Threat Level: green Handler on Duty: Daniel Wesemann

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
CF-RAY
Accept-Ranges
Expect-CT
X-XSS-Protection
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
P3P
X-Xss-Protection
X-Cache-Hits
X-UA-Compatible
X-Served-By
X-Download-Options
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
Accept-CH
X-AspNet-Version
Content-Security-Policy-Report-Only
X-Runtime
Accept-CH-Lifetime
X-DNS-Prefetch-Control
X-Drupal-Cache
X-Check
X-Cache-Status
X-Generator
X-Ua-Compatible
Server-Timing
X-Request-ID
X-Cacheable
X-Envoy-Upstream-Service-Time
Timing-Allow-Origin
X-FRAME-OPTIONS
X-Iinfo
X-Drupal-Dynamic-Cache
X-Content-Security-Policy
Access-Control-Expose-Headers
Feature-Policy
X-CDN
Content-Encoding
Status
X-AspNetMvc-Version
Upgrade
CF-Ray
Access-Control-Max-Age
X-Amz-Request-Id
X-Via
X-Amz-Id-2
Cf-Edge-Cache
Host-Header
EagleId
Keep-Alive
Request-Context
X-Backend
X-Cache-Group
X-AH-Environment
X-Robots-Tag
X-Server
X-UA-Device
X-Hacker
X-Turbo-Charged-By
X-Proxy-Cache
Permissions-Policy
X-Ws-Request-Id
Xkey
X-Rq
X-Age
X-Amz-Version-Id
X-Vhost
X-Dispatcher
Allow
Cf-Apo-Via
X-Dns-Prefetch-Control
X-Swift-CacheTime
X-Swift-SaveTime
X-Server-Powered-By
Grace
Ali-Swift-Global-Savetime
X-Varnish-Cache
X-LiteSpeed-Cache
X-Page-Speed
X-Pingback
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Cache-Lookup
X-OneAgent-JS-Injection
X-Device
Cf-Railgun
X-Backend-Server
EagleEye-TraceId
X-WebKit-CSP
X-Host
X-Server-Id
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Response-Time
X-Readtime
X-Akam-SW-Version
Surrogate-Control
X-HW
Request-Id
X-Cloud-Trace-Context
X-Ruxit-JS-Agent
Content-Location
X-Node
X-Application-Context
X-Nginx-Cache-Status
X-Nginx-Upstream-Cache-Status
P3p
X-NWS-LOG-UUID
X-Country
X-CST
Service-Worker-Allowed
X-Country-Code
X-Litespeed-Cache
X-Content-Type
X-Clacks-Overhead
Cache-Tag
X-Trace
X-Url
Rating
X-Rack-Cache
X-Amz-Server-Side-Encryption
Nginx-Cache
X-Times
X-FTR-Request-ID
X-Vname
X-TtlSet
X-PC
X-Daa-Tunnel
X-Server-Name
Cross-Origin-Opener-Policy
X-Oneagent-Js-Injection
X-Edge
X-Mcache
X-Midtier
X-Browser-Type
X-Webkit-Csp
X-Powered-By-Plesk
X-ESI
X-Cnection
X-ECACHE
X-Upstream
X-GitHub-Request-Id
Edge-Control
X-D2id
X-MS-InvokeApp
X-Ac
Verso
X-Element-Page-Cache
X-Cdn-Fetch
AR-SID
AR-Request-ID
X-Exp-Id
X-GoogleNews-Bot
X-Kinja-Revision
X-Kinja-Server
X-Kinja-Build
X-Kinja
AR-ATIME
X-Exp-Variant
AR-PoweredBy
X-Ser
X-Vcap-Request-Id
Accept-Ch-Lifetime
X-Cache-TTL
X-FastCGI-Cache
X-Abt-Application-Version
X-Navigation-Version
AR-CACHE
X-Mod-Pagespeed
X-Dw-Request-Base-Id
SPRequestDuration
SPIisLatency
X-Aws-Lambda-Call-Status
X-B3-TraceId
SPRequestGuid
X-SharePointHealthScore
X-Amz-Rid
X-NF-Request-ID
Fastly-Restarts
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Instrumentation
X-Client-IP
X-Middleton-Display
X-Sol
Pagespeed
Display
X-Mg-S
Edge-Cache-Tag
X-Ruxit-Js-Agent
X-Kinsta-Cache
X-Edge-Location-Klb
S
X-Powered-CMS
Cache-Status
X-Middleton-Response
Response
X-Amzn-Trace-Id
X-Goog-Hash
X-Version
Access-Control-Request-Method
X-VARITI-CCR
X-Fastly-Request-ID
X-Cache-Key
X-ARC
RTSS
X-RateLimit-Remaining
X-Content-Digest
X-TraceId
Cross-Origin-Resource-Policy
X-Forwarded-For
X-Ratelimit-Limit
X-Recruiting
Realpath
X-T
X-Ua-Device
X-Correlation-Id
Front-End-Https
X-Server-ID
X-MSEdge-Ref
Fastcgi-Cache
X-Varnish-TTL
X-Cached
X-PDP-UNCACHING-HASH
MS-Author-Via
X-Pinterest-Rid
X-Ratelimit-Remaining
Pinterest-Version
Pinterest-Generated-By
Content-MD5
X-TTL
X-HS-Cache-Config
X-Ua-Browser
X-HS-Hub-Id
X-HS-Content-Id
X-FTR-Backend-Server
X-Country-Code-Real
X-FTR-Backend
X-FTR-Balancer
X-FTR-Cache-Status
X-Shield-Request-Id
Payment
X-Protected-By
Public-Key-Pins
Server-Node
X-Forwarded-Proto
X-HS-Combine-CSS
X-LLID
X-Frontend
TP-Cache
X-Request-Received
X-Request-Processing-Time
Arr-Disable-Session-Affinity
MicrosoftSharePointTeamServices
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Distributor
X-FTR-Expires
X-HP-Trace-Id
X-Accel-Expires
X-HP-Webp
X-Jurisdiction
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-ORACLE-DMS-RID
Count-Hit
X-Ttl
X-GUploader-UploadID
X-LB-Cache
X-Origin-Server
X-NODE
X-Ezoic-Cdn
X-Request-Handler-Origin-Region
X-Microsite
X-TEC-API-ROOT
X-Content-Security-Policy-Report-Only
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-Origin-Cache-Key
X-Activity-Id
X-Az
X-AppVersion
Host
X-PressLabs-Stats
Mrf-Cache-Status
MRF-Tech
X-B3-TraceId-Primal
X-Www-Served-By
X-Varnish-Server
X-App-Server
X-Hits
X-Cluster-Name
Cache-Tags
X-Varnish-Backend
Retry-After
Accept-Charset
X-Amz-Meta-S3cmd-Attrs
Server-Name
X-Newrelic-App-Data
Cleartype
X-Geo-Country
X-Hostname
X-Envoy-Decorator-Operation
X-NGENIX-Cache
X-Goog-Metageneration
Referer-Policy
X-ORACLE-DMS-ECID
X-CSRF-Token
X-DIS-Request-ID
X-Id
X-Upgrade-Enabled
TP-L2-Cache
X-Git-Hash
Access-Control-Allow-Method
X-Seen-By
TCN
X-Azure-Ref
X-Unique-Id
X-CCDN-CacheTTL
X-CCDN-Origin-Time
X-Hcs-Proxy-Type
X-Tt-Trace-Tag
X-Tt-Trace-Host
Filterid
X-F-Cache
X-Load-Cache
X-Proxy
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Revision
Healthy
X-Request-Guid
Section-Io-Cache
X-Cache-Control
X-B3-Sampled
X-Grace
X-B
X-Trace-Id
X-TT
X-Contextid
X-Debug-Info
X-Px
DC
X-Type
X-Fb-Rlafr
X-Logged-In
X-Page-Id
Paypal-Debug-Id
X-FB-Debug
X-Varnish-Ttl
X-Mobile
X-N
X-Debug
X-Oracle-Dms-Ecid
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
Viewport
X-RateLimit-Limit
X-Goog-Generation
X-Whom
X-Goog-Storage-Class
Fastly-SWR
X-Goog-Stored-Content-Length
Fastly-SIE
X-Goog-Stored-Content-Encoding
X-XRDS-LOCATION
X-Oracle-Dms-Rid
Charset
X-Datadog-Parent-Id
X-Template
X-Datadog-Sampling-Priority
X-Datadog-Trace-Id
X-Content-Options
X-Via-JSL
Content-Disposition
Version
X-Time
X-Cache-Grace
X-Magnolia-Registration
X-Wix-Request-Id
X-Varnish-Grace
X-Webkit-CSP
X-App-Environment
X-Language
X-EdgeConnect-Cache-Status
X-Rid
X-Signature
X-B3-SpanId
X-B-Cache
X-Node-Name
X-Origin-Cache
X-RemovedCookies
VIX-Pulpo-Node
SRV
X-ProcessESI
VIX-Pulpo-Upstream-Status
X-Amz-Replication-Status
X-Tumblr-Pixel-0
X-Yottaa-Optimizations
X-Debug-IsPreview
X-Datadog-Sampled
X-Yottaa-Metrics
X-Rule
X-Tumblr-User
X-Tumblr-Pixel-1
X-Debug-IsConnected
X-Tumblr-Pixel
SD-X-WS
X-UUID
Ms-Operation-Id
X-RTag
X-Hl-Ver
MS-CV
X-G
X-Adobe-Loc
X-Adobe-Content
X-Amzn-Remapped-Content-Length
GEO-INFO
ServerID
X-Storage
Liferay-Portal
NGB
X-Rendered-As
X-Is-Bot
X-Cacheable-TTL
X-FW-Version
X-FW-Dynamic
X-Device-Type
X-NYM-Debug-Backend
X-FW-Type
X-FW-Server
X-FW-Static
X-Backend-Name
X-FW-Serve
X-FW-Hash
X-L-Path
Country
X-Cache-Hit
X-IPS-LoggedIn
X-Environment-Context
X-RateLimit-Reset
X-Status
X-Instance
X-Proxy-Cache-Info
X-Region
X-User-Agent
Surrogate-Key
Countrycode
X-Real-IP
X-Cache-Age
X-Source
X-ServerID
X-NWS-UUID-VERIFY
Akamai-GRN
Amp-Access-Control-Allow-Source-Origin
Cross-Origin-Window-Policy
X-Sucuri-ID
X-WP-CF-Super-Cache-Active
X-Sucuri-Cache
X-Servername
OT-Force-Account-Verify
X-VC-Cache
From-Origin
X-RM-Cache-TTL
X-WebKit-CSP-Report-Only
X-Xrds-Location
Front
X-UA
Backend
X-Air-Pt
Upgrade-Insecure-Requests
X-Framework
X-INCAP-ABP
Refresh
X-Mode
X-Wormhole-Sdk
X-AB
X-Air-Hostname
X-Air-Source
X-Air-Trace-Id
X-Cache-Time
X-Akamai-Request-ID2
X-Content-Powered-By
X-DataDome
Xet-Cookie
X-URL
X-Handled-By
X-Nginx-Cache
X-Edge-Location
Frame-Options
X-HTML-Minification-Powered-By
Url
X-UPSTREAM-Address
X-JoinUs
Filters
X-Proxy-Build
X-Webstats-RespID
X-Xfnlog-Site
X-SaId
X-Rewrite-Enabled
X-Rn-Rsrv
X-Endurance-Cache-Level
X-Origin-TTL
Selected-Fe
Meta-Geo
X-Timing-Wait
X-B3-Traceid
X-Origin-CC
X-Vcache
X-RCS-CacheZone
ServedBy
Accept-Language
Atl-Traceid
X-Cache-Rule
X-Cluster
X-Container-Uri
X-Drupal-Cache-Tags
WPO-Cache-Message
WPO-Cache-Status
X-AWS-Id
Cache
X-Cache-Operation
X-Akamai-Edgescape
X-Git-Commit
X-Reqid
Access-Control-Request-Headers
X-LJ-Flow-ID
X-Provided-By
X-Labrador-Cache-Channel
X-Tumblr-Pixel-2
X-Served-From
X-Logging-Id
Webserver
X-PHP-Host
X-Origin
X-Origin-Date
X-No-Session
X-VWS-Id
X-Scope-Id
Webcakes-App-Version
X-Origin-Hint
Webcakes-Region
X-Adobe-Source
X-Buckets
X-Routing-Service
X-Accel-Version
X-Web-Node
X-VHOST
TWC-Privacy
TDXMobile
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
X-Redis-Cache
X-R9-Blue-Green-Version
Mn-Server-Ip
Property-Id
Section-Io-Id
Cache-Hits
Thinkindot-Control
X-Zipkin-Id
TWC-Locale-Group
Web-Mar-Node
X-Proxied
TWC-GeoIP-LatLong
TWC-Connection-Speed
TWC-Device-Class
TWC-GeoIP-Country
Webcakes-App-Name
X-Azure-Ref-OriginShield
X-Fetched-On
X-Hosted-By
X-Drupal-Cache-Contexts
X-CMSURLCustom
X-Cms-Context
X-Extlb
X-VC
X-Site-Version
X-Cloudmap
X-VCT
X-Shield-Cache-Expires
X-Cache-Debug
X-Tb
X-Thinkindot-L3
X-Is-Mobile
X-Is-Supported-Browser
X-Tcp-Rtt
X-Is-Tablet
X-IPLB-Instance
X-Frame-Option
X-Format
X-ProxyCache-Status
X-Geo-Region
X-ProxyCache-Key
X-IPLB-Request-ID
X-Lambda-Id
X-Httpd
X-Is-Desktop
X-Loop
X-SayCDN-TTL
X-BYPASS-REASON
X-Browser-Name
X-Upstream-Ht
X-Ms-Version
X-Soup
X-Varnish-Cache-Hits
X-Ms-Request-Id
X-Say-TTL
X-Forwarded-Host
X-Locale
X-Skip-Cache
X-Restarts
X-Upstream-Ct
X-Say-Cacheable
X-S
X-Tncms
Apigw-Requestid
X-CDN-Forward
X-GeoCountry
X-Cache-Status-Check
X-GeoCode
X-SRV
X-Detected-As
X-Director
X-ShardId
X-ShopId
X-Varnish-Age
X-Varnish-Beresp-Grace
X-Storefront-Renderer-Rendered
X-Sorting-Hat-ShopId
X-Shopify-Stage
X-Sorting-Hat-PodId
X-Alternate-Cache-Key
Xserver
X-Cache-Host
X-Generation-Time
X-Cdn-Origin
X-Generated-By
X-Optimistic-Header
X-Lagoon
X-TA-CDN-Provider
X-RID
X-Worker
X-Rocket-Nginx-Serving-Static
X-Ratelimit-Reset
LB
X-Vercel-Cache
X-Vercel-Id
Source
X-Request-URI
Node
X-WP-CF-Super-Cache-Cookies-Bypass
X-XRDS-Location
Azure-SlotName
Azure-SiteName
Azure-Version
Azure-InstanceId
Fastcgi-Useragent
Protected
Azure-RegionName
X-Pass-Why
CDN-PullZone
CDN-RequestPullCode
CDN-RequestCountryCode
CDN-EdgeStorageId
CDN-CachedAt
CDN-Uid
CDN-Cache
CDN-RequestPullSuccess
Expiry
X-Connection-Hash
X-App-Version
Cross-Origin-Embedder-Policy
X-Fastcgi-Cache
X-GEO
Onion-Location
X-Tumblr-Pixel-3
X-Vcl-Version
X-Erf-Stays-Pdp-Viaduct-Migration-Web-V2
X-Cache-Expired-At
Alternate-Protocol
X-Api-Version
X-Tec-Api-Root
X-Tec-Api-Origin
X-Tec-Api-Version
CDN-RequestId
X-Cache-Server
DB-Nickname
X-PHP-Backend
Environment
Priority
X-Server-W
X-Jobs
AMP-Access-Control-Allow-Source-Origin
Uber-Trace-Id
CF-IPCountry
X-Proxy-Cache-Status
X-Fastly-Request-Id
X-DC
X-Cache-Action
Sid
X-Cluster-Node
X-Urbn-Site-Id
X-Urbn-Context-Path
Locale
X-LSADC-Cache
Cdn-Requestid
User-Cache-Control
X-Tt-Logid
X-ID
X-MP-GENERATED-AT
X-Mg-Request-UUID
X-Tx-Id
X-Ismobilevalue
HostName
X-Ig-Origin-Region
X-Esi-Check
X-Hnp-Log
Candidate-Md5Url
A
X-Generated-On
X-Epic-Correlation-Id
X-Gen-Mode
X-Forwarded-Site
X-FB-TRIP-ID
X-GeoIP-City
Cache-Tv-Group
X-Gzip
Gannett-Cam-Experience-Id
Rendered-Blocks
X-Bc-Bl
Req-ID
X-Aed
Server-Host
Origin-Agent-Cluster
Origin
Ngx.Var.Host
X-Bl-Debug
X-Bip
X-BCube-Filmed-By
Sslversion
Surrogated-Key
Wxu-Next-Region
X-A
Vix-Hermes-Req-Id
Wxu-Next-Hostname
Wxu-Next-Commit
X-A-Ccd
X-A-Dam
T-Server
X-A-Wwc
X-A-Dgt
X-A-Dcw
X-Block-Status
X-Cache-Id
X-Developer
Edge-Cache
Fusion-Component-Id
Fusion-Content-Id
Fusion-Content-Source
X-Device-Os
DCR-Processing-Time-Ms
X-Ec-Fail
Content-Secure-Policy
X-Dispatcher-Server
DCR-Decision-By
Fusion-Deployment-Id
Fusion-Source
Magicmarker
Lang
X-Cache-NE
MD5-Digest
Meta-Geo-Continent
X-Clientip
X-Conf
Fusion-Template-Id
X-Jungle-Id
X-D
X-Content-Age
X-Ec-GeoHdr
X-Level-Front-Cache
X-Powered-By-VTEX-Cache
X-ScT
X-ND-Cache
X-NCache
X-SB
X-SRCache-Key
X-Origin-Expires
X-Varnish-Beresp-Ttl
X-Response-Served-From
X-Op-Id-All
X-Node-Id
X-Varnish-Hostname
X-Org
X-Rojux
X-Thanos
X-VTEX-Cache-Time
X-Vdms-Path
X-UA-Device-Type
X-Vtex-Remote-Cache
X-VTEX-Cache-Server
X-Viewer-Country
X-Original-Request-Id
X-Vdms-Version
X-Request-Start
X-TIM-N
X-Client-Ip
X-Origin-Response-Time
X-Zone
X-Uri
X-Cache-Info
X-Test
NM-Fastcgi-Cache
X-Cache-Bucket
X-CUA
X-Request-Time
Yak-Timeinfo
Fastly-SSL
X-Debug-Cache-Fetch
X-Scheme
X-Core-Value
X-Cdn-Srv
Host-ID
X-SD-PageType
X-Cache-TTL-Remaining
Powered-By
Server-Hostname
X-Varnishpool
Server-Ext
X-VarnishDD-TTL
Sever-Int
Ssr
XM
X-WA-Info
X-Via-Fastly
X-VG-WebCache
X-AK-Request-ID
X-Amz-Storage-Class
PFcat
Origin-EX
Origin-CC
X-Var-Ttl
X-Backend-Instance
Fastly-Backend-Name
X-Varnish-Director
Release
X-App-Name
X-Auth-Group-Type
X-V-Cache
X-Req
AKAMAI
X-FC-Vary-Parameters
X-Fmm-Version
X-Ig-Push-State
X-Nyt-Route
X-Debug-Cache-Store
C-Via
CDCHOST
Cdn-Host
X-PAYTM-SRV-ID
X-Origin-Time
Cache-Provider
X-Nf-Request-Id
X-Gdpr
X-GeoIP-Region-Code
X-GeoIP-Country-Code
X-HN
X-Loc
X-HS-Content-Campaign-Id
X-Mvc-Supplant-Cachable
X-GeoIP
X-Service
X-NMSegId
X-Nginx-Cache-Key
X-Geo-Header
Cdn-Request-Time
X-Fastly-Cache
DSUID
X-Edge-Server
Cdncip
X-Pubstack
X-RateLimit-Limit-Second
X-Policy
Content-Script-Type
X-RateLimit-Remaining-Second
Content-Style-Type
X-Platform
X-Proto
X-Region-Sid
Cdnsip
X-TT-LOGID
X-Mvc-Supplant-OutputCached
X-Mly-Id
X-Micro-Cache
X-Ad-Load-Variation
X-Request-Host
X-Location
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-Human
X-Men
Web-Mar-Region
X-Acquia-Purge-Cdn-Unconfigured
X-Access
X-Proxied-Request
X-VG-TLSProxy
Odigeo-Trace-Id
X-Varnish-Beresp-Status
X-CGP
X-Server-IP
X-Fastly-Backend
X-Sn-Servicetimems
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-Eu-Site
X-Section
X-BBC-Edge-Cache-Status
X-Ec-Custom-Error
X-Csrf-Jwt
X-DPWN-IS-SECURE
X-Pool
X-From
X-Tb-Optimization-Total-Bytes-Saved
X-B3-Trace-ID
X-Auto-Login
X-Aicache-OS
We-Hiring
Pramga
Platform
Click-Count-Action-Start
Canary
Producers
Redirect-Candidate
L5d-Success-Class
Cache-Key
Click-Count-Error
Country-Code
Mail-Subject
Machine
L
Is-Eu
HA-Ipaddr
Esi-Enabled
Fastly-GeoIP-CountryCode
Ha-Gx-Prefs
Apple-News-Services-Request-Url
X-LiteSpeed-Cache-Control
True-Client-Country-4JS
Tube-Got-Results
WP-Super-Cache
Apple-News-Services-Parsed-Url
Tube-Got-Eval
Tube-Get-Contents
Tube-Return
V-Age
Apple-News-Services-Handled
Apple-News-Services-Host
W
Adler-Geo
X-ECache
Req-Svc-Chain
X-Slack-Shared-Secret-Outcome
X-Varnish-Authentication
X-Hash
X-GoCache-CacheStatus
X-We-Are-Hiring
X-NodeID
X-Up
Cluster
X-Custom-Header
X-Date
Gh-Request-Id
X-Contensis-Viewer-Groups
X-PERF
X-Cache-Backend
X-Cache-Aspx
X-Render-Time
X-Accel-Expires-Debug
On-Server
NGX
RNT-Machine
X-CacheTTL
Proxy-Firewall
X-ApacheServer
X-Slack-Backend
RNT-Time
X-AIR-PT
X-Newrelic-Synthetics
Debug
X-NGINX-Cache
X-Varnish-Hits
X-LB-ID
X-Cs
Fastly-Drupal-HTML
X-COUNTRY
X-DefHash
X-DefElseHash
X-Varnish-CookieHashed-On
X-Dc
X-Varnish-Remaining-TTL
X-Nananana
X-Varnish-CookieINHashed-On
Mime-Version
X-Pad
SID
X-Via-Poph
X-Via-Popv
X-Via-Popn
Pics-Label
CloudFront-Viewer-Country
X-HA-Backend
Datacenter
X-CACHE-GROUP
X-Servedbyhost
X-Depends
X-Refresh
Locid
X-Akamai-Transformed
X-CACHE-AGE
X-VC-TTL
X-Cache-FS-Status
X-Amz-Meta-Cb-Modifiedtime
GeoIP-Latitude
X-Platform-Cluster
X-Platform-Processor
X-Platform-Router
X-TIME
X-LB-NoCache
X-Datadome
X-Parent-Response-Time
X-M-Log
X-M-Reqid
Ngx-Var-Key
X-Old-Content-Length
X-B3-Parentspanid
X-HITS
X-Litespeed-Tag
X-Cached-By
X-LiteSpeed-Tag
Resin-Trace
X-CS
Server-ID
Server-Info
X-DynaTrace-JS-Agent
Cdn
BehaviorPad-Version
X-Moov-Xdn-Version
X-CDN-Cache-Status
X-Moov-T
X-Nc
X-TH-Server
X-Wa
Cf-Ipcountry
Fastly-Drupal-Html
Cross-Origin-Embedder-Policy-Report-Only
GeoIp-Country-Code
X-Presslabs-Stats
X-Vgn-Hpd-Reason
X-IAuth-Set-Uid
X-VCache
X-APP
NtCoent-Length
X-Fpc
X-Content-Length
X-User
X-Vc
FSS-Cache
X-S-Cookie
X-External-Request-Id
X-NewRelic-App-Data
X-ZONE
X-Destination
Cf-Device-Type
X-B-Cookie
X-Application
X-Srv
X-Esi
Uri
Serverhost
True-Client-IP
X-Zen-Fury
True-Client-Ip
X-HostName
X-TX-ID
CDN
X-Sigma-Backend
X-Cache-Date
X-Sigma
X-Varnish-Beresp-TTL
X-Instance-Name
X-Rocket-Build-Number
X-Dynatrace-Js-Agent
X-Is-Crawler
X-Flags
X-Providence-Cookie
X-Route-Name
X-Aspnet-Duration-Ms
Vc-Max-Age
X-API-Version
Load-Balancing
S-Rt
X-Dispatcher-Number
GeoIP-Country-Code
Tcn
X-VServer
X-Oracle-DMS-ECID
X-DynaTrace
X-Cdn-Cache-Status
X-Cdn-Forward
X-Branch-Name
X-HOST
X-RequestId
X-Segment-20210421
Srv
Hostname
Request-ID
X-WA
Product
X-NC
X-FPC
X-Dispatch
X-CACHE-KEY
Ohc-File-Size
X-Page-View
X-DataCenter
X-APP-VERSION
X-B3-Spanid
Server-Id
X-Ckpd-Fst-Backend
ServerName
Geoip-Latitude
Type
X-FL-QIT-DEBUG
X-Webkit-Csp-Report-Only
Srvid
X-Lb-Nocache
X-Bug-Bounty
X-Sql-Count
X-SERVER-NAME
X-Irp-Debug
X-Sql-Duration-Ms
X-VCL-Version
X-Http-Reason
X-Geo
CacheControlHeader
DataCenter
Cl-Cache
X-ServedByHost
X-Ua
Epwk-X-Cache
Origin-Trial
Ohc-Cache-HIT
X-App
Edge-Copy-Time
Cloudfront-Viewer-Country
IsBot
X-Via-SSL
X-SIPLIST1
X-Via-Edge
X-Owner
X-Via-CDN
X-Cache-Ttl
WZWS-RAY
Cross-Origin-Opener-Policy-Report-Only
X-Ha-Backend
X-Proxy-CacheRZ
X-Correlation-ID
XkeyRZ
X-Via-PopH
X-Core-Mission
PICS-Label
MIME-Version
X-Via-PopV
X-Via-PopN
X-Nf-Country
X-Nf-Language
X-Srcache-Store-Status
X-Nf-Ats-Version
Rtss
X-HubSpot-Correlation-Id
X-Srcache-Fetch-Status
ServerHost
X-MSEdge-Flight
X-Hit
X-MSEdge-Features
X-CSRF-TOKEN
X-Lb-Id
X-Vmg-Version
X-Akamai-Device-Characteristics
Cneonction
N-Cache
X-Qloud-Router
X-MiniProfiler-Ids
Lb
X-Amz-Meta-Opti
X-Sqd-Ctime
X-Acquia-Site
X-Datacenter
Sm-Log-Id
X-Service-Response-Time
X-Acquia-Purge-Tags
X-Acquia-Application-UUID
X-Acquia-Application-Trace
CountryCode
X-Sqd-Stime
X-Info
X-Web-Server
X-Gamma-Serve
Cmsid
Warning
User-Agent
X-Fastly-Country-Code
X-Limited
Cmstype
X-Litespeed-Cache-Control
Servername
X-LAGOON
X-IN-APIGATEWAYSSL
X-Dw-Trace-Id
X-IN-APIGATEWAY
X-Amz-Meta-S3b-Last-Modified
X-Check-Cacheable
Ngx
X-Snapshot-Date
X-Ramcache
X-Serial
X-Th-Server
X-RAMCache
X-Akamai-Pragma-Client-IP
X-Proxy-Cache-La3
X-Amz-Meta-Sha256
X-Requestid
Xkeylog
Xkey-La3
X-Udemy-Cache-App-Namespace