Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
X-Frame-Options
Expires
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Accept-CH
Last-Modified
X-XSS-Protection
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
CF-RAY
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Alt-Svc
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
Cf-Request-Id
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
X-Xss-Protection
Access-Control-Allow-Credentials
Accept-CH-Lifetime
Content-Security-Policy-Report-Only
X-DNS-Prefetch-Control
X-AspNet-Version
X-Runtime
Server-Timing
Permissions-Policy
X-Drupal-Cache
CF-Ray
X-Generator
X-Envoy-Upstream-Service-Time
X-Cache-Status
X-Ua-Compatible
X-Cacheable
X-Iinfo
X-FRAME-OPTIONS
Timing-Allow-Origin
X-Drupal-Dynamic-Cache
Feature-Policy
X-Content-Security-Policy
X-CONTENT-TYPE-OPTIONS
Xkey
Upgrade
Access-Control-Expose-Headers
Content-Encoding
X-CDN
Status
X-XSS-PROTECTION
X-AspNetMvc-Version
Accept-Ch
Access-Control-Max-Age
Host-Header
X-Amz-Request-Id
X-Age
X-Amz-Id-2
Request-Context
Cf-Edge-Cache
X-Backend
X-Robots-Tag
X-Hacker
X-Via
Cf-Apo-Via
X-Request-ID
X-Turbo-Charged-By
X-Rq
X-Amz-Version-Id
X-Vhost
X-Cache-Group
Keep-Alive
X-Dispatcher
X-AH-Environment
X-UA-Device
X-Server
X-Proxy-Cache
EagleId
X-Ws-Request-Id
CONTENT-SECURITY-POLICY
X-OneAgent-JS-Injection
X-Varnish-Cache
Pantheon-Trace-Id
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
Grace
P3p
X-Server-Powered-By
Allow
X-Dns-Prefetch-Control
X-Pingback
X-Page-Speed
X-Swift-SaveTime
X-Swift-CacheTime
X-WebKit-CSP
Ali-Swift-Global-Savetime
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Litespeed-Cache
X-LiteSpeed-Cache
X-FTR-Request-ID
X-Node
X-Device
EagleEye-TraceId
X-Host
X-Cache-Lookup
X-Backend-Server
Surrogate-Control
X-Country-Code
X-Ruxit-JS-Agent
X-Server-Id
X-Readtime
X-Cloud-Trace-Context
X-Akam-SW-Version
Cf-Railgun
X-HW
X-Response-Time
Cache-Tag
Content-Location
X-Amz-Server-Side-Encryption
Cross-Origin-Opener-Policy
X-Rack-Cache
X-Trace
X-Nginx-Upstream-Cache-Status
Service-Worker-Allowed
X-Nginx-Cache-Status
X-Country
Fastly-Restarts
X-TraceId
Request-Id
X-Content-Type
X-Clacks-Overhead
X-Vname
X-PC
X-TtlSet
X-Application-Context
X-Times
Rating
X-Cnection
X-Cache-TTL
X-Edge
X-Mcache
X-Midtier
X-Browser-Type
X-ESI
X-Vcap-Request-Id
Surrogate-Key
X-FTR-Cache-Status
X-Country-Code-Real
X-FTR-Backend
X-FTR-Balancer
X-FTR-Backend-Server
X-Ac
X-FTR-Expires
Origin-Trial
Edge-Control
Accept-Ch-Lifetime
X-Powered-By-Plesk
X-Kinja-Server
X-Kinja
X-Exp-Variant
X-Exp-Id
X-Abt-Application-Version
X-Cdn-Fetch
X-Kinja-Build
X-GoogleNews-Bot
X-Kinja-Revision
X-Element-Page-Cache
X-NWS-LOG-UUID
X-D2id
Verso
X-FastCGI-Cache
X-Upstream
X-ORACLE-DMS-RID
X-ECACHE
X-Mod-Pagespeed
X-Amz-Rid
X-Navigation-Version
Nginx-Cache
X-B3-TraceId
X-Nf-Request-Id
Display
X-Middleton-Display
Pagespeed
X-Sol
X-Client-IP
X-GitHub-Request-Id
Pinterest-Generated-By
Pinterest-Version
X-Pinterest-Rid
X-Language
X-PDP-UNCACHING-HASH
X-Instrumentation
X-Kraken-Loop-Name
X-Erf-Bev-Bev
X-Server-Lifecycle-Phase
X-Middleton-Response
Response
X-Erf-Bev-Bev-Is-Generated
X-Envoy-Decorator-Operation
X-Ratelimit-Limit
S
AR-PoweredBy
Edge-Cache-Tag
AR-ATIME
AR-Request-ID
X-Goog-Hash
X-MS-InvokeApp
Akamai-GRN
X-ARC
X-Resp-Is-Stale
X-Ua-Device
X-Edge-Location-Klb
X-Kinsta-Cache
X-Ser
X-Url
X-Content-Digest
SPIisLatency
SPRequestDuration
X-Distributor
SPRequestGuid
X-SharePointHealthScore
Access-Control-Request-Method
X-Dw-Request-Base-Id
Front-End-Https
X-Cache-Key
X-Ezoic-Cdn
X-NGENIX-Cache
X-Shield-Request-Id
X-Recruiting
RTSS
Cache-Status
X-Amzn-Trace-Id
X-Powered-CMS
X-Version
X-Forwarded-For
Public-Key-Pins
TP-Cache
X-Mg-S
X-MSEdge-Ref
X-Ttl
Fastcgi-Cache
X-T
X-Daa-Tunnel
Arr-Disable-Session-Affinity
X-Accel-Expires
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Cache-Config
X-Server-Name
X-Correlation-Id
X-Ismobilevalue
X-Varnish-TTL
Realpath
X-Fastly-Request-ID
X-Cluster-Name
Cache-Tags
X-Cached
X-Id
X-CST
AR-CACHE
X-Newrelic-App-Data
X-HS-Combine-CSS
X-Request-Processing-Time
X-Request-Received
Payment
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-TTL
X-Ua-Browser
X-DIS-Request-ID
X-Xrds-Location
X-ORACLE-DMS-ECID
X-Content-Security-Policy-Report-Only
X-GUploader-UploadID
Content-MD5
X-RateLimit-Remaining
X-HP-Trace-Id
X-Cambria-Cache-Control
X-HP-Webp
X-Jurisdiction
X-HS-Prerendered
X-HS-CF-Cache-Status
Content-Disposition
Count-Hit
X-Oneagent-Js-Injection
X-Ratelimit-Remaining
X-Azure-Ref
X-Amz-Replication-Status
X-Webkit-Csp
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-PressLabs-Stats
X-Px
Cross-Origin-Resource-Policy
X-Page-Id
X-Unique-Id
X-Ruxit-Js-Agent
Accept-Charset
X-Logged-In
X-Ratelimit-Reset
X-Protected-By
X-Microsite
X-Request-Handler-Origin-Region
X-Proxy
X-FB-Debug
X-Git-Hash
Cleartype
Cross-Origin-Embedder-Policy
X-AppVersion
X-Activity-Id
X-VARITI-CCR
X-Az
X-Rid
X-Origin-Server
X-Www-Served-By
X-Load-Cache
X-Template
X-LLID
X-Goog-Metageneration
X-Hits
X-Varnish-Backend
X-Server-ID
MicrosoftSharePointTeamServices
YJS-ID
Version
Server-Node
X-Forwarded-Proto
X-Amz-Meta-S3cmd-Attrs
Server-Name
X-Geo-Country
X-URL
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Upgrade-Enabled
X-TEC-API-ROOT
Ar-SID
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-Varnish-Ttl
X-Frontend
X-NF-Request-ID
X-Hostname
X-Content-Options
X-B3-Sampled
X-Varnish-Server
X-SERVER-NAME
Section-Io-Cache
X-Varnish-Grace
X-TT
Mrf-Cache-Status
X-App-Server
MRF-Tech
X-B3-TraceId-Primal
X-Device-Type
Fastly-SIE
Fastly-SWR
X-Fb-Rlafr
X-B
Viewport
Access-Control-Allow-Method
X-Grace
X-Status
TCN
AKAMAI-GRN
Alternate-Protocol
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Request-Device-Id
Upgrade-Insecure-Requests
X-Cache-Age
Healthy
X-Request-Guid
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Wormhole-Sdk
Host
Amp-Access-Control-Allow-Source-Origin
X-Magnolia-Registration
X-Buckets
X-EdgeConnect-Cache-Status
X-CSRF-Token
AR-SID
X-Debug
DC
Retry-After
X-WebKit-CSP-Report-Only
X-Amzn-Remapped-Content-Length
X-Contextid
X-Cache-Control
X-Meli-Trace-Site
X-Meli-Trace-Platform
MS-Author-Via
X-Meli-Trace-Bu
X-Revision
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
X-Response-Served-From
X-Original-Request-Id
X-Adobe-Content
X-Adobe-Loc
X-Yottaa-Metrics
X-Fastcgi-Cache
X-Yottaa-Optimizations
X-Origin-CC
SD-X-WS
Cross-Origin-Opener-Policy-Report-Only
X-Mobile
Cross-Origin-Embedder-Policy-Report-Only
X-Akamai-Edgescape
X-Is-Bot
X-Rendered-As
X-Type
X-NYM-Debug-Backend
X-Lambda-Id
X-Instance
X-Origin-TTL
X-G
Access-Control-Request-Headers
X-Backend-Name
X-Trace-Id
X-Seen-By
X-Framework
X-Content-Powered-By
X-Debug-IsPreview
X-Debug-IsConnected
Section-Io-Id
X-ServerID
X-UUID
X-Hl-Ver
X-Cache-Hit
X-Tec-Api-Origin
X-Tec-Api-Root
X-Tec-Api-Version
Charset
X-DataDome
X-Mg-Request-UUID
X-RM-Cache-TTL
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-Tumblr-User
X-Server-W
X-RTag
X-Dc
X-Storage
MS-CV
Ms-Operation-Id
X-ProcessESI
X-RemovedCookies
X-Vcl-Version
X-COUNTRY
X-Akamai-Request-ID2
X-AB
NGB
X-INCAP-ABP
X-N
X-Cache-Time
X-Cache-Status-Check
X-App-Version
X-Request-Site
X-Time
Frame-Options
X-Request-Platform
Filterid
X-Request-Bu
Protected
Refresh
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
SRV
X-Real-IP
X-Region
Accept-Language
X-Node-Name
Cache
Webserver
CDN-RequestId
X-LB-Cache
X-B3-SpanId
X-Hcs-Proxy-Type
Cross-Origin-Window-Policy
X-CCDN-CacheTTL
X-CCDN-Origin-Time
X-Ms-Version
Paypal-Debug-Id
X-Ms-Request-Id
X-User-Agent
Onion-Location
X-Datadog-Trace-Id
X-Datadog-Parent-Id
X-Datadog-Sampled
X-Datadog-Sampling-Priority
Priority
X-Cache-Expired-At
X-F-Cache
X-VC-Cache
Liferay-Portal
X-WP-CF-Super-Cache-Active
X-Whom
X-Mode
X-IPS-LoggedIn
OT-Force-Account-Verify
X-Requestid
Backend
X-Rocket-Nginx-Serving-Static
X-Pass-Why
X-VC
X-Proxy-Cache-Info
X-HTML-Minification-Powered-By
Xet-Cookie
X-Environment-Context
X-Cacheable-TTL
X-L-Path
X-App-Environment
X-Tb
GEO-INFO
X-Service
X-Detected-As
X-Rn-Rsrv
Filters
Fastcgi-Useragent
Meta-Geo
X-Adobe-Source
X-Oracle-Dms-Ecid
X-JoinUs
X-Servername
X-MP-GENERATED-AT
LB
X-SaId
X-Zipkin-Id
X-UPSTREAM-Address
X-Cloudmap
X-Extlb
X-Debug-Info
X-Rewrite-Enabled
X-Proxied
Url
X-Routing-Service
X-Is-Mobile
X-Varnish-Beresp-Grace
X-Web-Node
X-Is-Desktop
X-Geo-Region
X-Forwarded-Host
X-Storefront-Renderer-Rendered
X-Tncms
X-Shopify-Stage
X-Origin-Date
X-Is-Supported-Browser
X-Handled-By
X-Rule
X-Loop
X-Alternate-Cache-Key
X-Tcp-Rtt
Country
X-Browser-Name
X-Is-Tablet
X-Hosted-By
X-Hit
X-Logging-Id
Web-Mar-Node
X-Vcache
X-Endurance-Cache-Level
ServedBy
Atl-Traceid
X-HITS
TWC-GeoIP-City
X-Skip-Cache
TWC-Connection-Speed
X-Format
TWC-Device-Class
TWC-GeoIP-Country
TWC-GeoIP-Region
TWC-Locale-Group
TWC-GeoIP-LatLong
TWC-GeoIP-DMA
X-Soup
Property-Id
X-Httpd
Apigw-Requestid
X-Locale
X-Origin-Hint
X-ProxyCache-Key
X-Cluster
X-Restarts
Mn-Server-Ip
X-SayCDN-TTL
X-Say-TTL
X-Say-Cacheable
X-ProxyCache-Status
TWC-Privacy
X-FW-Static
X-FW-Type
X-FW-Server
X-FW-Serve
X-Cms-Context
X-FW-Version
X-Cluster-Node
Environment
X-Cache-Host
X-Cache-Action
X-BYPASS-REASON
X-IPLB-Request-ID
X-Wix-Request-Id
X-Cdn-Origin
Webcakes-App-Name
Uber-Trace-Id
X-IPLB-Instance
X-FW-Hash
Webcakes-App-Version
X-Drupal-Cache-Tags
Webcakes-Region
X-Director
X-FW-Dynamic
X-PHP-Host
X-Edge-Location
X-Labrador-Cache-Channel
X-Redis-Cache
X-S
X-Served-From
X-Scope-Id
ServerID
X-Auth-Group-Type
Selected-Fe
X-Connection-Hash
X-Fetched-On
X-Mly-Id
DB-Nickname
X-FB-TRIP-ID
X-Timing-Wait
Cache-Hits
X-Proxy-Build
X-R9-Blue-Green-Version
Expiry
X-Origin
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Source
Locale
X-Urbn-Context-Path
X-Urbn-Site-Id
X-ECache
X-Generation-Time
X-Tumblr-Pixel-2
X-Tumblr-Pixel-3
Countrycode
X-Drupal-Cache-Contexts
X-ShardId
X-GEO
X-Origin-Cache
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-ShopId
X-RCS-CacheZone
X-VCT
X-No-Session
X-Varnish-Cache-Hits
X-B3-Traceid
X-Varnish-Age
Request-ID
Front
X-Cache-Debug
X-WP-CF-Super-Cache-Cookies-Bypass
YJS-CacheStatus
WPO-Cache-Status
X-Yandex-Req-Id
X-Is-Modern-Browser
X-SRV
X-Varnish-Beresp-Ttl
X-UA
X-CDN-Forward
Node
X-CLOUD-TRACE-CONTEXT
Xserver
X-Site-Version
X-Api-Version
X-Webstats-RespID
X-Lagoon
X-XRDS-Location
X-Webkit-CSP
From-Origin
X-Platform
Cache-Provider
X-Generated-By
X-TA-CDN-Provider
X-Is-Mobile-Only
X-Azure-Ref-OriginShield
X-Provided-By
X-Cdn
X-Accel-Version
Cache-Tv-Group
X-Xfnlog-Site
Referer-Policy
X-VC-TTL
X-TT-LOGID
X-NewRelic-App-Data
X-Ua
X-B-Cache
X-CDN-Cache-Status
X-Signature
CF-IPCountry
WPO-Cache-Message
X-Reqid
X-Sucuri-Cache
X-Tx-Id
Location
X-NWS-UUID-VERIFY
CDN-Cache
CDN-CachedAt
CDN-RequestPullSuccess
X-PHP-Backend
X-Air-Pt
CDN-Uid
CDN-RequestPullCode
CDN-PullZone
CDN-EdgeStorageId
CDN-RequestCountryCode
X-Sucuri-ID
X-Cache-Rule
X-Cache-Operation
AMP-Access-Control-Allow-Source-Origin
X-Content-Age
X-IsAdmin
X-CACHE-AGE
X-Frame-Option
X-ScT
X-Origin-Expires
X-BCube-Filmed-By
DCR-Decision-By
X-VG-WebCache
X-S-Cookie
X-A-Dgt
X-Fmm-Version
X-Forwarded-Site
X-Loc
X-Conf
Redirect-Candidate
X-A-Dcw
XM
X-Destination
Xc-Version
X-B-Cookie
X-VG-TLSProxy
Odigeo-Trace-Id
X-D
X-A-Wwc
X-Tb-Optimization-Total-Bytes-Saved
X-Old-Content-Length
X-Optimistic-Header
Ngx.Var.Host
X-Varnish-Director
Origin
X-Section
X-Rocket-Build-Number
X-Rojux
X-GeoCountry
X-Request-URI
X-Developer
Lang
MD5-Digest
X-GeoCode
X-Slack-Shared-Secret-Outcome
X-Fastly-Request-Id
X-External-Request-Id
Apple-News-Services-Parsed-Url
Candidate-Md5Url
Meta-Geo-Continent
Apple-News-Services-Handled
Apple-News-Services-Host
X-Cache-NE
Apple-News-Services-Request-Url
X-Bl-Debug
Fastly-SSL
X-Vdms-Version
Fl-Custom-Application
X-SRCache-Key
X-Ec-GeoHdr
Expect-Staple
X-Slack-Backend
Sslversion
X-Sigma
X-Application
X-A-Dam
X-Ig-Push-State
Rendered-Blocks
X-Ec-Fail
X-Clientip
X-Aed
X-A-Ccd
X-Access
DCR-Processing-Time-Ms
X-Sigma-Backend
X-Ig-Origin-Region
Cdnsip
X-A
X-Vtex-Remote-Cache
Cdncip
X-AK-Request-ID
X-Tt-Logid
X-Eu-Site
Web-Mar-Region
Wxu-Next-Commit
DSUID
X-Block-Status
X-Bug-Bounty
X-Cache-Aspx
User-Cache-Control
X-Epic-Correlation-Id
Gannett-Cam-Experience-Id
Wxu-Next-Hostname
X-Fastly-Backend
Country-Code
X-FC-Vary-Parameters
X-BBC-Edge-Cache-Status
X-Auto-Login
X-Akamai-Device-Characteristics
X-Aicache-OS
Wxu-Next-Region
X-Bc-Bl
X-Acquia-Purge-Cdn-Unconfigured
X-Action
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
Origin-EX
L
IsBot
X-Ec-Custom-Error
L5d-Success-Class
Origin-CC
X-DefHash
X-DefElseHash
Origin-Agent-Cluster
Log-Origin
Ha-Gx-Prefs
X-CUA
RNT-Machine
RNT-Time
ServerName
TDXMobile
Req-Svc-Chain
X-CGP
X-Csrf-Jwt
X-Content-Length
X-Contensis-Viewer-Groups
X-From
X-Depends
X-Moov-Xdn-Version
X-Varnish-Beresp-Status
X-Save-Cache
X-Shield-Cache-Expires
X-SIPLIST1
X-Varnish-Remaining-TTL
X-Sn-Servicetimems
X-Ee-Request-Id
X-Varnish-CookieHashed-On
X-SD-PageType
X-Pubstack
X-Policy
X-Region-Sid
X-Req
X-Viewer-Country
X-Varnish-Hostname
X-Ee-Request-Date
X-Ee-Origin
X-LSADC-Cache
X-Litespeed-Tag
X-Thinkindot-L3
X-UA-Device-Type
X-Up
X-V-Cache
X-Uri
X-Thinkindot-L1
X-Worker
X-Core-Value
X-Ee-Generated-By
X-Cms-Device
Time-Cloud-Cache
Store-Cloud-Cache
X-Varnish-Authentication
X-PAYTM-SRV-ID
X-Vary-Devices
X-GeoIP-Country-Code
X-Hnp-Log
X-Moov-T
X-GeoIP-Region-Code
X-Node-Id
X-Moov-Xdn-Caching-Status
X-Hash
X-Micro-Cache
X-GeoIP-City
CDCHOST
X-HS-Content-Campaign-Id
Cmsid
Cmstype
X-Men
X-Human
X-Varnish-CookieINHashed-On
X-Gen-Mode
X-Internal-TTL
X-HN
X-Gzip
X-Esi-Check
X-Bip
X-We-Are-Hiring
X-Vmg-Version
X-Via-Fastly
X-Gdpr
X-Backend-Instance
X-Vercel-Id
X-Vercel-Cache
X-SVT-ORM-VERSION
X-Thanos
X-GoCache-CacheStatus
X-SVT-ORM-RULES
Server-Host
X-Cache-Date
X-ApacheServer
X-SB
Host-ID
X-Nyt-Route
X-Gamma-Serve
X-Op-Id-All
X-PERF
X-Proto
X-Date
X-Origin-Time
X-Org
X-Dispatcher-Server
X-Server-IP
X-VarnishDD-TTL
X-Generated-On
X-Cache-Id
X-Cache-FS-Status
X-DPWN-IS-SECURE
X-CacheTTL
X-NMSegId
X-Mvc-Supplant-Cachable
X-Render-Time
X-Level-Front-Cache
X-Path
Tube-Got-Results
Release
Content-Style-Type
Azure-Version
N-Cache
Tube-Get-Contents
Machine
Producers
Pragrma
Azure-SiteName
Azure-SlotName
Azure-RegionName
Azure-InstanceId
Platform
PFcat
NM-Fastcgi-Cache
C-Via
X-Accel-Expires-Debug
X-AB-Test
Content-Script-Type
Fastly-GeoIP-CountryCode
X-Amz-Storage-Class
X-App-Name
Fastly-Backend-Name
Tube-Got-Eval
Cluster
Tube-Return
Gh-Request-Id
Click-Count-Error
V-Age
Click-Count-Action-Start
Fastly-Drupal-HTML
X-Presslabs-Stats
X-Parent-Response-Time
Cdn-Host
Cdn-Request-Time
Canary
CacheControlHeader
Source
Cache-Contol
X-TH-Server
X-Wikidot-Static-Cache
X-Wikidot-Backend
X-Proxied-Request
X-Ion-Healthy
X-Mvc-Supplant-OutputCached
Origin-Site
Nord-Request-ID
X-Origin-Response-Time
RewriteTeamHook
RewriteTestHook
Mail-Subject
X-Debug-Cache-Fetch
X-Edge-Server
X-Debug-Cache-Store
X-Jungle-Id
X-B3-Trace-ID
X-Ion-Hop
X-ElasticPress-Query
We-Hiring
X-AWS-Id
X-VWS-Id
X-Cs
Sid
X-LJ-Flow-ID
Debug
X-Location
Product
X-Litespeed-Cache-Control
X-Pad
X-ZONE
X-Cached-By
HA-Ipaddr
S-Rt
Powered-By
X-Amz-Meta-Cb-Modifiedtime
NGX
CloudFront-Viewer-Country
X-Nginx-Cache
X-Refresh
Mime-Version
X-Via-Popn
X-Via-Popv
X-Cache-VC
Vix-Hermes-Req-Id
X-Via-Poph
X-Varnish-Hits
X-APP
X-NGINX-Cache
X-Servedbyhost
X-Upstream-Ct
X-Upstream-Ht
Pics-Label
X-ND-Cache
X-HA-Backend
GeoIP-Latitude
X-Nananana
Cookie
X-LB-ID
X-Ah-Environment
Server-ID
X-User
Edge-Cache
X-Cdn-Forward
X-AIR-PT
X-Datadome
X-DynaTrace-JS-Agent
X-GeoIP
X-Wa
HostName
X-Fpc
Akamai-Mon-Iucid-Del
X-LB-NoCache
X-Nc
Surrogated-Key
MIME-Version
X-Srv
X-Zone
GeoIp-Country-Code
X-Request-Start
X-B3-Parentspanid
WZWS-RAY
X-Scheme
DataCenter
SID
Resin-Trace
X-Nginx-Cache-Key
X-Unity-Cache
X-Debug-Service
N1-Cache
X-VCL-Version
Fastly-Drupal-Html
X-LiteSpeed-Cache-Control
Server-Hostname
X-Request-Host
X-NodeID
Server-Ext
True-Client-Country-4JS
Sever-Int
X-Pool
X-B3-Spanid
X-CS
X-RequestId
Tcn
Cdn
Show-Do-Not-Sell-Link
Load-Balancing
Sm-Log-Id
X-DynaTrace
X-Cache-Grace
X-Service-Response-Time
X-Lsadc-Cache
X-Vgn-Hpd-Reason
Wsr-Cache
NtCoent-Length
Lb
X-DataCenter
Yak-Timeinfo
X-FORWARDED-FOR
X-Cache-Backend
X-Air-Hostname
Yjs-Id
X-Air-Trace-Id
X-Air-Source
Traceparent
X-Newrelic-Synthetics
X-Via-SSL
X-Zen-Fury
X-Via-Edge
Edge-Copy-Time
X-Via-CDN
X-TX-ID
X-HOST
X-Datacenter
X-Geolocation
X-NODE
X-Vc
X-HubSpot-Correlation-Id
X-Jobs
Req-ID
X-RateLimit-Limit
X-Client-Ip
X-CDN-Provider
X-API-Version
Serverhost
X-Cdn-Srv
X-WA
GeoIP-Country-Code
X-Fastly-Backend-Reqs
Cdn-Requestid
CDN
Datacenter
X-Html-Minification-Powered-By
X-LiteSpeed-Tag
X-ID
X-Udemy-Cache-App-Namespace
WP-Super-Cache
Hostname
X-VTEX-Cache-Server
X-Dynatrace-Js-Agent
Uri
X-Powered-By-VTEX-Cache
X-FPC
X-VTEX-Cache-Time
X-NC
X-Webkit-Csp-Report-Only
Xkeylog
True-Client-IP
XkeyR9
Xkey-La3
X-Proxy-CacheR9
Server-Id
X-Akamai-Pragma-Client-IP
A
X-Proxy-Cache-La3
Coldstone-Viewer-Currency
X-WA-Info
RATING
X-TimeS
Coldstone-Viewer-Country-Region-Name
Coldstone-Viewer-Country
X-Stale
Geoip-Latitude
T-Server
On-Server
X-Lb-Id
X-Ez-Minify-Js
Proxy-Firewall
X-Swift-Error
X-Varnish-Beresp-TTL
From-Cache
X-Lb-Nocache
ServerHost
X-ServedByHost
X-Via-JSL
Srv
Esi-Enabled
Cs
WebServer
X-Oracle-DMS-ECID
CountryCode
BehaviorPad-Version
X-CSRF-TOKEN
Cloudfront-Viewer-Country
X-Ha-Backend
X-App
X-VC-Age
X-LAGOON
X-Wp-Cf-Super-Cache-Cache-Control
X-Wp-Cf-Super-Cache
X-Ez-Minify-Html
X-Styx-Origin-Id
X-HA-Application-Name
Pramga
X-Ssense-Gql
X-Styx-Info
X-HA-Device-Type
X-Ssense-Shipping-Surcharge-Enabled
X-HA-Bot-Classification
X-MSEdge-Features
X-MSEdge-Flight
Cr
X-Web-Server
X-Fastly-Cache
X-Via-PopV
X-Via-PopN
X-Via-PopH
Ngx
X-Correlation-ID
FSS-Cache
X-Srcache-Store-Status
X-Srcache-Fetch-Status
X-Cdn-Cache-Status
X-TIM-N
X-Sorting-Hat-Podid
X-Geo
Content-Secure-Policy
X-Request-Time
X-Check-Cacheable
X-Shardid
X-Sorting-Hat-Shopid
X-Shopid
X-Nitro-Cache
X-Ramcache
X-Proxy-Cache-LA2
X-Elasticpress-Query
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-Serial
My-App
X-Var-Ttl
W
X-DC
User-Agent
X-Wp-Cf-Super-Cache-Active
X-Th-Server
Akamai-X-True-TTL
X-Fastly-Cache-Status
True-Client-Ip
X-Request-Url
X-ATG-Version
Cf-Ipcountry
Warning
X-Platform-Server
Host-Name
Ohc-File-Size
Cneonction
X-Env
Bxpunish
X-Sucuri-Id
FSS-Proxy
Ohc-Cache-HIT
X-Mg-Cache
X-Fastly-Cache-Hits
Bxuuid
X-VServer
X-Beacon
X-Cache-TTL-Remaining