Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
X-Frame-Options
Expires
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Accept-CH
CF-Cache-Status
ETag
Expect-CT
X-XSS-Protection
Accept-Ranges
Pragma
X-Powered-By
CF-RAY
X-Cache
Via
Age
Content-Security-Policy
Alt-Svc
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-Download-Options
X-Request-Id
X-Timer
CF-Ray
X-Xss-Protection
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
X-DNS-Prefetch-Control
Accept-CH-Lifetime
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
Accept-Ch
Permissions-Policy
Server-Timing
X-Drupal-Cache
X-Generator
X-Envoy-Upstream-Service-Time
X-Cache-Status
X-Cacheable
X-FRAME-OPTIONS
X-Iinfo
X-Drupal-Dynamic-Cache
Timing-Allow-Origin
X-Ua-Compatible
X-CONTENT-TYPE-OPTIONS
Feature-Policy
X-Content-Security-Policy
Xkey
Upgrade
Access-Control-Expose-Headers
X-CDN
X-XSS-PROTECTION
Content-Encoding
Status
X-AspNetMvc-Version
Access-Control-Max-Age
X-Amz-Request-Id
Host-Header
X-Amz-Id-2
X-Age
Request-Context
Cf-Edge-Cache
X-Backend
X-Robots-Tag
X-Hacker
Keep-Alive
X-Via
X-Request-ID
Cf-Apo-Via
X-Turbo-Charged-By
X-Amz-Version-Id
X-AH-Environment
X-Rq
X-Cache-Group
X-Vhost
X-Server
X-Dispatcher
X-Proxy-Cache
X-Ws-Request-Id
EagleId
CONTENT-SECURITY-POLICY
X-UA-Device
X-Varnish-Cache
Pantheon-Trace-Id
Grace
X-Litespeed-Cache
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-OneAgent-JS-Injection
X-Server-Powered-By
X-Pingback
Allow
X-Page-Speed
X-WebKit-CSP
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Swift-SaveTime
X-Swift-CacheTime
X-Dns-Prefetch-Control
Ali-Swift-Global-Savetime
X-FTR-Request-ID
X-Cache-Lookup
X-Node
X-Device
EagleEye-TraceId
X-Server-Id
X-Host
X-Country-Code
X-Backend-Server
Surrogate-Control
X-Cloud-Trace-Context
X-Readtime
X-Akam-SW-Version
Cf-Railgun
X-Ruxit-JS-Agent
X-HW
X-Response-Time
Accept-Ch-Lifetime
Cache-Tag
P3p
X-Amz-Server-Side-Encryption
Cf-Request-Id
X-LiteSpeed-Cache
X-Ua-Device
Content-Location
Cross-Origin-Opener-Policy
X-Nginx-Upstream-Cache-Status
X-Rack-Cache
X-Trace
X-Nginx-Cache-Status
Service-Worker-Allowed
Request-Id
X-TraceId
X-Application-Context
Fastly-Restarts
X-Content-Type
X-Times
Rating
X-Nf-Request-Id
X-Vname
X-PC
X-TtlSet
X-Clacks-Overhead
X-Cnection
X-Browser-Type
X-Mcache
X-Edge
X-Midtier
X-FTR-Backend-Server
X-Country-Code-Real
X-FTR-Backend
X-FTR-Balancer
X-FTR-Cache-Status
X-FTR-Expires
X-ESI
Edge-Control
X-Vcap-Request-Id
X-Cache-TTL
Origin-Trial
X-FastCGI-Cache
X-NWS-LOG-UUID
Surrogate-Key
X-Element-Page-Cache
X-Powered-By-Plesk
X-Country
X-Kinja-Server
X-Kinja
X-Abt-Application-Version
X-Cdn-Fetch
X-Exp-Variant
X-GoogleNews-Bot
X-Exp-Id
X-Kinja-Build
X-Kinja-Revision
X-D2id
X-Oneagent-Js-Injection
X-Ac
X-Upstream
Verso
X-Mod-Pagespeed
X-Url
X-ORACLE-DMS-RID
X-Navigation-Version
X-B3-TraceId
X-Amz-Rid
Akamai-GRN
X-Language
X-Pinterest-Rid
Pinterest-Generated-By
Pinterest-Version
Nginx-Cache
X-ECACHE
X-GitHub-Request-Id
Pagespeed
X-Sol
Display
X-Middleton-Display
S
X-Envoy-Decorator-Operation
X-Server-Lifecycle-Phase
X-Erf-Bev-Bev-Is-Generated
X-Kraken-Loop-Name
X-Erf-Bev-Bev
X-PDP-UNCACHING-HASH
X-Instrumentation
X-MS-InvokeApp
AR-ATIME
AR-Request-ID
Response
AR-PoweredBy
X-Middleton-Response
Edge-Cache-Tag
X-Ratelimit-Limit
X-Distributor
X-Goog-Hash
X-Kinsta-Cache
X-Resp-Is-Stale
X-Edge-Location-Klb
SPRequestGuid
X-SharePointHealthScore
SPIisLatency
SPRequestDuration
X-Ser
X-ARC
X-NGENIX-Cache
X-Client-IP
Access-Control-Request-Method
Front-End-Https
X-Ttl
X-Dw-Request-Base-Id
X-Shield-Request-Id
X-Content-Digest
X-Amzn-Trace-Id
X-Ruxit-Js-Agent
X-Ezoic-Cdn
RTSS
X-Recruiting
X-Cache-Key
X-Varnish-TTL
Cache-Status
X-Mg-S
X-Version
X-T
TP-Cache
Public-Key-Pins
X-MSEdge-Ref
Fastcgi-Cache
X-Powered-CMS
X-HS-Cache-Config
X-HS-Hub-Id
X-HS-Content-Id
X-Accel-Expires
Arr-Disable-Session-Affinity
X-Daa-Tunnel
X-Ismobilevalue
AR-CACHE
X-Cluster-Name
Realpath
X-Cached
X-Id
Cache-Tags
X-Correlation-Id
Content-MD5
X-Content-Security-Policy-Report-Only
YJS-ID
Ar-SID
X-HS-Combine-CSS
X-Forwarded-For
X-Request-Processing-Time
X-Request-Received
X-Newrelic-App-Data
X-Kong-Proxy-Latency
Payment
X-Kong-Upstream-Latency
X-Request-Device-Id
X-Fastly-Request-ID
X-DIS-Request-ID
X-Ua-Browser
X-RateLimit-Remaining
X-Xrds-Location
X-GUploader-UploadID
X-Azure-Ref
X-HS-CF-Cache-Status
X-HS-Prerendered
X-Cambria-Cache-Control
X-HP-Trace-Id
X-HP-Webp
X-Jurisdiction
X-COUNTRY
X-Amz-Replication-Status
Content-Disposition
X-Webkit-Csp
X-Server-Name
X-Ratelimit-Remaining
Count-Hit
X-Meli-Trace-Platform
X-Meli-Trace-Bu
X-Meli-Trace-Site
X-Origin-Server
Cross-Origin-Resource-Policy
X-Px
X-Page-Id
X-ORACLE-DMS-ECID
X-Unique-Id
Accept-Charset
X-Ratelimit-Reset
X-Protected-By
X-SRCache-Store-Status
X-Amz-Meta-S3cmd-Attrs
X-SRCache-Fetch-Status
MicrosoftSharePointTeamServices
X-Proxy
X-TTL
X-Logged-In
X-Activity-Id
X-FB-Debug
Cleartype
X-AppVersion
Cross-Origin-Embedder-Policy
X-Az
X-VARITI-CCR
X-Git-Hash
X-Www-Served-By
X-Rid
X-SERVER-NAME
X-Load-Cache
X-Request-Handler-Origin-Region
X-Microsite
X-Amz-Apigw-Id
X-Amzn-RequestId
X-LLID
X-Goog-Metageneration
Version
X-Template
X-Geo-Country
X-Forwarded-Proto
X-Varnish-Backend
X-TEC-API-ROOT
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-Hits
X-PressLabs-Stats
X-Upgrade-Enabled
Server-Node
X-CST
X-B3-Sampled
Server-Name
X-Hostname
X-WebKit-CSP-Report-Only
X-Content-Options
X-App-Server
X-TT
Section-Io-Cache
X-Varnish-Grace
Fastly-SIE
X-Grace
Fastly-SWR
Healthy
X-Fb-Rlafr
X-B
X-Device-Type
Access-Control-Allow-Method
X-Varnish-Server
Alternate-Protocol
Viewport
X-Request-Guid
X-Frontend
Mrf-Cache-Status
X-B3-TraceId-Primal
MRF-Tech
X-Status
X-Goog-Generation
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
TCN
X-Goog-Stored-Content-Length
Upgrade-Insecure-Requests
X-Contextid
DC
Host
X-Magnolia-Registration
X-Amzn-Remapped-Content-Length
X-Requestid
X-EdgeConnect-Cache-Status
X-Cache-Control
X-Varnish-Ttl
Retry-After
X-Cache-Age
AKAMAI-GRN
Amp-Access-Control-Allow-Source-Origin
MS-Author-Via
X-App-Version
X-CSRF-Token
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Debug
Frame-Options
X-Revision
X-Buckets
X-Type
X-Origin-TTL
X-Origin-CC
X-Response-Served-From
X-Original-Request-Id
X-ProcessESI
X-INCAP-ABP
X-RemovedCookies
X-Adobe-Content
X-Adobe-Loc
X-G
X-Backend-Name
X-NYM-Debug-Backend
X-Hl-Ver
X-Is-Bot
X-Lambda-Id
X-UUID
X-N
X-Seen-By
X-Instance
X-Yottaa-Metrics
X-Yottaa-Optimizations
VIX-Pulpo-Node
X-Rendered-As
SD-X-WS
Access-Control-Request-Headers
X-Akamai-Edgescape
VIX-Pulpo-Upstream-Status
X-Content-Powered-By
X-Debug-IsConnected
X-Oracle-Dms-Ecid
X-Cache-Status-Check
X-Akamai-Request-ID2
Cross-Origin-Embedder-Policy-Report-Only
Cross-Origin-Opener-Policy-Report-Only
Section-Io-Id
X-Mobile
X-Debug-IsPreview
X-Trace-Id
X-ServerID
MS-CV
Ms-Operation-Id
X-RTag
X-Mg-Request-UUID
X-Framework
X-RM-Cache-TTL
X-Tumblr-Pixel
X-Storage
X-Tumblr-Pixel-0
X-AB
X-Dc
X-Tumblr-User
X-Server-W
X-Tumblr-Pixel-1
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
NGB
Charset
Cache
X-Vcl-Version
X-DataDome
X-Yandex-Req-Id
X-Tec-Api-Root
X-Tec-Api-Version
Webserver
X-Tec-Api-Origin
Filterid
Accept-Language
X-Cache-Time
X-VC-Cache
SRV
Paypal-Debug-Id
X-Request-Platform
X-Request-Bu
X-B3-SpanId
X-Request-Site
X-Time
X-Ms-Version
X-Ms-Request-Id
Refresh
Onion-Location
X-URL
X-Cache-Hit
X-Real-IP
X-HITS
YJS-CacheStatus
X-ECache
X-Node-Name
X-F-Cache
X-Region
X-CCDN-Origin-Time
X-User-Agent
X-CCDN-CacheTTL
X-Hcs-Proxy-Type
CDN-RequestId
X-Environment-Context
X-L-Path
X-Mode
GEO-INFO
Liferay-Portal
Priority
X-Service
X-HTML-Minification-Powered-By
X-Fastcgi-Cache
X-Pass-Why
X-LB-Cache
Backend
X-Rocket-Nginx-Serving-Static
X-Adobe-Source
X-IPS-LoggedIn
Xet-Cookie
Country
Protected
X-Tb
Cross-Origin-Window-Policy
X-Rule
X-Datadog-Parent-Id
X-Datadog-Sampled
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
X-Is-Modern-Browser
Meta-Geo
X-Is-Mobile-Only
X-Drupal-Cache-Tags
X-Is-Supported-Browser
X-Rn-Rsrv
X-Proxy-Build
X-JoinUs
X-Proxied
X-Is-Tablet
Selected-Fe
X-Is-Mobile
X-Is-Desktop
X-Geo-Region
X-Detected-As
X-Servername
X-Cloudmap
X-SaId
X-Rewrite-Enabled
Url
X-Routing-Service
X-Browser-Name
X-Extlb
X-Cache-Expired-At
X-UPSTREAM-Address
X-Tcp-Rtt
X-Timing-Wait
X-Zipkin-Id
X-BYPASS-REASON
X-Vcache
X-Shopify-Stage
X-RCS-CacheZone
LB
X-Alternate-Cache-Key
X-Web-Node
X-Handled-By
X-Origin-Date
OT-Force-Account-Verify
X-Storefront-Renderer-Rendered
Web-Mar-Node
X-Origin
X-Origin-Cache
X-Logging-Id
X-Whom
X-Hit
X-ProxyCache-Status
X-Hosted-By
X-Httpd
X-Wix-Request-Id
X-Tncms
X-Loop
X-ProxyCache-Key
Atl-Traceid
X-Forwarded-Host
X-VC
X-Varnish-Beresp-Grace
X-Proxy-Cache-Info
X-Soup
X-Provided-By
X-Cluster
X-Format
X-Generation-Time
X-Urbn-Site-Id
X-Urbn-Context-Path
X-Director
X-Cms-Context
X-MP-GENERATED-AT
X-Cache-Action
X-Cdn-Origin
Mn-Server-Ip
Locale
X-Say-Cacheable
X-Say-TTL
X-VCT
X-SayCDN-TTL
X-Skip-Cache
TWC-Device-Class
TWC-GeoIP-Country
TWC-GeoIP-DMA
TWC-GeoIP-City
TWC-Connection-Speed
X-PHP-Host
Property-Id
X-Origin-Hint
X-S
TWC-GeoIP-LatLong
TWC-Privacy
X-Connection-Hash
X-Edge-Location
X-FB-TRIP-ID
X-Labrador-Cache-Channel
X-Cacheable-TTL
Webcakes-Region
TWC-Locale-Group
ServerID
Uber-Trace-Id
Webcakes-App-Name
TWC-GeoIP-Region
Webcakes-App-Version
Environment
Cache-Hits
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
Expiry
X-WP-CF-Super-Cache-Active
Fastcgi-Useragent
Apigw-Requestid
X-Redis-Cache
X-Fetched-On
X-Auth-Group-Type
X-App-Environment
X-Cache-Debug
X-Locale
X-Tumblr-Pixel-2
X-Tumblr-Pixel-3
ServedBy
DB-Nickname
X-FW-Hash
X-FW-Dynamic
X-Scope-Id
X-Served-From
X-Cache-Host
X-Endurance-Cache-Level
X-FW-Serve
X-Restarts
X-Cluster-Node
X-FW-Server
X-FW-Type
X-FW-Version
X-Debug-Info
X-FW-Static
Filters
X-IPLB-Request-ID
X-Drupal-Cache-Contexts
X-Server-ID
X-IPLB-Instance
X-GEO
X-NewRelic-App-Data
X-Platform
X-R9-Blue-Green-Version
Node
X-Tt-Logid
X-Mly-Id
X-CDN-Forward
X-CDN-Cache-Status
X-XRDS-Location
X-Api-Version
Front
X-B3-Traceid
Xserver
AR-SID
X-No-Session
WPO-Cache-Status
X-CLOUD-TRACE-CONTEXT
X-Optimistic-Header
X-ShardId
X-UA
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Varnish-Age
X-Varnish-Beresp-Ttl
X-ShopId
X-Varnish-Cache-Hits
X-Generated-By
Countrycode
X-WP-CF-Super-Cache-Cookies-Bypass
X-Fastly-Request-Id
Cache-Tv-Group
X-Lagoon
X-Presslabs-Stats
X-Wormhole-Sdk
X-B-Cache
X-Signature
X-SRV
X-NWS-UUID-VERIFY
X-Webstats-RespID
Referer-Policy
X-CACHE-AGE
X-Client-Ip
Cache-Provider
X-Azure-Ref-OriginShield
X-Site-Version
X-IsAdmin
From-Origin
Request-ID
X-Ua
X-Cache-Rule
X-PHP-Backend
X-LJ-Flow-ID
X-Cache-Operation
X-VWS-Id
X-AWS-Id
X-Webkit-CSP
X-Accel-Version
AMP-Access-Control-Allow-Source-Origin
X-Tx-Id
X-TA-CDN-Provider
X-Auto-Login
X-NF-Request-ID
Location
X-Worker
X-VC-TTL
S-Rt
X-Upstream-Ht
X-Upstream-Ct
CDN-PullZone
CDN-EdgeStorageId
CDN-CachedAt
CDN-RequestCountryCode
CDN-Uid
Cdnsip
Cdncip
CDN-Cache
CDN-RequestPullSuccess
CDN-RequestPullCode
X-Fmm-Version
X-Tb-Optimization-Total-Bytes-Saved
Apple-News-Services-Handled
Origin-Agent-Cluster
X-GeoCode
Source
Apple-News-Services-Host
X-Ec-GeoHdr
X-GeoCountry
X-External-Request-Id
X-Forwarded-Site
X-AK-Request-ID
Apple-News-Services-Parsed-Url
Candidate-Md5Url
DCR-Decision-By
X-Bl-Debug
X-BCube-Filmed-By
X-Bc-Bl
X-B-Cookie
Sslversion
ServerName
Redirect-Candidate
Rendered-Blocks
X-Cache-NE
X-Application
X-ApacheServer
X-A-Wwc
X-Access
X-Aed
X-A-Dgt
X-A-Dcw
X-A
X-A-Ccd
X-A-Dam
X-Conf
Pragrma
Fl-Custom-Application
Host-ID
IsBot
Lang
Fastly-SSL
Expect-Staple
DCR-Processing-Time-Ms
X-Developer
X-Destination
X-Vtex-Remote-Cache
X-D
Origin
X-Content-Age
Powered-By
Xc-Version
Ngx.Var.Host
MD5-Digest
Meta-Geo-Continent
N-Cache
X-Ec-Fail
Apple-News-Services-Request-Url
X-Slack-Backend
X-Slack-Shared-Secret-Outcome
X-SIPLIST1
X-Sigma-Backend
X-Sigma
X-Loc
X-VG-WebCache
X-PERF
X-Origin-Expires
X-VG-TLSProxy
X-Org
X-Old-Content-Length
X-SRCache-Key
X-Section
CF-IPCountry
X-Rocket-Build-Number
X-ScT
X-Rojux
WPO-Cache-Message
X-Vdms-Version
X-Varnish-Hostname
X-Varnish-Director
X-S-Cookie
X-Ig-Push-State
X-Ig-Origin-Region
X-Litespeed-Cache-Control
X-Xfnlog-Site
X-SVT-ORM-RULES
X-Content-Length
X-Depends
Origin-Site
Odigeo-Trace-Id
Origin-EX
Origin-CC
X-CUA
L
L5d-Success-Class
X-DefElseHash
X-SD-PageType
Ha-Gx-Prefs
Log-Origin
Gannett-Cam-Experience-Id
X-Csrf-Jwt
X-Sn-Servicetimems
Gh-Request-Id
Pics-Label
X-Core-Value
X-Clientip
X-Varnish-CookieHashed-On
Web-Mar-Region
X-Varnish-CookieINHashed-On
Vix-Hermes-Req-Id
X-Varnish-Beresp-Status
X-BBC-Edge-Cache-Status
User-Cache-Control
Wxu-Next-Commit
Wxu-Next-Hostname
X-Acquia-Purge-Cdn-Unconfigured
X-Action
X-Aicache-OS
X-Akamai-Device-Characteristics
X-Vary-Devices
Wxu-Next-Region
X-Varnish-Remaining-TTL
X-Varnish-Authentication
Time-Cloud-Cache
X-CGP
X-UA-Device-Type
RNT-Machine
Req-Svc-Chain
X-Save-Cache
X-Contensis-Viewer-Groups
X-Cms-Device
RNT-Time
X-Up
X-Block-Status
X-V-Cache
X-Bug-Bounty
Store-Cloud-Cache
X-Cache-Aspx
X-Uri
X-SVT-ORM-VERSION
X-DefHash
X-Fastly-Backend
X-Gamma-Serve
X-Node-Id
X-Gen-Mode
X-Mvc-Supplant-Cachable
X-From
DSUID
CDCHOST
X-Epic-Correlation-Id
Canary
X-Eu-Site
X-FC-Vary-Parameters
X-Micro-Cache
X-Men
X-Hnp-Log
X-Hash
X-HS-Content-Campaign-Id
X-Cs
X-Human
X-GoCache-CacheStatus
X-GeoIP-Region-Code
X-GeoIP-Country-Code
X-GeoIP-City
X-Internal-TTL
X-ND-Cache
X-Server-IP
X-PAYTM-SRV-ID
Sid
X-Sucuri-Cache
Country-Code
X-Ee-Generated-By
X-Ec-Custom-Error
X-Ee-Origin
X-Render-Time
X-Policy
Cluster
X-Ee-Request-Date
Cmstype
X-Req
Cmsid
X-Ee-Request-Id
X-Reqid
X-Parent-Response-Time
X-NGINX-Cache
X-Ion-Healthy
X-Date
X-Debug-Cache-Fetch
X-App-Name
X-Ion-Hop
X-Debug-Cache-Store
X-Request-URI
X-DPWN-IS-SECURE
X-SB
X-Vercel-Cache
X-Dispatcher-Server
X-HN
X-Amz-Storage-Class
X-Backend-Instance
X-Gzip
X-VarnishDD-TTL
X-Vmg-Version
X-Via-Fastly
X-Shield-Cache-Expires
X-Thinkindot-L1
X-Thanos
X-Frame-Option
X-Thinkindot-L3
X-Op-Id-All
X-Proxied-Request
X-Viewer-Country
X-Path
X-Esi-Check
X-Proto
X-Origin-Time
X-Pubstack
X-Nyt-Route
X-Mvc-Supplant-OutputCached
X-Generated-On
X-Bip
X-Level-Front-Cache
X-NMSegId
X-Gdpr
X-Region-Sid
X-Cache-Id
X-Cache-FS-Status
X-Cache-Date
X-Jungle-Id
RewriteTestHook
Machine
Mail-Subject
X-LSADC-Cache
X-Accel-Expires-Debug
Fastly-GeoIP-CountryCode
NM-Fastcgi-Cache
Nord-Request-ID
Release
C-Via
Platform
PFcat
Fastly-Backend-Name
X-CacheTTL
Click-Count-Error
Click-Count-Action-Start
Azure-Version
Cache-Contol
Azure-SlotName
Azure-SiteName
Azure-InstanceId
Azure-RegionName
Content-Style-Type
Content-Script-Type
X-Wikidot-Static-Cache
Producers
Tube-Got-Results
Tube-Got-Eval
X-Wikidot-Backend
Thinkindot-CacheControl-Type
Tube-Return
V-Age
X-AB-Test
X-Air-Pt
X-We-Are-Hiring
We-Hiring
Thinkindot-CacheControl
Tube-Get-Contents
X-FORWARDED-FOR
TDXMobile
RewriteTeamHook
Server-Host
X-Vercel-Id
Cdn-Request-Time
X-Moov-T
X-Edge-Server
Cdn-Host
X-ElasticPress-Query
Fastly-Drupal-HTML
CacheControlHeader
X-Moov-Xdn-Caching-Status
X-Moov-Xdn-Version
CloudFront-Viewer-Country
X-Origin-Response-Time
Mime-Version
X-B3-Trace-ID
X-Location
XM
X-Sucuri-ID
X-Source
NGX
X-Pad
X-Cached-By
X-ZONE
X-Varnish-Hits
X-Refresh
Debug
Load-Balancing
X-Debug-Service
GeoIP-Latitude
X-Servedbyhost
X-Via-Poph
X-APP
X-Via-Popn
X-Via-Popv
Cookie
X-Srv
X-AIR-PT
True-Client-Country-4JS
Sever-Int
X-HA-Backend
X-Nginx-Cache-Key
Server-ID
X-Datadome
Server-Ext
Server-Hostname
GeoIp-Country-Code
Show-Do-Not-Sell-Link
X-DynaTrace-JS-Agent
Product
X-Nananana
Traceparent
Cdn
X-TH-Server
HA-Ipaddr
X-Litespeed-Tag
X-TT-LOGID
X-Zone
X-Ez-Minify-Html
X-Nc
X-Fpc
X-Wa
X-Amz-Meta-Cb-Modifiedtime
X-Newrelic-Synthetics
X-GeoIP
X-Cache-Backend
WZWS-RAY
X-B3-Parentspanid
X-Cache-VC
X-Cdn-Forward
X-LB-ID
HostName
Edge-Cache
DataCenter
X-Unity-Cache
X-User
Fastly-Drupal-Html
X-B3-Spanid
X-VCL-Version
SID
X-CDN-Provider
MIME-Version
Tcn
X-Nginx-Cache
X-Lsadc-Cache
X-AC
X-Request-Start
X-LB-NoCache
Lb
Resin-Trace
Serverhost
Akamai-Mon-Iucid-Del
X-Vc
X-Proxy-Cache-La3
X-Scheme
X-Proxy-CacheR9
Xkey-La3
Xkeylog
X-Service-Response-Time
XkeyR9
Sm-Log-Id
Wsr-Cache
A
X-HOST
X-TX-ID
X-LiteSpeed-Tag
CountryCode
X-Datacenter
Yjs-Id
Cs
Surrogated-Key
NtCoent-Length
X-LiteSpeed-Cache-Control
X-CS
X-Request-Host
X-Lb-Id
X-RateLimit-Limit
Hostname
X-Pool
Esi-Enabled
X-Akamai-Pragma-Client-IP
X-Dynatrace-Js-Agent
Cdn-Requestid
X-NodeID
Uri
Datacenter
X-WA
CDN
X-HubSpot-Correlation-Id
X-RequestId
X-API-Version
X-VC-Age
X-Udemy-Cache-App-Namespace
X-Fastly-Backend-Reqs
X-FPC
X-Vgn-Hpd-Reason
X-NC
X-Cache-Grace
X-ID
X-Html-Minification-Powered-By
X-Air-Hostname
X-Air-Trace-Id
X-Air-Source
Cr
Yak-Timeinfo
X-Stale
X-Via-JSL
Server-Id
Pramga
Proxy-Firewall
Content-Secure-Policy
X-Styx-Origin-Id
X-DataCenter
X-TIM-N
X-HA-Device-Type
X-Styx-Info
X-HA-Application-Name
X-DynaTrace
X-HA-Bot-Classification
N1-Cache
X-CSRF-TOKEN
X-TimeS
RATING
W
X-Var-Ttl
ServerHost
T-Server
GeoIP-Country-Code
X-Ez-Minify-Js
Geoip-Latitude
X-Srcache-Fetch-Status
X-Srcache-Store-Status
X-Via-SSL
X-Via-Edge
X-Via-CDN
Edge-Copy-Time
X-Ha-Backend
X-ServedByHost
X-Varnish-Beresp-TTL
X-Lb-Nocache
X-Swift-Error
X-Zen-Fury
X-Jobs
X-Geolocation
Req-ID
X-Sorting-Hat-Shopid
Srv
From-Cache
X-Shardid
X-Sorting-Hat-Podid
X-Shopid
X-Wp-Cf-Super-Cache
X-Wp-Cf-Super-Cache-Cache-Control
X-Oracle-DMS-ECID
X-MSEdge-Features
X-Via-PopN
X-App
X-MSEdge-Flight
True-Client-IP
X-Via-PopH
WP-Super-Cache
X-CACHE-KEY
Cloudfront-Viewer-Country
X-Via-PopV
X-LAGOON
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-Wp-Cf-Super-Cache-Active
X-ByteArk-ReqID
X-VServer
X-Key
On-Server
X-Proxy-Cache-LA2
Ohc-Cache-HIT
Ohc-File-Size
X-Cdn-Srv
X-Ramcache
X-ByteArk-Cache
X-Ssense-Gql
FSS-Cache
X-Ssense-Shipping-Surcharge-Enabled
X-Correlation-ID
X-Web-Server
CF-Cached-On
X-VTEX-Cache-Time
X-Webkit-Csp-Report-Only
X-Cdn-Cache-Status
Cl-Cache
X-Powered-By-VTEX-Cache
X-Elasticpress-Query
X-Check-Cacheable
X-Geo
X-VTEX-Cache-Server
Ngx
X-Sucuri-Id
X-Serial
X-Fastly-Cache
X-PageType
X-DC
WebServer
X-Th-Server
Akamai-X-True-TTL
X-ATG-Version
X-Iplb-Instance
Cf-Ipcountry
X-Iplb-Request-Id
Coldstone-Viewer-Currency
Warning
My-App
X-Github-Request-Id
X-MiniProfiler-Ids
X-Limited
X-Beacon
X-Mg-Cache
Cneonction
FSS-Proxy
X-WA-Info
Coldstone-Viewer-Country-Region-Name
X-Fastly-Cache-Status
X-Request-Url
Host-Name
Xkey-G-Jp
User-Agent
Coldstone-Viewer-Country
X-Env