Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
Strict-Transport-Security
X-Frame-Options
X-Content-Type-Options
Last-Modified
Link
CF-Cache-Status
Cf-Request-Id
Accept-Ranges
ETag
CF-RAY
Expect-CT
Pragma
X-Powered-By
X-Cache
Via
Age
X-XSS-Protection
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Xss-Protection
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-FRAME-OPTIONS
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Request-Id
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-Adblock-Key
X-AspNet-Version
X-Permitted-Cross-Domain-Policies
Alt-Svc
X-Runtime
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Cache-Status
X-Generator
CF-Ray
X-Cacheable
X-Ua-Compatible
X-Request-ID
X-Iinfo
Timing-Allow-Origin
X-Envoy-Upstream-Service-Time
Feature-Policy
X-Content-Security-Policy
Status
X-Drupal-Dynamic-Cache
Content-Encoding
X-AspNetMvc-Version
Access-Control-Expose-Headers
X-CDN
Upgrade
X-XSS-PROTECTION
Access-Control-Max-Age
P3p
X-Via
X-Robots-Tag
X-Cache-Group
Server-Timing
X-UA-Device
Request-Context
Keep-Alive
X-Amz-Request-Id
X-AH-Environment
X-Dns-Prefetch-Control
X-Proxy-Cache
X-Turbo-Charged-By
X-Amz-Id-2
X-Backend
X-Age
Host-Header
X-Ws-Request-Id
X-Server-Powered-By
X-Hacker
X-Server
X-Rq
X-Vhost
X-Varnish-Cache
X-Amz-Version-Id
Grace
EagleId
X-Dispatcher
X-LiteSpeed-Cache
Cf-Edge-Cache
Allow
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Device
X-Page-Speed
X-Swift-SaveTime
X-Swift-CacheTime
X-Nginx-Cache-Status
Ali-Swift-Global-Savetime
X-Akamai-Path-Stats
X-WebKit-CSP
X-Aws-Lambda-Call-Status
Accept-CH
X-Host
X-Node
Cf-Railgun
X-Pingback
X-Server-Id
X-OneAgent-JS-Injection
X-Cache-Spec
Surrogate-Control
X-Backend-Server
X-Akam-SW-Version
Request-Id
EagleEye-TraceId
X-Response-Time
X-Cache-Lookup
X-Readtime
Accept-CH-Lifetime
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-HW
Content-Location
X-Content-Security-Policy-Report-Only
X-Application-Context
Rating
X-Cloud-Trace-Context
X-Trace
Fastly-Restarts
X-Country
X-Clacks-Overhead
X-Nginx-Upstream-Cache-Status
X-WebKit-CSP-Report-Only
X-Url
X-Amz-Server-Side-Encryption
X-MS-InvokeApp
Accept-Ch-Lifetime
X-Rack-Cache
Edge-Control
X-Edge
X-B3-TraceId
X-PC
X-Vname
X-TtlSet
X-Oneagent-Js-Injection
X-ESI
X-Content-Type
X-Mod-Pagespeed
X-Vcap-Request-Id
X-Ruxit-JS-Agent
X-CST
Verso
X-Ruxit-Js-Agent
Xkey
X-D2id
X-GoogleNews-Bot
X-Kinja-Server
X-Exp-Variant
X-Exp-Id
X-Kinja
X-Kinja-Build
X-Cdn-Fetch
X-Use-Magma
X-Kinja-Revision
X-GitHub-Request-Id
Cache-Tag
X-Amz-Rid
X-Mcache
X-Powered-By-Plesk
X-Varnish-TTL
X-FastCGI-Cache
Service-Worker-Allowed
RTSS
X-VARITI-CCR
X-ECACHE
X-Upstream
X-Navigation-Version
X-Version
X-Abt-Application-Version
X-Cached
X-Client-IP
X-Ac
X-Cnection
X-Dw-Request-Base-Id
X-Element-Page-Cache
X-Px
X-Server-Name
Arr-Disable-Session-Affinity
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Instrumentation
SPRequestGuid
X-SharePointHealthScore
X-Ttl
Public-Key-Pins
SPIisLatency
SPRequestDuration
Permissions-Policy
Display
X-Sol
X-Middleton-Display
Pagespeed
X-Country-Code
X-Cache-TTL
X-NWS-LOG-UUID
Cf-Apo-Via
X-Ser
X-Middleton-Response
Response
X-Cache-Key
X-Midtier
X-Kinsta-Cache
X-Goog-Hash
X-Edge-Location-Klb
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Forwarded-For
X-RateLimit-Remaining
Content-MD5
Access-Control-Request-Method
X-MSEdge-Ref
Front-End-Https
X-Shield-Request-Id
Accept-Ch
X-DataDome
X-Correlation-Id
X-NF-Request-ID
X-T
X-Recruiting
TP-Cache
TP-L2-Cache
X-HP-Trace-Id
Edge-Cache-Tag
X-Jurisdiction
X-HP-Webp
MicrosoftSharePointTeamServices
AR-CACHE
AR-ATIME
AR-PoweredBy
AR-SID
Nginx-Cache
AR-Request-ID
MRF-Tech
Mrf-Cache-Status
X-B3-TraceId-Primal
X-Accel-Expires
X-Powered-CMS
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
TCN
X-Grace
X-Daa-Tunnel
X-Mg-S
X-Content-Digest
X-RateLimit-Limit
X-Id
X-Hits
X-Request-Received
X-Request-Processing-Time
Filters
X-HS-Hub-Id
X-Amzn-Trace-Id
X-HS-Cache-Config
X-HS-Content-Id
X-HS-Combine-CSS
Server-Node
Server-Name
X-XRDS-Location
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
MS-Author-Via
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Browser-Type
X-Frontend
Fastcgi-Cache
X-Geo-Country
X-Distributor
X-PressLabs-Stats
S
X-Protected-By
X-Origin-Server
X-Fastly-Request-Id
Cache-Status
X-LLID
X-Ezoic-Cdn
Count-Hit
X-Webkit-Csp
X-Language
X-Fastcgi-Cache
X-Ab
X-Ua-Browser
X-Amz-Meta-S3cmd-Attrs
Filterid
Cross-Origin-Opener-Policy
X-F-Cache
X-LB-Cache
X-Forwarded-Proto
Payment
X-B3-Sampled
Charset
X-Seen-By
X-Microsite
X-Request-Handler-Origin-Region
X-Litespeed-Cache
X-FB-Debug
X-Page-Id
Host
X-Git-Hash
X-Ratelimit-Reset
X-Cluster-Name
X-VCache
X-ASPNET-VERSION
Surrogate-Key
X-Cache-Age
X-TTL
X-Rid
Cache-Tags
Realpath
Accept-Charset
X-Www-Served-By
Access-Control-Allow-Method
X-NGENIX-Cache
X-Logged-In
Alternate-Protocol
X-Origin-Cache
Retry-After
X-Upgrade-Enabled
X-Template
X-Source
X-Az
X-DIS-Request-ID
X-AppVersion
X-Activity-Id
X-Type
X-Varnish-Backend
Cleartype
ServerID
X-Wix-Request-Id
X-Amz-Replication-Status
X-TT
X-Tb
X-Signature
X-B-Cache
X-Envoy-Decorator-Operation
X-B
X-Is-Crawler
X-Request-Guid
X-App-Environment
X-Aspnet-Duration-Ms
X-Route-Name
X-Providence-Cookie
X-Varnish-Grace
X-Flags
Paypal-Debug-Id
DC
X-Hostname
X-DynaTrace
X-Node-Name
Frame-Options
X-Revision
X-Drupal-Cache-Tags
X-Fastly-Request-ID
X-Debug
X-Proxy
X-Contextid
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Cache-Rule
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Goog-Generation
X-Pinterest-Rid
X-Goog-Metageneration
Pinterest-Generated-By
Pinterest-Version
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Mobile
X-Content-Options
X-Load-Cache
X-Cache-Control
X-Ratelimit-Remaining
X-N
Refresh
Country
Amp-Access-Control-Allow-Source-Origin
Node
X-Magnolia-Registration
X-EdgeConnect-Cache-Status
NGB
X-Original-Request-Id
X-Response-Served-From
X-User-Agent
X-Whom
Akamai-GRN
X-Instance
X-Cache-Time
Content-Disposition
X-Debug-IsPreview
Viewport
X-Content-Powered-By
X-Debug-IsConnected
X-Cache-TTL-Remaining
X-Varnish-Age
X-NYM-Debug-Backend
X-Oracle-Dms-Ecid
X-L-Path
X-Environment-Context
Access-Control-Request-Headers
X-Varnish-Server
X-Status
X-Akamai-Request-ID2
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Adobe-Loc
X-Adobe-Content
X-Oracle-Dms-Rid
Referer-Policy
X-G
X-Unique-Id
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Framework
X-Servername
X-Jobs
X-Webkit-CSP
X-Mid
Uber-Trace-Id
X-Page-View
X-Cacheable-TTL
Url
X-Cache-Grace
X-Is-Bot
X-Real-IP
X-Rendered-As
Srv
Countrycode
X-Time
X-Content
X-ProcessESI
X-RemovedCookies
X-Drupal-Cache-Contexts
X-COUNTRY
Cross-Origin-Resource-Policy
Version
X-CDN-Forward
X-Cache-Expired-At
Accept-Language
X-Mg-Request-UUID
X-Via-JSL
X-Http-Reason
X-Ratelimit-Limit
X-XRDS-LOCATION
X-Cache-Hit
X-Restarts
X-Tumblr-Pixel
X-Cache-Operation
X-URL
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-Tumblr-User
Protected
X-APP-VERSION
X-App-Server
X-IPLB-Instance
X-Api-Version
X-IPLB-Request-ID
X-Backend-Name
Healthy
X-Hosted-By
X-Trace-Id
X-Debug-Info
X-Azure-Ref
Section-Io-Cache
X-Akamai-Edgescape
X-Rule
Content-Secure-Policy
X-Tt-Logid
X-Device-Type
X-Cache-Action
X-FW-Dynamic
X-FW-Hash
Backend
X-FW-Type
X-Nginx-Cache-Key
X-FW-Static
X-FW-Serve
X-FW-Server
X-Generation-Time
Liferay-Portal
Server-Info
X-Server-ID
GEO-INFO
X-VC-Cache
MS-CV
X-Storage
Meta-Geo
Ms-Operation-Id
Load-Balancing
X-SRV
X-RTag
X-Mobile-URL
X-RN-RSRV
X-UPSTREAM-Address
Fastcgi-Useragent
X-Proxy-Cache-Status
CF-IPCountry
X-Mode
X-Access
X-HTML-Minification-Powered-By
Azure-SiteName
Azure-RegionName
Azure-InstanceId
Azure-SlotName
Azure-Version
X-Content-Age
X-Format
X-Section
X-Handled-By
Onion-Location
X-AWS-Id
X-Alternate-Cache-Key
Webcakes-Region
TWC-Privacy
S-Rt
TWC-Connection-Speed
TWC-Device-Class
Property-Id
Eomportal-Instance
CDN-Cache
X-Varnish-Cache-Hits
TWC-GeoIP-Country
X-Region
Webcakes-App-Name
Web-Mar-Node
Locale
TWC-Locale-Group
X-Adobe-Source
TWC-GeoIP-LatLong
Webcakes-App-Version
CDN-Uid
X-Forwarded-Host
X-Sorting-Hat-PodId
X-ShopId
X-FireWall-Port
X-JoinUs
X-Sql-Count
X-Sorting-Hat-ShopId
X-ShardId
CDN-RequestId
X-Locale
X-OCL
CDN-RequestCountryCode
X-Say-Cacheable
X-Generated-By
X-SayCDN-TTL
X-Say-TTL
X-Sql-Duration-Ms
CDN-PullZone
X-VWS-Id
X-Varnish-Beresp-Grace
X-Edge-Location
X-PCL
X-Proto
X-Cache-Host
X-R9-Blue-Green-Version
X-Cache-Server
X-Urbn-Site-Id
X-SaId
CDN-CachedAt
CDN-EdgeStorageId
X-Labrador-Cache-Channel
X-LJ-Flow-ID
X-Urbn-Context-Path
X-Origin-Hint
X-PHP-Host
X-Shopify-Stage
Xserver
X-Proxied
X-Server-W
X-ProxyCache-Key
Apigw-Requestid
X-Skip-Cache
X-Extlb
X-Cache-Type
X-Redis-Cache
X-BYPASS-REASON
X-Storefront-Renderer-Rendered
X-Hl-Ver
X-UA-Device-Type
X-Site-Version
X-GeoCode
X-ProxyCache-Status
X-Cms-Context
X-Ms-Request-Id
X-ServerID
X-GeoCountry
X-Routing-Service
X-No-Session
X-Ms-Version
X-Xfnlog-Site
X-Varnish-Hostname
X-Zipkin-Id
X-Web-Node
X-Proxy-Build
X-Cache-Enabled
Mn-Server-Ip
X-Request-Time
Selected-Fe
X-Varnishpool
X-Timing-Wait
X-Cache-NGX
X-PHP-Backend
X-Tid
X-Uri
X-Nginx-Cache
X-Amz-Apigw-Id
X-Amzn-RequestId
Cache-Name
WP-Super-Cache
X-Datadome
X-Detected-As
DB-Nickname
X-WP-CF-Super-Cache
X-Correlation-ID
X-Via-Fastly
X-WP-CF-Super-Cache-Cache-Control
X-FB-TRIP-ID
X-Origin-Date
X-UUID
X-Cache-Status-Check
X-DynaTrace-JS-Agent
X-ECache
X-LSADC-Cache
X-Loop
X-Ua
X-TNCMS
ServedBy
X-Reqid
X-Amzn-Remapped-Content-Length
X-App-Version
Xet-Cookie
X-Varnish-Ttl
X-Pubstack
X-Zen-Fury
X-Provided-By
X-Vgn-Hpd-Reason
X-Human
X-Dc
X-RCS-CacheZone
Source
X-MP-GENERATED-AT
X-Soup
Cache
X-Tec-Api-Version
X-Tec-Api-Root
X-Tec-Api-Origin
X-Cache-Tags
X-Origin-TTL
X-Tumblr-Pixel-2
X-Aspnetmvc-Version
X-Origin-CC
Origin
X-TA-CDN-Provider
X-Cdn
X-Varnish-Hits
X-GEO
X-Cached-By
From-Origin
X-Service
Cross-Origin-Window-Policy
X-Debug-Cache
X-Varnish-Beresp-Ttl
X-Newrelic-Synthetics
WPO-Cache-Message
WPO-Cache-Status
SD-X-WS
Webserver
X-NewRelic-App-Data
LB
Rip
BehaviorPad-Version
MD5-Digest
X-ScT
Rendered-Blocks
X-Request-Host
X-Trace-ID
X-FW-Version
Host-ID
X-IPS-LoggedIn
X-AOL-HN
X-Cache-Debug
X-Application
X-A-Dam
X-AK-Request-ID
X-ARC
X-Ec-GeoHdr
X-Ec-Fail
X-Bc-Bl
X-A-Ccd
X-B-Cookie
Sslversion
Surrogated-Key
VNS-Age
X-Forwarded-Path
VNS-Cache
X-A-Dcw
X-External-Request-Id
X-A-Dgt
T-Server
X-BCube-Filmed-By
X-A-Wwc
X-Aed
Odigeo-Trace-Id
X-Parent-Response-Time
Cdnsip
CPC-Age
CPC-Cache
Cdncip
X-Developer
X-D
A
X-Connection-Hash
X-Destination
DCR-Decision-By
DCR-Processing-Time-Ms
Lang
Meta-Geo-Continent
Ngx.Var.Host
X-Orig-Expires
X-Cache-NE
Expiry
Environment
X-A
X-NAPM-TraceId
X-Processor
X-PBS-Appsvrname
Xc-Version
X-Nf-Request-Id
X-S-Cookie
X-VG-WebCache
X-Vdms-Path
X-TIM-N
X-SRCache-Key
X-User
X-S
X-Shop-Environment
X-Rojux
X-Tenant
X-Vdms-Version
X-Rewrite-Enabled
X-CSRF-Token
X-B3-SpanId
X-Platform-Server
HostName
X-B3-Traceid
X-Dispatcher-Number
X-Accel-Buffering
X-Aicache-OS
X-Cluster
X-Owner
Redirect-Candidate
X-Served-From
X-Cdn-Srv
X-Auto-Login
X-TIME
X-WP-CF-Super-Cache-Active
Gh-Request-Id
X-VC
Upgrade-Insecure-Requests
X-Is-Gdpr
Mime-Version
Fastly-Drupal-HTML
X-Cluster-Node
OT-Force-Account-Verify
X-INCAP-ABP
X-Developers
X-JWT-State
X-Has-Esi
Country-Code
Cmstype
X-Varnish-CookieHashed-On
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
X-Csrf-Jwt
Apple-News-Services-Host
Apple-News-Services-Handled
X-Varnish-Beresp-Status
Adler-Geo
Cache-Host
X-Core-Mission
Click-Count-Action-Start
Click-Count-Error
X-Varnish-Remaining-TTL
X-Varnish-CookieINHashed-On
Candidate-Md5Url
X-Clientip
Cmsid
Producers
Machine
Platform
Mail-Subject
X-Viewer-Country
L5d-Success-Class
IsBot
Kp-EeAlive
L
X-VServer
Mobile-Detection-Method
X-Bip
Origin-CC
Origin-EX
X-Wix-Viewer-Type
NM-Fastcgi-Cache
X-Nyt-Route
NGX
X-WADP-Cache
Is-Eu
X-Cache-Bucket
X-CGP
X-VG-TLSProxy
X-Cdn-Origin
X-Variation
DSUID
Decoy-Debug-Key
Decoy-Debug-Status
Decoy-Debug-TTL
X-CacheTTL
Fastly-GeoIP-CountryCode
X-Cache-Id
Ha-Gx-Prefs
HA-Ipaddr
X-Cache-Info
Fastly-SWR
Fastly-SIE
Fastly-SSL
X-Clara-WADP
State
X-Slack-Backend
X-Sn-Servicetimems
X-SplitTest
Web-Mar-Region
X-NodeID
X-SIPLIST1
X-Optimistic-Header
X-Mvc-Supplant-Cachable
X-Minions-Version
X-Hash
X-Gzip
X-SVT-ORM-RULES
We-Hiring
X-Loc
X-Irp-Debug
X-Sigma-Backend
X-Origin
X-Request-URI
X-Rocket-Build-Number
X-Via-NSCOPI
X-RateLimit-Remaining-Second
X-Qloud-Router
X-RateLimit-Limit-Second
X-Scale
X-Pool
X-Sigma
X-Origin-Response-Time
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Policy
X-Planisys-CDN-TTL
X-GeoIP-City
X-GeoIP
X-Origin-Time
X-DefHash
Servername
X-Ad-Defer-Variation
Traceparent
Tube-Got-Eval
Tube-Get-Contents
X-Gdpr
X-BBC-Edge-Cache-Status
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
Release
Req-Svc-Chain
X-DefElseHash
X-Datadog-Trace-Id
Tube-Got-Results
Tube-Return
X-Gateway-Cache-Key
X-Forwarded-Site
X-Gateway-Cache-Status
X-Gateway-Request-Id
X-SVT-ORM-VERSION
X-Gateway-Skip-Cache
X-Fmm-Version
X-Eu-Site
Vix-Hermes-Req-Id
V-Age
X-DPWN-IS-SECURE
X-Thanos
X-Esi-Check
X-Epic-Correlation-Id
X-Proxy-Cache-Info
X-Thinkindot-L3
Fastly-Backend-Name
X-Core-Value
Thinkindot-CacheControl
Server-Host
X-CMSURLCustom
Thinkindot-CacheControl-Type
Thinkindot-Control
TDXMobile
X-GG-Cache-Date
X-Generated-On
X-Sucuri-Cache
X-Sucuri-ID
X-Worker
X-HS-Content-Campaign-Id
X-Level-Front-Cache
X-Geo-Header
X-SB
X-Var-Ttl
X-Rocket-Nginx-Serving-Static
X-Hnp-Log
X-S-Maxage
X-Fetched-On
X-Ec-Custom-Error
X-Gamma-Serve
Memcached
Cluster
X-Ckpd-Fst-Backend
X-Branch-Name
X-V-Cache
X-ATG-Version
X-Device-Os
X-Block-Status
X-FC-Vary-Parameters
X-Fastly-Backend
X-Region-Sid
X-Gen-Mode
Server-Ext
Sever-Int
Datacenter
Server-Hostname
Canary
Wxu-Next-Region
Wxu-Next-Hostname
CDCHOST
Wxu-Next-Commit
User-Cache-Control
X-Cache-Remote
AKAMAI
X-Scheme
X-LB-NoCache
X-Mvc-Supplant-OutputCached
X-Tx-Id
Svr
CloudFront-Viewer-Country
X-Azure-Ref-OriginShield
X-NCache
Ec-Rule-Version
X-WA-Info
X-Newrelic-App-Data
Cache-Tv-Group
Cache-Hits
X-ND-Cache
X-Udemy-Cache-App-Namespace
Fastcgi-Cache-TTL
X-Webkit-CSP-Report-Only
Pics-Label
X-Tb-Optimization-Total-Bytes-Saved
Sid
WebServer
AMP-Access-Control-Allow-Source-Origin
X-ZONE
Memory
X-Session-Fingerprint
Ssr
Time
X-Fastly-Cache
X-Refresh
X-Via-Poph
X-Rebelmouse-Surrogate-Control
X-Via-Popn
X-Via-Popv
X-Rebelmouse-Cache-Control
X-Origin-Expires
X-Generated-In
SID
X-Pod-Name
X-Pass-Why
Server-ID
X-Up
X-Servedbyhost
Request-ID
X-Tumblr-Pixel-3
Env
X-Presslabs-Stats
X-Wa
X-Edge-Pop
X-DC
X-Cs
My-App
X-Release
X-Akamai-Transformed
X-Fpc
X-Dispatch
X-Ig-Push-State
X-Buckets
X-Lambda-Id
X-Cache-Date
X-Zone
X-Conf
X-NC
X-Esi
X-NWS-UUID-VERIFY
X-MSEdge-Features
X-MSEdge-Flight
X-PX
X-EC-Lua
X-MCACHE
X-Endurance-Cache-Level
X-ID
X-Req
X-Microcachable
CDN
X-TX-ID
X-Xrds-Location
X-Dmc
X-LB-ID
X-VCL-Version
X-CACHE-AGE
GeoIp-Country-Code
X-TRACE-ID
X-CS
CacheControlHeader
True-Client-Country-4JS
True-Client-IP
X-Be
Fastly-Drupal-Html
X-NGINX-Cache
X-TH-Server
Magicmarker
X-RateLimit-Reset
X-CACHE-KEY
X-B3-Spanid
X-Vc
X-Wikidot-Static-Cache
X-Wikidot-Backend
X-CSRF-TOKEN
Hostname
X-HS-Status
X-Op-Id-All
X-Srv
True-Client-Ip
Path
Resin-Trace
GeoIP-Country-Code
X-Vcl-Version
X-Hyper-Cache
X-Air-Hostname
X-Air-Trace-Id
X-Air-Source
Tcn
X-M-Reqid
WWW-Authenticate
X-GeoIP-Country-Code
X-Accel-Expires-Debug
X-Date
X-CF-Lambda-Version
X-CF-Lambda-Fn
X-M-Log
X-GeoIP-Region-Code
X-Check-Cacheable
X-Micro-Cache
X-Alfa-Service
X-Air-Pt
X-Vercel-Id
Pramga
X-Vercel-Cache
X-Qnm-Cache
Tracecode
X-Varnish-Beresp-TTL
X-App
X-SERVER-NAME
X-Datacenter
X-RAMCache
C-Via
Section-Io-Id
X-Old-Content-Length
X-LiteSpeed-Cache-Control
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
X-Akamai-Pragma-Client-IP
X-Geo
Yjs-Id
X-Cache-Ttl
NtCoent-Length
X-CLOUD-TRACE-CONTEXT
X-FPC
Proxy-Connection
Powered-By
X-Edge-POP
N-Cache
X-TrackingId
YJS-ID
X-Webkit-Csp-Report-Only
X-WA
Fastcgi-X-Cache-Version
X-Mly-Id
Esi-Enabled
X-Platform
X-Via-CDN
X-Platform-Cluster
X-PAYTM-SRV-ID
Hit
ENV
X-Yandex-Sdch-Disable
FSS-Cache
On-Server
X-Platform-Router
X-Platform-Processor
X-Location
X-API-Version
Lb
X-Lb-Id
Server-Id
X-Webstats-RespID
User-Agent
X-ServedByHost
X-Response-By
X-Cdn-Forward
X-Cache-ASPX
X-Contensis-Viewer-Groups
X-Varnish-Authentication
X-Dw-Trace-Id
X-Via-PopN
X-Via-PopV
X-Via-PopH
HIT
X-Vtex-Remote-Cache
X-Vtex-Processado-Em
X-UA
X-Edge-Origin-Shield-Bytes
X-Edge-Origin-Shield-Region
X-Node-Id
X-Client-Ip
GeoIP-Latitude
Cdn
X-Service-Response-Time
X-AIR-PT
Sm-Log-Id
X-LI-Proto
X-Li-Pop
X-Li-Fabric
Location
X-LI-UUID
X-Akamai-ERRuleID
X-FL-EDGE
Srvid
X-From
X-Director
X-LAGOON
Locid
X-Render-Time
X-Traceid
X-FORWARDED-FOR
X-SD-PageType
X-Instance-Name
X-Request-Start
X-TT-LOGID
X-CUA
X-Akamai-ERPolicy
Geoip-Latitude
Dnion-Transfer-Encoding
X-Server-IP
X-Test
X-RPM
X-RPS
X-LiteSpeed-Tag
Cache-Key
X-DW
X-Via-Ucdn
Ohc-File-Size
Swift-Performance
X-DB
X-DSS
X-RSL
Nginx-CQVIP
PICS-Label
Uri
X-Request-Url
X-HA-Backend
XServer
X-DataCenter
X-DI
X-CF-Powered-By
X-Wp-Cf-Super-Cache
X-Litespeed-Cache-Control
X-Wp-Cf-Super-Cache-Cache-Control
X-Fastly-Backend-Reqs
M-TraceId
X-Cache-Backend
X-Cache-Expires
X-Cdn-Request-ID
X-HostName
X-B3-ParentSpanId
X-Proxy-Upstream
X-PERF
Server-Ttl
X-ApacheServer
X-Fastly-Cache-Hits
DynaTrace
Wpo-Cache-Message
Vha6-Origin
Wpo-Cache-Status
X-Lb-Nocache
CountryCode
Warning
Wp-Super-Cache
X-Ramcache
X-Cc-Via
XkeyRZ
X-Cache-Ngx
X-Ips-Loggedin
X-Proxy-CacheRZ
X-NXG
X-Ittl
X-Ntj-Investigation-Id
X-Kebab
X-Kebabable
X-Is-SSL
X-IBD-Cache
X-GoCache-CacheStatus
X-Global-Transaction-ID
X-Group
X-Header-Sub
X-Keep
X-IBD-SID
X-LbNode
X-Matome-Cached
X-Newegg-Index
X-Newegg-Flow
X-Nerd
X-MTS-Cache
X-Git-Commit
X-Matched-Rule
X-NS-Authorization
X-NFL-Geo
X-NFL-Dma
X-Loadbalancer
X-N-OperationId
X-Eventloop-Lag
X-Doge
X-Developed-By
X-DT-Node
X-Edge-IP
X-Ee-Generated-By
X-Delivery
X-Dehri-Date
X-Coindesk-Cache
X-Container-Uri
X-Conten-Type-Options
X-Cms-Device
X-Dcm-Pdtf
X-Ee-Origin
X-Ee-Request-Date
X-Fastly-Is-Edge
X-Farm
X-Frame-Option
X-Fstrz
X-Full-Ttl
X-F-Status
X-Colour
X-Ee-Request-Id
X-Eid
X-Nyt-Data-Last-Modified
X-ETag
X-GG-Cache-Status
X-Pver
X-True-Client-Ip
X-Tried-To-Kebabify
X-U-Cache
X-Upstream-State
X-User-Auth
X-Toujours-Debout-Location
X-Toujours-Debout-Branch
X-SVR-IIS
X-Stack-Name
X-Svr-Proxy
X-Test-Nginx-Ingress
X-Timestamp
X-Utime
X-V2-Infrastructure
X-Xms-Page-Cache-Actions
X-WSR2
X-YSpaceId
XV-Cache
XV-H
X-WP-Bypass
X-Web-Hosting
X-Vary-Devices
X-Ver
X-Wag-Acs
X-Waitingroom
X-SSLProxy
X-Square
X-PG-ACCESS
X-Paywall
X-PGF-Deflate
X-Cf-Node-Idx
X-R-Cache
X-PageType
X-OVcl-Cache
X-Okws-Version
X-Onedio-Env
X-Origin-Ops
X-OVcl
X-Reboot
X-Redis
X-ServiceName
X-Server-L
X-Sh
X-Site
X-SMP-JWT
X-Save-Cache
X-Ruby
X-Render-Method
X-Request-Origin
X-Route
X-Route-Akamai
X-Odoo-Frontend
X-Cache-Cookie
Joe-X
Is-Https
NB-ESI
Nikkei-App-Version
NLCacheNote
HTTPProtocol
HServer
CMS-200
Cluster-Host
Deeplink
Ec-Policy-Id
H1
Npm-Cost
Npm-Remaining
Proxy-Cache
Panzer-Cache-Control
RawURL
Region
Request-Uuid
Origin-Site
Ok-Edge-Key
Ns
Ns-Ua
Ok-Cache-Status
OK-Edge-Date
Cf-Wrk
Cf-Locale
PFcat
WZWS-RAY
XM
X-Mg-Cache
X-Proxy-Cache-Hk
X-HN
X-VarnishDD-TTL
Fastcgi-Cache-Ttl
Req-ID
X-Moov-Xdn-Version
X-Moov-T
X-ElasticPress-Query
X-Yottaa-OS
Cache-Stat
Akamai-X-Url
Cachekey
Cdn-Country-Code
Cf-Device-Type
X-Th-Server
X-Serial
CF-Cached-On
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
Cneonction
Rt-Proxy-Cache
Scheme
X-ARRRG1
X-Arena-Request-Id
X-ASF-Cache
X-AspNetWebPages-Version
X-Backend-TTL
X-Ar-Stats
X-Apache-Server
X-Akamai-DeviceOS
X-Akamai-CacheKeyMod
X-Akamai-DeviceType
X-Akamai-Native
X-Amz-Meta-Cb-Modifiedtime
X-Backside-Transport
X-BeanStalkRole
X-Cache-ReqUri
X-Cache-Reason
X-Cache-Response
X-CacheVersion
X-CDN-Pop
X-Cache-Proxy
X-Cache-NPR
X-BeanStalkStage
SRV
X-Cache-IsMobileDevice
X-Cache-Length
X-AEO-Platform
X-Accor-Asset
Sw
Store-Cloud-Cache
T-Request-Id
Technodrome
Time-Cloud-Cache
SII
Shieldsquare-Response
Selected-Route
Served
Service-Uuid
SFRVia
Ttl
TWC-AK-Req-ID
X-77-NZT-Ray
X-77-NZT
X-Accel-Version
X-Accepted-Fulllang
X-Accepted-Language
Vttl
Userver
TWC-PATH-LOCALE
TWC-Subs
TWC-Unit
Uniqueid
X-CDN-Pop-IP