Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
CF-RAY
Expect-CT
Accept-Ranges
X-XSS-Protection
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-Xss-Protection
X-UA-Compatible
X-Served-By
X-Download-Options
X-Timer
X-Request-Id
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
X-DNS-Prefetch-Control
Content-Security-Policy-Report-Only
Accept-CH
Accept-CH-Lifetime
X-Runtime
X-Check
X-AspNet-Version
X-Drupal-Cache
X-Ua-Compatible
X-Generator
X-Cache-Status
Server-Timing
X-Cacheable
Timing-Allow-Origin
X-Envoy-Upstream-Service-Time
X-FRAME-OPTIONS
X-Iinfo
X-Request-ID
X-Drupal-Dynamic-Cache
X-Content-Security-Policy
Feature-Policy
Access-Control-Expose-Headers
Content-Encoding
X-CDN
Upgrade
Status
X-AspNetMvc-Version
CF-Ray
Access-Control-Max-Age
X-Amz-Request-Id
Cf-Edge-Cache
X-Amz-Id-2
Permissions-Policy
Host-Header
X-Via
EagleId
Keep-Alive
X-Cache-Group
Request-Context
X-Robots-Tag
X-Backend
X-AH-Environment
X-Hacker
X-UA-Device
X-Proxy-Cache
X-Server
X-Turbo-Charged-By
X-Rq
X-Age
X-Ws-Request-Id
Cf-Apo-Via
X-Vhost
X-Amz-Version-Id
Xkey
X-Dispatcher
X-Swift-CacheTime
X-Swift-SaveTime
Grace
X-Server-Powered-By
Ali-Swift-Global-Savetime
Allow
X-Varnish-Cache
P3p
X-LiteSpeed-Cache
X-OneAgent-JS-Injection
X-Page-Speed
X-Pingback
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Device
X-Cache-Lookup
EagleEye-TraceId
X-WebKit-CSP
X-Host
X-Backend-Server
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
Cf-Railgun
X-Server-Id
X-Dns-Prefetch-Control
X-Response-Time
X-Readtime
X-Akam-SW-Version
Surrogate-Control
X-Ruxit-JS-Agent
X-HW
X-Node
Request-Id
X-Litespeed-Cache
Accept-Ch
X-Cloud-Trace-Context
X-Country
X-Nginx-Cache-Status
Content-Location
X-Application-Context
Accept-Ch-Lifetime
X-Nginx-Upstream-Cache-Status
X-ASPNET-VERSION
X-NWS-LOG-UUID
X-Country-Code
Service-Worker-Allowed
X-Content-Type
X-Trace
X-Url
Cache-Tag
X-Clacks-Overhead
X-Amz-Server-Side-Encryption
Rating
X-Times
X-Vname
X-TtlSet
X-PC
X-Rack-Cache
Cross-Origin-Opener-Policy
X-Edge
X-Mcache
X-Midtier
X-Server-Name
X-Browser-Type
X-Daa-Tunnel
Nginx-Cache
X-ESI
X-Cache-TTL
AR-Request-ID
AR-ATIME
AR-SID
AR-PoweredBy
X-Powered-By-Plesk
X-Cnection
X-Ac
X-D2id
X-GitHub-Request-Id
X-Element-Page-Cache
Edge-Control
Verso
X-Kinja
X-GoogleNews-Bot
X-Cdn-Fetch
X-Kinja-Revision
X-Exp-Variant
X-Kinja-Server
X-Exp-Id
X-Kinja-Build
X-CST
X-FTR-Request-ID
AR-CACHE
X-MS-InvokeApp
X-Ser
X-Vcap-Request-Id
X-Abt-Application-Version
X-Dw-Request-Base-Id
X-Navigation-Version
Fastly-Restarts
X-Upstream
X-Webkit-Csp
X-B3-TraceId
X-ECACHE
SPIisLatency
SPRequestDuration
X-FastCGI-Cache
X-Amz-Rid
X-Mod-Pagespeed
X-ARC
X-Erf-Bev-Bev
X-PDP-UNCACHING-HASH
X-Erf-Bev-Bev-Is-Generated
X-Server-Lifecycle-Phase
X-Instrumentation
X-Kraken-Loop-Name
X-Goog-Hash
X-Client-IP
SPRequestGuid
X-SharePointHealthScore
X-Edge-Location-Klb
X-Kinsta-Cache
X-Sol
X-Middleton-Display
Display
Pagespeed
X-Oneagent-Js-Injection
X-Powered-CMS
X-Ratelimit-Limit
X-Mg-S
X-Amzn-Trace-Id
Edge-Cache-Tag
Cache-Status
S
X-Version
Access-Control-Request-Method
X-Middleton-Response
Response
X-VARITI-CCR
RTSS
X-Forwarded-For
Realpath
X-Cache-Key
X-T
X-TTL
X-Ratelimit-Remaining
X-Ua-Device
Cross-Origin-Resource-Policy
X-NF-Request-ID
X-Content-Digest
X-Cached
Fastcgi-Cache
X-Recruiting
X-Correlation-Id
X-ORACLE-DMS-RID
X-MSEdge-Ref
X-Shield-Request-Id
X-Fastly-Request-ID
X-TraceId
MicrosoftSharePointTeamServices
X-RateLimit-Remaining
X-PressLabs-Stats
Front-End-Https
X-Ruxit-Js-Agent
X-Ua-Browser
Public-Key-Pins
X-Request-Processing-Time
X-Forwarded-Proto
Arr-Disable-Session-Affinity
X-Request-Received
Payment
TP-Cache
X-HS-Hub-Id
X-HS-Cache-Config
X-LLID
X-HS-Content-Id
Server-Node
X-Frontend
Count-Hit
X-Protected-By
X-SRCache-Store-Status
X-SRCache-Fetch-Status
Surrogate-Key
X-Server-ID
X-GUploader-UploadID
X-Newrelic-App-Data
X-Varnish-TTL
X-LB-Cache
X-Accel-Expires
MS-Author-Via
X-HS-Combine-CSS
Content-MD5
X-Distributor
X-NODE
X-Origin-Server
X-Ezoic-Cdn
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-Content-Security-Policy-Report-Only
X-ORACLE-DMS-ECID
X-Microsite
X-Request-Handler-Origin-Region
X-Www-Served-By
Accept-Charset
X-HP-Trace-Id
X-Jurisdiction
X-HP-Webp
Mrf-Cache-Status
X-Activity-Id
X-Az
X-App-Server
X-AppVersion
MRF-Tech
X-B3-TraceId-Primal
X-Varnish-Server
Host
Cleartype
X-Amz-Meta-S3cmd-Attrs
Cache-Tags
X-Cluster-Name
X-Varnish-Backend
Retry-After
X-Goog-Metageneration
Filterid
X-Ttl
X-Unique-Id
X-FTR-Backend
X-FTR-Cache-Status
X-Country-Code-Real
X-FTR-Balancer
X-FTR-Backend-Server
X-Hits
X-Debug
X-Git-Hash
X-Aspnet-Version
X-FTR-Expires
Access-Control-Allow-Method
X-Logged-In
Server-Name
X-Load-Cache
X-Varnish-Ttl
X-Upgrade-Enabled
X-Azure-Ref
X-Id
X-FB-Debug
X-Hostname
X-Envoy-Decorator-Operation
X-NGENIX-Cache
X-Amz-Apigw-Id
X-CSRF-Token
X-Amzn-RequestId
TCN
X-Geo-Country
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-B
X-Proxy
Viewport
X-TT
X-Seen-By
X-Revision
X-Cache-Control
X-Request-Guid
Section-Io-Cache
X-Nf-Request-Id
X-Grace
DC
X-Ratelimit-Reset
X-Type
X-Contextid
X-Trace-Id
X-Fb-Rlafr
X-B3-Sampled
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
Healthy
TP-L2-Cache
X-Goog-Stored-Content-Encoding
X-Goog-Generation
Fastly-SIE
Fastly-SWR
Content-Disposition
X-N
X-F-Cache
X-XRDS-LOCATION
X-Mobile
X-Hcs-Proxy-Type
X-CCDN-Origin-Time
X-Time
X-CCDN-CacheTTL
Paypal-Debug-Id
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
X-Varnish-Grace
X-Magnolia-Registration
X-Amz-Replication-Status
X-Via-JSL
Referer-Policy
X-Webkit-CSP
X-Ismobilevalue
X-Origin-Cache
X-Debug-Info
X-Oracle-Dms-Ecid
X-Page-Id
X-DIS-Request-ID
X-Wormhole-Sdk
Version
X-Pinterest-Rid
Pinterest-Version
Pinterest-Generated-By
X-Content-Options
X-UUID
X-App-Environment
X-Template
X-RemovedCookies
X-Datadog-Sampling-Priority
X-Datadog-Trace-Id
X-Node-Name
X-Source
X-Datadog-Parent-Id
X-ProcessESI
X-Rule
MS-CV
NGB
Cross-Origin-Window-Policy
Ms-Operation-Id
X-Debug-IsPreview
X-Tumblr-Pixel
X-RTag
SD-X-WS
X-G
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Tumblr-User
X-Px
X-Hl-Ver
X-Debug-IsConnected
X-Datadog-Sampled
X-Adobe-Loc
X-Adobe-Content
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-Rendered-As
X-Storage
X-Backend-Name
X-Proxy-Cache-Info
X-Wix-Request-Id
X-User-Agent
X-NYM-Debug-Backend
X-Instance
X-Is-Bot
X-FW-Static
X-FW-Type
X-FW-Server
X-FW-Dynamic
X-FW-Serve
X-FW-Version
X-FW-Hash
GEO-INFO
X-L-Path
X-Environment-Context
X-Region
X-ServerID
Country
X-Status
X-Cacheable-TTL
X-Device-Type
X-Whom
X-B-Cache
X-Signature
X-RM-Cache-TTL
X-Cache-Age
Countrycode
X-Fastly-Request-Id
Front
X-NWS-UUID-VERIFY
X-Rid
X-IPS-LoggedIn
Amp-Access-Control-Allow-Source-Origin
Akamai-GRN
Charset
ServerID
X-EdgeConnect-Cache-Status
X-Framework
X-WP-CF-Super-Cache-Active
X-Real-IP
X-AB
X-ECache
X-Cache-Grace
SRV
X-Api-Version
X-WebKit-CSP-Report-Only
X-Language
X-Amzn-Remapped-Content-Length
Liferay-Portal
X-Content-Powered-By
X-B3-SpanId
X-Oracle-Dms-Rid
X-Akamai-Request-ID2
X-Cache-Hit
X-Air-Pt
Accept-Language
X-VC
X-DataDome
OT-Force-Account-Verify
X-Xrds-Location
X-Servername
X-URL
X-Mode
X-UA
X-Air-Trace-Id
X-Air-Source
X-Sucuri-Cache
Access-Control-Request-Headers
X-Sucuri-ID
X-Air-Hostname
LB
Xet-Cookie
Backend
X-VC-Cache
From-Origin
Webserver
X-Tt-Logid
Refresh
X-Cache-Status-Check
X-HTML-Minification-Powered-By
X-SRV
X-Mg-Request-UUID
X-Nginx-Cache
X-RID
X-Handled-By
X-Vcl-Version
X-JoinUs
X-SaId
X-Rn-Rsrv
X-UPSTREAM-Address
Meta-Geo
X-Rewrite-Enabled
Filters
X-Cms-Context
X-Request-URI
X-Provided-By
X-Tumblr-Pixel-2
X-Generated-By
Upgrade-Insecure-Requests
X-Labrador-Cache-Channel
X-R9-Blue-Green-Version
X-Varnish-Age
X-RCS-CacheZone
X-Hosted-By
X-Vcache
X-PHP-Host
X-S
X-No-Session
X-Browser-Name
X-Cache-Host
Onion-Location
X-Origin-Date
X-Webstats-RespID
X-Restarts
X-Served-From
Xserver
X-Alternate-Cache-Key
X-BYPASS-REASON
X-Cache-Debug
X-Accel-Version
X-Shopify-Stage
X-Site-Version
Webcakes-App-Name
Webcakes-App-Version
ServedBy
TWC-Privacy
X-Geo-Region
Webcakes-Region
TWC-Connection-Speed
X-Storefront-Renderer-Rendered
TWC-GeoIP-LatLong
X-Tncms
TWC-Locale-Group
X-Httpd
TWC-GeoIP-Country
TWC-Device-Class
X-Tcp-Rtt
Property-Id
X-Is-Desktop
X-Redis-Cache
X-ProxyCache-Status
X-ProxyCache-Key
X-Reqid
X-Is-Supported-Browser
Apigw-Requestid
X-Lambda-Id
X-Is-Tablet
X-Loop
X-Adobe-Source
X-Cache-Time
X-Is-Mobile
X-Locale
X-Origin-Hint
X-RateLimit-Limit
Atl-Traceid
Web-Mar-Node
Mn-Server-Ip
Section-Io-Id
X-Proxy-Build
Selected-Fe
Url
X-Origin
X-Format
X-Forwarded-Host
X-Logging-Id
X-Fetched-On
X-Director
X-Container-Uri
X-Varnish-Cache-Hits
X-Varnish-Beresp-Grace
X-Git-Commit
X-Tb
X-Timing-Wait
X-IPLB-Instance
X-Soup
X-Skip-Cache
X-Upstream-Ht
X-Upstream-Ct
X-Cluster
X-Detected-As
X-Xfnlog-Site
Expiry
Cache
X-Scope-Id
X-IPLB-Request-ID
X-SayCDN-TTL
X-Connection-Hash
X-Akamai-Edgescape
X-Say-Cacheable
X-Say-TTL
X-Zipkin-Id
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-ShopId
X-AWS-Id
X-Frame-Option
X-LJ-Flow-ID
X-Routing-Service
X-VCT
X-Optimistic-Header
X-ShardId
X-Extlb
X-Proxied
X-VWS-Id
X-Cloudmap
X-Cache-Operation
X-Web-Node
X-Cache-Rule
X-Cache-Expired-At
X-Ms-Version
X-Ms-Request-Id
X-Lagoon
X-Endurance-Cache-Level
Priority
CF-IPCountry
Frame-Options
Cdn-Requestid
X-WP-CF-Super-Cache-Cookies-Bypass
X-GeoCode
WPO-Cache-Message
Source
Environment
X-INCAP-ABP
X-Edge-Location
WPO-Cache-Status
Fastcgi-Useragent
X-GeoCountry
Protected
X-Cache-Action
X-Fastcgi-Cache
X-Proxy-Cache-Status
Uber-Trace-Id
X-Azure-Ref-OriginShield
X-Cluster-Node
X-CDN-Forward
X-Origin-CC
X-Origin-TTL
X-PHP-Backend
X-Generation-Time
X-Drupal-Cache-Tags
X-Drupal-Cache-Contexts
X-Cdn-Origin
X-Urbn-Context-Path
X-Urbn-Site-Id
X-Thinkindot-L3
X-CMSURLCustom
Thinkindot-CacheControl
TDXMobile
Thinkindot-Control
X-Shield-Cache-Expires
Thinkindot-CacheControl-Type
Locale
X-Pass-Why
X-ID
Sid
X-Aws-Lambda-Call-Status
X-Aspnetmvc-Version
X-Worker
X-Rocket-Nginx-Serving-Static
X-App-Version
X-GEO
Cache-Tv-Group
X-CLOUD-TRACE-CONTEXT
X-FB-TRIP-ID
X-Buckets
AMP-Access-Control-Allow-Source-Origin
X-XRDS-Location
Azure-InstanceId
Azure-Version
Azure-SlotName
Azure-RegionName
Azure-SiteName
Node
X-Auth-Group-Type
CDN-RequestPullSuccess
CDN-RequestPullCode
CDN-Cache
CDN-CachedAt
CDN-EdgeStorageId
CDN-PullZone
CDN-RequestCountryCode
CDN-Uid
X-Server-W
X-B3-Traceid
X-Vercel-Id
X-Vercel-Cache
X-Pad
Cache-Hits
X-Tumblr-Pixel-3
Alternate-Protocol
Cross-Origin-Embedder-Policy
X-LiteSpeed-Cache-Control
X-A
X-Client-Ip
X-Dc
X-Rojux
Magicmarker
Rendered-Blocks
DB-Nickname
X-Req
X-Cache-Id
X-Service
X-Edge-Server
X-ScT
A
X-LSADC-Cache
Gannett-Cam-Experience-Id
X-D
X-Gzip
DCR-Decision-By
MD5-Digest
X-Conf
X-Ig-Push-State
Odigeo-Trace-Id
X-Content-Age
Ngx.Var.Host
Lang
Origin-Agent-Cluster
X-Ig-Origin-Region
DCR-Processing-Time-Ms
X-Cache-NE
X-Epic-Correlation-Id
X-Ec-GeoHdr
Meta-Geo-Continent
X-Ec-Fail
X-Core-Value
X-Level-Front-Cache
Cdn-Request-Time
X-A-Ccd
X-Vdms-Version
Cdn-Host
X-Developer
Candidate-Md5Url
X-ND-Cache
X-A-Dam
X-A-Dcw
X-Vtex-Remote-Cache
X-Aed
X-A-Wwc
X-A-Dgt
X-Via-Fastly
X-Viewer-Country
X-Generated-On
X-Dispatcher-Server
Server-Info
X-Bc-Bl
Sslversion
X-SRCache-Key
X-BCube-Filmed-By
X-Org
X-Custom-Header
Surrogated-Key
T-Server
X-Esi-Check
X-Fastly-Backend
X-Cache-Server
X-V-Cache
X-TIM-N
Content-Secure-Policy
X-Bl-Debug
Mime-Version
X-TA-CDN-Provider
User-Cache-Control
Fastly-SSL
X-Fastly-Cache
X-Fmm-Version
X-DPWN-IS-SECURE
X-FC-Vary-Parameters
Fastly-Backend-Name
Country-Code
Content-Style-Type
Esi-Enabled
Edge-Cache
Content-Script-Type
X-Clientip
Ssr
True-Client-Country-4JS
X-Backend-Instance
X-Bip
Server-Host
RNT-Machine
RNT-Time
X-B3-Trace-ID
X-App-Name
Wxu-Next-Commit
Wxu-Next-Hostname
Wxu-Next-Region
X-Aicache-OS
X-Amz-Storage-Class
V-Age
Vix-Hermes-Req-Id
X-Block-Status
X-Cache-Bucket
Is-Eu
NM-Fastcgi-Cache
X-Forwarded-Site
Host-ID
X-Debug-Cache-Fetch
X-DefElseHash
X-Debug-Cache-Store
PFcat
X-CacheTTL
X-Cache-FS-Status
Req-ID
X-Cache-Info
Producers
Platform
X-Cache-TTL-Remaining
X-DefHash
X-GeoIP-Region-Code
X-RateLimit-Limit-Second
X-Pubstack
X-Gdpr
X-RateLimit-Remaining-Second
X-Region-Sid
X-SB
X-Request-Time
X-Powered-By-VTEX-Cache
X-Tx-Id
X-Origin-Response-Time
X-Origin-Expires
X-Origin-Time
X-PAYTM-SRV-ID
X-Policy
X-Platform
XM
X-Scheme
X-Wikidot-Backend
X-VarnishDD-TTL
X-Varnish-Remaining-TTL
X-VG-TLSProxy
X-VG-WebCache
X-VTEX-Cache-Time
X-VTEX-Cache-Server
X-Varnish-Director
X-Varnish-CookieINHashed-On
X-Server-IP
X-SD-PageType
X-Wikidot-Static-Cache
X-Test
X-Varnish-CookieHashed-On
X-Thanos
BehaviorPad-Version
X-Proto
X-HN
X-Acquia-Purge-Cdn-Unconfigured
X-Hnp-Log
X-Jobs
X-Micro-Cache
X-Men
Adler-Geo
AKAMAI
Cache-Provider
X-Gen-Mode
X-Geo-Header
X-GeoIP-City
X-GoCache-CacheStatus
X-GeoIP-Country-Code
X-Mly-Id
X-HS-Content-Campaign-Id
X-Mvc-Supplant-Cachable
X-Nyt-Route
X-NodeID
X-Node-Id
X-Mvc-Supplant-OutputCached
X-NMSegId
X-Op-Id-All
X-Tec-Api-Origin
X-DC
X-Tec-Api-Root
X-HITS
X-Tec-Api-Version
X-Varnish-Beresp-Ttl
X-Auto-Login
X-Varnish-Beresp-Status
X-BBC-Edge-Cache-Status
X-Var-Ttl
X-Csrf-Jwt
X-AK-Request-ID
X-UA-Device-Type
X-Eu-Site
X-GeoIP
X-CUA
X-Varnishpool
X-We-Are-Hiring
X-Varnish-Hostname
X-SVT-ORM-VERSION
X-Loc
X-Ec-Custom-Error
X-Human
X-Request-Start
X-Request-Host
X-CGP
X-Proxied-Request
X-Location
X-Cs
X-Section
X-Cdn-Srv
X-Tb-Optimization-Total-Bytes-Saved
X-Hash
X-SVT-ORM-RULES
X-Pool
X-Slack-Backend
X-Slack-Shared-Secret-Outcome
X-Sn-Servicetimems
X-Nginx-Cache-Key
X-Date
L5d-Success-Class
Machine
Apple-News-Services-Parsed-Url
L
HA-Ipaddr
Mail-Subject
HostName
Apple-News-Services-Handled
Proxy-Firewall
Pramga
Origin
Ha-Gx-Prefs
Gh-Request-Id
Cdnsip
Cluster
X-Access
Click-Count-Error
Click-Count-Action-Start
Cdncip
Fastly-GeoIP-CountryCode
Apple-News-Services-Request-Url
Cache-Key
Canary
CDCHOST
Req-Svc-Chain
Apple-News-Services-Host
Tube-Got-Results
Tube-Got-Eval
Sever-Int
Server-Hostname
Tube-Return
W
X-Accel-Expires-Debug
Web-Mar-Region
We-Hiring
Server-Ext
Tube-Get-Contents
X-NGINX-Cache
On-Server
X-Depends
Yak-Timeinfo
Powered-By
Debug
Release
X-Cache-Aspx
X-Varnish-Authentication
DSUID
C-Via
Origin-CC
NGX
X-Contensis-Viewer-Groups
Origin-EX
X-AIR-PT
X-Newrelic-Synthetics
X-WA-Info
X-Varnish-Hits
X-MP-GENERATED-AT
Fusion-Content-Id
Redirect-Candidate
X-Ad-Load-Variation
Fusion-Deployment-Id
X-APP
X-LB-ID
Fusion-Template-Id
Fusion-Content-Source
Fusion-Source
Fusion-Component-Id
X-HA-Backend
X-Via-Poph
X-Via-Popn
X-Content-Length
X-Device-Os
X-Via-Popv
X-LiteSpeed-Tag
X-Zone
X-VHOST
GeoIP-Latitude
Pics-Label
SID
Fastly-Drupal-HTML
X-CACHE-AGE
X-Up
X-Dispatcher-Number
CloudFront-Viewer-Country
X-From
X-Nananana
CDN-RequestId
X-NCache
X-Refresh
X-Parent-Response-Time
Vc-Max-Age
Fastly-Drupal-Html
X-Servedbyhost
X-B3-Parentspanid
X-LB-NoCache
X-Cache-Backend
Product
X-Jungle-Id
X-Akamai-Transformed
X-CDN-Cache-Status
X-Nc
X-RateLimit-Reset
X-Datadome
X-Vdms-Path
X-ZONE
X-CACHE-KEY
X-DynaTrace-JS-Agent
X-Litespeed-Tag
X-RequestId
Resin-Trace
Server-ID
S-Rt
X-Ckpd-Fst-Backend
X-Cached-By
X-Uri
X-Wa
X-Bug-Bounty
GeoIp-Country-Code
WP-Super-Cache
X-B3-Spanid
X-VC-TTL
Cdn
ServerName
X-Amz-Meta-Cb-Modifiedtime
X-ApacheServer
X-Render-Time
Datacenter
X-PERF
X-M-Reqid
X-CS
X-M-Log
X-HubSpot-Correlation-Id
X-IAuth-Set-Uid
NtCoent-Length
FSS-Cache
Uri
X-TX-ID
X-Varnish-Beresp-TTL
X-Fpc
X-SERVER-NAME
X-Nf-Language
True-Client-Ip
True-Client-IP
X-Nf-Ats-Version
X-Nf-Country
Serverhost
ServerHost
Locid
Srv
X-Gamma-Serve
User-Agent
X-Vmg-Version
X-Cdn-Forward
X-Info
X-TT-LOGID
X-Srv
X-Origin-Cache-Key
X-TIME
Xc-Version
X-WA
X-FPC
Tcn
X-NewRelic-App-Data
X-Dynatrace-Js-Agent
X-Akamai-Device-Characteristics
CDN
GeoIP-Country-Code
Request-ID
X-Hit
X-APP-VERSION
X-VCache
CacheControlHeader
X-Cdn-Cache-Status
Expect-Staple
X-HostName
X-Vc
X-Old-Content-Length
X-Amz-Meta-Opti
X-NC
Server-Id
Ngx-Var-Key
X-COUNTRY
X-V
X-Geo
Hostname
X-Moov-T
X-Moov-Xdn-Version
X-FL-QIT-DEBUG
Srvid
X-Vgn-Hpd-Reason
X-Response-Served-From
X-Original-Request-Id
X-Webkit-Csp-Report-Only
X-Presslabs-Stats
X-TH-Server
X-Platform-Server
X-Esi
N-Cache
X-Rollout
WZWS-RAY
X-New
Cneonction
X-Eligible
X-Lb-Nocache
PICS-Label
Geoip-Latitude
X-Limited
Cloudfront-Viewer-Country
XkeyRZ
X-ServedByHost
X-Proxy-CacheRZ
X-Dispatch
Origin-Trial
Permission-Policy
X-Oracle-DMS-ECID
X-VCL-Version
Cf-Ipcountry
X-Via-PopV
X-ElasticPress-Query
X-Ha-Backend
Ohc-File-Size
X-Platform-Router
X-Ftr-Request-Id
X-Platform-Cluster
X-Platform-Processor
X-Via-PopH
Cf-Device-Type
X-Via-PopN
X-Destination
X-EC-Lua
X-Ua
X-Path
X-Akamai-Pragma-Client-IP
Cl-Cache
X-Correlation-ID
X-S-Cookie
Cross-Origin-Embedder-Policy-Report-Only
X-User
X-B-Cookie
X-Application
X-App
X-Internal-TTL
X-External-Request-Id
Rtss
X-SIPLIST1
X-VTEX-Cache-Backend-Connect-Time
X-Sqd-Stime
IsBot
X-Sqd-Ctime
X-Lb-Id
X-Zen-Fury
X-Check-Cacheable
X-Serial
X-VTEX-Cache-Backend-Header-Time
X-Srcache-Fetch-Status
X-Wp-Cf-Super-Cache
X-Srcache-Store-Status
X-Wp-Cf-Super-Cache-Cache-Control
Lb
X-Cambria-Cache-Control
Epwk-X-Cache
Edge-Copy-Time
X-Cache-Date
X-Via-SSL
X-Acquia-Application-UUID
Ohc-Cache-HIT
X-Rocket-Build-Number
X-Instance-Name
X-Sigma
X-Sigma-Backend
Timeexpire
X-Acquia-Application-Trace
X-Via-Edge
X-Service-Response-Time
Sm-Log-Id
X-MiniProfiler-Ids
X-Web-Server
Pragrma
X-Acquia-Purge-Tags
X-Acquia-Site
X-Via-CDN
X-Cdn-Request-ID
X-MSEdge-Flight
Cmsid
X-Irp-Debug
X-DynaTrace
X-MSEdge-Features
Cmstype
Servername
X-Litespeed-Cache-Control
CountryCode
X-CSRF-TOKEN
X-LAGOON
X-AB-Test
Trailer
X-Fastly-Cache-Hits
X-Proxy-Cache-La3
Xkey-La3
Fl-Custom-Application
Xkeylog
X-Snapshot-Date
Ngx
X-Ramcache
Warning
X-Amz-Meta-S3b-Last-Modified
X-Amz-Meta-Sha256
X-Branch-Name
X-Th-Server
X-RAMCache
X-Segment-20210421
X-VServer
X-Datacenter
X-Udemy-Cache-App-Namespace
X-API-Version
X-Sorting-Hat-Podid
X-Sorting-Hat-Shopid
Wpo-Cache-Message
Wpo-Cache-Status
X-Shopid
X-Shardid
X-Dw-Trace-Id
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
X-Origin-Upstream-Status
X-Fastly-Backend-Reqs