Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
X-Frame-Options
Expires
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Accept-CH
CF-Cache-Status
ETag
X-XSS-Protection
Expect-CT
Accept-Ranges
Pragma
X-Powered-By
CF-RAY
X-Cache
Via
Age
Content-Security-Policy
Alt-Svc
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-Download-Options
X-Request-Id
X-Timer
X-Xss-Protection
Access-Control-Allow-Headers
Access-Control-Allow-Methods
CF-Ray
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
Accept-CH-Lifetime
Content-Security-Policy-Report-Only
X-DNS-Prefetch-Control
X-AspNet-Version
X-Runtime
Accept-Ch
Permissions-Policy
Server-Timing
X-Drupal-Cache
X-Generator
X-Envoy-Upstream-Service-Time
X-Cache-Status
X-Cacheable
X-FRAME-OPTIONS
X-Iinfo
X-Drupal-Dynamic-Cache
X-Ua-Compatible
Timing-Allow-Origin
X-CONTENT-TYPE-OPTIONS
Feature-Policy
X-Content-Security-Policy
Xkey
Upgrade
Access-Control-Expose-Headers
X-CDN
X-XSS-PROTECTION
Content-Encoding
Status
X-AspNetMvc-Version
Access-Control-Max-Age
X-Amz-Request-Id
Host-Header
X-Amz-Id-2
X-Age
Request-Context
Cf-Edge-Cache
X-Backend
X-Robots-Tag
X-Hacker
Keep-Alive
X-Request-ID
X-Via
Cf-Apo-Via
X-Amz-Version-Id
X-Turbo-Charged-By
X-AH-Environment
X-Rq
X-Cache-Group
X-Vhost
X-Server
X-Dispatcher
X-Proxy-Cache
X-Ws-Request-Id
EagleId
CONTENT-SECURITY-POLICY
X-UA-Device
X-Varnish-Cache
Pantheon-Trace-Id
Grace
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-OneAgent-JS-Injection
X-Server-Powered-By
X-Litespeed-Cache
X-Pingback
Allow
X-Page-Speed
X-Dns-Prefetch-Control
X-WebKit-CSP
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-Node
X-FTR-Request-ID
X-Device
X-Cache-Lookup
EagleEye-TraceId
X-Server-Id
X-Host
X-Backend-Server
X-Country-Code
Surrogate-Control
X-Readtime
X-Cloud-Trace-Context
X-Akam-SW-Version
Cf-Railgun
X-Ruxit-JS-Agent
X-HW
X-Response-Time
Accept-Ch-Lifetime
X-LiteSpeed-Cache
X-Ua-Device
Cache-Tag
P3p
Cf-Request-Id
X-Amz-Server-Side-Encryption
Content-Location
Cross-Origin-Opener-Policy
X-Rack-Cache
X-Nginx-Upstream-Cache-Status
X-Nginx-Cache-Status
X-Trace
Service-Worker-Allowed
Request-Id
X-TraceId
X-Application-Context
Fastly-Restarts
X-Content-Type
X-Nf-Request-Id
X-Times
Rating
X-TtlSet
X-PC
X-Vname
X-Clacks-Overhead
X-Cnection
X-Midtier
X-Mcache
X-Browser-Type
X-Edge
X-ESI
X-FTR-Backend-Server
X-FTR-Backend
X-FTR-Cache-Status
X-FTR-Balancer
X-Country-Code-Real
X-FTR-Expires
X-Vcap-Request-Id
Edge-Control
X-Cache-TTL
Origin-Trial
X-FastCGI-Cache
X-Element-Page-Cache
Surrogate-Key
X-NWS-LOG-UUID
X-D2id
X-Powered-By-Plesk
X-Country
X-Cdn-Fetch
X-Oneagent-Js-Injection
X-Exp-Id
X-GoogleNews-Bot
X-Kinja-Server
X-Kinja-Revision
X-Kinja-Build
X-Exp-Variant
X-Kinja
X-Abt-Application-Version
X-Ac
Verso
X-Upstream
X-Mod-Pagespeed
X-Navigation-Version
X-Url
X-ORACLE-DMS-RID
X-B3-TraceId
X-Amz-Rid
Akamai-GRN
Pinterest-Generated-By
X-Pinterest-Rid
Pinterest-Version
X-Language
Nginx-Cache
X-ECACHE
Display
X-Middleton-Display
X-GitHub-Request-Id
X-Sol
Pagespeed
S
X-Envoy-Decorator-Operation
X-Kraken-Loop-Name
X-Erf-Bev-Bev-Is-Generated
X-Instrumentation
X-PDP-UNCACHING-HASH
X-Erf-Bev-Bev
X-Server-Lifecycle-Phase
Response
AR-PoweredBy
X-Middleton-Response
AR-Request-ID
AR-ATIME
X-MS-InvokeApp
Edge-Cache-Tag
X-Ratelimit-Limit
X-Goog-Hash
X-Distributor
X-Resp-Is-Stale
SPIisLatency
SPRequestDuration
SPRequestGuid
X-SharePointHealthScore
X-Edge-Location-Klb
X-Kinsta-Cache
X-Ttl
X-ARC
X-NGENIX-Cache
X-Ser
X-Client-IP
Access-Control-Request-Method
Front-End-Https
X-Dw-Request-Base-Id
X-Shield-Request-Id
X-Amzn-Trace-Id
X-Ruxit-Js-Agent
X-Content-Digest
X-Ezoic-Cdn
RTSS
X-Recruiting
X-Varnish-TTL
X-Cache-Key
Cache-Status
X-Version
X-T
X-Mg-S
TP-Cache
Public-Key-Pins
X-Powered-CMS
X-HS-Hub-Id
Fastcgi-Cache
X-HS-Content-Id
X-HS-Cache-Config
X-MSEdge-Ref
X-Accel-Expires
Arr-Disable-Session-Affinity
AR-CACHE
X-Daa-Tunnel
X-Ismobilevalue
Realpath
X-Cluster-Name
X-Id
Cache-Tags
X-Cached
X-Correlation-Id
Content-MD5
X-Content-Security-Policy-Report-Only
X-Webkit-Csp
Ar-SID
YJS-ID
X-Request-Processing-Time
X-Request-Received
X-Forwarded-For
X-HS-Combine-CSS
X-Request-Device-Id
X-Newrelic-App-Data
Payment
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-DIS-Request-ID
X-Fastly-Request-ID
X-Ua-Browser
X-GUploader-UploadID
X-Xrds-Location
X-Cambria-Cache-Control
X-Jurisdiction
X-HP-Trace-Id
X-HP-Webp
X-HS-CF-Cache-Status
X-Azure-Ref
X-COUNTRY
X-RateLimit-Remaining
X-HS-Prerendered
X-Amz-Replication-Status
Content-Disposition
X-Meli-Trace-Bu
X-Meli-Trace-Platform
X-Meli-Trace-Site
X-Server-Name
X-Ratelimit-Remaining
Count-Hit
Cross-Origin-Resource-Policy
X-Px
X-Origin-Server
X-Ratelimit-Reset
X-Amz-Meta-S3cmd-Attrs
X-Protected-By
X-Unique-Id
Accept-Charset
X-Page-Id
MicrosoftSharePointTeamServices
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Logged-In
X-AppVersion
X-Az
X-Activity-Id
X-Proxy
Cross-Origin-Embedder-Policy
X-FB-Debug
Cleartype
X-Www-Served-By
X-VARITI-CCR
X-Rid
X-ORACLE-DMS-ECID
X-Git-Hash
X-SERVER-NAME
X-Request-Handler-Origin-Region
X-Microsite
X-Load-Cache
X-Amzn-RequestId
X-Amz-Apigw-Id
X-TTL
X-LLID
X-Goog-Metageneration
Version
X-Template
X-Geo-Country
X-Forwarded-Proto
X-Varnish-Backend
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-PressLabs-Stats
X-Upgrade-Enabled
X-Hits
Server-Node
X-CST
X-B3-Sampled
Server-Name
X-WebKit-CSP-Report-Only
X-Hostname
X-Content-Options
X-TT
X-App-Server
Section-Io-Cache
X-Grace
Access-Control-Allow-Method
Healthy
X-Fb-Rlafr
X-Device-Type
X-B
X-Varnish-Server
Viewport
X-Varnish-Grace
Alternate-Protocol
Fastly-SIE
Fastly-SWR
X-Frontend
Mrf-Cache-Status
MRF-Tech
X-B3-TraceId-Primal
X-Status
X-Goog-Stored-Content-Length
X-Request-Guid
X-Goog-Stored-Content-Encoding
TCN
X-Goog-Storage-Class
X-Goog-Generation
Upgrade-Insecure-Requests
X-Contextid
DC
Host
X-Magnolia-Registration
X-Requestid
AKAMAI-GRN
Retry-After
X-EdgeConnect-Cache-Status
X-Amzn-Remapped-Content-Length
MS-Author-Via
X-Cache-Age
X-CSRF-Token
X-Cache-Control
X-App-Version
Frame-Options
X-Tt-Trace-Tag
X-Tt-Trace-Host
Amp-Access-Control-Allow-Source-Origin
X-Debug
X-Type
X-Revision
X-Buckets
X-Varnish-Ttl
X-Origin-TTL
X-Origin-CC
X-Response-Served-From
X-Original-Request-Id
X-Hl-Ver
X-INCAP-ABP
X-ProcessESI
X-RemovedCookies
X-G
X-Akamai-Edgescape
X-Adobe-Content
X-Adobe-Loc
SD-X-WS
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-UUID
X-Lambda-Id
X-Debug-IsConnected
X-Cache-Status-Check
Access-Control-Request-Headers
X-Content-Powered-By
X-Debug-IsPreview
Section-Io-Id
Cross-Origin-Opener-Policy-Report-Only
Cross-Origin-Embedder-Policy-Report-Only
X-Mobile
X-NYM-Debug-Backend
X-Oracle-Dms-Ecid
X-N
X-RTag
X-Trace-Id
X-ServerID
X-Akamai-Request-ID2
X-Seen-By
Ms-Operation-Id
X-Instance
MS-CV
X-Backend-Name
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Tumblr-Pixel-0
X-Storage
X-Tumblr-Pixel
X-Tumblr-Pixel-1
X-Server-W
X-Tumblr-User
X-AB
X-Is-Bot
X-Rendered-As
X-Dc
NGB
Charset
X-Mg-Request-UUID
X-Framework
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
X-RM-Cache-TTL
Cache
X-Vcl-Version
X-Yandex-Req-Id
X-Tec-Api-Root
X-Tec-Api-Origin
X-Tec-Api-Version
Webserver
Filterid
X-DataDome
X-Cache-Time
Accept-Language
X-VC-Cache
Paypal-Debug-Id
X-Request-Bu
X-Request-Platform
X-Request-Site
SRV
X-B3-SpanId
Refresh
X-Time
Onion-Location
X-URL
X-Cache-Hit
X-ECache
X-HITS
X-Ms-Request-Id
X-Ms-Version
X-F-Cache
X-Real-IP
X-Region
YJS-CacheStatus
X-Node-Name
X-Hcs-Proxy-Type
X-CCDN-CacheTTL
X-User-Agent
X-CCDN-Origin-Time
CDN-RequestId
X-Environment-Context
X-Mode
X-L-Path
Xet-Cookie
X-IPS-LoggedIn
Liferay-Portal
Priority
X-Fastcgi-Cache
GEO-INFO
X-Service
X-HTML-Minification-Powered-By
X-Rocket-Nginx-Serving-Static
X-LB-Cache
X-CLOUD-TRACE-CONTEXT
X-Tb
X-Pass-Why
Protected
X-Drupal-Cache-Tags
Country
X-Adobe-Source
Backend
Cross-Origin-Window-Policy
X-Datadog-Sampling-Priority
X-Datadog-Trace-Id
X-Rule
X-Datadog-Sampled
X-Datadog-Parent-Id
Meta-Geo
X-Is-Mobile-Only
X-Cloudmap
X-Is-Modern-Browser
Selected-Fe
X-Is-Desktop
X-Browser-Name
X-Is-Supported-Browser
X-Is-Tablet
X-Extlb
X-Geo-Region
X-Is-Mobile
X-Cache-Expired-At
X-Proxied
X-SaId
X-JoinUs
X-Zipkin-Id
X-Timing-Wait
X-Proxy-Build
X-UPSTREAM-Address
X-Tcp-Rtt
X-Routing-Service
X-Rewrite-Enabled
X-Rn-Rsrv
X-Handled-By
X-Whom
X-Httpd
X-Hit
X-Servername
Url
X-BYPASS-REASON
X-Alternate-Cache-Key
OT-Force-Account-Verify
X-Storefront-Renderer-Rendered
X-VC
X-Varnish-Beresp-Grace
X-Shopify-Stage
X-Wix-Request-Id
X-Forwarded-Host
X-ProxyCache-Key
X-Proxy-Cache-Info
X-Origin
X-ProxyCache-Status
X-Origin-Cache
X-RCS-CacheZone
X-Web-Node
X-Generation-Time
X-Provided-By
X-VCT
Atl-Traceid
X-Cdn-Origin
X-Logging-Id
X-Cluster
X-Format
X-MP-GENERATED-AT
Mn-Server-Ip
X-Skip-Cache
TWC-Connection-Speed
TWC-Device-Class
X-Urbn-Context-Path
X-Urbn-Site-Id
X-FB-TRIP-ID
X-Cacheable-TTL
TWC-GeoIP-City
X-Edge-Location
Cache-Hits
Environment
Expiry
Fastcgi-Useragent
Locale
X-Loop
X-Connection-Hash
X-Tncms
TWC-GeoIP-Country
Property-Id
X-Detected-As
X-Origin-Date
ServerID
Webcakes-App-Name
TWC-GeoIP-DMA
Webcakes-App-Version
Webcakes-Region
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-S
Uber-Trace-Id
Web-Mar-Node
TWC-GeoIP-Region
TWC-Privacy
TWC-GeoIP-LatLong
X-WP-CF-Super-Cache-Active
X-Origin-Hint
TWC-Locale-Group
X-Vcache
X-Auth-Group-Type
LB
X-Tumblr-Pixel-2
ServedBy
X-Cache-Action
X-Locale
X-Labrador-Cache-Channel
Apigw-Requestid
X-Tumblr-Pixel-3
X-Drupal-Cache-Contexts
X-Soup
X-Redis-Cache
X-Director
X-Hosted-By
DB-Nickname
X-PHP-Host
X-Cms-Context
X-App-Environment
X-Fetched-On
X-FW-Static
X-FW-Version
X-Say-TTL
X-SayCDN-TTL
X-Scope-Id
X-Served-From
X-FW-Type
X-FW-Dynamic
X-Say-Cacheable
X-Debug-Info
X-Cluster-Node
X-Restarts
X-Cache-Host
X-FW-Serve
X-FW-Hash
X-Endurance-Cache-Level
X-FW-Server
X-Cache-Debug
Filters
X-IPLB-Instance
X-Server-ID
X-IPLB-Request-ID
X-NewRelic-App-Data
X-Platform
X-Mly-Id
X-CDN-Forward
X-R9-Blue-Green-Version
X-XRDS-Location
Node
Front
X-Api-Version
X-Tt-Logid
AR-SID
X-B3-Traceid
X-GEO
X-CDN-Cache-Status
WPO-Cache-Status
X-No-Session
Xserver
X-Optimistic-Header
X-ShopId
X-Varnish-Age
X-UA
X-ShardId
X-Sorting-Hat-PodId
X-Varnish-Cache-Hits
X-Sorting-Hat-ShopId
X-Varnish-Beresp-Ttl
Countrycode
X-Lagoon
Cache-Tv-Group
X-WP-CF-Super-Cache-Cookies-Bypass
X-Presslabs-Stats
X-Fastly-Request-Id
X-Wormhole-Sdk
X-Generated-By
X-SRV
X-NWS-UUID-VERIFY
X-B-Cache
X-Signature
X-CACHE-AGE
Referer-Policy
X-Client-Ip
X-Webstats-RespID
AMP-Access-Control-Allow-Source-Origin
X-Site-Version
X-Azure-Ref-OriginShield
From-Origin
X-IsAdmin
X-Ua
Request-ID
Cache-Provider
X-VWS-Id
X-LJ-Flow-ID
X-AWS-Id
X-Cache-Rule
X-Cache-Operation
X-PHP-Backend
X-Accel-Version
X-Auto-Login
Location
X-Worker
X-NF-Request-ID
S-Rt
X-TA-CDN-Provider
X-VC-TTL
X-Tx-Id
X-Upstream-Ct
X-Upstream-Ht
Apple-News-Services-Handled
X-Bl-Debug
X-B-Cookie
CDN-CachedAt
Lang
X-Bc-Bl
X-External-Request-Id
Origin-Agent-Cluster
Apple-News-Services-Request-Url
X-BCube-Filmed-By
X-A-Dam
CDN-EdgeStorageId
X-ApacheServer
X-Application
CDN-Cache
X-Developer
Apple-News-Services-Host
X-Ec-Fail
X-Ec-GeoHdr
X-Access
WPO-Cache-Message
X-Aed
Source
X-Destination
X-A-Wwc
Candidate-Md5Url
X-Cache-NE
X-Conf
X-Clientip
X-Tb-Optimization-Total-Bytes-Saved
Apple-News-Services-Parsed-Url
X-A-Dcw
X-Varnish-Hostname
X-A-Dgt
X-Content-Age
X-D
X-A
X-ScT
Rendered-Blocks
Redirect-Candidate
X-Section
X-Vdms-Version
X-VG-TLSProxy
X-S-Cookie
DCR-Decision-By
CDN-PullZone
X-Rocket-Build-Number
X-Rojux
X-Sigma
X-Sigma-Backend
N-Cache
Ngx.Var.Host
Host-ID
Meta-Geo-Continent
MD5-Digest
Origin
Fl-Custom-Application
Pragrma
Expect-Staple
Powered-By
X-SRCache-Key
X-PERF
DCR-Processing-Time-Ms
CDN-Uid
Xc-Version
X-Vtex-Remote-Cache
X-Ig-Push-State
CDN-RequestPullSuccess
X-GeoCountry
X-A-Ccd
CDN-RequestCountryCode
CDN-RequestPullCode
X-GeoCode
X-Loc
X-Ig-Origin-Region
X-Org
Sslversion
ServerName
X-Xfnlog-Site
X-Litespeed-Cache-Control
Origin-EX
Log-Origin
Req-Svc-Chain
Origin-CC
Mail-Subject
Origin-Site
RNT-Machine
Odigeo-Trace-Id
X-Acquia-Purge-Cdn-Unconfigured
Pics-Label
Time-Cloud-Cache
Web-Mar-Region
We-Hiring
X-Akamai-Device-Characteristics
X-AK-Request-ID
X-Aicache-OS
RNT-Time
Store-Cloud-Cache
Vix-Hermes-Req-Id
Wxu-Next-Region
Wxu-Next-Hostname
Wxu-Next-Commit
X-BBC-Edge-Cache-Status
X-Ee-Request-Date
X-Render-Time
X-Policy
X-Req
X-Save-Cache
X-SIPLIST1
X-SD-PageType
X-PAYTM-SRV-ID
X-Origin-Expires
X-Micro-Cache
X-Men
X-Mvc-Supplant-Cachable
X-Node-Id
X-VG-WebCache
X-Old-Content-Length
X-Slack-Backend
X-Slack-Shared-Secret-Outcome
X-Varnish-Authentication
X-V-Cache
X-Varnish-Beresp-Status
X-Varnish-CookieHashed-On
X-Varnish-Director
X-Varnish-CookieINHashed-On
X-Uri
X-Up
X-Vary-Devices
X-Sn-Servicetimems
X-Varnish-Remaining-TTL
X-SVT-ORM-RULES
X-UA-Device-Type
X-SVT-ORM-VERSION
X-Internal-TTL
X-HS-Content-Campaign-Id
X-DefHash
X-DefElseHash
X-Depends
X-Server-IP
X-Ee-Origin
X-Ee-Generated-By
X-CUA
X-Csrf-Jwt
X-CGP
X-Cache-Aspx
X-Cms-Device
X-Contensis-Viewer-Groups
X-Core-Value
X-Content-Length
X-Ee-Request-Id
X-Epic-Correlation-Id
X-GeoIP-City
Country-Code
X-GeoIP-Country-Code
X-GeoIP-Region-Code
X-Hash
X-GoCache-CacheStatus
X-Gamma-Serve
X-From
X-Eu-Site
X-ND-Cache
X-FC-Vary-Parameters
X-Fmm-Version
X-Forwarded-Site
X-Bug-Bounty
X-Action
Gannett-Cam-Experience-Id
Cluster
DSUID
Fastly-SSL
L5d-Success-Class
X-Cs
Cdnsip
Cdncip
Sid
Gh-Request-Id
IsBot
L
Cmstype
Cmsid
CF-IPCountry
CDCHOST
Ha-Gx-Prefs
Canary
X-Sucuri-Cache
X-Reqid
X-NGINX-Cache
X-Parent-Response-Time
X-Region-Sid
X-Pubstack
X-Block-Status
X-Bip
X-Backend-Instance
X-Request-URI
X-Amz-Storage-Class
X-Gen-Mode
Azure-Version
C-Via
X-Thanos
Azure-SiteName
X-Shield-Cache-Expires
Azure-InstanceId
X-App-Name
Azure-RegionName
X-Cache-Date
X-SB
X-Op-Id-All
X-Ion-Hop
X-Ion-Healthy
X-Jungle-Id
X-Level-Front-Cache
X-Ec-Custom-Error
X-Human
X-Hnp-Log
X-Generated-On
X-Gdpr
X-Frame-Option
X-FORWARDED-FOR
X-HN
X-Dispatcher-Server
X-LSADC-Cache
X-Origin-Time
Cache-Contol
X-Path
X-Air-Pt
X-Proto
X-Nyt-Route
X-NMSegId
X-Debug-Cache-Store
X-Debug-Cache-Fetch
X-Date
X-Mvc-Supplant-OutputCached
X-Cache-FS-Status
Azure-SlotName
Server-Host
Content-Style-Type
X-Vmg-Version
RewriteTeamHook
X-Viewer-Country
Content-Script-Type
TDXMobile
X-Vercel-Id
X-Via-Fastly
X-We-Are-Hiring
X-Wikidot-Backend
X-Fastly-Backend
Nord-Request-ID
NM-Fastcgi-Cache
Machine
PFcat
Fastly-Backend-Name
Release
X-Wikidot-Static-Cache
X-CacheTTL
Thinkindot-CacheControl
RewriteTestHook
X-VarnishDD-TTL
V-Age
User-Cache-Control
Tube-Return
X-Thinkindot-L3
Click-Count-Action-Start
X-Accel-Expires-Debug
X-AB-Test
X-Thinkindot-L1
Tube-Got-Results
Click-Count-Error
X-Vercel-Cache
Tube-Get-Contents
Thinkindot-CacheControl-Type
Tube-Got-Eval
X-Edge-Server
Cdn-Request-Time
X-Location
X-DPWN-IS-SECURE
Platform
Cdn-Host
X-Gzip
X-Esi-Check
Producers
X-ElasticPress-Query
Fastly-GeoIP-CountryCode
X-Cache-Id
CacheControlHeader
X-B3-Trace-ID
CloudFront-Viewer-Country
X-Moov-Xdn-Caching-Status
X-Moov-Xdn-Version
X-Moov-T
X-Proxied-Request
NGX
XM
X-Source
X-Sucuri-ID
X-Origin-Response-Time
Fastly-Drupal-HTML
Mime-Version
X-Pad
X-ZONE
X-Cached-By
X-Varnish-Hits
X-Refresh
Debug
Load-Balancing
X-Via-Popv
X-Servedbyhost
Cookie
X-Via-Poph
X-Via-Popn
X-Datadome
X-APP
X-AIR-PT
X-Srv
X-Nginx-Cache-Key
X-HA-Backend
X-Debug-Service
GeoIP-Latitude
GeoIp-Country-Code
Server-ID
True-Client-Country-4JS
X-TH-Server
Cdn
X-Nananana
Traceparent
X-DynaTrace-JS-Agent
Server-Hostname
Sever-Int
Product
Server-Ext
HA-Ipaddr
X-Litespeed-Tag
X-Zone
X-TT-LOGID
X-Webkit-CSP
X-Amz-Meta-Cb-Modifiedtime
X-Ez-Minify-Html
Show-Do-Not-Sell-Link
X-Fpc
X-Cache-VC
WZWS-RAY
X-B3-Parentspanid
X-Wa
X-GeoIP
X-Cache-Backend
X-Nc
X-Cdn-Forward
X-Newrelic-Synthetics
X-LB-ID
X-Unity-Cache
HostName
Edge-Cache
DataCenter
X-User
Fastly-Drupal-Html
X-B3-Spanid
Tcn
SID
MIME-Version
X-VCL-Version
X-Nginx-Cache
X-Lsadc-Cache
X-CDN-Provider
X-Request-Start
X-AC
Lb
X-LB-NoCache
Resin-Trace
Akamai-Mon-Iucid-Del
X-Vc
XkeyR9
Serverhost
X-Service-Response-Time
A
Sm-Log-Id
Xkey-La3
X-Scheme
Wsr-Cache
Xkeylog
X-Proxy-CacheR9
X-Proxy-Cache-La3
X-RateLimit-Limit
X-HOST
X-Datacenter
X-LiteSpeed-Tag
CountryCode
X-TX-ID
Yjs-Id
Cs
Surrogated-Key
X-Request-Host
X-LiteSpeed-Cache-Control
X-Pool
X-CS
NtCoent-Length
X-Lb-Id
Hostname
X-NodeID
CDN
X-Dynatrace-Js-Agent
Uri
Esi-Enabled
X-HubSpot-Correlation-Id
X-Akamai-Pragma-Client-IP
Cdn-Requestid
Datacenter
X-WA
X-API-Version
X-RequestId
X-Vgn-Hpd-Reason
X-Fastly-Backend-Reqs
X-FPC
X-NC
X-VC-Age
X-Cache-Grace
X-Udemy-Cache-App-Namespace
X-ID
X-Air-Trace-Id
X-Air-Source
X-Air-Hostname
Proxy-Firewall
X-DynaTrace
Server-Id
X-Stale
Cr
Pramga
X-Via-JSL
X-HA-Application-Name
Yak-Timeinfo
Content-Secure-Policy
X-Styx-Info
X-Html-Minification-Powered-By
X-TIM-N
X-HA-Device-Type
X-Styx-Origin-Id
X-DataCenter
X-HA-Bot-Classification
N1-Cache
X-CSRF-TOKEN
T-Server
ServerHost
X-Var-Ttl
W
GeoIP-Country-Code
X-TimeS
RATING
Geoip-Latitude
X-Srcache-Fetch-Status
X-Srcache-Store-Status
X-Via-Edge
X-Via-SSL
X-Ez-Minify-Js
X-Via-CDN
Edge-Copy-Time
X-Shopid
X-Lb-Nocache
X-Varnish-Beresp-TTL
X-Sorting-Hat-Podid
X-Swift-Error
X-Sorting-Hat-Shopid
From-Cache
X-ServedByHost
Srv
X-Zen-Fury
X-Ha-Backend
X-Geolocation
Req-ID
X-Jobs
X-Shardid
X-Wp-Cf-Super-Cache-Cache-Control
X-Oracle-DMS-ECID
X-Wp-Cf-Super-Cache
X-Via-PopH
X-MSEdge-Features
True-Client-IP
X-CACHE-KEY
X-MSEdge-Flight
X-Via-PopN
WP-Super-Cache
X-Via-PopV
Cloudfront-Viewer-Country
X-App
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-Wp-Cf-Super-Cache-Active
X-LAGOON
X-Ssense-Shipping-Surcharge-Enabled
Ohc-File-Size
X-Ramcache
X-Ssense-Gql
X-Cdn-Srv
Ohc-Cache-HIT
X-Key
X-ByteArk-Cache
X-ByteArk-ReqID
FSS-Cache
X-Correlation-ID
X-VServer
On-Server
X-Proxy-Cache-LA2
X-Geo
X-Elasticpress-Query
Ngx
Cl-Cache
X-VTEX-Cache-Server
X-Web-Server
X-Sucuri-Id
X-VTEX-Cache-Time
X-Check-Cacheable
X-Powered-By-VTEX-Cache
X-Cdn-Cache-Status
X-Webkit-Csp-Report-Only
CF-Cached-On
X-Fastly-Cache
WebServer
X-ATG-Version
X-Serial
X-Th-Server
X-PageType
Akamai-X-True-TTL
X-DC
X-Iplb-Instance
Cf-Ipcountry
X-Iplb-Request-Id
Xkey-G-Jp
Warning
X-MiniProfiler-Ids
X-Limited
X-Beacon
My-App
Coldstone-Viewer-Country
X-Fastly-Cache-Status
X-Mg-Cache
Host-Name
X-Env
FSS-Proxy
Cneonction
Coldstone-Viewer-Country-Region-Name
X-Request-Url
Coldstone-Viewer-Currency
X-WA-Info
User-Agent