Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
Strict-Transport-Security
X-Frame-Options
X-Content-Type-Options
Last-Modified
Link
CF-Cache-Status
Cf-Request-Id
CF-RAY
Accept-Ranges
ETag
Expect-CT
Pragma
X-Powered-By
X-Cache
Via
X-XSS-Protection
Age
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Xss-Protection
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
P3P
X-FRAME-OPTIONS
X-Served-By
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Request-Id
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-Adblock-Key
X-AspNet-Version
X-Permitted-Cross-Domain-Policies
Alt-Svc
X-Runtime
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Cache-Status
X-Generator
X-Cacheable
P3p
X-Request-ID
X-Iinfo
X-Envoy-Upstream-Service-Time
Timing-Allow-Origin
Feature-Policy
X-Content-Security-Policy
Status
X-Drupal-Dynamic-Cache
Content-Encoding
X-AspNetMvc-Version
Access-Control-Expose-Headers
Upgrade
X-CDN
X-Ua-Compatible
Access-Control-Max-Age
CF-Ray
X-Via
X-Robots-Tag
X-Cache-Group
Server-Timing
X-Dns-Prefetch-Control
X-UA-Device
Request-Context
Keep-Alive
X-AH-Environment
X-Amz-Request-Id
X-Turbo-Charged-By
X-Proxy-Cache
X-Backend
X-Amz-Id-2
X-Age
Host-Header
X-Ws-Request-Id
X-Hacker
X-Server-Powered-By
X-Server
X-Rq
X-Vhost
X-LiteSpeed-Cache
X-Varnish-Cache
X-Amz-Version-Id
Grace
EagleId
X-Dispatcher
Cf-Edge-Cache
Nel
Allow
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Device
X-Page-Speed
X-Nginx-Cache-Status
X-Swift-CacheTime
X-Swift-SaveTime
X-WebKit-CSP
Ali-Swift-Global-Savetime
X-Aws-Lambda-Call-Status
Accept-CH
X-Host
X-Node
Cf-Railgun
X-Pingback
X-Cache-Spec
X-Server-Id
X-OneAgent-JS-Injection
Surrogate-Control
X-Backend-Server
X-Akam-SW-Version
Request-Id
X-Akamai-Path-Stats
EagleEye-TraceId
X-Response-Time
X-Cache-Lookup
X-Readtime
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
Accept-CH-Lifetime
Content-Location
X-HW
X-Content-Security-Policy-Report-Only
X-Application-Context
Rating
X-Trace
X-Cloud-Trace-Context
Fastly-Restarts
X-WebKit-CSP-Report-Only
Accept-Ch-Lifetime
X-Clacks-Overhead
X-Nginx-Upstream-Cache-Status
X-Country
X-Oneagent-Js-Injection
X-MS-InvokeApp
X-Url
X-Amz-Server-Side-Encryption
X-Rack-Cache
X-Edge
X-B3-TraceId
X-Vname
X-TtlSet
X-PC
Edge-Control
X-Mod-Pagespeed
X-CST
X-Content-Type
X-Vcap-Request-Id
X-Ruxit-Js-Agent
X-ESI
X-FastCGI-Cache
X-Ruxit-JS-Agent
X-Mcache
Verso
X-D2id
Xkey
X-Kinja-Revision
X-Kinja-Server
X-Use-Magma
X-Kinja
X-Kinja-Build
X-Exp-Variant
X-Exp-Id
X-Cdn-Fetch
X-GoogleNews-Bot
X-GitHub-Request-Id
Cache-Tag
X-Amz-Rid
X-Powered-By-Plesk
Service-Worker-Allowed
RTSS
X-Varnish-TTL
X-VARITI-CCR
X-Navigation-Version
X-ECACHE
X-Version
X-Abt-Application-Version
X-Upstream
Cf-Apo-Via
X-Client-IP
X-Cached
X-Ac
X-Server-Name
X-Cnection
X-Element-Page-Cache
X-Dw-Request-Base-Id
Arr-Disable-Session-Affinity
X-Ttl
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Instrumentation
SPRequestGuid
X-SharePointHealthScore
Permissions-Policy
X-Px
SPIisLatency
SPRequestDuration
X-Middleton-Display
Display
Pagespeed
X-Sol
X-Country-Code
Public-Key-Pins
X-Cache-TTL
X-NWS-LOG-UUID
X-Middleton-Response
Response
X-RateLimit-Remaining
Accept-Ch
X-Ser
X-Midtier
X-Edge-Location-Klb
X-Kinsta-Cache
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Goog-Hash
X-Cache-Key
X-Forwarded-For
Content-MD5
X-NF-Request-ID
Access-Control-Request-Method
X-Correlation-Id
Front-End-Https
X-MSEdge-Ref
X-Shield-Request-Id
X-DataDome
X-ORACLE-DMS-ECID
X-Recruiting
X-ORACLE-DMS-RID
X-T
TP-L2-Cache
TP-Cache
X-B3-TraceId-Primal
AR-Request-ID
AR-PoweredBy
AR-CACHE
AR-ATIME
AR-SID
Mrf-Cache-Status
MRF-Tech
Edge-Cache-Tag
X-HP-Webp
X-Jurisdiction
X-HP-Trace-Id
MicrosoftSharePointTeamServices
Nginx-Cache
X-Accel-Expires
X-RateLimit-Limit
X-Daa-Tunnel
X-Mg-S
X-Powered-CMS
X-Grace
X-Content-Digest
X-Hits
TCN
Filters
X-Request-Processing-Time
X-Request-Received
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Amzn-Trace-Id
X-Browser-Type
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-HS-Content-Id
X-HS-Combine-CSS
X-HS-Hub-Id
Server-Node
X-Id
X-HS-Cache-Config
Server-Name
MS-Author-Via
X-Geo-Country
Fastcgi-Cache
X-Fastly-Request-Id
X-Webkit-Csp
X-PressLabs-Stats
X-Frontend
X-Distributor
Count-Hit
X-Origin-Server
X-XRDS-Location
X-Ezoic-Cdn
X-Ua-Browser
S
X-Protected-By
X-Ab
X-Amz-Meta-S3cmd-Attrs
Filterid
X-Forwarded-Proto
X-LLID
Cross-Origin-Opener-Policy
X-ASPNET-VERSION
X-B3-Sampled
Cache-Status
X-FB-Debug
X-F-Cache
X-Microsite
X-LB-Cache
X-Request-Handler-Origin-Region
Charset
X-Seen-By
Payment
X-Ratelimit-Reset
X-Git-Hash
X-Page-Id
Host
X-Language
X-VCache
X-Cluster-Name
Surrogate-Key
X-Rid
X-Www-Served-By
X-Cdn
Cache-Tags
Realpath
X-Fastcgi-Cache
Retry-After
X-TTL
Accept-Charset
X-Logged-In
X-Upgrade-Enabled
Access-Control-Allow-Method
X-Cache-Age
X-Source
Alternate-Protocol
X-Origin-Cache
X-DIS-Request-ID
X-NGENIX-Cache
X-Activity-Id
X-Az
X-AppVersion
X-Varnish-Backend
X-Type
DC
Paypal-Debug-Id
X-Amz-Replication-Status
X-Tb
X-TT
X-Wix-Request-Id
X-Flags
Cleartype
ServerID
X-Envoy-Decorator-Operation
X-Is-Crawler
X-Request-Guid
X-Providence-Cookie
X-Route-Name
X-Aspnet-Duration-Ms
X-B-Cache
X-B
X-Signature
X-Varnish-Grace
X-Template
X-App-Environment
X-Hostname
X-Revision
X-Node-Name
X-DynaTrace
Frame-Options
X-Drupal-Cache-Tags
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Contextid
X-Cache-Rule
Pinterest-Version
X-Pinterest-Rid
Pinterest-Generated-By
X-Proxy
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Debug
Refresh
X-Goog-Generation
X-Goog-Metageneration
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-Goog-Stored-Content-Encoding
X-Load-Cache
X-Fastly-Request-ID
X-Mobile
X-Content-Options
X-EdgeConnect-Cache-Status
X-N
X-XRDS-LOCATION
Node
Amp-Access-Control-Allow-Source-Origin
X-Cache-Control
Referer-Policy
Cross-Origin-Resource-Policy
NGB
X-Response-Served-From
Country
X-Original-Request-Id
X-Magnolia-Registration
Akamai-GRN
X-Debug-IsConnected
X-Debug-IsPreview
X-Varnish-Age
X-Cache-TTL-Remaining
X-L-Path
X-Content-Powered-By
X-NYM-Debug-Backend
X-Status
X-Varnish-Server
Access-Control-Request-Headers
X-Environment-Context
Content-Disposition
X-Instance
X-COUNTRY
X-Cache-Grace
X-Is-Bot
X-G
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Cacheable-TTL
X-Adobe-Loc
X-Adobe-Content
VIX-Pulpo-Node
X-Rendered-As
Viewport
X-Servername
X-Real-IP
X-Cache-Time
VIX-Pulpo-Upstream-Status
X-Page-View
Uber-Trace-Id
Url
X-Akamai-Request-ID2
X-Jobs
X-Framework
X-Mid
X-ProcessESI
X-Whom
X-RemovedCookies
Srv
X-User-Agent
X-Unique-Id
X-Trace-Id
Countrycode
X-Via-JSL
X-URL
X-Drupal-Cache-Contexts
X-CDN-Forward
X-Cache-Expired-At
X-Cache-Hit
X-Time
Version
X-Tumblr-User
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-Tumblr-Pixel
Accept-Language
X-Ratelimit-Remaining
X-Mg-Request-UUID
X-Cache-Operation
X-Content
X-Litespeed-Cache
X-Http-Reason
X-Api-Version
X-Oracle-Dms-Ecid
X-APP-VERSION
X-Rule
X-Backend-Name
X-Oracle-Dms-Rid
Healthy
Protected
X-App-Server
X-Server-ID
X-Cache-Action
Section-Io-Cache
X-Restarts
X-IPLB-Request-ID
X-IPLB-Instance
Content-Secure-Policy
X-Azure-Ref
X-Akamai-Edgescape
X-Debug-Info
X-Hosted-By
X-VC-Cache
X-Generation-Time
Server-Info
Backend
X-SRV
GEO-INFO
Xserver
X-FW-Hash
X-FW-Dynamic
Load-Balancing
X-RN-RSRV
X-FW-Serve
X-FW-Type
X-FW-Static
X-Nginx-Cache-Key
X-Tt-Logid
X-Device-Type
X-Storage
Liferay-Portal
X-Mobile-URL
X-UPSTREAM-Address
X-FW-Server
Meta-Geo
X-Generated-By
CF-IPCountry
X-HTML-Minification-Powered-By
Onion-Location
Azure-SlotName
Azure-SiteName
Azure-Version
X-Amz-Apigw-Id
X-Cms-Context
X-Locale
X-OCL
Azure-RegionName
X-Access
X-Format
S-Rt
X-Handled-By
X-Amzn-RequestId
Azure-InstanceId
X-Mode
X-FireWall-Port
X-PCL
MS-CV
Ms-Operation-Id
X-Section
X-RTag
Eomportal-Instance
TWC-Privacy
X-SaId
TWC-Locale-Group
X-Say-Cacheable
Locale
Webcakes-App-Version
Webcakes-Region
X-Say-TTL
TWC-GeoIP-LatLong
Webcakes-App-Name
X-PHP-Host
TWC-Connection-Speed
X-R9-Blue-Green-Version
X-Proxy-Cache-Status
X-Redis-Cache
Property-Id
CDN-RequestId
X-ShardId
X-Proto
X-Shopify-Stage
TWC-Device-Class
X-ShopId
X-SayCDN-TTL
CDN-Uid
TWC-GeoIP-Country
X-Sorting-Hat-PodId
CDN-Cache
Cache-Name
X-Edge-Location
X-Forwarded-Host
X-Varnish-Beresp-Grace
X-Cache-Status-Check
X-Region
X-Cache-Host
X-Adobe-Source
X-Cache-Server
X-Origin-Hint
X-Content-Age
X-JoinUs
X-Alternate-Cache-Key
X-Sql-Count
X-Sql-Duration-Ms
X-Sorting-Hat-ShopId
Web-Mar-Node
X-Skip-Cache
CDN-RequestCountryCode
CDN-PullZone
CDN-CachedAt
CDN-EdgeStorageId
X-Labrador-Cache-Channel
X-Urbn-Context-Path
X-Site-Version
X-Urbn-Site-Id
X-Via-Fastly
X-Web-Node
X-Xfnlog-Site
X-Zipkin-Id
Apigw-Requestid
X-No-Session
X-Routing-Service
X-Ratelimit-Limit
X-Proxied
X-Storefront-Renderer-Rendered
X-GeoCountry
X-GeoCode
X-Detected-As
X-Varnish-Hostname
X-Varnishpool
X-VWS-Id
X-Varnish-Cache-Hits
X-Extlb
X-AWS-Id
X-LJ-Flow-ID
X-PHP-Backend
X-Server-W
X-BYPASS-REASON
X-Hl-Ver
X-ProxyCache-Key
X-UA-Device-Type
X-ProxyCache-Status
X-Request-Time
X-Timing-Wait
Selected-Fe
X-Proxy-Build
Mn-Server-Ip
X-Tid
X-ECache
X-DynaTrace-JS-Agent
WP-Super-Cache
X-Ms-Version
X-Ms-Request-Id
X-Uri
X-Cache-Enabled
X-Provided-By
Fastcgi-Useragent
X-WP-CF-Super-Cache
X-ServerID
X-FB-TRIP-ID
X-Cache-Type
DB-Nickname
X-WP-CF-Super-Cache-Cache-Control
X-Nginx-Cache
X-Varnish-Ttl
X-Cache-NGX
X-Ua
X-Loop
X-Dc
X-Amzn-Remapped-Content-Length
X-Datadome
X-TNCMS
X-Origin-Date
X-UUID
Xet-Cookie
X-Vgn-Hpd-Reason
X-LSADC-Cache
X-Pubstack
X-Reqid
X-Correlation-ID
X-Aspnetmvc-Version
X-Tumblr-Pixel-2
X-Zen-Fury
ServedBy
X-App-Version
X-Webkit-CSP
X-Soup
X-Newrelic-Synthetics
X-Service
X-MP-GENERATED-AT
X-Origin-TTL
X-Human
X-Origin-CC
Origin
Source
X-TA-CDN-Provider
Cache
X-Varnish-Hits
From-Origin
X-Cache-Debug
X-GEO
X-RCS-CacheZone
X-Cached-By
X-Cache-Tags
Cross-Origin-Window-Policy
X-TIME
X-Tec-Api-Root
X-Tec-Api-Origin
X-Varnish-Beresp-Ttl
X-Tec-Api-Version
WPO-Cache-Status
WPO-Cache-Message
X-Debug-Cache
LB
X-NewRelic-App-Data
Rip
X-B3-Traceid
Rendered-Blocks
BehaviorPad-Version
MD5-Digest
X-ScT
SD-X-WS
Fastly-Drupal-HTML
X-Request-Host
Host-ID
CPC-Cache
DCR-Decision-By
CPC-Age
T-Server
Xc-Version
A
Meta-Geo-Continent
DCR-Processing-Time-Ms
Lang
Surrogated-Key
X-Ec-GeoHdr
X-TIM-N
X-Orig-Expires
X-A-Dgt
X-Shop-Environment
Cdnsip
X-A-Ccd
Cdncip
X-A
VNS-Cache
VNS-Age
X-Forwarded-Path
X-NAPM-TraceId
X-External-Request-Id
X-Tenant
X-A-Dcw
X-A-Dam
X-SRCache-Key
X-Ec-Fail
X-A-Wwc
X-Cache-NE
X-Vdms-Version
X-Application
X-B-Cookie
X-Connection-Hash
X-ARC
Odigeo-Trace-Id
Ngx.Var.Host
X-Vdms-Path
X-Bc-Bl
X-BCube-Filmed-By
X-Rewrite-Enabled
X-Processor
X-Rojux
X-S
X-AK-Request-ID
X-PBS-Appsvrname
X-Parent-Response-Time
X-Developer
Sslversion
X-VG-WebCache
Environment
X-D
X-S-Cookie
X-Aed
X-User
X-Destination
Expiry
X-Dispatcher-Number
X-Cluster
X-Accel-Buffering
X-Served-From
X-Aicache-OS
X-Owner
X-Gdpr
X-Origin-Time
Redirect-Candidate
X-AOL-HN
X-FW-Version
X-Nyt-Route
Webserver
X-Level-Front-Cache
X-Auto-Login
X-Is-Gdpr
X-JWT-State
Upgrade-Insecure-Requests
X-Geo-Header
X-CMSURLCustom
X-WP-CF-Super-Cache-Active
X-Has-Esi
X-HS-Content-Campaign-Id
X-Sucuri-Cache
X-INCAP-ABP
X-Cdn-Srv
Thinkindot-Control
X-Generated-On
Server-Host
Fastly-Backend-Name
AKAMAI
X-Developers
X-Core-Value
Mime-Version
TDXMobile
WebServer
X-Thinkindot-L3
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
X-Worker
X-Sucuri-ID
Vix-Hermes-Req-Id
Platform
Producers
Release
Origin-EX
Origin-CC
Machine
Mobile-Detection-Method
NGX
Req-Svc-Chain
State
Tube-Return
V-Age
Web-Mar-Region
Tube-Got-Results
Tube-Got-Eval
Svr
Traceparent
Tube-Get-Contents
X-Ad-Defer-Variation
X-Clientip
L
X-Optimistic-Header
X-Origin
X-Origin-Response-Time
X-Viewer-Country
X-VServer
X-Scale
X-WADP-Cache
X-NCache
X-Slack-Backend
X-SIPLIST1
X-Wix-Viewer-Type
X-Varnish-CookieINHashed-On
X-Scheme
X-SB
X-Varnish-Remaining-TTL
X-Proxy-Cache-Info
X-Pool
X-Qloud-Router
X-Request-URI
X-Region-Sid
X-RateLimit-Limit-Second
X-Rocket-Nginx-Serving-Static
X-VG-TLSProxy
X-S-Maxage
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Platform-Server
X-Sn-Servicetimems
X-SVT-ORM-RULES
X-RateLimit-Remaining-Second
X-Clara-WADP
X-Variation
X-Core-Mission
X-DefHash
X-DefElseHash
X-Cdn-Origin
X-Cache-Info
X-BBC-Edge-Cache-Status
X-Azure-Ref-OriginShield
X-Bip
X-Cache-Bucket
X-Cache-Id
X-DPWN-IS-SECURE
X-Epic-Correlation-Id
X-Gamma-Serve
X-Varnish-CookieHashed-On
X-GeoIP-City
X-Gzip
X-Var-Ttl
X-Minions-Version
X-SVT-ORM-VERSION
X-Forwarded-Site
X-Varnish-Beresp-Status
X-Esi-Check
X-Thanos
X-Fastly-Backend
X-Fmm-Version
X-ATG-Version
X-NodeID
Cmstype
Cmsid
Cluster
Country-Code
Decoy-Debug-Key
DSUID
Decoy-Debug-TTL
CloudFront-Viewer-Country
Click-Count-Error
Apple-News-Services-Host
Apple-News-Services-Handled
Adler-Geo
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
Click-Count-Action-Start
Candidate-Md5Url
Fastly-GeoIP-CountryCode
Decoy-Debug-Status
Fastly-SWR
X-IPS-LoggedIn
Fastly-SIE
Gh-Request-Id
Is-Eu
IsBot
Fastly-SSL
X-Esi
OT-Force-Account-Verify
X-B3-SpanId
X-Cache-Remote
X-Policy
Memcached
X-CGP
X-Mvc-Supplant-Cachable
Wxu-Next-Commit
X-Block-Status
X-Cluster-Node
X-Device-Os
X-Ckpd-Fst-Backend
Wxu-Next-Region
X-CacheTTL
Wxu-Next-Hostname
NM-Fastcgi-Cache
Datacenter
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
X-CSRF-Token
HostName
X-Eu-Site
X-Ec-Custom-Error
X-Fetched-On
X-Gen-Mode
X-Loc
Kp-EeAlive
X-FC-Vary-Parameters
X-Irp-Debug
X-Csrf-Jwt
X-Hnp-Log
X-Udemy-Cache-App-Namespace
X-Branch-Name
User-Cache-Control
Servername
CDCHOST
We-Hiring
X-V-Cache
Mail-Subject
Server-Hostname
Ha-Gx-Prefs
X-Gateway-Cache-Key
HA-Ipaddr
L5d-Success-Class
Server-Ext
X-SplitTest
Sever-Int
X-GeoIP
X-Gateway-Request-Id
X-Gateway-Cache-Status
X-Hash
X-Gateway-Skip-Cache
AMP-Access-Control-Allow-Source-Origin
X-VC
X-Trace-ID
X-Newrelic-App-Data
Sid
Ec-Rule-Version
X-Sigma-Backend
X-LB-NoCache
Cache-Host
X-Sigma
Canary
X-Rocket-Build-Number
X-ND-Cache
X-Mvc-Supplant-OutputCached
X-Pass-Why
X-Via-NSCOPI
X-Tx-Id
X-Nf-Request-Id
Pics-Label
X-GG-Cache-Date
X-Up
X-Tumblr-Pixel-3
X-WA-Info
Cache-Tv-Group
Time
Memory
Fastcgi-Cache-TTL
Request-ID
X-Tb-Optimization-Total-Bytes-Saved
X-ZONE
X-Dispatch
Cache-Hits
X-Via-Popv
X-Via-Poph
X-Via-Popn
X-Session-Fingerprint
Ssr
X-Refresh
X-Cs
X-Pod-Name
X-Origin-Expires
X-Rebelmouse-Cache-Control
X-Lambda-Id
X-Rebelmouse-Surrogate-Control
My-App
X-Edge-Pop
X-Fastly-Cache
X-Akamai-Transformed
X-Release
X-Servedbyhost
X-Generated-In
Server-ID
Env
SID
X-Zone
X-CACHE-AGE
X-CACHE-KEY
X-Req
X-Wa
X-Presslabs-Stats
X-PX
X-LB-ID
GeoIp-Country-Code
X-ID
X-Fpc
X-CLOUD-TRACE-CONTEXT
X-DC
X-TX-ID
X-NWS-UUID-VERIFY
X-MSEdge-Flight
X-Cache-Date
CacheControlHeader
True-Client-IP
X-MSEdge-Features
X-Ig-Push-State
True-Client-Country-4JS
X-Xrds-Location
X-Buckets
CDN
X-EC-Lua
X-NC
X-Conf
X-Endurance-Cache-Level
X-B3-Spanid
X-Vc
X-NGINX-Cache
X-Microcachable
X-Webkit-CSP-Report-Only
X-CSRF-TOKEN
Hostname
X-Op-Id-All
X-VCL-Version
X-TH-Server
Tcn
X-Dmc
X-CS
X-TRACE-ID
X-GeoIP-Country-Code
X-GeoIP-Region-Code
Fastly-Drupal-Html
X-HS-Status
X-Vcl-Version
Resin-Trace
X-Date
X-Accel-Expires-Debug
Magicmarker
WWW-Authenticate
X-RateLimit-Reset
X-RAMCache
X-MCACHE
X-Srv
X-Wikidot-Static-Cache
X-Be
X-Wikidot-Backend
X-Check-Cacheable
X-Vercel-Id
Path
X-Vercel-Cache
X-Varnish-Beresp-TTL
X-Old-Content-Length
X-FPC
Section-Origin-Responded
Powered-By
Section-Io-Origin-Status
X-Alfa-Service
X-Datacenter
X-Hyper-Cache
Pramga
Section-Io-Origin-Time-Seconds
True-Client-Ip
Section-Io-Id
X-Akamai-Pragma-Client-IP
X-Geo
X-LiteSpeed-Cache-Control
X-Cache-Ttl
Yjs-Id
GeoIP-Country-Code
X-CF-Lambda-Fn
X-Micro-Cache
X-WA
X-CF-Lambda-Version
X-M-Log
X-M-Reqid
Proxy-Connection
X-Location
X-Mly-Id
FSS-Cache
X-App
X-Via-CDN
X-ServedByHost
Tracecode
ENV
X-Webstats-RespID
X-Qnm-Cache
X-Varnish-Authentication
X-Contensis-Viewer-Groups
X-Air-Trace-Id
X-Edge-POP
X-Cache-ASPX
X-Air-Source
X-Air-Hostname
X-API-Version
YJS-ID
C-Via
X-Akamai-ERPolicy
User-Agent
X-Lb-Id
Server-Id
X-Akamai-ERRuleID
X-TT-LOGID
Lb
X-Response-By
X-Air-Pt
X-Director
X-Cdn-Forward
X-Server-IP
HIT
X-Via-PopV
X-Via-PopN
X-Via-PopH
X-TrackingId
Cdn
X-Platform-Router
N-Cache
X-Platform-Processor
X-Platform-Cluster
X-Client-Ip
X-AIR-PT
X-Service-Response-Time
X-SERVER-NAME
X-DataCenter
Sm-Log-Id
X-Dw-Trace-Id
X-PAYTM-SRV-ID
X-HA-Backend
X-Traceid
Swift-Performance
Uri
X-Instance-Name
Location
X-Test
X-FORWARDED-FOR
NtCoent-Length
Hit
Dnion-Transfer-Encoding
Geoip-Latitude
X-Li-Pop
Esi-Enabled
Fastcgi-X-Cache-Version
X-From
X-UA
X-Platform
X-FL-EDGE
X-LI-Proto
X-Li-Fabric
Srvid
On-Server
Locid
X-LI-UUID
X-LiteSpeed-Tag
X-RPS
XServer
X-DI
Ohc-File-Size
X-DW
X-DSS
X-RSL
X-RPM
X-CUA
M-TraceId
X-DB
Nginx-CQVIP
X-Cache-Backend
PICS-Label
X-Cc-Via
X-Wp-Cf-Super-Cache
X-Edge-Origin-Shield-Bytes
X-Litespeed-Cache-Control
X-Edge-Origin-Shield-Region
X-Wp-Cf-Super-Cache-Cache-Control
X-Cache-Proxy
X-Cache-Expires
X-Conten-Type-Options
X-We-Are-Hiring
Vha6-Origin
X-Vtex-Processado-Em
X-Request-Url
X-Fastly-Cache-Hits
X-Fastly-Backend-Reqs
X-B3-ParentSpanId
X-Vtex-Remote-Cache
X-HostName
GeoIP-Latitude
X-Node-Id
X-CF-Powered-By
Wpo-Cache-Message
X-Cdn-Request-ID
Wpo-Cache-Status
X-Lb-Nocache
Wp-Super-Cache
Warning
CountryCode
X-Cache-Ngx
X-Ips-Loggedin
X-Matome-Cached
X-MTS-Cache
X-LbNode
X-Ittl
X-Is-SSL
X-IBD-SID
X-Kebab
X-Kebabable
X-Loadbalancer
X-Keep
X-Matched-Rule
X-NFL-Dma
X-Nyt-Data-Last-Modified
X-NXG
X-Odoo-Frontend
X-Okws-Version
X-Onedio-Env
X-Ntj-Investigation-Id
X-NS-Authorization
X-Newegg-Flow
X-Nerd
X-Newegg-Index
X-IBD-Cache
X-NFL-Geo
X-N-OperationId
X-Fastly-Is-Edge
X-Ee-Origin
X-Ee-Generated-By
X-Ee-Request-Date
X-Ee-Request-Id
X-Eid
X-Edge-IP
X-DT-Node
X-Dehri-Date
X-Dcm-Pdtf
X-Delivery
X-Developed-By
X-Doge
X-ETag
X-Eventloop-Lag
X-Git-Commit
X-GG-Cache-Status
X-Global-Transaction-ID
X-GoCache-CacheStatus
X-Group
X-Full-Ttl
X-Fstrz
X-F-Status
X-Farm
X-Origin-Ops
X-Frame-Option
X-Header-Sub
X-Redis
X-Utime
X-User-Auth
X-V2-Infrastructure
X-Vary-Devices
X-Ver
X-Upstream-State
X-U-Cache
X-Toujours-Debout-Branch
X-Timestamp
X-Toujours-Debout-Location
X-Tried-To-Kebabify
X-True-Client-Ip
X-Wag-Acs
X-Waitingroom
Timeexpire
ServerName
X-ApacheServer
X-B3-Parentspanid
X-PERF
XV-H
XV-Cache
X-WP-Bypass
X-Web-Hosting
X-WSR2
X-Xms-Page-Cache-Actions
X-YSpaceId
X-Test-Nginx-Ingress
X-Svr-Proxy
X-Render-Method
X-Reboot
X-Render-Time
X-Request-Origin
X-Route
X-R-Cache
X-Pver
X-PageType
X-OVcl-Cache
X-Paywall
X-PG-ACCESS
X-PGF-Deflate
X-Route-Akamai
X-Ruby
X-Square
X-SMP-JWT
X-SSLProxy
X-Stack-Name
X-SVR-IIS
X-Slack-Shared-Secret-Outcome
X-Site
X-Save-Cache
X-Server-L
X-ServiceName
X-Sh
X-OVcl
X-Cache-Response
NB-ESI
Joe-X
Nikkei-App-Version
NLCacheNote
Npm-Cost
Is-Https
HTTPProtocol
Deeplink
CMS-200
Ec-Policy-Id
H1
HServer
Npm-Remaining
Ns
Region
RawURL
Request-Uuid
Rt-Proxy-Cache
Scheme
Proxy-Cache
Panzer-Cache-Control
Ok-Cache-Status
Ns-Ua
OK-Edge-Date
Ok-Edge-Key
Origin-Site
Cluster-Host
Cf-Wrk
X-Moov-T
X-Moov-Xdn-Version
X-ElasticPress-Query
X-Yottaa-OS
CF-Cached-On
X-Request-Start
X-Mg-Cache
DynaTrace
SRV
WZWS-RAY
Fastcgi-Cache-Ttl
Req-ID
X-SD-PageType
X-IN-APIGATEWAY
Cachekey
Cache-Stat
Cdn-Country-Code
Cf-Device-Type
Cf-Locale
Akamai-X-Url
X-Th-Server
X-IN-APIGATEWAYSSL
X-LAGOON
Cneonction
X-Serial
Selected-Route
Served
X-Backend-TTL
X-AspNetWebPages-Version
X-Backside-Transport
X-BeanStalkRole
X-BeanStalkStage
X-ASF-Cache
X-ARRRG1
X-Amz-Meta-Cb-Modifiedtime
X-Akamai-Native
X-Apache-Server
X-Ar-Stats
X-Arena-Request-Id
X-Cache-Cookie
X-Cache-IsMobileDevice
X-Cf-Node-Idx
X-CDN-Pop-IP
X-Cms-Device
X-Coindesk-Cache
X-Colour
X-CDN-Pop
X-CacheVersion
X-Cache-Length
X-Cache-NPR
X-Cache-Reason
X-Cache-ReqUri
X-Akamai-DeviceType
X-Akamai-DeviceOS
Time-Cloud-Cache
Technodrome
Ttl
TWC-AK-Req-ID
TWC-PATH-LOCALE
T-Request-Id
Sw
SFRVia
Service-Uuid
Shieldsquare-Response
SII
Store-Cloud-Cache
TWC-Subs
TWC-Unit
X-Accepted-Language
X-Accepted-Fulllang
X-Accor-Asset
X-AEO-Platform
X-Akamai-CacheKeyMod
X-Accel-Version
X-77-NZT-Ray
Uniqueid
Userver
Vttl
X-77-NZT
X-Container-Uri