Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
CF-RAY
Accept-Ranges
Expect-CT
X-XSS-Protection
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Xss-Protection
X-Cache-Hits
P3P
X-Served-By
X-UA-Compatible
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Request-Id
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
Accept-CH
X-AspNet-Version
Content-Security-Policy-Report-Only
X-Runtime
Accept-CH-Lifetime
X-Ua-Compatible
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Cache-Status
X-Generator
Server-Timing
X-Cacheable
X-Envoy-Upstream-Service-Time
Timing-Allow-Origin
X-Request-ID
X-FRAME-OPTIONS
X-Iinfo
X-Drupal-Dynamic-Cache
X-Content-Security-Policy
Access-Control-Expose-Headers
Feature-Policy
X-CDN
Content-Encoding
Status
X-AspNetMvc-Version
Upgrade
CF-Ray
Access-Control-Max-Age
X-Via
X-Amz-Request-Id
X-Amz-Id-2
Cf-Edge-Cache
Host-Header
EagleId
Keep-Alive
Request-Context
X-Backend
X-UA-Device
X-Cache-Group
X-AH-Environment
X-Robots-Tag
X-Server
X-Hacker
X-Dns-Prefetch-Control
X-Turbo-Charged-By
X-Proxy-Cache
X-Ws-Request-Id
Xkey
X-Rq
X-Age
Permissions-Policy
X-Vhost
X-Amz-Version-Id
Allow
X-Dispatcher
Cf-Apo-Via
X-Swift-SaveTime
X-Swift-CacheTime
X-Server-Powered-By
Grace
Ali-Swift-Global-Savetime
X-Varnish-Cache
P3p
X-LiteSpeed-Cache
X-Page-Speed
X-Pingback
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Cache-Lookup
X-Device
X-OneAgent-JS-Injection
Cf-Railgun
X-Backend-Server
X-Host
EagleEye-TraceId
X-Server-Id
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-WebKit-CSP
X-Response-Time
X-Readtime
X-Akam-SW-Version
Surrogate-Control
X-HW
Request-Id
X-Cloud-Trace-Context
X-Litespeed-Cache
X-Node
Content-Location
X-Application-Context
X-Ruxit-JS-Agent
X-Nginx-Cache-Status
X-Nginx-Upstream-Cache-Status
X-CST
X-NWS-LOG-UUID
Service-Worker-Allowed
X-Country-Code
X-Country
X-Url
X-Content-Type
X-Clacks-Overhead
Cache-Tag
X-Trace
X-Oneagent-Js-Injection
X-Webkit-Csp
Rating
X-Rack-Cache
X-Amz-Server-Side-Encryption
Nginx-Cache
X-Times
X-Server-Name
X-FTR-Request-ID
X-Vname
X-PC
X-TtlSet
X-Daa-Tunnel
Cross-Origin-Opener-Policy
X-Edge
X-Mcache
X-Midtier
X-Browser-Type
X-Powered-By-Plesk
X-Cnection
X-ESI
X-Upstream
Edge-Control
X-MS-InvokeApp
X-GitHub-Request-Id
X-D2id
X-Element-Page-Cache
X-Ac
Verso
X-Kinja
X-Kinja-Build
X-Kinja-Revision
X-GoogleNews-Bot
X-Exp-Variant
X-Exp-Id
X-Aws-Lambda-Call-Status
X-Cdn-Fetch
X-Kinja-Server
AR-PoweredBy
AR-ATIME
AR-Request-ID
AR-SID
X-ECACHE
Accept-Ch-Lifetime
X-FastCGI-Cache
X-Ser
X-Vcap-Request-Id
X-Navigation-Version
X-Abt-Application-Version
X-Cache-TTL
X-Mod-Pagespeed
SPIisLatency
SPRequestDuration
AR-CACHE
X-Ruxit-Js-Agent
X-NF-Request-ID
X-Dw-Request-Base-Id
X-SharePointHealthScore
SPRequestGuid
X-B3-TraceId
X-Amz-Rid
Fastly-Restarts
X-Client-IP
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Instrumentation
X-Middleton-Display
Display
Pagespeed
X-Sol
Edge-Cache-Tag
X-Mg-S
S
X-Cache-Key
X-Edge-Location-Klb
X-Kinsta-Cache
X-Powered-CMS
X-Amzn-Trace-Id
X-Middleton-Response
Response
Cache-Status
X-RateLimit-Remaining
X-VARITI-CCR
Access-Control-Request-Method
X-Version
X-Goog-Hash
X-ARC
RTSS
X-Content-Digest
X-Fastly-Request-ID
X-TraceId
X-Forwarded-For
X-Recruiting
Cross-Origin-Resource-Policy
X-T
Realpath
X-Pinterest-Rid
Pinterest-Generated-By
Pinterest-Version
X-Varnish-TTL
X-Correlation-Id
X-MSEdge-Ref
MS-Author-Via
Front-End-Https
X-Cached
Fastcgi-Cache
X-Ratelimit-Limit
X-Ttl
Content-MD5
X-HS-Cache-Config
X-HS-Hub-Id
X-HS-Content-Id
X-Ua-Browser
X-FTR-Balancer
X-Protected-By
Server-Node
Payment
X-Country-Code-Real
X-FTR-Cache-Status
X-FTR-Backend
X-FTR-Backend-Server
X-PDP-UNCACHING-HASH
Arr-Disable-Session-Affinity
X-Request-Received
X-Request-Processing-Time
MicrosoftSharePointTeamServices
Public-Key-Pins
X-Forwarded-Proto
X-LLID
X-HS-Combine-CSS
X-Frontend
X-SRCache-Fetch-Status
X-SRCache-Store-Status
TP-Cache
X-Origin-Cache-Key
X-Shield-Request-Id
X-Distributor
X-Accel-Expires
X-Kong-Upstream-Latency
X-Jurisdiction
X-Server-ID
X-FTR-Expires
X-Kong-Proxy-Latency
X-HP-Webp
X-HP-Trace-Id
Count-Hit
X-GUploader-UploadID
X-TTL
X-Origin-Server
X-LB-Cache
X-Ratelimit-Remaining
X-Ezoic-Cdn
X-ORACLE-DMS-RID
X-Hits
X-Request-Handler-Origin-Region
X-Microsite
X-Content-Security-Policy-Report-Only
X-AppVersion
X-Az
X-Activity-Id
X-Varnish-Backend
X-Www-Served-By
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Ua-Device
X-PressLabs-Stats
Host
X-Cluster-Name
X-TEC-API-VERSION
MRF-Tech
X-B3-TraceId-Primal
Mrf-Cache-Status
Retry-After
X-Varnish-Server
X-App-Server
Accept-Charset
Cache-Tags
X-Amz-Meta-S3cmd-Attrs
Server-Name
X-Hostname
X-Id
X-NGENIX-Cache
X-Geo-Country
Cleartype
X-NODE
X-Envoy-Decorator-Operation
X-DIS-Request-ID
Referer-Policy
X-Goog-Metageneration
X-Upgrade-Enabled
TP-L2-Cache
X-Seen-By
X-Newrelic-App-Data
X-Git-Hash
Access-Control-Allow-Method
X-Oracle-Dms-Ecid
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Azure-Ref
TCN
X-RateLimit-Limit
X-F-Cache
X-CCDN-CacheTTL
X-Hcs-Proxy-Type
X-Load-Cache
X-CCDN-Origin-Time
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Proxy
X-CSRF-Token
X-Unique-Id
X-ORACLE-DMS-ECID
X-Grace
Healthy
X-Debug-Info
X-Revision
X-Px
X-Cache-Control
Paypal-Debug-Id
X-Trace-Id
Section-Io-Cache
X-Request-Guid
Filterid
X-B3-Sampled
X-FB-Debug
X-B
X-Contextid
X-Page-Id
X-Fb-Rlafr
X-TT
DC
X-Oracle-Dms-Rid
X-Type
X-N
X-Logged-In
X-Mobile
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
Viewport
X-XRDS-LOCATION
X-Whom
X-Debug
X-Varnish-Ttl
X-Template
Charset
Fastly-SWR
Fastly-SIE
X-Language
X-Goog-Storage-Class
X-Goog-Generation
X-Time
X-Goog-Stored-Content-Encoding
X-Datadog-Parent-Id
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
X-Goog-Stored-Content-Length
X-Content-Options
X-Cache-Grace
X-Webkit-CSP
X-Via-JSL
Version
X-Wix-Request-Id
X-EdgeConnect-Cache-Status
X-RateLimit-Reset
X-Magnolia-Registration
Content-Disposition
X-App-Environment
X-Varnish-Grace
X-B-Cache
X-Signature
X-Node-Name
X-Origin-Cache
SRV
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-RemovedCookies
X-ProcessESI
X-Amzn-Remapped-Content-Length
X-Tumblr-Pixel-1
X-Debug-IsConnected
X-Yottaa-Metrics
X-Rule
X-Tumblr-Pixel-0
X-Yottaa-Optimizations
X-Debug-IsPreview
X-Tumblr-User
X-Tumblr-Pixel
X-Datadog-Sampled
X-RTag
Ms-Operation-Id
X-Backend-Name
X-Amz-Replication-Status
X-Hl-Ver
SD-X-WS
X-G
MS-CV
X-UUID
X-Device-Type
GEO-INFO
X-Adobe-Loc
X-Adobe-Content
ServerID
X-Instance
X-FW-Static
X-FW-Type
X-FW-Version
X-Proxy-Cache-Info
X-FW-Server
X-Storage
X-FW-Serve
X-FW-Dynamic
X-FW-Hash
X-User-Agent
X-NYM-Debug-Backend
X-Rendered-As
X-IPS-LoggedIn
NGB
X-Region
X-Is-Bot
Liferay-Portal
Country
X-B3-SpanId
X-Cacheable-TTL
X-Cache-Hit
X-Status
X-Environment-Context
X-L-Path
X-Real-IP
X-NWS-UUID-VERIFY
X-Rid
X-Source
Countrycode
X-ServerID
X-Cache-Age
Surrogate-Key
Akamai-GRN
X-Sucuri-ID
X-Sucuri-Cache
X-Servername
X-WP-CF-Super-Cache-Active
Amp-Access-Control-Allow-Source-Origin
OT-Force-Account-Verify
Cross-Origin-Window-Policy
X-Xrds-Location
X-VC-Cache
From-Origin
X-UA
X-WebKit-CSP-Report-Only
X-RM-Cache-TTL
Backend
Upgrade-Insecure-Requests
X-Framework
X-INCAP-ABP
Front
X-Mode
Refresh
X-Air-Pt
X-AB
Frame-Options
X-B3-Traceid
X-Buckets
X-HTML-Minification-Powered-By
X-DataDome
Xet-Cookie
X-Cache-Time
X-Air-Trace-Id
X-Content-Powered-By
X-Akamai-Request-ID2
X-Air-Source
X-Air-Hostname
X-RID
X-Edge-Location
X-Handled-By
Url
X-Endurance-Cache-Level
X-CDN-Forward
X-VC
X-Wormhole-Sdk
Webserver
X-JoinUs
X-Origin-TTL
X-Azure-Ref-OriginShield
X-RCS-CacheZone
X-Origin-Date
X-Timing-Wait
X-Xfnlog-Site
X-Reqid
X-LJ-Flow-ID
X-VWS-Id
Meta-Geo
Selected-Fe
Filters
X-Webstats-RespID
X-Cluster
X-UPSTREAM-Address
X-No-Session
X-AWS-Id
X-Rewrite-Enabled
X-Vcache
X-Proxy-Build
X-SaId
X-Origin-CC
X-Rn-Rsrv
X-Akamai-Edgescape
Atl-Traceid
X-Fetched-On
X-Cache-Rule
X-Logging-Id
X-VCT
X-PHP-Host
X-Generation-Time
X-Git-Commit
X-Cache-Operation
X-Labrador-Cache-Channel
X-Tumblr-Pixel-2
X-IPLB-Request-ID
X-R9-Blue-Green-Version
WPO-Cache-Message
Access-Control-Request-Headers
X-Drupal-Cache-Tags
X-Provided-By
X-IPLB-Instance
X-Container-Uri
WPO-Cache-Status
Mn-Server-Ip
X-Origin
TWC-GeoIP-LatLong
TWC-GeoIP-Country
TWC-Device-Class
X-Ms-Version
TWC-Connection-Speed
TWC-Locale-Group
TWC-Privacy
Webcakes-Region
X-Origin-Hint
Webcakes-App-Version
Webcakes-App-Name
X-Served-From
X-SRV
ServedBy
X-Ms-Request-Id
Property-Id
X-Cloudmap
X-Scope-Id
Web-Mar-Node
X-Shield-Cache-Expires
X-Web-Node
X-Tb
X-ProxyCache-Key
X-Httpd
X-BYPASS-REASON
X-Cache-Status-Check
X-Adobe-Source
X-Cache-Debug
X-Hosted-By
X-Extlb
X-Restarts
X-Locale
X-Drupal-Cache-Contexts
X-Zipkin-Id
X-Redis-Cache
Thinkindot-CacheControl
X-Proxied
Thinkindot-CacheControl-Type
X-Cms-Context
X-CMSURLCustom
Thinkindot-Control
X-Routing-Service
X-Accel-Version
Section-Io-Id
X-Site-Version
Cache
X-Varnish-Cache-Hits
X-ProxyCache-Status
X-Thinkindot-L3
TDXMobile
X-Director
X-Frame-Option
X-Format
X-Cdn-Origin
X-Forwarded-Host
X-Is-Tablet
X-Browser-Name
X-Varnish-Age
X-Lambda-Id
X-Tncms
X-Loop
X-Soup
X-Geo-Region
X-Tcp-Rtt
X-Upstream-Ht
X-Upstream-Ct
X-Say-TTL
X-Say-Cacheable
X-S
X-Is-Desktop
X-Is-Mobile
X-Is-Supported-Browser
X-SayCDN-TTL
Cache-Hits
X-Skip-Cache
X-Shopify-Stage
X-ShardId
X-Nginx-Cache
Xserver
X-ShopId
X-Alternate-Cache-Key
Apigw-Requestid
X-Erf-Stays-Pdp-Viaduct-Migration-Web-V2
X-Detected-As
X-GeoCountry
X-Storefront-Renderer-Rendered
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-GeoCode
Accept-Language
X-Cache-Host
X-Varnish-Beresp-Grace
X-Generated-By
X-Worker
X-Lagoon
X-Vercel-Id
X-Vercel-Cache
X-Rocket-Nginx-Serving-Static
X-Optimistic-Header
Azure-SlotName
Azure-InstanceId
Azure-Version
Azure-SiteName
Azure-RegionName
Node
Source
X-Fastly-Request-Id
CDN-RequestPullCode
CDN-Cache
X-Request-URI
CDN-RequestCountryCode
CDN-PullZone
CDN-CachedAt
CDN-EdgeStorageId
LB
CDN-Uid
X-WP-CF-Super-Cache-Cookies-Bypass
CDN-RequestPullSuccess
X-App-Version
CDN-RequestId
Protected
Cross-Origin-Embedder-Policy
Fastcgi-Useragent
X-Pass-Why
X-Vcl-Version
X-Tumblr-Pixel-3
Alternate-Protocol
Expiry
X-Connection-Hash
X-GEO
X-XRDS-Location
X-Tec-Api-Root
X-Tec-Api-Origin
X-Tec-Api-Version
X-Cache-Server
X-ECache
X-Ratelimit-Reset
X-Cache-Expired-At
X-COUNTRY
DB-Nickname
Onion-Location
AMP-Access-Control-Allow-Source-Origin
X-TA-CDN-Provider
X-Server-W
X-Jobs
Sid
CF-IPCountry
Environment
X-PHP-Backend
X-Original-Request-Id
X-Api-Version
X-Fastcgi-Cache
Uber-Trace-Id
Priority
X-Response-Served-From
X-LSADC-Cache
X-Proxy-Cache-Status
X-Cluster-Node
X-Uri
User-Cache-Control
X-TT-LOGID
X-Urbn-Site-Id
X-Cache-Action
Locale
X-Urbn-Context-Path
X-Mg-Request-UUID
X-Tx-Id
HostName
X-MP-GENERATED-AT
WP-Super-Cache
X-FB-TRIP-ID
X-Forwarded-Site
Wxu-Next-Hostname
X-Generated-On
Cache-Tv-Group
X-Gen-Mode
Wxu-Next-Commit
Fusion-Component-Id
X-Block-Status
X-BCube-Filmed-By
Fusion-Content-Id
Origin-Agent-Cluster
X-Bc-Bl
X-Bip
X-Bl-Debug
X-GeoIP-City
X-Cache-Id
Candidate-Md5Url
X-FC-Vary-Parameters
X-GeoIP
X-Epic-Correlation-Id
X-Device-Os
DCR-Processing-Time-Ms
DCR-Decision-By
X-Content-Age
X-Dispatcher-Server
A
X-Developer
X-A-Dcw
X-D
X-A-Dam
Edge-Cache
X-Ec-Fail
X-Conf
X-Cache-NE
X-Esi-Check
X-A
Content-Secure-Policy
X-Aed
X-A-Ccd
X-Clientip
X-Ec-GeoHdr
X-A-Dgt
X-A-Wwc
Wxu-Next-Region
X-NMSegId
X-SRCache-Key
Magicmarker
X-Test
X-DC
X-TIM-N
X-Thanos
X-ScT
X-LiteSpeed-Cache-Control
X-Request-Start
Server-Host
X-Gzip
X-Rojux
X-SB
X-UA-Device-Type
Req-ID
X-VTEX-Cache-Time
X-VTEX-Cache-Server
X-Vtex-Remote-Cache
Ngx.Var.Host
Origin
NM-Fastcgi-Cache
X-Viewer-Country
X-Vdms-Version
Meta-Geo-Continent
MD5-Digest
X-Varnish-Hostname
Rendered-Blocks
X-Vdms-Path
Sslversion
Lang
X-Mvc-Supplant-Cachable
Fusion-Source
Fusion-Template-Id
X-ND-Cache
Gannett-Cam-Experience-Id
X-Level-Front-Cache
X-Jungle-Id
Fusion-Content-Source
X-Hnp-Log
Fusion-Deployment-Id
X-Ig-Origin-Region
X-Node-Id
X-NCache
Surrogated-Key
X-Platform
X-Powered-By-VTEX-Cache
X-Proto
T-Server
Vix-Hermes-Req-Id
X-Origin-Expires
X-Org
X-Op-Id-All
X-URL
X-Origin-Response-Time
X-App-Name
Server-Hostname
X-AK-Request-ID
Origin-CC
Origin-EX
Ssr
X-ApacheServer
Powered-By
Sever-Int
X-Auth-Group-Type
We-Hiring
Release
W
Server-Ext
PFcat
X-GeoIP-Region-Code
X-Req
X-Render-Time
X-Request-Time
X-Scheme
X-SD-PageType
X-Region-Sid
X-RateLimit-Remaining-Second
X-Origin-Time
X-PAYTM-SRV-ID
X-PERF
X-RateLimit-Limit-Second
X-V-Cache
X-Var-Ttl
XM
Yak-Timeinfo
X-Policy
X-Pubstack
X-WA-Info
X-Via-Fastly
X-Varnish-Director
X-VarnishDD-TTL
X-Varnishpool
X-VG-WebCache
X-Nyt-Route
X-Nginx-Cache-Key
X-Csrf-Jwt
X-Core-Value
X-CUA
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-CGP
X-Cdn-Srv
X-Backend-Instance
X-Cache-Bucket
X-Cache-Info
X-Cache-TTL-Remaining
X-Edge-Server
X-Eu-Site
X-HN
X-HS-Content-Campaign-Id
X-Loc
X-Mvc-Supplant-OutputCached
X-GeoIP-Country-Code
X-Geo-Header
X-Fastly-Cache
X-Fmm-Version
X-From
X-Gdpr
X-Auto-Login
X-Amz-Storage-Class
Cache-Provider
Esi-Enabled
Cdn-Host
Cdn-Request-Time
Content-Style-Type
L5d-Success-Class
Canary
HA-Ipaddr
Ha-Gx-Prefs
Host-ID
DSUID
CDCHOST
AKAMAI
Cdncip
X-Varnish-Beresp-Ttl
X-NGINX-Cache
X-Zone
C-Via
Fastly-SSL
Mail-Subject
X-Tt-Logid
Cdnsip
Content-Script-Type
Fastly-Backend-Name
Cdn-Requestid
X-Newrelic-Synthetics
Cache-Key
X-Cache-Aspx
X-Wikidot-Backend
X-Wikidot-Static-Cache
Click-Count-Action-Start
X-BBC-Edge-Cache-Status
X-We-Are-Hiring
X-Cache-Backend
X-CacheTTL
X-Location
X-Human
Apple-News-Services-Handled
X-Fastly-Backend
X-Hash
X-Server-IP
X-Ec-Custom-Error
X-DPWN-IS-SECURE
X-Section
On-Server
X-GoCache-CacheStatus
X-Pool
X-Proxied-Request
X-Request-Host
X-Sn-Servicetimems
X-SVT-ORM-RULES
Click-Count-Error
X-Contensis-Viewer-Groups
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
X-Dc
X-Varnish-Authentication
X-SVT-ORM-VERSION
X-Tb-Optimization-Total-Bytes-Saved
X-Service
Adler-Geo
X-VG-TLSProxy
X-B3-Trace-ID
True-Client-Country-4JS
L
Machine
Tube-Get-Contents
Tube-Got-Eval
V-Age
Tube-Return
Tube-Got-Results
RNT-Time
RNT-Machine
Pramga
Platform
X-Men
Producers
Redirect-Candidate
X-Mly-Id
Req-Svc-Chain
X-Micro-Cache
Web-Mar-Region
Is-Eu
X-Ad-Load-Variation
X-Access
Country-Code
X-Aicache-OS
X-Varnish-Beresp-Status
Gh-Request-Id
Cluster
X-Ig-Push-State
X-Acquia-Purge-Cdn-Unconfigured
Fastly-GeoIP-CountryCode
X-AIR-PT
X-Accel-Expires-Debug
X-Slack-Backend
Proxy-Firewall
Odigeo-Trace-Id
X-Slack-Shared-Secret-Outcome
X-Date
X-Up
NGX
Datacenter
X-Varnish-Hits
X-NodeID
Debug
X-Custom-Header
X-Ismobilevalue
X-CACHE-GROUP
X-LB-ID
X-Akamai-Transformed
X-Cs
X-ID
X-Refresh
Locid
X-Nananana
X-Nf-Request-Id
Fastly-Drupal-HTML
X-Pad
X-DefHash
Pics-Label
CloudFront-Viewer-Country
X-DefElseHash
X-Varnish-CookieHashed-On
X-Platform-Processor
X-Amz-Meta-Cb-Modifiedtime
X-Client-Ip
X-Platform-Cluster
X-Varnish-Remaining-TTL
X-Varnish-CookieINHashed-On
X-Platform-Router
Mime-Version
SID
X-HA-Backend
X-Via-Popv
X-Via-Poph
X-Depends
X-VHOST
X-Via-Popn
X-Servedbyhost
X-LiteSpeed-Tag
X-M-Reqid
X-VC-TTL
X-M-Log
Ngx-Var-Key
X-Old-Content-Length
X-Cached-By
X-Datadome
X-CACHE-AGE
GeoIP-Latitude
X-Cache-FS-Status
X-Parent-Response-Time
X-LB-NoCache
X-TH-Server
X-CDN-Cache-Status
X-CS
X-Moov-Xdn-Version
X-B3-Parentspanid
X-Moov-T
Cross-Origin-Embedder-Policy-Report-Only
X-TIME
X-NewRelic-App-Data
Resin-Trace
GeoIp-Country-Code
Fastly-Drupal-Html
Cdn
Cf-Ipcountry
X-DynaTrace-JS-Agent
Server-ID
X-Wa
Server-Info
X-Nc
NtCoent-Length
X-Litespeed-Tag
X-Presslabs-Stats
X-Destination
BehaviorPad-Version
Uri
X-B-Cookie
X-Application
Cf-Device-Type
X-Vgn-Hpd-Reason
X-VCache
X-S-Cookie
X-User
X-External-Request-Id
X-HITS
X-APP
True-Client-IP
X-IAuth-Set-Uid
X-ZONE
X-Zen-Fury
FSS-Cache
X-Is-Crawler
X-Aspnet-Duration-Ms
X-Route-Name
X-Flags
X-Providence-Cookie
X-Sigma-Backend
X-Instance-Name
X-Esi
X-Cache-Date
X-Fpc
X-Rocket-Build-Number
X-Sigma
X-HostName
X-TX-ID
CDN
X-DynaTrace
X-API-Version
X-Dynatrace-Js-Agent
X-VServer
X-Srv
X-Content-Length
X-Vc
X-Varnish-Beresp-TTL
True-Client-Ip
Load-Balancing
X-Branch-Name
Tcn
X-Segment-20210421
X-Oracle-DMS-ECID
X-Page-View
Serverhost
GeoIP-Country-Code
Srv
X-HOST
X-B3-Spanid
S-Rt
Hostname
X-FPC
Request-ID
Ohc-File-Size
X-Dispatcher-Number
X-Cdn-Cache-Status
X-DataCenter
X-Dispatch
X-NC
X-WA
X-Cdn-Forward
X-RequestId
Product
Vc-Max-Age
Type
X-APP-VERSION
X-Sql-Duration-Ms
X-Http-Reason
X-CSRF-TOKEN
X-Sql-Count
X-FL-QIT-DEBUG
Srvid
X-Irp-Debug
Geoip-Latitude
Server-Id
X-Webkit-Csp-Report-Only
ServerName
X-Lb-Nocache
Cl-Cache
X-Geo
IsBot
X-Via-CDN
X-Via-Edge
X-Via-SSL
X-Bug-Bounty
Edge-Copy-Time
X-Owner
X-ServedByHost
X-SIPLIST1
DataCenter
X-Ckpd-Fst-Backend
WZWS-RAY
X-VCL-Version
Epwk-X-Cache
Cloudfront-Viewer-Country
X-Core-Mission
XkeyRZ
Ohc-Cache-HIT
X-Proxy-CacheRZ
Origin-Trial
CacheControlHeader
MIME-Version
X-Ha-Backend
Cross-Origin-Opener-Policy-Report-Only
X-Via-PopN
X-Via-PopH
X-Via-PopV
X-Cache-Ttl
X-Hit
PICS-Label
X-App
CountryCode
X-Qloud-Router
N-Cache
X-Correlation-ID
ServerHost
X-Ua
X-Lb-Id
X-Srcache-Store-Status
Rtss
X-Srcache-Fetch-Status
X-Amz-Meta-Opti
X-MSEdge-Flight
X-MSEdge-Features
X-Fastly-Country-Code
X-MiniProfiler-Ids
Lb
X-Acquia-Application-UUID
X-Sqd-Stime
X-Service-Response-Time
X-Acquia-Purge-Tags
Sm-Log-Id
X-Acquia-Application-Trace
X-Sqd-Ctime
X-Acquia-Site
X-Datacenter
Warning
X-Web-Server
X-LAGOON
X-Dw-Trace-Id
Xkeylog
Expect-Staple
X-Udemy-Cache-App-Namespace
X-Cdn-Request-ID
X-Cache-Type
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
X-Limited
X-Litespeed-Cache-Control
X-Vmg-Version
X-Akamai-Device-Characteristics
User-Agent
Xkey-La3
X-Proxy-Cache-La3
Cneonction
X-Amz-Meta-Sha256
X-CF-Lambda-Fn
Ngx
X-RAMCache
X-Orig-Expires
X-Check-Cacheable
X-Snapshot-Date
X-Th-Server
X-Ramcache
X-Akamai-Pragma-Client-IP
X-Forwarded-Path
X-CF-Lambda-Version
X-Serial
Akamai-Cache-Status
X-Tenant
X-Requestid
X-Shop-Environment
X-Amz-Meta-S3b-Last-Modified