Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
X-Frame-Options
Expires
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Accept-CH
Last-Modified
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
X-XSS-Protection
X-Cache
X-Powered-By
Pragma
Via
CF-RAY
Age
Content-Security-Policy
Alt-Svc
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
X-Amz-Cf-Pop
X-Amz-Cf-Id
Content-Language
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-Download-Options
X-Xss-Protection
X-Request-Id
X-Timer
Access-Control-Allow-Headers
CF-Ray
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
Accept-CH-Lifetime
Content-Security-Policy-Report-Only
X-DNS-Prefetch-Control
X-AspNet-Version
X-Runtime
Permissions-Policy
X-Drupal-Cache
Server-Timing
X-Generator
X-Envoy-Upstream-Service-Time
X-Cache-Status
X-FRAME-OPTIONS
X-Cacheable
X-Ua-Compatible
X-Iinfo
X-Drupal-Dynamic-Cache
Timing-Allow-Origin
X-CONTENT-TYPE-OPTIONS
Accept-Ch
Feature-Policy
X-Content-Security-Policy
Xkey
X-XSS-PROTECTION
Upgrade
Access-Control-Expose-Headers
X-CDN
Content-Encoding
Status
X-AspNetMvc-Version
Access-Control-Max-Age
X-Amz-Request-Id
X-Amz-Id-2
Host-Header
X-Age
Request-Context
X-Backend
Cf-Edge-Cache
X-Amz-Version-Id
X-Robots-Tag
X-Hacker
Keep-Alive
X-Via
Cf-Apo-Via
X-Turbo-Charged-By
X-Vhost
X-AH-Environment
X-Rq
X-Server
X-Dispatcher
X-Cache-Group
X-Proxy-Cache
CONTENT-SECURITY-POLICY
X-Request-ID
X-Ws-Request-Id
EagleId
X-UA-Device
X-Varnish-Cache
Pantheon-Trace-Id
Grace
X-Litespeed-Cache
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Server-Powered-By
X-OneAgent-JS-Injection
X-Dns-Prefetch-Control
X-WebKit-CSP
X-Pingback
X-Page-Speed
Allow
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-Cache-Lookup
X-Device
X-FTR-Request-ID
X-Node
X-Host
X-Server-Id
EagleEye-TraceId
X-Backend-Server
X-Country-Code
Surrogate-Control
X-Cloud-Trace-Context
X-Ruxit-JS-Agent
Cf-Railgun
X-Readtime
X-Akam-SW-Version
X-HW
X-Response-Time
P3p
Cache-Tag
X-Amz-Server-Side-Encryption
X-LiteSpeed-Cache
Content-Location
X-Ua-Device
Accept-Ch-Lifetime
Cross-Origin-Opener-Policy
X-Content-Type
X-Nginx-Cache-Status
X-Nginx-Upstream-Cache-Status
X-Rack-Cache
Request-Id
Service-Worker-Allowed
X-Trace
X-TraceId
X-Application-Context
Fastly-Restarts
X-Nf-Request-Id
X-Element-Page-Cache
X-Times
X-D2id
X-Vname
X-PC
X-TtlSet
Rating
X-Clacks-Overhead
X-Cnection
X-Oneagent-Js-Injection
X-Edge
X-Mcache
X-Midtier
X-Navigation-Version
X-Country
X-FTR-Backend
X-Country-Code-Real
X-FTR-Balancer
X-FTR-Backend-Server
X-Vcap-Request-Id
X-FTR-Cache-Status
Origin-Trial
X-Browser-Type
X-FTR-Expires
Edge-Control
X-ESI
X-Cache-TTL
Surrogate-Key
X-FastCGI-Cache
X-NWS-LOG-UUID
X-Kinja
X-Kinja-Revision
X-GoogleNews-Bot
X-Exp-Id
X-Kinja-Server
X-Cdn-Fetch
X-Exp-Variant
X-Kinja-Build
X-Powered-By-Plesk
X-Url
X-Ac
X-Abt-Application-Version
X-Upstream
X-Mod-Pagespeed
X-Amz-Rid
Verso
X-ORACLE-DMS-RID
X-B3-TraceId
X-Language
X-ECACHE
Akamai-GRN
Nginx-Cache
Pinterest-Version
Pinterest-Generated-By
X-Pinterest-Rid
X-GitHub-Request-Id
X-MS-InvokeApp
Pagespeed
Display
X-Middleton-Display
X-Sol
S
X-Erf-Bev-Bev-Is-Generated
X-Server-Lifecycle-Phase
X-Erf-Bev-Bev
X-PDP-UNCACHING-HASH
X-Instrumentation
X-Kraken-Loop-Name
X-Envoy-Decorator-Operation
X-Middleton-Response
Response
AR-ATIME
AR-Request-ID
AR-PoweredBy
Edge-Cache-Tag
X-Amzn-Trace-Id
X-Request-Device-Id
SPRequestDuration
SPRequestGuid
SPIisLatency
X-SharePointHealthScore
X-Distributor
X-Goog-Hash
X-T
X-Ratelimit-Limit
X-Resp-Is-Stale
X-Ser
X-Edge-Location-Klb
X-Kinsta-Cache
X-ARC
Access-Control-Request-Method
X-NGENIX-Cache
X-Meli-Trace-Site
X-Meli-Trace-Platform
X-Meli-Trace-Bu
Front-End-Https
X-Shield-Request-Id
X-Client-IP
X-Dw-Request-Base-Id
X-Ruxit-Js-Agent
X-Content-Digest
X-Ttl
X-Ezoic-Cdn
X-Recruiting
RTSS
X-Cache-Key
Cache-Status
X-Request-Received
X-Request-Processing-Time
X-Version
X-Varnish-TTL
X-Mg-S
X-Powered-CMS
Public-Key-Pins
TP-Cache
X-HS-Cache-Config
X-Ismobilevalue
X-HS-Content-Id
X-HS-Hub-Id
Fastcgi-Cache
X-Accel-Expires
X-MSEdge-Ref
AR-CACHE
Arr-Disable-Session-Affinity
Cache-Tags
X-Correlation-Id
X-Cluster-Name
X-Daa-Tunnel
Ar-SID
X-Cached
X-Amz-Replication-Status
YJS-ID
Realpath
X-Id
X-Content-Security-Policy-Report-Only
Content-MD5
X-Newrelic-App-Data
X-RateLimit-Remaining
X-HS-Combine-CSS
X-Fastly-Request-ID
Payment
X-Ua-Browser
X-Azure-Ref
X-Forwarded-For
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-HP-Webp
X-DIS-Request-ID
X-Jurisdiction
X-Cambria-Cache-Control
X-HP-Trace-Id
X-Xrds-Location
X-Server-Name
X-HS-Prerendered
X-HS-CF-Cache-Status
X-GUploader-UploadID
Content-Disposition
MicrosoftSharePointTeamServices
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Amz-Apigw-Id
X-TTL
X-Amzn-RequestId
X-Protected-By
X-Px
Count-Hit
X-ORACLE-DMS-ECID
X-Ratelimit-Reset
X-Unique-Id
X-AppVersion
X-Az
X-Origin-Server
X-Activity-Id
X-Page-Id
X-Logged-In
X-Rid
Accept-Charset
X-Git-Hash
Cross-Origin-Resource-Policy
X-Amz-Meta-S3cmd-Attrs
Cleartype
X-Proxy
X-Microsite
X-FB-Debug
X-VARITI-CCR
Cross-Origin-Embedder-Policy
X-Request-Handler-Origin-Region
X-Ratelimit-Remaining
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-Www-Served-By
X-TEC-API-ROOT
X-Load-Cache
X-COUNTRY
Version
X-Hits
X-LLID
X-Webkit-Csp
X-Geo-Country
X-Goog-Metageneration
X-Forwarded-Proto
X-Template
X-PressLabs-Stats
X-Varnish-Backend
X-SERVER-NAME
X-Upgrade-Enabled
Server-Node
X-WebKit-CSP-Report-Only
X-B3-Sampled
Server-Name
X-App-Server
X-Hostname
Healthy
Access-Control-Allow-Method
X-Content-Options
X-Frontend
X-Varnish-Grace
Section-Io-Cache
Viewport
X-Grace
X-TT
X-Fb-Rlafr
X-CST
X-Device-Type
Fastly-SIE
X-B
Fastly-SWR
Alternate-Protocol
X-Varnish-Server
AKAMAI-GRN
X-Request-Guid
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
X-Requestid
X-Status
X-Contextid
X-ProcessESI
X-RemovedCookies
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Cache-Age
X-Goog-Generation
DC
TCN
Upgrade-Insecure-Requests
X-Hl-Ver
X-Amzn-Remapped-Content-Length
X-Magnolia-Registration
X-Varnish-Ttl
Retry-After
X-EdgeConnect-Cache-Status
Host
X-Cache-Control
X-CSRF-Token
X-App-Version
MS-Author-Via
Frame-Options
X-Revision
X-Response-Served-From
X-Origin-CC
X-Origin-TTL
X-Type
X-Original-Request-Id
X-Buckets
Amp-Access-Control-Allow-Source-Origin
X-Debug
X-Tt-Trace-Tag
SD-X-WS
X-Tt-Trace-Host
X-Yandex-Req-Id
X-Mobile
X-ServerID
X-Seen-By
X-Backend-Name
X-Instance
VIX-Pulpo-Node
X-UUID
X-G
VIX-Pulpo-Upstream-Status
X-INCAP-ABP
Cross-Origin-Embedder-Policy-Report-Only
Cross-Origin-Opener-Policy-Report-Only
X-Adobe-Content
X-Akamai-Edgescape
X-Adobe-Loc
X-N
X-Lambda-Id
X-NYM-Debug-Backend
X-Tumblr-Pixel-0
X-Oracle-Dms-Ecid
X-Rendered-As
X-Tumblr-Pixel
X-Is-Bot
X-Tumblr-Pixel-1
X-Yottaa-Metrics
X-Cache-Status-Check
X-Yottaa-Optimizations
X-Tumblr-User
Access-Control-Request-Headers
NGB
X-Trace-Id
Section-Io-Id
X-AB
X-WP-CF-Super-Cache-Cache-Control
Ms-Operation-Id
X-WP-CF-Super-Cache
MS-CV
Xet-Cookie
X-Mg-Request-UUID
X-Framework
X-RTag
X-Akamai-Request-ID2
X-Debug-IsPreview
X-Debug-IsConnected
X-Content-Powered-By
X-Storage
X-Server-W
X-RM-Cache-TTL
Cache
Charset
X-Dc
Webserver
X-Vcl-Version
Filterid
Paypal-Debug-Id
X-DataDome
YJS-CacheStatus
X-VC-Cache
Accept-Language
Refresh
X-B3-SpanId
Onion-Location
X-Cache-Time
X-Ms-Version
X-Ms-Request-Id
X-ECache
X-Cache-Hit
X-ProxyCache-Key
X-Cacheable-TTL
X-BYPASS-REASON
X-ProxyCache-Status
X-User-Agent
SRV
X-Tec-Api-Root
X-Tec-Api-Version
X-Tec-Api-Origin
X-Fastcgi-Cache
X-Request-Bu
Selected-Fe
X-Timing-Wait
X-Proxy-Build
X-Time
X-Request-Platform
X-F-Cache
X-Request-Site
X-Region
X-Node-Name
X-Real-IP
X-VC
X-CCDN-CacheTTL
X-Hcs-Proxy-Type
Priority
Liferay-Portal
X-CCDN-Origin-Time
Apigw-Requestid
GEO-INFO
X-Mode
X-L-Path
X-Origin-Cache
X-Environment-Context
CDN-RequestId
X-HTML-Minification-Powered-By
X-IPS-LoggedIn
Front
X-Service
Backend
X-LB-Cache
X-Rule
X-Pass-Why
X-Cache-Expired-At
X-Tb
X-Server-ID
X-Drupal-Cache-Tags
Country
Meta-Geo
X-VCT
X-Rn-Rsrv
X-SaId
X-UPSTREAM-Address
X-Rocket-Nginx-Serving-Static
X-Rewrite-Enabled
X-HITS
X-JoinUs
X-Datadog-Sampling-Priority
X-Datadog-Trace-Id
X-Datadog-Parent-Id
X-Datadog-Sampled
X-Mly-Id
X-Api-Version
X-Origin
Cross-Origin-Window-Policy
X-Browser-Name
X-Adobe-Source
X-Is-Mobile
X-Tcp-Rtt
X-Wix-Request-Id
X-Handled-By
X-Is-Desktop
X-Geo-Region
X-Is-Supported-Browser
X-Is-Modern-Browser
X-Is-Mobile-Only
X-Is-Tablet
X-Whom
X-Generation-Time
Mn-Server-Ip
X-Web-Node
X-Provided-By
X-Cloudmap
X-Zipkin-Id
Expiry
X-Detected-As
X-Loop
X-Proxy-Cache-Info
X-Connection-Hash
TWC-Privacy
Url
X-Proxied
Web-Mar-Node
Uber-Trace-Id
X-Origin-Hint
Webcakes-Region
Webcakes-App-Version
Webcakes-App-Name
X-Origin-Date
TWC-Connection-Speed
TWC-Locale-Group
X-Httpd
TWC-GeoIP-LatLong
X-Servername
X-Routing-Service
X-RCS-CacheZone
TWC-GeoIP-Region
X-RateLimit-Limit-Second
X-Tncms
TWC-GeoIP-DMA
X-RateLimit-Remaining-Second
X-FB-TRIP-ID
X-Extlb
TWC-Device-Class
TWC-GeoIP-City
TWC-GeoIP-Country
X-Varnish-Beresp-Grace
X-Vcache
Property-Id
Fastcgi-Useragent
X-WP-CF-Super-Cache-Active
ServerID
X-Hit
ServedBy
OT-Force-Account-Verify
X-Hosted-By
X-App-Environment
X-Redis-Cache
X-MP-GENERATED-AT
X-Locale
X-Format
X-Cache-Debug
X-Cache-Action
X-Auth-Group-Type
X-Cluster
Protected
X-Fetched-On
X-Director
X-Cms-Context
DB-Nickname
X-Logging-Id
X-Alternate-Cache-Key
X-Skip-Cache
X-Soup
X-Tumblr-Pixel-2
X-Tumblr-Pixel-3
X-Forwarded-Host
X-Cdn-Origin
X-Storefront-Renderer-Rendered
Atl-Traceid
X-Shopify-Stage
X-Endurance-Cache-Level
X-Optimistic-Header
X-Edge-Location
X-Debug-Info
X-Urbn-Context-Path
X-Cluster-Node
X-Cache-Host
X-CLOUD-TRACE-CONTEXT
X-FW-Hash
X-Scope-Id
X-Served-From
X-SayCDN-TTL
X-Say-TTL
X-Say-Cacheable
X-FW-Version
X-FW-Type
X-Restarts
X-FW-Serve
X-FW-Server
X-FW-Static
X-FW-Dynamic
X-Urbn-Site-Id
Locale
Cache-Hits
Environment
X-IPLB-Instance
X-Tt-Logid
Node
X-S
X-PHP-Host
Filters
X-Labrador-Cache-Channel
X-Drupal-Cache-Contexts
X-IPLB-Request-ID
LB
X-Platform
Countrycode
X-R9-Blue-Green-Version
X-CDN-Cache-Status
X-CDN-Forward
X-URL
X-GEO
Xserver
AMP-Access-Control-Allow-Source-Origin
WPO-Cache-Status
X-XRDS-Location
X-No-Session
X-Varnish-Age
X-B3-Traceid
X-Sorting-Hat-ShopId
X-ShopId
X-Sorting-Hat-PodId
X-ShardId
X-WP-CF-Super-Cache-Cookies-Bypass
Cache-Tv-Group
X-Client-Ip
X-NWS-UUID-VERIFY
X-Lagoon
X-Varnish-Cache-Hits
X-Varnish-Beresp-Ttl
X-Generated-By
X-B-Cache
X-Presslabs-Stats
X-Signature
Request-ID
X-UA
X-Ua
X-NewRelic-App-Data
X-Fastly-Request-Id
Referer-Policy
X-SRCache-Key
Expect-Staple
X-SRV
X-Clientip
X-Azure-Ref-OriginShield
CloudFront-Viewer-Country
Mail-Subject
We-Hiring
X-Webstats-RespID
X-Cache-Operation
X-PHP-Backend
X-IsAdmin
X-Upstream-Ct
X-Upstream-Ht
X-Cache-Rule
X-Site-Version
AR-SID
From-Origin
X-Cache-FS-Status
X-TA-CDN-Provider
X-Auto-Login
Cache-Provider
Location
X-Worker
X-VWS-Id
X-AWS-Id
X-Server-IP
X-Bc-Bl
Fl-Custom-Application
X-Accel-Version
X-LJ-Flow-ID
Sid
X-Litespeed-Cache-Control
X-Loc
X-A-Ccd
X-Ig-Push-State
X-A-Dam
X-Org
Rendered-Blocks
X-Bl-Debug
X-BCube-Filmed-By
X-Cache-NE
X-Vtex-Remote-Cache
X-ND-Cache
X-A
X-Cs
WPO-Cache-Message
Xc-Version
X-A-Dcw
Source
Redirect-Candidate
X-Ec-GeoHdr
X-Tb-Optimization-Total-Bytes-Saved
X-Ec-Fail
S-Rt
Candidate-Md5Url
X-D
X-A-Wwc
X-GeoCountry
X-External-Request-Id
X-VC-TTL
Origin-Agent-Cluster
X-ApacheServer
X-ScT
X-GeoCode
Host-ID
X-Content-Age
Ngx.Var.Host
X-Aed
N-Cache
Meta-Geo-Continent
Pragrma
Lang
MD5-Digest
X-S-Cookie
Origin
X-Destination
DCR-Processing-Time-Ms
X-Developer
X-B-Cookie
X-PERF
X-CACHE-AGE
Sslversion
X-Conf
X-FORWARDED-FOR
X-Rojux
X-Application
X-Vdms-Version
X-A-Dgt
X-Ig-Origin-Region
DCR-Decision-By
X-Xfnlog-Site
X-Tx-Id
X-Epic-Correlation-Id
X-From
CDN-Cache
X-Fastly-Backend
Canary
X-Eu-Site
CDN-EdgeStorageId
CDN-CachedAt
X-Fmm-Version
X-FC-Vary-Parameters
X-Forwarded-Site
Country-Code
Gh-Request-Id
Ha-Gx-Prefs
X-Cms-Device
Gannett-Cam-Experience-Id
X-CGP
Fastly-SSL
X-CUA
X-Csrf-Jwt
Odigeo-Trace-Id
X-Contensis-Viewer-Groups
Log-Origin
L5d-Success-Class
IsBot
X-Core-Value
Origin-Site
X-Depends
CDN-Uid
Cdncip
CDN-RequestPullSuccess
CDN-RequestPullCode
X-Ee-Request-Id
CDN-RequestCountryCode
Cdnsip
X-Ee-Request-Date
X-CacheTTL
X-Gamma-Serve
X-Ee-Generated-By
Cluster
X-Ee-Origin
CDN-PullZone
X-Old-Content-Length
X-Save-Cache
X-Rocket-Build-Number
X-Vary-Devices
X-SD-PageType
X-Sigma
X-Section
X-Req
Store-Cloud-Cache
Powered-By
X-Policy
Wxu-Next-Commit
X-VG-WebCache
X-VG-TLSProxy
X-Sigma-Backend
X-SIPLIST1
X-AK-Request-ID
X-Varnish-Authentication
X-V-Cache
X-Access
X-Action
X-Aicache-OS
Time-Cloud-Cache
X-Varnish-Beresp-Status
X-Slack-Shared-Secret-Outcome
X-Slack-Backend
Web-Mar-Region
X-Varnish-Hostname
X-Varnish-Director
Wxu-Next-Hostname
ServerName
X-Hash
X-GoCache-CacheStatus
X-Cache-Aspx
X-HS-Content-Campaign-Id
X-Bug-Bounty
X-GeoIP-Region-Code
X-GeoIP-Country-Code
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
Apple-News-Services-Host
Apple-News-Services-Handled
X-GeoIP-City
X-PAYTM-SRV-ID
X-Internal-TTL
X-LSADC-Cache
X-Origin-Expires
X-Node-Id
RNT-Time
Wxu-Next-Region
RNT-Machine
X-Micro-Cache
X-Mvc-Supplant-Cachable
X-Parent-Response-Time
X-Accel-Expires-Debug
X-Backend-Instance
X-BBC-Edge-Cache-Status
X-Acquia-Purge-Cdn-Unconfigured
X-App-Name
X-Amz-Storage-Class
X-Block-Status
X-AB-Test
X-Bip
X-Akamai-Device-Characteristics
X-Cache-Date
X-Nyt-Route
X-Thanos
X-SVT-ORM-VERSION
X-Thinkindot-L1
X-Thinkindot-L3
X-UA-Device-Type
X-SVT-ORM-RULES
X-Sucuri-Cache
X-Reqid
X-Render-Time
X-Request-URI
X-SB
X-Shield-Cache-Expires
X-Up
X-Uri
X-We-Are-Hiring
X-Vmg-Version
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-Sn-Servicetimems
X-Viewer-Country
X-Via-Fastly
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
X-VarnishDD-TTL
X-Region-Sid
X-Pubstack
X-Gdpr
X-Frame-Option
X-Gen-Mode
X-Generated-On
X-HN
X-Ec-Custom-Error
X-Dispatcher-Server
X-Debug-Cache-Fetch
X-Date
X-Debug-Cache-Store
X-DefElseHash
X-DefHash
X-Hnp-Log
X-Human
X-Op-Id-All
X-NMSegId
X-Origin-Time
X-Path
X-Proto
X-Mvc-Supplant-OutputCached
X-Men
X-Ion-Healthy
X-Ion-Hop
X-Jungle-Id
X-Level-Front-Cache
X-Content-Length
TDXMobile
NM-Fastcgi-Cache
Nord-Request-ID
Machine
L
Fastly-Backend-Name
Origin-CC
Origin-EX
Req-Svc-Chain
Release
Pics-Label
PFcat
DSUID
Content-Script-Type
Azure-SiteName
Azure-RegionName
Azure-InstanceId
Mime-Version
Azure-SlotName
Azure-Version
Cmstype
Cmsid
CDCHOST
Cache-Contol
RewriteTeamHook
Content-Style-Type
User-Cache-Control
V-Age
Vix-Hermes-Req-Id
Thinkindot-CacheControl-Type
CF-IPCountry
RewriteTestHook
Thinkindot-CacheControl
Server-Host
X-NGINX-Cache
X-ElasticPress-Query
Click-Count-Error
Tube-Get-Contents
X-DPWN-IS-SECURE
X-Edge-Server
Tube-Got-Eval
Click-Count-Action-Start
X-Esi-Check
Cdn-Request-Time
C-Via
X-Location
Load-Balancing
X-Moov-T
X-Moov-Xdn-Caching-Status
X-Moov-Xdn-Version
X-Proxied-Request
X-Gzip
CacheControlHeader
Tube-Return
X-Vercel-Id
X-Wormhole-Sdk
Tube-Got-Results
Cdn-Host
X-Vercel-Cache
X-Cache-Id
X-B3-Trace-ID
Platform
Fastly-GeoIP-CountryCode
Producers
X-Cached-By
XM
X-ZONE
X-Origin-Response-Time
X-NF-Request-ID
X-Pad
X-Sucuri-ID
X-Varnish-Hits
Fastly-Drupal-HTML
X-Air-Pt
Cookie
NGX
X-Datadome
X-Debug-Service
X-Via-Poph
X-Nginx-Cache-Key
X-Via-Popn
Debug
X-Refresh
X-Via-Popv
True-Client-Country-4JS
X-HA-Backend
X-APP
Sever-Int
Server-Hostname
Server-Ext
X-Srv
X-AIR-PT
X-Webkit-CSP
Show-Do-Not-Sell-Link
X-Source
GeoIp-Country-Code
X-Servedbyhost
GeoIP-Latitude
X-DynaTrace-JS-Agent
Traceparent
X-Litespeed-Tag
Server-ID
X-Zone
HA-Ipaddr
X-TH-Server
X-Ez-Minify-Html
Product
X-Nananana
WZWS-RAY
X-Cache-Backend
DataCenter
HostName
Cdn
X-Amz-Meta-Cb-Modifiedtime
X-Unity-Cache
X-LB-ID
Fastly-Drupal-Html
X-Cdn-Forward
X-Nc
X-B3-Parentspanid
X-Fpc
X-Cache-VC
X-GeoIP
X-Wa
X-Newrelic-Synthetics
X-User
Edge-Cache
Tcn
X-TT-LOGID
X-VCL-Version
X-AC
Lb
X-CDN-Provider
X-Nginx-Cache
X-B3-Spanid
SID
Xkey-La3
X-Proxy-CacheR9
Xkeylog
A
XkeyR9
X-Proxy-Cache-La3
X-Vc
Serverhost
Resin-Trace
Akamai-Mon-Iucid-Del
X-Datacenter
CountryCode
X-TX-ID
X-LB-NoCache
MIME-Version
X-Request-Start
Yjs-Id
Cs
X-Lsadc-Cache
NtCoent-Length
Sm-Log-Id
Wsr-Cache
X-Service-Response-Time
X-RateLimit-Limit
X-Scheme
X-LiteSpeed-Tag
Cdn-Requestid
CDN
Esi-Enabled
X-WA
X-LiteSpeed-Cache-Control
X-API-Version
X-Pool
X-NC
X-Dynatrace-Js-Agent
Hostname
X-Aspnet-Version
X-Lb-Id
Uri
X-FPC
X-HubSpot-Correlation-Id
X-ID
X-VC-Age
X-Request-Host
X-Udemy-Cache-App-Namespace
Surrogated-Key
Proxy-Firewall
X-Styx-Origin-Id
Content-Secure-Policy
X-TIM-N
X-Fastly-Backend-Reqs
X-Via-JSL
X-Html-Minification-Powered-By
X-NodeID
X-Akamai-Pragma-Client-IP
X-Styx-Info
Server-Id
Datacenter
X-HA-Application-Name
Pramga
X-HA-Bot-Classification
X-Stale
X-CS
X-HA-Device-Type
Cr
X-RequestId
Geoip-Latitude
ServerHost
X-Var-Ttl
GeoIP-Country-Code
X-Srcache-Fetch-Status
X-Vgn-Hpd-Reason
X-Srcache-Store-Status
X-TimeS
X-Cache-Grace
RATING
X-Ez-Minify-Js
T-Server
X-Varnish-Beresp-TTL
Yak-Timeinfo
X-ServedByHost
X-DynaTrace
W
X-DataCenter
X-Lb-Nocache
From-Cache
Srv
X-Aspnetmvc-Version
X-Oracle-DMS-ECID
X-Wp-Cf-Super-Cache
X-Wp-Cf-Super-Cache-Cache-Control
X-Air-Hostname
X-Air-Source
X-Air-Trace-Id
X-Via-Edge
X-Via-SSL
X-CACHE-KEY
Edge-Copy-Time
X-MSEdge-Features
X-MSEdge-Flight
X-Via-CDN
X-CSRF-TOKEN
X-Swift-Error
X-Ha-Backend
Cloudfront-Viewer-Country
X-App
X-Sorting-Hat-Shopid
X-Sorting-Hat-Podid
X-LAGOON
X-Shardid
X-Shopid
X-Wp-Cf-Super-Cache-Cookies-Bypass
N1-Cache
X-Wp-Cf-Super-Cache-Active
X-Proxy-Cache-LA2
X-Zen-Fury
X-Geolocation
Req-ID
X-Via-PopH
X-ByteArk-Cache
X-Key
X-VServer
X-NODE
Ohc-File-Size
Ohc-Cache-HIT
X-ByteArk-ReqID
X-Ramcache
FSS-Cache
X-Via-PopN
X-Jobs
X-Correlation-ID
X-Ssense-Gql
X-Via-PopV
X-Ssense-Shipping-Surcharge-Enabled
WP-Super-Cache
True-Client-IP
X-Sucuri-Id
X-Elasticpress-Query
Ngx
X-Web-Server
CF-Cached-On
X-Cdn-Cache-Status
X-Check-Cacheable
X-Geo
X-Webkit-Csp-Report-Only
Cl-Cache
X-PageType
X-Serial
WebServer
X-Cdn-Srv
On-Server
X-Th-Server
Akamai-X-True-TTL
X-ATG-Version
X-DC
Cf-Ipcountry
X-Iplb-Request-Id
X-Iplb-Instance
My-App
X-VTEX-Cache-Time
Warning
X-Beacon
X-Limited
X-Mg-Cache
X-MiniProfiler-Ids
X-VTEX-Cache-Server
X-Request-Url
X-Fastly-Cache-Status
X-Powered-By-VTEX-Cache
User-Agent
Host-Name
Xkey-G-Jp
X-Env
FSS-Proxy
Cneonction