Threat Level: green Handler on Duty: Guy Bruneau

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
Strict-Transport-Security
X-Frame-Options
X-Content-Type-Options
Link
Last-Modified
CF-Cache-Status
Cf-Request-Id
CF-RAY
Accept-Ranges
ETag
Expect-CT
Pragma
X-Powered-By
X-Cache
Via
Age
X-XSS-Protection
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
X-Xss-Protection
Referrer-Policy
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-FRAME-OPTIONS
X-Served-By
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-Adblock-Key
X-AspNet-Version
X-Permitted-Cross-Domain-Policies
Alt-Svc
X-Runtime
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Cache-Status
X-Check
X-Generator
X-DNS-Prefetch-Control
X-Request-ID
X-Cacheable
X-Iinfo
X-Envoy-Upstream-Service-Time
Feature-Policy
Timing-Allow-Origin
X-Content-Security-Policy
Status
X-Drupal-Dynamic-Cache
P3p
Content-Encoding
Access-Control-Expose-Headers
X-AspNetMvc-Version
X-CDN
X-Ua-Compatible
Upgrade
Access-Control-Max-Age
CF-Ray
X-Dns-Prefetch-Control
X-Via
X-Robots-Tag
X-Cache-Group
X-UA-Device
Server-Timing
Keep-Alive
Request-Context
X-AH-Environment
X-Turbo-Charged-By
X-Amz-Request-Id
X-Proxy-Cache
X-Backend
X-Amz-Id-2
X-Age
X-Ws-Request-Id
Host-Header
X-Hacker
X-Server-Powered-By
X-Server
X-Rq
X-Vhost
X-LiteSpeed-Cache
X-Varnish-Cache
X-Amz-Version-Id
Grace
Cf-Edge-Cache
X-Dispatcher
Allow
EagleId
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Device
X-Page-Speed
Accept-CH
X-Nginx-Cache-Status
X-Aws-Lambda-Call-Status
X-Swift-SaveTime
X-Swift-CacheTime
X-WebKit-CSP
Ali-Swift-Global-Savetime
Cf-Railgun
X-Node
X-Host
X-OneAgent-JS-Injection
X-Pingback
X-Cache-Spec
X-Backend-Server
X-Akam-SW-Version
X-Server-Id
Surrogate-Control
Request-Id
X-Cache-Lookup
X-Response-Time
Accept-CH-Lifetime
EagleEye-TraceId
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Readtime
Content-Location
X-HW
X-Content-Security-Policy-Report-Only
X-Cloud-Trace-Context
X-Application-Context
Rating
X-Trace
X-Url
Fastly-Restarts
X-WebKit-CSP-Report-Only
X-Clacks-Overhead
X-Nginx-Upstream-Cache-Status
X-CST
X-Ruxit-Js-Agent
X-MS-InvokeApp
X-Edge
X-Amz-Server-Side-Encryption
X-Rack-Cache
X-ESI
X-Vname
X-TtlSet
X-PC
X-Mod-Pagespeed
X-Country
X-Content-Type
Edge-Control
X-B3-TraceId
X-FastCGI-Cache
Cf-Apo-Via
X-Oneagent-Js-Injection
Accept-Ch-Lifetime
X-Vcap-Request-Id
X-Akamai-Path-Stats
X-Mcache
X-D2id
Verso
X-GitHub-Request-Id
Xkey
X-Kinja-Build
X-Kinja-Revision
X-Kinja-Server
X-Use-Magma
X-Kinja
X-GoogleNews-Bot
X-Ttl
X-Cdn-Fetch
Cache-Tag
X-Exp-Id
X-Exp-Variant
Service-Worker-Allowed
X-Powered-By-Plesk
X-Amz-Rid
X-Navigation-Version
X-Server-Name
RTSS
X-Abt-Application-Version
X-VARITI-CCR
X-Version
X-Client-IP
X-Ac
X-Upstream
X-Cnection
X-Cached
X-Varnish-TTL
X-ECACHE
X-Element-Page-Cache
X-Ruxit-JS-Agent
Arr-Disable-Session-Affinity
Permissions-Policy
SPRequestGuid
X-Instrumentation
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-SharePointHealthScore
X-Dw-Request-Base-Id
X-RateLimit-Remaining
SPIisLatency
SPRequestDuration
X-Px
X-Sol
X-Middleton-Display
Pagespeed
Display
X-Cache-TTL
Public-Key-Pins
X-NWS-LOG-UUID
X-Country-Code
X-Middleton-Response
Response
X-Midtier
X-Cache-Key
X-Kinsta-Cache
X-Edge-Location-Klb
X-Ser
X-Forwarded-For
X-DataDome
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Goog-Hash
Content-MD5
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-NF-Request-ID
X-Shield-Request-Id
Access-Control-Request-Method
X-Correlation-Id
X-MSEdge-Ref
X-Jurisdiction
X-HP-Trace-Id
X-HP-Webp
Front-End-Https
X-RateLimit-Limit
MRF-Tech
Mrf-Cache-Status
X-B3-TraceId-Primal
X-Webkit-Csp
X-T
X-Recruiting
AR-SID
MicrosoftSharePointTeamServices
AR-ATIME
AR-CACHE
AR-Request-ID
AR-PoweredBy
Edge-Cache-Tag
X-Daa-Tunnel
TP-Cache
TP-L2-Cache
Nginx-Cache
X-Browser-Type
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Accel-Expires
X-Mg-S
X-Content-Digest
TCN
X-Grace
X-Powered-CMS
X-Hits
X-Request-Received
X-Request-Processing-Time
X-Amzn-Trace-Id
Server-Node
X-HS-Content-Id
X-HS-Combine-CSS
X-HS-Cache-Config
X-HS-Hub-Id
Server-Name
Filters
MS-Author-Via
Fastcgi-Cache
X-Id
X-Geo-Country
X-Fastly-Request-Id
Accept-Ch
Count-Hit
X-PressLabs-Stats
X-Frontend
X-XRDS-Location
X-TEC-API-VERSION
X-TEC-API-ROOT
X-Origin-Server
X-Distributor
X-TEC-API-ORIGIN
X-Ua-Browser
X-Ezoic-Cdn
Filterid
Cross-Origin-Opener-Policy
X-LLID
X-Language
Payment
X-ASPNET-VERSION
X-Forwarded-Proto
S
Charset
X-Page-Id
X-Request-Handler-Origin-Region
X-Microsite
X-Seen-By
X-Git-Hash
X-FB-Debug
X-F-Cache
X-Protected-By
Host
X-LB-Cache
X-B3-Sampled
X-Amz-Meta-S3cmd-Attrs
X-Ratelimit-Reset
X-VCache
X-Cluster-Name
Cache-Status
X-Rid
Surrogate-Key
X-Www-Served-By
Cache-Tags
X-Ab
Access-Control-Allow-Method
X-Logged-In
X-Upgrade-Enabled
X-Origin-Cache
X-Source
X-DIS-Request-ID
X-COUNTRY
Realpath
X-Varnish-Backend
Retry-After
X-Cache-Age
Alternate-Protocol
Accept-Charset
X-Az
X-AppVersion
X-Activity-Id
X-NGENIX-Cache
X-Template
Cleartype
X-Amz-Replication-Status
Paypal-Debug-Id
DC
X-Type
X-Aspnet-Duration-Ms
X-Route-Name
X-Wix-Request-Id
X-Request-Guid
X-Varnish-Grace
X-App-Environment
X-Envoy-Decorator-Operation
X-Providence-Cookie
X-Is-Crawler
X-Flags
X-Tb
X-B-Cache
X-Signature
X-TT
X-B
X-Hostname
X-Revision
ServerID
X-DynaTrace
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
Frame-Options
X-Contextid
X-Cache-Rule
X-Drupal-Cache-Tags
X-Trace-Id
X-Node-Name
X-Tt-Trace-Tag
X-Tt-Trace-Host
Refresh
X-Pinterest-Rid
Pinterest-Generated-By
Cross-Origin-Resource-Policy
Pinterest-Version
Amp-Access-Control-Allow-Source-Origin
X-Fastly-Request-ID
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-Goog-Metageneration
X-GUploader-UploadID
X-Goog-Stored-Content-Encoding
X-Proxy
X-Goog-Generation
Referer-Policy
X-Debug
X-Mobile
X-Load-Cache
X-Content-Options
X-XRDS-LOCATION
Node
X-Fastcgi-Cache
NGB
X-Response-Served-From
X-EdgeConnect-Cache-Status
X-Original-Request-Id
X-Varnish-Server
X-Cache-Control
Viewport
X-Magnolia-Registration
X-Varnish-Age
X-Content-Powered-By
Country
Akamai-GRN
X-N
X-NYM-Debug-Backend
X-Cache-Time
X-Instance
X-Debug-IsConnected
X-Debug-IsPreview
X-Whom
X-Adobe-Content
X-G
X-Framework
X-Is-Bot
X-Adobe-Loc
Uber-Trace-Id
X-Rendered-As
X-Status
X-Real-IP
Content-Disposition
X-Page-View
X-Cache-Grace
X-Akamai-Request-ID2
Url
X-Yottaa-Optimizations
X-Cacheable-TTL
X-RemovedCookies
X-Yottaa-Metrics
Access-Control-Request-Headers
X-Servername
X-User-Agent
X-ProcessESI
X-L-Path
X-Environment-Context
VIX-Pulpo-Node
X-Mid
Srv
VIX-Pulpo-Upstream-Status
X-Jobs
X-Cache-TTL-Remaining
X-Cache-Expired-At
X-Via-JSL
Healthy
Countrycode
X-Tumblr-User
X-Cache-Hit
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Rule
X-Unique-Id
X-Cache-Operation
X-CDN-Forward
X-TTL
X-Backend-Name
X-Drupal-Cache-Contexts
X-APP-VERSION
Version
X-Litespeed-Cache
Accept-Language
X-ECache
X-Debug-Info
X-Akamai-Edgescape
X-Cache-Action
Section-Io-Cache
X-Http-Reason
X-Server-ID
X-Mg-Request-UUID
X-Varnish-Ttl
X-VC-Cache
Content-Secure-Policy
X-IPLB-Instance
X-IPLB-Request-ID
Protected
X-Time
X-HTML-Minification-Powered-By
X-Generation-Time
X-Tt-Logid
X-Hosted-By
Xserver
Backend
Server-Info
X-Azure-Ref
X-Oracle-Dms-Ecid
X-FW-Dynamic
X-FW-Serve
X-FW-Server
X-FW-Hash
X-FW-Static
X-Generated-By
X-FW-Type
X-Oracle-Dms-Rid
Meta-Geo
X-Storage
X-RN-RSRV
X-UPSTREAM-Address
X-Api-Version
X-Cache-Status-Check
MS-CV
X-Amz-Apigw-Id
X-RTag
X-Amzn-RequestId
Ms-Operation-Id
X-Device-Type
X-OCL
X-Mobile-URL
X-Varnish-Cache-Hits
X-Section
X-PCL
X-Origin-Hint
Liferay-Portal
X-Cms-Context
Azure-RegionName
Property-Id
Azure-InstanceId
TWC-Connection-Speed
Azure-SiteName
X-Cache-Server
Azure-Version
Azure-SlotName
CF-IPCountry
TWC-Device-Class
TWC-GeoIP-Country
Webcakes-App-Version
Webcakes-Region
X-Access
X-Format
Webcakes-App-Name
TWC-Privacy
TWC-GeoIP-LatLong
TWC-Locale-Group
X-Hl-Ver
X-Handled-By
X-Proto
GEO-INFO
X-App-Server
Onion-Location
X-R9-Blue-Green-Version
X-Provided-By
X-FireWall-Port
X-Say-TTL
X-SRV
X-AWS-Id
X-Mode
X-Say-Cacheable
X-VWS-Id
Web-Mar-Node
X-Adobe-Source
X-Sql-Count
X-Sql-Duration-Ms
X-Redis-Cache
X-Locale
X-SayCDN-TTL
X-SaId
X-Restarts
X-Server-W
X-LJ-Flow-ID
X-Labrador-Cache-Channel
X-JoinUs
X-Varnishpool
X-PHP-Host
X-Dc
X-No-Session
X-Proxy-Cache-Status
X-Varnish-Hostname
Mn-Server-Ip
CDN-CachedAt
CDN-EdgeStorageId
X-Request-Time
Cache-Name
X-PHP-Backend
CDN-Cache
CDN-PullZone
X-Region
Locale
DB-Nickname
CDN-Uid
Selected-Fe
CDN-RequestCountryCode
X-Skip-Cache
X-Site-Version
CDN-RequestId
X-Xfnlog-Site
X-Content-Age
X-Detected-As
X-Edge-Location
X-Varnish-Beresp-Grace
X-Urbn-Site-Id
X-Cache-Type
X-ProxyCache-Status
X-FB-TRIP-ID
X-Forwarded-Host
X-Via-Fastly
X-Ms-Request-Id
X-Ms-Version
X-Proxy-Build
X-GeoCountry
X-GeoCode
X-ProxyCache-Key
Eomportal-Instance
X-Urbn-Context-Path
X-BYPASS-REASON
X-Web-Node
X-UA-Device-Type
X-Tec-Api-Root
X-Tec-Api-Version
X-Cache-Host
X-Timing-Wait
X-Tec-Api-Origin
X-Shopify-Stage
X-Zipkin-Id
Apigw-Requestid
X-Sorting-Hat-PodId
X-ShardId
X-ShopId
X-Proxied
S-Rt
X-DynaTrace-JS-Agent
X-Alternate-Cache-Key
X-ServerID
X-Routing-Service
X-Sorting-Hat-ShopId
X-Extlb
Load-Balancing
WP-Super-Cache
X-Storefront-Renderer-Rendered
X-Tid
X-Content
X-Nginx-Cache-Key
X-WP-CF-Super-Cache
X-Reqid
X-Amzn-Remapped-Content-Length
X-WP-CF-Super-Cache-Cache-Control
X-Vgn-Hpd-Reason
X-Loop
X-Cache-Enabled
X-LSADC-Cache
X-TNCMS
X-Cdn
Xet-Cookie
X-B3-Traceid
X-Pubstack
X-Newrelic-Synthetics
X-Ua
X-TIME
X-Uri
X-Soup
X-Tumblr-Pixel-2
X-Origin-Date
X-Cache-NGX
X-Correlation-ID
X-Zen-Fury
X-Aspnetmvc-Version
X-Ratelimit-Remaining
X-Service
X-TA-CDN-Provider
X-Origin-TTL
X-MP-GENERATED-AT
From-Origin
X-Origin-CC
X-Webkit-CSP
X-Cache-Debug
Source
Fastcgi-Useragent
X-Varnish-Hits
ServedBy
X-UUID
X-Nginx-Cache
X-GEO
Origin
X-App-Version
X-Human
X-NewRelic-App-Data
Cache
X-Cache-Tags
X-Cluster
Upgrade-Insecure-Requests
X-Rewrite-Enabled
X-Ratelimit-Limit
Rip
Fastly-Drupal-HTML
X-Cached-By
MD5-Digest
Rendered-Blocks
X-ScT
SD-X-WS
Cross-Origin-Window-Policy
X-Varnish-Beresp-Ttl
BehaviorPad-Version
Host-ID
WPO-Cache-Status
WPO-Cache-Message
X-Developer
X-Rojux
X-Ec-Fail
Xc-Version
X-S-Cookie
X-A-Dam
X-S
X-Connection-Hash
X-Destination
X-D
Cdncip
X-Application
X-AK-Request-ID
Sslversion
X-Shop-Environment
X-ARC
Ngx.Var.Host
Odigeo-Trace-Id
Surrogated-Key
T-Server
X-A
X-A-Ccd
X-A-Dcw
X-A-Dgt
X-Aed
X-A-Wwc
Meta-Geo-Continent
Lang
X-TIM-N
A
Cdnsip
Mime-Version
X-User
X-Vdms-Path
X-Cache-NE
DCR-Decision-By
DCR-Processing-Time-Ms
X-B-Cookie
X-SRCache-Key
X-Bc-Bl
Expiry
X-Tenant
X-BCube-Filmed-By
X-Vdms-Version
X-VG-WebCache
X-Orig-Expires
X-Processor
X-PBS-Appsvrname
X-Forwarded-Path
X-NAPM-TraceId
X-External-Request-Id
X-Parent-Response-Time
X-Ec-GeoHdr
X-FW-Version
X-RCS-CacheZone
X-Request-Host
OT-Force-Account-Verify
Gh-Request-Id
X-Served-From
Release
X-GeoIP-City
X-Gdpr
X-Nyt-Route
Webserver
X-Cluster-Node
Redirect-Candidate
X-Origin-Time
X-Aicache-OS
X-Accel-Buffering
X-Tumblr-Pixel-3
Environment
X-JWT-State
X-Developers
X-Is-Gdpr
WebServer
X-Worker
X-WP-CF-Super-Cache-Active
Fastly-Backend-Name
X-Level-Front-Cache
X-Sucuri-Cache
X-Sucuri-ID
X-Has-Esi
X-Thinkindot-L3
X-Geo-Header
TDXMobile
Thinkindot-CacheControl-Type
X-INCAP-ABP
AKAMAI
Thinkindot-Control
X-Auto-Login
Thinkindot-CacheControl
X-HS-Content-Campaign-Id
X-Generated-On
X-Core-Value
X-Cache-Remote
X-CMSURLCustom
X-Cdn-Srv
X-Optimistic-Header
HA-Ipaddr
X-Pass-Why
X-NCache
X-BBC-Edge-Cache-Status
X-Bip
Decoy-Debug-TTL
X-Mvc-Supplant-Cachable
Decoy-Debug-Key
Decoy-Debug-Status
Fastly-GeoIP-CountryCode
Fastly-SIE
X-SplitTest
Is-Eu
IsBot
Ha-Gx-Prefs
X-NodeID
Fastly-SSL
Fastly-SWR
Kp-EeAlive
Memcached
Tube-Get-Contents
Tube-Got-Eval
Tube-Got-Results
X-Ad-Defer-Variation
Traceparent
X-SB
X-AOL-HN
Servername
Tube-Return
VNS-Age
Wxu-Next-Region
X-Pool
X-Policy
Wxu-Next-Hostname
Wxu-Next-Commit
VNS-Cache
We-Hiring
Web-Mar-Region
Req-Svc-Chain
Producers
X-Origin-Response-Time
Mobile-Detection-Method
X-ATG-Version
Datacenter
Mail-Subject
L5d-Success-Class
Machine
X-Azure-Ref-OriginShield
X-SIPLIST1
NGX
Origin-EX
X-Proxy-Cache-Info
Platform
Origin-CC
X-Sigma
X-Owner
NM-Fastcgi-Cache
X-Sigma-Backend
L
Apple-News-Services-Request-Url
X-Esi-Check
X-Rocket-Build-Number
X-VG-TLSProxy
X-Dispatcher-Number
X-S-Maxage
CPC-Cache
X-Request-URI
X-Varnish-Remaining-TTL
X-Fetched-On
X-Varnish-CookieHashed-On
X-Epic-Correlation-Id
X-Irp-Debug
X-Varnish-CookieINHashed-On
X-Device-Os
X-Gzip
X-Eu-Site
X-Wix-Viewer-Type
X-DefHash
X-DefElseHash
X-FC-Vary-Parameters
X-WADP-Cache
X-GeoIP
X-Ckpd-Fst-Backend
X-CGP
X-Clara-WADP
X-Viewer-Country
X-VServer
X-Varnish-Beresp-Status
X-Variation
Click-Count-Action-Start
Click-Count-Error
X-Minions-Version
X-Qloud-Router
Candidate-Md5Url
X-Platform-Server
CloudFront-Viewer-Country
X-Rocket-Nginx-Serving-Static
X-Ec-Custom-Error
CPC-Age
X-DPWN-IS-SECURE
X-Cache-Bucket
Cluster
Canary
Cache-Host
X-Loc
X-RateLimit-Remaining-Second
X-Cache-Id
X-Cache-Info
X-Var-Ttl
X-Thanos
X-RateLimit-Limit-Second
X-Fmm-Version
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
Apple-News-Services-Handled
Adler-Geo
X-Csrf-Jwt
Server-Host
X-Debug-Cache
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
X-Planisys-CDN-TTL
X-Fastly-Backend
X-Planisys-CDN-Rules
X-Hnp-Log
X-Cdn-Origin
X-Hash
X-Gen-Mode
X-CacheTTL
X-Region-Sid
X-Block-Status
X-Branch-Name
X-Mvc-Supplant-OutputCached
X-Core-Mission
X-Gateway-Skip-Cache
X-Gateway-Cache-Key
X-Gamma-Serve
X-Datadog-Parent-Id
X-Gateway-Cache-Status
X-Scheme
X-Gateway-Request-Id
X-Scale
X-Planisys-CDN-Cache
CDCHOST
Country-Code
Cmstype
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-Sn-Servicetimems
X-Tx-Id
X-V-Cache
Vix-Hermes-Req-Id
DSUID
X-Clientip
X-URL
X-Forwarded-Site
X-Origin
X-Slack-Backend
Cmsid
User-Cache-Control
Svr
Sever-Int
Server-Hostname
V-Age
State
Server-Ext
LB
X-Udemy-Cache-App-Namespace
X-IPS-LoggedIn
X-CSRF-Token
Time
Sid
Memory
Ec-Rule-Version
X-LB-NoCache
X-Up
X-Dispatch
X-Nf-Request-Id
X-Edge-Pop
X-Akamai-Transformed
Pics-Label
HostName
X-Tb-Optimization-Total-Bytes-Saved
Request-ID
Ssr
X-VC
X-Newrelic-App-Data
AMP-Access-Control-Allow-Source-Origin
X-Presslabs-Stats
X-ZONE
X-Req
My-App
X-ND-Cache
X-B3-Spanid
X-Cs
X-Refresh
Env
X-Lambda-Id
X-Servedbyhost
X-Generated-In
X-NGINX-Cache
Cache-Tv-Group
X-WA-Info
CacheControlHeader
Fastcgi-Cache-TTL
X-Wa
X-Via-Popv
X-Via-Poph
X-Via-Popn
X-Via-NSCOPI
True-Client-Country-4JS
X-B3-SpanId
X-Datadome
X-GG-Cache-Date
Server-ID
GeoIp-Country-Code
X-Session-Fingerprint
X-Vc
X-EC-Lua
X-PX
X-Rebelmouse-Surrogate-Control
SID
X-Fastly-Cache
X-Origin-Expires
X-Zone
X-Op-Id-All
X-Release
X-Rebelmouse-Cache-Control
X-ID
Hostname
X-Pod-Name
True-Client-IP
Cache-Hits
X-Trace-ID
X-LB-ID
X-Xrds-Location
X-Fpc
X-TX-ID
X-CACHE-AGE
X-VCL-Version
X-GeoIP-Region-Code
X-GeoIP-Country-Code
X-CSRF-TOKEN
X-Webkit-CSP-Report-Only
X-NWS-UUID-VERIFY
WWW-Authenticate
X-TH-Server
X-CACHE-KEY
X-Buckets
X-Cache-Date
X-Accel-Expires-Debug
X-Ig-Push-State
X-MSEdge-Flight
X-MSEdge-Features
X-Date
X-RAMCache
X-TRACE-ID
X-Srv
Resin-Trace
X-Old-Content-Length
X-NC
X-Endurance-Cache-Level
CDN
X-HS-Status
X-Conf
X-DC
Fastly-Drupal-Html
X-Microcachable
X-Dmc
X-Varnish-Beresp-TTL
X-RateLimit-Reset
Tcn
Powered-By
X-MCACHE
X-Vcl-Version
X-CS
Magicmarker
X-Location
X-Webstats-RespID
X-Lb-Id
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
Path
Section-Io-Id
X-API-Version
X-Director
X-FPC
True-Client-Ip
X-Akamai-Pragma-Client-IP
X-Check-Cacheable
X-Contensis-Viewer-Groups
X-Cache-ASPX
X-DataCenter
Yjs-Id
X-Cache-Ttl
X-CLOUD-TRACE-CONTEXT
X-Varnish-Authentication
X-LiteSpeed-Cache-Control
X-Wikidot-Static-Cache
X-Wikidot-Backend
X-Alfa-Service
GeoIP-Country-Code
X-Datacenter
X-Esi
Lb
X-Geo
FSS-Cache
Proxy-Connection
X-Vercel-Id
X-Via-CDN
X-Vercel-Cache
X-Test
Server-Id
X-Be
X-WA
X-Mly-Id
Cdn
M-TraceId
X-Cache-Backend
X-Server-IP
X-Via-PopH
ENV
X-Via-PopV
X-Response-By
User-Agent
X-Micro-Cache
X-Hyper-Cache
Pramga
X-ServedByHost
X-Via-PopN
X-Cache-Expires
X-Cdn-Forward
X-Cc-Via
X-Dw-Trace-Id
YJS-ID
X-M-Reqid
X-PERF
X-We-Are-Hiring
XServer
X-M-Log
X-Client-Ip
X-CF-Lambda-Version
Uri
X-CF-Lambda-Fn
X-ApacheServer
HIT
X-HA-Backend
Sm-Log-Id
X-Service-Response-Time
X-AIR-PT
X-Edge-POP
X-TrackingId
X-LiteSpeed-Tag
X-Traceid
X-Frame-Option
X-Qnm-Cache
Dnion-Transfer-Encoding
X-Info
Geoip-Latitude
X-UA
Swift-Performance
X-TT-LOGID
Location
X-App
X-Akamai-ERRuleID
Locid
X-From
XM
Tracecode
X-Instance-Name
X-Akamai-ERPolicy
X-LI-Proto
X-LI-UUID
X-Li-Fabric
X-Li-Pop
Srvid
X-FL-EDGE
X-DB
X-Fastly-Backend-Reqs
PFcat
X-RPS
CF-Cached-On
X-RSL
CountryCode
X-HN
X-RPM
X-DI
X-DSS
X-VarnishDD-TTL
X-DW
C-Via
X-Platform
PICS-Label
X-Air-Trace-Id
X-Air-Source
X-Air-Hostname
Nginx-CQVIP
N-Cache
Ohc-File-Size
X-Wp-Cf-Super-Cache-Cache-Control
X-Wp-Cf-Super-Cache
Esi-Enabled
NtCoent-Length
Cneonction
X-Cache-Proxy
X-Platform-Router
X-Platform-Cluster
X-Platform-Processor
X-Conten-Type-Options
X-Request-Url
Timeexpire
X-Cdn-Request-ID
Vha6-Origin
X-Oss-Request-Id
X-Oss-Storage-Class
X-HostName
X-CF-Powered-By
X-Oss-Server-Time
X-Lb-Nocache
Wpo-Cache-Status
X-Oss-Object-Type
Wpo-Cache-Message
X-Fastly-Cache-Hits
Cache-Key
X-Oss-Hash-Crc64ecma
Warning
X-Cache-Ngx
X-Litespeed-Cache-Control
X-Ips-Loggedin
X-Air-Pt
Wp-Super-Cache
X-NFL-Dma
X-Matome-Cached
X-Matched-Rule
X-Newegg-Index
X-N-OperationId
X-Nerd
X-Newegg-Flow
X-NFL-Geo
X-MTS-Cache
X-NXG
X-OVcl-Cache
X-OVcl
X-PGF-Deflate
X-PG-ACCESS
X-PageType
X-Paywall
X-Loadbalancer
X-Origin-Ops
X-Nyt-Data-Last-Modified
X-Ntj-Investigation-Id
X-Odoo-Frontend
X-Okws-Version
X-Onedio-Env
X-NS-Authorization
X-IBD-Cache
X-Pver
X-Fastly-Is-Edge
X-Ee-Request-Date
X-Fstrz
X-Full-Ttl
X-Farm
X-F-Status
X-Eid
X-ETag
X-Ee-Request-Id
X-Eventloop-Lag
X-GG-Cache-Status
X-Git-Commit
X-Ittl
X-Kebab
X-Kebabable
X-Keep
X-Is-SSL
X-IBD-SID
X-Global-Transaction-ID
X-GoCache-CacheStatus
X-Group
X-Header-Sub
X-LbNode
X-SVR-IIS
X-Waitingroom
X-Wag-Acs
X-Web-Hosting
X-WP-Bypass
X-WSR2
X-Ver
X-Vary-Devices
X-Upstream-State
X-User-Auth
X-Utime
X-V2-Infrastructure
X-Xms-Page-Cache-Actions
X-YSpaceId
X-Ha-Backend
X-LAGOON
Create-Date
X-Request-URL
X-Ee-Origin
X-SD-PageType
X-UP
XV-Cache
XV-H
X-B3-Parentspanid
X-Fastly-Country-Code
X-U-Cache
X-True-Client-Ip
X-Ruby
X-Route-Akamai
X-Save-Cache
X-Server-L
X-ServiceName
X-Route
X-Request-Origin
X-Reboot
X-Redis
X-Render-Method
X-Render-Time
X-Sh
X-Site
X-Timestamp
X-Test-Nginx-Ingress
X-Toujours-Debout-Branch
X-Toujours-Debout-Location
X-Tried-To-Kebabify
X-Svr-Proxy
X-Stack-Name
X-Slack-Shared-Secret-Outcome
X-SMP-JWT
X-Square
X-SSLProxy
X-R-Cache
Npm-Remaining
Npm-Cost
NLCacheNote
Ns
Ns-Ua
OK-Edge-Date
Ok-Cache-Status
Nikkei-App-Version
NB-ESI
HServer
H1
HTTPProtocol
Is-Https
Joe-X
Ok-Edge-Key
Origin-Site
Served
Selected-Route
Service-Uuid
SFRVia
Shieldsquare-Response
Scheme
Rt-Proxy-Cache
Proxy-Cache
Panzer-Cache-Control
RawURL
Region
Request-Uuid
Ec-Policy-Id
Deeplink
DynaTrace
SRV
WZWS-RAY
X-B3-ParentSpanId
X-ElasticPress-Query
X-Mg-Cache
Fastcgi-Cache-Ttl
Req-ID
X-CUA
X-PAYTM-SRV-ID
On-Server
Hit
Fastcgi-X-Cache-Version
X-Yottaa-OS
X-IN-APIGATEWAY
Cf-Locale
Cf-Device-Type
Cf-Wrk
Cluster-Host
CMS-200
Cdn-Country-Code
Cachekey
X-Serial
X-IN-APIGATEWAYSSL
X-Th-Server
Akamai-X-Url
Cache-Stat
SII
Store-Cloud-Cache
X-Cache-NPR
X-Cache-Length
X-Cache-Reason
X-Cache-ReqUri
X-CacheVersion
X-Cache-Response
X-Cache-IsMobileDevice
X-Cache-Cookie
X-Backend-TTL
X-AspNetWebPages-Version
X-Backside-Transport
X-BeanStalkRole
X-BeanStalkStage
X-CDN-Pop
X-CDN-Pop-IP
X-Developed-By
X-Delivery
X-Doge
X-DT-Node
X-Edge-IP
X-Dehri-Date
X-Dcm-Pdtf
X-Cms-Device
X-Cf-Node-Idx
X-Coindesk-Cache
X-Colour
X-Container-Uri
X-ASF-Cache
X-ARRRG1
TWC-Unit
TWC-Subs
Uniqueid
Userver
X-77-NZT
Vttl
TWC-PATH-LOCALE
TWC-AK-Req-ID
T-Request-Id
Sw
Technodrome
Time-Cloud-Cache
Ttl
X-77-NZT-Ray
X-Accel-Version
X-Amz-Meta-Cb-Modifiedtime
X-Akamai-Native
X-Apache-Server
X-Ar-Stats
X-Arena-Request-Id
X-Akamai-DeviceType
X-Akamai-DeviceOS
X-Accepted-Language
X-Accepted-Fulllang
X-Accor-Asset
X-AEO-Platform
X-Akamai-CacheKeyMod
X-Ee-Generated-By