Threat Level: green Handler on Duty: Guy Bruneau

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
Strict-Transport-Security
X-Frame-Options
X-Content-Type-Options
Link
Last-Modified
CF-Cache-Status
Cf-Request-Id
CF-RAY
Accept-Ranges
ETag
Expect-CT
Pragma
X-Powered-By
X-Cache
Via
Age
X-XSS-Protection
Content-Security-Policy
Report-To
NEL
X-Xss-Protection
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-FRAME-OPTIONS
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Varnish
X-Request-Id
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-Adblock-Key
X-AspNet-Version
X-Permitted-Cross-Domain-Policies
Alt-Svc
X-Runtime
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Cache-Status
X-Check
X-Generator
X-DNS-Prefetch-Control
X-Request-ID
X-Cacheable
X-Iinfo
X-Envoy-Upstream-Service-Time
P3p
Timing-Allow-Origin
Feature-Policy
X-Content-Security-Policy
Status
X-Drupal-Dynamic-Cache
Content-Encoding
Access-Control-Expose-Headers
X-AspNetMvc-Version
X-CDN
Upgrade
X-Ua-Compatible
Access-Control-Max-Age
CF-Ray
X-Dns-Prefetch-Control
X-Via
X-Robots-Tag
X-Cache-Group
X-UA-Device
Server-Timing
Keep-Alive
Request-Context
X-AH-Environment
X-Turbo-Charged-By
X-Amz-Request-Id
X-Proxy-Cache
X-Backend
X-Amz-Id-2
X-Age
X-Ws-Request-Id
Host-Header
X-Hacker
X-Server-Powered-By
X-Rq
X-Server
X-Vhost
X-LiteSpeed-Cache
X-Varnish-Cache
Grace
X-Amz-Version-Id
Cf-Edge-Cache
X-Dispatcher
EagleId
Allow
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
Accept-CH
X-Page-Speed
X-WebKit-CSP
X-Nginx-Cache-Status
X-Swift-CacheTime
X-Swift-SaveTime
X-Aws-Lambda-Call-Status
Ali-Swift-Global-Savetime
Cf-Railgun
X-Node
X-Host
X-Pingback
X-Cache-Spec
X-OneAgent-JS-Injection
X-Server-Id
X-Backend-Server
X-Akam-SW-Version
Surrogate-Control
Request-Id
Accept-CH-Lifetime
X-Response-Time
X-Cache-Lookup
EagleEye-TraceId
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Readtime
Content-Location
X-HW
X-Cloud-Trace-Context
X-Content-Security-Policy-Report-Only
X-Application-Context
Rating
X-Trace
X-Ruxit-Js-Agent
Fastly-Restarts
X-Url
X-Clacks-Overhead
X-WebKit-CSP-Report-Only
X-Akamai-Path-Stats
X-Nginx-Upstream-Cache-Status
X-CST
X-MS-InvokeApp
X-Edge
X-Rack-Cache
X-Amz-Server-Side-Encryption
X-PC
X-TtlSet
X-Vname
X-Oneagent-Js-Injection
X-Mod-Pagespeed
Edge-Control
X-Content-Type
X-ESI
X-B3-TraceId
X-Country
X-Vcap-Request-Id
X-FastCGI-Cache
Cf-Apo-Via
X-D2id
X-Ttl
Verso
X-GitHub-Request-Id
Xkey
X-Kinja-Build
X-Kinja-Revision
X-Kinja-Server
X-Kinja
X-Use-Magma
X-Cdn-Fetch
X-Mcache
X-GoogleNews-Bot
X-Exp-Id
X-Exp-Variant
Cache-Tag
Service-Worker-Allowed
X-Powered-By-Plesk
X-Amz-Rid
Accept-Ch-Lifetime
X-Varnish-TTL
X-ECACHE
X-Navigation-Version
RTSS
X-Server-Name
X-VARITI-CCR
X-Abt-Application-Version
X-Client-IP
X-Version
X-Upstream
X-Ac
X-Cnection
X-Cached
X-Element-Page-Cache
Arr-Disable-Session-Affinity
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Dw-Request-Base-Id
X-Instrumentation
X-RateLimit-Remaining
Permissions-Policy
SPRequestGuid
X-SharePointHealthScore
X-Px
SPRequestDuration
SPIisLatency
X-Middleton-Display
X-Sol
Pagespeed
Display
X-Cache-TTL
Public-Key-Pins
X-NWS-LOG-UUID
X-Country-Code
Response
X-Middleton-Response
X-Ruxit-JS-Agent
X-Midtier
X-Cache-Key
X-Kinsta-Cache
X-Edge-Location-Klb
X-Ser
X-Forwarded-For
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Goog-Hash
Content-MD5
X-DataDome
X-NF-Request-ID
X-Correlation-Id
X-Shield-Request-Id
X-MSEdge-Ref
X-RateLimit-Limit
Access-Control-Request-Method
X-Jurisdiction
X-HP-Trace-Id
X-HP-Webp
Front-End-Https
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
X-Recruiting
X-T
AR-Request-ID
AR-SID
AR-ATIME
AR-PoweredBy
AR-CACHE
Edge-Cache-Tag
TP-L2-Cache
MicrosoftSharePointTeamServices
TP-Cache
Nginx-Cache
X-Daa-Tunnel
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-Browser-Type
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Accel-Expires
X-Mg-S
X-Content-Digest
TCN
X-Powered-CMS
X-Grace
X-Hits
X-Request-Received
X-Request-Processing-Time
X-Amzn-Trace-Id
X-HS-Cache-Config
X-HS-Combine-CSS
X-HS-Hub-Id
X-HS-Content-Id
Server-Node
Server-Name
Filters
X-XRDS-Location
X-Id
MS-Author-Via
Fastcgi-Cache
X-Geo-Country
Count-Hit
X-Webkit-Csp
X-Distributor
X-Frontend
X-Origin-Server
X-Ezoic-Cdn
X-Ua-Browser
Filterid
Cross-Origin-Opener-Policy
X-TEC-API-ROOT
X-LLID
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-Fastly-Request-Id
S
X-Language
X-Seen-By
X-Request-Handler-Origin-Region
Charset
X-Microsite
X-Protected-By
X-F-Cache
X-Git-Hash
X-Forwarded-Proto
Payment
Host
X-LB-Cache
X-FB-Debug
X-Page-Id
X-B3-Sampled
X-PressLabs-Stats
X-Ratelimit-Reset
X-Amz-Meta-S3cmd-Attrs
X-ASPNET-VERSION
X-VCache
Cache-Status
X-Cluster-Name
X-COUNTRY
X-Rid
Surrogate-Key
X-Ab
X-Www-Served-By
Cache-Tags
X-Logged-In
X-Upgrade-Enabled
Access-Control-Allow-Method
Realpath
Retry-After
X-DIS-Request-ID
X-Source
Alternate-Protocol
X-Origin-Cache
X-Varnish-Backend
Accept-Charset
Accept-Ch
X-Activity-Id
X-AppVersion
X-NGENIX-Cache
X-Az
Cleartype
Paypal-Debug-Id
DC
X-Template
X-Amz-Replication-Status
X-Type
X-Request-Guid
X-App-Environment
X-Is-Crawler
X-Flags
X-Aspnet-Duration-Ms
X-Wix-Request-Id
X-Varnish-Grace
X-Providence-Cookie
X-Route-Name
X-Envoy-Decorator-Operation
X-B-Cache
X-Signature
X-Tb
X-TT
X-Fastly-Request-ID
X-B
X-Hostname
X-Revision
X-Cache-Age
ServerID
X-DynaTrace
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
Frame-Options
X-Contextid
X-Cache-Rule
X-Fastcgi-Cache
X-Drupal-Cache-Tags
X-Node-Name
X-Tt-Trace-Tag
X-Tt-Trace-Host
Pinterest-Version
X-Pinterest-Rid
Amp-Access-Control-Allow-Source-Origin
Pinterest-Generated-By
X-Trace-Id
Refresh
X-Proxy
Cross-Origin-Resource-Policy
X-GUploader-UploadID
X-Goog-Metageneration
X-Goog-Generation
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Debug
X-Load-Cache
X-Mobile
X-Content-Options
X-EdgeConnect-Cache-Status
Referer-Policy
Node
X-Original-Request-Id
X-Cache-Control
NGB
X-Response-Served-From
X-Varnish-Server
Viewport
Akamai-GRN
X-Varnish-Age
Country
X-N
X-Debug-IsConnected
X-Magnolia-Registration
X-Debug-IsPreview
X-Whom
X-NYM-Debug-Backend
X-Instance
X-Cache-Time
X-Content-Powered-By
X-Rendered-As
X-Status
X-Is-Bot
Uber-Trace-Id
X-Adobe-Content
X-Adobe-Loc
X-G
Content-Disposition
X-Page-View
X-Servername
X-Yottaa-Optimizations
X-Framework
X-RemovedCookies
X-Real-IP
X-Yottaa-Metrics
Access-Control-Request-Headers
Url
X-ProcessESI
X-Akamai-Request-ID2
X-Cache-Grace
X-Cacheable-TTL
X-Environment-Context
X-L-Path
X-Cache-TTL-Remaining
X-User-Agent
VIX-Pulpo-Node
Srv
X-Jobs
X-Mid
VIX-Pulpo-Upstream-Status
X-Cache-Expired-At
X-Oracle-Dms-Ecid
X-Via-JSL
X-Oracle-Dms-Rid
Healthy
X-Cache-Hit
X-Unique-Id
X-Tumblr-User
X-Tumblr-Pixel
Countrycode
X-CDN-Forward
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-XRDS-LOCATION
X-Cache-Operation
X-APP-VERSION
X-Drupal-Cache-Contexts
X-Rule
Version
X-TTL
Accept-Language
X-Backend-Name
X-Debug-Info
X-Akamai-Edgescape
X-Mg-Request-UUID
X-Cache-Action
X-Http-Reason
X-Litespeed-Cache
Section-Io-Cache
X-VC-Cache
Content-Secure-Policy
Protected
X-IPLB-Request-ID
X-IPLB-Instance
Xserver
X-Server-ID
X-Tt-Logid
X-Hosted-By
X-Tec-Api-Origin
X-Generation-Time
X-Azure-Ref
X-HTML-Minification-Powered-By
Server-Info
X-Tec-Api-Root
X-Tec-Api-Version
X-FW-Dynamic
X-FW-Hash
X-FW-Serve
X-FW-Static
X-FW-Server
Backend
X-FW-Type
X-SRV
X-Time
X-Generated-By
X-Storage
Meta-Geo
X-RN-RSRV
X-UPSTREAM-Address
X-Api-Version
X-App-Server
X-Restarts
X-Cache-Status-Check
X-Amz-Apigw-Id
CF-IPCountry
X-Amzn-RequestId
X-Section
GEO-INFO
X-Device-Type
X-Mobile-URL
X-Varnish-Cache-Hits
Liferay-Portal
Azure-SlotName
X-Handled-By
TWC-Connection-Speed
Property-Id
Azure-InstanceId
Webcakes-App-Version
TWC-Device-Class
TWC-GeoIP-Country
TWC-Privacy
TWC-Locale-Group
TWC-GeoIP-LatLong
Onion-Location
X-Cache-Server
Webcakes-Region
X-Format
X-Cms-Context
Azure-SiteName
Azure-RegionName
X-R9-Blue-Green-Version
X-Access
X-OCL
X-Origin-Hint
X-PCL
Azure-Version
Webcakes-App-Name
Ms-Operation-Id
X-Provided-By
X-RTag
X-Server-W
X-Locale
MS-CV
X-PHP-Host
X-FireWall-Port
X-Adobe-Source
X-No-Session
X-Redis-Cache
X-Sql-Duration-Ms
X-Proto
X-Proxy-Cache-Status
X-VWS-Id
X-Labrador-Cache-Channel
X-Varnish-Hostname
X-AWS-Id
Web-Mar-Node
X-Sql-Count
X-SaId
X-Say-Cacheable
X-SayCDN-TTL
X-Say-TTL
X-LJ-Flow-ID
X-Content
X-JoinUs
X-Cache-Host
X-Varnish-Beresp-Grace
X-Request-Time
X-Urbn-Site-Id
X-Cache-Type
X-Via-Fastly
X-Skip-Cache
X-Site-Version
X-Detected-As
X-Content-Age
X-UA-Device-Type
X-Edge-Location
X-Xfnlog-Site
X-Ms-Request-Id
CDN-PullZone
CDN-EdgeStorageId
CDN-CachedAt
CDN-RequestCountryCode
CDN-RequestId
Locale
CDN-Uid
Mn-Server-Ip
CDN-Cache
X-GeoCountry
X-Varnishpool
DB-Nickname
X-FB-TRIP-ID
X-Region
X-Forwarded-Host
X-GeoCode
Cache-Name
X-Ms-Version
X-Web-Node
X-Urbn-Context-Path
X-Mode
Eomportal-Instance
X-BYPASS-REASON
X-Zipkin-Id
X-Proxied
X-ShardId
X-PHP-Backend
Apigw-Requestid
X-Extlb
X-Routing-Service
X-Shopify-Stage
X-ShopId
X-Alternate-Cache-Key
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Nginx-Cache-Key
X-ProxyCache-Key
X-Hl-Ver
S-Rt
X-ProxyCache-Status
X-Storefront-Renderer-Rendered
Load-Balancing
X-DynaTrace-JS-Agent
WP-Super-Cache
X-Dc
X-Tid
Selected-Fe
X-Timing-Wait
X-Proxy-Build
X-TIME
X-Cache-Enabled
X-ECache
X-Amzn-Remapped-Content-Length
X-WP-CF-Super-Cache-Cache-Control
X-Vgn-Hpd-Reason
X-WP-CF-Super-Cache
X-ServerID
X-Reqid
X-LSADC-Cache
X-TNCMS
X-Loop
X-Pubstack
X-Ua
X-Uri
X-Cdn
X-Varnish-Ttl
X-Soup
X-Tumblr-Pixel-2
X-B3-Traceid
Xet-Cookie
X-Origin-Date
X-Zen-Fury
Fastcgi-Useragent
X-Cache-NGX
X-Newrelic-Synthetics
X-NewRelic-App-Data
From-Origin
X-Service
X-Cache-Debug
X-Aspnetmvc-Version
X-Correlation-ID
X-Ratelimit-Remaining
X-UUID
X-MP-GENERATED-AT
Source
X-Origin-CC
ServedBy
X-Origin-TTL
X-Webkit-CSP
X-Varnish-Hits
Origin
X-GEO
X-Human
X-URL
X-TA-CDN-Provider
Fastly-Drupal-HTML
Cache
X-Nginx-Cache
X-App-Version
X-Varnish-Beresp-Ttl
X-Cache-Tags
X-Cached-By
Webserver
X-Cluster
Cross-Origin-Window-Policy
Upgrade-Insecure-Requests
X-Rewrite-Enabled
Rip
BehaviorPad-Version
Rendered-Blocks
X-ScT
MD5-Digest
X-Presslabs-Stats
Host-ID
WPO-Cache-Message
X-Ratelimit-Limit
WPO-Cache-Status
X-A-Dgt
Odigeo-Trace-Id
X-A-Dcw
X-Cache-NE
Ngx.Var.Host
X-Parent-Response-Time
X-AK-Request-ID
A
X-Shop-Environment
X-B-Cookie
X-ARC
SD-X-WS
Mime-Version
X-PBS-Appsvrname
X-SRCache-Key
X-BCube-Filmed-By
Expiry
X-Orig-Expires
X-Aed
X-A-Wwc
X-Connection-Hash
Sslversion
X-Ec-Fail
X-Ec-GeoHdr
X-Rojux
T-Server
DCR-Processing-Time-Ms
X-RCS-CacheZone
X-Vdms-Version
X-S
Surrogated-Key
X-FW-Version
X-User
X-External-Request-Id
X-TIM-N
X-Vdms-Path
X-Forwarded-Path
X-S-Cookie
DCR-Decision-By
X-D
X-NAPM-TraceId
X-A-Ccd
X-Application
Meta-Geo-Continent
Cdncip
Cdnsip
X-A
Lang
X-Processor
X-VG-WebCache
X-Developer
X-A-Dam
Xc-Version
X-Tenant
X-Destination
OT-Force-Account-Verify
X-Served-From
X-Gdpr
X-Aicache-OS
X-Nyt-Route
X-Bc-Bl
Redirect-Candidate
X-Accel-Buffering
X-Cluster-Node
Environment
X-Origin-Time
X-Generated-On
X-Has-Esi
X-Geo-Header
X-INCAP-ABP
X-JWT-State
X-Is-Gdpr
AKAMAI
X-HS-Content-Campaign-Id
X-WP-CF-Super-Cache-Active
Thinkindot-CacheControl
X-Cdn-Srv
X-CMSURLCustom
X-Core-Value
X-Auto-Login
Thinkindot-Control
LB
TDXMobile
Thinkindot-CacheControl-Type
Fastly-Backend-Name
X-Level-Front-Cache
X-Developers
X-Worker
X-AOL-HN
X-Thinkindot-L3
X-Request-Host
X-Sucuri-Cache
X-Sucuri-ID
Fastly-SSL
Platform
Fastly-SIE
Fastly-GeoIP-CountryCode
Req-Svc-Chain
Servername
Producers
X-SplitTest
Fastly-SWR
Memcached
Mail-Subject
Machine
L
IsBot
Is-Eu
Origin-CC
Kp-EeAlive
NM-Fastcgi-Cache
NGX
Origin-EX
X-Sigma-Backend
X-DefElseHash
X-S-Maxage
X-Minions-Version
X-DefHash
X-Request-URI
X-NCache
X-NodeID
X-Cache-Info
X-Cache-Id
X-SB
X-Ckpd-Fst-Backend
X-Clara-WADP
X-Loc
X-Rocket-Build-Number
X-Epic-Correlation-Id
X-GeoIP
X-Esi-Check
X-Fetched-On
X-Fmm-Version
X-Gzip
X-Ec-Custom-Error
X-Rocket-Nginx-Serving-Static
X-Device-Os
X-Dispatcher-Number
X-DPWN-IS-SECURE
X-Origin-Response-Time
X-Cache-Bucket
Web-Mar-Region
We-Hiring
Wxu-Next-Commit
Wxu-Next-Hostname
Wxu-Next-Region
VNS-Cache
VNS-Age
Tube-Get-Contents
Traceparent
Tube-Got-Eval
Tube-Got-Results
Tube-Return
X-Ad-Defer-Variation
X-SIPLIST1
X-Qloud-Router
X-Proxy-Cache-Info
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Owner
X-Platform-Server
X-Pool
X-Sigma
X-ATG-Version
X-Azure-Ref-OriginShield
X-BBC-Edge-Cache-Status
Svr
X-Varnish-CookieINHashed-On
Adler-Geo
X-Variation
X-Optimistic-Header
X-Varnish-Beresp-Status
Apple-News-Services-Handled
Apple-News-Services-Host
Cache-Host
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
X-Varnish-CookieHashed-On
X-Varnish-Remaining-TTL
Gh-Request-Id
Release
X-Debug-Cache
X-Tumblr-Pixel-3
X-Wix-Viewer-Type
X-WADP-Cache
X-VG-TLSProxy
X-Viewer-Country
X-VServer
Canary
X-GeoIP-City
Decoy-Debug-Status
Cluster
Decoy-Debug-Key
CPC-Age
Datacenter
Candidate-Md5Url
CloudFront-Viewer-Country
Click-Count-Error
Decoy-Debug-TTL
Click-Count-Action-Start
CPC-Cache
X-Cache-Remote
X-Tx-Id
Server-Host
X-Pass-Why
X-CacheTTL
X-Scale
X-Udemy-Cache-App-Namespace
X-Clientip
X-Core-Mission
X-Block-Status
X-Eu-Site
X-Csrf-Jwt
X-CGP
X-FC-Vary-Parameters
X-Irp-Debug
X-Scheme
X-Branch-Name
X-Mvc-Supplant-Cachable
X-Policy
X-Hash
X-Gen-Mode
X-Gateway-Skip-Cache
X-Gateway-Request-Id
X-Hnp-Log
X-Region-Sid
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
X-Gateway-Cache-Status
X-Gateway-Cache-Key
X-Thanos
X-Bip
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
X-Var-Ttl
X-Fastly-Backend
X-Gamma-Serve
X-Forwarded-Site
DSUID
X-Datadog-Parent-Id
X-Cdn-Origin
Sever-Int
V-Age
Cmstype
Server-Hostname
Ha-Gx-Prefs
X-SVT-ORM-RULES
X-V-Cache
X-SVT-ORM-VERSION
State
Mobile-Detection-Method
X-Slack-Backend
Country-Code
User-Cache-Control
Server-Ext
Vix-Hermes-Req-Id
Cmsid
HA-Ipaddr
L5d-Success-Class
CDCHOST
X-Sn-Servicetimems
X-IPS-LoggedIn
X-Origin
X-Mvc-Supplant-OutputCached
X-LB-NoCache
X-Datadome
Ec-Rule-Version
X-Up
Memory
Time
WebServer
X-Dispatch
X-Akamai-Transformed
Pics-Label
X-Nf-Request-Id
X-Tb-Optimization-Total-Bytes-Saved
Ssr
X-Edge-Pop
X-CSRF-Token
HostName
X-ZONE
Sid
X-Refresh
Request-ID
X-VC
X-NGINX-Cache
X-ND-Cache
AMP-Access-Control-Allow-Source-Origin
X-CACHE-AGE
X-Req
X-Via-Popn
Env
X-B3-Spanid
X-Via-Popv
X-Via-Poph
X-Servedbyhost
My-App
X-Via-NSCOPI
X-B3-SpanId
SID
Cache-Tv-Group
X-WA-Info
X-Lambda-Id
X-GG-Cache-Date
X-Generated-In
Fastcgi-Cache-TTL
X-Wa
Server-ID
X-Newrelic-App-Data
X-Vc
X-Cs
X-Session-Fingerprint
GeoIp-Country-Code
True-Client-Country-4JS
CacheControlHeader
X-EC-Lua
Hostname
X-Trace-ID
X-Origin-Expires
X-Rebelmouse-Cache-Control
True-Client-IP
X-Rebelmouse-Surrogate-Control
X-Fastly-Cache
X-Fpc
X-Pod-Name
X-Release
Cache-Hits
X-PX
X-CSRF-TOKEN
X-ID
X-Op-Id-All
X-MCACHE
X-LB-ID
X-VCL-Version
X-Xrds-Location
X-Zone
X-GeoIP-Region-Code
X-TX-ID
X-GeoIP-Country-Code
X-NWS-UUID-VERIFY
X-Webkit-CSP-Report-Only
WWW-Authenticate
X-TH-Server
X-MSEdge-Flight
X-HS-Status
X-Cache-Date
X-DC
X-MSEdge-Features
X-Ig-Push-State
X-RAMCache
X-Buckets
X-CACHE-KEY
X-Endurance-Cache-Level
X-Date
X-Conf
Resin-Trace
X-Accel-Expires-Debug
X-NC
X-TRACE-ID
X-CS
X-Microcachable
X-Dmc
X-Old-Content-Length
CDN
X-Esi
X-RateLimit-Reset
X-Srv
Powered-By
X-Vcl-Version
Tcn
Fastly-Drupal-Html
Magicmarker
X-Location
X-Check-Cacheable
X-Lb-Id
Path
X-Webstats-RespID
X-Varnish-Beresp-TTL
X-API-Version
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
X-Alfa-Service
True-Client-Ip
Section-Io-Origin-Status
X-Director
X-Wikidot-Backend
X-Wikidot-Static-Cache
Section-Io-Id
X-Akamai-Pragma-Client-IP
X-Cache-ASPX
X-Contensis-Viewer-Groups
X-Be
X-LiteSpeed-Cache-Control
X-Cache-Ttl
X-Varnish-Authentication
X-CLOUD-TRACE-CONTEXT
X-DataCenter
Yjs-Id
X-Vercel-Cache
X-FPC
X-Datacenter
Proxy-Connection
X-Vercel-Id
GeoIP-Country-Code
FSS-Cache
X-WA
Pramga
X-Mly-Id
X-Test
X-Hyper-Cache
X-Geo
X-Micro-Cache
Cdn
X-Via-CDN
ENV
X-Response-By
Lb
Server-Id
X-ServedByHost
User-Agent
X-Server-IP
X-Cache-Backend
M-TraceId
X-M-Reqid
X-CF-Lambda-Fn
X-M-Log
X-CF-Lambda-Version
X-HA-Backend
X-Cache-Expires
X-Dw-Trace-Id
X-Cdn-Forward
X-Cc-Via
X-PERF
X-Via-PopH
X-Via-PopV
X-ApacheServer
HIT
X-Via-PopN
X-Qnm-Cache
X-We-Are-Hiring
X-App
X-Akamai-ERRuleID
Uri
X-Client-Ip
Tracecode
X-Akamai-ERPolicy
Sm-Log-Id
X-Service-Response-Time
YJS-ID
X-AIR-PT
X-Edge-POP
X-Air-Hostname
X-Air-Source
X-Instance-Name
XM
N-Cache
Dnion-Transfer-Encoding
X-Air-Trace-Id
X-TrackingId
X-Traceid
X-Li-Fabric
X-Li-Pop
X-LI-Proto
Swift-Performance
X-Info
X-Frame-Option
Geoip-Latitude
X-From
X-UA
Srvid
Locid
X-LI-UUID
X-TT-LOGID
X-FL-EDGE
C-Via
X-LiteSpeed-Tag
Location
X-DSS
X-RPS
X-RPM
X-DI
X-Platform-Router
X-RSL
PFcat
CF-Cached-On
X-VarnishDD-TTL
X-HN
Timeexpire
X-DW
Nginx-CQVIP
X-Platform
CountryCode
XServer
X-Air-Pt
Ohc-File-Size
PICS-Label
X-DB
X-Platform-Processor
X-Fastly-Backend-Reqs
Esi-Enabled
X-Platform-Cluster
X-Wp-Cf-Super-Cache-Cache-Control
X-Wp-Cf-Super-Cache
X-Cache-Proxy
X-Request-Url
Fastcgi-X-Cache-Version
X-Conten-Type-Options
On-Server
X-PAYTM-SRV-ID
NtCoent-Length
Hit
X-Oss-Server-Time
X-Oss-Object-Type
Wpo-Cache-Message
Wpo-Cache-Status
X-Lb-Nocache
X-HostName
X-Oss-Request-Id
X-Oss-Hash-Crc64ecma
Cache-Key
X-Oss-Storage-Class
Vha6-Origin
X-Cdn-Request-ID
X-Fastly-Cache-Hits
X-CF-Powered-By
Wp-Super-Cache
X-Litespeed-Cache-Control
X-Cache-Ngx
X-Ips-Loggedin
Warning
X-OVcl-Cache
X-Nerd
X-Newegg-Flow
X-Newegg-Index
X-N-OperationId
X-PageType
X-LbNode
X-Loadbalancer
X-Matched-Rule
X-Matome-Cached
X-MTS-Cache
X-NFL-Geo
X-Nyt-Data-Last-Modified
X-Odoo-Frontend
X-Okws-Version
X-Onedio-Env
X-NXG
X-OVcl
X-Origin-Ops
X-NS-Authorization
X-Ntj-Investigation-Id
X-Keep
X-NFL-Dma
X-F-Status
X-Paywall
X-Farm
X-Fastly-Is-Edge
X-Fstrz
X-Eventloop-Lag
X-ETag
X-Ee-Origin
X-Ee-Request-Date
X-Ee-Request-Id
X-Eid
X-Full-Ttl
X-GG-Cache-Status
X-IBD-SID
X-Is-SSL
X-Ittl
X-Kebab
X-IBD-Cache
X-Header-Sub
X-Git-Commit
X-Global-Transaction-ID
X-GoCache-CacheStatus
X-Group
X-Kebabable
X-Square
X-V2-Infrastructure
X-Utime
X-Vary-Devices
X-Ver
X-Wag-Acs
X-User-Auth
X-Upstream-State
X-Toujours-Debout-Location
X-Tried-To-Kebabify
X-True-Client-Ip
X-U-Cache
X-Waitingroom
X-Web-Hosting
X-B3-Parentspanid
X-Fastly-Country-Code
X-Request-URL
X-Ee-Generated-By
XV-H
XV-Cache
X-WP-Bypass
X-WSR2
X-Xms-Page-Cache-Actions
X-YSpaceId
X-Toujours-Debout-Branch
X-Timestamp
X-Request-Origin
X-Render-Time
X-Route
X-Route-Akamai
X-Ruby
X-Render-Method
X-Redis
X-PGF-Deflate
X-Pver
X-R-Cache
X-Reboot
X-Save-Cache
X-Server-L
X-Stack-Name
X-SVR-IIS
X-Svr-Proxy
X-Test-Nginx-Ingress
X-SSLProxy
X-SMP-JWT
X-ServiceName
X-Sh
X-Site
X-Slack-Shared-Secret-Outcome
X-PG-ACCESS
HServer
Ns-Ua
Ns
Ok-Cache-Status
OK-Edge-Date
Ok-Edge-Key
Npm-Remaining
Npm-Cost
Joe-X
Is-Https
NB-ESI
Nikkei-App-Version
NLCacheNote
Origin-Site
Panzer-Cache-Control
Service-Uuid
Served
SFRVia
Shieldsquare-Response
SII
Selected-Route
Scheme
RawURL
Proxy-Cache
Region
Request-Uuid
Rt-Proxy-Cache
HTTPProtocol
H1
X-ElasticPress-Query
X-Mg-Cache
X-Yottaa-OS
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
X-B3-ParentSpanId
WZWS-RAY
Req-ID
X-CUA
Fastcgi-Cache-Ttl
SRV
DynaTrace
Cneonction
X-Serial
Cluster-Host
Cf-Wrk
CMS-200
Deeplink
Ec-Policy-Id
Cf-Locale
Cf-Device-Type
Akamai-X-Url
X-Th-Server
Cache-Stat
Cachekey
Cdn-Country-Code
Store-Cloud-Cache
Sw
X-Cache-NPR
X-Cache-Length
X-Cache-Reason
X-Cache-ReqUri
X-Cache-Response
X-Cache-IsMobileDevice
X-Cache-Cookie
X-Backend-TTL
X-AspNetWebPages-Version
X-Backside-Transport
X-BeanStalkRole
X-BeanStalkStage
X-CacheVersion
X-CDN-Pop
X-Delivery
X-Dehri-Date
X-Developed-By
X-Doge
X-DT-Node
X-Dcm-Pdtf
X-Container-Uri
X-Cf-Node-Idx
X-CDN-Pop-IP
X-Cms-Device
X-Coindesk-Cache
X-Colour
X-ASF-Cache
X-ARRRG1
Uniqueid
TWC-Unit
Userver
Vttl
X-77-NZT
TWC-Subs
TWC-PATH-LOCALE
Technodrome
T-Request-Id
Time-Cloud-Cache
Ttl
TWC-AK-Req-ID
X-77-NZT-Ray
X-Accel-Version
X-Amz-Meta-Cb-Modifiedtime
X-Akamai-Native
X-Apache-Server
X-Ar-Stats
X-Arena-Request-Id
X-Akamai-DeviceType
X-Akamai-DeviceOS
X-Accepted-Language
X-Accepted-Fulllang
X-Accor-Asset
X-AEO-Platform
X-Akamai-CacheKeyMod
X-Edge-IP