Threat Level: green Handler on Duty: Daniel Wesemann

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
CF-RAY
Expect-CT
Accept-Ranges
X-XSS-Protection
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Xss-Protection
P3P
X-Cache-Hits
X-UA-Compatible
X-Served-By
X-Download-Options
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Request-Id
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
X-AspNet-Version
Accept-CH
Content-Security-Policy-Report-Only
X-Runtime
Accept-CH-Lifetime
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Request-ID
X-Check
X-Cache-Status
X-Ua-Compatible
X-Generator
Server-Timing
X-Cacheable
X-Envoy-Upstream-Service-Time
Timing-Allow-Origin
X-FRAME-OPTIONS
X-Iinfo
X-Drupal-Dynamic-Cache
X-Content-Security-Policy
Access-Control-Expose-Headers
Feature-Policy
X-CDN
Content-Encoding
Status
X-AspNetMvc-Version
Upgrade
CF-Ray
Access-Control-Max-Age
X-Amz-Request-Id
X-Via
X-Amz-Id-2
Cf-Edge-Cache
Host-Header
EagleId
Keep-Alive
Request-Context
X-Backend
X-Cache-Group
X-AH-Environment
X-Robots-Tag
X-Server
X-UA-Device
X-Hacker
X-Dns-Prefetch-Control
X-Turbo-Charged-By
X-Proxy-Cache
X-Ws-Request-Id
Xkey
Permissions-Policy
X-Rq
X-Age
X-Vhost
X-Amz-Version-Id
Allow
X-Dispatcher
Cf-Apo-Via
X-Swift-SaveTime
X-Swift-CacheTime
X-Server-Powered-By
Grace
Ali-Swift-Global-Savetime
X-Varnish-Cache
X-LiteSpeed-Cache
X-Page-Speed
X-Pingback
X-Cache-Lookup
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-OneAgent-JS-Injection
X-Device
Cf-Railgun
X-Backend-Server
EagleEye-TraceId
X-Host
X-Server-Id
X-WebKit-CSP
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Response-Time
X-Readtime
X-Akam-SW-Version
Surrogate-Control
X-HW
Request-Id
X-Cloud-Trace-Context
X-Ruxit-JS-Agent
Content-Location
X-Application-Context
X-Node
X-Nginx-Cache-Status
P3p
X-Nginx-Upstream-Cache-Status
X-NWS-LOG-UUID
X-CST
X-Country
X-Litespeed-Cache
Service-Worker-Allowed
X-Country-Code
X-Content-Type
X-Url
X-Clacks-Overhead
Cache-Tag
X-Trace
X-Webkit-Csp
Rating
X-Rack-Cache
X-Amz-Server-Side-Encryption
Nginx-Cache
X-Server-Name
X-Times
X-FTR-Request-ID
X-PC
X-Vname
X-TtlSet
X-Daa-Tunnel
X-Oneagent-Js-Injection
Cross-Origin-Opener-Policy
X-Mcache
X-Edge
X-Midtier
X-Browser-Type
X-Powered-By-Plesk
X-ESI
X-Cnection
X-Upstream
X-GitHub-Request-Id
X-ECACHE
X-MS-InvokeApp
X-D2id
Edge-Control
X-Element-Page-Cache
Verso
X-Ac
X-Exp-Id
X-Kinja
X-Exp-Variant
X-Cdn-Fetch
X-GoogleNews-Bot
X-Kinja-Build
X-Kinja-Revision
X-Kinja-Server
AR-SID
AR-Request-ID
AR-PoweredBy
AR-ATIME
Accept-Ch-Lifetime
X-Vcap-Request-Id
X-Ser
X-Cache-TTL
X-Navigation-Version
X-FastCGI-Cache
X-Abt-Application-Version
X-B3-TraceId
X-Aws-Lambda-Call-Status
AR-CACHE
SPRequestDuration
SPIisLatency
X-Mod-Pagespeed
X-NF-Request-ID
X-Dw-Request-Base-Id
X-SharePointHealthScore
SPRequestGuid
X-Amz-Rid
Fastly-Restarts
X-Client-IP
X-Erf-Bev-Bev
X-Kraken-Loop-Name
X-Instrumentation
X-Erf-Bev-Bev-Is-Generated
X-Server-Lifecycle-Phase
Pagespeed
X-Sol
Display
X-Middleton-Display
X-Ruxit-Js-Agent
Edge-Cache-Tag
X-Mg-S
S
X-Kinsta-Cache
X-Edge-Location-Klb
X-Powered-CMS
X-Middleton-Response
Response
X-Amzn-Trace-Id
Cache-Status
X-RateLimit-Remaining
X-Cache-Key
X-Goog-Hash
Access-Control-Request-Method
X-Version
X-VARITI-CCR
X-Fastly-Request-ID
X-ARC
RTSS
X-Content-Digest
X-Forwarded-For
X-TraceId
Cross-Origin-Resource-Policy
X-Ua-Device
X-Recruiting
X-T
Realpath
X-Varnish-TTL
X-Correlation-Id
X-MSEdge-Ref
Front-End-Https
Fastcgi-Cache
X-Pinterest-Rid
Pinterest-Generated-By
Pinterest-Version
MS-Author-Via
X-Ratelimit-Limit
X-Cached
X-PDP-UNCACHING-HASH
Content-MD5
X-HS-Hub-Id
X-HS-Cache-Config
X-HS-Content-Id
X-Ua-Browser
X-Protected-By
X-FTR-Cache-Status
X-FTR-Backend-Server
X-Country-Code-Real
X-FTR-Balancer
Server-Node
Payment
X-FTR-Backend
Public-Key-Pins
X-Request-Received
X-Request-Processing-Time
X-Shield-Request-Id
X-HS-Combine-CSS
X-Forwarded-Proto
MicrosoftSharePointTeamServices
Arr-Disable-Session-Affinity
TP-Cache
X-Frontend
X-TTL
X-LLID
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Ttl
X-Distributor
X-HP-Webp
X-Jurisdiction
X-Server-ID
X-HP-Trace-Id
X-FTR-Expires
X-Accel-Expires
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-ORACLE-DMS-RID
X-NODE
Count-Hit
Accept-Ch
X-GUploader-UploadID
X-Ratelimit-Remaining
X-Origin-Server
X-LB-Cache
X-Origin-Cache-Key
X-Ezoic-Cdn
X-Hits
X-Microsite
X-Request-Handler-Origin-Region
X-Content-Security-Policy-Report-Only
X-Activity-Id
X-AppVersion
X-PressLabs-Stats
X-Az
Host
X-Www-Served-By
X-B3-TraceId-Primal
MRF-Tech
X-Cluster-Name
Mrf-Cache-Status
X-Varnish-Backend
X-App-Server
Cache-Tags
X-Varnish-Server
Retry-After
Accept-Charset
X-Amz-Meta-S3cmd-Attrs
Server-Name
X-Hostname
Cleartype
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Geo-Country
X-NGENIX-Cache
X-Newrelic-App-Data
X-Id
X-Envoy-Decorator-Operation
X-Goog-Metageneration
Referer-Policy
X-CSRF-Token
X-ORACLE-DMS-ECID
X-DIS-Request-ID
X-Upgrade-Enabled
TP-L2-Cache
X-Git-Hash
Access-Control-Allow-Method
X-Seen-By
X-Azure-Ref
X-CCDN-CacheTTL
X-CCDN-Origin-Time
X-Unique-Id
X-Hcs-Proxy-Type
X-Load-Cache
X-F-Cache
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-RateLimit-Limit
X-Proxy
X-Amz-Apigw-Id
Filterid
X-Amzn-RequestId
X-Grace
X-Trace-Id
X-Revision
Healthy
X-Px
X-Request-Guid
X-Cache-Control
TCN
Section-Io-Cache
X-XRDS-LOCATION
X-Debug-Info
Paypal-Debug-Id
X-B3-Sampled
X-Contextid
X-B
X-TT
DC
X-Fb-Rlafr
X-Oracle-Dms-Ecid
X-Page-Id
X-FB-Debug
X-Type
X-Logged-In
X-Mobile
X-N
Viewport
X-WP-CF-Super-Cache-Cache-Control
X-Debug
X-WP-CF-Super-Cache
X-Varnish-Ttl
X-Oracle-Dms-Rid
X-Whom
X-Template
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
Fastly-SWR
X-Goog-Storage-Class
X-Language
Fastly-SIE
X-Goog-Generation
X-Time
Charset
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
X-Datadog-Trace-Id
X-Content-Options
X-Cache-Grace
X-Webkit-CSP
Version
X-Via-JSL
Content-Disposition
X-Magnolia-Registration
X-Wix-Request-Id
X-Varnish-Grace
X-App-Environment
X-EdgeConnect-Cache-Status
X-B-Cache
X-Signature
X-Node-Name
X-Origin-Cache
X-Rule
X-ProcessESI
X-B3-SpanId
X-RemovedCookies
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
SRV
X-Tumblr-Pixel
X-RateLimit-Reset
X-Tumblr-Pixel-1
X-Yottaa-Metrics
X-Backend-Name
X-Debug-IsConnected
X-Hl-Ver
X-Tumblr-User
X-Datadog-Sampled
X-Yottaa-Optimizations
X-Debug-IsPreview
X-Tumblr-Pixel-0
X-G
X-Amzn-Remapped-Content-Length
SD-X-WS
X-RTag
X-Amz-Replication-Status
Ms-Operation-Id
X-UUID
MS-CV
X-Cache-Age
X-FW-Static
X-Device-Type
X-Adobe-Content
X-FW-Hash
X-FW-Serve
X-FW-Server
X-Storage
X-Proxy-Cache-Info
X-FW-Type
GEO-INFO
ServerID
X-Adobe-Loc
X-Instance
X-FW-Version
X-FW-Dynamic
Country
NGB
Liferay-Portal
X-Cacheable-TTL
Countrycode
X-User-Agent
X-Is-Bot
X-NYM-Debug-Backend
X-Rendered-As
X-Status
X-IPS-LoggedIn
X-Region
X-L-Path
X-Cache-Hit
X-Environment-Context
Surrogate-Key
X-Real-IP
X-NWS-UUID-VERIFY
X-Rid
X-Source
X-ServerID
X-Sucuri-ID
Akamai-GRN
X-Sucuri-Cache
Cross-Origin-Window-Policy
OT-Force-Account-Verify
X-WP-CF-Super-Cache-Active
X-Servername
From-Origin
X-VC-Cache
X-UA
X-WebKit-CSP-Report-Only
X-RM-Cache-TTL
X-Framework
Front
Backend
Upgrade-Insecure-Requests
Amp-Access-Control-Allow-Source-Origin
X-INCAP-ABP
X-Mode
X-Xrds-Location
Refresh
X-Wormhole-Sdk
X-AB
X-Content-Powered-By
X-Air-Source
X-Cache-Time
X-Air-Trace-Id
X-Air-Hostname
X-Handled-By
X-Akamai-Request-ID2
X-Buckets
X-HTML-Minification-Powered-By
Xet-Cookie
Frame-Options
X-RID
X-Edge-Location
X-Air-Pt
X-Endurance-Cache-Level
X-VC
X-Nginx-Cache
Url
Webserver
Selected-Fe
X-Cluster
Filters
X-Reqid
ServedBy
Meta-Geo
X-Timing-Wait
X-Rewrite-Enabled
X-RCS-CacheZone
X-Rn-Rsrv
X-SaId
X-Origin-CC
X-Proxy-Build
X-UPSTREAM-Address
X-Origin-Date
X-Xfnlog-Site
X-JoinUs
X-Webstats-RespID
X-No-Session
X-Origin-TTL
TWC-Device-Class
X-Provided-By
X-Cache-Rule
X-Served-From
TWC-Locale-Group
X-Labrador-Cache-Channel
X-Tumblr-Pixel-2
TWC-GeoIP-Country
X-Cache-Operation
X-R9-Blue-Green-Version
X-Azure-Ref-OriginShield
WPO-Cache-Message
TWC-Privacy
WPO-Cache-Status
TWC-Connection-Speed
TWC-GeoIP-LatLong
X-Logging-Id
Cache
X-AWS-Id
X-Origin-Hint
X-Container-Uri
X-Drupal-Cache-Tags
X-Origin
Cache-Hits
X-Akamai-Edgescape
Property-Id
X-Git-Commit
Webcakes-App-Name
Webcakes-App-Version
X-VWS-Id
X-PHP-Host
Webcakes-Region
X-LJ-Flow-ID
Atl-Traceid
X-DataDome
Access-Control-Request-Headers
X-Cache-Status-Check
X-SRV
X-Locale
X-Ms-Request-Id
Section-Io-Id
X-Ms-Version
Mn-Server-Ip
X-ProxyCache-Key
X-Routing-Service
Accept-Language
X-Scope-Id
X-CMSURLCustom
X-Redis-Cache
TDXMobile
X-ProxyCache-Status
X-Proxied
Thinkindot-CacheControl-Type
X-Drupal-Cache-Contexts
X-Extlb
X-Adobe-Source
X-BYPASS-REASON
X-Cache-Debug
X-Cms-Context
X-Cloudmap
X-Accel-Version
X-Fetched-On
Thinkindot-Control
X-Shield-Cache-Expires
X-Httpd
X-Hosted-By
Web-Mar-Node
X-Generation-Time
Thinkindot-CacheControl
X-Restarts
X-Varnish-Cache-Hits
X-Tb
X-VCT
X-Web-Node
X-Zipkin-Id
X-Site-Version
X-Thinkindot-L3
X-Tncms
X-Say-Cacheable
X-Is-Desktop
X-Director
X-Is-Supported-Browser
X-Tcp-Rtt
X-Lambda-Id
X-Is-Tablet
X-Upstream-Ct
X-Upstream-Ht
X-Forwarded-Host
X-Format
X-Browser-Name
X-Geo-Region
X-SayCDN-TTL
X-Varnish-Age
X-Varnish-Beresp-Grace
X-CDN-Forward
X-Loop
X-Is-Mobile
X-Soup
X-Skip-Cache
X-S
Apigw-Requestid
X-Say-TTL
Xserver
X-Cache-Host
X-Shopify-Stage
X-Frame-Option
X-Storefront-Renderer-Rendered
X-GeoCode
X-GeoCountry
X-Detected-As
X-IPLB-Instance
X-Sorting-Hat-PodId
X-ShardId
X-IPLB-Request-ID
X-ShopId
X-Cdn-Origin
X-Alternate-Cache-Key
X-Sorting-Hat-ShopId
X-Vcache
X-Generated-By
X-Optimistic-Header
X-Lagoon
X-Worker
X-Rocket-Nginx-Serving-Static
X-Tec-Api-Version
X-Tec-Api-Root
X-Tec-Api-Origin
X-Vercel-Id
Source
X-Vercel-Cache
Azure-SiteName
Azure-Version
Azure-SlotName
Azure-RegionName
X-B3-Traceid
Azure-InstanceId
X-Request-URI
Node
X-Fastcgi-Cache
X-Ratelimit-Reset
X-WP-CF-Super-Cache-Cookies-Bypass
Fastcgi-Useragent
X-URL
Protected
CDN-EdgeStorageId
X-Pass-Why
CDN-CachedAt
CDN-PullZone
CDN-RequestCountryCode
AMP-Access-Control-Allow-Source-Origin
CDN-RequestPullSuccess
CDN-Cache
CDN-RequestPullCode
CDN-Uid
LB
X-Vcl-Version
Cross-Origin-Embedder-Policy
X-Erf-Stays-Pdp-Viaduct-Migration-Web-V2
X-App-Version
Expiry
X-Connection-Hash
X-Tumblr-Pixel-3
X-TA-CDN-Provider
CDN-RequestId
Onion-Location
Alternate-Protocol
X-XRDS-Location
X-Cache-Expired-At
X-Cache-Server
X-GEO
X-PHP-Backend
Priority
DB-Nickname
X-Api-Version
Sid
X-Jobs
X-Server-W
Environment
X-Fastly-Request-Id
Uber-Trace-Id
CF-IPCountry
X-Proxy-Cache-Status
X-Cluster-Node
X-Cache-Action
X-Urbn-Context-Path
X-Urbn-Site-Id
User-Cache-Control
HostName
Locale
X-LSADC-Cache
X-Uri
X-Mg-Request-UUID
X-MP-GENERATED-AT
X-Original-Request-Id
X-Tt-Logid
Cdn-Requestid
X-Response-Served-From
X-AIR-PT
X-Epic-Correlation-Id
Fusion-Component-Id
X-Esi-Check
Edge-Cache
DCR-Processing-Time-Ms
Fusion-Deployment-Id
Fusion-Content-Id
Fusion-Template-Id
DCR-Decision-By
Fusion-Source
Fusion-Content-Source
Gannett-Cam-Experience-Id
Cache-Tv-Group
X-Hnp-Log
X-ScT
X-Gzip
X-Ig-Origin-Region
X-SB
X-Jungle-Id
X-SRCache-Key
A
X-GeoIP-City
X-FC-Vary-Parameters
X-FB-TRIP-ID
X-Forwarded-Site
Candidate-Md5Url
X-Gen-Mode
X-Ec-GeoHdr
Content-Secure-Policy
Lang
X-BCube-Filmed-By
X-Bc-Bl
Vix-Hermes-Req-Id
X-Bip
X-Bl-Debug
Surrogated-Key
T-Server
X-Block-Status
Wxu-Next-Commit
Wxu-Next-Hostname
X-A-Dgt
X-A-Wwc
X-Aed
X-A-Dcw
X-A-Dam
Wxu-Next-Region
X-A
X-A-Ccd
Sslversion
Server-Host
Meta-Geo-Continent
X-Developer
X-D
MD5-Digest
Magicmarker
X-Dispatcher-Server
X-Level-Front-Cache
X-Device-Os
Ngx.Var.Host
Origin
Req-ID
X-Cache-NE
X-Cache-Id
Rendered-Blocks
X-Clientip
Origin-Agent-Cluster
X-Content-Age
X-Conf
X-Ec-Fail
X-Generated-On
X-VTEX-Cache-Time
X-DC
X-VTEX-Cache-Server
X-Node-Id
X-Varnish-Hostname
X-Powered-By-VTEX-Cache
X-ND-Cache
X-Op-Id-All
X-Vdms-Path
X-UA-Device-Type
X-TIM-N
X-Origin-Expires
X-Org
X-Vdms-Version
X-Viewer-Country
X-Varnish-Beresp-Ttl
X-Rojux
X-NCache
X-Vtex-Remote-Cache
X-Mvc-Supplant-Cachable
X-Proto
X-Platform
X-Request-Start
X-Thanos
X-Policy
X-Pubstack
X-Tx-Id
X-TT-LOGID
X-Origin-Response-Time
X-LiteSpeed-Cache-Control
L5d-Success-Class
X-Test
Host-ID
Origin-EX
Origin-CC
X-CUA
X-Debug-Cache-Store
Mail-Subject
PFcat
X-Debug-Cache-Fetch
NM-Fastcgi-Cache
X-Csrf-Jwt
X-WA-Info
X-Core-Value
X-VG-WebCache
X-Auto-Login
X-ID
We-Hiring
W
X-Varnish-Director
X-Backend-Instance
X-Var-Ttl
X-Req
X-Amz-Storage-Class
X-Varnish-Beresp-Status
X-App-Name
X-Auth-Group-Type
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-VarnishDD-TTL
X-Varnishpool
HA-Ipaddr
X-Cache-Info
X-Cache-TTL-Remaining
X-Cdn-Srv
Powered-By
X-CGP
X-Cache-Bucket
Server-Ext
X-ECache
Ssr
Sever-Int
Server-Hostname
X-V-Cache
X-Via-Fastly
Ha-Gx-Prefs
Cache-Provider
Canary
C-Via
X-Region-Sid
X-Geo-Header
X-Mvc-Supplant-OutputCached
X-Ig-Push-State
Cdncip
Cdn-Request-Time
Cdn-Host
CDCHOST
X-GeoIP
AKAMAI
X-HN
X-NMSegId
X-Nginx-Cache-Key
X-Service
X-Nyt-Route
X-HS-Content-Campaign-Id
X-GeoIP-Country-Code
X-Scheme
X-SD-PageType
X-GeoIP-Region-Code
X-Gdpr
Cdnsip
X-Request-Time
X-PAYTM-SRV-ID
X-Ismobilevalue
X-Loc
X-Eu-Site
X-Edge-Server
Fastly-Backend-Name
WP-Super-Cache
X-Fastly-Cache
Content-Style-Type
X-AK-Request-ID
Gh-Request-Id
X-Fmm-Version
Yak-Timeinfo
X-Origin-Time
XM
Content-Script-Type
Fastly-SSL
X-Newrelic-Synthetics
X-B3-Trace-ID
X-Server-IP
X-Location
X-Varnish-Authentication
X-BBC-Edge-Cache-Status
X-Render-Time
X-ApacheServer
X-Sn-Servicetimems
X-Proxied-Request
X-Human
X-Mly-Id
X-Micro-Cache
X-Tb-Optimization-Total-Bytes-Saved
X-Wikidot-Static-Cache
X-SVT-ORM-VERSION
X-Fastly-Backend
X-SVT-ORM-RULES
X-Wikidot-Backend
X-We-Are-Hiring
X-Ec-Custom-Error
X-DPWN-IS-SECURE
X-PERF
X-From
X-Contensis-Viewer-Groups
X-GoCache-CacheStatus
X-Cache-Aspx
X-Pool
X-Section
Odigeo-Trace-Id
X-Cache-Backend
X-CacheTTL
X-VG-TLSProxy
X-Men
X-Request-Host
Platform
Req-Svc-Chain
Release
Redirect-Candidate
RNT-Machine
RNT-Time
Click-Count-Error
Cluster
Country-Code
DSUID
Producers
Is-Eu
L
Machine
On-Server
Fastly-GeoIP-CountryCode
Pramga
X-Dc
Esi-Enabled
Click-Count-Action-Start
True-Client-Country-4JS
Web-Mar-Region
Tube-Get-Contents
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
Apple-News-Services-Handled
X-Acquia-Purge-Cdn-Unconfigured
Adler-Geo
X-Access
X-Ad-Load-Variation
Apple-News-Services-Request-Url
V-Age
Tube-Got-Results
Tube-Return
X-Aicache-OS
Cache-Key
Tube-Got-Eval
X-Zone
X-NGINX-Cache
X-Hash
X-Slack-Shared-Secret-Outcome
NGX
X-Slack-Backend
X-Up
X-Date
Proxy-Firewall
X-NodeID
X-Custom-Header
X-Accel-Expires-Debug
X-Cs
X-LB-ID
Debug
X-Varnish-Hits
X-COUNTRY
X-Pad
X-DefElseHash
X-Nananana
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
X-CACHE-GROUP
X-DefHash
X-Varnish-CookieHashed-On
Datacenter
X-Nf-Request-Id
X-Client-Ip
Mime-Version
X-Via-Popv
X-Via-Popn
X-Datadome
X-Via-Poph
X-Refresh
Pics-Label
Locid
X-Depends
X-HA-Backend
X-Akamai-Transformed
Fastly-Drupal-HTML
SID
X-VHOST
CloudFront-Viewer-Country
X-Amz-Meta-Cb-Modifiedtime
X-VC-TTL
X-Platform-Router
X-Platform-Cluster
X-LiteSpeed-Tag
X-Platform-Processor
X-M-Log
X-M-Reqid
X-Cache-FS-Status
X-Servedbyhost
Ngx-Var-Key
X-LB-NoCache
X-Cached-By
GeoIP-Latitude
X-Parent-Response-Time
X-Old-Content-Length
X-CACHE-AGE
Fastly-Drupal-Html
X-B3-Parentspanid
X-TIME
X-DynaTrace-JS-Agent
X-VCache
X-TH-Server
Resin-Trace
Server-ID
X-CDN-Cache-Status
X-Moov-T
X-Moov-Xdn-Version
Server-Info
X-CS
Cf-Ipcountry
GeoIp-Country-Code
BehaviorPad-Version
X-Litespeed-Tag
Cross-Origin-Embedder-Policy-Report-Only
X-Presslabs-Stats
Cdn
X-ZONE
X-Vgn-Hpd-Reason
X-APP
X-HITS
X-Nc
NtCoent-Length
X-Wa
X-S-Cookie
X-Destination
X-External-Request-Id
Cf-Device-Type
X-IAuth-Set-Uid
X-NewRelic-App-Data
FSS-Cache
X-B-Cookie
X-Application
X-TX-ID
X-User
Tcn
CDN
X-Fpc
X-Zen-Fury
True-Client-Ip
Uri
X-Content-Length
X-Esi
X-HostName
True-Client-IP
X-Varnish-Beresp-TTL
X-Cache-Date
X-Instance-Name
X-Vc
X-Srv
X-Rocket-Build-Number
X-Sigma
X-Sigma-Backend
X-Flags
X-Aspnet-Duration-Ms
Load-Balancing
X-Providence-Cookie
X-API-Version
X-VServer
X-Is-Crawler
X-Route-Name
Serverhost
X-DynaTrace
X-Oracle-DMS-ECID
X-Dynatrace-Js-Agent
Srv
GeoIP-Country-Code
X-Dispatcher-Number
X-Cdn-Forward
X-Branch-Name
X-WA
X-HOST
X-Segment-20210421
S-Rt
X-FPC
X-NC
Request-ID
Vc-Max-Age
X-Dispatch
Product
X-Cdn-Cache-Status
X-Page-View
Hostname
Ohc-File-Size
X-RequestId
Geoip-Latitude
X-DataCenter
ServerName
X-APP-VERSION
X-Geo
X-B3-Spanid
Type
X-FL-QIT-DEBUG
Srvid
Server-Id
X-Webkit-Csp-Report-Only
X-Sql-Duration-Ms
X-ServedByHost
X-Bug-Bounty
X-Sql-Count
X-Irp-Debug
X-Ckpd-Fst-Backend
X-Http-Reason
X-Lb-Nocache
Cl-Cache
Cloudfront-Viewer-Country
DataCenter
CacheControlHeader
X-VCL-Version
X-Via-Edge
X-Owner
X-Via-SSL
X-SIPLIST1
Edge-Copy-Time
Origin-Trial
X-Via-CDN
Epwk-X-Cache
IsBot
X-CACHE-KEY
Ohc-Cache-HIT
X-Cache-Ttl
WZWS-RAY
Lb
Cross-Origin-Opener-Policy-Report-Only
ServerHost
X-App
MIME-Version
X-Core-Mission
XkeyRZ
X-Proxy-CacheRZ
X-Correlation-ID
X-Via-PopV
PICS-Label
X-Via-PopN
X-Via-PopH
X-Ha-Backend
X-Ua
Rtss
X-Srcache-Fetch-Status
X-Srcache-Store-Status
X-MiniProfiler-Ids
X-MSEdge-Features
X-MSEdge-Flight
X-Hit
N-Cache
X-CSRF-TOKEN
X-Lb-Id
X-Qloud-Router
Cneonction
X-Sqd-Stime
X-Acquia-Purge-Tags
X-Acquia-Application-UUID
X-Vmg-Version
X-Sqd-Ctime
X-Limited
User-Agent
X-Acquia-Site
X-Acquia-Application-Trace
Sm-Log-Id
X-Akamai-Device-Characteristics
X-Service-Response-Time
X-Fastly-Country-Code
X-Requestid
X-Amz-Meta-Opti
Warning
CountryCode
X-Datacenter
X-Web-Server
X-Iplb-Request-Id
X-LAGOON
X-Litespeed-Cache-Control
X-Iplb-Instance
Xkey-La3
X-Info
Xkeylog
X-Snapshot-Date
X-HubSpot-Correlation-Id
X-IN-APIGATEWAYSSL
X-Proxy-Cache-La3
X-Gamma-Serve
X-Dw-Trace-Id
X-Amz-Meta-S3b-Last-Modified
X-Serial
X-Check-Cacheable
X-Akamai-Pragma-Client-IP
X-Amz-Meta-Sha256
X-Udemy-Cache-App-Namespace
X-RAMCache
X-Ramcache
Ngx
X-Th-Server
X-IN-APIGATEWAY