Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
CF-RAY
Accept-Ranges
Expect-CT
Pragma
X-Powered-By
X-XSS-Protection
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Xss-Protection
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-Served-By
X-UA-Compatible
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Request-Id
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
Accept-CH
X-AspNet-Version
Content-Security-Policy-Report-Only
X-Runtime
Accept-CH-Lifetime
X-Ua-Compatible
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Cache-Status
X-Generator
Server-Timing
X-Cacheable
X-Envoy-Upstream-Service-Time
Timing-Allow-Origin
X-Request-ID
X-FRAME-OPTIONS
X-Iinfo
X-Drupal-Dynamic-Cache
X-Content-Security-Policy
Access-Control-Expose-Headers
Feature-Policy
X-CDN
Content-Encoding
Status
X-AspNetMvc-Version
Upgrade
CF-Ray
Access-Control-Max-Age
X-Via
X-Amz-Request-Id
X-Amz-Id-2
Cf-Edge-Cache
Host-Header
EagleId
Keep-Alive
Request-Context
X-Backend
X-Cache-Group
X-AH-Environment
X-Robots-Tag
X-Server
X-UA-Device
X-Hacker
X-Dns-Prefetch-Control
X-Turbo-Charged-By
X-Proxy-Cache
X-Ws-Request-Id
Xkey
X-Rq
X-Age
Permissions-Policy
X-Vhost
X-Amz-Version-Id
Allow
X-Dispatcher
Cf-Apo-Via
X-Swift-CacheTime
X-Swift-SaveTime
X-Server-Powered-By
Grace
Ali-Swift-Global-Savetime
X-Varnish-Cache
P3p
X-LiteSpeed-Cache
X-Page-Speed
X-Pingback
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Cache-Lookup
X-Device
X-OneAgent-JS-Injection
Cf-Railgun
X-Backend-Server
EagleEye-TraceId
X-Server-Id
X-WebKit-CSP
X-Host
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Response-Time
X-Readtime
X-Akam-SW-Version
Surrogate-Control
X-HW
X-Litespeed-Cache
Request-Id
X-Cloud-Trace-Context
X-Node
Content-Location
X-Application-Context
X-Nginx-Cache-Status
X-Nginx-Upstream-Cache-Status
X-CST
X-NWS-LOG-UUID
X-Ruxit-JS-Agent
Service-Worker-Allowed
X-Country-Code
X-Country
X-Url
X-Content-Type
X-Clacks-Overhead
Cache-Tag
X-Trace
X-Oneagent-Js-Injection
Rating
X-Rack-Cache
X-Amz-Server-Side-Encryption
Nginx-Cache
X-Server-Name
X-FTR-Request-ID
X-Times
X-PC
X-Vname
X-TtlSet
X-Daa-Tunnel
X-Webkit-Csp
Cross-Origin-Opener-Policy
X-Edge
X-Mcache
X-Midtier
X-Browser-Type
X-Powered-By-Plesk
X-ESI
X-Cnection
X-Upstream
Edge-Control
X-MS-InvokeApp
X-ECACHE
X-GitHub-Request-Id
X-D2id
X-Element-Page-Cache
Verso
X-Aws-Lambda-Call-Status
X-Ac
X-Kinja-Server
X-Exp-Variant
X-Cdn-Fetch
X-Exp-Id
X-GoogleNews-Bot
X-Kinja
X-Kinja-Revision
X-Kinja-Build
AR-PoweredBy
AR-Request-ID
AR-SID
AR-ATIME
X-Ruxit-Js-Agent
Accept-Ch-Lifetime
X-Ser
X-FastCGI-Cache
X-Vcap-Request-Id
X-Navigation-Version
X-Cache-TTL
X-Abt-Application-Version
X-Mod-Pagespeed
X-B3-TraceId
SPRequestDuration
SPIisLatency
AR-CACHE
X-NF-Request-ID
X-Dw-Request-Base-Id
SPRequestGuid
X-SharePointHealthScore
X-Amz-Rid
Fastly-Restarts
X-Client-IP
X-Erf-Bev-Bev
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-Instrumentation
X-Erf-Bev-Bev-Is-Generated
X-Middleton-Display
X-Sol
Display
Pagespeed
Edge-Cache-Tag
X-Mg-S
S
X-Edge-Location-Klb
X-Kinsta-Cache
X-Cache-Key
X-Powered-CMS
X-Amzn-Trace-Id
Response
X-Middleton-Response
Cache-Status
X-RateLimit-Remaining
X-VARITI-CCR
Access-Control-Request-Method
X-Version
X-Goog-Hash
X-Fastly-Request-ID
RTSS
X-ARC
X-Content-Digest
X-TraceId
X-Forwarded-For
Cross-Origin-Resource-Policy
X-Recruiting
X-Ua-Device
X-T
Realpath
Pinterest-Generated-By
Pinterest-Version
X-Pinterest-Rid
X-Correlation-Id
X-Varnish-TTL
X-MSEdge-Ref
MS-Author-Via
Front-End-Https
X-Cached
Fastcgi-Cache
X-Ratelimit-Limit
X-Ttl
Content-MD5
X-HS-Hub-Id
X-HS-Cache-Config
X-HS-Content-Id
X-Ua-Browser
X-FTR-Backend-Server
X-Country-Code-Real
X-FTR-Balancer
X-FTR-Cache-Status
Server-Node
Payment
X-FTR-Backend
X-Request-Received
X-Request-Processing-Time
X-PDP-UNCACHING-HASH
Arr-Disable-Session-Affinity
X-Protected-By
X-HS-Combine-CSS
X-Forwarded-Proto
Public-Key-Pins
MicrosoftSharePointTeamServices
X-LLID
X-Origin-Cache-Key
TP-Cache
X-Shield-Request-Id
X-Frontend
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Distributor
X-Accel-Expires
X-HP-Webp
X-Server-ID
X-FTR-Expires
X-Jurisdiction
X-HP-Trace-Id
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
Count-Hit
X-GUploader-UploadID
X-TTL
X-Origin-Server
X-Ratelimit-Remaining
X-LB-Cache
X-Ezoic-Cdn
X-Hits
X-ORACLE-DMS-RID
X-Content-Security-Policy-Report-Only
X-Microsite
X-Request-Handler-Origin-Region
X-AppVersion
X-Activity-Id
X-Az
X-Www-Served-By
X-B3-TraceId-Primal
Host
Mrf-Cache-Status
MRF-Tech
X-Varnish-Backend
X-Cluster-Name
Retry-After
Cache-Tags
X-Varnish-Server
X-App-Server
Accept-Charset
X-Amz-Meta-S3cmd-Attrs
Server-Name
X-Hostname
X-Id
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-PressLabs-Stats
X-NGENIX-Cache
X-Geo-Country
X-NODE
Cleartype
X-DIS-Request-ID
Referer-Policy
X-Envoy-Decorator-Operation
X-Oracle-Dms-Ecid
X-Goog-Metageneration
X-Upgrade-Enabled
TP-L2-Cache
X-Newrelic-App-Data
X-Seen-By
X-Amzn-RequestId
X-Amz-Apigw-Id
X-CSRF-Token
X-Git-Hash
Access-Control-Allow-Method
TCN
X-RateLimit-Limit
X-Azure-Ref
X-Hcs-Proxy-Type
X-CCDN-CacheTTL
X-F-Cache
X-Load-Cache
X-CCDN-Origin-Time
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Proxy
X-Unique-Id
X-Grace
X-Debug-Info
Healthy
X-Cache-Control
X-Revision
X-Px
Paypal-Debug-Id
Section-Io-Cache
X-Trace-Id
X-Request-Guid
Filterid
X-TT
DC
X-Page-Id
X-Contextid
X-B
X-FB-Debug
X-Type
X-B3-Sampled
X-Oracle-Dms-Rid
X-Fb-Rlafr
X-Logged-In
X-N
X-Mobile
X-ORACLE-DMS-ECID
X-WP-CF-Super-Cache
Viewport
X-WP-CF-Super-Cache-Cache-Control
X-XRDS-LOCATION
X-Debug
X-Varnish-Ttl
X-Whom
X-Template
Charset
X-Language
Fastly-SIE
Fastly-SWR
X-Time
X-Goog-Generation
X-Goog-Stored-Content-Length
X-Datadog-Trace-Id
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
X-Cache-Grace
X-Content-Options
X-Webkit-CSP
Version
X-Magnolia-Registration
X-Wix-Request-Id
X-Via-JSL
X-EdgeConnect-Cache-Status
X-RateLimit-Reset
Content-Disposition
X-App-Environment
X-Varnish-Grace
X-B-Cache
X-Signature
X-Node-Name
X-Origin-Cache
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
SRV
X-RemovedCookies
X-ProcessESI
X-Amzn-Remapped-Content-Length
X-B3-SpanId
X-Tumblr-User
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Yottaa-Optimizations
X-Tumblr-Pixel-1
X-Yottaa-Metrics
X-Debug-IsPreview
X-Debug-IsConnected
X-Rule
MS-CV
X-RTag
X-UUID
Ms-Operation-Id
SD-X-WS
X-G
X-Datadog-Sampled
X-Backend-Name
X-Amz-Replication-Status
X-Hl-Ver
X-Instance
X-FW-Server
X-Proxy-Cache-Info
GEO-INFO
X-Storage
X-Adobe-Content
X-FW-Type
X-FW-Static
X-Device-Type
X-FW-Serve
X-FW-Hash
X-FW-Dynamic
ServerID
X-Adobe-Loc
X-FW-Version
X-Is-Bot
X-NYM-Debug-Backend
X-Rendered-As
NGB
X-IPS-LoggedIn
Liferay-Portal
X-Region
X-Cacheable-TTL
Country
X-User-Agent
X-Cache-Hit
X-Environment-Context
X-Status
X-L-Path
X-Real-IP
X-NWS-UUID-VERIFY
X-ServerID
Countrycode
X-Rid
X-Cache-Age
X-Source
Akamai-GRN
Surrogate-Key
X-Sucuri-ID
X-Sucuri-Cache
Amp-Access-Control-Allow-Source-Origin
X-WP-CF-Super-Cache-Active
X-Servername
OT-Force-Account-Verify
From-Origin
Cross-Origin-Window-Policy
X-VC-Cache
X-UA
X-WebKit-CSP-Report-Only
X-RM-Cache-TTL
Upgrade-Insecure-Requests
Backend
X-Framework
X-INCAP-ABP
Front
X-Mode
X-Air-Pt
X-Xrds-Location
Refresh
X-AB
Frame-Options
X-Air-Trace-Id
X-Air-Source
X-Air-Hostname
X-Cache-Time
X-Content-Powered-By
X-HTML-Minification-Powered-By
X-Buckets
X-Akamai-Request-ID2
Xet-Cookie
X-DataDome
X-RID
X-Edge-Location
X-Handled-By
Webserver
X-Wormhole-Sdk
X-Endurance-Cache-Level
X-CDN-Forward
Url
Meta-Geo
X-Akamai-Edgescape
Selected-Fe
Filters
X-LJ-Flow-ID
X-Azure-Ref-OriginShield
X-JoinUs
X-Cluster
X-No-Session
X-Origin-Date
X-Rewrite-Enabled
X-Origin-CC
X-Origin-TTL
X-Reqid
X-Rn-Rsrv
X-Timing-Wait
X-SaId
X-VWS-Id
X-Webstats-RespID
X-Xfnlog-Site
X-AWS-Id
X-RCS-CacheZone
X-Proxy-Build
X-UPSTREAM-Address
X-Origin-Hint
TWC-Privacy
X-Cache-Rule
X-IPLB-Request-ID
TWC-GeoIP-LatLong
TWC-Locale-Group
WPO-Cache-Status
X-Labrador-Cache-Channel
Webcakes-Region
Webcakes-App-Version
Webcakes-App-Name
WPO-Cache-Message
TWC-GeoIP-Country
TWC-Device-Class
X-Fetched-On
X-Generation-Time
X-Drupal-Cache-Tags
X-Container-Uri
Mn-Server-Ip
X-Git-Commit
X-Logging-Id
X-IPLB-Instance
ServedBy
X-Served-From
TWC-Connection-Speed
Atl-Traceid
Property-Id
X-Cache-Operation
X-Origin
X-SRV
X-VCT
X-Ms-Request-Id
X-R9-Blue-Green-Version
X-Tumblr-Pixel-2
X-PHP-Host
X-Provided-By
Access-Control-Request-Headers
X-Vcache
X-Ms-Version
Section-Io-Id
X-Site-Version
TDXMobile
Thinkindot-CacheControl-Type
Thinkindot-Control
Cache
X-Scope-Id
X-Cms-Context
X-Redis-Cache
X-Varnish-Cache-Hits
X-Drupal-Cache-Contexts
X-CMSURLCustom
X-Restarts
X-Httpd
X-ProxyCache-Status
Thinkindot-CacheControl
X-Tb
X-Locale
X-Web-Node
X-Accel-Version
X-Shield-Cache-Expires
X-Adobe-Source
X-Cache-Debug
X-BYPASS-REASON
Web-Mar-Node
X-ProxyCache-Key
X-Thinkindot-L3
X-Extlb
X-Format
X-Browser-Name
X-Cache-Status-Check
X-Director
X-Upstream-Ht
X-Upstream-Ct
X-S
X-Routing-Service
X-Proxied
X-Geo-Region
X-Cloudmap
X-Frame-Option
X-Hosted-By
X-Zipkin-Id
X-Is-Mobile
X-Is-Desktop
X-Is-Supported-Browser
X-VC
X-Tcp-Rtt
X-Soup
X-Say-TTL
X-Is-Tablet
X-SayCDN-TTL
X-Say-Cacheable
Cache-Hits
Xserver
X-Lambda-Id
X-Loop
X-Cdn-Origin
X-Nginx-Cache
X-Tncms
X-Skip-Cache
X-Erf-Stays-Pdp-Viaduct-Migration-Web-V2
X-Forwarded-Host
Apigw-Requestid
X-Varnish-Age
X-GeoCountry
Accept-Language
X-Detected-As
X-GeoCode
X-Alternate-Cache-Key
X-Cache-Host
X-Storefront-Renderer-Rendered
X-Varnish-Beresp-Grace
X-Sorting-Hat-PodId
X-ShopId
X-Shopify-Stage
X-ShardId
X-Sorting-Hat-ShopId
X-XRDS-Location
X-Worker
X-Generated-By
X-Optimistic-Header
X-Vercel-Cache
X-Rocket-Nginx-Serving-Static
X-Lagoon
X-Vercel-Id
Azure-SlotName
Azure-Version
Azure-RegionName
Azure-SiteName
Azure-InstanceId
X-Tec-Api-Root
Source
X-Tec-Api-Origin
X-Tec-Api-Version
X-B3-Traceid
Node
CDN-PullZone
CDN-RequestId
CDN-RequestCountryCode
CDN-EdgeStorageId
CDN-Cache
CDN-CachedAt
CDN-RequestPullCode
X-Request-URI
LB
X-App-Version
CDN-Uid
X-WP-CF-Super-Cache-Cookies-Bypass
CDN-RequestPullSuccess
X-Pass-Why
Protected
Fastcgi-Useragent
Cross-Origin-Embedder-Policy
X-Vcl-Version
X-Tumblr-Pixel-3
Expiry
X-Connection-Hash
Alternate-Protocol
X-GEO
X-Cache-Server
X-Ratelimit-Reset
X-Cache-Expired-At
AMP-Access-Control-Allow-Source-Origin
DB-Nickname
Onion-Location
X-TA-CDN-Provider
X-COUNTRY
X-Server-W
X-Jobs
X-Fastly-Request-Id
CF-IPCountry
X-PHP-Backend
Environment
X-Response-Served-From
X-Fastcgi-Cache
X-Original-Request-Id
Uber-Trace-Id
X-Api-Version
Priority
X-Proxy-Cache-Status
X-LSADC-Cache
Sid
X-Uri
User-Cache-Control
X-Cluster-Node
X-Cache-Action
X-Urbn-Context-Path
X-Urbn-Site-Id
Locale
X-TT-LOGID
X-DC
X-Mg-Request-UUID
X-Tx-Id
HostName
X-MP-GENERATED-AT
X-FB-TRIP-ID
WP-Super-Cache
X-Epic-Correlation-Id
X-Conf
X-Cache-NE
X-FC-Vary-Parameters
X-Esi-Check
X-Clientip
A
X-Developer
X-Cache-Id
X-D
X-Device-Os
X-Dispatcher-Server
X-Content-Age
X-Ec-Fail
X-Ec-GeoHdr
X-A-Dcw
Gannett-Cam-Experience-Id
Vix-Hermes-Req-Id
T-Server
Surrogated-Key
Fusion-Template-Id
Fusion-Source
Fusion-Content-Id
Fusion-Content-Source
Fusion-Deployment-Id
Sslversion
Server-Host
Meta-Geo-Continent
Ngx.Var.Host
NM-Fastcgi-Cache
Origin-Agent-Cluster
MD5-Digest
Rendered-Blocks
Lang
Req-ID
Magicmarker
Fusion-Component-Id
Wxu-Next-Commit
X-Bc-Bl
X-Aed
Content-Secure-Policy
X-A-Wwc
X-BCube-Filmed-By
X-Bip
Candidate-Md5Url
X-Block-Status
X-Bl-Debug
X-A-Dgt
X-Forwarded-Site
X-A
Wxu-Next-Region
Wxu-Next-Hostname
Edge-Cache
X-A-Ccd
DCR-Decision-By
DCR-Processing-Time-Ms
X-A-Dam
Cache-Tv-Group
X-GeoIP
X-Op-Id-All
X-Vdms-Path
X-Varnish-Hostname
X-Org
X-Origin-Expires
X-Node-Id
X-NMSegId
X-Mvc-Supplant-Cachable
X-NCache
X-Rojux
X-Vdms-Version
X-UA-Device-Type
X-TIM-N
X-ScT
X-LiteSpeed-Cache-Control
X-SB
X-Request-Start
X-SRCache-Key
X-Test
X-Platform
X-Powered-By-VTEX-Cache
X-Proto
X-Thanos
X-Level-Front-Cache
X-ND-Cache
Origin
X-VTEX-Cache-Server
X-Gzip
X-GeoIP-City
X-Generated-On
X-Vtex-Remote-Cache
X-Gen-Mode
X-Hnp-Log
X-VTEX-Cache-Time
X-Jungle-Id
X-Viewer-Country
X-Ig-Origin-Region
X-URL
X-Origin-Response-Time
We-Hiring
Server-Hostname
XM
W
Origin-EX
X-Scheme
X-WA-Info
X-VG-WebCache
PFcat
X-SD-PageType
Origin-CC
Release
X-VarnishDD-TTL
X-Via-Fastly
X-Varnishpool
Yak-Timeinfo
X-Policy
X-Varnish-Director
Server-Ext
Ssr
Sever-Int
X-V-Cache
X-Var-Ttl
Powered-By
X-RateLimit-Limit-Second
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-HS-Content-Campaign-Id
X-HN
X-Loc
X-CUA
X-Nginx-Cache-Key
X-Mvc-Supplant-OutputCached
X-Csrf-Jwt
X-GeoIP-Region-Code
X-GeoIP-Country-Code
X-Fastly-Cache
X-From
X-Fmm-Version
X-Eu-Site
X-Gdpr
X-Geo-Header
X-Pubstack
X-Edge-Server
X-Core-Value
X-Nyt-Route
X-ApacheServer
X-App-Name
X-Auth-Group-Type
X-AK-Request-ID
X-RateLimit-Remaining-Second
X-Req
X-Render-Time
X-Region-Sid
X-Auto-Login
X-Backend-Instance
X-Cache-TTL-Remaining
X-Cdn-Srv
X-CGP
X-Cache-Info
X-Origin-Time
X-PERF
X-PAYTM-SRV-ID
X-Cache-Bucket
X-Request-Time
X-Amz-Storage-Class
Canary
X-Tt-Logid
Fastly-SSL
CDCHOST
Cache-Provider
C-Via
Host-ID
HA-Ipaddr
Ha-Gx-Prefs
Cdn-Host
Fastly-Backend-Name
Content-Style-Type
X-Zone
Content-Script-Type
Cdnsip
DSUID
Cdn-Request-Time
Esi-Enabled
Cdncip
X-NGINX-Cache
Cdn-Requestid
X-ECache
X-Varnish-Beresp-Ttl
AKAMAI
Mail-Subject
L5d-Success-Class
X-Newrelic-Synthetics
X-BBC-Edge-Cache-Status
X-B3-Trace-ID
X-Human
X-Location
X-Mly-Id
X-Micro-Cache
X-GoCache-CacheStatus
X-Request-Host
Apple-News-Services-Host
X-Tb-Optimization-Total-Bytes-Saved
Click-Count-Error
X-SVT-ORM-VERSION
Click-Count-Action-Start
X-Ec-Custom-Error
X-DPWN-IS-SECURE
Cache-Key
X-Service
Adler-Geo
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
X-Section
X-Proxied-Request
X-Cache-Backend
On-Server
X-Contensis-Viewer-Groups
Apple-News-Services-Handled
X-Pool
X-Cache-Aspx
Cluster
X-SVT-ORM-RULES
X-We-Are-Hiring
Is-Eu
X-Wikidot-Static-Cache
L
True-Client-Country-4JS
Tube-Get-Contents
Tube-Return
Tube-Got-Results
Tube-Got-Eval
RNT-Time
RNT-Machine
Gh-Request-Id
Platform
X-Ig-Push-State
X-Varnish-Beresp-Status
Pramga
Producers
Req-Svc-Chain
Machine
Redirect-Candidate
X-VG-TLSProxy
X-Wikidot-Backend
X-Ad-Load-Variation
X-Acquia-Purge-Cdn-Unconfigured
X-Varnish-Authentication
X-Access
Web-Mar-Region
X-Aicache-OS
Fastly-GeoIP-CountryCode
V-Age
X-AIR-PT
Odigeo-Trace-Id
NGX
X-Sn-Servicetimems
X-Server-IP
Country-Code
X-Up
X-Fastly-Backend
X-CacheTTL
X-Hash
X-Men
Datacenter
X-NodeID
Proxy-Firewall
X-Accel-Expires-Debug
X-Date
Debug
X-Slack-Shared-Secret-Outcome
X-Custom-Header
X-Slack-Backend
X-Varnish-Hits
X-Dc
X-Ismobilevalue
X-LB-ID
SID
X-Akamai-Transformed
X-Cs
X-ID
X-CACHE-GROUP
X-Refresh
Locid
X-Nananana
Fastly-Drupal-HTML
X-Pad
X-Nf-Request-Id
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-DefHash
X-Varnish-Remaining-TTL
X-Platform-Router
X-Platform-Processor
X-DefElseHash
X-Platform-Cluster
X-Client-Ip
X-HOST
X-Amz-Meta-Cb-Modifiedtime
Pics-Label
CloudFront-Viewer-Country
Mime-Version
X-Depends
X-VHOST
X-HA-Backend
X-Servedbyhost
X-Via-Poph
X-Via-Popn
X-Via-Popv
X-LiteSpeed-Tag
X-Cached-By
X-Datadome
X-M-Reqid
X-Old-Content-Length
X-CACHE-AGE
GeoIP-Latitude
X-M-Log
X-VC-TTL
Ngx-Var-Key
X-Parent-Response-Time
X-Presslabs-Stats
X-Cache-FS-Status
X-LB-NoCache
X-TH-Server
X-CS
X-CDN-Cache-Status
X-Moov-T
X-Moov-Xdn-Version
Cross-Origin-Embedder-Policy-Report-Only
X-TIME
X-NewRelic-App-Data
X-B3-Parentspanid
GeoIp-Country-Code
Resin-Trace
Cdn
Cf-Ipcountry
Fastly-Drupal-Html
X-DynaTrace-JS-Agent
X-Wa
Server-Info
Server-ID
X-Nc
NtCoent-Length
X-Litespeed-Tag
BehaviorPad-Version
Cf-Device-Type
Uri
X-External-Request-Id
X-Vgn-Hpd-Reason
X-Application
X-User
X-S-Cookie
X-VCache
X-Destination
X-B-Cookie
X-HITS
FSS-Cache
X-Zen-Fury
X-ZONE
X-IAuth-Set-Uid
X-APP
True-Client-IP
X-Vc
X-Providence-Cookie
X-Route-Name
X-Is-Crawler
X-Flags
X-Aspnet-Duration-Ms
X-Sigma-Backend
X-Fpc
X-Instance-Name
X-Cache-Date
X-Sigma
X-Rocket-Build-Number
X-Esi
X-HostName
X-TX-ID
CDN
X-API-Version
X-Srv
X-DynaTrace
X-Content-Length
True-Client-Ip
X-Dynatrace-Js-Agent
X-VServer
X-Varnish-Beresp-TTL
X-Branch-Name
Load-Balancing
X-Segment-20210421
Tcn
X-Oracle-DMS-ECID
X-Page-View
Serverhost
GeoIP-Country-Code
Srv
Hostname
Ohc-File-Size
Request-ID
X-NC
X-DataCenter
X-WA
X-FPC
X-Cdn-Cache-Status
S-Rt
X-Dispatch
X-Cdn-Forward
X-Dispatcher-Number
X-RequestId
Vc-Max-Age
Type
Product
X-B3-Spanid
X-Sql-Count
X-APP-VERSION
X-Http-Reason
X-Sql-Duration-Ms
Srvid
X-Irp-Debug
Server-Id
X-Webkit-Csp-Report-Only
Geoip-Latitude
X-FL-QIT-DEBUG
ServerName
Cl-Cache
X-Lb-Nocache
X-Geo
WZWS-RAY
X-ServedByHost
X-Bug-Bounty
X-Ckpd-Fst-Backend
X-Owner
X-SIPLIST1
X-Via-CDN
X-Via-Edge
X-CSRF-TOKEN
DataCenter
IsBot
Edge-Copy-Time
X-Via-SSL
X-VCL-Version
X-Core-Mission
Epwk-X-Cache
Origin-Trial
Cloudfront-Viewer-Country
X-Proxy-CacheRZ
Cross-Origin-Opener-Policy-Report-Only
Ohc-Cache-HIT
XkeyRZ
MIME-Version
CacheControlHeader
X-Hit
X-Cache-Ttl
X-Correlation-ID
X-App
N-Cache
ServerHost
X-Via-PopH
X-Ha-Backend
X-Via-PopV
X-Ua
PICS-Label
X-Lb-Id
CountryCode
X-Via-PopN
X-Qloud-Router
X-Srcache-Store-Status
X-Srcache-Fetch-Status
Rtss
X-MSEdge-Flight
X-Amz-Meta-Opti
X-MSEdge-Features
X-MiniProfiler-Ids
X-Fastly-Country-Code
Lb
Sm-Log-Id
X-Acquia-Site
X-Acquia-Purge-Tags
X-Acquia-Application-UUID
X-Acquia-Application-Trace
X-Sqd-Ctime
X-Sqd-Stime
X-Service-Response-Time
Warning
X-Datacenter
X-Web-Server
X-LAGOON
X-Akamai-Device-Characteristics
X-Vmg-Version
X-Limited
X-Litespeed-Cache-Control
User-Agent
X-Amz-Meta-S3b-Last-Modified
X-IN-APIGATEWAYSSL
X-Dw-Trace-Id
X-Udemy-Cache-App-Namespace
X-Amz-Meta-Sha256
X-IN-APIGATEWAY
Cneonction
X-CF-Lambda-Fn
X-Requestid
X-Proxy-Cache-La3
X-Akamai-Pragma-Client-IP
X-RAMCache
Xkey-La3
X-Forwarded-Path
X-Orig-Expires
X-Shop-Environment
X-Tenant
Akamai-Cache-Status
X-Check-Cacheable
Xkeylog
Ngx
X-Cdn-Request-ID
X-Cache-Type
X-Snapshot-Date
X-Ramcache
X-CF-Lambda-Version
X-Serial
X-Th-Server
Expect-Staple