Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
Strict-Transport-Security
X-Frame-Options
X-Content-Type-Options
Last-Modified
Link
CF-Cache-Status
Cf-Request-Id
CF-RAY
Accept-Ranges
ETag
Expect-CT
Pragma
X-Powered-By
X-Cache
Via
X-XSS-Protection
Age
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Xss-Protection
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-FRAME-OPTIONS
X-Served-By
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Request-Id
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-Adblock-Key
X-AspNet-Version
X-Permitted-Cross-Domain-Policies
Alt-Svc
X-Runtime
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Cache-Status
X-Generator
X-Cacheable
X-Request-ID
X-Iinfo
P3p
X-Envoy-Upstream-Service-Time
Timing-Allow-Origin
Feature-Policy
X-Content-Security-Policy
Status
X-Drupal-Dynamic-Cache
Content-Encoding
X-AspNetMvc-Version
Access-Control-Expose-Headers
Upgrade
X-CDN
X-Ua-Compatible
Access-Control-Max-Age
CF-Ray
X-Via
X-Robots-Tag
X-Cache-Group
Server-Timing
X-Dns-Prefetch-Control
X-UA-Device
Request-Context
Keep-Alive
X-AH-Environment
X-Amz-Request-Id
X-Turbo-Charged-By
X-Proxy-Cache
X-Backend
X-Amz-Id-2
X-Age
Host-Header
X-Ws-Request-Id
X-Hacker
X-Server-Powered-By
X-Server
X-Rq
X-Vhost
X-LiteSpeed-Cache
X-Varnish-Cache
X-Amz-Version-Id
Grace
EagleId
X-Dispatcher
Cf-Edge-Cache
Allow
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
X-Page-Speed
X-Nginx-Cache-Status
X-Swift-CacheTime
X-Swift-SaveTime
X-WebKit-CSP
Ali-Swift-Global-Savetime
X-Aws-Lambda-Call-Status
Accept-CH
X-Host
X-Node
Cf-Railgun
X-Pingback
X-Cache-Spec
X-Server-Id
X-OneAgent-JS-Injection
Surrogate-Control
X-Backend-Server
X-Akam-SW-Version
Request-Id
X-Akamai-Path-Stats
EagleEye-TraceId
X-Response-Time
X-Cache-Lookup
X-Readtime
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Content-Location
Accept-CH-Lifetime
X-HW
X-Content-Security-Policy-Report-Only
X-Cloud-Trace-Context
X-Application-Context
Rating
X-Trace
Fastly-Restarts
X-WebKit-CSP-Report-Only
Accept-Ch-Lifetime
X-Clacks-Overhead
X-Nginx-Upstream-Cache-Status
X-Country
X-Oneagent-Js-Injection
X-Url
X-MS-InvokeApp
X-Amz-Server-Side-Encryption
X-Rack-Cache
X-Edge
X-TtlSet
X-PC
X-Vname
X-B3-TraceId
X-Ruxit-Js-Agent
Edge-Control
X-Mod-Pagespeed
X-CST
X-Content-Type
X-Vcap-Request-Id
X-ESI
X-FastCGI-Cache
X-Mcache
X-D2id
Verso
Xkey
X-Kinja-Revision
X-Cdn-Fetch
X-Use-Magma
X-Kinja-Server
X-Kinja
X-Exp-Variant
X-Exp-Id
X-Kinja-Build
X-GoogleNews-Bot
X-GitHub-Request-Id
Cache-Tag
X-Amz-Rid
Service-Worker-Allowed
X-Powered-By-Plesk
RTSS
X-Varnish-TTL
X-VARITI-CCR
X-Ruxit-JS-Agent
X-Navigation-Version
X-ECACHE
X-Version
X-Abt-Application-Version
X-Upstream
X-Client-IP
Cf-Apo-Via
X-Cached
X-Ac
X-Cnection
X-Server-Name
X-Element-Page-Cache
X-Dw-Request-Base-Id
Arr-Disable-Session-Affinity
X-Ttl
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-Instrumentation
X-SharePointHealthScore
SPRequestGuid
Permissions-Policy
X-Px
SPIisLatency
SPRequestDuration
Public-Key-Pins
Pagespeed
Display
X-Sol
X-Middleton-Display
X-Country-Code
X-Cache-TTL
X-NWS-LOG-UUID
Response
X-Middleton-Response
X-RateLimit-Remaining
X-Ser
Accept-Ch
X-Kinsta-Cache
X-Edge-Location-Klb
X-Midtier
X-Goog-Hash
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Cache-Key
X-Forwarded-For
Content-MD5
X-NF-Request-ID
Access-Control-Request-Method
X-Correlation-Id
X-MSEdge-Ref
Front-End-Https
X-Shield-Request-Id
X-DataDome
X-Recruiting
X-ORACLE-DMS-ECID
X-T
X-ORACLE-DMS-RID
TP-L2-Cache
TP-Cache
Edge-Cache-Tag
AR-Request-ID
AR-PoweredBy
AR-CACHE
AR-ATIME
AR-SID
Mrf-Cache-Status
MRF-Tech
X-B3-TraceId-Primal
X-HP-Webp
X-Jurisdiction
X-HP-Trace-Id
MicrosoftSharePointTeamServices
Nginx-Cache
X-Accel-Expires
X-RateLimit-Limit
X-Daa-Tunnel
X-Mg-S
X-Powered-CMS
X-Grace
X-Content-Digest
X-Hits
TCN
X-Request-Processing-Time
X-Request-Received
Filters
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Browser-Type
X-Amzn-Trace-Id
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-HS-Combine-CSS
X-HS-Content-Id
X-HS-Cache-Config
X-Id
X-HS-Hub-Id
Server-Node
Server-Name
MS-Author-Via
Fastcgi-Cache
X-Geo-Country
X-Webkit-Csp
X-PressLabs-Stats
X-Fastly-Request-Id
X-Frontend
X-Distributor
Count-Hit
X-Origin-Server
X-XRDS-Location
X-Ezoic-Cdn
X-Ua-Browser
S
X-Protected-By
X-Ab
Filterid
X-Amz-Meta-S3cmd-Attrs
Cross-Origin-Opener-Policy
X-LLID
X-Forwarded-Proto
X-F-Cache
Cache-Status
X-ASPNET-VERSION
X-LB-Cache
X-FB-Debug
Charset
Payment
X-B3-Sampled
X-Request-Handler-Origin-Region
X-Microsite
X-Seen-By
X-Ratelimit-Reset
X-Git-Hash
Host
X-Page-Id
X-Language
X-Cluster-Name
X-VCache
Surrogate-Key
X-Rid
X-Www-Served-By
X-Cdn
Cache-Tags
Realpath
X-Fastcgi-Cache
Accept-Charset
X-Logged-In
X-TTL
Retry-After
Access-Control-Allow-Method
X-Upgrade-Enabled
X-Cache-Age
X-Source
X-Origin-Cache
Alternate-Protocol
X-NGENIX-Cache
X-DIS-Request-ID
X-Az
X-AppVersion
X-Activity-Id
X-Varnish-Backend
X-Type
DC
X-Amz-Replication-Status
Paypal-Debug-Id
X-Wix-Request-Id
X-TT
X-Tb
X-Route-Name
ServerID
X-Envoy-Decorator-Operation
X-B-Cache
X-Flags
X-Is-Crawler
Cleartype
X-Request-Guid
X-Providence-Cookie
X-Signature
X-Aspnet-Duration-Ms
X-B
X-Varnish-Grace
X-App-Environment
X-Template
X-Hostname
X-Revision
X-Node-Name
X-DynaTrace
Frame-Options
X-Contextid
X-Drupal-Cache-Tags
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Cache-Rule
Pinterest-Version
X-Pinterest-Rid
Pinterest-Generated-By
X-Proxy
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Debug
X-Goog-Generation
X-Goog-Metageneration
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-GUploader-UploadID
Refresh
X-Mobile
X-Fastly-Request-ID
X-Load-Cache
X-Content-Options
X-EdgeConnect-Cache-Status
X-N
X-XRDS-LOCATION
X-Cache-Control
Node
Country
Amp-Access-Control-Allow-Source-Origin
X-Magnolia-Registration
Referer-Policy
Cross-Origin-Resource-Policy
X-Response-Served-From
X-Original-Request-Id
NGB
Akamai-GRN
X-Debug-IsConnected
X-Debug-IsPreview
X-Varnish-Age
Access-Control-Request-Headers
X-Varnish-Server
X-L-Path
X-Content-Powered-By
X-Environment-Context
X-Cache-TTL-Remaining
Content-Disposition
X-Instance
X-Status
X-NYM-Debug-Backend
X-Adobe-Loc
X-Adobe-Content
X-Cacheable-TTL
X-Is-Bot
X-Cache-Grace
X-G
X-COUNTRY
X-Yottaa-Optimizations
VIX-Pulpo-Upstream-Status
X-Rendered-As
X-Cache-Time
X-Servername
Viewport
X-Real-IP
X-Page-View
VIX-Pulpo-Node
X-Yottaa-Metrics
X-Akamai-Request-ID2
X-Jobs
Uber-Trace-Id
Url
X-Framework
X-Mid
X-RemovedCookies
X-Whom
X-ProcessESI
X-User-Agent
Srv
X-Unique-Id
Countrycode
X-Trace-Id
X-Via-JSL
X-URL
X-Drupal-Cache-Contexts
X-Cache-Expired-At
X-CDN-Forward
X-Time
X-Cache-Hit
Version
X-Tumblr-User
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-Tumblr-Pixel
Accept-Language
X-Ratelimit-Remaining
X-Mg-Request-UUID
X-Cache-Operation
X-Content
X-Litespeed-Cache
X-Http-Reason
X-Api-Version
X-APP-VERSION
X-Oracle-Dms-Ecid
X-Rule
X-Oracle-Dms-Rid
Healthy
X-Backend-Name
Protected
X-App-Server
X-Server-ID
X-Cache-Action
Section-Io-Cache
X-Restarts
X-IPLB-Request-ID
X-IPLB-Instance
Content-Secure-Policy
X-Azure-Ref
X-Akamai-Edgescape
X-Debug-Info
X-Hosted-By
X-VC-Cache
X-Generation-Time
Server-Info
Backend
X-SRV
GEO-INFO
Xserver
X-FW-Dynamic
X-FW-Hash
Load-Balancing
X-RN-RSRV
X-FW-Serve
X-FW-Type
X-FW-Server
X-Nginx-Cache-Key
X-Tt-Logid
X-Device-Type
X-UPSTREAM-Address
X-Storage
X-Mobile-URL
Liferay-Portal
X-FW-Static
Meta-Geo
Onion-Location
X-HTML-Minification-Powered-By
X-Generated-By
CF-IPCountry
X-Locale
Azure-RegionName
Azure-SiteName
Azure-SlotName
Azure-Version
X-OCL
S-Rt
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Cms-Context
X-FireWall-Port
X-Format
X-Mode
X-Handled-By
X-Access
Azure-InstanceId
X-PCL
Ms-Operation-Id
MS-CV
Eomportal-Instance
X-Section
X-RTag
Locale
TWC-Privacy
X-SaId
TWC-Locale-Group
X-Say-Cacheable
X-PHP-Host
Webcakes-App-Version
X-Say-TTL
TWC-GeoIP-LatLong
Webcakes-App-Name
Webcakes-Region
TWC-Connection-Speed
X-Redis-Cache
X-Proto
X-Proxy-Cache-Status
Property-Id
CDN-RequestId
X-Region
X-ShardId
X-Shopify-Stage
TWC-Device-Class
X-SayCDN-TTL
CDN-Uid
X-ShopId
TWC-GeoIP-Country
X-Sorting-Hat-PodId
CDN-Cache
Cache-Name
X-Edge-Location
X-Forwarded-Host
X-Varnish-Beresp-Grace
X-Varnish-Cache-Hits
X-R9-Blue-Green-Version
X-Cache-Host
X-Alternate-Cache-Key
X-Cache-Server
X-Origin-Hint
X-Content-Age
X-JoinUs
X-Adobe-Source
X-Sql-Count
X-Sql-Duration-Ms
X-Sorting-Hat-ShopId
Web-Mar-Node
X-Skip-Cache
CDN-RequestCountryCode
CDN-PullZone
CDN-CachedAt
CDN-EdgeStorageId
X-Labrador-Cache-Channel
X-Urbn-Context-Path
X-Site-Version
X-Urbn-Site-Id
X-PHP-Backend
X-Routing-Service
X-Proxied
X-Ratelimit-Limit
X-VWS-Id
X-Server-W
Apigw-Requestid
X-Cache-Status-Check
X-Varnish-Hostname
X-Extlb
X-GeoCode
X-GeoCountry
X-Detected-As
X-No-Session
X-Cache-Type
X-Varnishpool
X-Storefront-Renderer-Rendered
X-LJ-Flow-ID
X-Xfnlog-Site
X-Zipkin-Id
X-Web-Node
X-AWS-Id
X-Via-Fastly
X-ProxyCache-Key
X-BYPASS-REASON
X-Timing-Wait
X-Request-Time
X-Proxy-Build
X-ProxyCache-Status
X-ECache
X-UA-Device-Type
Selected-Fe
X-Hl-Ver
Mn-Server-Ip
X-Tid
WP-Super-Cache
X-Cache-Enabled
X-DynaTrace-JS-Agent
X-Uri
X-Ms-Request-Id
X-Provided-By
X-Ms-Version
X-WP-CF-Super-Cache-Cache-Control
Fastcgi-Useragent
DB-Nickname
X-WP-CF-Super-Cache
X-ServerID
X-FB-TRIP-ID
X-Varnish-Ttl
X-Nginx-Cache
X-Cache-NGX
X-TNCMS
X-Amzn-Remapped-Content-Length
X-Datadome
X-Ua
X-Loop
X-Dc
Xet-Cookie
X-Origin-Date
X-UUID
X-Vgn-Hpd-Reason
X-Pubstack
X-Reqid
X-LSADC-Cache
X-Correlation-ID
X-Aspnetmvc-Version
X-App-Version
X-Soup
X-Zen-Fury
X-Tumblr-Pixel-2
X-Webkit-CSP
ServedBy
X-Newrelic-Synthetics
X-MP-GENERATED-AT
X-Service
X-Human
Origin
X-Origin-TTL
X-Origin-CC
Source
X-TA-CDN-Provider
From-Origin
Cache
X-Varnish-Hits
X-Cache-Debug
X-GEO
X-RCS-CacheZone
X-Cache-Tags
X-Cached-By
Cross-Origin-Window-Policy
X-TIME
X-Tec-Api-Origin
X-Tec-Api-Root
X-Varnish-Beresp-Ttl
X-Tec-Api-Version
WPO-Cache-Status
WPO-Cache-Message
X-Debug-Cache
LB
X-B3-Traceid
X-NewRelic-App-Data
Rip
SD-X-WS
X-ScT
MD5-Digest
BehaviorPad-Version
Rendered-Blocks
Host-ID
Fastly-Drupal-HTML
X-Request-Host
X-Aed
X-Cache-NE
X-D
X-Connection-Hash
X-B-Cookie
Cdnsip
X-Application
X-Orig-Expires
Lang
X-Bc-Bl
X-ARC
X-BCube-Filmed-By
A
X-A-Dam
X-A-Dcw
X-Forwarded-Path
X-A-Ccd
VNS-Age
X-NAPM-TraceId
X-A
X-A-Dgt
X-A-Wwc
X-Ec-Fail
X-Developer
Cdncip
X-Ec-GeoHdr
X-External-Request-Id
VNS-Cache
X-Destination
X-Processor
X-Vdms-Version
Surrogated-Key
X-Vdms-Path
Ngx.Var.Host
T-Server
X-User
X-S-Cookie
X-Shop-Environment
Environment
X-Tenant
X-TIM-N
Odigeo-Trace-Id
X-SRCache-Key
Expiry
Sslversion
X-Rojux
X-S
Meta-Geo-Continent
X-PBS-Appsvrname
Xc-Version
X-Parent-Response-Time
X-VG-WebCache
X-AK-Request-ID
CPC-Age
CPC-Cache
DCR-Decision-By
DCR-Processing-Time-Ms
X-Rewrite-Enabled
Redirect-Candidate
X-Cluster
X-Owner
X-Accel-Buffering
Upgrade-Insecure-Requests
X-Nyt-Route
X-Origin-Time
X-Gdpr
X-Dispatcher-Number
X-Aicache-OS
Webserver
X-FW-Version
X-AOL-HN
X-Served-From
AKAMAI
Fastly-Backend-Name
Server-Host
X-Developers
X-Has-Esi
X-WP-CF-Super-Cache-Active
X-Is-Gdpr
X-INCAP-ABP
X-HS-Content-Campaign-Id
TDXMobile
Thinkindot-CacheControl
X-Generated-On
X-Cdn-Srv
X-CMSURLCustom
X-Geo-Header
X-Auto-Login
X-Level-Front-Cache
Thinkindot-CacheControl-Type
Thinkindot-Control
X-Core-Value
X-JWT-State
Mime-Version
X-Sucuri-ID
WebServer
X-Sucuri-Cache
OT-Force-Account-Verify
X-Thinkindot-L3
X-Worker
Servername
Req-Svc-Chain
Origin-EX
Platform
Producers
X-Ad-Defer-Variation
Machine
Web-Mar-Region
Origin-CC
Vix-Hermes-Req-Id
NGX
Tube-Get-Contents
Tube-Got-Eval
Release
Mobile-Detection-Method
Tube-Return
Tube-Got-Results
Svr
Traceparent
V-Age
State
X-Optimistic-Header
X-SB
X-S-Maxage
X-Scale
X-Scheme
X-Slack-Backend
X-SIPLIST1
X-Rocket-Nginx-Serving-Static
X-Request-URI
X-Proxy-Cache-Info
X-Platform-Server
X-Qloud-Router
X-RateLimit-Limit-Second
X-Region-Sid
X-RateLimit-Remaining-Second
X-Sn-Servicetimems
X-SVT-ORM-RULES
X-VG-TLSProxy
X-Varnish-Remaining-TTL
X-Viewer-Country
X-VServer
X-Wix-Viewer-Type
X-WADP-Cache
X-Varnish-CookieINHashed-On
X-Varnish-CookieHashed-On
X-Thanos
X-SVT-ORM-VERSION
X-Var-Ttl
X-Variation
X-Varnish-Beresp-Status
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-Clientip
X-Clara-WADP
X-Core-Mission
X-DefElseHash
X-DPWN-IS-SECURE
X-DefHash
X-Cdn-Origin
X-Cache-Info
X-BBC-Edge-Cache-Status
X-Azure-Ref-OriginShield
X-Bip
X-Cache-Bucket
X-Cache-Id
X-Ec-Custom-Error
X-Epic-Correlation-Id
X-Minions-Version
X-Loc
X-NCache
X-Origin
X-Planisys-CDN-Cache
X-Origin-Response-Time
X-Gzip
X-GeoIP-City
X-Fastly-Backend
X-Esi-Check
X-Fmm-Version
X-Forwarded-Site
X-Gamma-Serve
X-ATG-Version
X-NodeID
Cmstype
Cmsid
Cluster
Country-Code
Decoy-Debug-Key
Fastly-GeoIP-CountryCode
DSUID
Decoy-Debug-Status
CloudFront-Viewer-Country
Click-Count-Error
Apple-News-Services-Host
Apple-News-Services-Handled
Adler-Geo
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
Click-Count-Action-Start
Candidate-Md5Url
Fastly-SIE
Decoy-Debug-TTL
Gh-Request-Id
IsBot
Is-Eu
Fastly-SSL
X-IPS-LoggedIn
Fastly-SWR
X-Cache-Remote
X-B3-SpanId
X-Esi
X-CacheTTL
X-Cluster-Node
X-Device-Os
Wxu-Next-Commit
X-Mvc-Supplant-Cachable
X-Policy
Wxu-Next-Region
X-Branch-Name
Wxu-Next-Hostname
X-Hnp-Log
X-Irp-Debug
X-Udemy-Cache-App-Namespace
X-Block-Status
X-Gen-Mode
Datacenter
X-CSRF-Token
X-Csrf-Jwt
X-Datadog-Parent-Id
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
X-Fetched-On
Kp-EeAlive
X-Pool
X-CGP
Memcached
X-FC-Vary-Parameters
HostName
X-Eu-Site
NM-Fastcgi-Cache
X-Ckpd-Fst-Backend
X-V-Cache
Sever-Int
X-SplitTest
User-Cache-Control
CDCHOST
Server-Hostname
X-Gateway-Cache-Key
L
Mail-Subject
L5d-Success-Class
HA-Ipaddr
Ha-Gx-Prefs
We-Hiring
Server-Ext
X-Gateway-Skip-Cache
X-GeoIP
X-Hash
X-Rocket-Build-Number
X-Gateway-Request-Id
X-Sigma
X-Gateway-Cache-Status
Cache-Host
X-Sigma-Backend
X-VC
X-Trace-ID
X-Newrelic-App-Data
AMP-Access-Control-Allow-Source-Origin
X-ND-Cache
Sid
X-Mvc-Supplant-OutputCached
Canary
X-LB-NoCache
Ec-Rule-Version
X-Nf-Request-Id
X-Via-NSCOPI
X-Tx-Id
X-Pass-Why
X-GG-Cache-Date
X-Up
Pics-Label
X-WA-Info
Cache-Tv-Group
X-Tumblr-Pixel-3
Memory
Time
Request-ID
Fastcgi-Cache-TTL
X-Tb-Optimization-Total-Bytes-Saved
X-Dispatch
X-Refresh
X-ZONE
Cache-Hits
X-Session-Fingerprint
X-Via-Popn
X-Via-Popv
X-Via-Poph
Ssr
X-Cs
X-Origin-Expires
X-Lambda-Id
X-Akamai-Transformed
X-Edge-Pop
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
My-App
X-Pod-Name
X-Release
Server-ID
X-Fastly-Cache
SID
Env
X-Generated-In
X-Servedbyhost
X-CACHE-AGE
X-Zone
X-Wa
X-CACHE-KEY
X-Presslabs-Stats
X-Req
X-PX
X-Fpc
X-LB-ID
X-ID
GeoIp-Country-Code
X-TX-ID
X-NWS-UUID-VERIFY
X-DC
X-Xrds-Location
True-Client-IP
X-Cache-Date
X-Ig-Push-State
CacheControlHeader
True-Client-Country-4JS
CDN
X-Buckets
X-EC-Lua
X-Conf
X-Endurance-Cache-Level
X-B3-Spanid
X-MSEdge-Flight
X-MSEdge-Features
X-Vc
X-NC
X-NGINX-Cache
Hostname
X-CSRF-TOKEN
X-Microcachable
X-Webkit-CSP-Report-Only
X-TH-Server
Tcn
X-VCL-Version
X-Op-Id-All
X-Dmc
X-TRACE-ID
X-CS
X-HS-Status
X-GeoIP-Country-Code
X-GeoIP-Region-Code
Fastly-Drupal-Html
X-Date
X-Vcl-Version
Magicmarker
WWW-Authenticate
Resin-Trace
X-Accel-Expires-Debug
X-Srv
X-RAMCache
X-MCACHE
X-RateLimit-Reset
X-Check-Cacheable
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-Be
X-Vercel-Cache
X-Vercel-Id
Path
X-Old-Content-Length
X-Varnish-Beresp-TTL
Powered-By
X-Datacenter
X-Hyper-Cache
Section-Io-Id
True-Client-Ip
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
X-FPC
X-Akamai-Pragma-Client-IP
X-Alfa-Service
Pramga
X-Geo
X-LiteSpeed-Cache-Control
X-Cache-Ttl
Yjs-Id
X-CLOUD-TRACE-CONTEXT
X-CF-Lambda-Version
Proxy-Connection
X-Micro-Cache
X-WA
GeoIP-Country-Code
X-CF-Lambda-Fn
X-M-Log
X-M-Reqid
X-Mly-Id
X-Location
X-Qnm-Cache
X-App
X-Webstats-RespID
X-Via-CDN
FSS-Cache
ENV
Tracecode
X-ServedByHost
X-Varnish-Authentication
X-Edge-POP
X-Contensis-Viewer-Groups
X-Air-Hostname
X-Air-Trace-Id
X-Air-Source
X-API-Version
X-Cache-ASPX
YJS-ID
X-Response-By
X-Air-Pt
X-Akamai-ERRuleID
C-Via
User-Agent
Server-Id
Lb
X-Akamai-ERPolicy
X-Lb-Id
X-TT-LOGID
X-Director
X-Cdn-Forward
X-Server-IP
X-Platform-Processor
X-Client-Ip
HIT
N-Cache
X-Via-PopN
X-TrackingId
X-Via-PopV
X-Via-PopH
X-Platform-Cluster
X-Platform-Router
Cdn
X-AIR-PT
X-Dw-Trace-Id
X-Service-Response-Time
X-SERVER-NAME
Sm-Log-Id
X-DataCenter
X-Test
X-Traceid
X-HA-Backend
X-PAYTM-SRV-ID
Uri
Location
X-Instance-Name
X-FORWARDED-FOR
X-LiteSpeed-Tag
X-FL-EDGE
Dnion-Transfer-Encoding
Geoip-Latitude
X-Platform
X-From
Esi-Enabled
X-UA
Swift-Performance
X-Li-Fabric
Fastcgi-X-Cache-Version
Srvid
Locid
NtCoent-Length
Hit
X-LI-UUID
On-Server
X-Li-Pop
X-LI-Proto
X-DSS
Ohc-File-Size
M-TraceId
X-RSL
X-CUA
X-DB
X-RPS
X-Cache-Expires
X-DI
PICS-Label
XServer
X-DW
X-Cache-Backend
Nginx-CQVIP
X-RPM
X-Edge-Origin-Shield-Region
X-Litespeed-Cache-Control
X-Edge-Origin-Shield-Bytes
X-Wp-Cf-Super-Cache-Cache-Control
X-Cc-Via
X-Wp-Cf-Super-Cache
X-Conten-Type-Options
X-We-Are-Hiring
X-Cache-Proxy
Vha6-Origin
X-Fastly-Cache-Hits
GeoIP-Latitude
X-Vtex-Processado-Em
X-Request-Url
X-Vtex-Remote-Cache
X-B3-ParentSpanId
X-Fastly-Backend-Reqs
X-Node-Id
X-Cdn-Request-ID
Wpo-Cache-Status
X-Lb-Nocache
X-HostName
Wpo-Cache-Message
X-CF-Powered-By
X-Cache-Ngx
CountryCode
Wp-Super-Cache
Warning
X-Ips-Loggedin
X-Loadbalancer
X-LbNode
X-Matched-Rule
X-Matome-Cached
X-MTS-Cache
X-Keep
X-Kebabable
X-IBD-SID
X-Is-SSL
X-Ittl
X-Kebab
X-Onedio-Env
X-Okws-Version
X-NXG
X-NFL-Dma
X-Ntj-Investigation-Id
X-IBD-Cache
X-NS-Authorization
X-Nyt-Data-Last-Modified
X-Newegg-Index
X-Odoo-Frontend
X-N-OperationId
X-Nerd
X-Newegg-Flow
X-NFL-Geo
X-Fastly-Is-Edge
X-Ee-Origin
X-Ee-Generated-By
X-Ee-Request-Date
X-Ee-Request-Id
X-Eid
X-Edge-IP
X-DT-Node
X-Dehri-Date
X-Dcm-Pdtf
X-Delivery
X-Developed-By
X-Doge
X-ETag
X-Eventloop-Lag
X-Git-Commit
X-GG-Cache-Status
X-Global-Transaction-ID
X-GoCache-CacheStatus
X-Group
X-Full-Ttl
X-Fstrz
X-F-Status
X-Farm
X-Origin-Ops
X-Frame-Option
X-Header-Sub
X-Reboot
X-Utime
X-User-Auth
X-V2-Infrastructure
X-Vary-Devices
X-Ver
X-Upstream-State
X-U-Cache
X-Toujours-Debout-Branch
X-Timestamp
X-Toujours-Debout-Location
X-Tried-To-Kebabify
X-True-Client-Ip
X-Wag-Acs
X-Waitingroom
Timeexpire
XV-H
X-ApacheServer
X-B3-Parentspanid
X-PERF
XV-Cache
X-YSpaceId
X-Web-Hosting
X-WP-Bypass
X-WSR2
X-Xms-Page-Cache-Actions
X-Test-Nginx-Ingress
X-Svr-Proxy
X-Render-Method
X-Redis
X-Render-Time
X-Request-Origin
X-Route
X-R-Cache
X-Pver
X-PageType
X-OVcl-Cache
X-Paywall
X-PG-ACCESS
X-PGF-Deflate
X-Route-Akamai
X-Ruby
X-Square
X-SMP-JWT
X-SSLProxy
X-Stack-Name
X-SVR-IIS
X-Slack-Shared-Secret-Outcome
X-Site
X-Save-Cache
X-Server-L
X-ServiceName
X-Sh
X-OVcl
X-Cache-ReqUri
NB-ESI
Joe-X
Nikkei-App-Version
NLCacheNote
Npm-Cost
Is-Https
HTTPProtocol
Deeplink
CMS-200
Ec-Policy-Id
H1
HServer
Npm-Remaining
Ns
Region
RawURL
Request-Uuid
Rt-Proxy-Cache
Scheme
Proxy-Cache
Panzer-Cache-Control
Ok-Cache-Status
Ns-Ua
OK-Edge-Date
Ok-Edge-Key
Origin-Site
Cluster-Host
Cf-Wrk
X-Moov-T
X-Moov-Xdn-Version
X-ElasticPress-Query
X-Yottaa-OS
CF-Cached-On
X-Request-Start
X-Mg-Cache
DynaTrace
SRV
WZWS-RAY
Fastcgi-Cache-Ttl
Req-ID
X-SD-PageType
X-IN-APIGATEWAY
Cachekey
Cache-Stat
Cdn-Country-Code
Cf-Device-Type
Cf-Locale
Akamai-X-Url
X-Th-Server
X-IN-APIGATEWAYSSL
X-LAGOON
Cneonction
X-Serial
Selected-Route
Served
X-Backend-TTL
X-AspNetWebPages-Version
X-Backside-Transport
X-BeanStalkRole
X-BeanStalkStage
X-ASF-Cache
X-ARRRG1
X-Amz-Meta-Cb-Modifiedtime
X-Akamai-Native
X-Apache-Server
X-Ar-Stats
X-Arena-Request-Id
X-Cache-Cookie
X-Cache-IsMobileDevice
X-Cf-Node-Idx
X-CDN-Pop-IP
X-Cms-Device
X-Coindesk-Cache
X-Colour
X-CDN-Pop
X-CacheVersion
X-Cache-Length
X-Cache-NPR
X-Cache-Reason
X-Cache-Response
X-Akamai-DeviceType
X-Akamai-DeviceOS
Time-Cloud-Cache
Technodrome
Ttl
TWC-AK-Req-ID
TWC-PATH-LOCALE
T-Request-Id
Sw
SFRVia
Service-Uuid
Shieldsquare-Response
SII
Store-Cloud-Cache
TWC-Subs
TWC-Unit
X-Accepted-Language
X-Accepted-Fulllang
X-Accor-Asset
X-AEO-Platform
X-Akamai-CacheKeyMod
X-Accel-Version
X-77-NZT-Ray
Uniqueid
Userver
Vttl
X-77-NZT
X-Container-Uri