Threat Level: green Handler on Duty: Yee Ching Tok

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
X-Frame-Options
Expires
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Accept-CH
Last-Modified
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
X-XSS-Protection
X-Cache
Via
X-Powered-By
Pragma
CF-RAY
Age
Content-Security-Policy
Report-To
Alt-Svc
NEL
Referrer-Policy
Access-Control-Allow-Origin
X-Amz-Cf-Pop
X-Amz-Cf-Id
Content-Language
P3P
X-Cache-Hits
X-UA-Compatible
X-Served-By
X-Xss-Protection
X-Download-Options
X-Request-Id
CF-Ray
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
X-DNS-Prefetch-Control
Content-Security-Policy-Report-Only
Accept-CH-Lifetime
X-AspNet-Version
X-Runtime
Permissions-Policy
X-Drupal-Cache
Server-Timing
X-FRAME-OPTIONS
X-Envoy-Upstream-Service-Time
X-Generator
X-Ua-Compatible
X-Cache-Status
X-Cacheable
X-CONTENT-TYPE-OPTIONS
Accept-Ch
X-Iinfo
X-Drupal-Dynamic-Cache
Timing-Allow-Origin
X-XSS-PROTECTION
Feature-Policy
X-Content-Security-Policy
Xkey
Upgrade
Access-Control-Expose-Headers
X-CDN
Status
Content-Encoding
X-AspNetMvc-Version
Access-Control-Max-Age
X-Amz-Request-Id
X-Amz-Id-2
Host-Header
X-Age
Request-Context
X-Amz-Version-Id
X-Backend
Cf-Edge-Cache
X-Hacker
X-Robots-Tag
Keep-Alive
CONTENT-SECURITY-POLICY
Cf-Apo-Via
X-Via
X-Turbo-Charged-By
X-Vhost
X-Request-ID
X-AH-Environment
X-Server
X-Dispatcher
X-Rq
X-Proxy-Cache
X-Cache-Group
X-Ws-Request-Id
EagleId
X-Varnish-Cache
X-UA-Device
Grace
Pantheon-Trace-Id
X-Litespeed-Cache
X-WebKit-CSP
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Server-Powered-By
X-OneAgent-JS-Injection
X-Pingback
X-Page-Speed
Allow
X-Dns-Prefetch-Control
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Cache-Lookup
X-Swift-SaveTime
X-Swift-CacheTime
X-Device
X-FTR-Request-ID
X-Node
Ali-Swift-Global-Savetime
X-Host
X-Backend-Server
EagleEye-TraceId
X-Server-Id
X-Country-Code
Surrogate-Control
X-Cloud-Trace-Context
Cf-Railgun
X-Readtime
X-Ruxit-JS-Agent
X-Akam-SW-Version
X-HW
Cache-Tag
Accept-Ch-Lifetime
X-Response-Time
X-Amz-Server-Side-Encryption
X-Ua-Device
X-Content-Type
X-LiteSpeed-Cache
Content-Location
Cross-Origin-Opener-Policy
X-Element-Page-Cache
X-Nginx-Cache-Status
X-D2id
X-Nginx-Upstream-Cache-Status
Request-Id
X-Oneagent-Js-Injection
X-Rack-Cache
X-Application-Context
Service-Worker-Allowed
X-Trace
X-TraceId
Fastly-Restarts
X-Nf-Request-Id
X-Navigation-Version
X-Times
X-PC
X-TtlSet
X-Vname
Rating
X-Clacks-Overhead
X-Cnection
X-Country
X-Midtier
X-Edge
X-Mcache
X-Vcap-Request-Id
Origin-Trial
X-Browser-Type
Edge-Control
X-Country-Code-Real
X-FTR-Backend
X-FTR-Cache-Status
X-FTR-Backend-Server
X-FTR-Balancer
X-FTR-Expires
X-ESI
X-Cache-TTL
X-Url
X-FastCGI-Cache
Surrogate-Key
X-NWS-LOG-UUID
X-Kinja-Server
X-Kinja-Revision
X-Kinja-Build
X-Exp-Id
X-Kinja
X-Cdn-Fetch
X-Exp-Variant
X-GoogleNews-Bot
X-ECACHE
X-Request-Device-Id
X-Powered-By-Plesk
X-Ac
X-Abt-Application-Version
X-Amz-Rid
X-Mod-Pagespeed
X-Upstream
Verso
X-ORACLE-DMS-RID
X-B3-TraceId
X-Meli-Trace-Site
X-Meli-Trace-Bu
X-Meli-Trace-Platform
X-MS-InvokeApp
X-Language
X-Pinterest-Rid
Pinterest-Version
Pinterest-Generated-By
Akamai-GRN
Nginx-Cache
X-Amzn-Trace-Id
X-T
Display
X-GitHub-Request-Id
Pagespeed
X-Middleton-Display
X-Sol
S
X-Instrumentation
X-PDP-UNCACHING-HASH
X-Kraken-Loop-Name
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Server-Lifecycle-Phase
X-Ruxit-Js-Agent
X-Envoy-Decorator-Operation
SPRequestDuration
SPRequestGuid
SPIisLatency
X-SharePointHealthScore
AR-Request-ID
X-Middleton-Response
Response
AR-PoweredBy
AR-ATIME
Edge-Cache-Tag
X-Distributor
X-Goog-Hash
X-Ratelimit-Limit
X-Resp-Is-Stale
X-Ser
X-Request-Processing-Time
X-Request-Received
X-Kinsta-Cache
X-Edge-Location-Klb
X-ARC
X-NGENIX-Cache
Access-Control-Request-Method
Front-End-Https
X-Shield-Request-Id
X-Dw-Request-Base-Id
Ar-SID
RTSS
X-Ezoic-Cdn
X-Recruiting
X-Cache-Key
X-Client-IP
X-Content-Digest
Cache-Status
X-Amz-Replication-Status
X-Varnish-TTL
X-Version
X-Mg-S
YJS-ID
X-Fastly-Request-ID
X-Newrelic-App-Data
X-Ismobilevalue
Public-Key-Pins
X-Powered-CMS
X-Correlation-Id
TP-Cache
X-Accel-Expires
X-HS-Hub-Id
X-HS-Cache-Config
X-HS-Content-Id
AR-CACHE
Fastcgi-Cache
X-MSEdge-Ref
Cache-Tags
X-Cached
X-Ttl
X-Server-Name
X-Cluster-Name
Arr-Disable-Session-Affinity
X-Content-Security-Policy-Report-Only
Realpath
X-Daa-Tunnel
X-Id
Content-MD5
X-HS-Combine-CSS
X-Azure-Ref
X-TTL
X-RateLimit-Remaining
X-HP-Webp
X-Cambria-Cache-Control
X-Jurisdiction
X-Ua-Browser
X-HP-Trace-Id
Payment
X-DIS-Request-ID
MicrosoftSharePointTeamServices
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Amzn-RequestId
X-Amz-Apigw-Id
X-HS-Prerendered
X-HS-CF-Cache-Status
X-Xrds-Location
X-GUploader-UploadID
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Forwarded-For
Content-Disposition
X-Px
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-Protected-By
X-TEC-API-ROOT
Count-Hit
X-Ratelimit-Remaining
X-Ratelimit-Reset
X-Activity-Id
X-Unique-Id
X-Az
X-AppVersion
X-Page-Id
X-Rid
Cross-Origin-Resource-Policy
X-Logged-In
Cleartype
X-Origin-Server
Accept-Charset
Cross-Origin-Embedder-Policy
X-Git-Hash
X-Proxy
X-Amz-Meta-S3cmd-Attrs
X-FB-Debug
X-Microsite
X-Request-Handler-Origin-Region
X-VARITI-CCR
X-Www-Served-By
Version
X-Geo-Country
X-COUNTRY
X-Load-Cache
X-Hits
X-LLID
X-Goog-Metageneration
X-ORACLE-DMS-ECID
X-Forwarded-Proto
X-Template
X-Varnish-Backend
X-Requestid
X-WebKit-CSP-Report-Only
X-Upgrade-Enabled
X-B3-Sampled
Server-Node
X-ProcessESI
X-RemovedCookies
X-App-Server
X-PressLabs-Stats
X-Hostname
Server-Name
Healthy
X-Content-Options
Access-Control-Allow-Method
X-TT
X-Frontend
Viewport
X-Device-Type
X-B
X-Request-Guid
Section-Io-Cache
X-Varnish-Grace
X-Grace
Fastly-SWR
Fastly-SIE
X-Fb-Rlafr
X-Varnish-Server
Alternate-Protocol
X-Hl-Ver
X-Contextid
AKAMAI-GRN
Mrf-Cache-Status
X-B3-TraceId-Primal
MRF-Tech
X-Status
X-CSRF-Token
X-Cache-Age
DC
X-Goog-Generation
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Amzn-Remapped-Content-Length
X-Yandex-Req-Id
X-Magnolia-Registration
Xet-Cookie
X-Varnish-Ttl
Upgrade-Insecure-Requests
MS-Author-Via
Frame-Options
X-App-Version
X-Oracle-Dms-Ecid
X-EdgeConnect-Cache-Status
X-Cache-Control
TCN
Host
Retry-After
X-CST
X-Origin-CC
X-Origin-TTL
X-Type
X-SERVER-NAME
X-Original-Request-Id
X-Response-Served-From
X-Revision
SD-X-WS
X-AB
X-Debug
Amp-Access-Control-Allow-Source-Origin
X-ServerID
X-G
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-Mobile
NGB
X-Cacheable-TTL
X-Instance
X-N
X-Seen-By
X-INCAP-ABP
X-UUID
X-Akamai-Edgescape
X-Adobe-Content
X-Adobe-Loc
X-Backend-Name
X-Buckets
X-Rendered-As
X-Debug-IsConnected
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-NYM-Debug-Backend
Cross-Origin-Opener-Policy-Report-Only
X-Lambda-Id
X-Is-Bot
Cache
Access-Control-Request-Headers
X-Tumblr-User
X-Debug-IsPreview
X-Akamai-Request-ID2
X-Tumblr-Pixel-1
X-Cache-Status-Check
Cross-Origin-Embedder-Policy-Report-Only
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Framework
MS-CV
Ms-Operation-Id
X-WP-CF-Super-Cache
X-Content-Powered-By
Section-Io-Id
X-WP-CF-Super-Cache-Cache-Control
X-Mg-Request-UUID
X-RTag
X-B3-SpanId
Selected-Fe
X-Server-W
X-Timing-Wait
X-Proxy-Build
X-Tt-Trace-Host
X-Trace-Id
X-Tt-Trace-Tag
X-RM-Cache-TTL
X-Storage
X-ProxyCache-Status
X-ProxyCache-Key
Charset
YJS-CacheStatus
X-BYPASS-REASON
X-Dc
Paypal-Debug-Id
Webserver
X-VC-Cache
Accept-Language
Front
X-Ms-Version
X-Ms-Request-Id
Filterid
Onion-Location
X-Vcl-Version
SRV
X-Cache-Time
X-User-Agent
X-DataDome
X-F-Cache
Refresh
X-Server-ID
Apigw-Requestid
X-Cache-Hit
X-Time
X-VC
X-Origin-Cache
Priority
X-Real-IP
X-Mly-Id
X-Region
Liferay-Portal
X-Node-Name
X-Fastcgi-Cache
GEO-INFO
X-Environment-Context
X-CLOUD-TRACE-CONTEXT
X-Webkit-Csp
X-L-Path
X-Service
X-CCDN-CacheTTL
X-CCDN-Origin-Time
X-Mode
X-Hcs-Proxy-Type
X-HTML-Minification-Powered-By
X-Tec-Api-Version
X-LB-Cache
X-Api-Version
X-Tec-Api-Root
X-Rule
X-Origin
X-Optimistic-Header
X-Request-Site
X-Tec-Api-Origin
X-Request-Platform
X-Request-Bu
X-Tb
X-Rewrite-Enabled
X-Rn-Rsrv
X-Drupal-Cache-Tags
Meta-Geo
X-Rocket-Nginx-Serving-Static
X-UPSTREAM-Address
X-VCT
X-SaId
X-HITS
CDN-RequestId
Country
X-JoinUs
X-Tt-Logid
X-Tcp-Rtt
X-IPS-LoggedIn
X-Is-Desktop
X-Is-Supported-Browser
X-Wix-Request-Id
X-Is-Mobile-Only
X-Handled-By
X-Geo-Region
X-Is-Modern-Browser
X-Is-Tablet
X-Is-Mobile
Backend
X-Adobe-Source
X-Browser-Name
Mn-Server-Ip
Expiry
X-Cache-Expired-At
X-Datadog-Parent-Id
X-Web-Node
X-Pass-Why
X-Connection-Hash
X-Datadog-Sampling-Priority
X-Datadog-Sampled
Countrycode
X-Generation-Time
X-XRDS-Location
X-Platform
X-Provided-By
X-Datadog-Trace-Id
TWC-Locale-Group
Web-Mar-Node
TWC-GeoIP-DMA
Url
TWC-Connection-Speed
X-Cache-Action
TWC-Privacy
TWC-Device-Class
TWC-GeoIP-LatLong
TWC-GeoIP-Country
Property-Id
Uber-Trace-Id
Fastcgi-Useragent
Webcakes-App-Version
Webcakes-App-Name
X-Cloudmap
X-WP-CF-Super-Cache-Active
Webcakes-Region
X-Alternate-Cache-Key
OT-Force-Account-Verify
X-Cms-Context
TWC-GeoIP-Region
X-Cdn-Origin
X-Shopify-Stage
X-Storefront-Renderer-Rendered
X-Origin-Date
X-Loop
X-Routing-Service
X-S
X-Tncms
X-Origin-Hint
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Proxy-Cache-Info
X-Proxied
X-Detected-As
X-Whom
X-Servername
ServerID
TWC-GeoIP-City
X-FB-TRIP-ID
X-Extlb
Node
X-Zipkin-Id
X-Forwarded-Host
Cross-Origin-Window-Policy
X-Varnish-Beresp-Grace
X-Httpd
X-Vcache
X-Hit
X-RCS-CacheZone
X-Tumblr-Pixel-3
X-Cluster
X-Urbn-Site-Id
X-Urbn-Context-Path
X-Soup
X-Tumblr-Pixel-2
X-App-Environment
X-Hosted-By
X-Cache-Host
X-Format
X-Fetched-On
X-Director
X-Cache-Debug
X-Locale
X-Redis-Cache
X-Auth-Group-Type
X-MP-GENERATED-AT
X-Logging-Id
X-Skip-Cache
Environment
DB-Nickname
Cache-Hits
Atl-Traceid
Locale
X-CDN-Forward
ServedBy
X-FW-Dynamic
X-FW-Hash
X-FW-Serve
X-Scope-Id
X-Endurance-Cache-Level
X-SayCDN-TTL
X-Say-TTL
X-Debug-Info
X-Edge-Location
X-Cluster-Node
X-Say-Cacheable
X-FW-Server
X-Restarts
Protected
X-Labrador-Cache-Channel
X-PHP-Host
X-FW-Static
AMP-Access-Control-Allow-Source-Origin
X-FW-Type
X-FW-Version
X-Served-From
X-Client-Ip
X-Drupal-Cache-Contexts
X-IPLB-Request-ID
X-IPLB-Instance
Filters
Xserver
WPO-Cache-Status
X-Presslabs-Stats
X-Ua
Request-ID
X-NWS-UUID-VERIFY
X-R9-Blue-Green-Version
LB
X-Varnish-Beresp-Ttl
X-GEO
X-CDN-Cache-Status
X-WP-CF-Super-Cache-Cookies-Bypass
X-No-Session
X-Sorting-Hat-ShopId
X-Clientip
X-ShardId
X-Varnish-Age
CloudFront-Viewer-Country
X-SRCache-Key
Expect-Staple
X-ShopId
X-Sorting-Hat-PodId
X-Upstream-Ht
X-Upstream-Ct
X-Generated-By
X-Signature
X-B-Cache
X-Cache-FS-Status
Mail-Subject
X-Varnish-Cache-Hits
We-Hiring
Cache-Tv-Group
X-Lagoon
X-B3-Traceid
X-Cs
X-Azure-Ref-OriginShield
Referer-Policy
X-FORWARDED-FOR
X-PHP-Backend
X-TA-CDN-Provider
X-Cache-Operation
X-IsAdmin
X-Cache-Rule
X-LSADC-Cache
X-Webstats-RespID
Location
X-Worker
X-SRV
X-Auto-Login
X-Bc-Bl
X-ECache
From-Origin
X-Server-IP
Fl-Custom-Application
X-Site-Version
Cache-Provider
X-UA
Load-Balancing
Candidate-Md5Url
X-Tb-Optimization-Total-Bytes-Saved
DCR-Processing-Time-Ms
Host-ID
S-Rt
Lang
DCR-Decision-By
Origin-Agent-Cluster
MD5-Digest
Source
X-A-Wwc
X-GeoCode
X-GeoCountry
X-Ig-Origin-Region
X-Ig-Push-State
X-External-Request-Id
X-Ec-GeoHdr
X-Destination
X-Developer
X-Ec-Fail
X-Loc
X-ND-Cache
X-Vdms-Version
X-Vtex-Remote-Cache
Xc-Version
X-ScT
X-S-Cookie
X-Org
X-PERF
X-Rojux
X-D
X-Content-Age
Rendered-Blocks
Sslversion
X-A
X-A-Ccd
Redirect-Candidate
Pragrma
N-Cache
Ngx.Var.Host
Origin
X-A-Dcw
X-A-Dgt
X-Bl-Debug
X-Cache-NE
X-Conf
X-BCube-Filmed-By
X-B-Cookie
X-Aed
X-ApacheServer
X-Application
Meta-Geo-Continent
X-A-Dam
WPO-Cache-Message
Mime-Version
X-VWS-Id
X-AWS-Id
X-LJ-Flow-ID
X-Accel-Version
X-CACHE-AGE
X-Xfnlog-Site
Store-Cloud-Cache
X-Req
Time-Cloud-Cache
X-Rocket-Build-Number
ServerName
RNT-Time
Server-Host
Vix-Hermes-Req-Id
RNT-Machine
Web-Mar-Region
X-Access
X-Action
X-Aicache-OS
X-PAYTM-SRV-ID
X-Policy
Wxu-Next-Commit
Wxu-Next-Hostname
Wxu-Next-Region
X-Save-Cache
X-Section
L5d-Success-Class
Log-Origin
X-Sn-Servicetimems
IsBot
Ha-Gx-Prefs
Fastly-SSL
Gannett-Cam-Experience-Id
Gh-Request-Id
X-Slack-Shared-Secret-Outcome
X-Slack-Backend
Origin-Site
Powered-By
X-GoCache-CacheStatus
X-Sigma
Odigeo-Trace-Id
X-SIPLIST1
X-Sigma-Backend
NM-Fastcgi-Cache
X-AK-Request-ID
X-Origin-Expires
X-Epic-Correlation-Id
X-Eu-Site
X-Fastly-Backend
X-Ee-Request-Id
X-Ee-Request-Date
X-Internal-TTL
X-Ee-Generated-By
X-Ee-Origin
X-FC-Vary-Parameters
X-Fmm-Version
X-GeoIP-City
X-GeoIP-Country-Code
X-GeoIP-Region-Code
X-Hash
X-Gamma-Serve
X-Forwarded-Site
X-HS-Content-Campaign-Id
X-From
X-Dispatcher-Server
X-Depends
X-Mvc-Supplant-Cachable
X-CacheTTL
X-CGP
X-Cache-Aspx
X-Bug-Bounty
X-Old-Content-Length
X-Node-Id
X-NMSegId
X-Cms-Device
X-Micro-Cache
X-CUA
X-DefElseHash
X-DefHash
X-Csrf-Jwt
X-Core-Value
X-Contensis-Viewer-Groups
X-Men
X-Up
X-SD-PageType
CDN-CachedAt
CDN-EdgeStorageId
CDN-Cache
X-Varnish-CookieINHashed-On
Canary
CDN-PullZone
CDN-RequestCountryCode
Cdncip
CDN-Uid
CDN-RequestPullSuccess
CDN-RequestPullCode
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
X-VG-WebCache
X-Via-Fastly
X-URL
Sid
X-VG-TLSProxy
X-Vary-Devices
Apple-News-Services-Handled
X-Varnish-Director
X-Varnish-Hostname
X-Varnish-Remaining-TTL
Cdnsip
Apple-News-Services-Request-Url
Cluster
Country-Code
X-V-Cache
X-Varnish-Authentication
X-Varnish-CookieHashed-On
X-Varnish-Beresp-Status
X-NewRelic-App-Data
X-Parent-Response-Time
X-Cached-By
X-VC-TTL
X-NF-Request-ID
X-Cache-Date
X-Vercel-Id
X-Cache-Id
DSUID
X-Viewer-Country
X-Vmg-Version
X-Content-Length
X-Vercel-Cache
X-Level-Front-Cache
X-Thinkindot-L3
X-Mvc-Supplant-OutputCached
X-Thanos
CF-IPCountry
X-App-Name
X-Op-Id-All
X-Amz-Storage-Class
X-Thinkindot-L1
X-B3-Trace-ID
X-Bip
X-Date
X-VarnishDD-TTL
X-BBC-Edge-Cache-Status
X-Backend-Instance
X-Block-Status
X-Wikidot-Backend
X-Tx-Id
X-Frame-Option
X-Reqid
X-Render-Time
X-UA-Device-Type
X-Human
X-SB
X-Gdpr
X-HN
X-Gzip
X-Hnp-Log
X-Generated-On
X-Gen-Mode
X-Esi-Check
Cmstype
Fastly-Backend-Name
X-Jungle-Id
X-Akamai-Device-Characteristics
X-We-Are-Hiring
X-Debug-Cache-Store
X-Ion-Hop
X-Wikidot-Static-Cache
X-Edge-Server
Cmsid
X-Ec-Custom-Error
X-Ion-Healthy
X-DPWN-IS-SECURE
X-Debug-Cache-Fetch
X-Nyt-Route
X-Sucuri-Cache
L
Cdn-Host
RewriteTestHook
Content-Style-Type
RewriteTeamHook
CDCHOST
X-Request-URI
Tube-Get-Contents
Tube-Got-Eval
CacheControlHeader
Thinkindot-CacheControl-Type
TDXMobile
X-SVT-ORM-VERSION
Req-Svc-Chain
Cdn-Request-Time
Origin-CC
Origin-EX
Click-Count-Error
Cookie
Click-Count-Action-Start
Nord-Request-ID
PFcat
Pics-Label
Machine
Release
Producers
X-Shield-Cache-Expires
Platform
Content-Script-Type
Tube-Got-Results
Thinkindot-CacheControl
X-Pubstack
X-SVT-ORM-RULES
X-Proto
Azure-RegionName
X-Litespeed-Cache-Control
Tube-Return
X-Acquia-Purge-Cdn-Unconfigured
Azure-Version
Azure-SiteName
Azure-InstanceId
X-Region-Sid
User-Cache-Control
X-Accel-Expires-Debug
X-Uri
X-AB-Test
V-Age
X-Origin-Time
X-Path
Cache-Contol
Azure-SlotName
X-ZONE
X-Moov-Xdn-Version
Fastly-GeoIP-CountryCode
X-Via-Popn
X-Moov-Xdn-Caching-Status
X-Via-Poph
C-Via
X-Origin-Response-Time
X-Debug-Service
X-ElasticPress-Query
X-Nginx-Cache-Key
X-Via-Popv
X-Proxied-Request
X-Location
X-Datadome
X-Moov-T
Fastly-Drupal-HTML
X-Pad
True-Client-Country-4JS
X-NGINX-Cache
X-HA-Backend
X-Sucuri-ID
Server-Hostname
XM
Server-Ext
Sever-Int
X-Srv
X-AIR-PT
X-Webkit-CSP
X-Varnish-Hits
Show-Do-Not-Sell-Link
NGX
Traceparent
X-Cache-Backend
X-Refresh
X-Ez-Minify-Html
Debug
Server-ID
X-Unity-Cache
X-Air-Pt
X-APP
X-Fastly-Request-Id
X-Fpc
X-Nananana
HostName
X-Servedbyhost
GeoIp-Country-Code
GeoIP-Latitude
X-LB-ID
X-TH-Server
X-DynaTrace-JS-Agent
DataCenter
HA-Ipaddr
Product
WZWS-RAY
Cdn
Tcn
X-Zone
X-VCL-Version
AR-SID
X-AC
X-Amz-Meta-Cb-Modifiedtime
X-B3-Parentspanid
X-Nc
X-Wa
Lb
X-CDN-Provider
Fastly-Drupal-Html
SID
X-Nginx-Cache
Xkeylog
X-Newrelic-Synthetics
X-Proxy-Cache-La3
Xkey-La3
XkeyR9
X-Proxy-CacheR9
X-GeoIP
A
X-Vc
Serverhost
X-Cache-VC
X-Cdn-Forward
X-User
X-TX-ID
X-Litespeed-Tag
X-Datacenter
Edge-Cache
CountryCode
Cs
X-RateLimit-Limit
Resin-Trace
NtCoent-Length
X-Source
Cdn-Requestid
X-LB-NoCache
X-LiteSpeed-Tag
Esi-Enabled
X-Request-Start
X-LiteSpeed-Cache-Control
X-TT-LOGID
X-API-Version
X-Wormhole-Sdk
X-Dynatrace-Js-Agent
X-VC-Age
Akamai-Mon-Iucid-Del
Sm-Log-Id
MIME-Version
X-NC
X-HubSpot-Correlation-Id
X-B3-Spanid
X-WA
X-ID
X-Aspnet-Version
X-Service-Response-Time
CDN
Datacenter
Wsr-Cache
X-Html-Minification-Powered-By
Proxy-Firewall
X-Udemy-Cache-App-Namespace
Cr
Content-Secure-Policy
X-TIM-N
X-Scheme
Pramga
X-Styx-Info
X-Styx-Origin-Id
X-HA-Device-Type
X-HA-Bot-Classification
X-HA-Application-Name
X-Ez-Minify-Js
X-Var-Ttl
X-Lsadc-Cache
X-Srcache-Fetch-Status
X-Via-JSL
X-Srcache-Store-Status
X-Fastly-Backend-Reqs
Hostname
Yjs-Id
Uri
Geoip-Latitude
X-Lb-Id
X-TimeS
GeoIP-Country-Code
ServerHost
RATING
X-FPC
X-ServedByHost
X-NodeID
Server-Id
From-Cache
X-Request-Host
X-Pool
W
X-NODE
X-Stale
X-Wp-Cf-Super-Cache-Cache-Control
X-Wp-Cf-Super-Cache
X-Aspnetmvc-Version
X-Oracle-DMS-ECID
X-Swift-Error
Cloudfront-Viewer-Country
X-CACHE-KEY
X-MSEdge-Flight
X-Akamai-Pragma-Client-IP
X-Lb-Nocache
X-App
X-MSEdge-Features
X-Air-Hostname
X-Air-Source
X-Sorting-Hat-Shopid
X-Wp-Cf-Super-Cache-Active
X-Air-Trace-Id
X-LAGOON
X-RequestId
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-Shardid
X-Shopid
X-Sorting-Hat-Podid
X-ByteArk-ReqID
X-ByteArk-Cache
X-Vgn-Hpd-Reason
X-Ramcache
X-Proxy-Cache-LA2
X-DynaTrace
X-Cache-Grace
X-Correlation-ID
Surrogated-Key
X-VServer
X-Ssense-Gql
X-Key
Ohc-File-Size
T-Server
Ohc-Cache-HIT
Srv
X-Ssense-Shipping-Surcharge-Enabled
X-CS
X-Varnish-Beresp-TTL
X-Elasticpress-Query
CF-Cached-On
X-DataCenter
Yak-Timeinfo
X-Webkit-Csp-Report-Only
X-Cdn-Cache-Status
X-Geo
Cl-Cache
Ngx
X-CSRF-TOKEN
Edge-Copy-Time
Req-ID
X-Sucuri-Id
X-PageType
X-Web-Server
X-Via-SSL
X-Via-Edge
X-DC
X-Jobs
X-ATG-Version
WebServer
X-Via-CDN
X-Ha-Backend
X-Th-Server
Akamai-X-True-TTL
X-Iplb-Instance
X-Iplb-Request-Id
N1-Cache
X-Via-PopV
X-Via-PopN
X-Via-PopH
Warning
X-Beacon
X-Limited
My-App
X-MiniProfiler-Ids
X-Check-Cacheable
X-Env
Host-Name
X-Mg-Cache
X-Zen-Fury
X-Geolocation
User-Agent
X-Request-Url
X-Fastly-Cache-Status
Xkey-G-Jp