Threat Level: green Handler on Duty: Yee Ching Tok

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
X-Frame-Options
Expires
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Accept-CH
CF-Cache-Status
X-XSS-Protection
ETag
Expect-CT
Accept-Ranges
CF-RAY
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Alt-Svc
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Xss-Protection
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Cf-Request-Id
Access-Control-Allow-Credentials
CF-Ray
X-DNS-Prefetch-Control
Accept-CH-Lifetime
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
Accept-Ch
Permissions-Policy
Server-Timing
X-Drupal-Cache
X-Generator
X-Envoy-Upstream-Service-Time
X-Cache-Status
X-Ua-Compatible
X-Cacheable
X-Iinfo
X-FRAME-OPTIONS
X-Drupal-Dynamic-Cache
Timing-Allow-Origin
Feature-Policy
X-Content-Security-Policy
X-CONTENT-TYPE-OPTIONS
Xkey
Upgrade
Access-Control-Expose-Headers
X-CDN
Content-Encoding
Status
X-XSS-PROTECTION
X-AspNetMvc-Version
Access-Control-Max-Age
Host-Header
X-Amz-Request-Id
X-Age
X-Amz-Id-2
Request-Context
Cf-Edge-Cache
X-Backend
X-Robots-Tag
X-Hacker
X-Via
Cf-Apo-Via
Keep-Alive
X-Request-ID
X-Turbo-Charged-By
X-Amz-Version-Id
X-AH-Environment
X-Rq
X-Cache-Group
X-Vhost
X-Dispatcher
X-Server
X-Proxy-Cache
X-Ws-Request-Id
EagleId
X-UA-Device
CONTENT-SECURITY-POLICY
X-Varnish-Cache
Pantheon-Trace-Id
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
Grace
X-OneAgent-JS-Injection
X-Server-Powered-By
X-Pingback
Allow
X-Page-Speed
X-WebKit-CSP
X-Litespeed-Cache
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-Dns-Prefetch-Control
X-Node
X-FTR-Request-ID
X-Device
EagleEye-TraceId
X-Server-Id
X-Cache-Lookup
X-Host
X-Country-Code
X-Backend-Server
Surrogate-Control
X-LiteSpeed-Cache
X-Cloud-Trace-Context
X-Readtime
X-Akam-SW-Version
Cf-Railgun
X-HW
X-Ruxit-JS-Agent
X-Response-Time
Accept-Ch-Lifetime
Cache-Tag
X-Amz-Server-Side-Encryption
P3p
Content-Location
Cross-Origin-Opener-Policy
X-Rack-Cache
X-Nginx-Upstream-Cache-Status
X-Trace
Service-Worker-Allowed
X-Nginx-Cache-Status
X-Ua-Device
Request-Id
Fastly-Restarts
X-TraceId
X-Application-Context
X-Content-Type
X-Clacks-Overhead
Rating
X-Times
X-PC
X-Vname
X-TtlSet
X-Cnection
X-Browser-Type
X-Midtier
X-Edge
X-Country
X-Mcache
X-FTR-Balancer
X-FTR-Cache-Status
X-Country-Code-Real
X-FTR-Backend
X-FTR-Backend-Server
X-ESI
X-Cache-TTL
X-Vcap-Request-Id
X-FTR-Expires
Origin-Trial
Edge-Control
X-FastCGI-Cache
X-Nf-Request-Id
Surrogate-Key
X-Powered-By-Plesk
X-Ac
X-Element-Page-Cache
X-Abt-Application-Version
X-Exp-Variant
X-Exp-Id
X-GoogleNews-Bot
X-Kinja-Revision
X-Kinja-Server
X-D2id
X-Kinja-Build
X-Kinja
X-Cdn-Fetch
X-NWS-LOG-UUID
X-Upstream
Verso
X-B3-TraceId
X-Oneagent-Js-Injection
X-ECACHE
X-Navigation-Version
X-Mod-Pagespeed
X-ORACLE-DMS-RID
Nginx-Cache
X-Amz-Rid
X-Pinterest-Rid
Pinterest-Generated-By
Pinterest-Version
Display
Pagespeed
X-Sol
X-Middleton-Display
X-GitHub-Request-Id
Akamai-GRN
X-Language
X-Envoy-Decorator-Operation
X-Middleton-Response
Response
X-Erf-Bev-Bev
X-Kraken-Loop-Name
X-PDP-UNCACHING-HASH
X-Erf-Bev-Bev-Is-Generated
X-Server-Lifecycle-Phase
X-Instrumentation
S
AR-PoweredBy
AR-ATIME
X-Ratelimit-Limit
AR-Request-ID
Edge-Cache-Tag
X-MS-InvokeApp
X-Goog-Hash
X-Kinsta-Cache
X-Edge-Location-Klb
X-Client-IP
X-Resp-Is-Stale
X-Distributor
X-Url
X-ARC
X-Ruxit-Js-Agent
X-Ser
X-NGENIX-Cache
X-SharePointHealthScore
SPRequestGuid
SPRequestDuration
SPIisLatency
Access-Control-Request-Method
X-Content-Digest
Front-End-Https
X-Ezoic-Cdn
X-Shield-Request-Id
X-Dw-Request-Base-Id
X-Varnish-TTL
X-Recruiting
X-Cache-Key
RTSS
X-Ttl
X-Amzn-Trace-Id
Cache-Status
X-Version
X-Powered-CMS
X-Mg-S
Public-Key-Pins
X-T
X-MSEdge-Ref
TP-Cache
Fastcgi-Cache
X-Accel-Expires
X-HS-Content-Id
Arr-Disable-Session-Affinity
X-HS-Cache-Config
X-HS-Hub-Id
X-Daa-Tunnel
Realpath
X-Cluster-Name
AR-CACHE
X-Fastly-Request-ID
X-Correlation-Id
X-Cached
Cache-Tags
X-Id
X-Ismobilevalue
X-Forwarded-For
X-Newrelic-App-Data
X-Request-Received
X-Request-Processing-Time
X-Content-Security-Policy-Report-Only
X-HS-Combine-CSS
X-Ua-Browser
Content-MD5
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Ratelimit-Remaining
Payment
X-DIS-Request-ID
X-GUploader-UploadID
X-Azure-Ref
X-HS-CF-Cache-Status
X-HS-Prerendered
Content-Disposition
X-HP-Webp
X-Jurisdiction
X-Amz-Replication-Status
X-HP-Trace-Id
X-Cambria-Cache-Control
YJS-ID
X-TTL
X-Server-Name
Count-Hit
Ar-SID
X-CST
X-RateLimit-Remaining
X-SERVER-NAME
X-Webkit-Csp
X-Px
X-Unique-Id
Cross-Origin-Embedder-Policy
Cleartype
X-Ratelimit-Reset
X-Origin-Server
X-Page-Id
X-SRCache-Store-Status
X-SRCache-Fetch-Status
Accept-Charset
X-Xrds-Location
X-AppVersion
X-Protected-By
Cross-Origin-Resource-Policy
X-Request-Device-Id
X-Az
X-Activity-Id
X-Proxy
X-Rid
X-Logged-In
X-FB-Debug
X-Request-Handler-Origin-Region
X-Git-Hash
X-Www-Served-By
X-Microsite
X-VARITI-CCR
X-LLID
X-COUNTRY
X-Template
X-Amz-Meta-S3cmd-Attrs
X-Goog-Metageneration
X-Load-Cache
MicrosoftSharePointTeamServices
X-ORACLE-DMS-ECID
X-Varnish-Backend
X-TEC-API-VERSION
Version
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Forwarded-Proto
X-Geo-Country
Server-Node
Server-Name
X-Upgrade-Enabled
X-URL
X-Meli-Trace-Site
X-Meli-Trace-Platform
X-Meli-Trace-Bu
X-PressLabs-Stats
X-Hostname
X-B3-Sampled
X-Hits
X-Content-Options
Section-Io-Cache
X-Frontend
Viewport
X-TT
MRF-Tech
X-B3-TraceId-Primal
Mrf-Cache-Status
X-Varnish-Grace
X-App-Server
X-Varnish-Server
Alternate-Protocol
Fastly-SWR
X-Fb-Rlafr
X-B
Fastly-SIE
X-WebKit-CSP-Report-Only
X-Status
X-Grace
X-Device-Type
Access-Control-Allow-Method
Healthy
X-Goog-Stored-Content-Encoding
TCN
X-Request-Guid
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Goog-Storage-Class
Upgrade-Insecure-Requests
Host
DC
Amp-Access-Control-Allow-Source-Origin
X-Magnolia-Registration
X-CSRF-Token
X-EdgeConnect-Cache-Status
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Contextid
X-Amzn-Remapped-Content-Length
X-Buckets
Retry-After
X-Debug
MS-Author-Via
X-Cache-Control
AKAMAI-GRN
X-Revision
X-Type
X-App-Version
X-Origin-CC
X-Origin-TTL
X-Oracle-Dms-Ecid
X-Cache-Age
X-Seen-By
SD-X-WS
X-Response-Served-From
X-Original-Request-Id
X-Instance
Frame-Options
X-Vcl-Version
X-RemovedCookies
X-NYM-Debug-Backend
X-ProcessESI
X-Rendered-As
X-Tumblr-Pixel
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-UUID
X-Tumblr-User
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-Is-Bot
Cross-Origin-Opener-Policy-Report-Only
Cross-Origin-Embedder-Policy-Report-Only
X-Adobe-Loc
X-Adobe-Content
X-Hl-Ver
X-N
Access-Control-Request-Headers
X-INCAP-ABP
X-Debug-IsPreview
Section-Io-Id
X-Debug-IsConnected
X-Akamai-Edgescape
X-G
X-Lambda-Id
Ms-Operation-Id
Charset
X-RTag
X-Storage
MS-CV
X-Akamai-Request-ID2
X-Varnish-Ttl
X-HITS
X-Backend-Name
X-Content-Powered-By
X-Framework
NGB
X-Mobile
X-Server-W
X-DataDome
X-RM-Cache-TTL
X-Mg-Request-UUID
X-ServerID
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
X-Trace-Id
X-Requestid
X-AB
X-Dc
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-Cache-Status-Check
Filterid
X-B3-SpanId
Cache
Accept-Language
X-Cache-Hit
X-Request-Bu
X-Request-Platform
X-Cache-Time
X-Request-Site
Refresh
X-Server-ID
X-Tec-Api-Version
X-Tec-Api-Root
X-NF-Request-ID
X-Tec-Api-Origin
SRV
X-Time
Webserver
AR-SID
Paypal-Debug-Id
X-Node-Name
X-Region
X-Real-IP
Onion-Location
X-VC-Cache
X-Wormhole-Sdk
X-XRDS-Location
X-Ms-Version
X-Ms-Request-Id
X-F-Cache
CDN-RequestId
Protected
X-User-Agent
X-Hcs-Proxy-Type
X-Cache-Expired-At
Liferay-Portal
X-CCDN-Origin-Time
X-CCDN-CacheTTL
X-Rocket-Nginx-Serving-Static
Cross-Origin-Window-Policy
Priority
X-Pass-Why
X-Yandex-Req-Id
X-IPS-LoggedIn
Xet-Cookie
X-HTML-Minification-Powered-By
X-LB-Cache
X-Whom
X-Datadog-Trace-Id
X-L-Path
X-Environment-Context
X-Datadog-Sampling-Priority
X-Mode
X-Datadog-Parent-Id
X-Datadog-Sampled
GEO-INFO
X-Service
Backend
X-Drupal-Cache-Tags
OT-Force-Account-Verify
X-Tb
Country
X-App-Environment
X-Fastcgi-Cache
YJS-CacheStatus
LB
X-Tncms
X-Tcp-Rtt
Meta-Geo
Filters
X-FB-TRIP-ID
X-Extlb
X-Origin-Hint
X-MP-GENERATED-AT
X-Vcache
X-Wix-Request-Id
X-Handled-By
ServerID
X-JoinUs
X-UPSTREAM-Address
X-Servername
TWC-Connection-Speed
Webcakes-App-Version
Webcakes-App-Name
Web-Mar-Node
Webcakes-Region
X-Adobe-Source
X-Cloudmap
X-Browser-Name
X-Detected-As
Url
TWC-Privacy
TWC-GeoIP-Country
TWC-GeoIP-City
TWC-Device-Class
TWC-GeoIP-DMA
TWC-GeoIP-LatLong
TWC-Locale-Group
TWC-GeoIP-Region
Property-Id
X-Rule
X-Is-Desktop
X-Cacheable-TTL
X-Loop
X-WP-CF-Super-Cache-Active
X-Rewrite-Enabled
X-Rn-Rsrv
X-Zipkin-Id
X-Is-Tablet
X-SaId
X-Proxied
X-Proxy-Cache-Info
X-Routing-Service
X-Geo-Region
X-Is-Supported-Browser
X-Is-Mobile
X-Director
X-Alternate-Cache-Key
X-Hosted-By
X-Format
X-Tumblr-Pixel-2
Atl-Traceid
X-Redis-Cache
X-Storefront-Renderer-Rendered
X-Tumblr-Pixel-3
X-Logging-Id
X-Forwarded-Host
X-Locale
X-Soup
X-Restarts
X-Cache-Host
Environment
X-Web-Node
X-Generation-Time
X-Cdn-Origin
X-Connection-Hash
X-Cms-Context
X-Hit
X-Cache-Action
X-Skip-Cache
Expiry
X-Shopify-Stage
DB-Nickname
X-Scope-Id
Locale
Apigw-Requestid
Uber-Trace-Id
X-RateLimit-Remaining-Second
X-Httpd
X-Origin-Date
X-Edge-Location
X-Say-Cacheable
X-FW-Server
X-FW-Serve
X-FW-Hash
X-FW-Dynamic
X-FW-Static
X-FW-Type
X-Varnish-Beresp-Grace
X-Say-TTL
X-RateLimit-Limit-Second
X-Fetched-On
X-IPLB-Instance
Mn-Server-Ip
X-SayCDN-TTL
ServedBy
X-IPLB-Request-ID
X-FW-Version
X-Urbn-Site-Id
X-Urbn-Context-Path
X-PHP-Host
Selected-Fe
X-Auth-Group-Type
X-ProxyCache-Key
X-BYPASS-REASON
X-Debug-Info
X-Endurance-Cache-Level
X-Cluster
X-Proxy-Build
X-ProxyCache-Status
Cache-Hits
X-Timing-Wait
X-Labrador-Cache-Channel
X-Is-Modern-Browser
X-Cluster-Node
X-Drupal-Cache-Contexts
X-RCS-CacheZone
X-Origin
X-Served-From
X-S
X-VCT
X-Origin-Cache
X-ECache
X-Cache-Debug
X-Mly-Id
Fastcgi-Useragent
X-GEO
X-ShopId
X-Sorting-Hat-PodId
X-No-Session
X-Sorting-Hat-ShopId
X-ShardId
X-UA
X-Provided-By
X-CACHE-AGE
Front
X-Is-Mobile-Only
X-R9-Blue-Green-Version
X-CDN-Forward
X-Varnish-Age
X-Varnish-Cache-Hits
X-Presslabs-Stats
X-VC
X-NewRelic-App-Data
Node
Xserver
X-Lagoon
Cache-Tv-Group
X-Platform
X-CLOUD-TRACE-CONTEXT
X-Varnish-Beresp-Ttl
X-Generated-By
X-CDN-Cache-Status
WPO-Cache-Status
X-Api-Version
X-WP-CF-Super-Cache-Cookies-Bypass
Countrycode
X-SRV
X-Webstats-RespID
X-Site-Version
X-Signature
Referer-Policy
X-B-Cache
X-Tt-Logid
Cache-Provider
X-B3-Traceid
From-Origin
X-Optimistic-Header
X-Accel-Version
X-Source
X-TA-CDN-Provider
X-Azure-Ref-OriginShield
X-NWS-UUID-VERIFY
X-VC-TTL
X-Tx-Id
X-PHP-Backend
X-Cache-Operation
X-Cache-Rule
Location
X-Ua
X-Worker
X-IsAdmin
Request-ID
X-Xfnlog-Site
CF-IPCountry
X-Sucuri-Cache
X-Tb-Optimization-Total-Bytes-Saved
X-Air-Pt
X-Auto-Login
X-Reqid
CDN-CachedAt
CDN-RequestCountryCode
CDN-RequestPullCode
CDN-PullZone
CDN-EdgeStorageId
CDN-Cache
CDN-RequestPullSuccess
CDN-Uid
AMP-Access-Control-Allow-Source-Origin
X-A-Wwc
Wxu-Next-Hostname
X-Access
X-Aed
X-Action
Wxu-Next-Region
X-A
X-A-Dgt
X-AK-Request-ID
X-A-Dam
X-A-Ccd
X-A-Dcw
X-Bl-Debug
X-Cms-Device
X-Clientip
X-Conf
X-Contensis-Viewer-Groups
X-Content-Age
X-Cache-NE
X-Cache-Aspx
X-Application
X-B-Cookie
X-BCube-Filmed-By
Wxu-Next-Commit
X-ApacheServer
RNT-Time
Host-ID
Fl-Custom-Application
IsBot
Lang
Log-Origin
Fastly-SSL
Expect-Staple
Cdnsip
Cdncip
Cluster
DCR-Decision-By
DCR-Processing-Time-Ms
MD5-Digest
Meta-Geo-Continent
X-Core-Value
RNT-Machine
Sslversion
Store-Cloud-Cache
Time-Cloud-Cache
Rendered-Blocks
Redirect-Candidate
N-Cache
Ngx.Var.Host
Odigeo-Trace-Id
Origin
Web-Mar-Region
X-Ec-Fail
X-Sigma
X-Section
X-Sigma-Backend
X-SIPLIST1
X-Slack-Backend
X-SD-PageType
X-ScT
X-Rocket-Build-Number
X-Request-URI
X-Rojux
X-S-Cookie
X-Save-Cache
X-Slack-Shared-Secret-Outcome
X-SRCache-Key
X-VG-WebCache
X-VG-TLSProxy
X-Viewer-Country
X-Vtex-Remote-Cache
Xc-Version
X-Vdms-Version
X-Vary-Devices
X-V-Cache
X-Varnish-Authentication
X-Varnish-Director
X-Varnish-Hostname
X-Req
X-PERF
X-Ee-Request-Id
X-Ee-Request-Date
X-External-Request-Id
X-Fmm-Version
X-Forwarded-Site
X-Ee-Origin
X-Ee-Generated-By
X-Depends
X-Developer
Candidate-Md5Url
X-Ec-GeoHdr
X-GeoCode
X-GeoCountry
X-Old-Content-Length
X-Node-Id
X-Org
X-Origin-Expires
X-PAYTM-SRV-ID
X-Micro-Cache
X-Loc
X-GeoIP-City
X-HS-Content-Campaign-Id
X-Ig-Origin-Region
X-Ig-Push-State
X-D
X-Destination
Apple-News-Services-Request-Url
Apple-News-Services-Host
Apple-News-Services-Handled
X-Fastly-Request-Id
Apple-News-Services-Parsed-Url
X-Litespeed-Cache-Control
X-Sucuri-ID
X-LSADC-Cache
X-VWS-Id
WPO-Cache-Message
X-AWS-Id
X-LJ-Flow-ID
X-DefHash
X-DefElseHash
X-Date
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-Ec-Custom-Error
X-Gen-Mode
X-From
X-Gamma-Serve
X-Fastly-Backend
X-Epic-Correlation-Id
X-Gdpr
X-Generated-On
X-Content-Length
X-Dispatcher-Server
X-Bc-Bl
X-AB-Test
X-Accel-Expires-Debug
X-Acquia-Purge-Cdn-Unconfigured
V-Age
User-Cache-Control
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
X-Aicache-OS
X-Akamai-Device-Characteristics
X-GeoIP-Country-Code
X-Block-Status
X-BBC-Edge-Cache-Status
X-Backend-Instance
X-Amz-Storage-Class
X-App-Name
X-Cache-Date
X-HN
X-Thinkindot-L3
X-UA-Device-Type
X-Up
X-Thinkindot-L1
X-Sn-Servicetimems
X-Render-Time
X-SB
X-Shield-Cache-Expires
X-Uri
X-Varnish-CookieHashed-On
X-Vmg-Version
X-We-Are-Hiring
X-Frame-Option
X-Via-Fastly
X-VarnishDD-TTL
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
X-Region-Sid
X-Path
X-Internal-TTL
X-Ion-Healthy
X-Ion-Hop
X-Human
X-Hnp-Log
X-GoCache-CacheStatus
X-Hash
TDXMobile
X-Jungle-Id
X-Level-Front-Cache
X-Nyt-Route
X-Op-Id-All
X-Origin-Time
Azure-InstanceId
X-Moov-Xdn-Caching-Status
X-Men
X-Moov-T
X-GeoIP-Region-Code
X-Moov-Xdn-Version
CDCHOST
DSUID
RewriteTestHook
S-Rt
Cache-Contol
Azure-Version
Server-Host
RewriteTeamHook
Country-Code
Cmstype
Content-Script-Type
Req-Svc-Chain
Cmsid
Origin-EX
Content-Style-Type
Azure-SlotName
Gannett-Cam-Experience-Id
Nord-Request-ID
Source
PFcat
Origin-Site
Origin-CC
Origin-Agent-Cluster
Azure-RegionName
ServerName
L
Azure-SiteName
X-FC-Vary-Parameters
Powered-By
X-Server-IP
Fastly-GeoIP-CountryCode
X-DPWN-IS-SECURE
X-Gzip
X-Esi-Check
X-NMSegId
X-Edge-Server
NM-Fastcgi-Cache
X-Location
Click-Count-Action-Start
Gh-Request-Id
Ha-Gx-Prefs
XM
X-Wikidot-Static-Cache
X-Wikidot-Backend
L5d-Success-Class
Pragrma
X-Eu-Site
X-Csrf-Jwt
X-CGP
X-Bug-Bounty
X-Policy
X-Vercel-Id
Cdn-Request-Time
Click-Count-Error
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-Pubstack
Cdn-Host
X-Vercel-Cache
C-Via
Fastly-Drupal-HTML
CacheControlHeader
X-Varnish-Beresp-Status
Fastly-Backend-Name
X-Upstream-Ct
Tube-Got-Eval
Producers
Tube-Get-Contents
Tube-Got-Results
Tube-Return
X-Upstream-Ht
X-Cache-FS-Status
X-Cache-Id
Platform
Release
X-CUA
X-B3-Trace-ID
X-Client-Ip
X-NGINX-Cache
X-Parent-Response-Time
X-Bip
X-CacheTTL
X-Thanos
X-Origin-Response-Time
X-Proto
X-TT-LOGID
Canary
X-Mvc-Supplant-Cachable
Machine
Mail-Subject
X-FORWARDED-FOR
Vix-Hermes-Req-Id
We-Hiring
X-Cs
X-Proxied-Request
X-ElasticPress-Query
X-ND-Cache
Pics-Label
X-Mvc-Supplant-OutputCached
CloudFront-Viewer-Country
Sid
X-Pad
X-Refresh
NGX
X-Via-Popn
X-APP
X-Via-Popv
Debug
X-Via-Poph
X-ZONE
X-Nananana
X-Varnish-Hits
X-Cached-By
Mime-Version
X-TH-Server
X-Servedbyhost
Product
GeoIP-Latitude
X-HA-Backend
X-Amz-Meta-Cb-Modifiedtime
HA-Ipaddr
Server-ID
Cookie
X-Srv
X-Litespeed-Tag
GeoIp-Country-Code
X-Cache-VC
MIME-Version
X-Datadome
X-Zone
X-AIR-PT
X-GeoIP
X-Fpc
X-DynaTrace-JS-Agent
X-Wa
X-User
X-Nc
Edge-Cache
X-Debug-Service
X-Cdn-Forward
X-Vc
SID
X-Webkit-CSP
Load-Balancing
X-Nginx-Cache-Key
X-B3-Parentspanid
Server-Hostname
Server-Ext
True-Client-Country-4JS
Sever-Int
WZWS-RAY
X-LB-ID
Show-Do-Not-Sell-Link
Cdn
X-LB-NoCache
X-Cache-Backend
X-Nginx-Cache
Resin-Trace
Traceparent
Akamai-Mon-Iucid-Del
DataCenter
HostName
X-Unity-Cache
X-Newrelic-Synthetics
Fastly-Drupal-Html
X-Scheme
X-Request-Start
Surrogated-Key
Tcn
Sm-Log-Id
X-Service-Response-Time
X-Ez-Minify-Html
X-Lsadc-Cache
X-VCL-Version
Wsr-Cache
X-Pool
Lb
X-CS
X-B3-Spanid
X-Request-Host
Hostname
Yjs-Id
X-CDN-Provider
X-NodeID
Serverhost
X-RequestId
X-API-Version
X-HOST
N1-Cache
X-Datacenter
Xkeylog
XkeyR9
X-Vgn-Hpd-Reason
Datacenter
X-Proxy-CacheR9
Xkey-La3
X-TX-ID
NtCoent-Length
X-Proxy-Cache-La3
X-Cache-Grace
CountryCode
X-LiteSpeed-Cache-Control
X-Dynatrace-Js-Agent
X-RateLimit-Limit
X-DynaTrace
X-HubSpot-Correlation-Id
X-DataCenter
X-LiteSpeed-Tag
Yak-Timeinfo
A
X-Air-Trace-Id
X-Air-Hostname
X-Air-Source
X-WA
X-Via-Edge
Cdn-Requestid
X-Lb-Id
X-Udemy-Cache-App-Namespace
CDN
X-Akamai-Pragma-Client-IP
Uri
X-Via-SSL
X-Via-CDN
Edge-Copy-Time
Cs
X-NC
X-Jobs
X-Fastly-Backend-Reqs
X-ID
X-FPC
X-Zen-Fury
X-Geolocation
X-VC-Age
Esi-Enabled
X-Via-JSL
Server-Id
X-Stale
X-Html-Minification-Powered-By
Req-ID
True-Client-IP
X-Ez-Minify-Js
X-Traceid
X-AC
X-TimeS
RATING
Geoip-Latitude
X-Srcache-Fetch-Status
WP-Super-Cache
Proxy-Firewall
GeoIP-Country-Code
X-Cdn-Srv
T-Server
X-Srcache-Store-Status
On-Server
Pramga
Srv
X-HA-Application-Name
X-HA-Bot-Classification
X-HA-Device-Type
X-Lb-Nocache
X-VTEX-Cache-Time
From-Cache
X-Varnish-Beresp-TTL
X-VTEX-Cache-Server
ServerHost
X-ServedByHost
X-Styx-Info
Cr
X-Swift-Error
X-Powered-By-VTEX-Cache
X-Wp-Cf-Super-Cache-Cache-Control
X-Wp-Cf-Super-Cache
X-TIM-N
X-Styx-Origin-Id
Content-Secure-Policy
X-Oracle-DMS-ECID
WebServer
X-MSEdge-Features
X-MSEdge-Flight
X-CACHE-KEY
W
X-Var-Ttl
X-CSRF-TOKEN
X-Ha-Backend
X-App
X-Wp-Cf-Super-Cache-Active
X-Wp-Cf-Super-Cache-Cookies-Bypass
Cloudfront-Viewer-Country
X-LAGOON
Cl-Cache
X-Ssense-Shipping-Surcharge-Enabled
X-Proxy-Cache-LA2
X-Elasticpress-Query
X-WA-Info
X-Fastly-Cache
X-Ramcache
X-Ssense-Gql
Ngx
Coldstone-Viewer-Country-Region-Name
Coldstone-Viewer-Currency
X-Via-PopN
Coldstone-Viewer-Country
X-Correlation-ID
X-Via-PopV
FSS-Cache
X-Via-PopH
X-Cdn-Cache-Status
X-Shardid
X-Geo
X-Webkit-Csp-Report-Only
CF-Cached-On
X-Sorting-Hat-Shopid
X-Shopid
X-Web-Server
X-Sorting-Hat-Podid
X-Check-Cacheable
X-Sucuri-Id
X-Serial
X-Th-Server
BehaviorPad-Version
X-Key
Akamai-X-True-TTL
X-VServer
Ohc-File-Size
Ohc-Cache-HIT
X-Request-Url
X-ATG-Version
X-DC
Cf-Ipcountry
X-Request-Time
Xkey-G-Jp
X-Fastly-Cache-Status
X-Cache-TTL-Remaining
X-Env
Host-Name
X-Fastly-Cache-Hits
X-Mg-Cache
Cneonction
FSS-Proxy
User-Agent