Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
CF-RAY
Accept-Ranges
Expect-CT
Pragma
X-Powered-By
X-XSS-Protection
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Xss-Protection
X-Cache-Hits
P3P
X-Served-By
X-UA-Compatible
X-Download-Options
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
Accept-CH
X-AspNet-Version
Content-Security-Policy-Report-Only
X-Runtime
Accept-CH-Lifetime
X-DNS-Prefetch-Control
X-Ua-Compatible
X-Drupal-Cache
X-Check
X-Cache-Status
X-Generator
Server-Timing
X-Request-ID
X-Cacheable
X-Envoy-Upstream-Service-Time
Timing-Allow-Origin
X-FRAME-OPTIONS
X-Iinfo
X-Drupal-Dynamic-Cache
X-Content-Security-Policy
Access-Control-Expose-Headers
Feature-Policy
X-CDN
Content-Encoding
Status
X-AspNetMvc-Version
Upgrade
Access-Control-Max-Age
CF-Ray
X-Amz-Request-Id
X-Via
X-Amz-Id-2
Cf-Edge-Cache
Host-Header
EagleId
Keep-Alive
Request-Context
X-Backend
X-UA-Device
X-Cache-Group
X-AH-Environment
X-Robots-Tag
X-Server
X-Hacker
X-Turbo-Charged-By
X-Proxy-Cache
X-Ws-Request-Id
Xkey
X-Rq
Permissions-Policy
X-Age
X-Vhost
X-Amz-Version-Id
Allow
X-Dispatcher
X-Dns-Prefetch-Control
Cf-Apo-Via
X-Swift-SaveTime
X-Swift-CacheTime
X-Server-Powered-By
Grace
Ali-Swift-Global-Savetime
X-Varnish-Cache
P3p
X-LiteSpeed-Cache
X-Page-Speed
X-Pingback
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Cache-Lookup
X-Device
X-OneAgent-JS-Injection
Cf-Railgun
X-Backend-Server
EagleEye-TraceId
X-WebKit-CSP
X-Host
X-Server-Id
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Response-Time
X-Readtime
X-Akam-SW-Version
Surrogate-Control
X-HW
Request-Id
X-Litespeed-Cache
X-Cloud-Trace-Context
Content-Location
X-Application-Context
X-Node
X-Nginx-Cache-Status
X-Nginx-Upstream-Cache-Status
X-Ruxit-JS-Agent
X-CST
X-NWS-LOG-UUID
X-Country
Service-Worker-Allowed
X-Country-Code
X-Oneagent-Js-Injection
X-Content-Type
X-Url
X-Clacks-Overhead
Cache-Tag
X-Trace
Rating
X-Rack-Cache
X-Amz-Server-Side-Encryption
Nginx-Cache
X-Times
X-FTR-Request-ID
X-Server-Name
X-Vname
X-PC
X-TtlSet
X-Daa-Tunnel
Cross-Origin-Opener-Policy
X-Mcache
X-Edge
X-Midtier
X-Webkit-Csp
X-Browser-Type
X-Powered-By-Plesk
X-ESI
X-Cnection
X-ECACHE
X-Upstream
X-MS-InvokeApp
Edge-Control
X-GitHub-Request-Id
X-D2id
Verso
X-Ac
X-Element-Page-Cache
X-Kinja
X-Kinja-Build
X-GoogleNews-Bot
X-Kinja-Revision
X-Kinja-Server
X-Exp-Id
X-Exp-Variant
X-Cdn-Fetch
AR-PoweredBy
AR-SID
AR-Request-ID
AR-ATIME
X-Aws-Lambda-Call-Status
X-Ser
X-Ruxit-Js-Agent
X-Vcap-Request-Id
Accept-Ch-Lifetime
X-FastCGI-Cache
X-Cache-TTL
X-Navigation-Version
X-Abt-Application-Version
X-Mod-Pagespeed
AR-CACHE
SPIisLatency
SPRequestDuration
X-Dw-Request-Base-Id
X-B3-TraceId
SPRequestGuid
X-SharePointHealthScore
Fastly-Restarts
X-NF-Request-ID
X-Amz-Rid
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Instrumentation
X-Middleton-Display
Display
X-Sol
Pagespeed
X-Client-IP
Edge-Cache-Tag
X-Mg-S
S
X-Edge-Location-Klb
X-Kinsta-Cache
X-Powered-CMS
X-Amzn-Trace-Id
Response
X-Middleton-Response
Cache-Status
X-Cache-Key
X-Goog-Hash
X-Version
Access-Control-Request-Method
X-VARITI-CCR
X-RateLimit-Remaining
X-Fastly-Request-ID
X-ARC
RTSS
X-Content-Digest
X-TraceId
X-Forwarded-For
Cross-Origin-Resource-Policy
X-Recruiting
X-T
Realpath
X-Correlation-Id
X-Server-ID
X-Ratelimit-Limit
X-MSEdge-Ref
X-Varnish-TTL
Front-End-Https
X-Pinterest-Rid
Pinterest-Version
Pinterest-Generated-By
MS-Author-Via
Fastcgi-Cache
X-Cached
Content-MD5
X-HS-Content-Id
X-HS-Hub-Id
X-PDP-UNCACHING-HASH
X-HS-Cache-Config
X-Ttl
X-Ua-Browser
X-FTR-Backend-Server
X-FTR-Backend
Payment
X-FTR-Balancer
X-FTR-Cache-Status
X-Protected-By
X-Country-Code-Real
Public-Key-Pins
Server-Node
MicrosoftSharePointTeamServices
X-Shield-Request-Id
X-Forwarded-Proto
X-HS-Combine-CSS
X-SRCache-Store-Status
X-SRCache-Fetch-Status
TP-Cache
X-LLID
Arr-Disable-Session-Affinity
X-Frontend
X-Request-Received
X-Request-Processing-Time
X-Distributor
X-Accel-Expires
X-FTR-Expires
X-Jurisdiction
X-HP-Webp
X-HP-Trace-Id
X-Ratelimit-Remaining
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Origin-Cache-Key
X-TTL
Count-Hit
X-GUploader-UploadID
X-LB-Cache
X-Origin-Server
X-ORACLE-DMS-RID
X-NODE
X-Ezoic-Cdn
X-Hits
X-Content-Security-Policy-Report-Only
X-Microsite
X-Request-Handler-Origin-Region
X-AppVersion
X-Az
X-Activity-Id
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
Host
X-PressLabs-Stats
MRF-Tech
X-Www-Served-By
X-B3-TraceId-Primal
Mrf-Cache-Status
X-Cluster-Name
X-Varnish-Backend
X-Varnish-Server
X-App-Server
Cache-Tags
Retry-After
Accept-Charset
X-Amz-Meta-S3cmd-Attrs
X-Ua-Device
Server-Name
X-Hostname
X-Geo-Country
Cleartype
X-NGENIX-Cache
X-Envoy-Decorator-Operation
X-Id
X-Newrelic-App-Data
Referer-Policy
X-Goog-Metageneration
X-DIS-Request-ID
X-Upgrade-Enabled
TP-L2-Cache
X-Seen-By
X-Git-Hash
X-CSRF-Token
Access-Control-Allow-Method
TCN
X-ORACLE-DMS-ECID
X-Azure-Ref
X-Amzn-RequestId
X-Hcs-Proxy-Type
X-Amz-Apigw-Id
X-CCDN-CacheTTL
X-Load-Cache
X-CCDN-Origin-Time
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Unique-Id
X-F-Cache
X-Proxy
X-Oracle-Dms-Ecid
Healthy
X-RateLimit-Limit
X-Revision
X-Debug-Info
X-Grace
X-Cache-Control
X-Trace-Id
X-Request-Guid
Filterid
X-Px
Section-Io-Cache
Paypal-Debug-Id
X-B
X-B3-Sampled
X-FB-Debug
DC
X-TT
X-Fb-Rlafr
X-Contextid
X-Page-Id
X-Type
X-Logged-In
X-Varnish-Ttl
X-N
X-Mobile
X-Oracle-Dms-Rid
Viewport
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
X-Debug
X-Whom
X-Language
X-Template
Fastly-SIE
Fastly-SWR
X-Goog-Stored-Content-Encoding
Charset
X-Goog-Generation
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-XRDS-LOCATION
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
X-Datadog-Trace-Id
X-Cache-Grace
X-Content-Options
Version
Content-Disposition
X-Via-JSL
X-Time
X-EdgeConnect-Cache-Status
X-Wix-Request-Id
X-Magnolia-Registration
X-App-Environment
X-Varnish-Grace
X-Webkit-CSP
X-Signature
X-Node-Name
X-RateLimit-Reset
X-B-Cache
X-Rid
X-B3-SpanId
X-Origin-Cache
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-RemovedCookies
X-ProcessESI
SRV
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Datadog-Sampled
X-Debug-IsConnected
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Rule
X-Tumblr-Pixel-1
X-Debug-IsPreview
X-Tumblr-User
X-Hl-Ver
MS-CV
X-UUID
Ms-Operation-Id
X-RTag
X-Amzn-Remapped-Content-Length
X-G
SD-X-WS
X-Amz-Replication-Status
X-Adobe-Content
X-Proxy-Cache-Info
X-Storage
X-Adobe-Loc
X-Device-Type
ServerID
GEO-INFO
X-Backend-Name
X-NYM-Debug-Backend
X-Cacheable-TTL
X-FW-Serve
Liferay-Portal
X-FW-Server
X-FW-Static
X-FW-Type
X-Instance
X-Is-Bot
X-FW-Hash
X-FW-Dynamic
X-FW-Version
Country
X-Rendered-As
NGB
X-Region
X-L-Path
X-User-Agent
X-Environment-Context
X-Cache-Hit
X-Status
X-IPS-LoggedIn
X-Real-IP
X-Source
X-Cache-Age
X-NWS-UUID-VERIFY
Surrogate-Key
Countrycode
X-ServerID
Amp-Access-Control-Allow-Source-Origin
Akamai-GRN
X-Servername
X-Sucuri-Cache
X-WP-CF-Super-Cache-Active
X-Sucuri-ID
OT-Force-Account-Verify
Cross-Origin-Window-Policy
From-Origin
X-VC-Cache
X-UA
X-WebKit-CSP-Report-Only
X-Xrds-Location
X-RM-Cache-TTL
Backend
Upgrade-Insecure-Requests
X-Framework
Front
X-Air-Pt
X-Mode
X-INCAP-ABP
Refresh
X-AB
X-Content-Powered-By
X-DataDome
Frame-Options
X-Air-Hostname
X-Air-Source
X-Air-Trace-Id
X-Cache-Time
X-Akamai-Request-ID2
Xet-Cookie
X-HTML-Minification-Powered-By
X-Nginx-Cache
X-Buckets
X-Wormhole-Sdk
X-Handled-By
X-Edge-Location
Url
X-Vcache
Webserver
X-Endurance-Cache-Level
X-Xfnlog-Site
X-Rn-Rsrv
X-Proxy-Build
X-Origin-Date
X-UPSTREAM-Address
X-SaId
X-No-Session
X-B3-Traceid
X-Timing-Wait
X-Reqid
X-Rewrite-Enabled
X-RCS-CacheZone
X-JoinUs
Filters
Meta-Geo
Selected-Fe
X-Cluster
X-Webstats-RespID
Access-Control-Request-Headers
X-AWS-Id
X-Served-From
X-LJ-Flow-ID
X-Logging-Id
X-Akamai-Edgescape
X-Tumblr-Pixel-2
X-Provided-By
X-Git-Commit
Atl-Traceid
X-Cache-Rule
X-Cache-Operation
X-Drupal-Cache-Tags
X-Container-Uri
WPO-Cache-Message
WPO-Cache-Status
X-Labrador-Cache-Channel
X-Azure-Ref-OriginShield
X-Origin-CC
X-Origin-TTL
ServedBy
X-Origin
X-R9-Blue-Green-Version
X-VCT
X-VWS-Id
X-PHP-Host
Web-Mar-Node
X-Redis-Cache
X-Cms-Context
Cache
X-Routing-Service
X-Thinkindot-L3
X-Site-Version
X-Origin-Hint
X-Zipkin-Id
Webcakes-App-Name
TWC-Locale-Group
X-Hosted-By
TDXMobile
TWC-Connection-Speed
X-Httpd
Thinkindot-Control
Thinkindot-CacheControl
X-Web-Node
TWC-Device-Class
X-Tb
Section-Io-Id
TWC-GeoIP-LatLong
X-CDN-Forward
TWC-GeoIP-Country
TWC-Privacy
Webcakes-Region
X-Scope-Id
X-Drupal-Cache-Contexts
Property-Id
X-Cache-Status-Check
X-Extlb
X-ProxyCache-Key
X-Ms-Version
X-CMSURLCustom
X-Cache-Debug
X-Proxied
X-BYPASS-REASON
Mn-Server-Ip
X-Ms-Request-Id
X-ProxyCache-Status
X-Locale
X-Cloudmap
X-Shield-Cache-Expires
X-Accel-Version
Thinkindot-CacheControl-Type
X-Fetched-On
X-Adobe-Source
Webcakes-App-Version
X-VC
X-Forwarded-Host
X-Director
X-Geo-Region
X-Format
X-Frame-Option
X-Tcp-Rtt
X-Upstream-Ct
X-Varnish-Cache-Hits
X-Loop
X-Lambda-Id
X-Upstream-Ht
X-Browser-Name
X-Say-Cacheable
X-Say-TTL
X-SayCDN-TTL
Apigw-Requestid
X-Tncms
X-Is-Mobile
X-Is-Desktop
Accept-Language
X-Skip-Cache
X-Soup
X-Is-Supported-Browser
X-S
X-Restarts
X-Is-Tablet
X-Cdn-Origin
X-Alternate-Cache-Key
X-Sorting-Hat-ShopId
Cache-Hits
X-ShardId
X-Storefront-Renderer-Rendered
X-Detected-As
X-Sorting-Hat-PodId
X-ShopId
Xserver
X-Shopify-Stage
X-Cache-Host
X-IPLB-Request-ID
X-GeoCode
X-Generation-Time
X-Varnish-Beresp-Grace
X-GeoCountry
X-SRV
X-Varnish-Age
X-IPLB-Instance
X-Generated-By
X-Optimistic-Header
X-RID
X-Worker
X-Lagoon
X-Erf-Stays-Pdp-Viaduct-Migration-Web-V2
X-Vercel-Cache
X-Vercel-Id
X-Rocket-Nginx-Serving-Static
X-XRDS-Location
Source
Node
LB
X-Request-URI
Azure-Version
Azure-RegionName
Azure-SiteName
Azure-InstanceId
Azure-SlotName
X-WP-CF-Super-Cache-Cookies-Bypass
CDN-RequestCountryCode
CDN-RequestPullCode
CDN-RequestPullSuccess
CDN-PullZone
CDN-EdgeStorageId
CDN-Uid
CDN-CachedAt
X-App-Version
CDN-Cache
Fastcgi-Useragent
Protected
Cross-Origin-Embedder-Policy
X-Fastcgi-Cache
X-Pass-Why
X-Ratelimit-Reset
CDN-RequestId
Expiry
X-Connection-Hash
X-GEO
X-Tumblr-Pixel-3
X-URL
Alternate-Protocol
X-Vcl-Version
Onion-Location
X-Cache-Server
X-Cache-Expired-At
X-Tec-Api-Version
DB-Nickname
X-Tec-Api-Origin
X-Jobs
X-Tec-Api-Root
Priority
X-Server-W
AMP-Access-Control-Allow-Source-Origin
X-TA-CDN-Provider
Environment
X-PHP-Backend
CF-IPCountry
X-Api-Version
Uber-Trace-Id
X-DC
X-Fastly-Request-Id
Sid
X-Proxy-Cache-Status
X-Cache-Action
X-LSADC-Cache
X-Cluster-Node
X-Urbn-Site-Id
X-Urbn-Context-Path
X-Original-Request-Id
X-MP-GENERATED-AT
X-Response-Served-From
X-Uri
Locale
User-Cache-Control
X-Mg-Request-UUID
X-Tx-Id
HostName
X-TT-LOGID
X-FB-TRIP-ID
X-Gen-Mode
X-Generated-On
X-Cache-Id
X-A-Dam
X-Varnish-Beresp-Ttl
Wxu-Next-Commit
X-Forwarded-Site
Vix-Hermes-Req-Id
X-Block-Status
X-Cache-NE
X-GeoIP-City
Cache-Tv-Group
X-BCube-Filmed-By
Candidate-Md5Url
X-Bc-Bl
X-Gzip
X-Bip
Wxu-Next-Hostname
X-A-Dcw
Ngx.Var.Host
X-Bl-Debug
Edge-Cache
DCR-Processing-Time-Ms
X-Clientip
X-Device-Os
X-Dispatcher-Server
X-Ec-Fail
X-Developer
X-A
X-Content-Age
X-D
X-Conf
X-Ec-GeoHdr
A
X-Esi-Check
X-Aed
DCR-Decision-By
X-A-Ccd
X-Epic-Correlation-Id
Content-Secure-Policy
X-A-Dgt
X-A-Wwc
Wxu-Next-Region
X-FC-Vary-Parameters
X-Node-Id
Rendered-Blocks
X-SRCache-Key
X-Thanos
X-TIM-N
X-UA-Device-Type
Req-ID
X-ScT
Cdn-Requestid
Server-Host
X-Hnp-Log
X-SB
X-LiteSpeed-Cache-Control
Lang
X-Varnish-Hostname
X-Vtex-Remote-Cache
X-VTEX-Cache-Time
Meta-Geo-Continent
Origin-Agent-Cluster
Origin
X-VTEX-Cache-Server
X-Viewer-Country
Magicmarker
X-Tt-Logid
X-Vdms-Path
X-Vdms-Version
MD5-Digest
X-Request-Start
X-Rojux
X-ND-Cache
X-NCache
Fusion-Component-Id
Fusion-Content-Source
X-Op-Id-All
X-Mvc-Supplant-Cachable
Surrogated-Key
T-Server
X-Ig-Origin-Region
X-Jungle-Id
X-Level-Front-Cache
X-Org
Fusion-Content-Id
Sslversion
X-Platform
Fusion-Source
X-Origin-Expires
X-Powered-By-VTEX-Cache
Fusion-Deployment-Id
Fusion-Template-Id
X-Proto
Gannett-Cam-Experience-Id
WP-Super-Cache
X-Origin-Response-Time
Origin-CC
NM-Fastcgi-Cache
Server-Hostname
X-Amz-Storage-Class
W
Origin-EX
X-App-Name
Powered-By
Release
Sever-Int
PFcat
X-AK-Request-ID
Ssr
Server-Ext
We-Hiring
X-GeoIP-Region-Code
X-Req
X-Region-Sid
X-Request-Time
X-Scheme
X-SD-PageType
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-Nyt-Route
X-Origin-Time
X-PAYTM-SRV-ID
X-PERF
X-Test
X-V-Cache
XM
X-WA-Info
Yak-Timeinfo
X-Policy
X-Pubstack
X-Via-Fastly
X-VG-WebCache
X-Var-Ttl
X-Varnish-Director
X-VarnishDD-TTL
X-Varnishpool
X-NMSegId
X-Nginx-Cache-Key
X-Csrf-Jwt
X-Core-Value
X-CUA
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-CGP
X-Cdn-Srv
X-Backend-Instance
X-Cache-Bucket
X-Cache-Info
X-Cache-TTL-Remaining
X-Edge-Server
X-Eu-Site
X-HN
X-HS-Content-Campaign-Id
X-Loc
X-Mvc-Supplant-OutputCached
X-GeoIP-Country-Code
X-GeoIP
X-Fastly-Cache
X-Fmm-Version
X-Gdpr
X-Geo-Header
X-Auth-Group-Type
X-ApacheServer
Canary
Host-ID
X-Service
CDCHOST
Cdn-Host
HA-Ipaddr
Ha-Gx-Prefs
C-Via
Fastly-Backend-Name
Fastly-SSL
Cache-Provider
AKAMAI
Cdn-Request-Time
DSUID
X-Client-Ip
L5d-Success-Class
Mail-Subject
Cdnsip
X-Nf-Request-Id
Content-Script-Type
Cdncip
Content-Style-Type
X-Aicache-OS
X-Pool
Click-Count-Action-Start
Cache-Key
X-Cache-Backend
Apple-News-Services-Request-Url
X-Render-Time
X-Proxied-Request
X-Zone
X-B3-Trace-ID
Apple-News-Services-Parsed-Url
X-BBC-Edge-Cache-Status
X-CacheTTL
X-Fastly-Backend
X-ID
X-Location
X-Men
X-Human
X-Wikidot-Static-Cache
X-ECache
X-From
X-We-Are-Hiring
X-Wikidot-Backend
X-Micro-Cache
X-Ec-Custom-Error
X-Ismobilevalue
X-Ad-Load-Variation
X-VG-TLSProxy
Apple-News-Services-Handled
Adler-Geo
X-Ig-Push-State
X-DPWN-IS-SECURE
X-Mly-Id
X-Varnish-Beresp-Status
Apple-News-Services-Host
X-Auto-Login
X-Server-IP
On-Server
X-SVT-ORM-VERSION
Fastly-GeoIP-CountryCode
Tube-Get-Contents
Tube-Return
Tube-Got-Results
Tube-Got-Eval
X-Acquia-Purge-Cdn-Unconfigured
X-SVT-ORM-RULES
Is-Eu
Producers
L
Pramga
Platform
Machine
X-Sn-Servicetimems
Req-Svc-Chain
X-Section
True-Client-Country-4JS
X-Tb-Optimization-Total-Bytes-Saved
Country-Code
Web-Mar-Region
X-Request-Host
Esi-Enabled
Click-Count-Error
V-Age
X-Access
Redirect-Candidate
X-Newrelic-Synthetics
X-GoCache-CacheStatus
X-Contensis-Viewer-Groups
RNT-Time
Cluster
Odigeo-Trace-Id
X-Accel-Expires-Debug
X-Date
RNT-Machine
X-Varnish-Authentication
Gh-Request-Id
X-Slack-Shared-Secret-Outcome
X-Up
X-Cache-Aspx
X-Hash
Proxy-Firewall
X-Slack-Backend
NGX
Datacenter
X-AIR-PT
X-NGINX-Cache
X-LB-ID
X-NodeID
Debug
X-Custom-Header
X-Varnish-Hits
Fastly-Drupal-HTML
X-Cs
X-Nananana
X-Dc
X-COUNTRY
X-Pad
SID
X-HA-Backend
Pics-Label
X-DefElseHash
X-Varnish-CookieINHashed-On
X-Varnish-CookieHashed-On
X-Varnish-Remaining-TTL
CloudFront-Viewer-Country
X-Refresh
X-Via-Poph
X-DefHash
X-CACHE-GROUP
X-Via-Popv
Locid
X-Via-Popn
Mime-Version
X-Platform-Router
X-LiteSpeed-Tag
X-Platform-Processor
X-Servedbyhost
X-Akamai-Transformed
X-Amz-Meta-Cb-Modifiedtime
X-Platform-Cluster
X-VHOST
X-Depends
X-VC-TTL
X-CACHE-AGE
GeoIP-Latitude
X-TIME
X-Cached-By
X-Datadome
X-Old-Content-Length
X-M-Log
X-Cache-FS-Status
X-Parent-Response-Time
Ngx-Var-Key
X-M-Reqid
X-LB-NoCache
X-B3-Parentspanid
X-Moov-T
X-Moov-Xdn-Version
X-TH-Server
Server-ID
X-CS
X-DynaTrace-JS-Agent
Cdn
Cross-Origin-Embedder-Policy-Report-Only
Server-Info
X-CDN-Cache-Status
X-Wa
X-Nc
Resin-Trace
Fastly-Drupal-Html
Cf-Ipcountry
BehaviorPad-Version
X-Litespeed-Tag
NtCoent-Length
GeoIp-Country-Code
X-Presslabs-Stats
X-ZONE
X-User
X-External-Request-Id
X-B-Cookie
Cf-Device-Type
X-Fpc
X-S-Cookie
X-Application
X-VCache
X-Vgn-Hpd-Reason
X-HITS
X-IAuth-Set-Uid
X-Destination
Uri
X-APP
X-Vc
X-NewRelic-App-Data
FSS-Cache
X-Zen-Fury
X-Flags
X-Aspnet-Duration-Ms
X-Srv
X-Providence-Cookie
X-Route-Name
X-Is-Crawler
True-Client-IP
X-Sigma-Backend
X-Sigma
X-Rocket-Build-Number
X-Esi
X-Cache-Date
True-Client-Ip
X-Content-Length
X-Instance-Name
CDN
X-TX-ID
X-HostName
Serverhost
X-Varnish-Beresp-TTL
X-VServer
X-DynaTrace
X-Dynatrace-Js-Agent
X-API-Version
GeoIP-Country-Code
Tcn
Load-Balancing
X-Branch-Name
X-Segment-20210421
S-Rt
X-Oracle-DMS-ECID
X-Page-View
X-Cdn-Cache-Status
X-HOST
X-Dispatcher-Number
Hostname
X-Cdn-Forward
Srv
Ohc-File-Size
Vc-Max-Age
Request-ID
X-NC
X-Dispatch
X-RequestId
Product
X-WA
X-FPC
X-DataCenter
Type
ServerName
X-Sql-Duration-Ms
X-APP-VERSION
X-B3-Spanid
X-Sql-Count
X-Http-Reason
X-Irp-Debug
X-FL-QIT-DEBUG
Srvid
Server-Id
Geoip-Latitude
X-Webkit-Csp-Report-Only
X-Geo
Cl-Cache
X-Ckpd-Fst-Backend
X-Bug-Bounty
X-VCL-Version
X-Lb-Nocache
X-CSRF-TOKEN
X-Owner
DataCenter
X-Via-CDN
X-ServedByHost
X-Via-SSL
Edge-Copy-Time
X-Via-Edge
IsBot
X-SIPLIST1
WZWS-RAY
CacheControlHeader
Cloudfront-Viewer-Country
Cross-Origin-Opener-Policy-Report-Only
Ohc-Cache-HIT
Origin-Trial
X-App
Epwk-X-Cache
X-Proxy-CacheRZ
MIME-Version
X-Core-Mission
X-CACHE-KEY
XkeyRZ
X-Hit
X-Cache-Ttl
X-Ua
X-Ha-Backend
N-Cache
X-Qloud-Router
CountryCode
X-Via-PopH
X-Via-PopN
X-Correlation-ID
PICS-Label
X-Via-PopV
X-Srcache-Fetch-Status
X-Srcache-Store-Status
Rtss
ServerHost
X-MiniProfiler-Ids
X-MSEdge-Flight
X-Fastly-Country-Code
X-Lb-Id
X-MSEdge-Features
X-Amz-Meta-Opti
Lb
X-Web-Server
X-Acquia-Application-UUID
X-Acquia-Application-Trace
X-Sqd-Ctime
X-Acquia-Purge-Tags
X-Acquia-Site
Cneonction
X-Datacenter
Sm-Log-Id
X-Service-Response-Time
Warning
X-Vmg-Version
X-Limited
User-Agent
X-Akamai-Device-Characteristics
X-Sqd-Stime
X-LAGOON
X-Litespeed-Cache-Control
X-Gamma-Serve
X-Iplb-Instance
X-Iplb-Request-Id
X-Amz-Meta-S3b-Last-Modified
X-IN-APIGATEWAYSSL
X-Dw-Trace-Id
X-Amz-Meta-Sha256
X-IN-APIGATEWAY
X-Udemy-Cache-App-Namespace
Xkey-La3
Expect-Staple
X-Akamai-Pragma-Client-IP
X-RAMCache
X-Tenant
X-CF-Lambda-Fn
X-Cdn-Request-ID
Akamai-Cache-Status
X-Requestid
X-Cache-Type
X-CF-Lambda-Version
X-Orig-Expires
X-Forwarded-Path
Ngx
Xkeylog
X-Proxy-Cache-La3
X-Snapshot-Date
X-Ramcache
X-Check-Cacheable
X-Serial
X-Th-Server
X-Shop-Environment