Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
CF-RAY
Expect-CT
Accept-Ranges
X-XSS-Protection
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Xss-Protection
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-Download-Options
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Request-Id
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
Content-Security-Policy-Report-Only
Accept-CH
X-DNS-Prefetch-Control
X-Runtime
Accept-CH-Lifetime
X-AspNet-Version
X-Check
X-Drupal-Cache
X-Generator
X-Ua-Compatible
X-Cache-Status
Server-Timing
X-Cacheable
X-Request-ID
Timing-Allow-Origin
X-Envoy-Upstream-Service-Time
X-FRAME-OPTIONS
X-Iinfo
X-Drupal-Dynamic-Cache
X-Content-Security-Policy
Feature-Policy
Access-Control-Expose-Headers
Content-Encoding
X-CDN
Upgrade
Status
X-AspNetMvc-Version
CF-Ray
Access-Control-Max-Age
X-Amz-Request-Id
Cf-Edge-Cache
X-Amz-Id-2
X-Via
Host-Header
Permissions-Policy
EagleId
Keep-Alive
Request-Context
X-Cache-Group
X-Robots-Tag
X-Backend
X-UA-Device
X-AH-Environment
X-Hacker
X-Proxy-Cache
X-Server
X-Turbo-Charged-By
X-Rq
X-Age
X-Ws-Request-Id
X-Vhost
Cf-Apo-Via
X-Amz-Version-Id
Xkey
X-Dispatcher
X-Swift-SaveTime
X-Swift-CacheTime
Grace
X-Server-Powered-By
X-LiteSpeed-Cache
Ali-Swift-Global-Savetime
Allow
X-Varnish-Cache
P3p
X-OneAgent-JS-Injection
X-Page-Speed
X-Pingback
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Dns-Prefetch-Control
X-Device
X-Cache-Lookup
EagleEye-TraceId
X-WebKit-CSP
X-Host
X-Backend-Server
Cf-Railgun
X-Server-Id
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Response-Time
X-Readtime
Surrogate-Control
X-Akam-SW-Version
X-Ruxit-JS-Agent
X-HW
X-Node
Request-Id
X-Cloud-Trace-Context
Content-Location
X-Nginx-Cache-Status
X-Application-Context
X-Country
X-Nginx-Upstream-Cache-Status
Accept-Ch-Lifetime
X-Litespeed-Cache
X-NWS-LOG-UUID
X-Country-Code
X-ASPNET-VERSION
Service-Worker-Allowed
X-Content-Type
X-Url
X-Trace
Cache-Tag
X-Clacks-Overhead
X-Amz-Server-Side-Encryption
Rating
X-Times
X-Rack-Cache
X-Vname
X-PC
X-TtlSet
Cross-Origin-Opener-Policy
X-Mcache
X-Edge
X-Midtier
X-Browser-Type
X-Daa-Tunnel
Nginx-Cache
X-Server-Name
AR-ATIME
AR-PoweredBy
AR-Request-ID
AR-SID
X-Powered-By-Plesk
X-Cache-TTL
X-Cnection
X-FTR-Request-ID
Accept-Ch
X-Ac
X-ESI
X-GitHub-Request-Id
X-D2id
X-Element-Page-Cache
Edge-Control
X-Kinja-Revision
X-CST
X-Exp-Variant
X-Cdn-Fetch
X-GoogleNews-Bot
Verso
X-Kinja-Server
X-Kinja-Build
X-Kinja
X-Exp-Id
X-Webkit-Csp
X-MS-InvokeApp
AR-CACHE
X-Ser
X-Vcap-Request-Id
X-Abt-Application-Version
X-Dw-Request-Base-Id
X-Upstream
X-Navigation-Version
X-FastCGI-Cache
X-B3-TraceId
Fastly-Restarts
X-ECACHE
X-Oneagent-Js-Injection
SPIisLatency
SPRequestDuration
X-Mod-Pagespeed
X-Amz-Rid
X-Server-Lifecycle-Phase
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Instrumentation
X-Kraken-Loop-Name
X-PDP-UNCACHING-HASH
X-SharePointHealthScore
X-Client-IP
SPRequestGuid
X-ARC
X-Goog-Hash
X-Kinsta-Cache
X-Edge-Location-Klb
X-Sol
X-Middleton-Display
Display
Pagespeed
X-Powered-CMS
X-Ratelimit-Limit
X-Mg-S
X-Amzn-Trace-Id
Edge-Cache-Tag
S
Cache-Status
X-Version
Access-Control-Request-Method
X-Middleton-Response
Response
X-VARITI-CCR
X-NF-Request-ID
RTSS
Realpath
X-Forwarded-For
X-Ratelimit-Remaining
X-Cache-Key
X-T
X-Content-Digest
Cross-Origin-Resource-Policy
X-Recruiting
X-ORACLE-DMS-RID
X-Cached
Fastcgi-Cache
X-Correlation-Id
X-Fastly-Request-ID
X-Ruxit-Js-Agent
X-MSEdge-Ref
X-TTL
X-Shield-Request-Id
X-TraceId
X-Varnish-TTL
Front-End-Https
MicrosoftSharePointTeamServices
X-Ua-Browser
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Request-Processing-Time
X-Forwarded-Proto
X-Request-Received
Arr-Disable-Session-Affinity
X-Frontend
Payment
TP-Cache
X-HS-Hub-Id
X-HS-Content-Id
X-LLID
X-HS-Cache-Config
X-Protected-By
Server-Node
Public-Key-Pins
X-RateLimit-Remaining
Count-Hit
MS-Author-Via
X-PressLabs-Stats
X-TEC-API-VERSION
Content-MD5
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-HS-Combine-CSS
X-Accel-Expires
X-GUploader-UploadID
X-LB-Cache
X-Distributor
X-Origin-Server
X-Server-ID
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Newrelic-App-Data
Surrogate-Key
X-Ezoic-Cdn
X-NODE
X-Ttl
X-Request-Handler-Origin-Region
X-Jurisdiction
X-Microsite
X-HP-Trace-Id
X-HP-Webp
X-FTR-Backend-Server
X-FTR-Backend
X-Country-Code-Real
X-FTR-Balancer
X-FTR-Cache-Status
X-Content-Security-Policy-Report-Only
X-Www-Served-By
X-AppVersion
X-App-Server
Host
Accept-Charset
X-Activity-Id
X-Varnish-Server
X-Az
X-ORACLE-DMS-ECID
Cache-Tags
X-Amz-Meta-S3cmd-Attrs
Cleartype
X-Cluster-Name
X-B3-TraceId-Primal
Mrf-Cache-Status
MRF-Tech
Retry-After
X-Varnish-Backend
X-FTR-Expires
X-Goog-Metageneration
Filterid
X-Unique-Id
X-Ua-Device
X-Debug
Server-Name
X-Git-Hash
Access-Control-Allow-Method
X-Hits
X-Logged-In
X-Load-Cache
X-Id
X-Aspnet-Version
X-NGENIX-Cache
X-Azure-Ref
X-Envoy-Decorator-Operation
X-Upgrade-Enabled
X-Geo-Country
X-FB-Debug
X-CSRF-Token
X-Hostname
X-Amz-Apigw-Id
TCN
X-Amzn-RequestId
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-B
TP-L2-Cache
X-TT
X-Proxy
Section-Io-Cache
X-Cache-Control
X-Revision
DC
X-Grace
Viewport
X-Seen-By
X-Request-Guid
X-B3-Sampled
X-Contextid
X-Fb-Rlafr
Healthy
X-Trace-Id
X-Type
X-Time
X-Goog-Generation
X-CCDN-Origin-Time
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Varnish-Ttl
X-F-Cache
X-Goog-Stored-Content-Length
X-Hcs-Proxy-Type
X-CCDN-CacheTTL
Fastly-SIE
Fastly-SWR
X-Mobile
X-N
Content-Disposition
X-XRDS-LOCATION
Paypal-Debug-Id
X-Ratelimit-Reset
Referer-Policy
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
Pinterest-Generated-By
X-Pinterest-Rid
X-Varnish-Grace
Pinterest-Version
X-Amz-Replication-Status
X-Oracle-Dms-Ecid
X-DIS-Request-ID
X-Magnolia-Registration
X-Origin-Cache
X-Nf-Request-Id
X-Via-JSL
X-Debug-Info
X-Page-Id
X-Webkit-CSP
X-Px
X-Wormhole-Sdk
Version
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
X-Datadog-Trace-Id
X-RemovedCookies
X-ProcessESI
X-G
X-UUID
X-Tumblr-User
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-App-Environment
X-Adobe-Loc
X-Content-Options
X-Whom
X-Debug-IsConnected
X-Debug-IsPreview
X-Rule
X-Node-Name
X-Tumblr-Pixel
X-Adobe-Content
X-Datadog-Sampled
X-Template
X-RTag
X-Ismobilevalue
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
MS-CV
Ms-Operation-Id
NGB
SD-X-WS
X-Storage
X-Hl-Ver
X-Yottaa-Metrics
X-Source
X-Yottaa-Optimizations
X-B-Cache
X-Instance
X-Backend-Name
Cross-Origin-Window-Policy
X-Cacheable-TTL
X-NYM-Debug-Backend
X-User-Agent
X-Region
X-Wix-Request-Id
X-Signature
X-Rendered-As
X-Proxy-Cache-Info
X-Device-Type
X-Is-Bot
GEO-INFO
X-FW-Serve
X-FW-Version
Country
X-L-Path
X-ServerID
X-FW-Type
X-FW-Static
X-FW-Dynamic
X-FW-Hash
X-FW-Server
X-Environment-Context
X-Status
X-Rid
Amp-Access-Control-Allow-Source-Origin
Charset
X-IPS-LoggedIn
X-NWS-UUID-VERIFY
X-RM-Cache-TTL
X-EdgeConnect-Cache-Status
Front
Akamai-GRN
ServerID
X-Real-IP
X-Cache-Age
Countrycode
X-Cache-Grace
X-Framework
X-WP-CF-Super-Cache-Active
SRV
Liferay-Portal
X-Amzn-Remapped-Content-Length
X-B3-SpanId
X-AB
X-Cache-Hit
X-WebKit-CSP-Report-Only
X-Language
X-Air-Pt
X-ECache
X-Akamai-Request-ID2
X-Content-Powered-By
X-Oracle-Dms-Rid
X-Api-Version
X-Air-Source
X-Air-Trace-Id
X-Air-Hostname
X-Servername
OT-Force-Account-Verify
X-Fastly-Request-Id
X-UA
Xet-Cookie
X-Sucuri-ID
X-DataDome
X-Sucuri-Cache
Accept-Language
X-VC-Cache
From-Origin
X-Mode
X-SRV
X-VC
Backend
Webserver
Refresh
Access-Control-Request-Headers
X-Cache-Status-Check
X-HTML-Minification-Powered-By
X-URL
X-Xrds-Location
LB
Upgrade-Insecure-Requests
X-Aws-Lambda-Call-Status
X-Handled-By
X-Tt-Logid
X-Cache-Time
X-Rn-Rsrv
X-RCS-CacheZone
X-Rewrite-Enabled
Meta-Geo
X-SaId
X-UPSTREAM-Address
X-Mg-Request-UUID
Filters
X-RID
X-JoinUs
X-Cms-Context
X-Adobe-Source
Webcakes-Region
X-Request-URI
TWC-Device-Class
X-S
TWC-Connection-Speed
Property-Id
X-Varnish-Age
X-Tumblr-Pixel-2
TWC-GeoIP-Country
TWC-GeoIP-LatLong
Webcakes-App-Version
Webcakes-App-Name
TWC-Privacy
TWC-Locale-Group
X-Container-Uri
X-Git-Commit
X-Labrador-Cache-Channel
X-R9-Blue-Green-Version
X-Hosted-By
X-Origin-Date
X-Origin-Hint
X-Provided-By
X-PHP-Host
X-Generated-By
X-Webstats-RespID
X-Lambda-Id
Section-Io-Id
X-ProxyCache-Status
X-Locale
ServedBy
X-Site-Version
X-Is-Supported-Browser
X-Skip-Cache
X-Is-Tablet
X-Logging-Id
X-Tb
X-Fetched-On
X-Served-From
Atl-Traceid
X-Scope-Id
X-Redis-Cache
X-Tcp-Rtt
X-Loop
X-ProxyCache-Key
X-No-Session
X-Is-Mobile
X-Vcl-Version
X-Accel-Version
X-Geo-Region
X-Reqid
X-Web-Node
X-Forwarded-Host
X-Akamai-Edgescape
X-Cache-Debug
X-BYPASS-REASON
X-Browser-Name
X-Httpd
X-Tncms
Cache
Web-Mar-Node
X-Xfnlog-Site
X-Is-Desktop
Url
X-Cluster
X-SayCDN-TTL
X-Director
X-Proxy-Build
X-Timing-Wait
X-Frame-Option
X-Detected-As
X-IPLB-Instance
Selected-Fe
X-Soup
X-IPLB-Request-ID
X-Origin
X-Optimistic-Header
X-Say-Cacheable
X-Upstream-Ht
X-Restarts
Mn-Server-Ip
X-Varnish-Cache-Hits
X-Varnish-Beresp-Grace
X-Shopify-Stage
X-Storefront-Renderer-Rendered
X-Say-TTL
X-Format
X-Alternate-Cache-Key
X-Cache-Host
X-Upstream-Ct
X-VCT
Apigw-Requestid
X-Routing-Service
X-RateLimit-Limit
X-Cache-Operation
X-LJ-Flow-ID
X-Zipkin-Id
X-AWS-Id
X-Extlb
X-VWS-Id
X-Cloudmap
Onion-Location
X-Cache-Rule
Xserver
X-Proxied
Expiry
X-Sorting-Hat-ShopId
X-ShopId
X-Ms-Version
X-Endurance-Cache-Level
X-Ms-Request-Id
X-Edge-Location
X-Connection-Hash
X-Sorting-Hat-PodId
X-ShardId
X-INCAP-ABP
X-Nginx-Cache
X-Lagoon
X-Vcache
Priority
Frame-Options
X-Cache-Expired-At
X-Azure-Ref-OriginShield
X-GeoCode
X-GeoCountry
X-WP-CF-Super-Cache-Cookies-Bypass
Source
X-CDN-Forward
Protected
Cdn-Requestid
Environment
WPO-Cache-Status
WPO-Cache-Message
X-Thinkindot-L3
X-Cache-Action
Thinkindot-Control
TDXMobile
Fastcgi-Useragent
X-Proxy-Cache-Status
Thinkindot-CacheControl
X-Generation-Time
X-Shield-Cache-Expires
X-CMSURLCustom
Thinkindot-CacheControl-Type
X-Drupal-Cache-Tags
X-XRDS-Location
X-Drupal-Cache-Contexts
X-Origin-TTL
CF-IPCountry
X-PHP-Backend
Uber-Trace-Id
X-Cdn-Origin
X-Origin-CC
X-Pass-Why
X-GEO
X-Urbn-Context-Path
X-Worker
X-Rocket-Nginx-Serving-Static
X-Urbn-Site-Id
X-Cluster-Node
Locale
X-App-Version
Azure-Version
Azure-RegionName
Azure-InstanceId
Azure-SiteName
X-ID
Sid
Azure-SlotName
Node
X-Buckets
X-Vercel-Cache
X-Vercel-Id
X-Aspnetmvc-Version
X-FB-TRIP-ID
Cache-Tv-Group
X-Auth-Group-Type
Cache-Hits
CDN-Cache
CDN-EdgeStorageId
CDN-PullZone
CDN-RequestCountryCode
CDN-RequestPullCode
CDN-Uid
CDN-CachedAt
CDN-RequestPullSuccess
X-Tumblr-Pixel-3
Cross-Origin-Embedder-Policy
AMP-Access-Control-Allow-Source-Origin
X-Server-W
X-Fastcgi-Cache
X-TA-CDN-Provider
Alternate-Protocol
X-HITS
X-NGINX-Cache
X-B3-Traceid
X-Pad
X-Cache-Server
DB-Nickname
X-A
A
X-D
X-Dispatcher-Server
X-Custom-Header
X-DefHash
Cdn-Request-Time
Candidate-Md5Url
X-DefElseHash
Cdn-Host
X-Developer
X-Edge-Server
X-Ig-Origin-Region
X-GeoIP-City
X-Ig-Push-State
X-Level-Front-Cache
X-Service
X-Generated-On
X-Fastly-Backend
X-Ec-GeoHdr
X-Ec-Fail
X-Core-Value
X-Epic-Correlation-Id
X-Esi-Check
X-LSADC-Cache
Content-Secure-Policy
Odigeo-Trace-Id
X-A-Dam
X-A-Ccd
X-A-Dcw
X-A-Dgt
X-A-Wwc
Ngx.Var.Host
Origin-Agent-Cluster
Wxu-Next-Region
Surrogated-Key
Sslversion
T-Server
Rendered-Blocks
Wxu-Next-Hostname
Wxu-Next-Commit
Meta-Geo-Continent
MD5-Digest
X-Cache-Id
DCR-Decision-By
X-Cache-NE
X-Cache-TTL-Remaining
X-Conf
X-ND-Cache
DCR-Processing-Time-Ms
X-Bl-Debug
Magicmarker
X-Aed
Lang
Gannett-Cam-Experience-Id
X-BCube-Filmed-By
X-Bc-Bl
X-Content-Age
X-Gzip
X-TIM-N
X-V-Cache
X-SRCache-Key
X-ScT
X-Req
X-Rojux
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-Viewer-Country
X-Vtex-Remote-Cache
X-Via-Fastly
X-Vdms-Version
X-Varnish-Remaining-TTL
X-Origin-Expires
X-LiteSpeed-Cache-Control
X-Op-Id-All
X-Org
X-Client-Ip
X-Tx-Id
Mime-Version
User-Cache-Control
X-DC
X-Varnish-Director
X-AK-Request-ID
X-Loc
X-Amz-Storage-Class
X-Varnish-Hostname
X-Aicache-OS
X-B3-Trace-ID
X-UA-Device-Type
X-Block-Status
X-Cache-Bucket
X-Cache-FS-Status
X-Bip
X-Node-Id
X-Men
X-Backend-Instance
X-NMSegId
X-App-Name
X-VG-TLSProxy
Tube-Got-Eval
Tube-Got-Results
Tube-Return
V-Age
Tube-Get-Contents
PFcat
X-VarnishDD-TTL
Ssr
X-NodeID
X-HN
Vix-Hermes-Req-Id
Fastly-SSL
X-Mly-Id
X-Micro-Cache
X-VG-WebCache
X-Nyt-Route
X-VTEX-Cache-Server
X-VTEX-Cache-Time
Cache-Provider
X-Wikidot-Static-Cache
X-Wikidot-Backend
X-Acquia-Purge-Cdn-Unconfigured
X-Cache-Info
X-PAYTM-SRV-ID
X-Fastly-Cache
X-FC-Vary-Parameters
X-Forwarded-Site
X-Platform
X-Policy
X-Pubstack
X-Proto
X-Powered-By-VTEX-Cache
X-Gdpr
X-Gen-Mode
X-GeoIP-Region-Code
X-GoCache-CacheStatus
Server-Host
X-HS-Content-Campaign-Id
X-GeoIP-Country-Code
X-Origin-Response-Time
X-Origin-Time
X-Geo-Header
X-GeoIP
X-RateLimit-Limit-Second
X-DPWN-IS-SECURE
X-CacheTTL
X-Clientip
X-Mvc-Supplant-Cachable
X-Sn-Servicetimems
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-Test
X-Hnp-Log
X-Tb-Optimization-Total-Bytes-Saved
X-Server-IP
X-SD-PageType
X-Request-Time
X-Region-Sid
X-RateLimit-Remaining-Second
X-Debug-Cache-Store
X-SB
X-Debug-Cache-Fetch
X-Jobs
X-Scheme
X-Thanos
X-Fmm-Version
Edge-Cache
Country-Code
Content-Style-Type
Fastly-Backend-Name
Host-ID
NM-Fastcgi-Cache
Is-Eu
Content-Script-Type
Click-Count-Error
AKAMAI
Adler-Geo
X-Dc
Cdncip
Click-Count-Action-Start
Cdnsip
Platform
Esi-Enabled
Req-ID
Powered-By
RNT-Time
RNT-Machine
Producers
X-Varnishpool
X-Date
Cache-Key
Canary
Sever-Int
X-CUA
Req-Svc-Chain
Yak-Timeinfo
XM
Release
X-Cdn-Srv
Cluster
C-Via
X-Contensis-Viewer-Groups
X-We-Are-Hiring
Server-Info
Server-Hostname
X-Pool
X-Proxied-Request
X-Request-Host
X-Nginx-Cache-Key
X-Mvc-Supplant-OutputCached
X-Human
X-Location
X-Request-Start
X-Slack-Backend
X-Varnish-Authentication
X-Varnish-Beresp-Status
Apple-News-Services-Handled
X-Var-Ttl
X-Ec-Custom-Error
X-Slack-Shared-Secret-Outcome
Server-Ext
X-Depends
Apple-News-Services-Host
Pramga
Machine
Mail-Subject
X-CGP
X-Access
True-Client-Country-4JS
W
X-Csrf-Jwt
NGX
Origin-CC
Origin-EX
We-Hiring
Origin
On-Server
X-Accel-Expires-Debug
X-Eu-Site
Web-Mar-Region
Gh-Request-Id
X-Section
HostName
X-Hash
Apple-News-Services-Request-Url
X-Cache-Aspx
Apple-News-Services-Parsed-Url
DSUID
L5d-Success-Class
Proxy-Firewall
L
X-Auto-Login
Fastly-GeoIP-CountryCode
HA-Ipaddr
X-BBC-Edge-Cache-Status
CDCHOST
Ha-Gx-Prefs
X-Varnish-Beresp-Ttl
Debug
BehaviorPad-Version
X-Cs
X-AIR-PT
Fusion-Component-Id
X-RateLimit-Reset
X-WA-Info
Fusion-Content-Id
X-Ad-Load-Variation
Fusion-Content-Source
Fusion-Template-Id
Fusion-Deployment-Id
Fusion-Source
X-Varnish-Hits
X-APP
X-Device-Os
Redirect-Candidate
X-Zone
X-CACHE-AGE
X-Newrelic-Synthetics
X-CLOUD-TRACE-CONTEXT
X-MP-GENERATED-AT
X-Via-Popn
X-Via-Poph
X-Via-Popv
X-LB-ID
X-HA-Backend
SID
X-Tec-Api-Origin
X-Tec-Api-Version
X-Tec-Api-Root
CDN-RequestId
X-Up
X-NCache
X-From
Fastly-Drupal-HTML
GeoIP-Latitude
Pics-Label
X-Content-Length
X-LiteSpeed-Tag
X-VHOST
X-Jungle-Id
CloudFront-Viewer-Country
X-B3-Parentspanid
X-Akamai-Transformed
X-Nananana
X-Servedbyhost
X-Refresh
X-Vdms-Path
X-Cache-Backend
X-CDN-Cache-Status
X-Litespeed-Tag
X-SERVER-NAME
Fastly-Drupal-Html
Vc-Max-Age
X-Parent-Response-Time
X-Origin-Cache-Key
X-Dispatcher-Number
X-Nc
X-LB-NoCache
WP-Super-Cache
X-Cached-By
X-Datadome
X-RequestId
X-CACHE-KEY
Product
X-ZONE
X-Uri
X-DynaTrace-JS-Agent
X-VC-TTL
X-PERF
Datacenter
X-M-Reqid
X-M-Log
GeoIp-Country-Code
X-ApacheServer
X-COUNTRY
Resin-Trace
X-Wa
Server-ID
X-Render-Time
X-CS
NtCoent-Length
X-Ckpd-Fst-Backend
Cdn
X-Amz-Meta-Cb-Modifiedtime
S-Rt
X-B3-Spanid
X-Bug-Bounty
X-Varnish-Beresp-TTL
X-NewRelic-App-Data
X-IAuth-Set-Uid
Uri
Locid
X-TX-ID
ServerName
True-Client-IP
FSS-Cache
X-Fpc
X-HubSpot-Correlation-Id
X-TT-LOGID
X-VCache
X-Esi
X-HostName
True-Client-Ip
Srv
X-Nf-Language
Serverhost
X-Nf-Country
X-Nf-Ats-Version
X-Dynatrace-Js-Agent
CDN
User-Agent
X-Old-Content-Length
X-Akamai-Device-Characteristics
X-Vmg-Version
X-Original-Request-Id
Tcn
X-Response-Served-From
X-FPC
X-Vc
ServerHost
X-TIME
X-Presslabs-Stats
X-Srv
X-Info
Ngx-Var-Key
GeoIP-Country-Code
X-WA
X-Gamma-Serve
X-Hit
Request-ID
X-Cdn-Forward
Xc-Version
X-Cdn-Cache-Status
CacheControlHeader
Server-Id
X-Vgn-Hpd-Reason
X-APP-VERSION
Cf-Ipcountry
Hostname
X-Moov-T
X-NC
X-Moov-Xdn-Version
Expect-Staple
X-TH-Server
Cneonction
X-FL-QIT-DEBUG
X-Platform-Cluster
X-Platform-Router
Srvid
X-Platform-Processor
X-Webkit-Csp-Report-Only
X-Dispatch
X-Amz-Meta-Opti
X-Lb-Nocache
X-V
Cf-Device-Type
Geoip-Latitude
X-Geo
X-ServedByHost
Cloudfront-Viewer-Country
Permission-Policy
X-Rollout
X-New
X-External-Request-Id
PICS-Label
X-User
X-Platform-Server
X-B-Cookie
X-Destination
X-S-Cookie
X-Application
X-Eligible
Cross-Origin-Embedder-Policy-Report-Only
N-Cache
WZWS-RAY
X-VCL-Version
X-Oracle-DMS-ECID
X-Limited
X-Proxy-CacheRZ
X-Via-PopV
Origin-Trial
X-Zen-Fury
X-Ha-Backend
X-Via-PopN
X-Via-PopH
XkeyRZ
X-Correlation-ID
X-Instance-Name
Epwk-X-Cache
X-Sigma-Backend
X-Cache-Date
X-Ua
X-Lb-Id
X-Internal-TTL
Ohc-File-Size
X-Akamai-Pragma-Client-IP
X-Ftr-Request-Id
X-Rocket-Build-Number
X-App
X-ElasticPress-Query
X-Sigma
Rtss
CountryCode
X-Via-Edge
X-Segment-20210421
Cl-Cache
X-Sqd-Stime
X-Sqd-Ctime
X-Branch-Name
X-MSEdge-Features
X-Via-CDN
X-MSEdge-Flight
X-Check-Cacheable
X-VTEX-Cache-Backend-Connect-Time
X-Serial
X-MiniProfiler-Ids
X-Litespeed-Cache-Control
X-VServer
X-Via-SSL
X-VTEX-Cache-Backend-Header-Time
X-Path
X-API-Version
Edge-Copy-Time
X-Wp-Cf-Super-Cache-Cache-Control
X-Wp-Cf-Super-Cache
Lb
X-Acquia-Application-Trace
X-Acquia-Application-UUID
X-Acquia-Purge-Tags
Cmstype
Sm-Log-Id
X-Service-Response-Time
X-Web-Server
X-Datacenter
Timeexpire
X-Acquia-Site
Cmsid
X-EC-Lua
X-SIPLIST1
IsBot
X-CSRF-TOKEN
X-CDN-Origin
X-LAGOON
Servername
X-Traceid
X-Ramcache
X-RAMCache
X-Snapshot-Date
X-Th-Server
Fl-Custom-Application
X-Fastly-Backend-Reqs
X-Sorting-Hat-Podid
X-Sorting-Hat-Shopid
X-IN-APIGATEWAY
X-Shopid
X-Shardid
X-IN-APIGATEWAYSSL
X-Origin-Upstream-Status
X-Dw-Trace-Id
Ohc-Cache-HIT
X-Amz-Meta-S3b-Last-Modified
Warning
X-Amz-Meta-Sha256
Wpo-Cache-Status
X-Udemy-Cache-App-Namespace
Wpo-Cache-Message
Ngx