Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
X-Frame-Options
Expires
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Accept-CH
Last-Modified
X-XSS-Protection
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
CF-RAY
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Alt-Svc
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-Download-Options
Cf-Request-Id
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
X-Xss-Protection
Access-Control-Allow-Credentials
Accept-CH-Lifetime
Content-Security-Policy-Report-Only
X-DNS-Prefetch-Control
X-AspNet-Version
X-Runtime
Server-Timing
Permissions-Policy
X-Drupal-Cache
CF-Ray
X-Generator
X-Envoy-Upstream-Service-Time
X-Cache-Status
X-Ua-Compatible
X-Cacheable
X-FRAME-OPTIONS
X-Iinfo
X-Drupal-Dynamic-Cache
Timing-Allow-Origin
Feature-Policy
X-CONTENT-TYPE-OPTIONS
X-Content-Security-Policy
Xkey
Upgrade
Access-Control-Expose-Headers
Content-Encoding
X-CDN
X-XSS-PROTECTION
Status
X-AspNetMvc-Version
Accept-Ch
Access-Control-Max-Age
Host-Header
X-Amz-Request-Id
X-Age
X-Amz-Id-2
Request-Context
Cf-Edge-Cache
X-Backend
X-Robots-Tag
X-Hacker
X-Request-ID
X-Via
Cf-Apo-Via
X-Turbo-Charged-By
X-Rq
X-Amz-Version-Id
X-Cache-Group
X-Vhost
Keep-Alive
X-AH-Environment
X-Dispatcher
X-Server
X-Proxy-Cache
EagleId
X-UA-Device
X-Ws-Request-Id
CONTENT-SECURITY-POLICY
X-OneAgent-JS-Injection
X-Varnish-Cache
Pantheon-Trace-Id
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
Grace
X-Server-Powered-By
X-Dns-Prefetch-Control
Allow
X-Pingback
X-Page-Speed
X-WebKit-CSP
X-Swift-CacheTime
X-Swift-SaveTime
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Ali-Swift-Global-Savetime
X-Litespeed-Cache
X-FTR-Request-ID
X-Node
X-Device
EagleEye-TraceId
X-LiteSpeed-Cache
X-Host
X-Cache-Lookup
X-Backend-Server
Surrogate-Control
X-Country-Code
X-Server-Id
X-Readtime
X-Cloud-Trace-Context
X-Ruxit-JS-Agent
X-Akam-SW-Version
Cf-Railgun
X-HW
X-Response-Time
Cache-Tag
P3p
Content-Location
X-Amz-Server-Side-Encryption
Cross-Origin-Opener-Policy
X-Rack-Cache
X-Trace
X-Nginx-Upstream-Cache-Status
Service-Worker-Allowed
X-Nginx-Cache-Status
Request-Id
X-TraceId
Fastly-Restarts
X-Clacks-Overhead
X-Content-Type
X-Country
X-Application-Context
X-PC
X-TtlSet
X-Vname
Rating
X-Times
X-Cnection
X-ESI
X-Cache-TTL
X-Browser-Type
X-Edge
X-Midtier
X-Mcache
X-FTR-Backend
X-FTR-Backend-Server
X-FTR-Cache-Status
X-FTR-Balancer
X-Country-Code-Real
X-Vcap-Request-Id
Surrogate-Key
X-FTR-Expires
Accept-Ch-Lifetime
X-Ac
Origin-Trial
Edge-Control
X-Powered-By-Plesk
X-GoogleNews-Bot
X-Exp-Variant
X-Kinja-Build
X-Element-Page-Cache
X-D2id
X-Kinja-Revision
X-Abt-Application-Version
X-Cdn-Fetch
X-Exp-Id
X-Kinja
X-Kinja-Server
X-NWS-LOG-UUID
X-FastCGI-Cache
X-Ua-Device
Verso
X-Upstream
X-Nf-Request-Id
X-B3-TraceId
X-ORACLE-DMS-RID
X-Navigation-Version
X-ECACHE
X-Mod-Pagespeed
X-Amz-Rid
Nginx-Cache
X-Sol
Pagespeed
X-Middleton-Display
Display
X-Pinterest-Rid
Pinterest-Version
X-GitHub-Request-Id
Pinterest-Generated-By
X-Client-IP
X-Language
X-Kraken-Loop-Name
X-PDP-UNCACHING-HASH
Response
X-Erf-Bev-Bev
X-Server-Lifecycle-Phase
X-Middleton-Response
X-Erf-Bev-Bev-Is-Generated
X-Instrumentation
Akamai-GRN
X-Envoy-Decorator-Operation
X-Ratelimit-Limit
S
Edge-Cache-Tag
AR-PoweredBy
AR-Request-ID
AR-ATIME
X-Goog-Hash
X-Resp-Is-Stale
X-MS-InvokeApp
X-ARC
X-Kinsta-Cache
X-Edge-Location-Klb
X-Ser
X-Distributor
X-Content-Digest
SPIisLatency
SPRequestDuration
SPRequestGuid
X-SharePointHealthScore
X-Url
Access-Control-Request-Method
X-Cache-Key
X-Dw-Request-Base-Id
X-Ezoic-Cdn
Front-End-Https
X-NGENIX-Cache
X-Recruiting
X-Shield-Request-Id
RTSS
X-Amzn-Trace-Id
X-Oneagent-Js-Injection
Cache-Status
X-Version
X-Powered-CMS
X-Varnish-TTL
X-Ttl
Public-Key-Pins
X-T
Fastcgi-Cache
X-MSEdge-Ref
X-Mg-S
TP-Cache
Arr-Disable-Session-Affinity
X-Forwarded-For
X-Accel-Expires
X-Daa-Tunnel
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Cache-Config
X-Correlation-Id
X-Ismobilevalue
Realpath
X-Fastly-Request-ID
X-Cluster-Name
Cache-Tags
X-Cached
X-Id
X-Ruxit-Js-Agent
AR-CACHE
X-CST
X-Server-Name
X-HS-Combine-CSS
X-Request-Received
X-Request-Processing-Time
Payment
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Ua-Browser
X-DIS-Request-ID
X-Content-Security-Policy-Report-Only
Content-MD5
X-GUploader-UploadID
X-Newrelic-App-Data
X-Ratelimit-Remaining
X-TTL
X-HP-Trace-Id
X-Jurisdiction
X-HP-Webp
X-HS-Prerendered
X-HS-CF-Cache-Status
X-Cambria-Cache-Control
X-Xrds-Location
Content-Disposition
X-Webkit-Csp
X-RateLimit-Remaining
Count-Hit
X-Azure-Ref
X-ORACLE-DMS-ECID
X-Amz-Replication-Status
X-Px
X-Page-Id
Cleartype
X-Unique-Id
X-Request-Handler-Origin-Region
X-Ratelimit-Reset
Cross-Origin-Resource-Policy
X-Microsite
Accept-Charset
X-Proxy
X-Logged-In
X-FB-Debug
X-Git-Hash
X-Az
X-Activity-Id
X-Origin-Server
X-Protected-By
X-AppVersion
X-Rid
X-SRCache-Store-Status
X-SRCache-Fetch-Status
Cross-Origin-Embedder-Policy
X-VARITI-CCR
X-Www-Served-By
X-Load-Cache
X-LLID
X-Template
X-Goog-Metageneration
X-PressLabs-Stats
YJS-ID
X-Varnish-Backend
MicrosoftSharePointTeamServices
X-SERVER-NAME
X-Amz-Meta-S3cmd-Attrs
X-URL
Version
X-Forwarded-Proto
Server-Node
X-Hits
X-Geo-Country
Server-Name
Ar-SID
X-Upgrade-Enabled
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Hostname
X-Content-Options
X-Frontend
X-B3-Sampled
Section-Io-Cache
X-Varnish-Server
Viewport
X-Status
X-App-Server
X-Varnish-Grace
X-TT
X-B3-TraceId-Primal
X-Device-Type
X-Request-Device-Id
Mrf-Cache-Status
MRF-Tech
Alternate-Protocol
X-Fb-Rlafr
X-Grace
X-B
Fastly-SIE
Fastly-SWR
Access-Control-Allow-Method
X-Server-ID
TCN
X-NF-Request-ID
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Goog-Storage-Class
Upgrade-Insecure-Requests
Healthy
X-Request-Guid
X-COUNTRY
Host
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Magnolia-Registration
Amp-Access-Control-Allow-Source-Origin
X-Buckets
X-WebKit-CSP-Report-Only
X-CSRF-Token
X-Varnish-Ttl
DC
X-EdgeConnect-Cache-Status
AKAMAI-GRN
X-Cache-Age
Retry-After
X-Wormhole-Sdk
X-Debug
X-Amzn-Remapped-Content-Length
X-Meli-Trace-Bu
X-Contextid
X-Meli-Trace-Site
X-Meli-Trace-Platform
X-Cache-Control
MS-Author-Via
AR-SID
X-Revision
X-Instance
X-WP-CF-Super-Cache
X-Original-Request-Id
X-WP-CF-Super-Cache-Cache-Control
X-Response-Served-From
X-Yottaa-Optimizations
X-Yottaa-Metrics
Cross-Origin-Embedder-Policy-Report-Only
X-Origin-TTL
X-Adobe-Loc
X-NYM-Debug-Backend
X-Adobe-Content
X-Seen-By
X-Origin-CC
X-UUID
X-Rendered-As
Cross-Origin-Opener-Policy-Report-Only
X-Is-Bot
X-Vcl-Version
X-Type
X-Akamai-Edgescape
Access-Control-Request-Headers
X-Lambda-Id
X-Hl-Ver
X-G
SD-X-WS
Section-Io-Id
X-Backend-Name
X-Trace-Id
X-Debug-IsConnected
X-ServerID
X-Mobile
X-Content-Powered-By
X-Mg-Request-UUID
X-Framework
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
Charset
X-Tumblr-User
X-Debug-IsPreview
X-Tumblr-Pixel
X-Server-W
Ms-Operation-Id
X-INCAP-ABP
NGB
X-Cache-Hit
MS-CV
X-RM-Cache-TTL
X-RTag
X-Storage
X-Dc
X-Akamai-Request-ID2
X-N
X-AB
X-DataDome
X-App-Version
X-ProcessESI
X-RemovedCookies
X-Request-Bu
X-Request-Site
X-Request-Platform
X-Cache-Status-Check
X-Cache-Time
X-Tec-Api-Root
X-Tec-Api-Origin
X-Tec-Api-Version
Refresh
Filterid
Frame-Options
VIX-Pulpo-Upstream-Status
X-Time
VIX-Pulpo-Node
Cache
X-Fastcgi-Cache
Accept-Language
X-B3-SpanId
Protected
SRV
X-Real-IP
X-Region
X-Node-Name
X-Oracle-Dms-Ecid
Webserver
Paypal-Debug-Id
CDN-RequestId
X-User-Agent
X-HITS
Onion-Location
X-Hcs-Proxy-Type
X-Ms-Request-Id
X-Ms-Version
X-CCDN-Origin-Time
X-CCDN-CacheTTL
Cross-Origin-Window-Policy
X-LB-Cache
Liferay-Portal
X-Datadog-Sampling-Priority
X-Datadog-Sampled
X-VC-Cache
X-Datadog-Trace-Id
X-Datadog-Parent-Id
X-Cache-Expired-At
X-F-Cache
X-Whom
X-IPS-LoggedIn
X-Requestid
Priority
X-HTML-Minification-Powered-By
X-WP-CF-Super-Cache-Active
X-Mode
X-Rocket-Nginx-Serving-Static
Xet-Cookie
OT-Force-Account-Verify
X-Pass-Why
Backend
X-L-Path
GEO-INFO
X-Environment-Context
X-Proxy-Cache-Info
X-Tb
X-Service
X-Drupal-Cache-Tags
X-App-Environment
X-Cacheable-TTL
X-Loop
X-MP-GENERATED-AT
X-JoinUs
X-Proxied
X-UPSTREAM-Address
X-Is-Supported-Browser
X-Tncms
X-Zipkin-Id
X-Is-Tablet
X-Servername
X-Rewrite-Enabled
Web-Mar-Node
Url
X-Routing-Service
X-Handled-By
X-SaId
X-Adobe-Source
X-Browser-Name
X-Rn-Rsrv
ServerID
X-Is-Mobile
X-FW-Dynamic
X-Vcache
Fastcgi-Useragent
X-Detected-As
X-FW-Version
X-FW-Type
Filters
X-Extlb
X-Debug-Info
Meta-Geo
X-Endurance-Cache-Level
X-Geo-Region
X-Cloudmap
X-Is-Desktop
X-Tcp-Rtt
X-FW-Hash
X-FW-Serve
X-FW-Static
X-FW-Server
LB
Webcakes-App-Name
X-Rule
Webcakes-Region
TWC-GeoIP-DMA
Webcakes-App-Version
X-Restarts
X-IPLB-Request-ID
TWC-Locale-Group
X-IPLB-Instance
TWC-GeoIP-LatLong
TWC-Privacy
TWC-GeoIP-Region
X-Origin-Hint
TWC-GeoIP-City
TWC-GeoIP-Country
X-Hit
X-Locale
X-Web-Node
X-Logging-Id
X-Shopify-Stage
X-Varnish-Beresp-Grace
X-Wix-Request-Id
X-Storefront-Renderer-Rendered
Property-Id
X-Hosted-By
X-Cdn-Origin
X-Generation-Time
Atl-Traceid
X-Director
X-Cache-Host
Country
X-Alternate-Cache-Key
TWC-Device-Class
X-Forwarded-Host
TWC-Connection-Speed
X-Format
X-Origin-Date
ServedBy
Mn-Server-Ip
X-ProxyCache-Status
X-BYPASS-REASON
X-Httpd
X-Cache-Action
X-Edge-Location
X-ProxyCache-Key
X-Cluster
X-Cluster-Node
X-Soup
Uber-Trace-Id
X-Skip-Cache
X-Say-TTL
X-SayCDN-TTL
X-Redis-Cache
X-Cms-Context
X-Scope-Id
X-Say-Cacheable
Apigw-Requestid
X-VC
X-ECache
Environment
X-Labrador-Cache-Channel
X-FB-TRIP-ID
X-Mly-Id
X-Drupal-Cache-Contexts
X-S
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-Served-From
X-PHP-Host
X-XRDS-Location
X-Timing-Wait
X-Origin-Cache
Expiry
X-Auth-Group-Type
DB-Nickname
X-Proxy-Build
X-Origin
X-R9-Blue-Green-Version
X-Urbn-Site-Id
X-Fetched-On
X-Tumblr-Pixel-2
X-Tumblr-Pixel-3
X-Connection-Hash
Locale
X-Urbn-Context-Path
Selected-Fe
Cache-Hits
X-GEO
X-VCT
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-No-Session
X-RCS-CacheZone
X-ShopId
X-ShardId
YJS-CacheStatus
X-Varnish-Cache-Hits
X-Cache-Debug
X-Source
X-NewRelic-App-Data
X-Yandex-Req-Id
X-Varnish-Age
X-Is-Modern-Browser
Front
X-SRV
Countrycode
X-WP-CF-Super-Cache-Cookies-Bypass
X-CLOUD-TRACE-CONTEXT
X-UA
WPO-Cache-Status
X-Api-Version
X-Lagoon
Node
Xserver
X-Varnish-Beresp-Ttl
X-Provided-By
X-CDN-Forward
X-Webstats-RespID
X-Is-Mobile-Only
X-Site-Version
Cache-Tv-Group
X-Generated-By
X-Platform
X-Cdn
From-Origin
Cache-Provider
X-Accel-Version
X-B3-Traceid
X-Azure-Ref-OriginShield
X-TA-CDN-Provider
Referer-Policy
X-CACHE-AGE
X-Xfnlog-Site
X-CDN-Cache-Status
X-VC-TTL
X-Signature
X-B-Cache
X-Ua
Request-ID
X-TT-LOGID
X-Presslabs-Stats
CF-IPCountry
X-PHP-Backend
X-NWS-UUID-VERIFY
X-Sucuri-Cache
WPO-Cache-Message
Location
CDN-PullZone
CDN-RequestCountryCode
CDN-Uid
CDN-RequestPullSuccess
X-Tx-Id
CDN-RequestPullCode
CDN-EdgeStorageId
AMP-Access-Control-Allow-Source-Origin
X-Reqid
CDN-Cache
CDN-CachedAt
X-Air-Pt
X-Cache-Rule
X-Cache-Operation
X-Optimistic-Header
X-Tb-Optimization-Total-Bytes-Saved
X-Fastly-Request-Id
X-IsAdmin
X-Sucuri-ID
X-Tt-Logid
Candidate-Md5Url
Log-Origin
Rendered-Blocks
X-Access
Apple-News-Services-Parsed-Url
Odigeo-Trace-Id
Apple-News-Services-Host
Ngx.Var.Host
Origin
Redirect-Candidate
Apple-News-Services-Request-Url
RNT-Machine
MD5-Digest
Store-Cloud-Cache
DCR-Decision-By
Cdnsip
Expect-Staple
X-A-Dgt
X-A-Ccd
X-A-Dam
Meta-Geo-Continent
X-A-Dcw
Cdncip
X-A
X-A-Wwc
DCR-Processing-Time-Ms
Sslversion
Time-Cloud-Cache
Lang
Fastly-SSL
Web-Mar-Region
Fl-Custom-Application
RNT-Time
X-Cms-Device
X-Rocket-Build-Number
X-Request-URI
X-Rojux
X-S-Cookie
X-ScT
X-Save-Cache
X-Origin-Expires
X-Old-Content-Length
X-Ig-Origin-Region
XM
X-Ig-Push-State
X-Loc
X-Micro-Cache
X-Section
X-Sigma
X-VG-TLSProxy
X-Vdms-Version
X-VG-WebCache
X-Viewer-Country
Xc-Version
X-Vtex-Remote-Cache
X-Vary-Devices
X-Varnish-Director
X-Slack-Backend
X-Sigma-Backend
X-Slack-Shared-Secret-Outcome
X-SRCache-Key
X-Varnish-Authentication
X-HS-Content-Campaign-Id
X-GeoCountry
X-Clientip
X-Cache-NE
X-Conf
Apple-News-Services-Handled
X-Content-Age
X-Contensis-Viewer-Groups
X-Cache-Aspx
X-Bl-Debug
X-Application
X-AK-Request-ID
X-Auto-Login
X-B-Cookie
X-BCube-Filmed-By
X-Core-Value
X-D
X-Ee-Request-Id
X-Ee-Request-Date
X-External-Request-Id
X-Fmm-Version
X-GeoCode
X-Forwarded-Site
X-Ee-Origin
X-Ee-Generated-By
X-Destination
X-Depends
X-Developer
X-Ec-Fail
X-Ec-GeoHdr
X-Aed
X-Action
X-Frame-Option
X-DefHash
X-Ec-Custom-Error
X-Epic-Correlation-Id
X-Eu-Site
X-DefElseHash
X-CUA
X-Date
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-Fastly-Backend
X-From
X-GeoIP-Region-Code
X-GoCache-CacheStatus
X-Hash
X-GeoIP-Country-Code
X-GeoIP-City
X-Gdpr
X-Gen-Mode
X-Generated-On
X-Csrf-Jwt
X-Content-Length
Wxu-Next-Commit
Wxu-Next-Hostname
Wxu-Next-Region
X-Accel-Expires-Debug
V-Age
User-Cache-Control
TDXMobile
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
X-Acquia-Purge-Cdn-Unconfigured
X-Aicache-OS
X-Block-Status
X-Bug-Bounty
X-CGP
X-Bc-Bl
X-BBC-Edge-Cache-Status
X-Akamai-Device-Characteristics
X-App-Name
X-Backend-Instance
X-Hnp-Log
X-Human
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
X-We-Are-Hiring
X-Varnish-Beresp-Status
X-V-Cache
X-UA-Device-Type
X-Up
X-Uri
Cluster
Host-ID
X-SD-PageType
X-Varnish-Hostname
X-Worker
X-Req
X-PERF
X-ApacheServer
X-Node-Id
X-PAYTM-SRV-ID
X-Thinkindot-L3
X-Thinkindot-L1
X-Men
X-Moov-T
X-Moov-Xdn-Caching-Status
X-Moov-Xdn-Version
X-Level-Front-Cache
X-Jungle-Id
X-Internal-TTL
X-Ion-Healthy
X-Ion-Hop
X-Nyt-Route
X-Origin-Time
X-Shield-Cache-Expires
X-SIPLIST1
X-Sn-Servicetimems
X-Render-Time
X-Region-Sid
X-Path
X-Policy
X-Pubstack
ServerName
X-FC-Vary-Parameters
Azure-RegionName
Azure-SiteName
Azure-InstanceId
Cmstype
Req-Svc-Chain
L5d-Success-Class
Azure-SlotName
CDCHOST
Cache-Contol
Origin-Agent-Cluster
Origin-CC
Origin-EX
Nord-Request-ID
Azure-Version
RewriteTeamHook
Cmsid
L
Ha-Gx-Prefs
Gannett-Cam-Experience-Id
Server-Host
DSUID
Country-Code
Gh-Request-Id
RewriteTestHook
IsBot
X-LSADC-Cache
X-Mvc-Supplant-Cachable
CacheControlHeader
X-NMSegId
NM-Fastcgi-Cache
Cdn-Host
X-Gzip
X-Vercel-Cache
X-Gamma-Serve
X-Vmg-Version
Fastly-Backend-Name
X-Vercel-Id
X-Wikidot-Static-Cache
Cdn-Request-Time
Fastly-GeoIP-CountryCode
X-DPWN-IS-SECURE
Machine
X-Server-IP
X-CacheTTL
X-Esi-Check
Mail-Subject
Content-Style-Type
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
Click-Count-Error
Click-Count-Action-Start
X-Thanos
Content-Script-Type
X-Litespeed-Cache-Control
X-Edge-Server
X-Proto
X-Wikidot-Backend
Tube-Get-Contents
X-HN
Producers
We-Hiring
X-Dispatcher-Server
X-Org
X-B3-Trace-ID
X-Op-Id-All
Tube-Got-Eval
X-VarnishDD-TTL
X-Via-Fastly
X-SB
Tube-Return
Tube-Got-Results
Release
N-Cache
Pragrma
PFcat
X-Amz-Storage-Class
X-AB-Test
X-Cache-FS-Status
X-Cache-Date
X-Cache-Id
X-Bip
Platform
Origin-Site
C-Via
X-AWS-Id
X-Parent-Response-Time
X-LJ-Flow-ID
X-VWS-Id
X-ElasticPress-Query
Canary
Source
X-Proxied-Request
X-Origin-Response-Time
X-Location
X-Mvc-Supplant-OutputCached
Fastly-Drupal-HTML
X-ZONE
Sid
X-Pad
X-Litespeed-Tag
Debug
Powered-By
S-Rt
X-Cs
X-TH-Server
Product
X-Cached-By
X-NGINX-Cache
X-Refresh
Vix-Hermes-Req-Id
NGX
X-Amz-Meta-Cb-Modifiedtime
HA-Ipaddr
CloudFront-Viewer-Country
X-Upstream-Ct
X-Upstream-Ht
X-ND-Cache
X-Via-Popv
X-Via-Poph
Pics-Label
X-Via-Popn
X-Nananana
X-APP
X-Cache-VC
Mime-Version
X-HA-Backend
X-Servedbyhost
X-Ah-Environment
X-Varnish-Hits
GeoIP-Latitude
Cookie
X-Cdn-Forward
X-Datadome
X-User
Edge-Cache
Server-ID
X-Nginx-Cache
GeoIp-Country-Code
X-AIR-PT
X-DynaTrace-JS-Agent
X-LB-ID
X-Webkit-CSP
MIME-Version
X-Wa
X-GeoIP
X-Fpc
X-LB-NoCache
Akamai-Mon-Iucid-Del
X-Nc
Surrogated-Key
WZWS-RAY
X-FORWARDED-FOR
X-Request-Start
SID
HostName
X-B3-Parentspanid
X-Srv
X-Zone
Resin-Trace
X-Unity-Cache
X-Scheme
DataCenter
X-Nginx-Cache-Key
X-Debug-Service
X-Client-Ip
Fastly-Drupal-Html
Sever-Int
Server-Ext
True-Client-Country-4JS
Server-Hostname
X-CS
Tcn
X-NodeID
N1-Cache
X-Request-Host
Cdn
Load-Balancing
X-Pool
Show-Do-Not-Sell-Link
X-RequestId
X-VCL-Version
X-Lsadc-Cache
X-Cache-Backend
Sm-Log-Id
X-Cache-Grace
Lb
X-Service-Response-Time
Wsr-Cache
X-Vc
X-Newrelic-Synthetics
X-B3-Spanid
X-Vgn-Hpd-Reason
X-DynaTrace
NtCoent-Length
Yak-Timeinfo
X-DataCenter
Yjs-Id
Traceparent
Edge-Copy-Time
X-LiteSpeed-Cache-Control
X-Datacenter
X-Via-SSL
X-HOST
X-Via-Edge
X-Via-CDN
X-TX-ID
X-NODE
X-Air-Hostname
X-Air-Trace-Id
X-Air-Source
Datacenter
X-Zen-Fury
X-RateLimit-Limit
X-Geolocation
X-HubSpot-Correlation-Id
X-CDN-Provider
X-WA
CDN
Serverhost
Req-ID
Cdn-Requestid
X-Jobs
X-API-Version
Hostname
X-LiteSpeed-Tag
X-Dynatrace-Js-Agent
X-Proxy-CacheR9
X-Fastly-Backend-Reqs
X-NC
X-Cdn-Srv
X-Udemy-Cache-App-Namespace
Uri
X-ID
X-FPC
XkeyR9
Xkey-La3
Xkeylog
X-Proxy-Cache-La3
X-Powered-By-VTEX-Cache
X-Lb-Id
X-Akamai-Pragma-Client-IP
A
X-VTEX-Cache-Time
X-VTEX-Cache-Server
X-Html-Minification-Powered-By
GeoIP-Country-Code
WP-Super-Cache
True-Client-IP
Server-Id
CountryCode
On-Server
T-Server
X-Ez-Minify-Js
X-Srcache-Store-Status
X-Srcache-Fetch-Status
Proxy-Firewall
Geoip-Latitude
RATING
X-Stale
X-TimeS
X-Webkit-Csp-Report-Only
X-Swift-Error
X-ServedByHost
Srv
Coldstone-Viewer-Country-Region-Name
Coldstone-Viewer-Currency
X-Varnish-Beresp-TTL
Coldstone-Viewer-Country
ServerHost
From-Cache
X-Lb-Nocache
Esi-Enabled
X-WA-Info
X-Via-JSL
WebServer
Cs
X-Oracle-DMS-ECID
X-CSRF-TOKEN
Cloudfront-Viewer-Country
X-App
X-VC-Age
X-Ha-Backend
X-Ez-Minify-Html
X-Wp-Cf-Super-Cache
X-Wp-Cf-Super-Cache-Cache-Control
X-LAGOON
X-Via-PopH
X-Ssense-Gql
X-Correlation-ID
X-HA-Device-Type
X-HA-Bot-Classification
X-Via-PopV
X-Styx-Origin-Id
X-Styx-Info
Cr
BehaviorPad-Version
X-HA-Application-Name
X-Via-PopN
Pramga
X-Ssense-Shipping-Surcharge-Enabled
Ngx
X-MSEdge-Features
FSS-Cache
X-MSEdge-Flight
X-Fastly-Cache
X-Var-Ttl
X-Sorting-Hat-Shopid
X-Sorting-Hat-Podid
X-Geo
X-Shopid
X-Cdn-Cache-Status
X-Web-Server
X-TIM-N
X-Check-Cacheable
X-Shardid
Content-Secure-Policy
X-Request-Url
W
X-Proxy-Cache-LA2
X-Th-Server
X-Elasticpress-Query
X-ATG-Version
X-Sucuri-Id
X-Wp-Cf-Super-Cache-Active
X-DC
X-Nitro-Cache
X-Wp-Cf-Super-Cache-Cookies-Bypass
Akamai-X-True-TTL
X-Request-Time
My-App
X-Serial
Cf-Ipcountry
X-Ramcache
Xkey-G-Jp
Cl-Cache
User-Agent
Host-Name
X-Cache-TTL-Remaining
X-Fastly-Cache-Hits
FSS-Proxy
Cneonction
Bxuuid
Bxpunish
X-Env
True-Client-Ip
X-Mg-Cache
X-Fastly-Cache-Status