-Matome-Cached
X-N-OperationId
X-NXG
X-OVcl
X-Origin-Ops
X-PG-ACCESS
X-OVcl-Cache
X-Paywall
X-Onedio-Env
X-Okws-Version
X-Ntj-Investigation-Id
X-PageType
X-Nyt-Data-Last-Modified
X-Odoo-Frontend
X-NS-Authorization
X-IBD-Cache
X-Farm
X-Fastly-Is-Edge
X-Fstrz
X-Full-Ttl
X-F-Status
X-Eid
X-PGF-Deflate
X-ETag
X-Eventloop-Lag
X-Ee-Request-Id
X-GG-Cache-Status
X-Git-Commit
X-Ittl
X-Kebab
X-Kebabable
X-Keep
X-Is-SSL
X-IBD-SID
X-Global-Transaction-ID
X-GoCache-CacheStatus
X-Group
X-Header-Sub
X-LbNode
X-V2-Infrastructure
X-Ver
X-Vary-Devices
X-Wag-Acs
X-Waitingroom
X-Web-Hosting
X-Ee-Request-Date
X-Utime
X-True-Client-Ip
X-U-Cache
X-Upstream-State
X-User-Auth
X-WP-Bypass
X-WSR2
Hit
Fastcgi-X-Cache-Version
X-Request-URL
X-Ha-Backend
X-UP
X-Fastly-Country-Code
X-B3-Parentspanid
X-Xms-Page-Cache-Actions
X-YSpaceId
XV-Cache
XV-H
X-Tried-To-Kebabify
X-Toujours-Debout-Location
X-Route-Akamai
X-Route
X-Ruby
X-Save-Cache
X-Server-L
X-Request-Origin
X-Render-Time
X-R-Cache
X-Reboot
X-Redis
X-Render-Method
X-ServiceName
X-Sh
X-Svr-Proxy
X-SVR-IIS
X-Test-Nginx-Ingress
X-Timestamp
X-Toujours-Debout-Branch
X-Stack-Name
X-SSLProxy
X-Site
X-Slack-Shared-Secret-Outcome
X-SMP-JWT
X-Square
X-Pver
X-BeanStalkRole
Ns
Npm-Remaining
Ns-Ua
Ok-Cache-Status
Ok-Edge-Key
OK-Edge-Date
Npm-Cost
NLCacheNote
Is-Https
HTTPProtocol
Joe-X
NB-ESI
Nikkei-App-Version
Origin-Site
Panzer-Cache-Control
Service-Uuid
Served
SFRVia
Shieldsquare-Response
SII
Selected-Route
Scheme
RawURL
Proxy-Cache
Region
Request-Uuid
Rt-Proxy-Cache
HServer
H1
X-CUA
X-Mg-Cache
X-ElasticPress-Query
X-Yottaa-OS
X-IN-APIGATEWAYSSL
X-IN-APIGATEWAY
X-B3-ParentSpanId
WZWS-RAY
Req-ID
Fastcgi-Cache-Ttl
SRV
X-PAYTM-SRV-ID
DynaTrace
On-Server
X-Serial
Cluster-Host
Cf-Wrk
CMS-200
Deeplink
Ec-Policy-Id
Cf-Locale
Cf-Device-Type
Akamai-X-Url
X-Th-Server
Cache-Stat
Cachekey
Cdn-Country-Code
Store-Cloud-Cache
Sw
X-Cache-Reason
X-Cache-NPR
X-Cache-ReqUri
X-Cache-Response
X-CDN-Pop
X-CacheVersion
X-Cache-Length
X-Cache-IsMobileDevice
X-Backend-TTL
X-AspNetWebPages-Version
X-Backside-Transport
X-BeanStalkStage
X-Cache-Cookie
X-CDN-Pop-IP
X-Cf-Node-Idx
X-Doge
X-Developed-By
X-DT-Node
X-Edge-IP
X-Ee-Generated-By
X-Delivery
X-Dehri-Date
X-Coindesk-Cache
X-Cms-Device
X-Colour
X-Container-Uri
X-Dcm-Pdtf
X-ASF-Cache
X-ARRRG1
Uniqueid
TWC-Unit
Userver
Vttl
X-77-NZT
TWC-Subs
TWC-PATH-LOCALE
Technodrome
T-Request-Id
Time-Cloud-Cache
Ttl
TWC-AK-Req-ID
X-77-NZT-Ray
X-Accel-Version
X-Amz-Meta-Cb-Modifiedtime
X-Akamai-Native
X-Apache-Server
X-Ar-Stats
X-Arena-Request-Id
X-Akamai-DeviceType
X-Akamai-DeviceOS
X-Accepted-Language
X-Accepted-Fulllang
X-Accor-Asset
X-AEO-Platform
X-Akamai-CacheKeyMod
X-Ee-Origin