Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
CF-RAY
Expect-CT
Accept-Ranges
X-XSS-Protection
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-Xss-Protection
X-UA-Compatible
X-Served-By
X-Download-Options
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
X-DNS-Prefetch-Control
Content-Security-Policy-Report-Only
Accept-CH
X-Runtime
Accept-CH-Lifetime
X-AspNet-Version
X-Drupal-Cache
X-Check
X-Generator
X-Cache-Status
X-Ua-Compatible
Server-Timing
X-Cacheable
X-Request-ID
Timing-Allow-Origin
X-Envoy-Upstream-Service-Time
X-FRAME-OPTIONS
X-Iinfo
X-Drupal-Dynamic-Cache
X-Content-Security-Policy
Feature-Policy
Access-Control-Expose-Headers
Content-Encoding
X-CDN
Status
Upgrade
X-AspNetMvc-Version
CF-Ray
Access-Control-Max-Age
X-Amz-Request-Id
Cf-Edge-Cache
X-Amz-Id-2
X-Via
Host-Header
EagleId
Permissions-Policy
Keep-Alive
Request-Context
X-Cache-Group
X-Backend
X-Robots-Tag
X-UA-Device
X-AH-Environment
X-Hacker
X-Server
X-Proxy-Cache
X-Turbo-Charged-By
X-Rq
X-Age
X-Ws-Request-Id
Xkey
X-Vhost
Cf-Apo-Via
X-Amz-Version-Id
X-Dispatcher
X-Swift-CacheTime
X-LiteSpeed-Cache
X-Swift-SaveTime
Grace
X-Server-Powered-By
Allow
Ali-Swift-Global-Savetime
X-Varnish-Cache
X-OneAgent-JS-Injection
P3p
X-Page-Speed
X-Pingback
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Cache-Lookup
X-Device
X-WebKit-CSP
EagleEye-TraceId
X-Host
Cf-Railgun
X-Backend-Server
X-Server-Id
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Dns-Prefetch-Control
X-Response-Time
X-Readtime
X-Ruxit-JS-Agent
Surrogate-Control
X-Akam-SW-Version
X-HW
X-Cloud-Trace-Context
Request-Id
X-Node
Content-Location
X-Country
X-Nginx-Cache-Status
X-Application-Context
X-Nginx-Upstream-Cache-Status
Accept-Ch-Lifetime
X-NWS-LOG-UUID
X-Country-Code
Service-Worker-Allowed
X-ASPNET-VERSION
X-Content-Type
X-Trace
X-Clacks-Overhead
Cache-Tag
X-Url
X-Litespeed-Cache
Rating
X-Amz-Server-Side-Encryption
X-Times
X-Rack-Cache
X-PC
X-TtlSet
X-Vname
Cross-Origin-Opener-Policy
X-Mcache
X-Edge
X-Midtier
X-Daa-Tunnel
X-Browser-Type
X-FTR-Request-ID
X-Server-Name
Nginx-Cache
X-Powered-By-Plesk
X-CST
AR-ATIME
AR-SID
AR-PoweredBy
AR-Request-ID
X-Cnection
X-Cache-TTL
Accept-Ch
X-ESI
X-Ac
X-GitHub-Request-Id
X-D2id
X-Element-Page-Cache
X-Kinja
X-GoogleNews-Bot
X-Exp-Variant
X-Cdn-Fetch
X-Exp-Id
X-Kinja-Build
X-Kinja-Revision
X-Kinja-Server
Edge-Control
Verso
X-MS-InvokeApp
X-Ser
AR-CACHE
X-Vcap-Request-Id
X-Abt-Application-Version
X-Upstream
X-ECACHE
X-FastCGI-Cache
X-Navigation-Version
X-B3-TraceId
X-Dw-Request-Base-Id
Fastly-Restarts
SPRequestDuration
SPIisLatency
X-Webkit-Csp
X-Mod-Pagespeed
X-Amz-Rid
X-Kraken-Loop-Name
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Instrumentation
SPRequestGuid
X-Server-Lifecycle-Phase
X-SharePointHealthScore
X-PDP-UNCACHING-HASH
X-Edge-Location-Klb
X-Kinsta-Cache
X-ARC
X-Goog-Hash
X-Client-IP
X-Ratelimit-Limit
Display
Pagespeed
X-Middleton-Display
X-Mg-S
X-Sol
X-Powered-CMS
X-NF-Request-ID
S
Edge-Cache-Tag
X-Oneagent-Js-Injection
X-Amzn-Trace-Id
Cache-Status
X-Version
Access-Control-Request-Method
X-Middleton-Response
Response
X-VARITI-CCR
RTSS
X-Ratelimit-Remaining
X-TTL
X-Varnish-TTL
X-Fastly-Request-ID
X-Cache-Key
Realpath
X-Forwarded-For
X-T
X-Content-Digest
Cross-Origin-Resource-Policy
X-Recruiting
X-Correlation-Id
X-TraceId
X-ORACLE-DMS-RID
Fastcgi-Cache
X-Cached
X-MSEdge-Ref
X-Shield-Request-Id
Front-End-Https
X-RateLimit-Remaining
MicrosoftSharePointTeamServices
X-Ua-Browser
X-Request-Received
X-Request-Processing-Time
X-Forwarded-Proto
X-HS-Hub-Id
X-HS-Content-Id
Payment
X-PressLabs-Stats
MS-Author-Via
TP-Cache
X-HS-Cache-Config
X-Protected-By
Arr-Disable-Session-Affinity
X-LLID
X-Frontend
Server-Node
Public-Key-Pins
X-SRCache-Store-Status
X-SRCache-Fetch-Status
Content-MD5
X-Ruxit-Js-Agent
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
Count-Hit
X-HS-Combine-CSS
X-Accel-Expires
X-Distributor
X-GUploader-UploadID
X-LB-Cache
X-FTR-Backend-Server
X-FTR-Backend
X-FTR-Balancer
X-FTR-Cache-Status
X-Country-Code-Real
X-Origin-Server
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Server-ID
X-NODE
X-Ezoic-Cdn
X-FTR-Expires
X-HP-Webp
X-Jurisdiction
X-HP-Trace-Id
X-Request-Handler-Origin-Region
X-Microsite
X-Newrelic-App-Data
X-Www-Served-By
X-Az
X-Varnish-Server
X-AppVersion
X-ORACLE-DMS-ECID
X-App-Server
Host
X-Content-Security-Policy-Report-Only
Accept-Charset
X-Activity-Id
X-Cluster-Name
Mrf-Cache-Status
MRF-Tech
X-B3-TraceId-Primal
X-Amz-Meta-S3cmd-Attrs
X-Varnish-Backend
Cache-Tags
Cleartype
Retry-After
X-Ua-Device
Surrogate-Key
X-Goog-Metageneration
Filterid
X-Unique-Id
Server-Name
X-Ttl
X-Git-Hash
Access-Control-Allow-Method
X-Debug
X-Hits
X-Envoy-Decorator-Operation
X-Azure-Ref
X-NGENIX-Cache
X-Load-Cache
X-Upgrade-Enabled
X-Geo-Country
X-Logged-In
X-CSRF-Token
X-Hostname
X-FB-Debug
TCN
X-Id
TP-L2-Cache
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Proxy
Section-Io-Cache
X-Seen-By
X-Grace
X-B
X-TT
X-Request-Guid
X-Revision
X-Pinterest-Rid
Pinterest-Version
DC
Pinterest-Generated-By
X-CCDN-CacheTTL
X-CCDN-Origin-Time
X-F-Cache
X-Fb-Rlafr
Healthy
X-B3-Sampled
Viewport
X-Hcs-Proxy-Type
X-Trace-Id
X-Cache-Control
X-Type
X-Contextid
X-Time
Referer-Policy
X-Mobile
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-Goog-Storage-Class
X-N
Fastly-SIE
Fastly-SWR
X-XRDS-LOCATION
Paypal-Debug-Id
Content-Disposition
X-DIS-Request-ID
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
X-Page-Id
X-Varnish-Grace
X-Debug-Info
X-Px
X-Via-JSL
X-Magnolia-Registration
X-Origin-Cache
Version
X-Amz-Replication-Status
X-Webkit-CSP
X-Ratelimit-Reset
X-Whom
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
X-Datadog-Trace-Id
X-Aws-Lambda-Call-Status
X-Content-Options
X-ProcessESI
X-UUID
X-G
X-RemovedCookies
X-Debug-IsPreview
X-Oracle-Dms-Ecid
X-Debug-IsConnected
X-Template
X-Node-Name
X-App-Environment
X-Adobe-Loc
X-Adobe-Content
X-Tumblr-Pixel
X-Rule
X-Tumblr-User
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
MS-CV
SD-X-WS
NGB
VIX-Pulpo-Node
X-Yottaa-Optimizations
VIX-Pulpo-Upstream-Status
X-Hl-Ver
X-Yottaa-Metrics
X-Storage
X-Wormhole-Sdk
X-Datadog-Sampled
X-Wix-Request-Id
X-RTag
X-Source
Charset
Ms-Operation-Id
X-Cacheable-TTL
X-Device-Type
X-B-Cache
X-Varnish-Ttl
X-Backend-Name
X-Region
X-Rendered-As
X-Signature
X-Instance
X-Proxy-Cache-Info
X-NYM-Debug-Backend
X-Is-Bot
GEO-INFO
X-FW-Version
X-ServerID
X-L-Path
X-Rid
X-Status
X-User-Agent
Amp-Access-Control-Allow-Source-Origin
X-Environment-Context
Country
X-FW-Hash
X-FW-Dynamic
X-FW-Type
X-FW-Serve
X-FW-Server
X-FW-Static
Cross-Origin-Window-Policy
Countrycode
ServerID
X-Cache-Grace
X-EdgeConnect-Cache-Status
X-IPS-LoggedIn
X-Real-IP
Akamai-GRN
X-NWS-UUID-VERIFY
X-Cache-Age
X-URL
X-RM-Cache-TTL
Front
X-Cache-Hit
SRV
Liferay-Portal
X-WP-CF-Super-Cache-Active
X-Amzn-Remapped-Content-Length
X-Framework
X-B3-SpanId
X-Language
X-Ismobilevalue
X-Air-Pt
X-AB
X-WebKit-CSP-Report-Only
X-Sucuri-Cache
OT-Force-Account-Verify
X-Sucuri-ID
X-Servername
X-Nf-Request-Id
X-Oracle-Dms-Rid
X-Content-Powered-By
X-Akamai-Request-ID2
X-UA
X-Air-Hostname
X-VC-Cache
X-Air-Trace-Id
X-Air-Source
From-Origin
Backend
Xet-Cookie
X-Mode
X-VC
X-SRV
X-DataDome
Refresh
Accept-Language
X-Api-Version
Upgrade-Insecure-Requests
X-Xrds-Location
X-Handled-By
X-Cache-Time
Access-Control-Request-Headers
X-Cache-Status-Check
LB
X-Tt-Logid
X-HTML-Minification-Powered-By
Filters
X-RCS-CacheZone
Meta-Geo
X-Rewrite-Enabled
X-UPSTREAM-Address
X-JoinUs
X-RID
X-Rn-Rsrv
X-SaId
Cache
X-Cache-Rule
TWC-Device-Class
X-Tumblr-Pixel-2
X-Xfnlog-Site
TWC-Connection-Speed
ServedBy
TWC-GeoIP-Country
X-Webstats-RespID
Property-Id
X-Varnish-Age
X-Cache-Operation
TWC-Locale-Group
Webcakes-App-Version
Webcakes-Region
Webcakes-App-Name
TWC-Privacy
X-Origin-Hint
X-Origin-Date
X-Adobe-Source
X-Cms-Context
X-Nginx-Cache
X-ECache
X-Git-Commit
X-Generated-By
X-Container-Uri
X-PHP-Host
X-Labrador-Cache-Channel
X-Hosted-By
X-S
X-Provided-By
X-R9-Blue-Green-Version
TWC-GeoIP-LatLong
X-Tcp-Rtt
X-Browser-Name
X-Httpd
X-Accel-Version
X-BYPASS-REASON
X-Tncms
X-Reqid
X-Geo-Region
X-Skip-Cache
X-Served-From
X-Tb
X-Forwarded-Host
X-Cluster
Webserver
X-Cache-Debug
Atl-Traceid
X-Loop
Url
X-Logging-Id
X-No-Session
X-ProxyCache-Status
X-Web-Node
X-ProxyCache-Key
X-Locale
X-Lambda-Id
X-Is-Supported-Browser
X-Is-Mobile
X-Is-Desktop
Web-Mar-Node
X-Is-Tablet
X-Scope-Id
Section-Io-Id
X-Redis-Cache
X-Site-Version
X-Endurance-Cache-Level
X-Fastly-Request-Id
X-Proxy-Build
X-Optimistic-Header
X-Restarts
X-Detected-As
X-Say-TTL
X-Storefront-Renderer-Rendered
X-Soup
X-Shopify-Stage
X-SayCDN-TTL
X-Say-Cacheable
Selected-Fe
X-Format
X-Fetched-On
X-Cache-Host
X-Director
X-Frame-Option
X-Alternate-Cache-Key
X-INCAP-ABP
X-IPLB-Request-ID
X-IPLB-Instance
X-Akamai-Edgescape
X-Timing-Wait
X-Origin
X-Varnish-Beresp-Grace
X-VCT
Apigw-Requestid
X-Varnish-Cache-Hits
X-Edge-Location
X-Request-URI
X-Upstream-Ct
X-Upstream-Ht
X-Mg-Request-UUID
X-Proxied
Xserver
X-Extlb
X-RateLimit-Limit
X-Zipkin-Id
Mn-Server-Ip
X-Routing-Service
X-Cloudmap
X-Ms-Version
X-ShardId
X-ShopId
X-AWS-Id
X-LJ-Flow-ID
X-VWS-Id
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
Frame-Options
X-Ms-Request-Id
X-GeoCountry
X-GeoCode
X-Azure-Ref-OriginShield
Onion-Location
X-Vcl-Version
X-Connection-Hash
X-Lagoon
Expiry
X-Vcache
X-CDN-Forward
WPO-Cache-Message
WPO-Cache-Status
Source
X-Cache-Expired-At
X-WP-CF-Super-Cache-Cookies-Bypass
X-CMSURLCustom
X-Generation-Time
Thinkindot-CacheControl
X-Thinkindot-L3
TDXMobile
X-Shield-Cache-Expires
Thinkindot-CacheControl-Type
Protected
Thinkindot-Control
X-Drupal-Cache-Contexts
Cdn-Requestid
X-Drupal-Cache-Tags
X-ID
X-Cdn-Origin
Fastcgi-Useragent
X-Origin-CC
X-Origin-TTL
Environment
X-PHP-Backend
X-Proxy-Cache-Status
X-XRDS-Location
Priority
X-Pass-Why
X-Vercel-Cache
X-Worker
X-Vercel-Id
X-Cache-Action
X-Rocket-Nginx-Serving-Static
Uber-Trace-Id
X-GEO
Cache-Hits
Azure-Version
Azure-RegionName
Azure-SiteName
Azure-SlotName
Azure-InstanceId
X-App-Version
Node
X-TA-CDN-Provider
X-Urbn-Context-Path
Locale
X-Client-Ip
X-Urbn-Site-Id
X-Buckets
X-Cluster-Node
Sid
CF-IPCountry
CDN-PullZone
CDN-Uid
CDN-EdgeStorageId
X-Aspnetmvc-Version
CDN-RequestPullCode
CDN-Cache
CDN-RequestCountryCode
CDN-RequestPullSuccess
Cross-Origin-Embedder-Policy
CDN-CachedAt
Cache-Tv-Group
X-Tumblr-Pixel-3
X-FB-TRIP-ID
X-RateLimit-Reset
X-Auth-Group-Type
X-Cache-Server
X-Fastcgi-Cache
X-HITS
AMP-Access-Control-Allow-Source-Origin
Alternate-Protocol
X-B3-Traceid
X-Pad
X-Tx-Id
DB-Nickname
X-A
X-A-Wwc
A
Surrogated-Key
X-Cache-NE
X-Edge-Server
X-Ec-GeoHdr
X-Gzip
X-Via-Fastly
X-Viewer-Country
X-Content-Age
X-TIM-N
X-Service
Lang
X-Server-W
X-Vtex-Remote-Cache
X-Custom-Header
X-Core-Value
X-Fastly-Backend
Gannett-Cam-Experience-Id
X-Aed
X-Conf
Ngx.Var.Host
X-ScT
X-Epic-Correlation-Id
X-Cache-TTL-Remaining
T-Server
Meta-Geo-Continent
Magicmarker
X-Generated-On
MD5-Digest
X-Esi-Check
Odigeo-Trace-Id
X-Ig-Push-State
X-A-Dam
Cdn-Host
X-A-Ccd
Wxu-Next-Region
X-Req
X-Origin-Cache-Key
X-DefHash
X-A-Dcw
Candidate-Md5Url
X-SRCache-Key
X-ND-Cache
Cdn-Request-Time
Wxu-Next-Hostname
X-DefElseHash
X-Bc-Bl
Sslversion
X-Op-Id-All
User-Cache-Control
X-Varnish-CookieINHashed-On
Wxu-Next-Commit
Content-Secure-Policy
X-BCube-Filmed-By
X-Vdms-Version
X-Bl-Debug
X-A-Dgt
DCR-Decision-By
X-Origin-Expires
X-Varnish-Remaining-TTL
X-Level-Front-Cache
X-Varnish-CookieHashed-On
X-Ec-Fail
X-D
X-Cache-Id
X-Org
X-Ig-Origin-Region
X-Dispatcher-Server
DCR-Processing-Time-Ms
Origin-Agent-Cluster
X-V-Cache
X-Rojux
X-Developer
Rendered-Blocks
Mime-Version
X-DC
Edge-Cache
Fastly-SSL
Country-Code
Content-Style-Type
X-Debug-Cache-Store
X-Debug-Cache-Fetch
Fastly-Backend-Name
Content-Script-Type
Tube-Get-Contents
Producers
X-Block-Status
Req-ID
X-Cache-Bucket
Powered-By
PFcat
Platform
RNT-Machine
RNT-Time
X-App-Name
Vix-Hermes-Req-Id
X-Varnish-Hostname
X-Varnish-Director
X-Bip
Server-Host
Tube-Return
Origin
X-Acquia-Purge-Cdn-Unconfigured
X-Cdn-Srv
X-CacheTTL
X-Ad-Load-Variation
X-Clientip
Is-Eu
X-Backend-Instance
X-AK-Request-ID
X-Amz-Storage-Class
X-Cache-Info
Tube-Got-Results
Tube-Got-Eval
V-Age
X-B3-Trace-ID
X-VarnishDD-TTL
Host-ID
X-Hnp-Log
X-Mvc-Supplant-Cachable
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-NGINX-Cache
X-Node-Id
X-Origin-Response-Time
X-Nyt-Route
X-NodeID
X-Mly-Id
X-Micro-Cache
X-Jobs
X-HS-Content-Campaign-Id
X-Aicache-OS
X-Tb-Optimization-Total-Bytes-Saved
Click-Count-Error
X-Men
X-LSADC-Cache
X-Origin-Time
X-LiteSpeed-Cache-Control
HostName
X-Region-Sid
X-Server-IP
X-Request-Time
X-Sn-Servicetimems
X-SD-PageType
X-Scheme
X-SB
X-RateLimit-Remaining-Second
X-Dc
X-Policy
X-Platform
X-PAYTM-SRV-ID
X-Powered-By-VTEX-Cache
X-Proto
X-RateLimit-Limit-Second
X-Pubstack
X-HN
X-Loc
X-FC-Vary-Parameters
X-Fastly-Cache
X-UA-Device-Type
X-Thanos
X-VTEX-Cache-Server
X-Forwarded-Site
X-VTEX-Cache-Time
X-VG-WebCache
X-VG-TLSProxy
Cdncip
Cdnsip
Click-Count-Action-Start
Cache-Provider
X-DPWN-IS-SECURE
Adler-Geo
AKAMAI
X-Gdpr
X-Fmm-Version
X-GeoIP
X-Geo-Header
X-Gen-Mode
X-GeoIP-Country-Code
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-GeoIP-Region-Code
X-GeoIP-City
XM
X-GoCache-CacheStatus
X-Request-Start
X-Ec-Custom-Error
X-Request-Host
X-Depends
X-Section
X-Slack-Backend
X-Human
X-Slack-Shared-Secret-Outcome
X-Test
X-Date
X-Varnish-Authentication
X-Auto-Login
X-BBC-Edge-Cache-Status
X-Varnish-Beresp-Status
X-NMSegId
X-Nginx-Cache-Key
X-Mvc-Supplant-OutputCached
X-Contensis-Viewer-Groups
X-Csrf-Jwt
X-CUA
X-Var-Ttl
X-Proxied-Request
X-Eu-Site
X-Pool
X-Cache-Aspx
X-CGP
X-Location
CDCHOST
DSUID
Esi-Enabled
Cluster
Canary
C-Via
Cache-Key
Fastly-GeoIP-CountryCode
Gh-Request-Id
L5d-Success-Class
Machine
L
HA-Ipaddr
Ha-Gx-Prefs
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
X-We-Are-Hiring
X-WA-Info
X-Access
X-Cache-FS-Status
Yak-Timeinfo
Fusion-Component-Id
Fusion-Content-Id
Apple-News-Services-Handled
Apple-News-Services-Host
Fusion-Source
Fusion-Deployment-Id
Fusion-Content-Source
Mail-Subject
Fusion-Template-Id
W
We-Hiring
Proxy-Firewall
Web-Mar-Region
True-Client-Country-4JS
Release
Server-Hostname
Ssr
Server-Ext
Req-Svc-Chain
Sever-Int
Pramga
X-Accel-Expires-Debug
NM-Fastcgi-Cache
On-Server
X-Varnishpool
Origin-CC
Origin-EX
X-Varnish-Beresp-Ttl
X-Hash
X-Device-Os
NGX
X-AIR-PT
X-Varnish-Hits
X-Zone
X-Cs
X-NCache
Server-Info
BehaviorPad-Version
X-LB-ID
Debug
X-Up
Redirect-Candidate
X-From
X-Akamai-Transformed
CDN-RequestId
X-APP
X-MP-GENERATED-AT
X-Jungle-Id
X-Refresh
X-CACHE-AGE
X-Tec-Api-Version
X-Tec-Api-Root
X-Tec-Api-Origin
X-HA-Backend
X-Via-Poph
CloudFront-Viewer-Country
X-Via-Popn
Pics-Label
SID
X-Vdms-Path
X-Cache-Backend
X-Via-Popv
Fastly-Drupal-HTML
X-Parent-Response-Time
WP-Super-Cache
X-VHOST
X-Servedbyhost
GeoIP-Latitude
X-B3-Parentspanid
X-Uri
X-Content-Length
X-Datadome
X-Litespeed-Tag
Fastly-Drupal-Html
X-Nananana
X-Render-Time
X-PERF
X-LB-NoCache
X-ApacheServer
X-M-Reqid
X-Nc
X-Newrelic-Synthetics
X-VC-TTL
X-M-Log
X-CDN-Cache-Status
Datacenter
X-LiteSpeed-Tag
X-CS
X-NewRelic-App-Data
X-Cached-By
X-CACHE-KEY
Vc-Max-Age
X-DynaTrace-JS-Agent
NtCoent-Length
Server-ID
Resin-Trace
X-Dispatcher-Number
X-Wa
X-RequestId
X-ZONE
Cdn
Locid
GeoIp-Country-Code
X-Amz-Meta-Cb-Modifiedtime
Product
X-B3-Spanid
X-Response-Served-From
X-Varnish-Beresp-TTL
X-Original-Request-Id
X-VCache
X-IAuth-Set-Uid
X-Ckpd-Fst-Backend
FSS-Cache
X-Fpc
X-TT-LOGID
Uri
X-TIME
True-Client-IP
Srv
X-Esi
Serverhost
X-Old-Content-Length
X-Bug-Bounty
True-Client-Ip
X-SERVER-NAME
S-Rt
X-HostName
X-TX-ID
Cf-Ipcountry
ServerName
CDN
X-Nf-Language
Ngx-Var-Key
X-HubSpot-Correlation-Id
X-Nf-Country
X-Nf-Ats-Version
Tcn
X-FPC
X-Dynatrace-Js-Agent
X-Vgn-Hpd-Reason
X-Vc
X-Cdn-Cache-Status
X-Cdn-Forward
X-Srv
X-Oracle-DMS-ECID
X-Platform-Cluster
X-Platform-Router
X-TH-Server
X-Moov-T
X-Moov-Xdn-Version
X-WA
X-Platform-Processor
GeoIP-Country-Code
Request-ID
X-Akamai-Device-Characteristics
User-Agent
X-Dispatch
Server-Id
CacheControlHeader
X-APP-VERSION
X-Vmg-Version
Cf-Device-Type
X-Gamma-Serve
X-NC
X-Info
ServerHost
X-COUNTRY
Hostname
Srvid
Xc-Version
X-Webkit-Csp-Report-Only
Geoip-Latitude
X-FL-QIT-DEBUG
X-B-Cookie
Cross-Origin-Embedder-Policy-Report-Only
X-User
X-Application
X-External-Request-Id
X-Lb-Nocache
X-S-Cookie
X-Destination
X-Hit
X-Presslabs-Stats
Expect-Staple
X-Zen-Fury
X-Geo
X-Instance-Name
X-Sigma-Backend
PICS-Label
X-Ha-Backend
X-Amz-Meta-Opti
X-ServedByHost
Ohc-File-Size
Cneonction
X-Via-PopN
X-Rocket-Build-Number
X-Cache-Date
X-Via-PopH
X-Via-PopV
Origin-Trial
Cloudfront-Viewer-Country
X-Sigma
X-VCL-Version
Epwk-X-Cache
X-API-Version
X-VServer
X-Segment-20210421
X-V
X-Limited
X-App
X-Correlation-ID
X-Branch-Name
Permission-Policy
X-Ua
X-Eligible
X-Platform-Server
X-Rollout
WZWS-RAY
X-New
X-Akamai-Pragma-Client-IP
N-Cache
X-Srcache-Fetch-Status
X-Srcache-Store-Status
Rtss
XkeyRZ
X-Sqd-Stime
X-Sqd-Ctime
X-Proxy-CacheRZ
X-Lb-Id
X-MiniProfiler-Ids
X-Erf-Stays-Pdp-Viaduct-Migration-Web-V2
X-Serial
X-Check-Cacheable
X-Wp-Cf-Super-Cache-Cache-Control
Lb
X-Wp-Cf-Super-Cache
X-ElasticPress-Query
X-Ftr-Request-Id
X-Internal-TTL
X-Acquia-Site
Cmstype
Timeexpire
Cmsid
X-Fastly-Backend-Reqs
Sm-Log-Id
X-Web-Server
X-Datacenter
X-DataCenter
X-Acquia-Purge-Tags
X-MSEdge-Flight
Ohc-Cache-HIT
WebServer
X-MSEdge-Features
X-Service-Response-Time
Ngx
X-Acquia-Application-Trace
X-Acquia-Application-UUID
X-Litespeed-Cache-Control
X-CSRF-TOKEN
Load-Balancing
DataCenter
Servername
X-LAGOON
CountryCode
X-Via-SSL
X-Via-Edge
X-Via-CDN
X-Requestid
X-VTEX-Cache-Backend-Connect-Time
Edge-Copy-Time
X-EC-Lua
X-Traceid
Fl-Custom-Application
X-VTEX-Cache-Backend-Header-Time
X-RAMCache
X-Amz-Meta-S3b-Last-Modified
X-DynaTrace
Warning
X-Amz-Meta-Sha256
X-Udemy-Cache-App-Namespace
X-Dw-Trace-Id
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
X-Snapshot-Date
X-Ramcache
X-Sorting-Hat-Shopid
Type
Wpo-Cache-Message
X-Sorting-Hat-Podid
X-Shopid
X-Th-Server
X-Origin-Upstream-Status
X-Shardid
Wpo-Cache-Status