Threat Level: green Handler on Duty: Guy Bruneau

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
X-Frame-Options
Expires
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Accept-CH
CF-Cache-Status
ETag
X-XSS-Protection
Expect-CT
Accept-Ranges
X-Powered-By
Pragma
CF-RAY
X-Cache
Via
Age
Content-Security-Policy
Alt-Svc
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
X-Amz-Cf-Pop
X-Amz-Cf-Id
Content-Language
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-Download-Options
X-Request-Id
X-Timer
X-Xss-Protection
Access-Control-Allow-Headers
Access-Control-Allow-Methods
CF-Ray
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
X-DNS-Prefetch-Control
Content-Security-Policy-Report-Only
Accept-CH-Lifetime
X-AspNet-Version
X-Runtime
Accept-Ch
Permissions-Policy
Server-Timing
X-Drupal-Cache
X-Generator
X-Envoy-Upstream-Service-Time
X-Cache-Status
X-Cacheable
X-FRAME-OPTIONS
X-Iinfo
X-Drupal-Dynamic-Cache
X-Ua-Compatible
Timing-Allow-Origin
X-CONTENT-TYPE-OPTIONS
Feature-Policy
X-Content-Security-Policy
Xkey
Upgrade
Access-Control-Expose-Headers
X-CDN
X-XSS-PROTECTION
Content-Encoding
Status
X-AspNetMvc-Version
Access-Control-Max-Age
X-Amz-Request-Id
Host-Header
X-Amz-Id-2
X-Age
Request-Context
Cf-Edge-Cache
X-Backend
X-Request-ID
X-Robots-Tag
X-Hacker
Keep-Alive
X-Amz-Version-Id
X-Via
Cf-Apo-Via
X-Turbo-Charged-By
X-AH-Environment
X-Rq
X-Vhost
X-Cache-Group
X-Server
X-Dispatcher
X-Proxy-Cache
X-Ws-Request-Id
EagleId
CONTENT-SECURITY-POLICY
X-UA-Device
X-Varnish-Cache
Pantheon-Trace-Id
Grace
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Litespeed-Cache
X-OneAgent-JS-Injection
X-Server-Powered-By
X-Pingback
Allow
X-Page-Speed
X-WebKit-CSP
X-Dns-Prefetch-Control
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-FTR-Request-ID
X-Device
X-Node
X-Cache-Lookup
X-Server-Id
EagleEye-TraceId
X-Host
X-Backend-Server
X-Country-Code
Surrogate-Control
X-Cloud-Trace-Context
X-Readtime
Accept-Ch-Lifetime
X-Akam-SW-Version
Cf-Railgun
X-Ruxit-JS-Agent
X-HW
X-Response-Time
Cache-Tag
P3p
X-Amz-Server-Side-Encryption
Cf-Request-Id
X-LiteSpeed-Cache
X-Ua-Device
Content-Location
Cross-Origin-Opener-Policy
X-Content-Type
X-Rack-Cache
X-Nginx-Upstream-Cache-Status
X-Nginx-Cache-Status
X-Trace
Service-Worker-Allowed
Request-Id
X-TraceId
Fastly-Restarts
X-Application-Context
X-Times
X-PC
X-Vname
X-TtlSet
X-Nf-Request-Id
Rating
X-Clacks-Overhead
X-Cnection
X-Element-Page-Cache
X-D2id
X-Mcache
X-Midtier
X-Edge
X-Vcap-Request-Id
X-FTR-Balancer
X-FTR-Cache-Status
X-FTR-Backend-Server
X-Country-Code-Real
X-Browser-Type
X-FTR-Backend
X-FTR-Expires
X-ESI
Origin-Trial
Edge-Control
X-Cache-TTL
X-FastCGI-Cache
Surrogate-Key
X-Oneagent-Js-Injection
X-Powered-By-Plesk
X-NWS-LOG-UUID
X-Cdn-Fetch
X-Exp-Variant
X-Exp-Id
X-GoogleNews-Bot
X-Navigation-Version
X-Kinja
X-Kinja-Build
X-Kinja-Revision
X-Kinja-Server
X-Country
X-Abt-Application-Version
X-Ac
X-Upstream
X-Mod-Pagespeed
Verso
X-ORACLE-DMS-RID
X-Amz-Rid
X-B3-TraceId
X-Url
Akamai-GRN
Nginx-Cache
X-Language
Pinterest-Version
X-Pinterest-Rid
Pinterest-Generated-By
X-GitHub-Request-Id
X-ECACHE
Pagespeed
X-Middleton-Display
Display
X-Sol
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-Instrumentation
X-PDP-UNCACHING-HASH
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
S
X-Envoy-Decorator-Operation
X-MS-InvokeApp
X-Middleton-Response
Response
AR-Request-ID
AR-ATIME
AR-PoweredBy
Edge-Cache-Tag
X-Ratelimit-Limit
X-Goog-Hash
X-Distributor
X-Ser
SPRequestGuid
SPIisLatency
X-SharePointHealthScore
SPRequestDuration
X-Resp-Is-Stale
X-Edge-Location-Klb
X-Amzn-Trace-Id
X-Kinsta-Cache
X-ARC
X-Ttl
X-Ruxit-Js-Agent
Access-Control-Request-Method
X-NGENIX-Cache
X-Client-IP
X-Dw-Request-Base-Id
X-T
X-Shield-Request-Id
Front-End-Https
X-Content-Digest
X-Ezoic-Cdn
X-Recruiting
RTSS
X-Cache-Key
X-Varnish-TTL
Cache-Status
X-Version
X-Mg-S
X-Request-Device-Id
X-Powered-CMS
TP-Cache
Public-Key-Pins
X-HS-Hub-Id
X-HS-Content-Id
X-MSEdge-Ref
X-HS-Cache-Config
Fastcgi-Cache
X-Ismobilevalue
X-Accel-Expires
X-Request-Received
X-Request-Processing-Time
Arr-Disable-Session-Affinity
X-Daa-Tunnel
Cache-Tags
AR-CACHE
X-Cached
X-Cluster-Name
X-Correlation-Id
Realpath
X-Id
X-Meli-Trace-Bu
X-Meli-Trace-Platform
Content-MD5
X-Meli-Trace-Site
X-Content-Security-Policy-Report-Only
X-Forwarded-For
X-HS-Combine-CSS
Ar-SID
X-Amz-Replication-Status
YJS-ID
X-Fastly-Request-ID
Payment
X-Ua-Browser
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-DIS-Request-ID
X-Newrelic-App-Data
X-HP-Trace-Id
X-HP-Webp
X-Cambria-Cache-Control
X-Jurisdiction
X-Azure-Ref
X-COUNTRY
X-Xrds-Location
X-GUploader-UploadID
X-RateLimit-Remaining
X-HS-CF-Cache-Status
X-HS-Prerendered
X-Webkit-Csp
Content-Disposition
X-Ratelimit-Remaining
X-Server-Name
Count-Hit
X-SRCache-Fetch-Status
X-Protected-By
X-SRCache-Store-Status
MicrosoftSharePointTeamServices
X-Ratelimit-Reset
X-Unique-Id
X-Px
X-Origin-Server
X-Activity-Id
X-AppVersion
X-Az
X-ORACLE-DMS-ECID
X-Page-Id
X-Logged-In
X-Rid
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Amz-Meta-S3cmd-Attrs
Cross-Origin-Resource-Policy
X-SERVER-NAME
X-Git-Hash
Cleartype
Accept-Charset
X-VARITI-CCR
X-Request-Handler-Origin-Region
X-Proxy
Cross-Origin-Embedder-Policy
X-Microsite
X-FB-Debug
X-Www-Served-By
X-TTL
X-Load-Cache
Version
X-TEC-API-VERSION
X-LLID
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Goog-Metageneration
X-Forwarded-Proto
X-Geo-Country
X-Template
X-Varnish-Backend
X-CST
X-Upgrade-Enabled
X-PressLabs-Stats
Server-Node
X-Hits
Server-Name
X-B3-Sampled
X-App-Server
X-Hostname
X-WebKit-CSP-Report-Only
X-Content-Options
Healthy
X-Frontend
Access-Control-Allow-Method
X-Varnish-Grace
Section-Io-Cache
Viewport
X-Grace
X-Fb-Rlafr
X-Device-Type
X-TT
Fastly-SIE
Fastly-SWR
Alternate-Protocol
X-B
X-Varnish-Server
Mrf-Cache-Status
X-B3-TraceId-Primal
MRF-Tech
X-Status
X-Request-Guid
TCN
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Contextid
DC
Upgrade-Insecure-Requests
Retry-After
AKAMAI-GRN
X-Magnolia-Registration
Host
X-Amzn-Remapped-Content-Length
X-EdgeConnect-Cache-Status
X-Requestid
X-RemovedCookies
X-ProcessESI
X-Cache-Age
MS-Author-Via
X-Cache-Control
X-App-Version
X-Hl-Ver
Amp-Access-Control-Allow-Source-Origin
X-CSRF-Token
Frame-Options
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Buckets
X-Debug
X-Origin-CC
X-Varnish-Ttl
X-Origin-TTL
X-Response-Served-From
X-Type
X-Original-Request-Id
X-Revision
SD-X-WS
X-Oracle-Dms-Ecid
X-Mobile
VIX-Pulpo-Node
X-G
VIX-Pulpo-Upstream-Status
X-Seen-By
X-ServerID
X-Backend-Name
X-INCAP-ABP
X-UUID
X-Instance
X-Cache-Status-Check
X-NYM-Debug-Backend
X-Is-Bot
X-N
Cross-Origin-Embedder-Policy-Report-Only
X-Tumblr-Pixel
X-Tumblr-User
X-Yottaa-Metrics
X-Yottaa-Optimizations
Cross-Origin-Opener-Policy-Report-Only
X-Rendered-As
X-Tumblr-Pixel-1
X-Akamai-Edgescape
X-Tumblr-Pixel-0
X-Adobe-Loc
X-Adobe-Content
X-Lambda-Id
X-Trace-Id
X-RTag
X-Framework
NGB
X-WP-CF-Super-Cache-Cache-Control
Ms-Operation-Id
MS-CV
Access-Control-Request-Headers
X-WP-CF-Super-Cache
Section-Io-Id
X-Debug-IsPreview
X-Debug-IsConnected
X-Content-Powered-By
X-Akamai-Request-ID2
X-Mg-Request-UUID
X-AB
X-RM-Cache-TTL
X-Storage
X-Server-W
Charset
X-Vcl-Version
Cache
X-Dc
X-ECache
Webserver
Filterid
X-DataDome
X-Yandex-Req-Id
Paypal-Debug-Id
X-Request-Bu
X-Request-Platform
X-B3-SpanId
Accept-Language
X-Request-Site
Refresh
X-Cache-Time
X-VC-Cache
X-Cache-Hit
X-URL
X-Tec-Api-Version
X-HITS
X-Tec-Api-Root
X-Tec-Api-Origin
SRV
Xet-Cookie
Onion-Location
X-Ms-Request-Id
X-Ms-Version
X-Time
X-Node-Name
X-Real-IP
X-User-Agent
X-Region
X-F-Cache
YJS-CacheStatus
X-CCDN-CacheTTL
X-Hcs-Proxy-Type
X-CCDN-Origin-Time
X-Proxy-Build
X-Timing-Wait
Selected-Fe
X-BYPASS-REASON
Liferay-Portal
X-ProxyCache-Status
X-ProxyCache-Key
CDN-RequestId
Priority
X-HTML-Minification-Powered-By
X-Fastcgi-Cache
GEO-INFO
X-LB-Cache
X-Environment-Context
X-Mode
X-Cacheable-TTL
X-L-Path
X-IPS-LoggedIn
X-Pass-Why
Cross-Origin-Window-Policy
X-VC
X-Service
X-Datadog-Sampled
X-Datadog-Sampling-Priority
X-Rocket-Nginx-Serving-Static
X-Datadog-Trace-Id
X-Rule
X-Datadog-Parent-Id
X-Rewrite-Enabled
Apigw-Requestid
X-Rn-Rsrv
X-Drupal-Cache-Tags
X-Cache-Expired-At
Country
X-JoinUs
X-Tb
Meta-Geo
X-SaId
X-Origin
Protected
Backend
X-UPSTREAM-Address
X-Is-Mobile-Only
X-Is-Mobile
X-Whom
X-Is-Tablet
X-Origin-Cache
X-Wix-Request-Id
X-Is-Supported-Browser
X-Is-Modern-Browser
X-Is-Desktop
X-Browser-Name
X-Handled-By
X-VCT
X-Geo-Region
X-Tcp-Rtt
X-Adobe-Source
X-Generation-Time
X-Web-Node
X-Provided-By
Mn-Server-Ip
X-Loop
X-Origin-Hint
TWC-GeoIP-Country
X-Tncms
TWC-GeoIP-DMA
ServerID
TWC-Connection-Speed
X-Detected-As
X-Api-Version
X-Connection-Hash
Property-Id
Fastcgi-Useragent
Expiry
X-Proxied
X-Extlb
X-Proxy-Cache-Info
TWC-GeoIP-City
TWC-Device-Class
X-Cloudmap
X-FB-TRIP-ID
X-Origin-Date
X-WP-CF-Super-Cache-Active
TWC-GeoIP-LatLong
Web-Mar-Node
X-Varnish-Beresp-Grace
TWC-Locale-Group
TWC-GeoIP-Region
X-Servername
TWC-Privacy
X-Routing-Service
Url
Uber-Trace-Id
X-RateLimit-Remaining-Second
X-RCS-CacheZone
X-Httpd
X-Vcache
Webcakes-Region
Webcakes-App-Name
Webcakes-App-Version
X-RateLimit-Limit-Second
X-Zipkin-Id
X-Director
X-Cache-Action
X-Auth-Group-Type
OT-Force-Account-Verify
ServedBy
X-Cdn-Origin
X-Cms-Context
DB-Nickname
Atl-Traceid
X-Shopify-Stage
X-Fetched-On
X-Mly-Id
X-MP-GENERATED-AT
X-Tumblr-Pixel-2
X-Storefront-Renderer-Rendered
X-Hosted-By
X-Logging-Id
X-Locale
X-Hit
LB
X-Tumblr-Pixel-3
X-Format
X-Cluster
X-Alternate-Cache-Key
X-Forwarded-Host
X-Redis-Cache
X-Soup
X-Skip-Cache
X-App-Environment
X-FW-Server
X-Urbn-Context-Path
X-Say-TTL
X-NewRelic-App-Data
X-FW-Version
X-Cache-Host
X-SayCDN-TTL
X-Restarts
X-Scope-Id
X-Served-From
X-Urbn-Site-Id
X-FW-Type
X-FW-Static
X-Debug-Info
Environment
X-Say-Cacheable
X-Cluster-Node
Cache-Hits
X-Edge-Location
X-FW-Serve
X-FW-Hash
X-FW-Dynamic
X-Endurance-Cache-Level
Locale
X-PHP-Host
X-Cache-Debug
Front
X-S
X-Labrador-Cache-Channel
X-Drupal-Cache-Contexts
Filters
X-IPLB-Instance
X-Server-ID
X-IPLB-Request-ID
X-XRDS-Location
Node
X-R9-Blue-Green-Version
X-Platform
X-CDN-Cache-Status
Countrycode
AR-SID
X-GEO
X-CDN-Forward
X-Optimistic-Header
X-CLOUD-TRACE-CONTEXT
X-No-Session
Xserver
X-Tt-Logid
X-UA
X-ShopId
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-ShardId
WPO-Cache-Status
X-Varnish-Age
X-Fastly-Request-Id
X-Varnish-Beresp-Ttl
Cache-Tv-Group
X-Varnish-Cache-Hits
X-WP-CF-Super-Cache-Cookies-Bypass
X-Lagoon
X-Presslabs-Stats
X-Wormhole-Sdk
X-Generated-By
X-SRV
X-B3-Traceid
X-Signature
X-B-Cache
X-NWS-UUID-VERIFY
AMP-Access-Control-Allow-Source-Origin
X-CACHE-AGE
Referer-Policy
X-Client-Ip
X-Webstats-RespID
X-Azure-Ref-OriginShield
X-Site-Version
From-Origin
X-Ua
Request-ID
X-PHP-Backend
X-Cache-Operation
X-Cache-Rule
Cache-Provider
X-IsAdmin
X-SRCache-Key
Expect-Staple
X-Accel-Version
X-Clientip
X-LJ-Flow-ID
Location
X-AWS-Id
X-VWS-Id
X-NF-Request-ID
X-Worker
X-Auto-Login
X-TA-CDN-Provider
X-Bc-Bl
Fl-Custom-Application
X-VC-TTL
Mail-Subject
We-Hiring
X-Tx-Id
X-Upstream-Ht
X-Upstream-Ct
Candidate-Md5Url
Source
X-Tb-Optimization-Total-Bytes-Saved
WPO-Cache-Message
DCR-Decision-By
CloudFront-Viewer-Country
S-Rt
Origin-Agent-Cluster
Rendered-Blocks
X-Ec-GeoHdr
X-External-Request-Id
X-GeoCode
X-GeoCountry
X-Ec-Fail
X-Developer
X-Conf
X-Content-Age
X-D
X-Destination
X-Ig-Origin-Region
X-Ig-Push-State
X-Vdms-Version
X-Vtex-Remote-Cache
Xc-Version
X-Server-IP
X-ScT
X-S-Cookie
X-Loc
X-Org
X-PERF
X-Rojux
X-Cache-NE
X-Cache-FS-Status
Origin
Pragrma
Redirect-Candidate
Sslversion
Ngx.Var.Host
N-Cache
Host-ID
Lang
MD5-Digest
Meta-Geo-Continent
X-A
X-A-Ccd
X-Application
X-B-Cookie
X-BCube-Filmed-By
X-Bl-Debug
X-ApacheServer
X-A-Wwc
X-A-Dam
X-A-Dcw
X-A-Dgt
DCR-Processing-Time-Ms
X-Aed
Sid
X-Litespeed-Cache-Control
X-Xfnlog-Site
X-CGP
X-V-Cache
X-Varnish-Authentication
Gh-Request-Id
Ha-Gx-Prefs
X-Varnish-Beresp-Status
X-PAYTM-SRV-ID
CF-IPCountry
X-Bug-Bounty
Fastly-SSL
X-Cache-Aspx
X-Policy
X-Cms-Device
Gannett-Cam-Experience-Id
Cluster
X-CUA
CDN-RequestCountryCode
CDN-PullZone
X-Origin-Expires
CDN-CachedAt
CDN-EdgeStorageId
CDN-RequestPullCode
CDN-RequestPullSuccess
X-Core-Value
IsBot
Cdnsip
Cdncip
CDN-Uid
X-Contensis-Viewer-Groups
Log-Origin
X-Section
X-Sigma-Backend
X-SIPLIST1
X-SD-PageType
X-Slack-Backend
Wxu-Next-Commit
Web-Mar-Region
RNT-Machine
Store-Cloud-Cache
Time-Cloud-Cache
X-Sigma
ServerName
RNT-Time
Wxu-Next-Hostname
Wxu-Next-Region
X-Aicache-OS
X-Action
X-AK-Request-ID
X-Req
CDN-Cache
X-Access
Odigeo-Trace-Id
X-Save-Cache
Powered-By
Origin-Site
X-Rocket-Build-Number
X-Slack-Shared-Secret-Outcome
L5d-Success-Class
X-Csrf-Jwt
X-Ee-Request-Date
X-GeoIP-Region-Code
X-Ee-Request-Id
X-GeoIP-Country-Code
X-GoCache-CacheStatus
X-Hash
X-Ee-Generated-By
X-Sucuri-Cache
X-Gamma-Serve
X-Vary-Devices
X-GeoIP-City
X-VG-TLSProxy
X-Fmm-Version
X-ND-Cache
X-Forwarded-Site
X-From
X-FC-Vary-Parameters
X-Eu-Site
X-VG-WebCache
X-Mvc-Supplant-Cachable
X-Epic-Correlation-Id
X-HS-Content-Campaign-Id
X-Ee-Origin
X-Depends
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
X-Micro-Cache
X-Internal-TTL
Apple-News-Services-Host
Apple-News-Services-Handled
X-Node-Id
X-Old-Content-Length
Canary
X-Varnish-Hostname
X-Varnish-Director
X-Reqid
X-NGINX-Cache
X-Parent-Response-Time
X-Gen-Mode
X-Human
X-Ion-Hop
X-AB-Test
X-Accel-Expires-Debug
X-Jungle-Id
X-Gdpr
X-HN
X-Shield-Cache-Expires
V-Age
X-SB
User-Cache-Control
X-Men
Vix-Hermes-Req-Id
X-Ion-Healthy
X-Generated-On
X-Hnp-Log
X-Render-Time
X-Ec-Custom-Error
Thinkindot-CacheControl-Type
X-Content-Length
X-Origin-Time
X-NMSegId
X-Path
X-Nyt-Route
X-Dispatcher-Server
X-Debug-Cache-Store
X-Debug-Cache-Fetch
X-DefElseHash
X-DefHash
X-Op-Id-All
X-Cache-Date
X-Block-Status
X-Amz-Storage-Class
X-Date
X-Akamai-Device-Characteristics
X-Mvc-Supplant-OutputCached
X-Frame-Option
X-Request-URI
X-App-Name
X-Region-Sid
X-Bip
X-Proto
X-Pubstack
X-BBC-Edge-Cache-Status
X-Backend-Instance
X-Acquia-Purge-Cdn-Unconfigured
RewriteTeamHook
DSUID
X-Up
X-UA-Device-Type
X-Viewer-Country
X-Uri
Content-Style-Type
X-FORWARDED-FOR
X-Thinkindot-L3
Fastly-Backend-Name
X-Thanos
L
X-Thinkindot-L1
X-Wikidot-Static-Cache
X-Vmg-Version
X-Wikidot-Backend
Content-Script-Type
X-Varnish-CookieHashed-On
Azure-SiteName
Azure-SlotName
Azure-RegionName
Azure-InstanceId
X-VarnishDD-TTL
X-Varnish-Remaining-TTL
Azure-Version
Cache-Contol
Cmstype
X-Via-Fastly
Thinkindot-CacheControl
Cmsid
X-Varnish-CookieINHashed-On
CDCHOST
Country-Code
X-We-Are-Hiring
Server-Host
Machine
Pics-Label
PFcat
Origin-EX
RewriteTestHook
Release
X-Cs
X-Level-Front-Cache
Req-Svc-Chain
X-Air-Pt
Nord-Request-ID
Origin-CC
X-CacheTTL
X-Fastly-Backend
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
TDXMobile
NM-Fastcgi-Cache
X-Sn-Servicetimems
X-Edge-Server
X-ElasticPress-Query
Tube-Got-Results
Tube-Got-Eval
Cdn-Host
X-Vercel-Id
Tube-Get-Contents
Tube-Return
C-Via
X-Location
X-DPWN-IS-SECURE
CacheControlHeader
X-Vercel-Cache
X-LSADC-Cache
X-Esi-Check
X-Moov-Xdn-Version
Cdn-Request-Time
Fastly-GeoIP-CountryCode
X-Proxied-Request
X-ZONE
X-B3-Trace-ID
X-Cache-Id
X-Moov-Xdn-Caching-Status
Click-Count-Error
Click-Count-Action-Start
Platform
X-Gzip
X-Moov-T
Producers
X-Sucuri-ID
XM
Mime-Version
X-Origin-Response-Time
Fastly-Drupal-HTML
X-Source
X-Pad
Load-Balancing
NGX
X-Cached-By
Debug
X-Refresh
X-APP
X-Varnish-Hits
Cookie
X-Via-Popn
X-Servedbyhost
X-Nginx-Cache-Key
X-Via-Popv
X-Via-Poph
X-Debug-Service
X-Datadome
GeoIp-Country-Code
GeoIP-Latitude
True-Client-Country-4JS
X-Srv
Server-Ext
Server-Hostname
Server-ID
X-AIR-PT
Sever-Int
X-HA-Backend
X-TH-Server
X-Nananana
Product
HA-Ipaddr
X-DynaTrace-JS-Agent
X-Webkit-CSP
X-Litespeed-Tag
X-TT-LOGID
Show-Do-Not-Sell-Link
Cdn
X-Amz-Meta-Cb-Modifiedtime
Traceparent
X-Cdn-Forward
X-GeoIP
X-Fpc
WZWS-RAY
X-Nc
X-Cache-Backend
X-Wa
X-Cache-VC
X-Zone
X-Ez-Minify-Html
X-Newrelic-Synthetics
X-User
Edge-Cache
X-B3-Parentspanid
HostName
X-LB-ID
DataCenter
X-Unity-Cache
Fastly-Drupal-Html
SID
Tcn
MIME-Version
X-VCL-Version
X-Lsadc-Cache
Akamai-Mon-Iucid-Del
X-Request-Start
X-LB-NoCache
X-CDN-Provider
X-AC
Resin-Trace
Lb
X-B3-Spanid
Yjs-Id
X-Nginx-Cache
X-Vc
X-Service-Response-Time
Serverhost
X-Proxy-Cache-La3
Wsr-Cache
Xkeylog
Xkey-La3
Sm-Log-Id
X-Proxy-CacheR9
XkeyR9
A
X-Scheme
X-TX-ID
X-Datacenter
CountryCode
X-LiteSpeed-Tag
X-HOST
Surrogated-Key
Cs
X-RateLimit-Limit
X-Pool
X-Request-Host
X-Lb-Id
X-CS
Hostname
NtCoent-Length
X-LiteSpeed-Cache-Control
X-NodeID
Datacenter
CDN
X-Dynatrace-Js-Agent
X-WA
X-Akamai-Pragma-Client-IP
X-HubSpot-Correlation-Id
Uri
Esi-Enabled
Cdn-Requestid
X-API-Version
X-RequestId
X-Aspnet-Version
X-VC-Age
X-NC
X-Udemy-Cache-App-Namespace
X-Fastly-Backend-Reqs
X-Vgn-Hpd-Reason
X-FPC
X-Cache-Grace
X-ID
X-Air-Hostname
X-Air-Trace-Id
X-Air-Source
Yak-Timeinfo
X-Styx-Origin-Id
Server-Id
X-TIM-N
X-Via-JSL
Content-Secure-Policy
X-Stale
X-DynaTrace
X-Styx-Info
Cr
X-HA-Device-Type
Pramga
X-HA-Application-Name
Proxy-Firewall
X-DataCenter
X-HA-Bot-Classification
X-Html-Minification-Powered-By
N1-Cache
X-CSRF-TOKEN
Geoip-Latitude
T-Server
RATING
X-Var-Ttl
Edge-Copy-Time
X-Ez-Minify-Js
X-TimeS
X-Via-SSL
X-Via-Edge
X-Srcache-Store-Status
X-Via-CDN
ServerHost
GeoIP-Country-Code
X-Srcache-Fetch-Status
X-Swift-Error
Req-ID
X-ServedByHost
W
X-Geolocation
X-Lb-Nocache
X-Jobs
Srv
X-Varnish-Beresp-TTL
X-Zen-Fury
From-Cache
X-Ha-Backend
X-Wp-Cf-Super-Cache-Cache-Control
X-Aspnetmvc-Version
X-Oracle-DMS-ECID
X-Wp-Cf-Super-Cache
X-App
X-MSEdge-Features
X-Via-PopV
WP-Super-Cache
True-Client-IP
X-Via-PopH
X-CACHE-KEY
Cloudfront-Viewer-Country
X-Via-PopN
X-MSEdge-Flight
X-Sorting-Hat-Shopid
X-Shopid
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-Wp-Cf-Super-Cache-Active
X-LAGOON
X-Sorting-Hat-Podid
X-Shardid
X-Cdn-Srv
FSS-Cache
On-Server
X-Proxy-Cache-LA2
X-ByteArk-Cache
X-Key
X-VServer
Ohc-File-Size
Ohc-Cache-HIT
X-Ramcache
X-ByteArk-ReqID
X-Correlation-ID
X-Ssense-Shipping-Surcharge-Enabled
X-Ssense-Gql
X-Check-Cacheable
Cl-Cache
X-Cdn-Cache-Status
X-Elasticpress-Query
X-Powered-By-VTEX-Cache
X-Webkit-Csp-Report-Only
Ngx
X-Sucuri-Id
X-VTEX-Cache-Time
CF-Cached-On
X-VTEX-Cache-Server
X-Geo
X-Web-Server
X-NODE
X-PageType
X-Fastly-Cache
X-Serial
WebServer
X-DC
X-ATG-Version
Akamai-X-True-TTL
X-Th-Server
X-Iplb-Request-Id
Cf-Ipcountry
X-Iplb-Instance
X-Mg-Cache
Warning
X-Env
X-Beacon
X-WA-Info
X-MiniProfiler-Ids
X-Limited
My-App
Coldstone-Viewer-Country
FSS-Proxy
X-Fastly-Cache-Status
X-Request-Url
User-Agent
Coldstone-Viewer-Currency
Xkey-G-Jp
Host-Name
Coldstone-Viewer-Country-Region-Name
Cneonction