Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
CF-RAY
Expect-CT
Accept-Ranges
Pragma
X-Powered-By
X-XSS-Protection
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Xss-Protection
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-Served-By
X-UA-Compatible
X-Download-Options
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
Accept-CH
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
Accept-CH-Lifetime
X-Ua-Compatible
X-DNS-Prefetch-Control
X-Drupal-Cache
X-Check
X-Cache-Status
X-Generator
Server-Timing
X-Request-ID
X-Cacheable
X-Envoy-Upstream-Service-Time
Timing-Allow-Origin
X-FRAME-OPTIONS
X-Iinfo
X-Drupal-Dynamic-Cache
X-Content-Security-Policy
Access-Control-Expose-Headers
Feature-Policy
X-CDN
Content-Encoding
Status
Upgrade
X-AspNetMvc-Version
CF-Ray
Access-Control-Max-Age
X-Amz-Request-Id
X-Via
X-Amz-Id-2
Cf-Edge-Cache
Host-Header
EagleId
Keep-Alive
Request-Context
X-Backend
X-Cache-Group
X-UA-Device
X-AH-Environment
X-Robots-Tag
X-Server
X-Hacker
X-Turbo-Charged-By
X-Proxy-Cache
Permissions-Policy
Xkey
X-Ws-Request-Id
X-Rq
X-Age
X-Vhost
X-Amz-Version-Id
X-Dns-Prefetch-Control
X-Dispatcher
Cf-Apo-Via
Allow
X-Swift-SaveTime
X-Swift-CacheTime
X-Server-Powered-By
Grace
Ali-Swift-Global-Savetime
X-Varnish-Cache
X-LiteSpeed-Cache
P3p
X-Page-Speed
X-Pingback
X-Cache-Lookup
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-OneAgent-JS-Injection
X-Device
Cf-Railgun
X-Backend-Server
EagleEye-TraceId
X-Host
X-Server-Id
X-WebKit-CSP
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Response-Time
X-Readtime
X-Akam-SW-Version
Surrogate-Control
X-HW
Request-Id
X-Ruxit-JS-Agent
X-Cloud-Trace-Context
Content-Location
X-Node
X-Application-Context
X-Nginx-Upstream-Cache-Status
X-Nginx-Cache-Status
X-NWS-LOG-UUID
X-Litespeed-Cache
X-Country
Service-Worker-Allowed
X-Country-Code
X-CST
X-Content-Type
X-Clacks-Overhead
Cache-Tag
X-Trace
X-Url
Rating
X-Rack-Cache
X-Amz-Server-Side-Encryption
X-Times
Nginx-Cache
X-FTR-Request-ID
X-TtlSet
X-PC
X-Vname
X-Daa-Tunnel
X-Oneagent-Js-Injection
X-Server-Name
X-Webkit-Csp
Cross-Origin-Opener-Policy
X-Edge
X-Mcache
X-Midtier
X-Browser-Type
X-Powered-By-Plesk
X-ESI
X-Cnection
X-GitHub-Request-Id
X-Upstream
Edge-Control
X-D2id
X-Element-Page-Cache
Verso
X-MS-InvokeApp
X-Ac
AR-ATIME
X-Cdn-Fetch
AR-Request-ID
AR-SID
AR-PoweredBy
X-Exp-Id
X-Kinja
X-Kinja-Build
X-Kinja-Server
X-GoogleNews-Bot
X-Kinja-Revision
X-Exp-Variant
Accept-Ch-Lifetime
X-ECACHE
X-FastCGI-Cache
X-B3-TraceId
X-Vcap-Request-Id
X-Cache-TTL
X-Ser
X-Abt-Application-Version
X-Navigation-Version
AR-CACHE
X-Dw-Request-Base-Id
SPRequestDuration
SPIisLatency
X-Mod-Pagespeed
X-SharePointHealthScore
SPRequestGuid
X-Amz-Rid
Fastly-Restarts
X-NF-Request-ID
X-Client-IP
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Erf-Bev-Bev
X-Instrumentation
X-Erf-Bev-Bev-Is-Generated
X-Aws-Lambda-Call-Status
X-Middleton-Display
Pagespeed
X-Sol
Display
Edge-Cache-Tag
X-Mg-S
X-Kinsta-Cache
X-Edge-Location-Klb
S
X-Powered-CMS
X-Goog-Hash
Response
X-Middleton-Response
Cache-Status
Access-Control-Request-Method
X-Version
X-Amzn-Trace-Id
X-VARITI-CCR
X-Ruxit-Js-Agent
X-ARC
X-Cache-Key
RTSS
X-Fastly-Request-ID
X-Content-Digest
X-Ratelimit-Limit
X-TraceId
Cross-Origin-Resource-Policy
X-Forwarded-For
X-RateLimit-Remaining
X-T
X-Recruiting
Realpath
X-Correlation-Id
X-PDP-UNCACHING-HASH
X-Varnish-TTL
X-MSEdge-Ref
Fastcgi-Cache
Front-End-Https
X-Cached
X-Ratelimit-Remaining
MS-Author-Via
Content-MD5
X-Pinterest-Rid
Pinterest-Version
Pinterest-Generated-By
X-HS-Hub-Id
X-Ua-Browser
X-HS-Cache-Config
X-HS-Content-Id
X-Shield-Request-Id
X-FTR-Backend-Server
X-FTR-Balancer
X-FTR-Cache-Status
X-FTR-Backend
X-Country-Code-Real
X-Protected-By
Public-Key-Pins
Server-Node
X-Request-Received
X-Request-Processing-Time
Payment
X-Forwarded-Proto
MicrosoftSharePointTeamServices
X-Frontend
X-LLID
TP-Cache
X-TTL
X-HS-Combine-CSS
Arr-Disable-Session-Affinity
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Ttl
X-Distributor
X-FTR-Expires
X-Server-ID
X-Jurisdiction
X-Accel-Expires
X-HP-Webp
X-HP-Trace-Id
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
Count-Hit
X-GUploader-UploadID
X-NODE
X-Origin-Server
X-ORACLE-DMS-RID
X-LB-Cache
X-PressLabs-Stats
X-Ezoic-Cdn
X-Microsite
X-Request-Handler-Origin-Region
X-Content-Security-Policy-Report-Only
X-Az
X-Activity-Id
X-AppVersion
Host
X-Www-Served-By
X-TEC-API-ORIGIN
X-Ua-Device
X-TEC-API-VERSION
X-TEC-API-ROOT
X-B3-TraceId-Primal
X-Varnish-Server
Mrf-Cache-Status
X-Varnish-Backend
X-Hits
X-App-Server
X-Cluster-Name
MRF-Tech
Cache-Tags
Retry-After
X-Amz-Meta-S3cmd-Attrs
Accept-Charset
Server-Name
X-Newrelic-App-Data
X-ASPNET-VERSION
Cleartype
X-ORACLE-DMS-ECID
X-Origin-Cache-Key
X-CSRF-Token
X-Hostname
X-Goog-Metageneration
X-NGENIX-Cache
X-Geo-Country
X-Envoy-Decorator-Operation
Referer-Policy
X-Upgrade-Enabled
TP-L2-Cache
Access-Control-Allow-Method
X-Id
X-Git-Hash
X-DIS-Request-ID
X-Azure-Ref
X-Unique-Id
X-Seen-By
Filterid
TCN
X-CCDN-Origin-Time
X-Hcs-Proxy-Type
X-CCDN-CacheTTL
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Load-Cache
X-Proxy
X-F-Cache
X-Revision
X-Cache-Control
X-Trace-Id
X-Grace
Section-Io-Cache
Healthy
X-XRDS-LOCATION
X-Request-Guid
DC
X-Amz-Apigw-Id
X-Amzn-RequestId
X-B3-Sampled
X-B
X-TT
X-Contextid
X-Type
Paypal-Debug-Id
X-Px
X-Logged-In
X-FB-Debug
X-Fb-Rlafr
X-Debug-Info
X-Mobile
X-Page-Id
X-Debug
X-N
Viewport
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
X-Varnish-Ttl
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Oracle-Dms-Rid
Fastly-SIE
Fastly-SWR
X-Whom
X-Oracle-Dms-Ecid
X-Time
X-Webkit-CSP
X-Via-JSL
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
X-Datadog-Trace-Id
Charset
Content-Disposition
X-Content-Options
X-Template
Version
X-Cache-Grace
X-RateLimit-Limit
X-Magnolia-Registration
X-Origin-Cache
X-Varnish-Grace
X-Wix-Request-Id
X-App-Environment
X-EdgeConnect-Cache-Status
X-B-Cache
X-Signature
X-Language
VIX-Pulpo-Upstream-Status
X-ProcessESI
X-Node-Name
VIX-Pulpo-Node
X-RemovedCookies
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Debug-IsPreview
X-Yottaa-Metrics
X-Amz-Replication-Status
X-Yottaa-Optimizations
X-Tumblr-Pixel-1
X-Datadog-Sampled
X-Rule
X-Tumblr-User
X-Debug-IsConnected
X-G
Ms-Operation-Id
X-Hl-Ver
X-UUID
SD-X-WS
MS-CV
X-RTag
Countrycode
ServerID
X-Adobe-Content
X-Backend-Name
X-Adobe-Loc
X-FW-Serve
X-FW-Type
X-Cache-Age
X-FW-Server
X-FW-Static
X-Instance
GEO-INFO
X-FW-Version
X-FW-Dynamic
X-Device-Type
X-FW-Hash
X-Storage
X-Amzn-Remapped-Content-Length
SRV
X-Cacheable-TTL
NGB
X-Proxy-Cache-Info
X-User-Agent
X-Status
X-NYM-Debug-Backend
X-Region
X-Is-Bot
X-Cache-Hit
X-Rendered-As
Surrogate-Key
X-L-Path
Country
Liferay-Portal
X-B3-SpanId
X-IPS-LoggedIn
X-Environment-Context
X-NWS-UUID-VERIFY
X-Real-IP
X-Source
X-Rid
X-ServerID
X-RateLimit-Reset
Cross-Origin-Window-Policy
Akamai-GRN
X-Sucuri-ID
X-Sucuri-Cache
X-WP-CF-Super-Cache-Active
OT-Force-Account-Verify
X-Servername
X-UA
From-Origin
X-RM-Cache-TTL
X-VC-Cache
X-WebKit-CSP-Report-Only
Front
X-Framework
Upgrade-Insecure-Requests
Amp-Access-Control-Allow-Source-Origin
X-Air-Pt
Backend
X-INCAP-ABP
X-Wormhole-Sdk
X-Mode
X-AB
X-Xrds-Location
X-Air-Hostname
X-Air-Source
X-URL
X-Air-Trace-Id
Refresh
X-Content-Powered-By
X-Cache-Time
X-Akamai-Request-ID2
Xet-Cookie
X-Handled-By
X-RID
X-DataDome
X-Edge-Location
X-HTML-Minification-Powered-By
Frame-Options
X-VC
X-Endurance-Cache-Level
X-RCS-CacheZone
Meta-Geo
Filters
Accept-Language
X-Xfnlog-Site
X-Timing-Wait
Selected-Fe
X-Origin-CC
X-Webstats-RespID
Url
X-SaId
X-JoinUs
X-Rn-Rsrv
X-Origin-TTL
X-UPSTREAM-Address
X-Rewrite-Enabled
X-Proxy-Build
Atl-Traceid
X-Git-Commit
X-SRV
X-Provided-By
X-LJ-Flow-ID
X-Labrador-Cache-Channel
WPO-Cache-Status
X-PHP-Host
WPO-Cache-Message
X-Cache-Operation
X-Cache-Rule
X-VWS-Id
X-Logging-Id
X-AWS-Id
Cache
X-Tumblr-Pixel-2
X-Cluster
TWC-Locale-Group
TWC-Privacy
TWC-GeoIP-LatLong
TWC-GeoIP-Country
TWC-Device-Class
X-Served-From
X-Origin-Date
Webcakes-App-Name
X-Akamai-Edgescape
X-Origin-Hint
X-Reqid
Webcakes-Region
Webcakes-App-Version
ServedBy
TWC-Connection-Speed
X-No-Session
X-Container-Uri
Property-Id
X-Origin
X-Accel-Version
X-IPLB-Instance
X-Cms-Context
X-Adobe-Source
Cache-Hits
X-Drupal-Cache-Tags
X-Fetched-On
X-Extlb
X-Proxied
X-Hosted-By
Access-Control-Request-Headers
X-IPLB-Request-ID
Mn-Server-Ip
X-Cloudmap
Web-Mar-Node
Section-Io-Id
X-Cache-Debug
X-Azure-Ref-OriginShield
X-Locale
X-Tb
X-Varnish-Cache-Hits
X-Scope-Id
X-R9-Blue-Green-Version
X-Zipkin-Id
X-Web-Node
X-Site-Version
X-VCT
X-Redis-Cache
Webserver
X-Restarts
X-Vcache
X-Routing-Service
X-Ms-Version
X-CMSURLCustom
X-Drupal-Cache-Contexts
X-Ms-Request-Id
X-Forwarded-Host
X-Is-Tablet
X-Format
X-Director
Thinkindot-CacheControl
X-Say-TTL
X-SayCDN-TTL
X-Say-Cacheable
X-S
X-Browser-Name
X-Shield-Cache-Expires
Thinkindot-Control
X-Skip-Cache
TDXMobile
X-Buckets
Thinkindot-CacheControl-Type
X-Soup
X-Tcp-Rtt
X-Loop
X-Is-Desktop
X-Frame-Option
X-Tncms
X-Httpd
X-Upstream-Ht
X-Lambda-Id
X-Varnish-Age
X-Is-Supported-Browser
X-Is-Mobile
X-Nginx-Cache
X-Thinkindot-L3
X-Upstream-Ct
X-Geo-Region
X-Generation-Time
Apigw-Requestid
X-ProxyCache-Key
X-Varnish-Beresp-Grace
X-ShopId
X-CDN-Forward
X-Generated-By
X-ShardId
X-Shopify-Stage
X-GeoCountry
X-ProxyCache-Status
X-Sorting-Hat-ShopId
X-Storefront-Renderer-Rendered
X-Alternate-Cache-Key
X-GeoCode
X-Cache-Host
Xserver
X-Sorting-Hat-PodId
X-BYPASS-REASON
X-Detected-As
X-Cache-Status-Check
X-Cdn-Origin
X-Optimistic-Header
X-Ratelimit-Reset
LB
X-Lagoon
X-Rocket-Nginx-Serving-Static
X-Worker
X-Request-URI
Source
X-Vercel-Id
Fastcgi-Useragent
X-Vercel-Cache
Azure-RegionName
Azure-SlotName
Azure-InstanceId
X-Fastly-Request-Id
Azure-Version
X-WP-CF-Super-Cache-Cookies-Bypass
Azure-SiteName
X-TA-CDN-Provider
Node
AMP-Access-Control-Allow-Source-Origin
Protected
X-Pass-Why
CDN-CachedAt
CDN-PullZone
X-Vcl-Version
X-Connection-Hash
CDN-Cache
CDN-EdgeStorageId
CDN-Uid
CDN-RequestCountryCode
CDN-RequestPullSuccess
Expiry
CDN-RequestPullCode
Cross-Origin-Embedder-Policy
Onion-Location
X-GEO
X-Tec-Api-Origin
X-Api-Version
X-Tec-Api-Root
X-Cache-Expired-At
X-ECache
X-Tec-Api-Version
X-Tumblr-Pixel-3
X-PHP-Backend
CDN-RequestId
X-Aspnetmvc-Version
X-App-Version
X-XRDS-Location
X-Cache-Server
Alternate-Protocol
Sid
Environment
DB-Nickname
X-Server-W
X-Erf-Stays-Pdp-Viaduct-Migration-Web-V2
X-Jobs
Priority
Uber-Trace-Id
X-Tt-Logid
X-Proxy-Cache-Status
X-Cache-Action
X-Fastcgi-Cache
X-ID
CF-IPCountry
X-Cluster-Node
X-Ismobilevalue
X-Urbn-Site-Id
X-Urbn-Context-Path
Locale
X-B3-Traceid
User-Cache-Control
X-LSADC-Cache
X-Mg-Request-UUID
X-Tx-Id
HostName
X-MP-GENERATED-AT
Cdn-Requestid
Fusion-Source
Fusion-Content-Source
Fusion-Content-Id
Fusion-Component-Id
Fusion-Deployment-Id
Cache-Tv-Group
Fusion-Template-Id
X-Nf-Request-Id
X-Zone
X-Generated-On
A
X-Jungle-Id
X-Gen-Mode
X-Hnp-Log
X-Forwarded-Site
X-GeoIP-City
X-Gzip
Wxu-Next-Region
X-Ig-Push-State
X-D
X-BCube-Filmed-By
Req-ID
X-Bc-Bl
Server-Host
Sslversion
Rendered-Blocks
X-Bip
Origin
Origin-Agent-Cluster
X-Block-Status
X-Bl-Debug
Surrogated-Key
T-Server
X-A-Ccd
X-A
Wxu-Next-Commit
Wxu-Next-Hostname
X-A-Dam
Vix-Hermes-Req-Id
X-Aed
X-A-Wwc
X-A-Dgt
X-A-Dcw
X-Cache-Id
X-Cache-NE
DCR-Processing-Time-Ms
X-Ec-Fail
Edge-Cache
X-Dispatcher-Server
DCR-Decision-By
X-Ec-GeoHdr
X-FB-TRIP-ID
X-Esi-Check
X-Epic-Correlation-Id
Content-Secure-Policy
Gannett-Cam-Experience-Id
X-Device-Os
MD5-Digest
Meta-Geo-Continent
X-Clientip
Ngx.Var.Host
X-Conf
Magicmarker
X-Developer
X-Level-Front-Cache
X-Content-Age
Lang
Candidate-Md5Url
X-Ig-Origin-Region
X-DC
X-SRCache-Key
X-Origin-Expires
X-Org
X-Viewer-Country
X-Request-Start
X-Powered-By-VTEX-Cache
X-Vtex-Remote-Cache
X-Thanos
X-TIM-N
X-UA-Device-Type
X-Node-Id
X-Op-Id-All
X-NCache
X-SB
X-VTEX-Cache-Time
X-ScT
X-Vdms-Version
X-Vdms-Path
X-ND-Cache
X-Varnish-Hostname
X-Rojux
X-VTEX-Cache-Server
X-Auth-Group-Type
X-Origin-Response-Time
X-NGINX-Cache
X-SD-PageType
Ssr
X-CUA
X-Loc
Host-ID
X-Debug-Cache-Fetch
Fastly-Backend-Name
Server-Hostname
Fastly-SSL
DSUID
Sever-Int
X-Debug-Cache-Store
X-Auto-Login
X-Tb-Optimization-Total-Bytes-Saved
X-V-Cache
PFcat
Origin-EX
Origin-CC
X-Response-Served-From
X-Cache-Bucket
Powered-By
Release
X-Varnishpool
X-VarnishDD-TTL
X-VG-WebCache
X-Varnish-Director
X-Original-Request-Id
X-Var-Ttl
Content-Style-Type
X-Via-Fastly
X-Test
Server-Ext
X-Cdn-Srv
X-Cache-Info
NM-Fastcgi-Cache
X-Backend-Instance
X-Cache-TTL-Remaining
X-Core-Value
X-App-Name
X-GeoIP-Country-Code
X-GeoIP-Region-Code
X-PAYTM-SRV-ID
X-Origin-Time
X-Platform
X-GeoIP
X-Scheme
X-WA-Info
X-Policy
X-Uri
X-Nyt-Route
X-Service
X-Mvc-Supplant-Cachable
Yak-Timeinfo
Odigeo-Trace-Id
X-Region-Sid
XM
X-HS-Content-Campaign-Id
X-HN
X-NMSegId
X-Nginx-Cache-Key
X-Pubstack
X-Proto
Cdn-Host
Cdn-Request-Time
X-Request-Time
X-Geo-Header
X-FC-Vary-Parameters
Cdncip
Cdnsip
Content-Script-Type
X-Edge-Server
X-Amz-Storage-Class
X-Fastly-Cache
Cache-Provider
CDCHOST
X-RateLimit-Limit-Second
X-Gdpr
X-RateLimit-Remaining-Second
AKAMAI
X-AK-Request-ID
X-Fmm-Version
C-Via
X-VG-TLSProxy
X-Custom-Header
X-Access
X-BBC-Edge-Cache-Status
X-Wikidot-Backend
X-Aicache-OS
X-B3-Trace-ID
X-We-Are-Hiring
X-Wikidot-Static-Cache
X-DPWN-IS-SECURE
X-Pool
X-GoCache-CacheStatus
X-Proxied-Request
X-Req
X-Request-Host
X-From
X-NodeID
X-Human
X-Men
X-Location
X-Micro-Cache
X-Mly-Id
X-Mvc-Supplant-OutputCached
X-Fastly-Backend
X-Eu-Site
X-Varnish-Authentication
X-Contensis-Viewer-Groups
X-CGP
X-Varnish-Beresp-Status
X-Cache-Backend
X-Csrf-Jwt
X-SVT-ORM-VERSION
X-Server-IP
X-Section
X-Sn-Servicetimems
X-Ec-Custom-Error
X-SVT-ORM-RULES
X-Cache-Aspx
X-Ad-Load-Variation
HA-Ipaddr
Is-Eu
Ha-Gx-Prefs
Gh-Request-Id
Esi-Enabled
Fastly-GeoIP-CountryCode
L
L5d-Success-Class
Platform
Pramga
On-Server
Mail-Subject
Machine
Country-Code
Cluster
X-Dc
Adler-Geo
X-Varnish-Beresp-Ttl
X-LiteSpeed-Cache-Control
Web-Mar-Region
X-Newrelic-Synthetics
Apple-News-Services-Handled
Apple-News-Services-Host
Click-Count-Action-Start
Click-Count-Error
Canary
Cache-Key
Apple-News-Services-Request-Url
Producers
Apple-News-Services-Parsed-Url
Tube-Got-Eval
W
Tube-Return
True-Client-Country-4JS
Tube-Got-Results
We-Hiring
V-Age
Tube-Get-Contents
Redirect-Candidate
Req-Svc-Chain
WP-Super-Cache
X-TT-LOGID
X-AIR-PT
X-Acquia-Purge-Cdn-Unconfigured
X-Accel-Expires-Debug
X-Date
Proxy-Firewall
X-ApacheServer
X-Hash
RNT-Time
X-CacheTTL
X-Render-Time
X-Slack-Shared-Secret-Outcome
X-Slack-Backend
X-Up
NGX
RNT-Machine
X-PERF
X-Varnish-CookieINHashed-On
Debug
X-COUNTRY
X-Varnish-Remaining-TTL
X-Varnish-Hits
X-Varnish-CookieHashed-On
X-DefElseHash
X-DefHash
X-Pad
X-Nananana
X-Client-Ip
X-Refresh
X-LB-ID
X-CACHE-GROUP
X-Cs
X-Depends
Mime-Version
CloudFront-Viewer-Country
SID
Fastly-Drupal-HTML
Datacenter
X-VHOST
X-Akamai-Transformed
X-Cache-FS-Status
X-Via-Poph
Locid
X-Via-Popn
X-Via-Popv
Pics-Label
X-Servedbyhost
X-HA-Backend
X-Parent-Response-Time
X-VC-TTL
X-M-Log
X-M-Reqid
GeoIP-Latitude
X-Amz-Meta-Cb-Modifiedtime
X-Datadome
X-Platform-Router
X-Platform-Cluster
X-CACHE-AGE
X-Platform-Processor
X-HITS
X-Cached-By
X-TIME
X-LiteSpeed-Tag
Fastly-Drupal-Html
X-CS
Ngx-Var-Key
X-B3-Parentspanid
X-LB-NoCache
X-Old-Content-Length
Server-Info
X-Litespeed-Tag
X-DynaTrace-JS-Agent
BehaviorPad-Version
X-CDN-Cache-Status
Resin-Trace
Cf-Ipcountry
Server-ID
X-APP
X-TH-Server
GeoIp-Country-Code
X-Moov-T
X-Moov-Xdn-Version
X-Nc
Cross-Origin-Embedder-Policy-Report-Only
X-Vgn-Hpd-Reason
X-Wa
X-VCache
Cdn
X-NewRelic-App-Data
NtCoent-Length
X-IAuth-Set-Uid
X-Content-Length
FSS-Cache
X-Varnish-Beresp-TTL
CDN
Cf-Device-Type
X-External-Request-Id
X-S-Cookie
X-Fpc
X-Esi
X-Destination
X-B-Cookie
X-Application
X-User
True-Client-IP
X-TX-ID
X-HostName
X-ZONE
X-Vc
Serverhost
Srv
Uri
X-Presslabs-Stats
X-Zen-Fury
X-Srv
True-Client-Ip
X-Dispatcher-Number
X-Sigma-Backend
Tcn
X-Instance-Name
X-Cache-Date
X-Rocket-Build-Number
X-Sigma
Vc-Max-Age
X-Oracle-DMS-ECID
X-Dynatrace-Js-Agent
S-Rt
X-RequestId
X-API-Version
GeoIP-Country-Code
X-HOST
X-B3-Spanid
X-VServer
X-Cdn-Forward
X-FPC
Load-Balancing
Request-ID
X-WA
Hostname
X-NC
X-APP-VERSION
X-Dispatch
X-Branch-Name
X-DynaTrace
X-Segment-20210421
Product
X-Cdn-Cache-Status
X-Flags
X-Aspnet-Duration-Ms
X-CACHE-KEY
X-Providence-Cookie
X-Is-Crawler
X-Route-Name
Server-Id
Ohc-File-Size
X-Ckpd-Fst-Backend
Srvid
Geoip-Latitude
X-FL-QIT-DEBUG
ServerName
X-Lb-Nocache
X-DataCenter
X-Webkit-Csp-Report-Only
X-Page-View
Type
X-Bug-Bounty
X-Geo
X-SERVER-NAME
CacheControlHeader
X-ServedByHost
X-Irp-Debug
DataCenter
X-Sql-Duration-Ms
X-Sql-Count
X-Http-Reason
X-VCL-Version
Cloudfront-Viewer-Country
Epwk-X-Cache
Cl-Cache
PICS-Label
Origin-Trial
X-Via-PopN
X-Ha-Backend
X-Via-PopH
X-Via-PopV
X-Cache-Ttl
X-Correlation-ID
X-App
ServerHost
X-Owner
X-Via-Edge
Ohc-Cache-HIT
X-Via-CDN
X-Lb-Id
Edge-Copy-Time
X-Via-SSL
Cross-Origin-Opener-Policy-Report-Only
X-Ua
X-SIPLIST1
IsBot
X-Srcache-Store-Status
X-HubSpot-Correlation-Id
X-Srcache-Fetch-Status
Rtss
X-Nf-Country
X-Vmg-Version
XkeyRZ
X-Nf-Ats-Version
X-Core-Mission
X-Nf-Language
X-Akamai-Device-Characteristics
User-Agent
MIME-Version
Cneonction
X-Proxy-CacheRZ
WZWS-RAY
X-MiniProfiler-Ids
Lb
Sm-Log-Id
X-Sqd-Ctime
X-Sqd-Stime
X-Acquia-Application-Trace
X-Service-Response-Time
X-Acquia-Purge-Tags
X-Acquia-Application-UUID
X-Acquia-Site
X-Datacenter
X-Limited
X-Qloud-Router
X-Fastly-Country-Code
N-Cache
X-Web-Server
X-MSEdge-Features
X-MSEdge-Flight
Cmstype
X-Gamma-Serve
Warning
X-Info
Cmsid
Servername
X-LAGOON
X-Hit
X-Litespeed-Cache-Control
X-IN-APIGATEWAYSSL
X-IN-APIGATEWAY
Xc-Version
X-RAMCache
X-Serial
X-Th-Server
X-Check-Cacheable
X-Akamai-Pragma-Client-IP
X-Requestid
X-Ramcache
X-Snapshot-Date
X-Amz-Meta-Sha256
X-Udemy-Cache-App-Namespace
X-Amz-Meta-S3b-Last-Modified
X-Amz-Meta-Opti
Ngx
X-Dw-Trace-Id