Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
Strict-Transport-Security
X-Frame-Options
X-Content-Type-Options
Last-Modified
Link
CF-Cache-Status
Cf-Request-Id
CF-RAY
Accept-Ranges
ETag
Expect-CT
Pragma
X-Powered-By
X-Cache
Via
Age
X-XSS-Protection
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
X-Xss-Protection
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
P3P
X-Served-By
X-FRAME-OPTIONS
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Request-Id
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-Adblock-Key
X-AspNet-Version
X-Permitted-Cross-Domain-Policies
Alt-Svc
X-Runtime
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Cache-Status
X-Check
X-Generator
X-Cacheable
P3p
X-Request-ID
X-Iinfo
X-Envoy-Upstream-Service-Time
Timing-Allow-Origin
Feature-Policy
X-Content-Security-Policy
Status
X-Drupal-Dynamic-Cache
Content-Encoding
Access-Control-Expose-Headers
X-AspNetMvc-Version
Upgrade
X-CDN
X-Ua-Compatible
Access-Control-Max-Age
CF-Ray
X-Via
X-Robots-Tag
X-Cache-Group
X-UA-Device
Server-Timing
X-Dns-Prefetch-Control
Request-Context
Keep-Alive
X-AH-Environment
X-Amz-Request-Id
X-Turbo-Charged-By
X-Proxy-Cache
X-Backend
X-Amz-Id-2
X-Age
X-Ws-Request-Id
Host-Header
X-Hacker
X-Server-Powered-By
X-Server
X-Rq
X-Vhost
X-LiteSpeed-Cache
X-Varnish-Cache
X-Amz-Version-Id
Grace
X-Dispatcher
Cf-Edge-Cache
EagleId
Allow
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
X-Page-Speed
X-WebKit-CSP
X-Nginx-Cache-Status
X-Swift-SaveTime
X-Swift-CacheTime
Accept-CH
X-Aws-Lambda-Call-Status
Ali-Swift-Global-Savetime
X-Node
X-Host
Cf-Railgun
X-Pingback
X-Cache-Spec
X-Server-Id
X-Backend-Server
X-Akam-SW-Version
Surrogate-Control
X-OneAgent-JS-Injection
Request-Id
EagleEye-TraceId
X-Response-Time
X-Cache-Lookup
Accept-CH-Lifetime
X-Readtime
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
Content-Location
X-Akamai-Path-Stats
X-HW
X-Content-Security-Policy-Report-Only
X-Cloud-Trace-Context
X-Application-Context
Rating
X-Trace
Fastly-Restarts
X-WebKit-CSP-Report-Only
X-Clacks-Overhead
X-Nginx-Upstream-Cache-Status
X-Oneagent-Js-Injection
X-Ruxit-Js-Agent
X-Country
X-Url
X-MS-InvokeApp
X-CST
X-Amz-Server-Side-Encryption
X-Rack-Cache
X-Edge
X-TtlSet
X-PC
X-Vname
Accept-Ch-Lifetime
Edge-Control
X-Content-Type
X-Mod-Pagespeed
X-B3-TraceId
X-FastCGI-Cache
X-Vcap-Request-Id
X-ESI
X-D2id
Verso
Xkey
X-Kinja-Build
X-Kinja
X-Exp-Id
X-Kinja-Revision
X-GoogleNews-Bot
X-Cdn-Fetch
X-Use-Magma
X-Exp-Variant
X-Kinja-Server
X-GitHub-Request-Id
Cache-Tag
X-Mcache
Cf-Apo-Via
Service-Worker-Allowed
X-Amz-Rid
X-Powered-By-Plesk
X-Varnish-TTL
RTSS
X-ECACHE
X-Navigation-Version
X-VARITI-CCR
X-Server-Name
X-Abt-Application-Version
X-Ttl
X-Version
X-Upstream
X-Client-IP
X-Cnection
X-Ac
X-Cached
X-Element-Page-Cache
Arr-Disable-Session-Affinity
X-Dw-Request-Base-Id
X-Ruxit-JS-Agent
X-Server-Lifecycle-Phase
X-Instrumentation
SPRequestGuid
X-SharePointHealthScore
X-Kraken-Loop-Name
Permissions-Policy
X-Px
SPRequestDuration
SPIisLatency
X-Sol
X-Middleton-Display
Pagespeed
X-Cache-TTL
Display
X-RateLimit-Remaining
Public-Key-Pins
X-Country-Code
X-NWS-LOG-UUID
X-Middleton-Response
Response
X-Ser
X-Midtier
X-Cache-Key
X-Kinsta-Cache
X-Edge-Location-Klb
X-Forwarded-For
X-Goog-Hash
X-SRCache-Store-Status
X-SRCache-Fetch-Status
Content-MD5
X-Correlation-Id
X-NF-Request-ID
X-DataDome
X-Shield-Request-Id
X-MSEdge-Ref
Access-Control-Request-Method
Front-End-Https
AR-Request-ID
AR-PoweredBy
AR-SID
X-T
X-Recruiting
AR-CACHE
AR-ATIME
X-B3-TraceId-Primal
Mrf-Cache-Status
MRF-Tech
TP-L2-Cache
TP-Cache
X-RateLimit-Limit
Edge-Cache-Tag
MicrosoftSharePointTeamServices
Nginx-Cache
X-HP-Trace-Id
X-HP-Webp
X-Jurisdiction
X-Cdn
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-Accel-Expires
X-Daa-Tunnel
X-Mg-S
Accept-Ch
TCN
X-Browser-Type
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Content-Digest
X-Grace
X-Powered-CMS
X-Hits
X-Request-Processing-Time
X-Request-Received
X-Amzn-Trace-Id
X-HS-Combine-CSS
X-HS-Content-Id
X-HS-Cache-Config
Server-Node
X-HS-Hub-Id
Filters
X-Id
Server-Name
X-XRDS-Location
MS-Author-Via
X-TEC-API-ROOT
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-Geo-Country
Fastcgi-Cache
X-Frontend
Count-Hit
X-Distributor
X-Webkit-Csp
X-Origin-Server
X-Ezoic-Cdn
X-Ua-Browser
X-PressLabs-Stats
X-LLID
X-Protected-By
Filterid
S
X-Language
Cross-Origin-Opener-Policy
X-F-Cache
X-Fastly-Request-Id
X-Forwarded-Proto
X-FB-Debug
X-B3-Sampled
X-Microsite
Charset
X-Seen-By
X-Request-Handler-Origin-Region
X-Amz-Meta-S3cmd-Attrs
Payment
X-LB-Cache
Host
X-Git-Hash
X-Page-Id
X-Ratelimit-Reset
Cache-Status
X-ASPNET-VERSION
X-VCache
X-Cluster-Name
Surrogate-Key
X-Ab
X-Rid
Cache-Tags
X-Www-Served-By
X-Upgrade-Enabled
Realpath
X-Logged-In
Retry-After
X-Origin-Cache
Access-Control-Allow-Method
Alternate-Protocol
Accept-Charset
X-Source
X-Varnish-Backend
X-DIS-Request-ID
X-NGENIX-Cache
X-Template
X-AppVersion
X-Activity-Id
Cleartype
X-Az
X-Type
Paypal-Debug-Id
X-Amz-Replication-Status
DC
X-Flags
X-B-Cache
X-Route-Name
X-Providence-Cookie
X-Is-Crawler
X-Wix-Request-Id
X-Signature
X-App-Environment
X-Request-Guid
X-Envoy-Decorator-Operation
X-Aspnet-Duration-Ms
X-Tb
X-B
X-TT
X-Fastly-Request-ID
ServerID
X-Varnish-Grace
X-Hostname
X-Revision
X-Cache-Age
X-DynaTrace
Frame-Options
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Node-Name
X-Contextid
X-Cache-Rule
X-Fastcgi-Cache
X-Drupal-Cache-Tags
X-TTL
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Pinterest-Rid
Pinterest-Version
X-COUNTRY
Pinterest-Generated-By
X-Proxy
Amp-Access-Control-Allow-Source-Origin
X-Goog-Stored-Content-Length
Refresh
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-GUploader-UploadID
X-Goog-Generation
X-Goog-Metageneration
X-Debug
Cross-Origin-Resource-Policy
X-Content-Options
X-Mobile
X-Load-Cache
X-EdgeConnect-Cache-Status
Referer-Policy
X-Magnolia-Registration
Node
NGB
Country
X-Varnish-Server
X-Cache-Control
X-Response-Served-From
X-Original-Request-Id
X-N
X-Varnish-Age
Viewport
X-Debug-IsPreview
Akamai-GRN
X-Debug-IsConnected
X-NYM-Debug-Backend
X-Environment-Context
X-L-Path
X-Whom
X-Status
X-Instance
Content-Disposition
X-Content-Powered-By
X-Adobe-Content
X-Adobe-Loc
X-Jobs
Access-Control-Request-Headers
VIX-Pulpo-Upstream-Status
X-Servername
VIX-Pulpo-Node
X-Rendered-As
X-Cache-Grace
X-Cacheable-TTL
X-Page-View
X-Cache-Time
X-G
X-Is-Bot
X-Real-IP
Url
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Framework
X-Cache-TTL-Remaining
X-ProcessESI
X-Akamai-Request-ID2
X-Mid
X-RemovedCookies
Uber-Trace-Id
X-User-Agent
Srv
X-Trace-Id
X-Oracle-Dms-Ecid
X-Via-JSL
X-Cache-Expired-At
X-Oracle-Dms-Rid
X-Unique-Id
X-CDN-Forward
X-Cache-Hit
X-APP-VERSION
Countrycode
X-Drupal-Cache-Contexts
X-Tumblr-User
X-XRDS-LOCATION
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-Cache-Operation
X-URL
Healthy
Version
Accept-Language
X-Rule
X-Backend-Name
X-Http-Reason
X-Mg-Request-UUID
X-Debug-Info
X-Akamai-Edgescape
X-Cache-Action
X-Litespeed-Cache
Protected
Section-Io-Cache
Content-Secure-Policy
X-VC-Cache
X-IPLB-Request-ID
X-IPLB-Instance
X-Hosted-By
X-App-Server
X-Tt-Logid
X-Azure-Ref
X-Api-Version
X-Server-ID
Xserver
Backend
X-Generation-Time
X-SRV
X-Content
Server-Info
X-Restarts
X-Generated-By
X-HTML-Minification-Powered-By
X-Time
X-Storage
X-UPSTREAM-Address
X-FW-Dynamic
X-FW-Static
X-FW-Serve
X-FW-Hash
X-RN-RSRV
Meta-Geo
X-FW-Type
X-FW-Server
X-Device-Type
X-Mobile-URL
GEO-INFO
X-Cache-Status-Check
Onion-Location
Liferay-Portal
CF-IPCountry
Azure-InstanceId
Azure-RegionName
X-Amzn-RequestId
X-Ratelimit-Remaining
X-PCL
X-Origin-Hint
Webcakes-App-Version
Azure-SiteName
Azure-SlotName
TWC-Privacy
X-Amz-Apigw-Id
Webcakes-App-Name
X-Section
Azure-Version
X-Access
TWC-Locale-Group
X-OCL
Webcakes-Region
X-FireWall-Port
TWC-Device-Class
TWC-GeoIP-Country
X-Cms-Context
Property-Id
TWC-GeoIP-LatLong
X-Format
X-Mode
TWC-Connection-Speed
S-Rt
X-Handled-By
X-Varnish-Cache-Hits
X-Locale
Ms-Operation-Id
X-Cache-Host
Web-Mar-Node
CDN-Uid
Load-Balancing
X-Content-Age
Locale
Eomportal-Instance
CDN-RequestId
X-Adobe-Source
MS-CV
X-JoinUs
X-Provided-By
CDN-Cache
CDN-CachedAt
CDN-EdgeStorageId
X-Urbn-Site-Id
X-Varnish-Beresp-Grace
X-Sql-Duration-Ms
X-Sql-Count
X-Cache-Server
X-R9-Blue-Green-Version
X-Server-W
X-Site-Version
X-RTag
X-Skip-Cache
X-Edge-Location
X-Proto
X-Labrador-Cache-Channel
X-Region
CDN-RequestCountryCode
X-Proxy-Cache-Status
X-Forwarded-Host
X-Nginx-Cache-Key
X-Urbn-Context-Path
X-SaId
X-SayCDN-TTL
X-PHP-Host
CDN-PullZone
X-Say-TTL
X-Redis-Cache
X-Say-Cacheable
Apigw-Requestid
Cache-Name
X-GeoCountry
X-Proxied
X-ShopId
X-ShardId
DB-Nickname
X-PHP-Backend
X-Varnish-Hostname
X-Xfnlog-Site
X-Web-Node
X-Sorting-Hat-PodId
X-VWS-Id
X-Via-Fastly
X-Varnishpool
X-Zipkin-Id
X-LJ-Flow-ID
X-No-Session
X-Cache-Type
X-AWS-Id
X-Alternate-Cache-Key
Mn-Server-Ip
X-Detected-As
X-Extlb
X-Shopify-Stage
X-Request-Time
X-Routing-Service
X-GeoCode
X-FB-TRIP-ID
X-Sorting-Hat-ShopId
X-ProxyCache-Key
X-BYPASS-REASON
X-Hl-Ver
X-ProxyCache-Status
X-Storefront-Renderer-Rendered
X-UA-Device-Type
X-Tid
WP-Super-Cache
X-Ms-Request-Id
X-Ms-Version
X-DynaTrace-JS-Agent
X-TIME
Selected-Fe
X-ServerID
X-Timing-Wait
X-Proxy-Build
X-Cache-Enabled
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
X-ECache
X-Uri
X-Vgn-Hpd-Reason
X-Loop
X-TNCMS
X-Amzn-Remapped-Content-Length
X-Ua
X-Pubstack
X-Varnish-Ttl
Xet-Cookie
X-Reqid
X-B3-Traceid
X-LSADC-Cache
X-Cache-NGX
X-Zen-Fury
X-Tumblr-Pixel-2
X-Dc
X-Origin-Date
X-Soup
X-Nginx-Cache
X-UUID
Fastcgi-Useragent
X-Service
X-Newrelic-Synthetics
X-Correlation-ID
X-Tec-Api-Origin
X-Tec-Api-Root
X-Aspnetmvc-Version
X-Tec-Api-Version
ServedBy
From-Origin
X-GEO
X-MP-GENERATED-AT
X-Ratelimit-Limit
X-Cache-Debug
Origin
X-Webkit-CSP
X-Origin-CC
X-Origin-TTL
Source
X-Human
X-Varnish-Hits
X-TA-CDN-Provider
Cache
Fastly-Drupal-HTML
X-App-Version
X-Cache-Tags
X-Cached-By
X-Varnish-Beresp-Ttl
Cross-Origin-Window-Policy
X-NewRelic-App-Data
X-Datadome
Webserver
X-RCS-CacheZone
Rip
Rendered-Blocks
X-Rewrite-Enabled
MD5-Digest
WPO-Cache-Status
WPO-Cache-Message
X-ScT
BehaviorPad-Version
Upgrade-Insecure-Requests
Host-ID
LB
X-A-Wwc
X-A-Dgt
X-Aed
X-AK-Request-ID
X-Application
X-A-Dcw
X-A-Dam
VNS-Cache
X-A
X-A-Ccd
X-Processor
X-ARC
X-B-Cookie
X-Developer
X-Destination
X-Connection-Hash
X-D
X-Cache-NE
X-S-Cookie
X-Rojux
X-S
X-Bc-Bl
X-BCube-Filmed-By
VNS-Age
X-Ec-Fail
Expiry
Environment
Lang
X-Forwarded-Path
Meta-Geo-Continent
A
Cdncip
CPC-Age
Cdnsip
DCR-Decision-By
DCR-Processing-Time-Ms
X-NAPM-TraceId
Ngx.Var.Host
X-PBS-Appsvrname
Surrogated-Key
T-Server
X-Ec-GeoHdr
X-Parent-Response-Time
Sslversion
X-Orig-Expires
Odigeo-Trace-Id
X-External-Request-Id
SD-X-WS
CPC-Cache
X-Cluster
X-Shop-Environment
X-User
X-SRCache-Key
X-VG-WebCache
X-Tenant
X-Vdms-Version
Xc-Version
X-TIM-N
X-Vdms-Path
Mime-Version
X-Debug-Cache
X-Request-Host
OT-Force-Account-Verify
X-AOL-HN
X-Accel-Buffering
X-Dispatcher-Number
X-Origin-Time
X-Owner
Redirect-Candidate
X-Aicache-OS
X-FW-Version
X-Nyt-Route
X-Served-From
X-Gdpr
X-Worker
Thinkindot-Control
X-Auto-Login
Thinkindot-CacheControl-Type
Fastly-Backend-Name
X-Cdn-Srv
TDXMobile
Server-Host
Thinkindot-CacheControl
X-CMSURLCustom
X-JWT-State
X-Geo-Header
X-Has-Esi
X-HS-Content-Campaign-Id
X-INCAP-ABP
X-Generated-On
X-Developers
X-Sucuri-ID
X-Thinkindot-L3
X-Sucuri-Cache
X-Core-Value
X-Level-Front-Cache
X-Is-Gdpr
AKAMAI
X-WP-CF-Super-Cache-Active
Svr
Fastly-SSL
Fastly-SIE
X-Ad-Defer-Variation
Fastly-GeoIP-CountryCode
State
Fastly-SWR
Servername
X-Gamma-Serve
Tube-Return
Tube-Got-Results
X-Varnish-CookieINHashed-On
X-Epic-Correlation-Id
X-Varnish-CookieHashed-On
X-Varnish-Beresp-Status
Decoy-Debug-Key
X-ATG-Version
Datacenter
X-Variation
Decoy-Debug-Status
Decoy-Debug-TTL
X-Wix-Viewer-Type
X-Esi-Check
Traceparent
Tube-Get-Contents
X-Ec-Custom-Error
X-WADP-Cache
V-Age
NGX
X-Fmm-Version
X-VG-TLSProxy
IsBot
Is-Eu
Mobile-Detection-Method
Wxu-Next-Commit
Wxu-Next-Region
L
X-Azure-Ref-OriginShield
X-Varnish-Remaining-TTL
Machine
Web-Mar-Region
X-Fetched-On
Release
Producers
Req-Svc-Chain
Vix-Hermes-Req-Id
X-VServer
X-Viewer-Country
Gh-Request-Id
Origin-CC
Origin-EX
X-Fastly-Backend
Platform
Wxu-Next-Hostname
X-V-Cache
X-Platform-Server
X-Planisys-CDN-TTL
X-Ckpd-Fst-Backend
X-Clara-WADP
X-Sn-Servicetimems
X-Pool
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
X-Cdn-Origin
X-NodeID
Country-Code
X-Origin-Response-Time
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-Proxy-Cache-Info
X-Qloud-Router
X-DefHash
X-Rocket-Nginx-Serving-Static
X-S-Maxage
X-SB
X-Scale
X-Scheme
X-Core-Mission
X-Cluster-Node
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-Region-Sid
X-Slack-Backend
X-SIPLIST1
X-Request-URI
X-NCache
X-Device-Os
Candidate-Md5Url
X-GeoIP-City
X-Gzip
X-BBC-Edge-Cache-Status
X-DPWN-IS-SECURE
X-Cache-Info
Tube-Got-Eval
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
Apple-News-Services-Handled
Adler-Geo
Click-Count-Action-Start
Click-Count-Error
X-DefElseHash
Cmstype
X-Minions-Version
X-Cache-Id
Cmsid
X-Loc
CloudFront-Viewer-Country
X-Branch-Name
Cluster
X-Cache-Bucket
Apple-News-Services-Host
X-Optimistic-Header
X-Cache-Remote
X-Tx-Id
Canary
Mail-Subject
X-CGP
X-Block-Status
X-Csrf-Jwt
X-Clientip
X-CacheTTL
We-Hiring
Cache-Host
X-Bip
User-Cache-Control
X-Gen-Mode
X-SplitTest
X-Var-Ttl
X-Presslabs-Stats
X-Sigma-Backend
DSUID
X-Gateway-Request-Id
X-Origin
CDCHOST
X-GeoIP
X-Mvc-Supplant-Cachable
X-Thanos
X-Policy
X-Irp-Debug
X-Hash
X-Hnp-Log
X-Gateway-Cache-Status
X-Gateway-Skip-Cache
X-FC-Vary-Parameters
NM-Fastcgi-Cache
Memcached
L5d-Success-Class
X-Udemy-Cache-App-Namespace
X-Eu-Site
Sever-Int
Server-Hostname
Server-Ext
X-Gateway-Cache-Key
Kp-EeAlive
Ha-Gx-Prefs
X-Sigma
X-Forwarded-Site
X-Rocket-Build-Number
HA-Ipaddr
X-Esi
X-Pass-Why
X-Tumblr-Pixel-3
Ec-Rule-Version
X-Up
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
X-LB-NoCache
X-Trace-ID
X-Mvc-Supplant-OutputCached
WebServer
X-IPS-LoggedIn
Pics-Label
X-Tb-Optimization-Total-Bytes-Saved
X-CACHE-AGE
X-Nf-Request-Id
X-Dispatch
Memory
Time
X-ND-Cache
Ssr
X-CSRF-Token
X-ZONE
Sid
HostName
X-Refresh
X-VC
X-Via-Popv
X-Via-NSCOPI
X-Via-Popn
Request-ID
X-B3-SpanId
X-Via-Poph
SID
X-Akamai-Transformed
AMP-Access-Control-Allow-Source-Origin
X-WA-Info
X-GG-Cache-Date
Cache-Tv-Group
X-Newrelic-App-Data
X-Edge-Pop
X-Servedbyhost
My-App
Fastcgi-Cache-TTL
Env
Server-ID
X-Session-Fingerprint
X-Req
X-Lambda-Id
X-Wa
X-B3-Spanid
X-Generated-In
X-Cs
X-Vc
Cache-Hits
X-Rebelmouse-Surrogate-Control
X-Release
X-Rebelmouse-Cache-Control
X-Pod-Name
X-Fastly-Cache
X-Fpc
X-CSRF-TOKEN
X-Origin-Expires
Hostname
X-NGINX-Cache
X-DC
CacheControlHeader
True-Client-Country-4JS
GeoIp-Country-Code
X-PX
X-EC-Lua
True-Client-IP
X-Zone
X-LB-ID
X-ID
X-MCACHE
X-Op-Id-All
X-VCL-Version
X-Xrds-Location
X-NWS-UUID-VERIFY
X-TX-ID
X-Cache-Date
X-Ig-Push-State
X-MSEdge-Features
X-MSEdge-Flight
X-Webkit-CSP-Report-Only
X-Buckets
X-CS
X-TH-Server
X-Conf
X-Endurance-Cache-Level
X-GeoIP-Region-Code
X-GeoIP-Country-Code
X-NC
X-Microcachable
X-CACHE-KEY
Resin-Trace
CDN
WWW-Authenticate
X-Date
X-Accel-Expires-Debug
X-TRACE-ID
X-RAMCache
X-HS-Status
X-Dmc
X-Old-Content-Length
X-Srv
X-RateLimit-Reset
Tcn
X-Vcl-Version
Path
Magicmarker
Powered-By
Fastly-Drupal-Html
X-Wikidot-Static-Cache
X-Wikidot-Backend
X-Check-Cacheable
X-Varnish-Beresp-TTL
X-Be
X-Akamai-Pragma-Client-IP
X-Vercel-Cache
True-Client-Ip
Section-Io-Origin-Status
Section-Io-Id
Section-Io-Origin-Time-Seconds
X-Alfa-Service
Section-Origin-Responded
X-Webstats-RespID
X-Vercel-Id
X-Cache-Ttl
X-Varnish-Authentication
X-API-Version
Yjs-Id
X-LiteSpeed-Cache-Control
X-Cache-ASPX
X-CLOUD-TRACE-CONTEXT
X-Contensis-Viewer-Groups
X-Datacenter
X-Director
Pramga
Proxy-Connection
X-Lb-Id
X-FPC
X-Hyper-Cache
GeoIP-Country-Code
X-Micro-Cache
X-Location
X-DataCenter
X-Geo
Cdn
FSS-Cache
X-CF-Lambda-Version
X-Via-CDN
X-CF-Lambda-Fn
X-M-Log
X-M-Reqid
X-Mly-Id
X-WA
X-Edge-POP
Lb
X-App
X-Qnm-Cache
X-Response-By
X-HA-Backend
Server-Id
Tracecode
User-Agent
X-Server-IP
ENV
X-ServedByHost
X-Cdn-Forward
X-Dw-Trace-Id
YJS-ID
X-Air-Trace-Id
X-Air-Source
X-Air-Hostname
X-Via-PopH
X-Via-PopV
X-Via-PopN
HIT
C-Via
N-Cache
M-TraceId
X-Test
X-Client-Ip
X-Cache-Backend
Uri
X-Akamai-ERPolicy
X-Akamai-ERRuleID
X-Cache-Expires
X-Service-Response-Time
Sm-Log-Id
X-AIR-PT
X-Cc-Via
X-Air-Pt
X-FL-EDGE
X-From
Srvid
X-Traceid
Location
X-We-Are-Hiring
Swift-Performance
Locid
X-Instance-Name
X-Platform-Router
Dnion-Transfer-Encoding
Geoip-Latitude
X-Li-Fabric
X-Platform-Processor
X-Platform-Cluster
Esi-Enabled
X-TT-LOGID
X-Platform
X-Li-Pop
X-UA
X-LI-UUID
X-LI-Proto
X-LiteSpeed-Tag
X-TrackingId
X-RPM
X-RPS
X-DSS
X-Fastly-Backend-Reqs
X-DB
X-DI
X-RSL
X-DW
X-PAYTM-SRV-ID
On-Server
X-Frame-Option
NtCoent-Length
Hit
CF-Cached-On
Fastcgi-X-Cache-Version
X-Request-Url
X-ApacheServer
Ohc-File-Size
Nginx-CQVIP
XM
X-PERF
XServer
PICS-Label
X-Info
CountryCode
X-Wp-Cf-Super-Cache
X-Wp-Cf-Super-Cache-Cache-Control
Wpo-Cache-Status
PFcat
X-Lb-Nocache
Wpo-Cache-Message
X-VarnishDD-TTL
X-CF-Powered-By
X-HostName
X-HN
X-Cdn-Request-ID
Vha6-Origin
X-Conten-Type-Options
X-Fastly-Cache-Hits
X-B3-ParentSpanId
X-Cache-Proxy
X-CUA
Warning
X-Litespeed-Cache-Control
X-Edge-Origin-Shield-Bytes
Wp-Super-Cache
X-Edge-Origin-Shield-Region
X-Cache-Ngx
X-Ips-Loggedin
X-MTS-Cache
X-Matome-Cached
X-Ittl
X-Kebab
X-N-OperationId
X-Is-SSL
X-Kebabable
X-Keep
X-Loadbalancer
X-LbNode
X-Matched-Rule
X-NXG
X-Odoo-Frontend
X-Nyt-Data-Last-Modified
X-Okws-Version
X-Onedio-Env
X-Origin-Ops
X-Ntj-Investigation-Id
X-NS-Authorization
X-Newegg-Flow
X-Newegg-Index
X-NFL-Dma
X-NFL-Geo
X-Nerd
X-Ee-Origin
X-Ee-Request-Id
X-Ee-Request-Date
X-Eid
X-ETag
X-Eventloop-Lag
X-Ee-Generated-By
X-Edge-IP
X-Developed-By
X-Doge
X-OVcl
X-DT-Node
X-F-Status
X-Farm
X-GoCache-CacheStatus
X-Group
X-Header-Sub
X-IBD-Cache
X-Global-Transaction-ID
X-Git-Commit
X-Fastly-Is-Edge
X-Fstrz
X-Full-Ttl
X-GG-Cache-Status
X-IBD-SID
X-Toujours-Debout-Location
X-User-Auth
X-Upstream-State
X-Utime
X-V2-Infrastructure
X-Vary-Devices
X-U-Cache
X-True-Client-Ip
X-Timestamp
X-Test-Nginx-Ingress
X-Toujours-Debout-Branch
X-Delivery
X-Tried-To-Kebabify
X-Ver
X-Wag-Acs
XV-H
XV-Cache
Timeexpire
X-B3-Parentspanid
X-Fastly-Country-Code
X-YSpaceId
X-Xms-Page-Cache-Actions
X-Waitingroom
X-Web-Hosting
X-WP-Bypass
X-WSR2
X-Svr-Proxy
X-SVR-IIS
X-Redis
X-Reboot
X-Render-Method
X-Render-Time
X-Request-Origin
X-R-Cache
X-Pver
X-PageType
X-Paywall
X-PG-ACCESS
X-PGF-Deflate
X-Route
X-Route-Akamai
X-SMP-JWT
X-Slack-Shared-Secret-Outcome
X-Square
X-SSLProxy
X-Stack-Name
X-Site
X-Sh
X-Ruby
X-Save-Cache
X-Server-L
X-ServiceName
X-OVcl-Cache
X-Apache-Server
NB-ESI
Joe-X
Nikkei-App-Version
NLCacheNote
Npm-Cost
Is-Https
HTTPProtocol
Deeplink
CMS-200
Ec-Policy-Id
H1
HServer
Npm-Remaining
Ns
Region
RawURL
Request-Uuid
Rt-Proxy-Cache
Scheme
Proxy-Cache
Panzer-Cache-Control
Ok-Cache-Status
Ns-Ua
OK-Edge-Date
Ok-Edge-Key
Origin-Site
Cluster-Host
Cf-Wrk
X-Mg-Cache
WZWS-RAY
X-Node-Id
X-ElasticPress-Query
X-Moov-Xdn-Version
DynaTrace
X-Request-Start
Req-ID
Fastcgi-Cache-Ttl
X-Vtex-Remote-Cache
X-Vtex-Processado-Em
SRV
X-Yottaa-OS
X-Moov-T
Cachekey
Cache-Stat
Cdn-Country-Code
Cf-Device-Type
Cf-Locale
Akamai-X-Url
X-Th-Server
X-IN-APIGATEWAYSSL
X-IN-APIGATEWAY
GeoIP-Latitude
Cneonction
X-Serial
Selected-Route
Served
X-BeanStalkRole
X-Backside-Transport
X-BeanStalkStage
X-Cache-Cookie
X-Cache-IsMobileDevice
X-Backend-TTL
X-AspNetWebPages-Version
X-Ar-Stats
X-Amz-Meta-Cb-Modifiedtime
X-Arena-Request-Id
X-ARRRG1
X-ASF-Cache
X-Cache-Length
X-Cache-NPR
X-Coindesk-Cache
X-Cms-Device
X-Colour
X-Container-Uri
X-Dcm-Pdtf
X-Cf-Node-Idx
X-CDN-Pop-IP
X-Cache-ReqUri
X-Cache-Reason
X-Cache-Response
X-CacheVersion
X-CDN-Pop
X-Akamai-Native
X-Akamai-DeviceType
Time-Cloud-Cache
Technodrome
Ttl
TWC-AK-Req-ID
TWC-PATH-LOCALE
T-Request-Id
Sw
SFRVia
Service-Uuid
Shieldsquare-Response
SII
Store-Cloud-Cache
TWC-Subs
TWC-Unit
X-Accor-Asset
X-Accepted-Language
X-AEO-Platform
X-Akamai-CacheKeyMod
X-Akamai-DeviceOS
X-Accepted-Fulllang
X-Accel-Version
Userver
Uniqueid
Vttl
X-77-NZT
X-77-NZT-Ray
X-Dehri-Date