Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
X-Frame-Options
Expires
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Accept-CH
Last-Modified
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
X-XSS-Protection
X-Powered-By
Pragma
X-Cache
Via
CF-RAY
Age
Content-Security-Policy
Alt-Svc
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
X-Amz-Cf-Pop
X-Amz-Cf-Id
Content-Language
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-Download-Options
X-Xss-Protection
X-Request-Id
X-Timer
Access-Control-Allow-Headers
CF-Ray
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
Accept-CH-Lifetime
X-DNS-Prefetch-Control
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
Permissions-Policy
X-Drupal-Cache
Server-Timing
X-Generator
X-Envoy-Upstream-Service-Time
X-Cache-Status
X-FRAME-OPTIONS
X-Cacheable
X-Ua-Compatible
X-Iinfo
X-Drupal-Dynamic-Cache
Timing-Allow-Origin
X-CONTENT-TYPE-OPTIONS
Accept-Ch
Feature-Policy
X-Content-Security-Policy
Xkey
X-XSS-PROTECTION
Upgrade
Access-Control-Expose-Headers
X-CDN
Content-Encoding
Status
X-AspNetMvc-Version
Access-Control-Max-Age
X-Amz-Request-Id
X-Amz-Id-2
Host-Header
X-Age
Request-Context
X-Backend
Cf-Edge-Cache
X-Amz-Version-Id
X-Robots-Tag
X-Hacker
Keep-Alive
X-Via
Cf-Apo-Via
X-Turbo-Charged-By
X-AH-Environment
X-Rq
X-Vhost
X-Server
X-Cache-Group
X-Dispatcher
X-Proxy-Cache
CONTENT-SECURITY-POLICY
X-Request-ID
X-Ws-Request-Id
EagleId
X-UA-Device
X-Varnish-Cache
Pantheon-Trace-Id
Grace
X-Litespeed-Cache
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Server-Powered-By
X-OneAgent-JS-Injection
X-WebKit-CSP
X-Pingback
X-Dns-Prefetch-Control
X-Page-Speed
Allow
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-Cache-Lookup
X-FTR-Request-ID
X-Device
X-Node
X-Host
X-Server-Id
EagleEye-TraceId
X-Backend-Server
X-Country-Code
Surrogate-Control
X-Cloud-Trace-Context
X-Ruxit-JS-Agent
Cf-Railgun
X-Readtime
X-Akam-SW-Version
X-HW
X-Response-Time
P3p
Cache-Tag
X-Amz-Server-Side-Encryption
X-LiteSpeed-Cache
Content-Location
X-Ua-Device
Cross-Origin-Opener-Policy
Accept-Ch-Lifetime
X-Content-Type
X-Nginx-Cache-Status
X-Nginx-Upstream-Cache-Status
X-Rack-Cache
Request-Id
Service-Worker-Allowed
X-Trace
X-TraceId
X-Application-Context
Fastly-Restarts
X-Nf-Request-Id
X-Times
X-Vname
X-TtlSet
X-PC
X-Element-Page-Cache
Rating
X-Clacks-Overhead
X-D2id
X-Cnection
X-Oneagent-Js-Injection
X-Edge
X-Midtier
X-Mcache
X-Country
X-Country-Code-Real
X-FTR-Backend-Server
X-FTR-Backend
X-Vcap-Request-Id
X-FTR-Cache-Status
X-FTR-Balancer
X-Browser-Type
Origin-Trial
X-FTR-Expires
Edge-Control
X-ESI
X-Cache-TTL
X-Navigation-Version
X-FastCGI-Cache
Surrogate-Key
X-NWS-LOG-UUID
X-Exp-Variant
X-GoogleNews-Bot
X-Exp-Id
X-Cdn-Fetch
X-Kinja-Build
X-Kinja
X-Kinja-Server
X-Kinja-Revision
X-Powered-By-Plesk
X-Ac
X-Abt-Application-Version
X-Url
X-Upstream
X-Mod-Pagespeed
Verso
X-Amz-Rid
X-ORACLE-DMS-RID
X-B3-TraceId
X-Language
X-ECACHE
Akamai-GRN
Nginx-Cache
Pinterest-Generated-By
Pinterest-Version
X-Pinterest-Rid
X-GitHub-Request-Id
Pagespeed
Display
X-Middleton-Display
X-Sol
X-MS-InvokeApp
S
X-Erf-Bev-Bev
X-Instrumentation
X-Erf-Bev-Bev-Is-Generated
X-Server-Lifecycle-Phase
X-PDP-UNCACHING-HASH
X-Kraken-Loop-Name
X-Envoy-Decorator-Operation
Response
AR-ATIME
AR-Request-ID
AR-PoweredBy
X-Middleton-Response
Edge-Cache-Tag
X-Amzn-Trace-Id
X-Distributor
X-Goog-Hash
SPRequestDuration
SPRequestGuid
SPIisLatency
X-Ratelimit-Limit
X-SharePointHealthScore
X-Resp-Is-Stale
X-Ser
X-T
X-Edge-Location-Klb
X-Kinsta-Cache
X-ARC
X-Request-Device-Id
Access-Control-Request-Method
X-NGENIX-Cache
Front-End-Https
X-Shield-Request-Id
X-Client-IP
X-Dw-Request-Base-Id
X-Ruxit-Js-Agent
X-Content-Digest
X-Ttl
X-Ezoic-Cdn
X-Recruiting
RTSS
X-Cache-Key
Cache-Status
X-Meli-Trace-Bu
X-Meli-Trace-Platform
X-Meli-Trace-Site
X-Version
X-Varnish-TTL
X-Mg-S
X-Request-Processing-Time
X-Request-Received
X-Powered-CMS
TP-Cache
X-HS-Hub-Id
X-Ismobilevalue
X-HS-Content-Id
X-HS-Cache-Config
Public-Key-Pins
X-MSEdge-Ref
Fastcgi-Cache
X-Accel-Expires
AR-CACHE
Arr-Disable-Session-Affinity
Cache-Tags
X-Daa-Tunnel
X-Cached
Ar-SID
X-Cluster-Name
X-Correlation-Id
YJS-ID
Realpath
X-Id
Content-MD5
X-Content-Security-Policy-Report-Only
X-Amz-Replication-Status
X-Newrelic-App-Data
X-HS-Combine-CSS
X-RateLimit-Remaining
X-Fastly-Request-ID
X-Ua-Browser
Payment
X-Azure-Ref
X-Forwarded-For
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-HP-Trace-Id
X-Cambria-Cache-Control
X-HP-Webp
X-Jurisdiction
X-Xrds-Location
X-DIS-Request-ID
X-Server-Name
X-HS-CF-Cache-Status
X-HS-Prerendered
X-GUploader-UploadID
Content-Disposition
MicrosoftSharePointTeamServices
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-TTL
X-Protected-By
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Px
Count-Hit
X-ORACLE-DMS-ECID
X-Ratelimit-Reset
X-Az
X-Activity-Id
X-Origin-Server
X-AppVersion
X-Unique-Id
X-Page-Id
X-Rid
X-Logged-In
Cross-Origin-Resource-Policy
Accept-Charset
X-Git-Hash
Cleartype
X-Amz-Meta-S3cmd-Attrs
X-Ratelimit-Remaining
X-VARITI-CCR
Cross-Origin-Embedder-Policy
X-FB-Debug
X-Proxy
X-Request-Handler-Origin-Region
X-Microsite
X-TEC-API-ROOT
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-Www-Served-By
X-Load-Cache
Version
X-COUNTRY
X-Hits
X-LLID
X-Webkit-Csp
X-Geo-Country
X-Goog-Metageneration
X-Forwarded-Proto
X-Template
X-Varnish-Backend
X-PressLabs-Stats
X-Upgrade-Enabled
X-SERVER-NAME
Server-Node
X-WebKit-CSP-Report-Only
X-B3-Sampled
Server-Name
X-Hostname
X-App-Server
Healthy
X-Content-Options
Access-Control-Allow-Method
X-Frontend
Section-Io-Cache
Viewport
X-Varnish-Grace
X-Grace
X-Device-Type
X-CST
X-TT
X-Fb-Rlafr
Fastly-SIE
Fastly-SWR
X-B
X-Varnish-Server
AKAMAI-GRN
Alternate-Protocol
X-Request-Guid
MRF-Tech
X-B3-TraceId-Primal
Mrf-Cache-Status
X-Contextid
X-Requestid
X-Status
X-Cache-Age
X-Goog-Storage-Class
X-Goog-Generation
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
DC
TCN
X-RemovedCookies
X-ProcessESI
Upgrade-Insecure-Requests
X-Magnolia-Registration
Retry-After
X-Varnish-Ttl
X-Amzn-Remapped-Content-Length
X-EdgeConnect-Cache-Status
X-Hl-Ver
Host
X-CSRF-Token
MS-Author-Via
X-App-Version
X-Cache-Control
Frame-Options
X-Type
X-Response-Served-From
Amp-Access-Control-Allow-Source-Origin
X-Revision
X-Origin-TTL
X-Origin-CC
X-Original-Request-Id
X-Buckets
SD-X-WS
X-Tt-Trace-Tag
X-Debug
X-Tt-Trace-Host
X-Yandex-Req-Id
X-Mobile
X-INCAP-ABP
X-G
X-UUID
VIX-Pulpo-Upstream-Status
X-Instance
X-ServerID
X-Backend-Name
VIX-Pulpo-Node
X-Seen-By
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Tumblr-User
X-Tumblr-Pixel-1
X-Oracle-Dms-Ecid
X-Yottaa-Optimizations
X-N
X-Adobe-Content
X-Adobe-Loc
X-Yottaa-Metrics
X-Is-Bot
X-Akamai-Edgescape
Cross-Origin-Opener-Policy-Report-Only
Cross-Origin-Embedder-Policy-Report-Only
X-NYM-Debug-Backend
X-Lambda-Id
X-Rendered-As
X-Cache-Status-Check
NGB
X-Akamai-Request-ID2
X-Content-Powered-By
X-RTag
Ms-Operation-Id
MS-CV
X-WP-CF-Super-Cache-Cache-Control
X-Framework
Section-Io-Id
Access-Control-Request-Headers
X-AB
X-Trace-Id
X-Mg-Request-UUID
X-WP-CF-Super-Cache
X-Debug-IsConnected
X-Debug-IsPreview
Cache
X-RM-Cache-TTL
X-Server-W
X-Storage
Charset
X-Dc
Webserver
X-Vcl-Version
Xet-Cookie
Filterid
Paypal-Debug-Id
X-DataDome
YJS-CacheStatus
Accept-Language
X-VC-Cache
Onion-Location
X-Ms-Request-Id
X-Ms-Version
Refresh
X-Cache-Time
X-B3-SpanId
X-Cache-Hit
X-ECache
SRV
X-User-Agent
X-Tec-Api-Origin
X-Tec-Api-Root
X-Tec-Api-Version
X-Fastcgi-Cache
X-Request-Site
X-Proxy-Build
X-Request-Bu
X-Request-Platform
X-F-Cache
X-Timing-Wait
Selected-Fe
X-Time
X-Node-Name
X-ProxyCache-Key
X-Region
X-BYPASS-REASON
X-ProxyCache-Status
X-Cacheable-TTL
X-Real-IP
X-VC
Liferay-Portal
X-CCDN-CacheTTL
Priority
X-Hcs-Proxy-Type
X-CCDN-Origin-Time
GEO-INFO
X-Mode
X-Environment-Context
CDN-RequestId
X-HTML-Minification-Powered-By
X-Origin-Cache
X-L-Path
X-Service
X-IPS-LoggedIn
Apigw-Requestid
Backend
X-LB-Cache
X-Rule
X-Tb
X-Server-ID
X-Rocket-Nginx-Serving-Static
X-HITS
X-Pass-Why
Country
X-Datadog-Sampled
Cross-Origin-Window-Policy
X-VCT
Meta-Geo
X-UPSTREAM-Address
X-JoinUs
X-Cache-Expired-At
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
X-SaId
X-Rn-Rsrv
X-Rewrite-Enabled
X-Origin
X-Drupal-Cache-Tags
X-Wix-Request-Id
X-Tcp-Rtt
X-Handled-By
X-Is-Modern-Browser
X-Is-Desktop
X-Adobe-Source
X-Is-Mobile
X-Is-Mobile-Only
X-Is-Tablet
X-Geo-Region
Front
X-Is-Supported-Browser
X-Browser-Name
X-Mly-Id
X-Web-Node
X-Generation-Time
X-Provided-By
Mn-Server-Ip
X-Whom
X-Vcache
TWC-GeoIP-City
Expiry
X-Zipkin-Id
Property-Id
TWC-Connection-Speed
TWC-Device-Class
Webcakes-App-Version
X-Origin-Hint
X-Origin-Date
X-Proxied
X-Proxy-Cache-Info
Url
TWC-Locale-Group
X-Loop
TWC-GeoIP-Region
X-Detected-As
X-Connection-Hash
X-Extlb
X-FB-TRIP-ID
X-Httpd
Webcakes-Region
TWC-Privacy
X-Servername
X-Routing-Service
Web-Mar-Node
X-Tncms
X-Varnish-Beresp-Grace
TWC-GeoIP-DMA
Webcakes-App-Name
X-RCS-CacheZone
X-Cloudmap
Uber-Trace-Id
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
TWC-GeoIP-LatLong
TWC-GeoIP-Country
Fastcgi-Useragent
X-WP-CF-Super-Cache-Active
ServerID
X-Api-Version
X-Format
X-Shopify-Stage
X-Storefront-Renderer-Rendered
ServedBy
X-Tumblr-Pixel-3
X-Hosted-By
OT-Force-Account-Verify
X-Fetched-On
Protected
X-Forwarded-Host
X-Cluster
X-Cms-Context
X-Alternate-Cache-Key
X-Director
X-Cache-Debug
X-Auth-Group-Type
X-Cdn-Origin
X-Cache-Action
X-App-Environment
X-Hit
X-MP-GENERATED-AT
X-Logging-Id
X-Skip-Cache
X-Soup
Atl-Traceid
X-Tumblr-Pixel-2
X-Locale
X-Redis-Cache
DB-Nickname
X-Cluster-Node
X-Say-Cacheable
X-FW-Dynamic
Environment
X-Endurance-Cache-Level
X-Edge-Location
X-Cache-Host
X-SayCDN-TTL
X-Optimistic-Header
X-Scope-Id
X-Restarts
X-Served-From
X-Say-TTL
Cache-Hits
X-CLOUD-TRACE-CONTEXT
X-FW-Version
X-FW-Hash
X-Urbn-Site-Id
X-Urbn-Context-Path
Locale
X-FW-Type
X-Debug-Info
X-FW-Serve
X-FW-Static
X-FW-Server
LB
X-S
Filters
X-IPLB-Request-ID
X-IPLB-Instance
X-Labrador-Cache-Channel
X-Tt-Logid
X-PHP-Host
X-Drupal-Cache-Contexts
Node
X-Platform
Countrycode
X-R9-Blue-Green-Version
X-URL
X-CDN-Cache-Status
X-CDN-Forward
Xserver
X-GEO
X-No-Session
WPO-Cache-Status
X-XRDS-Location
X-Varnish-Age
X-B3-Traceid
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-ShardId
X-ShopId
X-WP-CF-Super-Cache-Cookies-Bypass
AMP-Access-Control-Allow-Source-Origin
X-Varnish-Beresp-Ttl
X-Client-Ip
X-Lagoon
Cache-Tv-Group
X-Varnish-Cache-Hits
X-NWS-UUID-VERIFY
X-Generated-By
X-NewRelic-App-Data
X-Signature
Request-ID
X-B-Cache
X-Presslabs-Stats
X-UA
X-Ua
X-Fastly-Request-Id
Referer-Policy
X-SRV
X-Azure-Ref-OriginShield
X-Webstats-RespID
X-SRCache-Key
X-Clientip
Expect-Staple
X-Site-Version
X-PHP-Backend
X-Cache-Operation
X-Upstream-Ht
X-Cache-Rule
X-IsAdmin
X-Upstream-Ct
AR-SID
From-Origin
Mail-Subject
We-Hiring
X-TA-CDN-Provider
Cache-Provider
Location
X-Worker
X-Auto-Login
X-VWS-Id
X-Bc-Bl
X-Cache-FS-Status
X-Server-IP
Fl-Custom-Application
X-AWS-Id
X-Accel-Version
X-LJ-Flow-ID
X-Litespeed-Cache-Control
Sid
X-Rojux
X-S-Cookie
Rendered-Blocks
X-ApacheServer
Meta-Geo-Continent
N-Cache
X-Cache-NE
X-ND-Cache
S-Rt
X-BCube-Filmed-By
X-Ig-Origin-Region
Xc-Version
X-Ig-Push-State
X-ScT
WPO-Cache-Message
X-PERF
CloudFront-Viewer-Country
X-Tb-Optimization-Total-Bytes-Saved
X-Loc
Source
X-B-Cookie
X-Bl-Debug
X-Application
DCR-Processing-Time-Ms
X-Org
X-Cs
MD5-Digest
Sslversion
X-External-Request-Id
Candidate-Md5Url
DCR-Decision-By
Pragrma
Origin
X-A-Dam
X-A-Dcw
X-A
X-Ec-GeoHdr
X-GeoCode
X-GeoCountry
X-FORWARDED-FOR
X-D
Host-ID
X-Vdms-Version
X-Conf
X-CACHE-AGE
X-Vtex-Remote-Cache
Lang
X-Aed
X-Developer
Origin-Agent-Cluster
Redirect-Candidate
X-A-Ccd
X-Ec-Fail
X-Destination
X-VC-TTL
X-A-Wwc
X-A-Dgt
X-Content-Age
Ngx.Var.Host
X-Tx-Id
X-Xfnlog-Site
Apple-News-Services-Request-Url
CDN-Cache
X-Fmm-Version
Powered-By
CDN-CachedAt
X-From
Canary
X-Gamma-Serve
X-Forwarded-Site
Cluster
X-Depends
Fastly-SSL
L5d-Success-Class
X-CacheTTL
X-Ee-Generated-By
Country-Code
Origin-Site
X-CGP
Ha-Gx-Prefs
IsBot
Gh-Request-Id
X-Cms-Device
Gannett-Cam-Experience-Id
X-Ee-Origin
X-Ee-Request-Date
CDN-RequestPullCode
CDN-RequestPullSuccess
CDN-RequestCountryCode
X-Fastly-Backend
X-FC-Vary-Parameters
CDN-PullZone
CDN-Uid
Cdncip
X-Epic-Correlation-Id
X-Ee-Request-Id
Apple-News-Services-Parsed-Url
X-Eu-Site
Cdnsip
CDN-EdgeStorageId
X-Micro-Cache
X-SIPLIST1
X-Sigma-Backend
X-Slack-Backend
X-Slack-Shared-Secret-Outcome
X-Action
X-Aicache-OS
X-Sigma
X-AK-Request-ID
X-Save-Cache
X-Rocket-Build-Number
X-SD-PageType
X-Section
Time-Cloud-Cache
Odigeo-Trace-Id
X-Access
X-Vary-Devices
Wxu-Next-Hostname
X-VG-TLSProxy
X-VG-WebCache
Wxu-Next-Region
Wxu-Next-Commit
X-Varnish-Hostname
X-V-Cache
Web-Mar-Region
X-Varnish-Authentication
X-Varnish-Beresp-Status
X-Varnish-Director
X-LSADC-Cache
X-Req
X-Internal-TTL
X-HS-Content-Campaign-Id
X-Bug-Bounty
X-Contensis-Viewer-Groups
Log-Origin
X-Cache-Aspx
X-Hash
X-GeoIP-City
Apple-News-Services-Handled
X-GeoIP-Country-Code
X-GeoIP-Region-Code
X-GoCache-CacheStatus
X-CUA
X-Mvc-Supplant-Cachable
X-Core-Value
X-Origin-Expires
X-PAYTM-SRV-ID
X-Policy
ServerName
Apple-News-Services-Host
RNT-Time
X-Csrf-Jwt
X-Node-Id
RNT-Machine
X-Old-Content-Length
Store-Cloud-Cache
X-Parent-Response-Time
X-Block-Status
X-Akamai-Device-Characteristics
X-Acquia-Purge-Cdn-Unconfigured
X-Accel-Expires-Debug
X-AB-Test
X-Amz-Storage-Class
X-App-Name
X-Cache-Date
X-Bip
X-BBC-Edge-Cache-Status
X-Backend-Instance
X-Sn-Servicetimems
X-Gdpr
X-Shield-Cache-Expires
X-Wikidot-Backend
X-Sucuri-Cache
X-We-Are-Hiring
X-SVT-ORM-RULES
X-SB
X-Request-URI
X-Pubstack
X-Region-Sid
X-Render-Time
X-Reqid
X-SVT-ORM-VERSION
X-Thanos
X-Varnish-Remaining-TTL
X-Varnish-CookieINHashed-On
X-VarnishDD-TTL
X-Vmg-Version
X-Via-Fastly
X-Varnish-CookieHashed-On
X-Uri
X-Thinkindot-L1
X-Thinkindot-L3
X-UA-Device-Type
X-Up
X-Proto
X-Wikidot-Static-Cache
X-Frame-Option
X-Ec-Custom-Error
X-Gen-Mode
X-Generated-On
X-HN
X-Dispatcher-Server
X-DefHash
X-Date
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-DefElseHash
X-Hnp-Log
X-Human
X-Nyt-Route
X-NMSegId
X-Op-Id-All
X-Origin-Time
X-Path
X-Mvc-Supplant-OutputCached
X-Men
X-Ion-Healthy
X-Ion-Hop
X-Jungle-Id
X-Level-Front-Cache
X-Content-Length
V-Age
CDCHOST
Cmsid
Pics-Label
PFcat
Release
Req-Svc-Chain
Server-Host
RewriteTestHook
X-Viewer-Country
Cache-Contol
Origin-EX
Cmstype
DSUID
Machine
L
Fastly-Backend-Name
NM-Fastcgi-Cache
Nord-Request-ID
Content-Script-Type
Origin-CC
Content-Style-Type
Azure-Version
RewriteTeamHook
CF-IPCountry
Azure-SlotName
User-Cache-Control
Vix-Hermes-Req-Id
Mime-Version
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
Azure-InstanceId
Azure-SiteName
TDXMobile
Azure-RegionName
X-NGINX-Cache
Load-Balancing
X-Moov-Xdn-Version
C-Via
Fastly-GeoIP-CountryCode
X-DPWN-IS-SECURE
X-Proxied-Request
X-Moov-Xdn-Caching-Status
X-Edge-Server
X-Location
Click-Count-Action-Start
Cdn-Request-Time
Cdn-Host
X-Vercel-Id
Click-Count-Error
X-Esi-Check
CacheControlHeader
X-Vercel-Cache
X-Gzip
X-Moov-T
X-ElasticPress-Query
Tube-Got-Eval
X-Cache-Id
Platform
X-Wormhole-Sdk
Tube-Get-Contents
Tube-Got-Results
Tube-Return
Producers
X-B3-Trace-ID
X-Cached-By
XM
X-ZONE
X-Origin-Response-Time
X-NF-Request-ID
X-Pad
X-Sucuri-ID
NGX
Cookie
X-Air-Pt
Fastly-Drupal-HTML
X-Varnish-Hits
X-Refresh
X-Via-Popv
X-Via-Popn
X-Datadome
X-Nginx-Cache-Key
X-Debug-Service
Debug
X-Via-Poph
True-Client-Country-4JS
Server-Hostname
X-HA-Backend
X-Srv
X-APP
Server-Ext
X-AIR-PT
Sever-Int
X-Webkit-CSP
GeoIP-Latitude
GeoIp-Country-Code
X-Servedbyhost
Show-Do-Not-Sell-Link
X-Source
X-DynaTrace-JS-Agent
Traceparent
X-Litespeed-Tag
Product
X-Zone
X-Nananana
HA-Ipaddr
X-TH-Server
X-Cache-Backend
Server-ID
WZWS-RAY
X-Ez-Minify-Html
X-Unity-Cache
X-Amz-Meta-Cb-Modifiedtime
HostName
Cdn
DataCenter
X-LB-ID
X-Cdn-Forward
Fastly-Drupal-Html
X-GeoIP
X-Cache-VC
X-B3-Parentspanid
X-Fpc
X-Nc
X-Wa
Tcn
Edge-Cache
X-User
X-Newrelic-Synthetics
X-TT-LOGID
X-VCL-Version
X-CDN-Provider
Lb
X-AC
X-B3-Spanid
X-Nginx-Cache
SID
Serverhost
Xkeylog
X-Proxy-Cache-La3
Resin-Trace
Xkey-La3
A
XkeyR9
X-Proxy-CacheR9
CountryCode
X-Request-Start
Akamai-Mon-Iucid-Del
X-LB-NoCache
X-TX-ID
X-Vc
MIME-Version
X-Datacenter
X-Lsadc-Cache
Cs
Yjs-Id
X-Service-Response-Time
NtCoent-Length
Wsr-Cache
X-Scheme
X-RateLimit-Limit
Sm-Log-Id
Cdn-Requestid
CDN
Esi-Enabled
X-WA
X-LiteSpeed-Tag
X-LiteSpeed-Cache-Control
X-API-Version
X-Udemy-Cache-App-Namespace
Uri
X-FPC
X-VC-Age
X-NC
Hostname
X-Lb-Id
X-Pool
X-Aspnet-Version
X-Dynatrace-Js-Agent
X-HubSpot-Correlation-Id
X-Request-Host
X-ID
Surrogated-Key
Proxy-Firewall
X-Via-JSL
X-Styx-Origin-Id
X-Styx-Info
X-HA-Device-Type
Cr
X-Akamai-Pragma-Client-IP
X-Fastly-Backend-Reqs
X-Html-Minification-Powered-By
Content-Secure-Policy
Server-Id
X-NodeID
X-HA-Bot-Classification
X-CS
X-Stale
Datacenter
Pramga
X-TIM-N
X-HA-Application-Name
X-RequestId
X-Var-Ttl
ServerHost
GeoIP-Country-Code
Geoip-Latitude
T-Server
X-TimeS
X-Vgn-Hpd-Reason
RATING
X-Srcache-Fetch-Status
X-Srcache-Store-Status
X-Cache-Grace
X-Ez-Minify-Js
Cloudfront-Viewer-Country
X-DataCenter
X-DynaTrace
X-ServedByHost
Srv
W
X-Lb-Nocache
Yak-Timeinfo
From-Cache
X-Varnish-Beresp-TTL
X-Wp-Cf-Super-Cache
X-Wp-Cf-Super-Cache-Cache-Control
X-Air-Hostname
X-Oracle-DMS-ECID
X-Aspnetmvc-Version
X-Air-Source
X-Air-Trace-Id
Edge-Copy-Time
X-CACHE-KEY
X-MSEdge-Features
X-CSRF-TOKEN
X-Via-SSL
X-Swift-Error
X-MSEdge-Flight
X-Via-CDN
X-App
X-Via-Edge
X-Ha-Backend
X-Shardid
X-LAGOON
X-Sorting-Hat-Podid
X-Sorting-Hat-Shopid
X-Shopid
X-Wp-Cf-Super-Cache-Active
X-Wp-Cf-Super-Cache-Cookies-Bypass
N1-Cache
X-Ssense-Gql
X-Correlation-ID
X-Proxy-Cache-LA2
X-Via-PopN
X-Ssense-Shipping-Surcharge-Enabled
FSS-Cache
Ohc-File-Size
Ohc-Cache-HIT
X-Zen-Fury
X-Key
X-VServer
X-Via-PopV
X-Via-PopH
X-Jobs
X-Geolocation
X-ByteArk-ReqID
Req-ID
X-ByteArk-Cache
X-Ramcache
X-Webkit-Csp-Report-Only
Cl-Cache
X-NODE
X-Elasticpress-Query
Ngx
X-Geo
X-Check-Cacheable
True-Client-IP
X-Web-Server
X-Cdn-Cache-Status
CF-Cached-On
X-Sucuri-Id
WP-Super-Cache
X-Th-Server
On-Server
X-Cdn-Srv
X-PageType
X-Serial
X-DC
WebServer
Akamai-X-True-TTL
X-ATG-Version
Cf-Ipcountry
X-Iplb-Request-Id
X-Iplb-Instance
Warning
X-VTEX-Cache-Time
X-VTEX-Cache-Server
X-MiniProfiler-Ids
X-Beacon
My-App
X-Limited
Xkey-G-Jp
Cneonction
X-Mg-Cache
FSS-Proxy
User-Agent
Host-Name
X-Powered-By-VTEX-Cache
X-Request-Url
X-Fastly-Cache-Status
X-Env