Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
X-Frame-Options
Expires
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Accept-CH
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
X-XSS-Protection
Pragma
X-Powered-By
CF-RAY
X-Cache
Via
Age
Content-Security-Policy
Alt-Svc
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-Download-Options
X-Xss-Protection
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
CF-Ray
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
X-DNS-Prefetch-Control
Content-Security-Policy-Report-Only
Accept-CH-Lifetime
X-AspNet-Version
X-Runtime
Accept-Ch
Permissions-Policy
Server-Timing
X-Drupal-Cache
X-Generator
X-Envoy-Upstream-Service-Time
X-Cache-Status
X-Cacheable
X-FRAME-OPTIONS
X-Iinfo
X-Drupal-Dynamic-Cache
X-Ua-Compatible
Timing-Allow-Origin
X-CONTENT-TYPE-OPTIONS
Feature-Policy
X-Content-Security-Policy
Xkey
Upgrade
Access-Control-Expose-Headers
X-CDN
X-XSS-PROTECTION
Content-Encoding
Status
X-AspNetMvc-Version
Access-Control-Max-Age
X-Amz-Request-Id
Host-Header
X-Amz-Id-2
Request-Context
X-Age
Cf-Edge-Cache
X-Backend
X-Robots-Tag
X-Hacker
Keep-Alive
X-Request-ID
X-Via
Cf-Apo-Via
X-Turbo-Charged-By
X-Amz-Version-Id
X-Rq
X-AH-Environment
X-Cache-Group
X-Vhost
X-Server
X-Dispatcher
X-Proxy-Cache
X-Ws-Request-Id
EagleId
CONTENT-SECURITY-POLICY
X-UA-Device
X-Varnish-Cache
Pantheon-Trace-Id
Grace
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-OneAgent-JS-Injection
X-Litespeed-Cache
X-Server-Powered-By
X-Pingback
Allow
X-Page-Speed
X-WebKit-CSP
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Swift-SaveTime
X-Swift-CacheTime
X-Dns-Prefetch-Control
Ali-Swift-Global-Savetime
X-Node
X-FTR-Request-ID
X-Device
X-Cache-Lookup
X-Server-Id
EagleEye-TraceId
X-Host
X-Backend-Server
X-Country-Code
Surrogate-Control
X-Cloud-Trace-Context
X-Readtime
X-Akam-SW-Version
Cf-Railgun
X-Ruxit-JS-Agent
X-HW
X-Response-Time
Accept-Ch-Lifetime
X-LiteSpeed-Cache
Cache-Tag
P3p
Cf-Request-Id
X-Amz-Server-Side-Encryption
X-Ua-Device
Content-Location
Cross-Origin-Opener-Policy
X-Rack-Cache
X-Nginx-Upstream-Cache-Status
X-Nginx-Cache-Status
X-Trace
Service-Worker-Allowed
Request-Id
X-TraceId
X-Application-Context
Fastly-Restarts
X-Content-Type
X-Nf-Request-Id
X-Times
Rating
X-Vname
X-TtlSet
X-PC
X-Clacks-Overhead
X-Cnection
X-Mcache
X-Edge
X-Midtier
X-ESI
X-Vcap-Request-Id
X-Browser-Type
X-FTR-Backend
X-FTR-Backend-Server
X-FTR-Balancer
X-Country-Code-Real
X-FTR-Cache-Status
Edge-Control
X-FTR-Expires
X-Cache-TTL
Origin-Trial
X-Element-Page-Cache
X-D2id
Surrogate-Key
X-NWS-LOG-UUID
X-FastCGI-Cache
X-Country
X-Powered-By-Plesk
X-Oneagent-Js-Injection
X-Kinja-Build
X-Exp-Variant
X-Exp-Id
X-Kinja-Revision
X-GoogleNews-Bot
X-Kinja
X-Kinja-Server
X-Cdn-Fetch
X-Ac
X-Abt-Application-Version
X-Upstream
Verso
X-Mod-Pagespeed
X-Navigation-Version
X-B3-TraceId
X-Url
X-ORACLE-DMS-RID
Akamai-GRN
X-Amz-Rid
X-Pinterest-Rid
Pinterest-Version
Pinterest-Generated-By
X-Language
Nginx-Cache
X-ECACHE
Display
Pagespeed
X-GitHub-Request-Id
X-Sol
X-Middleton-Display
X-Envoy-Decorator-Operation
S
X-PDP-UNCACHING-HASH
X-Kraken-Loop-Name
X-Erf-Bev-Bev-Is-Generated
X-Server-Lifecycle-Phase
X-Erf-Bev-Bev
X-Instrumentation
Response
X-Middleton-Response
AR-PoweredBy
AR-ATIME
AR-Request-ID
X-MS-InvokeApp
Edge-Cache-Tag
X-Ratelimit-Limit
X-Distributor
X-Goog-Hash
X-Resp-Is-Stale
SPRequestGuid
SPRequestDuration
X-SharePointHealthScore
SPIisLatency
X-Edge-Location-Klb
X-Kinsta-Cache
X-Ser
X-NGENIX-Cache
X-ARC
X-Client-IP
X-Ttl
Front-End-Https
Access-Control-Request-Method
X-Dw-Request-Base-Id
X-Ruxit-Js-Agent
X-Amzn-Trace-Id
X-Shield-Request-Id
X-Content-Digest
X-Ezoic-Cdn
RTSS
X-Varnish-TTL
X-Recruiting
X-Cache-Key
Cache-Status
X-Version
X-T
X-Mg-S
TP-Cache
X-Powered-CMS
Public-Key-Pins
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Cache-Config
Fastcgi-Cache
X-Accel-Expires
X-MSEdge-Ref
X-Ismobilevalue
Arr-Disable-Session-Affinity
AR-CACHE
X-Daa-Tunnel
Realpath
Cache-Tags
X-Cluster-Name
X-Cached
X-Id
X-Correlation-Id
Content-MD5
X-Content-Security-Policy-Report-Only
X-Request-Received
Ar-SID
X-Request-Processing-Time
YJS-ID
X-Request-Device-Id
X-Forwarded-For
X-HS-Combine-CSS
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Fastly-Request-ID
X-Newrelic-App-Data
Payment
X-DIS-Request-ID
X-Ua-Browser
X-Xrds-Location
X-HP-Webp
X-HP-Trace-Id
X-Cambria-Cache-Control
X-Jurisdiction
X-COUNTRY
X-Azure-Ref
X-GUploader-UploadID
X-RateLimit-Remaining
X-HS-Prerendered
X-HS-CF-Cache-Status
X-Amz-Replication-Status
X-Webkit-Csp
Content-Disposition
X-Meli-Trace-Site
X-Meli-Trace-Bu
X-Meli-Trace-Platform
X-Ratelimit-Remaining
X-Server-Name
Count-Hit
X-Px
X-Ratelimit-Reset
X-Origin-Server
X-Page-Id
X-Protected-By
X-Unique-Id
Accept-Charset
X-AppVersion
X-Logged-In
Cross-Origin-Resource-Policy
X-SRCache-Store-Status
X-Activity-Id
X-Proxy
X-SRCache-Fetch-Status
X-Az
Cleartype
Cross-Origin-Embedder-Policy
X-Www-Served-By
MicrosoftSharePointTeamServices
X-FB-Debug
X-Rid
X-Git-Hash
X-ORACLE-DMS-ECID
X-TTL
X-SERVER-NAME
X-Amz-Meta-S3cmd-Attrs
X-Microsite
X-VARITI-CCR
X-Request-Handler-Origin-Region
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Load-Cache
Version
X-LLID
X-Template
X-Goog-Metageneration
X-Forwarded-Proto
X-Geo-Country
X-TEC-API-ROOT
X-TEC-API-VERSION
X-Varnish-Backend
X-TEC-API-ORIGIN
X-PressLabs-Stats
X-Upgrade-Enabled
X-CST
X-Hits
Server-Node
X-B3-Sampled
Server-Name
X-App-Server
X-Content-Options
X-Hostname
X-WebKit-CSP-Report-Only
X-TT
X-B
X-Varnish-Server
X-Grace
X-Fb-Rlafr
Access-Control-Allow-Method
Healthy
Section-Io-Cache
Fastly-SWR
Fastly-SIE
Alternate-Protocol
Viewport
X-Varnish-Grace
X-Device-Type
X-Frontend
X-B3-TraceId-Primal
Mrf-Cache-Status
MRF-Tech
X-Status
X-Request-Guid
X-Goog-Generation
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
TCN
X-Goog-Stored-Content-Length
X-Contextid
Upgrade-Insecure-Requests
DC
Host
X-Magnolia-Registration
AKAMAI-GRN
MS-Author-Via
X-EdgeConnect-Cache-Status
X-Amzn-Remapped-Content-Length
Retry-After
X-App-Version
X-CSRF-Token
X-Requestid
X-Cache-Age
X-Cache-Control
Frame-Options
Amp-Access-Control-Allow-Source-Origin
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Type
X-Varnish-Ttl
X-Origin-CC
X-Buckets
X-Debug
X-Origin-TTL
X-Response-Served-From
X-Revision
X-Original-Request-Id
X-Hl-Ver
X-INCAP-ABP
X-RemovedCookies
X-ProcessESI
SD-X-WS
X-UUID
X-Mobile
Cross-Origin-Embedder-Policy-Report-Only
X-Oracle-Dms-Ecid
X-Lambda-Id
Cross-Origin-Opener-Policy-Report-Only
Section-Io-Id
X-NYM-Debug-Backend
X-Adobe-Content
X-Adobe-Loc
X-Akamai-Edgescape
VIX-Pulpo-Upstream-Status
X-Backend-Name
VIX-Pulpo-Node
Ms-Operation-Id
MS-CV
X-Content-Powered-By
X-Debug-IsConnected
X-RTag
X-ServerID
X-Instance
X-G
X-Debug-IsPreview
Access-Control-Request-Headers
X-Seen-By
X-Rendered-As
X-Is-Bot
X-Cache-Status-Check
X-AB
X-Server-W
X-Tumblr-Pixel-0
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Tumblr-User
X-Tumblr-Pixel-1
X-N
X-Tumblr-Pixel
X-WP-CF-Super-Cache
X-Framework
X-Mg-Request-UUID
X-Trace-Id
X-WP-CF-Super-Cache-Cache-Control
NGB
X-Akamai-Request-ID2
X-Storage
X-Dc
X-RM-Cache-TTL
X-Vcl-Version
Charset
Cache
Webserver
X-Yandex-Req-Id
X-DataDome
X-B3-SpanId
Filterid
X-Tec-Api-Origin
X-Tec-Api-Version
X-Tec-Api-Root
X-Cache-Time
Paypal-Debug-Id
SRV
X-Request-Platform
Accept-Language
X-Request-Bu
X-Request-Site
Refresh
X-VC-Cache
X-Cache-Hit
X-URL
Onion-Location
X-ECache
X-HITS
X-Ms-Version
X-Ms-Request-Id
X-Fastcgi-Cache
X-F-Cache
X-Time
X-Real-IP
X-Node-Name
YJS-CacheStatus
X-Region
X-User-Agent
X-Mode
X-CCDN-Origin-Time
X-CCDN-CacheTTL
X-Hcs-Proxy-Type
X-Environment-Context
Xet-Cookie
X-L-Path
Liferay-Portal
Priority
X-IPS-LoggedIn
CDN-RequestId
X-HTML-Minification-Powered-By
GEO-INFO
X-LB-Cache
X-Pass-Why
X-Service
X-Drupal-Cache-Tags
Cross-Origin-Window-Policy
X-Adobe-Source
X-Rocket-Nginx-Serving-Static
X-Datadog-Trace-Id
X-Datadog-Parent-Id
X-Rule
X-Datadog-Sampled
X-Datadog-Sampling-Priority
Backend
X-UPSTREAM-Address
X-Proxied
X-Is-Supported-Browser
X-Cache-Expired-At
X-Extlb
Meta-Geo
X-Cloudmap
X-Tcp-Rtt
Country
X-Tb
Selected-Fe
X-Is-Mobile
X-Is-Mobile-Only
X-Timing-Wait
X-Is-Desktop
X-Geo-Region
X-SaId
X-Is-Modern-Browser
X-Zipkin-Id
X-Is-Tablet
X-JoinUs
X-Browser-Name
Protected
X-Routing-Service
X-Rewrite-Enabled
X-Rn-Rsrv
X-Proxy-Build
Url
X-VC
X-Whom
X-Hit
X-RCS-CacheZone
X-Proxy-Cache-Info
X-Wix-Request-Id
X-Servername
X-Origin-Cache
X-Httpd
X-Handled-By
X-Origin
X-MP-GENERATED-AT
OT-Force-Account-Verify
X-Provided-By
X-ProxyCache-Status
Mn-Server-Ip
X-Shopify-Stage
X-Web-Node
X-Cluster
X-Alternate-Cache-Key
X-ProxyCache-Key
X-Forwarded-Host
X-Generation-Time
X-Storefront-Renderer-Rendered
X-BYPASS-REASON
Uber-Trace-Id
TWC-Privacy
X-FB-TRIP-ID
Webcakes-App-Name
X-RateLimit-Limit-Second
TWC-GeoIP-Country
TWC-GeoIP-Region
X-Varnish-Beresp-Grace
X-RateLimit-Remaining-Second
TWC-Locale-Group
Environment
Cache-Hits
X-Connection-Hash
Expiry
X-Detected-As
X-Vcache
Fastcgi-Useragent
Web-Mar-Node
X-WP-CF-Super-Cache-Active
X-Origin-Date
TWC-Device-Class
ServerID
X-VCT
TWC-GeoIP-City
Webcakes-App-Version
TWC-Connection-Speed
TWC-GeoIP-DMA
X-Origin-Hint
Property-Id
X-Loop
X-Tncms
X-S
Webcakes-Region
TWC-GeoIP-LatLong
DB-Nickname
X-Auth-Group-Type
X-App-Environment
ServedBy
X-Cacheable-TTL
X-Cdn-Origin
X-Cache-Action
X-Cms-Context
X-Soup
LB
X-Skip-Cache
X-Tumblr-Pixel-3
X-Tumblr-Pixel-2
X-Hosted-By
X-Redis-Cache
X-Fetched-On
X-Format
X-Drupal-Cache-Contexts
X-Director
Apigw-Requestid
X-Logging-Id
X-Locale
Atl-Traceid
X-Urbn-Context-Path
X-Say-TTL
X-Urbn-Site-Id
X-Scope-Id
X-Served-From
X-Restarts
X-SayCDN-TTL
X-FW-Version
X-FW-Dynamic
X-FW-Hash
Locale
X-Endurance-Cache-Level
X-Debug-Info
X-Edge-Location
X-Say-Cacheable
X-FW-Serve
X-FW-Type
X-FW-Server
X-Cluster-Node
X-FW-Static
X-Cache-Host
X-PHP-Host
X-Labrador-Cache-Channel
X-Cache-Debug
Filters
X-IPLB-Request-ID
X-IPLB-Instance
X-Server-ID
X-Platform
X-NewRelic-App-Data
X-XRDS-Location
Node
X-R9-Blue-Green-Version
X-Api-Version
X-Mly-Id
X-GEO
AR-SID
X-CDN-Cache-Status
Front
X-Sorting-Hat-PodId
X-CDN-Forward
X-ShopId
X-CLOUD-TRACE-CONTEXT
X-No-Session
X-Sorting-Hat-ShopId
X-ShardId
X-Tt-Logid
X-Optimistic-Header
Xserver
X-Varnish-Age
X-UA
WPO-Cache-Status
Countrycode
X-Varnish-Beresp-Ttl
X-WP-CF-Super-Cache-Cookies-Bypass
Cache-Tv-Group
X-Varnish-Cache-Hits
X-Lagoon
X-Wormhole-Sdk
X-Presslabs-Stats
X-SRV
X-Fastly-Request-Id
X-Generated-By
X-B3-Traceid
X-Signature
X-NWS-UUID-VERIFY
X-B-Cache
X-CACHE-AGE
Referer-Policy
X-Client-Ip
X-Webstats-RespID
X-Azure-Ref-OriginShield
X-Site-Version
X-Ua
From-Origin
AMP-Access-Control-Allow-Source-Origin
Request-ID
X-Cache-Operation
X-Cache-Rule
X-IsAdmin
X-PHP-Backend
Cache-Provider
X-Accel-Version
X-Worker
X-VWS-Id
X-NF-Request-ID
X-Auto-Login
X-LJ-Flow-ID
X-AWS-Id
Location
X-TA-CDN-Provider
X-VC-TTL
X-Upstream-Ht
X-Upstream-Ct
X-Tx-Id
X-A-Dgt
ServerName
X-A-Wwc
X-Org
X-A-Ccd
X-A-Dam
X-Ig-Push-State
Source
X-Tb-Optimization-Total-Bytes-Saved
WPO-Cache-Message
X-A-Dcw
X-BCube-Filmed-By
S-Rt
Xc-Version
X-Bc-Bl
X-Loc
X-Bl-Debug
Origin-Agent-Cluster
X-D
Lang
Host-ID
X-Clientip
Fl-Custom-Application
MD5-Digest
Meta-Geo-Continent
Origin
X-Conf
X-Content-Age
Ngx.Var.Host
N-Cache
Expect-Staple
X-Destination
Candidate-Md5Url
X-External-Request-Id
Redirect-Candidate
Rendered-Blocks
X-GeoCode
X-Ec-GeoHdr
X-Ec-Fail
Pragrma
X-Developer
DCR-Processing-Time-Ms
DCR-Decision-By
X-Cache-NE
X-GeoCountry
X-Ig-Origin-Region
X-PERF
X-Rojux
X-Vdms-Version
X-Varnish-Hostname
X-B-Cookie
X-Application
X-S-Cookie
X-Aed
X-ApacheServer
X-A
X-ScT
Sslversion
X-Vtex-Remote-Cache
X-Xfnlog-Site
X-Litespeed-Cache-Control
X-Ee-Request-Id
Cluster
X-SD-PageType
Cmsid
X-Ee-Origin
X-Ee-Generated-By
X-Epic-Correlation-Id
X-Ee-Request-Date
Cmstype
X-Save-Cache
CDN-RequestPullSuccess
CDN-Cache
CDN-CachedAt
X-FC-Vary-Parameters
CDCHOST
Canary
X-Up
CDN-EdgeStorageId
We-Hiring
CDN-Uid
Cdncip
CDN-RequestPullCode
CDN-RequestCountryCode
CDN-PullZone
X-Eu-Site
Cdnsip
X-CGP
Mail-Subject
X-Slack-Shared-Secret-Outcome
X-Csrf-Jwt
Log-Origin
L5d-Success-Class
X-Slack-Backend
X-Core-Value
X-SRCache-Key
X-Contensis-Viewer-Groups
X-AK-Request-ID
Odigeo-Trace-Id
X-Aicache-OS
X-Content-Length
X-CUA
IsBot
Fastly-SSL
X-Action
X-Fmm-Version
Powered-By
X-Depends
X-Sigma
Gannett-Cam-Experience-Id
Pics-Label
X-Sigma-Backend
X-SIPLIST1
Origin-Site
Ha-Gx-Prefs
Gh-Request-Id
X-Section
X-Gamma-Serve
Country-Code
X-Render-Time
X-Vary-Devices
X-Men
X-Micro-Cache
RNT-Time
RNT-Machine
X-Forwarded-Site
X-Varnish-Director
Wxu-Next-Commit
X-Internal-TTL
X-Sucuri-Cache
X-Cs
X-Policy
Wxu-Next-Hostname
X-VG-WebCache
Wxu-Next-Region
Store-Cloud-Cache
X-Origin-Expires
X-Cms-Device
X-Old-Content-Length
CF-IPCountry
X-Mvc-Supplant-Cachable
X-PAYTM-SRV-ID
X-Node-Id
X-VG-TLSProxy
X-Access
X-HS-Content-Campaign-Id
Time-Cloud-Cache
X-Rocket-Build-Number
X-GeoIP-City
X-GeoIP-Country-Code
X-V-Cache
X-Req
Apple-News-Services-Handled
Apple-News-Services-Host
Sid
X-From
X-Uri
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
X-GeoIP-Region-Code
X-Varnish-Authentication
X-ND-Cache
Web-Mar-Region
X-Bug-Bounty
X-Server-IP
X-Cache-Aspx
X-Hash
X-Varnish-Beresp-Status
X-GoCache-CacheStatus
X-Reqid
X-Parent-Response-Time
X-NGINX-Cache
X-Accel-Expires-Debug
X-Cache-FS-Status
X-Akamai-Device-Characteristics
X-Cache-Date
X-Amz-Storage-Class
X-Bip
X-App-Name
X-Backend-Instance
X-BBC-Edge-Cache-Status
X-Block-Status
X-Ion-Healthy
X-Thanos
X-SVT-ORM-VERSION
X-Thinkindot-L1
X-Thinkindot-L3
X-UA-Device-Type
X-SVT-ORM-RULES
X-Sn-Servicetimems
X-Region-Sid
X-Request-URI
X-SB
X-Shield-Cache-Expires
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-CacheTTL
X-Fastly-Backend
X-We-Are-Hiring
X-Vmg-Version
X-Varnish-Remaining-TTL
X-VarnishDD-TTL
X-Via-Fastly
X-Viewer-Country
X-Pubstack
X-Proto
X-Gdpr
X-Frame-Option
X-Gen-Mode
X-Generated-On
X-HN
X-Ec-Custom-Error
X-Dispatcher-Server
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-DefElseHash
X-DefHash
X-Hnp-Log
X-Human
X-Nyt-Route
X-Op-Id-All
X-Origin-Time
X-Path
X-NMSegId
X-Mvc-Supplant-OutputCached
X-AB-Test
X-Ion-Hop
X-Jungle-Id
X-Level-Front-Cache
X-Date
X-Acquia-Purge-Cdn-Unconfigured
Origin-CC
Nord-Request-ID
NM-Fastcgi-Cache
Machine
Origin-EX
Release
RewriteTeamHook
X-FORWARDED-FOR
Req-Svc-Chain
L
Fastly-Backend-Name
Content-Script-Type
Azure-SlotName
Azure-Version
Cache-Contol
Content-Style-Type
Azure-SiteName
DSUID
Azure-InstanceId
Azure-RegionName
RewriteTestHook
PFcat
V-Age
Thinkindot-CacheControl-Type
Vix-Hermes-Req-Id
User-Cache-Control
TDXMobile
Server-Host
X-Air-Pt
Thinkindot-CacheControl
Tube-Got-Results
X-Vercel-Id
Fastly-GeoIP-CountryCode
Tube-Got-Eval
X-Gzip
Tube-Return
X-DPWN-IS-SECURE
X-Edge-Server
X-Esi-Check
Cdn-Request-Time
Cdn-Host
Click-Count-Action-Start
X-ElasticPress-Query
C-Via
Click-Count-Error
X-Location
X-Moov-T
Platform
X-B3-Trace-ID
Producers
X-Cache-Id
X-Proxied-Request
X-LSADC-Cache
CacheControlHeader
Tube-Get-Contents
X-Moov-Xdn-Version
X-Moov-Xdn-Caching-Status
X-Vercel-Cache
X-Source
X-Sucuri-ID
X-Origin-Response-Time
XM
Mime-Version
Fastly-Drupal-HTML
X-Pad
CloudFront-Viewer-Country
X-ZONE
NGX
X-Cached-By
X-Varnish-Hits
X-Refresh
Debug
Load-Balancing
X-Via-Popv
X-Via-Popn
X-Datadome
X-APP
Cookie
X-Via-Poph
X-AIR-PT
GeoIP-Latitude
GeoIp-Country-Code
X-Debug-Service
X-Servedbyhost
X-Nginx-Cache-Key
X-HA-Backend
X-TT-LOGID
True-Client-Country-4JS
X-Nananana
X-Srv
X-DynaTrace-JS-Agent
HA-Ipaddr
X-TH-Server
Sever-Int
Server-Hostname
Product
Server-Ext
Server-ID
X-Zone
X-Webkit-CSP
X-Litespeed-Tag
X-Ez-Minify-Html
X-Amz-Meta-Cb-Modifiedtime
Show-Do-Not-Sell-Link
Cdn
Traceparent
X-Cdn-Forward
X-GeoIP
X-Nc
X-Cache-VC
X-Cache-Backend
X-Wa
WZWS-RAY
X-Fpc
X-Newrelic-Synthetics
HostName
X-B3-Parentspanid
DataCenter
X-LB-ID
X-Unity-Cache
X-User
Edge-Cache
Fastly-Drupal-Html
MIME-Version
Tcn
SID
X-VCL-Version
X-Lsadc-Cache
Resin-Trace
X-LB-NoCache
Lb
X-Request-Start
X-CDN-Provider
X-AC
Akamai-Mon-Iucid-Del
X-Nginx-Cache
X-Vc
X-B3-Spanid
X-Service-Response-Time
X-Scheme
Wsr-Cache
A
Xkeylog
Sm-Log-Id
Xkey-La3
XkeyR9
X-Proxy-Cache-La3
Serverhost
X-Proxy-CacheR9
X-TX-ID
CountryCode
X-Datacenter
X-LiteSpeed-Tag
X-HOST
Yjs-Id
Surrogated-Key
Cs
X-CS
X-Lb-Id
X-LiteSpeed-Cache-Control
X-Pool
X-RateLimit-Limit
Hostname
X-Request-Host
NtCoent-Length
Cdn-Requestid
X-WA
Esi-Enabled
X-Akamai-Pragma-Client-IP
CDN
X-Dynatrace-Js-Agent
X-NodeID
Uri
X-HubSpot-Correlation-Id
Datacenter
X-API-Version
X-RequestId
X-FPC
X-Vgn-Hpd-Reason
X-VC-Age
X-ID
X-Udemy-Cache-App-Namespace
X-Cache-Grace
X-NC
X-Fastly-Backend-Reqs
X-Air-Source
X-Air-Hostname
X-Air-Trace-Id
X-Styx-Origin-Id
Content-Secure-Policy
X-DynaTrace
Pramga
Cr
Yak-Timeinfo
X-HA-Application-Name
X-TIM-N
X-Via-JSL
Server-Id
X-HA-Device-Type
X-Styx-Info
X-Html-Minification-Powered-By
X-Stale
X-DataCenter
X-HA-Bot-Classification
Proxy-Firewall
N1-Cache
X-CSRF-TOKEN
Geoip-Latitude
Edge-Copy-Time
GeoIP-Country-Code
T-Server
W
ServerHost
X-Via-Edge
X-Srcache-Store-Status
X-Via-SSL
X-Via-CDN
X-Var-Ttl
X-Srcache-Fetch-Status
X-Ez-Minify-Js
RATING
X-TimeS
X-Jobs
X-Varnish-Beresp-TTL
Srv
Cloudfront-Viewer-Country
X-Swift-Error
X-ServedByHost
Req-ID
X-Geolocation
X-Lb-Nocache
X-Ha-Backend
From-Cache
X-Zen-Fury
X-Oracle-DMS-ECID
X-Wp-Cf-Super-Cache
X-Wp-Cf-Super-Cache-Cache-Control
True-Client-IP
X-MSEdge-Features
X-Via-PopN
X-CACHE-KEY
X-Via-PopV
X-MSEdge-Flight
X-Via-PopH
WP-Super-Cache
X-App
X-Sorting-Hat-Shopid
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-Shardid
X-LAGOON
X-Sorting-Hat-Podid
X-Shopid
X-Wp-Cf-Super-Cache-Active
X-Ssense-Shipping-Surcharge-Enabled
Ohc-Cache-HIT
X-Ssense-Gql
X-ByteArk-Cache
Ohc-File-Size
X-Proxy-Cache-LA2
X-ByteArk-ReqID
FSS-Cache
X-Ramcache
X-Cdn-Srv
X-Key
X-Correlation-ID
X-VServer
On-Server
X-Elasticpress-Query
Ngx
Cl-Cache
X-Webkit-Csp-Report-Only
X-Sucuri-Id
X-Powered-By-VTEX-Cache
X-Check-Cacheable
X-VTEX-Cache-Server
X-VTEX-Cache-Time
X-Web-Server
X-Cdn-Cache-Status
CF-Cached-On
X-Geo
X-PageType
WebServer
X-ATG-Version
X-Fastly-Cache
X-DC
X-Th-Server
X-Serial
Akamai-X-True-TTL
Cf-Ipcountry
X-Iplb-Request-Id
X-Iplb-Instance
Warning
Coldstone-Viewer-Currency
Coldstone-Viewer-Country-Region-Name
X-Env
My-App
X-MiniProfiler-Ids
X-Limited
X-Beacon
Coldstone-Viewer-Country
Cneonction
User-Agent
X-Request-Url
X-Mg-Cache
Host-Name
X-WA-Info
Xkey-G-Jp
FSS-Proxy
X-Fastly-Cache-Status