Threat Level: green Handler on Duty: Guy Bruneau

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
Strict-Transport-Security
X-Frame-Options
X-Content-Type-Options
Link
Last-Modified
CF-Cache-Status
Cf-Request-Id
CF-RAY
Accept-Ranges
ETag
Expect-CT
Pragma
X-Powered-By
X-Cache
Via
Age
X-XSS-Protection
Content-Security-Policy
Report-To
NEL
X-Xss-Protection
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-FRAME-OPTIONS
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Request-Id
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-Adblock-Key
X-AspNet-Version
X-Permitted-Cross-Domain-Policies
Alt-Svc
X-Runtime
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Cache-Status
X-Check
X-Generator
X-DNS-Prefetch-Control
X-Request-ID
X-Cacheable
X-Iinfo
X-Envoy-Upstream-Service-Time
X-Ua-Compatible
Feature-Policy
Timing-Allow-Origin
X-Content-Security-Policy
Status
X-Drupal-Dynamic-Cache
Content-Encoding
Access-Control-Expose-Headers
X-AspNetMvc-Version
X-CDN
P3p
Upgrade
X-Dns-Prefetch-Control
Access-Control-Max-Age
CF-Ray
X-Via
X-Robots-Tag
X-Cache-Group
X-UA-Device
Server-Timing
Keep-Alive
Request-Context
X-AH-Environment
X-Turbo-Charged-By
X-Amz-Request-Id
X-Proxy-Cache
X-Backend
X-Amz-Id-2
X-Age
X-Ws-Request-Id
Host-Header
X-Hacker
X-Server-Powered-By
X-Server
X-Rq
X-LiteSpeed-Cache
X-Vhost
X-Varnish-Cache
X-Amz-Version-Id
Grace
Cf-Edge-Cache
X-Dispatcher
Allow
EagleId
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Device
X-Page-Speed
X-Nginx-Cache-Status
Accept-CH
X-Aws-Lambda-Call-Status
X-Swift-SaveTime
X-Swift-CacheTime
Cf-Railgun
Ali-Swift-Global-Savetime
X-WebKit-CSP
X-Node
X-Host
X-OneAgent-JS-Injection
X-Pingback
X-Cache-Spec
X-Backend-Server
X-Akam-SW-Version
X-Server-Id
Surrogate-Control
Request-Id
X-Cache-Lookup
X-Response-Time
EagleEye-TraceId
Accept-CH-Lifetime
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Readtime
Content-Location
X-HW
X-Cloud-Trace-Context
X-Content-Security-Policy-Report-Only
Rating
X-Application-Context
X-Trace
X-Url
Fastly-Restarts
X-WebKit-CSP-Report-Only
X-Clacks-Overhead
X-Nginx-Upstream-Cache-Status
X-CST
X-Ruxit-Js-Agent
X-MS-InvokeApp
X-Edge
X-Amz-Server-Side-Encryption
X-Rack-Cache
X-ESI
X-Mod-Pagespeed
X-Country
X-PC
X-Vname
X-TtlSet
Accept-Ch-Lifetime
X-Content-Type
X-B3-TraceId
X-FastCGI-Cache
Cf-Apo-Via
Edge-Control
X-Vcap-Request-Id
X-Oneagent-Js-Injection
X-Akamai-Path-Stats
X-Mcache
X-D2id
Verso
X-Ttl
X-GitHub-Request-Id
Xkey
Cache-Tag
X-Kinja
X-Use-Magma
X-Exp-Id
X-Cdn-Fetch
X-Kinja-Revision
X-Kinja-Build
X-Kinja-Server
X-Exp-Variant
X-GoogleNews-Bot
Service-Worker-Allowed
X-Powered-By-Plesk
X-Amz-Rid
X-Server-Name
X-Navigation-Version
RTSS
X-Abt-Application-Version
X-VARITI-CCR
X-Ruxit-JS-Agent
X-Client-IP
X-Ac
X-Version
X-Upstream
X-Cnection
X-Cached
X-Element-Page-Cache
X-Varnish-TTL
Arr-Disable-Session-Affinity
X-ECACHE
Permissions-Policy
X-Kraken-Loop-Name
X-Instrumentation
X-Server-Lifecycle-Phase
SPRequestGuid
X-Dw-Request-Base-Id
X-SharePointHealthScore
X-RateLimit-Remaining
X-Px
SPIisLatency
SPRequestDuration
Display
X-Middleton-Display
Pagespeed
X-Sol
X-Cache-TTL
X-NWS-LOG-UUID
Public-Key-Pins
X-Country-Code
X-Middleton-Response
Response
X-Midtier
X-Webkit-Csp
X-Cache-Key
X-Kinsta-Cache
X-Edge-Location-Klb
X-Ser
X-Forwarded-For
X-DataDome
X-Goog-Hash
X-SRCache-Fetch-Status
X-SRCache-Store-Status
Content-MD5
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-NF-Request-ID
X-Correlation-Id
X-Shield-Request-Id
Access-Control-Request-Method
X-HP-Webp
X-MSEdge-Ref
X-HP-Trace-Id
X-Jurisdiction
X-RateLimit-Limit
Front-End-Https
Mrf-Cache-Status
X-B3-TraceId-Primal
MRF-Tech
AR-SID
X-T
X-Recruiting
AR-CACHE
AR-PoweredBy
AR-Request-ID
AR-ATIME
X-Daa-Tunnel
MicrosoftSharePointTeamServices
Edge-Cache-Tag
Nginx-Cache
TP-L2-Cache
TP-Cache
X-Erf-Bev-Bev-Is-Generated
X-Browser-Type
X-Erf-Bev-Bev
Accept-Ch
X-Mg-S
X-Accel-Expires
X-Content-Digest
TCN
X-Grace
X-Powered-CMS
X-Hits
X-Amzn-Trace-Id
X-Request-Processing-Time
X-Request-Received
X-HS-Content-Id
X-HS-Hub-Id
Server-Node
X-HS-Cache-Config
X-HS-Combine-CSS
Server-Name
Filters
MS-Author-Via
X-Id
Fastcgi-Cache
X-Fastly-Request-Id
X-Geo-Country
Count-Hit
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-PressLabs-Stats
X-Origin-Server
X-Ua-Browser
X-Ezoic-Cdn
X-Distributor
X-Frontend
Filterid
Cross-Origin-Opener-Policy
X-XRDS-Location
X-LLID
Payment
S
X-Forwarded-Proto
X-Protected-By
X-Microsite
X-Request-Handler-Origin-Region
Charset
X-Language
X-Page-Id
X-Seen-By
X-F-Cache
X-Git-Hash
Host
X-FB-Debug
X-LB-Cache
X-B3-Sampled
X-Amz-Meta-S3cmd-Attrs
X-Ratelimit-Reset
X-ASPNET-VERSION
X-VCache
X-Cluster-Name
X-Rid
Surrogate-Key
Cache-Status
X-Www-Served-By
Cache-Tags
X-Logged-In
Access-Control-Allow-Method
X-Upgrade-Enabled
X-Origin-Cache
X-Ab
X-DIS-Request-ID
X-Source
X-Varnish-Backend
Realpath
X-Cache-Age
Retry-After
Alternate-Protocol
X-Activity-Id
X-Az
X-AppVersion
Accept-Charset
Cleartype
X-NGENIX-Cache
X-Amz-Replication-Status
X-COUNTRY
X-Type
Paypal-Debug-Id
DC
X-Is-Crawler
X-Flags
X-Envoy-Decorator-Operation
X-Varnish-Grace
X-Template
X-Wix-Request-Id
X-Route-Name
X-Providence-Cookie
X-App-Environment
X-Request-Guid
X-Aspnet-Duration-Ms
X-Tb
X-Signature
X-B-Cache
X-TT
X-Hostname
X-Revision
X-B
X-DynaTrace
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
ServerID
X-Contextid
Frame-Options
X-Cache-Rule
X-Trace-Id
X-Drupal-Cache-Tags
X-Node-Name
X-Tt-Trace-Host
X-Tt-Trace-Tag
Cross-Origin-Resource-Policy
Pinterest-Version
Pinterest-Generated-By
X-Pinterest-Rid
Refresh
X-XRDS-LOCATION
Amp-Access-Control-Allow-Source-Origin
X-GUploader-UploadID
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-Goog-Generation
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
Referer-Policy
X-Proxy
X-Debug
X-Fastly-Request-ID
X-Mobile
X-Load-Cache
X-Content-Options
Node
X-Varnish-Server
X-EdgeConnect-Cache-Status
Viewport
NGB
X-Original-Request-Id
X-Response-Served-From
X-Cache-Control
X-Varnish-Age
X-Whom
Country
Akamai-GRN
X-Content-Powered-By
X-N
X-Fastcgi-Cache
X-NYM-Debug-Backend
X-Cache-Time
X-Debug-IsPreview
X-Debug-IsConnected
X-Instance
X-Magnolia-Registration
X-Framework
X-Is-Bot
X-Rendered-As
X-Real-IP
X-Page-View
X-G
Content-Disposition
X-Adobe-Loc
Uber-Trace-Id
X-Adobe-Content
X-Status
X-User-Agent
X-Yottaa-Optimizations
Access-Control-Request-Headers
X-Servername
X-Yottaa-Metrics
X-RemovedCookies
X-L-Path
X-Cacheable-TTL
X-Akamai-Request-ID2
X-ProcessESI
X-Environment-Context
Url
X-Cache-Grace
VIX-Pulpo-Node
X-Jobs
Srv
VIX-Pulpo-Upstream-Status
X-Cache-Expired-At
X-Mid
X-ECache
Healthy
X-Cache-TTL-Remaining
X-Via-JSL
Countrycode
X-Rule
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Tumblr-User
X-Cache-Hit
X-Tumblr-Pixel-1
X-CDN-Forward
X-Varnish-Ttl
X-Cache-Operation
X-Backend-Name
X-APP-VERSION
X-Unique-Id
X-Drupal-Cache-Contexts
Version
X-TTL
X-Debug-Info
Accept-Language
X-Akamai-Edgescape
X-Cache-Action
X-Litespeed-Cache
Section-Io-Cache
X-Http-Reason
X-VC-Cache
X-Mg-Request-UUID
Content-Secure-Policy
X-IPLB-Request-ID
X-Hosted-By
X-Server-ID
X-IPLB-Instance
X-HTML-Minification-Powered-By
X-Tt-Logid
Protected
X-Generation-Time
Server-Info
X-Azure-Ref
Backend
X-FW-Server
X-FW-Hash
X-FW-Static
X-FW-Type
X-Generated-By
X-FW-Dynamic
X-FW-Serve
X-Time
X-RN-RSRV
Ms-Operation-Id
X-Storage
X-RTag
X-Cache-Status-Check
Meta-Geo
X-UPSTREAM-Address
MS-CV
X-Oracle-Dms-Ecid
Xserver
X-Amzn-RequestId
X-Device-Type
X-Amz-Apigw-Id
X-Hl-Ver
Azure-RegionName
X-Mode
X-Dc
X-Cache-Server
X-Oracle-Dms-Rid
Azure-InstanceId
Azure-SlotName
Azure-SiteName
Azure-Version
TWC-Privacy
GEO-INFO
X-Cms-Context
X-Access
X-Proto
Property-Id
X-Format
Onion-Location
X-PCL
Liferay-Portal
X-Origin-Hint
X-OCL
X-Handled-By
Webcakes-App-Version
Webcakes-Region
TWC-GeoIP-Country
X-Varnish-Cache-Hits
TWC-Device-Class
TWC-Connection-Speed
TWC-GeoIP-LatLong
X-R9-Blue-Green-Version
X-Section
Webcakes-App-Name
TWC-Locale-Group
X-Adobe-Source
X-Provided-By
Web-Mar-Node
CF-IPCountry
X-Locale
X-FireWall-Port
X-Server-W
X-AWS-Id
X-SaId
X-PHP-Host
X-VWS-Id
X-Redis-Cache
X-SayCDN-TTL
X-Say-Cacheable
X-Say-TTL
X-Sql-Count
X-App-Server
X-Sql-Duration-Ms
X-Proxy-Cache-Status
X-Api-Version
X-Varnishpool
X-Varnish-Hostname
X-Mobile-URL
X-No-Session
X-LJ-Flow-ID
X-Labrador-Cache-Channel
X-JoinUs
Cache-Name
CDN-Cache
X-Edge-Location
Selected-Fe
X-Detected-As
X-PHP-Backend
DB-Nickname
X-Proxy-Build
X-Web-Node
X-Xfnlog-Site
X-Timing-Wait
X-UA-Device-Type
X-Urbn-Context-Path
Locale
X-ProxyCache-Key
X-Forwarded-Host
X-FB-TRIP-ID
Mn-Server-Ip
X-GeoCountry
X-Content-Age
X-GeoCode
X-Site-Version
X-Urbn-Site-Id
Eomportal-Instance
CDN-PullZone
CDN-EdgeStorageId
CDN-CachedAt
X-Cache-Host
X-Ms-Request-Id
X-Request-Time
X-Varnish-Beresp-Grace
X-Region
X-Cache-Type
CDN-Uid
X-ProxyCache-Status
X-Via-Fastly
X-Skip-Cache
CDN-RequestId
X-Ms-Version
X-Restarts
CDN-RequestCountryCode
X-BYPASS-REASON
X-ShopId
X-Sorting-Hat-ShopId
Apigw-Requestid
X-ServerID
X-Routing-Service
X-Extlb
X-Zipkin-Id
S-Rt
X-Alternate-Cache-Key
X-DynaTrace-JS-Agent
X-Proxied
X-ShardId
X-Shopify-Stage
X-Sorting-Hat-PodId
X-Storefront-Renderer-Rendered
WP-Super-Cache
X-Tid
X-Vgn-Hpd-Reason
X-SRV
X-Tec-Api-Version
X-Amzn-Remapped-Content-Length
X-Nginx-Cache-Key
X-Tec-Api-Root
X-Tec-Api-Origin
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
X-TIME
X-Reqid
X-LSADC-Cache
X-Newrelic-Synthetics
X-TNCMS
X-Loop
X-Content
Load-Balancing
X-Cache-Enabled
X-Pubstack
Xet-Cookie
X-Ua
X-Cdn
X-Soup
X-Tumblr-Pixel-2
X-Origin-CC
X-Uri
X-Origin-TTL
X-B3-Traceid
X-TA-CDN-Provider
X-Zen-Fury
X-Cache-NGX
From-Origin
X-Origin-Date
X-Service
X-Cache-Debug
X-MP-GENERATED-AT
X-Correlation-ID
X-Ratelimit-Remaining
X-Aspnetmvc-Version
Fastcgi-Useragent
X-Varnish-Hits
Source
X-Nginx-Cache
ServedBy
X-GEO
X-UUID
X-Webkit-CSP
Origin
X-Human
X-App-Version
X-NewRelic-App-Data
Cache
X-Cache-Tags
X-Cluster
X-Rewrite-Enabled
Upgrade-Insecure-Requests
SD-X-WS
Rip
X-Cached-By
Cross-Origin-Window-Policy
X-ScT
BehaviorPad-Version
MD5-Digest
Rendered-Blocks
Host-ID
Mime-Version
WPO-Cache-Status
X-Ratelimit-Limit
WPO-Cache-Message
Fastly-Drupal-HTML
X-A-Dam
X-PBS-Appsvrname
X-A-Dgt
X-External-Request-Id
X-Varnish-Beresp-Ttl
X-Ec-GeoHdr
X-S-Cookie
X-A-Dcw
X-NAPM-TraceId
X-ARC
X-Aed
X-Application
X-Processor
X-BCube-Filmed-By
X-Forwarded-Path
X-S
X-FW-Version
X-Rojux
X-AK-Request-ID
X-Orig-Expires
X-A-Wwc
X-Developer
X-User
Odigeo-Trace-Id
X-A-Ccd
Expiry
X-D
X-TIM-N
X-Bc-Bl
X-B-Cookie
X-Connection-Hash
Ngx.Var.Host
X-Cache-NE
Sslversion
Meta-Geo-Continent
X-Vdms-Version
Lang
X-Vdms-Path
Surrogated-Key
A
Cdncip
Cdnsip
X-VG-WebCache
Xc-Version
X-Ec-Fail
X-Shop-Environment
X-Parent-Response-Time
X-SRCache-Key
X-Tenant
DCR-Decision-By
DCR-Processing-Time-Ms
X-A
X-Destination
T-Server
OT-Force-Account-Verify
WebServer
X-Cluster-Node
X-Tumblr-Pixel-3
X-Request-Host
Release
Redirect-Candidate
Environment
Gh-Request-Id
X-GeoIP-City
X-Nyt-Route
X-Gdpr
X-Accel-Buffering
X-Origin-Time
X-Served-From
X-Aicache-OS
X-Generated-On
X-Worker
X-Is-Gdpr
Thinkindot-CacheControl
TDXMobile
X-WP-CF-Super-Cache-Active
X-JWT-State
Fastly-Backend-Name
X-Level-Front-Cache
X-Sucuri-Cache
X-Sucuri-ID
X-Thinkindot-L3
X-Optimistic-Header
Thinkindot-CacheControl-Type
X-Has-Esi
X-CMSURLCustom
X-Core-Value
X-RCS-CacheZone
X-Geo-Header
X-Developers
X-Cdn-Srv
X-HS-Content-Campaign-Id
X-Auto-Login
Thinkindot-Control
X-Pass-Why
X-INCAP-ABP
X-Cache-Remote
AKAMAI
Fastly-SSL
Decoy-Debug-Status
Decoy-Debug-TTL
X-Azure-Ref-OriginShield
Decoy-Debug-Key
X-Thanos
Datacenter
Webserver
X-Wix-Viewer-Type
X-WADP-Cache
Fastly-GeoIP-CountryCode
Fastly-SIE
Wxu-Next-Region
X-Var-Ttl
X-Csrf-Jwt
X-DefElseHash
X-DefHash
Fastly-SWR
X-Ckpd-Fst-Backend
Origin-CC
Origin-EX
X-Cache-Id
X-Cache-Info
X-Varnish-Remaining-TTL
X-Varnish-CookieINHashed-On
NM-Fastcgi-Cache
Platform
X-Cache-Bucket
Req-Svc-Chain
Servername
X-Bip
X-VServer
X-Viewer-Country
Producers
X-VG-TLSProxy
NGX
X-Varnish-CookieHashed-On
Is-Eu
IsBot
Kp-EeAlive
X-SplitTest
HA-Ipaddr
X-Clara-WADP
Ha-Gx-Prefs
L
L5d-Success-Class
Memcached
Mobile-Detection-Method
X-BBC-Edge-Cache-Status
Mail-Subject
X-CGP
X-Varnish-Beresp-Status
Machine
X-Variation
Adler-Geo
Tube-Got-Eval
X-Ad-Defer-Variation
Tube-Got-Results
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-GeoIP
Tube-Get-Contents
X-Request-URI
X-FC-Vary-Parameters
X-ATG-Version
X-Fetched-On
X-Fmm-Version
Traceparent
X-Rocket-Build-Number
X-Gzip
Tube-Return
X-NCache
X-Policy
X-NodeID
X-Platform-Server
X-Owner
X-Origin-Response-Time
X-Pool
X-Mvc-Supplant-Cachable
X-Proxy-Cache-Info
X-Qloud-Router
X-Irp-Debug
X-Loc
X-Minions-Version
X-Rocket-Nginx-Serving-Static
X-S-Maxage
Cache-Host
Canary
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
Apple-News-Services-Handled
Apple-News-Services-Host
Candidate-Md5Url
X-Device-Os
Click-Count-Error
CloudFront-Viewer-Country
Click-Count-Action-Start
Wxu-Next-Hostname
Wxu-Next-Commit
X-AOL-HN
X-SIPLIST1
X-Epic-Correlation-Id
We-Hiring
X-Esi-Check
X-Eu-Site
X-SB
Cluster
Web-Mar-Region
X-Dispatcher-Number
X-Sigma-Backend
X-DPWN-IS-SECURE
X-Ec-Custom-Error
X-Sigma
Server-Host
X-Tx-Id
X-Gateway-Request-Id
X-Scheme
X-Slack-Backend
X-Scale
X-Region-Sid
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Sn-Servicetimems
X-SVT-ORM-RULES
X-Forwarded-Site
X-Origin
X-Clientip
DSUID
X-SVT-ORM-VERSION
X-V-Cache
X-Planisys-CDN-Cache
X-Hnp-Log
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
X-Core-Mission
X-Cdn-Origin
X-Branch-Name
X-CacheTTL
X-Datadog-Trace-Id
X-Fastly-Backend
X-Gen-Mode
X-Hash
X-Gateway-Skip-Cache
X-Gateway-Cache-Status
X-Gamma-Serve
X-Gateway-Cache-Key
X-Block-Status
X-Mvc-Supplant-OutputCached
Server-Ext
Server-Hostname
Sever-Int
CPC-Cache
Country-Code
CDCHOST
Cmsid
Cmstype
State
CPC-Age
V-Age
VNS-Age
User-Cache-Control
VNS-Cache
Vix-Hermes-Req-Id
X-CSRF-Token
Sid
X-Udemy-Cache-App-Namespace
X-Debug-Cache
X-IPS-LoggedIn
Ec-Rule-Version
X-LB-NoCache
Memory
X-URL
Time
Svr
X-Dispatch
X-Akamai-Transformed
X-Newrelic-App-Data
LB
Pics-Label
X-Edge-Pop
X-Up
X-Nf-Request-Id
Ssr
X-Tb-Optimization-Total-Bytes-Saved
HostName
X-B3-Spanid
X-Req
X-VC
Request-ID
AMP-Access-Control-Allow-Source-Origin
X-Cs
X-Presslabs-Stats
X-ND-Cache
X-ZONE
My-App
X-Servedbyhost
X-Generated-In
Env
True-Client-Country-4JS
X-NGINX-Cache
X-Refresh
X-Wa
X-Lambda-Id
CacheControlHeader
X-Vc
X-WA-Info
Cache-Tv-Group
GeoIp-Country-Code
X-B3-SpanId
X-Via-Popv
Fastcgi-Cache-TTL
X-Datadome
X-Via-Popn
X-Via-Poph
X-Via-NSCOPI
X-GG-Cache-Date
X-Zone
Hostname
True-Client-IP
Server-ID
X-Session-Fingerprint
X-Op-Id-All
X-EC-Lua
X-PX
X-ID
SID
X-Release
X-Rebelmouse-Surrogate-Control
X-Origin-Expires
X-Pod-Name
X-Rebelmouse-Cache-Control
X-Fastly-Cache
Cache-Hits
X-VCL-Version
X-GeoIP-Country-Code
X-Fpc
X-LB-ID
X-Xrds-Location
X-Trace-ID
X-GeoIP-Region-Code
X-NWS-UUID-VERIFY
X-CACHE-AGE
WWW-Authenticate
X-TX-ID
X-CSRF-TOKEN
X-Webkit-CSP-Report-Only
X-Srv
X-Date
X-Accel-Expires-Debug
X-TH-Server
Fastly-Drupal-Html
X-CACHE-KEY
X-Buckets
X-MSEdge-Features
X-Cache-Date
CDN
X-Old-Content-Length
X-MSEdge-Flight
X-Ig-Push-State
X-TRACE-ID
X-RAMCache
X-Varnish-Beresp-TTL
X-NC
X-HS-Status
X-DC
X-Endurance-Cache-Level
Resin-Trace
X-Conf
X-Microcachable
Powered-By
X-Dmc
X-RateLimit-Reset
Tcn
X-MCACHE
X-CS
Section-Io-Id
Section-Io-Origin-Time-Seconds
Path
X-Location
X-Lb-Id
X-Vcl-Version
Section-Io-Origin-Status
X-Webstats-RespID
Section-Origin-Responded
X-API-Version
Magicmarker
X-Director
X-FPC
X-Varnish-Authentication
X-Cache-ASPX
X-Contensis-Viewer-Groups
X-DataCenter
X-Akamai-Pragma-Client-IP
True-Client-Ip
X-Check-Cacheable
X-Cache-Ttl
X-LiteSpeed-Cache-Control
X-CLOUD-TRACE-CONTEXT
Yjs-Id
X-Alfa-Service
Lb
X-Wikidot-Static-Cache
X-Wikidot-Backend
X-Datacenter
X-Test
Server-Id
GeoIP-Country-Code
X-Esi
X-Via-PopH
XServer
FSS-Cache
X-Vercel-Id
X-Mly-Id
Proxy-Connection
X-Via-PopV
X-Cache-Backend
X-Vercel-Cache
X-Via-CDN
X-Via-PopN
M-TraceId
X-Server-IP
X-WA
X-Cache-Expires
X-Be
X-Geo
X-ApacheServer
YJS-ID
X-PERF
X-Cc-Via
ENV
X-Micro-Cache
Pramga
Cdn
X-We-Are-Hiring
X-ServedByHost
User-Agent
X-Hyper-Cache
X-Response-By
X-Dw-Trace-Id
X-Cdn-Forward
X-Info
X-CF-Lambda-Version
X-CF-Lambda-Fn
XM
X-Frame-Option
X-Client-Ip
X-HA-Backend
Uri
X-M-Reqid
X-M-Log
HIT
X-Edge-POP
X-Service-Response-Time
Sm-Log-Id
X-AIR-PT
X-UA
X-LiteSpeed-Tag
X-Traceid
X-Li-Pop
Location
X-LI-Proto
X-Li-Fabric
Swift-Performance
X-Qnm-Cache
X-TT-LOGID
X-Instance-Name
X-VarnishDD-TTL
X-App
X-From
X-Akamai-ERRuleID
X-Akamai-ERPolicy
Srvid
Locid
Tracecode
X-FL-EDGE
X-LI-UUID
X-HN
Dnion-Transfer-Encoding
PFcat
X-TrackingId
Geoip-Latitude
X-DSS
X-DW
Cneonction
X-Oss-Object-Type
X-Oss-Request-Id
X-Oss-Storage-Class
X-Oss-Server-Time
CF-Cached-On
X-RSL
X-DI
X-Oss-Hash-Crc64ecma
Cache-Key
X-RPM
X-RPS
X-Air-Hostname
X-Platform
X-Air-Trace-Id
C-Via
X-Air-Source
CountryCode
PICS-Label
Nginx-CQVIP
N-Cache
Ohc-File-Size
X-DB
X-Fastly-Backend-Reqs
X-Wp-Cf-Super-Cache
X-Wp-Cf-Super-Cache-Cache-Control
X-Platform-Router
X-Cache-Proxy
X-Platform-Cluster
X-Request-Url
NtCoent-Length
Esi-Enabled
X-Platform-Processor
X-Conten-Type-Options
Timeexpire
X-Lb-Nocache
X-LAGOON
Wpo-Cache-Status
X-Cdn-Request-ID
X-SD-PageType
X-Ha-Backend
X-CF-Powered-By
X-Fastly-Cache-Hits
X-UP
X-HostName
Create-Date
Vha6-Origin
Wpo-Cache-Message
Wp-Super-Cache
X-Ips-Loggedin
X-Litespeed-Cache-Control
X-Air-Pt
X-Cache-Ngx
Warning
X-Newegg-Index
X-NFL-Dma
X-NFL-Geo
X-PGF-Deflate
X-Newegg-Flow
X-PageType
X-Matome-Cached
X-MTS-Cache
X-N-OperationId
X-Nerd
X-NS-Authorization
X-Ntj-Investigation-Id
X-Okws-Version
X-Onedio-Env
X-Origin-Ops
X-Matched-Rule
X-OVcl-Cache
X-Odoo-Frontend
X-PG-ACCESS
X-Paywall
X-NXG
X-Nyt-Data-Last-Modified
X-OVcl
X-Header-Sub
X-Pver
X-Fstrz
X-Full-Ttl
X-GG-Cache-Status
X-Fastly-Is-Edge
X-Farm
X-Eid
X-ETag
X-Eventloop-Lag
X-F-Status
X-Git-Commit
X-Global-Transaction-ID
X-Kebab
X-Kebabable
X-Keep
X-LbNode
X-Ittl
X-Is-SSL
X-GoCache-CacheStatus
X-Group
X-IBD-Cache
X-IBD-SID
X-Loadbalancer
X-SVR-IIS
X-Ver
X-Vary-Devices
X-Wag-Acs
X-Waitingroom
X-Web-Hosting
X-V2-Infrastructure
X-Utime
X-True-Client-Ip
X-U-Cache
X-Upstream-State
X-User-Auth
X-WP-Bypass
X-WSR2
Fastcgi-X-Cache-Version
X-CUA
Hit
On-Server
X-Request-URL
X-Fastly-Country-Code
X-B3-Parentspanid
X-Xms-Page-Cache-Actions
X-YSpaceId
XV-Cache
XV-H
X-Tried-To-Kebabify
X-Toujours-Debout-Location
X-Ruby
X-Route-Akamai
X-Save-Cache
X-Server-L
X-ServiceName
X-Route
X-Request-Origin
X-Reboot
X-Redis
X-Render-Method
X-Render-Time
X-Sh
X-Site
X-Svr-Proxy
X-Test-Nginx-Ingress
X-Timestamp
X-Toujours-Debout-Branch
X-Ee-Request-Id
X-Stack-Name
X-Slack-Shared-Secret-Outcome
X-SMP-JWT
X-Square
X-SSLProxy
X-R-Cache
X-Cms-Device
Ns-Ua
Ns
Ok-Cache-Status
OK-Edge-Date
Origin-Site
Ok-Edge-Key
Npm-Remaining
Npm-Cost
Joe-X
Is-Https
NB-ESI
Nikkei-App-Version
NLCacheNote
Panzer-Cache-Control
Proxy-Cache
SFRVia
Service-Uuid
Shieldsquare-Response
SII
Store-Cloud-Cache
Served
Selected-Route
Region
RawURL
Request-Uuid
Rt-Proxy-Cache
Scheme
HTTPProtocol
HServer
X-Yottaa-OS
X-ElasticPress-Query
X-PAYTM-SRV-ID
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
Req-ID
X-Mg-Cache
DynaTrace
SRV
WZWS-RAY
X-B3-ParentSpanId
Fastcgi-Cache-Ttl
X-Serial
X-Th-Server
CMS-200
Cluster-Host
Deeplink
Ec-Policy-Id
H1
Cf-Wrk
Cf-Locale
Cache-Stat
Akamai-X-Url
Cachekey
Cdn-Country-Code
Cf-Device-Type
Sw
T-Request-Id
X-Cache-Reason
X-Cache-NPR
X-Cache-ReqUri
X-Cache-Response
X-CDN-Pop
X-CacheVersion
X-Cache-Length
X-Cache-IsMobileDevice
X-Backside-Transport
X-Backend-TTL
X-BeanStalkRole
X-BeanStalkStage
X-Cache-Cookie
X-CDN-Pop-IP
X-Cf-Node-Idx
X-DT-Node
X-Doge
X-Edge-IP
X-Ee-Generated-By
X-Ee-Origin
X-Developed-By
X-Delivery
X-Colour
X-Coindesk-Cache
X-Container-Uri
X-Dcm-Pdtf
X-Dehri-Date
X-AspNetWebPages-Version
X-ASF-Cache
Userver
Uniqueid
Vttl
X-77-NZT
X-77-NZT-Ray
TWC-Unit
TWC-Subs
Time-Cloud-Cache
Technodrome
Ttl
TWC-AK-Req-ID
TWC-PATH-LOCALE
X-Accel-Version
X-Accepted-Fulllang
X-Apache-Server
X-Amz-Meta-Cb-Modifiedtime
X-Ar-Stats
X-Arena-Request-Id
X-ARRRG1
X-Akamai-Native
X-Akamai-DeviceType
X-Accor-Asset
X-Accepted-Language
X-AEO-Platform
X-Akamai-CacheKeyMod
X-Akamai-DeviceOS
X-Ee-Request-Date