Threat Level: green Handler on Duty: Yee Ching Tok

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
X-Frame-Options
Expires
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Accept-CH
Last-Modified
CF-Cache-Status
X-XSS-Protection
ETag
Expect-CT
Accept-Ranges
CF-RAY
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Alt-Svc
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
Cf-Request-Id
X-UA-Compatible
X-Served-By
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Xss-Protection
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
Accept-CH-Lifetime
Content-Security-Policy-Report-Only
X-DNS-Prefetch-Control
X-AspNet-Version
X-Runtime
Server-Timing
X-Drupal-Cache
Permissions-Policy
CF-Ray
X-Generator
X-Envoy-Upstream-Service-Time
X-Cache-Status
X-Ua-Compatible
X-Cacheable
X-Iinfo
X-FRAME-OPTIONS
Timing-Allow-Origin
X-Drupal-Dynamic-Cache
Feature-Policy
X-CONTENT-TYPE-OPTIONS
X-Content-Security-Policy
Xkey
Upgrade
Access-Control-Expose-Headers
Content-Encoding
X-CDN
Status
X-XSS-PROTECTION
X-AspNetMvc-Version
Accept-Ch
Access-Control-Max-Age
Host-Header
X-Age
X-Amz-Request-Id
X-Amz-Id-2
Request-Context
Cf-Edge-Cache
X-Backend
X-Robots-Tag
X-Hacker
X-Via
Cf-Apo-Via
X-Request-ID
X-UA-Device
X-Turbo-Charged-By
X-Rq
X-Vhost
X-Amz-Version-Id
X-Cache-Group
Keep-Alive
X-Dispatcher
X-AH-Environment
EagleId
X-Proxy-Cache
X-Server
X-Ws-Request-Id
X-OneAgent-JS-Injection
CONTENT-SECURITY-POLICY
X-Varnish-Cache
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
Grace
P3p
Pantheon-Trace-Id
X-Server-Powered-By
Allow
X-Dns-Prefetch-Control
X-Pingback
X-Page-Speed
X-Swift-CacheTime
X-Swift-SaveTime
X-WebKit-CSP
Ali-Swift-Global-Savetime
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-LiteSpeed-Cache
X-Node
X-FTR-Request-ID
X-Litespeed-Cache
X-Device
EagleEye-TraceId
X-Host
X-Cache-Lookup
X-Ruxit-JS-Agent
X-Backend-Server
Surrogate-Control
X-Country-Code
X-Server-Id
X-Readtime
X-Cloud-Trace-Context
X-Akam-SW-Version
Cf-Railgun
X-HW
X-Response-Time
Cache-Tag
Content-Location
X-Amz-Server-Side-Encryption
Cross-Origin-Opener-Policy
X-Rack-Cache
X-Nginx-Upstream-Cache-Status
X-Country
X-Trace
Service-Worker-Allowed
X-Nginx-Cache-Status
Fastly-Restarts
X-TraceId
Request-Id
X-Content-Type
X-Clacks-Overhead
X-PC
X-Vname
X-TtlSet
X-Application-Context
X-Times
Rating
X-Cnection
X-Cache-TTL
Surrogate-Key
X-Midtier
X-Edge
X-Mcache
X-ESI
X-Browser-Type
X-Vcap-Request-Id
X-FTR-Balancer
X-FTR-Backend
X-FTR-Cache-Status
X-Country-Code-Real
X-FTR-Backend-Server
X-Ac
X-FTR-Expires
Origin-Trial
Edge-Control
Accept-Ch-Lifetime
X-Powered-By-Plesk
X-Cdn-Fetch
X-GoogleNews-Bot
X-Kinja
X-Exp-Id
X-Kinja-Revision
X-Abt-Application-Version
X-Exp-Variant
X-Kinja-Build
X-Kinja-Server
X-Element-Page-Cache
X-NWS-LOG-UUID
X-D2id
Verso
X-Upstream
X-ECACHE
X-ORACLE-DMS-RID
X-B3-TraceId
X-Client-IP
Nginx-Cache
X-Navigation-Version
X-Amz-Rid
X-Mod-Pagespeed
X-Middleton-Display
Pagespeed
X-Sol
Display
X-FastCGI-Cache
X-GitHub-Request-Id
Pinterest-Generated-By
X-Pinterest-Rid
Pinterest-Version
X-Nf-Request-Id
X-Erf-Bev-Bev
Response
X-Server-Lifecycle-Phase
X-Middleton-Response
X-Kraken-Loop-Name
X-Erf-Bev-Bev-Is-Generated
X-Instrumentation
X-PDP-UNCACHING-HASH
X-Ratelimit-Limit
X-Language
X-Envoy-Decorator-Operation
X-Goog-Hash
X-MS-InvokeApp
AR-Request-ID
AR-PoweredBy
AR-ATIME
X-ARC
Edge-Cache-Tag
S
X-Ser
Akamai-GRN
X-Edge-Location-Klb
X-Kinsta-Cache
X-Resp-Is-Stale
X-Content-Digest
X-Url
SPRequestDuration
SPIisLatency
X-Distributor
X-SharePointHealthScore
SPRequestGuid
Access-Control-Request-Method
X-Dw-Request-Base-Id
Front-End-Https
X-Cache-Key
X-Ezoic-Cdn
X-NGENIX-Cache
X-Recruiting
X-Shield-Request-Id
X-Forwarded-For
Cache-Status
X-Amzn-Trace-Id
RTSS
X-Powered-CMS
X-Version
Public-Key-Pins
X-Server-Name
X-Ttl
TP-Cache
X-MSEdge-Ref
Fastcgi-Cache
X-T
Arr-Disable-Session-Affinity
X-Accel-Expires
X-Daa-Tunnel
X-Mg-S
X-HS-Content-Id
X-HS-Hub-Id
X-HS-Cache-Config
X-Correlation-Id
X-Id
X-Ua-Device
X-Ismobilevalue
X-Fastly-Request-ID
Realpath
X-CST
X-Cluster-Name
Cache-Tags
X-Cached
X-Xrds-Location
AR-CACHE
X-Varnish-TTL
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-HS-Combine-CSS
X-ORACLE-DMS-ECID
X-Request-Processing-Time
X-Request-Received
Payment
X-TTL
X-Ua-Browser
X-DIS-Request-ID
X-GUploader-UploadID
X-Ratelimit-Remaining
Content-MD5
X-Newrelic-App-Data
X-Content-Security-Policy-Report-Only
X-Jurisdiction
X-HP-Trace-Id
X-HP-Webp
X-Cambria-Cache-Control
X-HS-CF-Cache-Status
X-HS-Prerendered
Count-Hit
Content-Disposition
X-PressLabs-Stats
X-Amz-Replication-Status
X-Webkit-Csp
X-RateLimit-Remaining
X-Azure-Ref
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Microsite
X-Request-Handler-Origin-Region
Cross-Origin-Resource-Policy
X-Hits
X-Px
X-Page-Id
X-Logged-In
X-Ratelimit-Reset
X-Protected-By
Accept-Charset
X-Unique-Id
X-Proxy
X-FB-Debug
X-Load-Cache
Cleartype
X-Git-Hash
X-Activity-Id
X-AppVersion
X-VARITI-CCR
X-Rid
X-Az
X-Www-Served-By
X-Origin-Server
X-Goog-Metageneration
X-Template
X-LLID
X-Varnish-Backend
Cross-Origin-Embedder-Policy
X-Server-ID
MicrosoftSharePointTeamServices
X-NF-Request-ID
X-Varnish-Ttl
Version
Server-Node
Server-Name
X-Forwarded-Proto
X-URL
YJS-ID
X-Amz-Meta-S3cmd-Attrs
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Upgrade-Enabled
X-Geo-Country
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Frontend
X-Hostname
X-Content-Options
X-Varnish-Server
X-B3-Sampled
X-Varnish-Grace
X-Wormhole-Sdk
X-TT
Section-Io-Cache
Mrf-Cache-Status
X-B3-TraceId-Primal
MRF-Tech
X-App-Server
X-Device-Type
X-B
X-Cache-Age
X-Fb-Rlafr
X-Grace
Fastly-SWR
Fastly-SIE
Ar-SID
Viewport
Access-Control-Allow-Method
TCN
X-Ruxit-Js-Agent
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Status
Alternate-Protocol
Upgrade-Insecure-Requests
AKAMAI-GRN
AR-SID
X-Tt-Trace-Host
X-Tt-Trace-Tag
Healthy
X-Oneagent-Js-Injection
Amp-Access-Control-Allow-Source-Origin
Host
X-Magnolia-Registration
X-SERVER-NAME
X-Request-Guid
X-Buckets
X-Fastcgi-Cache
X-CSRF-Token
X-EdgeConnect-Cache-Status
X-Debug
X-Request-Device-Id
Retry-After
DC
X-Amzn-Remapped-Content-Length
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
X-Cache-Control
X-WebKit-CSP-Report-Only
X-Contextid
X-Revision
X-Original-Request-Id
X-Response-Served-From
X-Origin-TTL
X-Adobe-Content
X-Adobe-Loc
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Origin-CC
X-Mobile
MS-Author-Via
X-Rendered-As
X-Akamai-Edgescape
X-NYM-Debug-Backend
X-G
Cross-Origin-Embedder-Policy-Report-Only
X-Instance
Access-Control-Request-Headers
X-Type
SD-X-WS
Cross-Origin-Opener-Policy-Report-Only
X-Vcl-Version
X-Is-Bot
X-Lambda-Id
X-Backend-Name
X-Hl-Ver
X-Debug-IsPreview
X-ServerID
X-Tec-Api-Version
X-Tec-Api-Root
X-UUID
X-Tec-Api-Origin
X-Debug-IsConnected
X-Trace-Id
Section-Io-Id
X-Content-Powered-By
X-Cache-Hit
X-Mg-Request-UUID
X-DataDome
X-Seen-By
X-Tumblr-User
X-Tumblr-Pixel-0
Charset
X-Framework
X-Tumblr-Pixel-1
X-Tumblr-Pixel
X-RM-Cache-TTL
X-RemovedCookies
X-Server-W
X-Storage
MS-CV
Ms-Operation-Id
X-Dc
X-ProcessESI
X-RTag
X-Cache-Time
NGB
X-INCAP-ABP
X-AB
X-Akamai-Request-ID2
Protected
X-N
X-Time
X-Meli-Trace-Site
X-Cache-Status-Check
Filterid
X-Meli-Trace-Platform
X-Meli-Trace-Bu
X-Request-Platform
X-Request-Bu
X-Request-Site
Refresh
X-Region
X-Real-IP
X-LB-Cache
SRV
Frame-Options
X-Node-Name
X-App-Version
Accept-Language
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
Cache
Webserver
X-B3-SpanId
CDN-RequestId
Cross-Origin-Window-Policy
X-CCDN-Origin-Time
X-CCDN-CacheTTL
X-Hcs-Proxy-Type
X-WP-CF-Super-Cache-Active
X-Datadog-Sampling-Priority
X-Datadog-Sampled
X-Datadog-Trace-Id
X-User-Agent
X-Datadog-Parent-Id
Paypal-Debug-Id
X-Ms-Version
X-Ms-Request-Id
X-Whom
Onion-Location
X-Cache-Expired-At
Priority
X-VC
OT-Force-Account-Verify
X-F-Cache
X-IPS-LoggedIn
Liferay-Portal
X-VC-Cache
X-COUNTRY
X-Mode
X-Proxy-Cache-Info
X-Rocket-Nginx-Serving-Static
X-HTML-Minification-Powered-By
X-Cacheable-TTL
Backend
X-App-Environment
Xet-Cookie
X-Tb
X-Pass-Why
X-L-Path
X-Environment-Context
X-Debug-Info
X-Source
X-Routing-Service
X-Rn-Rsrv
X-SaId
X-Rewrite-Enabled
X-Extlb
GEO-INFO
X-Cloudmap
X-MP-GENERATED-AT
X-Detected-As
X-Zipkin-Id
Url
X-JoinUs
X-Adobe-Source
X-UPSTREAM-Address
LB
X-Servername
X-Proxied
Meta-Geo
X-Forwarded-Host
X-Handled-By
X-Origin-Date
X-Hit
X-Service
X-Logging-Id
X-Loop
X-FW-Serve
ServedBy
X-Storefront-Renderer-Rendered
X-Shopify-Stage
X-FW-Dynamic
X-Rule
X-Varnish-Beresp-Grace
X-Alternate-Cache-Key
Web-Mar-Node
X-Web-Node
X-Vcache
X-FW-Hash
X-Tncms
X-FW-Version
Fastcgi-Useragent
Country
Atl-Traceid
X-FW-Type
X-Oracle-Dms-Ecid
X-FW-Static
X-FW-Server
X-Cms-Context
Webcakes-App-Name
Uber-Trace-Id
TWC-Locale-Group
Webcakes-App-Version
TWC-Privacy
X-Cache-Host
X-Cache-Action
X-IPLB-Instance
X-IPLB-Request-ID
TWC-GeoIP-Region
Webcakes-Region
TWC-GeoIP-DMA
X-Cdn-Origin
TWC-Connection-Speed
X-Cluster-Node
Mn-Server-Ip
Property-Id
TWC-Device-Class
X-Director
TWC-GeoIP-Country
X-Cluster
Apigw-Requestid
X-Format
TWC-GeoIP-City
TWC-GeoIP-LatLong
X-R9-Blue-Green-Version
X-Skip-Cache
X-Soup
X-Hosted-By
X-Say-TTL
X-Restarts
X-Say-Cacheable
X-Browser-Name
X-Endurance-Cache-Level
X-Is-Tablet
X-Tcp-Rtt
X-Is-Supported-Browser
X-Is-Mobile
X-Geo-Region
X-Is-Desktop
X-BYPASS-REASON
X-SayCDN-TTL
X-Origin-Hint
X-Drupal-Cache-Tags
X-Locale
X-Httpd
X-ProxyCache-Key
Environment
X-ProxyCache-Status
X-Wix-Request-Id
Filters
X-Requestid
X-Served-From
Countrycode
X-Edge-Location
X-Mly-Id
X-S
ServerID
X-Redis-Cache
X-Origin
X-Labrador-Cache-Channel
X-Scope-Id
X-Timing-Wait
Selected-Fe
X-Connection-Hash
X-Fetched-On
X-RateLimit-Remaining-Second
X-FB-TRIP-ID
X-Proxy-Build
DB-Nickname
X-RateLimit-Limit-Second
X-Auth-Group-Type
Cache-Hits
X-PHP-Host
Expiry
X-ECache
X-Tumblr-Pixel-3
X-Tumblr-Pixel-2
X-Generation-Time
X-Urbn-Context-Path
X-Urbn-Site-Id
Locale
X-Drupal-Cache-Contexts
X-Sorting-Hat-ShopId
X-Origin-Cache
X-Sorting-Hat-PodId
X-Varnish-Cache-Hits
X-ShardId
X-GEO
X-ShopId
X-Varnish-Age
X-No-Session
X-VCT
X-RCS-CacheZone
Request-ID
Front
WPO-Cache-Status
X-WP-CF-Super-Cache-Cookies-Bypass
X-SRV
X-HITS
X-Cache-Debug
X-NewRelic-App-Data
X-Varnish-Beresp-Ttl
X-Site-Version
X-UA
X-CLOUD-TRACE-CONTEXT
X-Webstats-RespID
X-Api-Version
X-CDN-Forward
X-Is-Modern-Browser
X-Lagoon
YJS-CacheStatus
Node
Xserver
From-Origin
X-TT-LOGID
X-Yandex-Req-Id
X-TA-CDN-Provider
X-Azure-Ref-OriginShield
Cache-Provider
X-Platform
X-Xfnlog-Site
X-Cdn
X-Generated-By
X-Accel-Version
X-Is-Mobile-Only
Referer-Policy
X-VC-TTL
X-B3-Traceid
X-Provided-By
X-Ua
WPO-Cache-Message
X-Reqid
CF-IPCountry
Cache-Tv-Group
X-Signature
X-B-Cache
X-Sucuri-Cache
X-CDN-Cache-Status
X-XRDS-Location
X-Tx-Id
X-Sucuri-ID
CDN-Uid
CDN-RequestPullSuccess
CDN-EdgeStorageId
CDN-CachedAt
CDN-Cache
CDN-PullZone
CDN-RequestCountryCode
CDN-RequestPullCode
X-Tb-Optimization-Total-Bytes-Saved
X-PHP-Backend
Location
X-Content-Age
AMP-Access-Control-Allow-Source-Origin
X-Ig-Origin-Region
X-GeoCountry
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
X-Ig-Push-State
Apple-News-Services-Handled
Apple-News-Services-Host
Candidate-Md5Url
X-GeoCode
X-Ec-GeoHdr
X-Ec-Fail
X-Developer
X-External-Request-Id
Cdnsip
Cdncip
X-Forwarded-Site
X-IsAdmin
X-Loc
X-Slack-Shared-Secret-Outcome
X-Slack-Backend
X-Sigma-Backend
X-SRCache-Key
X-Varnish-Director
X-VG-TLSProxy
X-Vdms-Version
X-Sigma
X-Section
X-Request-URI
X-Origin-Expires
X-Old-Content-Length
X-Rocket-Build-Number
X-Rojux
X-ScT
X-S-Cookie
X-Destination
X-D
Sslversion
X-BCube-Filmed-By
X-A
Rendered-Blocks
Redirect-Candidate
Origin
X-Bl-Debug
X-A-Ccd
X-B-Cookie
X-A-Dam
X-A-Dcw
X-A-Dgt
X-Access
X-Aed
X-Application
X-AK-Request-ID
Odigeo-Trace-Id
X-Cache-NE
Xc-Version
X-Cache-Rule
DCR-Decision-By
X-Vtex-Remote-Cache
XM
X-Conf
X-Clientip
DCR-Processing-Time-Ms
Expect-Staple
MD5-Digest
Meta-Geo-Continent
Lang
X-Cache-Operation
Fastly-SSL
Fl-Custom-Application
X-A-Wwc
Ngx.Var.Host
X-Frame-Option
X-NWS-UUID-VERIFY
X-VG-WebCache
X-Air-Pt
X-Fastly-Request-Id
X-Cache-Aspx
X-Akamai-Device-Characteristics
X-Bug-Bounty
X-Bc-Bl
X-Block-Status
X-Auto-Login
X-CGP
X-DefHash
X-Depends
X-Ec-Custom-Error
X-DefElseHash
X-CUA
X-Content-Length
X-Core-Value
X-Csrf-Jwt
X-Contensis-Viewer-Groups
X-Action
Origin-EX
Req-Svc-Chain
RNT-Machine
Origin-CC
Origin-Agent-Cluster
L
L5d-Success-Class
Log-Origin
RNT-Time
ServerName
X-Litespeed-Tag
X-Acquia-Purge-Cdn-Unconfigured
X-Epic-Correlation-Id
Wxu-Next-Region
Wxu-Next-Hostname
User-Cache-Control
Web-Mar-Region
Wxu-Next-Commit
X-Aicache-OS
X-Fastly-Backend
X-SD-PageType
X-SIPLIST1
X-Sn-Servicetimems
X-Req
X-Region-Sid
X-Viewer-Country
X-Policy
X-Pubstack
X-UA-Device-Type
X-Up
X-Varnish-CookieINHashed-On
X-Varnish-Hostname
X-Varnish-Remaining-TTL
X-Varnish-CookieHashed-On
X-Varnish-Beresp-Status
X-Uri
X-V-Cache
X-Varnish-Authentication
X-PAYTM-SRV-ID
X-Node-Id
X-Gen-Mode
X-GeoIP-City
X-Hash
X-From
X-LSADC-Cache
IsBot
X-FC-Vary-Parameters
X-Fmm-Version
X-Hnp-Log
X-HS-Content-Campaign-Id
X-Moov-T
X-Moov-Xdn-Caching-Status
X-Moov-Xdn-Version
X-Micro-Cache
X-Men
X-Human
X-Internal-TTL
X-Eu-Site
X-BBC-Edge-Cache-Status
X-Worker
Gannett-Cam-Experience-Id
Country-Code
CDCHOST
Cmstype
Cmsid
Ha-Gx-Prefs
DSUID
X-Optimistic-Header
Thinkindot-CacheControl
TDXMobile
X-Level-Front-Cache
X-App-Name
X-HN
Content-Script-Type
X-ApacheServer
X-Amz-Storage-Class
X-AB-Test
X-NMSegId
X-Nyt-Route
X-Op-Id-All
X-Org
X-Vmg-Version
X-Mvc-Supplant-Cachable
Thinkindot-CacheControl-Type
X-Accel-Expires-Debug
X-Backend-Instance
Content-Style-Type
X-Bip
Azure-SiteName
X-CacheTTL
Azure-RegionName
Azure-InstanceId
Azure-SlotName
Azure-Version
X-Date
C-Via
X-Dispatcher-Server
X-DPWN-IS-SECURE
X-Gamma-Serve
X-Gdpr
Click-Count-Error
X-GeoIP-Region-Code
X-Save-Cache
X-GoCache-CacheStatus
Click-Count-Action-Start
X-GeoIP-Country-Code
X-Generated-On
X-Cache-FS-Status
X-Cache-Date
Cluster
X-Vary-Devices
X-Ee-Origin
X-Server-IP
X-Ee-Generated-By
X-Via-Fastly
PFcat
Platform
Release
X-SB
Producers
Pragrma
NM-Fastcgi-Cache
X-SVT-ORM-RULES
X-Vercel-Cache
Gh-Request-Id
X-Vercel-Id
Host-ID
X-VarnishDD-TTL
X-Cms-Device
X-SVT-ORM-VERSION
N-Cache
X-Thanos
Time-Cloud-Cache
X-Ee-Request-Id
X-Ee-Request-Date
X-Origin-Time
X-Path
X-Shield-Cache-Expires
Store-Cloud-Cache
Tube-Get-Contents
Tube-Got-Eval
V-Age
X-We-Are-Hiring
Tube-Return
Tube-Got-Results
Server-Host
X-PERF
X-Render-Time
X-Thinkindot-L3
X-Proto
X-Thinkindot-L1
X-Tt-Logid
X-Parent-Response-Time
Fastly-Drupal-HTML
X-Ion-Healthy
X-Nginx-Cache
Cache-Contol
X-Debug-Cache-Store
X-Origin-Response-Time
X-Debug-Cache-Fetch
X-Esi-Check
X-Jungle-Id
X-Cs
X-Ion-Hop
X-TH-Server
X-ElasticPress-Query
X-Gzip
X-Mvc-Supplant-OutputCached
X-Edge-Server
X-Wikidot-Backend
We-Hiring
Mail-Subject
Fastly-GeoIP-CountryCode
Machine
Product
X-B3-Trace-ID
NGX
Nord-Request-ID
X-CACHE-AGE
X-Wikidot-Static-Cache
X-Cache-Id
Origin-Site
Cdn-Request-Time
Canary
RewriteTeamHook
CacheControlHeader
RewriteTestHook
Cdn-Host
Fastly-Backend-Name
Sid
Source
X-Location
X-Litespeed-Cache-Control
X-Amz-Meta-Cb-Modifiedtime
X-Proxied-Request
HA-Ipaddr
X-Refresh
X-AWS-Id
X-VWS-Id
X-ZONE
X-LJ-Flow-ID
X-Pad
X-Cached-By
Debug
X-Via-Popn
Powered-By
X-Via-Popv
S-Rt
X-Via-Poph
CloudFront-Viewer-Country
X-Cache-VC
X-Presslabs-Stats
X-AIR-PT
X-LB-ID
Vix-Hermes-Req-Id
Edge-Cache
X-Servedbyhost
X-Nananana
X-APP
GeoIP-Latitude
X-HA-Backend
X-User
X-Varnish-Hits
Mime-Version
Pics-Label
Cookie
X-ND-Cache
Server-ID
X-Ah-Environment
X-Upstream-Ht
Surrogated-Key
X-Cdn-Forward
X-Upstream-Ct
X-NGINX-Cache
HostName
X-DynaTrace-JS-Agent
X-Datadome
X-LB-NoCache
X-GeoIP
Akamai-Mon-Iucid-Del
X-Fpc
X-Wa
X-Nc
X-Request-Start
X-Webkit-CSP
MIME-Version
DataCenter
X-Zone
X-Scheme
SID
N1-Cache
GeoIp-Country-Code
X-LiteSpeed-Cache-Control
X-Srv
WZWS-RAY
X-Request-Host
X-NodeID
Resin-Trace
X-Pool
Fastly-Drupal-Html
X-RequestId
X-Unity-Cache
X-Cache-Grace
X-B3-Parentspanid
X-Nginx-Cache-Key
X-CS
Tcn
X-DataCenter
X-Vgn-Hpd-Reason
X-Debug-Service
Yak-Timeinfo
X-Lsadc-Cache
X-VCL-Version
True-Client-Country-4JS
Show-Do-Not-Sell-Link
Cdn
Sever-Int
X-Service-Response-Time
Sm-Log-Id
X-Air-Source
Lb
Server-Hostname
Wsr-Cache
X-DynaTrace
Server-Ext
X-Air-Hostname
X-Air-Trace-Id
Load-Balancing
X-Via-SSL
X-Newrelic-Synthetics
X-Via-CDN
Edge-Copy-Time
X-Via-Edge
X-B3-Spanid
Yjs-Id
X-Geolocation
X-Zen-Fury
X-Jobs
X-Datacenter
X-HOST
NtCoent-Length
Req-ID
X-Cache-Backend
X-TX-ID
Traceparent
X-NODE
X-LiteSpeed-Tag
X-Cdn-Srv
X-RateLimit-Limit
GeoIP-Country-Code
Uri
X-Udemy-Cache-App-Namespace
CDN
X-HubSpot-Correlation-Id
Cdn-Requestid
X-API-Version
X-Powered-By-VTEX-Cache
X-VTEX-Cache-Server
X-WA
X-VTEX-Cache-Time
X-Html-Minification-Powered-By
X-Vc
Datacenter
X-FPC
X-CDN-Provider
X-FORWARDED-FOR
WP-Super-Cache
X-NC
X-Fastly-Backend-Reqs
X-Webkit-Csp-Report-Only
Coldstone-Viewer-Currency
True-Client-IP
X-Stale
Hostname
Serverhost
Coldstone-Viewer-Country-Region-Name
X-WA-Info
Coldstone-Viewer-Country
Server-Id
X-Ez-Minify-Js
X-Dynatrace-Js-Agent
X-Akamai-Pragma-Client-IP
Geoip-Latitude
T-Server
On-Server
X-TimeS
RATING
X-Proxy-CacheR9
Xkeylog
XkeyR9
A
X-Proxy-Cache-La3
Xkey-La3
X-Swift-Error
X-Lb-Id
ServerHost
Srv
From-Cache
X-Lb-Nocache
X-Varnish-Beresp-TTL
X-ServedByHost
BehaviorPad-Version
WebServer
X-Oracle-DMS-ECID
X-Client-Ip
X-Via-JSL
X-Ha-Backend
X-CSRF-TOKEN
Proxy-Firewall
Cloudfront-Viewer-Country
Esi-Enabled
X-App
X-ID
X-LAGOON
X-Request-Time
Cs
X-Correlation-ID
X-Ssense-Shipping-Surcharge-Enabled
FSS-Cache
X-Fastly-Cache
X-Nitro-Cache
X-Ssense-Gql
X-MSEdge-Features
X-Via-PopH
X-Via-PopN
X-MSEdge-Flight
X-VC-Age
X-Via-PopV
X-Srcache-Fetch-Status
X-Srcache-Store-Status
CountryCode
Cr
Pramga
X-HA-Application-Name
X-HA-Device-Type
X-Shardid
X-Styx-Info
My-App
X-Styx-Origin-Id
X-Geo
X-Sorting-Hat-Shopid
X-Cdn-Cache-Status
Ohc-Cache-HIT
Ohc-File-Size
True-Client-Ip
X-Shopid
X-Web-Server
X-HA-Bot-Classification
X-Check-Cacheable
X-Sorting-Hat-Podid
X-ATG-Version
Ms-Author-Via
X-DC
X-Th-Server
X-Fastly-Cache-Status
X-Elasticpress-Query
X-TIM-N
X-Request-Url
X-Platform-Server
X-Proxy-Cache-LA2
X-Serial
X-Wp-Cf-Super-Cache-Cache-Control
Ngx
Content-Secure-Policy
X-Wp-Cf-Super-Cache
Akamai-X-True-TTL
X-VServer
Cf-Ipcountry
X-Var-Ttl
User-Agent
X-Sucuri-Id
Bxuuid
X-Cache-TTL-Remaining
Bxpunish
X-Beacon
Warning
X-Fastly-Cache-Hits
Cneonction
X-Snapshot-Date
Host-Name
X-Mg-Cache
FSS-Proxy
X-Env