Threat Level: green Handler on Duty: Yee Ching Tok

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
X-Frame-Options
Expires
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Accept-CH
Last-Modified
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
X-XSS-Protection
X-Cache
Via
X-Powered-By
Pragma
CF-RAY
Age
Content-Security-Policy
Report-To
Alt-Svc
NEL
Referrer-Policy
Access-Control-Allow-Origin
X-Amz-Cf-Pop
X-Amz-Cf-Id
Content-Language
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-Download-Options
X-Xss-Protection
X-Request-Id
X-Timer
CF-Ray
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
X-DNS-Prefetch-Control
Content-Security-Policy-Report-Only
Accept-CH-Lifetime
X-AspNet-Version
X-Runtime
Permissions-Policy
X-Drupal-Cache
Server-Timing
X-Envoy-Upstream-Service-Time
X-Generator
X-FRAME-OPTIONS
X-Cache-Status
X-Ua-Compatible
X-Cacheable
X-CONTENT-TYPE-OPTIONS
X-Iinfo
X-Drupal-Dynamic-Cache
Accept-Ch
Timing-Allow-Origin
X-XSS-PROTECTION
Feature-Policy
X-Content-Security-Policy
Xkey
Upgrade
Access-Control-Expose-Headers
X-CDN
Status
Content-Encoding
X-AspNetMvc-Version
Access-Control-Max-Age
X-Amz-Request-Id
X-Amz-Id-2
Host-Header
X-Age
Request-Context
X-Backend
X-Amz-Version-Id
Cf-Edge-Cache
X-Hacker
X-Robots-Tag
Keep-Alive
Cf-Apo-Via
X-Via
X-Turbo-Charged-By
CONTENT-SECURITY-POLICY
X-Vhost
X-AH-Environment
X-Server
X-Rq
X-Dispatcher
X-Request-ID
X-Cache-Group
X-Proxy-Cache
X-Ws-Request-Id
EagleId
X-Varnish-Cache
X-UA-Device
X-Litespeed-Cache
Grace
Pantheon-Trace-Id
X-WebKit-CSP
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Server-Powered-By
X-OneAgent-JS-Injection
X-Pingback
X-Page-Speed
Allow
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Dns-Prefetch-Control
X-Swift-SaveTime
X-Swift-CacheTime
X-Cache-Lookup
X-Device
X-FTR-Request-ID
Ali-Swift-Global-Savetime
X-Node
X-Host
X-Backend-Server
EagleEye-TraceId
X-Server-Id
X-Country-Code
Surrogate-Control
X-Cloud-Trace-Context
P3p
Cf-Railgun
X-Ruxit-JS-Agent
X-Readtime
X-Akam-SW-Version
X-HW
Cache-Tag
X-Response-Time
X-Amz-Server-Side-Encryption
Accept-Ch-Lifetime
X-Ua-Device
X-Content-Type
Content-Location
X-LiteSpeed-Cache
Cross-Origin-Opener-Policy
X-Nginx-Cache-Status
X-Element-Page-Cache
X-Nginx-Upstream-Cache-Status
Request-Id
X-D2id
X-Rack-Cache
X-Trace
X-Application-Context
Service-Worker-Allowed
X-TraceId
Fastly-Restarts
X-Oneagent-Js-Injection
X-Nf-Request-Id
X-Times
X-PC
X-Vname
X-TtlSet
X-Navigation-Version
Rating
X-Clacks-Overhead
X-Cnection
X-Country
X-Edge
X-Midtier
X-Mcache
X-Vcap-Request-Id
X-Browser-Type
Origin-Trial
Edge-Control
X-Country-Code-Real
X-FTR-Backend-Server
X-FTR-Cache-Status
X-FTR-Backend
X-FTR-Balancer
X-ESI
X-FTR-Expires
X-Cache-TTL
X-Url
Surrogate-Key
X-NWS-LOG-UUID
X-Kinja-Server
X-Kinja-Build
X-Cdn-Fetch
X-Exp-Id
X-GoogleNews-Bot
X-FastCGI-Cache
X-Kinja
X-Exp-Variant
X-Kinja-Revision
X-Powered-By-Plesk
X-Ac
X-Abt-Application-Version
X-Amz-Rid
X-Mod-Pagespeed
X-Upstream
X-ECACHE
X-Request-Device-Id
Verso
X-B3-TraceId
X-ORACLE-DMS-RID
X-Language
X-MS-InvokeApp
Nginx-Cache
X-Pinterest-Rid
X-Meli-Trace-Platform
Pinterest-Generated-By
X-Meli-Trace-Bu
X-Meli-Trace-Site
Pinterest-Version
X-Amzn-Trace-Id
X-GitHub-Request-Id
X-Middleton-Display
Pagespeed
Display
X-Sol
X-T
S
X-Server-Lifecycle-Phase
X-PDP-UNCACHING-HASH
X-Kraken-Loop-Name
X-Instrumentation
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
Akamai-GRN
X-Envoy-Decorator-Operation
SPRequestDuration
X-SharePointHealthScore
SPIisLatency
SPRequestGuid
AR-PoweredBy
X-Middleton-Response
Response
AR-Request-ID
AR-ATIME
Edge-Cache-Tag
X-Distributor
X-Ruxit-Js-Agent
X-Goog-Hash
X-Ratelimit-Limit
X-Resp-Is-Stale
X-Ser
X-Kinsta-Cache
X-Edge-Location-Klb
X-ARC
X-Request-Processing-Time
X-Request-Received
Access-Control-Request-Method
X-NGENIX-Cache
Front-End-Https
X-Shield-Request-Id
X-Dw-Request-Base-Id
RTSS
X-Client-IP
X-Ezoic-Cdn
X-Recruiting
X-Content-Digest
X-Cache-Key
X-Varnish-TTL
Cache-Status
X-Amz-Replication-Status
Ar-SID
YJS-ID
X-Version
X-Mg-S
X-Ttl
X-Newrelic-App-Data
X-Ismobilevalue
Public-Key-Pins
X-Correlation-Id
X-Powered-CMS
TP-Cache
X-HS-Cache-Config
X-HS-Content-Id
X-Accel-Expires
X-HS-Hub-Id
Fastcgi-Cache
X-MSEdge-Ref
Cache-Tags
X-Fastly-Request-ID
AR-CACHE
X-Cached
X-Cluster-Name
Arr-Disable-Session-Affinity
Realpath
X-Id
X-Content-Security-Policy-Report-Only
X-Daa-Tunnel
Content-MD5
X-Server-Name
X-RateLimit-Remaining
X-HS-Combine-CSS
X-Azure-Ref
X-HP-Trace-Id
X-HP-Webp
X-Jurisdiction
X-Cambria-Cache-Control
Payment
X-Ua-Browser
X-DIS-Request-ID
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Xrds-Location
X-TTL
MicrosoftSharePointTeamServices
X-HS-Prerendered
X-HS-CF-Cache-Status
X-Amz-Apigw-Id
X-GUploader-UploadID
X-Forwarded-For
X-Amzn-RequestId
X-SRCache-Fetch-Status
X-SRCache-Store-Status
Content-Disposition
X-Px
X-Protected-By
Count-Hit
X-Ratelimit-Reset
X-Unique-Id
X-Activity-Id
X-Az
X-AppVersion
X-Page-Id
X-Origin-Server
X-Rid
Cross-Origin-Resource-Policy
X-Logged-In
X-Proxy
Cleartype
X-TEC-API-ORIGIN
X-Amz-Meta-S3cmd-Attrs
X-TEC-API-VERSION
X-Git-Hash
X-TEC-API-ROOT
Accept-Charset
X-VARITI-CCR
X-Request-Handler-Origin-Region
Cross-Origin-Embedder-Policy
X-Microsite
X-FB-Debug
X-Www-Served-By
X-Ratelimit-Remaining
X-Hits
Version
X-ORACLE-DMS-ECID
X-Load-Cache
X-Geo-Country
X-LLID
X-Goog-Metageneration
X-Forwarded-Proto
X-Template
X-COUNTRY
X-Varnish-Backend
X-Upgrade-Enabled
X-WebKit-CSP-Report-Only
X-PressLabs-Stats
Server-Node
AKAMAI-GRN
X-B3-Sampled
X-App-Server
X-Requestid
X-RemovedCookies
Server-Name
X-ProcessESI
X-Hostname
Healthy
Access-Control-Allow-Method
X-Content-Options
X-TT
X-Frontend
X-Varnish-Grace
X-Grace
Section-Io-Cache
Viewport
X-B
X-Request-Guid
Fastly-SIE
X-Fb-Rlafr
X-Device-Type
Fastly-SWR
Alternate-Protocol
X-Varnish-Server
X-Hl-Ver
X-Cache-Age
X-Contextid
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
X-Status
X-CSRF-Token
DC
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-SERVER-NAME
Upgrade-Insecure-Requests
X-Amzn-Remapped-Content-Length
X-Magnolia-Registration
X-CST
X-EdgeConnect-Cache-Status
TCN
X-App-Version
MS-Author-Via
Xet-Cookie
Frame-Options
Host
X-Cache-Control
Retry-After
X-Yandex-Req-Id
X-Varnish-Ttl
X-Oracle-Dms-Ecid
X-Origin-CC
X-Origin-TTL
X-Type
X-Revision
X-Response-Served-From
X-Original-Request-Id
SD-X-WS
X-G
X-AB
VIX-Pulpo-Node
X-ServerID
X-Debug
VIX-Pulpo-Upstream-Status
X-Buckets
X-Mobile
X-Adobe-Loc
X-Adobe-Content
X-N
X-Instance
X-UUID
X-INCAP-ABP
X-Seen-By
X-Backend-Name
X-Akamai-Edgescape
Cross-Origin-Opener-Policy-Report-Only
Access-Control-Request-Headers
Cache
X-Debug-IsPreview
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-Tumblr-User
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Tumblr-Pixel
X-Rendered-As
X-Debug-IsConnected
X-Cache-Status-Check
X-Is-Bot
X-Lambda-Id
X-NYM-Debug-Backend
X-Akamai-Request-ID2
Cross-Origin-Embedder-Policy-Report-Only
X-Cacheable-TTL
Ms-Operation-Id
NGB
X-Server-W
X-RM-Cache-TTL
X-WP-CF-Super-Cache-Cache-Control
Section-Io-Id
X-RTag
X-Tt-Trace-Tag
X-Framework
X-Mg-Request-UUID
X-Trace-Id
X-Tt-Trace-Host
X-WP-CF-Super-Cache
X-Content-Powered-By
Amp-Access-Control-Allow-Source-Origin
MS-CV
X-Storage
X-Proxy-Build
X-Timing-Wait
Selected-Fe
Charset
X-ProxyCache-Key
X-ProxyCache-Status
X-Dc
X-BYPASS-REASON
YJS-CacheStatus
Paypal-Debug-Id
X-Fastcgi-Cache
Webserver
X-B3-SpanId
X-VC-Cache
Filterid
X-Vcl-Version
Accept-Language
X-Ms-Request-Id
X-Ms-Version
Onion-Location
X-Cache-Time
Front
X-DataDome
Refresh
X-User-Agent
SRV
Apigw-Requestid
X-Cache-Hit
X-F-Cache
X-Time
X-VC
X-Tec-Api-Version
X-Tec-Api-Root
X-Tec-Api-Origin
X-Node-Name
X-Server-ID
X-Region
X-Real-IP
Priority
Liferay-Portal
X-Mly-Id
X-Origin-Cache
X-Environment-Context
X-Request-Bu
X-L-Path
X-Request-Site
GEO-INFO
X-Request-Platform
X-Hcs-Proxy-Type
X-CCDN-CacheTTL
X-Api-Version
X-Service
X-CCDN-Origin-Time
X-HTML-Minification-Powered-By
X-Mode
X-Webkit-Csp
X-CLOUD-TRACE-CONTEXT
CDN-RequestId
X-Rule
X-Origin
X-Optimistic-Header
X-LB-Cache
X-Rocket-Nginx-Serving-Static
X-Drupal-Cache-Tags
X-IPS-LoggedIn
X-JoinUs
X-Rn-Rsrv
Country
X-Rewrite-Enabled
X-VCT
X-Tb
X-SaId
X-UPSTREAM-Address
X-Tt-Logid
Backend
Meta-Geo
X-Is-Desktop
X-Handled-By
X-Geo-Region
X-Is-Mobile
X-Datadog-Sampling-Priority
X-Cache-Expired-At
X-Is-Mobile-Only
X-Is-Tablet
X-Is-Supported-Browser
X-Wix-Request-Id
X-Is-Modern-Browser
X-Datadog-Parent-Id
X-Datadog-Sampled
X-Browser-Name
X-Datadog-Trace-Id
X-Tcp-Rtt
X-Adobe-Source
Countrycode
X-Web-Node
Mn-Server-Ip
Cross-Origin-Window-Policy
X-Whom
X-Pass-Why
X-Provided-By
X-Generation-Time
AMP-Access-Control-Allow-Source-Origin
X-Cache-Action
TWC-Locale-Group
Url
Fastcgi-Useragent
X-Detected-As
X-Platform
TWC-GeoIP-Region
X-WP-CF-Super-Cache-Active
Uber-Trace-Id
X-Alternate-Cache-Key
Property-Id
Webcakes-App-Version
Webcakes-App-Name
TWC-GeoIP-Country
TWC-Privacy
TWC-GeoIP-City
Web-Mar-Node
Webcakes-Region
TWC-GeoIP-DMA
X-Cdn-Origin
X-Cloudmap
TWC-Device-Class
OT-Force-Account-Verify
TWC-GeoIP-LatLong
X-Shopify-Stage
X-Routing-Service
X-S
X-Servername
X-RCS-CacheZone
X-Extlb
X-Proxied
X-Proxy-Cache-Info
X-RateLimit-Limit-Second
TWC-Connection-Speed
X-HITS
X-Zipkin-Id
Expiry
X-Connection-Hash
X-Vcache
X-Varnish-Beresp-Grace
X-Storefront-Renderer-Rendered
X-Tncms
X-Origin-Hint
X-RateLimit-Remaining-Second
X-Origin-Date
X-Forwarded-Host
ServerID
X-FB-TRIP-ID
X-Httpd
X-Hit
X-Loop
X-Auth-Group-Type
X-Format
X-Urbn-Site-Id
X-Urbn-Context-Path
X-Fetched-On
X-MP-GENERATED-AT
Node
X-Director
X-Cms-Context
X-Tumblr-Pixel-3
X-Tumblr-Pixel-2
X-Hosted-By
X-App-Environment
X-Locale
X-Logging-Id
X-Skip-Cache
X-Cache-Debug
X-Cache-Host
X-Cluster
X-Soup
X-Redis-Cache
DB-Nickname
Locale
Protected
Environment
Cache-Hits
Atl-Traceid
ServedBy
X-Say-TTL
X-Scope-Id
X-Say-Cacheable
X-SayCDN-TTL
X-PHP-Host
X-Endurance-Cache-Level
X-Labrador-Cache-Channel
X-Debug-Info
X-Cluster-Node
X-Edge-Location
X-Restarts
X-Served-From
X-FW-Dynamic
X-FW-Type
X-FW-Version
X-FW-Server
X-FW-Static
X-FW-Serve
X-FW-Hash
X-XRDS-Location
X-IPLB-Instance
X-Drupal-Cache-Contexts
Filters
X-IPLB-Request-ID
X-CDN-Forward
Xserver
LB
X-R9-Blue-Green-Version
WPO-Cache-Status
X-CDN-Cache-Status
X-Client-Ip
X-GEO
Request-ID
X-WP-CF-Super-Cache-Cookies-Bypass
X-NWS-UUID-VERIFY
X-Presslabs-Stats
X-ECache
X-No-Session
X-Ua
X-Varnish-Beresp-Ttl
X-ShardId
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Varnish-Age
X-ShopId
CloudFront-Viewer-Country
X-Clientip
X-SRCache-Key
Expect-Staple
X-Varnish-Cache-Hits
X-Generated-By
X-Cache-FS-Status
Mail-Subject
X-Lagoon
We-Hiring
Cache-Tv-Group
X-Signature
X-B-Cache
X-Upstream-Ct
X-Upstream-Ht
Referer-Policy
X-TA-CDN-Provider
X-PHP-Backend
X-Azure-Ref-OriginShield
X-Cache-Rule
X-Cache-Operation
X-IsAdmin
X-B3-Traceid
X-SRV
X-Cs
X-UA
X-FORWARDED-FOR
X-Webstats-RespID
X-Auto-Login
X-Site-Version
Location
From-Origin
X-Worker
X-Server-IP
Cache-Provider
X-LSADC-Cache
X-Bc-Bl
Fl-Custom-Application
X-A-Dam
X-VWS-Id
Host-ID
Ngx.Var.Host
X-Developer
X-GeoCode
X-PERF
X-ApacheServer
Origin
Xc-Version
X-BCube-Filmed-By
X-A
X-Loc
N-Cache
Meta-Geo-Continent
X-A-Dgt
X-Application
X-ND-Cache
X-A-Ccd
X-LJ-Flow-ID
X-Tb-Optimization-Total-Bytes-Saved
X-Destination
MD5-Digest
Candidate-Md5Url
Mime-Version
X-Org
WPO-Cache-Message
X-Cache-NE
X-Vdms-Version
X-D
X-Vtex-Remote-Cache
X-Aed
X-AWS-Id
X-Ec-GeoHdr
X-Accel-Version
Rendered-Blocks
S-Rt
Sslversion
DCR-Decision-By
DCR-Processing-Time-Ms
Origin-Agent-Cluster
X-Content-Age
X-ScT
X-A-Wwc
Redirect-Candidate
Lang
X-Ig-Push-State
Pragrma
X-B-Cookie
X-Ec-Fail
Source
X-Rojux
X-Ig-Origin-Region
X-A-Dcw
X-External-Request-Id
X-GeoCountry
X-Bl-Debug
X-S-Cookie
X-Conf
X-Xfnlog-Site
Sid
X-Cms-Device
X-Ee-Request-Id
RNT-Machine
Country-Code
X-Eu-Site
X-Ee-Request-Date
X-Epic-Correlation-Id
X-Ee-Origin
X-Action
Wxu-Next-Commit
X-Access
X-Contensis-Viewer-Groups
X-Ee-Generated-By
RNT-Time
X-Fastly-Backend
CDN-RequestCountryCode
CDN-RequestPullCode
X-CGP
X-FC-Vary-Parameters
X-Fmm-Version
CDN-PullZone
CDN-RequestPullSuccess
CDN-Uid
ServerName
Server-Host
Cluster
Cdnsip
Cdncip
X-Aicache-OS
CDN-EdgeStorageId
Wxu-Next-Hostname
X-DefHash
X-Dispatcher-Server
NM-Fastcgi-Cache
Ha-Gx-Prefs
X-DefElseHash
IsBot
Time-Cloud-Cache
Log-Origin
X-Cache-Aspx
L5d-Success-Class
X-Bug-Bounty
X-Depends
Gh-Request-Id
Gannett-Cam-Experience-Id
X-AK-Request-ID
Vix-Hermes-Req-Id
Web-Mar-Region
Store-Cloud-Cache
Wxu-Next-Region
X-Core-Value
X-Csrf-Jwt
Odigeo-Trace-Id
X-CacheTTL
Origin-Site
X-CUA
Powered-By
Fastly-SSL
X-Men
X-Varnish-CookieHashed-On
X-Origin-Expires
X-Varnish-Beresp-Status
X-PAYTM-SRV-ID
X-VC-TTL
X-Policy
X-Varnish-CookieINHashed-On
X-Old-Content-Length
Load-Balancing
X-Micro-Cache
X-Mvc-Supplant-Cachable
X-Varnish-Hostname
X-Varnish-Director
X-Node-Id
X-Varnish-Authentication
X-V-Cache
X-SIPLIST1
X-Sigma-Backend
X-Litespeed-Cache-Control
X-Slack-Backend
X-Sn-Servicetimems
X-Slack-Shared-Secret-Outcome
X-Sigma
X-Section
CDN-CachedAt
X-Up
X-Req
X-Rocket-Build-Number
X-SD-PageType
X-Save-Cache
X-Varnish-Remaining-TTL
X-NMSegId
X-GeoIP-City
Apple-News-Services-Host
X-GeoIP-Country-Code
X-GeoIP-Region-Code
X-GoCache-CacheStatus
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
X-Forwarded-Site
CDN-Cache
Canary
X-From
X-Gamma-Serve
X-Hash
Apple-News-Services-Handled
X-VG-TLSProxy
X-Vary-Devices
X-HS-Content-Campaign-Id
X-Internal-TTL
X-VG-WebCache
X-Tx-Id
X-Parent-Response-Time
X-CACHE-AGE
X-Cached-By
X-Backend-Instance
X-Via-Fastly
X-Thanos
X-Wikidot-Static-Cache
X-App-Name
X-Cache-Id
X-Vmg-Version
X-Vercel-Cache
X-Vercel-Id
X-Wikidot-Backend
X-Cache-Date
X-Block-Status
X-We-Are-Hiring
X-VarnishDD-TTL
X-Uri
X-BBC-Edge-Cache-Status
X-UA-Device-Type
X-Bip
X-SVT-ORM-VERSION
X-Viewer-Country
X-Thinkindot-L3
X-Thinkindot-L1
X-Date
X-Ion-Hop
X-Ion-Healthy
X-Human
X-Ec-Custom-Error
X-DPWN-IS-SECURE
X-Level-Front-Cache
X-Jungle-Id
X-Edge-Server
X-Hnp-Log
X-Gen-Mode
X-Gdpr
X-Frame-Option
X-Generated-On
X-Esi-Check
X-HN
X-Gzip
X-Mvc-Supplant-OutputCached
X-Nyt-Route
X-Request-URI
X-Reqid
X-Render-Time
X-Content-Length
X-SB
X-Sucuri-Cache
X-Shield-Cache-Expires
X-Region-Sid
X-Debug-Cache-Fetch
X-Origin-Time
X-Op-Id-All
X-Path
X-Proto
X-Debug-Cache-Store
X-Pubstack
X-SVT-ORM-RULES
X-AB-Test
L
Machine
Fastly-Backend-Name
DSUID
X-ZONE
Content-Style-Type
Nord-Request-ID
Origin-CC
Platform
Producers
Pics-Label
PFcat
Origin-EX
Cmstype
Cmsid
Azure-RegionName
Azure-SiteName
Azure-InstanceId
X-Amz-Storage-Class
X-URL
Azure-SlotName
Azure-Version
Cdn-Host
Cdn-Request-Time
CDCHOST
CacheControlHeader
Cache-Contol
Release
Content-Script-Type
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
User-Cache-Control
V-Age
X-Akamai-Device-Characteristics
X-Acquia-Purge-Cdn-Unconfigured
TDXMobile
X-Accel-Expires-Debug
RewriteTeamHook
RewriteTestHook
Req-Svc-Chain
X-NF-Request-ID
X-NewRelic-App-Data
CF-IPCountry
X-ElasticPress-Query
Click-Count-Action-Start
Click-Count-Error
Tube-Got-Eval
Tube-Get-Contents
C-Via
Tube-Got-Results
Tube-Return
X-B3-Trace-ID
X-Location
X-Moov-T
X-Moov-Xdn-Caching-Status
X-NGINX-Cache
Cookie
X-Proxied-Request
X-Moov-Xdn-Version
Fastly-GeoIP-CountryCode
X-Pad
X-Fastly-Request-Id
X-Nginx-Cache-Key
X-Datadome
XM
X-Sucuri-ID
X-Via-Popn
X-Debug-Service
X-Origin-Response-Time
X-Via-Poph
X-Via-Popv
True-Client-Country-4JS
Fastly-Drupal-HTML
X-Varnish-Hits
X-HA-Backend
Server-Hostname
X-AIR-PT
NGX
Server-Ext
X-Srv
Sever-Int
X-Webkit-CSP
AR-SID
X-Refresh
Show-Do-Not-Sell-Link
Debug
Traceparent
X-Air-Pt
X-Ez-Minify-Html
X-Cache-Backend
X-APP
X-Servedbyhost
X-Unity-Cache
X-Nananana
HostName
X-TH-Server
X-DynaTrace-JS-Agent
Server-ID
X-LB-ID
GeoIp-Country-Code
GeoIP-Latitude
Product
DataCenter
WZWS-RAY
HA-Ipaddr
X-Fpc
X-Zone
Cdn
X-B3-Parentspanid
X-Amz-Meta-Cb-Modifiedtime
Tcn
Fastly-Drupal-Html
X-VCL-Version
X-Wormhole-Sdk
X-Cdn-Forward
X-Litespeed-Tag
X-Newrelic-Synthetics
X-Nc
X-CDN-Provider
X-Wa
X-Cache-VC
X-GeoIP
X-AC
Lb
X-Nginx-Cache
SID
X-Source
X-Vc
Serverhost
Edge-Cache
A
X-User
XkeyR9
Xkeylog
X-Proxy-CacheR9
Xkey-La3
X-Proxy-Cache-La3
CountryCode
X-Datacenter
X-TX-ID
Cs
X-Request-Start
NtCoent-Length
X-B3-Spanid
Resin-Trace
X-RateLimit-Limit
X-LiteSpeed-Tag
X-LB-NoCache
Esi-Enabled
Akamai-Mon-Iucid-Del
X-Service-Response-Time
CDN
X-WA
Cdn-Requestid
Sm-Log-Id
X-API-Version
X-LiteSpeed-Cache-Control
X-TT-LOGID
X-VC-Age
Wsr-Cache
X-Dynatrace-Js-Agent
MIME-Version
X-NC
X-HubSpot-Correlation-Id
X-Aspnet-Version
X-ID
X-Scheme
X-Lsadc-Cache
X-HA-Device-Type
X-HA-Bot-Classification
X-Styx-Info
X-HA-Application-Name
X-Styx-Origin-Id
Content-Secure-Policy
Datacenter
Uri
X-Udemy-Cache-App-Namespace
Proxy-Firewall
Cr
X-TIM-N
Pramga
X-FPC
X-Html-Minification-Powered-By
X-Fastly-Backend-Reqs
X-NodeID
X-Lb-Id
X-Pool
X-Ez-Minify-Js
Yjs-Id
RATING
Server-Id
X-Via-JSL
GeoIP-Country-Code
ServerHost
X-Request-Host
Geoip-Latitude
X-Srcache-Fetch-Status
X-TimeS
X-Srcache-Store-Status
X-Var-Ttl
Hostname
From-Cache
X-Lb-Nocache
Srv
X-ServedByHost
X-Stale
W
X-NODE
X-Akamai-Pragma-Client-IP
X-Wp-Cf-Super-Cache
X-Oracle-DMS-ECID
Surrogated-Key
X-Wp-Cf-Super-Cache-Cache-Control
X-Aspnetmvc-Version
X-RequestId
T-Server
X-MSEdge-Features
X-MSEdge-Flight
X-Vgn-Hpd-Reason
X-CS
X-CACHE-KEY
Cloudfront-Viewer-Country
X-Cache-Grace
X-App
X-Swift-Error
X-DynaTrace
X-Sorting-Hat-Shopid
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-Air-Source
X-LAGOON
X-Air-Trace-Id
X-Shardid
X-Varnish-Beresp-TTL
X-Shopid
X-Wp-Cf-Super-Cache-Active
X-Sorting-Hat-Podid
X-Air-Hostname
X-Proxy-Cache-LA2
X-VServer
X-Key
X-Ramcache
Ohc-File-Size
X-Correlation-ID
X-Ssense-Gql
Ohc-Cache-HIT
Yak-Timeinfo
X-DataCenter
X-Ssense-Shipping-Surcharge-Enabled
X-ByteArk-ReqID
X-ByteArk-Cache
X-Elasticpress-Query
Edge-Copy-Time
X-Via-CDN
X-Ha-Backend
X-Via-Edge
X-Jobs
X-Via-SSL
X-Webkit-Csp-Report-Only
CF-Cached-On
N1-Cache
X-Geo
X-Cdn-Cache-Status
Req-ID
Cl-Cache
Ngx
X-CSRF-TOKEN
X-Sucuri-Id
X-Via-PopV
Akamai-X-True-TTL
X-DC
X-Via-PopH
X-Via-PopN
X-Zen-Fury
WebServer
X-PageType
X-Geolocation
X-Check-Cacheable
X-Web-Server
X-Th-Server
X-ATG-Version
X-Iplb-Request-Id
Cf-Ipcountry
X-Iplb-Instance
X-Beacon
My-App
X-MiniProfiler-Ids
Warning
X-Limited
True-Client-IP
Host-Name
X-Mg-Cache
FSS-Cache
X-Serial
WP-Super-Cache
X-Env
User-Agent
X-Request-Url
X-Fastly-Cache-Status
Xkey-G-Jp