Threat Level: green Handler on Duty: Guy Bruneau

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
Strict-Transport-Security
X-Frame-Options
X-Content-Type-Options
Last-Modified
Link
CF-Cache-Status
Cf-Request-Id
CF-RAY
Accept-Ranges
ETag
Expect-CT
Pragma
X-Powered-By
X-Cache
Via
Age
X-XSS-Protection
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
X-Xss-Protection
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-FRAME-OPTIONS
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-Adblock-Key
X-AspNet-Version
X-Permitted-Cross-Domain-Policies
Alt-Svc
X-Runtime
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Cache-Status
X-Check
X-Generator
X-Request-ID
X-Cacheable
X-Iinfo
X-Envoy-Upstream-Service-Time
P3p
Timing-Allow-Origin
X-Ua-Compatible
Feature-Policy
X-Content-Security-Policy
Status
X-Drupal-Dynamic-Cache
Content-Encoding
Access-Control-Expose-Headers
X-AspNetMvc-Version
X-CDN
Upgrade
Access-Control-Max-Age
CF-Ray
X-Via
X-Robots-Tag
X-Cache-Group
X-UA-Device
Server-Timing
X-Dns-Prefetch-Control
Keep-Alive
Request-Context
X-AH-Environment
X-Turbo-Charged-By
X-Amz-Request-Id
X-Proxy-Cache
X-Backend
X-Amz-Id-2
X-Age
X-Ws-Request-Id
Host-Header
X-Hacker
X-Server-Powered-By
X-Server
X-Rq
X-Vhost
X-LiteSpeed-Cache
X-Varnish-Cache
X-Amz-Version-Id
Grace
Cf-Edge-Cache
X-Dispatcher
EagleId
Allow
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
Accept-CH
X-Page-Speed
X-Nginx-Cache-Status
X-Swift-CacheTime
X-Swift-SaveTime
X-WebKit-CSP
X-Aws-Lambda-Call-Status
Ali-Swift-Global-Savetime
Cf-Railgun
X-Host
X-Node
X-Pingback
X-Cache-Spec
X-OneAgent-JS-Injection
X-Server-Id
X-Backend-Server
X-Akam-SW-Version
Surrogate-Control
Request-Id
Accept-CH-Lifetime
X-Cache-Lookup
X-Response-Time
EagleEye-TraceId
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Readtime
Content-Location
X-HW
X-Cloud-Trace-Context
X-Content-Security-Policy-Report-Only
X-Application-Context
Rating
X-Trace
Fastly-Restarts
X-WebKit-CSP-Report-Only
X-Clacks-Overhead
X-Akamai-Path-Stats
X-Nginx-Upstream-Cache-Status
X-Ruxit-Js-Agent
X-Url
X-CST
X-MS-InvokeApp
X-Edge
X-Amz-Server-Side-Encryption
X-Rack-Cache
X-Oneagent-Js-Injection
X-Country
X-TtlSet
X-PC
X-Vname
X-Mod-Pagespeed
Edge-Control
X-Content-Type
X-ESI
X-B3-TraceId
X-Vcap-Request-Id
X-FastCGI-Cache
Accept-Ch-Lifetime
Cf-Apo-Via
X-D2id
Verso
Xkey
X-Use-Magma
X-Exp-Id
X-GoogleNews-Bot
X-Exp-Variant
X-Cdn-Fetch
X-Kinja-Revision
X-Kinja-Server
X-Kinja-Build
X-Kinja
X-Mcache
X-GitHub-Request-Id
Cache-Tag
Service-Worker-Allowed
X-Powered-By-Plesk
X-Amz-Rid
X-Ttl
X-Varnish-TTL
X-ECACHE
X-Navigation-Version
RTSS
X-Server-Name
X-Abt-Application-Version
X-VARITI-CCR
X-Version
X-Upstream
X-Client-IP
X-Cnection
X-Ac
X-Cached
X-Element-Page-Cache
Arr-Disable-Session-Affinity
X-Instrumentation
X-Ruxit-JS-Agent
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-Dw-Request-Base-Id
X-SharePointHealthScore
Permissions-Policy
SPRequestGuid
X-Px
X-RateLimit-Remaining
SPRequestDuration
SPIisLatency
X-Sol
X-Cache-TTL
Display
Pagespeed
X-Middleton-Display
Public-Key-Pins
X-NWS-LOG-UUID
X-Country-Code
Response
X-Middleton-Response
X-Midtier
X-Cache-Key
X-Ser
X-Edge-Location-Klb
X-Kinsta-Cache
X-Forwarded-For
X-SRCache-Fetch-Status
X-SRCache-Store-Status
Content-MD5
X-Goog-Hash
X-Shield-Request-Id
X-DataDome
X-MSEdge-Ref
X-Jurisdiction
X-HP-Trace-Id
X-HP-Webp
Front-End-Https
Access-Control-Request-Method
X-RateLimit-Limit
X-ORACLE-DMS-ECID
X-B3-TraceId-Primal
MRF-Tech
X-NF-Request-ID
X-ORACLE-DMS-RID
Mrf-Cache-Status
X-T
X-Recruiting
X-Correlation-Id
AR-Request-ID
Edge-Cache-Tag
AR-ATIME
AR-CACHE
AR-PoweredBy
AR-SID
MicrosoftSharePointTeamServices
TP-Cache
TP-L2-Cache
Nginx-Cache
X-Daa-Tunnel
X-Accel-Expires
X-Erf-Bev-Bev-Is-Generated
X-Browser-Type
X-Erf-Bev-Bev
X-Mg-S
X-Content-Digest
X-Powered-CMS
TCN
X-Grace
X-Request-Received
X-Request-Processing-Time
X-Amzn-Trace-Id
X-HS-Cache-Config
X-HS-Content-Id
Server-Node
X-HS-Combine-CSS
X-HS-Hub-Id
Filters
X-Hits
Server-Name
X-Id
MS-Author-Via
Fastcgi-Cache
X-Geo-Country
X-XRDS-Location
Count-Hit
X-Webkit-Csp
X-Frontend
X-Origin-Server
X-Ezoic-Cdn
X-Fastly-Request-Id
X-Ua-Browser
X-Distributor
Cross-Origin-Opener-Policy
X-PressLabs-Stats
X-TEC-API-ROOT
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-LLID
Filterid
X-Language
X-Microsite
S
Charset
X-Request-Handler-Origin-Region
X-F-Cache
X-Protected-By
X-Forwarded-Proto
X-Git-Hash
X-B3-Sampled
Host
Payment
X-FB-Debug
X-Seen-By
X-Page-Id
X-LB-Cache
X-Amz-Meta-S3cmd-Attrs
X-ASPNET-VERSION
X-VCache
Cache-Status
X-Cluster-Name
X-Ratelimit-Reset
X-Rid
Surrogate-Key
X-Www-Served-By
X-Ab
Cache-Tags
X-Logged-In
Access-Control-Allow-Method
X-Upgrade-Enabled
Realpath
Retry-After
X-Varnish-Backend
X-DIS-Request-ID
X-Source
X-Origin-Cache
Alternate-Protocol
Accept-Charset
X-Az
X-Activity-Id
Accept-Ch
X-AppVersion
X-COUNTRY
X-Cache-Age
X-NGENIX-Cache
Cleartype
X-Type
DC
Paypal-Debug-Id
X-Amz-Replication-Status
X-Varnish-Grace
X-Signature
X-Envoy-Decorator-Operation
X-Route-Name
X-Template
X-Is-Crawler
X-B-Cache
X-Aspnet-Duration-Ms
X-Flags
X-Providence-Cookie
X-Request-Guid
X-Tb
X-TT
X-Wix-Request-Id
X-Hostname
X-B
X-App-Environment
X-Revision
ServerID
X-DynaTrace
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Contextid
Frame-Options
X-Cache-Rule
X-Fastcgi-Cache
X-Node-Name
X-Drupal-Cache-Tags
X-Fastly-Request-ID
X-Pinterest-Rid
Pinterest-Generated-By
Pinterest-Version
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Proxy
Cross-Origin-Resource-Policy
Refresh
X-Debug
X-Goog-Stored-Content-Length
X-Goog-Metageneration
X-Goog-Generation
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Load-Cache
X-Mobile
X-GUploader-UploadID
Amp-Access-Control-Allow-Source-Origin
X-Content-Options
Node
Referer-Policy
X-EdgeConnect-Cache-Status
X-Trace-Id
X-Original-Request-Id
X-Response-Served-From
X-Varnish-Server
Viewport
X-TTL
X-N
X-Varnish-Age
NGB
Country
X-Cache-Control
X-Cache-Time
Akamai-GRN
X-Magnolia-Registration
X-Debug-IsConnected
X-Instance
X-Debug-IsPreview
X-NYM-Debug-Backend
X-Content-Powered-By
X-Adobe-Loc
X-G
Content-Disposition
Uber-Trace-Id
X-Adobe-Content
X-Whom
X-Status
Access-Control-Request-Headers
X-Cache-Grace
Url
X-Cacheable-TTL
X-Rendered-As
X-RemovedCookies
X-Servername
X-Yottaa-Metrics
X-Real-IP
X-Yottaa-Optimizations
X-Page-View
X-ProcessESI
X-Is-Bot
X-Environment-Context
X-L-Path
VIX-Pulpo-Node
X-Framework
X-User-Agent
X-Cache-TTL-Remaining
X-Jobs
VIX-Pulpo-Upstream-Status
X-Akamai-Request-ID2
Srv
X-Mid
X-Webkit-CSP
X-Cache-Expired-At
Healthy
X-Via-JSL
X-CDN-Forward
X-Unique-Id
X-Tumblr-User
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-Tumblr-Pixel
Countrycode
X-Cache-Hit
X-Cache-Operation
X-XRDS-LOCATION
X-Drupal-Cache-Contexts
Version
X-Rule
X-Backend-Name
Accept-Language
X-Debug-Info
X-Akamai-Edgescape
X-APP-VERSION
X-Mg-Request-UUID
X-Oracle-Dms-Ecid
X-Cache-Action
X-Litespeed-Cache
X-Oracle-Dms-Rid
X-Http-Reason
Section-Io-Cache
X-Time
Protected
X-IPLB-Request-ID
X-VC-Cache
X-IPLB-Instance
Content-Secure-Policy
Xserver
X-Server-ID
X-Tt-Logid
Server-Info
X-Generation-Time
X-Hosted-By
X-HTML-Minification-Powered-By
X-FW-Hash
X-FW-Dynamic
X-Tec-Api-Root
X-FW-Serve
X-FW-Server
X-FW-Type
X-FW-Static
X-Tec-Api-Origin
X-Azure-Ref
X-Tec-Api-Version
Backend
X-Generated-By
X-App-Server
X-Api-Version
X-Storage
X-RN-RSRV
X-UPSTREAM-Address
Meta-Geo
X-Amz-Apigw-Id
X-Cache-Status-Check
X-Restarts
X-Amzn-RequestId
X-SRV
X-R9-Blue-Green-Version
X-Cache-Server
X-Device-Type
X-Varnish-Cache-Hits
X-Access
X-Cms-Context
X-Mobile-URL
Webcakes-Region
Webcakes-App-Name
CF-IPCountry
X-Format
X-Handled-By
Onion-Location
X-Section
X-RTag
X-PCL
X-OCL
X-Origin-Hint
TWC-Privacy
Webcakes-App-Version
Property-Id
TWC-GeoIP-Country
TWC-Connection-Speed
TWC-Device-Class
Ms-Operation-Id
TWC-GeoIP-LatLong
TWC-Locale-Group
MS-CV
Azure-Version
X-Content
X-Provided-By
X-Server-W
Azure-SlotName
Azure-InstanceId
X-Adobe-Source
X-Mode
X-AWS-Id
Azure-RegionName
Liferay-Portal
Azure-SiteName
X-Locale
X-SaId
X-VWS-Id
X-LJ-Flow-ID
X-Proto
X-JoinUs
X-No-Session
X-Proxy-Cache-Status
GEO-INFO
X-Varnish-Hostname
X-Labrador-Cache-Channel
X-PHP-Host
DB-Nickname
Eomportal-Instance
X-Edge-Location
X-Xfnlog-Site
X-FireWall-Port
X-PHP-Backend
X-Ms-Version
X-UA-Device-Type
X-Sql-Duration-Ms
X-Sql-Count
X-Via-Fastly
X-Varnish-Beresp-Grace
X-Ms-Request-Id
X-Skip-Cache
X-Request-Time
X-Cache-Host
X-GeoCode
X-Say-Cacheable
Web-Mar-Node
X-Forwarded-Host
X-FB-TRIP-ID
X-Detected-As
X-Region
X-Cache-Type
X-GeoCountry
Mn-Server-Ip
X-Say-TTL
X-SayCDN-TTL
X-Varnishpool
X-Urbn-Site-Id
CDN-RequestId
CDN-Cache
CDN-Uid
X-Routing-Service
X-Shopify-Stage
X-Extlb
X-ProxyCache-Status
X-Content-Age
Apigw-Requestid
CDN-CachedAt
X-ShardId
Cache-Name
X-Sorting-Hat-ShopId
X-BYPASS-REASON
X-Zipkin-Id
X-Site-Version
X-Hl-Ver
CDN-PullZone
X-Proxied
X-ProxyCache-Key
X-Web-Node
X-Sorting-Hat-PodId
X-Alternate-Cache-Key
CDN-EdgeStorageId
Locale
X-ShopId
CDN-RequestCountryCode
X-Urbn-Context-Path
X-Nginx-Cache-Key
S-Rt
X-Tid
Load-Balancing
X-Correlation-ID
X-Storefront-Renderer-Rendered
X-Redis-Cache
WP-Super-Cache
X-DynaTrace-JS-Agent
X-URL
X-Dc
Selected-Fe
X-Timing-Wait
X-Proxy-Build
X-Vgn-Hpd-Reason
X-WP-CF-Super-Cache
X-Reqid
X-ServerID
X-WP-CF-Super-Cache-Cache-Control
X-Amzn-Remapped-Content-Length
X-ECache
X-LSADC-Cache
X-Pubstack
X-Cache-Enabled
X-Ua
X-Loop
X-TNCMS
X-Cdn
X-Uri
X-Varnish-Ttl
X-Soup
X-B3-Traceid
X-Tumblr-Pixel-2
X-Zen-Fury
X-TIME
X-Origin-Date
X-Newrelic-Synthetics
X-Cache-NGX
Xet-Cookie
Fastcgi-Useragent
X-Service
From-Origin
X-Aspnetmvc-Version
X-Cache-Debug
X-Ratelimit-Remaining
X-UUID
X-Origin-TTL
ServedBy
Source
X-Origin-CC
X-App-Version
X-MP-GENERATED-AT
Origin
X-Varnish-Hits
X-Nginx-Cache
X-NewRelic-App-Data
X-GEO
X-TA-CDN-Provider
Fastly-Drupal-HTML
X-Human
X-Varnish-Beresp-Ttl
X-Cache-Tags
Cache
X-Rewrite-Enabled
X-Cluster
Upgrade-Insecure-Requests
Cross-Origin-Window-Policy
Webserver
X-ScT
SD-X-WS
BehaviorPad-Version
MD5-Digest
Rendered-Blocks
X-Cached-By
X-Ratelimit-Limit
Host-ID
WPO-Cache-Message
WPO-Cache-Status
Rip
Xc-Version
X-Ec-GeoHdr
X-External-Request-Id
X-Ec-Fail
Sslversion
X-A-Dcw
X-A-Dgt
X-A-Wwc
X-Aed
X-A-Dam
X-A-Ccd
T-Server
Surrogated-Key
X-A
X-AK-Request-ID
X-Application
X-Connection-Hash
X-D
X-Destination
X-Developer
X-Cache-NE
X-BCube-Filmed-By
X-ARC
X-B-Cookie
X-Bc-Bl
X-Vdms-Path
X-Forwarded-Path
X-Rojux
X-Vdms-Version
X-S
Lang
DCR-Processing-Time-Ms
X-Processor
Cdnsip
Meta-Geo-Continent
Expiry
X-RCS-CacheZone
Cdncip
X-Shop-Environment
X-FW-Version
X-SRCache-Key
X-Tenant
X-User
X-TIM-N
X-S-Cookie
Ngx.Var.Host
DCR-Decision-By
A
X-VG-WebCache
X-Orig-Expires
Odigeo-Trace-Id
X-NAPM-TraceId
X-PBS-Appsvrname
X-Parent-Response-Time
X-Nf-Request-Id
OT-Force-Account-Verify
X-Cluster-Node
X-Aicache-OS
X-Served-From
X-Datadome
Environment
X-Nyt-Route
X-Origin-Time
X-Gdpr
Redirect-Candidate
X-Generated-On
AKAMAI
TDXMobile
X-WP-CF-Super-Cache-Active
X-Cdn-Srv
X-Auto-Login
Thinkindot-Control
Thinkindot-CacheControl
X-CMSURLCustom
Thinkindot-CacheControl-Type
X-Developers
X-Core-Value
X-AOL-HN
X-Is-Gdpr
X-Level-Front-Cache
X-INCAP-ABP
X-Request-Host
X-Worker
LB
X-Has-Esi
X-Thinkindot-L3
X-Geo-Header
Mime-Version
X-JWT-State
NGX
Producers
NM-Fastcgi-Cache
Origin-CC
Tube-Get-Contents
Origin-EX
Traceparent
L
Platform
IsBot
Fastly-SSL
Fastly-SWR
Fastly-SIE
Kp-EeAlive
Memcached
Svr
Is-Eu
Servername
Req-Svc-Chain
X-DPWN-IS-SECURE
X-Qloud-Router
X-Proxy-Cache-Info
X-Request-URI
X-Rocket-Build-Number
X-Rocket-Nginx-Serving-Static
X-Pool
X-Platform-Server
X-NCache
X-NodeID
X-Tumblr-Pixel-3
X-VServer
X-VG-TLSProxy
X-S-Maxage
X-Varnish-Beresp-Status
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
X-Variation
X-SplitTest
X-SB
X-Sigma
X-Sigma-Backend
X-SIPLIST1
X-Minions-Version
X-Loc
X-Ad-Defer-Variation
Wxu-Next-Region
X-ATG-Version
X-BBC-Edge-Cache-Status
X-Cache-Bucket
Wxu-Next-Hostname
Wxu-Next-Commit
Tube-Got-Results
Tube-Return
VNS-Age
VNS-Cache
X-Ckpd-Fst-Backend
X-GeoIP-City
X-Epic-Correlation-Id
Datacenter
X-Fetched-On
X-GeoIP
Gh-Request-Id
X-Ec-Custom-Error
X-DefElseHash
X-DefHash
Release
X-Device-Os
Tube-Got-Eval
X-Owner
Canary
Cache-Host
Candidate-Md5Url
Click-Count-Action-Start
Click-Count-Error
X-Accel-Buffering
Apple-News-Services-Request-Url
Apple-News-Services-Handled
Adler-Geo
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
X-Debug-Cache
CloudFront-Viewer-Country
X-Pass-Why
CPC-Cache
CPC-Age
X-Cache-Remote
Fastly-Backend-Name
X-HS-Content-Campaign-Id
X-Sucuri-ID
X-Optimistic-Header
X-Sucuri-Cache
Server-Host
Vix-Hermes-Req-Id
V-Age
X-Wix-Viewer-Type
X-SVT-ORM-RULES
X-Viewer-Country
X-Sn-Servicetimems
X-Gateway-Request-Id
X-Fmm-Version
Web-Mar-Region
We-Hiring
X-V-Cache
X-Gzip
X-SVT-ORM-VERSION
X-Scheme
X-Datadog-Parent-Id
X-Core-Mission
X-Clara-WADP
X-RateLimit-Limit-Second
X-Datadog-Sampling-Priority
X-Datadog-Trace-Id
X-Dispatcher-Number
X-Udemy-Cache-App-Namespace
X-Origin
X-Origin-Response-Time
X-RateLimit-Remaining-Second
X-Cdn-Origin
X-Scale
X-Azure-Ref-OriginShield
X-Gateway-Skip-Cache
X-Esi-Check
X-Branch-Name
X-Cache-Id
X-CacheTTL
X-Region-Sid
X-Cache-Info
X-Hash
X-WADP-Cache
Machine
CDCHOST
Cluster
Mail-Subject
X-Thanos
X-Gamma-Serve
X-Policy
Ha-Gx-Prefs
Fastly-GeoIP-CountryCode
X-Gateway-Cache-Key
Decoy-Debug-Status
Decoy-Debug-Key
Country-Code
Decoy-Debug-TTL
DSUID
Cmsid
Cmstype
X-Gateway-Cache-Status
X-Eu-Site
Mobile-Detection-Method
X-Bip
State
X-CGP
Server-Ext
Server-Hostname
L5d-Success-Class
Sever-Int
HA-Ipaddr
X-Csrf-Jwt
X-IPS-LoggedIn
X-Presslabs-Stats
X-Up
X-Var-Ttl
X-Clientip
X-Planisys-CDN-TTL
X-Forwarded-Site
Time
X-LB-NoCache
X-Hnp-Log
X-Tx-Id
X-Planisys-CDN-Cache
User-Cache-Control
X-Planisys-CDN-Rules
X-Gen-Mode
X-Mvc-Supplant-Cachable
X-Slack-Backend
X-Irp-Debug
Ec-Rule-Version
X-FC-Vary-Parameters
Memory
X-Fastly-Backend
X-Block-Status
WebServer
X-Akamai-Transformed
X-ZONE
Pics-Label
HostName
X-CSRF-Token
X-Mvc-Supplant-OutputCached
X-Dispatch
AMP-Access-Control-Allow-Source-Origin
Sid
X-VC
Ssr
X-Edge-Pop
X-ND-Cache
X-Tb-Optimization-Total-Bytes-Saved
Request-ID
X-Newrelic-App-Data
X-B3-SpanId
X-Via-Popv
X-Refresh
X-Via-Poph
My-App
X-Servedbyhost
X-Xrds-Location
X-Req
X-Via-Popn
X-WA-Info
Cache-Tv-Group
X-Via-NSCOPI
X-Cs
X-GG-Cache-Date
X-NGINX-Cache
X-Wa
X-Generated-In
X-Lambda-Id
Env
Fastcgi-Cache-TTL
Server-ID
X-B3-Spanid
SID
X-Session-Fingerprint
CacheControlHeader
True-Client-Country-4JS
X-Trace-ID
X-CACHE-AGE
X-Rebelmouse-Cache-Control
Cache-Hits
X-Pod-Name
X-Rebelmouse-Surrogate-Control
X-Fpc
GeoIp-Country-Code
X-Fastly-Cache
X-Origin-Expires
X-Release
X-Vc
X-EC-Lua
X-PX
True-Client-IP
X-ID
X-Op-Id-All
X-LB-ID
Hostname
X-MCACHE
X-TX-ID
X-CSRF-TOKEN
X-Zone
X-NWS-UUID-VERIFY
X-VCL-Version
X-TRACE-ID
X-Webkit-CSP-Report-Only
X-GeoIP-Region-Code
X-GeoIP-Country-Code
X-MSEdge-Features
X-DC
X-TH-Server
X-MSEdge-Flight
X-Ig-Push-State
X-Cache-Date
X-Buckets
X-CACHE-KEY
X-Endurance-Cache-Level
X-Conf
X-HS-Status
X-NC
WWW-Authenticate
Resin-Trace
X-Srv
X-RAMCache
X-Microcachable
X-Date
X-Dmc
X-Accel-Expires-Debug
CDN
X-CS
X-Esi
X-Old-Content-Length
X-RateLimit-Reset
Tcn
Fastly-Drupal-Html
Powered-By
X-Vcl-Version
X-Check-Cacheable
Magicmarker
X-Varnish-Beresp-TTL
Path
X-Location
True-Client-Ip
X-API-Version
Section-Io-Id
GeoIP-Country-Code
X-Webstats-RespID
X-Alfa-Service
X-Wikidot-Static-Cache
X-Lb-Id
X-Datacenter
Section-Io-Origin-Status
X-Wikidot-Backend
X-Akamai-Pragma-Client-IP
Section-Io-Origin-Time-Seconds
X-Director
Section-Origin-Responded
X-Varnish-Authentication
X-Cache-ASPX
X-LiteSpeed-Cache-Control
X-Be
X-Contensis-Viewer-Groups
Yjs-Id
X-CLOUD-TRACE-CONTEXT
X-Cache-Ttl
Proxy-Connection
X-FPC
X-Vercel-Cache
X-Geo
X-Vercel-Id
X-DataCenter
X-WA
Cdn
X-Mly-Id
X-Via-CDN
FSS-Cache
Pramga
X-Test
X-Hyper-Cache
X-Micro-Cache
X-CF-Lambda-Fn
X-CF-Lambda-Version
User-Agent
X-ServedByHost
Server-Id
ENV
X-Response-By
X-Cache-Backend
X-Server-IP
X-M-Log
X-M-Reqid
Lb
M-TraceId
X-HA-Backend
X-Cdn-Forward
X-Cc-Via
X-Dw-Trace-Id
Tracecode
X-Via-PopN
X-Via-PopH
Uri
X-Akamai-ERRuleID
X-Akamai-ERPolicy
X-Cache-Expires
X-App
X-Via-PopV
X-PERF
X-ApacheServer
HIT
X-Client-Ip
X-Qnm-Cache
X-We-Are-Hiring
YJS-ID
X-AIR-PT
Sm-Log-Id
X-Service-Response-Time
X-Edge-POP
X-Li-Pop
Geoip-Latitude
X-Traceid
X-From
X-UA
Dnion-Transfer-Encoding
X-Instance-Name
Locid
Srvid
X-Li-Fabric
X-FL-EDGE
X-LI-Proto
X-LiteSpeed-Tag
X-Frame-Option
XM
X-TrackingId
N-Cache
C-Via
Location
Swift-Performance
X-Air-Hostname
X-Air-Source
X-Air-Trace-Id
X-TT-LOGID
X-LI-UUID
X-HITS
X-Info
X-DSS
X-RPS
X-DW
X-RPM
CountryCode
CF-Cached-On
X-DI
X-VarnishDD-TTL
X-HN
Nginx-CQVIP
X-RSL
PFcat
X-Platform
Ohc-File-Size
PICS-Label
Esi-Enabled
XServer
X-DB
X-Air-Pt
X-Fastly-Backend-Reqs
X-Platform-Cluster
X-Platform-Processor
X-Platform-Router
X-Wp-Cf-Super-Cache-Cache-Control
X-Wp-Cf-Super-Cache
X-HostName
Vha6-Origin
Cneonction
On-Server
X-Cache-Proxy
NtCoent-Length
Timeexpire
X-Request-Url
X-Fastly-Cache-Hits
Hit
Fastcgi-X-Cache-Version
X-Conten-Type-Options
X-Lb-Nocache
X-Oss-Storage-Class
Wpo-Cache-Message
X-Oss-Request-Id
X-Oss-Server-Time
X-Oss-Hash-Crc64ecma
X-PAYTM-SRV-ID
X-Oss-Object-Type
Wpo-Cache-Status
X-Cdn-Request-ID
X-CF-Powered-By
X-Litespeed-Cache-Control
X-Cache-Ngx
Wp-Super-Cache
X-Ips-Loggedin
Warning
X-NFL-Geo
X-NS-Authorization
X-Ntj-Investigation-Id
X-NFL-Dma
X-Newegg-Index
X-Newegg-Flow
X-Nerd
X-N-OperationId
X-MTS-Cache
X-OVcl
X-Paywall
X-PageType
X-PG-ACCESS
X-Ee-Request-Id
X-PGF-Deflate
X-OVcl-Cache
X-Matome-Cached
X-Odoo-Frontend
X-Nyt-Data-Last-Modified
X-Okws-Version
X-Onedio-Env
X-Origin-Ops
X-NXG
X-Is-SSL
X-Fstrz
X-Pver
X-Full-Ttl
X-GG-Cache-Status
X-Git-Commit
X-Fastly-Is-Edge
X-Farm
X-ETag
X-Eid
X-Eventloop-Lag
X-F-Status
X-Global-Transaction-ID
X-GoCache-CacheStatus
X-Kebabable
X-Keep
X-LbNode
X-Loadbalancer
X-Kebab
X-Ittl
X-Group
X-Header-Sub
X-IBD-Cache
X-IBD-SID
X-Matched-Rule
X-Stack-Name
X-Wag-Acs
X-Ver
X-Waitingroom
X-Web-Hosting
X-WP-Bypass
X-Vary-Devices
X-V2-Infrastructure
X-U-Cache
X-Upstream-State
X-User-Auth
X-Utime
X-WSR2
X-Xms-Page-Cache-Actions
X-Ee-Request-Date
Create-Date
Cache-Key
X-SD-PageType
X-Request-URL
MIME-Version
X-Fastly-Country-Code
X-YSpaceId
XV-Cache
XV-H
X-B3-Parentspanid
X-True-Client-Ip
X-Tried-To-Kebabify
X-Ruby
X-Route-Akamai
X-Save-Cache
X-Server-L
X-ServiceName
X-Route
X-Request-Origin
X-Reboot
X-Redis
X-Render-Method
X-Render-Time
X-Sh
X-Site
X-Test-Nginx-Ingress
X-Timestamp
X-Toujours-Debout-Branch
X-Toujours-Debout-Location
X-Svr-Proxy
X-SVR-IIS
X-Slack-Shared-Secret-Outcome
X-SMP-JWT
X-Square
X-SSLProxy
X-R-Cache
TWC-PATH-LOCALE
Ns-Ua
Ns
Ok-Cache-Status
OK-Edge-Date
Origin-Site
Ok-Edge-Key
Npm-Remaining
Npm-Cost
Joe-X
Is-Https
NB-ESI
Nikkei-App-Version
NLCacheNote
Panzer-Cache-Control
Proxy-Cache
SFRVia
Service-Uuid
Shieldsquare-Response
SII
Store-Cloud-Cache
Served
Selected-Route
Region
RawURL
Request-Uuid
Rt-Proxy-Cache
Scheme
HTTPProtocol
HServer
X-ElasticPress-Query
X-Mg-Cache
X-Yottaa-OS
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
X-B3-ParentSpanId
WZWS-RAY
Req-ID
X-CUA
Fastcgi-Cache-Ttl
SRV
DynaTrace
X-Serial
X-Th-Server
CMS-200
Cluster-Host
Deeplink
Ec-Policy-Id
H1
Cf-Wrk
Cf-Locale
Cache-Stat
Akamai-X-Url
Cachekey
Cdn-Country-Code
Cf-Device-Type
Sw
T-Request-Id
X-Cache-ReqUri
X-Cache-Reason
X-Cache-Response
X-CacheVersion
X-CDN-Pop
X-Cache-NPR
X-Cache-Length
X-BeanStalkRole
X-Backside-Transport
X-BeanStalkStage
X-Cache-Cookie
X-Cache-IsMobileDevice
X-CDN-Pop-IP
X-Cf-Node-Idx
X-Doge
X-Developed-By
X-DT-Node
X-Edge-IP
X-Ee-Generated-By
X-Delivery
X-Dehri-Date
X-Coindesk-Cache
X-Cms-Device
X-Colour
X-Container-Uri
X-Dcm-Pdtf
X-Backend-TTL
X-AspNetWebPages-Version
Vttl
Userver
X-77-NZT
X-77-NZT-Ray
X-Accel-Version
Uniqueid
TWC-Unit
Time-Cloud-Cache
Technodrome
Ttl
TWC-AK-Req-ID
TWC-Subs
X-Accepted-Fulllang
X-Accepted-Language
X-Ar-Stats
X-Apache-Server
X-Arena-Request-Id
X-ARRRG1
X-ASF-Cache
X-Amz-Meta-Cb-Modifiedtime
X-Akamai-Native
X-AEO-Platform
X-Accor-Asset
X-Akamai-CacheKeyMod
X-Akamai-DeviceOS
X-Akamai-DeviceType
X-Ee-Origin