Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
Strict-Transport-Security
X-Frame-Options
X-Content-Type-Options
Last-Modified
Link
CF-Cache-Status
Cf-Request-Id
Accept-Ranges
ETag
CF-RAY
Expect-CT
Pragma
X-Powered-By
X-Cache
Via
X-XSS-Protection
Age
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Xss-Protection
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-FRAME-OPTIONS
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Request-Id
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-Adblock-Key
X-AspNet-Version
X-Permitted-Cross-Domain-Policies
Alt-Svc
X-Runtime
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Check
X-DNS-Prefetch-Control
X-Cache-Status
X-Generator
CF-Ray
X-Cacheable
X-Request-ID
X-Iinfo
X-Envoy-Upstream-Service-Time
Timing-Allow-Origin
Feature-Policy
X-Ua-Compatible
X-Content-Security-Policy
Status
X-Drupal-Dynamic-Cache
Content-Encoding
X-AspNetMvc-Version
Access-Control-Expose-Headers
X-CDN
Upgrade
X-XSS-PROTECTION
Access-Control-Max-Age
P3p
X-Dns-Prefetch-Control
X-Via
X-Robots-Tag
X-Cache-Group
Server-Timing
X-UA-Device
Request-Context
Keep-Alive
X-Amz-Request-Id
X-AH-Environment
X-Turbo-Charged-By
X-Proxy-Cache
X-Amz-Id-2
X-Backend
X-Age
Host-Header
X-Ws-Request-Id
X-Server-Powered-By
X-Hacker
X-Server
X-Rq
X-Vhost
X-Varnish-Cache
X-Amz-Version-Id
Grace
EagleId
X-Dispatcher
Cf-Edge-Cache
X-LiteSpeed-Cache
Allow
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Device
X-Page-Speed
X-Swift-SaveTime
X-Swift-CacheTime
X-Nginx-Cache-Status
X-WebKit-CSP
Ali-Swift-Global-Savetime
X-Akamai-Path-Stats
X-Aws-Lambda-Call-Status
Accept-CH
X-Host
X-Node
Cf-Railgun
X-Pingback
X-Server-Id
X-OneAgent-JS-Injection
X-Cache-Spec
Surrogate-Control
X-Backend-Server
X-Akam-SW-Version
Request-Id
EagleEye-TraceId
X-Response-Time
X-Cache-Lookup
X-Readtime
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-HW
Content-Location
Accept-CH-Lifetime
X-Content-Security-Policy-Report-Only
X-Application-Context
Rating
X-Cloud-Trace-Context
X-Trace
Fastly-Restarts
Accept-Ch-Lifetime
X-Country
X-WebKit-CSP-Report-Only
X-Url
X-Clacks-Overhead
X-Nginx-Upstream-Cache-Status
X-MS-InvokeApp
X-Amz-Server-Side-Encryption
X-Rack-Cache
Edge-Control
X-Edge
X-Ruxit-JS-Agent
X-TtlSet
X-Vname
X-PC
X-Oneagent-Js-Injection
X-B3-TraceId
X-ESI
X-Content-Type
X-Mod-Pagespeed
X-Vcap-Request-Id
X-CST
Verso
Xkey
X-Kinja-Build
X-Exp-Variant
X-Cdn-Fetch
X-Exp-Id
X-GoogleNews-Bot
X-Kinja
X-Kinja-Server
X-Use-Magma
X-Kinja-Revision
X-D2id
X-GitHub-Request-Id
Cache-Tag
X-Amz-Rid
X-Mcache
X-Powered-By-Plesk
Service-Worker-Allowed
RTSS
X-VARITI-CCR
X-ECACHE
X-Upstream
X-Ruxit-Js-Agent
X-Version
X-Varnish-TTL
X-Navigation-Version
X-Abt-Application-Version
X-Cached
X-Client-IP
X-FastCGI-Cache
X-Ac
X-Cnection
X-Ttl
X-Dw-Request-Base-Id
X-Element-Page-Cache
X-Server-Name
Arr-Disable-Session-Affinity
X-Px
X-Kraken-Loop-Name
X-SharePointHealthScore
X-Server-Lifecycle-Phase
SPRequestGuid
X-Instrumentation
SPRequestDuration
Public-Key-Pins
SPIisLatency
Permissions-Policy
X-Sol
X-Middleton-Display
Display
Pagespeed
X-Country-Code
X-Cache-TTL
X-NWS-LOG-UUID
Cf-Apo-Via
Response
X-Ser
X-Middleton-Response
X-Cache-Key
X-Midtier
X-Goog-Hash
X-Kinsta-Cache
X-Edge-Location-Klb
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Forwarded-For
X-Correlation-Id
Content-MD5
Access-Control-Request-Method
X-Shield-Request-Id
Front-End-Https
X-MSEdge-Ref
Accept-Ch
X-DataDome
X-RateLimit-Remaining
TP-Cache
X-T
TP-L2-Cache
X-NF-Request-ID
X-Recruiting
X-HP-Webp
Edge-Cache-Tag
MicrosoftSharePointTeamServices
X-Jurisdiction
X-HP-Trace-Id
AR-SID
AR-PoweredBy
AR-ATIME
AR-Request-ID
AR-CACHE
Nginx-Cache
MRF-Tech
X-B3-TraceId-Primal
Mrf-Cache-Status
X-Accel-Expires
X-Litespeed-Cache
X-Powered-CMS
X-Daa-Tunnel
TCN
X-Grace
X-Mg-S
X-Content-Digest
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
X-Id
X-Hits
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-TEC-API-ROOT
X-Request-Received
X-Request-Processing-Time
Filters
X-HS-Combine-CSS
X-HS-Cache-Config
X-HS-Hub-Id
X-Amzn-Trace-Id
X-HS-Content-Id
Server-Node
X-XRDS-Location
Server-Name
X-Fastcgi-Cache
X-RateLimit-Limit
MS-Author-Via
X-Erf-Bev-Bev
X-Browser-Type
X-Erf-Bev-Bev-Is-Generated
X-Geo-Country
X-Frontend
Fastcgi-Cache
X-Distributor
X-PressLabs-Stats
S
X-Protected-By
X-Origin-Server
X-Ezoic-Cdn
Count-Hit
X-LLID
X-Webkit-Csp
Cache-Status
X-Language
X-Ua-Browser
Filterid
X-Amz-Meta-S3cmd-Attrs
X-Ab
Cross-Origin-Opener-Policy
X-LB-Cache
X-F-Cache
X-Forwarded-Proto
Payment
X-Seen-By
X-Page-Id
Charset
X-B3-Sampled
X-Microsite
X-Request-Handler-Origin-Region
X-FB-Debug
Host
X-Git-Hash
X-Ratelimit-Reset
X-Fastly-Request-Id
X-Cluster-Name
X-VCache
X-ASPNET-VERSION
Surrogate-Key
X-Cache-Age
X-Rid
Cache-Tags
Realpath
Accept-Charset
X-Www-Served-By
Access-Control-Allow-Method
X-NGENIX-Cache
Alternate-Protocol
X-Logged-In
X-Origin-Cache
Retry-After
X-Upgrade-Enabled
X-Template
X-Source
X-AppVersion
X-Az
X-DIS-Request-ID
X-Activity-Id
X-Type
X-Fastly-Request-ID
X-Varnish-Backend
ServerID
Cleartype
X-Aspnet-Duration-Ms
X-Route-Name
X-Signature
X-Wix-Request-Id
X-B-Cache
X-Tb
X-Is-Crawler
X-TT
X-Request-Guid
X-Providence-Cookie
X-Flags
X-Amz-Replication-Status
X-Envoy-Decorator-Operation
X-Varnish-Grace
X-TTL
X-B
X-App-Environment
DC
Paypal-Debug-Id
X-Hostname
X-DynaTrace
X-Node-Name
Frame-Options
X-Revision
X-Ratelimit-Remaining
X-Drupal-Cache-Tags
X-Contextid
X-Proxy
X-Debug
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Cache-Rule
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Pinterest-Rid
X-GUploader-UploadID
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Goog-Metageneration
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
Pinterest-Version
Pinterest-Generated-By
X-Oracle-Dms-Ecid
Amp-Access-Control-Allow-Source-Origin
X-Mobile
X-Oracle-Dms-Rid
X-Load-Cache
X-Content-Options
X-Cache-Control
X-N
X-EdgeConnect-Cache-Status
Country
Refresh
Node
X-Magnolia-Registration
X-Original-Request-Id
X-Response-Served-From
NGB
X-User-Agent
X-Whom
Akamai-GRN
X-Environment-Context
Access-Control-Request-Headers
X-Content-Powered-By
X-L-Path
X-Instance
Viewport
Content-Disposition
X-Cache-TTL-Remaining
X-Debug-IsPreview
X-Status
X-Varnish-Age
X-Varnish-Server
X-Debug-IsConnected
X-NYM-Debug-Backend
X-Cache-Time
X-Akamai-Request-ID2
X-Cache-Grace
X-Cacheable-TTL
X-Framework
X-Adobe-Loc
X-Adobe-Content
Referer-Policy
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-G
X-Is-Bot
X-Unique-Id
X-Yottaa-Optimizations
X-Servername
X-Yottaa-Metrics
X-Rendered-As
X-Page-View
Url
X-Real-IP
Uber-Trace-Id
X-Jobs
X-Mid
Srv
X-Time
X-Ratelimit-Limit
Countrycode
X-Content
X-RemovedCookies
X-ProcessESI
X-Drupal-Cache-Contexts
X-COUNTRY
Version
Cross-Origin-Resource-Policy
X-CDN-Forward
Accept-Language
X-Cache-Expired-At
X-Mg-Request-UUID
X-Via-JSL
X-Http-Reason
X-Cache-Hit
X-XRDS-LOCATION
X-Restarts
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Cache-Operation
X-Tumblr-User
Protected
X-APP-VERSION
X-App-Server
X-IPLB-Request-ID
X-Backend-Name
X-Api-Version
Healthy
X-IPLB-Instance
X-Hosted-By
X-Debug-Info
X-Azure-Ref
X-Trace-Id
Section-Io-Cache
Content-Secure-Policy
X-Akamai-Edgescape
X-Tt-Logid
X-Rule
X-Cache-Action
X-SRV
X-Device-Type
Liferay-Portal
X-FW-Static
X-FW-Server
Backend
X-FW-Hash
X-Generation-Time
X-FW-Dynamic
X-Nginx-Cache-Key
X-FW-Serve
X-FW-Type
Server-Info
X-VC-Cache
X-Server-ID
GEO-INFO
X-Varnish-Ttl
MS-CV
X-UPSTREAM-Address
Load-Balancing
X-Mobile-URL
X-Storage
Ms-Operation-Id
X-RN-RSRV
X-RTag
Meta-Geo
CF-IPCountry
X-Mode
X-HTML-Minification-Powered-By
Fastcgi-Useragent
X-Proxy-Cache-Status
X-Access
X-Content-Age
Azure-Version
X-Section
Onion-Location
X-Handled-By
Azure-SlotName
Azure-InstanceId
Azure-SiteName
X-Format
Azure-RegionName
TWC-Connection-Speed
S-Rt
Property-Id
Eomportal-Instance
TWC-GeoIP-Country
X-Say-Cacheable
Webcakes-App-Version
Webcakes-Region
X-Say-TTL
Webcakes-App-Name
TWC-Privacy
X-ShardId
TWC-GeoIP-LatLong
TWC-Locale-Group
TWC-Device-Class
X-Cms-Context
X-Origin-Hint
X-PCL
X-Proto
X-R9-Blue-Green-Version
CDN-RequestId
X-Varnish-Beresp-Grace
X-AWS-Id
X-OCL
X-VWS-Id
X-Urbn-Site-Id
CDN-PullZone
CDN-EdgeStorageId
CDN-CachedAt
CDN-Cache
X-Cache-Host
X-Urbn-Context-Path
X-Varnish-Cache-Hits
X-PHP-Host
X-Region
X-Alternate-Cache-Key
X-Adobe-Source
X-Sql-Duration-Ms
X-Sorting-Hat-PodId
X-FireWall-Port
X-Forwarded-Host
Locale
X-ShopId
CDN-Uid
X-Cache-Server
X-Edge-Location
X-Generated-By
X-JoinUs
CDN-RequestCountryCode
Web-Mar-Node
X-Sql-Count
X-Sorting-Hat-ShopId
X-Locale
X-Labrador-Cache-Channel
X-LJ-Flow-ID
X-SayCDN-TTL
X-SaId
X-Shopify-Stage
Xserver
X-Web-Node
X-UA-Device-Type
X-BYPASS-REASON
X-Xfnlog-Site
X-Zipkin-Id
X-Detected-As
X-GeoCountry
X-Extlb
X-Server-W
X-ProxyCache-Status
X-ProxyCache-Key
X-Proxied
X-Routing-Service
X-GeoCode
X-Storefront-Renderer-Rendered
X-ServerID
Apigw-Requestid
X-Ms-Request-Id
X-Hl-Ver
X-Redis-Cache
X-No-Session
X-Site-Version
X-Cache-Type
X-Varnish-Hostname
X-Ms-Version
X-Skip-Cache
X-Timing-Wait
Selected-Fe
X-Varnishpool
X-Cache-Enabled
X-Proxy-Build
X-Request-Time
Mn-Server-Ip
X-Tid
X-PHP-Backend
X-Uri
X-Cache-NGX
X-Nginx-Cache
WP-Super-Cache
Cache-Name
X-Amz-Apigw-Id
X-URL
X-Amzn-RequestId
X-Via-Fastly
X-Datadome
X-FB-TRIP-ID
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
DB-Nickname
X-Cache-Status-Check
X-Origin-Date
X-UUID
X-DynaTrace-JS-Agent
X-ECache
X-LSADC-Cache
X-Loop
X-TNCMS
ServedBy
X-Amzn-Remapped-Content-Length
X-Reqid
Xet-Cookie
X-B3-Traceid
X-Pubstack
X-App-Version
X-Zen-Fury
X-Provided-By
X-Vgn-Hpd-Reason
X-Human
X-GEO
X-Ua
X-RCS-CacheZone
X-Soup
Source
Cache
X-MP-GENERATED-AT
X-Cache-Tags
X-Origin-CC
X-Tumblr-Pixel-2
X-Aspnetmvc-Version
X-TA-CDN-Provider
Origin
X-Origin-TTL
X-Correlation-ID
X-Cdn
X-Varnish-Hits
X-Dc
X-Cached-By
X-Service
X-Webkit-CSP
From-Origin
Cross-Origin-Window-Policy
X-Debug-Cache
WPO-Cache-Status
X-Trace-ID
SD-X-WS
X-Varnish-Beresp-Ttl
WPO-Cache-Message
X-Newrelic-Synthetics
Webserver
LB
X-NewRelic-App-Data
Rip
X-Cache-Debug
X-ScT
BehaviorPad-Version
X-Tec-Api-Origin
X-Tec-Api-Root
X-Tec-Api-Version
MD5-Digest
Rendered-Blocks
X-IPS-LoggedIn
Host-ID
X-AOL-HN
X-Request-Host
X-FW-Version
X-Aed
X-AK-Request-ID
X-A-Dam
Meta-Geo-Continent
X-A-Dgt
X-A-Wwc
X-A-Dcw
VNS-Age
Surrogated-Key
X-External-Request-Id
Sslversion
X-S-Cookie
X-S
X-Rewrite-Enabled
T-Server
X-Rojux
X-Shop-Environment
X-Processor
X-Parent-Response-Time
Ngx.Var.Host
X-A
VNS-Cache
X-PBS-Appsvrname
X-Forwarded-Path
Odigeo-Trace-Id
Cdnsip
X-A-Ccd
X-Tenant
DCR-Processing-Time-Ms
X-SRCache-Key
X-NAPM-TraceId
X-Ec-Fail
X-Cache-NE
DCR-Decision-By
X-D
A
X-Connection-Hash
Expiry
X-Vdms-Version
X-Vdms-Path
Environment
X-VG-WebCache
Lang
CPC-Cache
X-Bc-Bl
X-Destination
X-BCube-Filmed-By
X-Developer
X-B-Cookie
X-Application
X-ARC
Xc-Version
X-Ec-GeoHdr
Cdncip
X-Orig-Expires
X-Nf-Request-Id
X-User
CPC-Age
X-TIM-N
X-CSRF-Token
HostName
X-Platform-Server
X-Dispatcher-Number
X-Served-From
X-Accel-Buffering
Redirect-Candidate
X-Owner
X-Aicache-OS
X-Cluster
X-WP-CF-Super-Cache-Active
Gh-Request-Id
X-Auto-Login
X-Developers
X-Is-Gdpr
X-JWT-State
Upgrade-Insecure-Requests
X-INCAP-ABP
X-Has-Esi
X-Cdn-Srv
X-VC
Mime-Version
X-TIME
Fastly-Drupal-HTML
X-Cluster-Node
OT-Force-Account-Verify
Fastly-SWR
X-Clientip
X-DPWN-IS-SECURE
Fastly-SSL
Fastly-SIE
X-Clara-WADP
Ha-Gx-Prefs
X-Cdn-Origin
Is-Eu
X-CacheTTL
X-Gateway-Request-Id
X-Ec-Custom-Error
Fastly-GeoIP-CountryCode
HA-Ipaddr
X-CGP
X-Gateway-Skip-Cache
X-GeoIP
Country-Code
X-DefElseHash
X-Datadog-Trace-Id
Cmstype
Cmsid
X-DefHash
Click-Count-Action-Start
Click-Count-Error
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
X-Gzip
X-GeoIP-City
IsBot
DSUID
Decoy-Debug-TTL
Decoy-Debug-Key
Decoy-Debug-Status
X-Csrf-Jwt
X-Core-Mission
Kp-EeAlive
Tube-Got-Results
Platform
Producers
Tube-Return
Origin-EX
V-Age
X-Forwarded-Site
Origin-CC
Tube-Got-Eval
Tube-Get-Contents
Servername
Traceparent
State
X-Fmm-Version
Req-Svc-Chain
X-Eu-Site
Release
NM-Fastcgi-Cache
Vix-Hermes-Req-Id
X-Gateway-Cache-Status
X-Bip
Mail-Subject
X-Cache-Bucket
Machine
L
L5d-Success-Class
X-Cache-Id
X-BBC-Edge-Cache-Status
X-Epic-Correlation-Id
X-Ad-Defer-Variation
Web-Mar-Region
We-Hiring
NGX
X-Esi-Check
Mobile-Detection-Method
X-Gateway-Cache-Key
X-Cache-Info
X-NodeID
X-Qloud-Router
X-Proxy-Cache-Info
X-Pool
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Thanos
X-WADP-Cache
X-Policy
X-Wix-Viewer-Type
X-Varnish-Beresp-Status
X-Origin
X-Variation
X-Planisys-CDN-Cache
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-B3-SpanId
X-VServer
X-Nyt-Route
X-Via-NSCOPI
X-Origin-Time
X-Gdpr
X-SplitTest
X-Slack-Backend
X-Sn-Servicetimems
X-SIPLIST1
X-Sigma-Backend
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-Request-URI
X-Rocket-Build-Number
X-Sigma
X-Scale
X-Varnish-CookieHashed-On
X-Origin-Response-Time
X-Hash
X-Viewer-Country
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
Apple-News-Services-Host
Cache-Host
X-Minions-Version
X-Mvc-Supplant-Cachable
Candidate-Md5Url
X-Loc
Adler-Geo
X-VG-TLSProxy
Apple-News-Services-Parsed-Url
Apple-News-Services-Handled
Apple-News-Services-Request-Url
X-Optimistic-Header
X-Irp-Debug
X-Thinkindot-L3
X-Tx-Id
X-Sucuri-ID
Thinkindot-CacheControl
X-Worker
X-Sucuri-Cache
X-HS-Content-Campaign-Id
Thinkindot-CacheControl-Type
Thinkindot-Control
Fastly-Backend-Name
Server-Host
TDXMobile
X-Level-Front-Cache
X-CMSURLCustom
X-GG-Cache-Date
X-Geo-Header
X-Generated-On
X-Core-Value
Cluster
X-SB
X-S-Maxage
X-V-Cache
X-FC-Vary-Parameters
X-Fastly-Backend
X-ATG-Version
X-Var-Ttl
X-Branch-Name
X-Ckpd-Fst-Backend
X-Region-Sid
Memcached
X-Gamma-Serve
X-Block-Status
X-Rocket-Nginx-Serving-Static
Sever-Int
Wxu-Next-Region
Server-Hostname
X-Fetched-On
CDCHOST
X-Device-Os
X-Gen-Mode
Canary
X-Hnp-Log
Datacenter
User-Cache-Control
Server-Ext
Wxu-Next-Hostname
Wxu-Next-Commit
AKAMAI
X-Cache-Remote
Svr
X-Azure-Ref-OriginShield
Ec-Rule-Version
X-Mvc-Supplant-OutputCached
CloudFront-Viewer-Country
X-LB-NoCache
X-Scheme
X-NCache
Cache-Tv-Group
X-WA-Info
X-Newrelic-App-Data
Cache-Hits
Fastcgi-Cache-TTL
X-ND-Cache
SID
Pics-Label
X-Udemy-Cache-App-Namespace
WebServer
X-Tb-Optimization-Total-Bytes-Saved
X-Session-Fingerprint
Memory
Time
X-ZONE
Ssr
X-Via-Popv
X-Rebelmouse-Surrogate-Control
X-Pod-Name
X-Origin-Expires
X-Fastly-Cache
X-Rebelmouse-Cache-Control
X-Via-Poph
X-Via-Popn
X-Generated-In
X-Refresh
X-DC
Sid
X-Pass-Why
Server-ID
X-Up
X-Servedbyhost
Request-ID
Env
AMP-Access-Control-Allow-Source-Origin
X-Tumblr-Pixel-3
X-Presslabs-Stats
X-Wa
X-Edge-Pop
X-Dispatch
X-Akamai-Transformed
X-Fpc
X-Release
My-App
X-Cs
X-Ig-Push-State
X-Lambda-Id
X-Buckets
X-Cache-Date
X-Zone
X-Esi
X-MSEdge-Features
X-NC
X-NWS-UUID-VERIFY
X-Conf
X-MSEdge-Flight
X-EC-Lua
X-PX
X-MCACHE
X-ID
X-CS
X-VCL-Version
X-Endurance-Cache-Level
X-Req
CDN
X-Microcachable
GeoIp-Country-Code
X-CACHE-AGE
X-Dmc
X-Xrds-Location
X-LB-ID
CacheControlHeader
X-TX-ID
True-Client-Country-4JS
True-Client-IP
X-B3-Spanid
X-Webkit-CSP-Report-Only
Fastly-Drupal-Html
X-NGINX-Cache
X-Be
X-TH-Server
Magicmarker
X-RateLimit-Reset
X-CACHE-KEY
X-Vc
X-Op-Id-All
X-Wikidot-Backend
X-CSRF-TOKEN
X-Wikidot-Static-Cache
X-HS-Status
Hostname
X-TRACE-ID
True-Client-Ip
Path
X-GeoIP-Region-Code
GeoIP-Country-Code
X-GeoIP-Country-Code
Resin-Trace
X-Srv
X-Hyper-Cache
Tcn
X-Accel-Expires-Debug
X-Date
X-Vcl-Version
X-Check-Cacheable
X-CF-Lambda-Version
X-M-Log
X-Alfa-Service
X-Air-Hostname
X-Air-Trace-Id
X-Micro-Cache
X-M-Reqid
X-Air-Source
WWW-Authenticate
X-CF-Lambda-Fn
X-Air-Pt
X-Varnish-Beresp-TTL
X-Qnm-Cache
X-Vercel-Cache
Tracecode
Pramga
X-App
X-Vercel-Id
X-SERVER-NAME
X-LiteSpeed-Cache-Control
X-Datacenter
C-Via
X-Akamai-Pragma-Client-IP
X-RAMCache
Section-Origin-Responded
Section-Io-Id
X-Old-Content-Length
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
NtCoent-Length
Yjs-Id
X-Cache-Ttl
X-CLOUD-TRACE-CONTEXT
X-Edge-POP
Proxy-Connection
X-TrackingId
X-FPC
Powered-By
N-Cache
X-Webkit-Csp-Report-Only
YJS-ID
X-UA
X-Platform-Router
X-Platform-Cluster
X-Platform-Processor
X-Geo
X-Mly-Id
Fastcgi-X-Cache-Version
X-Via-CDN
X-PAYTM-SRV-ID
FSS-Cache
X-Platform
Hit
X-WA
On-Server
Esi-Enabled
X-Yandex-Sdch-Disable
X-Location
X-API-Version
X-Webstats-RespID
Server-Id
User-Agent
ENV
X-ServedByHost
Lb
X-Response-By
X-Lb-Id
X-Contensis-Viewer-Groups
X-Cache-ASPX
X-Dw-Trace-Id
X-Varnish-Authentication
X-Cdn-Forward
X-Vtex-Remote-Cache
HIT
X-Edge-Origin-Shield-Bytes
X-Node-Id
X-Edge-Origin-Shield-Region
X-Via-PopH
X-Vtex-Processado-Em
X-Via-PopV
Cdn
GeoIP-Latitude
X-Director
X-Via-PopN
X-Client-Ip
X-Service-Response-Time
X-AIR-PT
Sm-Log-Id
X-LI-Proto
X-Li-Pop
X-LI-UUID
Location
X-FORWARDED-FOR
X-From
X-Instance-Name
Srvid
X-FL-EDGE
X-Li-Fabric
X-Request-Start
X-TT-LOGID
X-SD-PageType
X-LAGOON
X-Server-IP
X-Akamai-ERRuleID
Dnion-Transfer-Encoding
Geoip-Latitude
X-Akamai-ERPolicy
Locid
X-CUA
X-Traceid
X-Render-Time
X-Test
Swift-Performance
X-DataCenter
X-RPS
X-DB
X-HA-Backend
Ohc-File-Size
Uri
X-DI
X-RPM
X-DW
X-RSL
X-DSS
X-Via-Ucdn
Nginx-CQVIP
Cache-Key
X-LiteSpeed-Tag
X-Request-Url
XServer
PICS-Label
X-CF-Powered-By
X-Litespeed-Cache-Control
X-Wp-Cf-Super-Cache
X-Wp-Cf-Super-Cache-Cache-Control
X-PERF
DynaTrace
X-Cache-Backend
X-Cache-Expires
M-TraceId
X-Cdn-Request-ID
X-ApacheServer
Server-Ttl
X-Proxy-Upstream
X-B3-ParentSpanId
X-HostName
X-Fastly-Cache-Hits
Wpo-Cache-Message
Vha6-Origin
Wpo-Cache-Status
X-Fastly-Backend-Reqs
X-Lb-Nocache
X-Ips-Loggedin
X-Ramcache
Warning
X-Proxy-CacheRZ
XkeyRZ
CountryCode
X-Cache-Ngx
Wp-Super-Cache
X-Ittl
X-NS-Authorization
X-Ntj-Investigation-Id
X-IBD-SID
X-GoCache-CacheStatus
X-Global-Transaction-ID
X-Git-Commit
X-Group
X-Header-Sub
X-Kebab
X-IBD-Cache
X-Is-SSL
X-LbNode
X-Matome-Cached
X-GG-Cache-Status
X-Newegg-Flow
X-MTS-Cache
X-N-OperationId
X-Matched-Rule
X-Loadbalancer
X-NFL-Geo
X-Keep
X-Nerd
X-NFL-Dma
X-Newegg-Index
X-Kebabable
X-Ee-Origin
X-Delivery
X-Dehri-Date
X-Developed-By
X-Doge
X-DT-Node
X-Dcm-Pdtf
X-Conten-Type-Options
X-Cms-Device
X-Coindesk-Cache
X-Colour
X-Container-Uri
X-Edge-IP
X-Ee-Generated-By
X-Farm
X-F-Status
X-Fastly-Is-Edge
X-Frame-Option
X-Fstrz
X-Eventloop-Lag
X-ETag
X-NXG
X-Ee-Request-Date
X-Ee-Request-Id
X-Eid
X-Full-Ttl
X-Route-Akamai
X-True-Client-Ip
X-Tried-To-Kebabify
X-U-Cache
X-Upstream-State
X-User-Auth
X-Toujours-Debout-Location
X-Toujours-Debout-Branch
X-SVR-IIS
X-Stack-Name
X-Svr-Proxy
X-Test-Nginx-Ingress
X-Timestamp
X-Utime
X-V2-Infrastructure
X-Xms-Page-Cache-Actions
X-WSR2
X-YSpaceId
XV-Cache
XV-H
X-WP-Bypass
X-Web-Hosting
X-Vary-Devices
X-Ver
X-Wag-Acs
X-Waitingroom
X-SSLProxy
X-Square
X-PG-ACCESS
X-Paywall
X-PGF-Deflate
X-Pver
X-R-Cache
X-PageType
X-OVcl-Cache
X-Okws-Version
X-Odoo-Frontend
X-Onedio-Env
X-Origin-Ops
X-OVcl
X-Reboot
X-Redis
X-ServiceName
X-Server-L
X-Sh
X-Site
X-SMP-JWT
X-Save-Cache
X-Ruby
X-Render-Method
X-Request-Origin
X-Route
X-Cf-Node-Idx
X-Nyt-Data-Last-Modified
X-ARRRG1
Joe-X
Is-Https
NB-ESI
Nikkei-App-Version
NLCacheNote
HTTPProtocol
HServer
CMS-200
Cluster-Host
Deeplink
Ec-Policy-Id
H1
Npm-Cost
Npm-Remaining
Proxy-Cache
Panzer-Cache-Control
RawURL
Region
Request-Uuid
Origin-Site
Ok-Edge-Key
Ns
Ns-Ua
Ok-Cache-Status
OK-Edge-Date
Cf-Wrk
Cf-Locale
XM
PFcat
WZWS-RAY
X-Proxy-Cache-Hk
X-Mg-Cache
X-HN
X-VarnishDD-TTL
Req-ID
Fastcgi-Cache-Ttl
X-Moov-Xdn-Version
X-Moov-T
SRV
X-ElasticPress-Query
X-Yottaa-OS
Cache-Stat
Akamai-X-Url
Cachekey
Cdn-Country-Code
Cf-Device-Type
X-Th-Server
X-Serial
CF-Cached-On
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
Cneonction
Rt-Proxy-Cache
Scheme
X-ASF-Cache
X-Arena-Request-Id
X-AspNetWebPages-Version
X-Backend-TTL
X-Backside-Transport
X-Ar-Stats
X-Apache-Server
X-Akamai-DeviceOS
X-Akamai-CacheKeyMod
X-Akamai-DeviceType
X-Akamai-Native
X-Amz-Meta-Cb-Modifiedtime
X-BeanStalkRole
X-BeanStalkStage
X-Cache-Response
X-Cache-ReqUri
X-CacheVersion
X-Cc-Via
X-CDN-Pop
X-Cache-Reason
X-Cache-Proxy
X-Cache-Cookie
X-Cache-IsMobileDevice
X-Cache-Length
X-Cache-NPR
X-AEO-Platform
X-Accor-Asset
Sw
Store-Cloud-Cache
T-Request-Id
Technodrome
Time-Cloud-Cache
SII
Shieldsquare-Response
Selected-Route
Served
Service-Uuid
SFRVia
Ttl
TWC-AK-Req-ID
X-77-NZT-Ray
X-77-NZT
X-Accel-Version
X-Accepted-Fulllang
X-Accepted-Language
Vttl
Userver
TWC-PATH-LOCALE
TWC-Subs
TWC-Unit
Uniqueid
X-CDN-Pop-IP