Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
X-Frame-Options
Expires
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Accept-CH
Last-Modified
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
X-XSS-Protection
X-Cache
X-Powered-By
Pragma
Via
CF-RAY
Age
Content-Security-Policy
Alt-Svc
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
X-Amz-Cf-Pop
X-Amz-Cf-Id
Content-Language
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-Download-Options
X-Request-Id
X-Xss-Protection
X-Timer
Access-Control-Allow-Headers
CF-Ray
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
Accept-CH-Lifetime
Content-Security-Policy-Report-Only
X-DNS-Prefetch-Control
X-AspNet-Version
X-Runtime
Permissions-Policy
X-Drupal-Cache
Server-Timing
X-Generator
X-Envoy-Upstream-Service-Time
X-Cache-Status
X-FRAME-OPTIONS
X-Cacheable
X-Ua-Compatible
X-Iinfo
X-Drupal-Dynamic-Cache
Timing-Allow-Origin
X-CONTENT-TYPE-OPTIONS
Accept-Ch
Feature-Policy
X-Content-Security-Policy
Xkey
X-XSS-PROTECTION
Upgrade
Access-Control-Expose-Headers
X-CDN
Content-Encoding
Status
X-AspNetMvc-Version
Access-Control-Max-Age
X-Amz-Request-Id
X-Amz-Id-2
Host-Header
X-Age
Request-Context
X-Backend
Cf-Edge-Cache
X-Amz-Version-Id
X-Robots-Tag
X-Hacker
Keep-Alive
X-Via
Cf-Apo-Via
X-Turbo-Charged-By
X-Vhost
X-AH-Environment
X-Rq
X-Server
X-Dispatcher
X-Cache-Group
X-Proxy-Cache
CONTENT-SECURITY-POLICY
X-Request-ID
X-Ws-Request-Id
EagleId
X-UA-Device
X-Varnish-Cache
Pantheon-Trace-Id
Grace
X-Litespeed-Cache
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Server-Powered-By
X-OneAgent-JS-Injection
X-Dns-Prefetch-Control
X-WebKit-CSP
X-Pingback
X-Page-Speed
Allow
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-Cache-Lookup
X-Device
X-FTR-Request-ID
X-Node
X-Host
X-Server-Id
EagleEye-TraceId
X-Backend-Server
X-Country-Code
Surrogate-Control
X-Cloud-Trace-Context
X-Ruxit-JS-Agent
Cf-Railgun
X-Readtime
X-Akam-SW-Version
X-HW
X-Response-Time
P3p
Cache-Tag
X-Amz-Server-Side-Encryption
X-LiteSpeed-Cache
Content-Location
X-Ua-Device
Accept-Ch-Lifetime
Cross-Origin-Opener-Policy
X-Content-Type
X-Nginx-Cache-Status
X-Nginx-Upstream-Cache-Status
X-Rack-Cache
Request-Id
Service-Worker-Allowed
X-Trace
X-TraceId
X-Application-Context
Fastly-Restarts
X-Nf-Request-Id
X-Element-Page-Cache
X-Times
X-D2id
X-Vname
X-PC
X-TtlSet
Rating
X-Clacks-Overhead
X-Cnection
X-Oneagent-Js-Injection
X-Edge
X-Mcache
X-Midtier
X-Navigation-Version
X-Country
X-FTR-Backend
X-Country-Code-Real
X-FTR-Balancer
X-FTR-Backend-Server
X-Vcap-Request-Id
X-FTR-Cache-Status
Origin-Trial
X-Browser-Type
X-FTR-Expires
X-ESI
Edge-Control
X-Cache-TTL
X-FastCGI-Cache
Surrogate-Key
X-NWS-LOG-UUID
X-Exp-Id
X-Cdn-Fetch
X-Exp-Variant
X-Kinja-Build
X-GoogleNews-Bot
X-Kinja
X-Kinja-Server
X-Kinja-Revision
X-Powered-By-Plesk
X-Url
X-Ac
X-Abt-Application-Version
X-Upstream
X-Mod-Pagespeed
X-Amz-Rid
Verso
X-ORACLE-DMS-RID
X-B3-TraceId
X-Language
X-ECACHE
Akamai-GRN
Nginx-Cache
X-Pinterest-Rid
Pinterest-Generated-By
Pinterest-Version
X-GitHub-Request-Id
Pagespeed
Display
X-Middleton-Display
X-Sol
X-MS-InvokeApp
S
X-Erf-Bev-Bev-Is-Generated
X-PDP-UNCACHING-HASH
X-Instrumentation
X-Erf-Bev-Bev
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Envoy-Decorator-Operation
Response
X-Middleton-Response
AR-ATIME
AR-Request-ID
AR-PoweredBy
Edge-Cache-Tag
X-Amzn-Trace-Id
X-Request-Device-Id
X-T
X-Goog-Hash
X-Distributor
SPRequestDuration
X-SharePointHealthScore
SPRequestGuid
SPIisLatency
X-Ratelimit-Limit
X-Resp-Is-Stale
X-Ser
X-Edge-Location-Klb
X-Kinsta-Cache
X-ARC
Access-Control-Request-Method
X-NGENIX-Cache
X-Meli-Trace-Site
X-Meli-Trace-Platform
X-Meli-Trace-Bu
Front-End-Https
X-Shield-Request-Id
X-Dw-Request-Base-Id
X-Client-IP
X-Ruxit-Js-Agent
X-Content-Digest
X-Ttl
X-Ezoic-Cdn
RTSS
X-Recruiting
X-Cache-Key
Cache-Status
X-Request-Processing-Time
X-Request-Received
X-Varnish-TTL
X-Version
X-Mg-S
X-Powered-CMS
TP-Cache
X-HS-Cache-Config
X-HS-Content-Id
Public-Key-Pins
X-HS-Hub-Id
X-Ismobilevalue
Fastcgi-Cache
X-MSEdge-Ref
X-Accel-Expires
AR-CACHE
Cache-Tags
X-Correlation-Id
Arr-Disable-Session-Affinity
X-Cached
Ar-SID
X-Amz-Replication-Status
X-Cluster-Name
X-Daa-Tunnel
YJS-ID
Realpath
X-Id
Content-MD5
X-Content-Security-Policy-Report-Only
X-Newrelic-App-Data
X-RateLimit-Remaining
X-Fastly-Request-ID
X-HS-Combine-CSS
X-Ua-Browser
Payment
X-Kong-Upstream-Latency
X-Azure-Ref
X-Kong-Proxy-Latency
X-Forwarded-For
X-DIS-Request-ID
X-Cambria-Cache-Control
X-Xrds-Location
X-Jurisdiction
X-HP-Trace-Id
X-HP-Webp
X-Server-Name
X-HS-CF-Cache-Status
X-HS-Prerendered
X-GUploader-UploadID
Content-Disposition
X-SRCache-Fetch-Status
X-SRCache-Store-Status
MicrosoftSharePointTeamServices
X-Amzn-RequestId
X-Amz-Apigw-Id
X-TTL
X-Protected-By
Count-Hit
X-Px
X-Ratelimit-Reset
X-ORACLE-DMS-ECID
X-Unique-Id
X-Activity-Id
X-Origin-Server
X-AppVersion
X-Az
X-Page-Id
X-Rid
X-Logged-In
X-Git-Hash
X-Amz-Meta-S3cmd-Attrs
Cleartype
Accept-Charset
Cross-Origin-Resource-Policy
X-VARITI-CCR
Cross-Origin-Embedder-Policy
X-Microsite
X-FB-Debug
X-Ratelimit-Remaining
X-Proxy
X-Request-Handler-Origin-Region
X-TEC-API-ORIGIN
X-Www-Served-By
X-TEC-API-ROOT
X-TEC-API-VERSION
Version
X-Load-Cache
X-COUNTRY
X-Hits
X-LLID
X-Webkit-Csp
X-Goog-Metageneration
X-Geo-Country
X-Forwarded-Proto
X-Template
X-PressLabs-Stats
X-Varnish-Backend
X-Upgrade-Enabled
X-SERVER-NAME
Server-Node
X-WebKit-CSP-Report-Only
X-B3-Sampled
Server-Name
X-App-Server
X-Hostname
Healthy
X-Content-Options
Access-Control-Allow-Method
X-Frontend
Section-Io-Cache
Viewport
X-Varnish-Grace
X-Device-Type
X-Grace
X-CST
X-TT
X-Fb-Rlafr
X-B
Fastly-SWR
Fastly-SIE
AKAMAI-GRN
Alternate-Protocol
X-Varnish-Server
X-Request-Guid
MRF-Tech
Mrf-Cache-Status
X-B3-TraceId-Primal
X-Contextid
X-Status
X-Requestid
X-RemovedCookies
X-ProcessESI
X-Cache-Age
X-Goog-Generation
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
DC
TCN
Upgrade-Insecure-Requests
X-Hl-Ver
X-Magnolia-Registration
X-Varnish-Ttl
X-Amzn-Remapped-Content-Length
Retry-After
X-EdgeConnect-Cache-Status
Host
X-App-Version
MS-Author-Via
X-Cache-Control
X-CSRF-Token
Frame-Options
X-Revision
X-Original-Request-Id
X-Origin-TTL
X-Response-Served-From
X-Type
X-Origin-CC
X-Buckets
X-Tt-Trace-Host
Amp-Access-Control-Allow-Source-Origin
X-Tt-Trace-Tag
X-Debug
SD-X-WS
X-Yandex-Req-Id
X-Mobile
X-INCAP-ABP
VIX-Pulpo-Upstream-Status
X-Seen-By
X-Instance
X-G
X-UUID
X-ServerID
X-Backend-Name
VIX-Pulpo-Node
X-Cache-Status-Check
X-Tumblr-User
X-Tumblr-Pixel
X-Akamai-Edgescape
X-Tumblr-Pixel-1
X-Is-Bot
X-Lambda-Id
X-NYM-Debug-Backend
X-N
X-Rendered-As
X-Oracle-Dms-Ecid
X-Tumblr-Pixel-0
X-Adobe-Content
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Adobe-Loc
Cross-Origin-Embedder-Policy-Report-Only
Cross-Origin-Opener-Policy-Report-Only
X-AB
X-Akamai-Request-ID2
Section-Io-Id
X-WP-CF-Super-Cache-Cache-Control
Ms-Operation-Id
NGB
MS-CV
Access-Control-Request-Headers
X-WP-CF-Super-Cache
X-Mg-Request-UUID
X-Debug-IsPreview
X-Framework
X-Trace-Id
Xet-Cookie
X-Debug-IsConnected
X-RTag
X-Content-Powered-By
X-Server-W
X-RM-Cache-TTL
X-Storage
Cache
Charset
X-Dc
X-Vcl-Version
Webserver
Filterid
Paypal-Debug-Id
X-DataDome
YJS-CacheStatus
Accept-Language
X-VC-Cache
X-Proxy-Build
X-Cache-Time
X-B3-SpanId
X-Timing-Wait
Selected-Fe
Refresh
Onion-Location
X-Ms-Request-Id
X-Ms-Version
X-Cacheable-TTL
X-ECache
X-Cache-Hit
X-User-Agent
SRV
X-Tec-Api-Root
X-ProxyCache-Key
X-Fastcgi-Cache
X-BYPASS-REASON
X-ProxyCache-Status
X-Tec-Api-Origin
X-Tec-Api-Version
X-Request-Platform
X-Request-Bu
X-Time
X-Request-Site
X-F-Cache
X-Region
X-Node-Name
X-Real-IP
X-VC
Liferay-Portal
X-Hcs-Proxy-Type
X-CCDN-Origin-Time
Priority
X-CCDN-CacheTTL
GEO-INFO
Apigw-Requestid
X-Origin-Cache
X-L-Path
X-Environment-Context
X-HTML-Minification-Powered-By
X-Mode
CDN-RequestId
Front
X-Service
X-IPS-LoggedIn
Backend
X-LB-Cache
X-Rule
X-Pass-Why
X-Cache-Expired-At
X-Tb
X-Server-ID
X-Drupal-Cache-Tags
Country
Meta-Geo
X-VCT
X-Rn-Rsrv
X-SaId
X-Rocket-Nginx-Serving-Static
X-UPSTREAM-Address
X-Rewrite-Enabled
X-HITS
X-Datadog-Sampling-Priority
X-JoinUs
X-Datadog-Sampled
X-Api-Version
X-Datadog-Parent-Id
X-Mly-Id
X-Datadog-Trace-Id
X-Origin
Cross-Origin-Window-Policy
X-Is-Tablet
X-Wix-Request-Id
X-Handled-By
X-Browser-Name
X-Is-Desktop
X-Geo-Region
X-Adobe-Source
X-Is-Supported-Browser
X-Is-Modern-Browser
X-Is-Mobile-Only
X-Tcp-Rtt
X-Is-Mobile
X-Whom
X-Generation-Time
Mn-Server-Ip
X-Provided-By
X-Web-Node
Expiry
X-Detected-As
Property-Id
Webcakes-App-Version
Webcakes-App-Name
Uber-Trace-Id
Url
Web-Mar-Node
X-Extlb
TWC-Privacy
X-Cloudmap
X-Zipkin-Id
Webcakes-Region
X-Connection-Hash
X-Tncms
X-RateLimit-Remaining-Second
X-RCS-CacheZone
X-Routing-Service
TWC-Locale-Group
X-RateLimit-Limit-Second
TWC-GeoIP-Region
X-Proxied
X-Origin-Date
X-Proxy-Cache-Info
X-Loop
X-Httpd
X-Servername
X-Varnish-Beresp-Grace
TWC-GeoIP-City
TWC-Device-Class
TWC-Connection-Speed
X-FB-TRIP-ID
TWC-GeoIP-Country
TWC-GeoIP-LatLong
X-Origin-Hint
TWC-GeoIP-DMA
X-Vcache
Fastcgi-Useragent
X-WP-CF-Super-Cache-Active
ServerID
X-Hit
ServedBy
OT-Force-Account-Verify
X-Hosted-By
X-App-Environment
X-Redis-Cache
X-MP-GENERATED-AT
X-Locale
X-Format
X-Cache-Debug
X-Cache-Action
X-Auth-Group-Type
X-Cluster
Protected
X-Fetched-On
X-Director
X-Cms-Context
DB-Nickname
X-Logging-Id
X-Alternate-Cache-Key
X-Skip-Cache
X-Soup
X-Tumblr-Pixel-2
X-Tumblr-Pixel-3
X-Forwarded-Host
X-Cdn-Origin
X-Storefront-Renderer-Rendered
Atl-Traceid
X-Shopify-Stage
X-Endurance-Cache-Level
X-Optimistic-Header
X-Edge-Location
X-Debug-Info
X-Urbn-Context-Path
X-Cluster-Node
X-Cache-Host
X-CLOUD-TRACE-CONTEXT
X-FW-Hash
X-Scope-Id
X-Served-From
X-SayCDN-TTL
X-Say-TTL
X-Say-Cacheable
X-FW-Version
X-FW-Type
X-Restarts
X-FW-Serve
X-FW-Server
X-FW-Static
X-FW-Dynamic
X-Urbn-Site-Id
Locale
Cache-Hits
Environment
LB
Node
X-IPLB-Request-ID
X-Drupal-Cache-Contexts
X-IPLB-Instance
X-Tt-Logid
X-S
X-PHP-Host
X-Labrador-Cache-Channel
Countrycode
Filters
X-Platform
X-R9-Blue-Green-Version
X-CDN-Cache-Status
X-CDN-Forward
X-URL
X-GEO
AMP-Access-Control-Allow-Source-Origin
Xserver
X-XRDS-Location
WPO-Cache-Status
X-No-Session
X-Varnish-Age
X-B3-Traceid
X-ShopId
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-ShardId
X-WP-CF-Super-Cache-Cookies-Bypass
X-Lagoon
Cache-Tv-Group
X-Client-Ip
X-Varnish-Beresp-Ttl
X-NWS-UUID-VERIFY
X-Varnish-Cache-Hits
X-Generated-By
X-B-Cache
X-UA
X-Signature
X-Ua
Request-ID
X-Presslabs-Stats
X-NewRelic-App-Data
X-Fastly-Request-Id
Referer-Policy
X-SRCache-Key
X-Clientip
Expect-Staple
X-SRV
X-Azure-Ref-OriginShield
X-Webstats-RespID
CloudFront-Viewer-Country
X-Upstream-Ct
X-Cache-Operation
X-PHP-Backend
X-IsAdmin
X-Site-Version
X-Cache-Rule
X-Upstream-Ht
AR-SID
From-Origin
We-Hiring
X-Cache-FS-Status
Mail-Subject
X-TA-CDN-Provider
Location
X-Worker
Cache-Provider
X-Auto-Login
X-VWS-Id
X-Accel-Version
X-LJ-Flow-ID
X-Bc-Bl
X-Server-IP
X-AWS-Id
Fl-Custom-Application
X-Litespeed-Cache-Control
Sid
X-Cache-NE
X-Ig-Push-State
X-A-Dam
Xc-Version
X-Loc
Rendered-Blocks
X-Ec-Fail
X-Bl-Debug
Source
X-ND-Cache
X-A
X-Cs
WPO-Cache-Message
Redirect-Candidate
X-Tb-Optimization-Total-Bytes-Saved
X-Org
X-Vtex-Remote-Cache
X-Ec-GeoHdr
X-A-Ccd
X-A-Dcw
X-BCube-Filmed-By
S-Rt
Candidate-Md5Url
X-D
X-A-Wwc
X-GeoCountry
X-External-Request-Id
X-VC-TTL
Origin-Agent-Cluster
X-ApacheServer
X-ScT
X-GeoCode
Host-ID
X-Content-Age
Ngx.Var.Host
X-Aed
N-Cache
Meta-Geo-Continent
Pragrma
Lang
MD5-Digest
X-S-Cookie
Origin
X-Destination
DCR-Processing-Time-Ms
X-Developer
X-B-Cookie
X-PERF
X-CACHE-AGE
Sslversion
X-Conf
X-FORWARDED-FOR
X-Rojux
X-Application
X-Vdms-Version
X-A-Dgt
X-Ig-Origin-Region
DCR-Decision-By
X-Xfnlog-Site
X-Tx-Id
X-Epic-Correlation-Id
X-From
CDN-Cache
X-Fastly-Backend
Canary
X-Eu-Site
CDN-EdgeStorageId
CDN-CachedAt
X-Fmm-Version
X-FC-Vary-Parameters
X-Forwarded-Site
Country-Code
Gh-Request-Id
Ha-Gx-Prefs
X-Cms-Device
Gannett-Cam-Experience-Id
X-CGP
Fastly-SSL
X-CUA
X-Csrf-Jwt
Odigeo-Trace-Id
X-Contensis-Viewer-Groups
Log-Origin
L5d-Success-Class
IsBot
X-Core-Value
Origin-Site
X-Depends
CDN-Uid
Cdncip
CDN-RequestPullSuccess
CDN-RequestPullCode
X-Ee-Request-Id
CDN-RequestCountryCode
Cdnsip
X-Ee-Request-Date
X-CacheTTL
X-Gamma-Serve
X-Ee-Generated-By
Cluster
X-Ee-Origin
CDN-PullZone
X-Old-Content-Length
X-Save-Cache
X-Rocket-Build-Number
X-Vary-Devices
X-SD-PageType
X-Sigma
X-Section
X-Req
Store-Cloud-Cache
Powered-By
X-Policy
Wxu-Next-Commit
X-VG-WebCache
X-VG-TLSProxy
X-Sigma-Backend
X-SIPLIST1
X-AK-Request-ID
X-Varnish-Authentication
X-V-Cache
X-Access
X-Action
X-Aicache-OS
Time-Cloud-Cache
X-Varnish-Beresp-Status
X-Slack-Shared-Secret-Outcome
X-Slack-Backend
Web-Mar-Region
X-Varnish-Hostname
X-Varnish-Director
Wxu-Next-Hostname
ServerName
X-Hash
X-GoCache-CacheStatus
X-Cache-Aspx
X-HS-Content-Campaign-Id
X-Bug-Bounty
X-GeoIP-Region-Code
X-GeoIP-Country-Code
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
Apple-News-Services-Host
Apple-News-Services-Handled
X-GeoIP-City
X-PAYTM-SRV-ID
X-Internal-TTL
X-LSADC-Cache
X-Origin-Expires
X-Node-Id
RNT-Time
Wxu-Next-Region
RNT-Machine
X-Micro-Cache
X-Mvc-Supplant-Cachable
X-Parent-Response-Time
X-Accel-Expires-Debug
X-Backend-Instance
X-BBC-Edge-Cache-Status
X-Acquia-Purge-Cdn-Unconfigured
X-App-Name
X-Amz-Storage-Class
X-Block-Status
X-AB-Test
X-Bip
X-Akamai-Device-Characteristics
X-Cache-Date
X-Nyt-Route
X-Thanos
X-SVT-ORM-VERSION
X-Thinkindot-L1
X-Thinkindot-L3
X-UA-Device-Type
X-SVT-ORM-RULES
X-Sucuri-Cache
X-Reqid
X-Render-Time
X-Request-URI
X-SB
X-Shield-Cache-Expires
X-Up
X-Uri
X-We-Are-Hiring
X-Vmg-Version
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-Sn-Servicetimems
X-Viewer-Country
X-Via-Fastly
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
X-VarnishDD-TTL
X-Region-Sid
X-Pubstack
X-Gdpr
X-Frame-Option
X-Gen-Mode
X-Generated-On
X-HN
X-Ec-Custom-Error
X-Dispatcher-Server
X-Debug-Cache-Fetch
X-Date
X-Debug-Cache-Store
X-DefElseHash
X-DefHash
X-Hnp-Log
X-Human
X-Op-Id-All
X-NMSegId
X-Origin-Time
X-Path
X-Proto
X-Mvc-Supplant-OutputCached
X-Men
X-Ion-Healthy
X-Ion-Hop
X-Jungle-Id
X-Level-Front-Cache
X-Content-Length
TDXMobile
NM-Fastcgi-Cache
Nord-Request-ID
Machine
L
Fastly-Backend-Name
Origin-CC
Origin-EX
Req-Svc-Chain
Release
Pics-Label
PFcat
DSUID
Content-Script-Type
Azure-SiteName
Azure-RegionName
Azure-InstanceId
Mime-Version
Azure-SlotName
Azure-Version
Cmstype
Cmsid
CDCHOST
Cache-Contol
RewriteTeamHook
Content-Style-Type
User-Cache-Control
V-Age
Vix-Hermes-Req-Id
Thinkindot-CacheControl-Type
CF-IPCountry
RewriteTestHook
Thinkindot-CacheControl
Server-Host
X-NGINX-Cache
X-ElasticPress-Query
Click-Count-Error
Tube-Get-Contents
X-DPWN-IS-SECURE
X-Edge-Server
Tube-Got-Eval
Click-Count-Action-Start
X-Esi-Check
Cdn-Request-Time
C-Via
X-Location
Load-Balancing
X-Moov-T
X-Moov-Xdn-Caching-Status
X-Moov-Xdn-Version
X-Proxied-Request
X-Gzip
CacheControlHeader
Tube-Return
X-Vercel-Id
X-Wormhole-Sdk
Tube-Got-Results
Cdn-Host
X-Vercel-Cache
X-Cache-Id
X-B3-Trace-ID
Platform
Fastly-GeoIP-CountryCode
Producers
X-Cached-By
XM
X-ZONE
X-Origin-Response-Time
X-NF-Request-ID
X-Pad
X-Sucuri-ID
X-Varnish-Hits
Fastly-Drupal-HTML
X-Air-Pt
Cookie
NGX
X-Datadome
X-Debug-Service
X-Via-Poph
X-Nginx-Cache-Key
X-Via-Popn
Debug
X-Refresh
X-Via-Popv
True-Client-Country-4JS
X-HA-Backend
X-APP
Sever-Int
Server-Hostname
Server-Ext
X-Srv
X-AIR-PT
X-Webkit-CSP
Show-Do-Not-Sell-Link
X-Source
GeoIp-Country-Code
X-Servedbyhost
GeoIP-Latitude
X-DynaTrace-JS-Agent
Traceparent
X-Litespeed-Tag
Server-ID
X-Zone
HA-Ipaddr
X-TH-Server
X-Ez-Minify-Html
Product
X-Nananana
WZWS-RAY
X-Cache-Backend
DataCenter
HostName
Cdn
X-Amz-Meta-Cb-Modifiedtime
X-Unity-Cache
X-LB-ID
Fastly-Drupal-Html
X-Cdn-Forward
X-Nc
X-B3-Parentspanid
X-Fpc
X-Cache-VC
X-GeoIP
X-Wa
X-Newrelic-Synthetics
X-User
Edge-Cache
Tcn
X-TT-LOGID
X-VCL-Version
X-AC
Lb
X-CDN-Provider
X-Nginx-Cache
X-B3-Spanid
SID
Xkey-La3
X-Proxy-CacheR9
Xkeylog
A
XkeyR9
X-Proxy-Cache-La3
X-Vc
Serverhost
Resin-Trace
Akamai-Mon-Iucid-Del
X-Datacenter
CountryCode
X-TX-ID
X-LB-NoCache
MIME-Version
X-Request-Start
Yjs-Id
Cs
X-Lsadc-Cache
NtCoent-Length
Sm-Log-Id
Wsr-Cache
X-Service-Response-Time
X-RateLimit-Limit
X-Scheme
X-LiteSpeed-Tag
Cdn-Requestid
CDN
Esi-Enabled
X-WA
X-LiteSpeed-Cache-Control
X-API-Version
X-Pool
X-NC
X-Dynatrace-Js-Agent
Hostname
X-Aspnet-Version
X-Lb-Id
Uri
X-FPC
X-HubSpot-Correlation-Id
X-ID
X-VC-Age
X-Request-Host
X-Udemy-Cache-App-Namespace
Surrogated-Key
Proxy-Firewall
X-Styx-Origin-Id
Content-Secure-Policy
X-TIM-N
X-Fastly-Backend-Reqs
X-Via-JSL
X-Html-Minification-Powered-By
X-NodeID
X-Akamai-Pragma-Client-IP
X-Styx-Info
Server-Id
Datacenter
X-HA-Application-Name
Pramga
X-HA-Bot-Classification
X-Stale
X-CS
X-HA-Device-Type
Cr
X-RequestId
Geoip-Latitude
ServerHost
X-Var-Ttl
GeoIP-Country-Code
X-Srcache-Fetch-Status
X-Vgn-Hpd-Reason
X-Srcache-Store-Status
X-TimeS
X-Cache-Grace
RATING
X-Ez-Minify-Js
T-Server
X-Varnish-Beresp-TTL
Yak-Timeinfo
X-ServedByHost
X-DynaTrace
W
X-DataCenter
X-Lb-Nocache
From-Cache
Srv
X-Aspnetmvc-Version
X-Oracle-DMS-ECID
X-Wp-Cf-Super-Cache
X-Wp-Cf-Super-Cache-Cache-Control
X-Air-Hostname
X-Air-Source
X-Air-Trace-Id
X-Via-Edge
X-Via-SSL
X-CACHE-KEY
Edge-Copy-Time
X-MSEdge-Features
X-MSEdge-Flight
X-Via-CDN
X-CSRF-TOKEN
X-Swift-Error
X-Ha-Backend
Cloudfront-Viewer-Country
X-App
X-Sorting-Hat-Shopid
X-Sorting-Hat-Podid
X-LAGOON
X-Shardid
X-Shopid
X-Wp-Cf-Super-Cache-Cookies-Bypass
N1-Cache
X-Wp-Cf-Super-Cache-Active
X-Proxy-Cache-LA2
X-Zen-Fury
X-Geolocation
Req-ID
X-Via-PopH
X-ByteArk-Cache
X-Key
X-VServer
X-NODE
Ohc-File-Size
Ohc-Cache-HIT
X-ByteArk-ReqID
X-Ramcache
FSS-Cache
X-Via-PopN
X-Jobs
X-Correlation-ID
X-Ssense-Gql
X-Via-PopV
X-Ssense-Shipping-Surcharge-Enabled
WP-Super-Cache
True-Client-IP
X-Sucuri-Id
X-Elasticpress-Query
Ngx
X-Web-Server
CF-Cached-On
X-Cdn-Cache-Status
X-Check-Cacheable
X-Geo
X-Webkit-Csp-Report-Only
Cl-Cache
X-PageType
X-Serial
WebServer
X-Cdn-Srv
On-Server
X-Th-Server
Akamai-X-True-TTL
X-ATG-Version
X-DC
Cf-Ipcountry
X-Iplb-Request-Id
X-Iplb-Instance
My-App
X-VTEX-Cache-Time
Warning
X-Beacon
X-Limited
X-Mg-Cache
X-MiniProfiler-Ids
X-VTEX-Cache-Server
X-Request-Url
X-Fastly-Cache-Status
X-Powered-By-VTEX-Cache
User-Agent
Host-Name
Xkey-G-Jp
X-Env
FSS-Proxy
Cneonction