Threat Level: green Handler on Duty: Johannes Ullrich

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
X-Frame-Options
Expires
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Accept-CH
Last-Modified
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
X-XSS-Protection
X-Cache
X-Powered-By
Pragma
Via
CF-RAY
Age
Content-Security-Policy
Alt-Svc
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
X-Amz-Cf-Pop
X-Amz-Cf-Id
Content-Language
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-Download-Options
X-Xss-Protection
X-Request-Id
X-Timer
CF-Ray
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
Accept-CH-Lifetime
X-DNS-Prefetch-Control
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
Permissions-Policy
X-Drupal-Cache
Server-Timing
X-Generator
X-Envoy-Upstream-Service-Time
X-FRAME-OPTIONS
X-Cache-Status
X-Ua-Compatible
X-Cacheable
X-Iinfo
X-Drupal-Dynamic-Cache
X-CONTENT-TYPE-OPTIONS
Timing-Allow-Origin
Accept-Ch
Feature-Policy
X-XSS-PROTECTION
X-Content-Security-Policy
Xkey
Upgrade
Access-Control-Expose-Headers
X-CDN
Content-Encoding
Status
X-AspNetMvc-Version
Access-Control-Max-Age
X-Amz-Request-Id
X-Amz-Id-2
Host-Header
X-Age
Request-Context
X-Backend
Cf-Edge-Cache
X-Amz-Version-Id
X-Robots-Tag
X-Hacker
Keep-Alive
Cf-Apo-Via
X-Via
X-Turbo-Charged-By
X-Vhost
X-AH-Environment
X-Rq
CONTENT-SECURITY-POLICY
X-Server
X-Dispatcher
X-Cache-Group
X-Proxy-Cache
X-Request-ID
X-Ws-Request-Id
EagleId
X-UA-Device
X-Varnish-Cache
Pantheon-Trace-Id
Grace
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Litespeed-Cache
X-Server-Powered-By
X-WebKit-CSP
X-OneAgent-JS-Injection
X-Dns-Prefetch-Control
X-Pingback
X-Page-Speed
Allow
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Swift-SaveTime
X-Swift-CacheTime
X-Cache-Lookup
Ali-Swift-Global-Savetime
X-Device
X-FTR-Request-ID
X-Node
X-Host
X-Server-Id
EagleEye-TraceId
X-Backend-Server
X-Country-Code
Surrogate-Control
X-Cloud-Trace-Context
X-Ruxit-JS-Agent
Cf-Railgun
X-Readtime
X-Akam-SW-Version
P3p
X-HW
X-Response-Time
Cache-Tag
X-Amz-Server-Side-Encryption
X-LiteSpeed-Cache
X-Ua-Device
Accept-Ch-Lifetime
Content-Location
X-Content-Type
Cross-Origin-Opener-Policy
X-Nginx-Cache-Status
X-Nginx-Upstream-Cache-Status
X-Rack-Cache
Request-Id
Service-Worker-Allowed
X-Trace
X-TraceId
X-Application-Context
Fastly-Restarts
X-Nf-Request-Id
X-Element-Page-Cache
X-D2id
X-Times
X-PC
X-Vname
X-TtlSet
X-Oneagent-Js-Injection
Rating
X-Clacks-Overhead
X-Country
X-Cnection
X-Navigation-Version
X-Mcache
X-Edge
X-Midtier
X-Vcap-Request-Id
X-FTR-Cache-Status
X-FTR-Backend-Server
Origin-Trial
X-FTR-Balancer
X-Country-Code-Real
X-FTR-Backend
X-Browser-Type
X-FTR-Expires
Edge-Control
X-ESI
X-Cache-TTL
X-Url
Surrogate-Key
X-NWS-LOG-UUID
X-FastCGI-Cache
X-Exp-Id
X-GoogleNews-Bot
X-Kinja
X-Kinja-Build
X-Kinja-Revision
X-Exp-Variant
X-Kinja-Server
X-Cdn-Fetch
X-Powered-By-Plesk
X-Ac
X-Abt-Application-Version
X-Upstream
X-Mod-Pagespeed
X-Amz-Rid
Verso
X-ORACLE-DMS-RID
X-ECACHE
X-Language
X-B3-TraceId
Nginx-Cache
X-Pinterest-Rid
Pinterest-Version
Pinterest-Generated-By
Akamai-GRN
X-GitHub-Request-Id
X-MS-InvokeApp
Pagespeed
Display
X-Middleton-Display
X-Sol
S
X-Instrumentation
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-Erf-Bev-Bev-Is-Generated
X-PDP-UNCACHING-HASH
X-Erf-Bev-Bev
X-Envoy-Decorator-Operation
X-Request-Device-Id
Response
X-Amzn-Trace-Id
AR-ATIME
AR-PoweredBy
AR-Request-ID
X-Middleton-Response
Edge-Cache-Tag
X-SharePointHealthScore
SPRequestDuration
SPIisLatency
SPRequestGuid
X-Distributor
X-T
X-Goog-Hash
X-Ratelimit-Limit
X-Resp-Is-Stale
X-Meli-Trace-Bu
X-Meli-Trace-Site
X-Ser
X-Meli-Trace-Platform
X-Edge-Location-Klb
X-Kinsta-Cache
X-Ruxit-Js-Agent
X-ARC
Access-Control-Request-Method
X-NGENIX-Cache
X-Shield-Request-Id
Front-End-Https
X-Dw-Request-Base-Id
X-Client-IP
X-Content-Digest
X-Ezoic-Cdn
RTSS
X-Recruiting
X-Cache-Key
X-Request-Received
X-Request-Processing-Time
Cache-Status
X-Ttl
X-Version
X-Mg-S
X-Varnish-TTL
Ar-SID
YJS-ID
X-Ismobilevalue
X-HS-Content-Id
X-HS-Hub-Id
X-Powered-CMS
TP-Cache
Public-Key-Pins
X-HS-Cache-Config
X-Accel-Expires
Fastcgi-Cache
X-MSEdge-Ref
AR-CACHE
X-Amz-Replication-Status
Cache-Tags
X-Cached
Arr-Disable-Session-Affinity
X-Cluster-Name
X-Correlation-Id
X-Newrelic-App-Data
X-Daa-Tunnel
Realpath
X-Content-Security-Policy-Report-Only
X-Fastly-Request-ID
X-RateLimit-Remaining
X-Id
Content-MD5
X-HS-Combine-CSS
X-Server-Name
X-Azure-Ref
Payment
X-Ua-Browser
X-HP-Trace-Id
X-HP-Webp
X-Cambria-Cache-Control
X-Jurisdiction
X-Kong-Proxy-Latency
X-DIS-Request-ID
X-Kong-Upstream-Latency
X-Xrds-Location
X-Forwarded-For
X-HS-Prerendered
X-HS-CF-Cache-Status
X-GUploader-UploadID
X-TTL
MicrosoftSharePointTeamServices
Content-Disposition
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Protected-By
X-Px
X-Ratelimit-Reset
Count-Hit
X-AppVersion
X-Az
X-Unique-Id
X-Activity-Id
X-Origin-Server
X-Page-Id
X-Hits
X-Logged-In
X-Rid
X-ORACLE-DMS-ECID
X-Git-Hash
Accept-Charset
Cross-Origin-Resource-Policy
Cleartype
X-Amz-Meta-S3cmd-Attrs
X-Request-Handler-Origin-Region
X-Proxy
X-FB-Debug
X-VARITI-CCR
X-Microsite
Cross-Origin-Embedder-Policy
X-Www-Served-By
Version
X-Load-Cache
X-TEC-API-VERSION
X-LLID
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Goog-Metageneration
X-Geo-Country
X-Ratelimit-Remaining
X-Forwarded-Proto
X-Template
X-Varnish-Backend
X-PressLabs-Stats
X-Upgrade-Enabled
Server-Node
X-COUNTRY
X-B3-Sampled
X-WebKit-CSP-Report-Only
X-App-Server
Server-Name
Healthy
X-Hostname
Access-Control-Allow-Method
AKAMAI-GRN
X-Content-Options
X-Frontend
X-SERVER-NAME
Section-Io-Cache
Viewport
X-Requestid
X-Varnish-Grace
X-Grace
X-Fb-Rlafr
X-Device-Type
X-TT
X-Cache-Age
Fastly-SWR
Fastly-SIE
X-Request-Guid
X-B
X-Varnish-Server
Alternate-Protocol
X-Contextid
MRF-Tech
Mrf-Cache-Status
X-B3-TraceId-Primal
X-Status
X-ProcessESI
X-RemovedCookies
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-Varnish-Ttl
X-Goog-Generation
DC
X-CST
X-CSRF-Token
TCN
X-Hl-Ver
Upgrade-Insecure-Requests
X-Amzn-Remapped-Content-Length
X-EdgeConnect-Cache-Status
X-Magnolia-Registration
X-Webkit-Csp
Retry-After
X-App-Version
MS-Author-Via
X-Cache-Control
Host
Frame-Options
X-Origin-CC
X-Origin-TTL
X-Yandex-Req-Id
X-Type
X-Response-Served-From
X-Original-Request-Id
X-Revision
X-Oracle-Dms-Ecid
X-Debug
SD-X-WS
X-Buckets
Amp-Access-Control-Allow-Source-Origin
X-Mobile
X-Backend-Name
X-Seen-By
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Instance
X-G
X-INCAP-ABP
X-UUID
X-Tt-Trace-Tag
X-ServerID
X-Tt-Trace-Host
X-Is-Bot
X-Lambda-Id
X-Yottaa-Metrics
X-Yottaa-Optimizations
Cross-Origin-Opener-Policy-Report-Only
Cross-Origin-Embedder-Policy-Report-Only
X-Adobe-Content
X-Adobe-Loc
X-Cache-Status-Check
X-NYM-Debug-Backend
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-Tumblr-User
X-N
Xet-Cookie
X-Akamai-Edgescape
X-Rendered-As
Cache
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
Access-Control-Request-Headers
X-Content-Powered-By
X-Mg-Request-UUID
X-RTag
X-Trace-Id
X-Framework
X-Akamai-Request-ID2
Ms-Operation-Id
NGB
Section-Io-Id
MS-CV
X-AB
X-Debug-IsConnected
X-Debug-IsPreview
X-Server-W
X-Storage
X-RM-Cache-TTL
Charset
X-Dc
YJS-CacheStatus
Webserver
Paypal-Debug-Id
Filterid
X-Vcl-Version
X-DataDome
X-Tec-Api-Version
X-VC-Cache
X-Tec-Api-Root
X-Fastcgi-Cache
X-Tec-Api-Origin
Accept-Language
X-Ms-Request-Id
Selected-Fe
X-B3-SpanId
X-Timing-Wait
X-Ms-Version
X-Proxy-Build
Onion-Location
X-ProxyCache-Status
X-Cacheable-TTL
X-Cache-Time
X-BYPASS-REASON
Refresh
X-ProxyCache-Key
X-Cache-Hit
X-User-Agent
SRV
X-F-Cache
X-Time
X-Node-Name
X-Region
X-VC
X-Real-IP
X-Origin-Cache
X-Request-Site
Priority
X-Request-Bu
X-Request-Platform
Liferay-Portal
Apigw-Requestid
GEO-INFO
X-CCDN-Origin-Time
X-CCDN-CacheTTL
X-Hcs-Proxy-Type
X-Server-ID
Front
X-Environment-Context
X-L-Path
X-Mode
X-HTML-Minification-Powered-By
X-Service
CDN-RequestId
X-IPS-LoggedIn
X-LB-Cache
X-Rule
X-UPSTREAM-Address
X-Tb
Country
X-VCT
X-Rn-Rsrv
X-Rocket-Nginx-Serving-Static
X-Drupal-Cache-Tags
X-SaId
X-Rewrite-Enabled
X-Mly-Id
X-Origin
X-JoinUs
Meta-Geo
X-Cache-Expired-At
Backend
X-ECache
X-Datadog-Sampled
X-Is-Mobile
X-Is-Desktop
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
X-Is-Mobile-Only
X-Is-Supported-Browser
X-Is-Modern-Browser
X-Api-Version
X-Geo-Region
X-Datadog-Trace-Id
X-Handled-By
X-Adobe-Source
Cross-Origin-Window-Policy
X-Wix-Request-Id
X-Pass-Why
X-Tcp-Rtt
X-Browser-Name
X-Is-Tablet
Mn-Server-Ip
X-Optimistic-Header
X-CLOUD-TRACE-CONTEXT
X-Web-Node
X-Generation-Time
X-Provided-By
TWC-GeoIP-LatLong
TWC-GeoIP-Region
TWC-GeoIP-DMA
TWC-GeoIP-Country
TWC-Locale-Group
TWC-Privacy
Web-Mar-Node
Url
Uber-Trace-Id
TWC-GeoIP-City
X-RCS-CacheZone
X-Shopify-Stage
X-Zipkin-Id
Fastcgi-Useragent
Expiry
X-Servername
X-Routing-Service
Webcakes-App-Name
Property-Id
X-Storefront-Renderer-Rendered
TWC-Connection-Speed
Webcakes-App-Version
X-Proxy-Cache-Info
X-Forwarded-Host
X-FB-TRIP-ID
X-Extlb
X-Tncms
X-Httpd
X-Origin-Date
X-Origin-Hint
X-Proxied
X-Detected-As
X-Connection-Hash
X-Alternate-Cache-Key
X-Vcache
Webcakes-Region
X-Varnish-Beresp-Grace
X-RateLimit-Remaining-Second
X-Cloudmap
X-Cdn-Origin
X-RateLimit-Limit-Second
X-Loop
TWC-Device-Class
X-Whom
ServerID
X-Tt-Logid
X-WP-CF-Super-Cache-Active
X-Cluster
X-Cms-Context
X-Cache-Debug
X-Auth-Group-Type
X-Tumblr-Pixel-3
X-Director
X-Soup
X-Redis-Cache
X-Tumblr-Pixel-2
X-Logging-Id
X-Locale
X-MP-GENERATED-AT
X-Hosted-By
ServedBy
X-Fetched-On
X-Format
OT-Force-Account-Verify
X-App-Environment
Atl-Traceid
DB-Nickname
X-Skip-Cache
X-Cache-Action
X-Hit
X-Debug-Info
X-Restarts
X-FW-Version
Protected
X-Cache-Host
Environment
X-Cluster-Node
X-Endurance-Cache-Level
X-FW-Hash
X-FW-Serve
X-FW-Server
X-FW-Dynamic
X-FW-Type
X-FW-Static
Cache-Hits
X-Edge-Location
X-Say-Cacheable
X-Scope-Id
X-SayCDN-TTL
X-Urbn-Site-Id
X-Urbn-Context-Path
Locale
Node
X-Served-From
X-Say-TTL
X-Platform
Filters
X-S
X-PHP-Host
X-CDN-Forward
Countrycode
X-Drupal-Cache-Contexts
X-HITS
X-IPLB-Request-ID
X-Labrador-Cache-Channel
X-IPLB-Instance
LB
X-R9-Blue-Green-Version
X-XRDS-Location
X-B3-Traceid
Xserver
X-CDN-Cache-Status
AMP-Access-Control-Allow-Source-Origin
X-GEO
WPO-Cache-Status
X-No-Session
X-Sorting-Hat-ShopId
X-NWS-UUID-VERIFY
X-ShardId
X-WP-CF-Super-Cache-Cookies-Bypass
X-Varnish-Age
X-ShopId
X-Client-Ip
X-Sorting-Hat-PodId
X-Presslabs-Stats
Request-ID
X-Ua
X-Generated-By
X-Lagoon
X-Varnish-Cache-Hits
X-Varnish-Beresp-Ttl
Cache-Tv-Group
X-Signature
X-B-Cache
Referer-Policy
X-Clientip
Expect-Staple
X-SRCache-Key
X-UA
X-Upstream-Ct
X-Upstream-Ht
X-Azure-Ref-OriginShield
We-Hiring
Mail-Subject
X-TA-CDN-Provider
X-URL
X-Webstats-RespID
X-Cache-Rule
X-Cache-Operation
X-IsAdmin
X-SRV
X-Site-Version
X-PHP-Backend
X-Cache-FS-Status
X-Worker
CloudFront-Viewer-Country
X-NewRelic-App-Data
Location
X-Auto-Login
From-Origin
Cache-Provider
X-Server-IP
X-Cs
X-Bc-Bl
X-FORWARDED-FOR
Fl-Custom-Application
X-VWS-Id
X-Accel-Version
X-AWS-Id
X-Fastly-Request-Id
X-LJ-Flow-ID
X-ND-Cache
X-Tb-Optimization-Total-Bytes-Saved
N-Cache
X-Vtex-Remote-Cache
X-Org
Lang
Meta-Geo-Continent
MD5-Digest
Origin
X-Content-Age
Pragrma
Redirect-Candidate
X-PERF
X-LSADC-Cache
Host-ID
X-Vdms-Version
WPO-Cache-Message
X-D
X-Destination
DCR-Decision-By
Origin-Agent-Cluster
DCR-Processing-Time-Ms
X-External-Request-Id
X-GeoCountry
Candidate-Md5Url
X-Rojux
X-GeoCode
S-Rt
X-Ig-Origin-Region
Xc-Version
X-Developer
X-Conf
Source
X-Ec-Fail
X-Ig-Push-State
X-Ec-GeoHdr
X-Loc
Ngx.Var.Host
X-A-Dgt
Sslversion
X-A-Dcw
X-A-Dam
X-A-Wwc
X-Application
X-B-Cookie
X-BCube-Filmed-By
X-Bl-Debug
X-ScT
X-ApacheServer
X-Aed
X-A-Ccd
X-S-Cookie
Rendered-Blocks
Sid
X-A
X-Cache-NE
X-Xfnlog-Site
X-VC-TTL
X-Litespeed-Cache-Control
X-Epic-Correlation-Id
X-Ee-Request-Date
X-Access
X-Ee-Request-Id
Country-Code
X-Fastly-Backend
CDN-RequestPullCode
CDN-RequestPullSuccess
X-Action
CDN-RequestCountryCode
CDN-PullZone
CDN-CachedAt
CDN-EdgeStorageId
CDN-Uid
Cdncip
X-FC-Vary-Parameters
X-Ee-Origin
X-AK-Request-ID
Cluster
X-Fmm-Version
Cdnsip
X-Forwarded-Site
X-Eu-Site
Gannett-Cam-Experience-Id
X-Csrf-Jwt
X-Core-Value
ServerName
X-CUA
CDN-Cache
Odigeo-Trace-Id
RNT-Time
Origin-Site
X-Cms-Device
X-Contensis-Viewer-Groups
Powered-By
X-CGP
RNT-Machine
X-CacheTTL
Store-Cloud-Cache
X-Cache-Aspx
Wxu-Next-Commit
Ha-Gx-Prefs
Gh-Request-Id
Wxu-Next-Hostname
Fastly-SSL
Wxu-Next-Region
X-Depends
Web-Mar-Region
Time-Cloud-Cache
X-Bug-Bounty
Log-Origin
L5d-Success-Class
IsBot
X-Ee-Generated-By
X-Gamma-Serve
X-Varnish-Director
X-Varnish-Hostname
X-Varnish-Beresp-Status
X-Varnish-Authentication
X-Policy
X-V-Cache
X-Vary-Devices
X-PAYTM-SRV-ID
X-Node-Id
X-Mvc-Supplant-Cachable
X-Old-Content-Length
X-Origin-Expires
X-VG-WebCache
Mime-Version
X-Sn-Servicetimems
X-Section
X-Rocket-Build-Number
X-SD-PageType
X-Tx-Id
X-Save-Cache
X-Aicache-OS
X-Sigma
X-Slack-Shared-Secret-Outcome
X-Req
X-Slack-Backend
X-SIPLIST1
X-Sigma-Backend
X-Micro-Cache
X-VG-TLSProxy
Apple-News-Services-Handled
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
X-GeoIP-Region-Code
X-GoCache-CacheStatus
X-HS-Content-Campaign-Id
X-Hash
X-Internal-TTL
X-GeoIP-City
X-GeoIP-Country-Code
Canary
X-From
X-Parent-Response-Time
X-SB
X-Block-Status
X-Sucuri-Cache
X-Bip
X-Region-Sid
X-SVT-ORM-RULES
X-Thanos
X-Pubstack
X-SVT-ORM-VERSION
X-Cache-Date
X-Gdpr
X-Thinkindot-L1
X-Varnish-CookieINHashed-On
X-Gen-Mode
X-Amz-Storage-Class
X-Reqid
X-Generated-On
X-Request-URI
X-App-Name
X-Thinkindot-L3
X-Backend-Instance
X-BBC-Edge-Cache-Status
X-Render-Time
X-Varnish-Remaining-TTL
X-Akamai-Device-Characteristics
X-Shield-Cache-Expires
X-HN
X-Ion-Healthy
X-Nyt-Route
X-Debug-Cache-Fetch
X-Date
X-NMSegId
X-Dispatcher-Server
X-We-Are-Hiring
X-Op-Id-All
NM-Fastcgi-Cache
X-Debug-Cache-Store
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-Jungle-Id
X-Level-Front-Cache
X-Men
X-Mvc-Supplant-OutputCached
X-Ion-Hop
X-Vmg-Version
X-Viewer-Country
X-Human
X-DefHash
X-DefElseHash
X-Hnp-Log
X-Uri
X-Proto
X-Ec-Custom-Error
X-Varnish-CookieHashed-On
X-VarnishDD-TTL
X-Content-Length
Server-Host
X-Via-Fastly
X-Up
X-Frame-Option
X-Origin-Time
Vix-Hermes-Req-Id
X-Path
X-UA-Device-Type
Nord-Request-ID
AR-SID
Machine
Origin-CC
X-Acquia-Purge-Cdn-Unconfigured
TDXMobile
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
RewriteTestHook
Origin-EX
Load-Balancing
Pics-Label
Release
Req-Svc-Chain
RewriteTeamHook
Cmsid
L
Azure-InstanceId
Content-Style-Type
CDCHOST
DSUID
X-AB-Test
Content-Script-Type
X-Accel-Expires-Debug
Cmstype
Cache-Contol
V-Age
Azure-SiteName
Azure-RegionName
Azure-SlotName
User-Cache-Control
Fastly-Backend-Name
Azure-Version
PFcat
X-Cached-By
X-CACHE-AGE
CF-IPCountry
X-Esi-Check
X-Edge-Server
X-DPWN-IS-SECURE
C-Via
Click-Count-Action-Start
X-Vercel-Id
X-Gzip
Click-Count-Error
X-Cache-Id
X-Vercel-Cache
Platform
X-Moov-T
X-Moov-Xdn-Caching-Status
X-Moov-Xdn-Version
X-NGINX-Cache
X-Location
CacheControlHeader
X-ZONE
Cdn-Request-Time
Cdn-Host
Producers
X-Proxied-Request
X-B3-Trace-ID
Fastly-GeoIP-CountryCode
Tube-Get-Contents
Tube-Got-Eval
Tube-Got-Results
Tube-Return
X-ElasticPress-Query
X-Pad
X-NF-Request-ID
Cookie
X-Sucuri-ID
X-Origin-Response-Time
XM
X-Datadome
X-Varnish-Hits
X-Nginx-Cache-Key
NGX
X-Via-Popv
X-Via-Popn
X-Via-Poph
X-Debug-Service
True-Client-Country-4JS
Fastly-Drupal-HTML
X-Refresh
X-AIR-PT
Debug
Server-Hostname
X-Srv
Sever-Int
X-Air-Pt
Server-Ext
X-HA-Backend
X-Webkit-CSP
X-APP
Show-Do-Not-Sell-Link
X-Wormhole-Sdk
Traceparent
X-Servedbyhost
X-Cache-Backend
X-Ez-Minify-Html
GeoIp-Country-Code
GeoIP-Latitude
HostName
X-Unity-Cache
DataCenter
Server-ID
X-LB-ID
X-DynaTrace-JS-Agent
X-TH-Server
X-Nananana
Product
WZWS-RAY
HA-Ipaddr
Fastly-Drupal-Html
X-Zone
X-Litespeed-Tag
X-Source
X-B3-Parentspanid
X-Amz-Meta-Cb-Modifiedtime
X-Fpc
Cdn
X-Cache-VC
X-GeoIP
X-Nc
X-Newrelic-Synthetics
Tcn
X-Wa
X-VCL-Version
X-Cdn-Forward
Lb
X-User
Edge-Cache
X-CDN-Provider
X-AC
SID
X-Nginx-Cache
X-B3-Spanid
XkeyR9
A
Serverhost
Xkeylog
X-Proxy-CacheR9
X-Proxy-Cache-La3
Xkey-La3
Resin-Trace
CountryCode
X-TX-ID
X-TT-LOGID
X-Vc
X-Datacenter
Cs
X-LB-NoCache
X-RateLimit-Limit
Akamai-Mon-Iucid-Del
NtCoent-Length
X-Request-Start
Yjs-Id
MIME-Version
CDN
X-WA
Sm-Log-Id
Cdn-Requestid
Esi-Enabled
X-LiteSpeed-Tag
Wsr-Cache
X-Scheme
X-Lsadc-Cache
X-Service-Response-Time
X-LiteSpeed-Cache-Control
X-API-Version
X-Udemy-Cache-App-Namespace
X-Dynatrace-Js-Agent
X-FPC
X-HubSpot-Correlation-Id
X-NC
X-Aspnet-Version
X-VC-Age
X-ID
X-Styx-Info
Proxy-Firewall
Uri
Server-Id
Cr
X-Pool
X-HA-Device-Type
X-TIM-N
X-Lb-Id
X-Styx-Origin-Id
Content-Secure-Policy
Datacenter
Hostname
X-Request-Host
X-HA-Bot-Classification
Pramga
X-HA-Application-Name
X-Html-Minification-Powered-By
X-Akamai-Pragma-Client-IP
X-NodeID
Geoip-Latitude
X-Var-Ttl
X-Via-JSL
X-Srcache-Fetch-Status
Surrogated-Key
X-TimeS
RATING
X-Stale
GeoIP-Country-Code
X-Srcache-Store-Status
ServerHost
X-Fastly-Backend-Reqs
X-Ez-Minify-Js
X-RequestId
Cloudfront-Viewer-Country
X-CS
Srv
X-Cache-Grace
T-Server
X-Vgn-Hpd-Reason
W
From-Cache
X-ServedByHost
X-Varnish-Beresp-TTL
X-Lb-Nocache
X-Oracle-DMS-ECID
X-Wp-Cf-Super-Cache
X-Wp-Cf-Super-Cache-Cache-Control
X-Aspnetmvc-Version
X-App
X-MSEdge-Flight
X-MSEdge-Features
X-Swift-Error
X-CACHE-KEY
Yak-Timeinfo
X-DataCenter
X-DynaTrace
X-Shardid
X-LAGOON
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-Shopid
X-Air-Hostname
X-Air-Trace-Id
X-Air-Source
X-Wp-Cf-Super-Cache-Active
X-Sorting-Hat-Shopid
X-Sorting-Hat-Podid
X-Via-SSL
X-Proxy-Cache-LA2
X-VServer
X-ByteArk-Cache
X-ByteArk-ReqID
Edge-Copy-Time
Ohc-File-Size
X-Ramcache
X-Ha-Backend
X-Key
X-Via-CDN
X-Via-Edge
X-Ssense-Gql
X-Ssense-Shipping-Surcharge-Enabled
X-Correlation-ID
X-NODE
Ohc-Cache-HIT
Ngx
X-Webkit-Csp-Report-Only
CF-Cached-On
X-Jobs
X-Geolocation
X-Via-PopN
X-Elasticpress-Query
X-Cdn-Cache-Status
Cl-Cache
X-Via-PopV
X-Via-PopH
Req-ID
N1-Cache
X-Web-Server
X-Geo
X-Zen-Fury
X-CSRF-TOKEN
FSS-Cache
X-PageType
True-Client-IP
X-Sucuri-Id
WP-Super-Cache
X-Th-Server
Akamai-X-True-TTL
X-ATG-Version
X-Check-Cacheable
WebServer
X-DC
Cf-Ipcountry
X-Iplb-Request-Id
X-Iplb-Instance
X-MiniProfiler-Ids
X-Limited
X-Beacon
Warning
My-App
X-Fastly-Cache-Status
X-Mg-Cache
X-Env
Host-Name
X-Serial
X-Request-Url
User-Agent
X-Cdn-Srv
On-Server
Xkey-G-Jp