Threat Level: green Handler on Duty: Jan Kopriva

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
CF-RAY
X-XSS-Protection
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-Xss-Protection
X-UA-Compatible
X-Served-By
X-Download-Options
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
Content-Security-Policy-Report-Only
Accept-CH
X-AspNet-Version
X-Runtime
X-DNS-Prefetch-Control
Accept-CH-Lifetime
X-Drupal-Cache
X-Check
CF-Ray
X-Cache-Status
X-Generator
Server-Timing
X-Request-ID
X-Cacheable
X-Ua-Compatible
Timing-Allow-Origin
X-Envoy-Upstream-Service-Time
X-FRAME-OPTIONS
X-Iinfo
X-Drupal-Dynamic-Cache
X-Content-Security-Policy
Access-Control-Expose-Headers
Feature-Policy
Content-Encoding
X-CDN
Status
Upgrade
X-AspNetMvc-Version
Access-Control-Max-Age
X-Amz-Request-Id
X-Amz-Id-2
Cf-Edge-Cache
X-Via
Host-Header
EagleId
Keep-Alive
Request-Context
X-Cache-Group
X-Backend
Permissions-Policy
X-UA-Device
X-Robots-Tag
X-AH-Environment
X-Hacker
X-Server
X-Proxy-Cache
X-Turbo-Charged-By
Xkey
X-Rq
X-Ws-Request-Id
X-Age
X-Vhost
X-Amz-Version-Id
Cf-Apo-Via
X-Dispatcher
X-LiteSpeed-Cache
X-Swift-SaveTime
X-Swift-CacheTime
X-Server-Powered-By
Allow
Grace
Ali-Swift-Global-Savetime
X-Varnish-Cache
P3p
X-OneAgent-JS-Injection
X-Page-Speed
X-Pingback
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Dns-Prefetch-Control
X-Cache-Lookup
X-Device
EagleEye-TraceId
Cf-Railgun
X-Host
X-WebKit-CSP
X-Backend-Server
X-Server-Id
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Response-Time
X-Readtime
X-Ruxit-JS-Agent
Surrogate-Control
X-Akam-SW-Version
X-HW
Request-Id
X-Cloud-Trace-Context
X-Node
Content-Location
X-Application-Context
X-Nginx-Cache-Status
X-Country
X-Nginx-Upstream-Cache-Status
Accept-Ch-Lifetime
X-NWS-LOG-UUID
X-Country-Code
Service-Worker-Allowed
X-Content-Type
X-Trace
X-Url
Cache-Tag
X-Clacks-Overhead
Rating
X-Amz-Server-Side-Encryption
X-Rack-Cache
X-Times
X-FTR-Request-ID
X-TtlSet
X-Vname
X-PC
X-CST
X-Daa-Tunnel
X-Litespeed-Cache
Nginx-Cache
Cross-Origin-Opener-Policy
X-Edge
X-Mcache
X-Midtier
X-Browser-Type
X-Server-Name
X-Powered-By-Plesk
Accept-Ch
X-Cnection
AR-PoweredBy
AR-SID
AR-ATIME
AR-Request-ID
X-ESI
X-Ac
X-GitHub-Request-Id
X-Element-Page-Cache
X-D2id
X-Cache-TTL
Edge-Control
X-Kinja-Build
X-Kinja-Revision
X-Kinja-Server
X-Kinja
X-GoogleNews-Bot
X-Cdn-Fetch
X-Exp-Id
X-Exp-Variant
Verso
X-MS-InvokeApp
X-ECACHE
X-Upstream
X-Vcap-Request-Id
X-FastCGI-Cache
AR-CACHE
X-Ser
X-Abt-Application-Version
X-Navigation-Version
X-Dw-Request-Base-Id
X-Webkit-Csp
SPIisLatency
SPRequestDuration
X-B3-TraceId
X-Mod-Pagespeed
Fastly-Restarts
X-SharePointHealthScore
SPRequestGuid
X-Amz-Rid
X-Kraken-Loop-Name
X-Instrumentation
X-Erf-Bev-Bev-Is-Generated
X-Server-Lifecycle-Phase
X-Erf-Bev-Bev
X-NF-Request-ID
X-Client-IP
X-Edge-Location-Klb
X-Kinsta-Cache
X-Oneagent-Js-Injection
X-Ratelimit-Limit
X-Mg-S
X-Goog-Hash
Edge-Cache-Tag
S
X-Powered-CMS
X-ARC
X-Middleton-Display
Display
X-Sol
Pagespeed
X-PDP-UNCACHING-HASH
Cache-Status
X-Amzn-Trace-Id
Access-Control-Request-Method
X-Version
X-VARITI-CCR
Response
X-Middleton-Response
X-Cache-Key
X-Ratelimit-Remaining
X-Fastly-Request-ID
X-TTL
RTSS
X-TraceId
X-Content-Digest
Realpath
Cross-Origin-Resource-Policy
X-T
X-Forwarded-For
X-Recruiting
X-Correlation-Id
X-ORACLE-DMS-RID
Fastcgi-Cache
X-Cached
Front-End-Https
X-MSEdge-Ref
X-Shield-Request-Id
X-Varnish-TTL
MS-Author-Via
Content-MD5
X-HS-Hub-Id
X-Country-Code-Real
X-HS-Cache-Config
X-Protected-By
X-FTR-Backend
X-FTR-Balancer
X-FTR-Backend-Server
X-FTR-Cache-Status
X-HS-Content-Id
X-Ruxit-Js-Agent
MicrosoftSharePointTeamServices
X-Ua-Browser
X-Request-Received
X-Request-Processing-Time
X-Forwarded-Proto
Public-Key-Pins
X-RateLimit-Remaining
Server-Node
X-Frontend
TP-Cache
Payment
X-LLID
Arr-Disable-Session-Affinity
X-PressLabs-Stats
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-HS-Combine-CSS
X-FTR-Expires
Count-Hit
X-Server-ID
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Accel-Expires
X-GUploader-UploadID
X-Distributor
X-Origin-Server
X-NODE
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
X-LB-Cache
X-HP-Webp
X-HP-Trace-Id
X-Jurisdiction
X-Ezoic-Cdn
X-Aws-Lambda-Call-Status
X-Microsite
X-Request-Handler-Origin-Region
X-AppVersion
X-Www-Served-By
X-Az
X-Activity-Id
X-Newrelic-App-Data
X-Varnish-Server
X-Cluster-Name
MRF-Tech
Mrf-Cache-Status
X-B3-TraceId-Primal
X-App-Server
Host
X-Varnish-Backend
Accept-Charset
X-Ua-Device
Cache-Tags
X-ORACLE-DMS-ECID
Retry-After
X-Amz-Meta-S3cmd-Attrs
X-Content-Security-Policy-Report-Only
Server-Name
X-Webkit-CSP
Cleartype
Pinterest-Generated-By
X-Pinterest-Rid
Pinterest-Version
X-Goog-Metageneration
X-ASPNET-VERSION
X-Hits
Filterid
X-Unique-Id
X-Envoy-Decorator-Operation
X-Git-Hash
Access-Control-Allow-Method
X-CSRF-Token
X-Hostname
X-NGENIX-Cache
X-Azure-Ref
X-Upgrade-Enabled
X-Geo-Country
X-Load-Cache
X-Debug
X-Id
X-Logged-In
Referer-Policy
X-Ttl
TP-L2-Cache
TCN
X-Time
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Proxy
X-FB-Debug
X-B
X-CCDN-CacheTTL
X-Seen-By
X-Hcs-Proxy-Type
X-CCDN-Origin-Time
X-Grace
X-TT
X-B3-Sampled
X-Amzn-RequestId
X-Varnish-Ttl
X-Amz-Apigw-Id
Section-Io-Cache
X-Cache-Control
X-F-Cache
X-Request-Guid
X-Revision
X-Trace-Id
Surrogate-Key
X-Contextid
X-Fb-Rlafr
DC
X-Type
Healthy
X-DIS-Request-ID
Viewport
X-Mobile
X-N
Paypal-Debug-Id
X-Goog-Stored-Content-Length
X-WP-CF-Super-Cache-Cache-Control
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
Fastly-SWR
X-WP-CF-Super-Cache
Fastly-SIE
X-Goog-Generation
X-XRDS-LOCATION
X-Debug-Info
X-Page-Id
Content-Disposition
X-Px
X-Origin-Cache
X-Varnish-Grace
Version
X-Via-JSL
X-Whom
X-Magnolia-Registration
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
X-Datadog-Trace-Id
X-Content-Options
X-Oracle-Dms-Ecid
X-Amz-Replication-Status
Charset
X-Template
X-Rid
X-G
X-UUID
X-ProcessESI
X-RemovedCookies
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-Debug-IsConnected
X-Adobe-Content
X-Adobe-Loc
X-Wix-Request-Id
X-Tumblr-Pixel
X-Debug-IsPreview
X-Tumblr-User
Ms-Operation-Id
MS-CV
X-RTag
X-Node-Name
X-Rule
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-NWS-UUID-VERIFY
X-B-Cache
X-Datadog-Sampled
X-App-Environment
VIX-Pulpo-Upstream-Status
SD-X-WS
VIX-Pulpo-Node
X-Cache-Grace
X-Signature
X-Cache-Age
X-Hl-Ver
X-Cacheable-TTL
X-Backend-Name
X-Device-Type
X-L-Path
X-EdgeConnect-Cache-Status
X-NYM-Debug-Backend
X-Storage
X-Region
X-Environment-Context
X-Source
NGB
X-Proxy-Cache-Info
X-User-Agent
X-Rendered-As
X-Real-IP
Country
X-Instance
X-FW-Serve
X-ServerID
X-FW-Dynamic
X-FW-Server
X-FW-Static
X-Is-Bot
X-FW-Version
X-FW-Type
ServerID
X-FW-Hash
GEO-INFO
X-Status
X-Cache-Hit
Countrycode
X-Language
Cross-Origin-Window-Policy
SRV
X-IPS-LoggedIn
X-Amzn-Remapped-Content-Length
Liferay-Portal
X-Wormhole-Sdk
Akamai-GRN
X-Ratelimit-Reset
X-B3-SpanId
X-RM-Cache-TTL
X-WP-CF-Super-Cache-Active
Front
X-Sucuri-ID
X-Sucuri-Cache
Amp-Access-Control-Allow-Source-Origin
OT-Force-Account-Verify
X-Framework
X-Xrds-Location
X-Oracle-Dms-Rid
X-Servername
X-AB
X-Air-Pt
X-UA
From-Origin
X-Content-Powered-By
X-VC-Cache
X-WebKit-CSP-Report-Only
Xet-Cookie
X-Air-Source
X-Air-Trace-Id
X-Mode
X-VC
X-Air-Hostname
Backend
X-Akamai-Request-ID2
X-URL
Upgrade-Insecure-Requests
Refresh
X-Origin-Cache-Key
X-Cache-Time
X-DataDome
X-Handled-By
X-INCAP-ABP
X-Nginx-Cache
Accept-Language
X-Endurance-Cache-Level
X-Ismobilevalue
X-SRV
X-UPSTREAM-Address
X-Edge-Location
X-JoinUs
X-SaId
X-Rn-Rsrv
Filters
Meta-Geo
X-RCS-CacheZone
X-Xfnlog-Site
Cache
X-Rewrite-Enabled
X-VWS-Id
X-Reqid
X-Generated-By
X-LJ-Flow-ID
Webcakes-Region
Webcakes-App-Version
X-R9-Blue-Green-Version
X-Cms-Context
X-Cache-Rule
X-Origin-Date
X-Origin-Hint
X-PHP-Host
Webserver
Access-Control-Request-Headers
X-Cache-Status-Check
X-No-Session
X-Cloudmap
X-Provided-By
X-S
TWC-GeoIP-LatLong
X-Cache-Operation
X-Cluster
LB
X-Proxied
X-Adobe-Source
TWC-GeoIP-Country
TWC-Privacy
TWC-Device-Class
X-Extlb
X-RateLimit-Limit
X-Webstats-RespID
ServedBy
X-AWS-Id
X-Varnish-Age
TWC-Connection-Speed
Property-Id
X-Tumblr-Pixel-2
TWC-Locale-Group
X-Routing-Service
X-Git-Commit
X-Hosted-By
Webcakes-App-Name
X-Lambda-Id
X-Zipkin-Id
X-Container-Uri
X-Labrador-Cache-Channel
X-ProxyCache-Key
Atl-Traceid
X-Browser-Name
X-Httpd
X-HTML-Minification-Powered-By
X-Web-Node
X-Cache-Debug
X-Ms-Version
X-Geo-Region
Url
X-Skip-Cache
Apigw-Requestid
X-IPLB-Request-ID
X-Locale
X-BYPASS-REASON
X-Logging-Id
X-Is-Tablet
X-Tcp-Rtt
X-Served-From
X-Fetched-On
X-Api-Version
Mn-Server-Ip
X-Restarts
X-Is-Supported-Browser
X-Is-Desktop
X-Ms-Request-Id
X-IPLB-Instance
X-Is-Mobile
X-Akamai-Edgescape
X-ProxyCache-Status
X-Site-Version
X-Forwarded-Host
X-Loop
Web-Mar-Node
X-Azure-Ref-OriginShield
X-Storefront-Renderer-Rendered
X-Format
X-Tb
Frame-Options
X-Tncms
X-Varnish-Beresp-Grace
X-Detected-As
X-Upstream-Ct
X-Upstream-Ht
Selected-Fe
Section-Io-Id
X-Soup
X-Origin
X-Scope-Id
X-Accel-Version
X-Shopify-Stage
X-Proxy-Build
X-Say-Cacheable
X-Say-TTL
X-Timing-Wait
X-Redis-Cache
X-VCT
X-SayCDN-TTL
X-Varnish-Cache-Hits
X-Alternate-Cache-Key
X-GeoCountry
X-GeoCode
X-Cache-Host
WPO-Cache-Status
X-Optimistic-Header
X-Frame-Option
Xserver
X-Director
WPO-Cache-Message
X-RID
X-ShardId
X-ShopId
X-Request-URI
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Generation-Time
X-CMSURLCustom
X-RateLimit-Reset
X-Shield-Cache-Expires
X-Tt-Logid
Thinkindot-Control
X-Origin-CC
X-Thinkindot-L3
Cache-Hits
X-Origin-TTL
Thinkindot-CacheControl
TDXMobile
Thinkindot-CacheControl-Type
X-Vcache
Onion-Location
X-Drupal-Cache-Tags
Source
Cdn-Requestid
Fastcgi-Useragent
Expiry
X-Cdn-Origin
X-Connection-Hash
Protected
X-CDN-Forward
X-Drupal-Cache-Contexts
X-Lagoon
X-Fastly-Request-Id
X-WP-CF-Super-Cache-Cookies-Bypass
X-B3-Traceid
X-Cache-Expired-At
X-Buckets
X-Vercel-Cache
X-Mg-Request-UUID
X-Vercel-Id
X-Worker
X-Pass-Why
X-TA-CDN-Provider
X-PHP-Backend
Azure-SiteName
Azure-SlotName
Azure-InstanceId
X-Nf-Request-Id
X-Rocket-Nginx-Serving-Static
Azure-Version
Azure-RegionName
Node
X-Vcl-Version
Environment
X-ECache
X-App-Version
X-Proxy-Cache-Status
X-Cache-Action
X-GEO
X-ID
Sid
Priority
CDN-RequestPullSuccess
Uber-Trace-Id
AMP-Access-Control-Allow-Source-Origin
X-Aspnetmvc-Version
CDN-Uid
Cross-Origin-Embedder-Policy
CDN-PullZone
CDN-RequestCountryCode
CDN-RequestPullCode
CDN-CachedAt
CDN-EdgeStorageId
CDN-Cache
X-XRDS-Location
X-Cluster-Node
X-Tumblr-Pixel-3
X-Urbn-Context-Path
X-Urbn-Site-Id
Locale
X-Cache-Server
X-Fastcgi-Cache
X-Server-W
DB-Nickname
HostName
Cache-Tv-Group
CF-IPCountry
X-Auth-Group-Type
X-FB-TRIP-ID
Alternate-Protocol
User-Cache-Control
Fusion-Content-Source
Fusion-Source
Fusion-Content-Id
X-Tx-Id
Fusion-Template-Id
Fusion-Component-Id
Fusion-Deployment-Id
X-Pad
X-DC
X-Jobs
X-Client-Ip
Gannett-Cam-Experience-Id
Edge-Cache
X-Epic-Correlation-Id
X-Fastly-Backend
X-Esi-Check
X-Edge-Server
Lang
MD5-Digest
Meta-Geo-Continent
X-Ec-Fail
Magicmarker
X-Ec-GeoHdr
X-Gen-Mode
DCR-Processing-Time-Ms
X-Ig-Push-State
X-Ig-Origin-Region
A
X-BCube-Filmed-By
X-Vtex-Remote-Cache
X-Viewer-Country
X-Level-Front-Cache
X-Hnp-Log
X-Gzip
Content-Secure-Policy
X-Generated-On
DCR-Decision-By
X-UA-Device-Type
Cdn-Request-Time
Candidate-Md5Url
Cdn-Host
Ngx.Var.Host
Odigeo-Trace-Id
X-A-Dam
X-A-Dcw
X-A-Dgt
X-A-Ccd
X-A
Wxu-Next-Hostname
Wxu-Next-Region
X-A-Wwc
X-Aed
X-Bl-Debug
X-Bc-Bl
X-Block-Status
X-Cache-Id
X-Cache-TTL-Remaining
X-Cache-NE
Wxu-Next-Commit
X-Conf
X-Developer
X-DefHash
X-DefElseHash
X-Device-Os
Origin-Agent-Cluster
X-Dispatcher-Server
Origin
Rendered-Blocks
X-D
X-Core-Value
X-Content-Age
T-Server
Surrogated-Key
X-Custom-Header
Sslversion
X-Via-Fastly
X-GeoIP-City
X-Rojux
X-Varnish-CookieHashed-On
X-SB
X-ScT
X-SRCache-Key
X-Req
X-Op-Id-All
X-Origin-Expires
X-Org
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
X-Vdms-Version
X-ND-Cache
X-Service
X-TIM-N
X-V-Cache
Mime-Version
X-LSADC-Cache
Producers
Platform
X-Thanos
Powered-By
X-Region-Sid
RNT-Time
Server-Ext
RNT-Machine
Req-ID
X-Cache-Bucket
PFcat
Origin-CC
X-Varnish-Director
X-Policy
X-Varnish-Hostname
X-Platform
X-DPWN-IS-SECURE
X-Proto
Server-Host
X-Bip
X-Pubstack
NM-Fastcgi-Cache
Origin-EX
Server-Hostname
X-Server-IP
X-Sn-Servicetimems
X-SD-PageType
X-Cache-Info
X-Clientip
X-SVT-ORM-RULES
X-Cdn-Srv
X-SVT-ORM-VERSION
X-AK-Request-ID
X-Ad-Load-Variation
X-Acquia-Purge-Cdn-Unconfigured
X-CacheTTL
Vix-Hermes-Req-Id
X-Scheme
X-Request-Time
X-Test
Ssr
Sever-Int
X-Auto-Login
Tube-Get-Contents
X-PAYTM-SRV-ID
X-App-Name
Tube-Return
Tube-Got-Results
Tube-Got-Eval
X-Amz-Storage-Class
X-Powered-By-VTEX-Cache
CDCHOST
X-Nginx-Cache-Key
X-GeoIP-Region-Code
Cache-Provider
C-Via
X-GoCache-CacheStatus
X-Origin-Time
Cdncip
Click-Count-Error
X-GeoIP
Click-Count-Action-Start
X-Node-Id
Cdnsip
X-GeoIP-Country-Code
X-VarnishDD-TTL
X-HN
X-VTEX-Cache-Time
X-VG-TLSProxy
X-Loc
X-Men
X-VG-WebCache
X-VTEX-Cache-Server
X-Mly-Id
X-WA-Info
Adler-Geo
AKAMAI
X-HS-Content-Campaign-Id
X-Mvc-Supplant-Cachable
XM
X-Geo-Header
X-NMSegId
X-Fmm-Version
Esi-Enabled
X-Gdpr
X-Nyt-Route
Fastly-SSL
X-FC-Vary-Parameters
Is-Eu
Host-ID
X-Origin-Response-Time
X-Fastly-Cache
X-NodeID
X-Forwarded-Site
Content-Style-Type
Country-Code
Content-Script-Type
X-HITS
X-Varnish-Beresp-Ttl
X-Tb-Optimization-Total-Bytes-Saved
X-Wikidot-Backend
X-Aicache-OS
X-Wikidot-Static-Cache
Yak-Timeinfo
X-Varnishpool
X-Request-Host
X-Eu-Site
X-Debug-Cache-Store
X-Request-Start
X-Up
X-Location
X-Micro-Cache
X-Pool
X-Ec-Custom-Error
X-Proxied-Request
X-Hash
X-Varnish-Authentication
X-RateLimit-Limit-Second
X-Contensis-Viewer-Groups
X-Depends
X-CUA
X-RateLimit-Remaining-Second
X-From
X-CGP
X-NCache
X-Slack-Shared-Secret-Outcome
X-Mvc-Supplant-OutputCached
X-Csrf-Jwt
X-Slack-Backend
X-Varnish-Beresp-Status
X-Debug-Cache-Fetch
X-Section
X-Human
X-Cache-Aspx
Ha-Gx-Prefs
HA-Ipaddr
Gh-Request-Id
Fastly-GeoIP-CountryCode
Fastly-Backend-Name
L
L5d-Success-Class
Release
Pramga
NGX
Machine
DSUID
Cluster
X-Tec-Api-Version
X-Tec-Api-Root
X-BBC-Edge-Cache-Status
X-Dc
X-MP-GENERATED-AT
X-Tec-Api-Origin
Apple-News-Services-Handled
Canary
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
Req-Svc-Chain
X-LiteSpeed-Cache-Control
V-Age
W
X-B3-Trace-ID
X-Access
True-Client-Country-4JS
X-Backend-Instance
X-AIR-PT
X-NGINX-Cache
Web-Mar-Region
X-Var-Ttl
X-We-Are-Hiring
X-Accel-Expires-Debug
X-Date
Proxy-Firewall
Cache-Key
We-Hiring
On-Server
Mail-Subject
X-Jungle-Id
X-Cs
X-Zone
X-Cache-FS-Status
X-Varnish-Hits
X-LB-ID
X-Cache-Backend
X-Akamai-Transformed
Debug
X-Vdms-Path
X-Uri
CDN-RequestId
WP-Super-Cache
Fastly-Drupal-HTML
X-Via-Poph
Pics-Label
Server-Info
Redirect-Candidate
X-Refresh
X-Via-Popn
X-Via-Popv
CloudFront-Viewer-Country
X-HA-Backend
X-Render-Time
X-Nananana
X-VHOST
BehaviorPad-Version
X-ApacheServer
X-Newrelic-Synthetics
X-PERF
X-Servedbyhost
SID
X-Datadome
X-M-Log
X-VC-TTL
GeoIP-Latitude
X-M-Reqid
X-Parent-Response-Time
X-B3-Parentspanid
X-CACHE-AGE
X-LB-NoCache
X-Response-Served-From
X-Original-Request-Id
X-APP
Locid
X-Content-Length
X-Cached-By
Datacenter
Fastly-Drupal-Html
X-DynaTrace-JS-Agent
X-Litespeed-Tag
X-TT-LOGID
X-Wa
Resin-Trace
Server-ID
X-Nc
Cf-Ipcountry
X-CS
Cdn
X-LiteSpeed-Tag
X-Amz-Meta-Cb-Modifiedtime
X-CDN-Cache-Status
X-IAuth-Set-Uid
X-VCache
X-ZONE
X-Old-Content-Length
NtCoent-Length
GeoIp-Country-Code
Vc-Max-Age
X-RequestId
X-Fpc
FSS-Cache
Ngx-Var-Key
Uri
X-Dispatcher-Number
X-Varnish-Beresp-TTL
X-NewRelic-App-Data
X-Platform-Processor
X-Platform-Router
Product
X-Platform-Cluster
Serverhost
True-Client-Ip
X-Esi
X-Vgn-Hpd-Reason
X-B3-Spanid
X-Srv
X-SERVER-NAME
X-TX-ID
X-HostName
X-Moov-T
X-TH-Server
True-Client-IP
CDN
X-Moov-Xdn-Version
X-Erf-Stays-Pdp-Viaduct-Migration-Web-V2
Srv
X-Cdn-Forward
Tcn
X-Nf-Language
X-Nf-Country
GeoIP-Country-Code
X-Ckpd-Fst-Backend
X-Nf-Ats-Version
X-TIME
X-Oracle-DMS-ECID
X-Bug-Bounty
X-Dynatrace-Js-Agent
X-FPC
ServerName
S-Rt
Cf-Device-Type
Cross-Origin-Embedder-Policy-Report-Only
X-Cdn-Cache-Status
X-HubSpot-Correlation-Id
Request-ID
X-S-Cookie
X-Vc
X-NC
X-WA
X-Destination
X-Dispatch
X-Application
X-B-Cookie
X-External-Request-Id
X-User
X-CACHE-KEY
CacheControlHeader
X-Zen-Fury
Server-Id
X-COUNTRY
Hostname
X-APP-VERSION
X-Cache-Date
Srvid
X-Webkit-Csp-Report-Only
X-Sigma-Backend
Geoip-Latitude
X-Sigma
X-FL-QIT-DEBUG
X-Instance-Name
X-Rocket-Build-Number
X-Presslabs-Stats
X-API-Version
X-Lb-Nocache
User-Agent
X-VCL-Version
X-Segment-20210421
X-Geo
Ohc-File-Size
X-VServer
X-Akamai-Device-Characteristics
X-Vmg-Version
X-Info
X-ServedByHost
X-Gamma-Serve
ServerHost
Origin-Trial
X-Ha-Backend
X-Via-PopV
X-Via-PopN
X-Branch-Name
X-Via-PopH
PICS-Label
Cneonction
Cloudfront-Viewer-Country
Xc-Version
X-App
Epwk-X-Cache
DataCenter
Load-Balancing
X-Ua
X-DataCenter
X-Correlation-ID
X-Limited
X-DynaTrace
Expect-Staple
X-Srcache-Store-Status
Rtss
X-Srcache-Fetch-Status
Type
X-MSEdge-Features
X-Lb-Id
X-Hit
X-Amz-Meta-Opti
X-MSEdge-Flight
X-MiniProfiler-Ids
X-Serial
X-Check-Cacheable
Ohc-Cache-HIT
X-Akamai-Pragma-Client-IP
Lb
Sm-Log-Id
X-Acquia-Site
Cross-Origin-Opener-Policy-Report-Only
X-Acquia-Application-UUID
X-Service-Response-Time
X-Sqd-Ctime
X-Acquia-Purge-Tags
X-Irp-Debug
Cmstype
X-Acquia-Application-Trace
X-Owner
Cmsid
X-Datacenter
Timeexpire
X-Web-Server
Warning
X-Sqd-Stime
X-Litespeed-Cache-Control
CountryCode
X-LAGOON
Servername
X-CSRF-TOKEN
X-Shopid
X-Shardid
X-Core-Mission
X-RAMCache
X-Origin-Upstream-Status
X-Sorting-Hat-Podid
N-Cache
Permission-Policy
Edge-Copy-Time
X-Requestid
X-Sorting-Hat-Shopid
X-Th-Server
X-Snapshot-Date
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
X-Dw-Trace-Id
X-Amz-Meta-S3b-Last-Modified
X-Amz-Meta-Sha256
Cl-Cache
X-Via-CDN
X-Udemy-Cache-App-Namespace
X-Ramcache
X-Qloud-Router
Ngx
X-Via-Edge
X-Via-SSL