Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
X-Frame-Options
Expires
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Accept-CH
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
X-XSS-Protection
Pragma
X-Powered-By
CF-RAY
X-Cache
Via
Age
Content-Security-Policy
Alt-Svc
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-Xss-Protection
X-Download-Options
CF-Ray
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
X-DNS-Prefetch-Control
Accept-CH-Lifetime
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
Accept-Ch
Permissions-Policy
Server-Timing
X-Drupal-Cache
X-Generator
X-Envoy-Upstream-Service-Time
X-Cache-Status
X-Cacheable
X-FRAME-OPTIONS
X-Iinfo
X-Drupal-Dynamic-Cache
Timing-Allow-Origin
X-Ua-Compatible
Feature-Policy
X-CONTENT-TYPE-OPTIONS
X-Content-Security-Policy
Xkey
Upgrade
Access-Control-Expose-Headers
X-CDN
Content-Encoding
X-XSS-PROTECTION
Status
X-AspNetMvc-Version
Access-Control-Max-Age
Host-Header
X-Amz-Request-Id
X-Age
X-Amz-Id-2
Request-Context
Cf-Edge-Cache
X-Backend
X-Robots-Tag
Keep-Alive
X-Hacker
X-Via
Cf-Apo-Via
X-Request-ID
X-Turbo-Charged-By
X-Amz-Version-Id
X-Rq
X-AH-Environment
X-Cache-Group
X-Vhost
X-Server
X-Dispatcher
X-Proxy-Cache
X-Ws-Request-Id
EagleId
CONTENT-SECURITY-POLICY
X-UA-Device
X-Varnish-Cache
Pantheon-Trace-Id
X-Litespeed-Cache
Grace
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Server-Powered-By
X-OneAgent-JS-Injection
X-Pingback
Allow
X-Page-Speed
X-WebKit-CSP
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-Dns-Prefetch-Control
X-FTR-Request-ID
X-Cache-Lookup
X-Device
X-Node
X-Server-Id
EagleEye-TraceId
X-Host
X-Country-Code
X-Backend-Server
Surrogate-Control
X-Cloud-Trace-Context
X-Readtime
X-Akam-SW-Version
Cf-Railgun
X-HW
X-Ruxit-JS-Agent
X-Response-Time
X-Ua-Device
Accept-Ch-Lifetime
Cache-Tag
P3p
X-Amz-Server-Side-Encryption
Cf-Request-Id
X-LiteSpeed-Cache
Content-Location
Cross-Origin-Opener-Policy
X-Nginx-Upstream-Cache-Status
X-Rack-Cache
X-Nginx-Cache-Status
X-Trace
Service-Worker-Allowed
Request-Id
X-TraceId
Fastly-Restarts
X-Application-Context
X-Content-Type
X-Nf-Request-Id
X-Times
Rating
X-Vname
X-TtlSet
X-PC
X-Clacks-Overhead
X-Cnection
X-Oneagent-Js-Injection
X-FTR-Balancer
X-FTR-Backend-Server
X-Edge
X-Mcache
X-Midtier
X-Country-Code-Real
X-FTR-Cache-Status
X-FTR-Backend
X-FTR-Expires
Edge-Control
X-ESI
X-Browser-Type
X-Vcap-Request-Id
Origin-Trial
X-Cache-TTL
X-FastCGI-Cache
X-NWS-LOG-UUID
Surrogate-Key
X-Powered-By-Plesk
X-Element-Page-Cache
X-D2id
X-Kinja-Build
X-Cdn-Fetch
X-Kinja-Revision
X-Kinja-Server
X-GoogleNews-Bot
X-Exp-Variant
X-Exp-Id
X-Kinja
X-Abt-Application-Version
X-Country
X-Upstream
Verso
X-Ac
X-Mod-Pagespeed
X-Url
X-B3-TraceId
X-ORACLE-DMS-RID
X-Navigation-Version
Akamai-GRN
X-Amz-Rid
X-Language
Nginx-Cache
X-ECACHE
Pinterest-Generated-By
X-Pinterest-Rid
Pinterest-Version
X-GitHub-Request-Id
X-Middleton-Display
Display
X-Sol
Pagespeed
X-Envoy-Decorator-Operation
S
X-Instrumentation
X-PDP-UNCACHING-HASH
X-Server-Lifecycle-Phase
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Kraken-Loop-Name
X-Middleton-Response
Response
AR-PoweredBy
AR-Request-ID
AR-ATIME
Edge-Cache-Tag
X-MS-InvokeApp
X-Ratelimit-Limit
X-Ruxit-Js-Agent
X-Goog-Hash
X-Distributor
X-Ttl
X-Edge-Location-Klb
X-Kinsta-Cache
X-Ser
X-Resp-Is-Stale
X-ARC
X-SharePointHealthScore
SPRequestDuration
SPRequestGuid
SPIisLatency
X-NGENIX-Cache
Access-Control-Request-Method
Front-End-Https
X-Shield-Request-Id
X-Amzn-Trace-Id
X-Content-Digest
X-Dw-Request-Base-Id
X-Ezoic-Cdn
X-Varnish-TTL
X-Client-IP
X-Recruiting
RTSS
X-Cache-Key
Cache-Status
X-Version
X-Mg-S
X-Powered-CMS
X-T
TP-Cache
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Cache-Config
Public-Key-Pins
X-MSEdge-Ref
Fastcgi-Cache
X-Accel-Expires
AR-CACHE
Arr-Disable-Session-Affinity
X-Ismobilevalue
X-Daa-Tunnel
X-Cluster-Name
X-Cached
Cache-Tags
Realpath
X-Id
X-Correlation-Id
X-Content-Security-Policy-Report-Only
Content-MD5
Ar-SID
X-COUNTRY
X-HS-Combine-CSS
YJS-ID
X-Fastly-Request-ID
X-Request-Processing-Time
X-Request-Received
X-Request-Device-Id
X-Newrelic-App-Data
Payment
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-DIS-Request-ID
X-Ua-Browser
X-Forwarded-For
X-GUploader-UploadID
X-HS-CF-Cache-Status
X-Azure-Ref
X-HS-Prerendered
X-Ratelimit-Remaining
X-Cambria-Cache-Control
X-HP-Webp
X-Jurisdiction
X-HP-Trace-Id
X-Amz-Replication-Status
Content-Disposition
X-Xrds-Location
X-Webkit-Csp
X-RateLimit-Remaining
X-Meli-Trace-Bu
X-Meli-Trace-Site
X-Meli-Trace-Platform
Count-Hit
X-SERVER-NAME
X-Server-Name
X-Origin-Server
X-Px
X-Unique-Id
Cross-Origin-Resource-Policy
Cleartype
X-Page-Id
X-Protected-By
X-Ratelimit-Reset
X-Amz-Meta-S3cmd-Attrs
X-Az
X-Proxy
X-Rid
Accept-Charset
X-VARITI-CCR
X-Logged-In
X-FB-Debug
X-SRCache-Store-Status
X-Activity-Id
X-AppVersion
X-SRCache-Fetch-Status
Cross-Origin-Embedder-Policy
MicrosoftSharePointTeamServices
X-Git-Hash
X-Load-Cache
X-Www-Served-By
X-Amzn-RequestId
X-Amz-Apigw-Id
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-TEC-API-ROOT
X-Request-Handler-Origin-Region
X-Microsite
X-Goog-Metageneration
X-LLID
X-ORACLE-DMS-ECID
Version
X-TTL
X-Template
X-Geo-Country
X-Varnish-Backend
X-Forwarded-Proto
X-Upgrade-Enabled
Server-Node
X-CST
X-PressLabs-Stats
X-Hits
Server-Name
X-B3-Sampled
X-WebKit-CSP-Report-Only
X-Hostname
X-Content-Options
X-App-Server
Section-Io-Cache
Viewport
X-Varnish-Grace
X-Grace
Access-Control-Allow-Method
X-TT
X-Device-Type
X-Fb-Rlafr
Fastly-SIE
Fastly-SWR
Healthy
X-Varnish-Server
X-B
Alternate-Protocol
X-Frontend
X-Request-Guid
X-B3-TraceId-Primal
MRF-Tech
X-Status
Mrf-Cache-Status
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
TCN
X-Goog-Generation
DC
Upgrade-Insecure-Requests
X-Contextid
X-Amzn-Remapped-Content-Length
X-Magnolia-Registration
X-Requestid
X-EdgeConnect-Cache-Status
Host
MS-Author-Via
Retry-After
X-Cache-Control
AKAMAI-GRN
Amp-Access-Control-Allow-Source-Origin
X-App-Version
X-CSRF-Token
Frame-Options
X-Oracle-Dms-Ecid
X-Debug
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Type
X-Revision
X-Buckets
X-Cache-Age
X-Varnish-Ttl
X-Origin-CC
X-Origin-TTL
X-INCAP-ABP
X-Response-Served-From
X-UUID
X-Seen-By
X-Original-Request-Id
SD-X-WS
X-Backend-Name
X-Instance
X-ProcessESI
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-NYM-Debug-Backend
X-N
X-Rendered-As
X-RemovedCookies
X-Hl-Ver
X-Is-Bot
X-Tumblr-Pixel-1
X-Cache-Status-Check
X-Adobe-Content
X-Adobe-Loc
X-Akamai-Edgescape
Cross-Origin-Embedder-Policy-Report-Only
Cross-Origin-Opener-Policy-Report-Only
X-Tumblr-User
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-WP-CF-Super-Cache-Cache-Control
X-Mg-Request-UUID
X-Akamai-Request-ID2
Section-Io-Id
X-Content-Powered-By
Ms-Operation-Id
X-Framework
X-Debug-IsConnected
X-G
Access-Control-Request-Headers
MS-CV
X-WP-CF-Super-Cache
X-Debug-IsPreview
X-Mobile
X-ServerID
X-RTag
X-Lambda-Id
X-Trace-Id
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-RM-Cache-TTL
X-Server-W
X-Storage
X-AB
NGB
Cache
X-Vcl-Version
X-Dc
Charset
Webserver
Filterid
X-DataDome
X-Yandex-Req-Id
X-HITS
X-B3-SpanId
Paypal-Debug-Id
Accept-Language
X-VC-Cache
X-Cache-Time
Refresh
X-Ms-Version
Onion-Location
X-Ms-Request-Id
SRV
X-Request-Site
X-Cache-Hit
X-Request-Platform
X-Request-Bu
X-Time
X-URL
X-Node-Name
X-F-Cache
X-Region
YJS-CacheStatus
X-Tec-Api-Origin
X-ECache
X-Real-IP
X-Tec-Api-Version
X-Tec-Api-Root
X-User-Agent
X-CCDN-CacheTTL
X-Hcs-Proxy-Type
X-CCDN-Origin-Time
CDN-RequestId
X-LB-Cache
GEO-INFO
X-HTML-Minification-Powered-By
Liferay-Portal
X-Mode
X-Environment-Context
X-L-Path
Priority
X-IPS-LoggedIn
X-Pass-Why
Xet-Cookie
X-Service
X-Datadog-Sampled
X-Datadog-Parent-Id
Country
X-Datadog-Sampling-Priority
X-Datadog-Trace-Id
Cross-Origin-Window-Policy
X-Rocket-Nginx-Serving-Static
X-Fastcgi-Cache
X-Adobe-Source
Backend
X-Drupal-Cache-Tags
X-Tb
X-XRDS-Location
X-Handled-By
X-Rule
Protected
X-Origin-Cache
X-Whom
X-Is-Modern-Browser
Property-Id
Meta-Geo
X-FB-TRIP-ID
ServerID
Selected-Fe
X-Extlb
X-Detected-As
X-WP-CF-Super-Cache-Active
X-Cloudmap
TWC-GeoIP-Country
Webcakes-App-Name
Web-Mar-Node
X-Is-Mobile
Url
X-Cache-Expired-At
Webcakes-App-Version
X-Browser-Name
X-Is-Mobile-Only
Webcakes-Region
X-Is-Desktop
X-Httpd
TWC-GeoIP-DMA
TWC-GeoIP-City
TWC-Device-Class
TWC-GeoIP-LatLong
TWC-GeoIP-Region
X-Geo-Region
TWC-Privacy
TWC-Locale-Group
TWC-Connection-Speed
X-Proxied
X-Zipkin-Id
X-Rn-Rsrv
X-Rewrite-Enabled
X-UPSTREAM-Address
X-Tncms
X-Proxy-Cache-Info
X-Routing-Service
X-Varnish-Beresp-Grace
X-Is-Supported-Browser
X-Wix-Request-Id
X-Tcp-Rtt
X-Servername
X-Vcache
X-SaId
X-Proxy-Build
X-RCS-CacheZone
X-Origin-Date
LB
X-JoinUs
X-Is-Tablet
X-Origin-Hint
X-Loop
X-Timing-Wait
DB-Nickname
X-App-Environment
X-Cdn-Origin
X-Fetched-On
X-Format
X-BYPASS-REASON
X-Hit
X-Web-Node
Atl-Traceid
X-Cluster
Mn-Server-Ip
X-Director
X-Cache-Action
OT-Force-Account-Verify
X-Generation-Time
X-Locale
X-Redis-Cache
X-Cms-Context
X-Skip-Cache
X-Alternate-Cache-Key
X-Soup
X-Tumblr-Pixel-3
X-Hosted-By
X-ProxyCache-Key
X-Tumblr-Pixel-2
X-Logging-Id
X-Forwarded-Host
X-Provided-By
X-Shopify-Stage
X-Origin
X-Storefront-Renderer-Rendered
X-ProxyCache-Status
Locale
X-Urbn-Context-Path
X-Urbn-Site-Id
ServedBy
X-Served-From
X-Edge-Location
X-Say-Cacheable
X-Say-TTL
X-SayCDN-TTL
X-Scope-Id
X-RateLimit-Limit-Second
X-FW-Dynamic
X-RateLimit-Remaining-Second
X-FW-Serve
X-FW-Hash
X-FW-Server
X-FW-Static
X-VCT
X-MP-GENERATED-AT
Environment
X-FW-Type
Cache-Hits
X-FW-Version
X-Labrador-Cache-Channel
X-Cache-Host
X-PHP-Host
Uber-Trace-Id
X-S
X-Connection-Hash
X-Cluster-Node
Expiry
X-Restarts
X-Auth-Group-Type
Fastcgi-Useragent
X-Cacheable-TTL
X-Cache-Debug
X-Drupal-Cache-Contexts
X-VC
Apigw-Requestid
X-Platform
X-Endurance-Cache-Level
X-Debug-Info
Filters
X-IPLB-Instance
X-IPLB-Request-ID
X-Api-Version
X-Server-ID
X-GEO
X-CDN-Forward
X-CDN-Cache-Status
X-NewRelic-App-Data
X-Mly-Id
X-UA
X-Presslabs-Stats
Node
X-Tt-Logid
X-R9-Blue-Green-Version
Front
X-No-Session
Xserver
AR-SID
WPO-Cache-Status
X-Client-Ip
X-CLOUD-TRACE-CONTEXT
X-Varnish-Beresp-Ttl
X-Optimistic-Header
X-Lagoon
X-WP-CF-Super-Cache-Cookies-Bypass
Cache-Tv-Group
X-CACHE-AGE
X-ShardId
X-Sorting-Hat-PodId
X-ShopId
X-Varnish-Age
X-Sorting-Hat-ShopId
X-Varnish-Cache-Hits
X-SRV
X-Generated-By
X-B-Cache
X-Wormhole-Sdk
X-NWS-UUID-VERIFY
X-Signature
Countrycode
X-Fastly-Request-Id
X-B3-Traceid
Referer-Policy
X-Webstats-RespID
X-Site-Version
From-Origin
X-Azure-Ref-OriginShield
Cache-Provider
X-Worker
X-IsAdmin
X-Ua
Request-ID
X-Accel-Version
X-VWS-Id
X-Cache-Operation
X-Cache-Rule
X-PHP-Backend
X-FORWARDED-FOR
X-AWS-Id
X-LJ-Flow-ID
Location
X-Upstream-Ht
X-Auto-Login
X-VC-TTL
X-Tx-Id
X-Upstream-Ct
X-NF-Request-ID
X-TA-CDN-Provider
AMP-Access-Control-Allow-Source-Origin
Source
WPO-Cache-Message
X-Tb-Optimization-Total-Bytes-Saved
S-Rt
X-Air-Pt
Origin-Agent-Cluster
L5d-Success-Class
Lang
IsBot
Log-Origin
X-BCube-Filmed-By
Meta-Geo-Continent
X-Bl-Debug
Cluster
MD5-Digest
X-AK-Request-ID
X-ApacheServer
Gh-Request-Id
Fl-Custom-Application
Fastly-SSL
Expect-Staple
X-B-Cookie
DCR-Processing-Time-Ms
X-Bc-Bl
Ha-Gx-Prefs
X-Application
DCR-Decision-By
Host-ID
X-Access
Wxu-Next-Region
Wxu-Next-Hostname
X-A
X-A-Ccd
CDN-Uid
X-A-Dam
Cdnsip
Sslversion
Store-Cloud-Cache
Cdncip
Web-Mar-Region
X-Bug-Bounty
Wxu-Next-Commit
X-A-Dcw
X-A-Dgt
Origin
Powered-By
Time-Cloud-Cache
Ngx.Var.Host
X-Aed
Pragrma
Redirect-Candidate
RNT-Time
ServerName
X-A-Wwc
RNT-Machine
Rendered-Blocks
N-Cache
X-Csrf-Jwt
X-PERF
X-PAYTM-SRV-ID
X-Origin-Expires
X-Policy
X-Req
X-VG-TLSProxy
X-Rocket-Build-Number
X-Org
X-Old-Content-Length
X-Ig-Push-State
X-Ig-Origin-Region
X-VG-WebCache
X-Loc
X-Micro-Cache
X-Node-Id
X-Mvc-Supplant-Cachable
X-Vdms-Version
X-Vary-Devices
X-SRCache-Key
X-Slack-Shared-Secret-Outcome
X-Slack-Backend
X-V-Cache
X-Varnish-Authentication
X-Varnish-Director
X-Varnish-Beresp-Status
X-SIPLIST1
X-Sigma-Backend
X-Save-Cache
X-S-Cookie
X-Rojux
X-ScT
X-SD-PageType
X-Sigma
X-Section
X-HS-Content-Campaign-Id
X-Hash
X-CUA
X-Varnish-Hostname
X-Core-Value
CDN-RequestPullSuccess
X-D
X-Destination
X-Depends
X-Content-Age
X-Contensis-Viewer-Groups
X-Clientip
X-CGP
X-Cache-NE
Xc-Version
X-Cms-Device
X-Conf
X-Vtex-Remote-Cache
X-Developer
X-Ec-Fail
X-Gamma-Serve
X-From
X-Forwarded-Site
X-GeoCode
X-GeoCountry
X-GoCache-CacheStatus
X-GeoIP-City
X-Fmm-Version
X-FC-Vary-Parameters
X-Ee-Origin
X-Ee-Generated-By
X-Ec-GeoHdr
X-Ee-Request-Date
X-Ee-Request-Id
X-External-Request-Id
X-Eu-Site
X-Cache-Aspx
X-Action
Candidate-Md5Url
CDN-Cache
CDN-CachedAt
CF-IPCountry
X-NGINX-Cache
Apple-News-Services-Request-Url
X-Sucuri-Cache
Apple-News-Services-Handled
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
CDN-EdgeStorageId
CDN-RequestPullCode
CDN-RequestCountryCode
CDN-PullZone
X-Reqid
X-Xfnlog-Site
X-Litespeed-Cache-Control
X-DefHash
X-Gdpr
X-Epic-Correlation-Id
X-VarnishDD-TTL
X-Server-IP
X-Dispatcher-Server
X-Ec-Custom-Error
X-Generated-On
X-GeoIP-Region-Code
X-HN
X-GeoIP-Country-Code
X-Fastly-Backend
X-DefElseHash
X-ND-Cache
X-Gen-Mode
X-Debug-Cache-Fetch
X-Akamai-Device-Characteristics
X-Amz-Storage-Class
X-App-Name
X-Aicache-OS
X-Acquia-Purge-Cdn-Unconfigured
X-AB-Test
X-Accel-Expires-Debug
X-Cs
X-Backend-Instance
X-Content-Length
X-Date
X-Hnp-Log
X-Cache-Date
X-Block-Status
X-BBC-Edge-Cache-Status
X-Bip
X-Debug-Cache-Store
X-Human
X-Thanos
X-Thinkindot-L1
X-Thinkindot-L3
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-Shield-Cache-Expires
X-Sn-Servicetimems
Country-Code
X-Wikidot-Static-Cache
X-UA-Device-Type
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-Vmg-Version
X-We-Are-Hiring
X-Uri
X-Up
X-Wikidot-Backend
X-SB
X-Render-Time
X-Ion-Hop
X-Jungle-Id
We-Hiring
X-Ion-Healthy
X-Internal-TTL
X-Via-Fastly
X-CacheTTL
X-Men
X-Mvc-Supplant-OutputCached
X-Path
X-Proto
X-Region-Sid
X-Origin-Time
X-Op-Id-All
X-NMSegId
X-Nyt-Route
X-Varnish-Remaining-TTL
X-Level-Front-Cache
Machine
Azure-Version
Mail-Subject
Server-Host
RewriteTestHook
Azure-SlotName
Cache-Contol
Vix-Hermes-Req-Id
TDXMobile
Thinkindot-CacheControl
Gannett-Cam-Experience-Id
CDCHOST
Canary
Azure-SiteName
RewriteTeamHook
Origin-Site
Origin-EX
PFcat
Release
Pics-Label
Origin-CC
Odigeo-Trace-Id
Azure-RegionName
Req-Svc-Chain
Azure-InstanceId
NM-Fastcgi-Cache
Nord-Request-ID
Thinkindot-CacheControl-Type
L
Content-Style-Type
Cmsid
DSUID
Cmstype
Content-Script-Type
User-Cache-Control
V-Age
X-LSADC-Cache
X-Parent-Response-Time
Fastly-GeoIP-CountryCode
Tube-Got-Results
X-Frame-Option
Cdn-Host
Tube-Return
X-Vercel-Cache
X-Edge-Server
X-Esi-Check
Click-Count-Action-Start
X-Viewer-Country
Cdn-Request-Time
X-Gzip
X-Vercel-Id
Tube-Got-Eval
X-Location
X-DPWN-IS-SECURE
Click-Count-Error
X-Cache-FS-Status
C-Via
X-Request-URI
Producers
Platform
X-B3-Trace-ID
Fastly-Backend-Name
CacheControlHeader
X-Cache-Id
X-Proxied-Request
Tube-Get-Contents
X-Pubstack
Sid
Fastly-Drupal-HTML
X-Moov-Xdn-Version
X-ElasticPress-Query
Mime-Version
CloudFront-Viewer-Country
X-Origin-Response-Time
X-Moov-Xdn-Caching-Status
X-Moov-T
X-Sucuri-ID
X-Source
XM
NGX
X-Cached-By
X-Pad
X-ZONE
Debug
X-Refresh
X-Varnish-Hits
X-APP
Load-Balancing
X-Via-Poph
GeoIP-Latitude
GeoIp-Country-Code
X-Servedbyhost
X-Nginx-Cache-Key
X-Debug-Service
X-Via-Popn
X-Via-Popv
Cookie
True-Client-Country-4JS
Server-Ext
X-Ez-Minify-Html
Server-ID
Sever-Int
X-HA-Backend
Server-Hostname
X-Datadome
X-AC
Cdn
HA-Ipaddr
X-AIR-PT
X-Nananana
X-Srv
Traceparent
X-TH-Server
Show-Do-Not-Sell-Link
X-DynaTrace-JS-Agent
Product
X-Zone
X-Webkit-CSP
X-TT-LOGID
X-Litespeed-Tag
X-Nc
X-Wa
X-GeoIP
X-Fpc
X-Cache-Backend
X-Amz-Meta-Cb-Modifiedtime
X-Newrelic-Synthetics
X-B3-Parentspanid
WZWS-RAY
X-Cache-VC
X-Cdn-Forward
Edge-Cache
X-Unity-Cache
X-User
DataCenter
X-LB-ID
HostName
SID
Fastly-Drupal-Html
X-Vc
MIME-Version
X-CDN-Provider
Tcn
X-Lsadc-Cache
X-VCL-Version
X-Proxy-Cache-La3
X-Proxy-CacheR9
CountryCode
Resin-Trace
Akamai-Mon-Iucid-Del
X-LB-NoCache
X-Request-Start
Serverhost
Xkeylog
Xkey-La3
XkeyR9
Lb
X-Nginx-Cache
X-B3-Spanid
X-Service-Response-Time
A
Wsr-Cache
Sm-Log-Id
X-LiteSpeed-Tag
Cs
X-Scheme
X-Datacenter
X-LiteSpeed-Cache-Control
Hostname
X-HOST
X-Lb-Id
Yjs-Id
X-TX-ID
Surrogated-Key
X-CS
X-Pool
Datacenter
X-RateLimit-Limit
Esi-Enabled
X-Dynatrace-Js-Agent
NtCoent-Length
X-Request-Host
Cdn-Requestid
X-HubSpot-Correlation-Id
X-Akamai-Pragma-Client-IP
CDN
Uri
X-NodeID
X-Air-Trace-Id
X-VC-Age
X-Air-Source
X-WA
X-Air-Hostname
X-RequestId
X-API-Version
X-Styx-Origin-Id
X-Styx-Info
X-Cache-Grace
X-Fastly-Backend-Reqs
Cr
X-FPC
X-Udemy-Cache-App-Namespace
X-HA-Device-Type
Pramga
X-HA-Bot-Classification
X-HA-Application-Name
Proxy-Firewall
X-ID
X-NC
X-Vgn-Hpd-Reason
Yak-Timeinfo
Content-Secure-Policy
X-Via-JSL
X-Stale
X-TIM-N
Server-Id
X-Var-Ttl
X-Html-Minification-Powered-By
X-DataCenter
X-DynaTrace
N1-Cache
X-CSRF-TOKEN
Geoip-Latitude
Edge-Copy-Time
X-Via-CDN
X-Ez-Minify-Js
ServerHost
RATING
W
X-TimeS
GeoIP-Country-Code
T-Server
X-Srcache-Store-Status
X-Srcache-Fetch-Status
X-Via-SSL
X-Via-Edge
X-Shopid
X-Lb-Nocache
Srv
X-Sorting-Hat-Shopid
X-Jobs
X-Geolocation
X-ServedByHost
X-Sorting-Hat-Podid
X-Ha-Backend
From-Cache
X-Varnish-Beresp-TTL
X-Shardid
X-Swift-Error
X-Zen-Fury
Req-ID
X-Oracle-DMS-ECID
True-Client-IP
X-App
X-CACHE-KEY
X-Via-PopN
X-MSEdge-Flight
X-MSEdge-Features
X-Via-PopH
X-Via-PopV
Cloudfront-Viewer-Country
WP-Super-Cache
X-Wp-Cf-Super-Cache-Cache-Control
X-LAGOON
X-Wp-Cf-Super-Cache
X-Correlation-ID
X-Cdn-Srv
X-ByteArk-ReqID
X-Key
X-VServer
On-Server
X-Proxy-Cache-LA2
Ohc-File-Size
X-ByteArk-Cache
X-Ramcache
FSS-Cache
X-Ssense-Shipping-Surcharge-Enabled
Ohc-Cache-HIT
X-Ssense-Gql
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-Wp-Cf-Super-Cache-Active
X-PageType
Ngx
X-Elasticpress-Query
CF-Cached-On
Cl-Cache
X-Cdn-Cache-Status
X-Geo
X-VTEX-Cache-Server
X-Powered-By-VTEX-Cache
X-VTEX-Cache-Time
X-Web-Server
X-Sucuri-Id
X-Check-Cacheable
X-Iplb-Request-Id
X-Webkit-Csp-Report-Only
X-Iplb-Instance
X-Th-Server
X-Serial
X-DC
WebServer
My-App
X-Fastly-Cache
X-MiniProfiler-Ids
X-ATG-Version
X-Beacon
X-Limited
Akamai-X-True-TTL
Cf-Ipcountry
Cneonction
Coldstone-Viewer-Currency
Coldstone-Viewer-Country-Region-Name
Warning
Coldstone-Viewer-Country
X-Request-Url
X-Env
FSS-Proxy
Host-Name
X-Mg-Cache
Xkey-G-Jp
X-Fastly-Cache-Status
User-Agent
X-WA-Info