Threat Level: green Handler on Duty: Guy Bruneau

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
Pragma
X-Powered-By
X-XSS-Protection
CF-RAY
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
P3P
Alt-Svc
X-Cache-Hits
X-UA-Compatible
X-Xss-Protection
X-Served-By
CF-Ray
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Request-Id
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
Access-Control-Allow-Credentials
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
X-Drupal-Cache
X-Generator
X-Cache-Status
X-Check
X-Cacheable
X-Envoy-Upstream-Service-Time
X-DNS-Prefetch-Control
X-Request-ID
Timing-Allow-Origin
X-Iinfo
X-FRAME-OPTIONS
X-Dns-Prefetch-Control
X-Drupal-Dynamic-Cache
Feature-Policy
X-Content-Security-Policy
Content-Encoding
Access-Control-Expose-Headers
Upgrade
Status
X-CDN
X-AspNetMvc-Version
Server-Timing
X-XSS-PROTECTION
Access-Control-Max-Age
X-Amz-Request-Id
Request-Context
X-Amz-Id-2
X-Turbo-Charged-By
X-AH-Environment
X-Via
X-Robots-Tag
X-Backend
X-Cache-Group
Cf-Edge-Cache
Keep-Alive
Host-Header
X-Proxy-Cache
X-Hacker
X-UA-Device
X-Server
X-Rq
X-Server-Powered-By
X-Age
Allow
X-Vhost
X-Varnish-Cache
X-Ws-Request-Id
EagleId
X-Dispatcher
X-Amz-Version-Id
X-LiteSpeed-Cache
Grace
Cf-Apo-Via
P3p
Nel
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Page-Speed
X-Device
Cf-Railgun
EagleEye-TraceId
X-Aws-Lambda-Call-Status
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
Accept-CH
X-Pingback
X-Node
X-Host
X-WebKit-CSP
X-Server-Id
X-OneAgent-JS-Injection
Surrogate-Control
X-Backend-Server
X-CST
X-Readtime
X-Nginx-Cache-Status
X-Akam-SW-Version
X-Cache-Lookup
Permissions-Policy
X-Content-Security-Policy-Report-Only
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Request-Id
X-Application-Context
X-Nginx-Upstream-Cache-Status
X-Cloud-Trace-Context
X-Trace
X-Response-Time
X-Edge
Accept-CH-Lifetime
X-HW
Accept-Ch-Lifetime
X-Ua-Compatible
Content-Location
X-Mod-Pagespeed
X-Clacks-Overhead
X-Oneagent-Js-Injection
X-Url
X-Midtier
X-ECACHE
X-ESI
Rating
X-Amz-Server-Side-Encryption
X-Mcache
Xkey
X-Country
X-Ruxit-JS-Agent
X-Upstream
X-Ruxit-Js-Agent
X-Litespeed-Cache
X-Vcap-Request-Id
X-Vname
X-PC
X-TtlSet
Cache-Tag
X-D2id
X-Rack-Cache
X-MS-InvokeApp
Verso
X-Exp-Variant
X-GoogleNews-Bot
X-Cdn-Fetch
X-Element-Page-Cache
X-Exp-Id
X-Kinja-Server
X-Kinja-Build
X-Kinja
X-Use-Magma
X-Kinja-Revision
Edge-Control
X-Cache-TTL
Fastly-Restarts
RTSS
X-Powered-By-Plesk
X-VARITI-CCR
Origin-Trial
X-Ac
X-Navigation-Version
X-Abt-Application-Version
X-Content-Type
X-Cached
X-Goog-Hash
Service-Worker-Allowed
Accept-Ch
X-Country-Code
X-Ttl
X-GitHub-Request-Id
X-Amz-Rid
X-Sol
Display
X-Middleton-Display
Pagespeed
X-Browser-Type
X-Mg-S
X-Dw-Request-Base-Id
X-WebKit-CSP-Report-Only
X-Server-Name
X-SharePointHealthScore
SPRequestGuid
Cross-Origin-Opener-Policy
Arr-Disable-Session-Affinity
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Instrumentation
X-Webkit-CSP
X-Varnish-TTL
X-Powered-CMS
X-Amzn-Trace-Id
Response
X-Middleton-Response
AR-ATIME
AR-PoweredBy
AR-SID
AR-Request-ID
X-B3-TraceId
SPRequestDuration
SPIisLatency
X-Cache-Key
AR-CACHE
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Fastly-Request-ID
X-Version
X-Fastcgi-Cache
X-Jurisdiction
X-HP-Trace-Id
X-HP-Webp
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-Cnection
X-Accel-Expires
Cache-Tags
X-T
Cache-Status
Front-End-Https
X-Client-IP
Edge-Cache-Tag
X-Pinterest-Rid
Pinterest-Generated-By
Pinterest-Version
X-MSEdge-Ref
X-Px
X-Ser
X-B3-Traceid
X-Hits
X-Times
Nginx-Cache
X-NF-Request-ID
Public-Key-Pins
X-NWS-LOG-UUID
X-Recruiting
MRF-Tech
X-RateLimit-Remaining
X-B3-TraceId-Primal
Mrf-Cache-Status
X-LLID
X-Request-Processing-Time
X-Request-Received
X-Frontend
Server-Node
X-Kinja-CCPA
X-Ua-Browser
X-Ua-Device
Payment
X-Shield-Request-Id
X-Webkit-CSP-Report-Only
Access-Control-Request-Method
X-DIS-Request-ID
X-Erf-Stays-Pdp-Viaduct-Migration-Web
TP-Cache
X-RateLimit-Limit
X-Goog-Metageneration
S
X-HS-Combine-CSS
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Cache-Config
MicrosoftSharePointTeamServices
TP-L2-Cache
X-LB-Cache
X-Content-Digest
X-PressLabs-Stats
Content-MD5
X-Distributor
Realpath
X-Request-Handler-Origin-Region
X-Microsite
X-Ezoic-Cdn
X-Forwarded-For
X-Hostname
X-FB-Debug
X-Page-Id
X-FastCGI-Cache
Access-Control-Allow-Method
Fastcgi-Cache
Accept-Charset
X-GUploader-UploadID
X-Geo-Country
X-Cluster-Name
X-Rid
X-Amz-Apigw-Id
X-Protected-By
X-Amzn-RequestId
X-Seen-By
X-Ratelimit-Remaining
X-Envoy-Decorator-Operation
Cleartype
TCN
X-B3-Sampled
X-Correlation-Id
DC
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-Newrelic-App-Data
Referer-Policy
X-TEC-API-VERSION
X-Mobile
X-Origin-Server
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Origin-Cache
X-Debug-Info
Cross-Origin-Resource-Policy
X-Ratelimit-Limit
X-Varnish-Backend
X-Logged-In
X-Git-Hash
X-XRDS-Location
X-Webkit-Csp
X-Contextid
X-TTL
X-Varnish-Grace
X-Edge-Location-Klb
X-Azure-Ref
X-Kinsta-Cache
X-Grace
X-Is-Crawler
X-Amz-Replication-Status
X-Fb-Rlafr
X-App-Environment
X-Providence-Cookie
X-Flags
X-Request-Guid
X-Aspnet-Duration-Ms
X-Route-Name
X-Aspnet-Version
Surrogate-Key
X-Revision
X-Content-Options
Count-Hit
Alternate-Protocol
X-TT
X-IPS-LoggedIn
X-Amz-Meta-S3cmd-Attrs
X-Server-ID
Healthy
X-Wix-Request-Id
X-Forwarded-Proto
X-App-Server
X-Whom
Frame-Options
X-Hosted-By
Charset
WPO-Cache-Status
WPO-Cache-Message
MS-Author-Via
X-Akamai-Edgescape
Viewport
X-Daa-Tunnel
X-Id
Filterid
X-Magnolia-Registration
Retry-After
X-B
Paypal-Debug-Id
X-Backend-Name
X-Cache-Age
Section-Io-Cache
X-F-Cache
X-Client-Ip
X-Az
SRV
X-AppVersion
X-Activity-Id
X-Trace-Id
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Cache-Control
X-Proxy-Cache-Info
X-Www-Served-By
Server-Name
X-Nf-Request-Id
X-App-Version
X-Type
X-RateLimit-Reset
X-Time
X-Varnish-Server
X-Varnish-Ttl
VIX-Pulpo-Upstream-Status
Host
X-ARC
X-Http-Reason
X-Instance
VIX-Pulpo-Node
Akamai-GRN
X-Proxy
X-Cache-Rule
SD-X-WS
X-Rule
X-Original-Request-Id
Refresh
X-Response-Served-From
X-UUID
Front
X-Edge-Location
X-User-Agent
Protected
X-Akamai-Request-ID2
X-Cache-Grace
X-Varnish-Age
X-Status
X-Rocket-Nginx-Serving-Static
X-FW-Type
X-Region
X-Rendered-As
From-Origin
X-L-Path
Fastly-SIE
X-FW-Dynamic
Fastly-SWR
X-FW-Version
X-FW-Serve
Amp-Access-Control-Allow-Source-Origin
X-Is-Bot
X-FW-Server
X-FW-Hash
Version
X-Page-View
X-Environment-Context
X-Unique-Id
X-Cacheable-TTL
X-Framework
X-Jobs
X-FW-Static
X-N
X-Adobe-Content
X-Cache-Time
X-Adobe-Loc
X-Oracle-Dms-Ecid
X-EdgeConnect-Cache-Status
Access-Control-Request-Headers
X-Tumblr-Pixel
X-Oracle-Dms-Rid
X-RemovedCookies
X-Tumblr-Pixel-0
X-ProcessESI
X-G
X-Tumblr-User
X-Tumblr-Pixel-1
X-Load-Cache
X-Language
ServerID
X-COUNTRY
X-Source
Country
Content-Disposition
X-Datadog-Parent-Id
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
X-CDN-Forward
X-Upgrade-Enabled
X-Drupal-Cache-Tags
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Vcache
X-HTML-Minification-Powered-By
X-Datadog-Sampled
X-Mg-Request-UUID
Countrycode
X-Amzn-Remapped-Content-Length
Accept-Language
X-Tt-Trace-Tag
X-Debug-IsConnected
X-Tt-Trace-Host
X-Debug-IsPreview
X-DynaTrace
X-Generated-By
X-B-Cache
X-DynaTrace-JS-Agent
Backend
X-Signature
Xet-Cookie
X-ID
CF-IPCountry
X-Xrds-Location
Webserver
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
X-Nginx-Cache
Liferay-Portal
X-DataDome
Xserver
X-ECache
X-Tt-Logid
X-Httpd
X-Servername
X-Mode
X-Device-Type
X-NYM-Debug-Backend
Url
X-Tec-Api-Origin
X-Tec-Api-Root
X-Drupal-Cache-Contexts
X-Tec-Api-Version
X-Content-Powered-By
X-B3-SpanId
X-Zen-Fury
X-Content-Age
X-Erf-Web-Scheduler
Load-Balancing
X-Tb
X-Cache-Operation
S-Rt
Onion-Location
Meta-Geo
GEO-INFO
Locale
Fastcgi-Useragent
Azure-RegionName
X-Urbn-Context-Path
X-Urbn-Site-Id
X-Varnish-Cache-Hits
Azure-InstanceId
Azure-SiteName
X-UPSTREAM-Address
Azure-Version
X-Sucuri-Cache
Azure-SlotName
X-Sucuri-ID
Filters
X-ServerID
X-GeoCountry
X-JoinUs
X-GeoCode
X-Director
X-Cache-Action
X-Container-Uri
X-LAGOON
X-Git-Commit
X-Rewrite-Enabled
X-Say-Cacheable
X-Say-TTL
X-SayCDN-TTL
X-Proto
X-SaId
X-Cluster-Node
X-Soup
X-Varnish-Hostname
Uber-Trace-Id
X-VC-Cache
X-PHP-Host
X-Forwarded-Host
X-RM-Cache-TTL
X-Labrador-Cache-Channel
X-XRDS-LOCATION
X-Adobe-Source
X-Ms-Request-Id
X-VCT
X-Ms-Version
X-Served-From
X-Sql-Duration-Ms
X-Generation-Time
X-Storage
X-Logging-Id
X-Sql-Count
X-Detected-As
X-Cache-Server
Web-Mar-Node
TWC-GeoIP-LatLong
TWC-Locale-Group
TWC-Privacy
Webcakes-App-Name
TWC-GeoIP-Country
TWC-Device-Class
Node
Property-Id
TWC-Connection-Speed
Webcakes-Region
X-Zipkin-Id
X-RCS-CacheZone
X-R9-Blue-Green-Version
X-Proxied
X-Origin-Hint
X-Routing-Service
X-FB-TRIP-ID
X-Debug
X-Skip-Cache
X-Extlb
Mn-Server-Ip
Webcakes-App-Version
DB-Nickname
X-Format
X-Fetched-On
X-Tumblr-Pixel-3
Selected-Fe
X-Tumblr-Pixel-2
X-Uri
X-LSADC-Cache
X-Proxy-Build
X-Timing-Wait
X-Lambda-Id
X-Template
OT-Force-Account-Verify
Fastly-Drupal-HTML
X-TimeS
Source
CDN-RequestId
X-MP-GENERATED-AT
X-Origin-Date
X-Ratelimit-Reset
X-Loop
X-Srv
X-Cache-Expired-At
X-Cache-Hit
X-Tncms
X-MCACHE
X-Varnish-Hits
X-Pass-Why
X-Endurance-Cache-Level
X-Redis-Cache
X-Ua
Content-Secure-Policy
X-NGENIX-Cache
X-Cache-TTL-Remaining
Upgrade-Insecure-Requests
X-UA-Device-Type
X-Via-JSL
X-Datadome
X-Real-IP
Cross-Origin-Window-Policy
X-Pubstack
X-AIR-PT
X-Origin-TTL
X-Hcs-Proxy-Type
X-CCDN-CacheTTL
X-Node-Name
X-CCDN-Origin-Time
Section-Io-Id
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
X-Origin-CC
Section-Origin-Responded
X-Fastly-Request-Id
X-Server-W
X-S
NGB
X-Rn-Rsrv
Cache-Hits
X-Cache-Host
Cache-Provider
X-CSRF-Token
X-PHP-Backend
X-RTag
CDN-Uid
Cache-Name
CDN-CachedAt
CDN-PullZone
CDN-Cache
CDN-RequestCountryCode
CDN-EdgeStorageId
CDN-RequestPullCode
MS-CV
CDN-RequestPullSuccess
Ms-Operation-Id
X-Restarts
X-Xfnlog-Site
X-Hl-Ver
X-Reqid
X-IPLB-Instance
X-Cms-Context
Apigw-Requestid
X-Cache-Type
X-Akamai-Transformed
X-Optimistic-Header
X-IPLB-Request-ID
X-GEO
X-URL
X-No-Session
X-Parent-Response-Time
X-BYPASS-REASON
X-Newrelic-Synthetics
X-Aspnetmvc-Version
X-ProxyCache-Status
X-ProxyCache-Key
X-Correlation-ID
X-Vtex-Remote-Cache
X-Viewer-Country
X-SRCache-Key
X-We-Are-Hiring
X-Wikidot-Static-Cache
X-A-Dam
X-Wikidot-Backend
X-VG-WebCache
X-A-Ccd
T-Server
VNS-Cache
We-Hiring
X-Vdms-Path
X-Var-Ttl
W
X-A
VNS-Age
True-Client-Country-4JS
Vix-Hermes-Req-Id
X-Vdms-Version
Web-Mar-Region
X-Tenant
X-Worker
Gannett-Cam-Experience-Id
Fastly-SSL
Gh-Request-Id
Ha-Gx-Prefs
L
HA-Ipaddr
Fastly-GeoIP-CountryCode
Fastly-Backend-Name
Candidate-Md5Url
Canary
CPC-Age
CPC-Cache
DCR-Processing-Time-Ms
DCR-Decision-By
L5d-Success-Class
Xc-Version
Rendered-Blocks
Redirect-Candidate
Server-Host
X-Slack-Shared-Secret-Outcome
Surrogated-Key
Sslversion
Odigeo-Trace-Id
Ngx.Var.Host
Magicmarker
Lang
Mail-Subject
MD5-Digest
N-Cache
Meta-Geo-Continent
X-Wix-Viewer-Type
X-Rojux
X-Debug-Cache-Fetch
X-Date
X-Has-Esi
X-Debug-Cache-Store
X-Destination
X-GeoIP-Region-Code
X-Irp-Debug
X-D
X-JWT-State
X-CGP
X-Conf
X-Is-Gdpr
X-Csrf-Jwt
X-Developer
X-Dispatcher-Number
X-External-Request-Id
X-Ec-Fail
X-Ec-GeoHdr
X-Eu-Site
X-Epic-Correlation-Id
X-Fastly-Backend
X-FC-Vary-Parameters
X-GeoIP-Country-Code
X-Ec-Custom-Error
BehaviorPad-Version
X-Gdpr
X-Forwarded-Path
X-CF-Lambda-Version
X-Mvc-Supplant-Cachable
X-Request-Host
X-Accel-Expires-Debug
X-RateLimit-Remaining-Second
X-Aed
X-B-Cookie
X-Application
X-Accel-Buffering
X-S-Cookie
X-Slack-Backend
X-A-Wwc
X-Shop-Environment
X-SD-PageType
X-ScT
X-Bc-Bl
X-BCube-Filmed-By
X-Origin-Time
X-Cdn-Diag
X-CF-Lambda-Fn
X-Orig-Expires
X-Nyt-Route
X-CacheTTL
X-Cache-NE
X-Cache-Bucket
X-Bl-Debug
X-RateLimit-Limit-Second
X-Cache-Info
X-Policy
X-A-Dgt
X-A-Dcw
X-Handled-By
X-VWS-Id
X-CACHE-AGE
X-AWS-Id
X-Cluster
X-LJ-Flow-ID
X-Via-Fastly
X-Access
X-Section
X-Fmm-Version
X-Forwarded-Site
X-Generated-On
Thinkindot-CacheControl-Type
Thinkindot-Control
X-Proxy-Cache-Status
X-Esi-Check
X-Geo-Header
X-Gzip
X-Level-Front-Cache
X-Mid
X-INCAP-ABP
X-Human
Thinkindot-CacheControl
X-Hash
X-Alternate-Cache-Key
X-DPWN-IS-SECURE
X-Cdn-Origin
X-Clara-WADP
X-Clientip
X-Cache-Id
X-Cache-Debug
X-BBC-Edge-Cache-Status
X-Bip
X-CMSURLCustom
X-Core-Mission
X-DefHash
X-ApacheServer
X-App-Name
X-DefElseHash
X-Core-Value
X-Mly-Id
X-Auto-Login
X-Old-Content-Length
X-Thinkindot-L3
X-Up
X-Variation
X-Thanos
X-Test
X-Storefront-Renderer-Rendered
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-VServer
X-WADP-Cache
X-App
X-Vmg-Version
X-VG-TLSProxy
X-Varnish-Remaining-TTL
X-Varnishpool
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-PAYTM-SRV-ID
X-PERF
X-Platform
X-Owner
X-Origin-Response-Time
X-Node-Id
TDXMobile
X-Org
X-Pool
X-Qloud-Router
X-ShopId
X-Shopify-Stage
X-Sn-Servicetimems
X-ShardId
X-Server-IP
X-Request-Time
X-S-Maxage
X-Nitro-Cache
X-Loc
Memcached
Machine
Is-Eu
Origin
Platform
Release
Producers
Host-ID
Expect-Staple
Adler-Geo
AKAMAI
Cmsid
Cmstype
Environment
Datacenter
Req-Svc-Chain
ServedBy
AMP-Access-Control-Allow-Source-Origin
User-Cache-Control
X-Cdn-Srv
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
X-TA-CDN-Provider
Apple-News-Services-Request-Url
Server-Hostname
X-Mvc-Supplant-OutputCached
X-NodeID
X-Nginx-Cache-Key
X-Nananana
X-WA-Info
X-Block-Status
Apple-News-Services-Handled
X-GeoIP
X-TIM-N
CDCHOST
X-Gen-Mode
X-From
CloudFront-Viewer-Country
NM-Fastcgi-Cache
X-Origin
X-Hnp-Log
X-Device-Os
X-Dispatcher-Server
Country-Code
DSUID
X-Akamai-Device-Characteristics
Esi-Enabled
Server-Ext
Sever-Int
X-Scale
X-Vcl-Version
X-Tx-Id
X-NCache
X-Presslabs-Stats
Origin-EX
X-LB-NoCache
Origin-CC
C-Via
Wxu-Next-Commit
WP-Super-Cache
Ssr
Wxu-Next-Hostname
X-Refresh
X-Instance-Name
Wxu-Next-Region
Pics-Label
Server-Info
X-Op-Id-All
X-Cache-Enabled
X-Cs
X-Air-Trace-Id
X-Air-Source
X-Air-Hostname
X-Amz-Meta-Cb-Modifiedtime
Server-ID
X-Cache-Status-Check
X-Web-Node
Time
Memory
X-TIME
X-Azure-Ref-OriginShield
Hostname
X-HA-Backend
X-ZONE
X-API-Version
GeoIP-Latitude
X-Dc
Origin-Agent-Cluster
Cf-Device-Type
NGX
X-Tb-Optimization-Total-Bytes-Saved
X-Origin-Expires
Cache-Host
X-Platform-Cluster
X-Microcachable
X-Platform-Processor
X-Platform-Router
X-VHOST
XM
X-Varnish-Beresp-Ttl
X-CACHE-GROUP
X-Varnish-Beresp-Grace
Cdn-Requestid
X-Site-Version
X-Locale
X-VarnishDD-TTL
PFcat
X-Fpc
X-HN
X-Wp-Cf-Super-Cache-Active
Resin-Trace
X-Micro-Cache
X-Ad-Defer-Variation
X-Vgn-Hpd-Reason
X-DC
A
Edge-Copy-Time
Locid
YJS-ID
X-Via-CDN
X-FL-EDGE
X-Via-Edge
X-Internal-Host
X-Webkit-Csp-Report-Only
X-FL-QIT-DEBUG
X-Via-SSL
Srvid
Sid
X-B3-Spanid
X-TraceId
X-WP-CF-Super-Cache-Active
X-Zone
X-AB
X-Cache-ASPX
True-Client-Ip
X-FireWall-Port
X-Github-Request-Id
X-Pod-Name
X-Contensis-Viewer-Groups
X-ATG-Version
X-Upstream-Ht
X-Cached-By
X-Upstream-Ct
X-Buckets
Location
User-Agent
X-B3-Parentspanid
GeoIP-Country-Code
X-DataCenter
Uri
X-Moov-Xdn-Version
X-Moov-T
Cache-Key
X-Geo-Region
X-Varnish-Authentication
X-LiteSpeed-Cache-Control
X-FTR-Request-ID
IsBot
X-Backend-Instance
X-Info
X-SIPLIST1
X-VCache
X-Accel-Version
CF-Ctrl
X-Planisys-CDN-Rules
X-Datacenter
X-Planisys-CDN-TTL
X-Nitro-Cache-From
X-Nitro-Rev
X-Platform-Server
X-Planisys-CDN-Cache
X-NGINX-Cache
State
X-HS-Content-Campaign-Id
X-LiteSpeed-Tag
Lb
X-Is-Desktop
X-Provided-By
X-Is-Tablet
X-Geo
X-Tcp-Rtt
X-Is-Mobile
X-Is-Supported-Browser
X-Browser-Name
X-MSEdge-Features
GeoIp-Country-Code
X-Release
X-MSEdge-Flight
X-Fastly-Cache
NtCoent-Length
X-VC
SID
X-Sigma-Backend
Cdn
X-Sigma
XServer
X-Rocket-Build-Number
X-CS
X-RN-RSRV
X-Cache-Remote
X-NewRelic-App-Data
X-CSRF-TOKEN
Path
X-Vgn-Hpd-Cached
Cache
X-Vgn-Hpd-Variations-Key
True-Client-IP
X-Hyper-Cache
X-Vgn-Hpd-Ssi
Epwk-X-Cache
X-Api-Version
X-GeoIP-City
X-Generated-In
X-HS-Status
X-TRACE-ID
X-Scheme
X-Gamma-Serve
X-Frame-Option
Fastly-Drupal-Html
X-Service
X-Webstats-RespID
X-FPC
Tcn
X-HostName
X-GoCache-CacheStatus
X-SRV
Ohc-File-Size
Cache-Tv-Group
Cf-Ipcountry
X-UA
Serverid
CountryCode
X-Rebelmouse-Cache-Control
X-APP-VERSION
X-Rebelmouse-Surrogate-Control
Cdnsip
X-Air-Pt
X-EC-Lua
X-Pad
X-AK-Request-ID
X-Esi
Cdncip
Kp-EeAlive
X-Amz-Meta-Opti
X-Guploader-Uploadid
Srv
X-Vercel-Id
X-Edge-Server
HostName
X-Branch-Name
X-Vercel-Cache
X-Traceid
WebServer
Cdn-Request-Time
X-Wp-Cf-Super-Cache
Cdn-Host
X-Wp-Cf-Super-Cache-Cache-Control
X-Cache-Ttl
X-Location
X-Origin-Cache-Key
X-Mobile-URL
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-NMSegId
Env
X-Aicache-OS
X-Vc
Proxy-Connection
X-FTR-Backend
WZWS-RAY
Req-ID
X-Proxy-CacheRZ
XkeyRZ
X-Country-Code-Real
M-TraceId
X-FTR-Cache-Status
X-FTR-Balancer
Yak-Timeinfo
X-FTR-Backend-Server
X-FTR-Expires
X-Cdn-Cache-Status
On-Server
X-Men
X-Region-Sid
X-Cache-Tags
Ohc-Cache-HIT
CacheControlHeader
X-Developers
X-Cdn-Request-ID
X-CACHE-KEY
X-VCL-Version
X-TX-ID
CDN
X-Wa
Ngx
Tube-Get-Contents
Geoip-Latitude
X-LB-ID
X-Nc
X-Cache-FS-Status
X-Via-Popv
X-Via-Poph
X-V-Cache
X-Akamai-Pragma-Client-IP
X-NWS-UUID-VERIFY
Click-Count-Action-Start
V-Age
X-Cdn-Forward
Click-Count-Error
X-Via-Popn
X-Minions-Version
X-B3-Trace-ID
X-SB
RNT-Time
Tube-Got-Eval
Tube-Return
Cluster
Tube-Got-Results
X-Ad-Load-Variation
RNT-Machine
X-CDN-Cache-Status
X-Edge-Pop
X-Req
Mime-Version
X-Servedbyhost
LB
X-Acquia-Purge-Cdn-Unconfigured
X-Lb-Cache
Server-Id
Pramga
X-M-Reqid
X-Scope-Id
X-Request-Start
X-M-Log
ENV
Content-Script-Type
Content-Style-Type
WWW-Authenticate
X-Ha-Backend
X-Fastly-Country-Code
X-WP-CF-Super-Cache-Cookies-Bypass
CF-Cached-On
X-TT-LOGID
X-Snapshot-Date
X-MiniProfiler-Ids
X-Qnm-Cache
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
X-Request-URI
X-Dw-Trace-Id
X-Edge-POP
X-Lb-Nocache
X-Acquia-Site
X-Check-Cacheable
X-Acquia-Purge-Tags
X-Acquia-Application-UUID
X-Via-Ucdn
X-Acquia-Application-Trace
X-Varnish-Beresp-Status
X-Tim-N
X-Shield-Cache-Expires
X-User
PICS-Label
Yjs-Id
X-APP
X-Fastly-Backend-Reqs
X-Processor
X-Iauth-Set-Uid
X-Ckpd-Fst-Backend
X-RAMCache
Vha6-Origin
X-Cached-Since
X-ElasticPress-Query
X-Litespeed-Cache-Control
X-Fastly-Cache-Hits
X-TH-Server
CACHE-MISS-TO-ORIGIN
Log-Origin
X-Miniprofiler-Ids
Inserted-Into-Cache-At
Cneonction