Threat Level: green Handler on Duty: Guy Bruneau

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
Pragma
X-Powered-By
X-XSS-Protection
CF-RAY
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
P3P
Alt-Svc
X-Cache-Hits
X-UA-Compatible
X-Xss-Protection
X-Served-By
CF-Ray
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Request-Id
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
Access-Control-Allow-Credentials
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
X-Drupal-Cache
X-Generator
X-Cache-Status
X-Check
X-Request-ID
X-Cacheable
X-Envoy-Upstream-Service-Time
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Iinfo
X-FRAME-OPTIONS
X-Dns-Prefetch-Control
X-Drupal-Dynamic-Cache
Feature-Policy
X-Content-Security-Policy
Content-Encoding
Access-Control-Expose-Headers
Upgrade
Status
X-CDN
X-AspNetMvc-Version
Server-Timing
X-XSS-PROTECTION
Access-Control-Max-Age
X-Amz-Request-Id
Request-Context
X-Amz-Id-2
X-Turbo-Charged-By
X-AH-Environment
X-Via
X-Robots-Tag
X-Backend
X-Cache-Group
Cf-Edge-Cache
Keep-Alive
Host-Header
X-Hacker
X-Proxy-Cache
X-Server
X-UA-Device
X-Rq
X-Server-Powered-By
X-Age
Allow
X-Vhost
X-Varnish-Cache
X-Ws-Request-Id
EagleId
X-Dispatcher
X-Amz-Version-Id
Grace
X-LiteSpeed-Cache
Cf-Apo-Via
P3p
Nel
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Page-Speed
Cf-Railgun
X-Device
EagleEye-TraceId
X-Aws-Lambda-Call-Status
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
Accept-CH
X-Pingback
X-WebKit-CSP
X-Host
X-Node
X-Server-Id
X-OneAgent-JS-Injection
X-Backend-Server
Surrogate-Control
X-CST
X-Nginx-Cache-Status
X-Readtime
X-Akam-SW-Version
X-Cache-Lookup
Permissions-Policy
X-Content-Security-Policy-Report-Only
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
Request-Id
X-Application-Context
X-Nginx-Upstream-Cache-Status
X-Cloud-Trace-Context
X-Trace
X-Response-Time
X-Edge
Accept-CH-Lifetime
X-HW
Accept-Ch-Lifetime
X-Ua-Compatible
Content-Location
X-Mod-Pagespeed
X-Clacks-Overhead
X-Url
X-Ruxit-JS-Agent
X-Midtier
X-Litespeed-Cache
Rating
X-Oneagent-Js-Injection
X-ESI
X-Mcache
X-Amz-Server-Side-Encryption
X-ECACHE
X-Country
Xkey
X-Upstream
X-Vname
X-PC
X-TtlSet
X-Vcap-Request-Id
Cache-Tag
X-D2id
X-MS-InvokeApp
X-Exp-Id
X-Rack-Cache
X-Exp-Variant
X-Cdn-Fetch
X-Kinja
X-Use-Magma
X-Kinja-Server
X-Kinja-Revision
X-Kinja-Build
X-GoogleNews-Bot
X-Element-Page-Cache
Verso
X-Cache-TTL
Edge-Control
RTSS
Fastly-Restarts
X-Ruxit-Js-Agent
X-Powered-By-Plesk
X-VARITI-CCR
Origin-Trial
X-Ac
X-Navigation-Version
X-Abt-Application-Version
X-Content-Type
X-Cached
X-Goog-Hash
Accept-Ch
Service-Worker-Allowed
X-Country-Code
X-GitHub-Request-Id
X-Ttl
X-Sol
Display
X-Middleton-Display
Pagespeed
X-Amz-Rid
X-WebKit-CSP-Report-Only
X-Browser-Type
X-Mg-S
X-Dw-Request-Base-Id
SPRequestGuid
X-SharePointHealthScore
X-Server-Name
Cross-Origin-Opener-Policy
X-B3-TraceId
Arr-Disable-Session-Affinity
X-Kraken-Loop-Name
X-Instrumentation
X-Server-Lifecycle-Phase
X-Erf-Bev-Bev-Is-Generated
X-Varnish-TTL
X-Erf-Bev-Bev
X-Powered-CMS
X-Amzn-Trace-Id
Response
X-Middleton-Response
AR-Request-ID
AR-ATIME
AR-SID
AR-PoweredBy
SPRequestDuration
SPIisLatency
X-Cache-Key
AR-CACHE
X-Fastly-Request-ID
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Version
X-HP-Webp
X-Jurisdiction
X-HP-Trace-Id
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
X-Accel-Expires
X-Cnection
X-T
Front-End-Https
Cache-Status
Cache-Tags
X-Webkit-CSP
X-Client-IP
Edge-Cache-Tag
X-Times
X-Pinterest-Rid
Pinterest-Version
Pinterest-Generated-By
X-MSEdge-Ref
X-NF-Request-ID
X-Px
X-Fastcgi-Cache
X-Ser
X-Hits
Nginx-Cache
X-NWS-LOG-UUID
Public-Key-Pins
X-Recruiting
MRF-Tech
X-B3-TraceId-Primal
Mrf-Cache-Status
X-LLID
X-Request-Processing-Time
X-Request-Received
X-Ua-Device
X-Shield-Request-Id
X-Kinja-CCPA
X-B3-Traceid
X-Frontend
Payment
Server-Node
X-Ua-Browser
X-RateLimit-Remaining
Access-Control-Request-Method
X-DIS-Request-ID
X-Erf-Stays-Pdp-Viaduct-Migration-Web
TP-Cache
X-FastCGI-Cache
X-Goog-Metageneration
X-HS-Combine-CSS
X-Webkit-CSP-Report-Only
X-HS-Content-Id
X-HS-Cache-Config
S
MicrosoftSharePointTeamServices
X-HS-Hub-Id
TP-L2-Cache
X-Content-Digest
X-LB-Cache
X-PressLabs-Stats
X-RateLimit-Limit
X-Distributor
X-Ratelimit-Remaining
Content-MD5
Realpath
X-Request-Handler-Origin-Region
X-Microsite
X-Forwarded-For
X-Geo-Country
X-Page-Id
X-FB-Debug
Access-Control-Allow-Method
X-Hostname
X-Ezoic-Cdn
Fastcgi-Cache
X-GUploader-UploadID
Accept-Charset
X-Rid
X-Cluster-Name
X-Protected-By
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Seen-By
X-Envoy-Decorator-Operation
X-Correlation-Id
Cleartype
X-Ratelimit-Limit
X-TEC-API-ROOT
TCN
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-B3-Sampled
DC
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-Newrelic-App-Data
Referer-Policy
X-Origin-Server
X-Mobile
X-Origin-Cache
X-Debug-Info
Cross-Origin-Resource-Policy
X-Varnish-Backend
X-Logged-In
X-Git-Hash
X-XRDS-Location
X-Webkit-Csp
X-TTL
X-Azure-Ref
X-Varnish-Grace
X-Flags
X-Grace
X-Fb-Rlafr
X-Amz-Replication-Status
X-App-Environment
X-Is-Crawler
X-Aspnet-Duration-Ms
X-Kinsta-Cache
X-Edge-Location-Klb
X-Providence-Cookie
X-Route-Name
X-Aspnet-Version
X-Request-Guid
X-Contextid
Alternate-Protocol
X-Revision
Surrogate-Key
Count-Hit
X-Content-Options
X-TT
X-IPS-LoggedIn
X-Amz-Meta-S3cmd-Attrs
X-Server-ID
Healthy
X-Wix-Request-Id
X-Forwarded-Proto
X-App-Server
X-Whom
Frame-Options
X-Hosted-By
MS-Author-Via
X-Akamai-Edgescape
WPO-Cache-Status
WPO-Cache-Message
X-Daa-Tunnel
Viewport
Filterid
Charset
X-Id
X-Magnolia-Registration
X-B
Retry-After
Paypal-Debug-Id
X-Backend-Name
X-Cache-Age
Section-Io-Cache
X-F-Cache
X-Client-Ip
X-AppVersion
X-Activity-Id
X-Az
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Www-Served-By
X-Trace-Id
X-Cache-Control
X-Proxy-Cache-Info
Server-Name
X-RateLimit-Reset
X-Time
SRV
Refresh
X-ARC
X-Varnish-Server
X-Rule
SD-X-WS
X-Type
X-Original-Request-Id
X-Response-Served-From
X-Cache-Grace
Host
X-Proxy
X-User-Agent
X-Varnish-Age
X-UUID
X-Varnish-Ttl
Protected
X-Cache-Rule
X-Instance
X-Http-Reason
Front
Akamai-GRN
X-FW-Serve
X-Edge-Location
X-Environment-Context
X-FW-Dynamic
X-FW-Hash
X-Akamai-Request-ID2
From-Origin
X-Rendered-As
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
Fastly-SWR
Fastly-SIE
X-FW-Server
X-Status
X-Rocket-Nginx-Serving-Static
X-Cacheable-TTL
X-Framework
X-Is-Bot
X-FW-Version
Version
X-Jobs
X-FW-Type
Amp-Access-Control-Allow-Source-Origin
X-FW-Static
X-L-Path
X-Page-View
X-Cache-Time
X-N
X-Unique-Id
X-Region
Access-Control-Request-Headers
X-Oracle-Dms-Ecid
X-Adobe-Loc
X-App-Version
X-EdgeConnect-Cache-Status
X-Adobe-Content
X-Tumblr-Pixel-0
X-RemovedCookies
X-Tumblr-User
X-Tumblr-Pixel
X-Tumblr-Pixel-1
X-Oracle-Dms-Rid
X-G
X-ProcessESI
X-Language
X-Load-Cache
X-COUNTRY
ServerID
Country
X-Datadog-Parent-Id
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
Content-Disposition
X-Source
X-Nf-Request-Id
X-Upgrade-Enabled
X-Drupal-Cache-Tags
X-ECache
X-Vcache
X-Yottaa-Optimizations
X-CDN-Forward
X-Yottaa-Metrics
X-Datadog-Sampled
X-HTML-Minification-Powered-By
X-Mg-Request-UUID
X-Amzn-Remapped-Content-Length
Countrycode
X-Debug-IsPreview
X-Debug-IsConnected
X-DynaTrace
Accept-Language
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-DataDome
X-Signature
X-DynaTrace-JS-Agent
X-Generated-By
X-B-Cache
Backend
X-Xrds-Location
X-ID
Xet-Cookie
Webserver
Liferay-Portal
CF-IPCountry
X-Httpd
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
X-Device-Type
X-Tt-Logid
X-Drupal-Cache-Contexts
X-Servername
Xserver
X-Nginx-Cache
X-NYM-Debug-Backend
X-Content-Powered-By
X-Content-Age
Url
X-B3-SpanId
X-Mode
X-Zen-Fury
X-Erf-Web-Scheduler
Azure-SlotName
Onion-Location
S-Rt
Load-Balancing
Filters
Azure-RegionName
Azure-InstanceId
Fastcgi-Useragent
Azure-SiteName
Meta-Geo
X-Tb
Azure-Version
X-ServerID
X-Varnish-Cache-Hits
X-Director
X-SaId
X-Proto
X-GeoCountry
X-GeoCode
X-LAGOON
X-JoinUs
X-Cache-Action
X-Rewrite-Enabled
X-UPSTREAM-Address
X-Sucuri-ID
X-Sucuri-Cache
GEO-INFO
Locale
X-RM-Cache-TTL
X-SayCDN-TTL
X-XRDS-LOCATION
X-Urbn-Context-Path
X-Soup
X-Cache-Operation
X-Say-TTL
X-Say-Cacheable
X-PHP-Host
X-Git-Commit
X-Container-Uri
X-VC-Cache
X-Varnish-Hostname
X-Labrador-Cache-Channel
X-Urbn-Site-Id
X-VCT
X-Sql-Duration-Ms
X-Storage
X-Adobe-Source
X-Sql-Count
X-Cache-Server
X-Cluster-Node
X-Forwarded-Host
X-Ms-Request-Id
X-Ms-Version
X-Logging-Id
X-Generation-Time
Uber-Trace-Id
X-Served-From
X-Detected-As
X-R9-Blue-Green-Version
X-Debug
X-FB-TRIP-ID
Node
X-Skip-Cache
Web-Mar-Node
TWC-GeoIP-LatLong
TWC-Locale-Group
TWC-Privacy
TWC-GeoIP-Country
TWC-Device-Class
Property-Id
Selected-Fe
TWC-Connection-Speed
Webcakes-App-Name
Webcakes-App-Version
X-Tumblr-Pixel-2
X-Tumblr-Pixel-3
X-Uri
X-Timing-Wait
X-RCS-CacheZone
Webcakes-Region
X-Fetched-On
X-Origin-Hint
Mn-Server-Ip
X-Proxy-Build
DB-Nickname
X-LSADC-Cache
X-Template
X-Zipkin-Id
X-Tec-Api-Version
X-Routing-Service
X-Extlb
X-Tec-Api-Root
X-Tec-Api-Origin
X-Lambda-Id
X-Proxied
CDN-RequestId
X-Format
OT-Force-Account-Verify
Source
X-Origin-Date
Fastly-Drupal-HTML
X-Tncms
X-MP-GENERATED-AT
X-Ratelimit-Reset
X-Loop
X-Cache-Expired-At
X-Cache-Hit
X-Pass-Why
X-MCACHE
X-Varnish-Hits
X-Endurance-Cache-Level
X-Srv
X-Ua
Content-Secure-Policy
X-Redis-Cache
Upgrade-Insecure-Requests
X-Via-JSL
X-NGENIX-Cache
X-UA-Device-Type
X-TimeS
X-Real-IP
X-AIR-PT
Cross-Origin-Window-Policy
X-Cache-TTL-Remaining
X-Origin-TTL
Section-Io-Origin-Status
X-Origin-CC
X-Hcs-Proxy-Type
Section-Origin-Responded
X-CCDN-Origin-Time
X-Node-Name
Section-Io-Origin-Time-Seconds
Section-Io-Id
X-CCDN-CacheTTL
X-Pubstack
X-Fastly-Request-Id
NGB
X-Server-W
X-S
X-Rn-Rsrv
Cache-Hits
X-Datadome
X-CSRF-Token
X-Cache-Host
CDN-RequestPullCode
CDN-Uid
CDN-RequestPullSuccess
CDN-CachedAt
X-RTag
CDN-Cache
CDN-RequestCountryCode
CDN-PullZone
Ms-Operation-Id
X-PHP-Backend
Cache-Name
MS-CV
CDN-EdgeStorageId
X-GEO
X-Xfnlog-Site
Cache-Provider
X-Akamai-Transformed
X-Reqid
X-IPLB-Request-ID
X-Cms-Context
X-Hl-Ver
X-IPLB-Instance
X-Cache-Type
X-Optimistic-Header
X-URL
X-Restarts
X-No-Session
X-Aspnetmvc-Version
X-BYPASS-REASON
Apigw-Requestid
X-ProxyCache-Key
X-ProxyCache-Status
X-Newrelic-Synthetics
X-Parent-Response-Time
CPC-Cache
CPC-Age
DCR-Decision-By
X-A
DCR-Processing-Time-Ms
Fastly-Backend-Name
X-A-Dam
X-A-Wwc
X-Accel-Buffering
X-Handled-By
BehaviorPad-Version
X-A-Dgt
Candidate-Md5Url
Canary
Gannett-Cam-Experience-Id
X-A-Ccd
Lang
X-Accel-Expires-Debug
VNS-Age
Odigeo-Trace-Id
Redirect-Candidate
Rendered-Blocks
Sslversion
VNS-Cache
Server-Host
Ngx.Var.Host
N-Cache
Surrogated-Key
Gh-Request-Id
We-Hiring
T-Server
Mail-Subject
Meta-Geo-Continent
MD5-Digest
Web-Mar-Region
X-Debug-Cache-Fetch
X-Policy
X-Origin-Time
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Rojux
X-Request-Host
X-Orig-Expires
X-Nyt-Route
X-Has-Esi
X-GeoIP-Region-Code
X-Irp-Debug
X-Is-Gdpr
X-Mvc-Supplant-Cachable
X-JWT-State
X-S-Cookie
X-ScT
X-Slack-Backend
X-Shop-Environment
X-Slack-Shared-Secret-Outcome
X-SRCache-Key
X-Var-Ttl
X-Tenant
X-Vdms-Path
X-SD-PageType
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-We-Are-Hiring
X-Vtex-Remote-Cache
X-Vdms-Version
X-GeoIP-Country-Code
X-Gdpr
X-Cache-NE
X-Cache-Bucket
X-CacheTTL
X-Cdn-Diag
X-CF-Lambda-Version
X-CF-Lambda-Fn
X-Bl-Debug
X-Worker
X-Application
Xc-Version
X-B-Cookie
X-Bc-Bl
X-BCube-Filmed-By
X-Conf
X-D
X-Ec-GeoHdr
X-Ec-Fail
X-External-Request-Id
X-Fastly-Backend
X-Forwarded-Path
X-FC-Vary-Parameters
X-Ec-Custom-Error
X-Wix-Viewer-Type
X-Debug-Cache-Store
X-Date
X-Destination
X-Developer
X-Dispatcher-Number
X-Aed
X-A-Dcw
X-CACHE-AGE
X-Via-Fastly
X-Proxy-Cache-Status
X-Epic-Correlation-Id
X-DPWN-IS-SECURE
X-DefHash
X-DefElseHash
X-Core-Mission
X-Core-Value
X-Csrf-Jwt
X-Esi-Check
X-LJ-Flow-ID
X-Gzip
X-Hash
X-INCAP-ABP
X-Level-Front-Cache
X-Geo-Header
X-Generated-On
X-CMSURLCustom
X-Fmm-Version
X-Forwarded-Site
X-Eu-Site
X-Clientip
Vix-Hermes-Req-Id
W
X-VWS-Id
X-Alternate-Cache-Key
True-Client-Country-4JS
Thinkindot-Control
TDXMobile
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
X-ApacheServer
X-App-Name
X-Cdn-Origin
X-CGP
X-Clara-WADP
X-TA-CDN-Provider
X-Cache-Info
X-Bip
X-Cache-Debug
X-Cache-Id
X-Loc
X-Mid
X-Test
X-Thanos
X-Thinkindot-L3
X-Up
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Storefront-Renderer-Rendered
X-Variation
X-Varnish-CookieHashed-On
X-Vmg-Version
X-VServer
X-WADP-Cache
X-App
X-Viewer-Country
X-VG-WebCache
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
X-Varnishpool
X-Sn-Servicetimems
X-Shopify-Stage
X-Origin-Response-Time
X-Cluster
X-Owner
X-PAYTM-SRV-ID
X-Org
X-Old-Content-Length
X-Mly-Id
X-Nitro-Cache
X-Node-Id
X-PERF
X-Platform
X-Server-IP
X-ShardId
X-ShopId
X-S-Maxage
X-Request-Time
X-Pool
X-Qloud-Router
X-AWS-Id
Release
X-Human
Cmstype
Is-Eu
Datacenter
Host-ID
L5d-Success-Class
AKAMAI
L
Origin
Environment
Expect-Staple
Ha-Gx-Prefs
Machine
HA-Ipaddr
Magicmarker
Memcached
Fastly-GeoIP-CountryCode
Fastly-SSL
Platform
Cmsid
Producers
Adler-Geo
X-Section
User-Cache-Control
X-Access
X-Nananana
X-Nginx-Cache-Key
X-BBC-Edge-Cache-Status
X-VG-TLSProxy
NM-Fastcgi-Cache
Sever-Int
Country-Code
X-Akamai-Device-Characteristics
X-Mvc-Supplant-OutputCached
X-Auto-Login
DSUID
X-GeoIP
X-From
Server-Ext
X-WA-Info
X-Gen-Mode
X-Dispatcher-Server
X-Hnp-Log
X-Block-Status
CloudFront-Viewer-Country
AMP-Access-Control-Allow-Source-Origin
Server-Hostname
Esi-Enabled
Req-Svc-Chain
X-Origin
X-TIM-N
X-Device-Os
ServedBy
X-Tx-Id
X-Vcl-Version
WP-Super-Cache
Ssr
X-Scale
Apple-News-Services-Request-Url
Apple-News-Services-Handled
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
X-Cache-Enabled
X-Presslabs-Stats
X-Cdn-Srv
Server-Info
X-Refresh
CDCHOST
X-Cs
X-NodeID
X-Correlation-ID
X-Instance-Name
X-LB-NoCache
Time
X-Web-Node
Origin-CC
Pics-Label
C-Via
Memory
Origin-EX
X-NCache
Wxu-Next-Hostname
Wxu-Next-Region
Wxu-Next-Commit
X-Cache-Status-Check
X-Op-Id-All
X-Amz-Meta-Cb-Modifiedtime
X-Air-Hostname
X-Air-Trace-Id
X-TIME
X-Air-Source
Hostname
Server-ID
X-HA-Backend
X-ZONE
X-Azure-Ref-OriginShield
X-API-Version
Origin-Agent-Cluster
NGX
X-Dc
Cf-Device-Type
X-Tb-Optimization-Total-Bytes-Saved
X-Origin-Expires
Cache-Host
X-Platform-Router
X-Platform-Cluster
X-Microcachable
GeoIP-Latitude
X-Platform-Processor
X-VHOST
X-CACHE-GROUP
XM
X-Site-Version
X-Locale
X-Varnish-Beresp-Grace
PFcat
X-VarnishDD-TTL
X-HN
X-Wp-Cf-Super-Cache-Active
X-Varnish-Beresp-Ttl
X-DC
X-Ad-Defer-Variation
X-Fpc
X-Vgn-Hpd-Reason
Resin-Trace
X-Micro-Cache
Cdn-Requestid
X-Webkit-Csp-Report-Only
YJS-ID
Srvid
A
Edge-Copy-Time
X-Via-CDN
X-Via-Edge
X-Via-SSL
X-FL-EDGE
X-FL-QIT-DEBUG
X-Internal-Host
Locid
X-B3-Spanid
X-TraceId
X-WP-CF-Super-Cache-Active
Sid
X-AB
X-Zone
X-Upstream-Ct
X-Upstream-Ht
X-Github-Request-Id
X-Cache-ASPX
X-ATG-Version
X-Contensis-Viewer-Groups
X-Cached-By
X-FireWall-Port
X-Pod-Name
Location
X-Buckets
X-LiteSpeed-Cache-Control
User-Agent
Uri
X-B3-Parentspanid
True-Client-Ip
X-Moov-T
X-Moov-Xdn-Version
X-Varnish-Authentication
X-DataCenter
Cache-Key
X-Geo-Region
X-NGINX-Cache
X-Backend-Instance
GeoIP-Country-Code
IsBot
X-SIPLIST1
X-Info
X-FTR-Request-ID
X-Accel-Version
X-LiteSpeed-Tag
X-Planisys-CDN-Cache
GeoIp-Country-Code
CF-Ctrl
X-Planisys-CDN-Rules
X-Nitro-Cache-From
X-Platform-Server
X-Nitro-Rev
X-Planisys-CDN-TTL
State
X-HS-Content-Campaign-Id
X-Is-Mobile
X-Is-Tablet
X-Tcp-Rtt
X-Provided-By
Lb
X-Is-Supported-Browser
X-Is-Desktop
X-Browser-Name
X-MSEdge-Flight
X-VC
X-Fastly-Cache
X-Release
X-Datacenter
NtCoent-Length
X-MSEdge-Features
XServer
SID
X-VCache
X-Rocket-Build-Number
Cdn
X-Geo
X-Cache-Remote
X-Sigma-Backend
X-Sigma
X-CS
True-Client-IP
X-RN-RSRV
X-NewRelic-App-Data
X-CSRF-TOKEN
Cache
X-Vgn-Hpd-Variations-Key
Path
X-Vgn-Hpd-Ssi
X-Hyper-Cache
X-Vgn-Hpd-Cached
Epwk-X-Cache
Fastly-Drupal-Html
X-Api-Version
X-TRACE-ID
X-Gamma-Serve
X-GeoIP-City
X-FPC
X-Scheme
X-HS-Status
X-Generated-In
X-SRV
X-APP-VERSION
Cf-Ipcountry
X-Webstats-RespID
X-Frame-Option
X-Service
X-CACHE-KEY
Tcn
X-HostName
X-GoCache-CacheStatus
Cache-Tv-Group
Ohc-File-Size
Srv
X-UA
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
CountryCode
X-Wp-Cf-Super-Cache-Cache-Control
Serverid
X-Wp-Cf-Super-Cache
X-Air-Pt
X-Pad
X-EC-Lua
X-Amz-Meta-Opti
X-Esi
Cdnsip
X-AK-Request-ID
Kp-EeAlive
Cdncip
X-Guploader-Uploadid
X-Cache-Ttl
X-Edge-Server
Cdn-Host
X-Traceid
X-Mobile-URL
Cdn-Request-Time
X-Vercel-Cache
X-Location
X-Branch-Name
HostName
WebServer
X-Vercel-Id
X-Origin-Cache-Key
X-Cdn-Forward
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-Cdn-Cache-Status
X-Proxy-CacheRZ
X-NMSegId
XkeyRZ
Env
X-Vc
Ohc-Cache-HIT
Yak-Timeinfo
Proxy-Connection
X-FTR-Expires
X-Region-Sid
WZWS-RAY
X-FTR-Cache-Status
X-Developers
X-FTR-Balancer
X-FTR-Backend
X-Men
X-FTR-Backend-Server
X-Cache-Tags
Req-ID
M-TraceId
X-Aicache-OS
On-Server
CacheControlHeader
X-Country-Code-Real
X-VCL-Version
CDN
X-Cdn-Request-ID
X-TX-ID
Server-Id
X-LB-ID
X-Akamai-Pragma-Client-IP
Tube-Got-Results
X-Via-Poph
X-Cache-FS-Status
Tube-Got-Eval
X-B3-Trace-ID
X-V-Cache
Click-Count-Error
Click-Count-Action-Start
X-Ad-Load-Variation
Mime-Version
Tube-Get-Contents
Cluster
X-Via-Popv
X-Edge-Pop
V-Age
X-Acquia-Purge-Cdn-Unconfigured
X-Servedbyhost
RNT-Machine
Geoip-Latitude
X-Req
Ngx
X-SB
X-CDN-Cache-Status
X-Minions-Version
X-Nc
X-NWS-UUID-VERIFY
X-Via-Popn
Tube-Return
RNT-Time
X-Wa
LB
X-Lb-Cache
X-Ha-Backend
X-M-Reqid
X-M-Log
X-Fastly-Country-Code
ENV
Content-Style-Type
X-Scope-Id
CF-Cached-On
X-Request-Start
WWW-Authenticate
X-WP-CF-Super-Cache-Cookies-Bypass
Pramga
Content-Script-Type
X-TT-LOGID
X-Shield-Cache-Expires
X-MiniProfiler-Ids
X-IN-APIGATEWAY
X-Tim-N
X-User
X-Snapshot-Date
X-IN-APIGATEWAYSSL
X-Check-Cacheable
PICS-Label
X-Acquia-Application-Trace
X-Acquia-Site
X-Acquia-Purge-Tags
X-Qnm-Cache
X-Dw-Trace-Id
X-Lb-Nocache
X-Acquia-Application-UUID
X-Via-Ucdn
X-Edge-POP
Yjs-Id
X-Varnish-Beresp-Status
X-Varnish-Beresp-TTL
X-Request-URI
X-Ckpd-Fst-Backend
X-Iauth-Set-Uid
CACHE-MISS-TO-ORIGIN
Inserted-Into-Cache-At
X-Fastly-Backend-Reqs
X-TH-Server
X-APP
X-Processor
X-Fastly-Cache-Hits
Vha6-Origin
X-RAMCache
X-Miniprofiler-Ids
Log-Origin
X-Litespeed-Cache-Control
X-Cached-Since
X-ElasticPress-Query
Cneonction