Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
Strict-Transport-Security
X-Frame-Options
X-Content-Type-Options
Last-Modified
Link
CF-Cache-Status
Cf-Request-Id
CF-RAY
Accept-Ranges
ETag
Expect-CT
Pragma
X-Powered-By
X-Cache
Via
X-XSS-Protection
Age
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Xss-Protection
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-FRAME-OPTIONS
X-Served-By
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Request-Id
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-Adblock-Key
X-AspNet-Version
X-Permitted-Cross-Domain-Policies
Alt-Svc
X-Runtime
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Cache-Status
X-Check
X-Generator
X-Cacheable
X-Request-ID
X-Iinfo
P3p
X-Envoy-Upstream-Service-Time
Timing-Allow-Origin
Feature-Policy
X-Content-Security-Policy
Status
X-Drupal-Dynamic-Cache
Content-Encoding
Access-Control-Expose-Headers
X-AspNetMvc-Version
Upgrade
X-CDN
X-Ua-Compatible
Access-Control-Max-Age
CF-Ray
X-Via
X-Robots-Tag
X-Cache-Group
Server-Timing
X-UA-Device
Request-Context
Keep-Alive
X-AH-Environment
X-Amz-Request-Id
X-Turbo-Charged-By
X-Proxy-Cache
X-Backend
X-Amz-Id-2
X-Age
X-Ws-Request-Id
Host-Header
X-Dns-Prefetch-Control
X-Hacker
X-Server-Powered-By
X-Server
X-Rq
X-Vhost
X-LiteSpeed-Cache
X-Varnish-Cache
X-Amz-Version-Id
Grace
X-Dispatcher
Cf-Edge-Cache
EagleId
Allow
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
X-Page-Speed
X-Nginx-Cache-Status
X-WebKit-CSP
X-Swift-SaveTime
X-Swift-CacheTime
Accept-CH
X-Aws-Lambda-Call-Status
Ali-Swift-Global-Savetime
X-Node
X-Host
Cf-Railgun
X-Pingback
X-Cache-Spec
X-Server-Id
X-OneAgent-JS-Injection
X-Backend-Server
X-Akam-SW-Version
Surrogate-Control
Request-Id
EagleEye-TraceId
X-Response-Time
X-Cache-Lookup
Accept-CH-Lifetime
X-Readtime
X-Akamai-Path-Stats
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Content-Location
X-HW
X-Content-Security-Policy-Report-Only
X-Application-Context
Rating
X-Cloud-Trace-Context
X-Trace
Fastly-Restarts
X-WebKit-CSP-Report-Only
X-Clacks-Overhead
X-Nginx-Upstream-Cache-Status
X-Country
X-Url
X-MS-InvokeApp
X-Oneagent-Js-Injection
Accept-Ch-Lifetime
X-Amz-Server-Side-Encryption
X-CST
X-Rack-Cache
X-Edge
X-PC
X-TtlSet
X-Vname
Edge-Control
X-Ruxit-Js-Agent
X-Mod-Pagespeed
X-Content-Type
X-B3-TraceId
X-Vcap-Request-Id
X-ESI
X-FastCGI-Cache
X-D2id
Verso
Xkey
X-GoogleNews-Bot
X-Kinja-Revision
X-Kinja-Build
X-Kinja-Server
X-Kinja
X-Exp-Id
X-Cdn-Fetch
X-Exp-Variant
X-Use-Magma
X-GitHub-Request-Id
Cache-Tag
X-Mcache
Service-Worker-Allowed
X-Amz-Rid
X-Powered-By-Plesk
Cf-Apo-Via
X-Ruxit-JS-Agent
RTSS
X-Varnish-TTL
X-Navigation-Version
X-ECACHE
X-Abt-Application-Version
X-Server-Name
X-VARITI-CCR
X-Version
X-Upstream
X-Client-IP
X-Ttl
X-Cached
X-Ac
X-Cnection
X-Element-Page-Cache
Arr-Disable-Session-Affinity
X-Dw-Request-Base-Id
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-Instrumentation
SPRequestGuid
X-SharePointHealthScore
Permissions-Policy
SPRequestDuration
X-Px
SPIisLatency
X-Sol
X-Middleton-Display
Display
Pagespeed
Public-Key-Pins
X-Cache-TTL
X-Country-Code
X-RateLimit-Remaining
X-NWS-LOG-UUID
Response
X-Middleton-Response
X-Ser
X-Kinsta-Cache
X-Edge-Location-Klb
X-Midtier
X-Goog-Hash
X-Forwarded-For
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Cache-Key
X-ORACLE-DMS-ECID
Content-MD5
X-ORACLE-DMS-RID
X-Correlation-Id
X-NF-Request-ID
X-Shield-Request-Id
Access-Control-Request-Method
Front-End-Https
X-MSEdge-Ref
X-Recruiting
X-T
X-DataDome
AR-SID
AR-ATIME
AR-Request-ID
AR-PoweredBy
AR-CACHE
MRF-Tech
TP-L2-Cache
Mrf-Cache-Status
TP-Cache
X-B3-TraceId-Primal
Edge-Cache-Tag
X-Jurisdiction
X-HP-Trace-Id
X-RateLimit-Limit
MicrosoftSharePointTeamServices
X-HP-Webp
Nginx-Cache
Accept-Ch
X-Accel-Expires
X-Daa-Tunnel
X-Mg-S
X-Powered-CMS
X-Grace
X-Content-Digest
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Browser-Type
X-Hits
X-Request-Received
X-Request-Processing-Time
X-Amzn-Trace-Id
TCN
X-HS-Hub-Id
X-HS-Cache-Config
X-TEC-API-VERSION
X-HS-Combine-CSS
X-TEC-API-ORIGIN
Server-Node
X-TEC-API-ROOT
X-HS-Content-Id
Server-Name
Filters
X-Id
MS-Author-Via
X-Geo-Country
Fastcgi-Cache
X-Fastly-Request-Id
X-Webkit-Csp
X-Frontend
X-Distributor
Count-Hit
X-PressLabs-Stats
X-Origin-Server
X-XRDS-Location
X-Ezoic-Cdn
X-Ua-Browser
Filterid
X-LLID
X-Protected-By
S
X-Language
X-ASPNET-VERSION
X-F-Cache
X-Forwarded-Proto
Cross-Origin-Opener-Policy
X-Microsite
X-Seen-By
X-Amz-Meta-S3cmd-Attrs
X-B3-Sampled
X-FB-Debug
X-Request-Handler-Origin-Region
Charset
X-Git-Hash
Host
Payment
X-LB-Cache
Cache-Status
X-Page-Id
X-Ratelimit-Reset
X-Ab
X-VCache
X-Cluster-Name
Surrogate-Key
X-Rid
Cache-Tags
X-Cdn
X-Www-Served-By
Realpath
X-Upgrade-Enabled
X-Logged-In
Access-Control-Allow-Method
Retry-After
Accept-Charset
X-Source
X-Cache-Age
Alternate-Protocol
X-Origin-Cache
X-DIS-Request-ID
X-Varnish-Backend
X-NGENIX-Cache
X-Az
X-Activity-Id
X-AppVersion
X-Type
X-Template
Cleartype
Paypal-Debug-Id
X-Amz-Replication-Status
DC
X-Request-Guid
X-Flags
X-Providence-Cookie
X-Varnish-Grace
X-B-Cache
X-Route-Name
X-Is-Crawler
X-App-Environment
X-Tb
X-Envoy-Decorator-Operation
X-Wix-Request-Id
X-Signature
X-Aspnet-Duration-Ms
X-TT
ServerID
X-B
X-Hostname
X-Revision
X-DynaTrace
X-TTL
X-Fastcgi-Cache
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
Frame-Options
X-Node-Name
X-Contextid
X-Cache-Rule
X-Drupal-Cache-Tags
X-Proxy
X-Tt-Trace-Tag
X-Tt-Trace-Host
Pinterest-Version
X-Pinterest-Rid
Pinterest-Generated-By
X-Goog-Generation
X-Goog-Stored-Content-Length
X-Goog-Metageneration
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-GUploader-UploadID
X-Debug
Refresh
Cross-Origin-Resource-Policy
X-Fastly-Request-ID
X-Content-Options
X-Mobile
X-Load-Cache
X-XRDS-LOCATION
Referer-Policy
X-Cache-Control
X-N
Amp-Access-Control-Allow-Source-Origin
Node
X-EdgeConnect-Cache-Status
Country
X-Response-Served-From
X-Original-Request-Id
NGB
X-Magnolia-Registration
X-Varnish-Server
X-Varnish-Age
X-Debug-IsPreview
X-Debug-IsConnected
X-Trace-Id
Akamai-GRN
X-NYM-Debug-Backend
Viewport
X-Environment-Context
X-Cache-Time
X-L-Path
X-Cache-TTL-Remaining
Content-Disposition
X-Content-Powered-By
X-Status
X-Instance
X-Real-IP
X-Servername
X-Rendered-As
X-Whom
X-Cache-Grace
X-Akamai-Request-ID2
X-G
X-Is-Bot
X-Jobs
X-Adobe-Loc
X-Adobe-Content
Uber-Trace-Id
Access-Control-Request-Headers
Url
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Page-View
X-Cacheable-TTL
X-COUNTRY
X-ProcessESI
X-User-Agent
X-Mid
X-RemovedCookies
X-Framework
X-Yottaa-Optimizations
Srv
X-Yottaa-Metrics
X-Unique-Id
X-Cache-Expired-At
X-Via-JSL
X-Drupal-Cache-Contexts
Countrycode
X-Cache-Hit
X-CDN-Forward
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Tumblr-User
X-Tumblr-Pixel-1
X-Cache-Operation
Version
Accept-Language
Healthy
X-Rule
X-Mg-Request-UUID
X-Litespeed-Cache
X-Http-Reason
X-Backend-Name
X-Time
X-Akamai-Edgescape
X-Cache-Action
X-APP-VERSION
X-Api-Version
X-Server-ID
X-Debug-Info
Protected
X-App-Server
X-Content
Section-Io-Cache
Content-Secure-Policy
X-IPLB-Instance
X-Azure-Ref
X-IPLB-Request-ID
Backend
X-VC-Cache
X-Hosted-By
X-Generation-Time
Server-Info
Xserver
X-Restarts
X-SRV
X-Ratelimit-Remaining
X-HTML-Minification-Powered-By
Meta-Geo
X-Generated-By
Load-Balancing
X-Storage
X-RN-RSRV
X-FW-Hash
X-FW-Dynamic
X-FW-Serve
X-FW-Server
X-FW-Static
X-FW-Type
X-Tt-Logid
X-Mobile-URL
X-URL
X-UPSTREAM-Address
X-Amz-Apigw-Id
X-Amzn-RequestId
Liferay-Portal
X-Oracle-Dms-Ecid
CF-IPCountry
X-Device-Type
GEO-INFO
Onion-Location
X-Oracle-Dms-Rid
X-PCL
X-OCL
TWC-GeoIP-LatLong
X-Locale
X-Format
X-Origin-Hint
X-Access
S-Rt
TWC-Locale-Group
TWC-Connection-Speed
TWC-Device-Class
TWC-GeoIP-Country
Property-Id
TWC-Privacy
X-Cms-Context
Webcakes-Region
Webcakes-App-Version
Webcakes-App-Name
X-FireWall-Port
X-Handled-By
X-Section
X-Cache-Status-Check
X-Nginx-Cache-Key
X-Varnish-Cache-Hits
X-Mode
Azure-InstanceId
Azure-RegionName
X-Server-W
CDN-Cache
X-Adobe-Source
X-Varnish-Hostname
X-JoinUs
X-AWS-Id
Azure-SiteName
Web-Mar-Node
Azure-Version
Ms-Operation-Id
MS-CV
X-LJ-Flow-ID
X-Region
X-Labrador-Cache-Channel
X-VWS-Id
Locale
X-Cache-Host
X-Redis-Cache
X-Site-Version
Eomportal-Instance
Azure-SlotName
CDN-Uid
X-Proxy-Cache-Status
X-Urbn-Site-Id
X-PHP-Host
X-Forwarded-Host
X-Skip-Cache
CDN-RequestCountryCode
CDN-CachedAt
CDN-PullZone
X-Cache-Server
X-Provided-By
CDN-EdgeStorageId
X-RTag
X-Urbn-Context-Path
CDN-RequestId
X-Varnish-Beresp-Grace
X-Edge-Location
X-SayCDN-TTL
X-Content-Age
X-R9-Blue-Green-Version
X-Sql-Duration-Ms
X-Sql-Count
X-SaId
X-Say-Cacheable
X-Say-TTL
X-PHP-Backend
X-Proto
X-Web-Node
Cache-Name
Apigw-Requestid
X-Xfnlog-Site
X-Zipkin-Id
X-Proxied
X-Sorting-Hat-PodId
DB-Nickname
X-No-Session
X-ShardId
X-ShopId
X-Shopify-Stage
X-Request-Time
X-FB-TRIP-ID
X-Sorting-Hat-ShopId
X-Cache-Type
Mn-Server-Ip
X-Alternate-Cache-Key
X-Detected-As
X-Routing-Service
X-Via-Fastly
X-Varnishpool
X-Extlb
X-Tid
X-UA-Device-Type
X-BYPASS-REASON
X-Ms-Version
X-GeoCountry
X-GeoCode
X-Ms-Request-Id
X-ProxyCache-Key
X-Hl-Ver
X-ProxyCache-Status
X-Storefront-Renderer-Rendered
X-ECache
X-Cache-Enabled
X-DynaTrace-JS-Agent
WP-Super-Cache
Selected-Fe
X-Uri
X-Timing-Wait
X-ServerID
X-Proxy-Build
X-Varnish-Ttl
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
X-TNCMS
X-B3-Traceid
X-Loop
X-Amzn-Remapped-Content-Length
X-Vgn-Hpd-Reason
X-Dc
X-Ua
X-Reqid
X-Cache-NGX
X-Nginx-Cache
X-Pubstack
X-LSADC-Cache
Fastcgi-Useragent
X-Origin-Date
Xet-Cookie
X-App-Version
X-Soup
X-UUID
X-Correlation-ID
X-Tumblr-Pixel-2
X-Aspnetmvc-Version
X-Zen-Fury
X-Ratelimit-Limit
ServedBy
X-Service
X-Webkit-CSP
X-Newrelic-Synthetics
X-Datadome
From-Origin
X-MP-GENERATED-AT
X-TIME
X-TA-CDN-Provider
X-Origin-CC
X-Varnish-Hits
X-Origin-TTL
X-Cache-Debug
Origin
X-Human
Source
Cache
X-GEO
X-Cache-Tags
X-Cached-By
X-Varnish-Beresp-Ttl
X-Tec-Api-Root
X-Tec-Api-Version
Cross-Origin-Window-Policy
X-NewRelic-App-Data
X-Tec-Api-Origin
X-RCS-CacheZone
Rip
Rendered-Blocks
WPO-Cache-Message
BehaviorPad-Version
X-ScT
WPO-Cache-Status
Fastly-Drupal-HTML
MD5-Digest
X-Request-Host
Upgrade-Insecure-Requests
Host-ID
X-Rewrite-Enabled
X-Debug-Cache
LB
X-AK-Request-ID
X-Processor
Sslversion
X-Aed
CPC-Age
SD-X-WS
VNS-Cache
X-Cache-NE
X-Parent-Response-Time
Meta-Geo-Continent
Environment
Expiry
X-Developer
A
X-Ec-Fail
Cdncip
CPC-Cache
DCR-Decision-By
DCR-Processing-Time-Ms
Cdnsip
X-Ec-GeoHdr
X-Destination
Ngx.Var.Host
X-Application
X-NAPM-TraceId
Odigeo-Trace-Id
X-ARC
Lang
X-External-Request-Id
X-Forwarded-Path
X-D
X-Connection-Hash
X-Orig-Expires
X-PBS-Appsvrname
X-User
X-Vdms-Path
X-TIM-N
X-Bc-Bl
T-Server
Surrogated-Key
X-A-Dgt
X-Shop-Environment
X-A-Dam
X-Vdms-Version
X-A
X-B-Cookie
X-VG-WebCache
X-Rojux
X-Tenant
X-SRCache-Key
X-A-Ccd
Xc-Version
X-A-Dcw
VNS-Age
X-A-Wwc
X-S-Cookie
X-BCube-Filmed-By
X-S
X-Cluster
OT-Force-Account-Verify
X-Gdpr
X-Owner
X-FW-Version
Mime-Version
X-Nyt-Route
Webserver
X-Dispatcher-Number
X-Accel-Buffering
X-Origin-Time
X-Served-From
Redirect-Candidate
X-Aicache-OS
X-WP-CF-Super-Cache-Active
X-Core-Value
X-Generated-On
X-Has-Esi
X-Geo-Header
X-Cdn-Srv
X-Developers
Fastly-Backend-Name
Thinkindot-CacheControl
X-HS-Content-Campaign-Id
Thinkindot-CacheControl-Type
TDXMobile
X-Auto-Login
Thinkindot-Control
Server-Host
AKAMAI
X-Level-Front-Cache
X-Sucuri-ID
WebServer
X-Worker
X-CMSURLCustom
X-Sucuri-Cache
X-Thinkindot-L3
X-INCAP-ABP
X-JWT-State
X-Is-Gdpr
Vix-Hermes-Req-Id
X-Device-Os
Wxu-Next-Hostname
V-Age
Decoy-Debug-TTL
X-DPWN-IS-SECURE
Decoy-Debug-Status
Web-Mar-Region
Datacenter
Wxu-Next-Region
Wxu-Next-Commit
Decoy-Debug-Key
Fastly-GeoIP-CountryCode
Fastly-SIE
X-Core-Mission
Origin-EX
X-Cdn-Origin
Platform
X-Azure-Ref-OriginShield
Origin-CC
X-BBC-Edge-Cache-Status
X-Ckpd-Fst-Backend
Traceparent
Svr
Producers
X-Cache-Id
X-Cache-Bucket
X-Branch-Name
State
X-Cache-Info
Release
X-Ad-Defer-Variation
Req-Svc-Chain
X-Clara-WADP
Tube-Get-Contents
IsBot
Kp-EeAlive
L
Is-Eu
Gh-Request-Id
Fastly-SWR
X-DefHash
X-DefElseHash
Tube-Return
Machine
NGX
Tube-Got-Eval
NM-Fastcgi-Cache
Mobile-Detection-Method
Tube-Got-Results
X-Cluster-Node
Memcached
Fastly-SSL
X-GeoIP-City
X-Rocket-Build-Number
X-Request-URI
X-Region-Sid
X-RateLimit-Remaining-Second
X-Rocket-Nginx-Serving-Static
X-S-Maxage
X-Scheme
X-Scale
X-SB
X-RateLimit-Limit-Second
X-Qloud-Router
X-Planisys-CDN-Cache
X-Origin-Response-Time
X-Origin
X-Planisys-CDN-Rules
Country-Code
X-Proxy-Cache-Info
X-Pool
X-Platform-Server
X-Sigma
X-Sigma-Backend
X-VG-TLSProxy
X-Varnish-Remaining-TTL
X-Varnish-CookieINHashed-On
X-Viewer-Country
X-AOL-HN
X-Wix-Viewer-Type
X-WADP-Cache
X-VServer
X-Varnish-CookieHashed-On
X-Varnish-Beresp-Status
X-Sn-Servicetimems
X-Slack-Backend
X-SIPLIST1
X-SplitTest
X-SVT-ORM-RULES
X-Variation
X-V-Cache
X-SVT-ORM-VERSION
X-NodeID
X-Planisys-CDN-TTL
X-NCache
X-Fastly-Backend
CloudFront-Viewer-Country
X-Fetched-On
X-Fmm-Version
Cmsid
X-Gamma-Serve
Cluster
X-Esi-Check
X-Epic-Correlation-Id
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
Candidate-Md5Url
Apple-News-Services-Host
Click-Count-Action-Start
Adler-Geo
Click-Count-Error
Apple-News-Services-Handled
X-Gateway-Cache-Key
X-Gateway-Cache-Status
X-Gzip
X-ATG-Version
X-Ec-Custom-Error
X-Loc
X-Minions-Version
X-GeoIP
X-Hash
X-Gateway-Request-Id
X-Gateway-Skip-Cache
Cmstype
X-Cache-Remote
Cache-Host
X-Datadog-Sampling-Priority
X-Datadog-Trace-Id
We-Hiring
Mail-Subject
Canary
X-CacheTTL
X-Datadog-Parent-Id
X-FC-Vary-Parameters
X-Hnp-Log
X-Policy
X-Irp-Debug
X-Clientip
X-Mvc-Supplant-Cachable
X-CGP
X-Gen-Mode
X-Block-Status
X-Eu-Site
X-Thanos
X-Forwarded-Site
X-Csrf-Jwt
X-Bip
X-Var-Ttl
X-Optimistic-Header
L5d-Success-Class
Server-Ext
HA-Ipaddr
Ha-Gx-Prefs
CDCHOST
DSUID
Server-Hostname
X-Udemy-Cache-App-Namespace
User-Cache-Control
Sever-Int
Servername
X-Pass-Why
AMP-Access-Control-Allow-Source-Origin
X-IPS-LoggedIn
Ec-Rule-Version
X-Tumblr-Pixel-3
HostName
Sid
X-CSRF-Token
X-Mvc-Supplant-OutputCached
X-LB-NoCache
X-Up
X-Nf-Request-Id
X-VC
X-Tx-Id
X-B3-SpanId
Pics-Label
Memory
Time
X-ND-Cache
X-Tb-Optimization-Total-Bytes-Saved
Ssr
X-Presslabs-Stats
Request-ID
X-Dispatch
X-Via-NSCOPI
X-Trace-ID
Cache-Tv-Group
X-WA-Info
X-GG-Cache-Date
X-ZONE
Fastcgi-Cache-TTL
X-Via-Popv
X-Via-Popn
X-Via-Poph
My-App
X-Edge-Pop
X-Refresh
X-Cs
X-Lambda-Id
Server-ID
X-Akamai-Transformed
X-Session-Fingerprint
X-Newrelic-App-Data
Cache-Hits
X-Rebelmouse-Surrogate-Control
X-Release
X-Origin-Expires
X-Rebelmouse-Cache-Control
X-Pod-Name
X-Servedbyhost
X-Fastly-Cache
Env
X-Req
X-CACHE-KEY
X-Esi
X-Zone
SID
X-Wa
X-Generated-In
GeoIp-Country-Code
X-CACHE-AGE
X-PX
X-ID
X-CLOUD-TRACE-CONTEXT
True-Client-Country-4JS
X-B3-Spanid
CacheControlHeader
X-LB-ID
X-Fpc
True-Client-IP
X-EC-Lua
X-Vc
X-NGINX-Cache
X-TX-ID
Hostname
X-CSRF-TOKEN
X-DC
X-MCACHE
X-Xrds-Location
X-NWS-UUID-VERIFY
X-MSEdge-Features
X-Cache-Date
X-MSEdge-Flight
X-Ig-Push-State
X-Op-Id-All
X-Buckets
X-Webkit-CSP-Report-Only
Tcn
X-TH-Server
X-Endurance-Cache-Level
X-Conf
X-NC
X-VCL-Version
X-Microcachable
X-GeoIP-Country-Code
CDN
X-GeoIP-Region-Code
X-TRACE-ID
Fastly-Drupal-Html
X-Date
X-Dmc
X-CS
X-HS-Status
Resin-Trace
X-Accel-Expires-Debug
WWW-Authenticate
X-RAMCache
X-Vcl-Version
Path
X-RateLimit-Reset
X-Srv
Magicmarker
X-Old-Content-Length
X-Wikidot-Static-Cache
X-Wikidot-Backend
X-Check-Cacheable
X-Varnish-Beresp-TTL
Powered-By
X-Be
X-Akamai-Pragma-Client-IP
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
X-Alfa-Service
X-Vercel-Id
X-FPC
Section-Origin-Responded
X-Datacenter
X-Vercel-Cache
True-Client-Ip
Section-Io-Id
X-Geo
X-Cache-Ttl
Yjs-Id
X-LiteSpeed-Cache-Control
X-Location
X-Micro-Cache
X-WA
X-Webstats-RespID
Proxy-Connection
GeoIP-Country-Code
Pramga
X-Hyper-Cache
X-Cache-ASPX
X-Contensis-Viewer-Groups
X-API-Version
X-Varnish-Authentication
X-Via-CDN
X-Director
X-ServedByHost
X-Lb-Id
X-M-Log
X-CF-Lambda-Version
X-M-Reqid
X-Mly-Id
X-CF-Lambda-Fn
ENV
FSS-Cache
Server-Id
Tracecode
User-Agent
X-App
X-Response-By
X-Qnm-Cache
X-TT-LOGID
Lb
X-Edge-POP
X-Air-Hostname
X-Cdn-Forward
X-Air-Source
X-Dw-Trace-Id
YJS-ID
X-Air-Trace-Id
X-DataCenter
N-Cache
X-Akamai-ERRuleID
X-Via-PopH
HIT
Cdn
X-Test
X-Via-PopV
C-Via
X-Akamai-ERPolicy
X-Client-Ip
X-Server-IP
X-Via-PopN
X-HA-Backend
Sm-Log-Id
X-AIR-PT
X-Air-Pt
X-Service-Response-Time
X-Traceid
Locid
X-Instance-Name
X-FL-EDGE
Swift-Performance
X-Cache-Expires
X-From
Location
Srvid
M-TraceId
X-Cache-Backend
X-Fastly-Backend-Reqs
X-LI-Proto
X-Platform-Processor
X-Platform-Router
X-Li-Pop
Dnion-Transfer-Encoding
X-Li-Fabric
X-LI-UUID
X-Platform-Cluster
X-UA
Esi-Enabled
X-LiteSpeed-Tag
X-Platform
X-TrackingId
Geoip-Latitude
X-Cc-Via
X-RPM
X-RPS
X-DW
X-DSS
X-DB
X-DI
X-RSL
XServer
NtCoent-Length
On-Server
X-We-Are-Hiring
Hit
Fastcgi-X-Cache-Version
Nginx-CQVIP
X-PAYTM-SRV-ID
Uri
CountryCode
PICS-Label
Ohc-File-Size
X-Wp-Cf-Super-Cache
X-Wp-Cf-Super-Cache-Cache-Control
Wpo-Cache-Status
X-Conten-Type-Options
X-CUA
X-Lb-Nocache
X-CF-Powered-By
X-Slack-Shared-Secret-Outcome
X-Cache-Proxy
X-Request-Url
Vha6-Origin
Wpo-Cache-Message
X-B3-ParentSpanId
X-Fastly-Cache-Hits
X-HostName
XM
X-PERF
X-Fastly-Country-Code
X-Info
X-Cdn-Request-ID
X-ApacheServer
Wp-Super-Cache
X-Edge-Origin-Shield-Bytes
X-Edge-Origin-Shield-Region
Warning
X-Litespeed-Cache-Control
X-Ips-Loggedin
X-Cache-Ngx
X-N-OperationId
X-Matome-Cached
X-MTS-Cache
X-Loadbalancer
X-Kebabable
X-Kebab
X-Keep
X-Nerd
X-Ittl
X-LbNode
X-Matched-Rule
X-NFL-Geo
X-Okws-Version
X-Odoo-Frontend
X-Onedio-Env
X-Origin-Ops
X-OVcl
X-Nyt-Data-Last-Modified
X-NXG
X-NFL-Dma
X-Newegg-Index
X-Is-SSL
X-NS-Authorization
X-Ntj-Investigation-Id
X-Newegg-Flow
X-Git-Commit
X-ETag
X-Eid
X-Eventloop-Lag
X-F-Status
X-DT-Node
X-Ee-Request-Id
X-Ee-Request-Date
X-Ee-Origin
X-Edge-IP
X-OVcl-Cache
X-Developed-By
X-Doge
X-Farm
X-GoCache-CacheStatus
X-Global-Transaction-ID
X-Group
X-Header-Sub
X-IBD-Cache
X-Ee-Generated-By
X-GG-Cache-Status
X-Fastly-Is-Edge
X-Frame-Option
X-Fstrz
X-Full-Ttl
X-IBD-SID
X-Toujours-Debout-Location
X-Vary-Devices
X-V2-Infrastructure
X-Ver
X-Wag-Acs
X-Waitingroom
X-Utime
X-User-Auth
X-Tried-To-Kebabify
X-Delivery
X-True-Client-Ip
X-U-Cache
X-Upstream-State
X-Web-Hosting
X-WP-Bypass
PFcat
X-B3-Parentspanid
ServerName
X-HN
X-VarnishDD-TTL
Timeexpire
XV-H
X-WSR2
X-Xms-Page-Cache-Actions
X-YSpaceId
XV-Cache
X-Toujours-Debout-Branch
X-Timestamp
X-Render-Time
X-Render-Method
X-Request-Origin
X-Route
X-Route-Akamai
X-Redis
X-Reboot
X-PG-ACCESS
X-Paywall
X-PGF-Deflate
X-Pver
X-R-Cache
X-Ruby
X-Save-Cache
X-Stack-Name
X-SSLProxy
X-SVR-IIS
X-Svr-Proxy
X-Test-Nginx-Ingress
X-Square
X-SMP-JWT
X-Server-L
X-ServiceName
X-Sh
X-Site
X-PageType
X-Apache-Server
Joe-X
Is-Https
NB-ESI
Nikkei-App-Version
Npm-Cost
NLCacheNote
HTTPProtocol
HServer
CMS-200
Cluster-Host
Deeplink
Ec-Policy-Id
H1
Npm-Remaining
Ns
Region
RawURL
Request-Uuid
Rt-Proxy-Cache
Scheme
Proxy-Cache
Panzer-Cache-Control
Ok-Cache-Status
Ns-Ua
OK-Edge-Date
Ok-Edge-Key
Origin-Site
Cf-Wrk
Cf-Locale
X-Moov-Xdn-Version
DynaTrace
WZWS-RAY
X-Moov-T
X-Mg-Cache
X-Node-Id
X-Request-Start
Req-ID
Fastcgi-Cache-Ttl
X-Vtex-Remote-Cache
X-Vtex-Processado-Em
SRV
X-ElasticPress-Query
X-Yottaa-OS
Cache-Stat
Akamai-X-Url
Cachekey
Cdn-Country-Code
Cf-Device-Type
X-Th-Server
X-Serial
GeoIP-Latitude
CF-Cached-On
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
Cneonction
Selected-Route
Served
X-BeanStalkRole
X-Backside-Transport
X-BeanStalkStage
X-Cache-Cookie
X-Cache-IsMobileDevice
X-Backend-TTL
X-AspNetWebPages-Version
X-Ar-Stats
X-Amz-Meta-Cb-Modifiedtime
X-Arena-Request-Id
X-ARRRG1
X-ASF-Cache
X-Cache-Length
X-Cache-NPR
X-Coindesk-Cache
X-Cms-Device
X-Colour
X-Container-Uri
X-Dcm-Pdtf
X-Cf-Node-Idx
X-CDN-Pop-IP
X-Cache-ReqUri
X-Cache-Reason
X-Cache-Response
X-CacheVersion
X-CDN-Pop
X-Akamai-Native
X-Akamai-DeviceType
Time-Cloud-Cache
Technodrome
Ttl
TWC-AK-Req-ID
TWC-PATH-LOCALE
T-Request-Id
Sw
SFRVia
Service-Uuid
Shieldsquare-Response
SII
Store-Cloud-Cache
TWC-Subs
TWC-Unit
X-Accor-Asset
X-Accepted-Language
X-AEO-Platform
X-Akamai-CacheKeyMod
X-Akamai-DeviceOS
X-Accepted-Fulllang
X-Accel-Version
Userver
Uniqueid
Vttl
X-77-NZT
X-77-NZT-Ray
X-Dehri-Date