Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
X-Frame-Options
Expires
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Accept-CH
Last-Modified
X-XSS-Protection
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
CF-RAY
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Alt-Svc
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
Cf-Request-Id
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
X-Xss-Protection
Access-Control-Allow-Credentials
Accept-CH-Lifetime
Content-Security-Policy-Report-Only
X-DNS-Prefetch-Control
X-AspNet-Version
X-Runtime
Server-Timing
X-Drupal-Cache
Permissions-Policy
CF-Ray
X-Generator
X-Envoy-Upstream-Service-Time
X-Cache-Status
X-Ua-Compatible
X-Cacheable
X-FRAME-OPTIONS
X-Iinfo
Timing-Allow-Origin
X-Drupal-Dynamic-Cache
Feature-Policy
X-CONTENT-TYPE-OPTIONS
X-Content-Security-Policy
Xkey
Upgrade
Access-Control-Expose-Headers
Content-Encoding
X-CDN
X-XSS-PROTECTION
Status
X-AspNetMvc-Version
Accept-Ch
Access-Control-Max-Age
Host-Header
X-Age
X-Amz-Request-Id
X-Amz-Id-2
Request-Context
Cf-Edge-Cache
X-Backend
X-Robots-Tag
X-Hacker
X-Via
X-Request-ID
Cf-Apo-Via
X-Turbo-Charged-By
X-Rq
X-Vhost
X-Cache-Group
X-Amz-Version-Id
Keep-Alive
X-Dispatcher
X-AH-Environment
X-UA-Device
X-Proxy-Cache
X-Server
EagleId
X-Ws-Request-Id
CONTENT-SECURITY-POLICY
X-OneAgent-JS-Injection
X-Varnish-Cache
P3p
Pantheon-Trace-Id
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
Grace
X-Server-Powered-By
X-Dns-Prefetch-Control
Allow
X-Pingback
X-Page-Speed
X-Swift-SaveTime
X-Swift-CacheTime
X-WebKit-CSP
Ali-Swift-Global-Savetime
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-LiteSpeed-Cache
X-Litespeed-Cache
X-FTR-Request-ID
X-Node
X-Device
EagleEye-TraceId
X-Host
X-Cache-Lookup
X-Backend-Server
Surrogate-Control
X-Country-Code
X-Ruxit-JS-Agent
X-Server-Id
X-Readtime
X-Cloud-Trace-Context
X-Akam-SW-Version
Cf-Railgun
X-HW
X-Response-Time
Cache-Tag
Content-Location
X-Amz-Server-Side-Encryption
Cross-Origin-Opener-Policy
X-Rack-Cache
X-Trace
X-Nginx-Upstream-Cache-Status
Service-Worker-Allowed
X-Nginx-Cache-Status
X-TraceId
X-Country
Fastly-Restarts
X-Clacks-Overhead
X-Content-Type
Request-Id
X-PC
X-Vname
X-TtlSet
Rating
X-Application-Context
X-Times
X-Cnection
X-Cache-TTL
X-ESI
X-Edge
X-Browser-Type
X-Midtier
X-Mcache
Surrogate-Key
X-Vcap-Request-Id
X-FTR-Balancer
X-Country-Code-Real
X-FTR-Backend-Server
X-FTR-Backend
X-FTR-Cache-Status
X-FTR-Expires
Accept-Ch-Lifetime
X-Ac
Origin-Trial
Edge-Control
X-Powered-By-Plesk
X-Exp-Variant
X-GoogleNews-Bot
X-Abt-Application-Version
X-Cdn-Fetch
X-Element-Page-Cache
X-Exp-Id
X-Kinja
X-Kinja-Server
X-Kinja-Revision
X-Kinja-Build
X-NWS-LOG-UUID
X-D2id
Verso
X-FastCGI-Cache
X-Upstream
X-B3-TraceId
X-ORACLE-DMS-RID
X-ECACHE
X-Amz-Rid
X-Mod-Pagespeed
Nginx-Cache
X-Navigation-Version
X-Middleton-Display
Display
Pagespeed
X-Sol
X-GitHub-Request-Id
X-Nf-Request-Id
X-Client-IP
X-Pinterest-Rid
Pinterest-Version
Pinterest-Generated-By
X-PDP-UNCACHING-HASH
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Instrumentation
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Middleton-Response
Response
X-Language
Akamai-GRN
X-Envoy-Decorator-Operation
X-Ua-Device
X-Ratelimit-Limit
X-Goog-Hash
S
Edge-Cache-Tag
AR-ATIME
X-ARC
AR-PoweredBy
AR-Request-ID
X-Resp-Is-Stale
X-MS-InvokeApp
X-Edge-Location-Klb
X-Kinsta-Cache
X-Ser
X-Content-Digest
X-Distributor
SPIisLatency
SPRequestDuration
X-Url
SPRequestGuid
X-SharePointHealthScore
Access-Control-Request-Method
X-Dw-Request-Base-Id
X-Cache-Key
Front-End-Https
X-Ezoic-Cdn
X-Recruiting
X-NGENIX-Cache
X-Shield-Request-Id
RTSS
Cache-Status
X-Amzn-Trace-Id
X-Powered-CMS
X-Version
X-Ttl
X-Forwarded-For
Public-Key-Pins
X-MSEdge-Ref
X-T
Fastcgi-Cache
TP-Cache
Arr-Disable-Session-Affinity
X-Mg-S
X-Daa-Tunnel
X-Accel-Expires
X-Varnish-TTL
X-HS-Content-Id
X-HS-Hub-Id
X-HS-Cache-Config
X-Correlation-Id
X-Ismobilevalue
X-Server-Name
X-Fastly-Request-ID
Realpath
X-Cluster-Name
Cache-Tags
X-Id
X-CST
X-Cached
AR-CACHE
X-Request-Received
X-Request-Processing-Time
X-HS-Combine-CSS
X-Newrelic-App-Data
X-Ua-Browser
Payment
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-DIS-Request-ID
X-GUploader-UploadID
X-Content-Security-Policy-Report-Only
X-Xrds-Location
Content-MD5
X-ORACLE-DMS-ECID
X-Oneagent-Js-Injection
X-TTL
X-HP-Trace-Id
X-Cambria-Cache-Control
X-Ratelimit-Remaining
X-Jurisdiction
X-HP-Webp
X-HS-Prerendered
X-HS-CF-Cache-Status
X-RateLimit-Remaining
X-Webkit-Csp
Count-Hit
Content-Disposition
X-Azure-Ref
X-Amz-Replication-Status
X-Ruxit-Js-Agent
X-Px
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-PressLabs-Stats
Cross-Origin-Resource-Policy
X-Page-Id
X-Request-Handler-Origin-Region
X-Unique-Id
X-Microsite
Accept-Charset
Cleartype
X-Ratelimit-Reset
X-Logged-In
X-FB-Debug
X-Proxy
X-Git-Hash
X-Protected-By
X-Load-Cache
X-Rid
X-Origin-Server
X-Az
X-Activity-Id
X-AppVersion
X-VARITI-CCR
X-Www-Served-By
Cross-Origin-Embedder-Policy
X-Server-ID
X-LLID
X-Goog-Metageneration
X-Template
X-Hits
X-Varnish-Backend
MicrosoftSharePointTeamServices
Version
Server-Node
X-Forwarded-Proto
X-URL
YJS-ID
Server-Name
X-Amz-Meta-S3cmd-Attrs
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-Upgrade-Enabled
X-Geo-Country
X-Amz-Apigw-Id
X-Amzn-RequestId
X-NF-Request-ID
X-SERVER-NAME
X-Hostname
X-Frontend
X-Content-Options
Ar-SID
X-Varnish-Server
Section-Io-Cache
X-B3-Sampled
Viewport
X-App-Server
X-TT
X-Varnish-Grace
X-Device-Type
Mrf-Cache-Status
X-Status
MRF-Tech
X-B3-TraceId-Primal
X-Fb-Rlafr
X-Grace
X-B
Fastly-SWR
Fastly-SIE
Alternate-Protocol
Access-Control-Allow-Method
X-Varnish-Ttl
TCN
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Generation
Upgrade-Insecure-Requests
X-Wormhole-Sdk
Healthy
X-Tt-Trace-Host
X-Tt-Trace-Tag
Host
X-Request-Guid
X-Cache-Age
X-Magnolia-Registration
X-Buckets
Amp-Access-Control-Allow-Source-Origin
AR-SID
X-Request-Device-Id
X-EdgeConnect-Cache-Status
X-CSRF-Token
DC
X-Debug
AKAMAI-GRN
Retry-After
X-WebKit-CSP-Report-Only
X-Amzn-Remapped-Content-Length
X-Contextid
X-Cache-Control
MS-Author-Via
X-Fastcgi-Cache
X-Revision
X-Original-Request-Id
X-Instance
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
X-Response-Served-From
X-Type
X-Yottaa-Metrics
X-Yottaa-Optimizations
Cross-Origin-Opener-Policy-Report-Only
Cross-Origin-Embedder-Policy-Report-Only
X-Adobe-Content
X-Is-Bot
X-NYM-Debug-Backend
X-Rendered-As
X-Adobe-Loc
X-Origin-TTL
X-Vcl-Version
X-Origin-CC
SD-X-WS
Section-Io-Id
X-Mobile
X-COUNTRY
X-G
Access-Control-Request-Headers
X-Lambda-Id
X-Seen-By
X-Akamai-Edgescape
X-Cache-Hit
X-Backend-Name
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-UUID
X-Tumblr-User
Charset
X-Hl-Ver
X-Tumblr-Pixel
X-Debug-IsConnected
X-Trace-Id
X-Debug-IsPreview
X-Content-Powered-By
X-Framework
X-Mg-Request-UUID
X-ServerID
X-RM-Cache-TTL
NGB
X-Storage
X-Server-W
X-Meli-Trace-Bu
Ms-Operation-Id
X-Meli-Trace-Site
X-RemovedCookies
X-ProcessESI
X-Dc
MS-CV
X-INCAP-ABP
X-Meli-Trace-Platform
X-DataDome
X-RTag
X-Request-Site
X-N
X-AB
X-Request-Bu
X-Cache-Time
X-Akamai-Request-ID2
X-Request-Platform
Filterid
Refresh
X-App-Version
X-Cache-Status-Check
X-Tec-Api-Root
X-Tec-Api-Origin
X-Tec-Api-Version
X-Time
Protected
VIX-Pulpo-Upstream-Status
X-Real-IP
VIX-Pulpo-Node
Frame-Options
X-Region
Accept-Language
Cache
X-Node-Name
SRV
X-B3-SpanId
Webserver
X-LB-Cache
CDN-RequestId
Paypal-Debug-Id
X-User-Agent
Cross-Origin-Window-Policy
X-CCDN-Origin-Time
X-Hcs-Proxy-Type
X-CCDN-CacheTTL
Onion-Location
X-Whom
X-Datadog-Parent-Id
X-Datadog-Sampled
X-Datadog-Sampling-Priority
X-Datadog-Trace-Id
X-Ms-Request-Id
X-Ms-Version
Liferay-Portal
Priority
X-Cache-Expired-At
X-F-Cache
X-IPS-LoggedIn
X-WP-CF-Super-Cache-Active
X-HTML-Minification-Powered-By
X-VC-Cache
OT-Force-Account-Verify
X-Mode
Backend
Xet-Cookie
X-Rocket-Nginx-Serving-Static
X-Oracle-Dms-Ecid
X-Proxy-Cache-Info
X-Pass-Why
X-Tb
X-HITS
X-Cacheable-TTL
X-App-Environment
X-VC
X-FW-Version
X-FW-Static
X-Environment-Context
X-FW-Type
X-FW-Dynamic
GEO-INFO
X-L-Path
X-FW-Hash
X-Drupal-Cache-Tags
X-FW-Server
X-FW-Serve
X-Rewrite-Enabled
Meta-Geo
Web-Mar-Node
X-Tncms
X-JoinUs
X-Vcache
Fastcgi-Useragent
Filters
X-Zipkin-Id
Url
X-Adobe-Source
X-Rn-Rsrv
X-Proxied
X-MP-GENERATED-AT
X-Servername
X-Handled-By
X-Routing-Service
X-Service
ServerID
X-Cloudmap
X-Detected-As
X-UPSTREAM-Address
X-Requestid
X-Loop
X-Debug-Info
X-SaId
X-Extlb
X-Web-Node
X-Hit
X-Rule
X-IPLB-Request-ID
X-Cache-Host
Atl-Traceid
X-Browser-Name
X-Format
X-Varnish-Beresp-Grace
X-Endurance-Cache-Level
X-IPLB-Instance
X-Forwarded-Host
X-Director
Webcakes-App-Name
TWC-Locale-Group
X-Tcp-Rtt
TWC-Connection-Speed
X-Is-Tablet
X-Origin-Hint
TWC-Privacy
X-Storefront-Renderer-Rendered
TWC-Device-Class
TWC-GeoIP-City
X-Logging-Id
TWC-GeoIP-LatLong
X-Locale
LB
TWC-GeoIP-DMA
X-Origin-Date
TWC-GeoIP-Country
ServedBy
X-Is-Supported-Browser
X-Alternate-Cache-Key
Webcakes-Region
Country
X-Restarts
X-Geo-Region
X-Hosted-By
Webcakes-App-Version
X-Is-Desktop
X-Is-Mobile
Property-Id
X-Shopify-Stage
TWC-GeoIP-Region
Uber-Trace-Id
X-Cache-Action
X-Cluster
X-Wix-Request-Id
X-BYPASS-REASON
Mn-Server-Ip
Apigw-Requestid
X-Source
X-Cluster-Node
X-Skip-Cache
X-ECache
X-Httpd
X-Say-TTL
X-ProxyCache-Status
X-Scope-Id
X-SayCDN-TTL
X-Say-Cacheable
X-ProxyCache-Key
X-Redis-Cache
X-Soup
X-Edge-Location
X-Cdn-Origin
X-Cms-Context
Environment
X-Generation-Time
X-PHP-Host
X-Labrador-Cache-Channel
X-Mly-Id
X-S
X-Served-From
X-Drupal-Cache-Contexts
X-RateLimit-Remaining-Second
X-FB-TRIP-ID
X-RateLimit-Limit-Second
X-R9-Blue-Green-Version
X-Origin
X-Tumblr-Pixel-3
X-Connection-Hash
X-Fetched-On
X-Timing-Wait
X-Proxy-Build
X-Auth-Group-Type
X-Tumblr-Pixel-2
Cache-Hits
DB-Nickname
Expiry
Selected-Fe
Locale
X-Urbn-Site-Id
X-Urbn-Context-Path
Request-ID
X-GEO
X-Origin-Cache
Countrycode
X-No-Session
X-Varnish-Cache-Hits
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-ShopId
X-ShardId
X-Varnish-Age
X-VCT
X-RCS-CacheZone
Front
X-Cache-Debug
WPO-Cache-Status
X-SRV
X-CLOUD-TRACE-CONTEXT
X-UA
X-Lagoon
YJS-CacheStatus
X-WP-CF-Super-Cache-Cookies-Bypass
X-Is-Modern-Browser
X-Api-Version
X-Varnish-Beresp-Ttl
X-XRDS-Location
X-Site-Version
X-Webstats-RespID
Node
X-Yandex-Req-Id
Xserver
X-CDN-Forward
Cache-Provider
From-Origin
X-TA-CDN-Provider
X-Cdn
X-Provided-By
X-Azure-Ref-OriginShield
X-Platform
X-Generated-By
X-Xfnlog-Site
Referer-Policy
X-TT-LOGID
X-Is-Mobile-Only
Cache-Tv-Group
X-Accel-Version
X-B3-Traceid
X-NewRelic-App-Data
X-VC-TTL
X-B-Cache
X-Signature
CF-IPCountry
WPO-Cache-Message
X-CDN-Cache-Status
X-Sucuri-Cache
X-Ua
X-Reqid
X-Air-Pt
X-Sucuri-ID
CDN-EdgeStorageId
CDN-CachedAt
CDN-Cache
X-Tx-Id
CDN-PullZone
CDN-RequestCountryCode
CDN-Uid
CDN-RequestPullSuccess
CDN-RequestPullCode
X-CACHE-AGE
X-PHP-Backend
Location
AMP-Access-Control-Allow-Source-Origin
X-NWS-UUID-VERIFY
X-Tb-Optimization-Total-Bytes-Saved
X-Fastly-Request-Id
X-Content-Age
X-Frame-Option
X-Cache-Rule
X-Cache-Operation
Ngx.Var.Host
Meta-Geo-Continent
XM
X-IsAdmin
X-Varnish-Authentication
Odigeo-Trace-Id
X-Sigma
X-Section
X-ScT
X-S-Cookie
Redirect-Candidate
X-Sigma-Backend
X-Slack-Shared-Secret-Outcome
Apple-News-Services-Handled
Origin
X-Slack-Backend
X-SRCache-Key
MD5-Digest
Cdncip
Cdnsip
DCR-Decision-By
DCR-Processing-Time-Ms
Candidate-Md5Url
X-VG-TLSProxy
Apple-News-Services-Request-Url
X-Vtex-Remote-Cache
X-VG-WebCache
Xc-Version
Expect-Staple
X-Varnish-Director
Log-Origin
Apple-News-Services-Parsed-Url
Lang
X-Vdms-Version
Fastly-SSL
Fl-Custom-Application
X-Rojux
Apple-News-Services-Host
X-A
X-Fmm-Version
X-Auto-Login
X-B-Cookie
X-External-Request-Id
X-Application
X-AK-Request-ID
X-GeoCode
X-Forwarded-Site
X-Aed
X-Ec-GeoHdr
X-Ec-Fail
X-Clientip
X-Conf
X-Contensis-Viewer-Groups
X-D
X-Cache-NE
X-Cache-Aspx
X-Developer
X-Destination
X-Bl-Debug
X-GeoCountry
X-HS-Content-Campaign-Id
Web-Mar-Region
X-Depends
X-Origin-Expires
X-Old-Content-Length
X-Request-URI
Sslversion
Rendered-Blocks
RNT-Machine
RNT-Time
X-A-Ccd
X-A-Dam
X-Access
X-Action
X-Ig-Push-State
X-Ig-Origin-Region
X-A-Wwc
X-A-Dgt
X-Micro-Cache
X-A-Dcw
X-Loc
X-Rocket-Build-Number
X-BCube-Filmed-By
X-Litespeed-Tag
X-Optimistic-Header
X-Epic-Correlation-Id
X-Eu-Site
X-Ec-Custom-Error
X-DefHash
X-Csrf-Jwt
X-CUA
X-Date
X-DefElseHash
X-Fastly-Backend
X-FC-Vary-Parameters
X-GeoIP-Region-Code
X-Hash
X-Hnp-Log
X-Human
X-GeoIP-Country-Code
X-GeoIP-City
X-From
X-Gdpr
X-Gen-Mode
X-Content-Length
X-CGP
V-Age
Wxu-Next-Commit
Wxu-Next-Hostname
Wxu-Next-Region
User-Cache-Control
Thinkindot-CacheControl-Type
ServerName
TDXMobile
Thinkindot-CacheControl
X-Accel-Expires-Debug
X-Acquia-Purge-Cdn-Unconfigured
X-Bc-Bl
X-Block-Status
X-Bug-Bounty
X-BBC-Edge-Cache-Status
X-Backend-Instance
X-Aicache-OS
X-Akamai-Device-Characteristics
X-App-Name
X-Internal-TTL
X-Men
X-Varnish-Remaining-TTL
X-We-Are-Hiring
X-Worker
Store-Cloud-Cache
X-Varnish-Hostname
X-Varnish-CookieINHashed-On
X-V-Cache
X-Varnish-Beresp-Status
X-Varnish-CookieHashed-On
Time-Cloud-Cache
X-Cms-Device
X-Save-Cache
X-Vary-Devices
X-Viewer-Country
X-Ee-Request-Id
X-Ee-Request-Date
X-Core-Value
X-Ee-Generated-By
X-Ee-Origin
X-Uri
X-Up
X-Origin-Time
X-Path
X-PAYTM-SRV-ID
X-Policy
X-Nyt-Route
X-Node-Id
X-Moov-T
X-Moov-Xdn-Caching-Status
X-Moov-Xdn-Version
X-Pubstack
X-Region-Sid
X-Thinkindot-L1
X-Thinkindot-L3
X-UA-Device-Type
X-Sn-Servicetimems
X-SIPLIST1
X-Req
X-SD-PageType
X-Shield-Cache-Expires
Req-Svc-Chain
X-GoCache-CacheStatus
Azure-SiteName
Cmstype
Azure-RegionName
L5d-Success-Class
DSUID
Azure-SlotName
Origin-CC
Origin-EX
Country-Code
Cmsid
Gannett-Cam-Experience-Id
Azure-InstanceId
IsBot
L
Origin-Agent-Cluster
Ha-Gx-Prefs
CDCHOST
Gh-Request-Id
Cluster
Azure-Version
X-LSADC-Cache
X-Tt-Logid
X-Presslabs-Stats
X-Proto
X-Org
Click-Count-Error
Content-Style-Type
X-Gamma-Serve
Fastly-GeoIP-CountryCode
X-Esi-Check
X-Edge-Server
X-Dispatcher-Server
X-DPWN-IS-SECURE
Fastly-Backend-Name
X-Gzip
X-Mvc-Supplant-Cachable
X-NMSegId
Content-Script-Type
Cdn-Request-Time
X-HN
X-Op-Id-All
X-SVT-ORM-VERSION
X-Debug-Cache-Store
X-Generated-On
X-Debug-Cache-Fetch
Server-Host
RewriteTeamHook
RewriteTestHook
X-Ion-Healthy
X-Ion-Hop
X-ApacheServer
X-PERF
Host-ID
X-Render-Time
X-Jungle-Id
X-Level-Front-Cache
Nord-Request-ID
Cache-Contol
CacheControlHeader
C-Via
X-Thanos
X-SVT-ORM-RULES
Cdn-Host
X-Server-IP
X-VarnishDD-TTL
X-Vercel-Cache
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-Vmg-Version
X-Via-Fastly
X-Vercel-Id
X-SB
Click-Count-Action-Start
Tube-Got-Results
Tube-Return
X-Cache-FS-Status
Tube-Got-Eval
Tube-Get-Contents
Pragrma
Platform
PFcat
We-Hiring
X-B3-Trace-ID
NM-Fastcgi-Cache
X-Amz-Storage-Class
N-Cache
X-Bip
X-AB-Test
Machine
Mail-Subject
X-Cache-Id
X-Cache-Date
X-CacheTTL
Producers
Release
X-Parent-Response-Time
Product
Canary
X-Litespeed-Cache-Control
X-TH-Server
X-ElasticPress-Query
X-Location
Origin-Site
X-Mvc-Supplant-OutputCached
X-Origin-Response-Time
Fastly-Drupal-HTML
X-Proxied-Request
Sid
X-AWS-Id
X-Cs
X-VWS-Id
Source
X-LJ-Flow-ID
HA-Ipaddr
X-Amz-Meta-Cb-Modifiedtime
NGX
Debug
X-Pad
X-Cached-By
X-Cache-VC
S-Rt
Powered-By
X-ZONE
X-Refresh
X-APP
X-NGINX-Cache
CloudFront-Viewer-Country
X-Via-Poph
X-Nginx-Cache
Vix-Hermes-Req-Id
Mime-Version
X-Via-Popn
X-Via-Popv
X-Ah-Environment
X-ND-Cache
X-Servedbyhost
X-Upstream-Ht
X-Varnish-Hits
X-Upstream-Ct
X-Nananana
Pics-Label
X-User
Cookie
Edge-Cache
GeoIP-Latitude
X-HA-Backend
X-Cdn-Forward
X-LB-ID
X-Datadome
Server-ID
X-DynaTrace-JS-Agent
Surrogated-Key
X-AIR-PT
X-LB-NoCache
X-GeoIP
Akamai-Mon-Iucid-Del
MIME-Version
X-Webkit-CSP
X-Fpc
HostName
GeoIp-Country-Code
X-Request-Start
X-Zone
X-Nc
X-Wa
WZWS-RAY
X-Scheme
X-Srv
SID
DataCenter
Resin-Trace
X-B3-Parentspanid
Fastly-Drupal-Html
N1-Cache
X-Debug-Service
X-NodeID
X-Nginx-Cache-Key
X-Request-Host
X-Unity-Cache
X-Pool
X-RequestId
X-CS
X-Cache-Grace
True-Client-Country-4JS
Sever-Int
Tcn
Server-Hostname
Server-Ext
X-LiteSpeed-Cache-Control
X-Lsadc-Cache
X-VCL-Version
X-Vgn-Hpd-Reason
Wsr-Cache
Sm-Log-Id
X-DynaTrace
X-Service-Response-Time
Show-Do-Not-Sell-Link
X-DataCenter
Cdn
Yak-Timeinfo
Lb
Load-Balancing
X-B3-Spanid
X-FORWARDED-FOR
X-Air-Hostname
Yjs-Id
NtCoent-Length
X-Air-Trace-Id
X-Cache-Backend
X-Air-Source
X-Newrelic-Synthetics
Edge-Copy-Time
X-Via-Edge
X-Via-SSL
X-HOST
X-Geolocation
X-Datacenter
X-TX-ID
X-Zen-Fury
X-Via-CDN
X-Vc
X-NODE
X-RateLimit-Limit
Traceparent
X-Jobs
Req-ID
X-Client-Ip
X-API-Version
Cdn-Requestid
Datacenter
X-Cdn-Srv
X-WA
X-HubSpot-Correlation-Id
CDN
X-LiteSpeed-Tag
X-FPC
Hostname
X-CDN-Provider
X-ID
X-NC
X-Powered-By-VTEX-Cache
X-Fastly-Backend-Reqs
X-Dynatrace-Js-Agent
Uri
X-Udemy-Cache-App-Namespace
X-VTEX-Cache-Server
WP-Super-Cache
X-VTEX-Cache-Time
GeoIP-Country-Code
Serverhost
X-Webkit-Csp-Report-Only
X-Akamai-Pragma-Client-IP
Server-Id
Xkey-La3
X-Proxy-CacheR9
XkeyR9
X-Proxy-Cache-La3
True-Client-IP
X-Html-Minification-Powered-By
Xkeylog
X-Ez-Minify-Js
X-TimeS
On-Server
X-Stale
Geoip-Latitude
X-WA-Info
A
Coldstone-Viewer-Country
RATING
T-Server
Coldstone-Viewer-Country-Region-Name
Coldstone-Viewer-Currency
X-Lb-Id
Proxy-Firewall
ServerHost
X-Swift-Error
X-Varnish-Beresp-TTL
X-Lb-Nocache
Srv
X-ServedByHost
From-Cache
CountryCode
X-Oracle-DMS-ECID
WebServer
Esi-Enabled
X-Ha-Backend
Cloudfront-Viewer-Country
X-Via-JSL
X-CSRF-TOKEN
X-App
BehaviorPad-Version
X-Wp-Cf-Super-Cache-Cache-Control
X-LAGOON
X-Wp-Cf-Super-Cache
X-Fastly-Cache
X-MSEdge-Flight
X-Ssense-Gql
X-VC-Age
X-Ssense-Shipping-Surcharge-Enabled
X-Correlation-ID
FSS-Cache
X-Via-PopN
X-Via-PopV
Cs
X-MSEdge-Features
X-Via-PopH
X-Srcache-Fetch-Status
X-Srcache-Store-Status
X-HA-Device-Type
X-HA-Application-Name
Pramga
X-HA-Bot-Classification
Cr
X-Styx-Info
X-Styx-Origin-Id
X-Nitro-Cache
X-Sorting-Hat-Shopid
Ngx
X-Shopid
X-Shardid
X-Geo
X-Request-Time
X-Sorting-Hat-Podid
X-Web-Server
X-Cdn-Cache-Status
X-Check-Cacheable
X-Wp-Cf-Super-Cache-Active
X-Elasticpress-Query
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-ATG-Version
True-Client-Ip
X-DC
X-Fastly-Cache-Status
X-Th-Server
Akamai-X-True-TTL
X-Proxy-Cache-LA2
X-Serial
X-Request-Url
X-Var-Ttl
My-App
Content-Secure-Policy
X-TIM-N
X-Ez-Minify-Html
Cf-Ipcountry
X-Ramcache
Ohc-Cache-HIT
W
User-Agent
X-Platform-Server
X-Cache-TTL-Remaining
Bxuuid
X-Fastly-Cache-Hits
Cneonction
X-Sucuri-Id
FSS-Proxy
Bxpunish
Host-Name
X-Beacon
Warning
X-Mg-Cache
X-VServer
X-Env
Ohc-File-Size