Threat Level: green Handler on Duty: Daniel Wesemann

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
CF-RAY
Accept-Ranges
Expect-CT
X-XSS-Protection
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Xss-Protection
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-Download-Options
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
Accept-CH
X-AspNet-Version
Content-Security-Policy-Report-Only
X-Runtime
Accept-CH-Lifetime
X-DNS-Prefetch-Control
X-Drupal-Cache
X-Check
X-Cache-Status
X-Ua-Compatible
X-Generator
Server-Timing
X-Request-ID
X-Cacheable
X-Envoy-Upstream-Service-Time
Timing-Allow-Origin
X-FRAME-OPTIONS
X-Iinfo
X-Drupal-Dynamic-Cache
X-Content-Security-Policy
Access-Control-Expose-Headers
Feature-Policy
X-CDN
Content-Encoding
Status
Upgrade
X-AspNetMvc-Version
CF-Ray
Access-Control-Max-Age
X-Amz-Request-Id
X-Via
X-Amz-Id-2
Cf-Edge-Cache
Host-Header
EagleId
Keep-Alive
Request-Context
X-Backend
X-Cache-Group
X-UA-Device
X-AH-Environment
X-Robots-Tag
X-Server
X-Hacker
X-Turbo-Charged-By
X-Proxy-Cache
X-Ws-Request-Id
Xkey
Permissions-Policy
X-Rq
X-Age
X-Vhost
X-Amz-Version-Id
X-Dns-Prefetch-Control
Allow
X-Dispatcher
Cf-Apo-Via
X-Swift-CacheTime
X-Swift-SaveTime
X-Server-Powered-By
Grace
Ali-Swift-Global-Savetime
X-Varnish-Cache
X-LiteSpeed-Cache
P3p
X-Page-Speed
X-Pingback
X-Cache-Lookup
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-OneAgent-JS-Injection
X-Device
Cf-Railgun
X-Backend-Server
EagleEye-TraceId
X-Host
X-Server-Id
X-WebKit-CSP
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Response-Time
X-Readtime
X-Akam-SW-Version
Surrogate-Control
X-HW
Request-Id
X-Ruxit-JS-Agent
X-Cloud-Trace-Context
X-Litespeed-Cache
Content-Location
X-Application-Context
X-Node
X-Nginx-Cache-Status
X-Nginx-Upstream-Cache-Status
X-NWS-LOG-UUID
X-CST
X-Country
Service-Worker-Allowed
X-Country-Code
X-Content-Type
X-Url
X-Clacks-Overhead
Cache-Tag
X-Trace
Rating
X-Rack-Cache
X-Amz-Server-Side-Encryption
Nginx-Cache
X-Server-Name
X-Times
X-FTR-Request-ID
X-Vname
X-PC
X-TtlSet
X-Daa-Tunnel
X-Oneagent-Js-Injection
X-Webkit-Csp
Cross-Origin-Opener-Policy
X-Edge
X-Mcache
X-Midtier
X-Browser-Type
X-Powered-By-Plesk
X-Cnection
X-ESI
X-Upstream
X-ECACHE
X-GitHub-Request-Id
X-D2id
Edge-Control
X-MS-InvokeApp
X-Element-Page-Cache
X-Kinja-Server
X-Kinja
Verso
X-Cdn-Fetch
X-GoogleNews-Bot
X-Kinja-Build
X-Kinja-Revision
X-Exp-Variant
X-Exp-Id
X-Ac
AR-Request-ID
AR-SID
AR-PoweredBy
AR-ATIME
Accept-Ch-Lifetime
X-FastCGI-Cache
X-Vcap-Request-Id
X-Ser
X-Cache-TTL
X-Navigation-Version
X-Abt-Application-Version
X-B3-TraceId
X-Aws-Lambda-Call-Status
AR-CACHE
X-Mod-Pagespeed
X-Dw-Request-Base-Id
X-NF-Request-ID
SPRequestDuration
SPIisLatency
SPRequestGuid
X-SharePointHealthScore
X-Amz-Rid
Fastly-Restarts
X-Instrumentation
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-Client-IP
X-Sol
Pagespeed
X-Middleton-Display
Display
X-Ruxit-Js-Agent
Edge-Cache-Tag
X-Mg-S
S
X-Edge-Location-Klb
X-Kinsta-Cache
X-Powered-CMS
Response
X-Middleton-Response
Cache-Status
X-Amzn-Trace-Id
X-RateLimit-Remaining
X-Cache-Key
X-Goog-Hash
Access-Control-Request-Method
X-VARITI-CCR
X-Version
X-ARC
RTSS
X-Fastly-Request-ID
X-Content-Digest
X-Forwarded-For
X-TraceId
Cross-Origin-Resource-Policy
X-Recruiting
X-T
Realpath
X-Ratelimit-Limit
X-Varnish-TTL
X-Correlation-Id
X-MSEdge-Ref
Front-End-Https
X-Pinterest-Rid
Pinterest-Generated-By
Pinterest-Version
Fastcgi-Cache
MS-Author-Via
X-Cached
X-PDP-UNCACHING-HASH
X-Ttl
Content-MD5
X-HS-Hub-Id
X-HS-Cache-Config
X-HS-Content-Id
X-Ua-Browser
Server-Node
X-Protected-By
X-Shield-Request-Id
Payment
X-FTR-Backend
X-Request-Processing-Time
X-Request-Received
Public-Key-Pins
X-FTR-Balancer
X-FTR-Backend-Server
X-FTR-Cache-Status
X-Country-Code-Real
X-HS-Combine-CSS
X-LLID
Arr-Disable-Session-Affinity
X-SRCache-Fetch-Status
X-SRCache-Store-Status
TP-Cache
MicrosoftSharePointTeamServices
X-Forwarded-Proto
X-Frontend
X-Distributor
X-Jurisdiction
X-HP-Webp
X-HP-Trace-Id
X-Server-ID
X-Accel-Expires
X-FTR-Expires
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-ORACLE-DMS-RID
Count-Hit
X-NODE
X-GUploader-UploadID
X-Origin-Server
X-Ratelimit-Remaining
X-TTL
X-LB-Cache
X-Origin-Cache-Key
X-Ezoic-Cdn
X-Hits
X-Content-Security-Policy-Report-Only
X-Request-Handler-Origin-Region
X-Microsite
X-AppVersion
X-Activity-Id
X-Az
X-PressLabs-Stats
Host
Mrf-Cache-Status
MRF-Tech
X-Ua-Device
X-B3-TraceId-Primal
X-Cluster-Name
X-Varnish-Backend
X-Www-Served-By
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-App-Server
X-Varnish-Server
Cache-Tags
Retry-After
X-Amz-Meta-S3cmd-Attrs
Accept-Charset
Server-Name
X-Hostname
Cleartype
X-Geo-Country
X-NGENIX-Cache
X-Envoy-Decorator-Operation
X-Newrelic-App-Data
X-Goog-Metageneration
X-Id
Referer-Policy
X-CSRF-Token
X-DIS-Request-ID
X-ORACLE-DMS-ECID
X-Upgrade-Enabled
Access-Control-Allow-Method
TP-L2-Cache
X-Git-Hash
X-Seen-By
X-Azure-Ref
X-Unique-Id
X-Hcs-Proxy-Type
X-CCDN-Origin-Time
X-CCDN-CacheTTL
TCN
X-Load-Cache
X-F-Cache
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Amzn-RequestId
X-Amz-Apigw-Id
Filterid
X-Proxy
X-Trace-Id
X-Grace
X-Revision
Healthy
Section-Io-Cache
X-Cache-Control
X-Px
X-Request-Guid
X-XRDS-LOCATION
X-B3-Sampled
X-B
X-Contextid
X-TT
Paypal-Debug-Id
X-Debug-Info
DC
X-Fb-Rlafr
X-Page-Id
X-FB-Debug
X-Oracle-Dms-Ecid
X-Type
X-Logged-In
X-Mobile
X-N
X-RateLimit-Limit
Viewport
X-Debug
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
X-Varnish-Ttl
X-Whom
X-Oracle-Dms-Rid
X-Template
Fastly-SWR
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
Fastly-SIE
X-Goog-Stored-Content-Length
Charset
X-Language
X-Time
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
X-Webkit-CSP
X-Cache-Grace
X-Via-JSL
X-Content-Options
Content-Disposition
Version
X-Magnolia-Registration
X-Varnish-Grace
X-Wix-Request-Id
X-EdgeConnect-Cache-Status
X-App-Environment
X-B-Cache
X-Signature
X-Node-Name
X-Origin-Cache
VIX-Pulpo-Upstream-Status
X-Rule
X-B3-SpanId
X-RemovedCookies
X-ProcessESI
VIX-Pulpo-Node
X-Hl-Ver
X-Tumblr-Pixel
X-Tumblr-Pixel-1
X-Debug-IsConnected
X-Backend-Name
X-RateLimit-Reset
X-Datadog-Sampled
X-Debug-IsPreview
X-Tumblr-User
X-Tumblr-Pixel-0
X-Yottaa-Metrics
X-Yottaa-Optimizations
Ms-Operation-Id
X-Amz-Replication-Status
X-RTag
SD-X-WS
MS-CV
X-G
X-Amzn-Remapped-Content-Length
X-UUID
X-FW-Static
X-FW-Type
X-FW-Dynamic
X-FW-Hash
X-FW-Version
X-FW-Server
X-FW-Serve
X-Adobe-Loc
X-Proxy-Cache-Info
ServerID
X-Device-Type
X-Cache-Age
X-Storage
X-Adobe-Content
NGB
Liferay-Portal
GEO-INFO
Country
X-Cacheable-TTL
Countrycode
X-Is-Bot
X-User-Agent
SRV
X-Rendered-As
X-Instance
X-Cache-Hit
X-NYM-Debug-Backend
X-Environment-Context
X-L-Path
X-IPS-LoggedIn
X-Status
X-Real-IP
Surrogate-Key
X-Region
X-NWS-UUID-VERIFY
X-ServerID
X-Rid
X-Source
X-Sucuri-Cache
X-Sucuri-ID
OT-Force-Account-Verify
Akamai-GRN
X-Servername
X-WP-CF-Super-Cache-Active
Cross-Origin-Window-Policy
From-Origin
X-VC-Cache
X-WebKit-CSP-Report-Only
X-UA
X-RM-Cache-TTL
Upgrade-Insecure-Requests
Front
X-Framework
Backend
Amp-Access-Control-Allow-Source-Origin
X-INCAP-ABP
X-Mode
X-Xrds-Location
Refresh
X-Wormhole-Sdk
X-AB
X-Air-Pt
X-Air-Source
X-Cache-Time
X-Air-Trace-Id
X-Content-Powered-By
X-Air-Hostname
X-Handled-By
X-HTML-Minification-Powered-By
X-RID
Xet-Cookie
Frame-Options
X-Akamai-Request-ID2
X-Buckets
X-Endurance-Cache-Level
X-Edge-Location
Url
X-VC
X-Reqid
X-Timing-Wait
X-RCS-CacheZone
X-Rn-Rsrv
X-Rewrite-Enabled
X-Cluster
X-No-Session
X-Origin-Date
X-UPSTREAM-Address
X-SaId
ServedBy
X-Xfnlog-Site
Webserver
X-Proxy-Build
Selected-Fe
Filters
Meta-Geo
X-JoinUs
X-Webstats-RespID
X-Origin-CC
X-Origin-TTL
X-VWS-Id
X-Akamai-Edgescape
X-SRV
Cache
X-AWS-Id
X-Azure-Ref-OriginShield
X-Provided-By
X-R9-Blue-Green-Version
X-VCT
X-PHP-Host
X-Cache-Operation
X-Cache-Rule
X-DataDome
X-Origin
Atl-Traceid
Access-Control-Request-Headers
X-Labrador-Cache-Channel
X-Tumblr-Pixel-2
X-Logging-Id
X-LJ-Flow-ID
X-Drupal-Cache-Tags
Cache-Hits
X-Served-From
X-Cache-Status-Check
Property-Id
TWC-Privacy
WPO-Cache-Message
TWC-GeoIP-Country
Section-Io-Id
X-Locale
WPO-Cache-Status
X-ProxyCache-Key
X-Git-Commit
X-Hosted-By
X-Accel-Version
X-Adobe-Source
Webcakes-Region
X-Scope-Id
Webcakes-App-Version
X-ProxyCache-Status
X-Zipkin-Id
X-Shield-Cache-Expires
X-BYPASS-REASON
X-Httpd
TWC-Locale-Group
X-Site-Version
X-Tb
Thinkindot-CacheControl-Type
X-Web-Node
Thinkindot-CacheControl
TDXMobile
TWC-Device-Class
X-Origin-Hint
X-Fetched-On
Thinkindot-Control
X-Drupal-Cache-Contexts
TWC-Connection-Speed
X-Routing-Service
X-Extlb
X-Cache-Debug
X-Ms-Version
X-Ms-Request-Id
X-Cms-Context
X-Generation-Time
TWC-GeoIP-LatLong
X-Cloudmap
X-CMSURLCustom
X-Thinkindot-L3
X-Container-Uri
Webcakes-App-Name
X-Proxied
X-Vcache
X-Redis-Cache
X-Varnish-Cache-Hits
Mn-Server-Ip
Web-Mar-Node
X-Loop
X-Upstream-Ct
X-Upstream-Ht
X-Varnish-Age
X-Say-Cacheable
X-Tncms
X-Tcp-Rtt
X-SayCDN-TTL
X-Say-TTL
X-Skip-Cache
X-Soup
X-Varnish-Beresp-Grace
X-S
X-Is-Desktop
X-Geo-Region
X-Frame-Option
X-Director
X-Is-Mobile
X-Is-Supported-Browser
X-Restarts
X-Lambda-Id
X-Is-Tablet
X-Browser-Name
Apigw-Requestid
X-CDN-Forward
Accept-Language
X-Storefront-Renderer-Rendered
X-Nginx-Cache
X-Forwarded-Host
X-IPLB-Request-ID
X-Format
X-Alternate-Cache-Key
X-GeoCountry
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Detected-As
X-Cdn-Origin
X-IPLB-Instance
X-ShardId
X-Shopify-Stage
X-GeoCode
X-ShopId
X-Generated-By
X-Cache-Host
X-Worker
X-Lagoon
X-Optimistic-Header
Xserver
X-Rocket-Nginx-Serving-Static
Source
X-Vercel-Cache
X-Vercel-Id
X-B3-Traceid
Azure-SiteName
Azure-SlotName
Azure-RegionName
Azure-Version
Azure-InstanceId
X-Request-URI
Node
X-Ratelimit-Reset
X-Fastly-Request-Id
X-WP-CF-Super-Cache-Cookies-Bypass
X-TA-CDN-Provider
CDN-RequestId
X-Pass-Why
X-URL
CDN-RequestCountryCode
CDN-Cache
CDN-PullZone
CDN-EdgeStorageId
Fastcgi-Useragent
CDN-CachedAt
CDN-RequestPullCode
Protected
CDN-RequestPullSuccess
CDN-Uid
Cross-Origin-Embedder-Policy
LB
X-Vcl-Version
X-Erf-Stays-Pdp-Viaduct-Migration-Web-V2
AMP-Access-Control-Allow-Source-Origin
X-Connection-Hash
Expiry
X-Tumblr-Pixel-3
X-GEO
X-Tec-Api-Origin
X-Tec-Api-Version
X-Tec-Api-Root
Onion-Location
Alternate-Protocol
X-XRDS-Location
X-App-Version
X-Cache-Server
X-Cache-Expired-At
X-Api-Version
X-PHP-Backend
DB-Nickname
Priority
Sid
X-Server-W
X-Jobs
Environment
Uber-Trace-Id
CF-IPCountry
X-Proxy-Cache-Status
X-Aspnetmvc-Version
X-Fastcgi-Cache
X-Cache-Action
HostName
User-Cache-Control
X-LSADC-Cache
X-Cluster-Node
X-Urbn-Context-Path
Locale
X-Uri
X-Urbn-Site-Id
X-Mg-Request-UUID
X-TT-LOGID
X-Response-Served-From
X-Original-Request-Id
X-MP-GENERATED-AT
X-Hnp-Log
X-Conf
X-Block-Status
X-Bl-Debug
Req-ID
Rendered-Blocks
X-Cache-Id
X-Gzip
Origin
Ngx.Var.Host
Origin-Agent-Cluster
X-Cache-NE
X-Bip
X-Clientip
X-BCube-Filmed-By
X-A-Ccd
X-A
Vix-Hermes-Req-Id
X-Level-Front-Cache
X-A-Dam
X-A-Dgt
X-A-Dcw
X-Aed
X-Jungle-Id
Server-Host
X-Bc-Bl
X-Ig-Origin-Region
Sslversion
T-Server
Surrogated-Key
X-Content-Age
Meta-Geo-Continent
X-FC-Vary-Parameters
X-FB-TRIP-ID
X-Esi-Check
Candidate-Md5Url
Cache-Tv-Group
X-Gen-Mode
X-Forwarded-Site
Fusion-Content-Id
Content-Secure-Policy
DCR-Processing-Time-Ms
Edge-Cache
X-Ec-Fail
DCR-Decision-By
X-Epic-Correlation-Id
Fusion-Component-Id
X-Generated-On
A
X-Mvc-Supplant-Cachable
X-Developer
X-D
Lang
MD5-Digest
Magicmarker
X-Device-Os
X-Dispatcher-Server
Fusion-Content-Source
X-GeoIP-City
Fusion-Deployment-Id
Fusion-Source
Gannett-Cam-Experience-Id
Fusion-Template-Id
X-Ec-GeoHdr
X-ND-Cache
X-Varnish-Hostname
X-Pubstack
X-UA-Device-Type
X-SRCache-Key
X-Vdms-Version
X-Vdms-Path
X-DC
X-Platform
X-Thanos
X-TIM-N
X-Proto
X-Powered-By-VTEX-Cache
X-Policy
X-Request-Start
X-Org
X-Origin-Expires
X-SB
X-VTEX-Cache-Server
X-Viewer-Country
X-ScT
X-Rojux
X-Node-Id
X-Vtex-Remote-Cache
X-A-Wwc
X-VTEX-Cache-Time
X-NGINX-Cache
X-Origin-Response-Time
X-Tx-Id
X-Debug-Cache-Store
Host-ID
X-Debug-Cache-Fetch
X-V-Cache
Gh-Request-Id
X-CUA
X-Mvc-Supplant-OutputCached
X-Amz-Storage-Class
Fastly-Backend-Name
X-SD-PageType
X-App-Name
X-Auth-Group-Type
X-Auto-Login
Cdn-Requestid
X-Test
NM-Fastcgi-Cache
X-Cache-Info
X-Cache-Bucket
X-Cache-TTL-Remaining
Origin-EX
Origin-CC
X-Backend-Instance
Server-Hostname
X-Via-Fastly
Release
X-VG-WebCache
X-Tt-Logid
X-Varnishpool
Sever-Int
X-LiteSpeed-Cache-Control
WP-Super-Cache
Mail-Subject
X-Var-Ttl
X-Varnish-Beresp-Status
X-Varnish-Director
X-Cdn-Srv
X-WA-Info
X-Scheme
Ssr
X-Core-Value
Content-Style-Type
Wxu-Next-Commit
We-Hiring
X-Service
Wxu-Next-Hostname
Wxu-Next-Region
X-GeoIP-Region-Code
X-GeoIP-Country-Code
DSUID
AKAMAI
X-GeoIP
X-RateLimit-Limit-Second
X-ECache
X-PAYTM-SRV-ID
X-Loc
X-Nginx-Cache-Key
Yak-Timeinfo
X-NCache
X-Ig-Push-State
X-NMSegId
X-Nyt-Route
X-HS-Content-Campaign-Id
X-Origin-Time
XM
X-Op-Id-All
X-ID
X-Geo-Header
X-Fastly-Cache
Cdnsip
X-RateLimit-Remaining-Second
Cdn-Request-Time
X-AK-Request-ID
X-Request-Time
X-Edge-Server
Server-Ext
X-Ismobilevalue
Content-Script-Type
Cdn-Host
Cdncip
C-Via
X-Gdpr
X-Fmm-Version
X-Region-Sid
X-Req
Canary
X-Newrelic-Synthetics
X-Varnish-Beresp-Ttl
X-Acquia-Purge-Cdn-Unconfigured
X-Tb-Optimization-Total-Bytes-Saved
Odigeo-Trace-Id
X-ApacheServer
X-Ad-Load-Variation
X-Wikidot-Static-Cache
X-Aicache-OS
X-B3-Trace-ID
X-Wikidot-Backend
X-We-Are-Hiring
X-SVT-ORM-RULES
X-GoCache-CacheStatus
X-Proxied-Request
X-From
X-Render-Time
X-Fastly-Backend
X-Request-Host
X-Pool
X-HN
X-Micro-Cache
X-Mly-Id
X-Men
X-Location
X-PERF
X-Human
X-Eu-Site
X-Ec-Custom-Error
X-CGP
X-VarnishDD-TTL
X-CacheTTL
X-Cache-Backend
X-VG-TLSProxy
X-Cache-Aspx
X-Contensis-Viewer-Groups
X-Varnish-Authentication
X-Server-IP
X-DPWN-IS-SECURE
X-Sn-Servicetimems
X-SVT-ORM-VERSION
X-Csrf-Jwt
X-BBC-Edge-Cache-Status
W
X-Dc
Machine
L5d-Success-Class
HA-Ipaddr
On-Server
PFcat
Producers
Pramga
Powered-By
Platform
Ha-Gx-Prefs
Fastly-SSL
CDCHOST
Cache-Provider
Cache-Key
Adler-Geo
Click-Count-Action-Start
Click-Count-Error
Fastly-GeoIP-CountryCode
Esi-Enabled
Country-Code
Cluster
Redirect-Candidate
Is-Eu
Web-Mar-Region
Tube-Get-Contents
V-Age
Req-Svc-Chain
Tube-Got-Results
Tube-Return
Tube-Got-Eval
RNT-Machine
RNT-Time
X-AIR-PT
X-Zone
X-Accel-Expires-Debug
X-Up
X-Date
NGX
L
Apple-News-Services-Parsed-Url
X-Slack-Backend
X-Hash
X-Custom-Header
Proxy-Firewall
X-Slack-Shared-Secret-Outcome
X-Access
X-Section
Apple-News-Services-Host
Apple-News-Services-Handled
True-Client-Country-4JS
Apple-News-Services-Request-Url
X-Cs
X-COUNTRY
X-Varnish-Hits
Debug
X-LB-ID
X-NodeID
X-Pad
Datacenter
X-Varnish-CookieINHashed-On
X-DefElseHash
X-Varnish-CookieHashed-On
X-DefHash
X-CACHE-GROUP
X-Varnish-Remaining-TTL
Mime-Version
X-Nf-Request-Id
X-Client-Ip
X-Nananana
X-HA-Backend
X-Depends
X-Refresh
X-Via-Popv
X-Via-Poph
Locid
X-Datadome
X-Via-Popn
SID
Fastly-Drupal-HTML
X-Akamai-Transformed
X-VHOST
X-Amz-Meta-Cb-Modifiedtime
CloudFront-Viewer-Country
X-VC-TTL
Pics-Label
X-Platform-Router
X-Platform-Processor
X-LiteSpeed-Tag
X-Platform-Cluster
X-M-Log
X-M-Reqid
X-Servedbyhost
X-Cache-FS-Status
X-Parent-Response-Time
X-Cached-By
Ngx-Var-Key
X-Old-Content-Length
GeoIP-Latitude
X-CACHE-AGE
Fastly-Drupal-Html
X-TIME
X-B3-Parentspanid
X-LB-NoCache
X-DynaTrace-JS-Agent
Resin-Trace
X-TH-Server
X-Moov-T
X-CDN-Cache-Status
Server-Info
X-Moov-Xdn-Version
Cf-Ipcountry
X-CS
GeoIp-Country-Code
Server-ID
Cross-Origin-Embedder-Policy-Report-Only
BehaviorPad-Version
X-Litespeed-Tag
X-Presslabs-Stats
Cdn
X-ZONE
X-Wa
X-APP
X-Nc
X-HITS
X-VCache
X-Vgn-Hpd-Reason
NtCoent-Length
X-S-Cookie
X-Application
X-External-Request-Id
X-NewRelic-App-Data
X-TX-ID
X-Destination
X-B-Cookie
FSS-Cache
X-User
Cf-Device-Type
X-IAuth-Set-Uid
X-Varnish-Beresp-TTL
CDN
X-Fpc
Uri
True-Client-IP
X-Zen-Fury
X-Esi
X-HostName
X-Sigma-Backend
X-Rocket-Build-Number
X-Instance-Name
X-Cache-Date
X-Sigma
X-Srv
X-Vc
X-Content-Length
True-Client-Ip
X-Route-Name
X-Providence-Cookie
Tcn
Load-Balancing
Srv
X-VServer
X-Flags
X-Is-Crawler
X-Aspnet-Duration-Ms
X-API-Version
Serverhost
X-Dynatrace-Js-Agent
X-DynaTrace
X-Oracle-DMS-ECID
X-Cdn-Forward
X-Dispatcher-Number
GeoIP-Country-Code
X-WA
X-NC
X-HOST
S-Rt
X-Branch-Name
X-FPC
X-Segment-20210421
Request-ID
Vc-Max-Age
Product
X-Dispatch
X-Cdn-Cache-Status
X-CLOUD-TRACE-CONTEXT
X-APP-VERSION
Hostname
Ohc-File-Size
X-Page-View
Server-Id
X-DataCenter
X-RequestId
X-B3-Spanid
ServerName
Geoip-Latitude
X-FL-QIT-DEBUG
Srvid
X-Lb-Nocache
Type
X-Webkit-Csp-Report-Only
X-Ckpd-Fst-Backend
X-Sql-Count
X-Sql-Duration-Ms
X-Http-Reason
X-Irp-Debug
X-ServedByHost
X-Geo
X-Bug-Bounty
Cloudfront-Viewer-Country
Cl-Cache
CacheControlHeader
DataCenter
X-VCL-Version
X-Via-Edge
IsBot
X-Via-CDN
X-SIPLIST1
X-Via-SSL
X-CACHE-KEY
Epwk-X-Cache
Edge-Copy-Time
Ohc-Cache-HIT
X-Owner
Origin-Trial
Lb
WZWS-RAY
X-Cache-Ttl
PICS-Label
X-Via-PopH
X-Ua
X-Core-Mission
X-Proxy-CacheRZ
ServerHost
X-Correlation-ID
X-Via-PopN
X-Ha-Backend
Cross-Origin-Opener-Policy-Report-Only
X-App
MIME-Version
X-Via-PopV
XkeyRZ
X-Srcache-Store-Status
X-Srcache-Fetch-Status
Rtss
X-MSEdge-Flight
X-CSRF-TOKEN
X-MSEdge-Features
X-MiniProfiler-Ids
N-Cache
X-Qloud-Router
X-Lb-Id
X-Hit
Sm-Log-Id
X-Vmg-Version
X-Service-Response-Time
X-Acquia-Application-UUID
X-Sqd-Ctime
X-Sqd-Stime
Cneonction
X-Acquia-Site
X-Acquia-Purge-Tags
X-Akamai-Device-Characteristics
X-Acquia-Application-Trace
X-Limited
X-Datacenter
X-Web-Server
Warning
X-Requestid
X-Fastly-Country-Code
CountryCode
X-Amz-Meta-Opti
X-Iplb-Request-Id
X-Iplb-Instance
X-Litespeed-Cache-Control
X-LAGOON
User-Agent
X-Th-Server
X-Ramcache
X-Serial
X-Snapshot-Date
X-Info
X-HubSpot-Correlation-Id
X-Gamma-Serve
Xkeylog
X-IN-APIGATEWAYSSL
X-IN-APIGATEWAY
X-Udemy-Cache-App-Namespace
X-Amz-Meta-Sha256
X-Amz-Meta-S3b-Last-Modified
Xkey-La3
X-RAMCache
Ngx
X-Dw-Trace-Id
X-Proxy-Cache-La3
X-Check-Cacheable
X-Akamai-Pragma-Client-IP