Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
X-Frame-Options
Expires
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Accept-CH
Last-Modified
X-XSS-Protection
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
CF-RAY
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Alt-Svc
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-Download-Options
X-Request-Id
Cf-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
X-Xss-Protection
Access-Control-Allow-Credentials
Accept-CH-Lifetime
Content-Security-Policy-Report-Only
X-DNS-Prefetch-Control
X-AspNet-Version
X-Runtime
Permissions-Policy
Server-Timing
X-Drupal-Cache
CF-Ray
X-Generator
X-Envoy-Upstream-Service-Time
X-Cache-Status
X-Ua-Compatible
X-Cacheable
X-Iinfo
X-FRAME-OPTIONS
X-Drupal-Dynamic-Cache
Timing-Allow-Origin
Feature-Policy
X-Content-Security-Policy
X-CONTENT-TYPE-OPTIONS
Xkey
Upgrade
Access-Control-Expose-Headers
Content-Encoding
X-CDN
Status
X-XSS-PROTECTION
X-AspNetMvc-Version
Access-Control-Max-Age
Accept-Ch
Host-Header
X-Amz-Request-Id
X-Age
X-Amz-Id-2
Request-Context
Cf-Edge-Cache
X-Backend
X-Robots-Tag
X-Hacker
X-Via
Cf-Apo-Via
X-Request-ID
X-Turbo-Charged-By
X-Rq
X-Amz-Version-Id
Keep-Alive
X-Cache-Group
X-Vhost
X-AH-Environment
X-Dispatcher
X-Server
X-Proxy-Cache
EagleId
X-Ws-Request-Id
X-UA-Device
CONTENT-SECURITY-POLICY
X-Varnish-Cache
X-OneAgent-JS-Injection
Pantheon-Trace-Id
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
Grace
X-Server-Powered-By
X-Dns-Prefetch-Control
X-Pingback
Allow
X-Page-Speed
X-WebKit-CSP
X-Swift-SaveTime
X-Swift-CacheTime
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Litespeed-Cache
Ali-Swift-Global-Savetime
X-FTR-Request-ID
X-Device
X-Node
EagleEye-TraceId
X-Host
X-Cache-Lookup
X-Backend-Server
X-LiteSpeed-Cache
X-Country-Code
Surrogate-Control
X-Server-Id
X-Cloud-Trace-Context
X-Readtime
X-Akam-SW-Version
Cf-Railgun
X-Ruxit-JS-Agent
X-HW
X-Response-Time
Cache-Tag
Content-Location
P3p
X-Amz-Server-Side-Encryption
Cross-Origin-Opener-Policy
X-Rack-Cache
X-Trace
X-Nginx-Upstream-Cache-Status
Service-Worker-Allowed
X-Nginx-Cache-Status
Request-Id
X-TraceId
Fastly-Restarts
X-Content-Type
X-Clacks-Overhead
X-Application-Context
X-PC
X-Vname
X-TtlSet
X-Times
Rating
X-Country
X-Cnection
X-Ua-Device
X-Browser-Type
X-ESI
X-Cache-TTL
X-Midtier
X-Mcache
X-Edge
X-FTR-Cache-Status
X-FTR-Backend
X-Country-Code-Real
X-FTR-Balancer
X-FTR-Backend-Server
X-Vcap-Request-Id
X-FTR-Expires
Surrogate-Key
X-Ac
Origin-Trial
Edge-Control
X-Powered-By-Plesk
Accept-Ch-Lifetime
X-Abt-Application-Version
X-D2id
X-Cdn-Fetch
X-Kinja-Build
X-Kinja-Revision
X-Kinja-Server
X-FastCGI-Cache
X-Kinja
X-Element-Page-Cache
X-Exp-Variant
X-Exp-Id
X-GoogleNews-Bot
X-NWS-LOG-UUID
Verso
X-Nf-Request-Id
X-B3-TraceId
X-Upstream
X-ECACHE
X-ORACLE-DMS-RID
X-Navigation-Version
X-Amz-Rid
X-Mod-Pagespeed
Nginx-Cache
Display
Pagespeed
X-Middleton-Display
X-Sol
Pinterest-Version
X-Pinterest-Rid
Pinterest-Generated-By
X-GitHub-Request-Id
Akamai-GRN
X-Language
X-Kraken-Loop-Name
X-Middleton-Response
X-PDP-UNCACHING-HASH
X-Server-Lifecycle-Phase
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Instrumentation
Response
X-Envoy-Decorator-Operation
X-Ratelimit-Limit
X-Client-IP
X-Oneagent-Js-Injection
S
Edge-Cache-Tag
AR-PoweredBy
AR-Request-ID
AR-ATIME
X-Resp-Is-Stale
X-Goog-Hash
X-MS-InvokeApp
X-ARC
X-Edge-Location-Klb
X-Kinsta-Cache
X-Ser
X-Distributor
SPIisLatency
X-Content-Digest
SPRequestDuration
SPRequestGuid
X-SharePointHealthScore
Access-Control-Request-Method
X-Cache-Key
X-Ezoic-Cdn
Front-End-Https
X-Dw-Request-Base-Id
X-NGENIX-Cache
X-Recruiting
X-Shield-Request-Id
X-Url
RTSS
X-Amzn-Trace-Id
X-Ttl
X-Varnish-TTL
Cache-Status
X-Version
X-Powered-CMS
Public-Key-Pins
X-Ruxit-Js-Agent
X-T
X-Mg-S
Fastcgi-Cache
TP-Cache
X-MSEdge-Ref
Arr-Disable-Session-Affinity
X-Accel-Expires
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Cache-Config
X-Daa-Tunnel
X-Forwarded-For
X-Correlation-Id
X-Ismobilevalue
X-Fastly-Request-ID
Realpath
X-Cluster-Name
Cache-Tags
X-Cached
X-Id
AR-CACHE
X-HS-Combine-CSS
X-CST
X-Request-Processing-Time
X-Request-Received
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
Payment
X-Content-Security-Policy-Report-Only
X-Ua-Browser
X-DIS-Request-ID
X-Ratelimit-Remaining
Content-MD5
X-Server-Name
X-GUploader-UploadID
X-HP-Trace-Id
X-HP-Webp
X-Jurisdiction
X-Cambria-Cache-Control
X-HS-CF-Cache-Status
X-HS-Prerendered
X-Newrelic-App-Data
Content-Disposition
X-TTL
X-Azure-Ref
Count-Hit
X-Amz-Replication-Status
X-Xrds-Location
X-RateLimit-Remaining
X-Webkit-Csp
X-Px
X-ORACLE-DMS-ECID
X-Page-Id
Accept-Charset
X-Microsite
X-Request-Handler-Origin-Region
Cross-Origin-Resource-Policy
X-Unique-Id
X-Ratelimit-Reset
Cleartype
X-Proxy
X-Logged-In
X-Az
X-AppVersion
X-Protected-By
X-URL
X-FB-Debug
X-Activity-Id
X-Origin-Server
X-Git-Hash
Cross-Origin-Embedder-Policy
X-Rid
X-Www-Served-By
X-VARITI-CCR
YJS-ID
X-SERVER-NAME
X-LLID
X-Load-Cache
X-Template
X-Goog-Metageneration
X-Varnish-Backend
X-SRCache-Store-Status
X-SRCache-Fetch-Status
MicrosoftSharePointTeamServices
X-PressLabs-Stats
Ar-SID
X-Amz-Meta-S3cmd-Attrs
Version
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Forwarded-Proto
Server-Node
X-Geo-Country
X-Upgrade-Enabled
Server-Name
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Hits
X-Request-Device-Id
X-Hostname
X-COUNTRY
X-B3-Sampled
X-Content-Options
X-Frontend
X-Varnish-Server
Section-Io-Cache
X-App-Server
X-TT
Viewport
X-Status
X-Varnish-Grace
X-Device-Type
Mrf-Cache-Status
MRF-Tech
X-B3-TraceId-Primal
Fastly-SIE
X-B
X-Fb-Rlafr
X-Grace
Alternate-Protocol
Fastly-SWR
Access-Control-Allow-Method
TCN
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-Goog-Generation
Upgrade-Insecure-Requests
Healthy
X-Server-ID
X-Request-Guid
X-NF-Request-ID
Amp-Access-Control-Allow-Source-Origin
Host
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-WebKit-CSP-Report-Only
X-Magnolia-Registration
X-Meli-Trace-Platform
X-Meli-Trace-Site
X-Meli-Trace-Bu
X-CSRF-Token
X-Buckets
X-EdgeConnect-Cache-Status
DC
Retry-After
X-Debug
X-Amzn-Remapped-Content-Length
X-Varnish-Ttl
X-Contextid
X-Cache-Control
X-Cache-Age
AKAMAI-GRN
MS-Author-Via
X-Wormhole-Sdk
X-Revision
X-WP-CF-Super-Cache-Cache-Control
X-Type
X-WP-CF-Super-Cache
X-Vcl-Version
X-Original-Request-Id
X-Response-Served-From
X-Instance
AR-SID
Cross-Origin-Embedder-Policy-Report-Only
X-Adobe-Loc
X-Yottaa-Metrics
X-UUID
X-Rendered-As
X-Yottaa-Optimizations
X-Origin-CC
X-Seen-By
X-Origin-TTL
Cross-Origin-Opener-Policy-Report-Only
X-NYM-Debug-Backend
X-Adobe-Content
X-Is-Bot
X-Hl-Ver
Access-Control-Request-Headers
X-Akamai-Edgescape
SD-X-WS
X-G
X-Backend-Name
X-Lambda-Id
Section-Io-Id
Charset
X-Debug-IsConnected
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Tumblr-User
X-Tumblr-Pixel-1
X-Content-Powered-By
X-Debug-IsPreview
X-Framework
X-Mobile
X-Mg-Request-UUID
X-Trace-Id
X-ServerID
X-App-Version
X-RTag
X-Server-W
X-DataDome
X-INCAP-ABP
NGB
Ms-Operation-Id
MS-CV
X-RM-Cache-TTL
X-Storage
X-N
X-ProcessESI
X-AB
X-Akamai-Request-ID2
X-Dc
X-RemovedCookies
X-Cache-Hit
X-Cache-Status-Check
Frame-Options
X-Cache-Time
X-Oracle-Dms-Ecid
Filterid
X-Request-Platform
Refresh
VIX-Pulpo-Upstream-Status
X-B3-SpanId
X-Request-Site
X-Request-Bu
VIX-Pulpo-Node
Cache
X-Time
X-Tec-Api-Root
X-Tec-Api-Version
Accept-Language
X-Tec-Api-Origin
SRV
X-HITS
X-Region
Protected
X-Real-IP
X-Node-Name
Webserver
X-Fastcgi-Cache
Paypal-Debug-Id
CDN-RequestId
Onion-Location
X-Ms-Request-Id
X-User-Agent
X-Ms-Version
X-Requestid
Liferay-Portal
X-CCDN-Origin-Time
X-CCDN-CacheTTL
X-Hcs-Proxy-Type
Cross-Origin-Window-Policy
X-VC-Cache
X-F-Cache
X-LB-Cache
X-Cache-Expired-At
X-Datadog-Trace-Id
X-Datadog-Sampled
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
X-IPS-LoggedIn
X-HTML-Minification-Powered-By
X-Whom
X-WP-CF-Super-Cache-Active
X-Rocket-Nginx-Serving-Static
Priority
X-Mode
OT-Force-Account-Verify
Xet-Cookie
Backend
X-XRDS-Location
X-Pass-Why
GEO-INFO
X-Environment-Context
X-L-Path
X-Tb
X-Proxy-Cache-Info
X-Drupal-Cache-Tags
X-Service
X-App-Environment
X-Cacheable-TTL
X-Browser-Name
X-Handled-By
X-Rewrite-Enabled
X-Cloudmap
X-Rn-Rsrv
Url
Web-Mar-Node
ServerID
X-Adobe-Source
X-FW-Serve
X-Vcache
X-Tncms
X-Tcp-Rtt
X-Is-Mobile
LB
X-Detected-As
X-NewRelic-App-Data
X-Is-Desktop
X-Endurance-Cache-Level
X-Loop
X-Geo-Region
X-UPSTREAM-Address
X-JoinUs
X-MP-GENERATED-AT
X-Extlb
X-Routing-Service
X-Debug-Info
X-Is-Tablet
X-Is-Supported-Browser
X-FW-Version
X-Zipkin-Id
X-Servername
Filters
X-SaId
X-Proxied
X-FW-Type
X-FW-Dynamic
Meta-Geo
Fastcgi-Useragent
X-FW-Static
X-FW-Hash
X-FW-Server
Webcakes-Region
Webcakes-App-Version
Webcakes-App-Name
X-Storefront-Renderer-Rendered
X-Locale
TWC-Locale-Group
TWC-GeoIP-Region
TWC-GeoIP-LatLong
X-Shopify-Stage
Property-Id
X-IPLB-Instance
X-IPLB-Request-ID
X-Web-Node
TWC-Privacy
X-Varnish-Beresp-Grace
X-Hit
TWC-GeoIP-Country
X-Cdn-Origin
TWC-Connection-Speed
X-Origin-Hint
X-Restarts
Atl-Traceid
X-Rule
ServedBy
X-Wix-Request-Id
Country
X-Alternate-Cache-Key
X-Origin-Date
X-Generation-Time
X-Logging-Id
X-Hosted-By
TWC-GeoIP-DMA
TWC-Device-Class
X-Cache-Host
X-Director
TWC-GeoIP-City
X-Format
X-Forwarded-Host
Mn-Server-Ip
X-SayCDN-TTL
X-Soup
X-Scope-Id
X-Say-TTL
Uber-Trace-Id
X-Cms-Context
X-Skip-Cache
X-Redis-Cache
X-Say-Cacheable
X-ProxyCache-Status
X-Cluster
X-Cache-Action
X-Cluster-Node
X-Edge-Location
X-ProxyCache-Key
X-Httpd
X-BYPASS-REASON
Apigw-Requestid
Environment
X-Origin-Cache
X-FB-TRIP-ID
X-RateLimit-Limit-Second
X-Labrador-Cache-Channel
X-Served-From
X-S
X-PHP-Host
X-RateLimit-Remaining-Second
X-Drupal-Cache-Contexts
X-Auth-Group-Type
DB-Nickname
X-Urbn-Context-Path
Locale
Expiry
X-Tumblr-Pixel-2
X-Urbn-Site-Id
X-Timing-Wait
X-Proxy-Build
X-Origin
X-Mly-Id
X-Connection-Hash
X-Fetched-On
Cache-Hits
X-Tumblr-Pixel-3
Selected-Fe
X-VC
X-Yandex-Req-Id
X-ECache
X-R9-Blue-Green-Version
YJS-CacheStatus
X-RCS-CacheZone
X-VCT
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-ShopId
X-GEO
X-ShardId
X-No-Session
X-Cache-Debug
Front
X-Varnish-Cache-Hits
X-UA
X-Is-Modern-Browser
X-SRV
X-WP-CF-Super-Cache-Cookies-Bypass
X-Varnish-Age
X-Source
X-Lagoon
Countrycode
X-Varnish-Beresp-Ttl
Node
Xserver
WPO-Cache-Status
X-Provided-By
X-CLOUD-TRACE-CONTEXT
X-CDN-Forward
X-CACHE-AGE
X-Is-Mobile-Only
X-Api-Version
X-Webstats-RespID
X-Generated-By
X-Site-Version
X-Platform
Cache-Tv-Group
Cache-Provider
From-Origin
X-Presslabs-Stats
Referer-Policy
X-Azure-Ref-OriginShield
X-Cdn
X-Accel-Version
X-CDN-Cache-Status
X-Signature
X-TA-CDN-Provider
X-B-Cache
X-B3-Traceid
X-VC-TTL
X-Xfnlog-Site
X-NWS-UUID-VERIFY
X-PHP-Backend
Location
CF-IPCountry
X-Sucuri-Cache
X-Ua
X-Air-Pt
WPO-Cache-Message
X-Tx-Id
Request-ID
X-TT-LOGID
CDN-RequestPullCode
CDN-CachedAt
X-Tt-Logid
CDN-RequestCountryCode
X-Cache-Rule
CDN-EdgeStorageId
CDN-Cache
CDN-Uid
X-Cache-Operation
X-Optimistic-Header
CDN-RequestPullSuccess
X-Reqid
CDN-PullZone
X-Tb-Optimization-Total-Bytes-Saved
X-IsAdmin
AMP-Access-Control-Allow-Source-Origin
X-A-Dgt
X-A-Dcw
Rendered-Blocks
DCR-Processing-Time-Ms
DCR-Decision-By
Expect-Staple
Fastly-SSL
Lang
Fl-Custom-Application
Cdnsip
Cdncip
Apple-News-Services-Host
Apple-News-Services-Handled
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
Candidate-Md5Url
Log-Origin
MD5-Digest
Store-Cloud-Cache
Sslversion
Time-Cloud-Cache
Web-Mar-Region
X-A-Ccd
X-A
RNT-Time
RNT-Machine
Ngx.Var.Host
Meta-Geo-Continent
Odigeo-Trace-Id
Origin
Redirect-Candidate
X-A-Dam
X-Contensis-Viewer-Groups
X-Rojux
X-Rocket-Build-Number
X-S-Cookie
X-Save-Cache
X-Section
X-ScT
X-Request-URI
X-Origin-Expires
X-Ig-Origin-Region
X-HS-Content-Campaign-Id
X-Ig-Push-State
X-Loc
X-Old-Content-Length
X-Micro-Cache
X-Sigma
X-Sigma-Backend
X-VG-WebCache
X-VG-TLSProxy
X-Viewer-Country
X-Vtex-Remote-Cache
XM
Xc-Version
X-Vdms-Version
X-Vary-Devices
X-Slack-Shared-Secret-Outcome
X-Slack-Backend
X-SRCache-Key
X-Varnish-Authentication
X-Varnish-Director
X-GeoCountry
X-GeoCode
X-Cache-NE
X-Cache-Aspx
X-Clientip
X-Cms-Device
X-Worker
X-Conf
X-Bl-Debug
X-BCube-Filmed-By
X-Aed
X-Access
X-AK-Request-ID
X-Application
X-B-Cookie
X-Auto-Login
X-Content-Age
X-Core-Value
X-Ee-Request-Date
X-Ee-Origin
X-Ee-Request-Id
X-External-Request-Id
X-Forwarded-Site
X-Fmm-Version
X-Ee-Generated-By
X-Ec-GeoHdr
X-Depends
X-D
X-Destination
X-Developer
X-Ec-Fail
X-A-Wwc
X-Action
X-Fastly-Request-Id
X-Frame-Option
X-Sucuri-ID
X-Debug-Cache-Store
X-DefElseHash
X-DefHash
X-Debug-Cache-Fetch
X-CUA
X-Content-Length
X-Csrf-Jwt
X-Ec-Custom-Error
X-Date
X-Eu-Site
X-Generated-On
X-GeoIP-City
X-GeoIP-Country-Code
X-Gen-Mode
X-Gdpr
X-Fastly-Backend
X-FC-Vary-Parameters
X-From
X-Epic-Correlation-Id
X-CGP
Wxu-Next-Commit
Wxu-Next-Hostname
Wxu-Next-Region
X-Accel-Expires-Debug
V-Age
User-Cache-Control
TDXMobile
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
X-Acquia-Purge-Cdn-Unconfigured
X-LSADC-Cache
X-Bc-Bl
X-Block-Status
X-Bug-Bounty
X-BBC-Edge-Cache-Status
X-Backend-Instance
X-Aicache-OS
X-Akamai-Device-Characteristics
X-App-Name
X-GeoIP-Region-Code
X-GoCache-CacheStatus
X-V-Cache
X-Varnish-Beresp-Status
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-Uri
X-Up
X-Thinkindot-L1
X-Thinkindot-L3
X-UA-Device-Type
X-Varnish-Remaining-TTL
X-We-Are-Hiring
X-PERF
X-Req
X-SD-PageType
X-Varnish-Hostname
X-PAYTM-SRV-ID
X-Node-Id
Cluster
Host-ID
X-ApacheServer
X-Sn-Servicetimems
X-SIPLIST1
X-Ion-Hop
X-Jungle-Id
X-Level-Front-Cache
X-Moov-T
X-Ion-Healthy
X-Internal-TTL
X-Hash
X-Hnp-Log
X-Human
X-Moov-Xdn-Caching-Status
X-Moov-Xdn-Version
X-Region-Sid
X-Render-Time
X-Shield-Cache-Expires
X-Pubstack
X-Policy
X-Nyt-Route
X-Origin-Time
X-Path
ServerName
X-Men
IsBot
Gh-Request-Id
Gannett-Cam-Experience-Id
DSUID
L
L5d-Success-Class
Origin-CC
Origin-Agent-Cluster
Nord-Request-ID
Country-Code
Azure-InstanceId
CDCHOST
Cache-Contol
Azure-Version
Azure-SlotName
Azure-SiteName
Cmstype
Cmsid
Azure-RegionName
Origin-EX
Ha-Gx-Prefs
Server-Host
Req-Svc-Chain
RewriteTestHook
RewriteTeamHook
X-SB
Fastly-Backend-Name
Fastly-GeoIP-CountryCode
X-Mvc-Supplant-Cachable
X-Op-Id-All
Content-Script-Type
Content-Style-Type
X-NMSegId
X-Gzip
Tube-Return
X-Gamma-Serve
X-Litespeed-Cache-Control
X-Edge-Server
Machine
X-DPWN-IS-SECURE
X-Org
X-Esi-Check
Tube-Got-Results
We-Hiring
N-Cache
X-Via-Fastly
X-HN
CacheControlHeader
Cdn-Host
Cdn-Request-Time
X-Thanos
C-Via
X-Wikidot-Static-Cache
X-Vmg-Version
X-Vercel-Id
X-Vercel-Cache
X-Wikidot-Backend
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
Tube-Get-Contents
Tube-Got-Eval
X-Dispatcher-Server
X-Proto
X-Amz-Storage-Class
X-AB-Test
Click-Count-Action-Start
Click-Count-Error
X-Server-IP
PFcat
Mail-Subject
X-VarnishDD-TTL
X-Cache-Date
X-Bip
X-Cache-FS-Status
NM-Fastcgi-Cache
X-CacheTTL
X-Cache-Id
Origin-Site
Platform
Release
Pragrma
Producers
X-B3-Trace-ID
X-LJ-Flow-ID
X-Parent-Response-Time
Fastly-Drupal-HTML
X-AWS-Id
X-VWS-Id
Source
X-ZONE
X-Origin-Response-Time
X-Mvc-Supplant-OutputCached
X-ElasticPress-Query
X-Location
Canary
X-Proxied-Request
X-Pad
X-NGINX-Cache
Debug
S-Rt
X-Cs
Powered-By
X-Cached-By
Sid
X-Litespeed-Tag
Product
X-Upstream-Ct
CloudFront-Viewer-Country
Vix-Hermes-Req-Id
X-Upstream-Ht
X-Refresh
X-TH-Server
Pics-Label
NGX
X-Nananana
X-APP
X-Amz-Meta-Cb-Modifiedtime
HA-Ipaddr
X-Via-Popv
X-Via-Poph
X-Via-Popn
X-ND-Cache
GeoIP-Latitude
Mime-Version
X-HA-Backend
X-Servedbyhost
X-Varnish-Hits
X-Cache-VC
X-FORWARDED-FOR
X-Client-Ip
X-Ah-Environment
Server-ID
Cookie
X-Cdn-Forward
X-User
X-Datadome
GeoIp-Country-Code
Edge-Cache
MIME-Version
X-Nginx-Cache
X-Fpc
X-DynaTrace-JS-Agent
X-Wa
X-AIR-PT
X-LB-ID
X-Nc
X-Webkit-CSP
SID
X-GeoIP
Akamai-Mon-Iucid-Del
X-B3-Parentspanid
X-LB-NoCache
Surrogated-Key
X-Request-Start
X-Nginx-Cache-Key
X-Unity-Cache
X-Srv
X-Debug-Service
WZWS-RAY
HostName
X-Zone
Server-Ext
DataCenter
Server-Hostname
X-Scheme
Sever-Int
Resin-Trace
True-Client-Country-4JS
Load-Balancing
Fastly-Drupal-Html
Cdn
Show-Do-Not-Sell-Link
X-CS
X-Vc
X-Cache-Backend
Tcn
N1-Cache
X-Request-Host
X-NodeID
X-Pool
X-VCL-Version
X-RequestId
X-Lsadc-Cache
X-Newrelic-Synthetics
Wsr-Cache
Traceparent
X-Service-Response-Time
X-Cache-Grace
Sm-Log-Id
NtCoent-Length
Lb
X-B3-Spanid
Yak-Timeinfo
X-DataCenter
Yjs-Id
X-Vgn-Hpd-Reason
X-DynaTrace
X-Via-Edge
X-Via-SSL
X-HOST
X-TX-ID
X-Datacenter
Datacenter
Edge-Copy-Time
X-LiteSpeed-Cache-Control
X-Via-CDN
X-Air-Trace-Id
X-Air-Source
X-NODE
X-Air-Hostname
X-HubSpot-Correlation-Id
X-Dynatrace-Js-Agent
X-API-Version
X-Geolocation
X-RateLimit-Limit
Hostname
Serverhost
X-Zen-Fury
X-CDN-Provider
X-Srcache-Store-Status
X-Srcache-Fetch-Status
XkeyR9
X-Proxy-CacheR9
X-WA
X-Udemy-Cache-App-Namespace
Cdn-Requestid
X-Jobs
X-Proxy-Cache-La3
Xkeylog
Req-ID
Xkey-La3
CDN
X-LiteSpeed-Tag
CountryCode
X-NC
Uri
A
X-FPC
X-Cdn-Srv
X-Fastly-Backend-Reqs
X-ID
X-Lb-Id
X-Ez-Minify-Html
X-Powered-By-VTEX-Cache
WP-Super-Cache
True-Client-IP
Server-Id
X-Akamai-Pragma-Client-IP
X-Html-Minification-Powered-By
X-VTEX-Cache-Server
Proxy-Firewall
X-VTEX-Cache-Time
GeoIP-Country-Code
T-Server
X-TimeS
Esi-Enabled
RATING
Geoip-Latitude
X-Ez-Minify-Js
X-Via-JSL
X-Stale
On-Server
Cs
X-Webkit-Csp-Report-Only
X-VC-Age
Srv
X-ServedByHost
X-Lb-Nocache
X-Varnish-Beresp-TTL
Coldstone-Viewer-Country
ServerHost
Coldstone-Viewer-Currency
From-Cache
X-Swift-Error
X-WA-Info
Coldstone-Viewer-Country-Region-Name
X-Oracle-DMS-ECID
WebServer
X-App
X-Styx-Origin-Id
Ngx
X-HA-Bot-Classification
X-HA-Device-Type
X-CSRF-TOKEN
X-Styx-Info
Cloudfront-Viewer-Country
X-HA-Application-Name
X-Ha-Backend
Pramga
Cr
X-Wp-Cf-Super-Cache-Cache-Control
X-Wp-Cf-Super-Cache
X-LAGOON
X-TIM-N
X-Fastly-Cache
X-Ssense-Shipping-Surcharge-Enabled
Content-Secure-Policy
BehaviorPad-Version
X-Correlation-ID
X-Via-PopN
X-Ssense-Gql
X-Via-PopH
X-Var-Ttl
FSS-Cache
X-MSEdge-Features
X-MSEdge-Flight
X-Via-PopV
X-Sorting-Hat-Podid
X-Sucuri-Id
X-Sorting-Hat-Shopid
X-Geo
W
X-Web-Server
X-Cdn-Cache-Status
X-Shopid
X-Check-Cacheable
X-Shardid
X-Elasticpress-Query
Xkey-G-Jp
Cl-Cache
X-Th-Server
X-Proxy-Cache-LA2
X-DC
X-Request-Time
X-Nitro-Cache
X-Request-Url
X-ATG-Version
X-Wp-Cf-Super-Cache-Active
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-Serial
Akamai-X-True-TTL
My-App
Cf-Ipcountry
True-Client-Ip
X-Ramcache
User-Agent
X-Cache-TTL-Remaining
X-Mg-Cache
Host-Name
X-Env
X-Fastly-Cache-Status
FSS-Proxy
Bxuuid
X-Fastly-Cache-Hits
Cneonction
Bxpunish