Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
CF-RAY
Expect-CT
Accept-Ranges
X-XSS-Protection
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-Xss-Protection
X-UA-Compatible
X-Served-By
X-Download-Options
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
X-DNS-Prefetch-Control
Content-Security-Policy-Report-Only
Accept-CH
X-Runtime
Accept-CH-Lifetime
X-AspNet-Version
X-Drupal-Cache
X-Check
X-Generator
X-Cache-Status
X-Ua-Compatible
Server-Timing
X-Cacheable
X-Request-ID
Timing-Allow-Origin
X-Envoy-Upstream-Service-Time
X-FRAME-OPTIONS
X-Iinfo
X-Drupal-Dynamic-Cache
X-Content-Security-Policy
Feature-Policy
Access-Control-Expose-Headers
Content-Encoding
X-CDN
Upgrade
Status
X-AspNetMvc-Version
CF-Ray
Access-Control-Max-Age
X-Amz-Request-Id
Cf-Edge-Cache
X-Amz-Id-2
X-Via
Host-Header
EagleId
Permissions-Policy
Keep-Alive
Request-Context
X-Cache-Group
X-Backend
X-Robots-Tag
X-UA-Device
X-AH-Environment
X-Hacker
X-Server
X-Proxy-Cache
X-Turbo-Charged-By
X-Rq
X-Age
X-Ws-Request-Id
Xkey
X-Vhost
Cf-Apo-Via
X-Amz-Version-Id
X-Dispatcher
X-Swift-SaveTime
X-Swift-CacheTime
Grace
X-Server-Powered-By
Allow
X-LiteSpeed-Cache
Ali-Swift-Global-Savetime
X-Varnish-Cache
X-OneAgent-JS-Injection
P3p
X-Page-Speed
X-Pingback
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Cache-Lookup
X-Device
X-WebKit-CSP
EagleEye-TraceId
X-Host
Cf-Railgun
X-Backend-Server
X-Server-Id
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Dns-Prefetch-Control
X-Response-Time
X-Readtime
X-Ruxit-JS-Agent
Surrogate-Control
X-ASPNET-VERSION
X-Akam-SW-Version
X-HW
X-Cloud-Trace-Context
Request-Id
X-Node
Content-Location
X-Country
X-Nginx-Cache-Status
X-Application-Context
X-Nginx-Upstream-Cache-Status
Accept-Ch-Lifetime
X-NWS-LOG-UUID
X-Country-Code
X-Litespeed-Cache
Service-Worker-Allowed
X-Content-Type
X-Trace
X-Url
X-Clacks-Overhead
Cache-Tag
Rating
X-Amz-Server-Side-Encryption
X-Times
X-Rack-Cache
X-TtlSet
X-Vname
X-PC
Cross-Origin-Opener-Policy
X-Edge
X-Mcache
X-Midtier
X-Daa-Tunnel
X-FTR-Request-ID
X-Browser-Type
X-Server-Name
Nginx-Cache
X-Powered-By-Plesk
AR-SID
AR-Request-ID
AR-PoweredBy
AR-ATIME
X-CST
X-Cnection
X-Cache-TTL
Accept-Ch
X-ESI
X-Ac
X-GitHub-Request-Id
X-Element-Page-Cache
X-D2id
Edge-Control
X-Kinja-Revision
X-Kinja-Server
X-GoogleNews-Bot
X-Kinja-Build
X-Kinja
X-Exp-Id
X-Exp-Variant
Verso
X-Cdn-Fetch
X-MS-InvokeApp
X-Ser
AR-CACHE
X-Vcap-Request-Id
X-Abt-Application-Version
X-Upstream
X-FastCGI-Cache
X-B3-TraceId
X-Navigation-Version
X-Dw-Request-Base-Id
X-ECACHE
Fastly-Restarts
SPIisLatency
SPRequestDuration
X-Webkit-Csp
X-Mod-Pagespeed
X-Amz-Rid
X-Instrumentation
X-Kraken-Loop-Name
X-Erf-Bev-Bev-Is-Generated
X-Server-Lifecycle-Phase
X-Erf-Bev-Bev
X-SharePointHealthScore
SPRequestGuid
X-Client-IP
X-PDP-UNCACHING-HASH
X-Kinsta-Cache
X-Edge-Location-Klb
X-Goog-Hash
X-ARC
X-Ratelimit-Limit
Display
X-Middleton-Display
Pagespeed
X-Mg-S
X-Sol
X-Powered-CMS
S
Edge-Cache-Tag
X-Oneagent-Js-Injection
X-Amzn-Trace-Id
Cache-Status
X-Version
Access-Control-Request-Method
X-NF-Request-ID
Response
X-Middleton-Response
X-VARITI-CCR
RTSS
X-Forwarded-For
X-Varnish-TTL
Realpath
X-T
X-Content-Digest
Cross-Origin-Resource-Policy
X-TraceId
X-Recruiting
X-Cache-Key
X-Correlation-Id
X-Fastly-Request-ID
X-ORACLE-DMS-RID
Fastcgi-Cache
X-Ratelimit-Remaining
X-Cached
X-TTL
X-RateLimit-Remaining
X-MSEdge-Ref
X-Shield-Request-Id
Front-End-Https
MicrosoftSharePointTeamServices
X-Ua-Browser
X-Request-Processing-Time
X-Forwarded-Proto
X-Request-Received
X-LLID
MS-Author-Via
Payment
X-HS-Hub-Id
X-HS-Cache-Config
X-Frontend
X-PressLabs-Stats
X-Protected-By
X-HS-Content-Id
TP-Cache
Arr-Disable-Session-Affinity
Server-Node
Public-Key-Pins
Content-MD5
X-SRCache-Store-Status
X-SRCache-Fetch-Status
Count-Hit
X-TEC-API-VERSION
X-Ruxit-Js-Agent
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-HS-Combine-CSS
X-Accel-Expires
X-GUploader-UploadID
X-Distributor
X-LB-Cache
X-Country-Code-Real
X-FTR-Backend
X-FTR-Cache-Status
X-FTR-Balancer
X-FTR-Backend-Server
X-Kong-Proxy-Latency
X-Origin-Server
X-Kong-Upstream-Latency
X-Server-ID
X-Newrelic-App-Data
X-NODE
X-Ezoic-Cdn
X-FTR-Expires
X-HP-Webp
X-HP-Trace-Id
X-Jurisdiction
X-Microsite
X-Request-Handler-Origin-Region
X-Ttl
X-Www-Served-By
X-App-Server
X-AppVersion
Host
X-Az
X-Activity-Id
Accept-Charset
X-Content-Security-Policy-Report-Only
X-Varnish-Server
X-ORACLE-DMS-ECID
MRF-Tech
Cache-Tags
Mrf-Cache-Status
X-Cluster-Name
X-B3-TraceId-Primal
Retry-After
Cleartype
X-Amz-Meta-S3cmd-Attrs
X-Varnish-Backend
X-Ua-Device
X-Goog-Metageneration
Filterid
Surrogate-Key
X-Hits
X-Unique-Id
Server-Name
X-Git-Hash
Access-Control-Allow-Method
X-Debug
X-Id
X-Envoy-Decorator-Operation
X-NGENIX-Cache
X-Azure-Ref
X-Geo-Country
X-Upgrade-Enabled
X-Load-Cache
X-Logged-In
X-CSRF-Token
X-Hostname
X-FB-Debug
TCN
X-Amzn-RequestId
TP-L2-Cache
X-Amz-Apigw-Id
X-Tt-Trace-Tag
X-Proxy
X-Time
X-Tt-Trace-Host
X-XRDS-LOCATION
X-Grace
X-Seen-By
X-TT
X-B
Section-Io-Cache
X-Cache-Control
X-Request-Guid
DC
X-Revision
X-Trace-Id
X-Type
X-Contextid
Viewport
X-F-Cache
X-CCDN-Origin-Time
Healthy
X-B3-Sampled
X-CCDN-CacheTTL
X-Hcs-Proxy-Type
X-Fb-Rlafr
Pinterest-Version
Pinterest-Generated-By
X-Pinterest-Rid
Referer-Policy
X-Mobile
X-Goog-Generation
X-N
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
Fastly-SIE
Fastly-SWR
Paypal-Debug-Id
X-DIS-Request-ID
Content-Disposition
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
X-Varnish-Grace
X-Debug-Info
X-Page-Id
X-Magnolia-Registration
X-Px
X-Via-JSL
X-Origin-Cache
X-Webkit-CSP
Version
X-Amz-Replication-Status
X-Ratelimit-Reset
X-Whom
X-Aws-Lambda-Call-Status
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
X-Datadog-Trace-Id
X-Content-Options
X-G
X-ProcessESI
X-UUID
X-RemovedCookies
X-Adobe-Content
X-Template
X-Adobe-Loc
X-Oracle-Dms-Ecid
X-Rule
X-Tumblr-Pixel-0
X-Debug-IsConnected
X-Debug-IsPreview
X-Node-Name
X-Tumblr-User
X-Tumblr-Pixel-1
X-Tumblr-Pixel
X-App-Environment
X-Datadog-Sampled
VIX-Pulpo-Upstream-Status
Ms-Operation-Id
MS-CV
NGB
X-Wormhole-Sdk
VIX-Pulpo-Node
SD-X-WS
X-Wix-Request-Id
X-Hl-Ver
X-Source
X-Storage
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-RTag
Charset
X-Backend-Name
X-Varnish-Ttl
X-Cacheable-TTL
X-B-Cache
X-Rendered-As
X-Instance
X-User-Agent
X-Signature
X-Is-Bot
X-Region
X-Proxy-Cache-Info
X-NYM-Debug-Backend
X-Device-Type
X-L-Path
X-FW-Serve
X-FW-Server
Cross-Origin-Window-Policy
X-Status
GEO-INFO
X-ServerID
X-Environment-Context
X-FW-Static
X-FW-Dynamic
X-FW-Type
X-FW-Hash
X-FW-Version
Country
Amp-Access-Control-Allow-Source-Origin
X-Cache-Age
X-Nf-Request-Id
Countrycode
X-IPS-LoggedIn
ServerID
X-Cache-Grace
X-Real-IP
X-EdgeConnect-Cache-Status
X-NWS-UUID-VERIFY
X-RM-Cache-TTL
Akamai-GRN
Front
X-Cache-Hit
X-Rid
X-Amzn-Remapped-Content-Length
Liferay-Portal
X-WP-CF-Super-Cache-Active
X-Framework
X-Language
X-Ismobilevalue
SRV
X-AB
X-Air-Pt
X-ECache
X-WebKit-CSP-Report-Only
X-Sucuri-ID
X-B3-SpanId
OT-Force-Account-Verify
X-Sucuri-Cache
X-Content-Powered-By
X-Oracle-Dms-Rid
X-Akamai-Request-ID2
X-Servername
X-UA
From-Origin
X-Air-Source
X-VC
X-Air-Hostname
X-Air-Trace-Id
X-Fastly-Request-Id
X-VC-Cache
Backend
X-RID
Xet-Cookie
X-Mode
X-DataDome
X-SRV
Upgrade-Insecure-Requests
Refresh
X-Api-Version
Accept-Language
X-URL
X-Handled-By
X-Cache-Time
X-Xrds-Location
Webserver
X-Cache-Status-Check
Access-Control-Request-Headers
X-HTML-Minification-Powered-By
LB
X-Tt-Logid
Cache
X-UPSTREAM-Address
X-JoinUs
X-Rewrite-Enabled
Filters
X-Rn-Rsrv
X-SaId
X-RCS-CacheZone
Meta-Geo
TWC-GeoIP-Country
Webcakes-Region
X-Hosted-By
X-S
TWC-Privacy
X-Adobe-Source
TWC-Locale-Group
TWC-Connection-Speed
X-Git-Commit
Property-Id
X-Origin-Date
Webcakes-App-Name
X-Webstats-RespID
X-Cache-Rule
X-Cms-Context
X-Generated-By
X-Labrador-Cache-Channel
X-Container-Uri
X-Origin-Hint
TWC-GeoIP-LatLong
X-Xfnlog-Site
X-Cache-Operation
X-R9-Blue-Green-Version
ServedBy
TWC-Device-Class
Webcakes-App-Version
X-Tumblr-Pixel-2
X-Varnish-Age
X-PHP-Host
X-Provided-By
X-Locale
Section-Io-Id
X-Lambda-Id
X-Is-Tablet
X-ProxyCache-Key
X-Is-Desktop
X-Httpd
X-Logging-Id
X-Loop
Atl-Traceid
X-Is-Mobile
X-No-Session
X-Ms-Version
X-ProxyCache-Status
X-Ms-Request-Id
X-Is-Supported-Browser
X-Akamai-Edgescape
X-Site-Version
X-Skip-Cache
X-BYPASS-REASON
X-Browser-Name
X-Served-From
X-Geo-Region
Url
X-Tb
X-Forwarded-Host
X-Fetched-On
X-Tncms
X-Cluster
X-Tcp-Rtt
X-Web-Node
X-Cache-Debug
X-Endurance-Cache-Level
X-Reqid
X-Scope-Id
Web-Mar-Node
X-Redis-Cache
X-Accel-Version
X-Upstream-Ct
X-Detected-As
X-VCT
X-Varnish-Beresp-Grace
X-Timing-Wait
X-Upstream-Ht
Selected-Fe
X-Format
X-IPLB-Request-ID
X-IPLB-Instance
Apigw-Requestid
X-Director
X-Request-URI
X-Frame-Option
X-Shopify-Stage
X-Say-TTL
X-Say-Cacheable
X-Edge-Location
X-SayCDN-TTL
X-Proxy-Build
X-Alternate-Cache-Key
X-Optimistic-Header
X-Varnish-Cache-Hits
X-INCAP-ABP
X-Restarts
Mn-Server-Ip
X-Storefront-Renderer-Rendered
X-Origin
X-Cache-Host
X-Soup
X-VWS-Id
X-Mg-Request-UUID
X-AWS-Id
X-Proxied
X-Routing-Service
X-Cloudmap
X-Extlb
Xserver
X-RateLimit-Limit
X-LJ-Flow-ID
X-Zipkin-Id
Frame-Options
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-ShopId
X-ShardId
X-GeoCode
X-Azure-Ref-OriginShield
X-GeoCountry
Onion-Location
X-Nginx-Cache
X-Vcl-Version
Expiry
X-Lagoon
X-Connection-Hash
Source
WPO-Cache-Status
X-Vcache
WPO-Cache-Message
X-Shield-Cache-Expires
X-CMSURLCustom
X-Thinkindot-L3
Protected
X-Generation-Time
X-Cache-Expired-At
Thinkindot-Control
X-WP-CF-Super-Cache-Cookies-Bypass
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
TDXMobile
X-Drupal-Cache-Tags
X-Drupal-Cache-Contexts
Fastcgi-Useragent
X-Cdn-Origin
X-CDN-Forward
X-Origin-CC
X-Origin-TTL
Environment
X-Cache-Action
Priority
X-Proxy-Cache-Status
X-PHP-Backend
X-Pass-Why
X-Vercel-Id
X-Worker
X-Vercel-Cache
Cdn-Requestid
Sid
X-Rocket-Nginx-Serving-Static
Uber-Trace-Id
Cache-Hits
X-GEO
Azure-SlotName
Azure-SiteName
Azure-Version
Azure-RegionName
Azure-InstanceId
X-TA-CDN-Provider
Node
Locale
X-Buckets
X-Urbn-Context-Path
X-ID
X-Cluster-Node
X-Urbn-Site-Id
CF-IPCountry
X-App-Version
Cross-Origin-Embedder-Policy
X-Aspnetmvc-Version
CDN-Cache
CDN-CachedAt
CDN-RequestPullSuccess
CDN-Uid
CDN-RequestPullCode
CDN-RequestCountryCode
CDN-EdgeStorageId
CDN-PullZone
X-FB-TRIP-ID
Cache-Tv-Group
X-XRDS-Location
X-Tumblr-Pixel-3
X-Auth-Group-Type
X-RateLimit-Reset
X-Fastcgi-Cache
X-Cache-Server
X-B3-Traceid
DB-Nickname
AMP-Access-Control-Allow-Source-Origin
X-NGINX-Cache
Alternate-Protocol
X-Dc
X-Server-W
X-Pad
X-Tx-Id
X-A
X-ND-Cache
X-Fastly-Backend
X-Origin-Cache-Key
X-Aed
Candidate-Md5Url
X-Epic-Correlation-Id
Gannett-Cam-Experience-Id
X-Origin-Expires
X-Op-Id-All
X-Org
X-Esi-Check
Rendered-Blocks
X-Cache-Id
Cdn-Request-Time
X-Gzip
X-Service
X-GeoIP-City
X-Generated-On
X-Cache-TTL-Remaining
X-Cache-NE
Cdn-Host
Content-Secure-Policy
X-BCube-Filmed-By
DCR-Decision-By
DCR-Processing-Time-Ms
X-Conf
X-Level-Front-Cache
X-Ig-Origin-Region
X-Ig-Push-State
X-Bl-Debug
X-Bc-Bl
X-Req
X-Varnish-Remaining-TTL
T-Server
X-Vdms-Version
Origin-Agent-Cluster
X-Dispatcher-Server
A
X-Content-Age
X-V-Cache
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
Surrogated-Key
X-Via-Fastly
X-DefElseHash
User-Cache-Control
X-Core-Value
X-Custom-Header
HostName
X-DefHash
X-Viewer-Country
X-Developer
Sslversion
X-Vtex-Remote-Cache
X-TIM-N
Odigeo-Trace-Id
X-Edge-Server
Wxu-Next-Region
X-Rojux
Magicmarker
Lang
X-A-Ccd
X-A-Dgt
X-A-Dcw
X-A-Dam
X-D
Wxu-Next-Hostname
X-SRCache-Key
X-Ec-GeoHdr
Ngx.Var.Host
X-Ec-Fail
X-A-Wwc
Wxu-Next-Commit
X-ScT
Meta-Geo-Continent
MD5-Digest
X-Client-Ip
Mime-Version
X-Clientip
X-Cdn-Srv
X-Ad-Load-Variation
Tube-Got-Eval
Tube-Got-Results
Tube-Return
V-Age
Tube-Get-Contents
Ssr
Req-ID
RNT-Machine
RNT-Time
Server-Host
Vix-Hermes-Req-Id
X-Acquia-Purge-Cdn-Unconfigured
X-Backend-Instance
X-Bip
X-Block-Status
X-Cache-Bucket
X-B3-Trace-ID
X-App-Name
X-Aicache-OS
X-AK-Request-ID
X-Amz-Storage-Class
X-Cache-Info
X-Hnp-Log
X-SD-PageType
X-Scheme
X-Server-IP
X-Sn-Servicetimems
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-SB
X-Request-Time
X-Proto
X-Powered-By-VTEX-Cache
X-Pubstack
X-RateLimit-Limit-Second
X-Region-Sid
X-RateLimit-Remaining-Second
X-Tb-Optimization-Total-Bytes-Saved
X-Test
X-VTEX-Cache-Time
X-VTEX-Cache-Server
X-WA-Info
X-Wikidot-Backend
XM
X-Wikidot-Static-Cache
X-VG-WebCache
X-VG-TLSProxy
X-UA-Device-Type
X-Thanos
X-Varnish-Director
X-Varnish-Hostname
X-VarnishDD-TTL
X-Policy
X-Platform
X-GeoIP
X-Geo-Header
X-GeoIP-Country-Code
X-GeoIP-Region-Code
X-HN
X-GoCache-CacheStatus
X-Gen-Mode
X-Gdpr
X-DPWN-IS-SECURE
X-Debug-Cache-Store
X-Fastly-Cache
X-FC-Vary-Parameters
X-Forwarded-Site
X-Fmm-Version
X-HS-Content-Campaign-Id
X-Jobs
X-NodeID
X-Node-Id
X-Nyt-Route
X-Origin-Response-Time
X-PAYTM-SRV-ID
X-Origin-Time
X-NMSegId
X-Mvc-Supplant-Cachable
X-LSADC-Cache
X-Loc
X-Men
X-Micro-Cache
X-Mly-Id
X-Debug-Cache-Fetch
X-CacheTTL
Fastly-SSL
Click-Count-Action-Start
AKAMAI
Adler-Geo
Click-Count-Error
NM-Fastcgi-Cache
Cdnsip
Cache-Provider
Is-Eu
Host-ID
Cdncip
PFcat
Origin
Content-Script-Type
Platform
Esi-Enabled
Content-Style-Type
Producers
X-LiteSpeed-Cache-Control
Country-Code
Powered-By
Edge-Cache
Fastly-Backend-Name
CDCHOST
X-CGP
Proxy-Firewall
X-Request-Host
Cluster
X-Contensis-Viewer-Groups
X-Cache-Aspx
X-Proxied-Request
X-Request-Start
X-Pool
Cache-Key
Fusion-Template-Id
X-Eu-Site
X-Location
X-Mvc-Supplant-OutputCached
Fusion-Source
Fusion-Deployment-Id
X-Human
Fusion-Component-Id
Fusion-Content-Id
Fusion-Content-Source
X-Ec-Custom-Error
X-Nginx-Cache-Key
C-Via
X-Section
X-CUA
X-Csrf-Jwt
X-Date
Apple-News-Services-Request-Url
X-Depends
Apple-News-Services-Handled
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
Canary
DSUID
X-Hash
X-We-Are-Hiring
Yak-Timeinfo
X-Cache-FS-Status
W
We-Hiring
Mail-Subject
NGX
Web-Mar-Region
On-Server
True-Client-Country-4JS
Req-Svc-Chain
Pramga
Release
Server-Ext
Server-Hostname
Origin-CC
Origin-EX
Sever-Int
Machine
X-Varnishpool
Fastly-GeoIP-CountryCode
L5d-Success-Class
X-BBC-Edge-Cache-Status
X-Var-Ttl
X-Slack-Backend
X-Auto-Login
X-Slack-Shared-Secret-Outcome
X-Varnish-Beresp-Status
X-Varnish-Authentication
X-Accel-Expires-Debug
X-Access
HA-Ipaddr
Ha-Gx-Prefs
L
Gh-Request-Id
X-HITS
X-DC
X-Device-Os
CDN-RequestId
X-AIR-PT
X-Varnish-Hits
X-Varnish-Beresp-Ttl
Server-Info
X-Cs
X-Akamai-Transformed
Redirect-Candidate
X-From
X-LB-ID
X-NCache
BehaviorPad-Version
Debug
X-Up
X-APP
X-Jungle-Id
X-Zone
X-MP-GENERATED-AT
X-CACHE-KEY
X-Refresh
X-Tec-Api-Version
X-Tec-Api-Root
X-Tec-Api-Origin
X-Vdms-Path
X-Cache-Backend
CloudFront-Viewer-Country
WP-Super-Cache
X-Parent-Response-Time
X-B3-Parentspanid
Fastly-Drupal-Html
X-Via-Popv
Pics-Label
X-Via-Popn
X-Via-Poph
X-HA-Backend
GeoIP-Latitude
X-Servedbyhost
X-VHOST
SID
X-CACHE-AGE
Fastly-Drupal-HTML
X-Content-Length
X-Datadome
X-Uri
X-CDN-Cache-Status
X-LiteSpeed-Tag
X-Nananana
X-Nc
X-Newrelic-Synthetics
X-Render-Time
X-ApacheServer
X-VC-TTL
X-PERF
X-M-Log
X-M-Reqid
X-DynaTrace-JS-Agent
X-LB-NoCache
X-CS
X-B3-Spanid
X-ZONE
Datacenter
Vc-Max-Age
X-Litespeed-Tag
NtCoent-Length
X-RequestId
Resin-Trace
X-Dispatcher-Number
X-Cached-By
GeoIp-Country-Code
X-Varnish-Beresp-TTL
Product
Server-ID
X-Wa
X-Amz-Meta-Cb-Modifiedtime
Locid
Srv
X-Original-Request-Id
Cdn
X-VCache
X-Response-Served-From
X-IAuth-Set-Uid
FSS-Cache
X-Ckpd-Fst-Backend
True-Client-IP
X-NewRelic-App-Data
X-TT-LOGID
CDN
X-Fpc
X-Bug-Bounty
X-Esi
X-Old-Content-Length
X-TX-ID
Cf-Ipcountry
X-HostName
X-SERVER-NAME
X-Nf-Language
X-FPC
X-Cdn-Forward
True-Client-Ip
X-Nf-Ats-Version
Serverhost
Uri
Ngx-Var-Key
X-Nf-Country
ServerName
S-Rt
X-HubSpot-Correlation-Id
X-Vgn-Hpd-Reason
X-WA
Tcn
X-APP-VERSION
X-Oracle-DMS-ECID
X-Srv
X-TIME
X-Moov-Xdn-Version
Server-Id
X-TH-Server
X-Dynatrace-Js-Agent
X-Platform-Router
X-Platform-Processor
X-Platform-Cluster
GeoIP-Country-Code
X-Moov-T
Request-ID
CacheControlHeader
User-Agent
X-Dispatch
X-Akamai-Device-Characteristics
X-Vmg-Version
X-Vc
ServerHost
X-Cdn-Cache-Status
X-Info
X-Lb-Nocache
X-Gamma-Serve
X-NC
Cf-Device-Type
Hostname
X-COUNTRY
Geoip-Latitude
X-Application
Xc-Version
X-Webkit-Csp-Report-Only
Cross-Origin-Embedder-Policy-Report-Only
Srvid
X-External-Request-Id
X-B-Cookie
X-User
X-Destination
X-FL-QIT-DEBUG
X-S-Cookie
X-Hit
X-Presslabs-Stats
X-Via-PopV
X-Geo
X-Via-PopN
Expect-Staple
X-Via-PopH
X-Zen-Fury
X-Ha-Backend
PICS-Label
X-Sigma-Backend
X-Sigma
Origin-Trial
X-Amz-Meta-Opti
X-Instance-Name
Cneonction
Cloudfront-Viewer-Country
X-Cache-Date
Ohc-File-Size
X-Rocket-Build-Number
X-ServedByHost
X-VCL-Version
X-VServer
X-Segment-20210421
X-API-Version
Epwk-X-Cache
X-V
X-Platform-Server
X-Rollout
X-Branch-Name
X-App
X-Ua
X-New
X-Limited
Permission-Policy
X-Eligible
WZWS-RAY
X-Correlation-ID
X-Akamai-Pragma-Client-IP
N-Cache
Rtss
X-Srcache-Fetch-Status
X-Srcache-Store-Status
XkeyRZ
X-Sqd-Stime
X-Check-Cacheable
X-MiniProfiler-Ids
X-Proxy-CacheRZ
X-Serial
X-Erf-Stays-Pdp-Viaduct-Migration-Web-V2
X-Sqd-Ctime
X-Lb-Id
X-Wp-Cf-Super-Cache-Cache-Control
X-Wp-Cf-Super-Cache
Lb
X-Fastly-Backend-Reqs
X-Datacenter
X-Internal-TTL
Cmsid
X-MSEdge-Flight
X-MSEdge-Features
Cmstype
X-Acquia-Site
X-Ftr-Request-Id
Ohc-Cache-HIT
Timeexpire
Sm-Log-Id
X-Web-Server
X-DataCenter
X-Service-Response-Time
X-Acquia-Purge-Tags
X-Acquia-Application-UUID
Fl-Custom-Application
X-Acquia-Application-Trace
X-ElasticPress-Query
X-LAGOON
X-Litespeed-Cache-Control
Servername
Load-Balancing
CountryCode
X-CSRF-TOKEN
DataCenter
X-VTEX-Cache-Backend-Connect-Time
Wpo-Cache-Message
Wpo-Cache-Status
X-VTEX-Cache-Backend-Header-Time
X-Dw-Trace-Id
Type
Warning
X-Amz-Meta-S3b-Last-Modified
Ngx
X-Snapshot-Date
X-Th-Server
X-Requestid
X-Ramcache
X-Amz-Meta-Sha256
X-Udemy-Cache-App-Namespace
X-Shardid
X-Shopid
X-Sorting-Hat-Podid
X-Origin-Upstream-Status
X-DynaTrace
X-RAMCache
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
X-Sorting-Hat-Shopid