Threat Level: green Handler on Duty: Guy Bruneau

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
Strict-Transport-Security
X-Frame-Options
X-Content-Type-Options
Link
Last-Modified
CF-Cache-Status
Cf-Request-Id
CF-RAY
Accept-Ranges
ETag
Expect-CT
Pragma
X-Powered-By
X-Cache
Via
Age
X-XSS-Protection
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
X-Xss-Protection
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-FRAME-OPTIONS
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Request-Id
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-Adblock-Key
X-AspNet-Version
X-Permitted-Cross-Domain-Policies
Alt-Svc
X-Runtime
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Cache-Status
X-Check
X-Generator
X-DNS-Prefetch-Control
X-Request-ID
X-Cacheable
P3p
X-Iinfo
X-Envoy-Upstream-Service-Time
X-Ua-Compatible
Feature-Policy
Timing-Allow-Origin
X-Content-Security-Policy
Status
X-Drupal-Dynamic-Cache
Content-Encoding
Access-Control-Expose-Headers
X-AspNetMvc-Version
X-CDN
Upgrade
Access-Control-Max-Age
CF-Ray
X-Dns-Prefetch-Control
X-Via
X-Robots-Tag
X-Cache-Group
X-UA-Device
Server-Timing
Keep-Alive
Request-Context
X-AH-Environment
X-Turbo-Charged-By
X-Amz-Request-Id
X-Proxy-Cache
X-Backend
X-Age
X-Amz-Id-2
X-Ws-Request-Id
Host-Header
X-Hacker
X-Server-Powered-By
X-Server
X-Rq
X-LiteSpeed-Cache
X-Vhost
X-Varnish-Cache
X-Amz-Version-Id
Grace
Cf-Edge-Cache
X-Dispatcher
Allow
EagleId
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
X-Page-Speed
X-Nginx-Cache-Status
Accept-CH
X-WebKit-CSP
X-Aws-Lambda-Call-Status
X-Swift-CacheTime
X-Swift-SaveTime
Cf-Railgun
Ali-Swift-Global-Savetime
X-Node
X-Host
X-Pingback
X-Cache-Spec
X-OneAgent-JS-Injection
X-Backend-Server
X-Akam-SW-Version
X-Server-Id
Surrogate-Control
Request-Id
X-Cache-Lookup
X-Response-Time
EagleEye-TraceId
Accept-CH-Lifetime
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Readtime
Content-Location
X-HW
X-Content-Security-Policy-Report-Only
X-Cloud-Trace-Context
X-Application-Context
Rating
X-Trace
Fastly-Restarts
X-WebKit-CSP-Report-Only
X-Url
X-Clacks-Overhead
X-Nginx-Upstream-Cache-Status
X-CST
X-Ruxit-Js-Agent
X-MS-InvokeApp
X-Edge
X-Amz-Server-Side-Encryption
X-Rack-Cache
X-Oneagent-Js-Injection
X-Country
X-Mod-Pagespeed
X-TtlSet
X-PC
X-Vname
Accept-Ch-Lifetime
X-Content-Type
X-B3-TraceId
Cf-Apo-Via
X-ESI
Edge-Control
X-Vcap-Request-Id
X-FastCGI-Cache
X-Akamai-Path-Stats
X-Mcache
X-D2id
Verso
X-GitHub-Request-Id
Xkey
X-Kinja
X-Kinja-Build
X-Kinja-Revision
X-Exp-Variant
X-Kinja-Server
X-GoogleNews-Bot
X-Exp-Id
X-Use-Magma
X-Cdn-Fetch
Cache-Tag
Service-Worker-Allowed
X-Powered-By-Plesk
X-Amz-Rid
X-Ttl
X-Server-Name
X-Navigation-Version
RTSS
X-Abt-Application-Version
X-VARITI-CCR
X-Client-IP
X-Version
X-Ac
X-Varnish-TTL
X-ECACHE
X-Cnection
X-Upstream
X-Element-Page-Cache
X-Cached
Arr-Disable-Session-Affinity
Permissions-Policy
X-Ruxit-JS-Agent
X-Instrumentation
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
SPRequestGuid
X-Dw-Request-Base-Id
X-RateLimit-Remaining
X-SharePointHealthScore
X-Px
SPIisLatency
SPRequestDuration
X-Cache-TTL
Display
X-Middleton-Display
Pagespeed
X-Sol
Public-Key-Pins
X-NWS-LOG-UUID
X-Country-Code
X-Middleton-Response
Response
X-Midtier
X-Cache-Key
X-Edge-Location-Klb
X-Kinsta-Cache
X-Ser
X-Forwarded-For
X-DataDome
X-Goog-Hash
X-SRCache-Store-Status
X-SRCache-Fetch-Status
Content-MD5
X-NF-Request-ID
X-Correlation-Id
X-Shield-Request-Id
Access-Control-Request-Method
X-HP-Trace-Id
X-MSEdge-Ref
X-Jurisdiction
X-RateLimit-Limit
X-HP-Webp
Front-End-Https
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
AR-Request-ID
AR-SID
X-T
AR-ATIME
AR-CACHE
AR-PoweredBy
X-Recruiting
X-Daa-Tunnel
MicrosoftSharePointTeamServices
Edge-Cache-Tag
TP-Cache
TP-L2-Cache
Nginx-Cache
X-Webkit-Csp
X-Browser-Type
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
Accept-Ch
X-Mg-S
X-Accel-Expires
X-Content-Digest
TCN
X-Grace
X-Hits
X-Powered-CMS
X-Request-Processing-Time
X-Request-Received
X-Amzn-Trace-Id
Server-Node
X-HS-Combine-CSS
X-HS-Cache-Config
X-HS-Content-Id
X-HS-Hub-Id
Filters
Server-Name
MS-Author-Via
X-Id
Fastcgi-Cache
X-Geo-Country
Count-Hit
X-XRDS-Location
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Fastly-Request-Id
X-PressLabs-Stats
X-Origin-Server
X-Distributor
X-Ua-Browser
X-Frontend
X-Ezoic-Cdn
Filterid
Cross-Origin-Opener-Policy
X-LLID
S
X-Forwarded-Proto
Payment
X-Page-Id
X-Language
X-LB-Cache
X-Request-Handler-Origin-Region
X-Microsite
X-Seen-By
Charset
X-Protected-By
X-FB-Debug
X-Git-Hash
Host
X-F-Cache
X-B3-Sampled
X-Amz-Meta-S3cmd-Attrs
X-Ratelimit-Reset
X-ASPNET-VERSION
X-VCache
X-Cluster-Name
X-Rid
Surrogate-Key
Cache-Status
X-Www-Served-By
Cache-Tags
X-Logged-In
Access-Control-Allow-Method
X-Cdn
X-Upgrade-Enabled
X-Ab
X-Origin-Cache
X-DIS-Request-ID
X-Source
X-Varnish-Backend
Realpath
Retry-After
Alternate-Protocol
X-AppVersion
X-Az
X-Activity-Id
Accept-Charset
Cleartype
X-COUNTRY
X-NGENIX-Cache
X-Amz-Replication-Status
X-Cache-Age
X-Type
DC
Paypal-Debug-Id
X-Aspnet-Duration-Ms
X-Flags
X-Is-Crawler
X-Envoy-Decorator-Operation
X-Wix-Request-Id
X-Providence-Cookie
X-Template
X-Request-Guid
X-App-Environment
X-Route-Name
X-Tb
X-B-Cache
X-Signature
X-Varnish-Grace
X-TT
X-Revision
X-Hostname
X-B
X-DynaTrace
ServerID
X-Kong-Upstream-Latency
X-Contextid
X-Kong-Proxy-Latency
Frame-Options
X-Cache-Rule
X-Fastly-Request-ID
X-Fastcgi-Cache
X-Node-Name
X-Drupal-Cache-Tags
X-Tt-Trace-Host
X-Tt-Trace-Tag
Pinterest-Version
X-Pinterest-Rid
Pinterest-Generated-By
Refresh
Cross-Origin-Resource-Policy
Amp-Access-Control-Allow-Source-Origin
X-Trace-Id
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-GUploader-UploadID
X-Goog-Generation
Referer-Policy
X-Proxy
X-Load-Cache
X-Debug
X-Mobile
Node
X-Content-Options
X-Response-Served-From
Viewport
X-Varnish-Server
X-EdgeConnect-Cache-Status
NGB
X-Original-Request-Id
X-XRDS-LOCATION
X-Whom
X-Varnish-Age
Country
X-Content-Powered-By
X-N
X-TTL
X-Cache-Control
Akamai-GRN
X-NYM-Debug-Backend
X-Debug-IsPreview
X-Magnolia-Registration
X-Instance
X-Debug-IsConnected
Content-Disposition
X-Adobe-Loc
X-Status
X-G
X-Page-View
X-Real-IP
X-Rendered-As
X-Framework
X-Is-Bot
X-Adobe-Content
X-Cache-Time
Access-Control-Request-Headers
X-Servername
X-Yottaa-Metrics
X-Yottaa-Optimizations
Uber-Trace-Id
Url
X-Cache-Grace
X-L-Path
X-ProcessESI
X-Environment-Context
X-RemovedCookies
X-Cacheable-TTL
VIX-Pulpo-Node
X-Akamai-Request-ID2
X-Jobs
X-User-Agent
Srv
VIX-Pulpo-Upstream-Status
X-Mid
X-Cache-Expired-At
X-Cache-TTL-Remaining
Healthy
X-Via-JSL
Countrycode
X-Tumblr-Pixel-1
X-Tumblr-User
X-Rule
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Cache-Hit
X-Cache-Operation
X-CDN-Forward
X-Backend-Name
X-Unique-Id
X-APP-VERSION
X-Drupal-Cache-Contexts
Version
X-Oracle-Dms-Ecid
X-Debug-Info
Accept-Language
X-Oracle-Dms-Rid
X-Akamai-Edgescape
X-Cache-Action
Section-Io-Cache
X-Litespeed-Cache
X-Http-Reason
X-ECache
X-VC-Cache
X-Mg-Request-UUID
Content-Secure-Policy
X-HTML-Minification-Powered-By
X-Tt-Logid
Protected
X-IPLB-Instance
X-IPLB-Request-ID
X-Hosted-By
X-Server-ID
Xserver
X-Generation-Time
X-Varnish-Ttl
X-FW-Hash
Backend
X-FW-Dynamic
X-Generated-By
X-FW-Serve
X-FW-Static
X-Azure-Ref
X-FW-Type
X-FW-Server
Server-Info
X-Time
X-Cache-Status-Check
Ms-Operation-Id
MS-CV
X-RN-RSRV
Meta-Geo
X-Storage
X-UPSTREAM-Address
X-RTag
X-Device-Type
X-Access
X-Cms-Context
X-PCL
Azure-InstanceId
Azure-RegionName
X-Hl-Ver
Liferay-Portal
X-Amzn-RequestId
X-Mode
X-Origin-Hint
GEO-INFO
Azure-SiteName
X-SRV
X-Amz-Apigw-Id
X-OCL
X-Cache-Server
X-Handled-By
Azure-Version
X-Proto
Azure-SlotName
Webcakes-App-Version
TWC-Device-Class
TWC-GeoIP-Country
X-R9-Blue-Green-Version
X-Format
TWC-GeoIP-LatLong
Webcakes-Region
TWC-Connection-Speed
Webcakes-App-Name
X-Varnish-Cache-Hits
X-Section
TWC-Privacy
Onion-Location
TWC-Locale-Group
Property-Id
X-Provided-By
X-Server-W
CF-IPCountry
X-Adobe-Source
Web-Mar-Node
X-Locale
X-FireWall-Port
X-Say-Cacheable
X-Mobile-URL
X-Proxy-Cache-Status
X-SaId
X-Varnishpool
X-App-Server
X-Sql-Duration-Ms
X-SayCDN-TTL
X-Say-TTL
X-No-Session
X-Api-Version
X-JoinUs
X-Labrador-Cache-Channel
X-Redis-Cache
X-PHP-Host
X-Sql-Count
X-Proxy-Build
CDN-Uid
X-Varnish-Hostname
X-GeoCountry
DB-Nickname
X-Xfnlog-Site
X-Urbn-Site-Id
Locale
X-ProxyCache-Key
Mn-Server-Ip
X-ProxyCache-Status
X-Timing-Wait
X-Via-Fastly
X-Urbn-Context-Path
CDN-RequestId
X-Restarts
Cache-Name
Selected-Fe
X-PHP-Backend
X-Varnish-Beresp-Grace
X-Content-Age
X-Detected-As
X-Cache-Type
X-Cache-Host
X-Web-Node
X-Edge-Location
CDN-Cache
X-GeoCode
X-Forwarded-Host
X-FB-TRIP-ID
X-LJ-Flow-ID
CDN-CachedAt
CDN-EdgeStorageId
X-Skip-Cache
X-UA-Device-Type
CDN-RequestCountryCode
X-VWS-Id
X-AWS-Id
Eomportal-Instance
CDN-PullZone
X-Site-Version
X-BYPASS-REASON
X-Request-Time
X-Region
X-Sorting-Hat-PodId
S-Rt
Apigw-Requestid
X-ServerID
X-Ms-Version
X-Extlb
X-Ms-Request-Id
X-Zipkin-Id
X-Routing-Service
X-Proxied
X-ShardId
X-Sorting-Hat-ShopId
X-DynaTrace-JS-Agent
X-Shopify-Stage
X-ShopId
X-Alternate-Cache-Key
X-Storefront-Renderer-Rendered
WP-Super-Cache
X-Tid
X-Vgn-Hpd-Reason
X-Dc
X-Tec-Api-Version
X-Tec-Api-Root
X-TIME
X-Nginx-Cache-Key
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
X-Reqid
X-Tec-Api-Origin
X-Amzn-Remapped-Content-Length
X-Loop
X-LSADC-Cache
X-Newrelic-Synthetics
X-TNCMS
X-Content
Load-Balancing
Xet-Cookie
X-Pubstack
X-Cache-Enabled
X-Ua
X-Soup
X-Tumblr-Pixel-2
X-B3-Traceid
X-Origin-TTL
X-Origin-CC
X-Uri
X-Zen-Fury
X-TA-CDN-Provider
X-Origin-Date
X-Cache-NGX
X-Service
From-Origin
X-Cache-Debug
X-MP-GENERATED-AT
Source
X-Correlation-ID
X-Aspnetmvc-Version
X-Ratelimit-Remaining
Fastcgi-Useragent
X-Nginx-Cache
X-Varnish-Hits
X-GEO
X-Webkit-CSP
X-UUID
ServedBy
Origin
X-URL
X-Human
X-App-Version
X-NewRelic-App-Data
Cache
X-Cache-Tags
Fastly-Drupal-HTML
X-Rewrite-Enabled
SD-X-WS
X-Cluster
X-Cached-By
Rip
Upgrade-Insecure-Requests
X-Varnish-Beresp-Ttl
Rendered-Blocks
BehaviorPad-Version
Cross-Origin-Window-Policy
X-ScT
MD5-Digest
WPO-Cache-Message
X-Ratelimit-Limit
WPO-Cache-Status
Host-ID
Mime-Version
DCR-Decision-By
X-Tenant
Cdnsip
X-TIM-N
X-User
X-Vdms-Version
DCR-Processing-Time-Ms
X-Vdms-Path
X-Processor
X-SRCache-Key
X-Rojux
X-FW-Version
A
Expiry
X-S
X-Shop-Environment
X-S-Cookie
Cdncip
Sslversion
X-B-Cookie
X-External-Request-Id
X-Bc-Bl
X-Forwarded-Path
X-ARC
X-Application
X-VG-WebCache
X-BCube-Filmed-By
X-Cache-NE
X-Ec-Fail
X-Destination
Xc-Version
X-D
X-Ec-GeoHdr
X-Connection-Hash
X-AK-Request-ID
X-Aed
Surrogated-Key
T-Server
X-PBS-Appsvrname
X-Developer
Odigeo-Trace-Id
Meta-Geo-Continent
Ngx.Var.Host
X-A
X-A-Ccd
X-A-Dgt
X-A-Wwc
X-Orig-Expires
X-Parent-Response-Time
X-A-Dam
X-A-Dcw
Lang
X-NAPM-TraceId
OT-Force-Account-Verify
Webserver
X-Request-Host
X-Tumblr-Pixel-3
X-Cluster-Node
Redirect-Candidate
X-Nyt-Route
X-Gdpr
X-Origin-Time
X-Served-From
X-Aicache-OS
Environment
X-GeoIP-City
Release
Gh-Request-Id
X-Optimistic-Header
X-Accel-Buffering
X-Cdn-Srv
Thinkindot-CacheControl
Fastly-Backend-Name
AKAMAI
TDXMobile
X-CMSURLCustom
Thinkindot-CacheControl-Type
X-Auto-Login
X-HS-Content-Campaign-Id
X-Sucuri-Cache
X-Level-Front-Cache
X-Sucuri-ID
X-Thinkindot-L3
X-Pass-Why
X-Worker
X-JWT-State
X-Is-Gdpr
X-Generated-On
X-Developers
X-Geo-Header
X-Has-Esi
X-INCAP-ABP
X-Core-Value
Thinkindot-Control
X-Cache-Remote
X-RCS-CacheZone
X-WP-CF-Super-Cache-Active
HA-Ipaddr
X-Epic-Correlation-Id
Ha-Gx-Prefs
X-DPWN-IS-SECURE
We-Hiring
Is-Eu
IsBot
X-Ec-Custom-Error
L
X-Ad-Defer-Variation
X-Esi-Check
X-AOL-HN
L5d-Success-Class
X-Eu-Site
Wxu-Next-Commit
Web-Mar-Region
Decoy-Debug-TTL
Decoy-Debug-Status
Wxu-Next-Hostname
Decoy-Debug-Key
X-Fmm-Version
X-Fetched-On
Fastly-SSL
Fastly-SWR
Fastly-SIE
Fastly-GeoIP-CountryCode
X-FC-Vary-Parameters
Tube-Return
Tube-Got-Eval
Producers
Datacenter
Mobile-Detection-Method
X-CGP
X-Cache-Info
Req-Svc-Chain
X-Ckpd-Fst-Backend
Platform
Origin-EX
X-Csrf-Jwt
X-Clara-WADP
NGX
X-DefElseHash
X-DefHash
Servername
X-ATG-Version
X-Azure-Ref-OriginShield
Traceparent
Tube-Get-Contents
Origin-CC
Machine
X-BBC-Edge-Cache-Status
X-Bip
Mail-Subject
X-Device-Os
X-Dispatcher-Number
X-Cache-Id
X-Cache-Bucket
Tube-Got-Results
X-Mvc-Supplant-Cachable
X-Proxy-Cache-Info
X-Pool
X-VG-TLSProxy
X-Qloud-Router
X-Varnish-Remaining-TTL
X-Policy
X-Platform-Server
X-Origin-Response-Time
X-Owner
X-VServer
X-Viewer-Country
X-Varnish-CookieINHashed-On
X-RateLimit-Limit-Second
X-Variation
X-SB
X-Var-Ttl
X-Thanos
X-SIPLIST1
X-S-Maxage
X-Rocket-Nginx-Serving-Static
X-Varnish-CookieHashed-On
X-RateLimit-Remaining-Second
X-Varnish-Beresp-Status
X-Request-URI
X-NodeID
X-WADP-Cache
Click-Count-Action-Start
X-NCache
X-Minions-Version
Wxu-Next-Region
Click-Count-Error
CloudFront-Viewer-Country
X-Gzip
X-Irp-Debug
Cluster
Candidate-Md5Url
X-Loc
Apple-News-Services-Host
Apple-News-Services-Handled
Canary
X-Wix-Viewer-Type
Apple-News-Services-Parsed-Url
Adler-Geo
Cache-Host
Apple-News-Services-Request-Url
Server-Host
WebServer
X-Tx-Id
X-Origin
X-Branch-Name
X-SVT-ORM-RULES
X-Block-Status
X-Forwarded-Site
DSUID
X-Clientip
X-SplitTest
X-SVT-ORM-VERSION
X-Datadog-Parent-Id
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
X-Planisys-CDN-Cache
X-Mvc-Supplant-OutputCached
X-Gen-Mode
X-Hnp-Log
X-Gamma-Serve
X-Fastly-Backend
X-GeoIP
X-Core-Mission
X-Sigma-Backend
X-Cdn-Origin
X-CacheTTL
X-Slack-Backend
X-Sigma
X-Scheme
X-Region-Sid
X-Rocket-Build-Number
X-Scale
X-Sn-Servicetimems
X-V-Cache
Kp-EeAlive
Sever-Int
State
Cmsid
CDCHOST
Country-Code
CPC-Age
NM-Fastcgi-Cache
Memcached
CPC-Cache
Server-Ext
Server-Hostname
User-Cache-Control
Cmstype
V-Age
X-IPS-LoggedIn
VNS-Age
Vix-Hermes-Req-Id
VNS-Cache
LB
X-Udemy-Cache-App-Namespace
X-Debug-Cache
X-Dispatch
X-Up
X-Gateway-Cache-Key
X-Gateway-Cache-Status
X-Gateway-Request-Id
X-Gateway-Skip-Cache
Ec-Rule-Version
X-Hash
X-LB-NoCache
X-Akamai-Transformed
Svr
Sid
Pics-Label
X-CSRF-Token
X-Newrelic-App-Data
Memory
Time
X-Nf-Request-Id
Ssr
X-Edge-Pop
X-Tb-Optimization-Total-Bytes-Saved
HostName
X-ZONE
X-B3-Spanid
Request-ID
X-VC
X-Req
AMP-Access-Control-Allow-Source-Origin
X-Presslabs-Stats
X-Servedbyhost
X-Generated-In
X-ND-Cache
Env
My-App
X-Cs
X-Via-Popv
True-Client-Country-4JS
X-Via-Popn
X-Refresh
CacheControlHeader
X-Wa
X-Via-Poph
X-Lambda-Id
X-NGINX-Cache
X-WA-Info
Cache-Tv-Group
X-Vc
X-Trace-ID
Server-ID
X-B3-SpanId
X-Via-NSCOPI
X-Datadome
Fastcgi-Cache-TTL
Hostname
X-GG-Cache-Date
SID
X-Session-Fingerprint
X-Op-Id-All
GeoIp-Country-Code
X-CACHE-AGE
X-EC-Lua
X-PX
True-Client-IP
X-ID
X-Release
X-Rebelmouse-Surrogate-Control
X-Pod-Name
X-Origin-Expires
X-LB-ID
X-Fastly-Cache
X-Zone
X-Fpc
X-Rebelmouse-Cache-Control
Cache-Hits
X-VCL-Version
X-GeoIP-Region-Code
X-CSRF-TOKEN
X-Xrds-Location
X-GeoIP-Country-Code
X-TX-ID
WWW-Authenticate
X-Webkit-CSP-Report-Only
X-NWS-UUID-VERIFY
X-TH-Server
X-DC
X-Date
X-Accel-Expires-Debug
X-CACHE-KEY
X-Buckets
X-Esi
X-MSEdge-Features
X-Ig-Push-State
X-MSEdge-Flight
X-Cache-Date
X-Old-Content-Length
X-RAMCache
X-TRACE-ID
X-Srv
CDN
X-HS-Status
X-Conf
X-Endurance-Cache-Level
Fastly-Drupal-Html
Resin-Trace
X-NC
X-Microcachable
X-CS
X-Dmc
Powered-By
X-Varnish-Beresp-TTL
X-RateLimit-Reset
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
X-Webstats-RespID
Section-Origin-Responded
Path
X-MCACHE
Section-Io-Id
X-Vcl-Version
Tcn
X-API-Version
X-Location
Magicmarker
X-Director
X-Lb-Id
X-Varnish-Authentication
X-Contensis-Viewer-Groups
X-Cache-ASPX
X-DataCenter
True-Client-Ip
X-Akamai-Pragma-Client-IP
X-FPC
X-CLOUD-TRACE-CONTEXT
X-Cache-Ttl
X-LiteSpeed-Cache-Control
Yjs-Id
X-Check-Cacheable
X-Alfa-Service
GeoIP-Country-Code
X-Wikidot-Backend
X-Datacenter
X-Wikidot-Static-Cache
X-Server-IP
Lb
X-Via-CDN
FSS-Cache
X-WA
M-TraceId
X-Geo
Proxy-Connection
X-Vercel-Cache
X-Cache-Expires
X-Cache-Backend
Server-Id
X-Vercel-Id
Cdn
X-Mly-Id
X-Test
X-Be
X-PERF
X-Cc-Via
X-ApacheServer
YJS-ID
ENV
X-Via-PopN
Pramga
X-Via-PopV
X-Via-PopH
X-ServedByHost
X-HA-Backend
X-We-Are-Hiring
X-Micro-Cache
X-Hyper-Cache
X-Response-By
User-Agent
Uri
X-Edge-POP
X-Cdn-Forward
X-Dw-Trace-Id
X-Frame-Option
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-Info
X-M-Log
HIT
XServer
X-M-Reqid
XM
X-Client-Ip
X-AIR-PT
X-Service-Response-Time
Sm-Log-Id
X-Traceid
Location
X-Instance-Name
X-Qnm-Cache
Locid
X-HN
Dnion-Transfer-Encoding
X-Li-Fabric
X-Li-Pop
Geoip-Latitude
X-VarnishDD-TTL
X-Air-Source
X-Air-Hostname
X-Air-Trace-Id
X-App
Tracecode
X-LI-Proto
PFcat
X-LI-UUID
Srvid
X-Akamai-ERRuleID
X-Akamai-ERPolicy
X-FL-EDGE
X-LiteSpeed-Tag
X-From
X-TT-LOGID
X-TrackingId
X-UA
Swift-Performance
X-DW
X-RPS
X-RPM
X-Oss-Request-Id
Cache-Key
CF-Cached-On
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
X-RSL
X-Oss-Server-Time
X-Oss-Storage-Class
X-DSS
X-Platform
PICS-Label
Nginx-CQVIP
N-Cache
X-DI
CountryCode
X-DB
X-Fastly-Backend-Reqs
C-Via
Ohc-File-Size
X-Wp-Cf-Super-Cache-Cache-Control
X-Wp-Cf-Super-Cache
Esi-Enabled
NtCoent-Length
X-Platform-Cluster
X-Request-Url
Cneonction
X-Platform-Processor
X-HostName
X-Conten-Type-Options
Create-Date
Wpo-Cache-Message
X-SD-PageType
Wpo-Cache-Status
X-Lb-Nocache
X-Cache-Proxy
X-LAGOON
X-CF-Powered-By
Timeexpire
X-Platform-Router
Vha6-Origin
X-Fastly-Cache-Hits
X-Cdn-Request-ID
X-Air-Pt
Wp-Super-Cache
X-Litespeed-Cache-Control
Warning
X-Cache-Ngx
X-Ips-Loggedin
X-NFL-Dma
X-NFL-Geo
X-Pver
X-Ntj-Investigation-Id
X-Newegg-Index
X-NS-Authorization
X-Newegg-Flow
X-MTS-Cache
X-N-OperationId
X-Nerd
X-NXG
X-R-Cache
X-PGF-Deflate
X-Paywall
X-OVcl
X-OVcl-Cache
X-PageType
X-Origin-Ops
X-PG-ACCESS
X-Odoo-Frontend
X-Matome-Cached
X-Okws-Version
X-Onedio-Env
X-Nyt-Data-Last-Modified
X-Git-Commit
X-Full-Ttl
X-GG-Cache-Status
X-Reboot
X-Global-Transaction-ID
X-Fstrz
X-Fastly-Is-Edge
X-ETag
X-Eventloop-Lag
X-F-Status
X-Farm
X-GoCache-CacheStatus
X-Group
X-Kebabable
X-Keep
X-LbNode
X-Loadbalancer
X-Kebab
X-Ittl
X-Header-Sub
X-IBD-Cache
X-IBD-SID
X-Is-SSL
X-Matched-Rule
X-Svr-Proxy
X-WP-Bypass
X-Web-Hosting
X-WSR2
X-Xms-Page-Cache-Actions
X-YSpaceId
X-Waitingroom
X-Wag-Acs
X-Utime
X-User-Auth
X-V2-Infrastructure
X-Vary-Devices
X-Ver
XV-Cache
XV-H
X-Request-URL
On-Server
X-Ha-Backend
X-UP
X-Request-Start
X-CUA
Hit
X-B3-Parentspanid
X-Fastly-Country-Code
X-PAYTM-SRV-ID
Fastcgi-X-Cache-Version
X-Upstream-State
X-U-Cache
X-Server-L
X-Save-Cache
X-ServiceName
X-Sh
X-Site
X-Ruby
X-Route-Akamai
X-Render-Method
X-Render-Time
X-Request-Origin
X-Route
X-Slack-Shared-Secret-Outcome
X-SMP-JWT
X-Toujours-Debout-Branch
X-Timestamp
X-Toujours-Debout-Location
X-Tried-To-Kebabify
X-True-Client-Ip
X-Test-Nginx-Ingress
X-Eid
X-Square
X-SSLProxy
X-Stack-Name
X-SVR-IIS
X-Redis
X-Coindesk-Cache
Ok-Cache-Status
Ns-Ua
OK-Edge-Date
Ok-Edge-Key
Panzer-Cache-Control
Origin-Site
Ns
Npm-Remaining
NB-ESI
Joe-X
Nikkei-App-Version
NLCacheNote
Npm-Cost
Proxy-Cache
RawURL
Shieldsquare-Response
SFRVia
SII
Store-Cloud-Cache
Sw
Service-Uuid
Served
Request-Uuid
Region
Rt-Proxy-Cache
Scheme
Selected-Route
Is-Https
HTTPProtocol
X-Yottaa-OS
X-ElasticPress-Query
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
X-Serial
Req-ID
Fastcgi-Cache-Ttl
DynaTrace
SRV
WZWS-RAY
X-B3-ParentSpanId
X-Mg-Cache
X-Th-Server
Akamai-X-Url
Deeplink
CMS-200
Ec-Policy-Id
H1
HServer
Cluster-Host
Cf-Wrk
Cachekey
Cache-Stat
Cdn-Country-Code
Cf-Device-Type
Cf-Locale
T-Request-Id
Technodrome
X-Cache-ReqUri
X-Cache-Reason
X-Cache-Response
X-CacheVersion
X-CDN-Pop-IP
X-CDN-Pop
X-Cache-NPR
X-Cache-Length
X-BeanStalkRole
X-Backside-Transport
X-BeanStalkStage
X-Cache-Cookie
X-Cache-IsMobileDevice
X-Cf-Node-Idx
X-Cms-Device
X-Edge-IP
X-DT-Node
X-Ee-Generated-By
X-Ee-Origin
X-Ee-Request-Date
X-Doge
X-Developed-By
X-Container-Uri
X-Colour
X-Dcm-Pdtf
X-Dehri-Date
X-Delivery
X-Backend-TTL
X-AspNetWebPages-Version
Vttl
Userver
X-77-NZT
X-77-NZT-Ray
X-Accel-Version
Uniqueid
TWC-Unit
Ttl
Time-Cloud-Cache
TWC-AK-Req-ID
TWC-PATH-LOCALE
TWC-Subs
X-Accepted-Fulllang
X-Accepted-Language
X-Ar-Stats
X-Apache-Server
X-Arena-Request-Id
X-ARRRG1
X-ASF-Cache
X-Amz-Meta-Cb-Modifiedtime
X-Akamai-Native
X-AEO-Platform
X-Accor-Asset
X-Akamai-CacheKeyMod
X-Akamai-DeviceOS
X-Akamai-DeviceType
X-Ee-Request-Id