Threat Level: green Handler on Duty: Guy Bruneau

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
Strict-Transport-Security
X-Frame-Options
X-Content-Type-Options
Link
Last-Modified
CF-Cache-Status
Cf-Request-Id
CF-RAY
Accept-Ranges
ETag
Expect-CT
Pragma
X-Powered-By
X-Cache
Via
Age
X-XSS-Protection
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
X-Xss-Protection
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-FRAME-OPTIONS
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Request-Id
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-Adblock-Key
X-AspNet-Version
X-Permitted-Cross-Domain-Policies
Alt-Svc
X-Runtime
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Cache-Status
X-Check
X-Generator
X-DNS-Prefetch-Control
X-Request-ID
X-Cacheable
X-Iinfo
X-Envoy-Upstream-Service-Time
Feature-Policy
Timing-Allow-Origin
X-Content-Security-Policy
Status
X-Drupal-Dynamic-Cache
Content-Encoding
Access-Control-Expose-Headers
X-AspNetMvc-Version
X-CDN
P3p
Upgrade
X-Ua-Compatible
Access-Control-Max-Age
CF-Ray
X-Dns-Prefetch-Control
X-Via
X-Robots-Tag
X-Cache-Group
X-UA-Device
Server-Timing
Keep-Alive
Request-Context
X-AH-Environment
X-Turbo-Charged-By
X-Amz-Request-Id
X-Proxy-Cache
X-Backend
X-Age
X-Amz-Id-2
X-Ws-Request-Id
Host-Header
X-Hacker
X-Server-Powered-By
X-Rq
X-Server
X-Vhost
X-LiteSpeed-Cache
X-Varnish-Cache
X-Amz-Version-Id
Grace
Cf-Edge-Cache
X-Dispatcher
Allow
EagleId
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Device
X-Page-Speed
Accept-CH
X-Nginx-Cache-Status
X-WebKit-CSP
X-Aws-Lambda-Call-Status
X-Swift-SaveTime
X-Swift-CacheTime
Cf-Railgun
Ali-Swift-Global-Savetime
X-Node
X-Host
X-OneAgent-JS-Injection
X-Pingback
X-Cache-Spec
X-Backend-Server
X-Akam-SW-Version
X-Server-Id
Surrogate-Control
Request-Id
X-Cache-Lookup
Accept-CH-Lifetime
X-Response-Time
EagleEye-TraceId
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Readtime
Content-Location
X-HW
X-Content-Security-Policy-Report-Only
X-Cloud-Trace-Context
Rating
X-Application-Context
X-Trace
X-Url
Fastly-Restarts
X-WebKit-CSP-Report-Only
X-Clacks-Overhead
X-Nginx-Upstream-Cache-Status
X-CST
X-Ruxit-Js-Agent
X-MS-InvokeApp
X-Edge
X-Amz-Server-Side-Encryption
X-Rack-Cache
X-ESI
X-PC
X-TtlSet
X-Vname
X-Mod-Pagespeed
X-Content-Type
X-B3-TraceId
Cf-Apo-Via
Edge-Control
X-Country
X-Vcap-Request-Id
X-FastCGI-Cache
X-Oneagent-Js-Injection
Accept-Ch-Lifetime
X-Akamai-Path-Stats
X-D2id
Verso
X-Ttl
X-GitHub-Request-Id
Xkey
X-Kinja
X-Cdn-Fetch
X-Use-Magma
X-Kinja-Server
X-GoogleNews-Bot
X-Kinja-Build
Cache-Tag
X-Kinja-Revision
X-Mcache
X-Exp-Id
X-Exp-Variant
Service-Worker-Allowed
X-Powered-By-Plesk
X-Amz-Rid
X-Navigation-Version
X-Server-Name
RTSS
X-Abt-Application-Version
X-VARITI-CCR
X-Client-IP
X-Ac
X-Varnish-TTL
X-Version
X-Upstream
X-Cnection
X-ECACHE
X-Cached
X-Element-Page-Cache
Arr-Disable-Session-Affinity
Permissions-Policy
X-Ruxit-JS-Agent
X-Server-Lifecycle-Phase
X-Instrumentation
X-Kraken-Loop-Name
X-Dw-Request-Base-Id
X-SharePointHealthScore
X-RateLimit-Remaining
SPRequestGuid
X-Px
SPIisLatency
SPRequestDuration
X-Cache-TTL
Display
Pagespeed
X-Sol
X-Middleton-Display
X-NWS-LOG-UUID
Public-Key-Pins
X-Country-Code
Response
X-Middleton-Response
X-Midtier
X-Cache-Key
X-Edge-Location-Klb
X-Kinsta-Cache
X-Ser
X-Forwarded-For
X-Goog-Hash
X-SRCache-Store-Status
Content-MD5
X-DataDome
X-SRCache-Fetch-Status
X-NF-Request-ID
X-Correlation-Id
X-Shield-Request-Id
Access-Control-Request-Method
X-Jurisdiction
X-HP-Webp
X-HP-Trace-Id
X-RateLimit-Limit
X-MSEdge-Ref
X-ORACLE-DMS-ECID
Front-End-Https
X-ORACLE-DMS-RID
MRF-Tech
Mrf-Cache-Status
X-B3-TraceId-Primal
AR-Request-ID
AR-SID
X-T
AR-PoweredBy
AR-CACHE
AR-ATIME
X-Recruiting
MicrosoftSharePointTeamServices
X-Daa-Tunnel
Edge-Cache-Tag
TP-Cache
TP-L2-Cache
Nginx-Cache
X-Webkit-Csp
X-Browser-Type
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Mg-S
X-Accel-Expires
X-Content-Digest
TCN
X-Grace
X-Hits
X-Powered-CMS
X-Request-Processing-Time
X-Amzn-Trace-Id
X-Request-Received
X-HS-Combine-CSS
X-HS-Cache-Config
Server-Node
X-HS-Hub-Id
X-HS-Content-Id
Filters
Server-Name
MS-Author-Via
X-Id
Fastcgi-Cache
X-Geo-Country
Count-Hit
X-XRDS-Location
X-TEC-API-ROOT
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-Fastly-Request-Id
X-Origin-Server
Accept-Ch
X-Distributor
X-Ezoic-Cdn
X-Ua-Browser
X-Frontend
Filterid
Cross-Origin-Opener-Policy
X-PressLabs-Stats
X-LLID
Payment
S
X-Seen-By
X-Page-Id
X-Microsite
X-Request-Handler-Origin-Region
Charset
X-Forwarded-Proto
X-Language
X-F-Cache
X-Git-Hash
X-Protected-By
Host
X-FB-Debug
X-LB-Cache
X-B3-Sampled
X-Ratelimit-Reset
X-Amz-Meta-S3cmd-Attrs
X-VCache
X-ASPNET-VERSION
X-Cluster-Name
X-COUNTRY
X-Rid
Cache-Status
Surrogate-Key
X-Www-Served-By
Cache-Tags
Access-Control-Allow-Method
X-Logged-In
X-Upgrade-Enabled
X-Origin-Cache
X-DIS-Request-ID
X-Ab
X-Source
X-Varnish-Backend
Retry-After
Realpath
Alternate-Protocol
X-Az
X-AppVersion
X-Activity-Id
Accept-Charset
Cleartype
X-NGENIX-Cache
X-Amz-Replication-Status
X-Cache-Age
X-Type
Paypal-Debug-Id
DC
X-Is-Crawler
X-Wix-Request-Id
X-Template
X-Flags
X-Varnish-Grace
X-Envoy-Decorator-Operation
X-Route-Name
X-Request-Guid
X-Providence-Cookie
X-Aspnet-Duration-Ms
X-App-Environment
X-B-Cache
X-Signature
X-TT
X-Tb
X-Revision
X-Hostname
X-B
X-DynaTrace
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
ServerID
X-Contextid
Frame-Options
X-Cache-Rule
X-Trace-Id
X-Fastly-Request-ID
X-Fastcgi-Cache
X-Drupal-Cache-Tags
X-Node-Name
X-Tt-Trace-Host
X-Tt-Trace-Tag
Refresh
Cross-Origin-Resource-Policy
X-Pinterest-Rid
Pinterest-Version
Pinterest-Generated-By
Amp-Access-Control-Allow-Source-Origin
X-Goog-Metageneration
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-GUploader-UploadID
X-Goog-Generation
X-Proxy
Referer-Policy
X-Debug
X-Load-Cache
X-Mobile
Node
X-Content-Options
NGB
Viewport
X-Varnish-Server
X-EdgeConnect-Cache-Status
X-Original-Request-Id
X-Response-Served-From
X-Cache-Control
X-Varnish-Age
X-XRDS-LOCATION
X-Whom
X-Content-Powered-By
X-N
Akamai-GRN
Country
X-Magnolia-Registration
X-NYM-Debug-Backend
X-Instance
X-Debug-IsPreview
X-Cache-Time
X-Debug-IsConnected
Content-Disposition
X-Adobe-Loc
X-Status
X-G
X-Page-View
X-Real-IP
X-Rendered-As
X-Framework
X-Is-Bot
X-Adobe-Content
Uber-Trace-Id
X-Servername
X-User-Agent
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-RemovedCookies
Url
X-Cache-Grace
X-Akamai-Request-ID2
X-L-Path
X-ProcessESI
X-Environment-Context
X-Cacheable-TTL
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Jobs
Srv
Access-Control-Request-Headers
X-Cache-Expired-At
X-Mid
X-Cache-TTL-Remaining
X-Via-JSL
Healthy
X-Rule
X-Tumblr-Pixel-1
X-Cache-Hit
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Tumblr-User
X-CDN-Forward
X-Cache-Operation
X-Backend-Name
Countrycode
X-APP-VERSION
X-Unique-Id
X-Drupal-Cache-Contexts
X-TTL
Version
X-Oracle-Dms-Ecid
X-Debug-Info
Accept-Language
X-Akamai-Edgescape
X-Oracle-Dms-Rid
X-Cache-Action
Section-Io-Cache
X-Litespeed-Cache
X-VC-Cache
X-ECache
X-Http-Reason
X-Mg-Request-UUID
Content-Secure-Policy
X-HTML-Minification-Powered-By
Protected
X-Tt-Logid
X-Server-ID
X-Hosted-By
X-IPLB-Request-ID
X-IPLB-Instance
X-Generation-Time
Xserver
X-Varnish-Ttl
X-FW-Type
X-Azure-Ref
Backend
X-Generated-By
X-FW-Static
X-FW-Hash
X-FW-Server
X-FW-Dynamic
Server-Info
X-FW-Serve
X-Time
X-RN-RSRV
X-Cache-Status-Check
Meta-Geo
X-Storage
X-RTag
MS-CV
X-UPSTREAM-Address
Ms-Operation-Id
X-Amz-Apigw-Id
X-Device-Type
X-Amzn-RequestId
Azure-InstanceId
X-Hl-Ver
X-Cache-Server
X-Mode
TWC-GeoIP-LatLong
X-Handled-By
X-Format
X-Cms-Context
X-Access
X-OCL
X-Origin-Hint
X-Varnish-Cache-Hits
X-Section
Liferay-Portal
X-PCL
Webcakes-Region
Webcakes-App-Version
Property-Id
Azure-Version
Azure-SlotName
Azure-SiteName
TWC-Connection-Speed
TWC-Device-Class
Webcakes-App-Name
TWC-Privacy
TWC-Locale-Group
TWC-GeoIP-Country
Azure-RegionName
X-Dc
X-R9-Blue-Green-Version
GEO-INFO
Onion-Location
X-Proto
X-SRV
X-Server-W
X-Varnish-Hostname
X-AWS-Id
X-VWS-Id
X-Redis-Cache
X-Adobe-Source
X-PHP-Host
Web-Mar-Node
X-Varnishpool
X-Proxy-Cache-Status
X-Locale
X-Sql-Duration-Ms
X-Api-Version
X-Provided-By
X-No-Session
X-FireWall-Port
X-App-Server
X-Sql-Count
CF-IPCountry
X-Say-TTL
X-SayCDN-TTL
X-Labrador-Cache-Channel
X-JoinUs
X-Say-Cacheable
X-SaId
X-Mobile-URL
X-LJ-Flow-ID
X-GeoCode
CDN-Cache
X-UA-Device-Type
X-GeoCountry
X-Restarts
Locale
X-Proxy-Build
X-ProxyCache-Key
X-Via-Fastly
X-Xfnlog-Site
Mn-Server-Ip
Selected-Fe
X-Request-Time
X-Web-Node
X-Ms-Request-Id
Cache-Name
X-Forwarded-Host
CDN-CachedAt
X-Edge-Location
X-Urbn-Context-Path
X-Skip-Cache
X-BYPASS-REASON
CDN-PullZone
X-Detected-As
X-Cache-Type
X-Content-Age
X-Cache-Host
CDN-EdgeStorageId
X-Timing-Wait
Eomportal-Instance
CDN-Uid
X-FB-TRIP-ID
X-Urbn-Site-Id
DB-Nickname
CDN-RequestId
X-Varnish-Beresp-Grace
X-Region
X-Site-Version
X-ProxyCache-Status
CDN-RequestCountryCode
X-Ms-Version
S-Rt
X-Sorting-Hat-PodId
X-Shopify-Stage
Apigw-Requestid
X-Sorting-Hat-ShopId
X-ServerID
X-Extlb
X-Zipkin-Id
X-Routing-Service
X-Alternate-Cache-Key
X-DynaTrace-JS-Agent
X-PHP-Backend
X-Proxied
X-ShopId
X-ShardId
X-Storefront-Renderer-Rendered
WP-Super-Cache
X-Tid
X-Vgn-Hpd-Reason
X-Nginx-Cache-Key
X-TIME
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
X-Amzn-Remapped-Content-Length
X-Tec-Api-Version
X-Reqid
X-Tec-Api-Origin
X-Tec-Api-Root
X-Loop
X-TNCMS
X-Newrelic-Synthetics
X-LSADC-Cache
X-Cache-Enabled
X-Pubstack
X-Content
Load-Balancing
Xet-Cookie
X-Ua
X-Soup
X-Tumblr-Pixel-2
X-Cdn
X-Origin-CC
X-Origin-TTL
X-B3-Traceid
X-Uri
X-TA-CDN-Provider
X-Zen-Fury
From-Origin
X-Cache-NGX
X-Service
X-Origin-Date
X-MP-GENERATED-AT
X-Cache-Debug
Fastcgi-Useragent
X-Ratelimit-Remaining
X-Aspnetmvc-Version
X-Correlation-ID
Source
X-Varnish-Hits
X-UUID
X-GEO
X-Webkit-CSP
ServedBy
Origin
X-Nginx-Cache
X-Human
X-App-Version
X-NewRelic-App-Data
Cache
X-Cache-Tags
Fastly-Drupal-HTML
Upgrade-Insecure-Requests
X-Cluster
X-Rewrite-Enabled
SD-X-WS
X-Varnish-Beresp-Ttl
Rip
X-Cached-By
X-ScT
Cross-Origin-Window-Policy
MD5-Digest
BehaviorPad-Version
Rendered-Blocks
Host-ID
WPO-Cache-Message
Mime-Version
WPO-Cache-Status
X-Ratelimit-Limit
X-User
Expiry
Lang
Xc-Version
Meta-Geo-Continent
X-Vdms-Path
X-Vdms-Version
X-FW-Version
Cdncip
A
Ngx.Var.Host
Cdnsip
DCR-Decision-By
X-VG-WebCache
DCR-Processing-Time-Ms
X-A-Wwc
X-Ec-GeoHdr
X-External-Request-Id
X-Forwarded-Path
X-Ec-Fail
X-Developer
X-Connection-Hash
X-D
X-Destination
X-SRCache-Key
X-Orig-Expires
X-S
X-S-Cookie
X-Shop-Environment
X-Rojux
X-Processor
X-Parent-Response-Time
X-PBS-Appsvrname
X-Cache-NE
X-BCube-Filmed-By
X-A
X-A-Ccd
X-A-Dam
X-TIM-N
T-Server
Sslversion
Surrogated-Key
X-A-Dcw
X-A-Dgt
X-ARC
X-B-Cookie
X-Bc-Bl
X-Application
X-Tenant
X-Aed
X-AK-Request-ID
Odigeo-Trace-Id
X-NAPM-TraceId
X-Cluster-Node
Webserver
OT-Force-Account-Verify
X-Tumblr-Pixel-3
Redirect-Candidate
X-Served-From
X-Origin-Time
X-Nyt-Route
Release
X-GeoIP-City
X-Gdpr
X-Aicache-OS
Environment
Gh-Request-Id
X-Accel-Buffering
X-Sucuri-Cache
X-Cdn-Srv
X-Level-Front-Cache
X-CMSURLCustom
X-Auto-Login
Thinkindot-Control
AKAMAI
Fastly-Backend-Name
TDXMobile
Thinkindot-CacheControl-Type
X-JWT-State
X-Core-Value
X-HS-Content-Campaign-Id
X-Worker
X-INCAP-ABP
X-Is-Gdpr
X-Has-Esi
X-Geo-Header
X-Optimistic-Header
X-Developers
X-Sucuri-ID
X-Generated-On
X-Thinkindot-L3
Thinkindot-CacheControl
X-Cache-Remote
X-RCS-CacheZone
X-WP-CF-Super-Cache-Active
X-Pass-Why
X-Request-Host
Wxu-Next-Hostname
We-Hiring
Tube-Return
Fastly-SSL
Fastly-SWR
X-NodeID
Wxu-Next-Commit
Web-Mar-Region
Traceparent
X-NCache
Servername
Fastly-GeoIP-CountryCode
Decoy-Debug-Key
Decoy-Debug-Status
X-Eu-Site
Datacenter
X-AOL-HN
X-Esi-Check
Decoy-Debug-TTL
X-Platform-Server
X-Origin-Response-Time
Wxu-Next-Region
X-Owner
Tube-Got-Results
Tube-Get-Contents
X-FC-Vary-Parameters
Fastly-SIE
X-GeoIP
X-Epic-Correlation-Id
Memcached
X-Loc
Mobile-Detection-Method
X-Ad-Defer-Variation
IsBot
Kp-EeAlive
X-Minions-Version
X-Mvc-Supplant-Cachable
L5d-Success-Class
L
Mail-Subject
Is-Eu
X-Irp-Debug
Platform
Origin-EX
Producers
Machine
Req-Svc-Chain
Origin-CC
HA-Ipaddr
X-Fetched-On
NGX
NM-Fastcgi-Cache
X-Fmm-Version
X-Gzip
Ha-Gx-Prefs
Apple-News-Services-Handled
X-Cache-Id
X-Thanos
X-Cache-Info
X-Device-Os
X-Variation
X-Var-Ttl
X-Dispatcher-Number
X-Cache-Bucket
X-Sigma
X-DPWN-IS-SECURE
X-Sigma-Backend
X-SIPLIST1
X-SplitTest
X-Varnish-Beresp-Status
X-Varnish-CookieHashed-On
X-CGP
X-DefHash
X-Ckpd-Fst-Backend
X-Clara-WADP
X-Csrf-Jwt
X-DefElseHash
X-Wix-Viewer-Type
X-WADP-Cache
X-Varnish-Remaining-TTL
X-Varnish-CookieINHashed-On
X-VG-TLSProxy
X-Viewer-Country
X-VServer
X-Ec-Custom-Error
X-Bip
X-SB
Candidate-Md5Url
Cache-Host
Apple-News-Services-Request-Url
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
X-Azure-Ref-OriginShield
X-Pool
Cluster
X-ATG-Version
CloudFront-Viewer-Country
Click-Count-Error
X-Policy
Click-Count-Action-Start
Tube-Got-Eval
Canary
X-BBC-Edge-Cache-Status
X-Rocket-Nginx-Serving-Static
X-Rocket-Build-Number
X-Request-URI
X-S-Maxage
Adler-Geo
X-Proxy-Cache-Info
X-Qloud-Router
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
WebServer
Server-Host
X-Tx-Id
X-Core-Mission
User-Cache-Control
X-CacheTTL
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
V-Age
Vix-Hermes-Req-Id
X-Cdn-Origin
X-Branch-Name
X-Fastly-Backend
VNS-Cache
VNS-Age
X-Block-Status
X-Planisys-CDN-Cache
X-Gamma-Serve
Cmstype
Cmsid
Country-Code
CPC-Age
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
CPC-Cache
CDCHOST
X-Region-Sid
X-SVT-ORM-VERSION
X-IPS-LoggedIn
X-V-Cache
X-SVT-ORM-RULES
X-Sn-Servicetimems
X-Scale
X-Scheme
X-Slack-Backend
X-Datadog-Parent-Id
X-Forwarded-Site
X-Mvc-Supplant-OutputCached
X-Gen-Mode
Server-Hostname
X-Gateway-Skip-Cache
State
X-Gateway-Cache-Key
X-Gateway-Cache-Status
X-Gateway-Request-Id
Server-Ext
Sever-Int
X-Hnp-Log
X-Hash
LB
X-Udemy-Cache-App-Namespace
X-Debug-Cache
X-Presslabs-Stats
X-Akamai-Transformed
X-Clientip
DSUID
Memory
X-LB-NoCache
X-URL
Svr
X-Origin
X-Dispatch
Time
X-Up
Ec-Rule-Version
X-Edge-Pop
Sid
X-CSRF-Token
Pics-Label
X-Newrelic-App-Data
X-Nf-Request-Id
Ssr
X-Tb-Optimization-Total-Bytes-Saved
X-B3-Spanid
HostName
Request-ID
X-VC
X-NGINX-Cache
X-Req
AMP-Access-Control-Allow-Source-Origin
X-ND-Cache
Env
X-Generated-In
X-ZONE
My-App
X-Servedbyhost
X-Cs
X-Wa
X-Refresh
True-Client-Country-4JS
CacheControlHeader
X-Via-Popn
X-Via-Popv
X-Lambda-Id
X-Via-Poph
X-Vc
Cache-Tv-Group
X-WA-Info
X-Via-NSCOPI
X-B3-SpanId
Server-ID
X-Datadome
GeoIp-Country-Code
Fastcgi-Cache-TTL
SID
Hostname
X-GG-Cache-Date
True-Client-IP
X-Op-Id-All
X-Session-Fingerprint
X-CACHE-AGE
X-EC-Lua
X-PX
X-Rebelmouse-Surrogate-Control
X-Release
X-Rebelmouse-Cache-Control
X-Pod-Name
X-ID
X-Zone
X-Fpc
X-Fastly-Cache
X-Origin-Expires
Cache-Hits
X-MCACHE
X-VCL-Version
X-Xrds-Location
X-Trace-ID
X-GeoIP-Region-Code
X-CSRF-TOKEN
X-LB-ID
X-GeoIP-Country-Code
X-TX-ID
WWW-Authenticate
X-Webkit-CSP-Report-Only
X-NWS-UUID-VERIFY
X-TH-Server
X-Date
X-Accel-Expires-Debug
X-Buckets
X-CACHE-KEY
X-MSEdge-Features
X-Ig-Push-State
X-MSEdge-Flight
X-Old-Content-Length
X-Cache-Date
X-RAMCache
X-TRACE-ID
X-Srv
X-NC
X-Conf
X-HS-Status
Fastly-Drupal-Html
X-Endurance-Cache-Level
X-DC
CDN
Resin-Trace
X-Microcachable
X-Dmc
X-CS
Powered-By
X-RateLimit-Reset
X-Varnish-Beresp-TTL
X-Lb-Id
X-Vcl-Version
X-Location
X-Webstats-RespID
Tcn
Section-Origin-Responded
Section-Io-Id
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
Path
X-API-Version
X-Director
Magicmarker
X-Contensis-Viewer-Groups
X-DataCenter
X-Cache-ASPX
X-Varnish-Authentication
X-FPC
X-Akamai-Pragma-Client-IP
True-Client-Ip
Yjs-Id
X-LiteSpeed-Cache-Control
X-CLOUD-TRACE-CONTEXT
X-Check-Cacheable
X-Cache-Ttl
X-Wikidot-Backend
X-Wikidot-Static-Cache
GeoIP-Country-Code
X-Alfa-Service
X-Datacenter
X-Test
X-Esi
X-Mly-Id
X-Cache-Backend
Proxy-Connection
X-Be
M-TraceId
X-Cache-Expires
X-Vercel-Id
FSS-Cache
Lb
Server-Id
X-Via-CDN
X-WA
Cdn
X-Server-IP
X-Vercel-Cache
X-Geo
X-ApacheServer
YJS-ID
X-PERF
X-Cc-Via
X-We-Are-Hiring
X-Response-By
X-Via-PopH
X-Via-PopN
Uri
X-Via-PopV
Pramga
X-Micro-Cache
X-Hyper-Cache
X-ServedByHost
X-HA-Backend
ENV
User-Agent
X-Dw-Trace-Id
X-Cdn-Forward
X-Frame-Option
XM
X-Info
X-CF-Lambda-Version
X-CF-Lambda-Fn
XServer
X-M-Log
HIT
X-Client-Ip
X-M-Reqid
Sm-Log-Id
CountryCode
X-Service-Response-Time
X-AIR-PT
X-Edge-POP
Dnion-Transfer-Encoding
X-Instance-Name
X-Qnm-Cache
X-Air-Source
X-Air-Hostname
Locid
X-Traceid
X-Air-Trace-Id
X-App
Swift-Performance
PFcat
X-TrackingId
X-Akamai-ERPolicy
X-UA
X-HN
X-TT-LOGID
X-FL-EDGE
X-VarnishDD-TTL
Tracecode
Srvid
X-From
Location
Geoip-Latitude
X-Akamai-ERRuleID
X-Li-Fabric
X-LiteSpeed-Tag
X-Li-Pop
X-LI-UUID
X-LI-Proto
X-RSL
X-Oss-Server-Time
X-Oss-Object-Type
PICS-Label
X-Oss-Request-Id
Cache-Key
N-Cache
Cneonction
CF-Cached-On
Nginx-CQVIP
X-RPS
X-Oss-Hash-Crc64ecma
X-Oss-Storage-Class
X-DB
X-Fastly-Backend-Reqs
X-Platform
Ohc-File-Size
X-DI
X-DSS
C-Via
X-DW
X-RPM
X-Wp-Cf-Super-Cache-Cache-Control
X-Wp-Cf-Super-Cache
Esi-Enabled
X-Fastly-Cache-Hits
X-CF-Powered-By
Wpo-Cache-Message
Wpo-Cache-Status
X-Lb-Nocache
X-Cache-Proxy
X-Request-Url
Vha6-Origin
X-Platform-Processor
X-LAGOON
NtCoent-Length
X-Cdn-Request-ID
X-Platform-Router
X-HostName
X-Conten-Type-Options
X-SD-PageType
X-Platform-Cluster
Timeexpire
Create-Date
X-Ips-Loggedin
Wp-Super-Cache
X-Cache-Ngx
Warning
X-Litespeed-Cache-Control
X-Air-Pt
X-Newegg-Index
X-Matched-Rule
X-NFL-Dma
X-NFL-Geo
X-Newegg-Flow
X-Matome-Cached
X-N-OperationId
X-Nerd
X-NS-Authorization
X-MTS-Cache
X-NXG
X-OVcl-Cache
X-OVcl
X-PageType
X-Paywall
X-PG-ACCESS
X-Origin-Ops
X-Onedio-Env
X-Loadbalancer
X-Nyt-Data-Last-Modified
X-Odoo-Frontend
X-Okws-Version
X-Ntj-Investigation-Id
X-Keep
X-Fstrz
X-Eid
X-Full-Ttl
X-GG-Cache-Status
X-ETag
X-Eventloop-Lag
X-Fastly-Is-Edge
X-Ee-Request-Date
X-F-Status
X-Farm
X-Ee-Request-Id
X-Git-Commit
X-Global-Transaction-ID
X-Ittl
X-Kebab
X-Kebabable
X-PGF-Deflate
X-Is-SSL
X-IBD-SID
X-GoCache-CacheStatus
X-Group
X-Header-Sub
X-IBD-Cache
X-LbNode
X-YSpaceId
X-Vary-Devices
X-V2-Infrastructure
X-Ver
X-Wag-Acs
X-Waitingroom
X-Utime
X-User-Auth
X-Tried-To-Kebabify
X-True-Client-Ip
X-U-Cache
X-Upstream-State
X-Web-Hosting
X-WP-Bypass
X-Request-URL
X-Ee-Origin
X-Request-Start
X-UP
X-Ha-Backend
X-Fastly-Country-Code
X-B3-Parentspanid
X-WSR2
X-Xms-Page-Cache-Actions
XV-Cache
XV-H
X-Toujours-Debout-Location
X-Toujours-Debout-Branch
X-Route-Akamai
X-Route
X-Ruby
X-Save-Cache
X-Server-L
X-Request-Origin
X-Render-Time
X-R-Cache
X-Reboot
X-Redis
X-Render-Method
X-ServiceName
X-Sh
X-SVR-IIS
X-Svr-Proxy
X-Test-Nginx-Ingress
X-Timestamp
X-Stack-Name
X-SSLProxy
X-Site
X-Slack-Shared-Secret-Outcome
X-SMP-JWT
X-Square
X-Pver
Scheme
Npm-Cost
NLCacheNote
Npm-Remaining
Ns
Ok-Cache-Status
Ns-Ua
Nikkei-App-Version
NB-ESI
HServer
H1
HTTPProtocol
Is-Https
Joe-X
OK-Edge-Date
Ok-Edge-Key
Served
Selected-Route
Service-Uuid
SFRVia
Shieldsquare-Response
Rt-Proxy-Cache
Request-Uuid
Panzer-Cache-Control
Origin-Site
Proxy-Cache
RawURL
Region
Ec-Policy-Id
Deeplink
WZWS-RAY
DynaTrace
X-B3-ParentSpanId
X-Mg-Cache
X-ElasticPress-Query
X-CUA
SRV
On-Server
Fastcgi-X-Cache-Version
X-PAYTM-SRV-ID
Hit
Req-ID
Fastcgi-Cache-Ttl
X-Yottaa-OS
X-IN-APIGATEWAY
Cf-Locale
Cf-Device-Type
Cf-Wrk
Cluster-Host
CMS-200
Cdn-Country-Code
Cachekey
X-Serial
X-IN-APIGATEWAYSSL
X-Th-Server
Akamai-X-Url
Cache-Stat
SII
Store-Cloud-Cache
X-Cache-NPR
X-Cache-Length
X-Cache-Reason
X-Cache-ReqUri
X-CacheVersion
X-Cache-Response
X-Cache-IsMobileDevice
X-Cache-Cookie
X-Backend-TTL
X-AspNetWebPages-Version
X-Backside-Transport
X-BeanStalkRole
X-BeanStalkStage
X-CDN-Pop
X-CDN-Pop-IP
X-Developed-By
X-Delivery
X-Doge
X-DT-Node
X-Edge-IP
X-Dehri-Date
X-Dcm-Pdtf
X-Cms-Device
X-Cf-Node-Idx
X-Coindesk-Cache
X-Colour
X-Container-Uri
X-ASF-Cache
X-ARRRG1
TWC-Unit
TWC-Subs
Uniqueid
Userver
X-77-NZT
Vttl
TWC-PATH-LOCALE
TWC-AK-Req-ID
T-Request-Id
Sw
Technodrome
Time-Cloud-Cache
Ttl
X-77-NZT-Ray
X-Accel-Version
X-Amz-Meta-Cb-Modifiedtime
X-Akamai-Native
X-Apache-Server
X-Ar-Stats
X-Arena-Request-Id
X-Akamai-DeviceType
X-Akamai-DeviceOS
X-Accepted-Language
X-Accepted-Fulllang
X-Accor-Asset
X-AEO-Platform
X-Akamai-CacheKeyMod
X-Ee-Generated-By