Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
Strict-Transport-Security
X-Frame-Options
X-Content-Type-Options
Last-Modified
Link
CF-Cache-Status
Cf-Request-Id
CF-RAY
Accept-Ranges
ETag
Expect-CT
Pragma
X-Powered-By
X-Cache
X-XSS-Protection
Via
Age
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Xss-Protection
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-FRAME-OPTIONS
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Request-Id
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-Adblock-Key
X-AspNet-Version
X-Permitted-Cross-Domain-Policies
Alt-Svc
X-Runtime
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Check
X-Cache-Status
X-DNS-Prefetch-Control
X-Generator
X-Cacheable
X-Request-ID
X-Iinfo
X-Envoy-Upstream-Service-Time
P3p
Timing-Allow-Origin
Feature-Policy
X-Content-Security-Policy
Status
X-Drupal-Dynamic-Cache
Content-Encoding
X-AspNetMvc-Version
Access-Control-Expose-Headers
Upgrade
X-CDN
X-Ua-Compatible
Access-Control-Max-Age
CF-Ray
X-Dns-Prefetch-Control
X-Via
X-Robots-Tag
X-Cache-Group
Server-Timing
X-UA-Device
Request-Context
Keep-Alive
X-AH-Environment
X-Amz-Request-Id
X-Turbo-Charged-By
X-Proxy-Cache
X-Backend
X-Amz-Id-2
X-Age
X-Ws-Request-Id
Host-Header
X-Hacker
X-Server-Powered-By
X-Server
X-Rq
X-Vhost
X-Varnish-Cache
X-Amz-Version-Id
X-LiteSpeed-Cache
Grace
X-Dispatcher
EagleId
Cf-Edge-Cache
Allow
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Device
X-Page-Speed
X-Nginx-Cache-Status
X-Swift-SaveTime
X-Swift-CacheTime
X-WebKit-CSP
Accept-CH
Ali-Swift-Global-Savetime
X-Aws-Lambda-Call-Status
X-Host
X-Node
Cf-Railgun
X-Pingback
X-Cache-Spec
X-Server-Id
X-Akam-SW-Version
X-Backend-Server
Surrogate-Control
X-OneAgent-JS-Injection
Request-Id
EagleEye-TraceId
X-Akamai-Path-Stats
X-Response-Time
X-Cache-Lookup
X-Readtime
Accept-CH-Lifetime
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Content-Location
X-HW
X-Content-Security-Policy-Report-Only
X-Cloud-Trace-Context
X-Application-Context
Rating
X-Trace
Fastly-Restarts
X-WebKit-CSP-Report-Only
X-Clacks-Overhead
X-Nginx-Upstream-Cache-Status
X-Country
X-Oneagent-Js-Injection
Accept-Ch-Lifetime
X-Url
X-MS-InvokeApp
X-Amz-Server-Side-Encryption
X-Rack-Cache
X-Edge
X-PC
X-Vname
X-TtlSet
X-CST
Edge-Control
X-Mod-Pagespeed
X-Ruxit-Js-Agent
X-Content-Type
X-Vcap-Request-Id
X-B3-TraceId
X-ESI
X-Exp-Id
X-Kinja-Revision
X-Kinja-Build
X-Kinja-Server
X-Use-Magma
Xkey
X-Kinja
X-GoogleNews-Bot
X-Cdn-Fetch
Verso
X-Exp-Variant
X-FastCGI-Cache
X-D2id
Cache-Tag
X-GitHub-Request-Id
X-Mcache
X-Amz-Rid
X-Powered-By-Plesk
Service-Worker-Allowed
X-Ruxit-JS-Agent
RTSS
X-ECACHE
X-VARITI-CCR
X-Abt-Application-Version
X-Version
X-Navigation-Version
X-Varnish-TTL
Cf-Apo-Via
X-Upstream
X-Ttl
X-Client-IP
X-Cached
X-Ac
X-Server-Name
X-Cnection
X-Element-Page-Cache
X-Dw-Request-Base-Id
Arr-Disable-Session-Affinity
X-Kraken-Loop-Name
X-SharePointHealthScore
X-Instrumentation
X-Server-Lifecycle-Phase
SPRequestGuid
Permissions-Policy
X-Px
SPIisLatency
SPRequestDuration
Public-Key-Pins
X-Country-Code
X-Sol
Pagespeed
X-Middleton-Display
Display
X-Cache-TTL
X-NWS-LOG-UUID
Response
X-Middleton-Response
X-RateLimit-Remaining
X-Ser
X-Edge-Location-Klb
X-Kinsta-Cache
X-Cache-Key
X-Midtier
X-Goog-Hash
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Forwarded-For
Content-MD5
X-Correlation-Id
Front-End-Https
Access-Control-Request-Method
X-Shield-Request-Id
X-MSEdge-Ref
X-NF-Request-ID
AR-SID
AR-Request-ID
AR-ATIME
AR-PoweredBy
AR-CACHE
X-B3-TraceId-Primal
X-T
Mrf-Cache-Status
X-Recruiting
MRF-Tech
TP-L2-Cache
X-DataDome
TP-Cache
X-Jurisdiction
X-HP-Webp
X-HP-Trace-Id
Edge-Cache-Tag
MicrosoftSharePointTeamServices
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
Nginx-Cache
X-Accel-Expires
X-RateLimit-Limit
X-Daa-Tunnel
X-Mg-S
Accept-Ch
TCN
X-Powered-CMS
X-Grace
X-Content-Digest
X-Browser-Type
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Hits
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-Request-Received
X-Request-Processing-Time
Server-Node
X-Id
X-Amzn-Trace-Id
Server-Name
X-HS-Hub-Id
X-HS-Cache-Config
X-HS-Combine-CSS
X-HS-Content-Id
X-XRDS-Location
Filters
MS-Author-Via
X-Geo-Country
Fastcgi-Cache
X-Frontend
X-Distributor
X-Webkit-Csp
Count-Hit
X-PressLabs-Stats
X-Origin-Server
X-Ezoic-Cdn
X-Ua-Browser
S
X-Protected-By
Filterid
Cross-Origin-Opener-Policy
X-LLID
X-Fastly-Request-Id
X-Forwarded-Proto
X-F-Cache
X-B3-Sampled
X-FB-Debug
X-Seen-By
X-Microsite
X-Request-Handler-Origin-Region
Charset
X-Git-Hash
X-LB-Cache
Cache-Status
Payment
X-Language
X-Page-Id
X-Amz-Meta-S3cmd-Attrs
Host
X-Ab
X-ASPNET-VERSION
X-VCache
X-Ratelimit-Reset
X-Cluster-Name
Surrogate-Key
X-Fastcgi-Cache
X-Rid
Realpath
X-Www-Served-By
Cache-Tags
Accept-Charset
Access-Control-Allow-Method
X-Cdn
X-Logged-In
Retry-After
X-Upgrade-Enabled
Alternate-Protocol
X-DIS-Request-ID
X-Source
X-Origin-Cache
X-NGENIX-Cache
X-Varnish-Backend
X-Cache-Age
X-Litespeed-Cache
X-Wix-Request-Id
X-Is-Crawler
X-B-Cache
X-Envoy-Decorator-Operation
X-Aspnet-Duration-Ms
Cleartype
Paypal-Debug-Id
X-Flags
X-Providence-Cookie
X-Tb
X-Signature
X-Route-Name
X-Request-Guid
X-Type
DC
X-Activity-Id
X-AppVersion
X-Az
X-TT
X-B
X-Amz-Replication-Status
ServerID
X-Template
X-Varnish-Grace
X-App-Environment
X-Hostname
X-Fastly-Request-ID
X-DynaTrace
X-Revision
X-Node-Name
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
Frame-Options
X-Contextid
X-Drupal-Cache-Tags
X-Cache-Rule
X-Tt-Trace-Host
X-TTL
X-Tt-Trace-Tag
X-Pinterest-Rid
Pinterest-Version
Pinterest-Generated-By
X-Proxy
X-GUploader-UploadID
X-Goog-Generation
X-Goog-Metageneration
X-Goog-Stored-Content-Length
Amp-Access-Control-Allow-Source-Origin
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Debug
Refresh
X-Mobile
X-Load-Cache
X-Content-Options
Referer-Policy
Node
X-N
Cross-Origin-Resource-Policy
X-Original-Request-Id
X-Response-Served-From
X-Cache-Control
Country
NGB
X-Magnolia-Registration
X-EdgeConnect-Cache-Status
X-Varnish-Server
X-Debug-IsPreview
X-Debug-IsConnected
X-Varnish-Age
X-Environment-Context
X-L-Path
X-Cache-TTL-Remaining
X-NYM-Debug-Backend
X-Instance
X-Real-IP
X-Rendered-As
X-Cacheable-TTL
Access-Control-Request-Headers
X-Content-Powered-By
X-Servername
X-Cache-Grace
X-Adobe-Loc
X-Is-Bot
X-G
VIX-Pulpo-Upstream-Status
Content-Disposition
VIX-Pulpo-Node
Viewport
X-Page-View
X-Adobe-Content
X-Status
Akamai-GRN
X-Yottaa-Metrics
X-Yottaa-Optimizations
Uber-Trace-Id
X-Whom
Url
X-ProcessESI
X-RemovedCookies
X-Framework
X-Mid
X-Akamai-Request-ID2
X-Jobs
X-Cache-Time
Srv
X-User-Agent
X-COUNTRY
X-Oracle-Dms-Ecid
X-Unique-Id
X-Via-JSL
X-Cache-Expired-At
X-Oracle-Dms-Rid
X-Drupal-Cache-Contexts
X-Trace-Id
Countrycode
X-CDN-Forward
X-XRDS-LOCATION
X-Cache-Hit
Version
X-Tumblr-Pixel-0
Accept-Language
X-Tumblr-Pixel-1
X-Tumblr-User
X-URL
X-Tumblr-Pixel
X-Cache-Operation
X-APP-VERSION
X-Time
X-Mg-Request-UUID
Healthy
X-Http-Reason
X-Ratelimit-Remaining
X-Content
X-Backend-Name
X-Debug-Info
X-Rule
X-Api-Version
Protected
X-App-Server
X-Akamai-Edgescape
Content-Secure-Policy
Section-Io-Cache
X-Cache-Action
X-Azure-Ref
X-Tt-Logid
X-IPLB-Request-ID
X-B3-Traceid
X-IPLB-Instance
X-Hosted-By
X-Server-ID
Backend
X-SRV
X-Restarts
X-VC-Cache
X-Generation-Time
X-Varnish-Ttl
Xserver
Server-Info
Meta-Geo
X-UPSTREAM-Address
Liferay-Portal
X-RN-RSRV
X-Generated-By
X-Storage
Load-Balancing
GEO-INFO
X-HTML-Minification-Powered-By
X-Device-Type
X-Mobile-URL
X-FW-Static
X-FW-Serve
X-FW-Hash
X-FW-Dynamic
X-Nginx-Cache-Key
X-FW-Server
X-FW-Type
X-Mode
X-Cache-Status-Check
CF-IPCountry
Web-Mar-Node
Locale
X-Varnish-Beresp-Grace
CDN-EdgeStorageId
X-Handled-By
X-Locale
Azure-Version
Azure-SlotName
X-Format
X-FireWall-Port
X-Access
S-Rt
X-Cms-Context
Azure-SiteName
Azure-RegionName
CDN-CachedAt
CDN-PullZone
CDN-RequestCountryCode
CDN-RequestId
CDN-Cache
X-Section
Azure-InstanceId
X-OCL
X-PCL
CDN-Uid
X-Adobe-Source
X-Say-Cacheable
X-Say-TTL
X-Sql-Count
X-Content-Age
X-SaId
X-Cache-Host
X-SayCDN-TTL
X-PHP-Host
Ms-Operation-Id
MS-CV
X-Forwarded-Host
X-Site-Version
X-Sql-Duration-Ms
X-Skip-Cache
X-Proxy-Cache-Status
X-RTag
X-Urbn-Context-Path
X-Labrador-Cache-Channel
X-JoinUs
X-Urbn-Site-Id
X-Redis-Cache
X-Edge-Location
X-Region
X-ShopId
X-Detected-As
Webcakes-App-Version
Webcakes-App-Name
X-LJ-Flow-ID
X-Sorting-Hat-ShopId
X-Proto
X-Sorting-Hat-PodId
X-Extlb
Webcakes-Region
X-Varnish-Hostname
X-Shopify-Stage
Apigw-Requestid
X-Routing-Service
X-No-Session
X-GeoCountry
X-AWS-Id
X-Proxied
X-Xfnlog-Site
X-Zipkin-Id
X-R9-Blue-Green-Version
X-Alternate-Cache-Key
TWC-Privacy
X-Varnish-Cache-Hits
X-GeoCode
X-Origin-Hint
X-ShardId
X-VWS-Id
Cache-Name
X-Web-Node
X-Cache-Server
X-Cache-Type
X-Via-Fastly
TWC-Locale-Group
Eomportal-Instance
Property-Id
Onion-Location
TWC-Connection-Speed
TWC-GeoIP-LatLong
TWC-GeoIP-Country
TWC-Device-Class
X-PHP-Backend
X-Server-W
X-Varnishpool
X-Amzn-RequestId
X-ProxyCache-Status
X-Tid
X-BYPASS-REASON
X-ProxyCache-Key
X-Storefront-Renderer-Rendered
X-UA-Device-Type
Mn-Server-Ip
X-Amz-Apigw-Id
X-Request-Time
X-Ms-Request-Id
WP-Super-Cache
X-Hl-Ver
X-Ms-Version
DB-Nickname
X-FB-TRIP-ID
X-Cache-Enabled
X-Uri
X-ServerID
X-Provided-By
Fastcgi-Useragent
X-Ratelimit-Limit
Selected-Fe
X-ECache
X-WP-CF-Super-Cache-Cache-Control
X-Timing-Wait
X-WP-CF-Super-Cache
X-Proxy-Build
X-DynaTrace-JS-Agent
X-Cache-NGX
X-TNCMS
X-Loop
X-Nginx-Cache
X-Vgn-Hpd-Reason
X-LSADC-Cache
X-Origin-Date
X-Pubstack
X-Ua
X-Amzn-Remapped-Content-Length
X-Datadome
X-Reqid
X-UUID
X-Soup
X-Zen-Fury
X-Tumblr-Pixel-2
Xet-Cookie
X-App-Version
X-Service
ServedBy
X-Correlation-ID
X-Aspnetmvc-Version
X-Dc
X-TA-CDN-Provider
X-GEO
X-Origin-TTL
X-Origin-CC
Origin
X-Webkit-CSP
X-Human
X-Varnish-Hits
X-MP-GENERATED-AT
Source
X-TIME
From-Origin
Cache
X-Newrelic-Synthetics
X-Cache-Debug
X-Cache-Tags
X-NewRelic-App-Data
X-Cached-By
Fastly-Drupal-HTML
Cross-Origin-Window-Policy
X-Varnish-Beresp-Ttl
X-RCS-CacheZone
X-Tec-Api-Root
X-Tec-Api-Origin
Webserver
X-Tec-Api-Version
Rip
WPO-Cache-Message
WPO-Cache-Status
LB
SD-X-WS
X-Debug-Cache
BehaviorPad-Version
Rendered-Blocks
MD5-Digest
X-ScT
X-Request-Host
X-D
X-Orig-Expires
X-Developer
DCR-Decision-By
X-Vdms-Path
X-Connection-Hash
X-Parent-Response-Time
Meta-Geo-Continent
X-Forwarded-Path
X-Cache-NE
DCR-Processing-Time-Ms
Lang
X-Vdms-Version
Expiry
X-Ec-GeoHdr
X-Ec-Fail
Ngx.Var.Host
Environment
Cdnsip
CPC-Age
Xc-Version
X-Destination
Cdncip
CPC-Cache
X-VG-WebCache
X-NAPM-TraceId
X-User
X-S-Cookie
X-A-Dgt
X-A-Dcw
X-S
X-Rojux
X-Rewrite-Enabled
X-A-Wwc
X-SRCache-Key
X-A-Dam
X-Shop-Environment
T-Server
VNS-Cache
Surrogated-Key
X-A-Ccd
X-A
X-Aed
X-External-Request-Id
VNS-Age
X-B-Cookie
X-ARC
X-Bc-Bl
X-BCube-Filmed-By
A
X-PBS-Appsvrname
Odigeo-Trace-Id
X-Processor
Sslversion
X-Application
X-Tenant
X-AK-Request-ID
X-TIM-N
Host-ID
Upgrade-Insecure-Requests
X-Cluster
Mime-Version
X-Aicache-OS
Redirect-Candidate
X-Dispatcher-Number
X-Owner
X-AOL-HN
X-Accel-Buffering
X-Origin-Time
X-Trace-ID
X-Gdpr
X-Served-From
X-Nyt-Route
OT-Force-Account-Verify
X-WP-CF-Super-Cache-Active
X-SVT-ORM-RULES
Producers
Platform
Servername
Req-Svc-Chain
State
Release
X-SVT-ORM-VERSION
Traceparent
Tube-Got-Results
Tube-Return
V-Age
Vix-Hermes-Req-Id
Tube-Got-Eval
Tube-Get-Contents
Svr
X-Slack-Backend
Origin-EX
X-Sn-Servicetimems
X-Varnish-CookieHashed-On
Fastly-SIE
Fastly-SSL
Fastly-SWR
Is-Eu
Fastly-GeoIP-CountryCode
X-VServer
Decoy-Debug-TTL
X-Wix-Viewer-Type
X-WADP-Cache
X-Viewer-Country
X-VG-TLSProxy
X-Varnish-CookieINHashed-On
X-SIPLIST1
Origin-CC
X-Varnish-Beresp-Status
NGX
Mobile-Detection-Method
IsBot
L
X-Varnish-Remaining-TTL
X-Variation
X-Scheme
X-Origin
X-DefElseHash
X-DefHash
X-NodeID
X-Core-Mission
X-Origin-Response-Time
X-Cache-Info
Decoy-Debug-Status
X-Cdn-Origin
X-Clara-WADP
X-NCache
X-Minions-Version
X-Gamma-Serve
X-Epic-Correlation-Id
X-Fmm-Version
X-Fastly-Backend
X-GeoIP-City
X-Gzip
X-Loc
X-DPWN-IS-SECURE
X-Ec-Custom-Error
X-Cache-Id
X-Planisys-CDN-Cache
X-Ad-Defer-Variation
X-Request-URI
X-Region-Sid
X-RateLimit-Remaining-Second
X-Rocket-Nginx-Serving-Static
X-S-Maxage
X-Esi-Check
X-Scale
X-SB
X-RateLimit-Limit-Second
X-Qloud-Router
X-BBC-Edge-Cache-Status
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-Cache-Bucket
X-Platform-Server
X-Azure-Ref-OriginShield
X-Proxy-Cache-Info
X-Pool
X-ATG-Version
Web-Mar-Region
Machine
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
Candidate-Md5Url
Click-Count-Action-Start
Apple-News-Services-Handled
Adler-Geo
Decoy-Debug-Key
X-Nf-Request-Id
X-FW-Version
Click-Count-Error
Apple-News-Services-Host
Country-Code
Cmsid
Cluster
CloudFront-Viewer-Country
Cmstype
X-Core-Value
X-Level-Front-Cache
X-Sucuri-ID
X-Sucuri-Cache
X-Cache-Remote
X-CMSURLCustom
X-Cdn-Srv
X-Is-Gdpr
X-Geo-Header
X-Generated-On
X-Developers
X-Tx-Id
X-Has-Esi
X-Thinkindot-L3
X-INCAP-ABP
X-HS-Content-Campaign-Id
X-JWT-State
X-Auto-Login
TDXMobile
Server-Host
Fastly-Backend-Name
AKAMAI
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
X-Worker
Thinkindot-Control
X-Eu-Site
X-Forwarded-Site
X-FC-Vary-Parameters
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
X-CGP
X-Gen-Mode
X-Datadog-Parent-Id
X-Csrf-Jwt
X-Optimistic-Header
X-Udemy-Cache-App-Namespace
X-Irp-Debug
X-Clientip
X-Hnp-Log
X-Var-Ttl
X-Gateway-Request-Id
X-Gateway-Skip-Cache
X-Gateway-Cache-Status
X-Gateway-Cache-Key
X-Fetched-On
X-GeoIP
X-Hash
X-SplitTest
X-V-Cache
X-Sigma-Backend
X-Sigma
X-Rocket-Build-Number
X-Device-Os
X-Cluster-Node
Datacenter
Kp-EeAlive
X-CacheTTL
X-Thanos
X-IPS-LoggedIn
Memcached
NM-Fastcgi-Cache
X-Branch-Name
X-Ckpd-Fst-Backend
Wxu-Next-Region
Wxu-Next-Hostname
Wxu-Next-Commit
X-Policy
X-Mvc-Supplant-Cachable
Server-Hostname
HA-Ipaddr
User-Cache-Control
Ha-Gx-Prefs
Gh-Request-Id
DSUID
Sever-Int
CDCHOST
X-Bip
L5d-Success-Class
Mail-Subject
Server-Ext
X-Block-Status
Cache-Host
We-Hiring
X-Esi
X-Mvc-Supplant-OutputCached
X-CSRF-Token
X-LB-NoCache
HostName
Canary
WebServer
X-Pass-Why
X-VC
Ec-Rule-Version
X-ND-Cache
X-Up
Pics-Label
X-B3-SpanId
X-Via-NSCOPI
X-Tumblr-Pixel-3
X-GG-Cache-Date
Time
Memory
Sid
X-WA-Info
Cache-Tv-Group
X-Presslabs-Stats
X-Akamai-Transformed
X-Via-Poph
Ssr
X-Via-Popn
X-Newrelic-App-Data
Request-ID
X-Via-Popv
X-Dispatch
Fastcgi-Cache-TTL
SID
AMP-Access-Control-Allow-Source-Origin
X-Tb-Optimization-Total-Bytes-Saved
My-App
X-Refresh
X-CACHE-AGE
X-Session-Fingerprint
Server-ID
Cache-Hits
X-Servedbyhost
Env
X-ZONE
X-Edge-Pop
X-Rebelmouse-Cache-Control
X-Origin-Expires
X-Zone
X-Wa
X-Pod-Name
X-Rebelmouse-Surrogate-Control
X-DC
X-Fastly-Cache
X-Release
X-Lambda-Id
X-Cs
X-B3-Spanid
X-Generated-In
X-Fpc
X-Req
X-PX
X-NWS-UUID-VERIFY
GeoIp-Country-Code
X-LB-ID
True-Client-Country-4JS
X-ID
X-NGINX-Cache
X-Vc
X-EC-Lua
X-MSEdge-Flight
X-VCL-Version
X-Ig-Push-State
X-CSRF-TOKEN
True-Client-IP
X-MSEdge-Features
X-MCACHE
CacheControlHeader
Hostname
X-Xrds-Location
X-Cache-Date
X-Buckets
X-Conf
X-TX-ID
X-Op-Id-All
X-Endurance-Cache-Level
X-NC
X-Microcachable
X-Webkit-CSP-Report-Only
X-CS
CDN
X-TH-Server
X-CACHE-KEY
X-RateLimit-Reset
X-GeoIP-Country-Code
X-Dmc
X-GeoIP-Region-Code
X-TRACE-ID
Resin-Trace
X-Date
X-HS-Status
WWW-Authenticate
X-Accel-Expires-Debug
Magicmarker
Path
X-Srv
X-RAMCache
X-Vcl-Version
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-Old-Content-Length
Tcn
Fastly-Drupal-Html
X-Be
True-Client-Ip
X-Varnish-Beresp-TTL
X-Check-Cacheable
X-Vercel-Id
X-Vercel-Cache
Powered-By
X-LiteSpeed-Cache-Control
Section-Io-Id
X-Alfa-Service
Section-Io-Origin-Status
Proxy-Connection
Section-Origin-Responded
Section-Io-Origin-Time-Seconds
X-Akamai-Pragma-Client-IP
GeoIP-Country-Code
X-Hyper-Cache
Pramga
X-CLOUD-TRACE-CONTEXT
X-Cache-Ttl
Yjs-Id
X-FPC
X-Datacenter
X-M-Reqid
X-Micro-Cache
X-M-Log
X-Webstats-RespID
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-API-Version
X-Qnm-Cache
X-App
X-Via-CDN
X-Geo
FSS-Cache
X-Location
X-Mly-Id
X-Director
X-Lb-Id
Tracecode
X-WA
X-Dw-Trace-Id
YJS-ID
X-Varnish-Authentication
X-Air-Hostname
X-Air-Source
X-Air-Trace-Id
X-Contensis-Viewer-Groups
X-Edge-POP
X-Cache-ASPX
Lb
User-Agent
ENV
X-ServedByHost
Server-Id
X-Response-By
X-Air-Pt
C-Via
X-DataCenter
X-Cdn-Forward
X-Via-PopH
X-TrackingId
HIT
X-Platform-Router
X-Via-PopV
X-Client-Ip
X-Akamai-ERPolicy
X-Server-IP
N-Cache
Cdn
X-UA
X-HA-Backend
X-Via-PopN
X-Platform-Processor
X-Akamai-ERRuleID
X-Platform-Cluster
X-AIR-PT
Sm-Log-Id
X-SERVER-NAME
X-Service-Response-Time
X-Test
X-FL-EDGE
X-From
Srvid
Locid
X-Instance-Name
Swift-Performance
X-Fastly-Backend-Reqs
X-Traceid
X-Cache-Expires
X-Cache-Backend
M-TraceId
Location
X-PAYTM-SRV-ID
X-Platform
X-TT-LOGID
Geoip-Latitude
X-Li-Fabric
Fastcgi-X-Cache-Version
Hit
On-Server
Esi-Enabled
NtCoent-Length
X-Li-Pop
Dnion-Transfer-Encoding
X-LI-UUID
X-LI-Proto
X-LiteSpeed-Tag
X-FORWARDED-FOR
X-CUA
X-RSL
Ohc-File-Size
X-DSS
X-We-Are-Hiring
X-DI
PICS-Label
X-RPS
CountryCode
Nginx-CQVIP
Uri
XServer
X-DB
X-DW
X-RPM
X-Wp-Cf-Super-Cache
X-Edge-Origin-Shield-Bytes
X-Edge-Origin-Shield-Region
X-Wp-Cf-Super-Cache-Cache-Control
X-Cc-Via
X-Litespeed-Cache-Control
X-Request-Url
X-Fastly-Cache-Hits
X-HostName
X-B3-Parentspanid
X-Lb-Nocache
Wpo-Cache-Status
X-Conten-Type-Options
X-CF-Powered-By
X-Cdn-Request-ID
Wpo-Cache-Message
XM
X-PERF
X-Vtex-Remote-Cache
X-Vtex-Processado-Em
X-Fastly-Country-Code
X-Node-Id
X-B3-ParentSpanId
X-ApacheServer
GeoIP-Latitude
X-Cache-Proxy
X-Info
Vha6-Origin
Warning
X-Cache-Ngx
Wp-Super-Cache
X-Ips-Loggedin
X-Loadbalancer
X-Matome-Cached
X-N-OperationId
X-MTS-Cache
X-Matched-Rule
X-LbNode
X-Ittl
X-Is-SSL
X-Kebab
X-Kebabable
X-Keep
X-Origin-Ops
X-Nerd
X-Ntj-Investigation-Id
X-Okws-Version
X-Odoo-Frontend
X-Nyt-Data-Last-Modified
X-NS-Authorization
X-NFL-Geo
X-NXG
X-Newegg-Flow
X-Newegg-Index
X-NFL-Dma
X-Onedio-Env
X-Farm
X-Eid
X-Ee-Request-Id
X-ETag
X-Doge
X-Developed-By
X-Ee-Request-Date
X-Ee-Origin
X-DT-Node
X-Edge-IP
X-OVcl
X-Ee-Generated-By
X-Eventloop-Lag
X-F-Status
X-GoCache-CacheStatus
X-Global-Transaction-ID
X-Group
X-Header-Sub
X-IBD-Cache
X-Git-Commit
X-GG-Cache-Status
X-Fastly-Is-Edge
X-Frame-Option
X-Fstrz
X-Full-Ttl
X-IBD-SID
X-Toujours-Debout-Location
X-Utime
X-User-Auth
X-V2-Infrastructure
X-Vary-Devices
X-Ver
X-Upstream-State
X-U-Cache
X-Toujours-Debout-Branch
X-Timestamp
X-Delivery
X-Tried-To-Kebabify
X-True-Client-Ip
X-Wag-Acs
X-Waitingroom
Timeexpire
XV-H
PFcat
X-HN
X-VarnishDD-TTL
XV-Cache
X-YSpaceId
X-Web-Hosting
X-WP-Bypass
X-WSR2
X-Xms-Page-Cache-Actions
X-Test-Nginx-Ingress
X-Svr-Proxy
X-Render-Method
X-Redis
X-Render-Time
X-Request-Origin
X-Route
X-Reboot
X-R-Cache
X-Paywall
X-PageType
X-PG-ACCESS
X-PGF-Deflate
X-Pver
X-Route-Akamai
X-Ruby
X-Square
X-SMP-JWT
X-SSLProxy
X-Stack-Name
X-SVR-IIS
X-Slack-Shared-Secret-Outcome
X-Site
X-Save-Cache
X-Server-L
X-ServiceName
X-Sh
X-OVcl-Cache
X-Ar-Stats
Nikkei-App-Version
NB-ESI
NLCacheNote
Npm-Cost
Npm-Remaining
Joe-X
Is-Https
Ec-Policy-Id
Deeplink
H1
HServer
HTTPProtocol
Ns
Ns-Ua
Request-Uuid
Region
Rt-Proxy-Cache
Scheme
Selected-Route
RawURL
Proxy-Cache
OK-Edge-Date
Ok-Cache-Status
Ok-Edge-Key
Origin-Site
Panzer-Cache-Control
CMS-200
Cluster-Host
DynaTrace
X-LAGOON
WZWS-RAY
X-Mg-Cache
X-ElasticPress-Query
X-SD-PageType
SRV
Req-ID
Fastcgi-Cache-Ttl
X-Request-Start
X-Moov-Xdn-Version
X-Moov-T
X-Yottaa-OS
CF-Cached-On
Cdn-Country-Code
Cachekey
Cf-Device-Type
Cf-Locale
Cf-Wrk
Cache-Stat
Akamai-X-Url
X-IN-APIGATEWAYSSL
X-IN-APIGATEWAY
Cneonction
X-Serial
X-Th-Server
Served
Service-Uuid
X-BeanStalkRole
X-Backside-Transport
X-BeanStalkStage
X-Cache-Cookie
X-Cache-IsMobileDevice
X-Backend-TTL
X-AspNetWebPages-Version
X-Apache-Server
X-Amz-Meta-Cb-Modifiedtime
X-Arena-Request-Id
X-ARRRG1
X-ASF-Cache
X-Cache-Length
X-Cache-NPR
X-Coindesk-Cache
X-Cms-Device
X-Colour
X-Container-Uri
X-Dcm-Pdtf
X-Cf-Node-Idx
X-CDN-Pop-IP
X-Cache-ReqUri
X-Cache-Reason
X-Cache-Response
X-CacheVersion
X-CDN-Pop
X-Akamai-Native
X-Akamai-DeviceType
Ttl
Time-Cloud-Cache
TWC-AK-Req-ID
TWC-PATH-LOCALE
TWC-Subs
Technodrome
T-Request-Id
Shieldsquare-Response
SFRVia
SII
Store-Cloud-Cache
Sw
TWC-Unit
Uniqueid
X-Accor-Asset
X-Accepted-Language
X-AEO-Platform
X-Akamai-CacheKeyMod
X-Akamai-DeviceOS
X-Accepted-Fulllang
X-Accel-Version
Userver
Vttl
X-77-NZT
X-77-NZT-Ray
X-Dehri-Date