Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
X-Frame-Options
Expires
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Accept-CH
CF-Cache-Status
ETag
X-XSS-Protection
Expect-CT
Accept-Ranges
Pragma
X-Powered-By
CF-RAY
X-Cache
Via
Age
Content-Security-Policy
Alt-Svc
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-Download-Options
X-Request-Id
X-Timer
X-Xss-Protection
Access-Control-Allow-Headers
Access-Control-Allow-Methods
CF-Ray
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
Accept-CH-Lifetime
Content-Security-Policy-Report-Only
X-DNS-Prefetch-Control
X-AspNet-Version
X-Runtime
Accept-Ch
Permissions-Policy
Server-Timing
X-Drupal-Cache
X-Generator
X-Envoy-Upstream-Service-Time
X-Cache-Status
X-Cacheable
X-FRAME-OPTIONS
X-Iinfo
X-Drupal-Dynamic-Cache
X-Ua-Compatible
Timing-Allow-Origin
X-CONTENT-TYPE-OPTIONS
Feature-Policy
X-Content-Security-Policy
Xkey
Upgrade
Access-Control-Expose-Headers
X-CDN
X-XSS-PROTECTION
Content-Encoding
Status
X-AspNetMvc-Version
Access-Control-Max-Age
X-Amz-Request-Id
Host-Header
X-Amz-Id-2
X-Age
Request-Context
Cf-Edge-Cache
X-Backend
X-Robots-Tag
X-Hacker
Keep-Alive
X-Request-ID
X-Via
Cf-Apo-Via
X-Amz-Version-Id
X-Turbo-Charged-By
X-AH-Environment
X-Rq
X-Cache-Group
X-Vhost
X-Server
X-Dispatcher
X-Proxy-Cache
X-Ws-Request-Id
EagleId
CONTENT-SECURITY-POLICY
X-UA-Device
X-Varnish-Cache
Pantheon-Trace-Id
Grace
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-OneAgent-JS-Injection
X-Server-Powered-By
X-Litespeed-Cache
X-Pingback
Allow
X-Page-Speed
X-Dns-Prefetch-Control
X-WebKit-CSP
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-Node
X-FTR-Request-ID
X-Device
X-Cache-Lookup
EagleEye-TraceId
X-Server-Id
X-Host
X-Backend-Server
X-Country-Code
Surrogate-Control
X-Readtime
X-Cloud-Trace-Context
X-Akam-SW-Version
Cf-Railgun
X-Ruxit-JS-Agent
X-HW
X-Response-Time
Accept-Ch-Lifetime
X-LiteSpeed-Cache
X-Ua-Device
Cache-Tag
P3p
Cf-Request-Id
X-Amz-Server-Side-Encryption
Content-Location
Cross-Origin-Opener-Policy
X-Rack-Cache
X-Nginx-Upstream-Cache-Status
X-Nginx-Cache-Status
X-Trace
Service-Worker-Allowed
Request-Id
X-TraceId
X-Application-Context
Fastly-Restarts
X-Content-Type
X-Nf-Request-Id
X-Times
Rating
X-TtlSet
X-PC
X-Vname
X-Clacks-Overhead
X-Cnection
X-Midtier
X-Mcache
X-Browser-Type
X-Edge
X-ESI
X-FTR-Backend-Server
X-FTR-Backend
X-FTR-Cache-Status
X-FTR-Balancer
X-Country-Code-Real
X-FTR-Expires
X-Vcap-Request-Id
Edge-Control
X-Cache-TTL
Origin-Trial
X-FastCGI-Cache
X-Element-Page-Cache
Surrogate-Key
X-NWS-LOG-UUID
X-D2id
X-Powered-By-Plesk
X-Country
X-Cdn-Fetch
X-Oneagent-Js-Injection
X-Exp-Id
X-GoogleNews-Bot
X-Kinja-Server
X-Kinja-Revision
X-Kinja-Build
X-Exp-Variant
X-Kinja
X-Abt-Application-Version
X-Ac
Verso
X-Upstream
X-Mod-Pagespeed
X-Navigation-Version
X-Url
X-ORACLE-DMS-RID
X-B3-TraceId
X-Amz-Rid
Akamai-GRN
Pinterest-Generated-By
X-Pinterest-Rid
Pinterest-Version
X-Language
Nginx-Cache
X-ECACHE
Display
X-Middleton-Display
X-GitHub-Request-Id
X-Sol
Pagespeed
S
X-Envoy-Decorator-Operation
X-Kraken-Loop-Name
X-Erf-Bev-Bev-Is-Generated
X-Instrumentation
X-PDP-UNCACHING-HASH
X-Erf-Bev-Bev
X-Server-Lifecycle-Phase
Response
AR-PoweredBy
X-Middleton-Response
AR-Request-ID
AR-ATIME
X-MS-InvokeApp
Edge-Cache-Tag
X-Ratelimit-Limit
X-Goog-Hash
X-Distributor
X-Resp-Is-Stale
SPIisLatency
SPRequestDuration
SPRequestGuid
X-SharePointHealthScore
X-Edge-Location-Klb
X-Kinsta-Cache
X-Ttl
X-ARC
X-NGENIX-Cache
X-Ser
X-Client-IP
Access-Control-Request-Method
Front-End-Https
X-Dw-Request-Base-Id
X-Shield-Request-Id
X-Amzn-Trace-Id
X-Ruxit-Js-Agent
X-Content-Digest
X-Ezoic-Cdn
RTSS
X-Recruiting
X-Varnish-TTL
X-Cache-Key
Cache-Status
X-Version
X-T
X-Mg-S
TP-Cache
Public-Key-Pins
X-Powered-CMS
X-HS-Hub-Id
Fastcgi-Cache
X-HS-Content-Id
X-HS-Cache-Config
X-MSEdge-Ref
X-Accel-Expires
Arr-Disable-Session-Affinity
AR-CACHE
X-Daa-Tunnel
X-Ismobilevalue
Realpath
X-Cluster-Name
X-Id
Cache-Tags
X-Cached
X-Correlation-Id
Content-MD5
X-Content-Security-Policy-Report-Only
X-Webkit-Csp
Ar-SID
YJS-ID
X-Request-Processing-Time
X-Request-Received
X-Forwarded-For
X-HS-Combine-CSS
X-Request-Device-Id
X-Newrelic-App-Data
Payment
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-DIS-Request-ID
X-Fastly-Request-ID
X-Ua-Browser
X-GUploader-UploadID
X-Xrds-Location
X-Cambria-Cache-Control
X-Jurisdiction
X-HP-Trace-Id
X-HP-Webp
X-HS-CF-Cache-Status
X-Azure-Ref
X-COUNTRY
X-RateLimit-Remaining
X-HS-Prerendered
X-Amz-Replication-Status
Content-Disposition
X-Meli-Trace-Bu
X-Meli-Trace-Platform
X-Meli-Trace-Site
X-Server-Name
X-Ratelimit-Remaining
Count-Hit
Cross-Origin-Resource-Policy
X-Px
X-Origin-Server
X-Ratelimit-Reset
X-Amz-Meta-S3cmd-Attrs
X-Protected-By
X-Unique-Id
Accept-Charset
X-Page-Id
MicrosoftSharePointTeamServices
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Logged-In
X-AppVersion
X-Az
X-Activity-Id
X-Proxy
Cross-Origin-Embedder-Policy
X-FB-Debug
Cleartype
X-Www-Served-By
X-VARITI-CCR
X-Rid
X-ORACLE-DMS-ECID
X-Git-Hash
X-SERVER-NAME
X-Request-Handler-Origin-Region
X-Microsite
X-Load-Cache
X-Amzn-RequestId
X-Amz-Apigw-Id
X-TTL
X-LLID
X-Goog-Metageneration
Version
X-Template
X-Geo-Country
X-Forwarded-Proto
X-Varnish-Backend
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-PressLabs-Stats
X-Upgrade-Enabled
X-Hits
Server-Node
X-CST
X-B3-Sampled
Server-Name
X-WebKit-CSP-Report-Only
X-Hostname
X-Content-Options
X-TT
X-App-Server
Section-Io-Cache
X-Grace
Access-Control-Allow-Method
Healthy
X-Fb-Rlafr
X-Device-Type
X-B
X-Varnish-Server
Viewport
X-Varnish-Grace
Alternate-Protocol
Fastly-SIE
Fastly-SWR
X-Frontend
Mrf-Cache-Status
MRF-Tech
X-B3-TraceId-Primal
X-Status
X-Goog-Stored-Content-Length
X-Request-Guid
X-Goog-Stored-Content-Encoding
TCN
X-Goog-Storage-Class
X-Goog-Generation
Upgrade-Insecure-Requests
X-Contextid
DC
Host
X-Magnolia-Registration
X-Requestid
AKAMAI-GRN
Retry-After
X-EdgeConnect-Cache-Status
X-Amzn-Remapped-Content-Length
MS-Author-Via
X-Cache-Age
X-CSRF-Token
X-Cache-Control
X-App-Version
Frame-Options
X-Tt-Trace-Tag
X-Tt-Trace-Host
Amp-Access-Control-Allow-Source-Origin
X-Debug
X-Type
X-Revision
X-Buckets
X-Varnish-Ttl
X-Origin-TTL
X-Origin-CC
X-Response-Served-From
X-Original-Request-Id
X-Hl-Ver
X-INCAP-ABP
X-ProcessESI
X-RemovedCookies
X-G
X-Akamai-Edgescape
X-Adobe-Content
X-Adobe-Loc
SD-X-WS
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-UUID
X-Lambda-Id
X-Debug-IsConnected
X-Cache-Status-Check
Access-Control-Request-Headers
X-Content-Powered-By
X-Debug-IsPreview
Section-Io-Id
Cross-Origin-Opener-Policy-Report-Only
Cross-Origin-Embedder-Policy-Report-Only
X-Mobile
X-NYM-Debug-Backend
X-Oracle-Dms-Ecid
X-N
X-RTag
X-Trace-Id
X-ServerID
X-Akamai-Request-ID2
X-Seen-By
Ms-Operation-Id
X-Instance
MS-CV
X-Backend-Name
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Tumblr-Pixel-0
X-Storage
X-Tumblr-Pixel
X-Tumblr-Pixel-1
X-Server-W
X-Tumblr-User
X-AB
X-Is-Bot
X-Rendered-As
X-Dc
NGB
Charset
X-Mg-Request-UUID
X-Framework
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
X-RM-Cache-TTL
Cache
X-Vcl-Version
X-Yandex-Req-Id
X-Tec-Api-Root
X-Tec-Api-Origin
X-Tec-Api-Version
Webserver
Filterid
X-DataDome
X-Cache-Time
Accept-Language
X-VC-Cache
Paypal-Debug-Id
X-Request-Bu
X-Request-Platform
X-Request-Site
SRV
X-B3-SpanId
Refresh
X-Time
Onion-Location
X-URL
X-Cache-Hit
X-ECache
X-HITS
X-Ms-Request-Id
X-Ms-Version
X-F-Cache
X-Real-IP
X-Region
YJS-CacheStatus
X-Node-Name
X-Hcs-Proxy-Type
X-CCDN-CacheTTL
X-User-Agent
X-CCDN-Origin-Time
CDN-RequestId
X-Environment-Context
X-Mode
X-L-Path
Xet-Cookie
X-IPS-LoggedIn
Liferay-Portal
Priority
X-Fastcgi-Cache
GEO-INFO
X-Service
X-HTML-Minification-Powered-By
X-Rocket-Nginx-Serving-Static
X-LB-Cache
X-CLOUD-TRACE-CONTEXT
X-Tb
X-Pass-Why
Protected
X-Drupal-Cache-Tags
Country
X-Adobe-Source
Backend
Cross-Origin-Window-Policy
X-Datadog-Sampling-Priority
X-Datadog-Trace-Id
X-Rule
X-Datadog-Sampled
X-Datadog-Parent-Id
Meta-Geo
X-Is-Mobile-Only
X-Cloudmap
X-Is-Modern-Browser
Selected-Fe
X-Is-Desktop
X-Browser-Name
X-Is-Supported-Browser
X-Is-Tablet
X-Extlb
X-Geo-Region
X-Is-Mobile
X-Cache-Expired-At
X-Proxied
X-SaId
X-JoinUs
X-Zipkin-Id
X-Timing-Wait
X-Proxy-Build
X-UPSTREAM-Address
X-Tcp-Rtt
X-Routing-Service
X-Rewrite-Enabled
X-Rn-Rsrv
X-Handled-By
X-Whom
X-Httpd
X-Hit
X-Servername
Url
X-BYPASS-REASON
X-Alternate-Cache-Key
OT-Force-Account-Verify
X-Storefront-Renderer-Rendered
X-VC
X-Varnish-Beresp-Grace
X-Shopify-Stage
X-Wix-Request-Id
X-Forwarded-Host
X-ProxyCache-Key
X-Proxy-Cache-Info
X-Origin
X-ProxyCache-Status
X-Origin-Cache
X-RCS-CacheZone
X-Web-Node
X-Generation-Time
X-Provided-By
X-VCT
Atl-Traceid
X-Cdn-Origin
X-Logging-Id
X-Cluster
X-Format
X-MP-GENERATED-AT
Mn-Server-Ip
X-Skip-Cache
TWC-Connection-Speed
TWC-Device-Class
X-Urbn-Context-Path
X-Urbn-Site-Id
X-FB-TRIP-ID
X-Cacheable-TTL
TWC-GeoIP-City
X-Edge-Location
Cache-Hits
Environment
Expiry
Fastcgi-Useragent
Locale
X-Loop
X-Connection-Hash
X-Tncms
TWC-GeoIP-Country
Property-Id
X-Detected-As
X-Origin-Date
ServerID
Webcakes-App-Name
TWC-GeoIP-DMA
Webcakes-App-Version
Webcakes-Region
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-S
Uber-Trace-Id
Web-Mar-Node
TWC-GeoIP-Region
TWC-Privacy
TWC-GeoIP-LatLong
X-WP-CF-Super-Cache-Active
X-Origin-Hint
TWC-Locale-Group
X-Vcache
X-Auth-Group-Type
LB
X-Tumblr-Pixel-2
ServedBy
X-Cache-Action
X-Locale
X-Labrador-Cache-Channel
Apigw-Requestid
X-Tumblr-Pixel-3
X-Drupal-Cache-Contexts
X-Soup
X-Redis-Cache
X-Director
X-Hosted-By
DB-Nickname
X-PHP-Host
X-Cms-Context
X-App-Environment
X-Fetched-On
X-FW-Static
X-FW-Version
X-Say-TTL
X-SayCDN-TTL
X-Scope-Id
X-Served-From
X-FW-Type
X-FW-Dynamic
X-Say-Cacheable
X-Debug-Info
X-Cluster-Node
X-Restarts
X-Cache-Host
X-FW-Serve
X-FW-Hash
X-Endurance-Cache-Level
X-FW-Server
X-Cache-Debug
Filters
X-IPLB-Instance
X-Server-ID
X-IPLB-Request-ID
X-NewRelic-App-Data
X-Platform
X-Mly-Id
X-CDN-Forward
X-R9-Blue-Green-Version
X-XRDS-Location
Node
Front
X-Api-Version
X-Tt-Logid
AR-SID
X-B3-Traceid
X-GEO
X-CDN-Cache-Status
X-No-Session
WPO-Cache-Status
X-Optimistic-Header
Xserver
X-ShardId
X-ShopId
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Varnish-Cache-Hits
X-UA
X-Varnish-Age
X-Varnish-Beresp-Ttl
Countrycode
X-Lagoon
Cache-Tv-Group
X-WP-CF-Super-Cache-Cookies-Bypass
X-Presslabs-Stats
X-Wormhole-Sdk
X-Generated-By
X-Fastly-Request-Id
X-SRV
X-Signature
X-NWS-UUID-VERIFY
X-B-Cache
Referer-Policy
X-CACHE-AGE
X-Client-Ip
X-Webstats-RespID
X-Site-Version
AMP-Access-Control-Allow-Source-Origin
X-Azure-Ref-OriginShield
X-IsAdmin
From-Origin
X-Ua
Request-ID
Cache-Provider
X-PHP-Backend
X-AWS-Id
X-Cache-Rule
X-Cache-Operation
X-LJ-Flow-ID
X-VWS-Id
X-Accel-Version
X-NF-Request-ID
X-Auto-Login
X-Worker
Location
S-Rt
X-TA-CDN-Provider
X-VC-TTL
X-Upstream-Ct
X-Tx-Id
X-Upstream-Ht
X-BCube-Filmed-By
X-D
X-Tb-Optimization-Total-Bytes-Saved
X-Cache-NE
X-Content-Age
X-External-Request-Id
X-B-Cookie
CDN-EdgeStorageId
X-Bl-Debug
Lang
CDN-CachedAt
Apple-News-Services-Request-Url
Origin-Agent-Cluster
X-ApacheServer
Apple-News-Services-Handled
X-Developer
X-Clientip
X-Ec-Fail
X-Ec-GeoHdr
WPO-Cache-Message
Apple-News-Services-Host
X-A-Dam
X-Aed
X-Destination
X-Access
X-A-Wwc
X-A-Dcw
Source
X-Conf
X-Application
X-A-Dgt
Candidate-Md5Url
X-Varnish-Hostname
Apple-News-Services-Parsed-Url
CDN-Cache
CDN-Uid
Redirect-Candidate
X-PERF
X-Sigma-Backend
DCR-Decision-By
Pragrma
ServerName
X-Org
Powered-By
Sslversion
X-Sigma
CDN-PullZone
X-VG-TLSProxy
X-Section
Rendered-Blocks
X-Vdms-Version
X-S-Cookie
DCR-Processing-Time-Ms
X-Rocket-Build-Number
X-Rojux
X-SRCache-Key
Fl-Custom-Application
CDN-RequestPullSuccess
X-Bc-Bl
Xc-Version
X-Vtex-Remote-Cache
CDN-RequestPullCode
X-GeoCountry
X-A-Ccd
CDN-RequestCountryCode
X-GeoCode
X-A
MD5-Digest
N-Cache
Ngx.Var.Host
Origin
X-Loc
Meta-Geo-Continent
Host-ID
X-Ig-Origin-Region
X-Ig-Push-State
X-ScT
X-Xfnlog-Site
X-Litespeed-Cache-Control
Web-Mar-Region
We-Hiring
Odigeo-Trace-Id
Vix-Hermes-Req-Id
X-BBC-Edge-Cache-Status
Wxu-Next-Commit
Log-Origin
Mail-Subject
Wxu-Next-Region
Wxu-Next-Hostname
Origin-CC
Origin-EX
RNT-Machine
X-Aicache-OS
X-AK-Request-ID
Req-Svc-Chain
X-Acquia-Purge-Cdn-Unconfigured
RNT-Time
X-Akamai-Device-Characteristics
Origin-Site
Store-Cloud-Cache
Pics-Label
Time-Cloud-Cache
X-Ee-Request-Id
X-Render-Time
X-Policy
X-Req
X-Save-Cache
X-SIPLIST1
X-SD-PageType
X-PAYTM-SRV-ID
X-Origin-Expires
X-Micro-Cache
X-Men
X-Mvc-Supplant-Cachable
X-Node-Id
X-VG-WebCache
X-Old-Content-Length
X-Slack-Backend
X-Slack-Shared-Secret-Outcome
X-Varnish-Authentication
X-V-Cache
X-Varnish-Beresp-Status
X-Varnish-CookieHashed-On
X-Varnish-Director
X-Varnish-CookieINHashed-On
X-Uri
X-Up
X-Vary-Devices
X-Sn-Servicetimems
X-Varnish-Remaining-TTL
X-SVT-ORM-RULES
X-UA-Device-Type
X-SVT-ORM-VERSION
X-Internal-TTL
X-HS-Content-Campaign-Id
X-DefHash
X-DefElseHash
X-Depends
X-Server-IP
X-Ee-Origin
X-Ee-Generated-By
X-CUA
X-Csrf-Jwt
X-CGP
X-Cache-Aspx
X-Cms-Device
X-Contensis-Viewer-Groups
X-Core-Value
X-Content-Length
X-Ee-Request-Date
X-Epic-Correlation-Id
X-GeoIP-City
Country-Code
X-GeoIP-Country-Code
X-GeoIP-Region-Code
X-Hash
X-GoCache-CacheStatus
X-Gamma-Serve
X-From
X-Eu-Site
X-ND-Cache
X-FC-Vary-Parameters
X-Fmm-Version
X-Forwarded-Site
X-Bug-Bounty
X-Action
X-Cs
Cdnsip
Cdncip
Fastly-SSL
Cluster
DSUID
CF-IPCountry
L5d-Success-Class
Cmstype
Cmsid
Gannett-Cam-Experience-Id
Expect-Staple
Gh-Request-Id
L
Ha-Gx-Prefs
X-Sucuri-Cache
Canary
IsBot
Sid
CDCHOST
X-Parent-Response-Time
X-Reqid
X-NGINX-Cache
X-Bip
X-Block-Status
X-Pubstack
X-Backend-Instance
X-Region-Sid
X-Thanos
X-Request-URI
X-Gen-Mode
X-Cache-Date
X-Amz-Storage-Class
X-Shield-Cache-Expires
Azure-SiteName
Azure-RegionName
X-App-Name
C-Via
Azure-SlotName
Azure-InstanceId
X-SB
X-Nyt-Route
X-Ion-Hop
X-Ion-Healthy
X-Jungle-Id
X-Level-Front-Cache
X-Ec-Custom-Error
X-Human
X-Hnp-Log
X-Generated-On
X-Gdpr
X-Frame-Option
X-FORWARDED-FOR
X-HN
X-Dispatcher-Server
X-LSADC-Cache
X-Origin-Time
X-Op-Id-All
X-Path
X-Air-Pt
X-Proto
Cache-Contol
X-NMSegId
X-Debug-Cache-Store
X-Debug-Cache-Fetch
X-Date
X-Mvc-Supplant-OutputCached
X-Cache-FS-Status
Azure-Version
Server-Host
Content-Style-Type
X-Vmg-Version
RewriteTeamHook
X-Viewer-Country
Content-Script-Type
TDXMobile
X-Vercel-Id
X-Via-Fastly
X-We-Are-Hiring
X-Wikidot-Backend
X-Fastly-Backend
Nord-Request-ID
NM-Fastcgi-Cache
Machine
PFcat
Fastly-Backend-Name
Release
X-Wikidot-Static-Cache
X-CacheTTL
Thinkindot-CacheControl
RewriteTestHook
X-VarnishDD-TTL
V-Age
User-Cache-Control
Tube-Return
X-Thinkindot-L3
Click-Count-Action-Start
X-Accel-Expires-Debug
X-AB-Test
X-Thinkindot-L1
Tube-Got-Results
Click-Count-Error
X-Vercel-Cache
Tube-Get-Contents
Thinkindot-CacheControl-Type
Tube-Got-Eval
X-Edge-Server
Platform
X-Location
X-DPWN-IS-SECURE
Cdn-Request-Time
Cdn-Host
X-Gzip
X-Esi-Check
Producers
X-ElasticPress-Query
Fastly-GeoIP-CountryCode
X-Cache-Id
CacheControlHeader
X-B3-Trace-ID
CloudFront-Viewer-Country
X-Moov-Xdn-Caching-Status
X-Moov-Xdn-Version
X-Moov-T
X-Proxied-Request
XM
X-Source
Mime-Version
NGX
X-Sucuri-ID
X-Origin-Response-Time
Fastly-Drupal-HTML
X-Pad
X-ZONE
X-Cached-By
X-Varnish-Hits
X-Refresh
Debug
Load-Balancing
X-Via-Popv
X-Servedbyhost
Cookie
X-Via-Poph
X-Via-Popn
X-Datadome
X-APP
X-Srv
X-AIR-PT
X-Nginx-Cache-Key
GeoIP-Latitude
X-Debug-Service
X-HA-Backend
Server-ID
GeoIp-Country-Code
True-Client-Country-4JS
X-TH-Server
Traceparent
X-Nananana
Cdn
X-DynaTrace-JS-Agent
Server-Hostname
Sever-Int
Product
Server-Ext
HA-Ipaddr
X-Litespeed-Tag
X-Zone
X-TT-LOGID
X-Webkit-CSP
X-Amz-Meta-Cb-Modifiedtime
X-Ez-Minify-Html
Show-Do-Not-Sell-Link
X-Fpc
X-Cache-VC
WZWS-RAY
X-B3-Parentspanid
X-Wa
X-GeoIP
X-Cache-Backend
X-Nc
X-Cdn-Forward
X-Newrelic-Synthetics
X-LB-ID
X-Unity-Cache
HostName
DataCenter
X-User
Edge-Cache
Fastly-Drupal-Html
X-B3-Spanid
Tcn
SID
MIME-Version
X-VCL-Version
X-Nginx-Cache
X-Lsadc-Cache
X-CDN-Provider
X-Request-Start
X-AC
Lb
X-LB-NoCache
Resin-Trace
Akamai-Mon-Iucid-Del
X-Vc
XkeyR9
Serverhost
X-Service-Response-Time
A
Sm-Log-Id
Xkey-La3
X-Scheme
Wsr-Cache
Xkeylog
X-Proxy-CacheR9
X-Proxy-Cache-La3
X-RateLimit-Limit
X-HOST
X-Datacenter
X-LiteSpeed-Tag
CountryCode
X-TX-ID
Yjs-Id
Cs
Surrogated-Key
X-Request-Host
X-LiteSpeed-Cache-Control
X-Pool
X-CS
NtCoent-Length
X-Lb-Id
Hostname
X-NodeID
CDN
X-Dynatrace-Js-Agent
Uri
Esi-Enabled
X-HubSpot-Correlation-Id
X-Akamai-Pragma-Client-IP
Cdn-Requestid
Datacenter
X-WA
X-API-Version
X-RequestId
X-Fastly-Backend-Reqs
X-Vgn-Hpd-Reason
X-FPC
X-NC
X-VC-Age
X-Cache-Grace
X-Udemy-Cache-App-Namespace
X-ID
X-Air-Trace-Id
X-Air-Source
X-Air-Hostname
Proxy-Firewall
X-DynaTrace
Server-Id
X-Stale
Cr
Pramga
X-Via-JSL
X-HA-Application-Name
Yak-Timeinfo
X-Styx-Info
X-DataCenter
Content-Secure-Policy
X-HA-Device-Type
X-Html-Minification-Powered-By
X-Styx-Origin-Id
X-TIM-N
X-HA-Bot-Classification
X-CSRF-TOKEN
N1-Cache
T-Server
RATING
ServerHost
Geoip-Latitude
X-Via-CDN
X-TimeS
X-Ez-Minify-Js
X-Var-Ttl
W
X-Via-SSL
GeoIP-Country-Code
X-Srcache-Fetch-Status
X-Via-Edge
Edge-Copy-Time
X-Srcache-Store-Status
X-Sorting-Hat-Podid
X-Lb-Nocache
X-Shopid
X-Geolocation
X-Jobs
From-Cache
Srv
X-Sorting-Hat-Shopid
X-ServedByHost
X-Swift-Error
X-Varnish-Beresp-TTL
X-Ha-Backend
X-Zen-Fury
X-Shardid
Req-ID
X-Wp-Cf-Super-Cache
X-Wp-Cf-Super-Cache-Cache-Control
X-Oracle-DMS-ECID
X-Via-PopV
X-MSEdge-Flight
X-CACHE-KEY
X-App
X-Via-PopH
X-MSEdge-Features
X-Via-PopN
WP-Super-Cache
True-Client-IP
Cloudfront-Viewer-Country
X-LAGOON
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-Wp-Cf-Super-Cache-Active
X-Geo
Ohc-Cache-HIT
Ohc-File-Size
X-Ramcache
X-ByteArk-Cache
On-Server
X-Ssense-Shipping-Surcharge-Enabled
X-Key
X-Proxy-Cache-LA2
X-ByteArk-ReqID
FSS-Cache
X-Ssense-Gql
X-Cdn-Srv
X-VServer
X-Correlation-ID
Cl-Cache
Ngx
X-Elasticpress-Query
X-VTEX-Cache-Server
X-Web-Server
X-Sucuri-Id
X-VTEX-Cache-Time
X-Check-Cacheable
X-Powered-By-VTEX-Cache
X-Cdn-Cache-Status
X-Webkit-Csp-Report-Only
CF-Cached-On
X-Fastly-Cache
WebServer
X-ATG-Version
X-Serial
X-Th-Server
X-PageType
Akamai-X-True-TTL
X-DC
X-Iplb-Instance
Cf-Ipcountry
X-Iplb-Request-Id
Xkey-G-Jp
Warning
X-MiniProfiler-Ids
X-Limited
X-Beacon
My-App
Coldstone-Viewer-Country
X-Fastly-Cache-Status
X-Mg-Cache
Host-Name
X-Env
FSS-Proxy
Cneonction
Coldstone-Viewer-Country-Region-Name
X-Request-Url
Coldstone-Viewer-Currency
X-WA-Info
User-Agent