Threat Level: green Handler on Duty: Yee Ching Tok

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
X-Frame-Options
Expires
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Accept-CH
Last-Modified
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
X-XSS-Protection
X-Cache
Via
X-Powered-By
Pragma
CF-RAY
Age
Content-Security-Policy
Report-To
Alt-Svc
NEL
Referrer-Policy
Access-Control-Allow-Origin
X-Amz-Cf-Pop
X-Amz-Cf-Id
Content-Language
P3P
X-Cache-Hits
X-UA-Compatible
X-Served-By
X-Xss-Protection
X-Download-Options
X-Request-Id
CF-Ray
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
X-DNS-Prefetch-Control
Content-Security-Policy-Report-Only
Accept-CH-Lifetime
X-AspNet-Version
X-Runtime
Permissions-Policy
X-Drupal-Cache
Server-Timing
X-FRAME-OPTIONS
X-Envoy-Upstream-Service-Time
X-Generator
X-Ua-Compatible
X-Cache-Status
X-Cacheable
X-CONTENT-TYPE-OPTIONS
Accept-Ch
X-Iinfo
X-Drupal-Dynamic-Cache
Timing-Allow-Origin
X-XSS-PROTECTION
Feature-Policy
X-Content-Security-Policy
Xkey
Upgrade
Access-Control-Expose-Headers
X-CDN
Status
Content-Encoding
X-AspNetMvc-Version
Access-Control-Max-Age
X-Amz-Request-Id
X-Amz-Id-2
Host-Header
X-Age
Request-Context
X-Backend
X-Amz-Version-Id
Cf-Edge-Cache
X-Robots-Tag
Keep-Alive
X-Hacker
CONTENT-SECURITY-POLICY
Cf-Apo-Via
X-Via
X-Turbo-Charged-By
X-Request-ID
X-Vhost
X-AH-Environment
X-Server
X-Rq
X-Dispatcher
X-Cache-Group
X-Proxy-Cache
X-Ws-Request-Id
EagleId
X-Varnish-Cache
X-UA-Device
Grace
Pantheon-Trace-Id
X-Litespeed-Cache
X-WebKit-CSP
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Server-Powered-By
X-OneAgent-JS-Injection
X-Pingback
X-Page-Speed
Allow
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Dns-Prefetch-Control
X-Cache-Lookup
X-Swift-CacheTime
X-Swift-SaveTime
X-Device
X-FTR-Request-ID
X-Node
Ali-Swift-Global-Savetime
X-Host
X-Backend-Server
EagleEye-TraceId
X-Server-Id
X-Country-Code
Surrogate-Control
X-Cloud-Trace-Context
Cf-Railgun
X-Readtime
X-Ruxit-JS-Agent
X-HW
X-Akam-SW-Version
Cache-Tag
Accept-Ch-Lifetime
X-Response-Time
X-Amz-Server-Side-Encryption
X-Ua-Device
X-Content-Type
X-LiteSpeed-Cache
Content-Location
Cross-Origin-Opener-Policy
X-Nginx-Cache-Status
X-D2id
X-Element-Page-Cache
X-Nginx-Upstream-Cache-Status
Request-Id
X-Oneagent-Js-Injection
X-Rack-Cache
X-Application-Context
Service-Worker-Allowed
X-Trace
X-TraceId
Fastly-Restarts
X-Nf-Request-Id
X-Times
X-Navigation-Version
X-Vname
X-PC
X-TtlSet
Rating
X-Clacks-Overhead
X-Cnection
X-Country
X-Midtier
X-Edge
X-Mcache
X-Vcap-Request-Id
Origin-Trial
X-Browser-Type
Edge-Control
X-Country-Code-Real
X-FTR-Backend
X-FTR-Cache-Status
X-FTR-Backend-Server
X-FTR-Balancer
X-ESI
X-FTR-Expires
X-Cache-TTL
X-Url
X-FastCGI-Cache
Surrogate-Key
X-NWS-LOG-UUID
X-Kinja-Revision
X-Kinja-Build
X-Cdn-Fetch
X-Exp-Variant
X-Kinja
X-GoogleNews-Bot
X-Exp-Id
X-Kinja-Server
X-ECACHE
X-Ac
X-Request-Device-Id
X-Powered-By-Plesk
X-Abt-Application-Version
X-Mod-Pagespeed
X-Amz-Rid
X-Upstream
Verso
X-ORACLE-DMS-RID
X-B3-TraceId
X-Meli-Trace-Platform
X-Meli-Trace-Site
X-Meli-Trace-Bu
X-MS-InvokeApp
X-Language
Pinterest-Version
Pinterest-Generated-By
Akamai-GRN
X-Pinterest-Rid
Nginx-Cache
X-Amzn-Trace-Id
X-GitHub-Request-Id
X-Middleton-Display
Pagespeed
Display
X-Sol
S
X-T
X-Erf-Bev-Bev
X-PDP-UNCACHING-HASH
X-Instrumentation
X-Kraken-Loop-Name
X-Erf-Bev-Bev-Is-Generated
X-Server-Lifecycle-Phase
X-Ruxit-Js-Agent
X-Envoy-Decorator-Operation
SPRequestDuration
X-SharePointHealthScore
SPRequestGuid
SPIisLatency
X-Middleton-Response
AR-Request-ID
AR-PoweredBy
AR-ATIME
Response
Edge-Cache-Tag
X-Distributor
X-Goog-Hash
X-Ratelimit-Limit
X-Resp-Is-Stale
X-Ser
X-Edge-Location-Klb
X-Kinsta-Cache
X-ARC
X-Request-Received
X-NGENIX-Cache
X-Request-Processing-Time
Access-Control-Request-Method
Front-End-Https
X-Shield-Request-Id
X-Dw-Request-Base-Id
Ar-SID
RTSS
X-Ezoic-Cdn
X-Client-IP
X-Cache-Key
X-Recruiting
X-Content-Digest
Cache-Status
X-Version
X-Varnish-TTL
X-Amz-Replication-Status
X-Mg-S
YJS-ID
X-Fastly-Request-ID
X-Newrelic-App-Data
X-Ismobilevalue
Public-Key-Pins
X-Powered-CMS
X-Accel-Expires
X-HS-Cache-Config
X-HS-Hub-Id
TP-Cache
X-HS-Content-Id
AR-CACHE
Fastcgi-Cache
X-MSEdge-Ref
Cache-Tags
X-Ttl
X-Correlation-Id
X-Cached
X-Server-Name
X-Cluster-Name
Arr-Disable-Session-Affinity
Realpath
X-Content-Security-Policy-Report-Only
X-Id
X-Daa-Tunnel
Content-MD5
X-HS-Combine-CSS
X-Azure-Ref
X-TTL
X-RateLimit-Remaining
X-Cambria-Cache-Control
X-HP-Webp
X-Jurisdiction
X-Ua-Browser
X-HP-Trace-Id
Payment
X-DIS-Request-ID
MicrosoftSharePointTeamServices
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Amzn-RequestId
X-Amz-Apigw-Id
X-HS-CF-Cache-Status
X-HS-Prerendered
X-Xrds-Location
X-GUploader-UploadID
X-Forwarded-For
X-SRCache-Fetch-Status
X-SRCache-Store-Status
Content-Disposition
X-Px
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-Protected-By
X-TEC-API-ROOT
Count-Hit
X-Ratelimit-Remaining
X-Ratelimit-Reset
X-Activity-Id
X-Unique-Id
X-Az
X-AppVersion
X-Page-Id
X-Rid
Cross-Origin-Resource-Policy
X-Logged-In
Cleartype
X-Origin-Server
Accept-Charset
Cross-Origin-Embedder-Policy
X-Git-Hash
X-Proxy
X-Amz-Meta-S3cmd-Attrs
X-FB-Debug
X-Microsite
X-Request-Handler-Origin-Region
X-VARITI-CCR
X-Www-Served-By
Version
X-Load-Cache
X-Geo-Country
X-COUNTRY
X-Hits
X-LLID
X-Goog-Metageneration
X-ORACLE-DMS-ECID
X-Forwarded-Proto
X-Template
X-Varnish-Backend
X-Requestid
X-WebKit-CSP-Report-Only
X-Upgrade-Enabled
X-B3-Sampled
Server-Node
X-ProcessESI
X-PressLabs-Stats
X-App-Server
X-RemovedCookies
X-Hostname
Server-Name
Healthy
X-Content-Options
Access-Control-Allow-Method
X-Frontend
X-TT
Section-Io-Cache
Viewport
X-B
X-Device-Type
X-Request-Guid
X-Grace
X-Varnish-Grace
X-Varnish-Server
Alternate-Protocol
X-Fb-Rlafr
Fastly-SIE
Fastly-SWR
X-Contextid
X-Hl-Ver
AKAMAI-GRN
MRF-Tech
X-B3-TraceId-Primal
Mrf-Cache-Status
X-CSRF-Token
X-Status
DC
X-Cache-Age
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Goog-Generation
X-Goog-Stored-Content-Length
X-Yandex-Req-Id
X-Amzn-Remapped-Content-Length
X-Magnolia-Registration
Upgrade-Insecure-Requests
X-Varnish-Ttl
X-App-Version
X-Oracle-Dms-Ecid
Frame-Options
MS-Author-Via
TCN
X-Cache-Control
X-EdgeConnect-Cache-Status
Xet-Cookie
Host
Retry-After
X-CST
X-Origin-TTL
X-Origin-CC
X-SERVER-NAME
X-Type
X-Original-Request-Id
X-Response-Served-From
X-Revision
Amp-Access-Control-Allow-Source-Origin
VIX-Pulpo-Upstream-Status
SD-X-WS
X-G
X-ServerID
X-Debug
VIX-Pulpo-Node
X-AB
X-Mobile
X-Cacheable-TTL
NGB
X-UUID
X-Seen-By
X-Backend-Name
X-INCAP-ABP
X-Akamai-Edgescape
X-Instance
X-Adobe-Content
X-Adobe-Loc
X-N
X-Rendered-As
X-Buckets
X-Debug-IsConnected
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-NYM-Debug-Backend
Cross-Origin-Opener-Policy-Report-Only
X-Lambda-Id
X-Is-Bot
Cache
Access-Control-Request-Headers
Cross-Origin-Embedder-Policy-Report-Only
X-Tumblr-User
X-Akamai-Request-ID2
X-Tumblr-Pixel-1
X-Cache-Status-Check
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Debug-IsPreview
X-Framework
MS-CV
Ms-Operation-Id
X-WP-CF-Super-Cache
X-Mg-Request-UUID
Section-Io-Id
X-WP-CF-Super-Cache-Cache-Control
X-Content-Powered-By
X-RTag
Selected-Fe
X-B3-SpanId
X-Server-W
X-Timing-Wait
X-Proxy-Build
X-RM-Cache-TTL
X-Trace-Id
X-Tt-Trace-Host
X-Tt-Trace-Tag
Charset
X-Storage
X-ProxyCache-Key
YJS-CacheStatus
X-BYPASS-REASON
X-ProxyCache-Status
X-Dc
Paypal-Debug-Id
X-VC-Cache
Webserver
Accept-Language
Front
X-Ms-Version
X-Ms-Request-Id
Filterid
Onion-Location
X-Vcl-Version
SRV
X-Cache-Time
X-User-Agent
X-DataDome
X-VC
X-F-Cache
Refresh
X-Server-ID
Apigw-Requestid
X-Cache-Hit
X-Time
X-Origin-Cache
Priority
X-Real-IP
X-Node-Name
X-Region
X-Mly-Id
Liferay-Portal
X-Fastcgi-Cache
GEO-INFO
X-Environment-Context
X-CLOUD-TRACE-CONTEXT
X-L-Path
X-Webkit-Csp
X-Service
X-CCDN-CacheTTL
X-CCDN-Origin-Time
X-Hcs-Proxy-Type
X-Mode
X-HTML-Minification-Powered-By
X-Tec-Api-Version
X-LB-Cache
X-Api-Version
X-Tec-Api-Root
X-Rule
X-Origin
X-Optimistic-Header
X-Request-Site
X-Tec-Api-Origin
X-Request-Platform
X-Request-Bu
X-Tb
X-Rewrite-Enabled
X-Rn-Rsrv
X-Drupal-Cache-Tags
Meta-Geo
X-Rocket-Nginx-Serving-Static
X-UPSTREAM-Address
X-VCT
X-SaId
X-HITS
CDN-RequestId
Country
X-JoinUs
X-Tt-Logid
X-Tcp-Rtt
X-IPS-LoggedIn
X-Is-Desktop
X-Is-Supported-Browser
X-Wix-Request-Id
X-Is-Mobile-Only
X-Handled-By
X-Geo-Region
X-Is-Modern-Browser
X-Is-Tablet
X-Is-Mobile
Backend
X-Adobe-Source
X-Browser-Name
Mn-Server-Ip
Expiry
X-Cache-Expired-At
X-Datadog-Parent-Id
X-Web-Node
X-Pass-Why
X-Connection-Hash
X-Datadog-Sampling-Priority
X-Datadog-Sampled
Countrycode
X-Generation-Time
X-XRDS-Location
X-Platform
X-Provided-By
X-Datadog-Trace-Id
TWC-Locale-Group
Web-Mar-Node
TWC-GeoIP-DMA
Url
TWC-Connection-Speed
X-Cache-Action
TWC-Privacy
TWC-Device-Class
TWC-GeoIP-LatLong
TWC-GeoIP-Country
Property-Id
Uber-Trace-Id
Fastcgi-Useragent
Webcakes-App-Version
Webcakes-App-Name
X-Cloudmap
X-WP-CF-Super-Cache-Active
Webcakes-Region
X-Alternate-Cache-Key
OT-Force-Account-Verify
X-Cms-Context
TWC-GeoIP-Region
X-Cdn-Origin
X-Shopify-Stage
X-Storefront-Renderer-Rendered
X-Origin-Date
X-Loop
X-Routing-Service
X-S
X-Tncms
X-Origin-Hint
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Proxy-Cache-Info
X-Proxied
X-Detected-As
X-Whom
X-Servername
ServerID
TWC-GeoIP-City
X-FB-TRIP-ID
X-Extlb
Node
X-Zipkin-Id
X-Forwarded-Host
Cross-Origin-Window-Policy
X-Varnish-Beresp-Grace
X-Httpd
X-Vcache
X-Hit
X-RCS-CacheZone
X-Tumblr-Pixel-3
X-Cluster
X-Urbn-Site-Id
X-Urbn-Context-Path
X-Soup
X-Tumblr-Pixel-2
X-App-Environment
X-Hosted-By
X-Cache-Host
X-Format
X-Fetched-On
X-Director
X-Cache-Debug
X-Locale
X-Redis-Cache
X-Auth-Group-Type
X-MP-GENERATED-AT
X-Logging-Id
X-Skip-Cache
Environment
DB-Nickname
Cache-Hits
Atl-Traceid
Locale
X-CDN-Forward
ServedBy
X-FW-Dynamic
X-FW-Hash
X-FW-Serve
X-Scope-Id
X-Endurance-Cache-Level
X-SayCDN-TTL
X-Say-TTL
X-Debug-Info
X-Edge-Location
X-Cluster-Node
X-Say-Cacheable
X-FW-Server
X-Restarts
Protected
X-Labrador-Cache-Channel
X-PHP-Host
X-FW-Static
AMP-Access-Control-Allow-Source-Origin
X-FW-Type
X-FW-Version
X-Served-From
X-Client-Ip
X-Drupal-Cache-Contexts
X-IPLB-Request-ID
X-IPLB-Instance
Filters
Xserver
WPO-Cache-Status
X-Presslabs-Stats
X-Ua
Request-ID
X-NWS-UUID-VERIFY
X-R9-Blue-Green-Version
LB
X-Varnish-Beresp-Ttl
X-GEO
X-CDN-Cache-Status
X-WP-CF-Super-Cache-Cookies-Bypass
X-No-Session
X-Sorting-Hat-ShopId
X-ShardId
X-Clientip
X-Sorting-Hat-PodId
CloudFront-Viewer-Country
X-ShopId
Expect-Staple
X-Varnish-Age
X-Upstream-Ct
X-Generated-By
X-Upstream-Ht
X-Varnish-Cache-Hits
X-Signature
X-SRCache-Key
X-B-Cache
X-Cache-FS-Status
Cache-Tv-Group
X-Lagoon
We-Hiring
Mail-Subject
X-B3-Traceid
X-Cs
X-Azure-Ref-OriginShield
Referer-Policy
X-FORWARDED-FOR
X-PHP-Backend
X-TA-CDN-Provider
X-Cache-Operation
X-IsAdmin
X-Cache-Rule
X-LSADC-Cache
X-Webstats-RespID
Location
X-Worker
X-SRV
X-Auto-Login
X-Bc-Bl
X-ECache
From-Origin
X-Server-IP
Fl-Custom-Application
X-Site-Version
Cache-Provider
X-UA
Load-Balancing
Candidate-Md5Url
X-Tb-Optimization-Total-Bytes-Saved
DCR-Processing-Time-Ms
Host-ID
S-Rt
Lang
DCR-Decision-By
Origin-Agent-Cluster
MD5-Digest
Source
X-A-Wwc
X-GeoCode
X-GeoCountry
X-Ig-Origin-Region
X-Ig-Push-State
X-External-Request-Id
X-Ec-GeoHdr
X-Destination
X-Developer
X-Ec-Fail
X-Loc
X-ND-Cache
X-Vdms-Version
X-Vtex-Remote-Cache
Xc-Version
X-ScT
X-S-Cookie
X-Org
X-PERF
X-Rojux
X-D
X-Content-Age
Rendered-Blocks
Sslversion
X-A
X-A-Ccd
Redirect-Candidate
Pragrma
N-Cache
Ngx.Var.Host
Origin
X-A-Dcw
X-A-Dgt
X-Bl-Debug
X-Cache-NE
X-Conf
X-BCube-Filmed-By
X-B-Cookie
X-Aed
X-ApacheServer
X-Application
Meta-Geo-Continent
X-A-Dam
WPO-Cache-Message
Mime-Version
X-VWS-Id
X-AWS-Id
X-LJ-Flow-ID
X-Accel-Version
X-CACHE-AGE
X-Xfnlog-Site
Store-Cloud-Cache
X-Req
Time-Cloud-Cache
X-Rocket-Build-Number
ServerName
RNT-Time
Server-Host
Vix-Hermes-Req-Id
RNT-Machine
Web-Mar-Region
X-Access
X-Action
X-Aicache-OS
X-PAYTM-SRV-ID
X-Policy
Wxu-Next-Commit
Wxu-Next-Hostname
Wxu-Next-Region
X-Save-Cache
X-Section
L5d-Success-Class
Log-Origin
X-Sn-Servicetimems
IsBot
Ha-Gx-Prefs
Fastly-SSL
Gannett-Cam-Experience-Id
Gh-Request-Id
X-Slack-Shared-Secret-Outcome
X-Slack-Backend
Origin-Site
Powered-By
X-GoCache-CacheStatus
X-Sigma
Odigeo-Trace-Id
X-SIPLIST1
X-Sigma-Backend
NM-Fastcgi-Cache
X-AK-Request-ID
X-Origin-Expires
X-Epic-Correlation-Id
X-Eu-Site
X-Fastly-Backend
X-Ee-Request-Id
X-Ee-Request-Date
X-Internal-TTL
X-Ee-Generated-By
X-Ee-Origin
X-FC-Vary-Parameters
X-Fmm-Version
X-GeoIP-City
X-GeoIP-Country-Code
X-GeoIP-Region-Code
X-Hash
X-Gamma-Serve
X-Forwarded-Site
X-HS-Content-Campaign-Id
X-From
X-Dispatcher-Server
X-Depends
X-Mvc-Supplant-Cachable
X-CacheTTL
X-CGP
X-Cache-Aspx
X-Bug-Bounty
X-Old-Content-Length
X-Node-Id
X-NMSegId
X-Cms-Device
X-Micro-Cache
X-CUA
X-DefElseHash
X-DefHash
X-Csrf-Jwt
X-Core-Value
X-Contensis-Viewer-Groups
X-Men
X-Up
X-SD-PageType
CDN-CachedAt
CDN-EdgeStorageId
CDN-Cache
X-Varnish-CookieINHashed-On
Canary
CDN-PullZone
CDN-RequestCountryCode
Cdncip
CDN-Uid
CDN-RequestPullSuccess
CDN-RequestPullCode
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
X-VG-WebCache
X-Via-Fastly
X-URL
Sid
X-VG-TLSProxy
X-Vary-Devices
Apple-News-Services-Handled
X-Varnish-Director
X-Varnish-Hostname
X-Varnish-Remaining-TTL
Cdnsip
Apple-News-Services-Request-Url
Cluster
Country-Code
X-V-Cache
X-Varnish-Authentication
X-Varnish-CookieHashed-On
X-Varnish-Beresp-Status
X-NewRelic-App-Data
X-Parent-Response-Time
X-Cached-By
X-VC-TTL
X-NF-Request-ID
X-Cache-Date
X-Vercel-Id
X-Cache-Id
DSUID
X-Viewer-Country
X-Vmg-Version
X-Content-Length
X-Vercel-Cache
X-Level-Front-Cache
X-Thinkindot-L3
X-Mvc-Supplant-OutputCached
X-Thanos
CF-IPCountry
X-App-Name
X-Op-Id-All
X-Amz-Storage-Class
X-Thinkindot-L1
X-B3-Trace-ID
X-Bip
X-Date
X-VarnishDD-TTL
X-BBC-Edge-Cache-Status
X-Backend-Instance
X-Block-Status
X-Wikidot-Backend
X-Tx-Id
X-Frame-Option
X-Reqid
X-Render-Time
X-UA-Device-Type
X-Human
X-SB
X-Gdpr
X-HN
X-Gzip
X-Hnp-Log
X-Generated-On
X-Gen-Mode
X-Esi-Check
Cmstype
Fastly-Backend-Name
X-Jungle-Id
X-Akamai-Device-Characteristics
X-We-Are-Hiring
X-Debug-Cache-Store
X-Ion-Hop
X-Wikidot-Static-Cache
X-Edge-Server
Cmsid
X-Ec-Custom-Error
X-Ion-Healthy
X-DPWN-IS-SECURE
X-Debug-Cache-Fetch
X-Nyt-Route
X-Sucuri-Cache
L
Cdn-Host
RewriteTestHook
Content-Style-Type
RewriteTeamHook
CDCHOST
X-Request-URI
Tube-Get-Contents
Tube-Got-Eval
CacheControlHeader
Thinkindot-CacheControl-Type
TDXMobile
X-SVT-ORM-VERSION
Req-Svc-Chain
Cdn-Request-Time
Origin-CC
Origin-EX
Click-Count-Error
Cookie
Click-Count-Action-Start
Nord-Request-ID
PFcat
Pics-Label
Machine
Release
Producers
X-Shield-Cache-Expires
Platform
Content-Script-Type
Tube-Got-Results
Thinkindot-CacheControl
X-Pubstack
X-SVT-ORM-RULES
X-Proto
Azure-RegionName
X-Litespeed-Cache-Control
Tube-Return
X-Acquia-Purge-Cdn-Unconfigured
Azure-Version
Azure-SiteName
Azure-InstanceId
X-Region-Sid
User-Cache-Control
X-Accel-Expires-Debug
X-Uri
X-AB-Test
V-Age
X-Origin-Time
X-Path
Cache-Contol
Azure-SlotName
X-ZONE
X-Moov-Xdn-Version
Fastly-GeoIP-CountryCode
X-Via-Popn
X-Moov-Xdn-Caching-Status
X-Via-Poph
C-Via
X-Origin-Response-Time
X-Debug-Service
X-ElasticPress-Query
X-Nginx-Cache-Key
X-Via-Popv
X-Proxied-Request
X-Location
X-Datadome
X-Moov-T
Fastly-Drupal-HTML
X-Pad
True-Client-Country-4JS
X-NGINX-Cache
X-HA-Backend
X-Sucuri-ID
Server-Hostname
XM
Server-Ext
Sever-Int
X-Srv
X-AIR-PT
X-Webkit-CSP
X-Varnish-Hits
Show-Do-Not-Sell-Link
NGX
Traceparent
X-Cache-Backend
X-Refresh
X-Ez-Minify-Html
Debug
Server-ID
X-Unity-Cache
X-Air-Pt
X-APP
X-Fastly-Request-Id
X-Fpc
X-Nananana
HostName
X-Servedbyhost
GeoIp-Country-Code
GeoIP-Latitude
X-LB-ID
X-TH-Server
X-DynaTrace-JS-Agent
DataCenter
HA-Ipaddr
Product
WZWS-RAY
Cdn
Tcn
X-Zone
X-VCL-Version
AR-SID
X-AC
X-Amz-Meta-Cb-Modifiedtime
X-B3-Parentspanid
X-Nc
X-Wa
Lb
X-CDN-Provider
X-Nginx-Cache
Fastly-Drupal-Html
SID
X-Newrelic-Synthetics
Xkey-La3
X-Proxy-Cache-La3
X-Proxy-CacheR9
Xkeylog
Serverhost
A
XkeyR9
X-Cache-VC
X-GeoIP
X-Cdn-Forward
X-User
X-Litespeed-Tag
X-TX-ID
X-Vc
X-Datacenter
Edge-Cache
CountryCode
Cs
NtCoent-Length
X-RateLimit-Limit
Resin-Trace
X-Source
X-LB-NoCache
Cdn-Requestid
X-LiteSpeed-Tag
Esi-Enabled
X-Request-Start
X-API-Version
X-LiteSpeed-Cache-Control
X-TT-LOGID
X-Wormhole-Sdk
Akamai-Mon-Iucid-Del
MIME-Version
X-HubSpot-Correlation-Id
X-B3-Spanid
X-NC
X-Aspnet-Version
X-WA
X-Dynatrace-Js-Agent
X-VC-Age
X-ID
X-Service-Response-Time
Sm-Log-Id
CDN
X-Html-Minification-Powered-By
X-Udemy-Cache-App-Namespace
Content-Secure-Policy
X-Scheme
X-TIM-N
X-Styx-Origin-Id
Proxy-Firewall
Pramga
X-Styx-Info
X-HA-Device-Type
X-HA-Bot-Classification
Datacenter
Cr
Wsr-Cache
X-HA-Application-Name
Uri
X-Via-JSL
ServerHost
X-Lsadc-Cache
X-Srcache-Store-Status
X-Srcache-Fetch-Status
X-Fastly-Backend-Reqs
X-Ez-Minify-Js
X-Lb-Id
RATING
Hostname
X-FPC
Geoip-Latitude
Yjs-Id
X-TimeS
GeoIP-Country-Code
X-Var-Ttl
From-Cache
X-ServedByHost
X-Pool
X-NodeID
X-Stale
Server-Id
X-Request-Host
W
X-Wp-Cf-Super-Cache-Cache-Control
X-Wp-Cf-Super-Cache
X-Oracle-DMS-ECID
X-Aspnetmvc-Version
X-CACHE-KEY
Cloudfront-Viewer-Country
X-NODE
X-MSEdge-Flight
X-App
X-MSEdge-Features
X-Swift-Error
X-Lb-Nocache
X-Akamai-Pragma-Client-IP
X-Air-Source
X-Air-Trace-Id
X-Air-Hostname
X-Sorting-Hat-Shopid
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-LAGOON
X-RequestId
X-Shardid
X-Wp-Cf-Super-Cache-Active
X-Shopid
X-Sorting-Hat-Podid
X-Ramcache
X-ByteArk-Cache
X-Correlation-ID
X-DynaTrace
X-ByteArk-ReqID
X-Proxy-Cache-LA2
X-Vgn-Hpd-Reason
Ohc-Cache-HIT
X-Key
X-Cache-Grace
X-VServer
X-Ssense-Gql
X-Ssense-Shipping-Surcharge-Enabled
Ohc-File-Size
Surrogated-Key
T-Server
Srv
X-CS
X-Webkit-Csp-Report-Only
CF-Cached-On
X-Varnish-Beresp-TTL
X-Elasticpress-Query
Yak-Timeinfo
X-DataCenter
Cl-Cache
X-Cdn-Cache-Status
Ngx
X-Geo
X-CSRF-TOKEN
X-PageType
X-Sucuri-Id
X-Web-Server
Req-ID
Edge-Copy-Time
X-Via-Edge
X-Via-SSL
X-Via-CDN
X-Jobs
X-ATG-Version
Akamai-X-True-TTL
WebServer
X-DC
X-Ha-Backend
X-Th-Server
N1-Cache
X-Iplb-Instance
X-Iplb-Request-Id
X-Beacon
Warning
X-Via-PopN
X-Via-PopV
X-Via-PopH
X-Limited
X-MiniProfiler-Ids
My-App
X-Check-Cacheable
X-Env
Host-Name
X-Mg-Cache
X-Zen-Fury
X-Geolocation
User-Agent
X-Request-Url
X-Fastly-Cache-Status
Xkey-G-Jp