Threat Level: green Handler on Duty: Jan Kopriva

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
CF-RAY
Expect-CT
Accept-Ranges
X-XSS-Protection
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-Xss-Protection
X-UA-Compatible
X-Served-By
X-Download-Options
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
Content-Security-Policy-Report-Only
X-DNS-Prefetch-Control
Accept-CH
X-AspNet-Version
X-Runtime
Accept-CH-Lifetime
X-Drupal-Cache
X-Check
X-Cache-Status
X-Generator
Server-Timing
X-Cacheable
X-Ua-Compatible
Timing-Allow-Origin
X-Envoy-Upstream-Service-Time
X-FRAME-OPTIONS
X-Request-ID
X-Iinfo
X-Drupal-Dynamic-Cache
X-Content-Security-Policy
Access-Control-Expose-Headers
Feature-Policy
Content-Encoding
X-CDN
Status
Upgrade
X-AspNetMvc-Version
CF-Ray
Access-Control-Max-Age
X-Amz-Request-Id
X-Amz-Id-2
Cf-Edge-Cache
X-Via
Host-Header
EagleId
Keep-Alive
Request-Context
X-Cache-Group
X-Backend
Permissions-Policy
X-UA-Device
X-Robots-Tag
X-AH-Environment
X-Hacker
X-Server
X-Proxy-Cache
X-Turbo-Charged-By
Xkey
X-Rq
X-Ws-Request-Id
X-Age
X-Vhost
X-Amz-Version-Id
Cf-Apo-Via
X-Dispatcher
X-LiteSpeed-Cache
X-Swift-SaveTime
X-Swift-CacheTime
X-Server-Powered-By
Allow
Grace
Ali-Swift-Global-Savetime
X-Varnish-Cache
P3p
X-OneAgent-JS-Injection
X-Page-Speed
X-Pingback
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Cache-Lookup
X-Device
EagleEye-TraceId
Cf-Railgun
X-Host
X-WebKit-CSP
X-Backend-Server
X-Server-Id
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Dns-Prefetch-Control
X-Response-Time
X-Readtime
X-Ruxit-JS-Agent
Surrogate-Control
X-Akam-SW-Version
X-HW
Request-Id
X-Cloud-Trace-Context
X-Node
Content-Location
X-Application-Context
X-Country
X-Nginx-Cache-Status
X-Nginx-Upstream-Cache-Status
Accept-Ch-Lifetime
X-NWS-LOG-UUID
X-Country-Code
Service-Worker-Allowed
X-Content-Type
X-Trace
X-Url
X-Clacks-Overhead
Cache-Tag
Rating
X-Amz-Server-Side-Encryption
X-Rack-Cache
X-Times
X-FTR-Request-ID
X-TtlSet
X-Vname
X-PC
X-CST
X-Daa-Tunnel
X-Litespeed-Cache
Cross-Origin-Opener-Policy
Nginx-Cache
X-Edge
X-Mcache
X-Midtier
X-Browser-Type
X-Server-Name
X-Powered-By-Plesk
Accept-Ch
X-Cnection
AR-PoweredBy
AR-SID
AR-ATIME
AR-Request-ID
X-ESI
X-Ac
X-GitHub-Request-Id
X-Element-Page-Cache
X-D2id
X-Cache-TTL
Edge-Control
X-Kinja-Build
X-Kinja-Revision
X-Kinja-Server
X-Kinja
X-GoogleNews-Bot
X-Cdn-Fetch
X-Exp-Id
X-Exp-Variant
Verso
X-MS-InvokeApp
X-ECACHE
X-Upstream
X-Vcap-Request-Id
X-FastCGI-Cache
AR-CACHE
X-Ser
X-Abt-Application-Version
X-Navigation-Version
X-Dw-Request-Base-Id
X-Webkit-Csp
SPRequestDuration
SPIisLatency
X-B3-TraceId
Fastly-Restarts
X-Mod-Pagespeed
X-SharePointHealthScore
SPRequestGuid
X-Amz-Rid
X-Erf-Bev-Bev-Is-Generated
X-Server-Lifecycle-Phase
X-Instrumentation
X-Erf-Bev-Bev
X-Kraken-Loop-Name
X-NF-Request-ID
X-Client-IP
X-Kinsta-Cache
X-Edge-Location-Klb
X-Oneagent-Js-Injection
X-Goog-Hash
X-Ratelimit-Limit
X-Mg-S
Edge-Cache-Tag
S
X-Powered-CMS
X-ARC
X-Middleton-Display
Display
X-Sol
Pagespeed
X-PDP-UNCACHING-HASH
Cache-Status
X-Amzn-Trace-Id
X-Version
Access-Control-Request-Method
Response
X-Middleton-Response
X-VARITI-CCR
X-Cache-Key
X-Ratelimit-Remaining
X-Fastly-Request-ID
X-TTL
RTSS
X-TraceId
X-Content-Digest
Realpath
X-T
Cross-Origin-Resource-Policy
X-Forwarded-For
X-Recruiting
X-Correlation-Id
Fastcgi-Cache
X-ORACLE-DMS-RID
X-Cached
Front-End-Https
X-MSEdge-Ref
X-Shield-Request-Id
MS-Author-Via
X-Varnish-TTL
Content-MD5
X-HS-Hub-Id
X-Country-Code-Real
X-HS-Content-Id
X-HS-Cache-Config
X-FTR-Cache-Status
X-FTR-Backend-Server
X-FTR-Backend
X-Protected-By
X-Ruxit-Js-Agent
X-Ua-Browser
X-FTR-Balancer
MicrosoftSharePointTeamServices
X-Forwarded-Proto
X-Request-Received
X-Request-Processing-Time
X-LLID
X-RateLimit-Remaining
Public-Key-Pins
Server-Node
X-Frontend
TP-Cache
Payment
Arr-Disable-Session-Affinity
X-PressLabs-Stats
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-FTR-Expires
X-HS-Combine-CSS
X-Server-ID
Count-Hit
X-GUploader-UploadID
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Accel-Expires
X-Distributor
X-Origin-Server
X-NODE
X-LB-Cache
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
X-Jurisdiction
X-HP-Trace-Id
X-HP-Webp
X-Ezoic-Cdn
X-Aws-Lambda-Call-Status
X-Request-Handler-Origin-Region
X-Microsite
X-Activity-Id
X-Varnish-Server
X-Az
X-Newrelic-App-Data
X-Www-Served-By
X-AppVersion
Accept-Charset
Host
X-Cluster-Name
MRF-Tech
Mrf-Cache-Status
X-B3-TraceId-Primal
X-App-Server
X-Varnish-Backend
X-Ua-Device
X-ORACLE-DMS-ECID
Cache-Tags
X-Amz-Meta-S3cmd-Attrs
Retry-After
X-Content-Security-Policy-Report-Only
Cleartype
X-Webkit-CSP
Server-Name
X-Pinterest-Rid
Pinterest-Generated-By
Pinterest-Version
X-Goog-Metageneration
X-ASPNET-VERSION
X-Hits
Filterid
X-Unique-Id
X-Envoy-Decorator-Operation
X-Git-Hash
X-CSRF-Token
Access-Control-Allow-Method
X-Hostname
X-Azure-Ref
X-Geo-Country
X-Upgrade-Enabled
X-NGENIX-Cache
X-Load-Cache
Referer-Policy
X-Id
X-Ttl
X-Logged-In
X-Debug
TP-L2-Cache
X-Time
TCN
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Seen-By
X-FB-Debug
X-Proxy
X-CCDN-CacheTTL
X-B
X-CCDN-Origin-Time
X-Hcs-Proxy-Type
X-TT
X-B3-Sampled
Section-Io-Cache
X-Varnish-Ttl
X-Grace
X-Amz-Apigw-Id
X-Amzn-RequestId
DC
X-Trace-Id
X-Revision
X-Cache-Control
Surrogate-Key
X-Request-Guid
X-F-Cache
X-Type
X-Contextid
X-Fb-Rlafr
Healthy
Viewport
X-DIS-Request-ID
X-Mobile
Paypal-Debug-Id
X-N
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Goog-Generation
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
Fastly-SIE
Fastly-SWR
X-Page-Id
X-XRDS-LOCATION
X-Debug-Info
Content-Disposition
X-Px
X-Origin-Cache
X-Via-JSL
X-Whom
X-Varnish-Grace
Version
X-Magnolia-Registration
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
X-Template
X-Content-Options
X-Oracle-Dms-Ecid
Charset
X-Amz-Replication-Status
X-UUID
X-Wix-Request-Id
X-Rid
X-G
X-ProcessESI
X-RemovedCookies
X-Cache-Grace
Ms-Operation-Id
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-Debug-IsConnected
X-Debug-IsPreview
X-App-Environment
X-Adobe-Loc
X-Tumblr-User
X-Tumblr-Pixel
X-Rule
X-RTag
X-Adobe-Content
X-Node-Name
MS-CV
X-B-Cache
VIX-Pulpo-Node
X-Yottaa-Optimizations
VIX-Pulpo-Upstream-Status
X-Yottaa-Metrics
NGB
X-Hl-Ver
X-Cache-Age
X-Source
X-Storage
X-NWS-UUID-VERIFY
X-Signature
SD-X-WS
X-Datadog-Sampled
ServerID
X-FW-Static
X-NYM-Debug-Backend
X-L-Path
X-Is-Bot
X-Proxy-Cache-Info
X-Region
X-User-Agent
X-Rendered-As
X-Instance
X-FW-Version
X-FW-Dynamic
X-Device-Type
X-Cacheable-TTL
X-FW-Hash
X-FW-Serve
X-FW-Type
X-FW-Server
X-Backend-Name
X-Environment-Context
X-EdgeConnect-Cache-Status
X-Cache-Hit
Country
X-Real-IP
X-Status
GEO-INFO
X-ServerID
Countrycode
X-Language
X-IPS-LoggedIn
Cross-Origin-Window-Policy
SRV
Liferay-Portal
X-Amzn-Remapped-Content-Length
Akamai-GRN
X-B3-SpanId
X-Ratelimit-Reset
X-Wormhole-Sdk
X-WP-CF-Super-Cache-Active
X-Sucuri-Cache
Front
X-RM-Cache-TTL
X-Sucuri-ID
Amp-Access-Control-Allow-Source-Origin
X-Xrds-Location
OT-Force-Account-Verify
X-Framework
X-Oracle-Dms-Rid
X-Servername
X-AB
X-Air-Pt
X-UA
From-Origin
X-VC-Cache
X-Content-Powered-By
X-Mode
Xet-Cookie
X-VC
X-Air-Hostname
X-Air-Source
X-Air-Trace-Id
X-WebKit-CSP-Report-Only
X-Akamai-Request-ID2
Backend
X-URL
Upgrade-Insecure-Requests
Refresh
X-Cache-Time
X-Origin-Cache-Key
X-Handled-By
X-DataDome
X-Nginx-Cache
X-INCAP-ABP
Accept-Language
X-Endurance-Cache-Level
X-Ismobilevalue
X-Xfnlog-Site
Cache
X-JoinUs
X-RCS-CacheZone
X-SRV
X-SaId
X-UPSTREAM-Address
X-Rewrite-Enabled
X-Edge-Location
Filters
Meta-Geo
X-Rn-Rsrv
LB
X-Cms-Context
X-Proxied
Webserver
TWC-Privacy
X-Provided-By
X-HTML-Minification-Powered-By
X-Generated-By
X-VWS-Id
X-Varnish-Age
Access-Control-Request-Headers
ServedBy
X-Reqid
TWC-Connection-Speed
TWC-GeoIP-LatLong
TWC-Locale-Group
X-Cache-Operation
X-Cache-Rule
X-Cloudmap
X-Origin-Date
X-S
Property-Id
Webcakes-Region
X-R9-Blue-Green-Version
X-Adobe-Source
X-Cache-Status-Check
X-Origin-Hint
X-No-Session
TWC-GeoIP-Country
X-Extlb
X-Hosted-By
X-Routing-Service
Webcakes-App-Name
X-LJ-Flow-ID
TWC-Device-Class
X-Git-Commit
X-Zipkin-Id
X-Container-Uri
X-RateLimit-Limit
Webcakes-App-Version
X-Lambda-Id
X-AWS-Id
X-Webstats-RespID
X-Tumblr-Pixel-2
X-Cluster
X-Httpd
X-IPLB-Instance
X-Is-Desktop
Mn-Server-Ip
X-IPLB-Request-ID
Web-Mar-Node
Url
X-Is-Mobile
Apigw-Requestid
Section-Io-Id
Atl-Traceid
X-Locale
X-Logging-Id
X-Loop
X-PHP-Host
X-Ms-Version
X-Ms-Request-Id
X-Web-Node
X-Geo-Region
X-Is-Tablet
X-Labrador-Cache-Channel
X-Is-Supported-Browser
X-Redis-Cache
X-Cache-Debug
X-Tb
X-Restarts
X-BYPASS-REASON
X-Tncms
X-Fetched-On
X-Scope-Id
X-Site-Version
X-Skip-Cache
X-Tcp-Rtt
X-Forwarded-Host
X-Akamai-Edgescape
X-Served-From
X-ProxyCache-Key
X-Browser-Name
X-Accel-Version
X-ProxyCache-Status
X-Api-Version
X-Detected-As
X-Director
X-Storefront-Renderer-Rendered
X-Upstream-Ht
X-Soup
X-Proxy-Build
X-Say-TTL
X-SayCDN-TTL
X-Upstream-Ct
X-Azure-Ref-OriginShield
X-Shopify-Stage
X-Timing-Wait
Frame-Options
X-Frame-Option
X-Cache-Host
X-Alternate-Cache-Key
X-VCT
X-Varnish-Cache-Hits
X-Origin
X-Say-Cacheable
Selected-Fe
X-Varnish-Beresp-Grace
X-Format
X-GeoCode
X-Optimistic-Header
WPO-Cache-Status
X-GeoCountry
WPO-Cache-Message
X-RID
Xserver
X-ShardId
X-ShopId
X-Request-URI
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Drupal-Cache-Tags
X-Generation-Time
X-CMSURLCustom
X-RateLimit-Reset
X-Origin-TTL
X-Origin-CC
X-Tt-Logid
Thinkindot-Control
X-Shield-Cache-Expires
Cache-Hits
X-Thinkindot-L3
TDXMobile
X-Vcache
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
X-Drupal-Cache-Contexts
Source
Cdn-Requestid
Onion-Location
Expiry
X-Cdn-Origin
X-Connection-Hash
Protected
X-CDN-Forward
Fastcgi-Useragent
X-Fastly-Request-Id
X-WP-CF-Super-Cache-Cookies-Bypass
X-Lagoon
X-B3-Traceid
X-Mg-Request-UUID
X-Cache-Expired-At
X-Buckets
X-Vercel-Id
X-Worker
X-Vercel-Cache
X-Pass-Why
X-TA-CDN-Provider
X-PHP-Backend
Azure-RegionName
Azure-SiteName
Azure-SlotName
Azure-Version
X-Rocket-Nginx-Serving-Static
Azure-InstanceId
X-Nf-Request-Id
Node
X-ECache
Environment
X-Vcl-Version
X-App-Version
Sid
Priority
X-Cache-Action
X-ID
X-GEO
X-Proxy-Cache-Status
AMP-Access-Control-Allow-Source-Origin
CDN-Cache
X-Aspnetmvc-Version
CDN-EdgeStorageId
CDN-Uid
Uber-Trace-Id
CDN-CachedAt
CDN-RequestPullSuccess
Cross-Origin-Embedder-Policy
CDN-RequestPullCode
CDN-RequestCountryCode
CDN-PullZone
X-Tumblr-Pixel-3
X-Cluster-Node
X-XRDS-Location
X-Urbn-Context-Path
Locale
X-Urbn-Site-Id
X-Cache-Server
X-Fastcgi-Cache
X-Server-W
Cache-Tv-Group
DB-Nickname
X-FB-TRIP-ID
HostName
Alternate-Protocol
User-Cache-Control
X-Auth-Group-Type
CF-IPCountry
Fusion-Deployment-Id
Fusion-Content-Source
Fusion-Component-Id
Fusion-Content-Id
Fusion-Source
Fusion-Template-Id
X-Tx-Id
X-Pad
X-DC
X-Jobs
X-Client-Ip
Rendered-Blocks
X-Device-Os
X-Dispatcher-Server
X-Ec-Fail
X-Vtex-Remote-Cache
X-Op-Id-All
X-Org
T-Server
X-Origin-Expires
Gannett-Cam-Experience-Id
Sslversion
X-Service
X-ND-Cache
X-Ec-GeoHdr
X-DefHash
X-Developer
X-Ig-Push-State
X-Fastly-Backend
Lang
Magicmarker
MD5-Digest
Meta-Geo-Continent
Content-Secure-Policy
DCR-Decision-By
X-Generated-On
X-Gen-Mode
Edge-Cache
X-GeoIP-City
DCR-Processing-Time-Ms
X-Epic-Correlation-Id
X-Varnish-Remaining-TTL
Origin-Agent-Cluster
Origin
X-Ig-Origin-Region
X-DefElseHash
A
X-Hnp-Log
X-Edge-Server
Cdn-Request-Time
Ngx.Var.Host
Cdn-Host
Candidate-Md5Url
Odigeo-Trace-Id
X-Level-Front-Cache
Surrogated-Key
X-A-Dgt
X-A-Wwc
X-Core-Value
X-Bl-Debug
X-UA-Device-Type
X-Block-Status
X-A-Dam
X-V-Cache
X-A-Dcw
X-Req
X-TIM-N
X-Rojux
X-Bc-Bl
X-Vdms-Version
X-Conf
X-SRCache-Key
X-Content-Age
X-ScT
X-Aed
X-SB
X-BCube-Filmed-By
X-A-Ccd
X-Via-Fastly
X-Cache-NE
Wxu-Next-Hostname
Wxu-Next-Commit
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-D
X-Viewer-Country
X-Custom-Header
X-Cache-TTL-Remaining
X-A
Wxu-Next-Region
X-LSADC-Cache
X-Gdpr
X-Backend-Instance
X-Cdn-Srv
X-B3-Trace-ID
X-Cache-Info
X-Forwarded-Site
X-Cache-Bucket
NM-Fastcgi-Cache
Host-ID
X-CacheTTL
X-FC-Vary-Parameters
Is-Eu
X-Auto-Login
X-Esi-Check
X-Fastly-Cache
X-Bip
X-Fmm-Version
Platform
Sever-Int
Ssr
Server-Hostname
Server-Host
RNT-Time
Server-Ext
Vix-Hermes-Req-Id
V-Age
Tube-Get-Contents
Tube-Got-Eval
X-Debug-Cache-Store
Tube-Return
X-Debug-Cache-Fetch
RNT-Machine
Req-ID
Origin-EX
PFcat
X-Amz-Storage-Class
Origin-CC
X-App-Name
X-AK-Request-ID
Tube-Got-Results
Producers
X-DPWN-IS-SECURE
X-Acquia-Purge-Cdn-Unconfigured
X-Ad-Load-Variation
Powered-By
X-Clientip
Cdnsip
X-NMSegId
X-Nginx-Cache-Key
X-WA-Info
X-Node-Id
X-NodeID
Fastly-SSL
X-Nyt-Route
X-Scheme
X-Wikidot-Backend
X-Sn-Servicetimems
X-SVT-ORM-RULES
XM
X-Wikidot-Static-Cache
X-SD-PageType
X-Server-IP
X-Origin-Response-Time
X-Origin-Time
X-VG-WebCache
X-VTEX-Cache-Server
X-Pubstack
X-RateLimit-Limit-Second
X-Region-Sid
X-RateLimit-Remaining-Second
X-Proto
X-Powered-By-VTEX-Cache
X-VTEX-Cache-Time
X-VG-TLSProxy
X-PAYTM-SRV-ID
X-Platform
X-Request-Time
X-Policy
X-Mvc-Supplant-Cachable
X-Mly-Id
X-GoCache-CacheStatus
X-GeoIP-Region-Code
Content-Script-Type
X-Varnish-Director
Click-Count-Error
X-Gzip
Click-Count-Action-Start
Content-Style-Type
Country-Code
X-Varnish-Hostname
Fastly-Backend-Name
Esi-Enabled
X-Geo-Header
X-GeoIP-Country-Code
X-GeoIP
X-VarnishDD-TTL
Cdncip
X-Loc
Adler-Geo
X-Test
X-Cache-Id
X-Micro-Cache
X-Men
X-SVT-ORM-VERSION
AKAMAI
X-HN
CDCHOST
Cache-Provider
C-Via
X-Thanos
X-HS-Content-Campaign-Id
X-Tb-Optimization-Total-Bytes-Saved
X-HITS
X-Tec-Api-Version
X-Varnish-Beresp-Ttl
X-Tec-Api-Root
Mime-Version
X-Tec-Api-Origin
X-Location
X-Human
X-Ec-Custom-Error
X-Aicache-OS
X-Mvc-Supplant-OutputCached
X-Varnishpool
X-Hash
X-Varnish-Beresp-Status
X-Eu-Site
X-Varnish-Authentication
X-Var-Ttl
X-CGP
X-Up
X-From
X-Slack-Shared-Secret-Outcome
X-Request-Host
X-Request-Start
X-Csrf-Jwt
X-Pool
X-CUA
X-Date
X-We-Are-Hiring
X-NCache
X-Slack-Backend
X-Contensis-Viewer-Groups
X-Section
X-Depends
Yak-Timeinfo
X-Cache-Aspx
Req-Svc-Chain
Release
Canary
Proxy-Firewall
Cache-Key
Apple-News-Services-Request-Url
True-Client-Country-4JS
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
Pramga
Cluster
L
HA-Ipaddr
Ha-Gx-Prefs
L5d-Success-Class
Mail-Subject
On-Server
DSUID
NGX
Gh-Request-Id
Apple-News-Services-Handled
X-Accel-Expires-Debug
X-Dc
X-BBC-Edge-Cache-Status
Web-Mar-Region
X-Access
X-LiteSpeed-Cache-Control
We-Hiring
X-MP-GENERATED-AT
W
X-AIR-PT
X-NGINX-Cache
Machine
X-Proxied-Request
Fastly-GeoIP-CountryCode
X-Jungle-Id
X-Zone
X-Cs
X-LB-ID
X-Akamai-Transformed
X-Vdms-Path
X-Varnish-Hits
X-Cache-FS-Status
X-Cache-Backend
WP-Super-Cache
X-Uri
Debug
CDN-RequestId
Redirect-Candidate
X-Via-Popv
X-Refresh
Pics-Label
X-Via-Popn
X-HA-Backend
CloudFront-Viewer-Country
Fastly-Drupal-HTML
Server-Info
X-Via-Poph
X-VHOST
X-Render-Time
X-Nananana
X-PERF
X-ApacheServer
X-Newrelic-Synthetics
BehaviorPad-Version
X-Servedbyhost
SID
GeoIP-Latitude
X-VC-TTL
X-M-Log
X-Datadome
X-M-Reqid
X-Parent-Response-Time
X-LB-NoCache
X-CACHE-AGE
X-APP
X-Response-Served-From
X-B3-Parentspanid
X-Original-Request-Id
X-Cached-By
Locid
Fastly-Drupal-Html
X-Content-Length
Datacenter
X-TT-LOGID
X-DynaTrace-JS-Agent
X-Litespeed-Tag
Resin-Trace
Server-ID
X-Nc
X-Wa
X-CS
Cf-Ipcountry
Cdn
X-Amz-Meta-Cb-Modifiedtime
X-CDN-Cache-Status
X-LiteSpeed-Tag
X-IAuth-Set-Uid
X-Old-Content-Length
X-VCache
GeoIp-Country-Code
NtCoent-Length
X-ZONE
Vc-Max-Age
X-Dispatcher-Number
Uri
FSS-Cache
X-RequestId
X-Fpc
Ngx-Var-Key
X-NewRelic-App-Data
X-Varnish-Beresp-TTL
X-Platform-Cluster
X-Platform-Router
X-Vgn-Hpd-Reason
X-Esi
True-Client-Ip
X-B3-Spanid
X-Platform-Processor
Serverhost
Product
X-TX-ID
X-SERVER-NAME
X-Srv
X-HostName
X-Moov-T
CDN
X-Erf-Stays-Pdp-Viaduct-Migration-Web-V2
Srv
X-Moov-Xdn-Version
X-TH-Server
True-Client-IP
X-Cdn-Forward
X-Ckpd-Fst-Backend
X-Nf-Language
GeoIP-Country-Code
X-Nf-Country
X-Nf-Ats-Version
Tcn
X-Oracle-DMS-ECID
X-TIME
X-FPC
ServerName
Cross-Origin-Embedder-Policy-Report-Only
S-Rt
X-Dynatrace-Js-Agent
X-Cdn-Cache-Status
Cf-Device-Type
X-Bug-Bounty
Request-ID
X-HubSpot-Correlation-Id
X-Vc
X-Application
CacheControlHeader
X-WA
X-NC
X-User
X-External-Request-Id
X-Dispatch
X-S-Cookie
X-Destination
X-B-Cookie
X-CACHE-KEY
X-Zen-Fury
Server-Id
Hostname
X-COUNTRY
X-APP-VERSION
Geoip-Latitude
X-Webkit-Csp-Report-Only
X-FL-QIT-DEBUG
X-Rocket-Build-Number
X-Sigma
X-Cache-Date
X-Instance-Name
X-Sigma-Backend
Srvid
X-Presslabs-Stats
User-Agent
X-API-Version
X-Lb-Nocache
X-Vmg-Version
X-Geo
X-VServer
Ohc-File-Size
X-VCL-Version
X-Akamai-Device-Characteristics
X-Segment-20210421
X-Info
X-Via-PopN
X-ServedByHost
Origin-Trial
X-Branch-Name
X-Via-PopH
X-Gamma-Serve
ServerHost
X-Ha-Backend
X-Via-PopV
PICS-Label
X-App
Xc-Version
Cneonction
Cloudfront-Viewer-Country
Epwk-X-Cache
Load-Balancing
DataCenter
X-DynaTrace
X-Correlation-ID
X-Ua
Expect-Staple
X-DataCenter
X-Limited
X-Srcache-Store-Status
X-Srcache-Fetch-Status
Rtss
Type
X-Lb-Id
X-Amz-Meta-Opti
X-MSEdge-Features
X-MSEdge-Flight
X-MiniProfiler-Ids
X-LAGOON
X-Hit
X-Akamai-Pragma-Client-IP
Ohc-Cache-HIT
X-Check-Cacheable
X-Serial
Lb
Timeexpire
X-Acquia-Site
X-Acquia-Purge-Tags
X-Acquia-Application-Trace
X-Sqd-Ctime
X-Owner
X-Web-Server
Warning
Cmsid
Cmstype
X-Sqd-Stime
X-Acquia-Application-UUID
X-Irp-Debug
Sm-Log-Id
X-Datacenter
X-Service-Response-Time
Cross-Origin-Opener-Policy-Report-Only
CountryCode
Servername
X-CSRF-TOKEN
X-Litespeed-Cache-Control
X-Origin-Upstream-Status
X-Via-SSL
X-Via-Edge
X-Via-CDN
X-Sorting-Hat-Podid
X-Qloud-Router
N-Cache
Permission-Policy
X-Ramcache
X-Sorting-Hat-Shopid
X-Shopid
X-Snapshot-Date
X-Shardid
Cl-Cache
X-Th-Server
X-Dw-Trace-Id
X-Udemy-Cache-App-Namespace
X-Amz-Meta-Sha256
X-Amz-Meta-S3b-Last-Modified
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
Edge-Copy-Time
X-RAMCache
X-Core-Mission
X-Requestid
Ngx