Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
X-Frame-Options
Expires
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Accept-CH
CF-Cache-Status
ETag
Expect-CT
X-XSS-Protection
Accept-Ranges
Pragma
X-Powered-By
CF-RAY
X-Cache
Via
Age
Content-Security-Policy
Alt-Svc
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-Download-Options
X-Request-Id
X-Timer
X-Xss-Protection
Access-Control-Allow-Headers
Access-Control-Allow-Methods
CF-Ray
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
X-DNS-Prefetch-Control
Content-Security-Policy-Report-Only
Accept-CH-Lifetime
X-AspNet-Version
X-Runtime
Accept-Ch
Permissions-Policy
Server-Timing
X-Drupal-Cache
X-Generator
X-Envoy-Upstream-Service-Time
X-Cache-Status
X-Cacheable
X-FRAME-OPTIONS
X-Iinfo
X-Drupal-Dynamic-Cache
X-Ua-Compatible
Timing-Allow-Origin
X-CONTENT-TYPE-OPTIONS
Feature-Policy
X-Content-Security-Policy
Xkey
Upgrade
Access-Control-Expose-Headers
X-CDN
X-XSS-PROTECTION
Content-Encoding
Status
X-AspNetMvc-Version
Access-Control-Max-Age
X-Amz-Request-Id
Host-Header
X-Amz-Id-2
X-Age
Request-Context
Cf-Edge-Cache
X-Backend
X-Robots-Tag
X-Hacker
X-Request-ID
Keep-Alive
X-Via
Cf-Apo-Via
X-Amz-Version-Id
X-Turbo-Charged-By
X-Rq
X-AH-Environment
X-Cache-Group
X-Vhost
X-Server
X-Dispatcher
X-Proxy-Cache
X-Ws-Request-Id
EagleId
CONTENT-SECURITY-POLICY
X-UA-Device
X-Varnish-Cache
Pantheon-Trace-Id
Grace
X-Litespeed-Cache
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-OneAgent-JS-Injection
X-Server-Powered-By
X-Pingback
Allow
X-Page-Speed
X-WebKit-CSP
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Swift-SaveTime
X-Swift-CacheTime
X-Dns-Prefetch-Control
Ali-Swift-Global-Savetime
X-FTR-Request-ID
X-Node
X-Device
X-Cache-Lookup
X-Server-Id
EagleEye-TraceId
X-Host
X-Country-Code
X-Backend-Server
Surrogate-Control
X-Cloud-Trace-Context
X-Readtime
X-Akam-SW-Version
Cf-Railgun
X-Ruxit-JS-Agent
X-HW
X-Response-Time
Accept-Ch-Lifetime
Cache-Tag
P3p
Cf-Request-Id
X-Amz-Server-Side-Encryption
X-LiteSpeed-Cache
X-Ua-Device
Content-Location
Cross-Origin-Opener-Policy
X-Rack-Cache
X-Nginx-Upstream-Cache-Status
X-Nginx-Cache-Status
X-Trace
Service-Worker-Allowed
Request-Id
X-TraceId
X-Content-Type
X-Application-Context
Fastly-Restarts
X-Times
X-Nf-Request-Id
X-Vname
X-PC
X-TtlSet
Rating
X-Clacks-Overhead
X-Cnection
X-Edge
X-Mcache
X-Midtier
X-ESI
X-Browser-Type
X-Country-Code-Real
X-FTR-Backend
X-FTR-Backend-Server
X-FTR-Balancer
X-Vcap-Request-Id
X-FTR-Cache-Status
X-FTR-Expires
Origin-Trial
Edge-Control
X-Cache-TTL
X-Element-Page-Cache
X-D2id
Surrogate-Key
X-NWS-LOG-UUID
X-FastCGI-Cache
X-Country
X-Powered-By-Plesk
X-Oneagent-Js-Injection
X-Kinja-Server
X-Kinja-Revision
X-Cdn-Fetch
X-Kinja
X-Exp-Variant
X-Exp-Id
X-Kinja-Build
X-GoogleNews-Bot
X-Ac
X-Abt-Application-Version
X-Upstream
Verso
X-Mod-Pagespeed
X-Navigation-Version
X-B3-TraceId
X-Url
X-ORACLE-DMS-RID
X-Amz-Rid
X-Pinterest-Rid
Pinterest-Generated-By
Pinterest-Version
X-Language
Nginx-Cache
Akamai-GRN
X-GitHub-Request-Id
Pagespeed
Display
X-Sol
X-Middleton-Display
X-ECACHE
X-Envoy-Decorator-Operation
S
X-PDP-UNCACHING-HASH
X-Kraken-Loop-Name
X-Instrumentation
X-Server-Lifecycle-Phase
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
Response
X-Middleton-Response
X-MS-InvokeApp
AR-Request-ID
AR-ATIME
AR-PoweredBy
Edge-Cache-Tag
X-Ratelimit-Limit
X-Goog-Hash
X-Distributor
X-Resp-Is-Stale
SPIisLatency
X-Edge-Location-Klb
X-SharePointHealthScore
X-Kinsta-Cache
SPRequestGuid
SPRequestDuration
X-Ser
X-ARC
X-NGENIX-Cache
X-Ttl
Front-End-Https
Access-Control-Request-Method
X-Dw-Request-Base-Id
X-Client-IP
X-Ruxit-Js-Agent
X-Amzn-Trace-Id
X-Content-Digest
X-Shield-Request-Id
X-Ezoic-Cdn
RTSS
X-Recruiting
X-Varnish-TTL
X-Cache-Key
Cache-Status
X-Version
X-T
X-Mg-S
TP-Cache
X-Powered-CMS
Public-Key-Pins
X-Accel-Expires
X-MSEdge-Ref
Fastcgi-Cache
X-HS-Cache-Config
X-HS-Content-Id
X-HS-Hub-Id
X-Ismobilevalue
X-Daa-Tunnel
Arr-Disable-Session-Affinity
AR-CACHE
X-Cached
Cache-Tags
Realpath
X-Cluster-Name
X-Id
X-Correlation-Id
Content-MD5
X-Content-Security-Policy-Report-Only
X-Request-Received
X-Request-Processing-Time
Ar-SID
X-Request-Device-Id
X-HS-Combine-CSS
X-Forwarded-For
YJS-ID
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Fastly-Request-ID
Payment
X-Ua-Browser
X-Newrelic-App-Data
X-DIS-Request-ID
X-Xrds-Location
X-HP-Webp
X-HP-Trace-Id
X-Jurisdiction
X-Cambria-Cache-Control
X-COUNTRY
X-RateLimit-Remaining
X-Azure-Ref
X-GUploader-UploadID
X-HS-CF-Cache-Status
X-Amz-Replication-Status
X-HS-Prerendered
X-Webkit-Csp
Content-Disposition
X-Meli-Trace-Bu
X-Meli-Trace-Platform
X-Meli-Trace-Site
X-Ratelimit-Remaining
X-Server-Name
Count-Hit
X-Ratelimit-Reset
X-Origin-Server
X-Protected-By
X-Page-Id
X-Unique-Id
X-Px
Cross-Origin-Resource-Policy
X-SRCache-Fetch-Status
Accept-Charset
X-SRCache-Store-Status
X-Activity-Id
X-AppVersion
MicrosoftSharePointTeamServices
X-FB-Debug
X-Logged-In
X-Www-Served-By
X-Az
X-Rid
X-ORACLE-DMS-ECID
X-Amz-Meta-S3cmd-Attrs
X-Git-Hash
Cleartype
X-SERVER-NAME
X-Proxy
X-Request-Handler-Origin-Region
Cross-Origin-Embedder-Policy
X-VARITI-CCR
X-Microsite
X-TTL
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Load-Cache
X-LLID
Version
X-Goog-Metageneration
X-Template
X-Geo-Country
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Forwarded-Proto
X-Varnish-Backend
X-Hits
X-CST
X-PressLabs-Stats
X-Upgrade-Enabled
Server-Node
Server-Name
X-B3-Sampled
X-WebKit-CSP-Report-Only
X-App-Server
X-Hostname
X-TT
X-Content-Options
X-Fb-Rlafr
X-Grace
X-B
Access-Control-Allow-Method
Section-Io-Cache
Viewport
X-Varnish-Grace
X-Varnish-Server
Healthy
Fastly-SWR
Fastly-SIE
Alternate-Protocol
X-Device-Type
X-Frontend
X-Status
Mrf-Cache-Status
X-B3-TraceId-Primal
MRF-Tech
X-Request-Guid
AKAMAI-GRN
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
TCN
X-Goog-Generation
X-Contextid
Upgrade-Insecure-Requests
DC
X-Magnolia-Registration
Host
X-Amzn-Remapped-Content-Length
X-EdgeConnect-Cache-Status
Retry-After
MS-Author-Via
X-Cache-Control
X-CSRF-Token
X-Requestid
Amp-Access-Control-Allow-Source-Origin
X-Cache-Age
X-App-Version
Frame-Options
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Revision
X-Buckets
X-Origin-TTL
X-Debug
X-Origin-CC
X-Varnish-Ttl
X-Original-Request-Id
X-Type
X-Response-Served-From
X-ProcessESI
X-RemovedCookies
SD-X-WS
X-UUID
X-Hl-Ver
X-Adobe-Loc
X-Akamai-Edgescape
X-Adobe-Content
X-Oracle-Dms-Ecid
X-Mobile
X-Debug-IsConnected
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-ServerID
X-Seen-By
X-G
Access-Control-Request-Headers
X-Instance
X-INCAP-ABP
X-Debug-IsPreview
X-Backend-Name
X-N
X-Rendered-As
X-NYM-Debug-Backend
X-Yottaa-Metrics
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Tumblr-User
X-Yottaa-Optimizations
X-Tumblr-Pixel-1
Cross-Origin-Embedder-Policy-Report-Only
X-Is-Bot
Cross-Origin-Opener-Policy-Report-Only
X-Cache-Status-Check
X-AB
Section-Io-Id
X-Content-Powered-By
X-Akamai-Request-ID2
X-Trace-Id
X-WP-CF-Super-Cache
X-Mg-Request-UUID
X-Framework
MS-CV
Ms-Operation-Id
X-WP-CF-Super-Cache-Cache-Control
NGB
X-RTag
X-Lambda-Id
X-Server-W
X-RM-Cache-TTL
X-Storage
X-Dc
Charset
X-Vcl-Version
Cache
Webserver
X-DataDome
Filterid
X-Yandex-Req-Id
X-B3-SpanId
X-Tec-Api-Root
X-Tec-Api-Version
X-Cache-Time
X-Tec-Api-Origin
X-ECache
Paypal-Debug-Id
X-Request-Bu
X-Request-Platform
Accept-Language
X-Request-Site
Refresh
X-URL
X-Cache-Hit
X-VC-Cache
X-HITS
X-Ms-Version
X-Fastcgi-Cache
Onion-Location
SRV
X-Ms-Request-Id
X-F-Cache
X-Time
X-Real-IP
X-Node-Name
X-Region
X-User-Agent
YJS-CacheStatus
X-CCDN-Origin-Time
X-CCDN-CacheTTL
X-Hcs-Proxy-Type
Xet-Cookie
X-Mode
X-IPS-LoggedIn
CDN-RequestId
Priority
Liferay-Portal
GEO-INFO
X-HTML-Minification-Powered-By
X-L-Path
X-LB-Cache
X-Environment-Context
X-Service
X-Pass-Why
Cross-Origin-Window-Policy
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
X-Rocket-Nginx-Serving-Static
X-Datadog-Sampled
X-Rule
X-Adobe-Source
X-Is-Supported-Browser
Country
X-UPSTREAM-Address
X-Timing-Wait
X-SaId
Meta-Geo
Backend
X-Browser-Name
Protected
X-Proxy-Build
X-Is-Mobile
X-Drupal-Cache-Tags
X-Geo-Region
X-Cache-Expired-At
X-Is-Mobile-Only
X-Is-Modern-Browser
X-Tcp-Rtt
X-Is-Tablet
X-Tb
X-Is-Desktop
X-JoinUs
Selected-Fe
X-Rn-Rsrv
X-Rewrite-Enabled
X-Wix-Request-Id
X-Whom
X-Proxy-Cache-Info
X-Httpd
X-Origin
X-BYPASS-REASON
X-Handled-By
X-Origin-Cache
X-ProxyCache-Key
X-ProxyCache-Status
X-VC
X-Generation-Time
X-Alternate-Cache-Key
X-Storefront-Renderer-Rendered
X-Web-Node
X-Shopify-Stage
OT-Force-Account-Verify
X-MP-GENERATED-AT
Mn-Server-Ip
X-Provided-By
TWC-GeoIP-City
Property-Id
X-Detected-As
X-Cacheable-TTL
TWC-GeoIP-Country
X-WP-CF-Super-Cache-Active
TWC-GeoIP-LatLong
X-Connection-Hash
X-CLOUD-TRACE-CONTEXT
TWC-GeoIP-DMA
X-Zipkin-Id
X-RateLimit-Limit-Second
X-Cloudmap
X-Tncms
Fastcgi-Useragent
Expiry
TWC-Connection-Speed
TWC-Device-Class
X-FB-TRIP-ID
Cache-Hits
X-Extlb
X-Servername
Environment
X-RateLimit-Remaining-Second
Webcakes-App-Version
Webcakes-Region
X-Proxied
X-VCT
X-Varnish-Beresp-Grace
Webcakes-App-Name
X-Routing-Service
Url
Web-Mar-Node
X-S
X-Vcache
X-RCS-CacheZone
X-Loop
ServerID
Uber-Trace-Id
X-Origin-Date
TWC-Privacy
X-Origin-Hint
TWC-Locale-Group
TWC-GeoIP-Region
X-Locale
DB-Nickname
X-Logging-Id
ServedBy
X-Cdn-Origin
X-Cms-Context
X-Skip-Cache
X-Tumblr-Pixel-2
X-Cluster
X-Soup
X-Redis-Cache
X-Format
X-Forwarded-Host
X-App-Environment
X-Auth-Group-Type
X-Tumblr-Pixel-3
X-Fetched-On
X-Hit
X-Cache-Action
Atl-Traceid
X-Director
LB
X-Hosted-By
X-Drupal-Cache-Contexts
X-Cache-Host
X-Say-Cacheable
X-SayCDN-TTL
X-Say-TTL
X-FW-Version
X-Scope-Id
X-Served-From
X-Urbn-Context-Path
X-Urbn-Site-Id
X-Restarts
Locale
X-FW-Type
X-Endurance-Cache-Level
X-Cluster-Node
X-Edge-Location
X-FW-Static
X-FW-Dynamic
X-FW-Server
X-FW-Serve
X-FW-Hash
X-Debug-Info
X-Cache-Debug
X-Labrador-Cache-Channel
X-PHP-Host
Filters
X-IPLB-Request-ID
X-IPLB-Instance
X-Server-ID
Apigw-Requestid
X-NewRelic-App-Data
X-Platform
X-R9-Blue-Green-Version
X-XRDS-Location
X-Mly-Id
Node
X-Api-Version
X-CDN-Cache-Status
AR-SID
X-GEO
Front
X-ShardId
X-CDN-Forward
X-No-Session
X-ShopId
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
Xserver
X-Tt-Logid
WPO-Cache-Status
X-Varnish-Age
X-Optimistic-Header
X-UA
X-Varnish-Cache-Hits
Countrycode
X-WP-CF-Super-Cache-Cookies-Bypass
X-Lagoon
Cache-Tv-Group
X-Varnish-Beresp-Ttl
X-Wormhole-Sdk
X-SRV
X-Fastly-Request-Id
X-Presslabs-Stats
X-Generated-By
X-B3-Traceid
X-B-Cache
X-NWS-UUID-VERIFY
X-Signature
X-CACHE-AGE
Referer-Policy
X-Client-Ip
X-Webstats-RespID
X-Azure-Ref-OriginShield
X-Site-Version
X-Ua
Request-ID
From-Origin
Cache-Provider
X-Cache-Rule
X-Cache-Operation
X-IsAdmin
X-PHP-Backend
X-Accel-Version
X-Auto-Login
X-VWS-Id
Location
X-NF-Request-ID
AMP-Access-Control-Allow-Source-Origin
X-LJ-Flow-ID
X-AWS-Id
X-Worker
X-TA-CDN-Provider
X-VC-TTL
X-Upstream-Ht
X-Tx-Id
X-Upstream-Ct
X-Content-Age
X-D
Expect-Staple
DCR-Decision-By
X-Developer
X-A-Wwc
X-Ec-Fail
X-A-Dcw
X-Aed
X-External-Request-Id
X-A-Dgt
X-Destination
Origin-Agent-Cluster
S-Rt
DCR-Processing-Time-Ms
X-Ec-GeoHdr
X-Ig-Push-State
X-Vtex-Remote-Cache
Ngx.Var.Host
N-Cache
Meta-Geo-Continent
Xc-Version
X-Cache-NE
X-Rojux
X-S-Cookie
Origin
X-ScT
MD5-Digest
X-SRCache-Key
X-Bc-Bl
X-Varnish-Hostname
X-B-Cookie
X-Vdms-Version
Fl-Custom-Application
Host-ID
Lang
X-Bl-Debug
X-BCube-Filmed-By
X-A-Dam
X-Tb-Optimization-Total-Bytes-Saved
X-Ig-Origin-Region
X-Application
X-GeoCode
X-Clientip
Source
X-A
WPO-Cache-Message
X-Conf
Candidate-Md5Url
X-Loc
Redirect-Candidate
X-PERF
Pragrma
X-A-Ccd
X-ApacheServer
Sslversion
X-Org
Rendered-Blocks
X-GeoCountry
X-Xfnlog-Site
X-Litespeed-Cache-Control
X-Aicache-OS
Wxu-Next-Region
Log-Origin
Mail-Subject
Odigeo-Trace-Id
Origin-Site
L5d-Success-Class
IsBot
Fastly-SSL
Gannett-Cam-Experience-Id
Gh-Request-Id
Ha-Gx-Prefs
Powered-By
RNT-Machine
Web-Mar-Region
Wxu-Next-Commit
Wxu-Next-Hostname
X-AK-Request-ID
We-Hiring
Time-Cloud-Cache
RNT-Time
ServerName
Store-Cloud-Cache
X-Action
X-Ee-Request-Date
X-Save-Cache
X-Rocket-Build-Number
X-SD-PageType
X-Section
X-Sigma-Backend
X-Sigma
X-Req
X-Render-Time
X-Old-Content-Length
X-Node-Id
X-Origin-Expires
X-PAYTM-SRV-ID
X-Policy
X-SIPLIST1
X-Slack-Backend
X-VG-WebCache
X-VG-TLSProxy
Country-Code
X-ND-Cache
X-Server-IP
X-Vary-Devices
X-Varnish-Director
X-Up
X-Slack-Shared-Secret-Outcome
X-V-Cache
X-Varnish-Authentication
X-Varnish-Beresp-Status
X-Mvc-Supplant-Cachable
X-Micro-Cache
X-Ee-Generated-By
X-Depends
X-Ee-Origin
X-Ee-Request-Id
X-Epic-Correlation-Id
X-CUA
X-Csrf-Jwt
X-CGP
X-Cache-Aspx
X-Cms-Device
X-Contensis-Viewer-Groups
X-Core-Value
X-Eu-Site
X-FC-Vary-Parameters
X-Hash
X-GoCache-CacheStatus
X-HS-Content-Campaign-Id
X-Internal-TTL
X-Men
X-GeoIP-Region-Code
X-GeoIP-Country-Code
X-Forwarded-Site
X-Fmm-Version
X-From
X-Gamma-Serve
X-GeoIP-City
X-Bug-Bounty
X-Access
CDN-RequestPullCode
CDN-RequestCountryCode
CDN-RequestPullSuccess
CDN-Uid
Cdnsip
Cdncip
CDN-PullZone
CDN-CachedAt
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
Apple-News-Services-Host
Apple-News-Services-Handled
CDN-Cache
Canary
CF-IPCountry
CDN-EdgeStorageId
Sid
Cmsid
Cluster
X-Cs
Cmstype
X-Sucuri-Cache
X-NGINX-Cache
X-Reqid
X-Parent-Response-Time
Content-Script-Type
X-Mvc-Supplant-OutputCached
X-Air-Pt
X-NMSegId
X-AB-Test
X-Jungle-Id
X-Acquia-Purge-Cdn-Unconfigured
X-Level-Front-Cache
X-Accel-Expires-Debug
X-Bip
X-Nyt-Route
User-Cache-Control
X-Op-Id-All
X-Origin-Time
X-Path
V-Age
Vix-Hermes-Req-Id
X-DefElseHash
X-Debug-Cache-Fetch
X-Content-Length
X-Debug-Cache-Store
X-Ion-Hop
X-Ec-Custom-Error
X-Gdpr
X-Gen-Mode
X-Proto
X-Backend-Instance
X-Frame-Option
X-Cache-Date
X-Cache-FS-Status
X-BBC-Edge-Cache-Status
X-Generated-On
X-App-Name
X-Block-Status
X-Akamai-Device-Characteristics
X-Human
X-Ion-Healthy
X-Hnp-Log
X-Amz-Storage-Class
X-Dispatcher-Server
X-HN
X-DefHash
X-FORWARDED-FOR
TDXMobile
X-Uri
X-UA-Device-Type
X-Varnish-CookieHashed-On
Machine
L
NM-Fastcgi-Cache
Nord-Request-ID
PFcat
Pics-Label
Origin-EX
Origin-CC
X-Thinkindot-L3
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
X-Wikidot-Static-Cache
X-Wikidot-Backend
X-CacheTTL
X-Fastly-Backend
Content-Style-Type
DSUID
X-We-Are-Hiring
X-Via-Fastly
X-VarnishDD-TTL
Fastly-Backend-Name
X-Viewer-Country
X-Vmg-Version
X-Thanos
X-Thinkindot-L1
X-Region-Sid
Azure-SlotName
Server-Host
Azure-Version
RewriteTestHook
CDCHOST
X-Pubstack
Azure-SiteName
Thinkindot-CacheControl-Type
Azure-InstanceId
Thinkindot-CacheControl
X-Date
Azure-RegionName
RewriteTeamHook
X-Request-URI
Cache-Contol
X-SB
X-Shield-Cache-Expires
Req-Svc-Chain
Release
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-Sn-Servicetimems
X-Proxied-Request
X-Gzip
X-DPWN-IS-SECURE
X-Location
X-Vercel-Cache
X-Moov-Xdn-Version
X-Vercel-Id
X-Esi-Check
X-ElasticPress-Query
X-Moov-Xdn-Caching-Status
X-Edge-Server
X-Moov-T
Tube-Get-Contents
C-Via
Tube-Got-Eval
Tube-Got-Results
X-B3-Trace-ID
Tube-Return
CacheControlHeader
Producers
Click-Count-Error
Fastly-GeoIP-CountryCode
Click-Count-Action-Start
Cdn-Host
Platform
X-Cache-Id
Cdn-Request-Time
X-LSADC-Cache
Mime-Version
X-Source
Fastly-Drupal-HTML
X-Origin-Response-Time
XM
X-Sucuri-ID
X-Pad
CloudFront-Viewer-Country
NGX
X-ZONE
X-Cached-By
X-Refresh
Debug
Load-Balancing
X-Varnish-Hits
Cookie
X-APP
X-Datadome
X-Servedbyhost
X-Via-Popn
GeoIp-Country-Code
X-Via-Poph
X-Debug-Service
X-Nginx-Cache-Key
GeoIP-Latitude
X-Via-Popv
True-Client-Country-4JS
X-TH-Server
Server-Ext
Product
Server-Hostname
Server-ID
X-DynaTrace-JS-Agent
X-Nananana
Sever-Int
X-AIR-PT
X-Srv
X-HA-Backend
HA-Ipaddr
X-Zone
X-Webkit-CSP
X-Litespeed-Tag
X-TT-LOGID
X-Amz-Meta-Cb-Modifiedtime
Cdn
Show-Do-Not-Sell-Link
X-Cdn-Forward
Traceparent
X-Nc
WZWS-RAY
X-GeoIP
X-Ez-Minify-Html
X-Cache-VC
X-Fpc
X-Wa
X-Cache-Backend
X-Newrelic-Synthetics
DataCenter
Edge-Cache
X-Unity-Cache
X-User
X-LB-ID
X-B3-Parentspanid
HostName
Fastly-Drupal-Html
MIME-Version
SID
Tcn
X-VCL-Version
X-Lsadc-Cache
Lb
X-Request-Start
X-LB-NoCache
Resin-Trace
Akamai-Mon-Iucid-Del
X-CDN-Provider
X-AC
Yjs-Id
X-Nginx-Cache
X-B3-Spanid
X-Vc
Xkey-La3
Sm-Log-Id
Xkeylog
X-Service-Response-Time
A
Wsr-Cache
XkeyR9
X-Scheme
X-Proxy-CacheR9
Serverhost
X-Proxy-Cache-La3
X-HOST
X-TX-ID
X-Datacenter
CountryCode
X-LiteSpeed-Tag
Cs
Surrogated-Key
NtCoent-Length
Hostname
X-Lb-Id
X-RateLimit-Limit
X-CS
X-Pool
X-LiteSpeed-Cache-Control
X-Request-Host
X-Akamai-Pragma-Client-IP
Esi-Enabled
Cdn-Requestid
CDN
X-NodeID
X-FPC
X-HubSpot-Correlation-Id
Datacenter
X-Dynatrace-Js-Agent
X-WA
Uri
X-API-Version
X-RequestId
X-ID
X-Udemy-Cache-App-Namespace
X-Vgn-Hpd-Reason
X-Fastly-Backend-Reqs
X-NC
X-VC-Age
X-Cache-Grace
X-Air-Trace-Id
X-Air-Hostname
X-Air-Source
X-TIM-N
X-Stale
X-Via-JSL
Content-Secure-Policy
X-DynaTrace
Yak-Timeinfo
Server-Id
X-Styx-Origin-Id
Proxy-Firewall
X-HA-Bot-Classification
X-HA-Device-Type
X-Html-Minification-Powered-By
Cr
Pramga
X-HA-Application-Name
X-Styx-Info
X-DataCenter
N1-Cache
X-CSRF-TOKEN
ServerHost
RATING
X-TimeS
X-Srcache-Fetch-Status
T-Server
Edge-Copy-Time
GeoIP-Country-Code
X-Srcache-Store-Status
X-Via-CDN
X-Via-Edge
X-Ez-Minify-Js
X-Via-SSL
Geoip-Latitude
X-Var-Ttl
Cloudfront-Viewer-Country
X-Swift-Error
W
X-Lb-Nocache
X-Zen-Fury
Srv
X-Varnish-Beresp-TTL
X-Geolocation
X-ServedByHost
From-Cache
X-Jobs
Req-ID
X-Ha-Backend
X-Oracle-DMS-ECID
X-Wp-Cf-Super-Cache-Cache-Control
X-Wp-Cf-Super-Cache
X-App
X-MSEdge-Features
X-MSEdge-Flight
X-Via-PopH
WP-Super-Cache
True-Client-IP
X-Via-PopN
X-CACHE-KEY
X-Via-PopV
X-Sorting-Hat-Shopid
X-Wp-Cf-Super-Cache-Active
X-Sorting-Hat-Podid
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-Shopid
X-Shardid
X-LAGOON
X-Correlation-ID
X-Proxy-Cache-LA2
Ohc-File-Size
X-ByteArk-Cache
X-VServer
X-ByteArk-ReqID
X-Key
On-Server
X-Ssense-Shipping-Surcharge-Enabled
X-Ssense-Gql
Ohc-Cache-HIT
FSS-Cache
X-Ramcache
X-Cdn-Srv
Cl-Cache
X-Elasticpress-Query
X-Webkit-Csp-Report-Only
CF-Cached-On
X-Powered-By-VTEX-Cache
Ngx
X-Geo
X-Cdn-Cache-Status
X-VTEX-Cache-Time
X-Web-Server
X-Check-Cacheable
X-VTEX-Cache-Server
X-Sucuri-Id
WebServer
X-DC
X-Fastly-Cache
X-Serial
Akamai-X-True-TTL
X-PageType
X-ATG-Version
X-Th-Server
Cf-Ipcountry
X-Iplb-Instance
X-Iplb-Request-Id
Xkey-G-Jp
X-MiniProfiler-Ids
X-Beacon
My-App
Warning
X-Limited
Host-Name
Coldstone-Viewer-Country-Region-Name
X-Fastly-Cache-Status
X-WA-Info
X-Mg-Cache
X-Env
X-Request-Url
User-Agent
Cneonction
Coldstone-Viewer-Currency
Coldstone-Viewer-Country
FSS-Proxy