Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
Pragma
X-Powered-By
X-XSS-Protection
CF-RAY
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
Alt-Svc
P3P
X-Cache-Hits
X-UA-Compatible
X-Xss-Protection
X-Served-By
CF-Ray
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Request-Id
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
Access-Control-Allow-Credentials
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
X-Drupal-Cache
X-Generator
X-Cache-Status
X-Check
X-Cacheable
X-Envoy-Upstream-Service-Time
X-Request-ID
X-Dns-Prefetch-Control
Timing-Allow-Origin
X-FRAME-OPTIONS
X-DNS-Prefetch-Control
X-Iinfo
X-Drupal-Dynamic-Cache
Feature-Policy
X-Content-Security-Policy
Content-Encoding
Access-Control-Expose-Headers
Upgrade
Status
X-CDN
X-AspNetMvc-Version
Server-Timing
X-XSS-PROTECTION
Access-Control-Max-Age
X-Amz-Request-Id
Request-Context
X-Amz-Id-2
X-Turbo-Charged-By
X-Via
X-AH-Environment
X-Robots-Tag
X-Backend
X-Cache-Group
Cf-Edge-Cache
Host-Header
Keep-Alive
X-UA-Device
X-Proxy-Cache
X-Hacker
X-Server
X-Rq
X-Server-Powered-By
X-Age
Allow
X-Vhost
X-Varnish-Cache
X-Ws-Request-Id
X-Dispatcher
X-Amz-Version-Id
EagleId
Grace
X-LiteSpeed-Cache
P3p
Cf-Apo-Via
Nel
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Page-Speed
X-Device
Cf-Railgun
EagleEye-TraceId
X-Aws-Lambda-Call-Status
X-Swift-SaveTime
X-Swift-CacheTime
X-WebKit-CSP
Ali-Swift-Global-Savetime
Accept-CH
X-Pingback
X-Host
X-Node
X-Server-Id
X-OneAgent-JS-Injection
X-Backend-Server
Surrogate-Control
X-CST
X-Nginx-Cache-Status
X-Readtime
X-Cache-Lookup
X-Akam-SW-Version
Permissions-Policy
X-Content-Security-Policy-Report-Only
Request-Id
X-Application-Context
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Nginx-Upstream-Cache-Status
X-Cloud-Trace-Context
X-Trace
Accept-Ch-Lifetime
X-Response-Time
X-Edge
X-HW
X-Ua-Compatible
Content-Location
X-Clacks-Overhead
X-Mod-Pagespeed
Accept-CH-Lifetime
X-Oneagent-Js-Injection
X-Url
X-Midtier
X-ECACHE
Rating
X-ESI
X-Ruxit-JS-Agent
X-Amz-Server-Side-Encryption
X-Mcache
Xkey
X-Country
X-Litespeed-Cache
X-Upstream
X-Vcap-Request-Id
X-Vname
X-TtlSet
X-PC
Cache-Tag
X-Ruxit-Js-Agent
X-D2id
X-MS-InvokeApp
X-Rack-Cache
X-Kinja
X-Exp-Id
X-Kinja-Build
X-Kinja-Revision
X-Kinja-Server
X-Use-Magma
Verso
X-Element-Page-Cache
X-Exp-Variant
X-GoogleNews-Bot
X-Cdn-Fetch
Edge-Control
RTSS
Fastly-Restarts
X-Powered-By-Plesk
X-Cache-TTL
X-VARITI-CCR
Origin-Trial
X-Ac
X-Navigation-Version
Accept-Ch
X-Abt-Application-Version
X-Cached
X-Ttl
X-Goog-Hash
X-Content-Type
Service-Worker-Allowed
X-Country-Code
X-GitHub-Request-Id
Display
X-Sol
Pagespeed
X-Middleton-Display
X-Amz-Rid
X-WebKit-CSP-Report-Only
X-Browser-Type
X-Varnish-TTL
X-Mg-S
X-Dw-Request-Base-Id
X-SharePointHealthScore
SPRequestGuid
X-Server-Name
Cross-Origin-Opener-Policy
Arr-Disable-Session-Affinity
X-Erf-Bev-Bev
X-Server-Lifecycle-Phase
X-Erf-Bev-Bev-Is-Generated
X-Kraken-Loop-Name
X-Instrumentation
X-Powered-CMS
X-Middleton-Response
X-Amzn-Trace-Id
Response
AR-ATIME
AR-Request-ID
AR-PoweredBy
AR-SID
SPIisLatency
SPRequestDuration
X-Cache-Key
X-B3-TraceId
AR-CACHE
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Fastly-Request-ID
X-Version
X-HP-Webp
X-Jurisdiction
X-HP-Trace-Id
X-Times
X-Accel-Expires
X-Cnection
X-T
Cache-Tags
Cache-Status
X-Fastcgi-Cache
Front-End-Https
Pinterest-Version
X-Pinterest-Rid
Pinterest-Generated-By
X-Client-IP
X-B3-Traceid
Edge-Cache-Tag
X-MSEdge-Ref
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
X-Px
X-NF-Request-ID
X-Hits
X-Ser
Nginx-Cache
X-NWS-LOG-UUID
Public-Key-Pins
X-Kinja-CCPA
X-Recruiting
X-B3-TraceId-Primal
Mrf-Cache-Status
MRF-Tech
X-LLID
X-Request-Received
X-Request-Processing-Time
X-Frontend
Server-Node
Payment
X-Ua-Browser
X-Shield-Request-Id
X-Webkit-CSP
X-DIS-Request-ID
X-Erf-Stays-Pdp-Viaduct-Migration-Web
Access-Control-Request-Method
TP-Cache
X-Webkit-CSP-Report-Only
X-RateLimit-Remaining
X-Ratelimit-Remaining
X-Goog-Metageneration
S
X-HS-Combine-CSS
X-HS-Content-Id
X-HS-Hub-Id
X-HS-Cache-Config
MicrosoftSharePointTeamServices
TP-L2-Cache
X-LB-Cache
X-FastCGI-Cache
X-Content-Digest
X-PressLabs-Stats
X-Distributor
Content-MD5
Realpath
X-Request-Handler-Origin-Region
X-Microsite
X-Ezoic-Cdn
X-Geo-Country
X-RateLimit-Limit
X-Page-Id
X-Hostname
X-FB-Debug
Access-Control-Allow-Method
X-Forwarded-For
Fastcgi-Cache
X-GUploader-UploadID
Accept-Charset
X-Protected-By
X-Cluster-Name
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Correlation-Id
X-Rid
X-Ratelimit-Limit
X-TEC-API-VERSION
X-Seen-By
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Envoy-Decorator-Operation
X-B3-Sampled
Cleartype
TCN
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
DC
X-Goog-Generation
X-Goog-Stored-Content-Encoding
Referer-Policy
X-Newrelic-App-Data
X-Origin-Cache
X-Mobile
X-XRDS-Location
X-Origin-Server
X-Debug-Info
X-Webkit-Csp
Cross-Origin-Resource-Policy
X-Varnish-Backend
X-Aspnet-Version
X-Ua-Device
X-Logged-In
X-Git-Hash
X-Azure-Ref
X-Contextid
X-Server-ID
X-Content-Options
X-Varnish-Grace
X-Aspnet-Duration-Ms
X-Flags
X-Fb-Rlafr
X-App-Environment
X-Amz-Replication-Status
X-Is-Crawler
X-Grace
Surrogate-Key
X-Route-Name
X-Request-Guid
X-Revision
X-Providence-Cookie
Count-Hit
X-Edge-Location-Klb
X-Kinsta-Cache
X-IPS-LoggedIn
Alternate-Protocol
X-TT
X-Amz-Meta-S3cmd-Attrs
Healthy
X-Wix-Request-Id
X-Forwarded-Proto
X-App-Server
X-Hosted-By
Frame-Options
X-Whom
WPO-Cache-Message
Charset
WPO-Cache-Status
X-TTL
MS-Author-Via
X-Akamai-Edgescape
Viewport
X-Daa-Tunnel
Filterid
Retry-After
X-Oracle-Dms-Ecid
X-Magnolia-Registration
Paypal-Debug-Id
X-Client-Ip
X-Backend-Name
X-Oracle-Dms-Rid
X-B
X-F-Cache
SRV
Section-Io-Cache
X-Id
Amp-Access-Control-Allow-Source-Origin
X-Cache-Age
X-AppVersion
X-Activity-Id
X-Az
X-Proxy-Cache-Info
X-Cache-Control
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Trace-Id
Server-Name
X-Www-Served-By
X-App-Version
X-Type
X-Time
VIX-Pulpo-Node
SD-X-WS
X-Cache-Rule
X-Varnish-Server
Host
VIX-Pulpo-Upstream-Status
X-ARC
X-Rule
X-Response-Served-From
X-Original-Request-Id
X-Instance
X-Http-Reason
Akamai-GRN
X-EdgeConnect-Cache-Status
X-Rocket-Nginx-Serving-Static
X-RateLimit-Reset
X-Status
X-Proxy
X-Edge-Location
Refresh
X-Cache-Grace
X-Akamai-Request-ID2
Front
Protected
X-Varnish-Age
X-User-Agent
X-UUID
X-FW-Type
Fastly-SIE
X-Page-View
X-L-Path
Fastly-SWR
X-FW-Version
X-Is-Bot
X-Jobs
X-N
X-Region
X-Environment-Context
X-FW-Dynamic
X-FW-Server
X-FW-Serve
X-COUNTRY
X-Cacheable-TTL
X-Framework
X-Unique-Id
X-FW-Static
From-Origin
X-Rendered-As
X-FW-Hash
X-Adobe-Content
X-Adobe-Loc
Access-Control-Request-Headers
X-Cache-Time
X-Tumblr-User
Version
X-Load-Cache
X-Tumblr-Pixel-1
X-Tumblr-Pixel
X-ProcessESI
X-RemovedCookies
X-G
X-Tumblr-Pixel-0
ServerID
X-Nf-Request-Id
X-Language
Country
X-Datadog-Sampling-Priority
X-Datadog-Trace-Id
X-Source
X-Datadog-Parent-Id
X-Vcache
X-CDN-Forward
Content-Disposition
X-Drupal-Cache-Tags
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Upgrade-Enabled
X-DataDome
X-Mg-Request-UUID
X-Datadog-Sampled
X-HTML-Minification-Powered-By
Accept-Language
X-Amzn-Remapped-Content-Length
X-Debug-IsPreview
X-Debug-IsConnected
Countrycode
X-DynaTrace
X-Xrds-Location
X-ID
X-Generated-By
Xet-Cookie
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-B-Cache
Backend
X-Signature
X-ECache
X-Varnish-Ttl
X-DynaTrace-JS-Agent
CF-IPCountry
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
X-Nginx-Cache
Xserver
X-B3-SpanId
X-Mode
X-Httpd
Liferay-Portal
Webserver
X-Erf-Web-Scheduler
X-Servername
X-Tt-Logid
Url
X-NYM-Debug-Backend
X-Device-Type
X-Content-Age
X-Drupal-Cache-Contexts
X-Content-Powered-By
X-Zen-Fury
X-JoinUs
X-Varnish-Cache-Hits
X-Git-Commit
X-GeoCode
X-UPSTREAM-Address
X-SayCDN-TTL
X-Say-Cacheable
X-ServerID
X-Urbn-Context-Path
X-GeoCountry
X-Urbn-Site-Id
X-Say-TTL
X-Container-Uri
X-Proto
Azure-Version
Fastcgi-Useragent
Filters
GEO-INFO
Azure-SlotName
Azure-SiteName
X-Cache-Action
X-Tb
Azure-RegionName
X-LAGOON
Load-Balancing
Onion-Location
X-Cache-Operation
X-SaId
X-Rewrite-Enabled
X-Director
Locale
Meta-Geo
Azure-InstanceId
S-Rt
X-Storage
X-RM-Cache-TTL
X-VC-Cache
X-Varnish-Hostname
X-Forwarded-Host
X-PHP-Host
X-Labrador-Cache-Channel
X-Sucuri-Cache
X-Soup
X-Sucuri-ID
X-Cluster-Node
Uber-Trace-Id
X-Logging-Id
X-Ms-Version
X-Served-From
X-Generation-Time
X-Detected-As
Web-Mar-Node
X-Adobe-Source
X-Cache-Server
X-Sql-Count
X-Ms-Request-Id
X-VCT
CDN-RequestId
X-Sql-Duration-Ms
Webcakes-Region
X-Zipkin-Id
X-Debug
Property-Id
Webcakes-App-Version
Webcakes-App-Name
TWC-GeoIP-LatLong
TWC-Locale-Group
TWC-Privacy
Node
X-Extlb
DB-Nickname
X-Proxied
X-Origin-Hint
X-R9-Blue-Green-Version
X-RCS-CacheZone
X-Routing-Service
TWC-GeoIP-Country
TWC-Device-Class
Mn-Server-Ip
X-FB-TRIP-ID
TWC-Connection-Speed
X-Skip-Cache
Selected-Fe
X-Format
X-Uri
X-Lambda-Id
X-Tumblr-Pixel-3
X-Tumblr-Pixel-2
X-LSADC-Cache
X-Timing-Wait
X-Fetched-On
X-Proxy-Build
X-Template
OT-Force-Account-Verify
X-Ratelimit-Reset
Fastly-Drupal-HTML
Source
X-XRDS-LOCATION
X-Origin-Date
X-MP-GENERATED-AT
X-Loop
X-Tncms
X-MCACHE
X-Cache-Hit
X-Srv
X-Tec-Api-Version
X-Tec-Api-Root
X-Pass-Why
X-Tec-Api-Origin
X-Cache-Expired-At
X-Varnish-Hits
X-Endurance-Cache-Level
X-Redis-Cache
Content-Secure-Policy
X-Cache-TTL-Remaining
X-UA-Device-Type
Upgrade-Insecure-Requests
Cross-Origin-Window-Policy
X-Real-IP
X-Fastly-Request-Id
X-Via-JSL
X-Ua
Section-Io-Id
Section-Origin-Responded
Section-Io-Origin-Time-Seconds
X-CCDN-CacheTTL
X-Origin-TTL
X-Origin-CC
X-CCDN-Origin-Time
X-Hcs-Proxy-Type
X-Pubstack
Section-Io-Origin-Status
X-AIR-PT
X-NGENIX-Cache
X-Node-Name
X-Rn-Rsrv
X-Server-W
X-TimeS
X-S
X-GEO
NGB
Cache-Hits
Cache-Provider
CDN-RequestPullSuccess
X-URL
Ms-Operation-Id
X-CSRF-Token
CDN-PullZone
CDN-RequestCountryCode
CDN-CachedAt
CDN-Cache
MS-CV
CDN-Uid
CDN-EdgeStorageId
CDN-RequestPullCode
X-RTag
X-Cache-Host
X-Aspnetmvc-Version
X-PHP-Backend
X-Hl-Ver
X-Newrelic-Synthetics
Cache-Name
X-Datadome
X-Akamai-Transformed
X-Restarts
X-Reqid
X-Optimistic-Header
X-Cms-Context
X-IPLB-Request-ID
X-IPLB-Instance
Apigw-Requestid
X-Cache-Type
X-Xfnlog-Site
X-CACHE-AGE
X-No-Session
X-Parent-Response-Time
X-ProxyCache-Key
X-ProxyCache-Status
X-BYPASS-REASON
Xc-Version
X-A-Wwc
X-A-Dam
Web-Mar-Region
X-A
X-A-Ccd
X-A-Dcw
X-A-Dgt
X-Aed
X-Accel-Expires-Debug
X-Accel-Buffering
X-App
Vix-Hermes-Req-Id
Gh-Request-Id
Gannett-Cam-Experience-Id
Fastly-SSL
Ha-Gx-Prefs
HA-Ipaddr
L5d-Success-Class
L
Fastly-GeoIP-CountryCode
Fastly-Backend-Name
Candidate-Md5Url
Canary
CPC-Age
CPC-Cache
DCR-Processing-Time-Ms
DCR-Decision-By
Lang
Magicmarker
Surrogated-Key
Sslversion
Server-Host
T-Server
True-Client-Country-4JS
VNS-Cache
VNS-Age
Rendered-Blocks
Redirect-Candidate
MD5-Digest
Mail-Subject
Meta-Geo-Continent
N-Cache
Odigeo-Trace-Id
Ngx.Var.Host
W
X-Csrf-Jwt
X-FC-Vary-Parameters
X-Slack-Backend
X-Fastly-Backend
X-Forwarded-Path
X-Gdpr
X-GeoIP-Region-Code
X-GeoIP-Country-Code
X-Slack-Shared-Secret-Outcome
X-External-Request-Id
X-SRCache-Key
X-Tenant
X-Ec-Fail
X-Ec-GeoHdr
X-Eu-Site
X-Epic-Correlation-Id
X-Has-Esi
X-Irp-Debug
X-Request-Host
X-Orig-Expires
X-Rojux
X-Origin-Time
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-Policy
X-S-Cookie
X-Nyt-Route
X-JWT-State
X-Is-Gdpr
X-Mvc-Supplant-Cachable
X-Shop-Environment
X-ScT
X-SD-PageType
X-Var-Ttl
X-Vdms-Path
X-CacheTTL
X-Wikidot-Static-Cache
X-Cache-NE
X-Cdn-Diag
X-CF-Lambda-Fn
X-Wikidot-Backend
X-CF-Lambda-Version
X-Cache-Info
X-Cache-Bucket
X-B-Cookie
X-Worker
X-Bc-Bl
X-BCube-Filmed-By
X-Bl-Debug
X-Wix-Viewer-Type
X-We-Are-Hiring
X-Vtex-Remote-Cache
X-Destination
X-Vdms-Version
X-Developer
BehaviorPad-Version
X-Ec-Custom-Error
X-Dispatcher-Number
X-Debug-Cache-Store
X-Debug-Cache-Fetch
X-Viewer-Country
X-CGP
X-Conf
X-D
X-Date
X-VG-WebCache
X-Application
We-Hiring
X-Handled-By
X-Cluster
X-VWS-Id
X-LJ-Flow-ID
X-AWS-Id
Thinkindot-Control
Thinkindot-CacheControl-Type
X-Node-Id
X-Old-Content-Length
X-Access
X-Level-Front-Cache
X-Alternate-Cache-Key
X-Loc
X-Mid
X-Mly-Id
X-Nitro-Cache
X-Org
Platform
Producers
X-Pool
Origin
X-Request-Time
X-Qloud-Router
Release
Req-Svc-Chain
X-Owner
X-Origin-Response-Time
X-PAYTM-SRV-ID
X-PERF
X-Platform
Thinkindot-CacheControl
X-App-Name
X-CMSURLCustom
X-Fmm-Version
X-Clientip
X-Clara-WADP
X-Forwarded-Site
X-Core-Mission
X-Core-Value
X-DefHash
X-DPWN-IS-SECURE
X-DefElseHash
X-Section
X-Esi-Check
X-Cdn-Origin
X-Generated-On
X-Auto-Login
X-BBC-Edge-Cache-Status
X-Human
X-S-Maxage
X-INCAP-ABP
X-Bip
X-Hash
X-Geo-Header
X-Gzip
X-Cache-Id
X-Cache-Debug
X-ApacheServer
TDXMobile
X-Storefront-Renderer-Rendered
Expect-Staple
X-Varnish-CookieHashed-On
Machine
Environment
X-Sorting-Hat-ShopId
X-Varnish-Remaining-TTL
X-Varnish-CookieINHashed-On
ServedBy
X-SVT-ORM-RULES
X-Up
Is-Eu
X-Thinkindot-L3
X-Thanos
X-Test
X-Variation
X-SVT-ORM-VERSION
Host-ID
X-Varnishpool
Cmsid
X-ShardId
Cmstype
X-WADP-Cache
Adler-Geo
AKAMAI
X-Server-IP
X-Sorting-Hat-PodId
X-ShopId
X-VG-TLSProxy
X-Sn-Servicetimems
X-Shopify-Stage
Memcached
X-VServer
Datacenter
X-Vmg-Version
X-Proxy-Cache-Status
User-Cache-Control
X-Via-Fastly
X-Tx-Id
X-Block-Status
Country-Code
X-GeoIP
CloudFront-Viewer-Country
Server-Ext
X-NodeID
Esi-Enabled
Sever-Int
X-Hnp-Log
DSUID
X-WA-Info
X-Cdn-Srv
Apple-News-Services-Request-Url
NM-Fastcgi-Cache
Apple-News-Services-Parsed-Url
X-Device-Os
Apple-News-Services-Handled
X-TA-CDN-Provider
X-Gen-Mode
X-From
CDCHOST
X-Presslabs-Stats
X-Akamai-Device-Characteristics
Server-Hostname
X-Origin
Apple-News-Services-Host
X-TIM-N
X-Mvc-Supplant-OutputCached
X-Nginx-Cache-Key
X-Nananana
X-Scale
X-Dispatcher-Server
Wxu-Next-Commit
WP-Super-Cache
Wxu-Next-Hostname
Wxu-Next-Region
Pics-Label
Origin-CC
X-Refresh
X-Instance-Name
X-NCache
C-Via
X-Op-Id-All
X-Cache-Enabled
Origin-EX
Ssr
X-LB-NoCache
Server-Info
X-Cs
X-TIME
X-Cache-Status-Check
X-Air-Trace-Id
X-Air-Source
X-Amz-Meta-Cb-Modifiedtime
Hostname
X-Air-Hostname
X-Vcl-Version
Server-ID
Memory
Time
X-API-Version
X-Web-Node
Origin-Agent-Cluster
X-HA-Backend
X-Azure-Ref-OriginShield
Cf-Device-Type
X-ZONE
NGX
GeoIP-Latitude
X-Tb-Optimization-Total-Bytes-Saved
X-VHOST
AMP-Access-Control-Allow-Source-Origin
X-Origin-Expires
X-Microcachable
X-Platform-Cluster
X-Platform-Processor
X-Platform-Router
Cache-Host
X-CACHE-GROUP
X-Correlation-ID
X-DC
XM
X-Dc
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Ttl
X-Wp-Cf-Super-Cache-Active
PFcat
X-Micro-Cache
X-Site-Version
X-VarnishDD-TTL
X-Fpc
X-HN
X-Internal-Host
X-Locale
X-Vgn-Hpd-Reason
X-Ad-Defer-Variation
X-Webkit-Csp-Report-Only
Resin-Trace
YJS-ID
Srvid
Locid
Edge-Copy-Time
X-Via-Edge
A
X-Via-CDN
X-Via-SSL
X-FL-EDGE
X-FL-QIT-DEBUG
Cdn-Requestid
X-AB
X-Zone
X-WP-CF-Super-Cache-Active
X-TraceId
X-Pod-Name
Sid
X-LiteSpeed-Cache-Control
X-Github-Request-Id
Location
X-Buckets
X-B3-Spanid
X-Moov-T
Uri
X-Cache-ASPX
X-Moov-Xdn-Version
X-Contensis-Viewer-Groups
X-FireWall-Port
X-Cached-By
True-Client-Ip
X-DataCenter
User-Agent
X-B3-Parentspanid
X-Geo-Region
X-ATG-Version
X-Upstream-Ht
X-Upstream-Ct
X-FTR-Request-ID
GeoIP-Country-Code
X-SIPLIST1
X-Backend-Instance
X-Varnish-Authentication
X-Info
Cache-Key
IsBot
X-Accel-Version
X-NGINX-Cache
X-Nitro-Cache-From
CF-Ctrl
X-Nitro-Rev
X-Is-Mobile
X-Is-Desktop
X-Browser-Name
X-Is-Tablet
X-Is-Supported-Browser
X-Tcp-Rtt
X-Planisys-CDN-Cache
X-HS-Content-Campaign-Id
X-Planisys-CDN-Rules
GeoIp-Country-Code
X-Planisys-CDN-TTL
State
X-Platform-Server
X-MSEdge-Flight
Cdn
X-Datacenter
X-MSEdge-Features
X-VCache
SID
X-LiteSpeed-Tag
X-Provided-By
X-Release
NtCoent-Length
X-Fastly-Cache
XServer
X-CS
X-VC
X-CSRF-TOKEN
X-NewRelic-App-Data
X-Cache-Ttl
X-Cache-Remote
Lb
X-Rocket-Build-Number
True-Client-IP
X-Hyper-Cache
X-Sigma-Backend
Path
Epwk-X-Cache
X-Sigma
X-RN-RSRV
X-Geo
X-Vgn-Hpd-Ssi
Cache
X-Vgn-Hpd-Variations-Key
X-Vgn-Hpd-Cached
X-TRACE-ID
X-HS-Status
X-Scheme
X-GeoIP-City
X-Frame-Option
X-Webstats-RespID
X-FPC
X-Generated-In
X-Api-Version
Fastly-Drupal-Html
X-Gamma-Serve
X-UA
X-Service
X-HostName
Tcn
X-GoCache-CacheStatus
X-SRV
WebServer
Cf-Ipcountry
CountryCode
X-Rebelmouse-Surrogate-Control
X-APP-VERSION
X-Rebelmouse-Cache-Control
Serverid
X-Esi
Cdncip
X-Pad
Cdnsip
X-Air-Pt
X-Amz-Meta-Opti
Ohc-File-Size
X-AK-Request-ID
Cache-Tv-Group
X-Guploader-Uploadid
Cdn-Host
X-Origin-Cache-Key
X-Vercel-Id
X-Branch-Name
X-Edge-Server
Cdn-Request-Time
X-Vercel-Cache
X-EC-Lua
X-Wp-Cf-Super-Cache-Cache-Control
X-Wp-Cf-Super-Cache
Kp-EeAlive
X-Traceid
LB
X-VCL-Version
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-Vc
X-Location
Proxy-Connection
X-Cdn-Cache-Status
M-TraceId
Yak-Timeinfo
Env
X-Mobile-URL
X-Country-Code-Real
XkeyRZ
X-FTR-Balancer
X-FTR-Expires
X-FTR-Cache-Status
X-Proxy-CacheRZ
X-FTR-Backend-Server
X-NMSegId
WZWS-RAY
X-FTR-Backend
Req-ID
CDN
X-CACHE-KEY
HostName
X-Cdn-Request-ID
Cluster
X-Ad-Load-Variation
X-Cdn-Forward
Ohc-Cache-HIT
X-Cache-Tags
On-Server
X-Aicache-OS
Geoip-Latitude
X-Region-Sid
Srv
X-Akamai-Pragma-Client-IP
X-NWS-UUID-VERIFY
X-Edge-Pop
CacheControlHeader
Ngx
X-Men
X-Developers
X-Lb-Cache
X-M-Log
Server-Id
X-Ha-Backend
X-Request-Start
Content-Style-Type
Pramga
Content-Script-Type
X-Scope-Id
X-M-Reqid
X-LB-ID
X-TX-ID
X-CDN-Cache-Status
X-Cache-FS-Status
X-B3-Trace-ID
X-Minions-Version
X-Req
X-V-Cache
X-Servedbyhost
X-SB
X-Acquia-Purge-Cdn-Unconfigured
V-Age
RNT-Machine
Mime-Version
Click-Count-Error
Click-Count-Action-Start
RNT-Time
Tube-Get-Contents
Tube-Return
Tube-Got-Results
Tube-Got-Eval
X-Via-Poph
X-Nc
X-Via-Popn
X-Wa
X-WP-CF-Super-Cache-Cookies-Bypass
X-Via-Popv
CF-Cached-On
X-TT-LOGID
X-Acquia-Application-Trace
X-Qnm-Cache
X-Request-URI
X-Shield-Cache-Expires
WWW-Authenticate
ENV
X-Edge-POP
X-Snapshot-Date
X-MiniProfiler-Ids
X-Fastly-Country-Code
X-Dw-Trace-Id
X-IN-APIGATEWAY
X-Via-Ucdn
X-IN-APIGATEWAYSSL
X-Acquia-Site
X-Acquia-Purge-Tags
X-Acquia-Application-UUID
X-Varnish-Beresp-Status
PICS-Label
X-Tim-N
X-Check-Cacheable
X-Lb-Nocache
Yjs-Id
Edge-Cache
X-Fastly-Cache-Hits
Inserted-Into-Cache-At
X-Cache-Date
X-Cached-Since
X-RAMCache
CACHE-MISS-TO-ORIGIN
X-User
Log-Origin
X-Fastly-Backend-Reqs
X-Miniprofiler-Ids
Vha6-Origin
Cneonction
X-ElasticPress-Query
X-Litespeed-Cache-Control
X-Iauth-Set-Uid