Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
CF-RAY
Expect-CT
Accept-Ranges
X-XSS-Protection
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-Xss-Protection
X-UA-Compatible
X-Served-By
X-Download-Options
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
X-DNS-Prefetch-Control
Accept-CH
Content-Security-Policy-Report-Only
Accept-CH-Lifetime
X-Runtime
X-Check
X-AspNet-Version
X-Drupal-Cache
X-Ua-Compatible
X-Generator
X-Cache-Status
Server-Timing
X-Cacheable
Timing-Allow-Origin
X-Envoy-Upstream-Service-Time
X-FRAME-OPTIONS
X-Request-ID
X-Iinfo
X-Drupal-Dynamic-Cache
X-Content-Security-Policy
Feature-Policy
Access-Control-Expose-Headers
Content-Encoding
X-CDN
Upgrade
Status
X-AspNetMvc-Version
CF-Ray
Access-Control-Max-Age
X-Amz-Request-Id
Cf-Edge-Cache
X-Amz-Id-2
Permissions-Policy
Host-Header
X-Via
EagleId
Keep-Alive
X-Cache-Group
Request-Context
X-Robots-Tag
P3p
X-Backend
X-AH-Environment
X-Hacker
X-UA-Device
X-Proxy-Cache
X-Server
X-Turbo-Charged-By
X-Rq
X-Age
X-Ws-Request-Id
X-Vhost
Cf-Apo-Via
X-Amz-Version-Id
Xkey
X-Dispatcher
X-Swift-CacheTime
X-Swift-SaveTime
Grace
X-Server-Powered-By
Ali-Swift-Global-Savetime
Allow
X-Varnish-Cache
X-LiteSpeed-Cache
X-OneAgent-JS-Injection
X-Page-Speed
X-Pingback
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
X-WebKit-CSP
X-Cache-Lookup
EagleEye-TraceId
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Host
X-Backend-Server
Cf-Railgun
X-Server-Id
X-Response-Time
X-Readtime
X-Akam-SW-Version
Surrogate-Control
X-Ruxit-JS-Agent
X-HW
X-Node
Request-Id
X-Litespeed-Cache
X-Dns-Prefetch-Control
X-Cloud-Trace-Context
X-Country
X-Nginx-Cache-Status
Content-Location
X-Application-Context
Accept-Ch-Lifetime
X-Nginx-Upstream-Cache-Status
X-ASPNET-VERSION
X-NWS-LOG-UUID
X-Country-Code
Service-Worker-Allowed
X-Content-Type
X-Trace
X-Url
Cache-Tag
X-Clacks-Overhead
X-Amz-Server-Side-Encryption
Rating
X-Times
X-Vname
X-PC
X-TtlSet
X-Rack-Cache
Cross-Origin-Opener-Policy
X-Mcache
X-Edge
X-Midtier
X-Browser-Type
X-Server-Name
X-Daa-Tunnel
Accept-Ch
AR-SID
AR-PoweredBy
AR-ATIME
AR-Request-ID
Nginx-Cache
X-ESI
X-Cache-TTL
X-Powered-By-Plesk
X-Cnection
X-D2id
X-Ac
X-GitHub-Request-Id
X-Element-Page-Cache
Edge-Control
X-Kinja-Build
Verso
X-Cdn-Fetch
X-GoogleNews-Bot
X-Exp-Id
X-Kinja
X-Kinja-Server
X-Exp-Variant
X-Kinja-Revision
X-FTR-Request-ID
X-CST
AR-CACHE
X-MS-InvokeApp
X-Ser
X-Vcap-Request-Id
X-Abt-Application-Version
X-Dw-Request-Base-Id
Fastly-Restarts
X-Navigation-Version
X-Upstream
X-B3-TraceId
X-ECACHE
X-FastCGI-Cache
SPRequestDuration
SPIisLatency
X-Mod-Pagespeed
X-Amz-Rid
X-Instrumentation
X-PDP-UNCACHING-HASH
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-ARC
X-Client-IP
X-Goog-Hash
SPRequestGuid
X-SharePointHealthScore
X-Kinsta-Cache
X-Edge-Location-Klb
X-Middleton-Display
X-Sol
Display
Pagespeed
X-Powered-CMS
X-Oneagent-Js-Injection
X-Ratelimit-Limit
X-Webkit-Csp
X-Mg-S
X-Amzn-Trace-Id
Cache-Status
Edge-Cache-Tag
S
X-Version
Access-Control-Request-Method
Response
X-Middleton-Response
X-VARITI-CCR
RTSS
X-Forwarded-For
Realpath
X-Ua-Device
X-T
X-Cache-Key
Cross-Origin-Resource-Policy
X-Ratelimit-Remaining
X-TTL
X-NF-Request-ID
X-Content-Digest
Fastcgi-Cache
X-Cached
X-Recruiting
X-Correlation-Id
X-ORACLE-DMS-RID
X-MSEdge-Ref
X-Shield-Request-Id
X-TraceId
MicrosoftSharePointTeamServices
X-Fastly-Request-ID
Front-End-Https
X-PressLabs-Stats
X-RateLimit-Remaining
X-Ruxit-Js-Agent
X-Forwarded-Proto
Public-Key-Pins
X-Request-Processing-Time
Arr-Disable-Session-Affinity
X-Ua-Browser
X-Request-Received
Payment
X-HS-Cache-Config
X-LLID
TP-Cache
X-HS-Hub-Id
X-HS-Content-Id
Server-Node
Count-Hit
X-Frontend
X-Protected-By
X-Newrelic-App-Data
Surrogate-Key
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-LB-Cache
X-GUploader-UploadID
X-Server-ID
X-Varnish-TTL
MS-Author-Via
X-Accel-Expires
X-HS-Combine-CSS
X-Distributor
Content-MD5
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-NODE
X-Origin-Server
X-Ezoic-Cdn
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Content-Security-Policy-Report-Only
X-ORACLE-DMS-ECID
X-Microsite
X-Request-Handler-Origin-Region
X-Www-Served-By
X-Jurisdiction
X-App-Server
X-HP-Webp
Mrf-Cache-Status
X-AppVersion
X-HP-Trace-Id
X-B3-TraceId-Primal
MRF-Tech
X-Activity-Id
Accept-Charset
X-Az
X-Amz-Meta-S3cmd-Attrs
Cleartype
X-Varnish-Server
Host
X-Cluster-Name
Retry-After
Cache-Tags
X-Varnish-Backend
X-Goog-Metageneration
Filterid
X-Ttl
X-Unique-Id
X-FTR-Backend-Server
X-Debug
X-FTR-Backend
X-FTR-Cache-Status
X-FTR-Balancer
X-Country-Code-Real
X-Hits
X-Git-Hash
Access-Control-Allow-Method
X-FTR-Expires
X-Aspnet-Version
X-Logged-In
Server-Name
X-Load-Cache
X-Upgrade-Enabled
X-Varnish-Ttl
X-Id
X-Azure-Ref
X-FB-Debug
X-Hostname
X-Envoy-Decorator-Operation
X-NGENIX-Cache
X-CSRF-Token
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Geo-Country
TCN
X-TT
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-B
X-Proxy
Section-Io-Cache
X-Seen-By
X-Request-Guid
X-Nf-Request-Id
X-Cache-Control
DC
X-Grace
Viewport
X-Revision
X-Ratelimit-Reset
X-Fb-Rlafr
X-Trace-Id
X-Type
X-Contextid
X-B3-Sampled
Healthy
TP-L2-Cache
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Generation
Fastly-SIE
Fastly-SWR
Content-Disposition
X-Time
X-N
X-XRDS-LOCATION
X-F-Cache
X-CCDN-CacheTTL
X-Hcs-Proxy-Type
X-CCDN-Origin-Time
X-Mobile
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
Paypal-Debug-Id
X-Varnish-Grace
X-Amz-Replication-Status
X-Magnolia-Registration
X-Via-JSL
Referer-Policy
X-Webkit-CSP
X-Ismobilevalue
X-Origin-Cache
X-Wormhole-Sdk
X-DIS-Request-ID
X-Oracle-Dms-Ecid
X-Page-Id
X-Debug-Info
Pinterest-Version
Pinterest-Generated-By
Version
X-Pinterest-Rid
X-G
X-RemovedCookies
X-Content-Options
X-ProcessESI
X-UUID
X-Adobe-Loc
X-Tumblr-User
X-Tumblr-Pixel-1
X-Datadog-Sampling-Priority
X-Rule
X-App-Environment
X-Node-Name
X-Debug-IsConnected
X-Datadog-Trace-Id
X-Datadog-Parent-Id
X-Tumblr-Pixel
X-Adobe-Content
X-Source
X-Tumblr-Pixel-0
X-Debug-IsPreview
X-Px
X-Template
SD-X-WS
NGB
Ms-Operation-Id
VIX-Pulpo-Node
X-Datadog-Sampled
X-Hl-Ver
VIX-Pulpo-Upstream-Status
MS-CV
X-RTag
X-Yottaa-Optimizations
X-Yottaa-Metrics
Cross-Origin-Window-Policy
X-Storage
X-Instance
X-Cacheable-TTL
X-Device-Type
X-Backend-Name
X-Is-Bot
X-Wix-Request-Id
X-User-Agent
X-NYM-Debug-Backend
X-Rendered-As
X-Proxy-Cache-Info
X-Region
X-Environment-Context
X-FW-Dynamic
X-Whom
GEO-INFO
X-FW-Version
X-FW-Hash
X-ServerID
X-L-Path
Country
X-FW-Type
X-Status
X-FW-Serve
X-FW-Static
X-FW-Server
X-Signature
X-Cache-Age
X-B-Cache
X-RM-Cache-TTL
Countrycode
Front
Amp-Access-Control-Allow-Source-Origin
X-NWS-UUID-VERIFY
X-IPS-LoggedIn
X-Rid
X-Fastly-Request-Id
Charset
ServerID
X-Framework
Akamai-GRN
X-WP-CF-Super-Cache-Active
X-EdgeConnect-Cache-Status
X-Real-IP
X-AB
X-ECache
SRV
X-Cache-Grace
X-Api-Version
X-Language
X-WebKit-CSP-Report-Only
X-Amzn-Remapped-Content-Length
Liferay-Portal
X-Oracle-Dms-Rid
X-Akamai-Request-ID2
X-B3-SpanId
X-Content-Powered-By
X-Cache-Hit
X-Air-Pt
Accept-Language
X-VC
X-DataDome
X-Air-Hostname
X-Air-Source
OT-Force-Account-Verify
X-Air-Trace-Id
X-Xrds-Location
X-UA
X-Mode
X-Servername
X-URL
Webserver
X-Cache-Status-Check
Access-Control-Request-Headers
X-VC-Cache
X-Sucuri-Cache
X-Sucuri-ID
Xet-Cookie
LB
From-Origin
Backend
Refresh
X-SRV
X-HTML-Minification-Powered-By
X-Mg-Request-UUID
X-RID
Upgrade-Insecure-Requests
X-Rewrite-Enabled
X-Vcl-Version
X-UPSTREAM-Address
X-Handled-By
X-Rn-Rsrv
X-Tt-Logid
X-JoinUs
Filters
Meta-Geo
X-SaId
X-Varnish-Age
X-Tumblr-Pixel-2
X-Origin-Date
X-PHP-Host
X-Adobe-Source
X-Webstats-RespID
X-Request-URI
X-Provided-By
X-R9-Blue-Green-Version
X-RCS-CacheZone
X-Cms-Context
X-Hosted-By
X-Labrador-Cache-Channel
X-Generated-By
X-S
X-Vcache
X-Cache-Time
Property-Id
X-Storefront-Renderer-Rendered
Onion-Location
X-ProxyCache-Status
X-Reqid
Section-Io-Id
X-Restarts
X-Redis-Cache
Apigw-Requestid
X-Tb
X-ProxyCache-Key
TWC-Privacy
X-Geo-Region
X-Httpd
X-Forwarded-Host
X-Fetched-On
X-Cache-Debug
X-Cache-Host
X-Is-Desktop
X-Is-Mobile
X-Logging-Id
X-Loop
X-Locale
X-Lambda-Id
X-Is-Supported-Browser
X-Is-Tablet
X-BYPASS-REASON
X-Browser-Name
TWC-Locale-Group
X-Skip-Cache
TWC-GeoIP-LatLong
TWC-GeoIP-Country
TWC-Connection-Speed
TWC-Device-Class
Webcakes-App-Name
Webcakes-App-Version
X-Akamai-Edgescape
X-Alternate-Cache-Key
X-Accel-Version
X-Origin-Hint
Webcakes-Region
ServedBy
Atl-Traceid
X-Web-Node
X-No-Session
X-Scope-Id
X-RateLimit-Limit
Xserver
X-Tncms
X-Served-From
X-Tcp-Rtt
X-Site-Version
X-Shopify-Stage
Url
Web-Mar-Node
X-Say-TTL
X-Proxy-Build
Mn-Server-Ip
Selected-Fe
Expiry
X-Upstream-Ht
X-Nginx-Cache
X-Origin
X-IPLB-Request-ID
X-IPLB-Instance
X-VCT
X-Timing-Wait
X-Varnish-Cache-Hits
X-Git-Commit
X-Frame-Option
X-Container-Uri
X-Cluster
X-Detected-As
X-Director
X-Format
X-Varnish-Beresp-Grace
X-Xfnlog-Site
X-SayCDN-TTL
X-Upstream-Ct
X-Connection-Hash
X-Soup
Cache
X-Say-Cacheable
X-Zipkin-Id
X-Sorting-Hat-PodId
X-VWS-Id
X-Cloudmap
X-Sorting-Hat-ShopId
X-Routing-Service
X-Extlb
X-Optimistic-Header
X-ShopId
X-AWS-Id
X-ShardId
X-LJ-Flow-ID
X-Proxied
X-Cache-Operation
X-Cache-Rule
X-Cache-Expired-At
X-Ms-Version
X-Ms-Request-Id
X-Endurance-Cache-Level
X-Edge-Location
X-Lagoon
X-INCAP-ABP
X-WP-CF-Super-Cache-Cookies-Bypass
Priority
CF-IPCountry
Frame-Options
Cdn-Requestid
Fastcgi-Useragent
Environment
Source
X-GeoCountry
WPO-Cache-Message
WPO-Cache-Status
X-GeoCode
X-Fastcgi-Cache
Protected
X-Cache-Action
X-Proxy-Cache-Status
X-Azure-Ref-OriginShield
Uber-Trace-Id
X-Cdn-Origin
Thinkindot-CacheControl-Type
TDXMobile
X-Origin-TTL
Thinkindot-Control
X-Cluster-Node
X-CDN-Forward
X-Generation-Time
X-Shield-Cache-Expires
X-CMSURLCustom
X-Thinkindot-L3
Thinkindot-CacheControl
X-PHP-Backend
X-Origin-CC
X-Drupal-Cache-Tags
X-Drupal-Cache-Contexts
Locale
X-Urbn-Context-Path
X-Urbn-Site-Id
X-ID
X-Pass-Why
Sid
X-Worker
X-Aspnetmvc-Version
X-Rocket-Nginx-Serving-Static
X-Aws-Lambda-Call-Status
X-CLOUD-TRACE-CONTEXT
X-FB-TRIP-ID
X-App-Version
X-GEO
X-Buckets
Cache-Tv-Group
AMP-Access-Control-Allow-Source-Origin
Azure-SlotName
Azure-Version
X-Auth-Group-Type
X-XRDS-Location
Azure-InstanceId
Azure-RegionName
Azure-SiteName
Node
CDN-Uid
CDN-EdgeStorageId
CDN-PullZone
CDN-RequestCountryCode
CDN-RequestPullCode
CDN-CachedAt
CDN-Cache
CDN-RequestPullSuccess
X-B3-Traceid
X-Vercel-Cache
X-Vercel-Id
X-Server-W
Cache-Hits
X-Pad
Cross-Origin-Embedder-Policy
X-Tumblr-Pixel-3
Alternate-Protocol
X-LiteSpeed-Cache-Control
X-LSADC-Cache
X-Dc
X-A
X-Client-Ip
X-D
X-DefElseHash
X-DefHash
A
X-Custom-Header
X-Core-Value
Candidate-Md5Url
X-Conf
X-Content-Age
X-Cache-Server
X-Ig-Origin-Region
X-Gzip
X-Edge-Server
X-Ec-GeoHdr
X-Epic-Correlation-Id
X-Esi-Check
X-Fastly-Backend
X-Ec-Fail
X-Cache-NE
X-Developer
X-Ig-Push-State
X-Dispatcher-Server
X-Service
X-GeoIP-City
X-Cache-Id
Meta-Geo-Continent
T-Server
MD5-Digest
Magicmarker
X-A-Ccd
Lang
Surrogated-Key
Ngx.Var.Host
Origin-Agent-Cluster
Rendered-Blocks
Server-Info
Odigeo-Trace-Id
Sslversion
Gannett-Cam-Experience-Id
X-A-Dam
Content-Secure-Policy
X-Bc-Bl
X-BCube-Filmed-By
X-Bl-Debug
Cdn-Request-Time
X-Level-Front-Cache
DB-Nickname
DCR-Decision-By
X-A-Dgt
X-A-Dcw
X-A-Wwc
X-Aed
DCR-Processing-Time-Ms
Cdn-Host
X-Generated-On
X-TIM-N
X-V-Cache
X-NGINX-Cache
X-Rojux
X-Origin-Expires
X-Req
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-Viewer-Country
X-Vtex-Remote-Cache
X-Via-Fastly
X-Vdms-Version
X-Varnish-Remaining-TTL
X-Org
X-ScT
X-ND-Cache
User-Cache-Control
Mime-Version
X-TA-CDN-Provider
X-VTEX-Cache-Server
X-UA-Device-Type
X-Acquia-Purge-Cdn-Unconfigured
X-Node-Id
X-NMSegId
Req-ID
Wxu-Next-Region
X-Mvc-Supplant-OutputCached
X-Varnish-Director
X-Jobs
X-Aicache-OS
X-AK-Request-ID
X-B3-Trace-ID
X-Backend-Instance
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-App-Name
X-Tb-Optimization-Total-Bytes-Saved
X-Amz-Storage-Class
X-Thanos
X-Test
Wxu-Next-Hostname
Wxu-Next-Commit
RNT-Machine
X-Micro-Cache
X-Men
X-VG-WebCache
Ssr
X-Wikidot-Static-Cache
X-VTEX-Cache-Time
Server-Host
X-Mly-Id
X-Wikidot-Backend
X-VG-TLSProxy
True-Client-Country-4JS
Tube-Return
V-Age
X-SRCache-Key
Vix-Hermes-Req-Id
Tube-Got-Results
Tube-Got-Eval
X-Loc
Tube-Get-Contents
X-VarnishDD-TTL
RNT-Time
X-Sn-Servicetimems
X-Origin-Response-Time
X-Hnp-Log
X-Fastly-Cache
X-FC-Vary-Parameters
X-Origin-Time
X-PAYTM-SRV-ID
X-DPWN-IS-SECURE
X-Powered-By-VTEX-Cache
X-Policy
X-Platform
X-Fmm-Version
X-Forwarded-Site
X-GeoIP-Country-Code
X-GeoIP-Region-Code
Producers
X-GoCache-CacheStatus
X-Op-Id-All
X-GeoIP
X-Gdpr
X-Gen-Mode
X-HN
X-Geo-Header
X-Proto
BehaviorPad-Version
X-SD-PageType
X-HS-Content-Campaign-Id
X-Mvc-Supplant-Cachable
X-Cache-TTL-Remaining
X-Cache-Info
X-Server-IP
X-Nyt-Route
X-Block-Status
X-Cache-Bucket
X-Cache-FS-Status
X-Scheme
X-CacheTTL
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-Pubstack
XM
X-Debug-Cache-Store
X-Region-Sid
X-Clientip
X-SB
X-Request-Time
X-NodeID
X-Bip
X-Debug-Cache-Fetch
Fastly-Backend-Name
Adler-Geo
AKAMAI
Esi-Enabled
Cache-Provider
Is-Eu
Edge-Cache
NM-Fastcgi-Cache
Host-ID
X-Tx-Id
Cdncip
Click-Count-Error
Content-Style-Type
Platform
Content-Script-Type
Cdnsip
Country-Code
Click-Count-Action-Start
Fastly-SSL
PFcat
X-Varnish-Beresp-Ttl
X-DC
X-HITS
Apple-News-Services-Parsed-Url
X-CUA
X-Csrf-Jwt
Cache-Key
Canary
CDCHOST
X-Cache-Aspx
X-Cdn-Srv
X-CGP
C-Via
X-Contensis-Viewer-Groups
Apple-News-Services-Host
Apple-News-Services-Request-Url
X-Ec-Custom-Error
X-Var-Ttl
X-Varnish-Authentication
X-Slack-Shared-Secret-Outcome
X-Slack-Backend
X-Section
X-Varnish-Beresp-Status
X-Varnish-Hostname
Yak-Timeinfo
HostName
X-We-Are-Hiring
X-Varnishpool
Powered-By
X-Request-Host
Cluster
X-Eu-Site
X-Depends
Apple-News-Services-Handled
X-Cs
X-Hash
X-Human
X-Proxied-Request
X-Pool
X-Nginx-Cache-Key
X-Location
X-Date
X-Request-Start
L
L5d-Success-Class
Machine
Mail-Subject
HA-Ipaddr
W
Gh-Request-Id
Ha-Gx-Prefs
Web-Mar-Region
We-Hiring
NGX
Sever-Int
Req-Svc-Chain
Release
Proxy-Firewall
Pramga
Origin-CC
Server-Ext
On-Server
Server-Hostname
Origin
Fastly-GeoIP-CountryCode
Origin-EX
X-Auto-Login
X-BBC-Edge-Cache-Status
X-Accel-Expires-Debug
X-Access
DSUID
Debug
X-AIR-PT
X-Newrelic-Synthetics
Fusion-Template-Id
Fusion-Source
X-APP
X-MP-GENERATED-AT
X-LB-ID
Fusion-Content-Id
X-WA-Info
X-Varnish-Hits
Fusion-Component-Id
Fusion-Content-Source
Fusion-Deployment-Id
X-Ad-Load-Variation
Redirect-Candidate
X-Tec-Api-Origin
X-Tec-Api-Root
X-Tec-Api-Version
X-HA-Backend
X-Device-Os
X-Via-Poph
X-Via-Popv
X-Content-Length
X-Via-Popn
X-LiteSpeed-Tag
X-Zone
Pics-Label
GeoIP-Latitude
X-VHOST
X-CACHE-AGE
Vc-Max-Age
SID
Fastly-Drupal-HTML
X-Nananana
X-Refresh
CloudFront-Viewer-Country
X-Up
CDN-RequestId
X-NCache
X-From
X-Dispatcher-Number
Fastly-Drupal-Html
X-Akamai-Transformed
Product
X-B3-Parentspanid
X-Servedbyhost
X-Jungle-Id
X-LB-NoCache
X-Cache-Backend
X-CDN-Cache-Status
X-Parent-Response-Time
X-Nc
X-RateLimit-Reset
X-ZONE
X-Datadome
X-Vdms-Path
X-CACHE-KEY
X-Litespeed-Tag
X-DynaTrace-JS-Agent
X-RequestId
X-Cached-By
Resin-Trace
X-Ckpd-Fst-Backend
Server-ID
S-Rt
X-Uri
X-Wa
GeoIp-Country-Code
X-Bug-Bounty
WP-Super-Cache
X-B3-Spanid
X-VC-TTL
X-CS
X-ApacheServer
Datacenter
X-Render-Time
X-M-Reqid
Cdn
X-M-Log
X-Amz-Meta-Cb-Modifiedtime
ServerName
X-PERF
X-HubSpot-Correlation-Id
X-IAuth-Set-Uid
NtCoent-Length
FSS-Cache
X-TX-ID
Uri
X-Varnish-Beresp-TTL
X-TT-LOGID
True-Client-IP
X-Fpc
X-SERVER-NAME
True-Client-Ip
Serverhost
X-Vmg-Version
X-Nf-Language
Locid
X-Nf-Country
Srv
X-Nf-Ats-Version
ServerHost
X-Cdn-Forward
X-Akamai-Device-Characteristics
X-FPC
User-Agent
X-Info
X-Gamma-Serve
X-TIME
X-Origin-Cache-Key
Tcn
X-Srv
X-WA
GeoIP-Country-Code
CDN
X-Dynatrace-Js-Agent
Xc-Version
X-NewRelic-App-Data
X-Hit
Request-ID
X-APP-VERSION
X-Old-Content-Length
CacheControlHeader
X-VCache
X-Vc
X-HostName
X-Cdn-Cache-Status
Expect-Staple
X-V
X-Amz-Meta-Opti
X-NC
Server-Id
Ngx-Var-Key
X-Geo
Hostname
X-COUNTRY
X-Vgn-Hpd-Reason
X-Response-Served-From
X-Moov-Xdn-Version
X-Webkit-Csp-Report-Only
X-Moov-T
X-FL-QIT-DEBUG
Srvid
Cneonction
X-Original-Request-Id
X-Presslabs-Stats
X-Rollout
Cloudfront-Viewer-Country
X-Platform-Server
X-New
X-Eligible
X-Esi
X-ServedByHost
N-Cache
X-TH-Server
WZWS-RAY
X-Lb-Nocache
XkeyRZ
X-Limited
PICS-Label
X-Dispatch
Geoip-Latitude
Permission-Policy
X-Proxy-CacheRZ
Origin-Trial
Cf-Ipcountry
X-Oracle-DMS-ECID
X-VCL-Version
Ohc-File-Size
X-Ftr-Request-Id
X-Internal-TTL
X-Platform-Router
X-Via-PopH
X-ElasticPress-Query
X-Platform-Cluster
X-Ha-Backend
Cf-Device-Type
X-Via-PopN
X-Via-PopV
X-Platform-Processor
Cl-Cache
X-B-Cookie
Cross-Origin-Embedder-Policy-Report-Only
X-Ua
X-Correlation-ID
X-External-Request-Id
X-User
X-App
X-Destination
X-EC-Lua
X-Path
X-S-Cookie
X-Akamai-Pragma-Client-IP
X-Application
Rtss
X-Sqd-Ctime
X-Lb-Id
X-Sqd-Stime
X-VTEX-Cache-Backend-Header-Time
X-VTEX-Cache-Backend-Connect-Time
IsBot
X-SIPLIST1
X-Zen-Fury
X-Srcache-Store-Status
X-Srcache-Fetch-Status
X-Check-Cacheable
X-Serial
X-Wp-Cf-Super-Cache-Cache-Control
X-Cambria-Cache-Control
Lb
X-Wp-Cf-Super-Cache
X-Acquia-Site
X-Acquia-Purge-Tags
X-Fastly-Backend-Reqs
X-Acquia-Application-UUID
Pragrma
Edge-Copy-Time
Timeexpire
X-Sigma
X-Rocket-Build-Number
X-Sigma-Backend
X-Cache-Date
Ohc-Cache-HIT
X-Acquia-Application-Trace
X-Instance-Name
X-MiniProfiler-Ids
X-MSEdge-Features
Sm-Log-Id
X-Cdn-Request-ID
X-Web-Server
X-Service-Response-Time
X-Via-CDN
X-Via-Edge
Epwk-X-Cache
X-MSEdge-Flight
Cmstype
Cmsid
X-Via-SSL
X-Irp-Debug
X-DynaTrace
Servername
X-LAGOON
X-CSRF-TOKEN
CountryCode
X-Litespeed-Cache-Control
Xkeylog
X-Proxy-Cache-La3
Akamai-Mon-Iucid-Del
X-Fastly-Cache-Hits
Trailer
X-AB-Test
X-Requestid
Xkey-La3
X-Ramcache
Warning
Ngx
X-Datacenter
X-Amz-Meta-S3b-Last-Modified
X-Amz-Meta-Sha256
X-Snapshot-Date
X-Th-Server
X-RAMCache
X-Segment-20210421
X-VServer
X-Branch-Name
X-Udemy-Cache-App-Namespace
X-API-Version
X-Sorting-Hat-Podid
X-Sorting-Hat-Shopid
Wpo-Cache-Message
Wpo-Cache-Status
X-Shopid
X-Shardid
X-Dw-Trace-Id
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
X-Origin-Upstream-Status
Fl-Custom-Application