Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
X-Frame-Options
Expires
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Accept-CH
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
X-XSS-Protection
X-Powered-By
Pragma
X-Cache
CF-RAY
Via
Age
Content-Security-Policy
Alt-Svc
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
X-Amz-Cf-Pop
X-Amz-Cf-Id
Content-Language
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-Download-Options
X-Request-Id
X-Xss-Protection
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
CF-Ray
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
X-DNS-Prefetch-Control
Content-Security-Policy-Report-Only
Accept-CH-Lifetime
X-AspNet-Version
Accept-Ch
X-Runtime
Permissions-Policy
X-Drupal-Cache
Server-Timing
X-Generator
X-Envoy-Upstream-Service-Time
X-Cache-Status
X-FRAME-OPTIONS
X-Cacheable
X-Iinfo
X-Ua-Compatible
X-Drupal-Dynamic-Cache
Timing-Allow-Origin
X-CONTENT-TYPE-OPTIONS
Feature-Policy
X-Content-Security-Policy
Xkey
Upgrade
X-XSS-PROTECTION
Access-Control-Expose-Headers
X-CDN
Content-Encoding
Status
X-AspNetMvc-Version
Access-Control-Max-Age
X-Amz-Request-Id
Host-Header
X-Amz-Id-2
X-Age
Request-Context
Cf-Edge-Cache
X-Backend
X-Robots-Tag
X-Hacker
Keep-Alive
X-Amz-Version-Id
X-Via
Cf-Apo-Via
X-Turbo-Charged-By
X-Rq
X-AH-Environment
X-Vhost
X-Cache-Group
X-Server
X-Dispatcher
X-Proxy-Cache
CONTENT-SECURITY-POLICY
X-Ws-Request-Id
EagleId
X-Request-ID
X-UA-Device
X-Varnish-Cache
X-Litespeed-Cache
Pantheon-Trace-Id
Grace
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Server-Powered-By
X-OneAgent-JS-Injection
X-Pingback
Allow
X-Page-Speed
X-WebKit-CSP
X-Dns-Prefetch-Control
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-FTR-Request-ID
X-Device
X-Node
X-Cache-Lookup
X-Host
X-Server-Id
EagleEye-TraceId
X-Backend-Server
X-Country-Code
Surrogate-Control
Accept-Ch-Lifetime
X-Cloud-Trace-Context
X-Ruxit-JS-Agent
X-Readtime
Cf-Railgun
X-Akam-SW-Version
X-HW
X-Response-Time
P3p
Cache-Tag
X-Amz-Server-Side-Encryption
Content-Location
X-LiteSpeed-Cache
Cross-Origin-Opener-Policy
X-Ua-Device
X-Content-Type
X-Nginx-Upstream-Cache-Status
X-Nginx-Cache-Status
X-Rack-Cache
Service-Worker-Allowed
Request-Id
X-Trace
X-TraceId
X-Application-Context
Fastly-Restarts
X-Nf-Request-Id
X-Times
X-TtlSet
X-Vname
X-PC
Rating
X-Clacks-Overhead
X-Cnection
X-Element-Page-Cache
X-D2id
X-Edge
X-Midtier
X-Mcache
X-Vcap-Request-Id
X-Country-Code-Real
X-FTR-Cache-Status
X-FTR-Backend-Server
X-FTR-Backend
X-FTR-Balancer
X-Browser-Type
X-FTR-Expires
Origin-Trial
X-ESI
Edge-Control
X-Cache-TTL
X-Oneagent-Js-Injection
X-Country
X-FastCGI-Cache
Surrogate-Key
X-NWS-LOG-UUID
X-Navigation-Version
X-Kinja-Revision
X-Kinja-Server
X-Kinja
X-Cdn-Fetch
X-GoogleNews-Bot
X-Kinja-Build
X-Exp-Variant
X-Exp-Id
X-Powered-By-Plesk
X-Abt-Application-Version
X-Ac
X-Upstream
X-Url
X-Mod-Pagespeed
Verso
X-ORACLE-DMS-RID
X-Amz-Rid
X-B3-TraceId
Akamai-GRN
X-Language
Nginx-Cache
X-Pinterest-Rid
Pinterest-Generated-By
Pinterest-Version
X-GitHub-Request-Id
Pagespeed
X-Middleton-Display
X-Sol
Display
X-ECACHE
X-Kraken-Loop-Name
X-PDP-UNCACHING-HASH
X-Instrumentation
X-Server-Lifecycle-Phase
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
S
X-Envoy-Decorator-Operation
X-MS-InvokeApp
Response
X-Middleton-Response
AR-Request-ID
AR-ATIME
AR-PoweredBy
Edge-Cache-Tag
X-Ratelimit-Limit
X-Goog-Hash
X-Distributor
SPRequestDuration
SPRequestGuid
X-SharePointHealthScore
SPIisLatency
X-Resp-Is-Stale
X-Ser
X-Edge-Location-Klb
X-Amzn-Trace-Id
X-Kinsta-Cache
X-ARC
Access-Control-Request-Method
X-NGENIX-Cache
X-Ttl
Front-End-Https
X-Client-IP
X-Dw-Request-Base-Id
X-Shield-Request-Id
X-T
X-Content-Digest
X-Ezoic-Cdn
X-Recruiting
X-Cache-Key
RTSS
Cache-Status
X-Request-Device-Id
X-Varnish-TTL
X-Ruxit-Js-Agent
X-Version
X-Mg-S
X-Powered-CMS
X-HS-Hub-Id
TP-Cache
Public-Key-Pins
X-HS-Cache-Config
X-HS-Content-Id
X-MSEdge-Ref
Fastcgi-Cache
X-Ismobilevalue
X-Accel-Expires
AR-CACHE
Arr-Disable-Session-Affinity
X-Meli-Trace-Platform
X-Meli-Trace-Bu
X-Request-Processing-Time
X-Request-Received
Cache-Tags
X-Meli-Trace-Site
X-Cached
X-Daa-Tunnel
X-Cluster-Name
X-Correlation-Id
Realpath
X-Id
Content-MD5
Ar-SID
X-Content-Security-Policy-Report-Only
YJS-ID
X-HS-Combine-CSS
X-Newrelic-App-Data
X-Amz-Replication-Status
X-Forwarded-For
Payment
X-Ua-Browser
X-Xrds-Location
X-RateLimit-Remaining
X-Kong-Upstream-Latency
X-Fastly-Request-ID
X-Kong-Proxy-Latency
X-DIS-Request-ID
X-Cambria-Cache-Control
X-Azure-Ref
X-HP-Webp
X-HP-Trace-Id
X-Jurisdiction
X-Webkit-Csp
X-HS-Prerendered
X-HS-CF-Cache-Status
X-GUploader-UploadID
X-Server-Name
Content-Disposition
X-COUNTRY
X-ORACLE-DMS-ECID
X-SRCache-Fetch-Status
X-SRCache-Store-Status
Count-Hit
X-Protected-By
X-Ratelimit-Remaining
MicrosoftSharePointTeamServices
X-Ratelimit-Reset
X-Origin-Server
X-Px
X-Unique-Id
X-Az
X-Activity-Id
X-AppVersion
X-Page-Id
X-Amzn-RequestId
X-Amz-Apigw-Id
X-TTL
X-Rid
X-Logged-In
X-TEC-API-ORIGIN
X-Git-Hash
X-Amz-Meta-S3cmd-Attrs
X-TEC-API-VERSION
Cross-Origin-Resource-Policy
X-TEC-API-ROOT
Accept-Charset
Cleartype
X-Microsite
X-FB-Debug
X-Request-Handler-Origin-Region
X-Proxy
Cross-Origin-Embedder-Policy
X-VARITI-CCR
X-Www-Served-By
X-Load-Cache
Version
X-LLID
X-Goog-Metageneration
X-SERVER-NAME
X-Forwarded-Proto
X-Geo-Country
X-PressLabs-Stats
X-Template
X-Hits
X-Varnish-Backend
X-Upgrade-Enabled
Server-Node
X-B3-Sampled
X-CST
Server-Name
X-WebKit-CSP-Report-Only
X-Hostname
X-App-Server
Healthy
X-Content-Options
Access-Control-Allow-Method
X-Frontend
X-Varnish-Grace
Viewport
Section-Io-Cache
X-TT
X-Device-Type
X-Fb-Rlafr
X-Grace
Fastly-SWR
Fastly-SIE
X-B
X-Varnish-Server
Alternate-Protocol
X-B3-TraceId-Primal
Mrf-Cache-Status
X-Request-Guid
MRF-Tech
X-Status
X-Contextid
X-Goog-Generation
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
AKAMAI-GRN
TCN
DC
Upgrade-Insecure-Requests
X-Requestid
Retry-After
X-Cache-Age
X-Magnolia-Registration
X-EdgeConnect-Cache-Status
X-Amzn-Remapped-Content-Length
Host
X-RemovedCookies
X-ProcessESI
MS-Author-Via
X-App-Version
X-Cache-Control
X-Varnish-Ttl
X-Hl-Ver
Frame-Options
X-CSRF-Token
Amp-Access-Control-Allow-Source-Origin
X-Buckets
X-Response-Served-From
X-Original-Request-Id
X-Tt-Trace-Host
X-Revision
X-Tt-Trace-Tag
X-Type
X-Debug
X-Origin-TTL
X-Origin-CC
SD-X-WS
X-Mobile
X-ServerID
X-Seen-By
X-UUID
X-INCAP-ABP
X-G
VIX-Pulpo-Upstream-Status
X-Backend-Name
VIX-Pulpo-Node
X-Instance
X-Lambda-Id
X-Tumblr-User
X-Yottaa-Metrics
X-Is-Bot
Cross-Origin-Opener-Policy-Report-Only
X-Cache-Status-Check
X-Tumblr-Pixel-1
X-Yottaa-Optimizations
X-Tumblr-Pixel
X-Adobe-Loc
X-Adobe-Content
X-Akamai-Edgescape
Cross-Origin-Embedder-Policy-Report-Only
X-Rendered-As
X-NYM-Debug-Backend
X-Tumblr-Pixel-0
X-N
X-ECache
NGB
X-WP-CF-Super-Cache
X-Akamai-Request-ID2
X-AB
Section-Io-Id
MS-CV
Access-Control-Request-Headers
X-Content-Powered-By
X-WP-CF-Super-Cache-Cache-Control
X-Trace-Id
X-RTag
Ms-Operation-Id
X-Mg-Request-UUID
X-Framework
X-Debug-IsConnected
X-Debug-IsPreview
X-RM-Cache-TTL
X-Yandex-Req-Id
X-Server-W
X-Storage
Cache
Charset
X-Vcl-Version
X-Dc
X-Oracle-Dms-Ecid
Webserver
Filterid
X-DataDome
Paypal-Debug-Id
X-B3-SpanId
Accept-Language
X-Cache-Time
Xet-Cookie
X-VC-Cache
Refresh
X-Ms-Request-Id
X-Request-Bu
X-Request-Site
X-Ms-Version
Onion-Location
X-Cache-Hit
X-Request-Platform
YJS-CacheStatus
SRV
X-Time
X-User-Agent
X-Node-Name
X-Region
X-F-Cache
X-Real-IP
X-Tec-Api-Root
X-Fastcgi-Cache
X-Tec-Api-Origin
X-Tec-Api-Version
X-CCDN-CacheTTL
X-Timing-Wait
X-Hcs-Proxy-Type
X-HITS
X-CCDN-Origin-Time
X-Proxy-Build
Priority
Selected-Fe
X-BYPASS-REASON
X-ProxyCache-Status
X-ProxyCache-Key
Liferay-Portal
X-VC
GEO-INFO
X-HTML-Minification-Powered-By
CDN-RequestId
X-L-Path
X-Mode
X-Environment-Context
X-IPS-LoggedIn
X-Cacheable-TTL
X-URL
X-Service
X-LB-Cache
X-Origin-Cache
X-Pass-Why
Backend
X-Rule
X-Datadog-Trace-Id
Cross-Origin-Window-Policy
X-Datadog-Parent-Id
X-Datadog-Sampled
X-Datadog-Sampling-Priority
X-UPSTREAM-Address
X-VCT
Country
X-Rewrite-Enabled
X-Cache-Expired-At
X-JoinUs
Meta-Geo
Apigw-Requestid
X-Rocket-Nginx-Serving-Static
X-Rn-Rsrv
X-Origin
X-SaId
X-Tb
X-Drupal-Cache-Tags
X-Is-Tablet
X-Is-Modern-Browser
X-Whom
X-Is-Mobile-Only
X-Wix-Request-Id
X-Is-Desktop
X-Adobe-Source
X-Browser-Name
X-Handled-By
X-Geo-Region
X-Is-Supported-Browser
X-Is-Mobile
X-Tcp-Rtt
Mn-Server-Ip
Protected
X-Provided-By
X-Generation-Time
X-Web-Node
Expiry
TWC-Connection-Speed
TWC-Device-Class
TWC-GeoIP-City
TWC-GeoIP-Country
Property-Id
Uber-Trace-Id
X-Httpd
X-Proxied
X-Routing-Service
X-FB-TRIP-ID
X-RateLimit-Remaining-Second
X-RCS-CacheZone
X-Servername
X-Tncms
X-Loop
X-Zipkin-Id
X-Origin-Date
X-Origin-Hint
X-Varnish-Beresp-Grace
X-Vcache
X-RateLimit-Limit-Second
X-Extlb
Url
Web-Mar-Node
TWC-Privacy
TWC-Locale-Group
TWC-GeoIP-LatLong
TWC-GeoIP-Region
Webcakes-App-Name
Webcakes-App-Version
X-Proxy-Cache-Info
X-Detected-As
X-Connection-Hash
X-Cloudmap
Webcakes-Region
TWC-GeoIP-DMA
Fastcgi-Useragent
ServerID
X-WP-CF-Super-Cache-Active
X-Server-ID
X-Hit
X-Hosted-By
X-Director
X-Format
X-Alternate-Cache-Key
X-Auth-Group-Type
X-App-Environment
X-Shopify-Stage
X-Locale
OT-Force-Account-Verify
X-Forwarded-Host
X-Redis-Cache
X-Fetched-On
X-MP-GENERATED-AT
ServedBy
X-Logging-Id
X-Mly-Id
X-Skip-Cache
DB-Nickname
X-Api-Version
X-Tumblr-Pixel-3
X-Cdn-Origin
X-Cluster
X-Cms-Context
X-Tumblr-Pixel-2
X-Cache-Action
X-Soup
X-Storefront-Renderer-Rendered
Atl-Traceid
X-Restarts
X-FW-Hash
LB
X-Debug-Info
X-FW-Dynamic
X-Cluster-Node
X-FW-Serve
X-FW-Version
X-FW-Static
X-Cache-Host
X-FW-Server
X-FW-Type
X-Say-Cacheable
Cache-Hits
X-Served-From
X-Edge-Location
Environment
Locale
X-Scope-Id
X-SayCDN-TTL
X-Cache-Debug
Front
X-Endurance-Cache-Level
X-Urbn-Site-Id
X-Say-TTL
X-Urbn-Context-Path
X-S
X-IPLB-Request-ID
X-IPLB-Instance
X-PHP-Host
Filters
X-Labrador-Cache-Channel
X-Drupal-Cache-Contexts
Node
X-CLOUD-TRACE-CONTEXT
X-Platform
X-R9-Blue-Green-Version
X-Optimistic-Header
X-Tt-Logid
X-CDN-Cache-Status
X-GEO
Countrycode
Xserver
X-Fastly-Request-Id
X-NewRelic-App-Data
X-No-Session
X-CDN-Forward
WPO-Cache-Status
X-Varnish-Age
X-Sorting-Hat-ShopId
X-ShopId
X-ShardId
X-Sorting-Hat-PodId
X-WP-CF-Super-Cache-Cookies-Bypass
X-XRDS-Location
X-B3-Traceid
X-Lagoon
X-UA
Cache-Tv-Group
X-Varnish-Cache-Hits
X-Varnish-Beresp-Ttl
X-Generated-By
AR-SID
AMP-Access-Control-Allow-Source-Origin
X-Client-Ip
X-B-Cache
X-NWS-UUID-VERIFY
X-Signature
X-SRV
Referer-Policy
X-Presslabs-Stats
Request-ID
X-Ua
X-Webstats-RespID
X-Site-Version
X-Azure-Ref-OriginShield
X-Cache-Operation
X-PHP-Backend
X-CACHE-AGE
X-Cache-Rule
X-IsAdmin
From-Origin
Expect-Staple
Cache-Provider
X-Clientip
X-SRCache-Key
X-Upstream-Ct
X-VWS-Id
X-Upstream-Ht
Location
X-Wormhole-Sdk
X-Auto-Login
X-Worker
X-AWS-Id
X-LJ-Flow-ID
X-Accel-Version
Sid
X-Bc-Bl
X-TA-CDN-Provider
X-Server-IP
Fl-Custom-Application
X-VC-TTL
X-A-Dam
X-Content-Age
Lang
WPO-Cache-Message
Rendered-Blocks
X-A-Dcw
X-Tb-Optimization-Total-Bytes-Saved
Mail-Subject
X-Conf
N-Cache
X-A
Ngx.Var.Host
Xc-Version
Meta-Geo-Continent
MD5-Digest
Host-ID
X-Vtex-Remote-Cache
X-Loc
X-ND-Cache
X-A-Ccd
X-D
X-Ec-GeoHdr
X-GeoCountry
X-Ec-Fail
X-Cache-FS-Status
X-A-Dgt
X-GeoCode
Origin-Agent-Cluster
X-External-Request-Id
S-Rt
Candidate-Md5Url
X-Developer
X-Destination
Redirect-Candidate
X-Bl-Debug
X-Ig-Origin-Region
X-Ig-Push-State
Origin
X-Cache-NE
CloudFront-Viewer-Country
Source
DCR-Decision-By
DCR-Processing-Time-Ms
Pragrma
X-BCube-Filmed-By
X-ScT
X-PERF
X-Tx-Id
X-Vdms-Version
X-A-Wwc
We-Hiring
Sslversion
X-Org
X-Rojux
X-ApacheServer
X-B-Cookie
X-S-Cookie
X-Aed
X-Application
X-Xfnlog-Site
X-Litespeed-Cache-Control
Cluster
X-Aicache-OS
X-Req
Cdncip
CDN-Uid
Cdnsip
CDN-RequestPullCode
X-Ee-Request-Date
CDN-Cache
X-Ee-Request-Id
X-Action
X-Epic-Correlation-Id
Canary
CDN-CachedAt
CDN-EdgeStorageId
CDN-RequestCountryCode
Country-Code
X-Ee-Generated-By
CDN-PullZone
X-Ee-Origin
CDN-RequestPullSuccess
X-CacheTTL
L5d-Success-Class
Log-Origin
IsBot
Odigeo-Trace-Id
X-SD-PageType
X-Contensis-Viewer-Groups
X-Slack-Shared-Secret-Outcome
X-Sigma
X-Cms-Device
X-Sigma-Backend
X-SIPLIST1
X-Slack-Backend
X-Core-Value
Ha-Gx-Prefs
X-Save-Cache
Time-Cloud-Cache
X-Eu-Site
Origin-Site
X-Rocket-Build-Number
X-CGP
Fastly-SSL
X-Csrf-Jwt
Gh-Request-Id
X-CUA
Gannett-Cam-Experience-Id
X-AK-Request-ID
X-Depends
X-Forwarded-Site
X-Varnish-Hostname
X-Varnish-Director
X-Internal-TTL
Wxu-Next-Commit
X-Origin-Expires
X-HS-Content-Campaign-Id
X-Hash
X-Varnish-Authentication
X-Varnish-Beresp-Status
Web-Mar-Region
X-GoCache-CacheStatus
X-Section
X-Cs
Wxu-Next-Hostname
X-Old-Content-Length
RNT-Time
Wxu-Next-Region
RNT-Machine
X-Mvc-Supplant-Cachable
X-Vary-Devices
X-VG-TLSProxy
X-VG-WebCache
X-Micro-Cache
X-GeoIP-Country-Code
X-GeoIP-Region-Code
Apple-News-Services-Handled
Apple-News-Services-Host
X-From
X-Gamma-Serve
X-V-Cache
Powered-By
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
X-FC-Vary-Parameters
X-Fastly-Backend
X-Fmm-Version
X-Node-Id
X-Cache-Aspx
X-FORWARDED-FOR
Store-Cloud-Cache
X-Access
X-PAYTM-SRV-ID
X-Policy
ServerName
X-GeoIP-City
X-Bug-Bounty
CF-IPCountry
X-Parent-Response-Time
X-Sucuri-Cache
X-Acquia-Purge-Cdn-Unconfigured
X-App-Name
X-Amz-Storage-Class
X-Cache-Date
X-AB-Test
X-Bip
X-Backend-Instance
X-Accel-Expires-Debug
X-Akamai-Device-Characteristics
X-BBC-Edge-Cache-Status
X-Block-Status
X-NMSegId
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-Thanos
X-Thinkindot-L1
X-Thinkindot-L3
X-Sn-Servicetimems
X-Shield-Cache-Expires
X-Render-Time
X-Region-Sid
X-Reqid
X-Request-URI
X-SB
X-UA-Device-Type
X-Up
X-Vmg-Version
X-Viewer-Country
X-We-Are-Hiring
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-Via-Fastly
X-VarnishDD-TTL
X-Uri
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
X-Pubstack
X-Proto
X-Frame-Option
X-Ec-Custom-Error
X-Gdpr
X-Gen-Mode
X-Generated-On
X-Dispatcher-Server
X-DefHash
X-Date
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-DefElseHash
X-HN
X-Hnp-Log
X-Nyt-Route
X-Mvc-Supplant-OutputCached
X-Op-Id-All
X-Origin-Time
X-Path
X-Men
X-Level-Front-Cache
X-Human
X-Ion-Healthy
X-Ion-Hop
X-Jungle-Id
X-Content-Length
TDXMobile
Machine
L
Fastly-Backend-Name
DSUID
NM-Fastcgi-Cache
Nord-Request-ID
Pics-Label
PFcat
Origin-EX
Origin-CC
Content-Style-Type
Content-Script-Type
Azure-RegionName
Azure-InstanceId
X-LSADC-Cache
X-NGINX-Cache
Azure-SiteName
Azure-Version
Cmstype
Cmsid
CDCHOST
Cache-Contol
Release
Azure-SlotName
Server-Host
V-Age
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
RewriteTestHook
User-Cache-Control
Req-Svc-Chain
Vix-Hermes-Req-Id
RewriteTeamHook
Cdn-Host
Tube-Got-Eval
CacheControlHeader
Cdn-Request-Time
Click-Count-Action-Start
X-DPWN-IS-SECURE
Tube-Get-Contents
Click-Count-Error
X-Esi-Check
X-Edge-Server
X-Location
X-Moov-Xdn-Caching-Status
X-Moov-T
X-Vercel-Id
X-Vercel-Cache
X-Moov-Xdn-Version
X-Gzip
C-Via
Tube-Return
X-Proxied-Request
Mime-Version
Tube-Got-Results
X-ElasticPress-Query
Fastly-GeoIP-CountryCode
X-B3-Trace-ID
Platform
Producers
X-Cache-Id
X-Air-Pt
X-ZONE
X-Origin-Response-Time
Load-Balancing
XM
Fastly-Drupal-HTML
X-Pad
X-Cached-By
X-Sucuri-ID
NGX
X-NF-Request-ID
X-Source
X-Varnish-Hits
Cookie
Debug
X-Refresh
X-Via-Popn
X-Via-Popv
X-Via-Poph
X-Debug-Service
X-APP
X-Nginx-Cache-Key
X-Datadome
True-Client-Country-4JS
X-HA-Backend
Sever-Int
X-Srv
GeoIp-Country-Code
GeoIP-Latitude
X-AIR-PT
Server-Hostname
X-Servedbyhost
X-DynaTrace-JS-Agent
Server-Ext
X-Webkit-CSP
HA-Ipaddr
Product
X-Nananana
Server-ID
X-TH-Server
Show-Do-Not-Sell-Link
Traceparent
X-Cdn-Forward
X-Litespeed-Tag
X-Ez-Minify-Html
Cdn
WZWS-RAY
X-Cache-Backend
X-Zone
X-Amz-Meta-Cb-Modifiedtime
X-Nc
X-TT-LOGID
X-GeoIP
HostName
DataCenter
X-B3-Parentspanid
X-Fpc
X-Unity-Cache
X-Cache-VC
X-LB-ID
X-Wa
Fastly-Drupal-Html
X-User
Edge-Cache
X-Newrelic-Synthetics
Tcn
X-VCL-Version
X-CDN-Provider
X-AC
Lb
X-B3-Spanid
MIME-Version
X-Nginx-Cache
SID
X-Proxy-CacheR9
Xkey-La3
X-Request-Start
X-Lsadc-Cache
A
Serverhost
Akamai-Mon-Iucid-Del
X-Proxy-Cache-La3
Resin-Trace
Xkeylog
X-LB-NoCache
XkeyR9
Yjs-Id
X-Vc
CountryCode
Wsr-Cache
X-Datacenter
X-Service-Response-Time
X-LiteSpeed-Tag
X-Scheme
X-TX-ID
Sm-Log-Id
Cs
X-RateLimit-Limit
NtCoent-Length
X-LiteSpeed-Cache-Control
Uri
X-WA
X-Pool
Hostname
Cdn-Requestid
X-Request-Host
X-Lb-Id
CDN
Esi-Enabled
Surrogated-Key
X-API-Version
X-CS
X-HubSpot-Correlation-Id
X-Aspnet-Version
X-ID
X-VC-Age
X-NodeID
Datacenter
X-Fastly-Backend-Reqs
X-Dynatrace-Js-Agent
X-FPC
X-NC
X-Udemy-Cache-App-Namespace
X-Akamai-Pragma-Client-IP
X-RequestId
Cr
Server-Id
X-Html-Minification-Powered-By
Pramga
X-Stale
X-Via-JSL
Proxy-Firewall
X-Cache-Grace
X-Vgn-Hpd-Reason
X-TIM-N
Content-Secure-Policy
X-Styx-Origin-Id
X-HA-Device-Type
X-Styx-Info
X-HA-Application-Name
X-HA-Bot-Classification
X-CSRF-TOKEN
X-Air-Trace-Id
X-Air-Source
X-Air-Hostname
T-Server
X-Srcache-Store-Status
X-DataCenter
GeoIP-Country-Code
ServerHost
X-Ez-Minify-Js
X-Srcache-Fetch-Status
X-Var-Ttl
Yak-Timeinfo
X-DynaTrace
Geoip-Latitude
X-TimeS
RATING
X-Varnish-Beresp-TTL
N1-Cache
X-Via-SSL
Edge-Copy-Time
X-Lb-Nocache
W
X-Via-Edge
Srv
From-Cache
X-Ha-Backend
X-ServedByHost
X-Via-CDN
X-Aspnetmvc-Version
X-Oracle-DMS-ECID
X-Wp-Cf-Super-Cache
X-Wp-Cf-Super-Cache-Cache-Control
X-MSEdge-Flight
Cloudfront-Viewer-Country
X-Via-PopV
X-MSEdge-Features
X-Via-PopN
X-Via-PopH
X-CACHE-KEY
X-Jobs
X-Zen-Fury
X-Swift-Error
X-App
Req-ID
X-Geolocation
X-Sorting-Hat-Shopid
X-Shardid
X-Shopid
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-LAGOON
X-Wp-Cf-Super-Cache-Active
X-Sorting-Hat-Podid
WP-Super-Cache
FSS-Cache
X-Correlation-ID
True-Client-IP
X-Ramcache
Expect-Ct
Ohc-Cache-HIT
X-Key
X-Proxy-Cache-LA2
X-VServer
X-ByteArk-Cache
X-Ssense-Gql
X-ByteArk-ReqID
X-Ssense-Shipping-Surcharge-Enabled
Ohc-File-Size
X-Geo
X-Elasticpress-Query
Ngx
X-Cdn-Cache-Status
X-Cdn-Srv
X-Web-Server
CF-Cached-On
X-Sucuri-Id
On-Server
X-Webkit-Csp-Report-Only
X-Check-Cacheable
Cl-Cache
X-PageType
X-DC
X-Powered-By-VTEX-Cache
X-VTEX-Cache-Time
WebServer
X-ATG-Version
X-VTEX-Cache-Server
X-Serial
X-Th-Server
Akamai-X-True-TTL
X-Iplb-Request-Id
X-Iplb-Instance
Cf-Ipcountry
Warning
My-App
X-Beacon
X-NODE
X-MiniProfiler-Ids
X-Limited
X-Mg-Cache
Host-Name
User-Agent
X-Request-Url
Cneonction
FSS-Proxy
X-Env
Xkey-G-Jp
X-Fastly-Cache
X-Fastly-Cache-Status