Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
Strict-Transport-Security
X-Frame-Options
X-Content-Type-Options
Last-Modified
Link
CF-Cache-Status
Cf-Request-Id
CF-RAY
Accept-Ranges
ETag
Expect-CT
Pragma
X-Powered-By
X-Cache
Via
Age
X-XSS-Protection
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
X-Xss-Protection
Referrer-Policy
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-FRAME-OPTIONS
X-Served-By
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-Adblock-Key
X-AspNet-Version
X-Permitted-Cross-Domain-Policies
Alt-Svc
X-Runtime
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Check
X-Cache-Status
X-Request-ID
X-Generator
X-DNS-Prefetch-Control
X-Cacheable
X-Iinfo
X-Envoy-Upstream-Service-Time
Timing-Allow-Origin
Feature-Policy
X-Content-Security-Policy
Status
X-Drupal-Dynamic-Cache
Content-Encoding
X-AspNetMvc-Version
Access-Control-Expose-Headers
X-CDN
Upgrade
P3p
X-Ua-Compatible
Access-Control-Max-Age
CF-Ray
X-Dns-Prefetch-Control
X-Via
X-Robots-Tag
X-Cache-Group
Server-Timing
X-UA-Device
Request-Context
Keep-Alive
X-AH-Environment
X-Amz-Request-Id
X-Turbo-Charged-By
X-Proxy-Cache
X-Backend
X-Amz-Id-2
X-Age
Host-Header
X-Ws-Request-Id
X-Hacker
X-Server-Powered-By
X-Server
X-Rq
X-Vhost
X-Varnish-Cache
X-Amz-Version-Id
Grace
X-LiteSpeed-Cache
EagleId
X-Dispatcher
Cf-Edge-Cache
Allow
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
X-Page-Speed
X-Swift-SaveTime
X-Swift-CacheTime
X-Nginx-Cache-Status
X-WebKit-CSP
Ali-Swift-Global-Savetime
X-Aws-Lambda-Call-Status
Accept-CH
X-Host
X-Node
X-Akamai-Path-Stats
Cf-Railgun
X-Pingback
X-OneAgent-JS-Injection
X-Cache-Spec
X-Server-Id
Surrogate-Control
X-Backend-Server
X-Akam-SW-Version
Request-Id
EagleEye-TraceId
X-Response-Time
X-Cache-Lookup
X-Readtime
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
Accept-CH-Lifetime
Content-Location
X-HW
X-Content-Security-Policy-Report-Only
X-Cloud-Trace-Context
X-Application-Context
Rating
X-Trace
Fastly-Restarts
X-WebKit-CSP-Report-Only
Accept-Ch-Lifetime
X-Clacks-Overhead
X-Country
X-Nginx-Upstream-Cache-Status
X-Url
X-MS-InvokeApp
X-Amz-Server-Side-Encryption
X-Rack-Cache
X-Edge
Edge-Control
X-PC
X-TtlSet
X-Vname
X-B3-TraceId
X-Mod-Pagespeed
X-Content-Type
X-ESI
X-Ruxit-JS-Agent
X-Vcap-Request-Id
X-CST
X-Oneagent-Js-Injection
X-Mcache
X-D2id
Verso
Xkey
X-Kinja-Revision
X-GoogleNews-Bot
X-Use-Magma
X-Cdn-Fetch
X-Kinja-Server
X-Kinja-Build
X-Exp-Variant
X-Exp-Id
X-Kinja
X-GitHub-Request-Id
Cache-Tag
X-Ruxit-Js-Agent
X-Amz-Rid
X-Powered-By-Plesk
X-FastCGI-Cache
Service-Worker-Allowed
RTSS
X-Varnish-TTL
X-VARITI-CCR
X-Navigation-Version
X-Upstream
X-Version
X-Abt-Application-Version
X-Ttl
X-Cached
X-Client-IP
X-Ac
X-ECACHE
X-Cnection
X-Dw-Request-Base-Id
X-Element-Page-Cache
X-Server-Name
Arr-Disable-Session-Affinity
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-Instrumentation
X-SharePointHealthScore
SPRequestGuid
Cf-Apo-Via
X-Px
SPRequestDuration
SPIisLatency
Permissions-Policy
Public-Key-Pins
X-Middleton-Display
Display
X-Sol
Pagespeed
X-Country-Code
X-Cache-TTL
X-NWS-LOG-UUID
Response
X-Middleton-Response
Accept-Ch
X-Ser
X-Midtier
X-Cache-Key
X-Kinsta-Cache
X-Edge-Location-Klb
X-Goog-Hash
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-RateLimit-Remaining
X-Forwarded-For
Content-MD5
X-NF-Request-ID
Access-Control-Request-Method
X-Shield-Request-Id
X-Correlation-Id
X-MSEdge-Ref
X-DataDome
Front-End-Https
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
X-T
X-Recruiting
Edge-Cache-Tag
TP-Cache
TP-L2-Cache
AR-PoweredBy
AR-CACHE
AR-ATIME
AR-Request-ID
AR-SID
MicrosoftSharePointTeamServices
X-HP-Trace-Id
X-HP-Webp
X-Jurisdiction
Nginx-Cache
MRF-Tech
X-B3-TraceId-Primal
Mrf-Cache-Status
X-Accel-Expires
X-Powered-CMS
X-Daa-Tunnel
TCN
X-Mg-S
X-Grace
X-RateLimit-Limit
X-Content-Digest
Filters
X-Hits
X-Request-Received
X-Request-Processing-Time
Server-Node
X-HS-Content-Id
X-HS-Combine-CSS
X-HS-Cache-Config
X-Amzn-Trace-Id
X-HS-Hub-Id
X-Id
Server-Name
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Browser-Type
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
MS-Author-Via
Fastcgi-Cache
X-PressLabs-Stats
X-Fastly-Request-Id
X-Webkit-Csp
X-Geo-Country
X-Frontend
X-Distributor
X-XRDS-Location
S
X-Origin-Server
X-Ezoic-Cdn
Count-Hit
X-Protected-By
X-Ab
X-Ua-Browser
X-Language
Cache-Status
Filterid
X-Amz-Meta-S3cmd-Attrs
X-LB-Cache
Cross-Origin-Opener-Policy
X-LLID
Charset
Payment
X-ASPNET-VERSION
X-Forwarded-Proto
X-F-Cache
X-Ratelimit-Reset
X-Request-Handler-Origin-Region
X-Page-Id
X-B3-Sampled
X-Seen-By
X-FB-Debug
X-Microsite
X-Fastcgi-Cache
Host
X-Git-Hash
X-Cluster-Name
X-VCache
Surrogate-Key
X-Rid
Cache-Tags
X-Cache-Age
X-Www-Served-By
Accept-Charset
Access-Control-Allow-Method
Retry-After
Realpath
X-Origin-Cache
X-Logged-In
X-Upgrade-Enabled
X-Source
X-AppVersion
X-DIS-Request-ID
X-Activity-Id
X-Az
X-Template
Alternate-Protocol
X-Varnish-Backend
X-Type
X-Litespeed-Cache
ServerID
X-Amz-Replication-Status
X-NGENIX-Cache
X-Wix-Request-Id
X-Varnish-Grace
X-Tb
Cleartype
X-Flags
X-Envoy-Decorator-Operation
X-Is-Crawler
X-Providence-Cookie
X-Request-Guid
X-Aspnet-Duration-Ms
X-Route-Name
X-Signature
X-B-Cache
Paypal-Debug-Id
DC
X-TT
X-App-Environment
X-Hostname
X-B
X-Node-Name
X-DynaTrace
X-TTL
X-Revision
Frame-Options
X-Drupal-Cache-Tags
X-Contextid
X-Proxy
X-Kong-Upstream-Latency
X-Debug
X-Cache-Rule
X-Kong-Proxy-Latency
X-Tt-Trace-Host
X-Tt-Trace-Tag
Pinterest-Generated-By
X-Pinterest-Rid
Pinterest-Version
X-Goog-Metageneration
X-GUploader-UploadID
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Goog-Generation
X-Mobile
Amp-Access-Control-Allow-Source-Origin
Refresh
X-Load-Cache
X-Content-Options
X-Fastly-Request-ID
X-N
X-Cache-Control
X-XRDS-LOCATION
X-Magnolia-Registration
Country
X-EdgeConnect-Cache-Status
X-Original-Request-Id
Node
X-Response-Served-From
X-Varnish-Age
X-Debug-IsPreview
Akamai-GRN
NGB
X-Debug-IsConnected
X-Ratelimit-Remaining
X-Varnish-Server
X-L-Path
Access-Control-Request-Headers
X-Status
X-Cache-Time
X-Environment-Context
X-Instance
X-Content-Powered-By
X-Cache-TTL-Remaining
X-User-Agent
X-Cacheable-TTL
X-Cache-Grace
X-Is-Bot
X-NYM-Debug-Backend
X-Mid
VIX-Pulpo-Upstream-Status
X-Framework
Content-Disposition
X-Akamai-Request-ID2
X-Servername
X-Page-View
X-COUNTRY
Referer-Policy
X-Whom
Uber-Trace-Id
VIX-Pulpo-Node
X-Real-IP
Viewport
X-Rendered-As
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Adobe-Content
X-Unique-Id
X-Jobs
Url
X-Adobe-Loc
Cross-Origin-Resource-Policy
X-ProcessESI
Srv
X-RemovedCookies
X-G
Countrycode
X-Trace-Id
X-Content
X-Drupal-Cache-Contexts
X-APP-VERSION
X-Via-JSL
X-CDN-Forward
X-Cache-Expired-At
Version
X-Api-Version
X-Time
X-Mg-Request-UUID
Accept-Language
X-Cache-Hit
X-Tumblr-Pixel
X-Tumblr-Pixel-1
X-Tumblr-User
X-Tumblr-Pixel-0
X-Oracle-Dms-Ecid
X-Cache-Operation
X-Http-Reason
X-Oracle-Dms-Rid
X-Backend-Name
X-Restarts
X-ECache
Healthy
X-Ratelimit-Limit
Protected
X-IPLB-Instance
X-App-Server
X-Rule
X-IPLB-Request-ID
X-Server-ID
X-Azure-Ref
X-Cache-Action
Section-Io-Cache
Content-Secure-Policy
X-Debug-Info
X-Akamai-Edgescape
X-Hosted-By
X-Tt-Logid
X-Generation-Time
Backend
X-Nginx-Cache-Key
GEO-INFO
X-VC-Cache
Server-Info
X-FW-Static
X-FW-Type
X-FW-Dynamic
X-FW-Hash
X-Device-Type
X-FW-Serve
X-FW-Server
Liferay-Portal
X-Mobile-URL
X-Storage
Meta-Geo
X-URL
X-UPSTREAM-Address
X-RN-RSRV
Load-Balancing
X-HTML-Minification-Powered-By
Onion-Location
MS-CV
X-RTag
CF-IPCountry
Ms-Operation-Id
X-Locale
X-Mode
X-SRV
S-Rt
Eomportal-Instance
X-Handled-By
X-Proto
X-Format
X-Access
Azure-InstanceId
Azure-RegionName
Azure-SiteName
X-Cache-Server
X-Section
Azure-SlotName
Azure-Version
X-FireWall-Port
X-Generated-By
X-R9-Blue-Green-Version
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Content-Age
Webcakes-App-Version
X-Forwarded-Host
X-Edge-Location
X-Cms-Context
Webcakes-App-Name
X-Labrador-Cache-Channel
Webcakes-Region
CDN-Uid
X-SaId
X-JoinUs
TWC-Privacy
CDN-RequestId
X-Region
TWC-GeoIP-LatLong
TWC-Connection-Speed
Cache-Name
CDN-PullZone
CDN-EdgeStorageId
CDN-CachedAt
CDN-RequestCountryCode
X-Varnish-Cache-Hits
X-Redis-Cache
TWC-GeoIP-Country
TWC-Device-Class
X-Cache-Host
TWC-Locale-Group
X-Alternate-Cache-Key
X-OCL
X-Shopify-Stage
X-Urbn-Context-Path
X-Urbn-Site-Id
X-Varnish-Beresp-Grace
CDN-Cache
X-Site-Version
X-Skip-Cache
X-Sql-Count
X-Sorting-Hat-ShopId
X-No-Session
X-Sql-Duration-Ms
Locale
X-ShopId
X-Ms-Version
X-Hl-Ver
X-Say-TTL
X-PCL
X-Adobe-Source
X-PHP-Host
X-Origin-Hint
Web-Mar-Node
Property-Id
X-Ms-Request-Id
X-ShardId
X-Varnish-Hostname
X-SayCDN-TTL
X-Sorting-Hat-PodId
X-Say-Cacheable
X-Cache-Type
X-Proxy-Cache-Status
Apigw-Requestid
X-Routing-Service
X-Proxied
X-PHP-Backend
X-Extlb
X-GeoCode
X-GeoCountry
X-LJ-Flow-ID
X-Detected-As
X-ServerID
X-Varnishpool
X-VWS-Id
X-Web-Node
X-Zipkin-Id
X-Storefront-Renderer-Rendered
X-Server-W
X-UA-Device-Type
X-AWS-Id
Fastcgi-Useragent
Mn-Server-Ip
X-BYPASS-REASON
Selected-Fe
X-Cache-Enabled
X-ProxyCache-Key
X-Uri
X-Xfnlog-Site
X-Cache-Status-Check
X-Timing-Wait
X-Tid
X-ProxyCache-Status
X-Request-Time
X-Proxy-Build
X-Via-Fastly
Xserver
WP-Super-Cache
X-DynaTrace-JS-Agent
X-WP-CF-Super-Cache-Cache-Control
DB-Nickname
X-WP-CF-Super-Cache
X-Cache-NGX
X-FB-TRIP-ID
X-Origin-Date
X-Varnish-Ttl
X-Nginx-Cache
X-UUID
X-Datadome
X-Dc
X-Amzn-Remapped-Content-Length
X-TNCMS
X-Ua
X-Loop
X-Provided-By
X-Pubstack
X-LSADC-Cache
X-Reqid
X-Correlation-ID
X-Aspnetmvc-Version
Xet-Cookie
ServedBy
X-Vgn-Hpd-Reason
X-Zen-Fury
X-Cdn
X-Soup
X-Webkit-CSP
X-Tumblr-Pixel-2
X-MP-GENERATED-AT
X-Human
X-Origin-TTL
X-Service
X-TA-CDN-Provider
Origin
Source
X-Origin-CC
X-GEO
X-RCS-CacheZone
X-Newrelic-Synthetics
X-Cache-Tags
Cache
From-Origin
X-Varnish-Hits
X-App-Version
X-Cached-By
Cross-Origin-Window-Policy
X-TIME
X-Debug-Cache
X-Tec-Api-Root
WPO-Cache-Message
X-Tec-Api-Version
X-Tec-Api-Origin
X-Cache-Debug
WPO-Cache-Status
SD-X-WS
X-B3-Traceid
X-Varnish-Beresp-Ttl
Rip
BehaviorPad-Version
Rendered-Blocks
X-ScT
MD5-Digest
X-Request-Host
LB
Host-ID
X-Destination
X-NAPM-TraceId
Xc-Version
X-Tenant
X-SRCache-Key
X-A
Lang
X-Cache-NE
VNS-Age
CPC-Age
X-Connection-Hash
X-BCube-Filmed-By
X-Bc-Bl
X-D
X-Orig-Expires
Cdncip
X-TIM-N
A
X-External-Request-Id
X-Aed
X-AK-Request-ID
X-Application
X-Forwarded-Path
CPC-Cache
X-A-Wwc
X-B-Cookie
X-Developer
X-ARC
Cdnsip
X-Ec-Fail
X-Ec-GeoHdr
X-A-Dgt
X-A-Dcw
X-A-Dam
X-A-Ccd
VNS-Cache
Ngx.Var.Host
Expiry
X-NewRelic-App-Data
Environment
Surrogated-Key
X-VG-WebCache
Sslversion
Odigeo-Trace-Id
X-Rojux
X-S
X-Vdms-Path
Meta-Geo-Continent
X-S-Cookie
X-Rewrite-Enabled
X-Processor
X-Vdms-Version
DCR-Decision-By
X-Shop-Environment
X-PBS-Appsvrname
DCR-Processing-Time-Ms
X-Parent-Response-Time
T-Server
X-User
Webserver
X-IPS-LoggedIn
X-AOL-HN
X-FW-Version
X-Served-From
Redirect-Candidate
X-Aicache-OS
X-Dispatcher-Number
X-Cluster
X-Accel-Buffering
Upgrade-Insecure-Requests
X-Origin-Time
X-Gdpr
X-Owner
X-Nyt-Route
X-Is-Gdpr
X-JWT-State
X-Thinkindot-L3
X-Has-Esi
X-Sucuri-ID
X-Sucuri-Cache
X-Level-Front-Cache
AKAMAI
X-CSRF-Token
X-HS-Content-Campaign-Id
X-WP-CF-Super-Cache-Active
Server-Host
X-Cdn-Srv
X-Geo-Header
X-Auto-Login
Fastly-Drupal-HTML
X-CMSURLCustom
X-Generated-On
X-Developers
X-Core-Value
X-Newrelic-App-Data
X-Worker
Thinkindot-Control
X-INCAP-ABP
Gh-Request-Id
Fastly-Backend-Name
TDXMobile
OT-Force-Account-Verify
WebServer
Thinkindot-CacheControl-Type
X-Platform-Server
Thinkindot-CacheControl
X-Bip
X-Azure-Ref-OriginShield
Mail-Subject
Web-Mar-Region
Svr
State
We-Hiring
Traceparent
Vix-Hermes-Req-Id
Machine
V-Age
Memcached
Servername
X-BBC-Edge-Cache-Status
NM-Fastcgi-Cache
NGX
Origin-CC
X-ATG-Version
Req-Svc-Chain
Release
Origin-EX
Mobile-Detection-Method
X-Gateway-Cache-Key
X-Policy
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-Pool
X-Proxy-Cache-Info
X-VG-TLSProxy
X-Qloud-Router
X-Planisys-CDN-Cache
X-Viewer-Country
X-Origin
X-Wix-Viewer-Type
X-WADP-Cache
X-Origin-Response-Time
X-SVT-ORM-VERSION
X-VServer
X-RateLimit-Limit-Second
X-SVT-ORM-RULES
X-Scheme
X-Var-Ttl
X-Scale
X-Sigma
X-Sigma-Backend
X-Slack-Backend
X-SIPLIST1
X-SB
X-S-Maxage
X-Region-Sid
X-RateLimit-Remaining-Second
X-Request-URI
X-Rocket-Build-Number
X-Varnish-Beresp-Status
X-Rocket-Nginx-Serving-Static
X-NCache
X-Mvc-Supplant-Cachable
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
X-Csrf-Jwt
X-Datadog-Trace-Id
X-Ec-Custom-Error
X-Esi-Check
X-Epic-Correlation-Id
X-Core-Mission
X-Clientip
X-Cache-Info
X-Cache-Id
X-CacheTTL
X-Cdn-Origin
X-Clara-WADP
X-CGP
X-Eu-Site
X-Fastly-Backend
X-GeoIP-City
X-Thanos
X-Gzip
X-Hash
X-Loc
X-Irp-Debug
X-GeoIP
X-Gateway-Skip-Cache
X-Fmm-Version
X-FC-Vary-Parameters
X-Gamma-Serve
X-Sn-Servicetimems
X-Gateway-Request-Id
X-Gateway-Cache-Status
X-Cache-Bucket
X-Forwarded-Site
Fastly-SSL
Fastly-SIE
Cache-Host
Fastly-SWR
Apple-News-Services-Handled
Fastly-GeoIP-CountryCode
Apple-News-Services-Request-Url
Decoy-Debug-TTL
DSUID
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
Decoy-Debug-Status
Decoy-Debug-Key
Candidate-Md5Url
Country-Code
L5d-Success-Class
IsBot
HA-Ipaddr
Kp-EeAlive
Ha-Gx-Prefs
Cluster
L
X-Cluster-Node
Wxu-Next-Region
Click-Count-Action-Start
Canary
X-V-Cache
X-Ad-Defer-Variation
CDCHOST
Click-Count-Error
CloudFront-Viewer-Country
X-Optimistic-Header
X-Via-NSCOPI
X-Tx-Id
X-NodeID
X-Fetched-On
X-Hnp-Log
X-Gen-Mode
X-ND-Cache
X-DPWN-IS-SECURE
X-Device-Os
X-Block-Status
X-Minions-Version
HostName
X-Branch-Name
X-B3-SpanId
X-DefHash
X-DefElseHash
Wxu-Next-Hostname
Adler-Geo
X-SplitTest
X-Varnish-Remaining-TTL
X-Varnish-CookieHashed-On
Server-Hostname
Is-Eu
Platform
Producers
Server-Ext
X-Varnish-CookieINHashed-On
Sever-Int
Wxu-Next-Commit
Mime-Version
X-Variation
User-Cache-Control
Tube-Return
Datacenter
Cmstype
Cmsid
Tube-Got-Eval
Tube-Got-Results
Tube-Get-Contents
X-Trace-ID
X-Cache-Remote
X-VC
X-GG-Cache-Date
Sid
X-Mvc-Supplant-OutputCached
X-Udemy-Cache-App-Namespace
X-LB-NoCache
X-Ckpd-Fst-Backend
Ec-Rule-Version
X-Nf-Request-Id
X-WA-Info
Cache-Tv-Group
Pics-Label
Time
Memory
Fastcgi-Cache-TTL
X-Tb-Optimization-Total-Bytes-Saved
Cache-Hits
X-ZONE
X-Pass-Why
Request-ID
X-Session-Fingerprint
X-Refresh
AMP-Access-Control-Allow-Source-Origin
Ssr
X-Fastly-Cache
X-Tumblr-Pixel-3
X-Pod-Name
X-Up
X-Origin-Expires
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-Edge-Pop
X-Cs
Env
X-Via-Poph
X-Via-Popn
X-Dispatch
X-Release
X-Generated-In
X-Via-Popv
X-Servedbyhost
My-App
X-Akamai-Transformed
Server-ID
X-Lambda-Id
SID
X-Wa
X-Presslabs-Stats
X-Esi
X-PX
X-Cache-Date
X-Zone
X-Ig-Push-State
X-ID
GeoIp-Country-Code
X-Fpc
X-DC
CDN
X-Buckets
X-EC-Lua
X-NWS-UUID-VERIFY
X-MSEdge-Features
X-MSEdge-Flight
X-Req
X-Xrds-Location
True-Client-IP
X-Conf
X-CACHE-AGE
X-NC
X-Microcachable
CacheControlHeader
X-B3-Spanid
X-LB-ID
X-TX-ID
True-Client-Country-4JS
X-Vc
X-Endurance-Cache-Level
X-NGINX-Cache
X-Webkit-CSP-Report-Only
X-TH-Server
X-VCL-Version
Hostname
X-Dmc
Fastly-Drupal-Html
X-CACHE-KEY
X-CS
X-HS-Status
X-CSRF-TOKEN
X-Op-Id-All
X-TRACE-ID
X-Srv
Magicmarker
X-Be
X-GeoIP-Region-Code
X-GeoIP-Country-Code
X-Wikidot-Static-Cache
X-Wikidot-Backend
X-Varnish-Beresp-TTL
X-MCACHE
X-RateLimit-Reset
X-Check-Cacheable
X-Vcl-Version
WWW-Authenticate
Path
X-Date
X-Accel-Expires-Debug
Tcn
Resin-Trace
X-Hyper-Cache
X-RAMCache
X-Alfa-Service
X-Vercel-Id
X-Akamai-Pragma-Client-IP
True-Client-Ip
X-Vercel-Cache
X-SERVER-NAME
Pramga
Section-Io-Id
Section-Io-Origin-Status
X-M-Reqid
Section-Origin-Responded
X-CF-Lambda-Fn
X-Old-Content-Length
X-M-Log
X-Micro-Cache
Section-Io-Origin-Time-Seconds
X-CF-Lambda-Version
X-FPC
GeoIP-Country-Code
Yjs-Id
X-CLOUD-TRACE-CONTEXT
X-Cache-Ttl
Tracecode
X-Datacenter
X-App
X-LiteSpeed-Cache-Control
X-Air-Trace-Id
Proxy-Connection
X-Air-Source
X-Qnm-Cache
X-Air-Hostname
Powered-By
YJS-ID
X-Air-Pt
X-Via-CDN
FSS-Cache
Lb
X-Geo
X-Mly-Id
Server-Id
X-WA
C-Via
X-Location
User-Agent
X-Webstats-RespID
X-ServedByHost
X-Response-By
X-Lb-Id
X-Via-PopH
ENV
X-Via-PopN
X-Via-PopV
X-Edge-POP
X-Platform-Processor
X-Platform-Cluster
X-TrackingId
X-Platform-Router
N-Cache
X-Varnish-Authentication
X-Contensis-Viewer-Groups
X-Cdn-Forward
X-Cache-ASPX
X-API-Version
NtCoent-Length
On-Server
X-Platform
Esi-Enabled
Fastcgi-X-Cache-Version
HIT
X-Client-Ip
XServer
X-PAYTM-SRV-ID
Hit
X-Director
X-DataCenter
X-Dw-Trace-Id
Sm-Log-Id
X-AIR-PT
X-Service-Response-Time
X-TT-LOGID
Location
Cdn
X-FL-EDGE
X-From
X-Server-IP
Srvid
Locid
X-UA
X-Instance-Name
X-CUA
X-Traceid
X-Akamai-ERPolicy
X-Li-Fabric
X-LI-UUID
X-FORWARDED-FOR
Geoip-Latitude
X-Akamai-ERRuleID
X-Li-Pop
X-LI-Proto
Dnion-Transfer-Encoding
X-Test
Nginx-CQVIP
Ohc-File-Size
X-Vtex-Processado-Em
X-DSS
X-Request-Url
X-Vtex-Remote-Cache
Swift-Performance
Uri
GeoIP-Latitude
X-RSL
X-DW
X-RPM
X-RPS
X-DI
X-DB
X-LiteSpeed-Tag
X-Node-Id
X-CF-Powered-By
PICS-Label
X-Edge-Origin-Shield-Bytes
X-Litespeed-Cache-Control
X-Wp-Cf-Super-Cache-Cache-Control
X-Wp-Cf-Super-Cache
X-Edge-Origin-Shield-Region
X-HA-Backend
X-LAGOON
X-Serial
M-TraceId
X-B3-ParentSpanId
X-Cache-Expires
X-SD-PageType
X-Cache-Backend
Vha6-Origin
X-Request-Start
X-HostName
X-Render-Time
X-Cdn-Request-ID
X-Fastly-Cache-Hits
X-Lb-Nocache
Wpo-Cache-Message
Wpo-Cache-Status
X-Fastly-Backend-Reqs
X-Ips-Loggedin
Wp-Super-Cache
X-Cache-Ngx
X-Cc-Via
Warning
CountryCode
X-Kebabable
X-Keep
X-Ittl
X-Header-Sub
X-Ha-Backend
X-Group
X-IBD-Cache
X-IBD-SID
X-LbNode
X-Is-SSL
X-Kebab
X-Matched-Rule
X-Nerd
X-N-OperationId
X-Newegg-Flow
X-Newegg-Index
X-GoCache-CacheStatus
X-NFL-Dma
X-NFL-Geo
X-NXG
X-Matome-Cached
X-Loadbalancer
X-Ntj-Investigation-Id
X-MTS-Cache
X-NS-Authorization
X-Nyt-Data-Last-Modified
X-Ee-Origin
X-Edge-IP
X-Container-Uri
X-Ee-Generated-By
X-Dehri-Date
X-Colour
X-Conten-Type-Options
X-DT-Node
X-Dcm-Pdtf
X-Delivery
X-Developed-By
X-Odoo-Frontend
X-Doge
X-Ee-Request-Date
X-Ee-Request-Id
X-Fstrz
X-Frame-Option
X-Full-Ttl
X-GG-Cache-Status
X-Git-Commit
X-Fastly-Is-Edge
X-Farm
X-Eid
X-ETag
X-Eventloop-Lag
X-F-Status
X-Global-Transaction-ID
X-V2-Infrastructure
X-UP
X-U-Cache
X-Upstream-State
X-User-Auth
X-Utime
X-True-Client-Ip
X-Tried-To-Kebabify
X-Test-Nginx-Ingress
X-Svr-Proxy
X-Timestamp
X-Toujours-Debout-Branch
X-Toujours-Debout-Location
X-Coindesk-Cache
X-Vary-Devices
X-Xms-Page-Cache-Actions
X-WSR2
X-YSpaceId
XV-Cache
XV-H
X-WP-Bypass
X-Web-Hosting
X-Ver
X-Wag-Acs
X-Waitingroom
X-We-Are-Hiring
X-SVR-IIS
X-Stack-Name
X-Pver
X-PGF-Deflate
X-R-Cache
X-Reboot
X-Redis
X-PG-ACCESS
X-Paywall
X-Origin-Ops
X-Onedio-Env
X-OVcl
X-OVcl-Cache
X-PageType
X-Render-Method
X-Request-Origin
X-Site
X-Sh
X-SMP-JWT
X-Square
X-SSLProxy
X-ServiceName
X-Server-L
X-Route
X-Route-Akamai
X-Ruby
X-Save-Cache
X-Okws-Version
SII
NB-ESI
Joe-X
Nikkei-App-Version
NLCacheNote
Npm-Cost
Is-Https
HTTPProtocol
Deeplink
CMS-200
Ec-Policy-Id
H1
HServer
Npm-Remaining
Ns
RawURL
Proxy-Cache
Region
Request-Uuid
Rt-Proxy-Cache
Panzer-Cache-Control
Origin-Site
Ns-Ua
Ok-Cache-Status
OK-Edge-Date
Ok-Edge-Key
Cluster-Host
Cf-Wrk
Cache-Key
X-ApacheServer
DynaTrace
WZWS-RAY
X-Mg-Cache
SRV
Fastcgi-Cache-Ttl
X-Moov-T
X-Via-Ucdn
X-Moov-Xdn-Version
X-PERF
Req-ID
X-ElasticPress-Query
X-Yottaa-OS
Cachekey
Cache-Stat
Cdn-Country-Code
Cf-Device-Type
Cf-Locale
Akamai-X-Url
X-Th-Server
CF-Cached-On
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
Cneonction
Scheme
Selected-Route
X-AspNetWebPages-Version
X-ASF-Cache
X-Backend-TTL
X-Backside-Transport
X-BeanStalkRole
X-ARRRG1
X-Arena-Request-Id
X-Akamai-Native
X-Akamai-DeviceType
X-Amz-Meta-Cb-Modifiedtime
X-Apache-Server
X-Ar-Stats
X-BeanStalkStage
X-Cache-Cookie
X-CacheVersion
X-Cache-Response
X-CDN-Pop
X-CDN-Pop-IP
X-Cf-Node-Idx
X-Cache-ReqUri
X-Cache-Reason
X-Cache-IsMobileDevice
X-Cache-Length
X-Cache-NPR
X-Cache-Proxy
X-Akamai-DeviceOS
X-Akamai-CacheKeyMod
Technodrome
T-Request-Id
Time-Cloud-Cache
Ttl
TWC-AK-Req-ID
Sw
Store-Cloud-Cache
Served
Service-Uuid
SFRVia
Shieldsquare-Response
TWC-PATH-LOCALE
TWC-Subs
X-Accepted-Fulllang
X-Accel-Version
X-Accepted-Language
X-Accor-Asset
X-AEO-Platform
X-77-NZT-Ray
X-77-NZT
TWC-Unit
Uniqueid
Userver
Vttl
X-Cms-Device