Threat Level: green Handler on Duty: Yee Ching Tok

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
X-Frame-Options
Expires
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Accept-CH
Last-Modified
CF-Cache-Status
ETag
X-XSS-Protection
Expect-CT
Accept-Ranges
CF-RAY
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Alt-Svc
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-Download-Options
X-Timer
X-Request-Id
X-Xss-Protection
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Cf-Request-Id
Access-Control-Allow-Credentials
Accept-CH-Lifetime
X-DNS-Prefetch-Control
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
Permissions-Policy
CF-Ray
Server-Timing
X-Drupal-Cache
X-Generator
X-Envoy-Upstream-Service-Time
X-Cache-Status
X-Ua-Compatible
X-Cacheable
X-FRAME-OPTIONS
X-Iinfo
X-Drupal-Dynamic-Cache
Timing-Allow-Origin
Feature-Policy
X-CONTENT-TYPE-OPTIONS
X-Content-Security-Policy
Xkey
Upgrade
X-CDN
Access-Control-Expose-Headers
Content-Encoding
X-XSS-PROTECTION
Status
X-AspNetMvc-Version
Accept-Ch
Access-Control-Max-Age
X-Request-ID
Host-Header
X-Amz-Request-Id
X-Age
X-Amz-Id-2
Request-Context
Cf-Edge-Cache
X-Backend
X-Robots-Tag
X-Hacker
X-Via
Cf-Apo-Via
Keep-Alive
X-Turbo-Charged-By
X-Amz-Version-Id
X-Rq
X-AH-Environment
X-Cache-Group
X-Vhost
X-Dispatcher
X-Server
X-Proxy-Cache
X-Ws-Request-Id
EagleId
X-UA-Device
CONTENT-SECURITY-POLICY
X-Varnish-Cache
X-OneAgent-JS-Injection
Pantheon-Trace-Id
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
Grace
P3p
X-Server-Powered-By
X-Pingback
Allow
X-Page-Speed
X-WebKit-CSP
X-Litespeed-Cache
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-Dns-Prefetch-Control
X-Node
X-FTR-Request-ID
X-Device
X-Server-Id
X-Host
X-Cache-Lookup
EagleEye-TraceId
X-Country-Code
X-Backend-Server
Surrogate-Control
X-LiteSpeed-Cache
X-Cloud-Trace-Context
X-Akam-SW-Version
X-Readtime
Cf-Railgun
X-Ruxit-JS-Agent
X-HW
X-Response-Time
Cache-Tag
X-Amz-Server-Side-Encryption
Content-Location
Cross-Origin-Opener-Policy
X-Rack-Cache
X-Nginx-Upstream-Cache-Status
X-Trace
Service-Worker-Allowed
X-Nginx-Cache-Status
X-TraceId
Request-Id
Fastly-Restarts
X-Content-Type
X-Application-Context
X-Clacks-Overhead
X-PC
X-Vname
X-TtlSet
X-Times
Rating
X-Ua-Device
X-Cnection
X-Country
X-Edge
X-Midtier
X-Mcache
X-ESI
X-Browser-Type
X-Country-Code-Real
X-FTR-Balancer
X-FTR-Backend-Server
X-FTR-Backend
X-Cache-TTL
X-FTR-Cache-Status
X-Vcap-Request-Id
X-FTR-Expires
Edge-Control
Origin-Trial
X-Ac
Accept-Ch-Lifetime
Surrogate-Key
X-FastCGI-Cache
X-Powered-By-Plesk
X-Nf-Request-Id
X-Element-Page-Cache
X-Cdn-Fetch
X-GoogleNews-Bot
X-Kinja-Build
X-Kinja-Revision
X-Kinja-Server
X-Exp-Variant
X-Kinja
X-D2id
X-Exp-Id
X-Abt-Application-Version
X-NWS-LOG-UUID
Verso
X-Upstream
X-B3-TraceId
X-Navigation-Version
X-Mod-Pagespeed
X-ORACLE-DMS-RID
X-Amz-Rid
Nginx-Cache
Display
X-GitHub-Request-Id
X-Middleton-Display
X-Sol
X-ECACHE
Pagespeed
X-Pinterest-Rid
Pinterest-Version
Pinterest-Generated-By
X-Language
X-Envoy-Decorator-Operation
Response
X-Middleton-Response
X-PDP-UNCACHING-HASH
X-Instrumentation
X-Server-Lifecycle-Phase
X-Erf-Bev-Bev-Is-Generated
X-Oneagent-Js-Injection
X-Erf-Bev-Bev
X-Kraken-Loop-Name
AR-Request-ID
AR-PoweredBy
AR-ATIME
S
X-Client-IP
Akamai-GRN
Edge-Cache-Tag
X-MS-InvokeApp
X-Url
X-Goog-Hash
X-Ratelimit-Limit
X-Edge-Location-Klb
X-Resp-Is-Stale
X-Kinsta-Cache
X-ARC
X-Distributor
X-Ser
SPRequestGuid
SPRequestDuration
SPIisLatency
X-SharePointHealthScore
X-Content-Digest
X-NGENIX-Cache
Front-End-Https
X-Ezoic-Cdn
Access-Control-Request-Method
X-Shield-Request-Id
X-Ttl
X-Dw-Request-Base-Id
X-Varnish-TTL
X-Recruiting
X-Cache-Key
RTSS
X-Amzn-Trace-Id
X-Ruxit-Js-Agent
Cache-Status
X-Version
X-Powered-CMS
Public-Key-Pins
X-Mg-S
X-T
TP-Cache
X-MSEdge-Ref
Fastcgi-Cache
X-Accel-Expires
Arr-Disable-Session-Affinity
X-HS-Content-Id
X-HS-Hub-Id
X-HS-Cache-Config
X-Daa-Tunnel
X-Ismobilevalue
Cache-Tags
X-Cluster-Name
X-Correlation-Id
AR-CACHE
X-Cached
X-Forwarded-For
X-Id
Realpath
X-Fastly-Request-ID
X-Request-Received
X-Request-Processing-Time
X-Content-Security-Policy-Report-Only
X-Ua-Browser
X-HS-Combine-CSS
X-Kong-Upstream-Latency
Payment
Content-MD5
X-Kong-Proxy-Latency
X-Newrelic-App-Data
X-DIS-Request-ID
X-RateLimit-Remaining
X-GUploader-UploadID
X-Cambria-Cache-Control
X-Jurisdiction
X-HP-Webp
X-HP-Trace-Id
X-HS-Prerendered
X-HS-CF-Cache-Status
X-Xrds-Location
X-Azure-Ref
Content-Disposition
X-CST
X-Amz-Replication-Status
X-Webkit-Csp
X-SERVER-NAME
Count-Hit
X-Ratelimit-Remaining
YJS-ID
X-Server-Name
Ar-SID
X-TTL
X-Px
X-Unique-Id
X-Origin-Server
Cleartype
X-Ratelimit-Reset
Cross-Origin-Embedder-Policy
X-Page-Id
X-ORACLE-DMS-ECID
X-SRCache-Store-Status
X-Protected-By
X-SRCache-Fetch-Status
Cross-Origin-Resource-Policy
X-FB-Debug
X-Rid
X-VARITI-CCR
X-Activity-Id
Accept-Charset
X-AppVersion
X-Az
X-Proxy
X-Git-Hash
X-Logged-In
X-LLID
X-Www-Served-By
X-Request-Handler-Origin-Region
X-Request-Device-Id
X-Goog-Metageneration
X-Microsite
X-Load-Cache
X-Amz-Meta-S3cmd-Attrs
X-Template
MicrosoftSharePointTeamServices
X-Varnish-Backend
Version
X-Forwarded-Proto
X-Hits
X-PressLabs-Stats
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Geo-Country
Server-Node
X-Upgrade-Enabled
Server-Name
X-COUNTRY
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Hostname
X-Meli-Trace-Bu
X-Meli-Trace-Site
X-Meli-Trace-Platform
X-B3-Sampled
X-Content-Options
X-Frontend
Viewport
X-Varnish-Grace
Section-Io-Cache
X-URL
X-App-Server
X-TT
X-B3-TraceId-Primal
X-Grace
AKAMAI-GRN
Mrf-Cache-Status
X-Fb-Rlafr
MRF-Tech
X-WebKit-CSP-Report-Only
Fastly-SWR
X-Device-Type
Access-Control-Allow-Method
Fastly-SIE
X-Status
Alternate-Protocol
X-B
X-Varnish-Server
Healthy
TCN
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-Request-Guid
Upgrade-Insecure-Requests
Host
X-Magnolia-Registration
DC
X-CSRF-Token
X-EdgeConnect-Cache-Status
X-Tt-Trace-Host
X-Tt-Trace-Tag
Amp-Access-Control-Allow-Source-Origin
X-Amzn-Remapped-Content-Length
X-Cache-Age
X-Contextid
Retry-After
X-Buckets
X-Cache-Control
MS-Author-Via
X-Debug
X-Revision
X-Type
X-Tec-Api-Version
X-Varnish-Ttl
X-Tec-Api-Origin
X-Tec-Api-Root
X-App-Version
X-WP-CF-Super-Cache
SD-X-WS
X-WP-CF-Super-Cache-Cache-Control
X-Instance
X-Original-Request-Id
X-Seen-By
X-Response-Served-From
X-Yottaa-Metrics
X-UUID
X-Yottaa-Optimizations
X-Hl-Ver
X-Akamai-Edgescape
X-Adobe-Content
X-N
X-ProcessESI
X-RemovedCookies
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Tumblr-User
X-Adobe-Loc
X-Origin-CC
X-Origin-TTL
X-Lambda-Id
X-NYM-Debug-Backend
X-INCAP-ABP
X-Backend-Name
X-Rendered-As
X-Vcl-Version
Access-Control-Request-Headers
X-Debug-IsPreview
X-Akamai-Request-ID2
Frame-Options
X-Debug-IsConnected
X-G
Section-Io-Id
X-Is-Bot
Cross-Origin-Embedder-Policy-Report-Only
X-Framework
X-Storage
X-Mg-Request-UUID
Charset
Cross-Origin-Opener-Policy-Report-Only
X-ServerID
X-Mobile
X-RM-Cache-TTL
X-Server-W
X-Oracle-Dms-Ecid
X-Trace-Id
X-AB
X-RTag
Ms-Operation-Id
MS-CV
X-DataDome
X-Cache-Status-Check
X-Content-Powered-By
X-Dc
X-Request-Site
X-Request-Bu
VIX-Pulpo-Node
NGB
X-Request-Platform
VIX-Pulpo-Upstream-Status
X-Cache-Hit
X-Requestid
X-NF-Request-ID
Cache
Accept-Language
X-Cache-Time
Filterid
Refresh
Webserver
AR-SID
X-Time
X-Wormhole-Sdk
X-Region
Paypal-Debug-Id
X-Real-IP
X-Node-Name
Onion-Location
X-Ms-Version
X-Ms-Request-Id
SRV
X-B3-SpanId
X-VC-Cache
X-HITS
X-ECache
X-Hcs-Proxy-Type
X-CCDN-Origin-Time
X-User-Agent
X-CCDN-CacheTTL
CDN-RequestId
X-F-Cache
Protected
Cross-Origin-Window-Policy
X-Cache-Expired-At
X-Pass-Why
Liferay-Portal
X-Rocket-Nginx-Serving-Static
X-IPS-LoggedIn
X-Datadog-Sampled
X-Datadog-Parent-Id
X-Datadog-Trace-Id
X-LB-Cache
Priority
X-Whom
Xet-Cookie
X-Datadog-Sampling-Priority
X-HTML-Minification-Powered-By
X-Mode
Backend
X-Yandex-Req-Id
X-Environment-Context
X-Fastcgi-Cache
X-L-Path
GEO-INFO
X-WP-CF-Super-Cache-Active
X-Service
OT-Force-Account-Verify
X-Tb
X-Proxy-Cache-Info
X-Rule
X-Handled-By
Country
X-App-Environment
Webcakes-App-Name
X-Browser-Name
Webcakes-App-Version
X-Zipkin-Id
Web-Mar-Node
X-Adobe-Source
Webcakes-Region
TWC-GeoIP-Region
TWC-Connection-Speed
TWC-Device-Class
Property-Id
X-Servername
Filters
X-Vcache
TWC-GeoIP-City
TWC-GeoIP-Country
TWC-Locale-Group
TWC-Privacy
TWC-GeoIP-LatLong
X-Wix-Request-Id
TWC-GeoIP-DMA
Url
X-FB-TRIP-ID
X-SaId
X-Drupal-Cache-Tags
X-Loop
X-UPSTREAM-Address
X-JoinUs
X-Origin-Hint
X-Proxied
X-Routing-Service
X-Cacheable-TTL
X-Rn-Rsrv
X-Rewrite-Enabled
LB
X-Is-Tablet
X-Is-Supported-Browser
ServerID
Meta-Geo
X-Extlb
X-Tcp-Rtt
X-Cloudmap
X-Tncms
X-Geo-Region
X-Is-Desktop
X-Is-Mobile
Atl-Traceid
X-Skip-Cache
DB-Nickname
X-Tumblr-Pixel-2
X-Cache-Action
X-Hosted-By
X-Hit
X-Generation-Time
X-Httpd
X-Locale
X-Redis-Cache
X-MP-GENERATED-AT
X-Logging-Id
X-Forwarded-Host
X-Format
X-Cache-Host
X-Tumblr-Pixel-3
Uber-Trace-Id
X-Cdn-Origin
X-Detected-As
X-Fetched-On
X-Director
Mn-Server-Ip
X-Soup
X-Varnish-Beresp-Grace
ServedBy
X-Origin-Date
Environment
X-Web-Node
X-Shopify-Stage
X-Cms-Context
Expiry
X-SayCDN-TTL
X-Scope-Id
Locale
X-Connection-Hash
X-Debug-Info
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Restarts
YJS-CacheStatus
X-Say-Cacheable
X-IPLB-Instance
X-Edge-Location
X-Endurance-Cache-Level
X-Say-TTL
X-Alternate-Cache-Key
X-Storefront-Renderer-Rendered
X-XRDS-Location
X-Urbn-Context-Path
X-IPLB-Request-ID
X-Urbn-Site-Id
X-Auth-Group-Type
X-PHP-Host
Cache-Hits
X-Timing-Wait
X-Proxy-Build
X-FW-Dynamic
X-ProxyCache-Status
Apigw-Requestid
X-FW-Hash
X-Cluster-Node
X-Labrador-Cache-Channel
X-BYPASS-REASON
X-Cluster
X-Is-Modern-Browser
X-FW-Version
X-FW-Serve
X-FW-Server
X-FW-Static
X-FW-Type
X-S
X-ProxyCache-Key
Fastcgi-Useragent
Selected-Fe
X-RCS-CacheZone
X-Served-From
X-Drupal-Cache-Contexts
X-Origin
X-Origin-Cache
X-Mly-Id
X-VCT
X-VC
X-No-Session
X-R9-Blue-Green-Version
X-Server-ID
X-Cache-Debug
X-GEO
X-Sorting-Hat-PodId
X-NewRelic-App-Data
X-ShardId
X-ShopId
X-Provided-By
X-Sorting-Hat-ShopId
X-Is-Mobile-Only
X-Api-Version
Front
X-Varnish-Age
X-SRV
X-Varnish-Cache-Hits
X-UA
X-CLOUD-TRACE-CONTEXT
Xserver
Node
X-Lagoon
Cache-Tv-Group
X-WP-CF-Super-Cache-Cookies-Bypass
Countrycode
X-Platform
X-Generated-By
X-CDN-Cache-Status
WPO-Cache-Status
X-CDN-Forward
X-Presslabs-Stats
X-Varnish-Beresp-Ttl
X-Site-Version
X-Webstats-RespID
X-B3-Traceid
Referer-Policy
X-Fastly-Request-Id
From-Origin
Cache-Provider
X-Source
X-Azure-Ref-OriginShield
X-CACHE-AGE
X-NWS-UUID-VERIFY
X-Signature
X-Accel-Version
X-B-Cache
X-Tt-Logid
X-Optimistic-Header
X-TA-CDN-Provider
X-VC-TTL
X-Ua
Request-ID
X-PHP-Backend
Location
X-Xfnlog-Site
X-Cache-Rule
X-Cache-Operation
AMP-Access-Control-Allow-Source-Origin
CF-IPCountry
X-Sucuri-Cache
X-Worker
X-Tx-Id
X-Tb-Optimization-Total-Bytes-Saved
CDN-EdgeStorageId
CDN-RequestCountryCode
CDN-RequestPullCode
CDN-PullZone
CDN-CachedAt
CDN-Cache
CDN-RequestPullSuccess
CDN-Uid
WPO-Cache-Message
X-A-Wwc
Wxu-Next-Hostname
X-Access
X-Action
X-Aed
Wxu-Next-Region
X-A-Dcw
X-AK-Request-ID
X-A-Dam
X-A-Ccd
X-A
X-A-Dgt
X-BCube-Filmed-By
X-Clientip
X-Cache-NE
X-Cms-Device
X-Conf
X-Contensis-Viewer-Groups
X-Cache-Aspx
X-Bl-Debug
X-Application
X-Auto-Login
X-B-Cookie
Wxu-Next-Commit
X-ApacheServer
Rendered-Blocks
Fastly-SSL
Expect-Staple
Fl-Custom-Application
Host-ID
IsBot
DCR-Processing-Time-Ms
DCR-Decision-By
Candidate-Md5Url
Cdncip
Cdnsip
Cluster
Lang
Log-Origin
X-Content-Age
Redirect-Candidate
Sslversion
Store-Cloud-Cache
Time-Cloud-Cache
Origin
Odigeo-Trace-Id
MD5-Digest
Meta-Geo-Continent
N-Cache
Ngx.Var.Host
Web-Mar-Region
X-Ec-Fail
X-Sigma
X-Section
X-Sigma-Backend
X-SIPLIST1
X-Slack-Backend
X-SD-PageType
X-ScT
X-Rocket-Build-Number
X-Rojux
X-S-Cookie
X-Save-Cache
X-Slack-Shared-Secret-Outcome
X-SRCache-Key
X-VG-WebCache
X-VG-TLSProxy
X-Viewer-Country
X-Vtex-Remote-Cache
Xc-Version
X-Vdms-Version
X-Vary-Devices
X-V-Cache
X-Varnish-Authentication
X-Varnish-Director
X-Varnish-Hostname
X-Request-URI
X-PERF
X-Ee-Request-Date
X-Ee-Origin
X-Ee-Request-Id
X-External-Request-Id
X-Forwarded-Site
X-Ee-Generated-By
X-Ec-GeoHdr
X-D
X-Depends
X-Destination
Apple-News-Services-Request-Url
X-GeoCode
X-GeoCountry
X-Node-Id
X-Micro-Cache
X-Org
X-Origin-Expires
X-PAYTM-SRV-ID
X-Loc
X-Ig-Push-State
X-GeoIP-City
X-Hash
X-HS-Content-Campaign-Id
X-Ig-Origin-Region
X-Core-Value
X-Developer
Apple-News-Services-Handled
Apple-News-Services-Host
X-IsAdmin
Apple-News-Services-Parsed-Url
X-VWS-Id
X-Reqid
X-AWS-Id
X-Litespeed-Cache-Control
X-Sucuri-ID
X-LJ-Flow-ID
X-Air-Pt
X-Fastly-Backend
X-From
X-Fmm-Version
X-Human
X-Internal-TTL
X-Epic-Correlation-Id
X-Gamma-Serve
X-Gdpr
X-Ec-Custom-Error
X-GeoIP-Region-Code
X-GoCache-CacheStatus
X-HN
X-Generated-On
X-GeoIP-Country-Code
X-DefElseHash
X-App-Name
X-Backend-Instance
X-Bc-Bl
X-Amz-Storage-Class
X-Akamai-Device-Characteristics
X-AB-Test
X-Accel-Expires-Debug
X-Aicache-OS
X-Cache-Date
X-Content-Length
X-Ion-Healthy
X-DefHash
X-LSADC-Cache
X-Debug-Cache-Store
X-Debug-Cache-Fetch
X-CUA
X-Date
X-Dispatcher-Server
X-Level-Front-Cache
XM
Gh-Request-Id
Ha-Gx-Prefs
X-Frame-Option
X-We-Are-Hiring
X-Varnish-Remaining-TTL
X-VarnishDD-TTL
X-Vmg-Version
L5d-Success-Class
Pragrma
X-Policy
X-Pubstack
X-Varnish-Beresp-Status
X-FC-Vary-Parameters
X-Eu-Site
X-Bug-Bounty
X-CGP
X-Csrf-Jwt
X-Varnish-CookieINHashed-On
X-Varnish-CookieHashed-On
Azure-InstanceId
X-NMSegId
X-Nyt-Route
X-Moov-Xdn-Caching-Status
X-Moov-T
X-Jungle-Id
V-Age
X-Men
X-Old-Content-Length
X-Op-Id-All
X-Sn-Servicetimems
X-Thinkindot-L1
X-Thinkindot-L3
X-Shield-Cache-Expires
X-Req
X-Origin-Time
X-Path
X-Region-Sid
X-Ion-Hop
X-Moov-Xdn-Version
RNT-Time
NM-Fastcgi-Cache
Azure-SiteName
RNT-Machine
PFcat
TDXMobile
Source
Azure-RegionName
Nord-Request-ID
Origin-Agent-Cluster
Origin-CC
Server-Host
Content-Script-Type
Content-Style-Type
ServerName
Origin-Site
Origin-EX
Thinkindot-CacheControl
Release
Azure-Version
Thinkindot-CacheControl-Type
Cache-Contol
L
Gannett-Cam-Experience-Id
DSUID
RewriteTeamHook
RewriteTestHook
Azure-SlotName
X-NGINX-Cache
S-Rt
Req-Svc-Chain
Cmstype
X-Vercel-Id
Producers
X-DPWN-IS-SECURE
X-Via-Fastly
Powered-By
X-Edge-Server
Platform
X-TT-LOGID
X-Server-IP
Machine
X-SVT-ORM-RULES
X-Location
X-SB
Fastly-Backend-Name
Fastly-GeoIP-CountryCode
X-Render-Time
X-Hnp-Log
X-SVT-ORM-VERSION
X-Up
X-Gen-Mode
X-Uri
X-UA-Device-Type
Country-Code
X-Gzip
X-Thanos
X-Esi-Check
X-Vercel-Cache
Cdn-Request-Time
Cdn-Host
Sid
Canary
X-BBC-Edge-Cache-Status
X-Bip
X-Wikidot-Static-Cache
CDCHOST
X-Acquia-Purge-Cdn-Unconfigured
User-Cache-Control
X-Mvc-Supplant-Cachable
C-Via
X-CacheTTL
We-Hiring
CacheControlHeader
X-Block-Status
Mail-Subject
X-Proto
X-Cache-Id
X-Wikidot-Backend
Cmsid
X-Upstream-Ct
X-Parent-Response-Time
X-Upstream-Ht
Tube-Got-Eval
Tube-Got-Results
Tube-Return
X-Mvc-Supplant-OutputCached
Click-Count-Error
Click-Count-Action-Start
X-B3-Trace-ID
X-Origin-Response-Time
X-Cache-FS-Status
X-ElasticPress-Query
X-Proxied-Request
Vix-Hermes-Req-Id
Tube-Get-Contents
X-Pad
X-ZONE
Fastly-Drupal-HTML
X-Cs
X-ND-Cache
CloudFront-Viewer-Country
NGX
X-Refresh
Debug
Pics-Label
X-Cached-By
X-TH-Server
X-Nananana
Mime-Version
Product
X-APP
X-Varnish-Hits
X-FORWARDED-FOR
X-Via-Popv
GeoIp-Country-Code
HA-Ipaddr
Cookie
X-Amz-Meta-Cb-Modifiedtime
GeoIP-Latitude
X-Litespeed-Tag
X-Via-Poph
X-Via-Popn
X-Client-Ip
X-Cdn-Forward
X-Servedbyhost
X-Cache-VC
X-HA-Backend
X-Datadome
X-DynaTrace-JS-Agent
X-GeoIP
Edge-Cache
Server-ID
X-User
X-AIR-PT
X-Webkit-CSP
X-Nginx-Cache-Key
MIME-Version
X-Debug-Service
X-Srv
X-Wa
X-LB-ID
DataCenter
X-Fpc
X-Nc
X-B3-Parentspanid
True-Client-Country-4JS
Load-Balancing
Fastly-Drupal-Html
WZWS-RAY
X-Zone
Resin-Trace
HostName
X-LB-NoCache
Server-Ext
Server-Hostname
Sever-Int
Show-Do-Not-Sell-Link
Akamai-Mon-Iucid-Del
X-Unity-Cache
SID
Cdn
X-B3-Spanid
X-Nginx-Cache
X-Scheme
X-Request-Start
X-RateLimit-Limit
X-Cache-Backend
Traceparent
X-Vc
X-Newrelic-Synthetics
Surrogated-Key
Tcn
X-Lsadc-Cache
X-VCL-Version
Sm-Log-Id
X-CS
Wsr-Cache
Lb
X-Service-Response-Time
X-Pool
X-Request-Host
Yjs-Id
X-NodeID
X-RequestId
X-HOST
N1-Cache
X-Vgn-Hpd-Reason
X-Cache-Grace
X-TX-ID
X-CDN-Provider
NtCoent-Length
X-Datacenter
X-LiteSpeed-Cache-Control
X-Ez-Minify-Html
X-Proxy-Cache-La3
Hostname
X-DataCenter
Serverhost
XkeyR9
Xkey-La3
Yak-Timeinfo
CDN
X-DynaTrace
X-Proxy-CacheR9
Xkeylog
X-LiteSpeed-Tag
X-HubSpot-Correlation-Id
A
Edge-Copy-Time
X-FPC
X-WA
X-Via-SSL
X-Via-Edge
X-Udemy-Cache-App-Namespace
Datacenter
X-Via-CDN
Cdn-Requestid
CountryCode
X-API-Version
X-Lb-Id
X-Geolocation
X-NC
X-ID
X-Fastly-Backend-Reqs
Server-Id
X-Zen-Fury
X-Jobs
X-Akamai-Pragma-Client-IP
X-Air-Hostname
X-Dynatrace-Js-Agent
X-Air-Trace-Id
Cs
X-Air-Source
Esi-Enabled
X-Stale
X-Via-JSL
Uri
X-Html-Minification-Powered-By
True-Client-IP
Srv
Req-ID
X-Varnish-Beresp-TTL
Geoip-Latitude
ServerHost
On-Server
RATING
X-TimeS
X-Srcache-Store-Status
X-Srcache-Fetch-Status
Proxy-Firewall
X-VC-Age
WP-Super-Cache
GeoIP-Country-Code
T-Server
X-Cdn-Srv
X-Ez-Minify-Js
X-VTEX-Cache-Time
X-Swift-Error
Pramga
X-HA-Application-Name
X-Lb-Nocache
X-VTEX-Cache-Server
X-Ha-Backend
From-Cache
X-ServedByHost
X-HA-Bot-Classification
Cr
X-Styx-Origin-Id
X-Powered-By-VTEX-Cache
X-Styx-Info
X-HA-Device-Type
X-Oracle-DMS-ECID
X-MSEdge-Features
X-Var-Ttl
X-MSEdge-Flight
X-TIM-N
X-App
Cloudfront-Viewer-Country
X-CSRF-TOKEN
Content-Secure-Policy
X-CACHE-KEY
X-Wp-Cf-Super-Cache
X-Wp-Cf-Super-Cache-Cache-Control
X-LAGOON
W
X-Ssense-Shipping-Surcharge-Enabled
X-Correlation-ID
X-Ssense-Gql
X-Fastly-Cache
Coldstone-Viewer-Country-Region-Name
Coldstone-Viewer-Country
Coldstone-Viewer-Currency
X-Via-PopN
X-Via-PopV
Ngx
X-Via-PopH
X-WA-Info
FSS-Cache
X-Wp-Cf-Super-Cache-Cookies-Bypass
WebServer
X-Wp-Cf-Super-Cache-Active
X-Geo
X-Sorting-Hat-Shopid
X-Proxy-Cache-LA2
X-Check-Cacheable
Cl-Cache
X-Ramcache
X-Sorting-Hat-Podid
X-Web-Server
X-Elasticpress-Query
X-Shopid
X-Cdn-Cache-Status
X-Webkit-Csp-Report-Only
X-Shardid
X-Request-Url
X-Serial
X-Th-Server
Akamai-X-True-TTL
X-DC
X-Sucuri-Id
BehaviorPad-Version
X-ATG-Version
Cf-Ipcountry
Xkey-G-Jp
X-Cache-TTL-Remaining
Ohc-Cache-HIT
X-Key
URI
X-VServer
Ohc-File-Size
X-Request-Time
X-Fastly-Cache-Hits
X-Fastly-Cache-Status
X-Mg-Cache
FSS-Proxy
Cneonction
User-Agent
X-Env
Host-Name