Threat Level: green Handler on Duty: Jan Kopriva

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
CF-RAY
Accept-Ranges
X-XSS-Protection
Expect-CT
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-Xss-Protection
X-Download-Options
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
Content-Security-Policy-Report-Only
X-DNS-Prefetch-Control
Accept-CH
X-AspNet-Version
X-Runtime
Accept-CH-Lifetime
X-Drupal-Cache
X-Check
X-Cache-Status
X-Generator
Server-Timing
X-Cacheable
X-Ua-Compatible
Timing-Allow-Origin
X-Envoy-Upstream-Service-Time
X-FRAME-OPTIONS
X-Request-ID
X-Iinfo
X-Drupal-Dynamic-Cache
X-Content-Security-Policy
Access-Control-Expose-Headers
Feature-Policy
Content-Encoding
X-CDN
Status
Upgrade
X-AspNetMvc-Version
CF-Ray
Access-Control-Max-Age
X-Amz-Request-Id
X-Amz-Id-2
Cf-Edge-Cache
X-Via
Host-Header
EagleId
Expect-Ct
Keep-Alive
Request-Context
X-Cache-Group
X-Backend
Permissions-Policy
X-Robots-Tag
X-UA-Device
P3p
X-AH-Environment
X-Hacker
X-Server
X-Proxy-Cache
X-Turbo-Charged-By
X-Rq
Xkey
X-Ws-Request-Id
X-Age
X-Vhost
X-Amz-Version-Id
Cf-Apo-Via
X-Dispatcher
X-LiteSpeed-Cache
X-Swift-CacheTime
X-Swift-SaveTime
Grace
X-Server-Powered-By
Allow
Ali-Swift-Global-Savetime
X-Varnish-Cache
X-OneAgent-JS-Injection
X-Page-Speed
X-Pingback
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Cache-Lookup
X-Device
X-WebKit-CSP
EagleEye-TraceId
Cf-Railgun
X-Host
X-Backend-Server
X-Server-Id
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Dns-Prefetch-Control
X-Response-Time
X-Readtime
Surrogate-Control
X-Akam-SW-Version
X-Ruxit-JS-Agent
X-HW
Request-Id
X-Cloud-Trace-Context
X-Node
Content-Location
X-Country
X-Application-Context
X-Nginx-Cache-Status
X-Nginx-Upstream-Cache-Status
Accept-Ch-Lifetime
X-NWS-LOG-UUID
X-Country-Code
Service-Worker-Allowed
X-Content-Type
X-Trace
X-Url
X-Clacks-Overhead
Cache-Tag
Rating
X-Amz-Server-Side-Encryption
X-Rack-Cache
X-Times
X-PC
X-Vname
X-TtlSet
X-CST
X-FTR-Request-ID
X-Litespeed-Cache
X-Daa-Tunnel
Nginx-Cache
Cross-Origin-Opener-Policy
X-Mcache
X-Edge
X-Browser-Type
X-Midtier
X-Server-Name
X-Powered-By-Plesk
Accept-Ch
X-Cnection
AR-SID
AR-PoweredBy
AR-ATIME
AR-Request-ID
X-ESI
X-D2id
X-Cache-TTL
X-Ac
X-Element-Page-Cache
X-GitHub-Request-Id
X-Exp-Variant
Verso
X-Cdn-Fetch
X-GoogleNews-Bot
X-Kinja-Server
Edge-Control
X-Kinja-Revision
X-Kinja-Build
X-Kinja
X-Exp-Id
X-MS-InvokeApp
X-ECACHE
X-Upstream
X-Vcap-Request-Id
X-FastCGI-Cache
X-Ser
AR-CACHE
X-Abt-Application-Version
X-Navigation-Version
X-Dw-Request-Base-Id
X-Webkit-Csp
X-Oneagent-Js-Injection
SPRequestDuration
SPIisLatency
X-B3-TraceId
X-NF-Request-ID
Fastly-Restarts
X-Mod-Pagespeed
SPRequestGuid
X-SharePointHealthScore
X-Amz-Rid
X-Erf-Bev-Bev
X-Kraken-Loop-Name
X-Instrumentation
X-Server-Lifecycle-Phase
X-Erf-Bev-Bev-Is-Generated
X-Client-IP
X-Kinsta-Cache
X-Edge-Location-Klb
X-Goog-Hash
Edge-Cache-Tag
S
X-ARC
X-Powered-CMS
Display
X-Mg-S
Pagespeed
X-Sol
X-Middleton-Display
X-PDP-UNCACHING-HASH
Cache-Status
X-Ratelimit-Limit
X-Amzn-Trace-Id
Access-Control-Request-Method
X-Version
Response
X-Middleton-Response
X-VARITI-CCR
X-Cache-Key
X-Fastly-Request-ID
RTSS
X-Content-Digest
X-TraceId
Realpath
Cross-Origin-Resource-Policy
X-T
X-Forwarded-For
X-Ruxit-Js-Agent
X-Ratelimit-Remaining
X-TTL
X-Recruiting
X-Correlation-Id
Fastcgi-Cache
X-Cached
X-ORACLE-DMS-RID
Front-End-Https
X-MSEdge-Ref
X-RateLimit-Remaining
X-Shield-Request-Id
MS-Author-Via
X-Varnish-TTL
Content-MD5
MicrosoftSharePointTeamServices
X-Ua-Browser
X-Protected-By
X-Request-Processing-Time
X-Forwarded-Proto
X-HS-Content-Id
X-HS-Hub-Id
X-HS-Cache-Config
X-Request-Received
Public-Key-Pins
Server-Node
X-LLID
TP-Cache
X-Frontend
Payment
X-FTR-Balancer
X-FTR-Backend
X-FTR-Cache-Status
X-FTR-Backend-Server
X-Country-Code-Real
Arr-Disable-Session-Affinity
X-PressLabs-Stats
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-HS-Combine-CSS
X-Server-ID
Count-Hit
X-Accel-Expires
X-Distributor
X-GUploader-UploadID
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-FTR-Expires
X-NODE
X-Origin-Server
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-LB-Cache
X-HP-Webp
X-Jurisdiction
X-HP-Trace-Id
X-Ezoic-Cdn
X-Aws-Lambda-Call-Status
X-Request-Handler-Origin-Region
X-Microsite
X-Az
X-AppVersion
X-Varnish-Server
X-Www-Served-By
X-Activity-Id
MRF-Tech
Host
Mrf-Cache-Status
X-Newrelic-App-Data
X-Cluster-Name
X-B3-TraceId-Primal
X-App-Server
X-Varnish-Backend
Accept-Charset
X-Ua-Device
Cache-Tags
X-Content-Security-Policy-Report-Only
X-Amz-Meta-S3cmd-Attrs
Retry-After
Cleartype
X-ORACLE-DMS-ECID
Pinterest-Generated-By
Pinterest-Version
X-Pinterest-Rid
Server-Name
X-Ttl
X-Goog-Metageneration
X-ASPNET-VERSION
Filterid
X-Hits
X-Unique-Id
X-Envoy-Decorator-Operation
X-Git-Hash
X-CSRF-Token
Access-Control-Allow-Method
X-Hostname
X-Azure-Ref
X-Upgrade-Enabled
X-NGENIX-Cache
X-Geo-Country
X-Load-Cache
Referer-Policy
X-Logged-In
X-Id
X-Debug
TP-L2-Cache
TCN
X-Time
X-Tt-Trace-Host
X-FB-Debug
X-Proxy
X-Tt-Trace-Tag
X-CCDN-Origin-Time
X-B
X-CCDN-CacheTTL
X-Hcs-Proxy-Type
X-Seen-By
X-B3-Sampled
X-TT
X-Grace
X-F-Cache
Surrogate-Key
X-Amzn-RequestId
X-Amz-Apigw-Id
Section-Io-Cache
DC
X-Revision
X-Trace-Id
X-Type
X-Fb-Rlafr
Healthy
X-Varnish-Ttl
X-Cache-Control
X-Contextid
Viewport
X-XRDS-LOCATION
X-DIS-Request-ID
X-Request-Guid
X-Mobile
Paypal-Debug-Id
X-N
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-Goog-Generation
Fastly-SIE
Fastly-SWR
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
X-Page-Id
Content-Disposition
X-Px
X-Debug-Info
X-Webkit-CSP
X-Whom
X-Origin-Cache
X-Via-JSL
Version
X-Varnish-Grace
X-Magnolia-Registration
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
X-Datadog-Trace-Id
X-Oracle-Dms-Ecid
X-Content-Options
X-Template
X-Amz-Replication-Status
Charset
X-RemovedCookies
X-G
X-ProcessESI
X-Rid
X-UUID
X-Wix-Request-Id
X-RTag
MS-CV
X-Debug-IsPreview
X-Tumblr-Pixel-1
X-Tumblr-Pixel
Ms-Operation-Id
X-Tumblr-Pixel-0
X-Tumblr-User
X-Debug-IsConnected
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
NGB
X-Cache-Grace
X-Adobe-Content
X-App-Environment
X-Hl-Ver
X-Signature
X-B-Cache
X-Datadog-Sampled
X-Adobe-Loc
X-Node-Name
X-Source
X-NWS-UUID-VERIFY
X-Storage
X-Rule
X-FW-Serve
X-FW-Server
X-FW-Static
X-FW-Version
X-FW-Type
X-Region
X-Environment-Context
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-User-Agent
X-Cache-Age
X-Device-Type
X-FW-Dynamic
X-FW-Hash
X-Proxy-Cache-Info
X-L-Path
X-NYM-Debug-Backend
X-EdgeConnect-Cache-Status
SD-X-WS
ServerID
X-Cacheable-TTL
X-Backend-Name
X-Status
Country
X-Instance
X-Cache-Hit
X-Real-IP
X-ServerID
GEO-INFO
X-Rendered-As
X-Is-Bot
X-IPS-LoggedIn
Cross-Origin-Window-Policy
Countrycode
X-Language
SRV
Liferay-Portal
Akamai-GRN
X-Amzn-Remapped-Content-Length
X-Wormhole-Sdk
X-B3-SpanId
X-RM-Cache-TTL
X-Sucuri-ID
X-Sucuri-Cache
X-WP-CF-Super-Cache-Active
Front
OT-Force-Account-Verify
X-Ratelimit-Reset
X-Framework
X-Oracle-Dms-Rid
X-UA
X-Servername
X-AB
X-Air-Pt
X-VC-Cache
From-Origin
X-Content-Powered-By
X-WebKit-CSP-Report-Only
X-Air-Hostname
X-Air-Trace-Id
X-Mode
Amp-Access-Control-Allow-Source-Origin
X-VC
X-Air-Source
Xet-Cookie
Backend
X-RateLimit-Limit
X-Akamai-Request-ID2
X-URL
Upgrade-Insecure-Requests
X-Xrds-Location
Refresh
X-Cache-Time
X-Origin-Cache-Key
X-Handled-By
X-INCAP-ABP
X-Nginx-Cache
X-Ismobilevalue
X-Endurance-Cache-Level
Filters
Meta-Geo
X-Xfnlog-Site
X-Rewrite-Enabled
X-UPSTREAM-Address
X-Edge-Location
Accept-Language
X-Rn-Rsrv
X-SaId
X-JoinUs
X-RCS-CacheZone
X-SRV
X-Tumblr-Pixel-2
X-Extlb
X-No-Session
X-LJ-Flow-ID
X-Reqid
X-Cache-Operation
X-Cache-Rule
Cache
X-Cloudmap
X-Routing-Service
Webcakes-App-Name
X-Lambda-Id
X-S
X-R9-Blue-Green-Version
Webcakes-App-Version
TWC-Device-Class
Webcakes-Region
X-Cache-Status-Check
X-VWS-Id
ServedBy
Access-Control-Request-Headers
Property-Id
X-Cluster
TWC-Privacy
TWC-Locale-Group
TWC-Connection-Speed
X-AWS-Id
X-Proxied
X-Origin-Hint
TWC-GeoIP-LatLong
TWC-GeoIP-Country
X-Zipkin-Id
Webserver
X-Varnish-Age
X-HTML-Minification-Powered-By
X-Is-Supported-Browser
X-Locale
X-Accel-Version
X-PHP-Host
X-Is-Tablet
X-IPLB-Request-ID
X-ProxyCache-Key
X-Is-Desktop
X-ProxyCache-Status
X-Ms-Version
X-Ms-Request-Id
X-Git-Commit
Section-Io-Id
X-Is-Mobile
X-Httpd
X-IPLB-Instance
Mn-Server-Ip
X-Labrador-Cache-Channel
X-Origin-Date
Apigw-Requestid
X-Browser-Name
X-BYPASS-REASON
X-Restarts
X-Skip-Cache
X-Api-Version
X-DataDome
X-Tcp-Rtt
X-Fetched-On
X-Container-Uri
X-Webstats-RespID
X-Generated-By
X-Cms-Context
X-Forwarded-Host
X-Served-From
X-Tb
X-Akamai-Edgescape
X-Scope-Id
X-Adobe-Source
X-Geo-Region
X-Upstream-Ct
X-Azure-Ref-OriginShield
X-Redis-Cache
X-Format
X-Timing-Wait
X-Cache-Host
X-Logging-Id
X-Frame-Option
X-Proxy-Build
X-Upstream-Ht
X-VCT
Selected-Fe
X-Web-Node
Url
X-Varnish-Cache-Hits
X-Loop
X-Varnish-Beresp-Grace
Web-Mar-Node
X-Tncms
X-Shopify-Stage
X-Site-Version
Atl-Traceid
X-Origin
X-Alternate-Cache-Key
Frame-Options
X-Storefront-Renderer-Rendered
X-GeoCountry
Xserver
X-Say-TTL
X-GeoCode
WPO-Cache-Message
X-Hosted-By
X-SayCDN-TTL
WPO-Cache-Status
X-Provided-By
X-Director
X-RID
X-Soup
X-Optimistic-Header
LB
X-Say-Cacheable
X-ShardId
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Cache-Debug
X-ShopId
X-Request-URI
X-Drupal-Cache-Tags
X-Detected-As
X-Generation-Time
X-CMSURLCustom
X-RateLimit-Reset
X-Shield-Cache-Expires
Thinkindot-Control
X-Origin-CC
X-Thinkindot-L3
Cache-Hits
X-Origin-TTL
Thinkindot-CacheControl
TDXMobile
Thinkindot-CacheControl-Type
X-Lagoon
Source
X-Drupal-Cache-Contexts
X-Vcache
Cdn-Requestid
X-Tt-Logid
Onion-Location
Expiry
X-Connection-Hash
X-Cdn-Origin
X-CDN-Forward
Protected
Fastcgi-Useragent
X-Fastly-Request-Id
X-Mg-Request-UUID
X-Buckets
X-Cache-Expired-At
X-B3-Traceid
AMP-Access-Control-Allow-Source-Origin
X-Worker
X-Vercel-Cache
X-Vercel-Id
X-Pass-Why
X-WP-CF-Super-Cache-Cookies-Bypass
X-PHP-Backend
X-Vcl-Version
X-TA-CDN-Provider
Azure-InstanceId
Azure-SlotName
Azure-SiteName
Azure-RegionName
X-Rocket-Nginx-Serving-Static
Azure-Version
X-App-Version
X-ECache
Node
Environment
Priority
X-Proxy-Cache-Status
X-ID
Sid
X-Cache-Action
CDN-Cache
CDN-CachedAt
Uber-Trace-Id
CDN-EdgeStorageId
CDN-RequestCountryCode
CDN-Uid
CDN-PullZone
CDN-RequestPullSuccess
Cross-Origin-Embedder-Policy
X-Aspnetmvc-Version
CDN-RequestPullCode
X-GEO
X-Cluster-Node
X-Tumblr-Pixel-3
X-XRDS-Location
X-Urbn-Site-Id
Locale
X-Urbn-Context-Path
X-Cache-Server
X-Fastcgi-Cache
X-Server-W
Cache-Tv-Group
DB-Nickname
X-FB-TRIP-ID
HostName
X-Auth-Group-Type
Fusion-Content-Source
Fusion-Template-Id
Fusion-Source
Fusion-Component-Id
Fusion-Deployment-Id
Fusion-Content-Id
X-Pad
CF-IPCountry
X-Client-Ip
X-Nf-Request-Id
Alternate-Protocol
User-Cache-Control
X-Jobs
X-Viewer-Country
Origin
Origin-Agent-Cluster
X-Vtex-Remote-Cache
X-DefHash
X-DefElseHash
Ngx.Var.Host
Odigeo-Trace-Id
X-Service
X-Custom-Header
X-Core-Value
X-Op-Id-All
X-Org
X-Conf
Rendered-Blocks
X-Vdms-Version
X-D
X-ND-Cache
Meta-Geo-Continent
X-Via-Fastly
Magicmarker
Cdn-Request-Time
X-GeoIP-City
Cdn-Host
Candidate-Md5Url
X-Epic-Correlation-Id
Gannett-Cam-Experience-Id
X-Generated-On
DCR-Decision-By
Content-Secure-Policy
DCR-Processing-Time-Ms
Edge-Cache
X-Edge-Server
X-Ec-GeoHdr
X-Ig-Origin-Region
X-Ig-Push-State
Sslversion
X-Level-Front-Cache
X-Developer
A
X-Ec-Fail
X-Dispatcher-Server
X-Device-Os
Lang
MD5-Digest
X-Content-Age
X-A-Ccd
X-A-Dam
X-A-Dcw
X-A-Dgt
X-ScT
X-A
Wxu-Next-Hostname
X-Rojux
Wxu-Next-Region
X-SB
X-SRCache-Key
X-A-Wwc
X-Varnish-CookieINHashed-On
X-V-Cache
X-Bc-Bl
X-Varnish-CookieHashed-On
X-BCube-Filmed-By
X-Aed
X-Bl-Debug
X-TIM-N
X-UA-Device-Type
X-Req
Wxu-Next-Commit
X-Varnish-Remaining-TTL
T-Server
Surrogated-Key
X-Cache-NE
X-Cache-TTL-Remaining
X-LSADC-Cache
X-Dc
X-Tx-Id
RNT-Machine
Origin-EX
Vix-Hermes-Req-Id
Country-Code
X-CacheTTL
X-Bip
X-Acquia-Purge-Cdn-Unconfigured
X-Ad-Load-Variation
RNT-Time
X-Esi-Check
X-Amz-Storage-Class
X-B3-Trace-ID
X-Clientip
Server-Host
X-Fastly-Backend
X-DPWN-IS-SECURE
Fastly-Backend-Name
Esi-Enabled
Ssr
Is-Eu
X-Cdn-Srv
V-Age
Origin-CC
NM-Fastcgi-Cache
X-Debug-Cache-Fetch
X-Cache-Bucket
X-Block-Status
X-Debug-Cache-Store
Tube-Return
Platform
PFcat
Req-ID
X-Cache-Id
Tube-Get-Contents
Tube-Got-Eval
Powered-By
Producers
Tube-Got-Results
Host-ID
CDCHOST
X-Origin-Expires
X-Nyt-Route
X-Origin-Time
X-PAYTM-SRV-ID
X-VarnishDD-TTL
X-Platform
X-NodeID
X-NMSegId
X-Men
X-Loc
X-Micro-Cache
X-Mly-Id
X-Nginx-Cache-Key
X-VG-TLSProxy
X-Proto
X-Pubstack
X-SVT-ORM-RULES
X-Sn-Servicetimems
X-SVT-ORM-VERSION
X-Tb-Optimization-Total-Bytes-Saved
X-Thanos
X-Test
X-Server-IP
X-Scheme
X-Varnish-Hostname
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Region-Sid
X-Request-Time
X-WA-Info
X-Node-Id
Click-Count-Action-Start
X-Hnp-Log
X-GeoIP
Adler-Geo
X-Gen-Mode
Click-Count-Error
X-HN
X-Gzip
X-GeoIP-Region-Code
X-GeoIP-Country-Code
X-GoCache-CacheStatus
C-Via
X-Auto-Login
X-Geo-Header
X-Gdpr
AKAMAI
XM
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-Tec-Api-Root
X-Tec-Api-Origin
X-DC
Mime-Version
X-Tec-Api-Version
X-Varnish-Beresp-Ttl
X-HITS
X-Varnish-Authentication
X-BBC-Edge-Cache-Status
X-Backend-Instance
X-Varnish-Beresp-Status
X-Eu-Site
X-Section
X-Forwarded-Site
X-From
X-FC-Vary-Parameters
X-SD-PageType
X-Varnish-Director
X-Fastly-Cache
X-Var-Ttl
X-Up
X-Request-Start
X-Pool
X-Date
Yak-Timeinfo
X-NCache
X-Depends
X-VG-WebCache
X-Mvc-Supplant-Cachable
X-We-Are-Hiring
X-Location
X-VTEX-Cache-Time
X-VTEX-Cache-Server
X-Csrf-Jwt
X-Aicache-OS
X-CGP
X-Hash
X-Policy
X-Powered-By-VTEX-Cache
X-Origin-Response-Time
X-Varnishpool
X-Fmm-Version
X-HS-Content-Campaign-Id
X-Contensis-Viewer-Groups
X-Cache-Info
X-Cache-Aspx
Release
Cdnsip
Proxy-Firewall
Apple-News-Services-Request-Url
Req-Svc-Chain
DSUID
Server-Hostname
Apple-News-Services-Parsed-Url
Cache-Key
On-Server
NGX
Gh-Request-Id
Apple-News-Services-Handled
Apple-News-Services-Host
Fastly-SSL
Ha-Gx-Prefs
HA-Ipaddr
Mail-Subject
L5d-Success-Class
L
Sever-Int
Server-Ext
X-Access
X-Accel-Expires-Debug
Content-Script-Type
Content-Style-Type
X-AK-Request-ID
Cluster
Cdncip
X-App-Name
Canary
X-MP-GENERATED-AT
Cache-Provider
X-LiteSpeed-Cache-Control
We-Hiring
W
True-Client-Country-4JS
X-AIR-PT
X-NGINX-Cache
Fastly-GeoIP-CountryCode
X-Slack-Backend
X-Proxied-Request
X-Request-Host
X-Ec-Custom-Error
X-CUA
X-Jungle-Id
X-Mvc-Supplant-OutputCached
Web-Mar-Region
X-Human
Pramga
Machine
X-Slack-Shared-Secret-Outcome
X-Cs
X-Zone
X-Varnish-Hits
X-Vdms-Path
X-Cache-Backend
X-LB-ID
X-Cache-FS-Status
WP-Super-Cache
X-Akamai-Transformed
X-Uri
Debug
CDN-RequestId
X-Via-Popn
X-Refresh
X-Via-Poph
Pics-Label
Server-Info
Redirect-Candidate
X-Datadome
Fastly-Drupal-HTML
X-HA-Backend
X-Via-Popv
CloudFront-Viewer-Country
X-Nananana
X-Newrelic-Synthetics
X-ApacheServer
BehaviorPad-Version
X-PERF
X-VHOST
X-Render-Time
X-Servedbyhost
SID
X-VC-TTL
X-M-Log
X-M-Reqid
X-Parent-Response-Time
X-Response-Served-From
X-APP
X-B3-Parentspanid
X-CACHE-AGE
X-Original-Request-Id
X-LB-NoCache
GeoIP-Latitude
Datacenter
Fastly-Drupal-Html
Locid
X-Content-Length
X-TT-LOGID
X-Litespeed-Tag
X-DynaTrace-JS-Agent
Resin-Trace
Server-ID
X-Cached-By
X-Wa
X-Nc
Cf-Ipcountry
X-CS
X-CDN-Cache-Status
X-Amz-Meta-Cb-Modifiedtime
X-LiteSpeed-Tag
Cdn
X-IAuth-Set-Uid
X-ZONE
X-Old-Content-Length
NtCoent-Length
X-VCache
GeoIp-Country-Code
Vc-Max-Age
X-RequestId
FSS-Cache
Uri
Ngx-Var-Key
X-Fpc
X-NewRelic-App-Data
X-Varnish-Beresp-TTL
X-TX-ID
True-Client-Ip
X-Platform-Cluster
Serverhost
X-Vgn-Hpd-Reason
X-Esi
X-Dispatcher-Number
Product
X-Platform-Router
X-Platform-Processor
X-B3-Spanid
X-HostName
X-SERVER-NAME
X-Srv
CDN
X-TH-Server
Srv
True-Client-IP
X-Moov-Xdn-Version
X-Moov-T
X-Erf-Stays-Pdp-Viaduct-Migration-Web-V2
X-Cdn-Forward
Tcn
X-Ckpd-Fst-Backend
X-Nf-Country
X-Nf-Language
X-Nf-Ats-Version
X-Oracle-DMS-ECID
X-TIME
S-Rt
ServerName
X-FPC
X-Bug-Bounty
X-Dynatrace-Js-Agent
Cross-Origin-Embedder-Policy-Report-Only
Cf-Device-Type
GeoIP-Country-Code
Request-ID
X-Destination
X-Application
CacheControlHeader
X-WA
X-S-Cookie
X-User
X-Cdn-Cache-Status
X-NC
X-HubSpot-Correlation-Id
X-External-Request-Id
X-Dispatch
X-Vc
X-B-Cookie
X-CACHE-KEY
Server-Id
X-Zen-Fury
X-APP-VERSION
Hostname
X-COUNTRY
X-Sigma-Backend
X-Instance-Name
X-Sigma
X-Cache-Date
Geoip-Latitude
X-Rocket-Build-Number
Srvid
X-Geo
X-Webkit-Csp-Report-Only
X-FL-QIT-DEBUG
X-Presslabs-Stats
X-Vmg-Version
X-Lb-Nocache
X-Akamai-Device-Characteristics
User-Agent
X-Segment-20210421
X-VServer
Ohc-File-Size
X-API-Version
Origin-Trial
X-Info
X-Gamma-Serve
X-ServedByHost
ServerHost
X-Via-PopN
X-Via-PopV
X-Ha-Backend
X-Via-PopH
X-Branch-Name
X-VCL-Version
Epwk-X-Cache
Cloudfront-Viewer-Country
Xc-Version
PICS-Label
DataCenter
Load-Balancing
X-DynaTrace
Expect-Staple
X-Limited
X-Correlation-ID
X-App
X-Ua
Cneonction
X-DataCenter
X-Srcache-Fetch-Status
Rtss
X-Srcache-Store-Status
X-Amz-Meta-Opti
X-Check-Cacheable
X-MSEdge-Flight
X-MSEdge-Features
X-MiniProfiler-Ids
X-Hit
Ohc-Cache-HIT
X-Akamai-Pragma-Client-IP
X-Lb-Id
Type
X-Serial
Lb
X-Acquia-Site
Sm-Log-Id
X-Service-Response-Time
X-Acquia-Purge-Tags
Cross-Origin-Opener-Policy-Report-Only
X-Web-Server
X-Irp-Debug
X-Acquia-Application-UUID
X-Sqd-Stime
Warning
Timeexpire
Cmsid
X-Acquia-Application-Trace
X-Owner
X-Datacenter
X-Sqd-Ctime
Cmstype
X-Litespeed-Cache-Control
X-LAGOON
Servername
CountryCode
X-CSRF-TOKEN
X-Sorting-Hat-Podid
N-Cache
X-Sorting-Hat-Shopid
X-Shopid
Edge-Copy-Time
X-Origin-Upstream-Status
Cl-Cache
X-Core-Mission
X-Shardid
X-Amz-Meta-S3b-Last-Modified
X-Snapshot-Date
Ngx
X-Ramcache
X-Th-Server
X-Via-Edge
X-RAMCache
X-Qloud-Router
X-Via-SSL
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
X-Dw-Trace-Id
X-Udemy-Cache-App-Namespace
X-Via-CDN
X-Amz-Meta-Sha256
X-Requestid