Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
X-Frame-Options
Expires
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Accept-CH
CF-Cache-Status
ETag
Expect-CT
X-XSS-Protection
Accept-Ranges
Pragma
X-Powered-By
CF-RAY
X-Cache
Via
Age
Content-Security-Policy
Alt-Svc
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-Download-Options
X-Request-Id
X-Timer
X-Xss-Protection
Access-Control-Allow-Headers
Access-Control-Allow-Methods
CF-Ray
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
Accept-CH-Lifetime
Content-Security-Policy-Report-Only
X-DNS-Prefetch-Control
X-AspNet-Version
X-Runtime
Accept-Ch
Permissions-Policy
Server-Timing
X-Drupal-Cache
X-Generator
X-Envoy-Upstream-Service-Time
X-Cache-Status
X-Cacheable
X-FRAME-OPTIONS
X-Iinfo
X-Drupal-Dynamic-Cache
X-Ua-Compatible
Timing-Allow-Origin
X-CONTENT-TYPE-OPTIONS
Feature-Policy
X-Content-Security-Policy
Xkey
Upgrade
Access-Control-Expose-Headers
X-CDN
X-XSS-PROTECTION
Content-Encoding
Status
X-AspNetMvc-Version
Access-Control-Max-Age
X-Amz-Request-Id
Host-Header
X-Amz-Id-2
Request-Context
X-Age
Cf-Edge-Cache
X-Backend
X-Robots-Tag
X-Hacker
Keep-Alive
X-Request-ID
X-Via
Cf-Apo-Via
X-Turbo-Charged-By
X-Amz-Version-Id
X-AH-Environment
X-Rq
X-Cache-Group
X-Vhost
X-Server
X-Dispatcher
X-Proxy-Cache
X-Ws-Request-Id
EagleId
CONTENT-SECURITY-POLICY
X-UA-Device
X-Varnish-Cache
Pantheon-Trace-Id
Grace
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-OneAgent-JS-Injection
X-Server-Powered-By
X-Litespeed-Cache
X-Pingback
Allow
X-Page-Speed
X-Dns-Prefetch-Control
X-WebKit-CSP
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-Node
X-FTR-Request-ID
X-Device
X-Cache-Lookup
EagleEye-TraceId
X-Server-Id
X-Host
X-Backend-Server
X-Country-Code
Surrogate-Control
X-Readtime
X-Cloud-Trace-Context
X-Akam-SW-Version
Cf-Railgun
X-Ruxit-JS-Agent
X-HW
X-Response-Time
Accept-Ch-Lifetime
X-LiteSpeed-Cache
X-Ua-Device
Cache-Tag
P3p
Cf-Request-Id
X-Amz-Server-Side-Encryption
Content-Location
Cross-Origin-Opener-Policy
X-Rack-Cache
X-Nginx-Upstream-Cache-Status
X-Nginx-Cache-Status
X-Trace
Service-Worker-Allowed
Request-Id
X-TraceId
X-Application-Context
Fastly-Restarts
X-Content-Type
X-Nf-Request-Id
X-Times
Rating
X-TtlSet
X-PC
X-Vname
X-Clacks-Overhead
X-Cnection
X-Midtier
X-Mcache
X-Browser-Type
X-Edge
X-ESI
X-FTR-Backend-Server
X-FTR-Backend
X-FTR-Cache-Status
X-FTR-Balancer
X-Country-Code-Real
X-FTR-Expires
X-Vcap-Request-Id
Edge-Control
X-Cache-TTL
Origin-Trial
X-FastCGI-Cache
X-NWS-LOG-UUID
Surrogate-Key
X-Element-Page-Cache
X-D2id
X-Powered-By-Plesk
X-Country
X-Cdn-Fetch
X-Oneagent-Js-Injection
X-Exp-Id
X-GoogleNews-Bot
X-Kinja-Server
X-Kinja-Revision
X-Kinja-Build
X-Exp-Variant
X-Kinja
X-Abt-Application-Version
X-Ac
Verso
X-Upstream
X-Mod-Pagespeed
X-Navigation-Version
X-Url
X-ORACLE-DMS-RID
X-B3-TraceId
Akamai-GRN
X-Amz-Rid
Pinterest-Generated-By
X-Pinterest-Rid
Pinterest-Version
X-Language
Nginx-Cache
X-ECACHE
Display
X-Middleton-Display
X-GitHub-Request-Id
X-Sol
Pagespeed
S
X-Envoy-Decorator-Operation
X-Kraken-Loop-Name
X-Erf-Bev-Bev-Is-Generated
X-Instrumentation
X-PDP-UNCACHING-HASH
X-Erf-Bev-Bev
X-Server-Lifecycle-Phase
Response
AR-PoweredBy
X-Middleton-Response
AR-Request-ID
AR-ATIME
X-MS-InvokeApp
Edge-Cache-Tag
X-Ratelimit-Limit
X-Goog-Hash
X-Distributor
X-Resp-Is-Stale
SPIisLatency
SPRequestDuration
SPRequestGuid
X-SharePointHealthScore
X-Edge-Location-Klb
X-Kinsta-Cache
X-Ttl
X-ARC
X-NGENIX-Cache
X-Ser
X-Client-IP
Access-Control-Request-Method
Front-End-Https
X-Dw-Request-Base-Id
X-Shield-Request-Id
X-Ruxit-Js-Agent
X-Amzn-Trace-Id
X-Content-Digest
X-Ezoic-Cdn
RTSS
X-Recruiting
X-Varnish-TTL
X-Cache-Key
Cache-Status
X-Version
X-T
TP-Cache
X-Mg-S
Public-Key-Pins
X-Powered-CMS
X-HS-Hub-Id
Fastcgi-Cache
X-HS-Content-Id
X-HS-Cache-Config
X-MSEdge-Ref
X-Accel-Expires
Arr-Disable-Session-Affinity
AR-CACHE
X-Daa-Tunnel
X-Ismobilevalue
Realpath
X-Cluster-Name
X-Id
Cache-Tags
X-Cached
X-Correlation-Id
Content-MD5
X-Content-Security-Policy-Report-Only
X-Webkit-Csp
Ar-SID
YJS-ID
X-Request-Processing-Time
X-Request-Received
X-Forwarded-For
X-HS-Combine-CSS
X-Request-Device-Id
Payment
X-Newrelic-App-Data
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-DIS-Request-ID
X-Fastly-Request-ID
X-Ua-Browser
X-GUploader-UploadID
X-Xrds-Location
X-Cambria-Cache-Control
X-Jurisdiction
X-HP-Trace-Id
X-HP-Webp
X-HS-CF-Cache-Status
X-Azure-Ref
X-COUNTRY
X-RateLimit-Remaining
X-HS-Prerendered
X-Amz-Replication-Status
Content-Disposition
X-Meli-Trace-Bu
X-Meli-Trace-Platform
X-Meli-Trace-Site
X-Server-Name
X-Ratelimit-Remaining
Count-Hit
Cross-Origin-Resource-Policy
X-Px
X-Origin-Server
X-Ratelimit-Reset
X-Protected-By
X-Amz-Meta-S3cmd-Attrs
X-Unique-Id
X-Logged-In
MicrosoftSharePointTeamServices
Accept-Charset
X-Page-Id
X-Az
X-AppVersion
Cleartype
X-Activity-Id
X-Proxy
X-SRCache-Store-Status
Cross-Origin-Embedder-Policy
X-SRCache-Fetch-Status
X-FB-Debug
X-Rid
X-VARITI-CCR
X-Www-Served-By
X-SERVER-NAME
X-Git-Hash
X-ORACLE-DMS-ECID
X-Request-Handler-Origin-Region
X-Microsite
X-Load-Cache
X-Amzn-RequestId
X-Amz-Apigw-Id
X-TTL
X-LLID
X-Goog-Metageneration
Version
X-Template
X-Geo-Country
X-Forwarded-Proto
X-Varnish-Backend
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-PressLabs-Stats
X-Upgrade-Enabled
X-Hits
Server-Node
X-CST
X-B3-Sampled
Server-Name
X-WebKit-CSP-Report-Only
X-Hostname
X-Content-Options
X-TT
X-App-Server
Section-Io-Cache
X-Grace
Access-Control-Allow-Method
Healthy
X-Fb-Rlafr
X-Device-Type
X-B
X-Varnish-Server
Viewport
X-Varnish-Grace
Alternate-Protocol
Fastly-SIE
Fastly-SWR
X-Frontend
Mrf-Cache-Status
MRF-Tech
X-B3-TraceId-Primal
X-Status
X-Goog-Stored-Content-Length
X-Request-Guid
X-Goog-Stored-Content-Encoding
TCN
X-Goog-Storage-Class
X-Goog-Generation
Upgrade-Insecure-Requests
X-Contextid
DC
Host
X-Magnolia-Registration
X-Requestid
AKAMAI-GRN
Retry-After
X-EdgeConnect-Cache-Status
X-Amzn-Remapped-Content-Length
MS-Author-Via
X-Cache-Age
X-CSRF-Token
X-Cache-Control
X-App-Version
Frame-Options
X-Tt-Trace-Tag
X-Tt-Trace-Host
Amp-Access-Control-Allow-Source-Origin
X-Debug
X-Type
X-Revision
X-Buckets
X-Varnish-Ttl
X-Origin-TTL
X-Origin-CC
X-Response-Served-From
X-Original-Request-Id
X-Hl-Ver
X-INCAP-ABP
X-ProcessESI
X-RemovedCookies
X-G
X-Akamai-Edgescape
X-Adobe-Content
X-Adobe-Loc
SD-X-WS
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-UUID
X-Lambda-Id
X-Debug-IsConnected
X-Cache-Status-Check
Access-Control-Request-Headers
X-Content-Powered-By
X-Debug-IsPreview
Section-Io-Id
Cross-Origin-Opener-Policy-Report-Only
Cross-Origin-Embedder-Policy-Report-Only
X-Mobile
X-NYM-Debug-Backend
X-Oracle-Dms-Ecid
X-N
X-RTag
X-Trace-Id
X-ServerID
X-Akamai-Request-ID2
X-Seen-By
Ms-Operation-Id
X-Instance
MS-CV
X-Backend-Name
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Tumblr-Pixel-0
X-Storage
X-Tumblr-Pixel
X-Tumblr-Pixel-1
X-Server-W
X-Tumblr-User
X-AB
X-Is-Bot
X-Rendered-As
X-Dc
NGB
Charset
X-Mg-Request-UUID
X-Framework
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
X-RM-Cache-TTL
Cache
X-Vcl-Version
X-Yandex-Req-Id
X-Tec-Api-Root
X-Tec-Api-Origin
X-Tec-Api-Version
Webserver
Filterid
X-DataDome
X-Cache-Time
Accept-Language
X-VC-Cache
Paypal-Debug-Id
X-Request-Bu
X-Request-Platform
X-Request-Site
SRV
X-B3-SpanId
Refresh
X-Time
Onion-Location
X-URL
X-Cache-Hit
X-ECache
X-HITS
X-Ms-Request-Id
X-Ms-Version
X-Region
X-Real-IP
YJS-CacheStatus
X-Node-Name
X-Hcs-Proxy-Type
X-CCDN-CacheTTL
CDN-RequestId
X-F-Cache
X-CCDN-Origin-Time
X-User-Agent
X-Environment-Context
X-Mode
X-L-Path
X-IPS-LoggedIn
Priority
Xet-Cookie
Liferay-Portal
X-Fastcgi-Cache
GEO-INFO
X-Service
X-HTML-Minification-Powered-By
X-Rocket-Nginx-Serving-Static
X-LB-Cache
X-CLOUD-TRACE-CONTEXT
X-Tb
X-Pass-Why
Protected
X-Drupal-Cache-Tags
Country
X-Adobe-Source
Backend
Cross-Origin-Window-Policy
X-Datadog-Sampling-Priority
X-Datadog-Trace-Id
X-Rule
X-Datadog-Sampled
X-Datadog-Parent-Id
Meta-Geo
X-Is-Mobile-Only
X-Cloudmap
X-Is-Modern-Browser
Selected-Fe
X-Is-Desktop
X-Browser-Name
X-Is-Supported-Browser
X-Is-Tablet
X-Extlb
X-Geo-Region
X-Is-Mobile
X-Cache-Expired-At
X-Proxied
X-SaId
X-JoinUs
X-Zipkin-Id
X-Timing-Wait
X-Proxy-Build
X-UPSTREAM-Address
X-Tcp-Rtt
X-Routing-Service
X-Rewrite-Enabled
X-Rn-Rsrv
X-Handled-By
X-Whom
X-Httpd
X-Hit
X-Servername
Url
X-BYPASS-REASON
X-Alternate-Cache-Key
OT-Force-Account-Verify
X-Storefront-Renderer-Rendered
X-VC
X-Varnish-Beresp-Grace
X-Shopify-Stage
X-Wix-Request-Id
X-Forwarded-Host
X-ProxyCache-Key
X-Proxy-Cache-Info
X-Origin
X-ProxyCache-Status
X-Origin-Cache
X-RCS-CacheZone
X-Web-Node
X-Generation-Time
X-Provided-By
X-VCT
Atl-Traceid
X-Cdn-Origin
X-Logging-Id
X-Cluster
X-Format
X-MP-GENERATED-AT
Mn-Server-Ip
X-Skip-Cache
TWC-Connection-Speed
TWC-Device-Class
X-Urbn-Context-Path
X-Urbn-Site-Id
X-FB-TRIP-ID
X-Cacheable-TTL
TWC-GeoIP-City
X-Edge-Location
Cache-Hits
Environment
Expiry
Fastcgi-Useragent
Locale
X-Loop
X-Connection-Hash
X-Tncms
TWC-GeoIP-Country
Property-Id
X-Detected-As
X-Origin-Date
ServerID
Webcakes-App-Name
TWC-GeoIP-DMA
Webcakes-App-Version
Webcakes-Region
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-S
Uber-Trace-Id
Web-Mar-Node
TWC-GeoIP-Region
TWC-Privacy
TWC-GeoIP-LatLong
X-WP-CF-Super-Cache-Active
X-Origin-Hint
TWC-Locale-Group
X-Vcache
X-Auth-Group-Type
LB
X-Tumblr-Pixel-2
ServedBy
X-Cache-Action
X-Locale
X-Labrador-Cache-Channel
Apigw-Requestid
X-Tumblr-Pixel-3
X-Drupal-Cache-Contexts
X-Soup
X-Redis-Cache
X-Director
X-Hosted-By
DB-Nickname
X-PHP-Host
X-Cms-Context
X-App-Environment
X-Fetched-On
X-FW-Static
X-FW-Version
X-Say-TTL
X-SayCDN-TTL
X-Scope-Id
X-Served-From
X-FW-Type
X-FW-Dynamic
X-Say-Cacheable
X-Debug-Info
X-Cluster-Node
X-Restarts
X-Cache-Host
X-FW-Serve
X-FW-Hash
X-Endurance-Cache-Level
X-FW-Server
X-Cache-Debug
Filters
X-IPLB-Instance
X-Server-ID
X-IPLB-Request-ID
X-NewRelic-App-Data
X-Platform
X-Mly-Id
X-CDN-Forward
X-R9-Blue-Green-Version
X-XRDS-Location
Node
Front
X-Api-Version
X-Tt-Logid
AR-SID
X-B3-Traceid
X-GEO
X-CDN-Cache-Status
X-No-Session
WPO-Cache-Status
X-Optimistic-Header
Xserver
X-ShopId
X-ShardId
X-Varnish-Age
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Varnish-Beresp-Ttl
X-Varnish-Cache-Hits
X-UA
Countrycode
X-Lagoon
Cache-Tv-Group
X-WP-CF-Super-Cache-Cookies-Bypass
X-Presslabs-Stats
X-Wormhole-Sdk
X-Generated-By
X-Fastly-Request-Id
X-SRV
X-B-Cache
X-Signature
X-NWS-UUID-VERIFY
Referer-Policy
X-CACHE-AGE
X-Webstats-RespID
X-Client-Ip
X-Site-Version
AMP-Access-Control-Allow-Source-Origin
X-Azure-Ref-OriginShield
X-Ua
From-Origin
X-IsAdmin
Request-ID
X-PHP-Backend
X-LJ-Flow-ID
Cache-Provider
X-Cache-Rule
X-AWS-Id
X-Cache-Operation
X-VWS-Id
X-Accel-Version
X-NF-Request-ID
Location
X-Worker
X-Auto-Login
S-Rt
X-TA-CDN-Provider
X-VC-TTL
X-Upstream-Ct
X-Upstream-Ht
X-Tx-Id
X-Tb-Optimization-Total-Bytes-Saved
X-External-Request-Id
X-Cache-NE
X-B-Cookie
CDN-Cache
CDN-CachedAt
Apple-News-Services-Request-Url
Origin-Agent-Cluster
X-Bl-Debug
X-Bc-Bl
X-ApacheServer
Apple-News-Services-Parsed-Url
X-D
Source
X-Developer
Apple-News-Services-Handled
X-Ec-Fail
X-Ec-GeoHdr
X-Aed
X-Conf
CDN-EdgeStorageId
X-Destination
WPO-Cache-Message
X-Access
X-A-Wwc
X-Clientip
Apple-News-Services-Host
X-A-Dcw
X-A-Dgt
X-Application
X-Varnish-Hostname
X-Content-Age
Candidate-Md5Url
Lang
Xc-Version
X-PERF
Origin
X-Sigma-Backend
Fl-Custom-Application
ServerName
Sslversion
X-Org
Ngx.Var.Host
Rendered-Blocks
X-A-Dam
DCR-Decision-By
DCR-Processing-Time-Ms
X-ScT
X-Vdms-Version
X-VG-TLSProxy
X-Sigma
X-Rocket-Build-Number
X-Rojux
X-S-Cookie
X-Section
Redirect-Candidate
CDN-RequestPullCode
CDN-RequestPullSuccess
X-BCube-Filmed-By
X-Vtex-Remote-Cache
CDN-RequestCountryCode
X-GeoCountry
CDN-PullZone
X-A-Ccd
X-GeoCode
CDN-Uid
X-A
X-Loc
MD5-Digest
Host-ID
Meta-Geo-Continent
N-Cache
Pragrma
Powered-By
X-Ig-Push-State
X-Ig-Origin-Region
X-Xfnlog-Site
X-Litespeed-Cache-Control
Odigeo-Trace-Id
Mail-Subject
Log-Origin
X-BBC-Edge-Cache-Status
Pics-Label
Origin-EX
Origin-CC
Origin-Site
X-AK-Request-ID
We-Hiring
Vix-Hermes-Req-Id
Web-Mar-Region
Wxu-Next-Commit
Wxu-Next-Region
Wxu-Next-Hostname
Time-Cloud-Cache
X-Acquia-Purge-Cdn-Unconfigured
X-Aicache-OS
X-Akamai-Device-Characteristics
RNT-Machine
RNT-Time
Store-Cloud-Cache
Req-Svc-Chain
X-Ee-Request-Id
X-Req
X-Render-Time
X-Save-Cache
X-SD-PageType
X-Slack-Backend
X-SIPLIST1
X-Policy
X-PAYTM-SRV-ID
X-Mvc-Supplant-Cachable
X-Micro-Cache
X-Node-Id
X-Old-Content-Length
X-Origin-Expires
X-VG-WebCache
X-Slack-Shared-Secret-Outcome
X-Sn-Servicetimems
X-Varnish-Authentication
X-V-Cache
X-Varnish-Beresp-Status
X-Varnish-CookieHashed-On
X-Varnish-Director
X-Varnish-CookieINHashed-On
X-Uri
X-Up
X-Vary-Devices
X-SRCache-Key
X-Varnish-Remaining-TTL
X-SVT-ORM-RULES
X-UA-Device-Type
X-SVT-ORM-VERSION
X-Men
X-Internal-TTL
X-DefHash
X-DefElseHash
X-Depends
X-Server-IP
X-Ee-Origin
X-Ee-Generated-By
X-CUA
X-Csrf-Jwt
X-CGP
X-Cache-Aspx
X-Cms-Device
X-Contensis-Viewer-Groups
X-Core-Value
X-Content-Length
X-Ee-Request-Date
X-Epic-Correlation-Id
X-GeoIP-Country-Code
X-GeoIP-City
X-GeoIP-Region-Code
X-GoCache-CacheStatus
X-HS-Content-Campaign-Id
X-Hash
Country-Code
X-Gamma-Serve
X-Eu-Site
X-ND-Cache
X-FC-Vary-Parameters
X-Fmm-Version
X-From
X-Forwarded-Site
X-Bug-Bounty
X-Action
X-Cs
Cdnsip
Cdncip
Fastly-SSL
Cluster
DSUID
CF-IPCountry
L5d-Success-Class
Cmstype
Cmsid
Gannett-Cam-Experience-Id
Expect-Staple
Gh-Request-Id
L
Ha-Gx-Prefs
X-Sucuri-Cache
Canary
IsBot
Sid
CDCHOST
X-Parent-Response-Time
X-Reqid
X-NGINX-Cache
X-Bip
X-Block-Status
X-Pubstack
X-Backend-Instance
X-Region-Sid
X-Thanos
X-Request-URI
X-Gen-Mode
X-Cache-Date
X-Amz-Storage-Class
X-Shield-Cache-Expires
Azure-SiteName
Azure-RegionName
X-App-Name
C-Via
Azure-SlotName
Azure-InstanceId
X-SB
X-Nyt-Route
X-Ion-Hop
X-Ion-Healthy
X-Jungle-Id
X-Level-Front-Cache
X-Ec-Custom-Error
X-Human
X-Hnp-Log
X-Generated-On
X-Gdpr
X-Frame-Option
X-FORWARDED-FOR
X-HN
X-Dispatcher-Server
X-LSADC-Cache
X-Origin-Time
X-Op-Id-All
X-Path
X-Air-Pt
X-Proto
Cache-Contol
X-NMSegId
X-Debug-Cache-Store
X-Debug-Cache-Fetch
X-Date
X-Mvc-Supplant-OutputCached
X-Cache-FS-Status
Azure-Version
Server-Host
Content-Style-Type
X-Vmg-Version
RewriteTeamHook
X-Viewer-Country
Content-Script-Type
TDXMobile
X-Vercel-Id
X-Via-Fastly
X-We-Are-Hiring
X-Wikidot-Backend
X-Fastly-Backend
Nord-Request-ID
NM-Fastcgi-Cache
Machine
PFcat
Fastly-Backend-Name
Release
X-Wikidot-Static-Cache
X-CacheTTL
Thinkindot-CacheControl
RewriteTestHook
X-VarnishDD-TTL
V-Age
User-Cache-Control
Tube-Return
X-Thinkindot-L3
Click-Count-Action-Start
X-Accel-Expires-Debug
X-AB-Test
X-Thinkindot-L1
Tube-Got-Results
Click-Count-Error
X-Vercel-Cache
Tube-Get-Contents
Thinkindot-CacheControl-Type
Tube-Got-Eval
X-Edge-Server
Platform
X-Location
X-DPWN-IS-SECURE
Cdn-Request-Time
Cdn-Host
X-Gzip
X-Esi-Check
Producers
X-ElasticPress-Query
Fastly-GeoIP-CountryCode
X-Cache-Id
CacheControlHeader
X-B3-Trace-ID
CloudFront-Viewer-Country
X-Moov-Xdn-Caching-Status
X-Moov-Xdn-Version
X-Moov-T
X-Proxied-Request
XM
X-Source
Mime-Version
NGX
X-Sucuri-ID
X-Origin-Response-Time
Fastly-Drupal-HTML
X-Pad
X-ZONE
X-Cached-By
X-Varnish-Hits
X-Refresh
Debug
Load-Balancing
X-Via-Popv
X-Servedbyhost
Cookie
X-Via-Poph
X-Via-Popn
X-Datadome
X-APP
X-Srv
X-AIR-PT
X-Nginx-Cache-Key
GeoIP-Latitude
X-Debug-Service
X-HA-Backend
Server-ID
GeoIp-Country-Code
True-Client-Country-4JS
X-TH-Server
Traceparent
X-Nananana
Cdn
X-DynaTrace-JS-Agent
Server-Hostname
Sever-Int
Product
Server-Ext
HA-Ipaddr
X-Litespeed-Tag
X-Zone
X-TT-LOGID
X-Webkit-CSP
X-Amz-Meta-Cb-Modifiedtime
X-Ez-Minify-Html
Show-Do-Not-Sell-Link
X-Fpc
X-Cache-VC
WZWS-RAY
X-B3-Parentspanid
X-Wa
X-GeoIP
X-Cache-Backend
X-Nc
X-Cdn-Forward
X-Newrelic-Synthetics
X-LB-ID
X-Unity-Cache
HostName
DataCenter
X-User
Edge-Cache
Fastly-Drupal-Html
X-B3-Spanid
Tcn
SID
MIME-Version
X-VCL-Version
X-Nginx-Cache
X-Lsadc-Cache
X-CDN-Provider
X-Request-Start
X-AC
Lb
X-LB-NoCache
Resin-Trace
Akamai-Mon-Iucid-Del
X-Vc
XkeyR9
Serverhost
X-Service-Response-Time
A
Sm-Log-Id
Xkey-La3
X-Scheme
Wsr-Cache
Xkeylog
X-Proxy-CacheR9
X-Proxy-Cache-La3
X-RateLimit-Limit
X-HOST
X-Datacenter
X-LiteSpeed-Tag
CountryCode
X-TX-ID
Yjs-Id
Cs
Surrogated-Key
X-Request-Host
X-LiteSpeed-Cache-Control
X-Pool
X-CS
NtCoent-Length
X-Lb-Id
Hostname
X-NodeID
CDN
X-Dynatrace-Js-Agent
Uri
Esi-Enabled
X-HubSpot-Correlation-Id
X-Akamai-Pragma-Client-IP
Cdn-Requestid
Datacenter
X-WA
X-API-Version
X-RequestId
X-Fastly-Backend-Reqs
X-Vgn-Hpd-Reason
X-FPC
X-NC
X-VC-Age
X-Cache-Grace
X-Udemy-Cache-App-Namespace
X-ID
X-Air-Trace-Id
X-Air-Source
X-Air-Hostname
Proxy-Firewall
X-DynaTrace
Server-Id
X-Stale
Cr
Pramga
X-Via-JSL
X-HA-Application-Name
Yak-Timeinfo
X-Styx-Info
X-DataCenter
Content-Secure-Policy
X-HA-Device-Type
X-Html-Minification-Powered-By
X-Styx-Origin-Id
X-TIM-N
X-HA-Bot-Classification
X-CSRF-TOKEN
N1-Cache
T-Server
RATING
ServerHost
Geoip-Latitude
X-Via-CDN
X-TimeS
X-Ez-Minify-Js
X-Var-Ttl
W
X-Via-SSL
GeoIP-Country-Code
X-Srcache-Fetch-Status
X-Via-Edge
Edge-Copy-Time
X-Srcache-Store-Status
X-Sorting-Hat-Podid
X-Lb-Nocache
X-Shopid
X-Geolocation
X-Jobs
From-Cache
Srv
X-Sorting-Hat-Shopid
X-ServedByHost
X-Swift-Error
X-Varnish-Beresp-TTL
X-Ha-Backend
X-Zen-Fury
X-Shardid
Req-ID
X-Wp-Cf-Super-Cache
X-Wp-Cf-Super-Cache-Cache-Control
X-Oracle-DMS-ECID
X-Via-PopV
X-MSEdge-Flight
X-CACHE-KEY
X-App
X-Via-PopH
X-MSEdge-Features
X-Via-PopN
WP-Super-Cache
True-Client-IP
Cloudfront-Viewer-Country
X-LAGOON
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-Wp-Cf-Super-Cache-Active
X-Geo
Ohc-Cache-HIT
Ohc-File-Size
X-Ramcache
X-ByteArk-Cache
On-Server
X-Ssense-Shipping-Surcharge-Enabled
X-Key
X-Proxy-Cache-LA2
X-ByteArk-ReqID
FSS-Cache
X-Ssense-Gql
X-Cdn-Srv
X-VServer
X-Correlation-ID
Cl-Cache
Ngx
X-Elasticpress-Query
X-VTEX-Cache-Server
X-Web-Server
X-Sucuri-Id
X-VTEX-Cache-Time
X-Check-Cacheable
X-Powered-By-VTEX-Cache
X-Cdn-Cache-Status
X-Webkit-Csp-Report-Only
CF-Cached-On
X-Fastly-Cache
WebServer
X-ATG-Version
X-Serial
X-Th-Server
X-PageType
Akamai-X-True-TTL
X-DC
X-Iplb-Instance
Cf-Ipcountry
X-Iplb-Request-Id
Xkey-G-Jp
Warning
X-MiniProfiler-Ids
X-Limited
X-Beacon
My-App
Coldstone-Viewer-Country
X-Fastly-Cache-Status
X-Mg-Cache
Host-Name
X-Env
FSS-Proxy
Cneonction
Coldstone-Viewer-Country-Region-Name
X-Request-Url
Coldstone-Viewer-Currency
X-WA-Info
User-Agent