Threat Level: green Handler on Duty: Guy Bruneau

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
Strict-Transport-Security
X-Frame-Options
X-Content-Type-Options
Last-Modified
Link
CF-Cache-Status
Cf-Request-Id
CF-RAY
Accept-Ranges
ETag
Expect-CT
Pragma
X-Powered-By
X-Cache
Via
Age
X-XSS-Protection
Content-Security-Policy
Report-To
NEL
X-Xss-Protection
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-FRAME-OPTIONS
X-Served-By
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-Adblock-Key
X-AspNet-Version
X-Permitted-Cross-Domain-Policies
Alt-Svc
X-Runtime
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Cache-Status
X-Check
X-Generator
X-DNS-Prefetch-Control
X-Request-ID
X-Cacheable
X-Iinfo
P3p
X-Envoy-Upstream-Service-Time
Timing-Allow-Origin
Feature-Policy
X-Content-Security-Policy
Status
X-Drupal-Dynamic-Cache
Content-Encoding
Access-Control-Expose-Headers
X-AspNetMvc-Version
X-CDN
Upgrade
X-Ua-Compatible
Access-Control-Max-Age
CF-Ray
X-Dns-Prefetch-Control
X-Via
X-Robots-Tag
X-Cache-Group
Server-Timing
X-UA-Device
Request-Context
Keep-Alive
X-AH-Environment
X-Amz-Request-Id
X-Turbo-Charged-By
X-Proxy-Cache
X-Backend
X-Amz-Id-2
X-Age
X-Ws-Request-Id
Host-Header
X-Hacker
X-Server-Powered-By
X-Server
X-Rq
X-Vhost
X-LiteSpeed-Cache
X-Varnish-Cache
X-Amz-Version-Id
Grace
Cf-Edge-Cache
X-Dispatcher
EagleId
Allow
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
X-Page-Speed
Accept-CH
X-Nginx-Cache-Status
X-WebKit-CSP
X-Swift-SaveTime
X-Swift-CacheTime
X-Aws-Lambda-Call-Status
Ali-Swift-Global-Savetime
Cf-Railgun
X-Node
X-Host
X-Pingback
X-Cache-Spec
X-OneAgent-JS-Injection
X-Server-Id
X-Backend-Server
X-Akam-SW-Version
Surrogate-Control
Request-Id
Accept-CH-Lifetime
X-Response-Time
X-Cache-Lookup
EagleEye-TraceId
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Readtime
Content-Location
X-HW
X-Content-Security-Policy-Report-Only
X-Cloud-Trace-Context
Rating
X-Application-Context
X-Trace
X-Akamai-Path-Stats
Fastly-Restarts
X-Url
X-Clacks-Overhead
X-WebKit-CSP-Report-Only
X-Nginx-Upstream-Cache-Status
X-Ruxit-Js-Agent
X-CST
X-Oneagent-Js-Injection
X-Country
X-MS-InvokeApp
X-Edge
X-Amz-Server-Side-Encryption
X-Rack-Cache
X-TtlSet
X-PC
X-Vname
Edge-Control
X-Content-Type
X-Mod-Pagespeed
X-ESI
X-B3-TraceId
X-Vcap-Request-Id
X-FastCGI-Cache
Cf-Apo-Via
X-D2id
X-Exp-Id
X-Kinja-Revision
X-Kinja
X-Exp-Variant
X-Use-Magma
X-Kinja-Server
Verso
X-GoogleNews-Bot
X-Kinja-Build
X-Cdn-Fetch
X-GitHub-Request-Id
Xkey
Accept-Ch-Lifetime
X-Ttl
X-Mcache
Cache-Tag
Service-Worker-Allowed
X-Powered-By-Plesk
X-Amz-Rid
RTSS
X-Navigation-Version
X-VARITI-CCR
X-Server-Name
X-Abt-Application-Version
X-Varnish-TTL
X-Upstream
X-Version
X-Ac
X-Client-IP
X-Cached
X-Cnection
X-ECACHE
X-Element-Page-Cache
X-Ruxit-JS-Agent
Arr-Disable-Session-Affinity
X-Instrumentation
X-Dw-Request-Base-Id
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
Permissions-Policy
X-RateLimit-Remaining
SPRequestGuid
X-SharePointHealthScore
X-Px
X-Sol
X-Middleton-Display
SPIisLatency
SPRequestDuration
Display
Pagespeed
X-Cache-TTL
Public-Key-Pins
X-Country-Code
X-NWS-LOG-UUID
Response
X-Middleton-Response
X-Midtier
X-Ser
X-Cache-Key
X-Edge-Location-Klb
X-Kinsta-Cache
X-Forwarded-For
X-Goog-Hash
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-DataDome
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
Content-MD5
X-Shield-Request-Id
X-MSEdge-Ref
X-NF-Request-ID
X-RateLimit-Limit
X-Correlation-Id
X-Jurisdiction
X-HP-Webp
X-HP-Trace-Id
Front-End-Https
Access-Control-Request-Method
AR-SID
AR-Request-ID
AR-CACHE
AR-PoweredBy
AR-ATIME
X-T
X-Recruiting
Mrf-Cache-Status
X-B3-TraceId-Primal
Edge-Cache-Tag
MRF-Tech
Nginx-Cache
TP-L2-Cache
TP-Cache
MicrosoftSharePointTeamServices
X-Daa-Tunnel
X-Accel-Expires
X-Mg-S
X-Erf-Bev-Bev-Is-Generated
X-Browser-Type
X-Erf-Bev-Bev
X-Content-Digest
X-Powered-CMS
TCN
X-Grace
X-Hits
X-Request-Received
X-Amzn-Trace-Id
X-Request-Processing-Time
Server-Name
Filters
X-HS-Hub-Id
X-HS-Cache-Config
X-HS-Content-Id
X-HS-Combine-CSS
Server-Node
MS-Author-Via
X-Id
Fastcgi-Cache
X-Geo-Country
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Webkit-Csp
X-TEC-API-VERSION
X-Fastly-Request-Id
X-Frontend
Count-Hit
X-XRDS-Location
X-PressLabs-Stats
X-Origin-Server
X-Distributor
X-Ezoic-Cdn
X-Ua-Browser
Filterid
Cross-Origin-Opener-Policy
X-Language
X-Protected-By
Charset
X-LLID
X-ASPNET-VERSION
X-FB-Debug
X-Request-Handler-Origin-Region
X-F-Cache
X-Microsite
S
Host
X-Git-Hash
X-Seen-By
X-Amz-Meta-S3cmd-Attrs
X-B3-Sampled
X-LB-Cache
X-Forwarded-Proto
Payment
X-Page-Id
X-Ratelimit-Reset
X-VCache
X-Cluster-Name
Cache-Status
X-Ab
X-Rid
Surrogate-Key
Cache-Tags
X-Www-Served-By
Access-Control-Allow-Method
X-Upgrade-Enabled
X-Logged-In
X-Source
Accept-Ch
X-Cache-Age
X-Origin-Cache
Realpath
Retry-After
Accept-Charset
X-Varnish-Backend
Alternate-Protocol
X-DIS-Request-ID
Cleartype
X-Type
X-AppVersion
Paypal-Debug-Id
X-Az
X-Template
DC
X-Amz-Replication-Status
X-Activity-Id
X-Varnish-Grace
X-App-Environment
X-Wix-Request-Id
X-Signature
X-Envoy-Decorator-Operation
X-Route-Name
X-Flags
X-B-Cache
X-Is-Crawler
X-Request-Guid
X-Providence-Cookie
X-Aspnet-Duration-Ms
X-Tb
X-B
X-NGENIX-Cache
X-TT
ServerID
X-Revision
X-Hostname
X-DynaTrace
X-Fastcgi-Cache
X-Kong-Upstream-Latency
Frame-Options
X-Kong-Proxy-Latency
X-Contextid
X-COUNTRY
X-Cache-Rule
X-Node-Name
X-Drupal-Cache-Tags
Pinterest-Generated-By
Pinterest-Version
X-Pinterest-Rid
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Proxy
Refresh
X-GUploader-UploadID
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
Cross-Origin-Resource-Policy
X-Goog-Storage-Class
X-Debug
Amp-Access-Control-Allow-Source-Origin
X-Fastly-Request-ID
X-Mobile
X-Content-Options
X-Load-Cache
X-EdgeConnect-Cache-Status
X-Trace-Id
Node
X-XRDS-LOCATION
Referer-Policy
X-Cache-Control
X-Original-Request-Id
X-N
X-Response-Served-From
Country
X-Varnish-Server
X-Varnish-Age
Akamai-GRN
X-Whom
NGB
Viewport
X-Magnolia-Registration
X-Instance
X-Cache-Time
X-Status
X-Debug-IsPreview
X-Debug-IsConnected
VIX-Pulpo-Node
X-Content-Powered-By
VIX-Pulpo-Upstream-Status
X-Servername
X-L-Path
X-Akamai-Request-ID2
X-Jobs
X-Real-IP
X-Cacheable-TTL
X-G
X-Cache-Grace
Uber-Trace-Id
X-Environment-Context
Access-Control-Request-Headers
Url
X-NYM-Debug-Backend
X-Rendered-As
X-Yottaa-Metrics
X-Framework
X-User-Agent
X-RemovedCookies
X-ProcessESI
X-Page-View
Content-Disposition
X-Yottaa-Optimizations
X-Mid
X-Is-Bot
X-Adobe-Content
X-Adobe-Loc
X-Cache-TTL-Remaining
Srv
X-Via-JSL
X-Cache-Expired-At
X-Unique-Id
X-Cache-Hit
X-Tumblr-Pixel
Countrycode
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-Tumblr-User
Healthy
X-Cache-Operation
X-TTL
X-Drupal-Cache-Contexts
X-CDN-Forward
X-Rule
Accept-Language
Version
X-APP-VERSION
X-Backend-Name
X-Litespeed-Cache
X-ECache
X-Cache-Action
X-Mg-Request-UUID
X-Akamai-Edgescape
X-Http-Reason
X-Debug-Info
X-Server-ID
Content-Secure-Policy
Section-Io-Cache
Protected
X-Varnish-Ttl
X-Time
X-Tt-Logid
X-IPLB-Instance
X-VC-Cache
X-Azure-Ref
X-Hosted-By
X-IPLB-Request-ID
Server-Info
X-Api-Version
X-Generation-Time
Backend
X-App-Server
X-HTML-Minification-Powered-By
X-Generated-By
Xserver
X-Oracle-Dms-Ecid
X-FW-Server
X-FW-Static
X-FW-Serve
X-FW-Dynamic
X-FW-Hash
X-Oracle-Dms-Rid
X-RN-RSRV
X-FW-Type
X-UPSTREAM-Address
X-Content
Meta-Geo
CF-IPCountry
X-Mobile-URL
X-Amz-Apigw-Id
X-Storage
Onion-Location
X-Amzn-RequestId
X-Cache-Status-Check
Azure-SlotName
X-Origin-Hint
X-SRV
TWC-GeoIP-Country
TWC-Device-Class
S-Rt
GEO-INFO
X-Section
X-Varnish-Cache-Hits
Azure-RegionName
TWC-GeoIP-LatLong
Azure-Version
X-Format
Azure-SiteName
X-Cache-Server
X-FireWall-Port
TWC-Connection-Speed
Webcakes-App-Name
X-Access
X-Restarts
TWC-Locale-Group
X-Locale
Azure-InstanceId
X-Handled-By
Webcakes-App-Version
TWC-Privacy
Property-Id
Webcakes-Region
Eomportal-Instance
X-Edge-Location
X-Say-TTL
X-SayCDN-TTL
X-Say-Cacheable
X-SaId
X-Region
X-Site-Version
X-Skip-Cache
X-Proto
X-Varnish-Hostname
X-Varnish-Beresp-Grace
X-Urbn-Site-Id
X-Redis-Cache
X-R9-Blue-Green-Version
Load-Balancing
Locale
X-Provided-By
X-PCL
X-OCL
Web-Mar-Node
X-Content-Age
X-PHP-Host
X-Labrador-Cache-Channel
X-JoinUs
X-Forwarded-Host
X-Cms-Context
X-Urbn-Context-Path
X-Device-Type
Ms-Operation-Id
X-Sql-Duration-Ms
MS-CV
X-Sql-Count
X-RTag
X-Cache-Type
Cache-Name
X-GeoCode
X-Adobe-Source
X-Server-W
X-GeoCountry
X-Web-Node
X-PHP-Backend
CDN-Cache
X-FB-TRIP-ID
CDN-RequestId
CDN-Uid
DB-Nickname
X-No-Session
CDN-RequestCountryCode
X-Cache-Host
CDN-CachedAt
CDN-EdgeStorageId
CDN-PullZone
X-Varnishpool
X-Via-Fastly
X-Sorting-Hat-PodId
X-ShopId
X-Sorting-Hat-ShopId
X-Shopify-Stage
X-UA-Device-Type
Liferay-Portal
X-Hl-Ver
Apigw-Requestid
X-Ms-Request-Id
X-Detected-As
X-Ms-Version
X-ShardId
X-Alternate-Cache-Key
X-Xfnlog-Site
Mn-Server-Ip
X-Request-Time
X-LJ-Flow-ID
X-Proxy-Cache-Status
WP-Super-Cache
X-Nginx-Cache-Key
X-ProxyCache-Status
X-AWS-Id
X-BYPASS-REASON
X-Storefront-Renderer-Rendered
X-DynaTrace-JS-Agent
X-VWS-Id
X-Mode
X-ProxyCache-Key
X-Proxy-Build
X-ServerID
X-Timing-Wait
X-Extlb
X-Zipkin-Id
X-Cache-Enabled
X-Proxied
X-Routing-Service
Selected-Fe
X-Dc
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
X-Vgn-Hpd-Reason
X-Cdn
X-Tid
X-Amzn-Remapped-Content-Length
X-Loop
X-TNCMS
X-B3-Traceid
X-Reqid
Xet-Cookie
X-Uri
X-LSADC-Cache
X-Pubstack
X-TIME
X-Ua
X-Soup
X-Origin-Date
X-Tumblr-Pixel-2
X-Tec-Api-Version
X-Zen-Fury
X-Correlation-ID
X-Ratelimit-Remaining
X-Tec-Api-Origin
X-Cache-NGX
X-Tec-Api-Root
X-Aspnetmvc-Version
Fastcgi-Useragent
X-Service
X-Nginx-Cache
X-Newrelic-Synthetics
From-Origin
X-Webkit-CSP
ServedBy
Source
X-MP-GENERATED-AT
X-Origin-TTL
Origin
X-Origin-CC
X-GEO
X-Cache-Debug
X-UUID
X-NewRelic-App-Data
X-TA-CDN-Provider
X-URL
X-Varnish-Hits
X-Human
X-App-Version
Cache
X-Cached-By
X-Cache-Tags
Cross-Origin-Window-Policy
X-Varnish-Beresp-Ttl
Fastly-Drupal-HTML
X-Ratelimit-Limit
Rip
Upgrade-Insecure-Requests
X-ScT
X-Rewrite-Enabled
BehaviorPad-Version
MD5-Digest
Rendered-Blocks
X-RCS-CacheZone
Host-ID
X-Cluster
WPO-Cache-Status
WPO-Cache-Message
X-A-Wwc
X-Ec-Fail
X-Orig-Expires
X-Ec-GeoHdr
X-Vdms-Path
X-VG-WebCache
X-A-Dcw
X-Forwarded-Path
X-A-Dam
X-A-Ccd
Xc-Version
X-A
X-A-Dgt
Cdncip
X-External-Request-Id
X-NAPM-TraceId
A
X-Rojux
Cdnsip
X-Vdms-Version
Surrogated-Key
X-Shop-Environment
X-Cache-NE
Meta-Geo-Continent
Expiry
Ngx.Var.Host
T-Server
X-Connection-Hash
X-BCube-Filmed-By
X-Bc-Bl
X-Application
X-S
X-AK-Request-ID
Lang
X-ARC
X-B-Cookie
X-S-Cookie
X-SRCache-Key
Odigeo-Trace-Id
X-D
X-TIM-N
X-Aed
X-User
X-Developer
X-Destination
X-Tenant
X-PBS-Appsvrname
SD-X-WS
X-Processor
X-Parent-Response-Time
DCR-Processing-Time-Ms
Sslversion
DCR-Decision-By
X-Request-Host
X-FW-Version
OT-Force-Account-Verify
X-Aicache-OS
X-Dispatcher-Number
Mime-Version
X-Accel-Buffering
VNS-Cache
X-Origin-Time
CPC-Age
X-Nyt-Route
CPC-Cache
Redirect-Candidate
Environment
X-Served-From
X-Gdpr
X-Owner
X-Debug-Cache
VNS-Age
Webserver
AKAMAI
Fastly-Backend-Name
X-Developers
X-JWT-State
X-Generated-On
X-Is-Gdpr
X-INCAP-ABP
X-Has-Esi
X-CMSURLCustom
Thinkindot-CacheControl-Type
Thinkindot-Control
X-AOL-HN
Thinkindot-CacheControl
X-WP-CF-Super-Cache-Active
X-HS-Content-Campaign-Id
X-Cdn-Srv
TDXMobile
Server-Host
X-Sucuri-Cache
X-Sucuri-ID
X-Cluster-Node
X-Thinkindot-L3
WebServer
X-Geo-Header
LB
X-Level-Front-Cache
X-Worker
Web-Mar-Region
Wxu-Next-Hostname
Kp-EeAlive
Wxu-Next-Commit
L
We-Hiring
Vix-Hermes-Req-Id
Memcached
NM-Fastcgi-Cache
Wxu-Next-Region
Mobile-Detection-Method
Platform
Mail-Subject
X-Ad-Defer-Variation
V-Age
Svr
Machine
X-Fetched-On
X-Planisys-CDN-Cache
X-V-Cache
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-SVT-ORM-VERSION
X-Pool
X-Variation
X-Varnish-Beresp-Status
X-Minions-Version
X-Loc
X-NCache
Is-Eu
X-Origin-Response-Time
X-SVT-ORM-RULES
X-Proxy-Cache-Info
X-Scheme
X-Region-Sid
X-S-Maxage
X-Request-URI
X-Rocket-Nginx-Serving-Static
X-Rocket-Build-Number
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-Slack-Backend
X-Sn-Servicetimems
X-Sigma-Backend
X-Sigma
X-Qloud-Router
X-Hash
X-Viewer-Country
X-Datadog-Parent-Id
X-Core-Mission
X-Datadog-Sampling-Priority
X-Datadog-Trace-Id
X-Ec-Custom-Error
X-Device-Os
X-Cdn-Origin
X-CacheTTL
X-Branch-Name
X-Azure-Ref-OriginShield
X-Cache-Bucket
X-Cache-Id
X-Cache-Info
X-GeoIP-City
X-Epic-Correlation-Id
X-GeoIP
X-Gateway-Skip-Cache
X-Gzip
X-Wix-Viewer-Type
X-VServer
X-Gateway-Request-Id
X-Gateway-Cache-Key
X-Fastly-Backend
X-Esi-Check
Release
Gh-Request-Id
X-Gamma-Serve
X-ATG-Version
X-Gateway-Cache-Status
Cluster
Decoy-Debug-Status
Adler-Geo
Datacenter
Apple-News-Services-Request-Url
Decoy-Debug-Key
Decoy-Debug-TTL
Apple-News-Services-Handled
CloudFront-Viewer-Country
Canary
Cache-Host
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
Fastly-SSL
Candidate-Md5Url
Fastly-GeoIP-CountryCode
X-Tumblr-Pixel-3
X-Core-Value
X-Auto-Login
X-Clientip
X-Mvc-Supplant-Cachable
X-DefElseHash
X-Irp-Debug
X-BBC-Edge-Cache-Status
X-Var-Ttl
IsBot
X-Thanos
X-Policy
X-Ckpd-Fst-Backend
X-Optimistic-Header
X-Clara-WADP
X-CGP
X-VG-TLSProxy
X-SB
X-Datadome
X-Platform-Server
X-Udemy-Cache-App-Namespace
X-Scale
X-SIPLIST1
X-Varnish-Remaining-TTL
X-Varnish-CookieINHashed-On
X-Varnish-CookieHashed-On
X-SplitTest
X-WADP-Cache
X-Origin
X-Bip
X-Csrf-Jwt
X-DPWN-IS-SECURE
X-Eu-Site
X-Fmm-Version
X-Forwarded-Site
X-NodeID
Ha-Gx-Prefs
HA-Ipaddr
L5d-Success-Class
X-DefHash
X-FC-Vary-Parameters
Cmstype
Req-Svc-Chain
Producers
State
Tube-Return
Country-Code
Tube-Got-Eval
Tube-Got-Results
Servername
Tube-Get-Contents
Traceparent
Cmsid
Fastly-SIE
Click-Count-Error
Click-Count-Action-Start
Fastly-SWR
Origin-EX
NGX
Origin-CC
DSUID
X-Cache-Remote
X-Tx-Id
X-Pass-Why
X-IPS-LoggedIn
Time
Ec-Rule-Version
X-CSRF-Token
Sid
Memory
X-Gen-Mode
X-Mvc-Supplant-OutputCached
Server-Hostname
Server-Ext
Sever-Int
X-Hnp-Log
X-Block-Status
CDCHOST
User-Cache-Control
X-Up
X-Nf-Request-Id
X-LB-NoCache
X-Dispatch
HostName
X-ZONE
X-Edge-Pop
X-VC
X-ND-Cache
X-Presslabs-Stats
Pics-Label
Request-ID
Ssr
X-Tb-Optimization-Total-Bytes-Saved
X-Akamai-Transformed
AMP-Access-Control-Allow-Source-Origin
My-App
X-Refresh
X-WA-Info
X-Via-NSCOPI
X-B3-SpanId
X-Cs
Cache-Tv-Group
X-Via-Popn
X-Via-Poph
X-Via-Popv
X-GG-Cache-Date
X-B3-Spanid
Env
Fastcgi-Cache-TTL
X-Lambda-Id
X-Newrelic-App-Data
Server-ID
X-Req
X-Generated-In
X-Servedbyhost
X-Session-Fingerprint
X-Trace-ID
X-NGINX-Cache
X-Wa
X-Origin-Expires
X-Fastly-Cache
Cache-Hits
SID
GeoIp-Country-Code
X-Release
X-Rebelmouse-Surrogate-Control
CacheControlHeader
X-Pod-Name
X-Rebelmouse-Cache-Control
X-PX
X-Vc
X-EC-Lua
X-CACHE-AGE
True-Client-IP
Hostname
X-Fpc
X-ID
True-Client-Country-4JS
X-Xrds-Location
X-CSRF-TOKEN
X-Op-Id-All
X-MCACHE
X-LB-ID
X-Zone
X-TX-ID
X-Webkit-CSP-Report-Only
X-NWS-UUID-VERIFY
X-TH-Server
X-GeoIP-Region-Code
X-MSEdge-Features
X-VCL-Version
X-GeoIP-Country-Code
X-Cache-Date
X-DC
X-MSEdge-Flight
X-Ig-Push-State
X-Buckets
X-CACHE-KEY
X-Accel-Expires-Debug
WWW-Authenticate
X-NC
X-Endurance-Cache-Level
CDN
X-HS-Status
X-Conf
X-Date
X-TRACE-ID
X-RAMCache
X-Microcachable
Resin-Trace
X-Srv
Fastly-Drupal-Html
X-Dmc
X-CS
X-Esi
X-Varnish-Beresp-TTL
X-RateLimit-Reset
Tcn
Powered-By
X-Old-Content-Length
X-Vcl-Version
Path
Magicmarker
X-Check-Cacheable
X-Wikidot-Static-Cache
True-Client-Ip
X-Webstats-RespID
Section-Io-Id
X-Wikidot-Backend
X-Location
X-FPC
Section-Io-Origin-Time-Seconds
X-Akamai-Pragma-Client-IP
Section-Io-Origin-Status
Section-Origin-Responded
X-Alfa-Service
X-LiteSpeed-Cache-Control
X-CLOUD-TRACE-CONTEXT
X-Cache-ASPX
X-Varnish-Authentication
Yjs-Id
X-API-Version
X-Contensis-Viewer-Groups
X-Be
X-Cache-Ttl
X-Datacenter
Proxy-Connection
GeoIP-Country-Code
X-Director
X-Vercel-Cache
X-Lb-Id
X-Vercel-Id
X-WA
X-DataCenter
X-Geo
FSS-Cache
Lb
X-Via-CDN
X-Mly-Id
Server-Id
Pramga
X-Micro-Cache
X-Hyper-Cache
X-Test
X-M-Log
X-CF-Lambda-Version
X-CF-Lambda-Fn
X-ServedByHost
ENV
X-M-Reqid
Cdn
X-Response-By
User-Agent
X-Server-IP
X-Dw-Trace-Id
X-Cdn-Forward
X-Via-PopH
X-Via-PopN
X-Client-Ip
X-Via-PopV
M-TraceId
X-Akamai-ERRuleID
X-Qnm-Cache
X-App
X-Cache-Expires
X-Cache-Backend
X-Akamai-ERPolicy
Uri
HIT
X-HA-Backend
Tracecode
Sm-Log-Id
X-AIR-PT
X-Edge-POP
X-Service-Response-Time
X-Cc-Via
XServer
YJS-ID
N-Cache
Srvid
X-FL-EDGE
X-We-Are-Hiring
X-From
C-Via
X-Air-Hostname
X-Air-Source
Swift-Performance
X-Air-Trace-Id
X-Traceid
X-Instance-Name
Locid
Geoip-Latitude
Dnion-Transfer-Encoding
X-TrackingId
X-LI-Proto
X-Li-Pop
X-TT-LOGID
X-Li-Fabric
X-UA
X-LI-UUID
X-LiteSpeed-Tag
Location
X-PERF
X-ApacheServer
X-RPS
X-RPM
X-DSS
X-DI
X-DW
Esi-Enabled
XM
Nginx-CQVIP
X-Air-Pt
X-Fastly-Backend-Reqs
CF-Cached-On
X-RSL
X-DB
Ohc-File-Size
X-Platform-Cluster
X-Platform-Processor
X-Platform-Router
CountryCode
PICS-Label
X-Platform
X-Wp-Cf-Super-Cache-Cache-Control
X-Wp-Cf-Super-Cache
Fastcgi-X-Cache-Version
Hit
NtCoent-Length
X-Cache-Proxy
X-Conten-Type-Options
X-Info
X-Frame-Option
Timeexpire
X-PAYTM-SRV-ID
PFcat
X-HostName
Wpo-Cache-Status
X-Lb-Nocache
X-Request-Url
Wpo-Cache-Message
X-Fastly-Cache-Hits
Vha6-Origin
X-Cdn-Request-ID
On-Server
X-CF-Powered-By
X-HN
X-VarnishDD-TTL
Warning
X-Cache-Ngx
X-Litespeed-Cache-Control
Wp-Super-Cache
X-Ips-Loggedin
X-NFL-Geo
X-Newegg-Flow
X-NFL-Dma
X-Newegg-Index
X-MTS-Cache
X-Matched-Rule
X-Loadbalancer
X-Matome-Cached
X-NS-Authorization
X-N-OperationId
X-Nerd
X-NXG
X-Onedio-Env
X-Paywall
X-Origin-Ops
X-OVcl
X-PageType
X-LbNode
X-Okws-Version
X-Ntj-Investigation-Id
X-OVcl-Cache
X-Nyt-Data-Last-Modified
X-Odoo-Frontend
X-PG-ACCESS
X-Header-Sub
X-Farm
X-F-Status
X-Fastly-Is-Edge
X-Fstrz
X-Full-Ttl
X-Eventloop-Lag
X-Ee-Request-Date
X-ETag
X-Eid
X-Ee-Request-Id
X-PGF-Deflate
X-GG-Cache-Status
X-Git-Commit
X-Is-SSL
X-IBD-SID
X-Ittl
X-Kebab
X-Kebabable
X-IBD-Cache
X-Group
X-Ee-Origin
X-Global-Transaction-ID
X-GoCache-CacheStatus
X-Ee-Generated-By
X-Keep
X-U-Cache
X-Waitingroom
X-Wag-Acs
X-Web-Hosting
X-WP-Bypass
X-WSR2
X-Ver
X-Vary-Devices
X-Upstream-State
X-True-Client-Ip
X-User-Auth
X-Utime
X-V2-Infrastructure
X-Xms-Page-Cache-Actions
X-YSpaceId
X-Oss-Hash-Crc64ecma
Cache-Key
X-Oss-Object-Type
X-Oss-Server-Time
X-Oss-Request-Id
X-Edge-IP
X-Oss-Storage-Class
XV-Cache
XV-H
X-B3-Parentspanid
X-Fastly-Country-Code
X-Tried-To-Kebabify
X-Toujours-Debout-Location
X-Route-Akamai
X-Route
X-Ruby
X-Save-Cache
X-Server-L
X-Request-Origin
X-Render-Time
X-R-Cache
X-Reboot
X-Redis
X-Render-Method
X-ServiceName
X-Sh
X-Svr-Proxy
X-SVR-IIS
X-Test-Nginx-Ingress
X-Timestamp
X-Toujours-Debout-Branch
X-Stack-Name
X-SSLProxy
X-Site
X-Slack-Shared-Secret-Outcome
X-SMP-JWT
X-Square
X-Pver
Rt-Proxy-Cache
Ns
Npm-Remaining
Ns-Ua
Ok-Cache-Status
OK-Edge-Date
Npm-Cost
NLCacheNote
Is-Https
HTTPProtocol
Joe-X
NB-ESI
Nikkei-App-Version
Ok-Edge-Key
Origin-Site
Service-Uuid
Served
SFRVia
Shieldsquare-Response
SII
Selected-Route
Scheme
Proxy-Cache
Panzer-Cache-Control
RawURL
Region
Request-Uuid
HServer
H1
X-ElasticPress-Query
X-Mg-Cache
X-Yottaa-OS
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
X-B3-ParentSpanId
WZWS-RAY
Req-ID
X-CUA
Fastcgi-Cache-Ttl
SRV
DynaTrace
Cneonction
X-Serial
Cluster-Host
Cf-Wrk
CMS-200
Deeplink
Ec-Policy-Id
Cf-Locale
Cf-Device-Type
Akamai-X-Url
X-Th-Server
Cache-Stat
Cachekey
Cdn-Country-Code
Store-Cloud-Cache
Sw
X-Cache-Length
X-Cache-IsMobileDevice
X-Cache-NPR
X-Cache-Reason
X-Cache-ReqUri
X-Cache-Cookie
X-BeanStalkStage
X-AspNetWebPages-Version
X-ASF-Cache
X-Backend-TTL
X-Backside-Transport
X-BeanStalkRole
X-Cache-Response
X-CacheVersion
X-Dehri-Date
X-Dcm-Pdtf
X-Delivery
X-Developed-By
X-Doge
X-Container-Uri
X-Colour
X-CDN-Pop-IP
X-CDN-Pop
X-Cf-Node-Idx
X-Cms-Device
X-Coindesk-Cache
X-ARRRG1
X-Arena-Request-Id
Uniqueid
TWC-Unit
Userver
Vttl
X-77-NZT
TWC-Subs
TWC-PATH-LOCALE
Technodrome
T-Request-Id
Time-Cloud-Cache
Ttl
TWC-AK-Req-ID
X-77-NZT-Ray
X-Accel-Version
X-Akamai-Native
X-Akamai-DeviceType
X-Amz-Meta-Cb-Modifiedtime
X-Apache-Server
X-Ar-Stats
X-Akamai-DeviceOS
X-Akamai-CacheKeyMod
X-Accepted-Fulllang
X-Accepted-Language
X-Accor-Asset
X-AEO-Platform
X-DT-Node