Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
X-Frame-Options
Expires
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Accept-CH
Last-Modified
X-XSS-Protection
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
CF-RAY
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Alt-Svc
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-Download-Options
X-Timer
X-Request-Id
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
Cf-Request-Id
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
X-Xss-Protection
Access-Control-Allow-Credentials
CF-Ray
Accept-CH-Lifetime
Content-Security-Policy-Report-Only
X-DNS-Prefetch-Control
X-AspNet-Version
X-Runtime
Permissions-Policy
Server-Timing
X-Drupal-Cache
X-Generator
X-Envoy-Upstream-Service-Time
X-Cache-Status
X-Ua-Compatible
X-Cacheable
X-Iinfo
X-FRAME-OPTIONS
X-Drupal-Dynamic-Cache
Timing-Allow-Origin
Feature-Policy
X-Content-Security-Policy
X-CONTENT-TYPE-OPTIONS
Xkey
Upgrade
Access-Control-Expose-Headers
Content-Encoding
X-CDN
Status
X-XSS-PROTECTION
X-AspNetMvc-Version
Access-Control-Max-Age
Accept-Ch
X-Request-ID
Host-Header
X-Amz-Request-Id
X-Age
X-Amz-Id-2
Request-Context
Cf-Edge-Cache
X-Backend
X-Robots-Tag
X-Hacker
X-Via
Cf-Apo-Via
Keep-Alive
X-Turbo-Charged-By
X-Rq
X-Amz-Version-Id
X-AH-Environment
X-Cache-Group
X-Vhost
X-Dispatcher
X-Server
X-Proxy-Cache
EagleId
X-Ws-Request-Id
X-UA-Device
CONTENT-SECURITY-POLICY
X-OneAgent-JS-Injection
X-Varnish-Cache
Pantheon-Trace-Id
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
Grace
X-Server-Powered-By
X-Pingback
X-Dns-Prefetch-Control
Allow
X-Page-Speed
X-WebKit-CSP
X-Swift-CacheTime
X-Swift-SaveTime
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Litespeed-Cache
Ali-Swift-Global-Savetime
X-Node
X-FTR-Request-ID
X-Device
EagleEye-TraceId
X-Host
X-Cache-Lookup
X-Backend-Server
X-Country-Code
X-LiteSpeed-Cache
Surrogate-Control
X-Server-Id
X-Cloud-Trace-Context
X-Readtime
X-Akam-SW-Version
Cf-Railgun
X-Ruxit-JS-Agent
X-HW
X-Response-Time
Cache-Tag
X-Amz-Server-Side-Encryption
Content-Location
P3p
Cross-Origin-Opener-Policy
X-Rack-Cache
X-Nginx-Upstream-Cache-Status
X-Trace
Service-Worker-Allowed
X-Nginx-Cache-Status
Request-Id
X-TraceId
Fastly-Restarts
X-Content-Type
X-Application-Context
X-Clacks-Overhead
X-PC
X-Vname
X-Times
X-TtlSet
Rating
X-Country
X-Cnection
X-Ua-Device
X-Edge
X-ESI
X-Midtier
X-Browser-Type
X-Mcache
X-FTR-Cache-Status
X-FTR-Balancer
X-Country-Code-Real
X-Cache-TTL
X-FTR-Backend-Server
X-FTR-Backend
X-Vcap-Request-Id
X-FTR-Expires
X-Ac
Origin-Trial
Surrogate-Key
Edge-Control
Accept-Ch-Lifetime
X-Powered-By-Plesk
X-Element-Page-Cache
X-Cdn-Fetch
X-Kinja-Revision
X-Kinja-Server
X-Kinja-Build
X-Kinja
X-Exp-Id
X-GoogleNews-Bot
X-Abt-Application-Version
X-Exp-Variant
X-FastCGI-Cache
X-Nf-Request-Id
X-D2id
X-NWS-LOG-UUID
Verso
X-Upstream
X-B3-TraceId
X-ECACHE
X-ORACLE-DMS-RID
X-Mod-Pagespeed
X-Navigation-Version
X-Amz-Rid
Nginx-Cache
X-Middleton-Display
Pagespeed
Display
Pinterest-Version
X-Pinterest-Rid
X-Sol
Pinterest-Generated-By
X-GitHub-Request-Id
Akamai-GRN
X-Language
X-Envoy-Decorator-Operation
X-Middleton-Response
Response
X-PDP-UNCACHING-HASH
X-Instrumentation
X-Kraken-Loop-Name
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Server-Lifecycle-Phase
S
X-Client-IP
X-Ratelimit-Limit
AR-Request-ID
AR-PoweredBy
AR-ATIME
Edge-Cache-Tag
X-Oneagent-Js-Injection
X-MS-InvokeApp
X-Goog-Hash
X-ARC
X-Edge-Location-Klb
X-Kinsta-Cache
X-Resp-Is-Stale
X-Ser
X-Distributor
X-Url
SPIisLatency
SPRequestDuration
X-SharePointHealthScore
SPRequestGuid
X-Content-Digest
X-Cache-Key
Access-Control-Request-Method
X-NGENIX-Cache
Front-End-Https
X-Ezoic-Cdn
X-Dw-Request-Base-Id
X-Shield-Request-Id
X-Recruiting
RTSS
X-Ttl
X-Amzn-Trace-Id
X-Varnish-TTL
Cache-Status
X-Powered-CMS
X-Version
X-Ruxit-Js-Agent
Public-Key-Pins
X-Mg-S
X-T
X-MSEdge-Ref
TP-Cache
Fastcgi-Cache
X-Accel-Expires
Arr-Disable-Session-Affinity
X-HS-Content-Id
X-HS-Hub-Id
X-HS-Cache-Config
X-Daa-Tunnel
X-Forwarded-For
X-Correlation-Id
X-Ismobilevalue
Realpath
X-Fastly-Request-ID
X-Cluster-Name
Cache-Tags
X-Cached
X-Id
AR-CACHE
X-Request-Processing-Time
X-Request-Received
X-HS-Combine-CSS
X-Ua-Browser
X-Content-Security-Policy-Report-Only
Payment
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Newrelic-App-Data
Content-MD5
X-DIS-Request-ID
X-Server-Name
X-GUploader-UploadID
X-RateLimit-Remaining
X-CST
X-HP-Webp
X-HP-Trace-Id
X-HS-CF-Cache-Status
X-Jurisdiction
X-HS-Prerendered
X-Cambria-Cache-Control
Content-Disposition
X-Azure-Ref
X-Ratelimit-Remaining
X-TTL
X-Amz-Replication-Status
X-Xrds-Location
Count-Hit
X-Webkit-Csp
YJS-ID
X-Px
X-ORACLE-DMS-ECID
X-Page-Id
Cleartype
Accept-Charset
X-Unique-Id
X-Ratelimit-Reset
Cross-Origin-Embedder-Policy
X-Logged-In
X-SRCache-Store-Status
X-Origin-Server
X-SRCache-Fetch-Status
X-Rid
Cross-Origin-Resource-Policy
X-FB-Debug
X-Proxy
X-Activity-Id
X-Protected-By
X-Az
X-AppVersion
X-Git-Hash
Ar-SID
X-Www-Served-By
X-VARITI-CCR
X-SERVER-NAME
X-Request-Handler-Origin-Region
X-Microsite
X-Template
X-Goog-Metageneration
X-LLID
X-Load-Cache
MicrosoftSharePointTeamServices
X-Varnish-Backend
X-Amz-Meta-S3cmd-Attrs
X-Request-Device-Id
X-PressLabs-Stats
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-TEC-API-VERSION
Version
X-Forwarded-Proto
Server-Node
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Upgrade-Enabled
X-URL
X-Geo-Country
Server-Name
X-Hits
X-Hostname
X-COUNTRY
X-Content-Options
X-Frontend
X-B3-Sampled
Section-Io-Cache
Viewport
X-Varnish-Grace
X-TT
X-Varnish-Server
X-App-Server
X-Meli-Trace-Bu
Mrf-Cache-Status
X-Device-Type
MRF-Tech
X-Fb-Rlafr
X-Meli-Trace-Site
X-Meli-Trace-Platform
X-B3-TraceId-Primal
Alternate-Protocol
Access-Control-Allow-Method
X-B
Fastly-SIE
X-Grace
Fastly-SWR
X-Status
TCN
Healthy
X-Goog-Generation
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Request-Guid
Upgrade-Insecure-Requests
X-Magnolia-Registration
Host
X-EdgeConnect-Cache-Status
X-Server-ID
Amp-Access-Control-Allow-Source-Origin
DC
X-WebKit-CSP-Report-Only
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-CSRF-Token
X-Buckets
X-Varnish-Ttl
Retry-After
X-Amzn-Remapped-Content-Length
X-Contextid
X-Debug
X-Cache-Age
X-Cache-Control
MS-Author-Via
AKAMAI-GRN
X-NF-Request-ID
X-Revision
X-Type
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
X-Vcl-Version
X-Response-Served-From
X-Instance
X-Original-Request-Id
X-Seen-By
SD-X-WS
X-Tumblr-Pixel
X-N
X-Yottaa-Metrics
X-Hl-Ver
X-UUID
X-Tumblr-Pixel-1
Cross-Origin-Embedder-Policy-Report-Only
X-NYM-Debug-Backend
X-Adobe-Content
X-Tumblr-User
X-Adobe-Loc
X-Yottaa-Optimizations
X-ProcessESI
X-RemovedCookies
X-App-Version
X-Rendered-As
X-Is-Bot
X-Tumblr-Pixel-0
Cross-Origin-Opener-Policy-Report-Only
X-Backend-Name
X-Debug-IsConnected
X-G
X-Lambda-Id
X-Debug-IsPreview
X-Akamai-Edgescape
Section-Io-Id
Access-Control-Request-Headers
X-Storage
X-Mobile
X-Trace-Id
X-Content-Powered-By
X-Mg-Request-UUID
Charset
X-INCAP-ABP
X-ServerID
X-Framework
Frame-Options
MS-CV
Ms-Operation-Id
X-Akamai-Request-ID2
X-Origin-CC
NGB
X-Server-W
X-RTag
X-RM-Cache-TTL
X-Origin-TTL
X-DataDome
X-AB
X-Dc
X-Cache-Status-Check
X-Wormhole-Sdk
AR-SID
X-Cache-Hit
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-Oracle-Dms-Ecid
Filterid
X-Cache-Time
X-Request-Bu
Accept-Language
Cache
Refresh
X-Request-Site
X-Request-Platform
X-B3-SpanId
X-Requestid
X-Time
X-Fastcgi-Cache
X-Tec-Api-Origin
X-Tec-Api-Root
X-Tec-Api-Version
SRV
X-HITS
Webserver
X-Region
Paypal-Debug-Id
X-Real-IP
X-Node-Name
Onion-Location
Protected
X-Hcs-Proxy-Type
X-Ms-Request-Id
X-CCDN-Origin-Time
X-Ms-Version
X-CCDN-CacheTTL
CDN-RequestId
X-VC-Cache
X-User-Agent
X-F-Cache
Cross-Origin-Window-Policy
Liferay-Portal
X-LB-Cache
Priority
X-Cache-Expired-At
X-WP-CF-Super-Cache-Active
X-Pass-Why
X-HTML-Minification-Powered-By
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
X-IPS-LoggedIn
X-Whom
X-Datadog-Parent-Id
X-Datadog-Sampled
X-Rocket-Nginx-Serving-Static
Xet-Cookie
Backend
X-Mode
X-XRDS-Location
X-L-Path
GEO-INFO
X-Environment-Context
OT-Force-Account-Verify
X-Service
X-Tb
X-Yandex-Req-Id
X-Handled-By
X-Rule
X-Drupal-Cache-Tags
X-Proxy-Cache-Info
X-Extlb
X-Cloudmap
X-App-Environment
ServerID
LB
X-Detected-As
X-Is-Supported-Browser
X-Tcp-Rtt
X-Is-Tablet
X-JoinUs
X-Tncms
X-Browser-Name
X-Geo-Region
X-Is-Desktop
X-Is-Mobile
X-Cacheable-TTL
X-Adobe-Source
X-Rn-Rsrv
X-Zipkin-Id
X-Wix-Request-Id
X-Proxied
X-Rewrite-Enabled
Filters
Fastcgi-Useragent
Meta-Geo
X-Routing-Service
Url
X-Vcache
X-Loop
Country
X-SaId
X-UPSTREAM-Address
X-MP-GENERATED-AT
Web-Mar-Node
X-Servername
Expiry
X-Hosted-By
X-Redis-Cache
Atl-Traceid
X-IPLB-Instance
X-Restarts
X-IPLB-Request-ID
X-Shopify-Stage
X-Connection-Hash
X-Locale
X-Cms-Context
X-Cdn-Origin
X-Cache-Host
X-Alternate-Cache-Key
X-Director
Uber-Trace-Id
X-Logging-Id
X-Generation-Time
X-Forwarded-Host
X-Format
X-Origin-Date
ServedBy
X-Hit
X-Web-Node
TWC-Locale-Group
TWC-GeoIP-Region
X-Varnish-Beresp-Grace
TWC-Privacy
Webcakes-App-Name
Webcakes-App-Version
X-FW-Dynamic
TWC-GeoIP-LatLong
TWC-GeoIP-DMA
TWC-Connection-Speed
X-Skip-Cache
Property-Id
TWC-Device-Class
TWC-GeoIP-City
X-Origin-Hint
TWC-GeoIP-Country
X-FW-Hash
Webcakes-Region
X-FW-Version
X-Tumblr-Pixel-2
X-Storefront-Renderer-Rendered
X-FW-Type
X-Tumblr-Pixel-3
X-FW-Static
X-FW-Serve
X-FW-Server
X-Debug-Info
X-Edge-Location
X-Endurance-Cache-Level
X-RateLimit-Limit-Second
X-ProxyCache-Status
X-ProxyCache-Key
X-Cluster-Node
X-Cache-Action
X-Httpd
Mn-Server-Ip
X-BYPASS-REASON
X-Cluster
X-RateLimit-Remaining-Second
X-Say-Cacheable
X-SayCDN-TTL
X-Scope-Id
X-Soup
Environment
X-Say-TTL
Apigw-Requestid
X-Urbn-Context-Path
X-Labrador-Cache-Channel
X-Drupal-Cache-Contexts
X-FB-TRIP-ID
X-Served-From
X-Urbn-Site-Id
X-S
YJS-CacheStatus
Locale
X-PHP-Host
X-Timing-Wait
X-Auth-Group-Type
X-VC
DB-Nickname
Cache-Hits
Selected-Fe
X-Proxy-Build
X-Fetched-On
X-Origin
X-Mly-Id
X-ECache
X-Is-Modern-Browser
X-RCS-CacheZone
X-R9-Blue-Green-Version
X-VCT
X-No-Session
X-Origin-Cache
X-Sorting-Hat-PodId
X-ShopId
X-GEO
X-UA
X-Sorting-Hat-ShopId
X-Cache-Debug
X-ShardId
Front
X-SRV
X-WP-CF-Super-Cache-Cookies-Bypass
X-Varnish-Age
X-CDN-Forward
X-Varnish-Cache-Hits
X-NewRelic-App-Data
X-Provided-By
X-Is-Mobile-Only
Countrycode
Node
Xserver
X-Lagoon
X-Varnish-Beresp-Ttl
X-Platform
X-CLOUD-TRACE-CONTEXT
X-Api-Version
WPO-Cache-Status
X-Generated-By
X-CACHE-AGE
Cache-Tv-Group
X-TA-CDN-Provider
X-Source
X-Webstats-RespID
X-CDN-Cache-Status
X-Site-Version
Cache-Provider
X-Azure-Ref-OriginShield
X-Cdn
From-Origin
X-Presslabs-Stats
Referer-Policy
X-B-Cache
X-Accel-Version
X-Signature
X-B3-Traceid
X-NWS-UUID-VERIFY
X-VC-TTL
X-Tt-Logid
X-Optimistic-Header
Location
X-Tx-Id
X-PHP-Backend
X-Xfnlog-Site
X-Ua
X-Sucuri-Cache
Request-ID
X-Cache-Operation
X-Cache-Rule
CF-IPCountry
X-Worker
X-IsAdmin
CDN-RequestCountryCode
CDN-RequestPullCode
CDN-Uid
X-Reqid
CDN-RequestPullSuccess
WPO-Cache-Message
X-Tb-Optimization-Total-Bytes-Saved
CDN-CachedAt
CDN-EdgeStorageId
CDN-Cache
CDN-PullZone
AMP-Access-Control-Allow-Source-Origin
X-A-Ccd
X-B-Cookie
X-Auto-Login
X-A-Dam
X-A-Dcw
X-Application
X-A-Wwc
X-AK-Request-ID
X-ApacheServer
X-Aed
X-Action
X-A
X-Access
X-A-Dgt
Redirect-Candidate
Fastly-SSL
Expect-Staple
Fl-Custom-Application
Host-ID
Lang
DCR-Processing-Time-Ms
DCR-Decision-By
Candidate-Md5Url
Cdncip
Cdnsip
Cluster
Log-Origin
MD5-Digest
RNT-Time
RNT-Machine
Sslversion
Store-Cloud-Cache
Time-Cloud-Cache
Rendered-Blocks
X-BCube-Filmed-By
Meta-Geo-Continent
Ngx.Var.Host
Odigeo-Trace-Id
Origin
Web-Mar-Region
X-Ec-Fail
X-Save-Cache
X-S-Cookie
X-ScT
X-SD-PageType
X-Sigma
X-Section
X-Rojux
X-Rocket-Build-Number
X-PAYTM-SRV-ID
X-Origin-Expires
X-PERF
X-Req
X-Request-URI
X-Sigma-Backend
X-Slack-Backend
X-VG-WebCache
X-VG-TLSProxy
X-Viewer-Country
X-Vtex-Remote-Cache
XM
Xc-Version
X-Vdms-Version
X-Vary-Devices
X-SRCache-Key
X-Slack-Shared-Secret-Outcome
X-Varnish-Authentication
X-Varnish-Director
X-Varnish-Hostname
X-Old-Content-Length
X-Node-Id
X-Depends
X-D
X-Destination
X-Developer
X-Ec-GeoHdr
Apple-News-Services-Request-Url
X-Core-Value
X-Content-Age
X-Cache-NE
X-Cache-Aspx
X-Clientip
X-Cms-Device
X-Conf
X-Ee-Generated-By
X-Ee-Origin
X-Ig-Origin-Region
X-HS-Content-Campaign-Id
X-Ig-Push-State
X-Loc
X-Micro-Cache
X-GeoCountry
X-GeoCode
X-Ee-Request-Id
X-Ee-Request-Date
X-External-Request-Id
X-Fmm-Version
X-Forwarded-Site
X-Bl-Debug
X-Contensis-Viewer-Groups
Apple-News-Services-Handled
X-Fastly-Request-Id
X-Sucuri-ID
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
X-Frame-Option
X-Air-Pt
X-TT-LOGID
X-LSADC-Cache
X-Eu-Site
X-GeoIP-Country-Code
X-Generated-On
X-Internal-TTL
X-Epic-Correlation-Id
X-Dispatcher-Server
X-Ec-Custom-Error
X-Human
X-HN
X-GoCache-CacheStatus
X-Gdpr
X-DefHash
X-FC-Vary-Parameters
X-Fastly-Backend
X-GeoIP-Region-Code
X-Gen-Mode
X-Date
X-Amz-Storage-Class
X-App-Name
X-Backend-Instance
X-BBC-Edge-Cache-Status
X-Akamai-Device-Characteristics
X-Aicache-OS
X-AB-Test
X-Accel-Expires-Debug
X-Acquia-Purge-Cdn-Unconfigured
X-Bc-Bl
X-Block-Status
X-Ion-Healthy
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-CUA
X-Csrf-Jwt
X-Bug-Bounty
X-CGP
X-Content-Length
X-DefElseHash
X-Men
X-VarnishDD-TTL
X-Via-Fastly
X-We-Are-Hiring
IsBot
X-Varnish-Remaining-TTL
X-Varnish-CookieINHashed-On
X-Uri
X-Varnish-Beresp-Status
X-Varnish-CookieHashed-On
N-Cache
Wxu-Next-Commit
X-Org
X-SIPLIST1
X-V-Cache
X-Hash
X-GeoIP-City
Wxu-Next-Hostname
Wxu-Next-Region
X-From
X-Up
X-UA-Device-Type
X-Moov-Xdn-Version
X-Nyt-Route
X-Op-Id-All
X-Origin-Time
X-Moov-Xdn-Caching-Status
X-Moov-T
X-Jungle-Id
X-Level-Front-Cache
V-Age
X-Path
X-Policy
X-Sn-Servicetimems
X-Thinkindot-L1
X-Thinkindot-L3
X-Shield-Cache-Expires
X-SB
X-Pubstack
X-Region-Sid
X-Render-Time
X-Ion-Hop
X-Hnp-Log
Azure-SlotName
Azure-SiteName
Azure-Version
PFcat
Origin-EX
Azure-RegionName
Azure-InstanceId
Server-Host
ServerName
RewriteTestHook
RewriteTeamHook
Req-Svc-Chain
Origin-Agent-Cluster
Nord-Request-ID
User-Cache-Control
DSUID
Cmsid
Cmstype
Country-Code
Gannett-Cam-Experience-Id
CDCHOST
L5d-Success-Class
Cache-Contol
L
Ha-Gx-Prefs
Gh-Request-Id
TDXMobile
Origin-CC
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
X-LJ-Flow-ID
X-VWS-Id
X-AWS-Id
NM-Fastcgi-Cache
Mail-Subject
Tube-Got-Results
Machine
X-Gzip
CacheControlHeader
Release
X-SVT-ORM-RULES
X-Esi-Check
Tube-Get-Contents
X-Gamma-Serve
X-Cache-Date
Tube-Return
C-Via
Tube-Got-Eval
X-B3-Trace-ID
Content-Style-Type
Click-Count-Action-Start
X-Vercel-Cache
X-Vercel-Id
Click-Count-Error
X-Server-IP
X-SVT-ORM-VERSION
X-Thanos
We-Hiring
X-Proto
Cdn-Request-Time
X-Mvc-Supplant-Cachable
X-Wikidot-Static-Cache
Content-Script-Type
X-Wikidot-Backend
Cdn-Host
Fastly-Backend-Name
Fastly-GeoIP-CountryCode
Source
X-Edge-Server
Origin-Site
X-CacheTTL
Producers
X-DPWN-IS-SECURE
X-Cache-Id
X-Vmg-Version
Pragrma
X-Cache-FS-Status
X-NMSegId
X-Bip
Platform
X-Parent-Response-Time
Fastly-Drupal-HTML
X-Litespeed-Cache-Control
S-Rt
Canary
X-Location
X-Proxied-Request
X-Origin-Response-Time
X-Mvc-Supplant-OutputCached
X-ElasticPress-Query
X-ZONE
Powered-By
X-Pad
X-Upstream-Ct
X-Upstream-Ht
Debug
X-NGINX-Cache
X-Cs
Vix-Hermes-Req-Id
CloudFront-Viewer-Country
X-Cached-By
Sid
X-Refresh
Pics-Label
NGX
X-ND-Cache
X-Nananana
X-TH-Server
Product
X-Via-Popv
X-Via-Poph
X-Litespeed-Tag
X-Via-Popn
X-APP
X-Servedbyhost
Mime-Version
GeoIP-Latitude
X-HA-Backend
X-Amz-Meta-Cb-Modifiedtime
HA-Ipaddr
X-FORWARDED-FOR
Cookie
X-Varnish-Hits
Server-ID
X-Client-Ip
X-Cache-VC
X-AIR-PT
X-Datadome
MIME-Version
Edge-Cache
GeoIp-Country-Code
X-User
X-DynaTrace-JS-Agent
X-Fpc
X-Wa
X-LB-ID
X-GeoIP
X-Nc
SID
X-Nginx-Cache
X-Cdn-Forward
X-Webkit-CSP
X-Debug-Service
X-Nginx-Cache-Key
X-B3-Parentspanid
X-Srv
True-Client-Country-4JS
DataCenter
Server-Hostname
X-LB-NoCache
Sever-Int
Akamai-Mon-Iucid-Del
Load-Balancing
WZWS-RAY
Server-Ext
HostName
X-Zone
Show-Do-Not-Sell-Link
X-Unity-Cache
Surrogated-Key
Resin-Trace
Cdn
X-Request-Start
X-Scheme
Fastly-Drupal-Html
X-Cache-Backend
Traceparent
X-CS
X-LiteSpeed-Cache-Control
X-Newrelic-Synthetics
X-Vc
Tcn
X-Lsadc-Cache
X-VCL-Version
X-NodeID
X-Pool
Sm-Log-Id
X-Request-Host
X-Service-Response-Time
Wsr-Cache
Lb
X-RequestId
N1-Cache
X-B3-Spanid
X-Vgn-Hpd-Reason
Yjs-Id
X-Cache-Grace
X-LiteSpeed-Tag
X-DataCenter
NtCoent-Length
X-Datacenter
X-CDN-Provider
X-DynaTrace
X-HubSpot-Correlation-Id
X-TX-ID
Serverhost
X-API-Version
X-HOST
Yak-Timeinfo
X-Ez-Minify-Html
Xkeylog
X-Via-SSL
Xkey-La3
Hostname
X-Via-Edge
Datacenter
Edge-Copy-Time
X-Via-CDN
X-Proxy-CacheR9
X-RateLimit-Limit
X-Proxy-Cache-La3
XkeyR9
X-Udemy-Cache-App-Namespace
X-Geolocation
X-Air-Trace-Id
A
X-Zen-Fury
CDN
X-Air-Source
X-WA
X-Air-Hostname
Cdn-Requestid
X-Dynatrace-Js-Agent
CountryCode
X-Jobs
Req-ID
X-ID
X-Fastly-Backend-Reqs
X-Lb-Id
X-Akamai-Pragma-Client-IP
X-FPC
X-NC
Cs
X-Cdn-Srv
Server-Id
X-Html-Minification-Powered-By
WP-Super-Cache
True-Client-IP
Uri
Esi-Enabled
GeoIP-Country-Code
X-Via-JSL
X-Webkit-Csp-Report-Only
X-Powered-By-VTEX-Cache
X-Stale
T-Server
X-VC-Age
Geoip-Latitude
X-Srcache-Store-Status
X-VTEX-Cache-Server
X-VTEX-Cache-Time
Proxy-Firewall
X-Srcache-Fetch-Status
On-Server
RATING
X-TimeS
X-Ez-Minify-Js
ServerHost
X-Varnish-Beresp-TTL
X-MSEdge-Flight
X-Lb-Nocache
X-MSEdge-Features
X-ServedByHost
Cr
X-HA-Device-Type
X-HA-Bot-Classification
X-Styx-Info
X-Styx-Origin-Id
Srv
Pramga
X-HA-Application-Name
X-Swift-Error
From-Cache
WebServer
X-Oracle-DMS-ECID
Cloudfront-Viewer-Country
Coldstone-Viewer-Country
Coldstone-Viewer-Currency
Coldstone-Viewer-Country-Region-Name
X-WA-Info
X-TIM-N
X-CSRF-TOKEN
X-Ha-Backend
X-App
X-Var-Ttl
Content-Secure-Policy
X-Wp-Cf-Super-Cache-Cache-Control
X-LAGOON
X-Wp-Cf-Super-Cache
X-Ssense-Shipping-Surcharge-Enabled
X-Ssense-Gql
X-Fastly-Cache
Ngx
X-Correlation-ID
X-Via-PopH
W
FSS-Cache
X-Via-PopN
X-Via-PopV
X-Shardid
X-Cdn-Cache-Status
X-Check-Cacheable
X-Elasticpress-Query
X-Geo
X-Sorting-Hat-Podid
X-Shopid
X-Sorting-Hat-Shopid
X-Ramcache
Cl-Cache
BehaviorPad-Version
X-Web-Server
Akamai-X-True-TTL
X-Request-Url
X-ATG-Version
X-Proxy-Cache-LA2
X-Serial
X-Sucuri-Id
X-Wp-Cf-Super-Cache-Active
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-Th-Server
X-DC
Cf-Ipcountry
X-Env
User-Agent
Cneonction
X-Fastly-Cache-Hits
Host-Name
X-Key
Xkey-G-Jp
Bxpunish
Bxuuid
X-Nitro-Cache
My-App
X-Mg-Cache
FSS-Proxy
X-Request-Time
X-Cache-TTL-Remaining
X-Fastly-Cache-Status