Threat Level: green Handler on Duty: Guy Bruneau

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
Strict-Transport-Security
X-Frame-Options
X-Content-Type-Options
Link
Last-Modified
CF-Cache-Status
Cf-Request-Id
CF-RAY
Accept-Ranges
ETag
Expect-CT
Pragma
X-Powered-By
X-Cache
Via
Age
X-XSS-Protection
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
X-Xss-Protection
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-FRAME-OPTIONS
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Varnish
X-Request-Id
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-Adblock-Key
X-AspNet-Version
X-Permitted-Cross-Domain-Policies
Alt-Svc
X-Runtime
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Cache-Status
X-Check
X-Generator
X-Request-ID
X-Cacheable
X-Iinfo
X-Envoy-Upstream-Service-Time
P3p
Timing-Allow-Origin
Feature-Policy
X-Content-Security-Policy
Status
X-Drupal-Dynamic-Cache
Content-Encoding
Access-Control-Expose-Headers
X-AspNetMvc-Version
X-CDN
Upgrade
X-Ua-Compatible
Access-Control-Max-Age
CF-Ray
X-Via
X-Robots-Tag
X-Cache-Group
Server-Timing
X-UA-Device
X-Dns-Prefetch-Control
Keep-Alive
Request-Context
X-AH-Environment
X-Turbo-Charged-By
X-Amz-Request-Id
X-Proxy-Cache
X-Backend
X-Amz-Id-2
X-Age
X-Ws-Request-Id
Host-Header
X-Hacker
X-Server-Powered-By
X-Server
X-Rq
X-Vhost
X-LiteSpeed-Cache
X-Varnish-Cache
Grace
X-Amz-Version-Id
Cf-Edge-Cache
X-Dispatcher
EagleId
Allow
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
Accept-CH
X-Page-Speed
X-WebKit-CSP
X-Nginx-Cache-Status
X-Swift-CacheTime
X-Swift-SaveTime
X-Aws-Lambda-Call-Status
Ali-Swift-Global-Savetime
Cf-Railgun
X-Node
X-Host
X-Pingback
X-Cache-Spec
X-OneAgent-JS-Injection
X-Server-Id
X-Backend-Server
X-Akam-SW-Version
Surrogate-Control
Request-Id
Accept-CH-Lifetime
X-Cache-Lookup
X-Response-Time
EagleEye-TraceId
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Readtime
Content-Location
X-HW
X-Content-Security-Policy-Report-Only
X-Cloud-Trace-Context
X-Application-Context
Rating
X-Trace
X-Ruxit-Js-Agent
Fastly-Restarts
X-Url
X-Clacks-Overhead
X-WebKit-CSP-Report-Only
X-Akamai-Path-Stats
X-Nginx-Upstream-Cache-Status
X-CST
X-MS-InvokeApp
X-Edge
X-Rack-Cache
X-Amz-Server-Side-Encryption
X-Vname
X-TtlSet
X-PC
X-Oneagent-Js-Injection
X-Country
X-Mod-Pagespeed
X-Content-Type
Edge-Control
X-ESI
X-Vcap-Request-Id
X-FastCGI-Cache
X-B3-TraceId
Cf-Apo-Via
X-D2id
X-Ttl
Verso
Xkey
X-Exp-Variant
X-Cdn-Fetch
X-GoogleNews-Bot
X-Exp-Id
X-Kinja-Revision
X-Kinja
X-Kinja-Server
X-Use-Magma
X-Kinja-Build
Cache-Tag
X-GitHub-Request-Id
Service-Worker-Allowed
X-Powered-By-Plesk
X-Amz-Rid
Accept-Ch-Lifetime
X-Mcache
X-Varnish-TTL
X-ECACHE
X-Navigation-Version
RTSS
X-Server-Name
X-VARITI-CCR
X-Abt-Application-Version
X-Version
X-Client-IP
X-Upstream
X-Ac
X-Cached
X-Cnection
X-Element-Page-Cache
Arr-Disable-Session-Affinity
X-Instrumentation
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-RateLimit-Remaining
X-Dw-Request-Base-Id
Permissions-Policy
X-Px
X-SharePointHealthScore
SPRequestGuid
X-Sol
SPIisLatency
SPRequestDuration
X-Middleton-Display
Display
Pagespeed
X-Cache-TTL
X-NWS-LOG-UUID
Public-Key-Pins
X-Country-Code
X-Middleton-Response
Response
X-Ruxit-JS-Agent
X-Midtier
X-Cache-Key
X-Ser
X-Kinsta-Cache
X-Edge-Location-Klb
X-Forwarded-For
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Goog-Hash
Content-MD5
X-DataDome
X-NF-Request-ID
X-Correlation-Id
X-Shield-Request-Id
X-RateLimit-Limit
X-MSEdge-Ref
Access-Control-Request-Method
Front-End-Https
X-Jurisdiction
X-HP-Trace-Id
X-HP-Webp
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-Recruiting
X-T
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
AR-CACHE
AR-SID
AR-ATIME
AR-PoweredBy
AR-Request-ID
Edge-Cache-Tag
TP-L2-Cache
TP-Cache
X-Daa-Tunnel
Nginx-Cache
MicrosoftSharePointTeamServices
X-Accel-Expires
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Browser-Type
X-Mg-S
X-Content-Digest
X-Powered-CMS
X-Grace
TCN
X-Hits
X-Request-Processing-Time
X-Request-Received
X-HS-Hub-Id
X-HS-Content-Id
X-Amzn-Trace-Id
X-HS-Combine-CSS
X-HS-Cache-Config
Server-Node
Server-Name
X-XRDS-Location
X-Id
MS-Author-Via
Filters
Fastcgi-Cache
X-Geo-Country
Count-Hit
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Webkit-Csp
X-Distributor
X-Frontend
X-Origin-Server
X-Ezoic-Cdn
X-Ua-Browser
Filterid
Cross-Origin-Opener-Policy
X-LLID
X-Language
X-Fastly-Request-Id
S
X-Seen-By
X-Forwarded-Proto
X-Request-Handler-Origin-Region
X-Microsite
X-Protected-By
Charset
X-Git-Hash
X-F-Cache
X-LB-Cache
X-B3-Sampled
Host
X-Page-Id
Payment
X-FB-Debug
X-Ratelimit-Reset
X-PressLabs-Stats
X-Amz-Meta-S3cmd-Attrs
X-ASPNET-VERSION
X-VCache
Cache-Status
X-Cluster-Name
X-Rid
Surrogate-Key
X-Ab
Cache-Tags
X-Www-Served-By
X-Logged-In
X-Upgrade-Enabled
Access-Control-Allow-Method
Realpath
Retry-After
X-DIS-Request-ID
X-Varnish-Backend
X-Source
Alternate-Protocol
X-Origin-Cache
Accept-Charset
Accept-Ch
X-NGENIX-Cache
X-Activity-Id
Cleartype
X-COUNTRY
X-AppVersion
X-Az
X-Type
Paypal-Debug-Id
DC
X-Template
X-Flags
X-Providence-Cookie
X-Varnish-Grace
X-Wix-Request-Id
X-Route-Name
X-Request-Guid
X-Is-Crawler
X-App-Environment
X-Aspnet-Duration-Ms
X-Amz-Replication-Status
X-Envoy-Decorator-Operation
X-Signature
X-Tb
X-B-Cache
X-TT
X-Hostname
X-B
X-Cache-Age
X-Revision
ServerID
X-Fastly-Request-ID
X-DynaTrace
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Contextid
Frame-Options
X-Cache-Rule
X-Fastcgi-Cache
X-Node-Name
X-Drupal-Cache-Tags
X-Tt-Trace-Host
X-Tt-Trace-Tag
Amp-Access-Control-Allow-Source-Origin
X-Pinterest-Rid
Cross-Origin-Resource-Policy
Pinterest-Version
Pinterest-Generated-By
X-Proxy
X-Trace-Id
Refresh
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-GUploader-UploadID
X-Goog-Metageneration
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Debug
X-Load-Cache
X-Mobile
Referer-Policy
X-Content-Options
Node
X-EdgeConnect-Cache-Status
X-Response-Served-From
X-Cache-Control
NGB
X-Original-Request-Id
Viewport
X-Varnish-Server
Akamai-GRN
Country
X-Varnish-Age
X-N
X-NYM-Debug-Backend
X-Whom
X-Instance
X-Debug-IsConnected
X-Debug-IsPreview
X-Cache-Time
X-Content-Powered-By
X-Magnolia-Registration
X-Is-Bot
X-Status
X-Adobe-Loc
Content-Disposition
Uber-Trace-Id
X-Adobe-Content
X-Page-View
X-G
X-Rendered-As
X-Real-IP
X-ProcessESI
X-Akamai-Request-ID2
X-RemovedCookies
Url
X-Environment-Context
X-Framework
X-Servername
X-Cache-Grace
X-L-Path
X-Cacheable-TTL
Access-Control-Request-Headers
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-Mid
X-Jobs
X-Yottaa-Metrics
X-Cache-TTL-Remaining
Srv
X-User-Agent
X-Yottaa-Optimizations
X-Cache-Expired-At
X-Via-JSL
Healthy
X-Tumblr-User
X-Cache-Hit
X-Tumblr-Pixel-1
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-CDN-Forward
X-Unique-Id
X-Cache-Operation
X-XRDS-LOCATION
X-Drupal-Cache-Contexts
X-APP-VERSION
X-Rule
Version
Countrycode
X-TTL
Accept-Language
X-Backend-Name
X-Debug-Info
X-Akamai-Edgescape
X-Oracle-Dms-Ecid
X-Cache-Action
X-Http-Reason
X-Litespeed-Cache
X-Mg-Request-UUID
X-Oracle-Dms-Rid
X-VC-Cache
Section-Io-Cache
Protected
X-IPLB-Instance
Xserver
Content-Secure-Policy
X-IPLB-Request-ID
X-Server-ID
X-Tt-Logid
X-Hosted-By
X-B3-Traceid
X-HTML-Minification-Powered-By
Server-Info
X-Azure-Ref
X-Generation-Time
X-FW-Static
X-FW-Dynamic
Backend
X-FW-Type
X-SRV
X-FW-Hash
X-FW-Server
X-FW-Serve
X-Generated-By
X-Time
X-RN-RSRV
Meta-Geo
X-Storage
X-UPSTREAM-Address
X-Api-Version
X-App-Server
CF-IPCountry
X-Amzn-RequestId
X-Cache-Status-Check
X-Restarts
X-Amz-Apigw-Id
Webcakes-App-Name
Webcakes-App-Version
X-PCL
Property-Id
TWC-Locale-Group
TWC-Privacy
X-R9-Blue-Green-Version
TWC-Connection-Speed
X-Mobile-URL
TWC-Device-Class
TWC-GeoIP-Country
X-Device-Type
X-Varnish-Cache-Hits
TWC-GeoIP-LatLong
X-Cache-Server
Liferay-Portal
X-Handled-By
Azure-SiteName
X-Section
Azure-RegionName
Onion-Location
X-Origin-Hint
X-OCL
Azure-InstanceId
X-Format
Azure-SlotName
X-Access
Webcakes-Region
Azure-Version
X-Cms-Context
X-Adobe-Source
Web-Mar-Node
X-AWS-Id
X-JoinUs
X-Labrador-Cache-Channel
MS-CV
Ms-Operation-Id
X-Redis-Cache
X-Server-W
X-Sql-Duration-Ms
X-LJ-Flow-ID
X-Sql-Count
X-Content
X-Varnish-Hostname
X-RTag
X-VWS-Id
X-FireWall-Port
X-Provided-By
X-SayCDN-TTL
X-Proxy-Cache-Status
X-PHP-Host
X-No-Session
X-Proto
GEO-INFO
X-Say-TTL
X-Say-Cacheable
X-SaId
X-Locale
CDN-EdgeStorageId
CDN-PullZone
CDN-CachedAt
CDN-RequestCountryCode
CDN-Cache
X-Edge-Location
X-Request-Time
X-Site-Version
X-Region
X-PHP-Backend
X-Ms-Request-Id
CDN-RequestId
X-Skip-Cache
X-UA-Device-Type
X-Web-Node
X-Xfnlog-Site
X-Via-Fastly
X-Varnish-Beresp-Grace
X-Urbn-Context-Path
X-Urbn-Site-Id
X-GeoCountry
X-Ms-Version
Mn-Server-Ip
X-GeoCode
X-Cache-Type
Locale
DB-Nickname
X-Mode
CDN-Uid
X-Content-Age
X-Cache-Host
X-Detected-As
X-FB-TRIP-ID
X-Forwarded-Host
X-Hl-Ver
X-ProxyCache-Key
X-ProxyCache-Status
X-Varnishpool
X-BYPASS-REASON
X-Zipkin-Id
X-Extlb
Cache-Name
X-Routing-Service
Apigw-Requestid
X-Proxied
X-Nginx-Cache-Key
S-Rt
Eomportal-Instance
X-Sorting-Hat-ShopId
X-Tid
X-Sorting-Hat-PodId
Load-Balancing
X-ShardId
X-ShopId
X-Shopify-Stage
WP-Super-Cache
X-DynaTrace-JS-Agent
X-Alternate-Cache-Key
X-Tec-Api-Version
X-Storefront-Renderer-Rendered
X-Tec-Api-Origin
X-Tec-Api-Root
X-TIME
X-ECache
X-Amzn-Remapped-Content-Length
X-Vgn-Hpd-Reason
X-ServerID
X-Cache-Enabled
X-Reqid
X-Loop
X-TNCMS
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
X-LSADC-Cache
Selected-Fe
X-Pubstack
X-Dc
X-Ua
X-Timing-Wait
X-Proxy-Build
X-Varnish-Ttl
X-Cdn
X-Uri
X-Tumblr-Pixel-2
X-Soup
Xet-Cookie
X-Origin-Date
X-Zen-Fury
X-NewRelic-App-Data
X-Newrelic-Synthetics
Fastcgi-Useragent
X-Service
From-Origin
X-Cache-Debug
X-Ratelimit-Remaining
X-UUID
X-Correlation-ID
X-Aspnetmvc-Version
X-Cache-NGX
X-MP-GENERATED-AT
ServedBy
Source
X-Origin-CC
X-Origin-TTL
X-GEO
X-Varnish-Hits
X-Webkit-CSP
Origin
X-Human
X-URL
X-TA-CDN-Provider
Fastly-Drupal-HTML
Cache
X-App-Version
X-Nginx-Cache
X-Varnish-Beresp-Ttl
X-Cache-Tags
X-Cached-By
Webserver
X-Cluster
Cross-Origin-Window-Policy
X-Rewrite-Enabled
Upgrade-Insecure-Requests
Rip
Rendered-Blocks
X-ScT
BehaviorPad-Version
MD5-Digest
X-Presslabs-Stats
X-Ratelimit-Limit
Host-ID
X-Connection-Hash
X-External-Request-Id
X-Rojux
X-Ec-GeoHdr
X-S
X-Developer
X-Destination
X-Forwarded-Path
X-Cache-NE
X-D
X-Application
Sslversion
SD-X-WS
Surrogated-Key
Cdnsip
Cdncip
DCR-Decision-By
DCR-Processing-Time-Ms
Expiry
Lang
Meta-Geo-Continent
Ngx.Var.Host
Odigeo-Trace-Id
T-Server
A
X-AK-Request-ID
X-Aed
X-ARC
X-B-Cookie
X-Bc-Bl
X-A-Wwc
X-A-Dgt
X-A
Mime-Version
X-A-Ccd
X-A-Dam
X-A-Dcw
X-BCube-Filmed-By
X-Ec-Fail
X-NAPM-TraceId
X-Vdms-Version
X-User
X-TIM-N
Xc-Version
X-VG-WebCache
X-Orig-Expires
X-Vdms-Path
X-S-Cookie
X-RCS-CacheZone
X-FW-Version
X-Shop-Environment
X-Processor
X-PBS-Appsvrname
X-SRCache-Key
X-Parent-Response-Time
X-Tenant
OT-Force-Account-Verify
WPO-Cache-Status
WPO-Cache-Message
X-Request-Host
X-Accel-Buffering
X-Nyt-Route
Environment
X-Aicache-OS
X-Served-From
X-Gdpr
Redirect-Candidate
X-Origin-Time
X-Cluster-Node
Thinkindot-Control
Thinkindot-CacheControl-Type
Fastly-Backend-Name
X-Cdn-Srv
AKAMAI
TDXMobile
Thinkindot-CacheControl
X-JWT-State
X-AOL-HN
X-Level-Front-Cache
X-WP-CF-Super-Cache-Active
X-Sucuri-Cache
X-Sucuri-ID
X-Worker
X-Thinkindot-L3
X-Is-Gdpr
X-INCAP-ABP
X-Developers
X-Core-Value
X-Generated-On
X-Geo-Header
X-HS-Content-Campaign-Id
X-Has-Esi
X-CMSURLCustom
X-Auto-Login
LB
X-Rocket-Nginx-Serving-Static
Release
X-Origin-Response-Time
Svr
X-Rocket-Build-Number
X-RateLimit-Limit-Second
Servername
Traceparent
Req-Svc-Chain
Tube-Get-Contents
We-Hiring
Web-Mar-Region
X-GeoIP-City
VNS-Cache
VNS-Age
Tube-Got-Eval
Tube-Got-Results
Tube-Return
X-Request-URI
Producers
Mail-Subject
Memcached
X-Platform-Server
X-Pool
Machine
X-SIPLIST1
IsBot
Kp-EeAlive
L
X-Loc
NGX
X-SplitTest
Origin-EX
Platform
X-Owner
Origin-CC
X-Minions-Version
NM-Fastcgi-Cache
X-RateLimit-Remaining-Second
Wxu-Next-Commit
Wxu-Next-Hostname
X-Ad-Defer-Variation
X-SB
X-VServer
X-Ckpd-Fst-Backend
X-Varnish-Remaining-TTL
X-DefElseHash
X-S-Maxage
Is-Eu
X-DefHash
X-Viewer-Country
X-Cache-Info
X-VG-TLSProxy
X-Sigma
X-Azure-Ref-OriginShield
X-Proxy-Cache-Info
X-BBC-Edge-Cache-Status
X-Cache-Id
X-Cache-Bucket
X-Qloud-Router
X-Varnish-CookieINHashed-On
X-NodeID
X-Varnish-Beresp-Status
X-Fmm-Version
X-Fetched-On
X-NCache
Gh-Request-Id
X-GeoIP
X-Gzip
Wxu-Next-Region
X-Variation
X-Esi-Check
X-Wix-Viewer-Type
X-Dispatcher-Number
X-Device-Os
X-Varnish-CookieHashed-On
X-DPWN-IS-SECURE
X-Ec-Custom-Error
X-Epic-Correlation-Id
X-WADP-Cache
X-Sigma-Backend
X-ATG-Version
X-Clara-WADP
CloudFront-Viewer-Country
Click-Count-Error
Click-Count-Action-Start
Cluster
CPC-Age
Datacenter
CPC-Cache
Canary
Cache-Host
Adler-Geo
X-Tumblr-Pixel-3
X-Debug-Cache
Apple-News-Services-Handled
Apple-News-Services-Host
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
Decoy-Debug-Key
Candidate-Md5Url
Decoy-Debug-TTL
Fastly-SWR
Decoy-Debug-Status
Fastly-SSL
Fastly-GeoIP-CountryCode
Fastly-SIE
X-Cache-Remote
X-Tx-Id
Server-Host
X-Pass-Why
X-Planisys-CDN-Cache
X-Origin
X-CGP
X-Region-Sid
X-Gamma-Serve
X-Clientip
X-Gateway-Cache-Key
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-Gateway-Cache-Status
X-Mvc-Supplant-Cachable
X-Hash
X-Gen-Mode
X-Gateway-Skip-Cache
X-Block-Status
X-Policy
X-Hnp-Log
X-CacheTTL
Ha-Gx-Prefs
X-Gateway-Request-Id
HA-Ipaddr
X-Irp-Debug
L5d-Success-Class
X-Cdn-Origin
X-Udemy-Cache-App-Namespace
X-V-Cache
Server-Hostname
Server-Ext
X-Scale
DSUID
X-SVT-ORM-RULES
Sever-Int
Cmsid
Cmstype
X-Datadog-Sampling-Priority
X-Sn-Servicetimems
X-Slack-Backend
X-Scheme
Country-Code
X-Datadog-Trace-Id
X-Datadog-Parent-Id
X-Fastly-Backend
X-Csrf-Jwt
User-Cache-Control
V-Age
Vix-Hermes-Req-Id
X-Eu-Site
X-Branch-Name
CDCHOST
Mobile-Detection-Method
State
X-FC-Vary-Parameters
X-Core-Mission
X-SVT-ORM-VERSION
X-IPS-LoggedIn
X-Optimistic-Header
Time
X-LB-NoCache
Memory
X-Forwarded-Site
X-Bip
Ec-Rule-Version
X-Up
X-Thanos
X-Mvc-Supplant-OutputCached
X-Var-Ttl
X-Datadome
WebServer
Pics-Label
X-Akamai-Transformed
X-ZONE
X-Dispatch
X-Nf-Request-Id
X-Edge-Pop
X-MCACHE
X-Tb-Optimization-Total-Bytes-Saved
Ssr
X-CSRF-Token
HostName
Sid
X-NGINX-Cache
Request-ID
X-ND-Cache
X-Refresh
X-VC
AMP-Access-Control-Allow-Source-Origin
X-CACHE-AGE
X-Via-Popv
X-Via-Popn
My-App
X-Servedbyhost
X-Req
X-Via-Poph
X-B3-Spanid
Env
X-WA-Info
Cache-Tv-Group
X-Via-NSCOPI
X-B3-SpanId
SID
X-GG-Cache-Date
X-Lambda-Id
X-Generated-In
X-Wa
Server-ID
Fastcgi-Cache-TTL
X-Cs
X-Vc
X-Newrelic-App-Data
CacheControlHeader
GeoIp-Country-Code
X-Session-Fingerprint
True-Client-Country-4JS
X-EC-Lua
X-Trace-ID
Hostname
X-Origin-Expires
X-Pod-Name
X-Release
X-Fpc
X-Fastly-Cache
Cache-Hits
True-Client-IP
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-CSRF-TOKEN
X-PX
X-ID
X-Op-Id-All
X-Xrds-Location
X-LB-ID
X-VCL-Version
X-Zone
X-NWS-UUID-VERIFY
X-DC
X-GeoIP-Country-Code
X-TX-ID
X-GeoIP-Region-Code
X-Webkit-CSP-Report-Only
X-HS-Status
X-TH-Server
X-Ig-Push-State
X-Cache-Date
WWW-Authenticate
X-MSEdge-Features
X-MSEdge-Flight
X-CACHE-KEY
X-RAMCache
X-Buckets
X-Date
X-Accel-Expires-Debug
X-Endurance-Cache-Level
X-Conf
Resin-Trace
X-NC
X-TRACE-ID
X-CS
X-Microcachable
X-Old-Content-Length
CDN
X-Dmc
X-Esi
X-RateLimit-Reset
X-Srv
Powered-By
Fastly-Drupal-Html
Tcn
X-Vcl-Version
X-Varnish-Beresp-TTL
X-Location
X-Webstats-RespID
Path
X-Lb-Id
Magicmarker
X-Check-Cacheable
X-API-Version
Section-Io-Id
Section-Io-Origin-Time-Seconds
X-Wikidot-Static-Cache
Section-Io-Origin-Status
X-Director
X-Wikidot-Backend
True-Client-Ip
Section-Origin-Responded
X-Alfa-Service
X-Akamai-Pragma-Client-IP
X-DataCenter
X-LiteSpeed-Cache-Control
X-Cache-ASPX
Yjs-Id
X-Be
X-Varnish-Authentication
X-Contensis-Viewer-Groups
X-Cache-Ttl
X-CLOUD-TRACE-CONTEXT
X-FPC
GeoIP-Country-Code
X-Datacenter
Proxy-Connection
X-Vercel-Cache
X-Vercel-Id
Cdn
X-Geo
X-Via-CDN
FSS-Cache
Pramga
X-Mly-Id
X-Test
X-WA
X-Micro-Cache
X-Hyper-Cache
X-CF-Lambda-Version
X-CF-Lambda-Fn
ENV
User-Agent
Lb
X-Response-By
X-ServedByHost
X-M-Reqid
M-TraceId
X-Cache-Backend
X-Cache-Expires
X-HA-Backend
X-M-Log
Server-Id
X-Cc-Via
X-Dw-Trace-Id
X-Cdn-Forward
X-Via-PopN
X-Client-Ip
X-Akamai-ERPolicy
X-Akamai-ERRuleID
X-We-Are-Hiring
CountryCode
X-Via-PopH
X-ApacheServer
X-App
X-Via-PopV
X-PERF
HIT
Uri
Tracecode
X-Qnm-Cache
X-Server-IP
X-Edge-POP
X-AIR-PT
X-Service-Response-Time
Sm-Log-Id
YJS-ID
X-Instance-Name
Swift-Performance
XM
X-Info
X-Frame-Option
N-Cache
X-From
C-Via
Srvid
X-FL-EDGE
X-Traceid
Locid
Geoip-Latitude
Dnion-Transfer-Encoding
X-Li-Pop
X-Li-Fabric
X-TrackingId
X-TT-LOGID
X-LiteSpeed-Tag
X-UA
X-LI-Proto
Location
X-LI-UUID
X-Air-Hostname
X-Air-Source
X-Air-Trace-Id
X-RSL
X-VarnishDD-TTL
X-Platform
CF-Cached-On
X-Platform-Processor
Timeexpire
X-Platform-Router
X-Air-Pt
X-Platform-Cluster
XServer
X-HN
PFcat
X-RPS
Esi-Enabled
Nginx-CQVIP
PICS-Label
X-Fastly-Backend-Reqs
Ohc-File-Size
X-DB
X-RPM
X-DSS
X-DW
X-DI
X-Wp-Cf-Super-Cache
X-Wp-Cf-Super-Cache-Cache-Control
Wpo-Cache-Message
X-PAYTM-SRV-ID
X-Oss-Server-Time
NtCoent-Length
X-Lb-Nocache
X-CF-Powered-By
X-Cdn-Request-ID
Hit
X-HostName
X-Oss-Storage-Class
X-Cache-Proxy
X-Conten-Type-Options
Vha6-Origin
Wpo-Cache-Status
X-Request-Url
Cache-Key
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
X-Fastly-Cache-Hits
On-Server
Fastcgi-X-Cache-Version
X-Oss-Request-Id
X-Cache-Ngx
Warning
X-Ips-Loggedin
X-Litespeed-Cache-Control
Wp-Super-Cache
X-Newegg-Flow
X-LbNode
X-Newegg-Index
X-Loadbalancer
X-Nerd
X-Matome-Cached
X-MTS-Cache
X-NFL-Dma
X-N-OperationId
X-Matched-Rule
X-Ntj-Investigation-Id
X-Okws-Version
X-Odoo-Frontend
X-PageType
X-Onedio-Env
X-Keep
X-Nyt-Data-Last-Modified
X-NXG
X-NS-Authorization
X-Origin-Ops
X-OVcl
X-OVcl-Cache
X-NFL-Geo
X-Fastly-Is-Edge
X-Eventloop-Lag
X-F-Status
X-Farm
X-Fstrz
X-ETag
X-Eid
X-Ee-Origin
X-Ee-Request-Date
X-Paywall
X-Ee-Request-Id
X-Full-Ttl
X-GG-Cache-Status
X-IBD-SID
X-Is-SSL
X-Ittl
X-Kebab
X-IBD-Cache
X-Header-Sub
X-Git-Commit
X-Global-Transaction-ID
X-GoCache-CacheStatus
X-Group
X-Kebabable
X-U-Cache
X-V2-Infrastructure
X-Utime
X-Vary-Devices
X-Ver
X-Wag-Acs
X-User-Auth
X-Upstream-State
X-Toujours-Debout-Branch
X-Toujours-Debout-Location
X-Tried-To-Kebabify
X-True-Client-Ip
X-Waitingroom
X-Web-Hosting
X-B3-Parentspanid
X-Fastly-Country-Code
X-Request-URL
X-Ee-Generated-By
XV-H
XV-Cache
X-WP-Bypass
X-WSR2
X-Xms-Page-Cache-Actions
X-YSpaceId
X-Timestamp
X-Test-Nginx-Ingress
X-Request-Origin
X-Render-Time
X-Route
X-Route-Akamai
X-Ruby
X-Render-Method
X-Redis
X-PGF-Deflate
X-Pver
X-R-Cache
X-Reboot
X-Save-Cache
X-Server-L
X-SSLProxy
X-Stack-Name
X-SVR-IIS
X-Svr-Proxy
X-Square
X-SMP-JWT
X-ServiceName
X-Sh
X-Site
X-Slack-Shared-Secret-Outcome
X-PG-ACCESS
Scheme
Ns
Npm-Remaining
Ns-Ua
Ok-Cache-Status
OK-Edge-Date
Npm-Cost
NLCacheNote
Is-Https
HTTPProtocol
Joe-X
NB-ESI
Nikkei-App-Version
Ok-Edge-Key
Origin-Site
Service-Uuid
Served
SFRVia
Shieldsquare-Response
SII
Selected-Route
Rt-Proxy-Cache
Proxy-Cache
Panzer-Cache-Control
RawURL
Region
Request-Uuid
HServer
H1
X-ElasticPress-Query
X-Mg-Cache
X-Yottaa-OS
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
X-B3-ParentSpanId
WZWS-RAY
Req-ID
X-CUA
Fastcgi-Cache-Ttl
SRV
DynaTrace
Cneonction
X-Serial
Cluster-Host
Cf-Wrk
CMS-200
Deeplink
Ec-Policy-Id
Cf-Locale
Cf-Device-Type
Akamai-X-Url
X-Th-Server
Cache-Stat
Cachekey
Cdn-Country-Code
Store-Cloud-Cache
Sw
X-Cache-NPR
X-Cache-Length
X-Cache-Reason
X-Cache-ReqUri
X-Cache-Response
X-Cache-IsMobileDevice
X-Cache-Cookie
X-Backend-TTL
X-AspNetWebPages-Version
X-Backside-Transport
X-BeanStalkRole
X-BeanStalkStage
X-CacheVersion
X-CDN-Pop
X-Delivery
X-Dehri-Date
X-Developed-By
X-Doge
X-DT-Node
X-Dcm-Pdtf
X-Container-Uri
X-Cf-Node-Idx
X-CDN-Pop-IP
X-Cms-Device
X-Coindesk-Cache
X-Colour
X-ASF-Cache
X-ARRRG1
Uniqueid
TWC-Unit
Userver
Vttl
X-77-NZT
TWC-Subs
TWC-PATH-LOCALE
Technodrome
T-Request-Id
Time-Cloud-Cache
Ttl
TWC-AK-Req-ID
X-77-NZT-Ray
X-Accel-Version
X-Amz-Meta-Cb-Modifiedtime
X-Akamai-Native
X-Apache-Server
X-Ar-Stats
X-Arena-Request-Id
X-Akamai-DeviceType
X-Akamai-DeviceOS
X-Accepted-Language
X-Accepted-Fulllang
X-Accor-Asset
X-AEO-Platform
X-Akamai-CacheKeyMod
X-Edge-IP