Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
CF-RAY
Expect-CT
Accept-Ranges
X-XSS-Protection
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-Xss-Protection
X-UA-Compatible
X-Served-By
X-Download-Options
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Request-Id
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
Content-Security-Policy-Report-Only
X-DNS-Prefetch-Control
Accept-CH
X-Runtime
Accept-CH-Lifetime
X-AspNet-Version
X-Drupal-Cache
X-Check
X-Cache-Status
X-Generator
Server-Timing
X-Request-ID
X-Cacheable
X-Ua-Compatible
Timing-Allow-Origin
X-Envoy-Upstream-Service-Time
X-FRAME-OPTIONS
X-Iinfo
X-Drupal-Dynamic-Cache
X-Content-Security-Policy
Feature-Policy
Access-Control-Expose-Headers
Content-Encoding
X-CDN
Status
Upgrade
X-AspNetMvc-Version
CF-Ray
Access-Control-Max-Age
X-Amz-Request-Id
X-Amz-Id-2
Cf-Edge-Cache
X-Via
Host-Header
EagleId
Permissions-Policy
Keep-Alive
Request-Context
X-Cache-Group
X-Backend
X-Robots-Tag
X-UA-Device
X-AH-Environment
X-Hacker
X-Server
X-Proxy-Cache
X-Turbo-Charged-By
X-Rq
Xkey
X-Age
X-Ws-Request-Id
X-Vhost
X-Amz-Version-Id
Cf-Apo-Via
X-Dispatcher
X-Swift-SaveTime
X-Swift-CacheTime
X-Server-Powered-By
X-LiteSpeed-Cache
Grace
Allow
Ali-Swift-Global-Savetime
X-Varnish-Cache
P3p
X-OneAgent-JS-Injection
X-Page-Speed
X-Pingback
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Cache-Lookup
X-Device
X-WebKit-CSP
EagleEye-TraceId
X-Host
Cf-Railgun
X-Backend-Server
X-Server-Id
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Dns-Prefetch-Control
X-Response-Time
X-Readtime
X-Ruxit-JS-Agent
Surrogate-Control
X-Akam-SW-Version
X-HW
Request-Id
X-Node
X-Cloud-Trace-Context
Content-Location
X-Country
X-Nginx-Cache-Status
X-Application-Context
X-Nginx-Upstream-Cache-Status
Accept-Ch-Lifetime
X-NWS-LOG-UUID
X-ASPNET-VERSION
X-Country-Code
Service-Worker-Allowed
X-Content-Type
X-Trace
X-Url
X-Litespeed-Cache
Cache-Tag
X-Clacks-Overhead
Rating
X-Amz-Server-Side-Encryption
X-Rack-Cache
X-Times
X-Vname
X-PC
X-TtlSet
X-FTR-Request-ID
Cross-Origin-Opener-Policy
X-Daa-Tunnel
X-Edge
X-Mcache
X-Midtier
X-Browser-Type
X-Server-Name
Nginx-Cache
X-CST
Accept-Ch
X-Powered-By-Plesk
AR-SID
AR-ATIME
AR-PoweredBy
AR-Request-ID
X-Cnection
X-Cache-TTL
X-ESI
X-Ac
X-D2id
X-Element-Page-Cache
X-GitHub-Request-Id
Edge-Control
X-Exp-Id
X-Kinja
X-Exp-Variant
X-GoogleNews-Bot
X-Kinja-Revision
X-Cdn-Fetch
X-Kinja-Build
X-Kinja-Server
Verso
X-MS-InvokeApp
X-ECACHE
AR-CACHE
X-Ser
X-Vcap-Request-Id
X-Upstream
X-Abt-Application-Version
X-FastCGI-Cache
X-Navigation-Version
X-B3-TraceId
X-Dw-Request-Base-Id
X-Webkit-Csp
SPRequestDuration
SPIisLatency
Fastly-Restarts
X-Mod-Pagespeed
X-Amz-Rid
SPRequestGuid
X-SharePointHealthScore
X-Server-Lifecycle-Phase
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Instrumentation
X-Kraken-Loop-Name
X-Client-IP
X-PDP-UNCACHING-HASH
X-Edge-Location-Klb
X-Kinsta-Cache
X-ARC
X-Goog-Hash
X-Oneagent-Js-Injection
X-Ratelimit-Limit
X-Mg-S
X-Powered-CMS
Display
Pagespeed
X-Sol
X-Middleton-Display
Edge-Cache-Tag
S
X-NF-Request-ID
X-Amzn-Trace-Id
Cache-Status
X-Version
Access-Control-Request-Method
X-VARITI-CCR
X-Middleton-Response
Response
RTSS
Realpath
X-Forwarded-For
X-Content-Digest
X-T
X-TraceId
X-Cache-Key
X-Fastly-Request-ID
Cross-Origin-Resource-Policy
X-Varnish-TTL
X-Ratelimit-Remaining
X-TTL
X-Recruiting
X-Correlation-Id
Fastcgi-Cache
X-Cached
X-ORACLE-DMS-RID
X-MSEdge-Ref
X-Shield-Request-Id
X-RateLimit-Remaining
Front-End-Https
MicrosoftSharePointTeamServices
X-HS-Content-Id
X-HS-Hub-Id
Content-MD5
X-HS-Cache-Config
X-Ua-Browser
X-Ruxit-Js-Agent
X-Forwarded-Proto
X-Request-Processing-Time
X-Request-Received
MS-Author-Via
X-Protected-By
X-LLID
Payment
X-Frontend
Server-Node
TP-Cache
X-PressLabs-Stats
Arr-Disable-Session-Affinity
Public-Key-Pins
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-FTR-Backend-Server
X-Country-Code-Real
X-FTR-Balancer
X-FTR-Backend
X-FTR-Cache-Status
Count-Hit
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-HS-Combine-CSS
X-TEC-API-VERSION
X-Server-ID
X-Accel-Expires
X-GUploader-UploadID
X-Distributor
X-Kong-Proxy-Latency
X-LB-Cache
X-Kong-Upstream-Latency
X-Origin-Server
X-NODE
X-FTR-Expires
X-Jurisdiction
X-HP-Webp
X-Ezoic-Cdn
X-HP-Trace-Id
X-Newrelic-App-Data
X-Request-Handler-Origin-Region
X-Microsite
X-Az
X-Activity-Id
X-AppVersion
X-Varnish-Server
X-Www-Served-By
X-Content-Security-Policy-Report-Only
MRF-Tech
Mrf-Cache-Status
Host
X-Cluster-Name
X-B3-TraceId-Primal
X-App-Server
Accept-Charset
X-Varnish-Backend
X-Ua-Device
Cache-Tags
X-Amz-Meta-S3cmd-Attrs
Retry-After
Cleartype
X-ORACLE-DMS-ECID
X-Ttl
X-Goog-Metageneration
Server-Name
Filterid
X-Unique-Id
X-Hits
Surrogate-Key
X-Git-Hash
Access-Control-Allow-Method
X-Debug
X-Envoy-Decorator-Operation
X-Azure-Ref
X-Logged-In
X-CSRF-Token
X-Upgrade-Enabled
X-NGENIX-Cache
X-Load-Cache
X-Id
X-Geo-Country
X-Hostname
X-FB-Debug
X-Tt-Trace-Host
TCN
X-Tt-Trace-Tag
X-Proxy
TP-L2-Cache
X-Pinterest-Rid
Pinterest-Version
X-Amz-Apigw-Id
Pinterest-Generated-By
X-Amzn-RequestId
X-B
X-Time
Section-Io-Cache
X-B3-Sampled
X-TT
X-Seen-By
X-Grace
X-Cache-Control
X-Trace-Id
X-Revision
X-Hcs-Proxy-Type
X-CCDN-CacheTTL
X-Request-Guid
X-CCDN-Origin-Time
DC
Healthy
X-Contextid
X-F-Cache
X-Fb-Rlafr
Viewport
X-Type
Referer-Policy
X-XRDS-LOCATION
X-Mobile
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-N
Fastly-SIE
Fastly-SWR
Paypal-Debug-Id
X-DIS-Request-ID
Content-Disposition
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
X-Page-Id
X-Debug-Info
X-Varnish-Grace
X-Webkit-CSP
X-Px
X-Origin-Cache
X-Via-JSL
X-Magnolia-Registration
X-Aws-Lambda-Call-Status
Version
X-Amz-Replication-Status
X-Whom
X-Oracle-Dms-Ecid
X-Datadog-Sampling-Priority
X-Datadog-Trace-Id
X-Datadog-Parent-Id
X-Ratelimit-Reset
X-Content-Options
X-Varnish-Ttl
X-Template
X-RemovedCookies
X-G
X-ProcessESI
X-UUID
X-Rule
X-Adobe-Loc
Charset
X-Adobe-Content
X-RTag
X-Tumblr-User
X-App-Environment
X-Node-Name
MS-CV
X-Tumblr-Pixel-1
Ms-Operation-Id
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Debug-IsConnected
X-Debug-IsPreview
X-Storage
X-Source
X-Yottaa-Optimizations
X-Wix-Request-Id
VIX-Pulpo-Upstream-Status
X-Datadog-Sampled
X-Hl-Ver
X-Wormhole-Sdk
X-Yottaa-Metrics
NGB
VIX-Pulpo-Node
SD-X-WS
X-FW-Hash
X-FW-Server
X-Region
X-Rendered-As
X-Backend-Name
X-Signature
X-FW-Dynamic
X-User-Agent
X-FW-Serve
X-NYM-Debug-Backend
X-Instance
X-Proxy-Cache-Info
X-FW-Type
X-FW-Version
X-FW-Static
X-L-Path
X-Is-Bot
X-B-Cache
X-Environment-Context
X-Device-Type
X-Cacheable-TTL
X-NWS-UUID-VERIFY
GEO-INFO
Country
X-ServerID
X-Cache-Grace
Cross-Origin-Window-Policy
X-Status
ServerID
X-Cache-Age
Countrycode
X-Real-IP
X-IPS-LoggedIn
X-EdgeConnect-Cache-Status
X-Rid
X-Cache-Hit
X-RM-Cache-TTL
Akamai-GRN
Front
X-Amzn-Remapped-Content-Length
X-WP-CF-Super-Cache-Active
X-Language
Liferay-Portal
SRV
X-Framework
Amp-Access-Control-Allow-Source-Origin
X-B3-SpanId
X-Oracle-Dms-Rid
X-Nf-Request-Id
X-AB
X-Sucuri-ID
X-Sucuri-Cache
X-Ismobilevalue
X-Air-Pt
OT-Force-Account-Verify
X-Content-Powered-By
X-Servername
X-WebKit-CSP-Report-Only
X-UA
X-Akamai-Request-ID2
X-VC
X-Air-Source
From-Origin
X-Air-Hostname
X-VC-Cache
X-Air-Trace-Id
X-Mode
Backend
Xet-Cookie
X-URL
X-Xrds-Location
Refresh
X-Api-Version
Upgrade-Insecure-Requests
X-SRV
X-Cache-Time
Accept-Language
X-Handled-By
X-RID
Access-Control-Request-Headers
Webserver
LB
X-Fastly-Request-Id
X-Cache-Status-Check
X-HTML-Minification-Powered-By
X-JoinUs
Cache
Filters
X-RCS-CacheZone
Meta-Geo
X-DataDome
X-SaId
X-Xfnlog-Site
X-UPSTREAM-Address
X-Rewrite-Enabled
X-Rn-Rsrv
TWC-Connection-Speed
TWC-Device-Class
TWC-GeoIP-Country
ServedBy
X-Cache-Rule
TWC-GeoIP-LatLong
X-Cache-Operation
TWC-Privacy
Webcakes-App-Version
X-Tumblr-Pixel-2
Webcakes-App-Name
X-Endurance-Cache-Level
TWC-Locale-Group
Property-Id
X-R9-Blue-Green-Version
X-VWS-Id
X-Labrador-Cache-Channel
X-Zipkin-Id
X-RateLimit-Limit
X-Lambda-Id
X-No-Session
X-LJ-Flow-ID
X-Origin-Date
X-Origin-Hint
X-Hosted-By
Webcakes-Region
X-Proxied
X-Webstats-RespID
X-PHP-Host
X-Provided-By
X-Git-Commit
X-Varnish-Age
X-Cms-Context
X-Cluster
X-Cloudmap
X-Generated-By
X-Reqid
X-Routing-Service
X-S
X-Extlb
X-AWS-Id
X-Container-Uri
X-Adobe-Source
X-Is-Tablet
X-Fetched-On
X-Accel-Version
X-Is-Supported-Browser
X-Is-Mobile
X-IPLB-Request-ID
X-Is-Desktop
X-Tb
X-Tcp-Rtt
X-Restarts
X-Geo-Region
Atl-Traceid
X-Ms-Version
X-Ms-Request-Id
X-Loop
Apigw-Requestid
X-Forwarded-Host
X-INCAP-ABP
X-Web-Node
X-Locale
X-IPLB-Instance
X-Httpd
X-BYPASS-REASON
X-Cache-Debug
Section-Io-Id
X-Akamai-Edgescape
X-Browser-Name
X-Site-Version
X-Logging-Id
X-ProxyCache-Status
X-Skip-Cache
X-ProxyCache-Key
Url
X-Served-From
Web-Mar-Node
X-Scope-Id
X-Tncms
X-Edge-Location
X-Redis-Cache
Mn-Server-Ip
X-Director
X-Detected-As
X-Cache-Host
X-Alternate-Cache-Key
Selected-Fe
X-Format
X-Optimistic-Header
X-Proxy-Build
X-Frame-Option
X-Upstream-Ht
X-Nginx-Cache
X-Upstream-Ct
X-VCT
X-Varnish-Cache-Hits
X-Storefront-Renderer-Rendered
X-Timing-Wait
X-Soup
X-Shopify-Stage
X-Varnish-Beresp-Grace
X-SayCDN-TTL
X-Tt-Logid
X-Origin
X-Say-TTL
X-Request-URI
X-Say-Cacheable
Xserver
X-ShardId
X-Sorting-Hat-ShopId
X-Mg-Request-UUID
X-Azure-Ref-OriginShield
X-ShopId
X-Sorting-Hat-PodId
X-GeoCountry
X-GeoCode
Frame-Options
Onion-Location
X-Lagoon
Expiry
X-Connection-Hash
WPO-Cache-Message
WPO-Cache-Status
X-Drupal-Cache-Tags
X-Vcl-Version
X-Vcache
X-Generation-Time
X-CMSURLCustom
X-Shield-Cache-Expires
X-Thinkindot-L3
X-CDN-Forward
TDXMobile
Source
Protected
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
X-WP-CF-Super-Cache-Cookies-Bypass
Thinkindot-Control
X-Drupal-Cache-Contexts
X-Cache-Expired-At
X-Origin-TTL
X-Origin-CC
X-Cdn-Origin
Fastcgi-Useragent
Cdn-Requestid
X-Pass-Why
Environment
X-ECache
Cache-Hits
X-PHP-Backend
Priority
X-Worker
X-Vercel-Cache
X-Vercel-Id
X-Cache-Action
X-Proxy-Cache-Status
X-Rocket-Nginx-Serving-Static
X-TA-CDN-Provider
Uber-Trace-Id
X-GEO
Azure-SlotName
Azure-RegionName
X-Buckets
Azure-SiteName
Azure-Version
Azure-InstanceId
X-ID
Sid
Node
AMP-Access-Control-Allow-Source-Origin
X-Cluster-Node
X-App-Version
X-Aspnetmvc-Version
X-Urbn-Site-Id
X-Urbn-Context-Path
Locale
CDN-Cache
CDN-CachedAt
CF-IPCountry
CDN-RequestPullCode
CDN-EdgeStorageId
Cross-Origin-Embedder-Policy
CDN-RequestPullSuccess
CDN-Uid
X-XRDS-Location
CDN-PullZone
CDN-RequestCountryCode
X-RateLimit-Reset
X-Tumblr-Pixel-3
Cache-Tv-Group
X-FB-TRIP-ID
X-Fastcgi-Cache
X-Auth-Group-Type
X-B3-Traceid
X-Server-W
X-Cache-Server
DB-Nickname
User-Cache-Control
Alternate-Protocol
X-Pad
X-Origin-Cache-Key
X-Client-Ip
X-A
A
X-Ig-Origin-Region
X-Ec-Fail
X-DefHash
X-D
X-DefElseHash
X-Developer
X-Dispatcher-Server
X-Service
X-Gen-Mode
X-GeoIP-City
X-Custom-Header
X-Generated-On
X-Fastly-Backend
X-Esi-Check
X-Ec-GeoHdr
X-Edge-Server
X-Epic-Correlation-Id
X-Hnp-Log
X-Bl-Debug
MD5-Digest
Meta-Geo-Continent
Wxu-Next-Region
X-A-Ccd
Magicmarker
X-A-Dcw
Lang
X-A-Dam
Wxu-Next-Hostname
Ngx.Var.Host
Surrogated-Key
Sslversion
Rendered-Blocks
T-Server
Origin-Agent-Cluster
Wxu-Next-Commit
Odigeo-Trace-Id
Origin
X-A-Dgt
X-A-Wwc
X-Cache-TTL-Remaining
X-Cache-NE
X-Cache-Id
Cdn-Request-Time
Cdn-Host
X-Content-Age
Candidate-Md5Url
X-Conf
X-Block-Status
Content-Secure-Policy
Edge-Cache
Gannett-Cam-Experience-Id
X-Aed
X-Bc-Bl
DCR-Processing-Time-Ms
X-Ig-Push-State
X-BCube-Filmed-By
DCR-Decision-By
X-Core-Value
X-Gzip
X-Varnish-CookieINHashed-On
X-Varnish-CookieHashed-On
X-V-Cache
X-Varnish-Remaining-TTL
X-Vdms-Version
X-Via-Fastly
X-Op-Id-All
X-Org
X-UA-Device-Type
X-Req
X-ScT
X-TIM-N
X-SRCache-Key
X-NGINX-Cache
X-SB
X-Dc
X-Rojux
X-Viewer-Country
X-Origin-Expires
X-Level-Front-Cache
X-ND-Cache
HostName
X-Vtex-Remote-Cache
X-Tx-Id
Mime-Version
X-Wikidot-Static-Cache
Server-Host
X-AK-Request-ID
Server-Hostname
X-Amz-Storage-Class
Sever-Int
Server-Ext
X-B3-Trace-ID
X-Test
X-Tb-Optimization-Total-Bytes-Saved
XM
X-SVT-ORM-VERSION
X-Thanos
X-Backend-Instance
X-Auto-Login
X-Aicache-OS
RNT-Time
X-App-Name
X-Acquia-Purge-Cdn-Unconfigured
X-VG-WebCache
X-VG-TLSProxy
X-WA-Info
Tube-Got-Results
X-VTEX-Cache-Server
V-Age
X-VTEX-Cache-Time
Vix-Hermes-Req-Id
X-Bip
Tube-Got-Eval
X-Wikidot-Backend
Tube-Return
X-Ad-Load-Variation
X-Varnish-Director
X-Varnish-Hostname
X-VarnishDD-TTL
Tube-Get-Contents
Ssr
X-SD-PageType
X-NMSegId
X-Node-Id
X-Geo-Header
X-Nginx-Cache-Key
X-GeoIP
X-NodeID
X-Gdpr
X-Fastly-Cache
X-FC-Vary-Parameters
X-Fmm-Version
X-Forwarded-Site
X-Mvc-Supplant-Cachable
X-Mly-Id
X-GoCache-CacheStatus
RNT-Machine
X-HN
X-HS-Content-Campaign-Id
X-Loc
X-GeoIP-Region-Code
X-Micro-Cache
X-Men
X-LSADC-Cache
X-GeoIP-Country-Code
X-Nyt-Route
X-Origin-Response-Time
X-Clientip
X-Scheme
X-Request-Time
X-Region-Sid
X-Cdn-Srv
X-Jobs
X-Sn-Servicetimems
X-Cache-Bucket
X-Server-IP
X-Cache-Info
X-RateLimit-Remaining-Second
X-Debug-Cache-Fetch
X-DPWN-IS-SECURE
X-Platform
X-PAYTM-SRV-ID
X-Origin-Time
X-Policy
X-Powered-By-VTEX-Cache
X-Debug-Cache-Store
X-RateLimit-Limit-Second
X-Pubstack
X-Proto
X-SVT-ORM-RULES
X-CacheTTL
Adler-Geo
NM-Fastcgi-Cache
Cdncip
Cdnsip
Country-Code
X-LiteSpeed-Cache-Control
Content-Style-Type
Esi-Enabled
AKAMAI
Fastly-SSL
Cache-Provider
C-Via
Host-ID
Is-Eu
Fastly-Backend-Name
CDCHOST
Fusion-Template-Id
Content-Script-Type
Fusion-Component-Id
Fusion-Source
Platform
Producers
Click-Count-Action-Start
Req-ID
Click-Count-Error
Fusion-Content-Id
Powered-By
Origin-EX
Origin-CC
PFcat
Fusion-Content-Source
Fusion-Deployment-Id
X-DC
X-HITS
X-Csrf-Jwt
X-CUA
X-Contensis-Viewer-Groups
X-Var-Ttl
X-CGP
Canary
X-Depends
Req-Svc-Chain
X-Request-Host
X-Request-Start
X-Ec-Custom-Error
X-Eu-Site
X-Proxied-Request
X-Hash
X-Mvc-Supplant-OutputCached
X-Pool
X-Section
X-Device-Os
Apple-News-Services-Request-Url
X-Date
X-Slack-Shared-Secret-Outcome
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
X-Slack-Backend
X-Varnish-Authentication
Apple-News-Services-Handled
Cache-Key
Cluster
L
L5d-Success-Class
Mail-Subject
X-Accel-Expires-Debug
X-Access
Ha-Gx-Prefs
HA-Ipaddr
NGX
X-Cache-FS-Status
True-Client-Country-4JS
Pramga
Proxy-Firewall
On-Server
W
Web-Mar-Region
We-Hiring
Gh-Request-Id
Machine
X-BBC-Edge-Cache-Status
Fastly-GeoIP-CountryCode
DSUID
X-Cache-Aspx
X-Varnish-Beresp-Status
X-Location
X-Varnishpool
Yak-Timeinfo
Release
X-We-Are-Hiring
X-Human
X-AIR-PT
X-Varnish-Beresp-Ttl
X-Cs
X-Up
X-From
Server-Info
X-NCache
X-Varnish-Hits
CDN-RequestId
X-Akamai-Transformed
X-MP-GENERATED-AT
X-Jungle-Id
BehaviorPad-Version
Debug
X-Zone
Redirect-Candidate
X-LB-ID
X-Tec-Api-Version
X-Tec-Api-Origin
X-Tec-Api-Root
X-Datadome
X-APP
X-Vdms-Path
X-Cache-Backend
X-Via-Popv
X-HA-Backend
X-Refresh
X-Via-Poph
X-Via-Popn
WP-Super-Cache
CloudFront-Viewer-Country
X-VHOST
Pics-Label
SID
X-CACHE-AGE
Fastly-Drupal-HTML
X-Parent-Response-Time
GeoIP-Latitude
X-Content-Length
X-Uri
X-B3-Parentspanid
X-Servedbyhost
Fastly-Drupal-Html
X-Nananana
X-Newrelic-Synthetics
X-VC-TTL
X-PERF
X-Render-Time
X-M-Log
X-ApacheServer
X-M-Reqid
X-CDN-Cache-Status
X-CACHE-KEY
X-LB-NoCache
Datacenter
X-Nc
X-LiteSpeed-Tag
X-Litespeed-Tag
X-DynaTrace-JS-Agent
Resin-Trace
X-Cached-By
X-CS
X-ZONE
Vc-Max-Age
GeoIp-Country-Code
Server-ID
X-Amz-Meta-Cb-Modifiedtime
Locid
X-Dispatcher-Number
NtCoent-Length
X-Wa
X-B3-Spanid
X-TT-LOGID
X-RequestId
Cdn
X-Original-Request-Id
X-Varnish-Beresp-TTL
Product
X-Response-Served-From
X-VCache
X-TX-ID
FSS-Cache
X-IAuth-Set-Uid
X-NewRelic-App-Data
X-Ckpd-Fst-Backend
X-Old-Content-Length
True-Client-IP
X-Esi
X-Fpc
Srv
X-SERVER-NAME
X-HostName
Cf-Ipcountry
CDN
X-Nf-Ats-Version
X-Nf-Language
Uri
Ngx-Var-Key
X-Nf-Country
True-Client-Ip
ServerName
X-Bug-Bounty
Serverhost
X-HubSpot-Correlation-Id
S-Rt
X-Vgn-Hpd-Reason
Tcn
X-FPC
X-Oracle-DMS-ECID
X-TIME
X-Cdn-Forward
X-Srv
X-Platform-Processor
X-Platform-Router
X-Moov-Xdn-Version
X-Platform-Cluster
X-Dynatrace-Js-Agent
X-WA
GeoIP-Country-Code
X-CLOUD-TRACE-CONTEXT
X-Moov-T
X-TH-Server
Request-ID
X-Cdn-Cache-Status
X-Dispatch
CacheControlHeader
X-APP-VERSION
X-Vc
Server-Id
Cf-Device-Type
X-Vmg-Version
X-Akamai-Device-Characteristics
ServerHost
User-Agent
X-NC
X-COUNTRY
Hostname
X-Gamma-Serve
Srvid
X-FL-QIT-DEBUG
X-Info
Geoip-Latitude
Cross-Origin-Embedder-Policy-Report-Only
X-Webkit-Csp-Report-Only
X-S-Cookie
X-Destination
X-Application
X-B-Cookie
X-External-Request-Id
X-User
X-Lb-Nocache
X-Presslabs-Stats
X-Geo
Xc-Version
X-Zen-Fury
X-ServedByHost
PICS-Label
Expect-Staple
X-Rocket-Build-Number
Cneonction
X-Ha-Backend
X-Hit
Ohc-File-Size
X-Sigma
X-Sigma-Backend
X-Via-PopH
X-Via-PopN
X-Instance-Name
X-Via-PopV
Origin-Trial
Cloudfront-Viewer-Country
X-Cache-Date
X-VCL-Version
X-Amz-Meta-Opti
Epwk-X-Cache
X-API-Version
X-Segment-20210421
X-VServer
X-V
X-Akamai-Pragma-Client-IP
X-Branch-Name
X-Limited
X-Ua
X-App
X-Correlation-ID
X-Srcache-Store-Status
X-Srcache-Fetch-Status
Rtss
X-Rollout
X-Sqd-Ctime
N-Cache
X-Sqd-Stime
X-Platform-Server
X-Erf-Stays-Pdp-Viaduct-Migration-Web-V2
X-MiniProfiler-Ids
Permission-Policy
WZWS-RAY
X-Serial
X-Check-Cacheable
X-New
X-Eligible
X-Lb-Id
X-Wp-Cf-Super-Cache-Cache-Control
X-Wp-Cf-Super-Cache
Lb
X-Acquia-Purge-Tags
X-Acquia-Application-UUID
X-Acquia-Site
XkeyRZ
Cmstype
X-Proxy-CacheRZ
Timeexpire
Cmsid
X-Web-Server
X-Service-Response-Time
Sm-Log-Id
X-MSEdge-Features
X-MSEdge-Flight
X-Datacenter
X-DataCenter
Ohc-Cache-HIT
X-Acquia-Application-Trace
X-Requestid
X-CSRF-TOKEN
DataCenter
Load-Balancing
CountryCode
Servername
X-Litespeed-Cache-Control
X-LAGOON
Wpo-Cache-Message
X-ElasticPress-Query
X-Ftr-Request-Id
X-Internal-TTL
Fl-Custom-Application
Wpo-Cache-Status
X-VTEX-Cache-Backend-Header-Time
X-DynaTrace
X-Fastly-Backend-Reqs
X-VTEX-Cache-Backend-Connect-Time
X-Shopid
X-Amz-Meta-Sha256
X-Amz-Meta-S3b-Last-Modified
Warning
X-IN-APIGATEWAYSSL
X-IN-APIGATEWAY
X-Udemy-Cache-App-Namespace
X-Dw-Trace-Id
Ngx
X-Snapshot-Date
X-Origin-Upstream-Status
X-Shardid
X-Sorting-Hat-Podid
Type
X-RAMCache
X-Ramcache
X-Th-Server
X-Sorting-Hat-Shopid