Threat Level: green Handler on Duty: Guy Bruneau

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
Strict-Transport-Security
X-Frame-Options
X-Content-Type-Options
Link
Last-Modified
CF-Cache-Status
Cf-Request-Id
CF-RAY
Accept-Ranges
ETag
Expect-CT
Pragma
X-Powered-By
X-Cache
Via
Age
X-XSS-Protection
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
X-Xss-Protection
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-FRAME-OPTIONS
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Request-Id
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-Adblock-Key
X-AspNet-Version
X-Permitted-Cross-Domain-Policies
Alt-Svc
X-Runtime
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Cache-Status
X-Check
X-Generator
X-DNS-Prefetch-Control
X-Request-ID
X-Cacheable
X-Iinfo
X-Envoy-Upstream-Service-Time
Feature-Policy
Timing-Allow-Origin
X-Content-Security-Policy
Status
X-Drupal-Dynamic-Cache
Content-Encoding
Access-Control-Expose-Headers
X-AspNetMvc-Version
P3p
X-CDN
Upgrade
X-Ua-Compatible
Access-Control-Max-Age
CF-Ray
X-Dns-Prefetch-Control
X-Via
X-Robots-Tag
X-Cache-Group
X-UA-Device
Server-Timing
Keep-Alive
Request-Context
X-AH-Environment
X-Turbo-Charged-By
X-Amz-Request-Id
X-Proxy-Cache
X-Backend
X-Amz-Id-2
X-Age
X-Ws-Request-Id
Host-Header
X-Hacker
X-Server-Powered-By
X-Server
X-Rq
X-Vhost
X-LiteSpeed-Cache
X-Varnish-Cache
X-Amz-Version-Id
Grace
Cf-Edge-Cache
X-Dispatcher
Allow
EagleId
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
X-Page-Speed
X-Nginx-Cache-Status
Accept-CH
X-WebKit-CSP
X-Aws-Lambda-Call-Status
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
Cf-Railgun
X-Node
X-Host
X-OneAgent-JS-Injection
X-Pingback
X-Cache-Spec
X-Backend-Server
X-Akam-SW-Version
X-Server-Id
Surrogate-Control
Request-Id
X-Cache-Lookup
X-Response-Time
EagleEye-TraceId
Accept-CH-Lifetime
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Readtime
Content-Location
X-HW
X-Cloud-Trace-Context
X-Content-Security-Policy-Report-Only
Rating
X-Application-Context
X-Trace
Fastly-Restarts
X-WebKit-CSP-Report-Only
X-Url
X-Clacks-Overhead
X-Nginx-Upstream-Cache-Status
X-CST
X-Ruxit-Js-Agent
X-MS-InvokeApp
X-Edge
X-Amz-Server-Side-Encryption
X-Rack-Cache
X-Mod-Pagespeed
X-Country
X-TtlSet
X-Vname
X-PC
Accept-Ch-Lifetime
X-Content-Type
X-ESI
X-B3-TraceId
Edge-Control
Cf-Apo-Via
X-Vcap-Request-Id
X-FastCGI-Cache
X-Oneagent-Js-Injection
X-Akamai-Path-Stats
X-Mcache
X-D2id
Verso
X-GitHub-Request-Id
Xkey
Cache-Tag
X-Cdn-Fetch
X-Kinja-Build
X-Kinja-Revision
X-Kinja
X-GoogleNews-Bot
X-Use-Magma
X-Exp-Variant
X-Kinja-Server
X-Exp-Id
Service-Worker-Allowed
X-Powered-By-Plesk
X-Amz-Rid
X-Ttl
X-Server-Name
X-Navigation-Version
RTSS
X-Abt-Application-Version
X-VARITI-CCR
X-Ruxit-JS-Agent
X-Client-IP
X-Version
X-Ac
X-Cnection
X-Varnish-TTL
X-Upstream
X-ECACHE
X-Element-Page-Cache
X-Cached
Arr-Disable-Session-Affinity
Permissions-Policy
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Instrumentation
X-RateLimit-Remaining
X-Dw-Request-Base-Id
SPRequestGuid
X-SharePointHealthScore
X-Px
X-Cache-TTL
X-Middleton-Display
X-Sol
Display
Pagespeed
SPRequestDuration
SPIisLatency
Public-Key-Pins
X-NWS-LOG-UUID
X-Country-Code
Response
X-Middleton-Response
X-Midtier
X-Cache-Key
X-Edge-Location-Klb
X-Kinsta-Cache
X-Ser
X-Forwarded-For
X-DataDome
X-Goog-Hash
Content-MD5
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Correlation-Id
X-NF-Request-ID
X-Shield-Request-Id
X-RateLimit-Limit
X-MSEdge-Ref
Access-Control-Request-Method
X-HP-Trace-Id
X-ORACLE-DMS-ECID
X-Jurisdiction
X-HP-Webp
Front-End-Https
X-ORACLE-DMS-RID
MRF-Tech
Mrf-Cache-Status
X-B3-TraceId-Primal
AR-PoweredBy
AR-CACHE
AR-ATIME
X-T
X-Recruiting
AR-Request-ID
AR-SID
X-Daa-Tunnel
Edge-Cache-Tag
MicrosoftSharePointTeamServices
TP-L2-Cache
TP-Cache
Nginx-Cache
X-Webkit-Csp
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Browser-Type
X-Mg-S
X-Accel-Expires
Accept-Ch
X-Content-Digest
TCN
X-Grace
X-Hits
X-Powered-CMS
X-Request-Processing-Time
X-Request-Received
X-Amzn-Trace-Id
X-HS-Hub-Id
X-HS-Content-Id
Server-Node
X-HS-Combine-CSS
X-HS-Cache-Config
Filters
Server-Name
X-Id
MS-Author-Via
Fastcgi-Cache
X-Geo-Country
Count-Hit
X-XRDS-Location
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
X-Fastly-Request-Id
X-Origin-Server
X-Frontend
X-Ua-Browser
X-Ezoic-Cdn
X-Distributor
Filterid
Cross-Origin-Opener-Policy
X-PressLabs-Stats
X-LLID
X-Request-Handler-Origin-Region
X-Seen-By
X-Protected-By
X-Forwarded-Proto
X-Microsite
X-F-Cache
X-Language
X-Git-Hash
Payment
S
Charset
Host
X-LB-Cache
X-B3-Sampled
X-Page-Id
X-FB-Debug
X-Ratelimit-Reset
X-Amz-Meta-S3cmd-Attrs
X-VCache
X-ASPNET-VERSION
X-Cluster-Name
X-Rid
Cache-Status
Surrogate-Key
X-Www-Served-By
Cache-Tags
X-Logged-In
Access-Control-Allow-Method
X-Upgrade-Enabled
X-DIS-Request-ID
X-Ab
X-Source
X-Origin-Cache
Retry-After
Realpath
Alternate-Protocol
X-Cdn
X-Varnish-Backend
X-AppVersion
X-Az
Accept-Charset
X-Activity-Id
Cleartype
X-COUNTRY
X-Cache-Age
Paypal-Debug-Id
X-Amz-Replication-Status
X-Type
X-NGENIX-Cache
DC
X-Flags
X-Request-Guid
X-Is-Crawler
X-Wix-Request-Id
X-Varnish-Grace
X-App-Environment
X-Route-Name
X-Aspnet-Duration-Ms
X-Providence-Cookie
X-Signature
X-Tb
X-B-Cache
X-Template
X-Envoy-Decorator-Operation
X-TT
X-B
X-Revision
X-Hostname
X-DynaTrace
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
ServerID
X-Contextid
Frame-Options
X-Cache-Rule
X-Fastcgi-Cache
X-Drupal-Cache-Tags
X-Node-Name
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Fastly-Request-ID
Pinterest-Version
Pinterest-Generated-By
X-Pinterest-Rid
Cross-Origin-Resource-Policy
Amp-Access-Control-Allow-Source-Origin
Refresh
X-Trace-Id
X-Goog-Storage-Class
X-GUploader-UploadID
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Metageneration
X-Goog-Generation
Referer-Policy
X-Proxy
X-Mobile
X-Debug
X-Load-Cache
Node
X-Content-Options
X-Varnish-Server
Viewport
NGB
X-Response-Served-From
X-EdgeConnect-Cache-Status
X-Original-Request-Id
X-Cache-Control
X-N
X-XRDS-LOCATION
Country
X-Varnish-Age
Akamai-GRN
X-NYM-Debug-Backend
X-Cache-Time
X-Whom
X-Content-Powered-By
X-Debug-IsConnected
X-TTL
X-Debug-IsPreview
X-Instance
X-Magnolia-Registration
X-Page-View
X-Is-Bot
X-G
X-Rendered-As
X-Adobe-Content
X-Status
Uber-Trace-Id
Content-Disposition
X-Adobe-Loc
Access-Control-Request-Headers
X-Real-IP
X-RemovedCookies
X-Servername
X-Environment-Context
X-ProcessESI
X-Akamai-Request-ID2
Url
X-Cache-Grace
X-Cacheable-TTL
X-L-Path
X-Framework
VIX-Pulpo-Node
X-Yottaa-Optimizations
X-User-Agent
X-Jobs
VIX-Pulpo-Upstream-Status
X-Yottaa-Metrics
Srv
X-Cache-Expired-At
X-Cache-TTL-Remaining
X-Via-JSL
X-Mid
Healthy
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-Cache-Hit
X-Tumblr-User
X-CDN-Forward
X-Rule
X-Cache-Operation
Countrycode
X-APP-VERSION
X-Unique-Id
X-Drupal-Cache-Contexts
X-Backend-Name
Version
Accept-Language
X-Debug-Info
X-Akamai-Edgescape
X-Oracle-Dms-Ecid
Section-Io-Cache
X-Litespeed-Cache
X-Cache-Action
X-VC-Cache
X-ECache
X-Http-Reason
X-Oracle-Dms-Rid
X-Mg-Request-UUID
Content-Secure-Policy
X-Tt-Logid
X-Hosted-By
Protected
X-Server-ID
X-IPLB-Instance
X-IPLB-Request-ID
X-Varnish-Ttl
Xserver
X-Generation-Time
X-FW-Type
Backend
X-FW-Static
X-Generated-By
X-HTML-Minification-Powered-By
X-Azure-Ref
X-FW-Hash
X-FW-Serve
X-FW-Server
Server-Info
X-FW-Dynamic
X-Time
X-RN-RSRV
X-Cache-Status-Check
X-UPSTREAM-Address
Meta-Geo
X-Storage
X-Amzn-RequestId
Ms-Operation-Id
X-Amz-Apigw-Id
X-RTag
MS-CV
X-Cms-Context
X-Access
Webcakes-Region
X-OCL
X-Handled-By
Webcakes-App-Version
Onion-Location
X-Varnish-Cache-Hits
X-SRV
X-Format
X-Mode
Azure-SiteName
Azure-Version
Azure-SlotName
X-PCL
Liferay-Portal
TWC-Connection-Speed
X-Section
Property-Id
TWC-Device-Class
TWC-GeoIP-Country
Azure-InstanceId
X-Origin-Hint
TWC-Privacy
Azure-RegionName
TWC-GeoIP-LatLong
TWC-Locale-Group
Webcakes-App-Name
Web-Mar-Node
X-FireWall-Port
CF-IPCountry
X-Adobe-Source
X-AWS-Id
X-Cache-Server
X-Say-TTL
X-PHP-Host
X-Provided-By
X-SayCDN-TTL
X-Api-Version
X-LJ-Flow-ID
X-Sql-Count
X-Server-W
X-VWS-Id
X-Mobile-URL
X-R9-Blue-Green-Version
X-Proto
GEO-INFO
X-Labrador-Cache-Channel
X-SaId
X-Redis-Cache
X-Locale
X-App-Server
X-JoinUs
X-Proxy-Cache-Status
X-Varnish-Hostname
X-Say-Cacheable
X-Sql-Duration-Ms
X-PHP-Backend
X-No-Session
X-Urbn-Site-Id
X-Via-Fastly
X-Varnish-Beresp-Grace
CDN-CachedAt
CDN-Cache
CDN-EdgeStorageId
Locale
X-Xfnlog-Site
X-Urbn-Context-Path
X-Varnishpool
CDN-PullZone
CDN-RequestId
X-Edge-Location
X-Detected-As
X-Content-Age
X-Cache-Type
X-FB-TRIP-ID
X-Forwarded-Host
X-GeoCountry
X-Web-Node
X-GeoCode
X-Cache-Host
X-Site-Version
X-Device-Type
Eomportal-Instance
X-Region
Mn-Server-Ip
X-Restarts
CDN-Uid
DB-Nickname
X-Skip-Cache
X-Request-Time
CDN-RequestCountryCode
X-Hl-Ver
X-ProxyCache-Status
X-Ms-Version
X-UA-Device-Type
X-ShardId
X-Alternate-Cache-Key
X-ProxyCache-Key
X-Proxied
X-Zipkin-Id
Cache-Name
X-DynaTrace-JS-Agent
X-ShopId
X-Shopify-Stage
X-Routing-Service
X-Extlb
X-BYPASS-REASON
S-Rt
Apigw-Requestid
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Ms-Request-Id
WP-Super-Cache
X-Storefront-Renderer-Rendered
X-Tid
X-Dc
X-Vgn-Hpd-Reason
X-Timing-Wait
X-Tec-Api-Root
X-Tec-Api-Version
X-TIME
X-Amzn-Remapped-Content-Length
X-Proxy-Build
Selected-Fe
X-Tec-Api-Origin
X-Nginx-Cache-Key
X-Newrelic-Synthetics
X-LSADC-Cache
X-Loop
X-TNCMS
X-ServerID
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
X-Reqid
X-Cache-Enabled
Xet-Cookie
X-Content
Load-Balancing
X-Ua
X-Pubstack
X-Soup
X-Tumblr-Pixel-2
X-Origin-TTL
X-Uri
X-Origin-CC
X-B3-Traceid
X-Zen-Fury
X-TA-CDN-Provider
X-Service
From-Origin
X-Cache-Debug
X-MP-GENERATED-AT
X-Correlation-ID
X-Cache-NGX
X-Origin-Date
Fastcgi-Useragent
X-Aspnetmvc-Version
X-Ratelimit-Remaining
Source
X-Varnish-Hits
X-GEO
X-Webkit-CSP
X-UUID
X-Nginx-Cache
ServedBy
Origin
X-URL
X-Human
X-App-Version
Cache
X-NewRelic-App-Data
Fastly-Drupal-HTML
X-Cache-Tags
Upgrade-Insecure-Requests
SD-X-WS
X-Rewrite-Enabled
X-Varnish-Beresp-Ttl
X-Cached-By
X-Cluster
Rip
BehaviorPad-Version
Cross-Origin-Window-Policy
MD5-Digest
Rendered-Blocks
X-ScT
X-Ratelimit-Limit
Host-ID
Mime-Version
X-SRCache-Key
X-ARC
X-BCube-Filmed-By
X-S
X-S-Cookie
X-Application
Expiry
X-B-Cookie
Ngx.Var.Host
Cdncip
Lang
DCR-Decision-By
Cdnsip
DCR-Processing-Time-Ms
Meta-Geo-Continent
X-AK-Request-ID
X-A-Ccd
X-A-Dam
X-A-Dcw
Sslversion
Surrogated-Key
T-Server
X-Vdms-Version
X-VG-WebCache
X-A
X-User
X-A-Dgt
Xc-Version
X-Vdms-Path
A
Odigeo-Trace-Id
X-Tenant
X-Aed
X-A-Wwc
X-FW-Version
X-TIM-N
X-Shop-Environment
X-Bc-Bl
X-Developer
X-NAPM-TraceId
X-D
X-Processor
X-Ec-Fail
X-Forwarded-Path
X-External-Request-Id
X-Ec-GeoHdr
X-Connection-Hash
X-Destination
X-Cache-NE
X-Orig-Expires
X-PBS-Appsvrname
X-Rojux
X-Parent-Response-Time
X-Request-Host
X-Tumblr-Pixel-3
WPO-Cache-Message
OT-Force-Account-Verify
WPO-Cache-Status
X-Cluster-Node
X-Aicache-OS
Webserver
X-Accel-Buffering
Redirect-Candidate
X-Gdpr
X-Origin-Time
X-Served-From
X-Nyt-Route
Environment
X-CMSURLCustom
X-Cdn-Srv
X-Core-Value
X-Pass-Why
Fastly-Backend-Name
X-Developers
TDXMobile
Thinkindot-CacheControl-Type
Thinkindot-Control
X-Auto-Login
X-Level-Front-Cache
X-Sucuri-Cache
AKAMAI
X-Sucuri-ID
X-Thinkindot-L3
X-Worker
X-JWT-State
X-Is-Gdpr
X-Geo-Header
X-Has-Esi
X-HS-Content-Campaign-Id
X-INCAP-ABP
X-Generated-On
Thinkindot-CacheControl
X-Cache-Remote
X-WP-CF-Super-Cache-Active
X-RCS-CacheZone
X-Sigma
NGX
X-Rocket-Build-Number
X-Sigma-Backend
X-NodeID
X-ATG-Version
X-SplitTest
NM-Fastcgi-Cache
X-NCache
X-Azure-Ref-OriginShield
X-Request-URI
Platform
Origin-EX
Origin-CC
X-BBC-Edge-Cache-Status
Mobile-Detection-Method
Producers
Memcached
Fastly-SSL
Fastly-SWR
Gh-Request-Id
Fastly-SIE
Fastly-GeoIP-CountryCode
X-Cache-Id
X-Rocket-Nginx-Serving-Static
X-Cache-Bucket
X-Owner
X-Origin-Response-Time
Machine
X-SIPLIST1
X-DefElseHash
X-Ckpd-Fst-Backend
L
Is-Eu
IsBot
Kp-EeAlive
X-Clara-WADP
X-Device-Os
X-Gzip
Web-Mar-Region
X-Cache-Info
Wxu-Next-Commit
Servername
Wxu-Next-Region
Wxu-Next-Hostname
Req-Svc-Chain
Tube-Return
Tube-Got-Results
X-Qloud-Router
Traceparent
Tube-Get-Contents
X-Proxy-Cache-Info
X-Loc
X-RateLimit-Remaining-Second
Tube-Got-Eval
Release
X-GeoIP-City
X-Ec-Custom-Error
X-Platform-Server
X-S-Maxage
X-AOL-HN
X-DPWN-IS-SECURE
X-RateLimit-Limit-Second
X-Dispatcher-Number
X-SB
X-Epic-Correlation-Id
X-Minions-Version
X-Pool
X-GeoIP
X-Fmm-Version
X-Fetched-On
X-Esi-Check
X-Ad-Defer-Variation
X-DefHash
Adler-Geo
Apple-News-Services-Request-Url
X-Varnish-CookieINHashed-On
Apple-News-Services-Handled
X-Varnish-Remaining-TTL
X-Varnish-CookieHashed-On
Cluster
X-Varnish-Beresp-Status
Click-Count-Action-Start
Click-Count-Error
CloudFront-Viewer-Country
X-Wix-Viewer-Type
Datacenter
Decoy-Debug-Status
Decoy-Debug-TTL
Apple-News-Services-Host
X-Variation
Apple-News-Services-Parsed-Url
X-VG-TLSProxy
X-VServer
X-WADP-Cache
X-Viewer-Country
Decoy-Debug-Key
Candidate-Md5Url
Server-Host
X-Tx-Id
X-Optimistic-Header
WebServer
X-Cdn-Origin
X-Origin
X-Branch-Name
X-Clientip
X-IPS-LoggedIn
We-Hiring
VNS-Cache
X-Scale
DSUID
X-Bip
X-CGP
X-Block-Status
X-Eu-Site
X-Hnp-Log
X-Hash
X-Gen-Mode
X-Gateway-Skip-Cache
X-Region-Sid
X-Irp-Debug
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Mvc-Supplant-Cachable
X-Policy
X-Gateway-Request-Id
X-Gateway-Cache-Status
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
X-Csrf-Jwt
VNS-Age
X-Fastly-Backend
X-Gateway-Cache-Key
X-Gamma-Serve
X-FC-Vary-Parameters
X-Core-Mission
X-Forwarded-Site
State
X-Thanos
X-SVT-ORM-VERSION
X-Planisys-CDN-Cache
X-Sn-Servicetimems
Ha-Gx-Prefs
X-V-Cache
X-SVT-ORM-RULES
Server-Hostname
Mail-Subject
Server-Ext
Sever-Int
X-Var-Ttl
X-Scheme
HA-Ipaddr
User-Cache-Control
L5d-Success-Class
Vix-Hermes-Req-Id
CDCHOST
Cmstype
V-Age
Cmsid
Country-Code
Canary
Cache-Host
CPC-Age
X-Slack-Backend
CPC-Cache
LB
X-Debug-Cache
X-Udemy-Cache-App-Namespace
X-Presslabs-Stats
X-Dispatch
X-LB-NoCache
X-CacheTTL
Memory
Ec-Rule-Version
Time
Svr
X-Mvc-Supplant-OutputCached
X-Up
X-Akamai-Transformed
X-CSRF-Token
Sid
X-Newrelic-App-Data
Pics-Label
X-Nf-Request-Id
X-Tb-Optimization-Total-Bytes-Saved
Ssr
X-Edge-Pop
X-B3-Spanid
HostName
X-ZONE
Request-ID
X-Req
X-VC
AMP-Access-Control-Allow-Source-Origin
Env
X-ND-Cache
My-App
X-Servedbyhost
X-Cs
X-Wa
X-Via-Popv
X-Via-Popn
X-Via-Poph
True-Client-Country-4JS
X-NGINX-Cache
X-Refresh
X-Generated-In
X-Lambda-Id
X-Vc
Cache-Tv-Group
X-WA-Info
GeoIp-Country-Code
X-B3-SpanId
CacheControlHeader
Server-ID
X-Trace-ID
X-Via-NSCOPI
Fastcgi-Cache-TTL
X-Datadome
X-GG-Cache-Date
SID
Hostname
X-Op-Id-All
True-Client-IP
X-Session-Fingerprint
X-PX
X-CACHE-AGE
X-EC-Lua
X-Zone
X-Fpc
X-Rebelmouse-Surrogate-Control
X-Release
X-Fastly-Cache
X-Origin-Expires
X-Pod-Name
X-Rebelmouse-Cache-Control
X-ID
Cache-Hits
X-VCL-Version
X-GeoIP-Region-Code
X-GeoIP-Country-Code
X-CSRF-TOKEN
X-LB-ID
X-Xrds-Location
X-NWS-UUID-VERIFY
X-TX-ID
X-Webkit-CSP-Report-Only
X-TH-Server
X-Date
WWW-Authenticate
X-Accel-Expires-Debug
X-DC
X-Buckets
X-CACHE-KEY
X-Old-Content-Length
X-MSEdge-Flight
X-Ig-Push-State
X-MSEdge-Features
X-Cache-Date
X-Srv
X-RAMCache
X-TRACE-ID
Resin-Trace
X-HS-Status
X-Endurance-Cache-Level
CDN
X-Conf
Fastly-Drupal-Html
X-NC
X-Microcachable
X-Esi
X-Dmc
X-CS
Powered-By
X-RateLimit-Reset
X-Varnish-Beresp-TTL
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
X-Location
X-Webstats-RespID
Section-Io-Id
Section-Io-Origin-Status
X-Vcl-Version
Path
X-MCACHE
Tcn
X-API-Version
X-Director
Magicmarker
X-Lb-Id
X-Contensis-Viewer-Groups
X-Varnish-Authentication
X-DataCenter
X-Cache-ASPX
X-Akamai-Pragma-Client-IP
True-Client-Ip
X-FPC
X-CLOUD-TRACE-CONTEXT
X-Cache-Ttl
Yjs-Id
X-Check-Cacheable
X-LiteSpeed-Cache-Control
X-Wikidot-Backend
GeoIP-Country-Code
X-Datacenter
X-Test
X-Wikidot-Static-Cache
X-Alfa-Service
X-WA
X-Mly-Id
X-Geo
Proxy-Connection
X-Vercel-Id
M-TraceId
X-Via-CDN
X-Vercel-Cache
X-Cache-Backend
Lb
X-Be
Cdn
X-Cache-Expires
FSS-Cache
Server-Id
X-Cc-Via
X-ApacheServer
YJS-ID
X-PERF
X-Via-PopH
X-ServedByHost
X-Via-PopV
X-Via-PopN
X-Micro-Cache
X-We-Are-Hiring
Uri
ENV
X-Hyper-Cache
X-Server-IP
X-HA-Backend
User-Agent
X-Response-By
Pramga
X-Dw-Trace-Id
X-Cdn-Forward
X-M-Reqid
X-CF-Lambda-Version
XServer
X-Frame-Option
X-Client-Ip
X-CF-Lambda-Fn
XM
X-Info
HIT
X-M-Log
Sm-Log-Id
X-Service-Response-Time
X-Edge-POP
X-AIR-PT
X-Traceid
X-LI-Proto
X-Instance-Name
Location
X-Qnm-Cache
X-LI-UUID
X-Akamai-ERRuleID
X-Li-Pop
X-From
Tracecode
X-UA
X-TrackingId
Dnion-Transfer-Encoding
Geoip-Latitude
X-TT-LOGID
Swift-Performance
X-Air-Source
X-Air-Hostname
Srvid
X-Akamai-ERPolicy
Locid
X-Li-Fabric
X-Air-Trace-Id
X-LiteSpeed-Tag
X-FL-EDGE
X-App
X-DW
X-RPM
X-RPS
X-RSL
X-Oss-Object-Type
PFcat
X-DSS
X-Oss-Hash-Crc64ecma
X-Oss-Request-Id
X-HN
X-VarnishDD-TTL
Cache-Key
X-Oss-Server-Time
CF-Cached-On
X-DB
C-Via
PICS-Label
N-Cache
X-Platform
X-DI
Ohc-File-Size
Nginx-CQVIP
CountryCode
X-Oss-Storage-Class
X-Fastly-Backend-Reqs
X-Wp-Cf-Super-Cache
X-Wp-Cf-Super-Cache-Cache-Control
Cneonction
NtCoent-Length
X-LAGOON
X-HostName
X-Platform-Router
X-Platform-Cluster
X-Cache-Proxy
X-Conten-Type-Options
Timeexpire
Esi-Enabled
X-Platform-Processor
X-Request-Url
X-SD-PageType
Wpo-Cache-Message
X-Lb-Nocache
X-Cdn-Request-ID
X-CF-Powered-By
Vha6-Origin
X-Fastly-Cache-Hits
Wpo-Cache-Status
X-Air-Pt
X-Cache-Ngx
X-Ips-Loggedin
Warning
Wp-Super-Cache
X-Litespeed-Cache-Control
X-Newegg-Flow
X-NFL-Dma
X-Newegg-Index
X-NFL-Geo
X-Nerd
X-Matome-Cached
X-Matched-Rule
X-MTS-Cache
X-N-OperationId
X-NS-Authorization
X-PG-ACCESS
X-Okws-Version
X-OVcl
X-PageType
X-Loadbalancer
X-OVcl-Cache
X-Paywall
X-Origin-Ops
X-NXG
X-Nyt-Data-Last-Modified
X-Odoo-Frontend
X-Onedio-Env
X-Ntj-Investigation-Id
X-Fastly-Is-Edge
X-PGF-Deflate
X-Farm
X-Fstrz
X-Full-Ttl
X-GG-Cache-Status
X-F-Status
X-Eventloop-Lag
X-Ee-Request-Date
X-Ee-Request-Id
X-Eid
X-ETag
X-Git-Commit
X-Global-Transaction-ID
X-Ittl
X-Kebab
X-Kebabable
X-Keep
X-Is-SSL
X-IBD-SID
X-GoCache-CacheStatus
X-Group
X-Header-Sub
X-IBD-Cache
X-LbNode
X-Square
X-Ver
X-Vary-Devices
X-Wag-Acs
X-Waitingroom
X-Web-Hosting
X-V2-Infrastructure
X-Utime
X-True-Client-Ip
X-U-Cache
X-Upstream-State
X-User-Auth
X-WP-Bypass
X-WSR2
X-Ha-Backend
X-UP
Create-Date
X-Request-URL
X-Ee-Origin
X-Fastly-Country-Code
X-B3-Parentspanid
X-Xms-Page-Cache-Actions
X-YSpaceId
XV-Cache
XV-H
X-Tried-To-Kebabify
X-Toujours-Debout-Location
X-Route-Akamai
X-Route
X-Ruby
X-Save-Cache
X-Server-L
X-Request-Origin
X-Render-Time
X-R-Cache
X-Reboot
X-Redis
X-Render-Method
X-ServiceName
X-Sh
X-Svr-Proxy
X-Test-Nginx-Ingress
X-Timestamp
X-Toujours-Debout-Branch
X-SVR-IIS
X-Stack-Name
X-Site
X-Slack-Shared-Secret-Outcome
X-SMP-JWT
X-SSLProxy
X-Pver
Nikkei-App-Version
Npm-Remaining
Npm-Cost
Ns
Ns-Ua
OK-Edge-Date
Ok-Cache-Status
NLCacheNote
X-PAYTM-SRV-ID
HTTPProtocol
HServer
Is-Https
Joe-X
NB-ESI
Ok-Edge-Key
Origin-Site
Served
Selected-Route
Service-Uuid
SFRVia
Shieldsquare-Response
Scheme
Rt-Proxy-Cache
Proxy-Cache
Panzer-Cache-Control
RawURL
Region
Request-Uuid
H1
Ec-Policy-Id
WZWS-RAY
DynaTrace
X-B3-ParentSpanId
X-Mg-Cache
X-Yottaa-OS
X-ElasticPress-Query
SRV
Fastcgi-Cache-Ttl
On-Server
X-CUA
Hit
Fastcgi-X-Cache-Version
Req-ID
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
Cf-Wrk
Cf-Locale
Cluster-Host
CMS-200
Deeplink
Cf-Device-Type
Cdn-Country-Code
X-Th-Server
X-Serial
Akamai-X-Url
Cache-Stat
Cachekey
SII
Store-Cloud-Cache
X-Cache-NPR
X-Cache-Length
X-Cache-Reason
X-Cache-ReqUri
X-CacheVersion
X-Cache-Response
X-Cache-IsMobileDevice
X-Cache-Cookie
X-Backend-TTL
X-AspNetWebPages-Version
X-Backside-Transport
X-BeanStalkRole
X-BeanStalkStage
X-CDN-Pop
X-CDN-Pop-IP
X-Developed-By
X-Delivery
X-Doge
X-DT-Node
X-Edge-IP
X-Dehri-Date
X-Dcm-Pdtf
X-Cms-Device
X-Cf-Node-Idx
X-Coindesk-Cache
X-Colour
X-Container-Uri
X-ASF-Cache
X-ARRRG1
TWC-Unit
TWC-Subs
Uniqueid
Userver
X-77-NZT
Vttl
TWC-PATH-LOCALE
TWC-AK-Req-ID
T-Request-Id
Sw
Technodrome
Time-Cloud-Cache
Ttl
X-77-NZT-Ray
X-Accel-Version
X-Amz-Meta-Cb-Modifiedtime
X-Akamai-Native
X-Apache-Server
X-Ar-Stats
X-Arena-Request-Id
X-Akamai-DeviceType
X-Akamai-DeviceOS
X-Accepted-Language
X-Accepted-Fulllang
X-Accor-Asset
X-AEO-Platform
X-Akamai-CacheKeyMod
X-Ee-Generated-By