Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
CF-RAY
Expect-CT
Accept-Ranges
X-XSS-Protection
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-Xss-Protection
X-Download-Options
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Request-Id
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
Content-Security-Policy-Report-Only
X-DNS-Prefetch-Control
Accept-CH
X-Runtime
Accept-CH-Lifetime
X-AspNet-Version
X-Drupal-Cache
X-Check
X-Cache-Status
X-Generator
Server-Timing
X-Request-ID
X-Cacheable
X-Ua-Compatible
Timing-Allow-Origin
X-Envoy-Upstream-Service-Time
X-FRAME-OPTIONS
X-Iinfo
X-Drupal-Dynamic-Cache
X-Content-Security-Policy
Feature-Policy
Access-Control-Expose-Headers
Content-Encoding
X-CDN
Status
Upgrade
X-AspNetMvc-Version
CF-Ray
Access-Control-Max-Age
X-Amz-Request-Id
X-Amz-Id-2
Cf-Edge-Cache
X-Via
Host-Header
EagleId
Permissions-Policy
Keep-Alive
X-Cache-Group
Request-Context
X-Backend
X-Robots-Tag
X-UA-Device
X-AH-Environment
X-Hacker
X-Server
X-Proxy-Cache
X-Turbo-Charged-By
Xkey
X-Rq
X-Age
X-Ws-Request-Id
X-Vhost
X-Amz-Version-Id
Cf-Apo-Via
X-Dispatcher
X-Swift-SaveTime
X-Swift-CacheTime
X-Server-Powered-By
X-LiteSpeed-Cache
Grace
Allow
Ali-Swift-Global-Savetime
X-Varnish-Cache
P3p
X-OneAgent-JS-Injection
X-Pingback
X-Page-Speed
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Cache-Lookup
X-Device
X-WebKit-CSP
EagleEye-TraceId
X-Host
Cf-Railgun
X-Backend-Server
X-Server-Id
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Dns-Prefetch-Control
X-Response-Time
X-Readtime
X-Ruxit-JS-Agent
Surrogate-Control
X-Akam-SW-Version
X-HW
X-Cloud-Trace-Context
Request-Id
X-Node
Content-Location
X-Country
X-Nginx-Cache-Status
X-Application-Context
X-Nginx-Upstream-Cache-Status
Accept-Ch-Lifetime
X-NWS-LOG-UUID
X-Country-Code
X-ASPNET-VERSION
Service-Worker-Allowed
X-Content-Type
X-Trace
X-Litespeed-Cache
Cache-Tag
X-Clacks-Overhead
X-Url
Rating
X-Amz-Server-Side-Encryption
X-Rack-Cache
X-Times
X-Vname
X-TtlSet
X-PC
X-FTR-Request-ID
Cross-Origin-Opener-Policy
X-Daa-Tunnel
X-Mcache
X-Edge
X-Midtier
X-Browser-Type
X-Server-Name
Nginx-Cache
X-CST
Accept-Ch
X-Powered-By-Plesk
AR-SID
AR-PoweredBy
AR-Request-ID
AR-ATIME
X-Cnection
X-Cache-TTL
X-ESI
X-Ac
X-Element-Page-Cache
X-GitHub-Request-Id
X-D2id
Edge-Control
X-Exp-Id
X-Cdn-Fetch
Verso
X-Exp-Variant
X-Kinja-Revision
X-Kinja-Server
X-Kinja
X-Kinja-Build
X-GoogleNews-Bot
X-MS-InvokeApp
X-ECACHE
AR-CACHE
X-Ser
X-Vcap-Request-Id
X-Abt-Application-Version
X-Upstream
X-Navigation-Version
X-B3-TraceId
X-Dw-Request-Base-Id
X-Webkit-Csp
Fastly-Restarts
SPRequestDuration
SPIisLatency
X-FastCGI-Cache
X-Mod-Pagespeed
X-Amz-Rid
X-SharePointHealthScore
SPRequestGuid
X-Erf-Bev-Bev
X-Kraken-Loop-Name
X-Instrumentation
X-Erf-Bev-Bev-Is-Generated
X-Server-Lifecycle-Phase
X-Client-IP
X-PDP-UNCACHING-HASH
X-NF-Request-ID
X-Edge-Location-Klb
X-Kinsta-Cache
X-ARC
X-Goog-Hash
X-Oneagent-Js-Injection
X-Mg-S
X-Powered-CMS
X-Sol
X-Ratelimit-Limit
X-Middleton-Display
Display
Pagespeed
Edge-Cache-Tag
S
X-Amzn-Trace-Id
Cache-Status
X-Version
Access-Control-Request-Method
X-VARITI-CCR
Response
X-Middleton-Response
X-Ratelimit-Remaining
RTSS
X-Fastly-Request-ID
X-TraceId
Realpath
X-Content-Digest
X-Forwarded-For
X-T
X-Cache-Key
Cross-Origin-Resource-Policy
X-TTL
X-Correlation-Id
X-Recruiting
Fastcgi-Cache
X-Cached
X-ORACLE-DMS-RID
X-Varnish-TTL
X-MSEdge-Ref
Front-End-Https
X-Shield-Request-Id
MicrosoftSharePointTeamServices
Content-MD5
X-Ruxit-Js-Agent
X-HS-Cache-Config
X-Ua-Browser
X-HS-Hub-Id
X-HS-Content-Id
X-Request-Processing-Time
X-Request-Received
X-FTR-Cache-Status
X-FTR-Balancer
MS-Author-Via
X-FTR-Backend
X-FTR-Backend-Server
X-Country-Code-Real
X-Protected-By
X-Forwarded-Proto
Payment
Server-Node
TP-Cache
X-Frontend
X-LLID
X-PressLabs-Stats
Public-Key-Pins
Arr-Disable-Session-Affinity
X-RateLimit-Remaining
X-SRCache-Store-Status
X-SRCache-Fetch-Status
Count-Hit
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-FTR-Expires
X-HS-Combine-CSS
X-Server-ID
X-GUploader-UploadID
X-Accel-Expires
X-Distributor
X-Kong-Upstream-Latency
X-LB-Cache
X-Kong-Proxy-Latency
X-NODE
X-Origin-Server
X-Ezoic-Cdn
X-HP-Webp
X-HP-Trace-Id
X-Jurisdiction
X-Newrelic-App-Data
X-Request-Handler-Origin-Region
X-Microsite
X-Varnish-Server
X-Www-Served-By
X-Content-Security-Policy-Report-Only
X-B3-TraceId-Primal
Host
MRF-Tech
Mrf-Cache-Status
Accept-Charset
X-AppVersion
X-Cluster-Name
X-Az
X-Activity-Id
X-App-Server
X-Ua-Device
Cache-Tags
X-Varnish-Backend
X-Amz-Meta-S3cmd-Attrs
Retry-After
Cleartype
X-ORACLE-DMS-ECID
X-Ttl
X-Goog-Metageneration
Filterid
Server-Name
X-Hits
X-Unique-Id
Surrogate-Key
X-Git-Hash
Access-Control-Allow-Method
X-Debug
X-Envoy-Decorator-Operation
X-Azure-Ref
X-Upgrade-Enabled
X-NGENIX-Cache
X-CSRF-Token
X-Load-Cache
X-Logged-In
X-Geo-Country
X-Hostname
X-FB-Debug
TCN
X-Tt-Trace-Tag
X-Tt-Trace-Host
Pinterest-Version
X-Pinterest-Rid
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Proxy
TP-L2-Cache
Pinterest-Generated-By
X-Time
X-B
Section-Io-Cache
X-B3-Sampled
X-Id
X-TT
X-Grace
X-Seen-By
X-Cache-Control
DC
X-CCDN-Origin-Time
X-Hcs-Proxy-Type
X-CCDN-CacheTTL
X-Revision
X-Request-Guid
X-Trace-Id
X-Contextid
Healthy
X-Type
Viewport
X-Fb-Rlafr
X-F-Cache
Referer-Policy
X-Mobile
X-N
X-Goog-Generation
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
Fastly-SIE
Fastly-SWR
Paypal-Debug-Id
X-DIS-Request-ID
Content-Disposition
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
X-XRDS-LOCATION
X-Varnish-Ttl
X-Debug-Info
X-Page-Id
X-Varnish-Grace
X-Px
X-Webkit-CSP
X-Origin-Cache
X-Via-JSL
X-Aws-Lambda-Call-Status
X-Magnolia-Registration
Version
X-Amz-Replication-Status
X-Whom
X-Oracle-Dms-Ecid
X-Ratelimit-Reset
X-Datadog-Sampling-Priority
X-Datadog-Trace-Id
X-Datadog-Parent-Id
X-Content-Options
X-RemovedCookies
X-Rid
X-G
X-UUID
X-ProcessESI
X-Tumblr-Pixel
X-Adobe-Loc
X-Adobe-Content
X-Tumblr-Pixel-0
X-Rule
Charset
X-App-Environment
X-Tumblr-Pixel-1
X-Template
X-Debug-IsPreview
X-Debug-IsConnected
X-Tumblr-User
X-Node-Name
Ms-Operation-Id
MS-CV
X-Hl-Ver
X-Yottaa-Optimizations
VIX-Pulpo-Node
X-Yottaa-Metrics
SD-X-WS
X-Wormhole-Sdk
X-Wix-Request-Id
NGB
X-RTag
X-Storage
VIX-Pulpo-Upstream-Status
X-Source
X-Datadog-Sampled
X-Proxy-Cache-Info
X-NYM-Debug-Backend
X-Device-Type
X-User-Agent
X-Environment-Context
X-FW-Dynamic
X-Is-Bot
X-FW-Static
X-FW-Server
X-FW-Type
X-FW-Version
X-Cacheable-TTL
X-Instance
X-L-Path
X-FW-Hash
X-Region
X-Rendered-As
X-Signature
X-B-Cache
X-FW-Serve
X-Backend-Name
Cross-Origin-Window-Policy
X-URL
Country
GEO-INFO
X-Status
X-NWS-UUID-VERIFY
X-ServerID
X-Cache-Grace
X-Cache-Age
ServerID
X-IPS-LoggedIn
X-Real-IP
Countrycode
Amp-Access-Control-Allow-Source-Origin
SRV
X-EdgeConnect-Cache-Status
X-Cache-Hit
X-RM-Cache-TTL
Akamai-GRN
X-WP-CF-Super-Cache-Active
X-Amzn-Remapped-Content-Length
Liferay-Portal
Front
X-Language
X-Framework
X-Xrds-Location
X-B3-SpanId
X-AB
X-Oracle-Dms-Rid
X-Sucuri-ID
X-Sucuri-Cache
X-Ismobilevalue
X-Air-Pt
OT-Force-Account-Verify
X-Servername
X-Content-Powered-By
X-Akamai-Request-ID2
X-UA
X-VC
X-Air-Source
X-Air-Hostname
From-Origin
X-Air-Trace-Id
X-VC-Cache
X-Mode
Xet-Cookie
Backend
X-WebKit-CSP-Report-Only
Upgrade-Insecure-Requests
X-DataDome
Refresh
X-Handled-By
X-Cache-Time
Accept-Language
X-Nginx-Cache
Access-Control-Request-Headers
X-Tt-Logid
Webserver
LB
X-HTML-Minification-Powered-By
X-Api-Version
X-Cache-Status-Check
X-Rewrite-Enabled
X-SRV
Cache
X-JoinUs
Filters
X-UPSTREAM-Address
Meta-Geo
X-Nf-Request-Id
X-RCS-CacheZone
X-SaId
X-Xfnlog-Site
X-Rn-Rsrv
TWC-GeoIP-LatLong
TWC-Connection-Speed
TWC-GeoIP-Country
TWC-Device-Class
ServedBy
X-PHP-Host
X-LJ-Flow-ID
X-No-Session
X-Origin-Hint
X-Lambda-Id
X-Labrador-Cache-Channel
X-Provided-By
TWC-Locale-Group
Property-Id
Webcakes-App-Version
X-R9-Blue-Green-Version
X-Extlb
X-Container-Uri
X-Generated-By
X-Origin-Date
X-Reqid
X-Cache-Operation
X-Cache-Rule
X-Cms-Context
X-Cluster
X-Hosted-By
Webcakes-Region
Webcakes-App-Name
X-Adobe-Source
X-Proxied
X-Cloudmap
X-AWS-Id
X-Git-Commit
TWC-Privacy
X-Routing-Service
X-Tumblr-Pixel-2
X-VWS-Id
X-Varnish-Age
X-Zipkin-Id
X-S
X-RateLimit-Limit
X-Webstats-RespID
X-Ms-Version
X-Akamai-Edgescape
X-Ms-Request-Id
X-Loop
X-Logging-Id
X-Browser-Name
Atl-Traceid
X-Cache-Debug
X-Tcp-Rtt
X-BYPASS-REASON
Apigw-Requestid
X-Locale
X-Tncms
X-Accel-Version
X-Is-Desktop
X-Is-Mobile
X-IPLB-Request-ID
X-Httpd
Mn-Server-Ip
Web-Mar-Node
X-Is-Supported-Browser
X-Web-Node
Section-Io-Id
X-Skip-Cache
Url
X-Is-Tablet
X-IPLB-Instance
X-Tb
X-Geo-Region
X-ProxyCache-Key
X-Fetched-On
X-Forwarded-Host
X-Redis-Cache
X-Served-From
X-Restarts
X-INCAP-ABP
X-ProxyCache-Status
X-Edge-Location
X-Site-Version
X-Scope-Id
X-Director
X-SayCDN-TTL
X-Say-TTL
X-Format
X-Endurance-Cache-Level
Selected-Fe
X-Request-URI
X-Varnish-Beresp-Grace
X-Timing-Wait
X-Frame-Option
X-Say-Cacheable
X-Detected-As
X-Proxy-Build
X-Upstream-Ct
X-Varnish-Cache-Hits
X-Storefront-Renderer-Rendered
X-Soup
X-Upstream-Ht
X-Cache-Host
X-Shopify-Stage
X-Alternate-Cache-Key
X-Optimistic-Header
X-Origin
X-VCT
X-GeoCode
Xserver
X-RID
X-GeoCountry
X-ShardId
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Azure-Ref-OriginShield
X-ShopId
X-Mg-Request-UUID
Frame-Options
Onion-Location
X-Lagoon
Expiry
X-Connection-Hash
X-Drupal-Cache-Tags
X-Vcl-Version
WPO-Cache-Status
Cdn-Requestid
X-ID
WPO-Cache-Message
X-WP-CF-Super-Cache-Cookies-Bypass
X-Vcache
Source
X-Generation-Time
X-CDN-Forward
Protected
X-Drupal-Cache-Contexts
X-Cache-Expired-At
X-Fastly-Request-Id
X-Shield-Cache-Expires
X-CMSURLCustom
X-Fastcgi-Cache
X-Origin-CC
TDXMobile
Thinkindot-Control
Thinkindot-CacheControl
X-Cdn-Origin
X-Origin-TTL
Thinkindot-CacheControl-Type
X-Thinkindot-L3
Fastcgi-Useragent
Environment
X-PHP-Backend
X-ECache
X-Pass-Why
Cache-Hits
X-Worker
X-Vercel-Cache
Priority
X-Cache-Action
X-Vercel-Id
X-Rocket-Nginx-Serving-Static
X-Proxy-Cache-Status
X-TA-CDN-Provider
X-App-Version
Uber-Trace-Id
Azure-SiteName
Azure-SlotName
Azure-RegionName
Azure-InstanceId
X-Buckets
Azure-Version
X-GEO
Node
X-Cluster-Node
X-Aspnetmvc-Version
Locale
X-Urbn-Context-Path
X-Urbn-Site-Id
CDN-Cache
CDN-CachedAt
X-XRDS-Location
CF-IPCountry
CDN-EdgeStorageId
CDN-PullZone
CDN-Uid
Sid
CDN-RequestPullSuccess
Cross-Origin-Embedder-Policy
CDN-RequestCountryCode
CDN-RequestPullCode
X-RateLimit-Reset
Cache-Tv-Group
X-Tumblr-Pixel-3
X-FB-TRIP-ID
X-B3-Traceid
X-Auth-Group-Type
AMP-Access-Control-Allow-Source-Origin
X-Cache-Server
X-Server-W
X-Pad
DB-Nickname
X-Origin-Cache-Key
X-Tx-Id
User-Cache-Control
X-Client-Ip
X-A
Alternate-Protocol
X-DC
X-Req
X-V-Cache
Content-Secure-Policy
X-Custom-Header
X-D
T-Server
Surrogated-Key
X-SB
X-UA-Device-Type
X-Varnish-CookieINHashed-On
X-Content-Age
X-Core-Value
X-Varnish-CookieHashed-On
X-Conf
X-BCube-Filmed-By
X-ScT
Wxu-Next-Region
Wxu-Next-Hostname
Candidate-Md5Url
A
X-Aed
X-A-Dgt
X-A-Wwc
X-A-Dam
X-A-Ccd
Wxu-Next-Commit
Cdn-Host
X-Cache-Id
X-Service
X-Cache-NE
X-Cache-TTL-Remaining
X-SRCache-Key
X-Block-Status
Cdn-Request-Time
X-Bc-Bl
X-DefElseHash
X-Bl-Debug
X-TIM-N
X-Ec-GeoHdr
X-Vtex-Remote-Cache
Meta-Geo-Continent
X-GeoIP-City
X-DefHash
Ngx.Var.Host
X-Gen-Mode
HostName
X-Org
X-Rojux
MD5-Digest
Rendered-Blocks
Lang
X-Ig-Origin-Region
X-Ig-Push-State
X-Op-Id-All
X-Hnp-Log
X-Gzip
Magicmarker
X-Origin-Expires
Origin-Agent-Cluster
Gannett-Cam-Experience-Id
X-Edge-Server
Origin
X-Vdms-Version
X-Dispatcher-Server
X-A-Dcw
DCR-Processing-Time-Ms
Odigeo-Trace-Id
X-Ec-Fail
X-Epic-Correlation-Id
X-Esi-Check
Sslversion
X-Via-Fastly
X-ND-Cache
X-Fastly-Backend
DCR-Decision-By
Edge-Cache
X-Developer
X-Varnish-Remaining-TTL
Mime-Version
Vix-Hermes-Req-Id
Origin-CC
Origin-EX
PFcat
Platform
RNT-Machine
Server-Hostname
Server-Host
Tube-Got-Eval
X-Region-Sid
Tube-Get-Contents
Ssr
Sever-Int
Server-Ext
RNT-Time
Powered-By
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
Producers
Tube-Return
Req-ID
Tube-Got-Results
V-Age
X-Clientip
X-GeoIP-Country-Code
X-GeoIP
X-GeoIP-Region-Code
X-GoCache-CacheStatus
X-HN
X-Geo-Header
X-Generated-On
X-Fmm-Version
X-Forwarded-Site
X-Origin-Response-Time
X-Gdpr
X-HS-Content-Campaign-Id
X-Jobs
X-NodeID
X-Nyt-Route
X-Mvc-Supplant-Cachable
X-Node-Id
X-Nginx-Cache-Key
X-Mly-Id
X-Micro-Cache
X-Level-Front-Cache
X-Loc
X-LSADC-Cache
X-Men
X-FC-Vary-Parameters
X-Fastly-Cache
X-Proto
X-Auto-Login
X-B3-Trace-ID
X-Backend-Instance
X-Bip
X-App-Name
X-Amz-Storage-Class
X-Ad-Load-Variation
X-Aicache-OS
X-AK-Request-ID
X-Pubstack
X-Powered-By-VTEX-Cache
X-Cache-Bucket
X-Platform
X-DPWN-IS-SECURE
X-PAYTM-SRV-ID
X-Origin-Time
X-Debug-Cache-Store
X-Debug-Cache-Fetch
X-Cache-Info
X-CacheTTL
X-Cdn-Srv
X-Policy
X-Acquia-Purge-Cdn-Unconfigured
Is-Eu
Fusion-Deployment-Id
Fusion-Template-Id
X-Server-IP
Fusion-Content-Source
Fusion-Content-Id
X-Sn-Servicetimems
Fusion-Component-Id
X-SD-PageType
Adler-Geo
Cdncip
Cdnsip
X-Scheme
CDCHOST
Cache-Provider
AKAMAI
C-Via
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-VTEX-Cache-Time
X-VTEX-Cache-Server
X-Viewer-Country
X-WA-Info
X-Wikidot-Backend
XM
X-Wikidot-Static-Cache
X-VG-WebCache
X-VG-TLSProxy
X-Test
X-Tb-Optimization-Total-Bytes-Saved
X-Thanos
X-Varnish-Director
X-VarnishDD-TTL
X-Varnish-Hostname
Click-Count-Action-Start
Fusion-Source
Fastly-SSL
X-Request-Time
Fastly-Backend-Name
Content-Style-Type
Country-Code
X-NMSegId
Esi-Enabled
Host-ID
Content-Script-Type
NM-Fastcgi-Cache
Click-Count-Error
X-Varnish-Beresp-Ttl
X-HITS
On-Server
X-Pool
X-Varnish-Beresp-Status
Release
X-Contensis-Viewer-Groups
X-CGP
X-Var-Ttl
X-Varnish-Authentication
X-Request-Host
Proxy-Firewall
X-Ec-Custom-Error
Pramga
L
X-Varnishpool
X-Request-Start
X-Eu-Site
L5d-Success-Class
X-Cache-FS-Status
X-Device-Os
Machine
X-CUA
X-Date
Mail-Subject
X-Human
X-Depends
X-Csrf-Jwt
X-We-Are-Hiring
W
X-Access
We-Hiring
Apple-News-Services-Handled
X-Cache-Aspx
Web-Mar-Region
DSUID
X-Accel-Expires-Debug
Apple-News-Services-Host
Canary
X-Mvc-Supplant-OutputCached
True-Client-Country-4JS
Cache-Key
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
X-Dc
X-Section
NGX
X-BBC-Edge-Cache-Status
X-Hash
Gh-Request-Id
Ha-Gx-Prefs
Req-Svc-Chain
HA-Ipaddr
X-LiteSpeed-Cache-Control
Fastly-GeoIP-CountryCode
X-Slack-Shared-Secret-Outcome
X-Proxied-Request
X-Slack-Backend
Cluster
Yak-Timeinfo
X-Location
X-NGINX-Cache
X-AIR-PT
X-Cs
X-Akamai-Transformed
X-Up
Server-Info
X-From
X-NCache
X-Varnish-Hits
Redirect-Candidate
Debug
BehaviorPad-Version
X-MP-GENERATED-AT
X-Zone
X-LB-ID
X-Jungle-Id
X-Tec-Api-Version
WP-Super-Cache
X-Tec-Api-Root
X-Tec-Api-Origin
SID
X-Via-Popn
Pics-Label
X-Via-Popv
X-Via-Poph
X-HA-Backend
X-APP
Fastly-Drupal-HTML
X-Cache-Backend
X-Vdms-Path
CloudFront-Viewer-Country
X-Refresh
CDN-RequestId
X-VHOST
X-Servedbyhost
X-Parent-Response-Time
X-CACHE-AGE
X-B3-Parentspanid
GeoIP-Latitude
X-Content-Length
X-Datadome
X-Uri
X-Nananana
X-PERF
X-Nc
X-Newrelic-Synthetics
X-Render-Time
X-LB-NoCache
X-M-Reqid
X-M-Log
X-VC-TTL
X-ApacheServer
X-Litespeed-Tag
Datacenter
Fastly-Drupal-Html
Resin-Trace
X-CACHE-KEY
X-Wa
Server-ID
X-Cached-By
X-CDN-Cache-Status
X-CS
X-ZONE
X-DynaTrace-JS-Agent
X-RequestId
Cdn
X-Amz-Meta-Cb-Modifiedtime
X-LiteSpeed-Tag
NtCoent-Length
Locid
X-Dispatcher-Number
X-B3-Spanid
Vc-Max-Age
X-Original-Request-Id
X-Response-Served-From
X-VCache
GeoIp-Country-Code
Product
FSS-Cache
X-Fpc
X-NewRelic-App-Data
X-TT-LOGID
X-Varnish-Beresp-TTL
X-IAuth-Set-Uid
Serverhost
X-Ckpd-Fst-Backend
X-Old-Content-Length
X-Esi
True-Client-Ip
X-TX-ID
Cf-Ipcountry
X-SERVER-NAME
X-HostName
X-Srv
ServerName
Ngx-Var-Key
Uri
X-Nf-Country
X-Nf-Language
True-Client-IP
X-Nf-Ats-Version
X-Bug-Bounty
X-HubSpot-Correlation-Id
CDN
X-Vgn-Hpd-Reason
GeoIP-Country-Code
S-Rt
Tcn
Srv
X-Oracle-DMS-ECID
X-TIME
X-Cdn-Cache-Status
X-Platform-Router
X-Cdn-Forward
X-FPC
X-Platform-Processor
X-Moov-Xdn-Version
X-Dynatrace-Js-Agent
X-TH-Server
X-Platform-Cluster
X-Moov-T
X-Webkit-Csp-Report-Only
Request-ID
CacheControlHeader
X-WA
X-Vc
X-Dispatch
Server-Id
X-Vmg-Version
Cf-Device-Type
X-Akamai-Device-Characteristics
User-Agent
X-COUNTRY
Hostname
X-APP-VERSION
X-Gamma-Serve
X-User
X-Destination
X-Info
X-NC
Geoip-Latitude
X-External-Request-Id
Srvid
X-FL-QIT-DEBUG
ServerHost
X-S-Cookie
Cross-Origin-Embedder-Policy-Report-Only
X-Application
X-B-Cookie
X-Presslabs-Stats
Xc-Version
Cneonction
X-Geo
X-Zen-Fury
X-Lb-Nocache
X-API-Version
Expect-Staple
X-ServedByHost
Origin-Trial
X-Hit
X-Via-PopN
X-Cache-Date
X-Sigma
X-Sigma-Backend
X-Instance-Name
X-Ha-Backend
X-Rocket-Build-Number
X-Via-PopH
Ohc-File-Size
X-Via-PopV
X-VCL-Version
Epwk-X-Cache
Cloudfront-Viewer-Country
PICS-Label
X-Segment-20210421
X-VServer
X-Amz-Meta-Opti
X-V
X-App
X-Correlation-ID
X-Branch-Name
X-Limited
X-Ua
X-Akamai-Pragma-Client-IP
Rtss
X-Srcache-Fetch-Status
X-Srcache-Store-Status
X-Lb-Id
WZWS-RAY
X-Check-Cacheable
X-Serial
N-Cache
X-Platform-Server
X-MiniProfiler-Ids
X-Rollout
X-New
X-Erf-Stays-Pdp-Viaduct-Migration-Web-V2
Permission-Policy
X-Eligible
Lb
X-Wp-Cf-Super-Cache-Cache-Control
X-Wp-Cf-Super-Cache
XkeyRZ
X-Sqd-Ctime
X-Sqd-Stime
X-VTEX-Cache-Backend-Header-Time
X-Proxy-CacheRZ
X-Acquia-Site
X-DataCenter
Cmsid
Cmstype
Timeexpire
X-VTEX-Cache-Backend-Connect-Time
Ohc-Cache-HIT
X-Datacenter
X-MSEdge-Flight
X-Service-Response-Time
Sm-Log-Id
X-Acquia-Application-Trace
X-MSEdge-Features
X-Acquia-Purge-Tags
X-Acquia-Application-UUID
X-Web-Server
CountryCode
X-CSRF-TOKEN
X-Litespeed-Cache-Control
Load-Balancing
Servername
DataCenter
X-LAGOON
Wpo-Cache-Message
X-Snapshot-Date
X-Ramcache
Wpo-Cache-Status
X-Th-Server
Fl-Custom-Application
X-Requestid
X-RAMCache
X-Fastly-Backend-Reqs
X-Shardid
Type
X-Amz-Meta-Sha256
X-Udemy-Cache-App-Namespace
X-IN-APIGATEWAYSSL
X-Dw-Trace-Id
X-IN-APIGATEWAY
X-Amz-Meta-S3b-Last-Modified
Warning
X-Sorting-Hat-Podid
X-Sorting-Hat-Shopid
X-Shopid
X-Origin-Upstream-Status
X-DynaTrace
Ngx