Threat Level: green Handler on Duty: Jan Kopriva

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
CF-RAY
Expect-CT
Accept-Ranges
X-XSS-Protection
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-Xss-Protection
X-Download-Options
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
Content-Security-Policy-Report-Only
X-DNS-Prefetch-Control
Accept-CH
X-AspNet-Version
X-Runtime
Accept-CH-Lifetime
X-Drupal-Cache
X-Check
X-Cache-Status
X-Generator
Server-Timing
X-Request-ID
X-Cacheable
X-Ua-Compatible
Timing-Allow-Origin
X-Envoy-Upstream-Service-Time
X-FRAME-OPTIONS
X-Iinfo
X-Drupal-Dynamic-Cache
X-Content-Security-Policy
Access-Control-Expose-Headers
Feature-Policy
Content-Encoding
X-CDN
Status
Upgrade
X-AspNetMvc-Version
CF-Ray
Access-Control-Max-Age
X-Amz-Request-Id
X-Amz-Id-2
Cf-Edge-Cache
X-Via
Host-Header
EagleId
Keep-Alive
Request-Context
X-Cache-Group
X-Backend
Permissions-Policy
X-UA-Device
X-Robots-Tag
X-AH-Environment
X-Hacker
X-Server
X-Proxy-Cache
X-Turbo-Charged-By
Xkey
X-Rq
X-Ws-Request-Id
X-Age
X-Vhost
X-Amz-Version-Id
Cf-Apo-Via
X-Dispatcher
X-LiteSpeed-Cache
X-Swift-SaveTime
X-Swift-CacheTime
X-Server-Powered-By
Allow
Grace
Ali-Swift-Global-Savetime
X-Varnish-Cache
P3p
X-OneAgent-JS-Injection
X-Page-Speed
X-Pingback
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Cache-Lookup
X-Device
EagleEye-TraceId
Cf-Railgun
X-Host
X-WebKit-CSP
X-Backend-Server
X-Server-Id
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Dns-Prefetch-Control
X-Response-Time
X-Readtime
X-Ruxit-JS-Agent
Surrogate-Control
X-Akam-SW-Version
X-HW
Request-Id
X-Cloud-Trace-Context
X-Node
Content-Location
X-Country
X-Application-Context
X-Nginx-Cache-Status
X-Nginx-Upstream-Cache-Status
Accept-Ch-Lifetime
X-NWS-LOG-UUID
X-Country-Code
Service-Worker-Allowed
X-Content-Type
X-Trace
X-Url
X-Clacks-Overhead
Cache-Tag
Rating
X-Amz-Server-Side-Encryption
X-Rack-Cache
X-Times
X-FTR-Request-ID
X-TtlSet
X-Vname
X-PC
X-CST
X-Daa-Tunnel
X-Litespeed-Cache
Nginx-Cache
Cross-Origin-Opener-Policy
X-Edge
X-Mcache
X-Server-Name
X-Midtier
X-Browser-Type
X-Powered-By-Plesk
Accept-Ch
X-Cnection
AR-PoweredBy
AR-ATIME
AR-SID
AR-Request-ID
X-ESI
X-Ac
X-Cache-TTL
X-D2id
X-Element-Page-Cache
X-GitHub-Request-Id
Edge-Control
X-Exp-Variant
X-Kinja-Build
X-Exp-Id
Verso
X-Kinja-Server
X-Cdn-Fetch
X-Kinja-Revision
X-Kinja
X-GoogleNews-Bot
X-MS-InvokeApp
X-ECACHE
X-Upstream
X-Vcap-Request-Id
X-FastCGI-Cache
X-Ser
AR-CACHE
X-Abt-Application-Version
X-Navigation-Version
X-Dw-Request-Base-Id
X-Webkit-Csp
SPIisLatency
SPRequestDuration
X-B3-TraceId
X-Mod-Pagespeed
Fastly-Restarts
SPRequestGuid
X-SharePointHealthScore
X-Amz-Rid
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Erf-Bev-Bev-Is-Generated
X-Instrumentation
X-Erf-Bev-Bev
X-NF-Request-ID
X-Client-IP
X-Kinsta-Cache
X-Edge-Location-Klb
X-Oneagent-Js-Injection
X-Ratelimit-Limit
X-Mg-S
X-Goog-Hash
Edge-Cache-Tag
S
X-Powered-CMS
X-ARC
Display
X-Sol
Pagespeed
X-Middleton-Display
X-PDP-UNCACHING-HASH
Cache-Status
X-Amzn-Trace-Id
X-Version
Access-Control-Request-Method
Response
X-Middleton-Response
X-VARITI-CCR
X-Cache-Key
X-Ratelimit-Remaining
X-TTL
X-Fastly-Request-ID
RTSS
X-Content-Digest
X-TraceId
Realpath
X-T
Cross-Origin-Resource-Policy
X-Forwarded-For
X-Recruiting
X-Correlation-Id
Fastcgi-Cache
X-ORACLE-DMS-RID
X-Cached
Front-End-Https
X-MSEdge-Ref
X-Shield-Request-Id
MS-Author-Via
X-Varnish-TTL
X-Protected-By
Content-MD5
X-HS-Hub-Id
X-HS-Cache-Config
X-Country-Code-Real
X-FTR-Backend
X-FTR-Backend-Server
X-FTR-Cache-Status
X-FTR-Balancer
MicrosoftSharePointTeamServices
X-HS-Content-Id
X-Ua-Browser
X-Ruxit-Js-Agent
X-Request-Received
X-Forwarded-Proto
X-Request-Processing-Time
X-RateLimit-Remaining
X-LLID
Public-Key-Pins
Server-Node
X-Frontend
TP-Cache
Payment
Arr-Disable-Session-Affinity
X-PressLabs-Stats
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-FTR-Expires
X-HS-Combine-CSS
X-Server-ID
Count-Hit
X-GUploader-UploadID
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Accel-Expires
X-Distributor
X-Origin-Server
X-NODE
X-LB-Cache
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
X-Jurisdiction
X-HP-Trace-Id
X-HP-Webp
X-Ezoic-Cdn
X-Aws-Lambda-Call-Status
X-Request-Handler-Origin-Region
X-Microsite
X-Activity-Id
X-Varnish-Server
X-Az
X-Newrelic-App-Data
X-Www-Served-By
X-AppVersion
Accept-Charset
Host
X-Cluster-Name
MRF-Tech
Mrf-Cache-Status
X-B3-TraceId-Primal
X-App-Server
X-Varnish-Backend
X-Ua-Device
X-ORACLE-DMS-ECID
Cache-Tags
X-Amz-Meta-S3cmd-Attrs
Retry-After
X-Content-Security-Policy-Report-Only
Cleartype
X-Webkit-CSP
Server-Name
X-Pinterest-Rid
Pinterest-Generated-By
Pinterest-Version
X-Goog-Metageneration
X-ASPNET-VERSION
X-Hits
Filterid
X-Unique-Id
X-Envoy-Decorator-Operation
X-Git-Hash
X-CSRF-Token
Access-Control-Allow-Method
X-Hostname
X-Azure-Ref
X-Geo-Country
X-Upgrade-Enabled
X-NGENIX-Cache
X-Load-Cache
Referer-Policy
X-Ttl
X-Id
X-Debug
X-Logged-In
TP-L2-Cache
X-Time
TCN
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Seen-By
X-FB-Debug
X-Proxy
X-CCDN-CacheTTL
X-B
X-CCDN-Origin-Time
X-Hcs-Proxy-Type
X-TT
X-B3-Sampled
Section-Io-Cache
X-Amz-Apigw-Id
X-Varnish-Ttl
X-Grace
X-Amzn-RequestId
X-Revision
X-Trace-Id
Surrogate-Key
X-Request-Guid
X-Cache-Control
DC
X-F-Cache
X-Type
X-Fb-Rlafr
Healthy
X-Contextid
Viewport
X-DIS-Request-ID
X-Mobile
X-N
Paypal-Debug-Id
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
Fastly-SIE
Fastly-SWR
X-Page-Id
X-XRDS-LOCATION
X-Debug-Info
Content-Disposition
X-Px
X-Origin-Cache
X-Via-JSL
X-Whom
X-Varnish-Grace
Version
X-Magnolia-Registration
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
X-Template
X-Content-Options
X-Oracle-Dms-Ecid
Charset
X-Amz-Replication-Status
X-UUID
X-Wix-Request-Id
X-Rid
X-G
X-ProcessESI
X-RemovedCookies
X-Cache-Grace
Ms-Operation-Id
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-Debug-IsConnected
X-Debug-IsPreview
X-App-Environment
X-Adobe-Loc
X-Tumblr-User
X-Tumblr-Pixel
X-Rule
X-RTag
X-Adobe-Content
X-Node-Name
MS-CV
X-B-Cache
VIX-Pulpo-Node
X-Yottaa-Optimizations
VIX-Pulpo-Upstream-Status
X-Yottaa-Metrics
NGB
X-Hl-Ver
X-Cache-Age
X-Source
X-Storage
X-NWS-UUID-VERIFY
X-Signature
SD-X-WS
X-Datadog-Sampled
ServerID
X-FW-Static
X-NYM-Debug-Backend
X-L-Path
X-Is-Bot
X-Proxy-Cache-Info
X-Region
X-User-Agent
X-Rendered-As
X-Instance
X-FW-Version
X-FW-Dynamic
X-Device-Type
X-Cacheable-TTL
X-FW-Hash
X-FW-Serve
X-FW-Type
X-FW-Server
X-Backend-Name
X-Environment-Context
X-EdgeConnect-Cache-Status
X-Cache-Hit
X-ServerID
X-Status
Country
GEO-INFO
X-Real-IP
X-Language
Countrycode
Cross-Origin-Window-Policy
X-IPS-LoggedIn
SRV
Liferay-Portal
X-Amzn-Remapped-Content-Length
Akamai-GRN
X-B3-SpanId
X-Ratelimit-Reset
X-Wormhole-Sdk
X-RM-Cache-TTL
X-WP-CF-Super-Cache-Active
X-Sucuri-Cache
Front
X-Sucuri-ID
Amp-Access-Control-Allow-Source-Origin
X-Xrds-Location
X-Framework
OT-Force-Account-Verify
X-Oracle-Dms-Rid
X-Servername
X-AB
X-Air-Pt
X-UA
From-Origin
X-VC-Cache
X-Content-Powered-By
X-Mode
Xet-Cookie
X-VC
X-Air-Hostname
X-Air-Source
X-WebKit-CSP-Report-Only
X-Air-Trace-Id
Backend
X-Akamai-Request-ID2
X-URL
Upgrade-Insecure-Requests
Refresh
X-Cache-Time
X-Origin-Cache-Key
X-Handled-By
X-DataDome
X-Nginx-Cache
X-INCAP-ABP
Accept-Language
X-Endurance-Cache-Level
X-Ismobilevalue
X-Xfnlog-Site
Cache
X-JoinUs
X-RCS-CacheZone
X-SRV
X-SaId
X-UPSTREAM-Address
X-Rewrite-Enabled
X-Edge-Location
Filters
Meta-Geo
X-Rn-Rsrv
LB
X-Cms-Context
X-Proxied
Webserver
TWC-Privacy
X-Provided-By
X-HTML-Minification-Powered-By
X-Generated-By
X-VWS-Id
X-Varnish-Age
Access-Control-Request-Headers
ServedBy
X-Reqid
TWC-Connection-Speed
TWC-GeoIP-LatLong
TWC-Locale-Group
X-Cache-Operation
X-Cache-Rule
X-Cloudmap
X-Origin-Date
X-S
Property-Id
Webcakes-Region
X-R9-Blue-Green-Version
X-Adobe-Source
X-Cache-Status-Check
X-Origin-Hint
X-No-Session
TWC-GeoIP-Country
X-Extlb
X-Labrador-Cache-Channel
X-Routing-Service
Webcakes-App-Name
X-LJ-Flow-ID
Webcakes-App-Version
X-Hosted-By
TWC-Device-Class
X-Zipkin-Id
X-Container-Uri
X-RateLimit-Limit
X-Git-Commit
X-PHP-Host
X-Lambda-Id
X-Webstats-RespID
X-AWS-Id
X-Tumblr-Pixel-2
X-Cluster
X-Httpd
X-IPLB-Instance
X-IPLB-Request-ID
Mn-Server-Ip
Apigw-Requestid
Url
X-Is-Desktop
Section-Io-Id
Web-Mar-Node
X-Is-Supported-Browser
X-Ms-Version
X-Web-Node
X-Locale
X-Logging-Id
X-Ms-Request-Id
X-Is-Tablet
X-Loop
Atl-Traceid
X-Geo-Region
X-Is-Mobile
X-Redis-Cache
X-Cache-Debug
X-Tb
X-Restarts
X-BYPASS-REASON
X-Tncms
X-Fetched-On
X-Scope-Id
X-Site-Version
X-Skip-Cache
X-Tcp-Rtt
X-Forwarded-Host
X-Akamai-Edgescape
X-Served-From
X-ProxyCache-Key
X-Browser-Name
X-Accel-Version
X-ProxyCache-Status
X-Api-Version
X-Detected-As
X-Director
X-Storefront-Renderer-Rendered
X-Upstream-Ht
X-Soup
X-Proxy-Build
X-Say-TTL
X-SayCDN-TTL
X-Upstream-Ct
X-Azure-Ref-OriginShield
X-Shopify-Stage
X-Timing-Wait
Frame-Options
X-Frame-Option
X-Cache-Host
X-Alternate-Cache-Key
X-VCT
X-Varnish-Cache-Hits
X-Origin
X-Say-Cacheable
Selected-Fe
X-Varnish-Beresp-Grace
X-Format
X-GeoCode
X-Optimistic-Header
WPO-Cache-Status
X-GeoCountry
WPO-Cache-Message
X-RID
Xserver
X-ShardId
X-ShopId
X-Request-URI
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Drupal-Cache-Tags
X-Generation-Time
X-CMSURLCustom
X-RateLimit-Reset
X-Origin-TTL
X-Origin-CC
X-Tt-Logid
Thinkindot-Control
X-Shield-Cache-Expires
Cache-Hits
X-Thinkindot-L3
TDXMobile
X-Vcache
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
X-Drupal-Cache-Contexts
Source
Cdn-Requestid
Onion-Location
Expiry
X-Cdn-Origin
X-Connection-Hash
Protected
X-CDN-Forward
Fastcgi-Useragent
X-Fastly-Request-Id
X-WP-CF-Super-Cache-Cookies-Bypass
X-Lagoon
X-B3-Traceid
X-Mg-Request-UUID
X-Cache-Expired-At
X-Buckets
X-Vercel-Id
X-Worker
X-Vercel-Cache
X-Pass-Why
X-TA-CDN-Provider
X-PHP-Backend
Azure-RegionName
Azure-SiteName
Azure-SlotName
Azure-Version
X-Rocket-Nginx-Serving-Static
Azure-InstanceId
X-Nf-Request-Id
Node
X-ECache
Environment
X-Vcl-Version
X-App-Version
Sid
Priority
X-Cache-Action
X-ID
X-GEO
X-Proxy-Cache-Status
AMP-Access-Control-Allow-Source-Origin
CDN-Cache
X-Aspnetmvc-Version
CDN-EdgeStorageId
CDN-Uid
Uber-Trace-Id
CDN-CachedAt
CDN-RequestPullSuccess
Cross-Origin-Embedder-Policy
CDN-RequestPullCode
CDN-RequestCountryCode
CDN-PullZone
X-Tumblr-Pixel-3
X-Cluster-Node
X-XRDS-Location
X-Urbn-Context-Path
Locale
X-Urbn-Site-Id
X-Cache-Server
X-Fastcgi-Cache
X-Server-W
Cache-Tv-Group
DB-Nickname
X-FB-TRIP-ID
HostName
Alternate-Protocol
CF-IPCountry
X-Auth-Group-Type
User-Cache-Control
Fusion-Source
Fusion-Content-Id
Fusion-Component-Id
Fusion-Content-Source
Fusion-Deployment-Id
Fusion-Template-Id
X-Tx-Id
X-Pad
X-DC
X-Client-Ip
X-Jobs
Rendered-Blocks
X-Dispatcher-Server
X-Ec-GeoHdr
X-Ec-Fail
X-Service
X-Op-Id-All
X-Gen-Mode
X-Org
X-Origin-Expires
X-DefHash
Surrogated-Key
Sslversion
X-Developer
X-ND-Cache
A
X-Vtex-Remote-Cache
X-Device-Os
X-Ig-Push-State
Content-Secure-Policy
Magicmarker
X-Fastly-Backend
MD5-Digest
Meta-Geo-Continent
X-Gzip
Lang
DCR-Decision-By
Gannett-Cam-Experience-Id
X-Generated-On
Edge-Cache
X-GeoIP-City
DCR-Processing-Time-Ms
X-Esi-Check
Ngx.Var.Host
Origin-Agent-Cluster
Origin
X-Ig-Origin-Region
X-DefElseHash
X-Level-Front-Cache
X-Hnp-Log
Candidate-Md5Url
Odigeo-Trace-Id
X-Varnish-Remaining-TTL
Cdn-Request-Time
Cdn-Host
X-Epic-Correlation-Id
X-Edge-Server
T-Server
X-A-Wwc
X-Block-Status
X-TIM-N
X-Aed
X-A-Dgt
X-Req
X-A-Ccd
X-Via-Fastly
X-UA-Device-Type
X-A-Dcw
X-Rojux
X-Bl-Debug
X-Vdms-Version
X-Content-Age
X-SRCache-Key
X-Conf
X-ScT
X-Bc-Bl
X-BCube-Filmed-By
X-SB
X-Core-Value
X-V-Cache
X-A-Dam
X-Custom-Header
Wxu-Next-Commit
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-Cache-Id
X-Cache-NE
X-Cache-TTL-Remaining
X-D
Wxu-Next-Region
Wxu-Next-Hostname
X-A
X-Viewer-Country
Mime-Version
X-LSADC-Cache
X-Forwarded-Site
NM-Fastcgi-Cache
X-B3-Trace-ID
X-Clientip
X-Gdpr
Host-ID
X-Backend-Instance
X-Cdn-Srv
X-FC-Vary-Parameters
X-Cache-Bucket
X-CacheTTL
X-Fastly-Cache
X-Fmm-Version
X-Bip
Is-Eu
Platform
Ssr
Vix-Hermes-Req-Id
Sever-Int
Server-Hostname
Server-Ext
Server-Host
V-Age
X-Debug-Cache-Fetch
Tube-Get-Contents
Tube-Got-Eval
Tube-Got-Results
Tube-Return
X-Debug-Cache-Store
RNT-Time
RNT-Machine
X-Amz-Storage-Class
PFcat
Origin-EX
Origin-CC
X-App-Name
Powered-By
X-AK-Request-ID
X-DPWN-IS-SECURE
Req-ID
X-Acquia-Purge-Cdn-Unconfigured
X-Ad-Load-Variation
Producers
X-Auto-Login
X-HN
X-NMSegId
X-WA-Info
X-Scheme
X-Node-Id
X-NodeID
Fastly-SSL
X-Nyt-Route
X-Nginx-Cache-Key
X-SD-PageType
X-Sn-Servicetimems
X-SVT-ORM-RULES
X-Server-IP
XM
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-Origin-Response-Time
X-Origin-Time
X-Pubstack
X-VTEX-Cache-Server
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Region-Sid
X-VG-WebCache
X-Request-Time
X-Proto
X-VTEX-Cache-Time
X-PAYTM-SRV-ID
X-Platform
X-Policy
X-Powered-By-VTEX-Cache
X-VG-TLSProxy
X-Mvc-Supplant-Cachable
X-SVT-ORM-VERSION
Content-Script-Type
Content-Style-Type
X-GoCache-CacheStatus
Click-Count-Error
Click-Count-Action-Start
X-Varnish-Director
Country-Code
X-GeoIP-Region-Code
X-Geo-Header
X-Varnish-Hostname
Fastly-Backend-Name
Esi-Enabled
X-GeoIP-Country-Code
X-GeoIP
X-VarnishDD-TTL
Cdnsip
X-Men
X-Test
X-Cache-Info
X-Micro-Cache
X-Mly-Id
X-Tb-Optimization-Total-Bytes-Saved
X-Loc
Adler-Geo
Cache-Provider
CDCHOST
Cdncip
X-HS-Content-Campaign-Id
C-Via
AKAMAI
X-Thanos
X-Tec-Api-Version
X-HITS
X-Varnish-Beresp-Ttl
X-Tec-Api-Origin
X-Tec-Api-Root
X-Location
X-Human
X-Ec-Custom-Error
X-Aicache-OS
X-Varnishpool
X-CGP
X-Up
X-Eu-Site
X-From
X-Varnish-Beresp-Status
X-Varnish-Authentication
X-Mvc-Supplant-OutputCached
X-Var-Ttl
X-Hash
X-Slack-Shared-Secret-Outcome
X-Request-Start
X-Date
X-Request-Host
X-Csrf-Jwt
X-Proxied-Request
X-CUA
X-Pool
X-Depends
Yak-Timeinfo
X-Slack-Backend
X-Contensis-Viewer-Groups
X-Section
X-We-Are-Hiring
X-NCache
X-Cache-Aspx
Release
Cluster
Proxy-Firewall
Pramga
Req-Svc-Chain
Canary
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
Cache-Key
On-Server
DSUID
L
HA-Ipaddr
Gh-Request-Id
L5d-Success-Class
Machine
NGX
Fastly-GeoIP-CountryCode
Mail-Subject
True-Client-Country-4JS
Apple-News-Services-Host
X-MP-GENERATED-AT
X-Access
Ha-Gx-Prefs
X-Dc
X-BBC-Edge-Cache-Status
Web-Mar-Region
X-Accel-Expires-Debug
X-LiteSpeed-Cache-Control
Apple-News-Services-Handled
W
We-Hiring
X-NGINX-Cache
X-AIR-PT
X-Jungle-Id
X-Cs
X-Zone
Debug
X-LB-ID
X-Akamai-Transformed
X-Vdms-Path
X-Varnish-Hits
X-Cache-FS-Status
X-Cache-Backend
WP-Super-Cache
X-Uri
CDN-RequestId
X-Via-Popn
X-Via-Popv
X-HA-Backend
Fastly-Drupal-HTML
X-Refresh
Pics-Label
X-Via-Poph
Server-Info
Redirect-Candidate
CloudFront-Viewer-Country
BehaviorPad-Version
X-ApacheServer
X-VHOST
X-Nananana
X-Newrelic-Synthetics
X-PERF
X-Render-Time
X-Servedbyhost
SID
X-VC-TTL
X-Datadome
X-M-Reqid
X-M-Log
GeoIP-Latitude
X-Parent-Response-Time
X-CACHE-AGE
X-LB-NoCache
X-Response-Served-From
X-B3-Parentspanid
X-APP
X-Original-Request-Id
X-Cached-By
Locid
Fastly-Drupal-Html
X-Content-Length
Datacenter
X-Litespeed-Tag
X-DynaTrace-JS-Agent
X-TT-LOGID
X-Wa
Resin-Trace
X-Nc
Server-ID
Cf-Ipcountry
X-CS
X-CDN-Cache-Status
X-Amz-Meta-Cb-Modifiedtime
Cdn
X-LiteSpeed-Tag
X-IAuth-Set-Uid
NtCoent-Length
X-VCache
X-Old-Content-Length
X-ZONE
GeoIp-Country-Code
Vc-Max-Age
Uri
X-RequestId
Ngx-Var-Key
X-Fpc
FSS-Cache
X-Dispatcher-Number
X-NewRelic-App-Data
X-Varnish-Beresp-TTL
X-Esi
X-Platform-Cluster
X-Platform-Router
X-Vgn-Hpd-Reason
X-B3-Spanid
True-Client-Ip
X-Platform-Processor
Serverhost
Product
X-Srv
X-SERVER-NAME
X-TX-ID
X-HostName
X-Moov-T
Srv
X-Erf-Stays-Pdp-Viaduct-Migration-Web-V2
X-Moov-Xdn-Version
True-Client-IP
CDN
X-TH-Server
X-Cdn-Forward
X-Ckpd-Fst-Backend
GeoIP-Country-Code
X-Nf-Language
X-Nf-Country
X-Nf-Ats-Version
Tcn
X-Oracle-DMS-ECID
X-TIME
S-Rt
X-FPC
Cross-Origin-Embedder-Policy-Report-Only
X-Dynatrace-Js-Agent
X-Bug-Bounty
Cf-Device-Type
X-Cdn-Cache-Status
ServerName
X-HubSpot-Correlation-Id
Request-ID
X-Application
X-Vc
CacheControlHeader
X-NC
X-WA
X-User
X-External-Request-Id
X-Dispatch
X-B-Cookie
X-S-Cookie
X-Destination
X-CACHE-KEY
X-Zen-Fury
Server-Id
Hostname
X-APP-VERSION
X-COUNTRY
Geoip-Latitude
X-Webkit-Csp-Report-Only
X-FL-QIT-DEBUG
X-Rocket-Build-Number
X-Sigma
X-Cache-Date
X-Instance-Name
X-Sigma-Backend
Srvid
X-Presslabs-Stats
User-Agent
X-API-Version
X-Lb-Nocache
X-Vmg-Version
X-Geo
X-VServer
X-VCL-Version
Ohc-File-Size
X-Segment-20210421
X-Akamai-Device-Characteristics
Origin-Trial
X-Via-PopN
X-Info
X-Branch-Name
X-Ha-Backend
X-Gamma-Serve
ServerHost
X-ServedByHost
X-Via-PopV
X-Via-PopH
X-App
PICS-Label
Xc-Version
Cneonction
Cloudfront-Viewer-Country
Epwk-X-Cache
Load-Balancing
DataCenter
X-Correlation-ID
X-DynaTrace
X-DataCenter
Expect-Staple
X-Limited
X-Ua
X-Srcache-Store-Status
X-Srcache-Fetch-Status
Rtss
Type
X-Lb-Id
X-Amz-Meta-Opti
X-MSEdge-Features
X-MSEdge-Flight
X-MiniProfiler-Ids
X-LAGOON
X-Hit
X-Akamai-Pragma-Client-IP
Ohc-Cache-HIT
X-Check-Cacheable
X-Serial
Lb
Timeexpire
X-Acquia-Site
X-Acquia-Purge-Tags
X-Acquia-Application-Trace
X-Sqd-Ctime
Warning
Cmsid
X-Web-Server
Cmstype
X-Owner
X-Sqd-Stime
X-Acquia-Application-UUID
Sm-Log-Id
X-Irp-Debug
Cross-Origin-Opener-Policy-Report-Only
X-Service-Response-Time
X-Datacenter
Servername
X-Litespeed-Cache-Control
X-CSRF-TOKEN
CountryCode
X-Shardid
X-Origin-Upstream-Status
X-Via-CDN
X-Via-SSL
X-Via-Edge
X-Shopid
N-Cache
Permission-Policy
X-Qloud-Router
X-Ramcache
X-Sorting-Hat-Podid
X-Sorting-Hat-Shopid
X-Snapshot-Date
X-RAMCache
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
X-Dw-Trace-Id
X-Amz-Meta-Sha256
X-Th-Server
X-Requestid
X-Amz-Meta-S3b-Last-Modified
Edge-Copy-Time
X-Udemy-Cache-App-Namespace
Cl-Cache
X-Core-Mission
Ngx