Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
X-Frame-Options
Expires
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Accept-CH
Last-Modified
X-XSS-Protection
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
CF-RAY
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Alt-Svc
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-Download-Options
Cf-Request-Id
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
X-Xss-Protection
Access-Control-Allow-Credentials
Accept-CH-Lifetime
Content-Security-Policy-Report-Only
X-DNS-Prefetch-Control
X-AspNet-Version
X-Runtime
Server-Timing
Permissions-Policy
X-Drupal-Cache
CF-Ray
X-Generator
X-Envoy-Upstream-Service-Time
X-Cache-Status
X-Ua-Compatible
X-Cacheable
X-FRAME-OPTIONS
X-Iinfo
X-Drupal-Dynamic-Cache
Timing-Allow-Origin
Feature-Policy
X-CONTENT-TYPE-OPTIONS
X-Content-Security-Policy
Xkey
Upgrade
Access-Control-Expose-Headers
Content-Encoding
X-CDN
X-XSS-PROTECTION
Status
X-AspNetMvc-Version
Accept-Ch
Access-Control-Max-Age
Host-Header
X-Amz-Request-Id
X-Age
X-Amz-Id-2
Request-Context
Cf-Edge-Cache
X-Backend
X-Robots-Tag
X-Hacker
X-Request-ID
X-Via
Cf-Apo-Via
X-Turbo-Charged-By
X-Rq
X-Amz-Version-Id
X-Cache-Group
X-Vhost
Keep-Alive
X-AH-Environment
X-Dispatcher
X-Server
X-Proxy-Cache
EagleId
X-UA-Device
X-Ws-Request-Id
CONTENT-SECURITY-POLICY
X-OneAgent-JS-Injection
X-Varnish-Cache
Pantheon-Trace-Id
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
Grace
X-Server-Powered-By
X-Dns-Prefetch-Control
Allow
X-Pingback
X-Page-Speed
X-WebKit-CSP
X-Swift-CacheTime
X-Swift-SaveTime
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Ali-Swift-Global-Savetime
X-Litespeed-Cache
X-FTR-Request-ID
X-Node
X-Device
EagleEye-TraceId
X-LiteSpeed-Cache
X-Host
X-Cache-Lookup
X-Backend-Server
Surrogate-Control
X-Country-Code
X-Server-Id
X-Readtime
X-Cloud-Trace-Context
X-Ruxit-JS-Agent
X-Akam-SW-Version
Cf-Railgun
X-HW
X-Response-Time
Cache-Tag
P3p
Content-Location
X-Amz-Server-Side-Encryption
Cross-Origin-Opener-Policy
X-Rack-Cache
X-Trace
X-Nginx-Upstream-Cache-Status
Service-Worker-Allowed
X-Nginx-Cache-Status
Request-Id
X-TraceId
Fastly-Restarts
X-Clacks-Overhead
X-Content-Type
X-Country
X-Application-Context
X-PC
X-TtlSet
X-Vname
Rating
X-Times
X-Cnection
X-ESI
X-Cache-TTL
X-Browser-Type
X-Edge
X-Midtier
X-Mcache
X-FTR-Backend
X-FTR-Backend-Server
X-FTR-Cache-Status
X-FTR-Balancer
X-Country-Code-Real
X-Vcap-Request-Id
Surrogate-Key
X-FTR-Expires
Accept-Ch-Lifetime
X-Ac
Origin-Trial
Edge-Control
X-Powered-By-Plesk
X-GoogleNews-Bot
X-Exp-Variant
X-Kinja-Build
X-Element-Page-Cache
X-D2id
X-Kinja-Revision
X-Abt-Application-Version
X-Cdn-Fetch
X-Exp-Id
X-Kinja
X-Kinja-Server
X-NWS-LOG-UUID
X-FastCGI-Cache
X-Ua-Device
Verso
X-Upstream
X-Nf-Request-Id
X-B3-TraceId
X-ORACLE-DMS-RID
X-Navigation-Version
X-ECACHE
X-Mod-Pagespeed
X-Amz-Rid
Nginx-Cache
X-Sol
Pagespeed
X-Middleton-Display
Display
X-Pinterest-Rid
Pinterest-Version
X-GitHub-Request-Id
Pinterest-Generated-By
X-Client-IP
X-Language
X-Kraken-Loop-Name
X-PDP-UNCACHING-HASH
Response
X-Erf-Bev-Bev
X-Server-Lifecycle-Phase
X-Middleton-Response
X-Erf-Bev-Bev-Is-Generated
X-Instrumentation
Akamai-GRN
X-Envoy-Decorator-Operation
X-Ratelimit-Limit
S
Edge-Cache-Tag
AR-PoweredBy
AR-Request-ID
AR-ATIME
X-Goog-Hash
X-Resp-Is-Stale
X-MS-InvokeApp
X-ARC
X-Kinsta-Cache
X-Edge-Location-Klb
X-Ser
X-Distributor
X-Content-Digest
SPIisLatency
SPRequestDuration
SPRequestGuid
X-SharePointHealthScore
X-Url
Access-Control-Request-Method
X-Cache-Key
X-Dw-Request-Base-Id
X-Ezoic-Cdn
Front-End-Https
X-NGENIX-Cache
X-Recruiting
X-Shield-Request-Id
RTSS
X-Amzn-Trace-Id
X-Oneagent-Js-Injection
Cache-Status
X-Version
X-Powered-CMS
X-Varnish-TTL
X-Ttl
Public-Key-Pins
X-T
Fastcgi-Cache
X-MSEdge-Ref
X-Mg-S
TP-Cache
Arr-Disable-Session-Affinity
X-Forwarded-For
X-Accel-Expires
X-Daa-Tunnel
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Cache-Config
X-Correlation-Id
X-Ismobilevalue
Realpath
X-Fastly-Request-ID
X-Cluster-Name
Cache-Tags
X-Cached
X-Id
X-Ruxit-Js-Agent
AR-CACHE
X-CST
X-Server-Name
X-HS-Combine-CSS
X-Request-Received
X-Request-Processing-Time
Payment
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Ua-Browser
X-DIS-Request-ID
X-Content-Security-Policy-Report-Only
Content-MD5
X-GUploader-UploadID
X-Newrelic-App-Data
X-Ratelimit-Remaining
X-TTL
X-HP-Trace-Id
X-Jurisdiction
X-HP-Webp
X-HS-Prerendered
X-HS-CF-Cache-Status
X-Cambria-Cache-Control
X-Xrds-Location
Content-Disposition
X-Webkit-Csp
X-RateLimit-Remaining
Count-Hit
X-Azure-Ref
X-ORACLE-DMS-ECID
X-Amz-Replication-Status
X-Px
X-Page-Id
Cleartype
X-Unique-Id
X-Request-Handler-Origin-Region
X-Ratelimit-Reset
Cross-Origin-Resource-Policy
X-Microsite
Accept-Charset
X-Proxy
X-Logged-In
X-FB-Debug
X-Git-Hash
X-Az
X-Activity-Id
X-Origin-Server
X-Protected-By
X-AppVersion
X-Rid
X-SRCache-Store-Status
X-SRCache-Fetch-Status
Cross-Origin-Embedder-Policy
X-VARITI-CCR
X-Www-Served-By
X-Load-Cache
X-LLID
X-Template
X-Goog-Metageneration
X-PressLabs-Stats
YJS-ID
X-Varnish-Backend
MicrosoftSharePointTeamServices
X-SERVER-NAME
X-URL
X-Amz-Meta-S3cmd-Attrs
Version
X-Forwarded-Proto
Server-Node
X-Hits
X-Geo-Country
Server-Name
Ar-SID
X-Upgrade-Enabled
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Hostname
X-Content-Options
X-Frontend
X-B3-Sampled
Section-Io-Cache
X-Varnish-Server
Viewport
X-Status
X-App-Server
X-Varnish-Grace
X-TT
X-B3-TraceId-Primal
X-Device-Type
X-Request-Device-Id
Mrf-Cache-Status
MRF-Tech
Alternate-Protocol
X-Fb-Rlafr
X-Grace
X-B
Fastly-SIE
Fastly-SWR
Access-Control-Allow-Method
TCN
X-Server-ID
X-Goog-Storage-Class
X-NF-Request-ID
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-Goog-Stored-Content-Length
Upgrade-Insecure-Requests
Healthy
X-Request-Guid
X-COUNTRY
Host
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Magnolia-Registration
Amp-Access-Control-Allow-Source-Origin
X-Buckets
X-CSRF-Token
X-WebKit-CSP-Report-Only
X-Varnish-Ttl
X-EdgeConnect-Cache-Status
DC
Retry-After
AKAMAI-GRN
X-Cache-Age
X-Debug
X-Wormhole-Sdk
X-Amzn-Remapped-Content-Length
X-Meli-Trace-Bu
X-Contextid
X-Meli-Trace-Site
X-Meli-Trace-Platform
X-Cache-Control
MS-Author-Via
AR-SID
X-Revision
X-Response-Served-From
X-Type
X-WP-CF-Super-Cache
X-Original-Request-Id
X-Instance
X-WP-CF-Super-Cache-Cache-Control
Cross-Origin-Embedder-Policy-Report-Only
Cross-Origin-Opener-Policy-Report-Only
X-Origin-CC
X-Seen-By
X-Adobe-Loc
X-Origin-TTL
X-Adobe-Content
X-Is-Bot
X-Yottaa-Optimizations
X-UUID
X-NYM-Debug-Backend
X-Rendered-As
X-Vcl-Version
X-Yottaa-Metrics
SD-X-WS
X-Backend-Name
X-Lambda-Id
X-Hl-Ver
Access-Control-Request-Headers
X-G
Section-Io-Id
X-Akamai-Edgescape
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-Debug-IsConnected
X-Mobile
X-Tumblr-Pixel
X-ServerID
X-Tumblr-User
X-Trace-Id
X-Mg-Request-UUID
X-Framework
X-Content-Powered-By
X-Debug-IsPreview
Charset
MS-CV
X-Server-W
X-RTag
X-Cache-Hit
Ms-Operation-Id
X-Storage
X-INCAP-ABP
X-RM-Cache-TTL
NGB
X-Dc
X-N
X-DataDome
X-App-Version
X-ProcessESI
X-AB
X-Akamai-Request-ID2
X-RemovedCookies
X-Request-Bu
X-Request-Site
X-Request-Platform
X-Cache-Status-Check
X-Cache-Time
X-Tec-Api-Root
X-Tec-Api-Version
X-Tec-Api-Origin
Frame-Options
Filterid
Refresh
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Time
Cache
Protected
X-Fastcgi-Cache
X-B3-SpanId
Accept-Language
X-Real-IP
SRV
X-Region
X-Node-Name
X-Oracle-Dms-Ecid
Webserver
CDN-RequestId
Paypal-Debug-Id
X-HITS
X-User-Agent
Onion-Location
X-Ms-Request-Id
X-Ms-Version
X-CCDN-CacheTTL
Cross-Origin-Window-Policy
X-CCDN-Origin-Time
X-Hcs-Proxy-Type
Liferay-Portal
X-LB-Cache
X-Datadog-Sampling-Priority
X-Datadog-Sampled
X-Datadog-Trace-Id
X-F-Cache
X-Cache-Expired-At
X-Datadog-Parent-Id
X-Whom
X-VC-Cache
X-IPS-LoggedIn
X-Requestid
X-HTML-Minification-Powered-By
X-WP-CF-Super-Cache-Active
Priority
X-Mode
X-Rocket-Nginx-Serving-Static
X-Pass-Why
Xet-Cookie
Backend
OT-Force-Account-Verify
X-Proxy-Cache-Info
X-L-Path
X-Tb
GEO-INFO
X-Environment-Context
X-Service
X-Drupal-Cache-Tags
X-Cacheable-TTL
X-App-Environment
X-Rewrite-Enabled
X-Rn-Rsrv
Meta-Geo
X-Proxied
Filters
X-Is-Supported-Browser
X-Tncms
X-Geo-Region
X-SaId
X-Vcache
X-Routing-Service
X-Servername
X-Handled-By
X-Is-Mobile
X-Cloudmap
X-Detected-As
X-Is-Tablet
X-Adobe-Source
Url
X-Loop
Fastcgi-Useragent
ServerID
X-Browser-Name
X-Debug-Info
X-Tcp-Rtt
Web-Mar-Node
X-Endurance-Cache-Level
X-UPSTREAM-Address
X-FW-Static
X-Is-Desktop
X-JoinUs
X-FW-Type
X-Zipkin-Id
X-FW-Version
X-FW-Server
X-FW-Serve
X-FW-Dynamic
X-MP-GENERATED-AT
X-Extlb
X-FW-Hash
TWC-Privacy
ServedBy
X-IPLB-Request-ID
Property-Id
X-Wix-Request-Id
Webcakes-App-Name
TWC-Locale-Group
Atl-Traceid
TWC-Connection-Speed
X-Storefront-Renderer-Rendered
TWC-GeoIP-DMA
TWC-GeoIP-Region
X-IPLB-Instance
Webcakes-App-Version
TWC-GeoIP-LatLong
X-Format
TWC-GeoIP-Country
TWC-Device-Class
TWC-GeoIP-City
X-Restarts
Country
X-Cache-Host
X-Origin-Date
X-Forwarded-Host
X-Varnish-Beresp-Grace
X-Hosted-By
X-Hit
X-Cdn-Origin
X-Rule
LB
X-Web-Node
X-Locale
X-Alternate-Cache-Key
Webcakes-Region
X-Director
X-Shopify-Stage
X-Generation-Time
X-Logging-Id
X-Origin-Hint
X-Httpd
Uber-Trace-Id
X-Scope-Id
X-Cms-Context
Mn-Server-Ip
X-Redis-Cache
X-Soup
X-Cache-Action
X-Edge-Location
X-BYPASS-REASON
X-ProxyCache-Status
X-ProxyCache-Key
X-Say-Cacheable
X-SayCDN-TTL
X-Cluster-Node
X-Skip-Cache
X-Say-TTL
X-Cluster
Apigw-Requestid
X-VC
X-ECache
Environment
X-Mly-Id
X-Labrador-Cache-Channel
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-XRDS-Location
X-Drupal-Cache-Contexts
X-FB-TRIP-ID
X-S
X-PHP-Host
X-Served-From
Selected-Fe
X-Origin
X-Proxy-Build
X-R9-Blue-Green-Version
X-Timing-Wait
X-Connection-Hash
X-Urbn-Context-Path
Locale
X-Urbn-Site-Id
X-Fetched-On
X-Auth-Group-Type
DB-Nickname
X-Tumblr-Pixel-3
Cache-Hits
Expiry
X-Origin-Cache
X-Tumblr-Pixel-2
X-GEO
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-VCT
X-RCS-CacheZone
X-ShopId
X-ShardId
X-No-Session
X-Cache-Debug
YJS-CacheStatus
X-Varnish-Cache-Hits
X-Yandex-Req-Id
X-NewRelic-App-Data
X-Source
X-Is-Modern-Browser
X-Varnish-Age
Front
Countrycode
X-SRV
X-UA
X-CLOUD-TRACE-CONTEXT
X-WP-CF-Super-Cache-Cookies-Bypass
WPO-Cache-Status
X-Api-Version
X-Lagoon
Node
Xserver
X-Varnish-Beresp-Ttl
X-Provided-By
X-Webstats-RespID
X-Is-Mobile-Only
X-Site-Version
X-CDN-Forward
X-Cdn
X-Platform
Cache-Tv-Group
X-Generated-By
From-Origin
Cache-Provider
X-Azure-Ref-OriginShield
X-TA-CDN-Provider
X-B3-Traceid
X-Accel-Version
Referer-Policy
X-CACHE-AGE
X-Xfnlog-Site
X-CDN-Cache-Status
X-B-Cache
X-Signature
X-VC-TTL
X-Ua
Request-ID
X-TT-LOGID
X-Presslabs-Stats
CF-IPCountry
X-Sucuri-Cache
X-PHP-Backend
X-NWS-UUID-VERIFY
WPO-Cache-Message
Location
CDN-CachedAt
X-Tx-Id
CDN-Cache
CDN-Uid
CDN-RequestCountryCode
CDN-PullZone
CDN-EdgeStorageId
CDN-RequestPullCode
CDN-RequestPullSuccess
X-Air-Pt
X-Reqid
AMP-Access-Control-Allow-Source-Origin
X-Tb-Optimization-Total-Bytes-Saved
X-Cache-Rule
X-Cache-Operation
X-Fastly-Request-Id
X-Optimistic-Header
X-IsAdmin
X-Tt-Logid
X-Sucuri-ID
X-Developer
X-A
X-D
X-Ec-Fail
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
Rendered-Blocks
Time-Cloud-Cache
Redirect-Candidate
X-Depends
Web-Mar-Region
Apple-News-Services-Host
X-Destination
Candidate-Md5Url
Sslversion
X-GeoCode
X-Ee-Request-Id
RNT-Machine
X-External-Request-Id
X-Forwarded-Site
X-Viewer-Country
Store-Cloud-Cache
X-Ee-Request-Date
X-Ee-Generated-By
X-Ec-GeoHdr
RNT-Time
Cdncip
X-Ee-Origin
Apple-News-Services-Handled
X-Core-Value
Lang
Log-Origin
X-A-Ccd
X-Action
X-Aed
X-Application
X-AK-Request-ID
X-Access
MD5-Digest
X-A-Dcw
X-A-Dam
Odigeo-Trace-Id
X-A-Dgt
Ngx.Var.Host
Meta-Geo-Continent
X-A-Wwc
X-Auto-Login
X-B-Cookie
X-Cms-Device
X-Clientip
X-Cache-NE
X-Conf
X-Contensis-Viewer-Groups
Origin
X-Content-Age
X-GeoCountry
X-Cache-Aspx
Expect-Staple
Fastly-SSL
Fl-Custom-Application
X-BCube-Filmed-By
X-Bl-Debug
DCR-Decision-By
DCR-Processing-Time-Ms
Cdnsip
X-Fmm-Version
Xc-Version
X-VG-TLSProxy
X-Vdms-Version
X-Section
X-Ig-Push-State
X-Varnish-Authentication
X-Ig-Origin-Region
XM
X-Sigma-Backend
X-Varnish-Director
X-Frame-Option
X-Origin-Expires
X-Loc
X-Sigma
X-SRCache-Key
X-Micro-Cache
X-Request-URI
X-Slack-Shared-Secret-Outcome
X-Old-Content-Length
X-ScT
X-Rojux
X-Vtex-Remote-Cache
X-Save-Cache
X-S-Cookie
X-VG-WebCache
X-Rocket-Build-Number
X-Slack-Backend
X-HS-Content-Campaign-Id
X-Vary-Devices
X-Worker
X-PERF
X-Origin-Time
X-Akamai-Device-Characteristics
X-Aicache-OS
X-BBC-Edge-Cache-Status
X-Backend-Instance
X-Bc-Bl
X-Varnish-Remaining-TTL
X-SIPLIST1
X-PAYTM-SRV-ID
X-App-Name
X-Pubstack
X-We-Are-Hiring
Wxu-Next-Commit
Wxu-Next-Hostname
Wxu-Next-Region
V-Age
User-Cache-Control
TDXMobile
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
X-Render-Time
X-Region-Sid
X-Policy
X-Path
X-ApacheServer
Host-ID
Cluster
X-Block-Status
X-Accel-Expires-Debug
X-Shield-Cache-Expires
X-Node-Id
X-SD-PageType
X-Uri
X-V-Cache
X-Epic-Correlation-Id
X-Eu-Site
X-Fastly-Backend
X-Human
X-Thinkindot-L3
X-Ion-Hop
X-Varnish-Beresp-Status
X-Ion-Healthy
X-Internal-TTL
X-FC-Vary-Parameters
X-Hnp-Log
X-Generated-On
X-GeoIP-Country-Code
X-Up
X-UA-Device-Type
X-GeoIP-Region-Code
X-Gen-Mode
X-Hash
X-From
X-Gdpr
X-GoCache-CacheStatus
X-Jungle-Id
X-Thinkindot-L1
X-Sn-Servicetimems
X-Moov-T
X-Content-Length
X-Men
X-Csrf-Jwt
X-Moov-Xdn-Caching-Status
X-GeoIP-City
X-Req
X-Bug-Bounty
X-Moov-Xdn-Version
X-CGP
X-CUA
X-Varnish-Hostname
X-Ec-Custom-Error
X-Level-Front-Cache
X-Varnish-CookieINHashed-On
X-Varnish-CookieHashed-On
X-DefHash
X-DefElseHash
ServerName
X-Date
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-Nyt-Route
X-Acquia-Purge-Cdn-Unconfigured
Azure-RegionName
Azure-SiteName
Azure-SlotName
IsBot
L
Origin-Agent-Cluster
Nord-Request-ID
L5d-Success-Class
Ha-Gx-Prefs
Gh-Request-Id
Country-Code
Cmsid
Cmstype
DSUID
CDCHOST
Azure-Version
Cache-Contol
Gannett-Cam-Experience-Id
Origin-CC
Azure-InstanceId
RewriteTeamHook
Req-Svc-Chain
RewriteTestHook
Server-Host
Origin-EX
X-LSADC-Cache
X-Dispatcher-Server
CacheControlHeader
C-Via
X-Mvc-Supplant-Cachable
X-NMSegId
Cdn-Request-Time
Content-Script-Type
X-SB
X-Op-Id-All
X-HN
X-Amz-Storage-Class
Click-Count-Error
Cdn-Host
X-Server-IP
X-Edge-Server
PFcat
X-CacheTTL
X-Wikidot-Static-Cache
X-Wikidot-Backend
X-Vmg-Version
X-Esi-Check
X-Vercel-Id
X-Vercel-Cache
X-Gamma-Serve
X-SVT-ORM-RULES
X-Gzip
X-Litespeed-Cache-Control
X-DPWN-IS-SECURE
X-AB-Test
X-Thanos
X-SVT-ORM-VERSION
X-Proto
Click-Count-Action-Start
N-Cache
Tube-Got-Results
X-Via-Fastly
X-B3-Trace-ID
Fastly-GeoIP-CountryCode
Tube-Return
X-Org
Machine
Pragrma
We-Hiring
Producers
NM-Fastcgi-Cache
Fastly-Backend-Name
Tube-Get-Contents
X-Cache-FS-Status
Release
X-Cache-Id
Content-Style-Type
X-Cache-Date
Origin-Site
X-VarnishDD-TTL
X-Bip
Platform
Tube-Got-Eval
Mail-Subject
X-VWS-Id
X-AWS-Id
X-LJ-Flow-ID
X-Parent-Response-Time
X-Proxied-Request
Fastly-Drupal-HTML
X-Mvc-Supplant-OutputCached
X-ElasticPress-Query
X-Origin-Response-Time
Canary
X-Location
Source
Sid
X-ZONE
X-Litespeed-Tag
X-Pad
Product
X-Cs
Debug
X-TH-Server
S-Rt
Powered-By
X-NGINX-Cache
X-Cached-By
X-Refresh
NGX
Vix-Hermes-Req-Id
X-Amz-Meta-Cb-Modifiedtime
HA-Ipaddr
CloudFront-Viewer-Country
X-Upstream-Ct
X-Upstream-Ht
X-Via-Popv
Pics-Label
X-ND-Cache
X-Nananana
X-Via-Popn
X-Via-Poph
X-APP
X-Cache-VC
Mime-Version
X-Ah-Environment
Cookie
X-HA-Backend
GeoIP-Latitude
X-Servedbyhost
X-Varnish-Hits
X-Cdn-Forward
X-User
X-Datadome
Edge-Cache
Server-ID
X-Nginx-Cache
X-LB-ID
GeoIp-Country-Code
X-AIR-PT
X-DynaTrace-JS-Agent
MIME-Version
X-Webkit-CSP
X-Wa
X-Nc
X-Fpc
Akamai-Mon-Iucid-Del
X-LB-NoCache
X-GeoIP
Surrogated-Key
X-Request-Start
HostName
SID
X-Srv
X-FORWARDED-FOR
X-B3-Parentspanid
WZWS-RAY
X-Zone
X-Unity-Cache
Resin-Trace
X-Scheme
DataCenter
X-Debug-Service
X-Nginx-Cache-Key
Fastly-Drupal-Html
X-Client-Ip
Server-Hostname
True-Client-Country-4JS
Server-Ext
Sever-Int
X-CS
Show-Do-Not-Sell-Link
X-NodeID
N1-Cache
X-Pool
Cdn
Tcn
Load-Balancing
X-Request-Host
X-RequestId
X-Lsadc-Cache
X-VCL-Version
X-Cache-Backend
Lb
X-Cache-Grace
Wsr-Cache
Sm-Log-Id
X-Service-Response-Time
X-B3-Spanid
X-Newrelic-Synthetics
X-Vc
NtCoent-Length
Yjs-Id
X-Vgn-Hpd-Reason
X-DataCenter
X-DynaTrace
Yak-Timeinfo
Traceparent
X-Via-SSL
X-Datacenter
X-LiteSpeed-Cache-Control
X-TX-ID
X-Via-CDN
Edge-Copy-Time
X-HOST
X-Via-Edge
X-Air-Hostname
X-Air-Trace-Id
X-NODE
X-Air-Source
Datacenter
X-Geolocation
X-Zen-Fury
X-RateLimit-Limit
Cdn-Requestid
Serverhost
X-Jobs
X-WA
CDN
X-CDN-Provider
X-HubSpot-Correlation-Id
Req-ID
Hostname
X-API-Version
X-LiteSpeed-Tag
X-Dynatrace-Js-Agent
Xkeylog
X-Udemy-Cache-App-Namespace
X-Proxy-Cache-La3
Xkey-La3
XkeyR9
X-FPC
X-Proxy-CacheR9
X-Fastly-Backend-Reqs
X-NC
X-ID
X-Cdn-Srv
Uri
X-Lb-Id
A
Server-Id
X-Akamai-Pragma-Client-IP
X-Powered-By-VTEX-Cache
GeoIP-Country-Code
True-Client-IP
X-Html-Minification-Powered-By
X-VTEX-Cache-Time
X-VTEX-Cache-Server
WP-Super-Cache
CountryCode
X-Srcache-Fetch-Status
Geoip-Latitude
Proxy-Firewall
X-Srcache-Store-Status
X-Ez-Minify-Js
T-Server
X-Stale
RATING
X-TimeS
On-Server
X-Webkit-Csp-Report-Only
X-Via-JSL
X-Varnish-Beresp-TTL
X-WA-Info
X-Swift-Error
X-Lb-Nocache
Coldstone-Viewer-Country-Region-Name
ServerHost
From-Cache
Srv
Coldstone-Viewer-Country
Coldstone-Viewer-Currency
X-ServedByHost
Esi-Enabled
WebServer
X-Oracle-DMS-ECID
Cs
X-Ha-Backend
X-App
X-CSRF-TOKEN
X-VC-Age
X-Ez-Minify-Html
Cloudfront-Viewer-Country
X-Wp-Cf-Super-Cache
X-Wp-Cf-Super-Cache-Cache-Control
X-LAGOON
X-MSEdge-Flight
X-MSEdge-Features
X-Correlation-ID
X-Fastly-Cache
X-Styx-Info
Ngx
X-Via-PopV
X-Via-PopH
X-Ssense-Shipping-Surcharge-Enabled
X-HA-Device-Type
X-HA-Bot-Classification
Pramga
FSS-Cache
X-Styx-Origin-Id
X-Via-PopN
Cr
X-Ssense-Gql
BehaviorPad-Version
X-HA-Application-Name
Content-Secure-Policy
X-Cdn-Cache-Status
X-Geo
X-Sorting-Hat-Podid
X-Sorting-Hat-Shopid
X-Check-Cacheable
X-Web-Server
X-TIM-N
X-Shardid
X-Shopid
X-Var-Ttl
X-Proxy-Cache-LA2
X-Th-Server
X-Elasticpress-Query
My-App
X-Request-Url
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-Wp-Cf-Super-Cache-Active
X-DC
X-ATG-Version
W
Akamai-X-True-TTL
X-Nitro-Cache
X-Request-Time
X-Serial
X-Sucuri-Id
Cf-Ipcountry
User-Agent
Xkey-G-Jp
Cl-Cache
X-Ramcache
True-Client-Ip
X-Fastly-Cache-Hits
X-Cache-TTL-Remaining
Bxuuid
Bxpunish
Cneonction
FSS-Proxy
X-Env
Host-Name
X-Mg-Cache
X-Fastly-Cache-Status