Threat Level: green Handler on Duty: Guy Bruneau

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
Strict-Transport-Security
X-Frame-Options
X-Content-Type-Options
Link
Last-Modified
CF-Cache-Status
Cf-Request-Id
CF-RAY
Accept-Ranges
ETag
Expect-CT
Pragma
X-Powered-By
X-Cache
Via
Age
X-XSS-Protection
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
X-Xss-Protection
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-FRAME-OPTIONS
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-Adblock-Key
X-AspNet-Version
X-Permitted-Cross-Domain-Policies
Alt-Svc
X-Runtime
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Request-ID
X-Cache-Status
X-Check
X-Generator
X-Cacheable
X-Iinfo
X-Envoy-Upstream-Service-Time
P3p
Timing-Allow-Origin
Feature-Policy
X-Content-Security-Policy
Status
X-Drupal-Dynamic-Cache
Content-Encoding
Access-Control-Expose-Headers
X-CDN
X-AspNetMvc-Version
Upgrade
X-Ua-Compatible
Access-Control-Max-Age
CF-Ray
X-Via
X-Robots-Tag
X-Cache-Group
Server-Timing
X-UA-Device
X-Dns-Prefetch-Control
Keep-Alive
Request-Context
X-AH-Environment
X-Amz-Request-Id
X-Turbo-Charged-By
X-Proxy-Cache
X-Backend
X-Amz-Id-2
X-Age
X-Ws-Request-Id
Host-Header
X-Hacker
X-Server-Powered-By
X-Server
X-Rq
X-Vhost
X-LiteSpeed-Cache
X-Varnish-Cache
X-Amz-Version-Id
Grace
Cf-Edge-Cache
X-Dispatcher
Allow
EagleId
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Device
Accept-CH
X-Page-Speed
X-WebKit-CSP
X-Nginx-Cache-Status
X-Swift-SaveTime
X-Swift-CacheTime
X-Aws-Lambda-Call-Status
Ali-Swift-Global-Savetime
Cf-Railgun
X-Node
X-Host
X-Pingback
X-Cache-Spec
X-OneAgent-JS-Injection
X-Backend-Server
X-Akam-SW-Version
Surrogate-Control
X-Server-Id
Request-Id
Accept-CH-Lifetime
X-Response-Time
X-Cache-Lookup
EagleEye-TraceId
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Readtime
Content-Location
X-HW
X-Cloud-Trace-Context
X-Content-Security-Policy-Report-Only
Rating
X-Application-Context
X-Trace
Fastly-Restarts
X-Url
X-WebKit-CSP-Report-Only
X-Clacks-Overhead
X-Akamai-Path-Stats
X-Nginx-Upstream-Cache-Status
X-Ruxit-Js-Agent
X-CST
X-MS-InvokeApp
X-Edge
X-Rack-Cache
X-Amz-Server-Side-Encryption
X-TtlSet
X-PC
X-Oneagent-Js-Injection
X-Vname
X-Country
X-Mod-Pagespeed
Edge-Control
X-ESI
X-Content-Type
X-B3-TraceId
X-Vcap-Request-Id
X-FastCGI-Cache
Cf-Apo-Via
Accept-Ch-Lifetime
X-D2id
Verso
X-Ttl
Xkey
X-Kinja-Build
X-Kinja-Revision
X-Exp-Variant
X-Kinja
X-Kinja-Server
X-Cdn-Fetch
X-GoogleNews-Bot
X-Use-Magma
X-Exp-Id
Cache-Tag
X-Mcache
X-GitHub-Request-Id
X-Powered-By-Plesk
Service-Worker-Allowed
X-Amz-Rid
X-Varnish-TTL
X-ECACHE
X-Navigation-Version
RTSS
X-Server-Name
X-Abt-Application-Version
X-VARITI-CCR
X-Version
X-Client-IP
X-Upstream
X-Ac
X-Cnection
X-Cached
X-Element-Page-Cache
Arr-Disable-Session-Affinity
X-Kraken-Loop-Name
X-Instrumentation
X-Server-Lifecycle-Phase
X-Dw-Request-Base-Id
X-Ruxit-JS-Agent
SPRequestGuid
X-SharePointHealthScore
Permissions-Policy
X-Px
SPIisLatency
SPRequestDuration
Display
X-Sol
Pagespeed
X-Middleton-Display
X-RateLimit-Remaining
Public-Key-Pins
X-Cache-TTL
X-NWS-LOG-UUID
X-Country-Code
Response
X-Middleton-Response
X-Midtier
X-Cache-Key
X-Kinsta-Cache
X-Edge-Location-Klb
X-Ser
X-Forwarded-For
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Goog-Hash
Content-MD5
X-DataDome
X-Correlation-Id
X-NF-Request-ID
X-MSEdge-Ref
X-Shield-Request-Id
Access-Control-Request-Method
X-HP-Trace-Id
X-HP-Webp
X-Jurisdiction
Front-End-Https
X-Recruiting
Mrf-Cache-Status
X-B3-TraceId-Primal
MRF-Tech
X-RateLimit-Limit
X-T
Edge-Cache-Tag
AR-PoweredBy
AR-CACHE
AR-SID
TP-Cache
TP-L2-Cache
AR-ATIME
AR-Request-ID
MicrosoftSharePointTeamServices
Nginx-Cache
X-ORACLE-DMS-ECID
X-Daa-Tunnel
X-ORACLE-DMS-RID
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Browser-Type
X-Accel-Expires
X-Mg-S
X-Content-Digest
TCN
X-Grace
X-Powered-CMS
X-Hits
X-Amzn-Trace-Id
X-HS-Hub-Id
X-HS-Combine-CSS
X-Request-Processing-Time
X-Request-Received
X-HS-Content-Id
X-HS-Cache-Config
Filters
Server-Node
X-Id
Server-Name
MS-Author-Via
X-XRDS-Location
Fastcgi-Cache
X-Geo-Country
Count-Hit
X-Webkit-Csp
X-Frontend
X-Distributor
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-TEC-API-ROOT
X-Ezoic-Cdn
X-Origin-Server
X-Ua-Browser
Filterid
Cross-Origin-Opener-Policy
X-PressLabs-Stats
X-Fastly-Request-Id
S
X-LLID
X-Seen-By
Charset
X-Microsite
X-Protected-By
X-Forwarded-Proto
X-Language
X-Request-Handler-Origin-Region
X-F-Cache
Payment
X-B3-Sampled
X-Page-Id
X-Ratelimit-Reset
X-Git-Hash
X-FB-Debug
X-LB-Cache
X-Amz-Meta-S3cmd-Attrs
X-ASPNET-VERSION
Host
X-VCache
Cache-Status
X-Cluster-Name
Surrogate-Key
X-Rid
X-Ab
X-Www-Served-By
Cache-Tags
X-Logged-In
Access-Control-Allow-Method
Realpath
X-Upgrade-Enabled
Retry-After
X-DIS-Request-ID
X-Varnish-Backend
X-Source
Alternate-Protocol
Accept-Charset
X-Origin-Cache
Accept-Ch
X-Az
X-AppVersion
X-Activity-Id
X-COUNTRY
X-NGENIX-Cache
Cleartype
X-Cache-Age
X-Type
X-Request-Guid
X-Template
X-Aspnet-Duration-Ms
X-Flags
X-Route-Name
X-Is-Crawler
X-Providence-Cookie
X-Wix-Request-Id
DC
X-Envoy-Decorator-Operation
X-Amz-Replication-Status
X-Signature
X-B-Cache
X-Tb
Paypal-Debug-Id
X-Varnish-Grace
X-TT
X-App-Environment
X-B
X-Hostname
ServerID
X-Revision
X-Fastly-Request-ID
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-DynaTrace
X-Contextid
Frame-Options
X-Cache-Rule
X-Fastcgi-Cache
X-Drupal-Cache-Tags
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Node-Name
Pinterest-Version
X-Pinterest-Rid
Pinterest-Generated-By
Cross-Origin-Resource-Policy
Amp-Access-Control-Allow-Source-Origin
X-Proxy
X-Goog-Metageneration
X-Goog-Generation
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
Refresh
X-GUploader-UploadID
X-Goog-Stored-Content-Encoding
X-Debug
Referer-Policy
X-Load-Cache
X-EdgeConnect-Cache-Status
X-Mobile
Node
X-Content-Options
X-Trace-Id
X-Cache-Control
NGB
X-Original-Request-Id
X-Response-Served-From
X-Server-ID
X-Varnish-Server
Akamai-GRN
Viewport
X-N
X-Debug-IsPreview
X-Instance
X-Magnolia-Registration
Country
X-Debug-IsConnected
X-Whom
X-Content-Powered-By
X-NYM-Debug-Backend
X-Cache-Time
X-Varnish-Age
X-Page-View
X-Rendered-As
X-Is-Bot
X-G
X-Adobe-Loc
X-Adobe-Content
Content-Disposition
X-Status
X-Cache-Grace
X-L-Path
X-Akamai-Request-ID2
Uber-Trace-Id
Access-Control-Request-Headers
X-Servername
X-Environment-Context
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Real-IP
Srv
X-User-Agent
VIX-Pulpo-Node
X-Framework
X-Cache-TTL-Remaining
X-Cacheable-TTL
VIX-Pulpo-Upstream-Status
Url
X-Jobs
X-Mid
X-ProcessESI
X-RemovedCookies
X-Oracle-Dms-Ecid
X-Cache-Expired-At
X-Via-JSL
X-Oracle-Dms-Rid
X-CDN-Forward
X-Cache-Hit
X-Unique-Id
Countrycode
Healthy
X-Cache-Operation
X-XRDS-LOCATION
X-Tumblr-Pixel
X-Tumblr-User
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-Drupal-Cache-Contexts
X-Rule
Version
X-Backend-Name
Accept-Language
X-TTL
X-Debug-Info
X-APP-VERSION
X-Akamai-Edgescape
X-Mg-Request-UUID
X-Http-Reason
X-Cache-Action
X-Litespeed-Cache
Section-Io-Cache
X-VC-Cache
Content-Secure-Policy
X-IPLB-Request-ID
X-IPLB-Instance
X-Time
Protected
Xserver
X-Hosted-By
X-Tt-Logid
X-HTML-Minification-Powered-By
X-Generation-Time
X-FW-Dynamic
X-FW-Serve
X-FW-Type
X-SRV
X-Azure-Ref
X-FW-Static
X-FW-Server
X-FW-Hash
Server-Info
Backend
X-Generated-By
X-Api-Version
X-RN-RSRV
X-UPSTREAM-Address
X-Storage
Meta-Geo
X-App-Server
X-Amzn-RequestId
CF-IPCountry
X-Amz-Apigw-Id
X-Restarts
X-PCL
X-Cms-Context
Azure-Version
Azure-RegionName
X-R9-Blue-Green-Version
MS-CV
GEO-INFO
X-OCL
X-Section
Azure-InstanceId
Ms-Operation-Id
Azure-SlotName
X-Format
Onion-Location
Azure-SiteName
X-Device-Type
X-Access
Liferay-Portal
X-RTag
X-Mobile-URL
X-Handled-By
X-Varnish-Cache-Hits
X-Provided-By
X-LJ-Flow-ID
X-Content
X-Origin-Hint
X-Cache-Status-Check
X-Adobe-Source
X-SaId
X-Say-Cacheable
Webcakes-Region
X-Proto
X-Labrador-Cache-Channel
TWC-Privacy
X-Say-TTL
Webcakes-App-Version
Webcakes-App-Name
X-Sql-Duration-Ms
X-Sql-Count
X-SayCDN-TTL
X-JoinUs
TWC-Locale-Group
TWC-Connection-Speed
X-VWS-Id
X-AWS-Id
Property-Id
TWC-Device-Class
Web-Mar-Node
X-Proxy-Cache-Status
TWC-GeoIP-LatLong
TWC-GeoIP-Country
X-FireWall-Port
X-Cache-Server
X-PHP-Host
CDN-PullZone
X-Xfnlog-Site
X-GeoCountry
X-Ms-Request-Id
X-Ms-Version
X-No-Session
X-GeoCode
X-Forwarded-Host
X-Cache-Host
X-Cache-Type
X-Content-Age
X-Detected-As
X-Edge-Location
X-Web-Node
X-Varnish-Hostname
CDN-EdgeStorageId
CDN-RequestCountryCode
CDN-CachedAt
CDN-Cache
X-Server-W
CDN-RequestId
CDN-Uid
X-UA-Device-Type
X-Urbn-Site-Id
X-Redis-Cache
X-Region
Locale
X-Locale
X-Urbn-Context-Path
Eomportal-Instance
X-Mode
X-Sorting-Hat-ShopId
X-BYPASS-REASON
X-Hl-Ver
X-Sorting-Hat-PodId
X-ProxyCache-Key
X-Skip-Cache
Cache-Name
Apigw-Requestid
X-Extlb
X-PHP-Backend
X-Proxied
X-Zipkin-Id
X-Varnish-Beresp-Grace
X-ProxyCache-Status
X-Ratelimit-Remaining
Mn-Server-Ip
X-Routing-Service
X-Request-Time
S-Rt
X-Site-Version
X-Alternate-Cache-Key
X-Shopify-Stage
X-ShardId
X-ShopId
WP-Super-Cache
X-DynaTrace-JS-Agent
X-Storefront-Renderer-Rendered
Load-Balancing
X-Tid
DB-Nickname
X-Nginx-Cache-Key
X-Tec-Api-Origin
X-Tec-Api-Version
X-Varnishpool
X-Tec-Api-Root
X-FB-TRIP-ID
X-Via-Fastly
X-Timing-Wait
X-Vgn-Hpd-Reason
X-WP-CF-Super-Cache-Cache-Control
X-Reqid
X-ServerID
X-WP-CF-Super-Cache
X-Amzn-Remapped-Content-Length
X-Proxy-Build
Selected-Fe
X-ECache
X-Cache-Enabled
X-TNCMS
X-Loop
X-Pubstack
X-Ua
X-Dc
X-LSADC-Cache
X-Uri
X-Varnish-Ttl
X-Cdn
X-B3-Traceid
Xet-Cookie
X-Origin-Date
X-Soup
X-TIME
X-Cache-NGX
X-Newrelic-Synthetics
X-Zen-Fury
Fastcgi-Useragent
X-Tumblr-Pixel-2
X-Correlation-ID
X-Aspnetmvc-Version
X-Cache-Debug
X-UUID
From-Origin
X-Origin-CC
X-App-Version
X-Origin-TTL
X-GEO
Origin
X-Service
X-Webkit-CSP
X-Varnish-Hits
X-Nginx-Cache
Source
X-MP-GENERATED-AT
ServedBy
X-Human
X-NewRelic-App-Data
X-URL
X-TA-CDN-Provider
X-Ratelimit-Limit
Request-ID
Cache
Fastly-Drupal-HTML
X-Cache-Tags
X-Varnish-Beresp-Ttl
X-Cached-By
Rip
Cross-Origin-Window-Policy
Upgrade-Insecure-Requests
X-Cluster
Webserver
X-Rewrite-Enabled
MD5-Digest
Rendered-Blocks
X-ScT
BehaviorPad-Version
WPO-Cache-Status
WPO-Cache-Message
X-PBS-Appsvrname
Mime-Version
X-Rojux
X-External-Request-Id
X-S
X-Parent-Response-Time
Expiry
X-Orig-Expires
X-NAPM-TraceId
Cdncip
X-Processor
A
X-S-Cookie
X-Shop-Environment
DCR-Decision-By
X-VG-WebCache
Cdnsip
DCR-Processing-Time-Ms
X-Forwarded-Path
X-A-Wwc
X-Aed
X-AK-Request-ID
X-D
Lang
X-A-Dgt
X-User
X-A-Dam
X-A-Dcw
X-Connection-Hash
X-Application
X-BCube-Filmed-By
X-Vdms-Version
X-Cache-NE
X-Vdms-Path
X-Bc-Bl
X-ARC
X-FW-Version
X-B-Cookie
X-A-Ccd
Xc-Version
Sslversion
X-Developer
Surrogated-Key
T-Server
SD-X-WS
X-Ec-Fail
Meta-Geo-Continent
Ngx.Var.Host
Odigeo-Trace-Id
X-Ec-GeoHdr
X-Destination
X-SRCache-Key
X-A
X-Tenant
X-RCS-CacheZone
X-TIM-N
X-Request-Host
Host-ID
X-Nyt-Route
X-Accel-Buffering
X-Gdpr
Redirect-Candidate
X-Aicache-OS
Environment
X-Origin-Time
Thinkindot-CacheControl
TDXMobile
X-Worker
X-Thinkindot-L3
Fastly-Backend-Name
X-WP-CF-Super-Cache-Active
X-Cdn-Srv
X-HS-Content-Campaign-Id
X-Has-Esi
X-INCAP-ABP
X-Is-Gdpr
X-JWT-State
X-Cluster-Node
X-Sucuri-ID
X-Auto-Login
Thinkindot-Control
X-Sucuri-Cache
X-CMSURLCustom
X-Core-Value
Thinkindot-CacheControl-Type
X-Developers
OT-Force-Account-Verify
LB
Tube-Return
Decoy-Debug-TTL
Decoy-Debug-Key
Decoy-Debug-Status
X-Sigma-Backend
X-SIPLIST1
Fastly-GeoIP-CountryCode
Fastly-SIE
Tube-Got-Eval
X-Fmm-Version
X-GeoIP-City
Tube-Got-Results
CPC-Age
X-Sigma
Click-Count-Action-Start
Cache-Host
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
Click-Count-Error
Web-Mar-Region
Fastly-SSL
VNS-Age
VNS-Cache
We-Hiring
CPC-Cache
Fastly-SWR
X-Ec-Custom-Error
Platform
Origin-EX
Origin-CC
X-SplitTest
X-DPWN-IS-SECURE
Producers
Servername
Req-Svc-Chain
Release
X-Dispatcher-Number
NM-Fastcgi-Cache
NGX
IsBot
Kp-EeAlive
Is-Eu
X-DefElseHash
Tube-Get-Contents
L
Traceparent
X-Epic-Correlation-Id
X-Esi-Check
Mail-Subject
X-DefHash
Apple-News-Services-Host
Candidate-Md5Url
Apple-News-Services-Handled
X-GeoIP
X-Rocket-Build-Number
X-ATG-Version
X-VServer
X-Cache-Bucket
X-Varnish-CookieINHashed-On
X-Clara-WADP
X-Gzip
X-Request-URI
X-Debug-Cache
X-Proxy-Cache-Info
X-Platform-Server
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Varnish-Remaining-TTL
X-BBC-Edge-Cache-Status
X-Viewer-Country
X-Loc
X-Varnish-CookieHashed-On
X-Wix-Viewer-Type
X-Cache-Info
X-Served-From
Gh-Request-Id
X-NodeID
Adler-Geo
X-Origin-Response-Time
X-VG-TLSProxy
X-WADP-Cache
X-Ad-Defer-Variation
X-Cache-Id
X-Variation
X-Minions-Version
AKAMAI
X-Level-Front-Cache
Server-Host
X-Generated-On
X-AOL-HN
X-Optimistic-Header
X-Cache-Remote
X-Geo-Header
L5d-Success-Class
X-Ckpd-Fst-Backend
Sever-Int
State
Svr
X-CacheTTL
X-Azure-Ref-OriginShield
Wxu-Next-Commit
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
Wxu-Next-Hostname
X-Device-Os
HA-Ipaddr
Ha-Gx-Prefs
Wxu-Next-Region
Vix-Hermes-Req-Id
X-Datadog-Parent-Id
X-Clientip
X-SVT-ORM-VERSION
X-Block-Status
X-Core-Mission
User-Cache-Control
V-Age
X-Varnish-Beresp-Status
X-SVT-ORM-RULES
X-Eu-Site
X-Var-Ttl
X-Gateway-Request-Id
X-Gateway-Skip-Cache
X-Scale
X-SB
X-Policy
X-Gateway-Cache-Status
Canary
X-Irp-Debug
Server-Hostname
X-Mvc-Supplant-Cachable
X-S-Maxage
X-Gen-Mode
X-Planisys-CDN-Rules
X-Cdn-Origin
X-Planisys-CDN-Cache
X-NCache
X-Origin
X-Planisys-CDN-TTL
X-Pool
X-Rocket-Nginx-Serving-Static
X-Hash
X-Hnp-Log
X-Qloud-Router
CDCHOST
X-Gateway-Cache-Key
Machine
Memcached
X-Slack-Backend
X-Owner
X-Fetched-On
CloudFront-Viewer-Country
X-Csrf-Jwt
Mobile-Detection-Method
X-CGP
Server-Ext
X-Tx-Id
X-Udemy-Cache-App-Namespace
X-Sn-Servicetimems
X-FC-Vary-Parameters
X-Fastly-Backend
Country-Code
Cmstype
Cmsid
Cluster
X-Forwarded-Site
Datacenter
DSUID
X-Presslabs-Stats
X-Pass-Why
X-IPS-LoggedIn
X-Tumblr-Pixel-3
X-Bip
X-Scheme
X-Gamma-Serve
X-V-Cache
X-Region-Sid
X-Mvc-Supplant-OutputCached
X-Thanos
X-Up
X-LB-NoCache
X-Branch-Name
X-Datadome
WebServer
Time
X-ZONE
Memory
Pics-Label
Ec-Rule-Version
X-Nf-Request-Id
X-CSRF-Token
HostName
X-Akamai-Transformed
X-Tb-Optimization-Total-Bytes-Saved
X-Dispatch
Sid
X-ND-Cache
X-VC
X-Newrelic-App-Data
X-Trace-ID
Ssr
X-Refresh
X-Edge-Pop
AMP-Access-Control-Allow-Source-Origin
X-Via-Popn
Env
X-Via-Poph
X-Servedbyhost
X-Via-Popv
My-App
X-B3-Spanid
X-B3-SpanId
X-WA-Info
SID
Cache-Tv-Group
X-Via-NSCOPI
Fastcgi-Cache-TTL
Server-ID
X-NGINX-Cache
X-Generated-In
X-GG-Cache-Date
X-Req
X-Wa
X-Lambda-Id
X-Cs
CacheControlHeader
True-Client-Country-4JS
X-Session-Fingerprint
X-CACHE-AGE
X-Pod-Name
GeoIp-Country-Code
X-Fpc
X-Fastly-Cache
X-Origin-Expires
Cache-Hits
X-Release
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-Vc
X-PX
X-EC-Lua
X-LB-ID
Hostname
True-Client-IP
X-ID
X-CSRF-TOKEN
X-VCL-Version
X-Xrds-Location
X-Op-Id-All
X-DC
X-MCACHE
X-NWS-UUID-VERIFY
X-Zone
X-TX-ID
X-GeoIP-Region-Code
X-GeoIP-Country-Code
X-Webkit-CSP-Report-Only
WWW-Authenticate
X-Cache-Date
X-TH-Server
X-MSEdge-Features
X-MSEdge-Flight
X-Ig-Push-State
X-CACHE-KEY
X-Buckets
X-RAMCache
Resin-Trace
X-Accel-Expires-Debug
X-NC
X-Date
X-HS-Status
X-Conf
X-Endurance-Cache-Level
X-CS
X-Microcachable
X-TRACE-ID
CDN
X-Dmc
X-Old-Content-Length
X-Esi
X-Srv
X-RateLimit-Reset
Fastly-Drupal-Html
Tcn
X-Vcl-Version
Powered-By
X-Webstats-RespID
X-Varnish-Beresp-TTL
X-Check-Cacheable
True-Client-Ip
X-Location
Magicmarker
Path
X-API-Version
Section-Io-Id
X-Director
X-Wikidot-Static-Cache
Section-Io-Origin-Status
Section-Origin-Responded
X-Akamai-Pragma-Client-IP
Section-Io-Origin-Time-Seconds
X-Lb-Id
GeoIP-Country-Code
X-Alfa-Service
X-Wikidot-Backend
Yjs-Id
X-Contensis-Viewer-Groups
X-DataCenter
X-CLOUD-TRACE-CONTEXT
X-Cache-Ttl
X-Cache-ASPX
X-Be
X-Varnish-Authentication
X-LiteSpeed-Cache-Control
X-Vercel-Cache
X-FPC
Proxy-Connection
X-Vercel-Id
X-Datacenter
Cdn
Pramga
X-Via-CDN
X-Test
X-Mly-Id
FSS-Cache
X-Micro-Cache
X-Hyper-Cache
X-WA
X-Geo
X-ServedByHost
Lb
Server-Id
User-Agent
X-CF-Lambda-Version
X-HA-Backend
M-TraceId
X-Cache-Backend
X-Server-IP
X-CF-Lambda-Fn
X-M-Log
X-Cache-Expires
X-M-Reqid
ENV
X-Response-By
X-Dw-Trace-Id
X-Edge-POP
X-Cc-Via
X-Cdn-Forward
X-Via-PopN
X-Via-PopH
X-Via-PopV
X-Akamai-ERRuleID
Tracecode
X-We-Are-Hiring
X-App
X-Client-Ip
Uri
X-Qnm-Cache
HIT
X-Akamai-ERPolicy
X-Service-Response-Time
Sm-Log-Id
X-AIR-PT
YJS-ID
X-ApacheServer
X-PERF
X-From
X-Info
Swift-Performance
X-Traceid
X-FL-EDGE
Locid
Location
XM
X-Frame-Option
Srvid
X-Instance-Name
X-TT-LOGID
X-Li-Pop
Geoip-Latitude
Dnion-Transfer-Encoding
N-Cache
X-LI-Proto
X-TrackingId
X-Li-Fabric
X-UA
C-Via
X-Air-Source
X-Air-Trace-Id
X-Air-Hostname
X-LiteSpeed-Tag
X-LI-UUID
X-RSL
X-RPM
X-RPS
CountryCode
X-VarnishDD-TTL
Esi-Enabled
PFcat
CF-Cached-On
X-HN
X-Platform-Cluster
X-DW
X-Platform-Router
X-Platform-Processor
XServer
X-DSS
Ohc-File-Size
X-DI
PICS-Label
Nginx-CQVIP
X-Platform
X-Air-Pt
X-Fastly-Backend-Reqs
X-DB
X-Wp-Cf-Super-Cache
X-Wp-Cf-Super-Cache-Cache-Control
X-CF-Powered-By
X-HostName
Cneonction
X-Fastly-Cache-Hits
Vha6-Origin
X-Cdn-Request-ID
X-Cache-Proxy
X-PAYTM-SRV-ID
Wpo-Cache-Message
On-Server
X-Conten-Type-Options
Timeexpire
Hit
Fastcgi-X-Cache-Version
NtCoent-Length
Wpo-Cache-Status
X-Lb-Nocache
X-Request-Url
Wp-Super-Cache
Warning
X-Cache-Ngx
X-Litespeed-Cache-Control
X-Ips-Loggedin
X-Newegg-Index
X-Newegg-Flow
X-NFL-Dma
X-NS-Authorization
X-Nerd
X-NFL-Geo
X-Matome-Cached
X-Loadbalancer
X-Matched-Rule
X-Ntj-Investigation-Id
X-MTS-Cache
X-N-OperationId
X-Odoo-Frontend
X-OVcl-Cache
X-PageType
X-Paywall
X-PG-ACCESS
X-OVcl
X-Origin-Ops
X-Nyt-Data-Last-Modified
X-LbNode
X-Okws-Version
X-Onedio-Env
X-NXG
X-Kebabable
X-Full-Ttl
X-Fstrz
X-GG-Cache-Status
X-Git-Commit
X-Global-Transaction-ID
X-Eid
X-Fastly-Is-Edge
X-F-Status
X-Eventloop-Lag
X-Farm
X-ETag
X-Ee-Request-Id
X-GoCache-CacheStatus
X-Ittl
X-Kebab
X-PGF-Deflate
X-Keep
X-Is-SSL
X-IBD-SID
X-Group
X-Header-Sub
X-Ee-Request-Date
X-IBD-Cache
X-Ee-Origin
X-User-Auth
X-Waitingroom
X-Wag-Acs
X-Web-Hosting
X-WP-Bypass
X-WSR2
X-Ver
X-Vary-Devices
X-Upstream-State
X-U-Cache
X-Ee-Generated-By
X-Utime
X-V2-Infrastructure
X-Xms-Page-Cache-Actions
X-YSpaceId
X-Oss-Request-Id
X-Oss-Object-Type
X-Oss-Server-Time
X-Oss-Storage-Class
X-Request-URL
X-Oss-Hash-Crc64ecma
Cache-Key
XV-Cache
XV-H
X-B3-Parentspanid
X-Fastly-Country-Code
X-True-Client-Ip
X-Tried-To-Kebabify
X-Ruby
X-Route-Akamai
X-Save-Cache
X-Server-L
X-ServiceName
X-Route
X-Request-Origin
X-Reboot
X-R-Cache
X-Redis
X-Render-Method
X-Render-Time
X-Sh
X-Site
X-Test-Nginx-Ingress
X-Svr-Proxy
X-Timestamp
X-Toujours-Debout-Branch
X-Toujours-Debout-Location
X-SVR-IIS
X-Stack-Name
X-Slack-Shared-Secret-Outcome
X-SMP-JWT
X-Square
X-SSLProxy
X-Pver
X-Backend-TTL
Ns-Ua
Ns
Ok-Cache-Status
OK-Edge-Date
Ok-Edge-Key
Npm-Remaining
Npm-Cost
Joe-X
Is-Https
NB-ESI
Nikkei-App-Version
NLCacheNote
Origin-Site
Panzer-Cache-Control
Service-Uuid
Served
SFRVia
Shieldsquare-Response
SII
Selected-Route
Scheme
RawURL
Proxy-Cache
Region
Request-Uuid
Rt-Proxy-Cache
HTTPProtocol
HServer
X-ElasticPress-Query
X-Mg-Cache
X-Yottaa-OS
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
X-B3-ParentSpanId
WZWS-RAY
Req-ID
Fastcgi-Cache-Ttl
SRV
X-CUA
DynaTrace
X-Serial
X-Th-Server
CMS-200
Cluster-Host
Deeplink
Ec-Policy-Id
H1
Cf-Wrk
Cf-Locale
Cache-Stat
Akamai-X-Url
Cachekey
Cdn-Country-Code
Cf-Device-Type
Store-Cloud-Cache
Sw
X-Cache-NPR
X-Cache-Length
X-Cache-Reason
X-Cache-ReqUri
X-Cache-Response
X-Cache-IsMobileDevice
X-Cache-Cookie
X-AspNetWebPages-Version
X-ASF-Cache
X-Backside-Transport
X-BeanStalkRole
X-BeanStalkStage
X-CacheVersion
X-CDN-Pop
X-Delivery
X-Dehri-Date
X-Developed-By
X-Doge
X-DT-Node
X-Dcm-Pdtf
X-Container-Uri
X-Cf-Node-Idx
X-CDN-Pop-IP
X-Cms-Device
X-Coindesk-Cache
X-Colour
X-ARRRG1
X-Arena-Request-Id
Uniqueid
TWC-Unit
Userver
Vttl
X-77-NZT
TWC-Subs
TWC-PATH-LOCALE
Technodrome
T-Request-Id
Time-Cloud-Cache
Ttl
TWC-AK-Req-ID
X-77-NZT-Ray
X-Accel-Version
X-Akamai-Native
X-Akamai-DeviceType
X-Amz-Meta-Cb-Modifiedtime
X-Apache-Server
X-Ar-Stats
X-Akamai-DeviceOS
X-Akamai-CacheKeyMod
X-Accepted-Fulllang
X-Accepted-Language
X-Accor-Asset
X-AEO-Platform
X-Edge-IP