Threat Level: green Handler on Duty: Guy Bruneau

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
Strict-Transport-Security
X-Frame-Options
X-Content-Type-Options
Link
Last-Modified
CF-Cache-Status
Cf-Request-Id
Accept-Ranges
ETag
CF-RAY
Expect-CT
Pragma
X-Powered-By
X-Cache
Via
Age
X-XSS-Protection
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
X-Xss-Protection
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-FRAME-OPTIONS
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-Adblock-Key
X-AspNet-Version
X-Permitted-Cross-Domain-Policies
Alt-Svc
X-Runtime
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Request-ID
X-DNS-Prefetch-Control
X-Cache-Status
X-Check
X-Generator
CF-Ray
X-Cacheable
X-Iinfo
X-Envoy-Upstream-Service-Time
P3p
Timing-Allow-Origin
Feature-Policy
X-Content-Security-Policy
Status
X-Drupal-Dynamic-Cache
Content-Encoding
Access-Control-Expose-Headers
X-AspNetMvc-Version
X-CDN
Upgrade
X-Ua-Compatible
Access-Control-Max-Age
X-Via
X-Robots-Tag
X-Cache-Group
Server-Timing
X-UA-Device
X-Dns-Prefetch-Control
Keep-Alive
Request-Context
X-AH-Environment
X-Turbo-Charged-By
X-Amz-Request-Id
X-Proxy-Cache
X-Backend
X-Amz-Id-2
X-Age
X-Ws-Request-Id
Host-Header
X-Hacker
X-Server-Powered-By
X-Server
X-Rq
X-Varnish-Cache
X-Vhost
X-LiteSpeed-Cache
Grace
X-Amz-Version-Id
Cf-Edge-Cache
X-Dispatcher
EagleId
Allow
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
X-Page-Speed
Accept-CH
X-Nginx-Cache-Status
X-WebKit-CSP
X-Swift-CacheTime
X-Swift-SaveTime
X-Aws-Lambda-Call-Status
Ali-Swift-Global-Savetime
Cf-Railgun
X-Host
X-Node
X-Pingback
X-Cache-Spec
X-OneAgent-JS-Injection
X-Backend-Server
X-Akam-SW-Version
Surrogate-Control
X-Server-Id
Request-Id
Accept-CH-Lifetime
X-Cache-Lookup
X-Response-Time
EagleEye-TraceId
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Readtime
Content-Location
X-HW
X-Cloud-Trace-Context
X-Content-Security-Policy-Report-Only
X-Application-Context
Rating
X-Trace
Fastly-Restarts
X-Url
X-Akamai-Path-Stats
X-WebKit-CSP-Report-Only
X-Nginx-Upstream-Cache-Status
X-Clacks-Overhead
X-Ruxit-Js-Agent
X-CST
X-MS-InvokeApp
X-Edge
X-Amz-Server-Side-Encryption
X-Rack-Cache
X-Oneagent-Js-Injection
X-Country
X-Vname
X-PC
X-TtlSet
X-Mod-Pagespeed
Edge-Control
X-Content-Type
X-ESI
X-Vcap-Request-Id
X-B3-TraceId
Cf-Apo-Via
X-FastCGI-Cache
Accept-Ch-Lifetime
X-Ttl
X-D2id
Verso
X-Kinja-Revision
Xkey
X-Kinja-Server
X-GitHub-Request-Id
X-Cdn-Fetch
X-Kinja
X-GoogleNews-Bot
X-Exp-Variant
X-Exp-Id
X-Kinja-Build
X-Mcache
X-Use-Magma
Cache-Tag
Service-Worker-Allowed
X-Powered-By-Plesk
X-Amz-Rid
X-ECACHE
X-Varnish-TTL
RTSS
X-Server-Name
X-Abt-Application-Version
X-VARITI-CCR
X-Navigation-Version
X-Version
X-Client-IP
X-Ac
X-Upstream
X-Cnection
X-Cached
X-Element-Page-Cache
Arr-Disable-Session-Affinity
X-Dw-Request-Base-Id
X-Server-Lifecycle-Phase
X-Ruxit-JS-Agent
X-Instrumentation
X-Kraken-Loop-Name
X-RateLimit-Remaining
SPRequestGuid
Permissions-Policy
X-SharePointHealthScore
X-Px
SPRequestDuration
SPIisLatency
X-Cache-TTL
X-Sol
X-NWS-LOG-UUID
X-Middleton-Display
Pagespeed
Display
Public-Key-Pins
X-Country-Code
Response
X-Middleton-Response
X-Midtier
X-Cache-Key
X-Kinsta-Cache
X-Ser
X-Edge-Location-Klb
X-Forwarded-For
X-SRCache-Store-Status
X-Goog-Hash
X-SRCache-Fetch-Status
Content-MD5
X-DataDome
X-Correlation-Id
X-Shield-Request-Id
X-RateLimit-Limit
Access-Control-Request-Method
Front-End-Https
X-Jurisdiction
X-HP-Trace-Id
X-HP-Webp
X-MSEdge-Ref
Mrf-Cache-Status
X-NF-Request-ID
X-B3-TraceId-Primal
MRF-Tech
AR-PoweredBy
AR-Request-ID
AR-CACHE
AR-ATIME
AR-SID
X-Recruiting
X-T
Edge-Cache-Tag
MicrosoftSharePointTeamServices
TP-L2-Cache
TP-Cache
X-Daa-Tunnel
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
Nginx-Cache
X-Accel-Expires
X-Mg-S
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Browser-Type
X-Content-Digest
TCN
X-Powered-CMS
X-Grace
X-Hits
X-Request-Received
X-Request-Processing-Time
X-HS-Cache-Config
X-Amzn-Trace-Id
X-HS-Combine-CSS
X-HS-Content-Id
Server-Name
X-HS-Hub-Id
Server-Node
X-XRDS-Location
Filters
X-Id
MS-Author-Via
Fastcgi-Cache
X-Geo-Country
Count-Hit
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-TEC-API-ROOT
X-Webkit-Csp
X-Frontend
X-Distributor
X-Origin-Server
X-Ua-Browser
X-Ezoic-Cdn
Filterid
Cross-Origin-Opener-Policy
X-LLID
X-PressLabs-Stats
S
X-Fastly-Request-Id
X-Request-Handler-Origin-Region
X-Language
X-Microsite
X-Forwarded-Proto
X-Seen-By
Charset
Payment
X-Git-Hash
X-Protected-By
X-FB-Debug
X-LB-Cache
X-F-Cache
Host
X-B3-Sampled
X-Page-Id
X-ASPNET-VERSION
X-VCache
X-Amz-Meta-S3cmd-Attrs
Cache-Status
X-Ratelimit-Reset
X-Cluster-Name
X-Rid
Surrogate-Key
X-Ab
X-Www-Served-By
Cache-Tags
Access-Control-Allow-Method
X-Upgrade-Enabled
X-Logged-In
Realpath
X-DIS-Request-ID
Alternate-Protocol
X-Origin-Cache
Accept-Charset
Retry-After
X-Source
X-Varnish-Backend
Accept-Ch
X-COUNTRY
X-Cache-Age
X-NGENIX-Cache
X-Fastcgi-Cache
X-Flags
X-Is-Crawler
X-Providence-Cookie
X-Route-Name
X-Varnish-Grace
X-AppVersion
X-Activity-Id
X-Request-Guid
X-App-Environment
X-Az
X-Amz-Replication-Status
X-Template
X-Aspnet-Duration-Ms
X-Wix-Request-Id
X-Type
X-Envoy-Decorator-Operation
X-Litespeed-Cache
X-Tb
Cleartype
X-B-Cache
X-Signature
DC
X-TT
Paypal-Debug-Id
X-B
X-Fastly-Request-ID
X-Hostname
X-Revision
X-DynaTrace
X-Kong-Proxy-Latency
Frame-Options
X-Contextid
ServerID
X-Kong-Upstream-Latency
X-Cache-Rule
X-Drupal-Cache-Tags
X-Node-Name
X-Tt-Trace-Tag
X-Tt-Trace-Host
Pinterest-Generated-By
Pinterest-Version
X-Pinterest-Rid
Amp-Access-Control-Allow-Source-Origin
Cross-Origin-Resource-Policy
Refresh
X-Proxy
X-Goog-Generation
X-Goog-Stored-Content-Length
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-GUploader-UploadID
X-Goog-Storage-Class
Referer-Policy
X-Debug
X-Mobile
X-Load-Cache
X-Content-Options
Node
X-Trace-Id
X-EdgeConnect-Cache-Status
X-Response-Served-From
X-Original-Request-Id
NGB
X-Cache-Control
X-Varnish-Server
X-N
Country
X-Magnolia-Registration
X-Varnish-Age
X-NYM-Debug-Backend
X-Whom
Viewport
X-Debug-IsConnected
X-Adobe-Loc
X-Is-Bot
X-Cache-Time
X-Page-View
X-Rendered-As
X-Content-Powered-By
X-Debug-IsPreview
X-G
Uber-Trace-Id
X-Adobe-Content
Akamai-GRN
X-Servername
X-Instance
X-RemovedCookies
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Framework
X-ProcessESI
X-Real-IP
Url
X-Cacheable-TTL
X-Cache-Grace
Content-Disposition
X-Environment-Context
Access-Control-Request-Headers
X-L-Path
X-Akamai-Request-ID2
X-Status
X-Cache-TTL-Remaining
Srv
VIX-Pulpo-Upstream-Status
X-Server-ID
VIX-Pulpo-Node
X-Jobs
X-Mid
X-User-Agent
X-Cache-Expired-At
X-Via-JSL
X-Oracle-Dms-Ecid
X-Oracle-Dms-Rid
Healthy
X-Cache-Hit
Countrycode
X-Tumblr-Pixel-1
X-CDN-Forward
X-Tumblr-User
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-XRDS-LOCATION
X-Cache-Operation
X-Drupal-Cache-Contexts
X-Unique-Id
Version
X-TTL
Accept-Language
X-Rule
X-Backend-Name
X-Debug-Info
X-Akamai-Edgescape
X-APP-VERSION
X-Http-Reason
X-Mg-Request-UUID
X-Cache-Action
X-Time
Section-Io-Cache
Xserver
X-VC-Cache
Content-Secure-Policy
X-IPLB-Request-ID
X-IPLB-Instance
X-Hosted-By
Protected
X-B3-Traceid
X-Tt-Logid
Server-Info
X-Azure-Ref
X-HTML-Minification-Powered-By
X-Generation-Time
Backend
X-Generated-By
X-FW-Type
X-FW-Hash
X-FW-Static
X-FW-Server
X-FW-Dynamic
X-FW-Serve
X-Storage
X-UPSTREAM-Address
X-App-Server
Meta-Geo
X-Api-Version
X-RN-RSRV
X-Cache-Status-Check
X-Device-Type
X-Mobile-URL
Liferay-Portal
CF-IPCountry
X-SRV
GEO-INFO
X-Varnish-Cache-Hits
X-LJ-Flow-ID
X-Content
X-Labrador-Cache-Channel
X-JoinUs
X-Section
X-RTag
X-OCL
Webcakes-App-Version
Property-Id
Ms-Operation-Id
MS-CV
Webcakes-App-Name
TWC-Connection-Speed
TWC-Locale-Group
TWC-GeoIP-LatLong
TWC-GeoIP-Country
TWC-Device-Class
Webcakes-Region
X-Access
Azure-InstanceId
X-Format
X-Handled-By
X-Origin-Hint
Azure-RegionName
Azure-SiteName
X-Cms-Context
Azure-Version
Azure-SlotName
X-PCL
TWC-Privacy
X-Redis-Cache
X-R9-Blue-Green-Version
X-Proxy-Cache-Status
X-SayCDN-TTL
X-Say-TTL
X-VWS-Id
X-Say-Cacheable
X-SaId
X-Varnish-Hostname
X-Cache-Server
X-PHP-Host
X-Sql-Duration-Ms
X-No-Session
X-AWS-Id
X-Sql-Count
X-Restarts
X-Adobe-Source
X-Site-Version
X-Varnish-Beresp-Grace
X-Detected-As
X-Urbn-Site-Id
X-Cache-Type
Web-Mar-Node
Mn-Server-Ip
X-Skip-Cache
X-Content-Age
X-GeoCountry
X-UA-Device-Type
X-FireWall-Port
X-Via-Fastly
X-Edge-Location
X-Web-Node
CDN-EdgeStorageId
CDN-CachedAt
CDN-Cache
X-GeoCode
DB-Nickname
CDN-PullZone
CDN-RequestId
X-Ms-Version
CDN-RequestCountryCode
CDN-Uid
Cache-Name
X-Varnishpool
Locale
X-Forwarded-Host
X-Ms-Request-Id
X-Locale
X-Xfnlog-Site
X-Provided-By
X-Proto
X-Server-W
X-Region
X-Request-Time
X-FB-TRIP-ID
X-Urbn-Context-Path
X-Amz-Apigw-Id
X-Mode
X-Amzn-RequestId
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Shopify-Stage
X-Nginx-Cache-Key
X-ProxyCache-Key
Apigw-Requestid
X-Zipkin-Id
X-BYPASS-REASON
X-ProxyCache-Status
X-ShopId
X-Cache-Host
X-Proxied
X-PHP-Backend
X-Extlb
X-Routing-Service
Eomportal-Instance
Onion-Location
X-ShardId
X-Alternate-Cache-Key
X-Storefront-Renderer-Rendered
X-Tid
Load-Balancing
WP-Super-Cache
S-Rt
X-Hl-Ver
X-Timing-Wait
X-Tec-Api-Root
X-Tec-Api-Origin
X-Proxy-Build
X-Tec-Api-Version
Selected-Fe
X-WP-CF-Super-Cache-Cache-Control
X-Vgn-Hpd-Reason
X-ServerID
X-ECache
X-WP-CF-Super-Cache
X-Cache-Enabled
X-TNCMS
X-LSADC-Cache
X-Reqid
X-Loop
X-DynaTrace-JS-Agent
X-Dc
X-Cdn
X-Amzn-Remapped-Content-Length
X-Varnish-Ttl
X-Pubstack
X-Uri
X-Soup
X-TIME
X-Origin-Date
X-Ua
X-Zen-Fury
X-Tumblr-Pixel-2
Fastcgi-Useragent
X-Newrelic-Synthetics
Xet-Cookie
X-Cache-NGX
From-Origin
X-Service
X-Cache-Debug
X-Aspnetmvc-Version
X-App-Version
X-Correlation-ID
X-Ratelimit-Remaining
ServedBy
X-Origin-CC
X-Origin-TTL
Source
X-Varnish-Hits
X-GEO
X-Webkit-CSP
Origin
X-UUID
X-Nginx-Cache
X-MP-GENERATED-AT
X-Human
X-NewRelic-App-Data
X-URL
X-TA-CDN-Provider
Fastly-Drupal-HTML
Cache
X-Varnish-Beresp-Ttl
X-Cache-Tags
X-Cached-By
Webserver
Upgrade-Insecure-Requests
Cross-Origin-Window-Policy
X-Rewrite-Enabled
Rip
X-Cluster
Rendered-Blocks
BehaviorPad-Version
X-ScT
MD5-Digest
WPO-Cache-Message
X-Ratelimit-Limit
WPO-Cache-Status
X-VG-WebCache
X-A
X-Cache-NE
X-Connection-Hash
X-D
Odigeo-Trace-Id
DCR-Decision-By
X-BCube-Filmed-By
Ngx.Var.Host
X-Bc-Bl
X-Forwarded-Path
Expiry
X-Vdms-Version
X-S-Cookie
X-Destination
SD-X-WS
X-External-Request-Id
X-Ec-Fail
X-Ec-GeoHdr
DCR-Processing-Time-Ms
Sslversion
Surrogated-Key
X-Rojux
X-Developer
X-Shop-Environment
T-Server
Xc-Version
X-S
Mime-Version
X-Vdms-Path
X-Parent-Response-Time
X-A-Dcw
X-A-Dgt
X-A-Wwc
X-Aed
X-SRCache-Key
X-User
X-PBS-Appsvrname
X-Tenant
X-A-Ccd
X-TIM-N
X-Processor
X-A-Dam
X-Orig-Expires
Lang
Meta-Geo-Continent
Cdncip
X-B-Cookie
Cdnsip
X-ARC
X-NAPM-TraceId
A
X-Application
X-RCS-CacheZone
X-AK-Request-ID
OT-Force-Account-Verify
Host-ID
X-Request-Host
X-FW-Version
X-Served-From
X-Aicache-OS
X-Gdpr
Redirect-Candidate
X-Accel-Buffering
Environment
X-Origin-Time
X-Cluster-Node
X-Nyt-Route
X-AOL-HN
X-WP-CF-Super-Cache-Active
LB
Memcached
Mail-Subject
Wxu-Next-Commit
NGX
Wxu-Next-Hostname
Fastly-SIE
Wxu-Next-Region
Kp-EeAlive
IsBot
Is-Eu
Datacenter
Fastly-SSL
L
We-Hiring
Machine
VNS-Cache
Traceparent
Tube-Get-Contents
Origin-EX
Platform
Producers
Req-Svc-Chain
Fastly-SWR
Svr
Origin-CC
Decoy-Debug-Status
VNS-Age
Servername
NM-Fastcgi-Cache
Tube-Return
Decoy-Debug-TTL
Tube-Got-Eval
Tube-Got-Results
Fastly-GeoIP-CountryCode
X-DPWN-IS-SECURE
X-Owner
X-Origin-Response-Time
X-Varnish-Beresp-Status
X-Variation
X-Platform-Server
X-Varnish-CookieHashed-On
X-NodeID
X-Varnish-Remaining-TTL
X-Loc
X-Minions-Version
X-NCache
X-Varnish-CookieINHashed-On
X-Pool
X-Qloud-Router
X-Rocket-Build-Number
X-Request-URI
X-Rocket-Nginx-Serving-Static
X-S-Maxage
X-SB
X-Sigma
X-Sigma-Backend
X-SplitTest
X-RateLimit-Limit-Second
X-SIPLIST1
X-RateLimit-Remaining-Second
CPC-Cache
X-Gzip
X-DefElseHash
X-Clara-WADP
X-DefHash
X-Device-Os
X-Dispatcher-Number
X-Ckpd-Fst-Backend
X-Cache-Info
X-Azure-Ref-OriginShield
X-ATG-Version
X-BBC-Edge-Cache-Status
X-Cache-Bucket
X-Cache-Id
X-Ec-Custom-Error
X-GeoIP-City
X-Viewer-Country
X-VServer
X-Fmm-Version
X-VG-TLSProxy
X-GeoIP
X-WADP-Cache
X-Wix-Viewer-Type
X-Epic-Correlation-Id
X-Esi-Check
X-Fetched-On
Release
X-Ad-Defer-Variation
Decoy-Debug-Key
X-Nf-Request-Id
Canary
Candidate-Md5Url
Click-Count-Action-Start
Cache-Host
X-Pass-Why
Adler-Geo
Apple-News-Services-Handled
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
CPC-Age
Apple-News-Services-Host
Cluster
CloudFront-Viewer-Country
X-Debug-Cache
Click-Count-Error
X-Sucuri-Cache
Fastly-Backend-Name
X-Sucuri-ID
X-Thinkindot-L3
X-Geo-Header
X-Has-Esi
TDXMobile
X-Level-Front-Cache
X-Is-Gdpr
X-INCAP-ABP
X-JWT-State
X-Tx-Id
X-HS-Content-Campaign-Id
X-Worker
AKAMAI
X-Tumblr-Pixel-3
X-CMSURLCustom
X-Generated-On
X-Developers
X-Core-Value
X-Auto-Login
X-Cache-Remote
X-Cdn-Srv
X-Optimistic-Header
Thinkindot-CacheControl
Thinkindot-Control
Thinkindot-CacheControl-Type
X-Thanos
Web-Mar-Region
X-Scheme
X-Hnp-Log
X-Gen-Mode
X-Fastly-Backend
X-Forwarded-Site
X-Gamma-Serve
X-Gateway-Cache-Key
X-Block-Status
X-Branch-Name
X-SVT-ORM-RULES
X-Sn-Servicetimems
X-Slack-Backend
X-Gateway-Cache-Status
X-Gateway-Request-Id
Ha-Gx-Prefs
HA-Ipaddr
L5d-Success-Class
Gh-Request-Id
X-Hash
X-Gateway-Skip-Cache
Vix-Hermes-Req-Id
X-CacheTTL
X-Var-Ttl
X-Origin
X-V-Cache
X-Proxy-Cache-Info
X-Irp-Debug
Mobile-Detection-Method
X-Clientip
X-Planisys-CDN-Rules
X-FC-Vary-Parameters
X-Planisys-CDN-TTL
CDCHOST
X-Datadog-Sampling-Priority
X-Mvc-Supplant-Cachable
Cmstype
Country-Code
Cmsid
DSUID
X-Core-Mission
X-Region-Sid
V-Age
X-Eu-Site
X-Scale
X-Datadog-Parent-Id
X-Udemy-Cache-App-Namespace
X-Cdn-Origin
X-CGP
User-Cache-Control
X-Bip
X-Planisys-CDN-Cache
State
Server-Ext
X-Csrf-Jwt
X-Policy
X-Datadog-Trace-Id
Server-Hostname
Sever-Int
X-SVT-ORM-VERSION
X-Presslabs-Stats
X-IPS-LoggedIn
Server-Host
Time
X-Up
X-Mvc-Supplant-OutputCached
Memory
X-LB-NoCache
X-Datadome
WebServer
X-CSRF-Token
HostName
X-ZONE
X-Dispatch
Ec-Rule-Version
Pics-Label
X-Akamai-Transformed
X-VC
Ssr
X-Tb-Optimization-Total-Bytes-Saved
Sid
X-Refresh
X-Newrelic-App-Data
X-ND-Cache
X-Trace-ID
Request-ID
X-Edge-Pop
AMP-Access-Control-Allow-Source-Origin
My-App
X-Servedbyhost
X-Via-Popn
X-Req
X-Via-Popv
Env
X-B3-Spanid
X-Via-Poph
X-Via-NSCOPI
X-WA-Info
Cache-Tv-Group
X-B3-SpanId
Fastcgi-Cache-TTL
X-VHOST
X-Lambda-Id
X-Generated-In
X-GG-Cache-Date
SID
Server-ID
X-NGINX-Cache
X-Wa
X-Cs
True-Client-Country-4JS
X-Session-Fingerprint
X-CACHE-AGE
X-Fastly-Cache
X-Pod-Name
X-Rebelmouse-Surrogate-Control
X-Origin-Expires
X-Rebelmouse-Cache-Control
Cache-Hits
GeoIp-Country-Code
X-Fpc
X-Release
CacheControlHeader
X-Vc
X-EC-Lua
X-PX
X-Op-Id-All
X-LB-ID
X-ID
True-Client-IP
Hostname
X-VCL-Version
X-DC
X-CSRF-TOKEN
X-Xrds-Location
X-MCACHE
X-Zone
X-NWS-UUID-VERIFY
X-TX-ID
X-GeoIP-Country-Code
X-GeoIP-Region-Code
X-Webkit-CSP-Report-Only
X-TH-Server
X-MSEdge-Features
WWW-Authenticate
X-Ig-Push-State
X-Cache-Date
X-MSEdge-Flight
X-CACHE-KEY
X-Buckets
Resin-Trace
X-RateLimit-Reset
X-Endurance-Cache-Level
X-Accel-Expires-Debug
X-HS-Status
X-Conf
X-NC
X-Date
X-TRACE-ID
X-Microcachable
X-RAMCache
X-Old-Content-Length
X-Srv
X-Dmc
CDN
X-CS
X-Esi
Fastly-Drupal-Html
Powered-By
X-Vcl-Version
Tcn
Magicmarker
True-Client-Ip
X-Varnish-Beresp-TTL
Path
X-Check-Cacheable
X-Webstats-RespID
X-API-Version
X-Wikidot-Static-Cache
Section-Origin-Responded
X-Akamai-Pragma-Client-IP
X-Alfa-Service
Section-Io-Origin-Status
X-Location
X-Wikidot-Backend
X-Lb-Id
GeoIP-Country-Code
Section-Io-Id
Section-Io-Origin-Time-Seconds
X-Director
X-LiteSpeed-Cache-Control
X-Be
X-CLOUD-TRACE-CONTEXT
Yjs-Id
X-Cache-Ttl
X-FPC
Proxy-Connection
X-Datacenter
X-Vercel-Cache
X-Vercel-Id
X-DataCenter
X-Cache-ASPX
X-Contensis-Viewer-Groups
X-Varnish-Authentication
X-Hyper-Cache
X-Micro-Cache
X-WA
FSS-Cache
Pramga
X-Mly-Id
X-Via-CDN
Cdn
X-Geo
X-Cache-Expires
X-HA-Backend
User-Agent
X-ServedByHost
Lb
X-Test
M-TraceId
X-Response-By
ENV
X-Server-IP
Server-Id
X-M-Reqid
X-M-Log
X-CF-Lambda-Version
X-CF-Lambda-Fn
X-Cdn-Forward
X-Dw-Trace-Id
X-Cc-Via
X-Client-Ip
X-Cache-Backend
Uri
X-ApacheServer
Tracecode
X-Akamai-ERRuleID
X-App
X-Via-PopN
X-PERF
X-Akamai-ERPolicy
X-Via-PopV
HIT
X-Qnm-Cache
X-Via-PopH
Sm-Log-Id
X-AIR-PT
X-Service-Response-Time
YJS-ID
X-Edge-POP
C-Via
X-Instance-Name
XM
X-Info
Srvid
X-FL-EDGE
X-TT-LOGID
X-UA
X-Traceid
Swift-Performance
Locid
X-From
N-Cache
X-LiteSpeed-Tag
X-Li-Fabric
X-LI-Proto
Dnion-Transfer-Encoding
X-TrackingId
Geoip-Latitude
X-Li-Pop
X-We-Are-Hiring
X-Air-Trace-Id
Location
X-LI-UUID
X-Air-Hostname
X-Air-Source
XServer
X-DW
X-DI
X-VarnishDD-TTL
X-DSS
X-RPM
X-RSL
X-DB
X-Platform
X-RPS
X-Frame-Option
X-HN
X-Platform-Cluster
X-Platform-Processor
Esi-Enabled
PICS-Label
X-Air-Pt
X-Fastly-Backend-Reqs
CF-Cached-On
CountryCode
Nginx-CQVIP
PFcat
Ohc-File-Size
X-Platform-Router
X-Wp-Cf-Super-Cache-Cache-Control
X-Wp-Cf-Super-Cache
Cneonction
X-Conten-Type-Options
X-Cache-Proxy
Timeexpire
X-HostName
On-Server
X-Cdn-Request-ID
Hit
Fastcgi-X-Cache-Version
X-PAYTM-SRV-ID
Vha6-Origin
NtCoent-Length
X-Request-Url
X-Oss-Storage-Class
X-Fastly-Cache-Hits
X-CF-Powered-By
X-Oss-Server-Time
X-Oss-Hash-Crc64ecma
Wpo-Cache-Message
Cache-Key
X-Oss-Request-Id
Wpo-Cache-Status
X-Lb-Nocache
X-Oss-Object-Type
Warning
X-Ips-Loggedin
Wp-Super-Cache
X-Cache-Ngx
X-Litespeed-Cache-Control
X-Newegg-Index
X-Nerd
X-Newegg-Flow
X-Matched-Rule
X-Loadbalancer
X-LbNode
X-NFL-Dma
X-Matome-Cached
X-MTS-Cache
X-N-OperationId
X-NXG
X-Origin-Ops
X-Keep
X-OVcl
X-OVcl-Cache
X-Onedio-Env
X-Okws-Version
X-NS-Authorization
X-Ntj-Investigation-Id
X-Nyt-Data-Last-Modified
X-Odoo-Frontend
X-NFL-Geo
X-Git-Commit
X-Request-URL
X-F-Status
X-Farm
X-Fastly-Is-Edge
X-Fstrz
X-Eventloop-Lag
X-ETag
X-Ee-Origin
X-Ee-Request-Date
X-Ee-Request-Id
X-Eid
X-Full-Ttl
X-GG-Cache-Status
X-IBD-SID
X-Is-SSL
X-Ittl
X-Kebab
X-IBD-Cache
X-Header-Sub
X-PageType
X-Global-Transaction-ID
X-GoCache-CacheStatus
X-Group
X-Kebabable
X-Route
X-Utime
X-User-Auth
X-V2-Infrastructure
X-Vary-Devices
X-Ver
X-Upstream-State
X-U-Cache
X-Toujours-Debout-Branch
X-Toujours-Debout-Location
X-Tried-To-Kebabify
X-True-Client-Ip
X-Wag-Acs
X-Waitingroom
XV-H
X-B3-Parentspanid
X-Fastly-Country-Code
X-Ee-Generated-By
XV-Cache
X-YSpaceId
X-Web-Hosting
X-WP-Bypass
X-WSR2
X-Xms-Page-Cache-Actions
X-Timestamp
X-Test-Nginx-Ingress
X-Render-Time
X-Render-Method
X-Request-Origin
X-Route-Akamai
X-Ruby
X-Redis
X-Reboot
X-PG-ACCESS
X-PGF-Deflate
X-Pver
X-R-Cache
X-Save-Cache
X-Server-L
X-SSLProxy
X-Stack-Name
X-SVR-IIS
X-Svr-Proxy
X-Square
X-SMP-JWT
X-ServiceName
X-Sh
X-Site
X-Slack-Shared-Secret-Outcome
X-Paywall
Vttl
Ns-Ua
Ns
Ok-Cache-Status
OK-Edge-Date
Ok-Edge-Key
Npm-Remaining
Npm-Cost
Joe-X
Is-Https
NB-ESI
Nikkei-App-Version
NLCacheNote
Origin-Site
Panzer-Cache-Control
Service-Uuid
Served
SFRVia
Shieldsquare-Response
SII
Selected-Route
Scheme
RawURL
Proxy-Cache
Region
Request-Uuid
Rt-Proxy-Cache
HTTPProtocol
HServer
X-ElasticPress-Query
X-Mg-Cache
X-Yottaa-OS
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
X-B3-ParentSpanId
WZWS-RAY
Req-ID
X-CUA
Fastcgi-Cache-Ttl
SRV
DynaTrace
X-Serial
X-Th-Server
CMS-200
Cluster-Host
Deeplink
Ec-Policy-Id
H1
Cf-Wrk
Cf-Locale
Cache-Stat
Akamai-X-Url
Cachekey
Cdn-Country-Code
Cf-Device-Type
Store-Cloud-Cache
Sw
X-Cache-NPR
X-Cache-Length
X-Cache-Reason
X-Cache-ReqUri
X-Cache-Response
X-Cache-IsMobileDevice
X-Cache-Cookie
X-Backend-TTL
X-AspNetWebPages-Version
X-Backside-Transport
X-BeanStalkRole
X-BeanStalkStage
X-CacheVersion
X-CDN-Pop
X-Delivery
X-Dehri-Date
X-Developed-By
X-Doge
X-DT-Node
X-Dcm-Pdtf
X-Container-Uri
X-Cf-Node-Idx
X-CDN-Pop-IP
X-Cms-Device
X-Coindesk-Cache
X-Colour
X-ASF-Cache
X-ARRRG1
Uniqueid
TWC-Unit
Userver
X-77-NZT
X-77-NZT-Ray
TWC-Subs
TWC-PATH-LOCALE
Technodrome
T-Request-Id
Time-Cloud-Cache
Ttl
TWC-AK-Req-ID
X-Accel-Version
X-Accepted-Fulllang
X-Amz-Meta-Cb-Modifiedtime
X-Akamai-Native
X-Apache-Server
X-Ar-Stats
X-Arena-Request-Id
X-Akamai-DeviceType
X-Akamai-DeviceOS
X-Accepted-Language
X-Accor-Asset
X-AEO-Platform
X-Akamai-CacheKeyMod
X-Edge-IP